Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
28 commits
Select commit Hold shift + click to select a range
7047d1f
Prevent forced vault REP redemption
KillariDev Aug 26, 2026
4b1c361
Merge remote-tracking branch 'origin/main' into t3code/audit-solidity…
KillariDev Aug 26, 2026
d06d5dd
fix late escalation residual capture
KillariDev Aug 27, 2026
be09939
Merge remote-tracking branch 'origin/main' into t3code/audit-solidity…
KillariDev Aug 27, 2026
0d99a4f
stabilize reporting approval actions
KillariDev Aug 27, 2026
8f0870e
load escalation freeze for vault views
KillariDev Aug 27, 2026
d50c38f
clarify automatic vault loading
KillariDev Aug 27, 2026
b8f2821
prioritize terminal vault guidance
KillariDev Aug 27, 2026
eada9e4
cover truth auction vault guidance
KillariDev Aug 27, 2026
35c8a8b
Fix fixed-outcome child collateral operations
KillariDev Aug 29, 2026
a7b9e06
Fix late vault residual capture
KillariDev Aug 29, 2026
ff0d840
Fix capacity exit liquidation
KillariDev Aug 30, 2026
446a1cd
Merge remote-tracking branch 'origin/main' into t3code/audit-solidity…
KillariDev Aug 31, 2026
3f602ce
Merge remote-tracking branch 'origin/main' into t3code/audit-solidity…
KillariDev Aug 31, 2026
980da36
Close vault admission boundary after main merge
KillariDev Aug 31, 2026
be684a3
Merge remote-tracking branch 'origin/main' into t3code/audit-solidity…
KillariDev Aug 31, 2026
26cbb18
Merge remote-tracking branch 'origin/main' into t3code/audit-solidity…
KillariDev Aug 31, 2026
0c9157a
Prevent post-escrow collateral loss (#788)
KillariDev Aug 31, 2026
fc0472b
Document strict vault admission boundary
KillariDev Aug 31, 2026
c0f7a94
Merge remote-tracking branch 'origin/main' into t3code/audit-solidity…
KillariDev Aug 31, 2026
195b2ae
Merge branch 'main' into t3code/audit-solidity-exploit-round-4
KillariDev Aug 31, 2026
5910568
Merge branch 'main' into t3code/audit-solidity-exploit-round-4
KillariDev Aug 31, 2026
62fe7b0
Retry CI after transient runner failure
KillariDev Aug 31, 2026
76ce185
Merge remote-tracking branch 'origin/main' into t3code/audit-solidity…
KillariDev Aug 31, 2026
b3a4fa9
Merge PR base into audit solidity exploit round 5
KillariDev Aug 31, 2026
c7df775
Merge remote-tracking branch 'origin/main' into t3code/audit-solidity…
KillariDev Aug 31, 2026
e13fd0a
Merge remote-tracking branch 'origin/main' into t3code/audit-solidity…
KillariDev Aug 31, 2026
551a8b2
Fix AugurScan metadata freshness check
KillariDev Sep 1, 2026
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
15 changes: 14 additions & 1 deletion augurScan/config/abis.json
Original file line number Diff line number Diff line change
@@ -1,5 +1,5 @@
{
"sourceHash": "4a28ef122a390b3eff20a06824ba592450a4bcad59d2b55414a7029c81046712",
"sourceHash": "f5371811642485aabdfd08a5af62229cfb3cfc75e9330acb2d710b8b492370c8",
"contracts": {
"DeploymentStatusOracle": {
"source": "contracts/DeploymentStatusOracle.sol",
Expand Down Expand Up @@ -23164,6 +23164,19 @@
"stateMutability": "view",
"type": "function"
},
{
"inputs": [
{
"internalType": "uint256",
"name": "nextSettlementCollateralAttoEth",
"type": "uint256"
}
],
"name": "setValidatedSettlementCollateral",
"outputs": [],
"stateMutability": "payable",
"type": "function"
},
{
"inputs": [
{
Expand Down
5 changes: 4 additions & 1 deletion augurScan/config/manifests/mainnet.json
Original file line number Diff line number Diff line change
Expand Up @@ -34,6 +34,9 @@
["0x2BA90891589f443d1f146c3D25866f0c6871191C", "Deployment Status Oracle", "deploymentStatusOracle"],
