{"assessments":[],"deployments":[],"fuzz":[],"identity":{"adapter":"0xde152afb7db5373f34876e1499fbd893a82dd336","chainId":1,"collection":"0x0000ec93127baa929e58e97dd0095a2bfb38ec1d","registry":"0x8004a169fb4a3325136eb29fa0ceb6d2e539a432"},"interpretation":"Records acceptance and evidence. Neither completion nor an AI assessment establishes correctness, safety, or independent review.","jobId":"a017ded9-6a66-48aa-973e-1c54bc56792a","kind":"shape:chain","nodes":[{"acceptedSubmissionHash":"eea24a513d99a9900f40e2b90b6eb787f9dc2b0c4bffb8276d55a4d2784967cf","dependsOn":["build_contract_project"],"execution":{"network":false,"profile":"foundry","requires":[],"skillHash":"e5ac2cb1fd91a56aa40b16487fc230c48de0d317c8266140331dd3219bb40a85","skillId":"audit-specialist","tools":[]},"key":"audit_economics","kind":"code","role":"review","skillHash":"e5ac2cb1fd91a56aa40b16487fc230c48de0d317c8266140331dd3219bb40a85","skillId":"audit-specialist","state":"accepted"},{"acceptedSubmissionHash":"fcd362670cb908ccf64a02a4329b307468b5fe433e9986ff45fa7973a6a5f87f","dependsOn":["build_contract_project"],"execution":{"network":false,"profile":"foundry","requires":[],"skillHash":"e5ac2cb1fd91a56aa40b16487fc230c48de0d317c8266140331dd3219bb40a85","skillId":"audit-specialist","tools":[]},"key":"audit_flow","kind":"code","role":"review","skillHash":"e5ac2cb1fd91a56aa40b16487fc230c48de0d317c8266140331dd3219bb40a85","skillId":"audit-specialist","state":"accepted"},{"acceptedSubmissionHash":"035b7df3dcf23cf7598bb7b51db6472d225f2a9979134408b2062aca8589cceb","dependsOn":["build_contract_project","write_foundry_tests","manifest","audit_math","audit_permissions","audit_economics","audit_flow"],"execution":{"network":false,"profile":"foundry","requires":[],"skillHash":"3014f1ea5961918ca059453a484bf4c8bcbbfc2248dbe31d94ac7c5cdf8f50bd","skillId":"audit-judge","tools":[]},"key":"audit_judge","kind":"code","role":"review","skillHash":"3014f1ea5961918ca059453a484bf4c8bcbbfc2248dbe31d94ac7c5cdf8f50bd","skillId":"audit-judge","state":"accepted"},{"acceptedSubmissionHash":"386bc19973d2d2955af0480b0cd52c51b5dac417107252b66c70f53b5019f92d","dependsOn":["build_contract_project"],"execution":{"network":false,"profile":"foundry","requires":[],"skillHash":"e5ac2cb1fd91a56aa40b16487fc230c48de0d317c8266140331dd3219bb40a85","skillId":"audit-specialist","tools":[]},"key":"audit_math","kind":"code","role":"review","skillHash":"e5ac2cb1fd91a56aa40b16487fc230c48de0d317c8266140331dd3219bb40a85","skillId":"audit-specialist","state":"accepted"},{"acceptedSubmissionHash":"20509a6d6238592d3227dee21d31c761a5eb9957e349eb31c36ea51312f3d5ba","dependsOn":["build_contract_project"],"execution":{"network":false,"profile":"foundry","requires":[],"skillHash":"e5ac2cb1fd91a56aa40b16487fc230c48de0d317c8266140331dd3219bb40a85","skillId":"audit-specialist","tools":[]},"key":"audit_permissions","kind":"code","role":"review","skillHash":"e5ac2cb1fd91a56aa40b16487fc230c48de0d317c8266140331dd3219bb40a85","skillId":"audit-specialist","state":"accepted"},{"acceptedSubmissionHash":"e9f93a5293e2434a29837f16b8a51d229a01e21b0cad2344f7593eb5370d34ab","dependsOn":[],"execution":{"mustProduce":["src/LaunchToken.sol"],"network":false,"profile":"foundry","requires":[],"skillHash":"47381b166d1f406a34f0ebdc740ee21bc0383e56e7ad9084b26abf1bf7570904","skillId":"build-contract-project","tools":[]},"key":"build_contract_project","kind":"code","role":"implement","skillHash":"47381b166d1f406a34f0ebdc740ee21bc0383e56e7ad9084b26abf1bf7570904","skillId":"build-contract-project","state":"accepted"},{"acceptedSubmissionHash":"28500319df8883ce55e227167600c1b2660a6cc1bcb6e5c0a6104097b6540c69","dependsOn":["build_contract_project"],"execution":{"network":false,"profile":"foundry","requires":[],"tools":[]},"key":"manifest","kind":"code","role":"integrate","skillHash":null,"skillId":null,"state":"accepted"},{"acceptedSubmissionHash":"792503f71221950663430d26154d754b875742e518f3082927341d3d674d9272","dependsOn":["build_contract_project"],"execution":{"network":false,"profile":"foundry","requires":[],"skillHash":"73431852439ad3a343f3d2b7db1c43cd363b9f48f9bb51497374a0cf6d50b223","skillId":"write-foundry-tests","tools":[]},"key":"write_foundry_tests","kind":"code","role":"tests","skillHash":"73431852439ad3a343f3d2b7db1c43cd363b9f48f9bb51497374a0cf6d50b223","skillId":"write-foundry-tests","state":"accepted"}],"objective":"a contract that accepts only eth. and doesnt accept more than 1 eth in total.","parentJobId":null,"planHash":"70e89904c2d0960c9d0d21b99be7617788c666ed675dfc27dcf04de53e2d2ead","previousHash":"0000000000000000000000000000000000000000000000000000000000000000","projectId":"a017ded9-6a66-48aa-973e-1c54bc56792a","publication":{"commit":null,"deliveredAt":null,"repoUrl":"https://github.com/identity-md-launches/launch-571-contract-accepts-only-eth"},"receiptIdentity":{"adapter":"0xde152afb7db5373f34876e1499fbd893a82dd336","chainId":1,"collection":"0x0000ec93127baa929e58e97dd0095a2bfb38ec1d","registry":"0x8004a169fb4a3325136eb29fa0ceb6d2e539a432"},"registry":"0xb6d0a187b050fa5bb0b87033a203f37becf4a775","research":[],"schema":"identitymd-work-v1","signals":[{"agentId":"50974","feedbackHash":"a955250e4241002e72c2860261dda3772f66165b4f3c91b2c3921261ec604344","nodeKey":"audit_economics","submissionHash":"eea24a513d99a9900f40e2b90b6eb787f9dc2b0c4bffb8276d55a4d2784967cf","tag1":"review:submission","tag2":"acceptance-v2","value":1},{"agentId":"50956","feedbackHash":"ddd80419950fb3bc3d5b1cfc04329d90f36cc61474c730bd931649e670ec4697","nodeKey":"audit_flow","submissionHash":"fcd362670cb908ccf64a02a4329b307468b5fe433e9986ff45fa7973a6a5f87f","tag1":"review:submission","tag2":"acceptance-v2","value":1},{"agentId":"51432","feedbackHash":"c731b03c28f9455248cb508af2ff170a4223f286fb5c7fcdd26b1de9d62863a2","nodeKey":"audit_judge","submissionHash":"035b7df3dcf23cf7598bb7b51db6472d225f2a9979134408b2062aca8589cceb","tag1":"review:submission","tag2":"acceptance-v2","value":1},{"agentId":"50959","feedbackHash":"edf53c793d706875dda68ac106b3218eaa559cd7badd2e1f5136b79e17288410","nodeKey":"audit_math","submissionHash":"386bc19973d2d2955af0480b0cd52c51b5dac417107252b66c70f53b5019f92d","tag1":"review:submission","tag2":"acceptance-v2","value":1},{"agentId":"50962","feedbackHash":"fd299486111da988313105c4c91f34089dd6b474a18249bb15146414f9ca4031","nodeKey":"audit_permissions","submissionHash":"20509a6d6238592d3227dee21d31c761a5eb9957e349eb31c36ea51312f3d5ba","tag1":"review:submission","tag2":"acceptance-v2","value":1},{"agentId":"50955","feedbackHash":"a78726e5347b153f3a9b1f33bc850af67dc096b5c34cf3486a051edc842a950d","nodeKey":"build_contract_project","submissionHash":"e9f93a5293e2434a29837f16b8a51d229a01e21b0cad2344f7593eb5370d34ab","tag1":"verification:checks","tag2":"acceptance-v2","value":1},{"agentId":"51046","feedbackHash":"91c7355705962b71177ffd3cb2d27554524b892f7c027820abf0c9e5d5faf0b1","nodeKey":"manifest","submissionHash":"28500319df8883ce55e227167600c1b2660a6cc1bcb6e5c0a6104097b6540c69","tag1":"verification:checks","tag2":"acceptance-v2","value":1},{"agentId":"50957","feedbackHash":"0476481201857808689b4dd801d21a96c14850e401447d02971a98f4e4c62820","nodeKey":"write_foundry_tests","submissionHash":"792503f71221950663430d26154d754b875742e518f3082927341d3d674d9272","tag1":"verification:checks","tag2":"acceptance-v2","value":1}],"site":null,"snapshotHash":"4f484009c82a9b01347c78857a23567f49e07db17b45ca9a8fb2cde55b89ad59","state":"completed","submissions":[{"artifacts":[],"attempt":1,"bundleHash":null,"device":"03f15d1296244279","findings":[{"citation":"resolved","description":"Kept