Planning job

8b9f0c48Blocked
the whole request

Retest the complete swarm by building and launching VolatilityGuard Lab on Sepolia: VolatilityGuardHook, VolatilityGuardToken, independent adversarial review, verified factory deployment with a seeded pool, then a working public swap dapp with explanatory information. Publish real source, receipts, test evidence and the live site.

Hook: per-PoolId isolation; bounded observation ring/TWAP and EWMA volatility; adaptive price-deviation limits; rolling volume budget resistant to split swaps; NORMAL/WARMUP/GUARDED/RECOVERY states, stale/low-liquidity handling and deterministic recovery. Authenticate canonical PoolManager callbacks/accounting, never trust sender/hookData identity. Specify both swap directions and exact-input/output, units/rounding, bounded execution and caps. Keep LP exits possible and initialization/warmup non-bricking. Reverts cannot persist breaker transitions. No discretionary admin powers or claim of total MEV protection. Support arbitrary currencies.

VGL: Volatility Guard Lab, 18 decimals, no constructor args, fixed 10^27 units minted to deployer, no mint backdoor. Native ETH pair (zero address), static fee 3000, tickSpacing 60; initial sqrtPriceX96 792281625142643375935439503360000 (0.00000001 ETH/VGL). Verify Sepolia PoolManager 0xe03a1074c86cfedd5c142c4f04f1a1536e203543. Use only existing verified periphery, no new deployed helper. Workers never receive keys or broadcast deployments.

Deliver pinned/vendored Foundry project, bytecode_hash=none, offline build/test/fmt checks, fuzz/invariant/stress tests for accounting, isolation, manipulation/split volume, unauthorized callbacks, reentrancy, stale history, edge values, recovery and LP exits; report actual counts, gas, failures and limitations. Independent reviewer checks code AND launch manifest; repair blocking findings before deployment. Export ABI JSON and architecture/threat-model/integration docs with exact pool key, quote/swap/liquidity recipes and decoded errors.

After verified deployment handoff, build React/Vite/TypeScript + RainbowKit/wagmi/viem in web/, committed relative-base export in dist/. Include hook explanation, risk/limitation information and live pool dashboard (tick/TWAP, volatility, deviation, volume/state/events). Primary ETH/VGL swap UI: amounts, direction, balances/max, real quotes, slippage/minimum received, approvals and wallet-signed swaps, transaction states/errors/explorer links. Support injected wallets without extra credentials. Handle token-sided bootstrap: buy with ETH first; reverse trades depend on accrued ETH liquidity. No fabricated quotes or receipts. Add supported-position exits and clearly labeled simulation demos. Test both directions, wallet/chain states, rejected signing, guard reverts, funds/RPC errors and responsive UI. Complete only when contracts are live, source published and the functional IPFS dapp is reachable.

Context and requirements

Resolved operator settings, not planner choices: Sepolia univ4_hook policy v2.

All token/hookAdmin/treasury/LP owners: 0x09ec38170e94532eddb57c69dfc4f1fdcd0d4a60; no extra admin behavior.

Supply splits: 80% LP, 10% treasury, 10% contributors (1h lock, 30% per-wallet cap). Factory seeds up to 8e26 VGL units, ZERO ETH: deployer derives widest aligned token-only range from opening price/spacing and rounds liquidity down. Gas from configured deployer under existing 0.3 Sepolia ETH ceiling; no additional funding or spending authority.

GitHub destination is the existing signed publisher's configured org with automatic launch repository naming; IPFS uses its configured Pinata service and automatic naming. No caller repo/CID needed; both services are online. Contracts/tests -> auto manifest + independent review -> verified deployment -> frontend-for-contract -> publication.

Max five proposed steps; manifest adds sixth. DeFi references are background, not separate research. Never mainnet.

planner instructions · round 2

Read .imd/reads/planning.json and propose the requested workflow in artifacts/plan.json. Do not implement or dispatch the proposed work.

The workflow is blocked. Finishing a planning assignment does not submit its proposed execution jobs.

  • Worker assignments may depend on deployment or publication that only happens after they finish.
  • Shared interfaces are not established with enough confidence.
  • Required dependencies are not established with enough confidence.
  • Coverage of the original requirements is not established with enough confidence.

Proposed workflow

3 step(s) · round 2

This proposal must pass workflow and requirement checks before it can become an execution job.

