Skip to content

CMTAT v3.3.0-rc3 - #396

Open
rya-sge wants to merge 38 commits into
masterfrom
dev
Open

CMTAT v3.3.0-rc3#396
rya-sge wants to merge 38 commits into
masterfrom
dev

Conversation

@rya-sge

@rya-sge rya-sge commented Jul 24, 2026

Copy link
Copy Markdown
Collaborator

No description provided.

rya-sge added 30 commits July 24, 2026 12:50
…7) to prevent mint-path DoS, with regression tests
…hile paused or restricted (NM-3/NM-8), with regression tests
…lbacks (NM-6) in IRuleEngine NatSpec and

  integration notes
…in and that signers must use eip712Domain() (NM-21)
…oc/README pause Note with the per-path split (NM-20)
… size-permitting variants (NM-7/9/11/16/18), with a malicious-engine mock and per-variant docs
…ts, required by EIP-1153 transient storage in the RuleEngine reentrancy guard
…nce-spend-event technical note with the two-path consistency improvement (NM-24)
…nd trim the allowance-event issue to the remaining transferFrom/burnFrom unification (NM-24)
…sfer (NM-5) and document that freezing an operator blocks batchTransfer/transfers but not mint
…ler) to be allowlisted, and add a test that a non-allowlisted minter can still mint
…ender frozen, I-3/NM-3-8) and fix stale reentrancy-guard NatSpec in ValidationModuleRuleEngine
…ment page (I-5) and link/complete the Spend-event row in doc/README.md
…ite counts up to date (12 code fixes) and align AUDIT.md + README
…ry config and update USAGE/README/CHANGELOG (source pragma stays ^0.8.24)
…fer between existing holders does no SSTORE but still performs ~3 SLOADs (doc + NatSpec)
…se eth_call at a historical block; the Snapshot Engine is only needed on-chai
…use eth_call at a historical block; the Snapshot Engine is only needed on-chai
…ion-analyse, rescope it to a spec-vs-implementation comparison, and point porting to the CMTAT-equivalency-assessment rep
… from the root README, keeping the full tab in doc/security/AUDIT.md
…tTransferRestriction) and reworked-only Extension (detectTransferRestrictionFrom, spender path, new in v3.3.0)
…cumentEngine section — native DocumentERC1643Module vs external DocumentEngineModule, with functions, roles, events and a comparison table
…C-1363 = Standard base + ERC1363Upgradeable mixin, Light = level-0 CMTATBaseCore only
…ritance schemas, adding a full inheritance block (with schemas) to the Permit section
…n on Zama fhEVM) under official CMTA-managed implementations
…iew table (Aderyn, Slither, Mythril, Nethermind AuditAgent, Wake Arena) with latest run and outcome
rya-sge added 8 commits July 28, 2026 11:29
…nt remediation (fixes, reentrancy guard, docs, tests) and dependency bumps
…List to the Optional features list + update ERC schema
…3.0 → DocumentEngine v0.4.0 and mark v3.0.0–v3.2.0 as not developed
… through CMTAT (kills the spender!=address(0) mutant) with a recording engine mock; catalogue in Test.md
…n burn(uint256) is onlySelfBurn, EnforcementModule onlyEnforcer gates address-freeze(BugPoCer 4.3.4/4.3.7)
…nally survive deactivation (ERC-8343) and correct the absolute no operation after deactivation wording in README/stablecoin + NatSpec (BugPoCer 4.1.1, option 2)
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant