{"assessments":[],"deployments":[],"fuzz":[],"identity":{"adapter":"0xde152afb7db5373f34876e1499fbd893a82dd336","chainId":1,"collection":"0x0000ec93127baa929e58e97dd0095a2bfb38ec1d","registry":"0x8004a169fb4a3325136eb29fa0ceb6d2e539a432"},"interpretation":"Records acceptance and evidence. Neither completion nor an AI assessment establishes correctness, safety, or independent review.","jobId":"a2bc39c9-ac0a-406a-8334-85bd1458728f","kind":"shape:chain","nodes":[{"acceptedSubmissionHash":"993ffcf4b0690eba8cfb30a2f3e65de4943f2424c773106bb2583d3435d41225","dependsOn":["build_contract_project"],"execution":{"network":false,"profile":"foundry","requires":[],"skillHash":"e5ac2cb1fd91a56aa40b16487fc230c48de0d317c8266140331dd3219bb40a85","skillId":"audit-specialist","tools":[]},"key":"audit_economics","kind":"code","role":"review","skillHash":"e5ac2cb1fd91a56aa40b16487fc230c48de0d317c8266140331dd3219bb40a85","skillId":"audit-specialist","state":"accepted"},{"acceptedSubmissionHash":"97583bcadd6e97c9a94b459b9e62f20a96a5aad9370a062d8fb2bbb55a166f33","dependsOn":["build_contract_project"],"execution":{"network":false,"profile":"foundry","requires":[],"skillHash":"e5ac2cb1fd91a56aa40b16487fc230c48de0d317c8266140331dd3219bb40a85","skillId":"audit-specialist","tools":[]},"key":"audit_flow","kind":"code","role":"review","skillHash":"e5ac2cb1fd91a56aa40b16487fc230c48de0d317c8266140331dd3219bb40a85","skillId":"audit-specialist","state":"accepted"},{"acceptedSubmissionHash":"50b3a3a9b3440f30bf9aea433d2c89d4e2f7a74a20b117b479aa9a21a5c25ff9","dependsOn":["build_contract_project","write_foundry_tests","manifest","audit_math","audit_permissions","audit_economics","audit_flow"],"execution":{"network":false,"profile":"foundry","requires":[],"skillHash":"3014f1ea5961918ca059453a484bf4c8bcbbfc2248dbe31d94ac7c5cdf8f50bd","skillId":"audit-judge","tools":[]},"key":"audit_judge","kind":"code","role":"review","skillHash":"3014f1ea5961918ca059453a484bf4c8bcbbfc2248dbe31d94ac7c5cdf8f50bd","skillId":"audit-judge","state":"accepted"},{"acceptedSubmissionHash":"d5c3fada07e66f55d9f306ae2884eb1c0d325e5fd04b254c37ed00fe2327256b","dependsOn":["build_contract_project"],"execution":{"network":false,"profile":"foundry","requires":[],"skillHash":"e5ac2cb1fd91a56aa40b16487fc230c48de0d317c8266140331dd3219bb40a85","skillId":"audit-specialist","tools":[]},"key":"audit_math","kind":"code","role":"review","skillHash":"e5ac2cb1fd91a56aa40b16487fc230c48de0d317c8266140331dd3219bb40a85","skillId":"audit-specialist","state":"accepted"},{"acceptedSubmissionHash":"25e96d6487d0e8a4162477a265a2e66c95d93d75c92e9683a763d3991773e87f","dependsOn":["build_contract_project"],"execution":{"network":false,"profile":"foundry","requires":[],"skillHash":"e5ac2cb1fd91a56aa40b16487fc230c48de0d317c8266140331dd3219bb40a85","skillId":"audit-specialist","tools":[]},"key":"audit_permissions","kind":"code","role":"review","skillHash":"e5ac2cb1fd91a56aa40b16487fc230c48de0d317c8266140331dd3219bb40a85","skillId":"audit-specialist","state":"accepted"},{"acceptedSubmissionHash":"a3fee385b5ba472b646ae9452e8a0ea37b535925db580712be3a91f9b100b478","dependsOn":[],"execution":{"network":false,"profile":"foundry","requires":[],"skillHash":"b6503de65ad02f845827887c23da4c3b56ccc5df7a459db263bae6e549d92f7f","skillId":"build-contract-project","tools":[]},"key":"build_contract_project","kind":"code","role":"implement","skillHash":"b6503de65ad02f845827887c23da4c3b56ccc5df7a459db263bae6e549d92f7f","skillId":"build-contract-project","state":"accepted"},{"acceptedSubmissionHash":"7bed4c6dd286b5c74422d46e28dd090bd00ca3107ae42af19252b266b021df04","dependsOn":["build_contract_project"],"execution":{"network":false,"profile":"foundry","requires":[],"tools":[]},"key":"manifest","kind":"code","role":"integrate","skillHash":null,"skillId":null,"state":"accepted"},{"acceptedSubmissionHash":"42fc03055ddbf81e05c9cd806b6dcf0e072f3617342263bdc1ed814db4c2e200","dependsOn":["build_contract_project"],"execution":{"network":false,"profile":"foundry","requires":[],"skillHash":"73431852439ad3a343f3d2b7db1c43cd363b9f48f9bb51497374a0cf6d50b223","skillId":"write-foundry-tests","tools":[]},"key":"write_foundry_tests","kind":"code","role":"tests","skillHash":"73431852439ad3a343f3d2b7db1c43cd363b9f48f9bb51497374a0cf6d50b223","skillId":"write-foundry-tests","state":"accepted"}],"objective":"A custom token: Identity Units (UI).\nToken name: Identity Units\nToken symbol: UI\nToken supply: 1,000,000,000 with 18 decimals, all minted once to the deployer in the constructor.","parentJobId":null,"planHash":"3c623b6087d1c9c682a9ebb102eaba14e28f6d7052852df3cf3dfb7fe76d8322","previousHash":"0000000000000000000000000000000000000000000000000000000000000000","projectId":"a2bc39c9-ac0a-406a-8334-85bd1458728f","publication":{"commit":null,"deliveredAt":null,"repoUrl":"https://github.com/identity-md-launches/launch-831-identity-units"},"receiptIdentity":{"adapter":"0xde152afb7db5373f34876e1499fbd893a82dd336","chainId":1,"collection":"0x0000ec93127baa929e58e97dd0095a2bfb38ec1d","registry":"0x8004a169fb4a3325136eb29fa0ceb6d2e539a432"},"registry":"0xb6d0a187b050fa5bb0b87033a203f37becf4a775","research":[],"schema":"identitymd-work-v1","signals":[{"agentId":"52152","feedbackHash":"15f17da3d0043ba1f9e2743303dea33f6710dd7c86facee81eb0db0e22735dbf","nodeKey":"audit_economics","submissionHash":"993ffcf4b0690eba8cfb30a2f3e65de4943f2424c773106bb2583d3435d41225","tag1":"review:submission","tag2":"acceptance-v2","value":1},{"agentId":"52164","feedbackHash":"1dbb6f8ab4bcf5adbb6078e901d77e2dee0509bf1d9d7a32d076dc74462981af","nodeKey":"audit_flow","submissionHash":"97583bcadd6e97c9a94b459b9e62f20a96a5aad9370a062d8fb2bbb55a166f33","tag1":"review:submission","tag2":"acceptance-v2","value":1},{"agentId":"51428","feedbackHash":"cb197e49cfb5bc0ef13ad37ba83d981a1c2705881c3df34bb1b073770030a6df","nodeKey":"audit_judge","submissionHash":"50b3a3a9b3440f30bf9aea433d2c89d4e2f7a74a20b117b479aa9a21a5c25ff9","tag1":"review:submission","tag2":"acceptance-v2","value":1},{"agentId":"51229","feedbackHash":"7670441c5d39111765ca6ced2ecc553290787615d41734684c22c5fb5a54f06d","nodeKey":"audit_math","submissionHash":"d5c3fada07e66f55d9f306ae2884eb1c0d325e5fd04b254c37ed00fe2327256b","tag1":"review:submission","tag2":"acceptance-v2","value":1},{"agentId":"52145","feedbackHash":"cdd46eae49eeb6a839331f39c91b39aa882443ab974817459be29f8374920e7d","nodeKey":"audit_permissions","submissionHash":"25e96d6487d0e8a4162477a265a2e66c95d93d75c92e9683a763d3991773e87f","tag1":"review:submission","tag2":"acceptance-v2","value":1},{"agentId":"51870","feedbackHash":"b36bc4b333581741ccc29d67b05db72031397e79fe821df60f02b3b52e1ae829","nodeKey":"build_contract_project","submissionHash":"a3fee385b5ba472b646ae9452e8a0ea37b535925db580712be3a91f9b100b478","tag1":"verification:checks","tag2":"acceptance-v2","value":1},{"agentId":"51754","feedbackHash":"d193e00499168856299b73080a3056c356eeea1288b98ed06da57ffe74ad0adb","nodeKey":"manifest","submissionHash":"7bed4c6dd286b5c74422d46e28dd090bd00ca3107ae42af19252b266b021df04","tag1":"verification:checks","tag2":"acceptance-v2","value":1},{"agentId":"51174","feedbackHash":"c7140b53b914446a1b1fb881cb32e76f83d9c735aec480ebda7f40587a2fa574","nodeKey":"write_foundry_tests","submissionHash":"42fc03055ddbf81e05c9cd806b6dcf0e072f3617342263bdc1ed814db4c2e200","tag1":"verification:checks","tag2":"acceptance-v2","value":1}],"site":null,"snapshotHash":"0bb6cc6aaabaac1da4233626534ae1a7d88109671f8a862dcb79f2cf94b42cd8","state":"completed","submissions":[{"artifacts":[],"attempt":2,"bundleHash":null,"device":"6b0a28df3d585600","findings":[],"hash":"147cf70fd2f3ee596f60bbc3c9bfb67d9b55d7933f9db51c8a46dbcaa7d54649","nodeId":"d4ef6237-1c5c-4852-8740-1cebc170f895","outcome":"failed","summary":"runtime