The Projective Bregman Safety Law
Multiswap prices are gradients of a concave projective potential. Post-trade execution therefore produces a nonnegative Bregman divergence. For a closed swap, that divergence accumulates in LP Token backing. For a partial liquidity action, it finances the permitted change in the price surface. For externally owned Surplus, it combines with an explicit value flow across the Reserve boundary.
These are not three unrelated safety arguments. They are special cases of one exact balance law:
Projective-potential change equals Bregman production plus Reserve boundary value flow plus price-surface reset.
This article derives that law from the native Multiswap state and applies it to swaps, liquidity operations, and externally owned Surplus.
Status: Exact-arithmetic mathematical model. The results assume positive reserves and scales, , post-trade execution, the stated same-token journal entries, and exact enforcement of each operation's equations. The externally owned Surplus mechanism is proposed rather than current executable behavior. Fixed-point rounding and Solidity implementation remain separate verification obligations.
1. Native state
Reserve Asset has reserve , scale , and marginal price :
The LP Token is the derived claim on all Reserve Assets:
Consequently,
The economically relevant reserve coordinates are projective:
They measure units of Reserve Asset per LP Token. Their corresponding marginal prices are also relative:
2. The projective potential
Define the projective potential
Here denotes the complete vector of Reserve Asset amounts per LP Token. The symbol names a new object: the scalar potential whose gradient generates every Reserve-Asset-to-LP-Token relative price.
Indeed,
Therefore:
For , the power sum is concave and positive. The logarithm is increasing and concave, so is concave.
At an actual Multiswap state,
Multiplying every by one positive common factor adds a constant to . Its gradient and Bregman divergence do not change. The geometry is therefore invariant under the common scale gauge.
3. Journal value in projective coordinates
Consider one atomic action from to . Every token ledger must first balance through equal-amount same-token debit and credit entries. Only after those conservation laws hold do we value the entries that touch Reserve Asset or LP Token state.
The post-trade value entering the Reserve--LP subsystem is
The minus sign reflects LP Tokens issued by the pool when . The following identity is exact:
To verify it, use
The identity converts post-trade journal value into the relative-price gradient applied to the change in Reserve Assets per LP Token.
A closed post-trade swap or liquidity operation satisfies
Therefore its projective value flow is zero:
An open operation need not make this expression zero. Its nonzero value is an explicit flow across the Reserve--LP boundary.
4. Bregman production
An action can also change the price surface. Let denote the opening potential and the potential formed from the ending Reserve Asset coefficients. Concavity of gives
The nonnegative difference is the Bregman divergence generated by the convex function :
This divergence is the finite curvature produced by executing the complete action at its post-trade marginal prices.
5. The exact balance law
Add and subtract the ending potential evaluated at the opening projective reserves:
Using the projective journal identity and the actual-state value of each potential gives the master equation:
The three terms on the right have distinct meanings:
- Bregman production is nonnegative finite-step curvature.
- Reserve boundary value flow is post-trade value entering the Reserve--LP subsystem, net of LP Tokens issued.
- Price-surface reset measures the coefficient change at the projective reserve state where the action began.
The equation is gauge-consistent. A common coefficient rescaling adds the same potential constant to both sides through the corresponding change in and the reset term. The Bregman divergence and relative prices remain unchanged.
5.1 The gauge-invariant safety margin
The master equation tracks the LP Token coefficient in a selected common gauge. Subtracting the change in Reserve Asset 's coefficient produces a fully gauge-invariant identity:
The left side is nonnegative exactly when
This is therefore an exact necessary-and-sufficient test for Reserve Asset to move in the established projective safety order. It is not merely a sufficient estimate.
Under a common gauge transformation, the price-surface reset and the final Reserve Asset coefficient term change by equal amounts and cancel. Every remaining term is already gauge invariant.
6. Closed swaps
An atomic swap has
The boundary and price-surface-reset terms are therefore zero. The balance law reduces to
Thus . Because every Reserve Asset coefficient remains fixed,
The projective safety inequality is therefore derived from post-trade self-financing and concavity. It is not an independent assumption for swaps.
For a nontrivial finite swap, strict concavity makes the divergence positive. The LP Token's projective backing gain is exactly the Bregman divergence.
7. Liquidity operations
An liquidity operation has zero Reserve boundary flow:
For participating Reserve Assets and the LP Token,
When , every nonparticipating Reserve Asset receives the common multiplier
for every admissible nontrivial action. This is a genuine price-surface change, so a fixed-potential proof would be wrong.
Because , the left side of the balance law is zero. Therefore:
The Bregman divergence exactly finances the downward reset of the projective price surface. Participating coefficient ratios remain unchanged, while every nonparticipating ratio decreases:
For proportional all-Reserve-Asset liquidity, every projective reserve remains unchanged. The Bregman divergence and price-surface reset are both zero. The action is projectively neutral even though absolute LP Token price can change.
8. Externally owned Surplus
Consider a user exchanging for CAV. The ordinary direct quote is
It satisfies post-trade value-flow balance at the direct endpoint:
Externally owned Surplus routes independent fractions of these token legs through Reserve:
The fractions are independent. Multiswap does not require
8.1 Same-token journals
The non-Reserve leg is posted on the ledger:
| Debit | Credit | Amount |
|---|---|---|
| CavalRe Treasury | CavalRe Payable |
The non-Reserve CAV leg is posted separately on the CAV ledger:
| Debit | Credit | Amount |
|---|---|---|
| CavalRe Payable CAV | Surplus CAV |
The Reserve legs use the ordinary same-token Reserve settlement journals. There is no debit in matched with a credit in CAV.