["0x1E720f00d7Bb5D848513CCc1C18eCF4389E5f671", "Security Pool Factory", "securityPoolFactory"],
["0xf8f6eA0f2149b59CD56C4370Ab4ec4De8bb6BFd2", "Deployment Status Oracle", "deploymentStatusOracle"],
["0x13022CB4d0B53bCFF07B0EaaEC34c1969A81aa6C", "Deployment Status Oracle", "deploymentStatusOracle"]
["0x13022CB4d0B53bCFF07B0EaaEC34c1969A81aa6C", "Deployment Status Oracle", "deploymentStatusOracle"],
["0x88f345BaEaDBf2396Ce9428B0A9b81A5eeDF21Af", "Deployment Status Oracle", "deploymentStatusOracle"],
["0xf3684bD2423B02eD4b623cE92a3acF2C0bE06632", "Security Pool Forker", "securityPoolForker"],
["0x6abe652079D39490Dcdc6B054d111B97E1cee021", "Security Pool Factory", "securityPoolFactory"]
]
}
5 changes: 4 additions & 1 deletion augurScan/config/manifests/sepolia.json
Original file line number Diff line number Diff line change
Expand Up @@ -34,6 +34,9 @@
["0x00Ea7782173E7F04f90eF0376F77d55b90Aa7B61", "Deployment Status Oracle", "deploymentStatusOracle"],
["0x030004773B8FC48CE7AC79fa27ea10548237A949", "Security Pool Factory", "securityPoolFactory"],
["0x19138180CFb059b5695789e73c79bA300db03A3c", "Deployment Status Oracle", "deploymentStatusOracle"],
["0x20Af49DF3573ac604404a5E31c78e88683F80b71", "Deployment Status Oracle", "deploymentStatusOracle"]
["0x20Af49DF3573ac604404a5E31c78e88683F80b71", "Deployment Status Oracle", "deploymentStatusOracle"],
["0xf698EAF15DdFFb53c59EB87D11D049e7c6D4D980", "Deployment Status Oracle", "deploymentStatusOracle"],
["0x6fb8Da6212190F529eAD5D1fC7f9b87e75D03696", "Security Pool Forker", "securityPoolForker"],
["0x43228Ee091ECa19031a839DB099A002463607aAb", "Security Pool Factory", "securityPoolFactory"]
]
}
7 changes: 5 additions & 2 deletions augurScan/scripts/check-project-metadata.ts
Original file line number Diff line number Diff line change
@@ -1,4 +1,4 @@
import { access, mkdtemp, readFile, rm } from 'node:fs/promises'
import { access, copyFile, mkdir, mkdtemp, readFile, rm } from 'node:fs/promises'
import { tmpdir } from 'node:os'
import path from 'node:path'
import { contractSourceHash, contractSources } from './project-metadata-source.ts'
Expand All @@ -21,6 +21,9 @@ const artifactAvailable = await access(artifactPath).then(
if (artifactAvailable) {
const generatedRoot = await mkdtemp(path.join(tmpdir(), 'augurscan-metadata-'))
try {
const manifestPaths = ['manifests/mainnet.json', 'manifests/sepolia.json'] as const
await mkdir(path.join(generatedRoot, 'manifests'))
await Promise.all(manifestPaths.map((relativePath) => copyFile(path.join(projectRoot, 'config', relativePath), path.join(generatedRoot, relativePath))))
const generation = Bun.spawn(['bun', 'scripts/snapshot-project-metadata.ts', '--output-root', generatedRoot], {
cwd: projectRoot,
stdout: 'pipe',
Expand All @@ -29,7 +32,7 @@ if (artifactAvailable) {
const [exitCode, stdout, stderr] = await Promise.all([generation.exited, new Response(generation.stdout).text(), new Response(generation.stderr).text()])
if (exitCode !== 0) throw new Error(`Unable to generate augurScan metadata for comparison\n${stderr || stdout}`)
const stale: string[] = []
for (const relativePath of ['abis.json']) {
for (const relativePath of ['abis.json', ...manifestPaths]) {
const [expected, current] = await Promise.all([
readFile(path.join(generatedRoot, relativePath), 'utf8'),
readFile(path.join(projectRoot, 'config', relativePath), 'utf8'),
Expand Down
2 changes: 1 addition & 1 deletion docs/assets/js/docsSearchData.js

Large diffs are not rendered by default.

