{"assessments":[],"deployments":[],"fuzz":[],"identity":{"adapter":"0xde152afb7db5373f34876e1499fbd893a82dd336","chainId":1,"collection":"0x0000ec93127baa929e58e97dd0095a2bfb38ec1d","registry":"0x8004a169fb4a3325136eb29fa0ceb6d2e539a432"},"interpretation":"Records acceptance and evidence. Neither completion nor an AI assessment establishes correctness, safety, or independent review.","jobId":"63f1158b-144f-4329-9db5-38dae40c63c9","kind":"shape:chain","nodes":[{"acceptedSubmissionHash":"9650fdfd6a6501426d818f691f814552ffda19f82c91c9e167cc77f054514700","dependsOn":["build_contract_project","write_foundry_tests","manifest"],"execution":{"network":false,"profile":"foundry","requires":[],"skillHash":"52c77656f96edcc87204d8dca8e43a8fcfdede031263d415e04ee0709f0c338b","skillId":"audit-specialist","tools":[]},"key":"audit_economics","kind":"code","role":"review","skillHash":"52c77656f96edcc87204d8dca8e43a8fcfdede031263d415e04ee0709f0c338b","skillId":"audit-specialist","state":"accepted"},{"acceptedSubmissionHash":"9ec8e31fe0ea4e4a54f691d6c138b1240331cfbd9b3f0325697699ef505c3f7d","dependsOn":["build_contract_project","write_foundry_tests","manifest"],"execution":{"network":false,"profile":"foundry","requires":[],"skillHash":"52c77656f96edcc87204d8dca8e43a8fcfdede031263d415e04ee0709f0c338b","skillId":"audit-specialist","tools":[]},"key":"audit_flow","kind":"code","role":"review","skillHash":"52c77656f96edcc87204d8dca8e43a8fcfdede031263d415e04ee0709f0c338b","skillId":"audit-specialist","state":"accepted"},{"acceptedSubmissionHash":"2e95f493d2368e97e8cee1f2f4eea246ed77fbebe991c2dea70c8f423f435570","dependsOn":["build_contract_project","write_foundry_tests","manifest","audit_math","audit_permissions","audit_economics","audit_flow"],"execution":{"network":false,"profile":"foundry","requires":[],"skillHash":"647c9348a215ef5349cba3f6861c71bafaa0abf3723adf02f141ad0770ffced7","skillId":"audit-judge","tools":[]},"key":"audit_judge","kind":"code","role":"review","skillHash":"647c9348a215ef5349cba3f6861c71bafaa0abf3723adf02f141ad0770ffced7","skillId":"audit-judge","state":"accepted"},{"acceptedSubmissionHash":"f34579a7e29d379b2716b77d64b6d443b33b0f493f735da647bca9019b7da02c","dependsOn":["build_contract_project","write_foundry_tests","manifest"],"execution":{"network":false,"profile":"foundry","requires":[],"skillHash":"52c77656f96edcc87204d8dca8e43a8fcfdede031263d415e04ee0709f0c338b","skillId":"audit-specialist","tools":[]},"key":"audit_math","kind":"code","role":"review","skillHash":"52c77656f96edcc87204d8dca8e43a8fcfdede031263d415e04ee0709f0c338b","skillId":"audit-specialist","state":"accepted"},{"acceptedSubmissionHash":"75df20189207da0abf0587da8efe570144b49f4fdfac49d3df81388e2c0b4899","dependsOn":["build_contract_project","write_foundry_tests","manifest"],"execution":{"network":false,"profile":"foundry","requires":[],"skillHash":"52c77656f96edcc87204d8dca8e43a8fcfdede031263d415e04ee0709f0c338b","skillId":"audit-specialist","tools":[]},"key":"audit_permissions","kind":"code","role":"review","skillHash":"52c77656f96edcc87204d8dca8e43a8fcfdede031263d415e04ee0709f0c338b","skillId":"audit-specialist","state":"accepted"},{"acceptedSubmissionHash":"afea32308cbdccce581e76bbed8ead0b5e34bb6fd18c032e938c92e13d7d96a8","dependsOn":[],"execution":{"mustProduce":["src/LaunchToken.sol"],"network":false,"profile":"foundry","requires":[],"skillHash":"47381b166d1f406a34f0ebdc740ee21bc0383e56e7ad9084b26abf1bf7570904","skillId":"build-contract-project","tools":[]},"key":"build_contract_project","kind":"code","role":"implement","skillHash":"47381b166d1f406a34f0ebdc740ee21bc0383e56e7ad9084b26abf1bf7570904","skillId":"build-contract-project","state":"accepted"},{"acceptedSubmissionHash":"84070c9e6c785197e02aa18100004d19c79ad8599c62b320b6354763762c2c2c","dependsOn":["build_contract_project","write_foundry_tests"],"execution":{"network":false,"profile":"foundry","requires":[],"tools":[]},"key":"manifest","kind":"code","role":"integrate","skillHash":null,"skillId":null,"state":"accepted"},{"acceptedSubmissionHash":"7bb441e68e8cf4faff3a45a296dc0a9e2a12016652a7cba346805bcd24dcee6a","dependsOn":["build_contract_project"],"execution":{"network":false,"profile":"foundry","requires":[],"skillHash":"34855370ca090d6b3d67ca9be2b888d13d0f9f81b742b9f9f7eca5cad54281ba","skillId":"write-foundry-tests","tools":[]},"key":"write_foundry_tests","kind":"code","role":"tests","skillHash":"34855370ca090d6b3d67ca9be2b888d13d0f9f81b742b9f9f7eca5cad54281ba","skillId":"write-foundry-tests","state":"accepted"}],"objective":"Original request:\n\nBuild a fixed-supply launch token and a StakeVault, have them independently tested and audited, publish the source on GitHub and deploy them on Sepolia through the launch pipeline.\n\nPrior decisions:\n\nThis is a test launch of the new contract-review pipeline (tests step, audit panel, Slither/Aderyn, proofs). The standard policy split applies, including the swarm's ten percent. GitHub publication and Sepolia deployment are authorized.\n\nExisting implementation objective:\n\nBuild and independently review a fixed-supply launch token and a StakeVault: users stake the token and withdraw after a lock set in the constructor (7 days); stakers earn rewards from a pool the owner funds, pro rata by stake over time; the owner can fund rewards and pause new deposits but can never move staked funds. Constructor takes $token, $owner and the lock in seconds. Follow evm-project-launch guidance and test staking, rewards, lock, pause and owner limits. Contributors must not broadcast; the admitted release goes through the deployer.","parentJobId":null,"planHash":"334212233c0419fba8f1ff542fcdd1c7c259397226303bddf154187feea2ff2a","previousHash":"0000000000000000000000000000000000000000000000000000000000000000","projectId":"63f1158b-144f-4329-9db5-38dae40c63c9","publication":{"commit":null,"deliveredAt":null,"repoUrl":"https://github.com/identity-md-launches/launch-429-original-request-build-fixed-supply"},"receiptIdentity":{"adapter":"0xde152afb7db5373f34876e1499fbd893a82dd336","chainId":1,"collection":"0x0000ec93127baa929e58e97dd0095a2bfb38ec1d","registry":"0x8004a169fb4a3325136eb29fa0ceb6d2e539a432"},"registry":"0xb6d0a187b050fa5bb0b87033a203f37becf4a775","research":[],"schema":"identitymd-work-v1","signals":[{"agentId":"50956","feedbackHash":"c54816a229680e8f421c0cf138fd38e54b50cf4bdf61ef3ba8b108d001a9a440","nodeKey":"audit_economics","submissionHash":"9650fdfd6a6501426d818f691f814552ffda19f82c91c9e167cc77f054514700","tag1":"review:submission","tag2":"acceptance-v2","value":1},{"agentId":"51046","feedbackHash":"ebf306bf614d6fe21f1feac6971c17d598b29b091761a8091041deff5f487996","nodeKey":"audit_flow","submissionHash":"9ec8e31fe0ea4e4a54f691d6c138b1240331cfbd9b3f0325697699ef505c3f7d","tag1":"review:submission","tag2":"acceptance-v2","value":1},{"agentId":"51300","feedbackHash":"06e8699015c2454216dd10c04071e81706baa371fc7b50032a4632c9c1776355","nodeKey":"audit_judge","submissionHash":"2e95f493d2368e97e8cee1f2f4eea246ed77fbebe991c2dea70c8f423f435570","tag1":"review:submission","tag2":"acceptance-v2","value":1},{"agentId":"50975","feedbackHash":"3328927641edd0bcafb70e1dc2a5b95c958d80fd4df9973059d4a91752b5b022","nodeKey":"audit_math","submissionHash":"f34579a7e29d379b2716b77d64b6d443b33b0f493f735da647bca9019b7da02c","tag1":"review:submission","tag2":"acceptance-v2","value":1},{"agentId":"50959","feedbackHash":"4242db5743edcc694877b8077b9e6359c37321df9c62da899dfec3d2e3ef6966","nodeKey":"audit_permissions","submissionHash":"75df20189207da0abf0587da8efe570144b49f4fdfac49d3df81388e2c0b4899","tag1":"review:submission","tag2":"acceptance-v2","value":1},{"agentId":"50971","feedbackHash":"a8403746c9a31c437c84e5392630bb9b26b9708db4a3978cfb5c00c4fe1b85dd","nodeKey":"build_contract_project","submissionHash":"afea32308cbdccce581e76bbed8ead0b5e34bb6fd18c032e938c92e13d7d96a8","tag1":"verification:checks","tag2":"acceptance-v2","value":1},{"agentId":"50971","feedbackHash":"be2dd16765b4095db0586b9b35e44de19a04372a662193978d1d6a3d5184d567","nodeKey":"manifest","submissionHash":"84070c9e6c785197e02aa18100004d19c79ad8599c62b320b6354763762c2c2c","tag1":"verification:checks","tag2":"acceptance-v2","value":1},{"agentId":"50971","feedbackHash":"c4c268d8db7e5c27c89bf2e0037247fbfd91260720321a2bf783163a3da2fcf1","nodeKey":"write_foundry_tests","submissionHash":"7bb441e68e8cf4faff3a45a296dc0a9e2a12016652a7cba346805bcd24dcee6a","tag1":"verification:checks","tag2":"acceptance-v2","value":1}],"site":null,"snapshotHash":"5f47b4e5a88b47b1ddc37d7887449e26e26974e6fdc046c6b8dd4bf0fc8d434c","state":"completed","submissions":[{"artifacts":[],"attempt":1,"bundleHash":null,"device":"05778e691c371384","findings":[],"hash":"2e95f493d2368e97e8cee1f2f4eea246ed77fbebe991c2dea70c8f423f435570","nodeId":"2b57cfa9-fee4-43ab-8f70-da62ec6b9d8b","outcome":"completed","summary":"Wrote [ .imd-findings.json ](/root/.identitymd/work/63f1158b-144f-4329-9db5-38dae40c63c9/2b57cfa9-fee4-43ab-8f70-da62ec6b9d8b/.imd-findings.json) containing `{\"findings\":[]}`.\n\nNo substantiated defects remained. Specialist observations were documented trust assumptions or coverage records.\n\nValidation passed: 64 project tests and 8 protected checks using local deployment fixtures. Project source and configuration remain unchanged.","treeHash":null,"usage":{"cachedInputTokens":819328,"inputTokens":103991,"model":"gpt-6-astra","outputTokens":6945,"runtime":"codex","turns":5,"wallClockMs":244518}},{"artifacts":[],"attempt":1,"bundleHash":null,"device":"468e82a89b9bfe18","findings":[{"description":"fundRewards() (onlyOwner) re-spreads `remaining = periodReward - _releasedAt(now)` plus the new amount over a fresh 7-day window (lines 115-120) regardless of how small `amount` is. This is the standard Synthetix-style restart and matches the design (\"pro rata by stake over time\"); already-checkpointed rewards are never reduced, principal is untouched, and SECURITY.md line 64 discloses it. It is reported as a privileged-power trust assumption, not a defect: no unprivileged amplifier exists (a front-runner of the top-up is locked for the full 7-day stream and only earns pro rata, verified). Seam: access x asymmetry. Actor: owner only. Impact is bounded to the timing/sharing of not-yet-vested rewards. No code change is required; the README/UI disclosure already present should stay.","line":116,"path":"src/StakeVault.sol","reproduction":"t0: Alice stake(100e18); owner fundRewards(700e18) -> periodFinish = t0+7d. t0+6d: earned(Alice) == 600e18. Owner fundRewards(1): periodReward becomes 100e18+1, periodFinish becomes t0+13d (6 days later than before). At t0+7d earned(Alice) == 614285714285714285714 instead of the 700e18 she was streaming toward. Bob then stake(100e18) at t0+7d; at t0+13d earned(Alice) == 657142857142857142857 and earned(Bob) == 42857142857142857143, i.e. Bob receives ~43e18 of the 100e18 that was in flight to Alice alone. Reserve stays solvent: total paid == 700e18+1 == rewardReserve funded. Verified with a scratch Foundry test under test/scratch (not kept).","severity":"info","title":"Trust assumption: owner can defer unvested rewards and dilute the in-flight stream with a 1-wei top-up"},{"description":"_updateReward() moves rewards that vest while totalStaked == 0 into unallocatedRewards (line 144). They are only rescheduled inside fundRewards() (line 116), which is onlyOwner and requires amount > 0. There is deliberately no rescue path and the owner is immutable. Consequently reward liveness for idle periods depends on the owner remaining active; principal withdrawal and claims of already-credited rewards do not. README and SECURITY.md disclose this. Not a defect against the stated requirements (owner may fund, may never move staked funds); recorded so the judge and operator see the operational dependency. Mitigation is operational: fund only once stakers exist, or accept that an idle-period balance needs a later positive fundRewards() call.","line":144,"path":"src/StakeVault.sol","reproduction":"Fresh vault, no stakers. Owner fundRewards(700e18). Warp +7 days. Alice stake(100e18): unallocatedRewards == 700e18, earned(Alice) == 0, claimRewards() == 0. If the owner never calls fundRewards(>=1) again the 700e18 remain in the contract permanently (no other function reads unallocatedRewards). With owner fundRewards(1) after that, periodReward == 700e18+1 and Alice earns all of it over the next 7 days (matches existing test test_ExpiredIdleRewardsCannotBeSnipedByFirstStaker).","severity":"info","title":"Trust assumption: rewards released while nobody is staked stay idle until the owner funds again; owner-key loss strands them"},{"description":"Entry-point inventory (all state-changing): stake (public, nonReentrant, blocked by depositsPaused), withdraw (public, nonReentrant, lock check on msg.sender only), claimRewards (public, nonReentrant), fundRewards (onlyOwner, nonReentrant, pulls only from msg.sender), setDepositsPaused (onlyOwner, no external call). No receive/fallback (ETH call with value reverts, verified). Constructor sets immutable token/owner/lockDuration; the factory (msg.sender) receives no role; $owner comes from policy per launch.json. Roles: exactly one (owner), non-transferable, no initializer, no proxy/delegatecall/selfdestruct (protected floor and adversarial suite scan the runtime). Every storage variable was checked for multiple writers with differing guards: balanceOf/totalStaked/unlockAt are written only by stake/withdraw for msg.sender; rewardReserve only by fundRewards(+)/claimRewards(-); periodReward/periodStart/periodFinish only by fundRewards; unallocatedRewards by _updateReward(+) and fundRewards(=0). Pairs diffed: stake/withdraw (mirror writes; unlockAt reset on full exit only, partial withdraw keeps lock, verified), earned()/_updateReward (same totalStaked==0 branch), fundRewards vs user paths (fundRewards is not paused-gated by design). Reserve solvency: sum of credited rewards <= released <= funded, so rewardReserve -= amount cannot underflow; checked across empty gaps and restarts. Unprivileged attacks tried and refuted: 512-run fuzz of arbitrary selectors from a non-owner leaves totalStaked/balanceOf/depositsPaused/vault balance unchanged; owner withdraw(1) with no stake reverts InsufficientStake and owner claim returns 0; front-running fundRewards with a stake only earns pro rata and is locked past periodFinish; checkpoint griefing (stake(1) hourly for 7 days against ~1e23 staked) leaves 1 wei of dust. Not reached: nothing in the assigned area was left unexamined; economics, math precision and periphery beyond what touches permissions were left to the other specialists. Slither/Aderyn leads reviewed: incorrect-equality at claimRewards is `amount == 0` early return (benign); the strict balance equality in _receiveExact is the intended exact-receipt check; timestamp comparisons implement the specified lock/vesting; centralization-risk is the two documented owner powers above.","line":68,"path":"src/StakeVault.sol","reproduction":"Not a defect. See scratch results in the description; each claim names the concrete call and observed state.","severity":"info","title":"Coverage record for the Access Control / Trust Gap / Asymmetry area: no permission bypass or asymmetric extraction found"}],"hash":"75df20189207da0abf0587da8efe570144b49f4fdfac49d3df81388e2c0b4899","nodeId":"cb29ea8a-ee65-4ce8-87de-60bce10bf130","outcome":"completed","summary":"The review is complete. No exploitable defect exists in the assigned area, and `.imd-findings.json` records two owner-power trust assumptions plus a coverage note. No source or test files were changed. The scratch tests I used were removed.\n\n**What I checked**\n\n- Every state-changing entry point of the vault and who may call it: stake, withdraw, claimRewards, fundRewards, setDepositsPaused, and the absent receive/fallback.\n- Constructor role handout: token, owner and lock are immutable, the factory receives no privilege, and the manifest passes `$owner` from policy.\n- Storage-write symmetry between stake and withdraw, between the view `earned` and the checkpoint, and between the owner's funding path and user paths.\n- Reserve solvency across empty periods and schedule restarts, since claims subtract from the reserve without a floor check.\n- Unprivileged attacks: a 512-run fuzz of arbitrary selectors from a non-owner, owner attempts to withdraw or claim without a stake, front-running a top-up, and hourly checkpoint griefing.\n\n**Findings written**\n\n- Info: the owner can restart the seven-day stream with a 1-wei top-up, which defers not-yet-vested rewards and lets a newcomer share them. Verified numerically. Documented in SECURITY.md, no unprivileged amplifier, so it stays a trust assumption.\n- Info: rewards vested while nobody is staked stay idle until the owner funds again, so idle-period liveness depends on the owner key.\n- Info: coverage record with the entry-point inventory and the refuted attacks, so the judge sees what was tested.\n\n**Static-analysis leads**\n\nThe strict-equality, timestamp and centralization lines all map to intended behaviour: an early return on a zero claim, the exact-receipt check, the specified lock and vesting clock, and the two documented owner powers.\n\n**Verification status**\n\nThe accepted tree builds offline and all 64 existing tests pass. Formatting is clean on `src/` and `test/`.","treeHash":null,"usage":{"cachedInputTokens":811765,"inputTokens":322,"model":"claude-fable-5-1","outputTokens":23476,"runtime":"claude","turns":24,"wallClockMs":348100}},{"artifacts":[],"attempt":1,"bundleHash":"892cac8627898ce6e28237f57e29255fc040b2334b4e2fc46550f0ee7028d31b","device":"35c52a5b502e847c","findings":[],"hash":"7bb441e68e8cf4faff3a45a296dc0a9e2a12016652a7cba346805bcd24dcee6a","nodeId":"b9801658-abcf-4ced-8e39-58e4cf2f7a1b","outcome":"completed","summary":"Added failure-path, boundary, and reward property tests, plus stronger token and vault invariants. All changes are under `test/`.\n\nOffline verification passed:\n- `forge build`\n- `forge test`: **64 passed, 0 failed**\n- 1,000 runs per new fuzz test; 40,960 invariant calls\n\nNo new contract defect was reproduced.","treeHash":"b5fdba28d8fdf5e1e1e2a5dae2ae1a02029ea8c1","usage":{"cachedInputTokens":1136896,"inputTokens":81635,"model":"gpt-6-astra","outputTokens":15581,"runtime":"codex","turns":6,"wallClockMs":524052}},{"artifacts":[],"attempt":1,"bundleHash":"27841753be0b538135a716d9d6a298ba0eb41d7e312ef6cd827cbd6ccefbf110","device":"35c52a5b502e847c","findings":[],"hash":"84070c9e6c785197e02aa18100004d19c79ad8599c62b320b6354763762c2c2c","nodeId":"fd2a408c-4923-498d-a76c-2fae30be109b","outcome":"completed","summary":"Created [launch.json](/home/identitymd5/.identitymd/work/63f1158b-144f-4329-9db5-38dae40c63c9/fd2a408c-4923-498d-a76c-2fae30be109b/launch.json) with StakeLaunch metadata, `StakeVault($token, $owner, 604800)`, and native-ETH pool settings.\n\nSchema and compiled constructor ABI checks passed. `forge build` succeeded; `forge test` passed all 64 tests. Only `launch.json` changed outside scratch artifacts.","treeHash":"8e32d9f276c5c417d40a9ee911ccd36a0b5e9ad8","usage":{"cachedInputTokens":194944,"inputTokens":32787,"model":"gpt-6-astra","outputTokens":2929,"runtime":"codex","turns":3,"wallClockMs":128728}},{"artifacts":[],"attempt":1,"bundleHash":null,"device":"bb0a3bf63233e5e5","findings":[],"hash":"9650fdfd6a6501426d818f691f814552ffda19f82c91c9e167cc77f054514700","nodeId":"17811a8d-e94d-4df7-bed3-1fe6f6be70ba","outcome":"completed","summary":"Wrote [`.imd-findings.json`](/home/imd-worker/.identitymd/work/63f1158b-144f-4329-9db5-38dae40c63c9/17811a8d-e94d-4df7-bed3-1fe6f6be70ba/.imd-findings.json) with `{\"findings\":[]}`.\n\nReviewed reward allocation, solvency, stake transitions, idle periods, top-ups, rounding, pause/withdrawal flows, and token interactions. No substantiated defects found. All 68 existing Foundry tests and invariant checks passed offline.\n\nProtected checks were inspected; deployment-pipeline execution and formal proofs were not performed. No source or configuration files changed.","treeHash":null,"usage":{"cachedInputTokens":436480,"inputTokens":83597,"model":"gpt-6-astra","outputTokens":4476,"runtime":"codex","turns":4,"wallClockMs":170613}},{"artifacts":[],"attempt":1,"bundleHash":null,"device":"02ae6543274731ab","findings":[],"hash":"9ec8e31fe0ea4e4a54f691d6c138b1240331cfbd9b3f0325697699ef505c3f7d","nodeId":"47c22bac-2fa8-4241-84e5-5e4cedaf5714","outcome":"completed","summary":"Wrote `{\"findings\":[]}` to [.imd-findings.json](/home/imd-worker/.identitymd/work/63f1158b-144f-4329-9db5-38dae40c63c9/47c22bac-2fa8-4241-84e5-5e4cedaf5714/.imd-findings.json).\n\nCompleted Execution Trace, Periphery, and First Principles review. No substantiated defects found. All 64 local tests passed offline. Protected checks were inspected; deployment services were outside scope. No source or configuration files changed.","treeHash":null,"usage":{"cachedInputTokens":606976,"inputTokens":79498,"model":"gpt-6-astra","outputTokens":3957,"runtime":"codex","turns":5,"wallClockMs":215316}},{"artifacts":[],"attempt":1,"bundleHash":"7e4f47ba578ba0e3c7a03204ad148a9d3bd31508a958a74a944148943471ec19","device":"35c52a5b502e847c","findings":[],"hash":"afea32308cbdccce581e76bbed8ead0b5e34bb6fd18c032e938c92e13d7d96a8","nodeId":"3674f060-7ae1-4e68-8586-c88aa4827d03","outcome":"completed","summary":"Implemented LaunchToken and StakeVault with seven-day locking, proportional rewards, deposit pausing, and restricted owner powers.\n\nValidation passed: `forge build`, `forge test` (44 tests), `forge fmt --check`, and a forced offline build. Includes fuzz/invariant tests and a separate local adversarial review.\n\n[README](/home/identitymd5/.identitymd/work/63f1158b-144f-4329-9db5-38dae40c63c9/3674f060-7ae1-4e68-8586-c88aa4827d03/README.md) documents assumptions, tradeoffs, and deployment parameters.\n\nPipeline audits/analyzers/proofs, GitHub publication, and Sepolia deployment remain pending. No transactions were broadcast.","treeHash":"a128592b1b5a6477f9835a05dbe00e7b1f0eb49d","usage":{"cachedInputTokens":491904,"inputTokens":43741,"model":"gpt-6-astra","outputTokens":19860,"runtime":"codex","turns":5,"wallClockMs":666636}},{"artifacts":[],"attempt":1,"bundleHash":null,"device":"377843575071cdb1","findings":[],"hash":"f34579a7e29d379b2716b77d64b6d443b33b0f493f735da647bca9019b7da02c","nodeId":"faada884-a097-4c9f-a83d-d981462d6cce","outcome":"completed","summary":"Wrote `{\"findings\":[]}` to [.imd-findings.json](/home/worker/.identitymd/work/63f1158b-144f-4329-9db5-38dae40c63c9/faada884-a097-4c9f-a83d-d981462d6cce/.imd-findings.json).