Planning job

4cf799e1Blocked
the whole request

Retest the complete swarm by building and launching VolatilityGuard Lab on Sepolia: VolatilityGuardHook, VolatilityGuardToken, independent adversarial review, verified factory deployment with a seeded pool, then a working public swap dapp with explanatory information. Publish real source, receipts, test evidence and the live site.

Hook: per-PoolId isolation; bounded observation ring/TWAP and EWMA volatility; adaptive price-deviation limits; rolling volume budget resistant to split swaps; NORMAL/WARMUP/GUARDED/RECOVERY states, stale/low-liquidity handling and deterministic recovery. Authenticate canonical PoolManager callbacks/accounting, never trust sender/hookData identity. Specify both swap directions and exact-input/output, units/rounding, bounded execution and caps. Keep LP exits possible and initialization/warmup non-bricking. Reverts cannot persist breaker transitions. No discretionary admin powers or claim of total MEV protection. Support arbitrary currencies.

VGL: Volatility Guard Lab, 18 decimals, no constructor args, fixed 10^27 units minted to deployer, no mint backdoor. Native ETH pair (zero address), static fee 3000, tickSpacing 60; initial sqrtPriceX96 792281625142643375935439503360000 (0.00000001 ETH/VGL). Verify Sepolia PoolManager 0xe03a1074c86cfedd5c142c4f04f1a1536e203543. Use only existing verified periphery, no new deployed helper. Workers never receive keys or broadcast deployments.

Deliver pinned/vendored Foundry project, bytecode_hash=none, offline build/test/fmt checks, fuzz/invariant/stress tests for accounting, isolation, manipulation/split volume, unauthorized callbacks, reentrancy, stale history, edge values, recovery and LP exits; report actual counts, gas, failures and limitations. Independent reviewer checks code AND launch manifest; repair blocking findings before deployment. Export ABI JSON and architecture/threat-model/integration docs with exact pool key, quote/swap/liquidity recipes and decoded errors.

After verified deployment handoff, build React/Vite/TypeScript + RainbowKit/wagmi/viem in web/, committed relative-base export in dist/. Include hook explanation, risk/limitation information and live pool dashboard (tick/TWAP, volatility, deviation, volume/state/events). Primary ETH/VGL swap UI: amounts, direction, balances/max, real quotes, slippage/minimum received, approvals and wallet-signed swaps, transaction states/errors/explorer links. Support injected wallets without extra credentials. Handle token-sided bootstrap: buy with ETH first; reverse trades depend on accrued ETH liquidity. No fabricated quotes or receipts. Add supported-position exits and clearly labeled simulation demos. Test both directions, wallet/chain states, rejected signing, guard reverts, funds/RPC errors and responsive UI. Complete only when contracts are live, source published and the functional IPFS dapp is reachable.

Context and requirements

Resolved operator settings, not planner choices: Sepolia univ4_hook policy v2.

All token/hookAdmin/treasury/LP owners: 0x09ec38170e94532eddb57c69dfc4f1fdcd0d4a60; no extra admin behavior.

Supply splits: 80% LP, 10% treasury, 10% contributors (1h lock, 30% per-wallet cap). Factory seeds up to 8e26 VGL units, ZERO ETH: deployer derives widest aligned token-only range from opening price/spacing and rounds liquidity down. Gas from configured deployer under existing 0.3 Sepolia ETH ceiling; no additional funding or spending authority.

GitHub destination is the existing signed publisher's configured org with automatic launch repository naming; IPFS uses its configured Pinata service and automatic naming. No caller repo/CID needed; both services are online. Contracts/tests -> auto manifest + independent review -> verified deployment -> frontend-for-contract -> publication.

Max five proposed steps; manifest adds sixth. DeFi references are background, not separate research. Never mainnet.

planner instructions · round 1

Read .imd/reads/planning.json and propose the requested workflow in artifacts/plan.json. Do not implement or dispatch the proposed work.

The workflow is blocked. Finishing a planning assignment does not submit its proposed execution jobs.

  • Shared interfaces are not established with enough confidence.
  • Required dependencies are not established with enough confidence.

Proposed workflow

5 step(s) · round 1

This proposal must pass workflow and requirement checks before it can become an execution job.

Sequential workflow.

