Proof
Every claim, the command that reproduces it, the file that holds the evidence, and what it does not show. A claim without evidence says so.
Fork suite
18 passed, 0 failed on a BSC mainnet fork. Log: evidence/fork/forge_test_full.txt.
Discovery snapshot covers 30 wrappers over 10 tickers; recorder cycles at snapshot: 225.
Claims ledger
- C1SUPPORTED
Each of the measured tickers has a bStocks, an Ondo and an xStocks wrapper on BSC with a verified address.
$ pnpm discover
evidence: data/discovery/e1_wrapper_map.json
Limits: Addresses come from a third-party catalogue and are verified on-chain by symbol and decimals; issuer-published lists were not available.
- C2SUPPORTED
The three issuers expose the unit differently: a scaled multiplier on the token (bStocks), a separate oracle (Ondo), a rebasing balance (xStocks).
$ node scripts/discovery/e2_unit_factors.mjs
evidence: data/discovery/e2_unit_factors.json, data/discovery/src
Limits: That one xStocks balance unit equals one share follows issuer documentation and is not confirmed by price because the pools are thin.
- C3SUPPORTED
The API reports a different multiplier from the token itself for some xStocks.
$ node scripts/discovery/e3_reference_and_units.mjs
evidence: data/discovery/e3_reference_and_units.json
Limits: Point-in-time snapshot; the count changes as multipliers update.
- C4SUPPORTED
bStocks have no equity reference price in the public per-token response.
$ node scripts/discovery/e3_reference_and_units.mjs
evidence: data/discovery/e3_reference_and_units.json
Limits: Public keyless endpoints only; a keyed endpoint may expose more.
- C5SUPPORTED
Ondo and xStocks pools on BNB Chain are far thinner than bStocks pools.
$ node scripts/discovery/e11_pools.mjs
evidence: data/discovery/e11_pools.json, data/discovery/summary.json
Limits: Liquidity as reported by a public pool indexer at snapshot time.
- C6PARTIAL
A contract can receive the tested wrappers.
$ node scripts/discovery/e7_contract_receive.mjs
evidence: data/discovery/e7_contract_receive.json
Limits: eth_call simulation from a pool holder; wrappers with no holder are unknown. The fork suite fills into the book for one wrapper.
- C7SUPPORTED
TareBook reverts a buy that delivers fewer share-equivalents than the signed floor.
$ cd contracts && forge test --match-test test_shareFloorRevert
evidence: evidence/fork/forge_test_full.txt
Limits: BSC mainnet fork, public RPC, one wrapper family in the fuzz suite.
- C8SUPPORTED
TareBook reverts a sale that pays less than the signed USDT per share.
$ cd contracts && forge test --match-test test_sellFloorRevert
evidence: evidence/fork/forge_test_full.txt
Limits: BSC mainnet fork.
- C9SUPPORTED
A token-denominated order fills wrong after a unit change; the share-denominated order reverts.
$ cd contracts && forge test --match-test test_unitJump
evidence: evidence/fork/forge_test_full.txt
Limits: Unit change simulated by writing the multiplier storage slot on a fork.
- C10SUPPORTED
The keeper filled standing orders (two buys, one sell) on BSC mainnet while the owner wallet sent nothing and New York was closed.
$ npx tsx scripts/autonomy.ts
evidence: data/autonomy/summary.json, data/autonomy/placement.json, data/keeper/journal.jsonl, evidence/mainnet/verify_order_0.txt, evidence/mainnet/verify_order_1.txt, evidence/mainnet/verify_order_2.txt
Limits: The keeper ran on the author machine, not a hosted worker. Three fills, cents in size, one ticker, one wrapper (bStocks).
- C11PARTIAL
On direct pools the share-aware pick equals the cheapest-token pick and beats a random wrapper; with the aggregator, the two picks differ in a minority of cases by a few basis points.
$ npx tsx scripts/counterfactual.ts && npx tsx scripts/counterfactual_aggregator.ts
evidence: data/counterfactual/summary.json, data/counterfactual/aggregator_snapshot.json
Limits: Short recorder window over one weekend; small samples; the pick matters less than the guarantee.
- C12PARTIAL
Some quotes are more than 5 percent from the equity reference, and more often outside the regular session.
