thinking above the code - microsoft.comhunting a sabre-toothed tiger. building a house. writing a...

391
Thinking Above the Code Leslie Lamport Microsoft Research 0

Upload: others

Post on 25-May-2020

1 views

Category:

Documents


0 download

TRANSCRIPT

Page 1: Thinking Above the Code - microsoft.comHunting a sabre-toothed tiger. Building a house. Writing a program. 0. Why Think? It helps us do most things: Hunting a sabre-toothed tiger

Thinking Above the Code

Leslie LamportMicrosoft Research

0

Page 2: Thinking Above the Code - microsoft.comHunting a sabre-toothed tiger. Building a house. Writing a program. 0. Why Think? It helps us do most things: Hunting a sabre-toothed tiger

Why Think?

It helps us do most things:

Hunting a sabre-toothed tiger.

Building a house.

Writing a program.

0

Page 3: Thinking Above the Code - microsoft.comHunting a sabre-toothed tiger. Building a house. Writing a program. 0. Why Think? It helps us do most things: Hunting a sabre-toothed tiger

Why Think?

It helps us do most things:

Hunting a sabre-toothed tiger.

Building a house.

Writing a program.

0

Page 4: Thinking Above the Code - microsoft.comHunting a sabre-toothed tiger. Building a house. Writing a program. 0. Why Think? It helps us do most things: Hunting a sabre-toothed tiger

Why Think?

It helps us do most things:

Hunting a sabre-toothed tiger.

Building a house.

Writing a program.

0

Page 5: Thinking Above the Code - microsoft.comHunting a sabre-toothed tiger. Building a house. Writing a program. 0. Why Think? It helps us do most things: Hunting a sabre-toothed tiger

Why Think?

It helps us do most things:

Hunting a sabre-toothed tiger.

Building a house.

Writing a program.

0

Page 6: Thinking Above the Code - microsoft.comHunting a sabre-toothed tiger. Building a house. Writing a program. 0. Why Think? It helps us do most things: Hunting a sabre-toothed tiger

Why Think?

It helps us do most things:

Hunting a sabre-toothed tiger.

Building a house.

Writing a program.

0

Page 7: Thinking Above the Code - microsoft.comHunting a sabre-toothed tiger. Building a house. Writing a program. 0. Why Think? It helps us do most things: Hunting a sabre-toothed tiger

When to Think

Hunting a sabre-toothed tiger.

Before leaving the cave.

Building a house.

Before beginning construction.

Writing a program.

Before writing any code.

1

Page 8: Thinking Above the Code - microsoft.comHunting a sabre-toothed tiger. Building a house. Writing a program. 0. Why Think? It helps us do most things: Hunting a sabre-toothed tiger

When to Think

Hunting a sabre-toothed tiger.

Before leaving the cave.

Building a house.

Before beginning construction.

Writing a program.

Before writing any code.

1

Page 9: Thinking Above the Code - microsoft.comHunting a sabre-toothed tiger. Building a house. Writing a program. 0. Why Think? It helps us do most things: Hunting a sabre-toothed tiger

When to Think

Hunting a sabre-toothed tiger.

Before leaving the cave.

Building a house.

Before beginning construction.

Writing a program.

Before writing any code.

1

Page 10: Thinking Above the Code - microsoft.comHunting a sabre-toothed tiger. Building a house. Writing a program. 0. Why Think? It helps us do most things: Hunting a sabre-toothed tiger

When to Think

Hunting a sabre-toothed tiger.

Before leaving the cave.

Building a house.

Before beginning construction.

Writing a program.

Before writing any code.

1

Page 11: Thinking Above the Code - microsoft.comHunting a sabre-toothed tiger. Building a house. Writing a program. 0. Why Think? It helps us do most things: Hunting a sabre-toothed tiger

When to Think

Hunting a sabre-toothed tiger.

Before leaving the cave.

Building a house.

Before beginning construction.

Writing a program.

Before writing any code.

1

Page 12: Thinking Above the Code - microsoft.comHunting a sabre-toothed tiger. Building a house. Writing a program. 0. Why Think? It helps us do most things: Hunting a sabre-toothed tiger

When to Think

Hunting a sabre-toothed tiger.

Before leaving the cave.

Building a house.

Before beginning construction.

Writing a program.

Before writing any code.

1

Page 13: Thinking Above the Code - microsoft.comHunting a sabre-toothed tiger. Building a house. Writing a program. 0. Why Think? It helps us do most things: Hunting a sabre-toothed tiger

When to Think

Hunting a sabre-toothed tiger.

Before leaving the cave.

Building a house.

Before beginning construction.

Writing a program.

Before writing any code.

1

Page 14: Thinking Above the Code - microsoft.comHunting a sabre-toothed tiger. Building a house. Writing a program. 0. Why Think? It helps us do most things: Hunting a sabre-toothed tiger

How to Think

“Writing is nature’s way of letting you know howsloppy your thinking is.”

Guindon

To think, you have to write.

If you’re thinking without writing, you only think you’re thinking.

1

Page 15: Thinking Above the Code - microsoft.comHunting a sabre-toothed tiger. Building a house. Writing a program. 0. Why Think? It helps us do most things: Hunting a sabre-toothed tiger

How to Think

“Writing is nature’s way of letting you know howsloppy your thinking is.”

Guindon

To think, you have to write.

If you’re thinking without writing, you only think you’re thinking.

1

Page 16: Thinking Above the Code - microsoft.comHunting a sabre-toothed tiger. Building a house. Writing a program. 0. Why Think? It helps us do most things: Hunting a sabre-toothed tiger

How to Think

“Writing is nature’s way of letting you know howsloppy your thinking is.”

Guindon

To think, you have to write.

If you’re thinking without writing, you only think you’re thinking.

1

Page 17: Thinking Above the Code - microsoft.comHunting a sabre-toothed tiger. Building a house. Writing a program. 0. Why Think? It helps us do most things: Hunting a sabre-toothed tiger

How to Think

“Writing is nature’s way of letting you know howsloppy your thinking is.”

Guindon

To think, you have to write.

If you’re thinking without writing, you only think you’re thinking.

1

Page 18: Thinking Above the Code - microsoft.comHunting a sabre-toothed tiger. Building a house. Writing a program. 0. Why Think? It helps us do most things: Hunting a sabre-toothed tiger

What to Write

Hunting a sabre-toothed tiger.

Writing not invented, dangerous activity.

Building a house.

Draw blueprints.

Writing a program.

Write a

2

Page 19: Thinking Above the Code - microsoft.comHunting a sabre-toothed tiger. Building a house. Writing a program. 0. Why Think? It helps us do most things: Hunting a sabre-toothed tiger

What to Write

Hunting a sabre-toothed tiger.

Writing not invented, dangerous activity.

Building a house.

Draw blueprints.

Writing a program.

Write a

2

Page 20: Thinking Above the Code - microsoft.comHunting a sabre-toothed tiger. Building a house. Writing a program. 0. Why Think? It helps us do most things: Hunting a sabre-toothed tiger

What to Write

Hunting a sabre-toothed tiger.

Writing not invented, dangerous activity.

Building a house.

Draw blueprints.

Writing a program.

Write a

2

Page 21: Thinking Above the Code - microsoft.comHunting a sabre-toothed tiger. Building a house. Writing a program. 0. Why Think? It helps us do most things: Hunting a sabre-toothed tiger

What to Write

Hunting a sabre-toothed tiger.

Writing not invented, dangerous activity.

Building a house.

Draw blueprints.

Writing a program.

Write a

2

Page 22: Thinking Above the Code - microsoft.comHunting a sabre-toothed tiger. Building a house. Writing a program. 0. Why Think? It helps us do most things: Hunting a sabre-toothed tiger

What to Write

Hunting a sabre-toothed tiger.

Writing not invented, dangerous activity.

Building a house.

Draw blueprints.

Writing a program.

Write a

2

Page 23: Thinking Above the Code - microsoft.comHunting a sabre-toothed tiger. Building a house. Writing a program. 0. Why Think? It helps us do most things: Hunting a sabre-toothed tiger

What to Write

Hunting a sabre-toothed tiger.

Writing not invented, dangerous activity.

Building a house.

Draw blueprints.

Writing a program.

Write a

2

Page 24: Thinking Above the Code - microsoft.comHunting a sabre-toothed tiger. Building a house. Writing a program. 0. Why Think? It helps us do most things: Hunting a sabre-toothed tiger

What to Write

Hunting a sabre-toothed tiger.

Writing not invented, dangerous activity.

Building a house.

Draw blueprints.

Writing a program.

Write a blueprint

2

Page 25: Thinking Above the Code - microsoft.comHunting a sabre-toothed tiger. Building a house. Writing a program. 0. Why Think? It helps us do most things: Hunting a sabre-toothed tiger

What to Write

Hunting a sabre-toothed tiger.

Writing not invented, dangerous activity.

Building a house.

Draw blueprints.

Writing a program.

Write a blueprint specification.

2

Page 26: Thinking Above the Code - microsoft.comHunting a sabre-toothed tiger. Building a house. Writing a program. 0. Why Think? It helps us do most things: Hunting a sabre-toothed tiger

Specifications

Don’t Panic!

3

Page 27: Thinking Above the Code - microsoft.comHunting a sabre-toothed tiger. Building a house. Writing a program. 0. Why Think? It helps us do most things: Hunting a sabre-toothed tiger

Specifications

Don’t Panic!

3

Page 28: Thinking Above the Code - microsoft.comHunting a sabre-toothed tiger. Building a house. Writing a program. 0. Why Think? It helps us do most things: Hunting a sabre-toothed tiger

Specifications

Don’t Panic!

This is a blueprint:

3

Page 29: Thinking Above the Code - microsoft.comHunting a sabre-toothed tiger. Building a house. Writing a program. 0. Why Think? It helps us do most things: Hunting a sabre-toothed tiger

Specifications

Don’t Panic!