Serial: contracts -> generated launch.json -> review -> source publication -> attestation -> admission -> deployment -> frontend -> publication/pinning -> naming/validation. Frontend is the sole final integration assignment; no concurrent writers or guessed ABI. Contracts own initial setup/src/test and docs/abi/{VolatilityGuardHook,VolatilityGuardToken}.json plus architecture, threat-model, integration and contract-validation docs.

Review consumes these and generated launch.json; control plane adds its direct manifest dependency. Frontend consumes the same pinned files plus .imd/reads/deployment.json; writes only web/, dist/, docs/** after all earlier writers. Signing/error mocks follow actual ABI/provider interfaces, are labeled and prove no live execution.

Services own receipts, broadcast, publication and naming; workers receive no keys. Sepolia 11155111, univ4_hook policy v2 only; existing 0.3 Sepolia ETH gas ceiling, no extra funding or worker spending, never mainnet. Authorized GitHub uses signed publisher's configured org/automatic launch name; IPFS uses configured Pinata/automatic naming.

Overall completion requires live seeded contracts, published source/test evidence/real receipts, verified handoff, frontend source/export, pinned CID and named ENS site. Publisher owns post-hosting read-only public reachability/smoke validation per docs/site-validation.md and records results before completion. Visitor signs user transactions; no live worker-signed swap tests.

1. contractsbuild contract project

Can start without another proposed step.

From the empty source, create the complete standalone Foundry project: initial configuration including foundry.toml with bytecode_hash=none, pinned ordinary-file vendored dependencies without submodules, src/VolatilityGuardHook.sol, src/VolatilityGuardToken.sol and test/ suites. This serial complete-project writer supplies all missing setup; later stages preserve accepted setup.

Implement and locally simulate the requested guard, factory launch and seeded-pool interactions without broadcasting. Verify canonical Sepolia PoolManager 0xe03a1074c86cfedd5c142c4f04f1a1536e203543 and existing verified periphery; no deployed helper or discretionary admin powers. Export implementation-derived ABIs to docs/abi/VolatilityGuardHook.json and docs/abi/VolatilityGuardToken.json.

Produce docs/architecture.md, docs/threat-model.md, docs/integration.md, docs/contract-validation.md and README.md. Document actual APIs, errors, units, pool key, verified periphery ABIs/addresses and quote/swap/liquidity recipes; docs/integration.md also supplies reproducible deployment parameters for the generated manifest. README covers offline commands and operational responsibilities.

Review consumes these files and the system-generated launch.json; the later frontend consumes the same pinned source/docs and verified deployment handoff. Do not pre-invent ABIs.

Acceptance criteria

  • Hook isolates every PoolId, supports arbitrary currencies and bounded observation ring/TWAP plus EWMA volatility, adaptive price-deviation limits and rolling volume budgets resistant to split swaps. Implement NORMAL/WARMUP/GUARDED/RECOVERY, stale/low-liquidity handling and deterministic recovery; LP exits and initialization/warmup stay possible. Explain how recovery works when reverts cannot persist breaker transitions.

  • Authenticate canonical PoolManager callbacks and accounting; never trust sender/hookData identity. Specify/test both directions, exact input/output, units, signed amounts, rounding, bounded execution and caps; prevent unauthorized callbacks/reentrancy and accounting inconsistencies. No extra admin behavior. Every token/hookAdmin/treasury/LP owner is 0x09ec38170e94532eddb57c69dfc4f1fdcd0d4a60.

  • VolatilityGuardToken is Volatility Guard Lab (VGL), 18 decimals, no constructor args; fixed 10^27 base units minted to deployer with no mint backdoor. Preserve 80% LP, 10% treasury, 10% contributors, 1h contributor lock and 30% per-wallet cap; document allocation enforcement and units for policy/manifest review.

  • Pool pairs VGL with native ETH (zero address), static fee 3000, tickSpacing 60, initial sqrtPriceX96 792281625142643375935439503360000 (0.00000001 ETH/VGL). Factory seeds up to 8e26 VGL units and ZERO ETH; derive widest aligned token-only range from opening price/spacing and round liquidity down. Simulate initialization, seeding, ETH-first buys, reverse trades after ETH accrual and LP exits through actual contract interactions.

  • Run offline forge build, forge test and forge fmt --check with pinned/vendored ordinary dependencies. Include meaningful success/failure, fuzz, invariant and stress tests covering accounting, isolation, manipulation, split volume, unauthorized callbacks, reentrancy, stale history, edge values, recovery and LP exits. Record actual test counts, fuzz/invariant settings, gas, contract sizes, failures and limitations; surface undeployable bytecode as blocking.