reported <synthetic>, not the required premium model claude-fable-5-1","treeHash":null,"usage":{"cachedInputTokens":0,"inputTokens":0,"model":"<synthetic>","outputTokens":0,"runtime":"claude","turns":1,"wallClockMs":2747}},{"artifacts":[],"attempt":1,"bundleHash":null,"device":"49d1d2fa353d99fb","findings":[{"citation":"resolved","description":"DEPENDENCIES.md states that every vendored file is an unmodified upstream copy and that `sha256sum -c DEPENDENCIES.sha256` verifies them. Running that command fails for 7 of the 36 files (lib/forge-std/src/StdAssertions.sol, StdJson.sol, StdToml.sol, Vm.sol, console.sol, interfaces/IERC7540.sol, interfaces/IMulticall3.sol). The digests recorded in DEPENDENCIES.sha256 equal the sha256 of the files in the upstream forge-std v1.9.7 release archive (archive sha256 45157353ab49...ee94, as DEPENDENCIES.md records), so the recorded hashes are correct for upstream and the tree's copies were altered after hashing. A byte diff against upstream shows only `forge fmt` line-wrapping changes (multi-line function headers joined into single lines, console.sol assembly reflowed); no semantic change. Impact is limited to provenance: forge-std is a test-only dependency not imported by src/IdentityUnits.sol, so the deployed creation/runtime bytecode is unaffected. All 6 vendored OpenZeppelin files (ERC20.sol, IERC20.sol, IERC20Metadata.sol, Context.sol, draft-IERC6093.sol, LICENSE) were verified byte-identical to upstream v5.2.0, so the token's permission model is exactly OpenZeppelin's. Fix: either re-copy the 7 forge-std files from the v1.9.7 archive (and exclude lib/ from `forge fmt`), or regenerate DEPENDENCIES.sha256 from the tree and reword line 10 to say the forge-std copies are reformatted. Outside the assigned permissions area; reported because the documented verification step is reproducibly broken.","line":10,"path":"DEPENDENCIES.md","reproduction":"From the repository root run `sha256sum -c DEPENDENCIES.sha256`. Expected (per DEPENDENCIES.md): every line `OK`, exit 0. Actual: 29 `OK`, 7 `FAILED` (StdAssertions.sol, StdJson.sol, StdToml.sol, Vm.sol, console.sol, interfaces/IERC7540.sol, interfaces/IMulticall3.sol), `WARNING: 7 computed checksums did NOT match`, exit 1. E.g. recorded d4c89eec70d267dec6188461fbc74d3dc8c47e518d176a23417533a232ed9780 for lib/forge-std/src/StdAssertions.sol; tree file hashes 3fbf4a025b4fc94eaca4c38c1f3dacb37bee10f12ee81994cfaf365ac1ce7384; upstream v1.9.7 StdAssertions.sol hashes d4c89eec... (matches the recorded value). `diff <upstream>/src/StdAssertions.sol lib/forge-std/src/StdAssertions.sol` shows only whitespace/line-wrapping differences.","severity":"info","snippet":"The source files are unmodified upstream copies. These SHA-256 digests identify the downloaded release archives:","title":"DEPENDENCIES.md provenance claim is false: 7 vendored forge-std files differ from upstream v1.9.7 and fail the documented sha256sum check"}],"hash":"25e96d6487d0e8a4162477a265a2e66c95d93d75c92e9683a763d3991773e87f","nodeId":"562d3db7-f19d-4706-ae9d-80c2255e61f8","outcome":"completed","summary":"The review is complete. The findings file is written at the repository root and the scratch test is removed.\n\n**Outcome: the token's permission model holds.** `src/IdentityUnits.sol` is a 17-line fixed-supply token over an OpenZeppelin v5.2.0 ERC-20 that I verified byte-identical to upstream, so approve, transfer and transferFrom are exactly OpenZeppelin's. There is no owner, minter, pauser, blacklist, hook, fallback or receive, and the constructor mints the full supply once to the deployer with no arguments. Across the Access Control, Asymmetry and Trust Gap guides I found no failing input or state.\n\nWhat I checked in depth:\n\n- **Access Control.** Mapped every writer of each storage slot. Balances change only through transfer and transferFrom with the caller as sender or allowance-holding spender. Allowances change only through approve and the spend path. Context returns plain msg.sender, so no forwarder confusion. A scratch test replayed the launch floor's 22 privileged selectors from both the factory and a stranger, plus unknown selectors and ETH-bearing calls. All reverted with supply and holder balances unchanged.\n- **Asymmetry.** The mint branch is reachable only from the constructor and the burn branch is unreachable because both external paths reject the zero address. Approve sets and spend decrements the same slot, with the unlimited sentinel behaving as the README documents. Transfer and transferFrom share the same internal guard, so no validation differs between them.\n- **Trust Gap.** With no privileged actor and no economic formula in the token there is no seam. The sole trust assumption is that the constructor caller, the factory, holds the entire supply at deployment, which the launch design requires.\n\n**One informational finding, outside my area.** DEPENDENCIES.md claims all vendored files are unmodified upstream copies verifiable with the shipped hash list, but that check fails for 7 forge-std files. The recorded digests match the upstream v1.9.7 archive, so the tree's copies were reformatted after hashing. The diff is formatting only, and forge-std is a test-only dependency, so deployed bytecode is unaffected. The reproduction is:\n\n```\nsha256sum -c DEPENDENCIES.sha256   # 29 OK, 7 FAILED, exit 1\n```\n\nCoverage has 10 rows: the three ABI entry points hold, the constructor and invariant rows hold, provenance points to the finding, and the protected launch harness is marked unreached because its seed-and-swap test needs Uniswap v4 contracts and environment variables absent from the tree. Build, the existing 31 tests and `forge fmt --check` all pass. Slither reported nothing and the aderyn large-literal lead is the correct value of one billion times ten to the eighteenth.","treeHash":null,"usage":{"cachedInputTokens":716724,"inputTokens":290,"model":"claude-fable-5-1","outputTokens":17296,"runtime":"claude","turns":28,"wallClockMs":300834}},{"artifacts":[],"attempt":1,"bundleHash":"99fc264a1a22015cb9ab1259eadf67df2e2a3d8d9421c8e1b0e97fd9465b737a","device":"e89087c02a1681bf","findings":[],"hash":"42fc03055ddbf81e05c9cd806b6dcf0e072f3617342263bdc1ed814db4c2e200","nodeId":"a481f97d-191e-4a36-92ff-892cc4c426d9","outcome":"completed","summary":"Added 9 edge-case tests and strengthened invariants for balances, allowances, failed-call rollback, and fixed supply.\n\n`forge build` and `forge test` pass offline, including 256 invariant sequences totaling 16,384 calls.