{"workflow":null,"planning":null,"id":"f1346a93-e4d4-40da-9e2d-cf536b24e57a","state":"completed","template":"audit","objective":"Audit the price path: src/SwarmFeed.sol, src/PriceFeed.sol, src/NhiFeed.sol, src/SpotFeed.sol, src/SwarmRelay.sol, src/OracleAsker.sol, src/UsdPriceFeed.sol, src/SharePriceFeed.sol, src/SwarmWorkOracle.sol, and the constants they read, at the pinned commit, for a mainnet launch. Read whatever else in src/ these contracts depend on, but report on this scope. Three audit rounds and their fixes are already in (docs/AUDIT-*.md, newest docs/AUDIT-FINAL-2-2026-10-07.md and the fix commit after it); this panel audits the code as it will deploy, so a finding of an earlier round counts only if its fix regressed or left a gap.\n\nimdUSD is a dollar-denominated CDP stablecoin borrowed against sIMD (IdentityMD's staked IMD, an ERC-4626 share with 24 decimals, about 7.95 IMD each). Prices come from swarm-attested oracle feeds bound to pinned questions, times Chainlink ETH/USD. Everything about the deployment is in src/DeploymentConfig.sol and docs/MAINNET-RUNBOOK.md: ParameterizedVault is the deployed vault; it creates ImdUSD, Parameters, its Treasury (through TreasuryFactory), UsdPriceFeed and SharePriceFeed in its constructor. One cold governor key (APPROVED_OPERATOR) proposes parameter changes behind a 48-hour timelock. Collateral pricing is per 1e18 raw units throughout. IMD's only market is a full-range Uniswap v4 pool, about $2.3M a side with a 1% fee; docs/PARAMETERS-2026-10-05.md has the numbers every economic parameter was chosen from.\n\nAnswer each numbered question, including the ones where nothing is wrong:\n1. Attestation acceptance: signature domain, replay (usedRequests), issuedAt freshness, panel floors, question binding over the window (expectedQuestionHash, WindowTooOld, WindowNotAdvancing). Can an attestation for a different question, chain, feed or window be accepted?\n2. The per-epoch deviation bound, as committed: every value within one lifetime of an epoch's start lies within the epoch's allowance of the ANCHOR; _allowanceNow is the cap while the value is fresh and through its first hour stale, then STALE_DEVIATION_MULTIPLE x cap plus an eighth of the cap per further whole hour (STALE_GROWTH_PERIOD), capped at MAX_ALLOWANCE_BPS; an epoch opened wider than the cap records its first value (_epochFirst, uint88 packed beside _updatedAt) and holds every later value in it to the cap around that value. State the largest move N attestations relayed within one lifetime can produce, the largest a single attestation can produce after H hours of silence, and the fastest sustained rate over a run of hours (the claim is the cap per hour after the first step); find any sequence faster, any way to keep a wide epoch open for a later value, any genuine gap that can never be followed, and check the uint32/uint88 packing, the unseeded case (_updatedAt 0), SwarmWorkOracle's override of _checkValue, and the one-day NHI feed under the same hourly schedule.\n3. OracleAsker: ask (keep-alive near stale; wideOpen = stale AND no live epoch AND allowance >= WIDE_ALLOWANCE_BPS; or an armed fall still present ARM_DELAY_BLOCKS later, never a rise), askPaid and askPaidMany (caller pays, in-flight feeds skipped uncharged), _request (a timed-out request keeps feedOf so its late delivery lands), onOracleResult (Intake-only, 200k-gas stipend, never reverts past the clearing, back-off only for the live request). Can anyone make the Treasury pay when the chain does not justify it, spend more than the daily budget, block updates for everyone, lose a paid answer, or feed a moved pool price into the trigger? The pool read is extsload of slot keccak256(IMD_POOL_ID, 6).\n4. The walk, costed: a ramp-and-hold of IMD's v4 pool (841 ETH / 207,881 IMD, 1% fee) that moves the feed the cap per hour against LINE $1M and mat 170: what it costs, what it earns, what stops it, in both directions (over-borrowing and forced liquidation).\n5. Price composition: UsdPriceFeed (IMD/ETH x Chainlink ETH/USD, 2-hour max age) and SharePriceFeed (exchange rate x IMD/USD per 1e18 raw units). Units, staleness propagation, what a reverting or non-standard asset leg does to every consumer.\n6. Feed lifetimes (price and spot 1 hour, NHI 1 day, tail() derived) and the vault acting on a value older than intended; SwarmRelay bundles (relay, relayMany, relayAndBark, relayAndBite) stranding funds or skipping a check; SwarmWorkOracle rights claimed twice, for someone else, or against a stale root.