Rust for Solana Best Practices
Habits that keep Solana programs safe, cheap to run, and easy to audit. Walk this list before mainnet deploy and during code review.
Search across all documentation pages
Habits that keep Solana programs safe, cheap to run, and easy to audit. Walk this list before mainnet deploy and during code review.
ProgramError instead of panicking. Fails cleanly with decodable codes.LEN constants and assert data_len() at runtime. Avoids partial writes and parse panics.msg! and string formatting in production paths. Logs are expensive.cargo tree for non-no_std dependencies. Keeps binaries building and small.Clippy covers Rust idioms; this list is Solana-specific security and ops.
Many rules apply to both; native requires manual enforcement.
At least one happy path and one failure per instruction.
When profiling shows deserialize dominates CU.
Focus validation, arithmetic, CPI, and PDA signing first.
Still matters - clients and indexers depend on stable errors.
Yes - consistent layout helps reviewers.
Required for native; generate from Anchor IDL when possible.
cargo build-sbf on every PR.
Recommended for fast integration tests with Agave 4.1.1 behavior.
Version IDL and error tables with deployed program id.
Publish verifiable build hashes with deploy.
Stack versions: This page was written for Agave 4.1.1, Solana CLI 3.0.10, Anchor 0.32.1, anchor-lang 0.32.1, Rust 1.91.1, @solana/kit 7.0.0, Surfpool 0.12.0, and LiteSVM 0.6.x.
Reviewed by Chris St. John·Last updated Jul 16, 2026