Skip to content

certora: fix prover timeouts and spec cleanup - #46

Open
avniculae wants to merge 20 commits into
mainfrom
fix/certora-timeouts-and-spec-cleanup
Open

certora: fix prover timeouts and spec cleanup#46
avniculae wants to merge 20 commits into
mainfrom
fix/certora-timeouts-and-spec-cleanup

Conversation

@avniculae

@avniculae avniculae commented Aug 3, 2026

Copy link
Copy Markdown
Collaborator

Ports Certora#9, which supersedes #6 and #8 — all three can be closed once this lands. Commits and authorship retained; main is a direct ancestor, so the diff is only the Certora spec/conf/CI changes.

All 48 prover jobs verify.

On top of the ported work:

  • Rounding.Expand was modelled as a floor division; the summaries now mirror OZ's unsignedRoundsUp
  • mulDiv_equivalence.spec proves the exact, nondeterministic and closed-form mulDiv encodings denote the same value
  • -copyLoopUnroll 6 was silently dropped on the optimality.conf R2 line, since a line-level --prover_args replaces the conf's array
  • gho-fixedPriceStrategy4626.conf pointed at a spec that isn't in the tree, and gho-assetToGhoInvertibility-4626.conf failed typechecking on a missing GhoReserve.sol; both fixed and wired into CI
  • balances-sell-4626 R1/R1a/R2 and gho-assetToGhoInvertibility-4626 were green only via timeout reruns; both now verify on the committed config, the latter via a z3 seed race (119m timeout → 3m)
  • remaining unchecked twostagetwostage-checked; optimality4626.spec moved to the closed-form Ceil encoding to match its non-4626 twin

One pre-existing item left open: getAmount-properties-4626.conf --rule getAssetAmountForSellAsset_optimality getAssetAmountForBuyAsset_funcProperty has gone green via rerun on two of five runs (#issuecomment-5177477733).

shellygr added 10 commits July 10, 2026 18:18
Remove the representative-constant pins on price ratio and sell fee from
R4_buyGhoUpdatesGhoBalanceCorrectly: route the conf's mulDiv summaries to a
nondeterministic (multiplicative) encoding, where the quotient is a fresh
variable pinned by its floor/ceil bounds plus implied product-free hints.
@github-actions

github-actions Bot commented Aug 3, 2026

Copy link
Copy Markdown

Certora Run Started (Certora Prover Run)

  • Group ID: 88126f38-e174-4280-a1c5-bcf4473d6ed2
Config Status Link Log File
balances-buy-4626.conf Submitted link certora/gsm/conf/gsm4626/balances-buy-4626.conf-83ebbafb2abb.log
balances-sell-4626.conf --rule R1_getAssetAmountForSellAsset_arg_vs_return R1a_buyGhoUpdatesGhoBalanceCorrectly1 R2_getAssetAmountForSellAsset_sellAsset_eq Submitted link certora/gsm/conf/gsm4626/balances-sell-4626.conf-edfc405e3678.log
balances-sell-4626.conf --rule R3a_sellAssetUpdatesAssetBalanceCorrectly Submitted link certora/gsm/conf/gsm4626/balances-sell-4626.conf-305570ff4b97.log
balances-sell-4626.conf --rule R4_buyGhoUpdatesGhoBalanceCorrectly Submitted link certora/gsm/conf/gsm4626/balances-sell-4626.conf-e4c5ab60b780.log
balances-sell-4626.conf --rule R4a_buyGhoAmountGtGhoBalanceChange Submitted link certora/gsm/conf/gsm4626/balances-sell-4626.conf-16d2b29a467d.log
fees-buy-4626.conf Submitted link certora/gsm/conf/gsm4626/fees-buy-4626.conf-e7d498c5655e.log
fees-sell-4626.conf --rule R3a_estimatedSellFeeCanBeLowerThanActualSellFee R2_getAssetAmountForSellAssetVsActualSellFee R4a_getSellFeeVsgetAssetAmountForSellAsset R4_getSellFeeVsgetAssetAmountForSellAsset R1a_getAssetAmountForSellAssetFeeNeGetSellFee R2a_getAssetAmountForSellAssetNeActualSellFee R4b_getSellFeeVsgetAssetAmountForSellAsset R1_getAssetAmountForSellAssetFeeGeGetSellFee R3b_estimatedSellFeeEqActualSellFee Submitted link certora/gsm/conf/gsm4626/fees-sell-4626.conf-f871a62bc2b7.log
finishedRules-4626.conf --rule cantBuyOrSellWhenSeized cantBuyOrSellWhenFrozen sellAssetIncreasesExposure buyAssetDecreasesExposure rescuingAssetKeepsAccruedFees rescuingGhoKeepsAccruedFees giftingGhoDoesntAffectStorageSIMPLE correctnessOfBuyAsset giftingUnderlyingDoesntAffectStorageSIMPLE sellAssetSameAsGetGhoAmountForSellAsset correctnessOfSellAsset giftingGhoDoesntCreateExcessOrDearth backWithGhoDoesntCreateExcess getAssetAmountForSellAsset_correctness collectedSellFeeIsAtLeastAsRequired collectedBuyFeePlus2IsAtLeastAsRequired collectedBuyFeePlus1IsAtLeastAsRequired collectedBuyFeeIsAtLeastAsRequired sellingDoesntExceedExposureCap whoCanChangeAccruedFees whoCanChangeExposure Submitted link certora/gsm/conf/gsm4626/finishedRules-4626.conf-b2aaf6c0c47b.log
finishedRules-4626.conf --rule giftingUnderlyingDoesntCreateExcessOrDearth Submitted link certora/gsm/conf/gsm4626/finishedRules-4626.conf-fa938922b634.log
getAmount-properties-4626.conf --rule getAssetAmountForBuyAsset_correctness_bound1 getAssetAmountForBuyAsset_correctness_bound2 getGhoAmountForBuyAsset_correctness_bound1 getAssetAmountForSellAsset_correctness getAssetAmountForBuyAsset_optimality getAssetAmountForBuyAsset_correctness Submitted link certora/gsm/conf/gsm4626/getAmount-properties-4626.conf-f51437517067.log
getAmount-properties-4626.conf --rule getAssetAmountForSellAsset_optimality getAssetAmountForBuyAsset_funcProperty --prover_args "-destructiveOptimizations twostage" Submitted link certora/gsm/conf/gsm4626/getAmount-properties-4626.conf-840720238e9b.log
getAmount-properties-4626.conf --rule getGhoAmountForBuyAsset_correctness Submitted link certora/gsm/conf/gsm4626/getAmount-properties-4626.conf-deedd828f04c.log
getAmount-properties-4626.conf --rule getGhoAmountForBuyAsset_optimality Submitted link certora/gsm/conf/gsm4626/getAmount-properties-4626.conf-7494fc3e89ee.log
gho-gsm4626-1.conf Submitted link certora/gsm/conf/gsm4626/gho-gsm4626-1.conf-d724becac628.log
gho-gsm4626-2.conf --rule accruedFeesLEGhoBalanceOfThis Submitted link certora/gsm/conf/gsm4626/gho-gsm4626-2.conf-14e86f9dae3d.log
gho-gsm4626-2.conf --rule accruedFeesNeverDecrease Submitted link certora/gsm/conf/gsm4626/gho-gsm4626-2.conf-d8aea5002500.log
gho-gsm4626-inverse.conf --rule buySellInverse27 buySellInverse26 buySellInverse25 buySellInverse24 buySellInverse23 buySellInverse22 buySellInverse21 buySellInverse20 buySellInverse19 Submitted link certora/gsm/conf/gsm4626/gho-gsm4626-inverse.conf-c176a9b519fd.log
optimality4626.conf --rule R1_optimalityOfBuyAsset_v1 Submitted link certora/gsm/conf/gsm4626/optimality4626.conf-e2760620fc84.log
optimality4626.conf --rule R3_optimalityOfSellAsset_v1 Submitted link certora/gsm/conf/gsm4626/optimality4626.conf-338c1d7ec102.log
optimality4626.conf --rule R5a_externalOptimalityOfSellAsset R6a_externalOptimalityOfBuyAsset Submitted link certora/gsm/conf/gsm4626/optimality4626.conf-7f1ed359b6b9.log

Certora Run Summary

  • Started 20 jobs
  • 0 jobs failed

Download Logs

@github-actions

github-actions Bot commented Aug 3, 2026

Copy link
Copy Markdown

Certora Run Started (Certora Prover Run)

  • Group ID: bf503479-bdc2-4dad-9108-0dacc6b8c081
Config Status Link Log File
FixedFeeStrategy.conf Submitted link certora/gsm/conf/gsm/FixedFeeStrategy.conf-ebd5661fda3f.log
OracleSwapFreezer.conf Submitted link certora/gsm/conf/gsm/OracleSwapFreezer.conf-37dc1e99f8a1.log
balances-buy.conf Submitted link certora/gsm/conf/gsm/balances-buy.conf-456f8315f38f.log
balances-sell.conf Submitted link certora/gsm/conf/gsm/balances-sell.conf-9d843612caa8.log
fees-buy.conf Submitted link certora/gsm/conf/gsm/fees-buy.conf-1ea2523d559f.log
fees-sell.conf --exclude_rule R3a_estimatedSellFeeCanBeLowerThanActualSellFee Submitted link certora/gsm/conf/gsm/fees-sell.conf-7686735dbc1a.log
fees-sell.conf --rule R3a_estimatedSellFeeCanBeLowerThanActualSellFee Submitted link certora/gsm/conf/gsm/fees-sell.conf-c301fb5759bd.log
finishedRules.conf --rule whoCanChangeExposure whoCanChangeAccruedFees sellingDoesntExceedExposureCap cantBuyOrSellWhenSeized giftingGhoDoesntAffectStorageSIMPLE giftingUnderlyingDoesntAffectStorageSIMPLE collectedBuyFeePlus1IsAtLeastAsRequired sellAssetSameAsGetGhoAmountForSellAsset collectedSellFeeIsAtLeastAsRequired collectedBuyFeeIsAtLeastAsRequired correctnessOfBuyAsset collectedBuyFeePlus2IsAtLeastAsRequired getAssetAmountForSellAsset_correctness cantBuyOrSellWhenFrozen whoCanChangeExposureCap cantSellIfExposureTooHigh sellAssetIncreasesExposure buyAssetDecreasesExposure rescuingGhoKeepsAccruedFees rescuingAssetKeepsAccruedFees Submitted link certora/gsm/conf/gsm/finishedRules.conf-79b42996457e.log
getAmount_properties.conf --rule getAssetAmountForBuyAsset_funcProperty_LR getAssetAmountForBuyAsset_funcProperty_RL Submitted link certora/gsm/conf/gsm/getAmount_properties.conf-28a8a4892622.log
gho-assetToGhoInvertibility.conf --rule basicProperty2_getAssetAmountForBuyAsset Submitted link certora/gsm/conf/gsm/gho-assetToGhoInvertibility.conf-f47215d43810.log
gho-assetToGhoInvertibility.conf --rule basicProperty_getAssetAmountForBuyAsset sellAssetInverse_all buyAssetInverse_all basicProperty_getGhoAmountForSellAsset basicProperty_getAssetAmountForSellAsset basicProperty_getGhoAmountForBuyAsset Submitted link certora/gsm/conf/gsm/gho-assetToGhoInvertibility.conf-28d83d828a73.log
gho-fixedPriceStrategy.conf Submitted link certora/gsm/conf/gsm/gho-fixedPriceStrategy.conf-62c567b9a9dc.log
gho-gsm-1.conf Submitted link certora/gsm/conf/gsm/gho-gsm-1.conf-9ae04f61a37a.log
gho-gsm-2.conf --exclude_rule systemBalanceStabilityBuy Submitted link certora/gsm/conf/gsm/gho-gsm-2.conf-0610fdc4d60d.log
gho-gsm-2.conf --rule systemBalanceStabilityBuy Submitted link certora/gsm/conf/gsm/gho-gsm-2.conf-d81e39858579.log
gho-gsm-inverse.conf Submitted link certora/gsm/conf/gsm/gho-gsm-inverse.conf-af68e33837f7.log
optimality.conf --rule R2_optimalityOfBuyAsset_v2 --prover_args "-destructiveOptimizations twostage" Submitted link certora/gsm/conf/gsm/optimality.conf-e734757ad560.log
optimality.conf --rule R3_optimalityOfSellAsset_v1 R1_optimalityOfBuyAsset_v1 R6a_externalOptimalityOfBuyAsset R5a_externalOptimalityOfSellAsset Submitted link certora/gsm/conf/gsm/optimality.conf-531dd0e4e447.log

Certora Run Summary

  • Started 18 jobs
  • 0 jobs failed

Download Logs

@certora-run certora-run Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

@github-actions

github-actions Bot commented Aug 3, 2026

Copy link
Copy Markdown

Certora Run Started (Certora Prover Run)

  • Group ID: 7bd15000-aa4d-4fe5-bcc2-77c74237a212
Config Status Link Log File
GhoAaveSteward.conf Submitted link certora/steward/conf/GhoAaveSteward.conf-9b97e34eb222.log
GhoBucketSteward.conf Submitted link certora/steward/conf/GhoBucketSteward.conf-bf972efef43b.log
GhoCcipSteward.conf Submitted link certora/steward/conf/GhoCcipSteward.conf-5750ccaa7912.log
GhoGsmSteward.conf Submitted link certora/steward/conf/GhoGsmSteward.conf-eceb8e6c3bb8.log

Certora Run Summary

  • Started 4 jobs
  • 0 jobs failed

Download Logs

@certora-run certora-run Bot left a comment

Copy link
Copy Markdown

@certora-run certora-run Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Certora Prover Run

  • Group ID: 7bd15000-aa4d-4fe5-bcc2-77c74237a212
  • Commit: d63123f
JobResultVERIFIED
GhoGsmStewar…12
GhoCcipStewa…11
GhoBucketSte…8
GhoAaveStewa…17

@github-actions

github-actions Bot commented Aug 3, 2026

Copy link
Copy Markdown

Certora Run Started (Certora Prover Run)

  • Group ID: 989119a6-410f-45e4-b71a-546a520f721b
Config Status Link Log File
verifyFlashMinter.conf --rule balanceOfFlashMinterGrows integrityOfTreasurySet integrityOfFeeSet availableLiquidityDoesntChange integrityOfDistributeFeesToTreasury feeSimulationEqualsActualFee Submitted link certora/gho/conf/verifyFlashMinter.conf-14cae1f4c96b.log
verifyGhoToken.conf Submitted link certora/gho/conf/verifyGhoToken.conf-b730c11ad6ec.log
verifyUpgradeableGhoToken.conf Submitted link certora/gho/conf/verifyUpgradeableGhoToken.conf-d0dcb876d131.log

Certora Run Summary

  • Started 3 jobs
  • 0 jobs failed

Download Logs

@certora-run certora-run Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Certora Prover Run

  • Group ID: 989119a6-410f-45e4-b71a-546a520f721b
  • Commit: d63123f
JobResultVERIFIED
verifyUpgrad…28
verifyGhoTok…28
verifyFlashM…7

The summaries decided rounding with `rounding == Ceil`, but OZ v5 rounds up
whenever `uint8(rounding) % 2 == 1`, i.e. for Ceil and Expand. An Expand call
would silently have been modelled as a floor division. Nothing in scene passes
Expand today, so this is a no-op on the current proofs, but it removes a
footgun that was replicated across all eight call sites.
The confs pick between the exact, nondeterministic and closed-form mulDiv
encodings purely for solver tractability, so they must all denote the same
value. Nothing enforced that: loosening one of the nondet bounds would weaken
every proof routed through it while leaving CI green.

