2 ms·
You also have the problem of potentially having to re-verify everything by hand for every little change. Maybe fine for the kinds of projects Dijkstra was worki
by bunderbunder 20d ago
You also have the problem of potentially having to re-verify everything by hand for every little change. Maybe fine for the kinds of projects Dijkstra was working on, but less practical in a business setting.
Tools like QuickCheck and Hypothesis are an interesting middle ground, though. I strongly prefer them over standard-issue unit testing for verifying algorithm implementations.
- agentultra 20d agoHundred percent. All about trade-offs. Although proof techniques such as proof repair have come a long way, it’s still impractical for a lot of scenarios. TLA+ is great for systems design and such. Quick check style tests are awesome and a very low bar to clear from unit tests.
- bunderbunder 19d agoYeah. And TLA+ can confirm that the design is sound, but it can’t confirm that the implementation conforms to the design. QuickCheck style tests can’t solve that problem, but perhaps they can mitigate it.
- agentultra 18d agoI think it might be possible to write a TLA+ parser and generate QuickCheck tests from it that will exercise invariants at least.