Skip to content

Lint Catalog ​

This document provides a concise reference for all lints supported by soroban-cost-linter. Each entry includes the lint name, its default severity, a brief description, and a link to the full documentation.

LintDefault SeverityDescriptionDocs
soroban_storage_in_loopdenyperforms a storage read or write inside a loop bodyLink
redundant_env_clonewarnclones the Env handle redundantlyLink
unnecessary_host_function_callwarncalls host functions that could be hoisted or avoidedLink
soroban_redundant_storage_readwarnperforms sequential redundant reads or has/get checks on the same keyLink
storage_write_without_readwarnperforms a storage set without any prior get or has in the functionLink
discarded_storage_readwarnreads from storage whose result is never usedLink
instance_storage_for_unbounded_datawarnstores unbounded collections like Vec, Map, or Bytes in instance storageLink
persistent_read_without_ttl_extensionwarnreads from persistent storage without extending its TTL in the same functionLink
loop_invariant_storage_accesswarnperforms storage access inside a loop with loop-invariant operandsLink
storage_key_construction_in_loopwarnconstructs storage keys inside loop bodies where the key is invariantLink
bytes_append_in_loopwarnappends to Bytes or Vec inside loop bodies causing repeated host reallocationsLink
unbounded_input_loopwarnloops with iteration count derived from untrusted input performing storage writesLink
unnecessary_string_to_byteswarnperforms unnecessary string to bytes conversionLink
unnecessary_host_function_call_legacywarnlegacy unnecessary host function callLink
map_insert_in_loopwarninserts into Map inside a loopLink
inefficient_bytes_concatwarninefficient bytes concatenationLink
contract_call_in_loopwarnperforms contract call inside loopLink
extend_ttl_in_loopwarnextends ttl inside loopLink
formatted_panic_payloadwarnformatted panic payloadLink
linear_scan_in_loopwarnlinear scan inside loopLink
require_auth_in_loopwarnrequires auth inside loopLink
signature_verification_in_loopwarnsignature verification inside loopLink
symbol_key_boundarywarnsymbol key boundaryLink
symbol_key_enum_storagewarnsymbol key enum storageLink
symbol_key_event_topicswarnsymbol key event topicsLink
symbol_new_for_short_literalwarnuses Symbol::new for short literalLink
unbounded_recursionwarnunbounded recursionLink
unwrap_on_storage_getwarnunwraps on storage getLink
vec_where_slice_could_be_usedwarnuses Vec where slice could be usedLink
soroban_inefficient_bytes_concatwarnsoroban inefficient bytes concatLink
u128_where_u64_sufficeswarnuses 128-bit arithmetic where 64 bits would suffice, which is extremely expensive on wasm32Link
float_arithmetic_in_contractwarnperforms floating-point arithmetic in contract code where fixed-point integer arithmetic is preferredLink
duplicate_storage_key_constructionwarnconstructs the same storage key expression in multiple function bodiesLink
option_wrapping_in_storagewarnstores an `Option<T> in storage where the key already models absenceLink
ledger_context_read_in_loopwarnreads a ledger context value inside a loop when it cannot change during the invocationLink
redundant_require_authwarnrequire_auth called more than once on the same address in a single function bodyLink

Severities can be overridden via budget.toml.

Built for the Stellar & Soroban ecosystem.