開発者へ / 現実世界資産

価格はどう作られるか

二つの集約方式、一つの公開者。以下の算術は、取引所の一つがおかしくなっても価格が壊れないようにするものです。価格を信頼に値させるものではありません。それは最後の節であり、これらの数値で何かを清算する前に読むべき節です。

価格はどこから来るか

Thirteen feeds are aggregated from five public spot venues, each subscribed with that venue's own product id. The other twenty have no venue leg and come from Pyth Network's Hermes service alone.

情報源内容
スポット取引所Coinbase, Kraken, Bitstamp, Gemini, Bitfinexeach subscribed with that venue's own product id, taken from the catalog
第二の情報源Pyth Network, over its Hermes servicethe only source for the twenty feeds with no venue leg, and a cross-check for the other thirteen

二つの方式は違う壊れ方をするので、利用者には両方のふるまいが必要です。取引所に裏打ちされた フィードは、一つの取引所が落ちても生き延びます。中央値は五つにわたって取られ、それぞれが 自分の新鮮さを持つからです。単一の情報源のフィードは、その情報源が使えなくなれば生き延び られず、推測する代わりにそう言います。

取引所が数に入るとき

何かが組み合わされる前に、各取引所は単独で評価されます。規則はこの順に適用され、最初に 失敗したものがその評価での中央値からその取引所を外します。

規則しきい値
Connection statemust be onlinea venue whose socket is down is never fresh, whatever its last quote said
Quote age10 smeasured on a MONOTONIC receive clock, never on the exchange's timestamp or the host's wall clock
Delivery lag5 s either waya timestamp trailing its receipt means the socket is replaying a backlog; one leading it means the venue dates quotes in the future. The whole venue sits out rather than falling through to its last trade
Spread50 bpsthe mid is used when the book is uncrossed and tighter than this
Last trade60 sthe fallback when no usable mid exists, inside its own longer window
新鮮さは単調な時計で判断されます

取引所のタイムスタンプでもなく、ホストの実時計でもありません。時計が進んでいたり遅れて いたりする取引所が、自分の気配を新鮮に見せかけることはできませんし、時計が飛ぶホストが すべての取引所を一度に無効にすることもできません。取引所のタイムスタンプが使われるのは 一つの用途だけです。受信の時点と双方向に比べる、配送遅れの検査です。

板が新しく、クロスしておらず、スプレッドの上限より狭いときは、最良の bid と ask が 優先されます。そうでなければ、自身のより長い窓の中で、直近の約定が代役を務めます。 ソケットが滞留分を再生している取引所は、直近の約定へ落ちるのではなく丸ごと外されます。 その約定も同じだけ遅れているからです。

中央値

  1. Evaluate every venue against the rules above and keep the fresh ones.
  2. If fewer than minSources are fresh, publish nothing and report the reason - no_sources when none is fresh, too_few_sources otherwise. Nothing thin is ever published.
  3. Take the median of what survives.
  4. If the spread between the included venues exceeds 200 bps and dropping one would still leave minSources, drop the venue furthest from the median - on a tie the older observation - and take the median again. At most one venue is dropped.
  5. Round half-even to the feed's decimals. The result is an integer, not a float.
  6. Date the aggregate with the NEWEST included quote, capped at the current wall clock so no venue with a fast clock can date a median into the future.

degraded is set when the median rested on exactly minSources venues: still published, one drop-out from silence.

情報の薄いフィードは、何かを公開するのではなく何も公開しません

minSources はフィードごとで、取引所に裏打ちされたフィードではどれも 3 です。 それを下回ると、答えはまったくありません。最後に分かっていた値がチェーンに再公開される ことはなく、ラウンドは進まず、updatedAt は動かなくなります。サービスは診断の ために最後の良い回答を lastKnown として報告し続けますが、そのフィールドは 明示的に、取引に使う価格ではありません。

集約値には、含まれた気配のうち最も新しいものの時刻が付き、現在の実時計で 頭打ちにされます。この二つの半分はどちらも効いています。六十秒前の約定が陳腐化した板の 代役を務めた取引所が、他の入力が一秒未満である中央値に日付を付けてはなりませんし、時計が 進んだ取引所が観測時刻を未来へ押し出せてもなりません。未来へ出れば、コントラクトは理由 4 としてそれを飛ばします。

クロスチェックと代役

An exchange-backed feed that also has a Pyth leg is cross-checked against it on every evaluation. Within 100 bps the two are recorded as agreeing; beyond it the feed is marked diverged and the dispersion flag is raised.

When the venues go stale, Pyth may stand in for them - but only if the two agreed recently and are not diverging now. A feed publishing from the stand-in is marked degraded and its source reads pyth rather than exchanges-median, so a consumer can tell. If they are diverged and Pyth is fresh, the feed publishes nothing and reports cross_check_diverged.