\n\nOnly `test/` changed. No defects found.","treeHash":"97c3482b5db34104a2f55cec44de89c1e1c36b0f","usage":{"cachedInputTokens":588928,"inputTokens":62950,"model":"gpt-6-astra","outputTokens":9256,"runtime":"codex","turns":5,"wallClockMs":287711}},{"artifacts":[],"attempt":1,"bundleHash":null,"device":"bc1e515ca5c78ac4","findings":[{"citation":"resolved","description":"Merged from four specialist reports (audit_economics, audit_permissions, audit_flow, audit_math), all describing the same root cause. DEPENDENCIES.md states that every vendored file is an unmodified upstream copy and that an offline verifier can confirm this with `sha256sum -c DEPENDENCIES.sha256`. On the committed tree (HEAD e26757a, clean) that command reports 7 of 36 files FAILED: lib/forge-std/src/StdAssertions.sol, StdJson.sol, StdToml.sol, Vm.sol, console.sol, interfaces/IERC7540.sol and interfaces/IMulticall3.sol. I fetched the forge-std v1.9.7 release archive (its SHA-256 is 45157353ab49eab01d294565866731e599b32401757229689ee459aa26b7ee94, matching the digest DEPENDENCIES.md records) and diffed each of the seven files against the committed copy with all whitespace stripped: every diff is empty, so the committed files were reformatted (consistent with `forge fmt` having run over lib/) after the digests were recorded, and the recorded digests are the genuine upstream ones. The five OpenZeppelin v5.2.0 files and its LICENSE verify OK, so the only production dependency is byte-identical to upstream and the token's bytecode is unaffected; `forge build` and all 40 project tests pass. Impact is confined to provenance: the repository's integrity claim is false and the one offline check it tells a verifier to run exits non-zero. Fix: restore the seven files to their byte-exact v1.9.7 content (and keep lib/ out of `forge fmt`), or regenerate DEPENDENCIES.sha256 from the committed tree and reword line 10 so it no longer calls the forge-std copies unmodified. Severity is low: no fund, supply or transfer behaviour is involved.","line":10,"path":"DEPENDENCIES.md","reproduction":"State: clean checkout of HEAD e26757a. Run from the repository root: `sha256sum -c DEPENDENCIES.sha256; echo exit=$?`. Expected (per DEPENDENCIES.md line 10 and its last paragraph): 36 lines print OK and exit=0. Actual: 29 lines OK, then `lib/forge-std/src/StdAssertions.sol: FAILED`, `lib/forge-std/src/StdJson.sol: FAILED`, `lib/forge-std/src/StdToml.sol: FAILED`, `lib/forge-std/src/Vm.sol: FAILED`, `lib/forge-std/src/console.sol: FAILED`, `lib/forge-std/src/interfaces/IERC7540.sol: FAILED`, `lib/forge-std/src/interfaces/IMulticall3.sol: FAILED`, `sha256sum: WARNING: 7 computed checksums did NOT match`, exit=1. Concretely `sha256sum lib/forge-std/src/Vm.sol` prints a1b1c82924aecf0f38b53192fd1e801cccc1e1fd2ecd6b2301e4f4c4ab102a15 while DEPENDENCIES.sha256 line 18 records 9068805b59ac1d0ea03a8fa1f15ae49c094e0c6c852a2500e0dd112f264b2cb1. Cross-check: `diff <(tr -d ' \\n\\t\\r' < upstream-v1.9.7/src/Vm.sol) <(tr -d ' \\n\\t\\r' < lib/forge-std/src/Vm.sol)` is empty for all seven files, i.e. whitespace-only differences.","severity":"low","snippet":"The source files are unmodified upstream copies. These SHA-256 digests identify the downloaded release archives:","title":"DEPENDENCIES.sha256 does not match seven committed forge-std files, so the documented provenance check fails"}],"hash":"50b3a3a9b3440f30bf9aea433d2c89d4e2f7a74a20b117b479aa9a21a5c25ff9","nodeId":"326290aa-745f-4105-b1a9-a0270995d976","outcome":"completed","summary":"Review complete. The findings file is written and validated.\n\n**Outcome:** The token holds on every entry point. One low-severity finding survives, merged from all four specialists.\n\n**What I verified on the token**\n- IdentityUnits.sol is a 17-line subclass of unmodified OpenZeppelin v5.2.0 ERC20 with a no-argument constructor that mints the manifest supply to msg.sender. The OpenZeppelin files pass their recorded digests byte for byte.\n- A scratch Foundry test deploying through a CREATE2 factory confirmed: supply and decimals match launch.json, the factory holds everything, the swarm-share and claim flows arrive whole, allowance accounting is exact, 22 admin/mint/pause/blacklist/burnFrom selectors revert from both the factory and a stranger, there is no receive or fallback, and the runtime bytecode contains no DELEGATECALL, CALLCODE or SELFDESTRUCT. All five scratch tests and the project's 40 existing tests pass.\n- The manifest's initialPrice recomputes exactly from the stated market cap and supply.\n- The aderyn large-numeric-literal lead is a style note, not a defect.\n\n**The one finding (low):** DEPENDENCIES.md claims every vendored file is an unmodified upstream copy and tells a verifier to run `sha256sum -c DEPENDENCIES.sha256`. On the clean tree that command exits 1 with 7 forge-std files FAILED. I fetched the forge-std v1.9.7 archive, whose hash matches the one recorded, and confirmed each of the seven differs only in whitespace, so the recorded digests are the genuine upstream ones and the committed copies were reformatted after hashing. Production code and bytecode are unaffected since forge-std is test-only. Fix is to restore the byte-exact files or regenerate the digest file and reword the claim.\n\n**Coverage:** all three ABI entry points marked holds, plus rows for the constructor, the no-privilege invariant, manifest consistency and the static-analysis lead.\n\nThe protected test itself could not be executed here because it imports v4-core, which is not vendored in this tree. My scratch test reproduces its non-pool checks; the pool seed and swap checks rely on plain ERC20 transfer and transferFrom, which I traced as exact.","treeHash":null,"usage":{"cachedInputTokens":553659,"inputTokens":386,"model":"claude-fable-5-1","outputTokens":9005,"runtime":"claude","turns":13,"wallClockMs":138793}},{"artifacts":[],"attempt":1,"bundleHash":"e4e81bac7c0ff4335d68aeadd6a0a4654f997b1b9dcae1b6532cd048bf5da4f8","device":"e9bb398fec9e3e04","findings":[],"hash":"7bed4c6dd286b5c74422d46e28dd090bd00ca3107ae42af19252b266b021df04","nodeId":"77b9c2cb-d735-49c8-9fb4-83be1335b397","outcome":"completed","summary":"Created [launch.json](/root/.identitymd-45/work/a2bc39c9-ac0a-406a-8334-85bd1458728f/77b9c2cb-d735-49c8-9fb4-83be1335b397/launch.json) with the exact supply, verbatim economics, matching constructor arguments, and requested paired currency.\n\nSchema and ABI checks passed. `forge build` succeeded; `forge test` passed all 31 tests. Only `launch.json` is changed for submission.","treeHash":"3e0d66aadb711ad6b620885dee75caa54842eb3a","usage":{"cachedInputTokens":188288,"inputTokens":26962,"model":"gpt-6-astra","outputTokens":3281,"runtime":"codex","turns":3,"wallClockMs":73020}},{"artifacts":[],"attempt":3,"bundleHash":null,"device":"63458a1bd2b2d376","findings":[{"citation":"resolved","description":"Periphery/provenance. DEPENDENCIES.md states that every vendored file is an unmodified upstream copy and tells the verifier to confirm this with `sha256sum -c DEPENDENCIES.sha256`. Running that command on the committed tree fails for seven files under lib/forge-std/src (StdAssertions.sol, StdJson.sol, StdToml.sol, Vm.sol, console.sol, interfaces/IERC7540.sol, interfaces/IMulticall3.sol). I downloaded the forge-std v1.9.7 release archive (its SHA-256 matches the digest recorded in DEPENDENCIES.md) and diffed: the seven files differ from upstream only in whitespace/line wrapping (they appear to have been run through `forge fmt`), and the five vendored OpenZeppelin v5.2.0 files are byte-identical to upstream. So the production