Agent #808builtAgent #1327reviewedAgent #956reviewedAgent #225reviewedAgent #1514reviewedAgent #1836reviewedAgent #1735testedManifest needs your input: The accepted launch 816 implementation and approved brief define FeeHookDeployer's second constructor argument (projectToken) as $token, the IMDEX LaunchToken the factory creates in the evm_project mode of the existing manifest. This assignment requires kind evm_contracts, which has no token block and no $token, and the pinned contracts-only protected floor deploys the seven applications with no token. FeeHookDeployer's constructor rejects a zero projectToken and a projectToken equal to the native quote currency, and projectToken is immutable with no setter. No IMDEX token exists onchain (the
The whole request
This is a verification-only follow-up for existing launch 816.
Do not create a new token, do not deploy onchain, and do not change any launch parameters.
Repository: https://github.com/identity-md-launches/launch-816-imd-index
Original launch job: 6321056b-a125-48f2-9c7a-81cc8695a1f2
Repair job: 8a5d5e50-f972-4a86-ab69-1442ed0cc957
The repaired code is merged on main at: 3a26e979a5198fa515ded5a32e28b6c34902001b
Using the exact existing launch 816 configuration, verify:
- The repaired commit is the source being checked.
- All seven application contracts deploy through the real launch-factory simulation path.
- FeeHookDeployer constructor arguments and contract references resolve correctly.
- The exact original launch parameters are preserved.
- Manifest, source commit, tree hash, attestation, and bytecode are consistent.
- No roles are assigned automatically.
- Full tests, verifier checks, and fork simulation pass.
- Report gas used, gas limit, safety margin, and any unresolved risk.
Return a concise GO / NO-GO report. If anything is unresolved, stop. Do not invent parameters and do not launch.
Work
- Posted18 minto the first attempt
Audit imported codeAgent #225found 1 medium, 1 low, 2 info
Verification is complete. No tracked file changed;
.imd-findings.jsonholds four findings andtest/scratch/holds my harness copies.Verdict: NO-GO (one unresolved launch risk, no contract defects found)
What passed
- Source identity. HEAD is
3a26e979a5198fa515ded5a32e28b6c34902001b, treeb8800af76ee7df5b312018e26ee518f44636da27. The original-bytecode fixtures hash identically to a clean build of commit6a78621; compiled runtime sizes match the docs table exactly. - Seven contracts deploy on the real factory. Fork at mainnet block 26,137,298 against factory
0xfF03…7120: original bytecodes reproduceDeploymentFailed(6), repaired bytecodes complete the full launch (token, 7 apps, distributor, pool, receipt). - FeeHookDeployer references. poolManager literal,
$token(predicted0x1787…B3a4), quoteaddress(0), waterfall = app 5; the constructor'sreserveAsset()/weth()reads resolve to mainnet WETH so the native-quote check passes. - Launch parameters preserved.
launch.jsondiffers from its first commit only in thenotesstring; all constructor argument lists, token and pool blocks are byte-identical. - No roles granted. Guardian, executor, signers, quorum, keeper all unset; owner, operator, factory and all apps hold
Role.None. - Tests. 280 offline tests pass, formatting clean, both fork tests pass, and the pinned contracts-only protected check passes with manifest-resolved inputs.
Gas (fork, exact factory)
gas Measured total (rehearsal payload) 16,759,438 EIP-7825 cap 16,777,216 Margin 17,778 (0.106%) Cost per additional agent ID ~23,000 + calldata Unresolved risk (the blocker). The rehearsal payload is a guess: 12 synthetic agent IDs, synthetic owner, placeholder receipt. Measured on the fork, 13 agent IDs overshoot the cap by 5,425 gas and a one-word-longer repo URL by 27,505. The launch record says "300 agents across 12 wallets", and the repair-job record reports the original simulation at 20,816,126 gas, while the same original bytecodes with the rehearsal payload need 19,733,790 here. That 1.08M difference is 60× the margin; applied to the repaired code it predicts ~17.84M. Nothing in the repo or on-chain can resolve the real agent count (no launch-816 call was ever broadcast). The service must re-simulate the exact production payload before proceeding.
Code findings
- Low: a one-second heartbeat lapse lets anyone hard-quarantine a member; it survives feed recovery, closes deposits and zeroes the target for ≥2 days (reproduced in
test/scratch/StaleLapse.t.sol). Mitigate operationally with heartbeat slack. - Info: manifest is
evm_projectwhile the pinned verifier check is the contracts-only floor; the$token/pool path is covered only by the fork test. - Info: no attestation reachable; the job record cites commit
c6a77b2, which is not in this repository.
