11 MARKETSUSDG10 S GRIDNEXT FILL 00:10
//16_ Docs

ADMIN POWERS

//01_ TWO ROLES

The contract knows two privileged addresses: the owner and the keeper. Their current addresses, and a pending owner if a transfer is in progress, are public in the contract's house() view. Everything else in the contract is either open to every address or limited to the wallet whose money is involved.

//02_ THE OWNER

FUNCTIONWHAT IT DOESBOUNDS
addMarketadds a marketsame bounds as updateMarket
updateMarketchanges a market's limits, impact parameters, fees, reference feed, band and reference ageleverage 2 to 100; base rate up to 20%; win and loss fees up to 5%; holder fee not above the win fee; profit cap 1 to 100 times the margin; band 0.1% to 20%; reference age 60 s to 7 days; the reference must report 8 decimals; margin, notional and open interest limits are otherwise free
retireMarketfreezes a market at a signed price, permanentlythe price must be at most 60 s old
setOpensPausedpauses or resumes new opens on every marketcloses and liquidations are not affected
setSignersreplaces the RedStone signer setthreshold at least 3, at most 16 signers
setTokensets the token and balance that qualify a wallet for the holder win feenone
setTreasurychanges where the treasury half of fees is sentnot the zero address
setKeeperchanges the keeper addressnot the zero address
transferOwnership, acceptOwnershiphands the owner role to a new addresstwo steps: the new owner must accept

A market's feed and its equity status can never be changed after it is added. Impact parameters, profit cap and fees are versioned: an update applies to positions opened after it, and every open position settles under the version it was opened with. Limits (leverage, margin, notional, open interest caps) apply to new requests. The reference feed, band and reference age apply to every price checked after the update, including closes and liquidations of existing positions.

//03_ THE KEEPER

The keeper has exactly one privileged function: setSession(marketId, open), which opens or closes the session flag of an equity market. It cannot use it on a crypto market or a retired one, and an open flag has no effect outside Monday to Friday, 09:30 to 16:00 New York time, because the contract also checks its own clock.

Everything else the keeper does (executing requests, liquidating, sweeping the excess, withdrawing the treasury share, cancelling expired requests) uses functions that any address can call.

//04_ WHAT NOBODY CAN DO

  • Move, freeze or seize a user's balance, the house's cash, a queue claim, paper or rewards. There is no function for it.
  • Mint paper, except to a trader who has just lost, on the rules of the mint curve.
  • Change the entry price, bust price or settlement terms of an open position.
  • Cancel a request before its 3,600 s TTL, or fill it at any price other than the one for its fill time.
  • Change the constants: the 5 bps bust buffer, the 3,600 s TTL, the 60 s liquidation proof age, the 30 s full-signer window, the 30-day session key limit, the 50% paper share of fees, the paper curve (100 per $1, $25,000, $1,500,000) and the $75,000 reserve cap.
  • Withdraw on behalf of a user, or send treasury fees anywhere but the treasury address.
  • Upgrade the contract. There is no proxy and no upgrade path: the deployed code is the code that runs.

//05_ WHAT THE OWNER COULD BREAK

Credits: hands from Michelangelo, The Creation of Adam (detail), public domain, via Wikimedia Commons. Marks of the markets and integrations belong to their owners (sources, credits).