dependency is intact and the token's behaviour is unaffected, but the repository's own integrity claim is false and the file-level manifest cannot be used as written by an offline verifier. Either the seven files should be restored to the exact upstream bytes (so the manifest is true) or DEPENDENCIES.sha256 should be regenerated and DEPENDENCIES.md should stop calling the forge-std copies unmodified.","line":10,"path":"DEPENDENCIES.md","reproduction":"State: clean checkout of this tree. Input: run `sha256sum -c DEPENDENCIES.sha256` from the repository root. Expected (per DEPENDENCIES.md line 10 and line 17): every line prints OK and the command exits 0. Actual: 29 lines print OK, then `lib/forge-std/src/StdAssertions.sol: FAILED`, `lib/forge-std/src/StdJson.sol: FAILED`, `lib/forge-std/src/StdToml.sol: FAILED`, `lib/forge-std/src/Vm.sol: FAILED`, `lib/forge-std/src/console.sol: FAILED`, `lib/forge-std/src/interfaces/IERC7540.sol: FAILED`, `lib/forge-std/src/interfaces/IMulticall3.sol: FAILED`, `sha256sum: WARNING: 7 computed checksums did NOT match`, exit status 1. Cross-check: `curl -sSL https://codeload.github.com/foundry-rs/forge-std/tar.gz/refs/tags/v1.9.7 | sha256sum` gives 45157353ab49eab01d294565866731e599b32401757229689ee459aa26b7ee94 (matches DEPENDENCIES.md), and `diff upstream/src/Vm.sol lib/forge-std/src/Vm.sol` shows only re-wrapped function signatures; stripping all whitespace from both copies yields identical content for all seven files.","severity":"low","snippet":"The source files are unmodified upstream copies. These SHA-256 digests identify the downloaded release archives:","title":"DEPENDENCIES.sha256 does not match seven vendored forge-std files, so the documented provenance check fails"}],"hash":"97583bcadd6e97c9a94b459b9e62f20a96a5aad9370a062d8fb2bbb55a166f33","nodeId":"d4ef6237-1c5c-4852-8740-1cebc170f895","outcome":"completed","summary":"The review is complete and `.imd-findings.json` is written. The tree is otherwise untouched: the scratch test was removed and no tracked file changed.\n\n**Outcome.** The Identity Units token has no defect in its control flow. It is a seventeen-line wrapper over an unmodified OpenZeppelin v5.2.0 ERC20 with a no-argument constructor that mints exactly 10^27 units to the factory. One low-severity provenance defect was found outside the Solidity code.\n\n**What I checked, per the Execution Trace, Periphery and First Principles guides:**\n- Traced approve, transfer and transferFrom through the inherited code to final state. Every zero-address, insufficient-balance and insufficient-allowance path reverts atomically. The only sentinel is the unlimited allowance, which behaves as documented.\n- Confirmed there is no receive, fallback, callback, external call, owner, mint, burn, pause or upgrade entry point in the compiled ABI, and no dangerous opcode in the runtime.\n- Modelled the launch flows in a scratch Foundry harness: factory to distributor, distributor claims, pool seeding via transferFrom under a finite allowance, trader buy and sell under an unlimited allowance. Every flow moved exactly the stated amount and the supply stayed constant.\n- Diffed all five vendored OpenZeppelin files against the upstream v5.2.0 archive. They are byte-identical.\n- The existing project suite passes, 31 tests including fuzz and invariant runs.\n\n**The one finding, low severity.** DEPENDENCIES.md states that all vendored files are unmodified upstream copies and tells the verifier to confirm this with the committed checksum manifest. That command fails for seven forge-std files. I downloaded the forge-std v1.9.7 archive and confirmed the differences are whitespace and line wrapping only, so the test-only dependency is functionally intact. The repository's integrity claim is still false as written and should be fixed by restoring the exact upstream bytes or regenerating the manifest.\n\n**Coverage.** All three listed entry points hold, plus rows for the constructor, the fixed-supply invariant, the opcode invariant and both vendored dependencies. The protected launch harness is marked unreached because it needs Uniswap v4 sources and launch environment variables that are not in the tree. The behaviours it checks were traced in source and reproduced with stubs instead.","treeHash":null,"usage":{"cachedInputTokens":1139192,"inputTokens":450,"model":"claude-fable-5-1","outputTokens":16787,"runtime":"claude","turns":32,"wallClockMs":227466}},{"artifacts":[],"attempt":1,"bundleHash":null,"device":"7c748c02cd2ee98f","findings":[{"citation":"resolved","description":"DEPENDENCIES.md states that every vendored file is an unmodified upstream copy and that DEPENDENCIES.sha256 can be checked with `sha256sum -c DEPENDENCIES.sha256`. Running that command on the committed tree fails for seven forge-std files (StdAssertions.sol, StdJson.sol, StdToml.sol, Vm.sol, console.sol, interfaces/IERC7540.sol, interfaces/IMulticall3.sol). The digests recorded in DEPENDENCIES.sha256 are the genuine forge-std v1.9.7 digests (the upstream files fetched from the v1.9.7 tag hash to the recorded values), but the files committed under lib/forge-std/src/ were reformatted after vendoring (a whitespace-only diff, consistent with `forge fmt` having been run over lib/). The five OpenZeppelin v5.2.0 production files are byte-identical to upstream and their digests verify, so the token's runtime code is not affected; the defect is that the repository's own integrity claim is false and the check an offline verifier is told to run reports failure. Fix: either restore the seven forge-std files to their byte-exact v1.9.7 content (and exclude lib/ from `forge fmt`), or regenerate DEPENDENCIES.sha256 from the committed files and reword the 'unmodified upstream copies' sentence to say the forge-std files were reformatted.","line":10,"path":"DEPENDENCIES.md","reproduction":"State: the committed tree at HEAD (git status clean). Run `sha256sum -c DEPENDENCIES.sha256` from the repository root. Expected (per DEPENDENCIES.md): every line reports OK. Actual: 29 lines OK and 7 FAILED, ending with `sha256sum: WARNING: 7 computed checksums did NOT match`. Concretely, `sha256sum lib/forge-std/src/Vm.sol` prints a1b1c82924aecf0f38b53192fd1e801cccc1e1fd2ecd6b2301e4f4c4ab102a15 while DEPENDENCIES.sha256 line 18 records 9068805b59ac1d0ea03a8fa1f15ae49c094e0c6c852a2500e0dd112f264b2cb1, which is the digest of the upstream v1.9.7 Vm.sol. `diff <(tr -d ' \\n\\t' < upstream-v1.9.7/src/Vm.sol) <(tr -d ' \\n\\t' < lib/forge-std/src/Vm.sol)` is empty, showing the difference is whitespace only.","severity":"low","snippet":"The source files are unmodified upstream copies. These SHA-256 digests identify the downloaded release archives:","title":"Recorded dependency digests do not match the committed forge-std files, so the documented provenance check fails"}],"hash":"993ffcf4b0690eba8cfb30a2f3e65de4943f2424c773106bb2583d3435d41225","nodeId":"df526a31-3d32-44ec-9adc-e2369643de3f","outcome":"completed","summary":"The economics review is complete and the findings file is written. The token's economic behaviour holds; the only reproducible defect is a provenance inconsistency outside the economics area.\n\n**What I reviewed.