# Enforce some level of community standards on tests/test coverage/auditing for contracts

**URL:** <https://forum.scrt.network/t/enforce-some-level-of-community-standards-on-tests-test-coverage-auditing-for-contracts/4372>\
**Category:** Secret Contracts and Secret Apps\
**Created:** [September 14, 2021, 9:32pm UTC](https://forum.scrt.network/t/enforce-some-level-of-community-standards-on-tests-test-coverage-auditing-for-contracts/4372 "2021-09-14T21:32:55Z")\
**Posts on this page:** 10\
**Page:** 1

<div class="post-metadata">

**Author:** ![Avret](https://yyz1.discourse-cdn.com/flex035/user_avatar/forum.scrt.network/avret/32/603_2.png) [@Avret](https://forum.scrt.network/u/Avret)\
**Post date:** [September 14, 2021, 9:32pm UTC](https://forum.scrt.network/t/enforce-some-level-of-community-standards-on-tests-test-coverage-auditing-for-contracts/4372/1 "2021-09-14T21:32:55Z")

</div>

so, as the recent exploit showed us (not like we needed more evidence) it turns out writing code is actually hard (who knew). Especially when you want that code to be exploit proof. And this got me thinking…we can, as a community, require some level of proof of test coverage, if _nothing else_, before we allow contracts to start running on SN (_even more so if they’re LPs on the bridge._) Leaving this here to get the convo started. (My personal thoughts are requiring 100% test coverage with ideally fuzz tests/PBTs.)

---

<div class="post-metadata">

**Author:** ![darwinzer0](https://yyz1.discourse-cdn.com/flex035/user_avatar/forum.scrt.network/darwinzer0/32/1009_2.png) [@darwinzer0](https://forum.scrt.network/u/darwinzer0)\
**Post date:** [September 14, 2021, 10:25pm UTC](https://forum.scrt.network/t/enforce-some-level-of-community-standards-on-tests-test-coverage-auditing-for-contracts/4372/2 "2021-09-14T22:25:53Z")

</div>

The problem is that we do not know that a given testing regime would have caught this particular exploit. Perhaps that will come out in the post mortem. Anyway, it is hard to justify putting this requirement on a permissionless chain. The issue is really about having contracts that are “too big to fail” in the network. If there were lots of other dApps moving money on SN, it would not have been so easy to make the call to rollback the network without public discussion.

I suppose you could try to limit the amount of funds that a contract without “proof-of-test” can hold, but I’m not even sure that’s possible given that the value of the funds in fiat is not fixed.

The more important question imo is how, going forward as a community, are decisions to be made around when or if to rollback the whole network given a bug in a contract?

---

<div class="post-metadata">

**Author:** ![mumuse](https://avatars.discourse-cdn.com/v4/letter/m/bbe5ce/32.png) [@mumuse](https://forum.scrt.network/u/mumuse)\
**Post date:** [September 14, 2021, 10:46pm UTC](https://forum.scrt.network/t/enforce-some-level-of-community-standards-on-tests-test-coverage-auditing-for-contracts/4372/4 "2021-09-14T22:46:41Z")

</div>

I don’t believe on making anything permissioned on the network. Ironically enough the permissioned bridges (besides everyone’s hard work) are what saved us this time around. At the same time, I think the people involved have learned the lesson that there is more of a spectrum to the phrase “audits are useless”.

The reality is there’s no reason to believe an audit would have caught this though, just check [Rekt - Leaderboard](https://rekt.news/leaderboard/). It’s also nevertheless true that an audit = more eyes looking at the code and that will _never_ be worse.

> [@darwinzer0](#):
>
> The more important question imo is how, going forward as a community, are decisions to be made around when or if to rollback the whole network given a bug in a contract?

We were lucky this time cause the only product active was secretswap (not really counting secretheroes nor the fardels beta here). Going onward we won’t have that option, this was our get out of jail card imo.

TL;DR Stop being nerds and get audits. Audits = more people looking. It’s that simple.

