{"workflow":null,"planning":null,"id":"ed4f7f6d-0b24-4762-91b5-3f1d61657d68","state":"completed","template":"audit","objective":"Audit the whole system: src/, script/DeployMainnet.s.sol, script/DeployPreflight.sol and deploy/mainnet/, at the pinned commit, for a mainnet launch. Sixteen audit rounds and their fixes are in (docs/AUDIT-*.md; the chain is web/content/docs/reference/audit-history.md). This is the LAST review before mainnet: a panel over the whole system at the commit that will deploy. Since the previous whole-system sweep (a3aa9e4, docs/AUDIT-FINAL-SWEEP-2-2026-10-09.md) the vault changed twice and nothing else in src/ did: git diff a3aa9e4 e4baedf -- src script deploy. The sweep's high (a pool held down through the feed's window paid a redeemer the whole fall in IMD) was answered with a paced payout price: cash pays at max(attested, paced), the paced price falling at a bounded rate. A panel on that fix (docs/AUDIT-PAYOUT-VAULT-PANEL-2026-10-09.md) showed the rate bounds the speed of a fall, not its size (at 5% an hour a five-hour hold was paid the whole step); the rate is now 1% an hour, a 20% step reaches the payout after about 22 paced hours, and the fix rests on the claim that a pool cannot be held 20% down on its only market for most of a day at a cost below the gain. The same commits clamp the paced debt against pre-existing principal a transaction cancels, with the position's own principal minted within FRESH_DEBT_WINDOW (12 hours) netted out, seed the paced supply no higher than the fee-base floor, read the price and NHI once per entry point, replace the reentrancy guard with a transient-storage one, and make verifySeeded check the first NHI. Both records' Resolution sections say how each finding was answered and what was ACCEPTED with its bound stated; an accepted item is a finding only if the reason is wrong or the bound does not hold. A finding of an earlier round counts only if its fix regressed or left a gap. Rank severity by what a finding lets someone take or block with the constants as committed (LINE $1M, wage 0, mat 170 at NHI >= 0.85, the backing's rise 2 points of par an hour, the follow 10% an hour, the payout price's fall 1% an hour, PACE_INTERVAL 1 hour, fee floor 100,000 imdUSD, fee cap 5%, FEED_MAX_DEVIATION_BPS 2000, SKEW_BPS 500).\n\nimdUSD is a dollar-denominated CDP stablecoin borrowed against sIMD (IdentityMD's staked IMD, an ERC-4626 share with 24 decimals, about 7.95 IMD each). Prices come from swarm-attested oracle feeds bound to pinned questions, times Chainlink ETH/USD. Everything about the deployment is in src/DeploymentConfig.sol and docs/MAINNET-RUNBOOK.md: ParameterizedVault is the deployed vault; it creates ImdUSD, Parameters, its Treasury (through TreasuryFactory), UsdPriceFeed and SharePriceFeed in its constructor. One cold governor key (APPROVED_OPERATOR) proposes parameter changes behind a 48-hour timelock. Collateral pricing is per 1e18 raw units throughout. IMD's only market is a full-range Uniswap v4 pool, about $2.3M a side with a 1% fee; docs/PARAMETERS-2026-10-05.md has the numbers every economic parameter was chosen from.\n\nAnswer each numbered question, including the ones where nothing is wrong:\n1. THE PAYOUT PRICE'S ECONOMICS (cash, _pacedPrice, _paceWith, payoutPrice). With the pool as it is (about $2.3M a side, 1% fee, no other market) and the feeds as committed (a 20% step from a fresh anchor, 40% after two silent hours, both feeds reading the one pool, the 13-sample two-hour median): the cheapest profitable hold-down in money and hours, now that each paced hour is worth 1% of redeemed volume and the fee cap eats the first five; what dip-buying, arbitrage and the attacker's inventory cost over such a hold, and whether anything in the protocol (the Treasury's fall trigger, resecure, liquidations at the held price) shortens it or pays for it; whether a RISE held through one window then released, or any fall-and-rise sequence, pays a redeemer more than the honest IMD or blocks more than the stated 18 hours; the cost to honest redeemers after a real fall against the NatSpec. Is 1% an hour the right bound, and if not, what is?\n2. THE CLAMP AND THE NETTING (_tallyPrincipalRetired, _recentlyMinted, _clampPacedDebt, CANCELLED_PRE_SLOT, MINTED_BY_SLOT). Every ordering of draw, wipe, cash, bite and cover by one or several positions, in one transaction and across blocks and across the twelve-hour window: can zero-second debt count for the work ceiling sooner than the follow rate, can the netting of a position's recent principal hide the cancellation of seasoned debt (a confederate's, or the same position's older tranche after a redraw moved its record), and can the paced debt be driven below the seasoned book for less than holding the debt twelve hours?