11 MARKETSUSDG10 S GRIDNEXT FILL 00:10
//12_ Docs

THE ORACLE AND THE FILL RULE

//Fig_ oracle
NOW
//Request_
WAITING
//Fill_ts_
//BTC_price_

UTC. Prices: RedStone medians for BTC, one per grid point.

//01_ THE PRICE SOURCE

Every price Paperhands settles on comes from RedStone's primary data service, redstone-primary-prod. RedStone signers publish a signed package for each feed every 10,000 ms, on a fixed grid: package timestamps are exact multiples of 10,000 ms. The exchange verifies the signatures itself, on chain, with no intermediary contract.

//DATA SERVICE_
redstone-primary-prod
//AUTHORISED SIGNERS_
5
//THRESHOLD_
3
//GRID_
10,000 ms
//PRICE FORMAT_
8 decimals

The five signer addresses are listed on the contract addresses page. The owner can replace the signer set, with a threshold that can never be lower than 3 (see admin powers).

//02_ A PRICE PROOF

A proof for one market is a set of packages for that market's feed. The contract requires:

  • at least 3 packages, all with the same timestamp;
  • each signed by a different authorised signer (no duplicates, no unknown signers);
  • no zero values;
  • for the first 30 s after the timestamp, the packages of all five signers. After 30 s, any three or more are accepted.

The price is the median of the values: the middle value for an odd count, the mean of the two middle values for an even count. With five packages it is the third value in ascending order. Each signature is checked with ecrecover against the exact message RedStone signs.

//03_ THE FILL RULE

A request fills at the price of the first grid point strictly after the block that recorded it:

FILL TIME
fillTs = (floor(requestTime x 1000 / 10000) + 1) x 10000      (ms)

execute(requestId, proof)   requires   proof timestamp == fillTs

The timestamp is fixed the moment the request is recorded, and it is in the future. Nobody can choose another one. During the first 30 s after it, the proof must carry all five signers, so the price is the median of all five and there is exactly one valid price for the request. The keeper executes about 2 s after the grid point, inside that window.

After 30 s, a proof from any three or more authorised signers at that same timestamp is accepted. This lets a request fill even if one signer's package is missing, at the cost that a late executor could choose which packages to include. The keeper's normal timing keeps that from mattering.

//04_ ANYONE CAN EXECUTE

execute and executeMany are permissionless. If the keeper is slow or down, you can fill your own request, or anyone else's, with the package for its fill time, fetched from RedStone's public historical endpoint:

HISTORICAL PACKAGES
https://oracle-gateway-1.a.redstone.finance/data-packages/historical/redstone-primary-prod/<fillTs>
https://oracle-gateway-2.a.redstone.finance/data-packages/historical/redstone-primary-prod/<fillTs>

The result is the same price whoever submits it. executeMany skips a request that fails instead of reverting the whole batch.

//05_ THE REFERENCE BAND

Each market also has a Chainlink price feed on chain 4663, used only as a sanity check. Those feeds update on a 0.5% deviation threshold or every 24 h, whichever comes first. Every RedStone price is compared with the reference before it is used:

  1. 01
    If the reference was updated within the last 90,000 s (25 h), the RedStone price must be within 2.5% of it. Otherwise the proof is refused.
  2. 02
    If the reference is older than that, the check is skipped.
  3. 03
    If the reference cannot be read at all, or returns a zero or negative value, the proof is refused for that market until it recovers.

The band bounds what a compromised signer set could do: it cannot settle a trade more than 2.5% away from an independent reference while that reference is fresh. The addresses of the eleven references are in markets and sessions.

//06_ WHEN A PRICE IS REFUSED

If no valid proof can ever be built for a request's fill time (the package was never published, or its price falls outside the band), the request cannot execute. After 3,600 s anyone can cancel it: an open is refunded in full, a close is dropped and the position stays open, ready for a new close request.

Credits: hands from Michelangelo, The Creation of Adam (detail), public domain, via Wikimedia Commons. Marks of the markets and integrations belong to their owners (sources, credits).