Externally Owned Surplus
Surplus is externally owned CAV held by the Protocol for sale. CavalRe owns the CAV, authorizes its use, and receives the sale proceeds in CavalRe Treasury. CavalRe and the Protocol are distinct accounting entities.
The mechanism can route independent fractions of the user's pay and receive legs through Reserve. The remaining amounts execute as a CavalRe-owned CAV sale. A pure sale bypasses Reserve and leaves Multiswap prices unchanged. A mixed settlement is accepted when its complete Reserve endpoint passes the gauge-invariant safety condition.
1. Direct quote
Consider a user exchanging for CAV. First calculate the ordinary direct Multiswap quote
with
The user receives the same quoted CAV amount under Surplus settlement. Surplus changes the sources and destinations of the token legs, not the user's quote.
2. Ownership journal
When CavalRe places CAV in Surplus, the CAV ledger posts
| Debit | Credit |
|---|---|
| Surplus CAV | CavalRe Payable CAV |
The asset and liability are equal amounts of the same token. At any CAV price their net Protocol-equity contribution is zero:
Repricing changes both marked values equally, so the cancellation remains exact.
3. Settlement fractions
Let
be the fraction of the user's routed to Reserve, and let
be the fraction of the user's CAV supplied by Reserve. The fractions are independent. Multiswap does not require them to be equal.
The Reserve endpoint is
Surplus supplies
CAV, and CavalRe Treasury receives the corresponding non-Reserve amount. Reserve coefficients remain fixed and LP Token supply does not change.
4. Pure Surplus sale
When
the sale posts two separate same-token journals.
On the ledger:
| Debit | Credit |
|---|---|
| CavalRe Treasury | CavalRe Payable |
On the CAV ledger:
| Debit | Credit |
|---|---|
| CavalRe Payable CAV | Surplus CAV |
Every debit and credit is matched within its own token ledger. There is no cross-token journal.
No Reserve Asset amount or scale changes, and neither the LP Token amount nor its derived scale changes. Therefore
for every Reserve Asset . The pure sale is projectively neutral and produces no price impact.
Economically, CavalRe has sold some of its finite CAV inventory for . The Protocol has provided quotation, custody, and settlement without selling Protocol-owned CAV.
5. General safety condition
Because Reserve coefficients and LP Token supply are fixed, the projective condition
for every Reserve Asset is equivalent here to
where
This is the complete endpoint test for independent settlement fractions. Inventory availability, positive reserves, and exact journal balance are separate admissibility requirements.
6. An always-safe path
Equal fractions are not required, but they give a useful proof that nontrivial safe mixed settlements always exist. Set
Along this line,
For , this function is strictly concave for a nonzero trade, and
At the direct endpoint,
by the direct post-trade value-flow equation. Strict concavity makes the derivative positive for . Hence
for the entire interval, with equality at the pure-sale endpoint. Equal fractions are therefore a sufficient safe subfamily inside the larger independently allocated mechanism.
7. Round trips
Consider a pure Surplus sale followed by an ordinary Reserve swap. The first leg has no Multiswap price impact. The second adds CAV to Reserve and removes , so the Multiswap CAV price moves down and the price moves up.
This is not a closed-state round trip. Surplus CAV has decreased, CavalRe Treasury has increased, Reserve CAV has increased, and Reserve has decreased. The user is an intermediary through which CavalRe sells CAV into the Reserve for .
Repeated loops can continue only while authorized Surplus remains. If no other action removes CAV from Reserve, the finite inventory bounds the absolute CAV price response by
The CAV-to- relative price also reflects the simultaneous change in the Reserve. CavalRe controls tolerated sale pressure by limiting authorized Surplus relative to live Reserve depth.
Splitting is not an accounting exploit. It can change the execution path and reduce finite-trade price impact, so Surplus sizing and execution policy should assume users can split across transactions.
8. Atomic settlement requirements
An implementation must:
- calculate the direct user quote from live Reserve state;
- choose authorized independent settlement fractions;
- verify sufficient CavalRe-owned CAV in Surplus;
- post every same-token Reserve, Surplus, Treasury, payable, and user entry;
- update the Reserve endpoint once for the complete atomic action;
- preserve exact matched Surplus and CavalRe payable balances;
- enforce the projective endpoint condition, positive Reserve balances, and pool-favorable rounding; and
- apply cumulative endpoint accounting to compatible split calls inside one transaction.
Conclusion
Surplus is a finite, externally owned CAV sale facility. CavalRe supplies CAV and receives in CavalRe Treasury. Exact matched asset--liability postings remove the externally owned inventory from Protocol-equity repricing.
The pure sale is price-neutral because it does not touch price-forming state. Mixed settlement may use independent pay and receive fractions. The complete Reserve endpoint is accepted exactly when it satisfies