Contract handoff: abi/VolatilityGuardHook.json and abi/VolatilityGuardToken.json, docs/integration.md defining typed reads/events, units, rounding, decoded errors and canonical periphery quote/swap/exit recipes. Live dashboard reads expose per-PoolId tick/TWAP, EWMA volatility, adaptive deviation limit, rolling volume, state and history freshness.

Frontend consumes these actual ABIs and the verified deployment handoff: chainId, addresses, runtime verification, pool key/id, start block, seeded position and real transaction receipts. No invented addresses. Mocks implement the documented ABI/errors and wallet lifecycle, remain labeled simulation/test fixtures, and never supply production quotes, receipts or dashboard success.

Dependencies need actual outputs. Control plane adds the sole integrate-role launch manifest (sixth assignment); do not add integrate-project. Review both code and manifest, regenerate/review manifest after fixes, and block deployment until findings are closed.

Only authorized services deploy/publish: Sepolia 11155111, existing signed publisher configured GitHub org with automatic repository naming, configured Pinata with automatic naming. Workers never receive keys or broadcast. Verified factory deployment precedes frontend execution; final frontend acceptance joins all actual outputs and service publication evidence.

No new destination, funding, mainnet, helper deployment or discretionary admin authority.

1. contracts and testsbuild contract project

Can start without another proposed step.

Implement and test VolatilityGuardHook and VolatilityGuardToken as a complete Foundry deliverable using the accepted pinned/vendored dependencies and configuration, bytecode_hash=none. Do not rewrite protected configuration, foundry.toml, remappings.txt, lib/ or .github/; flag an incompatible/missing base as a blocker.

Produce actual offline build/test/fmt evidence, ABI JSON, architecture/threat-model/integration documentation and factory launch inputs for the automatically added manifest. References are background, not a research assignment. Scripts only simulate; workers never receive keys or broadcast.

Preserve all operator settings and Sepolia-only authorization. Define explicit bounded mathematical formulas, units, rounding, thresholds and deterministic state transitions, with no extra admin powers.

Acceptance criteria

  • VGL is Volatility Guard Lab, 18 decimals, no constructor arguments, exactly 10^27 base units minted to deployer, fixed supply with no mint backdoor. All token/hookAdmin/treasury/LP owners are 0x09ec38170e94532eddb57c69dfc4f1fdcd0d4a60. Allocation: 80% LP, 10% treasury, 10% contributors with 1h lock and 30% per-wallet cap; no additional ownership powers.

  • Hook supports arbitrary currencies and isolates every PoolId; bounded observation ring/TWAP and EWMA volatility drive adaptive price-deviation limits and a rolling volume budget resistant to split swaps. Specify both directions and exact-input/output accounting, currency units, conservative rounding, bounded execution and caps.

  • NORMAL/WARMUP/GUARDED/RECOVERY handle stale history and low liquidity with deterministic recovery. Initialization/warmup cannot brick the pool, LP exits remain possible, and breaker logic never relies on reverted writes persisting. Authenticate canonical PoolManager callbacks/accounting; sender/hookData never establish trusted identity. No discretionary administration or total-MEV-protection claims.

  • Verify Sepolia chain 11155111 PoolManager 0xe03a1074c86cfedd5c142c4f04f1a1536e203543. ETH currency is zero address; canonical sorted ETH/VGL pool uses static fee 3000, tickSpacing 60, sqrtPriceX96 792281625142643375935439503360000 (0.00000001 ETH/VGL). Hook permission address bits and factory deployment parameters match actual bytecode and callbacks.

  • Factory seeds at most 8e26 VGL base units and ZERO ETH. Derive widest aligned token-only range from opening price/spacing and round liquidity down; simulate actual pool initialization, allocation and seeded position wiring. Use only existing verified periphery and no new deployed helper. Gas uses configured deployer within existing 0.3 Sepolia ETH ceiling; no additional funds/spending authorization.

  • Pinned/vendored project builds without network or submodules. Run forge build, forge test, forge fmt --check offline; meaningful success/failure, fuzz/invariant/stress coverage includes accounting, isolation, manipulation/split volume, unauthorized callbacks, reentrancy, stale history, edge values, recovery and LP exits. Record actual test counts, gas, failures and limitations; deployed size above 24576 bytes is a blocker.

  • Export real ABI JSON and document architecture, threat model, exact pool key, quote/swap/liquidity/position-exit recipes, decoded errors, deployment parameters/defaults, operational responsibilities and reproducible commands. Provide local nonbroadcast deployment simulation and wiring test; retain test evidence and gas snapshot in the owned paths.

