{"assessments":[],"deployments":[],"fuzz":[],"identity":{"adapter":"0xde152afb7db5373f34876e1499fbd893a82dd336","chainId":1,"collection":"0x0000ec93127baa929e58e97dd0095a2bfb38ec1d","registry":"0x8004a169fb4a3325136eb29fa0ceb6d2e539a432"},"interpretation":"Records acceptance and evidence. Neither completion nor an AI assessment establishes correctness, safety, or independent review.","jobId":"54901d48-36f3-40c2-a126-108c8702136c","kind":"shape:chain","nodes":[{"acceptedSubmissionHash":"9737c5ec4e6fef7aa9bcfb2de0bee09b165d82e86e57abc26bb4c6f7c47fcda5","dependsOn":["build_contract_project"],"execution":{"network":false,"profile":"foundry","requires":[],"skillHash":"e5ac2cb1fd91a56aa40b16487fc230c48de0d317c8266140331dd3219bb40a85","skillId":"audit-specialist","tools":[]},"key":"audit_economics","kind":"code","role":"review","skillHash":"e5ac2cb1fd91a56aa40b16487fc230c48de0d317c8266140331dd3219bb40a85","skillId":"audit-specialist","state":"accepted"},{"acceptedSubmissionHash":"84dd70e4fce0c711aec8128496ec6571b261671e02c2d5706b4c08ff0c172009","dependsOn":["build_contract_project"],"execution":{"network":false,"profile":"foundry","requires":[],"skillHash":"e5ac2cb1fd91a56aa40b16487fc230c48de0d317c8266140331dd3219bb40a85","skillId":"audit-specialist","tools":[]},"key":"audit_flow","kind":"code","role":"review","skillHash":"e5ac2cb1fd91a56aa40b16487fc230c48de0d317c8266140331dd3219bb40a85","skillId":"audit-specialist","state":"accepted"},{"acceptedSubmissionHash":"941128cf3c4153b35068b97b3ee6c971c44296065ac48f8f05eaa7a852b22f1d","dependsOn":["build_contract_project","write_foundry_tests","manifest","audit_math","audit_permissions","audit_economics","audit_flow"],"execution":{"network":false,"profile":"foundry","requires":[],"skillHash":"3014f1ea5961918ca059453a484bf4c8bcbbfc2248dbe31d94ac7c5cdf8f50bd","skillId":"audit-judge","tools":[]},"key":"audit_judge","kind":"code","role":"review","skillHash":"3014f1ea5961918ca059453a484bf4c8bcbbfc2248dbe31d94ac7c5cdf8f50bd","skillId":"audit-judge","state":"accepted"},{"acceptedSubmissionHash":"4f06c1cb08dedd3649131bba9633f853a7d92f40e887af8494ed4d55f16e5996","dependsOn":["build_contract_project"],"execution":{"network":false,"profile":"foundry","requires":[],"skillHash":"e5ac2cb1fd91a56aa40b16487fc230c48de0d317c8266140331dd3219bb40a85","skillId":"audit-specialist","tools":[]},"key":"audit_math","kind":"code","role":"review","skillHash":"e5ac2cb1fd91a56aa40b16487fc230c48de0d317c8266140331dd3219bb40a85","skillId":"audit-specialist","state":"accepted"},{"acceptedSubmissionHash":"9b210483f79ce815301ec0b524f89ccdd35357fd3d990b9a57405e336441704d","dependsOn":["build_contract_project"],"execution":{"network":false,"profile":"foundry","requires":[],"skillHash":"e5ac2cb1fd91a56aa40b16487fc230c48de0d317c8266140331dd3219bb40a85","skillId":"audit-specialist","tools":[]},"key":"audit_permissions","kind":"code","role":"review","skillHash":"e5ac2cb1fd91a56aa40b16487fc230c48de0d317c8266140331dd3219bb40a85","skillId":"audit-specialist","state":"accepted"},{"acceptedSubmissionHash":"b340de3927f4f1af40a8567d4206a37a96e78a92c78db357ae4695474409e97b","dependsOn":[],"execution":{"network":false,"profile":"foundry","requires":[],"skillHash":"b6503de65ad02f845827887c23da4c3b56ccc5df7a459db263bae6e549d92f7f","skillId":"build-contract-project","tools":[]},"key":"build_contract_project","kind":"code","role":"implement","skillHash":"b6503de65ad02f845827887c23da4c3b56ccc5df7a459db263bae6e549d92f7f","skillId":"build-contract-project","state":"accepted"},{"acceptedSubmissionHash":"4964a1fabea0bba2e33deed90f7c2491cd762b475f0a6e428deffc832d93550a","dependsOn":["build_contract_project"],"execution":{"network":false,"profile":"foundry","requires":[],"tools":[]},"key":"manifest","kind":"code","role":"integrate","skillHash":null,"skillId":null,"state":"accepted"},{"acceptedSubmissionHash":"f61909ae72439f2984a36f60a24043c44169dc93a4a30239061c371be0b8ed4a","dependsOn":["build_contract_project"],"execution":{"network":false,"profile":"foundry","requires":[],"skillHash":"73431852439ad3a343f3d2b7db1c43cd363b9f48f9bb51497374a0cf6d50b223","skillId":"write-foundry-tests","tools":[]},"key":"write_foundry_tests","kind":"code","role":"tests","skillHash":"73431852439ad3a343f3d2b7db1c43cd363b9f48f9bb51497374a0cf6d50b223","skillId":"write-foundry-tests","state":"accepted"}],"objective":"A custom token: StrataIMD (STRATA).\nToken name: StrataIMD\nToken symbol: STRATA\nToken supply: 1,000,000,000 with 18 decimals, all minted once to the deployer in the constructor.","parentJobId":null,"planHash":"68a63ed6e5eb2e9b4a506ccb70e2c412897401f83bed4c15496de405b456e9b6","previousHash":"0000000000000000000000000000000000000000000000000000000000000000","projectId":"54901d48-36f3-40c2-a126-108c8702136c","publication":{"commit":null,"deliveredAt":null,"repoUrl":"https://github.com/identity-md-launches/launch-829-strataimd"},"receiptIdentity":{"adapter":"0xde152afb7db5373f34876e1499fbd893a82dd336","chainId":1,"collection":"0x0000ec93127baa929e58e97dd0095a2bfb38ec1d","registry":"0x8004a169fb4a3325136eb29fa0ceb6d2e539a432"},"registry":"0xb6d0a187b050fa5bb0b87033a203f37becf4a775","research":[],"schema":"identitymd-work-v1","signals":[{"agentId":"51487","feedbackHash":"98c5b65ddf69401d22f74466e55ff0f251c1cd69d5e3200e404a99bceab7c504","nodeKey":"audit_economics","submissionHash":"9737c5ec4e6fef7aa9bcfb2de0bee09b165d82e86e57abc26bb4c6f7c47fcda5","tag1":"review:submission","tag2":"acceptance-v2","value":1},{"agentId":"51231","feedbackHash":"f6de63d8f5cb6b0a339f899576bfe63a33937c5b0e81c41b941a177b8410ccc2","nodeKey":"audit_flow","submissionHash":"84dd70e4fce0c711aec8128496ec6571b261671e02c2d5706b4c08ff0c172009","tag1":"review:submission","tag2":"acceptance-v2","value":1},{"agentId":"51473","feedbackHash":"978bf6ba5768d3cb39498d7256087aa6e0aa61fb86e774d1b40c6ec233bf12eb","nodeKey":"audit_judge","submissionHash":"941128cf3c4153b35068b97b3ee6c971c44296065ac48f8f05eaa7a852b22f1d","tag1":"review:submission","tag2":"acceptance-v2","value":1},{"agentId":"51214","feedbackHash":"476917174ed07c841087f75e03a09bb55131a6636a053ce6a7e29b70f06ba0be","nodeKey":"audit_math","submissionHash":"4f06c1cb08dedd3649131bba9633f853a7d92f40e887af8494ed4d55f16e5996","tag1":"review:submission","tag2":"acceptance-v2","value":1},{"agentId":"50995","feedbackHash":"8d1b62e3646fff868f69a1dbeb6be63100ed0b419824c16b62ab9c0849335a4b","nodeKey":"audit_permissions","submissionHash":"9b210483f79ce815301ec0b524f89ccdd35357fd3d990b9a57405e336441704d","tag1":"review:submission","tag2":"acceptance-v2","value":1},{"agentId":"51411","feedbackHash":"20e0ffeab58bf5c443c7b6c551392797fa5f974094189ccfc24daa366d4cb545","nodeKey":"build_contract_project","submissionHash":"b340de3927f4f1af40a8567d4206a37a96e78a92c78db357ae4695474409e97b","tag1":"verification:checks","tag2":"acceptance-v2","value":1},{"agentId":"51503","feedbackHash":"0c60e34f3c1974af91c788ebab8e9834e5d2389222951067431e91b2f27307e4","nodeKey":"manifest","submissionHash":"4964a1fabea0bba2e33deed90f7c2491cd762b475f0a6e428deffc832d93550a","tag1":"verification:checks","tag2":"acceptance-v2","value":1},{"agentId":"51525","feedbackHash":"8694fb97c1f17d62c526ada8ec8b0f4dcb3cade0f8391e70f66756a323f00864","nodeKey":"write_foundry_tests","submissionHash":"f61909ae72439f2984a36f60a24043c44169dc93a4a30239061c371be0b8ed4a","tag1":"verification:checks","tag2":"acceptance-v2","value":1}],"site":null,"snapshotHash":"8e0dd68d4f8fe551de9293207f1d802efea1356aad52e01807017b40dd39c861","state":"completed","submissions":[{"artifacts":[],"attempt":1,"bundleHash":"7153bdc70b4e6a263810214cbcead40680496f9948cc1d15d49f4b6bc086f54d","device":"c1fc321231608a52","findings":[],"hash":"4964a1fabea0bba2e33deed90f7c2491cd762b475f0a6e428deffc832d93550a","nodeId":"d5895dc0-6601-4180-ac0c-aeb9ef917f28","outcome":"completed","summary":"Created [launch.json](/home/seat/.identitymd/work/54901d48-36f3-40c2-a126-108c8702136c/d5895dc0-6601-4180-ac0c-aeb9ef917f28/launch.json) matching the accepted token, exact supply, empty constructor arguments, requested pairing, and verbatim economics.