-
Notifications
You must be signed in to change notification settings - Fork 0
/
Copy pathjson-input.json
65 lines (65 loc) · 201 KB
/
json-input.json
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
{
"language": "Solidity",
"sources": {
"src/Pool.sol": {
"content": "// SPDX-License-Identifier: MIT\npragma solidity ^0.8.0;\n\nimport {Ownable} from \"solady/auth/Ownable.sol\";\nimport {ERC20} from \"solady/tokens/ERC20.sol\";\nimport {ReentrancyGuard} from \"solady/utils/ReentrancyGuard.sol\";\nimport {FixedPointMathLib} from \"solady/utils/FixedPointMathLib.sol\";\nimport {SafeTransferLib} from \"solady/utils/SafeTransferLib.sol\";\n\nimport {IRateProvider} from \"./RateProvider/IRateProvider.sol\";\nimport {LogExpMath} from \"./BalancerLibCode/LogExpMath.sol\";\nimport {PoolToken} from \"./PoolToken.sol\";\n\ncontract Pool is Ownable, ReentrancyGuard {\n uint256 constant PRECISION = 1_000_000_000_000_000_000;\n uint256 constant MAX_NUM_TOKENS = 32;\n uint256 constant ALL_TOKENS_FLAG =\n 14_528_991_250_861_404_666_834_535_435_384_615_765_856_667_510_756_806_797_353_855_100_662_256_435_713; // sum((i+1) << 8*i)\n uint256 constant POOL_VB_MASK = 2 ** 128 - 1;\n uint128 constant POOL_VB_SHIFT = 128;\n\n uint256 constant VB_MASK = 2 ** 96 - 1;\n uint256 constant RATE_MASK = 2 ** 80 - 1;\n uint128 constant RATE_SHIFT = 96;\n uint128 constant PACKED_WEIGHT_SHIFT = 176;\n\n uint256 constant WEIGHT_SCALE = 1_000_000_000_000;\n uint256 constant WEIGHT_MASK = 2 ** 20 - 1;\n uint128 constant TARGET_WEIGHT_SHIFT = 20;\n uint128 constant LOWER_BAND_SHIFT = 40;\n uint128 constant UPPER_BAND_SHIFT = 60;\n uint256 constant MAX_POW_REL_ERR = 100; // 1e-16\n\n /*´:°•.°+.*•´.*:˚.°*.˚•´.°:°•.°•.*•´.*:˚.°*.˚•´.°:°•.°+.*•´.*:*/\n /* ERRORS */\n /*.•°:°.´+˚.*°.˚:*.´•*.+°.•°:´*.´•*.•°.•°:°.´:•˚°.*°.˚:*.´+°.•*/\n\n error Pool__InputOutputTokensSame();\n error Pool__IndexOutOfBounds();\n error Pool__MaxLimitExceeded();\n error Pool__ZeroAmount();\n error Pool__MustBeInitiatedWithMoreThanOneToken();\n error Pool__MustBeInitiatedWithAGreaterThanZero();\n error Pool__InvalidParams();\n error Pool__CannotBeZeroAddress();\n error Pool__InvalidDecimals();\n error Pool__SumOfWeightsMustBeOne();\n error Pool__InvalidRateProvided();\n error Pool__NoConvergence();\n error Pool__RatioBelowLowerBound();\n error Pool__RatioAboveUpperBound();\n error Pool__SlippageLimitExceeded();\n error Pool__NeedToDepositAtleastOneToken();\n error Pool__InitialDepositAmountMustBeNonZero();\n error Pool__AmountsMustBeNonZero();\n error Pool__WeightOutOfBounds();\n error Pool__PoolIsFull();\n error Pool__RampActive();\n error Pool__PoolIsEmpty();\n error Pool__TokenAlreadyPartOfPool();\n error Pool__CannotRescuePoolToken();\n error Pool__BandsOutOfBounds();\n error Pool__WeightsDoNotAddUp();\n error Pool__AlreadyPaused();\n error Pool__NotPaused();\n error Pool__Killed();\n error Pool__NoSurplus();\n error Pool__NoRate();\n error Pool__Paused();\n\n /*´:°•.°+.*•´.*:˚.°*.˚•´.°:°•.°•.*•´.*:˚.°*.˚•´.°:°•.°+.*•´.*:*/\n /* EVENTS */\n /*.•°:°.´+˚.*°.˚:*.´•*.+°.•°:´*.´•*.•°.•°:°.´:•˚°.*°.˚:*.´+°.•*/\n event Swap(\n address indexed caller, address receiver, uint256 tokenIn, uint256 tokenOut, uint256 amountIn, uint256 amountOut\n );\n event AddLiquidity(address indexed caller, address receiver, uint256[] amountsIn, uint256 lpAmount);\n event RemoveLiquidity(address indexed caller, address receiver, uint256 lpAmount);\n event RemoveLiquiditySingle(\n address indexed caller, address receiver, uint256 token, uint256 amountOut, uint256 lpAmount\n );\n event RateUpdate(uint256 indexed token, uint256 rate);\n event Pause(address indexed caller);\n event Unpause(address indexed caller);\n event Kill();\n event AddToken(uint256 index, address token, address rateProvider, uint256 rate, uint256 weight, uint256 amount);\n event SetSwapFeeRate(uint256 rate);\n event SetWeightBand(uint256 indexed token, uint256 lower, uint256 upper);\n event SetRateProvider(uint256 token, address rateProvider);\n event SetRamp(uint256 amplification, uint256[] weights, uint256 duration, uint256 start);\n event SetRampStep(uint256 rampStep);\n event StopRamp();\n event SetStaking(address stakingAddress);\n event SetGuardian(address indexed caller, address guardian);\n\n uint256 public amplification; // A * f**n\n uint256 public numTokens;\n uint256 public supply;\n address public tokenAddress;\n address public stakingAddress;\n address[MAX_NUM_TOKENS] public tokens;\n address[MAX_NUM_TOKENS] public rateProviders;\n uint256[MAX_NUM_TOKENS] public packedVirtualBalances; // x_i = b_i r_i (96) | r_i (80) | w_i (20) | target w_i (20) | lower (20) | upper (20)\n bool public paused;\n bool public killed;\n uint256 public swapFeeRate;\n uint256 public rampStep;\n uint256 public rampLastTime;\n uint256 public rampStopTime;\n uint256 public targetAmplification;\n uint256 packedPoolVirtualBalance; // vbProd (128) | vbSum (128)\n // vbProd: pi, product term `product((w_i * D / x_i)^(w_i n))`\n // vbSum: sigma, sum term `sum(x_i)`\n\n /// @notice constructor\n /// @dev sum of all weights\n /// @dev rebasing tokens not supported\n /// @param tokenAddress_ address of the poolToken\n /// @param amplification_ the pool amplification factor (in 18 decimals)\n /// @param tokens_ array of addresses of tokens in the pool\n /// @param rateProviders_ array of addresses of rate providers for the tokens in the pool\n /// @param weights_ weight of each token (in 18 decimals)\n constructor(\n address tokenAddress_,\n uint256 amplification_,\n address[] memory tokens_,\n address[] memory rateProviders_,\n uint256[] memory weights_,\n address owner_\n ) {\n if (tokenAddress_ == address(0)) revert Pool__InvalidParams();\n uint256 _numTokens = tokens_.length;\n\n if (_numTokens > MAX_NUM_TOKENS) revert Pool__MaxLimitExceeded();\n\n if (_numTokens < 2) {\n revert Pool__MustBeInitiatedWithMoreThanOneToken();\n }\n if (rateProviders_.length != _numTokens || weights_.length != _numTokens) {\n revert Pool__InvalidParams();\n }\n if (amplification_ < PRECISION) {\n revert Pool__MustBeInitiatedWithAGreaterThanZero();\n }\n\n amplification = amplification_;\n numTokens = _numTokens;\n\n uint256 weightSum;\n\n for (uint256 t = 0; t < MAX_NUM_TOKENS; t++) {\n if (t == _numTokens) break;\n if (tokens_[t] == address(0)) {\n revert Pool__CannotBeZeroAddress();\n }\n if (ERC20(tokens_[t]).decimals() != 18) {\n revert Pool__InvalidDecimals();\n }\n tokens[t] = tokens_[t];\n if (rateProviders_[t] == address(0)) {\n revert Pool__CannotBeZeroAddress();\n }\n rateProviders[t] = rateProviders_[t];\n if (weights_[t] == 0) {\n revert Pool__InvalidParams();\n }\n uint256 _packedWeight = _packWeight(weights_[t], weights_[t], PRECISION, PRECISION);\n\n packedVirtualBalances[t] = _packVirtualBalance(0, 0, _packedWeight);\n\n weightSum += weights_[t];\n }\n\n if (weightSum != PRECISION) {\n revert Pool__SumOfWeightsMustBeOne();\n }\n\n rampStep = 1;\n _setOwner(owner_);\n\n tokenAddress = tokenAddress_;\n }\n\n /*´:°•.°+.*•´.*:˚.°*.˚•´.°:°•.°•.*•´.*:˚.°*.˚•´.°:°•.°+.*•´.*:*/\n /* POOL FUNCTIONS */\n /*.•°:°.´+˚.*°.˚:*.´•*.+°.•°:´*.´•*.•°.•°:°.´:•˚°.*°.˚:*.´+°.•*/\n\n /// @notice swap one pool token for another\n /// @param tokenIn_ index of the input token\n /// @param tokenOut_ index of the output token\n /// @param tokenInAmount_ amount of input token to take from the caller\n /// @param minTokenOutAmount_ minimum amount of output token to send\n /// @param receiver_ account to receive the output token\n /// @return the amount of output token\n function swap(\n uint256 tokenIn_,\n uint256 tokenOut_,\n uint256 tokenInAmount_,\n uint256 minTokenOutAmount_,\n address receiver_\n ) external nonReentrant returns (uint256) {\n uint256 _numTokens = numTokens;\n if (tokenIn_ == tokenOut_) revert Pool__InputOutputTokensSame();\n if (tokenIn_ >= _numTokens || tokenOut_ >= _numTokens) revert Pool__IndexOutOfBounds();\n if (tokenInAmount_ == 0) revert Pool__ZeroAmount();\n\n // update rates for from and to tokens\n (uint256 _virtualBalanceProd, uint256 _virtualBalanceSum) = _unpackPoolVirtualBalance(packedPoolVirtualBalance);\n (_virtualBalanceProd, _virtualBalanceSum) = _updateRates(\n FixedPointMathLib.rawAdd(tokenIn_, 1) | (FixedPointMathLib.rawAdd(tokenOut_, 1) << 8),\n _virtualBalanceProd,\n _virtualBalanceSum\n );\n\n uint256 _prevVirtualBalanceSum = _virtualBalanceSum;\n\n (uint256 _prevVirtualBalanceX, uint256 _rateX, uint256 _packedWeightX) =\n _unpackVirtualBalance(packedVirtualBalances[tokenIn_]);\n uint256 _weightTimesNOfX = _unpackWeightTimesN(_packedWeightX, _numTokens);\n\n (uint256 _prevVirtualBalanceY, uint256 _rateY, uint256 _packedWeightY) =\n _unpackVirtualBalance(packedVirtualBalances[tokenOut_]);\n uint256 _weightTimesNOfY = _unpackWeightTimesN(_packedWeightY, _numTokens);\n\n uint256 _tokenInFee = (tokenInAmount_ * swapFeeRate) / PRECISION;\n uint256 _changeInVirtualBalanceTokenIn = ((tokenInAmount_ - _tokenInFee) * _rateX) / PRECISION;\n uint256 _virtualBalanceX = _prevVirtualBalanceX + _changeInVirtualBalanceTokenIn;\n\n // update x_i and remove x_j from variables\n _virtualBalanceProd = _virtualBalanceProd * _powUp(_prevVirtualBalanceY, _weightTimesNOfY)\n / _powDown((_virtualBalanceX * PRECISION) / _prevVirtualBalanceX, _weightTimesNOfX);\n _virtualBalanceSum = _virtualBalanceSum + _changeInVirtualBalanceTokenIn - _prevVirtualBalanceY;\n\n // calculate new balance of out token\n uint256 _virtualBalanceY = _calculateVirtualBalance(\n _weightTimesNOfY, _prevVirtualBalanceY, supply, amplification, _virtualBalanceProd, _virtualBalanceSum\n );\n\n _virtualBalanceSum += _virtualBalanceY;\n\n // check bands\n _checkBands(\n (_prevVirtualBalanceX * PRECISION) / _prevVirtualBalanceSum,\n (_virtualBalanceX * PRECISION) / _virtualBalanceSum,\n _packedWeightX\n );\n _checkBands(\n (_prevVirtualBalanceY * PRECISION) / _prevVirtualBalanceSum,\n (_virtualBalanceY * PRECISION) / _virtualBalanceSum,\n _packedWeightY\n );\n\n uint256 _tokenOutAmount = ((_prevVirtualBalanceY - _virtualBalanceY) * PRECISION) / _rateY;\n if (_tokenOutAmount < minTokenOutAmount_) {\n revert Pool__SlippageLimitExceeded();\n }\n\n if (_tokenInFee > 0) {\n // add fee to pool\n _changeInVirtualBalanceTokenIn = (_tokenInFee * _rateX) / PRECISION;\n _virtualBalanceProd = (_virtualBalanceProd * PRECISION)\n / _powDown(\n (_virtualBalanceX + _changeInVirtualBalanceTokenIn) * PRECISION / _virtualBalanceX, _weightTimesNOfX\n );\n _virtualBalanceX += _changeInVirtualBalanceTokenIn;\n _virtualBalanceSum += _changeInVirtualBalanceTokenIn;\n }\n\n // update variables\n packedVirtualBalances[tokenIn_] = _packVirtualBalance(_virtualBalanceX, _rateX, _packedWeightX);\n packedVirtualBalances[tokenOut_] = _packVirtualBalance(_virtualBalanceY, _rateY, _packedWeightY);\n _virtualBalanceProd = (_virtualBalanceProd * PRECISION) / _powUp(_virtualBalanceY, _weightTimesNOfY);\n\n // mint fees\n if (_tokenInFee > 0) {\n uint256 _supply;\n (_supply, _virtualBalanceProd) = _updateSupply(supply, _virtualBalanceProd, _virtualBalanceSum);\n }\n\n packedPoolVirtualBalance = _packPoolVirtualBalance(_virtualBalanceProd, _virtualBalanceSum);\n\n // transfer tokens\n SafeTransferLib.safeTransferFrom(tokens[tokenIn_], msg.sender, address(this), tokenInAmount_);\n SafeTransferLib.safeTransfer(tokens[tokenOut_], receiver_, _tokenOutAmount);\n emit Swap(msg.sender, receiver_, tokenIn_, tokenOut_, tokenInAmount_, _tokenOutAmount);\n\n return _tokenOutAmount;\n }\n\n /// @notice deposit tokens into the pool\n /// @param amounts_ array of the amount for each token to take from caller\n /// @param minLpAmount_ minimum amount of lp tokens to mint\n /// @param receiver_ account to receive the lp tokens\n /// @return amount of LP tokens minted\n function addLiquidity(uint256[] calldata amounts_, uint256 minLpAmount_, address receiver_)\n external\n nonReentrant\n returns (uint256)\n {\n uint256 _numTokens = numTokens;\n if (amounts_.length != _numTokens) revert Pool__InvalidParams();\n\n (uint256 _virtualBalanceProd, uint256 _virtualBalanceSum) = _unpackPoolVirtualBalance(packedPoolVirtualBalance);\n\n uint256 _prevVirtualBalance;\n uint256 _rate;\n uint256 _packedWeight;\n\n // find lowest relative increase in balance\n uint256 _tokens = 0;\n uint256 _lowest = type(uint256).max;\n uint256 _sh;\n\n for (uint256 t = 0; t < MAX_NUM_TOKENS; t++) {\n if (t == _numTokens) break;\n\n uint256 __amount = amounts_[t];\n\n if (__amount > 0) {\n _tokens = _tokens | (FixedPointMathLib.rawAdd(t, 1) << _sh);\n _sh = FixedPointMathLib.rawAdd(_sh, 8);\n if (_virtualBalanceSum > 0 && _lowest > 0) {\n (_prevVirtualBalance, _rate, _packedWeight) = _unpackVirtualBalance(packedVirtualBalances[t]);\n _lowest = FixedPointMathLib.min(__amount * _rate / _prevVirtualBalance, _lowest);\n }\n } else {\n _lowest = 0;\n }\n }\n if (_sh == 0) revert Pool__NeedToDepositAtleastOneToken();\n\n // update rates\n (_virtualBalanceProd, _virtualBalanceSum) = _updateRates(_tokens, _virtualBalanceProd, _virtualBalanceSum);\n uint256 _prevSupply = supply;\n\n uint256 _virtualBalanceProdFinal = _virtualBalanceProd;\n uint256 _virtualBalanceSumFinal = _virtualBalanceSum;\n uint256 _prevVirtualBalanceSum = _virtualBalanceSum;\n uint256[] memory _prevRatios = new uint256[](_numTokens);\n uint256 _virtualBalance;\n\n for (uint256 t = 0; t < MAX_NUM_TOKENS; t++) {\n if (t == _numTokens) break;\n\n uint256 __amount = amounts_[t];\n\n if (__amount == 0) {\n if (!(_prevSupply > 0)) {\n revert Pool__InitialDepositAmountMustBeNonZero();\n }\n continue;\n }\n\n // update stored virtual balance\n (_prevVirtualBalance, _rate, _packedWeight) = _unpackVirtualBalance(packedVirtualBalances[t]);\n uint256 _changeInVirtualBalance = (__amount * _rate) / PRECISION;\n _virtualBalance = _prevVirtualBalance + _changeInVirtualBalance;\n packedVirtualBalances[t] = _packVirtualBalance(_virtualBalance, _rate, _packedWeight);\n\n if (_prevSupply > 0) {\n _prevRatios[t] = (_prevVirtualBalance * PRECISION) / _prevVirtualBalanceSum;\n uint256 _weightTimesN = _unpackWeightTimesN(_packedWeight, _numTokens);\n\n // update product and sum of virtual balances\n _virtualBalanceProdFinal = (\n _virtualBalanceProdFinal\n * _powUp((_prevVirtualBalance * PRECISION) / _virtualBalance, _weightTimesN)\n ) / PRECISION;\n\n // the `D^n` factor will be updated in `_calculateSupply()`\n _virtualBalanceSumFinal += _changeInVirtualBalance;\n\n // remove fees from balance and recalculate sum and product\n uint256 _fee = (\n (_changeInVirtualBalance - (_prevVirtualBalance * _lowest) / PRECISION) * (swapFeeRate / 2)\n ) / PRECISION;\n _virtualBalanceProd = (\n _virtualBalanceProd\n * _powUp((_prevVirtualBalance * PRECISION) / (_virtualBalance - _fee), _weightTimesN)\n ) / PRECISION;\n _virtualBalanceSum += _changeInVirtualBalance - _fee;\n }\n\n SafeTransferLib.safeTransferFrom(tokens[t], msg.sender, address(this), __amount);\n }\n\n uint256 _supply = _prevSupply;\n if (_prevSupply == 0) {\n // initial deposit, calculate necessary variables\n (_virtualBalanceProd, _virtualBalanceSum) = _calculateVirtualBalanceProdSum();\n if (!(_virtualBalanceProd > 0)) revert Pool__AmountsMustBeNonZero();\n _supply = _virtualBalanceSum;\n } else {\n // check bands\n for (uint256 t = 0; t < MAX_NUM_TOKENS; t++) {\n if (t == _numTokens) break;\n if (amounts_[t] == 0) continue;\n (_virtualBalance, _rate, _packedWeight) = _unpackVirtualBalance(packedVirtualBalances[t]);\n _checkBands(_prevRatios[t], (_virtualBalance * PRECISION) / _virtualBalanceSumFinal, _packedWeight);\n }\n }\n\n // mint LP tokens\n (_supply, _virtualBalanceProd) = _calculateSupply(\n _numTokens, _supply, amplification, _virtualBalanceProd, _virtualBalanceSum, _prevSupply == 0\n );\n uint256 _toMint = _supply - _prevSupply;\n\n if (!(_toMint > 0 && _toMint >= minLpAmount_)) {\n revert Pool__SlippageLimitExceeded();\n }\n PoolToken(tokenAddress).mint(receiver_, _toMint);\n emit AddLiquidity(msg.sender, receiver_, amounts_, _toMint);\n\n uint256 _supplyFinal = _supply;\n if (_prevSupply > 0) {\n // mint fees\n (_supplyFinal, _virtualBalanceProdFinal) = _calculateSupply(\n _numTokens, _prevSupply, amplification, _virtualBalanceProdFinal, _virtualBalanceSumFinal, true\n );\n PoolToken(tokenAddress).mint(stakingAddress, _supplyFinal - _supply);\n } else {\n _virtualBalanceProdFinal = _virtualBalanceProd;\n _virtualBalanceSumFinal = _virtualBalanceSum;\n }\n supply = _supplyFinal;\n\n packedPoolVirtualBalance = _packPoolVirtualBalance(_virtualBalanceProdFinal, _virtualBalanceSumFinal);\n return _toMint;\n }\n\n /// @notice withdraw tokens from the pool in a balanced manner\n /// @param lpAmount_ amount of lp tokens to burn\n /// @param minAmounts_ array of minimum amount of each token to send\n /// @param receiver_ account to receive the tokens\n function removeLiquidity(uint256 lpAmount_, uint256[] calldata minAmounts_, address receiver_)\n external\n nonReentrant\n {\n uint256 _numTokens = numTokens;\n\n if (minAmounts_.length != _numTokens || minAmounts_.length > MAX_NUM_TOKENS) revert Pool__InvalidParams();\n\n // update supply\n uint256 _prevSupply = supply;\n uint256 _supply = _prevSupply - lpAmount_;\n supply = _supply;\n PoolToken(tokenAddress).burn(msg.sender, lpAmount_);\n emit RemoveLiquidity(msg.sender, receiver_, lpAmount_);\n\n // update variables and transfer tokens\n uint256 _virtualBalanceProd = PRECISION;\n uint256 _virtualBalanceSum = 0;\n\n uint256 _prevVirtualBalance;\n uint256 _rate;\n uint256 _packedWeight;\n for (uint256 t = 0; t < MAX_NUM_TOKENS; t++) {\n if (t == _numTokens) break;\n\n (_prevVirtualBalance, _rate, _packedWeight) = _unpackVirtualBalance(packedVirtualBalances[t]);\n\n uint256 __weight = _unpackWeightTimesN(_packedWeight, 1);\n\n uint256 dVb = (_prevVirtualBalance * lpAmount_) / _prevSupply;\n uint256 vb = _prevVirtualBalance - dVb;\n packedVirtualBalances[t] = _packVirtualBalance(vb, _rate, _packedWeight);\n\n _virtualBalanceProd = FixedPointMathLib.rawDiv(\n FixedPointMathLib.rawMul(\n _virtualBalanceProd,\n _powDown(\n FixedPointMathLib.rawDiv(FixedPointMathLib.rawMul(_supply, __weight), vb),\n FixedPointMathLib.rawMul(__weight, _numTokens)\n )\n ),\n PRECISION\n );\n _virtualBalanceSum = FixedPointMathLib.rawAdd(_virtualBalanceSum, vb);\n\n uint256 amount = (dVb * PRECISION) / _rate;\n if (amount < minAmounts_[t]) revert Pool__SlippageLimitExceeded();\n SafeTransferLib.safeTransfer(tokens[t], receiver_, amount);\n }\n\n packedPoolVirtualBalance = _packPoolVirtualBalance(_virtualBalanceProd, _virtualBalanceSum);\n }\n\n /// @notice withdraw a single token from the pool\n /// @param token_ index of the token to withdraw\n /// @param lpAmount_ amount of lp tokens to burn\n /// @param minTokenOutAmount_ minimum amount of tokens to send\n /// @param receiver_ account to receive the token\n /// @return the amount of the token sent\n function removeLiquiditySingle(uint256 token_, uint256 lpAmount_, uint256 minTokenOutAmount_, address receiver_)\n external\n nonReentrant\n returns (uint256)\n {\n uint256 _numTokens = numTokens;\n if (token_ >= _numTokens) revert Pool__InvalidParams();\n\n // update rate\n (uint256 _virtualBalanceProd, uint256 _virtualBalanceSum) = _unpackPoolVirtualBalance(packedPoolVirtualBalance);\n (_virtualBalanceProd, _virtualBalanceSum) =\n _updateRates(FixedPointMathLib.rawAdd(token_, 1), _virtualBalanceProd, _virtualBalanceSum);\n uint256 _prevVirtualBalanceSum = _virtualBalanceSum;\n\n // update supply\n uint256 _prevSupply = supply;\n uint256 _newSupply = _prevSupply - lpAmount_;\n supply = _newSupply;\n PoolToken(tokenAddress).burn(msg.sender, lpAmount_);\n\n (uint256 _prevVirtualBalance, uint256 _rate, uint256 _packedWeight) =\n _unpackVirtualBalance(packedVirtualBalances[token_]);\n uint256 _weightTimesN = _unpackWeightTimesN(_packedWeight, _numTokens);\n\n // update variables\n _virtualBalanceProd = (_virtualBalanceProd * _powUp(_prevVirtualBalance, _weightTimesN)) / PRECISION;\n for (uint256 t = 0; t < MAX_NUM_TOKENS; t++) {\n if (t == _numTokens) break;\n _virtualBalanceProd = (_virtualBalanceProd * _newSupply) / _prevSupply;\n }\n _virtualBalanceSum = _virtualBalanceSum - _prevVirtualBalance;\n\n // calculate new balance of token\n uint256 _virtualBalance = _calculateVirtualBalance(\n _weightTimesN, _prevVirtualBalance, _newSupply, amplification, _virtualBalanceProd, _virtualBalanceSum\n );\n uint256 _changeInVirtualBalance = _prevVirtualBalance - _virtualBalance;\n uint256 _fee = _changeInVirtualBalance * swapFeeRate / 2 / PRECISION;\n _changeInVirtualBalance -= _fee;\n _virtualBalance += _fee;\n uint256 _tokenOutAmount = (_changeInVirtualBalance * PRECISION) / _rate;\n if (_tokenOutAmount < minTokenOutAmount_) {\n revert Pool__SlippageLimitExceeded();\n }\n\n // update variables\n packedVirtualBalances[token_] = _packVirtualBalance(_virtualBalance, _rate, _packedWeight);\n _virtualBalanceProd = (_virtualBalanceProd * PRECISION) / _powUp(_virtualBalance, _weightTimesN);\n _virtualBalanceSum = _virtualBalanceSum + _virtualBalance;\n\n for (uint256 t = 0; t < MAX_NUM_TOKENS; t++) {\n if (t == _numTokens) break;\n if (t == token_) {\n _checkBands(\n (_prevVirtualBalance * PRECISION) / _prevVirtualBalanceSum,\n (_virtualBalance * PRECISION) / _virtualBalanceSum,\n _packedWeight\n );\n } else {\n (uint256 _virtualBalanceLoop,, uint256 _packedWeightLoop) =\n _unpackVirtualBalance(packedVirtualBalances[t]);\n _checkBands(\n (_virtualBalanceLoop * PRECISION) / _prevVirtualBalanceSum,\n (_virtualBalanceLoop * PRECISION) / _virtualBalanceSum,\n _packedWeightLoop\n );\n }\n }\n\n if (_fee > 0) {\n // mint fee\n (_newSupply, _virtualBalanceProd) = _updateSupply(_newSupply, _virtualBalanceProd, _virtualBalanceSum);\n }\n\n packedPoolVirtualBalance = _packPoolVirtualBalance(_virtualBalanceProd, _virtualBalanceSum);\n\n SafeTransferLib.safeTransfer(tokens[token_], receiver_, _tokenOutAmount);\n\n emit RemoveLiquiditySingle(msg.sender, receiver_, token_, _tokenOutAmount, lpAmount_);\n return _tokenOutAmount;\n }\n\n /// @notice update the stored rate of any of the pool's tokens\n /// @dev if no assets are passed in, every asset will be updated\n /// @param tokens_ array of indices of tokens to update\n function updateRates(uint256[] calldata tokens_) external {\n uint256 _numTokens = numTokens;\n\n uint256 _tokens;\n for (uint256 t = 0; t < MAX_NUM_TOKENS; t++) {\n if (t == tokens_.length) break;\n if (tokens_[t] >= _numTokens) revert Pool__IndexOutOfBounds();\n _tokens = _tokens | ((tokens_[t] + 1) << (FixedPointMathLib.rawMul(8, t)));\n }\n\n if (tokens_.length == 0) _tokens = ALL_TOKENS_FLAG;\n (uint256 _virtualBalanceProd, uint256 _virtualBalanceSum) = _unpackPoolVirtualBalance(packedPoolVirtualBalance);\n (_virtualBalanceProd, _virtualBalanceSum) = _updateRates(_tokens, _virtualBalanceProd, _virtualBalanceSum);\n packedPoolVirtualBalance = _packPoolVirtualBalance(_virtualBalanceProd, _virtualBalanceSum);\n }\n\n /// @notice update weights and amplification factor, if possible\n /// @dev will only update the weights if a ramp is active and at least the minimum time step has been reached\n /// @return boolean to indicate whether the weights and amplification factor have been updated\n function updateWeights() external returns (bool) {\n _checkIfPaused();\n bool _updated = false;\n (uint256 _virtualBalanceProd, uint256 _virtualBalanceSum) = _unpackPoolVirtualBalance(packedPoolVirtualBalance);\n (_virtualBalanceProd, _updated) = _updateWeights(_virtualBalanceProd);\n if (_updated && _virtualBalanceSum > 0) {\n (, _virtualBalanceProd) = _updateSupply(supply, _virtualBalanceProd, _virtualBalanceSum);\n packedPoolVirtualBalance = _packPoolVirtualBalance(_virtualBalanceProd, _virtualBalanceSum);\n }\n return _updated;\n }\n\n /// @notice get the pool's virtual balance product (pi) and sum (sigma)\n /// @return tuple with product and sum\n function virtualBalanceProdSum() external view returns (uint256, uint256) {\n return _unpackPoolVirtualBalance(packedPoolVirtualBalance);\n }\n\n /// @notice get the virtual balance of a token\n /// @param token_ index of the token in the pool\n /// @return virtual balance of the token\n function virtualBalance(uint256 token_) external view returns (uint256) {\n if (token_ >= numTokens) revert Pool__IndexOutOfBounds();\n return packedVirtualBalances[token_] & VB_MASK;\n }\n\n /// @notice get the rate of an token\n /// @param token_ index of the token\n /// @return rate of the token\n function rate(uint256 token_) external view returns (uint256) {\n if (token_ >= numTokens) revert Pool__IndexOutOfBounds();\n return (packedVirtualBalances[token_] >> RATE_SHIFT) & RATE_MASK;\n }\n\n /// @notice get the weight of a token\n /// @dev does not take into account any active ramp\n /// @param token_ index of the token\n /// @return tuple with weight, target weight, lower band width, upper weight band width\n function weight(uint256 token_) external view returns (uint256, uint256, uint256, uint256) {\n if (token_ >= numTokens) revert Pool__IndexOutOfBounds();\n (uint256 _weight, uint256 _target, uint256 _lower, uint256 _upper) =\n _unpackWeight(packedVirtualBalances[token_] >> PACKED_WEIGHT_SHIFT);\n if (rampLastTime == 0) _target = _weight;\n return (_weight, _target, _lower, _upper);\n }\n\n /// @notice get the packed weight of a token in a packed format\n /// @dev does not take into account any active ramp\n /// @param token_ index of the token\n /// @return weight in packed format\n function packedWeight(uint256 token_) external view returns (uint256) {\n if (token_ >= numTokens) revert Pool__IndexOutOfBounds();\n return packedVirtualBalances[token_] >> PACKED_WEIGHT_SHIFT;\n }\n\n /*´:°•.°+.*•´.*:˚.°*.˚•´.°:°•.°•.*•´.*:˚.°*.˚•´.°:°•.°+.*•´.*:*/\n /* ADMIN FUNCTIONS */\n /*.•°:°.´+˚.*°.˚:*.´•*.+°.•°:´*.´•*.•°.•°:°.´:•˚°.*°.˚:*.´+°.•*/\n\n /// @notice pause the pool\n function pause() external onlyOwner {\n if (paused) revert Pool__AlreadyPaused();\n paused = true;\n emit Pause(msg.sender);\n }\n\n /// @notice unpause the pool\n function unpause() external onlyOwner {\n if (!paused) revert Pool__NotPaused();\n if (killed) revert Pool__Killed();\n paused = false;\n emit Unpause(msg.sender);\n }\n\n /// @notice kill the pool\n function kill() external onlyOwner {\n if (!paused) revert Pool__NotPaused();\n if (killed) revert Pool__Killed();\n killed = true;\n emit Kill();\n }\n\n /// @notice add a new token to the pool\n /// @dev can only be called if no ramp is currently active\n /// @dev every other token will their weight reduced pro rata\n /// @dev caller should assure that amplification before and after the call are the same\n /// @param token_ address of the token to add\n /// @param rateProvider_ rate provider for the token\n /// @param weight_ weight of the new token\n /// @param lower_ lower band width\n /// @param upper_ upper band width\n /// @param amount_ amount of tokens\n /// @param amplification_ new pool amplification factor\n /// @param receiver_ account to receive the lp tokens minted\n function addToken(\n address token_,\n address rateProvider_,\n uint256 weight_,\n uint256 lower_,\n uint256 upper_,\n uint256 amount_,\n uint256 amplification_,\n uint256 minLpAmount_,\n address receiver_\n ) external onlyOwner {\n if (amount_ == 0) revert Pool__ZeroAmount();\n uint256 _prevNumTokens = numTokens;\n if (_prevNumTokens >= MAX_NUM_TOKENS) revert Pool__PoolIsFull();\n if (amplification_ == 0) revert Pool__ZeroAmount();\n if (rampLastTime != 0) revert Pool__RampActive();\n if (supply == 0) revert Pool__PoolIsEmpty();\n\n if (!(weight_ > 0 && weight_ <= PRECISION / 100)) {\n revert Pool__InvalidParams();\n }\n if (lower_ > PRECISION || upper_ > PRECISION) {\n revert Pool__InvalidParams();\n }\n\n // update weights for existing tokens\n uint256 _numTokens = _prevNumTokens + 1;\n uint256 _virtualBalance;\n uint256 _rate;\n uint256 _packedWeight;\n uint256 _prevWeight;\n uint256 _target;\n uint256 _lower;\n uint256 _upper;\n\n for (uint256 t = 0; t < MAX_NUM_TOKENS; t++) {\n if (t == _prevNumTokens) break;\n if (tokens[t] == token_) revert Pool__TokenAlreadyPartOfPool();\n (_virtualBalance, _rate, _packedWeight) = _unpackVirtualBalance(packedVirtualBalances[t]);\n (_prevWeight, _target, _lower, _upper) = _unpackWeight(_packedWeight);\n _packedWeight = _packWeight(\n FixedPointMathLib.rawSub(\n _prevWeight, FixedPointMathLib.rawDiv(FixedPointMathLib.rawMul(_prevWeight, weight_), PRECISION)\n ),\n _target,\n _lower,\n _upper\n );\n packedVirtualBalances[t] = _packVirtualBalance(_virtualBalance, _rate, _packedWeight);\n }\n\n if (ERC20(token_).decimals() != 18) revert Pool__InvalidParams();\n _rate = IRateProvider(rateProvider_).rate(token_);\n if (_rate == 0) revert Pool__NoRate();\n\n _virtualBalance = (amount_ * _rate) / PRECISION;\n _packedWeight = _packWeight(weight_, weight_, _lower, _upper);\n\n // set parameters for new token\n numTokens = _numTokens;\n tokens[_prevNumTokens] = token_;\n rateProviders[_prevNumTokens] = rateProvider_;\n packedVirtualBalances[_prevNumTokens] = _packVirtualBalance(_virtualBalance, _rate, _packedWeight);\n\n // recalculate variables\n (uint256 _virtualBalanceProd, uint256 _virtualBalanceSum) = _calculateVirtualBalanceProdSum();\n\n // update supply\n uint256 _prevSupply = supply;\n uint256 __supply;\n (__supply, _virtualBalanceProd) = _calculateSupply(\n _numTokens, _virtualBalanceSum, amplification_, _virtualBalanceProd, _virtualBalanceSum, true\n );\n\n amplification = amplification_;\n supply = __supply;\n packedPoolVirtualBalance = _packPoolVirtualBalance(_virtualBalanceProd, _virtualBalanceSum);\n\n SafeTransferLib.safeTransferFrom(token_, msg.sender, address(this), amount_);\n if (__supply <= _prevSupply) revert Pool__InvalidParams();\n uint256 _lpAmount = FixedPointMathLib.rawSub(__supply, _prevSupply);\n if (_lpAmount < minLpAmount_) revert Pool__InvalidParams();\n PoolToken(tokenAddress).mint(receiver_, _lpAmount);\n emit AddToken(_prevNumTokens, token_, rateProvider_, _rate, weight_, amount_);\n }\n\n /// @notice rescue tokens from this contract\n /// @dev cannot be used to rescue pool tokens\n /// @param token_ the token to be rescued\n /// @param receiver_ receiver of the rescued tokens\n function rescue(address token_, address receiver_) external onlyOwner {\n uint256 _numTokens = numTokens;\n for (uint256 t = 0; t < MAX_NUM_TOKENS; t++) {\n if (t == _numTokens) break;\n if (!(token_ != tokens[t])) revert Pool__CannotRescuePoolToken();\n }\n uint256 _amount = ERC20(token_).balanceOf(address(this));\n SafeTransferLib.safeTransfer(token_, receiver_, _amount);\n }\n\n /// @notice skim surplus of a pool token\n /// @param token_ index of the token\n /// @param receiver_ receiver of the skimmed tokens\n function skim(uint256 token_, address receiver_) external onlyOwner {\n if (token_ >= numTokens) revert Pool__IndexOutOfBounds();\n (uint256 _virtualBalance, uint256 _rate,) = _unpackVirtualBalance(packedVirtualBalances[token_]);\n uint256 _expected = (_virtualBalance * PRECISION) / _rate + 1;\n address _token = tokens[token_];\n uint256 _actual = ERC20(_token).balanceOf(address(this));\n if (_actual <= _expected) revert Pool__NoSurplus();\n SafeTransferLib.safeTransfer(_token, receiver_, _actual - _expected);\n }\n\n /// @notice set new swap fee rate\n /// @param feeRate_ new swap fee rate (in 18 decimals)\n function setSwapFeeRate(uint256 feeRate_) external onlyOwner {\n if (feeRate_ > PRECISION / 100) revert Pool__InvalidParams();\n swapFeeRate = feeRate_;\n emit SetSwapFeeRate(feeRate_);\n }\n\n /// @notice set safeft weight bands, if any user operation puts the weight outside of the bands, the transaction will revert\n /// @param tokens_ array of indices of the tokens to set the bands for\n /// @param lower_ array of widths of the lower band\n /// @param upper_ array of widths of the upper band\n function setWeightBands(uint256[] calldata tokens_, uint256[] calldata lower_, uint256[] calldata upper_)\n external\n onlyOwner\n {\n if (!(lower_.length == tokens_.length && upper_.length == tokens_.length)) revert Pool__InvalidParams();\n\n uint256 _numTokens = numTokens;\n for (uint256 t = 0; t < MAX_NUM_TOKENS; t++) {\n if (t == tokens_.length) break;\n uint256 _token = tokens_[t];\n if (_token >= _numTokens) revert Pool__IndexOutOfBounds();\n if (!(lower_[t] <= PRECISION && upper_[t] <= PRECISION)) {\n revert Pool__BandsOutOfBounds();\n }\n\n (uint256 _virtualBalance, uint256 _rate, uint256 _packedWeight) =\n _unpackVirtualBalance(packedVirtualBalances[_token]);\n (uint256 _weight, uint256 _target,,) = _unpackWeight(_packedWeight);\n _packedWeight = _packWeight(_weight, _target, lower_[t], upper_[t]);\n packedVirtualBalances[_token] = _packVirtualBalance(_virtualBalance, _rate, _packedWeight);\n emit SetWeightBand(_token, lower_[t], upper_[t]);\n }\n }\n\n /// @notice set a rate provider for a token\n /// @param token_ index of the token\n /// @param rateProvider_ new rate provider for the token\n function setRateProvider(uint256 token_, address rateProvider_) external onlyOwner {\n if (token_ >= numTokens) revert Pool__IndexOutOfBounds();\n\n rateProviders[token_] = rateProvider_;\n (uint256 _virtualBalanceProd, uint256 _virtualBalanceSum) = _unpackPoolVirtualBalance(packedPoolVirtualBalance);\n (_virtualBalanceProd, _virtualBalanceSum) = _updateRates(token_ + 1, _virtualBalanceProd, _virtualBalanceSum);\n packedPoolVirtualBalance = _packPoolVirtualBalance(_virtualBalanceProd, _virtualBalanceSum);\n emit SetRateProvider(token_, rateProvider_);\n }\n\n /// @notice schedule an amplification and/or weight change\n /// @dev effective amplification at any time is `amplification/f^n`\n /// @param amplification_ new amplification factor (in 18 decimals)\n /// @param weights_ array of the new weight for each token (in 18 decimals)\n /// @param duration_ duration of the ramp (in seconds)\n /// @param start_ ramp start time\n function setRamp(uint256 amplification_, uint256[] calldata weights_, uint256 duration_, uint256 start_)\n external\n onlyOwner\n {\n uint256 _numTokens = numTokens;\n if (amplification_ == 0) revert Pool__InvalidParams();\n if (weights_.length != _numTokens) revert Pool__InvalidParams();\n if (start_ < block.timestamp) revert Pool__InvalidParams();\n\n bool _updated;\n (uint256 _virtualBalanceProd, uint256 _virtualBalanceSum) = _unpackPoolVirtualBalance(packedPoolVirtualBalance);\n (_virtualBalanceProd, _updated) = _updateWeights(_virtualBalanceProd);\n if (_updated) {\n uint256 _supply;\n (_supply, _virtualBalanceProd) = _updateSupply(supply, _virtualBalanceProd, _virtualBalanceSum);\n packedPoolVirtualBalance = _packPoolVirtualBalance(_virtualBalanceProd, _virtualBalanceSum);\n }\n\n if (rampLastTime != 0) revert Pool__RampActive();\n\n rampLastTime = start_;\n rampStopTime = start_ + duration_;\n\n targetAmplification = amplification_;\n\n uint256 _total;\n\n for (uint256 t = 0; t < MAX_NUM_TOKENS; t++) {\n if (t == _numTokens) break;\n uint256 _newWeight = weights_[t];\n if (_newWeight >= PRECISION) revert Pool__WeightOutOfBounds();\n _total += _newWeight;\n\n (uint256 _virtualBalance, uint256 _rate, uint256 _packedWeight) =\n _unpackVirtualBalance(packedVirtualBalances[t]);\n\n (uint256 _weight,, uint256 _lower, uint256 _upper) = _unpackWeight(_packedWeight);\n\n _packedWeight = _packWeight(_weight, _newWeight, _lower, _upper);\n packedVirtualBalances[t] = _packVirtualBalance(_virtualBalance, _rate, _packedWeight);\n }\n\n if (_total != PRECISION) revert Pool__WeightsDoNotAddUp();\n emit SetRamp(amplification_, weights_, duration_, start_);\n }\n\n /// @notice set the minimum time b/w ramp step\n /// @param rampStep_ minimum step time (in seconds)\n function setRampStep(uint256 rampStep_) external onlyOwner {\n if (rampStep_ == 0) revert Pool__InvalidParams();\n rampStep = rampStep_;\n emit SetRampStep(rampStep_);\n }\n\n /// @notice stop an active ramp\n function stopRamp() external onlyOwner {\n rampLastTime = 0;\n rampStopTime = 0;\n emit StopRamp();\n }\n\n /// @notice set the address that receives yield, slashings and swap fees\n /// @param stakingAddress_ new staking address\n function setStaking(address stakingAddress_) external onlyOwner {\n if (stakingAddress_ == address(0)) revert Pool__InvalidParams();\n stakingAddress = stakingAddress_;\n emit SetStaking(stakingAddress_);\n }\n\n /*´:°•.°+.*•´.*:˚.°*.˚•´.°:°•.°•.*•´.*:˚.°*.˚•´.°:°•.°+.*•´.*:*/\n /* INTERNAL FUNCTIONS */\n /*.•°:°.´+˚.*°.˚:*.´•*.+°.•°:´*.´•*.•°.•°:°.´:•˚°.*°.˚:*.´+°.•*/\n\n /// @notice update rates of specific tokens\n /// @dev loops through the bytes in `token_` until a zero or a number larger than the number of assets is encountered\n /// @dev update weights (if needed) prior to checking any rates\n /// @dev will recalculate supply and mint/burn to staking contract if any weight or rate has updated\n /// @dev will revert if any rate increases by more than 10%, unless called by management\n /// @param tokens_ integer where each byte represents a token index offset by one\n /// @param virtualBalanceProd_ product term (pi) before update\n /// @param virtualBalanceSum_ sum term (sigma) before update\n /// @return tuple with new product and sum term\n function _updateRates(uint256 tokens_, uint256 virtualBalanceProd_, uint256 virtualBalanceSum_)\n internal\n returns (uint256, uint256)\n {\n _checkIfPaused();\n\n uint256 _virtualBalanceSum = virtualBalanceSum_;\n (uint256 _virtualBalanceProd, bool _updated) = _updateWeights(virtualBalanceProd_);\n\n uint256 _numTokens = numTokens;\n for (uint256 t = 0; t < MAX_NUM_TOKENS; t++) {\n uint256 token = (tokens_ >> FixedPointMathLib.rawMul(8, t)) & 255;\n if (token == 0 || token > _numTokens) {\n break;\n }\n token = FixedPointMathLib.rawSub(token, 1);\n address provider = rateProviders[token];\n\n (uint256 _prevVirtualBalance, uint256 _prevRate, uint256 _packedWeight) =\n _unpackVirtualBalance(packedVirtualBalances[token]);\n\n uint256 _rate = IRateProvider(provider).rate(tokens[token]);\n\n if (!(_rate > 0)) revert Pool__InvalidRateProvided();\n\n // no rate change\n if (_rate == _prevRate) continue;\n\n // cap upward rate movement to 10%\n if (_rate > (_prevRate * 11) / 10 && _prevRate > 0) {\n _checkOwner();\n }\n\n uint256 _virtualBalance;\n if (_prevRate > 0 && _virtualBalanceSum > 0) {\n // factor out old rate and factor in new rate\n uint256 weightTimesN = _unpackWeightTimesN(_packedWeight, _numTokens);\n _virtualBalanceProd =\n (_virtualBalanceProd * _powUp((_prevRate * PRECISION) / _rate, weightTimesN)) / PRECISION;\n _virtualBalance = (_prevVirtualBalance * _rate) / _prevRate;\n _virtualBalanceSum = _virtualBalanceSum + _virtualBalance - _prevVirtualBalance;\n }\n\n packedVirtualBalances[token] = _packVirtualBalance(_virtualBalance, _rate, _packedWeight);\n emit RateUpdate(token, _rate);\n }\n\n if (!_updated && _virtualBalanceProd == virtualBalanceProd_ && _virtualBalanceSum == virtualBalanceSum_) {\n return (_virtualBalanceProd, _virtualBalanceSum);\n }\n\n // recalculate supply and mint/burn token to staking address\n uint256 _supply;\n (_supply, _virtualBalanceProd) = _updateSupply(supply, _virtualBalanceProd, _virtualBalanceSum);\n return (_virtualBalanceProd, _virtualBalanceSum);\n }\n\n /// @notice apply a step in amplitude and weight ramp, if applicable\n /// @dev caller is reponsible for updating supply if a step has been taken\n /// @param vbProd_ product term(pi) before update\n /// @return tuple with new product term and flag indicating if a step has been taken\n function _updateWeights(uint256 vbProd_) internal returns (uint256, bool) {\n uint256 _span = rampLastTime;\n uint256 _duration = rampStopTime;\n if (\n _span == 0 || _span > block.timestamp || (block.timestamp - _span < rampStep && _duration > block.timestamp)\n ) {\n // scenarios:\n // 1) no ramp is active\n // 2) ramp is scheduled for in the future\n // 3) weights have been updated too recently and ramp hasnt finished yet\n return (vbProd_, false);\n }\n\n if (block.timestamp < _duration) {\n // ramp in progress\n _duration -= _span;\n rampLastTime = block.timestamp;\n } else {\n // ramp has finished\n _duration = 0;\n rampLastTime = 0;\n rampStopTime = 0;\n }\n\n _span = block.timestamp - _span;\n\n // update amplification\n uint256 _current = amplification;\n uint256 _target = targetAmplification;\n\n if (_duration == 0) {\n _current = _target;\n } else {\n if (_current > _target) {\n _current = _current - ((_current - _target) * _span) / _duration;\n } else {\n _current = _current + ((_target - _current) * _span) / _duration;\n }\n }\n amplification = _current;\n\n // update weights\n uint256 _virtualBalance = 0;\n uint256 _rate = 0;\n uint256 _packedWeight = 0;\n uint256 _lower = 0;\n uint256 _upper = 0;\n for (uint256 t = 0; t < MAX_NUM_TOKENS; t++) {\n if (t == numTokens) break;\n (_virtualBalance, _rate, _packedWeight) = _unpackVirtualBalance(packedVirtualBalances[t]);\n (_current, _target, _lower, _upper) = _unpackWeight(_packedWeight);\n if (_duration == 0) {\n _current = _target;\n } else {\n if (_current > _target) {\n _current -= ((_current - _target) * _span) / _duration;\n } else {\n _current += ((_target - _current) * _span) / _duration;\n }\n }\n _packedWeight = _packWeight(_current, _target, _lower, _upper);\n packedVirtualBalances[t] = _packVirtualBalance(_virtualBalance, _rate, _packedWeight);\n }\n\n uint256 vbProd = 0;\n uint256 _supply = supply;\n if (_supply > 0) {\n vbProd = _calculateVirtualBalanceProd(_supply);\n }\n return (vbProd, true);\n }\n\n /// @notice calculate supply and burn or mint difference from the staking contract\n /// @param supply_ previous supply\n /// @param vbProd_ product term (pi)\n /// @param vbSum_ sum term (sigma)\n /// @return tuple with new supply and product term\n function _updateSupply(uint256 supply_, uint256 vbProd_, uint256 vbSum_) internal returns (uint256, uint256) {\n if (supply_ == 0) return (0, vbProd_);\n\n (uint256 _supply, uint256 _virtualBalanceProd) =\n _calculateSupply(numTokens, supply_, amplification, vbProd_, vbSum_, true);\n\n if (_supply > supply_) {\n PoolToken(tokenAddress).mint(stakingAddress, _supply - supply_);\n } else if (_supply < supply_) {\n PoolToken(tokenAddress).burn(stakingAddress, supply_ - _supply);\n }\n supply = _supply;\n return (_supply, _virtualBalanceProd);\n }\n\n /// @notice check whether asset is within safety band, or if previously outside, moves closer to it\n /// @dev reverts if conditions are not met\n /// @param prevRatio_ token ratio before user action\n /// @param ratio_ token ratio after user action\n /// @param packedWeight_ packed weight\n function _checkBands(uint256 prevRatio_, uint256 ratio_, uint256 packedWeight_) internal pure {\n uint256 _weight = FixedPointMathLib.rawMul(packedWeight_ & WEIGHT_MASK, WEIGHT_SCALE);\n\n // lower limit check\n uint256 limit = FixedPointMathLib.rawMul((packedWeight_ >> LOWER_BAND_SHIFT) & WEIGHT_MASK, WEIGHT_SCALE);\n if (limit > _weight) {\n limit = 0;\n } else {\n limit = FixedPointMathLib.rawSub(_weight, limit);\n }\n if (ratio_ < limit) {\n if (ratio_ <= prevRatio_) {\n revert Pool__RatioBelowLowerBound();\n }\n return;\n }\n\n // upper limit check\n limit = FixedPointMathLib.min(\n FixedPointMathLib.rawAdd(_weight, FixedPointMathLib.rawMul(packedWeight_ >> UPPER_BAND_SHIFT, WEIGHT_SCALE)),\n PRECISION\n );\n if (ratio_ > limit) {\n if (ratio_ >= prevRatio_) {\n revert Pool__RatioAboveUpperBound();\n }\n }\n }\n\n /*´:°•.