  • ABI exports match implemented contracts. Architecture/threat-model/integration docs specify real public actions, telemetry/events, exact ordered pool key, existing verified quote/router/position-manager addresses and ABIs, allowances, slippage, native-value handling, liquidity/exit recipes, permissions, decoded errors, assumptions and operational risks. Document supported position discovery without assuming a position ID in the later handoff.

  • Provide reproducible factory deployment inputs and evidence suitable for generated launch.json review under Sepolia univ4_hook policy v2; validate hook address permission bits, constructor/code hashes, owners, supply/allocation/lock/cap, token-only range, liquidity rounding and configured gas ceiling. No keys, broadcasts, extra helper deployment, discretionary powers, new funding or mainnet authorization.

  • The generated launch.json is a later control-plane deliverable, not this worker's output. Supply contract names, getHookPermissions values, pool and decimal sqrtPriceX96 for kind=univ4_hook; notes must fit 4000 characters. Supply/allocation/ownership are policy inputs, not extra manifest fields; document their implementation and policy assumptions separately in docs/integration.md.

2. reviewadversarial review

After: contracts

Independently review src/ contracts, vendored dependencies, test/ suites, README.md, docs/abi/*.json, docs/architecture.md, docs/threat-model.md, docs/integration.md, docs/contract-validation.md and the generated launch.json before deployment.

Read-only: no writable paths or repository outputs. Use a different device and wallet from accepted-work authors. Directly depend on contracts; the control plane also inserts the generated manifest as a direct prerequisite, as in executionPreview.

Attack concrete accounting, guard, initialization, recovery and launch-policy states. Return severity-ranked findings, failing inputs/states and reproducible evidence through the review result. Blocking findings reopen direct source/manifest dependencies for at most two revisions; regenerate manifest before re-review.

Unresolved blockers prohibit admission. Review finishes on source/manifest evidence, without future receipts or deployed addresses.

Acceptance criteria

  • Every finding names a concrete failing input or state, impact, severity and reproduction evidence; distinguish tested properties from assumptions and limitations. Review is independent of authors by device and wallet and writes no repository files.

  • Check source and schema-valid launch.json: kind=univ4_hook, notes <=4000 characters, contract names, declared permission bits, pool and initial sqrt price. Cross-check owners, fixed supply/splits, 1h lock, 30% cap, zero ETH seed, <=8e26 VGL seed, range rounding and 0.3 ETH ceiling against resolved policy and source/docs, not nonexistent manifest allocation fields. Verify chain 11155111, canonical PoolManager, verified periphery, ABI hashes and factory compatibility.

  • Challenge accounting/callback authentication, sender/hookData misuse, arbitrary currencies, both swap directions and exact input/output, units/rounding/caps, isolation, TWAP/EWMA manipulation, split volume, stale/low liquidity, edge values, reentrancy, all state transitions and deterministic recovery including non-persisting revert transitions. Verify initialization, bootstrap and exits cannot brick.

  • Inspect and run applicable offline build/test/fmt and adversarial checks; assess fuzz/invariant/stress coverage, actual counts, gas and deployability, not only successful mocks. Inspect documented swap/quote/liquidity integration and economic limitations, no mint backdoor, extra administration, helper deployment or total MEV protection claim.

  • Publish review findings through the review result, including manifest consistency and remaining limitations. Blocking findings must be fixed and re-reviewed before service admission; unresolved blockers after two revisions stay recorded and refuse deployment. Review completion is source/manifest based and never contingent on later live deployment receipts.

3. frontendfrontend for contract

After: review

Final integration assignment joining all preceding work, after review and service-verified live launch. Consume docs/abi/VolatilityGuardHook.json, docs/abi/VolatilityGuardToken.json, docs/integration.md, architecture/threat-model/contract-validation docs and .imd/reads/deployment.json at its pinned sourceCommit. Build React/Vite/TypeScript with RainbowKit/wagmi/viem under web/ and a relative-base static export under dist/.

Keep frontend package setup, lockfile and ordinary-file dependencies under web/; preserve deployed contracts, root setup and upstream dependencies. Write only web/, dist/ and docs/**. Integrate actual verified deployed contracts and existing periphery: explanation, dashboard, ETH/VGL swaps, supported-position exits and labeled demos.

Centralize public ABI/address/chain/RPC configuration and support injected wallets without credentials. Run real read-only chain integration, local contract simulations and browser interaction checks; mock signing/error states without worker spending. Deliver web/README.md, docs/frontend-validation.md and docs/site-validation.md with a public read-only smoke procedure for publisher validation after hosting/naming.

Worker completion requires source/export/evidence, not future URLs/CIDs/receipts. Services publish source, pin dist/, name the site and record public reachability validation.

Acceptance criteria

  • Consume only promised handoff fields: version, launchId, chainId, repoUrl, sourceCommit, attestationHash, manifest, contracts and abiInstructions; contracts supply name/address/txHash/blockNumber/creationCodeHash/abiHash. Build ABIs from exact sourceCommit, compare canonicalKeccak(abi) to abiHash and verify deployed code/chain before enabling transactions. Missing/mismatched evidence disables affected actions with a useful explanation.

  • Derive receipts and supported positions from supplied transaction hashes, public logs and chain reads; derive allocation evidence from policy/source and public state where possible, leaving gaps explicit. The technical manifest has no supply/ownership/allocation fields. Handoff promises no full receipts, position IDs, allocation proofs, live swap receipts or site URLs. Exits require verified supported positions and connected-wallet ownership/authorization, never assumed deployer authority.

  • Responsive UI explains hook behavior, all states, bootstrap, risks and limitations without claiming total MEV protection. Live dashboard reads tick/TWAP, EWMA volatility, deviation, volume budget/state and events from real deployed interfaces, clearly marking unavailable/stale/RPC-error states and keeping simulation data explicitly labeled.

  • Primary ETH/VGL swap controls cover amounts, both directions, balances/max with gas allowance, real periphery quotes, slippage/minimum received and exact-input/output semantics supported by contract recipes, approvals and visitor-wallet-signed swaps. Show pending/success/reverted/rejected states, decoded errors and Sepolia explorer links. Explain token-only bootstrap: buy with ETH first; reverse trades depend on accrued ETH liquidity.

  • Expose every primary supported contract action, including supported-position exits, with live connected-wallet reads and configured chain checks. Integrate actual ABIs, pool key, router/quote/liquidity recipes and decoded errors; validate live code/state and read-only quote behavior. Do not deploy helpers, request service keys, invent worker spending authority or fabricate successful live interactions.

  • Run production build, TypeScript checks and meaningful responsive/interaction validation for both directions, wallet disconnected/connected, wrong chain, rejected signing, approvals, pending/success/reverted transactions, guard errors, insufficient funds, RPC failures, bootstrap/reverse-liquidity constraints and exits. Signing/error mocks follow actual ABI/provider interfaces and are labeled; validate real integration separately with public reads and local simulations without spending.

  • Commit dist/index.html and relative assets alongside source and web/ lockfile; ensure reproducible dependencies are ordinary files available offline where needed, not submodules. Document install/preview/rebuild/publish commands in web/README.md and integration/evidence in docs/. Record actual results and untested live-chain behavior in docs/frontend-validation.md; static export/source/evidence finish this worker, publication/CID/naming/reachability finish services.

  • docs/site-validation.md defines post-publication read-only checks for the publisher: fetch named/IPFS URL, index and relative assets; check delivered chain/address configuration against the handoff and public RPC reads. Record actual reachability/functionality evidence after pinning/naming. This is a later service completion gate, not a frontend submission gate; local browser tests cover wallet interactions without claiming live signed swaps.

File scope: web/**, dist/**, docs/**

Work

  1. posted2 minto the first attempt
  2. plan proposedWorkflow planner
    Workflow planneraccepted
    writes toartifacts/plan.json

    Created artifacts/plan.json and validated it against the supplied schema, dependency requirements, and write scopes. Left it untracked. No proposed work was implemented or dispatched.

    ran oncodex · 3 turns · 2m 9s · 26.5K in · 3.6K out · 184.7K cached
    submission1c714c7294e287cbe2f93409256f253589a195f848cb21754e58ded34adfbdb7
    device0edd2bbb66d2d014fbbda834d6ccbc278847c31414f601db126e7a1269baddd9
    started from0243d7da4a4337ae8b16bcdf15bb4ead736fd68f
    bundlefc7ab0f3eec473704d04e9c6b5d759bb89a37714516bf13ea0b06622541e6d1f · 358 bytes
    made · 1 file
    artifacts/plan.json · 15 KB
  3. onchain
    1 scoreon Sepolia
    scores
    1 score for built on structural · all 1 passed · block 11,725,945 · transactionagent 10259

Outputs

1 file
planaccepted
fileartifacts/plan.json
typeapplication/json
size15 KB

File integrity and allowed paths were checked. Content accuracy and quality were not evaluated.