From network interface to multithreaded web applications: A case study in modular program verification
A Chlipala - ACM SIGPLAN Notices, 2015 - dl.acm.org
ACM SIGPLAN Notices, 2015•dl.acm.org
Many verifications of realistic software systems are monolithic, in the sense that they define
single global invariants over complete system state. More modular proof techniques promise
to support reuse of component proofs and even reduce the effort required to verify one
concrete system, just as modularity simplifies standard software development. This paper
reports on one case study applying modular proof techniques in the Coq proof assistant. To
our knowledge, it is the first modular verification certifying a system that combines …
single global invariants over complete system state. More modular proof techniques promise
to support reuse of component proofs and even reduce the effort required to verify one
concrete system, just as modularity simplifies standard software development. This paper
reports on one case study applying modular proof techniques in the Coq proof assistant. To
our knowledge, it is the first modular verification certifying a system that combines …
Many verifications of realistic software systems are monolithic, in the sense that they define single global invariants over complete system state. More modular proof techniques promise to support reuse of component proofs and even reduce the effort required to verify one concrete system, just as modularity simplifies standard software development. This paper reports on one case study applying modular proof techniques in the Coq proof assistant. To our knowledge, it is the first modular verification certifying a system that combines infrastructure with an application of interest to end users. We assume a nonblocking API for managing TCP networking streams, and on top of that we work our way up to certifying multithreaded, database-backed Web applications. Key verified components include a cooperative threading library and an implementation of a domain-specific language for XML processing. We have deployed our case-study system on mobile robots, where it interfaces with off-the-shelf components for sensing, actuation, and control.
ACM Digital Library