0Pricing
Blockchain Smart Contracts with Solidity · Ders

SafeMath ile Güvenli Kodlama

Aritmetik işlemlerde tamsayı taşması ve eksik taşması saldırılarını önlemek için SafeMath gibi kitaplıkları kullanmayı öğrenin.

SafeMath ile Güvenli Kodlama, CoddyKit'te ücretsiz bir Blockchain Smart Contracts with Solidity dersidir. Bu, 4 dersinin 3. dersidir. Aşağıdan dersin tamamını ücretsiz okuyabilir, sonra tarayıcıda yerleşik kod editörü ve 7/24 yapay zeka koçu ile uygulamalı olarak pratik yapabilirsin. Bu, Blockchain Smart Contracts with Solidity öğrenme yolunun bir parçasıdır ve ilerlemeniz web ve CoddyKit uygulaması arasında senkronize olur. Blockchain Smart Contracts with Solidity kursu toplamda 4 dersten oluşur.

Bu dersin bazı bölümleri henüz çevrilmemiş olup İngilizce olarak gösterilmektedir.

The Integer Problem

In Solidity, integer types like uint256 have a fixed size. This means they can only store numbers up to a certain maximum value and down to a minimum (usually 0 for unsigned integers).

When an arithmetic operation exceeds these limits, it can lead to critical vulnerabilities called integer overflows and underflows.

Unchecked Math Dangers

Solidity's default arithmetic operations (+, -, *, /) do not automatically check for overflows or underflows. Instead, the number 'wraps around'.

This behavior can be exploited by attackers, leading to incorrect token balances, unexpected contract state, and financial losses.

Overflow in Action

Consider a uint8 variable, which can hold values from 0 to 255. What happens if we try to add 1 to 255? Run this code and call incrementUnsafely(). You'll see the value reset to 0!

/*
  This contract demonstrates an integer overflow.
  A uint8 can only hold values from 0 to 255.
  Adding 1 to 255 will cause it to wrap around to 0.
*/
// SPDX-License-Identifier: MIT
pragma solidity ^0.8.0;

contract UnsafeCounter {
    uint8 public count = 255; // Max value for uint8

    // Function to increment the counter unsafely
    function incrementUnsafely() public {
        count = count + 1;
    }
}

Underflow Example

Similarly, an underflow occurs when a number goes below its minimum value. For a uint (unsigned integer), the minimum is 0.

If you subtract 1 from 0, it wraps around to the maximum value (255 for uint8, or 2^256 - 1 for uint256).

/*
  This contract demonstrates an integer underflow.
  A uint8 can only hold values from 0 to 255.
  Subtracting 1 from 0 will cause it to wrap around to 255.
*/
// SPDX-License-Identifier: MIT
pragma solidity ^0.8.0;

contract UnderflowDemo {
    uint8 public value = 0; // Min value for uint8

    // Function to decrement the value unsafely
    function decrementUnsafely() public {
        value = value - 1;
    }
}

Introducing SafeMath

To prevent these critical errors, we use libraries like SafeMath. SafeMath provides functions for arithmetic operations (addition, subtraction, multiplication, division) that revert the transaction if an overflow or underflow would occur.

This ensures your contract's state remains consistent and secure, preventing malicious exploits.

Solidity Libraries Explained

A Solidity Library is a special type of contract that contains reusable code. Unlike regular contracts, libraries are stateless (they don't store data directly) and cannot hold Ether.

  • They are deployed once and their functions are called via DELEGATECALL.
  • This means the library's code runs in the context of the calling contract.
  • Libraries are perfect for shared utility functions like SafeMath.

Integrating SafeMath

To use SafeMath, you typically import it from a trusted source like OpenZeppelin. Then, you tell Solidity to apply SafeMath's functions to a specific integer type using the using A for B; directive.

This makes SafeMath's functions available as member functions on type B.

/*
  This contract demonstrates how to integrate and use SafeMath.
  We're including a simplified mock SafeMath library for demonstration.
*/
// SPDX-License-Identifier: MIT
pragma solidity ^0.8.0;

// A simplified mock SafeMath library for demonstration
library SafeMath {
    function add(uint256 a, uint256 b) internal pure returns (uint256) {
        uint256 c = a + b;
        require(c >= a, "SafeMath: addition overflow");
        return c;
    }
}

contract MySafeContract {
    // Use SafeMath functions for all uint256 variables
    using SafeMath for uint256;

    uint256 public balance = 100;

    function deposit(uint256 amount) public {
        // Now you can call .add() directly on balance
        balance = balance.add(amount);
    }
    
    function getBalance() public view returns (uint256) {
        return balance;
    }
}

Safe Addition in Action

With SafeMath integrated, you use .add() instead of the standard + operator. If the addition would overflow, the transaction will revert, preventing incorrect state changes.

Call safeAdd() with a value like 10. Try calling it with a value that would cause an overflow (e.g., if total was max uint8 and you added 1).

/*
  This contract uses SafeMath for secure addition.
  If the addition causes an overflow, the transaction will revert.
*/
// SPDX-License-Identifier: MIT
pragma solidity ^0.8.0;

library SafeMath {
    function add(uint256 a, uint256 b) internal pure returns (uint256) {
        uint256 c = a + b;
        require(c >= a, "SafeMath: addition overflow");
        return c;
    }
}

contract SafeAdder {
    using SafeMath for uint256;
    uint256 public total = 0;

    function safeAdd(uint256 _value) public {
        total = total.add(_value); // Uses SafeMath.add
    }
}

Safe Subtraction in Action

Similarly, use .sub() for subtraction. This prevents underflows, ensuring that a subtraction operation will revert if the result would be negative (below zero for unsigned integers).

Call safeSubtract() with a value like 10. Try calling it with a value larger than balance (e.g., 101) to see it revert.

/*
  This contract uses SafeMath for secure subtraction.
  If the subtraction causes an underflow, the transaction will revert.
*/
// SPDX-License-Identifier: MIT
pragma solidity ^0.8.0;

library SafeMath {
    function sub(uint256 a, uint256 b) internal pure returns (uint256) {
        require(b <= a, "SafeMath: subtraction underflow");
        uint256 c = a - b;
        return c;
    }
}

contract SafeSubtractor {
    using SafeMath for uint256;
    uint256 public balance = 100;

    function safeSubtract(uint256 _value) public {
        balance = balance.sub(_value); // Uses SafeMath.sub
    }
}

Multiply, Divide, Modulo

SafeMath also provides .mul(), .div(), and .mod() for multiplication, division, and modulo operations, respectively.

  • .mul() checks for overflow.
  • .div() checks for division by zero and overflow.
  • .mod() checks for division by zero.

Always use these safe versions for critical arithmetic in your contracts.

Quick Check on SafeMath

You've learned about the importance of SafeMath. Let's test your understanding.

Recap: Secure Math

You've learned about the critical vulnerabilities of integer overflows and underflows in Solidity and how SafeMath provides a robust solution.

  • Always use SafeMath (or similar audited libraries) for arithmetic operations on unsigned integers in your smart contracts.
  • This prevents unexpected behavior and protects your contract's integrity.

Keep practicing secure coding! The next lessons will dive deeper into advanced security patterns.

Sıkça Sorulan Sorular

“SafeMath ile Güvenli Kodlama” dersi ücretsiz mi?

Evet — “SafeMath ile Güvenli Kodlama” dersin tüm metni burada web'de ücretsiz olarak okunabilir. Etkileşimli olarak pratik yapmak (yerleşik kod editörü ve 7/24 yapay zeka koçu) ve Blockchain Smart Contracts with Solidity kursunun geri kalanını açmak için CoddyKit PRO'ya yükselt. Blockchain Smart Contracts with Solidity kursu toplamda 4 dersten oluşur.

“SafeMath ile Güvenli Kodlama” dersinde ne öğreneceğim?

Aritmetik işlemlerde tamsayı taşması ve eksik taşması saldırılarını önlemek için SafeMath gibi kitaplıkları kullanmayı öğrenin. Blockchain Smart Contracts with Solidity ile uygulamalı kodu tarayıcıda doğrudan çalıştırarak pratik yaparsın ve 7/24 yapay zeka koçu dersi çalışırken sorularını yanıtlar.

Blockchain Smart Contracts with Solidity öğrenmeye başlamak için deneyim gerekli mi?

Önceden deneyim gerekmez. CoddyKit'te Blockchain Smart Contracts with Solidity, başlangıçtan ileri seviyeye kadar yapılandırıldığı için buradan başlayabilir veya başından başlayıp kendi hızında ilerleme yapabilirsin. Bu, 4 dersinin 3. dersidir.

“SafeMath ile Güvenli Kodlama” dersi ne kadar sürer?

Çoğu CoddyKit dersi yaklaşık 5–10 dakika sürer. Her biri kısa ve etkileşimli olduğu için sabit ilerleme yaparsın ve web ile uygulama arasında tam olarak bıraktığın yerden devam edebilirsin.

Bu Blockchain Smart Contracts with Solidity dersinde kod yazıp çalıştırabilir miyim?

Evet. Her Blockchain Smart Contracts with Solidity dersi yerleşik bir kod editörü içerir, bu sayede tarayıcıda gerçek kod yazıp çalıştırabilir ve anlık yapay zeka geri bildirimi alırsın — yerel kurulum gerekli değildir.

Bu kursun tüm dersleri

  1. Yaygın Güvenlik Açıkları (Yeniden Giriş vb.)
  2. Erişim Denetimi Kalıpları
  3. SafeMath ile Güvenli Kodlama
  4. Denetim, Test ve Hata Ödülleri
← Blockchain Smart Contracts with Solidity Sayfasına Dön