Each external asset--liability pair contains equal amounts of the same token and inherits the same token price. Repricing therefore changes both sides equally. The entries remain on the ledger for ownership, authorization, and auditability, but their net Protocol-equity revaluation is exactly zero.
The surviving price-forming endpoint is
with
8.2 The Surplus boundary term
Because the Reserve coefficients remain fixed, there is no price-surface reset. The Reserve boundary value flow is
The balance law becomes
This gives the exact acceptance condition:
Because Reserve Asset coefficients and LP Token supply remain fixed, this condition is equivalent to each of
and
The Reserve boundary value flow need not be nonnegative by itself. A moderately negative flow can be offset by positive Bregman production. Safety fails exactly when the value leaving Reserve exceeds the curvature produced by the Reserve transition.
8.3 Immediate cases
For a pure Surplus sale,
No Reserve or LP Token coordinate changes. Both the Bregman and boundary terms are zero, so the sale is projectively neutral.
If
Reserve receives and supplies no CAV. Both terms are nonnegative and .
If
Reserve supplies CAV and receives nothing. Direct evaluation gives , so the action fails the acceptance condition.
Equal fractions form one sufficient subfamily, but equality is not enforced. Independent fractions are accepted exactly when the complete Bregman-plus-boundary expression is nonnegative.
To see the sufficient result, set
Along this Reserve path,
This function is concave. Its derivative at the direct endpoint is zero because
The derivative is therefore nonnegative before that endpoint, giving
This proves that the equal-fraction path is safe without turning equality of the fractions into a protocol requirement.
8.4 One-parameter self-financing construction
The general mechanism permits independent pay-side and receive-side fractions. A distinguished subfamily needs only one policy input.
Choose
and route
to Reserve. Then calculate as the output of an ordinary smaller Reserve swap:
Surplus supplies only the difference between the direct quote and the smaller Reserve output:
The user therefore receives the complete direct quote:
CavalRe Treasury receives the remaining pay asset:
This construction lies inside the independent-fraction model with the derived receive-side fraction
It is not a second policy parameter. Once the direct quote, live Reserve state, and are fixed, the ordinary Reserve swap determines it.
The defining Reserve equation makes the boundary value flow exactly zero. Reserve coefficients also remain fixed, so there is no price-surface reset. The balance law reduces to
Thus the Reserve portion inherits the closed-swap proof directly. The external journals determine ownership and complete the user's direct quote; they do not need to compensate for an unsafe Reserve endpoint.
At , the construction is a pure Surplus sale with no Reserve movement. At , it is the complete direct Reserve swap with no Surplus fill. Interior values continuously combine a smaller ordinary Reserve swap with an externally owned Surplus sale.
9. Numerical verification
9.1 Independent equal-fraction example
Take a two-Reserve-Asset pool with
Then
Use the direct quote
and choose
The Reserve endpoint is
The ending prices are approximately
The normalized Reserve boundary flow is
The Bregman divergence is
Their sum is
The independently calculated projective-state change is
The two sides agree.
9.2 One-parameter self-financing example
Keep the same opening state and direct quote, but choose only
Reserve receives
The ordinary smaller Reserve swap determines
Therefore the Reserve endpoint is
and Surplus supplies
The ending prices are approximately
The Reserve boundary value flow is zero:
The entire projective-state gain is therefore Bregman production:
10. Finite sequences
Apply the balance law to every atomic action in a finite sequence. The actual-state potential changes telescope:
This is the finite-sequence accounting identity. It does not assume that intermediate operations use the same price surface.
For the currently analyzed operation classes:
- swaps have zero boundary flow and zero price-surface reset;
- partial liquidity actions have zero boundary flow and use their Bregman production to finance the permitted price-surface reset;
- full proportional liquidity is projectively neutral;
- pure externally owned Surplus sales have all three terms equal to zero; and
- mixed externally owned Surplus settlements have zero price-surface reset and an explicit Reserve boundary flow.
If every atomic endpoint satisfies
the inequalities compose across splits, round trips, and subsequent actions. The Bregman balance law now explains where that one-sided coefficient movement comes from for each supported operation, rather than merely declaring it.
The law also identifies the remaining general problem. An arbitrary non-uniform coefficient update introduces a price-surface-reset term. A scalar condition on cannot by itself control every Reserve Asset ratio. Such an operation needs either its own componentwise proof or a direct cyclic-monotonicity proof over the supported continuation actions.
Conclusion
Multiswap's projective safety structure is generated by a concave potential whose gradient is the complete vector of Reserve-Asset-to-LP-Token prices. Post-trade execution produces a nonnegative Bregman divergence.
For swaps, that divergence becomes additional derived LP Token backing. For partial liquidity, it exactly pays for the permitted downward reset of the price surface. For externally owned Surplus, exact same-token asset--liability journals cancel, leaving a measurable value flow across the Reserve boundary.
In words, projective-potential change equals Bregman production plus Reserve boundary value flow plus price-surface reset.
This supplies one auditable framework for closed operations, open settlement, round trips, and subsequent actions. It also makes the unresolved boundary precise: general non-uniform coefficient changes require control of the price-surface-reset term, not another isolated endpoint heuristic.
