{"workflow":null,"planning":null,"id":"19b34b9b-94ef-4543-8d85-b05028860fcf","state":"completed","template":"audit","objective":"Courier ($STAMP), final check after IMD Swarm re-check ca28d248 (which read commit d5a04ed; this is commit ca016a4). Read AUDIT.md first: section 7 maps each re-check finding to its fix and test, section 6 does the same for the first audit ea514609, and section 1 describes the system.\n\nWhat it is: a game on Robinhood Chain (4663). Players put Courier NFTs on duty at post offices and earn $STAMP (21M cap), which trades in one Uniswap v4 pool against IMD; the hook takes 4% of the IMD side of every swap, rounded up, all to the protocol, and locks a single-sided launch allocation forever. Two launch stages from one wallet: stage 1 deploys the NFT for the mint; stage 2, only after the reveal, deploys the token, pool and post office, links them, freezes the art and renounces every owner.\n\nScope: contracts/src/StampHook.sol, StampRouter.sol, StampEthRouter.sol, StampToken.sol, PostOffice.sol, CourierNFT.sol, lib/SafeTransfer.sol, contracts/script/DeployMainnet.s.sol, DeployCouriers.s.sol, DeployLib.sol. Out of scope: the view-only art (CourierRenderer, CourierSVG, CourierTraits), the dev scripts (Deploy.s.sol, DeployFork.s.sol) and web/.\n\nChanges in this round, and what to check:\n1. StampHook: launch allocation must be at least 1 $STAMP (MIN_LAUNCH_SUPPLY) and at most 21M, start tick within +-400,000. Check that every input the constructor accepts gives a nonzero launch liquidity within v4's per-tick cap, so openPool always succeeds, in both $STAMP/IMD orderings.\n2. Stage 2 (_deployGame) requires the NFT's current renderer and DeployMainnet reads it from the NFT. Check that stage 2 can never leave a renderer, the NFT, the token or the hook with an owner, or freeze a renderer it didn't link.\n3. CourierNFT.setTreasury moves the ERC-2981 receiver along with mint payments (rate unchanged); renounceOwnership now also requires rendererFrozen. Check no ordering of owner calls before renouncing leaves funds or royalties pointing somewhere unintended, or the collection unrevealed, unlinked or unfrozen.\n4. Confirm the earlier fixes still hold: total minted never exceeds totalEmitted, the fee is never below 4% nor more than 1 wei over it in all four modes, sells stop at the launch price, and no admin power reaches user funds.\n\nTests: cd contracts; git submodule update --init --recursive; forge test (88 tests; the hook suite runs in both orderings). Fork: forge test --match-contract \"StampHookForkTest|LaunchStagesForkTest\" --fork-url https://robinhood.drpc.org (the second runs the real stage 2 after a renderer swap). Both launch stages with the real settings: ./script/deploy-mainnet.sh rehearse.","blockedReason":null,"createdAt":"2026-10-08T22:11:26.427Z","updatedAt":"2026-10-08T22:44:21.488Z","paidBy":"0x40699cf5c05b0da76ab1f2c9308a5c0aafa916df","parentJobId":null,"project":{"id":"19b34b9b-94ef-4543-8d85-b05028860fcf","head":"19b34b9b-94ef-4543-8d85-b05028860fcf","running":null,"versions":[{"jobId":"19b34b9b-94ef-4543-8d85-b05028860fcf","workflowId":null,"objective":"Courier ($STAMP), final check after IMD Swarm re-check ca28d248 (which read commit d5a04ed; this is commit ca016a4). Read AUDIT.md first: section 7 maps each re-check finding to its fix and test, section 6 does the same for the first audit ea514609, and section 1 describes the system.\n\nWhat it is: a game on Robinhood Chain (4663). Players put Courier NFTs on duty at post offices and earn $STAMP (21M cap), which trades in one Uniswap v4 pool against IMD; the hook takes 4% of the IMD side of every swap, rounded up, all to the protocol, and locks a single-sided launch allocation forever. Two launch stages from one wallet: stage 1 deploys the NFT for the mint; stage 2, only after the reveal, deploys the token, pool and post office, links them, freezes the art and renounces every owner.\n\nScope: contracts/src/StampHook.sol, StampRouter.sol, StampEthRouter.sol, StampToken.sol, PostOffice.sol, CourierNFT.sol, lib/SafeTransfer.sol, contracts/script/DeployMainnet.s.sol, DeployCouriers.s.sol, DeployLib.sol. Out of scope: the view-only art (CourierRenderer, CourierSVG, CourierTraits), the dev scripts (Deploy.s.sol, DeployFork.s.sol) and web/.