Native Programs Best Practices
Native code owns every security check. These practices keep programs small, readable, and resistant to common Solana exploits.
Search across all documentation pages
Native code owns every security check. These practices keep programs small, readable, and resistant to common Solana exploits.
cargo build-sbf and LiteSVM tests in CI.Often only hot paths, not whole app.
At least one Solana-security-focused reviewer.
Strongly recommended for clients.
Instruction parser and account validator.
Small internal macros OK; avoid hidden control flow.
instruction, processor, state, error standard.
Run on host cfg tests.
List callee programs and privilege changes.
Extra scrutiny before burning upgrade key.
Validate extension layouts explicitly.
Default dev environment per manifest.
Encouraged for auditability.
Stack versions: This page was written for Agave 4.1.1, Solana CLI 3.0.10, Anchor 0.32.1, anchor-lang 0.32.1, Rust 1.91.1, @solana/kit 7.0.0, Surfpool 0.12.0, and LiteSVM 0.6.x.
Reviewed by Chris St. John·Last updated Jul 16, 2026