Urgent.News

What's breaking now, across thousands of outlets.

Tech

What TLA+ can and can't check

TLA+ is a powerful tool for designing complex concurrent systems and verifying their properties. However, there are certain limitations to what TLA+ can check. First and foremost, if you cannot formalize your property as a logical formula, TLA+ cannot assist you in verifying it. Furthermore, TLA+ is limited in its ability to express properties that are not expressible as invariants, action properties, or liveness properties.

Safety properties can only express invariants or actions, but cannot define properties that span multiple steps or those over real-time or floating-point operations. Reachability properties, which express that a certain state is reachable at least once, are also impossible to express in TLA+. Hyperproperties, such as properties that hold for all behaviors or over a set of behaviors, are also beyond TLA+'s capabilities.

Finally, TLA+ cannot express metaproperties, such as the uniqueness of a path from one state to another. While some of these limitations might seem niche, they can cover important security properties and statistical properties that are essential for verifying complex systems.

Written by urgent.news from Lobsters's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

Read the original at buttondown.com →

More in Tech

More from Wednesday 30 September →