Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Ape Staking Vault #399

Closed
wants to merge 54 commits into from
Closed

Ape Staking Vault #399

wants to merge 54 commits into from

Conversation

zhoujia6139
Copy link
Contributor

Security Checklist

  • 1. Re-Entrancy
  • 2. Arithmetic Over/Under Flows
  • 3. Unexpected Ether
  • 4. Delegatecall
  • 5. Default Visibilities
  • 6. Entropy Illusion
  • 7. External Contract Referencing
  • 8. Short Address/Parameter Attack (off chain)
  • 9. Unchecked CALL Return Values
  • 10. Race Conditions / Front Running
  • 11. Denial Of Service (DOS)
  • 12. Block Timestamp Manipulation
  • 13. Constructors with Care
  • 14. Uninitialized Storage Pointers
  • 15. Floating Points and Precision
  • 16. Tx.Origin Authentication
  • 17. Address.isContract Re-Entrancy via Constructor

⚠️ NOTES ⚠️

Make sure to think about each of these exploits in this PR.

zhoujia6139 and others added 2 commits July 3, 2023 11:21
* chore: receiver contract support claim without transfer

* update: batch transfer ERC721 from flash claim receiver

---------

Co-authored-by: rjman <[email protected]>
@zhoujia6139 zhoujia6139 requested a review from a team as a code owner July 3, 2023 14:45
@zhoujia6139 zhoujia6139 marked this pull request as draft July 3, 2023 14:45
zhoujia6139 and others added 26 commits July 27, 2023 13:48
…393)

* feat: add experimental code

Signed-off-by: GopherJ <[email protected]>

* fix: typo

Signed-off-by: GopherJ <[email protected]>

* fix: compilation

Signed-off-by: GopherJ <[email protected]>

* fix: use solc-docgen instead of forked one

Signed-off-by: GopherJ <[email protected]>

* feat: add back blur exchange

Signed-off-by: GopherJ <[email protected]>

* feat: add back uniswap

Signed-off-by: GopherJ <[email protected]>

* feat: add back seaport but comment selfdestruct related code

Signed-off-by: GopherJ <[email protected]>

* feat: unify version

Signed-off-by: GopherJ <[email protected]>

* feat: add back deleted contracts

Signed-off-by: GopherJ <[email protected]>

* fix: getFirstSigner

Signed-off-by: GopherJ <[email protected]>

* fix: deployment of simple contracts

Signed-off-by: GopherJ <[email protected]>

* fix: typo

Signed-off-by: GopherJ <[email protected]>

* fix: lint

Signed-off-by: GopherJ <[email protected]>

* fix: lint

Signed-off-by: GopherJ <[email protected]>

* fix: deployment

Signed-off-by: GopherJ <[email protected]>

* fix: libraries linking in non-zksync network

Signed-off-by: GopherJ <[email protected]>

* feat: add deploy:all-libraries task

Signed-off-by: GopherJ <[email protected]>

* chore: simplify zksync mainnet config

Signed-off-by: GopherJ <[email protected]>

* chore: output foundry verify-contract command

Signed-off-by: GopherJ <[email protected]>

* feat: store zk libraries into file

Signed-off-by: GopherJ <[email protected]>

* chore: support contract verification

Signed-off-by: GopherJ <[email protected]>

* fix: missing space

Signed-off-by: GopherJ <[email protected]>

* feat: add polygon zkevm experiment code (#394)