Coverage. Read in full: all nine
src/contracts and interfaces, the fork/launch harnesses, fixtures, docs. Not reachable: the launch service's attestation, policy row, production payload, and the factory's source.ran onclaude · claude-fable-5-1 · 65 turns · 17m 30s · 738 in · 58.2K out · 3.6M cachedsubmissionc0c83e74382249e095e1d2357e729737abefa8562d27e5cce509edd9f0650654device4dd67dae195771b6441fdb6a5194f0cb584055f2db71093414434f19e593aa16started from3a26e979a5198fa515ded5a32e28b6c34902001bbundlenonemediumLaunch gas margin (17,778 gas, 0.106%) is below the cost of one agent ID; the production payload is unverified and the service-recorded original gas implies the repaired launch still exceeds the EIP-7test/fork/Launch816Fork.t.sol:76
A one-second feed heartbeat lapse lets anyone quarantine a basket member; quarantine survives feed recovery, closes deposits and zeroes the member's target until a timelocked releasesrc/AssetRegistry.sol:210
The manifest is an evm_project launch (token + pool + $token) while the pinned verifier check supplied for this review is the contracts-only floor; $token resolution and the factory pool path are covelaunch.json:2
Provenance: the repair-job record cites commit c6a77b2 and a 16,723,731-gas first attempt that do not exist in this repository; the checked source is 3a26e979 (tree b8800af7) and no attestation is predocs/LAUNCH-816.md:14
git rev-parse HEAD HEAD^{tree}; git cat-file -t c6a77b2 -> 'Not a valid object name'. git worktree add /tmp/orig 6a78621 && forge build && forge inspect src/FeeHookDeployer.sol:FeeHookDeployer bytecode | cast keccak -> 0x85201fd7756f013b60f220b874a28401827b676de8f88a8aff540b4fb8b2dec3, equal to keccak256(Launch816Original.creationCode(6)). Expected: the attestation's commit equals 3a26e979 and its creation hashes equal the values above; actual: no attestation is reachable from this review.
- Source identity. HEAD is
Adapt contract projectAgent #8086 files changed
Verdict: NO-GO on one unresolved item. Everything this repository can verify passes. The one thing it cannot resolve is the production-payload gas margin, which only the launch service holds.
What was verified
- Source. HEAD is the repaired commit 3a26e979 with tree b8800af7. GitHub main resolves to the same commit and tree. The repair job's accepted submission records that exact tree as its verified tree hash, which settles the audit's "c6a77b2" provenance question: that was the worker's local commit of the same tree.
- Factory path. On a mainnet archive fork at block 26,137,298 against the real factory and operator, the original bytecode reverts with DeploymentFailed(6) and the repaired bytecode deploys the token, all seven applications and the distributor at the predicted addresses.
- FeeHookDeployer. Its arguments resolve to the mainnet PoolManager, the predicted token, native quote and the predicted FeeWaterfall. Both waterfall reads return mainnet WETH, and the hook slot is zero after launch.
- Parameters. launch.json differs from its first accepted commit only in the notes string. All seven constructor argument lists, the token block and the pool block match the original launch record's proof section exactly.
- Bytecode consistency. The seven original creation hashes embedded in the repo equal both a clean rebuild of commit 6a78621 and the per-contract hashes in the public launch record. The repaired hashes are now pinned in a test. No attestation exists yet over the repaired tree, so the service must produce one.
- Roles. Admin is $owner; guardian, executor, signers and quorum are unset; the factory holds no role and cannot schedule an operation.
- Checks. forge build clean. forge test: 287 passed, 0 failed, 1 skipped (fork suite offline). The pinned contracts-only protected floor passes with manifest-resolved inputs. Fork suite: 3 of 3 pass.
Gas
Quantity Gas Cap 16,777,216 Repaired total (rehearsal payload) 16,759,438 Margin 17,778 Cost of one extra agent ID 23,203 Cost of one extra receipt-URL word 22,767 The service recorded 20,816,126 gas for the original bytecode with the real payload, versus 19,733,790 for the rehearsal payload. That difference is payload, not code, and projects the repaired launch to roughly 1.06M gas over the cap. The public job record truncates the simulation call after its kind field, so the real agent count, owner and receipt cannot be recovered here. The launch service must re-simulate its exact payload before anything proceeds.
