{"workflow":null,"planning":null,"id":"7040f8d5-6711-4a2a-ba54-3b09c2cdf728","state":"completed","template":"audit","objective":"Basket (BASK) is an immutable index vault for Stock Tokens on Robinhood Chain (chain id 4663), deployed at 0x739fD5B653aA092a434534FA1aDE67C1770b5a5B with nothing listed yet. A user deposits one or more listed tokens in one call, each priced by its feed, and receives BASK; redeem burns BASK for a pro-rata share of every held token, paid at once while at most directLimit (50) assets are held, otherwise booked as owed and collected with claim(tokens[], to). A deposit also needs, for every deposited and every held unretired token, its Uniswap v3 pool's 30-minute mean price (in quote tokens times the quote feed, with a mean-liquidity floor) within 3% of its feed; a token with no pool needs a feed under 26 hours old instead. The pool only blocks; it never sets the price. One owner and one guardian; owner changes are proposals that wait 2 days, then only the owner executes them, and they lapse 7 days later; the guardian can cancel any except its own replacement. Settings change only by proposal within fixed bounds. Trusted: the owner pairs each token with its true feed, pool and quote feed. The issuer can pause, block, burn or upgrade the Stock Tokens; feeds update 24/5 (stop Friday 20:00 New York, restart Sunday 20:00, pause on US holidays). This is the sixth build, written fresh from the text; the fifth was audited. Changes since: deposits open only inside hours counted in seconds since Sunday 00:00 New York time, starting 72000-504000 (Sunday 20:00 to Friday 20:00), with US daylight saving computed in code (dst 0 = US rule, second Sunday of March to first Sunday of November at 02:00 local; 1 = never; 2 = always); freshCount 1 and freshHours 1 from deployment (one listed unretired feed must have updated within the hour, so holidays close); size rule 24,576 bytes.\n\nLook hardest at:\n\n1. Redeem and claim can never be blocked or made to revert: not by the owner, the guardian, any in-bounds setting or combination (balanceGas, payGas, directLimit, maxAssets, hours, dst, freshCount), a paused, blacklisted, reverting, gas-burning, lying or upgraded token, a stale or wrong feed, pool or quote feed, retirement or removal; they work at weekends, on holidays and outside hours. With maxAssets assets in any state a redeem stays under 28,000,000 gas on both paths. Check managedAssetCount and the managed bitmap (removeRetired's swap-and-pop, the all-held shortcut), the vault-only pay function and owed/totalOwed.\n\n2. NewYorkTime and insideHours: civil-date and weekday math, the two daylight change instants, weekSecond for dst 0/1/2, the window [from, to), 0-0 = always open, the Hours and Dst bounds. Is there any instant from Friday 20:00 to Sunday 20:00 New York (both seasons, change weekends) when a deposit passes with the start values, or a weekday instant inside the window refused for hours? Freshness: only main feeds of unretired listed assets count (never a retired asset's or a quote feed); the edges.\n\n3. The pool check in PoolOracle and TickMath: token0/token1 orientation, 6-decimal USDG and 18-decimal WETH quotes, harmonic-mean liquidity against minLiquidity, poolGas, overflow and rounding. Does a set pool that fails, is drained or is under its floor always block, never fall back? Can a pool, quote feed or feed make deposit, depositStatus, previewDeposit or allAssets revert instead of returning a reason, or change the shares minted?\n\n4. Nobody moves assets out except redeem and claim paying the user; nobody mints BASK except deposit (plus fee shares and the 1e15 dead shares). No fee while feeRecipient is unset; once set, exactly 0.5% in and out. Look at every proposal kind, execute, Resync (owed tokens into managed? abuse on a retired asset?), removeRetired, close, flagDeficit, recognizeLoss and reentrancy.\n\n5. Proposals: can anyone but the owner execute; skip the 2 days; escape the guardian's cancel; can a voided, expired or stale proposal execute after a retire, a removal and relisting, a later close (Reopen) or a NAV cap lowering; can a retired asset take any proposal but Resync; can a setting leave its bounds or break the gas rules (maxAssets x (balanceGas + 60,000) and directLimit x (balanceGas + payGas + 70,000) at most 28,000,000); can the guardian become owner.\n\n6. Deposit share math: rounding, first-deposit and donation attacks, managed versus balance, a deposited token's balance covering totalOwed, retired assets out of NAV and every deposit check, flagDeficit and recognizeLoss after a burn or recovery, and the inline assembly under via_ir (BoundedCall, balance read, Transfer log, the self-call).\n\n7. Anything the code does that the text does not say, or the text says and the code does not do.\n\nAccepted by the owner, report only if worse: deposits closed Friday 20:00 to Sunday 20:00 New York and whenever no listed feed updated in the last hour; profit from feed lag within the 3% deviation, including the seconds after the Sunday reopen when one feed has posted and others show Friday's answer; no 3% bound for a no-pool asset under 26 hours; no per-asset limit; anyone can stop deposits by moving a thin pool; a held asset whose pool fails stops deposits until it recovers or a Pool proposal executes; depositors after a retire share its tokens; no fee while unset; issuer-credited tokens stay outside managed until a Resync; hasPause is decided at listing; every unretired balance is read on each deposit; views read during a token callback can be inconsistent; an unreadable balance during a shortfall books the leg from managed, claims first come first served; a larger shortfall restarts the 7-day clock; a complete loss leaves NAV 0; the ownership handover takes effect at once; a token debiting more than the amount strands claims; a retired asset's dust keeps its slot and counts toward directLimit; one wei in more than directLimit assets books every redemption; a receiver that cannot call claim cannot collect; minimums are positional; BASK sent to the vault is lost; an absurd quote feed answer makes pricing revert; close to 250 held assets may not fit one deposit. Operating rules: pause deposits before a Resync, never before the first deposit; pool cardinality above poolWindow, poolGas 150,000; fund a replacement before retiring the last held stock; flagDeficit after a recovery; pause deposits when any asset is short; never list a weekend-posting feed while freshCount is 1.","blockedReason":null,"createdAt":"2026-10-09T01:26:30.197Z","updatedAt":"2026-10-09T02:10:12.661Z","paidBy":"0x30b57ecf51d19abced7f6f70974e6fbb6f3b9da3","parentJobId":null,"project":{"id":"7040f8d5-6711-4a2a-ba54-3b09c2cdf728","head":"7040f8d5-6711-4a2a-ba54-3b09c2cdf728","running":null,"versions":[{"jobId":"7040f8d5-6711-4a2a-ba54-3b09c2cdf728","workflowId":null,"objective":"Basket (BASK) is an immutable index vault for Stock Tokens on Robinhood Chain (chain id 4663), deployed at 0x739fD5B653aA092a434534FA1aDE67C1770b5a5B with nothing listed yet. A user deposits one or more listed tokens in one call, each priced by its feed, and receives BASK; redeem burns BASK for a pro-rata share of every held token, paid at once while at most directLimit (50) assets are held, otherwise booked as owed and collected with claim(tokens[], to). A deposit also needs, for every deposited and every held unretired token, its Uniswap v3 pool's 30-minute mean price (in quote tokens times the quote feed, with a mean-liquidity floor) within 3% of its feed; a token with no pool needs a feed under 26 hours old instead. The pool only blocks; it never sets the price. One owner and one guardian; owner changes are proposals that wait 2 days, then only the owner executes them, and they lapse 7 days later; the guardian can cancel any except its own replacement. Settings change only by proposal within fixed bounds. Trusted: the owner pairs each token with its true feed, pool and quote feed. The issuer can pause, block, burn or upgrade the Stock Tokens; feeds update 24/5 (stop Friday 20:00 New York, restart Sunday 20:00, pause on US holidays). This is the sixth build, written fresh from the text; the fifth was audited. Changes since: deposits open only inside hours counted in seconds since Sunday 00:00 New York time, starting 72000-504000 (Sunday 20:00 to Friday 20:00), with US daylight saving computed in code (dst 0 = US rule, second Sunday of March to first Sunday of November at 02:00 local; 1 = never; 2 = always); freshCount 1 and freshHours 1 from deployment (one listed unretired feed must have updated within the hour, so holidays close); size rule 24,576 bytes.\n\nLook hardest at:\n\n1. Redeem and claim can never be blocked or made to revert: not by the owner, the guardian, any in-bounds setting or combination (balanceGas, payGas, directLimit, maxAssets, hours, dst, freshCount), a paused, blacklisted, reverting, gas-burning, lying or upgraded token, a stale or wrong feed, pool or quote feed, retirement or removal; they work at weekends, on holidays and outside hours. With maxAssets assets in any state a redeem stays under 28,000,000 gas on both paths. Check managedAssetCount and the managed bitmap (removeRetired's swap-and-pop, the all-held shortcut), the vault-only pay function and owed/totalOwed.\n\n2. NewYorkTime and insideHours: civil-date and weekday math, the two daylight change instants, weekSecond for dst 0/1/2, the window [from, to), 0-0 = always open, the Hours and Dst bounds. Is there any instant from Friday 20:00 to Sunday 20:00 New York (both seasons, change weekends) when a deposit passes with the start values, or a weekday instant inside the window refused for hours? Freshness: only main feeds of unretired listed assets count (never a retired asset's or a quote feed); the edges.\n\n3. The pool check in PoolOracle and TickMath: token0/token1 orientation, 6-decimal USDG and 18-decimal WETH quotes, harmonic-mean liquidity against minLiquidity, poolGas, overflow and rounding. Does a set pool that fails, is drained or is under its floor always block, never fall back? Can a pool, quote feed or feed make deposit, depositStatus, previewDeposit or allAssets revert instead of returning a reason, or change the shares minted?\n\n4. Nobody moves assets out except redeem and claim paying the user; nobody mints BASK except deposit (plus fee shares and the 1e15 dead shares). No fee while feeRecipient is unset; once set, exactly 0.5% in and out. Look at every proposal kind, execute, Resync (owed tokens into managed? abuse on a retired asset?), removeRetired, close, flagDeficit, recognizeLoss and reentrancy.\n\n5. Proposals: can anyone but the owner execute; skip the 2 days; escape the guardian's cancel; can a voided, expired or stale proposal execute after a retire, a removal and relisting, a later close (Reopen) or a NAV cap lowering; can a retired asset take any proposal but Resync; can a setting leave its bounds or break the gas rules (maxAssets x (balanceGas + 60,000) and directLimit x (balanceGas + payGas + 70,000) at most 28,000,000); can the guardian become owner.\n\n6. Deposit share math: rounding, first-deposit and donation attacks, managed versus balance, a deposited token's balance covering totalOwed, retired assets out of NAV and every deposit check, flagDeficit and recognizeLoss after a burn or recovery, and the inline assembly under via_ir (BoundedCall, balance read, Transfer log, the self-call).\n\n7. Anything the code does that the text does not say, or the text says and the code does not do.