{"workflow":null,"planning":null,"id":"08a12413-5e3b-4baf-9f1c-6d1ba99e9487","state":"completed","template":"audit","objective":"Audit the whole system: src/, script/DeployMainnet.s.sol and deploy/mainnet/, at the pinned commit, for a mainnet launch. Nine audit rounds and their fixes are already in (docs/AUDIT-*.md). The newest is docs/AUDIT-FINAL-VAULT-PANEL-2026-10-08.md, whose fixes are this commit (6085c8a); its Resolution section says how each finding was answered. Since the last whole-system sweep (973369e, docs/AUDIT-SWEEP-PANEL-*-2026-10-07.md) only src/CDPVault.sol and src/ParameterizedVault.sol changed: git diff 973369e 6085c8a -- src. A finding of an earlier round counts only if its fix regressed or left a gap. Two items are accepted with their reasons stated where they live, and are findings only if the reason is wrong: the repay-then-redeem premium (CDPVault._backingPerUnit) and a redraw after a redemption releasing a repayment's fee share early (CDPVault._lag).\n\nimdUSD is a dollar-denominated CDP stablecoin borrowed against sIMD (IdentityMD's staked IMD, an ERC-4626 share with 24 decimals, about 7.95 IMD each). Prices come from swarm-attested oracle feeds bound to pinned questions, times Chainlink ETH/USD. Everything about the deployment is in src/DeploymentConfig.sol and docs/MAINNET-RUNBOOK.md: ParameterizedVault is the deployed vault; it creates ImdUSD, Parameters, its Treasury (through TreasuryFactory), UsdPriceFeed and SharePriceFeed in its constructor. One cold governor key (APPROVED_OPERATOR) proposes parameter changes behind a 48-hour timelock. Collateral pricing is per 1e18 raw units throughout. IMD's only market is a full-range Uniswap v4 pool, about $2.3M a side with a 1% fee; docs/PARAMETERS-2026-10-05.md has the numbers every economic parameter was chosen from.\n\nAnswer each numbered question, including the ones where nothing is wrong:\n1. THE VAULT'S NEWEST LINES (git diff d7fceab 6085c8a -- src). (a) The excess of 58f73de is removed: confirm nothing of it remains, that the same-call repayment tally (REPAID_THIS_TX_SLOT, added in _payDebt and cover, not cash) closes the same-transaction wipe, cash, draw, and that the accepted cross-transaction premium is bounded as stated. (b) The quiet-day cutoff in _cool now applies to the vault totals, the positions and the banks alike: prove no sequence lets one position's capital warm another's, and that what remains (a stale position reading zero while a busy total keeps its share) only understates the lagged figures. (c) The fee base (_feeBase) is floored at 1,000 imdUSD (_feeBaseFloor) and read once per redemption, before the candidate is touched: can the floor be used to dilute fees once the protocol is past it, or the single read to misprice the stored rate?\n2. CROSS-SUBSYSTEM SEQUENCES. Any sequence across the vault, the Treasury, Parameters, the feeds, OracleAsker and SwarmRelay (bundled through relayMany, relayAndBark, relayAndBite or a contract of your own) that extracts value, mints unbacked imdUSD, blocks liquidation or redemption, or desynchronises an accounting record. Consider transaction boundaries explicitly: what the vault tallies per transaction (debt at transaction start, secured and minted, work minted, repaid) and what it keeps per position across transactions (cold capital, banks, feeExcess).\n3. THE ORACLE AS AN ATTACK SURFACE ON THE VAULT: with the per-epoch deviation bound, silence measured from the relay, the Treasury's refresh rules and the two-stage deploy as committed, the cheapest profitable manipulation of collateral prices (over-borrowing) or NHI (liquidation timing), in money and hours, at LINE $1M.\n4. LIVENESS AND THE LAUNCH: every way the protocol can halt and how each recovers, with docs/MAINNET-RUNBOOK.md and docs/PARAMETERS-2026-10-05.md checked against the code; the first hours after launch, when most supply is new (the lag, the fee base and its floor, the oracle's day-one funding through fundOracle and the keeper's fallback).\n5. THE DEPLOYMENT: DeployMainnet.run (stage one), verifySeeded (against the pool and REFERENCE_IMD_ETH_WEI), runVault (stage two), verify, deploy/mainnet/plan.py and the pinned bodies. What can still be deployed wrong and pass, and what can happen between the two stages? Contract size: ParameterizedVault's initcode is 46,662 of 49,152 bytes.\n6. Every comment or NatSpec in src/ that claims a property the code does not have.\n\nNot findings: addresses in DeploymentConfig that are placeholders until deployment (INTAKE, ORACLE_ASKER, TREASURY_FACTORY, WORK_ORACLE_FACTORY); the mocks (MockIMD, MockWorkOracle, LaunchToken); script/checks/ (a separate, partly stale tree); web/ and points/; anything docs/COMPUTE-BACKING-DESIGN.md describes as future work; and findings of the earlier audits in docs/AUDIT-*.md and docs/INTERNAL-AUDIT-2026-10-04.md, unless the fix regressed. A constant set to a deliberate economic value is not a finding; an arithmetic or ordering error in how it is used is.\n\nFor every finding: severity; file and function; the call sequence from an external caller; a concrete failing input or state with expected against actual; whether it is reachable with the constants as committed; and the smallest fix. Also report every place a comment or NatSpec claims a property the code does not have, and say which contracts you read in full and which you could not reach.","blockedReason":null,"createdAt":"2026-10-08T09:40:55.826Z","updatedAt":"2026-10-08T10:26:56.475Z","paidBy":"0x5167d014a056e43883e1bbea5530c3c0dc993281","parentJobId":null,"project":{"id":"08a12413-5e3b-4baf-9f1c-6d1ba99e9487","head":"08a12413-5e3b-4baf-9f1c-6d1ba99e9487","running":null,"versions":[{"jobId":"08a12413-5e3b-4baf-9f1c-6d1ba99e9487","workflowId":null,"objective":"Audit the whole system: src/, script/DeployMainnet.s.sol and deploy/mainnet/, at the pinned commit, for a mainnet launch. Nine audit rounds and their fixes are already in (docs/AUDIT-*.md). The newest is docs/AUDIT-FINAL-VAULT-PANEL-2026-10-08.md, whose fixes are this commit (6085c8a); its Resolution section says how each finding was answered. Since the last whole-system sweep (973369e, docs/AUDIT-SWEEP-PANEL-*-2026-10-07.md) only src/CDPVault.sol and src/ParameterizedVault.sol changed: git diff 973369e 6085c8a -- src. A finding of an earlier round counts only if its fix regressed or left a gap. Two items are accepted with their reasons stated where they live, and are findings only if the reason is wrong: the repay-then-redeem premium (CDPVault._backingPerUnit) and a redraw after a redemption releasing a repayment's fee share early (CDPVault._lag).\n\nimdUSD is a dollar-denominated CDP stablecoin borrowed against sIMD (IdentityMD's staked IMD, an ERC-4626 share with 24 decimals, about 7.95 IMD each). Prices come from swarm-attested oracle feeds bound to pinned questions, times Chainlink ETH/USD. Everything about the deployment is in src/DeploymentConfig.sol and docs/MAINNET-RUNBOOK.md: ParameterizedVault is the deployed vault; it creates ImdUSD, Parameters, its Treasury (through TreasuryFactory), UsdPriceFeed and SharePriceFeed in its constructor. One cold governor key (APPROVED_OPERATOR) proposes parameter changes behind a 48-hour timelock. Collateral pricing is per 1e18 raw units throughout. IMD's only market is a full-range Uniswap v4 pool, about $2.3M a side with a 1% fee; docs/PARAMETERS-2026-10-05.md has the numbers every economic parameter was chosen from.\n\nAnswer each numbered question, including the ones where nothing is wrong:\n1. THE VAULT'S NEWEST LINES (git diff d7fceab 6085c8a -- src). (a) The excess of 58f73de is removed: confirm nothing of it remains, that the same-call repayment tally (REPAID_THIS_TX_SLOT, added in _payDebt and cover, not cash) closes the same-transaction wipe, cash, draw, and that the accepted cross-transaction premium is bounded as stated. (b) The quiet-day cutoff in _cool now applies to the vault totals, the positions and the banks alike: prove no sequence lets one position's capital warm another's, and that what remains (a stale position reading zero while a busy total keeps its share) only understates the lagged figures. (c) The fee base (_feeBase) is floored at 1,000 imdUSD (_feeBaseFloor) and read once per redemption, before the candidate is touched: can the floor be used to dilute fees once the protocol is past it, or the single read to misprice the stored rate?\n2. CROSS-SUBSYSTEM SEQUENCES. Any sequence across the vault, the Treasury, Parameters, the feeds, OracleAsker and SwarmRelay (bundled through relayMany, relayAndBark, relayAndBite or a contract of your own) that extracts value, mints unbacked imdUSD, blocks liquidation or redemption, or desynchronises an accounting record. Consider transaction boundaries explicitly: what the vault tallies per transaction (debt at transaction start, secured and minted, work minted, repaid) and what it keeps per position across transactions (cold capital, banks, feeExcess).