# Jing v6-3 deploy set + 3 swap vaults — pre-deploy audit **ZER0C00L crew.** Scope (as posted): `jing-contracts-v3` `df091b8` (markets-v6-3, router-v5-3, jing-core-v6, ladder-v1, dispatch, buy/sell-stx-core-spread-v1); juicestx `60ac298` (juice-pool-sbtc-signer, juice-sbtc-autoswap); fastpool `3e9262d` (fastpool-swap-vault); citycoins `1688dec` (ccd016-swap-vault-mia-v2). Sources from the pinned commits. Known-fixed items and the tx-sender/contract-caller proxy class excluded. ## Findings ### F1 — MEDIUM — 64-bit overflow window in `execute-fill` (markets; class D) `execute-fill` computes `x-from-y = (/ (* y-amt scale) price)` with `scale = 1e10` (~2766). Clarity multiplies first; uint is 64-bit, so the product aborts whenever `y-amt > (2^64-1)/1e10 ≈ 1.84e9` micro-STX — the division never happens. In the taker-walk the STX-side operand is the **taker's full remaining side** (`(execute-fill cycle takr rem maker ...)` at ~2960/~3001), not a per-maker slice. That threshold sits within ~2x of the vaults' `max-chunk-sats = 1e6` sats at current prices: a chunk clearing mostly through the book can overflow the multiply and abort the book leg at that size, silently pushing the flow to DLMM/XYK — and on the split paths the `min-stx-out` floor then reverts the whole sale (see F2). Fix: halve both factors before multiplying (`(/ y-amt u10) (* x (/ scale u10))` style), or cap the STX-side operand entering the walk. Verify with one stxer run: max-chunk taker, thin book. ### F2 — MEDIUM — vault `router-swap-split` cannot degrade when the book leg fails (class E) The market swap is de-facto fill-or-kill: `cross-remainder-as-y/x` ends with `(asserts! (< rem min-token-x-deposit) ERR_PARTIAL_FILL)` (~3270/~3340) — any residual ≥ the minimum deposit errors. The vault split paths (fastpool ~456, ccd016 ~616, juice ~393) build `min-stx-out` as `floor-out(jing+dlmm+xyk) + floor-out(velar)`, always *assuming the jing leg fills*. The router treats a market `err` as `none` and leaves the jing amount `unsold` (fills go AMM-only, as designed), so `out` lands under that floor and the **entire swap asserts**; the cooldown rolls back, but the DAO liquidation stalls until a human re-splits with `jing = u0`. Small fix: when `jing-ok` is false, subtract the jing leg's floor from `min-stx-out` (or use `fallback`), so a rejected book leg degrades like `router-swap` already does. ### F3 — MEDIUM — 80-second oracle gate coupled to a 24-hour maker penalty (class A) `MAX_STALENESS = u80`, enforced inside `verify-price-feeds`, so every deposit/settle/swap needs a feed younger than 80 s. A rung that can't settle its escrow falls back to `cancel-token-x-deposit`, and `push-to-market` then refuses until `escrow-cancelled-at + 86400` (~987). A Lazer outage or decoder bump longer than ~80 s therefore doesn't just pause the market: rungs mid-escrow cancel, and after the feed returns they are barred from pushing for 24 h while nothing settles meanwhile — a stale-free day costs a day and a day more of dark maker flow. The cooldown was built against escrow ping-pong but is armed by oracle unavailability; arm it only when a settle was attempted with a fresh update. ### F4 — LOW — `capacity-rebate-hint` decoded, never verified (class E) The hint (~3938) derives rebate bps from raw payload timestamps. The swap re-verifies, so no fee leakage — but a caller presenting an 80-s-old hint against a fresh envelope gets a quote up to 70 bps, `jing-size` sizes the leg at the inflated gross-cap, and the market then caps at the true lower cap: residual ≥ min-x → the F2 revert, residual < min → unintended AMM re-sell. Also `get-taker-capacity`'s `rebate-bps` output is hint-based, so UI quotes of "rebate you'll receive" can be wrong. Self-inflicted and bounded; worth a doc line and a frontend rule to only quote with the envelope it will submit. ### F5 — LOW — `dlmm-pick` ranks pools by whole-pool balance, not in-window depth (class E) The pick (~841-865) compares `stx-get-balance`/`sbtc-balance` of the pool principals — the **entire** pool, including bins far outside the 30-bin walk and outside the caller's limit. A pool with a rich far wing and a thin active bin beats one with dense in-range bins; the capacity walk then under-fills against the other pool. Capacity and swap agree within one tx, so no misfill — but it is the "wrong DLMM pick" case. Price-at-limit selection over active-bin balances near the walk window keeps the interface; show the read_count/runtime delta per swap on an stxer run as the bounty asks. ## Clean Reentrancy is structurally impossible in Clarity; sampled paths follow checks-effects-interactions (execute-fill decrements rebate vars before transfers). Authorization: hash-verified registration, owner-gated `set-verified-contract`, propose/accept two-step ownership in core/ladder/signer (`accept-owner` binds to pending; signer handoff asserts `contract-caller == new-admin`); vaults are POOL / `is-dao-or-extension` gated. Permissionless surfaces move fixed or whole-pool amounts; dispatch budget-validates allocations before any transfer, rejects duplicates, rolls back atomically. Rounding: withdraw ceil-rounds partial burns and forces full exit below 1 sat; `gross-up` ceilings; rebate crumbs refund via `left`. The `"sel-band"` pair in dispatch matches the ladder constant. `ccd016` allowing `dia-band-bps = 0` (cross-check off) is a key-management choice, not a flaw. **Ship priority:** fix F1 and F2 before deploy; F3 is a policy decision; F4/F5 polish.