Carlos Toledo
SIN-MFG · a living note · v0.3 · everything below is solved live in this page — no libraries, no precomputed data

Price formation with a stock constraint:
a mean-field model of a hydro-dominated power system

Storage agents and log-utility consumers meet a Hotelling-type hydro resource under an administrative price band. Three clearing regimes emerge; the water value pins the price; every numerical claim on this page carries a machine-checked certificate, and the structural results are labeled by proof status.
Carlos Toledo · carlos@carlostoledo.co · working note in the tradition of Gomes–Saúde (2021), Gomes–Gutierrez–Ribeiro (2021), Bakaryan–Aoun–de Lima Ribeiro–Hovakimyan–Gomes (2025) · Brazil, 2026
Abstract. I couple a mean field of small storage/consumption agents — quasi-linear preferences with log (unit-elastic) demand, truncated at an exogenous consumption cap c̄, giving closed-form demand min(a(t)/ϖ, c̄) — to a price-taking hydro resource with an intertemporal stock constraint and a convex thermal fringe, clearing under an exogenous price band (Brazil's PLD floor/cap). The model contains three regimes — curtailment, interior, scarcity — and two structural results: the equilibrium is the KKT/VI system of a convex program projected onto the band [SKETCHED], and the water value pins the price flat on hydro-marginal windows — proved in the deterministic interior-reservoir case this page runs (Hotelling; it is the clearing system the certificates check to machine zero), and a martingale between constraint events in the stochastic form — proved in discrete time (scenario trees, by LP duality; machine-certified in the repository battery) [PROVED], with the continuum well-posedness open [OPEN] — a prediction testable on public hourly PLD data. The figure below is not an illustration: it is the equilibrium, computed in your browser as you read, with its certificates printed beside it.

What this is for, if you dispatch or price hydro

Hydrothermal scheduling in Brazil runs on the SDDP lineage (Pereira–Pinto; NEWAVE/DECOMP). Those methods return a policy. What they do not return is a machine-checkable statement that the answer is optimal — the value functions are approximations built from sampled cuts, and their error is bounded statistically, not certified. This page returns the certificate.

The questionWhat is actually delivered
Is this release schedule optimal, or merely feasible? An exact primal–dual pair on the scenario tree — piecewise-linear concave value functions with every breakpoint tracked — and a zero duality gap proving it. Weak duality is checked with its sign, so a dual that undershoots the primal is caught rather than absorbed into an absolute value.
What is my water worth, and when does that number stop being trustworthy? The water value w is a martingale between stock-binding events, exactly — and the certificate names the nodes where it is allowed to break (full reservoir: steps down; empty: steps up). The binding set is an output, not an assumption.
Can my regulator or counterparty re-run it? Yes, without reading the prose. The kernel is one file, the battery is one command, and the artifact and the tool are held byte-identical by a gate — one kernel, two carriers, and they cannot drift.
What happens when it cannot prove the answer? It refuses and says why. The dispatch stalls honestly rather than returning a number without a certificate. That is the distinguishing behaviour, not a limitation.

What it costs to be wrong. A water value that is too low spills stored energy; too high withholds it into a scarcity window and buys thermal or unserved energy at the cap. Both errors are priced at the difference between w and the band, per MWh, every hour of the horizon — and neither is visible in a solver that reports only a policy.

Stated honestly, because it bounds the offer. The certified object is the discrete scenario-tree problem: a finite LP, so KKT holds with no constraint qualification because the constraints are linear — that is finiteness, not a strength of the argument. The continuum statement is open. The interior-reservoir reduction on this page imposes only the daily energy budget; the piecewise-w regime with binding stock bounds lives in the stochastic tree model. The method is validated continuation / LP duality and is not ours: water values and their martingale behaviour are classical in hydro scheduling. What is ours is the precise tree-LP statement, its one-page duality proof, and a certificate you can execute.

1 · The model in four lines

agentmaxc,α ∫ [ a(t)·log c − ϖ(c+α) − ½η α² ] dt + Ψ(x_T),   dx = α dt + σ dW,   x ∈ [0, x̄] reflecting  ⇒  c* = min(a/ϖ, c̄),   α* = clamp((u_x − ϖ)/η)
field−∂_t u − ½σ²∂_xx u − H(∂_x u − ϖ) = 0,   H(p) = max|α|≤ᾱ ( α·p − ½η α² )  ·  ∂_t m − ½σ²∂_xx m + ∂_x(m α*) = 0   (conservative flux form — mass exact; diffusion self-adjoint)
clearingD(ϖ) + L + φ·A[m,u] = h + q*(ϖ) + S − κ + d,   0 ≤ κ ⟂ (ϖ − ϖ_min) ≥ 0,   0 ≤ d ⟂ (ϖ_max − ϖ) ≥ 0   — the residual of this line is the first certificate below
hydrodR = (I − h)dt,   Σh·dt = E_hydro,   h interior ⇒ ϖ = w   — Hotelling-type: on hydro-marginal hours the price is pinned to the water value w (the stock's shadow price), constant here because this benchmark imposes only the daily budget — the interior-reservoir reduction [T3]
idle

Fig. 1 — the day, cleared price · regimes · water value

equilibrium price ϖ(t) water value w (dashed) curtailment regime (floor, κ>0) scarcity regime (cap, d>0) administrative band

Fig. 2 — who serves the load stack

VRE used hydro thermal deficit curtailed VRE total demand

Fig. 3 — the fleet, as a density m(x,t) · storage

population density over state-of-charge (dark = dense) — charging into the solar hours, discharging into the peak

Certificates every claim above, checked — pre-update residuals only

clearing residual (worst slice)
mass of m (drift)
min m (positivity)
hydro budget error
hydro complementarity
T3 · Hotelling complementarity (marginal hours)
band complementarity
w dual feasibility (±1% bracket)
exploitability (independent DP audit)
regimes today (C · I · S hours)
curtailed energy · this fleet vs φ=0
welfare gap of a posted TOU tariff
fixed-point residual (price path)
price-path residual per Picard iteration (log)

Real data — a look, not a proof SE hourly PLD · CCEE PLD_HORARIO · Jul 2024

hourly PLDflat hydro-marginal windowsadministrative floor

The shape T3 predicts is descriptively present in two real weeks: prices sit flat within hydro-marginal windows (shaded), the level steps between them (~R$95 → ~R$78, the water value as a day-to-day martingale), and jumps arrive at the evening peak. This is consistency, not a test: PLD is the administered CMO of the official dispatch model, whose hydro-marginal value is the constructed water value, so flatness here partly reflects the price's own construction — and the flatness statistic measures persistence, on windows selected to be non-extreme. The five-year picture (2021–2025), including the 2021 water crisis as the flattest year, is in the note text and the companion script; a clean test needs a persistence-matched null on a market — not administered — price.

What you just watched. The solve animates a damped Picard iteration on the price path: field (HJB backward, FP forward in conservative flux form) → hydro water value by bisection on the energy budget → three-regime clearing per hour. The price lands flat on the water value across the hydro-marginal hours. Stated carefully: the Hotelling rule assigns ϖ = w on marginal hours — the emergent, checked content is which hours are marginal, that a single constant w closes the hydro energy budget through the fixed point (dual-feasibility receipt: perturbing w by ±1% breaks the budget in the correct directions), and the complementarity pattern off the marginal set. The fully falsifiable form of T3 — w a martingale, flat windows in data — lives in the stochastic model and in the PLD test below. Slide the solar amplitude up and watch the curtailment regime widen at the floor; slide the fleet φ up and watch it shrink — the curtailment line in the certificates is Theorem-target T4's sign, live. The welfare-gap line prices posted time-of-use tariffs against the equilibrium signal — including the best two-level tariff found by grid search, so the gap is not an artifact of a badly chosen strawman: the gap is the deadweight cost of pricing a crowd without pricing its reaction to itself. Both sides are held to the same stock constraint. The counterfactual's hydro obeys the same KKT trichotomy as the equilibrium's — including the withholding branch, so it can decline to sell below its own water value — and closes Σh·dt = E_hydro to machine precision at every tariff evaluated. If any counterfactual on the grid fails to close it, this line prints refused and the budget error instead of a percentage, because a comparison between a constrained equilibrium and an unconstrained alternative is not a comparison. It did exactly that before 2026-07-29: the counterfactual dispatched hydro as a pure residual, overspent the daily budget on 50 of 50 grid points (worst 4.93 against 3.2), and the figure it produced understated the equilibrium.