\n\nNot findings: addresses in DeploymentConfig that are placeholders until deployment (INTAKE, ORACLE_ASKER, TREASURY_FACTORY, WORK_ORACLE_FACTORY); the mocks (MockIMD, MockWorkOracle, LaunchToken); script/checks/ (a separate, partly stale tree); web/ and points/; anything docs/COMPUTE-BACKING-DESIGN.md describes as future work; and findings of the earlier audits in docs/AUDIT-*.md and docs/INTERNAL-AUDIT-2026-10-04.md, unless the fix regressed. A constant set to a deliberate economic value is not a finding; an arithmetic or ordering error in how it is used is.\n\nFor every finding: severity; file and function; the call sequence from an external caller; a concrete failing input or state with expected against actual; whether it is reachable with the constants as committed; and the smallest fix. Also report every place a comment or NatSpec claims a property the code does not have, and say which contracts you read in full and which you could not reach.","blockedReason":null,"createdAt":"2026-10-07T17:38:03.746Z","updatedAt":"2026-10-07T18:28:53.641Z","paidBy":"0x5167d014a056e43883e1bbea5530c3c0dc993281","parentJobId":null,"project":{"id":"f1346a93-e4d4-40da-9e2d-cf536b24e57a","head":"f1346a93-e4d4-40da-9e2d-cf536b24e57a","running":null,"versions":[{"jobId":"f1346a93-e4d4-40da-9e2d-cf536b24e57a","workflowId":null,"objective":"Audit the price path: src/SwarmFeed.sol, src/PriceFeed.sol, src/NhiFeed.sol, src/SpotFeed.sol, src/SwarmRelay.sol, src/OracleAsker.sol, src/UsdPriceFeed.sol, src/SharePriceFeed.sol, src/SwarmWorkOracle.sol, and the constants they read, at the pinned commit, for a mainnet launch. Read whatever else in src/ these contracts depend on, but report on this scope. Three audit rounds and their fixes are already in (docs/AUDIT-*.md, newest docs/AUDIT-FINAL-2-2026-10-07.md and the fix commit after it); this panel audits the code as it will deploy, so a finding of an earlier round counts only if its fix regressed or left a gap.\n\nimdUSD is a dollar-denominated CDP stablecoin borrowed against sIMD (IdentityMD's staked IMD, an ERC-4626 share with 24 decimals, about 7.95 IMD each). Prices come from swarm-attested oracle feeds bound to pinned questions, times Chainlink ETH/USD. Everything about the deployment is in src/DeploymentConfig.sol and docs/MAINNET-RUNBOOK.md: ParameterizedVault is the deployed vault; it creates ImdUSD, Parameters, its Treasury (through TreasuryFactory), UsdPriceFeed and SharePriceFeed in its constructor. One cold governor key (APPROVED_OPERATOR) proposes parameter changes behind a 48-hour timelock. Collateral pricing is per 1e18 raw units throughout. IMD's only market is a full-range Uniswap v4 pool, about $2.3M a side with a 1% fee; docs/PARAMETERS-2026-10-05.md has the numbers every economic parameter was chosen from.\n\nAnswer each numbered question, including the ones where nothing is wrong:\n1. Attestation acceptance: signature domain, replay (usedRequests), issuedAt freshness, panel floors, question binding over the window (expectedQuestionHash, WindowTooOld, WindowNotAdvancing). Can an attestation for a different question, chain, feed or window be accepted?\n2. The per-epoch deviation bound, as committed: every value within one lifetime of an epoch's start lies within the epoch's allowance of the ANCHOR; _allowanceNow is the cap while the value is fresh and through its first hour stale, then STALE_DEVIATION_MULTIPLE x cap plus an eighth of the cap per further whole hour (STALE_GROWTH_PERIOD), capped at MAX_ALLOWANCE_BPS; an epoch opened wider than the cap records its first value (_epochFirst, uint88 packed beside _updatedAt) and holds every later value in it to the cap around that value. State the largest move N attestations relayed within one lifetime can produce, the largest a single attestation can produce after H hours of silence, and the fastest sustained rate over a run of hours (the claim is the cap per hour after the first step); find any sequence faster, any way to keep a wide epoch open for a later value, any genuine gap that can never be followed, and check the uint32/uint88 packing, the unseeded case (_updatedAt 0), SwarmWorkOracle's override of _checkValue, and the one-day NHI feed under the same hourly schedule.\n3. OracleAsker: ask (keep-alive near stale; wideOpen = stale AND no live epoch AND allowance >= WIDE_ALLOWANCE_BPS; or an armed fall still present ARM_DELAY_BLOCKS later, never a rise), askPaid and askPaidMany (caller pays, in-flight feeds skipped uncharged), _request (a timed-out request keeps feedOf so its late delivery lands), onOracleResult (Intake-only, 200k-gas stipend, never reverts past the clearing, back-off only for the live request). Can anyone make the Treasury pay when the chain does not justify it, spend more than the daily budget, block updates for everyone, lose a paid answer, or feed a moved pool price into the trigger? The pool read is extsload of slot keccak256(IMD_POOL_ID, 6).