THE ORACLE AND THE FILL RULE
- //Request_
- WAITING
- //Fill_ts_
- //BTC_price_
UTC. Prices: RedStone medians for BTC, one per grid point.
//01_ THE PRICE SOURCE
Every price Paperhands settles on comes from RedStone's primary data service, redstone-primary-prod. RedStone signers publish a signed package for each feed every 10,000 ms, on a fixed grid: package timestamps are exact multiples of 10,000 ms. The exchange verifies the signatures itself, on chain, with no intermediary contract.
- //DATA SERVICE_
- redstone-primary-prod
- //AUTHORISED SIGNERS_
- 5
- //THRESHOLD_
- 3
- //GRID_
- 10,000 ms
- //PRICE FORMAT_
- 8 decimals
The five signer addresses are listed on the contract addresses page. The owner can replace the signer set, with a threshold that can never be lower than 3 (see admin powers).
//02_ A PRICE PROOF
A proof for one market is a set of packages for that market's feed. The contract requires:
- at least 3 packages, all with the same timestamp;
- each signed by a different authorised signer (no duplicates, no unknown signers);
- no zero values;
- for the first 30 s after the timestamp, the packages of all five signers. After 30 s, any three or more are accepted.
The price is the median of the values: the middle value for an odd count, the mean of the two middle values for an even count. With five packages it is the third value in ascending order. Each signature is checked with ecrecover against the exact message RedStone signs.
//03_ THE FILL RULE
A request fills at the price of the first grid point strictly after the block that recorded it:
fillTs = (floor(requestTime x 1000 / 10000) + 1) x 10000 (ms) execute(requestId, proof) requires proof timestamp == fillTs
The timestamp is fixed the moment the request is recorded, and it is in the future. Nobody can choose another one. During the first 30 s after it, the proof must carry all five signers, so the price is the median of all five and there is exactly one valid price for the request. The keeper executes about 2 s after the grid point, inside that window.
After 30 s, a proof from any three or more authorised signers at that same timestamp is accepted. This lets a request fill even if one signer's package is missing, at the cost that a late executor could choose which packages to include. The keeper's normal timing keeps that from mattering.
//04_ ANYONE CAN EXECUTE
execute and executeMany are permissionless. If the keeper is slow or down, you can fill your own request, or anyone else's, with the package for its fill time, fetched from RedStone's public historical endpoint:
https://oracle-gateway-1.a.redstone.finance/data-packages/historical/redstone-primary-prod/<fillTs> https://oracle-gateway-2.a.redstone.finance/data-packages/historical/redstone-primary-prod/<fillTs>
The result is the same price whoever submits it. executeMany skips a request that fails instead of reverting the whole batch.
//05_ THE REFERENCE BAND
Each market also has a Chainlink price feed on chain 4663, used only as a sanity check. Those feeds update on a 0.5% deviation threshold or every 24 h, whichever comes first. Every RedStone price is compared with the reference before it is used:
- 01If the reference was updated within the last 90,000 s (25 h), the RedStone price must be within 2.5% of it. Otherwise the proof is refused.
- 02If the reference is older than that, the check is skipped.
- 03If the reference cannot be read at all, or returns a zero or negative value, the proof is refused for that market until it recovers.
The band bounds what a compromised signer set could do: it cannot settle a trade more than 2.5% away from an independent reference while that reference is fresh. The addresses of the eleven references are in markets and sessions.
//06_ WHEN A PRICE IS REFUSED
If no valid proof can ever be built for a request's fill time (the package was never published, or its price falls outside the band), the request cannot execute. After 3,600 s anyone can cancel it: an open is refunded in full, a close is dropped and the position stays open, ready for a new close request.
Credits: hands from Michelangelo, The Creation of Adam (detail), public domain, via Wikimedia Commons. Marks of the markets and integrations belong to their owners (sources, credits).