\n\nManifest checks and `forge build` passed. `forge test`: 27 passed, 0 failed.\n\nOnly `launch.json` is changed for submission.","treeHash":"e9168c062cd49208db6348d71544ee9e6d498c27","usage":{"cachedInputTokens":171392,"inputTokens":23310,"model":"gpt-6-astra","outputTokens":3187,"runtime":"codex","turns":3,"wallClockMs":108793}},{"artifacts":[],"attempt":1,"bundleHash":null,"device":"dd2ee4882a1be950","findings":[{"citation":"resolved","description":"README.md lists `sha256sum -c SHA256SUMS` as one of the four build-and-test commands, and DEPENDENCIES.md states that the selected upstream source files are unmodified and that SHA256SUMS records every vendored file. Running the command on the committed tree reports six failures, all under lib/forge-std/src (StdAssertions.sol, StdJson.sol, StdToml.sol, Vm.sol, console.sol, interfaces/IMulticall3.sol). Diffing each against upstream forge-std v1.9.6 shows whitespace-only reformatting (multi-line signatures collapsed to one line, as `forge fmt` would do); no semantic change, and the files are test-only. The vendored OpenZeppelin files are byte-identical to upstream v5.0.2 and their hashes pass. Impact: the documented provenance claim is false and the documented verification step fails, so an operator following the README cannot complete its checks. No effect on the token bytecode or on any on-chain behaviour. Fix: either regenerate SHA256SUMS from the committed files or restore the six files to their upstream v1.9.6 bytes, and keep DEPENDENCIES.md accurate.","line":36,"path":"README.md","reproduction":"State: the committed tree at HEAD, no local changes. Run `sha256sum -c SHA256SUMS` from the repository root. Expected (per README/DEPENDENCIES.md): every line OK. Actual: `lib/forge-std/src/StdAssertions.sol: FAILED`, `lib/forge-std/src/StdJson.sol: FAILED`, `lib/forge-std/src/StdToml.sol: FAILED`, `lib/forge-std/src/Vm.sol: FAILED`, `lib/forge-std/src/console.sol: FAILED`, `lib/forge-std/src/interfaces/IMulticall3.sol: FAILED`, `WARNING: 6 computed checksums did NOT match`. Example: SHA256SUMS records 37cdc224...bc73c for lib/forge-std/src/Vm.sol while the committed file hashes to 9ef7ee8c...9f408.","severity":"low","snippet":"sha256sum -c SHA256SUMS","title":"README-documented integrity check `sha256sum -c SHA256SUMS` fails: six vendored forge-std files do not match the recorded hashes"}],"hash":"4f06c1cb08dedd3649131bba9633f853a7d92f40e887af8494ed4d55f16e5996","nodeId":"1a081b05-956b-4bb1-96b1-153d464d1e05","outcome":"completed","summary":"The review is complete and the findings file is written. The working tree is otherwise untouched: the scratch tests were removed and no project file was changed.\n\n**Outcome:** no math, precision, boundary or numerical-gap defect in the token. One low finding outside the assigned area.\n\n**What was checked in the assigned area**\n- The supply constant is a compile-time literal product that equals exactly 10^27, which the deployed contract confirms. The aderyn \"large numeric literal\" lead is not a defect.\n- All three entry points are the unmodified OpenZeppelin v5.0.2 ERC20, verified byte-for-byte against upstream. The token adds no division, scaling, casts, fees or external calls, so the precision and truncation failure modes have nothing to attach to.\n- Boundary tests I ran on the deployed contract all passed: transfer of max uint and balance plus one revert without wrapping, exact-equality allowance and balance succeed and leave zero, the unlimited-allowance sentinel is exactly max uint while max-minus-one still decrements, self-transfer and self-spend preserve balance, a failed balance check rolls back allowance, two deployments are isolated, and a fuzzed split of the supply always sums exactly.\n- Build, the project's 27 unit, fuzz and invariant tests, and the format check all pass.\n\n**The one finding (low):** the README lists a hash check as a build step, and DEPENDENCIES.md claims the vendored files are unmodified, but that check fails on the committed tree. Six forge-std files are whitespace-reformatted relative to upstream v1.9.6. The difference is test-only and has no on-chain effect, but the documented verification step cannot be completed as written. The fix is to regenerate the hash list or restore the upstream bytes.\n\n**Coverage:** all three entry points are marked `holds`, plus rows for the supply invariant, balance conservation, the static-analysis lead and the Boundary guide's external-call enumeration. Nothing was left unreached.","treeHash":null,"usage":{"cachedInputTokens":594270,"inputTokens":322,"model":"claude-fable-5-1","outputTokens":11352,"runtime":"claude","turns":18,"wallClockMs":169421}},{"artifacts":[],"attempt":1,"bundleHash":null,"device":"1507f63d3f1b973a","findings":[{"citation":"resolved","description":"Periphery/provenance. README.md line 36 lists `sha256sum -c SHA256SUMS` as one of the four repository checks, and DEPENDENCIES.md line 15 states 'The selected upstream source files are unmodified.' Neither holds for the tree as committed. Six files under lib/forge-std/src (StdAssertions.sol, StdJson.sol, StdToml.sol, Vm.sol, console.sol, interfaces/IMulticall3.sol) hash to values different from the ones recorded in SHA256SUMS, and differ from the pinned upstream forge-std v1.9.6 archive (whose own SHA-256 does match the one DEPENDENCIES.md records). I diffed each against the upstream archive: every difference is a line-wrapping change consistent with `forge fmt` having been run over lib/ (for example StdAssertions.sol line 480 collapses a four-line function header to one line), and the whitespace-stripped contents are byte-identical, so the files are semantically unchanged. All five vendored OpenZeppelin v5.0.2 files, which are what the deployed token compiles from, are byte-identical to upstream and their SHA256SUMS lines verify. Impact is limited to the integrity record: the repository's stated verification command fails, so a reviewer or the offline verifier cannot distinguish this reformat from a tamper without re-fetching upstream, and the provenance statement in DEPENDENCIES.md is false for forge-std. No effect on the token's bytecode, supply or behaviour; forge-std is used only by tests. Minimal fix: either restore the six files byte-for-byte from the v1.9.6 archive (keeping SHA256SUMS as is), or regenerate the six SHA256SUMS lines and amend DEPENDENCIES.md to say forge-std was reformatted. Do not format lib/ in future runs.","line":5,"path":"SHA256SUMS","reproduction":"State: the committed tree at HEAD (85dabc6). Input: run `sha256sum -c SHA256SUMS` from the repository root, exactly as README.md line 36 instructs. Expected: every line reports OK and the command exits 0. Actual: it exits 1 and reports 'WARNING: 6 computed checksums did NOT match' for lib/forge-std/src/StdAssertions.sol, StdJson.sol, StdToml.sol, Vm.sol, console.sol and interfaces/IMulticall3.sol. For example `sha256sum lib/forge-std/src/StdAssertions.sol` prints 3fbf4a025b4fc94eaca4c38c1f3dacb37bee10f12ee81994cfaf365ac1ce7384 while SHA256SUMS line 5 records d4c89eec70d267dec6188461fbc74d3dc8c47e518d176a23417533a232ed9780. Cross-check: the upstream archive https://codeload.github.com/foundry-rs/forge-std/tar.gz/refs/tags/v1.9.6 hashes to 53d2b498183cb7dc62cf726cc6c1a222ad728b0d87976a877ca1f3ed3707b1c6 (matching DEPENDENCIES.md), and `diff forge-std-1.9.6/src/StdAssertions.sol lib/forge-std/src/StdAssertions.sol` shows 48 changed lines, all re-wrapping; `tr -d ' \\t\\n\\r'` on both files yields identical SHA-256 digests. The vendored OpenZeppelin files verify and are identical to the v5.0.2 archive (18c7b7e9...3925a).","severity":"low","snippet":"d4c89eec70d267dec6188461fbc74d3dc8c47e518d176a23417533a232ed9780  lib/forge-std/src/StdAssertions.sol","title":"Documented provenance check fails: six vendored forge-std files do not match SHA256SUMS or the 'unmodified' claim"}],"hash":"84dd70e4fce0c711aec8128496ec6571b261671e02c2d5706b4c08ff0c172009","nodeId":"30d3d692-fe4b-43c4-9a9f-d974c18a75ad","outcome":"completed","summary":"The review is complete. The findings file is valid JSON, the snippet matches the tree, the scratch test and temp archives are deleted, and the working tree holds no new files beyond the required output and the build cache.