Urgent.News

What's breaking now, across thousands of outlets.

Tech

Your spec is not brittle because it is strict — it is brittle in proportion to how much it names your internals

A specification is a predicate over behaviour, and the advice for writing one is uniform: make it stronger. Pin more of the observable behaviour, add another invariant, tighten the bound. It is good advice for a predicate that is written once and read once. Most predicates are not read once. They are maintained, and the same clause that rejects a defect rejects the legitimate change you make next…

A specification is a predicate over behaviour, and writing one involves making it stronger by adding more invariants and tightening the bounds. However, the problem lies in how much the specification names the internals of the system, as this directly affects its brittleness. The article examines two constructs: observational specificity (s) and representation exposure (r), which are computed from the specification's own text.

The former measures the share of observable behaviour that the specification pins, while the latter measures the share of clauses that mention internals. These constructs are measured independently on a small straight-line expression language over Z_256, with a program's meaning being its complete 256-point table. The study then measured how these constructs react to legitimate changes and defects in 262 references, 591 semantics-changing mutations, and 2160 semantics-preserving mutations.

The results show that the two channels have different arguments, with detection rising with specificity and breaking at zero exposure. Breakage, on the other hand, is zero at every grade of specificity and increases steeply as representation exposure increases. The optimal specification, according to the study, is the empty specification, as it rejects all semantics-changing mutations and does not falsely reject any legitimate changes.

The article concludes by emphasizing that the split in specification strength is a crucial factor in determining a specification's brittleness and should not be overlooked.

Written by urgent.news from Dev.to's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

Read the original at dev.to →

More in Tech

36 Tools, Zero Backend: The Real Cost of Running a Free PDF Site

Series: Building PdfWord — a free, no-backend PDF tools site (Part 15) "How much does it cost to run?" is the question I get most, usually followed by "...and how are you not losing money?" The answer…

  • PdfWord runs all tools in browser as HTML and JavaScript, eliminating backend costs
  • Static files on Cloudflare Pages and a free Pages tier support the site
  • Monetization plan includes AdSense revenue from backlinks and SEO content

WildNotes - Wonder that grows with you

This is a submission for the Hacktoberfest Open-Source AI Challenge Week 1: Touch Grass What I Built Most modern nature applications suffer from a quiet paradox: they claim to connect us with the…

  • WildNotes reconnects users with nature offline
  • Encourages sensory engagement with outdoor elements
  • Promotes mindfulness through deep breathing and contemplation

Why Cursor Decodes JWTs Instead of Verifying Them (CWE-347)

TL;DR AI editors regularly write auth middleware that calls jwt.decode() where it needs jwt.verify() , so the token's signature is never checked.

  • Cursor developers use jwt.decode() instead of jwt.verify() for authentication middleware.
  • Switching to jose library and verifying signatures resolves the CWE-347 vulnerability.

More from Saturday 10 October →