$ node scripts/discovery/e12_broken_quotes.mjs
evidence: data/discovery/e12_broken_quotes.json
Limits: Direct-pool quotes and public API prices only; recorder window is short.
- C13SUPPORTED
The keeper holds an ERC-8004 identity on BSC mainnet.
$ node -e "see evidence/mainnet/identity.json"
evidence: evidence/mainnet/identity.json
Limits: Registration only; reputation feedback is empty.
- C14PARTIAL
An ERC-8183 certificate job reached the Submitted state on BSC mainnet at price zero.
$ npx tsx services/agent/src/job.ts
evidence: evidence/mainnet/erc8183_job.json
Limits: The policy dispute window is seven days, so settlement cannot complete before the submission deadline. Not claimed as completed.
- C15SUPPORTED
The Trading API returns executable swap calldata with the book as taker for bStocks and for Ondo wrappers, and a standing order was filled on BSC mainnet through that route; xStocks return no liquidity.
$ npx tsx scripts/discovery/e6_keyed.ts
evidence: data/discovery/e6_contract_taker.json, data/discovery/e6_swap_build.json, evidence/mainnet/verify_order_5.txt
Limits: Ondo quotes enforce a 5 USD minimum order, so the mainnet fill used a bStocks wrapper; Ondo calldata was built, not sent. Documentation says Ondo is RFQ only.
- C16SUPPORTED
A paid certificate call settled through B402 (x402 V2) on BSC mainnet.
$ npx tsx scripts/mainnet/paid_certificate.ts
evidence: evidence/mainnet/paid_certificate.json, data/discovery/b402_supported.json
Limits: The pay-to address fixed at onboarding is the owner test wallet, so the call proves the loop and the settlement, not revenue to the keeper. Price is 0.01 of the facilitator payment token.
- C17SUPPORTED
The web app works end to end with a connected wallet: buy now, standing buy filled by the keeper, standing sell, cancel, holdings.
$ cd apps/web && BASE_URL=https://tare-olive.vercel.app npx playwright test journey.spec.ts --project=desktop
evidence: apps/web/e2e/journey.spec.ts, evidence/mainnet/verify_order_5.txt
Limits: The test signs with the owner test wallet through an injected provider bridge in headless Chromium; mainnet transactions of cents.
- C18SUPPORTED
A standing order was placed through the Binance Agentic Wallet on BSC mainnet and filled by the keeper.
$ baw contract-call preview/execute with the calls from POST /api/plan
evidence: evidence/mainnet/agentic_wallet.json, evidence/mainnet/verify_order_7.txt
Limits: The Agentic Wallet is a separate address from the owner test wallet; cents in size.
- C19SUPPORTED
The keeper runs on a hosted service (Render, Singapore) and the web app reads its live status.
$ curl https://tare-keeper.onrender.com/api/agent/keeper ; curl https://tare-olive.vercel.app/api/agent/keeper (source: live)
evidence: data/keeper/hosted_status.json, render.yaml, .github/workflows/keepalive.yml
Limits: Free plan; kept awake by a self-ping and a scheduled workflow. The mainnet autonomy run (C11) predates the hosted deployment.
Invariants and where each is checked
| ID | Invariant | Checked by |
|---|---|---|
| T1 | Unit normalisation | packages/kernel/test, contracts TareBook._fillBuy |
| T2 | Share floor (buy) | test_shareFloorRevert, invariant_floorAndExactlyOnce |
| T2b | Sell floor | test_sellFloorRevert |
| T3 | Live unit | test_keeperCannotPassUnit |
| T4 | Corporate-action freeze | test_corporatePauseBStock, test_corporatePauseOndoOracle |
| T5 | Allowlist | test_unlistedRouter, test_wrongWrapper |
| T6 | No custody | testFuzz_noResidual, invariant_bookHoldsNothing |
| T7 | Recipient lock | test_maliciousRecipient |
| T8 | Exactly once | test_replay |
| T9 | Simulate before send | services/keeper journal |
| T10 | Stale is labelled | packages/kernel/test (T10) |
| T11 | Decomposition closure | packages/kernel/test, packages/verify/test |
| T12 | Degraded is distinct | packages/binance/test, packages/kernel/test |