{"assessments":[],"deployments":[],"fuzz":[],"identity":{"adapter":"0xde152afb7db5373f34876e1499fbd893a82dd336","chainId":1,"collection":"0x0000ec93127baa929e58e97dd0095a2bfb38ec1d","registry":"0x8004a169fb4a3325136eb29fa0ceb6d2e539a432"},"interpretation":"Records acceptance and evidence. Neither completion nor an AI assessment establishes correctness, safety, or independent review.","jobId":"ce98ced1-f003-48d7-9f6b-27f8c403e5d0","kind":"shape:chain","nodes":[{"acceptedSubmissionHash":"fbb3b4bb5bd19bd06c6b6719896e0c973db136e1b88ba0df7aa6fd0854e3e48f","dependsOn":["build_contract_project","write_foundry_tests","manifest"],"execution":{"network":false,"profile":"foundry","requires":[],"skillHash":"e5ac2cb1fd91a56aa40b16487fc230c48de0d317c8266140331dd3219bb40a85","skillId":"audit-specialist","tools":[]},"key":"audit_economics","kind":"code","role":"review","skillHash":"e5ac2cb1fd91a56aa40b16487fc230c48de0d317c8266140331dd3219bb40a85","skillId":"audit-specialist","state":"accepted"},{"acceptedSubmissionHash":"353d1ffa7f9c867df1454495d8ec4316769843a0cddd5cb201234c1a8a903eaf","dependsOn":["build_contract_project","write_foundry_tests","manifest"],"execution":{"network":false,"profile":"foundry","requires":[],"skillHash":"e5ac2cb1fd91a56aa40b16487fc230c48de0d317c8266140331dd3219bb40a85","skillId":"audit-specialist","tools":[]},"key":"audit_flow","kind":"code","role":"review","skillHash":"e5ac2cb1fd91a56aa40b16487fc230c48de0d317c8266140331dd3219bb40a85","skillId":"audit-specialist","state":"accepted"},{"acceptedSubmissionHash":"66dace6fc21fe6d5c77fb0f767591f1a195b90b73c40f98d9d99b5b3ca928df6","dependsOn":["build_contract_project","write_foundry_tests","manifest","audit_math","audit_permissions","audit_economics","audit_flow"],"execution":{"network":false,"profile":"foundry","requires":[],"skillHash":"3014f1ea5961918ca059453a484bf4c8bcbbfc2248dbe31d94ac7c5cdf8f50bd","skillId":"audit-judge","tools":[]},"key":"audit_judge","kind":"code","role":"review","skillHash":"3014f1ea5961918ca059453a484bf4c8bcbbfc2248dbe31d94ac7c5cdf8f50bd","skillId":"audit-judge","state":"accepted"},{"acceptedSubmissionHash":"13c44d2749f10a0bf34c2d743729440d22315bef2a415e11c2b9bd9d093ae64a","dependsOn":["build_contract_project","write_foundry_tests","manifest"],"execution":{"network":false,"profile":"foundry","requires":[],"skillHash":"e5ac2cb1fd91a56aa40b16487fc230c48de0d317c8266140331dd3219bb40a85","skillId":"audit-specialist","tools":[]},"key":"audit_math","kind":"code","role":"review","skillHash":"e5ac2cb1fd91a56aa40b16487fc230c48de0d317c8266140331dd3219bb40a85","skillId":"audit-specialist","state":"accepted"},{"acceptedSubmissionHash":"c7b543ac8b5a70074728f1b5a0c68311ee877735a93db6e4f40ebcfd184370b0","dependsOn":["build_contract_project","write_foundry_tests","manifest"],"execution":{"network":false,"profile":"foundry","requires":[],"skillHash":"e5ac2cb1fd91a56aa40b16487fc230c48de0d317c8266140331dd3219bb40a85","skillId":"audit-specialist","tools":[]},"key":"audit_permissions","kind":"code","role":"review","skillHash":"e5ac2cb1fd91a56aa40b16487fc230c48de0d317c8266140331dd3219bb40a85","skillId":"audit-specialist","state":"accepted"},{"acceptedSubmissionHash":"c9169557294fc312b03e1842c64399272c9437b2e9eff4885df947d36bd54daf","dependsOn":[],"execution":{"network":false,"profile":"foundry","requires":[],"skillHash":"587567a5ef71546b5973ceaf6ef1dbbd590f49503b5ac9a6973ed86b89584857","skillId":"build-contract-project","tools":[]},"key":"build_contract_project","kind":"code","role":"implement","skillHash":"587567a5ef71546b5973ceaf6ef1dbbd590f49503b5ac9a6973ed86b89584857","skillId":"build-contract-project","state":"accepted"},{"acceptedSubmissionHash":"85e81e240a699fe3b37c05c6879c2a0bdf9c5537f678b94b5ee8a1aa5929ae95","dependsOn":["build_contract_project","write_foundry_tests"],"execution":{"network":false,"profile":"foundry","requires":[],"tools":[]},"key":"manifest","kind":"code","role":"integrate","skillHash":null,"skillId":null,"state":"accepted"},{"acceptedSubmissionHash":"aa8b01e1b7a0ff7b81f5aff64da4e6982afe5823c6f077c87769659248c53185","dependsOn":["build_contract_project"],"execution":{"network":false,"profile":"foundry","requires":[],"skillHash":"73431852439ad3a343f3d2b7db1c43cd363b9f48f9bb51497374a0cf6d50b223","skillId":"write-foundry-tests","tools":[]},"key":"write_foundry_tests","kind":"code","role":"tests","skillHash":"73431852439ad3a343f3d2b7db1c43cd363b9f48f9bb51497374a0cf6d50b223","skillId":"write-foundry-tests","state":"accepted"}],"objective":"[SIMD-LAUNCH]\nA custom token: SIMDTEST (SIMDTEST).\nToken name: SIMDTEST\nToken symbol: SIMDTEST\nToken supply: 1,000,000,000 with 18 decimals, all minted once to the deployer in the constructor.\nMinting after launch: none, the supply is fixed forever.\nWho can call what: no owner and no admin functions; every parameter is a fixed constant.\n\nWhat it does:\n1. The token is named 'SIMDTEST' with symbol 'SIMDTEST', 1,000,000,000 fixed total supply minted with 18 decimals.\n2. 90% of the total supply seeds the Uniswap v4 pool; the remaining 10% is reserved for the swarm distribution outside the contract.\n3. The Uniswap v4 PoolManager is fixed as 0x000000000004444c5dc75cB358380D2e3dE08A90.\n4. On transfers *from* the PoolManager (i.e., buys), the token burns exactly 1% of the transferred amount, permanently reducing total supply.\n5. Transfers *to* the PoolManager (sells and pool seeding) and wallet-to-wallet transfers incur no fees.\n6. The burn fee applies only to buys; sells and normal transfers remain untaxed to ensure Uniswap v4 pool settlement correctness.\n7. No minting functions beyond the initial total supply mint in the constructor.\n8. No owner or admin powers; all parameters are fixed constants; the contract has no ownership.\n9. No dynamic fees, no blacklists or special permissions.\n10. The 10% swarm allocation is not minted or sent by this contract.\n\nWho can call what:\n- No owner or admin functions exist.\n- Anyone can transfer tokens freely, with the 1% burn triggered automatically when transferring *from* the PoolManager address.\n\nTests:\n1. Confirm total supply is 1,000,000,000 * 10^18 after deployment.\n2. Confirm no owner or admin functions exist.\n3. Transfer tokens from PoolManager address triggers exactly 1% burn (balance and total supply decrease accordingly).\n4. Transfer tokens to PoolManager address does not burn or fee.\n5. Token transfers between regular wallets have no fees and total supply remains unchanged.\n6. Initial balances confirm 90% minted to deployer (for pool seeding).\n7. Confirm Uniswap v4 PoolManager address is immutable and fees only apply on transfers from this address.\n8. Confirm total supply never increases after deployment.\n\nBuild requirements (mandatory):\n- A complete Foundry project at the repository root: foundry.toml with solc 0.8.26, evm_version cancun, optimizer on and bytecode_hash = \"none\", so the build is reproducible.\n- Token contract: SIMDTESTToken. No selfdestruct and no delegatecall anywhere. No proxies, no owner, no upgradeability.\n- Supply distribution is done by the launch factory: it mints the supply, seeds the pool from the deployer balance, sends the swarm's 10% through its Merkle distributor and any remainder to remainderTo. No contract here sends the swarm allocation, and the token always mints the entire 1,000,000,000 (1e27 units) to its deployer: never subtract the swarm's 10% (IMD's protected invariants park any launch whose deployer holds less).\n- Chain: Ethereum mainnet (chainId 1). Swaps happen in Uniswap v4, so the pool's tokens move to and from the PoolManager 0x000000000004444c5dc75cB358380D2e3dE08A90.\n- launch.json pool: pairedCurrency 0xd34a99bc0f67ae1bbd63c660e6d0b0dd03e263b7, fee 3000, tickSpacing 60, initialPrice \"125270724187523965593206900\" (paired-currency minor units per SIMDTEST minor unit with SIMDTEST as currency0, provenance only; the deployer derives the real opening price from the economics using the deployed currency order). launch.json also carries the economics block below.\n- launch.json economics, exactly: poolBps 9000, initialMarketCapWei \"2500000000000000000000\" (2500 IMD opening market cap), remainderTo 0x000000000000000000000000000000000000dead.","parentJobId":null,"planHash":"e585a5fe1fef89235c864646d8536b686c9cfd9ef5eeb0dc79b4736f2990e90e","previousHash":"0000000000000000000000000000000000000000000000000000000000000000","projectId":"ce98ced1-f003-48d7-9f6b-27f8c403e5d0","publication":{"commit":null,"deliveredAt":null,"repoUrl":"https://github.com/identity-md-launches/launch-998-simdtest"},"receiptIdentity":{"adapter":"0xde152afb7db5373f34876e1499fbd893a82dd336","chainId":1,"collection":"0x0000ec93127baa929e58e97dd0095a2bfb38ec1d","registry":"0x8004a169fb4a3325136eb29fa0ceb6d2e539a432"},"registry":"0xb6d0a187b050fa5bb0b87033a203f37becf4a775","research":[],"schema":"identitymd-work-v1","signals":[{"agentId":"52166","feedbackHash":"84628b658fb4302a6c59f4da12252a69795b8c697039d0088fcf96c9a5b11813","nodeKey":"audit_economics","submissionHash":"fbb3b4bb5bd19bd06c6b6719896e0c973db136e1b88ba0df7aa6fd0854e3e48f","tag1":"review:submission","tag2":"acceptance-v2","value":1},{"agentId":"52167","feedbackHash":"9a65c520151bca41059b4c96137cf4a0ef843035129f982b1db8fbf3893ce179","nodeKey":"audit_flow","submissionHash":"353d1ffa7f9c867df1454495d8ec4316769843a0cddd5cb201234c1a8a903eaf","tag1":"review:submission","tag2":"acceptance-v2","value":1},{"agentId":"51148","feedbackHash":"ccc57787e4e5f10812d454075970ef1a1b567d3ac80b09229ca4743a48997c22","nodeKey":"audit_judge","submissionHash":"66dace6fc21fe6d5c77fb0f767591f1a195b90b73c40f98d9d99b5b3ca928df6","tag1":"review:submission","tag2":"acceptance-v2","value":1},{"agentId":"51428","feedbackHash":"447c7ae0a6c7ee09fc83e060b80206b42abfdc6e6a451d596aa6c010840657db","nodeKey":"audit_math","submissionHash":"13c44d2749f10a0bf34c2d743729440d22315bef2a415e11c2b9bd9d093ae64a","