\n3. THE PACED FIGURES ACROSS THE SYSTEM. With the Treasury (fundOracle, redeemIMD, cover, withdraw's floor, donations), Parameters (a change mid-flight), the feeds (a first value, a widened epoch, a stale window, a Chainlink outage) and SwarmRelay (bundling a feed update with a liquidation, a pace or a resecure): any sequence that pays a redemption more than the honest backing at the paid price, mints work against debt not held for the follow rate, moves the fee base faster than the follow rate, or desynchronises a record.\n4. THE LAUNCH WINDOW, hour by hour for the first day, docs/MAINNET-RUNBOOK.md section 7 against the code: the first values and verifySeeded (both references, the bands), stage two with VAULT_SALT through a private relay, the keeper (pace() hourly, resecure after each update, bite with its own imdUSD), the first draws, the first redemptions (the fee floor, the seeded supply, the payout price seeded at the first usable price), the first fall and liquidation (grace, dust, bad debt covered with no fees accrued), and every way the protocol can halt that day and how each recovers.\n5. THE ORACLE AS AN ATTACK SURFACE ON THE VAULT beyond question 1: over-borrowing at a pushed-up price then a liquidation or redemption, NHI (mat and grace), the spot's skew, a first value after a silent lifetime; in money and hours at LINE $1M.\n6. GOVERNANCE, THE TREASURY AND THE DEPLOYMENT for regressions only: the timelock and bounds, every exit from the Treasury bounded as documented, the reserve valuation, the factories; DeployMainnet.run, verifySeeded, runVault (VAULT_SALT, _refuseAnotherVault, record before verify), verify, plan.py, the pinned bodies; what can still be deployed wrong and pass. Initcode 47,961 of 49,152 bytes.\n7. Every comment, NatSpec or runbook line in scope that claims a property the code does not have, and the list of what you read in full and what you could not reach.\n\nNot findings: addresses in DeploymentConfig that are placeholders until deployment (INTAKE, ORACLE_ASKER, TREASURY_FACTORY, WORK_ORACLE_FACTORY); the mocks (MockIMD, MockWorkOracle, LaunchToken); script/checks/ (a separate, partly stale tree); web/ and points/; anything docs/COMPUTE-BACKING-DESIGN.md describes as future work; and findings of the earlier audits in docs/AUDIT-*.md and docs/INTERNAL-AUDIT-2026-10-04.md, unless the fix regressed. A constant set to a deliberate economic value is not a finding; an arithmetic or ordering error in how it is used is.\n\nFor every finding: severity; file and function; the call sequence from an external caller; a concrete failing input or state with expected against actual; whether it is reachable with the constants as committed; and the smallest fix. Also report every place a comment or NatSpec claims a property the code does not have, and say which contracts you read in full and which you could not reach.","blockedReason":null,"createdAt":"2026-10-09T07:19:28.627Z","updatedAt":"2026-10-09T07:42:31.071Z","paidBy":"0x5167d014a056e43883e1bbea5530c3c0dc993281","parentJobId":null,"project":{"id":"ed4f7f6d-0b24-4762-91b5-3f1d61657d68","head":"ed4f7f6d-0b24-4762-91b5-3f1d61657d68","running":null,"versions":[{"jobId":"ed4f7f6d-0b24-4762-91b5-3f1d61657d68","workflowId":null,"objective":"Audit the whole system: src/, script/DeployMainnet.s.sol, script/DeployPreflight.sol and deploy/mainnet/, at the pinned commit, for a mainnet launch. Sixteen audit rounds and their fixes are in (docs/AUDIT-*.md; the chain is web/content/docs/reference/audit-history.md). This is the LAST review before mainnet: a panel over the whole system at the commit that will deploy. Since the previous whole-system sweep (a3aa9e4, docs/AUDIT-FINAL-SWEEP-2-2026-10-09.md) the vault changed twice and nothing else in src/ did: git diff a3aa9e4 e4baedf -- src script deploy. The sweep's high (a pool held down through the feed's window paid a redeemer the whole fall in IMD) was answered with a paced payout price: cash pays at max(attested, paced), the paced price falling at a bounded rate. A panel on that fix (docs/AUDIT-PAYOUT-VAULT-PANEL-2026-10-09.md) showed the rate bounds the speed of a fall, not its size (at 5% an hour a five-hour hold was paid the whole