{"sources":{"src/contracts/libraries/Errors.sol":{"content":"// SPDX-License-Identifier: MIT\npragma solidity ^0.8.0;\n\n/**\n * @title Errors library\n * @author BGD Labs\n * @notice Defines the error messages emitted by the different contracts of the Aave Governance V3\n */\nlibrary Errors {\n  string public constant VOTING_PORTALS_COUNT_NOT_0 = '1'; // to be able to rescue voting portals count must be 0\n  string public constant AT_LEAST_ONE_PAYLOAD = '2'; // to create a proposal, it must have at least one payload\n  string public constant VOTING_PORTAL_NOT_APPROVED = '3'; // the voting portal used to vote on proposal must be approved\n  string public constant PROPOSITION_POWER_IS_TOO_LOW = '4'; // proposition power of proposal creator must be equal or higher than the specified threshold for the access level\n  string public constant PROPOSAL_NOT_IN_CREATED_STATE = '5'; // proposal should be in the CREATED state\n  string public constant PROPOSAL_NOT_IN_ACTIVE_STATE = '6'; // proposal must be in an ACTIVE state\n  string public constant PROPOSAL_NOT_IN_QUEUED_STATE = '7'; // proposal must be in a QUEUED state\n  string public constant VOTING_START_COOLDOWN_PERIOD_NOT_PASSED = '8'; // to activate a proposal vote, the cool down delay must pass\n  string public constant CALLER_NOT_A_VALID_VOTING_PORTAL = '9'; // only an allowed voting portal can queue a proposal\n  string public constant QUEUE_COOLDOWN_PERIOD_NOT_PASSED = '10'; // to execute a proposal a cooldown delay must pass\n  string public constant PROPOSAL_NOT_IN_THE_CORRECT_STATE = '11'; // proposal must be created but not executed yet to be able to be canceled\n  string public constant CALLER_NOT_GOVERNANCE = '12'; // caller must be governance\n  string public constant VOTER_ALREADY_VOTED_ON_PROPOSAL = '13'; // voter can only vote once per proposal using voting portal\n  string public constant WRONG_MESSAGE_ORIGIN = '14'; // received message must come from registered source address, chain id, CrossChainController\n  string public constant NO_VOTING_ASSETS = '15'; // Strategy must have voting assets\n  string public constant PROPOSAL_VOTE_ALREADY_CREATED = '16'; // vote on proposal can only be created once\n  string public constant INVALID_SIGNATURE = '17'; // submitted signature is not valid\n  string public constant PROPOSAL_VOTE_NOT_FINISHED = '18'; // proposal vote must be finished\n  string public constant PROPOSAL_VOTE_NOT_IN_ACTIVE_STATE = '19'; // proposal vote must be in active state\n  string public constant PROPOSAL_VOTE_ALREADY_EXISTS = '20'; // proposal vote already exists\n  string public constant VOTE_ONCE_FOR_ASSET = '21'; // an asset can only be used once per vote\n  string public constant USER_BALANCE_DOES_NOT_EXISTS = '22'; // to vote an user must have balance in the token the user is voting with\n  string public constant USER_VOTING_BALANCE_IS_ZERO = '23'; // to vote an user must have some balance between all the tokens selected for voting\n  string public constant MISSING_AAVE_ROOTS = '24'; // must have AAVE roots registered to use strategy\n  string public constant MISSING_STK_AAVE_ROOTS = '25'; // must have stkAAVE roots registered to use strategy\n  string public constant MISSING_STK_AAVE_SLASHING_EXCHANGE_RATE = '26'; // must have stkAAVE slashing exchange rate registered to use strategy\n  string public constant UNPROCESSED_STORAGE_ROOT = '27'; // root must be registered beforehand\n  string public constant NOT_ENOUGH_MSG_VALUE = '28'; // method was not called with enough value to execute the call\n  string public constant FAILED_ACTION_EXECUTION = '29'; // action failed to execute\n  string public constant SHOULD_BE_AT_LEAST_ONE_EXECUTOR = '30'; // at least one executor is needed\n  string public constant INVALID_EMPTY_TARGETS = '31'; // target of the payload execution must not be empty\n  string public constant EXECUTOR_WAS_NOT_SPECIFIED_FOR_REQUESTED_ACCESS_LEVEL =\n    '32'; // payload executor must be registered for the specified payload access level\n  string public constant PAYLOAD_NOT_IN_QUEUED_STATE = '33'; // payload must be en the queued state\n  string public constant TIMELOCK_NOT_FINISHED = '34'; // delay has not passed before execution can be called\n  string public constant PAYLOAD_NOT_IN_THE_CORRECT_STATE = '35'; // payload must be created but not executed yet to be able to be canceled\n  string public constant PAYLOAD_NOT_IN_CREATED_STATE = '36'; // payload must be in the created state\n  string public constant MISSING_A_AAVE_ROOTS = '37'; // must have aAAVE roots registered to use strategy\n  string public constant MISSING_PROPOSAL_BLOCK_HASH = '38'; // block hash for this proposal was not bridged before\n  string public constant PROPOSAL_VOTE_CONFIGURATION_ALREADY_BRIDGED = '39'; // configuration for this proposal bridged already\n  string public constant INVALID_VOTING_PORTAL_ADDRESS = '40'; // voting portal address can't be 0x0\n  string public constant INVALID_POWER_STRATEGY = '41'; // 0x0 is not valid as the power strategy\n  string public constant INVALID_EXECUTOR_ADDRESS = '42'; // executor address can't be 0x0\n  string public constant EXECUTOR_ALREADY_SET_IN_DIFFERENT_LEVEL = '43'; // executor address already being used as executor of a different level\n  string public constant INVALID_VOTING_DURATION = '44'; // voting duration can not be bigger than the time it takes to execute a proposal\n  string public constant VOTING_DURATION_NOT_PASSED = '45'; // at least votingDuration should have passed since voting started for a proposal to be queued\n  string public constant INVALID_PROPOSAL_ACCESS_LEVEL = '46'; // the bridged proposal access level does not correspond with the maximum access level required by the payload\n  string public constant PAYLOAD_NOT_CREATED_BEFORE_PROPOSAL = '47'; // payload must be created before proposal\n  string public constant INVALID_CROSS_CHAIN_CONTROLLER_ADDRESS = '48';\n  string public constant INVALID_MESSAGE_ORIGINATOR_ADDRESS = '49';\n  string public constant INVALID_ORIGIN_CHAIN_ID = '50';\n  string public constant INVALID_ACTION_TARGET = '51';\n  string public constant INVALID_ACTION_ACCESS_LEVEL = '52';\n  string public constant INVALID_EXECUTOR_ACCESS_LEVEL = '53';\n  string public constant INVALID_VOTING_PORTAL_CROSS_CHAIN_CONTROLLER = '54';\n  string public constant INVALID_VOTING_PORTAL_VOTING_MACHINE = '55';\n  string public constant INVALID_VOTING_PORTAL_GOVERNANCE = '56';\n  string public constant INVALID_VOTING_MACHINE_CHAIN_ID = '57';\n  string public constant G_INVALID_CROSS_CHAIN_CONTROLLER_ADDRESS = '58';\n  string public constant G_INVALID_IPFS_HASH = '59';\n  string public constant G_INVALID_PAYLOAD_ACCESS_LEVEL = '60';\n  string public constant G_INVALID_PAYLOADS_CONTROLLER = '61';\n  string public constant G_INVALID_PAYLOAD_CHAIN = '62';\n  string public constant POWER_STRATEGY_HAS_NO_TOKENS = '63'; // power strategy should at least have\n  string public constant INVALID_VOTING_CONFIG_ACCESS_LEVEL = '64';\n  string public constant VOTING_DURATION_TOO_SMALL = '65';\n  string public constant NO_BRIDGED_VOTING_ASSETS = '66';\n  string public constant INVALID_VOTER = '67';\n  string public constant INVALID_DATA_WAREHOUSE = '68';\n  string public constant INVALID_VOTING_MACHINE_CROSS_CHAIN_CONTROLLER = '69';\n  string public constant INVALID_L1_VOTING_PORTAL = '70';\n  string public constant INVALID_VOTING_PORTAL_CHAIN_ID = '71';\n  string public constant INVALID_VOTING_STRATEGY = '72';\n  string public constant INVALID_VOTE_CONFIGURATION_BLOCKHASH = '73';\n  string public constant INVALID_VOTE_CONFIGURATION_VOTING_DURATION = '74';\n  string public constant INVALID_GAS_LIMIT = '75';\n  string public constant INVALID_VOTING_CONFIGS = '76'; // a lvl2 voting configuration must be sent to initializer\n  string public constant INVALID_EXECUTOR_DELAY = '77';\n  string public constant REPEATED_STRATEGY_ASSET = '78';\n  string public constant EMPTY_ASSET_STORAGE_SLOTS = '79';\n  string public constant REPEATED_STRATEGY_ASSET_SLOT = '80';\n  string public constant INVALID_EXECUTION_TARGET = '81';\n  string public constant MISSING_VOTING_CONFIGURATIONS = '82'; // voting configurations for lvl1 and lvl2 must be included on initialization\n  string public constant INVALID_PROPOSITION_POWER = '83';\n  string public constant INVALID_YES_THRESHOLD = '84';\n  string public constant INVALID_YES_NO_DIFFERENTIAL = '85';\n  string public constant ETH_TRANSFER_FAILED = '86';\n  string public constant INVALID_INITIAL_VOTING_CONFIGS = '87'; // initial voting configurations can not be of the same level\n  string public constant INVALID_VOTING_PORTAL_ADDRESS_IN_VOTING_MACHINE = '88';\n  string public constant INVALID_VOTING_PORTAL_OWNER = '89';\n  string public constant CANCELLATION_FEE_REDEEM_FAILED = '90'; // cancellation fee was not able to be redeemed\n  string public constant INVALID_CANCELLATION_FEE_COLLECTOR = '91'; // collector can not be address 0\n  string public constant INVALID_CANCELLATION_FEE_SENT = '92'; // cancellation fee sent does not match the needed amount\n  string public constant CANCELLATION_FEE_ALREADY_REDEEMED = '93'; // cancellation fee already redeemed\n  string public constant INVALID_STATE_TO_REDEEM_CANCELLATION_FEE = '94'; // proposal state is not a valid state to redeem cancellation fee\n  string public constant MISSING_REPRESENTATION_ROOTS = '95'; // to represent a voter the representation roots need to be registered\n  string public constant CALLER_IS_NOT_VOTER_REPRESENTATIVE = '96'; // to represent a voter, caller must be the stored representative\n  string public constant VM_INVALID_GOVERNANCE_ADDRESS = '97'; // governance address can not be 0\n  string public constant ALL_DELEGATION_ACTIONS_FAILED = '98'; // all meta delegation actions failed on MetaDelegateHelper\n}\n"},"src/contracts/payloads/PayloadsController.sol":{"content":"// SPDX-License-Identifier: BUSL-1.1\npragma solidity ^0.8.8;\n\nimport {PayloadsControllerCore, PayloadsControllerUtils} from './PayloadsControllerCore.sol';\nimport {IPayloadsController, IBaseReceiverPortal} from './interfaces/IPayloadsController.sol';\nimport {Errors} from '../libraries/Errors.sol';\n\n/**\n * @title PayloadsController\n * @author BGD Labs\n * @notice Contract with the logic to manage receiving cross chain messages. This contract knows how to receive and\n           decode messages from CrossChainController\n */\ncontract PayloadsController is PayloadsControllerCore, IPayloadsController {\n  /// @inheritdoc IPayloadsController\n  address public immutable MESSAGE_ORIGINATOR;\n\n  /// @inheritdoc IPayloadsController\n  address public immutable CROSS_CHAIN_CONTROLLER;\n\n  /// @inheritdoc IPayloadsController\n  uint256 public immutable ORIGIN_CHAIN_ID;\n\n  /**\n   * @param crossChainController address of the CrossChainController contract deployed on current chain. This contract\n            is the one responsible to send here the voting configurations once they are bridged.\n   * @param messageOriginator address of the contract where the message originates (mainnet governance)\n   * @param originChainId the id of the network where the messages originate from\n   */\n  constructor(\n    address crossChainController,\n    address messageOriginator,\n    uint256 originChainId\n  ) {\n    require(\n      crossChainController != address(0),\n      Errors.INVALID_CROSS_CHAIN_CONTROLLER_ADDRESS\n    );\n    require(\n      messageOriginator != address(0),\n      Errors.INVALID_MESSAGE_ORIGINATOR_ADDRESS\n    );\n    require(originChainId > 0, Errors.INVALID_ORIGIN_CHAIN_ID);\n\n    CROSS_CHAIN_CONTROLLER = crossChainController;\n    MESSAGE_ORIGINATOR = messageOriginator;\n    ORIGIN_CHAIN_ID = originChainId;\n  }\n\n  /// @inheritdoc IBaseReceiverPortal\n  function receiveCrossChainMessage(\n    address originSender,\n    uint256 originChainId,\n    bytes memory message\n  ) external {\n    require(\n      msg.sender == CROSS_CHAIN_CONTROLLER &&\n        originSender == MESSAGE_ORIGINATOR &&\n        originChainId == ORIGIN_CHAIN_ID,\n      Errors.WRONG_MESSAGE_ORIGIN\n    );\n\n    try this.decodeMessage(message) returns (\n      uint40 payloadId,\n      PayloadsControllerUtils.AccessControl accessLevel,\n      uint40 proposalVoteActivationTimestamp\n    ) {\n      _queuePayload(payloadId, accessLevel, proposalVoteActivationTimestamp);\n      bytes memory empty;\n      emit PayloadExecutionMessageReceived(\n        originSender,\n        originChainId,\n        true,\n        message,\n        empty\n      );\n    } catch (bytes memory decodingError) {\n      emit PayloadExecutionMessageReceived(\n        originSender,\n        originChainId,\n        false,\n        message,\n        decodingError\n      );\n    }\n  }\n\n  /// @inheritdoc IPayloadsController\n  function decodeMessage(\n    bytes memory message\n  )\n    external\n    pure\n    returns (uint40, PayloadsControllerUtils.AccessControl, uint40)\n  {\n    return\n      abi.decode(\n        message,\n        (uint40, PayloadsControllerUtils.AccessControl, uint40)\n      );\n  }\n}\n"},"src/contracts/payloads/interfaces/IExecutor.sol":{"content":"// SPDX-License-Identifier: MIT\npragma solidity ^0.8.0;\n\n/**\n * @title IExecutor\n * @author BGD Labs\n * @notice interface containing the objects, events and methods definitions of the Executor contract\n */\ninterface IExecutor {\n  /**\n   * @notice emitted when an action got executed\n   * @param target address of the targeted contract\n   * @param value wei value of the transaction\n   * @param signature function signature of the transaction\n   * @param data function arguments of the transaction or callData if signature empty\n   * @param executionTime time at which to execute the transaction\n   * @param withDelegatecall boolean, true = transaction delegatecalls the target, else calls the target\n   * @param resultData the actual callData used on the target\n   **/\n  event ExecutedAction(\n    address indexed target,\n    uint256 value,\n    string signature,\n    bytes data,\n    uint256 executionTime,\n    bool withDelegatecall,\n    bytes resultData\n  );\n\n  /**\n   * @notice Function, called by Governance, that executes a transaction, returns the callData executed\n   * @param target smart contract target\n   * @param value wei value of the transaction\n   * @param signature function signature of the transaction\n   * @param data function arguments of the transaction or callData if signature empty\n   * @param withDelegatecall boolean, true = transaction delegatecalls the target, else calls the target\n   * @return result data of the execution call.