SOURCE-ONLY Foundry prototype. GitHub contracts/tests/docs; NO deployment. ALL values/assets/wallets are LOCAL FIXTURES, not launch decisions.
SOURCE-ONLY Foundry prototype. GitHub contracts/tests/docs; NO deployment. ALL values/assets/wallets are LOCAL FIXTURES, not launch decisions. Token name: IMDAO Token symbol: IMDAO Total supply: 1,000,000 whole IMDAO, 18 decimals. Minting after launch: None; fixture mint/distribution/delegation to multiple voters, valueless liquidity. Transfer rules: OpenZeppelin ERC20Votes, block-number checkpoints; no tax/rebase/blacklist/pause/later mint. What each contract does: IMDAO/mock IMD Votes, restricted governor/timelock, v4 hook, treasury/recipient registry, V1/V2 policies, mock oracle. Who can call what: Anyone swaps/removes own liquidity; delegates propose/vote; governor queues/cancels; open execution. Timelock alone authorizes payout/enrollment/policy/oracle. Guardian ONLY suspends recipients. No admin/AI bypass. Numbers the contracts enforce: Fee/cap 25 bps additional to LP fee. Development/reserve V1 80/20, V2 60/40. Proposal threshold 10,000 base IMDAO at prior block; vote delay 1 block, duration 100 blocks; quorum 40,000 unboosted IMDAO FOR+ABSTAIN; weighted FOR>AGAINST. Timelock 3600 seconds. Per asset, lifetime gross payout caps: 10,000 whole units/recipient, 100,000 globally. One action/proposal. Oracle one pending, 3600-second timeout, zero payment. Upgrades and pausing: Only policy/recipient changes. No proxy/other upgrade/delegatecall/arbitrary call/trading pause. Suspension blocks payouts only. Token/hook/treasury/PoolId fixed. Outside services and values: Real local Uniswap v4 PoolManager/router; IMDAO/mock ERC20 pair, both 18 decimals. Separate mock IMD Votes: 18 decimals, not treasury asset. Fixture guardian; no live API/IMD/keys/ETH. VOTING Same past proposal snapshot: C=IMDAO.getPastVotes, I=mockIMD.getPastVotes; weight=C+min(floor(C/4),I). 18-decimal units; max 25% bonus, IMD alone zero. Threshold/quorum use C; base/weighted tallies separate. Both delegated; one vote/delegate/proposal, no current balances. Immutable fixture formula; delegated IMD power, NOT verified live holdings. Production checkpoints/escrow/chain/decimals/borrowing risk unresolved. AUTHORITY Proposal binds fixed target, zero value, canonical calldata and descriptionHash of frozen purpose/text/source links. ONLY allow hook.activatePolicy(candidate,codeHash), treasury.setRecipient(recipient,expectedVersion,enabled,metadataHash), treasury.pay(paymentId,asset,bucket,recipient,version,amount,purposeHash), oracle.request(questionHash). Reject other targets/selectors, batches, malformed/trailing data, timelock self-calls/role/delay changes. Governor sole proposer/canceller; execution open; timelock sole admin; remove bootstrap roles. Freeze/verify wiring; no reinitialization/cyclic constructors. Social/oracle confer no votes. Expose proposal/snapshot/deadline/tally/state events/views. Original proposer may cancel any unexecuted proposal. Direct timelock execution and governor wrappers share all checks/accounting. RECIPIENTS Start unapproved. Timelocked setRecipient requires current expectedVersion; each change increments version, clears acceptance and binds operator/purpose metadataHash. Enable creates PendingAcceptance; only recipient may accept current version to become Active. Disable blocks on execution. Guardian suspend increments version/blocks immediately; no enable/spend powers. Re-enable requires fresh governance/acceptance; stale enrollment proposals fail version check. Payment proposal/queue/execution require Active matching version, nonzero non-system recipient. Enroll BEFORE payment proposal; replacements need fresh enrollment, never edit payouts. Allowlisting proves no honesty/signer continuity; real operator/multisig verification deferred. FEES Authenticate manager/PoolId. afterSwap return-delta surcharge=floor(abs(unspecified delta)*25/10000), paid in unspecified currency. Prove signs/currency/slippage in both directions, exact-input/output. NOT verified IMD creator fees. manager.take sends settled cash to immutable treasury; hook alone credits exact receipt, never