Skip to main content
Unlisted page
This page is unlisted. Search engines will not index it, and only users having a direct link can access it.

11 posts tagged with "safety"

View All Tags

Portfolio Preferences, Relative Entropy, and Post-Trade Elasticity

· 18 min read
Eric Forgy
Founder of CavalRe

A liquidity pool is a portfolio. Its reserve and price updates define an investment strategy: which assets it accumulates, which it releases, and the terms on which it changes its composition.

Multiswap's post-trade elasticity model expresses that strategy with one elasticity parameter, while retaining a rich accounting and safety structure. A natural extension is to give the portfolio an explicit preferred composition. The question is whether that preference can enter through a coherent valuation rule, preserve the post-trade framework, and strengthen the response to scarce inventory.

This article develops one such candidate. Its central result is an exact identity: the composition-sensitive part of portfolio valuation equals reference-priced holdings discounted by relative entropy from the preferred composition. The resulting prices favor acquiring underrepresented assets, retain exact invariance under uniform reserve scaling, and develop stronger elasticity near depletion.

Externally Owned Surplus

· 7 min read
Eric Forgy
Founder of CavalRe

Status: Proposed exact-arithmetic mechanism for externally owned CAV. The independent settlement fractions and CavalRe payable journals below describe the research model. Current contracts implement a narrower Surplus top-up mechanism, summarized after the atomic settlement requirements.

In this proposal, Surplus is externally owned CAV held by the Protocol for sale. CavalRe owns the CAV, authorizes its use, and receives the sale proceeds in CavalRe Treasury. CavalRe and the Protocol are distinct accounting entities.

The mechanism can route independent fractions of the user's pay and receive legs through Reserve. The remaining amounts execute as a CavalRe-owned CAV sale. A pure sale bypasses Reserve and leaves Multiswap prices unchanged. A mixed settlement is accepted when its complete Reserve endpoint passes the gauge-invariant safety condition.

The Projective Bregman Safety Law

· 17 min read
Eric Forgy
Founder of CavalRe

Multiswap prices are gradients of a concave projective potential. Post-trade execution therefore produces a nonnegative Bregman divergence. For a closed swap, that divergence accumulates in LP Token backing. For a partial liquidity action, it finances the permitted change in the price surface. For externally owned Surplus, it combines with an explicit value flow across the Reserve boundary.

These are not three unrelated safety arguments. They are special cases of one exact balance law:

Projective-potential change equals Bregman production plus Reserve boundary value flow plus price-surface reset.

This article derives that law from the native Multiswap state and applies it to swaps, liquidity operations, and externally owned Surplus.

Full-Ledger Post-Trade Accounting

· 6 min read
Eric Forgy
Founder of CavalRe

Multiswap uses double-entry accounting. Every posting is balanced within one token ledger: the debit and credit contain the same amount of the same token. A cross-token action is therefore a collection of balanced same-token journal entries, never one debit in token AA and one credit in token BB.

Accounting conservation is always required. Safety is a second question: after the complete atomic action has been posted and the price-forming state has been updated, did the pool move in the permitted projective direction?

This article gives the full-ledger test and explains why many journal entries cancel before the safety calculation.

Scope: Exact-arithmetic accounting model. The externally owned CAV and CavalRe payable entries illustrate a proposed ownership structure. Current Surplus settlement uses a reduced Reserve quote and receive-side top-ups; it does not implement these proposed payable journals. See Fees and Surplus.

Two-Asset Surplus Settlement for Token Launches

· 13 min read
Eric Forgy
Founder of CavalRe

Historical proposal: This article explores a price-preserving Surplus candidate. The implemented settlement policy uses a reduced-pay second quote and Surplus top-ups; it preserves the direct user payout but can change relative pool prices. See Quote Engine for current behavior.

Multiswap pools can hold protocol-owned token inventory in a Surplus account. For a token-launch pool containing a pay asset AA and a launched receive asset BB, the protocol would like to sell available Surplus BB without changing the user's direct quote. Some of the user's AA can enter Reserve, and the rest can be divided between Rewards and Treasury.

The allocation cannot be chosen independently of pool safety. Protecting the BB Reserve changes the physical Reserve endpoint. Preserving the direct relative prices then requires a common price gauge, and that gauge changes the LP Token's total scale.

For a two-asset pool, the resulting allocation problem has a simple solution:

  1. available Surplus inventory determines the fraction of BB paid by Reserve;
  2. LP safety determines the minimum fraction of AA that must enter Reserve;
  3. an optional configured floor may increase that pay-side Reserve fraction;
  4. Rewards and Treasury divide the remainder equally; and
  5. an infeasible Surplus attempt uses ordinary direct settlement instead.

The minimum pay allocation is closed form for every 0<es<10<e_s<1. When es=eP=1/2e_s=e_P=1/2, the direct receive quote and the complete receive-side safety boundary are also closed form.

This article derives that candidate from first principles. It is not current implemented protocol behavior.

Gauge-Equivalent Surplus Settlement: A Candidate Model

· 22 min read
Eric Forgy
Founder of CavalRe

Historical proposal: This article explores a price-preserving Surplus candidate. The implemented settlement policy uses a reduced-pay second quote and Surplus top-ups; it preserves the direct user payout but can change relative pool prices. See Quote Engine for current behavior.

Obsolete research candidate

This article preserves an earlier large-pool coverage construction for historical context. Its receive-allocation notation and coverage algorithm have been superseded by Two-Asset Surplus Settlement for Token Launches.

Multiswap can hold protocol-owned token inventory in a Surplus account. When a user receives an asset held in Surplus, the protocol would like to deliver some or all of the output from that inventory instead of depleting the asset's pool Reserve.

The settlement source should not change the user's quote. It should not change the relative post-trade prices either. A user exchanging the same amounts against the same opening pool state should reach the same market prices whether the receive tokens come from Reserve, Surplus, or a combination of both.

That goal is harder than moving tokens between accounts. If Surplus protects a receive Reserve while the pool assigns the asset the higher price caused by direct Reserve depletion, the asset appears scarce without becoming scarce. The resulting coefficient expansion falls outside the Post-Trade Elasticity coefficient order.

This article develops a candidate alternative. The key observation is that Multiswap prices have a common scale gauge. Absolute prices depend on the internal scale unit; relative prices do not. Surplus settlement can therefore target a common multiple of the ordinary direct-swap price vector. A single global scale-accumulator update applies that gauge to the full pool without looping over every Reserve Asset. Explicit pay and receive legs then receive their own constant-time compensations.

The candidate has four principal results:

  1. the user's direct-swap quote is unchanged;
  2. every relative post-trade price equals the direct-swap relative price;
  3. every Reserve Asset coefficient remains fixed or contracts;
  4. Surplus coverage can be capped so the LP Token coefficient remains safe without minting or burning LP Tokens.

The construction is a research candidate, not implemented protocol behavior. It assumes exact arithmetic, positive reserves and scales, homogeneous elasticity

0<es<1,eP=1es,0<e_s<1, \qquad e_P=1-e_s,

and fee-free settlement. Fees are outside this candidate model rather than an unresolved part of it. Rounding, account-level authorization, and implementation tests remain open before implementation.

From Coefficient Differentials to General Safe Operations

· 17 min read
Eric Forgy
Founder of CavalRe

The Post-Trade Elasticity Model was initially developed around a small set of actions: Reserve Asset swaps, single-asset liquidity, proportional liquidity, and LP Token burns. Those actions were proved to satisfy the coefficient order individually and then composed into more elaborate transactions such as Surplus settlement.

The coefficient safety conditions reveal that the known actions are not the whole design space. They are particular paths through a larger region of admissible state transitions.

The differential of each coefficient identifies the local coefficient-order directions. Its exact finite form identifies the complete endpoint envelope induced by that order. The envelope admits direct permanent-reserve allocations, general LP under-minting, more general withdrawals, and multi-asset liquidity operations that need not share one common complement multiplier.

Execution pricing enters at a different layer. Coefficient order determines whether an endpoint is admissible. The execution rule determines whether value-flow balance reaches such an endpoint automatically. For positive scale elasticity, post-trade execution is the unique fixed linear execution rule that makes every finite fixed-coefficient reserve-only swap coefficient-safe without an additional admissibility check or protocol subsidy.

This article develops those results from first principles. It assumes exact arithmetic, positive reserves and scales, and homogeneous elasticities unless a section states otherwise.

The article describes the mathematical design space. The newly identified transitions are candidates for protocol operations, not claims about actions already exposed by the current implementation. A candidate becomes supported only after its consideration, account movements, rounding, and property tests have been specified and implemented.