\n   **/\n  function executeTransaction(\n    address target,\n    uint256 value,\n    string memory signature,\n    bytes memory data,\n    bool withDelegatecall\n  ) external payable returns (bytes memory);\n}\n"},"src/contracts/payloads/PayloadsControllerCore.sol":{"content":"// SPDX-License-Identifier: BUSL-1.1\npragma solidity ^0.8.8;\n\nimport {OwnableWithGuardian} from 'solidity-utils/contracts/access-control/OwnableWithGuardian.sol';\nimport {Rescuable, IRescuable} from 'solidity-utils/contracts/utils/Rescuable.sol';\nimport {IERC20} from 'solidity-utils/contracts/oz-common/interfaces/IERC20.sol';\nimport {Initializable} from 'solidity-utils/contracts/transparent-proxy/Initializable.sol';\nimport {SafeERC20} from 'solidity-utils/contracts/oz-common/SafeERC20.sol';\nimport {SafeCast} from 'solidity-utils/contracts/oz-common/SafeCast.sol';\n\nimport {IPayloadsControllerCore, PayloadsControllerUtils} from './interfaces/IPayloadsControllerCore.sol';\nimport {IExecutor} from './interfaces/IExecutor.sol';\nimport {Errors} from '../libraries/Errors.sol';\n\n/**\n * @title PayloadsControllerCore\n * @author BGD Labs\n * @notice this contract contains the logic to create and execute a payload.\n * @dev To execute a created payload, the payload id must be bridged from governance chain.\n * @dev The methods to update the contract configuration are callable only by owner. Owner being the registered\n        lvl1 Executor. So to update the PayloadsController configuration, a proposal will need to pass in gov chain and\n        be executed by the appropriate executor.\n */\nabstract contract PayloadsControllerCore is\n  OwnableWithGuardian,\n  Rescuable,\n  IPayloadsControllerCore,\n  Initializable\n{\n  using SafeCast for uint256;\n  using SafeERC20 for IERC20;\n\n  // should be always set with respect to the proposal flow duration\n  // for example: voting takes 5 days + 2 days for bridging + 3 days for cooldown + 2 days of safety gap\n  // then expirationDelay should be not less then 12 days.\n  // As expiration delay of proposal is 30 days, payload needs to be able to live longer as its created before and\n  // will be executed after.\n  // so nobody should be able to set expiration delay less then that\n  uint40 public constant EXPIRATION_DELAY = 35 days;\n\n  /// @inheritdoc IPayloadsControllerCore\n  uint40 public constant GRACE_PERIOD = 7 days;\n\n  uint40 internal _payloadsCount;\n\n  // stores the executor configuration for every lvl of access control\n  mapping(PayloadsControllerUtils.AccessControl => ExecutorConfig)\n    internal _accessLevelToExecutorConfig;\n\n  mapping(uint40 => Payload) internal _payloads;\n\n  /// @inheritdoc IPayloadsControllerCore\n  function MIN_EXECUTION_DELAY() public view virtual returns (uint40) {\n    return 1 days;\n  }\n\n  /// @inheritdoc IPayloadsControllerCore\n  function MAX_EXECUTION_DELAY() public view virtual returns (uint40) {\n    return 10 days;\n  }\n\n  function initialize(\n    address owner,\n    address guardian,\n    UpdateExecutorInput[] calldata executors\n  ) external initializer {\n    require(executors.length != 0, Errors.SHOULD_BE_AT_LEAST_ONE_EXECUTOR);\n\n    _updateExecutors(executors);\n\n    _updateGuardian(guardian);\n    _transferOwnership(owner);\n  }\n\n  /// @inheritdoc IPayloadsControllerCore\n  function createPayload(\n    ExecutionAction[] calldata actions\n  ) external returns (uint40) {\n    require(actions.length != 0, Errors.INVALID_EMPTY_TARGETS);\n\n    uint40 payloadId = _payloadsCount++;\n    uint40 creationTime = uint40(block.timestamp);\n    Payload storage newPayload = _payloads[payloadId];\n    newPayload.creator = msg.sender;\n    newPayload.state = PayloadState.Created;\n    newPayload.createdAt = creationTime;\n    newPayload.expirationTime = creationTime + EXPIRATION_DELAY;\n    newPayload.gracePeriod = GRACE_PERIOD;\n\n    PayloadsControllerUtils.AccessControl maximumAccessLevelRequired;\n    for (uint256 i = 0; i < actions.length; i++) {\n      require(actions[i].target != address(0), Errors.INVALID_ACTION_TARGET);\n      require(\n        actions[i].accessLevel >\n          PayloadsControllerUtils.AccessControl.Level_null,\n        Errors.INVALID_ACTION_ACCESS_LEVEL\n      );\n      require(\n        _accessLevelToExecutorConfig[actions[i].accessLevel].executor !=\n          address(0),\n        Errors.EXECUTOR_WAS_NOT_SPECIFIED_FOR_REQUESTED_ACCESS_LEVEL\n      );\n\n      newPayload.actions.push(actions[i]);\n\n      if (actions[i].accessLevel > maximumAccessLevelRequired) {\n        maximumAccessLevelRequired = actions[i].accessLevel;\n      }\n    }\n    newPayload.maximumAccessLevelRequired = maximumAccessLevelRequired;\n    ExecutorConfig\n      memory maxRequiredExecutorConfig = _accessLevelToExecutorConfig[\n        maximumAccessLevelRequired\n      ];\n    newPayload.delay = maxRequiredExecutorConfig.delay;\n\n    emit PayloadCreated(\n      payloadId,\n      msg.sender,\n      actions,\n      maximumAccessLevelRequired\n    );\n    return payloadId;\n  }\n\n  /// @inheritdoc IPayloadsControllerCore\n  function executePayload(uint40 payloadId) external payable {\n    Payload storage payload = _payloads[payloadId];\n\n    require(\n      _getPayloadState(payload) == PayloadState.Queued,\n      Errors.PAYLOAD_NOT_IN_QUEUED_STATE\n    );\n\n    uint256 executionTime = payload.queuedAt + payload.delay;\n    require(block.timestamp > executionTime, Errors.TIMELOCK_NOT_FINISHED);\n\n    payload.state = PayloadState.Executed;\n    payload.executedAt = uint40(block.timestamp);\n\n    for (uint256 i = 0; i < payload.actions.length; i++) {\n      ExecutionAction storage action = payload.actions[i];\n      IExecutor executor = IExecutor(\n        _accessLevelToExecutorConfig[action.accessLevel].executor\n      );\n\n      executor.executeTransaction{value: action.value}(\n        action.target,\n        action.value,\n        action.signature,\n        action.callData,\n        action.withDelegateCall\n      );\n    }\n\n    emit PayloadExecuted(payloadId);\n  }\n\n  /// @inheritdoc IPayloadsControllerCore\n  function cancelPayload(uint40 payloadId) external onlyGuardian {\n    Payload storage payload = _payloads[payloadId];\n\n    PayloadState payloadState = _getPayloadState(payload);\n    require(\n      payloadState < PayloadState.Executed &&\n        payloadState >= PayloadState.Created,\n      Errors.PAYLOAD_NOT_IN_THE_CORRECT_STATE\n    );\n    payload.state = PayloadState.Cancelled;\n    payload.cancelledAt = uint40(block.timestamp);\n\n    emit PayloadCancelled(payloadId);\n  }\n\n  /// @inheritdoc IPayloadsControllerCore\n  function updateExecutors(\n    UpdateExecutorInput[] calldata executors\n  ) external onlyOwner {\n    _updateExecutors(executors);\n  }\n\n  /// @inheritdoc IPayloadsControllerCore\n  function getPayloadById(\n    uint40 payloadId\n  ) external view returns (Payload memory) {\n    Payload memory payload = _payloads[payloadId];\n    payload.state = _getPayloadState(payload);\n    return payload;\n  }\n\n  /// @inheritdoc IPayloadsControllerCore\n  function getPayloadState(\n    uint40 payloadId\n  ) external view returns (PayloadState) {\n    return _getPayloadState(_payloads[payloadId]);\n  }\n\n  /// @inheritdoc IPayloadsControllerCore\n  function getPayloadsCount() external view returns (uint40) {\n    return _payloadsCount;\n  }\n\n  /// @inheritdoc IPayloadsControllerCore\n  function getExecutorSettingsByAccessControl(\n    PayloadsControllerUtils.AccessControl accessControl\n  ) external view returns (ExecutorConfig memory) {\n    return _accessLevelToExecutorConfig[accessControl];\n  }\n\n  /// @inheritdoc IRescuable\n  function whoCanRescue()\n    public\n    view\n    override(IRescuable, Rescuable)\n    returns (address)\n  {\n    return owner();\n  }\n\n  receive() external payable {}\n\n  /**\n   * @notice method to get the current state of a payload\n   * @param payload object with all pertinent payload information\n   * @return current state of the payload\n   */\n  function _getPayloadState(\n    Payload memory payload\n  ) internal view returns (PayloadState) {\n    PayloadState state = payload.state;\n    if (state == PayloadState.None || state >= PayloadState.Executed) {\n      return state;\n    }\n\n    if (\n      (state == PayloadState.Created &&\n        block.timestamp >= payload.expirationTime) ||\n      (state == PayloadState.Queued &&\n        block.timestamp >=\n        payload.queuedAt + payload.delay + payload.gracePeriod)\n    ) {\n      return PayloadState.Expired;\n    }\n\n    return state;\n  }\n\n  /**\n   * @notice method to queue a payload\n   * @param payloadId id of the payload that needs to be queued\n   * @param accessLevel access level used for the proposal voting\n   * @param proposalVoteActivationTimestamp proposal vote activation timestamp in seconds\n   * @dev this method will be called when a payload is bridged from governance chain\n   */\n  function _queuePayload(\n    uint40 payloadId,\n    PayloadsControllerUtils.AccessControl accessLevel,\n    uint40 proposalVoteActivationTimestamp\n  ) internal {\n    Payload storage payload = _payloads[payloadId];\n    require(\n      _getPayloadState(payload) == PayloadState.Created,\n      Errors.PAYLOAD_NOT_IN_CREATED_STATE\n    );\n\n    // by allowing >= it enables the proposal to use a higher level of voting configuration\n    // than the one set by the payload actions\n    require(\n      accessLevel >= payload.maximumAccessLevelRequired,\n      Errors.INVALID_PROPOSAL_ACCESS_LEVEL\n    );\n    // this checks that the payload has been created before the proposal vote started.\n    // this ensures that the voters where able to check the content of the payload they voted on\n    require(\n      proposalVoteActivationTimestamp > payload.createdAt,\n      Errors.PAYLOAD_NOT_CREATED_BEFORE_PROPOSAL\n    );\n\n    payload.state = PayloadState.Queued;\n    payload.queuedAt = uint40(block.timestamp);\n\n    emit PayloadQueued(payloadId);\n  }\n\n  /**\n   * @notice add new executor configs\n   * @param executors array of UpdateExecutorInput with needed executor configurations\n   */\n  function _updateExecutors(UpdateExecutorInput[] memory executors) internal {\n    for (uint256 i = 0; i < executors.length; i++) {\n      UpdateExecutorInput memory newExecutorConfig = executors[i];\n\n      require(\n        newExecutorConfig.executorConfig.executor != address(0),\n        Errors.INVALID_EXECUTOR_ADDRESS\n      );\n\n      require(\n        newExecutorConfig.accessLevel >\n          PayloadsControllerUtils.AccessControl.Level_null,\n        Errors.INVALID_EXECUTOR_ACCESS_LEVEL\n      );\n\n      require(\n        newExecutorConfig.executorConfig.delay >= MIN_EXECUTION_DELAY() &&\n          newExecutorConfig.executorConfig.delay <= MAX_EXECUTION_DELAY(),\n        Errors.INVALID_EXECUTOR_DELAY\n      );\n\n      // check that the new executor is not already being used in a different level\n      PayloadsControllerUtils.AccessControl levelToCheck = newExecutorConfig\n        .accessLevel == PayloadsControllerUtils.AccessControl.Level_1\n        ? PayloadsControllerUtils.AccessControl.Level_2\n        : PayloadsControllerUtils.AccessControl.Level_1;\n      require(\n        _accessLevelToExecutorConfig[levelToCheck].executor !=\n          newExecutorConfig.executorConfig.executor,\n        Errors.EXECUTOR_ALREADY_SET_IN_DIFFERENT_LEVEL\n      );\n\n      _accessLevelToExecutorConfig[\n        newExecutorConfig.accessLevel\n      ] = newExecutorConfig.executorConfig;\n\n      emit ExecutorSet(\n        newExecutorConfig.accessLevel,\n        newExecutorConfig.executorConfig.executor,\n        newExecutorConfig.executorConfig.delay\n      );\n    }\n  }\n}\n"},"src/contracts/payloads/PayloadsControllerUtils.sol":{"content":"// SPDX-License-Identifier: BUSL-1.1\npragma solidity ^0.8.0;\n\nlibrary PayloadsControllerUtils {\n  /// @notice enum with supported access levels\n  enum AccessControl {\n    Level_null, // to not use 0\n    Level_1, // LEVEL_1 - short executor before, listing assets, changes of assets params, updates of the protocol etc\n    Level_2 // LEVEL_2 - long executor before, payloads controller updates\n  }\n\n  /**\n   * @notice Object containing the necessary payload information.\n   * @param chain\n   * @param accessLevel\n   * @param payloadsController\n   * @param payloadId\n   */\n  struct Payload {\n    uint256 chain;\n    AccessControl accessLevel;\n    address payloadsController; // address which holds the logic to execute after success proposal voting\n    uint40 payloadId; // number of the payload placed to payloadsController, max is: ~10¹²\n  }\n}\n"},"lib/solidity-utils/src/contracts/utils/Rescuable.sol":{"content":"// SPDX-License-Identifier: MIT\npragma solidity ^0.8.8;\n\nimport {IERC20} from '../oz-common/interfaces/IERC20.sol';\nimport {SafeERC20} from '../oz-common/SafeERC20.sol';\nimport {IRescuable} from './interfaces/IRescuable.sol';\n\n/**\n * @title Rescuable\n * @author BGD Labs\n * @notice abstract contract with the methods to rescue tokens (ERC20 and native)  from a contract\n */\nabstract contract Rescuable is IRescuable {\n  using SafeERC20 for IERC20;\n\n  /// @notice modifier that checks that caller is allowed address\n  modifier onlyRescueGuardian() {\n    require(msg.sender == whoCanRescue(), 'ONLY_RESCUE_GUARDIAN');\n    _;\n  }\n\n  /// @inheritdoc IRescuable\n  function emergencyTokenTransfer(\n    address erc20Token,\n    address to,\n    uint256 amount\n  ) external onlyRescueGuardian {\n    IERC20(erc20Token).safeTransfer(to, amount);\n\n    emit ERC20Rescued(msg.sender, erc20Token, to, amount);\n  }\n\n  /// @inheritdoc IRescuable\n  function emergencyEtherTransfer(address to, uint256 amount) external onlyRescueGuardian {\n    (bool success, ) = to.call{value: amount}(new bytes(0));\n    require(success, 'ETH_TRANSFER_FAIL');\n\n    emit NativeTokensRescued(msg.sender, to, amount);\n  }\n\n  /// @inheritdoc IRescuable\n  function whoCanRescue() public view virtual returns (address);\n}\n"},"lib/solidity-utils/src/contracts/oz-common/Address.sol":{"content":"// SPDX-License-Identifier: MIT\n// OpenZeppelin Contracts (last updated v4.7.0) (utils/Address.sol)\n// From commit https://github.com/OpenZeppelin/openzeppelin-contracts/commit/8b778fa20d6d76340c5fac1ed66c80273f05b95a\n\npragma solidity ^0.8.1;\n\n/**\n * @dev Collection of functions related to the address type\n */\nlibrary Address {\n  /**\n   * @dev Returns true if `account` is a contract.\n   *\n   * [IMPORTANT]\n   * ====\n   * It is unsafe to assume that an address for which this function returns\n   * false is an externally-owned account (EOA) and not a contract.\n   *\n   * Among others, `isContract` will return false for the following\n   * types of addresses:\n   *\n   *  - an externally-owned account\n   *  - a contract in construction\n   *  - an address where a contract will be created\n   *  - an address where a contract lived, but was destroyed\n   * ====\n   *\n   * [IMPORTANT]\n   * ====\n   * You shouldn't rely on `isContract` to protect against flash loan attacks!