QiLOL / morpho-blue-fuzzing

Morpho Blue Protocol | Fuzzing setup using Recon

Geek Repo:Geek Repo

Github PK Tool:Github PK Tool

Morpho Blue fuzzing setup using Recon

Goal:
Create an example repo from an existing codebase for fuzzing with Medusa/Echidna using Recon.

Steps:

  1. Forked the Morpho Blue codebase at the state of the Cantina competition.
  2. Added Recon-Fuzz/chimera and Recon generated boilerplate contracts.
  3. Implemented setup routine for Morpho contract and restrained TargetMethods for fuzzing.
  4. Implemented a simple example property that "breaks" once medusa fuzz has found a way to supply collateral tokens, supply loan tokens and successfully borrow them.
  5. Implemented an assertion test that fails once Medusa finds a case where no interest was accrued although interest should have been accrued for a market.

All the above steps and involved problems can be seen in the commit history.

Result:
Recon reduced the entry barrier for building a fuzzing test and the example property and assertion test were sucessfully broken.
This serves as a basis for more advanced fuzzing tests.


Morpho Blue

Morpho Blue is a noncustodial lending protocol implemented for the Ethereum Virtual Machine. Morpho Blue offers a new trustless primitive with increased efficiency and flexibility compared to existing lending platforms. It provides permissionless risk management and permissionless market creation with oracle agnostic pricing. It also enables higher collateralization factors, improved interest rates, and lower gas consumption. The protocol is designed to be a simple, immutable, and governance-minimized base layer that allows for a wide variety of other layers to be built on top. Morpho Blue also offers a convenient developer experience with a singleton implementation, callbacks, free flash loans, and account management features.

Whitepaper

The protocol is described in detail in the Morpho Blue Whitepaper.

Repository Structure

Morpho.sol contains most of the source code of the core contract of Morpho Blue. It solely relies on internal libraries in the src/libraries subdirectory.

Libraries in the src/libraries/periphery directory are not used by Morpho Blue. They are useful helpers that integrators can reuse or adapt to their own needs.

The src/mocks directory contains contracts designed exclusively for testing.

You'll find relevant comments in IMorpho.sol, notably a list of requirements about market dependencies.

Getting Started

Install dependencies: yarn

Run forge tests: yarn test:forge

Run hardhat tests: yarn test:hardhat

You will find other useful commands in the package.json file.

Audits

All audits are stored in the audits' folder.

Licences

The primary license for Morpho Blue is the Business Source License 1.1 (BUSL-1.1), see LICENSE. However, all files in the following folders can also be licensed under GPL-2.0-or-later (as indicated in their SPDX headers): src/interfaces, src/libraries, src/mocks, test.

About

Morpho Blue Protocol | Fuzzing setup using Recon

License:Other


Languages

Language:Solidity 96.4%Language:TypeScript 3.5%Language:Shell 0.1%