\n\nReviewed precision, overflow bounds, reward conservation, time boundaries, and external-call behavior. No substantiated defects found.\n\nAll 64 existing Foundry tests passed. Protected deployment checks were reviewed but not executed. Implementation files remain unchanged.","treeHash":null,"usage":{"cachedInputTokens":573568,"inputTokens":91137,"model":"gpt-6-astra","outputTokens":4608,"runtime":"codex","turns":5,"wallClockMs":170055}}],"verification":[{"checks":[{"durationMs":3224,"exitCode":0,"name":"build","output":"Compiling 43 files with Solc 0.8.26\nSolc 0.8.26 finished in 3.06s\nCompiler run successful!\nwarning[reentrancy-events]: event emitted after an external call; reentrancy can reorder or fabricate logs that off-chain consumers rely on\n   ╭▸ src/StakeVault.sol:82:9\n   │\n82 │         emit Staked(msg.sender, amount, unlockAt[msg.sender]);\n   │         ━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━\n   │\n   ╰ help: https://getfoundry.sh/forge/linting/reentrancy-events\n\nwarning[block-timestamp]: usage of `block.timestamp` in a comparison may be manipulated by validators\n   ╭▸ src/StakeVault.sol:89:13\n   │\n89 │         if (block.timestamp < unlockAt[msg.sender]) revert StakeLocked(unlockAt[msg.sender]);\n   │             ━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━\n   │\n   ╰ help: https://getfoundry.sh/forge/linting/block-timestamp\n\nwarning[reentrancy-events]: event emitted after an external call; reentrancy can reorder or fabricate logs that off-chain consumers rely on\n   ╭▸ src/StakeVault.sol:95:9\n   │\n95 │         emit Withdrawn(msg.sender, amount);\n   │         ━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━\n   │\n   ╰ help: https://getfoundry.sh/forge/linting/reentrancy-events\n\nwarning[reentrancy-events]: event emitted after an external call; reentrancy can reorder or fabricate logs that off-chain consumers rely on\n    ╭▸ src/StakeVault.sol:106:9\n    │\n106 │         emit RewardPaid(msg.sender, amount);\n    │         ━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━\n    │\n    ╰ help: https://getfoundry.sh/forge/linting/reentrancy-events\n\nwarning[reentrancy-events]: event emitted after an external call; reentrancy can reorder or fabricate logs that off-chain consumers rely on\n    ╭▸ src/StakeVault.sol:122:9\n    │\n122 │         emit RewardsFunded(amount, periodReward, periodFinish);\n    │         ━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━\n    │\n    ╰ help: https://getfoundry.sh/forge/linting/reentrancy-events\n\nwarning[incorrect-strict-equality]: dangerous strict equality check on an externally-influenced value\n    ╭▸ src/StakeVault.sol:171:13\n    │\n171 │         if (token.balanceOf(address(this)) != beforeBalance + amount) revert UnsupportedToken();\n    │             ━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━\n    │\n    ╰ help: https://getfoundry.sh/forge/linting/incorrect-strict-equality\n\n","passed":true},{"durationMs":6914,"exitCode":0,"name":"test","output":"No files changed, compilation skipped\n\nRan 6 tests for test/LaunchToken.t.sol:LaunchTokenTest\n[PASS] testFuzz_transfersConserveSupply(uint256) (runs: 512, μ: 141615, ~: 141808)\nLogs:\n  Bound result 4028\n\n[PASS] test_allowanceAndTransferFrom() (gas: 235433)\n[PASS] test_fixedSupplyAndMetadata() (gas: 52773)\n[PASS] test_noMintOrAdministrativeEntrypointsEvenForDeployer() (gas: 385152)\n[PASS] test_rejectsZeroRecipientAndInsufficientBalance() (gas: 57316)\n[PASS] test_transferAndZeroTransfer() (gas: 154467)\nSuite result: ok. 6 passed; 0 failed; 0 skipped; finished in 24.18ms (25.17ms CPU time)\n\nRan 17 tests for test/StakeVault.t.sol:StakeVaultTest\n[PASS] testFuzz_twoStakersConserveRewards(uint96,uint96,uint96) (runs: 512, μ: 805106, ~: 812838)\nLogs:\n  Bound result 15561\n  Bound result 8889\n  Bound result 24465\n\n[PASS] test_constructorConfigurationAndValidation() (gas: 36453)\n[PASS] test_directDonationsAreNeitherPrincipalNorScheduledRewards() (gas: 563930)\n[PASS] test_emptyIntervalsAreNotAwardedToNextDepositorAndRecycleOnFunding() (gas: 695455)\n[PASS] test_fundingAfterFullyIdlePeriodRecyclesWholePool() (gas: 524634)\n[PASS] test_invalidAmountsAndUnapprovedDepositAreAtomic() (gas: 332171)\n[PASS] test_lateEntryDoesNotEarnHistoricalRewards() (gas: 689736)\n[PASS] test_oneWeiRewardIsNotLostToIntegerRateRounding() (gas: 491557)\n[PASS] test_onlyOwnerCanPauseOrFundAndOwnerCannotWithdrawUserStake() (gas: 401977)\n[PASS] test_pauseDoesNotStopClaimsWithdrawalsOrFunding() (gas: 863041)\n[PASS] test_rewardsAreProportionalToStake() (gas: 670561)\n[PASS] test_singleStakerEarnsOverTimeCanClaimWhileLockedAndCannotDoubleClaim() (gas: 701791)\n[PASS] test_stakeAndWithdrawExactlyAtLockBoundary() (gas: 426196)\n[PASS] test_stakingBeforeFundingAndAfterFinishDoesNotEarn() (gas: 670032)\n[PASS] test_topUpPreservesEarnedAndReschedulesOnlyUnvested() (gas: 647763)\n[PASS] test_topUpResetsOnlyCallersEntireLock() (gas: 546990)\n[PASS] test_withdrawalPreservesEarnedRewardsAndStopsNewEarnings() (gas: 776328)\nSuite result: ok. 17 passed; 0 failed; 0 skipped; finished in 144.55ms (150.66ms CPU time)\n\nRan 20 tests for test/StakeVaultAdversarial.t.sol:StakeVaultAdversarialTest\n[PASS] testFuzz_StaggeredStakesMatchIndependentTimeShareCalculation(uint96,uint96,uint96,uint32) (runs: 512, μ: 936490, ~: 936492)\nLogs:\n  Bound result 60944919301076186819\n  Bound result 9999000000000000001663\n  Bound result 99900000000000000083622\n  Bound result 10334\n\n[PASS] testFuzz_UnknownSelectorsCannotGiveOwnerPrincipal(uint96) (runs: 512, μ: 305203, ~: 305038)\nLogs:\n  Bound result 325042535589765700431\n\n[PASS] test_Create2FactoryKeepsSupplyAndHasNoImplicitOwnerAuthority() (gas: 2700356)\n[PASS] test_DonationIsNotClaimableByOwnerOrLateStaker() (gas: 387328)\n[PASS] test_ExpiredIdleRewardsCannotBeSnipedByFirstStaker() (gas: 651505)\n[PASS] test_FailedClaimKeepsAccruedRewardAndReserveForRetry() (gas: 1848168)\n[PASS] test_FailedDepositRollsBackRewardCheckpointAndBalances() (gas: 1521852)\n[PASS] test_FailedFundingDoesNotRescheduleOrIncreaseReserve() (gas: 1506267)\n[PASS] test_FailedWithdrawKeepsPrincipalAndUnlockForRetry() (gas: 1569556)\n[PASS] test_IncomingFeeRevertsBothDepositAndFundingWithoutBurningTokens() (gas: 1452471)\n[PASS] test_LastSecondDepositReceivesOnlyLastSecondShare() (gas: 577660)\n[PASS] test_OneWeiFundingIsVestedRatherThanDiscardedByRateDivision() (gas: 477987)\n[PASS] test_RoundingDustCannotConsumePrincipalOrBecomeOwnerWithdrawable() (gas: 539910)\n[PASS] test_SameBlockDepositAndWithdrawCannotEarnRewardsOrBypassLock() (gas: 403678)\n[PASS] test_TopUpPreservesEarnedRewardsButRestartsUnvestedSchedule() (gas: 708507)\n[PASS] test_TransferCallbackCannotReenterRewardClaim() (gas: 1757540)\n[PASS] test_TransferCallbackCannotReenterWithdrawal() (gas: 1570076)\n[PASS] test_TransferFromCallbackCannotReenterDeposit() (gas: 1500856)\n[PASS] test_TransferFromCallbackCannotReenterRewardClaimDuringFunding() (gas: 1471817)\n[PASS] test_ZeroStakeGapRecyclesOnlyRewardsReleasedDuringGap() (gas: 953266)\nSuite result: ok. 20 passed; 0 failed; 0 skipped; finished in 164.65ms (341.23ms CPU time)\n\nRan 13 tests for test/StakeVaultProperties.t.sol:StakeVaultPropertiesTest\n[PASS] testFuzz_claimSplittingPreservesExactlyDivisibleRewards(uint256,uint256) (runs: 1000, μ: 1940965, ~: 1931178)\nLogs:\n  Bound result 3148364957\n  Bound result 3\n\n[PASS] testFuzz_customLockUsesConstructorValue(uint256) (runs: 