Für Entwickler / Reale Vermögenswerte
Wie ein Preis entsteht
Zwei Aggregationsmethoden, ein Herausgeber. Die Rechnung unten ist das, was einen Preis gegen einen sich falsch verhaltenden Handelsplatz robust macht; sie ist nicht das, was ihn vertrauenswürdig macht. Das ist der letzte Abschnitt, und er ist der, den Sie lesen sollten, bevor Sie auf diesen Zahlen irgendetwas liquidieren.
Woher ein Preis kommt
Thirteen feeds are aggregated from five public spot venues, each subscribed with that venue's own product id. The other twenty have no venue leg and come from Pyth Network's Hermes service alone.
| Quelle | Was |
|---|---|
| Spot-Handelsplätze | Coinbase, Kraken, Bitstamp, Gemini, Bitfinexjeder mit der eigenen Produkt-ID dieses Handelsplatzes abonniert, aus dem Katalog genommen |
| Zweite Quelle | Pyth Network, über dessen Hermes-Dienstdie einzige Quelle für die zwanzig Feeds ohne Handelsplatz-Bein, und eine Gegenprüfung für die übrigen dreizehn |
Die beiden Methoden scheitern unterschiedlich, und eine Konsumentin braucht beide Verhaltensweisen. Ein durch Handelsplätze gestützter Feed überlebt es, wenn ein Handelsplatz ausfällt, denn der Median wird über fünf genommen, und jeder trägt seine eigene Frische. Ein Feed mit einer einzigen Quelle kann es nicht überleben, wenn seine Quelle nicht erreichbar ist, und sagt das, statt zu raten.
Wann ein Handelsplatz zählt
Jeder Handelsplatz wird für sich bewertet, bevor irgendetwas kombiniert wird. Die Regeln werden in dieser Reihenfolge angewandt, und die erste, die scheitert, nimmt den Handelsplatz für diese Auswertung aus dem Median:
| Regel | Schwelle |
|---|---|
| Connection state | must be onlinea venue whose socket is down is never fresh, whatever its last quote said |
| Quote age | 10 smeasured on a MONOTONIC receive clock, never on the exchange's timestamp or the host's wall clock |
| Delivery lag | 5 s either waya timestamp trailing its receipt means the socket is replaying a backlog; one leading it means the venue dates quotes in the future. The whole venue sits out rather than falling through to its last trade |
| Spread | 50 bpsthe mid is used when the book is uncrossed and tighter than this |
| Last trade | 60 sthe fallback when no usable mid exists, inside its own longer window |
Nicht am Zeitstempel der Börse und nicht an der Wanduhr des Hosts. Ein Handelsplatz mit einer vor- oder nachgehenden Uhr kann seine eigene Quotierung nicht frisch aussehen lassen, und ein Host, dessen Uhr springt, kann nicht alle Handelsplätze auf einmal entwerten. Der Zeitstempel der Börse wird für genau eine Sache benutzt: die Prüfung der Lieferverzögerung, die ihn in beide Richtungen mit dem Moment des Empfangs vergleicht.
Bestes Geld- und Briefangebot werden bevorzugt, wenn das Buch jung, nicht überkreuzt und enger als die Spread-Grenze ist. Andernfalls springt der letzte Trade ein, innerhalb seines eigenen längeren Fensters. Ein Handelsplatz, dessen Socket einen Rückstau nachspielt, wird ganz herausgenommen, statt auf seinen letzten Trade durchzufallen, denn dieser Trade ist um denselben Betrag verspätet.
Der Median
- Evaluate every venue against the rules above and keep the fresh ones.
- If fewer than minSources are fresh, publish nothing and report the reason - no_sources when none is fresh, too_few_sources otherwise. Nothing thin is ever published.
- Take the median of what survives.
- If the spread between the included venues exceeds 200 bps and dropping one would still leave minSources, drop the venue furthest from the median - on a tie the older observation - and take the median again. At most one venue is dropped.
- Round half-even to the feed's decimals. The result is an integer, not a float.
- Date the aggregate with the NEWEST included quote, capped at the current wall clock so no venue with a fast clock can date a median into the future.
degraded is set when the median rested on exactly minSources venues: still published, one drop-out from silence.
Ein dünner Feed veröffentlicht lieber nichts als etwas
minSources gilt pro Feed und ist 3 auf jedem durch Handelsplätze gestützten Feed. Darunter gibt es überhaupt keine Antwort: Kein letzter bekannter Wert wird on-chain erneut veröffentlicht, die Runde rückt nicht vor und updatedAt bewegt sich nicht mehr. Der Dienst meldet die letzte gute Antwort zur Diagnose weiterhin als lastKnown, und dieses Feld ist ausdrücklich kein Preis, auf dem man handelt.
Das Aggregat wird mit der jüngsten einbezogenen Quotierung datiert, gekappt an der aktuellen Wanduhr. Beide Hälften zählen: Ein Handelsplatz, dessen sechzig Sekunden alter letzter Trade für ein veraltetes Buch eingesprungen ist, darf keinen Median datieren, dessen übrige Eingaben im Subsekundenbereich liegen, und kein Handelsplatz mit vorgehender Uhr darf eine Beobachtungszeit in die Zukunft schieben - wo der Contract sie als Grund 4 auslassen würde.
Gegenprüfung und Einspringen
An exchange-backed feed that also has a Pyth leg is cross-checked against it on every evaluation. Within 100 bps the two are recorded as agreeing; beyond it the feed is marked diverged and the dispersion flag is raised.
When the venues go stale, Pyth may stand in for them - but only if the two agreed recently and are not diverging now. A feed publishing from the stand-in is marked degraded and its source reads pyth rather than exchanges-median, so a consumer can tell. If they are diverged and Pyth is fresh, the feed publishes nothing and reports cross_check_diverged.