step); the rate is now 1% an hour, a 20% step reaches the payout after about 22 paced hours, and the fix rests on the claim that a pool cannot be held 20% down on its only market for most of a day at a cost below the gain. The same commits clamp the paced debt against pre-existing principal a transaction cancels, with the position's own principal minted within FRESH_DEBT_WINDOW (12 hours) netted out, seed the paced supply no higher than the fee-base floor, read the price and NHI once per entry point, replace the reentrancy guard with a transient-storage one, and make verifySeeded check the first NHI. Both records' Resolution sections say how each finding was answered and what was ACCEPTED with its bound stated; an accepted item is a finding only if the reason is wrong or the bound does not hold. A finding of an earlier round counts only if its fix regressed or left a gap. Rank severity by what a finding lets someone take or block with the constants as committed (LINE $1M, wage 0, mat 170 at NHI >= 0.85, the backing's rise 2 points of par an hour, the follow 10% an hour, the payout price's fall 1% an hour, PACE_INTERVAL 1 hour, fee floor 100,000 imdUSD, fee cap 5%, FEED_MAX_DEVIATION_BPS 2000, SKEW_BPS 500).\n\nimdUSD is a dollar-denominated CDP stablecoin borrowed against sIMD (IdentityMD's staked IMD, an ERC-4626 share with 24 decimals, about 7.95 IMD each). Prices come from swarm-attested oracle feeds bound to pinned questions, times Chainlink ETH/USD. Everything about the deployment is in src/DeploymentConfig.sol and docs/MAINNET-RUNBOOK.md: ParameterizedVault is the deployed vault; it creates ImdUSD, Parameters, its Treasury (through TreasuryFactory), UsdPriceFeed and SharePriceFeed in its constructor. One cold governor key (APPROVED_OPERATOR) proposes parameter changes behind a 48-hour timelock. Collateral pricing is per 1e18 raw units throughout. IMD's only market is a full-range Uniswap v4 pool, about $2.3M a side with a 1% fee; docs/PARAMETERS-2026-10-05.md has the numbers every economic parameter was chosen from.\n\nAnswer each numbered question, including the ones where nothing is wrong:\n1. THE PAYOUT PRICE'S ECONOMICS (cash, _pacedPrice, _paceWith, payoutPrice). With the pool as it is (about $2.3M a side, 1% fee, no other market) and the feeds as committed (a 20% step from a fresh anchor, 40% after two silent hours, both feeds reading the one pool, the 13-sample two-hour median): the cheapest profitable hold-down in money and hours, now that each paced hour is worth 1% of redeemed volume and the fee cap eats the first five; what dip-buying, arbitrage and the attacker's inventory cost over such a hold, and whether anything in the protocol (the Treasury's fall trigger, resecure, liquidations at the held price) shortens it or pays for it; whether a RISE held through one window then released, or any fall-and-rise sequence, pays a redeemer more than the honest IMD or blocks more than the stated 18 hours; the cost to honest redeemers after a real fall against the NatSpec. Is 1% an hour the right bound, and if not, what is?\n2. THE CLAMP AND THE NETTING (_tallyPrincipalRetired, _recentlyMinted, _clampPacedDebt, CANCELLED_PRE_SLOT, MINTED_BY_SLOT). Every ordering of draw, wipe, cash, bite and cover by one or several positions, in one transaction and across blocks and across the twelve-hour window: can zero-second debt count for the work ceiling sooner than the follow rate, can the netting of a position's recent principal hide the cancellation of seasoned debt (a confederate's, or the same position's older tranche after a redraw moved its record), and can the paced debt be driven below the seasoned book for less than holding the debt twelve hours?\n3. THE PACED FIGURES ACROSS THE SYSTEM. With the Treasury (fundOracle, redeemIMD, cover, withdraw's floor, donations), Parameters (a change mid-flight), the feeds (a first value, a widened epoch, a stale window, a Chainlink outage) and SwarmRelay (bundling a feed update with a liquidation, a pace or a resecure): any sequence that pays a redemption more than the honest backing at the paid price, mints work against debt not held for the follow rate, moves the fee base faster than the follow rate, or desynchronises a record.