---

<div class="post-metadata">

**Author:** ![Avret](https://yyz1.discourse-cdn.com/flex035/user_avatar/forum.scrt.network/avret/32/603_2.png) [@Avret](https://forum.scrt.network/u/Avret)\
**Post date:** [September 14, 2021, 11:18pm UTC](https://forum.scrt.network/t/enforce-some-level-of-community-standards-on-tests-test-coverage-auditing-for-contracts/4372/5 "2021-09-14T23:18:51Z")

</div>

ok imo having an automated testing setup for contracts (or even something that just automatically checks for a testcov report that the contract can generate!!!) isn’t permissioning

---

<div class="post-metadata">

**Author:** ![mumuse](https://avatars.discourse-cdn.com/v4/letter/m/bbe5ce/32.png) [@mumuse](https://forum.scrt.network/u/mumuse)\
**Post date:** [September 14, 2021, 11:42pm UTC](https://forum.scrt.network/t/enforce-some-level-of-community-standards-on-tests-test-coverage-auditing-for-contracts/4372/7 "2021-09-14T23:42:26Z")

</div>

Maybe im misintepreting but how is ”before we allow contracts to start running on SN” not permissioning?

---

<div class="post-metadata">

**Author:** ![Avret](https://yyz1.discourse-cdn.com/flex035/user_avatar/forum.scrt.network/avret/32/603_2.png) [@Avret](https://forum.scrt.network/u/Avret)\
**Post date:** [September 15, 2021, 12:41am UTC](https://forum.scrt.network/t/enforce-some-level-of-community-standards-on-tests-test-coverage-auditing-for-contracts/4372/8 "2021-09-15T00:41:27Z")

</div>

automated testing plus a standard for communicating th results, yeah

---

<div class="post-metadata">

**Author:** ![Frank\_L\_Right](https://yyz1.discourse-cdn.com/flex035/user_avatar/forum.scrt.network/frank_l_right/32/2289_2.png) [@Frank\_L\_Right](https://forum.scrt.network/u/Frank_L_Right)\
**Post date:** [September 15, 2021, 8:39pm UTC](https://forum.scrt.network/t/enforce-some-level-of-community-standards-on-tests-test-coverage-auditing-for-contracts/4372/9 "2021-09-15T20:39:54Z")

</div>

This is the conversation we need to be having! Keep it up! If there was an error in a contract it means we need more proofreading. The competition is fierce in fast-moving crypto tech and that leads to things being pushed out sometimes before they are ready.

---

<div class="post-metadata">

**Author:** ![dylanschultzie](https://yyz1.discourse-cdn.com/flex035/user_avatar/forum.scrt.network/dylanschultzie/32/2595_2.png) [@dylanschultzie](https://forum.scrt.network/u/dylanschultzie)\
**Post date:** [September 26, 2021, 7:20pm UTC](https://forum.scrt.network/t/enforce-some-level-of-community-standards-on-tests-test-coverage-auditing-for-contracts/4372/10 "2021-09-26T19:20:36Z")

</div>

I don’t think an entire committee is necessary for this, but it _would_ be nice to have at least a strike team to audit the codebase/add tests/etc.

---

<div class="post-metadata">

**Author:** ![Avret](https://yyz1.discourse-cdn.com/flex035/user_avatar/forum.scrt.network/avret/32/603_2.png) [@Avret](https://forum.scrt.network/u/Avret)\
**Post date:** [September 26, 2021, 7:23pm UTC](https://forum.scrt.network/t/enforce-some-level-of-community-standards-on-tests-test-coverage-auditing-for-contracts/4372/11 "2021-09-26T19:23:10Z")

</div>

Strike team, committee, idc what it’s called

---

<div class="post-metadata">

**Author:** ![darwinzer0](https://yyz1.discourse-cdn.com/flex035/user_avatar/forum.scrt.network/darwinzer0/32/1009_2.png) [@darwinzer0](https://forum.scrt.network/u/darwinzer0)\
**Post date:** [September 27, 2021, 12:28am UTC](https://forum.scrt.network/t/enforce-some-level-of-community-standards-on-tests-test-coverage-auditing-for-contracts/4372/12 "2021-09-27T00:28:49Z")

</div>

In principle I like the idea of more testing, however, I am unsure what the mandate would be for such a committee/strike team. Is this about developing standards and an automated testing platform, or is this about having an ongoing team of auditors?

For the former, couldn’t this be a grant project?

For the latter, how do we allocate the resources, which projects does this group prioritise for testing, etc. How would that scale with growth of the network and in the number of applications running on it?
