{"workflow":null,"planning":null,"id":"ecd0a279-c5d7-4167-8e75-9fbbc85b41fe","state":"completed","template":"audit","objective":"Audit the price path: src/SwarmFeed.sol, src/PriceFeed.sol, src/NhiFeed.sol, src/SpotFeed.sol, src/SwarmRelay.sol, src/OracleAsker.sol, src/UsdPriceFeed.sol, src/SharePriceFeed.sol, and script/DeployMainnet.s.sol's verify and verifySeeded, at the pinned commit, for a mainnet launch. Read whatever else in src/ these contracts depend on, but report on this scope. Four audit rounds and their fixes are already in (docs/AUDIT-*.md; the newest are docs/AUDIT-FINAL-PANEL-VAULT/GOVERNANCE/ORACLE-2026-10-07.md, fixed in 8756817: git show 8756817). This is the last sweep before the deployment commit is frozen, so it audits the code as it will deploy; a finding of an earlier round counts only if its fix regressed or left a gap. Spend turns on breaking the newest fixes first.\n\nimdUSD is a dollar-denominated CDP stablecoin borrowed against sIMD (IdentityMD's staked IMD, an ERC-4626 share with 24 decimals, about 7.95 IMD each). Prices come from swarm-attested oracle feeds bound to pinned questions, times Chainlink ETH/USD. Everything about the deployment is in src/DeploymentConfig.sol and docs/MAINNET-RUNBOOK.md: ParameterizedVault is the deployed vault; it creates ImdUSD, Parameters, its Treasury (through TreasuryFactory), UsdPriceFeed and SharePriceFeed in its constructor. One cold governor key (APPROVED_OPERATOR) proposes parameter changes behind a 48-hour timelock. Collateral pricing is per 1e18 raw units throughout. IMD's only market is a full-range Uniswap v4 pool, about $2.3M a side with a 1% fee; docs/PARAMETERS-2026-10-05.md has the numbers every economic parameter was chosen from.\n\nAnswer each numbered question, including the ones where nothing is wrong:\n1. Attestation acceptance: signature domain, replay, issuedAt freshness, panel floors, question binding over the window. Any attestation for a different question, chain, feed or window accepted?\n2. The per-epoch bound as committed: the epoch's anchor and stored allowance; _allowanceNow (the cap while fresh and through the first hour of silence, measured from the LATER of the signature and the relay (_acceptedAt); then 2x the cap plus an eighth per further hour, capped at MAX_ALLOWANCE_BPS); a wide epoch holding later values to the cap around its first (_epochFirst, uint80). Slot 3 is repacked (uint64 updatedAt, bool, uint40 anchorAt, uint24 bound, uint40 acceptedAt, uint80 epochFirst): check the packing and every cast. State the fastest sustained rate a buyer who chooses issue times, relay times and windows can drive the price, in both directions and on the one-day NHI feed, and the largest single step after H hours of silence; find any sequence faster than the cap per hour after the first step, or any genuine gap never followed.\n3. OracleAsker: ask (keep-alive near stale; wideOpen = stale, no live epoch, allowance >= WIDE_ALLOWANCE_BPS; an armed fall), askPaid, askPaidMany, _request (a timed-out request keeps feedOf), onOracleResult (back-off only when the live request was the Treasury's own: lastAsk == inFlightAt). Can anyone make the Treasury pay without cause, exceed the daily budget, hold it off, lose a paid answer, or fake the Treasury-paid test?\n4. The first value: unbounded on chain, relayed by anyone; DeployMainnet.verifySeeded() (price and spot within a quarter of the cap of the pool, of each other within SKEW_BPS, NHI in (0, 1e18]) and runbook 7.1. Is the check sufficient to keep a raced first value from pricing any deposit, and what does a failed check cost?\n5. Price composition and dead legs: UsdPriceFeed, SharePriceFeed, a reverting or malformed Chainlink or share-vault leg, and what each consumer (vault actions, the ungated paths, the Treasury's reserve) does with it.\n6. The walk, costed at the committed constants against LINE $1M and mat 170, both directions, including the hold-then-relay variant: cost, earnings, and what stops it.