<< Chapter < Page Chapter >> Page >

Function calls are another standard kind of control flow. Surprisingly, Promela does not have function calls ! Every proctype instance is a separate process. Though if you really want, you could simulate a function call by creating a new process dynamically , and blocking until that process returns.

Verification

So far, we have determined the possible behaviors of a program simply by running the program abunch of times. For small programs, we can be very careful and make sure we exhibit all the possible traces, but the state spacesoon becomes unwieldy.

The real power of SPIN is as a tool for verification, our original goal.SPIN will search the entire state space for us , looking for (reachable) states which fail to have desired properties.

Assertions

The first verification technique we'll examine are assertion s, common to many programming languages. In Promela, the statement assert( condition ); evaluates the condition. If the result is true, execution continues as usual. Otherwise, the entire programis aborted and an error message is printed.

When simulating a single run of the program, SPIN automatically checks these run-time assertions;this is the usage that most programmers should be familiar with from traditional programming languages.But additionally, we'll see that SPIN, in the course of searching the entire state space,verifies whether an assertion can ever fail! (Though of course it can only search finite, feasible state spaces;happily,feasiblecan often include hundreds of millions of states.)

Consider our last race condition example . One of our original nave expectations was that, within each process,the value of z at the end of the process is exactly one more than at the beginning.The previous examples have shown that to be wrong, but we had to run the program until we encountered a run when it failed.Here, the assert statement puts that expectation explicitly into the program, for SPIN to check. 1 #define NUM_PROCS 3 23 show int z = 0; 45 active[NUM_PROCS] proctype increment()6 { 7 show int new_z;8 9 /* A saved copy of the old z, for the assertion. */10 show int old_z; 1112 old_z = z; 13 new_z = old_z + 1;14 z = new_z; 1516 assert(z == old_z+1); 17 }

It is often the case, as it is here, that to state the desired condition we need to add an extra variablehere, old_z . As always, it is important that when introducing such code fortesting that you don't substantially change the code to be tested, lest you inadvertently introduce new bugs!

Run this code several times, and observe when the assertion fails.This text indicates which assertion failed, and the line will be highlighted in the code window. To see which process' copy of increment failed and why, you have to look more closely at the steps shown. spin: line 16 "pan_in", Error: assertion violated spin: text of failed assertion: assert((z==(old_z+1)))

Questions & Answers

A golfer on a fairway is 70 m away from the green, which sits below the level of the fairway by 20 m. If the golfer hits the ball at an angle of 40° with an initial speed of 20 m/s, how close to the green does she come?
Aislinn Reply
cm
tijani
what is titration
John Reply
what is physics
Siyaka Reply
A mouse of mass 200 g falls 100 m down a vertical mine shaft and lands at the bottom with a speed of 8.0 m/s. During its fall, how much work is done on the mouse by air resistance
Jude Reply
Can you compute that for me. Ty
Jude
what is the dimension formula of energy?
David Reply
what is viscosity?
David
what is inorganic
emma Reply
what is chemistry
Youesf Reply
what is inorganic
emma
Chemistry is a branch of science that deals with the study of matter,it composition,it structure and the changes it undergoes
Adjei
please, I'm a physics student and I need help in physics
Adjanou
chemistry could also be understood like the sexual attraction/repulsion of the male and female elements. the reaction varies depending on the energy differences of each given gender. + masculine -female.
Pedro
A ball is thrown straight up.it passes a 2.0m high window 7.50 m off the ground on it path up and takes 1.30 s to go past the window.what was the ball initial velocity
Krampah Reply
2. A sled plus passenger with total mass 50 kg is pulled 20 m across the snow (0.20) at constant velocity by a force directed 25° above the horizontal. Calculate (a) the work of the applied force, (b) the work of friction, and (c) the total work.
Sahid Reply
you have been hired as an espert witness in a court case involving an automobile accident. the accident involved car A of mass 1500kg which crashed into stationary car B of mass 1100kg. the driver of car A applied his brakes 15 m before he skidded and crashed into car B. after the collision, car A s
Samuel Reply
can someone explain to me, an ignorant high school student, why the trend of the graph doesn't follow the fact that the higher frequency a sound wave is, the more power it is, hence, making me think the phons output would follow this general trend?
Joseph Reply
Nevermind i just realied that the graph is the phons output for a person with normal hearing and not just the phons output of the sound waves power, I should read the entire thing next time
Joseph
Follow up question, does anyone know where I can find a graph that accuretly depicts the actual relative "power" output of sound over its frequency instead of just humans hearing
Joseph
"Generation of electrical energy from sound energy | IEEE Conference Publication | IEEE Xplore" ***ieeexplore.ieee.org/document/7150687?reload=true
Ryan
what's motion
Maurice Reply
what are the types of wave
Maurice
answer
Magreth
progressive wave
Magreth
hello friend how are you
Muhammad Reply
fine, how about you?
Mohammed
hi
Mujahid
A string is 3.00 m long with a mass of 5.00 g. The string is held taut with a tension of 500.00 N applied to the string. A pulse is sent down the string. How long does it take the pulse to travel the 3.00 m of the string?
yasuo Reply
Who can show me the full solution in this problem?
Reofrir Reply
Got questions? Join the online conversation and get instant answers!
Jobilize.com Reply

Get Jobilize Job Search Mobile App in your pocket Now!

Get it on Google Play Download on the App Store Now




Source:  OpenStax, Model checking concurrent programs. OpenStax CNX. Oct 27, 2005 Download for free at http://cnx.org/content/col10294/1.3
Google Play and the Google Play logo are trademarks of Google Inc.

Notification Switch

Would you like to follow the 'Model checking concurrent programs' conversation and receive update notifications?

Ask