{"workflow":null,"planning":null,"id":"43b96259-a6e0-4bca-b04f-0308a7943b8b","state":"completed","template":"audit","objective":"Audit the vault: src/CDPVault.sol, src/ParameterizedVault.sol and src/ImdUSD.sol, at the pinned commit, for a mainnet launch. Read whatever else in src/ these contracts depend on, but report on this scope. Four audit rounds and their fixes are already in (docs/AUDIT-*.md; the newest are docs/AUDIT-FINAL-PANEL-VAULT/GOVERNANCE/ORACLE-2026-10-07.md, fixed in 8756817: git show 8756817). This is the last sweep before the deployment commit is frozen, so it audits the code as it will deploy; a finding of an earlier round counts only if its fix regressed or left a gap. Spend turns on breaking the newest fixes first.\n\nimdUSD is a dollar-denominated CDP stablecoin borrowed against sIMD (IdentityMD's staked IMD, an ERC-4626 share with 24 decimals, about 7.95 IMD each). Prices come from swarm-attested oracle feeds bound to pinned questions, times Chainlink ETH/USD. Everything about the deployment is in src/DeploymentConfig.sol and docs/MAINNET-RUNBOOK.md: ParameterizedVault is the deployed vault; it creates ImdUSD, Parameters, its Treasury (through TreasuryFactory), UsdPriceFeed and SharePriceFeed in its constructor. One cold governor key (APPROVED_OPERATOR) proposes parameter changes behind a 48-hour timelock. Collateral pricing is per 1e18 raw units throughout. IMD's only market is a full-range Uniswap v4 pool, about $2.3M a side with a 1% fee; docs/PARAMETERS-2026-10-05.md has the numbers every economic parameter was chosen from.\n\nAnswer each numbered question, including the ones where nothing is wrong:\n1. The lag (laggedDebt, laggedSecured, _advanceLag, _approach, BACKING_WARMUP) and its per-transaction netting (_clampLag, _lagAtStart, the two transient slots): can any sequence within one transaction raise the lagged figures above where the transaction found them, or keep them from falling when capital really leaves? Across transactions a decrease still counts at once: is there a cheap way to use that to drive backingPerUnit down (a dominant borrower's wipe then draw in the next transaction), and what does it cost and block?\n2. The earn gate (_earnOpen: wage != 0 in ParameterizedVault, the same switch as _lagApplies) and the D1 round trip (borrow / earn / unwind across adjacent transactions): is there any state in which earn mints with the lag off, or in which a rights holder can block a governed oracle replacement?\n3. cover: the ungated sweep of collateral below the one-wei seizure at the LAST price (_priceOrZero, possibly stale), the gated sweep of dust (_coverDust) or of collateral worth less than the recorded bad debt. Can cover take collateral that could make the debt good, can a borrower lose value it should keep, or can a drained borrower still keep cover off cheaply?\n4. _resecure with an unreadable price (the term kept, at most the collateral, zero with no debt): can a dead leg overstate securedCollateral in a way a redeemer or a work mint can use before the next priced checkpoint?\n5. The fresh-debt record in 1e18-scaled seconds (draw, _reduceDebt, _recentlyMinted, cash's freshCancelled): is principal-time conserved through every draw/wipe/redemption/liquidation sequence, and can any sequence keep seasoned principal fresh or age fresh principal early?\n6. Positions, liquidation (bark, barkFor, bite, heel, tail, lull, the mark's expiry), redemption (fee base, candidate eligibility mat + gap, the backingPerUnit cap), bad debt (totalBadDebt and the per-position record across wipe, cover, bite, cash), stability fee (duty, chi, drip). Anything a caller can receive beyond the formula, freeze, or desynchronise.\n7. Price gating and arithmetic: every value-moving action refused on stale or divergent feeds, the exceptions (lock, wipe, debt-free free, the ungated cover sweep) safe; overflow at extreme collateral or price, rounding direction in every payout, units where a price, a 24-decimal amount and basis points meet.\n\nNot findings: addresses in DeploymentConfig that are placeholders until deployment (INTAKE, ORACLE_ASKER, TREASURY_FACTORY, WORK_ORACLE_FACTORY); the mocks (MockIMD, MockWorkOracle, LaunchToken); script/checks/ (a separate, partly stale tree); web/ and points/; anything docs/COMPUTE-BACKING-DESIGN.md describes as future work; and findings of the earlier audits in docs/AUDIT-*.md and docs/INTERNAL-AUDIT-2026-10-04.md, unless the fix regressed. A constant set to a deliberate economic value is not a finding; an arithmetic or ordering error in how it is used is.\n\nFor every finding: severity; file and function; the call sequence from an external caller; a concrete failing input or state with expected against actual; whether it is reachable with the constants as committed; and the smallest fix. Also report every place a comment or NatSpec claims a property the code does not have, and say which contracts you read in full and which you could not reach.","blockedReason":null,"createdAt":"2026-10-07T20:32:01.564Z","updatedAt":"2026-10-07T21:59:39.766Z","paidBy":"0x5167d014a056e43883e1bbea5530c3c0dc993281","parentJobId":null,"project":{"id":"43b96259-a6e0-4bca-b04f-0308a7943b8b","head":"43b96259-a6e0-4bca-b04f-0308a7943b8b","running":null,"versions":[{"jobId":"43b96259-a6e0-4bca-b04f-0308a7943b8b","workflowId":null,"objective":"Audit the vault: src/CDPVault.sol, src/ParameterizedVault.sol and src/ImdUSD.sol, at the pinned commit, for a mainnet launch. Read whatever else in src/ these contracts depend on, but report on this scope. Four audit rounds and their fixes are already in (docs/AUDIT-*.md; the newest are docs/AUDIT-FINAL-PANEL-VAULT/GOVERNANCE/ORACLE-2026-10-07.md, fixed in 8756817: git show 8756817). This is the last sweep before the deployment commit is frozen, so it audits the code as it will deploy; a finding of an earlier round counts only if its fix regressed or left a gap. Spend turns on breaking the newest fixes first.\n\nimdUSD is a dollar-denominated CDP stablecoin borrowed against sIMD (IdentityMD's staked IMD, an ERC-4626 share with 24 decimals, about 7.95 IMD each). Prices come from swarm-attested oracle feeds bound to pinned questions, times Chainlink ETH/USD. Everything about the deployment is in src/DeploymentConfig.sol and docs/MAINNET-RUNBOOK.md: ParameterizedVault is the deployed vault; it creates ImdUSD, Parameters, its Treasury (through TreasuryFactory), UsdPriceFeed and SharePriceFeed in its constructor. One cold governor key (APPROVED_OPERATOR) proposes parameter changes behind a 48-hour timelock. Collateral pricing is per 1e18 raw units throughout. IMD's only market is a full-range Uniswap v4 pool, about $2.3M a side with a 1% fee; docs/PARAMETERS-2026-10-05.md has the numbers every economic parameter was chosen from.\n\nAnswer each numbered question, including the ones where nothing is wrong:\n1. The lag (laggedDebt, laggedSecured, _advanceLag, _approach, BACKING_WARMUP) and its per-transaction netting (_clampLag, _lagAtStart, the two transient slots): can any sequence within one transaction raise the lagged figures above where the transaction found them, or keep them from falling when capital really leaves? Across transactions a decrease still counts at once: is there a cheap way to use that to drive backingPerUnit down (a dominant borrower's wipe then draw in the next transaction), and what does it cost and block?\n2. The earn gate (_earnOpen: wage != 0 in ParameterizedVault, the same switch as _lagApplies) and the D1 round trip (borrow / earn / unwind across adjacent transactions): is there any state in which earn mints with the lag off, or in which a rights holder can block a governed oracle replacement?\n3. cover: the ungated sweep of collateral below the one-wei seizure at the LAST price (_priceOrZero, possibly stale), the gated sweep of dust (_coverDust) or of collateral worth less than the recorded bad debt. Can cover take collateral that could make the debt good, can a borrower lose value it should keep, or can a drained borrower still keep cover off cheaply?\n4. _resecure with an unreadable price (the term kept, at most the collateral, zero with no debt): can a dead leg overstate securedCollateral in a way a redeemer or a work mint can use before the next priced checkpoint?