1000, μ: 612650, ~: 612774)\nLogs:\n  Bound result 18446744073709465215\n\n[PASS] testFuzz_partialWithdrawalChangesOnlyFutureRewardShare(uint256,uint256,uint256,uint256,uint256) (runs: 1000, μ: 1115630, ~: 1125962)\nLogs:\n  Bound result 218825816827427081658337537\n  Bound result 19220904517065060954393470\n  Bound result 1891708837580589491806\n  Bound result 78012234555610666799841548\n  Bound result 196881\n\n[PASS] testFuzz_sameTimestampFundingPartitionsHaveSamePayout(uint256,uint256) (runs: 1000, μ: 636993, ~: 637092)\nLogs:\n  Bound result 40000000000000000000\n  Bound result 4100\n\n[PASS] test_constructorRejectsVaultAsItsOwnOwner() (gas: 6985)\n[PASS] test_entireSupplyCanBeStakedAndWithdrawnWhilePaused() (gas: 392161)\n[PASS] test_failedFundingAndDepositPreserveActiveRewardsAndFiniteAllowances() (gas: 1265769)\n[PASS] test_maximumLockRemainsEnforcedAfterRewardsFinish() (gas: 608647)\n[PASS] test_oneSecondLockDoesNotShortenRewardSchedule() (gas: 656170)\n[PASS] test_oneWeiStakeCanEarnAllRemainingSupply() (gas: 601919)\n[PASS] test_ownerStakesAndEarnsOnSameTermsAsEveryoneElse() (gas: 969615)\n[PASS] test_unstakeAndRestakeCannotAcquireRewardsFromTheGap() (gas: 1116282)\n[PASS] test_zeroAndMaximumInputsCannotAlterAnActivePosition() (gas: 916332)\nSuite result: ok. 13 passed; 0 failed; 0 skipped; finished in 169.26ms (652.74ms CPU time)\n\nRan 7 tests for test/LaunchTokenProperties.t.sol:LaunchTokenPropertiesTest\n[PASS]\nLaunchTokenPropertiesTest invariants:\n[PASS] invariant_allowancesMatchApprovalsAndSuccessfulSpending\n[PASS] invariant_balancesMatchLedgerAndSupplyNeverChanges\n LaunchTokenPropertiesTest invariants (runs: 256, calls: 16384, reverts: 0)\n\n╭-------------------------+--------------+-------+---------+----------╮\n| Contract                | Selector     | Calls | Reverts | Discards |\n+=====================================================================+\n| LaunchTokenModelHandler | approve      | 5518  | 0       | 0        |\n|-------------------------+--------------+-------+---------+----------|\n| LaunchTokenModelHandler | transfer     | 5431  | 0       | 0        |\n|-------------------------+--------------+-------+---------+----------|\n| LaunchTokenModelHandler | transferFrom | 5435  | 0       | 0        |\n╰-------------------------+--------------+-------+---------+----------╯\n\nLogs:\n  Bound result 165016966986853686698196592\n  Bound result 3251\n  Bound result 5489\n  Bound result 1247\n  Bound result 410067863252959672268027723\n  Bound result 1106684914829\n  Bound result 0\n\n[PASS] test_approvalReplacementAndRevocationTakeEffectImmediately() (gas: 232076)\n[PASS] test_cannotApproveZeroSpenderOrTransferFromZeroSender() (gas: 82327)\n[PASS] test_delegatedSelfTransferConsumesAllowanceButPreservesBalance() (gas: 119715)\n[PASS] test_failedTransferFromDoesNotConsumeFiniteAllowance() (gas: 134187)\n[PASS] test_zeroReceiverRevertsEvenForZeroTransferFrom() (gas: 69566)\n[PASS] test_zeroTransferFromNeedsNoAllowanceAndMovesNothing() (gas: 76395)\nSuite result: ok. 7 passed; 0 failed; 0 skipped; finished in 4.98s (4.98s CPU time)\n\nRan 1 test for test/StakeVaultInvariant.t.sol:StakeVaultInvariantTest\n[PASS]\nStakeVaultInvariantTest invariants:\n[PASS] invariant_actorBalancesAndClaimsAreFullyBacked\n[PASS] invariant_allTokensRemainInKnownCustody\n[PASS] invariant_locksAndPauseMatchAuthorizedOperations\n[PASS] invariant_tokenCustodyMatchesPrincipalRewardsAndDonations\n StakeVaultInvariantTest invariants (runs: 256, calls: 24576, reverts: 0)\n\n╭--------------+----------------------+-------+---------+----------╮\n| Contract     | Selector             | Calls | Reverts | Discards |\n+==================================================================+\n| VaultHandler | advanceTime          | 2714  | 0       | 0        |\n|--------------+----------------------+-------+---------+----------|\n| VaultHandler | claim                | 2685  | 0       | 0        |\n|--------------+----------------------+-------+---------+----------|\n| VaultHandler | donate               | 2784  | 0       | 0        |\n|--------------+----------------------+-------+---------+----------|\n| VaultHandler | fund                 | 2632  | 0       | 0        |\n|--------------+----------------------+-------+---------+----------|\n| VaultHandler | pause                | 2810  | 0       | 0        |\n|--------------+----------------------+-------+---------+----------|\n| VaultHandler | rejectInvalidAmounts | 2710  | 0       | 0        |\n|--------------+----------------------+-------+---------+----------|\n| VaultHandler | rejectUnauthorized   | 2767  | 0       | 0        |\n|--------------+----------------------+-------+---------+----------|\n| VaultHandler | stake                | 2655  | 0       | 0        |\n|--------------+----------------------+-------+---------+----------|\n| VaultHandler | withdraw             | 2819  | 0       | 0        |\n╰--------------+----------------------+-------+---------+----------╯\n\nLogs:\n  Bound result 100000000000000000002\n  Bound result 200000000000000000002\n  Bound result 700000000000000000002\n  Bound result 95\n  Bound result 457356\n  Bound result 24000000000000000000\n  Bound result 3227\n  Bound result 18\n  Bound result 2827\n  Bound result 13\n  Bound result 8962\n  Bound result 4\n  Bound result 851200\n  Bound result 1209600\n  Bound result 43200\n  Bound result 386\n  Bound result 1120000\n  Bound result 728751231\n  Bound result 2041\n  Bound result 659918\n  Bound result 7000000000000000000\n  Bound result 100000000000000000000000\n  Bound result 2\n  Bound result 699999999999999918110048\n  Bound result 172228552678156514414933687\n  Bound result 8539\n  Bound result 36321714573354223931331800\n  Bound result 741689\n  Bound result 311535\n  Bound result 12347\n  Bound result 604800\n  Bound result 3318\n  Bound result 7239\n  Bound result 40000000000000000000\n  Bound result 212493958473997113449332774\n  Bound result 2989\n\nSuite result: ok. 1 passed; 0 failed; 0 skipped; finished in 6.79s (6.79s CPU time)\n\nRan 6 test suites in 6.80s (12.28s CPU time): 64 tests passed, 0 failed, 0 skipped (64 total tests)\n","passed":true}],"detail":"all checks passed","evaluation":"checks","profile":"foundry","status":"accepted","submissionHash":"7bb441e68e8cf4faff3a45a296dc0a9e2a12016652a7cba346805bcd24dcee6a","verifiedTreeHash":"b5fdba28d8fdf5e1e1e2a5dae2ae1a02029ea8c1","verifierVersion":"0.1.0+78c54e29"},{"checks":[{"durationMs":2953,"exitCode":0,"name":"build","output":"Compiling 43 files with Solc 0.8.26\nSolc 0.8.26 finished in 2.81s\nCompiler run successful!\nwarning[reentrancy-events]: event emitted after an external call; reentrancy can reorder or fabricate logs that off-chain consumers rely on\n   ╭▸ src/StakeVault.sol:82:9\n   │\n82 │         emit Staked(msg.sender, amount, unlockAt[msg.sender]);\n   │         ━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━\n   │\n   ╰ help: https://getfoundry.sh/forge/linting/reentrancy-events\n\nwarning[block-timestamp]: usage of `block.timestamp` in a comparison may be manipulated by validators\n   ╭▸ src/StakeVault.sol:89:13\n   │\n89 │         if (block.timestamp < unlockAt[msg.sender]) revert StakeLocked(unlockAt[msg.sender]);\n   │             ━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━\n   │\n   ╰ help: https://getfoundry.sh/forge/linting/block-timestamp\n\nwarning[reentrancy-events]: event emitted after an external call; reentrancy can reorder or fabricate logs that off-chain consumers rely on\n   ╭▸ src/StakeVault.sol:95:9\n   │\n95 │         emit Withdrawn(msg.sender, amount);\n   │         ━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━\n   │\n   ╰ help: https://getfoundry.sh/forge/linting/reentrancy-events\n\nwarning[reentrancy-events]: event emitted after an external call; reentrancy can reorder or fabricate logs that off-chain consumers rely on\n    ╭▸ src/StakeVault.sol:106:9\n    │\n106 │         emit RewardPaid(msg.sender, amount);\n    │         ━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━\n    │\n    ╰ help: https://getfoundry.sh/forge/linting/reentrancy-events\n\nwarning[reentrancy-events]: event emitted after an external call; reentrancy can reorder or fabricate logs that off-chain consumers rely on\n    ╭▸ src/StakeVault.sol:122:9\n    │\n122 │         emit RewardsFunded(amount, periodReward, periodFinish);\n    │         ━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━\n    │\n    ╰ help: https://getfoundry.sh/forge/linting/reentrancy-events\n\nwarning[incorrect-strict-equality]: dangerous strict equality check on an externally-influenced value\n    ╭▸ src/StakeVault.sol:171:13\n    │\n171 │         if (token.balanceOf(address(this)) != beforeBalance + amount) revert UnsupportedToken();\n    │             ━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━\n    │\n    ╰ help: https://getfoundry.sh/forge/linting/incorrect-strict-equality\n\n","passed":true},{"durationMs":6730,"exitCode":0,"name":"test","output":"No files changed, compilation skipped\n\nRan 17 tests for test/StakeVault.t.sol:StakeVaultTest\n[PASS] testFuzz_twoStakersConserveRewards(uint96,uint96,uint96) (runs: 512, μ: 807236, ~: 812838)\nLogs:\n  Bound result 2545927184947636534\n  Bound result 27\n  Bound result 1645\n\n[PASS] test_constructorConfigurationAndValidation() (gas: 36453)\n[PASS] test_directDonationsAreNeitherPrincipalNorScheduledRewards() (gas: 563930)\n[PASS] test_emptyIntervalsAreNotAwardedToNextDepositorAndRecycleOnFunding() (gas: 695455)\n[PASS] test_fundingAfterFullyIdlePeriodRecyclesWholePool() (gas: 524634)\n[PASS] test_invalidAmountsAndUnapprovedDepositAreAtomic() (gas: 332171)\n[PASS] test_lateEntryDoesNotEarnHistoricalRewards() (gas: 689736)\n[PASS] test_oneWeiRewardIsNotLostToIntegerRateRounding() (gas: 491557)\n[PASS] test_onlyOwnerCanPauseOrFundAndOwnerCannotWithdrawUserStake() (gas: 401977)\n[PASS] test_pauseDoesNotStopClaimsWithdrawalsOrFunding() (gas: 863041)\n[PASS] test_rewardsAreProportionalToStake() (gas: 670561)\n[PASS] test_singleStakerEarnsOverTimeCanClaimWhileLockedAndCannotDoubleClaim() (gas: 701791)\n[PASS] test_stakeAndWithdrawExactlyAtLockBoundary() (gas: 426196)\n[PASS] test_stakingBeforeFundingAndAfterFinishDoesNotEarn() (gas: 670032)\n[PASS] test_topUpPreservesEarnedAndReschedulesOnlyUnvested() (gas: 647763)\n[PASS] test_topUpResetsOnlyCallersEntireLock() (gas: 546990)\n[PASS] test_withdrawalPreservesEarnedRewardsAndStopsNewEarnings() (gas: 776328)\nSuite result: ok. 17 passed; 0 failed; 0 skipped; finished in 168.88ms (150.50ms CPU time)\n\nRan 6 tests for test/LaunchToken.t.sol:LaunchTokenTest\n[PASS] testFuzz_transfersConserveSupply(uint256) (runs: 512, μ: 141368, ~: 141808)\nLogs:\n  Bound result 203169456008075678237900395\n\n[PASS] test_allowanceAndTransferFrom() (gas: 235433)\n[PASS] test_fixedSupplyAndMetadata() (gas: 52773)\n[PASS] test_noMintOrAdministrativeEntrypointsEvenForDeployer() (gas: 385152)\n[PASS] test_rejectsZeroRecipientAndInsufficientBalance() (gas: 57316)\n[PASS] test_transferAndZeroTransfer() (gas: 154467)\nSuite result: ok. 6 passed; 0 failed; 0 skipped; finished in 177.57ms (45.21ms CPU time)\n\nRan 20 tests for test/StakeVaultAdversarial.t.sol:StakeVaultAdversarialTest\n[PASS] testFuzz_StaggeredStakesMatchIndependentTimeShareCalculation(uint96,uint96,uint96,uint32) (runs: 512, μ: 936507, ~: 936492)\nLogs:\n  Bound result 1000000000000000003\n  Bound result 5728296663409473156234\n  Bound result 99900000032953930533202\n  Bound result 261113\n\n[PASS] testFuzz_UnknownSelectorsCannotGiveOwnerPrincipal(uint96) (runs: 512, μ: 305224, ~: 305038)\nLogs:\n  Bound result 14468\n\n[PASS] test_Create2FactoryKeepsSupplyAndHasNoImplicitOwnerAuthority() (gas: 2700356)\n[PASS] test_DonationIsNotClaimableByOwnerOrLateStaker() (gas: 387328)\n[PASS] test_ExpiredIdleRewardsCannotBeSnipedByFirstStaker() (gas: 651505)\n[PASS] test_FailedClaimKeepsAccruedRewardAndReserveForRetry() (gas: 1848168)\n[PASS] test_FailedDepositRollsBackRewardCheckpointAndBalances() (gas: 1521852)\n[PASS] test_FailedFundingDoesNotRescheduleOrIncreaseReserve() (gas: 1506267)\n[PASS] test_FailedWithdrawKeepsPrincipalAndUnlockForRetry() (gas: 1569556)\n[PASS] test_IncomingFeeRevertsBothDepositAndFundingWithoutBurningTokens() (gas: 1452471)\n[PASS] test_LastSecondDepositReceivesOnlyLastSecondShare() (gas: 577660)\n[PASS] test_OneWeiFundingIsVestedRatherThanDiscardedByRateDivision() (gas: 477987)\n[PASS] test_RoundingDustCannotConsumePrincipalOrBecomeOwnerWithdrawable() (gas: 539910)\n[PASS] test_SameBlockDepositAndWithdrawCannotEarnRewardsOrBypassLock() (gas: 403678)\n[PASS] test_TopUpPreservesEarnedRewardsButRestartsUnvestedSchedule() (gas: 708507)\n[PASS] test_TransferCallbackCannotReenterRewardClaim() (gas: 1757540)\n[PASS] test_TransferCallbackCannotReenterWithdrawal() (gas: 1570076)\n[PASS] test_TransferFromCallbackCannotReenterDeposit() (gas: 1500856)\n[PASS] test_TransferFromCallbackCannotReenterRewardClaimDuringFunding() (gas: 1471817)\n[PASS] test_ZeroStakeGapRecyclesOnlyRewardsReleasedDuringGap() (gas: 953266)\nSuite result: ok. 20 passed; 0 failed; 0 skipped; finished in 177.62ms (312.75ms CPU time)\n\nRan 13 tests for test/StakeVaultProperties.t.sol:StakeVaultPropertiesTest\n[PASS] testFuzz_claimSplittingPreservesExactlyDivisibleRewards(uint256,uint256) (runs: 1000, μ: 1908739, ~: 1931166)\nLogs:\n  Bound result 3\n  Bound result 16\n\n[PASS] testFuzz_customLockUsesConstructorValue(uint256) (runs: 1000, μ: 612645, ~: 612774)\nLogs:\n  Bound result 18446744073708948244\n\n[PASS] testFuzz_partialWithdrawalChangesOnlyFutureRewardShare(uint256,uint256,uint256,uint256,uint256) (runs: 1000, μ: 1116355, ~: 1126184)\nLogs:\n  Bound result 3\n  Bound result 276568608977045183053656\n  Bound result 2\n  Bound result 12520282128613475430415631\n  Bound result 337097\n\n[PASS] testFuzz_sameTimestampFundingPartitionsHaveSamePayout(uint256,uint256) (runs: 1000, μ: 636957, ~: 637092)\nLogs:\n  Bound result 184559421580552935937596704\n  Bound result 524856719\n\n[PASS] test_constructorRejectsVaultAsItsOwnOwner() (gas: 6985)\n[PASS] test_entireSupplyCanBeStakedAndWithdrawnWhilePaused() (gas: 392161)\n[PASS] test_failedFundingAndDepositPreserveActiveRewardsAndFiniteAllowances() (gas: 1265769)\n[PASS] test_maximumLockRemainsEnforcedAfterRewardsFinish() (gas: 608647)\n[PASS] test_oneSecondLockDoesNotShortenRewardSchedule() (gas: 656170)\n[PASS] test_oneWeiStakeCanEarnAllRemainingSupply() (gas: 601919)\n[PASS] test_ownerStakesAndEarnsOnSameTermsAsEveryoneElse() (gas: 969615)\n[PASS] test_unstakeAndRestakeCannotAcquireRewardsFromTheGap() (gas: 1116282)\n[PASS] test_zeroAndMaximumInputsCannotAlterAnActivePosition() (gas: 916332)\nSuite result: ok. 13 passed; 0 failed; 0 skipped; finished in 177.69ms (670.28ms CPU time)\n\nRan 7 tests for test/LaunchTokenProperties.t.sol:LaunchTokenPropertiesTest\n[PASS]\nLaunchTokenPropertiesTest invariants:\n[PASS] invariant_allowancesMatchApprovalsAndSuccessfulSpending\n[PASS] invariant_balancesMatchLedgerAndSupplyNeverChanges\n LaunchTokenPropertiesTest invariants (runs: 256, calls: 16384, reverts: 0)\n\n╭-------------------------+--------------+-------+---------+----------╮\n| Contract                | Selector     | Calls | Reverts | Discards |\n+=====================================================================+\n| LaunchTokenModelHandler | approve      | 5456  | 0       | 0        |\n|-------------------------+--------------+-------+---------+----------|\n| LaunchTokenModelHandler | transfer     | 5449  | 0       | 0        |\n|-------------------------+--------------+-------+---------+----------|\n| LaunchTokenModelHandler | transferFrom | 5479  | 0       | 0        |\n╰-------------------------+--------------+-------+---------+----------╯\n\nLogs:\n  Bound result 202477911219847267383686519\n  Bound result 110079576154098649145356941\n  Bound result 95\n  Bound result 10196757680459231619508114\n  Bound result 4697\n  Bound result 11\n  Bound result 5\n  Bound result 4337\n\n[PASS] test_approvalReplacementAndRevocationTakeEffectImmediately() (gas: 232076)\n[PASS] test_cannotApproveZeroSpenderOrTransferFromZeroSender() (gas: 82327)\n[PASS] test_delegatedSelfTransferConsumesAllowanceButPreservesBalance() (gas: 119715)\n[PASS] test_failedTransferFromDoesNotConsumeFiniteAllowance() (gas: 134187)\n[PASS] test_zeroReceiverRevertsEvenForZeroTransferFrom() (gas: 69566)\n[PASS] test_zeroTransferFromNeedsNoAllowanceAndMovesNothing() (gas: 76395)\nSuite result: ok. 7 passed; 0 failed; 0 skipped; finished in 4.66s (4.66s CPU time)\n\nRan 1 test for test/StakeVaultInvariant.t.sol:StakeVaultInvariantTest\n[PASS]\nStakeVaultInvariantTest invariants:\n[PASS] invariant_actorBalancesAndClaimsAreFullyBacked\n[PASS] invariant_allTokensRemainInKnownCustody\n[PASS] invariant_locksAndPauseMatchAuthorizedOperations\n[PASS] invariant_tokenCustodyMatchesPrincipalRewardsAndDonations\n StakeVaultInvariantTest invariants (runs: 256, calls: 24576, reverts: 0)\n\n╭--------------+----------------------+-------+---------+----------╮\n| Contract     | Selector             | Calls | Reverts | Discards |\n+==================================================================+\n| VaultHandler | advanceTime          | 2670  | 0       | 0        |\n|--------------+----------------------+-------+---------+----------|\n| VaultHandler | claim                | 2754  | 0       | 0        |\n|--------------+----------------------+-------+---------+----------|\n| VaultHandler | donate               | 2711  | 0       | 0        |\n|--------------+----------------------+-------+---------+----------|\n| VaultHandler | fund                 | 2771  | 0       | 0        |\n|--------------+----------------------+-------+---------+----------|\n| VaultHandler | pause                | 2683  | 0       | 0        |\n|--------------+----------------------+-------+---------+----------|\n| VaultHandler | rejectInvalidAmounts | 2749  | 0       | 0        |\n|--------------+----------------------+-------+---------+----------|\n| VaultHandler | rejectUnauthorized   | 2761  | 0       | 0        |\n|--------------+----------------------+-------+---------+----------|\n| VaultHandler | stake                | 2719  | 0       | 0        |\n|--------------+----------------------+-------+---------+----------|\n| VaultHandler | withdraw             | 2758  | 0       | 0        |\n╰--------------+----------------------+-------+---------+----------╯\n\nLogs:\n  Bound result 100000000000000000002\n  Bound result 200000000000000000002\n  Bound result 700000000000000000002\n  Bound result 236150338990\n  Bound result 2957397980\n  Bound result 4099\n  Bound result 1606064150627347\n  Bound result 6947\n  Bound result 870400\n  Bound result 368689\n  Bound result 200000000000000000002\n  Bound result 286847579627778816483663\n  Bound result 339200\n  Bound result 3547\n  Bound result 4087\n  Bound result 770000000000000000000\n  Bound result 1156963\n  Bound result 1608900\n  Bound result 11697\n  Bound result 10997\n  Bound result 6432\n  Bound result 612\n  Bound result 255\n  Bound result 10206\n  Bound result 1030400\n  Bound result 525000000000000000000\n  Bound result 60480000\n  Bound result 1846\n  Bound result 432\n  Bound result 2827\n  Bound result 422787\n  Bound result 3792478065\n  Bound result 1430\n  Bound result 10\n\nSuite result: ok. 1 passed; 0 failed; 0 skipped; finished in 6.62s (6.62s CPU time)\n\nRan 6 test suites in 6.62s (11.98s CPU time): 64 tests passed, 0 failed, 0 skipped (64 total tests)\n","passed":true}],"detail":"all checks passed","evaluation":"checks","profile":"foundry","status":"accepted","submissionHash":"84070c9e6c785197e02aa18100004d19c79ad8599c62b320b6354763762c2c2c","verifiedTreeHash":"8e32d9f276c5c417d40a9ee911ccd36a0b5e9ad8","verifierVersion":"0.1.0+78c54e29"},{"checks":[{"durationMs":1721,"exitCode":0,"name":"build","output":"Compiling 41 files with Solc 0.8.26\nSolc 0.8.26 finished in 1.62s\nCompiler run successful!\nwarning[reentrancy-events]: event emitted after an external call; reentrancy can reorder or fabricate logs that off-chain consumers rely on\n   ╭▸ src/StakeVault.sol:82:9\n   │\n82 │         emit Staked(msg.sender, amount, unlockAt[msg.sender]);\n   │         ━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━\n   │\n   ╰ help: https://getfoundry.sh/forge/linting/reentrancy-events\n\nwarning[block-timestamp]: usage of `block.timestamp` in a comparison may be manipulated by validators\n   ╭▸ src/StakeVault.sol:89:13\n   │\n89 │         if (block.timestamp < unlockAt[msg.sender]) revert StakeLocked(unlockAt[msg.sender]);\n   │             ━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━\n   │\n   ╰ help: https://getfoundry.sh/forge/linting/block-timestamp\n\nwarning[reentrancy-events]: event emitted after an external call; reentrancy can reorder or fabricate logs that off-chain consumers rely on\n   ╭▸ src/StakeVault.sol:95:9\n   │\n95 │         emit Withdrawn(msg.sender, amount);\n   │         ━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━\n   │\n   ╰ help: https://getfoundry.sh/forge/linting/reentrancy-events\n\nwarning[reentrancy-events]: event emitted after an external call; reentrancy can reorder or fabricate logs that off-chain consumers rely on\n    ╭▸ src/StakeVault.sol:106:9\n    │\n106 │         emit RewardPaid(msg.sender, amount);\n    │         ━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━\n    │\n    ╰ help: https://getfoundry.sh/forge/linting/reentrancy-events\n\nwarning[reentrancy-events]: event emitted after an external call; reentrancy can reorder or fabricate logs that off-chain consumers rely on\n    ╭▸ src/StakeVault.sol:122:9\n    │\n122 │         emit RewardsFunded(amount, periodReward, periodFinish);\n    │         ━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━\n    │\n    ╰ help: https://getfoundry.sh/forge/linting/reentrancy-events\n\nwarning[incorrect-strict-equality]: dangerous strict equality check on an externally-influenced value\n    ╭▸ src/StakeVault.sol:171:13\n    │\n171 │         if (token.balanceOf(address(this)) != beforeBalance + amount) revert UnsupportedToken();\n    │             ━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━\n    │\n    ╰ help: https://getfoundry.sh/forge/linting/incorrect-strict-equality\n\n","passed":true},{"durationMs":1449,"exitCode":0,"name":"test","output":"No files changed, compilation skipped\n\nRan 6 tests for test/LaunchToken.t.sol:LaunchTokenTest\n[PASS] testFuzz_transfersConserveSupply(uint256) (runs: 512, μ: 141274, ~: 141808)\nLogs:\n  Bound result 95092\n\n[PASS] test_allowanceAndTransferFrom() (gas: 235433)\n[PASS] test_fixedSupplyAndMetadata() (gas: 52773)\n[PASS] test_noMintOrAdministrativeEntrypointsEvenForDeployer() (gas: 385152)\n[PASS] test_rejectsZeroRecipientAndInsufficientBalance() (gas: 57316)\n[PASS] test_transferAndZeroTransfer() (gas: 154467)\nSuite result: ok. 6 passed; 0 failed; 0 skipped; finished in 19.73ms (20.33ms CPU time)\n\nRan 17 tests for test/StakeVault.t.sol:StakeVaultTest\n[PASS] testFuzz_twoStakersConserveRewards(uint96,uint96,uint96) (runs: 512, μ: 806634, ~: 812838)\nLogs:\n  Bound result 4007\n  Bound result 23398\n  Bound result 507\n\n[PASS] test_constructorConfigurationAndValidation() (gas: 36453)\n[PASS] test_directDonationsAreNeitherPrincipalNorScheduledRewards() (gas: 563930)\n[PASS] test_emptyIntervalsAreNotAwardedToNextDepositorAndRecycleOnFunding() (gas: 695455)\n[PASS] test_fundingAfterFullyIdlePeriodRecyclesWholePool() (gas: 524634)\n[PASS] test_invalidAmountsAndUnapprovedDepositAreAtomic() (gas: 332171)\n[PASS] test_lateEntryDoesNotEarnHistoricalRewards() (gas: 689736)\n[PASS] test_oneWeiRewardIsNotLostToIntegerRateRounding() (gas: 491557)\n[PASS] test_onlyOwnerCanPauseOrFundAndOwnerCannotWithdrawUserStake() (gas: 401977)\n[PASS] test_pauseDoesNotStopClaimsWithdrawalsOrFunding() (gas: 863041)\n[PASS] test_rewardsAreProportionalToStake() (gas: 670561)\n[PASS] test_singleStakerEarnsOverTimeCanClaimWhileLockedAndCannotDoubleClaim() (gas: 701791)\n[PASS] test_stakeAndWithdrawExactlyAtLockBoundary() (gas: 426196)\n[PASS] test_stakingBeforeFundingAndAfterFinishDoesNotEarn() (gas: 670032)\n[PASS] test_topUpPreservesEarnedAndReschedulesOnlyUnvested() (gas: 647763)\n[PASS] test_topUpResetsOnlyCallersEntireLock() (gas: 546990)\n[PASS] test_withdrawalPreservesEarnedRewardsAndStopsNewEarnings() (gas: 776328)\nSuite result: ok. 17 passed; 0 failed; 0 skipped; finished in 38.23ms (45.40ms CPU time)\n\nRan 20 tests for test/StakeVaultAdversarial.t.sol:StakeVaultAdversarialTest\n[PASS] testFuzz_StaggeredStakesMatchIndependentTimeShareCalculation(uint96,uint96,uint96,uint32) (runs: 512, μ: 936533, ~: 936492)\nLogs:\n  Bound result 9999000000000000025704\n  Bound result 9999000000000000015988\n  Bound result 99900000000000000000547\n  Bound result 11761\n\n[PASS] testFuzz_UnknownSelectorsCannotGiveOwnerPrincipal(uint96) (runs: 512, μ: 305182, ~: 305074)\nLogs:\n  Bound result 351\n\n[PASS] test_Create2FactoryKeepsSupplyAndHasNoImplicitOwnerAuthority() (gas: 2700356)\n[PASS] test_DonationIsNotClaimableByOwnerOrLateStaker() (gas: 387328)\n[PASS] test_ExpiredIdleRewardsCannotBeSnipedByFirstStaker() (gas: 651505)\n[PASS] test_FailedClaimKeepsAccruedRewardAndReserveForRetry() (gas: 1848168)\n[PASS] test_FailedDepositRollsBackRewardCheckpointAndBalances() (gas: 1521852)\n[PASS] test_FailedFundingDoesNotRescheduleOrIncreaseReserve() (gas: 1506267)\n[PASS] test_FailedWithdrawKeepsPrincipalAndUnlockForRetry() (gas: 1569556)\n[PASS] test_IncomingFeeRevertsBothDepositAndFundingWithoutBurningTokens() (gas: 1452471)\n[PASS] test_LastSecondDepositReceivesOnlyLastSecondShare() (gas: 577660)\n[PASS] test_OneWeiFundingIsVestedRatherThanDiscardedByRateDivision() (gas: 477987)\n[PASS] test_RoundingDustCannotConsumePrincipalOrBecomeOwnerWithdrawable() (gas: 539910)\n[PASS] test_SameBlockDepositAndWithdrawCannotEarnRewardsOrBypassLock() (gas: 403678)\n[PASS] test_TopUpPreservesEarnedRewardsButRestartsUnvestedSchedule() (gas: 708507)\n[PASS] test_TransferCallbackCannotReenterRewardClaim() (gas: 1757540)\n[PASS] test_TransferCallbackCannotReenterWithdrawal() (gas: 1570076)\n[PASS] test_TransferFromCallbackCannotReenterDeposit() (gas: 1500856)\n[PASS] test_TransferFromCallbackCannotReenterRewardClaimDuringFunding() (gas: 1471817)\n[PASS] test_ZeroStakeGapRecyclesOnlyRewardsReleasedDuringGap() (gas: 953266)\nSuite result: ok. 20 passed; 0 failed; 0 skipped; finished in 40.21ms (78.48ms CPU time)\n\nRan 1 test for test/StakeVaultInvariant.t.sol:StakeVaultInvariantTest\n[PASS]\nStakeVaultInvariantTest invariants:\n[PASS] invariant_actorBalancesAndClaimsAreFullyBacked\n[PASS] invariant_tokenCustodyMatchesPrincipalRewardsAndDonations\n StakeVaultInvariantTest invariants (runs: 128, calls: 8192, reverts: 0)\n\n╭--------------+-------------+-------+---------+----------╮\n| Contract     | Selector    | Calls | Reverts | Discards |\n+=========================================================+\n| VaultHandler | advanceTime | 1180  | 0       | 0        |\n|--------------+-------------+-------+---------+----------|\n| VaultHandler | claim       | 1201  | 0       | 0        |\n|--------------+-------------+-------+---------+----------|\n| VaultHandler | donate      | 1158  | 0       | 0        |\n|--------------+-------------+-------+---------+----------|\n| VaultHandler | fund        | 1113  | 0       | 0        |\n|--------------+-------------+-------+---------+----------|\n| VaultHandler | pause       | 1200  | 0       | 0        |\n|--------------+-------------+-------+---------+----------|\n| VaultHandler | stake       | 1191  | 0       | 0        |\n|--------------+-------------+-------+---------+----------|\n| VaultHandler | withdraw    | 1149  | 0       | 0        |\n╰--------------+-------------+-------+---------+----------╯\n\nLogs:\n  Bound result 244\n  Bound result 43847198871297868726420375\n  Bound result 16000000000000000000\n  Bound result 659918\n  Bound result 18\n  Bound result 9224802\n  Bound result 34548595813827058680232921\n  Bound result 1\n  Bound result 3\n  Bound result 47137591477094471441789676\n  Bound result 2871\n  Bound result 47666116232027143347081987\n  Bound result 1380\n  Bound result 30701506572615969064641440\n  Bound result 1965568837\n  Bound result 143554965570928414838219735\n  Bound result 22068023823235062878631633\n  Bound result 897\n  Bound result 668\n  Bound result 6082\n  Bound result 172800\n  Bound result 64557689289985235\n  Bound result 851200\n  Bound result 242\n  Bound result 760238\n  Bound result 242\n  Bound result 2233625728\n  Bound result 1642\n  Bound result 9922\n\nSuite result: ok. 1 passed; 0 failed; 0 skipped; finished in 1.37s (1.36s CPU time)\n\nRan 4 test suites in 1.37s (1.46s CPU time): 44 tests passed, 0 failed, 0 skipped (44 total tests)\n","passed":true},{"durationMs":911,"exitCode":0,"name":"slither","output":"[medium/high] incorrect-equality at src/StakeVault.sol:99: StakeVault.claimRewards() (src/StakeVault.sol#99-107) uses a dangerous strict equality:\n[low/medium] timestamp at src/StakeVault.sol:86: StakeVault.withdraw(uint256) (src/StakeVault.sol#86-96) uses timestamp for comparisons\n[low/medium] timestamp at src/StakeVault.sol:99: StakeVault.claimRewards() (src/StakeVault.sol#99-107) uses timestamp for comparisons\n[low/medium] timestamp at src/StakeVault.sol:162: StakeVault._releasedAt(uint256) (src/StakeVault.sol#162-166) uses timestamp for comparisons","passed":true},{"durationMs":336,"exitCode":0,"name":"aderyn","output":"[low] centralization-risk at src/StakeVault.sol:111: Centralization Risk (2 places)\n[low] large-numeric-literal at src/LaunchToken.sol:9: Large Numeric Literal\n[low] unused-public-function at src/StakeVault.sol:136: Public Function Not Used Internally","passed":true}],"detail":"all checks passed","evaluation":"checks","profile":"foundry","status":"accepted","submissionHash":"afea32308cbdccce581e76bbed8ead0b5e34bb6fd18c032e938c92e13d7d96a8","verifiedTreeHash":"a128592b1b5a6477f9835a05dbe00e7b1f0eb49d","verifierVersion":"0.1.0+78c54e29"}]}