Status of the mathematics, stated plainly. What is new here is the object, not the machinery: a mean-field storage crowd cleared against a Hotelling hydro stock, with the administrative band as a first-class equilibrium object, and most certificates read as a constraint residual or an adjoint martingale. The tools it stands on are standard — Benamou–Brenier convexity, Lasry–Lions monotonicity, the Hotelling water value — and each claim here is labeled proved, standard, or open, nothing blurred. The equilibrium is characterized as the KKT system of a convex program (convexified field, convex costs, linear constraints) projected onto the administrative band — a monotone variational inequality [SKETCHED — continuum convex structure standard (Lasry–Lions/Cardaliaguet); reflecting-boundary duality open. An exact discrete KKT needs the transport to be adjoint-matched (FP = HJBᵀ), the block-symmetric monotone scheme of Achdou–Capuzzo-Dolcetta — an upwind HJB with its exact-transpose FP; this page's diffusion is already adjoint-matched, but it pairs a centered HJB gradient with an upwind FP, so the transport is not, and conservation comes from the flux form instead. Not self-adjointness (A ≠ Aᵀ) — adjoint-matching between the two operators]. The water-value result [T3] splits by regime, and the split is honest about what is proved: in the deterministic interior-reservoir case this benchmark runs, T3 is a theorem [PROVED] — the water value w is the constant KKT multiplier of the daily energy budget, so on hydro-marginal hours ϖ = w by complementary slackness. That is exactly the hydro dispatch rule the certificate panel checks to machine zero (marginal-hour |ϖ−w| = 0, the withhold/marginal/full complementarity p<w⇒h=0 / p>w⇒h=h̄, budget monotone in w) — the demand-side band regimes (curtailment/scarcity) are the separate κ,d saturations, not this KKT. The stochastic form — w a martingale between constraint events, the costate of the reservoir with vanishing drift wherever the Hamiltonian does not see the stock — is the same mechanism as Lemma 3.1 of Gomes–Gutierrez–Ribeiro (Π a martingale), and in discrete time it is now a theorem [PROVED]: on any finite scenario tree the water value satisfies w = E[wchild | node] at every node with interior post-release stock, stepping down across full-reservoir events and up across empty ones — one page of LP duality — the constraints are linear, so strong duality is automatic and no constraint qualification has to be assumed; that is a property of finite LPs, not a strength of this argument — certified to machine precision in the repository battery (test-water-value.js: zero duality gap, off-binding martingale residual ~1e-13 across a 120-tree random sweep; spilling nodes get w = 0, the floor-spill regime as a dual complementarity). What remains [OPEN] is the continuum statement — reflected-FBSDE well-posedness through the mean-field coupling. Either way the organizing principle behind every number in the certificate panel falls into one of a few kinds, and it is worth being exact about how many, because the tempting one-liner — that a certificate is always either a constraint residual or an adjoint martingale — is falsified by this page's own panel. What is actually here is four classes: constraint residuals (clearing, mass, hydro budget), complementarity and feasibility checks (the band, the box, positivity), adjoint identities and martingales (the water value between binding events), and an independent optimality gap — the exploitability ε, measured by a separately coded DP best response, which is none of the first three. Exploitability as the equilibrium certificate is standard; see Guo, Hu & Zhang (MF-OMO, SIAM J. Control Optim. 62(1), 2024; arXiv:2206.09608) for the discrete-time optimisation formulation, whose Theorem 8 bounds exploitability by the optimisation residual with an explicit constant — for finite state, action and horizon only. No continuum analogue exists, so ε is reported here beside the residual that limits it. What is specific here is the stock-constrained continuum setting and the independently coded DP audit. Whether these are instances of one calculus or genuinely different certificate geometries is the one question this note deliberately leaves open; the honest guess today is the latter.

The falsifiable part — a first look at real data, and its limits. T3's deterministic form predicts that within hydro-marginal windows, strictly inside the band, the price is flat — jumping only at constraint events. Five years of Southeast hourly PLD (CCEE PLD_HORARIO, 2021–2025) show that shape descriptively: interior windows are flat, with the level stepping between windows, and the flatness tracks the hydro-marginal regime, not the calendar — the flattest year is 2021, the water crisis, when scarcity kept hydro marginal almost year-round, while in abundant years the wet season sits at the floor (curtailment) instead, so the naive wet-vs-dry seasonal proxy is refuted. But this is consistency, not yet a clean test, and the note says so plainly: PLD horário is the administered price — the capped CMO of the official dispatch model (DESSEM) — and in hydro-marginal hours that CMO is the constructed water value, so flatness there partly reflects the price's own construction rather than an independent market fact; the permutation null measures persistence, not pinning; and interior windows are selected and split at jumps. The honest statement: the model's water-value structure is consistent with how Brazil's official hourly price behaves — a starting point for a real test (a persistence-matched null on a market, not administered, price), not the test itself.

