(price, decimals) for a feed symbol. RiskEngine converts the result to USD WAD.
Resolution order
The production path can reuse a 30-second memo. Otherwise it checks a Reflector-compatible feed’s latest timestamp, uses a supported positive five-record TWAP when fresh, then a positive fresh spot price, then an admin-set fallback. Fresh upstream data must be no older than 600 seconds; fallback prices expire after 86,400 seconds. A missingtwap method is tolerated. The testutils path uses a mock oracle without the TWAP call.
A fallback is a configurable emergency price, not guaranteed live market data. If no usable price exists the call fails. RiskEngine handles failures differently for new risk and liquidation; plain collateral that cannot be priced blocks AccountManager liquidation.
Administration
The admin can set fallback prices, replace the Reflector address, and upgrade WASM. Configuration getters expose upstream address, staleness windows, and per-symbol fallback metadata. Stored metadata and memoization reduce cross-contract costs; read the implementation before assuming every call contacts Reflector.Function signatures
__constructor
get_price_latest
get_oracle_config
get_asset_config
get_admin
set_fallback_price
set_reflector_contract
upgrade
Source reference
Protocol_V1_Soroban_testnet/contracts/OracleContract/src/oracle_service.rs

