#cf-outreach: Hey all, I am Jon from Quantstamp. We audit Daml/C

Hey all, I am Jon from Quantstamp. We audit Daml/Canton apps and keep hitting a gap with insufficient coverage and fuzzing tooling for Daml. We’ve proposed building both as open source through the Canton dev fund: DamlCov (line/branch test coverage) and DamlFuzz (property-based fuzzing).

We are looking for some ecosystem support. If your project would use these, a short supporting comment on the PRs helps the committee gauge demand:

DamlCov: github.com/canton-foundation/canton-dev-fund/pull/323
DamlFuzz: github.com/canton-foundation/canton-dev-fund/pull/52

Something like:
“We are [project]. We want auditors and developers to have all the tools they need to secure the ecosystem, and we’d use [coverage in our CI / fuzzing on our contracts]. We’d like to see this built.”

Questions welcome - happy to share what’s planned. Thanks!

2 Likes

Hey Jon! I am Tomi from Moonsong Labs. We looked into fuzzing before and found DamlFuzz to be in line with what we expected from a strong fuzzer proposal. I will read this one again today, but it’s something we are interested in using.

Note: There was a related post and proposal worth flagging in this area, sharing for visibility [Dev Fund] daml-fuzz — property-based fuzzing for Daml (working PoC, 8/8 mutation score) — seeking a Daml Tooling SIG champion

2 Likes

Thanks again, Tomimor! We’ve already been in touch and discussed how we can collaborate

1 Like