\n   *\n   * Preventing calls from contracts is highly discouraged. It breaks composability, breaks support for smart wallets\n   * like Gnosis Safe, and does not provide security since it can be circumvented by calling from a contract\n   * constructor.\n   * ====\n   */\n  function isContract(address account) internal view returns (bool) {\n    // This method relies on extcodesize/address.code.length, which returns 0\n    // for contracts in construction, since the code is only stored at the end\n    // of the constructor execution.\n\n    return account.code.length > 0;\n  }\n\n  /**\n   * @dev Replacement for Solidity's `transfer`: sends `amount` wei to\n   * `recipient`, forwarding all available gas and reverting on errors.\n   *\n   * https://eips.ethereum.org/EIPS/eip-1884[EIP1884] increases the gas cost\n   * of certain opcodes, possibly making contracts go over the 2300 gas limit\n   * imposed by `transfer`, making them unable to receive funds via\n   * `transfer`. {sendValue} removes this limitation.\n   *\n   * https://diligence.consensys.net/posts/2019/09/stop-using-soliditys-transfer-now/[Learn more].\n   *\n   * IMPORTANT: because control is transferred to `recipient`, care must be\n   * taken to not create reentrancy vulnerabilities. Consider using\n   * {ReentrancyGuard} or the\n   * https://solidity.readthedocs.io/en/v0.5.11/security-considerations.html#use-the-checks-effects-interactions-pattern[checks-effects-interactions pattern].\n   */\n  function sendValue(address payable recipient, uint256 amount) internal {\n    require(address(this).balance >= amount, 'Address: insufficient balance');\n\n    (bool success, ) = recipient.call{value: amount}('');\n    require(success, 'Address: unable to send value, recipient may have reverted');\n  }\n\n  /**\n   * @dev Performs a Solidity function call using a low level `call`. A\n   * plain `call` is an unsafe replacement for a function call: use this\n   * function instead.\n   *\n   * If `target` reverts with a revert reason, it is bubbled up by this\n   * function (like regular Solidity function calls).\n   *\n   * Returns the raw returned data. To convert to the expected return value,\n   * use https://solidity.readthedocs.io/en/latest/units-and-global-variables.html?highlight=abi.decode#abi-encoding-and-decoding-functions[`abi.decode`].\n   *\n   * Requirements:\n   *\n   * - `target` must be a contract.\n   * - calling `target` with `data` must not revert.\n   *\n   * _Available since v3.1._\n   */\n  function functionCall(address target, bytes memory data) internal returns (bytes memory) {\n    return functionCallWithValue(target, data, 0, 'Address: low-level call failed');\n  }\n\n  /**\n   * @dev Same as {xref-Address-functionCall-address-bytes-}[`functionCall`], but with\n   * `errorMessage` as a fallback revert reason when `target` reverts.\n   *\n   * _Available since v3.1._\n   */\n  function functionCall(\n    address target,\n    bytes memory data,\n    string memory errorMessage\n  ) internal returns (bytes memory) {\n    return functionCallWithValue(target, data, 0, errorMessage);\n  }\n\n  /**\n   * @dev Same as {xref-Address-functionCall-address-bytes-}[`functionCall`],\n   * but also transferring `value` wei to `target`.\n   *\n   * Requirements:\n   *\n   * - the calling contract must have an ETH balance of at least `value`.\n   * - the called Solidity function must be `payable`.\n   *\n   * _Available since v3.1._\n   */\n  function functionCallWithValue(\n    address target,\n    bytes memory data,\n    uint256 value\n  ) internal returns (bytes memory) {\n    return functionCallWithValue(target, data, value, 'Address: low-level call with value failed');\n  }\n\n  /**\n   * @dev Same as {xref-Address-functionCallWithValue-address-bytes-uint256-}[`functionCallWithValue`], but\n   * with `errorMessage` as a fallback revert reason when `target` reverts.\n   *\n   * _Available since v3.1._\n   */\n  function functionCallWithValue(\n    address target,\n    bytes memory data,\n    uint256 value,\n    string memory errorMessage\n  ) internal returns (bytes memory) {\n    require(address(this).balance >= value, 'Address: insufficient balance for call');\n    (bool success, bytes memory returndata) = target.call{value: value}(data);\n    return verifyCallResultFromTarget(target, success, returndata, errorMessage);\n  }\n\n  /**\n   * @dev Same as {xref-Address-functionCall-address-bytes-}[`functionCall`],\n   * but performing a static call.\n   *\n   * _Available since v3.3._\n   */\n  function functionStaticCall(\n    address target,\n    bytes memory data\n  ) internal view returns (bytes memory) {\n    return functionStaticCall(target, data, 'Address: low-level static call failed');\n  }\n\n  /**\n   * @dev Same as {xref-Address-functionCall-address-bytes-string-}[`functionCall`],\n   * but performing a static call.\n   *\n   * _Available since v3.3._\n   */\n  function functionStaticCall(\n    address target,\n    bytes memory data,\n    string memory errorMessage\n  ) internal view returns (bytes memory) {\n    (bool success, bytes memory returndata) = target.staticcall(data);\n    return verifyCallResultFromTarget(target, success, returndata, errorMessage);\n  }\n\n  /**\n   * @dev Same as {xref-Address-functionCall-address-bytes-}[`functionCall`],\n   * but performing a delegate call.\n   *\n   * _Available since v3.4._\n   */\n  function functionDelegateCall(address target, bytes memory data) internal returns (bytes memory) {\n    return functionDelegateCall(target, data, 'Address: low-level delegate call failed');\n  }\n\n  /**\n   * @dev Same as {xref-Address-functionCall-address-bytes-string-}[`functionCall`],\n   * but performing a delegate call.\n   *\n   * _Available since v3.4._\n   */\n  function functionDelegateCall(\n    address target,\n    bytes memory data,\n    string memory errorMessage\n  ) internal returns (bytes memory) {\n    (bool success, bytes memory returndata) = target.delegatecall(data);\n    return verifyCallResultFromTarget(target, success, returndata, errorMessage);\n  }\n\n  /**\n   * @dev Tool to verify that a low level call to smart-contract was successful, and revert (either by bubbling\n   * the revert reason or using the provided one) in case of unsuccessful call or if target was not a contract.\n   *\n   * _Available since v4.8._\n   */\n  function verifyCallResultFromTarget(\n    address target,\n    bool success,\n    bytes memory returndata,\n    string memory errorMessage\n  ) internal view returns (bytes memory) {\n    if (success) {\n      if (returndata.length == 0) {\n        // only check isContract if the call was successful and the return data is empty\n        // otherwise we already know that it was a contract\n        require(isContract(target), 'Address: call to non-contract');\n      }\n      return returndata;\n    } else {\n      _revert(returndata, errorMessage);\n    }\n  }\n\n  /**\n   * @dev Tool to verify that a low level call was successful, and revert if it wasn't, either by bubbling the\n   * revert reason or using the provided one.\n   *\n   * _Available since v4.3._\n   */\n  function verifyCallResult(\n    bool success,\n    bytes memory returndata,\n    string memory errorMessage\n  ) internal pure returns (bytes memory) {\n    if (success) {\n      return returndata;\n    } else {\n      _revert(returndata, errorMessage);\n    }\n  }\n\n  function _revert(bytes memory returndata, string memory errorMessage) private pure {\n    // Look for revert reason and bubble it up if present\n    if (returndata.length > 0) {\n      // The easiest way to bubble the revert reason is using memory via assembly\n      /// @solidity memory-safe-assembly\n      assembly {\n        let returndata_size := mload(returndata)\n        revert(add(32, returndata), returndata_size)\n      }\n    } else {\n      revert(errorMessage);\n    }\n  }\n}\n"},"lib/solidity-utils/src/contracts/oz-common/Context.sol":{"content":"// SPDX-License-Identifier: MIT\n// OpenZeppelin Contracts v4.4.1 (utils/Context.sol)\n// From commit https://github.com/OpenZeppelin/openzeppelin-contracts/commit/8b778fa20d6d76340c5fac1ed66c80273f05b95a\n\npragma solidity ^0.8.0;\n\n/**\n * @dev Provides information about the current execution context, including the\n * sender of the transaction and its data. While these are generally available\n * via msg.sender and msg.data, they should not be accessed in such a direct\n * manner, since when dealing with meta-transactions the account sending and\n * paying for execution may not be the actual sender (as far as an application\n * is concerned).\n *\n * This contract is only required for intermediate, library-like contracts.\n */\nabstract contract Context {\n  function _msgSender() internal view virtual returns (address) {\n    return msg.sender;\n  }\n\n  function _msgData() internal view virtual returns (bytes calldata) {\n    return msg.data;\n  }\n}\n"},"lib/solidity-utils/src/contracts/oz-common/Ownable.sol":{"content":"// SPDX-License-Identifier: MIT\n// OpenZeppelin Contracts (last updated v4.7.0) (access/Ownable.sol)\n// From commit https://github.com/OpenZeppelin/openzeppelin-contracts/commit/8b778fa20d6d76340c5fac1ed66c80273f05b95a\n\npragma solidity ^0.8.0;\n\nimport './Context.sol';\n\n/**\n * @dev Contract module which provides a basic access control mechanism, where\n * there is an account (an owner) that can be granted exclusive access to\n * specific functions.\n *\n * By default, the owner account will be the one that deploys the contract. This\n * can later be changed with {transferOwnership}.\n *\n * This module is used through inheritance. It will make available the modifier\n * `onlyOwner`, which can be applied to your functions to restrict their use to\n * the owner.\n */\nabstract contract Ownable is Context {\n  address private _owner;\n\n  event OwnershipTransferred(address indexed previousOwner, address indexed newOwner);\n\n  /**\n   * @dev Initializes the contract setting the deployer as the initial owner.\n   */\n  constructor() {\n    _transferOwnership(_msgSender());\n  }\n\n  /**\n   * @dev Throws if called by any account other than the owner.\n   */\n  modifier onlyOwner() {\n    _checkOwner();\n    _;\n  }\n\n  /**\n   * @dev Returns the address of the current owner.\n   */\n  function owner() public view virtual returns (address) {\n    return _owner;\n  }\n\n  /**\n   * @dev Throws if the sender is not the owner.\n   */\n  function _checkOwner() internal view virtual {\n    require(owner() == _msgSender(), 'Ownable: caller is not the owner');\n  }\n\n  /**\n   * @dev Leaves the contract without owner. It will not be possible to call\n   * `onlyOwner` functions anymore. Can only be called by the current owner.\n   *\n   * NOTE: Renouncing ownership will leave the contract without an owner,\n   * thereby removing any functionality that is only available to the owner.\n   */\n  function renounceOwnership() public virtual onlyOwner {\n    _transferOwnership(address(0));\n  }\n\n  /**\n   * @dev Transfers ownership of the contract to a new account (`newOwner`).\n   * Can only be called by the current owner.\n   */\n  function transferOwnership(address newOwner) public virtual onlyOwner {\n    require(newOwner != address(0), 'Ownable: new owner is the zero address');\n    _transferOwnership(newOwner);\n  }\n\n  /**\n   * @dev Transfers ownership of the contract to a new account (`newOwner`).\n   * Internal function without access restriction.\n   */\n  function _transferOwnership(address newOwner) internal virtual {\n    address oldOwner = _owner;\n    _owner = newOwner;\n    emit OwnershipTransferred(oldOwner, newOwner);\n  }\n}\n"},"lib/solidity-utils/src/contracts/oz-common/SafeCast.sol":{"content":"// SPDX-License-Identifier: MIT\n// OpenZeppelin Contracts (last updated v4.8.0) (utils/math/SafeCast.sol)\n// This file was procedurally generated from scripts/generate/templates/SafeCast.js.\n\npragma solidity ^0.8.0;\n\n/**\n * @dev Wrappers over Solidity's uintXX/intXX casting operators with added overflow\n * checks.\n *\n * Downcasting from uint256/int256 in Solidity does not revert on overflow. This can\n * easily result in undesired exploitation or bugs, since developers usually\n * assume that overflows raise errors. `SafeCast` restores this intuition by\n * reverting the transaction when such an operation overflows.\n *\n * Using this library instead of the unchecked operations eliminates an entire\n * class of bugs, so it's recommended to use it always.\n *\n * Can be combined with {SafeMath} and {SignedSafeMath} to extend it to smaller types, by performing\n * all math on `uint256` and `int256` and then downcasting.\n */\nlibrary SafeCast {\n  /**\n   * @dev Returns the downcasted uint248 from uint256, reverting on\n   * overflow (when the input is greater than largest uint248).\n   *\n   * Counterpart to Solidity's `uint248` operator.\n   *\n   * Requirements:\n   *\n   * - input must fit into 248 bits\n   *\n   * _Available since v4.7._\n   */\n  function toUint248(uint256 value) internal pure returns (uint248) {\n    require(value <= type(uint248).max, \"SafeCast: value doesn't fit in 248 bits\");\n    return uint248(value);\n  }\n\n  /**\n   * @dev Returns the downcasted uint240 from uint256, reverting on\n   * overflow (when the input is greater than largest uint240).\n   *\n   * Counterpart to Solidity's `uint240` operator.\n   *\n   * Requirements:\n   *\n   * - input must fit into 240 bits\n   *\n   * _Available since v4.7._\n   */\n  function toUint240(uint256 value) internal pure returns (uint240) {\n    require(value <= type(uint240).max, \"SafeCast: value doesn't fit in 240 bits\");\n    return uint240(value);\n  }\n\n  /**\n   * @dev Returns the downcasted uint232 from uint256, reverting on\n   * overflow (when the input is greater than largest uint232).\n   *\n   * Counterpart to Solidity's `uint232` operator.\n   *\n   * Requirements:\n   *\n   * - input must fit into 232 bits\n   *\n   * _Available since v4.7._\n   */\n  function toUint232(uint256 value) internal pure returns (uint232) {\n    require(value <= type(uint232).max, \"SafeCast: value doesn't fit in 232 bits\");\n    return uint232(value);\n  }\n\n  /**\n   * @dev Returns the downcasted uint224 from uint256, reverting on\n   * overflow (when the input is greater than largest uint224).\n   *\n   * Counterpart to Solidity's `uint224` operator.