New Ethereum talks, every Monday. The week's conference uploads by event, in your inbox.

Loading player…

How I Audit by Dominik Teiml | Devcon SEA

DevconTue, Oct 7, 2025, 12:00 AM

Dom, a former security researcher at Trail of Bits, is going to give a peek of what it's like to be an auditor in 2024. Some of the techniques and tools discussed: * How to prepare for an audit? * How to hand over the resources? * What is the first thing auditors do? * How to communicate with auditors? * How I use the following tools, and their evaluation: * Codebase visualization with Wake and Neovim * Static analysis tools * Fuzzing (and debugging) * Manual review Speaker(s): Dominik Teiml Skill level: Expert Track: Security Keywords: Tooling, Security, Auditing, analysis, static Follow us: https://twitter.com/efdevcon, https://twitter.com/ethereum, https://warpcast.com/devcon Learn more about devcon: https://www.devcon.org/ Learn more about ethereum: https://ethereum.org/ Visit the https://archive.devcon.org/ to gain access to the entire library of Devcon talks with the ease of filtering, playlists, personalized suggestions, decentralized access on Swarm, IPFS and more. Devcon is the Ethereum conference for developers, researchers, thinkers, and makers. Devcon SEA was held in Bangkok, Thailand on Nov 12 - Nov 15, 2024. Devcon is organized and presented by the Ethereum Foundation. To find out more, please visit https://ethereum.foundation/

Transcript

[Music] should I start okay so hi everyone um so I prepared a presentation on uh mainly uh using various tools for auditing um so let's begin you'll see my okay perfect so let's maybe switch this off hopefully that will be okay um so let's begin at the top yeah yeah let's do that okay so uh a little bit about me so I organized pcoin meetups in 2013 um I worked on the nois Dutch X and the safe uh around 7 years ago and I've been doing the last around five years I've been doing uh security audits um so I have yeah long trace of uh various bugs uh but to be fair a lot of the I I felt my audit process I always felt like my audit process wasn't really sustainable um the the bugs required extremely high effort and so two to three years ago I embarked on a journey to make the process more efficient and uh here I'd like to present the results yeah yeah okay uhhuh maybe I can just move it would this be better okay um so I found myself working at TR bits I got an offer from a Czech company called Aki and so why did I leave so they wanted to invest in tooling and um and so that's where I went and that's where we developed a tool called wake which is also one of the things I'll be presenting today um so why why did I feel that was a good idea so I I felt that there were things in trail bits tooling that wered rewriting from scratch so I have four things listed here um so in particular um this so for example slyther uses Library called critic compile which tries to figure out which framework you're using and compile your project uh but the issue is that it doesn't really have control over the compilation so if you want to for example build a language server which will also be showing uh then um you're at the mercy of the underlying framework right so one thing that you might want to do when you're building a language server is you might want to try to minimize the size size of each compilation unit so that when the user makes a change in their editor like in vs code uh the recompilation is very fast yeah so all the other tools uh they try to um they try to minimize the number of compilation units so they try to minimize the time for first compilation whereas maybe you want to try to maximize the number of compilation units um so that you you optimize for recompilation um so that's that's one thing that I'll be I'll be showing today uh by the way if you guys have any questions then feel free to jump in um I can answer uh on the go um so I think fuzzing in our industry we call it fuzzing but that immediately evokes it's something that has to run very fast and um actually the way we do fuzzing is not by just sending random data uh because the reality is most of it would fail right so you try to be a little bit more intelligent and you just send uh like um the appropriate functions so the appropriate ABI encoding uh but even that is mostly going to fail because if you try to transfer token without sending an approval first it will always fail so the way we actually do fuzzing is we it's more like modeling uh so we uh design flows or uh rules as they're called in various Frameworks um and so when you think about it like that when you think about it as modeling the system uh then it's much more uh better to write it in a language where you can write it really fast right so my favorite language for modeling stuff um is python so I felt that it was a good idea to uh have a framework where you can model uh economic U and financial blockchain systems in in that language um on the static analysis side so um I felt that for example sler doesn't merge compilation units so this is really really tricky because you might have like this diamond pattern right where some Library can be compiled with multiple solidity versions so it has the appropriate pragma uh but then it's used in two different contracts that pin that solidity version and so as a result you have a valid project you'll just have two different compilation units and so this is kind of a problem because the way solity works is it gives you this huge Json and it just numbers the nodes one by one and so even if it's the same file let's call it lib um it's going to have different IDs in two different compilation units and the reason for that is solidity doesn't go file by file it just goes node by node so they're going to end up uh as different indices and so this is actually kind of a big problem so if you want to create the illusion of a single compilation unit of a single unified thing for the user you have to merge all of these compilation units um and slitter doesn't currently do that so um that's something that I think should be done um and then struct member references I'm not 100% sure about this but I wasn't able to find a way to uh find references to struct members only struct like variables there's no there's no model for the a so it's all just dictionary access whereas um if you create an actual model for example with the library like pantic uh then you can catch your assumptions about the model much faster and then obviously I wanted to use a lot of cool new libraries like rich and click and networkx Etc I think networkx is used in instead it um after about a year after that I uh started researching tooling full time and so I'm going to talk about both things General tooling and wake um so disclaimer oh yeah I was actually messaged uh by somebody at Trill bits um in my talk it says that I was a lead auditor um so I was a lead at audits uh but they actually turns out have a role called lead auditor so just wanted to make that clear um so uh you guys can join groups um so the thing is uh not everything here is done in fact almost nothing is done um and so I plan to uh update you guys right and so the best way to do that I think is with a uh with a telegram group because I don't want to like take anyone's emails or stuff like that so I'll post to this link um you know as I as I start publishing these things so if something you like here um you can find it out later and also I'm as a freelancer looking for Audits and other engagement like uh building tools but mainly my specialization is yeah Audits and and uh security and developer tooling um a lot of things I'll be presenting here involve a lot of external software so be very careful with that um so be very paranoid so before you download anything um you know make sure to check on the on the uh on the the developers um me listing it here does not mean it's safe um but that said I do try to keep in touch a little bit um so most security companies will tell you that you need to keep all your software up to date all the time uh that's true for things like operating system and stuff like that but I found that with some of these tools that I'll be showing today since they're Indie developers actually the opposite is true you want to uh pin your version and then ideally check on the