** The token is a 17-line fixed-supply wrapper over OpenZeppelin v5.2.0 ERC20 with no constructor arguments, no roles, and no overrides. I checked it against the Senior Auditor's Mindset and the Economic Security, Invariant and Flow Gap guides, plus the x-ray token-behaviour matrix and the launch-flow requirements in the protected harness. I confirmed the five vendored OpenZeppelin files are byte-identical to the upstream v5.2.0 tag, built with solc 0.8.26, and ran the repo suite. All 31 tests and both invariants pass.\n\n**Economics area: no defects.**\n- Supply is exactly 1e27, minted once to the constructor caller, with no mint, burn, rebase, proxy or delegatecall path in the ABI or runtime bytecode.\n- Every launch flow is exact. There is no fee, tax, exemption list or balance cap, so the swarm share, pool seed, swaps and remainder transfer move precisely what they say. The token makes no external calls, so there is no reentrancy surface through the PoolManager.\n- The conservation invariant (sum of balances equals total supply) is preserved by the unmodified OZ update path, including self-transfers and zero-value transfers.\n- The aderyn large-literal lead evaluates to exactly 1e27 and is not a defect. Slither reported nothing.\n\n**One low finding, outside the area.** DEPENDENCIES.md claims all vendored files are unmodified upstream copies and tells verifiers to run the sha256 check. That check fails on seven forge-std files because they were reformatted after vendoring (whitespace-only diff, likely `forge fmt` over lib/). The recorded digests are the genuine v1.9.7 values, so the record is honest but the committed files are not. Production code is unaffected. Repro is in the file:\n\n```\nsha256sum -c DEPENDENCIES.sha256   # 29 OK, 7 FAILED\n```\n\n**Coverage.** All three entry points are marked `holds`, with nine additional rows for the supply, flow, privilege and provenance invariants I traced. Nothing was left unreached. The protected Uniswap v4 harness could not be run locally since its v4 and factory dependencies are not in this tree, so the seed and swap flows were verified by code reading rather than execution.","treeHash":null,"usage":{"cachedInputTokens":793923,"inputTokens":290,"model":"claude-fable-5-1","outputTokens":13871,"runtime":"claude","turns":24,"wallClockMs":215779}},{"artifacts":[],"attempt":1,"bundleHash":"9c113092138c883b36cf88b841bb6be08e40f6658b5ccc6e2bd0111ecc155dcf","device":"403561621f0b349a","findings":[],"hash":"a3fee385b5ba472b646ae9452e8a0ea37b535925db580712be3a91f9b100b478","nodeId":"61507187-e346-439f-9618-9dbe58a3bfbc","outcome":"completed","summary":"Implemented Identity Units (UI): **1,000,000,000 tokens, 18 decimals**, minted once to the deployer.\n\nIncluded vendored dependencies, success/failure tests, fuzz tests, supply invariants, and deployment/operations documentation.\n\nVerified with Solidity **0.8.26**:\n\n- `forge build` — passed\n- `forge test` — passed\n- `forge fmt --check` — passed\n\nThe external launch integration harness was not run; its requirements are documented.","treeHash":"511ab01abd1ebbdf2393fbaf77d6f2061610f64a","usage":{"cachedInputTokens":489088,"inputTokens":45116,"model":"gpt-6-astra","outputTokens":11602,"runtime":"codex","turns":5,"wallClockMs":342905}},{"artifacts":[],"attempt":1,"bundleHash":null,"device":"ddfb1efa72fe9a94","findings":[],"hash":"c524a6182ca75546014c9b3b3d605651ecc47925dca05ec1f906510dc5d35bf9","nodeId":"d4ef6237-1c5c-4852-8740-1cebc170f895","outcome":"failed","summary":"runtime reported <synthetic>, not the required premium model claude-fable-5-1","treeHash":null,"usage":{"cachedInputTokens":0,"inputTokens":0,"model":"<synthetic>","outputTokens":0,"runtime":"claude","turns":1,"wallClockMs":5001}},{"artifacts":[],"attempt":1,"bundleHash":null,"device":"4199bf0c80a9d6cf","findings":[{"citation":"resolved","description":"DEPENDENCIES.md states that the vendored files are unmodified upstream copies and that DEPENDENCIES.sha256 verifies them. In the committed tree (HEAD b3df6ba, clean working copy) the recorded digests for lib/forge-std/src/StdAssertions.sol, StdJson.sol, StdToml.sol, Vm.sol, console.sol, interfaces/IERC7540.sol and interfaces/IMulticall3.sol do not match the files actually committed (e.g. Vm.sol recorded 9068805b...2cb1, actual a1b1c829...2a15). All OpenZeppelin production files match their digests, so the token's production dependency is not affected and the build and tests pass; the defect is that the shipped provenance record is wrong for the test library, which defeats the offline verifier's only means of confirming the forge-std copy is the pinned v1.9.7 release. Outside the assigned math area; reported because it is concrete and reproducible. Fix: regenerate DEPENDENCIES.sha256 from the committed lib/ tree (or restore the v1.9.7 files whose digests are recorded) so `sha256sum -c DEPENDENCIES.sha256` exits 0.","line":17,"path":"DEPENDENCIES.md","reproduction":"State: checkout of HEAD b3df6ba, no local changes. Run `sha256sum -c DEPENDENCIES.sha256` from the repository root. Expected (per DEPENDENCIES.md): every line reports OK and the command exits 0. Actual: 7 lines report FAILED (lib/forge-std/src/StdAssertions.sol, StdJson.sol, StdToml.sol, Vm.sol, console.sol, interfaces/IERC7540.sol, interfaces/IMulticall3.sol), `sha256sum: WARNING: 7 computed checksums did NOT match`, exit status 1. `sha256sum lib/forge-std/src/Vm.sol` prints a1b1c82924aecf0f38b53192fd1e801cccc1e1fd2ecd6b2301e4f4c4ab102a15 while DEPENDENCIES.sha256 line 18 records 9068805b59ac1d0ea03a8fa1f15ae49c094e0c6c852a2500e0dd112f264b2cb1.","severity":"low","snippet":"`remappings.txt` resolves both dependencies locally. OpenZeppelin is the only production dependency; forge-std is used by tests. `DEPENDENCIES.sha256` records individual file hashes and can be checked with `sha256sum -c DEPENDENCIES.sha256`.","title":"DEPENDENCIES.sha256 does not match seven committed forge-std files, so the documented provenance check fails"}],"hash":"d5c3fada07e66f55d9f306ae2884eb1c0d325e5fd04b254c37ed00fe2327256b","nodeId":"2df32cb4-76ae-46ed-9bc5-c4368fe640b3","outcome":"completed","summary":"The findings file is in place and excluded from git by the repository's own exclude rule. Only build output and the findings file are untracked, both ignored, and the scratch directory is removed. The review is complete.\n\n**Outcome: no math, boundary or numerical-gap defects in the token.** One low finding outside my area is recorded in `.imd-findings.json`, with nine coverage rows.\n\n**What was audited.** The token is a 17-line contract inheriting the vendored OpenZeppelin v5.2.0 ERC-20 with a constructor that mints one fixed constant to the deployer. The constant is computed at compile time and equals the minor-unit supply the README gives. There is no division, no downcast, no decimal scaling, no external call, no payable path and no bytes decoding anywhere in the token or its base. The only sentinels are the zero address, which always reverts, and the unlimited-allowance value, which is handled as documented.\n\n**Checks I ran.**\n- The existing suite: 31 tests and the invariant run with revert-on-failure, all passing.\n- A scratch Foundry test, since deleted, covering the unlimited allowance, an allowance of max minus one, full-supply transfer, a transfer that would exceed supply, spender equal to owner, zero-value transferFrom with no allowance, ether sent to the token, and a fuzz over received sums. All behaved as specified.\n- OpenZeppelin digests from the hash manifest all match the committed files.\n\n**The one finding (low).** The committed hash manifest fails for seven forge-std test-library files, so the documented verification command exits non-zero. Production code is unaffected and builds and tests pass. The reproduction is:\n\n```\nsha256sum -c DEPENDENCIES.sha256\n```\n\n**Coverage.** All three listed entry points hold, as do the constructor, decimals, the supply-conservation invariant, and the native-value and external-call boundaries. The provenance row points to the finding. Nothing in my area was left unreached.","treeHash":null,"usage":{"cachedInputTokens":702582,"inputTokens":290,"model":"claude-fable-5-1","outputTokens":12918,"runtime":"claude","turns":27,"wallClockMs":192717}}],"verification":[{"checks":[{"durationMs":2614,"exitCode":0,"name":"build","output":"Compiling 28 files with Solc 0.8.26\nSolc 0.8.26 finished in 2.41s\nCompiler run successful!\n","passed":true},{"durationMs":9436,"exitCode":0,"name":"test","output":"No files changed, compilation skipped\n\nRan 30 tests for test/IdentityUnits.t.sol:IdentityUnitsTest\n[PASS] testFuzz_constructorCreditsImmediateDeployer(address) (runs: 512, μ: 18159, ~: 18159)\n[PASS] testFuzz_overspendingAllowanceReverts(uint256,uint256) (runs: 512, μ: 116229, ~: 116738)\nLogs:\n  Bound result 999999999999999999999999999\n  Bound result 1\n\n[PASS] testFuzz_overspendingBalanceReverts(uint256,uint256) (runs: 512, μ: 120202, ~: 120429)\nLogs:\n  Bound result 18\n  Bound result 115792089237316195423570985008687907853269984665640564039457584007913129639916\n\n[PASS] testFuzz_transferConservesSupply(address,uint256) (runs: 512, μ: 92908, ~: 93051)\nLogs:\n  Bound result 149058171945587310225248945\n\n[PASS] testFuzz_transferFromAccounting(uint256,uint256) (runs: 512, μ: 156167, ~: 158181)\nLogs:\n  Bound result 652868650099074656967627418\n  Bound result 213303482313916597186474510\n\n[PASS] test_allowanceBelongsToSpecificSpender() (gas: 98473)\n[PASS] test_approveEmitsEventAndCanBeReplacedOrRevoked() (gas: 150332)\n[PASS] test_approveZeroSpenderReverts() (gas: 37596)\n[PASS] test_constructorEmitsExactlyOneMint() (gas: 9654)\n[PASS] test_create2FactoryAllocationAndExactDistribution() (gas: 416648)\n[PASS] test_deployerCannotSpendHolderBalanceWithoutApproval() (gas: 92583)\n[PASS] test_infiniteAllowancePersistsAndCanBeRevoked() (gas: 179615)\n[PASS] test_metadataAndInitialAllocation() (gas: 103382)\n[PASS] test_noMintBurnOrAdministrativeEntryPoints() (gas: 689544)\n[PASS] test_runtimeContainsNoDangerousOpcodes() (gas: 785970)\n[PASS] test_selfTransferPreservesBalanceAndSupply() (gas: 51387)\n[PASS] test_transferEmitsEventAndMovesExactAmount() (gas: 88881)\n[PASS] test_transferEntireSupplyAndOneSmallestUnitBack() (gas: 134722)\n[PASS] test_transferFromConsumesFiniteAllowanceAndEmitsTransfer() (gas: 218121)\n[PASS] test_transferFromInsufficientAllowanceRollsBack() (gas: 108960)\n[PASS] test_transferFromInsufficientBalanceRestoresAllowance() (gas: 104302)\n[PASS] test_transferFromToSelfStillConsumesAllowance() (gas: 100985)\n[PASS] test_transferFromToZeroRestoresAllowance() (gas: 111893)\n[PASS] test_transferFromZeroSenderReverts() (gas: 50223)\n[PASS] test_transferInsufficientBalanceReverts() (gas: 50450)\n[PASS] test_transferMaxUintReverts() (gas: 40121)\n[PASS] test_transferToZeroRevertsWithoutBurning() (gas: 47576)\n[PASS] test_zeroTransferFromEmptyAccountEmitsEvent() (gas: 56141)\n[PASS] test_zeroTransferFromNeedsNoAllowance() (gas: 57069)\n[PASS] test_zeroTransferToZeroAlsoReverts() (gas: 30434)\nSuite result: ok. 30 passed; 0 failed; 0 skipped; finished in 97.99ms (237.01ms CPU time)\n\nRan 9 tests for test/IdentityUnits.edge.t.sol:IdentityUnitsEdgeTest\n[PASS] testFuzz_insufficientBalancePreservesArbitraryAllowance(uint256,uint256,uint256) (runs: 1000, μ: 198661, ~: 199434)\nLogs:\n  Bound result 95\n  Bound result 2626\n  Bound result 123000000000000000000\n\n[PASS] testFuzz_replacingAllowanceLimitsTheNextSpend(uint256,uint256) (runs: 1000, μ: 228370, ~: 228598)\nLogs:\n  Bound result 820790993813283013484835077\n\n[PASS] testFuzz_roundTripPreservesBalancesAndApprovals(uint256,uint256) (runs: 1000, μ: 254454, ~: 254560)\nLogs:\n  Bound result 12\n\n[PASS] testFuzz_splittingDelegatedTransferMatchesSingleTransfer(uint256,uint256,uint256) (runs: 1000, μ: 348218, ~: 354747)\nLogs:\n  Bound result 46612919877\n  Bound result 17415421062\n\n[PASS] test_allowanceCannotBeBorrowedFromAnotherOwner() (gas: 235373)\n[PASS] test_exhaustedAllowanceCannotBeUsedTwice() (gas: 163046)\n[PASS] test_maximumMinusOneIsFiniteAndFullSupplyCanBeSpent() (gas: 200806)\n[PASS] test_transferFromByOwnerRequiresItsOwnAllowance() (gas: 162425)\n[PASS] test_zeroDelegatedTransferToZeroStillReverts() (gas: 61748)\nSuite result: ok. 9 passed; 0 failed; 0 skipped; finished in 98.24ms (388.38ms CPU time)\n\nRan 1 test for test/IdentityUnits.invariant.t.sol:IdentityUnitsInvariantTest\n[PASS]\nIdentityUnitsInvariantTest invariants:\n[PASS] invariant_allBalancesConserveSupply\n[PASS] invariant_balancesAndAllowancesMatchAuthorizedActions\n[PASS] invariant_supplyAlwaysEqualsOneBillionUI\n IdentityUnitsInvariantTest invariants (runs: 256, calls: 16384, reverts: 0)\n\n╭----------------------+---------------------------+-------+---------+----------╮\n| Contract             | Selector                  | Calls | Reverts | Discards |\n+===============================================================================+\n| IdentityUnitsHandler | approve                   | 2085  | 0       | 0        |\n|----------------------+---------------------------+-------+---------+----------|\n| IdentityUnitsHandler | rejectZeroReceiver        | 1991  | 0       | 0        |\n|----------------------+---------------------------+-------+---------+----------|\n| IdentityUnitsHandler | rejectZeroSpender         | 2036  | 0       | 0        |\n|----------------------+---------------------------+-------+---------+----------|\n| IdentityUnitsHandler | transfer                  | 2008  | 0       | 0        |\n|----------------------+---------------------------+-------+---------+----------|\n| IdentityUnitsHandler | transferFrom              | 2098  | 0       | 0        |\n|----------------------+---------------------------+-------+---------+----------|\n| IdentityUnitsHandler | transferFromOverAllowance | 2004  | 0       | 0        |\n|----------------------+---------------------------+-------+---------+----------|\n| IdentityUnitsHandler | transferFromOverBalance   | 2110  | 0       | 0        |\n|----------------------+---------------------------+-------+---------+----------|\n| IdentityUnitsHandler | transferOverBalance       | 2052  | 0       | 0        |\n╰----------------------+---------------------------+-------+---------+----------╯\n\nLogs:\n  Bound result 0\n  Bound result 6329\n  Bound result 170918512465535399490309296\n  Bound result 0\n  Bound result 117300738\n  Bound result 0\n  Bound result 115792089237316195423570985008687907853269984665640314039457584007913129633606\n  Bound result 2827\n  Bound result 0\n  Bound result 2\n  Bound result 9440\n  Bound result 4965\n  Bound result 255\n  Bound result 100\n  Bound result 7562\n  Bound result 24301\n  Bound result 40\n  Bound result 4810028720\n  Bound result 1\n  Bound result 25783047350465987068874547\n  Bound result 2\n  Bound result 60\n  Bound result 880\n  Bound result 3068136830458\n  Bound result 5968\n  Bound result 4030\n  Bound result 9616\n  Bound result 5191\n  Bound result 51966\n  Bound result 2592286113\n  Bound result 77915524974019083819912717298425565500630304021\n  Bound result 5374\n  Bound result 161902283151707198402\n  Bound result 1\n  Bound result 3834\n  Bound result 100\n  Bound result 6\n  Bound result 95\n  Bound result 6747\n  Bound result 477\n  Bound result 60\n  Bound result 1000000000000000000\n  Bound result 5609\n  Bound result 2\n  Bound result 214122333560001130396640538\n  Bound result 10435\n  Bound result 3310\n  Bound result 273643287483667063646813708\n\nSuite result: ok. 1 passed; 0 failed; 0 skipped; finished in 9.29s (9.29s CPU time)\n\nRan 3 test suites in 9.30s (9.49s CPU time): 40 tests passed, 0 failed, 0 skipped (40 total tests)\n","passed":true},{"durationMs":59,"exitCode":0,"name":"source-index","output":"{\"v\":1,\"entryPoints\":[\"IdentityUnits.approve(address,uint256)\",\"IdentityUnits.transfer(address,uint256)\",\"IdentityUnits.transferFrom(address,address,uint256)\"],\"files\":{\".gitignore\":3,\"DEPENDENCIES.md\":17,\"DEPENDENCIES.sha256\":36,\"README.md\":63,\"foundry.toml\":20,\"remappings.txt\":2,\"src/IdentityUnits.sol\":17,\"test/IdentityUnits.edge.t.sol\":165,\"test/IdentityUnits.invariant.t.sol\":200,\"test/IdentityUnits.t.sol\":367},\"excluded\":[\"lib/\",\"node_modules/\"],\"truncated\":false}","passed":true}],"detail":"all checks passed","evaluation":"checks","profile":"foundry","status":"accepted","submissionHash":"42fc03055ddbf81e05c9cd806b6dcf0e072f3617342263bdc1ed814db4c2e200","verifiedTreeHash":"97c3482b5db34104a2f55cec44de89c1e1c36b0f","verifierVersion":"0.1.0+94826a22"},{"checks":[{"durationMs":4003,"exitCode":0,"name":"build","output":"Compiling 27 files with Solc 0.8.26\nSolc 0.8.26 finished in 3.59s\nCompiler run successful!\n","passed":true},{"durationMs":1905,"exitCode":0,"name":"test","output":"No files changed, compilation skipped\n\nRan 30 tests for test/IdentityUnits.t.sol:IdentityUnitsTest\n[PASS] testFuzz_constructorCreditsImmediateDeployer(address) (runs: 512, μ: 18159, ~: 18159)\n[PASS] testFuzz_overspendingAllowanceReverts(uint256,uint256) (runs: 512, μ: 116356, ~: 116750)\nLogs:\n  Bound result 9343\n  Bound result 12407\n\n[PASS] testFuzz_overspendingBalanceReverts(uint256,uint256) (runs: 512, μ: 120379, ~: 120435)\nLogs:\n  Bound result 703290621\n  Bound result 11118036947724443187032\n\n[PASS] testFuzz_transferConservesSupply(address,uint256) (runs: 512, μ: 92588, ~: 93063)\nLogs:\n  Bound result 881245466435073235572178479\n\n[PASS] testFuzz_transferFromAccounting(uint256,uint256) (runs: 512, μ: 156601, ~: 158193)\nLogs:\n  Bound result 703290621\n  Bound result 499938032\n\n[PASS] test_allowanceBelongsToSpecificSpender() (gas: 98473)\n[PASS] test_approveEmitsEventAndCanBeReplacedOrRevoked() (gas: 150332)\n[PASS] test_approveZeroSpenderReverts() (gas: 37596)\n[PASS] test_constructorEmitsExactlyOneMint() (gas: 9654)\n[PASS] test_create2FactoryAllocationAndExactDistribution() (gas: 416648)\n[PASS] test_deployerCannotSpendHolderBalanceWithoutApproval() (gas: 92583)\n[PASS] test_infiniteAllowancePersistsAndCanBeRevoked() (gas: 179615)\n[PASS] test_metadataAndInitialAllocation() (gas: 103382)\n[PASS] test_noMintBurnOrAdministrativeEntryPoints() (gas: 689544)\n[PASS] test_runtimeContainsNoDangerousOpcodes() (gas: 785970)\n[PASS] test_selfTransferPreservesBalanceAndSupply() (gas: 51387)\n[PASS] test_transferEmitsEventAndMovesExactAmount() (gas: 88881)\n[PASS] test_transferEntireSupplyAndOneSmallestUnitBack() (gas: 134722)\n[PASS] test_transferFromConsumesFiniteAllowanceAndEmitsTransfer() (gas: 218121)\n[PASS] test_transferFromInsufficientAllowanceRollsBack() (gas: 108960)\n[PASS] test_transferFromInsufficientBalanceRestoresAllowance() (gas: 104302)\n[PASS] test_transferFromToSelfStillConsumesAllowance() (gas: 100985)\n[PASS] test_transferFromToZeroRestoresAllowance() (gas: 111893)\n[PASS] test_transferFromZeroSenderReverts() (gas: 50223)\n[PASS] test_transferInsufficientBalanceReverts() (gas: 50450)\n[PASS] test_transferMaxUintReverts() (gas: 40121)\n[PASS] test_transferToZeroRevertsWithoutBurning() (gas: 47576)\n[PASS] test_zeroTransferFromEmptyAccountEmitsEvent() (gas: 56141)\n[PASS] test_zeroTransferFromNeedsNoAllowance() (gas: 57069)\n[PASS] test_zeroTransferToZeroAlsoReverts() (gas: 30434)\nSuite result: ok. 30 passed; 0 failed; 0 skipped; finished in 44.52ms (214.38ms CPU time)\n\nRan 1 test for test/IdentityUnits.invariant.t.sol:IdentityUnitsInvariantTest\n[PASS]\nIdentityUnitsInvariantTest invariants:\n[PASS] invariant_allBalancesConserveSupply\n[PASS] invariant_supplyAlwaysEqualsOneBillionUI\n IdentityUnitsInvariantTest invariants (runs: 128, calls: 8192, reverts: 0)\n\n╭----------------------+--------------+-------+---------+----------╮\n| Contract             | Selector     | Calls | Reverts | Discards |\n+==================================================================+\n| IdentityUnitsHandler | approve      | 2800  | 0       | 0        |\n|----------------------+--------------+-------+---------+----------|\n| IdentityUnitsHandler | transfer     | 2751  | 0       | 0        |\n|----------------------+--------------+-------+---------+----------|\n| IdentityUnitsHandler | transferFrom | 2641  | 0       | 0        |\n╰----------------------+--------------+-------+---------+----------╯\n\nLogs:\n  Bound result 1767051332833740374\n  Bound result 6181\n  Bound result 3272\n  Bound result 92050009204436586545478687\n  Bound result 2592286112\n  Bound result 0\n  Bound result 0\n  Bound result 0\n  Bound result 254\n  Bound result 659919\n  Bound result 598131755636021426960871484\n  Bound result 0\n  Bound result 0\n  Bound result 0\n  Bound result 1000000000\n  Bound result 211801472\n  Bound result 0\n  Bound result 0\n  Bound result 0\n  Bound result 334\n  Bound result 957625570\n  Bound result 56\n  Bound result 1857123999\n  Bound result 1225804541158519513\n  Bound result 0\n  Bound result 26\n  Bound result 16\n  Bound result 0\n  Bound result 411\n  Bound result 0\n  Bound result 24301\n  Bound result 14\n  Bound result 0\n  Bound result 2\n  Bound result 0\n  Bound result 5379\n  Bound result 6461\n  Bound result 0\n  Bound result 18\n  Bound result 479425079593727744567321212\n  Bound result 450\n  Bound result 11\n  Bound result 1475\n  Bound result 100\n  Bound result 3\n  Bound result 1553\n  Bound result 60\n  Bound result 4764\n  Bound result 553\n  Bound result 6141\n  Bound result 4332\n  Bound result 4\n  Bound result 558\n  Bound result 0\n  Bound result 4967\n  Bound result 694364877662233200315262974\n  Bound result 161\n  Bound result 51966\n  Bound result 0\n  Bound result 767197786402972777676857069\n  Bound result 3213\n  Bound result 2987\n  Bound result 5\n  Bound result 7\n\nSuite result: ok. 1 passed; 0 failed; 0 skipped; finished in 1.62s (1.62s CPU time)\n\nRan 2 test suites in 1.63s (1.67s CPU time): 31 tests passed, 0 failed, 0 skipped (31 total tests)\n","passed":true},{"durationMs":144,"exitCode":0,"name":"source-index","output":"{\"v\":1,\"entryPoints\":[\"IdentityUnits.approve(address,uint256)\",\"IdentityUnits.transfer(address,uint256)\",\"IdentityUnits.transferFrom(address,address,uint256)\"],\"files\":{\".gitignore\":3,\"DEPENDENCIES.md\":17,\"DEPENDENCIES.sha256\":36,\"README.md\":63,\"foundry.toml\":20,\"launch.json\":20,\"remappings.txt\":2,\"src/IdentityUnits.sol\":17,\"test/IdentityUnits.invariant.t.sol\":83,\"test/IdentityUnits.t.sol\":367},\"excluded\":[\"lib/\",\"node_modules/\"],\"truncated\":false}","passed":true}],"detail":"all checks passed","evaluation":"checks","profile":"foundry","status":"accepted","submissionHash":"7bed4c6dd286b5c74422d46e28dd090bd00ca3107ae42af19252b266b021df04","verifiedTreeHash":"3e0d66aadb711ad6b620885dee75caa54842eb3a","verifierVersion":"0.1.0+94826a22"},{"checks":[{"durationMs":2028,"exitCode":0,"name":"build","output":"Compiling 27 files with Solc 0.8.26\nSolc 0.8.26 finished in 1.84s\nCompiler run successful!\n","passed":true},{"durationMs":1271,"exitCode":0,"name":"test","output":"No files changed, compilation skipped\n\nRan 30 tests for test/IdentityUnits.t.sol:IdentityUnitsTest\n[PASS] testFuzz_constructorCreditsImmediateDeployer(address) (runs: 512, μ: 18159, ~: 18159)\n[PASS] testFuzz_overspendingAllowanceReverts(uint256,uint256) (runs: 512, μ: 116148, ~: 116762)\nLogs:\n  Bound result 2827\n  Bound result 4975\n\n[PASS] testFuzz_overspendingBalanceReverts(uint256,uint256) (runs: 512, μ: 120074, ~: 120435)\nLogs:\n  Bound result 999257395720972835870701740\n  Bound result 185348932935498903\n\n[PASS] testFuzz_transferConservesSupply(address,uint256) (runs: 512, μ: 92856, ~: 93063)\nLogs:\n  Bound result 402478631772829789049422560\n\n[PASS] testFuzz_transferFromAccounting(uint256,uint256) (runs: 512, μ: 156258, ~: 158199)\nLogs:\n  Bound result 20107\n  Bound result 19112\n\n[PASS] test_allowanceBelongsToSpecificSpender() (gas: 98473)\n[PASS] test_approveEmitsEventAndCanBeReplacedOrRevoked() (gas: 150332)\n[PASS] test_approveZeroSpenderReverts() (gas: 37596)\n[PASS] test_constructorEmitsExactlyOneMint() (gas: 9654)\n[PASS] test_create2FactoryAllocationAndExactDistribution() (gas: 416648)\n[PASS] test_deployerCannotSpendHolderBalanceWithoutApproval() (gas: 92583)\n[PASS] test_infiniteAllowancePersistsAndCanBeRevoked() (gas: 179615)\n[PASS] test_metadataAndInitialAllocation() (gas: 103382)\n[PASS] test_noMintBurnOrAdministrativeEntryPoints() (gas: 689544)\n[PASS] test_runtimeContainsNoDangerousOpcodes() (gas: 785970)\n[PASS] test_selfTransferPreservesBalanceAndSupply() (gas: 51387)\n[PASS] test_transferEmitsEventAndMovesExactAmount() (gas: 88881)\n[PASS] test_transferEntireSupplyAndOneSmallestUnitBack() (gas: 134722)\n[PASS] test_transferFromConsumesFiniteAllowanceAndEmitsTransfer() (gas: 218121)\n[PASS] test_transferFromInsufficientAllowanceRollsBack() (gas: 108960)\n[PASS] test_transferFromInsufficientBalanceRestoresAllowance() (gas: 104302)\n[PASS] test_transferFromToSelfStillConsumesAllowance() (gas: 100985)\n[PASS] test_transferFromToZeroRestoresAllowance() (gas: 111893)\n[PASS] test_transferFromZeroSenderReverts() (gas: 50223)\n[PASS] test_transferInsufficientBalanceReverts() (gas: 50450)\n[PASS] test_transferMaxUintReverts() (gas: 40121)\n[PASS] test_transferToZeroRevertsWithoutBurning() (gas: 47576)\n[PASS] test_zeroTransferFromEmptyAccountEmitsEvent() (gas: 56141)\n[PASS] test_zeroTransferFromNeedsNoAllowance() (gas: 57069)\n[PASS] test_zeroTransferToZeroAlsoReverts() (gas: 30434)\nSuite result: ok. 30 passed; 0 failed; 0 skipped; finished in 28.96ms (151.78ms CPU time)\n\nRan 1 test for test/IdentityUnits.invariant.t.sol:IdentityUnitsInvariantTest\n[PASS]\nIdentityUnitsInvariantTest invariants:\n[PASS] invariant_allBalancesConserveSupply\n[PASS] invariant_supplyAlwaysEqualsOneBillionUI\n IdentityUnitsInvariantTest invariants (runs: 128, calls: 8192, reverts: 0)\n\n╭----------------------+--------------+-------+---------+----------╮\n| Contract             | Selector     | Calls | Reverts | Discards |\n+==================================================================+\n| IdentityUnitsHandler | approve      | 2728  | 0       | 0        |\n|----------------------+--------------+-------+---------+----------|\n| IdentityUnitsHandler | transfer     | 2716  | 0       | 0        |\n|----------------------+--------------+-------+---------+----------|\n| IdentityUnitsHandler | transferFrom | 2748  | 0       | 0        |\n╰----------------------+--------------+-------+---------+----------╯\n\nLogs:\n  Bound result 123000000000000000000\n  Bound result 0\n  Bound result 127\n  Bound result 51966\n  Bound result 0\n  Bound result 11\n  Bound result 2\n  Bound result 0\n  Bound result 0\n  Bound result 0\n  Bound result 4865\n  Bound result 18\n  Bound result 910472749550851594492877979\n  Bound result 4\n  Bound result 2\n  Bound result 123000000000000051954\n  Bound result 0\n  Bound result 96\n  Bound result 0\n  Bound result 0\n  Bound result 0\n  Bound result 0\n  Bound result 7376\n  Bound result 57\n  Bound result 13\n  Bound result 5241\n  Bound result 95\n  Bound result 693\n  Bound result 1000000000000000000\n  Bound result 9\n  Bound result 0\n  Bound result 0\n  Bound result 6036\n  Bound result 778\n  Bound result 858\n  Bound result 668\n  Bound result 53\n  Bound result 123000000000000000000\n  Bound result 51966\n  Bound result 127\n  Bound result 1074\n  Bound result 0\n  Bound result 95\n  Bound result 0\n  Bound result 24301\n  Bound result 343\n  Bound result 142\n  Bound result 5258\n  Bound result 5629491\n  Bound result 1\n  Bound result 0\n  Bound result 242\n  Bound result 0\n  Bound result 60\n  Bound result 404098524\n  Bound result 5621\n  Bound result 51966\n  Bound result 6\n  Bound result 246000000000000056807\n  Bound result 124\n  Bound result 2746\n  Bound result 0\n  Bound result 957449257536741836603726457\n  Bound result 11\n  Bound result 1000000000000000000000000000\n\nSuite result: ok. 1 passed; 0 failed; 0 skipped; finished in 1.12s (1.12s CPU time)\n\nRan 2 test suites in 1.12s (1.15s CPU time): 31 tests passed, 0 failed, 0 skipped (31 total tests)\n","passed":true},{"durationMs":60,"exitCode":0,"name":"source-index","output":"{\"v\":1,\"entryPoints\":[\"IdentityUnits.approve(address,uint256)\",\"IdentityUnits.transfer(address,uint256)\",\"IdentityUnits.transferFrom(address,address,uint256)\"],\"files\":{\".gitignore\":3,\"DEPENDENCIES.md\":17,\"DEPENDENCIES.sha256\":36,\"README.md\":63,\"foundry.toml\":20,\"remappings.txt\":2,\"src/IdentityUnits.sol\":17,\"test/IdentityUnits.invariant.t.sol\":83,\"test/IdentityUnits.t.sol\":367},\"excluded\":[\"lib/\",\"node_modules/\"],\"truncated\":false}","passed":true},{"durationMs":751,"exitCode":0,"name":"slither","output":"slither: no results at low impact or above","passed":true},{"durationMs":236,"exitCode":0,"name":"aderyn","output":"[low] large-numeric-literal at src/IdentityUnits.sol:10: Large Numeric Literal","passed":true}],"detail":"all checks passed","evaluation":"checks","profile":"foundry","status":"accepted","submissionHash":"a3fee385b5ba472b646ae9452e8a0ea37b535925db580712be3a91f9b100b478","verifiedTreeHash":"511ab01abd1ebbdf2393fbaf77d6f2061610f64a","verifierVersion":"0.1.0+94826a22"}]}