\n   *\n   * Requirements:\n   *\n   * - input must fit into 224 bits\n   *\n   * _Available since v4.2._\n   */\n  function toUint224(uint256 value) internal pure returns (uint224) {\n    require(value <= type(uint224).max, \"SafeCast: value doesn't fit in 224 bits\");\n    return uint224(value);\n  }\n\n  /**\n   * @dev Returns the downcasted uint216 from uint256, reverting on\n   * overflow (when the input is greater than largest uint216).\n   *\n   * Counterpart to Solidity's `uint216` operator.\n   *\n   * Requirements:\n   *\n   * - input must fit into 216 bits\n   *\n   * _Available since v4.7._\n   */\n  function toUint216(uint256 value) internal pure returns (uint216) {\n    require(value <= type(uint216).max, \"SafeCast: value doesn't fit in 216 bits\");\n    return uint216(value);\n  }\n\n  /**\n   * @dev Returns the downcasted uint208 from uint256, reverting on\n   * overflow (when the input is greater than largest uint208).\n   *\n   * Counterpart to Solidity's `uint208` operator.\n   *\n   * Requirements:\n   *\n   * - input must fit into 208 bits\n   *\n   * _Available since v4.7._\n   */\n  function toUint208(uint256 value) internal pure returns (uint208) {\n    require(value <= type(uint208).max, \"SafeCast: value doesn't fit in 208 bits\");\n    return uint208(value);\n  }\n\n  /**\n   * @dev Returns the downcasted uint200 from uint256, reverting on\n   * overflow (when the input is greater than largest uint200).\n   *\n   * Counterpart to Solidity's `uint200` operator.\n   *\n   * Requirements:\n   *\n   * - input must fit into 200 bits\n   *\n   * _Available since v4.7._\n   */\n  function toUint200(uint256 value) internal pure returns (uint200) {\n    require(value <= type(uint200).max, \"SafeCast: value doesn't fit in 200 bits\");\n    return uint200(value);\n  }\n\n  /**\n   * @dev Returns the downcasted uint192 from uint256, reverting on\n   * overflow (when the input is greater than largest uint192).\n   *\n   * Counterpart to Solidity's `uint192` operator.\n   *\n   * Requirements:\n   *\n   * - input must fit into 192 bits\n   *\n   * _Available since v4.7._\n   */\n  function toUint192(uint256 value) internal pure returns (uint192) {\n    require(value <= type(uint192).max, \"SafeCast: value doesn't fit in 192 bits\");\n    return uint192(value);\n  }\n\n  /**\n   * @dev Returns the downcasted uint184 from uint256, reverting on\n   * overflow (when the input is greater than largest uint184).\n   *\n   * Counterpart to Solidity's `uint184` operator.\n   *\n   * Requirements:\n   *\n   * - input must fit into 184 bits\n   *\n   * _Available since v4.7._\n   */\n  function toUint184(uint256 value) internal pure returns (uint184) {\n    require(value <= type(uint184).max, \"SafeCast: value doesn't fit in 184 bits\");\n    return uint184(value);\n  }\n\n  /**\n   * @dev Returns the downcasted uint176 from uint256, reverting on\n   * overflow (when the input is greater than largest uint176).\n   *\n   * Counterpart to Solidity's `uint176` operator.\n   *\n   * Requirements:\n   *\n   * - input must fit into 176 bits\n   *\n   * _Available since v4.7._\n   */\n  function toUint176(uint256 value) internal pure returns (uint176) {\n    require(value <= type(uint176).max, \"SafeCast: value doesn't fit in 176 bits\");\n    return uint176(value);\n  }\n\n  /**\n   * @dev Returns the downcasted uint168 from uint256, reverting on\n   * overflow (when the input is greater than largest uint168).\n   *\n   * Counterpart to Solidity's `uint168` operator.\n   *\n   * Requirements:\n   *\n   * - input must fit into 168 bits\n   *\n   * _Available since v4.7._\n   */\n  function toUint168(uint256 value) internal pure returns (uint168) {\n    require(value <= type(uint168).max, \"SafeCast: value doesn't fit in 168 bits\");\n    return uint168(value);\n  }\n\n  /**\n   * @dev Returns the downcasted uint160 from uint256, reverting on\n   * overflow (when the input is greater than largest uint160).\n   *\n   * Counterpart to Solidity's `uint160` operator.\n   *\n   * Requirements:\n   *\n   * - input must fit into 160 bits\n   *\n   * _Available since v4.7._\n   */\n  function toUint160(uint256 value) internal pure returns (uint160) {\n    require(value <= type(uint160).max, \"SafeCast: value doesn't fit in 160 bits\");\n    return uint160(value);\n  }\n\n  /**\n   * @dev Returns the downcasted uint152 from uint256, reverting on\n   * overflow (when the input is greater than largest uint152).\n   *\n   * Counterpart to Solidity's `uint152` operator.\n   *\n   * Requirements:\n   *\n   * - input must fit into 152 bits\n   *\n   * _Available since v4.7._\n   */\n  function toUint152(uint256 value) internal pure returns (uint152) {\n    require(value <= type(uint152).max, \"SafeCast: value doesn't fit in 152 bits\");\n    return uint152(value);\n  }\n\n  /**\n   * @dev Returns the downcasted uint144 from uint256, reverting on\n   * overflow (when the input is greater than largest uint144).\n   *\n   * Counterpart to Solidity's `uint144` operator.\n   *\n   * Requirements:\n   *\n   * - input must fit into 144 bits\n   *\n   * _Available since v4.7._\n   */\n  function toUint144(uint256 value) internal pure returns (uint144) {\n    require(value <= type(uint144).max, \"SafeCast: value doesn't fit in 144 bits\");\n    return uint144(value);\n  }\n\n  /**\n   * @dev Returns the downcasted uint136 from uint256, reverting on\n   * overflow (when the input is greater than largest uint136).\n   *\n   * Counterpart to Solidity's `uint136` operator.\n   *\n   * Requirements:\n   *\n   * - input must fit into 136 bits\n   *\n   * _Available since v4.7._\n   */\n  function toUint136(uint256 value) internal pure returns (uint136) {\n    require(value <= type(uint136).max, \"SafeCast: value doesn't fit in 136 bits\");\n    return uint136(value);\n  }\n\n  /**\n   * @dev Returns the downcasted uint128 from uint256, reverting on\n   * overflow (when the input is greater than largest uint128).\n   *\n   * Counterpart to Solidity's `uint128` operator.\n   *\n   * Requirements:\n   *\n   * - input must fit into 128 bits\n   *\n   * _Available since v2.5._\n   */\n  function toUint128(uint256 value) internal pure returns (uint128) {\n    require(value <= type(uint128).max, \"SafeCast: value doesn't fit in 128 bits\");\n    return uint128(value);\n  }\n\n  /**\n   * @dev Returns the downcasted uint120 from uint256, reverting on\n   * overflow (when the input is greater than largest uint120).\n   *\n   * Counterpart to Solidity's `uint120` operator.\n   *\n   * Requirements:\n   *\n   * - input must fit into 120 bits\n   *\n   * _Available since v4.7._\n   */\n  function toUint120(uint256 value) internal pure returns (uint120) {\n    require(value <= type(uint120).max, \"SafeCast: value doesn't fit in 120 bits\");\n    return uint120(value);\n  }\n\n  /**\n   * @dev Returns the downcasted uint112 from uint256, reverting on\n   * overflow (when the input is greater than largest uint112).\n   *\n   * Counterpart to Solidity's `uint112` operator.\n   *\n   * Requirements:\n   *\n   * - input must fit into 112 bits\n   *\n   * _Available since v4.7._\n   */\n  function toUint112(uint256 value) internal pure returns (uint112) {\n    require(value <= type(uint112).max, \"SafeCast: value doesn't fit in 112 bits\");\n    return uint112(value);\n  }\n\n  /**\n   * @dev Returns the downcasted uint104 from uint256, reverting on\n   * overflow (when the input is greater than largest uint104).\n   *\n   * Counterpart to Solidity's `uint104` operator.\n   *\n   * Requirements:\n   *\n   * - input must fit into 104 bits\n   *\n   * _Available since v4.7._\n   */\n  function toUint104(uint256 value) internal pure returns (uint104) {\n    require(value <= type(uint104).max, \"SafeCast: value doesn't fit in 104 bits\");\n    return uint104(value);\n  }\n\n  /**\n   * @dev Returns the downcasted uint96 from uint256, reverting on\n   * overflow (when the input is greater than largest uint96).\n   *\n   * Counterpart to Solidity's `uint96` operator.\n   *\n   * Requirements:\n   *\n   * - input must fit into 96 bits\n   *\n   * _Available since v4.2._\n   */\n  function toUint96(uint256 value) internal pure returns (uint96) {\n    require(value <= type(uint96).max, \"SafeCast: value doesn't fit in 96 bits\");\n    return uint96(value);\n  }\n\n  /**\n   * @dev Returns the downcasted uint88 from uint256, reverting on\n   * overflow (when the input is greater than largest uint88).\n   *\n   * Counterpart to Solidity's `uint88` operator.\n   *\n   * Requirements:\n   *\n   * - input must fit into 88 bits\n   *\n   * _Available since v4.7._\n   */\n  function toUint88(uint256 value) internal pure returns (uint88) {\n    require(value <= type(uint88).max, \"SafeCast: value doesn't fit in 88 bits\");\n    return uint88(value);\n  }\n\n  /**\n   * @dev Returns the downcasted uint80 from uint256, reverting on\n   * overflow (when the input is greater than largest uint80).\n   *\n   * Counterpart to Solidity's `uint80` operator.\n   *\n   * Requirements:\n   *\n   * - input must fit into 80 bits\n   *\n   * _Available since v4.7._\n   */\n  function toUint80(uint256 value) internal pure returns (uint80) {\n    require(value <= type(uint80).max, \"SafeCast: value doesn't fit in 80 bits\");\n    return uint80(value);\n  }\n\n  /**\n   * @dev Returns the downcasted uint72 from uint256, reverting on\n   * overflow (when the input is greater than largest uint72).\n   *\n   * Counterpart to Solidity's `uint72` operator.\n   *\n   * Requirements:\n   *\n   * - input must fit into 72 bits\n   *\n   * _Available since v4.7._\n   */\n  function toUint72(uint256 value) internal pure returns (uint72) {\n    require(value <= type(uint72).max, \"SafeCast: value doesn't fit in 72 bits\");\n    return uint72(value);\n  }\n\n  /**\n   * @dev Returns the downcasted uint64 from uint256, reverting on\n   * overflow (when the input is greater than largest uint64).\n   *\n   * Counterpart to Solidity's `uint64` operator.\n   *\n   * Requirements:\n   *\n   * - input must fit into 64 bits\n   *\n   * _Available since v2.5._\n   */\n  function toUint64(uint256 value) internal pure returns (uint64) {\n    require(value <= type(uint64).max, \"SafeCast: value doesn't fit in 64 bits\");\n    return uint64(value);\n  }\n\n  /**\n   * @dev Returns the downcasted uint56 from uint256, reverting on\n   * overflow (when the input is greater than largest uint56).\n   *\n   * Counterpart to Solidity's `uint56` operator.\n   *\n   * Requirements:\n   *\n   * - input must fit into 56 bits\n   *\n   * _Available since v4.7._\n   */\n  function toUint56(uint256 value) internal pure returns (uint56) {\n    require(value <= type(uint56).max, \"SafeCast: value doesn't fit in 56 bits\");\n    return uint56(value);\n  }\n\n  /**\n   * @dev Returns the downcasted uint48 from uint256, reverting on\n   * overflow (when the input is greater than largest uint48).\n   *\n   * Counterpart to Solidity's `uint48` operator.\n   *\n   * Requirements:\n   *\n   * - input must fit into 48 bits\n   *\n   * _Available since v4.7._\n   */\n  function toUint48(uint256 value) internal pure returns (uint48) {\n    require(value <= type(uint48).max, \"SafeCast: value doesn't fit in 48 bits\");\n    return uint48(value);\n  }\n\n  /**\n   * @dev Returns the downcasted uint40 from uint256, reverting on\n   * overflow (when the input is greater than largest uint40).\n   *\n   * Counterpart to Solidity's `uint40` operator.\n   *\n   * Requirements:\n   *\n   * - input must fit into 40 bits\n   *\n   * _Available since v4.7._\n   */\n  function toUint40(uint256 value) internal pure returns (uint40) {\n    require(value <= type(uint40).max, \"SafeCast: value doesn't fit in 40 bits\");\n    return uint40(value);\n  }\n\n  /**\n   * @dev Returns the downcasted uint32 from uint256, reverting on\n   * overflow (when the input is greater than largest uint32).\n   *\n   * Counterpart to Solidity's `uint32` operator.\n   *\n   * Requirements:\n   *\n   * - input must fit into 32 bits\n   *\n   * _Available since v2.5._\n   */\n  function toUint32(uint256 value) internal pure returns (uint32) {\n    require(value <= type(uint32).max, \"SafeCast: value doesn't fit in 32 bits\");\n    return uint32(value);\n  }\n\n  /**\n   * @dev Returns the downcasted uint24 from uint256, reverting on\n   * overflow (when the input is greater than largest uint24).\n   *\n   * Counterpart to Solidity's `uint24` operator.\n   *\n   * Requirements:\n   *\n   * - input must fit into 24 bits\n   *\n   * _Available since v4.7._\n   */\n  function toUint24(uint256 value) internal pure returns (uint24) {\n    require(value <= type(uint24).max, \"SafeCast: value doesn't fit in 24 bits\");\n    return uint24(value);\n  }\n\n  /**\n   * @dev Returns the downcasted uint16 from uint256, reverting on\n   * overflow (when the input is greater than largest uint16).\n   *\n   * Counterpart to Solidity's `uint16` operator.\n   *\n   * Requirements:\n   *\n   * - input must fit into 16 bits\n   *\n   * _Available since v2.5._\n   */\n  function toUint16(uint256 value) internal pure returns (uint16) {\n    require(value <= type(uint16).max, \"SafeCast: value doesn't fit in 16 bits\");\n    return uint16(value);\n  }\n\n  /**\n   * @dev Returns the downcasted uint8 from uint256, reverting on\n   * overflow (when the input is greater than largest uint8).\n   *\n   * Counterpart to Solidity's `uint8` operator.\n   *\n   * Requirements:\n   *\n   * - input must fit into 8 bits\n   *\n   * _Available since v2.5._\n   */\n  function toUint8(uint256 value) internal pure returns (uint8) {\n    require(value <= type(uint8).max, \"SafeCast: value doesn't fit in 8 bits\");\n    return uint8(value);\n  }\n\n  /**\n   * @dev Converts a signed int256 into an unsigned uint256.\n   *\n   * Requirements:\n   *\n   * - input must be greater than or equal to 0.\n   *\n   * _Available since v3.0._\n   */\n  function toUint256(int256 value) internal pure returns (uint256) {\n    require(value >= 0, 'SafeCast: value must be positive');\n    return uint256(value);\n  }\n\n  /**\n   * @dev Returns the downcasted int248 from int256, reverting on\n   * overflow (when the input is less than smallest int248 or\n   * greater than largest int248).\n   *\n   * Counterpart to Solidity's `int248` operator.\n   *\n   * Requirements:\n   *\n   * - input must fit into 248 bits\n   *\n   * _Available since v4.7._\n   */\n  function toInt248(int256 value) internal pure returns (int248 downcasted) {\n    downcasted = int248(value);\n    require(downcasted == value, \"SafeCast: value doesn't fit in 248 bits\");\n  }\n\n  /**\n   * @dev Returns the downcasted int240 from int256, reverting on\n   * overflow (when the input is less than smallest int240 or\n   * greater than largest int240).\n   *\n   * Counterpart to Solidity's `int240` operator.\n   *\n   * Requirements:\n   *\n   * - input must fit into 240 bits\n   *\n   * _Available since v4.7._\n   */\n  function toInt240(int256 value) internal pure returns (int240 downcasted) {\n    downcasted = int240(value);\n    require(downcasted == value, \"SafeCast: value doesn't fit in 240 bits\");\n  }\n\n  /**\n   * @dev Returns the downcasted int232 from int256, reverting on\n   * overflow (when the input is less than smallest int232 or\n   * greater than largest int232).\n   *\n   * Counterpart to Solidity's `int232` operator.\n   *\n   * Requirements:\n   *\n   * - input must fit into 232 bits\n   *\n   * _Available since v4.7._\n   */\n  function toInt232(int256 value) internal pure returns (int232 downcasted) {\n    downcasted = int232(value);\n    require(downcasted == value, \"SafeCast: value doesn't fit in 232 bits\");\n  }\n\n  /**\n   * @dev Returns the downcasted int224 from int256, reverting on\n   * overflow (when the input is less than smallest int224 or\n   * greater than largest int224).\n   *\n   * Counterpart to Solidity's `int224` operator.\n   *\n   * Requirements:\n   *\n   * - input must fit into 224 bits\n   *\n   * _Available since v4.7._\n   */\n  function toInt224(int256 value) internal pure returns (int224 downcasted) {\n    downcasted = int224(value);\n    require(downcasted == value, \"SafeCast: value doesn't fit in 224 bits\");\n  }\n\n  /**\n   * @dev Returns the downcasted int216 from int256, reverting on\n   * overflow (when the input is less than smallest int216 or\n   * greater than largest int216).\n   *\n   * Counterpart to Solidity's `int216` operator.\n   *\n   * Requirements:\n   *\n   * - input must fit into 216 bits\n   *\n   * _Available since v4.7._\n   */\n  function toInt216(int256 value) internal pure returns (int216 downcasted) {\n    downcasted = int216(value);\n    require(downcasted == value, \"SafeCast: value doesn't fit in 216 bits\");\n  }\n\n  /**\n   * @dev Returns the downcasted int208 from int256, reverting on\n   * overflow (when the input is less than smallest int208 or\n   * greater than largest int208).\n   *\n   * Counterpart to Solidity's `int208` operator.\n   *\n   * Requirements:\n   *\n   * - input must fit into 208 bits\n   *\n   * _Available since v4.7._\n   */\n  function toInt208(int256 value) internal pure returns (int208 downcasted) {\n    downcasted = int208(value);\n    require(downcasted == value, \"SafeCast: value doesn't fit in 208 bits\");\n  }\n\n  /**\n   * @dev Returns the downcasted int200 from int256, reverting on\n   * overflow (when the input is less than smallest int200 or\n   * greater than largest int200).\n   *\n   * Counterpart to Solidity's `int200` operator.\n   *\n   * Requirements:\n   *\n   * - input must fit into 200 bits\n   *\n   * _Available since v4.7._\n   */\n  function toInt200(int256 value) internal pure returns (int200 downcasted) {\n    downcasted = int200(value);\n    require(downcasted == value, \"SafeCast: value doesn't fit in 200 bits\");\n  }\n\n  /**\n   * @dev Returns the downcasted int192 from int256, reverting on\n   * overflow (when the input is less than smallest int192 or\n   * greater than largest int192).\n   *\n   * Counterpart to Solidity's `int192` operator.\n   *\n   * Requirements:\n   *\n   * - input must fit into 192 bits\n   *\n   * _Available since v4.7._\n   */\n  function toInt192(int256 value) internal pure returns (int192 downcasted) {\n    downcasted = int192(value);\n    require(downcasted == value, \"SafeCast: value doesn't fit in 192 bits\");\n  }\n\n  /**\n   * @dev Returns the downcasted int184 from int256, reverting on\n   * overflow (when the input is less than smallest int184 or\n   * greater than largest int184).\n   *\n   * Counterpart to Solidity's `int184` operator.\n   *\n   * Requirements:\n   *\n   * - input must fit into 184 bits\n   *\n   * _Available since v4.7._\n   */\n  function toInt184(int256 value) internal pure returns (int184 downcasted) {\n    downcasted = int184(value);\n    require(downcasted == value, \"SafeCast: value doesn't fit in 184 bits\");\n  }\n\n  /**\n   * @dev Returns the downcasted int176 from int256, reverting on\n   * overflow (when the input is less than smallest int176 or\n   * greater than largest int176).\n   *\n   * Counterpart to Solidity's `int176` operator.\n   *\n   * Requirements:\n   *\n   * - input must fit into 176 bits\n   *\n   * _Available since v4.7._\n   */\n  function toInt176(int256 value) internal pure returns (int176 downcasted) {\n    downcasted = int176(value);\n    require(downcasted == value, \"SafeCast: value doesn't fit in 176 bits\");\n  }\n\n  /**\n   * @dev Returns the downcasted int168 from int256, reverting on\n   * overflow (when the input is less than smallest int168 or\n   * greater than largest int168).\n   *\n   * Counterpart to Solidity's `int168` operator.\n   *\n   * Requirements:\n   *\n   * - input must fit into 168 bits\n   *\n   * _Available since v4.7._\n   */\n  function toInt168(int256 value) internal pure returns (int168 downcasted) {\n    downcasted = int168(value);\n    require(downcasted == value, \"SafeCast: value doesn't fit in 168 bits\");\n  }\n\n  /**\n   * @dev Returns the downcasted int160 from int256, reverting on\n   * overflow (when the input is less than smallest int160 or\n   * greater than largest int160).\n   *\n   * Counterpart to Solidity's `int160` operator.\n   *\n   * Requirements:\n   *\n   * - input must fit into 160 bits\n   *\n   * _Available since v4.7._\n   */\n  function toInt160(int256 value) internal pure returns (int160 downcasted) {\n    downcasted = int160(value);\n    require(downcasted == value, \"SafeCast: value doesn't fit in 160 bits\");\n  }\n\n  /**\n   * @dev Returns the downcasted int152 from int256, reverting on\n   * overflow (when the input is less than smallest int152 or\n   * greater than largest int152).\n   *\n   * Counterpart to Solidity's `int152` operator.\n   *\n   * Requirements:\n   *\n   * - input must fit into 152 bits\n   *\n   * _Available since v4.7._\n   */\n  function toInt152(int256 value) internal pure returns (int152 downcasted) {\n    downcasted = int152(value);\n    require(downcasted == value, \"SafeCast: value doesn't fit in 152 bits\");\n  }\n\n  /**\n   * @dev Returns the downcasted int144 from int256, reverting on\n   * overflow (when the input is less than smallest int144 or\n   * greater than largest int144).\n   *\n   * Counterpart to Solidity's `int144` operator.\n   *\n   * Requirements:\n   *\n   * - input must fit into 144 bits\n   *\n   * _Available since v4.7._\n   */\n  function toInt144(int256 value) internal pure returns (int144 downcasted) {\n    downcasted = int144(value);\n    require(downcasted == value, \"SafeCast: value doesn't fit in 144 bits\");\n  }\n\n  /**\n   * @dev Returns the downcasted int136 from int256, reverting on\n   * overflow (when the input is less than smallest int136 or\n   * greater than largest int136).\n   *\n   * Counterpart to Solidity's `int136` operator.\n   *\n   * Requirements:\n   *\n   * - input must fit into 136 bits\n   *\n   * _Available since v4.7._\n   */\n  function toInt136(int256 value) internal pure returns (int136 downcasted) {\n    downcasted = int136(value);\n    require(downcasted == value, \"SafeCast: value doesn't fit in 136 bits\");\n  }\n\n  /**\n   * @dev Returns the downcasted int128 from int256, reverting on\n   * overflow (when the input is less than smallest int128 or\n   * greater than largest int128).\n   *\n   * Counterpart to Solidity's `int128` operator.\n   *\n   * Requirements:\n   *\n   * - input must fit into 128 bits\n   *\n   * _Available since v3.1._\n   */\n  function toInt128(int256 value) internal pure returns (int128 downcasted) {\n    downcasted = int128(value);\n    require(downcasted == value, \"SafeCast: value doesn't fit in 128 bits\");\n  }\n\n  /**\n   * @dev Returns the downcasted int120 from int256, reverting on\n   * overflow (when the input is less than smallest int120 or\n   * greater than largest int120).\n   *\n   * Counterpart to Solidity's `int120` operator.\n   *\n   * Requirements:\n   *\n   * - input must fit into 120 bits\n   *\n   * _Available since v4.7._\n   */\n  function toInt120(int256 value) internal pure returns (int120 downcasted) {\n    downcasted = int120(value);\n    require(downcasted == value, \"SafeCast: value doesn't fit in 120 bits\");\n  }\n\n  /**\n   * @dev Returns the downcasted int112 from int256, reverting on\n   * overflow (when the input is less than smallest int112 or\n   * greater than largest int112).\n   *\n   * Counterpart to Solidity's `int112` operator.\n   *\n   * Requirements:\n   *\n   * - input must fit into 112 bits\n   *\n   * _Available since v4.7._\n   */\n  function toInt112(int256 value) internal pure returns (int112 downcasted) {\n    downcasted = int112(value);\n    require(downcasted == value, \"SafeCast: value doesn't fit in 112 bits\");\n  }\n\n  /**\n   * @dev Returns the downcasted int104 from int256, reverting on\n   * overflow (when the input is less than smallest int104 or\n   * greater than largest int104).\n   *\n   * Counterpart to Solidity's `int104` operator.\n   *\n   * Requirements:\n   *\n   * - input must fit into 104 bits\n   *\n   * _Available since v4.7._\n   */\n  function toInt104(int256 value) internal pure returns (int104 downcasted) {\n    downcasted = int104(value);\n    require(downcasted == value, \"SafeCast: value doesn't fit in 104 bits\");\n  }\n\n  /**\n   * @dev Returns the downcasted int96 from int256, reverting on\n   * overflow (when the input is less than smallest int96 or\n   * greater than largest int96).\n   *\n   * Counterpart to Solidity's `int96` operator.\n   *\n   * Requirements:\n   *\n   * - input must fit into 96 bits\n   *\n   * _Available since v4.7._\n   */\n  function toInt96(int256 value) internal pure returns (int96 downcasted) {\n    downcasted = int96(value);\n    require(downcasted == value, \"SafeCast: value doesn't fit in 96 bits\");\n  }\n\n  /**\n   * @dev Returns the downcasted int88 from int256, reverting on\n   * overflow (when the input is less than smallest int88 or\n   * greater than largest int88).\n   *\n   * Counterpart to Solidity's `int88` operator.\n   *\n   * Requirements:\n   *\n   * - input must fit into 88 bits\n   *\n   * _Available since v4.7._\n   */\n  function toInt88(int256 value) internal pure returns (int88 downcasted) {\n    downcasted = int88(value);\n    require(downcasted == value, \"SafeCast: value doesn't fit in 88 bits\");\n  }\n\n  /**\n   * @dev Returns the downcasted int80 from int256, reverting on\n   * overflow (when the input is less than smallest int80 or\n   * greater than largest int80).\n   *\n   * Counterpart to Solidity's `int80` operator.\n   *\n   * Requirements:\n   *\n   * - input must fit into 80 bits\n   *\n   * _Available since v4.7._\n   */\n  function toInt80(int256 value) internal pure returns (int80 downcasted) {\n    downcasted = int80(value);\n    require(downcasted == value, \"SafeCast: value doesn't fit in 80 bits\");\n  }\n\n  /**\n   * @dev Returns the downcasted int72 from int256, reverting on\n   * overflow (when the input is less than smallest int72 or\n   * greater than largest int72).\n   *\n   * Counterpart to Solidity's `int72` operator.\n   *\n   * Requirements:\n   *\n   * - input must fit into 72 bits\n   *\n   * _Available since v4.7._\n   */\n  function toInt72(int256 value) internal pure returns (int72 downcasted) {\n    downcasted = int72(value);\n    require(downcasted == value, \"SafeCast: value doesn't fit in 72 bits\");\n  }\n\n  /**\n   * @dev Returns the downcasted int64 from int256, reverting on\n   * overflow (when the input is less than smallest int64 or\n   * greater than largest int64).\n   *\n   * Counterpart to Solidity's `int64` operator.\n   *\n   * Requirements:\n   *\n   * - input must fit into 64 bits\n   *\n   * _Available since v3.1._\n   */\n  function toInt64(int256 value) internal pure returns (int64 downcasted) {\n    downcasted = int64(value);\n    require(downcasted == value, \"SafeCast: value doesn't fit in 64 bits\");\n  }\n\n  /**\n   * @dev Returns the downcasted int56 from int256, reverting on\n   * overflow (when the input is less than smallest int56 or\n   * greater than largest int56).\n   *\n   * Counterpart to Solidity's `int56` operator.\n   *\n   * Requirements:\n   *\n   * - input must fit into 56 bits\n   *\n   * _Available since v4.7._\n   */\n  function toInt56(int256 value) internal pure returns (int56 downcasted) {\n    downcasted = int56(value);\n    require(downcasted == value, \"SafeCast: value doesn't fit in 56 bits\");\n  }\n\n  /**\n   * @dev Returns the downcasted int48 from int256, reverting on\n   * overflow (when the input is less than smallest int48 or\n   * greater than largest int48).\n   *\n   * Counterpart to Solidity's `int48` operator.\n   *\n   * Requirements:\n   *\n   * - input must fit into 48 bits\n   *\n   * _Available since v4.7._\n   */\n  function toInt48(int256 value) internal pure returns (int48 downcasted) {\n    downcasted = int48(value);\n    require(downcasted == value, \"SafeCast: value doesn't fit in 48 bits\");\n  }\n\n  /**\n   * @dev Returns the downcasted int40 from int256, reverting on\n   * overflow (when the input is less than smallest int40 or\n   * greater than largest int40).\n   *\n   * Counterpart to Solidity's `int40` operator.\n   *\n   * Requirements:\n   *\n   * - input must fit into 40 bits\n   *\n   * _Available since v4.7._\n   */\n  function toInt40(int256 value) internal pure returns (int40 downcasted) {\n    downcasted = int40(value);\n    require(downcasted == value, \"SafeCast: value doesn't fit in 40 bits\");\n  }\n\n  /**\n   * @dev Returns the downcasted int32 from int256, reverting on\n   * overflow (when the input is less than smallest int32 or\n   * greater than largest int32).\n   *\n   * Counterpart to Solidity's `int32` operator.\n   *\n   * Requirements:\n   *\n   * - input must fit into 32 bits\n   *\n   * _Available since v3.1._\n   */\n  function toInt32(int256 value) internal pure returns (int32 downcasted) {\n    downcasted = int32(value);\n    require(downcasted == value, \"SafeCast: value doesn't fit in 32 bits\");\n  }\n\n  /**\n   * @dev Returns the downcasted int24 from int256, reverting on\n   * overflow (when the input is less than smallest int24 or\n   * greater than largest int24).\n   *\n   * Counterpart to Solidity's `int24` operator.\n   *\n   * Requirements:\n   *\n   * - input must fit into 24 bits\n   *\n   * _Available since v4.7._\n   */\n  function toInt24(int256 value) internal pure returns (int24 downcasted) {\n    downcasted = int24(value);\n    require(downcasted == value, \"SafeCast: value doesn't fit in 24 bits\");\n  }\n\n  /**\n   * @dev Returns the downcasted int16 from int256, reverting on\n   * overflow (when the input is less than smallest int16 or\n   * greater than largest int16).\n   *\n   * Counterpart to Solidity's `int16` operator.\n   *\n   * Requirements:\n   *\n   * - input must fit into 16 bits\n   *\n   * _Available since v3.1._\n   */\n  function toInt16(int256 value) internal pure returns (int16 downcasted) {\n    downcasted = int16(value);\n    require(downcasted == value, \"SafeCast: value doesn't fit in 16 bits\");\n  }\n\n  /**\n   * @dev Returns the downcasted int8 from int256, reverting on\n   * overflow (when the input is less than smallest int8 or\n   * greater than largest int8).\n   *\n   * Counterpart to Solidity's `int8` operator.\n   *\n   * Requirements:\n   *\n   * - input must fit into 8 bits\n   *\n   * _Available since v3.1._\n   */\n  function toInt8(int256 value) internal pure returns (int8 downcasted) {\n    downcasted = int8(value);\n    require(downcasted == value, \"SafeCast: value doesn't fit in 8 bits\");\n  }\n\n  /**\n   * @dev Converts an unsigned uint256 into a signed int256.\n   *\n   * Requirements:\n   *\n   * - input must be less than or equal to maxInt256.\n   *\n   * _Available since v3.0._\n   */\n  function toInt256(uint256 value) internal pure returns (int256) {\n    // Note: Unsafe cast below is okay because `type(int256).max` is guaranteed to be positive\n    require(value <= uint256(type(int256).max), \"SafeCast: value doesn't fit in an int256\");\n    return int256(value);\n  }\n}\n"},"lib/solidity-utils/src/contracts/oz-common/SafeERC20.sol":{"content":"// SPDX-License-Identifier: MIT\n// OpenZeppelin Contracts (last updated v4.7.0) (token/ERC20/utils/SafeERC20.sol)\n// From commit https://github.com/OpenZeppelin/openzeppelin-contracts/commit/3dac7bbed7b4c0dbf504180c33e8ed8e350b93eb\n\npragma solidity ^0.8.0;\n\nimport './interfaces/IERC20.sol';\nimport './interfaces/draft-IERC20Permit.sol';\nimport './Address.sol';\n\n/**\n * @title SafeERC20\n * @dev Wrappers around ERC20 operations that throw on failure (when the token\n * contract returns false). Tokens that return no value (and instead revert or\n * throw on failure) are also supported, non-reverting calls are assumed to be\n * successful.\n * To use this library you can add a `using SafeERC20 for IERC20;` statement to your contract,\n * which allows you to call the safe operations as `token.safeTransfer(...)`, etc.\n */\nlibrary SafeERC20 {\n  using Address for address;\n\n  function safeTransfer(IERC20 token, address to, uint256 value) internal {\n    _callOptionalReturn(token, abi.encodeWithSelector(token.transfer.selector, to, value));\n  }\n\n  function safeTransferFrom(IERC20 token, address from, address to, uint256 value) internal {\n    _callOptionalReturn(\n      token,\n      abi.encodeWithSelector(token.transferFrom.selector, from, to, value)\n    );\n  }\n\n  /**\n   * @dev Deprecated. This function has issues similar to the ones found in\n   * {IERC20-approve}, and its usage is discouraged.\n   *\n   * Whenever possible, use {safeIncreaseAllowance} and\n   * {safeDecreaseAllowance} instead.\n   */\n  function safeApprove(IERC20 token, address spender, uint256 value) internal {\n    // safeApprove should only be called when setting an initial allowance,\n    // or when resetting it to zero. To increase and decrease it, use\n    // 'safeIncreaseAllowance' and 'safeDecreaseAllowance'\n    require(\n      (value == 0) || (token.allowance(address(this), spender) == 0),\n      'SafeERC20: approve from non-zero to non-zero allowance'\n    );\n    _callOptionalReturn(token, abi.encodeWithSelector(token.approve.selector, spender, value));\n  }\n\n  function safeIncreaseAllowance(IERC20 token, address spender, uint256 value) internal {\n    uint256 newAllowance = token.allowance(address(this), spender) + value;\n    _callOptionalReturn(\n      token,\n      abi.encodeWithSelector(token.approve.selector, spender, newAllowance)\n    );\n  }\n\n  function safeDecreaseAllowance(IERC20 token, address spender, uint256 value) internal {\n    unchecked {\n      uint256 oldAllowance = token.allowance(address(this), spender);\n      require(oldAllowance >= value, 'SafeERC20: decreased allowance below zero');\n      uint256 newAllowance = oldAllowance - value;\n      _callOptionalReturn(\n        token,\n        abi.encodeWithSelector(token.approve.selector, spender, newAllowance)\n      );\n    }\n  }\n\n  function safePermit(\n    IERC20Permit token,\n    address owner,\n    address spender,\n    uint256 value,\n    uint256 deadline,\n    uint8 v,\n    bytes32 r,\n    bytes32 s\n  ) internal {\n    uint256 nonceBefore = token.nonces(owner);\n    token.permit(owner, spender, value, deadline, v, r, s);\n    uint256 nonceAfter = token.nonces(owner);\n    require(nonceAfter == nonceBefore + 1, 'SafeERC20: permit did not succeed');\n  }\n\n  /**\n   * @dev Imitates a Solidity high-level call (i.e. a regular function call to a contract), relaxing the requirement\n   * on the return value: the return value is optional (but if data is returned, it must not be false).\n   * @param token The token targeted by the call.\n   * @param data The call data (encoded using abi.encode or one of its variants).\n   */\n  function _callOptionalReturn(IERC20 token, bytes memory data) private {\n    // We need to perform a low level call here, to bypass Solidity's return data size checking mechanism, since\n    // we're implementing it ourselves. We use {Address.functionCall} to perform this call, which verifies that\n    // the target address contains contract code and also asserts for success in the low-level call.\n\n    bytes memory returndata = address(token).functionCall(data, 'SafeERC20: low-level call failed');\n    if (returndata.length > 0) {\n      // Return data is optional\n      require(abi.decode(returndata, (bool)), 'SafeERC20: ERC20 operation did not succeed');\n    }\n  }\n}\n"},"src/contracts/payloads/interfaces/IPayloadsController.sol":{"content":"// SPDX-License-Identifier: MIT\npragma solidity ^0.8.0;\n\nimport {IBaseReceiverPortal} from 'aave-crosschain-infra/contracts/interfaces/IBaseReceiverPortal.sol';\nimport {IPayloadsControllerCore} from './IPayloadsControllerCore.sol';\nimport {PayloadsControllerUtils} from '../PayloadsControllerUtils.sol';\n\n/**\n * @title IPayloadsController\n * @author BGD Labs\n * @notice interface containing the objects, events and methods definitions of the PayloadsController contract\n */\ninterface IPayloadsController is IBaseReceiverPortal, IPayloadsControllerCore {\n  /**\n   * @notice get contract address from where the messages come\n   * @return address of the message registry\n   */\n  function CROSS_CHAIN_CONTROLLER() external view returns (address);\n\n  /**\n   * @notice get chain id of the message originator network\n   * @return chain id of the originator network\n   */\n  function ORIGIN_CHAIN_ID() external view returns (uint256);\n\n  /**\n   * @notice get address of the message sender in originator network\n   * @return address of the originator contract\n   */\n  function MESSAGE_ORIGINATOR() external view returns (address);\n\n  /**\n   * @notice method to decode a message from from governance chain\n   * @param message encoded message with message type\n   * @return payloadId, accessLevel, proposalVoteActivationTimestamp from the decoded message\n   */\n  function decodeMessage(\n    bytes memory message\n  )\n    external\n    pure\n    returns (uint40, PayloadsControllerUtils.AccessControl, uint40);\n}\n"},"src/contracts/payloads/interfaces/IPayloadsControllerCore.sol":{"content":"// SPDX-License-Identifier: MIT\npragma solidity ^0.8.0;\n\nimport {IRescuable} from 'solidity-utils/contracts/utils/interfaces/IRescuable.sol';\nimport {PayloadsControllerUtils} from '../PayloadsControllerUtils.sol';\n\n/**\n * @title IPayloadsControllerCore\n * @author BGD Labs\n * @notice interface containing the objects, events and methods definitions of the IPayloadsControllerCore contract\n */\ninterface IPayloadsControllerCore is IRescuable {\n  /**\n   * @notice Enum indicating the possible payload states\n   * @dev PayloadState enum defines the state machine of a payload, so the order on which the state is\n          defined is important. Check logic correctness if new states are added / removed\n   */\n  enum PayloadState {\n    None, // state 0 left as empty\n    Created,\n    Queued,\n    Executed,\n    Cancelled,\n    Expired\n  }\n\n  /**\n   * @notice holds configuration of the executor\n   * @param executor address of the executor\n   * @param delay time in seconds between queuing and execution\n   */\n  struct ExecutorConfig {\n    address executor;\n    uint40 delay;\n  }\n\n  /**\n   * @notice Object containing the information necessary to set a new executor\n   * @param accessLevel level of access that the executor will be assigned to\n   * @param executorConfig object containing the configurations for the accessLevel specified\n   */\n  struct UpdateExecutorInput {\n    PayloadsControllerUtils.AccessControl accessLevel;\n    ExecutorConfig executorConfig;\n  }\n\n  /**\n   * @notice Object containing the information necessary to define a payload action\n   * @param target address of the contract that needs to be executed\n   * @param withDelegateCall boolean indicating if execution needs to be delegated\n   * @param accessLevel access level of the executor needed for the execution\n   * @param value value amount that needs to be sent to the executeTransaction method\n   * @param signature method signature that will be executed\n   * @param callData data needed for the execution of the signature\n   */\n  struct ExecutionAction {\n    address target;\n    bool withDelegateCall;\n    PayloadsControllerUtils.AccessControl accessLevel;\n    uint256 value;\n    string signature;\n    bytes callData;\n  }\n\n  /**\n   * @notice Object containing a payload information\n   * @param creator address of the createPayload method caller\n   * @param maximumAccessLevelRequired min level needed to be able to execute all actions\n   * @param state indicates the current state of the payload\n   * @param createdAt time indicating when payload has been created. In seconds // max is: 1.099511628×10¹² (ie 34'865 years)\n   * @param queuedAt time indicating when payload has been queued. In seconds  // max is: 1.099511628×10¹² (ie 34'865 years)\n   * @param executedAt time indicating when a payload has been executed. In seconds  // max is: 1.099511628×10¹² (ie 34'865 years)\n   * @param cancelledAt time indicating when the payload has been cancelled. In seconds\n   * @param expirationTime time indicating when the Payload will expire\n   * @param delay time in seconds that a payload must remain queued before execution\n   * @param gracePeriod time in seconds that a payload has to be executed\n   * @param actions array of actions to be executed\n   */\n  struct Payload {\n    address creator;\n    PayloadsControllerUtils.AccessControl maximumAccessLevelRequired;\n    PayloadState state;\n    uint40 createdAt;\n    uint40 queuedAt;\n    uint40 executedAt;\n    uint40 cancelledAt;\n    uint40 expirationTime;\n    uint40 delay;\n    uint40 gracePeriod;\n    ExecutionAction[] actions;\n  }\n\n  /**\n   * @notice Event emitted when an executor has been set for a determined access level\n   * @param accessLevel level of access that the executor will be set to\n   * @param executor address that will be set for the determined access level\n   * @param delay time in seconds between queuing and execution\n   */\n  event ExecutorSet(\n    PayloadsControllerUtils.AccessControl indexed accessLevel,\n    address indexed executor,\n    uint40 delay\n  );\n\n  /**\n   * @notice Event emitted when a payload has been created\n   * @param payloadId id of the payload created\n   * @param creator address pertaining to the caller of the method createPayload\n   * @param actions array of the actions conforming the payload\n   * @param maximumAccessLevelRequired maximum level of the access control\n   */\n  event PayloadCreated(\n    uint40 indexed payloadId,\n    address indexed creator,\n    ExecutionAction[] actions,\n    PayloadsControllerUtils.AccessControl indexed maximumAccessLevelRequired\n  );\n\n  /**\n   * @notice emitted when a cross chain message gets received\n   * @param originSender address that sent the message on the origin chain\n   * @param originChainId id of the chain where the message originated\n   * @param delivered flag indicating if message has been delivered\n   * @param message bytes containing the necessary information to queue the bridged payload id\n   * @param reason bytes with the revert information\n   */\n  event PayloadExecutionMessageReceived(\n    address indexed originSender,\n    uint256 indexed originChainId,\n    bool indexed delivered,\n    bytes message,\n    bytes reason\n  );\n\n  /**\n   * @notice Event emitted when a payload has been executed\n   * @param payloadId id of the payload being enqueued\n   */\n  event PayloadExecuted(uint40 payloadId);\n\n  /**\n   * @notice Event emitted when a payload has been queued\n   * @param payloadId id of the payload being enqueued\n   */\n  event PayloadQueued(uint40 payloadId);\n\n  /**\n   * @notice Event emitted when cancelling a payload\n   * @param payloadId id of the cancelled payload\n   */\n  event PayloadCancelled(uint40 payloadId);\n\n  /**\n   * @notice method to initialize the contract with starter params. Only callable by proxy\n   * @param owner address of the owner of the contract. with permissions to call certain methods\n   * @param guardian address of the guardian. With permissions to call certain methods\n   * @param executors array of executor configurations\n   */\n  function initialize(\n    address owner,\n    address guardian,\n    UpdateExecutorInput[] calldata executors\n  ) external;\n\n  /**\n   * @notice get the expiration delay of a payload\n   * @return expiration delay in seconds\n   */\n  function EXPIRATION_DELAY() external view returns (uint40);\n\n  /**\n   * @notice get the maximum time in seconds that a proposal must spend being queued\n   * @return max delay in seconds\n   */\n  function MAX_EXECUTION_DELAY() external view returns (uint40);\n\n  /**\n   * @notice get the minimum time in seconds that a proposal must spend being queued\n   * @return min delay in seconds\n   */\n  function MIN_EXECUTION_DELAY() external view returns (uint40);\n\n  /**\n   * @notice time in seconds where the proposal can be executed (from executionTime) before it expires\n   * @return grace period in seconds\n   */\n  function GRACE_PERIOD() external view returns (uint40);\n\n  /**\n   * @notice get a previously created payload object\n   * @param payloadId id of the payload to retrieve\n   * @return payload information\n   */\n  function getPayloadById(\n    uint40 payloadId\n  ) external view returns (Payload memory);\n\n  /**\n   * @notice get the current state of a payload\n   * @param payloadId id of the payload to retrieve the state from\n   * @return payload state\n   */\n  function getPayloadState(\n    uint40 payloadId\n  ) external view returns (PayloadState);\n\n  /**\n   * @notice get the total count of payloads created\n   * @return number of payloads\n   */\n  function getPayloadsCount() external view returns (uint40);\n\n  /**\n   * @notice method that will create a Payload object for every action sent\n   * @param actions array of actions which this proposal payload will contain\n   * @return id of the created payload\n   */\n  function createPayload(\n    ExecutionAction[] calldata actions\n  ) external returns (uint40);\n\n  /**\n   * @notice method to execute a payload\n   * @param payloadId id of the payload that needs to be executed\n   */\n  function executePayload(uint40 payloadId) external payable;\n\n  /**\n   * @notice method to cancel a payload\n   * @param payloadId id of the payload that needs to be canceled\n   */\n  function cancelPayload(uint40 payloadId) external;\n\n  /**\n   * @notice method to add executors and its configuration\n   * @param executors array of UpdateExecutorInput objects\n   */\n  function updateExecutors(UpdateExecutorInput[] calldata executors) external;\n\n  /**\n   * @notice method to get the executor configuration assigned to the specified level\n   * @param accessControl level of which we want to get the executor configuration from\n   * @return executor configuration\n   */\n  function getExecutorSettingsByAccessControl(\n    PayloadsControllerUtils.AccessControl accessControl\n  ) external view returns (ExecutorConfig memory);\n}\n"},"lib/solidity-utils/src/contracts/oz-common/interfaces/IERC20.sol":{"content":"// SPDX-License-Identifier: MIT\n// OpenZeppelin Contracts (last updated v4.6.0) (token/ERC20/IERC20.sol)\n// From commit https://github.com/OpenZeppelin/openzeppelin-contracts/commit/a035b235b4f2c9af4ba88edc4447f02e37f8d124\n\npragma solidity ^0.8.0;\n\n/**\n * @dev Interface of the ERC20 standard as defined in the EIP.\n */\ninterface IERC20 {\n  /**\n   * @dev Emitted when `value` tokens are moved from one account (`from`) to\n   * another (`to`).\n   *\n   * Note that `value` may be zero.\n   */\n  event Transfer(address indexed from, address indexed to, uint256 value);\n\n  /**\n   * @dev Emitted when the allowance of a `spender` for an `owner` is set by\n   * a call to {approve}. `value` is the new allowance.\n   */\n  event Approval(address indexed owner, address indexed spender, uint256 value);\n\n  /**\n   * @dev Returns the amount of tokens in existence.\n   */\n  function totalSupply() external view returns (uint256);\n\n  /**\n   * @dev Returns the amount of tokens owned by `account`.\n   */\n  function balanceOf(address account) external view returns (uint256);\n\n  /**\n   * @dev Moves `amount` tokens from the caller's account to `to`.\n   *\n   * Returns a boolean value indicating whether the operation succeeded.\n   *\n   * Emits a {Transfer} event.\n   */\n  function transfer(address to, uint256 amount) external returns (bool);\n\n  /**\n   * @dev Returns the remaining number of tokens that `spender` will be\n   * allowed to spend on behalf of `owner` through {transferFrom}. This is\n   * zero by default.\n   *\n   * This value changes when {approve} or {transferFrom} are called.\n   */\n  function allowance(address owner, address spender) external view returns (uint256);\n\n  /**\n   * @dev Sets `amount` as the allowance of `spender` over the caller's tokens.\n   *\n   * Returns a boolean value indicating whether the operation succeeded.\n   *\n   * IMPORTANT: Beware that changing an allowance with this method brings the risk\n   * that someone may use both the old and the new allowance by unfortunate\n   * transaction ordering. One possible solution to mitigate this race\n   * condition is to first reduce the spender's allowance to 0 and set the\n   * desired value afterwards:\n   * https://github.com/ethereum/EIPs/issues/20#issuecomment-263524729\n   *\n   * Emits an {Approval} event.\n   */\n  function approve(address spender, uint256 amount) external returns (bool);\n\n  /**\n   * @dev Moves `amount` tokens from `from` to `to` using the\n   * allowance mechanism. `amount` is then deducted from the caller's\n   * allowance.\n   *\n   * Returns a boolean value indicating whether the operation succeeded.\n   *\n   * Emits a {Transfer} event.\n   */\n  function transferFrom(address from, address to, uint256 amount) external returns (bool);\n}\n"},"lib/solidity-utils/src/contracts/utils/interfaces/IRescuable.sol":{"content":"// SPDX-License-Identifier: MIT\npragma solidity ^0.8.8;\n\n/**\n * @title IRescuable\n * @author BGD Labs\n * @notice interface containing the objects, events and methods definitions of the Rescuable contract\n */\ninterface IRescuable {\n  /**\n   * @notice emitted when erc20 tokens get rescued\n   * @param caller address that triggers the rescue\n   * @param token address of the rescued token\n   * @param to address that will receive the rescued tokens\n   * @param amount quantity of tokens rescued\n   */\n  event ERC20Rescued(\n    address indexed caller,\n    address indexed token,\n    address indexed to,\n    uint256 amount\n  );\n\n  /**\n   * @notice emitted when native tokens get rescued\n   * @param caller address that triggers the rescue\n   * @param to address that will receive the rescued tokens\n   * @param amount quantity of tokens rescued\n   */\n  event NativeTokensRescued(address indexed caller, address indexed to, uint256 amount);\n\n  /**\n   * @notice method called to rescue tokens sent erroneously to the contract. Only callable by owner\n   * @param erc20Token address of the token to rescue\n   * @param to address to send the tokens\n   * @param amount of tokens to rescue\n   */\n  function emergencyTokenTransfer(address erc20Token, address to, uint256 amount) external;\n\n  /**\n   * @notice method called to rescue ether sent erroneously to the contract. Only callable by owner\n   * @param to address to send the eth\n   * @param amount of eth to rescue\n   */\n  function emergencyEtherTransfer(address to, uint256 amount) external;\n\n  /**\n   * @notice method that defines the address that is allowed to rescue tokens\n   * @return the allowed address\n   */\n  function whoCanRescue() external view returns (address);\n}\n"},"lib/solidity-utils/src/contracts/transparent-proxy/Initializable.sol":{"content":"// SPDX-License-Identifier: MIT\n\n/**\n * @dev OpenZeppelin Contracts (last updated v4.7.0) (proxy/utils/Initializable.sol)\n * From https://github.com/OpenZeppelin/openzeppelin-contracts/tree/8b778fa20d6d76340c5fac1ed66c80273f05b95a\n *\n * BGD Labs adaptations:\n * - Added a constructor disabling initialization for implementation contracts\n * - Linting\n */\n\npragma solidity ^0.8.2;\n\nimport '../oz-common/Address.sol';\n\n/**\n * @dev This is a base contract to aid in writing upgradeable contracts, or any kind of contract that will be deployed\n * behind a proxy. Since proxied contracts do not make use of a constructor, it's common to move constructor logic to an\n * external initializer function, usually called `initialize`. It then becomes necessary to protect this initializer\n * function so it can only be called once. The {initializer} modifier provided by this contract will have this effect.\n *\n * The initialization functions use a version number. Once a version number is used, it is consumed and cannot be\n * reused. This mechanism prevents re-execution of each \"step\" but allows the creation of new initialization steps in\n * case an upgrade adds a module that needs to be initialized.\n *\n * For example:\n *\n * [.hljs-theme-light.nopadding]\n * ```\n * contract MyToken is ERC20Upgradeable {\n *     function initialize() initializer public {\n *         __ERC20_init(\"MyToken\", \"MTK\");\n *     }\n * }\n * contract MyTokenV2 is MyToken, ERC20PermitUpgradeable {\n *     function initializeV2() reinitializer(2) public {\n *         __ERC20Permit_init(\"MyToken\");\n *     }\n * }\n * ```\n *\n * TIP: To avoid leaving the proxy in an uninitialized state, the initializer function should be called as early as\n * possible by providing the encoded function call as the `_data` argument to {ERC1967Proxy-constructor}.\n *\n * CAUTION: When used with inheritance, manual care must be taken to not invoke a parent initializer twice, or to ensure\n * that all initializers are idempotent. This is not verified automatically as constructors are by Solidity.\n *\n * [CAUTION]\n * ====\n * Avoid leaving a contract uninitialized.\n *\n * An uninitialized contract can be taken over by an attacker. This applies to both a proxy and its implementation\n * contract, which may impact the proxy. To prevent the implementation contract from being used, you should invoke\n * the {_disableInitializers} function in the constructor to automatically lock it when it is deployed:\n *\n * [.hljs-theme-light.nopadding]\n * ```\n * /// @custom:oz-upgrades-unsafe-allow constructor\n * constructor() {\n *     _disableInitializers();\n * }\n * ```\n * ====\n */\nabstract contract Initializable {\n  /**\n   * @dev Indicates that the contract has been initialized.\n   * @custom:oz-retyped-from bool\n   */\n  uint8 private _initialized;\n\n  /**\n   * @dev Indicates that the contract is in the process of being initialized.\n   */\n  bool private _initializing;\n\n  /**\n   * @dev Triggered when the contract has been initialized or reinitialized.\n   */\n  event Initialized(uint8 version);\n\n  /**\n   * @dev OPINIONATED. Generally is not a good practise to allow initialization of implementations\n   */\n  constructor() {\n    _disableInitializers();\n  }\n\n  /**\n   * @dev A modifier that defines a protected initializer function that can be invoked at most once. In its scope,\n   * `onlyInitializing` functions can be used to initialize parent contracts. Equivalent to `reinitializer(1)`.\n   */\n  modifier initializer() {\n    bool isTopLevelCall = !_initializing;\n    require(\n      (isTopLevelCall && _initialized < 1) ||\n        (!Address.isContract(address(this)) && _initialized == 1),\n      'Initializable: contract is already initialized'\n    );\n    _initialized = 1;\n    if (isTopLevelCall) {\n      _initializing = true;\n    }\n    _;\n    if (isTopLevelCall) {\n      _initializing = false;\n      emit Initialized(1);\n    }\n  }\n\n  /**\n   * @dev A modifier that defines a protected reinitializer function that can be invoked at most once, and only if the\n   * contract hasn't been initialized to a greater version before. In its scope, `onlyInitializing` functions can be\n   * used to initialize parent contracts.\n   *\n   * `initializer` is equivalent to `reinitializer(1)`, so a reinitializer may be used after the original\n   * initialization step. This is essential to configure modules that are added through upgrades and that require\n   * initialization.\n   *\n   * Note that versions can jump in increments greater than 1; this implies that if multiple reinitializers coexist in\n   * a contract, executing them in the right order is up to the developer or operator.\n   */\n  modifier reinitializer(uint8 version) {\n    require(\n      !_initializing && _initialized < version,\n      'Initializable: contract is already initialized'\n    );\n    _initialized = version;\n    _initializing = true;\n    _;\n    _initializing = false;\n    emit Initialized(version);\n  }\n\n  /**\n   * @dev Modifier to protect an initialization function so that it can only be invoked by functions with the\n   * {initializer} and {reinitializer} modifiers, directly or indirectly.\n   */\n  modifier onlyInitializing() {\n    require(_initializing, 'Initializable: contract is not initializing');\n    _;\n  }\n\n  /**\n   * @dev Locks the contract, preventing any future reinitialization. This cannot be part of an initializer call.\n   * Calling this in the constructor of a contract will prevent that contract from being initialized or reinitialized\n   * to any version. It is recommended to use this to lock implementation contracts that are designed to be called\n   * through proxies.\n   */\n  function _disableInitializers() internal virtual {\n    require(!_initializing, 'Initializable: contract is initializing');\n    if (_initialized < type(uint8).max) {\n      _initialized = type(uint8).max;\n      emit Initialized(type(uint8).max);\n    }\n  }\n}\n"},"lib/solidity-utils/src/contracts/access-control/OwnableWithGuardian.sol":{"content":"// SPDX-License-Identifier: MIT\npragma solidity >=0.7.0;\n\nimport {IWithGuardian} from './interfaces/IWithGuardian.sol';\nimport {Ownable} from '../oz-common/Ownable.sol';\n\nabstract contract OwnableWithGuardian is Ownable, IWithGuardian {\n  address private _guardian;\n\n  constructor() {\n    _updateGuardian(_msgSender());\n  }\n\n  modifier onlyGuardian() {\n    _checkGuardian();\n    _;\n  }\n\n  modifier onlyOwnerOrGuardian() {\n    _checkOwnerOrGuardian();\n    _;\n  }\n\n  function guardian() public view override returns (address) {\n    return _guardian;\n  }\n\n  /// @inheritdoc IWithGuardian\n  function updateGuardian(address newGuardian) external override onlyOwnerOrGuardian {\n    _updateGuardian(newGuardian);\n  }\n\n  /**\n   * @dev method to update the guardian\n   * @param newGuardian the new guardian address\n   */\n  function _updateGuardian(address newGuardian) internal {\n    address oldGuardian = _guardian;\n    _guardian = newGuardian;\n    emit GuardianUpdated(oldGuardian, newGuardian);\n  }\n\n  function _checkGuardian() internal view {\n    require(guardian() == _msgSender(), 'ONLY_BY_GUARDIAN');\n  }\n\n  function _checkOwnerOrGuardian() internal view {\n    require(_msgSender() == owner() || _msgSender() == guardian(), 'ONLY_BY_OWNER_OR_GUARDIAN');\n  }\n}\n"},"lib/aave-crosschain-infra/src/contracts/interfaces/IBaseReceiverPortal.sol":{"content":"// SPDX-License-Identifier: MIT\npragma solidity ^0.8.0;\n\n/**\n * @title IBaseReceiverPortal\n * @author BGD Labs\n * @notice interface defining the method that needs to be implemented by all receiving portals, as its the one that\n           will be called when a received message gets confirmed\n */\ninterface IBaseReceiverPortal {\n  /**\n   * @notice method called by CrossChainController when a message has been confirmed\n   * @param originSender address of the sender of the bridged message\n   * @param originChainId id of the chain where the message originated\n   * @param message bytes bridged containing the desired information\n   */\n  function receiveCrossChainMessage(\n    address originSender,\n    uint256 originChainId,\n    bytes memory message\n  ) external;\n}\n"},"lib/solidity-utils/src/contracts/access-control/interfaces/IWithGuardian.sol":{"content":"// SPDX-License-Identifier: MIT\npragma solidity >=0.7.0;\n\ninterface IWithGuardian {\n  /**\n   * @dev Event emitted when guardian gets updated\n   * @param oldGuardian address of previous guardian\n   * @param newGuardian address of the new guardian\n   */\n  event GuardianUpdated(address oldGuardian, address newGuardian);\n\n  /**\n   * @dev get guardian address;\n   */\n  function guardian() external view returns (address);\n\n  /**\n   * @dev method to update the guardian\n   * @param newGuardian the new guardian address\n   */\n  function updateGuardian(address newGuardian) external;\n}\n"},"lib/solidity-utils/src/contracts/oz-common/interfaces/draft-IERC20Permit.sol":{"content":"// SPDX-License-Identifier: MIT\n// OpenZeppelin Contracts v4.4.1 (token/ERC20/extensions/draft-IERC20Permit.sol)\n// From commit https://github.com/OpenZeppelin/openzeppelin-contracts/commit/6bd6b76d1156e20e45d1016f355d154141c7e5b9\n\npragma solidity ^0.8.0;\n\n/**\n * @dev Interface of the ERC20 Permit extension allowing approvals to be made via signatures, as defined in\n * https://eips.ethereum.org/EIPS/eip-2612[EIP-2612].