ETH Price: $2,429.42 (-3.13%)

Transaction Decoder

Block:
12666741 at Jun-19-2021 07:42:04 PM +UTC
Transaction Fee:
0.002076822 ETH $5.05
Gas Used:
94,401 Gas / 22 Gwei

Emitted Events:

22 OlympusERC20Token.Transfer( from=[Sender] 0x1c2f37ace445fe988d62f6d4855a074aaa24747d, to=UniswapV2Pair, value=20000000000 )
23 OlympusERC20Token.Approval( owner=[Sender] 0x1c2f37ace445fe988d62f6d4855a074aaa24747d, spender=[Receiver] UniswapV2Router02, value=115792089237316195423570985008687907853269984665640564039457584007674895358427 )
24 Dai.Transfer( src=UniswapV2Pair, dst=[Sender] 0x1c2f37ace445fe988d62f6d4855a074aaa24747d, wad=5909293960130639532979 )
25 UniswapV2Pair.Sync( reserve0=30112707843845, reserve1=8918087096570169457122293 )
26 UniswapV2Pair.Swap( sender=[Receiver] UniswapV2Router02, amount0In=20000000000, amount1In=0, amount0Out=0, amount1Out=5909293960130639532979, to=[Sender] 0x1c2f37ace445fe988d62f6d4855a074aaa24747d )

Account State Difference:

  Address   Before After State Difference Code
(Hiveon Pool)
4,426.855698710467210212 Eth4,426.857775532467210212 Eth0.002076822
0x1C2F37ac...AAa24747d
0.287510145309029094 Eth
Nonce: 188
0.285433323309029094 Eth
Nonce: 189
0.002076822
0x34d7d7Aa...5fa2def7c
0x38351818...37814a899
0x6B175474...495271d0F

Execution Trace

UniswapV2Router02.swapExactTokensForTokens( amountIn=20000000000, amountOutMin=5879665204661649396371, path=[0x383518188C0C6d7730D91b2c03a03C837814a899, 0x6B175474E89094C44Da98b954EedeAC495271d0F], to=0x1C2F37acE445fE988D62f6d4855a074AAa24747d, deadline=1624132876 ) => ( amounts=[20000000000, 5909293960130639532979] )
  • UniswapV2Pair.STATICCALL( )
  • OlympusERC20Token.transferFrom( sender=0x1C2F37acE445fE988D62f6d4855a074AAa24747d, recipient=0x34d7d7Aaf50AD4944B70B320aCB24C95fa2def7c, amount=20000000000 ) => ( True )
  • UniswapV2Pair.swap( amount0Out=0, amount1Out=5909293960130639532979, to=0x1C2F37acE445fE988D62f6d4855a074AAa24747d, data=0x )
    • Dai.transfer( dst=0x1C2F37acE445fE988D62f6d4855a074AAa24747d, wad=5909293960130639532979 ) => ( True )
    • OlympusERC20Token.balanceOf( account=0x34d7d7Aaf50AD4944B70B320aCB24C95fa2def7c ) => ( 30112707843845 )
    • Dai.balanceOf( 0x34d7d7Aaf50AD4944B70B320aCB24C95fa2def7c ) => ( 8918087096570169457122293 )
      File 1 of 4: UniswapV2Router02
      // File: contracts/uniswapv2/interfaces/IUniswapV2Pair.sol
      
      pragma solidity >=0.5.0;
      
      interface IUniswapV2Pair {
          event Approval(address indexed owner, address indexed spender, uint value);
          event Transfer(address indexed from, address indexed to, uint value);
      
          function name() external pure returns (string memory);
          function symbol() external pure returns (string memory);
          function decimals() external pure returns (uint8);
          function totalSupply() external view returns (uint);
          function balanceOf(address owner) external view returns (uint);
          function allowance(address owner, address spender) external view returns (uint);
      
          function approve(address spender, uint value) external returns (bool);
          function transfer(address to, uint value) external returns (bool);
          function transferFrom(address from, address to, uint value) external returns (bool);
      
          function DOMAIN_SEPARATOR() external view returns (bytes32);
          function PERMIT_TYPEHASH() external pure returns (bytes32);
          function nonces(address owner) external view returns (uint);
      
          function permit(address owner, address spender, uint value, uint deadline, uint8 v, bytes32 r, bytes32 s) external;
      
          event Mint(address indexed sender, uint amount0, uint amount1);
          event Burn(address indexed sender, uint amount0, uint amount1, address indexed to);
          event Swap(
              address indexed sender,
              uint amount0In,
              uint amount1In,
              uint amount0Out,
              uint amount1Out,
              address indexed to
          );
          event Sync(uint112 reserve0, uint112 reserve1);
      
          function MINIMUM_LIQUIDITY() external pure returns (uint);
          function factory() external view returns (address);
          function token0() external view returns (address);
          function token1() external view returns (address);
          function getReserves() external view returns (uint112 reserve0, uint112 reserve1, uint32 blockTimestampLast);
          function price0CumulativeLast() external view returns (uint);
          function price1CumulativeLast() external view returns (uint);
          function kLast() external view returns (uint);
      
          function mint(address to) external returns (uint liquidity);
          function burn(address to) external returns (uint amount0, uint amount1);
          function swap(uint amount0Out, uint amount1Out, address to, bytes calldata data) external;
          function skim(address to) external;
          function sync() external;
      
          function initialize(address, address) external;
      }
      
      // File: contracts/uniswapv2/libraries/SafeMath.sol
      
      pragma solidity =0.6.12;
      
      // a library for performing overflow-safe math, courtesy of DappHub (https://github.com/dapphub/ds-math)
      
      library SafeMathUniswap {
          function add(uint x, uint y) internal pure returns (uint z) {
              require((z = x + y) >= x, 'ds-math-add-overflow');
          }
      
          function sub(uint x, uint y) internal pure returns (uint z) {
              require((z = x - y) <= x, 'ds-math-sub-underflow');
          }
      
          function mul(uint x, uint y) internal pure returns (uint z) {
              require(y == 0 || (z = x * y) / y == x, 'ds-math-mul-overflow');
          }
      }
      
      // File: contracts/uniswapv2/libraries/UniswapV2Library.sol
      
      pragma solidity >=0.5.0;
      
      
      
      library UniswapV2Library {
          using SafeMathUniswap for uint;
      
          // returns sorted token addresses, used to handle return values from pairs sorted in this order
          function sortTokens(address tokenA, address tokenB) internal pure returns (address token0, address token1) {
              require(tokenA != tokenB, 'UniswapV2Library: IDENTICAL_ADDRESSES');
              (token0, token1) = tokenA < tokenB ? (tokenA, tokenB) : (tokenB, tokenA);
              require(token0 != address(0), 'UniswapV2Library: ZERO_ADDRESS');
          }
      
          // calculates the CREATE2 address for a pair without making any external calls
          function pairFor(address factory, address tokenA, address tokenB) internal pure returns (address pair) {
              (address token0, address token1) = sortTokens(tokenA, tokenB);
              pair = address(uint(keccak256(abi.encodePacked(
                      hex'ff',
                      factory,
                      keccak256(abi.encodePacked(token0, token1)),
                      hex'e18a34eb0e04b04f7a0ac29a6e80748dca96319b42c54d679cb821dca90c6303' // init code hash
                  ))));
          }
      
          // fetches and sorts the reserves for a pair
          function getReserves(address factory, address tokenA, address tokenB) internal view returns (uint reserveA, uint reserveB) {
              (address token0,) = sortTokens(tokenA, tokenB);
              (uint reserve0, uint reserve1,) = IUniswapV2Pair(pairFor(factory, tokenA, tokenB)).getReserves();
              (reserveA, reserveB) = tokenA == token0 ? (reserve0, reserve1) : (reserve1, reserve0);
          }
      
          // given some amount of an asset and pair reserves, returns an equivalent amount of the other asset
          function quote(uint amountA, uint reserveA, uint reserveB) internal pure returns (uint amountB) {
              require(amountA > 0, 'UniswapV2Library: INSUFFICIENT_AMOUNT');
              require(reserveA > 0 && reserveB > 0, 'UniswapV2Library: INSUFFICIENT_LIQUIDITY');
              amountB = amountA.mul(reserveB) / reserveA;
          }
      
          // given an input amount of an asset and pair reserves, returns the maximum output amount of the other asset
          function getAmountOut(uint amountIn, uint reserveIn, uint reserveOut) internal pure returns (uint amountOut) {
              require(amountIn > 0, 'UniswapV2Library: INSUFFICIENT_INPUT_AMOUNT');
              require(reserveIn > 0 && reserveOut > 0, 'UniswapV2Library: INSUFFICIENT_LIQUIDITY');
              uint amountInWithFee = amountIn.mul(997);
              uint numerator = amountInWithFee.mul(reserveOut);
              uint denominator = reserveIn.mul(1000).add(amountInWithFee);
              amountOut = numerator / denominator;
          }
      
          // given an output amount of an asset and pair reserves, returns a required input amount of the other asset
          function getAmountIn(uint amountOut, uint reserveIn, uint reserveOut) internal pure returns (uint amountIn) {
              require(amountOut > 0, 'UniswapV2Library: INSUFFICIENT_OUTPUT_AMOUNT');
              require(reserveIn > 0 && reserveOut > 0, 'UniswapV2Library: INSUFFICIENT_LIQUIDITY');
              uint numerator = reserveIn.mul(amountOut).mul(1000);
              uint denominator = reserveOut.sub(amountOut).mul(997);
              amountIn = (numerator / denominator).add(1);
          }
      
          // performs chained getAmountOut calculations on any number of pairs
          function getAmountsOut(address factory, uint amountIn, address[] memory path) internal view returns (uint[] memory amounts) {
              require(path.length >= 2, 'UniswapV2Library: INVALID_PATH');
              amounts = new uint[](path.length);
              amounts[0] = amountIn;
              for (uint i; i < path.length - 1; i++) {
                  (uint reserveIn, uint reserveOut) = getReserves(factory, path[i], path[i + 1]);
                  amounts[i + 1] = getAmountOut(amounts[i], reserveIn, reserveOut);
              }
          }
      
          // performs chained getAmountIn calculations on any number of pairs
          function getAmountsIn(address factory, uint amountOut, address[] memory path) internal view returns (uint[] memory amounts) {
              require(path.length >= 2, 'UniswapV2Library: INVALID_PATH');
              amounts = new uint[](path.length);
              amounts[amounts.length - 1] = amountOut;
              for (uint i = path.length - 1; i > 0; i--) {
                  (uint reserveIn, uint reserveOut) = getReserves(factory, path[i - 1], path[i]);
                  amounts[i - 1] = getAmountIn(amounts[i], reserveIn, reserveOut);
              }
          }
      }
      
      // File: contracts/uniswapv2/libraries/TransferHelper.sol
      
      // SPDX-License-Identifier: GPL-3.0-or-later
      
      pragma solidity >=0.6.0;
      
      // helper methods for interacting with ERC20 tokens and sending ETH that do not consistently return true/false
      library TransferHelper {
          function safeApprove(address token, address to, uint value) internal {
              // bytes4(keccak256(bytes('approve(address,uint256)')));
              (bool success, bytes memory data) = token.call(abi.encodeWithSelector(0x095ea7b3, to, value));
              require(success && (data.length == 0 || abi.decode(data, (bool))), 'TransferHelper: APPROVE_FAILED');
          }
      
          function safeTransfer(address token, address to, uint value) internal {
              // bytes4(keccak256(bytes('transfer(address,uint256)')));
              (bool success, bytes memory data) = token.call(abi.encodeWithSelector(0xa9059cbb, to, value));
              require(success && (data.length == 0 || abi.decode(data, (bool))), 'TransferHelper: TRANSFER_FAILED');
          }
      
          function safeTransferFrom(address token, address from, address to, uint value) internal {
              // bytes4(keccak256(bytes('transferFrom(address,address,uint256)')));
              (bool success, bytes memory data) = token.call(abi.encodeWithSelector(0x23b872dd, from, to, value));
              require(success && (data.length == 0 || abi.decode(data, (bool))), 'TransferHelper: TRANSFER_FROM_FAILED');
          }
      
          function safeTransferETH(address to, uint value) internal {
              (bool success,) = to.call{value:value}(new bytes(0));
              require(success, 'TransferHelper: ETH_TRANSFER_FAILED');
          }
      }
      
      // File: contracts/uniswapv2/interfaces/IUniswapV2Router01.sol
      
      pragma solidity >=0.6.2;
      
      interface IUniswapV2Router01 {
          function factory() external pure returns (address);
          function WETH() external pure returns (address);
      
          function addLiquidity(
              address tokenA,
              address tokenB,
              uint amountADesired,
              uint amountBDesired,
              uint amountAMin,
              uint amountBMin,
              address to,
              uint deadline
          ) external returns (uint amountA, uint amountB, uint liquidity);
          function addLiquidityETH(
              address token,
              uint amountTokenDesired,
              uint amountTokenMin,
              uint amountETHMin,
              address to,
              uint deadline
          ) external payable returns (uint amountToken, uint amountETH, uint liquidity);
          function removeLiquidity(
              address tokenA,
              address tokenB,
              uint liquidity,
              uint amountAMin,
              uint amountBMin,
              address to,
              uint deadline
          ) external returns (uint amountA, uint amountB);
          function removeLiquidityETH(
              address token,
              uint liquidity,
              uint amountTokenMin,
              uint amountETHMin,
              address to,
              uint deadline
          ) external returns (uint amountToken, uint amountETH);
          function removeLiquidityWithPermit(
              address tokenA,
              address tokenB,
              uint liquidity,
              uint amountAMin,
              uint amountBMin,
              address to,
              uint deadline,
              bool approveMax, uint8 v, bytes32 r, bytes32 s
          ) external returns (uint amountA, uint amountB);
          function removeLiquidityETHWithPermit(
              address token,
              uint liquidity,
              uint amountTokenMin,
              uint amountETHMin,
              address to,
              uint deadline,
              bool approveMax, uint8 v, bytes32 r, bytes32 s
          ) external returns (uint amountToken, uint amountETH);
          function swapExactTokensForTokens(
              uint amountIn,
              uint amountOutMin,
              address[] calldata path,
              address to,
              uint deadline
          ) external returns (uint[] memory amounts);
          function swapTokensForExactTokens(
              uint amountOut,
              uint amountInMax,
              address[] calldata path,
              address to,
              uint deadline
          ) external returns (uint[] memory amounts);
          function swapExactETHForTokens(uint amountOutMin, address[] calldata path, address to, uint deadline)
              external
              payable
              returns (uint[] memory amounts);
          function swapTokensForExactETH(uint amountOut, uint amountInMax, address[] calldata path, address to, uint deadline)
              external
              returns (uint[] memory amounts);
          function swapExactTokensForETH(uint amountIn, uint amountOutMin, address[] calldata path, address to, uint deadline)
              external
              returns (uint[] memory amounts);
          function swapETHForExactTokens(uint amountOut, address[] calldata path, address to, uint deadline)
              external
              payable
              returns (uint[] memory amounts);
      
          function quote(uint amountA, uint reserveA, uint reserveB) external pure returns (uint amountB);
          function getAmountOut(uint amountIn, uint reserveIn, uint reserveOut) external pure returns (uint amountOut);
          function getAmountIn(uint amountOut, uint reserveIn, uint reserveOut) external pure returns (uint amountIn);
          function getAmountsOut(uint amountIn, address[] calldata path) external view returns (uint[] memory amounts);
          function getAmountsIn(uint amountOut, address[] calldata path) external view returns (uint[] memory amounts);
      }
      
      // File: contracts/uniswapv2/interfaces/IUniswapV2Router02.sol
      
      pragma solidity >=0.6.2;
      
      
      interface IUniswapV2Router02 is IUniswapV2Router01 {
          function removeLiquidityETHSupportingFeeOnTransferTokens(
              address token,
              uint liquidity,
              uint amountTokenMin,
              uint amountETHMin,
              address to,
              uint deadline
          ) external returns (uint amountETH);
          function removeLiquidityETHWithPermitSupportingFeeOnTransferTokens(
              address token,
              uint liquidity,
              uint amountTokenMin,
              uint amountETHMin,
              address to,
              uint deadline,
              bool approveMax, uint8 v, bytes32 r, bytes32 s
          ) external returns (uint amountETH);
      
          function swapExactTokensForTokensSupportingFeeOnTransferTokens(
              uint amountIn,
              uint amountOutMin,
              address[] calldata path,
              address to,
              uint deadline
          ) external;
          function swapExactETHForTokensSupportingFeeOnTransferTokens(
              uint amountOutMin,
              address[] calldata path,
              address to,
              uint deadline
          ) external payable;
          function swapExactTokensForETHSupportingFeeOnTransferTokens(
              uint amountIn,
              uint amountOutMin,
              address[] calldata path,
              address to,
              uint deadline
          ) external;
      }
      
      // File: contracts/uniswapv2/interfaces/IUniswapV2Factory.sol
      
      pragma solidity >=0.5.0;
      
      interface IUniswapV2Factory {
          event PairCreated(address indexed token0, address indexed token1, address pair, uint);
      
          function feeTo() external view returns (address);
          function feeToSetter() external view returns (address);
          function migrator() external view returns (address);
      
          function getPair(address tokenA, address tokenB) external view returns (address pair);
          function allPairs(uint) external view returns (address pair);
          function allPairsLength() external view returns (uint);
      
          function createPair(address tokenA, address tokenB) external returns (address pair);
      
          function setFeeTo(address) external;
          function setFeeToSetter(address) external;
          function setMigrator(address) external;
      }
      
      // File: contracts/uniswapv2/interfaces/IERC20.sol
      
      pragma solidity >=0.5.0;
      
      interface IERC20Uniswap {
          event Approval(address indexed owner, address indexed spender, uint value);
          event Transfer(address indexed from, address indexed to, uint value);
      
          function name() external view returns (string memory);
          function symbol() external view returns (string memory);
          function decimals() external view returns (uint8);
          function totalSupply() external view returns (uint);
          function balanceOf(address owner) external view returns (uint);
          function allowance(address owner, address spender) external view returns (uint);
      
          function approve(address spender, uint value) external returns (bool);
          function transfer(address to, uint value) external returns (bool);
          function transferFrom(address from, address to, uint value) external returns (bool);
      }
      
      // File: contracts/uniswapv2/interfaces/IWETH.sol
      
      pragma solidity >=0.5.0;
      
      interface IWETH {
          function deposit() external payable;
          function transfer(address to, uint value) external returns (bool);
          function withdraw(uint) external;
      }
      
      // File: contracts/uniswapv2/UniswapV2Router02.sol
      
      pragma solidity =0.6.12;
      
      
      
      
      
      
      
      
      contract UniswapV2Router02 is IUniswapV2Router02 {
          using SafeMathUniswap for uint;
      
          address public immutable override factory;
          address public immutable override WETH;
      
          modifier ensure(uint deadline) {
              require(deadline >= block.timestamp, 'UniswapV2Router: EXPIRED');
              _;
          }
      
          constructor(address _factory, address _WETH) public {
              factory = _factory;
              WETH = _WETH;
          }
      
          receive() external payable {
              assert(msg.sender == WETH); // only accept ETH via fallback from the WETH contract
          }
      
          // **** ADD LIQUIDITY ****
          function _addLiquidity(
              address tokenA,
              address tokenB,
              uint amountADesired,
              uint amountBDesired,
              uint amountAMin,
              uint amountBMin
          ) internal virtual returns (uint amountA, uint amountB) {
              // create the pair if it doesn't exist yet
              if (IUniswapV2Factory(factory).getPair(tokenA, tokenB) == address(0)) {
                  IUniswapV2Factory(factory).createPair(tokenA, tokenB);
              }
              (uint reserveA, uint reserveB) = UniswapV2Library.getReserves(factory, tokenA, tokenB);
              if (reserveA == 0 && reserveB == 0) {
                  (amountA, amountB) = (amountADesired, amountBDesired);
              } else {
                  uint amountBOptimal = UniswapV2Library.quote(amountADesired, reserveA, reserveB);
                  if (amountBOptimal <= amountBDesired) {
                      require(amountBOptimal >= amountBMin, 'UniswapV2Router: INSUFFICIENT_B_AMOUNT');
                      (amountA, amountB) = (amountADesired, amountBOptimal);
                  } else {
                      uint amountAOptimal = UniswapV2Library.quote(amountBDesired, reserveB, reserveA);
                      assert(amountAOptimal <= amountADesired);
                      require(amountAOptimal >= amountAMin, 'UniswapV2Router: INSUFFICIENT_A_AMOUNT');
                      (amountA, amountB) = (amountAOptimal, amountBDesired);
                  }
              }
          }
          function addLiquidity(
              address tokenA,
              address tokenB,
              uint amountADesired,
              uint amountBDesired,
              uint amountAMin,
              uint amountBMin,
              address to,
              uint deadline
          ) external virtual override ensure(deadline) returns (uint amountA, uint amountB, uint liquidity) {
              (amountA, amountB) = _addLiquidity(tokenA, tokenB, amountADesired, amountBDesired, amountAMin, amountBMin);
              address pair = UniswapV2Library.pairFor(factory, tokenA, tokenB);
              TransferHelper.safeTransferFrom(tokenA, msg.sender, pair, amountA);
              TransferHelper.safeTransferFrom(tokenB, msg.sender, pair, amountB);
              liquidity = IUniswapV2Pair(pair).mint(to);
          }
          function addLiquidityETH(
              address token,
              uint amountTokenDesired,
              uint amountTokenMin,
              uint amountETHMin,
              address to,
              uint deadline
          ) external virtual override payable ensure(deadline) returns (uint amountToken, uint amountETH, uint liquidity) {
              (amountToken, amountETH) = _addLiquidity(
                  token,
                  WETH,
                  amountTokenDesired,
                  msg.value,
                  amountTokenMin,
                  amountETHMin
              );
              address pair = UniswapV2Library.pairFor(factory, token, WETH);
              TransferHelper.safeTransferFrom(token, msg.sender, pair, amountToken);
              IWETH(WETH).deposit{value: amountETH}();
              assert(IWETH(WETH).transfer(pair, amountETH));
              liquidity = IUniswapV2Pair(pair).mint(to);
              // refund dust eth, if any
              if (msg.value > amountETH) TransferHelper.safeTransferETH(msg.sender, msg.value - amountETH);
          }
      
          // **** REMOVE LIQUIDITY ****
          function removeLiquidity(
              address tokenA,
              address tokenB,
              uint liquidity,
              uint amountAMin,
              uint amountBMin,
              address to,
              uint deadline
          ) public virtual override ensure(deadline) returns (uint amountA, uint amountB) {
              address pair = UniswapV2Library.pairFor(factory, tokenA, tokenB);
              IUniswapV2Pair(pair).transferFrom(msg.sender, pair, liquidity); // send liquidity to pair
              (uint amount0, uint amount1) = IUniswapV2Pair(pair).burn(to);
              (address token0,) = UniswapV2Library.sortTokens(tokenA, tokenB);
              (amountA, amountB) = tokenA == token0 ? (amount0, amount1) : (amount1, amount0);
              require(amountA >= amountAMin, 'UniswapV2Router: INSUFFICIENT_A_AMOUNT');
              require(amountB >= amountBMin, 'UniswapV2Router: INSUFFICIENT_B_AMOUNT');
          }
          function removeLiquidityETH(
              address token,
              uint liquidity,
              uint amountTokenMin,
              uint amountETHMin,
              address to,
              uint deadline
          ) public virtual override ensure(deadline) returns (uint amountToken, uint amountETH) {
              (amountToken, amountETH) = removeLiquidity(
                  token,
                  WETH,
                  liquidity,
                  amountTokenMin,
                  amountETHMin,
                  address(this),
                  deadline
              );
              TransferHelper.safeTransfer(token, to, amountToken);
              IWETH(WETH).withdraw(amountETH);
              TransferHelper.safeTransferETH(to, amountETH);
          }
          function removeLiquidityWithPermit(
              address tokenA,
              address tokenB,
              uint liquidity,
              uint amountAMin,
              uint amountBMin,
              address to,
              uint deadline,
              bool approveMax, uint8 v, bytes32 r, bytes32 s
          ) external virtual override returns (uint amountA, uint amountB) {
              address pair = UniswapV2Library.pairFor(factory, tokenA, tokenB);
              uint value = approveMax ? uint(-1) : liquidity;
              IUniswapV2Pair(pair).permit(msg.sender, address(this), value, deadline, v, r, s);
              (amountA, amountB) = removeLiquidity(tokenA, tokenB, liquidity, amountAMin, amountBMin, to, deadline);
          }
          function removeLiquidityETHWithPermit(
              address token,
              uint liquidity,
              uint amountTokenMin,
              uint amountETHMin,
              address to,
              uint deadline,
              bool approveMax, uint8 v, bytes32 r, bytes32 s
          ) external virtual override returns (uint amountToken, uint amountETH) {
              address pair = UniswapV2Library.pairFor(factory, token, WETH);
              uint value = approveMax ? uint(-1) : liquidity;
              IUniswapV2Pair(pair).permit(msg.sender, address(this), value, deadline, v, r, s);
              (amountToken, amountETH) = removeLiquidityETH(token, liquidity, amountTokenMin, amountETHMin, to, deadline);
          }
      
          // **** REMOVE LIQUIDITY (supporting fee-on-transfer tokens) ****
          function removeLiquidityETHSupportingFeeOnTransferTokens(
              address token,
              uint liquidity,
              uint amountTokenMin,
              uint amountETHMin,
              address to,
              uint deadline
          ) public virtual override ensure(deadline) returns (uint amountETH) {
              (, amountETH) = removeLiquidity(
                  token,
                  WETH,
                  liquidity,
                  amountTokenMin,
                  amountETHMin,
                  address(this),
                  deadline
              );
              TransferHelper.safeTransfer(token, to, IERC20Uniswap(token).balanceOf(address(this)));
              IWETH(WETH).withdraw(amountETH);
              TransferHelper.safeTransferETH(to, amountETH);
          }
          function removeLiquidityETHWithPermitSupportingFeeOnTransferTokens(
              address token,
              uint liquidity,
              uint amountTokenMin,
              uint amountETHMin,
              address to,
              uint deadline,
              bool approveMax, uint8 v, bytes32 r, bytes32 s
          ) external virtual override returns (uint amountETH) {
              address pair = UniswapV2Library.pairFor(factory, token, WETH);
              uint value = approveMax ? uint(-1) : liquidity;
              IUniswapV2Pair(pair).permit(msg.sender, address(this), value, deadline, v, r, s);
              amountETH = removeLiquidityETHSupportingFeeOnTransferTokens(
                  token, liquidity, amountTokenMin, amountETHMin, to, deadline
              );
          }
      
          // **** SWAP ****
          // requires the initial amount to have already been sent to the first pair
          function _swap(uint[] memory amounts, address[] memory path, address _to) internal virtual {
              for (uint i; i < path.length - 1; i++) {
                  (address input, address output) = (path[i], path[i + 1]);
                  (address token0,) = UniswapV2Library.sortTokens(input, output);
                  uint amountOut = amounts[i + 1];
                  (uint amount0Out, uint amount1Out) = input == token0 ? (uint(0), amountOut) : (amountOut, uint(0));
                  address to = i < path.length - 2 ? UniswapV2Library.pairFor(factory, output, path[i + 2]) : _to;
                  IUniswapV2Pair(UniswapV2Library.pairFor(factory, input, output)).swap(
                      amount0Out, amount1Out, to, new bytes(0)
                  );
              }
          }
          function swapExactTokensForTokens(
              uint amountIn,
              uint amountOutMin,
              address[] calldata path,
              address to,
              uint deadline
          ) external virtual override ensure(deadline) returns (uint[] memory amounts) {
              amounts = UniswapV2Library.getAmountsOut(factory, amountIn, path);
              require(amounts[amounts.length - 1] >= amountOutMin, 'UniswapV2Router: INSUFFICIENT_OUTPUT_AMOUNT');
              TransferHelper.safeTransferFrom(
                  path[0], msg.sender, UniswapV2Library.pairFor(factory, path[0], path[1]), amounts[0]
              );
              _swap(amounts, path, to);
          }
          function swapTokensForExactTokens(
              uint amountOut,
              uint amountInMax,
              address[] calldata path,
              address to,
              uint deadline
          ) external virtual override ensure(deadline) returns (uint[] memory amounts) {
              amounts = UniswapV2Library.getAmountsIn(factory, amountOut, path);
              require(amounts[0] <= amountInMax, 'UniswapV2Router: EXCESSIVE_INPUT_AMOUNT');
              TransferHelper.safeTransferFrom(
                  path[0], msg.sender, UniswapV2Library.pairFor(factory, path[0], path[1]), amounts[0]
              );
              _swap(amounts, path, to);
          }
          function swapExactETHForTokens(uint amountOutMin, address[] calldata path, address to, uint deadline)
              external
              virtual
              override
              payable
              ensure(deadline)
              returns (uint[] memory amounts)
          {
              require(path[0] == WETH, 'UniswapV2Router: INVALID_PATH');
              amounts = UniswapV2Library.getAmountsOut(factory, msg.value, path);
              require(amounts[amounts.length - 1] >= amountOutMin, 'UniswapV2Router: INSUFFICIENT_OUTPUT_AMOUNT');
              IWETH(WETH).deposit{value: amounts[0]}();
              assert(IWETH(WETH).transfer(UniswapV2Library.pairFor(factory, path[0], path[1]), amounts[0]));
              _swap(amounts, path, to);
          }
          function swapTokensForExactETH(uint amountOut, uint amountInMax, address[] calldata path, address to, uint deadline)
              external
              virtual
              override
              ensure(deadline)
              returns (uint[] memory amounts)
          {
              require(path[path.length - 1] == WETH, 'UniswapV2Router: INVALID_PATH');
              amounts = UniswapV2Library.getAmountsIn(factory, amountOut, path);
              require(amounts[0] <= amountInMax, 'UniswapV2Router: EXCESSIVE_INPUT_AMOUNT');
              TransferHelper.safeTransferFrom(
                  path[0], msg.sender, UniswapV2Library.pairFor(factory, path[0], path[1]), amounts[0]
              );
              _swap(amounts, path, address(this));
              IWETH(WETH).withdraw(amounts[amounts.length - 1]);
              TransferHelper.safeTransferETH(to, amounts[amounts.length - 1]);
          }
          function swapExactTokensForETH(uint amountIn, uint amountOutMin, address[] calldata path, address to, uint deadline)
              external
              virtual
              override
              ensure(deadline)
              returns (uint[] memory amounts)
          {
              require(path[path.length - 1] == WETH, 'UniswapV2Router: INVALID_PATH');
              amounts = UniswapV2Library.getAmountsOut(factory, amountIn, path);
              require(amounts[amounts.length - 1] >= amountOutMin, 'UniswapV2Router: INSUFFICIENT_OUTPUT_AMOUNT');
              TransferHelper.safeTransferFrom(
                  path[0], msg.sender, UniswapV2Library.pairFor(factory, path[0], path[1]), amounts[0]
              );
              _swap(amounts, path, address(this));
              IWETH(WETH).withdraw(amounts[amounts.length - 1]);
              TransferHelper.safeTransferETH(to, amounts[amounts.length - 1]);
          }
          function swapETHForExactTokens(uint amountOut, address[] calldata path, address to, uint deadline)
              external
              virtual
              override
              payable
              ensure(deadline)
              returns (uint[] memory amounts)
          {
              require(path[0] == WETH, 'UniswapV2Router: INVALID_PATH');
              amounts = UniswapV2Library.getAmountsIn(factory, amountOut, path);
              require(amounts[0] <= msg.value, 'UniswapV2Router: EXCESSIVE_INPUT_AMOUNT');
              IWETH(WETH).deposit{value: amounts[0]}();
              assert(IWETH(WETH).transfer(UniswapV2Library.pairFor(factory, path[0], path[1]), amounts[0]));
              _swap(amounts, path, to);
              // refund dust eth, if any
              if (msg.value > amounts[0]) TransferHelper.safeTransferETH(msg.sender, msg.value - amounts[0]);
          }
      
          // **** SWAP (supporting fee-on-transfer tokens) ****
          // requires the initial amount to have already been sent to the first pair
          function _swapSupportingFeeOnTransferTokens(address[] memory path, address _to) internal virtual {
              for (uint i; i < path.length - 1; i++) {
                  (address input, address output) = (path[i], path[i + 1]);
                  (address token0,) = UniswapV2Library.sortTokens(input, output);
                  IUniswapV2Pair pair = IUniswapV2Pair(UniswapV2Library.pairFor(factory, input, output));
                  uint amountInput;
                  uint amountOutput;
                  { // scope to avoid stack too deep errors
                  (uint reserve0, uint reserve1,) = pair.getReserves();
                  (uint reserveInput, uint reserveOutput) = input == token0 ? (reserve0, reserve1) : (reserve1, reserve0);
                  amountInput = IERC20Uniswap(input).balanceOf(address(pair)).sub(reserveInput);
                  amountOutput = UniswapV2Library.getAmountOut(amountInput, reserveInput, reserveOutput);
                  }
                  (uint amount0Out, uint amount1Out) = input == token0 ? (uint(0), amountOutput) : (amountOutput, uint(0));
                  address to = i < path.length - 2 ? UniswapV2Library.pairFor(factory, output, path[i + 2]) : _to;
                  pair.swap(amount0Out, amount1Out, to, new bytes(0));
              }
          }
          function swapExactTokensForTokensSupportingFeeOnTransferTokens(
              uint amountIn,
              uint amountOutMin,
              address[] calldata path,
              address to,
              uint deadline
          ) external virtual override ensure(deadline) {
              TransferHelper.safeTransferFrom(
                  path[0], msg.sender, UniswapV2Library.pairFor(factory, path[0], path[1]), amountIn
              );
              uint balanceBefore = IERC20Uniswap(path[path.length - 1]).balanceOf(to);
              _swapSupportingFeeOnTransferTokens(path, to);
              require(
                  IERC20Uniswap(path[path.length - 1]).balanceOf(to).sub(balanceBefore) >= amountOutMin,
                  'UniswapV2Router: INSUFFICIENT_OUTPUT_AMOUNT'
              );
          }
          function swapExactETHForTokensSupportingFeeOnTransferTokens(
              uint amountOutMin,
              address[] calldata path,
              address to,
              uint deadline
          )
              external
              virtual
              override
              payable
              ensure(deadline)
          {
              require(path[0] == WETH, 'UniswapV2Router: INVALID_PATH');
              uint amountIn = msg.value;
              IWETH(WETH).deposit{value: amountIn}();
              assert(IWETH(WETH).transfer(UniswapV2Library.pairFor(factory, path[0], path[1]), amountIn));
              uint balanceBefore = IERC20Uniswap(path[path.length - 1]).balanceOf(to);
              _swapSupportingFeeOnTransferTokens(path, to);
              require(
                  IERC20Uniswap(path[path.length - 1]).balanceOf(to).sub(balanceBefore) >= amountOutMin,
                  'UniswapV2Router: INSUFFICIENT_OUTPUT_AMOUNT'
              );
          }
          function swapExactTokensForETHSupportingFeeOnTransferTokens(
              uint amountIn,
              uint amountOutMin,
              address[] calldata path,
              address to,
              uint deadline
          )
              external
              virtual
              override
              ensure(deadline)
          {
              require(path[path.length - 1] == WETH, 'UniswapV2Router: INVALID_PATH');
              TransferHelper.safeTransferFrom(
                  path[0], msg.sender, UniswapV2Library.pairFor(factory, path[0], path[1]), amountIn
              );
              _swapSupportingFeeOnTransferTokens(path, address(this));
              uint amountOut = IERC20Uniswap(WETH).balanceOf(address(this));
              require(amountOut >= amountOutMin, 'UniswapV2Router: INSUFFICIENT_OUTPUT_AMOUNT');
              IWETH(WETH).withdraw(amountOut);
              TransferHelper.safeTransferETH(to, amountOut);
          }
      
          // **** LIBRARY FUNCTIONS ****
          function quote(uint amountA, uint reserveA, uint reserveB) public pure virtual override returns (uint amountB) {
              return UniswapV2Library.quote(amountA, reserveA, reserveB);
          }
      
          function getAmountOut(uint amountIn, uint reserveIn, uint reserveOut)
              public
              pure
              virtual
              override
              returns (uint amountOut)
          {
              return UniswapV2Library.getAmountOut(amountIn, reserveIn, reserveOut);
          }
      
          function getAmountIn(uint amountOut, uint reserveIn, uint reserveOut)
              public
              pure
              virtual
              override
              returns (uint amountIn)
          {
              return UniswapV2Library.getAmountIn(amountOut, reserveIn, reserveOut);
          }
      
          function getAmountsOut(uint amountIn, address[] memory path)
              public
              view
              virtual
              override
              returns (uint[] memory amounts)
          {
              return UniswapV2Library.getAmountsOut(factory, amountIn, path);
          }
      
          function getAmountsIn(uint amountOut, address[] memory path)
              public
              view
              virtual
              override
              returns (uint[] memory amounts)
          {
              return UniswapV2Library.getAmountsIn(factory, amountOut, path);
          }
      }

      File 2 of 4: UniswapV2Pair
      // File: contracts/uniswapv2/interfaces/IUniswapV2Factory.sol
      
      pragma solidity >=0.5.0;
      
      interface IUniswapV2Factory {
          event PairCreated(address indexed token0, address indexed token1, address pair, uint);
      
          function feeTo() external view returns (address);
          function feeToSetter() external view returns (address);
          function migrator() external view returns (address);
      
          function getPair(address tokenA, address tokenB) external view returns (address pair);
          function allPairs(uint) external view returns (address pair);
          function allPairsLength() external view returns (uint);
      
          function createPair(address tokenA, address tokenB) external returns (address pair);
      
          function setFeeTo(address) external;
          function setFeeToSetter(address) external;
          function setMigrator(address) external;
      }
      
      // File: contracts/uniswapv2/libraries/SafeMath.sol
      
      pragma solidity =0.6.12;
      
      // a library for performing overflow-safe math, courtesy of DappHub (https://github.com/dapphub/ds-math)
      
      library SafeMathUniswap {
          function add(uint x, uint y) internal pure returns (uint z) {
              require((z = x + y) >= x, 'ds-math-add-overflow');
          }
      
          function sub(uint x, uint y) internal pure returns (uint z) {
              require((z = x - y) <= x, 'ds-math-sub-underflow');
          }
      
          function mul(uint x, uint y) internal pure returns (uint z) {
              require(y == 0 || (z = x * y) / y == x, 'ds-math-mul-overflow');
          }
      }
      
      // File: contracts/uniswapv2/UniswapV2ERC20.sol
      
      pragma solidity =0.6.12;
      
      
      contract UniswapV2ERC20 {
          using SafeMathUniswap for uint;
      
          string public constant name = 'SushiSwap LP Token';
          string public constant symbol = 'SLP';
          uint8 public constant decimals = 18;
          uint  public totalSupply;
          mapping(address => uint) public balanceOf;
          mapping(address => mapping(address => uint)) public allowance;
      
          bytes32 public DOMAIN_SEPARATOR;
          // keccak256("Permit(address owner,address spender,uint256 value,uint256 nonce,uint256 deadline)");
          bytes32 public constant PERMIT_TYPEHASH = 0x6e71edae12b1b97f4d1f60370fef10105fa2faae0126114a169c64845d6126c9;
          mapping(address => uint) public nonces;
      
          event Approval(address indexed owner, address indexed spender, uint value);
          event Transfer(address indexed from, address indexed to, uint value);
      
          constructor() public {
              uint chainId;
              assembly {
                  chainId := chainid()
              }
              DOMAIN_SEPARATOR = keccak256(
                  abi.encode(
                      keccak256('EIP712Domain(string name,string version,uint256 chainId,address verifyingContract)'),
                      keccak256(bytes(name)),
                      keccak256(bytes('1')),
                      chainId,
                      address(this)
                  )
              );
          }
      
          function _mint(address to, uint value) internal {
              totalSupply = totalSupply.add(value);
              balanceOf[to] = balanceOf[to].add(value);
              emit Transfer(address(0), to, value);
          }
      
          function _burn(address from, uint value) internal {
              balanceOf[from] = balanceOf[from].sub(value);
              totalSupply = totalSupply.sub(value);
              emit Transfer(from, address(0), value);
          }
      
          function _approve(address owner, address spender, uint value) private {
              allowance[owner][spender] = value;
              emit Approval(owner, spender, value);
          }
      
          function _transfer(address from, address to, uint value) private {
              balanceOf[from] = balanceOf[from].sub(value);
              balanceOf[to] = balanceOf[to].add(value);
              emit Transfer(from, to, value);
          }
      
          function approve(address spender, uint value) external returns (bool) {
              _approve(msg.sender, spender, value);
              return true;
          }
      
          function transfer(address to, uint value) external returns (bool) {
              _transfer(msg.sender, to, value);
              return true;
          }
      
          function transferFrom(address from, address to, uint value) external returns (bool) {
              if (allowance[from][msg.sender] != uint(-1)) {
                  allowance[from][msg.sender] = allowance[from][msg.sender].sub(value);
              }
              _transfer(from, to, value);
              return true;
          }
      
          function permit(address owner, address spender, uint value, uint deadline, uint8 v, bytes32 r, bytes32 s) external {
              require(deadline >= block.timestamp, 'UniswapV2: EXPIRED');
              bytes32 digest = keccak256(
                  abi.encodePacked(
                      '\x19\x01',
                      DOMAIN_SEPARATOR,
                      keccak256(abi.encode(PERMIT_TYPEHASH, owner, spender, value, nonces[owner]++, deadline))
                  )
              );
              address recoveredAddress = ecrecover(digest, v, r, s);
              require(recoveredAddress != address(0) && recoveredAddress == owner, 'UniswapV2: INVALID_SIGNATURE');
              _approve(owner, spender, value);
          }
      }
      
      // File: contracts/uniswapv2/libraries/Math.sol
      
      pragma solidity =0.6.12;
      
      // a library for performing various math operations
      
      library Math {
          function min(uint x, uint y) internal pure returns (uint z) {
              z = x < y ? x : y;
          }
      
          // babylonian method (https://en.wikipedia.org/wiki/Methods_of_computing_square_roots#Babylonian_method)
          function sqrt(uint y) internal pure returns (uint z) {
              if (y > 3) {
                  z = y;
                  uint x = y / 2 + 1;
                  while (x < z) {
                      z = x;
                      x = (y / x + x) / 2;
                  }
              } else if (y != 0) {
                  z = 1;
              }
          }
      }
      
      // File: contracts/uniswapv2/libraries/UQ112x112.sol
      
      pragma solidity =0.6.12;
      
      // a library for handling binary fixed point numbers (https://en.wikipedia.org/wiki/Q_(number_format))
      
      // range: [0, 2**112 - 1]
      // resolution: 1 / 2**112
      
      library UQ112x112 {
          uint224 constant Q112 = 2**112;
      
          // encode a uint112 as a UQ112x112
          function encode(uint112 y) internal pure returns (uint224 z) {
              z = uint224(y) * Q112; // never overflows
          }
      
          // divide a UQ112x112 by a uint112, returning a UQ112x112
          function uqdiv(uint224 x, uint112 y) internal pure returns (uint224 z) {
              z = x / uint224(y);
          }
      }
      
      // File: contracts/uniswapv2/interfaces/IERC20.sol
      
      pragma solidity >=0.5.0;
      
      interface IERC20Uniswap {
          event Approval(address indexed owner, address indexed spender, uint value);
          event Transfer(address indexed from, address indexed to, uint value);
      
          function name() external view returns (string memory);
          function symbol() external view returns (string memory);
          function decimals() external view returns (uint8);
          function totalSupply() external view returns (uint);
          function balanceOf(address owner) external view returns (uint);
          function allowance(address owner, address spender) external view returns (uint);
      
          function approve(address spender, uint value) external returns (bool);
          function transfer(address to, uint value) external returns (bool);
          function transferFrom(address from, address to, uint value) external returns (bool);
      }
      
      // File: contracts/uniswapv2/interfaces/IUniswapV2Callee.sol
      
      pragma solidity >=0.5.0;
      
      interface IUniswapV2Callee {
          function uniswapV2Call(address sender, uint amount0, uint amount1, bytes calldata data) external;
      }
      
      // File: contracts/uniswapv2/UniswapV2Pair.sol
      
      pragma solidity =0.6.12;
      
      
      
      
      
      
      
      
      interface IMigrator {
          // Return the desired amount of liquidity token that the migrator wants.
          function desiredLiquidity() external view returns (uint256);
      }
      
      contract UniswapV2Pair is UniswapV2ERC20 {
          using SafeMathUniswap  for uint;
          using UQ112x112 for uint224;
      
          uint public constant MINIMUM_LIQUIDITY = 10**3;
          bytes4 private constant SELECTOR = bytes4(keccak256(bytes('transfer(address,uint256)')));
      
          address public factory;
          address public token0;
          address public token1;
      
          uint112 private reserve0;           // uses single storage slot, accessible via getReserves
          uint112 private reserve1;           // uses single storage slot, accessible via getReserves
          uint32  private blockTimestampLast; // uses single storage slot, accessible via getReserves
      
          uint public price0CumulativeLast;
          uint public price1CumulativeLast;
          uint public kLast; // reserve0 * reserve1, as of immediately after the most recent liquidity event
      
          uint private unlocked = 1;
          modifier lock() {
              require(unlocked == 1, 'UniswapV2: LOCKED');
              unlocked = 0;
              _;
              unlocked = 1;
          }
      
          function getReserves() public view returns (uint112 _reserve0, uint112 _reserve1, uint32 _blockTimestampLast) {
              _reserve0 = reserve0;
              _reserve1 = reserve1;
              _blockTimestampLast = blockTimestampLast;
          }
      
          function _safeTransfer(address token, address to, uint value) private {
              (bool success, bytes memory data) = token.call(abi.encodeWithSelector(SELECTOR, to, value));
              require(success && (data.length == 0 || abi.decode(data, (bool))), 'UniswapV2: TRANSFER_FAILED');
          }
      
          event Mint(address indexed sender, uint amount0, uint amount1);
          event Burn(address indexed sender, uint amount0, uint amount1, address indexed to);
          event Swap(
              address indexed sender,
              uint amount0In,
              uint amount1In,
              uint amount0Out,
              uint amount1Out,
              address indexed to
          );
          event Sync(uint112 reserve0, uint112 reserve1);
      
          constructor() public {
              factory = msg.sender;
          }
      
          // called once by the factory at time of deployment
          function initialize(address _token0, address _token1) external {
              require(msg.sender == factory, 'UniswapV2: FORBIDDEN'); // sufficient check
              token0 = _token0;
              token1 = _token1;
          }
      
          // update reserves and, on the first call per block, price accumulators
          function _update(uint balance0, uint balance1, uint112 _reserve0, uint112 _reserve1) private {
              require(balance0 <= uint112(-1) && balance1 <= uint112(-1), 'UniswapV2: OVERFLOW');
              uint32 blockTimestamp = uint32(block.timestamp % 2**32);
              uint32 timeElapsed = blockTimestamp - blockTimestampLast; // overflow is desired
              if (timeElapsed > 0 && _reserve0 != 0 && _reserve1 != 0) {
                  // * never overflows, and + overflow is desired
                  price0CumulativeLast += uint(UQ112x112.encode(_reserve1).uqdiv(_reserve0)) * timeElapsed;
                  price1CumulativeLast += uint(UQ112x112.encode(_reserve0).uqdiv(_reserve1)) * timeElapsed;
              }
              reserve0 = uint112(balance0);
              reserve1 = uint112(balance1);
              blockTimestampLast = blockTimestamp;
              emit Sync(reserve0, reserve1);
          }
      
          // if fee is on, mint liquidity equivalent to 1/6th of the growth in sqrt(k)
          function _mintFee(uint112 _reserve0, uint112 _reserve1) private returns (bool feeOn) {
              address feeTo = IUniswapV2Factory(factory).feeTo();
              feeOn = feeTo != address(0);
              uint _kLast = kLast; // gas savings
              if (feeOn) {
                  if (_kLast != 0) {
                      uint rootK = Math.sqrt(uint(_reserve0).mul(_reserve1));
                      uint rootKLast = Math.sqrt(_kLast);
                      if (rootK > rootKLast) {
                          uint numerator = totalSupply.mul(rootK.sub(rootKLast));
                          uint denominator = rootK.mul(5).add(rootKLast);
                          uint liquidity = numerator / denominator;
                          if (liquidity > 0) _mint(feeTo, liquidity);
                      }
                  }
              } else if (_kLast != 0) {
                  kLast = 0;
              }
          }
      
          // this low-level function should be called from a contract which performs important safety checks
          function mint(address to) external lock returns (uint liquidity) {
              (uint112 _reserve0, uint112 _reserve1,) = getReserves(); // gas savings
              uint balance0 = IERC20Uniswap(token0).balanceOf(address(this));
              uint balance1 = IERC20Uniswap(token1).balanceOf(address(this));
              uint amount0 = balance0.sub(_reserve0);
              uint amount1 = balance1.sub(_reserve1);
      
              bool feeOn = _mintFee(_reserve0, _reserve1);
              uint _totalSupply = totalSupply; // gas savings, must be defined here since totalSupply can update in _mintFee
              if (_totalSupply == 0) {
                  address migrator = IUniswapV2Factory(factory).migrator();
                  if (msg.sender == migrator) {
                      liquidity = IMigrator(migrator).desiredLiquidity();
                      require(liquidity > 0 && liquidity != uint256(-1), "Bad desired liquidity");
                  } else {
                      require(migrator == address(0), "Must not have migrator");
                      liquidity = Math.sqrt(amount0.mul(amount1)).sub(MINIMUM_LIQUIDITY);
                      _mint(address(0), MINIMUM_LIQUIDITY); // permanently lock the first MINIMUM_LIQUIDITY tokens
                  }
              } else {
                  liquidity = Math.min(amount0.mul(_totalSupply) / _reserve0, amount1.mul(_totalSupply) / _reserve1);
              }
              require(liquidity > 0, 'UniswapV2: INSUFFICIENT_LIQUIDITY_MINTED');
              _mint(to, liquidity);
      
              _update(balance0, balance1, _reserve0, _reserve1);
              if (feeOn) kLast = uint(reserve0).mul(reserve1); // reserve0 and reserve1 are up-to-date
              emit Mint(msg.sender, amount0, amount1);
          }
      
          // this low-level function should be called from a contract which performs important safety checks
          function burn(address to) external lock returns (uint amount0, uint amount1) {
              (uint112 _reserve0, uint112 _reserve1,) = getReserves(); // gas savings
              address _token0 = token0;                                // gas savings
              address _token1 = token1;                                // gas savings
              uint balance0 = IERC20Uniswap(_token0).balanceOf(address(this));
              uint balance1 = IERC20Uniswap(_token1).balanceOf(address(this));
              uint liquidity = balanceOf[address(this)];
      
              bool feeOn = _mintFee(_reserve0, _reserve1);
              uint _totalSupply = totalSupply; // gas savings, must be defined here since totalSupply can update in _mintFee
              amount0 = liquidity.mul(balance0) / _totalSupply; // using balances ensures pro-rata distribution
              amount1 = liquidity.mul(balance1) / _totalSupply; // using balances ensures pro-rata distribution
              require(amount0 > 0 && amount1 > 0, 'UniswapV2: INSUFFICIENT_LIQUIDITY_BURNED');
              _burn(address(this), liquidity);
              _safeTransfer(_token0, to, amount0);
              _safeTransfer(_token1, to, amount1);
              balance0 = IERC20Uniswap(_token0).balanceOf(address(this));
              balance1 = IERC20Uniswap(_token1).balanceOf(address(this));
      
              _update(balance0, balance1, _reserve0, _reserve1);
              if (feeOn) kLast = uint(reserve0).mul(reserve1); // reserve0 and reserve1 are up-to-date
              emit Burn(msg.sender, amount0, amount1, to);
          }
      