二つのフィールドがこれを外に見せます。crossCheckBps は二つの方式の現在の 隔たりで、source は今あなたが持っているラウンドをどちらが生んだかを述べます。1 なら取引所の中央値、2 なら第二の情報源です。source が変わったフィードも、別のやり方で作られた正当な価格です。それが あなたの製品にとって重要なら、推し量るのではなくそのフィールドを見張ってください。

第二の情報源

第二の情報源からの更新はすべて、価格になる資格を得る前にこれらの検査を通ります。拒否された 更新は理由ごとのカウンタを増やし、サービスの source と audit のルートでフィードごとに 見られます。

検査上限
Exponentpinned on the first updateany later drift is rejected, so a silent rescaling cannot pass
Slot and publish timemust advancean update that does not move them forward is dropped
Future tolerance5 sa publish time further ahead than this is rejected
Confidence50 bps crypto and index, 30 equity, 10 commodity and fxthe reported confidence interval as a fraction of the price; wider is rejected
EMA band10 % crypto and index, 5 % elsewherea jump away from the exponential moving average needs a SECOND sample within 100 bps of the first before it is used. A lone spike is dropped
Freshness10 s since receipt, 30 s publish lagboth measured at receipt on the monotonic clock

認証情報がなければ、33 のうち 20 のフィードが黙ります

The upstream needs a credential. Without one it answers unauthorised and every feed with no venue leg stays unpublished - twenty of the thirty-three, which is the whole real-world set plus XMR/USD.

The thirteen exchange-backed feeds continue: they are computed from public venues and need no credential. What they lose is the cross-check and the stand-in, since neither can be established without a Pyth price to compare against. Readiness reports this as a warning rather than a failure, so the service looks healthy while two thirds of the catalog is silent - check the per-feed status, not the service's.

指数の検査は地味で、最も重要なものです。更新のスケールは最初に認証されたものから固定され、 あとからのずれは即座に拒否されます。黙って尺度が変わることは、まったく正しい形に見えながら 10 の累乗ぶん間違った価格だからです。

チェーンへどう届くか

  1. The aggregating service holds no signing key at all. It computes prices and serves them on an internal port.
  2. The node's publisher polls that port, authenticates the body with a shared HMAC of the exact bytes, and re-checks every item against on-chain state before signing - mirroring the contract's own skip rules so a bad item costs a counter rather than gas.
  3. The batch is written as ONE system transaction per EVM block, signed by the publisher key, which lives in the node's process and is used by nothing else in it.
  4. The service then reads its own result back off the chain and reports it, which is what the onchain field of every FeedView is.

At most 64 feeds go into one batch by default, and the contract's own maxBatch caps it again. A batch older than 2 s is not published.

役割の分担が要点です。遅いもの、失敗しうるもの、つまりポーリング、認証、カタログの読み取り、 選別、符号化、署名、先行書き込みログへの追記は、すべて封印の経路の外で起こります。封印の 経路は出来上がったトランザクションを受け取り、ほかのどのトランザクションとも同じ費用で それを適用します。そして公開者は、署名する前にコントラクト自身のスキップ規則を写し取って 各項目をオンチェーンの状態に対して検査し直すので、集約サービスが悪いものを送っても、 代償はラウンドではなくカウンタで済みます。

信頼モデル

A price is as trustworthy as the operator that produces blocks, and no more. The publisher is the block producer.

  • One party operates the node, holds the publisher key and orders transactions. A price inherits exactly the assumption that already governs ordering.
  • Nothing on chain arbitrates a price. There is no second publisher, no dispute window and no slashing: the contract checks that an item is well formed, positive, not from the future and not older than the feed's last observation, and then writes it.
  • The owner role can add a feed, change a feed's policy, rotate the publisher and adjust the batch and tolerance parameters. Ownership transfer is two-step. Those are the only write paths that are not the publisher's.
  • Splitting the key from the computation limits one failure, not the other: compromising the aggregating service lets an attacker propose prices, and every one is still re-checked and signed by the node. Compromising the node is the end of the argument.
  • If you liquidate on these prices, that is the assumption you are taking, and it is the one to state to your own users.

以上のどれもそれを変えません。取引所の規則、中央値、外れ値の除去、クロスチェックは、情報源がおかしくなっても価格が壊れないようにするものであり、それは実際に起こる よくある失敗です。それらは署名する当事者に対しては何もしません。合意形成としてではなく、 品質管理として読んでください。

統合する人にとっての実際的な帰結。これらの価格は、誰がそれを作っているかを利用者に伝えて いる製品に向いています。そしてそれらは、あなた自身のトランザクションの順序付けと同じ前提を 運びます。だからチェーンを使うためにその前提をすでに受け入れているなら、フィードを使うことは 新しい前提を一つも足しません。単一の当事者では偽造できない価格が設計に必要なら、この レイヤーはそれを提供しませんし、どのパラメータもそうさせません。