Discrete Stochastic Calculus and Safe Multiswap Operations

· 27 min read
Eric Forgy
Founder of CavalRe

Multiswap is a discrete financial system. A transaction begins at one ledger state and ends at another. Reserves, scales, and prices are defined at the states; value flow occurs along the directed transition between them.

That description is not an approximation. It is the native geometry of a blockchain.

Discrete stochastic calculus gives this geometry an exact financial accounting rule. It distinguishes quantities defined at states from flows defined on transitions, preserves the order between previsible inventory and nonprevisible price, and recovers Itô calculus in the stochastic continuum limit. Applied to Multiswap, it produces post-trade value flow directly:

dsi=(dai)Pi+aidPi.\boxed{ ds_i=(da_i)P_i+a_i\,dP_i. }

The first term evaluates price at the destination state. The second revalues the opening reserve. Post-trade execution is therefore not an arbitrary conservative quote convention. It is the finite execution rule compatible with Itô accounting.

The same calculus gives an exact coefficient 1-form

dci=[G,ci]\boxed{ dc_i=[G,c_i] }

whose edge coefficients determine whether an operation moves each Reserve Asset and the LP Token in the permitted direction. This coefficient order contains the familiar swap and liquidity actions, but it also identifies a wider endpoint region containing direct permanent-reserve contributions, LP Token under-minting, general withdrawals, and heterogeneous multi-asset liquidity.

On the binary tree, exact coefficient order must hold on both outgoing branches. In the stochastic continuum limit, this removes the coefficient's Brownian component and leaves a one-sided generator condition. The boundary between safe and unsafe coefficient production is the backward diffusion equation

(t+12x2)ci=0.\boxed{ \left( \partial_t+\frac12\partial_x^2 \right)c_i=0. }

Surplus settlement provides the central application. A direct price-preserving state edit leaves this region by expanding the receive-asset coefficient. An ordinary counter-swap remains inside it because every step is an exact supported transition.

This article develops the complete argument from first principles. No prior knowledge of discrete calculus is assumed.

The results assume exact arithmetic, positive reserves and scales, homogeneous elasticities, and

0<es<1,eP=1es.0<e_s<1, \qquad e_P=1-e_s.

Coefficient order establishes state admissibility. A complete protocol operation must additionally specify funded token movements, valid consideration, account ownership, rounding, user limits, atomicity, and MEV policy.

Multiswap Safe Operations Cheat Sheet

· 5 min read
Eric Forgy
Founder of CavalRe

Scope: The operation classes below describe mathematical safety results. Current contracts expose Reserve Asset swaps and proportional LP liquidity; general coefficient updates and unequal liquidity baskets are not public operations. See Liquidity Operations.

This is the compact safety reference for the exact-arithmetic, claim-free Multiswap Reserve--LP system.

The Thermodynamic Structure of Multiswap

· 19 min read
Eric Forgy
Founder of CavalRe

Multiswap's Post-Trade Elasticity Model was not derived from thermodynamics. It was developed as a market-design framework: define Reserve Asset states, couple trades through execution value, preserve aggregate accounting, and identify state transitions that cannot weaken the pool's safety position.

Yet the resulting mathematics has a distinctly thermodynamic structure.

The pool has a state space. Value-flow balance constrains exchanges across its boundary. Coefficient inequalities define a cone of locally admissible processes. Finite coefficient multipliers integrate those inequalities across complete transitions. A logarithmic entropy summarizes the resulting irreversible motion. The execution-price rule acts as a constitutive law: it determines whether the balance equations naturally carry an ordinary swap through the admissible region.

This is more than a verbal analogy, but less than an identification with physical thermodynamics. Multiswap does not have a literal temperature, heat bath, or molecular entropy. The precise claim is structural:

The Post-Trade Elasticity Model has the same mathematical separation between state, balance laws, admissibility, entropy production, and process law that makes thermodynamics a general theory of physical processes.

That separation is useful. It clarifies what coefficient safety proves, what execution pricing contributes, why entropy is informative but incomplete, and why a state-safe operation can still have unfair consideration or MEV exposure.

This article develops that structure from first principles for positive scale elasticity,

0<es<1.0<e_s<1.

It assumes exact arithmetic, positive reserves and scales, and homogeneous elasticities. The thermodynamic interpretation is a mathematical framework for reasoning about the model, not a claim that every thermodynamic theorem automatically applies to Multiswap.