This is also a blueprint:

3

Page 30: Thinking Above the Code - microsoft.comHunting a sabre-toothed tiger. Building a house. Writing a program. 0. Why Think? It helps us do most things: Hunting a sabre-toothed tiger

A spectrum of blueprints

3

Page 31: Thinking Above the Code - microsoft.comHunting a sabre-toothed tiger. Building a house. Writing a program. 0. Why Think? It helps us do most things: Hunting a sabre-toothed tiger

A spectrum of blueprints

3

Page 32: Thinking Above the Code - microsoft.comHunting a sabre-toothed tiger. Building a house. Writing a program. 0. Why Think? It helps us do most things: Hunting a sabre-toothed tiger

A spectrum of blueprints

Very Detailed

3

Page 33: Thinking Above the Code - microsoft.comHunting a sabre-toothed tiger. Building a house. Writing a program. 0. Why Think? It helps us do most things: Hunting a sabre-toothed tiger

A spectrum of blueprints

Very Detailed

3

Page 34: Thinking Above the Code - microsoft.comHunting a sabre-toothed tiger. Building a house. Writing a program. 0. Why Think? It helps us do most things: Hunting a sabre-toothed tiger

A spectrum of blueprints

Very DetailedRough Sketch

3

Page 35: Thinking Above the Code - microsoft.comHunting a sabre-toothed tiger. Building a house. Writing a program. 0. Why Think? It helps us do most things: Hunting a sabre-toothed tiger

A spectrum of blueprints

Very DetailedRough Sketch

3

Page 36: Thinking Above the Code - microsoft.comHunting a sabre-toothed tiger. Building a house. Writing a program. 0. Why Think? It helps us do most things: Hunting a sabre-toothed tiger

A spectrum of blueprints

Very DetailedRough Sketch Ordinary

3

Page 37: Thinking Above the Code - microsoft.comHunting a sabre-toothed tiger. Building a house. Writing a program. 0. Why Think? It helps us do most things: Hunting a sabre-toothed tiger

A spectrum of specifications

5

Page 38: Thinking Above the Code - microsoft.comHunting a sabre-toothed tiger. Building a house. Writing a program. 0. Why Think? It helps us do most things: Hunting a sabre-toothed tiger

A spectrum of specifications

Formal

5

Page 39: Thinking Above the Code - microsoft.comHunting a sabre-toothed tiger. Building a house. Writing a program. 0. Why Think? It helps us do most things: Hunting a sabre-toothed tiger

A spectrum of specifications

FormalProse

5

Page 40: Thinking Above the Code - microsoft.comHunting a sabre-toothed tiger. Building a house. Writing a program. 0. Why Think? It helps us do most things: Hunting a sabre-toothed tiger

A spectrum of specifications

FormalProse Mathematical Prose

5

Page 41: Thinking Above the Code - microsoft.comHunting a sabre-toothed tiger. Building a house. Writing a program. 0. Why Think? It helps us do most things: Hunting a sabre-toothed tiger

A spectrum of specifications

Prose

Most code is really simple.

It can be specified with a couple of lines of prose.

5

Page 42: Thinking Above the Code - microsoft.comHunting a sabre-toothed tiger. Building a house. Writing a program. 0. Why Think? It helps us do most things: Hunting a sabre-toothed tiger

A spectrum of specifications

Prose

Most code is really simple.

It can be specified with a couple of lines of prose.

5

Page 43: Thinking Above the Code - microsoft.comHunting a sabre-toothed tiger. Building a house. Writing a program. 0. Why Think? It helps us do most things: Hunting a sabre-toothed tiger

A spectrum of specifications

Mathematical Prose

Some code is subtle.

It requires more thought.

5

Page 44: Thinking Above the Code - microsoft.comHunting a sabre-toothed tiger. Building a house. Writing a program. 0. Why Think? It helps us do most things: Hunting a sabre-toothed tiger

A spectrum of specifications

Mathematical Prose

Some code is subtle.

It requires more thought.

5

Page 45: Thinking Above the Code - microsoft.comHunting a sabre-toothed tiger. Building a house. Writing a program. 0. Why Think? It helps us do most things: Hunting a sabre-toothed tiger

A spectrum of specifications

Formal

Some code is complex or very subtle or critical.

5

Page 46: Thinking Above the Code - microsoft.comHunting a sabre-toothed tiger. Building a house. Writing a program. 0. Why Think? It helps us do most things: Hunting a sabre-toothed tiger

A spectrum of specifications

Formal

Some code is complex or very subtle or critical.

Especially in concurrent/distributed systems.

5

Page 47: Thinking Above the Code - microsoft.comHunting a sabre-toothed tiger. Building a house. Writing a program. 0. Why Think? It helps us do most things: Hunting a sabre-toothed tiger

A spectrum of specifications

Formal

Some code is complex or very subtle or critical.

We should use tools to check it.

5

Page 48: Thinking Above the Code - microsoft.comHunting a sabre-toothed tiger. Building a house. Writing a program. 0. Why Think? It helps us do most things: Hunting a sabre-toothed tiger

How to Write a Spec

Writing requires thinking.

5

Page 49: Thinking Above the Code - microsoft.comHunting a sabre-toothed tiger. Building a house. Writing a program. 0. Why Think? It helps us do most things: Hunting a sabre-toothed tiger

How to Write a Spec

Writing requires thinking.

5

Page 50: Thinking Above the Code - microsoft.comHunting a sabre-toothed tiger. Building a house. Writing a program. 0. Why Think? It helps us do most things: Hunting a sabre-toothed tiger

How to Think About Programs

Like a Scientist

A very successful way of thinking.

Science makes mathematical models of reality.

Astronomy:

Reality: planets have mountains, oceans, tides, weather, . . .

Model: planet a point mass with position & momentum.

6

Page 51: Thinking Above the Code - microsoft.comHunting a sabre-toothed tiger. Building a house. Writing a program. 0. Why Think? It helps us do most things: Hunting a sabre-toothed tiger

How to Think About Programs

Like a Scientist

A very successful way of thinking.

Science makes mathematical models of reality.

Astronomy:

Reality: planets have mountains, oceans, tides, weather, . . .

Model: planet a point mass with position & momentum.

6

Page 52: Thinking Above the Code - microsoft.comHunting a sabre-toothed tiger. Building a house. Writing a program. 0. Why Think? It helps us do most things: Hunting a sabre-toothed tiger

How to Think About Programs

Like a Scientist

A very successful way of thinking.

Science makes mathematical models of reality.

Astronomy:

Reality: planets have mountains, oceans, tides, weather, . . .

Model: planet a point mass with position & momentum.

6

Page 53: Thinking Above the Code - microsoft.comHunting a sabre-toothed tiger. Building a house. Writing a program. 0. Why Think? It helps us do most things: Hunting a sabre-toothed tiger

How to Think About Programs

Like a Scientist

A very successful way of thinking.

Science makes mathematical models of reality.

Astronomy:

Reality: planets have mountains, oceans, tides, weather, . . .

Model: planet a point mass with position & momentum.

6

Page 54: Thinking Above the Code - microsoft.comHunting a sabre-toothed tiger. Building a house. Writing a program. 0. Why Think? It helps us do most things: Hunting a sabre-toothed tiger

How to Think About Programs

Like a Scientist

A very successful way of thinking.

Science makes mathematical models of reality.

Astronomy:

Reality: planets have mountains, oceans, tides, weather, . . .

Model: planet a point mass with position & momentum.

6

Page 55: Thinking Above the Code - microsoft.comHunting a sabre-toothed tiger. Building a house. Writing a program. 0. Why Think? It helps us do most things: Hunting a sabre-toothed tiger

How to Think About Programs

Like a Scientist

A very successful way of thinking.

Science makes mathematical models of reality.

Astronomy:

Reality: planets have mountains, oceans, tides, weather, . . .

Model: planet a point mass with position & momentum.

6

Page 56: Thinking Above the Code - microsoft.comHunting a sabre-toothed tiger. Building a house. Writing a program. 0. Why Think? It helps us do most things: Hunting a sabre-toothed tiger

How to Think About Programs

Like a Scientist

A very successful way of thinking.

Science makes mathematical models of reality.

Astronomy:

Reality: planets have mountains, oceans, tides, weather, . . .

Model: planet a point mass with position & momentum.

6

Page 57: Thinking Above the Code - microsoft.comHunting a sabre-toothed tiger. Building a house. Writing a program. 0. Why Think? It helps us do most things: Hunting a sabre-toothed tiger

Computer Science

Reality: Digital systems

a processor chip

a game console

a computer executing a program...

Models: Turing machines

Partially ordered sets of events...

6

Page 58: Thinking Above the Code - microsoft.comHunting a sabre-toothed tiger. Building a house. Writing a program. 0. Why Think? It helps us do most things: Hunting a sabre-toothed tiger

Computer Science

Reality: Digital systems

a processor chip

a game console

a computer executing a program...

Models: Turing machines

Partially ordered sets of events...

6

Page 59: Thinking Above the Code - microsoft.comHunting a sabre-toothed tiger. Building a house. Writing a program. 0. Why Think? It helps us do most things: Hunting a sabre-toothed tiger

Computer Science

Reality: Digital systems

a processor chip

a game console

a computer executing a program...

Models: Turing machines

Partially ordered sets of events...

6

Page 60: Thinking Above the Code - microsoft.comHunting a sabre-toothed tiger. Building a house. Writing a program. 0. Why Think? It helps us do most things: Hunting a sabre-toothed tiger

Computer Science

Reality: Digital systems

a processor chip

a game console

a computer executing a program...

Models: Turing machines

Partially ordered sets of events...

6

Page 61: Thinking Above the Code - microsoft.comHunting a sabre-toothed tiger. Building a house. Writing a program. 0. Why Think? It helps us do most things: Hunting a sabre-toothed tiger

Computer Science

Reality: Digital systems

a processor chip

a game console

a computer executing a program...

Models: Turing machines

Partially ordered sets of events...

6

Page 62: Thinking Above the Code - microsoft.comHunting a sabre-toothed tiger. Building a house. Writing a program. 0. Why Think? It helps us do most things: Hunting a sabre-toothed tiger

Computer Science

Reality: Digital systems

a processor chip

a game console

a computer executing a program...

Models: Turing machines

Partially ordered sets of events...

6

Page 63: Thinking Above the Code - microsoft.comHunting a sabre-toothed tiger. Building a house. Writing a program. 0. Why Think? It helps us do most things: Hunting a sabre-toothed tiger

Computer Science

Reality: Digital systems

a processor chip

a game console

a computer executing a program...

Models: Turing machines

Partially ordered sets of events...

6

Page 64: Thinking Above the Code - microsoft.comHunting a sabre-toothed tiger. Building a house. Writing a program. 0. Why Think? It helps us do most things: Hunting a sabre-toothed tiger

Computer Science

Reality: Digital systems

a processor chip

a game console

a computer executing a program...

Models: Turing machines

Partially ordered sets of events...

6

Page 65: Thinking Above the Code - microsoft.comHunting a sabre-toothed tiger. Building a house. Writing a program. 0. Why Think? It helps us do most things: Hunting a sabre-toothed tiger

Computer Science

Reality: Digital systems

a processor chip

a game console

a computer executing a program...

Models: Turing machines

Partially ordered sets of events...