* feat: add polygon zkevm experiment code

Signed-off-by: GopherJ <[email protected]>

* fix: deploy

Signed-off-by: GopherJ <[email protected]>

---------

Signed-off-by: GopherJ <[email protected]>

* chore: rename to polygonMumbai

Signed-off-by: GopherJ <[email protected]>

* chore: add more polygon networks

Signed-off-by: GopherJ <[email protected]>

* feat: improve gas price

Signed-off-by: GopherJ <[email protected]>

* feat: refactor api & browser urls

Signed-off-by: GopherJ <[email protected]>

* feat: refactor api & browser urls

Signed-off-by: GopherJ <[email protected]>

* fix: contract size

Signed-off-by: GopherJ <[email protected]>

* chore: add etherscan keys

Signed-off-by: GopherJ <[email protected]>

* feat: add arbitrumGoerli

Signed-off-by: GopherJ <[email protected]>

* fix: dont verify UserFlashClaimRegistryProxy by default

Signed-off-by: GopherJ <[email protected]>

* feat: add arbitrumGoerli network

Signed-off-by: GopherJ <[email protected]>

* chore: remove rinkeby,kovan

Signed-off-by: GopherJ <[email protected]>

* feat: add matic, stMatic, crv

Signed-off-by: GopherJ <[email protected]>

* feat: simplify customChains config

Signed-off-by: GopherJ <[email protected]>

* fix: adjust to use type 0

Signed-off-by: GopherJ <[email protected]>

* fix: step 6

Signed-off-by: GopherJ <[email protected]>

* chore: add retry log

Signed-off-by: GopherJ <[email protected]>

* chore: refactor

Signed-off-by: GopherJ <[email protected]>

* chore: increase retres for zkevm & zksync

Signed-off-by: GopherJ <[email protected]>

* chore: remove extra space

Signed-off-by: GopherJ <[email protected]>

* chore: cleanup

Signed-off-by: GopherJ <[email protected]>

* feat: compile libraries from bottom to top

Signed-off-by: GopherJ <[email protected]>

* chore: improve anvil

Signed-off-by: GopherJ <[email protected]>

* chore: add more info

Signed-off-by: GopherJ <[email protected]>

* chore: add missing waitForTx

Signed-off-by: GopherJ <[email protected]>

* chore: improve tasks

Signed-off-by: GopherJ <[email protected]>

* chore: add wmatic

Signed-off-by: GopherJ <[email protected]>

* chore: remove matic

Signed-off-by: GopherJ <[email protected]>

* chore: format

Signed-off-by: GopherJ <[email protected]>

* chore: update emergency admins

Signed-off-by: GopherJ <[email protected]>

* feat: add polygon config

Signed-off-by: GopherJ <[email protected]>

* fix: lint

Signed-off-by: GopherJ <[email protected]>

* feat: add polygon multisig

Signed-off-by: GopherJ <[email protected]>

* fix: contract size

Signed-off-by: GopherJ <[email protected]>

* chore: update polygon admins

Signed-off-by: GopherJ <[email protected]>

* feat: add crv, stMatic oracle

Signed-off-by: GopherJ <[email protected]>

* feat: update stMatic, matic risk parameters

Signed-off-by: GopherJ <[email protected]>

* feat: add seaport for arbitrum,polygon

Signed-off-by: GopherJ <[email protected]>

* feat: update wmatic timelock

Signed-off-by: GopherJ <[email protected]>

* fix: missing UniV3 token address

Signed-off-by: GopherJ <[email protected]>

* chore: cleanup

Signed-off-by: GopherJ <[email protected]>

* chore: cleanup

Signed-off-by: GopherJ <[email protected]>

* feat: improve cmd

Signed-off-by: GopherJ <[email protected]>

* feat: support verify contract using forge

Signed-off-by: GopherJ <[email protected]>

* feat: improve zksync deployment

Signed-off-by: GopherJ <[email protected]>

* chore: simplify

Signed-off-by: GopherJ <[email protected]>

* chore: add walkdir

Signed-off-by: GopherJ <[email protected]>

* chore: rm zk-libraries during build

Signed-off-by: GopherJ <[email protected]>

* chore: simplify zksync goerli

Signed-off-by: GopherJ <[email protected]>

* fix: dont remove zk-libraries

Signed-off-by: GopherJ <[email protected]>

* fix: typo

Signed-off-by: GopherJ <[email protected]>

* fix: deps install

Signed-off-by: GopherJ <[email protected]>

* chore: add moonbase

Signed-off-by: GopherJ <[email protected]>

* chore: update moonbase wglmr address

Signed-off-by: GopherJ <[email protected]>

* chore: improve

Signed-off-by: GopherJ <[email protected]>

* chore: update moonbeam oracle config

Signed-off-by: GopherJ <[email protected]>

* fix: looksrare, blur

Signed-off-by: GopherJ <[email protected]>

* chore: rename

Signed-off-by: GopherJ <[email protected]>

* fix: lint

Signed-off-by: GopherJ <[email protected]>

* chore: add more assets