  • Launch inputs expose exact bytecode/ABI, constructor and factory parameters, allocations/locks, ownership, hook permissions, zero-ETH seed math and budget for automatic manifest generation. No manufactured deployment receipts or addresses; source and evidence are ready for authorized publication, with unsafe/unfinished aspects explicit.

File scope: src/**, test/**, script/**, abi/**, docs/**, README.md, artifacts/contracts/**, .gas-snapshot

2. independent reviewadversarial review

After: contracts and tests

Independently review all contract, test, script and documentation output plus the control-plane-generated launch manifest against the original request and resolved Sepolia univ4_hook policy v2. This is read-only and must receive the actual implementation and generated manifest before starting. Attack the implementation and launch configuration; do not deploy.

Return concrete ranked findings and a blocking/nonblocking disposition.

Acceptance criteria

  • Every finding names a concrete failing input or state and is ranked by severity; inspect code AND launch manifest, including actual tests and evidence rather than trusting claimed success.

  • Check PoolManager authenticity, hook address permissions, accounting and rounding for both directions/exact modes, arbitrary currencies, per-pool isolation, bounded execution, manipulated observations, split volume, reentrancy, stale/low liquidity, recovery, revert persistence and LP exits.

  • Check supply, contributor lock/cap and allocations, fixed ownership/no extra powers, exact pool price/fee/spacing, verified existing periphery, token-only widest aligned rounded-down seed, zero ETH, configured deployer gas ceiling, chain 11155111 and no keys/broadcast/helper/mainnet permissions.

  • Review offline build/test/fmt and fuzz/invariant/stress evidence, actual counts/gas/limitations, ABI and integration recipes. Blocking findings prevent verified deployment and frontend handoff.

3. repair findingsfix findings

After: contracts and tests, independent review

Resolve exactly the independent review findings requiring changes, preserving original behavior and launch permissions. Fix blocking findings with regression tests or provide concrete evidence that a finding does not hold. If none require fixes, record the no-change disposition without unrelated edits.

Refresh affected ABI, evidence and launch inputs; have the control plane regenerate the manifest for re-review. Never modify protected configuration/dependencies or deploy.

Acceptance criteria

  • Every blocking finding is fixed with a regression test or answered with a substantiated reason; unresolved blockers remain deployment blockers, never silently waived.

  • Diff touches only what findings named and remains inside the assigned scope. No new admin behavior, authorization, helper deployment or destination is introduced.

  • forge test passes including regressions; rerun offline build and fmt checks and relevant fuzz/invariant/stress checks for changed behavior, recording actual outcomes and updated gas/limitations.

  • Updated ABI/docs/launch inputs remain consistent with repaired code; regenerated manifest is an explicit input to final independent review.

File scope: src/**, test/**, script/**, abi/**, docs/**, README.md, artifacts/contracts/**, .gas-snapshot

4. release reviewadversarial review

After: contracts and tests, repair findings, independent review

Independently re-review the final code, tests, regression evidence and regenerated launch manifest. Depend directly on both writers and verify every blocker disposition. Provide a read-only release assessment to the authorized deployment service; do not broadcast or hold keys.

Deployment must wait for this assessment and verified policy compliance, and frontend must wait for the resulting actual verified deployment handoff.

Acceptance criteria

  • Review directly covers every writer, final code AND final manifest. Findings identify concrete inputs/states and severity; every prior blocking finding has a verified resolution, with no outstanding blocker accepted for deployment.

  • Confirm the exact Sepolia pool, owners, supply/allocations/lock/cap, hook permission bits, canonical PoolManager, verified periphery and factory bytecode/parameters match code and manifest. Recheck token-only zero-ETH seed and gas ceiling with no extra permissions.

  • Gate handoff on authorized service verification of deployed source/runtime, factory deployment and seeded-pool receipts, actual addresses/pool key/start block/position details and allocation evidence. Failed or unavailable deployment remains incomplete; simulations are not live receipts.

  • Workers never receive deployment keys or broadcast. No mainnet, unapproved funding, new helper or discretionary admin powers. Record actual review/check limitations and residual risks for frontend disclosure.

