{"workflow":null,"planning":null,"id":"dc27aade-6adb-40da-b6d8-0bddfe280ebf","state":"completed","template":"audit","objective":"Audit the vault: src/CDPVault.sol, src/ParameterizedVault.sol and src/ImdUSD.sol, in full, at the pinned commit, for a mainnet launch. Read whatever else in src/ these depend on, but report on this scope. Thirteen audit rounds and their fixes are in (docs/AUDIT-*.md; the chain is web/content/docs/reference/audit-history.md). The newest, docs/AUDIT-LAUNCH-VAULT-PANEL-2026-10-08.md if present, else the launch vault panel (job 5383ced0 at 9bd5f59: a high and two mediums in the per-position lag's latest repair), ended that lag: this commit replaces it with three PACED figures (CDPVault._pace and the NatSpec at BACKING_RISE_PER_HOUR), the one mechanism no panel has read. Read the vault in full, as it will deploy; the pacing is the newest code and the place to break first. A finding of an earlier round counts only if its fix regressed or left a gap. Items ACCEPTED with their reasons stated where they live are findings only if the reason is wrong or the stated bound does not hold: the dip (a withdrawal paced in one transaction and reversed in the next, stated at the paced figures' NatSpec: below par only, bounded by the book without that position, recovering at the rise rate), the stale-term read after a price fall (retry2 #6, same NatSpec), the redemption-fee floor, and the work ceiling as an aggregate once the wage is on. Rank severity by what a finding lets someone take or block with the constants as committed (LINE $1M, wage 0, BACKING_RISE_PER_HOUR 2 points of par, FOLLOW_BPS_PER_HOUR 10%, PACE_INTERVAL 1 hour).\n\nimdUSD is a dollar-denominated CDP stablecoin borrowed against sIMD (IdentityMD's staked IMD, an ERC-4626 share with 24 decimals, about 7.95 IMD each). Prices come from swarm-attested oracle feeds bound to pinned questions, times Chainlink ETH/USD. Everything about the deployment is in src/DeploymentConfig.sol and docs/MAINNET-RUNBOOK.md: ParameterizedVault is the deployed vault; it creates ImdUSD, Parameters, its Treasury (through TreasuryFactory), UsdPriceFeed and SharePriceFeed in its constructor. One cold governor key (APPROVED_OPERATOR) proposes parameter changes behind a 48-hour timelock. Collateral pricing is per 1e18 raw units throughout. IMD's only market is a full-range Uniswap v4 pool, about $2.3M a side with a 1% fee; docs/PARAMETERS-2026-10-05.md has the numbers every economic parameter was chosen from.\n\nAnswer each numbered question, including the ones where nothing is wrong:\n1. THE PACED BACKING (CDPVault._pace, _pacedBacking, _liveBacking, _clampPacedDebt, _priceAgrees, PACED_THIS_TX_SLOT, pace()). A redemption is paid min(live, paced backing), the paced backing falls at once to the live figure and rises by at most BACKING_RISE_PER_HOUR for at most PACE_INTERVAL of elapsed time between pacings, written at a transaction's first capital-moving call from the state it found, and only at a fresh, agreed price. Search every sequence of lock, lockIMD, free, draw, wipe, cash, cover, bite, earn, pace, a Treasury donation and a feed update, by one account or several, in one transaction or across many, with and without a price move between them, for one that makes a redemption paid more than the honest backing of the book plus the rise the elapsed time allows, from the reserve or from a candidate; and quantify every way honest redeemers are paid LESS than the live figure (the dip, the stale-term read, a quiet spell, a feed outage), as a cost in points and hours, against the accepted statements.\n2. THE PACED SUPPLY AND THE FEE (_pacedSupply, _step, _feeBase floored at 100,000, _redemptionRate with prior read once, the stored base rate's decay, the fresh-debt record). The cheapest way to pin the cap for everyone and the cheapest way to dilute the fee, now; whether a draw, repayment, redemption, work mint or their ordering moves the base off the paced supply by more than FOLLOW_BPS_PER_HOUR an hour; the fee a launch-day redeemer pays while the paced supply is below the live one.\n3. THE PACED DEBT AND THE WORK CEILING (_pacedDebt, _clampPacedDebt, WIPED_THIS_TX_SLOT, ParameterizedVault.backedDebt and earnLine, _debtAtTransactionStart) with WAGE_WAD 0 at launch (earn refused) and once governance turns the wage on: any way debt cancelled by cash, bite or cover and drawn again by anyone backs work minting sooner than the follow rate allows; whether a borrower's own wipe and redraw, in one transaction or across two, moves the ceiling; the cost of the aggregate (the ceiling tracks totals, not whose debt) once the wage is on.\n4. REDEMPTION PAYOUTS: cash's routes (reserve, candidate, mixed), candidate eligibility (mat + gap), RedemptionWorsensRatio, ExcessRepayment, minGemOut, the reserve valued at the vault's price, the transient tallies (MINTED, SECURED, REPAID, WORK_MINTED, WIPED, PACED this transaction) and the saturating arithmetic in _liveBacking and _securedCollateralValue. Can a redeemer pay less than the fee for its size, worsen a candidate, or take reserve beyond its share?\n5. LIQUIDATION AND BAD DEBT: bark, barkFor, bite (always marked: grace from lull, then a tail-long window), heel, the chip/cut split at CHOP_PERCENT 20, the dust seizure, cover (a re-lock below recorded bad debt taken at its value, CoverBelowCollateralValue, _coverDust) and totalBadDebt against the per-position record; and what each does to the paced figures. Can anyone take more than the formula, freeze a position unliquidatable, hold cover off cheaply, or desynchronise the bad-debt record?\n6. POSITIONS AND PRICING: lock, lockIMD (shares credited by balance delta), free, draw, wipe; the stability fee (duty, chi, drip, checkpoints); price gating (_requireFreshFeeds, _requirePriceAgreement, the ungated lock, wipe and debt-free free, which now pace, and the unreadable-price path in _resecureBounded). Below mat, double counting, reentrancy through the share vault, acting on a stale or divergent price, and whether pacing inside the ungated calls can ever revert them or write a figure from a bad price.\n7. ARITHMETIC, GAS AND SIZE: overflow at extreme collateral, price or elapsed time, rounding direction in every division that pays someone, units where a price, a 24-decimal amount and basis points meet; the gas pacing adds to lock and free; ParameterizedVault initcode 46,987 of 49,152 bytes.\n8. Every comment or NatSpec in these files that claims a property the code does not have, the paced figures' NatSpec first.\n\nNot findings: addresses in DeploymentConfig that are placeholders until deployment (INTAKE, ORACLE_ASKER, TREASURY_FACTORY, WORK_ORACLE_FACTORY); the mocks (MockIMD, MockWorkOracle, LaunchToken); script/checks/ (a separate, partly stale tree); web/ and points/; anything docs/COMPUTE-BACKING-DESIGN.md describes as future work; and findings of the earlier audits in docs/AUDIT-*.md and docs/INTERNAL-AUDIT-2026-10-04.md, unless the fix regressed. A constant set to a deliberate economic value is not a finding; an arithmetic or ordering error in how it is used is.\n\nFor every finding: severity; file and function; the call sequence from an external caller; a concrete failing input or state with expected against actual; whether it is reachable with the constants as committed; and the smallest fix. Also report every place a comment or NatSpec claims a property the code does not have, and say which contracts you read in full and which you could not reach.","blockedReason":null,"createdAt":"2026-10-09T02:34:10.700Z","updatedAt":"2026-10-09T03:25:44.108Z","paidBy":"0x5167d014a056e43883e1bbea5530c3c0dc993281","parentJobId":null,"project":{"id":"dc27aade-6adb-40da-b6d8-0bddfe280ebf","head":"dc27aade-6adb-40da-b6d8-0bddfe280ebf","running":null,"versions":[{"jobId":"dc27aade-6adb-40da-b6d8-0bddfe280ebf","workflowId":null,"objective":"Audit the vault: src/CDPVault.sol, src/ParameterizedVault.sol and src/ImdUSD.sol, in full, at the pinned commit, for a mainnet launch. Read whatever else in src/ these depend on, but report on this scope. Thirteen audit rounds and their fixes are in (docs/AUDIT-*.md; the chain is web/content/docs/reference/audit-history.md). The newest, docs/AUDIT-LAUNCH-VAULT-PANEL-2026-10-08.md if present, else the launch vault panel (job 5383ced0 at 9bd5f59: a high and two mediums in the per-position lag's latest repair), ended that lag: this commit replaces it with three PACED figures (CDPVault._pace and the NatSpec at BACKING_RISE_PER_HOUR), the one mechanism no panel has read. Read the vault in full, as it will deploy; the pacing is the newest code and the place to break first. A finding of an earlier round counts only if its fix regressed or left a gap. Items ACCEPTED with their reasons stated where they live are findings only if the reason is wrong or the stated bound does not hold: the dip (a withdrawal paced in one transaction and reversed in the next, stated at the paced figures' NatSpec: below par only, bounded by the book without that position, recovering at the rise rate), the stale-term read after a price fall (retry2 #6, same NatSpec), the redemption-fee floor, and the work ceiling as an aggregate once the wage is on. Rank severity by what a finding lets someone take or block with the constants as committed (LINE $1M, wage 0, BACKING_RISE_PER_HOUR 2 points of par, FOLLOW_BPS_PER_HOUR 10%, PACE_INTERVAL 1 hour).\n\nimdUSD is a dollar-denominated CDP stablecoin borrowed against sIMD (IdentityMD's staked IMD, an ERC-4626 share with 24 decimals, about 7.95 IMD each). Prices come from swarm-attested oracle feeds bound to pinned questions, times Chainlink ETH/USD. Everything about the deployment is in src/DeploymentConfig.sol and docs/MAINNET-RUNBOOK.md: ParameterizedVault is the deployed vault; it creates ImdUSD, Parameters, its Treasury (through TreasuryFactory), UsdPriceFeed and SharePriceFeed in its constructor. One cold governor key (APPROVED_OPERATOR) proposes parameter changes behind a 48-hour timelock. Collateral pricing is per 1e18 raw units throughout. IMD's only market is a full-range Uniswap v4 pool, about $2.3M a side with a 1% fee; docs/PARAMETERS-2026-10-05.md has the numbers every economic parameter was chosen from.\n\nAnswer each numbered question, including the ones where nothing is wrong:\n1. THE PACED BACKING (CDPVault._pace, _pacedBacking, _liveBacking, _clampPacedDebt, _priceAgrees, PACED_THIS_TX_SLOT, pace()). A redemption is paid min(live, paced backing), the paced backing falls at once to the live figure and rises by at most BACKING_RISE_PER_HOUR for at most PACE_INTERVAL of elapsed time between pacings, written at a transaction's first capital-moving call from the state it found, and only at a fresh, agreed price. Search every sequence of lock, lockIMD, free, draw, wipe, cash, cover, bite, earn, pace, a Treasury donation and a feed update, by one account or several, in one transaction or across many, with and without a price move between them, for one that makes a redemption paid more than the honest backing of the book plus the rise the elapsed time allows, from the reserve or from a candidate; and quantify every way honest redeemers are paid LESS than the live figure (the dip, the stale-term read, a quiet spell, a feed outage), as a cost in points and hours, against the accepted statements.\n2. THE PACED SUPPLY AND THE FEE (_pacedSupply, _step, _feeBase floored at 100,000, _redemptionRate with prior read once, the stored base rate's decay, the fresh-debt record). The cheapest way to pin the cap for everyone and the cheapest way to dilute the fee, now; whether a draw, repayment, redemption, work mint or their ordering moves the base off the paced supply by more than FOLLOW_BPS_PER_HOUR an hour; the fee a launch-day redeemer pays while the paced supply is below the live one.\n3. THE PACED DEBT AND THE WORK CEILING (_pacedDebt, _clampPacedDebt, WIPED_THIS_TX_SLOT, ParameterizedVault.backedDebt and earnLine, _debtAtTransactionStart) with WAGE_WAD 0 at launch (earn refused) and once governance turns the wage on: any way debt cancelled by cash, bite or cover and drawn again by anyone backs work minting sooner than the follow rate allows; whether a borrower's own wipe and redraw, in one transaction or across two, moves the ceiling; the cost of the aggregate (the ceiling tracks totals, not whose debt) once the wage is on.\n4. REDEMPTION PAYOUTS: cash's routes (reserve, candidate, mixed), candidate eligibility (mat + gap), RedemptionWorsensRatio, ExcessRepayment, minGemOut, the reserve valued at the vault's price, the transient tallies (MINTED, SECURED, REPAID, WORK_MINTED, WIPED, PACED this transaction) and the saturating arithmetic in _liveBacking and _securedCollateralValue. Can a redeemer pay less than the fee for its size, worsen a candidate, or take reserve beyond its share?\n5. LIQUIDATION AND BAD DEBT: bark, barkFor, bite (always marked: grace from lull, then a tail-long window), heel, the chip/cut split at CHOP_PERCENT 20, the dust seizure, cover (a re-lock below recorded bad debt taken at its value, CoverBelowCollateralValue, _coverDust) and totalBadDebt against the per-position record; and what each does to the paced figures. Can anyone take more than the formula, freeze a position unliquidatable, hold cover off cheaply, or desynchronise the bad-debt record?\n6. POSITIONS AND PRICING: lock, lockIMD (shares credited by balance delta), free, draw, wipe; the stability fee (duty, chi, drip, checkpoints); price gating (_requireFreshFeeds, _requirePriceAgreement, the ungated lock, wipe and debt-free free, which now pace, and the unreadable-price path in _resecureBounded). Below mat, double counting, reentrancy through the share vault, acting on a stale or divergent price, and whether pacing inside the ungated calls can ever revert them or write a figure from a bad price.\n7. ARITHMETIC, GAS AND SIZE: overflow at extreme collateral, price or elapsed time, rounding direction in every division that pays someone, units where a price, a 24-decimal amount and basis points meet; the gas pacing adds to lock and free; ParameterizedVault initcode 46,987 of 49,152 bytes.\n8. Every comment or NatSpec in these files that claims a property the code does not have, the paced figures' NatSpec first.\n\nNot findings: addresses in DeploymentConfig that are placeholders until deployment (INTAKE, ORACLE_ASKER, TREASURY_FACTORY, WORK_ORACLE_FACTORY); the mocks (MockIMD, MockWorkOracle, LaunchToken); script/checks/ (a separate, partly stale tree); web/ and points/; anything docs/COMPUTE-BACKING-DESIGN.md describes as future work; and findings of the earlier audits in docs/AUDIT-*.md and docs/INTERNAL-AUDIT-2026-10-04.md, unless the fix regressed. A constant set to a deliberate economic value is not a finding; an arithmetic or ordering error in how it is used is.\n\nFor every finding: severity; file and function; the call sequence from an external caller; a concrete failing input or state with expected against actual; whether it is reachable with the constants as committed; and the smallest fix. Also report every place a comment or NatSpec claims a property the code does not have, and say which contracts you read in full and which you could not reach.","baseCommit":"d3861ac5cd4fc50dfdac18dd59efed61b6d5bd8b","state":"completed","createdAt":"2026-10-09T02:34:10.700Z"}]},"deliver":false,"host":false,"site":null,"launch":{"requested":false,"kind":null,"id":null,"status":null,"chainId":null},"oracleRequestId":null,"delivery":null,"media":null,"nodes":[{"key":"audit_economics","role":"review","state":"accepted","attempt":1,"revisions":0,"judgeRevisions":0,"dependsOn":[],"allowedPaths":[],"failureReason":null,"dispatchNote":null,"dispatchNoteAt":null,"updatedAt":"2026-10-09T03:05:15.078Z","verdict":null,"seat":{"tokenId":"671","agentId":"51143"},"live":null},{"key":"audit_flow","role":"review","state":"accepted","attempt":1,"revisions":0,"judgeRevisions":0,"dependsOn":[],"allowedPaths":[],"failureReason":null,"dispatchNote":null,"dispatchNoteAt":null,"updatedAt":"2026-10-09T02:58:59.344Z","verdict":null,"seat":{"tokenId":"595","agentId":"51142"},"live":null},{"key":"audit_judge","role":"review","state":"accepted","attempt":1,"revisions":0,"judgeRevisions":0,"dependsOn":["audit_math","audit_permissions","audit_economics","audit_flow"],"allowedPaths":[],"failureReason":null,"dispatchNote":null,"dispatchNoteAt":null,"updatedAt":"2026-10-09T03:25:44.108Z","verdict":null,"seat":{"tokenId":"184","agentId":"52205"},"live":null},{"key":"audit_math","role":"review","state":"accepted","attempt":1,"revisions":0,"judgeRevisions":0,"dependsOn":[],"allowedPaths":[],"failureReason":null,"dispatchNote":null,"dispatchNoteAt":null,"updatedAt":"2026-10-09T03:14:12.939Z","verdict":null,"seat":{"tokenId":"435","agentId":"52255"},"live":null},{"key":"audit_permissions","role":"review","state":"accepted","attempt":1,"revisions":0,"judgeRevisions":0,"dependsOn":[],"allowedPaths":[],"failureReason":null,"dispatchNote":null,"dispatchNoteAt":null,"updatedAt":"2026-10-09T03:02:50.392Z","verdict":null,"seat":{"tokenId":"498","agentId":"51874"},"live":null}],"reviews":[{"status":"queued","chainId":1,"txHash":null,"blockNumber":null,"sentAt":null,"entries":[{"nodeKey":"audit_economics","agentId":"51143","value":1,"role":"review:submission"},{"nodeKey":"audit_flow","agentId":"51142","value":1,"role":"review:submission"},{"nodeKey":"audit_judge","agentId":"52205","value":1,"role":"review:submission"},{"nodeKey":"audit_math","agentId":"52255","value":1,"role":"review:submission"},{"nodeKey":"audit_permissions","agentId":"51874","value":1,"role":"review:submission"}]}]}