Skip to content

About

Verification of tulip

Resources

Stars

2 stars

Watchers

0 watching

Forks

Repository files navigation

Tulip's mechanized proof

CI

Program proofs for tulip, using Perennial (the "old" version, prior to new goose).

Building

To build run opam install --deps-only . and then dune build.

You can update the version of perennial used with go tool perennial-cli opam update.

Proof organization

Paths below are relative to src/program_proof/tulip/.

  • Action lemmas: invariance/ and paxos/invariance/. Some simple protocol updates are proved directly in program proofs.
  • Program specifications and proofs: program/ and paxos/program/.
  • Permissions and interaction rules: res*.v in the Tulip and Paxos proof roots.

PSM modules and invariants

The ten PSM module types (Section 5.1, Figure 13) map to the following definitions:

Module File Predicate
Transaction system inv_txnsys.v txnsys_inv
Key inv_key.v key_inv
Replica group inv_group.v group_inv
Replica inv_replica.v replica_inv
Tulip file inv.v replica_file_inv
Tulip network inv.v tulip_network_inv
Multi-Paxos proposers paxos/inv.v paxos_inv (excluding the per-acceptor node_inv)
Multi-Paxos acceptor paxos/inv.v node_inv
Multi-Paxos file paxos/inv.v node_file_inv
Multi-Paxos network paxos/inv.v paxos_network_inv

Other entry points

About

Verification of tulip

Resources

Stars

2 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages