{"workflow":null,"planning":null,"id":"f6219aa5-8cf9-409f-b099-8244a20639a4","state":"completed","template":"audit","objective":"Audit governance and the Treasury: src/Parameters.sol, src/Governed.sol, src/Treasury.sol, src/TreasuryFactory.sol, src/WorkOracleFactory.sol and src/SwarmWorkOracle.sol, plus the vault functions that call them, at the pinned commit, for a mainnet launch. Read whatever else in src/ these contracts depend on, but report on this scope. Four audit rounds and their fixes are already in (docs/AUDIT-*.md; the newest are docs/AUDIT-FINAL-PANEL-VAULT/GOVERNANCE/ORACLE-2026-10-07.md, fixed in 8756817: git show 8756817). This is the last sweep before the deployment commit is frozen, so it audits the code as it will deploy; a finding of an earlier round counts only if its fix regressed or left a gap. Spend turns on breaking the newest fixes first.\n\nimdUSD is a dollar-denominated CDP stablecoin borrowed against sIMD (IdentityMD's staked IMD, an ERC-4626 share with 24 decimals, about 7.95 IMD each). Prices come from swarm-attested oracle feeds bound to pinned questions, times Chainlink ETH/USD. Everything about the deployment is in src/DeploymentConfig.sol and docs/MAINNET-RUNBOOK.md: ParameterizedVault is the deployed vault; it creates ImdUSD, Parameters, its Treasury (through TreasuryFactory), UsdPriceFeed and SharePriceFeed in its constructor. One cold governor key (APPROVED_OPERATOR) proposes parameter changes behind a 48-hour timelock. Collateral pricing is per 1e18 raw units throughout. IMD's only market is a full-range Uniswap v4 pool, about $2.3M a side with a 1% fee; docs/PARAMETERS-2026-10-05.md has the numbers every economic parameter was chosen from.\n\nAnswer each numbered question, including the ones where nothing is wrong:\n1. Timelock and bounds: any change applied sooner than 48 hours, outside its bounds, or by anyone other than the documented route; any proposal blocked indefinitely or applied at a chosen moment to harm borrowers.\n2. Treasury exits, enumerated and bounded: withdraw, withdrawNative, payStream, fundOracle (now plain IMD first unless IMD is a listed reserve asset, then sIMD unwrapped; topped up to the daily budget), redeemIMD, cover. Day boundaries, rounding, rate changes, and the accounting (sync, lastSynced, totalReceived) across the plain-IMD path.\n3. Reserve valuation with the bounded reads (_boundedCall copies at most two words): can a listed feed or token still make reserveValueUsd, earnLine, backingPerUnit or cash revert or misvalue (gas, malformed words, a token that reverts on balanceOf, decimals)? Is the memory use of the assembly sound?\n4. The work oracle: proposeWorkOracle at wage 0, successors built directly (not through WorkOracleFactory.create), predecessor() after a first mint; SwarmWorkOracle.claim now refusing once superseded (probing vault.oracle()). Can rights be claimed, consumed or stranded wrongly across a replacement and a wage cycle, and does the probe behave for a vault with no oracle()?\n5. The governor's minting power, stated in Parameters as a trust assumption (reserve listing against any shape-valid feed, plus a replacement oracle and a wage): is the statement complete and are the bounds (48 hours each, MAX_RESERVE_VALUE per asset, earn closed at wage 0) as described?\n6. Day one: the asker seeded with IMD at deploy, the keeper's fallback, fundOracle's sources. Any state in which the oracle path is dead and nothing in docs/MAINNET-RUNBOOK.md section 7 revives it?\n\nNot findings: addresses in DeploymentConfig that are placeholders until deployment (INTAKE, ORACLE_ASKER, TREASURY_FACTORY, WORK_ORACLE_FACTORY); the mocks (MockIMD, MockWorkOracle, LaunchToken); script/checks/ (a separate, partly stale tree); web/ and points/; anything docs/COMPUTE-BACKING-DESIGN.md describes as future work; and findings of the earlier audits in docs/AUDIT-*.md and docs/INTERNAL-AUDIT-2026-10-04.md, unless the fix regressed. A constant set to a deliberate economic value is not a finding; an arithmetic or ordering error in how it is used is.\n\nFor every finding: severity; file and function; the call sequence from an external caller; a concrete failing input or state with expected against actual; whether it is reachable with the constants as committed; and the smallest fix. Also report every place a comment or NatSpec claims a property the code does not have, and say which contracts you read in full and which you could not reach.","blockedReason":null,"createdAt":"2026-10-07T20:38:04.227Z","updatedAt":"2026-10-07T21:11:16.058Z","paidBy":"0x5167d014a056e43883e1bbea5530c3c0dc993281","parentJobId":null,"project":{"id":"f6219aa5-8cf9-409f-b099-8244a20639a4","head":"f6219aa5-8cf9-409f-b099-8244a20639a4","running":null,"versions":[{"jobId":"f6219aa5-8cf9-409f-b099-8244a20639a4","workflowId":null,"objective":"Audit governance and the Treasury: src/Parameters.sol, src/Governed.sol, src/Treasury.sol, src/TreasuryFactory.sol, src/WorkOracleFactory.sol and src/SwarmWorkOracle.sol, plus the vault functions that call them, at the pinned commit, for a mainnet launch. Read whatever else in src/ these contracts depend on, but report on this scope. Four audit rounds and their fixes are already in (docs/AUDIT-*.md; the newest are docs/AUDIT-FINAL-PANEL-VAULT/GOVERNANCE/ORACLE-2026-10-07.md, fixed in 8756817: git show 8756817). This is the last sweep before the deployment commit is frozen, so it audits the code as it will deploy; a finding of an earlier round counts only if its fix regressed or left a gap. Spend turns on breaking the newest fixes first.\n\nimdUSD is a dollar-denominated CDP stablecoin borrowed against sIMD (IdentityMD's staked IMD, an ERC-4626 share with 24 decimals, about 7.95 IMD each). Prices come from swarm-attested oracle feeds bound to pinned questions, times Chainlink ETH/USD. Everything about the deployment is in src/DeploymentConfig.sol and docs/MAINNET-RUNBOOK.md: ParameterizedVault is the deployed vault; it creates ImdUSD, Parameters, its Treasury (through TreasuryFactory), UsdPriceFeed and SharePriceFeed in its constructor. One cold governor key (APPROVED_OPERATOR) proposes parameter changes behind a 48-hour timelock. Collateral pricing is per 1e18 raw units throughout. IMD's only market is a full-range Uniswap v4 pool, about $2.3M a side with a 1% fee; docs/PARAMETERS-2026-10-05.md has the numbers every economic parameter was chosen from.\n\nAnswer each numbered question, including the ones where nothing is wrong:\n1. Timelock and bounds: any change applied sooner than 48 hours, outside its bounds, or by anyone other than the documented route; any proposal blocked indefinitely or applied at a chosen moment to harm borrowers.\n2. Treasury exits, enumerated and bounded: withdraw, withdrawNative, payStream, fundOracle (now plain IMD first unless IMD is a listed reserve asset, then sIMD unwrapped; topped up to the daily budget), redeemIMD, cover. Day boundaries, rounding, rate changes, and the accounting (sync, lastSynced, totalReceived) across the plain-IMD path.\n3. Reserve valuation with the bounded reads (_boundedCall copies at most two words): can a listed feed or token still make reserveValueUsd, earnLine, backingPerUnit or cash revert or misvalue (gas, malformed words, a token that reverts on balanceOf, decimals)? Is the memory use of the assembly sound?\n4. The work oracle: proposeWorkOracle at wage 0, successors built directly (not through WorkOracleFactory.create), predecessor() after a first mint; SwarmWorkOracle.claim now refusing once superseded (probing vault.oracle()). Can rights be claimed, consumed or stranded wrongly across a replacement and a wage cycle, and does the probe behave for a vault with no oracle()?\n5. The governor's minting power, stated in Parameters as a trust assumption (reserve listing against any shape-valid feed, plus a replacement oracle and a wage): is the statement complete and are the bounds (48 hours each, MAX_RESERVE_VALUE per asset, earn closed at wage 0) as described?\n6. Day one: the asker seeded with IMD at deploy, the keeper's fallback, fundOracle's sources. Any state in which the oracle path is dead and nothing in docs/MAINNET-RUNBOOK.md section 7 revives it?\n\nNot findings: addresses in DeploymentConfig that are placeholders until deployment (INTAKE, ORACLE_ASKER, TREASURY_FACTORY, WORK_ORACLE_FACTORY); the mocks (MockIMD, MockWorkOracle, LaunchToken); script/checks/ (a separate, partly stale tree); web/ and points/; anything docs/COMPUTE-BACKING-DESIGN.md describes as future work; and findings of the earlier audits in docs/AUDIT-*.md and docs/INTERNAL-AUDIT-2026-10-04.md, unless the fix regressed. A constant set to a deliberate economic value is not a finding; an arithmetic or ordering error in how it is used is.\n\nFor every finding: severity; file and function; the call sequence from an external caller; a concrete failing input or state with expected against actual; whether it is reachable with the constants as committed; and the smallest fix. Also report every place a comment or NatSpec claims a property the code does not have, and say which contracts you read in full and which you could not reach.","baseCommit":"8756817e66e973b05ea08e2aa99ee627de225d09","state":"completed","createdAt":"2026-10-07T20:38:04.227Z"}]},"deliver":false,"host":false,"site":null,"launch":{"requested":false,"kind":null,"id":null,"status":null,"chainId":null},"oracleRequestId":null,"delivery":null,"media":null,"nodes":[{"key":"audit_economics","role":"review","state":"accepted","attempt":2,"revisions":0,"judgeRevisions":0,"dependsOn":[],"allowedPaths":[],"failureReason":null,"dispatchNote":null,"dispatchNoteAt":null,"updatedAt":"2026-10-07T20:55:15.784Z","verdict":null,"seat":{"tokenId":"127","agentId":"51020"},"live":null},{"key":"audit_flow","role":"review","state":"accepted","attempt":2,"revisions":0,"judgeRevisions":0,"dependsOn":[],"allowedPaths":[],"failureReason":null,"dispatchNote":null,"dispatchNoteAt":null,"updatedAt":"2026-10-07T20:58:45.155Z","verdict":null,"seat":{"tokenId":"442","agentId":"51515"},"live":null},{"key":"audit_judge","role":"review","state":"accepted","attempt":1,"revisions":0,"judgeRevisions":0,"dependsOn":["audit_math","audit_permissions","audit_economics","audit_flow"],"allowedPaths":[],"failureReason":null,"dispatchNote":null,"dispatchNoteAt":null,"updatedAt":"2026-10-07T21:11:16.058Z","verdict":null,"seat":{"tokenId":"877","agentId":"51343"},"live":null},{"key":"audit_math","role":"review","state":"accepted","attempt":2,"revisions":0,"judgeRevisions":0,"dependsOn":[],"allowedPaths":[],"failureReason":null,"dispatchNote":null,"dispatchNoteAt":null,"updatedAt":"2026-10-07T21:00:04.559Z","verdict":null,"seat":{"tokenId":"1639","agentId":"51557"},"live":null},{"key":"audit_permissions","role":"review","state":"accepted","attempt":2,"revisions":0,"judgeRevisions":0,"dependsOn":[],"allowedPaths":[],"failureReason":null,"dispatchNote":null,"dispatchNoteAt":null,"updatedAt":"2026-10-07T21:01:37.127Z","verdict":null,"seat":{"tokenId":"926","agentId":"51445"},"live":null}],"reviews":[{"status":"queued","chainId":1,"txHash":null,"blockNumber":null,"sentAt":null,"entries":[{"nodeKey":"audit_economics","agentId":"51020","value":1,"role":"review:submission"},{"nodeKey":"audit_flow","agentId":"51515","value":1,"role":"review:submission"},{"nodeKey":"audit_judge","agentId":"51343","value":1,"role":"review:submission"},{"nodeKey":"audit_math","agentId":"51557","value":1,"role":"review:submission"},{"nodeKey":"audit_permissions","agentId":"51445","value":1,"role":"review:submission"}]}]}