developer make sure they're still active before you update it unfortunately what happens is and I it's even in this in this talk we'll see it um tools get bought by uh Shady people right and then you don't know what happens okay so let's actually get into it um so yeah uh the the plan is to talk about mainly two things uh wake and general tooling I personally really like when people talk about their configs so this is sort of my uh my uh contribution here okay so um let's talk about about keyboard layout first so um I tried several uh keyboards I ended up uh using one called The Glove at um so the thing about these things is they're ortholinear um they're split and they're programmable um that said I found that uh you don't want to presumably get as much of the programming into the uh keyboard itself because then it won't work when you're using the laptop separately so you want to get as much of the programming on the on the OS level which will discuss um soon as well presumably um so for the keyboard layout um I use a a layout called vorak um and that's the thing I didn't know about any of these things just a few years ago um and so as I sort of started diving into it um so this is how it looks um so the idea obviously is to minimize travel of your of your keys um yeah um so some of the things I learned along the way oh yeah and then the third thing is um what for example Apple calls human interface modifications um and so for that you can use a tool called uh Carabiner so let's actually see it in action right here um so the way it works is it creates a Json or you create a Json and it reads from that Json to for the modifications uh and Json are pretty hard to create and so you have a tool called Goku where you can write it in a in a more sucin language called um edn and so you can use that uh so some of the things I learned along the way uh don't have too many layers for example for the programmable keyboard um it's nice to have the same key on different sides of the keyboard uh redundancy is fine it's easier to learn something where the key these are closer together than before than if they're like really far um so the main the main two uh layouts that people have apart from uh Cordy is dorak and KAC so the reason I didn't go for Colac is JK which is a very popular key combination obviously um and so as a pure pure chance and vorak they're next to each other which is just I guess pure chance uh whereas in col Ma they're not so if you want to you know be able to use those two keys uh very efficiently then then uh that's something to consider uh one thing that's really cool which I guess I didn't know is that it works on pretty much every single uh various device um I wouldn't I would say don't make your own modifications uh because then you have to make them across all the devices which can be pretty tricky uh dorak does come with a completely different punctuation so I I do remap it to to regular ones and then this one is was fairly important for me is um I remapped all of the command plus key and Control Plus key uh to their original uh values yeah to WC yeah yeah yeah yeah uh REM up caps to escape it's way easier to go to normal mode in b instead of like moving my pinky to the end of the keybo yeah it's feel nice yes yes absolutely agree in fact I have the same exact thing yeah so I have the same exact thing um so is vim fine yes in fact for some reason I think Vim gets even better uh with with these uh combinations just one more point on this if your Mac OS user Mac OS does have a uh a key layout where for command and control it goes to query but actually it's a buggy layout um so I wouldn't recommend that so I would recommend to do this remapping either on the level of the programmable keyboard or on the level of uh the cabin or the hid modifications it took a very long time for me to learn uh very long time uh whether it's worth it or not um you know there's obviously massive advantages uh because yeah typing is something we do very very often um so I think it was worth it um so Crainer is the the main thing for uh creating these modifications on Mac OS so you can create a hyper layer uh for example and um yeah I think um I think we can kind of move on um so for examp so what's a hyper layer so so when you hold one of the keys and you can access a whole another layer with like arrows and stuff so you can have like a systemwide uh Vim set up basically just pretty cool um don't spend too much time on this obviously once you learn it use it I haven't touched my config for many months now which I'm very proud of um so one thing I didn't know also uh which I might have just considered if I was starting again is there's also there already uh some existing layouts um so you might want to check into that before you you go I'm planning to publish my layout thisall um So currently uh I have caps lock bound to uh escape and when you hold it you get the hyper layer um and then therefore I don't need Escape itself um so that switches to the last app which is really really cool um yeah let's move on so actually all of this started in a tool called Alfred originally where uh it was all worked with command um then I moved it to keyboard then moved it to the alt or option modifier but really you want to use a custom layer so that you don't block obviously the um the keys with the with the modifications Okay cool so let's so that was around the the keyboard so let's talk about some other apps um so vimium is a Chrome extension I in particular use the one called vimium c um so what does that do so it allows you to let's find something I don't know like here allows you to scroll it allows you to to search right open your uh and then allows you to also uh like use your keyboard to open links uh go back and you can like uh configure all of this in the in the extension unfortunately you can't configure it with a text file which would honestly be the best um so if you're on if you're on and this one is for any operating system obviously since it's um you just need a chrome in browser if you're on Mac there's a app called hom row which does the same thing but on the operating system level so this is how it looks I just and then you can you can press anything from there um there's also one called shortcut but I personally like home R better it doesn't always work for electron apps um scrolling you can also do with hom roll so you can scroll anything very very useful stuff so many people use trackpad for gestures um so with an app called Mac gesture you can actually have gestures uh on your mouse so I have a lot of these for example uh dragging to the right will will dim the screen I don't want to do it right now so I'm not going to do it um so this is the one that you want to be careful about so um you can so this is an app that does several things so it allows you to minimize your menu bar and then you can search it uh you can search it like this and you see all the items here uh but this is one of the issues right is um actually recently it was acquired so before updating you might want to uh check the uh the current status um to be fair yeah so there is there is a one an open source tool that um that I want to migrate to soon um okay uh so yeah um let's let's let's move on okay so let's talk about hammerspoon um so if you're a Mac User this is a very very useful thing um so the idea of this is they expose uh for example Objective C uh Mac OS apis um in a scripting language in particular in Lua um so this is also used in neovim yatsi MPV um if you don't like Lua you can also use uh teal which is meant to be a typed version of Lua or fennel which is meant to be um like a closure or lisp uh syntax um I found that with teal people don't really use it uh because instead the most popular Lua language server has support for types um so people uh use that for example in the in the neim community um and then other obviously honorary mentions are uh keyboard Maestro raycast and Alfred um so uh window Management on Macos is very very hard uh but I'm pretty happy with the solution so far so I can show you so what I do is I take the function layer and I bound it to open apps now that sounds great but you also want to like retain the for example the volume keys right so you can do this all with crainers you can say some keys will uh open apps and others will remain the uh the media Keys um so yeah I just have browser chat GPT and terminal most the apps I use use the most by far um yeah and you can go really crazy with this um so in case anyone's interested um my current setup so you can combine the F keys with various modifiers right um so I have the following combination so uh if I press control then it sort of switches to a different app so for example Arc or Chrome uh YouTube music or Spotify so that's all the with control then shift as a modifier uh forces it to be on the current screen the current monitor um and then command and command does a different monitor next monitor it loops around and uh shift command does uh does previous monitor um so what I call Window Transformations I uh launch that with command M and that allows me to do stuff like this and if I have multiple monitors obviously move the window around or even focus various monitors uh all of this stuff is either public or will be public soon so um if anyone wants to use that they may um okay and then I also have this uh launcher at command control a uh which is basically like meant to be the best way for me to uh enter into all of these commands so once you start you know writing all of these commands you don't want to keybind everything some of it you want to keybind uh but maybe some of it you want to uh you want to keep as um as like a command like a searchable command so some examples of what I have there I don't know if I have some examples here oh yeah I do okay so for example inserting unic code keys so for some reason uh keyboards don't have an M Dash and so if you want to insert an M Dash you kind of have to do it yourself and in view ofm it's it's U shown with in monospace font obviously but if I use another app like telegram it will be an actual mdh um I also have some really cool clipboard Transformations so most people would use their text editor uh like to write a you know script in Yim or something but if you do it on the OS level it means you don't have to you know you can use it in any app so I can like um I can uh um um I can select some text and let's let's copy it and then I can say like um I can um here I can add or remove for spaces which is I guess the initation I use for uh for most things but you could obviously add anything else uh for example another one is if you have like if you have some if you have some text here and you want to copy it then you want to get rid of the everything before for the pipe right so I also have a I call that one remove pipe charart right and then everything else before the pipe as well um let's continue okay um so where were we again so we were okay and then um some things I want to add to the launcher is uh controlling timers um so we'll we'll talk about uh two timer use cases in a second so timers are um hammer spoon way of let like do right so this is like Hammer spoon's way of being able to schedule stuff so this is an app called Dash allows you to get like documentation um for various things so I use it for like python documentation laa documentation Hammer spoon documentation so it's offline and it's you don't have to go to the browser okay so brightness so this thing is very important for me because I have a thing called tunnel vision where I just focus like so much on one thing um and so what brightness does is every 20 seconds it dims the screen for one second so this was actually very important for me to uh get rid of that uh that status um Okay so so for notes for notes um I used to use an app called log seek um and I stopped using it in favor of as you guys can see actually in the screen right over here uh just neovim so it's an asky do based setup and it actually works really really well uh so yeah it's a custom custom Newen plugin and it works really well so what do I need for my notes so you guys can see the highlights that's pretty cool so uh whichever whichever uh bullet point you're on currently it highlights those stars all the previous stars and then sometimes it even and it also highlights all the parents yeah so very very easy to to see like the entire path all the way to the top um and then obviously the other thing you need is you need to bind uh stuff like when I press o which in Vim normally creates a new line you want it to create the you wanted to create the Stars at the same time right now when I press tab you wanted to indent right and then shift tab so like basic stuff but turns out like that's all you need for a really really good note system and if I ever wanted to publish this online asky do obviously has a HTML conversion so uh that's very easy to do as well um so this one this one um I haven't published yet uh but yeah we'll be publishing um soon um so it's based on asking doc um so that's the name of the the format I'm using and then also the the tool that can generate the HTML I'll export anyone else have any other questions so far how are we doing on time okay W already 30 minutes okay let's move on yeah so one thing I learned about the notes is uh it's very important to have fast access to them um and so people you know talk about all these systems uh like zedel Casten and that kind of stuff so for zetel Casten in particular I feel it's a little bit outdated um I get a most of my knowledge these days from Chad GPT um and in fact it's much faster than than um than like maintaining notes so um but still Fast Access is very important um so when I was using Loxy got this thing where I could search all the notes so command contrl n now I can uh search all the notes and then it would open it uh in the program just by hitting enter and also shows me how many lines words and characters are um so this is just a shell script that uh outputs the the data in the in this like Hammer spoon launcher okay um hammer spoon also gives you access to uh programmatic access of your a of your menu bar and so I mainly use that for three things one sec take a little break so the first one is for showing me the layer of the programmatic keyboard um So currently we're in normal mode and um so this is really really cool how the keyboard if you change the layer of the keyboard so the way I do that is it sends a private key I catch it in uh Carabiner and I use that to call hammerspoon a particular hammerspoon URL and that changes the uh the menu bar so I can see very visually on my screen always the the layer of the keyboard you're currently in um and then number of windows on each screen um So currently I have 23 windows I can actually even click on it to see all the windows although Arc is kind of misbehaving it looks like right now and then something I did actually quite recently which is pretty cool so if I uh let me see if this actually work Works uh because I haven't tried it uh just on my uh personal like laptop just by itself uh but um so toggle uh for me is the best tool for like counting time and yeah so it's it's worked really well right now so when I press command control and then the pause button or the play button it resumes the last session so the last session is called the last project is called Defcon the last thing I was doing was preparing this presentation and it does actually uh two more things it also shows me the current uh the current time today and the current time in the last seven days um so this is a visual representation to make sure I'm always counting the correct project that I'm working on and also kind of a motivational thing um you know I always want to be obviously above like 20 or 30 hours uh in terms of work done in the last seven days and like daily I want to get to you know like whatever like uh five six seven hours whatever um and then obviously if you uh I can also launch the app right um to see like all the details and all the projects and stuff like that I can show you guys how it looks if you're interested so you can see like the calendar here yeah and the list and all that stuff so that's for me the the best one um so should we keep the time counting now or should we stop it I'll keep it counting just to get more more hours okay so obviously hours are not important um the output is important but uh from a personal perspective U it might motivate you okay um yeah so that was the menu bar okay so let's talk about let's talk about terminal