°+.*•´.*:˚.°*.˚•´.°:°•.°•.*•´.*:˚.°*.˚•´.°:°•.°+.*•´.*:*/\n /* MATH FUNCTIONS */\n /*.•°:°.´+˚.*°.˚:*.´•*.+°.•°:´*.´•*.•°.•°:°.´:•˚°.*°.˚:*.´+°.•*/\n\n /// @notice calculate product term (pi) and sum term (sigma)\n /// @return tuple with product and sum term\n function _calculateVirtualBalanceProdSum() internal view returns (uint256, uint256) {\n uint256 s = 0;\n for (uint256 t = 0; t < MAX_NUM_TOKENS; t++) {\n if (t == numTokens) {\n break;\n }\n s = FixedPointMathLib.rawAdd(s, packedVirtualBalances[t] & VB_MASK);\n }\n uint256 p = _calculateVirtualBalanceProd(s);\n return (p, s);\n }\n\n /// @notice calculate product term (pi)\n /// @param supply_ supply to use in product term\n /// @return product term\n function _calculateVirtualBalanceProd(uint256 supply_) internal view returns (uint256) {\n uint256 _numTokens = numTokens;\n uint256 _p = PRECISION;\n for (uint256 t = 0; t < MAX_NUM_TOKENS; ++t) {\n if (t == _numTokens) {\n break;\n }\n uint256 _virtualBalance;\n uint256 _packedWeight;\n (_virtualBalance,, _packedWeight) = _unpackVirtualBalance(packedVirtualBalances[t]);\n uint256 _weight = _unpackWeightTimesN(_packedWeight, 1);\n\n if (!(_weight > 0 && _virtualBalance > 0)) revert Pool__InvalidParams();\n\n // p = product((D * w_i / vb_i)^(w_i * n))\n _p = FixedPointMathLib.rawDiv(\n FixedPointMathLib.rawMul(\n _p,\n _powDown(\n FixedPointMathLib.rawDiv(FixedPointMathLib.rawMul(supply_, _weight), _virtualBalance),\n FixedPointMathLib.rawMul(_weight, _numTokens)\n )\n ),\n PRECISION\n );\n }\n return _p;\n }\n\n /// @notice calculate supply iteratively\n /// @param numTokens_ number of tokens in the pool\n /// @param supply_ supply as used in product term\n /// @param amplification_ amplification factor (A f^n)\n /// @param virtualBalanceProd_ product term (pi)\n /// @param virtualBalanceSum_ sum term (sigma)\n /// @param up_ whether to round up\n /// @return tuple with new supply and product term\n function _calculateSupply(\n uint256 numTokens_,\n uint256 supply_,\n uint256 amplification_,\n uint256 virtualBalanceProd_,\n uint256 virtualBalanceSum_,\n bool up_\n ) internal pure returns (uint256, uint256) {\n // D[m+1] = (A f^n sigma - D[m] pi[m] )) / (A f^n - 1)\n // = (_l - _s _r) / _d\n\n uint256 _l = amplification_; // left: A f^n sigma\n uint256 _d = _l - PRECISION; // denominator: A f*n - 1\n _l = _l * virtualBalanceSum_;\n uint256 _s = supply_; // supply: D[m]\n uint256 _r = virtualBalanceProd_; // right: pi[m]\n\n for (uint256 i = 0; i < 256; i++) {\n if (!(_s > 0)) {\n revert Pool__InvalidParams();\n }\n uint256 _sp = FixedPointMathLib.rawDiv(FixedPointMathLib.rawSub(_l, FixedPointMathLib.rawMul(_s, _r)), _d); // D[m+1] = (_l - _s * _r) / _d\n // update product term pi[m+1] = (D[m+1]/D[m])^n pi(m)\n for (uint256 t = 0; t < MAX_NUM_TOKENS; t++) {\n if (t == numTokens_) {\n break;\n }\n _r = FixedPointMathLib.rawDiv(FixedPointMathLib.rawMul(_r, _sp), _s); // _r * _sp / _s\n }\n uint256 _delta = 0;\n if (_sp >= _s) {\n _delta = FixedPointMathLib.rawSub(_sp, _s);\n } else {\n _delta = FixedPointMathLib.rawSub(_s, _sp);\n }\n\n if (FixedPointMathLib.rawDiv(FixedPointMathLib.rawMul(_delta, PRECISION), _s) <= MAX_POW_REL_ERR) {\n _delta = FixedPointMathLib.rawDiv(FixedPointMathLib.rawMul(_sp, MAX_POW_REL_ERR), PRECISION);\n if (up_) {\n _sp += _delta;\n } else {\n _sp -= _delta;\n }\n return (_sp, _r);\n }\n\n _s = _sp;\n }\n\n revert Pool__NoConvergence();\n }\n\n /// @notice calculate a single token's virtual balance iteratively using newton's method\n /// @param wn_ token weight times number of tokens\n /// @param y_ starting value\n /// @param supply_ supply\n /// @param amplification_ amplification factor `A f^n`\n /// @param vbProd_ intermediary product term (pi~), pi with previous balances factored out and new balance factored in\n /// @param vbSum_ intermediary sum term (sigma~), sigma with previous balances subtracted and new balance added\n /// @return new token virtual balance\n function _calculateVirtualBalance(\n uint256 wn_,\n uint256 y_,\n uint256 supply_,\n uint256 amplification_,\n uint256 vbProd_,\n uint256 vbSum_\n ) internal pure returns (uint256) {\n // y = x_j, sum' = sum(x_i, i != j), prod' = D^n w_j^(v_j) prod((w_i/x_i)^v_i, i != j)\n // Iteratively find root of g(y) using Newton's method\n // g(y) = y^(v_j + 1) + (sum' + (1 / (A f^n) - 1) D) y^(v_j) - D prod' / (A f^n)\n // = y^(v_j + 1) + b y^(v_j) - c\n // y[n+1] = y[n] - g(y[n])/g'(y[n])\n // = (y[n]^2 + b (1 - q) y[n] + c q y[n]^(1 - v_j)) / ((q + 1) y[n] + b))\n\n uint256 b = (supply_ * PRECISION) / amplification_; // b' = sigma + D / (A f^n)\n uint256 c = (vbProd_ * b) / PRECISION; // c' = D / (A f^n) * pi\n b += vbSum_;\n uint256 q = (PRECISION * PRECISION) / wn_; // q = 1 / v_i = 1 / (w_i n)\n\n uint256 y = y_;\n for (uint256 i = 0; i < 256; i++) {\n if (!(y > 0)) revert Pool__InvalidParams();\n\n uint256 yp = (y + b + supply_ * q / PRECISION + c * q / _powUp(y, wn_) - b * q / PRECISION - supply_) * y\n / (q * y / PRECISION + y + b - supply_);\n uint256 delta = 0;\n if (yp >= y) {\n delta = yp - y;\n } else {\n delta = y - yp;\n }\n\n if (FixedPointMathLib.rawDiv(FixedPointMathLib.rawMul(delta, PRECISION), y) <= MAX_POW_REL_ERR) {\n yp += FixedPointMathLib.rawDiv(FixedPointMathLib.rawMul(yp, MAX_POW_REL_ERR), PRECISION);\n return yp;\n }\n y = yp;\n }\n\n revert Pool__NoConvergence();\n }\n\n /// @notice pack virtual balance of a token along with other related variables\n /// @param virtualBalance_ virtual balance of a token\n /// @param rate_ token rate\n /// @param packedWeight_ packed weight of a token\n /// @return packed variable\n function _packVirtualBalance(uint256 virtualBalance_, uint256 rate_, uint256 packedWeight_)\n internal\n pure\n returns (uint256)\n {\n if (virtualBalance_ > VB_MASK || rate_ > RATE_MASK) {\n revert Pool__InvalidParams();\n }\n\n return virtualBalance_ | (rate_ << RATE_SHIFT) | (packedWeight_ << PACKED_WEIGHT_SHIFT);\n }\n\n /// @notice unpack variable to it's components\n /// @param packed_ packed variable\n /// @return tuple with virtual balance, rate and packed weight\n function _unpackVirtualBalance(uint256 packed_) internal pure returns (uint256, uint256, uint256) {\n return (packed_ & VB_MASK, (packed_ >> RATE_SHIFT) & RATE_MASK, packed_ >> PACKED_WEIGHT_SHIFT);\n }\n\n /// @notice pack weight with target and bands\n /// @param weight_ weight with 18 decimals\n /// @param target_ target weight with 18 decimals\n /// @param lower_ lower band with 18 decimals, allowed distance from weight in negative direction\n /// @param upper_ upper band with 18 decimal, allowed distance from weight in positive direction\n function _packWeight(uint256 weight_, uint256 target_, uint256 lower_, uint256 upper_)\n internal\n pure\n returns (uint256)\n {\n return (\n (FixedPointMathLib.rawDiv(weight_, WEIGHT_SCALE))\n | (FixedPointMathLib.rawDiv(target_, WEIGHT_SCALE) << TARGET_WEIGHT_SHIFT)\n | (FixedPointMathLib.rawDiv(lower_, WEIGHT_SCALE) << LOWER_BAND_SHIFT)\n | (FixedPointMathLib.rawDiv(upper_, WEIGHT_SCALE) << UPPER_BAND_SHIFT)\n );\n }\n\n /// @notice unpack weight to its components\n /// @param packed_ packed weight\n /// @return tuple with weight, target weight, lower band and upper band (all in 18 decimals)\n function _unpackWeight(uint256 packed_) internal pure returns (uint256, uint256, uint256, uint256) {\n return (\n FixedPointMathLib.rawMul(packed_ & WEIGHT_MASK, WEIGHT_SCALE),\n FixedPointMathLib.rawMul((packed_ >> TARGET_WEIGHT_SHIFT) & WEIGHT_MASK, WEIGHT_SCALE),\n FixedPointMathLib.rawMul((packed_ >> LOWER_BAND_SHIFT) & WEIGHT_MASK, WEIGHT_SCALE),\n FixedPointMathLib.rawMul(packed_ >> UPPER_BAND_SHIFT, WEIGHT_SCALE)\n );\n }\n\n /// @notice unpack weight and multiply by number of tokens\n /// @param packed_ packed weight\n /// @param numTokens_ number of tokens\n /// @return weight multiplied by number of tokens (18 decimals)\n function _unpackWeightTimesN(uint256 packed_, uint256 numTokens_) internal pure returns (uint256) {\n return FixedPointMathLib.rawMul(FixedPointMathLib.rawMul(packed_ & WEIGHT_MASK, WEIGHT_SCALE), numTokens_);\n }\n\n /// @notice pack pool product and sum term\n /// @param prod_ Product term (pi)\n /// @param sum_ Sum term (sigma)\n /// @return packed term\n function _packPoolVirtualBalance(uint256 prod_, uint256 sum_) internal pure returns (uint256) {\n if (prod_ <= POOL_VB_MASK && sum_ <= POOL_VB_MASK) {\n return prod_ | (sum_ << POOL_VB_SHIFT);\n }\n revert Pool__InvalidParams();\n }\n\n /// @notice unpack pool product and sum term\n /// @param packed_ packed terms\n /// @return tuple with pool product term (pi) and pool sum term (sigma)\n function _unpackPoolVirtualBalance(uint256 packed_) internal pure returns (uint256, uint256) {\n return (packed_ & POOL_VB_MASK, packed_ >> POOL_VB_SHIFT);\n }\n\n function _checkIfPaused() internal view {\n if (paused == true) {\n revert Pool__Paused();\n }\n }\n\n function _powUp(uint256 x, uint256 y) internal pure returns (uint256) {\n uint256 p = LogExpMath.pow(x, y);\n // uint256 p = FixedPointMathLib.rpow(x, y, 1);\n if (p == 0) return 0;\n // p + (p * MAX_POW_REL_ERR - 1) / PRECISION + 1\n return FixedPointMathLib.rawAdd(\n FixedPointMathLib.rawAdd(\n p,\n FixedPointMathLib.rawDiv(\n FixedPointMathLib.rawSub(FixedPointMathLib.rawMul(p, MAX_POW_REL_ERR), 1), PRECISION\n )\n ),\n 1\n );\n }\n\n function _powDown(uint256 x, uint256 y) internal pure returns (uint256) {\n uint256 p = LogExpMath.pow(x, y);\n // uint256 p = FixedPointMathLib.rpow(x, y, 1);\n if (p == 0) return 0;\n // (p * MAX_POW_REL_ERR - 1) / PRECISION + 1\n uint256 e = FixedPointMathLib.rawAdd(\n FixedPointMathLib.rawDiv(\n FixedPointMathLib.rawSub(FixedPointMathLib.rawMul(p, MAX_POW_REL_ERR), 1), PRECISION\n ),\n 1\n );\n if (p < e) return 0;\n return FixedPointMathLib.rawSub(p, e);\n }\n}\n"
},
"lib/solady/src/auth/Ownable.sol": {
"content": "// SPDX-License-Identifier: MIT\npragma solidity ^0.8.4;\n\n/// @notice Simple single owner authorization mixin.\n/// @author Solady (https://github.com/vectorized/solady/blob/main/src/auth/Ownable.sol)\n///\n/// @dev Note:\n/// This implementation does NOT auto-initialize the owner to `msg.sender`.\n/// You MUST call the `_initializeOwner` in the constructor / initializer.\n///\n/// While the ownable portion follows\n/// [EIP-173](https://eips.ethereum.org/EIPS/eip-173) for compatibility,\n/// the nomenclature for the 2-step ownership handover may be unique to this codebase.\nabstract contract Ownable {\n /*´:°•.°+.*•´.*:˚.°*.˚•´.°:°•.°•.*•´.*:˚.°*.˚•´.°:°•.°+.*•´.*:*/\n /* CUSTOM ERRORS */\n /*.•°:°.´+˚.*°.˚:*.´•*.+°.•°:´*.´•*.•°.•°:°.´:•˚°.*°.˚:*.´+°.•*/\n\n /// @dev The caller is not authorized to call the function.\n error Unauthorized();\n\n /// @dev The `newOwner` cannot be the zero address.\n error NewOwnerIsZeroAddress();\n\n /// @dev The `pendingOwner` does not have a valid handover request.\n error NoHandoverRequest();\n\n /// @dev Cannot double-initialize.\n error AlreadyInitialized();\n\n /*´:°•.°+.*•´.*:˚.°*.˚•´.°:°•.°•.*•´.*:˚.°*.˚•´.°:°•.°+.*•´.*:*/\n /* EVENTS */\n /*.•°:°.´+˚.*°.˚:*.´•*.+°.•°:´*.´•*.•°.•°:°.´:•˚°.*°.˚:*.´+°.•*/\n\n /// @dev The ownership is transferred from `oldOwner` to `newOwner`.\n /// This event is intentionally kept the same as OpenZeppelin's Ownable to be\n /// compatible with indexers and [EIP-173](https://eips.ethereum.org/EIPS/eip-173),\n /// despite it not being as lightweight as a single argument event.\n event OwnershipTransferred(address indexed oldOwner, address indexed newOwner);\n\n /// @dev An ownership handover to `pendingOwner` has been requested.\n event OwnershipHandoverRequested(address indexed pendingOwner);\n\n /// @dev The ownership handover to `pendingOwner` has been canceled.\n event OwnershipHandoverCanceled(address indexed pendingOwner);\n\n /// @dev `keccak256(bytes(\"OwnershipTransferred(address,address)\"))`.\n uint256 private constant _OWNERSHIP_TRANSFERRED_EVENT_SIGNATURE =\n 0x8be0079c531659141344cd1fd0a4f28419497f9722a3daafe3b4186f6b6457e0;\n\n /// @dev `keccak256(bytes(\"OwnershipHandoverRequested(address)\"))`.\n uint256 private constant _OWNERSHIP_HANDOVER_REQUESTED_EVENT_SIGNATURE =\n 0xdbf36a107da19e49527a7176a1babf963b4b0ff8cde35ee35d6cd8f1f9ac7e1d;\n\n /// @dev `keccak256(bytes(\"OwnershipHandoverCanceled(address)\"))`.\n uint256 private constant _OWNERSHIP_HANDOVER_CANCELED_EVENT_SIGNATURE =\n 0xfa7b8eab7da67f412cc9575ed43464468f9bfbae89d1675917346ca6d8fe3c92;\n\n /*´:°•.°+.*•´.*:˚.°*.˚•´.°:°•.°•.*•´.*:˚.°*.˚•´.°:°•.°+.*•´.*:*/\n /* STORAGE */\n /*.•°:°.´+˚.*°.˚:*.´•*.+°.•°:´*.´•*.•°.•°:°.´:•˚°.*°.˚:*.´+°.•*/\n\n /// @dev The owner slot is given by:\n /// `bytes32(~uint256(uint32(bytes4(keccak256(\"_OWNER_SLOT_NOT\")))))`.\n /// It is intentionally chosen to be a high value\n /// to avoid collision with lower slots.\n /// The choice of manual storage layout is to enable compatibility\n /// with both regular and upgradeable contracts.\n bytes32 internal constant _OWNER_SLOT =\n 0xffffffffffffffffffffffffffffffffffffffffffffffffffffffff74873927;\n\n /// The ownership handover slot of `newOwner` is given by:\n /// ```\n /// mstore(0x00, or(shl(96, user), _HANDOVER_SLOT_SEED))\n /// let handoverSlot := keccak256(0x00, 0x20)\n /// ```\n /// It stores the expiry timestamp of the two-step ownership handover.\n uint256 private constant _HANDOVER_SLOT_SEED = 0x389a75e1;\n\n /*´:°•.°+.*•´.*:˚.°*.˚•´.°:°•.°•.*•´.*:˚.°*.˚•´.°:°•.°+.*•´.*:*/\n /* INTERNAL FUNCTIONS */\n /*.•°:°.´+˚.*°.˚:*.´•*.+°.•°:´*.´•*.•°.•°:°.´:•˚°.*°.˚:*.´+°.•*/\n\n /// @dev Override to return true to make `_initializeOwner` prevent double-initialization.\n function _guardInitializeOwner() internal pure virtual returns (bool guard) {}\n\n /// @dev Initializes the owner directly without authorization guard.\n /// This function must be called upon initialization,\n /// regardless of whether the contract is upgradeable or not.\n /// This is to enable generalization to both regular and upgradeable contracts,\n /// and to save gas in case the initial owner is not the caller.\n /// For performance reasons, this function will not check if there\n /// is an existing owner.\n function _initializeOwner(address newOwner) internal virtual {\n if (_guardInitializeOwner()) {\n /// @solidity memory-safe-assembly\n assembly {\n let ownerSlot := _OWNER_SLOT\n if sload(ownerSlot) {\n mstore(0x00, 0x0dc149f0) // `AlreadyInitialized()`.\n revert(0x1c, 0x04)\n }\n // Clean the upper 96 bits.\n newOwner := shr(96, shl(96, newOwner))\n // Store the new value.\n sstore(ownerSlot, or(newOwner, shl(255, iszero(newOwner))))\n // Emit the {OwnershipTransferred} event.\n log3(0, 0, _OWNERSHIP_TRANSFERRED_EVENT_SIGNATURE, 0, newOwner)\n }\n } else {\n /// @solidity memory-safe-assembly\n assembly {\n // Clean the upper 96 bits.\n newOwner := shr(96, shl(96, newOwner))\n // Store the new value.\n sstore(_OWNER_SLOT, newOwner)\n // Emit the {OwnershipTransferred} event.\n log3(0, 0, _OWNERSHIP_TRANSFERRED_EVENT_SIGNATURE, 0, newOwner)\n }\n }\n }\n\n /// @dev Sets the owner directly without authorization guard.\n function _setOwner(address newOwner) internal virtual {\n if (_guardInitializeOwner()) {\n /// @solidity memory-safe-assembly\n assembly {\n let ownerSlot := _OWNER_SLOT\n // Clean the upper 96 bits.\n newOwner := shr(96, shl(96, newOwner))\n // Emit the {OwnershipTransferred} event.\n log3(0, 0, _OWNERSHIP_TRANSFERRED_EVENT_SIGNATURE, sload(ownerSlot), newOwner)\n // Store the new value.\n sstore(ownerSlot, or(newOwner, shl(255, iszero(newOwner))))\n }\n } else {\n /// @solidity memory-safe-assembly\n assembly {\n let ownerSlot := _OWNER_SLOT\n // Clean the upper 96 bits.\n newOwner := shr(96, shl(96, newOwner))\n // Emit the {OwnershipTransferred} event.\n log3(0, 0, _OWNERSHIP_TRANSFERRED_EVENT_SIGNATURE, sload(ownerSlot), newOwner)\n // Store the new value.\n sstore(ownerSlot, newOwner)\n }\n }\n }\n\n /// @dev Throws if the sender is not the owner.\n function _checkOwner() internal view virtual {\n /// @solidity memory-safe-assembly\n assembly {\n // If the caller is not the stored owner, revert.\n if iszero(eq(caller(), sload(_OWNER_SLOT))) {\n mstore(0x00, 0x82b42900) // `Unauthorized()`.\n revert(0x1c, 0x04)\n }\n }\n }\n\n /// @dev Returns how long a two-step ownership handover is valid for in seconds.\n /// Override to return a different value if needed.\n /// Made internal to conserve bytecode. Wrap it in a public function if needed.\n function _ownershipHandoverValidFor() internal view virtual returns (uint64) {\n return 48 * 3600;\n }\n\n /*´:°•.°+.*•´.*:˚.°*.˚•´.°:°•.°•.*•´.*:˚.°*.˚•´.°:°•.°+.*•´.*:*/\n /* PUBLIC UPDATE FUNCTIONS */\n /*.•°:°.´+˚.*°.˚:*.´•*.+°.•°:´*.´•*.•°.•°:°.´:•˚°.*°.˚:*.´+°.•*/\n\n /// @dev Allows the owner to transfer the ownership to `newOwner`.\n function transferOwnership(address newOwner) public payable virtual onlyOwner {\n /// @solidity memory-safe-assembly\n assembly {\n if iszero(shl(96, newOwner)) {\n mstore(0x00, 0x7448fbae) // `NewOwnerIsZeroAddress()`.\n revert(0x1c, 0x04)\n }\n }\n _setOwner(newOwner);\n }\n\n /// @dev Allows the owner to renounce their ownership.\n function renounceOwnership() public payable virtual onlyOwner {\n _setOwner(address(0));\n }\n\n /// @dev Request a two-step ownership handover to the caller.\n /// The request will automatically expire in 48 hours (172800 seconds) by default.\n function requestOwnershipHandover() public payable virtual {\n unchecked {\n uint256 expires = block.timestamp + _ownershipHandoverValidFor();\n /// @solidity memory-safe-assembly\n assembly {\n // Compute and set the handover slot to `expires`.\n mstore(0x0c, _HANDOVER_SLOT_SEED)\n mstore(0x00, caller())\n sstore(keccak256(0x0c, 0x20), expires)\n // Emit the {OwnershipHandoverRequested} event.\n log2(0, 0, _OWNERSHIP_HANDOVER_REQUESTED_EVENT_SIGNATURE, caller())\n }\n }\n }\n\n /// @dev Cancels the two-step ownership handover to the caller, if any.\n function cancelOwnershipHandover() public payable virtual {\n /// @solidity memory-safe-assembly\n assembly {\n // Compute and set the handover slot to 0.\n mstore(0x0c, _HANDOVER_SLOT_SEED)\n mstore(0x00, caller())\n sstore(keccak256(0x0c, 0x20), 0)\n // Emit the {OwnershipHandoverCanceled} event.\n log2(0, 0, _OWNERSHIP_HANDOVER_CANCELED_EVENT_SIGNATURE, caller())\n }\n }\n\n /// @dev Allows the owner to complete the two-step ownership handover to `pendingOwner`.\n /// Reverts if there is no existing ownership handover requested by `pendingOwner`.\n function completeOwnershipHandover(address pendingOwner) public payable virtual onlyOwner {\n /// @solidity memory-safe-assembly\n assembly {\n // Compute and set the handover slot to 0.\n mstore(0x0c, _HANDOVER_SLOT_SEED)\n mstore(0x00, pendingOwner)\n let handoverSlot := keccak256(0x0c, 0x20)\n // If the handover does not exist, or has expired.\n if gt(timestamp(), sload(handoverSlot)) {\n mstore(0x00, 0x6f5e8818) // `NoHandoverRequest()`.\n revert(0x1c, 0x04)\n }\n // Set the handover slot to 0.\n sstore(handoverSlot, 0)\n }\n _setOwner(pendingOwner);\n }\n\n /*´:°•.°+.*•´.*:˚.°*.˚•´.°:°•.°•.*•´.*:˚.°*.˚•´.°:°•.°+.*•´.*:*/\n /* PUBLIC READ FUNCTIONS */\n /*.•°:°.´+˚.*°.˚:*.´•*.+°.•°:´*.´•*.•°.•°:°.´:•˚°.*°.˚:*.´+°.•*/\n\n /// @dev Returns the owner of the contract.\n function owner() public view virtual returns (address result) {\n /// @solidity memory-safe-assembly\n assembly {\n result := sload(_OWNER_SLOT)\n }\n }\n\n /// @dev Returns the expiry timestamp for the two-step ownership handover to `pendingOwner`.\n function ownershipHandoverExpiresAt(address pendingOwner)\n public\n view\n virtual\n returns (uint256 result)\n {\n /// @solidity memory-safe-assembly\n assembly {\n // Compute the handover slot.\n mstore(0x0c, _HANDOVER_SLOT_SEED)\n mstore(0x00, pendingOwner)\n // Load the handover slot.\n result := sload(keccak256(0x0c, 0x20))\n }\n }\n\n /*´:°•.°+.*•´.*:˚.°*.˚•´.°:°•.°•.*•´.*:˚.°*.˚•´.°:°•.°+.*•´.*:*/\n /* MODIFIERS */\n /*.•°:°.´+˚.*°.˚:*.´•*.+°.•°:´*.´•*.•°.•°:°.´:•˚°.*°.˚:*.´+°.•*/\n\n /// @dev Marks a function as only callable by the owner.\n modifier onlyOwner() virtual {\n _checkOwner();\n _;\n }\n}\n"
},
"lib/solady/src/tokens/ERC20.sol": {
"content": "// SPDX-License-Identifier: MIT\npragma solidity ^0.8.4;\n\n/// @notice Simple ERC20 + EIP-2612 implementation.\n/// @author Solady (https://github.com/vectorized/solady/blob/main/src/tokens/ERC20.sol)\n/// @author Modified from Solmate (https://github.com/transmissions11/solmate/blob/main/src/tokens/ERC20.sol)\n/// @author Modified from OpenZeppelin (https://github.com/OpenZeppelin/openzeppelin-contracts/blob/master/contracts/token/ERC20/ERC20.sol)\n///\n/// @dev Note:\n/// - The ERC20 standard allows minting and transferring to and from the zero address,\n/// minting and transferring zero tokens, as well as self-approvals.\n/// For performance, this implementation WILL NOT revert for such actions.\n/// Please add any checks with overrides if desired.\n/// - The `permit` function uses the ecrecover precompile (0x1).\n///\n/// If you are overriding:\n/// - NEVER violate the ERC20 invariant:\n/// the total sum of all balances must be equal to `totalSupply()`.\n/// - Check that the overridden function is actually used in the function you want to\n/// change the behavior of. Much of the code has been manually inlined for performance.\nabstract contract ERC20 {\n /*´:°•.°+.*•´.*:˚.°*.˚•´.°:°•.°•.*•´.*:˚.°*.˚•´.°:°•.°+.*•´.*:*/\n /* CUSTOM ERRORS */\n /*.•°:°.´+˚.*°.˚:*.´•*.+°.•°:´*.´•*.•°.•°:°.´:•˚°.*°.˚:*.´+°.•*/\n\n /// @dev The total supply has overflowed.\n error TotalSupplyOverflow();\n\n /// @dev The allowance has overflowed.\n error AllowanceOverflow();\n\n /// @dev The allowance has underflowed.\n error AllowanceUnderflow();\n\n /// @dev Insufficient balance.\n error InsufficientBalance();\n\n /// @dev Insufficient allowance.\n error InsufficientAllowance();\n\n /// @dev The permit is invalid.\n error InvalidPermit();\n\n /// @dev The permit has expired.\n error PermitExpired();\n\n /*´:°•.°+.*•´.*:˚.°*.˚•´.°:°•.°•.*•´.*:˚.°*.˚•´.°:°•.°+.*•´.*:*/\n /* EVENTS */\n /*.•°:°.´+˚.*°.˚:*.´•*.+°.•°:´*.´•*.•°.•°:°.´:•˚°.*°.˚:*.´+°.•*/\n\n /// @dev Emitted when `amount` tokens is transferred from `from` to `to`.\n event Transfer(address indexed from, address indexed to, uint256 amount);\n\n /// @dev Emitted when `amount` tokens is approved by `owner` to be used by `spender`.\n event Approval(address indexed owner, address indexed spender, uint256 amount);\n\n /// @dev `keccak256(bytes(\"Transfer(address,address,uint256)\"))`.\n uint256 private constant _TRANSFER_EVENT_SIGNATURE =\n 0xddf252ad1be2c89b69c2b068fc378daa952ba7f163c4a11628f55a4df523b3ef;\n\n /// @dev `keccak256(bytes(\"Approval(address,address,uint256)\"))`.\n uint256 private constant _APPROVAL_EVENT_SIGNATURE =\n 0x8c5be1e5ebec7d5bd14f71427d1e84f3dd0314c0f7b2291e5b200ac8c7c3b925;\n\n /*´:°•.°+.*•´.*:˚.°*.˚•´.°:°•.°•.*•´.*:˚.°*.˚•´.°:°•.°+.*•´.*:*/\n /* STORAGE */\n /*.•°:°.´+˚.*°.˚:*.´•*.+°.•°:´*.´•*.•°.•°:°.´:•˚°.*°.˚:*.´+°.•*/\n\n /// @dev The storage slot for the total supply.\n uint256 private constant _TOTAL_SUPPLY_SLOT = 0x05345cdf77eb68f44c;\n\n /// @dev The balance slot of `owner` is given by:\n /// ```\n /// mstore(0x0c, _BALANCE_SLOT_SEED)\n /// mstore(0x00, owner)\n /// let balanceSlot := keccak256(0x0c, 0x20)\n /// ```\n uint256 private constant _BALANCE_SLOT_SEED = 0x87a211a2;\n\n /// @dev The allowance slot of (`owner`, `spender`) is given by:\n /// ```\n /// mstore(0x20, spender)\n /// mstore(0x0c, _ALLOWANCE_SLOT_SEED)\n /// mstore(0x00, owner)\n /// let allowanceSlot := keccak256(0x0c, 0x34)\n /// ```\n uint256 private constant _ALLOWANCE_SLOT_SEED = 0x7f5e9f20;\n\n /// @dev The nonce slot of `owner` is given by:\n /// ```\n /// mstore(0x0c, _NONCES_SLOT_SEED)\n /// mstore(0x00, owner)\n /// let nonceSlot := keccak256(0x0c, 0x20)\n /// ```\n uint256 private constant _NONCES_SLOT_SEED = 0x38377508;\n\n /*´:°•.°+.*•´.*:˚.°*.˚•´.°:°•.°•.*•´.*:˚.°*.˚•´.°:°•.°+.*•´.*:*/\n /* CONSTANTS */\n /*.•°:°.´+˚.*°.˚:*.´•*.+°.•°:´*.´•*.•°.•°:°.´:•˚°.*°.˚:*.´+°.•*/\n\n /// @dev `(_NONCES_SLOT_SEED << 16) | 0x1901`.\n uint256 private constant _NONCES_SLOT_SEED_WITH_SIGNATURE_PREFIX = 0x383775081901;\n\n /// @dev `keccak256(\"EIP712Domain(string name,string version,uint256 chainId,address verifyingContract)\")`.\n bytes32 private constant _DOMAIN_TYPEHASH =\n 0x8b73c3c69bb8fe3d512ecc4cf759cc79239f7b179b0ffacaa9a75d522b39400f;\n\n /// @dev `keccak256(\"1\")`.\n bytes32 private constant _VERSION_HASH =\n 0xc89efdaa54c0f20c7adf612882df0950f5a951637e0307cdcb4c672f298b8bc6;\n\n /// @dev `keccak256(\"Permit(address owner,address spender,uint256 value,uint256 nonce,uint256 deadline)\")`.\n bytes32 private constant _PERMIT_TYPEHASH =\n 0x6e71edae12b1b97f4d1f60370fef10105fa2faae0126114a169c64845d6126c9;\n\n /*´:°•.°+.*•´.*:˚.°*.˚•´.°:°•.°•.*•´.*:˚.°*.˚•´.°:°•.°+.*•´.*:*/\n /* ERC20 METADATA */\n /*.•°:°.´+˚.*°.˚:*.´•*.+°.•°:´*.´•*.•°.•°:°.´:•˚°.*°.˚:*.´+°.•*/\n\n /// @dev Returns the name of the token.\n function name() public view virtual returns (string memory);\n\n /// @dev Returns the symbol of the token.\n function symbol() public view virtual returns (string memory);\n\n /// @dev Returns the decimals places of the token.\n function decimals() public view virtual returns (uint8) {\n return 18;\n }\n\n /*´:°•.°+.*•´.*:˚.°*.˚•´.°:°•.°•.*•´.*:˚.°*.˚•´.°:°•.°+.*•´.*:*/\n /* ERC20 */\n /*.•°:°.´+˚.*°.˚:*.´•*.+°.•°:´*.´•*.•°.•°:°.´:•˚°.*°.˚:*.´+°.•*/\n\n /// @dev Returns the amount of tokens in existence.\n function totalSupply() public view virtual returns (uint256 result) {\n /// @solidity memory-safe-assembly\n assembly {\n result := sload(_TOTAL_SUPPLY_SLOT)\n }\n }\n\n /// @dev Returns the amount of tokens owned by `owner`.\n function balanceOf(address owner) public view virtual returns (uint256 result) {\n /// @solidity memory-safe-assembly\n assembly {\n mstore(0x0c, _BALANCE_SLOT_SEED)\n mstore(0x00, owner)\n result := sload(keccak256(0x0c, 0x20))\n }\n }\n\n /// @dev Returns the amount of tokens that `spender` can spend on behalf of `owner`.\n function allowance(address owner, address spender)\n public\n view\n virtual\n returns (uint256 result)\n {\n /// @solidity memory-safe-assembly\n assembly {\n mstore(0x20, spender)\n mstore(0x0c, _ALLOWANCE_SLOT_SEED)\n mstore(0x00, owner)\n result := sload(keccak256(0x0c, 0x34))\n }\n }\n\n /// @dev Sets `amount` as the allowance of `spender` over the caller's tokens.\n ///\n /// Emits a {Approval} event.\n function approve(address spender, uint256 amount) public virtual returns (bool) {\n /// @solidity memory-safe-assembly\n assembly {\n // Compute the allowance slot and store the amount.\n mstore(0x20, spender)\n mstore(0x0c, _ALLOWANCE_SLOT_SEED)\n mstore(0x00, caller())\n sstore(keccak256(0x0c, 0x34), amount)\n // Emit the {Approval} event.\n mstore(0x00, amount)\n log3(0x00, 0x20, _APPROVAL_EVENT_SIGNATURE, caller(), shr(96, mload(0x2c)))\n }\n return true;\n }\n\n /// @dev Transfer `amount` tokens from the caller to `to`.\n ///\n /// Requirements:\n /// - `from` must at least have `amount`.\n ///\n /// Emits a {Transfer} event.\n function transfer(address to, uint256 amount) public virtual returns (bool) {\n _beforeTokenTransfer(msg.sender, to, amount);\n /// @solidity memory-safe-assembly\n assembly {\n // Compute the balance slot and load its value.\n mstore(0x0c, _BALANCE_SLOT_SEED)\n mstore(0x00, caller())\n let fromBalanceSlot := keccak256(0x0c, 0x20)\n let fromBalance := sload(fromBalanceSlot)\n // Revert if insufficient balance.\n if gt(amount, fromBalance) {\n mstore(0x00, 0xf4d678b8) // `InsufficientBalance()`.\n revert(0x1c, 0x04)\n }\n // Subtract and store the updated balance.\n sstore(fromBalanceSlot, sub(fromBalance, amount))\n // Compute the balance slot of `to`.\n mstore(0x00, to)\n let toBalanceSlot := keccak256(0x0c, 0x20)\n // Add and store the updated balance of `to`.\n // Will not overflow because the sum of all user balances\n // cannot exceed the maximum uint256 value.\n sstore(toBalanceSlot, add(sload(toBalanceSlot), amount))\n // Emit the {Transfer} event.\n mstore(0x20, amount)\n log3(0x20, 0x20, _TRANSFER_EVENT_SIGNATURE, caller(), shr(96, mload(0x0c)))\n }\n _afterTokenTransfer(msg.sender, to, amount);\n return true;\n }\n\n /// @dev Transfers `amount` tokens from `from` to `to`.\n ///\n /// Note: Does not update the allowance if it is the maximum uint256 value.\n ///\n /// Requirements:\n /// - `from` must at least have `amount`.\n /// - The caller must have at least `amount` of allowance to transfer the tokens of `from`.\n ///\n /// Emits a {Transfer} event.\n function transferFrom(address from, address to, uint256 amount) public virtual returns (bool) {\n _beforeTokenTransfer(from, to, amount);\n /// @solidity memory-safe-assembly\n assembly {\n let from_ := shl(96, from)\n // Compute the allowance slot and load its value.\n mstore(0x20, caller())\n mstore(0x0c, or(from_, _ALLOWANCE_SLOT_SEED))\n let allowanceSlot := keccak256(0x0c, 0x34)\n let allowance_ := sload(allowanceSlot)\n // If the allowance is not the maximum uint256 value.\n if add(allowance_, 1) {\n // Revert if the amount to be transferred exceeds the allowance.\n if gt(amount, allowance_) {\n mstore(0x00, 0x13be252b) // `InsufficientAllowance()`.\n revert(0x1c, 0x04)\n }\n // Subtract and store the updated allowance.\n sstore(allowanceSlot, sub(allowance_, amount))\n }\n // Compute the balance slot and load its value.\n mstore(0x0c, or(from_, _BALANCE_SLOT_SEED))\n let fromBalanceSlot := keccak256(0x0c, 0x20)\n let fromBalance := sload(fromBalanceSlot)\n // Revert if insufficient balance.\n if gt(amount, fromBalance) {\n mstore(0x00, 0xf4d678b8) // `InsufficientBalance()`.\n revert(0x1c, 0x04)\n }\n // Subtract and store the updated balance.\n sstore(fromBalanceSlot, sub(fromBalance, amount))\n // Compute the balance slot of `to`.\n mstore(0x00, to)\n let toBalanceSlot := keccak256(0x0c, 0x20)\n // Add and store the updated balance of `to`.\n // Will not overflow because the sum of all user balances\n // cannot exceed the maximum uint256 value.\n sstore(toBalanceSlot, add(sload(toBalanceSlot), amount))\n // Emit the {Transfer} event.\n mstore(0x20, amount)\n log3(0x20, 0x20, _TRANSFER_EVENT_SIGNATURE, shr(96, from_), shr(96, mload(0x0c)))\n }\n _afterTokenTransfer(from, to, amount);\n return true;\n }\n\n /*´:°•.°+.*•´.*:˚.°*.˚•´.°:°•.°•.*•´.*:˚.°*.˚•´.°:°•.°+.*•´.*:*/\n /* EIP-2612 */\n /*.•°:°.´+˚.*°.˚:*.´•*.+°.•°:´*.´•*.•°.•°:°.´:•˚°.*°.˚:*.´+°.•*/\n\n /// @dev For more performance, override to return the constant value\n /// of `keccak256(bytes(name()))` if `name()` will never change.\n function _constantNameHash() internal view virtual returns (bytes32 result) {}\n\n /// @dev Returns the current nonce for `owner`.\n /// This value is used to compute the signature for EIP-2612 permit.\n function nonces(address owner) public view virtual returns (uint256 result) {\n /// @solidity memory-safe-assembly\n assembly {\n // Compute the nonce slot and load its value.\n mstore(0x0c, _NONCES_SLOT_SEED)\n mstore(0x00, owner)\n result := sload(keccak256(0x0c, 0x20))\n }\n }\n\n /// @dev Sets `value` as the allowance of `spender` over the tokens of `owner`,\n /// authorized by a signed approval by `owner`.\n ///\n /// Emits a {Approval} event.\n function permit(\n address owner,\n address spender,\n uint256 value,\n uint256 deadline,\n uint8 v,\n bytes32 r,\n bytes32 s\n ) public virtual {\n bytes32 nameHash = _constantNameHash();\n // We simply calculate it on-the-fly to allow for cases where the `name` may change.\n if (nameHash == bytes32(0)) nameHash = keccak256(bytes(name()));\n /// @solidity memory-safe-assembly\n assembly {\n // Revert if the block timestamp is greater than `deadline`.\n if gt(timestamp(), deadline) {\n mstore(0x00, 0x1a15a3cc) // `PermitExpired()`.\n revert(0x1c, 0x04)\n }\n let m := mload(0x40) // Grab the free memory pointer.\n // Clean the upper 96 bits.\n owner := shr(96, shl(96, owner))\n spender := shr(96, shl(96, spender))\n // Compute the nonce slot and load its value.\n mstore(0x0e, _NONCES_SLOT_SEED_WITH_SIGNATURE_PREFIX)\n mstore(0x00, owner)\n let nonceSlot := keccak256(0x0c, 0x20)\n let nonceValue := sload(nonceSlot)\n // Prepare the domain separator.\n mstore(m, _DOMAIN_TYPEHASH)\n mstore(add(m, 0x20), nameHash)\n mstore(add(m, 0x40), _VERSION_HASH)\n mstore(add(m, 0x60), chainid())\n mstore(add(m, 0x80), address())\n mstore(0x2e, keccak256(m, 0xa0))\n // Prepare the struct hash.\n mstore(m, _PERMIT_TYPEHASH)\n mstore(add(m, 0x20), owner)\n mstore(add(m, 0x40), spender)\n mstore(add(m, 0x60), value)\n mstore(add(m, 0x80), nonceValue)\n mstore(add(m, 0xa0), deadline)\n mstore(0x4e, keccak256(m, 0xc0))\n // Prepare the ecrecover calldata.\n mstore(0x00, keccak256(0x2c, 0x42))\n mstore(0x20, and(0xff, v))\n mstore(0x40, r)\n mstore(0x60, s)\n let t := staticcall(gas(), 1, 0, 0x80, 0x20, 0x20)\n // If the ecrecover fails, the returndatasize will be 0x00,\n // `owner` will be checked if it equals the hash at 0x00,\n // which evaluates to false (i.e. 0), and we will revert.\n // If the ecrecover succeeds, the returndatasize will be 0x20,\n // `owner` will be compared against the returned address at 0x20.\n if iszero(eq(mload(returndatasize()), owner)) {\n mstore(0x00, 0xddafbaef) // `InvalidPermit()`.\n revert(0x1c, 0x04)\n }\n // Increment and store the updated nonce.\n sstore(nonceSlot, add(nonceValue, t)) // `t` is 1 if ecrecover succeeds.\n // Compute the allowance slot and store the value.\n // The `owner` is already at slot 0x20.\n mstore(0x40, or(shl(160, _ALLOWANCE_SLOT_SEED), spender))\n sstore(keccak256(0x2c, 0x34), value)\n // Emit the {Approval} event.\n log3(add(m, 0x60), 0x20, _APPROVAL_EVENT_SIGNATURE, owner, spender)\n mstore(0x40, m) // Restore the free memory pointer.\n mstore(0x60, 0) // Restore the zero pointer.\n }\n }\n\n /// @dev Returns the EIP-712 domain separator for the EIP-2612 permit.\n function DOMAIN_SEPARATOR() public view virtual returns (bytes32 result) {\n bytes32 nameHash = _constantNameHash();\n // We simply calculate it on-the-fly to allow for cases where the `name` may change.\n if (nameHash == bytes32(0)) nameHash = keccak256(bytes(name()));\n /// @solidity memory-safe-assembly\n assembly {\n let m := mload(0x40) // Grab the free memory pointer.\n mstore(m, _DOMAIN_TYPEHASH)\n mstore(add(m, 0x20), nameHash)\n mstore(add(m, 0x40), _VERSION_HASH)\n mstore(add(m, 0x60), chainid())\n mstore(add(m, 0x80), address())\n result := keccak256(m, 0xa0)\n }\n }\n\n /*´:°•.°+.*•´.*:˚.°*.˚•´.°:°•.°•.*•´.*:˚.°*.˚•´.°:°•.°+.*•´.*:*/\n /* INTERNAL MINT FUNCTIONS */\n /*.•°:°.´+˚.*°.˚:*.´•*.+°.•°:´*.´•*.•°.•°:°.´:•˚°.*°.˚:*.´+°.•*/\n\n /// @dev Mints `amount` tokens to `to`, increasing the total supply.\n ///\n /// Emits a {Transfer} event.\n function _mint(address to, uint256 amount) internal virtual {\n _beforeTokenTransfer(address(0), to, amount);\n /// @solidity memory-safe-assembly\n assembly {\n let totalSupplyBefore := sload(_TOTAL_SUPPLY_SLOT)\n let totalSupplyAfter := add(totalSupplyBefore, amount)\n // Revert if the total supply overflows.\n if lt(totalSupplyAfter, totalSupplyBefore) {\n mstore(0x00, 0xe5cfe957) // `TotalSupplyOverflow()`.\n revert(0x1c, 0x04)\n }\n // Store the updated total supply.\n sstore(_TOTAL_SUPPLY_SLOT, totalSupplyAfter)\n // Compute the balance slot and load its value.\n mstore(0x0c, _BALANCE_SLOT_SEED)\n mstore(0x00, to)\n let toBalanceSlot := keccak256(0x0c, 0x20)\n // Add and store the updated balance.\n sstore(toBalanceSlot, add(sload(toBalanceSlot), amount))\n // Emit the {Transfer} event.\n mstore(0x20, amount)\n log3(0x20, 0x20, _TRANSFER_EVENT_SIGNATURE, 0, shr(96, mload(0x0c)))\n }\n _afterTokenTransfer(address(0), to, amount);\n }\n\n /*´:°•.°+.*•´.*:˚.°*.˚•´.°:°•.°•.*•´.*:˚.°*.˚•´.°:°•.°+.*•´.*:*/\n /* INTERNAL BURN FUNCTIONS */\n /*.•°:°.´+˚.*°.˚:*.´•*.+°.•°:´*.´•*.•°.•°:°.´:•˚°.*°.˚:*.´+°.•*/\n\n /// @dev Burns `amount` tokens from `from`, reducing the total supply.\n ///\n /// Emits a {Transfer} event.\n function _burn(address from, uint256 amount) internal virtual {\n _beforeTokenTransfer(from, address(0), amount);\n /// @solidity memory-safe-assembly\n assembly {\n // Compute the balance slot and load its value.\n mstore(0x0c, _BALANCE_SLOT_SEED)\n mstore(0x00, from)\n let fromBalanceSlot := keccak256(0x0c, 0x20)\n let fromBalance := sload(fromBalanceSlot)\n // Revert if insufficient balance.\n if gt(amount, fromBalance) {\n mstore(0x00, 0xf4d678b8) // `InsufficientBalance()`.\n revert(0x1c, 0x04)\n }\n // Subtract and store the updated balance.\n sstore(fromBalanceSlot, sub(fromBalance, amount))\n // Subtract and store the updated total supply.\n sstore(_TOTAL_SUPPLY_SLOT, sub(sload(_TOTAL_SUPPLY_SLOT), amount))\n // Emit the {Transfer} event.\n mstore(0x00, amount)\n log3(0x00, 0x20, _TRANSFER_EVENT_SIGNATURE, shr(96, shl(96, from)), 0)\n }\n _afterTokenTransfer(from, address(0), amount);\n }\n\n /*´:°•.°+.*•´.*:˚.°*.˚•´.°:°•.°•.*•´.*:˚.°*.˚•´.°:°•.°+.*•´.*:*/\n /* INTERNAL TRANSFER FUNCTIONS */\n /*.•°:°.´+˚.*°.˚:*.´•*.+°.•°:´*.´•*.•°.•°:°.´:•˚°.*°.˚:*.´+°.•*/\n\n /// @dev Moves `amount` of tokens from `from` to `to`.\n function _transfer(address from, address to, uint256 amount) internal virtual {\n _beforeTokenTransfer(from, to, amount);\n /// @solidity memory-safe-assembly\n assembly {\n let from_ := shl(96, from)\n // Compute the balance slot and load its value.\n mstore(0x0c, or(from_, _BALANCE_SLOT_SEED))\n let fromBalanceSlot := keccak256(0x0c, 0x20)\n let fromBalance := sload(fromBalanceSlot)\n // Revert if insufficient balance.\n if gt(amount, fromBalance) {\n mstore(0x00, 0xf4d678b8) // `InsufficientBalance()`.\n revert(0x1c, 0x04)\n }\n // Subtract and store the updated balance.\n sstore(fromBalanceSlot, sub(fromBalance, amount))\n // Compute the balance slot of `to`.\n mstore(0x00, to)\n let toBalanceSlot := keccak256(0x0c, 0x20)\n // Add and store the updated balance of `to`.\n // Will not overflow because the sum of all user balances\n // cannot exceed the maximum uint256 value.\n sstore(toBalanceSlot, add(sload(toBalanceSlot), amount))\n // Emit the {Transfer} event.\n mstore(0x20, amount)\n log3(0x20, 0x20, _TRANSFER_EVENT_SIGNATURE, shr(96, from_), shr(96, mload(0x0c)))\n }\n _afterTokenTransfer(from, to, amount);\n }\n\n /*´:°•.°+.*•´.*:˚.°*.˚•´.°:°•.°•.*•´.*:˚.°*.˚•´.°:°•.°+.*•´.*:*/\n /* INTERNAL ALLOWANCE FUNCTIONS */\n /*.•°:°.´+˚.*°.˚:*.´•*.+°.•°:´*.´•*.•°.•°:°.´:•˚°.*°.˚:*.´+°.•*/\n\n /// @dev Updates the allowance of `owner` for `spender` based on spent `amount`.\n function _spendAllowance(address owner, address spender, uint256 amount) internal virtual {\n /// @solidity memory-safe-assembly\n assembly {\n // Compute the allowance slot and load its value.\n mstore(0x20, spender)\n mstore(0x0c, _ALLOWANCE_SLOT_SEED)\n mstore(0x00, owner)\n let allowanceSlot := keccak256(0x0c, 0x34)\n let allowance_ := sload(allowanceSlot)\n // If the allowance is not the maximum uint256 value.\n if add(allowance_, 1) {\n // Revert if the amount to be transferred exceeds the allowance.\n if gt(amount, allowance_) {\n mstore(0x00, 0x13be252b) // `InsufficientAllowance()`.\n revert(0x1c, 0x04)\n }\n // Subtract and store the updated allowance.\n sstore(allowanceSlot, sub(allowance_, amount))\n }\n }\n }\n\n /// @dev Sets `amount` as the allowance of `spender` over the tokens of `owner`.\n ///\n /// Emits a {Approval} event.\n function _approve(address owner, address spender, uint256 amount) internal virtual {\n /// @solidity memory-safe-assembly\n assembly {\n let owner_ := shl(96, owner)\n // Compute the allowance slot and store the amount.\n mstore(0x20, spender)\n mstore(0x0c, or(owner_, _ALLOWANCE_SLOT_SEED))\n sstore(keccak256(0x0c, 0x34), amount)\n // Emit the {Approval} event.\n mstore(0x00, amount)\n log3(0x00, 0x20, _APPROVAL_EVENT_SIGNATURE, shr(96, owner_), shr(96, mload(0x2c)))\n }\n }\n\n /*´:°•.°+.*•´.*:˚.°*.˚•´.°:°•.°•.*•´.*:˚.°*.˚•´.°:°•.°+.*•´.*:*/\n /* HOOKS TO OVERRIDE */\n /*.•°:°.´+˚.*°.˚:*.´•*.+°.•°:´*.´•*.•°.•°:°.´:•˚°.*°.˚:*.´+°.•*/\n\n /// @dev Hook that is called before any transfer of tokens.\n /// This includes minting and burning.\n function _beforeTokenTransfer(address from, address to, uint256 amount) internal virtual {}\n\n /// @dev Hook that is called after any transfer of tokens.\n /// This includes minting and burning.\n function _afterTokenTransfer(address from, address to, uint256 amount) internal virtual {}\n}\n"
},
"lib/solady/src/utils/ReentrancyGuard.sol": {