\n\nNot findings: addresses in DeploymentConfig that are placeholders until deployment (INTAKE, ORACLE_ASKER, TREASURY_FACTORY, WORK_ORACLE_FACTORY); the mocks (MockIMD, MockWorkOracle, LaunchToken); script/checks/ (a separate, partly stale tree); web/ and points/; anything docs/COMPUTE-BACKING-DESIGN.md describes as future work; and findings of the earlier audits in docs/AUDIT-*.md and docs/INTERNAL-AUDIT-2026-10-04.md, unless the fix regressed. A constant set to a deliberate economic value is not a finding; an arithmetic or ordering error in how it is used is.\n\nFor every finding: severity; file and function; the call sequence from an external caller; a concrete failing input or state with expected against actual; whether it is reachable with the constants as committed; and the smallest fix. Also report every place a comment or NatSpec claims a property the code does not have, and say which contracts you read in full and which you could not reach.","blockedReason":null,"createdAt":"2026-10-07T20:38:50.106Z","updatedAt":"2026-10-07T21:18:17.920Z","paidBy":"0x5167d014a056e43883e1bbea5530c3c0dc993281","parentJobId":null,"project":{"id":"ecd0a279-c5d7-4167-8e75-9fbbc85b41fe","head":"ecd0a279-c5d7-4167-8e75-9fbbc85b41fe","running":null,"versions":[{"jobId":"ecd0a279-c5d7-4167-8e75-9fbbc85b41fe","workflowId":null,"objective":"Audit the price path: src/SwarmFeed.sol, src/PriceFeed.sol, src/NhiFeed.sol, src/SpotFeed.sol, src/SwarmRelay.sol, src/OracleAsker.sol, src/UsdPriceFeed.sol, src/SharePriceFeed.sol, and script/DeployMainnet.s.sol's verify and verifySeeded, at the pinned commit, for a mainnet launch. Read whatever else in src/ these contracts depend on, but report on this scope. Four audit rounds and their fixes are already in (docs/AUDIT-*.md; the newest are docs/AUDIT-FINAL-PANEL-VAULT/GOVERNANCE/ORACLE-2026-10-07.md, fixed in 8756817: git show 8756817). This is the last sweep before the deployment commit is frozen, so it audits the code as it will deploy; a finding of an earlier round counts only if its fix regressed or left a gap. Spend turns on breaking the newest fixes first.\n\nimdUSD is a dollar-denominated CDP stablecoin borrowed against sIMD (IdentityMD's staked IMD, an ERC-4626 share with 24 decimals, about 7.95 IMD each). Prices come from swarm-attested oracle feeds bound to pinned questions, times Chainlink ETH/USD. Everything about the deployment is in src/DeploymentConfig.sol and docs/MAINNET-RUNBOOK.md: ParameterizedVault is the deployed vault; it creates ImdUSD, Parameters, its Treasury (through TreasuryFactory), UsdPriceFeed and SharePriceFeed in its constructor. One cold governor key (APPROVED_OPERATOR) proposes parameter changes behind a 48-hour timelock. Collateral pricing is per 1e18 raw units throughout. IMD's only market is a full-range Uniswap v4 pool, about $2.3M a side with a 1% fee; docs/PARAMETERS-2026-10-05.md has the numbers every economic parameter was chosen from.\n\nAnswer each numbered question, including the ones where nothing is wrong:\n1. Attestation acceptance: signature domain, replay, issuedAt freshness, panel floors, question binding over the window. Any attestation for a different question, chain, feed or window accepted?\n2. The per-epoch bound as committed: the epoch's anchor and stored allowance; _allowanceNow (the cap while fresh and through the first hour of silence, measured from the LATER of the signature and the relay (_acceptedAt); then 2x the cap plus an eighth per further hour, capped at MAX_ALLOWANCE_BPS); a wide epoch holding later values to the cap around its first (_epochFirst, uint80). Slot 3 is repacked (uint64 updatedAt, bool, uint40 anchorAt, uint24 bound, uint40 acceptedAt, uint80 epochFirst): check the packing and every cast. State the fastest sustained rate a buyer who chooses issue times, relay times and windows can drive the price, in both directions and on the one-day NHI feed, and the largest single step after H hours of silence; find any sequence faster than the cap per hour after the first step, or any genuine gap never followed.\n3. OracleAsker: ask (keep-alive near stale; wideOpen = stale, no live epoch, allowance >= WIDE_ALLOWANCE_BPS; an armed fall), askPaid, askPaidMany, _request (a timed-out request keeps feedOf), onOracleResult (back-off only when the live request was the Treasury's own: lastAsk == inFlightAt). Can anyone make the Treasury pay without cause, exceed the daily budget, hold it off, lose a paid answer, or fake the Treasury-paid test?