Skip to main content
Unlisted page
This page is unlisted. Search engines will not index it, and only users having a direct link can access it.

Discrete Stochastic Calculus and Safe Multiswap Operations

· 27 min read
Eric Forgy
Founder of CavalRe

Multiswap is a discrete financial system. A transaction begins at one ledger state and ends at another. Reserves, scales, and prices are defined at the states; value flow occurs along the directed transition between them.

That description is not an approximation. It is the native geometry of a blockchain.

Discrete stochastic calculus gives this geometry an exact financial accounting rule. It distinguishes quantities defined at states from flows defined on transitions, preserves the order between previsible inventory and nonprevisible price, and recovers Itô calculus in the stochastic continuum limit. Applied to Multiswap, it produces post-trade value flow directly:

dsi=(dai)Pi+aidPi.\boxed{ ds_i=(da_i)P_i+a_i\,dP_i. }

The first term evaluates price at the destination state. The second revalues the opening reserve. Post-trade execution is therefore not an arbitrary conservative quote convention. It is the finite execution rule compatible with Itô accounting.

The same calculus gives an exact coefficient 1-form

dci=[G,ci]\boxed{ dc_i=[G,c_i] }

whose edge coefficients determine whether an operation moves each Reserve Asset and the LP Token in the permitted direction. This coefficient order contains the familiar swap and liquidity actions, but it also identifies a wider endpoint region containing direct permanent-reserve contributions, LP Token under-minting, general withdrawals, and heterogeneous multi-asset liquidity.

On the binary tree, exact coefficient order must hold on both outgoing branches. In the stochastic continuum limit, this removes the coefficient's Brownian component and leaves a one-sided generator condition. The boundary between safe and unsafe coefficient production is the backward diffusion equation

(t+12x2)ci=0.\boxed{ \left( \partial_t+\frac12\partial_x^2 \right)c_i=0. }

Surplus settlement provides the central application. A direct price-preserving state edit leaves this region by expanding the receive-asset coefficient. An ordinary counter-swap remains inside it because every step is an exact supported transition.

This article develops the complete argument from first principles. No prior knowledge of discrete calculus is assumed.

The results assume exact arithmetic, positive reserves and scales, homogeneous elasticities, and

0<es<1,eP=1es.0<e_s<1, \qquad e_P=1-e_s.

Coefficient order establishes state admissibility. A complete protocol operation must additionally specify funded token movements, valid consideration, account ownership, rounding, user limits, atomicity, and MEV policy.

1. Multiswap state

Let a pool contain n>1n>1 Reserve Assets. Reserve Asset ii has reserve

ai>0,a_i>0,

scale

si>0,s_i>0,

and marginal price

Pi=siai.\boxed{ P_i=\frac{s_i}{a_i}. }

Equivalently,

si=aiPi.\boxed{s_i=a_iP_i.}

The factor order will matter once the discrete differential is applied. Reserve aia_i is previsible: it is held before the next price innovation. Price PiP_i is not. Scale si=aiPis_i=a_iP_i is the resulting value process and is likewise not previsible at the destination state.

Scale elasticity and price elasticity satisfy

es+eP=1.e_s+e_P=1.

Define the elasticity coefficient

ci=siaies.\boxed{ c_i=\frac{s_i}{a_i^{e_s}}. }

Using si=aiPis_i=a_iP_i,

ci=aiessi=aiePPi.\boxed{ c_i=a_i^{-e_s}s_i=a_i^{e_P}P_i. }

Both forms place the previsible reserve factor before the nonprevisible value or price factor.

The coefficient identifies the elastic curve. A fixed-coefficient reserve transition satisfies

sisi=(aiai)es\boxed{ \frac{s_i'}{s_i} = \left(\frac{a_i'}{a_i}\right)^{e_s} }

and

PiPi=(aiai)eP.\boxed{ \frac{P_i'}{P_i} = \left(\frac{a_i'}{a_i}\right)^{-e_P}. }

The LP Token is indexed by 00. It has reserve a0a_0, scale

s0=i=1nsi,\boxed{ s_0=\sum_{i=1}^{n}s_i, }

price

P0=s0a0,P_0=\frac{s_0}{a_0},

and coefficient

c0=s0a0es.c_0=\frac{s_0}{a_0^{e_s}}.

The aggregate scale identity is a ledger identity. It must hold after every primitive action, not merely after a compound transaction finishes.

2. A short introduction to discrete calculus

Ordinary calculus assigns functions to points and differentials to infinitesimal directions. Discrete calculus makes the same distinction on a directed graph:

  • a discrete 0-form assigns a scalar to every node;
  • a discrete 1-form assigns a scalar to every directed edge.

A blockchain state variable is a 0-form. Its change across a transaction is a 1-form.

2.1 Nodes and 0-forms

Consider first a realized sequence of states indexed by tt. Let ete^t denote the basis 0-form associated with state tt. A coefficient process is

ci=tci(t)et.\boxed{ c_i=\sum_t c_i(t)e^t. }

The basis multiplication rule is

eteu=δt,uet.e^t e^u=\delta_{t,u}e^t.

Discrete 0-forms commute. In particular,

aiPi=Piai.a_iP_i=P_i a_i.