emulator yeah so to be clear I went from a person who mainly used vs code to somebody who teral emulator so is it better um like I think it is obviously uh but there's kind of a learning curve right so there's there's a lot of stuff these these programs they're they're pretty simple in how they work it's just bites in and bites out uh but they're also not so Advanced so even to this day the most modern T like for example Kitty cannot actually handle well uh multi code Point graphes yeah um or and and and the the editor can't either um so for example if you want to use emojis yeah let's let's see some emojis um let's for example go to wake um and then let's like open some random file okay so this is something I'll be showing in not long um so this is how I read code uh these days um and so it's it's based around emojis um to largely agree um so they allow me much faster to see the uses of a particular identifier because every identifier has a unique emoji and then the colors are also uh every identifier also has its own color um so like yeah I mean I was going to talk about this later but might as well talk about it now um so in syntax highlighting we do the opposite of what we want we highlight useless words like class de try and four and we don't highlight the important stuff which is uh which is the identifiers and their uses um so this flips it around um and I think I can also try to decree to increase the contrast so let's try to do that let's see if it works um H and then what's okay so it's yeah this is pretty experimental it's only like uh Implement in a few days so it doesn't work right now the increasing of the contrast which is fine um so basically you can also fiddle around with the contrast obviously if you have higher contrast uh then uh you can see the uses of your identifiers much better um by the way it's a it's a pretty uh uh it's a pretty small screen right so we can also like split it like this and bind it together um but then if you have very high contrast it's also like visually striking so it's not that great so I have like pretty low contrast fast uh which makes it very very pleasant uh to read yeah so um I I and then I'll we'll have another example where we see uh where we see emojis in practice um and the thing is you have to pick among only the ones that are single code point so they can be multiple bytes they just have to be single code Point um and so there's there's a lot that you can't use for example you can't use flag and other ones um so I have it in fact I have a whole list of all of the all of the ones that are single single uh code Point yeah whereas vs code can handle anything okay um so uh this actually is not meant I'm not at this point meant to talk about Kitty here the terminal emulator I'm using that actually comes later um so at this in this section I was actually meant to talk about uh the hammer spoon uses of Kitty uh but let's talk about that a little later I'll let just scroll through everything right now uh yeah I mean um like just last thing I'll say like like contexts if you want a a better version for command tab then check out this app yeah and I think that's that's that's enough I spent too much time on window Management in the last uh few years so uh what I learned using hammer spoon so as with any other thing you want to have a very fast iteration process so for me instead of reloading the entire thing every single time by clicking reload config or even like having a key binding I find it much better to just reload one single module um and so the way the way you can do that yeah I mean that's it's pretty obvious um you can interact with a CLI or like with a with a uh with a prompt thingy instead of with this uh but it does not support readline so readline is a very popular C library uh that is used in many various prompts um to to handle text essentially so for example it's used in if you just type in Python um that actually uses read line unfortunately yeah so this actually use it so you can very quickly jump between the words um so Lua by itself or HS does not unfortunately use read line yeah so you can't quickly jump between words um which kind of sucks and you can't really embed it you can't really embed Hammer spoon and external Lua program uh which is unfortunate because then you could use Lua P which is the uh reline version of the Lua console um and then interact with hammerspoon that way but unfortunately there's not really a way to do that because the binary itself is like um Crosslink with u with Mac software so that's pretty unfortunate right now cool [Music] okay okay so let's talk about termin ulator so um I'm a big fan of this one called Kitty um so it's written go and Python and C uh by a guy called covid Goyle goyal he's also the author of caliber in case you know that uh that program um so my view on things I write it right here is system software versus user software so if you're writing system software like ZK or an operating system or whatever you want to use something like rust um when you want a fast iteration language or you want to write like scripts or modeling then um something like uh Gore python is great um [Music] so yeah um it has things like you can uh launch a console you can and uh for example if I have some output let's say where was my let's say we uh for example have some some file here so what does ef and CF do that I've been using uh recently so they they um they look up uh they use fzf to look up that particular file and then they either edit it or C it um so CF let's do server so it's going to it's going to cat it except uh it's going to use bat for that which also gives me syntax highlighting um and then and then uh if I want to just use this particular scroll back and like scroll through it I pipe it into less I can also do that with h so this is this is all supported out of the Hood um I didn't do any modifications for this one so um you know don't reinvent the wheel uh if you know don't don't allow users to like search the scroll back like create a whole new UI when you can just pipe it into less and have them search it uh you know with uh with less and then you know you can search with with less that way you can also modify less um so um so you can uh do that with something called less key yeah so you can also you can also uh you can also uh modify the the user shortcuts um in terms of a pager like a lot of people are working on a uh page right now but they're not done yet so there's a lot of things that uh Les doesn't have that we might want from it uh but it's it's what we use um right now but the the really coolest things are for example the keyboard protocol so the idea here is uh we're all um using us uh like this is the way the terminal communicates with the app that you're running for example your shell or your editor or whatever um so we're using standards from like a monitor in the 1970s and uh they're very limited so um they for example can distinguish between Tab and control I yeah so uh some of you might have encountered this in the past but but uh the way that alt and control were traditionally handled by uh terminal emulators between modern before modern standards Like the Kitty uh keyboard protocol is the following so when you pressed alt or option um it sent an escape and then it sent uh the key and if you pressed control and a key it actually just subtracted like 128 from it I think and so tab which is right over here um was actually the same exact thing as control I um so a lot of there's a lot of questions on the internet like how come I can't bind control I to Something in Vim or how come it's doing the same thing as tab so this is the reason um and so let me show you the yeah so this is it so it's called the kitty keyboard uh protocol and so the idea among other things is to distinguish between those things okay so it has uh it has uh it sends a particular bite sequence when you uh when you press a button when you release it and it sends you the exact information so as an app developer it's very easy for you to to handle that and it's currently supported in actually many many places not all of them have full support uh so for example NE ofm is is getting support but doesn't like have uh full support just yet um the only thing that that I feel it's missing so there might be like a 