Zwei Felder machen das sichtbar. crossCheckBps ist der aktuelle Abstand zwischen den beiden Methoden, und source sagt, welche davon die Runde erzeugt hat, die Sie halten - 1 für den Median der Handelsplätze, 2 für die zweite Quelle. Ein Feed, dessen source sich geändert hat, ist weiterhin ein gültiger Preis, auf andere Weise erzeugt; wenn das für Ihr Produkt zählt, beobachten Sie das Feld, statt es zu erschließen.
Die zweite Quelle
Jede Aktualisierung aus der zweiten Quelle durchläuft diese Prüfungen, bevor sie als Preis in Frage kommt. Eine abgelehnte Aktualisierung erhöht einen Zähler nach Grund, pro Feed sichtbar auf den Quellen- und Prüfrouten des Dienstes:
| Prüfung | Grenze |
|---|---|
| Exponent | pinned on the first updateany later drift is rejected, so a silent rescaling cannot pass |
| Slot and publish time | must advancean update that does not move them forward is dropped |
| Future tolerance | 5 sa publish time further ahead than this is rejected |
| Confidence | 50 bps crypto and index, 30 equity, 10 commodity and fxthe reported confidence interval as a fraction of the price; wider is rejected |
| EMA band | 10 % crypto and index, 5 % elsewherea jump away from the exponential moving average needs a SECOND sample within 100 bps of the first before it is used. A lone spike is dropped |
| Freshness | 10 s since receipt, 30 s publish lagboth measured at receipt on the monotonic clock |
Ohne die Zugangsdaten schweigen zwanzig der dreiunddreißig Feeds
The upstream needs a credential. Without one it answers unauthorised and every feed with no venue leg stays unpublished - twenty of the thirty-three, which is the whole real-world set plus XMR/USD.
The thirteen exchange-backed feeds continue: they are computed from public venues and need no credential. What they lose is the cross-check and the stand-in, since neither can be established without a Pyth price to compare against. Readiness reports this as a warning rather than a failure, so the service looks healthy while two thirds of the catalog is silent - check the per-feed status, not the service's.
Die Prüfung des Exponenten ist die stille und die wichtigste. Die Skala einer Aktualisierung wird von der ersten authentifizierten an festgehalten, und jede spätere Abweichung wird rundheraus abgelehnt, denn eine stille Umskalierung ist ein Preis, der um eine Zehnerpotenz falsch ist und dabei völlig wohlgeformt aussieht.
Wie er auf die Chain gelangt
- The aggregating service holds no signing key at all. It computes prices and serves them on an internal port.
- The node's publisher polls that port, authenticates the body with a shared HMAC of the exact bytes, and re-checks every item against on-chain state before signing - mirroring the contract's own skip rules so a bad item costs a counter rather than gas.
- The batch is written as ONE system transaction per EVM block, signed by the publisher key, which lives in the node's process and is used by nothing else in it.
- The service then reads its own result back off the chain and reports it, which is what the onchain field of every FeedView is.
At most 64 feeds go into one batch by default, and the contract's own maxBatch caps it again. A batch older than 2 s is not published.
Die Arbeitsteilung ist der Punkt. Alles Langsame oder Fehlbare - das Abfragen, die Authentifizierung, das Lesen des Katalogs, die Auswahl, die Kodierung, das Signieren und das Anhängen an das Write-Ahead-Log - geschieht abseits des Versiegelungspfads, der eine fertige Transaktion empfängt und sie zum Preis jeder anderen Transaktion anwendet. Und weil der Herausgeber vor dem Signieren jeden Eintrag erneut gegen den Zustand on-chain prüft und dabei die Auslassungsregeln des Contracts spiegelt, kostet ein Aggregator, der etwas Schlechtes schickt, einen Zähler statt einer Runde.
Das Vertrauensmodell
A price is as trustworthy as the operator that produces blocks, and no more. The publisher is the block producer.
- One party operates the node, holds the publisher key and orders transactions. A price inherits exactly the assumption that already governs ordering.
- Nothing on chain arbitrates a price. There is no second publisher, no dispute window and no slashing: the contract checks that an item is well formed, positive, not from the future and not older than the feed's last observation, and then writes it.
- The owner role can add a feed, change a feed's policy, rotate the publisher and adjust the batch and tolerance parameters. Ownership transfer is two-step. Those are the only write paths that are not the publisher's.
- Splitting the key from the computation limits one failure, not the other: compromising the aggregating service lets an attacker propose prices, and every one is still re-checked and signed by the node. Compromising the node is the end of the argument.
- If you liquidate on these prices, that is the assumption you are taking, and it is the one to state to your own users.
Nichts von alldem oben ändert das. Die Regeln für Handelsplätze, der Median, die Ausreißerabweisung und die Gegenprüfung machen einen Preis robust dagegen, dass sich eine Quelle falsch verhält, was ein echter und häufiger Fehlerfall ist. Gegen die Partei, die signiert, tun sie nichts. Lesen Sie sie als Qualitätskontrollen, nicht als Konsens.
Die praktische Folge für eine Integration: Diese Preise eignen sich für ein Produkt, dessen Nutzern gesagt wird, wer sie erzeugt, und sie tragen dieselbe Annahme wie die Reihenfolge Ihrer eigenen Transaktionen - wenn Sie diese Annahme also ohnehin akzeptieren, um die Chain überhaupt zu nutzen, kommt mit den Feeds keine neue hinzu. Wenn Ihr Entwurf einen Preis braucht, den keine einzelne Partei fälschen kann, liefert diese Schicht ihn nicht, und kein Parameter bringt sie dazu.