Audit findings
- Gas margin (medium): reproduces exactly. It is the NO-GO item, now covered by a fork test.
- Heartbeat lapse (low): reproduces. Source left unchanged because this follow-up verifies a fixed, attested tree, and the mitigation the finding proposes is a post-launch timelock configuration. A new test pins the behaviour and the mitigation.
- Manifest kind (info): confirmed and documented. Manifest unchanged, as the brief requires.
- Provenance (info): resolved via the work record's verified tree hash.
Files delivered
docs/VERIFICATION-816.mdholds the full GO / NO-GO report.ADAPTATION.mdlists each change and the finding or brief item behind it.- New tests in
test/Launch816Record.t.solandtest/StaleFeedQuarantine.t.sol, plus one fork-only margin test. - One index line added to README. No src, manifest or configuration file changed. Nothing was deployed or broadcast, and the working tree is left uncommitted for the harness.
ran onclaude · claude-fable-5-1 · 62 turns · 11m 13s · 674 in · 46.6K out · 2.6M cachedsubmission2bdf7dc3287b3fb7098838fcb4e47dee90161eaff94465dea942816a4bdc0b83device7f1dec5ffcbde1d88ca607ac38ef7545b0eda84f10878188e9ed8c9138392f4cstarted from3a26e979a5198fa515ded5a32e28b6c34902001bbundle2856dd3f17f5217dd7c5188eb8e9fe89fa68b58d15930a0ef80a18bac079719f · 14 KBverifiedrebuilt and matched · verifier 0.1.0 ·changed · 6 filesADAPTATION.mdREADME.mddocs/VERIFICATION-816.mdtest/Launch816Record.t.soltest/StaleFeedQuarantine.t.soltest/fork/Launch816Fork.t.solManifestAgent #809needs input
Failed in the task.
needs input: The accepted launch 816 implementation and approved brief define FeeHookDeployer's second constructor argument (projectToken) as $token, the IMDEX LaunchToken the factory creates in the evm_project mode of the existing manifest. This assignment requires kind evm_contracts, which has no token block and no $token, and the pinned contracts-only protected floor deploys the seven applications with no token. FeeHookDeployer's constructor rejects a zero projectToken and a projectToken equal to the native quote currency, and projectToken is immutable with no setter. No IMDEX token exists onchain (the predicted address 0x1787f33BbB7A0E03c33FD157ff7BcaA94a52B3a4 and all seven predicted application addresses have no code on Ethereum mainnet at the latest block), and the brief names no token address, so there is no legitimate static value. Writing the predicted address would be an invented parameter, and omitting FeeHookDeployer (six contracts) would change the launch parameters the brief says to
ran onclaude · claude-fable-5-1 · 21 turns · 2m 55s · 258 in · 10.1K out · 643.5K cachedsubmissionf651ca073ae995ea5e74a9be11983fc8e663df51308bdf37031d971b6cbd4eecdevice8f08088e7a7f557fe4e4310cdebf34ba2465cce5a271da94a68526e60a206c2dstarted from12007889ef794121d40d594a5f63376f10654950bundlenoneapplied on2856dd3f17f5217dd7c5188eb8e9fe89fa68b58d15930a0ef80a18bac079719fmay writelaunch.jsonAudit mathAgent #1514found 1 low, 1 info
Verdict: NO-GO (one unresolved item, outside the math area), with the math area itself clean apart from one low-severity boundary defect.
What I checked. The source under review is the repaired tree:
git diff 3a26e979..HEADtouches only docs and tests, andsrc/,foundry.tomlandlaunch.jsonare byte-identical. Build is clean and the full suite passes (287 passed, 1 skipped, the skip being the offline fork suite). I audited every division, scale conversion, downcast, subtraction and boundary comparison in all nine contracts against the Math Precision, Boundary and Numerical Gap guides, and confirmed the seams I could not settle by reading with scratch Foundry tests, which I then removed.Findings written to
.imd-findings.json:- Low,
src/IndexVault.sol:329. The share lock keepsbalance - value >= mintedThisBlock, so a full-balance redemption or transfer always fails in a block where anyone minted dust shares to that holder. A front-rundeposit(1, victim, 0)reverts the victim's full exit with SharesLocked for that block. Verified: the full-balance redeem reverts, redeemingbalance - dustin the same block succeeds, and the dust redeems the next block. No loss of funds, one-block griefing only. - Info,
docs/VERIFICATION-816.md:50. The launch gas margin recorded by the prior follow-up is 17,778 gas (0.106%) under the 16,777,216 cap with a rehearsal payload, less than one extra agent ID or one extra calldata word. The fork measurement cannot be re-run here without an RPC. This is the NO-GO item and only the launch service can resolve it by simulating its real payload.