2.0 version is currently we don't distinguish between left modifiers and WR modifiers so that's that's a bit unfortunate you know but um it is what it is so left control is the same thing as right control right now there's no distinction and so if you want to see an example of the of uh the protocol uh let's see if I can I can do that um yeah so we want to okay this one perfect sorry not except not unit code input but I think it's called showkey yeah perfect okay so here you can experiment with this for example when I press a it sends right the bite sequence corresponding to a if I press command a it sends this is escape and then these are the uh these are the the uh the bites that uh you can also figure out over here so this is very very useful uh because I use this uh to create something which is really really cool and that is uh having full Mac OS key bindings in basically every single shell app that I use so what do I mean by Mac ke binding so um on your computer you're used to that if you do option left it jumps back award and um and like command uh a like command Left Right Command right command backspace like you're used to these things you probably use them um and especially if you have a hyper layer right like we talked about earlier then they just become much closer and you just end up using them all the time right but you don't want to have this distinction obviously in vimi can always go to or even in your shell you can always go to normal mode that's true but sometimes you end up pressing it because you're not aware that you're in a shell app right you think you're still in the browser or something so ideally you want these key combinations to work in Shell applications as well and so that's a little tricky so how do we do that so the reason It's Tricky is um K is actually very intelligent and it actually figures out which app you're using and whether it's going to support the uh the protocol and if it doesn't it reverts back to the old standards and so what you want to do is you want to force it to use the new standard and while we're at it we might as well just uh pick like random keys that we're going to send okay this is not necessarily I could probably get rid of it but it works and so I'm not changing it so what I do is send f27 F28 f29 f30 all the way to like F35 and then you can catch it on the layer of the app and handle it there yeah so you can do this in currently in so this currently Works in everywhere that read line Works in which we talked about so for example bash or the python console this works in zsh and uh let me also say because it's not it's not obvious which of these were required Uh custom handling and which of them didn't so readline required custom handling so that one is uh is interacted with with um uh with with a file called input RC there we go and so this is how it looks if you want to if you want to get it to work in bash or in the python console it's just this uh let's look at how to do the same thing in zsh so that one is a little little different um so let's see if we can find it uh how should we do this ah here here it is so this is how you do it in in zsh yeah and I mean the other ones are similar as well uh so readline which is uh new Shell's version of read line so in Rust it actually supports it out of the hood and so this is available there out of the Hood um and so if you use New Shell you can yeah okay so it doesn't work right now um oh yeah because okay okay it doesn't work right now actually I had a pull request to newa which got merged a few days ago so I guess I'm not on my version I'm on their version right now because it's not working uh but uh this stuff was merged into New Shell as well a few days ago um so this this also works in New Shell uh same with IPython created a p Quest recently I was also merged um so let's see how it works in IPython um so let's for example go somewhere here and let's get rid of everything let's go back to yeah so you can type some text and then you can yeah so this is this was very important for me because it was extremely frustrating um when I'm used to this working in most places and then I'm you know doing my happy uh you know intera ction with wake and I python you know stuff like that and then you press one of these keys and sometimes what you get is it clears the entire input yeah so this is very very frustrating so I spend a lot of time making sure this works everywhere and yeah as I said uh two of my PRS have been merged recently so now it works also in New Shell and in IPython um and for a long time now I've added work in new of them insert mode and command line mode so let's look at uh command line mode um so it works perfectly in command line mode and I can also do backspace obviously right and then in insert mode it works as well there's a little bit of a Flash and I think I know why the flash happens but it's just not a super high priority to fix it right [Music] now okay so um I think we're in the foundation section in terms of like uh in terms of like you know everything I learned regarding the terminal um wait did we accidentally I think we skipped some some stuff um okay so yeah keyboard protocol so that's where we were so uh supporting a lot of apps including New Shell new stuff like that image protocol also really cool um so this is also supported in for example L for example in yatsi so um so you can so you can have a file manager like this and it prev previews uh it previews the images uh for you inside the terminal emulator uh automatically this required zero zero uh effort from my part it just does this uh does this under the hood because it supports the the keyboard protocol uh the image protocol uh the app signals to to kitty that it supports it and so it can ask for an image and kitty can give it that image uh has a text based config uh it has a remote control which is really really cool um and uh allows you to write python based plugins um for example one thing I wrote recently is this tab bar customization which I really like so the second letter always shows me the uh the app basically that I'm using but like I limit it to just a few so for example n is neovim L is less Y is yatsi and then the first character is the first character of the current directory um and while we're talking about this let me show you um this thing I built a few weeks ago I call it uh kills Kitty LS um so this I really really like so this shows me all my uh terminal windows let's Zoom it up a bit it shows me the current running program shows me the current directory um I'm using a tool called macup for syncing all the dot files through Dropbox across all the devices and then it shows this is very important if you're doing some like uh like kitty work it's always really frustrating to like not know the IDS of things and stuff like this um so uh what I do is I give the full full Json it's scrollable also the full tab also scrollable full OS window also scrollable um and then obviously I give the name so they're all called DC which is the current project I'm working on Defcon and they all have an ID uh tab ID and then uh obviously uh OS sorry uh window ID and then this is the ID on the OS window level so if you want to do things like maximize the window and stuff like this you also need the uh the sort of Mac OS ID so that's the that's sort of the Mac OS ID okay so uh where were we um we're kind of uh jumping up and down but I think um I think I'm doing a fairly good job like uh giving structure and stuff so let's just continue um so we might come back but let's let's talk a little bit about command line tools so one thing that you might want to check out is this link right here you can also yeah um you can also open it in the browser yeah so the idea is like there's a lot of advantages right to trying out uh new stuff and uh this is the best article for like uh doing that that I have seen okay so currently I'm using zshell but I plan to migrate to new shell so Newell is really really cool so let me tell you two main advantages um you don't so in traditional cells like all types are strings right and that's kind of annoying because you might want to have a dictionary or a list and it's very very painful to keep on decoding and encoding everything as like strings and so new shell is like you don't have to do that you can use your strings if you want uh but you can also uh use more higher level types um so you can call functions just as you would external programs but now you can also pass in uh things like dictionaries and stuff uh but the honestly the main advantage I personally would say is it makes it very easy to create Shi programs that's that's for me personally the the largest Advantage um so for me like using it first as a scripting language um and then migrating it uh to use it also like interactively is I think the uh the best approach and while I was using it I have um I made a a shortcut called n which just runs the uh just runs the command in Newell so I can very easily interact with it uh from from zsh so that's something that helped uh me a lot I don't have to go to the interactive session and the way the function works and you can ask Chad GPT for this to work it's possible is it works both like if it's if you pass in a string and if you pass in list of positional arguments it works in like both cases okay um let's where should we go let's let's jump here for just a second uh [Music] so for listing directories I used to use a tool called LS d uh the issue with that is that it's it's a little bit nicer than EXA um the issue with that is that uh Macos also has a a thing for last modified for files and for example if you want to sort it by last modified LD unfortunately doesn't give you access to the last modified thing um so I had to migrate away from LSD and So currently I'm using a tool called X um and yeah I mean you see it when I do L you can also see it when I do F that's that's a treb and moreover um this stuff is also uh also available as a CD hook um so you can do this in D St you can run C any program on on a CD so if I CD it automatically lists and so um for example um I can with Z oxide I can jump to a directory and I can have it give me the treeview and if it has a readme it also shows me the readme really really nice okay so where were we over here um yeah yeah we talked about all this Z oxide um allows you to jump between directories um super quickly um let's get rid of some some tabs here just to make it everything a lot simpler there we go two tabs um so where were we going UHD oh yeah yeah so this and then you can also use zi um and it it it pipes it into fzf and you can see all of your uh solutions that way um so you can and then obviously if you if you press enter I pressed control C but if you press enter Then you can uh CD into that uh directory okay I feel like we went a little quite far with this so let's maybe back up and see if we missed something from above let's split it um okay so we talked about Kitty right so let's let's talk about Kitty and hammerspoon integration so normally the way I work is I have my laptop and I have two monitors and um the convention that's worked for me is I name all of these Kitty Windows as position and project so for example there will be L Scratch R scratch L Defcon R Defcon and I have a shell command called Kos to rename right to name the the OS window essentially um and so and then you can bind command control tab to switch between Windows of the same project very very useful um and as we already said command plus an F button goes to the next window of the current APP and there's also command tab which does contacts remember the contacts app we mentioned earlier but just for this current APP so all in all I have three ways to navigate to Windows of the same app very very useful it sounds trivial but it's actually very useful um so and let's let's so let's write them out over here so command F3 to go to um to go to next then we had command control tab next window of same project so this is next monitor yeah I mean this stuff is meant to be as an inspiration so it's like not really important that we get it uh exactly correct and then obviously there's also like command tab which is just uh just contexts uh switch Yeah okay um and so that allows like really really high level handling of all the windows so for example command control e uh shows me three things it shows me all of the projects I'm running right now uh we created a new window recently so let's let's give it a name let's call it also let's call it Rd or like let's call it also DC just like this or maybe like 2dc or something right and so now let's press uh command control e so now we just have one project in the first window I have two kitty windows and then the second one I have one kitty window um the second thing that allows me to do is to create a new project interactively um I hope this will work I'll show it in a second um it's fairly recent Edition and then to open any of my safe projects so let's try to create a new project interactively um I can also get there by doing command control shift n so let's do it that way command control shift then so what this is going to do so the idea of this is the following once you start to think of your windows as projects let's say you want to start an audit you don't want to have to go into one of your existing Windows to get clone it right you want to you want to create a you want to sort of do it both at the same time you want to get clone it and create the uh the window so the way I do that is the following so first the first thing that happens is it creates a new window called new project and it gives me two tabs there so here I can do my good cloning okay so here I can do uh you know whatever I can do my G clone and then um it uh creates this this toml file and as soon as I close it it's listening to the process and as soon as I close it it's going to open the the windows to work on yeah so this solves the problem that you can both do your cloning and you can launch the uh the window so let's see it in practice so three two one close it and Bam so what did it do currently the way it's configured is it opens one window called LR and then RR and obviously this is customizable we call our project P so that's what we get as a result but we could have called it something else so um yeah okay um so where were we oh yeah um convention names Windows usually by position project working setup to monitors Okay blah blah blah blah blah blah here shows both running projects and then obviously if we also save the project uh oops I accidentally did the new thing so it's going to launch it again three two one bam so let's close it all again um then we would also if we also saved it then we would also see it here in the save projects okay let's just jump through this because I want to move on so let's see uh this one we talked about create new project um uh uh and then and then this one we also talked about so uh this is the one that has the web server and it gives you the view and it allows you to uh just by clicking it now it's going to focus it hopefully it's going to work let's try it it might not three two one it worked okay so it focused it let's try with the OS window 3 two one okay it focused it so it works um also you can also actually close it that is not implemented yet yeah it's it's not hard it's just just a few lines of cod just haven't hav been done yet so if you close this um then right now nothing happens okay it's not hard I just haven't done it yet cool um yeah so I wrote all of this Kitty integration with hammerspoon all of this stuff is written in hammerspoon Lua um while some of it was probably a good idea I should have considered the python based plugins much more seriously um for example for window opening you don't get a call back so you do get a call back when the process ends that's how we're able to remember the when I said let me close V and it's going to launch the window so you do get a call back when the process ends but you don't get a call back when you launch a window to it actually being available which is kind of unfortunate so it means I have to do this like yeah hack where you wait 100 milliseconds and then you interact with the window it is what it is it works it's never not worked uh but um not particularly proud of it um and generally sometimes I find myself asking what language do I want to use do I want to use Python uh which obviously I'm like super productive with and with like libraries like rich and stuff um lu which would then allow me to integrate it directly into into hammerspoon or