Full-Ledger Post-Trade Accounting
Multiswap uses double-entry accounting. Every posting is balanced within one token ledger: the debit and credit contain the same amount of the same token. A cross-token action is therefore a collection of balanced same-token journal entries, never one debit in token and one credit in token .
Accounting conservation is always required. Safety is a second question: after the complete atomic action has been posted and the price-forming state has been updated, did the pool move in the permitted projective direction?
This article gives the full-ledger test and explains why many journal entries cancel before the safety calculation.
1. Price-forming state
For each Reserve Asset ,
with . The LP Token is the derived claim on the Reserve:
The safety-relevant coordinates are for every Reserve Asset and for the LP Token .
An account may hold token without forming its price. Surplus, Treasury custody, Rewards custody, and a payable denominated in token inherit . Their marked scales are derived from their token amounts and the Reserve price.
2. Atomic journals stay inside one token ledger
If an action exchanges for , its accounting contains at least one balanced journal and one balanced journal. Schematically,
| Token ledger | Debit amount | Credit amount |
|---|---|---|
The table is not a cross-token journal. Each row balances independently in its own token.
The action endpoint is evaluated atomically. Repricing is applied to the completed endpoint, not to an arbitrary ordering of its bookkeeping entries.
3. Exact matched price-taking pairs cancel
Suppose CavalRe owns CAV held in Surplus. The funding entry is
| Debit | Credit |
|---|---|
| Surplus CAV | CavalRe Payable CAV |
If both balances contain the same amount , their net marked contribution is
After any repricing,
The cancellation is exact because the debit asset and credit liability are equal amounts of the same token and inherit the same token price.
This gives a precise screening rule:
A balanced journal entry that changes neither nor has no immediate effect on the projective safety coordinates.
The journal must still be posted and retained for ownership, authorization, solvency, and auditability. It drops only from the immediate repricing inequality.
The cancellation does not apply when amounts differ, the credit is denominated in another claim, either side has an independent price, or the entry changes a Reserve or LP Token amount or scale.
4. Gauge-invariant safety
The claim-free Reserve--LP balance sheet gives
Summing over Reserve Assets gives
The projective safety condition for an atomic action is
Only ratios appear. Multiplying all scales and coefficients by one positive common factor does not change the test.
5. Why the condition protects LP backing
The endpoint balance identity and the safety inequalities imply
Using the opening balance identity, this becomes
Because is concave, Jensen's inequality gives
The final Reserve basket per LP Token cannot be worth less at the opening Reserve prices.
The ratio inequalities also compose. If every atomic action makes every nonincreasing, the same is true across every finite sequence. Round trips and subsequent actions require no separate exception.
6. Per-entry safety procedure
For each atomic protocol action:
- Write every same-token debit and credit entry. Do not net away the journals.
- Verify equal token amounts on the debit and credit sides of every token ledger.
- Identify every posting that changes for any Reserve Asset or for the LP Token.
- Cancel only exact matched price-taking asset--liability pairs in the safety calculation.
- Reconstruct the complete post-action price-forming endpoint.
- Require positive reserves, positive scales, and every operation-specific admissibility condition.
- Enforce
for every Reserve Asset .
This is a per-action test, not a claim that each individual debit or credit is independently safe. Safety belongs to the complete atomic endpoint because one action can contain several balanced token journals that jointly determine the price-forming transition.
7. Closed and open systems
Swaps and liquidity operations are closed in the Reserve--LP state. Their price-forming journals remain inside the system described by , so their safety follows directly from the ratio test.
An open action can also contain external assets and liabilities. It reduces to the same closed proof when every external component is an exact same-token matched pair and its creation, repricing, and settlement cancel identically. The remaining price-forming core must still pass the ratio test.
Externally owned Surplus has exactly this form. Surplus CAV and CavalRe Payable CAV cancel at every CAV price. A pure Surplus sale changes no Reserve or LP Token coordinate. A mixed sale changes only the Reserve fractions, whose complete endpoint must pass the projective test.
More general liabilities do not automatically cancel. Independently priced claims, unmatched payables, owner distributions, and administrative changes to price-forming state require their own explicit model before they can inherit this theorem.
Conclusion
Double entry supplies conservation. The projective ratio supplies direction.
Every journal remains visible and balanced inside one token ledger. Exact matched price-taking pairs cancel under repricing. The safety calculation then focuses on all and only the entries that change , including , and accepts the atomic endpoint exactly when