estimates/ERC6909 claims. Insufficient manager cash reverts; disclose limitation. development=floor(receipt*developmentBps/10000), remainder reserve; policy affects future FEES only. Raw transfers=unallocated surplus, not spendable income. No conversion/sweep/LP-principal claim. PAYOUTS Positive amount, supported asset/bucket, purpose hash. Nonzero paymentId binds one proposal forever. Queue atomically reserves asset/bucket cash AND recipient/global cap capacity and schedules timelock. Enforce grossPaid+reserved<=cap per asset across ALL buckets. No cap reset/netting on returns or re-enrollment, no cross-asset valuation. Record readyAt, expiresAt=readyAt+604800 seconds. Timelock alone pays exact reserved tuple at readyAt<=now<expiresAt; recheck recipient version/status. Consume bucket/reservation, increase gross paid, transfer once. Failure rolls back for retry/cancel. Each milestone needs a vote. Governor cancellation atomically cancels timelock/releases cash/cap reservations. Anyone can cancel queued payment if expired OR recipient version/status invalid; proposer may cancel earlier. No loops/replay. Target enforces expiry/status on direct execution. Nonpayments have no expiry. BUSINESS RETURNS returnUnspent(paymentId,amount,evidenceHash) and depositProceeds(paymentId,amount,evidenceHash): only original recipient of PAID payment, even if suspended. Pull positive amount of original payment asset from caller; credit exact receipt to original bucket. Cumulative returns<=original payout; proceeds uncapped, separate ledger. Unique receipt IDs/evidence hashes. Returns are recipient-declared; proceeds NOT audited profit. Never reduce gross cap usage/rewrite payments. Recipient approvals INTO treasury allowed, treasury approvals OUT forbidden. Donations stay surplus. No clawback/business/fiat/tax automation. ACCOUNTING Per asset: fees+returns+proceeds-grossPayments=development+reserve. Reservations INCLUDED in buckets, not extra liabilities; reserved<=bucket; cash>=buckets, excess=surplus. Solvency and exact sender debit AND recipient credit on every movement; SafeERC20, CEI, reentrancy protection, atomic rollback. No unsupported tokens. V1/V2 direct pure non-proxy policies, no mutable/external dependencies: pin both runtime hashes; activation verifies code/hash. Two weights sum to 10000; STATICCALL 30000 gas, bounded copying, exactly 64 bytes; invalid uses built-in 80/20. Cannot raise fees/redirect custody/alter old balances. ORACLE MOCK Timelock-only request with nonce/chain/consumer/question-bound ID; Pending/Answered/Expired; unanswered=UNKNOWN. Immutable delivery authenticates fixture responder; fixed-size boolean envelope, matching request/domain/question, Pending and now<expiry. Anyone expires at now>=expiry. Reject forged/malformed/duplicate/late answers; retries need fresh governance. Callback records evidence only, no spending/upgrades/calls; never in swap/LP paths. Not live IMD/truth proof. DELIVER/VERIFY Order: governance/registry/treasury, fees/payouts/returns, policies/oracle. src/, test/, README: ABIs/roles/states/fixtures/invariants/limitations/commands. Pin dependencies/solc=0.8.26/EVM. No FFI/filesystem/env/network cheatcodes. Run forge fmt --check, forge build, forge test; report results/static-analysis availability. Unit/fuzz/invariants: four real-manager swap cases, hook permissions/LP exits, unauthorized/bootstrap routes, snapshots/redelegation/bonus/quorum/double votes, enrollment/version races/suspension, cross-bucket caps, queue/cancel/expiry/direct-execution boundaries, failed transfer/retry/replay, returns/re-spend/cap persistence, proceeds/surplus/conservation, reentrancy/nonstandard tokens, policy/oracle faults. Freeze commit for independent review. No public deploy/sign/fund, website/imports/dispatch/buybacks/rewards. Document live IMD/fee/hook/oracle gaps, production voting/budget/guardian/multisig/migration gates. No launch-ready claims.
Who paid
0x6031…5a62
Launch
Requested false
Delivery
No repository URL on this job.
No site object on this job.
Nodes
- implementworking
build_contract_project
Attempt 2
Verdict: rejected · checks
Seat: #686
Reviews
No review batches on this job.