"content": "// SPDX-License-Identifier: MIT\npragma solidity ^0.8.4;\n\n/// @notice Reentrancy guard mixin.\n/// @author Solady (https://github.com/vectorized/solady/blob/main/src/utils/ReentrancyGuard.sol)\nabstract contract ReentrancyGuard {\n /*´:°•.°+.*•´.*:˚.°*.˚•´.°:°•.°•.*•´.*:˚.°*.˚•´.°:°•.°+.*•´.*:*/\n /* CUSTOM ERRORS */\n /*.•°:°.´+˚.*°.˚:*.´•*.+°.•°:´*.´•*.•°.•°:°.´:•˚°.*°.˚:*.´+°.•*/\n\n /// @dev Unauthorized reentrant call.\n error Reentrancy();\n\n /*´:°•.°+.*•´.*:˚.°*.˚•´.°:°•.°•.*•´.*:˚.°*.˚•´.°:°•.°+.*•´.*:*/\n /* STORAGE */\n /*.•°:°.´+˚.*°.˚:*.´•*.+°.•°:´*.´•*.•°.•°:°.´:•˚°.*°.˚:*.´+°.•*/\n\n /// @dev Equivalent to: `uint72(bytes9(keccak256(\"_REENTRANCY_GUARD_SLOT\")))`.\n /// 9 bytes is large enough to avoid collisions with lower slots,\n /// but not too large to result in excessive bytecode bloat.\n uint256 private constant _REENTRANCY_GUARD_SLOT = 0x929eee149b4bd21268;\n\n /*´:°•.°+.*•´.*:˚.°*.˚•´.°:°•.°•.*•´.*:˚.°*.˚•´.°:°•.°+.*•´.*:*/\n /* REENTRANCY GUARD */\n /*.•°:°.´+˚.*°.˚:*.´•*.+°.•°:´*.´•*.•°.•°:°.´:•˚°.*°.˚:*.´+°.•*/\n\n /// @dev Guards a function from reentrancy.\n modifier nonReentrant() virtual {\n /// @solidity memory-safe-assembly\n assembly {\n if eq(sload(_REENTRANCY_GUARD_SLOT), address()) {\n mstore(0x00, 0xab143c06) // `Reentrancy()`.\n revert(0x1c, 0x04)\n }\n sstore(_REENTRANCY_GUARD_SLOT, address())\n }\n _;\n /// @solidity memory-safe-assembly\n assembly {\n sstore(_REENTRANCY_GUARD_SLOT, codesize())\n }\n }\n\n /// @dev Guards a view function from read-only reentrancy.\n modifier nonReadReentrant() virtual {\n /// @solidity memory-safe-assembly\n assembly {\n if eq(sload(_REENTRANCY_GUARD_SLOT), address()) {\n mstore(0x00, 0xab143c06) // `Reentrancy()`.\n revert(0x1c, 0x04)\n }\n }\n _;\n }\n}\n"
},
"lib/solady/src/utils/FixedPointMathLib.sol": {
"content": "// SPDX-License-Identifier: MIT\npragma solidity ^0.8.4;\n\n/// @notice Arithmetic library with operations for fixed-point numbers.\n/// @author Solady (https://github.com/vectorized/solady/blob/main/src/utils/FixedPointMathLib.sol)\n/// @author Modified from Solmate (https://github.com/transmissions11/solmate/blob/main/src/utils/FixedPointMathLib.sol)\nlibrary FixedPointMathLib {\n /*´:°•.°+.*•´.*:˚.°*.˚•´.°:°•.°•.*•´.*:˚.°*.˚•´.°:°•.°+.*•´.*:*/\n /* CUSTOM ERRORS */\n /*.•°:°.´+˚.*°.˚:*.´•*.+°.•°:´*.´•*.•°.•°:°.´:•˚°.*°.˚:*.´+°.•*/\n\n /// @dev The operation failed, as the output exceeds the maximum value of uint256.\n error ExpOverflow();\n\n /// @dev The operation failed, as the output exceeds the maximum value of uint256.\n error FactorialOverflow();\n\n /// @dev The operation failed, due to an overflow.\n error RPowOverflow();\n\n /// @dev The mantissa is too big to fit.\n error MantissaOverflow();\n\n /// @dev The operation failed, due to an multiplication overflow.\n error MulWadFailed();\n\n /// @dev The operation failed, due to an multiplication overflow.\n error SMulWadFailed();\n\n /// @dev The operation failed, either due to a multiplication overflow, or a division by a zero.\n error DivWadFailed();\n\n /// @dev The operation failed, either due to a multiplication overflow, or a division by a zero.\n error SDivWadFailed();\n\n /// @dev The operation failed, either due to a multiplication overflow, or a division by a zero.\n error MulDivFailed();\n\n /// @dev The division failed, as the denominator is zero.\n error DivFailed();\n\n /// @dev The full precision multiply-divide operation failed, either due\n /// to the result being larger than 256 bits, or a division by a zero.\n error FullMulDivFailed();\n\n /// @dev The output is undefined, as the input is less-than-or-equal to zero.\n error LnWadUndefined();\n\n /// @dev The input outside the acceptable domain.\n error OutOfDomain();\n\n /*´:°•.°+.*•´.*:˚.°*.˚•´.°:°•.°•.*•´.*:˚.°*.˚•´.°:°•.°+.*•´.*:*/\n /* CONSTANTS */\n /*.•°:°.´+˚.*°.˚:*.´•*.+°.•°:´*.´•*.•°.•°:°.´:•˚°.*°.˚:*.´+°.•*/\n\n /// @dev The scalar of ETH and most ERC20s.\n uint256 internal constant WAD = 1e18;\n\n /*´:°•.°+.*•´.*:˚.°*.˚•´.°:°•.°•.*•´.*:˚.°*.˚•´.°:°•.°+.*•´.*:*/\n /* SIMPLIFIED FIXED POINT OPERATIONS */\n /*.•°:°.´+˚.*°.˚:*.´•*.+°.•°:´*.´•*.•°.•°:°.´:•˚°.*°.˚:*.´+°.•*/\n\n /// @dev Equivalent to `(x * y) / WAD` rounded down.\n function mulWad(uint256 x, uint256 y) internal pure returns (uint256 z) {\n /// @solidity memory-safe-assembly\n assembly {\n // Equivalent to `require(y == 0 || x <= type(uint256).max / y)`.\n if mul(y, gt(x, div(not(0), y))) {\n mstore(0x00, 0xbac65e5b) // `MulWadFailed()`.\n revert(0x1c, 0x04)\n }\n z := div(mul(x, y), WAD)\n }\n }\n\n /// @dev Equivalent to `(x * y) / WAD` rounded down.\n function sMulWad(int256 x, int256 y) internal pure returns (int256 z) {\n /// @solidity memory-safe-assembly\n assembly {\n z := mul(x, y)\n // Equivalent to `require((x == 0 || z / x == y) && !(x == -1 && y == type(int256).min))`.\n if iszero(gt(or(iszero(x), eq(sdiv(z, x), y)), lt(not(x), eq(y, shl(255, 1))))) {\n mstore(0x00, 0xedcd4dd4) // `SMulWadFailed()`.\n revert(0x1c, 0x04)\n }\n z := sdiv(z, WAD)\n }\n }\n\n /// @dev Equivalent to `(x * y) / WAD` rounded down, but without overflow checks.\n function rawMulWad(uint256 x, uint256 y) internal pure returns (uint256 z) {\n /// @solidity memory-safe-assembly\n assembly {\n z := div(mul(x, y), WAD)\n }\n }\n\n /// @dev Equivalent to `(x * y) / WAD` rounded down, but without overflow checks.\n function rawSMulWad(int256 x, int256 y) internal pure returns (int256 z) {\n /// @solidity memory-safe-assembly\n assembly {\n z := sdiv(mul(x, y), WAD)\n }\n }\n\n /// @dev Equivalent to `(x * y) / WAD` rounded up.\n function mulWadUp(uint256 x, uint256 y) internal pure returns (uint256 z) {\n /// @solidity memory-safe-assembly\n assembly {\n // Equivalent to `require(y == 0 || x <= type(uint256).max / y)`.\n if mul(y, gt(x, div(not(0), y))) {\n mstore(0x00, 0xbac65e5b) // `MulWadFailed()`.\n revert(0x1c, 0x04)\n }\n z := add(iszero(iszero(mod(mul(x, y), WAD))), div(mul(x, y), WAD))\n }\n }\n\n /// @dev Equivalent to `(x * y) / WAD` rounded up, but without overflow checks.\n function rawMulWadUp(uint256 x, uint256 y) internal pure returns (uint256 z) {\n /// @solidity memory-safe-assembly\n assembly {\n z := add(iszero(iszero(mod(mul(x, y), WAD))), div(mul(x, y), WAD))\n }\n }\n\n /// @dev Equivalent to `(x * WAD) / y` rounded down.\n function divWad(uint256 x, uint256 y) internal pure returns (uint256 z) {\n /// @solidity memory-safe-assembly\n assembly {\n // Equivalent to `require(y != 0 && (WAD == 0 || x <= type(uint256).max / WAD))`.\n if iszero(mul(y, iszero(mul(WAD, gt(x, div(not(0), WAD)))))) {\n mstore(0x00, 0x7c5f487d) // `DivWadFailed()`.\n revert(0x1c, 0x04)\n }\n z := div(mul(x, WAD), y)\n }\n }\n\n /// @dev Equivalent to `(x * WAD) / y` rounded down.\n function sDivWad(int256 x, int256 y) internal pure returns (int256 z) {\n /// @solidity memory-safe-assembly\n assembly {\n z := mul(x, WAD)\n // Equivalent to `require(y != 0 && ((x * WAD) / WAD == x))`.\n if iszero(and(iszero(iszero(y)), eq(sdiv(z, WAD), x))) {\n mstore(0x00, 0x5c43740d) // `SDivWadFailed()`.\n revert(0x1c, 0x04)\n }\n z := sdiv(mul(x, WAD), y)\n }\n }\n\n /// @dev Equivalent to `(x * WAD) / y` rounded down, but without overflow and divide by zero checks.\n function rawDivWad(uint256 x, uint256 y) internal pure returns (uint256 z) {\n /// @solidity memory-safe-assembly\n assembly {\n z := div(mul(x, WAD), y)\n }\n }\n\n /// @dev Equivalent to `(x * WAD) / y` rounded down, but without overflow and divide by zero checks.\n function rawSDivWad(int256 x, int256 y) internal pure returns (int256 z) {\n /// @solidity memory-safe-assembly\n assembly {\n z := sdiv(mul(x, WAD), y)\n }\n }\n\n /// @dev Equivalent to `(x * WAD) / y` rounded up.\n function divWadUp(uint256 x, uint256 y) internal pure returns (uint256 z) {\n /// @solidity memory-safe-assembly\n assembly {\n // Equivalent to `require(y != 0 && (WAD == 0 || x <= type(uint256).max / WAD))`.\n if iszero(mul(y, iszero(mul(WAD, gt(x, div(not(0), WAD)))))) {\n mstore(0x00, 0x7c5f487d) // `DivWadFailed()`.\n revert(0x1c, 0x04)\n }\n z := add(iszero(iszero(mod(mul(x, WAD), y))), div(mul(x, WAD), y))\n }\n }\n\n /// @dev Equivalent to `(x * WAD) / y` rounded up, but without overflow and divide by zero checks.\n function rawDivWadUp(uint256 x, uint256 y) internal pure returns (uint256 z) {\n /// @solidity memory-safe-assembly\n assembly {\n z := add(iszero(iszero(mod(mul(x, WAD), y))), div(mul(x, WAD), y))\n }\n }\n\n /// @dev Equivalent to `x` to the power of `y`.\n /// because `x ** y = (e ** ln(x)) ** y = e ** (ln(x) * y)`.\n /// Note: This function is an approximation.\n function powWad(int256 x, int256 y) internal pure returns (int256) {\n // Using `ln(x)` means `x` must be greater than 0.\n return expWad((lnWad(x) * y) / int256(WAD));\n }\n\n /// @dev Returns `exp(x)`, denominated in `WAD`.\n /// Credit to Remco Bloemen under MIT license: https://2π.com/22/exp-ln\n /// Note: This function is an approximation. Monotonically increasing.\n function expWad(int256 x) internal pure returns (int256 r) {\n unchecked {\n // When the result is less than 0.5 we return zero.\n // This happens when `x <= (log(1e-18) * 1e18) ~ -4.15e19`.\n if (x <= -41446531673892822313) return r;\n\n /// @solidity memory-safe-assembly\n assembly {\n // When the result is greater than `(2**255 - 1) / 1e18` we can not represent it as\n // an int. This happens when `x >= floor(log((2**255 - 1) / 1e18) * 1e18) ≈ 135`.\n if iszero(slt(x, 135305999368893231589)) {\n mstore(0x00, 0xa37bfec9) // `ExpOverflow()`.\n revert(0x1c, 0x04)\n }\n }\n\n // `x` is now in the range `(-42, 136) * 1e18`. Convert to `(-42, 136) * 2**96`\n // for more intermediate precision and a binary basis. This base conversion\n // is a multiplication by 1e18 / 2**96 = 5**18 / 2**78.\n x = (x << 78) / 5 ** 18;\n\n // Reduce range of x to (-½ ln 2, ½ ln 2) * 2**96 by factoring out powers\n // of two such that exp(x) = exp(x') * 2**k, where k is an integer.\n // Solving this gives k = round(x / log(2)) and x' = x - k * log(2).\n int256 k = ((x << 96) / 54916777467707473351141471128 + 2 ** 95) >> 96;\n x = x - k * 54916777467707473351141471128;\n\n // `k` is in the range `[-61, 195]`.\n\n // Evaluate using a (6, 7)-term rational approximation.\n // `p` is made monic, we'll multiply by a scale factor later.\n int256 y = x + 1346386616545796478920950773328;\n y = ((y * x) >> 96) + 57155421227552351082224309758442;\n int256 p = y + x - 94201549194550492254356042504812;\n p = ((p * y) >> 96) + 28719021644029726153956944680412240;\n p = p * x + (4385272521454847904659076985693276 << 96);\n\n // We leave `p` in `2**192` basis so we don't need to scale it back up for the division.\n int256 q = x - 2855989394907223263936484059900;\n q = ((q * x) >> 96) + 50020603652535783019961831881945;\n q = ((q * x) >> 96) - 533845033583426703283633433725380;\n q = ((q * x) >> 96) + 3604857256930695427073651918091429;\n q = ((q * x) >> 96) - 14423608567350463180887372962807573;\n q = ((q * x) >> 96) + 26449188498355588339934803723976023;\n\n /// @solidity memory-safe-assembly\n assembly {\n // Div in assembly because solidity adds a zero check despite the unchecked.\n // The q polynomial won't have zeros in the domain as all its roots are complex.\n // No scaling is necessary because p is already `2**96` too large.\n r := sdiv(p, q)\n }\n\n // r should be in the range `(0.09, 0.25) * 2**96`.\n\n // We now need to multiply r by:\n // - The scale factor `s ≈ 6.031367120`.\n // - The `2**k` factor from the range reduction.\n // - The `1e18 / 2**96` factor for base conversion.\n // We do this all at once, with an intermediate result in `2**213`\n // basis, so the final right shift is always by a positive amount.\n r = int256(\n (uint256(r) * 3822833074963236453042738258902158003155416615667) >> uint256(195 - k)\n );\n }\n }\n\n /// @dev Returns `ln(x)`, denominated in `WAD`.\n /// Credit to Remco Bloemen under MIT license: https://2π.com/22/exp-ln\n /// Note: This function is an approximation. Monotonically increasing.\n function lnWad(int256 x) internal pure returns (int256 r) {\n /// @solidity memory-safe-assembly\n assembly {\n // We want to convert `x` from `10**18` fixed point to `2**96` fixed point.\n // We do this by multiplying by `2**96 / 10**18`. But since\n // `ln(x * C) = ln(x) + ln(C)`, we can simply do nothing here\n // and add `ln(2**96 / 10**18)` at the end.\n\n // Compute `k = log2(x) - 96`, `r = 159 - k = 255 - log2(x) = 255 ^ log2(x)`.\n r := shl(7, lt(0xffffffffffffffffffffffffffffffff, x))\n r := or(r, shl(6, lt(0xffffffffffffffff, shr(r, x))))\n r := or(r, shl(5, lt(0xffffffff, shr(r, x))))\n r := or(r, shl(4, lt(0xffff, shr(r, x))))\n r := or(r, shl(3, lt(0xff, shr(r, x))))\n // We place the check here for more optimal stack operations.\n if iszero(sgt(x, 0)) {\n mstore(0x00, 0x1615e638) // `LnWadUndefined()`.\n revert(0x1c, 0x04)\n }\n // forgefmt: disable-next-item\n r := xor(r, byte(and(0x1f, shr(shr(r, x), 0x8421084210842108cc6318c6db6d54be)),\n 0xf8f9f9faf9fdfafbf9fdfcfdfafbfcfef9fafdfafcfcfbfefafafcfbffffffff))\n\n // Reduce range of x to (1, 2) * 2**96\n // ln(2^k * x) = k * ln(2) + ln(x)\n x := shr(159, shl(r, x))\n\n // Evaluate using a (8, 8)-term rational approximation.\n // `p` is made monic, we will multiply by a scale factor later.\n // forgefmt: disable-next-item\n let p := sub( // This heavily nested expression is to avoid stack-too-deep for via-ir.\n sar(96, mul(add(43456485725739037958740375743393,\n sar(96, mul(add(24828157081833163892658089445524,\n sar(96, mul(add(3273285459638523848632254066296,\n x), x))), x))), x)), 11111509109440967052023855526967)\n p := sub(sar(96, mul(p, x)), 45023709667254063763336534515857)\n p := sub(sar(96, mul(p, x)), 14706773417378608786704636184526)\n p := sub(mul(p, x), shl(96, 795164235651350426258249787498))\n // We leave `p` in `2**192` basis so we don't need to scale it back up for the division.\n\n // `q` is monic by convention.\n let q := add(5573035233440673466300451813936, x)\n q := add(71694874799317883764090561454958, sar(96, mul(x, q)))\n q := add(283447036172924575727196451306956, sar(96, mul(x, q)))\n q := add(401686690394027663651624208769553, sar(96, mul(x, q)))\n q := add(204048457590392012362485061816622, sar(96, mul(x, q)))\n q := add(31853899698501571402653359427138, sar(96, mul(x, q)))\n q := add(909429971244387300277376558375, sar(96, mul(x, q)))\n\n // `p / q` is in the range `(0, 0.125) * 2**96`.\n\n // Finalization, we need to:\n // - Multiply by the scale factor `s = 5.549…`.\n // - Add `ln(2**96 / 10**18)`.\n // - Add `k * ln(2)`.\n // - Multiply by `10**18 / 2**96 = 5**18 >> 78`.\n\n // The q polynomial is known not to have zeros in the domain.\n // No scaling required because p is already `2**96` too large.\n p := sdiv(p, q)\n // Multiply by the scaling factor: `s * 5**18 * 2**96`, base is now `5**18 * 2**192`.\n p := mul(1677202110996718588342820967067443963516166, p)\n // Add `ln(2) * k * 5**18 * 2**192`.\n // forgefmt: disable-next-item\n p := add(mul(16597577552685614221487285958193947469193820559219878177908093499208371, sub(159, r)), p)\n // Add `ln(2**96 / 10**18) * 5**18 * 2**192`.\n p := add(600920179829731861736702779321621459595472258049074101567377883020018308, p)\n // Base conversion: mul `2**18 / 2**192`.\n r := sar(174, p)\n }\n }\n\n /// @dev Returns `W_0(x)`, denominated in `WAD`.\n /// See: https://en.wikipedia.org/wiki/Lambert_W_function\n /// a.k.a. Product log function. This is an approximation of the principal branch.\n /// Note: This function is an approximation. Monotonically increasing.\n function lambertW0Wad(int256 x) internal pure returns (int256 w) {\n // forgefmt: disable-next-item\n unchecked {\n if ((w = x) <= -367879441171442322) revert OutOfDomain(); // `x` less than `-1/e`.\n int256 wad = int256(WAD);\n int256 p = x;\n uint256 c; // Whether we need to avoid catastrophic cancellation.\n uint256 i = 4; // Number of iterations.\n if (w <= 0x1ffffffffffff) {\n if (-0x4000000000000 <= w) {\n i = 1; // Inputs near zero only take one step to converge.\n } else if (w <= -0x3ffffffffffffff) {\n i = 32; // Inputs near `-1/e` take very long to converge.\n }\n } else if (uint256(w >> 63) == uint256(0)) {\n /// @solidity memory-safe-assembly\n assembly {\n // Inline log2 for more performance, since the range is small.\n let v := shr(49, w)\n let l := shl(3, lt(0xff, v))\n l := add(or(l, byte(and(0x1f, shr(shr(l, v), 0x8421084210842108cc6318c6db6d54be)),\n 0x0706060506020504060203020504030106050205030304010505030400000000)), 49)\n w := sdiv(shl(l, 7), byte(sub(l, 31), 0x0303030303030303040506080c13))\n c := gt(l, 60)\n i := add(2, add(gt(l, 53), c))\n }\n } else {\n int256 ll = lnWad(w = lnWad(w));\n /// @solidity memory-safe-assembly\n assembly {\n // `w = ln(x) - ln(ln(x)) + b * ln(ln(x)) / ln(x)`.\n w := add(sdiv(mul(ll, 1023715080943847266), w), sub(w, ll))\n i := add(3, iszero(shr(68, x)))\n c := iszero(shr(143, x))\n }\n if (c == uint256(0)) {\n do { // If `x` is big, use Newton's so that intermediate values won't overflow.\n int256 e = expWad(w);\n /// @solidity memory-safe-assembly\n assembly {\n let t := mul(w, div(e, wad))\n w := sub(w, sdiv(sub(t, x), div(add(e, t), wad)))\n }\n if (p <= w) break;\n p = w;\n } while (--i != uint256(0));\n /// @solidity memory-safe-assembly\n assembly {\n w := sub(w, sgt(w, 2))\n }\n return w;\n }\n }\n do { // Otherwise, use Halley's for faster convergence.\n int256 e = expWad(w);\n /// @solidity memory-safe-assembly\n assembly {\n let t := add(w, wad)\n let s := sub(mul(w, e), mul(x, wad))\n w := sub(w, sdiv(mul(s, wad), sub(mul(e, t), sdiv(mul(add(t, wad), s), add(t, t)))))\n }\n if (p <= w) break;\n p = w;\n } while (--i != c);\n /// @solidity memory-safe-assembly\n assembly {\n w := sub(w, sgt(w, 2))\n }\n // For certain ranges of `x`, we'll use the quadratic-rate recursive formula of\n // R. Iacono and J.P. Boyd for the last iteration, to avoid catastrophic cancellation.\n if (c != uint256(0)) {\n int256 t = w | 1;\n /// @solidity memory-safe-assembly\n assembly {\n x := sdiv(mul(x, wad), t)\n }\n x = (t * (wad + lnWad(x)));\n /// @solidity memory-safe-assembly\n assembly {\n w := sdiv(x, add(wad, t))\n }\n }\n }\n }\n\n /*´:°•.°+.*•´.*:˚.°*.˚•´.°:°•.°•.*•´.*:˚.°*.˚•´.°:°•.°+.*•´.*:*/\n /* GENERAL NUMBER UTILITIES */\n /*.•°:°.´+˚.*°.˚:*.´•*.+°.•°:´*.´•*.•°.•°:°.´:•˚°.*°.˚:*.´+°.•*/\n\n /// @dev Calculates `floor(x * y / d)` with full precision.\n /// Throws if result overflows a uint256 or when `d` is zero.\n /// Credit to Remco Bloemen under MIT license: https://2π.com/21/muldiv\n function fullMulDiv(uint256 x, uint256 y, uint256 d) internal pure returns (uint256 result) {\n /// @solidity memory-safe-assembly\n assembly {\n // 512-bit multiply `[p1 p0] = x * y`.\n // Compute the product mod `2**256` and mod `2**256 - 1`\n // then use the Chinese Remainder Theorem to reconstruct\n // the 512 bit result. The result is stored in two 256\n // variables such that `product = p1 * 2**256 + p0`.\n\n // Temporarily use `result` as `p0` to save gas.\n result := mul(x, y) // Lower 256 bits of `x * y`.\n for {} 1 {} {\n // If overflows.\n if iszero(mul(or(iszero(x), eq(div(result, x), y)), d)) {\n let mm := mulmod(x, y, not(0))\n let p1 := sub(mm, add(result, lt(mm, result))) // Upper 256 bits of `x * y`.\n\n /*------------------- 512 by 256 division --------------------*/\n\n // Make division exact by subtracting the remainder from `[p1 p0]`.\n let r := mulmod(x, y, d) // Compute remainder using mulmod.\n let t := and(d, sub(0, d)) // The least significant bit of `d`. `t >= 1`.\n // Make sure the result is less than `2**256`. Also prevents `d == 0`.\n // Placing the check here seems to give more optimal stack operations.\n if iszero(gt(d, p1)) {\n mstore(0x00, 0xae47f702) // `FullMulDivFailed()`.\n revert(0x1c, 0x04)\n }\n d := div(d, t) // Divide `d` by `t`, which is a power of two.\n // Invert `d mod 2**256`\n // Now that `d` is an odd number, it has an inverse\n // modulo `2**256` such that `d * inv = 1 mod 2**256`.\n // Compute the inverse by starting with a seed that is correct\n // correct for four bits. That is, `d * inv = 1 mod 2**4`.\n let inv := xor(2, mul(3, d))\n // Now use Newton-Raphson iteration to improve the precision.\n // Thanks to Hensel's lifting lemma, this also works in modular\n // arithmetic, doubling the correct bits in each step.\n inv := mul(inv, sub(2, mul(d, inv))) // inverse mod 2**8\n inv := mul(inv, sub(2, mul(d, inv))) // inverse mod 2**16\n inv := mul(inv, sub(2, mul(d, inv))) // inverse mod 2**32\n inv := mul(inv, sub(2, mul(d, inv))) // inverse mod 2**64\n inv := mul(inv, sub(2, mul(d, inv))) // inverse mod 2**128\n result :=\n mul(\n // Divide [p1 p0] by the factors of two.\n // Shift in bits from `p1` into `p0`. For this we need\n // to flip `t` such that it is `2**256 / t`.\n or(\n mul(sub(p1, gt(r, result)), add(div(sub(0, t), t), 1)),\n div(sub(result, r), t)\n ),\n mul(sub(2, mul(d, inv)), inv) // inverse mod 2**256\n )\n break\n }\n result := div(result, d)\n break\n }\n }\n }\n\n /// @dev Calculates `floor(x * y / d)` with full precision.\n /// Behavior is undefined if `d` is zero or the final result cannot fit in 256 bits.\n /// Performs the full 512 bit calculation regardless.\n function fullMulDivUnchecked(uint256 x, uint256 y, uint256 d)\n internal\n pure\n returns (uint256 result)\n {\n /// @solidity memory-safe-assembly\n assembly {\n result := mul(x, y)\n let mm := mulmod(x, y, not(0))\n let p1 := sub(mm, add(result, lt(mm, result)))\n let t := and(d, sub(0, d))\n let r := mulmod(x, y, d)\n d := div(d, t)\n let inv := xor(2, mul(3, d))\n inv := mul(inv, sub(2, mul(d, inv)))\n inv := mul(inv, sub(2, mul(d, inv)))\n inv := mul(inv, sub(2, mul(d, inv)))\n inv := mul(inv, sub(2, mul(d, inv)))\n inv := mul(inv, sub(2, mul(d, inv)))\n result :=\n mul(\n or(mul(sub(p1, gt(r, result)), add(div(sub(0, t), t), 1)), div(sub(result, r), t)),\n mul(sub(2, mul(d, inv)), inv)\n )\n }\n }\n\n /// @dev Calculates `floor(x * y / d)` with full precision, rounded up.\n /// Throws if result overflows a uint256 or when `d` is zero.\n /// Credit to Uniswap-v3-core under MIT license:\n /// https://github.com/Uniswap/v3-core/blob/main/contracts/libraries/FullMath.sol\n function fullMulDivUp(uint256 x, uint256 y, uint256 d) internal pure returns (uint256 result) {\n result = fullMulDiv(x, y, d);\n /// @solidity memory-safe-assembly\n assembly {\n if mulmod(x, y, d) {\n result := add(result, 1)\n if iszero(result) {\n mstore(0x00, 0xae47f702) // `FullMulDivFailed()`.\n revert(0x1c, 0x04)\n }\n }\n }\n }\n\n /// @dev Returns `floor(x * y / d)`.\n /// Reverts if `x * y` overflows, or `d` is zero.\n function mulDiv(uint256 x, uint256 y, uint256 d) internal pure returns (uint256 z) {\n /// @solidity memory-safe-assembly\n assembly {\n z := mul(x, y)\n // Equivalent to `require(d != 0 && (y == 0 || x <= type(uint256).max / y))`.\n if iszero(mul(or(iszero(x), eq(div(z, x), y)), d)) {\n mstore(0x00, 0xad251c27) // `MulDivFailed()`.\n revert(0x1c, 0x04)\n }\n z := div(z, d)\n }\n }\n\n /// @dev Returns `ceil(x * y / d)`.\n /// Reverts if `x * y` overflows, or `d` is zero.\n function mulDivUp(uint256 x, uint256 y, uint256 d) internal pure returns (uint256 z) {\n /// @solidity memory-safe-assembly\n assembly {\n z := mul(x, y)\n // Equivalent to `require(d != 0 && (y == 0 || x <= type(uint256).max / y))`.\n if iszero(mul(or(iszero(x), eq(div(z, x), y)), d)) {\n mstore(0x00, 0xad251c27) // `MulDivFailed()`.\n revert(0x1c, 0x04)\n }\n z := add(iszero(iszero(mod(z, d))), div(z, d))\n }\n }\n\n /// @dev Returns `ceil(x / d)`.\n /// Reverts if `d` is zero.\n function divUp(uint256 x, uint256 d) internal pure returns (uint256 z) {\n /// @solidity memory-safe-assembly\n assembly {\n if iszero(d) {\n mstore(0x00, 0x65244e4e) // `DivFailed()`.\n revert(0x1c, 0x04)\n }\n z := add(iszero(iszero(mod(x, d))), div(x, d))\n }\n }\n\n /// @dev Returns `max(0, x - y)`.\n function zeroFloorSub(uint256 x, uint256 y) internal pure returns (uint256 z) {\n /// @solidity memory-safe-assembly\n assembly {\n z := mul(gt(x, y), sub(x, y))\n }\n }\n\n /// @dev Exponentiate `x` to `y` by squaring, denominated in base `b`.\n /// Reverts if the computation overflows.\n function rpow(uint256 x, uint256 y, uint256 b) internal pure returns (uint256 z) {\n /// @solidity memory-safe-assembly\n assembly {\n z := mul(b, iszero(y)) // `0 ** 0 = 1`. Otherwise, `0 ** n = 0`.\n if x {\n z := xor(b, mul(xor(b, x), and(y, 1))) // `z = isEven(y) ? scale : x`\n let half := shr(1, b) // Divide `b` by 2.\n // Divide `y` by 2 every iteration.\n for { y := shr(1, y) } y { y := shr(1, y) } {\n let xx := mul(x, x) // Store x squared.\n let xxRound := add(xx, half) // Round to the nearest number.\n // Revert if `xx + half` overflowed, or if `x ** 2` overflows.\n if or(lt(xxRound, xx), shr(128, x)) {\n mstore(0x00, 0x49f7642b) // `RPowOverflow()`.\n revert(0x1c, 0x04)\n }\n x := div(xxRound, b) // Set `x` to scaled `xxRound`.\n // If `y` is odd:\n if and(y, 1) {\n let zx := mul(z, x) // Compute `z * x`.\n let zxRound := add(zx, half) // Round to the nearest number.\n // If `z * x` overflowed or `zx + half` overflowed:\n if or(xor(div(zx, x), z), lt(zxRound, zx)) {\n // Revert if `x` is non-zero.\n if x {\n mstore(0x00, 0x49f7642b) // `RPowOverflow()`.\n revert(0x1c, 0x04)\n }\n }\n z := div(zxRound, b) // Return properly scaled `zxRound`.\n }\n }\n }\n }\n }\n\n /// @dev Returns the square root of `x`, rounded down.\n function sqrt(uint256 x) internal pure returns (uint256 z) {\n /// @solidity memory-safe-assembly\n assembly {\n // `floor(sqrt(2**15)) = 181`. `sqrt(2**15) - 181 = 2.84`.\n z := 181 // The \"correct\" value is 1, but this saves a multiplication later.\n\n // This segment is to get a reasonable initial estimate for the Babylonian method. With a bad\n // start, the correct # of bits increases ~linearly each iteration instead of ~quadratically.\n\n // Let `y = x / 2**r`. We check `y >= 2**(k + 8)`\n // but shift right by `k` bits to ensure that if `x >= 256`, then `y >= 256`.\n let r := shl(7, lt(0xffffffffffffffffffffffffffffffffff, x))\n r := or(r, shl(6, lt(0xffffffffffffffffff, shr(r, x))))\n r := or(r, shl(5, lt(0xffffffffff, shr(r, x))))\n r := or(r, shl(4, lt(0xffffff, shr(r, x))))\n z := shl(shr(1, r), z)\n\n // Goal was to get `z*z*y` within a small factor of `x`. More iterations could\n // get y in a tighter range. Currently, we will have y in `[256, 256*(2**16))`.\n // We ensured `y >= 256` so that the relative difference between `y` and `y+1` is small.\n // That's not possible if `x < 256` but we can just verify those cases exhaustively.\n\n // Now, `z*z*y <= x < z*z*(y+1)`, and `y <= 2**(16+8)`, and either `y >= 256`, or `x < 256`.\n // Correctness can be checked exhaustively for `x < 256`, so we assume `y >= 256`.\n // Then `z*sqrt(y)` is within `sqrt(257)/sqrt(256)` of `sqrt(x)`, or about 20bps.\n\n // For `s` in the range `[1/256, 256]`, the estimate `f(s) = (181/1024) * (s+1)`\n // is in the range `(1/2.84 * sqrt(s), 2.84 * sqrt(s))`,\n // with largest error when `s = 1` and when `s = 256` or `1/256`.\n\n // Since `y` is in `[256, 256*(2**16))`, let `a = y/65536`, so that `a` is in `[1/256, 256)`.\n // Then we can estimate `sqrt(y)` using\n // `sqrt(65536) * 181/1024 * (a + 1) = 181/4 * (y + 65536)/65536 = 181 * (y + 65536)/2**18`.\n\n // There is no overflow risk here since `y < 2**136` after the first branch above.\n z := shr(18, mul(z, add(shr(r, x), 65536))) // A `mul()` is saved from starting `z` at 181.\n\n // Given the worst case multiplicative error of 2.84 above, 7 iterations should be enough.\n z := shr(1, add(z, div(x, z)))\n z := shr(1, add(z, div(x, z)))\n z := shr(1, add(z, div(x, z)))\n z := shr(1, add(z, div(x, z)))\n z := shr(1, add(z, div(x, z)))\n z := shr(1, add(z, div(x, z)))\n z := shr(1, add(z, div(x, z)))\n\n // If `x+1` is a perfect square, the Babylonian method cycles between\n // `floor(sqrt(x))` and `ceil(sqrt(x))`. This statement ensures we return floor.\n // See: https://en.wikipedia.org/wiki/Integer_square_root#Using_only_integer_division\n z := sub(z, lt(div(x, z), z))\n }\n }\n\n /// @dev Returns the cube root of `x`, rounded down.\n /// Credit to bout3fiddy and pcaversaccio under AGPLv3 license:\n /// https://github.com/pcaversaccio/snekmate/blob/main/src/utils/Math.vy\n function cbrt(uint256 x) internal pure returns (uint256 z) {\n /// @solidity memory-safe-assembly\n assembly {\n let r := shl(7, lt(0xffffffffffffffffffffffffffffffff, x))\n r := or(r, shl(6, lt(0xffffffffffffffff, shr(r, x))))\n r := or(r, shl(5, lt(0xffffffff, shr(r, x))))\n r := or(r, shl(4, lt(0xffff, shr(r, x))))\n r := or(r, shl(3, lt(0xff, shr(r, x))))\n\n z := div(shl(div(r, 3), shl(lt(0xf, shr(r, x)), 0xf)), xor(7, mod(r, 3)))\n\n z := div(add(add(div(x, mul(z, z)), z), z), 3)\n z := div(add(add(div(x, mul(z, z)), z), z), 3)\n z := div(add(add(div(x, mul(z, z)), z), z), 3)\n z := div(add(add(div(x, mul(z, z)), z), z), 3)\n z := div(add(add(div(x, mul(z, z)), z), z), 3)\n z := div(add(add(div(x, mul(z, z)), z), z), 3)\n z := div(add(add(div(x, mul(z, z)), z), z), 3)\n\n z := sub(z, lt(div(x, mul(z, z)), z))\n }\n }\n\n /// @dev Returns the square root of `x`, denominated in `WAD`, rounded down.\n function sqrtWad(uint256 x) internal pure returns (uint256 z) {\n unchecked {\n if (x <= type(uint256).max / 10 ** 18) return sqrt(x * 10 ** 18);\n z = (1 + sqrt(x)) * 10 ** 9;\n z = (fullMulDivUnchecked(x, 10 ** 18, z) + z) >> 1;\n }\n /// @solidity memory-safe-assembly\n assembly {\n z := sub(z, gt(999999999999999999, sub(mulmod(z, z, x), 1)))\n }\n }\n\n /// @dev Returns the cube root of `x`, denominated in `WAD`, rounded down.\n function cbrtWad(uint256 x) internal pure returns (uint256 z) {\n unchecked {\n if (x <= type(uint256).max / 10 ** 36) return cbrt(x * 10 ** 36);\n z = (1 + cbrt(x)) * 10 ** 12;\n z = (fullMulDivUnchecked(x, 10 ** 36, z * z) + z + z) / 3;\n }\n /// @solidity memory-safe-assembly\n assembly {\n if iszero(lt(sub(exp(10, 36), 2), sub(mulmod(mul(z, z), z, x), 1))) {\n // forgefmt: disable-next-item\n z := sub(z, eq(mulmod(mul(z, z), z, sub(x, 1)),\n add(exp(10, 36), mulmod(mul(z, z), z, x))))\n }\n }\n }\n\n /// @dev Returns the factorial of `x`.\n function factorial(uint256 x) internal pure returns (uint256 result) {\n /// @solidity memory-safe-assembly\n assembly {\n if iszero(lt(x, 58)) {\n mstore(0x00, 0xaba0f2a2) // `FactorialOverflow()`.\n revert(0x1c, 0x04)\n }\n for { result := 1 } x { x := sub(x, 1) } { result := mul(result, x) }\n }\n }\n\n /// @dev Returns the log2 of `x`.\n /// Equivalent to computing the index of the most significant bit (MSB) of `x`.\n /// Returns 0 if `x` is zero.\n function log2(uint256 x) internal pure returns (uint256 r) {\n /// @solidity memory-safe-assembly\n assembly {\n r := shl(7, lt(0xffffffffffffffffffffffffffffffff, x))\n r := or(r, shl(6, lt(0xffffffffffffffff, shr(r, x))))\n r := or(r, shl(5, lt(0xffffffff, shr(r, x))))\n r := or(r, shl(4, lt(0xffff, shr(r, x))))\n r := or(r, shl(3, lt(0xff, shr(r, x))))\n // forgefmt: disable-next-item\n r := or(r, byte(and(0x1f, shr(shr(r, x), 0x8421084210842108cc6318c6db6d54be)),\n 0x0706060506020504060203020504030106050205030304010505030400000000))\n }\n }\n\n /// @dev Returns the log2 of `x`, rounded up.\n /// Returns 0 if `x` is zero.\n function log2Up(uint256 x) internal pure returns (uint256 r) {\n r = log2(x);\n /// @solidity memory-safe-assembly\n assembly {\n r := add(r, lt(shl(r, 1), x))\n }\n }\n\n /// @dev Returns the log10 of `x`.\n /// Returns 0 if `x` is zero.\n function log10(uint256 x) internal pure returns (uint256 r) {\n /// @solidity memory-safe-assembly\n assembly {\n if iszero(lt(x, 100000000000000000000000000000000000000)) {\n x := div(x, 100000000000000000000000000000000000000)\n r := 38\n }\n if iszero(lt(x, 100000000000000000000)) {\n x := div(x, 100000000000000000000)\n r := add(r, 20)\n }\n if iszero(lt(x, 10000000000)) {\n x := div(x, 10000000000)\n r := add(r, 10)\n }\n if iszero(lt(x, 100000)) {\n x := div(x, 100000)\n r := add(r, 5)\n }\n r := add(r, add(gt(x, 9), add(gt(x, 99), add(gt(x, 999), gt(x, 9999)))))\n }\n }\n\n /// @dev Returns the log10 of `x`, rounded up.\n /// Returns 0 if `x` is zero.\n function log10Up(uint256 x) internal pure returns (uint256 r) {\n r = log10(x);\n /// @solidity memory-safe-assembly\n assembly {\n r := add(r, lt(exp(10, r), x))\n }\n }\n\n /// @dev Returns the log256 of `x`.\n /// Returns 0 if `x` is zero.\n function log256(uint256 x) internal pure returns (uint256 r) {\n /// @solidity memory-safe-assembly\n assembly {\n r := shl(7, lt(0xffffffffffffffffffffffffffffffff, x))\n r := or(r, shl(6, lt(0xffffffffffffffff, shr(r, x))))\n r := or(r, shl(5, lt(0xffffffff, shr(r, x))))\n r := or(r, shl(4, lt(0xffff, shr(r, x))))\n r := or(shr(3, r), lt(0xff, shr(r, x)))\n }\n }\n\n /// @dev Returns the log256 of `x`, rounded up.\n /// Returns 0 if `x` is zero.\n function log256Up(uint256 x) internal pure returns (uint256 r) {\n r = log256(x);\n /// @solidity memory-safe-assembly\n assembly {\n r := add(r, lt(shl(shl(3, r), 1), x))\n }\n }\n\n /// @dev Returns the scientific notation format `mantissa * 10 ** exponent` of `x`.\n /// Useful for compressing prices (e.g. using 25 bit mantissa and 7 bit exponent).\n function sci(uint256 x) internal pure returns (uint256 mantissa, uint256 exponent) {\n /// @solidity memory-safe-assembly\n assembly {\n mantissa := x\n if mantissa {\n if iszero(mod(mantissa, 1000000000000000000000000000000000)) {\n mantissa := div(mantissa, 1000000000000000000000000000000000)\n exponent := 33\n }\n if iszero(mod(mantissa, 10000000000000000000)) {\n mantissa := div(mantissa, 10000000000000000000)\n exponent := add(exponent, 19)\n }\n if iszero(mod(mantissa, 1000000000000)) {\n mantissa := div(mantissa, 1000000000000)\n exponent := add(exponent, 12)\n }\n if iszero(mod(mantissa, 1000000)) {\n mantissa := div(mantissa, 1000000)\n exponent := add(exponent, 6)\n }\n if iszero(mod(mantissa, 10000)) {\n mantissa := div(mantissa, 10000)\n exponent := add(exponent, 4)\n }\n if iszero(mod(mantissa, 100)) {\n mantissa := div(mantissa, 100)\n exponent := add(exponent, 2)\n }\n if iszero(mod(mantissa, 10)) {\n mantissa := div(mantissa, 10)\n exponent := add(exponent, 1)\n }\n }\n }\n }\n\n /// @dev Convenience function for packing `x` into a smaller number using `sci`.\n /// The `mantissa` will be in bits [7..255] (the upper 249 bits).\n /// The `exponent` will be in bits [0..6] (the lower 7 bits).\n /// Use `SafeCastLib` to safely ensure that the `packed` number is small\n /// enough to fit in the desired unsigned integer type:\n /// ```\n /// uint32 packed = SafeCastLib.toUint32(FixedPointMathLib.packSci(777 ether));\n /// ```\n function packSci(uint256 x) internal pure returns (uint256 packed) {\n (x, packed) = sci(x); // Reuse for `mantissa` and `exponent`.\n /// @solidity memory-safe-assembly\n assembly {\n if shr(249, x) {\n mstore(0x00, 0xce30380c) // `MantissaOverflow()`.\n revert(0x1c, 0x04)\n }\n packed := or(shl(7, x), packed)\n }\n }\n\n /// @dev Convenience function for unpacking a packed number from `packSci`.\n function unpackSci(uint256 packed) internal pure returns (uint256 unpacked) {\n unchecked {\n unpacked = (packed >> 7) * 10 ** (packed & 0x7f);\n }\n }\n\n /// @dev Returns the average of `x` and `y`.\n function avg(uint256 x, uint256 y) internal pure returns (uint256 z) {\n unchecked {\n z = (x & y) + ((x ^ y) >> 1);\n }\n }\n\n /// @dev Returns the average of `x` and `y`.\n function avg(int256 x, int256 y) internal pure returns (int256 z) {\n unchecked {\n z = (x >> 1) + (y >> 1) + (x & y & 1);\n }\n }\n\n /// @dev Returns the absolute value of `x`.\n function abs(int256 x) internal pure returns (uint256 z) {\n /// @solidity memory-safe-assembly\n assembly {\n z := xor(sar(255, x), add(sar(255, x), x))\n }\n }\n\n /// @dev Returns the absolute distance between `x` and `y`.\n function dist(uint256 x, uint256 y) internal pure returns (uint256 z) {\n /// @solidity memory-safe-assembly\n assembly {\n z := xor(mul(xor(sub(y, x), sub(x, y)), gt(x, y)), sub(y, x))\n }\n }\n\n /// @dev Returns the absolute distance between `x` and `y`.\n function dist(int256 x, int256 y) internal pure returns (uint256 z) {\n /// @solidity memory-safe-assembly\n assembly {\n z := xor(mul(xor(sub(y, x), sub(x, y)), sgt(x, y)), sub(y, x))\n }\n }\n\n /// @dev Returns the minimum of `x` and `y`.\n function min(uint256 x, uint256 y) internal pure returns (uint256 z) {\n /// @solidity memory-safe-assembly\n assembly {\n z := xor(x, mul(xor(x, y), lt(y, x)))\n }\n }\n\n /// @dev Returns the minimum of `x` and `y`.\n function min(int256 x, int256 y) internal pure returns (int256 z) {\n /// @solidity memory-safe-assembly\n assembly {\n z := xor(x, mul(xor(x, y), slt(y, x)))\n }\n }\n\n /// @dev Returns the maximum of `x` and `y`.\n function max(uint256 x, uint256 y) internal pure returns (uint256 z) {\n /// @solidity memory-safe-assembly\n assembly {\n z := xor(x, mul(xor(x, y), gt(y, x)))\n }\n }\n\n /// @dev Returns the maximum of `x` and `y`.\n function max(int256 x, int256 y) internal pure returns (int256 z) {\n /// @solidity memory-safe-assembly\n assembly {\n z := xor(x, mul(xor(x, y), sgt(y, x)))\n }\n }\n\n /// @dev Returns `x`, bounded to `minValue` and `maxValue`.\n function clamp(uint256 x, uint256 minValue, uint256 maxValue)\n internal\n pure\n returns (uint256 z)\n {\n /// @solidity memory-safe-assembly\n assembly {\n z := xor(x, mul(xor(x, minValue), gt(minValue, x)))\n z := xor(z, mul(xor(z, maxValue), lt(maxValue, z)))\n }\n }\n\n /// @dev Returns `x`, bounded to `minValue` and `maxValue`.\n function clamp(int256 x, int256 minValue, int256 maxValue) internal pure returns (int256 z) {\n /// @solidity memory-safe-assembly\n assembly {\n z := xor(x, mul(xor(x, minValue), sgt(minValue, x)))\n z := xor(z, mul(xor(z, maxValue), slt(maxValue, z)))\n }\n }\n\n /// @dev Returns greatest common divisor of `x` and `y`.\n function gcd(uint256 x, uint256 y) internal pure returns (uint256 z) {\n /// @solidity memory-safe-assembly\n assembly {\n for { z := x } y {} {\n let t := y\n y := mod(z, y)\n z := t\n }\n }\n }\n\n /// @dev Returns `a + (b - a) * (t - begin) / (end - begin)`,\n /// with `t` clamped between `begin` and `end` (inclusive).\n /// Agnostic to the order of (`a`, `b`) and (`end`, `begin`).\n /// Reverts if `begin` equals `end` (due to division by zero).\n function lerp(uint256 a, uint256 b, uint256 t, uint256 begin, uint256 end)\n internal\n pure\n returns (uint256)\n {\n if (begin >= end) {\n t = ~t;\n begin = ~begin;\n end = ~end;\n }\n if (t <= begin) return a;\n if (t >= end) return b;\n unchecked {\n if (b >= a) return a + fullMulDiv(b - a, t - begin, end - begin);\n return a - fullMulDiv(a - b, t - begin, end - begin);\n }\n }\n\n /// @dev Returns `a + (b - a) * (t - begin) / (end - begin)`.\n /// with `t` clamped between `begin` and `end` (inclusive).\n /// Agnostic to the order of (`a`, `b`) and (`end`, `begin`).\n /// Reverts if `begin` equals `end` (due to division by zero).\n function lerp(int256 a, int256 b, int256 t, int256 begin, int256 end)\n internal\n pure\n returns (int256)\n {\n if (begin >= end) {\n t = int256(~uint256(t));\n begin = int256(~uint256(begin));\n end = int256(~uint256(end));\n }\n if (t <= begin) return a;\n if (t >= end) return b;\n // forgefmt: disable-next-item\n unchecked {\n if (b >= a) return int256(uint256(a) + fullMulDiv(uint256(b) - uint256(a),\n uint256(t) - uint256(begin), uint256(end) - uint256(begin)));\n return int256(uint256(a) - fullMulDiv(uint256(a) - uint256(b),\n uint256(t) - uint256(begin), uint256(end) - uint256(begin)));\n }\n }\n\n /*´:°•.°+.*•´.*:˚.°*.˚•´.°:°•.°•.*•´.*:˚.°*.˚•´.°:°•.°+.*•´.*:*/\n /* RAW NUMBER OPERATIONS */\n /*.•°:°.´+˚.*°.˚:*.´•*.+°.•°:´*.´•*.•°.•°:°.´:•˚°.*°.˚:*.´+°.•*/\n\n /// @dev Returns `x + y`, without checking for overflow.\n function rawAdd(uint256 x, uint256 y) internal pure returns (uint256 z) {\n unchecked {\n z = x + y;\n }\n }\n\n /// @dev Returns `x + y`, without checking for overflow.\n function rawAdd(int256 x, int256 y) internal pure returns (int256 z) {\n unchecked {\n z = x + y;\n }\n }\n\n /// @dev Returns `x - y`, without checking for underflow.\n function rawSub(uint256 x, uint256 y) internal pure returns (uint256 z) {\n unchecked {\n z = x - y;\n }\n }\n\n /// @dev Returns `x - y`, without checking for underflow.\n function rawSub(int256 x, int256 y) internal pure returns (int256 z) {\n unchecked {\n z = x - y;\n }\n }\n\n /// @dev Returns `x * y`, without checking for overflow.\n function rawMul(uint256 x, uint256 y) internal pure returns (uint256 z) {\n unchecked {\n z = x * y;\n }\n }\n\n /// @dev Returns `x * y`, without checking for overflow.\n function rawMul(int256 x, int256 y) internal pure returns (int256 z) {\n unchecked {\n z = x * y;\n }\n }\n\n /// @dev Returns `x / y`, returning 0 if `y` is zero.\n function rawDiv(uint256 x, uint256 y) internal pure returns (uint256 z) {\n /// @solidity memory-safe-assembly\n assembly {\n z := div(x, y)\n }\n }\n\n /// @dev Returns `x / y`, returning 0 if `y` is zero.\n function rawSDiv(int256 x, int256 y) internal pure returns (int256 z) {\n /// @solidity memory-safe-assembly\n assembly {\n z := sdiv(x, y)\n }\n }\n\n /// @dev Returns `x % y`, returning 0 if `y` is zero.\n function rawMod(uint256 x, uint256 y) internal pure returns (uint256 z) {\n /// @solidity memory-safe-assembly\n assembly {\n z := mod(x, y)\n }\n }\n\n /// @dev Returns `x % y`, returning 0 if `y` is zero.\n function rawSMod(int256 x, int256 y) internal pure returns (int256 z) {\n /// @solidity memory-safe-assembly\n assembly {\n z := smod(x, y)\n }\n }\n\n /// @dev Returns `(x + y) % d`, return 0 if `d` if zero.\n function rawAddMod(uint256 x, uint256 y, uint256 d) internal pure returns (uint256 z) {\n /// @solidity memory-safe-assembly\n assembly {\n z := addmod(x, y, d)\n }\n }\n\n /// @dev Returns `(x * y) % d`, return 0 if `d` if zero.\n function rawMulMod(uint256 x, uint256 y, uint256 d) internal pure returns (uint256 z) {\n /// @solidity memory-safe-assembly\n assembly {\n z := mulmod(x, y, d)\n }\n }\n}\n"
},
"lib/solady/src/utils/SafeTransferLib.sol": {
"content": "// SPDX-License-Identifier: MIT\npragma solidity ^0.8.4;\n\n/// @notice Safe ETH and ERC20 transfer library that gracefully handles missing return values.\n/// @author Solady (https://github.com/vectorized/solady/blob/main/src/utils/SafeTransferLib.sol)\n/// @author Modified from Solmate (https://github.com/transmissions11/solmate/blob/main/src/utils/SafeTransferLib.sol)\n/// @author Permit2 operations from (https://github.com/Uniswap/permit2/blob/main/src/libraries/Permit2Lib.sol)\n///\n/// @dev Note:\n/// - For ETH transfers, please use `forceSafeTransferETH` for DoS protection.\n/// - For ERC20s, this implementation won't check that a token has code,\n/// responsibility is delegated to the caller.\nlibrary SafeTransferLib {\n /*´:°•.°+.*•´.*:˚.°*.˚•´.°:°•.°•.*•´.*:˚.°*.˚•´.°:°•.°+.*•´.*:*/\n /* CUSTOM ERRORS */\n /*.•°:°.´+˚.*°.˚:*.´•*.+°.•°:´*.´•*.•°.•°:°.´:•˚°.*°.˚:*.´+°.•*/\n\n /// @dev The ETH transfer has failed.\n error ETHTransferFailed();\n\n /// @dev The ERC20 `transferFrom` has failed.\n error TransferFromFailed();\n\n /// @dev The ERC20 `transfer` has failed.\n error TransferFailed();\n\n /// @dev The ERC20 `approve` has failed.\n error ApproveFailed();\n\n /// @dev The Permit2 operation has failed.\n error Permit2Failed();\n\n /// @dev The Permit2 amount must be less than `2**160 - 1`.\n error Permit2AmountOverflow();\n\n /*´:°•.°+.*•´.*:˚.°*.˚•´.°:°•.°•.*•´.*:˚.°*.˚•´.°:°•.°+.*•´.*:*/\n /* CONSTANTS */\n /*.•°:°.´+˚.*°.˚:*.´•*.+°.•°:´*.´•*.•°.•°:°.´:•˚°.*°.˚:*.´+°.•*/\n\n /// @dev Suggested gas stipend for contract receiving ETH that disallows any storage writes.\n uint256 internal constant GAS_STIPEND_NO_STORAGE_WRITES = 2300;\n\n /// @dev Suggested gas stipend for contract receiving ETH to perform a few\n /// storage reads and writes, but low enough to prevent griefing.\n uint256 internal constant GAS_STIPEND_NO_GRIEF = 100000;\n\n /// @dev The unique EIP-712 domain domain separator for the DAI token contract.\n bytes32 internal constant DAI_DOMAIN_SEPARATOR =\n 0xdbb8cf42e1ecb028be3f3dbc922e1d878b963f411dc388ced501601c60f7c6f7;\n\n /// @dev The address for the WETH9 contract on Ethereum mainnet.\n address internal constant WETH9 = 0xC02aaA39b223FE8D0A0e5C4F27eAD9083C756Cc2;\n\n /// @dev The canonical Permit2 address.\n /// [Github](https://github.com/Uniswap/permit2)\n /// [Etherscan](https://etherscan.io/address/0x000000000022D473030F116dDEE9F6B43aC78BA3)\n address internal constant PERMIT2 = 0x000000000022D473030F116dDEE9F6B43aC78BA3;\n\n /*´:°•.°+.*•´.*:˚.°*.˚•´.°:°•.°•.*•´.*:˚.°*.˚•´.°:°•.°+.*•´.*:*/\n /* ETH OPERATIONS */\n /*.•°:°.´+˚.*°.˚:*.´•*.+°.•°:´*.´•*.•°.•°:°.´:•˚°.*°.˚:*.´+°.•*/\n\n // If the ETH transfer MUST succeed with a reasonable gas budget, use the force variants.\n //\n // The regular variants:\n // - Forwards all remaining gas to the target.\n // - Reverts if the target reverts.\n // - Reverts if the current contract has insufficient balance.\n //\n // The force variants:\n // - Forwards with an optional gas stipend\n // (defaults to `GAS_STIPEND_NO_GRIEF`, which is sufficient for most cases).\n // - If the target reverts, or if the gas stipend is exhausted,\n // creates a temporary contract to force send the ETH via `SELFDESTRUCT`.\n // Future compatible with `SENDALL`: https://eips.ethereum.org/EIPS/eip-4758.\n // - Reverts if the current contract has insufficient balance.\n //\n // The try variants:\n // - Forwards with a mandatory gas stipend.\n // - Instead of reverting, returns whether the transfer succeeded.\n\n /// @dev Sends `amount` (in wei) ETH to `to`.\n function safeTransferETH(address to, uint256 amount) internal {\n /// @solidity memory-safe-assembly\n assembly {\n if iszero(call(gas(), to, amount, codesize(), 0x00, codesize(), 0x00)) {\n mstore(0x00, 0xb12d13eb) // `ETHTransferFailed()`.\n revert(0x1c, 0x04)\n }\n }\n }\n\n /// @dev Sends all the ETH in the current contract to `to`.\n function safeTransferAllETH(address to) internal {\n /// @solidity memory-safe-assembly\n assembly {\n // Transfer all the ETH and check if it succeeded or not.\n if iszero(call(gas(), to, selfbalance(), codesize(), 0x00, codesize(), 0x00)) {\n mstore(0x00, 0xb12d13eb) // `ETHTransferFailed()`.\n revert(0x1c, 0x04)\n }\n }\n }\n\n /// @dev Force sends `amount` (in wei) ETH to `to`, with a `gasStipend`.\n function forceSafeTransferETH(address to, uint256 amount, uint256 gasStipend) internal {\n /// @solidity memory-safe-assembly\n assembly {\n if lt(selfbalance(), amount) {\n mstore(0x00, 0xb12d13eb) // `ETHTransferFailed()`.\n revert(0x1c, 0x04)\n }\n if iszero(call(gasStipend, to, amount, codesize(), 0x00, codesize(), 0x00)) {\n mstore(0x00, to) // Store the address in scratch space.\n mstore8(0x0b, 0x73) // Opcode `PUSH20`.\n mstore8(0x20, 0xff) // Opcode `SELFDESTRUCT`.\n if iszero(create(amount, 0x0b, 0x16)) { revert(codesize(), codesize()) } // For gas estimation.\n }\n }\n }\n\n /// @dev Force sends all the ETH in the current contract to `to`, with a `gasStipend`.\n function forceSafeTransferAllETH(address to, uint256 gasStipend) internal {\n /// @solidity memory-safe-assembly\n assembly {\n if iszero(call(gasStipend, to, selfbalance(), codesize(), 0x00, codesize(), 0x00)) {\n mstore(0x00, to) // Store the address in scratch space.\n mstore8(0x0b, 0x73) // Opcode `PUSH20`.\n mstore8(0x20, 0xff) // Opcode `SELFDESTRUCT`.\n if iszero(create(selfbalance(), 0x0b, 0x16)) { revert(codesize(), codesize()) } // For gas estimation.\n }\n }\n }\n\n /// @dev Force sends `amount` (in wei) ETH to `to`, with `GAS_STIPEND_NO_GRIEF`.\n function forceSafeTransferETH(address to, uint256 amount) internal {\n /// @solidity memory-safe-assembly\n assembly {\n if lt(selfbalance(), amount) {\n mstore(0x00, 0xb12d13eb) // `ETHTransferFailed()`.\n revert(0x1c, 0x04)\n }\n if iszero(call(GAS_STIPEND_NO_GRIEF, to, amount, codesize(), 0x00, codesize(), 0x00)) {\n mstore(0x00, to) // Store the address in scratch space.\n mstore8(0x0b, 0x73) // Opcode `PUSH20`.\n mstore8(0x20, 0xff) // Opcode `SELFDESTRUCT`.\n if iszero(create(amount, 0x0b, 0x16)) { revert(codesize(), codesize()) } // For gas estimation.\n }\n }\n }\n\n /// @dev Force sends all the ETH in the current contract to `to`, with `GAS_STIPEND_NO_GRIEF`.\n function forceSafeTransferAllETH(address to) internal {\n /// @solidity memory-safe-assembly\n assembly {\n // forgefmt: disable-next-item\n if iszero(call(GAS_STIPEND_NO_GRIEF, to, selfbalance(), codesize(), 0x00, codesize(), 0x00)) {\n mstore(0x00, to) // Store the address in scratch space.\n mstore8(0x0b, 0x73) // Opcode `PUSH20`.\n mstore8(0x20, 0xff) // Opcode `SELFDESTRUCT`.\n if iszero(create(selfbalance(), 0x0b, 0x16)) { revert(codesize(), codesize()) } // For gas estimation.\n }\n }\n }\n\n /// @dev Sends `amount` (in wei) ETH to `to`, with a `gasStipend`.\n function trySafeTransferETH(address to, uint256 amount, uint256 gasStipend)\n internal\n returns (bool success)\n {\n /// @solidity memory-safe-assembly\n assembly {\n success := call(gasStipend, to, amount, codesize(), 0x00, codesize(), 0x00)\n }\n }\n\n /// @dev Sends all the ETH in the current contract to `to`, with a `gasStipend`.\n function trySafeTransferAllETH(address to, uint256 gasStipend)\n internal\n returns (bool success)\n {\n /// @solidity memory-safe-assembly\n assembly {\n success := call(gasStipend, to, selfbalance(), codesize(), 0x00, codesize(), 0x00)\n }\n }\n\n /*´:°•.°+.*•´.*:˚.°*.˚•´.°:°•.°•.*•´.*:˚.°*.˚•´.°:°•.°+.*•´.*:*/\n /* ERC20 OPERATIONS */\n /*.•°:°.´+˚.*°.˚:*.´•*.+°.•°:´*.´•*.•°.•°:°.´:•˚°.*°.˚:*.´+°.•*/\n\n /// @dev Sends `amount` of ERC20 `token` from `from` to `to`.\n /// Reverts upon failure.\n ///\n /// The `from` account must have at least `amount` approved for\n /// the current contract to manage.\n function safeTransferFrom(address token, address from, address to, uint256 amount) internal {\n /// @solidity memory-safe-assembly\n assembly {\n let m := mload(0x40) // Cache the free memory pointer.\n mstore(0x60, amount) // Store the `amount` argument.\n mstore(0x40, to) // Store the `to` argument.\n mstore(0x2c, shl(96, from)) // Store the `from` argument.\n mstore(0x0c, 0x23b872dd000000000000000000000000) // `transferFrom(address,address,uint256)`.\n // Perform the transfer, reverting upon failure.\n if iszero(\n and( // The arguments of `and` are evaluated from right to left.\n or(eq(mload(0x00), 1), iszero(returndatasize())), // Returned 1 or nothing.\n call(gas(), token, 0, 0x1c, 0x64, 0x00, 0x20)\n )\n ) {\n mstore(0x00, 0x7939f424) // `TransferFromFailed()`.\n revert(0x1c, 0x04)\n }\n mstore(0x60, 0) // Restore the zero slot to zero.\n mstore(0x40, m) // Restore the free memory pointer.\n }\n }\n\n /// @dev Sends `amount` of ERC20 `token` from `from` to `to`.\n ///\n /// The `from` account must have at least `amount` approved for the current contract to manage.\n function trySafeTransferFrom(address token, address from, address to, uint256 amount)\n internal\n returns (bool success)\n {\n /// @solidity memory-safe-assembly\n assembly {\n let m := mload(0x40) // Cache the free memory pointer.\n mstore(0x60, amount) // Store the `amount` argument.\n mstore(0x40, to) // Store the `to` argument.\n mstore(0x2c, shl(96, from)) // Store the `from` argument.\n mstore(0x0c, 0x23b872dd000000000000000000000000) // `transferFrom(address,address,uint256)`.\n success :=\n and( // The arguments of `and` are evaluated from right to left.\n or(eq(mload(0x00), 1), iszero(returndatasize())), // Returned 1 or nothing.\n call(gas(), token, 0, 0x1c, 0x64, 0x00, 0x20)\n )\n mstore(0x60, 0) // Restore the zero slot to zero.\n mstore(0x40, m) // Restore the free memory pointer.\n }\n }\n\n /// @dev Sends all of ERC20 `token` from `from` to `to`.\n /// Reverts upon failure.\n ///\n /// The `from` account must have their entire balance approved for the current contract to manage.\n function safeTransferAllFrom(address token, address from, address to)\n internal\n returns (uint256 amount)\n {\n /// @solidity memory-safe-assembly\n assembly {\n let m := mload(0x40) // Cache the free memory pointer.\n mstore(0x40, to) // Store the `to` argument.\n mstore(0x2c, shl(96, from)) // Store the `from` argument.\n mstore(0x0c, 0x70a08231000000000000000000000000) // `balanceOf(address)`.\n // Read the balance, reverting upon failure.\n if iszero(\n and( // The arguments of `and` are evaluated from right to left.\n gt(returndatasize(), 0x1f), // At least 32 bytes returned.\n staticcall(gas(), token, 0x1c, 0x24, 0x60, 0x20)\n )\n ) {\n mstore(0x00, 0x7939f424) // `TransferFromFailed()`.\n revert(0x1c, 0x04)\n }\n mstore(0x00, 0x23b872dd) // `transferFrom(address,address,uint256)`.\n amount := mload(0x60) // The `amount` is already at 0x60. We'll need to return it.\n // Perform the transfer, reverting upon failure.\n if iszero(\n and( // The arguments of `and` are evaluated from right to left.\n or(eq(mload(0x00), 1), iszero(returndatasize())), // Returned 1 or nothing.\n call(gas(), token, 0, 0x1c, 0x64, 0x00, 0x20)\n )\n ) {\n mstore(0x00, 0x7939f424) // `TransferFromFailed()`.\n revert(0x1c, 0x04)\n }\n mstore(0x60, 0) // Restore the zero slot to zero.\n mstore(0x40, m) // Restore the free memory pointer.\n }\n }\n\n /// @dev Sends `amount` of ERC20 `token` from the current contract to `to`.\n /// Reverts upon failure.\n function safeTransfer(address token, address to, uint256 amount) internal {\n /// @solidity memory-safe-assembly\n assembly {\n mstore(0x14, to) // Store the `to` argument.\n mstore(0x34, amount) // Store the `amount` argument.\n mstore(0x00, 0xa9059cbb000000000000000000000000) // `transfer(address,uint256)`.\n // Perform the transfer, reverting upon failure.\n if iszero(\n and( // The arguments of `and` are evaluated from right to left.\n or(eq(mload(0x00), 1), iszero(returndatasize())), // Returned 1 or nothing.\n call(gas(), token, 0, 0x10, 0x44, 0x00, 0x20)\n )\n ) {\n mstore(0x00, 0x90b8ec18) // `TransferFailed()`.\n revert(0x1c, 0x04)\n }\n mstore(0x34, 0) // Restore the part of the free memory pointer that was overwritten.\n }\n }\n\n /// @dev Sends all of ERC20 `token` from the current contract to `to`.\n /// Reverts upon failure.\n function safeTransferAll(address token, address to) internal returns (uint256 amount) {\n /// @solidity memory-safe-assembly\n assembly {\n mstore(0x00, 0x70a08231) // Store the function selector of `balanceOf(address)`.\n mstore(0x20, address()) // Store the address of the current contract.\n // Read the balance, reverting upon failure.\n if iszero(\n and( // The arguments of `and` are evaluated from right to left.\n gt(returndatasize(), 0x1f), // At least 32 bytes returned.\n staticcall(gas(), token, 0x1c, 0x24, 0x34, 0x20)\n )\n ) {\n mstore(0x00, 0x90b8ec18) // `TransferFailed()`.\n revert(0x1c, 0x04)\n }\n mstore(0x14, to) // Store the `to` argument.\n amount := mload(0x34) // The `amount` is already at 0x34. We'll need to return it.\n mstore(0x00, 0xa9059cbb000000000000000000000000) // `transfer(address,uint256)`.\n // Perform the transfer, reverting upon failure.\n if iszero(\n and( // The arguments of `and` are evaluated from right to left.\n or(eq(mload(0x00), 1), iszero(returndatasize())), // Returned 1 or nothing.\n call(gas(), token, 0, 0x10, 0x44, 0x00, 0x20)\n )\n ) {\n mstore(0x00, 0x90b8ec18) // `TransferFailed()`.\n revert(0x1c, 0x04)\n }\n mstore(0x34, 0) // Restore the part of the free memory pointer that was overwritten.\n }\n }\n\n /// @dev Sets `amount` of ERC20 `token` for `to` to manage on behalf of the current contract.\n /// Reverts upon failure.\n function safeApprove(address token, address to, uint256 amount) internal {\n /// @solidity memory-safe-assembly\n assembly {\n mstore(0x14, to) // Store the `to` argument.\n mstore(0x34, amount) // Store the `amount` argument.\n mstore(0x00, 0x095ea7b3000000000000000000000000) // `approve(address,uint256)`.\n // Perform the approval, reverting upon failure.\n if iszero(\n and( // The arguments of `and` are evaluated from right to left.\n or(eq(mload(0x00), 1), iszero(returndatasize())), // Returned 1 or nothing.\n call(gas(), token, 0, 0x10, 0x44, 0x00, 0x20)\n )\n ) {\n mstore(0x00, 0x3e3f8f73) // `ApproveFailed()`.\n revert(0x1c, 0x04)\n }\n mstore(0x34, 0) // Restore the part of the free memory pointer that was overwritten.\n }\n }\n\n /// @dev Sets `amount` of ERC20 `token` for `to` to manage on behalf of the current contract.\n /// If the initial attempt to approve fails, attempts to reset the approved amount to zero,\n /// then retries the approval again (some tokens, e.g. USDT, requires this).\n /// Reverts upon failure.\n function safeApproveWithRetry(address token, address to, uint256 amount) internal {\n /// @solidity memory-safe-assembly\n assembly {\n mstore(0x14, to) // Store the `to` argument.\n mstore(0x34, amount) // Store the `amount` argument.\n mstore(0x00, 0x095ea7b3000000000000000000000000) // `approve(address,uint256)`.\n // Perform the approval, retrying upon failure.\n if iszero(\n and( // The arguments of `and` are evaluated from right to left.\n or(eq(mload(0x00), 1), iszero(returndatasize())), // Returned 1 or nothing.\n call(gas(), token, 0, 0x10, 0x44, 0x00, 0x20)\n )\n ) {\n mstore(0x34, 0) // Store 0 for the `amount`.\n mstore(0x00, 0x095ea7b3000000000000000000000000) // `approve(address,uint256)`.\n pop(call(gas(), token, 0, 0x10, 0x44, codesize(), 0x00)) // Reset the approval.\n mstore(0x34, amount) // Store back the original `amount`.\n // Retry the approval, reverting upon failure.\n if iszero(\n and(\n or(eq(mload(0x00), 1), iszero(returndatasize())), // Returned 1 or nothing.\n call(gas(), token, 0, 0x10, 0x44, 0x00, 0x20)\n )\n ) {\n mstore(0x00, 0x3e3f8f73) // `ApproveFailed()`.\n revert(0x1c, 0x04)\n }\n }\n mstore(0x34, 0) // Restore the part of the free memory pointer that was overwritten.\n }\n }\n\n /// @dev Returns the amount of ERC20 `token` owned by `account`.\n /// Returns zero if the `token` does not exist.\n function balanceOf(address token, address account) internal view returns (uint256 amount) {\n /// @solidity memory-safe-assembly\n assembly {\n mstore(0x14, account) // Store the `account` argument.\n mstore(0x00, 0x70a08231000000000000000000000000) // `balanceOf(address)`.\n amount :=\n mul( // The arguments of `mul` are evaluated from right to left.\n mload(0x20),\n and( // The arguments of `and` are evaluated from right to left.\n gt(returndatasize(), 0x1f), // At least 32 bytes returned.\n staticcall(gas(), token, 0x10, 0x24, 0x20, 0x20)\n )\n )\n }\n }\n\n /// @dev Sends `amount` of ERC20 `token` from `from` to `to`.\n /// If the initial attempt fails, try to use Permit2 to transfer the token.\n /// Reverts upon failure.\n ///\n /// The `from` account must have at least `amount` approved for the current contract to manage.\n function safeTransferFrom2(address token, address from, address to, uint256 amount) internal {\n if (!trySafeTransferFrom(token, from, to, amount)) {\n permit2TransferFrom(token, from, to, amount);\n }\n }\n\n /// @dev Sends `amount` of ERC20 `token` from `from` to `to` via Permit2.\n /// Reverts upon failure.\n function permit2TransferFrom(address token, address from, address to, uint256 amount)\n internal\n {\n /// @solidity memory-safe-assembly\n assembly {\n let m := mload(0x40)\n mstore(add(m, 0x74), shr(96, shl(96, token)))\n mstore(add(m, 0x54), amount)\n mstore(add(m, 0x34), to)\n mstore(add(m, 0x20), shl(96, from))\n // `transferFrom(address,address,uint160,address)`.\n mstore(m, 0x36c78516000000000000000000000000)\n let p := PERMIT2\n let exists := eq(chainid(), 1)\n if iszero(exists) { exists := iszero(iszero(extcodesize(p))) }\n if iszero(and(call(gas(), p, 0, add(m, 0x10), 0x84, codesize(), 0x00), exists)) {\n mstore(0x00, 0x7939f4248757f0fd) // `TransferFromFailed()` or `Permit2AmountOverflow()`.\n revert(add(0x18, shl(2, iszero(iszero(shr(160, amount))))), 0x04)\n }\n }\n }\n\n /// @dev Permit a user to spend a given amount of\n /// another user's tokens via native EIP-2612 permit if possible, falling\n /// back to Permit2 if native permit fails or is not implemented on the token.\n function permit2(\n address token,\n address owner,\n address spender,\n uint256 amount,\n uint256 deadline,\n uint8 v,\n bytes32 r,\n bytes32 s\n ) internal {\n bool success;\n /// @solidity memory-safe-assembly\n assembly {\n for {} shl(96, xor(token, WETH9)) {} {\n mstore(0x00, 0x3644e515) // `DOMAIN_SEPARATOR()`.\n if iszero(\n and( // The arguments of `and` are evaluated from right to left.\n lt(iszero(mload(0x00)), eq(returndatasize(), 0x20)), // Returns 1 non-zero word.\n // Gas stipend to limit gas burn for tokens that don't refund gas when\n // an non-existing function is called. 5K should be enough for a SLOAD.\n staticcall(5000, token, 0x1c, 0x04, 0x00, 0x20)\n )\n ) { break }\n // After here, we can be sure that token is a contract.\n let m := mload(0x40)\n mstore(add(m, 0x34), spender)\n mstore(add(m, 0x20), shl(96, owner))\n mstore(add(m, 0x74), deadline)\n if eq(mload(0x00), DAI_DOMAIN_SEPARATOR) {\n mstore(0x14, owner)\n mstore(0x00, 0x7ecebe00000000000000000000000000) // `nonces(address)`.\n mstore(add(m, 0x94), staticcall(gas(), token, 0x10, 0x24, add(m, 0x54), 0x20))\n mstore(m, 0x8fcbaf0c000000000000000000000000) // `IDAIPermit.permit`.\n // `nonces` is already at `add(m, 0x54)`.\n // `1` is already stored at `add(m, 0x94)`.\n mstore(add(m, 0xb4), and(0xff, v))\n mstore(add(m, 0xd4), r)\n mstore(add(m, 0xf4), s)\n success := call(gas(), token, 0, add(m, 0x10), 0x104, codesize(), 0x00)\n break\n }\n mstore(m, 0xd505accf000000000000000000000000) // `IERC20Permit.permit`.\n mstore(add(m, 0x54), amount)\n mstore(add(m, 0x94), and(0xff, v))\n mstore(add(m, 0xb4), r)\n mstore(add(m, 0xd4), s)\n success := call(gas(), token, 0, add(m, 0x10), 0xe4, codesize(), 0x00)\n break\n }\n }\n if (!success) simplePermit2(token, owner, spender, amount, deadline, v, r, s);\n }\n\n /// @dev Simple permit on the Permit2 contract.\n function simplePermit2(\n address token,\n address owner,\n address spender,\n uint256 amount,\n uint256 deadline,\n uint8 v,\n bytes32 r,\n bytes32 s\n ) internal {\n /// @solidity memory-safe-assembly\n assembly {\n let m := mload(0x40)\n mstore(m, 0x927da105) // `allowance(address,address,address)`.\n {\n let addressMask := shr(96, not(0))\n mstore(add(m, 0x20), and(addressMask, owner))\n mstore(add(m, 0x40), and(addressMask, token))\n mstore(add(m, 0x60), and(addressMask, spender))\n mstore(add(m, 0xc0), and(addressMask, spender))\n }\n let p := mul(PERMIT2, iszero(shr(160, amount)))\n if iszero(\n and( // The arguments of `and` are evaluated from right to left.\n gt(returndatasize(), 0x5f), // Returns 3 words: `amount`, `expiration`, `nonce`.\n staticcall(gas(), p, add(m, 0x1c), 0x64, add(m, 0x60), 0x60)\n )\n ) {\n mstore(0x00, 0x6b836e6b8757f0fd) // `Permit2Failed()` or `Permit2AmountOverflow()`.\n revert(add(0x18, shl(2, iszero(p))), 0x04)\n }\n mstore(m, 0x2b67b570) // `Permit2.permit` (PermitSingle variant).\n // `owner` is already `add(m, 0x20)`.\n // `token` is already at `add(m, 0x40)`.\n mstore(add(m, 0x60), amount)\n mstore(add(m, 0x80), 0xffffffffffff) // `expiration = type(uint48).max`.\n // `nonce` is already at `add(m, 0xa0)`.\n // `spender` is already at `add(m, 0xc0)`.\n mstore(add(m, 0xe0), deadline)\n mstore(add(m, 0x100), 0x100) // `signature` offset.\n mstore(add(m, 0x120), 0x41) // `signature` length.\n mstore(add(m, 0x140), r)\n mstore(add(m, 0x160), s)\n mstore(add(m, 0x180), shl(248, v))\n if iszero(call(gas(), p, 0, add(m, 0x1c), 0x184, codesize(), 0x00)) {\n mstore(0x00, 0x6b836e6b) // `Permit2Failed()`.\n revert(0x1c, 0x04)\n }\n }\n }\n}\n"
},
"src/RateProvider/IRateProvider.sol": {
"content": "// SPDX-License-Identifier: MIT\npragma solidity ^0.8.0;\n\ninterface IRateProvider {\n function rate(address token) external view returns (uint256);\n}\n"
},
"src/BalancerLibCode/LogExpMath.sol": {
"content": "// SPDX-License-Identifier: MIT\npragma solidity ^0.8.0;\n\n/* solhint-disable */\n\n/**\n * @dev Exponentiation and logarithm functions for 18 decimal fixed point numbers (both base and exponent/argument).\n * @dev forked from https://github.com/balancer/balancer-v2-monorepo/blob/599b0cd8f744e1eabef3600d79a2c2b0aea3ddcb/pkg/solidity-utils/contracts/math/LogExpMath.sol\n *\n * Exponentiation and logarithm with arbitrary bases (x^y and log_x(y)) are implemented by conversion to natural\n * exponentiation and logarithm (where the base is Euler's number).\n *\n * @author Fernando Martinelli - @fernandomartinelli\n * @author Sergio Yuhjtman - @sergioyuhjtman\n * @author Daniel Fernandez - @dmf7z\n */\nlibrary LogExpMath {\n // All fixed point multiplications and divisions are inlined. This means we need to divide by ONE when multiplying\n // two numbers, and multiply by ONE when dividing them.\n\n // All arguments and return values are 18 decimal fixed point numbers.\n int256 constant ONE_18 = 1e18;\n\n // Internally, intermediate values are computed with higher precision as 20 decimal fixed point numbers, and in the\n // case of ln36, 36 decimals.\n int256 constant ONE_20 = 1e20;\n int256 constant ONE_36 = 1e36;\n\n // The domain of natural exponentiation is bound by the word size and number of decimals used.\n //\n // Because internally the result will be stored using 20 decimals, the largest possible result is\n // (2^255 - 1) / 10^20, which makes the largest exponent ln((2^255 - 1) / 10^20) = 130.700829182905140221.\n // The smallest possible result is 10^(-18), which makes largest negative argument\n // ln(10^(-18)) = -41.446531673892822312.\n // We use 130.0 and -41.0 to have some safety margin.\n int256 constant MAX_NATURAL_EXPONENT = 130e18;\n int256 constant MIN_NATURAL_EXPONENT = -41e18;\n\n // Bounds for ln_36's argument. Both ln(0.9) and ln(1.1) can be represented with 36 decimal places in a fixed point\n // 256 bit integer.\n int256 constant LN_36_LOWER_BOUND = ONE_18 - 1e17;\n int256 constant LN_36_UPPER_BOUND = ONE_18 + 1e17;\n\n uint256 constant MILD_EXPONENT_BOUND = 2 ** 254 / uint256(ONE_20);\n\n // 18 decimal constants\n int256 constant x0 = 128000000000000000000; // 2ˆ7\n int256 constant a0 = 38877084059945950922200000000000000000000000000000000000; // eˆ(x0) (no decimals)\n int256 constant x1 = 64000000000000000000; // 2ˆ6\n int256 constant a1 = 6235149080811616882910000000; // eˆ(x1) (no decimals)\n\n // 20 decimal constants\n int256 constant x2 = 3200000000000000000000; // 2ˆ5\n int256 constant a2 = 7896296018268069516100000000000000; // eˆ(x2)\n int256 constant x3 = 1600000000000000000000; // 2ˆ4\n int256 constant a3 = 888611052050787263676000000; // eˆ(x3)\n int256 constant x4 = 800000000000000000000; // 2ˆ3\n int256 constant a4 = 298095798704172827474000; // eˆ(x4)\n int256 constant x5 = 400000000000000000000; // 2ˆ2\n int256 constant a5 = 5459815003314423907810; // eˆ(x5)\n int256 constant x6 = 200000000000000000000; // 2ˆ1\n int256 constant a6 = 738905609893065022723; // eˆ(x6)\n int256 constant x7 = 100000000000000000000; // 2ˆ0\n int256 constant a7 = 271828182845904523536; // eˆ(x7)\n int256 constant x8 = 50000000000000000000; // 2ˆ-1\n int256 constant a8 = 164872127070012814685; // eˆ(x8)\n int256 constant x9 = 25000000000000000000; // 2ˆ-2\n int256 constant a9 = 128402541668774148407; // eˆ(x9)\n int256 constant x10 = 12500000000000000000; // 2ˆ-3\n int256 constant a10 = 113314845306682631683; // eˆ(x10)\n int256 constant x11 = 6250000000000000000; // 2ˆ-4\n int256 constant a11 = 106449445891785942956; // eˆ(x11)\n\n /**\n * @dev Exponentiation (x^y) with unsigned 18 decimal fixed point base and exponent.\n *\n * Reverts if ln(x) * y is smaller than `MIN_NATURAL_EXPONENT`, or larger than `MAX_NATURAL_EXPONENT`.\n */\n function pow(uint256 x, uint256 y) internal pure returns (uint256) {\n if (y == 0) {\n // We solve the 0^0 indetermination by making it equal one.\n return uint256(ONE_18);\n }\n\n if (x == 0) {\n return 0;\n }\n\n // Instead of computing x^y directly, we instead rely on the properties of logarithms and exponentiation to\n // arrive at that result. In particular, exp(ln(x)) = x, and ln(x^y) = y * ln(x). This means\n // x^y = exp(y * ln(x)).\n\n // The ln function takes a signed value, so we need to make sure x fits in the signed 256 bit range.\n require(x >> 255 == 0, \"X out of bounds\");\n int256 x_int256 = int256(x);\n\n // We will compute y * ln(x) in a single step. Depending on the value of x, we can either use ln or ln_36. In\n // both cases, we leave the division by ONE_18 (due to fixed point multiplication) to the end.\n\n // This prevents y * ln(x) from overflowing, and at the same time guarantees y fits in the signed 256 bit range.\n require(y < MILD_EXPONENT_BOUND, \"Y out of bounds\");\n int256 y_int256 = int256(y);\n\n int256 logx_times_y;\n if (LN_36_LOWER_BOUND < x_int256 && x_int256 < LN_36_UPPER_BOUND) {\n int256 ln_36_x = _ln_36(x_int256);\n\n // ln_36_x has 36 decimal places, so multiplying by y_int256 isn't as straightforward, since we can't just\n // bring y_int256 to 36 decimal places, as it might overflow. Instead, we perform two 18 decimal\n // multiplications and add the results: one with the first 18 decimals of ln_36_x, and one with the\n // (downscaled) last 18 decimals.\n logx_times_y = ((ln_36_x / ONE_18) * y_int256 + ((ln_36_x % ONE_18) * y_int256) / ONE_18);\n } else {\n logx_times_y = _ln(x_int256) * y_int256;\n }\n logx_times_y /= ONE_18;\n\n // Finally, we compute exp(y * ln(x)) to arrive at x^y\n require(MIN_NATURAL_EXPONENT <= logx_times_y && logx_times_y <= MAX_NATURAL_EXPONENT, \"Product out of bounds\");\n\n return uint256(exp(logx_times_y));\n }\n\n /**\n * @dev Natural exponentiation (e^x) with signed 18 decimal fixed point exponent.\n *\n * Reverts if `x` is smaller than MIN_NATURAL_EXPONENT, or larger than `MAX_NATURAL_EXPONENT`.\n */\n function exp(int256 x) internal pure returns (int256) {\n require(x >= MIN_NATURAL_EXPONENT && x <= MAX_NATURAL_EXPONENT, \"Invalid Exponent\");\n\n if (x < 0) {\n // We only handle positive exponents: e^(-x) is computed as 1 / e^x. We can safely make x positive since it\n // fits in the signed 256 bit range (as it is larger than MIN_NATURAL_EXPONENT).\n // Fixed point division requires multiplying by ONE_18.\n return ((ONE_18 * ONE_18) / exp(-x));\n }\n\n // First, we use the fact that e^(x+y) = e^x * e^y to decompose x into a sum of powers of two, which we call x_n,\n // where x_n == 2^(7 - n), and e^x_n = a_n has been precomputed. We choose the first x_n, x0, to equal 2^7\n // because all larger powers are larger than MAX_NATURAL_EXPONENT, and therefore not present in the\n // decomposition.\n // At the end of this process we will have the product of all e^x_n = a_n that apply, and the remainder of this\n // decomposition, which will be lower than the smallest x_n.\n // exp(x) = k_0 * a_0 * k_1 * a_1 * ... + k_n * a_n * exp(remainder), where each k_n equals either 0 or 1.\n // We mutate x by subtracting x_n, making it the remainder of the decomposition.\n\n // The first two a_n (e^(2^7) and e^(2^6)) are too large if stored as 18 decimal numbers, and could cause\n // intermediate overflows. Instead we store them as plain integers, with 0 decimals.\n // Additionally, x0 + x1 is larger than MAX_NATURAL_EXPONENT, which means they will not both be present in the\n // decomposition.\n\n // For each x_n, we test if that term is present in the decomposition (if x is larger than it), and if so deduct\n // it and compute the accumulated product.\n\n int256 firstAN;\n if (x >= x0) {\n x -= x0;\n firstAN = a0;\n } else if (x >= x1) {\n x -= x1;\n firstAN = a1;\n } else {\n firstAN = 1; // One with no decimal places\n }\n\n // We now transform x into a 20 decimal fixed point number, to have enhanced precision when computing the\n // smaller terms.\n x *= 100;\n\n // `product` is the accumulated product of all a_n (except a0 and a1), which starts at 20 decimal fixed point\n // one. Recall that fixed point multiplication requires dividing by ONE_20.\n int256 product = ONE_20;\n\n if (x >= x2) {\n x -= x2;\n product = (product * a2) / ONE_20;\n }\n if (x >= x3) {\n x -= x3;\n product = (product * a3) / ONE_20;\n }\n if (x >= x4) {\n x -= x4;\n product = (product * a4) / ONE_20;\n }\n if (x >= x5) {\n x -= x5;\n product = (product * a5) / ONE_20;\n }\n if (x >= x6) {\n x -= x6;\n product = (product * a6) / ONE_20;\n }\n if (x >= x7) {\n x -= x7;\n product = (product * a7) / ONE_20;\n }\n if (x >= x8) {\n x -= x8;\n product = (product * a8) / ONE_20;\n }\n if (x >= x9) {\n x -= x9;\n product = (product * a9) / ONE_20;\n }\n\n // x10 and x11 are unnecessary here since we have high enough precision already.\n\n // Now we need to compute e^x, where x is small (in particular, it is smaller than x9). We use the Taylor series\n // expansion for e^x: 1 + x + (x^2 / 2!) + (x^3 / 3!) + ... + (x^n / n!).\n\n int256 seriesSum = ONE_20; // The initial one in the sum, with 20 decimal places.\n int256 term; // Each term in the sum, where the nth term is (x^n / n!).\n\n // The first term is simply x.\n term = x;\n seriesSum += term;\n\n // Each term (x^n / n!) equals the previous one times x, divided by n. Since x is a fixed point number,\n // multiplying by it requires dividing by ONE_20, but dividing by the non-fixed point n values does not.\n\n term = ((term * x) / ONE_20) / 2;\n seriesSum += term;\n\n term = ((term * x) / ONE_20) / 3;\n seriesSum += term;\n\n term = ((term * x) / ONE_20) / 4;\n seriesSum += term;\n\n term = ((term * x) / ONE_20) / 5;\n seriesSum += term;\n\n term = ((term * x) / ONE_20) / 6;\n seriesSum += term;\n\n term = ((term * x) / ONE_20) / 7;\n seriesSum += term;\n\n term = ((term * x) / ONE_20) / 8;\n seriesSum += term;\n\n term = ((term * x) / ONE_20) / 9;\n seriesSum += term;\n\n term = ((term * x) / ONE_20) / 10;\n seriesSum += term;\n\n term = ((term * x) / ONE_20) / 11;\n seriesSum += term;\n\n term = ((term * x) / ONE_20) / 12;\n seriesSum += term;\n\n // 12 Taylor terms are sufficient for 18 decimal precision.\n\n // We now have the first a_n (with no decimals), and the product of all other a_n present, and the Taylor\n // approximation of the exponentiation of the remainder (both with 20 decimals). All that remains is to multiply\n // all three (one 20 decimal fixed point multiplication, dividing by ONE_20, and one integer multiplication),\n // and then drop two digits to return an 18 decimal value.\n\n return (((product * seriesSum) / ONE_20) * firstAN) / 100;\n }\n\n /**\n * @dev Logarithm (log(arg, base), with signed 18 decimal fixed point base and argument.\n */\n function log(int256 arg, int256 base) internal pure returns (int256) {\n // This performs a simple base change: log(arg, base) = ln(arg) / ln(base).\n\n // Both logBase and logArg are computed as 36 decimal fixed point numbers, either by using ln_36, or by\n // upscaling.\n\n int256 logBase;\n if (LN_36_LOWER_BOUND < base && base < LN_36_UPPER_BOUND) {\n logBase = _ln_36(base);\n } else {\n logBase = _ln(base) * ONE_18;\n }\n\n int256 logArg;\n if (LN_36_LOWER_BOUND < arg && arg < LN_36_UPPER_BOUND) {\n logArg = _ln_36(arg);\n } else {\n logArg = _ln(arg) * ONE_18;\n }\n\n // When dividing, we multiply by ONE_18 to arrive at a result with 18 decimal places\n return (logArg * ONE_18) / logBase;\n }\n\n /**\n * @dev Natural logarithm (ln(a)) with signed 18 decimal fixed point argument.\n */\n function ln(int256 a) internal pure returns (int256) {\n // The real natural logarithm is not defined for negative numbers or zero.\n require(a > 0, \"Out of bounds\");\n if (LN_36_LOWER_BOUND < a && a < LN_36_UPPER_BOUND) {\n return _ln_36(a) / ONE_18;\n } else {\n return _ln(a);\n }\n }\n\n /**\n * @dev Internal natural logarithm (ln(a)) with signed 18 decimal fixed point argument.\n */\n function _ln(int256 a) private pure returns (int256) {\n if (a < ONE_18) {\n // Since ln(a^k) = k * ln(a), we can compute ln(a) as ln(a) = ln((1/a)^(-1)) = - ln((1/a)). If a is less\n // than one, 1/a will be greater than one, and this if statement will not be entered in the recursive call.\n // Fixed point division requires multiplying by ONE_18.\n return (-_ln((ONE_18 * ONE_18) / a));\n }\n\n // First, we use the fact that ln^(a * b) = ln(a) + ln(b) to decompose ln(a) into a sum of powers of two, which\n // we call x_n, where x_n == 2^(7 - n), which are the natural logarithm of precomputed quantities a_n (that is,\n // ln(a_n) = x_n). We choose the first x_n, x0, to equal 2^7 because the exponential of all larger powers cannot\n // be represented as 18 fixed point decimal numbers in 256 bits, and are therefore larger than a.\n // At the end of this process we will have the sum of all x_n = ln(a_n) that apply, and the remainder of this\n // decomposition, which will be lower than the smallest a_n.\n // ln(a) = k_0 * x_0 + k_1 * x_1 + ... + k_n * x_n + ln(remainder), where each k_n equals either 0 or 1.\n // We mutate a by subtracting a_n, making it the remainder of the decomposition.\n\n // For reasons related to how `exp` works, the first two a_n (e^(2^7) and e^(2^6)) are not stored as fixed point\n // numbers with 18 decimals, but instead as plain integers with 0 decimals, so we need to multiply them by\n // ONE_18 to convert them to fixed point.\n // For each a_n, we test if that term is present in the decomposition (if a is larger than it), and if so divide\n // by it and compute the accumulated sum.\n\n int256 sum = 0;\n if (a >= a0 * ONE_18) {\n a /= a0; // Integer, not fixed point division\n sum += x0;\n }\n\n if (a >= a1 * ONE_18) {\n a /= a1; // Integer, not fixed point division\n sum += x1;\n }\n\n // All other a_n and x_n are stored as 20 digit fixed point numbers, so we convert the sum and a to this format.\n sum *= 100;\n a *= 100;\n\n // Because further a_n are 20 digit fixed point numbers, we multiply by ONE_20 when dividing by them.\n\n if (a >= a2) {\n a = (a * ONE_20) / a2;\n sum += x2;\n }\n\n if (a >= a3) {\n a = (a * ONE_20) / a3;\n sum += x3;\n }\n\n if (a >= a4) {\n a = (a * ONE_20) / a4;\n sum += x4;\n }\n\n if (a >= a5) {\n a = (a * ONE_20) / a5;\n sum += x5;\n }\n\n if (a >= a6) {\n a = (a * ONE_20) / a6;\n sum += x6;\n }\n\n if (a >= a7) {\n a = (a * ONE_20) / a7;\n sum += x7;\n }\n\n if (a >= a8) {\n a = (a * ONE_20) / a8;\n sum += x8;\n }\n\n if (a >= a9) {\n a = (a * ONE_20) / a9;\n sum += x9;\n }\n\n if (a >= a10) {\n a = (a * ONE_20) / a10;\n sum += x10;\n }\n\n if (a >= a11) {\n a = (a * ONE_20) / a11;\n sum += x11;\n }\n\n // a is now a small number (smaller than a_11, which roughly equals 1.06). This means we can use a Taylor series\n // that converges rapidly for values of `a` close to one - the same one used in ln_36.\n // Let z = (a - 1) / (a + 1).\n // ln(a) = 2 * (z + z^3 / 3 + z^5 / 5 + z^7 / 7 + ... + z^(2 * n + 1) / (2 * n + 1))\n\n // Recall that 20 digit fixed point division requires multiplying by ONE_20, and multiplication requires\n // division by ONE_20.\n int256 z = ((a - ONE_20) * ONE_20) / (a + ONE_20);\n int256 z_squared = (z * z) / ONE_20;\n\n // num is the numerator of the series: the z^(2 * n + 1) term\n int256 num = z;\n\n // seriesSum holds the accumulated sum of each term in the series, starting with the initial z\n int256 seriesSum = num;\n\n // In each step, the numerator is multiplied by z^2\n num = (num * z_squared) / ONE_20;\n seriesSum += num / 3;\n\n num = (num * z_squared) / ONE_20;\n seriesSum += num / 5;\n\n num = (num * z_squared) / ONE_20;\n seriesSum += num / 7;\n\n num = (num * z_squared) / ONE_20;\n seriesSum += num / 9;\n\n num = (num * z_squared) / ONE_20;\n seriesSum += num / 11;\n\n // 6 Taylor terms are sufficient for 36 decimal precision.\n\n // Finally, we multiply by 2 (non fixed point) to compute ln(remainder)\n seriesSum *= 2;\n\n // We now have the sum of all x_n present, and the Taylor approximation of the logarithm of the remainder (both\n // with 20 decimals). All that remains is to sum these two, and then drop two digits to return a 18 decimal\n // value.\n\n return (sum + seriesSum) / 100;\n }\n\n /**\n * @dev Intrnal high precision (36 decimal places) natural logarithm (ln(x)) with signed 18 decimal fixed point argument,\n * for x close to one.\n *\n * Should only be used if x is between LN_36_LOWER_BOUND and LN_36_UPPER_BOUND.\n */\n function _ln_36(int256 x) private pure returns (int256) {\n // Since ln(1) = 0, a value of x close to one will yield a very small result, which makes using 36 digits\n // worthwhile.\n\n // First, we transform x to a 36 digit fixed point value.\n x *= ONE_18;\n\n // We will use the following Taylor expansion, which converges very rapidly. Let z = (x - 1) / (x + 1).\n // ln(x) = 2 * (z + z^3 / 3 + z^5 / 5 + z^7 / 7 + ... + z^(2 * n + 1) / (2 * n + 1))\n\n // Recall that 36 digit fixed point division requires multiplying by ONE_36, and multiplication requires\n // division by ONE_36.\n int256 z = ((x - ONE_36) * ONE_36) / (x + ONE_36);\n int256 z_squared = (z * z) / ONE_36;\n\n // num is the numerator of the series: the z^(2 * n + 1) term\n int256 num = z;\n\n // seriesSum holds the accumulated sum of each term in the series, starting with the initial z\n int256 seriesSum = num;\n\n // In each step, the numerator is multiplied by z^2\n num = (num * z_squared) / ONE_36;\n seriesSum += num / 3;\n\n num = (num * z_squared) / ONE_36;\n seriesSum += num / 5;\n\n num = (num * z_squared) / ONE_36;\n seriesSum += num / 7;\n\n num = (num * z_squared) / ONE_36;\n seriesSum += num / 9;\n\n num = (num * z_squared) / ONE_36;\n seriesSum += num / 11;\n\n num = (num * z_squared) / ONE_36;\n seriesSum += num / 13;\n\n num = (num * z_squared) / ONE_36;\n seriesSum += num / 15;\n\n // 8 Taylor terms are sufficient for 36 decimal precision.\n\n // All that remains is multiplying by 2 (non fixed point).\n return seriesSum * 2;\n }\n}\n"
},
"src/PoolToken.sol": {
"content": "// SPDX-License-Identifier: MIT\npragma solidity ^0.8.0;\n\nimport {ERC20} from \"solady/tokens/ERC20.sol\";\nimport {Ownable} from \"solady/auth/Ownable.sol\";\n\ncontract PoolToken is ERC20, Ownable {\n error Token__CallerIsNotPool();\n error Token__PoolAddressCannotBeZero();\n\n event PoolAddressSet(address newPoolAddress);\n\n string internal _name;\n string internal _symbol;\n uint8 internal _decimals;\n address poolAddress;\n\n function _checkCallerIsPool() internal view {\n if (msg.sender != poolAddress) {\n revert Token__CallerIsNotPool();\n }\n }\n\n constructor(string memory name_, string memory symbol_, uint8 decimals_, address owner_) {\n _name = name_;\n _symbol = symbol_;\n _decimals = decimals_;\n _setOwner(owner_);\n }\n\n function name() public view virtual override returns (string memory) {\n return _name;\n }\n\n function symbol() public view virtual override returns (string memory) {\n return _symbol;\n }\n\n function decimals() public view virtual override returns (uint8) {\n return _decimals;\n }\n\n function mint(address to_, uint256 amount_) public {\n _checkCallerIsPool();\n _mint(to_, amount_);\n }\n\n function burn(address from_, uint256 amount_) public {\n _checkCallerIsPool();\n _burn(from_, amount_);\n }\n\n function setPool(address poolAddress_) public onlyOwner {\n if (poolAddress_ == address(0)) revert Token__PoolAddressCannotBeZero();\n poolAddress = poolAddress_;\n renounceOwnership();\n emit PoolAddressSet(poolAddress);\n }\n}\n"
}
},
"settings": {
"remappings": [
"@openzeppelin/contracts/=lib/openzeppelin-contracts/contracts/",
"ds-test/=lib/openzeppelin-contracts/lib/forge-std/lib/ds-test/src/",
"erc4626-tests/=lib/erc4626-tests/",
"forge-std/=lib/forge-std/src/",
"openzeppelin-contracts/=lib/openzeppelin-contracts/",
"solady/=lib/solady/src/"
],
"optimizer": {
"enabled": true,
"runs": 100
},
"metadata": {
"useLiteralContent": false,
"bytecodeHash": "ipfs",
"appendCBOR": true
},
"outputSelection": {
"*": {
"*": [
"abi",
"evm.bytecode",
"evm.deployedBytecode",
"evm.methodIdentifiers",
"metadata"
]
}
},
"evmVersion": "cancun",
"viaIR": true,
"libraries": {}
}
}