Verified, and rule_sanity confirms the rules are not vacuous.
optimality.spec routes to the closed-form Ceil because the optimality proofs
reason about (x*y + d - 1)/d far better than about a floor plus a remainder
bump; the 4626 twin was still on the reuse-floor form.

Also drops the unused env binding from the constructor preserved blocks.
gho-fixedPriceStrategy4626.conf pointed at FixedPriceStrategy4626.spec, which
does not exist in the tree, so it could never run; point it at the spec that
does. gho-assetToGhoInvertibility-4626.conf failed typechecking outright -
methods4626_base.spec declares `using GhoReserve as _ghoReserve` but the conf's
files list had never been updated - so add GhoReserve plus the missing links and
remapping to match its working siblings.

Both had drifted precisely because nothing exercised them.
…ces-sell timeout

- Both remaining unchecked `-destructiveOptimizations twostage` uses become
  twostage-checked, matching the decision already applied to the six confs.
  Plain twostage only warns when a violation cannot be confirmed without the
  optimizations; the checked variant fails.
- balances-sell-4626 R1/R1a/R2 was only going green via auto-rerun-timeouts:
  the committed conf timed out and a rerun with different settings passed. The
  conf's nonlinear solver tuning is there for R4, so give these three their own
  args instead of relying on the rerun ladder.
- Wire in the two previously unrun 4626 confs and the mulDiv equivalence conf.
- Note that a --prover_args here replaces the conf's array rather than appending
  to it, which is easy to miss: the optimality R2 line therefore runs without
  the conf's -copyLoopUnroll 6 -depth 20.
@github-actions

github-actions Bot commented Aug 3, 2026

Copy link
Copy Markdown

Certora Run Started (Certora Prover Run)

  • Group ID: 360494a4-ae11-4d6d-b4a8-c6e70c433833
Config Status Link Log File
FixedFeeStrategy.conf Submitted link certora/gsm/conf/gsm/FixedFeeStrategy.conf-427bd9585a1c.log
OracleSwapFreezer.conf Submitted link certora/gsm/conf/gsm/OracleSwapFreezer.conf-ea77066051ee.log
balances-buy.conf Submitted link certora/gsm/conf/gsm/balances-buy.conf-71e8cf90636e.log
balances-sell.conf Submitted link certora/gsm/conf/gsm/balances-sell.conf-d63d1ba30202.log
fees-buy.conf Submitted link certora/gsm/conf/gsm/fees-buy.conf-85c7ed89479e.log
fees-sell.conf --exclude_rule R3a_estimatedSellFeeCanBeLowerThanActualSellFee Submitted link certora/gsm/conf/gsm/fees-sell.conf-8f98656c92d2.log
fees-sell.conf --rule R3a_estimatedSellFeeCanBeLowerThanActualSellFee Submitted link certora/gsm/conf/gsm/fees-sell.conf-ff133dfc590c.log
finishedRules.conf --rule whoCanChangeExposure whoCanChangeAccruedFees sellingDoesntExceedExposureCap cantBuyOrSellWhenSeized giftingGhoDoesntAffectStorageSIMPLE giftingUnderlyingDoesntAffectStorageSIMPLE collectedBuyFeePlus1IsAtLeastAsRequired sellAssetSameAsGetGhoAmountForSellAsset collectedSellFeeIsAtLeastAsRequired collectedBuyFeeIsAtLeastAsRequired correctnessOfBuyAsset collectedBuyFeePlus2IsAtLeastAsRequired getAssetAmountForSellAsset_correctness cantBuyOrSellWhenFrozen whoCanChangeExposureCap cantSellIfExposureTooHigh sellAssetIncreasesExposure buyAssetDecreasesExposure rescuingGhoKeepsAccruedFees rescuingAssetKeepsAccruedFees Submitted link certora/gsm/conf/gsm/finishedRules.conf-3ce8aba97062.log
getAmount_properties.conf --rule getAssetAmountForBuyAsset_funcProperty_LR getAssetAmountForBuyAsset_funcProperty_RL Submitted link certora/gsm/conf/gsm/getAmount_properties.conf-006d0ce7bda7.log
gho-assetToGhoInvertibility.conf --rule basicProperty2_getAssetAmountForBuyAsset Submitted link certora/gsm/conf/gsm/gho-assetToGhoInvertibility.conf-2c2e0f1be11b.log
gho-assetToGhoInvertibility.conf --rule basicProperty_getAssetAmountForBuyAsset sellAssetInverse_all buyAssetInverse_all basicProperty_getGhoAmountForSellAsset basicProperty_getAssetAmountForSellAsset basicProperty_getGhoAmountForBuyAsset Submitted link certora/gsm/conf/gsm/gho-assetToGhoInvertibility.conf-a13440b4110e.log
gho-fixedPriceStrategy.conf Submitted link certora/gsm/conf/gsm/gho-fixedPriceStrategy.conf-1bb97095bbad.log
gho-gsm-1.conf Submitted link certora/gsm/conf/gsm/gho-gsm-1.conf-472a70177933.log
gho-gsm-2.conf --exclude_rule systemBalanceStabilityBuy Submitted link certora/gsm/conf/gsm/gho-gsm-2.conf-8225ea86f3f3.log
gho-gsm-2.conf --rule systemBalanceStabilityBuy Submitted link certora/gsm/conf/gsm/gho-gsm-2.conf-fb8717ae8dc9.log
gho-gsm-inverse.conf Submitted link certora/gsm/conf/gsm/gho-gsm-inverse.conf-e7a16a908d87.log
mulDiv_equivalence.conf Submitted link certora/gsm/conf/gsm/mulDiv_equivalence.conf-2b9b352bb1aa.log
optimality.conf --rule R2_optimalityOfBuyAsset_v2 --prover_args "-destructiveOptimizations twostage-checked" Submitted link certora/gsm/conf/gsm/optimality.conf-2513f50c60a7.log
optimality.conf --rule R3_optimalityOfSellAsset_v1 R1_optimalityOfBuyAsset_v1 R6a_externalOptimalityOfBuyAsset R5a_externalOptimalityOfSellAsset Submitted link certora/gsm/conf/gsm/optimality.conf-939503cd2925.log

Certora Run Summary

  • Started 19 jobs
  • 0 jobs failed

Download Logs

@certora-run certora-run Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

@github-actions

github-actions Bot commented Aug 3, 2026

Copy link
Copy Markdown

Certora Run Started (Certora Prover Run)

  • Group ID: 28ae0c1e-8555-4342-9f38-3ad7e1c08ed1
Config Status Link Log File
balances-buy-4626.conf Submitted link certora/gsm/conf/gsm4626/balances-buy-4626.conf-823968824ee8.log
balances-sell-4626.conf --rule R1_getAssetAmountForSellAsset_arg_vs_return R1a_buyGhoUpdatesGhoBalanceCorrectly1 R2_getAssetAmountForSellAsset_sellAsset_eq --prover_args "-copyLoopUnroll 6 -destructiveOptimizations twostage-checked" Submitted link certora/gsm/conf/gsm4626/balances-sell-4626.conf-c20df490493d.log
balances-sell-4626.conf --rule R3a_sellAssetUpdatesAssetBalanceCorrectly Submitted link certora/gsm/conf/gsm4626/balances-sell-4626.conf-95131c528bb4.log
balances-sell-4626.conf --rule R4_buyGhoUpdatesGhoBalanceCorrectly Submitted link certora/gsm/conf/gsm4626/balances-sell-4626.conf-5a1e248c508f.log
balances-sell-4626.conf --rule R4a_buyGhoAmountGtGhoBalanceChange Submitted link certora/gsm/conf/gsm4626/balances-sell-4626.conf-43f64702087a.log
fees-buy-4626.conf Submitted link certora/gsm/conf/gsm4626/fees-buy-4626.conf-035ae838df2e.log
fees-sell-4626.conf --rule R3a_estimatedSellFeeCanBeLowerThanActualSellFee R2_getAssetAmountForSellAssetVsActualSellFee R4a_getSellFeeVsgetAssetAmountForSellAsset R4_getSellFeeVsgetAssetAmountForSellAsset R1a_getAssetAmountForSellAssetFeeNeGetSellFee R2a_getAssetAmountForSellAssetNeActualSellFee R4b_getSellFeeVsgetAssetAmountForSellAsset R1_getAssetAmountForSellAssetFeeGeGetSellFee R3b_estimatedSellFeeEqActualSellFee Submitted link certora/gsm/conf/gsm4626/fees-sell-4626.conf-46807aec9628.log
finishedRules-4626.conf --rule cantBuyOrSellWhenSeized cantBuyOrSellWhenFrozen sellAssetIncreasesExposure buyAssetDecreasesExposure rescuingAssetKeepsAccruedFees rescuingGhoKeepsAccruedFees giftingGhoDoesntAffectStorageSIMPLE correctnessOfBuyAsset giftingUnderlyingDoesntAffectStorageSIMPLE sellAssetSameAsGetGhoAmountForSellAsset correctnessOfSellAsset giftingGhoDoesntCreateExcessOrDearth backWithGhoDoesntCreateExcess getAssetAmountForSellAsset_correctness collectedSellFeeIsAtLeastAsRequired collectedBuyFeePlus2IsAtLeastAsRequired collectedBuyFeePlus1IsAtLeastAsRequired collectedBuyFeeIsAtLeastAsRequired sellingDoesntExceedExposureCap whoCanChangeAccruedFees whoCanChangeExposure Submitted link certora/gsm/conf/gsm4626/finishedRules-4626.conf-61e854ecd8c5.log
finishedRules-4626.conf --rule giftingUnderlyingDoesntCreateExcessOrDearth Submitted link certora/gsm/conf/gsm4626/finishedRules-4626.conf-e49c9c9ce8ed.log
getAmount-properties-4626.conf --rule getAssetAmountForBuyAsset_correctness_bound1 getAssetAmountForBuyAsset_correctness_bound2 getGhoAmountForBuyAsset_correctness_bound1 getAssetAmountForSellAsset_correctness getAssetAmountForBuyAsset_optimality getAssetAmountForBuyAsset_correctness Submitted link certora/gsm/conf/gsm4626/getAmount-properties-4626.conf-5e4c2e23570a.log
getAmount-properties-4626.conf --rule getAssetAmountForSellAsset_optimality getAssetAmountForBuyAsset_funcProperty --prover_args "-destructiveOptimizations twostage-checked" Submitted link certora/gsm/conf/gsm4626/getAmount-properties-4626.conf-96cae532f441.log
getAmount-properties-4626.conf --rule getGhoAmountForBuyAsset_correctness Submitted link certora/gsm/conf/gsm4626/getAmount-properties-4626.conf-0629b371fded.log
getAmount-properties-4626.conf --rule getGhoAmountForBuyAsset_optimality Submitted link certora/gsm/conf/gsm4626/getAmount-properties-4626.conf-babb807b9191.log
gho-assetToGhoInvertibility-4626.conf Submitted link certora/gsm/conf/gsm4626/gho-assetToGhoInvertibility-4626.conf-b17bdd84eecd.log
gho-fixedPriceStrategy4626.conf Submitted link certora/gsm/conf/gsm4626/gho-fixedPriceStrategy4626.conf-02b6ead3c675.log
gho-gsm4626-1.conf Submitted link certora/gsm/conf/gsm4626/gho-gsm4626-1.conf-6ac43372ad15.log
gho-gsm4626-2.conf --rule accruedFeesLEGhoBalanceOfThis Submitted link certora/gsm/conf/gsm4626/gho-gsm4626-2.conf-f19e89505fb0.log
gho-gsm4626-2.conf --rule accruedFeesNeverDecrease Submitted link certora/gsm/conf/gsm4626/gho-gsm4626-2.conf-93364bff4ac0.log
gho-gsm4626-inverse.conf --rule buySellInverse27 buySellInverse26 buySellInverse25 buySellInverse24 buySellInverse23 buySellInverse22 buySellInverse21 buySellInverse20 buySellInverse19 Submitted link certora/gsm/conf/gsm4626/gho-gsm4626-inverse.conf-2273b0e292f4.log
optimality4626.conf --rule R1_optimalityOfBuyAsset_v1 Submitted link certora/gsm/conf/gsm4626/optimality4626.conf-db0369c63d7b.log
optimality4626.conf --rule R3_optimalityOfSellAsset_v1 Submitted link certora/gsm/conf/gsm4626/optimality4626.conf-40c3b4ad9870.log
optimality4626.conf --rule R5a_externalOptimalityOfSellAsset R6a_externalOptimalityOfBuyAsset Submitted link certora/gsm/conf/gsm4626/optimality4626.conf-0c1f36f933e2.log

Certora Run Summary

  • Started 22 jobs
  • 0 jobs failed

Download Logs

@certora-run certora-run Bot left a comment

Copy link
Copy Markdown

@shellygr

shellygr commented Aug 3, 2026

Copy link
Copy Markdown

So optimality.conf --rule R2_optimalityOfBuyAsset_v2 --prover_args "-destructiveOptimizations twostage-checked" runs without the conf's -copyLoopUnroll 6 -depth 20. I left that arg set alone since it verifies as-is, and documented the semantics in both workflows. @shellygr — was the replacement intended there?

I would try to add back -copyLoopUnroll 6, as without it the default is 4. I am not 100% sure it is necessary in your case or why it was there to begin with. It affects the unrolling of compiler-generated copy-loops, so if the call has abi.* ops it could be relevant. The -depth option is only affecting performance/timeouts but not what is actually verified.

A --prover_args on a workflow line replaces the conf's array, so overriding it
for R2 silently dropped the conf's -copyLoopUnroll 6 and fell back to the
default of 4. With optimistic_loop the shortfall paths are assumed away rather
than reported, so the unroll bound is a coverage setting and not just a timing
one. -depth is left off, it only affects performance.

Per #46 (comment)
Running both rules in one job took 67 minutes and only passed via the rerun
ladder (2 of 11 strategies succeeded), which is the same masking this PR removes
from balances-sell-4626. Splitting matches how every other heavy conf here is
handled. buyAssetInverse_all verifies on its own with timed_out=False.
@avniculae

avniculae commented Aug 3, 2026

Copy link
Copy Markdown
Collaborator Author

Thanks — added -copyLoopUnroll 6 back to that line. Worth noting it's not only a performance knob: with optimistic_loop an insufficient unroll bound means the shortfall paths get assumed away rather than reported, so 6 vs the default 4 is a coverage difference. R2 verifies with it restored. Left -depth off per your point.

The other override, on getAmount-properties-4626.conf, only drops splitting/perf args and that conf has its -copyLoopUnroll line commented out, so nothing to restore there.

Two other things while I was in here:

gho-assetToGhoInvertibility-4626.conf was failing typechecking — methods4626_base.spec declares using GhoReserve as _ghoReserve but the conf's files list never got GhoReserve.sol. And gho-fixedPriceStrategy4626.conf pointed at FixedPriceStrategy4626.spec, which isn't in the tree. Both had drifted because no workflow ran them, so I fixed and wired them in. The invertibility conf was slow at first (67m) and I initially worked around that by splitting; adding the z3 seed race you already use elsewhere brought it to 5m for both rules, so it runs as a single unsplit line.

On auto-rerun-timeouts: balances-sell-4626 --rule R1/R1a/R2 reported green as "status from rerun" after 11 reruns on Certora#9, i.e. the configuration in the repo wasn't the one that verified. On this PR the same commit happened to run clean, so it's run-dependent. Its nonlinear tuning is there for R4, so I gave those three their own args.

(Edited: originally said the invertibility conf "needed splitting per rule" and did not say where the 11-rerun observation came from.)

@github-actions

github-actions Bot commented Aug 3, 2026

Copy link
Copy Markdown

Certora Run Started (Certora Prover Run)

  • Group ID: 7f157de4-037e-48db-b45f-217cd14b6dc8
Config Status Link Log File
FixedFeeStrategy.conf Submitted link certora/gsm/conf/gsm/FixedFeeStrategy.conf-07e277438983.log
OracleSwapFreezer.conf Submitted link certora/gsm/conf/gsm/OracleSwapFreezer.conf-514f06f4307b.log
balances-buy.conf Submitted link certora/gsm/conf/gsm/balances-buy.conf-bf02575723ba.log
balances-sell.conf Submitted link certora/gsm/conf/gsm/balances-sell.conf-7a28dd59cc95.log
fees-buy.conf Submitted link certora/gsm/conf/gsm/fees-buy.conf-68c55ba231e0.log
fees-sell.conf --exclude_rule R3a_estimatedSellFeeCanBeLowerThanActualSellFee Submitted link certora/gsm/conf/gsm/fees-sell.conf-c6c3a2ed2d24.log
fees-sell.conf --rule R3a_estimatedSellFeeCanBeLowerThanActualSellFee Submitted link certora/gsm/conf/gsm/fees-sell.conf-e044a4199478.log
finishedRules.conf --rule whoCanChangeExposure whoCanChangeAccruedFees sellingDoesntExceedExposureCap cantBuyOrSellWhenSeized giftingGhoDoesntAffectStorageSIMPLE giftingUnderlyingDoesntAffectStorageSIMPLE collectedBuyFeePlus1IsAtLeastAsRequired sellAssetSameAsGetGhoAmountForSellAsset collectedSellFeeIsAtLeastAsRequired collectedBuyFeeIsAtLeastAsRequired correctnessOfBuyAsset collectedBuyFeePlus2IsAtLeastAsRequired getAssetAmountForSellAsset_correctness cantBuyOrSellWhenFrozen whoCanChangeExposureCap cantSellIfExposureTooHigh sellAssetIncreasesExposure buyAssetDecreasesExposure rescuingGhoKeepsAccruedFees rescuingAssetKeepsAccruedFees Submitted link certora/gsm/conf/gsm/finishedRules.conf-398f0dfa71f0.log
getAmount_properties.conf --rule getAssetAmountForBuyAsset_funcProperty_LR getAssetAmountForBuyAsset_funcProperty_RL Submitted link certora/gsm/conf/gsm/getAmount_properties.conf-f772ba259c36.log
gho-assetToGhoInvertibility.conf --rule basicProperty2_getAssetAmountForBuyAsset Submitted link certora/gsm/conf/gsm/gho-assetToGhoInvertibility.conf-2019d57aa6a9.log
gho-assetToGhoInvertibility.conf --rule basicProperty_getAssetAmountForBuyAsset sellAssetInverse_all buyAssetInverse_all basicProperty_getGhoAmountForSellAsset basicProperty_getAssetAmountForSellAsset basicProperty_getGhoAmountForBuyAsset Submitted link certora/gsm/conf/gsm/gho-assetToGhoInvertibility.conf-ceb96af49d1c.log
gho-fixedPriceStrategy.conf Submitted link certora/gsm/conf/gsm/gho-fixedPriceStrategy.conf-69a20907d5bb.log
gho-gsm-1.conf Submitted link certora/gsm/conf/gsm/gho-gsm-1.conf-3b72efa070e1.log
gho-gsm-2.conf --exclude_rule systemBalanceStabilityBuy Submitted link certora/gsm/conf/gsm/gho-gsm-2.conf-28b757894e48.log
gho-gsm-2.conf --rule systemBalanceStabilityBuy Submitted link certora/gsm/conf/gsm/gho-gsm-2.conf-5cb787a119d9.log
gho-gsm-inverse.conf Submitted link certora/gsm/conf/gsm/gho-gsm-inverse.conf-aa395e8b5f78.log
mulDiv_equivalence.conf Submitted link certora/gsm/conf/gsm/mulDiv_equivalence.conf-f3835c6d632b.log
optimality.conf --rule R2_optimalityOfBuyAsset_v2 --prover_args "-copyLoopUnroll 6 -destructiveOptimizations twostage-checked" Submitted link certora/gsm/conf/gsm/optimality.conf-1b779a442e5c.log
optimality.conf --rule R3_optimalityOfSellAsset_v1 R1_optimalityOfBuyAsset_v1 R6a_externalOptimalityOfBuyAsset R5a_externalOptimalityOfSellAsset Submitted link certora/gsm/conf/gsm/optimality.conf-a32649e97cdd.log

Certora Run Summary

  • Started 19 jobs
  • 0 jobs failed

Download Logs

@certora-run certora-run Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

@github-actions

github-actions Bot commented Aug 3, 2026

Copy link
Copy Markdown

Certora Run Started (Certora Prover Run)

  • Group ID: afafce4b-dc5b-4df0-81db-6f45dce67139
Config Status Link Log File
balances-buy-4626.conf Submitted link certora/gsm/conf/gsm4626/balances-buy-4626.conf-bc9d62781fe7.log
balances-sell-4626.conf --rule R1_getAssetAmountForSellAsset_arg_vs_return R1a_buyGhoUpdatesGhoBalanceCorrectly1 R2_getAssetAmountForSellAsset_sellAsset_eq --prover_args "-copyLoopUnroll 6 -destructiveOptimizations twostage-checked" Submitted link certora/gsm/conf/gsm4626/balances-sell-4626.conf-a4d34e59385b.log
balances-sell-4626.conf --rule R3a_sellAssetUpdatesAssetBalanceCorrectly Submitted link certora/gsm/conf/gsm4626/balances-sell-4626.conf-f6fad24c5af1.log
balances-sell-4626.conf --rule R4_buyGhoUpdatesGhoBalanceCorrectly Submitted link certora/gsm/conf/gsm4626/balances-sell-4626.conf-1b1105a1ef53.log
balances-sell-4626.conf --rule R4a_buyGhoAmountGtGhoBalanceChange Submitted link certora/gsm/conf/gsm4626/balances-sell-4626.conf-4888a530619b.log
fees-buy-4626.conf Submitted link certora/gsm/conf/gsm4626/fees-buy-4626.conf-6750c07c933b.log
fees-sell-4626.conf --rule R3a_estimatedSellFeeCanBeLowerThanActualSellFee R2_getAssetAmountForSellAssetVsActualSellFee R4a_getSellFeeVsgetAssetAmountForSellAsset R4_getSellFeeVsgetAssetAmountForSellAsset R1a_getAssetAmountForSellAssetFeeNeGetSellFee R2a_getAssetAmountForSellAssetNeActualSellFee R4b_getSellFeeVsgetAssetAmountForSellAsset R1_getAssetAmountForSellAssetFeeGeGetSellFee R3b_estimatedSellFeeEqActualSellFee Submitted link certora/gsm/conf/gsm4626/fees-sell-4626.conf-c3ddfc74d3ff.log
finishedRules-4626.conf --rule cantBuyOrSellWhenSeized cantBuyOrSellWhenFrozen sellAssetIncreasesExposure buyAssetDecreasesExposure rescuingAssetKeepsAccruedFees rescuingGhoKeepsAccruedFees giftingGhoDoesntAffectStorageSIMPLE correctnessOfBuyAsset giftingUnderlyingDoesntAffectStorageSIMPLE sellAssetSameAsGetGhoAmountForSellAsset correctnessOfSellAsset giftingGhoDoesntCreateExcessOrDearth backWithGhoDoesntCreateExcess getAssetAmountForSellAsset_correctness collectedSellFeeIsAtLeastAsRequired collectedBuyFeePlus2IsAtLeastAsRequired collectedBuyFeePlus1IsAtLeastAsRequired collectedBuyFeeIsAtLeastAsRequired sellingDoesntExceedExposureCap whoCanChangeAccruedFees whoCanChangeExposure Submitted link certora/gsm/conf/gsm4626/finishedRules-4626.conf-d31434fe6ae8.log
finishedRules-4626.conf --rule giftingUnderlyingDoesntCreateExcessOrDearth Submitted link certora/gsm/conf/gsm4626/finishedRules-4626.conf-9363568c4470.log
getAmount-properties-4626.conf --rule getAssetAmountForBuyAsset_correctness_bound1 getAssetAmountForBuyAsset_correctness_bound2 getGhoAmountForBuyAsset_correctness_bound1 getAssetAmountForSellAsset_correctness getAssetAmountForBuyAsset_optimality getAssetAmountForBuyAsset_correctness Submitted link certora/gsm/conf/gsm4626/getAmount-properties-4626.conf-322bb4343689.log
getAmount-properties-4626.conf --rule getAssetAmountForSellAsset_optimality getAssetAmountForBuyAsset_funcProperty --prover_args "-destructiveOptimizations twostage-checked" Submitted link certora/gsm/conf/gsm4626/getAmount-properties-4626.conf-f68d146d871c.log
getAmount-properties-4626.conf --rule getGhoAmountForBuyAsset_correctness Submitted link certora/gsm/conf/gsm4626/getAmount-properties-4626.conf-1fc54b369c60.log
getAmount-properties-4626.conf --rule getGhoAmountForBuyAsset_optimality Submitted link certora/gsm/conf/gsm4626/getAmount-properties-4626.conf-7ff7772c4a7f.log
gho-assetToGhoInvertibility-4626.conf --rule buyAssetInverse_all Submitted link certora/gsm/conf/gsm4626/gho-assetToGhoInvertibility-4626.conf-4617e318af04.log
gho-assetToGhoInvertibility-4626.conf --rule sellAssetInverse_all Submitted link certora/gsm/conf/gsm4626/gho-assetToGhoInvertibility-4626.conf-cb1c15920fb6.log
gho-fixedPriceStrategy4626.conf Submitted link certora/gsm/conf/gsm4626/gho-fixedPriceStrategy4626.conf-889d360165cd.log
gho-gsm4626-1.conf Submitted link certora/gsm/conf/gsm4626/gho-gsm4626-1.conf-5b60fdc23fa8.log
gho-gsm4626-2.conf --rule accruedFeesLEGhoBalanceOfThis Submitted link certora/gsm/conf/gsm4626/gho-gsm4626-2.conf-d5e1cfa93b8e.log
gho-gsm4626-2.conf --rule accruedFeesNeverDecrease Submitted link certora/gsm/conf/gsm4626/gho-gsm4626-2.conf-0f617adbbb0e.log
gho-gsm4626-inverse.conf --rule buySellInverse27 buySellInverse26 buySellInverse25 buySellInverse24 buySellInverse23 buySellInverse22 buySellInverse21 buySellInverse20 buySellInverse19 Submitted link certora/gsm/conf/gsm4626/gho-gsm4626-inverse.conf-18bca898893d.log
optimality4626.conf --rule R1_optimalityOfBuyAsset_v1 Submitted link certora/gsm/conf/gsm4626/optimality4626.conf-7cc07ecbcd9a.log
optimality4626.conf --rule R3_optimalityOfSellAsset_v1 Submitted link certora/gsm/conf/gsm4626/optimality4626.conf-c39ebb3172e4.log
optimality4626.conf --rule R5a_externalOptimalityOfSellAsset R6a_externalOptimalityOfBuyAsset Submitted link certora/gsm/conf/gsm4626/optimality4626.conf-bee118d871a8.log

Certora Run Summary

  • Started 23 jobs
  • 0 jobs failed

Download Logs

@certora-run certora-run Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Certora Prover Run

  • Group ID: afafce4b-dc5b-4df0-81db-6f45dce67139
  • Commit: 49bf400
JobResultKILLEDTIMEOUTVERIFIED
set R1a_getAssetAmountForSellAssetFeeNeGet…0010
getAmount-properties-4626.conf --rule getA…
11 rerun(s) Default evm — ❌
Depth 0 — ❌
Underapproximation — ❌
Nonlin depth 0 — ❌
Nonlin — ❌
Depth between 4,10 — ✅
Z3 random seeds — ❌
Parallel splitter — ❌
Nonlin depth 0 with Z3 random seeds — ❌
deep — ❌
Autoconfig — ❌
✅ (status from rerun)003
gho-assetToGhoInvertibility-4626.conf --ru…
11 rerun(s) Default evm — ❌
Depth 0 — ❌
Underapproximation — ❌
Nonlin depth 0 — ❌
Nonlin — ❌
Depth between 4,10 — ❌
Z3 random seeds — ✅
Parallel splitter — ❌
Nonlin depth 0 with Z3 random seeds — ❌
deep — ❌
Autoconfig — ✅
✅ (status from rerun)002
orrectness_bound1 getAssetAmountForBuyAsse…007
optimality4626.conf --rule R5a_externalOpt…003
optimality4626.conf --rule R3_optimalityOf…002
optimality4626.conf --rule R1_optimalityOf…002
gho-gsm4626-inverse.conf --rule buySellInv…0010
gho-gsm4626-2.conf --rule accruedFeesNever…002
gho-gsm4626-2.conf --rule accruedFeesLEGho…002
gho-gsm4626-1.conf004
gho-fixedPriceStrategy4626.conf005
gho-assetToGhoInvertibility-4626.conf --ru…002
getAmount-properties-4626.conf --rule getG…002
getAmount-properties-4626.conf --rule getG…002
finishedRules-4626.conf --rule giftingUnde…002
fees-buy-4626.conf008
edSellFeeIsAtLeastAsRequired collectedBuyF…0022
balances-sell-4626.conf --rule R4_buyGhoUp…002
balances-sell-4626.conf --rule R4a_buyGhoA…002
balances-sell-4626.conf --rule R3a_sellAss…002
balances-sell-4626.conf --rule R1_getAsset…004
balances-buy-4626.conf008

Comment thread .github/workflows/certora-gsm-4626.yml Outdated
certora/gsm/conf/gsm4626/gho-assetToGhoInvertibility-4626.conf
# One rule per line: both are heavy enough that running them together times out.
certora/gsm/conf/gsm4626/gho-assetToGhoInvertibility-4626.conf --rule buyAssetInverse_all
certora/gsm/conf/gsm4626/gho-assetToGhoInvertibility-4626.conf --rule sellAssetInverse_all

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

are you sure we cover everything in the spec file for this conf? that's why we sometimes do --rule R and then --exclude_rule R

@avniculae avniculae Aug 4, 2026

Copy link
Copy Markdown
Collaborator Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Good catch — you were right that enumerating rules with --rule is fragile: add a third rule to that spec and it would silently never run with CI still green.

In the end the split went away entirely rather than being converted to --exclude_rule. The timeout that made me split it was fixable with the z3 seed race (see follow-up below), so the workflow is back to a single bare gho-assetToGhoInvertibility-4626.conf line with no rule enumeration at all.

Worth knowing this conf had never run in any workflow: its files list was missing GhoReserve.sol that methods4626_base.spec needs, so it failed typechecking.

(Edited: originally said I had excluded sellAssetInverse_all and asked for a ticket number to reference it. Both no longer apply — nothing is excluded and no ticket is needed.)

Copy link
Copy Markdown
Collaborator Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Update — I was wrong to exclude sellAssetInverse_all, and the fix was your own trick sitting in four sibling confs.

The assert is provable; it was just landing near the timeout. Adding the z3 random-seed race that balances-buy, fees-buy, fees-buy-4626 and optimality4626 already use:

before after
sellAssetInverse_all alone TIMEOUT at 119m (5 of 6 asserts) verified, 3m, 6 asserts
whole conf, both rules 67m verified, 5m, 11 asserts

So no rule is dropped, no ticket needed, and I've put the flag in the conf's prover_args rather than on the workflow line — both because that's where the other four keep it, and because a --prover_args on the line would replace the conf's array rather than add to it.

That also removes the thing you flagged: with the conf fast again there's no reason to split at all, so the workflow is back to a single bare gho-assetToGhoInvertibility-4626.conf line with no rule enumeration to go stale.

What led me astray was treating one unlucky 119m run as evidence the rule couldn't converge. Ignore the earlier ticket-number request.

…the timing-out rule

Two --rule lines enumerate the spec's rules, so a rule added later would silently
never run while CI stayed green. --exclude_rule is a partition and picks new rules
up automatically, matching how gho-gsm-2.conf and fees-sell.conf are split here.

sellAssetInverse_all times out on Assert_asset_amount (119m locally, one assert of
six) and only reported green through the rerun ladder, with a different winning
strategy each run. Commented out pending a ticket rather than left masked.
@github-actions

github-actions Bot commented Aug 4, 2026

Copy link
Copy Markdown

Certora Run Started (Certora Prover Run)

  • Group ID: 0e19bf8b-95b3-4920-ac2d-5ff6794d3d56
Config Status Link Log File
balances-buy-4626.conf Submitted link certora/gsm/conf/gsm4626/balances-buy-4626.conf-f64dc4021122.log
balances-sell-4626.conf --rule R1_getAssetAmountForSellAsset_arg_vs_return R1a_buyGhoUpdatesGhoBalanceCorrectly1 R2_getAssetAmountForSellAsset_sellAsset_eq --prover_args "-copyLoopUnroll 6 -destructiveOptimizations twostage-checked" Submitted link certora/gsm/conf/gsm4626/balances-sell-4626.conf-11ea2020e72c.log
balances-sell-4626.conf --rule R3a_sellAssetUpdatesAssetBalanceCorrectly Submitted link certora/gsm/conf/gsm4626/balances-sell-4626.conf-5252d0d21f41.log
balances-sell-4626.conf --rule R4_buyGhoUpdatesGhoBalanceCorrectly Submitted link certora/gsm/conf/gsm4626/balances-sell-4626.conf-1f00fa4b0052.log
balances-sell-4626.conf --rule R4a_buyGhoAmountGtGhoBalanceChange Submitted link certora/gsm/conf/gsm4626/balances-sell-4626.conf-e7296747814d.log
fees-buy-4626.conf Submitted link certora/gsm/conf/gsm4626/fees-buy-4626.conf-c838b6e6cd92.log
fees-sell-4626.conf --rule R3a_estimatedSellFeeCanBeLowerThanActualSellFee R2_getAssetAmountForSellAssetVsActualSellFee R4a_getSellFeeVsgetAssetAmountForSellAsset R4_getSellFeeVsgetAssetAmountForSellAsset R1a_getAssetAmountForSellAssetFeeNeGetSellFee R2a_getAssetAmountForSellAssetNeActualSellFee R4b_getSellFeeVsgetAssetAmountForSellAsset R1_getAssetAmountForSellAssetFeeGeGetSellFee R3b_estimatedSellFeeEqActualSellFee Submitted link certora/gsm/conf/gsm4626/fees-sell-4626.conf-23198f62c3ee.log
finishedRules-4626.conf --rule cantBuyOrSellWhenSeized cantBuyOrSellWhenFrozen sellAssetIncreasesExposure buyAssetDecreasesExposure rescuingAssetKeepsAccruedFees rescuingGhoKeepsAccruedFees giftingGhoDoesntAffectStorageSIMPLE correctnessOfBuyAsset giftingUnderlyingDoesntAffectStorageSIMPLE sellAssetSameAsGetGhoAmountForSellAsset correctnessOfSellAsset giftingGhoDoesntCreateExcessOrDearth backWithGhoDoesntCreateExcess getAssetAmountForSellAsset_correctness collectedSellFeeIsAtLeastAsRequired collectedBuyFeePlus2IsAtLeastAsRequired collectedBuyFeePlus1IsAtLeastAsRequired collectedBuyFeeIsAtLeastAsRequired sellingDoesntExceedExposureCap whoCanChangeAccruedFees whoCanChangeExposure Submitted link certora/gsm/conf/gsm4626/finishedRules-4626.conf-c5b1832b8fc0.log
finishedRules-4626.conf --rule giftingUnderlyingDoesntCreateExcessOrDearth Submitted link certora/gsm/conf/gsm4626/finishedRules-4626.conf-4665e26d317a.log
getAmount-properties-4626.conf --rule getAssetAmountForBuyAsset_correctness_bound1 getAssetAmountForBuyAsset_correctness_bound2 getGhoAmountForBuyAsset_correctness_bound1 getAssetAmountForSellAsset_correctness getAssetAmountForBuyAsset_optimality getAssetAmountForBuyAsset_correctness Submitted link certora/gsm/conf/gsm4626/getAmount-properties-4626.conf-bed075504de0.log
getAmount-properties-4626.conf --rule getAssetAmountForSellAsset_optimality getAssetAmountForBuyAsset_funcProperty --prover_args "-destructiveOptimizations twostage-checked" Submitted link certora/gsm/conf/gsm4626/getAmount-properties-4626.conf-d301ecd7de03.log
getAmount-properties-4626.conf --rule getGhoAmountForBuyAsset_correctness Submitted link certora/gsm/conf/gsm4626/getAmount-properties-4626.conf-71ecc1c58301.log
getAmount-properties-4626.conf --rule getGhoAmountForBuyAsset_optimality Submitted link certora/gsm/conf/gsm4626/getAmount-properties-4626.conf-a8a4582da1a2.log
gho-assetToGhoInvertibility-4626.conf --exclude_rule sellAssetInverse_all Submitted link certora/gsm/conf/gsm4626/gho-assetToGhoInvertibility-4626.conf-1fad080628d1.log
gho-fixedPriceStrategy4626.conf Submitted link certora/gsm/conf/gsm4626/gho-fixedPriceStrategy4626.conf-638358017098.log
gho-gsm4626-1.conf Submitted link certora/gsm/conf/gsm4626/gho-gsm4626-1.conf-7174c6d025e4.log
gho-gsm4626-2.conf --rule accruedFeesLEGhoBalanceOfThis Submitted link certora/gsm/conf/gsm4626/gho-gsm4626-2.conf-2195008852e9.log
gho-gsm4626-2.conf --rule accruedFeesNeverDecrease Submitted link certora/gsm/conf/gsm4626/gho-gsm4626-2.conf-992248598562.log
gho-gsm4626-inverse.conf --rule buySellInverse27 buySellInverse26 buySellInverse25 buySellInverse24 buySellInverse23 buySellInverse22 buySellInverse21 buySellInverse20 buySellInverse19 Submitted link certora/gsm/conf/gsm4626/gho-gsm4626-inverse.conf-c945dfe4530e.log
optimality4626.conf --rule R1_optimalityOfBuyAsset_v1 Submitted link certora/gsm/conf/gsm4626/optimality4626.conf-6e9e2c0c1676.log
optimality4626.conf --rule R3_optimalityOfSellAsset_v1 Submitted link certora/gsm/conf/gsm4626/optimality4626.conf-a0ebb9d8712b.log
optimality4626.conf --rule R5a_externalOptimalityOfSellAsset R6a_externalOptimalityOfBuyAsset Submitted link certora/gsm/conf/gsm4626/optimality4626.conf-51ce4d64f8eb.log