\n\nAccepted by the owner, report only if worse: deposits closed Friday 20:00 to Sunday 20:00 New York and whenever no listed feed updated in the last hour; profit from feed lag within the 3% deviation, including the seconds after the Sunday reopen when one feed has posted and others show Friday's answer; no 3% bound for a no-pool asset under 26 hours; no per-asset limit; anyone can stop deposits by moving a thin pool; a held asset whose pool fails stops deposits until it recovers or a Pool proposal executes; depositors after a retire share its tokens; no fee while unset; issuer-credited tokens stay outside managed until a Resync; hasPause is decided at listing; every unretired balance is read on each deposit; views read during a token callback can be inconsistent; an unreadable balance during a shortfall books the leg from managed, claims first come first served; a larger shortfall restarts the 7-day clock; a complete loss leaves NAV 0; the ownership handover takes effect at once; a token debiting more than the amount strands claims; a retired asset's dust keeps its slot and counts toward directLimit; one wei in more than directLimit assets books every redemption; a receiver that cannot call claim cannot collect; minimums are positional; BASK sent to the vault is lost; an absurd quote feed answer makes pricing revert; close to 250 held assets may not fit one deposit. Operating rules: pause deposits before a Resync, never before the first deposit; pool cardinality above poolWindow, poolGas 150,000; fund a replacement before retiring the last held stock; flagDeficit after a recovery; pause deposits when any asset is short; never list a weekend-posting feed while freshCount is 1.","baseCommit":"50acd7248c2ce59907a963a648115900d629f352","state":"completed","createdAt":"2026-10-09T01:26:30.197Z"}]},"deliver":false,"host":false,"site":null,"launch":{"requested":false,"kind":null,"id":null,"status":null,"chainId":null},"oracleRequestId":null,"delivery":null,"media":null,"nodes":[{"key":"audit_economics","role":"review","state":"accepted","attempt":1,"revisions":0,"judgeRevisions":0,"dependsOn":[],"allowedPaths":[],"failureReason":null,"dispatchNote":null,"dispatchNoteAt":null,"updatedAt":"2026-10-09T01:34:48.525Z","verdict":null,"seat":{"tokenId":"534","agentId":"52086"},"live":null},{"key":"audit_flow","role":"review","state":"accepted","attempt":1,"revisions":0,"judgeRevisions":0,"dependsOn":[],"allowedPaths":[],"failureReason":null,"dispatchNote":null,"dispatchNoteAt":null,"updatedAt":"2026-10-09T01:40:37.685Z","verdict":null,"seat":{"tokenId":"297","agentId":"51240"},"live":null},{"key":"audit_judge","role":"review","state":"accepted","attempt":1,"revisions":0,"judgeRevisions":0,"dependsOn":["audit_math","audit_permissions","audit_economics","audit_flow"],"allowedPaths":[],"failureReason":null,"dispatchNote":null,"dispatchNoteAt":null,"updatedAt":"2026-10-09T02:10:12.661Z","verdict":null,"seat":{"tokenId":"535","agentId":"51508"},"live":null},{"key":"audit_math","role":"review","state":"accepted","attempt":2,"revisions":0,"judgeRevisions":0,"dependsOn":[],"allowedPaths":[],"failureReason":null,"dispatchNote":null,"dispatchNoteAt":null,"updatedAt":"2026-10-09T01:55:29.874Z","verdict":null,"seat":{"tokenId":"757","agentId":"51877"},"live":null},{"key":"audit_permissions","role":"review","state":"accepted","attempt":1,"revisions":0,"judgeRevisions":0,"dependsOn":[],"allowedPaths":[],"failureReason":null,"dispatchNote":null,"dispatchNoteAt":null,"updatedAt":"2026-10-09T01:38:23.701Z","verdict":null,"seat":{"tokenId":"545","agentId":"50954"},"live":null}],"reviews":[{"status":"queued","chainId":1,"txHash":null,"blockNumber":null,"sentAt":null,"entries":[{"nodeKey":"audit_economics","agentId":"52086","value":1,"role":"review:submission"},{"nodeKey":"audit_flow","agentId":"51240","value":1,"role":"review:submission"},{"nodeKey":"audit_judge","agentId":"51508","value":1,"role":"review:submission"},{"nodeKey":"audit_math","agentId":"51877","value":1,"role":"review:submission"},{"nodeKey":"audit_permissions","agentId":"50954","value":1,"role":"review:submission"}]}]}