[DO NOT MERGE] Formal verification reference: TLA+/Lean models, defect catalogue and fix plans - #1549
Draft
joaodinissf wants to merge 3 commits into
Draft
joaodinissf wants to merge 3 commits into
joaodinissf wants to merge 3 commits into
Conversation
This was referenced Sep 25, 2026
joaodinissf
force-pushed
the
docs/formal-verification-reference
branch
from
September 26, 2026 00:19
37d19bd to
511e823
Compare
Blind models of the parallel resource loader, find-references batching, the binary-model storage executor, the qualified-name trie and the release pipeline, each in TLA+ and Lean 4, with fixed variants, ablations, planted bugs and witnesses. formal/check.sh re-runs every TLC matrix against its expected.txt, builds each Lean project, rejects sorry/admit and checks the axioms of every listed theorem. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Each @disabled method fails on master exactly as documented in formal/BUGS.md (LDR-1, REF-2, TRIE-1..15, RO-1) and passes with the corresponding reference fix; the fix PR enables it. Guard methods that pass on master stay enabled. xtext.test imports com.avaloq.tools.ddk.caching for CacheStatistics. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
formal/README.md describes the method, target status, models and how to reproduce. formal/BUGS.md catalogues 51 findings (49 confirmed, 1 plausible, 1 refuted) plus 9 observations, all verified by three independent skeptics, with traces, test status, fix plans, a proposed fix-PR sequence and links to the fix PRs opened so far (#1550, #1551, #1552, #1553). REPORT.md is the chronological log of rounds 1-2. The patches are reference fixes used to show each disabled test turns green. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
joaodinissf
force-pushed
the
docs/formal-verification-reference
branch
from
September 29, 2026 09:41
511e823 to
af49781
Compare
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Caution
Do not merge. This PR is a reference for the formal-verification campaign. Its fixes land as separate PRs.
Why the change
This keeps the formal models, the defect catalogue and the failing-first tests of the formal-verification campaign in one reviewable place, as the source for small, separate fix PRs.
Special things to note
formal/BUGS.md§5. So far fix(release): compute the next version from tags reachable from the branch #1550 (PIPE-2), fix(xtext): match case-sensitive pattern lookups against the candidate name #1551 (TRIE-1) and fix(xtext.ui): iterate a snapshot of the matches when showing a running search #1552 (REF-2) are merged; fix(builder): abandon the load operation when a resource load times out #1553 (LDR-1) is open.formal/check.shdoes not yet fail when a theorem depends on a forbidden axiom (BAD:), so--updatecan accept one. No current proof is affected.Change outline
Fix status:
🤖 Generated with Claude Code