tag1":"review:submission","tag2":"acceptance-v2","value":1},{"agentId":"52157","feedbackHash":"07925fba36ff50ea44ad5360098a13b3d2425dfc4c45897cddb8ca1e3f8f13fe","nodeKey":"audit_permissions","submissionHash":"c7b543ac8b5a70074728f1b5a0c68311ee877735a93db6e4f40ebcfd184370b0","tag1":"review:submission","tag2":"acceptance-v2","value":1},{"agentId":"52148","feedbackHash":"449d02ee0693f8c6fc6ac224c704b259e153a2ed90b5231834fb6b9baea0a7a2","nodeKey":"build_contract_project","submissionHash":"f3a35ab53f7bd345e880ad201f2137efd0900ad50b4ac7e910da175f8be59005","tag1":"verification:checks","tag2":"acceptance-v2","value":0},{"agentId":"51241","feedbackHash":"efddbfd0b19c2911f530fabb7f3444d43b65fd1c0525ef92b5e49de081734e7b","nodeKey":"build_contract_project","submissionHash":"c9169557294fc312b03e1842c64399272c9437b2e9eff4885df947d36bd54daf","tag1":"verification:checks","tag2":"acceptance-v2","value":1},{"agentId":"51313","feedbackHash":"1502fce9edfea68a5e7f339aea2407c5677db99ca76f46687809d77ade76a277","nodeKey":"manifest","submissionHash":"85e81e240a699fe3b37c05c6879c2a0bdf9c5537f678b94b5ee8a1aa5929ae95","tag1":"verification:checks","tag2":"acceptance-v2","value":1},{"agentId":"52143","feedbackHash":"ab4aeaf106ebc51ed4c92d2d7de81e6976fb046f513f11ac0951ba95cf0e7fe0","nodeKey":"write_foundry_tests","submissionHash":"aa8b01e1b7a0ff7b81f5aff64da4e6982afe5823c6f077c87769659248c53185","tag1":"verification:checks","tag2":"acceptance-v2","value":1}],"site":null,"snapshotHash":"29c2013751776ec9cfbe8f04c0510e347f55d8f8d4a24c4921fff8a1ac5cb38c","state":"completed","submissions":[{"artifacts":[],"attempt":1,"bundleHash":null,"device":"bc1e515ca5c78ac4","findings":[{"citation":"resolved","description":"Boundary: the sentinel branch `from == POOL_MANAGER` is the token's only notion of a buy. The calling code assumes that an outgoing PoolManager transfer is a swap output. At the Uniswap v4 boundary the same `take` path also delivers (a) a liquidity provider's principal when `modifyLiquidity` is called with a negative delta, (b) accrued LP fees, (c) protocol fees via `collectProtocolFees`, and (d) ERC-6909 claim redemptions. Each of those is debited `amount` from the PoolManager and credited `amount - floor(amount/100)` to the recipient, with the difference burned. Requirement 6 of the brief states the burn 'applies only to buys; sells and normal transfers remain untaxed', and requirement 4 glosses from-PoolManager transfers as '(i.e., buys)'. A liquidity withdrawal is neither a buy nor a sell, yet it is taxed. Whoever provides liquidity after launch (or the factory, if it ever unwinds the seed) receives 99% of the token side back. The README documents this consequence, so it is the author's reading of the brief; it is reported because the brief's 'only buys' guarantee does not hold and the loss is concrete. Fixing it inside the token is not possible without a hook, because the token cannot distinguish a swap output from a withdrawal; the requester must either accept and restate the rule as 'every PoolManager outflow burns 1%' or move the burn into a v4 hook that acts only on swaps. Reproduced locally with the vendored PoolManager runtime placed at the pinned address; the reproduction field gives the exact calls and observed values.","line":67,"path":"src/SIMDTESTToken.sol","reproduction":"State: chainId 1, real PoolManager runtime at 0x000000000004444c5dc75cB358380D2e3dE08A90, pool SIMDTEST/IMD fee 3000 spacing 60 initialised at sqrtPriceX96 125270724187523965593206900, provider seeds 9e26 single-sided (liquidity L). Call: provider unlocks and calls modifyLiquidity(key, {lower, upper, -L/2}) then take(token, provider, delta). Observed: gross token delta 449999999999999999999999380; provider balance rises by 445499999999999999999999387; totalSupply falls by 4499999999999999999999993 (4.5 million SIMDTEST burned). Expected under brief requirement 6: the provider receives its full 449999999999999999999999380 and totalSupply is unchanged, because a withdrawal is not a buy.","severity":"low","snippet":"        uint256 burned = from == POOL_MANAGER ? amount * BUY_BURN_BPS / BPS_DENOMINATOR : 0;","title":"Every PoolManager outflow is burned, so liquidity withdrawals and fee collections lose 1% although the brief says the burn applies only to buys"},{"citation":"resolved","description":"Boundary x invariant seam. The invariant the brief states is 'transfers from the PoolManager (i.e., buys) burn exactly 1%'. The code enforces the burn only when an ERC-20 transfer with `from == POOL_MANAGER` executes. Uniswap v4 lets a swapper settle a positive delta with `PoolManager.mint(to, currencyId, amount)` (ERC-6909 claim tokens) instead of `take`, and settle a negative delta with `PoolManager.burn(from, currencyId, amount)` instead of paying ERC-20. Neither path calls the token, so a buy, a hold, and a sell can all occur without any burn, and claims are themselves transferable between accounts via the PoolManager's ERC-6909 `transfer`. The burn is therefore an exit-from-PoolManager burn rather than a buy burn. No holder loses funds and nothing in the launch flow breaks (the protected harness takes ERC-20, which is burned as intended), but the stated guarantee is weaker than written. If the requester requires every buy to burn, a swap hook is needed; if the current rule is acceptable, the specification and README should state that claim-settled swaps are exempt. Reproduced locally with the vendored PoolManager runtime placed at the pinned address; the reproduction field gives the exact calls and observed values.","line":67,"path":"src/SIMDTESTToken.sol","reproduction":"State: as in finding 1, trader holds 10 IMD. Call 1: trader unlocks, swap(key, exactInput 0.01 IMD) and settles the positive SIMDTEST delta with manager.mint(trader, uint160(token), delta). Observed: gross output 3964663420314388146441 SIMDTEST credited as ERC-6909 claims; token.totalSupply unchanged (1e27); token.balanceOf(trader) == 0. Expected per brief requirement 4: 39646634203143881464 SIMDTEST burned on the buy. Call 2: trader unlocks, swap(key, exactInput 3964663420314388146441 SIMDTEST) and settles by manager.burn(trader, uint160(token), 3964663420314388146441). Observed: claims 0, totalSupply still 1e27, trader has bought and sold without any burn.","severity":"low","snippet":"        uint256 burned = from == POOL_MANAGER ? amount * BUY_BURN_BPS / BPS_DENOMINATOR : 0;","title":"A buy settled as ERC-6909 claims is never burned, so the 1% buy burn can be sidestepped by trading entirely inside the PoolManager"},{"citation":"resolved","description":"Math precision: `amount * 100 / 10000` is floor(amount/100), so the burn is rounded in the buyer's favour by up to 99 minor units per transfer (amount 99 burns 0, amount 199 burns 1 = 0.50% instead of 1%). Because v4 lets the taker split a positive delta across many `take` calls inside one unlock, a buyer can take 99 units at a time and burn zero. Quantified against the vendored PoolManager: taking a 9900-unit output in 100 chunks of 99 costs 788004 gas versus 121273 gas for one take, to save 99 minor units (99e-18 SIMDTEST, worth about 2.5e-22 IMD at the 2500 IMD opening cap). The arithmetic itself is safe: `amount <= balanceOf[from] <= totalSupply <= 1e27`, so `amount * 100 <= 1e29` cannot overflow, `amount - burned` cannot underflow, and `totalSupply -= burned` cannot underflow. The README already states that transfers below 100 units burn zero. No action is required; recorded so the judge sees the rounding direction was checked.","line":66,"path":"src/SIMDTESTToken.sol","reproduction":"State: as in finding 1. Call: trader unlocks, swap(key, exactOutput 9900 SIMDTEST) and settles with 100 calls of take(token, trader, 99). Observed: trader receives 9900, totalSupply unchanged. Same swap settled with one take(token, trader, 9900): trader receives 9801, totalSupply falls by 99. Direct: PoolManager transfer(alice, 99) burns 0; transfer(alice, 199) burns 1.","severity":"info","snippet":"        // Round down to whole minor units: transfers below 100 units burn zero.","title":"Burn rounds down, so outflows below 100 minor units burn nothing and splitting takes avoids the burn; not economically exploitable"}],"hash":"13c44d2749f10a0bf34c2d743729440d22315bef2a415e11c2b9bd9d093ae64a","nodeId":"3a744223-c899-4abb-bd35-07a19ac3eabc","outcome":"completed","summary":"The review is complete. The findings file is at the repository root with three findings and nine coverage rows, and the scratch tests I used were removed so the tree is otherwise untouched.\n\n**Outcome.** The token's arithmetic is sound. The one multiplication cannot overflow because any amount is bounded by the sender's balance, which is bounded by a supply that only shrinks. Balance conservation holds on every path including PoolManager self-transfers, and all zero, max and zero-address edges revert or no-op correctly. The defects I found sit at the Uniswap v4 boundary, not in the integer math, and none is severe enough to need a proof file.\n\n**Findings reported** (all reproduced against the vendored PoolManager runtime at the pinned mainnet address):\n\n- **Low: non-buy outflows are burned.** The only notion of a buy is the sender being the PoolManager. Removing liquidity, collecting LP fees and protocol fees all travel the same path. Withdrawing half the seeded position burned 4.5 million SIMDTEST from the provider's own principal, against the brief's statement that the burn applies only to buys. The README documents this reading, so the requester must either restate the rule or move the burn into a hook.\n- **Low: claim-settled buys are never burned.** A swapper who settles with ERC-6909 claims instead of taking ERC-20, and sells back by burning claims, bought and resold about 3,965 SIMDTEST with zero burn. The rule is effectively an exit-from-PoolManager burn, not a buy burn. No funds are lost and the launch flow is unaffected.