\n5. The fresh-debt record in 1e18-scaled seconds (draw, _reduceDebt, _recentlyMinted, cash's freshCancelled): is principal-time conserved through every draw/wipe/redemption/liquidation sequence, and can any sequence keep seasoned principal fresh or age fresh principal early?\n6. Positions, liquidation (bark, barkFor, bite, heel, tail, lull, the mark's expiry), redemption (fee base, candidate eligibility mat + gap, the backingPerUnit cap), bad debt (totalBadDebt and the per-position record across wipe, cover, bite, cash), stability fee (duty, chi, drip). Anything a caller can receive beyond the formula, freeze, or desynchronise.\n7. Price gating and arithmetic: every value-moving action refused on stale or divergent feeds, the exceptions (lock, wipe, debt-free free, the ungated cover sweep) safe; overflow at extreme collateral or price, rounding direction in every payout, units where a price, a 24-decimal amount and basis points meet.\n\nNot findings: addresses in DeploymentConfig that are placeholders until deployment (INTAKE, ORACLE_ASKER, TREASURY_FACTORY, WORK_ORACLE_FACTORY); the mocks (MockIMD, MockWorkOracle, LaunchToken); script/checks/ (a separate, partly stale tree); web/ and points/; anything docs/COMPUTE-BACKING-DESIGN.md describes as future work; and findings of the earlier audits in docs/AUDIT-*.md and docs/INTERNAL-AUDIT-2026-10-04.md, unless the fix regressed. A constant set to a deliberate economic value is not a finding; an arithmetic or ordering error in how it is used is.\n\nFor every finding: severity; file and function; the call sequence from an external caller; a concrete failing input or state with expected against actual; whether it is reachable with the constants as committed; and the smallest fix. Also report every place a comment or NatSpec claims a property the code does not have, and say which contracts you read in full and which you could not reach.","baseCommit":"8756817e66e973b05ea08e2aa99ee627de225d09","state":"completed","createdAt":"2026-10-07T20:32:01.564Z"}]},"deliver":false,"host":false,"site":null,"launch":{"requested":false,"kind":null,"id":null,"status":null,"chainId":null},"oracleRequestId":null,"delivery":null,"media":null,"nodes":[{"key":"audit_economics","role":"review","state":"accepted","attempt":1,"revisions":0,"judgeRevisions":0,"dependsOn":[],"allowedPaths":[],"failureReason":null,"dispatchNote":null,"dispatchNoteAt":null,"updatedAt":"2026-10-07T21:14:12.251Z","verdict":null,"seat":{"tokenId":"154","agentId":"52017"},"live":null},{"key":"audit_flow","role":"review","state":"accepted","attempt":1,"revisions":0,"judgeRevisions":0,"dependsOn":[],"allowedPaths":[],"failureReason":null,"dispatchNote":null,"dispatchNoteAt":null,"updatedAt":"2026-10-07T20:55:38.523Z","verdict":null,"seat":{"tokenId":"368","agentId":"51891"},"live":null},{"key":"audit_judge","role":"review","state":"accepted","attempt":1,"revisions":0,"judgeRevisions":0,"dependsOn":["audit_math","audit_permissions","audit_economics","audit_flow"],"allowedPaths":[],"failureReason":null,"dispatchNote":null,"dispatchNoteAt":null,"updatedAt":"2026-10-07T21:59:39.766Z","verdict":null,"seat":{"tokenId":"351","agentId":"51023"},"live":null},{"key":"audit_math","role":"review","state":"accepted","attempt":1,"revisions":0,"judgeRevisions":0,"dependsOn":[],"allowedPaths":[],"failureReason":null,"dispatchNote":null,"dispatchNoteAt":null,"updatedAt":"2026-10-07T20:59:50.438Z","verdict":null,"seat":{"tokenId":"470","agentId":"51216"},"live":null},{"key":"audit_permissions","role":"review","state":"accepted","attempt":1,"revisions":0,"judgeRevisions":0,"dependsOn":[],"allowedPaths":[],"failureReason":null,"dispatchNote":null,"dispatchNoteAt":null,"updatedAt":"2026-10-07T21:48:55.698Z","verdict":null,"seat":{"tokenId":"1188","agentId":"52019"},"live":null}],"reviews":[{"status":"queued","chainId":1,"txHash":null,"blockNumber":null,"sentAt":null,"entries":[{"nodeKey":"audit_economics","agentId":"52017","value":1,"role":"review:submission"},{"nodeKey":"audit_flow","agentId":"51891","value":1,"role":"review:submission"},{"nodeKey":"audit_judge","agentId":"51023","value":1,"role":"review:submission"},{"nodeKey":"audit_math","agentId":"51216","value":1,"role":"review:submission"},{"nodeKey":"audit_permissions","agentId":"52019","value":1,"role":"review:submission"}]}]}