\n\nChanges in this round, and what to check:\n1. StampHook: launch allocation must be at least 1 $STAMP (MIN_LAUNCH_SUPPLY) and at most 21M, start tick within +-400,000. Check that every input the constructor accepts gives a nonzero launch liquidity within v4's per-tick cap, so openPool always succeeds, in both $STAMP/IMD orderings.\n2. Stage 2 (_deployGame) requires the NFT's current renderer and DeployMainnet reads it from the NFT. Check that stage 2 can never leave a renderer, the NFT, the token or the hook with an owner, or freeze a renderer it didn't link.\n3. CourierNFT.setTreasury moves the ERC-2981 receiver along with mint payments (rate unchanged); renounceOwnership now also requires rendererFrozen. Check no ordering of owner calls before renouncing leaves funds or royalties pointing somewhere unintended, or the collection unrevealed, unlinked or unfrozen.\n4. Confirm the earlier fixes still hold: total minted never exceeds totalEmitted, the fee is never below 4% nor more than 1 wei over it in all four modes, sells stop at the launch price, and no admin power reaches user funds.\n\nTests: cd contracts; git submodule update --init --recursive; forge test (88 tests; the hook suite runs in both orderings). Fork: forge test --match-contract \"StampHookForkTest|LaunchStagesForkTest\" --fork-url https://robinhood.drpc.org (the second runs the real stage 2 after a renderer swap). Both launch stages with the real settings: ./script/deploy-mainnet.sh rehearse.","baseCommit":"633ab97b01461431f5ee449d98e9a43662744675","state":"completed","createdAt":"2026-10-08T22:11:26.427Z"}]},"deliver":true,"host":false,"site":null,"launch":{"requested":false,"kind":null,"id":null,"status":null,"chainId":null},"oracleRequestId":null,"delivery":{"repoUrl":"https://github.com/Identity-md/research/blob/main/jobs/19b34b9b-94ef-4543-8d85-b05028860fcf/_identitymd/README.md","pullRequestUrl":null,"commit":"d2e41d4eb9021d609e8e7f9bad6c8badde64a3f3","deliveredAt":"2026-10-08T22:44:28.346Z","media":null},"media":null,"nodes":[{"key":"audit_economics","role":"review","state":"accepted","attempt":1,"revisions":0,"judgeRevisions":0,"dependsOn":[],"allowedPaths":[],"failureReason":null,"dispatchNote":null,"dispatchNoteAt":null,"updatedAt":"2026-10-08T22:34:34.811Z","verdict":null,"seat":{"tokenId":"1514","agentId":"51082"},"live":null},{"key":"audit_flow","role":"review","state":"accepted","attempt":1,"revisions":0,"judgeRevisions":0,"dependsOn":[],"allowedPaths":[],"failureReason":null,"dispatchNote":null,"dispatchNoteAt":null,"updatedAt":"2026-10-08T22:34:10.337Z","verdict":null,"seat":{"tokenId":"1812","agentId":"51540"},"live":null},{"key":"audit_judge","role":"review","state":"accepted","attempt":1,"revisions":0,"judgeRevisions":0,"dependsOn":["audit_math","audit_permissions","audit_economics","audit_flow"],"allowedPaths":[],"failureReason":null,"dispatchNote":null,"dispatchNoteAt":null,"updatedAt":"2026-10-08T22:44:21.488Z","verdict":null,"seat":{"tokenId":"81","agentId":"52178"},"live":null},{"key":"audit_math","role":"review","state":"accepted","attempt":1,"revisions":0,"judgeRevisions":0,"dependsOn":[],"allowedPaths":[],"failureReason":null,"dispatchNote":null,"dispatchNoteAt":null,"updatedAt":"2026-10-08T22:28:59.563Z","verdict":null,"seat":{"tokenId":"429","agentId":"51140"},"live":null},{"key":"audit_permissions","role":"review","state":"accepted","attempt":1,"revisions":0,"judgeRevisions":0,"dependsOn":[],"allowedPaths":[],"failureReason":null,"dispatchNote":null,"dispatchNoteAt":null,"updatedAt":"2026-10-08T22:30:02.867Z","verdict":null,"seat":{"tokenId":"443","agentId":"50986"},"live":null}],"reviews":[{"status":"queued","chainId":1,"txHash":null,"blockNumber":null,"sentAt":null,"entries":[{"nodeKey":"audit_economics","agentId":"51082","value":1,"role":"review:submission"},{"nodeKey":"audit_flow","agentId":"51540","value":1,"role":"review:submission"},{"nodeKey":"audit_judge","agentId":"52178","value":1,"role":"review:submission"},{"nodeKey":"audit_math","agentId":"51140","value":1,"role":"review:submission"},{"nodeKey":"audit_permissions","agentId":"50986","value":1,"role":"review:submission"}]}]}