\n\n**Outcome.** The token is a plain OpenZeppelin v5.0.2 ERC-20 with a fixed constructor mint, and all three state-changing entry points hold. I found one low-severity defect, in the repository's provenance record rather than the contract.\n\n**What I covered, in my area.** Execution Trace: I traced approve, transfer and transferFrom through the vendored ERC20 line by line, then probed the corner cases with a scratch Foundry test deployed from a CREATE2 factory and a pool-manager-style puller. Exact delivery holds for factory to distributor, pool manager and remainder, and for a buy and sell round trip. Finite allowances decrement exactly, the max allowance is untouched, max minus one decrements, a spender equal to the owner still needs an allowance, and failed delegated transfers roll back the allowance. Periphery: the five vendored OpenZeppelin files are byte-identical to the upstream v5.0.2 archive, and the compiled ABI has no receive, fallback, payable function, or admin surface. First Principles: the constructor mints to msg.sender, which under factory CREATE2 is the factory, as the protected harness requires. The supply constant cannot overflow, so the aderyn large-literal lead is benign. Slither reported nothing.\n\n**The finding.** Six forge-std files fail the repository's own `sha256sum -c SHA256SUMS` check, which the README lists as a required check, and DEPENDENCIES.md claims the vendored files are unmodified. I diffed them against the pinned v1.9.6 archive, whose hash does match. Every difference is line re-wrapping consistent with a formatter run over lib, and the whitespace-stripped contents are identical. This is test-only and does not affect the token's bytecode, so I rated it low. The fix is either restoring the six files byte-for-byte or regenerating the six checksum lines and correcting the provenance note.\n\n**Coverage record.** Eight rows: the three listed entry points hold, the constructor holds, two invariants hold, OpenZeppelin periphery holds, and the forge-std provenance row points to finding 1. Nothing was left unreached. No critical or high finding exists, so no proof test accompanies the report.","treeHash":null,"usage":{"cachedInputTokens":1034163,"inputTokens":482,"model":"claude-fable-5-1","outputTokens":17825,"runtime":"claude","turns":28,"wallClockMs":268757}},{"artifacts":[],"attempt":1,"bundleHash":null,"device":"dc34db8e17664ebd","findings":[{"citation":"resolved","description":"Merged from four specialists (audit_math, audit_permissions, audit_economics, audit_flow), all reporting the same root cause. README.md line 36 lists `sha256sum -c SHA256SUMS` as one of the four repository checks, and DEPENDENCIES.md line 15 states 'The selected upstream source files are unmodified.' Neither holds for the committed tree. I re-derived it independently: I downloaded the forge-std v1.9.6 archive named in DEPENDENCIES.md (archive SHA-256 53d2b498183cb7dc62cf726cc6c1a222ad728b0d87976a877ca1f3ed3707b1c6, matching the recorded value) and compared every tracked file under lib/ byte for byte. Six files under lib/forge-std/src differ from upstream: StdAssertions.sol, StdJson.sol, StdToml.sol, Vm.sol, console.sol, interfaces/IMulticall3.sol. For each, stripping all whitespace (spaces, tabs, line breaks) from the committed copy and the upstream copy yields identical SHA-256 digests, so the change is line re-wrapping only, consistent with `forge fmt` (line_length 120 in foundry.toml) having been run over lib/. The hashes recorded in SHA256SUMS are the correct upstream hashes, so the file was written from pristine sources and the tree was reformatted afterwards. All six vendored OpenZeppelin v5.0.2 files, which are what StrataIMD compiles from, are byte-identical to the upstream v5.0.2 archive (SHA-256 18c7b7e949b9a82dcd8cd394426c9c2636dfc263aa2317d4749dbfa0c7b3925a) and their SHA256SUMS lines verify. Impact: no effect on the token's bytecode, supply or transfer behaviour; forge-std is test-only. The defect is that the repository's own integrity gate is red and its 'unmodified' claim is false, so an offline verifier following the README cannot distinguish this benign reformat from a tampered assertion library without re-fetching upstream. Minimal fix: restore the six files byte-for-byte from the v1.9.6 archive (keeping SHA256SUMS as is), or regenerate those six SHA256SUMS lines and amend DEPENDENCIES.md to say forge-std was reformatted. Also keep lib/ out of future `forge fmt` runs.","line":17,"path":"SHA256SUMS","reproduction":"State: the committed tree at HEAD, `git status` clean. Input: run `sha256sum -c SHA256SUMS` from the repository root, as README.md line 36 instructs. Expected: every line reports OK and the command exits 0. Actual: it reports `lib/forge-std/src/StdAssertions.sol: FAILED`, `lib/forge-std/src/StdJson.sol: FAILED`, `lib/forge-std/src/StdToml.sol: FAILED`, `lib/forge-std/src/Vm.sol: FAILED`, `lib/forge-std/src/console.sol: FAILED`, `lib/forge-std/src/interfaces/IMulticall3.sol: FAILED`, `sha256sum: WARNING: 6 computed checksums did NOT match`, exit status 1. Spot check: `sha256sum lib/forge-std/src/Vm.sol` prints 9ef7ee8c9a0a4fb18b830e85ce5cd31a56b97781e126ad1e7801389c49b0f408, while SHA256SUMS line 17 (and upstream v1.9.6 src/Vm.sol) give 37cdc22402df6c218ca65502e7fa2a24a3ce5b796eaaee330ad84fb9578bc73c. Cross-check that the change is whitespace-only: `tr -d ' \\t\\n\\r' < lib/forge-std/src/Vm.sol | sha256sum` and the same on upstream src/Vm.sol both print a digest beginning e38c6e2f5933a418. The OpenZeppelin files compare identical with `cmp` against the v5.0.2 archive.","severity":"low","snippet":"37cdc22402df6c218ca65502e7fa2a24a3ce5b796eaaee330ad84fb9578bc73c  lib/forge-std/src/Vm.sol","title":"Documented provenance check `sha256sum -c SHA256SUMS` fails: six vendored forge-std files were reformatted after their hashes were recorded"}],"hash":"941128cf3c4153b35068b97b3ee6c971c44296065ac48f8f05eaa7a852b22f1d","nodeId":"f74a3fac-c4ff-455a-9938-6ce08eccafd0","outcome":"completed","summary":"The review is complete and `.imd-findings.json` is written. No other file was changed.\n\n**Outcome.** The StrataIMD token is clean. It is the unmodified OpenZeppelin v5.0.2 ERC20 with an argument-free constructor that mints the manifest supply once to the deployer, and it has no privileged entry points. The three entry points in the ABI all hold.\n\n**Specialist findings.** Four specialists reported the same defect and one reported an informational note.\n\n- **Kept, merged into one low finding.** The documented `sha256sum -c SHA256SUMS` check fails for six vendored forge-std files. I reproduced it independently by downloading the pinned forge-std v1.9.6 archive, which matches the hash in DEPENDENCIES.md. The six committed files differ from upstream only by line re-wrapping, and the whitespace-stripped contents are identical. All six vendored OpenZeppelin files are byte-identical to upstream. The token's bytecode and behaviour are unaffected, but the repository's provenance claim is false and its integrity gate is red.