# Solidity - optimization and testing — Vladimir Culum | Bloxico

- Channel: [ETH Belgrade Community](https://streameth.org/eth-belgrade-community)
- Date: 2024-10-07
- Duration: 31:20
- Watch: https://streameth.org/watch/yt-I5reelrte_k
- YouTube: https://www.youtube.com/watch?v=I5reelrte_k

## Description

Recording from ETH Belgrade Meetup #6

## Transcript

so my hello everybody my name is Vladimir I'm coming in front of the bloo company we rep three company so have different side of projects one of the technology that we are using in solidity so as I know this is like first of the serious about the solidity like language so we will get some small intro and about the testing and optim ation so solidity is a language that Prim primarily targets the ethereum network interium virtual machine so uh evm it's objectoriented high level language it's statical type it supports inheritance like normal uh object oriented uh language and uh it's support complex user defined type so uh when you go deeper in defining everything and logic in solidity uh you will see that there is basically three languages that influenced the uh solidity at the beginning first language in a beginning was JavaScript and but most of the things that JavaScript influenced the solidity was depreciated out the 0.4 uh uh version and uh still you can see like function naming that keyword function also Imports and scope of the variables Scopes inside the functions and outside uh most influence for the solidity was under the C++ and we can see like a lot of different uh examples uh through the code like type conversions implicit and explicit Loops declarations and everything and uh last that's let's say uh uh newer version is uh Python and uh two like most things that we can see that python influence solidity is modifiers it's uh um in the solidity modifiers uh is U let's say performing like decorators in Python something like that they wanted to achieve that and for example super keyword that is uh inheriting everything uh uh when you're are using it um so solidity is a basically language that is implementing smart contracts to govern the state of the ethereum network second thing think that is important for like Network as Network that uh you can look at the solidity smart contracts as small Java classes or some uh executables on the network but it can store the state persiste the state of um whatever we defined also it can perform uh computation view searches and uh most important it's immutable uh there is a so when you deploy smart contract on a network it's not changeable there is some ways for the replacing like open sapping and other Frameworks uh introduced like upgradable but that doesn't mean that you're changing current contract you're just replacing with newer uh new contract that you're using in your application um there is a different uh uh uh approaches and this part that is um immutable like smart contract and that uh other point is that every operation have cost except like we will see later views from local node but when you are storing some state so whenever you are changing the state of the network even if it's small there is a gas fees that is involved and some cost it depends on the network it doesn't need to be ethereum but evm based Network there is a uh cheaper networks it's based on a price of the Native token on that Network so because of that uh we need to take care of the testing and optimization in the first place because in web 2 when you're are doing some development and deployment you can deploy on production after you perform some testing searches and you see that something is not good you can change it uh without the cost on uh uh ins solidity and uh evmb uh networks so uh when you deploy it it's immutable so that part of the testing it's let's say important uh regarding the testing uh there is a like for development there is different tools uh that use also for testing first let's say oldest of the old tools is truffle uh truffle is uh we spoke uh before this so trle is most mature Tool uh it's very welld developed also uh it has like a ganache that is UI for the uh for the local network that you bring up like you can use ethereum Explorer some block Explorer so you can look at the network from UI standpoint when you are testing and uh deploying on that your local network and my opinion that it's very good for the uh uh people who are getting into it to learn and uh to get uh everything on uh on place because uh trle is uh structured and when you start working in truffle it's not totally open that you type whatever you want uh truffle has his uh he has structure like architecture how where you're putting test how you're are calling of course everything is changeable via config files but still they're like forcing you to do truffle way like how you are structuring your project uh truffle uses uh truffle is using mocha and chai It's is like JavaScript uh uh testing environments and it's uh very well other tools are also uh using that tools next tool that is um in that series is hard Hut uh hardcut is newer tool it's not uh it for me it's more powerful than trle because it have a a big Marketplace it's also allow a lot of plugins um allow that you structure and setup whatever you want on a way you want to work and uh trle is uh hardcut is also using uh chai like testing framework uh it's everything automated in the background but um that is the framework they are using uh what is what I see as a Improvement for hardcut it's very well uh when you're writing test in typescript so if somebody's familiar with typescript it it will be easy for them to write tests on uh uh uh in harut also because uh we mentioned that that U uh gas fees are very important uh that is something that harut has like guas profiler you can like TR trace the gas for every contract function so in that process of the testing and optimization you can look how to lower down uh uh your gas fees what is let's say uh most important uh third software is that most of the people are whoever start doing something it's online tool you can download it and install it on locally but most of the people are using like online it's uh remix tool and remix tool has a different uh uh let's say it's like a a playground let me just see uh remix it's like a a playground this is remix so you can put uh type your contracts uh you can compile it in a different environments uh you can uh use different when when you're deploying you can deploy in virtual machine you have different versions uh of the evm so you can play and test with the uh with the remix uh a lot so um there is a option they they start building like testing environment that are Pur testing here in remix right now you can just like uh uh you can just um sorry uh you can just uh like test perform your own test on different environments and that's uh something that is good um last is brownie uh I wasn't working too much with it I just wanted to mention because people who is coming from python world Brown is a a good option because it's uh have uh a good console that gas profiling and python integration so you can uh use Python a lot you have some tws and things that you need to do but still um that is good option uh to have so to like me main main parts of the testing plus optimization I see in uh first thing that like tdd development in solidity means that if we are having some project big requirements smaller requirements we need to uh have clear picture what contracts should do and should not do I mean what is not allowed for example if I have some year SE tokens maybe it's allowed to go only to the owner of the smart contract and I need to ban all the other functions to stop all other actors to invoking that transfer function for example so when we have like clear uh picture of the requirements and the use cases scenarios I think that's my opinion that I like to work like that I first step I take all the requirements all the use cases think about them think about the workflows and then I wrote the tests for every use case but I'm writing the test to fail that's my first step I wrote Every test that every test is failing and then I start like okay this test is failing for example uh it expects uh two users that it it get in a return for example to some addresses and I'm getting three so I create test that it's always failing then I'm looking through the smart contract that specific function or workflow multiple functions that I'm testing and then I'm creating contracts on that side that it's not failing so uh uh that's the first step two main points is testing the workflows so when we are doing uh uh tdd in solidity means that we want to cover all the use cases and that's the first step that doesn't mean that it will be optimized for the gas usage that it will be maybe secured enough it just means that when we wrote those tests in the like first step it means okay now we have covered all the use cases and after that uh we are looking for security that's another main important of the uh evm and other blockchains also uh because when you deploy the smart contract it's publicly viewed so you can view every uh every contract that is uh uh on the Network current you can view if you know the address or you can search the contracts and you can see it so everything is in some way open source so in that case uh uh we need to take care of the security because if it's open source if it's immutable if you make some really security hole it's hardly that we are going to change that easily for that purpose just note uh there is for example some modifier that it's C posable in solidity where you can Implement posable in some functions like modifier and say this function is when you define it you define as possible that means that uh when you in some way figure it out that you need uh you cannot destroy the contract you can just like stop uh you know uh off execution and everything you can call that owner of the contract can for example cuse call that posable and contract still exist you can figure it out then how to fix the uh error how to deploy another contract do something else but nobody can invoke that security bug anymore um so first step is covering all the use cases second step is uh for me it's security testing that is most uh important also and at the end uh when it's secured enough we have all the use cases we are going to the optimization so then we are looking okay now everything is secure everything is working but when I call this function in this conditions it's using a lot of gas for example it will be costly nobody will will want them to use it like why to pay some you know enormous uh amount of the uh tokens at that moment we are going to that part of the optimization how to optimize the code regarding the uh testing tests are written in uh like I said we are using chai It's typescript JavaScript testing framework and it's it's u i mean it's standard all the other framework are using it's not something uh that is too complicated it is good to run through the documentation because they have a lot of uh useful functions that you can like compare figure it out different scenarios and everything but uh regarding the security there is like slow tools and fast tools slow tools first first of the slow tools uh fast tools sorry is uh static analysis what does it mean it means that first step is that we know use cases we know how to figure it out what what can be like security issue and then we look through the code because in some cases uh security issue can execute normally we are not going to get any error in any test or anything so for example uh good example if uh we are changing the state of the if we are changing the state on the contract for example we are having smart contract that is uh performing like Vault and storing balances on for every user who wants to deposit for example in that deposit function we can put different things steps what is performing for example and two two parts is like it's uh increasing the state of the balance for the specific user and it accepts uh Native tokens that user deposit imagine that order of execution would be increase the balance accept the tokens what if the user doesn't have like 50 tokens he wants to deposit and he invoked the function but balance is his balance in contract is increased for 50 and when it comes to the like transfer function uh accepting the tokens it will fail but state will be there so that that is like School example of the security issue that when you write function like that it's not going to produce any error it's totally valid but that first step is static analysis that you look uh through the code look again like use cases what is allowed what is not allowed and then figure it out of the possible scenarios and fix that order for example okay first do the transfer and if transfer is okay then increase the balance for example when I when I get the tokens then I will increase the state of uh that uh uh token another thing is lters uh I mean linters is more like to be uh everything uniform hardart has his own uh linters and everything you can change uh that linting in configuration file but it has good like linting that is can fix automatically like uh if you're using uh uppercase smaller case two empty spaces some other things you can do whatever you want uh tool that uh is free and it's good for starting point for like fixing at least Bas Stu but it can do a lot more is slighter slighter is a tool uh for mostly for the security checking and also