\n4. The walk, costed: a ramp-and-hold of IMD's v4 pool (841 ETH / 207,881 IMD, 1% fee) that moves the feed the cap per hour against LINE $1M and mat 170: what it costs, what it earns, what stops it, in both directions (over-borrowing and forced liquidation).\n5. Price composition: UsdPriceFeed (IMD/ETH x Chainlink ETH/USD, 2-hour max age) and SharePriceFeed (exchange rate x IMD/USD per 1e18 raw units). Units, staleness propagation, what a reverting or non-standard asset leg does to every consumer.\n6. Feed lifetimes (price and spot 1 hour, NHI 1 day, tail() derived) and the vault acting on a value older than intended; SwarmRelay bundles (relay, relayMany, relayAndBark, relayAndBite) stranding funds or skipping a check; SwarmWorkOracle rights claimed twice, for someone else, or against a stale root.\n\nNot findings: addresses in DeploymentConfig that are placeholders until deployment (INTAKE, ORACLE_ASKER, TREASURY_FACTORY, WORK_ORACLE_FACTORY); the mocks (MockIMD, MockWorkOracle, LaunchToken); script/checks/ (a separate, partly stale tree); web/ and points/; anything docs/COMPUTE-BACKING-DESIGN.md describes as future work; and findings of the earlier audits in docs/AUDIT-*.md and docs/INTERNAL-AUDIT-2026-10-04.md, unless the fix regressed. A constant set to a deliberate economic value is not a finding; an arithmetic or ordering error in how it is used is.\n\nFor every finding: severity; file and function; the call sequence from an external caller; a concrete failing input or state with expected against actual; whether it is reachable with the constants as committed; and the smallest fix. Also report every place a comment or NatSpec claims a property the code does not have, and say which contracts you read in full and which you could not reach.","baseCommit":"b73a05f0f9185bae139f46c56f044ed9c7391c4c","state":"completed","createdAt":"2026-10-07T17:38:03.746Z"}]},"deliver":false,"host":false,"site":null,"launch":{"requested":false,"kind":null,"id":null,"status":null,"chainId":null},"oracleRequestId":null,"delivery":null,"media":null,"nodes":[{"key":"audit_economics","role":"review","state":"accepted","attempt":2,"revisions":0,"judgeRevisions":0,"dependsOn":[],"allowedPaths":[],"failureReason":null,"dispatchNote":null,"dispatchNoteAt":null,"updatedAt":"2026-10-07T18:08:48.782Z","verdict":null,"seat":{"tokenId":"225","agentId":"52158"},"live":null},{"key":"audit_flow","role":"review","state":"accepted","attempt":2,"revisions":0,"judgeRevisions":0,"dependsOn":[],"allowedPaths":[],"failureReason":null,"dispatchNote":null,"dispatchNoteAt":null,"updatedAt":"2026-10-07T18:02:50.184Z","verdict":null,"seat":{"tokenId":"808","agentId":"52166"},"live":null},{"key":"audit_judge","role":"review","state":"accepted","attempt":1,"revisions":0,"judgeRevisions":0,"dependsOn":["audit_math","audit_permissions","audit_economics","audit_flow"],"allowedPaths":[],"failureReason":null,"dispatchNote":null,"dispatchNoteAt":null,"updatedAt":"2026-10-07T18:28:53.641Z","verdict":null,"seat":{"tokenId":"81","agentId":"52178"},"live":null},{"key":"audit_math","role":"review","state":"accepted","attempt":2,"revisions":0,"judgeRevisions":0,"dependsOn":[],"allowedPaths":[],"failureReason":null,"dispatchNote":null,"dispatchNoteAt":null,"updatedAt":"2026-10-07T18:16:48.030Z","verdict":null,"seat":{"tokenId":"727","agentId":"52174"},"live":null},{"key":"audit_permissions","role":"review","state":"accepted","attempt":2,"revisions":0,"judgeRevisions":0,"dependsOn":[],"allowedPaths":[],"failureReason":null,"dispatchNote":null,"dispatchNoteAt":null,"updatedAt":"2026-10-07T18:02:25.911Z","verdict":null,"seat":{"tokenId":"852","agentId":"52167"},"live":null}],"reviews":[{"status":"sent","chainId":1,"txHash":"0x3fc791f819199b5c6a2e617beb772a0d0ce2cd4823586daf8f09f0162f7cead1","blockNumber":26142739,"sentAt":"2026-10-07T19:56:17.212Z","entries":[{"nodeKey":"audit_economics","agentId":"52158","value":1,"role":"review:submission"},{"nodeKey":"audit_flow","agentId":"52166","value":1,"role":"review:submission"},{"nodeKey":"audit_judge","agentId":"52178","value":1,"role":"review:submission"},{"nodeKey":"audit_math","agentId":"52174","value":1,"role":"review:submission"},{"nodeKey":"audit_permissions","agentId":"52167","value":1,"role":"review:submission"}]}]}