\n- **Dropped.** The approve and transferFrom allowance replacement race. It reproduces, but it is standard ERC-20 behaviour inherited from the library and the README already documents the mitigation. It is not a defect in this code.\n\n**My own pass.** Project build and all 41 tests pass, including the invariant suite. The deployed runtime contains no DELEGATECALL, CALLCODE or SELFDESTRUCT. The manifest's totalSupply, decimals and empty constructorArgs match the contract, and its initialPrice equals the stated formula from the economics. The aderyn large-literal lead is a compile-time constant and is benign. The manifest's economics could not be checked against the job because the job's economics were not supplied to this task.\n\n**Coverage.** Six rows: the three entry points hold, plus three invariant rows for the supply mint, the runtime opcodes and the manifest consistency.","treeHash":null,"usage":{"cachedInputTokens":393774,"inputTokens":226,"model":"claude-fable-5-1","outputTokens":7210,"runtime":"claude","turns":8,"wallClockMs":134229}},{"artifacts":[],"attempt":1,"bundleHash":null,"device":"9e51ef2afd7c2af8","findings":[{"citation":"resolved","description":"README.md line 36 lists `sha256sum -c SHA256SUMS` as a build/verification step and DEPENDENCIES.md line 15 states 'The selected upstream source files are unmodified.' Neither holds for the committed tree. Six files under lib/forge-std/src (StdAssertions.sol, StdJson.sol, StdToml.sol, Vm.sol, console.sol, interfaces/IMulticall3.sol) differ from the hashes recorded in SHA256SUMS. I downloaded the forge-std v1.9.6 archive named in DEPENDENCIES.md (its SHA-256 matches the recorded 53d2b498...) and confirmed: the hashes in SHA256SUMS are the correct upstream hashes, but the committed files were re-wrapped (whitespace/line-break changes only, consistent with `forge fmt` at line_length 120 having been run over lib/; with all whitespace stripped the files are identical to upstream). All six vendored OpenZeppelin v5.0.2 files, which the production token actually inherits, are byte-identical to upstream, so this does not affect StrataIMD's behaviour or bytecode. It does make the repository's own provenance check fail and its 'unmodified' claim false, which weakens the offline reproducibility story the README sells. Out of my assigned area (economics); reported because it is concrete and reproducible. Fix: restore the six files from the upstream archive so they match SHA256SUMS (and keep formatting out of lib/, or exclude lib/ in the fmt config, a change that is for the author, not a worker).","line":17,"path":"SHA256SUMS","reproduction":"In the repository root run `sha256sum -c SHA256SUMS`. Expected: every line reports OK. Actual: `lib/forge-std/src/StdAssertions.sol: FAILED`, `lib/forge-std/src/StdJson.sol: FAILED`, `lib/forge-std/src/StdToml.sol: FAILED`, `lib/forge-std/src/Vm.sol: FAILED`, `lib/forge-std/src/console.sol: FAILED`, `lib/forge-std/src/interfaces/IMulticall3.sol: FAILED`, `sha256sum: WARNING: 6 computed checksums did NOT match`. For example `sha256sum lib/forge-std/src/Vm.sol` prints 9ef7ee8c9a0a4fb18b830e85ce5cd31a56b97781e126ad1e7801389c49b0f408 whereas SHA256SUMS line 17 and upstream v1.9.6 both give 37cdc22402df6c218ca65502e7fa2a24a3ce5b796eaaee330ad84fb9578bc73c. `git status` is clean, so the mismatch is in the committed blobs, not the working copy.","severity":"low","snippet":"37cdc22402df6c218ca65502e7fa2a24a3ce5b796eaaee330ad84fb9578bc73c  lib/forge-std/src/Vm.sol","title":"Committed SHA256SUMS does not verify: six vendored forge-std files differ from the recorded (upstream v1.9.6) hashes"}],"hash":"9737c5ec4e6fef7aa9bcfb2de0bee09b165d82e86e57abc26bb4c6f7c47fcda5","nodeId":"494a9580-d7fa-4bc7-9dfa-12959d96e085","outcome":"completed","summary":"The review is complete and recorded in `.imd-findings.json`. No tracked files were changed.\n\n**Result: no economic defects in the token.** StrataIMD is an unmodified OpenZeppelin v5.0.2 ERC-20 plus one constant and a constructor mint. I verified the six vendored OpenZeppelin files are byte-identical to the upstream release, so the token's transfer, approval and supply behaviour is exactly the library's.\n\nWhat I checked against the Economic Security, Invariant and Flow Gap guides:\n\n- **Supply invariant.** The only path that touches supply is the constructor mint of 10^27 units to the factory. No burn, mint, owner, pause, blacklist or initializer exists in the compiled ABI. The project's invariant test passes on re-run.\n- **Flow exactness.** Transfer and transferFrom move precisely the requested amount with no fee, hook, tax or exemption list. The swarm share, pool seed, and swaps each way therefore arrive whole. The protected harness itself could not be run here because v4-core is not vendored.\n- **Token misbehaviour and compliance.** No external calls, oracles, sentinel branches, rebasing, or void returns. Zero-address transfers and approvals revert. ETH is rejected. Runtime contains no DELEGATECALL, CALLCODE or SELFDESTRUCT.\n- **Privileged power.** The factory or deployer cannot move a holder's balance without allowance.\n\n**One low finding, outside my area.** The committed SHA256SUMS fails to verify: six forge-std files under lib/ were whitespace-reformatted, so the README's checksum step reports six failures and the \"unmodified upstream\" claim in DEPENDENCIES.md is false. The recorded hashes match upstream v1.9.6, the files do not. This is test-only tooling and does not affect the token's bytecode. The fix is to restore those six files from the upstream archive.\n\nCoverage: all three listed entry points marked `holds`, plus rows for the constructor, the supply invariant, launch-flow exactness, economic security, and dependency provenance (the finding).","treeHash":null,"usage":{"cachedInputTokens":744444,"inputTokens":322,"model":"claude-fable-5-1","outputTokens":14094,"runtime":"claude","turns":28,"wallClockMs":272209}},{"artifacts":[],"attempt":1,"bundleHash":null,"device":"b5e3297a04468fd3","findings":[{"citation":"resolved","description":"README.md lists `sha256sum -c SHA256SUMS` as one of the four build-and-test checks, and DEPENDENCIES.md states 'The selected upstream source files are unmodified.' Neither holds for the committed tree. Six files under lib/forge-std/src (StdAssertions.sol, StdJson.sol, StdToml.sol, Vm.sol, console.sol, interfaces/IMulticall3.sol) fail the recorded checksum. The recorded hashes match the upstream forge-std v1.9.6 archive (archive SHA-256 53d2b498... as stated in DEPENDENCIES.md), so the checksums were computed from pristine upstream files and the committed copies were reformatted afterwards (the diffs are line-wrapping only; a whitespace-stripped comparison of each file against upstream is byte-identical). Impact is limited: the six files are test-only, the deployed StrataIMD runtime does not include them, and all five vendored OpenZeppelin files are byte-identical to upstream v5.0.2. The defect is that the repository's own integrity gate is red, so a reviewer following the README cannot distinguish this benign reformat from a hostile edit to the assertion library (StdAssertions.sol is among the altered files) without re-deriving upstream themselves. Minimal fix: restore the six files from the v1.9.6 archive (or re-record SHA256SUMS from the reformatted files and drop the 'unmodified' claim), so `sha256sum -c SHA256SUMS` passes.","line":17,"path":"SHA256SUMS","reproduction":"State: the committed working tree at HEAD. Input: run `sha256sum -c SHA256SUMS` from the repository root. Expected (per README.md line 36 and DEPENDENCIES.md line 15): every line reports OK. Actual: 