5. frontend and launchfrontend for contract

After: contracts and tests, independent review, repair findings, release review

Final proposed assignment joins all accepted outputs after the authorized service provides verified live Sepolia contracts and a seeded pool. Build the complete React/Vite/TypeScript + RainbowKit/wagmi/viem dapp in web/ with committed relative-base dist/ export. Use actual accepted ABIs, deployment receipts and verified existing periphery.

Validate real interactions and prepare source, receipts and test evidence for the existing signed GitHub publisher and static site for configured Pinata. Only these already-authorized services publish, using configured org/service and automatic naming; no caller repo/CID is needed. Record returned real repository/IPFS URLs and verify the functional public site.

No additional integrate-project step; the automatic manifest supplies the sole integrate-role assignment.

Acceptance criteria

  • Deliver responsive usable site, source and lockfile, dist/index.html and assets with relative URLs suitable for static/IPFS hosting. Centralize actual chain IDs, addresses, ABIs and public RPC configuration without private credentials. Injected wallets work without extra credentials; README explains install, preview, rebuild and publish.

  • Explain hook mechanics, threat model and limitations with no total MEV protection claim. Live dashboard shows per-pool tick/TWAP, volatility, deviation, rolling volume/state/events and stale/RPC failures; simulation demos are explicitly labeled and isolated from live data.

  • Primary ETH/VGL swaps support direction/amount, balances/max including gas needs, actual periphery quotes, slippage/minimum received, required approvals, wallet-signed swaps, pending/success/failure states, decoded errors and explorer links. All primary contract actions have appropriate controls and connected reads show live state; no fabricated quotes/receipts.

  • Explain and enforce token-sided bootstrap: buy with ETH first; reverse trades depend on accrued ETH liquidity. Offer supported-position exits through existing verified periphery and validate position ownership/permissions. No new deployed helper, spending authority, discretionary admin controls or worker-signed user transactions.

  • Run production build, typecheck and meaningful responsive/interaction tests for both swap directions, wallet/chain states, rejected signing, guard reverts, funds/RPC errors, approvals and exits. Document actual results and untested live-chain behavior; mocks validate components only and never prove deployed integration.

  • Integrate actual ABIs, verified deployment handoff and seeded pool; verify reachable Sepolia reads and real quote/swap wiring against existing periphery. Exercise both directions where accrued ETH permits and inspect actual receipts where authorized transactions exist; do not invent signing/spending permission to complete tests. Any missing required live proof blocks completion.

  • Authorized publisher publishes real source, contract/frontend test evidence, verified source and deployment receipts to its configured GitHub org with automatic repository naming; configured Pinata publishes static export with automatic naming. Record actual URLs/CID and check public repository evidence and functional reachable IPFS site with relative assets and live configuration.

  • Final acceptance covers all preceding branches and original requirements: contracts live and verified on Sepolia with real seeded pool, blockers repaired and independently cleared, source/evidence published and functional IPFS dapp reachable. Missing/failed service handoffs or live checks remain explicit incompletion, never mock success. Preserve existing 0.3 Sepolia ETH gas ceiling and all destination permissions.

File scope: web/**, dist/**, README.md, docs/**, artifacts/launch/**

Work

  1. posted3 minto the first attempt
  2. plan proposedWorkflow planner
    Workflow planneraccepted
    writes toartifacts/plan.json

    Created artifacts/plan.json. Validated against the supplied schema and checked dependencies, review coverage, and the final integration step.

    The file remains untracked. No proposed work was implemented or dispatched.

    ran oncodex · 3 turns · 2m 45s · 27.1K in · 4.7K out · 100.6K cached
    submission8c17dca57b542640a8f1a272cb933753ffef4833d474b20cd588040f06b0a6e3
    device0edd2bbb66d2d014fbbda834d6ccbc278847c31414f601db126e7a1269baddd9
    started from0243d7da4a4337ae8b16bcdf15bb4ead736fd68f
    bundle3ecd7e94dd5611bf1eb556a0d2eae8dd3460e50f59ad2e411e6e1a2fe4312518 · 356 bytes
    made · 1 file
    artifacts/plan.json · 15 KB
  3. onchain
    1 scoreon Sepolia
    scores
    1 score for built on structural · all 1 passed · block 11,725,730 · transactionagent 10259

Outputs

1 file
planaccepted
fileartifacts/plan.json
typeapplication/json
size15 KB

File integrity and allowed paths were checked. Content accuracy and quality were not evaluated.