code-423n4 / 2024-07-basin-findings

9 stars 6 forks source link

QA Report #88

Open howlbot-integration[bot] opened 3 months ago

howlbot-integration[bot] commented 3 months ago

See the markdown file with the details of this report here.

Brean0 commented 3 months ago

QA-01 - Agreed.

QA-02 - This report is correct given that the contest requested that the well upgradeable adhere to EIP-1822, but since then, the Basin Development Community has agreed that the benefits of deviating from the standard outweigh the benefits.

QA-03 Agreed.

QA-04 By definition, the LP token supply is the summation of the reserves when the reserves are equal. This can be seen in the stableswap invariant. At most, this may be off by 1 unit due to division error, which is acceptable. Without a test to validate this claim it's unclear how to proceed.

QA-05 It is up to the upgrader to insure that the new implementation is different. Damage here is limited to the upgrader.

c4-judge commented 2 months ago

alex-ppg marked the issue as grade-a

Rhaydden commented 2 months ago

Hi @alex-ppg, thank you for the judging. Please could you consider QA-01 a duplicate of #19 pending the finalization of PJQA?

alex-ppg commented 2 months ago

Hey @Rhaydden, thank you for your contribution! While it would indeed be a duplicate it will not be assigned an HM severity so the finding will remain within the QA report.

thebrittfactor commented 2 months ago

For awarding purposes, C4 staff have marked as 1st place and selected for report.