6

Page 66: Thinking Above the Code - microsoft.comHunting a sabre-toothed tiger. Building a house. Writing a program. 0. Why Think? It helps us do most things: Hunting a sabre-toothed tiger

Computer Science

Reality: Digital systems

a processor chip

a game console

a computer executing a program...

Models: Turing machines

Partially ordered sets of events...

6

Page 67: Thinking Above the Code - microsoft.comHunting a sabre-toothed tiger. Building a house. Writing a program. 0. Why Think? It helps us do most things: Hunting a sabre-toothed tiger

The Two Most Useful Models

Functions

Sequences of States

7

Page 68: Thinking Above the Code - microsoft.comHunting a sabre-toothed tiger. Building a house. Writing a program. 0. Why Think? It helps us do most things: Hunting a sabre-toothed tiger

The Two Most Useful Models

Functions

Sequences of States

7

Page 69: Thinking Above the Code - microsoft.comHunting a sabre-toothed tiger. Building a house. Writing a program. 0. Why Think? It helps us do most things: Hunting a sabre-toothed tiger

The Two Most Useful Models

Functions

Sequences of States

7

Page 70: Thinking Above the Code - microsoft.comHunting a sabre-toothed tiger. Building a house. Writing a program. 0. Why Think? It helps us do most things: Hunting a sabre-toothed tiger

Functions

Model a program as a function mapping input(s) to output(s).

In math, a function is a set of ordered pairs.

Example: the square function on natural numbers

{〈0,0〉, 〈1,1〉, 〈2,4〉, 〈3,9〉, . . . }

8

Page 71: Thinking Above the Code - microsoft.comHunting a sabre-toothed tiger. Building a house. Writing a program. 0. Why Think? It helps us do most things: Hunting a sabre-toothed tiger

Functions

Model a program as a function mapping input(s) to output(s).

In math, a function is a set of ordered pairs.

Example: the square function on natural numbers

{〈0,0〉, 〈1,1〉, 〈2,4〉, 〈3,9〉, . . . }

8

Page 72: Thinking Above the Code - microsoft.comHunting a sabre-toothed tiger. Building a house. Writing a program. 0. Why Think? It helps us do most things: Hunting a sabre-toothed tiger

Functions

Model a program as a function mapping input(s) to output(s).

In math, a function is a set of ordered pairs.

Example: the square function on natural numbers

{〈0,0〉, 〈1,1〉, 〈2,4〉, 〈3,9〉, . . . }

8

Page 73: Thinking Above the Code - microsoft.comHunting a sabre-toothed tiger. Building a house. Writing a program. 0. Why Think? It helps us do most things: Hunting a sabre-toothed tiger

Functions

Model a program as a function mapping input(s) to output(s).

In math, a function is a set of ordered pairs.

Example: the square function on natural numbers

{〈0,0〉, 〈1,1〉, 〈2,4〉, 〈3,9〉, . . . }

8

Page 74: Thinking Above the Code - microsoft.comHunting a sabre-toothed tiger. Building a house. Writing a program. 0. Why Think? It helps us do most things: Hunting a sabre-toothed tiger

Functions

Model a program as a function mapping input(s) to output(s).

In math, a function is a set of ordered pairs.

Example: the square function on natural numbers

{〈0,0〉, 〈1,1〉, 〈2,4〉, 〈3,9〉, . . . }

8

Page 75: Thinking Above the Code - microsoft.comHunting a sabre-toothed tiger. Building a house. Writing a program. 0. Why Think? It helps us do most things: Hunting a sabre-toothed tiger

Functions

Model a program as a function mapping input(s) to output(s).

In math, a function is a set of ordered pairs.

Example: the square function on natural numbers

{〈0,0〉, 〈1,1〉, 〈2,4〉, 〈3,9〉, . . . }

square(2) = 4

8

Page 76: Thinking Above the Code - microsoft.comHunting a sabre-toothed tiger. Building a house. Writing a program. 0. Why Think? It helps us do most things: Hunting a sabre-toothed tiger

Functions

Model a program as a function mapping input(s) to output(s).

In math, a function is a set of ordered pairs.

Example: the square function on natural numbers

{〈0,0〉, 〈1,1〉, 〈2,4〉, 〈3,9〉, . . . }

Domain of square is {0,1,2,3, . . .} a.k.a. Nat

8

Page 77: Thinking Above the Code - microsoft.comHunting a sabre-toothed tiger. Building a house. Writing a program. 0. Why Think? It helps us do most things: Hunting a sabre-toothed tiger

Functions

Model a program as a function mapping input(s) to output(s).

In math, a function is a set of ordered pairs.

Example: the square function on natural numbers

{〈0,0〉, 〈1,1〉, 〈2,4〉, 〈3,9〉, . . . }

To define a function, specify:

Domain of square = Nat

square(x ) = x2 for all x in its domain.

8

Page 78: Thinking Above the Code - microsoft.comHunting a sabre-toothed tiger. Building a house. Writing a program. 0. Why Think? It helps us do most things: Hunting a sabre-toothed tiger

Functions

Model a program as a function mapping input(s) to output(s).

In math, a function is a set of ordered pairs.

Example: the square function on natural numbers

{〈0,0〉, 〈1,1〉, 〈2,4〉, 〈3,9〉, . . . }

To define a function, specify:

Domain of square = Nat

square(x ) = x2 for all x in its domain.

8

Page 79: Thinking Above the Code - microsoft.comHunting a sabre-toothed tiger. Building a house. Writing a program. 0. Why Think? It helps us do most things: Hunting a sabre-toothed tiger

Functions

Model a program as a function mapping input(s) to output(s).

In math, a function is a set of ordered pairs.

Example: the square function on natural numbers

{〈0,0〉, 〈1,1〉, 〈2,4〉, 〈3,9〉, . . . }

Functions in math 6= functions in programming languages.

8

Page 80: Thinking Above the Code - microsoft.comHunting a sabre-toothed tiger. Building a house. Writing a program. 0. Why Think? It helps us do most things: Hunting a sabre-toothed tiger

Functions

Model a program as a function mapping input(s) to output(s).

In math, a function is a set of ordered pairs.

Example: the square function on natural numbers

{〈0,0〉, 〈1,1〉, 〈2,4〉, 〈3,9〉, . . . }

Functions in math 6= functions in programming languages.

Math is much simpler.

8

Page 81: Thinking Above the Code - microsoft.comHunting a sabre-toothed tiger. Building a house. Writing a program. 0. Why Think? It helps us do most things: Hunting a sabre-toothed tiger

Limitations of the Function Model

Specifies what a program does, but not how.

– Quicksort and bubble sort compute the same function.

Some programs don’t just map inputs to outputs.

– Some programs run “forever”.

– Operating systems

9

Page 82: Thinking Above the Code - microsoft.comHunting a sabre-toothed tiger. Building a house. Writing a program. 0. Why Think? It helps us do most things: Hunting a sabre-toothed tiger

Limitations of the Function Model

Specifies what a program does, but not how.

– Quicksort and bubble sort compute the same function.

Some programs don’t just map inputs to outputs.

– Some programs run “forever”.

– Operating systems

9

Page 83: Thinking Above the Code - microsoft.comHunting a sabre-toothed tiger. Building a house. Writing a program. 0. Why Think? It helps us do most things: Hunting a sabre-toothed tiger

Limitations of the Function Model

Specifies what a program does, but not how.

– Quicksort and bubble sort compute the same function.

Some programs don’t just map inputs to outputs.

– Some programs run “forever”.

– Operating systems

9

Page 84: Thinking Above the Code - microsoft.comHunting a sabre-toothed tiger. Building a house. Writing a program. 0. Why Think? It helps us do most things: Hunting a sabre-toothed tiger

Limitations of the Function Model

Specifies what a program does, but not how.

– Quicksort and bubble sort compute the same function.

Some programs don’t just map inputs to outputs.

– Some programs run “forever”.

– Operating systems

9

Page 85: Thinking Above the Code - microsoft.comHunting a sabre-toothed tiger. Building a house. Writing a program. 0. Why Think? It helps us do most things: Hunting a sabre-toothed tiger

Limitations of the Function Model

Specifies what a program does, but not how.

– Quicksort and bubble sort compute the same function.

Some programs don’t just map inputs to outputs.

– Some programs run “forever”.

– Operating systems

9

Page 86: Thinking Above the Code - microsoft.comHunting a sabre-toothed tiger. Building a house. Writing a program. 0. Why Think? It helps us do most things: Hunting a sabre-toothed tiger

Limitations of the Function Model

Specifies what a program does, but not how.

– Quicksort and bubble sort compute the same function.

Some programs don’t just map inputs to outputs.

– Some programs run “forever”.

– Operating systems

9

Page 87: Thinking Above the Code - microsoft.comHunting a sabre-toothed tiger. Building a house. Writing a program. 0. Why Think? It helps us do most things: Hunting a sabre-toothed tiger

The Standard Behavioral Model

A program execution is represented by a behavior.

A behavior is a sequence of states.

A state is an assignment of values to variables.

A program is modeled by a set of behaviors:

the behaviors representing possible executions.

9

Page 88: Thinking Above the Code - microsoft.comHunting a sabre-toothed tiger. Building a house. Writing a program. 0. Why Think? It helps us do most things: Hunting a sabre-toothed tiger

The Standard Behavioral Model

A program execution is represented by a behavior.

A behavior is a sequence of states.

A state is an assignment of values to variables.

A program is modeled by a set of behaviors:

the behaviors representing possible executions.

9

Page 89: Thinking Above the Code - microsoft.comHunting a sabre-toothed tiger. Building a house. Writing a program. 0. Why Think? It helps us do most things: Hunting a sabre-toothed tiger

The Standard Behavioral Model

A program execution is represented by a behavior.

A behavior is a sequence of states.

A state is an assignment of values to variables.

A program is modeled by a set of behaviors:

the behaviors representing possible executions.

9

Page 90: Thinking Above the Code - microsoft.comHunting a sabre-toothed tiger. Building a house. Writing a program. 0. Why Think? It helps us do most things: Hunting a sabre-toothed tiger

The Standard Behavioral Model

A program execution is represented by a behavior.

A behavior is a sequence of states.

A state is an assignment of values to variables.

A program is modeled by a set of behaviors:

the behaviors representing possible executions.

9

Page 91: Thinking Above the Code - microsoft.comHunting a sabre-toothed tiger. Building a house. Writing a program. 0. Why Think? It helps us do most things: Hunting a sabre-toothed tiger

The Standard Behavioral Model

A program execution is represented by a behavior.

A behavior is a sequence of states.

