Skip to main content
OracleContract returns (price, decimals) for a feed symbol. RiskEngine converts the result to USD WAD.

Resolution order

The production path can reuse a 30-second memo. Otherwise it checks a Reflector-compatible feed’s latest timestamp, uses a supported positive five-record TWAP when fresh, then a positive fresh spot price, then an admin-set fallback. Fresh upstream data must be no older than 600 seconds; fallback prices expire after 86,400 seconds. A missing twap method is tolerated. The testutils path uses a mock oracle without the TWAP call. A fallback is a configurable emergency price, not guaranteed live market data. If no usable price exists the call fails. RiskEngine handles failures differently for new risk and liquidation; plain collateral that cannot be priced blocks AccountManager liquidation.

Administration

The admin can set fallback prices, replace the Reflector address, and upgrade WASM. Configuration getters expose upstream address, staleness windows, and per-symbol fallback metadata. Stored metadata and memoization reduce cross-contract costs; read the implementation before assuming every call contacts Reflector.

Function signatures

__constructor

get_price_latest

get_oracle_config

get_asset_config

get_admin

set_fallback_price

set_reflector_contract

upgrade

Source reference

  • Protocol_V1_Soroban_testnet/contracts/OracleContract/src/oracle_service.rs