\n *\n * Adds the {permit} method, which can be used to change an account's ERC20 allowance (see {IERC20-allowance}) by\n * presenting a message signed by the account. By not relying on {IERC20-approve}, the token holder account doesn't\n * need to send a transaction, and thus is not required to hold Ether at all.\n */\ninterface IERC20Permit {\n  /**\n   * @dev Sets `value` as the allowance of `spender` over ``owner``'s tokens,\n   * given ``owner``'s signed approval.\n   *\n   * IMPORTANT: The same issues {IERC20-approve} has related to transaction\n   * ordering also apply here.\n   *\n   * Emits an {Approval} event.\n   *\n   * Requirements:\n   *\n   * - `spender` cannot be the zero address.\n   * - `deadline` must be a timestamp in the future.\n   * - `v`, `r` and `s` must be a valid `secp256k1` signature from `owner`\n   * over the EIP712-formatted function arguments.\n   * - the signature must use ``owner``'s current nonce (see {nonces}).\n   *\n   * For more information on the signature format, see the\n   * https://eips.ethereum.org/EIPS/eip-2612#specification[relevant EIP\n   * section].\n   */\n  function permit(\n    address owner,\n    address spender,\n    uint256 value,\n    uint256 deadline,\n    uint8 v,\n    bytes32 r,\n    bytes32 s\n  ) external;\n\n  /**\n   * @dev Returns the current nonce for `owner`. This value must be\n   * included whenever a signature is generated for {permit}.\n   *\n   * Every successful call to {permit} increases ``owner``'s nonce by one. This\n   * prevents a signature from being used multiple times.\n   */\n  function nonces(address owner) external view returns (uint256);\n\n  /**\n   * @dev Returns the domain separator used in the encoding of the signature for {permit}, as defined by {EIP712}.\n   */\n  // solhint-disable-next-line func-name-mixedcase\n  function DOMAIN_SEPARATOR() external view returns (bytes32);\n}\n"}},"abi":[{"type":"constructor","inputs":[{"name":"crossChainController","type":"address","internalType":"address"},{"name":"messageOriginator","type":"address","internalType":"address"},{"name":"originChainId","type":"uint256","internalType":"uint256"}],"stateMutability":"nonpayable"},{"name":"ERC20Rescued","type":"event","inputs":[{"name":"caller","type":"address","indexed":true,"internalType":"address"},{"name":"token","type":"address","indexed":true,"internalType":"address"},{"name":"to","type":"address","indexed":true,"internalType":"address"},{"name":"amount","type":"uint256","indexed":false,"internalType":"uint256"}],"anonymous":false},{"name":"ExecutorSet","type":"event","inputs":[{"name":"accessLevel","type":"uint8","indexed":true,"internalType":"enum PayloadsControllerUtils.AccessControl"},{"name":"executor","type":"address","indexed":true,"internalType":"address"},{"name":"delay","type":"uint40","indexed":false,"internalType":"uint40"}],"anonymous":false},{"name":"GuardianUpdated","type":"event","inputs":[{"name":"oldGuardian","type":"address","indexed":false,"internalType":"address"},{"name":"newGuardian","type":"address","indexed":false,"internalType":"address"}],"anonymous":false},{"name":"Initialized","type":"event","inputs":[{"name":"version","type":"uint8","indexed":false,"internalType":"uint8"}],"anonymous":false},{"name":"NativeTokensRescued","type":"event","inputs":[{"name":"caller","type":"address","indexed":true,"internalType":"address"},{"name":"to","type":"address","indexed":true,"internalType":"address"},{"name":"amount","type":"uint256","indexed":false,"internalType":"uint256"}],"anonymous":false},{"name":"OwnershipTransferred","type":"event","inputs":[{"name":"previousOwner","type":"address","indexed":true,"internalType":"address"},{"name":"newOwner","type":"address","indexed":true,"internalType":"address"}],"anonymous":false},{"name":"PayloadCancelled","type":"event","inputs":[{"name":"payloadId","type":"uint40","indexed":false,"internalType":"uint40"}],"anonymous":false},{"name":"PayloadCreated","type":"event","inputs":[{"name":"payloadId","type":"uint40","indexed":true,"internalType":"uint40"},{"name":"creator","type":"address","indexed":true,"internalType":"address"},{"name":"actions","type":"tuple[]","indexed":false,"components":[{"name":"target","type":"address","internalType":"address"},{"name":"withDelegateCall","type":"bool","internalType":"bool"},{"name":"accessLevel","type":"uint8","internalType":"enum PayloadsControllerUtils.AccessControl"},{"name":"value","type":"uint256","internalType":"uint256"},{"name":"signature","type":"string","internalType":"string"},{"name":"callData","type":"bytes","internalType":"bytes"}],"internalType":"struct IPayloadsControllerCore.ExecutionAction[]"},{"name":"maximumAccessLevelRequired","type":"uint8","indexed":true,"internalType":"enum PayloadsControllerUtils.AccessControl"}],"anonymous":false},{"name":"PayloadExecuted","type":"event","inputs":[{"name":"payloadId","type":"uint40","indexed":false,"internalType":"uint40"}],"anonymous":false},{"name":"PayloadExecutionMessageReceived","type":"event","inputs":[{"name":"originSender","type":"address","indexed":true,"internalType":"address"},{"name":"originChainId","type":"uint256","indexed":true,"internalType":"uint256"},{"name":"delivered","type":"bool","indexed":true,"internalType":"bool"},{"name":"message","type":"bytes","indexed":false,"internalType":"bytes"},{"name":"reason","type":"bytes","indexed":false,"internalType":"bytes"}],"anonymous":false},{"name":"PayloadQueued","type":"event","inputs":[{"name":"payloadId","type":"uint40","indexed":false,"internalType":"uint40"}],"anonymous":false},{"name":"CROSS_CHAIN_CONTROLLER","type":"function","inputs":[],"outputs":[{"name":"","type":"address","internalType":"address"}],"stateMutability":"view"},{"name":"EXPIRATION_DELAY","type":"function","inputs":[],"outputs":[{"name":"","type":"uint40","internalType":"uint40"}],"stateMutability":"view"},{"name":"GRACE_PERIOD","type":"function","inputs":[],"outputs":[{"name":"","type":"uint40","internalType":"uint40"}],"stateMutability":"view"},{"name":"MAX_EXECUTION_DELAY","type":"function","inputs":[],"outputs":[{"name":"","type":"uint40","internalType":"uint40"}],"stateMutability":"view"},{"name":"MESSAGE_ORIGINATOR","type":"function","inputs":[],"outputs":[{"name":"","type":"address","internalType":"address"}],"stateMutability":"view"},{"name":"MIN_EXECUTION_DELAY","type":"function","inputs":[],"outputs":[{"name":"","type":"uint40","internalType":"uint40"}],"stateMutability":"view"},{"name":"ORIGIN_CHAIN_ID","type":"function","inputs":[],"outputs":[{"name":"","type":"uint256","internalType":"uint256"}],"stateMutability":"view"},{"name":"cancelPayload","type":"function","inputs":[{"name":"payloadId","type":"uint40","internalType":"uint40"}],"outputs":[],"stateMutability":"nonpayable"},{"name":"createPayload","type":"function","inputs":[{"name":"actions","type":"tuple[]","components":[{"name":"target","type":"address","internalType":"address"},{"name":"withDelegateCall","type":"bool","internalType":"bool"},{"name":"accessLevel","type":"uint8","internalType":"enum PayloadsControllerUtils.AccessControl"},{"name":"value","type":"uint256","internalType":"uint256"},{"name":"signature","type":"string","internalType":"string"},{"name":"callData","type":"bytes","internalType":"bytes"}],"internalType":"struct IPayloadsControllerCore.ExecutionAction[]"}],"outputs":[{"name":"","type":"uint40","internalType":"uint40"}],"stateMutability":"nonpayable"},{"name":"decodeMessage","type":"function","inputs":[{"name":"message","type":"bytes","internalType":"bytes"}],"outputs":[{"name":"","type":"uint40","internalType":"uint40"},{"name":"","type":"uint8","internalType":"enum PayloadsControllerUtils.AccessControl"},{"name":"","type":"uint40","internalType":"uint40"}],"stateMutability":"pure"},{"name":"emergencyEtherTransfer","type":"function","inputs":[{"name":"to","type":"address","internalType":"address"},{"name":"amount","type":"uint256","internalType":"uint256"}],"outputs":[],"stateMutability":"nonpayable"},{"name":"emergencyTokenTransfer","type":"function","inputs":[{"name":"erc20Token","type":"address","internalType":"address"},{"name":"to","type":"address","internalType":"address"},{"name":"amount","type":"uint256","internalType":"uint256"}],"outputs":[],"stateMutability":"nonpayable"},{"name":"executePayload","type":"function","inputs":[{"name":"payloadId","type":"uint40","internalType":"uint40"}],"outputs":[],"stateMutability":"payable"},{"name":"getExecutorSettingsByAccessControl","type":"function","inputs":[{"name":"accessControl","type":"uint8","internalType":"enum PayloadsControllerUtils.AccessControl"}],"outputs":[{"name":"","type":"tuple","components":[{"name":"executor","type":"address","internalType":"address"},{"name":"delay","type":"uint40","internalType":"uint40"}],"internalType":"struct IPayloadsControllerCore.ExecutorConfig"}],"stateMutability":"view"},{"name":"getPayloadById","type":"function","inputs":[{"name":"payloadId","type":"uint40","internalType":"uint40"}],"outputs":[{"name":"","type":"tuple","components":[{"name":"creator","type":"address","internalType":"address"},{"name":"maximumAccessLevelRequired","type":"uint8","internalType":"enum PayloadsControllerUtils.AccessControl"},{"name":"state","type":"uint8","internalType":"enum IPayloadsControllerCore.PayloadState"},{"name":"createdAt","type":"uint40","internalType":"uint40"},{"name":"queuedAt","type":"uint40","internalType":"uint40"},{"name":"executedAt","type":"uint40","internalType":"uint40"},{"name":"cancelledAt","type":"uint40","internalType":"uint40"},{"name":"expirationTime","type":"uint40","internalType":"uint40"},{"name":"delay","type":"uint40","internalType":"uint40"},{"name":"gracePeriod","type":"uint40","internalType":"uint40"},{"name":"actions","type":"tuple[]","components":[{"name":"target","type":"address","internalType":"address"},{"name":"withDelegateCall","type":"bool","internalType":"bool"},{"name":"accessLevel","type":"uint8","internalType":"enum PayloadsControllerUtils.AccessControl"},{"name":"value","type":"uint256","internalType":"uint256"},{"name":"signature","type":"string","internalType":"string"},{"name":"callData","type":"bytes","internalType":"bytes"}],"internalType":"struct IPayloadsControllerCore.ExecutionAction[]"}],"internalType":"struct IPayloadsControllerCore.Payload"}],"stateMutability":"view"},{"name":"getPayloadState","type":"function","inputs":[{"name":"payloadId","type":"uint40","internalType":"uint40"}],"outputs":[{"name":"","type":"uint8","internalType":"enum IPayloadsControllerCore.PayloadState"}],"stateMutability":"view"},{"name":"getPayloadsCount","type":"function","inputs":[],"outputs":[{"name":"","type":"uint40","internalType":"uint40"}],"stateMutability":"view"},{"name":"guardian","type":"function","inputs":[],"outputs":[{"name":"","type":"address","internalType":"address"}],"stateMutability":"view"},{"name":"initialize","type":"function","inputs":[{"name":"owner","type":"address","internalType":"address"},{"name":"guardian","type":"address","internalType":"address"},{"name":"executors","type":"tuple[]","components":[{"name":"accessLevel","type":"uint8","internalType":"enum PayloadsControllerUtils.AccessControl"},{"name":"executorConfig","type":"tuple","components":[{"name":"executor","type":"address","internalType":"address"},{"name":"delay","type":"uint40","internalType":"uint40"}],"internalType":"struct IPayloadsControllerCore.ExecutorConfig"}],"internalType":"struct IPayloadsControllerCore.UpdateExecutorInput[]"}],"outputs":[],"stateMutability":"nonpayable"},{"name":"owner","type":"function","inputs":[],"outputs":[{"name":"","type":"address","internalType":"address"}],"stateMutability":"view"},{"name":"receiveCrossChainMessage","type":"function","inputs":[{"name":"originSender","type":"address","internalType":"address"},{"name":"originChainId","type":"uint256","internalType":"uint256"},{"name":"message","type":"bytes","internalType":"bytes"}],"outputs":[],"stateMutability":"nonpayable"},{"name":"renounceOwnership","type":"function","inputs":[],"outputs":[],"stateMutability":"nonpayable"},{"name":"transferOwnership","type":"function","inputs":[{"name":"newOwner","type":"address","internalType":"address"}],"outputs":[],"stateMutability":"nonpayable"},{"name":"updateExecutors","type":"function","inputs":[{"name":"executors","type":"tuple[]","components":[{"name":"accessLevel","type":"uint8","internalType":"enum PayloadsControllerUtils.AccessControl"},{"name":"executorConfig","type":"tuple","components":[{"name":"executor","type":"address","internalType":"address"},{"name":"delay","type":"uint40","internalType":"uint40"}],"internalType":"struct IPayloadsControllerCore.ExecutorConfig"}],"internalType":"struct IPayloadsControllerCore.UpdateExecutorInput[]"}],"outputs":[],"stateMutability":"nonpayable"},{"name":"updateGuardian","type":"function","inputs":[{"name":"newGuardian","type":"address","internalType":"address"}],"outputs":[],"stateMutability":"nonpayable"},{"name":"whoCanRescue","type":"function","inputs":[],"outputs":[{"name":"","type":"address","internalType":"address"}],"stateMutability":"view"},{"type":"receive","stateMutability":"payable"}],"matchId":"1896040","creationMatch":"match","runtimeMatch":"match","verifiedAt":"2024-08-08T14:07:01Z","match":"match","chainId":"1","address":"0x7222182cB9c5320587b5148BF03eeE107AD64578"}