A state is an assignment of values to variables.

A program is modeled by a set of behaviors:

the behaviors representing possible executions.

9

Page 92: Thinking Above the Code - microsoft.comHunting a sabre-toothed tiger. Building a house. Writing a program. 0. Why Think? It helps us do most things: Hunting a sabre-toothed tiger

The Standard Behavioral Model

A program execution is represented by a behavior.

A behavior is a sequence of states.

A state is an assignment of values to variables.

A program is modeled by a set of behaviors:

the behaviors representing possible executions.

9

Page 93: Thinking Above the Code - microsoft.comHunting a sabre-toothed tiger. Building a house. Writing a program. 0. Why Think? It helps us do most things: Hunting a sabre-toothed tiger

An Example: Euclid’s Algorithm

Computes GCD of M and N by:

– Initialize x to M and y to N .

– Keep subtracting the smaller of x and y from the larger.

– Stop when x = y .

For M = 12 and N = 18, one behavior:

[x = 12, y = 18] → [x = 12, y = 6] → [x = 6, y = 6]

10

Page 94: Thinking Above the Code - microsoft.comHunting a sabre-toothed tiger. Building a house. Writing a program. 0. Why Think? It helps us do most things: Hunting a sabre-toothed tiger

An Example: Euclid’s Algorithm

An algorithm is an abstract program.

For M = 12 and N = 18, one behavior:

[x = 12, y = 18] → [x = 12, y = 6] → [x = 6, y = 6]

10

Page 95: Thinking Above the Code - microsoft.comHunting a sabre-toothed tiger. Building a house. Writing a program. 0. Why Think? It helps us do most things: Hunting a sabre-toothed tiger

An Example: Euclid’s Algorithm

Computes GCD of M and N by:

– Initialize x to M and y to N .

– Keep subtracting the smaller of x and y from the larger.

– Stop when x = y .

For M = 12 and N = 18, one behavior:

[x = 12, y = 18] → [x = 12, y = 6] → [x = 6, y = 6]

10

Page 96: Thinking Above the Code - microsoft.comHunting a sabre-toothed tiger. Building a house. Writing a program. 0. Why Think? It helps us do most things: Hunting a sabre-toothed tiger

An Example: Euclid’s Algorithm

Computes GCD of M and N by:

– Initialize x to M and y to N .

– Keep subtracting the smaller of x and y from the larger.

– Stop when x = y .

For M = 12 and N = 18, one behavior:

[x = 12, y = 18] → [x = 12, y = 6] → [x = 6, y = 6]

10

Page 97: Thinking Above the Code - microsoft.comHunting a sabre-toothed tiger. Building a house. Writing a program. 0. Why Think? It helps us do most things: Hunting a sabre-toothed tiger

An Example: Euclid’s Algorithm

Computes GCD of M and N by:

– Initialize x to M and y to N .

– Keep subtracting the smaller of x and y from the larger.

– Stop when x = y .

For M = 12 and N = 18, one behavior:

[x = 12, y = 18] → [x = 12, y = 6] → [x = 6, y = 6]

10

Page 98: Thinking Above the Code - microsoft.comHunting a sabre-toothed tiger. Building a house. Writing a program. 0. Why Think? It helps us do most things: Hunting a sabre-toothed tiger

An Example: Euclid’s Algorithm

Computes GCD of M and N by:

– Initialize x to M and y to N .

– Keep subtracting the smaller of x and y from the larger.

– Stop when x = y .

For M = 12 and N = 18, one behavior:

[x = 12, y = 18] → [x = 12, y = 6] → [x = 6, y = 6]

10

Page 99: Thinking Above the Code - microsoft.comHunting a sabre-toothed tiger. Building a house. Writing a program. 0. Why Think? It helps us do most things: Hunting a sabre-toothed tiger

How to Describe a Set of Behaviors

Theorem

Any set B of behaviors =

all behaviors satisfying a safety property S

∩ all behaviors satisfying a liveness property L

12

Page 100: Thinking Above the Code - microsoft.comHunting a sabre-toothed tiger. Building a house. Writing a program. 0. Why Think? It helps us do most things: Hunting a sabre-toothed tiger

How to Describe a Set of Behaviors

Theorem

Any set B of behaviors =

all behaviors satisfying a safety property S

∩ all behaviors satisfying a liveness property L

12

Page 101: Thinking Above the Code - microsoft.comHunting a sabre-toothed tiger. Building a house. Writing a program. 0. Why Think? It helps us do most things: Hunting a sabre-toothed tiger

How to Describe a Set of Behaviors

Theorem

Any set B of behaviors =

all behaviors satisfying a safety property S

∩ all behaviors satisfying a liveness property L

12

Page 102: Thinking Above the Code - microsoft.comHunting a sabre-toothed tiger. Building a house. Writing a program. 0. Why Think? It helps us do most things: Hunting a sabre-toothed tiger

How to Describe a Set of Behaviors

Theorem

Any set B of behaviors =

all behaviors satisfying a safety property S

∩ all behaviors satisfying a liveness property L

12

Page 103: Thinking Above the Code - microsoft.comHunting a sabre-toothed tiger. Building a house. Writing a program. 0. Why Think? It helps us do most things: Hunting a sabre-toothed tiger

How to Describe a Set of Behaviors

Theorem

Any set B of behaviors =

all behaviors satisfying a safety property S

∩ all behaviors satisfying a liveness property L

Safety Property:

False iff violated at some point in behavior.

12

Page 104: Thinking Above the Code - microsoft.comHunting a sabre-toothed tiger. Building a house. Writing a program. 0. Why Think? It helps us do most things: Hunting a sabre-toothed tiger

How to Describe a Set of Behaviors

Theorem

Any set B of behaviors =

all behaviors satisfying a safety property S

∩ all behaviors satisfying a liveness property L

Safety Property:

False iff violated at some point in behavior.

Example: partial correctness.

12

Page 105: Thinking Above the Code - microsoft.comHunting a sabre-toothed tiger. Building a house. Writing a program. 0. Why Think? It helps us do most things: Hunting a sabre-toothed tiger

How to Describe a Set of Behaviors

Theorem

Any set B of behaviors =

all behaviors satisfying a safety property S

∩ all behaviors satisfying a liveness property L

Liveness Property:

Need to see complete behavior to know if it’s false.

12

Page 106: Thinking Above the Code - microsoft.comHunting a sabre-toothed tiger. Building a house. Writing a program. 0. Why Think? It helps us do most things: Hunting a sabre-toothed tiger

How to Describe a Set of Behaviors

Theorem

Any set B of behaviors =

all behaviors satisfying a safety property S

∩ all behaviors satisfying a liveness property L

Liveness Property:

Need to see complete behavior to know if it’s false.

Example: termination.

12

Page 107: Thinking Above the Code - microsoft.comHunting a sabre-toothed tiger. Building a house. Writing a program. 0. Why Think? It helps us do most things: Hunting a sabre-toothed tiger

How to Describe a Set of Behaviors

Theorem

Any set B of behaviors =

all behaviors satisfying a safety property S

∩ all behaviors satisfying a liveness property L

Specify a set of behaviors with

– a safety property

– a liveness property

12

Page 108: Thinking Above the Code - microsoft.comHunting a sabre-toothed tiger. Building a house. Writing a program. 0. Why Think? It helps us do most things: Hunting a sabre-toothed tiger

In practice, specifying safety is more important.

That’s where errors are most likely to occur.

To save time, I’ll ignore liveness.

12

Page 109: Thinking Above the Code - microsoft.comHunting a sabre-toothed tiger. Building a house. Writing a program. 0. Why Think? It helps us do most things: Hunting a sabre-toothed tiger

In practice, specifying safety is more important.

That’s where errors are most likely to occur.

To save time, I’ll ignore liveness.

12

Page 110: Thinking Above the Code - microsoft.comHunting a sabre-toothed tiger. Building a house. Writing a program. 0. Why Think? It helps us do most things: Hunting a sabre-toothed tiger

In practice, specifying safety is more important.

That’s where errors are most likely to occur.

To save time, I’ll ignore liveness.

12

Page 111: Thinking Above the Code - microsoft.comHunting a sabre-toothed tiger. Building a house. Writing a program. 0. Why Think? It helps us do most things: Hunting a sabre-toothed tiger

How to Specify a Safety Property

With two things:

– The set of possible initial states.

– A next-state relation,describing all possible successor states of any state.

What language should we use?

Let’s act like scientists.

Let’s use math.

13

Page 112: Thinking Above the Code - microsoft.comHunting a sabre-toothed tiger. Building a house. Writing a program. 0. Why Think? It helps us do most things: Hunting a sabre-toothed tiger

How to Specify a Safety Property

With two things:

– The set of possible initial states.

– A next-state relation,describing all possible successor states of any state.

What language should we use?

Let’s act like scientists.

Let’s use math.

13

Page 113: Thinking Above the Code - microsoft.comHunting a sabre-toothed tiger. Building a house. Writing a program. 0. Why Think? It helps us do most things: Hunting a sabre-toothed tiger

How to Specify a Safety Property

With two things:

– The set of possible initial states.

– A next-state relation,describing all possible successor states of any state.

What language should we use?

Let’s act like scientists.

Let’s use math.

13

Page 114: Thinking Above the Code - microsoft.comHunting a sabre-toothed tiger. Building a house. Writing a program. 0. Why Think? It helps us do most things: Hunting a sabre-toothed tiger

How to Specify a Safety Property

With two things:

– The set of possible initial states.

– A next-state relation,describing all possible successor states of any state.

What language should we use?

Let’s act like scientists.

Let’s use math.

13

Page 115: Thinking Above the Code - microsoft.comHunting a sabre-toothed tiger. Building a house. Writing a program. 0. Why Think? It helps us do most things: Hunting a sabre-toothed tiger

How to Specify a Safety Property

With two things:

– The set of possible initial states.

– A next-state relation,describing all possible successor states of any state.

What language should we use?

Let’s act like scientists.

Let’s use math.

13

Page 116: Thinking Above the Code - microsoft.comHunting a sabre-toothed tiger. Building a house. Writing a program. 0. Why Think? It helps us do most things: Hunting a sabre-toothed tiger

How to Specify a Safety Property

With two things:

– The set of possible initial states.

– A next-state relation,describing all possible successor states of any state.

What language should we use?

Let’s act like scientists.

Let’s use math.

13

Page 117: Thinking Above the Code - microsoft.comHunting a sabre-toothed tiger. Building a house. Writing a program. 0. Why Think? It helps us do most things: Hunting a sabre-toothed tiger

How to Specify a Safety Property

With two things:

– The set of possible initial states.

– A next-state relation,describing all possible successor states of any state.

What language should we use?

Let’s act like scientists.

Let’s use math.

13

Page 118: Thinking Above the Code - microsoft.comHunting a sabre-toothed tiger. Building a house. Writing a program. 0. Why Think? It helps us do most things: Hunting a sabre-toothed tiger

The Set of Initial States

Described by a formula.

For Euclid’s Algorithm: (x = M ) ∧ (y = N )

Only possible initial state: [x = M , y = N ]

14

Page 119: Thinking Above the Code - microsoft.comHunting a sabre-toothed tiger. Building a house. Writing a program. 0. Why Think? It helps us do most things: Hunting a sabre-toothed tiger

The Set of Initial States

Described by a formula.

For Euclid’s Algorithm: (x = M ) ∧ (y = N )

Only possible initial state: [x = M , y = N ]

14

Page 120: Thinking Above the Code - microsoft.comHunting a sabre-toothed tiger. Building a house. Writing a program. 0. Why Think? It helps us do most things: Hunting a sabre-toothed tiger

The Set of Initial States

Described by a formula.

For Euclid’s Algorithm: (x = M ) ∧ (y = N )

Only possible initial state: [x = M , y = N ]

14

Page 121: Thinking Above the Code - microsoft.comHunting a sabre-toothed tiger. Building a house. Writing a program. 0. Why Think? It helps us do most things: Hunting a sabre-toothed tiger

The Set of Initial States

Described by a formula.

For Euclid’s Algorithm: (x = M ) ∧ (y = N )

Only possible initial state: [x = M , y = N ]

14

Page 122: Thinking Above the Code - microsoft.comHunting a sabre-toothed tiger. Building a house. Writing a program. 0. Why Think? It helps us do most things: Hunting a sabre-toothed tiger

The Next-State Relation

Described by a formula.

Unprimed variables for current state,Primed variables for next state.

For Euclid’s Algorithm: ( x > y

∧ x ′ = x − y

∧ y ′ = y )

∨ ( y > x

∧ y ′ = y − x

∧ x ′ = x )

15

Page 123: Thinking Above the Code - microsoft.comHunting a sabre-toothed tiger. Building a house. Writing a program. 0. Why Think? It helps us do most things: Hunting a sabre-toothed tiger

The Next-State Relation

Described by a formula.

Unprimed variables for current state,Primed variables for next state.

For Euclid’s Algorithm: ( x > y

∧ x ′ = x − y

∧ y ′ = y )

∨ ( y > x

∧ y ′ = y − x

∧ x ′ = x )

15

Page 124: Thinking Above the Code - microsoft.comHunting a sabre-toothed tiger. Building a house. Writing a program. 0. Why Think? It helps us do most things: Hunting a sabre-toothed tiger

The Next-State Relation

Described by a formula.

Unprimed variables for current state,Primed variables for next state.

For Euclid’s Algorithm: ( x > y

∧ x ′ = x − y

∧ y ′ = y )

∨ ( y > x

∧ y ′ = y − x

∧ x ′ = x )

15

Page 125: Thinking Above the Code - microsoft.comHunting a sabre-toothed tiger. Building a house. Writing a program. 0. Why Think? It helps us do most things: Hunting a sabre-toothed tiger

The Next-State Relation

Described by a formula.

Unprimed variables for current state,Primed variables for next state.

For Euclid’s Algorithm: ( x > y

∧ x ′ = x − y

∧ y ′ = y )

∨ ( y > x

∧ y ′ = y − x

∧ x ′ = x )

15

Page 126: Thinking Above the Code - microsoft.comHunting a sabre-toothed tiger. Building a house. Writing a program. 0. Why Think? It helps us do most things: Hunting a sabre-toothed tiger

The Next-State Relation

Described by a formula.

Unprimed variables for current state,Primed variables for next state.

For Euclid’s Algorithm: ( x > y

∧ x ′ = x − y

∧ y ′ = y )

∨ ( y > x

∧ y ′ = y − x

∧ x ′ = x )

15

Page 127: Thinking Above the Code - microsoft.comHunting a sabre-toothed tiger. Building a house. Writing a program. 0. Why Think? It helps us do most things: Hunting a sabre-toothed tiger

The Next-State Relation

Described by a formula.

Unprimed variables for current state,Primed variables for next state.

For Euclid’s Algorithm: ( x > y

∧ x ′ = x − y

∧ y ′ = y )

∨ ( y > x

∧ y ′ = y − x

∧ x ′ = x )

15

Page 128: Thinking Above the Code - microsoft.comHunting a sabre-toothed tiger. Building a house. Writing a program. 0. Why Think? It helps us do most things: Hunting a sabre-toothed tiger

For Euclid’s Algorithm

Take M = 12, N = 18

Next : ( x > y

∧ x ′ = x − y

∧ y ′ = y )

∨ ( y > x

∧ y ′ = y − x

∧ x ′ = x )

Behavior:

[x = 12, y = 18] → [x = 12, y = 6] → [x = 6, y = 6]

17

Page 129: Thinking Above the Code - microsoft.comHunting a sabre-toothed tiger. Building a house. Writing a program. 0. Why Think? It helps us do most things: Hunting a sabre-toothed tiger

For Euclid’s Algorithm

Take M = 12, N = 18

Next : ( x > y

∧ x ′ = x − y

∧ y ′ = y )

∨ ( y > x

∧ y ′ = y − x

∧ x ′ = x )

Behavior:

[x = 12, y = 18] → [x = 12, y = 6] → [x = 6, y = 6]

17

Page 130: Thinking Above the Code - microsoft.comHunting a sabre-toothed tiger. Building a house. Writing a program. 0. Why Think? It helps us do most things: Hunting a sabre-toothed tiger

For Euclid’s Algorithm

Init : (x = M ) ∧ (y = N )

Next : ( x > y

∧ x ′ = x − y

∧ y ′ = y )

∨ ( y > x

∧ y ′ = y − x

∧ x ′ = x )

Behavior:

[x = 12, y = 18] → [x = 12, y = 6] → [x = 6, y = 6]

17

Page 131: Thinking Above the Code - microsoft.comHunting a sabre-toothed tiger. Building a house. Writing a program. 0. Why Think? It helps us do most things: Hunting a sabre-toothed tiger

For Euclid’s Algorithm

Init : (x = 12) ∧ (y = 18)

Next : ( x > y

∧ x ′ = x − y

∧ y ′ = y )

∨ ( y > x

∧ y ′ = y − x

∧ x ′ = x )

Behavior:

[x = 12, y = 18] → [x = 12, y = 6] → [x = 6, y = 6]

17

Page 132: Thinking Above the Code - microsoft.comHunting a sabre-toothed tiger. Building a house. Writing a program. 0. Why Think? It helps us do most things: Hunting a sabre-toothed tiger

For Euclid’s Algorithm

Init : (x = M ) ∧ (y = N )

Next : ( x > y

∧ x ′ = x − y

∧ y ′ = y )

∨ ( y > x

∧ y ′ = y − x

∧ x ′ = x )

Behavior:

[x = 12, y = 18] → [x = 12, y = 6] → [x = 6, y = 6]

17

Page 133: Thinking Above the Code - microsoft.comHunting a sabre-toothed tiger. Building a house. Writing a program. 0. Why Think? It helps us do most things: Hunting a sabre-toothed tiger

For Euclid’s Algorithm

Init : (x = M ) ∧ (y = N )

Next : ( 12 > 18∧ x ′ = 12− 18∧ y ′ = 18 )

∨ ( 18 > 12∧ y ′ = 18− 12∧ x ′ = 12 )

Behavior:

[x = 12, y = 18] → [x = 12, y = 6] → [x = 6, y = 6]

17

Page 134: Thinking Above the Code - microsoft.comHunting a sabre-toothed tiger. Building a house. Writing a program. 0. Why Think? It helps us do most things: Hunting a sabre-toothed tiger

For Euclid’s Algorithm

Init : (x = M ) ∧ (y = N )

Next : ( FALSE12 > 18∧ x ′ = 12− 18∧ y ′ = 18 )

∨ ( TRUE18 > 12∧ y ′ = 18− 12∧ x ′ = 12 )

Behavior:

[x = 12, y = 18] → [x = 12, y = 6] → [x = 6, y = 6]

17

Page 135: Thinking Above the Code - microsoft.comHunting a sabre-toothed tiger. Building a house. Writing a program. 0. Why Think? It helps us do most things: Hunting a sabre-toothed tiger

For Euclid’s Algorithm

Init : (x = M ) ∧ (y = N )

Next : ( 12 > 18∧ x ′ = 12− 18�������

HHHH

HHH

FALSE∧ y ′ = 18 )

∨ ( 18 > 12∧ y ′ = 18− 12∧ x ′ = 12 )

Behavior:

[x = 12, y = 18] → [x = 12, y = 6] → [x = 6, y = 6]

17

Page 136: Thinking Above the Code - microsoft.comHunting a sabre-toothed tiger. Building a house. Writing a program. 0. Why Think? It helps us do most things: Hunting a sabre-toothed tiger

For Euclid’s Algorithm

Init : (x = M ) ∧ (y = N )

Next : ( 12 > 18∧ x ′ = 12− 18�������

HHHH

HHH

FALSE∧ y ′ = 18 )

∨ ( 18 > 12∧ y ′ = 18− 12∧ x ′ = 12 )

Behavior:

[x = 12, y = 18] → [x = 12, y = 6] → [x = 6, y = 6]

17

Page 137: Thinking Above the Code - microsoft.comHunting a sabre-toothed tiger. Building a house. Writing a program. 0. Why Think? It helps us do most things: Hunting a sabre-toothed tiger

For Euclid’s Algorithm

Init : (x = M ) ∧ (y = N )

Next : ( 12 > 18∧ x ′ = 12− 18�������

HHHH

HHH

FALSE∧ y ′ = 18 )

∨ ( 18 > 12∧ y ′ = 18− 12∧ x ′ = 12 )

Behavior:

[x = 12, y = 18] → [x = 12, y = 6] → [x = 6, y = 6]

17

Page 138: Thinking Above the Code - microsoft.comHunting a sabre-toothed tiger. Building a house. Writing a program. 0. Why Think? It helps us do most things: Hunting a sabre-toothed tiger

For Euclid’s Algorithm

Init : (x = M ) ∧ (y = N )

Next : ( x > y

∧ x ′ = x − y

∧ y ′ = y )

∨ ( y > x

∧ y ′ = y − x

∧ x ′ = x )

Behavior:

[x = 12, y = 18] → [x = 12, y = 6] → [x = 6, y = 6]