Signed-off-by: GopherJ <[email protected]>

* chore: add missing wglmr

Signed-off-by: GopherJ <[email protected]>

* feat: add stDOT, exrp

Signed-off-by: GopherJ <[email protected]>

* chore: update exrp param

Signed-off-by: GopherJ <[email protected]>

* chore: update moonbeam safe api

Signed-off-by: GopherJ <[email protected]>

* chore: support no timelock while decoding safe txs

Signed-off-by: GopherJ <[email protected]>

* feat: support L1, L2 rpc

Signed-off-by: GopherJ <[email protected]>

* chore: improve rpc url

Signed-off-by: GopherJ <[email protected]>

* chore: add extra info

Signed-off-by: GopherJ <[email protected]>

* chore: bump versions

Signed-off-by: GopherJ <[email protected]>

* chore: add script to list bytecode hashes

Signed-off-by: GopherJ <[email protected]>

* chore: tiny improve

Signed-off-by: GopherJ <[email protected]>

* chore: tiny improve

Signed-off-by: GopherJ <[email protected]>

* feat: increase zksync gas

Signed-off-by: GopherJ <[email protected]>

* fix: build

Signed-off-by: GopherJ <[email protected]>

* feat: add linea,lineaGoerli

Signed-off-by: GopherJ <[email protected]>

* chore: add linea config

Signed-off-by: GopherJ <[email protected]>

* chore: revert unused change

Signed-off-by: GopherJ <[email protected]>

* chore: update

Signed-off-by: GopherJ <[email protected]>

* chore: update retry params

Signed-off-by: GopherJ <[email protected]>

* feat: add missing gasLimit to create conduit

Signed-off-by: GopherJ <[email protected]>

* feat: add missing gasLimit to create conduit

Signed-off-by: GopherJ <[email protected]>

* fix: weth withdraw issue

Signed-off-by: GopherJ <[email protected]>

* chore: add redeploy market script

Signed-off-by: GopherJ <[email protected]>

* feat: add nft floor oracle abi

Signed-off-by: GopherJ <[email protected]>

* chore: dont update conduit controller channel in zksync

Signed-off-by: GopherJ <[email protected]>

* feat: update oracle config

Signed-off-by: GopherJ <[email protected]>

* chore: update zksync config

Signed-off-by: GopherJ <[email protected]>

* feat: add pyth

Signed-off-by: GopherJ <[email protected]>

* chore: remove verbose requirement

Signed-off-by: GopherJ <[email protected]>

* chore: update zksync config

Signed-off-by: GopherJ <[email protected]>

* feat: support deployer password

Signed-off-by: GopherJ <[email protected]>

* chore: add missing decimals

Signed-off-by: GopherJ <[email protected]>

* chore: add zksync, zksyncGoerli to etherscan network

Signed-off-by: GopherJ <[email protected]>

* feat: improve zksync contract verification

Signed-off-by: GopherJ <[email protected]>

* chore: improve set-timelock-strategy

Signed-off-by: GopherJ <[email protected]>

* chore: regenerate types after build

Signed-off-by: GopherJ <[email protected]>

* chore: support infura on linea

Signed-off-by: GopherJ <[email protected]>

* chore: add set price log

Signed-off-by: GopherJ <[email protected]>

* chore: support multichain etherscan key

Signed-off-by: GopherJ <[email protected]>

* chore: increase default blockGasLimit

Signed-off-by: GopherJ <[email protected]>

* fix: typo

Signed-off-by: GopherJ <[email protected]>

* fix: computeAddress

Signed-off-by: GopherJ <[email protected]>

* fix: uniswap v3 create2 address

Signed-off-by: GopherJ <[email protected]>

* fix: tests

Signed-off-by: GopherJ <[email protected]>

* fix: contract size

Signed-off-by: GopherJ <[email protected]>

* fix: tests

Signed-off-by: GopherJ <[email protected]>

* fix: missing filter

Signed-off-by: GopherJ <[email protected]>

* chore: add etherscan provider type

Signed-off-by: GopherJ <[email protected]>

* chore: refactor safeSdk & safeService fetch

Signed-off-by: GopherJ <[email protected]>

* chore: add missing verifiable network

Signed-off-by: GopherJ <[email protected]>

* chore: improve

Signed-off-by: GopherJ <[email protected]>

* chore: add missing xTokenTypes

Signed-off-by: GopherJ <[email protected]>

* feat: support foundry in make verify

Signed-off-by: GopherJ <[email protected]>

* feat: add contract name mapping for contract verification

Signed-off-by: GopherJ <[email protected]>

* fix: cyclic reference

Signed-off-by: GopherJ <[email protected]>

* fix: lint

Signed-off-by: GopherJ <[email protected]>

---------

Signed-off-by: GopherJ <[email protected]>
@zhoujia6139
Copy link
Contributor Author

Changes merged to #403

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants