Automatically checking an implementation against its formal specification

S. Antoy, D. Hamlet
2000 IEEE Transactions on Software Engineering  
We propose to check the execution of an abstract data type's imperative implementation against its algebraic specification. An explicit mapping from implementation states to abstract values is added to the imperative code. The form of specification allows mechanical checking of desirable properties such as consistency and completeness, particularly when operations are added incrementally to the data type. During unit testing, the specification serves as a test oracle. Any variance between
more » ... ed and specified values is automatically detected. When the module is made part of some application, the checking can be removed, or may remain in place for further validating the implementation. The specification, executed by rewriting, can be thought of as itself an implementation with maximum design diversity, and the validation as a form of multiversion-programming comparison.
doi:10.1109/32.825766 fatcat:qibvgj35ifdwnd2tywgeyuuidi