17

Page 139: Thinking Above the Code - microsoft.comHunting a sabre-toothed tiger. Building a house. Writing a program. 0. Why Think? It helps us do most things: Hunting a sabre-toothed tiger

For Euclid’s Algorithm

Init : (x = M ) ∧ (y = N )

Next : ( 12 > 6∧ x ′ = 12− 6∧ y ′ = 6 )

∨ ( 6 > 12∧ y ′ = 6− 12∧ x ′ = 12 )

Behavior:

[x = 12, y = 18] → [x = 12, y = 6] → [x = 6, y = 6]

17

Page 140: Thinking Above the Code - microsoft.comHunting a sabre-toothed tiger. Building a house. Writing a program. 0. Why Think? It helps us do most things: Hunting a sabre-toothed tiger

For Euclid’s Algorithm

Init : (x = M ) ∧ (y = N )

Next : ( TRUE12 > 6∧ x ′ = 12− 6∧ y ′ = 6 )

∨ ( FALSE6 > 12∧ y ′ = 6− 12∧ x ′ = 12 )

Behavior:

[x = 12, y = 18] → [x = 12, y = 6] → [x = 6, y = 6]

17

Page 141: Thinking Above the Code - microsoft.comHunting a sabre-toothed tiger. Building a house. Writing a program. 0. Why Think? It helps us do most things: Hunting a sabre-toothed tiger

For Euclid’s Algorithm

Init : (x = M ) ∧ (y = N )

Next : ( 12 > 6∧ x ′ = 12− 6∧ y ′ = 6 )

∨ ( 6 > 12∧ y ′ = 6− 12�����

��

HHHHH

HH

FALSE∧ x ′ = 12 )

Behavior:

[x = 12, y = 18] → [x = 12, y = 6] → [x = 6, y = 6]

17

Page 142: Thinking Above the Code - microsoft.comHunting a sabre-toothed tiger. Building a house. Writing a program. 0. Why Think? It helps us do most things: Hunting a sabre-toothed tiger

For Euclid’s Algorithm

Init : (x = M ) ∧ (y = N )

Next : ( 12 > 6∧ x ′ = 12− 6∧ y ′ = 6 )

∨ ( 6 > 12∧ y ′ = 6− 12�����

��

HHHHH

HH

FALSE∧ x ′ = 12 )

Behavior:

[x = 12, y = 18] → [x = 12, y = 6] → [x = 6, y = 6]

17

Page 143: Thinking Above the Code - microsoft.comHunting a sabre-toothed tiger. Building a house. Writing a program. 0. Why Think? It helps us do most things: Hunting a sabre-toothed tiger

For Euclid’s Algorithm

Init : (x = M ) ∧ (y = N )

Next : ( x > y

∧ x ′ = x − y

∧ y ′ = y )

∨ ( y > x

∧ y ′ = y − x

∧ x ′ = x )

Behavior:

[x = 12, y = 18] → [x = 12, y = 6] → [x = 6, y = 6]

17

Page 144: Thinking Above the Code - microsoft.comHunting a sabre-toothed tiger. Building a house. Writing a program. 0. Why Think? It helps us do most things: Hunting a sabre-toothed tiger

For Euclid’s Algorithm

Init : (x = M ) ∧ (y = N )

Next : ( FALSE6 > 6∧ x ′ = 6− 6∧ y ′ = 6 )

∨ ( FALSE6 > 6∧ y ′ = 6− 6∧ x ′ = 6 )

Behavior:

[x = 12, y = 18] → [x = 12, y = 6] → [x = 6, y = 6]

17

Page 145: Thinking Above the Code - microsoft.comHunting a sabre-toothed tiger. Building a house. Writing a program. 0. Why Think? It helps us do most things: Hunting a sabre-toothed tiger

For Euclid’s Algorithm

Init : (x = M ) ∧ (y = N )

Next : ( 6 > 6∧ x ′ = 6− 6�������

HHHH

HHH

FALSE∧ y ′ = 6 )

∨ ( 6 > 6∧ y ′ = 6− 6�������

HHHHH

HH

FALSE∧ x ′ = 6 )

Behavior:

[x = 12, y = 18] → [x = 12, y = 6] → [x = 6, y = 6]

17

Page 146: Thinking Above the Code - microsoft.comHunting a sabre-toothed tiger. Building a house. Writing a program. 0. Why Think? It helps us do most things: Hunting a sabre-toothed tiger

For Euclid’s Algorithm

Init : (x = M ) ∧ (y = N )

Next : ( 6 > 6∧ x ′ = 6− 6�������

HHHH

HHH

FALSE∧ y ′ = 6 )

∨ ( 6 > 6∧ y ′ = 6− 6�������

HHHHH

HH

FALSE

NO NEXT STATE

∧ x ′ = 6 )

Behavior:

[x = 12, y = 18] → [x = 12, y = 6] → [x = 6, y = 6]

17

Page 147: Thinking Above the Code - microsoft.comHunting a sabre-toothed tiger. Building a house. Writing a program. 0. Why Think? It helps us do most things: Hunting a sabre-toothed tiger

Euclid’s Algorithm

For any values of x and y , there are uniquevalues of x ′ and y ′ that make Next true.

Euclid’s algorithm is deterministic.

To Model Nondeterminism

Allow multiple next states for a current state.

Multiple assignments of values to primed variablesthat make Next true for a single assignment of valuesto unprimed variables.

18

Page 148: Thinking Above the Code - microsoft.comHunting a sabre-toothed tiger. Building a house. Writing a program. 0. Why Think? It helps us do most things: Hunting a sabre-toothed tiger

Euclid’s Algorithm

For any values of x and y , there are uniquevalues of x ′ and y ′ that make Next true.

Euclid’s algorithm is deterministic.

To Model Nondeterminism

Allow multiple next states for a current state.

Multiple assignments of values to primed variablesthat make Next true for a single assignment of valuesto unprimed variables.

18

Page 149: Thinking Above the Code - microsoft.comHunting a sabre-toothed tiger. Building a house. Writing a program. 0. Why Think? It helps us do most things: Hunting a sabre-toothed tiger

Euclid’s Algorithm

For any values of x and y , there are uniquevalues of x ′ and y ′ that make Next true.

Euclid’s algorithm is deterministic.

To Model Nondeterminism

Allow multiple next states for a current state.

Multiple assignments of values to primed variablesthat make Next true for a single assignment of valuesto unprimed variables.

18

Page 150: Thinking Above the Code - microsoft.comHunting a sabre-toothed tiger. Building a house. Writing a program. 0. Why Think? It helps us do most things: Hunting a sabre-toothed tiger

Euclid’s Algorithm

For any values of x and y , there are uniquevalues of x ′ and y ′ that make Next true.

Euclid’s algorithm is deterministic.

To Model Nondeterminism

Allow multiple next states for a current state.

Multiple assignments of values to primed variablesthat make Next true for a single assignment of valuesto unprimed variables.

18

Page 151: Thinking Above the Code - microsoft.comHunting a sabre-toothed tiger. Building a house. Writing a program. 0. Why Think? It helps us do most things: Hunting a sabre-toothed tiger

Euclid’s Algorithm

For any values of x and y , there are uniquevalues of x ′ and y ′ that make Next true.

Euclid’s algorithm is deterministic.

To Model Nondeterminism

Allow multiple next states for a current state.

Multiple assignments of values to primed variablesthat make Next true for a single assignment of valuesto unprimed variables.

18

Page 152: Thinking Above the Code - microsoft.comHunting a sabre-toothed tiger. Building a house. Writing a program. 0. Why Think? It helps us do most things: Hunting a sabre-toothed tiger

Euclid’s Algorithm

For any values of x and y , there are uniquevalues of x ′ and y ′ that make Next true.

Euclid’s algorithm is deterministic.

To Model Nondeterminism

Allow multiple next states for a current state.

Multiple assignments of values to primed variablesthat make Next true for a single assignment of valuesto unprimed variables.

18

Page 153: Thinking Above the Code - microsoft.comHunting a sabre-toothed tiger. Building a house. Writing a program. 0. Why Think? It helps us do most things: Hunting a sabre-toothed tiger

What About Formal Specs?

Need them only to apply tools.

Require a formal language.

18

Page 154: Thinking Above the Code - microsoft.comHunting a sabre-toothed tiger. Building a house. Writing a program. 0. Why Think? It helps us do most things: Hunting a sabre-toothed tiger

What About Formal Specs?

Need them only to apply tools.

Require a formal language.

18

Page 155: Thinking Above the Code - microsoft.comHunting a sabre-toothed tiger. Building a house. Writing a program. 0. Why Think? It helps us do most things: Hunting a sabre-toothed tiger

What About Formal Specs?

Need them only to apply tools.

Require a formal language.

18

Page 156: Thinking Above the Code - microsoft.comHunting a sabre-toothed tiger. Building a house. Writing a program. 0. Why Think? It helps us do most things: Hunting a sabre-toothed tiger

The Language: TLA+

19

Page 157: Thinking Above the Code - microsoft.comHunting a sabre-toothed tiger. Building a house. Writing a program. 0. Why Think? It helps us do most things: Hunting a sabre-toothed tiger

The Language: TLA+

This

Init : (x = M ) ∧ (y = N )

Next : ( x > y

∧ x ′ = x − y

∧ y ′ = y )

∨ ( y > x

∧ y ′ = y − x

∧ x ′ = x )

19

Page 158: Thinking Above the Code - microsoft.comHunting a sabre-toothed tiger. Building a house. Writing a program. 0. Why Think? It helps us do most things: Hunting a sabre-toothed tiger

The Language: TLA+

becomes this

MODULE EuclidEXTENDS Integers

CONSTANTS M , N

VARIABLES x , y

Init∆= (x = M ) ∧ (y = N )

Next∆= ( x > y

∧ x ′ = x − y

∧ y ′ = y )

∨ ( y > x

∧ y ′ = y − x

∧ x ′ = x )

19

Page 159: Thinking Above the Code - microsoft.comHunting a sabre-toothed tiger. Building a house. Writing a program. 0. Why Think? It helps us do most things: Hunting a sabre-toothed tiger

The Language: TLA+

plus declarations

MODULE EuclidEXTENDS Integers

CONSTANTS M , N

VARIABLES x , y

Init∆= (x = M ) ∧ (y = N )

Next∆= ( x > y

∧ x ′ = x − y

∧ y ′ = y )

∨ ( y > x

∧ y ′ = y − x

∧ x ′ = x )

19

Page 160: Thinking Above the Code - microsoft.comHunting a sabre-toothed tiger. Building a house. Writing a program. 0. Why Think? It helps us do most things: Hunting a sabre-toothed tiger

The Language: TLA+

plus some boilerplate.