          // this low-level function should be called from a contract which performs important safety checks
          function swap(uint amount0Out, uint amount1Out, address to, bytes calldata data) external lock {
              require(amount0Out > 0 || amount1Out > 0, 'UniswapV2: INSUFFICIENT_OUTPUT_AMOUNT');
              (uint112 _reserve0, uint112 _reserve1,) = getReserves(); // gas savings
              require(amount0Out < _reserve0 && amount1Out < _reserve1, 'UniswapV2: INSUFFICIENT_LIQUIDITY');
      
              uint balance0;
              uint balance1;
              { // scope for _token{0,1}, avoids stack too deep errors
              address _token0 = token0;
              address _token1 = token1;
              require(to != _token0 && to != _token1, 'UniswapV2: INVALID_TO');
              if (amount0Out > 0) _safeTransfer(_token0, to, amount0Out); // optimistically transfer tokens
              if (amount1Out > 0) _safeTransfer(_token1, to, amount1Out); // optimistically transfer tokens
              if (data.length > 0) IUniswapV2Callee(to).uniswapV2Call(msg.sender, amount0Out, amount1Out, data);
              balance0 = IERC20Uniswap(_token0).balanceOf(address(this));
              balance1 = IERC20Uniswap(_token1).balanceOf(address(this));
              }
              uint amount0In = balance0 > _reserve0 - amount0Out ? balance0 - (_reserve0 - amount0Out) : 0;
              uint amount1In = balance1 > _reserve1 - amount1Out ? balance1 - (_reserve1 - amount1Out) : 0;
              require(amount0In > 0 || amount1In > 0, 'UniswapV2: INSUFFICIENT_INPUT_AMOUNT');
              { // scope for reserve{0,1}Adjusted, avoids stack too deep errors
              uint balance0Adjusted = balance0.mul(1000).sub(amount0In.mul(3));
              uint balance1Adjusted = balance1.mul(1000).sub(amount1In.mul(3));
              require(balance0Adjusted.mul(balance1Adjusted) >= uint(_reserve0).mul(_reserve1).mul(1000**2), 'UniswapV2: K');
              }
      
              _update(balance0, balance1, _reserve0, _reserve1);
              emit Swap(msg.sender, amount0In, amount1In, amount0Out, amount1Out, to);
          }
      
          // force balances to match reserves
          function skim(address to) external lock {
              address _token0 = token0; // gas savings
              address _token1 = token1; // gas savings
              _safeTransfer(_token0, to, IERC20Uniswap(_token0).balanceOf(address(this)).sub(reserve0));
              _safeTransfer(_token1, to, IERC20Uniswap(_token1).balanceOf(address(this)).sub(reserve1));
          }
      
          // force reserves to match balances
          function sync() external lock {
              _update(IERC20Uniswap(token0).balanceOf(address(this)), IERC20Uniswap(token1).balanceOf(address(this)), reserve0, reserve1);
          }
      }

      File 3 of 4: OlympusERC20Token
      // SPDX-License-Identifier: AGPL-3.0-or-later
      pragma solidity 0.7.5;
      
      /**
       * @dev Intended to update the TWAP for a token based on accepting an update call from that token.
       *  expectation is to have this happen in the _beforeTokenTransfer function of ERC20.
       *  Provides a method for a token to register its price sourve adaptor.
       *  Provides a function for a token to register its TWAP updater. Defaults to token itself.
       *  Provides a function a tokent to set its TWAP epoch.
       *  Implements automatic closeing and opening up a TWAP epoch when epoch ends.
       *  Provides a function to report the TWAP from the last epoch when passed a token address.
       */
      interface ITWAPOracle {
      
        function uniV2CompPairAddressForLastEpochUpdateBlockTimstamp( address ) external returns ( uint32 );
      
        function priceTokenAddressForPricingTokenAddressForLastEpochUpdateBlockTimstamp( address tokenToPrice_, address tokenForPriceComparison_, uint epochPeriod_ ) external returns ( uint32 );
      
        function pricedTokenForPricingTokenForEpochPeriodForPrice( address, address, uint ) external returns ( uint );
      
        function pricedTokenForPricingTokenForEpochPeriodForLastEpochPrice( address, address, uint ) external returns ( uint );
      
        function updateTWAP( address uniV2CompatPairAddressToUpdate_, uint eopchPeriodToUpdate_ ) external returns ( bool );
      }
      
      library EnumerableSet {
      
        // To implement this library for multiple types with as little code
        // repetition as possible, we write it in terms of a generic Set type with
        // bytes32 values.
        // The Set implementation uses private functions, and user-facing
        // implementations (such as AddressSet) are just wrappers around the
        // underlying Set.
        // This means that we can only create new EnumerableSets for types that fit
        // in bytes32.
        struct Set {
          // Storage of set values
          bytes32[] _values;
      
          // Position of the value in the `values` array, plus 1 because index 0
          // means a value is not in the set.
          mapping (bytes32 => uint256) _indexes;
        }
      
        /**
         * @dev Add a value to a set. O(1).
         *
         * Returns true if the value was added to the set, that is if it was not
         * already present.
         */
        function _add(Set storage set, bytes32 value) private returns (bool) {
          if (!_contains(set, value)) {
            set._values.push(value);
            // The value is stored at length-1, but we add 1 to all indexes
            // and use 0 as a sentinel value
            set._indexes[value] = set._values.length;
            return true;
          } else {
            return false;
          }
        }
      
        /**
         * @dev Removes a value from a set. O(1).
         *
         * Returns true if the value was removed from the set, that is if it was
         * present.
         */
        function _remove(Set storage set, bytes32 value) private returns (bool) {
          // We read and store the value's index to prevent multiple reads from the same storage slot
          uint256 valueIndex = set._indexes[value];
      
          if (valueIndex != 0) { // Equivalent to contains(set, value)
            // To delete an element from the _values array in O(1), we swap the element to delete with the last one in
            // the array, and then remove the last element (sometimes called as 'swap and pop').
            // This modifies the order of the array, as noted in {at}.
      
            uint256 toDeleteIndex = valueIndex - 1;
            uint256 lastIndex = set._values.length - 1;
      
            // When the value to delete is the last one, the swap operation is unnecessary. However, since this occurs
            // so rarely, we still do the swap anyway to avoid the gas cost of adding an 'if' statement.
      
            bytes32 lastvalue = set._values[lastIndex];
      
            // Move the last value to the index where the value to delete is
            set._values[toDeleteIndex] = lastvalue;
            // Update the index for the moved value
            set._indexes[lastvalue] = toDeleteIndex + 1; // All indexes are 1-based
      
            // Delete the slot where the moved value was stored
            set._values.pop();
      
            // Delete the index for the deleted slot
            delete set._indexes[value];
      
            return true;
          } else {
            return false;
          }
        }
      
        /**
         * @dev Returns true if the value is in the set. O(1).
         */
        function _contains(Set storage set, bytes32 value) private view returns (bool) {
          return set._indexes[value] != 0;
        }
      
        /**
         * @dev Returns the number of values on the set. O(1).
         */
        function _length(Set storage set) private view returns (uint256) {
          return set._values.length;
        }
      
         /**
          * @dev Returns the value stored at position `index` in the set. O(1).
          *
          * Note that there are no guarantees on the ordering of values inside the
          * array, and it may change when more values are added or removed.
          *
          * Requirements:
          *
          * - `index` must be strictly less than {length}.
          */
        function _at(Set storage set, uint256 index) private view returns (bytes32) {
          require(set._values.length > index, "EnumerableSet: index out of bounds");
          return set._values[index];
        }
      
        function _getValues( Set storage set_ ) private view returns ( bytes32[] storage ) {
          return set_._values;
        }
      
        // TODO needs insert function that maintains order.
        // TODO needs NatSpec documentation comment.
        /**
         * Inserts new value by moving existing value at provided index to end of array and setting provided value at provided index
         */
        function _insert(Set storage set_, uint256 index_, bytes32 valueToInsert_ ) private returns ( bool ) {
          require(  set_._values.length > index_ );
          require( !_contains( set_, valueToInsert_ ), "Remove value you wish to insert if you wish to reorder array." );
          bytes32 existingValue_ = _at( set_, index_ );
          set_._values[index_] = valueToInsert_;
          return _add( set_, existingValue_);
        } 
      
        struct Bytes4Set {
          Set _inner;
        }
      
        /**
         * @dev Add a value to a set. O(1).
         *
         * Returns true if the value was added to the set, that is if it was not
         * already present.
         */
        function add(Bytes4Set storage set, bytes4 value) internal returns (bool) {
          return _add(set._inner, value);
        }
      
        /**
         * @dev Removes a value from a set. O(1).
         *
         * Returns true if the value was removed from the set, that is if it was
         * present.
         */
        function remove(Bytes4Set storage set, bytes4 value) internal returns (bool) {
          return _remove(set._inner, value);
        }
      
        /**
         * @dev Returns true if the value is in the set. O(1).
         */
        function contains(Bytes4Set storage set, bytes4 value) internal view returns (bool) {
          return _contains(set._inner, value);
        }
      
        /**
         * @dev Returns the number of values on the set. O(1).
         */
        function length(Bytes4Set storage set) internal view returns (uint256) {
          return _length(set._inner);
        }
      
        /**
         * @dev Returns the value stored at position `index` in the set. O(1).
         *
         * Note that there are no guarantees on the ordering of values inside the
         * array, and it may change when more values are added or removed.
         *
         * Requirements:
         *
         * - `index` must be strictly less than {length}.
         */
        function at(Bytes4Set storage set, uint256 index) internal view returns ( bytes4 ) {
          return bytes4( _at( set._inner, index ) );
        }
      
        function getValues( Bytes4Set storage set_ ) internal view returns ( bytes4[] memory ) {
          bytes4[] memory bytes4Array_;
          for( uint256 iteration_ = 0; _length( set_._inner ) > iteration_; iteration_++ ) {
            bytes4Array_[iteration_] = bytes4( _at( set_._inner, iteration_ ) );
          }
          return bytes4Array_;
        }
      
        function insert( Bytes4Set storage set_, uint256 index_, bytes4 valueToInsert_ ) internal returns ( bool ) {
          return _insert( set_._inner, index_, valueToInsert_ );
        }
      
          struct Bytes32Set {
              Set _inner;
          }
      
          /**
           * @dev Add a value to a set. O(1).
           *
           * Returns true if the value was added to the set, that is if it was not
           * already present.
           */
          function add(Bytes32Set storage set, bytes32 value) internal returns (bool) {
              return _add(set._inner, value);
          }
      
          /**
           * @dev Removes a value from a set. O(1).
           *
           * Returns true if the value was removed from the set, that is if it was
           * present.
           */
          function remove(Bytes32Set storage set, bytes32 value) internal returns (bool) {
              return _remove(set._inner, value);
          }
      
          /**
           * @dev Returns true if the value is in the set. O(1).
           */
          function contains(Bytes32Set storage set, bytes32 value) internal view returns (bool) {
              return _contains(set._inner, value);
          }
      
          /**
           * @dev Returns the number of values on the set. O(1).
           */
          function length(Bytes32Set storage set) internal view returns (uint256) {
              return _length(set._inner);
          }
      
          /**
           * @dev Returns the value stored at position `index` in the set. O(1).
           *
           * Note that there are no guarantees on the ordering of values inside the
           * array, and it may change when more values are added or removed.
           *
           * Requirements:
           *
           * - `index` must be strictly less than {length}.
           */
          function at(Bytes32Set storage set, uint256 index) internal view returns ( bytes32 ) {
              return _at(set._inner, index);
          }
      
        function getValues( Bytes32Set storage set_ ) internal view returns ( bytes4[] memory ) {
          bytes4[] memory bytes4Array_;
      
            for( uint256 iteration_ = 0; _length( set_._inner ) >= iteration_; iteration_++ ){
              bytes4Array_[iteration_] = bytes4( at( set_, iteration_ ) );
            }
      
            return bytes4Array_;
        }
      
        function insert( Bytes32Set storage set_, uint256 index_, bytes32 valueToInsert_ ) internal returns ( bool ) {
          return _insert( set_._inner, index_, valueToInsert_ );
        }
      
        // AddressSet
        struct AddressSet {
          Set _inner;
        }
      
        /**
         * @dev Add a value to a set. O(1).
         *
         * Returns true if the value was added to the set, that is if it was not
         * already present.
         */
        function add(AddressSet storage set, address value) internal returns (bool) {
          return _add(set._inner, bytes32(uint256(value)));
        }
      
        /**
         * @dev Removes a value from a set. O(1).
         *
         * Returns true if the value was removed from the set, that is if it was
         * present.
         */
        function remove(AddressSet storage set, address value) internal returns (bool) {
          return _remove(set._inner, bytes32(uint256(value)));
        }
      
        /**
         * @dev Returns true if the value is in the set. O(1).
         */
        function contains(AddressSet storage set, address value) internal view returns (bool) {
          return _contains(set._inner, bytes32(uint256(value)));
        }
      
        /**
         * @dev Returns the number of values in the set. O(1).
         */
        function length(AddressSet storage set) internal view returns (uint256) {
          return _length(set._inner);
        }
      
        /**
         * @dev Returns the value stored at position `index` in the set. O(1).
         *
         * Note that there are no guarantees on the ordering of values inside the
         * array, and it may change when more values are added or removed.
         *
         * Requirements:
         *
         * - `index` must be strictly less than {length}.
         */
        function at(AddressSet storage set, uint256 index) internal view returns (address) {
          return address(uint256(_at(set._inner, index)));
        }
      
        /**
         * TODO Might require explicit conversion of bytes32[] to address[].
         *  Might require iteration.
         */
        function getValues( AddressSet storage set_ ) internal view returns ( address[] memory ) {
      
          address[] memory addressArray;
      
          for( uint256 iteration_ = 0; _length(set_._inner) >= iteration_; iteration_++ ){
            addressArray[iteration_] = at( set_, iteration_ );
          }
      
          return addressArray;
        }
      
        function insert(AddressSet storage set_, uint256 index_, address valueToInsert_ ) internal returns ( bool ) {
          return _insert( set_._inner, index_, bytes32(uint256(valueToInsert_)) );
        }
      
      
          // UintSet
      
          struct UintSet {
              Set _inner;
          }
      
          /**
           * @dev Add a value to a set. O(1).
           *
           * Returns true if the value was added to the set, that is if it was not
           * already present.
           */
          function add(UintSet storage set, uint256 value) internal returns (bool) {
              return _add(set._inner, bytes32(value));
          }
      
          /**
           * @dev Removes a value from a set. O(1).
           *
           * Returns true if the value was removed from the set, that is if it was
           * present.
           */
          function remove(UintSet storage set, uint256 value) internal returns (bool) {
              return _remove(set._inner, bytes32(value));
          }
      
          /**
           * @dev Returns true if the value is in the set. O(1).
           */
          function contains(UintSet storage set, uint256 value) internal view returns (bool) {
              return _contains(set._inner, bytes32(value));
          }
      
          /**
           * @dev Returns the number of values on the set. O(1).
           */
          function length(UintSet storage set) internal view returns (uint256) {
              return _length(set._inner);
          }
      
         /**
          * @dev Returns the value stored at position `index` in the set. O(1).
          *
          * Note that there are no guarantees on the ordering of values inside the
          * array, and it may change when more values are added or removed.
          *
          * Requirements:
          *
          * - `index` must be strictly less than {length}.
          */
          function at(UintSet storage set, uint256 index) internal view returns (uint256) {
              return uint256(_at(set._inner, index));
          }
      
          struct UInt256Set {
              Set _inner;
          }
      
          /**
           * @dev Add a value to a set. O(1).
           *
           * Returns true if the value was added to the set, that is if it was not
           * already present.
           */
          function add(UInt256Set storage set, uint256 value) internal returns (bool) {
              return _add(set._inner, bytes32(value));
          }
      
          /**
           * @dev Removes a value from a set. O(1).
           *
           * Returns true if the value was removed from the set, that is if it was
           * present.
           */
          function remove(UInt256Set storage set, uint256 value) internal returns (bool) {
              return _remove(set._inner, bytes32(value));
          }
      
          /**
           * @dev Returns true if the value is in the set. O(1).
           */
          function contains(UInt256Set storage set, uint256 value) internal view returns (bool) {
              return _contains(set._inner, bytes32(value));
          }
      
          /**
           * @dev Returns the number of values on the set. O(1).
           */
          function length(UInt256Set storage set) internal view returns (uint256) {
              return _length(set._inner);
          }
      
          /**
           * @dev Returns the value stored at position `index` in the set. O(1).
           *
           * Note that there are no guarantees on the ordering of values inside the
           * array, and it may change when more values are added or removed.
           *
           * Requirements:
           *
           * - `index` must be strictly less than {length}.
           */
          function at(UInt256Set storage set, uint256 index) internal view returns (uint256) {
              return uint256(_at(set._inner, index));
          }
      }
      
      interface IERC20 {
        /**
         * @dev Returns the amount of tokens in existence.
         */
        function totalSupply() external view returns (uint256);
      
        /**
         * @dev Returns the amount of tokens owned by `account`.
         */
        function balanceOf(address account) external view returns (uint256);
      
        /**
         * @dev Moves `amount` tokens from the caller's account to `recipient`.
         *
         * Returns a boolean value indicating whether the operation succeeded.
         *
         * Emits a {Transfer} event.
         */
        function transfer(address recipient, uint256 amount) external returns (bool);
      
        /**
         * @dev Returns the remaining number of tokens that `spender` will be
         * allowed to spend on behalf of `owner` through {transferFrom}. This is
         * zero by default.
         *
         * This value changes when {approve} or {transferFrom} are called.
         */
        function allowance(address owner, address spender) external view returns (uint256);
      
        /**
         * @dev Sets `amount` as the allowance of `spender` over the caller's tokens.
         *
         * Returns a boolean value indicating whether the operation succeeded.
         *
         * IMPORTANT: Beware that changing an allowance with this method brings the risk
         * that someone may use both the old and the new allowance by unfortunate
         * transaction ordering. One possible solution to mitigate this race
         * condition is to first reduce the spender's allowance to 0 and set the
         * desired value afterwards:
         * https://github.com/ethereum/EIPs/issues/20#issuecomment-263524729
         *
         * Emits an {Approval} event.
         */
        function approve(address spender, uint256 amount) external returns (bool);
      
        /**
         * @dev Moves `amount` tokens from `sender` to `recipient` using the
         * allowance mechanism. `amount` is then deducted from the caller's
         * allowance.
         *
         * Returns a boolean value indicating whether the operation succeeded.
         *
         * Emits a {Transfer} event.
         */
        function transferFrom(address sender, address recipient, uint256 amount) external returns (bool);
      
        /**
         * @dev Emitted when `value` tokens are moved from one account (`from`) to
         * another (`to`).
         *
         * Note that `value` may be zero.
         */
        event Transfer(address indexed from, address indexed to, uint256 value);
      
        /**
         * @dev Emitted when the allowance of a `spender` for an `owner` is set by
         * a call to {approve}. `value` is the new allowance.
         */
        event Approval(address indexed owner, address indexed spender, uint256 value);
      }
      
      library SafeMath {
          /**
           * @dev Returns the addition of two unsigned integers, reverting on
           * overflow.
           *
           * Counterpart to Solidity's `+` operator.
           *
           * Requirements:
           *
           * - Addition cannot overflow.
           */
          function add(uint256 a, uint256 b) internal pure returns (uint256) {
              uint256 c = a + b;
              require(c >= a, "SafeMath: addition overflow");
      
              return c;
          }
      
          /**
           * @dev Returns the subtraction of two unsigned integers, reverting on
           * overflow (when the result is negative).
           *
           * Counterpart to Solidity's `-` operator.
           *
           * Requirements:
           *
           * - Subtraction cannot overflow.
           */
          function sub(uint256 a, uint256 b) internal pure returns (uint256) {
              return sub(a, b, "SafeMath: subtraction overflow");
          }
      
          /**
           * @dev Returns the subtraction of two unsigned integers, reverting with custom message on
           * overflow (when the result is negative).
           *
           * Counterpart to Solidity's `-` operator.
           *
           * Requirements:
           *
           * - Subtraction cannot overflow.
           */
          function sub(uint256 a, uint256 b, string memory errorMessage) internal pure returns (uint256) {
              require(b <= a, errorMessage);
              uint256 c = a - b;
      
              return c;
          }
      
          /**
           * @dev Returns the multiplication of two unsigned integers, reverting on
           * overflow.
           *
           * Counterpart to Solidity's `*` operator.
           *
           * Requirements:
           *
           * - Multiplication cannot overflow.
           */
          function mul(uint256 a, uint256 b) internal pure returns (uint256) {
              // Gas optimization: this is cheaper than requiring 'a' not being zero, but the
              // benefit is lost if 'b' is also tested.
              // See: https://github.com/OpenZeppelin/openzeppelin-contracts/pull/522
              if (a == 0) {
                  return 0;
              }
      
              uint256 c = a * b;
              require(c / a == b, "SafeMath: multiplication overflow");
      
              return c;
          }
      
          /**
           * @dev Returns the integer division of two unsigned integers. Reverts on
           * division by zero. The result is rounded towards zero.
           *
           * Counterpart to Solidity's `/` operator. Note: this function uses a
           * `revert` opcode (which leaves remaining gas untouched) while Solidity
           * uses an invalid opcode to revert (consuming all remaining gas).
           *
           * Requirements:
           *
           * - The divisor cannot be zero.
           */
          function div(uint256 a, uint256 b) internal pure returns (uint256) {
              return div(a, b, "SafeMath: division by zero");
          }
      
          /**
           * @dev Returns the integer division of two unsigned integers. Reverts with custom message on
           * division by zero. The result is rounded towards zero.
           *
           * Counterpart to Solidity's `/` operator. Note: this function uses a
           * `revert` opcode (which leaves remaining gas untouched) while Solidity
           * uses an invalid opcode to revert (consuming all remaining gas).
           *
           * Requirements:
           *
           * - The divisor cannot be zero.
           */
          function div(uint256 a, uint256 b, string memory errorMessage) internal pure returns (uint256) {
              require(b > 0, errorMessage);
              uint256 c = a / b;
              // assert(a == b * c + a % b); // There is no case in which this doesn't hold
      
              return c;
          }
      
          /**
           * @dev Returns the remainder of dividing two unsigned integers. (unsigned integer modulo),
           * Reverts when dividing by zero.
           *
           * Counterpart to Solidity's `%` operator. This function uses a `revert`
           * opcode (which leaves remaining gas untouched) while Solidity uses an
           * invalid opcode to revert (consuming all remaining gas).
           *
           * Requirements:
           *
           * - The divisor cannot be zero.
           */
          function mod(uint256 a, uint256 b) internal pure returns (uint256) {
              return mod(a, b, "SafeMath: modulo by zero");
          }
      
          /**
           * @dev Returns the remainder of dividing two unsigned integers. (unsigned integer modulo),
           * Reverts with custom message when dividing by zero.
           *
           * Counterpart to Solidity's `%` operator. This function uses a `revert`
           * opcode (which leaves remaining gas untouched) while Solidity uses an
           * invalid opcode to revert (consuming all remaining gas).
           *
           * Requirements:
           *
           * - The divisor cannot be zero.
           */
          function mod(uint256 a, uint256 b, string memory errorMessage) internal pure returns (uint256) {
              require(b != 0, errorMessage);
              return a % b;
          }
      
          // babylonian method (https://en.wikipedia.org/wiki/Methods_of_computing_square_roots#Babylonian_method)
          function sqrrt(uint256 a) internal pure returns (uint c) {
              if (a > 3) {
                  c = a;
                  uint b = add( div( a, 2), 1 );
                  while (b < c) {
                      c = b;
                      b = div( add( div( a, b ), b), 2 );
                  }
              } else if (a != 0) {
                  c = 1;
              }
          }
      
          /*
           * Expects percentage to be trailed by 00,
          */
          function percentageAmount( uint256 total_, uint8 percentage_ ) internal pure returns ( uint256 percentAmount_ ) {
              return div( mul( total_, percentage_ ), 1000 );
          }
      
          /*
           * Expects percentage to be trailed by 00,
          */
          function substractPercentage( uint256 total_, uint8 percentageToSub_ ) internal pure returns ( uint256 result_ ) {
              return sub( total_, div( mul( total_, percentageToSub_ ), 1000 ) );
          }
      
          function percentageOfTotal( uint256 part_, uint256 total_ ) internal pure returns ( uint256 percent_ ) {
              return div( mul(part_, 100) , total_ );
          }
      
          /**
           * Taken from Hypersonic https://github.com/M2629/HyperSonic/blob/main/Math.sol
           * @dev Returns the average of two numbers. The result is rounded towards
           * zero.
           */
          function average(uint256 a, uint256 b) internal pure returns (uint256) {
              // (a + b) / 2 can overflow, so we distribute
              return (a / 2) + (b / 2) + ((a % 2 + b % 2) / 2);
          }
      
          function quadraticPricing( uint256 payment_, uint256 multiplier_ ) internal pure returns (uint256) {
              return sqrrt( mul( multiplier_, payment_ ) );
          }
      
        function bondingCurve( uint256 supply_, uint256 multiplier_ ) internal pure returns (uint256) {
            return mul( multiplier_, supply_ );
        }
      }
      
      abstract contract ERC20
        is 
          IERC20
        {
      
        using SafeMath for uint256;
      
        // TODO comment actual hash value.
        bytes32 constant private ERC20TOKEN_ERC1820_INTERFACE_ID = keccak256( "ERC20Token" );
          
        // Present in ERC777
        mapping (address => uint256) internal _balances;
      
        // Present in ERC777
        mapping (address => mapping (address => uint256)) internal _allowances;
      
        // Present in ERC777
        uint256 internal _totalSupply;
      
        // Present in ERC777
        string internal _name;
          
        // Present in ERC777
        string internal _symbol;
          
        // Present in ERC777
        uint8 internal _decimals;
      
        /**
         * @dev Sets the values for {name} and {symbol}, initializes {decimals} with
         * a default value of 18.
         *
         * To select a different value for {decimals}, use {_setupDecimals}.
         *
         * All three of these values are immutable: they can only be set once during
         * construction.
         */
        constructor (string memory name_, string memory symbol_, uint8 decimals_) {
          _name = name_;
          _symbol = symbol_;
          _decimals = decimals_;
        }
      
        /**
         * @dev Returns the name of the token.
         */
        // Present in ERC777
        function name() public view returns (string memory) {
          return _name;
        }
      
        /**
         * @dev Returns the symbol of the token, usually a shorter version of the
         * name.
         */
        // Present in ERC777
        function symbol() public view returns (string memory) {
          return _symbol;
        }
      
        /**
         * @dev Returns the number of decimals used to get its user representation.
         * For example, if `decimals` equals `2`, a balance of `505` tokens should
         * be displayed to a user as `5,05` (`505 / 10 ** 2`).
         *
         * Tokens usually opt for a value of 18, imitating the relationship between
         * Ether and Wei. This is the value {ERC20} uses, unless {_setupDecimals} is
         * called.
         *
         * NOTE: This information is only used for _display_ purposes: it in
         * no way affects any of the arithmetic of the contract, including
         * {IERC20-balanceOf} and {IERC20-transfer}.
         */
        // Present in ERC777
        function decimals() public view returns (uint8) {
          return _decimals;
        }
      
        /**
         * @dev See {IERC20-totalSupply}.
         */
        // Present in ERC777
        function totalSupply() public view override returns (uint256) {
          return _totalSupply;
        }
      
        /**
         * @dev See {IERC20-balanceOf}.
         */
        // Present in ERC777
        function balanceOf(address account) public view virtual override returns (uint256) {
          return _balances[account];
        }
      
        /**
         * @dev See {IERC20-transfer}.
         *
         * Requirements:
         *
         * - `recipient` cannot be the zero address.
         * - the caller must have a balance of at least `amount`.
         */
        // Overrideen in ERC777
        // Confirm that this behavior changes 
        function transfer(address recipient, uint256 amount) public virtual override returns (bool) {
          _transfer(msg.sender, recipient, amount);
          return true;
        }
      
          /**
           * @dev See {IERC20-allowance}.
           */
          // Present in ERC777
          function allowance(address owner, address spender) public view virtual override returns (uint256) {
              return _allowances[owner][spender];
          }
      
          /**
           * @dev See {IERC20-approve}.
           *
           * Requirements:
           *
           * - `spender` cannot be the zero address.
           */
          // Present in ERC777
          function approve(address spender, uint256 amount) public virtual override returns (bool) {
              _approve(msg.sender, spender, amount);
              return true;
          }
      
          /**
           * @dev See {IERC20-transferFrom}.
           *
           * Emits an {Approval} event indicating the updated allowance. This is not
           * required by the EIP. See the note at the beginning of {ERC20}.
           *
           * Requirements:
           *
           * - `sender` and `recipient` cannot be the zero address.
           * - `sender` must have a balance of at least `amount`.
           * - the caller must have allowance for ``sender``'s tokens of at least
           * `amount`.
           */
          // Present in ERC777
          function transferFrom(address sender, address recipient, uint256 amount) public virtual override returns (bool) {
              _transfer(sender, recipient, amount);
              _approve(sender, msg.sender, _allowances[sender][msg.sender].sub(amount, "ERC20: transfer amount exceeds allowance"));
              return true;
          }
      
          /**
           * @dev Atomically increases the allowance granted to `spender` by the caller.
           *
           * This is an alternative to {approve} that can be used as a mitigation for
           * problems described in {IERC20-approve}.
           *
           * Emits an {Approval} event indicating the updated allowance.
           *
           * Requirements:
           *
           * - `spender` cannot be the zero address.
           */
          function increaseAllowance(address spender, uint256 addedValue) public virtual returns (bool) {
              _approve(msg.sender, spender, _allowances[msg.sender][spender].add(addedValue));
              return true;
          }
      
          /**
           * @dev Atomically decreases the allowance granted to `spender` by the caller.
           *
           * This is an alternative to {approve} that can be used as a mitigation for
           * problems described in {IERC20-approve}.
           *
           * Emits an {Approval} event indicating the updated allowance.
           *
           * Requirements:
           *
           * - `spender` cannot be the zero address.
           * - `spender` must have allowance for the caller of at least
           * `subtractedValue`.
           */
          function decreaseAllowance(address spender, uint256 subtractedValue) public virtual returns (bool) {
              _approve(msg.sender, spender, _allowances[msg.sender][spender].sub(subtractedValue, "ERC20: decreased allowance below zero"));
              return true;
          }
      
        /**
         * @dev Moves tokens `amount` from `sender` to `recipient`.
         *
         * This is internal function is equivalent to {transfer}, and can be used to
         * e.g. implement automatic token fees, slashing mechanisms, etc.
         *
         * Emits a {Transfer} event.
         *
         * Requirements:
         *
         * - `sender` cannot be the zero address.
         * - `recipient` cannot be the zero address.
         * - `sender` must have a balance of at least `amount`.
         */
        function _transfer(address sender, address recipient, uint256 amount) internal virtual {
          require(sender != address(0), "ERC20: transfer from the zero address");
          require(recipient != address(0), "ERC20: transfer to the zero address");
      
          _beforeTokenTransfer(sender, recipient, amount);
      
          _balances[sender] = _balances[sender].sub(amount, "ERC20: transfer amount exceeds balance");
          _balances[recipient] = _balances[recipient].add(amount);
          emit Transfer(sender, recipient, amount);
        }
      
          /** @dev Creates `amount` tokens and assigns them to `account`, increasing
           * the total supply.
           *
           * Emits a {Transfer} event with `from` set to the zero address.
           *
           * Requirements:
           *
           * - `to` cannot be the zero address.
           */
          // Present in ERC777
          function _mint(address account_, uint256 amount_) internal virtual {
              require(account_ != address(0), "ERC20: mint to the zero address");
              _beforeTokenTransfer(address( this ), account_, amount_);
              _totalSupply = _totalSupply.add(amount_);
              _balances[account_] = _balances[account_].add(amount_);
              emit Transfer(address( this ), account_, amount_);
          }
      
          /**
           * @dev Destroys `amount` tokens from `account`, reducing the
           * total supply.
           *
           * Emits a {Transfer} event with `to` set to the zero address.
           *
           * Requirements:
           *
           * - `account` cannot be the zero address.
           * - `account` must have at least `amount` tokens.
           */
          // Present in ERC777
          function _burn(address account, uint256 amount) internal virtual {
              require(account != address(0), "ERC20: burn from the zero address");
      
              _beforeTokenTransfer(account, address(0), amount);
      
              _balances[account] = _balances[account].sub(amount, "ERC20: burn amount exceeds balance");
              _totalSupply = _totalSupply.sub(amount);
              emit Transfer(account, address(0), amount);
          }
      
          /**
           * @dev Sets `amount` as the allowance of `spender` over the `owner` s tokens.
           *
           * This internal function is equivalent to `approve`, and can be used to
           * e.g. set automatic allowances for certain subsystems, etc.
           *
           * Emits an {Approval} event.
           *
           * Requirements:
           *
           * - `owner` cannot be the zero address.
           * - `spender` cannot be the zero address.
           */
          // Present in ERC777
          function _approve(address owner, address spender, uint256 amount) internal virtual {
              require(owner != address(0), "ERC20: approve from the zero address");
              require(spender != address(0), "ERC20: approve to the zero address");
      
              _allowances[owner][spender] = amount;
              emit Approval(owner, spender, amount);
          }
      
          /**
           * @dev Sets {decimals} to a value other than the default one of 18.
           *
           * WARNING: This function should only be called from the constructor. Most
           * applications that interact with token contracts will not expect
           * {decimals} to ever change, and may work incorrectly if it does.
           */
          // Considering deprication to reduce size of bytecode as changing _decimals to internal acheived the same functionality.
          // function _setupDecimals(uint8 decimals_) internal {
          //     _decimals = decimals_;
          // }
      
        /**
         * @dev Hook that is called before any transfer of tokens. This includes
         * minting and burning.
         *
         * Calling conditions:
         *
         * - when `from` and `to` are both non-zero, `amount` of ``from``'s tokens
         * will be to transferred to `to`.
         * - when `from` is zero, `amount` tokens will be minted for `to`.
         * - when `to` is zero, `amount` of ``from``'s tokens will be burned.
         * - `from` and `to` are never both zero.
         *
         * To learn more about hooks, head to xref:ROOT:extending-contracts.adoc#using-hooks[Using Hooks].
         */
        // Present in ERC777
        function _beforeTokenTransfer( address from_, address to_, uint256 amount_ ) internal virtual { }
      }
      
      library Counters {
          using SafeMath for uint256;
      
          struct Counter {
              // This variable should never be directly accessed by users of the library: interactions must be restricted to
              // the library's function. As of Solidity v0.5.2, this cannot be enforced, though there is a proposal to add
              // this feature: see https://github.com/ethereum/solidity/issues/4637
              uint256 _value; // default: 0
          }
      
          function current(Counter storage counter) internal view returns (uint256) {
              return counter._value;
          }
      
          function increment(Counter storage counter) internal {
              // The {SafeMath} overflow check can be skipped here, see the comment at the top
              counter._value += 1;
          }
      
          function decrement(Counter storage counter) internal {
              counter._value = counter._value.sub(1);
          }
      }
      
      interface IERC2612Permit {
          /**
           * @dev Sets `amount` as the allowance of `spender` over `owner`'s tokens,
           * given `owner`'s signed approval.
           *
           * IMPORTANT: The same issues {IERC20-approve} has related to transaction
           * ordering also apply here.
           *
           * Emits an {Approval} event.
           *
           * Requirements:
           *
           * - `owner` cannot be the zero address.
           * - `spender` cannot be the zero address.
           * - `deadline` must be a timestamp in the future.
           * - `v`, `r` and `s` must be a valid `secp256k1` signature from `owner`
           * over the EIP712-formatted function arguments.
           * - the signature must use ``owner``'s current nonce (see {nonces}).
           *
           * For more information on the signature format, see the
           * https://eips.ethereum.org/EIPS/eip-2612#specification[relevant EIP
           * section].
           */
          function permit(
              address owner,
              address spender,
              uint256 amount,
              uint256 deadline,
              uint8 v,
              bytes32 r,
              bytes32 s
          ) external;
      
          /**
           * @dev Returns the current ERC2612 nonce for `owner`. This value must be
           * included whenever a signature is generated for {permit}.
           *
           * Every successful call to {permit} increases ``owner``'s nonce by one. This
           * prevents a signature from being used multiple times.
           */
          function nonces(address owner) external view returns (uint256);
      }
      
      abstract contract ERC20Permit is ERC20, IERC2612Permit {
          using Counters for Counters.Counter;
      
          mapping(address => Counters.Counter) private _nonces;
      
          // keccak256("Permit(address owner,address spender,uint256 value,uint256 nonce,uint256 deadline)");
          bytes32 public constant PERMIT_TYPEHASH = 0x6e71edae12b1b97f4d1f60370fef10105fa2faae0126114a169c64845d6126c9;
      
          bytes32 public DOMAIN_SEPARATOR;
      
          constructor() {
              uint256 chainID;
              assembly {
                  chainID := chainid()
              }
      
              DOMAIN_SEPARATOR = keccak256(
                  abi.encode(
                      keccak256("EIP712Domain(string name,string version,uint256 chainId,address verifyingContract)"),
                      keccak256(bytes(name())),
                      keccak256(bytes("1")), // Version
                      chainID,
                      address(this)
                  )
              );
          }
      
          /**
           * @dev See {IERC2612Permit-permit}.
           *
           */
          function permit(
              address owner,
              address spender,
              uint256 amount,
              uint256 deadline,
              uint8 v,
              bytes32 r,
              bytes32 s
          ) public virtual override {
              require(block.timestamp <= deadline, "Permit: expired deadline");
      
              bytes32 hashStruct =
                  keccak256(abi.encode(PERMIT_TYPEHASH, owner, spender, amount, _nonces[owner].current(), deadline));
      
              bytes32 _hash = keccak256(abi.encodePacked(uint16(0x1901), DOMAIN_SEPARATOR, hashStruct));
      
              address signer = ecrecover(_hash, v, r, s);
              require(signer != address(0) && signer == owner, "ZeroSwapPermit: Invalid signature");
      
              _nonces[owner].increment();
              _approve(owner, spender, amount);
          }
      
          /**
           * @dev See {IERC2612Permit-nonces}.
           */
          function nonces(address owner) public view override returns (uint256) {
              return _nonces[owner].current();
          }
      }
      
      interface IOwnable {
      
        function owner() external view returns (address);
      
        function renounceOwnership() external;
        
        function transferOwnership( address newOwner_ ) external;
      }
      
      contract Ownable is IOwnable {
          
        address internal _owner;
      
        event OwnershipTransferred(address indexed previousOwner, address indexed newOwner);
      
        /**
         * @dev Initializes the contract setting the deployer as the initial owner.
         */
        constructor () {
          _owner = msg.sender;
          emit OwnershipTransferred( address(0), _owner );
        }
      
        /**
         * @dev Returns the address of the current owner.
         */
        function owner() public view override returns (address) {
          return _owner;
        }
      
        /**
         * @dev Throws if called by any account other than the owner.
         */
        modifier onlyOwner() {
          require( _owner == msg.sender, "Ownable: caller is not the owner" );
          _;
        }
      
        /**
         * @dev Leaves the contract without owner. It will not be possible to call
         * `onlyOwner` functions anymore. Can only be called by the current owner.
         *
         * NOTE: Renouncing ownership will leave the contract without an owner,
         * thereby removing any functionality that is only available to the owner.
         */
        function renounceOwnership() public virtual override onlyOwner() {
          emit OwnershipTransferred( _owner, address(0) );
          _owner = address(0);
        }
      
        /**
         * @dev Transfers ownership of the contract to a new account (`newOwner`).
         * Can only be called by the current owner.
         */
        function transferOwnership( address newOwner_ ) public virtual override onlyOwner() {
          require( newOwner_ != address(0), "Ownable: new owner is the zero address");
          emit OwnershipTransferred( _owner, newOwner_ );
          _owner = newOwner_;
        }
      }
      
      contract VaultOwned is Ownable {
          
        address internal _vault;
      
        function setVault( address vault_ ) external onlyOwner() returns ( bool ) {
          _vault = vault_;
      
          return true;
        }
      
        /**
         * @dev Returns the address of the current vault.
         */
        function vault() public view returns (address) {
          return _vault;
        }
      
        /**
         * @dev Throws if called by any account other than the vault.
         */
        modifier onlyVault() {
          require( _vault == msg.sender, "VaultOwned: caller is not the Vault" );
          _;
        }
      
      }
      
      contract TWAPOracleUpdater is ERC20Permit, VaultOwned {
      
        using EnumerableSet for EnumerableSet.AddressSet;
      
        event TWAPOracleChanged( address indexed previousTWAPOracle, address indexed newTWAPOracle );
        event TWAPEpochChanged( uint previousTWAPEpochPeriod, uint newTWAPEpochPeriod );
        event TWAPSourceAdded( address indexed newTWAPSource );
        event TWAPSourceRemoved( address indexed removedTWAPSource );
          
        EnumerableSet.AddressSet private _dexPoolsTWAPSources;
      
        ITWAPOracle public twapOracle;
      
        uint public twapEpochPeriod;
      
        constructor(
              string memory name_,
              string memory symbol_,
              uint8 decimals_
          ) ERC20(name_, symbol_, decimals_) {
          }
      
        function changeTWAPOracle( address newTWAPOracle_ ) external onlyOwner() {
          emit TWAPOracleChanged( address(twapOracle), newTWAPOracle_);
          twapOracle = ITWAPOracle( newTWAPOracle_ );
        }
      
        function changeTWAPEpochPeriod( uint newTWAPEpochPeriod_ ) external onlyOwner() {
          require( newTWAPEpochPeriod_ > 0, "TWAPOracleUpdater: TWAP Epoch period must be greater than 0." );
          emit TWAPEpochChanged( twapEpochPeriod, newTWAPEpochPeriod_ );
          twapEpochPeriod = newTWAPEpochPeriod_;
        }
      
        function addTWAPSource( address newTWAPSourceDexPool_ ) external onlyOwner() {
          require( _dexPoolsTWAPSources.add( newTWAPSourceDexPool_ ), "OlympusERC20TOken: TWAP Source already stored." );
          emit TWAPSourceAdded( newTWAPSourceDexPool_ );
        }
      
        function removeTWAPSource( address twapSourceToRemove_ ) external onlyOwner() {
          require( _dexPoolsTWAPSources.remove( twapSourceToRemove_ ), "OlympusERC20TOken: TWAP source not present." );
          emit TWAPSourceRemoved( twapSourceToRemove_ );
        }
      
        function _uodateTWAPOracle( address dexPoolToUpdateFrom_, uint twapEpochPeriodToUpdate_ ) internal {
          if ( _dexPoolsTWAPSources.contains( dexPoolToUpdateFrom_ )) {
            twapOracle.updateTWAP( dexPoolToUpdateFrom_, twapEpochPeriodToUpdate_ );
          }
        }
      
        function _beforeTokenTransfer( address from_, address to_, uint256 amount_ ) internal override virtual {
            if( _dexPoolsTWAPSources.contains( from_ ) ) {
              _uodateTWAPOracle( from_, twapEpochPeriod );
            } else {
              if ( _dexPoolsTWAPSources.contains( to_ ) ) {
                _uodateTWAPOracle( to_, twapEpochPeriod );
              }
            }
          }
      }
      
      contract Divine is TWAPOracleUpdater {
        constructor(
          string memory name_,
          string memory symbol_,
          uint8 decimals_
        ) TWAPOracleUpdater(name_, symbol_, decimals_) {
        }
      }
      
      contract OlympusERC20Token is Divine {
      
        using SafeMath for uint256;
      
          constructor() Divine("Olympus", "OHM", 9) {
          }
      
          function mint(address account_, uint256 amount_) external onlyVault() {
              _mint(account_, amount_);
          }
      
          /**
           * @dev Destroys `amount` tokens from the caller.
           *
           * See {ERC20-_burn}.
           */
          function burn(uint256 amount) public virtual {
              _burn(msg.sender, amount);
          }
      
          // function _beforeTokenTransfer( address from_, address to_, uint256 amount_ ) internal override virtual {
          //   if( _dexPoolsTWAPSources.contains( from_ ) ) {
          //     _uodateTWAPOracle( from_, twapEpochPeriod );
          //   } else {
          //     if ( _dexPoolsTWAPSources.contains( to_ ) ) {
          //       _uodateTWAPOracle( to_, twapEpochPeriod );
          //     }
          //   }
          // }
      
          /*
           * @dev Destroys `amount` tokens from `account`, deducting from the caller's
           * allowance.
           *
           * See {ERC20-_burn} and {ERC20-allowance}.
           *
           * Requirements:
           *
           * - the caller must have allowance for ``accounts``'s tokens of at least
           * `amount`.
           */
           
          function burnFrom(address account_, uint256 amount_) public virtual {
              _burnFrom(account_, amount_);
          }
      
          function _burnFrom(address account_, uint256 amount_) public virtual {
              uint256 decreasedAllowance_ =
                  allowance(account_, msg.sender).sub(
                      amount_,
                      "ERC20: burn amount exceeds allowance"
                  );
      
              _approve(account_, msg.sender, decreasedAllowance_);
              _burn(account_, amount_);
          }
      }

      File 4 of 4: Dai
      // hevm: flattened sources of /nix/store/8xb41r4qd0cjb63wcrxf1qmfg88p0961-dss-6fd7de0/src/dai.sol
      pragma solidity =0.5.12;
      
      ////// /nix/store/8xb41r4qd0cjb63wcrxf1qmfg88p0961-dss-6fd7de0/src/lib.sol
      // This program is free software: you can redistribute it and/or modify
      // it under the terms of the GNU General Public License as published by
      // the Free Software Foundation, either version 3 of the License, or
      // (at your option) any later version.
      
      // This program is distributed in the hope that it will be useful,
      // but WITHOUT ANY WARRANTY; without even the implied warranty of
      // MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.  See the
      // GNU General Public License for more details.
      
      // You should have received a copy of the GNU General Public License
      // along with this program.  If not, see <http://www.gnu.org/licenses/>.
      
      /* pragma solidity 0.5.12; */
      
      contract LibNote {
          event LogNote(
              bytes4   indexed  sig,
              address  indexed  usr,
              bytes32  indexed  arg1,
              bytes32  indexed  arg2,
              bytes             data
          ) anonymous;
      
          modifier note {
              _;
              assembly {
                  // log an 'anonymous' event with a constant 6 words of calldata
                  // and four indexed topics: selector, caller, arg1 and arg2
                  let mark := msize                         // end of memory ensures zero
                  mstore(0x40, add(mark, 288))              // update free memory pointer
                  mstore(mark, 0x20)                        // bytes type data offset
                  mstore(add(mark, 0x20), 224)              // bytes size (padded)
                  calldatacopy(add(mark, 0x40), 0, 224)     // bytes payload
                  log4(mark, 288,                           // calldata
                       shl(224, shr(224, calldataload(0))), // msg.sig
                       caller,                              // msg.sender
                       calldataload(4),                     // arg1
                       calldataload(36)                     // arg2
                      )
              }
          }
      }
      
      ////// /nix/store/8xb41r4qd0cjb63wcrxf1qmfg88p0961-dss-6fd7de0/src/dai.sol
      // Copyright (C) 2017, 2018, 2019 dbrock, rain, mrchico
      
      // This program is free software: you can redistribute it and/or modify
      // it under the terms of the GNU Affero General Public License as published by
      // the Free Software Foundation, either version 3 of the License, or
      // (at your option) any later version.
      //
      // This program is distributed in the hope that it will be useful,
      // but WITHOUT ANY WARRANTY; without even the implied warranty of
      // MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.  See the
      // GNU Affero General Public License for more details.
      //
      // You should have received a copy of the GNU Affero General Public License
      // along with this program.  If not, see <https://www.gnu.org/licenses/>.
      
      /* pragma solidity 0.5.12; */
      
      /* import "./lib.sol"; */
      
      contract Dai is LibNote {
          // --- Auth ---
          mapping (address => uint) public wards;
          function rely(address guy) external note auth { wards[guy] = 1; }
          function deny(address guy) external note auth { wards[guy] = 0; }
          modifier auth {
              require(wards[msg.sender] == 1, "Dai/not-authorized");
              _;
          }
      
          // --- ERC20 Data ---
          string  public constant name     = "Dai Stablecoin";
          string  public constant symbol   = "DAI";
          string  public constant version  = "1";
          uint8   public constant decimals = 18;
          uint256 public totalSupply;
      
          mapping (address => uint)                      public balanceOf;
          mapping (address => mapping (address => uint)) public allowance;
          mapping (address => uint)                      public nonces;
      
          event Approval(address indexed src, address indexed guy, uint wad);
          event Transfer(address indexed src, address indexed dst, uint wad);
      
          // --- Math ---
          function add(uint x, uint y) internal pure returns (uint z) {
              require((z = x + y) >= x);
          }
          function sub(uint x, uint y) internal pure returns (uint z) {
              require((z = x - y) <= x);
          }
      
          // --- EIP712 niceties ---
          bytes32 public DOMAIN_SEPARATOR;
          // bytes32 public constant PERMIT_TYPEHASH = keccak256("Permit(address holder,address spender,uint256 nonce,uint256 expiry,bool allowed)");
          bytes32 public constant PERMIT_TYPEHASH = 0xea2aa0a1be11a07ed86d755c93467f4f82362b452371d1ba94d1715123511acb;
      
          constructor(uint256 chainId_) public {
              wards[msg.sender] = 1;
              DOMAIN_SEPARATOR = keccak256(abi.encode(
                  keccak256("EIP712Domain(string name,string version,uint256 chainId,address verifyingContract)"),
                  keccak256(bytes(name)),
                  keccak256(bytes(version)),
                  chainId_,
                  address(this)
              ));
          }
      
          // --- Token ---
          function transfer(address dst, uint wad) external returns (bool) {
              return transferFrom(msg.sender, dst, wad);
          }
          function transferFrom(address src, address dst, uint wad)
              public returns (bool)
          {
              require(balanceOf[src] >= wad, "Dai/insufficient-balance");
              if (src != msg.sender && allowance[src][msg.sender] != uint(-1)) {
                  require(allowance[src][msg.sender] >= wad, "Dai/insufficient-allowance");
                  allowance[src][msg.sender] = sub(allowance[src][msg.sender], wad);
              }
              balanceOf[src] = sub(balanceOf[src], wad);
              balanceOf[dst] = add(balanceOf[dst], wad);
              emit Transfer(src, dst, wad);
              return true;
          }
          function mint(address usr, uint wad) external auth {
              balanceOf[usr] = add(balanceOf[usr], wad);
              totalSupply    = add(totalSupply, wad);
              emit Transfer(address(0), usr, wad);
          }
          function burn(address usr, uint wad) external {
              require(balanceOf[usr] >= wad, "Dai/insufficient-balance");
              if (usr != msg.sender && allowance[usr][msg.sender] != uint(-1)) {
                  require(allowance[usr][msg.sender] >= wad, "Dai/insufficient-allowance");
                  allowance[usr][msg.sender] = sub(allowance[usr][msg.sender], wad);
              }
              balanceOf[usr] = sub(balanceOf[usr], wad);
              totalSupply    = sub(totalSupply, wad);
              emit Transfer(usr, address(0), wad);
          }
          function approve(address usr, uint wad) external returns (bool) {
              allowance[msg.sender][usr] = wad;
              emit Approval(msg.sender, usr, wad);
              return true;
          }
      
          // --- Alias ---
          function push(address usr, uint wad) external {
              transferFrom(msg.sender, usr, wad);
          }
          function pull(address usr, uint wad) external {
              transferFrom(usr, msg.sender, wad);
          }
          function move(address src, address dst, uint wad) external {
              transferFrom(src, dst, wad);
          }
      
          // --- Approve by signature ---
          function permit(address holder, address spender, uint256 nonce, uint256 expiry,
                          bool allowed, uint8 v, bytes32 r, bytes32 s) external
          {
              bytes32 digest =
                  keccak256(abi.encodePacked(
                      "\x19\x01",
                      DOMAIN_SEPARATOR,
                      keccak256(abi.encode(PERMIT_TYPEHASH,
                                           holder,
                                           spender,
                                           nonce,
                                           expiry,
                                           allowed))
              ));
      
              require(holder != address(0), "Dai/invalid-address-0");
              require(holder == ecrecover(digest, v, r, s), "Dai/invalid-permit");
              require(expiry == 0 || now <= expiry, "Dai/permit-expired");
              require(nonce == nonces[holder]++, "Dai/invalid-nonce");
              uint wad = allowed ? uint(-1) : 0;
              allowance[holder][spender] = wad;
              emit Approval(holder, spender, wad);
          }
      }