2.2 Directed edges and 1-forms

Let et,t+1e^{t,t+1} denote the directed edge from state tt to state t+1t+1. Define the graph 1-form

G=tet,t+1.\boxed{ G=\sum_t e^{t,t+1}. }

Multiplying an edge by a 0-form from the right evaluates the 0-form at the destination:

et,t+1eu=δt+1,uet,t+1.e^{t,t+1}e^u = \delta_{t+1,u}e^{t,t+1}.

Multiplying from the left evaluates it at the source:

euet,t+1=δu,tet,t+1.e^u e^{t,t+1} = \delta_{u,t}e^{t,t+1}.

Discrete 0-forms therefore commute with one another but do not commute with discrete 1-forms. This noncommutativity carries the financial ordering information.

2.3 The discrete differential

The discrete differential is the commutator with GG:

df=[G,f]=GffG.\boxed{ df=[G,f]=Gf-fG. }

For a 0-form

f=tf(t)et,f=\sum_t f(t)e^t,

we obtain

df=t[f(t+1)f(t)]et,t+1.\boxed{ df = \sum_t \left[f(t+1)-f(t)\right]e^{t,t+1}. }

The object dfdf is a 1-form. The scalar difference f(t+1)f(t)f(t+1)-f(t) is its coefficient on one edge; it is not the form itself.

Throughout this article, dd is reserved for the discrete differential and its Itô continuum limit. A finite change, or the scalar coefficient of a differential on one directed edge, is written

Δf=f(t+1)f(t)=ff.\boxed{ \Delta f=f(t+1)-f(t)=f'-f. }

Because the differential is a commutator, it satisfies the exact Leibniz rule

d(fg)=(df)g+f(dg).\boxed{ d(fg)=(df)g+f(dg). }

The formula looks familiar, but multiplication order makes it an exact finite product rule. On the edge tt+1t\rightarrow t+1, its coefficient is

f(t+1)g(t+1)f(t)g(t)=[f(t+1)f(t)]g(t+1)+f(t)[g(t+1)g(t)].f(t+1)g(t+1)-f(t)g(t) = \left[f(t+1)-f(t)\right]g(t+1) + f(t)\left[g(t+1)-g(t)\right].

The first difference uses the destination value of the factor on its right. The second uses the source value of the factor on its left.

3. The binary tree and stochastic coordinates

A stochastic process has more than one possible successor state. The minimal example is a binary tree. At a node (m,j)(m,j), let the two outgoing edge 1-forms be

e+,e.\mathbf e^+, \qquad \mathbf e^-.

For any 0-form ff, write its two successor values as f+f_+ and ff_- and its opening value as ff. Then

df=(f+f)e++(ff)e.df = (f_+-f)\mathbf e^+ + (f_--f)\mathbf e^-.

3.1 Cartesian coordinates

Place time coordinate tt and stochastic coordinate xx on the tree so that

t±=t+Δtt_\pm=t+\Delta t

and

x±=x±Δx.x_\pm=x\pm\Delta x.

Their differentials are

dt=Δt(e++e)\boxed{ dt=\Delta t(\mathbf e^++\mathbf e^-) }

and

dx=Δx(e+e).\boxed{ dx=\Delta x(\mathbf e^+-\mathbf e^-). }

These relations invert to

e+=dt2Δt+dx2Δx,\mathbf e^+ = \frac{dt}{2\Delta t} + \frac{dx}{2\Delta x}, e=dt2Δtdx2Δx.\mathbf e^- = \frac{dt}{2\Delta t} - \frac{dx}{2\Delta x}.

Thus dtdt and dxdx span the discrete 1-forms on the binary tree. One stochastic coordinate xx is sufficient for this two-branch calculus. Every Multiswap variable may be a different 0-form of the same coordinates (t,x)(t,x).

The finite coordinate commutation relations are

[dx,x]=(Δx)2Δtdt,\boxed{ [dx,x] = \frac{(\Delta x)^2}{\Delta t}dt, } [dx,t]=[dt,x]=Δtdx,[dx,t]=[dt,x]=\Delta t\,dx,

and

[dt,t]=Δtdt.[dt,t]=\Delta t\,dt.

3.2 The stochastic continuum limit

Choose the stochastic scaling

Δt=(Δx)2.\boxed{ \Delta t=(\Delta x)^2. }

As Δt0\Delta t\rightarrow0, the commutation relations become

[dx,x]=dt,\boxed{ [dx,x]=dt, } [dx,t]=[dt,x]=[dt,t]=0.\boxed{ [dx,t]=[dt,x]=[dt,t]=0. }

For a 0-form f(t,x)f(t,x), the discrete differential then converges to

df=(tf+12x2f)dt+(xf)dx.\boxed{ df = \left( \partial_t f + \frac12\partial_x^2f \right)dt + (\partial_xf)dx. }

This is the Itô formula. Its second-order term is not added by hand. It follows from the noncommutative coordinate relation [dx,x]=dt[dx,x]=dt.

4. Previsibility forces post-trade value flow

Return to the exact Multiswap identity

si=aiPi.s_i=a_iP_i.

The discrete Leibniz rule gives the 1-form identity

dsi=(dai)Pi+aidPi.\boxed{ ds_i=(da_i)P_i+a_i\,dP_i. }

On a directed edge from the opening state to the final state, its coefficient is

Δsi=ΔaiPi+aiΔPi.\boxed{ \Delta s_i = \Delta a_iP_i' + a_i\Delta P_i. }

Define

Δai=aiai,ΔPi=PiPi.\Delta a_i=a_i'-a_i, \qquad \Delta P_i=P_i'-P_i.

The edge coefficient becomes

Δsi=ΔaiPi+aiΔPi.\Delta s_i=\Delta a_iP_i'+a_i\Delta P_i.

The two terms have distinct financial meanings:

Σi=ΔaiPi\boxed{ \Sigma_i=\Delta a_iP_i' }

is signed execution value flow, while

Γi=aiΔPi\boxed{ \Gamma_i=a_i\Delta P_i }

is revaluation of the opening reserve.

Reserve aia_i appears to the left of dPidP_i in the 1-form identity and is evaluated at the source. It is previsible. Price appears to the right of daida_i and is evaluated at the destination. It is not previsible before the edge is realized.

Under the stochastic continuum limit, the same identity becomes the Itô product rule. In ordinary commutative notation,

dsi=Pidai+aidPi+d[ai,Pi].ds_i = P_i\,da_i + a_i\,dP_i + d[a_i,P_i].

The quadratic-covariation term is already contained in the post-trade expression (dai)Pi(da_i)P_i.

Post-trade execution and Itô market accounting are therefore complementary descriptions of the same ordered product rule.

5. The execution gauge

Because discrete 0-forms commute,

aiPi=Piaia_iP_i=P_i a_i

and therefore

d(aiPi)=d(Piai).d(a_iP_i)=d(P_i a_i).

The two Leibniz expansions are

d(aiPi)=(dai)Pi+aidPid(a_iP_i)=(da_i)P_i+a_i\,dP_i

and

d(Piai)=(dPi)ai+Pidai.d(P_i a_i)=(dP_i)a_i+P_i\,da_i.

Any weighted combination remains the same total scale 1-form:

dsi=kd(aiPi)+(1k)d(Piai).ds_i = k\,d(a_iP_i) + (1-k)d(P_i a_i).

On one edge, define

EkPi=kPi+(1k)PiE_kP_i=kP_i'+(1-k)P_i

and

E1kai=kai+(1k)ai.E_{1-k}a_i=ka_i+(1-k)a_i'.

Then

Δsi=ΔaiEkPi+E1kaiΔPi.\boxed{ \Delta s_i = \Delta a_iE_kP_i + E_{1-k}a_i\Delta P_i. }

The total scale change is gauge invariant. The attribution between execution value and market revaluation is not.

Under a finite change kk+Δkk\rightarrow k+\Delta k, the execution component receives

ΔkΔaiΔPi\Delta k\,\Delta a_i\Delta P_i

while the market component loses the same amount.

Three gauges are especially recognizable:

kkExecution valueMarket revaluationContinuum convention
00PiΔaiP_i\Delta a_iaiΔPia_i'\Delta P_iBackward Itô
12\tfrac1212(Pi+Pi)Δai\tfrac12(P_i+P_i')\Delta a_i12(ai+ai)ΔPi\tfrac12(a_i+a_i')\Delta P_iStratonovich
11PiΔaiP_i'\Delta a_iaiΔPia_i\Delta P_iItô

The gauge freedom is mathematically real. Previsibility fixes the financial gauge. Market P&L must apply to inventory held before the price innovation, so its integrand must be aia_i, not aia_i' or a midpoint containing aia_i'. Therefore

k=1.\boxed{k=1.}

This is why midpoint value flow cannot be judged in isolation. Exact accounting forces midpoint reserve into the market term, causing newly acquired inventory to experience half of a price movement that occurred before it was acquired and disposed inventory to retain half of a movement after disposal.

At k=0k=0, the entire trade executes at a stale price and market P&L is assigned to destination inventory. The failure is immediate. Consider ABA\rightarrow B followed by returning exactly the received BB. The first trade satisfies

PAΔaA+PBΔaB=0.P_A\Delta a_A+P_B\Delta a_B=0.

The reverse trade executes at the new opening prices. The AA returned to the trader is

ΔaA(2)=ΔaAPB/PBPA/PA.-\Delta a_A^{(2)} = \Delta a_A \frac{P_B'/P_B}{P_A'/P_A}.

For fixed-coefficient elasticity,

PB/PBPA/PA=(1+rA1+rB)eP>1\frac{P_B'/P_B}{P_A'/P_A} = \left( \frac{1+r_A}{1+r_B} \right)^{e_P} >1

for every nonzero trade because rA>0r_A>0 and rB<0r_B<0. Every such round trip extracts AA from the pool without requiring reserve depletion.

6. Coefficients as discrete 0-forms

The coefficient process is a discrete 0-form

ci=tci(t)et.\boxed{ c_i=\sum_t c_i(t)e^t. }

Its discrete differential is the 1-form

dci=[G,ci]=t[ci(t+1)ci(t)]et,t+1.\boxed{ dc_i=[G,c_i] = \sum_t \left[c_i(t+1)-c_i(t)\right]e^{t,t+1}. }

The canonical ordered coefficient representation is

ci=aiePPi=aiessi.c_i=a_i^{e_P}P_i=a_i^{-e_s}s_i.

Therefore

dci=d(aieP)Pi+aiePdPi\boxed{ dc_i = d(a_i^{e_P})P_i + a_i^{e_P}dP_i }

and equivalently

dci=d(aies)si+aiesdsi.\boxed{ dc_i = d(a_i^{-e_s})s_i + a_i^{-e_s}ds_i. }

These are exact 1-form identities. On an edge, the factors to the right of a differential are evaluated at the destination; the factors to the left are evaluated at the source.