'lib/forge-std/src/StdAssertions.sol: FAILED', 'lib/forge-std/src/StdJson.sol: FAILED', 'lib/forge-std/src/StdToml.sol: FAILED', 'lib/forge-std/src/Vm.sol: FAILED', 'lib/forge-std/src/console.sol: FAILED', 'lib/forge-std/src/interfaces/IMulticall3.sol: FAILED', 'sha256sum: WARNING: 6 computed checksums did NOT match'. Cross-check: `sha256sum lib/forge-std/src/Vm.sol` prints 9ef7ee8c9a0a4fb18b830e85ce5cd31a56b97781e126ad1e7801389c49b0f408, while the upstream v1.9.6 src/Vm.sol prints 37cdc22402df6c218ca65502e7fa2a24a3ce5b796eaaee330ad84fb9578bc73c, the value on SHA256SUMS line 17. `diff -w` of each of the six files against the upstream archive is empty.","severity":"low","snippet":"37cdc22402df6c218ca65502e7fa2a24a3ce5b796eaaee330ad84fb9578bc73c  lib/forge-std/src/Vm.sol","title":"Documented provenance check fails: six vendored forge-std files do not match SHA256SUMS or upstream v1.9.6"},{"citation":"resolved","description":"Asymmetry check of the approve <-> pull pair. `approve` overwrites the allowance slot unconditionally while `transferFrom` decrements it, so an owner who lowers a non-zero allowance can have both the old and the new amount spent if the spender lands a transferFrom between the two approvals. This is the well-known ERC-20 property, not a defect introduced by StrataIMD: the token inherits OpenZeppelin v5.0.2 unchanged, which deliberately dropped increaseAllowance/decreaseAllowance, and README.md line 52 already tells holders to revoke to zero and wait for confirmation before setting a new value. Reported for completeness of the asymmetry pass; no code change is required and none is recommended that would alter the vendored library. No other asymmetry exists between transfer and transferFrom: both route through the same `_transfer`/`_update`, the only extra step in transferFrom is `_spendAllowance`, and a self-directed transferFrom still spends allowance (existing test test_transferFromSelfStillConsumesAllowance).","line":132,"path":"lib/openzeppelin-contracts/contracts/token/ERC20/ERC20.sol","reproduction":"State: ALICE holds 100e18 STRATA and has called approve(BOB, 50e18). Sequence: (1) ALICE submits approve(BOB, 30e18); (2) before it is mined BOB calls transferFrom(ALICE, BOB, 50e18), which succeeds; (3) ALICE's approve(BOB, 30e18) is mined and sets the allowance to 30e18; (4) BOB calls transferFrom(ALICE, BOB, 30e18), which succeeds. Expected by a naive owner: BOB can move at most 50e18. Actual: BOB holds 80e18 (verified in a scratch Foundry test, balanceOf(BOB) == 80e18). Mitigation already documented: approve(BOB, 0), wait for inclusion, then approve(BOB, 30e18).","severity":"info","snippet":"    function approve(address spender, uint256 value) public virtual returns (bool) {\n        address owner = _msgSender();\n        _approve(owner, spender, value);\n        return true;\n    }","title":"approve/transferFrom allowance replacement race is the standard ERC-20 behaviour and is retained by design"}],"hash":"9b210483f79ce815301ec0b524f89ccdd35357fd3d990b9a57405e336441704d","nodeId":"8c117121-69ef-47fc-bce2-31c4e9981252","outcome":"completed","summary":"The findings file is in place and excluded from git by the harness's own `.git/info/exclude`, so the working tree is otherwise clean. The review is complete.\n\n**Outcome:** no access-control, trust-gap, or asymmetry defect in the token. The review found one low provenance issue and one informational note, both recorded in `.imd-findings.json` with a nine-row coverage record.\n\n**What the token is.** `src/StrataIMD.sol` is a 16-line wrapper over the vendored OpenZeppelin v5.0.2 ERC20. The constructor takes no arguments and mints 10^27 units once to the deployer. The compiled ABI has exactly ten selectors: seven views plus approve, transfer and transferFrom. There is no owner, role, initializer, proxy, receive or fallback, and the runtime contains no DELEGATECALL, CALLCODE or SELFDESTRUCT.\n\n**Area coverage.**\n- **Access control.** Every state-changing path binds to plain `msg.sender` through an unmodified Context. approve writes only the caller's allowance row, transfer debits only the caller, transferFrom requires the caller's allowance from the owner. The deployer or factory has no bypass. Unknown selectors and raw ETH revert. All three listed entry points are marked `holds`.\n- **Trust gap.** There is no privileged actor, so none of the four seams has an actor to occupy it. The only trust assumption is that the factory holds the whole supply until it distributes, which is the launch design.\n- **Asymmetry.** transfer and transferFrom share the same internal path. The only pair difference is the allowance spend, and it behaves as specified, including on self-directed pulls and on reverts. The approve-overwrite race is standard ERC-20 and already documented in the README. I recorded it as info only.\n\n**Findings written.**\n1. **Low:** the README's own check `sha256sum -c SHA256SUMS` fails on six forge-std files. The recorded hashes match upstream v1.9.6, so the committed copies were reformatted afterwards. I downloaded both upstream archives and confirmed the diffs are whitespace-only and that all five OpenZeppelin files are byte-identical to upstream. The deployed bytecode is unaffected, but the stated integrity gate is red and the \"unmodified\" claim in DEPENDENCIES.md is false.\n2. **Info:** the allowance replacement race, with a concrete sequence, marked as retained by design.\n\n**Verification run.** The existing 27 unit, fuzz and invariant tests pass offline. I added five scratch probes under test/scratch covering the hand-traced access paths and the race sequence, all passed, and I deleted them afterwards along with the temporary download directory. Neither Slither nor Mythril ran beyond the verifier's supplied output, which reported nothing above the numeric-literal lint.\n\nNo critical or high findings exist, so no proof test was attached.","treeHash":null,"usage":{"cachedInputTokens":755935,"inputTokens":322,"model":"claude-fable-5-1","outputTokens":15795,"runtime":"claude","turns":26,"wallClockMs":227974}},{"artifacts":[],"attempt":1,"bundleHash":"26f3890e0a9bd35580cd59629fe2d8d965ef587914cb25e30cbba59ce10da803","device":"964f2d8baaf7b03b","findings":[],"hash":"b340de3927f4f1af40a8567d4206a37a96e78a92c78db357ae4695474409e97b","nodeId":"12bc3005-8157-43ed-a2a5-a3d35857d12d","outcome":"completed","summary":"Implemented StrataIMD (STRATA): 1 billion tokens, 18 decimals, minted once to the deployer, with no administrative powers.\n\n- `forge build`, `forge test`, and `forge fmt --check` pass.\n- All 27 tests pass, including fuzz and invariant checks.\n- Fresh offline build and parallel tests pass with an empty environment.\n- Dependencies are vendored; assumptions and deployment responsibilities are documented in [README.md](/home/worker/.identitymd-3/work/54901d48-36f3-40c2-a126-108c8702136c/12bc3005-8157-43ed-a2a5-a3d35857d12d/README.md).\n\nThe network-specific protected launch harness was not run locally.","treeHash":"6e7eec2a8d1d3811155af5545402f593bdae86c7","usage":{"cachedInputTokens":463616,"inputTokens":44553,"model":"gpt-6-astra","outputTokens":12936,"runtime":"codex","turns":5,"wallClockMs":479952}},{"artifacts":[],"attempt":1,"bundleHash":"f791e261395d18d3a22a994e01346b3d9106bd4e9c0f068313c4aa71b3705a5b","device":"c2c5d7ad583481d5","findings":[],"hash":"f61909ae72439f2984a36f60a24043c44169dc93a4a30239061c371be0b8ed4a","nodeId":"4aba8b4e-c229-46f2-a8f0-c31cea2e70d6","outcome":"completed","summary":"Added 14 tests covering authorization failures, allowance revocation, maximum values, and recovery after failed transfers. Expanded invariants to mix valid and rejected operations.\n\n`forge build` and `forge test` pass: **41 tests**, including **32,768 invariant calls**.\n\nOnly `test/` changed. No defects surfaced in these checks.","treeHash":"7d911b9686fd87ba143364d363f9551f80c712a0","usage":{"cachedInputTokens":534912,"inputTokens":81691,"model":"gpt-6-astra","outputTokens":9950,"runtime":"codex","turns":4,"wallClockMs":302710}}],"verification":[{"checks":[{"durationMs":3146,"exitCode":0,"name":"build","output":"Compiling 26 files with Solc 0.8.26\nSolc 0.8.26 finished in 2.75s\nCompiler run successful!\n","passed":true},{"durationMs":5631,"exitCode":0,"name":"test","output":"No files changed, compilation skipped\n\nRan 26 tests for test/StrataIMD.t.sol:StrataIMDTest\n[PASS] testFuzz_transferAboveBalanceReverts(uint256) (runs: 512, μ: 65073, ~: 65405)\nLogs:\n  Bound result 115792089237316195423570985008687907853269984665639564039457584007913129662372\n\n[PASS] testFuzz_transferFromAboveAllowanceReverts(uint256,uint256) (runs: 512, μ: 116220, ~: 116407)\nLogs:\n  Bound result 11684\n  Bound result 25453\n\n[PASS] testFuzz_transferFromRespectsAllowance(uint256,uint256) (runs: 512, μ: 156284, ~: 157994)\nLogs:\n  Bound result 20000000000000000000\n  Bound result 10\n\n[PASS] testFuzz_transfersConserveSupply(uint256) (runs: 512, μ: 148210, ~: 148683)\nLogs:\n  Bound result 20594003741\n\n[PASS] test_approveDoesNotRequireBalance() (gas: 71880)\n[PASS] test_approveEmitsEventAndCanReplaceOrRevokeAllowance() (gas: 178644)\n[PASS] test_approveZeroSpenderReverts() (gas: 37925)\n[PASS] test_constructorEmitsMintTransfer() (gas: 5953)\n[PASS] test_create2FactoryReceivesSupplyAndLaunchTransfersAreExact() (gas: 693273)\n[PASS] test_deployerCannotSpendHolderTokensWithoutApproval() (gas: 92688)\n[PASS] test_metadataAndEntireInitialSupply() (gas: 103272)\n[PASS] test_noMintBurnOrAdministrativeEntryPoints() (gas: 1260881)\n[PASS] test_rejectsNativeCurrency() (gas: 37194)\n[PASS] test_runtimeContainsNoProhibitedOpcodes() (gas: 1038921)\n[PASS] test_selfTransferPreservesBalance() (gas: 51559)\n[PASS] test_transferEmitsEventAndMovesExactAmount() (gas: 89346)\n[PASS] test_transferEntireSupply() (gas: 71705)\n[PASS] test_transferFromEmitsEventAndConsumesAllowance() (gas: 228105)\n[PASS] test_transferFromInsufficientBalanceRollsBackAllowance() (gas: 114438)\n[PASS] test_transferFromSelfStillConsumesAllowance() (gas: 100743)\n[PASS] test_transferFromToZeroRollsBackAllowance() (gas: 111776)\n[PASS] test_transferFromUnlimitedAllowanceDoesNotDecrease() (gas: 122092)\n[PASS] test_transferFromZeroSenderReverts() (gas: 61016)\n[PASS] test_transferToZeroRevertsEvenForZeroAmount() (gas: 72811)\n[PASS] test_zeroTransferFromEmptyAccountEmitsEvent() (gas: 66472)\n[PASS] test_zeroTransferFromWithoutAllowanceSucceeds() (gas: 57046)\nSuite result: ok. 26 passed; 0 failed; 0 skipped; finished in 77.78ms (214.95ms CPU time)\n\nRan 1 test for test/StrataIMD.invariant.t.sol:StrataIMDInvariantTest\n[PASS] invariant_balancesAndAllowancesMatchLedgerAndSupplyIsFixed() (runs: 128, calls: 8192, reverts: 0)\n\n╭---------------+--------------+-------+---------+----------╮\n| Contract      | Selector     | Calls | Reverts | Discards |\n+===========================================================+\n| StrataHandler | approve      | 2729  | 0       | 0        |\n|---------------+--------------+-------+---------+----------|\n| StrataHandler | transfer     | 2750  | 0       | 0        |\n|---------------+--------------+-------+---------+----------|\n| StrataHandler | transferFrom | 2713  | 0       | 0        |\n╰---------------+--------------+-------+---------+----------╯\n\nLogs:\n  Bound result 0\n  Bound result 0\n  Bound result 0\n  Bound result 0\n  Bound result 24576\n  Bound result 0\n  Bound result 0\n  Bound result 0\n  Bound result 0\n  Bound result 0\n  Bound result 0\n  Bound result 3015\n  Bound result 345840567272072987245489518\n  Bound result 1472\n  Bound result 0\n  Bound result 654159432727927012754509010\n  Bound result 0\n  Bound result 208\n  Bound result 1802\n  Bound result 3\n  Bound result 96\n  Bound result 1643\n  Bound result 1313\n  Bound result 659918\n  Bound result 0\n  Bound result 96\n  Bound result 2414\n  Bound result 0\n  Bound result 611\n  Bound result 793\n  Bound result 69046091852106080925046180\n  Bound result 335692276477148264294457663\n  Bound result 0\n  Bound result 442\n  Bound result 789\n  Bound result 772\n  Bound result 3\n  Bound result 259532777551843937752028653\n  Bound result 986\n  Bound result 0\n  Bound result 1983\n  Bound result 889\n  Bound result 4\n  Bound result 208\n  Bound result 218\n  Bound result 0\n  Bound result 260\n  Bound result 125\n  Bound result 244\n  Bound result 0\n  Bound result 1\n  Bound result 125\n  Bound result 4633\n\nSuite result: ok. 1 passed; 0 failed; 0 skipped; finished in 5.25s (5.25s CPU time)\n\nRan 2 test suites in 5.25s (5.33s CPU time): 27 tests passed, 0 failed, 0 skipped (27 total tests)\n","passed":true},{"durationMs":172,"exitCode":0,"name":"source-index","output":"{\"v\":1,\"entryPoints\":[\"StrataIMD.approve(address,uint256)\",\"StrataIMD.transfer(address,uint256)\",\"StrataIMD.transferFrom(address,address,uint256)\"],\"files\":{\".gitignore\":4,\"DEPENDENCIES.md\":16,\"LICENSE\":21,\"README.md\":58,\"SHA256SUMS\":32,\"foundry.toml\":23,\"launch.json\":20,\"remappings.txt\":2,\"src/StrataIMD.sol\":16,\"test/StrataIMD.invariant.t.sol\":88,\"test/StrataIMD.t.sol\":384},\"excluded\":[\"lib/\",\"node_modules/\"],\"truncated\":false}","passed":true}],"detail":"all checks passed","evaluation":"checks","profile":"foundry","status":"accepted","submissionHash":"4964a1fabea0bba2e33deed90f7c2491cd762b475f0a6e428deffc832d93550a","verifiedTreeHash":"e9168c062cd49208db6348d71544ee9e6d498c27","verifierVersion":"0.1.0+94826a22"},{"checks":[{"durationMs":1732,"exitCode":0,"name":"build","output":"Compiling 26 files with Solc 0.8.26\nSolc 0.8.26 finished in 1.56s\nCompiler run successful!\n","passed":true},{"durationMs":3066,"exitCode":0,"name":"test","output":"No files changed, compilation skipped\n\nRan 26 tests for test/StrataIMD.t.sol:StrataIMDTest\n[PASS] testFuzz_transferAboveBalanceReverts(uint256) (runs: 512, μ: 65070, ~: 65405)\nLogs:\n  Bound result 115792089237316195423570985008687907853269984665639564039457584007913129639953\n\n[PASS] testFuzz_transferFromAboveAllowanceReverts(uint256,uint256) (runs: 512, μ: 116281, ~: 116407)\nLogs:\n  Bound result 303\n  Bound result 643430984848976035014608701\n\n[PASS] testFuzz_transferFromRespectsAllowance(uint256,uint256) (runs: 512, μ: 156376, ~: 157990)\nLogs:\n  Bound result 16581\n  Bound result 1\n\n[PASS] testFuzz_transfersConserveSupply(uint256) (runs: 512, μ: 148344, ~: 148683)\nLogs:\n  Bound result 18\n\n[PASS] test_approveDoesNotRequireBalance() (gas: 71880)\n[PASS] test_approveEmitsEventAndCanReplaceOrRevokeAllowance() (gas: 178644)\n[PASS] test_approveZeroSpenderReverts() (gas: 37925)\n[PASS] test_constructorEmitsMintTransfer() (gas: 5953)\n[PASS] test_create2FactoryReceivesSupplyAndLaunchTransfersAreExact() (gas: 693273)\n[PASS] test_deployerCannotSpendHolderTokensWithoutApproval() (gas: 92688)\n[PASS] test_metadataAndEntireInitialSupply() (gas: 103272)\n[PASS] test_noMintBurnOrAdministrativeEntryPoints() (gas: 1260881)\n[PASS] test_rejectsNativeCurrency() (gas: 37194)\n[PASS] test_runtimeContainsNoProhibitedOpcodes() (gas: 1038921)\n[PASS] test_selfTransferPreservesBalance() (gas: 51559)\n[PASS] test_transferEmitsEventAndMovesExactAmount() (gas: 89346)\n[PASS] test_transferEntireSupply() (gas: 71705)\n[PASS] test_transferFromEmitsEventAndConsumesAllowance() (gas: 228105)\n[PASS] test_transferFromInsufficientBalanceRollsBackAllowance() (gas: 114438)\n[PASS] test_transferFromSelfStillConsumesAllowance() (gas: 100743)\n[PASS] test_transferFromToZeroRollsBackAllowance() (gas: 111776)\n[PASS] test_transferFromUnlimitedAllowanceDoesNotDecrease() (gas: 122092)\n[PASS] test_transferFromZeroSenderReverts() (gas: 61016)\n[PASS] test_transferToZeroRevertsEvenForZeroAmount() (gas: 72811)\n[PASS] test_zeroTransferFromEmptyAccountEmitsEvent() (gas: 66472)\n[PASS] test_zeroTransferFromWithoutAllowanceSucceeds() (gas: 57046)\nSuite result: ok. 26 passed; 0 failed; 0 skipped; finished in 31.99ms (126.04ms CPU time)\n\nRan 1 test for test/StrataIMD.invariant.t.sol:StrataIMDInvariantTest\n[PASS] invariant_balancesAndAllowancesMatchLedgerAndSupplyIsFixed() (runs: 128, calls: 8192, reverts: 0)\n\n╭---------------+--------------+-------+---------+----------╮\n| Contract      | Selector     | Calls | Reverts | Discards |\n+===========================================================+\n| StrataHandler | approve      | 2722  | 0       | 0        |\n|---------------+--------------+-------+---------+----------|\n| StrataHandler | transfer     | 2785  | 0       | 0        |\n|---------------+--------------+-------+---------+----------|\n| StrataHandler | transferFrom | 2685  | 0       | 0        |\n╰---------------+--------------+-------+---------+----------╯\n\nLogs:\n  Bound result 1000000000000000000\n  Bound result 604045560285630960582242607\n  Bound result 3224\n  Bound result 0\n  Bound result 604045561285630960582239382\n  Bound result 94911765551429421965285387\n  Bound result 0\n  Bound result 0\n  Bound result 0\n  Bound result 0\n  Bound result 957625570\n  Bound result 1000000000\n  Bound result 281544670937960821555816059\n  Bound result 258\n  Bound result 737963694047123647255306061\n  Bound result 2009\n  Bound result 4758\n  Bound result 368079706061877200324916995\n  Bound result 228\n  Bound result 0\n  Bound result 558900260265658893426926703\n  Bound result 0\n  Bound result 0\n  Bound result 0\n  Bound result 0\n  Bound result 0\n  Bound result 2827\n  Bound result 5339\n  Bound result 2590\n  Bound result 115273474953154\n  Bound result 1058133026239059202153\n  Bound result 208\n  Bound result 46232213213023482653634730\n  Bound result 165444153588614524594112577\n  Bound result 1264811663\n  Bound result 477\n  Bound result 18\n  Bound result 1\n  Bound result 340647507637286159135044683\n  Bound result 0\n  Bound result 897652910513824439615144427\n  Bound result 10\n  Bound result 3015\n  Bound result 3\n  Bound result 115273474955981\n  Bound result 262959570814768004658639710\n  Bound result 0\n  Bound result 21974745598751658457741545\n  Bound result 2683\n  Bound result 0\n  Bound result 123000000000000000000\n  Bound result 53591\n  Bound result 116906604632555970020170260\n  Bound result 259\n\nSuite result: ok. 1 passed; 0 failed; 0 skipped; finished in 2.92s (2.92s CPU time)\n\nRan 2 test suites in 2.93s (2.96s CPU time): 27 tests passed, 0 failed, 0 skipped (27 total tests)\n","passed":true},{"durationMs":72,"exitCode":0,"name":"source-index","output":"{\"v\":1,\"entryPoints\":[\"StrataIMD.approve(address,uint256)\",\"StrataIMD.transfer(address,uint256)\",\"StrataIMD.transferFrom(address,address,uint256)\"],\"files\":{\".gitignore\":4,\"DEPENDENCIES.md\":16,\"LICENSE\":21,\"README.md\":58,\"SHA256SUMS\":32,\"foundry.toml\":23,\"remappings.txt\":2,\"src/StrataIMD.sol\":16,\"test/StrataIMD.invariant.t.sol\":88,\"test/StrataIMD.t.sol\":384},\"excluded\":[\"lib/\",\"node_modules/\"],\"truncated\":false}","passed":true},{"durationMs":1460,"exitCode":0,"name":"slither","output":"slither: no results at low impact or above","passed":true},{"durationMs":370,"exitCode":0,"name":"aderyn","output":"[low] large-numeric-literal at src/StrataIMD.sol:9: Large Numeric Literal","passed":true}],"detail":"all checks passed","evaluation":"checks","profile":"foundry","status":"accepted","submissionHash":"b340de3927f4f1af40a8567d4206a37a96e78a92c78db357ae4695474409e97b","verifiedTreeHash":"6e7eec2a8d1d3811155af5545402f593bdae86c7","verifierVersion":"0.1.0+94826a22"},{"checks":[{"durationMs":2245,"exitCode":0,"name":"build","output":"Compiling 27 files with Solc 0.8.26\nSolc 0.8.26 finished in 2.08s\nCompiler run successful!\n","passed":true},{"durationMs":12328,"exitCode":0,"name":"test","output":"No files changed, compilation skipped\n\nRan 26 tests for test/StrataIMD.t.sol:StrataIMDTest\n[PASS] testFuzz_transferAboveBalanceReverts(uint256) (runs: 512, μ: 65065, ~: 65405)\nLogs:\n  Bound result 115792089237316195423570985008687907853269984665639564039457584007913129659122\n\n[PASS] testFuzz_transferFromAboveAllowanceReverts(uint256,uint256) (runs: 512, μ: 116028, ~: 116395)\nLogs:\n  Bound result 540170120294513216210008401\n  Bound result 1000000000000000000000000000\n\n[PASS] testFuzz_transferFromRespectsAllowance(uint256,uint256) (runs: 512, μ: 155704, ~: 157970)\nLogs:\n  Bound result 527132223764029569032951940\n  Bound result 527132223764029569032951940\n\n[PASS] testFuzz_transfersConserveSupply(uint256) (runs: 512, μ: 148041, ~: 148635)\nLogs:\n  Bound result 999999999999999999999999999\n\n[PASS] test_approveDoesNotRequireBalance() (gas: 71880)\n[PASS] test_approveEmitsEventAndCanReplaceOrRevokeAllowance() (gas: 178644)\n[PASS] test_approveZeroSpenderReverts() (gas: 37925)\n[PASS] test_constructorEmitsMintTransfer() (gas: 5953)\n[PASS] test_create2FactoryReceivesSupplyAndLaunchTransfersAreExact() (gas: 693273)\n[PASS] test_deployerCannotSpendHolderTokensWithoutApproval() (gas: 92688)\n[PASS] test_metadataAndEntireInitialSupply() (gas: 103272)\n[PASS] test_noMintBurnOrAdministrativeEntryPoints() (gas: 1260881)\n[PASS] test_rejectsNativeCurrency() (gas: 37194)\n[PASS] test_runtimeContainsNoProhibitedOpcodes() (gas: 1038921)\n[PASS] test_selfTransferPreservesBalance() (gas: 51559)\n[PASS] test_transferEmitsEventAndMovesExactAmount() (gas: 89346)\n[PASS] test_transferEntireSupply() (gas: 71705)\n[PASS] test_transferFromEmitsEventAndConsumesAllowance() (gas: 228105)\n[PASS] test_transferFromInsufficientBalanceRollsBackAllowance() (gas: 114438)\n[PASS] test_transferFromSelfStillConsumesAllowance() (gas: 100743)\n[PASS] test_transferFromToZeroRollsBackAllowance() (gas: 111776)\n[PASS] test_transferFromUnlimitedAllowanceDoesNotDecrease() (gas: 122092)\n[PASS] test_transferFromZeroSenderReverts() (gas: 61016)\n[PASS] test_transferToZeroRevertsEvenForZeroAmount() (gas: 72811)\n[PASS] test_zeroTransferFromEmptyAccountEmitsEvent() (gas: 66472)\n[PASS] test_zeroTransferFromWithoutAllowanceSucceeds() (gas: 57046)\nSuite result: ok. 26 passed; 0 failed; 0 skipped; finished in 104.93ms (387.71ms CPU time)\n\nRan 13 tests for test/StrataIMD.adversarial.t.sol:StrataIMDAdversarialTest\n[PASS] testFuzz_failedSpendCanBeRetriedAfterFunding(uint256,uint256) (runs: 1000, μ: 333473, ~: 333760)\nLogs:\n  Bound result 152230006445496903374660998\n  Bound result 999999999999999999999999998\n\n[PASS] testFuzz_replacingUnlimitedApprovalEnforcesFiniteLimit(uint256) (runs: 1000, μ: 239275, ~: 239637)\nLogs:\n  Bound result 999999999999999999999999998\n\n[PASS] testFuzz_splittingSpendMatchesSingleSpend(uint256,uint256,uint256) (runs: 1000, μ: 344400, ~: 345563)\nLogs:\n  Bound result 14505\n  Bound result 5000000000000000000\n  Bound result 115792089237316195423570985008687907853269984665640564039452584007913129625675\n\n[PASS] test_allowancesAreScopedToBothOwnerAndSpender() (gas: 349000)\n[PASS] test_contractSpenderCannotBorrowTransactionOriginAllowance() (gas: 417759)\n[PASS] test_largestFiniteAllowanceIsNotTreatedAsUnlimited() (gas: 226820)\n[PASS] test_maximumTransferAndSelfTransferRejectInsufficientBalance() (gas: 89170)\n[PASS] test_oneWeiRoundTripHasNoDustOrFee() (gas: 138526)\n[PASS] test_ownerNeedsAllowanceForTransferFromButCanTransferDirectly() (gas: 198662)\n[PASS] test_refundingOwnerDoesNotRestoreSpentAllowance() (gas: 