MODULE EuclidEXTENDS Integers

CONSTANTS M , N

VARIABLES x , y

Init∆= (x = M ) ∧ (y = N )

Next∆= ( x > y

∧ x ′ = x − y

∧ y ′ = y )

∨ ( y > x

∧ y ′ = y − x

∧ x ′ = x )

19

Page 161: Thinking Above the Code - microsoft.comHunting a sabre-toothed tiger. Building a house. Writing a program. 0. Why Think? It helps us do most things: Hunting a sabre-toothed tiger

The Language: TLA+

You type

------------------ MODULE Euclid -------------------EXTENDS Integers

CONSTANTS M, N

VARIABLES x, y

Init == (x = M) /\ (y = N)

Next == ( x > y/\ x’ = x - y/\ y’ = y )

\/ ( y > x/\ y’ = y - x/\ x’ = x )

=====================================================

19

Page 162: Thinking Above the Code - microsoft.comHunting a sabre-toothed tiger. Building a house. Writing a program. 0. Why Think? It helps us do most things: Hunting a sabre-toothed tiger

You can model check TLA+ specs.

You can write formal correctness proofsand check them mechanically.

But math works only for toy examples.

To model real systems, you need a real languagewith types, procedures, objects, etc.

Wrong

20

Page 163: Thinking Above the Code - microsoft.comHunting a sabre-toothed tiger. Building a house. Writing a program. 0. Why Think? It helps us do most things: Hunting a sabre-toothed tiger

You can model check TLA+ specs.

– Checks all executions of a small model.

You can write formal correctness proofsand check them mechanically.

But math works only for toy examples.

To model real systems, you need a real languagewith types, procedures, objects, etc.

Wrong

20

Page 164: Thinking Above the Code - microsoft.comHunting a sabre-toothed tiger. Building a house. Writing a program. 0. Why Think? It helps us do most things: Hunting a sabre-toothed tiger

You can model check TLA+ specs.

– Checks all executions of a small model.

– Extremely effective and fairly easy.

You can write formal correctness proofsand check them mechanically.

But math works only for toy examples.

To model real systems, you need a real languagewith types, procedures, objects, etc.

Wrong20

Page 165: Thinking Above the Code - microsoft.comHunting a sabre-toothed tiger. Building a house. Writing a program. 0. Why Think? It helps us do most things: Hunting a sabre-toothed tiger

You can model check TLA+ specs.

You can write formal correctness proofsand check them mechanically.

But math works only for toy examples.

To model real systems, you need a real languagewith types, procedures, objects, etc.

Wrong

20

Page 166: Thinking Above the Code - microsoft.comHunting a sabre-toothed tiger. Building a house. Writing a program. 0. Why Think? It helps us do most things: Hunting a sabre-toothed tiger

You can model check TLA+ specs.

You can write formal correctness proofsand check them mechanically.

– Hard work.

But math works only for toy examples.

To model real systems, you need a real languagewith types, procedures, objects, etc.

Wrong

20

Page 167: Thinking Above the Code - microsoft.comHunting a sabre-toothed tiger. Building a house. Writing a program. 0. Why Think? It helps us do most things: Hunting a sabre-toothed tiger

You can model check TLA+ specs.

You can write formal correctness proofsand check them mechanically.

But math works only for toy examples.

To model real systems, you need a real languagewith types, procedures, objects, etc.

Wrong

20

Page 168: Thinking Above the Code - microsoft.comHunting a sabre-toothed tiger. Building a house. Writing a program. 0. Why Think? It helps us do most things: Hunting a sabre-toothed tiger

You can model check TLA+ specs.

You can write formal correctness proofsand check them mechanically.

But math works only for toy examples.

To model real systems, you need a real languagewith types, procedures, objects, etc.

Wrong

20

Page 169: Thinking Above the Code - microsoft.comHunting a sabre-toothed tiger. Building a house. Writing a program. 0. Why Think? It helps us do most things: Hunting a sabre-toothed tiger

You can model check TLA+ specs.

You can write formal correctness proofsand check them mechanically.

But math works only for toy examples.

To model real systems, you need a real language

��������

����

����

������

PPPP

PPPP

PPPP

PPPP

PPPP

PP

with types, procedures, objects, etc.

Wrong

20

Page 170: Thinking Above the Code - microsoft.comHunting a sabre-toothed tiger. Building a house. Writing a program. 0. Why Think? It helps us do most things: Hunting a sabre-toothed tiger

[W]e have used TLA+ on 10 large complex real-world systems.In every case TLA+ has added significant value, eitherpreventing subtle serious bugs from reaching production, orgiving us enough understanding and confidence to makeaggressive performance optimizations without sacrificingcorrectness. Executive management are now proactivelyencouraging teams to write TLA+ specs for new features andother significant design changes. In annual planning, managersare now allocating engineering time to use TLA+.

Chris NewcombeAmazon EngineerNovember, 2013

21

Page 171: Thinking Above the Code - microsoft.comHunting a sabre-toothed tiger. Building a house. Writing a program. 0. Why Think? It helps us do most things: Hunting a sabre-toothed tiger

[W]e have used TLA+ on 10 large complex real-world systems.In every case TLA+ has added significant value, eitherpreventing subtle serious bugs from reaching production, orgiving us enough understanding and confidence to makeaggressive performance optimizations without sacrificingcorrectness. Executive management are now proactivelyencouraging teams to write TLA+ specs for new features andother significant design changes. In annual planning, managersare now allocating engineering time to use TLA+.

Chris NewcombeAmazon EngineerNovember, 2013

21

Page 172: Thinking Above the Code - microsoft.comHunting a sabre-toothed tiger. Building a house. Writing a program. 0. Why Think? It helps us do most things: Hunting a sabre-toothed tiger

[W]e have used TLA+ on 10 large complex real-world systems.In every case TLA+ has added significant value, eitherpreventing subtle serious bugs from reaching production, orgiving us enough understanding and confidence to makeaggressive performance optimizations without sacrificingcorrectness. Executive management are now proactivelyencouraging teams to write TLA+ specs for new features andother significant design changes. In annual planning, managersare now allocating engineering time to use TLA+.

Chris NewcombeAmazon EngineerNovember, 2013

21

Page 173: Thinking Above the Code - microsoft.comHunting a sabre-toothed tiger. Building a house. Writing a program. 0. Why Think? It helps us do most things: Hunting a sabre-toothed tiger

[W]e have used TLA+ on 10 large complex real-world systems.In every case TLA+ has added significant value, eitherpreventing subtle serious bugs from reaching production, orgiving us enough understanding and confidence to makeaggressive performance optimizations without sacrificingcorrectness. Executive management are now proactivelyencouraging teams to write TLA+ specs for new features andother significant design changes. In annual planning, managersare now allocating engineering time to use TLA+.

Chris NewcombeAmazon EngineerNovember, 2013

21

Page 174: Thinking Above the Code - microsoft.comHunting a sabre-toothed tiger. Building a house. Writing a program. 0. Why Think? It helps us do most things: Hunting a sabre-toothed tiger

[W]e have used TLA+ on 10 large complex real-world systems.In every case TLA+ has added significant value, eitherpreventing subtle serious bugs from reaching production, orgiving us enough understanding and confidence to makeaggressive performance optimizations without sacrificingcorrectness. Executive management are now proactivelyencouraging teams to write TLA+ specs for new features andother significant design changes. In annual planning, managersare now allocating engineering time to use TLA+.

Chris NewcombeAmazon EngineerNovember, 2013

21

Page 175: Thinking Above the Code - microsoft.comHunting a sabre-toothed tiger. Building a house. Writing a program. 0. Why Think? It helps us do most things: Hunting a sabre-toothed tiger

[W]e have used TLA+ on 10 large complex real-world systems.In every case TLA+ has added significant value, eitherpreventing subtle serious bugs from reaching production, orgiving us enough understanding and confidence to makeaggressive performance optimizations without sacrificingcorrectness. Executive management are now proactivelyencouraging teams to write TLA+ specs for new features andother significant design changes. In annual planning, managersare now allocating engineering time to use TLA+.

Chris NewcombeAmazon EngineerNovember, 2013

21

Page 176: Thinking Above the Code - microsoft.comHunting a sabre-toothed tiger. Building a house. Writing a program. 0. Why Think? It helps us do most things: Hunting a sabre-toothed tiger

[W]e have used TLA+ on 10 large complex real-world systems.In every case TLA+ has added significant value, eitherpreventing subtle serious bugs from reaching production, orgiving us enough understanding and confidence to makeaggressive performance optimizations without sacrificingcorrectness. Executive management are now proactivelyencouraging teams to write TLA+ specs for new features andother significant design changes. In annual planning, managersare now allocating engineering time to use TLA+.

Chris NewcombeAmazon EngineerNovember, 2013

21

Page 177: Thinking Above the Code - microsoft.comHunting a sabre-toothed tiger. Building a house. Writing a program. 0. Why Think? It helps us do most things: Hunting a sabre-toothed tiger

[W]e have used TLA+ on 10 large complex real-world systems.In every case TLA+ has added significant value, eitherpreventing subtle serious bugs from reaching production, orgiving us enough understanding and confidence to makeaggressive performance optimizations without sacrificingcorrectness. Executive management are now proactivelyencouraging teams to write TLA+ specs for new features andother significant design changes. In annual planning, managersare now allocating engineering time to use TLA+.

Chris NewcombeAmazon EngineerNovember, 2013

21

Page 178: Thinking Above the Code - microsoft.comHunting a sabre-toothed tiger. Building a house. Writing a program. 0. Why Think? It helps us do most things: Hunting a sabre-toothed tiger

The XBox 360 Memory System

Writing a TLA+ spec caught a bug that would nototherwise have been found.

That bug would have caused every XBox 360 to crashafter 4 hours of use.

21

Page 179: Thinking Above the Code - microsoft.comHunting a sabre-toothed tiger. Building a house. Writing a program. 0. Why Think? It helps us do most things: Hunting a sabre-toothed tiger

The XBox 360 Memory System

Writing a TLA+ spec caught a bug that would nototherwise have been found.

That bug would have caused every XBox 360 to crashafter 4 hours of use.

21

Page 180: Thinking Above the Code - microsoft.comHunting a sabre-toothed tiger. Building a house. Writing a program. 0. Why Think? It helps us do most things: Hunting a sabre-toothed tiger

The XBox 360 Memory System

Writing a TLA+ spec caught a bug that would nototherwise have been found.

