★ delegatecall/call in proposal execution without allowlist
Meteora's assessment for RD-F-039 — scored not_applicable on the v1.7.0 rubric. The evidence below is the curator's reasoning for this score.
Evidence summary #
Solana BPF has no delegatecall opcode. No EVM-style governor with delegatecall execution path exists. Solana uses CPI (Cross-Program Invocation) which is architecturally distinct and not subject to the same attack vector. Factor is structurally inapplicable to Solana non-EVM substrate.
Sources #
- InternalMeteora Protocol Profile — Substrate flag.research/protocols/meteora/00-profile.md §11 — non_evm_substrate: trueretrieved 2026-05-16
- Solana Governance Verification MethodologySOLANA_GOVERNANCE.md — Solana substrate methodology; no delegatecall equivalentretrieved 2026-05-16
Methodology #
Determine whether the governance executor contract uses `delegatecall` or `call` with proposal-supplied target, without enforcing an allowlist of permitted targets.
See the full factor methodology and distribution across all protocols →
rubric_version v1.7.0 protocol meteora factor RD-F-039 score not_applicable collected_at 2026-05-16 10:03:05