from audit_economics (its only non-info finding); reproduced. `receive()` calls `_accept()`, which does an SLOAD of `totalAccepted`, an SSTORE and a LOG2. Measured cost of the receive path on this build is 56,765 gas for the first deposit and 35,157 for later ones, against the 2,300 gas that Solidity's `payable(x).transfer()` and `.send()` forward. Any contract sender that uses those primitives (older payment splitters, some wallet modules) has its deposit reverted (`transfer`) or silently refused (`send` returns false), while an EOA or a `call{value:}` sender with the same amount is accepted. No ETH is lost and the lifetime cap is not weakened, so this is low. The contract's own NatSpec (line 8, 'a plain transfer with empty calldata') and the README ('plain transfer, empty calldata') describe the entry point in words a Solidity author reads as `.transfer()`. Counting a deposit in storage cannot be done under the stipend, so the realistic fix preserving the design is documentation: state that depositors must use `call{value:}` or `deposit()` and that `.transfer()`/`.send()` are not supported, and add a regression test for it (the current suite never exercises the stipend path).","line":54,"path":"src/OneEthCap.sol","reproduction":"State: fresh OneEthCap, totalAccepted = 0, remaining() = 1 ether. A helper contract S executes `payable(address(cap)).transfer(0.1 ether)`. Expected per README: deposit accepted, totalAccepted = 0.1 ether. Actual: the inner call runs out of gas inside _accept() and the outer transfer reverts; totalAccepted stays 0 and cap balance stays 0. `payable(address(cap)).send(0.1 ether)` returns false with the same state. Warm case: after one successful deposit via call, `address(cap).call{value: 0.1 ether, gas: 2300}(\"\")` also returns false and totalAccepted stays 0.1 ether. Verified with a scratch Foundry test (vm.expectRevert on the transfer helper, assertFalse on the send and 2300-gas call helpers); all three assertions pass on the current tree.","severity":"low","snippet":"    receive() external payable {\n        _accept();\n    }","title":"receive() cannot run inside the 2300-gas stipend, so ETH pushed with transfer()/send() is refused even when room remains under the cap"},{"citation":"resolved","description":"Merged from audit_math and audit_economics, which reported the same root cause at the same line; reproduced. The only way ETH leaves the contract is sweep() pushing the whole balance to `beneficiary`, which is immutable and set from the manifest's `$owner`. The constructor rejects only address(0); it cannot check that the address accepts ETH. If `$owner` resolves to a contract without a payable receive/fallback, one whose receive reverts, or an EOA later delegated under EIP-7702 to code that refuses ETH, every sweep() reverts with SweepFailed, the revert rolls back totalSwept, and there is no pull path, refund path or beneficiary change, so up to 1 ETH of deposits plus any forced ETH is unrecoverable. This is reachable only through deployment configuration, not by an unprivileged actor, and the README documents it under Operational responsibilities, so it is recorded as a trust assumption for the manifest review rather than a code defect: the `$owner` the policy resolves for this launch must be verified to accept a plain ETH call with empty calldata before admission. A pull-based claim would be the only code-level mitigation and is a design change, not a required fix.","line":79,"path":"src/OneEthCap.sol","reproduction":"State: `new OneEthCap(address(new RejectingBeneficiary()))` where RejectingBeneficiary's receive() reverts (or a contract with no receive/fallback at all; both reproduced). alice calls deposit{value: 0.1 ether}(); totalAccepted = 0.1 ether. Anyone calls sweep(). Expected for a receiving beneficiary: beneficiary.balance = 0.1 ether, totalSwept = 0.1 ether. Actual: revert SweepFailed(), address(cap).balance stays 0.1 ether, totalSwept stays 0, and no later call can move it because beneficiary is immutable. This is test_sweepRevertsWhenBeneficiaryRejects in test/OneEthCap.t.sol, which passes on the current tree; the no-receive variant was verified in a scratch test.","severity":"info","snippet":"        (bool ok,) = beneficiary.call{value: amount}(\"\");\n        if (!ok) revert SweepFailed();","title":"Trust assumption: sweep() is a push payment to an immutable beneficiary, so a $owner that cannot receive ETH locks every deposit permanently"},{"citation":"resolved","description":"Found in my own pass; not reported by any specialist. `_transfer` rejects a zero `to` but not a zero `from`, and `transferFrom` only consults the allowance mapping, where allowance[address(0)][anyone] is 0, so a zero-amount transferFrom with from = address(0) passes every check and emits `Transfer(address(0), to, 0)`. That is the exact shape indexers and explorers use to recognise a mint. No balance or supply changes (amount is 0, and any non-zero amount reverts with InsufficientAllowance(0, amount)), so there is no economic impact; it is an event-integrity nit for a token whose README promises no mint. OpenZeppelin v5's ERC20 rejects a zero sender (ERC20InvalidSender) for this reason. Minimal fix that preserves the design: `if (from == address(0)) revert ZeroAddress();` at the top of `_transfer`, plus a test. Not exercised by the current suite.","line":64,"path":"src/LaunchToken.sol","reproduction":"State: fresh LaunchToken, deployer holds 1e27. Input: any address `attacker` calls `token.transferFrom(address(0), attacker, 0)`. Expected (no-mint token, OZ semantics): revert. Actual: returns true and emits Transfer(from = 0x0, to = attacker, value = 0); totalSupply stays 1e27 and balanceOf(attacker) stays 0. Verified with a scratch Foundry test using vm.expectEmit(true, true, false, true) on Transfer(address(0), attacker, 0) followed by assertTrue(token.transferFrom(address(0), attacker, 0)); passes on the current tree. `transferFrom(address(0), attacker, 1)` reverts with InsufficientAllowance(0, 1), confirming no non-zero path exists.","severity":"info","snippet":"    function _transfer(address from, address to, uint256 amount) private {\n        if (to == address(0)) revert ZeroAddress();","title":"transferFrom(address(0), to, 0) succeeds and emits a mint-shaped Transfer(address(0), to, 0) event"}],"hash":"035b7df3dcf23cf7598bb7b51db6472d225f2a9979134408b2062aca8589cceb","nodeId":"9a42dd1b-464f-4936-8b14-361570806caa","outcome":"completed","summary":"Review complete. The findings file is written, every snippet and line checks out against the tree, and the scratch tests are removed so the working tree is clean apart from `.imd-findings.json`.\n\n**Outcome**: no critical, high or medium defects. The full suite of 53 tests passes, formatting is clean, and the OneEthCap runtime has no forbidden opcodes. Three findings are recorded, all reproduced against the code.\n\n- **Low, kept from audit_economics**: `receive()` needs a storage write, so ETH pushed with Solidity's `transfer()` or `send()` is refused even with room under the cap. Measured receive cost is 56,765 gas cold and 35,157 warm against the 2,300 stipend. No funds are lost, so the realistic fix is documentation and a regression test rather than a code change.\n- **Info, merged from audit_math and audit_economics**: the same root cause at the same line, reported twice. The sweep is a push to an immutable beneficiary, so a resolved `$owner` that cannot receive ETH locks all deposits forever. Reachable only through deployment configuration, so it is recorded as a trust assumption for the manifest review.\n- **Info, my own pass**: `transferFrom(address(0), to, 0)` on the token succeeds and emits a mint-shaped Transfer event. No balance or supply effect. A one-line zero-sender check in `_transfer` would close it.\n\n**Dropped**: the slither strict-equality lead, since `balance == 0` is an exact guard. The aderyn unchecked-address lead, since the constructor rejects zero and the call result is checked. The unused-public-function lead is not a defect.\n\n**Coverage**: all seven listed entry points are answered, plus four invariant and wiring rows. Two entry points carry findings and the rest hold. The specialist reports on `deposit`, `fallback`, and `sweep` accounting were traced independently and confirmed, including sweep reentrancy and forced-ETH conservation.","treeHash":null,"usage":{"cachedInputTokens":1121746,"inputTokens":418,"model":"claude-fable-5-1","outputTokens":15938,"runtime":"claude","turns":34,"wallClockMs":223327}},{"artifacts":[],"attempt":1,"bundleHash":null,"device":"3f6a9bdd601cb99f","findings":[],"hash":"20509a6d6238592d3227dee21d31c761a5eb9957e349eb31c36ea51312f3d5ba","nodeId":"9cecd3a0-3960-4e33-9fc0-ec7c1e182b19","outcome":"completed","summary":"Saved [.imd-findings.json](/home/seat/.identitymd/work/a017ded9-6a66-48aa-973e-1c54bc56792a/9cecd3a0-3960-4e33-9fc0-ec7c1e182b19/.imd-findings.json).\n\nNo substantiated permission defects. All seven entry points reviewed; 33 Foundry tests passed. Deployment beneficiary verification remains open because no manifest was supplied.","treeHash":null,"usage":{"cachedInputTokens":352256,"inputTokens":70935,"model":"gpt-6-astra","outputTokens":4759,"runtime":"codex","turns":5,"wallClockMs":197335}},{"artifacts":[],"attempt":1,"bundleHash":"214db18b07ea3c36b3ca1f79c77f5abdb1061c7c0fa2b17e1384b5a3054a59d5","device":"02ae6543274731ab","findings":[],"hash":"28500319df8883ce55e227167600c1b2660a6cc1bcb6e5c0a6104097b6540c69","nodeId":"7423c175-ada6-4677-93a4-637f135ecf65","outcome":"completed","summary":"Created `launch.json` matching the accepted contracts: `LaunchToken` metadata, `OneEthCap` with `$owner`, and the native ETH pool.\n\nSchema and constructor ABI checks passed. `forge build` succeeded; `forge test` passed all 33 tests. Only `launch.json` is changed.","treeHash":"002ee8b61f0405c4a847300bdafa62c3f35a6d7c","usage":{"cachedInputTokens":165504,"inputTokens":21665,"model":"gpt-6-astra","outputTokens":2951,"runtime":"codex","turns":3,"wallClockMs":258509}},{"artifacts":[],"attempt":1,"bundleHash":null,"device":"468e82a89b9bfe18","findings":[{"citation":"resolved","description":"Boundary guide, external call site: the only way ETH leaves the contract is sweep() pushing the whole balance to the immutable beneficiary. The constructor only rejects address(0); it cannot check that the address can accept ETH (an EOA and a Safe both can, a contract without a payable receive/fallback cannot). If the policy's $owner resolves to such a contract, every sweep() reverts SweepFailed, the revert rolls back totalSwept, and there is no rescue, pull-withdrawal or beneficiary change, so up to 1 ETH of depositors' funds plus any forced ETH is locked forever. The README documents this under Operational responsibilities and the suite tests it (test_sweepRevertsWhenBeneficiaryRejects). It is reported so the judge and the manifest review check the actual $owner value; nothing in the arithmetic, boundaries or seams of the contract is wrong. The intended design (fixed beneficiary, push-only sweep) should be preserved; a pull-based claim by the beneficiary would be the only code-level mitigation and is a design change, not a required fix.","line":79,"path":"src/OneEthCap.sol","reproduction":"State: new OneEthCap(address(new RejectingBeneficiary())) where RejectingBeneficiary's receive() reverts. Call deposit{value: 0.1 ether}() from alice (accepted, totalAccepted = 0.1 ether). Call sweep() from anyone. Expected if the beneficiary were an EOA: beneficiary.balance == 0.1 ether, totalSwept == 0.1 ether. Actual: revert SweepFailed(), address(cap).balance stays 0.1 ether, totalSwept stays 0, and no later call can ever move it. Verified by running the existing test_sweepRevertsWhenBeneficiaryRejects in test/OneEthCap.t.sol.","severity":"info","snippet":"        (bool ok,) = beneficiary.call{value: amount}(\"\");\n        if (!ok) revert SweepFailed();","title":"Trust assumption: an immutable beneficiary that cannot receive ETH locks every deposit permanently (deployment input, not a code defect)"}],"hash":"386bc19973d2d2955af0480b0cd52c51b5dac417107252b66c70f53b5019f92d","nodeId":"3a1fbd0f-4440-4152-bea7-f7a20d451e18","outcome":"completed","summary":"Review complete. The findings file is written and the scratch test directory is removed, so the tree holds no source changes.\n\n**Result: no defect in the assigned area.** The math, boundary and numerical-gap guides were applied to every line of `src/OneEthCap.sol` and the token, and nothing fails.\n\n- **Math Precision**: the cap contract has no division, multiplication, scaling, narrowing cast or unchecked block. The two subtractions `CAP - totalAccepted` cannot underflow because the only write to `totalAccepted` enforces `totalAccepted <= CAP`. The `totalSwept` accumulator cannot overflow in practice, confirmed with a forced balance of 2^128 - 1. The token's two unchecked blocks are each guarded by the check immediately before them.\n- **Boundary**: short calldata, unknown selectors, hook selectors and view calls with value all revert without accepting ETH. A deposit of exactly the remaining room is accepted and one wei more is refused with the exact `CapExceeded(room, requested)` values, including at `type(uint128).max`. A beneficiary that deposits and re-sweeps during the callback leaves `balance + totalSwept == totalAccepted` exact.\n- **Numerical Gap**: the cap check and `remaining()` read the same storage value at the same scale, and the zero-value path reverts instead of skipping state, so no seam exists.\n- **Static-analysis leads**: the slither strict-equality line on `sweep()` is a false lead since `balance == 0` is the correct emptiness test. The aderyn unchecked-address line is covered by the constructor's zero check.\n\n**One info entry** records the deployment-input trust assumption: the beneficiary is immutable and push-only, so if the policy's `$owner` resolves to a contract that cannot receive ETH, every sweep reverts and deposits are locked forever. This is documented in the README and tested, so it is flagged for the manifest review rather than as a code defect.