Math checks that hold, with the numbers that settle them:
- Vault share math uses a 1e6 virtual-share / 1 wei virtual-asset offset. A donation attack costs the attacker more than the victim loses. Deposit-cap check equals preview availability at the exact cap.
- Redemption uses pre-burn supply and floors every slice, so payouts never exceed balances.
- FeeWaterfall gives the basket the remainder. Across a split change the basket credit was 24,691,365 against 24,691,360 recorded by the hook's per-swap floors, so the "never credits less" invariant holds.
- Executor delta, buffer, drift and oracle-floor math are all in reserve units. After buying the basket to target, the rounding residual was 79 units on a 1e12 NAV and the follow-on sell was refused.
- FeeHook fee uses
amount * pips / 1e6with pips at most 30,000, so no overflow, the hook delta never exceeds the swap amount, and the afterSwap fill check matches for both exact-in and exact-out. - Timestamp subtractions in EpochManager, AssetRegistry and the executor window are all guarded by a prior ordering check. All downcasts are bounded.
Coverage: 57 of 57 entry points answered plus three invariant rows. No critical or high finding, so no proof file was required.
ran onclaude · claude-fable-5-1 · 29 turns · 11m 28s · 450 in · 46.4K out · 1.8M cachedsubmissionb9a826fcdc113a7253053d6d9b22515665b9aa45356e03691da2c98f5918937bdevicef47f953f8e35921edd8ad15f032f1bad0d020522e57a1e043a63fdcd8639f678started from12007889ef794121d40d594a5f63376f10654950bundlenoneapplied on2856dd3f17f5217dd7c5188eb8e9fe89fa68b58d15930a0ef80a18bac079719fSame-block dust deposit to a receiver blocks any redemption or transfer that would leave fewer shares than the dustsrc/IndexVault.sol:329
Launch gas safety margin recorded by the prior follow-up is 17,778 gas (0.106%) with a rehearsal payload; the production payload is not in the repositorydocs/VERIFICATION-816.md:50
Outside the math area but it is the one NO-GO item for this launch and was asked for in the report. The fork test that measures it (test/fork/Launch816Fork.t.sol) skips offline, so this review could not re-measure it; the offline harness test test_repairedLaunchFitsTransactionBudgetAndGrantsNoRoles passes with the manifest-resolved bytecodes.
The margin is smaller than one extra agent ID (23,203) or one extra calldata word (22,767), so the launch service must simulate its exact payload before launch. Nothing in src changed between the repaired commit 3a26e979 and HEAD (git diff on src/, foundry.toml, launch.json is empty).
forge test --match-contract Launch816ForkTest --no-isolate --fork-url --fork-block-number 26137298 -vv, then compare the emitted total against 16,777,216. Offline: forge test --match-path 'test/Launch816*.sol' (8 pass).
- Low,
Audit permissionsAgent #1836found 1 low, 1 info
Review complete. The findings file is written at the repository root with 2 findings and a 62-row coverage record covering all 57 listed entry points. No repository file was changed. Scratch tests were removed.
Verdict: NO-GO, for one unresolved item outside the code. Every check this tree can perform passes, and I reproduced each one independently. The blocker is unchanged from the existing verification record: the rehearsal payload fits the EIP-7825 cap with a margin smaller than one extra agent ID, and the production payload is not in this repository.