Newell right so I'm like um kind of undecided window management is really really good uh in in this term emulator um there's some really cool built-in plugins like for example Unicode so this allows you to search for any Unicode character a built-in the plugins are called kittens so this a built-in kitten as you just search for particular unic code character uh hints um so that is uh where for example if you had a link uh or actually I could show hints probably like this let's see if that works um uh well okay so I recently rebounded but you can for example this might work um okay let's just give me like 10 more seconds to try it out so let's see if we have for example Echo High there we go okay so what just happened there I mean nothing nothing fancy um it's a kitten that I'm bounding to a particular sequence I can even show you I can maybe show you in a different Tab and um yeah I mean honestly I don't think I need to to show it it's not that interesting um but since I'm already here I'll do it so uh hints is right here so map kitty mod which is command control uh command control uh plus p and then l so let's try it out in practice command control uh p and then it says shift l so let me press shift L okay press shift L and so what happened there so it ran a kitten called hints d D typ line dh- program the current scroll back D- multiple so now I can press one and it copies it to my clipboard I can press seven copies it to my clipboard um I have a feature request on GitHub to also support ranges it doesn't currently do that but it is what it is and then I press escape and now I have it in my clipboard yeah so this is kind of cool um I think most terminal emulators don't have that most people do that like with vim and stuff but this is very useful if you have some output so that you don't have to use the mouse right the idea here is I completely eliminated the Mouse um it also shars with nerd fonts so these are these are kind of important so uh a lot of CLI tools like LSD and EXA they show you these icons and you need you need like a what's called a nerd font um and so you can either download it online but Kitty ships with the ner font so it's going to work it should work out of the box uh without having to uh download anything um and then uh tab bar recent Edition we already talked about that um you can customize obviously how your tab bar tab bar looks let's continue yeah um so would you guys prefer I show you wake or I finish this what would you prefer I show you I show you wake because we don't have so much time left unfortunately so I'm going to show you wake but I also want to talk a little bit about this so let's see if we can do both at the same time okay so who here has heard of wake start like that not a single person oh okay one person I can't see you do I know you personally or not no okay that's cool wow how have you heard of it or uh online yeah okay um so what is it so okay so there's quite a lot of explaining to do so let's let's let's do it quickly [Music] okay there we go so alt is a little shell script that just toggles between underscored and not but it's actually really useful okay so uh two more very quick things so um SEC is a tool that allows you to count lines of code and I have a version called sccd that does the same thing but for directories um and then I have a thing which will probably be called Prague p r a for practical git but is currently called uh I think it's called G python or something um so let's run both of these tools and now um if we launch Ranger which is a file manager uh we can see two really interesting outputs so the first one is the recursive line count of every directory and the second one is G history so this is the first age it was edited um 63 months ago this is the last age it was edited and these are the top months that it was edited in um so I just wanted to show that because this is how I start any exploration of any directory is by running these two tools so here we are oh and by the way I also integrated the same thing in for example neovim yatsi and all the other tools I use okay so here we are so let's maybe start at the very beginning so in the past lity worked by specifying a number of files and they compiled it then they added a thing called standard Json which allows you to interact with the compiler through standard input in particular adjon and to specify the files that way the issue with that is people want to have dependencies and they don't want to specify the remappings they want to say just import at open Zeppelin and uh they want it to work they don't want to say import node modules at open Zeppelin Etc so what they added is thing called include paths that allows you to specify okay include paths node modules and now everything that uh for example if we do import at open Zeppelin if it doesn't find it it's going to look in node modules so there's a typ ER okay so we see that actually I was part of this uh audit many years ago um so there's a type error and uh there's something going on but we don't really care about this directory it's an audit directory so we want to exclude it so how do we do that so let's start by running wake in it config by the way if you want to see the the help just very quickly this is how it looks in fact we can even get it in color this way uh we have to rerun it there we go so let's run wake init config it's going to try to create intelligently the current config file um so it detects that the contract size is over the limit so it has to enable the optimizer does that um and it still gets the same errors right so now we need to tell it how to compile it so compiler see include paths this is a compiler thing whereas exclude paths that's for the tool and it's going to tell the tool which directories shouldn't be primary compilation targets they might still get compiled if they are imported from L square but they will not be primary targets okay so let's just add audits here is it called audit or audits audits let's try to switch it around there we go oops and now we can compile it and this is a clean uh G clone and we were able to compile it so the idea of this tool is it started as a static analysis tool you can also use it as a framework as a f um as a lot of other things that I'll be showing uh but uh the the main thing is it tries to work with all the other Frameworks out of the box ideally um and as you can see it did work out of the box this was kind of a well except if we excluded the audits this was kind of an easy example because they actually don't have any dependencies there's no dependencies so it was fairly easy but uh even if there were node modules by default uh node modules are actually include paths by default for the tool so if you come to a hard hat or truffle project uh it will uh it will work out of the box um the it will not work out of the box with Foundry it will but but listen so the reason is uh Foundry kind of uh screws up the entire import system so it doesn't just uh work with include paths like we've been uh using for years it actually strips out uh the SRC uh from every uh dependency which they have like as G sub modules and so it actually screws up the entire thing um luckily we have a special adapter for especially for Foundry as well um and so uh it will read the remappings txt and if it fails to read those it will run uh the remappings Command right is I believe this is what it's called this what it's called I believe this is what it's called something like that um and um and then it will it will put that into the the config for the compiler in particular compiler doc. remappings it would put it right here compiler doc. remappings in fact we can even see um so recently somebody asked me how do I compile this using wake so I'm going to show that uh so the the project that they asked me to do it on was this code Arena project so let's try to copy the link Let's uh try to let's see how should we do this let's just do gcdp single depth single branch that should hopefully get us where we want to be oops wake up and wake in it or synonyms okay so this is a little tricky because there are a lot of solidity uh files um here and um yeah so this one is going to be a little a little tricky and I don't think we have the time for that because we're out of time um so instead let me show you what you can do once you compile it so one of the things is we give you really really easy access to the so for example let's create a new thing um okay so let's let's hope this works I haven't tried this stuff before the presentation okay it worked right so anytime you know something can go wrong and then it requires maybe five minutes of focus which I don't want to do right here but um so this in particular uh we have a inheritance graph um this in particular is a reference graph okay so this is a reference graph so let's try to click on one of these in fact let's have just okay so this is uh references of the functions um this I built one year ago and I haven't published it yet it's on some pull requests but nothing merged yet but I plan to publish it soon a lot of people are like people ask me like for this even though it's like not really uh public yet um but the thing is it's not done like there's so much more we can do right it's really just the just the base um so you can annotate these functions with various things like whether or not they have for Loops whether or not they have external calls um you can add emojis um you can add probably much much better um like focusing like if I click on one of these uh functions it should probably highlight all of the all of the edges but already it is extremely useful especially if you have multiple monitors especially if you have a big wide monitor that as you're auditing to see all the references so for some reason uh for some reason it starts on the on the right I'm not sure why honestly the docs say that it should start at the top but whatever it is what it is um so this is the first function and yeah so we have check ticks um so I do call it a reference graph but the arrows are more in the direction of a call graph so this function um calls this function um right this function calls this function and so on um and same with inheritance graph so this is like this is in my opinion better than anything that's currently available um I personally have not found anything even close to uh to these tools that I built for myself but I think they might be also useful for other people in fact um just by typing in uh wake init uh printer DG you can create any printer you want um so so it creates this file um we can go there um one thing you want to do is you want to say export python path and you want to add the Wake side packages so that once you start importing stuff from wake it can see it okay so I started aring after quite a long time of doing tooling research around one month ago I was on the I was doing the um unisoft V4 uh code Arena thing and I ended up actually just writing massive amounts of these printers um and they are really cool uh so let me show you some of them so let's for example try write functions um in fact right now it's pretty ugly code actually but I'm in the process of structuring it so before each printer was a separate file now I'm in the process of uh putting it all into lib and just having like the entry points uh so let's for example do see if this works I call all of them like U dash for like user so I know that they're not like the built-in ones you can also see all the printers by typing list let's do it again now it has a wider terminal available printers so uh loaded from so this is the package so wake comes with this package called wake undor printers um so it comes built in with a bunch of uh printers so let's try at least one of them so that we can see it let's try for example C3 linearization let's see if we get uh tab complete we don't because it would be too probably imp performant to Loop okay so this is like similar stuff to what you have in existing tools the difference is um all the stuff I've been mentioning like you have the unified uh um Vision into the entire code base so when you write printer it's going to work on all the uh all the symbols there at once um so uh yeah so these are the ones we have right now and let's see uh okay let's try to run for example this one let's see if this one works maybe we need to add a u did it work okay so this is something that I wrote for myself so it's called Write functions so this is really interesting um so it takes all of the contracts in your in your project it puts them all here it sorts them by the number of statements but it is C3 resolved so for example if this was a very small file if this was the most derived file it would still be last so it resolves the C3 inheritance and then it counts the uh the the statements and for each of the contracts it goes back in the C3 linearization and for each ancestor it shows you the uh all the storage changes of all the functions it shows you the full storage layout there's nothing in this particular contract and then it shows each of the functions so you can actually just audit it it's much faster to uh to navigate all of the different uh different functions um let me show you one more thing so let's do for example I mean I have this one called types which is pretty cool oops I think I in the wrong directory okay so what types does it uses the same exact ordering yeah so that's where it's important to put this logic into a lib so that you can reuse it in all of your printers so it has the same exact ordering now for each contract it shows you the number of statements C3 resolved and then the types one is meant to be for like uh peripheral things um like uh stru types enum types I don't think it shows events uh but it does show um it I think it does show storage variables and it definitely shows constants um so that way you can can you can read the types all the structs and stuff and what they mean uh before you uh even begin and the final one I want to show you is the reference graph or the call graph uh but inside of a terminal um so I actually don't remember the name so let's see how I call this um contract call graph I believe um uh how are we going to do this should I try to okay one sec I have to find this first emojis create notes so this is meant to create an outline of notes for all the contracts and all the functions so that I can very easily take notes on everything also very cool this one um um actually okay let's try to let's try this one yeah it worked so what is this so this is the full call graph so when you're reading a function you can uh let's say you're reading TIG bit map position then you can see the entire depth of the entire uh uh color graph and since it's easier to see color and symbols than text um I also assign emojis yeah um I think we might end it here um so just for the record stuff I didn't get through so I haven't even touched upon our language server it used to work in neovim as well um right now for some reason it doesn't um so you know how the existing solidity extensions when you click go to definition it jumps to a different symbol symbol then is actually the definition so the reason is they don't use the compiler information um so we built is a language server that actually communicates with the compiler um to resolves all of the references and uh even actually gives you all the references here as uh like these little buttons that you can click on and it even works for struct members and it even works for uh function parameters and function return values take lower has three references take upper has three references this return value has zero references so this return value is never assigned now we can be 100% sure that these return values are never assigned and the reason for that is that there's a direct return so what we haven't got into is the fuzzing um so I guess next year or next time some other time um and let's see what I have not been able to do in terms of uh the other stuff yeah everything around neovim like the Emojis and the percentages that I showed um and some of the stuff I'm I'm working on uh right now for example one of my goals is what I call oneclick uh which is a printer that you run and it will export all of this information into a HTML file so that you can open it for example on your phone or on your tablet and you can audit on the go while having this like uh really Advanced uh information about your code base so that's it guys thanks a lot for coming and yeah thanks does anyone have any questions

Automatic transcript — names and jargon may be misspelled.