TON PRIMES — audit pack

Twenty-two documents, in reading order. Everything here is published deliberately: webapp/vite.config.ts's publishDocs() names each file, and nothing reaches primes.live/docs/audit/ that is not on that list. The repo holds further working notes that are not part of this pack — regenerated churn reports, internal design drafts and dated run logs — and they are not published, not because they are secret but because nothing in them is an auditor's business.

Status: pre-launch. Testnet only. No mainnet deployment, no real money, no third-party integration. CONCEPT.md is the specification the contracts are written against; where a document here and CONCEPT.md disagree, CONCEPT.md wins and the disagreement is a bug.

Several of these are regenerated from HEAD by a script, not written by hand — those say so in their own first lines, and the script is named there. A regenerated document cannot drift from the code without the generator being wrong, which is the point of generating it.

Start here

documentwhat it answers
scope.mdWhat is in the audited boundary and what is deliberately outside it. Read first; every other document assumes this boundary.
threat-model.mdEvery actor — attacker, operator, keeper, bug — what each can do, and what stops it.
known-limitations.mdWhat is not done, not proven, or accepted as a risk on purpose. The document most likely to change.

What is proven, and by what

documentwhat it answers
invariant-coverage.mdWhich must-never-break invariants have a named test proving them — and which do not.
test-coverage-map.mdThe full test inventory behind the line above. Regenerated.
contract-surface.mdEvery contract's get-methods and message opcodes. Regenerated from HEAD.
wire-format.mdThe message layouts those opcodes carry. Regenerated from HEAD.

The economics

documentwhat it answers
parameter-provenance.mdWhere each economic constant comes from. A number traceable to neither the simulation nor CONCEPT.md is a bug.
genesis-emission-curve.mdThe genesis emission schedule and the simulation run that produced it.
stat-provenance.mdEvery figure the app displays, mapped to the get-method it is read from (CONCEPT.md §9.1).
money-arithmetic.mdRounding, truncation and dust across every place the contracts divide TON.

Where money can move

documentwhat it answers
withdraw-surface.mdEvery outbound-message site in every contract, classified by destination. TON leaves a contract only through these, so "no admin withdraw path" is a property of this set.
sender-gates.mdWho each privileged handler will accept a message from.
bounce-coverage.mdWhat happens to the money when a message bounces or a standard protocol reply comes home.
privileged-credentials.mdThe three standing credentials that do exist, each one's powers, limits and bounding test. None can move a TON balance.
key-loss.mdThe failure half of the page above: what stops working the day each credential is lost, and which cannot be replaced without a genesis redeploy.

Building and running it

documentwhat it answers
reproducible-build.mdThe pinned toolchain, the build procedure, and the code hash each contract compiles to.
build-and-test.mdHow to build the repo and run every suite, from a cold clone.
deployment-story.mdWhat genesis actually does, in order, and which key can do what at each step.
index-rebuild.mdThe recovery path for the day the backups are gone — measured, from an empty database.
repo-hygiene.mdSecrets posture, tracked build artifacts, dependency audit.
nft-metadata-conformance.mdTEP-64 conformance of the metadata served for every minted number.

Elsewhere