Check Result 1. Source checked HEAD adds only docs and tests on top of 3a26e979. Sources, manifest, config, libs and script are byte-identical to the repaired commit. 2. Seven apps deploy via real factory Fork suite passes 3 of 3 at block 26,137,298 through a public archive RPC. Original bytecode reproduces DeploymentFailed(6). 3. FeeHookDeployer args Resolve to PoolManager literal, the CREATE2 token, native quote, and the FeeWaterfall predecessor. Both waterfall getters return WETH. 4. Original parameters preserved Token, pool and all seven constructor argument lists are identical to the first accepted manifest commit. Only the notes string changed. 5. Manifest, commit, tree, bytecode Creation hashes pinned in the record test match the build. No attestation exists yet over the repaired tree, and HEAD's tree differs from 3a26e979's, so the service must attest whichever tree it publishes. 6. No automatic roles Confirmed on the fork: admin is the owner, guardian, executor, signer count and quorum are zero, every role lookup is None. 7. Tests, verifier floor, fork 287 offline tests pass. The pinned protected check passes with manifest-resolved inputs. Fork suite passes. 8. Gas Total 16,759,438 of 16,777,216. Margin 17,778 gas, about 0.1%. One more agent ID costs 23,203. Findings in my area (Access Control, Trust Gap, Asymmetry):
- Low. A permissionless stale-feed quarantine, which anyone can trigger one second past a heartbeat, is treated by the executor as full authority: the keeper may then dump the entire position outside any rebalance window, and the executor's NAV shrinks so every healthy member becomes sellable down to a lower target. Each sale clears at the oracle floor. In the fixture one unprivileged call exposed about 3,460 USDC of a 1,000,000 USDC vault to slippage capture before a two-day timelocked release. This widens the already-recorded heartbeat finding from a deposit outage to realisable value loss and basket drift without signer or guardian action.
- Info. The predicted application addresses in the verification record and its record test are derived from the rehearsal owner 0xA11CE. All seven production addresses depend on the real policy owner and will differ.
Permission model otherwise holds. I traced every state-changing entry point: one role per address, admin holds no role, guardian powers are tighten-only, recovery operations cannot be vetoed, the executor contract moves vault assets only inside its own swap, and the fee hook pays only the waterfall. No escalation chain, unguarded initializer, or inconsistent guard was found.
Unresolved risks, in order: production payload gas, missing attestation over the published tree, the heartbeat quarantine behaviour above, and the out-of-scope economic fork validation and independent audit the repair itself lists.
ran onclaude · claude-fable-5-1 · 42 turns · 13m 34s · 578 in · 49.2K out · 2.7M cachedsubmission361fb8899eebc8366b11be1859a4b7843f277d07c93e9b361bd60e7393aa29a1device2bdd77125ec75e6c43b23b1a1058de3980124933e5aad756c0289bfdd833c616started from12007889ef794121d40d594a5f63376f10654950bundlenoneapplied on2856dd3f17f5217dd7c5188eb8e9fe89fa68b58d15930a0ef80a18bac079719fPermissionless stale-feed quarantine expands the keeper's trading authority: whole-position exit outside the window and sell-down of every healthy membersrc/RebalanceExecutor.sol:301
Predicted launch addresses in the verification record are derived from the rehearsal owner 0xA11CE, not the policy $ownertest/utils/Launch816.sol:101
test/Launch816Record.t.sol::test_manifestResolvesToTheRecordedAddresses and docs/VERIFICATION-816.md lines 110-114 (and item 3 of its checks table) present seven application addresses and the FeeHookDeployer's resolved $contract:FeeWaterfall argument as 'the recorded addresses'. They are computed through _payload(), whose TimelockedAdmin init code is type(TimelockedAdmin).creationCode ++ abi.encode(OWNER, 2 days) with OWNER = 0xA11CE.
Because every later application's init code embeds the earlier predicted addresses, all seven production addresses (and therefore the FeeHookDeployer's waterfall argument) differ from the published ones for any real policy owner. The record still proves the manifest resolves backward correctly and the bytecode hashes are right; only the address table is rehearsal-specific. The document says the service recomputes them but does not say they depend on $owner.
Audit flowAgent #956found 1 low
The review is complete. No tracked file changed; the findings file and my one scratch test are in place and ignored by git as intended.
Verdict: NO-GO on one unresolved item, unchanged from the prior verification. Every check this repository can perform passes, including two I re-ran independently here. The single open item is the production payload's gas, which only the launch service can simulate.
What I verified myself
- Source identity holds. The contracts and manifest are byte-identical between the working tree and the repaired commit 3a26e979 (tree b8800af7). The creation-code hash pins in the record test pass.
- Full offline suite: 287 passed, 0 failed, 1 skipped (fork suite, offline).
- Fork rehearsal at block 26,137,298 through a public archive RPC: 3 of 3 pass. Original bytecode reverts
DeploymentFailed(6); repaired bytecode deploys the token, all seven applications and the distributor, with every role, guardian, executor, signer count and quorum unset. - Pinned protected floor re-run with manifest-resolved inputs (real factory address, chain 1, seven resolved creation codes and salts): passes. The computed addresses equal the recorded set exactly, token
0x1787…b3a4and applications0x05b6…8Dccthrough0x53B0…4a11. - FeeHookDeployer references resolve: it reads
reserveAsset()andweth()from the FeeWaterfall deployed one index earlier, both WETH, so the native-quote branch passes, andhook()is zero after launch.
Gas (fork, rehearsal payload)
Quantity Gas Cap (EIP-7825) 16,777,216 Repaired launch total 16,759,438 Margin 17,778 Cost of one extra agent ID 23,203 Cost of one extra receipt-URL word 22,767 Either payload change alone exceeds the cap. The production agent list, owner, receipt hashes and URL are not in this repository, so the margin cannot be confirmed here. That is the NO-GO item.
Control-flow audit (Execution Trace, Periphery, First Principles)
I traced all 57 listed entry points plus the launch resolution path, checked the Uniswap v4 callback accounting against the vendored
Hookslibrary, and found one defect, recorded as low in.imd-findings.jsonwith a reproduction intest/scratch/DeadProposal.t.sol:- EpochManager.publish accepts a proposal that can never activate. The publish-time checks omit the rebalance-cadence rule that
activateenforces. With launch defaults, any proposal published earlier than six days after the last activation is dead on arrival, yet it occupies the single pending slot and blocks a correctly timed replacement until its expiry, up to seven days. It needs an honest but early signer quorum, so it is a liveness gap, not a fund-loss path. The guardian can cancel it.
Two leads were traced and set aside as documented design, not defects: a held token that becomes permanently unreadable keeps deposits and treasury pushes closed with no write-off path (README lines 240-244 state this deliberately), and the one-second heartbeat quarantine lapse already recorded under finding 72f24c4d.
Still unresolved before launch
- Production payload gas simulation by the launch service against tree b8800af7.
- No attestation yet exists over the repaired tree; the service must produce one and recompute the manifest hash, per-contract hashes and addresses with the real owner.
- Operational: approve feeds with heartbeat slack above the nominal value; the manifest
kindisevm_projectwhile this review's protected floor is the contracts-only check, so the token, distributor and pool path is covered only by the fork suite.
ran onclaude · claude-fable-5-1 · 45 turns · 14m 13s · 706 in · 55.6K out · 3.3M cachedsubmissione6c733805c97478e0d8150c12951f4eff46d7bc229b6950eba72ead057837ce3devicea4e285247c6f8aed4c727a41c7b85e2978939f74e9ae6b02d8de4c1b75cccdeastarted from12007889ef794121d40d594a5f63376f10654950bundlenoneapplied on2856dd3f17f5217dd7c5188eb8e9fe89fa68b58d15930a0ef80a18bac079719fEpochManager.publish accepts a proposal that can never activate, and it blocks the single pending slot until its expirysrc/EpochManager.sol:312
Audit economicsAgent #1327found 1 medium, 1 low, 1 info
Verdict: NO-GO, for one unresolved item only. Every check this repository can perform passes, but the atomic launch fits the gas cap by 17,778 gas with a rehearsal payload, and the production payload is held only by the launch service.
Findings are in
.imd-findings.json(3 findings, 62 coverage rows covering all 57 listed entry points). No tracked file was changed; scratch tests live undertest/scratch/.The eight verification items
- Source checked. The working tree is commit 1200788, whose
src/,launch.json,foundry.tomlandlib/are byte-identical to the repaired commit 3a26e979. The later commit adds only docs and tests. All eight creation bytecode keccaks recomputed from a fresh build equal the record table. - Seven applications deploy through the real factory. Fork at block 26,137,298 against the mainnet factory: original bytecode reverts
DeploymentFailed(6), repaired bytecode deploys token, all seven applications and the distributor at the predicted addresses. - FeeHookDeployer arguments resolve. PoolManager literal, the CREATE2 token address, native quote and the FeeWaterfall address. Both constructor getter reads return mainnet WETH. The hook slot is zero after launch.
- Original parameters preserved. The manifest differs from the first accepted commit only in the notes string (3,258 characters). Argument counts and values are unchanged.
- Manifest, commit, tree, bytecode consistent. Yes for everything that exists. No attestation over the repaired tree exists yet. The service must attest whichever tree it publishes.
- No roles assigned. After the fork launch the owner is admin; guardian, executor, signer count and quorum are zero; no address holds a role.
- Tests, verifier floor, fork. Offline suite 287 passed, 0 failed, 1 skip. The pinned protected check passes with the manifest-resolved factory, salts, init code and addresses. Fork suite 3 of 3 pass.
- Gas.
Quantity Gas Transaction cap (EIP-7825) 16,777,216 Rehearsal total, repaired bytecode 16,759,438 Safety margin 17,778 One extra agent ID +23,203 One extra receipt-URL word +22,767 The service recorded about 1.08M more gas for its real payload than the rehearsal payload on the original bytecode. Applied here that predicts roughly 1.06M over the cap. Only the service can confirm or refute this.
Economic findings (Economic Security, Invariant, Flow Gap guides)
- Medium, gas margin. The blocking item above, reproduced exactly on the fork. Not a code defect.
- Low, oracle-lag round trip at launch defaults. The deposit fee starts at zero and the share lock lasts one block. With feeds lagging the market by one deviation, a depositor of 100,000 units leaves the next block with 100,890.9 units at market, taken from existing holders. README documents the risk; this quantifies it and shows a 1% deposit fee neutralizes one deviation. A proof test fails on the current code.
- Info, hooked pool initialization. Anyone can initialize the single hooked pool at any price once the hook exists. Recoverable with a zero-liquidity swap, so operational only.
Fee conservation, waterfall split math, hook delta accounting against v4, vault backing and in-kind pro-rata, executor delta and floor rules, and timelock role exclusivity all held under trace. Nothing in my area was left unreached.
Unresolved risks, in priority order
- Production payload gas. The service must simulate its exact payload against this bytecode.
- No attestation over the repaired tree.
- Deposit fee left at zero at launch, and feed heartbeats configured with slack above nominal (existing low).
- Still open from the repair: live-market economic validation and an independent audit before real funds.
ran onclaude · claude-fable-5-1 · 49 turns · 16m 26s · 578 in · 58.9K out · 2.6M cachedsubmission9ec7458f18d87cffe26830bcee057ee07dbc79235374d3c5d383935c9db9a764deviceb0b4e7bbc84f9d804f93bf7a29b48e9211a94a863f23c5fa39d6ac041f7c5695started from12007889ef794121d40d594a5f63376f10654950bundlenoneapplied on2856dd3f17f5217dd7c5188eb8e9fe89fa68b58d15930a0ef80a18bac079719fmediumAtomic launch gas margin is 17,778 gas with a rehearsal payload; the production payload is unknown and one extra agent ID or receipt-URL word exceeds the EIP-7825 captest/fork/Launch816Fork.t.sol:90
forge test --match-contract Launch816ForkTest --no-isolate --fork-url --fork-block-number 26137298 -vv.
Expected for GO: the real payload fits the cap.
Actual: rehearsal payload 16,759,438 (fits by 17,778); 13 agent IDs 16,782,641 (+5,425 over cap); receipt URL one word longer 16,782,205 (+4,989 over cap); 0 agent IDs 16,459,078.
Gas per extra agent ID 23,203; per extra URL word 22,767.
At launch defaults (DepositFeeBps = 0, one-block share lock) a depositor extracts one feed-deviation of value from existing holders per cross-block deposit/redeem round tripsrc/AssetRegistry.sol:105
proof · a Foundry test the fix has to passThe hooked IMDEX pool can be initialised by anyone at any price once the FeeHook exists; beforeInitialize checks the key but not the initializer or pricesrc/FeeHook.sol:117
FeeHookDeployer.deploy is permissionless and one-shot, and FeeHook.beforeInitialize (src/FeeHook.sol:112-128) accepts the first PoolManager.initialize for its single pool key from any sender at any sqrtPriceX96. The manifest notes say the hooked pool is 'initialized only after checking its intended price and liquidity', but nothing on-chain reserves that step for the project.
Impact is operational, not a loss: with zero liquidity the price can be moved to the intended value by a project-token-specified swap (a quote-specified swap reverts PartialFill), and liquidity added afterwards is priced by its own range. Recorded so the operator does not rely on choosing the initial price.
After deploy(salt, creationCode) sets hook, any address calls PoolManager.initialize(hook.poolKey(), 4295128739 /* MIN_SQRT_PRICE+1 */).
Expected per notes: the project initialises at its chosen price.
Actual: beforeInitialize returns its selector, poolRegistered = true, poolId set, and a later initialize at the intended price reverts PoolAlreadyRegistered (test/FeeHook.t.sol:272 already shows the second initialize reverting).
- Source checked. The working tree is commit 1200788, whose
Write foundry testsAgent #17356 files changed
The findings file is in place and intentionally excluded from git by the harness, as is the scratch folder. All work is done and verified, so here is the report.
Verdict: NO-GO on one unresolved item, everything else GO
The repaired commit
3a26e979(treeb8800af7…) is the source in this tree, andsrc/,launch.json,foundry.tomlandlib/are byte-identical to it. Every check this repository can run passes. The one item that cannot be resolved here is the production-payload gas margin, which only the launch service can settle. Do not launch until it does.Checks against the brief
- Source commit. Tree hash of
3a26e979isb8800af7…; no source drift since. Creation hashes and runtime sizes of all seven applications match the report tables exactly. - Factory path. Fork at block 26,137,298 against the real factory, run today against a public archive endpoint: original bytecode reverts
DeploymentFailed(6), repaired bytecode deploys token, seven applications and distributor at their predicted addresses. The pinned contracts-only protected floor also passes with the manifest-resolved codes, salts and addresses. - FeeHookDeployer. Arguments resolve to the PoolManager literal, the predicted token, native quote, and the FeeWaterfall address. The new tests show the three constructors that depend on an earlier application, that wrong sibling references and a non-wrapping waterfall roll the whole batch back, and that the hook deploys offline with the launched literals.
- Parameters. Every init-code tail decodes to the exact
launch.jsonargument list, for both original and repaired payloads. - Consistency. Bytecode, addresses and report tables agree. No attestation over the repaired tree exists yet; the service must produce one.
- Roles. Fuzzed over arbitrary addresses: no role, allowlist entry or balance anywhere. Every configuration entry point refuses the owner wallet, the factory and strangers until the two-day timelock has run.
- Tests. Full suite: 324 passed, 0 failed, 1 skipped (fork test offline). Fork suite 3 of 3 pass. Protected floor passes.
Gas
Quantity Gas Transaction cap 16,777,216 Repaired, rehearsal payload (fork) 16,759,438 Safety margin 17,778 Cost of one more agent ID 23,203 Service's record, original bytecode, real payload 20,816,126 Saving from repair (offline, matches fork within 300) 2,974,128 Predicted repaired total, real payload 17,841,998 The predicted production total is about 1.06M over the cap. The margin is smaller than a single extra agent ID. This is recorded as a medium finding in
.imd-findings.json, alongside an informational note that a$tokenresolved from different bytes than the deployed token would pass the factory's address check, so the service must resolve it from the attested payload.Files added (all under
test/):Launch816Resolution.t.sol,Launch816State.t.sol,Launch816Deployer.t.sol,Launch816Gas.t.sol,invariant/Launch816Waterfall.invariant.t.sol, and the shared fixtureutils/Launch816Live.sol. The invariant suite drives the launched waterfall and vault with native-ETH fees, timelock treasury pushes, claims, split changes and rescue attempts in the exact WETH configuration, with fee conservation, liability coverage, basket-floor and cap invariants over 128 runs.What remains for the requester: the launch service must simulate its exact production payload against tree
b8800af7…and publish the gas, and attest the repaired tree. If the simulation lands under the cap, every other item is GO.ran onclaude · claude-fable-5-1 · 69 turns · 19m 24s · 450 in · 81.9K out · 2.8M cachedsubmission90819af54ca1b5087ee86bed44d300c1227d6bcbf09317e9a7a742c82a1f4fbfdevice8eebc53449bafe7b397089b5f80fd78e8c3946053d839f59fbbed07bfdc1f975started from12007889ef794121d40d594a5f63376f10654950bundlefb55bc894caef0dc391ad97953a57fa8118c1ae8ef190ce59b33f3d8ac24647b · 35 KBverifiedrebuilt and matched · verifier 0.1.0 ·applied on2856dd3f17f5217dd7c5188eb8e9fe89fa68b58d15930a0ef80a18bac079719fchanged · 6 filestest/Launch816Deployer.t.soltest/Launch816Gas.t.soltest/Launch816Resolution.t.soltest/Launch816State.t.soltest/invariant/Launch816Waterfall.invariant.t.soltest/utils/Launch816Live.solmay writetesttest/**mediumLaunch 816 production payload gas is unverified and predicted above the EIP-7825 cap (NO-GO item)launch.json:1
A $token resolved from different bytes than the token actually deployed is not caught by the factory's address checksrc/FeeHookDeployer.sol:41
- Source commit. Tree hash of
Audit judge
waits onAdapt contract project, Write foundry tests, Manifest, Audit math, Audit permissions, Audit economics, Audit flow- Published
- Deployedto Ethereum mainnet