\n- **Info: rounding down and chunked takes.** Outflows under 100 minor units burn nothing, and splitting a take into 99-unit chunks avoids the burn entirely. Quantified: about 788k gas to save 99e-18 tokens, so it is not exploitable. Recorded so the rounding direction is visibly covered.\n\n**Coverage.** All three ABI entry points have rows. The approve and transferFrom paths hold. The transfer path carries finding 1, with finding 2 noted in the same row. Six additional rows record the invariants and boundaries I checked, including inbound seed and sell settlement in both currency orders.\n\n**Not reached.** Nothing within the assigned math, boundary and numerical-gap area was left unchecked. Live-state fork checks against the real paired token and router remain owed to the operator, as the project's own README already states.","treeHash":null,"usage":{"cachedInputTokens":1235900,"inputTokens":482,"model":"claude-fable-5-1","outputTokens":26666,"runtime":"claude","turns":25,"wallClockMs":389615}},{"artifacts":[],"attempt":1,"bundleHash":null,"device":"1ca477e8d9b58040","findings":[{"citation":"resolved","description":"DEPENDENCIES.md:3 describes lib/v4-core as 'unchanged upstream files' and DEPENDENCIES.md:12 says '`lib/SHA256SUMS` records the exact downloaded file contents'. Neither statement is true of the committed tree. The checksums recorded in lib/SHA256SUMS are the genuine upstream values (I fetched the eight files from github.com/Uniswap/v4-core at the pinned commit 46c6834698c48bc4a463a86d8420f4eb1d7f3b75 and their sha256 equals the recorded sums exactly), but the committed copies of PoolManager.sol, libraries/Hooks.sol, libraries/Pool.sol, libraries/SqrtPriceMath.sol, libraries/SwapMath.sol, libraries/TickBitmap.sol, types/Currency.sol and types/Slot0.sol have different bytes (e.g. committed PoolManager.sol = b3c68cb554af5d13d715ad9c9a0255e677f5d6ef1392980ffc3fd7d2fcc8b19d). Root cause: foundry.toml has no [fmt] ignore for lib/, so a `forge fmt` run (README.md:92 lists `forge fmt --check` as a project check, and it passes on the reformatted files) reflowed the vendored sources after the sums were recorded; both the files and the stale sums were then committed together in e45e019. I verified the deviation is semantically nil: with all whitespace stripped, seven files are byte-identical to upstream and Hooks.sol differs only by braces added around a single-statement `if` at upstream line 293. So the integration tests (test/UniswapV4.t.sol) do run the pinned PoolManager logic, and the token itself is unaffected. The defect is that the project's only offline provenance check for the vendored dependency fails, so a verifier or the judge cannot use it to confirm the fixture is the real v4 code, and the written claim of 'unchanged' files is inaccurate. Fix (either): regenerate lib/SHA256SUMS from the committed files and reword DEPENDENCIES.md to say the files are upstream content reformatted by forge fmt; or restore the eight files to their upstream bytes (then `forge fmt --check` will flag them until a [fmt] ignore for lib/ can be added to the protected foundry.toml).","line":10,"path":"lib/SHA256SUMS","reproduction":"State: HEAD dbc54cc, clean checkout. Input: `sha256sum -c lib/SHA256SUMS` from the repository root. Expected: 48 lines 'OK'. Actual: 40 OK, 8 'FAILED' (lib/v4-core/src/PoolManager.sol, libraries/Hooks.sol, libraries/Pool.sol, libraries/SqrtPriceMath.sol, libraries/SwapMath.sol, libraries/TickBitmap.sol, types/Currency.sol, types/Slot0.sol) and exit status 1. Cross-check: `git show HEAD:lib/v4-core/src/PoolManager.sol | sha256sum` = b3c68cb5..., while `curl -sL https://raw.githubusercontent.com/Uniswap/v4-core/46c6834698c48bc4a463a86d8420f4eb1d7f3b75/src/PoolManager.sol | sha256sum` = 3b6ab111... which is exactly the value on lib/SHA256SUMS:10. `diff -w` between upstream and committed shows only line-break/indentation moves (plus the Hooks.sol brace pair).","severity":"low","snippet":"3b6ab111dadf613e3cfd617e4b1c6ab75b5445cd15cbe52d7c6207fc02449717  lib/v4-core/src/PoolManager.sol","title":"Vendored v4-core provenance record does not verify: 8 of 48 checksums in lib/SHA256SUMS fail against the committed files"},{"citation":"resolved","description":"The brief's rule is 'on transfers from the PoolManager (i.e., buys), the token burns exactly 1%'. The code implements the first half of that sentence literally: the trigger is the sender address, and the token has no way to tell a swap payout from any other PoolManager.take(). In Uniswap v4 every token that leaves the manager goes through the same CurrencyLibrary.transfer call (lib/v4-core/src/types/Currency.sol:40), so the burn also applies to (a) an LP removing liquidity via modifyLiquidity with a negative delta and taking the owed token, and (b) collectProtocolFees for the token. The parenthetical '(i.e., buys)' in the brief is therefore inexact; README.md already states 'every outgoing PoolManager transfer is subject to the burn, including liquidity withdrawals or other payouts', so this is the requester's accepted design and not a code defect. I record it because: (1) the launch factory holds the seeded position and would receive 99% of the token side if it ever withdrew it; (2) v4's BalanceDelta reports the gross amount while the recipient receives net, so any integrator checking amountOutMinimum against the delta (e.g. a router) accepts 1% less than it believes it enforced; (3) none of the existing tests exercise the liquidity-removal, ERC-6909 claim-then-take, or collectProtocolFees paths, so this behaviour is documented but not pinned by the suite. The protected floor's flows (distributor transfer, claim, seed, buy, sell) are all unaffected: I reproduced each locally and they move exactly what they say.","line":67,"path":"src/SIMDTESTToken.sol","reproduction":"State: local v4 PoolManager built at 0x000000000004444c5dc75cB358380D2e3dE08A90 (as test/UniswapV4.t.sol does), pair fixture at 0xd34a...63b7, token deployed with address < pair so it is currency0, pool initialised at sqrtPriceX96 125270724187523965593206900, fee 3000, tickSpacing 60, no hook. An LP contract seeds the single-sided 90% position (lower = next 60-aligned tick above current, upper = 887220, liquidity L as in test/UniswapV4.t.sol _singleSidedPosition) via modifyLiquidity(+L) and settles with transfer+settle (no burn, balanceOf(MANAGER) == seeded). Then, with no swap having happened, the same LP calls modifyLiquidity(-L) and take(currency0, lp, delta.amount0()). Expected if only buys burned: lp balance increases by exactly `returned` (= delta.amount0()) and totalSupply is unchanged. Actual: lp balance increases by `returned - returned/100`, totalSupply decreases by `returned/100`, and a Transfer(MANAGER, address(0), returned/100) is emitted. I ran this as a scratch Foundry test (test/scratch/LiquidityRemovalBurn.t.sol, removed after the run) and both assertions on the actual values pass, i.e. the withdrawal is taxed.","severity":"info","snippet":"        uint256 burned = from == POOL_MANAGER ? amount * BUY_BURN_BPS / BPS_DENOMINATOR : 0;","title":"The 1% burn fires on every PoolManager outflow, not only on buys: a liquidity withdrawal or protocol-fee collection returns 99% and burns 1%"}],"hash":"353d1ffa7f9c867df1454495d8ec4316769843a0cddd5cb201234c1a8a903eaf","nodeId":"fd59e84e-9af0-4123-878e-e5bf7fbff792","outcome":"completed","summary":"Both cited snippets match the tree exactly, the JSON parses (2 findings, 12 coverage rows), scratch files are removed, and the working tree is clean apart from `.imd-findings.json`. Nothing further is outstanding — the review is complete.\n\n## Summary\n\n**Area:** Execution Trace, Periphery, First Principles — on `SIMDTESTToken` (77 lines, 3 state-changing entry points).\n\n**Result: the token holds.** I traced every path of `approve`, `transfer` and `transferFrom` against the three guides' failure modes — parameter divergence, value leaks, sentinel bypass (`type(uint256).max`, `address(0)`), stale reads, partial state updates, approval residuals, desynchronized coupling, boundary abuse (0 / max / self-transfer / manager self-transfer), and the overflow assumption on line 65. None break: allowance is debited on the gross amount before the move, debit precedes credit so self-transfers are exact, `sum(balances) == totalSupply` after every path, supply only ever decreases, and there are no external calls so no reentrancy or inconsistent intermediate state. I also reproduced all five launch-floor flows (distributor transfer, claim, seed, buy, sell) against the real v4 `PoolManager` compiled in place: each moves exactly what it says.\n\n**Findings written to `.imd-findings.json`:**\n\n1. **Low — periphery provenance record does not verify.** `sha256sum -c lib/SHA256SUMS` fails on 8 of 48 vendored v4-core files. I fetched the pinned upstream commit and showed the *recorded* sums are the true upstream values; the *committed* files were reflowed by `forge fmt` (no `[fmt]` ignore for `lib/`). I verified the deviation is semantically nil (whitespace-only, plus one brace pair in `Hooks.sol`), so the integration tests do run real v4 logic — but DEPENDENCIES.md's \"unchanged upstream files / exact downloaded contents\" claim is false and the only offline provenance check fails.\n2. **Info — the 1% burn fires on every PoolManager outflow, not only buys.** Reproduced with `modifyLiquidity(-L)` + `take`: an LP withdrawing gets 99% and 1% burns. This is exactly the requester's address-based rule and the README documents it, so not a defect; recorded because the brief's \"(i.e., buys)\" is inexact, routers checking v4 deltas enforce 1% less slippage than they think, and no existing test pins the LP-withdrawal / ERC-6909 / protocol-fee paths.