6.1 The Itô coefficient limit

The stochastic continuum limit of dci=[G,ci]dc_i=[G,c_i] is not the ordinary quotient differential. In (ai,Pi)(a_i,P_i) coordinates it is

dcici=dPiPi+ePdaiai+ePd[ai,Pi]aiPieseP2d[ai]ai2.\boxed{ \frac{dc_i}{c_i} = \frac{dP_i}{P_i} + e_P\frac{da_i}{a_i} + e_P\frac{d[a_i,P_i]}{a_iP_i} - \frac{e_se_P}{2} \frac{d[a_i]}{a_i^2}. }

In (ai,si)(a_i,s_i) coordinates it is

dcici=dsisiesdaiaiesd[ai,si]aisi+es(es+1)2d[ai]ai2.\boxed{ \frac{dc_i}{c_i} = \frac{ds_i}{s_i} - e_s\frac{da_i}{a_i} - e_s\frac{d[a_i,s_i]}{a_is_i} + \frac{e_s(e_s+1)}{2} \frac{d[a_i]}{a_i^2}. }

The covariance and quadratic-variation terms are essential. Along an exactly fixed-coefficient process they cancel the apparent second-order drift and give dci=0dc_i=0, as they must.

For protocol transitions, however, the exact discrete 1-form remains primary. No continuum approximation is required to check an edge.

6.2 The diffusion equation on the coefficient boundary

The binary tree reveals the continuum boundary of exact coefficient order. Write the two branch coefficients of dcidc_i as

Δ+ci=ci,+ci,Δci=ci,ci.\Delta_+c_i=c_{i,+}-c_i, \qquad \Delta_-c_i=c_{i,-}-c_i.

Because dtdt and dxdx span the edge 1-forms, we may write

dci=Aidt+Bidx,\boxed{ dc_i=A_i\,dt+B_i\,dx, }

where

Ai=ci,++ci,2ci2ΔtA_i = \frac{c_{i,+}+c_{i,-}-2c_i}{2\Delta t}

and

Bi=ci,+ci,2Δx.B_i = \frac{c_{i,+}-c_{i,-}}{2\Delta x}.

The two edge coefficients are therefore

Δ±ci=AiΔt±BiΔx.\boxed{ \Delta_\pm c_i = A_i\Delta t \pm B_i\Delta x. }

Exact Reserve Asset safety requires both branches to be nonpositive:

Δ+ci0,Δci0.\Delta_+c_i\le0, \qquad \Delta_-c_i\le0.

Equivalently,

AiΔtBiΔx.\boxed{ A_i\Delta t\le-|B_i|\Delta x. }

LP Token safety reverses the inequality:

A0ΔtB0Δx.\boxed{ A_0\Delta t\ge|B_0|\Delta x. }

Under stochastic scaling, Δx=Δt\Delta x=\sqrt{\Delta t}. A smooth continuum limit with finite AiA_i and BiB_i can satisfy either pathwise inequality only if its Brownian coefficient vanishes:

Bi=xci=0.\boxed{ B_i=\partial_xc_i=0. }

Define the Brownian generator

L=t+12x2.\mathcal L = \partial_t+\frac12\partial_x^2.

The remaining finite-variation condition is

Lci0\boxed{ \mathcal Lc_i\le0 }

for a Reserve Asset and

Lc00\boxed{ \mathcal Lc_0\ge0 }

for the LP Token.

The boundary of either safe region is zero coefficient production. There,

Lci=0    tci+12x2ci=0.\boxed{ \mathcal Lc_i=0 \iff \partial_t c_i+\frac12\partial_x^2c_i=0. }

Thus the coefficient satisfies the backward diffusion equation on the coefficient-order boundary. For exact pathwise order, this boundary condition is accompanied by xci=0\partial_xc_i=0: the safe coefficient process has no Brownian component of its own even though reserves, prices, and scales may remain stochastic.

This is stronger than an expected-sign condition. A supermartingale or submartingale may retain a nonzero dxdx term, but it can move in the prohibited direction on an individual branch. Multiswap's finite protocol classifier remains the exact edgewise order in the next section; the generator inequalities and diffusion boundary are its stochastic continuum limit.

7. Exact coefficient order on directed edges

Multiswap uses a one-sided coefficient order. On every realized edge, the coefficient of dcidc_i must be nonpositive for each Reserve Asset and nonnegative for the LP Token:

Δci=ci(t+1)ci(t)0(i=1,,n),\boxed{ \Delta c_i = c_i(t+1)-c_i(t) \le0 \quad(i=1,\ldots,n), } Δc0=c0(t+1)c0(t)0.\boxed{ \Delta c_0 = c_0(t+1)-c_0(t) \ge0. }

Define the multiplicative edge certificate

χi(t)=ci(t+1)ci(t)=si(t+1)si(t)(ai(t)ai(t+1))es.\boxed{ \chi_i(t) = \frac{c_i(t+1)}{c_i(t)} = \frac{s_i(t+1)}{s_i(t)} \left( \frac{a_i(t)}{a_i(t+1)} \right)^{e_s}. }

Because every coefficient is positive, edge safety is equivalent to

χi1\boxed{ \chi_i\le1 }

for every Reserve Asset and

χ01\boxed{ \chi_0\ge1 }

for the LP Token.

The additive and multiplicative descriptions belong to the same edge. Left normalization of the 1-form gives

ci1dci=t[χi(t)1]et,t+1.c_i^{-1}dc_i = \sum_t \left[\chi_i(t)-1\right]e^{t,t+1}.

The logarithmic 1-form gives

dlogci=[G,logci]=tlogχi(t)et,t+1.\boxed{ d\log c_i = [G,\log c_i] = \sum_t \log\chi_i(t)e^{t,t+1}. }

For a path of sequential transitions,

cifinalciinitial=tχi(t).\frac{c_i^{\mathrm{final}}}{c_i^{\mathrm{initial}}} = \prod_t\chi_i(t).

Coefficient safety therefore composes exactly. Every safe primitive carries the certificate required by the next primitive.

7.1 Exact endpoint inequalities

For each Reserve Asset,

sisi(aiai)es.\boxed{ \frac{s_i'}{s_i} \le \left( \frac{a_i'}{a_i} \right)^{e_s}. }

For the LP Token,

s0s0(a0a0)es.\boxed{ \frac{s_0'}{s_0} \ge \left( \frac{a_0'}{a_0} \right)^{e_s}. }

These inequalities define the complete coefficient-order endpoint region. They are exact finite edge conditions, not integrations of an ordinary local differential.

8. Execution balance and LP Token safety

For a signed reserve change, define

ri=Δaiai,ri>1.r_i=\frac{\Delta a_i}{a_i}, \qquad r_i>-1.

A fixed-coefficient leg has

ai=ai(1+ri),a_i'=a_i(1+r_i), si=si(1+ri)es,s_i'=s_i(1+r_i)^{e_s},

and

Pi=Pi(1+ri)eP.P_i'=P_i(1+r_i)^{-e_P}.

At post-trade execution,

Σi=ΔaiPi=siri(1+ri)eP.\boxed{ \Sigma_i = \Delta a_iP_i' = s_i\frac{r_i}{(1+r_i)^{e_P}}. }

The general value-flow identity is

Σ0=i=1nΣi.\boxed{ \Sigma_0 = \sum_{i=1}^{n}\Sigma_i. }

For a reserve-only swap,

Σ0=0\Sigma_0=0

and therefore

i=1nΣi=0.\sum_{i=1}^{n}\Sigma_i=0.

The reserve-only specialization must not replace the general identity.

For k=1k=1, each fixed-coefficient leg admits the exact decomposition

Δsi=esΣi+Di,\boxed{ \Delta s_i=e_s\Sigma_i+\mathcal D_i, }

where

Di=si[(1+ri)es1esri(1+ri)eP]0.\mathcal D_i = s_i \left[ (1+r_i)^{e_s} -1 -e_s r_i(1+r_i)^{-e_P} \right] \ge0.

The inequality is strict for every nonzero leg. Summing and using the general value-flow identity gives

Δs0=esΣ0+i=1nDi.\boxed{ \Delta s_0 = e_s\Sigma_0 + \sum_{i=1}^{n}\mathcal D_i. }

For a nontrivial reserve-only swap, Σ0=0\Sigma_0=0, so

Δs0=i=1nDi>0.\Delta s_0 = \sum_{i=1}^{n}\mathcal D_i >0.

Every Reserve Asset coefficient remains fixed, a0a_0 remains fixed, and c0c_0 increases.

8.1 General fixed linear execution

For execution price

Piexec=Pi+kΔPi,P_i^{\mathrm{exec}}=P_i+k\Delta P_i,

define

Σi(k)=ΔaiPiexec.\Sigma_i^{(k)}=\Delta a_iP_i^{\mathrm{exec}}.

The exact product rule gives

Δs0=Σ0(k)+i=1naiΔPi+(1k)i=1nΔaiΔPi.\boxed{ \Delta s_0 = \Sigma_0^{(k)} + \sum_{i=1}^{n}a_i\Delta P_i + (1-k) \sum_{i=1}^{n}\Delta a_i\Delta P_i. }

For a reserve-only swap, define opening-reserve revaluation

R=i=1naiΔPi\mathcal R=\sum_{i=1}^{n}a_i\Delta P_i

and execution-to-final-price shortfall

S=i=1nΔaiΔPi>0.\mathcal S=-\sum_{i=1}^{n}\Delta a_i\Delta P_i>0.

Then

Δs0=R(1k)S.\boxed{ \Delta s_0 = \mathcal R-(1-k)\mathcal S. }

The exact LP coefficient condition is

R(1k)S0.\boxed{ \mathcal R-(1-k)\mathcal S\ge0. }

Post-trade execution eliminates the shortfall term. For every fixed k<1k<1, sufficiently asymmetric finite swaps make the shortfall dominate. Therefore, within 0k10\le k\le1,

k=1\boxed{k=1}

is the unique fixed linear execution rule that automatically makes every admissible finite fixed-coefficient reserve-only swap LP-coefficient-safe.

9. The wider coefficient-order region

The exact endpoint inequalities identify more admissible state transitions than the initially studied swap, single-asset liquidity, proportional liquidity, and burn formulas.

These are mathematical candidates. Coefficient order establishes their endpoint direction; it does not itself supply consideration or implementation.

9.1 Direct permanent-reserve allocation

Suppose Surplus contributes

ΔaA>0\Delta a_A>0

directly to Reserve Asset AA without minting LP Tokens:

aA=aA+ΔaA,a0=a0.a_A'=a_A+\Delta a_A, \qquad a_0'=a_0.

Leave every other Reserve Asset unchanged. If only AA scale changes, aggregate scale gives

Δs0=ΔsA.\Delta s_0=\Delta s_A.

LP coefficient safety requires sAsAs_A'\ge s_A. Reserve Asset safety supplies the upper bound. The complete coefficient-order interval is

sAsAsA(1+ΔaAaA)es.\boxed{ s_A \le s_A' \le s_A \left( 1+ \frac{\Delta a_A}{a_A} \right)^{e_s}. }

At the lower endpoint, cAc_A contracts and c0c_0 remains fixed. At the upper endpoint, cAc_A remains fixed and c0c_0 expands. Every point between them moves both coefficients in their permitted directions.

This direct transition is endpoint-equivalent to a range of explicit liquidity-mint-and-burn constructions.

9.2 LP Token under-minting

Suppose a funded reserve operation changes LP scale from s0s_0 to s0>s0s_0'>s_0. Conditional on every Reserve Asset satisfying its own coefficient inequality, LP Token safety requires

a0a0(s0s0)1/es.\boxed{ a_0' \le a_0 \left( \frac{s_0'}{s_0} \right)^{1/e_s}. }

The maximum permitted LP Token mint is

Δa0max=a0[(s0s0)1/es1].\boxed{ \Delta a_0^{\max} = a_0 \left[ \left( \frac{s_0'}{s_0} \right)^{1/e_s} -1 \right]. }

Minting the maximum preserves c0c_0. Minting less expands it. Minting nothing produces permanent liquidity. Minting the maximum and burning part of it is endpoint-equivalent to under-minting initially.

9.3 General withdrawals

If an operation reduces total Reserve Asset scale so that s0<s0s_0'<s_0, LP coefficient safety requires

a0a0(s0s0)1/es.a_0' \le a_0 \left( \frac{s_0'}{s_0} \right)^{1/e_s}.

Conditional on every Reserve Asset satisfying its own coefficient condition, the operation must burn at least

Δa0a0[1(s0s0)1/es].\boxed{ -\Delta a_0 \ge a_0 \left[ 1 - \left( \frac{s_0'}{s_0} \right)^{1/e_s} \right]. }

This is a coefficient boundary, not a fair-redemption formula. The reserve consideration owed for the burned LP Tokens must be specified separately.

9.4 General multi-asset liquidity

The supported common-λ\lambda construction contracts every nonparticipating Reserve Asset coefficient by one multiplier

0<λ<1.0<\lambda<1.

The exact discrete edge condition permits a larger region. Different Reserve Assets may have different multipliers provided

χi1\chi_i\le1

for every Reserve Asset,

χ01,\chi_0\ge1,

and

s0=i=1nsi.s_0'=\sum_{i=1}^{n}s_i'.

The common-λ\lambda construction remains computationally useful because it can update an entire complement set through one shared multiplier. It is a sufficient implementation pattern, not the definition of every coefficient-order-admissible endpoint.

10. Surplus settlement

Multiswap Surplus is exogenous protocol inventory. When a user receives an asset held in Surplus, the protocol can supply some or all of that output and convert the inventory into reserve growth, Rewards, Treasury revenue, or an ongoing CAV token sale.

The user still receives the ordinary swap quote. The question is how Surplus changes the pool state after supplying the output.

Two constructions have been considered:

  1. a direct price-preserving state adjustment;
  2. an ordinary Surplus counter-swap composed after the user swap.

They can deliver the same tokens to the user while leaving radically different coefficient states.

10.1 Why direct price preservation fails

Consider a user swap

ABA\longrightarrow B

with receive change

ΔaB<0.\Delta a_B<0.

If the pool settled the swap normally, the hypothetical final reserve would be

aB=aB+ΔaB,0<aB<aB.a_B^*=a_B+\Delta a_B, \qquad 0<a_B^*<a_B.

The original price-preserving construction instead supplied BB from Surplus and restored the pool reserve to aBa_B, while adjusting scale so that the final price equaled the ordinary hypothetical price:

PBPP=PB.P_B^{\mathrm{PP}}=P_B^*.

The ordinary fixed-coefficient state satisfies

PB=cB(aB)eP.P_B^*=c_B(a_B^*)^{-e_P}.

The price-preserving state satisfies

PBPP=cBPPaBeP.P_B^{\mathrm{PP}} = c_B^{\mathrm{PP}}a_B^{-e_P}.

Equating prices gives

cBPPcB=(aBaB)eP>1.\boxed{ \frac{c_B^{\mathrm{PP}}}{c_B} = \left( \frac{a_B}{a_B^*} \right)^{e_P} >1. }

The receive coefficient expands. The transition therefore gives dcBdc_B a positive edge coefficient and violates Reserve Asset coefficient order immediately.

The economic problem is exact: the state prices BB as though it were scarce while retaining the full reserve as future pricing depth. Preserving one marginal price did not preserve the elastic curve associated with that price.

This failure does not require an immediate closed round trip. External holders can later sell inventory into the artificially deep state and receive more than the ordinary post-swap curve would permit.

10.2 The ordinary counter-swap

The corrected construction uses only ordinary state transitions:

  1. the user executes ABA\rightarrow B;
  2. from the resulting state, Surplus executes BAB\rightarrow A;
  3. the protocol allocates the actual AA received by Surplus.

For full settlement, Surplus pays exactly the amount of BB required to restore the pool's BB reserve:

ΔaBuser+ΔaBSurplus=0.\Delta a_B^{\mathrm{user}} + \Delta a_B^{\mathrm{Surplus}} =0.

Both swaps preserve cBc_B. Restoring aBa_B therefore restores sBs_B and PBP_B.

Surplus receives less AA than the user paid. The difference remains in the pool as round-trip gain. The complete pool state is not restored, and the construction does not claim price preservation.

That distinction is essential. The counter-swap reaches its final price through a path of ordinary coefficient-preserving edges. It does not manufacture a price-preserving endpoint by expanding a Reserve Asset coefficient.

10.3 Partial and multi-asset settlement

Surplus may supply any amount between zero and the user's complete output. The covered amount becomes the size of an ordinary counter-swap calculated from the actual post-user state. Partial settlement does not interpolate reserves, scales, or prices after the fact.

For an atomic multi-asset user swap, the supplied receive assets form the pay side of one ordinary multi-asset Surplus sale. The counter-action obeys

Σ0=i=1nΣi.\Sigma_0 = \sum_{i=1}^{n}\Sigma_i.

Because it is reserve-only,

Σ0=0\Sigma_0=0

and therefore

i=1nΣi=0.\sum_{i=1}^{n}\Sigma_i=0.

Every participating Reserve Asset coefficient remains fixed.

The counter-action is an underlying ordinary action, not a new user action eligible for another Surplus adjustment. Counter-actions do not recurse.

11. Allocating realized Surplus proceeds

After selling supplied inventory through the counter-swap, Surplus holds actual proceeds. The protocol may allocate those proceeds among Reserves, Rewards, Treasury, or other declared accounts.

The pool-state and ownership questions must remain separate.

11.1 Supported liquidity allocation

One construction applies a supported single-asset liquidity action

ALP.A\longrightarrow LP.

The active coefficient cAc_A and LP coefficient c0c_0 remain fixed while every nonparticipating Reserve Asset coefficient contracts by one common multiplier

0<λ<1.0<\lambda<1.

The protocol may then:

  • retain the minted LP Tokens as protocol-owned liquidity;
  • distribute them to Rewards or Treasury;
  • place them in an irrevocable or time-controlled account;
  • burn some or all of them without withdrawing reserves.

Holding or transferring LP Tokens among external accounts does not change pool state. Burning protocol-owned LP Tokens reduces a0a_0 while leaving s0s_0 fixed, so c0c_0 increases and every Reserve Asset coefficient remains unchanged.

11.2 Direct permanent-reserve allocation

The exact endpoint interval from Section 9.1 permits a direct funded reserve allocation without an intermediate mint and burn:

sAsAsA(1+ΔaAaA)es.s_A \le s_A' \le s_A \left( 1+ \frac{\Delta a_A}{a_A} \right)^{e_s}.

This is often a cleaner state transition. It does not eliminate the allocation question. Adding reserves without issuing LP Tokens benefits whoever owns the existing LP Token supply.

11.3 Temporary-liquidity capture

Coefficient safety does not make permanent-liquidity allocation neutral to transaction ordering.

Suppose a temporary provider enters proportionally with relative increase rJ>0r_J>0. Every reserve and LP Token supply increases by 1+rJ1+r_J. A later Surplus allocation adds ΔaAalloc>0\Delta a_A^{\mathrm{alloc}}>0 to Reserve Asset AA without increasing the temporary provider's LP Token balance.

When the temporary provider exits proportionally, the amount of AA returned is

ΔaAexit=rJaA+rJ1+rJΔaAalloc.\boxed{ -\Delta a_A^{\mathrm{exit}} = r_Ja_A + \frac{r_J}{1+r_J}\Delta a_A^{\mathrm{alloc}}. }

The first term returns the provider's contribution. The second is a positive share of the Surplus allocation.

The proportional entry and exit preserve every coefficient. The allocation between them moves coefficients safely. The complete sequence remains coefficient-order admissible even though the temporary provider captures value intended for incumbent LP Token holders.

User minimum receive does not prevent this strategy because it targets ownership at the allocation, not the user's swap execution. The protocol must choose the intended beneficiary and then retain, distribute, lock, or burn LP Tokens accordingly.

12. Additive coefficient production

The logarithmic 1-form

dlogci=[G,logci]d\log c_i=[G,\log c_i]

has edge coefficient

logχi.\log\chi_i.

Define component production on each edge by

h0=logχ0h_0=\log\chi_0

for the LP Token and

hi=logχih_i=-\log\chi_i

for Reserve Assets. Every componentwise coefficient-safe edge has

h00,hi0.h_0\ge0, \qquad h_i\ge0.

An aggregate diagnostic is

ΔH=h0+1n1i=1nhi0.\boxed{ \Delta\mathcal H = h_0 + \frac{1}{n-1} \sum_{i=1}^{n}h_i \ge0. }

The scalar is additive along paths because logarithmic edge coefficients telescope. It is weaker than the componentwise order: one Reserve Asset coefficient can expand while larger safe movements elsewhere keep the aggregate positive. The individual edge signs remain authoritative.

The separate thermodynamic interpretation of this logarithmic monotone is not required for the safety proofs in this article.

13. Complete-operation requirements

Coefficient order classifies the resulting state. It does not prove that an authorized transition was fairly funded.

A complete operation must specify:

  • which account funds every positive reserve change;
  • which account receives every negative reserve change;
  • the execution or other consideration rule;
  • LP Token issuance or destruction;
  • aggregate scale consistency;
  • reserve and scale positivity;
  • pool-favorable rounding;
  • user minimum-receive or maximum-pay conditions;
  • atomicity of compound actions;
  • ownership and MEV policy.

