{
  "id": 10958032,
  "title": "What TLA+ can and can't check",
  "url": "https://urgent.news/2026/09/30/what-tla-can-and-cant-check",
  "topic": "tech",
  "section": "Tech",
  "published": "2026-09-30T14:02:33.000Z",
  "source": {
    "name": "Lobsters",
    "slug": "lobsters",
    "url": "https://buttondown.com/hillelwayne/archive/what-tla-can-and-cant-check/"
  },
  "original_language": "en",
  "account": "TLA+ is a powerful tool for designing complex concurrent systems and verifying their properties. However, there are certain limitations to what TLA+ can check. First and foremost, if you cannot formalize your property as a logical formula, TLA+ cannot assist you in verifying it. Furthermore, TLA+ is limited in its ability to express properties that are not expressible as invariants, action properties, or liveness properties. Safety properties can only express invariants or actions, but cannot define properties that span multiple steps or those over real-time or floating-point operations. Reachability properties, which express that a certain state is reachable at least once, are also impossible to express in TLA+. Hyperproperties, such as properties that hold for all behaviors or over a set of behaviors, are also beyond TLA+'s capabilities. Finally, TLA+ cannot express metaproperties, such as the uniqueness of a path from one state to another. While some of these limitations might seem niche, they can cover important security properties and statistical properties that are essential for verifying complex systems.",
  "summary": null,
  "key_points": [
    "TLA+ cannot verify properties not formalized as logical formulas",
    "Safety properties limited to invariants, actions, but not multi-step or real-time properties",
    "Hyperproperties and metaproperties beyond TLA+ capabilities"
  ],
  "editors_take": null,
  "illustration": null,
  "coverage": {
    "outlets": 1,
    "also_reported_by": []
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}