\n\n**Coverage:** all 3 ABI entry points `holds`, plus 9 invariant/periphery rows. No critical/high, so no proof files were needed. Static-analysis leads: slither empty; aderyn's large-literal lead at line 11 is style only — the literal is exactly 1e27 and left out.","treeHash":null,"usage":{"cachedInputTokens":1326865,"inputTokens":460,"model":"claude-fable-5-1","outputTokens":28691,"runtime":"claude","turns":30,"wallClockMs":465833}},{"artifacts":[],"attempt":1,"bundleHash":null,"device":"f2a99efe911b5581","findings":[{"citation":"resolved","description":"The recorded dependency hashes do not match the vendored files used by the offline integration suite. DEPENDENCIES.md calls them unchanged upstream files, but eight entries fail verification. This breaks the supplied dependency integrity check; it does not establish a token vulnerability or malicious dependency change. Reconcile the provenance documentation and recorded hashes with the committed bytes while preserving the pinned upstream identity. Merges audit_flow finding a727c0484b1f42d2d962f3fdaff4eeb4f096fbf87ee4cc114dcef68d2274efa7.","line":10,"path":"lib/SHA256SUMS","reproduction":"From the repository root, run sha256sum -c lib/SHA256SUMS. Expected: all 48 entries verify and exit status is 0. Actual: 40 OK, eight FAILED, exit status 1. Failures: lib/v4-core/src/PoolManager.sol; lib/v4-core/src/libraries/Hooks.sol, Pool.sol, SqrtPriceMath.sol, SwapMath.sol, TickBitmap.sol; lib/v4-core/src/types/Currency.sol and Slot0.sol. Running sha256sum lib/v4-core/src/PoolManager.sol gives b3c68cb554af5d13d715ad9c9a0255e677f5d6ef1392980ffc3fd7d2fcc8b19d, whereas line 10 records 3b6ab111dadf613e3cfd617e4b1c6ab75b5445cd15cbe52d7c6207fc02449717. Both commands were executed against this tree.","severity":"low","snippet":"3b6ab111dadf613e3cfd617e4b1c6ab75b5445cd15cbe52d7c6207fc02449717  lib/v4-core/src/PoolManager.sol","title":"Vendored dependency integrity check fails for eight committed files"}],"hash":"66dace6fc21fe6d5c77fb0f767591f1a195b90b73c40f98d9d99b5b3ca928df6","nodeId":"b16627f8-3b69-4b1d-99c5-6eb187a7b77d","outcome":"completed","summary":"Wrote [.imd-findings.json](/home/seat6/.identitymd/work/ce98ced1-f003-48d7-9f6b-27f8c403e5d0/b16627f8-3b69-4b1d-99c5-6eb187a7b77d/.imd-findings.json) with one low-severity finding: eight vendored dependency checksums fail verification.\n\nAll three entry points are covered. Burn-related reports were dropped because they follow the specified PoolManager-source transfer rule.\n\nOffline build, formatting, manifest checks, and all 44 local tests passed with two seeds. No source or configuration files changed.","treeHash":null,"usage":{"cachedInputTokens":1141504,"inputTokens":112440,"model":"gpt-6-astra","outputTokens":6038,"runtime":"codex","turns":5,"wallClockMs":234808}},{"artifacts":[],"attempt":1,"bundleHash":"6dd9a158e2f46ed0f833ca21234b030919d34a2e22a73974b124b058b4df0e8f","device":"c4e8f98d7a2a37dc","findings":[],"hash":"85e81e240a699fe3b37c05c6879c2a0bdf9c5537f678b94b5ee8a1aa5929ae95","nodeId":"4c47915b-7432-43fe-a880-b1b3271948c9","outcome":"completed","summary":"Updated [launch.json](/root/.identitymd/work/ce98ced1-f003-48d7-9f6b-27f8c403e5d0/4c47915b-7432-43fe-a880-b1b3271948c9/launch.json), preserving the exact token, pool, and economics values and correcting the notes.\n\nValidation passed against the supplied schema and compiled constructor ABI. `forge build` succeeded; `forge test` passed all 44 tests.\n\nOnly `launch.json` changed.","treeHash":"8ae4d54b441325f446387d0ed8f1e1483d31b54f","usage":{"cachedInputTokens":305152,"inputTokens":47112,"model":"gpt-6-astra","outputTokens":3220,"runtime":"codex","turns":3,"wallClockMs":102819}},{"artifacts":[],"attempt":1,"bundleHash":"088f8c64f2285f0aaef41e8457dd875166f6b62f23a0e37ea123e29403d22423","device":"f138d40b9355e7bf","findings":[],"hash":"aa8b01e1b7a0ff7b81f5aff64da4e6982afe5823c6f077c87769659248c53185","nodeId":"b621d3a4-f0ff-416b-921b-666390eb44ff","outcome":"completed","summary":"Added 13 tests under `test/`, covering failure rollback, admin-call rejection, allowance invariants, and exact-output v4 swaps.\n\n`forge build` and `forge test` pass: **44 tests, 0 failures**, including 40,960 invariant calls.\n\nNo reproducible defects found. Integration tests run offline; live mainnet factory/router verification remains outstanding.","treeHash":"855acc19831223d59fa50a3b24e42a6eb33ac4d7","usage":{"cachedInputTokens":689280,"inputTokens":53330,"model":"gpt-6-astra","outputTokens":12163,"runtime":"codex","turns":5,"wallClockMs":379392}},{"artifacts":[],"attempt":1,"bundleHash":null,"device":"37eed9f56188ea8b","findings":[{"citation":"resolved","description":"The burn is keyed solely on an ERC-20 transfer whose `from` is the PoolManager. Uniswap v4 lets any unlock caller settle a positive token delta with `PoolManager.mint(to, currency.toId(), amount)` (an ERC-6909 claim) instead of `take`, and settle a negative delta with `PoolManager.burn(...)` instead of transferring tokens in. Neither path moves SIMDTEST out of the PoolManager, so `from == POOL_MANAGER` is never true and `burned` is 0. A trader therefore has two economically identical buy paths with different tax: the `take` path burns 1%, the claims path burns 0%, and the trader picks the favorable side. The claim is itself transferable (ERC-6909 `transfer`) and can be sold back into the pool via `burn`, so SIMDTEST exposure can be bought, held, transferred and sold indefinitely with zero burn. This contradicts brief items 4 and 6 ('on buys the token burns exactly 1%') and the deflation guarantee holders are promised; Uniswap's Universal Router and PositionManager both support claims settlement, so no custom contract is needed on mainnet. No funds are lost directly, which is why this is medium rather than high. A plain ERC-20 cannot see this flow at all; closing the gap needs a design decision by the requester: either a v4 hook (afterSwap) that applies the burn on the swap delta regardless of settlement method, or an explicit acceptance that the burn is an ERC-20-transfer rule and that claims-settled buys are untaxed, stated in README and launch.json notes.","line":67,"path":"src/SIMDTESTToken.sol","reproduction":"State: vendored PoolManager at 0x000000000004444c5dc75cB358380D2e3dE08A90, pair token fixture at 0xd34a99bc0f67ae1bbd63c660e6d0b0dd03e263b7, token as currency0, pool initialised at sqrtPriceX96 125270724187523965593206900, 90% of supply seeded single-sided (as in test/UniswapV4.t.sol). Call sequence by an unprivileged trader inside manager.unlock: (1) manager.swap(key, zeroForOne=false, amountSpecified=-0.01e18, limit=MAX_SQRT_PRICE-1) -> SIMDTEST delta +3964663420314388146441; (2) manager.mint(trader, uint256(uint160(token)), 3964663420314388146441); (3) sync/transfer/settle 0.01e18 pair tokens. Expected per brief: totalSupply drops by 39646634203143881464 (1% of gross). Actual: totalSupply stays 1e27, balanceOf(PoolManager) unchanged, trader holds a 3964663420314388146441 ERC-6909 claim. (4) later unlock: manager.swap(zeroForOne=true, -3964663420314388146441) then manager.burn(trader, id, 3964663420314388146441) and take the pair token: trader exits with pair tokens; totalSupply still 1e27. Compare the `take` path for the same swap (test/UniswapV4.t.sol _roundTrip): supply drops by gross/100. Demonstrated in test/scratch/ClaimsBypass.t.sol (test_BuyViaClaimsThenSellViaClaimsNeverBurns, test_ClaimsAreTransferableWithoutBurn) and the failing proof below.","severity":"medium","snippet":"        uint256 burned = from == POOL_MANAGER ? amount * BUY_BURN_BPS / BPS_DENOMINATOR : 0;","title":"Buys settled with PoolManager ERC-6909 claims never trigger the 1% burn (economics x asymmetry seam)"},{"citation":"resolved","description":"Brief item 6 says the burn 'applies only to buys'. The code applies it to any transfer whose `from` is the PoolManager, which also covers `modifyLiquidity` with negative liquidity followed by `take` (the LP removing its position), `collectProtocolFees` paid to Uniswap governance, and `take` of accrued LP fees. The factory's single-sided seed is the only position at launch, so the main victim is the launch's own liquidity owner if it ever unwinds, plus Uniswap protocol-fee collection. README already documents this ('every outgoing PoolManager transfer is subject to the burn'), and the brief's own wording equates PoolManager outflows with buys, so this is reported as a low-severity guarantee mismatch for the requester to confirm, not a loss-of-funds defect. If non-buy outflows must be untaxed, the token cannot distinguish them; the same hook-based design decision as finding 1 applies.","line":67,"path":"src/SIMDTESTToken.sol","reproduction":"Same pool setup as finding 1. Liquidity owner calls, inside unlock, manager.modifyLiquidity(key, {tickLower, tickUpper, liquidityDelta = -liquidity, salt 0}) returning SIMDTEST delta +899999999999999999999998760, then manager.take(token, owner, 899999999999999999999998760). Expected (brief item 6: not a buy, no fee): owner balance +899999999999999999999998760, totalSupply unchanged. Actual: balanceOf(PoolManager) -899999999999999999999998760, owner balance +891000000000000000000001272, totalSupply = 1e27 - 8999999999999999999999987. Demonstrated in test/scratch/ClaimsBypass.t.sol test_LiquidityRemovalIsBurnedOnePercent (passes on current code).","severity":"low","snippet":"        uint256 burned = from == POOL_MANAGER ? amount * BUY_BURN_BPS / BPS_DENOMINATOR : 0;","title":"Every PoolManager outflow is burned, not only buys: liquidity withdrawals and fee collection lose 1%"}],"hash":"c7b543ac8b5a70074728f1b5a0c68311ee877735a93db6e4f40ebcfd184370b0","nodeId":"197b015e-c750-44dd-8db7-abbad2c89d8a","outcome":"completed","summary":"Review complete. The findings file is written and parses cleanly.\n\n**What I did.** I read the Senior Auditor's Mindset and the Access Control, Trust Gap and Asymmetry guides, then traced every entry point of `src/SIMDTESTToken.sol` against them. I ran the existing suite (44 tests pass) and reproduced each lead against the vendored Uniswap v4 PoolManager in scratch tests.