\n4. The first value: unbounded on chain, relayed by anyone; DeployMainnet.verifySeeded() (price and spot within a quarter of the cap of the pool, of each other within SKEW_BPS, NHI in (0, 1e18]) and runbook 7.1. Is the check sufficient to keep a raced first value from pricing any deposit, and what does a failed check cost?\n5. Price composition and dead legs: UsdPriceFeed, SharePriceFeed, a reverting or malformed Chainlink or share-vault leg, and what each consumer (vault actions, the ungated paths, the Treasury's reserve) does with it.\n6. The walk, costed at the committed constants against LINE $1M and mat 170, both directions, including the hold-then-relay variant: cost, earnings, and what stops it.\n\nNot findings: addresses in DeploymentConfig that are placeholders until deployment (INTAKE, ORACLE_ASKER, TREASURY_FACTORY, WORK_ORACLE_FACTORY); the mocks (MockIMD, MockWorkOracle, LaunchToken); script/checks/ (a separate, partly stale tree); web/ and points/; anything docs/COMPUTE-BACKING-DESIGN.md describes as future work; and findings of the earlier audits in docs/AUDIT-*.md and docs/INTERNAL-AUDIT-2026-10-04.md, unless the fix regressed. A constant set to a deliberate economic value is not a finding; an arithmetic or ordering error in how it is used is.\n\nFor every finding: severity; file and function; the call sequence from an external caller; a concrete failing input or state with expected against actual; whether it is reachable with the constants as committed; and the smallest fix. Also report every place a comment or NatSpec claims a property the code does not have, and say which contracts you read in full and which you could not reach.","baseCommit":"8756817e66e973b05ea08e2aa99ee627de225d09","state":"completed","createdAt":"2026-10-07T20:38:50.106Z"}]},"deliver":false,"host":false,"site":null,"launch":{"requested":false,"kind":null,"id":null,"status":null,"chainId":null},"oracleRequestId":null,"delivery":null,"media":null,"nodes":[{"key":"audit_economics","role":"review","state":"accepted","attempt":1,"revisions":0,"judgeRevisions":0,"dependsOn":[],"allowedPaths":[],"failureReason":null,"dispatchNote":null,"dispatchNoteAt":null,"updatedAt":"2026-10-07T21:03:04.233Z","verdict":null,"seat":{"tokenId":"1212","agentId":"52182"},"live":null},{"key":"audit_flow","role":"review","state":"accepted","attempt":1,"revisions":0,"judgeRevisions":0,"dependsOn":[],"allowedPaths":[],"failureReason":null,"dispatchNote":null,"dispatchNoteAt":null,"updatedAt":"2026-10-07T20:59:32.702Z","verdict":null,"seat":{"tokenId":"346","agentId":"52289"},"live":null},{"key":"audit_judge","role":"review","state":"accepted","attempt":2,"revisions":0,"judgeRevisions":0,"dependsOn":["audit_math","audit_permissions","audit_economics","audit_flow"],"allowedPaths":[],"failureReason":null,"dispatchNote":null,"dispatchNoteAt":null,"updatedAt":"2026-10-07T21:18:17.920Z","verdict":null,"seat":{"tokenId":"1473","agentId":"51481"},"live":null},{"key":"audit_math","role":"review","state":"accepted","attempt":1,"revisions":0,"judgeRevisions":0,"dependsOn":[],"allowedPaths":[],"failureReason":null,"dispatchNote":null,"dispatchNoteAt":null,"updatedAt":"2026-10-07T21:02:56.224Z","verdict":null,"seat":{"tokenId":"729","agentId":"50988"},"live":null},{"key":"audit_permissions","role":"review","state":"accepted","attempt":1,"revisions":0,"judgeRevisions":0,"dependsOn":[],"allowedPaths":[],"failureReason":null,"dispatchNote":null,"dispatchNoteAt":null,"updatedAt":"2026-10-07T21:03:12.403Z","verdict":null,"seat":{"tokenId":"158","agentId":"51474"},"live":null}],"reviews":[{"status":"queued","chainId":1,"txHash":null,"blockNumber":null,"sentAt":null,"entries":[{"nodeKey":"audit_economics","agentId":"52182","value":1,"role":"review:submission"},{"nodeKey":"audit_flow","agentId":"52289","value":1,"role":"review:submission"},{"nodeKey":"audit_judge","agentId":"51481","value":1,"role":"review:submission"},{"nodeKey":"audit_math","agentId":"50988","value":1,"role":"review:submission"},{"nodeKey":"audit_permissions","agentId":"51474","value":1,"role":"review:submission"}]}]}