\n4. THE LAUNCH WINDOW, hour by hour for the first day, docs/MAINNET-RUNBOOK.md section 7 against the code: the first values and verifySeeded (both references, the bands), stage two with VAULT_SALT through a private relay, the keeper (pace() hourly, resecure after each update, bite with its own imdUSD), the first draws, the first redemptions (the fee floor, the seeded supply, the payout price seeded at the first usable price), the first fall and liquidation (grace, dust, bad debt covered with no fees accrued), and every way the protocol can halt that day and how each recovers.\n5. THE ORACLE AS AN ATTACK SURFACE ON THE VAULT beyond question 1: over-borrowing at a pushed-up price then a liquidation or redemption, NHI (mat and grace), the spot's skew, a first value after a silent lifetime; in money and hours at LINE $1M.\n6. GOVERNANCE, THE TREASURY AND THE DEPLOYMENT for regressions only: the timelock and bounds, every exit from the Treasury bounded as documented, the reserve valuation, the factories; DeployMainnet.run, verifySeeded, runVault (VAULT_SALT, _refuseAnotherVault, record before verify), verify, plan.py, the pinned bodies; what can still be deployed wrong and pass. Initcode 47,961 of 49,152 bytes.\n7. Every comment, NatSpec or runbook line in scope that claims a property the code does not have, and the list of what you read in full and what you could not reach.\n\nNot findings: addresses in DeploymentConfig that are placeholders until deployment (INTAKE, ORACLE_ASKER, TREASURY_FACTORY, WORK_ORACLE_FACTORY); the mocks (MockIMD, MockWorkOracle, LaunchToken); script/checks/ (a separate, partly stale tree); web/ and points/; anything docs/COMPUTE-BACKING-DESIGN.md describes as future work; and findings of the earlier audits in docs/AUDIT-*.md and docs/INTERNAL-AUDIT-2026-10-04.md, unless the fix regressed. A constant set to a deliberate economic value is not a finding; an arithmetic or ordering error in how it is used is.\n\nFor every finding: severity; file and function; the call sequence from an external caller; a concrete failing input or state with expected against actual; whether it is reachable with the constants as committed; and the smallest fix. Also report every place a comment or NatSpec claims a property the code does not have, and say which contracts you read in full and which you could not reach.","baseCommit":"e4baedf95fc3bb10e3c7bd5264c829fbbc784cc3","state":"completed","createdAt":"2026-10-09T07:19:28.627Z"}]},"deliver":false,"host":false,"site":null,"launch":{"requested":false,"kind":null,"id":null,"status":null,"chainId":null},"oracleRequestId":null,"delivery":null,"media":null,"nodes":[{"key":"audit_economics","role":"review","state":"accepted","attempt":1,"revisions":0,"judgeRevisions":0,"dependsOn":[],"allowedPaths":[],"failureReason":null,"dispatchNote":null,"dispatchNoteAt":null,"updatedAt":"2026-10-09T07:36:28.523Z","verdict":null,"seat":{"tokenId":"1166","agentId":"52266"},"live":null},{"key":"audit_flow","role":"review","state":"accepted","attempt":1,"revisions":0,"judgeRevisions":0,"dependsOn":[],"allowedPaths":[],"failureReason":null,"dispatchNote":null,"dispatchNoteAt":null,"updatedAt":"2026-10-09T07:31:40.235Z","verdict":null,"seat":{"tokenId":"588","agentId":"52323"},"live":null},{"key":"audit_judge","role":"review","state":"accepted","attempt":1,"revisions":0,"judgeRevisions":0,"dependsOn":["audit_math","audit_permissions","audit_economics","audit_flow"],"allowedPaths":[],"failureReason":null,"dispatchNote":null,"dispatchNoteAt":null,"updatedAt":"2026-10-09T07:42:31.071Z","verdict":null,"seat":{"tokenId":"1626","agentId":"50969"},"live":null},{"key":"audit_math","role":"review","state":"accepted","attempt":1,"revisions":0,"judgeRevisions":0,"dependsOn":[],"allowedPaths":[],"failureReason":null,"dispatchNote":null,"dispatchNoteAt":null,"updatedAt":"2026-10-09T07:39:43.371Z","verdict":null,"seat":{"tokenId":"1122","agentId":"51347"},"live":null},{"key":"audit_permissions","role":"review","state":"accepted","attempt":1,"revisions":0,"judgeRevisions":0,"dependsOn":[],"allowedPaths":[],"failureReason":null,"dispatchNote":null,"dispatchNoteAt":null,"updatedAt":"2026-10-09T07:36:10.953Z","verdict":null,"seat":{"tokenId":"871","agentId":"51429"},"live":null}],"reviews":[{"status":"queued","chainId":1,"txHash":null,"blockNumber":null,"sentAt":null,"entries":[{"nodeKey":"audit_economics","agentId":"52266","value":1,"role":"review:submission"},{"nodeKey":"audit_flow","agentId":"52323","value":1,"role":"review:submission"},{"nodeKey":"audit_judge","agentId":"50969","value":1,"role":"review:submission"},{"nodeKey":"audit_math","agentId":"51347","value":1,"role":"review:submission"},{"nodeKey":"audit_permissions","agentId":"51429","value":1,"role":"review:submission"}]}]}