\n\n**Access control holds.** The contract has no owner, role, initializer, fallback or receive. The constructor mints exactly 1e27 to the factory and hands out nothing. All admin selectors revert from every launch role. Supply has one writer after deployment, and it only decreases.\n\n**Findings written to `.imd-findings.json`:**\n\n1. **Medium: claims-settled buys never burn.** The burn fires only on an ERC-20 transfer whose sender is the PoolManager. Uniswap v4 lets any trader settle the SIMDTEST leg with ERC-6909 claims (`mint` on buy, `burn` on sell) instead of `take`, so no tokens leave the PoolManager and nothing burns. A 0.01 IMD buy yields 3,964.66 SIMDTEST gross with zero burn, where the `take` path burns 39.65. The claim is transferable and can be sold back without ever burning. This breaks brief items 4 and 6 for any trader using a claims-aware router. A plain ERC-20 cannot see this flow, so the fix is a requester design decision (afterSwap hook, or explicitly documenting the gap). A self-contained proof fails on the current code.\n\n2. **Low: non-buy PoolManager outflows are burned.** Liquidity removal and protocol-fee collection are taxed 1% even though they are not buys. The README already documents this and the brief's own wording equates outflows with buys, so it is reported for confirmation only.\n\n**Coverage.** All three listed entry points have rows, plus seven invariant and asymmetry rows, including the PoolManager self-take edge case (self-harm only, not reported) and the gross-versus-net slippage note (documented, not reported). No area in my assignment was left unreached. Fork runs against live mainnet state remain outside this review.","treeHash":null,"usage":{"cachedInputTokens":814567,"inputTokens":322,"model":"claude-fable-5-1","outputTokens":25011,"runtime":"claude","turns":25,"wallClockMs":362965}},{"artifacts":[],"attempt":2,"bundleHash":"0a2e51be0edbbcbbebbdc12e0d85a265c47437d589cbc920ed59f2f3b1faa3ad","device":"b6e7758e5e0349d3","findings":[],"hash":"c9169557294fc312b03e1842c64399272c9437b2e9eff4885df947d36bd54daf","nodeId":"074174cd-25e3-4c28-866d-82b8820c4df3","outcome":"completed","summary":"Implemented the token, corrected `launch.json`, complete Foundry project, vendored dependencies, and operational documentation.\n\nVerified:\n- `forge build` passes with solc 0.8.26.\n- All 31 tests pass, including real v4 settlement, fuzzing, and 16,384 invariant calls.\n- `forge fmt --check` and local manifest checks pass.\n\nThe manifest uses `SIMDTESTToken` and omits `chainId`. No transactions were broadcast.","treeHash":"c0cb0b1a87beafb2613cb83a42a900b0be6fb51f","usage":{"cachedInputTokens":1470720,"inputTokens":75921,"model":"gpt-6-astra","outputTokens":21521,"runtime":"codex","turns":6,"wallClockMs":571652}},{"artifacts":[],"attempt":1,"bundleHash":"39dd38e677a249ccea4f24983b26e04f3021f202a89616fb8b65cbc64fe9275d","device":"94220c4a6ab72976","findings":[],"hash":"f3a35ab53f7bd345e880ad201f2137efd0900ad50b4ac7e910da175f8be59005","nodeId":"074174cd-25e3-4c28-866d-82b8820c4df3","outcome":"completed","summary":"Implemented `SIMDTESTToken`, the exact launch manifest, vendored dependencies, and deployment documentation.\n\n- `forge build` passed.\n- `forge test`: 26 passed, including local Uniswap v4 integration and 16,384 invariant calls.\n- `forge fmt --check` passed.\n- Clean offline build/tests passed with identical token bytecode.\n\nFull supply goes to the deployer; PoolManager outflows burn 1%, rounded down. No admin or later minting functions exist. Live mainnet validation remains outstanding.","treeHash":"0660463ef7e00c1230c67800a41effca2315a2b6","usage":{"cachedInputTokens":1040640,"inputTokens":78035,"model":"gpt-6-astra","outputTokens":19678,"runtime":"codex","turns":5,"wallClockMs":542144}},{"artifacts":[],"attempt":1,"bundleHash":null,"device":"7f1dec5ffcbde1d8","findings":[{"citation":"resolved","description":"The only economic mechanism of the token is 'exactly 1% of every buy is burned'. The code implements it as 'burn 1% of any ERC-20 transfer whose `from` is the PoolManager'. In Uniswap v4 a swap output does not have to leave the PoolManager as an ERC-20: the unlock caller may call PoolManager.mint(to, currency.toId(), amount) and receive the output as an ERC-6909 claim, and may pay the input of a later swap with PoolManager.burn(from, id, amount). Neither path calls SIMDTESTToken.transfer, so `from == POOL_MANAGER` never fires and nothing is burned. A trader (or an arbitrage/MEV bot, which is the class of trader that routinely uses claims for exactly this gas reason) can buy and sell SIMDTEST through the launch pool indefinitely with zero burn, while a retail buyer settling with take pays 1%. The burn is therefore not a property of buys but of ERC-20 withdrawals from the PoolManager, and the deflation promised in the brief (items 4 and 6) and README ('every outgoing PoolManager transfer is subject to the burn') is only enforced against the least sophisticated traders. Seam: periphery (v4 flash accounting / ERC-6909 claims) x first principles ('1% of every buy is burned'). No funds are lost and no launch flow is short; the guarantee is simply avoidable. Fixing it inside the token is impossible without a swap hook (afterSwap burn), which is a design decision outside the current 'no hooks, no application contracts' scope; alternatively the brief/README should state that claim-settled trades are untaxed.","line":67,"path":"src/SIMDTESTToken.sol","reproduction":"Local v4 PoolManager at 0x000000000004444c5dc75cB358380D2e3dE08A90, SIMDTEST as currency0 against the IMD pair address, pool fee 3000 / spacing 60, initialized at sqrtPriceX96 125270724187523965593206900, 900,000,000 SIMDTEST seeded single-sided (same fixture as test/UniswapV4.t.sol). Trader holds 10e18 pair tokens. Inside unlock: swap(zeroForOne=false, amountSpecified=-1e18) then settle the pair input with sync/transfer/settle and the SIMDTEST output with PoolManager.mint(trader, Currency.toId(SIMDTEST), delta.amount0()). Observed: delta.amount0() = 396293513287896371012766 (~396,293 SIMDTEST), PoolManager.balanceOf(trader, id) = 396293513287896371012766, SIMDTEST.totalSupply() unchanged at 1e27, SIMDTEST.balanceOf(PoolManager) unchanged. Then swap(zeroForOne=true, -396293513287896371012766) paying with PoolManager.burn(trader, id, amount): totalSupply still 1e27. Expected per the brief: a buy of 396293513287896371012766 units burns 3962935132878963710127 (1%). Control: the identical swap settled with PoolManager.take burns exactly 3962935132878963710127 and the trader receives 392330578155017407302639. Test source (uses the project's test/support/TestBase.sol, run with `forge test --match-path test/scratch/EconomicSeams.t.sol -vv`, test_buyViaClaimsNeverBurns vs test_buyViaTakeBurns):\n\n// SPDX-License-Identifier: MIT\npragma solidity 0.8.26;\n\nimport {TestBase} from \"../support/TestBase.sol\";\nimport {SIMDTESTToken} from \"../../src/SIMDTESTToken.sol\";\nimport {PoolManager} from \"v4-core/src/PoolManager.sol\";\nimport {IPoolManager} from \"v4-core/src/interfaces/IPoolManager.sol\";\nimport {IUnlockCallback} from \"v4-core/src/interfaces/callback/IUnlockCallback.sol\";\nimport {IHooks} from \"v4-core/src/interfaces/IHooks.sol\";\nimport {PoolKey} from \"v4-core/src/types/PoolKey.sol\";\nimport {Currency} from \"v4-core/src/types/Currency.sol\";\nimport {BalanceDelta} from \"v4-core/src/types/BalanceDelta.sol\";\nimport {ModifyLiquidityParams, SwapParams} from \"v4-core/src/types/PoolOperation.sol\";\nimport {TickMath} from \"v4-core/src/libraries/TickMath.sol\";\nimport {FullMath} from \"v4-core/src/libraries/FullMath.sol\";\n\ninterface Transferable {\n    function transfer(address to, uint256 amount) external returns (bool);\n}\n\ncontract PairFixture {\n    mapping(address => uint256) public balanceOf;\n    function mint(address to, uint256 amount) external { balanceOf[to] += amount; }\n    function transfer(address to, uint256 amount) external returns (bool) {\n        balanceOf[msg.sender] -= amount; balanceOf[to] += amount; return true;\n    }\n}\n\n/// @dev Unlock caller that can settle the token side either as an ERC-20 `take` or as ERC-6909 claims.\ncontract Actor is IUnlockCallback {\n    IPoolManager private immutable manager;\n    PoolKey private key;\n    enum Mode { ModifyLiquidity, SwapTake, SwapClaims }\n\n    constructor(IPoolManager m, PoolKey memory k) { manager = m; key = k; }\n\n    function modify(int24 lower, int24 upper, int256 liquidityDelta) external returns (BalanceDelta) {\n        bytes memory p = abi.encode(ModifyLiquidityParams(lower, upper, liquidityDelta, bytes32(0)));\n        return abi.decode(manager.unlock(abi.encode(Mode.ModifyLiquidity, p)), (BalanceDelta));\n    }\n\n    function swap(bool zeroForOne, int256 amount, bool claims) external returns (BalanceDelta) {\n        uint160 limit = zeroForOne ? TickMath.MIN_SQRT_PRICE + 1 : TickMath.MAX_SQRT_PRICE - 1;\n        bytes memory p = abi.encode(SwapParams(zeroForOne, amount, limit));\n        return abi.decode(manager.unlock(abi.encode(claims ? Mode.SwapClaims : Mode.SwapTake, p)), (BalanceDelta));\n    }\n\n    function unlockCallback(bytes calldata data) external returns (bytes memory) {\n        require(msg.sender == address(manager));\n        (Mode mode, bytes memory p) = abi.decode(data, (Mode, bytes));\n        BalanceDelta delta;\n        if (mode == Mode.ModifyLiquidity) {\n            (delta,) = manager.modifyLiquidity(key, abi.decode(p, (ModifyLiquidityParams)), \"\");\n        } else {\n            ","severity":"medium","snippet":"        uint256 burned = from == POOL_MANAGER ? amount * BUY_BURN_BPS / BPS_DENOMINATOR : 0;","title":"1% buy burn is bypassed by any v4 swap settled in ERC-6909 claims (mint/burn) instead of take; arbitrage/MEV volume never burns"},{"citation":"resolved","description":"The rule keys on the sender address only, so every PoolManager.take of SIMDTEST is taxed, not just swap outputs. The launch factory's single-sided position is the largest holder of SIMDTEST (900,000,000 of 1,000,000,000). If the factory (or whoever ends up controlling that position) ever removes liquidity, collects accrued SIMDTEST swap fees, or if Uniswap governance collects protocol fees in SIMDTEST, 1% of that outflow is burned and the recipient receives 99%. On a full liquidity withdrawal that is ~9,000,000 SIMDTEST burned from the LP's own capital. This matches the mechanism as the brief defines it ('transfers from the PoolManager') and the README documents it, but it contradicts brief items 5/6 ('the burn fee applies only to buys') and is worth an explicit sign-off from the requester, because the single largest future outflow from the PoolManager is the LP position, not a buy. Seam: execution (take path in modifyLiquidity/collect) x first principles ('only buys are taxed'). No third party loses funds; the LP pays a 1% exit cost that benefits all remaining holders.","line":67,"path":"src/SIMDTESTToken.sol","reproduction":"Same fixture as finding 1. The LP actor that seeded liquidity 899999999999999999999998760 (gross, liquidity L computed from the 900,000,000 allocation) calls PoolManager.modifyLiquidity(key, {lower, upper, -L}) inside unlock and takes its positive SIMDTEST delta. Observed: delta.amount0() = 899999999999999999999998760; LP SIMDTEST balance increases by 890999999999999999999998773 (= gross - gross/100); totalSupply decreases by 8999999999999999999999987. Expected under 'fee applies only to buys': LP receives 899999999999999999999998760 and totalSupply is unchanged. See test_lpWithdrawalIsTaxed in the test source attached to finding 1.","severity":"low","snippet":"        uint256 burned = from == POOL_MANAGER ? amount * BUY_BURN_BPS / BPS_DENOMINATOR : 0;","title":"Non-buy PoolManager outflows (liquidity withdrawal, LP fee collection, protocol fee collection) are burned 1%; the brief says the fee applies only to buys"}],"hash":"fbb3b4bb5bd19bd06c6b6719896e0c973db136e1b88ba0df7aa6fd0854e3e48f","nodeId":"f6f478a0-15d2-4fcb-86f9-f6e96fae94e8","outcome":"completed","summary":"The findings file is in place (excluded from git by the harness's own `.git/info/exclude`, as intended), the scratch directory is removed, and no tracked file changed.\n\n## Review summary — economics (Economic Security, Invariant, Flow Gap)\n\n**Scope covered:** `src/SIMDTESTToken.sol` in full (all three entry points, the constructor, `_transfer`), the launch manifest's economics/price consistency, and the four launch flows (swarm share → distributor → claimant, single-sided seed, buy, sell) traced against the vendored v4 `PoolManager` at the pinned address. The existing 44-test suite and `tools/check_manifest.py` pass. I did not run a mainnet fork (no network), so the real IMD pair token and production router are untested here — same gap the README already declares.\n\n**What holds:** supply conservation (`sum(balanceOf) == totalSupply`), supply monotonically non-increasing, no mint/admin surface, exact inbound settlement to the PM (sells and seeding untaxed, so `settle()` is never short), atomic rollback of a burn on a failed unlock, PM reserve accounting never falling below pool accounting (the burn comes out of the recipient's side, not the PM's), and `initialPrice` ≡ √(2500e18 / 1e27)·2⁹⁶ for SIMDTEST as currency0.\n\n**Findings (2):**\n\n1. **Medium — the 1% buy burn is avoidable via ERC-6909 claims.** A swap whose output is settled with `PoolManager.mint` (and later paid back with `PoolManager.burn`) never calls `SIMDTESTToken.transfer`, so `from == POOL_MANAGER` never fires. Reproduced: ~396,293 SIMDTEST bought and resold with `totalSupply` unchanged at 1e27, versus 3,962.9 burned for the identical swap settled with `take`. Arbitrage/MEV volume — usually the bulk of pool volume — pays nothing; only `take`-settling (retail) buyers pay. No funds lost; the stated guarantee is just not enforceable from inside a hookless token. Fix requires a design decision (an `afterSwap` hook, or documenting the limitation).\n2. **Low — non-buy PM outflows are taxed.** Liquidity withdrawal, LP fee collection and protocol-fee collection all go through `take`, so the factory's 900M-token position pays ~9,000,000 SIMDTEST on a full exit. Consistent with the brief's *mechanism* (\"transfers from the PoolManager\") and documented in the README, but contradicts its *claim* that \"the fee applies only to buys\"; flagged for an explicit requester sign-off.\n\n**Considered and not reported (dust/self-harm):** burn-avoidance by splitting withdrawals into <100-unit transfers; a `take` to the PM itself (the taker must pay the full amount — pure donation); router slippage checks measuring the gross delta rather than net delivery (intended consequence of the requested design, already in the README).\n\nCoverage record has 11 rows: the 3 ABI entry points (approve: holds, transfer: finding 1, transferFrom: holds) plus 8 invariant/flow/economics rows.","treeHash":null,"usage":{"cachedInputTokens":1339827,"inputTokens":36,"model":"claude-fable-5-1","outputTokens":26112,"runtime":"claude","turns":19,"wallClockMs":386792}}],"verification":[{"checks":[{"durationMs":1068,"exitCode":0,"name":"build","output":"Compiling 52 files with Solc 0.8.26\nSolc 0.8.26 finished in 1.00s\nCompiler run successful!\n","passed":true},{"durationMs":6297,"exitCode":0,"name":"test","output":"No files changed, compilation skipped\n\nRan 7 tests for test/TokenAdversarial.t.sol:TokenAdversarialTest\n[PASS] testFuzz_ArbitraryWalletsTransferWithoutFees(address,address,uint256) (runs: 1000, μ: 132973, ~: 133984)\n[PASS] testFuzz_DelegatedSelfTransferSpendsGrossAllowance(uint256,bool,bool) (runs: 1000, μ: 167295, ~: 164837)\n[PASS] testFuzz_DelegatedZeroTransferCannotSpendOrBurn(uint256,bool) (runs: 1000, μ: 165839, ~: 166107)\n[PASS] testFuzz_FailedDelegatedBuyPreservesEveryBalanceAndAllowance(uint256,bool) (runs: 1000, μ: 186419, ~: 186403)\n[PASS] test_AdminSelectorsRejectWellFormedArgumentsFromEveryLaunchRole() (gas: 5605842)\n[PASS] test_ExhaustedBuyAllowanceCannotBeReplayedAndOtherSpenderIsUnaffected() (gas: 459086)\n[PASS] test_OnlyExactManagerAddressIsTaxedAndRecipientsHaveNoExemptions() (gas: 571285)\nSuite result: ok. 7 passed; 0 failed; 0 skipped; finished in 88.44ms (298.92ms CPU time)\n\nRan 26 tests for test/SIMDTESTToken.t.sol:SIMDTESTTokenTest\n[PASS] testFuzz_BuyConservesGrossAmountAndBurn(uint256,bool) (runs: 1000, μ: 182939, ~: 160504)\n[PASS] testFuzz_WalletAndSellPreserveFullSupply(uint256,bool) (runs: 1000, μ: 125415, ~: 126128)\n[PASS] test_ApproveOverwriteAndRevoke() (gas: 147941)\n[PASS] test_BurnRoundingAndZeroTransfers() (gas: 572494)\n[PASS] test_BuyBurnsOnePercentAndEmitsSeparateBurnAndDelivery() (gas: 145424)\n[PASS] test_BuyCannotUseOnlyNetAllowance() (gas: 160222)\n[PASS] test_BuyHasNoDeployerExemption() (gas: 108109)\n[PASS] test_ContractDeployerReceivesEverythingRatherThanTransactionOrigin() (gas: 192922)\n[PASS] test_FactoryDistributionAndSwarmClaimAreUntaxed() (gas: 196370)\n[PASS] test_FailedBuyRollsBackAllowanceAndBurn() (gas: 165674)\n[PASS] test_InitialSupplyAndConstants() (gas: 68711)\n[PASS] test_InsufficientBalanceAndMaxAmountRevert() (gas: 112354)\n[PASS] test_ManagerAsSpenderDoesNotTaxWalletSource() (gas: 166546)\n[PASS] test_NoAdminMintOrPrivilegedBalanceFunctions() (gas: 1199644)\n[PASS] test_PoolManagerSelfTransferStillBurns() (gas: 107983)\n[PASS] test_RuntimeHasNoForbiddenOpcodes() (gas: 440757)\n[PASS] test_TransferFromBuyConsumesGrossAllowance() (gas: 189066)\n[PASS] test_TransferFromWalletAndSellAreUntaxed() (gas: 258912)\n[PASS] test_UnauthorizedTransferFromCannotMoveHolderBalance() (gas: 89902)\n[PASS] test_UnlimitedAllowanceRemainsUnlimited() (gas: 176005)\n[PASS] test_WalletSelfTransferDoesNotChangeBalanceOrSupply() (gas: 98292)\n[PASS] test_WalletTransfersAndSellsHaveNoFee() (gas: 186144)\n[PASS] test_ZeroReceiverRevertsWithoutBurnOrAllowanceLoss() (gas: 185659)\n[PASS] test_ZeroSourceCannotTransferEvenZero() (gas: 33512)\n[PASS] test_ZeroSpenderReverts() (gas: 30306)\n[PASS] test_ZeroTransferFromUnfundedWalletEmitsEvent() (gas: 42726)\nSuite result: ok. 26 passed; 0 failed; 0 skipped; finished in 88.50ms (172.00ms CPU time)\n\nRan 9 tests for test/UniswapV4.t.sol:UniswapV4Test\n[PASS] testFuzz_ExactOutputBuyThenSellSettlesInEitherCurrencyOrder(uint256,bool) (runs: 1000, μ: 3058602, ~: 3063476)\n[PASS] test_ExactOutputSellHasNoBurnWithTokenAsCurrency0() (gas: 3046070)\n[PASS] test_ExactOutputSellHasNoBurnWithTokenAsCurrency1() (gas: 3051832)\n[PASS] test_SeedBuyAndSellWithTokenAsCurrency0() (gas: 3068949)\n[PASS] test_SeedBuyAndSellWithTokenAsCurrency1() (gas: 3073499)\n[PASS] test_UnderpaidBuyRollsBackAndNextUnlockSucceedsWithTokenAsCurrency0() (gas: 3340136)\n[PASS] test_UnderpaidBuyRollsBackAndNextUnlockSucceedsWithTokenAsCurrency1() (gas: 3345669)\n[PASS] test_UnsettledBuyRevertsAndRollsBackBurn() (gas: 2908087)\n[PASS] test_UnsettledSellRevertsAndPreservesBalances() (gas: 3052390)\nSuite result: ok. 9 passed; 0 failed; 0 skipped; finished in 88.52ms (96.51ms CPU time)\n\nRan 1 test for test/SupplyInvariant.t.sol:SupplyInvariantTest\n[PASS] invariant_SupplyIsConservedAndNeverReminted() (runs: 256, calls: 16384, reverts: 0)\n\n╭---------------+-------------------+-------+---------+----------╮\n| Contract      | Selector          | Calls | Reverts | Discards |\n+================================================================+\n| SupplyHandler | move              | 8219  | 0       | 0        |\n|---------------+-------------------+-------+---------+----------|\n| SupplyHandler | rejectedOverspend | 8165  | 0       | 0        |\n╰---------------+-------------------+-------+---------+----------╯\n\nSuite result: ok. 1 passed; 0 failed; 0 skipped; finished in 1.02s (1.01s CPU time)\n\nRan 1 test for test/AllowanceInvariant.t.sol:AllowanceInvariantTest\n[PASS] invariant_EveryBalanceAndAllowanceMatchesIndependentHistory() (runs: 256, calls: 24576, reverts: 0)\n\n╭------------------+--------------------+-------+---------+----------╮\n| Contract         | Selector           | Calls | Reverts | Discards |\n+====================================================================+\n| AllowanceHandler | approve            | 6111  | 0       | 0        |\n|------------------+--------------------+-------+---------+----------|\n| AllowanceHandler | rejectZeroReceiver | 6108  | 0       | 0        |\n|------------------+--------------------+-------+---------+----------|\n| AllowanceHandler | transfer           | 6170  | 0       | 0        |\n|------------------+--------------------+-------+---------+----------|\n| AllowanceHandler | transferFrom       | 6187  | 0       | 0        |\n╰------------------+--------------------+-------+---------+----------╯\n\nSuite result: ok. 1 passed; 0 failed; 0 skipped; finished in 6.24s (6.24s CPU time)\n\nRan 5 test suites in 6.25s (7.53s CPU time): 44 tests passed, 0 failed, 0 skipped (44 total tests)\n","passed":true},{"durationMs":28,"exitCode":0,"name":"source-index","output":"{\"v\":1,\"entryPoints\":[\"SIMDTESTToken.approve(address,uint256)\",\"SIMDTESTToken.transfer(address,uint256)\",\"SIMDTESTToken.transferFrom(address,address,uint256)\"],\"files\":{\".gitignore\":3,\"DEPENDENCIES.md\":16,\"README.md\":120,\"foundry.toml\":11,\"launch.json\":24,\"remappings.txt\":2,\"src/SIMDTESTToken.sol\":77,\"test/AllowanceInvariant.t.sol\":157,\"test/COVERAGE.md\":32,\"test/SIMDTESTToken.t.sol\":353,\"test/SupplyInvariant.t.sol\":87,\"test/TokenAdversarial.t.sol\":201,\"test/UniswapV4.t.sol\":293,\"test/support/TestBase.sol\":32,\"tools/check_manifest.py\":64},\"excluded\":[\"lib/\",\"node_modules/\"],\"truncated\":false}","passed":true}],"detail":"all checks passed","evaluation":"checks","profile":"foundry","status":"accepted","submissionHash":"85e81e240a699fe3b37c05c6879c2a0bdf9c5537f678b94b5ee8a1aa5929ae95","verifiedTreeHash":"8ae4d54b441325f446387d0ed8f1e1483d31b54f","verifierVersion":"0.1.0+ad90ce4c"},{"checks":[{"durationMs":1041,"exitCode":0,"name":"build","output":"Compiling 52 files with Solc 0.8.26\nSolc 0.8.26 finished in 976.69ms\nCompiler run successful!\n","passed":true},{"durationMs":6204,"exitCode":0,"name":"test","output":"No files changed, compilation skipped\n\nRan 7 tests for test/TokenAdversarial.t.sol:TokenAdversarialTest\n[PASS] testFuzz_ArbitraryWalletsTransferWithoutFees(address,address,uint256) (runs: 1000, μ: 132922, ~: 133968)\n[PASS] testFuzz_DelegatedSelfTransferSpendsGrossAllowance(uint256,bool,bool) (runs: 1000, μ: 167260, ~: 164837)\n[PASS] testFuzz_DelegatedZeroTransferCannotSpendOrBurn(uint256,bool) (runs: 1000, μ: 165834, ~: 166095)\n[PASS] testFuzz_FailedDelegatedBuyPreservesEveryBalanceAndAllowance(uint256,bool) (runs: 1000, μ: 186348, ~: 183930)\n[PASS] test_AdminSelectorsRejectWellFormedArgumentsFromEveryLaunchRole() (gas: 5605842)\n[PASS] test_ExhaustedBuyAllowanceCannotBeReplayedAndOtherSpenderIsUnaffected() (gas: 459086)\n[PASS] test_OnlyExactManagerAddressIsTaxedAndRecipientsHaveNoExemptions() (gas: 571285)\nSuite result: ok. 7 passed; 0 failed; 0 skipped; finished in 79.97ms (282.29ms CPU time)\n\nRan 26 tests for test/SIMDTESTToken.t.sol:SIMDTESTTokenTest\n[PASS] testFuzz_BuyConservesGrossAmountAndBurn(uint256,bool) (runs: 1000, μ: 182183, ~: 156276)\n[PASS] testFuzz_WalletAndSellPreserveFullSupply(uint256,bool) (runs: 1000, μ: 125419, ~: 126086)\n[PASS] test_ApproveOverwriteAndRevoke() (gas: 147941)\n[PASS] test_BurnRoundingAndZeroTransfers() (gas: 572494)\n[PASS] test_BuyBurnsOnePercentAndEmitsSeparateBurnAndDelivery() (gas: 145424)\n[PASS] test_BuyCannotUseOnlyNetAllowance() (gas: 160222)\n[PASS] test_BuyHasNoDeployerExemption() (gas: 108109)\n[PASS] test_ContractDeployerReceivesEverythingRatherThanTransactionOrigin() (gas: 192922)\n[PASS] test_FactoryDistributionAndSwarmClaimAreUntaxed() (gas: 196370)\n[PASS] test_FailedBuyRollsBackAllowanceAndBurn() (gas: 165674)\n[PASS] test_InitialSupplyAndConstants() (gas: 68711)\n[PASS] test_InsufficientBalanceAndMaxAmountRevert() (gas: 112354)\n[PASS] test_ManagerAsSpenderDoesNotTaxWalletSource() (gas: 166546)\n[PASS] test_NoAdminMintOrPrivilegedBalanceFunctions() (gas: 1199644)\n[PASS] test_PoolManagerSelfTransferStillBurns() (gas: 107983)\n[PASS] test_RuntimeHasNoForbiddenOpcodes() (gas: 440757)\n[PASS] test_TransferFromBuyConsumesGrossAllowance() (gas: 189066)\n[PASS] test_TransferFromWalletAndSellAreUntaxed() (gas: 258912)\n[PASS] test_UnauthorizedTransferFromCannotMoveHolderBalance() (gas: 89902)\n[PASS] test_UnlimitedAllowanceRemainsUnlimited() (gas: 176005)\n[PASS] test_WalletSelfTransferDoesNotChangeBalanceOrSupply() (gas: 98292)\n[PASS] test_WalletTransfersAndSellsHaveNoFee() (gas: 186144)\n[PASS] test_ZeroReceiverRevertsWithoutBurnOrAllowanceLoss() (gas: 185659)\n[PASS] test_ZeroSourceCannotTransferEvenZero() (gas: 33512)\n[PASS] test_ZeroSpenderReverts() (gas: 30306)\n[PASS] test_ZeroTransferFromUnfundedWalletEmitsEvent() (gas: 42726)\nSuite result: ok. 26 passed; 0 failed; 0 skipped; finished in 82.11ms (167.70ms CPU time)\n\nRan 9 tests for test/UniswapV4.t.sol:UniswapV4Test\n[PASS] testFuzz_ExactOutputBuyThenSellSettlesInEitherCurrencyOrder(uint256,bool) (runs: 1000, μ: 3058287, ~: 3063476)\n[PASS] test_ExactOutputSellHasNoBurnWithTokenAsCurrency0() (gas: 3046070)\n[PASS] test_ExactOutputSellHasNoBurnWithTokenAsCurrency1() (gas: 3051832)\n[PASS] test_SeedBuyAndSellWithTokenAsCurrency0() (gas: 3068949)\n[PASS] test_SeedBuyAndSellWithTokenAsCurrency1() (gas: 3073499)\n[PASS] test_UnderpaidBuyRollsBackAndNextUnlockSucceedsWithTokenAsCurrency0() (gas: 3340136)\n[PASS] test_UnderpaidBuyRollsBackAndNextUnlockSucceedsWithTokenAsCurrency1() (gas: 3345669)\n[PASS] test_UnsettledBuyRevertsAndRollsBackBurn() (gas: 2908087)\n[PASS] test_UnsettledSellRevertsAndPreservesBalances() (gas: 3052390)\nSuite result: ok. 9 passed; 0 failed; 0 skipped; finished in 82.15ms (91.93ms CPU time)\n\nRan 1 test for test/SupplyInvariant.t.sol:SupplyInvariantTest\n[PASS] invariant_SupplyIsConservedAndNeverReminted() (runs: 256, calls: 16384, reverts: 0)\n\n╭---------------+-------------------+-------+---------+----------╮\n| Contract      | Selector          | Calls | Reverts | Discards |\n+================================================================+\n| SupplyHandler | move              | 8210  | 0       | 0        |\n|---------------+-------------------+-------+---------+----------|\n| SupplyHandler | rejectedOverspend | 8174  | 0       | 0        |\n╰---------------+-------------------+-------+---------+----------╯\n\nSuite result: ok. 1 passed; 0 failed; 0 skipped; finished in 1.03s (1.03s CPU time)\n\nRan 1 test for test/AllowanceInvariant.t.sol:AllowanceInvariantTest\n[PASS] invariant_EveryBalanceAndAllowanceMatchesIndependentHistory() (runs: 256, calls: 24576, reverts: 0)\n\n╭------------------+--------------------+-------+---------+----------╮\n| Contract         | Selector           | Calls | Reverts | Discards |\n+====================================================================+\n| AllowanceHandler | approve            | 6228  | 0       | 0        |\n|------------------+--------------------+-------+---------+----------|\n| AllowanceHandler | rejectZeroReceiver | 6049  | 0       | 0        |\n|------------------+--------------------+-------+---------+----------|\n| AllowanceHandler | transfer           | 6026  | 0       | 0        |\n|------------------+--------------------+-------+---------+----------|\n| AllowanceHandler | transferFrom       | 6273  | 0       | 0        |\n╰------------------+--------------------+-------+---------+----------╯\n\nSuite result: ok. 1 passed; 0 failed; 0 skipped; finished in 6.15s (6.15s CPU time)\n\nRan 5 test suites in 6.15s (7.42s CPU time): 44 tests passed, 0 failed, 0 skipped (44 total tests)\n","passed":true},{"durationMs":23,"exitCode":0,"name":"source-index","output":"{\"v\":1,\"entryPoints\":[\"SIMDTESTToken.approve(address,uint256)\",\"SIMDTESTToken.transfer(address,uint256)\",\"SIMDTESTToken.transferFrom(address,address,uint256)\"],\"files\":{\".gitignore\":3,\"DEPENDENCIES.md\":16,\"README.md\":120,\"foundry.toml\":11,\"launch.json\":24,\"remappings.txt\":2,\"src/SIMDTESTToken.sol\":77,\"test/AllowanceInvariant.t.sol\":157,\"test/COVERAGE.md\":32,\"test/SIMDTESTToken.t.sol\":353,\"test/SupplyInvariant.t.sol\":87,\"test/TokenAdversarial.t.sol\":201,\"test/UniswapV4.t.sol\":293,\"test/support/TestBase.sol\":32,\"tools/check_manifest.py\":64},\"excluded\":[\"lib/\",\"node_modules/\"],\"truncated\":false}","passed":true}],"detail":"all checks passed","evaluation":"checks","profile":"foundry","status":"accepted","submissionHash":"aa8b01e1b7a0ff7b81f5aff64da4e6982afe5823c6f077c87769659248c53185","verifiedTreeHash":"855acc19831223d59fa50a3b24e42a6eb33ac4d7","verifierVersion":"0.1.0+ad90ce4c"},{"checks":[{"durationMs":807,"exitCode":0,"name":"build","output":"Compiling 50 files with Solc 0.8.26\nSolc 0.8.26 finished in 745.90ms\nCompiler run successful!