The complete design rule is

valid operation=coefficient-order edge+valid consideration+funded token movement+aggregate consistency+implementation controls.\boxed{ \begin{aligned} \text{valid operation} ={}&\text{coefficient-order edge}\\ &+\text{valid consideration}\\ &+\text{funded token movement}\\ &+\text{aggregate consistency}\\ &+\text{implementation controls}. \end{aligned} }

Every primitive and randomized composition should verify:

Positive state

ai>0,si>0.a_i'>0, \qquad s_i'>0.

Aggregate scale

s0=i=1nsi.\boxed{ s_0'=\sum_{i=1}^{n}s_i'. }

General value-flow balance

Σ0=i=1nΣi.\boxed{ \Sigma_0 = \sum_{i=1}^{n}\Sigma_i. }

For a reserve-only action, separately verify the specialization

Σ0=0i=1nΣi=0.\Sigma_0=0 \quad\Longrightarrow\quad \sum_{i=1}^{n}\Sigma_i=0.

Componentwise coefficient direction

For every Reserve Asset,

χi1.\chi_i\le1.

For the LP Token,

χ01.\chi_0\ge1.

Token conservation and ownership

Every positive movement must be funded, every negative movement must reach its declared recipient, and every LP Token mint or burn must match the operation.

User and ordering controls

Enforce minimum receive, maximum pay, deterministic Surplus coverage, atomic user-plus-counter execution, and the declared policy for LP Token ownership around permanent-liquidity allocations.

14. What is established and what remains open

Within the stated exact-arithmetic domain, the analysis establishes:

  1. discrete stochastic calculus produces post-trade value flow from the ordered identity si=aiPis_i=a_iP_i;
  2. the stochastic continuum limit is Itô because [dx,x]=dt[dx,x]=dt;
  3. exact pathwise coefficient order removes the coefficient's Brownian component in the continuum limit and meets the diffusion equation Lci=0\mathcal Lc_i=0 on its boundary;
  4. k=1k=1 is the previsibility-compatible execution gauge;
  5. fixed-coefficient reserve transitions have zero coefficient 1-form on every edge;
  6. componentwise coefficient order composes exactly through the multipliers χi\chi_i;
  7. every nontrivial post-trade reserve-only swap increases the LP Token coefficient;
  8. no fixed linear k<1k<1 automatically protects the LP Token coefficient for every finite swap;
  9. the exact coefficient region admits direct permanent reserves, LP Token under-minting, general withdrawals, and heterogeneous multi-asset liquidity candidates;
  10. direct price-preserving Surplus settlement expands the receive coefficient and is inadmissible;
  11. ordinary Surplus counter-swaps remain inside coefficient order by composition;
  12. coefficient-safe permanent-liquidity allocation still requires an explicit ownership and MEV policy.

Open engineering and policy boundaries include:

  • fees and ownership of fee value flow;
  • finite-precision power evaluation and pool-favorable rounding;
  • external-price controls for protocol inventory sales;
  • production eligibility and size limits for Surplus assets;
  • implementation of newly identified general coefficient-order transitions;
  • temporary-liquidity policy around permanent allocations;
  • independent security and economic review.

Conclusion

Multiswap does not need to approximate a continuous market and then discretize it for the EVM. It begins with the directed state transitions that the EVM actually executes.

Discrete 0-forms describe reserves, scales, prices, and coefficients at ledger states. Discrete 1-forms describe changes and value flows across transaction edges. The graph 1-form GG generates the differential through

dci=[G,ci].dc_i=[G,c_i].

On a binary tree, the coordinates (t,x)(t,x) satisfy

[dx,x]=dt[dx,x]=dt

in the stochastic continuum limit, so the exact discrete calculus recovers Itô rather than ordinary calculus.

Exact coefficient order on both branches removes the coefficient's own Brownian term. Its continuum safe regions satisfy opposite generator inequalities for Reserve Assets and the LP Token, and their common boundary is

(t+12x2)ci=0.\left( \partial_t+\frac12\partial_x^2 \right)c_i=0.

Previsibility then fixes the economically meaningful ordering:

si=aiPi,ci=aiePPi=aiessi.s_i=a_iP_i, \qquad c_i=a_i^{e_P}P_i=a_i^{-e_s}s_i.

The first identity produces post-trade value flow. The second produces the coefficient 1-form whose edge coefficients define safe state motion. Together with

s0=i=1nsis_0=\sum_{i=1}^{n}s_i

and

Σ0=i=1nΣi,\Sigma_0=\sum_{i=1}^{n}\Sigma_i,

they separate four questions cleanly:

calculus:df=[G,f],execution:Σi=ΔaiPi,state safety:χi1, χ01,complete operation:funding, consideration, and controls.\boxed{ \begin{aligned} \text{calculus}&:\quad df=[G,f],\\ \text{execution}&:\quad \Sigma_i=\Delta a_iP_i',\\ \text{state safety}&:\quad \chi_i\le1,\ \chi_0\ge1,\\ \text{complete operation}&:\quad \text{funding, consideration, and controls}. \end{aligned} }

This structure explains both the wider design space and its limits. Safe operations are not a memorized list. They are directed edges that preserve balance, remain inside coefficient order, and carry economically valid boundary flows.