使用 Foundry/Hardhat 进行高级测试
利用 Foundry 或 Hardhat 等测试框架的高级功能,全面开展单元测试、集成测试和模糊测试。
使用 Foundry/Hardhat 进行高级测试 是 CoddyKit 上的免费 Blockchain Smart Contracts with Solidity 课时。 这是第 1 节课,共 4 节。 你可以在下方免费阅读本课时的完整内容 — 然后在浏览器中使用内置代码编辑器和全天候 AI 导师进行实践。 这是 Blockchain Smart Contracts with Solidity 学习路径的一部分,你的进度在网页和 CoddyKit 应用中同步。 Blockchain Smart Contracts with Solidity 课程共包含 4 节课。
本课时的部分内容尚未翻译,以英文显示。
Intro to Advanced Testing
Welcome to advanced smart contract testing! As contracts grow in complexity, simple unit tests aren't enough to guarantee robustness.
We need powerful strategies to catch subtle bugs and ensure security. This lesson dives into sophisticated techniques using frameworks like Foundry or Hardhat.
Why Advanced Testing Matters
Basic tests check expected behavior, but what about unexpected inputs or complex interactions? Advanced testing helps with:
- Edge Cases: Fuzz testing helps find inputs you didn't anticipate.
- Interactions: Integration tests verify how multiple contracts work together.
- Security: Advanced methods uncover vulnerabilities before deployment.
These are crucial for building battle-hardened smart contracts.
Foundry: Your Advanced Toolkit
While Hardhat is excellent, for truly advanced Solidity-native testing, Foundry stands out. It's a blazing fast, portable, and modular toolkit for Ethereum application development written in Rust.
Foundry uses Solidity for writing tests, making it very intuitive for smart contract developers.
Unit Testing Deep Dive with Foundry
Unit tests check individual functions in isolation. With Foundry, you write tests directly in Solidity, often inheriting from Test. Let's test a simple counter contract.
Notice how we set up the test environment in setUp() before each test.
pragma solidity ^0.8.0;
import "forge-std/Test.sol";
contract Counter {
uint public count;
function increment() public {
count++;
}
function decrement() public {
require(count > 0, "Count cannot be negative");
count--;
}
}
contract CounterTest is Test {
Counter public counter;
function setUp() public {
counter = new Counter();
}
function test_Increment() public {
counter.increment();
assertEq(counter.count(), 1, "Count should be 1 after increment");
}
function test_Decrement() public {
counter.increment(); // count is 1
counter.decrement(); // count is 0
assertEq(counter.count(), 0, "Count should be 0 after decrement");
}
function testFail_DecrementZero() public {
// This test specifically expects a revert
counter.decrement();
}
}Understanding Integration Testing
Integration tests verify the interactions between multiple smart contracts or between a contract and external services (like oracles). They ensure that different components work harmoniously.
This is crucial because individual contracts might be bug-free, but their combined logic could introduce issues.
Integration Test Example (Foundry)
Let's simulate a scenario where a Token contract interacts with a Vault contract. The vault allows users to deposit and withdraw tokens.
Our integration test will check if tokens are correctly transferred between them and user balances are updated.
pragma solidity ^0.8.0;
import "forge-std/Test.sol";
import "forge-std/console.sol";
contract MyToken {
mapping(address => uint) public balances;
constructor() {
balances[msg.sender] = 1000;
}
function transfer(address to, uint amount) public returns (bool) {
require(balances[msg.sender] >= amount, "Insufficient balance");
balances[msg.sender] -= amount;
balances[to] += amount;
return true;
}
}
contract Vault {
MyToken public token;
mapping(address => uint) public deposits;
constructor(address _token) {
token = MyToken(_token);
}
function deposit(uint amount) public {
// Assume token.transferFrom or approval for real world.
// Simplified here for demo to show interaction.
token.transfer(address(this), amount);
deposits[msg.sender] += amount;
}
function withdraw(uint amount) public {
require(deposits[msg.sender] >= amount, "Insufficient deposit");
deposits[msg.sender] -= amount;
token.transfer(msg.sender, amount);
}
}
contract IntegrationTest is Test {
MyToken public token;
Vault public vault;
address public ALICE = makeAddr("alice");
function setUp() public {
token = new MyToken();
vault = new Vault(address(token));
// Give ALICE some tokens for testing from initial deployer
vm.startPrank(address(this));
token.transfer(ALICE, 500);
vm.stopPrank();
}
function test_AliceDepositsAndWithdraws() public {
vm.startPrank(ALICE);
uint initialAliceBalance = token.balances(ALICE);
uint depositAmount = 100;
// Alice deposits
token.transfer(address(vault), depositAmount);
vault.deposit(depositAmount);
assertEq(token.balances(ALICE), initialAliceBalance - depositAmount, "Alice's balance should decrease");
assertEq(token.balances(address(vault)), depositAmount, "Vault should hold deposit amount");
assertEq(vault.deposits(ALICE), depositAmount, "Alice's vault deposit should be recorded");
// Alice withdraws
vault.withdraw(depositAmount);
assertEq(token.balances(ALICE), initialAliceBalance, "Alice's balance should be restored");
assertEq(token.balances(address(vault)), 0, "Vault should be empty");
assertEq(vault.deposits(ALICE), 0, "Alice's vault deposit should be zero");
vm.stopPrank();
}
}Fuzz Testing: Uncovering Edge Cases
Fuzz testing (or fuzzing) automatically generates random, unexpected inputs to your functions. Instead of you guessing edge cases, the fuzzer tries millions of combinations.
This is incredibly effective for finding vulnerabilities like integer overflows, underflows, or unexpected reverts that manual tests might miss.
Fuzz Testing in Action (Foundry)
With Foundry, fuzzing is built-in. Just add parameters to your test function! Foundry will automatically generate random values for a and b within reasonable ranges.
This helps ensure our functions handle various inputs correctly, especially when checking for unexpected behavior like overflows or underflows.
pragma solidity ^0.8.0;
import "forge-std/Test.sol";
contract Calculator {
function add(uint a, uint b) public pure returns (uint) {
return a + b;
}
function subtract(uint a, uint b) public pure returns (uint) {
require(a >= b, "Cannot subtract more than available");
return a - b;
}
}
contract FuzzTest is Test {
Calculator public calculator;
function setUp() public {
calculator = new Calculator();
}
// Fuzz test for addition: check if a + b >= a (unless overflow)
function testFuzz_Add(uint a, uint b) public {
// Note: For real-world, use SafeMath or explicit checks for overflows.
// This test implicitly relies on default Solidity overflow behavior.
uint sum = calculator.add(a, b);
// If no overflow, sum should be >= a
if (sum < a) {
// Overflow occurred
assertTrue(a > type(uint).max - b, "Expected overflow");
} else {
assertTrue(sum >= a, "Sum should be greater than or equal to a");
}
}
// Fuzz test for subtraction: ensure result is always <= a
function testFuzz_Subtract(uint a, uint b) public {
// Only run if a >= b to avoid expected reverts from 'require'
vm.assume(a >= b);
uint result = calculator.subtract(a, b);
assertTrue(result <= a, "Result should be less than or equal to a");
}
}Property-Based Testing (PBT)
Fuzz testing is a powerful form of Property-Based Testing (PBT). Instead of testing specific examples, PBT defines properties (invariants) that should always hold true for your code.
The fuzzer then generates inputs to try and break these properties. This approach leads to more robust and less brittle tests, identifying edge cases you might never think of manually.
Test Your Knowledge
Which of the following statements about advanced smart contract testing techniques are TRUE?
Recap: Advanced Testing
You've explored the world of advanced smart contract testing!
- We moved beyond basic unit tests to tackle complex scenarios.
- Foundry provides powerful tools for Solidity-native testing.
- Unit tests verify individual components.
- Integration tests ensure multiple contracts work together.
- Fuzz testing and Property-Based Testing help discover hidden bugs by generating random inputs and verifying invariants.
Mastering these techniques is essential for deploying secure and reliable smart contracts.
常见问题解答
「使用 Foundry/Hardhat 进行高级测试」课时是免费的吗?
是的 — 「使用 Foundry/Hardhat 进行高级测试」的完整文本可在网页上免费阅读。要进行交互式练习(内置代码编辑器和全天候 AI 导师)并解锁 Blockchain Smart Contracts with Solidity 课程的其余内容,请升级到 CoddyKit PRO。 Blockchain Smart Contracts with Solidity 课程共包含 4 节课。
「使用 Foundry/Hardhat 进行高级测试」这节课中我会学到什么?
利用 Foundry 或 Hardhat 等测试框架的高级功能,全面开展单元测试、集成测试和模糊测试。 你通过在浏览器中直接运行的动手代码来练习 Blockchain Smart Contracts with Solidity,全天候 AI 导师会在你学习这节课的过程中回答你的问题。
学习 Blockchain Smart Contracts with Solidity 需要有经验吗?
无需任何先前经验。CoddyKit 上的 Blockchain Smart Contracts with Solidity 课程适合初学者到高级学习者,你可以从这里开始或从头开始,按照自己的节奏学习。 这是第 1 节课,共 4 节。
「使用 Foundry/Hardhat 进行高级测试」课时需要多长时间?
大多数 CoddyKit 课程大约需要 5–10 分钟。每节课都很精短且互动,所以你能稳步进步,并在网页和应用中从离开的地方继续。
我能在这节 Blockchain Smart Contracts with Solidity 课中编写并运行代码吗?
能。每节 Blockchain Smart Contracts with Solidity 课都包含内置代码编辑器,你可以在浏览器中直接编写并运行真实代码,并获得即时 AI 反馈 — 无需本地设置。
此课程中的所有课时
- 使用 Foundry/Hardhat 进行高级测试
- 形式化验证基础
- 主网部署与监控
- 模糊测试与不变量测试