\n","passed":true},{"durationMs":1022,"exitCode":0,"name":"test","output":"No files changed, compilation skipped\n\nRan 4 tests for test/UniswapV4.t.sol:UniswapV4Test\n[PASS] test_SeedBuyAndSellWithTokenAsCurrency0() (gas: 3068847)\n[PASS] test_SeedBuyAndSellWithTokenAsCurrency1() (gas: 3073341)\n[PASS] test_UnsettledBuyRevertsAndRollsBackBurn() (gas: 2907996)\n[PASS] test_UnsettledSellRevertsAndPreservesBalances() (gas: 3052299)\nSuite result: ok. 4 passed; 0 failed; 0 skipped; finished in 12.01ms (3.33ms CPU time)\n\nRan 26 tests for test/SIMDTESTToken.t.sol:SIMDTESTTokenTest\n[PASS] testFuzz_BuyConservesGrossAmountAndBurn(uint256,bool) (runs: 1000, μ: 184825, ~: 205356)\n[PASS] testFuzz_WalletAndSellPreserveFullSupply(uint256,bool) (runs: 1000, μ: 125620, ~: 126128)\n[PASS] test_ApproveOverwriteAndRevoke() (gas: 147941)\n[PASS] test_BurnRoundingAndZeroTransfers() (gas: 572494)\n[PASS] test_BuyBurnsOnePercentAndEmitsSeparateBurnAndDelivery() (gas: 145424)\n[PASS] test_BuyCannotUseOnlyNetAllowance() (gas: 160222)\n[PASS] test_BuyHasNoDeployerExemption() (gas: 108109)\n[PASS] test_ContractDeployerReceivesEverythingRatherThanTransactionOrigin() (gas: 192922)\n[PASS] test_FactoryDistributionAndSwarmClaimAreUntaxed() (gas: 196370)\n[PASS] test_FailedBuyRollsBackAllowanceAndBurn() (gas: 165674)\n[PASS] test_InitialSupplyAndConstants() (gas: 68711)\n[PASS] test_InsufficientBalanceAndMaxAmountRevert() (gas: 112354)\n[PASS] test_ManagerAsSpenderDoesNotTaxWalletSource() (gas: 166546)\n[PASS] test_NoAdminMintOrPrivilegedBalanceFunctions() (gas: 1199644)\n[PASS] test_PoolManagerSelfTransferStillBurns() (gas: 107983)\n[PASS] test_RuntimeHasNoForbiddenOpcodes() (gas: 440757)\n[PASS] test_TransferFromBuyConsumesGrossAllowance() (gas: 189066)\n[PASS] test_TransferFromWalletAndSellAreUntaxed() (gas: 258912)\n[PASS] test_UnauthorizedTransferFromCannotMoveHolderBalance() (gas: 89902)\n[PASS] test_UnlimitedAllowanceRemainsUnlimited() (gas: 176005)\n[PASS] test_WalletSelfTransferDoesNotChangeBalanceOrSupply() (gas: 98292)\n[PASS] test_WalletTransfersAndSellsHaveNoFee() (gas: 186144)\n[PASS] test_ZeroReceiverRevertsWithoutBurnOrAllowanceLoss() (gas: 185659)\n[PASS] test_ZeroSourceCannotTransferEvenZero() (gas: 33512)\n[PASS] test_ZeroSpenderReverts() (gas: 30306)\n[PASS] test_ZeroTransferFromUnfundedWalletEmitsEvent() (gas: 42726)\nSuite result: ok. 26 passed; 0 failed; 0 skipped; finished in 15.83ms (35.04ms CPU time)\n\nRan 1 test for test/SupplyInvariant.t.sol:SupplyInvariantTest\n[PASS] invariant_SupplyIsConservedAndNeverReminted() (runs: 256, calls: 16384, reverts: 0)\n\n╭---------------+-------------------+-------+---------+----------╮\n| Contract      | Selector          | Calls | Reverts | Discards |\n+================================================================+\n| SupplyHandler | move              | 8195  | 0       | 0        |\n|---------------+-------------------+-------+---------+----------|\n| SupplyHandler | rejectedOverspend | 8189  | 0       | 0        |\n╰---------------+-------------------+-------+---------+----------╯\n\nSuite result: ok. 1 passed; 0 failed; 0 skipped; finished in 970.88ms (970.15ms CPU time)\n\nRan 3 test suites in 971.94ms (998.71ms CPU time): 31 tests passed, 0 failed, 0 skipped (31 total tests)\n","passed":true},{"durationMs":27,"exitCode":0,"name":"source-index","output":"{\"v\":1,\"entryPoints\":[\"SIMDTESTToken.approve(address,uint256)\",\"SIMDTESTToken.transfer(address,uint256)\",\"SIMDTESTToken.transferFrom(address,address,uint256)\"],\"files\":{\".gitignore\":3,\"DEPENDENCIES.md\":16,\"README.md\":120,\"foundry.toml\":11,\"launch.json\":24,\"remappings.txt\":2,\"src/SIMDTESTToken.sol\":77,\"test/SIMDTESTToken.t.sol\":353,\"test/SupplyInvariant.t.sol\":87,\"test/UniswapV4.t.sol\":212,\"test/support/TestBase.sol\":32,\"tools/check_manifest.py\":64},\"excluded\":[\"lib/\",\"node_modules/\"],\"truncated\":false}","passed":true},{"durationMs":272,"exitCode":0,"name":"slither","output":"slither: no results at low impact or above","passed":true},{"durationMs":175,"exitCode":0,"name":"aderyn","output":"[low] large-numeric-literal at src/SIMDTESTToken.sol:11: Large Numeric Literal (2 places)","passed":true}],"detail":"all checks passed","evaluation":"checks","profile":"foundry","status":"accepted","submissionHash":"c9169557294fc312b03e1842c64399272c9437b2e9eff4885df947d36bd54daf","verifiedTreeHash":"c0cb0b1a87beafb2613cb83a42a900b0be6fb51f","verifierVersion":"0.1.0+ad90ce4c"},{"checks":[{"durationMs":1786,"exitCode":0,"name":"build","output":"Compiling 73 files with Solc 0.8.26\nSolc 0.8.26 finished in 1.65s\nCompiler run successful!\n","passed":true},{"durationMs":1404,"exitCode":0,"name":"test","output":"No files changed, compilation skipped\n\nRan 5 tests for test/UniswapV4.t.sol:UniswapV4Test\n[PASS] test_CallbackRejectsNonManager() (gas: 31945)\n[PASS] test_ExactOutputBuyDeliversNetAfterBurn() (gas: 855930)\n[PASS] test_SeedBuySellWhenTokenIsCurrency0() (gas: 1084724)\n[PASS] test_SeedBuySellWhenTokenIsCurrency1() (gas: 1094076)\n[PASS] test_UnpaidSwapRevertsAndRollsBackBurn() (gas: 1308759)\nSuite result: ok. 5 passed; 0 failed; 0 skipped; finished in 35.45ms (5.74ms CPU time)\n\nRan 20 tests for test/SIMDTESTToken.t.sol:SIMDTESTTokenTest\n[PASS] testFuzz_BuyConservesBalancesAndRoundsDown(uint256) (runs: 1000, μ: 174118, ~: 175238)\nLogs:\n  Bound result 279975911833003761021692444\n\n[PASS] testFuzz_OnlyExactManagerAddressIsTaxed(address,uint256) (runs: 1000, μ: 204648, ~: 205409)\nLogs:\n  Bound result 22066\n\n[PASS] test_ApprovedSellIsUntaxed() (gas: 139396)\n[PASS] test_BuyBurnsOnePercentAndEmitsBothTransfers() (gas: 166568)\n[PASS] test_BuyToDeployerHasNoExemption() (gas: 114263)\n[PASS] test_ConstructorEmitsFullMint() (gas: 5502)\n[PASS] test_DeployerCannotMoveWalletBalanceWithoutApproval() (gas: 145288)\n[PASS] test_DeploymentMintsEntireSupplyOnlyToDeployer() (gas: 249081)\n[PASS] test_FactoryAllocationAndSwarmClaimArriveWhole() (gas: 218598)\n[PASS] test_InfiniteAllowanceIsPreservedOnBuy() (gas: 188672)\n[PASS] test_InsufficientBalanceRollsBackBurnAndAllowance() (gas: 195925)\n[PASS] test_InsufficientGrossAllowanceCannotSpendNetAmount() (gas: 155059)\n[PASS] test_ManagerAsSpenderDoesNotTaxWalletSource() (gas: 126579)\n[PASS] test_MaxAmountRevertsWithoutArithmeticOverflow() (gas: 105549)\n[PASS] test_NoAdminMintBurnOrConfigurationEntryPoints() (gas: 1202615)\n[PASS] test_RuntimeHasNoForbiddenOpcodes() (gas: 866341)\n[PASS] test_SelfTransfersCannotCreateSupply() (gas: 149711)\n[PASS] test_TransferFromBurnDependsOnSourceAndSpendsGrossAllowance() (gas: 208018)\n[PASS] test_ZeroAndDustBuyRounding() (gas: 510691)\n[PASS] test_ZeroRecipientRevertsWithoutBurn() (gas: 100288)\nSuite result: ok. 20 passed; 0 failed; 0 skipped; finished in 35.54ms (61.13ms CPU time)\n\nRan 1 test for test/SIMDTESTInvariant.t.sol:SIMDTESTInvariantTest\n[PASS] invariant_BalancesEqualSupplyAndBurnsExplainEveryDecrease() (runs: 256, calls: 16384, reverts: 0)\n\n╭-----------------+----------+-------+---------+----------╮\n| Contract        | Selector | Calls | Reverts | Discards |\n+=========================================================+\n| TransferHandler | move     | 16384 | 0       | 0        |\n╰-----------------+----------+-------+---------+----------╯\n\nLogs:\n  Bound result 2005\n  Bound result 95794855697644713271442676\n  Bound result 101\n  Bound result 1\n  Bound result 24576\n  Bound result 540\n  Bound result 18\n  Bound result 1\n  Bound result 900000000000000000000\n  Bound result 2452927966\n  Bound result 5608\n  Bound result 3427\n  Bound result 6000\n  Bound result 10000000000000000000\n  Bound result 609560186734005327675\n  Bound result 3197\n  Bound result 4053\n  Bound result 10000000000000000\n  Bound result 613\n  Bound result 3189\n  Bound result 1775\n  Bound result 39183709518114006598\n  Bound result 337\n  Bound result 204580990084183810070\n  Bound result 4367\n  Bound result 1928\n  Bound result 1816\n  Bound result 20831812193074809211\n  Bound result 1000000000000000000\n  Bound result 192\n  Bound result 199\n  Bound result 4547\n  Bound result 117300738\n  Bound result 516110393436442\n  Bound result 429\n  Bound result 607\n  Bound result 19043059055763934336\n  Bound result 3000\n  Bound result 1509\n  Bound result 1000\n  Bound result 1753183794624063916\n  Bound result 764\n  Bound result 834174235876522127902\n  Bound result 244\n  Bound result 34\n  Bound result 100\n  Bound result 815131176820758192960\n  Bound result 192\n  Bound result 358053470893430839515654878\n  Bound result 407928573766934029503911654\n  Bound result 99\n  Bound result 2\n  Bound result 362533409577372451042488103\n  Bound result 1752814112734208\n  Bound result 1000\n  Bound result 23366688004527170745353388\n  Bound result 10000000000000000\n  Bound result 134172253744969037365964632\n  Bound result 210\n  Bound result 10000000000000000\n  Bound result 6000\n  Bound result 622429498220862459613003638\n  Bound result 0\n  Bound result 101\n  Bound result 164811785497912853034230401\n\nSuite result: ok. 1 passed; 0 failed; 0 skipped; finished in 1.32s (1.31s CPU time)\n\nRan 3 test suites in 1.32s (1.39s CPU time): 26 tests passed, 0 failed, 0 skipped (26 total tests)\n","passed":true},{"durationMs":44,"exitCode":0,"name":"source-index","output":"{\"v\":1,\"entryPoints\":[\"SIMDTESTToken.approve(address,uint256)\",\"SIMDTESTToken.transfer(address,uint256)\",\"SIMDTESTToken.transferFrom(address,address,uint256)\"],\"files\":{\".gitignore\":4,\"README.md\":138,\"foundry.toml\":14,\"launch.json\":25,\"remappings.txt\":4,\"src/SIMDTESTToken.sol\":33,\"test/SIMDTESTInvariant.t.sol\":74,\"test/SIMDTESTToken.t.sol\":296,\"test/UniswapV4.t.sol\":252},\"excluded\":[\"lib/\",\"node_modules/\"],\"truncated\":false}","passed":true},{"durationMs":472,"exitCode":0,"name":"slither","output":"slither: no results at low impact or above","passed":true},{"durationMs":222,"exitCode":0,"name":"aderyn","output":"[low] large-numeric-literal at src/SIMDTESTToken.sol:10: Large Numeric Literal (2 places)","passed":true}],"detail":"launch.json is not a valid launch manifest: token.contract: expected a contract name fitting bytes32; (root): Unrecognized key: \"chainId\"","evaluation":"checks","profile":"foundry","status":"rejected","submissionHash":"f3a35ab53f7bd345e880ad201f2137efd0900ad50b4ac7e910da175f8be59005","verifiedTreeHash":"0660463ef7e00c1230c67800a41effca2315a2b6","verifierVersion":"0.1.0+ad90ce4c"}]}