# Canister audit advice

**URL:** <https://forum.dfinity.org/t/canister-audit-advice/8469>\
**Category:** Programs & Applications\
**Created:** [November 9, 2021, 5:58pm UTC](https://forum.dfinity.org/t/canister-audit-advice/8469 "2021-11-09T17:58:31Z")\
**Posts on this page:** 10\
**Page:** 1

<div class="post-metadata">

**Author:** ![nomeata](https://sea1.discourse-cdn.com/flex023/user_avatar/forum.dfinity.org/nomeata/32/733_2.png) [@nomeata](https://forum.dfinity.org/u/nomeata)\
**Post date:** [November 9, 2021, 5:58pm UTC](https://forum.dfinity.org/t/canister-audit-advice/8469/1 "2021-11-09T17:58:31Z")

</div>

From a recent Canister source code auditing gig I extracted some general advice, which I am happy to share here with the community. If you are implementing Canisters beyond toy examples, this might be a useful list to go through:

[https://www.joachim-breitner.de/blog/788-How\_to\_audit\_an\_Internet\_Computer\_canister](https://www.joachim-breitner.de/blog/788-How_to_audit_an_Internet_Computer_canister)

---

<div class="post-metadata">

**Author:** ![jzxchiang](https://sea1.discourse-cdn.com/flex023/user_avatar/forum.dfinity.org/jzxchiang/32/2592_2.png) [@jzxchiang](https://forum.dfinity.org/u/jzxchiang)\
**Post date:** [November 9, 2021, 10:19pm UTC](https://forum.dfinity.org/t/canister-audit-advice/8469/2 "2021-11-09T22:19:37Z")

</div>

This is incredibly helpful.

One question: when you mean reply/response handler to an inter-canister message, do you mean the code that happens after the `await`?

Also, I really hope canister upgrades are improved in the near future. I read somewhere in the forum that this is in the roadmap. Right now, it seems at best tedious and at worst quite dangerous.

---

<div class="post-metadata">

**Author:** ![GLdev](https://avatars.discourse-cdn.com/v4/letter/g/4bbf92/32.png) [@GLdev](https://forum.dfinity.org/u/GLdev)\
**Post date:** [November 10, 2021, 6:43am UTC](https://forum.dfinity.org/t/canister-audit-advice/8469/3 "2021-11-10T06:43:55Z")

</div>

Great insights! Two quick questions:

1. (in rust) There doesn’t seem to be a way to set a timeout when calling a canister. Are there any plans to support this in the future? Being able to handle long response times at source would be handy.

2. Regarding backups - I had this flow in mind: Have a canister state that goes from “live” to “maintenance”, and if it’s in maintenance drops every call in “inspect\_message” except for a set of backup related calls. Would dropping any update calls in “inspect\_message” guarantee that the state cannot change? How would one check if there are “in flight” calls still pending? Just wait some random amount of minutes before proceeding with backing up?

---

<div class="post-metadata">

**Author:** ![nomeata](https://sea1.discourse-cdn.com/flex023/user_avatar/forum.dfinity.org/nomeata/32/733_2.png) [@nomeata](https://forum.dfinity.org/u/nomeata)\
**Post date:** [November 10, 2021, 10:08am UTC](https://forum.dfinity.org/t/canister-audit-advice/8469/4 "2021-11-10T10:08:43Z")

</div>

> [@jzxchiang](#):
>
> when you mean reply/response handler to an inter-canister message, do you mean the code that happens after the `await` ?

Exactly! Unfortunately, I expect serious developers won’t get around thinking of their code in the form that the compiler transforms it to, with explicit continuations. At least sometimes.

---

<div class="post-metadata">

**Author:** ![nomeata](https://sea1.discourse-cdn.com/flex023/user_avatar/forum.dfinity.org/nomeata/32/733_2.png) [@nomeata](https://forum.dfinity.org/u/nomeata)\
**Post date:** [November 10, 2021, 10:10am UTC](https://forum.dfinity.org/t/canister-audit-advice/8469/5 "2021-11-10T10:10:08Z")

</div>

> [@GLdev](#):
>
> There doesn’t seem to be a way to set a timeout when calling a canister.

Inter-canister calls or external calls? For inter-canister calls you cannot. For external calls, your agent library has to poll for the response anyways, so there a timeout applies.

---

<div class="post-metadata">

**Author:** ![nomeata](https://sea1.discourse-cdn.com/flex023/user_avatar/forum.dfinity.org/nomeata/32/733_2.png) [@nomeata](https://forum.dfinity.org/u/nomeata)\
**Post date:** [November 10, 2021, 10:11am UTC](https://forum.dfinity.org/t/canister-audit-advice/8469/6 "2021-11-10T10:11:47Z")

</div>

> [@GLdev](#):
>
> Would dropping any update calls in “inspect\_message” guarantee that the state cannot change?

No, inspect message is _only_ for ingress messages, and will not block inter-canister messages.

You should add this “maintenance mode” check to the beginning of each update method, then your plan is good.

---

<div class="post-metadata">

**Author:** ![GLdev](https://avatars.discourse-cdn.com/v4/letter/g/4bbf92/32.png) [@GLdev](https://forum.dfinity.org/u/GLdev)\
**Post date:** [November 10, 2021, 11:19am UTC](https://forum.dfinity.org/t/canister-audit-advice/8469/7 "2021-11-10T11:19:15Z")

</div>

> [@nomeata](#):
>
> No, inspect message is _only_ for ingress messages, and will not block inter-canister messages.

I see. That’s an important distinction to make. Thanks.

---

<div class="post-metadata">

**Author:** ![nomeata](https://sea1.discourse-cdn.com/flex023/user_avatar/forum.dfinity.org/nomeata/32/733_2.png) [@nomeata](https://forum.dfinity.org/u/nomeata)\
**Post date:** [November 10, 2021, 10:49pm UTC](https://forum.dfinity.org/t/canister-audit-advice/8469/9 "2021-11-10T22:49:59Z")

</div>

Thanks for sharing that, great insights! (And a clear sign that the IC platform still has quite done way to go before it matches the vision…)

---

<div class="post-metadata">

**Author:** ![saikatdas0790](https://sea1.discourse-cdn.com/flex023/user_avatar/forum.dfinity.org/saikatdas0790/32/17147_2.png) [@saikatdas0790](https://forum.dfinity.org/u/saikatdas0790)\
**Post date:** [November 12, 2021, 6:42am UTC](https://forum.dfinity.org/t/canister-audit-advice/8469/10 "2021-11-12T06:42:25Z")

</div>

What is the destination for these backups?  
Also, have you considered off chain backup where a cloud hosted cron scheduled worker takes incremental backups to a cloud hosted data store?

Asking because I’m contemplating these exact questions myself

---

<div class="post-metadata">

**Author:** ![Motokoder](https://avatars.discourse-cdn.com/v4/letter/m/e47c2d/32.png) [@Motokoder](https://forum.dfinity.org/u/Motokoder)\
**Post date:** [December 28, 2021, 2:14pm UTC](https://forum.dfinity.org/t/canister-audit-advice/8469/11 "2021-12-28T14:14:20Z")

</div>

Thank you for sharing your experience. Your post has been very helpful for me and I’m sure many others. I’m not Rust developer, but it does not look like you are doing any kind of binary serialization in that code. By chunk, do you mean an array segment?

How would you handle large blob data that exceeds the transfer limits?