Certora Run Summary

  • Started 22 jobs
  • 0 jobs failed

Download Logs

@certora-run certora-run Bot left a comment

Copy link
Copy Markdown

@avniculae

avniculae commented Aug 4, 2026

Copy link
Copy Markdown
Collaborator Author

@shellygr one more thing on auto-rerun-timeouts, separate from the invertibility rule and untouched by this PR.

getAmount-properties-4626.conf --rule getAssetAmountForSellAsset_optimality getAssetAmountForBuyAsset_funcProperty has reported green through the rerun ladder on two of the five runs here, and cleanly on the other three:

commit result
9a0e396 clean
d0ca89b clean
49bf400 status from rerun, 11 rerun(s)
393c4f0 clean
ef88a55 status from rerun, 11 rerun(s)

Same flavour as balances-sell-4626 --rule R1/R1a/R2, which was clean here at 9a0e396 but needed 11 reruns for that same commit on Certora#9.

Is that expected variance, or are these confs close enough to the timeout that the ladder is doing real work? It matters because when the rerun fires, the configuration that verified isn't the one in the repo, and the winning strategy has differed every time I've looked.

For what it's worth, the z3 seed race fixed exactly this shape of problem on gho-assetToGhoInvertibility-4626 (119m timeout -> 3m), so it may be worth trying here too. Happy to test it if you'd like, or leave it to you.

…ad of dropping a rule

sellAssetInverse_all was timing out on its asset_amount assert and only reaching
green through the rerun ladder, and I had excluded it. That was wrong: the assert
is provable, it was just landing near the timeout. Adding the same z3 random-seed
race already used by balances-buy, fees-buy, fees-buy-4626 and optimality4626
takes the rule from a 119m timeout to 3m, and the whole conf from 67m to 5m for
all 11 asserts.

With the conf fast again the workflow needs no rule splitting at all, so the
--rule/--exclude_rule enumeration goes away entirely. Keeping the flag in the
conf rather than on the workflow line also avoids the CLI prover_args override
replacing the conf's array.
@avniculae
avniculae marked this pull request as ready for review August 4, 2026 12:37
@avniculae avniculae changed the title certora: fix prover timeouts, spec cleanup, unpin R4 certora: fix prover timeouts and spec cleanup Aug 4, 2026
Comment thread .github/workflows/certora-gsm-4626.yml Outdated
Comment on lines +35 to +36
# NB: a `--prover_args` here REPLACES the conf's `prover_args` array, it does not
# append to it. Restate every flag the run needs, not just the one being added.

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

do we need this comment here?

Copy link
Copy Markdown
Collaborator Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Dropped in d63123f, from both workflows that had it.

Comment thread .github/workflows/certora-gsm-4626.yml Outdated
submodules: recursive

- uses: Certora/certora-run-action@v2
- uses: Certora/certora-run-action@v2.10.0

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

we've been pinning by hash usually bc this can be updated as well but nbd this is fine also

Copy link
Copy Markdown
Collaborator Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pinned by SHA across all four workflows in d63123f.

is_in_facilitator_set_array(facilitator) <=> is_in_facilitator_set_map(facilitator)
{preserved{
requireInvariant addressSetInvariant_2();
requireInvariant length_leq_max_uint160();

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

why do we not need this anymore?

Copy link
Copy Markdown
Collaborator Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

set.spec:109 has axiom to_mathint(mirrorArrayLen) < TWO_TO_160() - 1 unconditionally, and the array-length Sload hook forces mirrorArrayLen == len, so the bound already holds without the requireInvariant.

The invariant itself was vacuous — its own docstring said so, "the proof of the assumption is vacuous because length > loop_iter" — so it went along with its five uses. verifyGhoToken went 29 -> 28 rules, just that one.

Comment on lines +44 to +45
// Same value as mulDivRounding, written as the single closed form (x*y+d-1)/d for Ceil.
// The optimality proofs reason about this closed form far better than the reuse-floor form.

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

very interesting, curious if it's bc of the consecutive random number gen (seed)

need to look into how that z3 rand works bc if it's deterministic then symbolically we're not checking all cases and instead adding a restriction correlation

Copy link
Copy Markdown
Collaborator Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

what do you mean here? what cases are we leaving out here?

Tags are mutable, so pin the action by SHA across all four workflows.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants