Repository navigation
Audit package. No contract or circuit changes: the deployed bytecode is unchanged and still reproduces from this release byte-for-byte.
Commit under review: 1ffe0d46c38603b612b165c54de403a5002a0fa6
Start here
- AUDIT.md: scope (2,488 hand-written lines plus 7,395 generated verifier lines), how to tie this commit to the deployed contracts on both chains, deployments and governance, build and test commands, known issues and accepted risks, and where we would like you to look hardest.
- docs/DARK-CB-1.md: the protocol specification the code cites as
§n, with dated implementation notes wherever the deployed code differs from the text. - docs/THREAT-MODEL.md, docs/INVARIANTS.md, docs/MUTATIONS.md, docs/CIRCUITS-REPORT.md: contract threat model, invariants I1–I15 and their tests, the mutation report (44/44 killed), and circuit measurements.
Changes
- The design documents above, published for the first time.
- AUDIT.md includes a reproduction of the timelock's bytecode (OpenZeppelin
TimelockController), alongside the existing pin checks for the vault, registry, verifiers and libraries. - The mutation runner's report is gitignored, and its out-of-scope rows are described accurately.