\n\n**Coverage**: all seven listed entry points have rows, six `holds` and `sweep()` pointing at the info entry, plus three invariant rows. Build, the 33 existing tests and 8 scratch edge tests all pass offline.","treeHash":null,"usage":{"cachedInputTokens":503499,"inputTokens":226,"model":"claude-fable-5-1","outputTokens":13035,"runtime":"claude","turns":17,"wallClockMs":175976}},{"artifacts":[],"attempt":1,"bundleHash":"edd876959b2ad55af90f342803a0d2341e1711a2aab7c03c36ac6514a23d7ba1","device":"0256823ae36e7900","findings":[],"hash":"792503f71221950663430d26154d754b875742e518f3082927341d3d674d9272","nodeId":"d9bdd4f7-44cc-48bf-8c32-28dd0e446874","outcome":"completed","summary":"Added failure-path, boundary, callback rollback, and fuzz tests, plus stronger ETH and token invariants.\n\nOffline verification passed: **53 tests, 0 failures**. Both invariant suites completed 256 sequences of 64 calls.\n\nOnly `test/` files changed. No reproducible implementation defects found.","treeHash":"59193fb7bb9b539e465992012b1287847a9dbe6d","usage":{"cachedInputTokens":640768,"inputTokens":63993,"model":"gpt-6-astra","outputTokens":5919,"runtime":"codex","turns":5,"wallClockMs":317987}},{"artifacts":[],"attempt":1,"bundleHash":"eb243e5164227dcb28770c71884f06aed56d18f9ba5b47e0d87928be92b97ba6","device":"3c7630b22a73c1fb","findings":[],"hash":"e9f93a5293e2434a29837f16b8a51d229a01e21b0cad2344f7593eb5370d34ab","nodeId":"2be1dfc4-d5a3-46d2-ab71-9ecc4d793e68","outcome":"completed","summary":"Committed. The vendored library is tracked as 30 regular files, with no submodule entries.\n\n**Delivered** a Foundry project implementing the brief, committed as `ca31a9b`.\n\n- **`src/OneEthCap.sol`**: accepts ETH through `receive()` or `deposit()`, keeps a lifetime `totalAccepted` counter, and reverts any deposit that would push it past exactly 1 ether. Zero-value deposits and any call with unknown calldata revert. No NFT or ERC-777 receiver hooks exist, so those transfers fail at the token. A permissionless `sweep()` pushes the balance to an immutable beneficiary, with state updated before the external call.\n- **`src/LaunchToken.sol`**: the required fixed-supply ERC-20, name OneEthCap, symbol ONECAP, 10^27 units minted to the deployer, no admin surface.\n- **Tests**: 33 tests pass, covering exact cap, cumulative cap, crossing the cap, one wei past full, lifetime behavior after sweep, unknown calldata, ERC-721/1155/777 hooks, rejecting beneficiary, reentrancy during sweep, forced ETH via selfdestruct, two fuzz tests, and an invariant suite checking the cap and conservation of funds. No test reads environment variables.\n- **Verification**: `forge build`, `forge test`, and `forge fmt --check` pass with the pinned solc 0.8.26, including from an empty environment. I also ran both protected floor tests from scratch against the real creation code, and all 8 passed.\n- **README** documents assumptions, the single deployment parameter (beneficiary, to be filled with `$owner`), operational responsibilities, and what the cap cannot cover.\n\nTwo design decisions to flag. The cap is interpreted as a lifetime total rather than a balance cap, so sweeping does not reopen room. The brief did not name a recipient for accepted ETH, so I added an immutable beneficiary with a permissionless sweep rather than locking funds forever. Forced ETH and plain ERC-20 transfers cannot be refused by any contract. The README states this and the independent adversarial review remains an open item.","treeHash":"237537b21b736c51917a49e9bd41727cf6d0da02","usage":{"cachedInputTokens":728500,"inputTokens":386,"model":"claude-fable-5-1","outputTokens":22432,"runtime":"claude","turns":27,"wallClockMs":270614}},{"artifacts":[],"attempt":1,"bundleHash":null,"device":"98b4506bef931d13","findings":[{"citation":"resolved","description":"Flow Gap, seam execution x periphery. `receive()` calls `_accept()`, which does a cold SLOAD of `totalAccepted` (2100 gas), an SSTORE (at least 2900 gas, 20000 on the first deposit) and a LOG2. That is far above the 2300 gas forwarded by Solidity's `payable(addr).transfer()` and `.send()`, so any contract (a Safe module, a splitter, an older payment contract) that pushes ETH with those primitives has its deposit reverted (`transfer`) or silently returns false (`send`), while an EOA or a `call{value:}` sender with the same amount is accepted. The README describes the entry point as 'plain transfer, empty calldata', which a Solidity author reads as `.transfer()`. No ETH is lost (the sender keeps it), and the lifetime cap is not weakened, which is why this is low. The rule 'the contract accepts ETH under 1 ether' is violated for one common class of senders. Fix options that preserve the design: document explicitly that depositors must use `call{value:}` or `deposit()` and that `.transfer()`/`.send()` are not supported, or (more invasive) accept that no storage can be written under a stipend and keep the current behaviour as a documented limitation. There is no way to count the deposit in `totalAccepted` within 2300 gas, so documenting is the realistic fix.","line":54,"path":"src/OneEthCap.sol","reproduction":"State: fresh OneEthCap, totalAccepted = 0, remaining() = 1 ether. Input: a contract S holding 0.1 ether executes `payable(address(cap)).transfer(0.1 ether)`. Expected (per README 'ETH arrives through receive() (plain transfer, empty calldata)'): accepted, totalAccepted = 0.1 ether. Actual: the inner call runs out of gas inside `_accept()` and the outer `transfer` reverts; totalAccepted stays 0 and cap balance stays 0. Same with `payable(address(cap)).send(0.1 ether)` which returns false. The warm case is the same: after one successful deposit via `call`, a second `call{value: 0.1 ether, gas: 2300}(\"\")` still fails. Verified with a scratch Foundry test: `vm.expectRevert(); s.sendViaTransfer{value: 0.1 ether}(payable(address(cap)));` passes and `assertFalse(s.sendViaSend{value: 0.1 ether}(payable(address(cap))))` passes.","severity":"low","snippet":"    receive() external payable {\n        _accept();\n    }","title":"receive() cannot complete within the 2300-gas stipend, so ETH pushed with transfer()/send() is refused even when room is available"},{"citation":"resolved","description":"Economic Security 'break dependencies': the only external dependency is `beneficiary`. It is set once in the constructor from the manifest's `$owner` and cannot change; there is no pull path, no refund path and no alternate recipient. If the policy owner address is a contract whose `receive`/`fallback` reverts, or an EOA later delegated (EIP-7702) to code that refuses ETH, `sweep()` reverts with `SweepFailed` on every call and all accepted ETH (up to 1 ether) plus any forced ETH is unrecoverable. Depositors have no claim on the funds by design, so the only victim is the beneficiary. This is reachable only through deployment configuration (privileged), not by an unprivileged actor, and the README documents it under 'Operational responsibilities'. Recorded as a trust assumption for the judge and the manifest reviewer, not as a defect: the `$owner` passed in launch.json must be an address verified to accept a plain ETH `call` with empty calldata.","line":79,"path":"src/OneEthCap.sol","reproduction":"State: `new OneEthCap(address(new RejectingBeneficiary()))` where RejectingBeneficiary's receive() reverts; alice deposits 0.1 ether. Input: anyone calls `sweep()`. Expected by the beneficiary: 0.1 ether delivered. Actual: `SweepFailed` revert, balance stays 0.1 ether, totalSwept stays 0, and no later call can change the outcome because `beneficiary` is immutable. This is exactly test_sweepRevertsWhenBeneficiaryRejects in test/OneEthCap.t.sol, which passes on the current tree.","severity":"info","snippet":"        (bool ok,) = beneficiary.call{value: amount}(\"\");\n        if (!ok) revert SweepFailed();","title":"Trust assumption: sweep() is a push payment to an immutable beneficiary, so a beneficiary that cannot receive ETH locks every deposit forever"}],"hash":"eea24a513d99a9900f40e2b90b6eb787f9dc2b0c4bffb8276d55a4d2784967cf","nodeId":"14cf1bf5-d0d8-433e-802d-2da1ba8380ae","outcome":"completed","summary":"The findings file is in place and ignored by git as intended, the scratch test is removed, and the tree is otherwise clean. Review complete.\n\n**Outcome:** `.imd-findings.json` holds 2 findings and 10 coverage rows covering all 7 listed entry points plus 3 invariants. No source file was changed. The existing suite passes offline (33 tests, including 3 invariants at 64 runs x depth 32).\n\n**Findings**\n\n- **Low, `receive()` at src/OneEthCap.sol:54.** The accept path does a cold storage read, a storage write and an event, so it cannot run inside the 2300-gas stipend. A contract that pushes ETH with `transfer()` reverts and one using `send()` gets `false`, even with room under the cap. No ETH is lost and the cap is not weakened, but the README's \"plain transfer\" wording promises a path that fails for that class of senders. Confirmed with a scratch test in both cold and warm storage states.\n- **Info, trust assumption at src/OneEthCap.sol:79.** `sweep()` is a push to an immutable beneficiary with no pull or fallback path. If the policy `$owner` address cannot receive ETH, every deposit is locked forever. Reachable only through deployment configuration, already documented and tested by the author, so recorded for the judge and manifest reviewer rather than as a defect.\n\n**What holds (traced, not just read)**\n\n- The lifetime cap has exactly one incrementing path, guarded in `_accept()`. Value sent to any non-payable selector or unknown calldata is refused, so nothing bypasses the counter except forced ETH, which is documented.\n- Conservation `balance + totalSwept == totalAccepted` survives reentrant sweep, a beneficiary that re-deposits and re-sweeps mid-callback, and a reverting beneficiary.\n- The slither strict-equality and aderyn unchecked-address leads are benign: the equality is an emptiness check and the beneficiary is non-zero by constructor.\n- No depositor claim exists, so there is no round-trip, sandwich, or griefing path that extracts value. Filling the cap costs the full 1 ETH and only enriches the beneficiary.\n\n**Not reached:** nothing within the assigned area. The LaunchToken rows were traced briefly as out-of-area and hold.","treeHash":null,"usage":{"cachedInputTokens":537816,"inputTokens":258,"model":"claude-fable-5-1","outputTokens":15036,"runtime":"claude","turns":23,"wallClockMs":230006}},{"artifacts":[],"attempt":1,"bundleHash":null,"device":"bb0a3bf63233e5e5","findings":[],"hash":"fcd362670cb908ccf64a02a4329b307468b5fe433e9986ff45fa7973a6a5f87f","nodeId":"37f66980-a027-497d-bda3-4d3e01681272","outcome":"completed","summary":"Wrote [.imd-findings.json](/home/imd-worker/.identitymd/work/a017ded9-6a66-48aa-973e-1c54bc56792a/37f66980-a027-497d-bda3-4d3e01681272/.imd-findings.json) with no substantiated defects and coverage for all seven entry points.\n\nValidation: 33 project tests and eight protected checks passed. Protected checks used synthetic deployment inputs. Source and configuration files remain unchanged.","treeHash":null,"usage":{"cachedInputTokens":762880,"inputTokens":73083,"model":"gpt-6-astra","outputTokens":6893,"runtime":"codex","turns":5,"wallClockMs":260912}}],"verification":[{"checks":[{"durationMs":5017,"exitCode":0,"name":"build","output":"Compiling 26 files with Solc 0.8.26\nSolc 0.8.26 finished in 4.48s\nCompiler run successful with warnings:\nWarning (5159): \"selfdestruct\" has been deprecated. Note that, starting from the Cancun hard fork, the underlying opcode no longer deletes the code and data associated with an account and only transfers its Ether to the beneficiary, unless executed in the same transaction in which the contract was created (see EIP-6780). Any use in newly deployed contracts is strongly discouraged even if the new behavior is taken into account. Future changes to the EVM might further reduce the functionality of the opcode.\n  --> test/OneEthCap.t.sol:64:9:\n   |\n64 |         selfdestruct(target);\n   |         ^^^^^^^^^^^^\n\n","passed":true},{"durationMs":809,"exitCode":0,"name":"test","output":"No files changed, compilation skipped\n\nRan 9 tests for test/LaunchToken.t.sol:LaunchTokenTest\n[PASS] testFuzz_transferConservesSupply(address,uint256) (runs: 256, μ: 80847, ~: 80883)\nLogs:\n  Bound result 332615659497969427734777937\n\n[PASS] test_approveAndTransferFrom() (gas: 194267)\n[PASS] test_fixedSupplyMintedToDeployer() (gas: 29143)\n[PASS] test_infiniteAllowanceIsNotDecremented() (gas: 122105)\n[PASS] test_metadata() (gas: 26725)\n[PASS] test_noMintOrAdminSurface() (gas: 154328)\n[PASS] test_transferMovesExactAmount() (gas: 92945)\n[PASS] test_transferRevertsOnInsufficientBalance() (gas: 37447)\n[PASS] test_transferRevertsToZeroAddress() (gas: 29923)\nSuite result: ok. 9 passed; 0 failed; 0 skipped; finished in 19.30ms (35.51ms CPU time)\n\nRan 23 tests for test/OneEthCap.t.sol:OneEthCapTest\n[PASS] testFuzz_depositSucceedsIffItFits(uint256,uint256) (runs: 256, μ: 112231, ~: 113127)\nLogs:\n  Bound result 6\n  Bound result 750000000000000000\n\n[PASS] testFuzz_totalAcceptedNeverExceedsCap(uint96[8]) (runs: 256, μ: 425628, ~: 427904)\nLogs:\n  Bound result 4425\n  Bound result 19635\n  Bound result 19487\n  Bound result 13041\n  Bound result 12923\n  Bound result 122\n  Bound result 42\n  Bound result 17080\n\n[PASS] test_acceptsExactlyOneEthAcrossDeposits() (gas: 111335)\n[PASS] test_acceptsExactlyOneEthInOneDeposit() (gas: 78476)\n[PASS] test_capIsLifetimeNotBalance() (gas: 182801)\n[PASS] test_constructorRejectsZeroBeneficiary() (gas: 3836)\n[PASS] test_constructorSetsBeneficiary() (gas: 39435)\n[PASS] test_deployScriptWiresConstructor() (gas: 1427465)\n[PASS] test_depositAcceptsEth() (gas: 73301)\n[PASS] test_fallbackRejectsUnknownCalldata() (gas: 71226)\n[PASS] test_forcedEthDoesNotCountTowardCapButIsSwept() (gas: 281131)\n[PASS] test_receiveAcceptsPlainTransfer() (gas: 85954)\n[PASS] test_rejectsDepositThatWouldCrossCap() (gas: 153636)\n[PASS] test_rejectsErc1155ReceiverHook() (gas: 33117)\n[PASS] test_rejectsErc721SafeTransfer() (gas: 370239)\n[PASS] test_rejectsErc777TokensReceivedHook() (gas: 33582)\n[PASS] test_rejectsEvenOneWeiOnceFull() (gas: 127790)\n[PASS] test_rejectsSingleDepositOverCap() (gas: 52266)\n[PASS] test_rejectsZeroValue() (gas: 54539)\n[PASS] test_sweepPushesWholeBalanceToBeneficiary() (gas: 166104)\n[PASS] test_sweepReentrancyGainsNothing() (gas: 400372)\n[PASS] test_sweepRevertsWhenBeneficiaryRejects() (gas: 221711)\n[PASS] test_sweepRevertsWhenEmpty() (gas: 29568)\nSuite result: ok. 23 passed; 0 failed; 0 skipped; finished in 57.47ms (100.83ms CPU time)\n\nRan 1 test for test/OneEthCap.invariant.t.sol:OneEthCapInvariantTest\n[PASS]\nOneEthCapInvariantTest invariants:\n[PASS] invariant_fundsAreConserved\n[PASS] invariant_ledgerMatchesGhost\n[PASS] invariant_totalAcceptedNeverExceedsCap\n OneEthCapInvariantTest invariants (runs: 64, calls: 2048, reverts: 0)\n\n╭------------+------------+-------+---------+----------╮\n| Contract   | Selector   | Calls | Reverts | Discards |\n+======================================================+\n| CapHandler | depositVia | 1068  | 0       | 0        |\n|------------+------------+-------+---------+----------|\n| CapHandler | sweep      | 980   | 0       | 0        |\n╰------------+------------+-------+---------+----------╯\n\nLogs:\n  Bound result 27\n  Bound result 999999999999999994\n  Bound result 300\n  Bound result 2\n  Bound result 4047\n  Bound result 3933\n  Bound result 999999999333333334\n  Bound result 1500000000000000000\n  Bound result 710\n  Bound result 1500000000000000000\n  Bound result 1161337468427144938\n  Bound result 999999999333341644\n  Bound result 575215677199611228\n  Bound result 1385\n  Bound result 500\n  Bound result 3829\n  Bound result 8\n  Bound result 1500000000000000000\n  Bound result 2573344818\n  Bound result 13721941326284898\n  Bound result 1500000000000000000\n\nSuite result: ok. 1 passed; 0 failed; 0 skipped; finished in 303.78ms (297.96ms CPU time)\n\nRan 3 test suites in 308.42ms (380.55ms CPU time): 33 tests passed, 0 failed, 0 skipped (33 total tests)\n","passed":true},{"durationMs":201,"exitCode":0,"name":"source-index","output":"{\"v\":1,\"entryPoints\":[\"LaunchToken.approve(address,uint256)\",\"LaunchToken.transfer(address,uint256)\",\"LaunchToken.transferFrom(address,address,uint256)\",\"OneEthCap.deposit()\",\"OneEthCap.fallback()\",\"OneEthCap.receive()\",\"OneEthCap.sweep()\"],\"files\":{\".gitignore\":4,\"README.md\":123,\"foundry.toml\":24,\"launch.json\":22,\"remappings.txt\":1,\"script/Deploy.s.sol\":24,\"src/LaunchToken.sol\":75,\"src/OneEthCap.sol\":91,\"test/LaunchToken.t.sol\":94,\"test/OneEthCap.invariant.t.sol\":70,\"test/OneEthCap.t.sol\":345},\"excluded\":[\"lib/\",\"node_modules/\"],\"truncated\":false}","passed":true}],"detail":"all checks passed","evaluation":"checks","profile":"foundry","status":"accepted","submissionHash":"28500319df8883ce55e227167600c1b2660a6cc1bcb6e5c0a6104097b6540c69","verifiedTreeHash":"002ee8b61f0405c4a847300bdafa62c3f35a6d7c","verifierVersion":"0.1.0+da6bdbe5"},{"checks":[{"durationMs":1957,"exitCode":0,"name":"build","output":"Compiling 28 files with Solc 0.8.26\nSolc 0.8.26 finished in 1.83s\nCompiler run successful with warnings:\nWarning (5159): \"selfdestruct\" has been deprecated. Note that, starting from the Cancun hard fork, the underlying opcode no longer deletes the code and data associated with an account and only transfers its Ether to the beneficiary, unless executed in the same transaction in which the contract was created (see EIP-6780). Any use in newly deployed contracts is strongly discouraged even if the new behavior is taken into account. Future changes to the EVM might further reduce the functionality of the opcode.\n  --> test/OneEthCap.invariant.t.sol:22:9:\n   |\n22 |         selfdestruct(target);\n   |         ^^^^^^^^^^^^\n\nWarning (5159): \"selfdestruct\" has been deprecated. Note that, starting from the Cancun hard fork, the underlying opcode no longer deletes the code and data associated with an account and only transfers its Ether to the beneficiary, unless executed in the same transaction in which the contract was created (see EIP-6780). Any use in newly deployed contracts is strongly discouraged even if the new behavior is taken into account. Future changes to the EVM might further reduce the functionality of the opcode.\n  --> test/OneEthCap.t.sol:64:9:\n   |\n64 |         selfdestruct(target);\n   |         ^^^^^^^^^^^^\n\n","passed":true},{"durationMs":4692,"exitCode":0,"name":"test","output":"No files changed, compilation skipped\n\nRan 9 tests for test/LaunchToken.t.sol:LaunchTokenTest\n[PASS] testFuzz_transferConservesSupply(address,uint256) (runs: 256, μ: 80707, ~: 80847)\nLogs:\n  Bound result 465\n\n[PASS] test_approveAndTransferFrom() (gas: 194267)\n[PASS] test_fixedSupplyMintedToDeployer() (gas: 29143)\n[PASS] test_infiniteAllowanceIsNotDecremented() (gas: 122105)\n[PASS] test_metadata() (gas: 26725)\n[PASS] test_noMintOrAdminSurface() (gas: 154328)\n[PASS] test_transferMovesExactAmount() (gas: 92945)\n[PASS] test_transferRevertsOnInsufficientBalance() (gas: 37447)\n[PASS] test_transferRevertsToZeroAddress() (gas: 29923)\nSuite result: ok. 9 passed; 0 failed; 0 skipped; finished in 77.08ms (20.10ms CPU time)\n\nRan 23 tests for test/OneEthCap.t.sol:OneEthCapTest\n[PASS] testFuzz_depositSucceedsIffItFits(uint256,uint256) (runs: 256, μ: 112419, ~: 113127)\nLogs:\n  Bound result 1\n  Bound result 600000000000000000\n\n[PASS] testFuzz_totalAcceptedNeverExceedsCap(uint96[8]) (runs: 256, μ: 426519, ~: 429272)\nLogs:\n  Bound result 703\n  Bound result 46\n  Bound result 14940\n  Bound result 13523\n  Bound result 12591\n  Bound result 11005\n  Bound result 206\n  Bound result 10416\n\n[PASS] test_acceptsExactlyOneEthAcrossDeposits() (gas: 111335)\n[PASS] test_acceptsExactlyOneEthInOneDeposit() (gas: 78476)\n[PASS] test_capIsLifetimeNotBalance() (gas: 182801)\n[PASS] test_constructorRejectsZeroBeneficiary() (gas: 3836)\n[PASS] test_constructorSetsBeneficiary() (gas: 39435)\n[PASS] test_deployScriptWiresConstructor() (gas: 1427465)\n[PASS] test_depositAcceptsEth() (gas: 73301)\n[PASS] test_fallbackRejectsUnknownCalldata() (gas: 71226)\n[PASS] test_forcedEthDoesNotCountTowardCapButIsSwept() (gas: 281131)\n[PASS] test_receiveAcceptsPlainTransfer() (gas: 85954)\n[PASS] test_rejectsDepositThatWouldCrossCap() (gas: 153636)\n[PASS] test_rejectsErc1155ReceiverHook() (gas: 33117)\n[PASS] test_rejectsErc721SafeTransfer() (gas: 370239)\n[PASS] test_rejectsErc777TokensReceivedHook() (gas: 33582)\n[PASS] test_rejectsEvenOneWeiOnceFull() (gas: 127790)\n[PASS] test_rejectsSingleDepositOverCap() (gas: 52266)\n[PASS] test_rejectsZeroValue() (gas: 54539)\n[PASS] test_sweepPushesWholeBalanceToBeneficiary() (gas: 166104)\n[PASS] test_sweepReentrancyGainsNothing() (gas: 400372)\n[PASS] test_sweepRevertsWhenBeneficiaryRejects() (gas: 221711)\n[PASS] test_sweepRevertsWhenEmpty() (gas: 29568)\nSuite result: ok. 23 passed; 0 failed; 0 skipped; finished in 79.51ms (100.70ms CPU time)\n\nRan 7 tests for test/OneEthCap.adversarial.t.sol:OneEthCapAdversarialTest\n[PASS] testFuzz_callbackRedepositAndNestedSweepConserveFunds(uint256,uint256,bool) (runs: 1000, μ: 784110, ~: 778238)\nLogs:\n  Bound result 78240\n  Bound result 59826\n\n[PASS] testFuzz_receiveOverCapRollsBackAndRemainingCanStillBeFilled(uint256,uint256,bool) (runs: 1000, μ: 307522, ~: 326988)\nLogs:\n  Bound result 78240\n  Bound result 241852798645799026\n\n[PASS] testFuzz_shortCalldataRejectsAndRefunds(uint24,uint8,uint256) (runs: 1000, μ: 128687, ~: 128725)\nLogs:\n  Bound result 2\n  Bound result 2000000000000000000\n\n[PASS] test_callbackCannotReopenLifetimeCapDuringSweep() (gas: 639539)\n[PASS] test_maximumValueIsRejectedWithoutArithmeticPanic() (gas: 101774)\n[PASS] test_nonpayableFunctionsRejectEthWithoutChangingState() (gas: 574915)\n[PASS] test_revertingBeneficiaryRollsBackNestedDepositAndSweepThenCanRetry() (gas: 901453)\nSuite result: ok. 7 passed; 0 failed; 0 skipped; finished in 91.11ms (161.25ms CPU time)\n\nRan 11 tests for test/LaunchToken.properties.t.sol:LaunchTokenPropertiesTest\n[PASS] testFuzz_approvalReplacesPreviousValueAndCanBeRevoked(uint256,uint256) (runs: 1000, μ: 184905, ~: 184998)\n[PASS] testFuzz_delegatedSelfTransferOnlySpendsAllowance(uint256) (runs: 1000, μ: 113141, ~: 113254)\nLogs:\n  Bound result 478558389857862390022916287\n\n[PASS] testFuzz_failedBalanceCheckRestoresSpentAllowance(uint256,uint256) (runs: 1000, μ: 192830, ~: 193080)\nLogs:\n  Bound result 10198\n  Bound result 2\n\n[PASS] testFuzz_finiteAllowanceCannotBeSpentTwice(uint256,uint256) (runs: 1000, μ: 173935, ~: 176141)\nLogs:\n  Bound result 999999999999999999999999998\n  Bound result 156981073560947757979160266\n\n[PASS] testFuzz_selfTransferPreservesBalance(uint256) (runs: 1000, μ: 52755, ~: 52479)\nLogs:\n  Bound result 478558389857862390022916287\n\n[PASS] testFuzz_zeroRecipientRestoresSpentAllowance(uint256) (runs: 1000, μ: 115964, ~: 116177)\nLogs:\n  Bound result 478558389857862390022916287\n\n[PASS] test_approveZeroAddressReverts() (gas: 47874)\n[PASS] test_maximumTransferAmountRevertsWithoutChangingBalances() (gas: 50298)\n[PASS] test_nativeEthAndValueAttachedToTokenCallsRevert() (gas: 72670)\n[PASS] test_zeroTransferNeedsNoBalanceOrAllowance() (gas: 108988)\n[PASS] test_zeroTransferToZeroAddressReverts() (gas: 47282)\nSuite result: ok. 11 passed; 0 failed; 0 skipped; finished in 91.76ms (507.85ms CPU time)\n\nRan 2 tests for test/OneEthCap.invariant.t.sol:OneEthCapInvariantTest\n[PASS]\nOneEthCapInvariantTest invariants:\n[PASS] invariant_fundsAreConserved\n[PASS] invariant_ledgerMatchesGhost\n[PASS] invariant_onlyDepositorsPayAndOnlyBeneficiaryReceives\n[PASS] invariant_totalAcceptedNeverExceedsCap\n OneEthCapInvariantTest invariants (runs: 256, calls: 16384, reverts: 0)\n\n╭------------+-------------------+-------+---------+----------╮\n| Contract   | Selector          | Calls | Reverts | Discards |\n+=============================================================+\n| CapHandler | depositAboveRoom  | 2668  | 0       | 0        |\n|------------+-------------------+-------+---------+----------|\n| CapHandler | depositVia        | 2767  | 0       | 0        |\n|------------+-------------------+-------+---------+----------|\n| CapHandler | depositWithinRoom | 2817  | 0       | 0        |\n|------------+-------------------+-------+---------+----------|\n| CapHandler | forceEth          | 2744  | 0       | 0        |\n|------------+-------------------+-------+---------+----------|\n| CapHandler | rejectCalldata    | 2697  | 0       | 0        |\n|------------+-------------------+-------+---------+----------|\n| CapHandler | sweep             | 2691  | 0       | 0        |\n╰------------+-------------------+-------+---------+----------╯\n\nLogs:\n  Bound result 4131\n  Bound result 1000000000000000000\n  Bound result 400000000000000000\n  Bound result 690\n  Bound result 3035\n  Bound result 6\n  Bound result 1234\n  Bound result 582\n  Bound result 3\n  Bound result 700000000000000000\n  Bound result 357797487616449885\n  Bound result 1272000000000\n  Bound result 50994276462768284\n  Bound result 524212229617247324\n  Bound result 13\n  Bound result 500\n  Bound result 618985450663604108\n  Bound result 6\n  Bound result 200\n  Bound result 2\n  Bound result 20929347247793523\n  Bound result 191\n  Bound result 250000000000000000\n  Bound result 2489\n  Bound result 5\n  Bound result 8\n  Bound result 3\n  Bound result 500\n  Bound result 300\n  Bound result 2643\n  Bound result 48172274787146390\n  Bound result 10036\n  Bound result 237626075703965187\n  Bound result 8265\n  Bound result 8\n  Bound result 1999999999999999996\n  Bound result 3579\n  Bound result 673\n  Bound result 906\n  Bound result 7186\n  Bound result 200000000000000000\n  Bound result 1781412264647553430\n  Bound result 72731039122523731\n  Bound result 201567320040\n  Bound result 258731318\n  Bound result 784\n  Bound result 3\n  Bound result 236358412935981649\n  Bound result 870\n  Bound result 4538\n  Bound result 200000000000000000\n  Bound result 660\n  Bound result 602\n  Bound result 27\n  Bound result 7828\n  Bound result 41232\n  Bound result 6349\n  Bound result 8460\n\n[PASS] test_handlerExercisesFundingRejectionAndLifetimeClosure() (gas: 1268084)\nLogs:\n  Bound result 0\n  Bound result 400000000000000000\n  Bound result 1\n  Bound result 1\n  Bound result 2000000000000000000\n  Bound result 600000000000000000\n\nSuite result: ok. 2 passed; 0 failed; 0 skipped; finished in 1.96s (1.96s CPU time)\n\nRan 1 test for test/LaunchToken.properties.t.sol:LaunchTokenLedgerInvariantTest\n[PASS]\nLaunchTokenLedgerInvariantTest invariants:\n[PASS] invariant_allowancesMatchApprovalsAndSuccessfulSpending\n[PASS] invariant_fixedSupplyIsConservedAndBalancesMatchLedger\n LaunchTokenLedgerInvariantTest invariants (runs: 256, calls: 16384, reverts: 0)\n\n╭--------------------------+-----------------------+-------+---------+----------╮\n| Contract                 | Selector              | Calls | Reverts | Discards |\n+===============================================================================+\n| LaunchTokenLedgerHandler | approve               | 2769  | 0       | 0        |\n|--------------------------+-----------------------+-------+---------+----------|\n| LaunchTokenLedgerHandler | rejectOverspend       | 2739  | 0       | 0        |\n|--------------------------+-----------------------+-------+---------+----------|\n| LaunchTokenLedgerHandler | rejectZeroRecipient   | 2690  | 0       | 0        |\n|--------------------------+-----------------------+-------+---------+----------|\n| LaunchTokenLedgerHandler | revokeThenRejectSpend | 2767  | 0       | 0        |\n|--------------------------+-----------------------+-------+---------+----------|\n| LaunchTokenLedgerHandler | transfer              | 2711  | 0       | 0        |\n|--------------------------+-----------------------+-------+---------+----------|\n| LaunchTokenLedgerHandler | transferFrom          | 2708  | 0       | 0        |\n╰--------------------------+-----------------------+-------+---------+----------╯\n\nLogs:\n  Bound result 5014\n  Bound result 1939\n  Bound result 0\n  Bound result 2866\n  Bound result 5\n  Bound result 1239446558\n  Bound result 750000000000000000\n  Bound result 170873946552475482082610667\n  Bound result 0\n  Bound result 59242069111418418682813271\n  Bound result 604\n  Bound result 2\n  Bound result 1219\n  Bound result 3\n  Bound result 5146\n  Bound result 8019\n  Bound result 2000000000000000000\n  Bound result 4500\n  Bound result 5\n  Bound result 1199\n  Bound result 500000000000000000\n  Bound result 5978\n  Bound result 27089331092587313515136665\n  Bound result 500\n  Bound result 2499\n  Bound result 1000000000000000000000\n  Bound result 10000000000000000000\n  Bound result 0\n  Bound result 0\n  Bound result 124227960933814613523651326\n  Bound result 700000000000000000\n  Bound result 0\n  Bound result 3\n  Bound result 0\n  Bound result 340\n  Bound result 500000000000000000\n  Bound result 47498060951357699094979640\n  Bound result 700000000000000000\n  Bound result 2\n  Bound result 1234\n  Bound result 5763\n  Bound result 802\n  Bound result 970\n  Bound result 400000000000000000\n  Bound result 750000000000000000\n  Bound result 8019\n  Bound result 799999999999997874\n  Bound result 88303035\n  Bound result 4775\n  Bound result 100000000000000000\n  Bound result 705\n  Bound result 5620\n  Bound result 2\n  Bound result 1290\n  Bound result 10000000000000000000\n\nSuite result: ok. 1 passed; 0 failed; 0 skipped; finished in 4.60s (4.60s CPU time)\n\nRan 6 test suites in 4.60s (6.90s CPU time): 53 tests passed, 0 failed, 0 skipped (53 total tests)\n","passed":true},{"durationMs":50,"exitCode":0,"name":"source-index","output":"{\"v\":1,\"entryPoints\":[\"LaunchToken.approve(address,uint256)\",\"LaunchToken.transfer(address,uint256)\",\"LaunchToken.transferFrom(address,address,uint256)\",\"OneEthCap.deposit()\",\"OneEthCap.fallback()\",\"OneEthCap.receive()\",\"OneEthCap.sweep()\"],\"files\":{\".gitignore\":4,\"README.md\":123,\"foundry.toml\":24,\"remappings.txt\":1,\"script/Deploy.s.sol\":24,\"src/LaunchToken.sol\":75,\"src/OneEthCap.sol\":91,\"test/LaunchToken.properties.t.sol\":268,\"test/LaunchToken.t.sol\":94,\"test/OneEthCap.adversarial.t.sol\":242,\"test/OneEthCap.invariant.t.sol\":241,\"test/OneEthCap.t.sol\":345},\"excluded\":[\"lib/\",\"node_modules/\"],\"truncated\":false}","passed":true}],"detail":"all checks passed","evaluation":"checks","profile":"foundry","status":"accepted","submissionHash":"792503f71221950663430d26154d754b875742e518f3082927341d3d674d9272","verifiedTreeHash":"59193fb7bb9b539e465992012b1287847a9dbe6d","verifierVersion":"0.1.0+da6bdbe5"},{"checks":[{"durationMs":1885,"exitCode":0,"name":"build","output":"Compiling 26 files with Solc 0.8.26\nSolc 0.8.26 finished in 1.65s\nCompiler run successful with warnings:\nWarning (5159): \"selfdestruct\" has been deprecated. Note that, starting from the Cancun hard fork, the underlying opcode no longer deletes the code and data associated with an account and only transfers its Ether to the beneficiary, unless executed in the same transaction in which the contract was created (see EIP-6780). Any use in newly deployed contracts is strongly discouraged even if the new behavior is taken into account. Future changes to the EVM might further reduce the functionality of the opcode.\n  --> test/OneEthCap.t.sol:64:9:\n   |\n64 |         selfdestruct(target);\n   |         ^^^^^^^^^^^^\n\n","passed":true},{"durationMs":340,"exitCode":0,"name":"test","output":"No files changed, compilation skipped\n\nRan 9 tests for test/LaunchToken.t.sol:LaunchTokenTest\n[PASS] testFuzz_transferConservesSupply(address,uint256) (runs: 256, μ: 80636, ~: 80895)\nLogs:\n  Bound result 96594767508673818340332432\n\n[PASS] test_approveAndTransferFrom() (gas: 194267)\n[PASS] test_fixedSupplyMintedToDeployer() (gas: 29143)\n[PASS] test_infiniteAllowanceIsNotDecremented() (gas: 122105)\n[PASS] test_metadata() (gas: 26725)\n[PASS] test_noMintOrAdminSurface() (gas: 154328)\n[PASS] test_transferMovesExactAmount() (gas: 92945)\n[PASS] test_transferRevertsOnInsufficientBalance() (gas: 37447)\n[PASS] test_transferRevertsToZeroAddress() (gas: 29923)\nSuite result: ok. 9 passed; 0 failed; 0 skipped; finished in 44.85ms (26.19ms CPU time)\n\nRan 23 tests for test/OneEthCap.t.sol:OneEthCapTest\n[PASS] testFuzz_depositSucceedsIffItFits(uint256,uint256) (runs: 256, μ: 112316, ~: 113127)\nLogs:\n  Bound result 300\n  Bound result 400000000000000000\n\n[PASS] testFuzz_totalAcceptedNeverExceedsCap(uint96[8]) (runs: 256, μ: 426076, ~: 429272)\nLogs:\n  Bound result 721262266865365155\n  Bound result 47\n  Bound result 1818876846132716792\n  Bound result 1174752111790360738\n  Bound result 1591196775782693738\n  Bound result 1562791410158775834\n  Bound result 245\n  Bound result 1530872706271653656\n\n[PASS] test_acceptsExactlyOneEthAcrossDeposits() (gas: 111335)\n[PASS] test_acceptsExactlyOneEthInOneDeposit() (gas: 78476)\n[PASS] test_capIsLifetimeNotBalance() (gas: 182801)\n[PASS] test_constructorRejectsZeroBeneficiary() (gas: 3836)\n[PASS] test_constructorSetsBeneficiary() (gas: 39435)\n[PASS] test_deployScriptWiresConstructor() (gas: 1427465)\n[PASS] test_depositAcceptsEth() (gas: 73301)\n[PASS] test_fallbackRejectsUnknownCalldata() (gas: 71226)\n[PASS] test_forcedEthDoesNotCountTowardCapButIsSwept() (gas: 281131)\n[PASS] test_receiveAcceptsPlainTransfer() (gas: 85954)\n[PASS] test_rejectsDepositThatWouldCrossCap() (gas: 153636)\n[PASS] test_rejectsErc1155ReceiverHook() (gas: 33117)\n[PASS] test_rejectsErc721SafeTransfer() (gas: 370239)\n[PASS] test_rejectsErc777TokensReceivedHook() (gas: 33582)\n[PASS] test_rejectsEvenOneWeiOnceFull() (gas: 127790)\n[PASS] test_rejectsSingleDepositOverCap() (gas: 52266)\n[PASS] test_rejectsZeroValue() (gas: 54539)\n[PASS] test_sweepPushesWholeBalanceToBeneficiary() (gas: 166104)\n[PASS] test_sweepReentrancyGainsNothing() (gas: 400372)\n[PASS] test_sweepRevertsWhenBeneficiaryRejects() (gas: 221711)\n[PASS] test_sweepRevertsWhenEmpty() (gas: 29568)\nSuite result: ok. 23 passed; 0 failed; 0 skipped; finished in 45.06ms (56.74ms CPU time)\n\nRan 1 test for test/OneEthCap.invariant.t.sol:OneEthCapInvariantTest\n[PASS]\nOneEthCapInvariantTest invariants:\n[PASS] invariant_fundsAreConserved\n[PASS] invariant_ledgerMatchesGhost\n[PASS] invariant_totalAcceptedNeverExceedsCap\n OneEthCapInvariantTest invariants (runs: 64, calls: 2048, reverts: 0)\n\n╭------------+------------+-------+---------+----------╮\n| Contract   | Selector   | Calls | Reverts | Discards |\n+======================================================+\n| CapHandler | depositVia | 1040  | 0       | 0        |\n|------------+------------+-------+---------+----------|\n| CapHandler | sweep      | 1008  | 0       | 0        |\n╰------------+------------+-------+---------+----------╯\n\nLogs:\n  Bound result 3\n  Bound result 2351\n  Bound result 88\n  Bound result 18\n  Bound result 869428951760045535\n  Bound result 400000000000000000\n  Bound result 19\n  Bound result 1499999999999999999\n  Bound result 6\n  Bound result 300\n  Bound result 600000000000000000\n  Bound result 3006009240033\n\nSuite result: ok. 1 passed; 0 failed; 0 skipped; finished in 202.05ms (180.07ms CPU time)\n\nRan 3 test suites in 210.81ms (291.97ms CPU time): 33 tests passed, 0 failed, 0 skipped (33 total tests)\n","passed":true},{"durationMs":64,"exitCode":0,"name":"source-index","output":"{\"v\":1,\"entryPoints\":[\"LaunchToken.approve(address,uint256)\",\"LaunchToken.transfer(address,uint256)\",\"LaunchToken.transferFrom(address,address,uint256)\",\"OneEthCap.deposit()\",\"OneEthCap.fallback()\",\"OneEthCap.receive()\",\"OneEthCap.sweep()\"],\"files\":{\".gitignore\":4,\"README.md\":123,\"foundry.toml\":24,\"remappings.txt\":1,\"script/Deploy.s.sol\":24,\"src/LaunchToken.sol\":75,\"src/OneEthCap.sol\":91,\"test/LaunchToken.t.sol\":94,\"test/OneEthCap.invariant.t.sol\":70,\"test/OneEthCap.t.sol\":345},\"excluded\":[\"lib/\",\"node_modules/\"],\"truncated\":false}","passed":true},{"durationMs":1193,"exitCode":0,"name":"slither","output":"[medium/high] incorrect-equality at src/OneEthCap.sol:74: OneEthCap.sweep() (src/OneEthCap.sol#74-81) uses a dangerous strict equality:","passed":true},{"durationMs":880,"exitCode":0,"name":"aderyn","output":"[high] eth-send-unchecked-address at src/OneEthCap.sol:74: ETH transferred without address checks\n[low] large-numeric-literal at src/LaunchToken.sol:17: Large Numeric Literal\n[low] unused-public-function at src/OneEthCap.sol:69: Public Function Not Used Internally","passed":true}],"detail":"all checks passed","evaluation":"checks","profile":"foundry","status":"accepted","submissionHash":"e9f93a5293e2434a29837f16b8a51d229a01e21b0cad2344f7593eb5370d34ab","verifiedTreeHash":"237537b21b736c51917a49e9bd41727cf6d0da02","verifierVersion":"0.1.0+da6bdbe5"}]}