for the linting for that basic stuff that uh when you run it on the code it's open source it's you're running like uh you're installing in like mpm package or globally on desktop whatever you like to use when you run it it produce a big log file and say okay in this contract this line of code you're for example you're defining um I will show you example of the slider so so no Jun it's so for the slider let's say uh for the slider it security testing okay it produce for example uh warnings like this and say okay in this contract this line of code you're using address token ID is it IM mutable not mutable do are you naming the for example uh uh parameters that you want to return if you're not you can just put like u in parameter I I will uh return you in and that's all but you can also name it so slider is a very good tool that will uh point you and have different things like warnings errors and everything and and if it's security error it will be in red like noticing so this is like security error you need to really fix this uh most of the use cases is that uh Rey that it's most of the people are trying to avoid uh in a smart contracts uh open saing and in solidity you also have modifi like you have re-entrancy guide uh uh re-entrancy uh uh guard so when you introduce to the function again uh defined like that it will prevent some cases it's not magic but slider can do like different type of checkings and you can put like different type of the scenarios that slider will check and it's very good Tool uh for that at least fixing basic stuff maybe you miss something think it's not so all of these errors it's not going to be errors in compile maybe warnings also maybe not but uh slider will cover a lot of things that uh you or other tools are uh Missing uh so that is the let's say fast tools it's called Fast tools because uh because it's that is first step and that is something that we are doing like fast okay I done everything let let's just run slighter through the all the contracts and I will get some report maybe to get some pictures or everything um slow tools it's much more powerful uh I think it's it's paying metics I'm not sure I'm not uh using all the time so so this is slow tools that you can Define totally totally scenarios different scenarios with fuzzy logic with you can do much more but it it needs to like you need uh much more work uh for them uh basically it's audit companies are using uh uh most of the slow tools and they're like performing auditing of the smart content contracts it takes time like 2 weeks 3 weeks depends on the project and size of the project but that's some tools that are writing different really complex scenarios and uh when you come to that point you need work only that you're not like just solidity developer so um that is regarding the tools and testing so if we imagine scenario that everything passed like we have secured contracts we have every use cases are covered what we can allow what we can what we need to forbid and uh we run like through the security checking and everything and everything is working and then you send the project to the like whoever uh you know want that project and he said yeah but you know there is a limitations we can on not run this it's too expensive uh then you're going to part of the optimization first part when when you start working or probably a lot of you whoever worked uh see this like okay this size of the contract is uh uh uh big big Point here is when you're writing smart contract locally it's not looking size of the file that you're writing and you're having on your computer so uh uh solidity compiler is compiling that in a bite code that compiled by code it's it deployed on network so when you get uh message like this like warning this is warning it's not I mean everything is working but it's a you know there is a possibility when you try to do deploy this on mainnet that mainnet network will refuse it and say I don't want to deploy something big so uh this is uh a uh part where uh you need to understand that it's not calculated the size of the file you're not sending anything you're uh compiling and deploying the bite code why it's important there is uh one function in remix and all tools in config files it's called Optimizer so you can say okay like it said of the uh like consider enabling the optimizer with a low runs value what does it means you can have the same contract and put the value of the runs I will explain soon uh for 10 runs it will have much much smaller size than you put like 100,000 TR it's the same code but it compile in different bite code why that is your prediction how many times that smart contract will be invoked on a network when you deployed through the history and uh uh that is the part when you have some small helper contract then you can just put like okay this is one time only I will put like 100 runs and you will compile smaller bite code for the same contract if it's same contract needs to be run over and over and over you put larger amount then next thing uh that you can then uh get the sizing is uh using the libraries like splitting the code in libraries then you can look the uh definition how you define the uh uh your vs inside the contract so if the VAR is immutable then it's uh uh if it's not using the state or changing the state if it's some fixed value immutable you can save a lot of gas there uh then defining the time time what is like in some cases problematic on every blockchain to get current time you're getting the time of the block that is in past so how fast is the network you need to think about that uh defining uh there is a type in solidity called address like you have in string you have address Li type you can use address as type but you can use uh uh put that address in bite 32 just different format and you will also you can save that gas and then uh like redefine the loops length of the loops how how much you're returning that's the uh important and librar S uh uh mentioned also uh using the pure and view modifiers so when you're are changing the state on the network you're the the gas when you're reading something but not reading for the whole uh Network like uh taking the values from the network then doing some calculations or you're not from The View calling some functions that are doing that in that case you're reading local node then you can use pure and View and that means that uh gas will go down you're not paying the gas you're just like uh telling the compiler okay when I call this function I will just look at the node this specific point in memory and give me that value so you're not doing anything also uh I will send uh uh like useful links and everything uh so you can run into this is more like in into all this question