10 changes: 5 additions & 5 deletions docs/mainnet-deployment-addresses.json
Original file line number Diff line number Diff line change
Expand Up @@ -23,7 +23,7 @@
{
"id": "deploymentStatusOracle",
"label": "Deployment Status Oracle",
"address": "0x13022CB4d0B53bCFF07B0EaaEC34c1969A81aa6C"
"address": "0x88f345BaEaDBf2396Ce9428B0A9b81A5eeDF21Af"
},
{
"id": "multicall3",
Expand Down Expand Up @@ -73,7 +73,7 @@
{
"id": "securityPoolForker",
"label": "Security Pool Forker",
"address": "0x51cf207A931e76C837441dA3b70c57d71C62fF77"
"address": "0xf3684bD2423B02eD4b623cE92a3acF2C0bE06632"
},
{
"id": "escalationGameClaimDelegate",
Expand All @@ -88,14 +88,14 @@
{
"id": "securityPoolFactory",
"label": "Security Pool Factory",
"address": "0x1E720f00d7Bb5D848513CCc1C18eCF4389E5f671"
"address": "0x6abe652079D39490Dcdc6B054d111B97E1cee021"
}
],
"derivedContracts": [
{
"id": "securityPoolForker",
"label": "Security Pool Forker",
"address": "0x51cf207A931e76C837441dA3b70c57d71C62fF77"
"address": "0xf3684bD2423B02eD4b623cE92a3acF2C0bE06632"
},
{
"id": "escalationGameClaimDelegate",
Expand All @@ -110,7 +110,7 @@
{
"id": "securityPoolFactory",
"label": "Security Pool Factory",
"address": "0x1E720f00d7Bb5D848513CCc1C18eCF4389E5f671"
"address": "0x6abe652079D39490Dcdc6B054d111B97E1cee021"
},
{
"id": "escalationGameProofVerifier",
Expand Down
10 changes: 5 additions & 5 deletions docs/reference/contracts.html
Original file line number Diff line number Diff line change
Expand Up @@ -248,7 +248,7 @@ <h2 id="securitypool">SecurityPool</h2>
<tr>
<td><code>createCompleteSet()</code> with ETH</td>
<td>Trader</td>
<td>Operational and unforked; <code>isEscalationResolved()</code> is false; not awaiting continuation; positive ETH converts to at least one complete-set unit; live oracle-priced minting capacity covers the resulting settlement collateral, not merely this deposit; any explicit unassigned auction position remains healthy after the mint; under <a href="./security-model.html#assumption-a22">A22 asset-recipient compatibility</a>, a contract trader accepts <code>onERC1155BatchReceived</code>.</td>
<td>Operational and unforked; <code>isEscalationResolved()</code> is false; not awaiting continuation; positive ETH converts to at least one complete-set unit; live oracle-priced minting capacity covers the resulting settlement collateral, not merely this deposit; actual pool-held REP satisfies both live backing constraints for resulting collateral net of recorded bad debt, with dispute-staked REP counting only toward the associated-REP constraint; any explicit unassigned auction position remains healthy after the mint; under <a href="./security-model.html#assumption-a22">A22 asset-recipient compatibility</a>, a contract trader accepts <code>onERC1155BatchReceived</code>.</td>
<td>Adds collateral and mints one <code>Invalid</code>, <code>Yes</code>, and <code>No</code> share per complete-set unit, then invokes the ERC-1155 batch-receiver callback for a contract trader. Callback rejection rolls back the ETH, pool accounting, events, and share mint.</td>
<td><code>CompleteSetCreated</code>, <code>PoolAccountingCheckpoint</code>, then ERC-1155 <code>TransferBatch</code> on a successful callback</td>
</tr>
Expand Down Expand Up @@ -318,8 +318,8 @@ <h2 id="securitypool">SecurityPool</h2>
<tr>
<td><code>withdrawRepFromVault(vault, attoRepAmount)</code></td>
<td>This pool's <code>OpenOraclePriceCoordinator</code> only</td>
<td>Fresh coordinator price; operational pool in an unforked universe; <code>isEscalationResolved()</code> is false; no vault REP escrow; the remaining vault and aggregate pool totals each meet the upward-rounded associated-REP and free-REP backing requirements, with equality healthy.</td>
<td>Removes the requested proportional REP backing units, or all backing units when the requested remainder would fall below the REP minimum; proportionally reduces the vault and pool capacity ownership; recalculates retention; and transfers the resulting withdrawable REP to <code>vault</code>.</td>
<td>Fresh coordinator price; operational pool in an unforked universe; <code>isEscalationResolved()</code> is false; no vault REP escrow. A withdrawal that would reduce capacity ownership requires zero settlement collateral; a backing-only withdrawal does not. The remaining vault and aggregate pool totals each meet the upward-rounded associated-REP and free-REP backing requirements, with equality healthy.</td>
