Lint Catalog
This document provides a concise reference for all lints supported by soroban-cost-linter. Each entry includes the lint name, its default severity, a brief description, and a link to the full documentation.
| Lint | Default Severity | Description | Docs |
|---|---|---|---|
soroban_storage_in_loop | deny | performs a storage read or write inside a loop body | Link |
redundant_env_clone | warn | clones the Env handle redundantly | Link |
unnecessary_host_function_call | warn | calls host functions that could be hoisted or avoided | Link |
soroban_redundant_storage_read | warn | performs sequential redundant reads or has/get checks on the same key | Link |
storage_write_without_read | warn | performs a storage set without any prior get or has in the function | Link |
discarded_storage_read | warn | reads from storage whose result is never used | Link |
instance_storage_for_unbounded_data | warn | stores unbounded collections like Vec, Map, or Bytes in instance storage | Link |
persistent_read_without_ttl_extension | warn | reads from persistent storage without extending its TTL in the same function | Link |
loop_invariant_storage_access | warn | performs storage access inside a loop with loop-invariant operands | Link |
storage_key_construction_in_loop | warn | constructs storage keys inside loop bodies where the key is invariant | Link |
bytes_append_in_loop | warn | appends to Bytes or Vec inside loop bodies causing repeated host reallocations | Link |
unbounded_input_loop | warn | loops with iteration count derived from untrusted input performing storage writes | Link |
unnecessary_string_to_bytes | warn | performs unnecessary string to bytes conversion | Link |
unnecessary_host_function_call_legacy | warn | legacy unnecessary host function call | Link |
map_insert_in_loop | warn | inserts into Map inside a loop | Link |
inefficient_bytes_concat | warn | inefficient bytes concatenation | Link |
contract_call_in_loop | warn | performs contract call inside loop | Link |
extend_ttl_in_loop | warn | extends ttl inside loop | Link |
formatted_panic_payload | warn | formatted panic payload | Link |
linear_scan_in_loop | warn | linear scan inside loop | Link |
require_auth_in_loop | warn | requires auth inside loop | Link |
signature_verification_in_loop | warn | signature verification inside loop | Link |
symbol_key_boundary | warn | symbol key boundary | Link |
symbol_key_enum_storage | warn | symbol key enum storage | Link |
symbol_key_event_topics | warn | symbol key event topics | Link |
symbol_new_for_short_literal | warn | uses Symbol::new for short literal | Link |
unbounded_recursion | warn | unbounded recursion | Link |
unwrap_on_storage_get | warn | unwraps on storage get | Link |
vec_where_slice_could_be_used | warn | uses Vec where slice could be used | Link |
soroban_inefficient_bytes_concat | warn | soroban inefficient bytes concat | Link |
u128_where_u64_suffices | warn | uses 128-bit arithmetic where 64 bits would suffice, which is extremely expensive on wasm32 | Link |
float_arithmetic_in_contract | warn | performs floating-point arithmetic in contract code where fixed-point integer arithmetic is preferred | Link |
duplicate_storage_key_construction | warn | constructs the same storage key expression in multiple function bodies | Link |
option_wrapping_in_storage | warn | stores an `Option<T> in storage where the key already models absence | Link |
ledger_context_read_in_loop | warn | reads a ledger context value inside a loop when it cannot change during the invocation | Link |
redundant_require_auth | warn | require_auth called more than once on the same address in a single function body | Link |
Severities can be overridden via budget.toml.