206385)\n[PASS] test_unlimitedAllowanceDoesNotBypassBalanceChecks() (gas: 122585)\n[PASS] test_unlimitedApprovalCanBeRevokedAfterSpendingAndRefill() (gas: 233821)\n[PASS] test_zeroAmountDoesNotMakeInvalidAddressesValid() (gas: 97244)\nSuite result: ok. 13 passed; 0 failed; 0 skipped; finished in 105.10ms (304.76ms CPU time)\n\nRan 2 tests for test/StrataIMD.invariant.t.sol:StrataIMDInvariantTest\n[PASS] invariant_balancesAndAllowancesMatchLedgerAndSupplyIsFixed() (runs: 256, calls: 32768, reverts: 0)\n\n╭---------------+----------------------------------+-------+---------+----------╮\n| Contract      | Selector                         | Calls | Reverts | Discards |\n+===============================================================================+\n| StrataHandler | approve                          | 3863  | 0       | 0        |\n|---------------+----------------------------------+-------+---------+----------|\n| StrataHandler | approveAndSpend                  | 3543  | 0       | 0        |\n|---------------+----------------------------------+-------+---------+----------|\n| StrataHandler | rejectTransferAboveBalance       | 3625  | 0       | 0        |\n|---------------+----------------------------------+-------+---------+----------|\n| StrataHandler | rejectTransferFromAboveAllowance | 3554  | 0       | 0        |\n|---------------+----------------------------------+-------+---------+----------|\n| StrataHandler | rejectTransferFromAboveBalance   | 3616  | 0       | 0        |\n|---------------+----------------------------------+-------+---------+----------|\n| StrataHandler | rejectZeroAddress                | 3585  | 0       | 0        |\n|---------------+----------------------------------+-------+---------+----------|\n| StrataHandler | revokeAndAttemptSpend            | 3659  | 0       | 0        |\n|---------------+----------------------------------+-------+---------+----------|\n| StrataHandler | transfer                         | 3713  | 0       | 0        |\n|---------------+----------------------------------+-------+---------+----------|\n| StrataHandler | transferFrom                     | 3610  | 0       | 0        |\n╰---------------+----------------------------------+-------+---------+----------╯\n\nLogs:\n  Bound result 0\n  Bound result 0\n  Bound result 123000000000000000000\n  Bound result 260\n  Bound result 115792089237316195423570985008687907853269984665639564039457584117465793276084\n  Bound result 0\n  Bound result 9823\n  Bound result 1446\n  Bound result 447\n  Bound result 8\n  Bound result 115792089237316195423570985008687907853269984665639564039457584007913129687070\n  Bound result 24301\n  Bound result 115792089237316195423570985008687907853269984665640564039457584007913129631242\n  Bound result 36865\n  Bound result 999999999999999999999989729\n  Bound result 7044\n  Bound result 1\n  Bound result 0\n  Bound result 421707694357573083908874893\n  Bound result 291\n  Bound result 0\n  Bound result 0\n  Bound result 401\n  Bound result 115792089237316195423570985008687907853269984665639564039457584007913130310123\n  Bound result 3884\n  Bound result 1303\n  Bound result 7\n  Bound result 115792089237316195423570985008687907853269984665639564039457584007913129674781\n  Bound result 64710109452175126066190132938720310051311316372125528192910133932444383782439\n  Bound result 115792089237316195423570985008687907853269984665639564039457584007913129650213\n  Bound result 1303\n  Bound result 255\n  Bound result 123000000000000000000\n  Bound result 115792089237316195423570985008687907853269984665639564039457584007913129687070\n  Bound result 0\n  Bound result 192\n  Bound result 24301\n  Bound result 2877\n  Bound result 0\n  Bound result 242\n  Bound result 380\n  Bound result 34378\n  Bound result 0\n  Bound result 177\n  Bound result 599290588\n  Bound result 70\n  Bound result 155\n  Bound result 407\n  Bound result 7000000000000000000\n  Bound result 659918\n  Bound result 115792089237316195423570985008687907853269984665639564039464584007913129642955\n  Bound result 179349856035289705653302941\n  Bound result 20000000000000000000\n  Bound result 585778444371183651757907619\n  Bound result 115792089237316195423570985008687907853269984665640149817908955191564887548007\n  Bound result 115792089237316195423570985008687907853269984665639978261013212824261371785907\n  Bound result 115792089237316195423570985008687907853269984665640564039457584007913129639770\n  Bound result 43\n  Bound result 115792089237316195423570985008687907853269984665640149819052216136420687415105\n  Bound result 115792089237316195423570985008687907853269984665640564039450584007913129639925\n  Bound result 143\n  Bound result 0\n  Bound result 4360\n  Bound result 53\n  Bound result 6603\n  Bound result 7000000000000000000\n  Bound result 0\n  Bound result 115792089237316195423570985008687907853269984665639981175205811042723671145001\n  Bound result 1650014642778453332200423491595583876647479405985678318652001988536990148167\n  Bound result 0\n  Bound result 36865\n  Bound result 1900415988556\n  Bound result 0\n  Bound result 0\n  Bound result 115792089237316195423570985008687907853269984665640564039450584007913129633566\n  Bound result 115792089237316195423570985008687907853269984665640564039457584007913129639905\n  Bound result 0\n  Bound result 211\n  Bound result 2560077217724511247444346513425155027501341527134035068851747058\n  Bound result 171556902742367303515889354\n  Bound result 115792089237316195423570985008687907853269984665640564039457584007913129639935\n  Bound result 5270\n  Bound result 36865\n  Bound result 20\n  Bound result 710\n  Bound result 319854868413\n  Bound result 3154\n  Bound result 127\n  Bound result 0\n  Bound result 115792089237316195423570985008687907853269984665640564039450584008142078759153\n  Bound result 0\n  Bound result 414221548628816348242055325\n  Bound result 523225646067116257509709941\n  Bound result 115792089237316195423570985008687907853269984665640564039450584007917424600392\n  Bound result 3773737478\n  Bound result 0\n  Bound result 115792089237316195423570985008687907853269984665640149817908955191564887591494\n\n[PASS] test_rejectionsThenSpendingAndRevocationPreserveLedger() (gas: 4090004)\nLogs:\n  Bound result 500000000000000000000000000\n  Bound result 1\n  Bound result 115792089237316195423570985008687907853269984665640564039457584007913129639935\n  Bound result 1000000000000000000000000000\n  Bound result 115792089237316195423570985008687907853269984665640564039457584007913129639935\n  Bound result 1\n  Bound result 1\n  Bound result 1\n  Bound result 1\n  Bound result 499999999999999999999999999\n  Bound result 500000000000000000000000000\n\nSuite result: ok. 2 passed; 0 failed; 0 skipped; finished in 12.20s (12.20s CPU time)\n\nRan 3 test suites in 12.20s (12.41s CPU time): 41 tests passed, 0 failed, 0 skipped (41 total tests)\n","passed":true},{"durationMs":66,"exitCode":0,"name":"source-index","output":"{\"v\":1,\"entryPoints\":[\"StrataIMD.approve(address,uint256)\",\"StrataIMD.transfer(address,uint256)\",\"StrataIMD.transferFrom(address,address,uint256)\"],\"files\":{\".gitignore\":4,\"DEPENDENCIES.md\":16,\"LICENSE\":21,\"README.md\":58,\"SHA256SUMS\":32,\"foundry.toml\":23,\"remappings.txt\":2,\"src/StrataIMD.sol\":16,\"test/StrataIMD.adversarial.t.sol\":259,\"test/StrataIMD.invariant.t.sol\":243,\"test/StrataIMD.t.sol\":384},\"excluded\":[\"lib/\",\"node_modules/\"],\"truncated\":false}","passed":true}],"detail":"all checks passed","evaluation":"checks","profile":"foundry","status":"accepted","submissionHash":"f61909ae72439f2984a36f60a24043c44169dc93a4a30239061c371be0b8ed4a","verifiedTreeHash":"7d911b9686fd87ba143364d363f9551f80c712a0","verifierVersion":"0.1.0+94826a22"}]}