<td>Removes the requested proportional REP backing units, or all backing units when the requested remainder would fall below the REP minimum; proportionally reduces vault and pool capacity ownership when the vault has positive capacity ownership; recalculates retention; and transfers the resulting withdrawable REP to <code>vault</code>.</td>
<td>REP <code>Transfer</code>; <code>RepWithdrawnFromVault</code>; <code>VaultAccountingCheckpoint</code>; and applicable fee-accrual or retention <code>PoolAccountingCheckpoint</code> events</td>
</tr>
<tr>
Expand Down Expand Up @@ -409,7 +409,7 @@ <h2 id="securitypool">SecurityPool</h2>
<tr>
<td><code>setPoolFinancials(newSettlementCollateralAttoEth, newTotalCapacityOwnershipAttoRep, newFeeEligibleCapacityOwnershipAttoRep, newTotalBadDebtAttoEth)</code></td>
<td><code>SecurityPoolForker</code> only</td>
<td>Fee-eligible capacity ownership does not exceed total capacity ownership, and the supplied settlement collateral does not exceed the current price-converted minting capacity; no lifecycle or value-change guard.</td>
<td>Fee-eligible capacity ownership does not exceed total capacity ownership; supplied settlement collateral does not exceed the current price-converted minting capacity; actual pool-held REP satisfies both live backing constraints for supplied collateral net of supplied aggregate bad debt, with dispute-staked REP counting only toward the associated-REP constraint; no lifecycle or value-change guard.</td>
<td>Replaces settlement collateral, both price-independent capacity-ownership totals, and aggregate pool bad debt, resets the fee timestamp to the current block, and clears fee-index rounding carry.</td>
<td><code>PoolAccountingCheckpoint</code>, including for repeated financial values</td>
</tr>
Expand Down Expand Up @@ -520,7 +520,7 @@ <h3 id="child-game-trust-boundary">Child-game trust boundary</h3>
<tr>
<td><code>finalizeTruthAuction(securityPool)</code></td>
<td>Anyone</td>
<td>Truth auction started, its one-week window has passed, <code>msg.value</code> is zero, and migrated collateral plus accepted bid ETH does not exceed current price-converted minting capacity. If unresolved escalation existed at fork, the game reported at completion passes the <a href="#child-game-trust-boundary">child-game trust boundary</a>.</td>
<td>Truth auction started, its one-week window has passed, and <code>msg.value</code> is zero. Migrated collateral plus accepted bid ETH does not exceed current price-converted minting capacity, and actual pool-held REP satisfies both live backing constraints for that collateral net of aggregate bad debt; dispute-staked REP counts only toward the associated-REP constraint. If unresolved escalation existed at fork, the game reported at completion passes the <a href="#child-game-trust-boundary">child-game trust boundary</a>.</td>
<td>Finalizes the ended auction, accounts migration-routed settlement collateral plus accepted bid ETH, and records every unmigrated REP backing unit, capacity unit, and proportional bad debt in an explicit nonwithdrawable unassigned position. It activates the child, fixes bidder REP-backing-unit and capacity-ownership rates, and saves the fee index. Positive-purchase auction ownership becomes fee eligible immediately; after a zero-purchase auction, the unassigned capacity remains outside fee eligibility. A nonzero repair contribution is rejected.</td>
<td><code>TruthAuctionFinalized</code>, auction <code>AuctionFinalized</code>, and pool accounting checkpoints; <code>TruthAuctionHaircutApplied</code> when purchased REP removes a positive escalation allocation; <code>ForkContinuationResumed</code> for an unresolved continuation</td>
</tr>
Expand Down
9 changes: 5 additions & 4 deletions docs/reference/invariants.html
Original file line number Diff line number Diff line change
Expand Up @@ -706,11 +706,11 @@ <h2>Pool Assets, Shares, and Vaults</h2>
</div>
</details>
<details class="invariant-entry" id="bal-03">
<summary><code>BAL-03</code><span class="invariant-title">Collateral capacity</span></summary>
<summary><code>BAL-03</code><span class="invariant-title">Collateral capacity and backing</span></summary>
<div class="invariant-details">
<p class="invariant-label">Required property</p>
<div class="invariant-property">At a complete-set mint boundary, the resulting tracked collateral must fit the current ETH minting capacity derived from total REP-denominated capacity ownership, the live REP-per-ETH price, and the pool security multiplier. Finalized auction ownership enters total ownership, and positive-purchase ownership also enters fee eligibility and accrues fees whether or not a bidder has claimed it. Unassigned auction ownership can provide additional minting headroom only when its explicit position remains healthy after the mint. Existing open interest is not deleted when later repricing lowers live capacity, so this is not a continuous collateral-below-capacity invariant. Fee checkpointing and redemption cannot reclassify unsolicited ETH as collateral, and a price change reprices capacity without iterating through vaults.</div>
<p class="invariant-example"><strong>Example:</strong> If current oracle-priced capacity is 10 ETH, a mint that would raise tracked collateral from 9 ETH to 11 ETH reverts even if the raw balance contains surplus ETH. A later REP price change can lower capacity below 9 ETH without changing the existing open interest or ownership records.</p>
<div class="invariant-property">At a complete-set mint or fork-finalization boundary, the resulting tracked collateral must fit the current ETH minting capacity derived from total REP-denominated capacity ownership, the live REP-per-ETH price, and the pool security multiplier. The pool must also hold enough actual REP to satisfy both backing constraints for collateral net of recorded bad debt. Dispute-staked REP contributes to the associated-REP constraint but not the migration-safety constraint. Finalized auction ownership enters total ownership, and positive-purchase ownership also enters fee eligibility and accrues fees whether or not a bidder has claimed it. Unassigned auction ownership can provide additional minting headroom only when its explicit position remains healthy after the mint. Existing open interest is not deleted when later repricing lowers live capacity, so these are transaction-boundary checks rather than continuous collateral-below-capacity or live-backing invariants. Fee checkpointing and redemption cannot reclassify unsolicited ETH as collateral, and a price change reprices capacity without iterating through vaults.</div>
<p class="invariant-example"><strong>Example:</strong> If current oracle-priced capacity is 10 ETH, a mint that would raise tracked collateral from 9 ETH to 11 ETH reverts even if the raw balance contains surplus ETH. A mint within that 10 ETH capacity also reverts if unresolved escalation has moved too much REP out of the pool to cover the resulting active open interest. A later REP price change can lower capacity or backing below the checked boundary without changing existing open interest or ownership records.</p>
<dl class="invariant-metadata">
<div>
<dt>Type</dt>
Expand All @@ -723,7 +723,8 @@ <h2>Pool Assets, Shares, and Vaults</h2>
<div>
<dt>Primary evidence</dt>
<dd>
<a href="../../solidity/contracts/statoblast/SecurityPool.sol"><code>_requireCapacityNotExceeded</code>, <code>setPoolFinancials</code>, and fee redemption</a>,
<a href="../../solidity/contracts/statoblast/SecurityPool.sol"><code>_requireCapacityNotExceeded</code>, <code>setPoolFinancials</code>, and fee redemption</a>, <a href="../../solidity/contracts/statoblast/SecurityPoolLiquidationDelegate.sol"><code>setValidatedSettlementCollateral</code></a
>,
<a href="../../solidity/contracts/statoblast/SecurityPoolForker.sol">fork finalization</a>
</dd>
</div>
Expand Down
10 changes: 5 additions & 5 deletions docs/sepolia-deployment-addresses.json
Original file line number Diff line number Diff line change
Expand Up @@ -23,7 +23,7 @@
{
"id": "deploymentStatusOracle",
"label": "Deployment Status Oracle",
"address": "0x20Af49DF3573ac604404a5E31c78e88683F80b71"
"address": "0xf698EAF15DdFFb53c59EB87D11D049e7c6D4D980"
},
{
"id": "weth",
Expand Down Expand Up @@ -83,7 +83,7 @@
{
"id": "securityPoolForker",
"label": "Security Pool Forker",
"address": "0x3997130491272Bd1B8a3aa84Fcf5d238F2126eb4"
"address": "0x6fb8Da6212190F529eAD5D1fC7f9b87e75D03696"
},
{
"id": "escalationGameClaimDelegate",
Expand All @@ -98,14 +98,14 @@
{
"id": "securityPoolFactory",
"label": "Security Pool Factory",
"address": "0x030004773B8FC48CE7AC79fa27ea10548237A949"
"address": "0x43228Ee091ECa19031a839DB099A002463607aAb"
}
],
"derivedContracts": [
{
"id": "securityPoolForker",
"label": "Security Pool Forker",
"address": "0x3997130491272Bd1B8a3aa84Fcf5d238F2126eb4"
"address": "0x6fb8Da6212190F529eAD5D1fC7f9b87e75D03696"
},
{
"id": "escalationGameClaimDelegate",
Expand All @@ -120,7 +120,7 @@
{
"id": "securityPoolFactory",
"label": "Security Pool Factory",
"address": "0x030004773B8FC48CE7AC79fa27ea10548237A949"
"address": "0x43228Ee091ECa19031a839DB099A002463607aAb"
},
{
"id": "escalationGameProofVerifier",
Expand Down
Loading
Loading