\n3. THE ORACLE AS AN ATTACK SURFACE ON THE VAULT: with the per-epoch deviation bound, silence measured from the relay, the Treasury's refresh rules and the two-stage deploy as committed, the cheapest profitable manipulation of collateral prices (over-borrowing) or NHI (liquidation timing), in money and hours, at LINE $1M.\n4. LIVENESS AND THE LAUNCH: every way the protocol can halt and how each recovers, with docs/MAINNET-RUNBOOK.md and docs/PARAMETERS-2026-10-05.md checked against the code; the first hours after launch, when most supply is new (the lag, the fee base and its floor, the oracle's day-one funding through fundOracle and the keeper's fallback).\n5. THE DEPLOYMENT: DeployMainnet.run (stage one), verifySeeded (against the pool and REFERENCE_IMD_ETH_WEI), runVault (stage two), verify, deploy/mainnet/plan.py and the pinned bodies. What can still be deployed wrong and pass, and what can happen between the two stages? Contract size: ParameterizedVault's initcode is 46,662 of 49,152 bytes.\n6. Every comment or NatSpec in src/ that claims a property the code does not have.\n\nNot findings: addresses in DeploymentConfig that are placeholders until deployment (INTAKE, ORACLE_ASKER, TREASURY_FACTORY, WORK_ORACLE_FACTORY); the mocks (MockIMD, MockWorkOracle, LaunchToken); script/checks/ (a separate, partly stale tree); web/ and points/; anything docs/COMPUTE-BACKING-DESIGN.md describes as future work; and findings of the earlier audits in docs/AUDIT-*.md and docs/INTERNAL-AUDIT-2026-10-04.md, unless the fix regressed. A constant set to a deliberate economic value is not a finding; an arithmetic or ordering error in how it is used is.\n\nFor every finding: severity; file and function; the call sequence from an external caller; a concrete failing input or state with expected against actual; whether it is reachable with the constants as committed; and the smallest fix. Also report every place a comment or NatSpec claims a property the code does not have, and say which contracts you read in full and which you could not reach.","baseCommit":"6085c8adb89d382b324c12b46ac22ba99a15c510","state":"completed","createdAt":"2026-10-08T09:40:55.826Z"}]},"deliver":false,"host":false,"site":null,"launch":{"requested":false,"kind":null,"id":null,"status":null,"chainId":null},"oracleRequestId":null,"delivery":null,"media":null,"nodes":[{"key":"audit_economics","role":"review","state":"accepted","attempt":1,"revisions":0,"judgeRevisions":0,"dependsOn":[],"allowedPaths":[],"failureReason":null,"dispatchNote":null,"dispatchNoteAt":null,"updatedAt":"2026-10-08T10:05:47.289Z","verdict":null,"seat":{"tokenId":"392","agentId":"52165"},"live":null},{"key":"audit_flow","role":"review","state":"accepted","attempt":1,"revisions":0,"judgeRevisions":0,"dependsOn":[],"allowedPaths":[],"failureReason":null,"dispatchNote":null,"dispatchNoteAt":null,"updatedAt":"2026-10-08T10:00:43.917Z","verdict":null,"seat":{"tokenId":"1357","agentId":"52169"},"live":null},{"key":"audit_judge","role":"review","state":"accepted","attempt":1,"revisions":0,"judgeRevisions":0,"dependsOn":["audit_math","audit_permissions","audit_economics","audit_flow"],"allowedPaths":[],"failureReason":null,"dispatchNote":null,"dispatchNoteAt":null,"updatedAt":"2026-10-08T10:26:56.475Z","verdict":null,"seat":{"tokenId":"1484","agentId":"51367"},"live":null},{"key":"audit_math","role":"review","state":"accepted","attempt":1,"revisions":0,"judgeRevisions":0,"dependsOn":[],"allowedPaths":[],"failureReason":null,"dispatchNote":null,"dispatchNoteAt":null,"updatedAt":"2026-10-08T10:11:33.033Z","verdict":null,"seat":{"tokenId":"11","agentId":"52173"},"live":null},{"key":"audit_permissions","role":"review","state":"accepted","attempt":1,"revisions":0,"judgeRevisions":0,"dependsOn":[],"allowedPaths":[],"failureReason":null,"dispatchNote":null,"dispatchNoteAt":null,"updatedAt":"2026-10-08T10:05:46.255Z","verdict":null,"seat":{"tokenId":"560","agentId":"52161"},"live":null}],"reviews":[{"status":"queued","chainId":1,"txHash":null,"blockNumber":null,"sentAt":null,"entries":[{"nodeKey":"audit_economics","agentId":"52165","value":1,"role":"review:submission"},{"nodeKey":"audit_flow","agentId":"52169","value":1,"role":"review:submission"},{"nodeKey":"audit_judge","agentId":"51367","value":1,"role":"review:submission"},{"nodeKey":"audit_math","agentId":"52173","value":1,"role":"review:submission"},{"nodeKey":"audit_permissions","agentId":"52161","value":1,"role":"review:submission"}]}]}