Protocol
Checkpoints
Every Phoenix funding record becomes an immutable checkpoint, in order and without gaps.
One checkpoint per funding interval
Phoenix closes a funding interval every hour, on the hour, and adds that hour's funding to its cumulative total. Each interval is one funding record, identified by the time it starts. Tack copies each record into a checkpoint, a program account of its own:
checkpoint = PDA("checkpoint", market, sequence as u64 LE)
market the market it belongs to
sequence 1, 2, 3, … with no gaps
cumulativeFunding Phoenix's cumulative funding, USD per SOL at 1e9
timestamp the start of the interval: the end of the hour it pays for
finalized true for the market's final checkpointPublishing a checkpoint is permissionless and the program accepts exactly one kind: the next one. Phoenix's current interval must start exactly one interval after the market's last, and the source must pass every check on the floating leg. Checkpoints are never edited or removed.
Why no gaps
The cumulative total only says where funding ended up, not how it got there. If two intervals passed between checkpoints, a spike and its reversal could sit between them unseen, and a position that should have been liquidated at the spike would survive it. So the program refuses to skip: if Phoenix has moved on by more than one interval, the market can publish nothing more, and after the freeze grace it can only close at its last checkpoint.
That makes the crank's timing part of the product. Tack's crank publishes each record within seconds of Phoenix starting a new interval, and has the whole hour to do it.
Checkpoints gate trading
A trade checks that the market has published Phoenix's latest record: the market's stored total and interval start must equal what Phoenix's account says now. Between Phoenix closing an hour and the checkpoint landing, new quotes and takes wait, usually for a few seconds; the app shows a notice while they do.
Settling against checkpoints
A position remembers the last checkpoint it has settled. Settlement passes the next checkpoints, in order, as read-only accounts:
- at most eight per transaction;
- each must be the next sequence for this market, at or after the position's start;
- the crank, or anyone, repeats until the position is caught up.
Each checkpoint is applied in full, including the maintenance check, before the next one is read. Settlement has the arithmetic.