Disclosures. Units are dimensionless and profiles stylized — this page validates a formulation, not Brazil; calibration (ONS/CCEE series, CVU merit order, LRCAP fleet) is the next phase and is where the demand-side parameters are weakest. Reflecting dynamics approximate state-of-charge constraints (they are not state constraints). Controls are power-limited (|α| ≤ ᾱ enters the Hamiltonian). The forward operator has self-adjoint diffusion (verified to machine zero) and upwind transport (chosen for positivity, verified strict); unlike the adjoint-matched HJB⇄FP pair of the continuum-lab tabs (upwind HJB with its exact-transpose FP, à la Achdou–Capuzzo-Dolcetta — certified there by an operator-level transpose check), this page's transport is not the exact discrete adjoint of its centered HJB drift, so mass conservation here comes from the conservative flux form (verified at the operator level: the transport matrix has machine-zero column sums), not from an adjoint identity. The exploitability certificate is computed by an independently coded Markov-chain best response and is reported on its own, to be read beside the Picard residual that limits it. No absolute floor is printed: an earlier O(h+Δt) "floor" was removed as fabricated (|ε|/floor is measured to span several orders across the slider box, so no single constant bounds ε — the same retraction made in the lab). When the hydro budget cannot be absorbed even at the price floor, the model spills the surplus and says so; when the water value pins to the cap, hydro is indifferent between selling and withholding and the dispatch mixes (θ reported) — both degenerate-dual cases are handled and labeled, not hidden, in the equilibrium and in the welfare counterfactual, which until 2026-07-29 had neither and silently overspent its hydro. This benchmark imposes only the daily energy budget Σh·dt = E_hydro — the interior-reservoir reduction, in which the reservoir state R_t and inflows are not resolved (there is no R_t in the solver, and nothing that could bind), which is exactly the regime where a single constant water value w appears; the piecewise-w regime with binding stock bounds and spill/empty events belongs to the deferred stochastic version with R_t. Four further honesty notes: the 24h horizon ends on a storage-target terminal condition, which shapes late-evening fleet behavior — the cleaner object is the periodic-day (cycle) equilibrium, on the roadmap; the welfare-gap's nonnegativity is exact as a continuum claim and holds numerically here with wide margin, but at coarse grids small negative values would indicate discretization, not a theorem failure; convergence of the damped Picard iteration is observed, not proven — the trust object is the end-state certificate panel, never the path; and slice prices can be set-valued on measure-zero plateaus (satiated demand + capped thermal + clamped fleet), a third benign degeneracy of the same species as the floor-spill and cap-mixed cases — aggregates remain unique throughout. Related literature I build beside, not instead of: Alasseur–Ben Tahar–Matoussi (storage MFG), Aïd–Basei–Pham (McKean–Vlasov distributed generation), Féron–Tankov–Tinsi (intraday markets); and, on the economics side, the rational-storage price theory of Scheinkman–Schechtman and Deaton–Laroque, of which T3's flat-when-interior / spike-at-constraint pattern is the hydro-MFG incarnation — the delta over that tradition is the mean-field coupling, the administrative band as a first-class object, and the certified national-calibration program. Deferred, not hidden: the Hessian–Riemannian solve of the market VI at scale, spill-event scenarios (piecewise water value), grid-refinement study, common-noise (reflected FBSDE) version.

For discussion. (1) Does the Gomes–Saúde multiplier formulation extend as sketched through the elastic-demand, banded balance — or is there a subtlety I owe more respect? (2) The adjoint-martingale half of this is standard Pontryagin — when the state derivative of the Hamiltonian vanishes the costate is a local martingale, and I am not claiming otherwise. The question I actually have is the other half: equilibrium clearing can force an exact pathwise first integral of the coupled price–aggregate–adjoint system, which is a different mechanism. In the LQ case that integral is linear and exactly solvable; is there a criterion for when the closure forces one at all, and does anything survive non-LQ demand — a nonlinear invariant, or only an asymptotic one? (3) The market VI shares its class with the Wardrop flow of arXiv:2504.16028 — is the Hessian–Riemannian flow the right solver for it at national scale?

Colophon. One HTML file, no libraries; the numerics were developed headless-first and are validated by a battery that EXTRACTS this page's kernel at run time (so it cannot certify a stale copy) and checks it in two layers — the mathematics, and the artifact's own display path — including the independent DP audit, every regime and degenerate-dual case, the operator-level conservation and self-adjoint-diffusion structure, and a permutation-null contrast that tested and rejected the naive seasonal proxy (the flatness tracks the hydro-marginal regime, not the month). Every fix is mutation-proven (reverted to confirm the check goes red). Built with the same kernel and certificate discipline as the MFG Lab, its interactive companion piece, and the computer-assisted proof.