That bug would have caused every XBox 360 to crashafter 4 hours of use.

21

Page 181: Thinking Above the Code - microsoft.comHunting a sabre-toothed tiger. Building a house. Writing a program. 0. Why Think? It helps us do most things: Hunting a sabre-toothed tiger

You can learn about TLA+ on the web.

Today, I’ll talk about informal specs, starting with an example.

22

Page 182: Thinking Above the Code - microsoft.comHunting a sabre-toothed tiger. Building a house. Writing a program. 0. Why Think? It helps us do most things: Hunting a sabre-toothed tiger

You can learn about TLA+ on the web.

Today, I’ll talk about informal specs, starting with an example.

22

Page 183: Thinking Above the Code - microsoft.comHunting a sabre-toothed tiger. Building a house. Writing a program. 0. Why Think? It helps us do most things: Hunting a sabre-toothed tiger

TLATEX — the TLA+ pretty-printer

22

Page 184: Thinking Above the Code - microsoft.comHunting a sabre-toothed tiger. Building a house. Writing a program. 0. Why Think? It helps us do most things: Hunting a sabre-toothed tiger

TLATEX — the TLA+ pretty-printer

The input:

Foo => /\ a = b

/\ ccc = d

23

Page 185: Thinking Above the Code - microsoft.comHunting a sabre-toothed tiger. Building a house. Writing a program. 0. Why Think? It helps us do most things: Hunting a sabre-toothed tiger

TLATEX — the TLA+ pretty-printer

The input:

Foo => /\ a = b

/\ ccc = d

The naive output:

Foo ⇒ ∧ a = b

∧ ccc = d

23

Page 186: Thinking Above the Code - microsoft.comHunting a sabre-toothed tiger. Building a house. Writing a program. 0. Why Think? It helps us do most things: Hunting a sabre-toothed tiger

TLATEX — the TLA+ pretty-printer

The input:

Foo => /\ a = b

/\ ccc = d

The naive output:

Foo ⇒ ∧ a = b

∧ ccc = d

The user probably wanted these aligned.

23

Page 187: Thinking Above the Code - microsoft.comHunting a sabre-toothed tiger. Building a house. Writing a program. 0. Why Think? It helps us do most things: Hunting a sabre-toothed tiger

TLATEX — the TLA+ pretty-printer

The input:

Foo => /\ a = b

/\ ccc = d

The right output:

Foo ⇒ ∧ a = b

∧ ccc = d

The user probably wanted these aligned.

23

Page 188: Thinking Above the Code - microsoft.comHunting a sabre-toothed tiger. Building a house. Writing a program. 0. Why Think? It helps us do most things: Hunting a sabre-toothed tiger

TLATEX — the TLA+ pretty-printer

The input:

/\ aaa + bb = c

/\ iii = jj * k

23

Page 189: Thinking Above the Code - microsoft.comHunting a sabre-toothed tiger. Building a house. Writing a program. 0. Why Think? It helps us do most things: Hunting a sabre-toothed tiger

TLATEX — the TLA+ pretty-printer

The input:

/\ aaa + bb = c

/\ iii = jj * k

The naive output:

∧ aaa + bb = c

∧ iii = jj ∗ k

23

Page 190: Thinking Above the Code - microsoft.comHunting a sabre-toothed tiger. Building a house. Writing a program. 0. Why Think? It helps us do most things: Hunting a sabre-toothed tiger

TLATEX — the TLA+ pretty-printer

The input:

/\ aaa + bb = c

/\ iii = jj * k

The naive output:

∧ aaa + bb = c

∧ iii = jj ∗ k

The user probably didn’t wanted these aligned.

23

Page 191: Thinking Above the Code - microsoft.comHunting a sabre-toothed tiger. Building a house. Writing a program. 0. Why Think? It helps us do most things: Hunting a sabre-toothed tiger

TLATEX — the TLA+ pretty-printer

The input:

/\ aaa + bb = c

/\ iii = jj * k

The right output:

∧ aaa + bb = c

∧ iii = jj ∗ k

The user probably didn’t wanted these aligned.

23

Page 192: Thinking Above the Code - microsoft.comHunting a sabre-toothed tiger. Building a house. Writing a program. 0. Why Think? It helps us do most things: Hunting a sabre-toothed tiger

There is no precise definition of correct alignment.

We can’t specify mathematically what the user wants.

If we can’t specify correctness, specification is useless.Wrong.

Not knowing what a program should do meanswe have to think even harder.

Which means that a spec is even more important.

24

Page 193: Thinking Above the Code - microsoft.comHunting a sabre-toothed tiger. Building a house. Writing a program. 0. Why Think? It helps us do most things: Hunting a sabre-toothed tiger

There is no precise definition of correct alignment.

We can’t specify mathematically what the user wants.

If we can’t specify correctness, specification is useless.Wrong.

Not knowing what a program should do meanswe have to think even harder.

Which means that a spec is even more important.

24

Page 194: Thinking Above the Code - microsoft.comHunting a sabre-toothed tiger. Building a house. Writing a program. 0. Why Think? It helps us do most things: Hunting a sabre-toothed tiger

There is no precise definition of correct alignment.

We can’t specify mathematically what the user wants.

If we can’t specify correctness, specification is useless.Wrong.

Not knowing what a program should do meanswe have to think even harder.

Which means that a spec is even more important.

24

Page 195: Thinking Above the Code - microsoft.comHunting a sabre-toothed tiger. Building a house. Writing a program. 0. Why Think? It helps us do most things: Hunting a sabre-toothed tiger

There is no precise definition of correct alignment.

We can’t specify mathematically what the user wants.

If we can’t specify correctness, specification is useless.Wrong.

Not knowing what a program should do meanswe have to think even harder.

Which means that a spec is even more important.

24

Page 196: Thinking Above the Code - microsoft.comHunting a sabre-toothed tiger. Building a house. Writing a program. 0. Why Think? It helps us do most things: Hunting a sabre-toothed tiger

There is no precise definition of correct alignment.

We can’t specify mathematically what the user wants.

If we can’t specify correctness, specification is useless.Wrong.

Not knowing what a program should do meanswe have to think even harder.

Which means that a spec is even more important.

24

Page 197: Thinking Above the Code - microsoft.comHunting a sabre-toothed tiger. Building a house. Writing a program. 0. Why Think? It helps us do most things: Hunting a sabre-toothed tiger

There is no precise definition of correct alignment.

We can’t specify mathematically what the user wants.

If we can’t specify correctness, specification is useless.Wrong.

Not knowing what a program should do meanswe have to think even harder.

Which means that a spec is even more important.

24

Page 198: Thinking Above the Code - microsoft.comHunting a sabre-toothed tiger. Building a house. Writing a program. 0. Why Think? It helps us do most things: Hunting a sabre-toothed tiger

My Spec

6 rules plus definitions (in comments).

Example:

A left-comment token is LeftComment alignedwith its covering token.

24

Page 199: Thinking Above the Code - microsoft.comHunting a sabre-toothed tiger. Building a house. Writing a program. 0. Why Think? It helps us do most things: Hunting a sabre-toothed tiger

My Spec

6 rules plus definitions (in comments).

Example:

A left-comment token is LeftComment alignedwith its covering token.

24

Page 200: Thinking Above the Code - microsoft.comHunting a sabre-toothed tiger. Building a house. Writing a program. 0. Why Think? It helps us do most things: Hunting a sabre-toothed tiger

My Spec

6 rules plus definitions (in comments).

Example:

A left-comment token is LeftComment alignedwith its covering token.

24

Page 201: Thinking Above the Code - microsoft.comHunting a sabre-toothed tiger. Building a house. Writing a program. 0. Why Think? It helps us do most things: Hunting a sabre-toothed tiger

My Spec

6 rules plus definitions (in comments).

Example:

A left-comment token is LeftComment alignedwith its covering token.

Defined term.

24

Page 202: Thinking Above the Code - microsoft.comHunting a sabre-toothed tiger. Building a house. Writing a program. 0. Why Think? It helps us do most things: Hunting a sabre-toothed tiger

Why did I write this spec?

It was a lot easier to understand and debug 6 rulesthan 850 lines of code.

I did a lot of debugging of the rules, aided by debugging codeto report what rules were being used.

The few bugs in implementing the rules were easy to catch.

Had I just written code, it would have taken me much longerand not produced formatting as good.

25

Page 203: Thinking Above the Code - microsoft.comHunting a sabre-toothed tiger. Building a house. Writing a program. 0. Why Think? It helps us do most things: Hunting a sabre-toothed tiger

Why did I write this spec?

It was a lot easier to understand and debug 6 rulesthan 850 lines of code.

I did a lot of debugging of the rules, aided by debugging codeto report what rules were being used.

The few bugs in implementing the rules were easy to catch.

Had I just written code, it would have taken me much longerand not produced formatting as good.

25

Page 204: Thinking Above the Code - microsoft.comHunting a sabre-toothed tiger. Building a house. Writing a program. 0. Why Think? It helps us do most things: Hunting a sabre-toothed tiger

Why did I write this spec?

It was a lot easier to understand and debug 6 rulesthan 850 lines of code.

I did a lot of debugging of the rules, aided by debugging codeto report what rules were being used.

The few bugs in implementing the rules were easy to catch.

Had I just written code, it would have taken me much longerand not produced formatting as good.

25

Page 205: Thinking Above the Code - microsoft.comHunting a sabre-toothed tiger. Building a house. Writing a program. 0. Why Think? It helps us do most things: Hunting a sabre-toothed tiger

Why did I write this spec?

It was a lot easier to understand and debug 6 rulesthan 850 lines of code.

I did a lot of debugging of the rules, aided by debugging codeto report what rules were being used.

The few bugs in implementing the rules were easy to catch.

Had I just written code, it would have taken me much longerand not produced formatting as good.

25

Page 206: Thinking Above the Code - microsoft.comHunting a sabre-toothed tiger. Building a house. Writing a program. 0. Why Think? It helps us do most things: Hunting a sabre-toothed tiger

Why did I write this spec?

It was a lot easier to understand and debug 6 rulesthan 850 lines of code.

I did a lot of debugging of the rules, aided by debugging codeto report what rules were being used.

The few bugs in implementing the rules were easy to catch.

Had I just written code, it would have taken me much longerand not produced formatting as good.

25

Page 207: Thinking Above the Code - microsoft.comHunting a sabre-toothed tiger. Building a house. Writing a program. 0. Why Think? It helps us do most things: Hunting a sabre-toothed tiger

Why did I write this spec?

It was a lot easier to understand and debug 6 rulesthan 850 lines of code.

I did a lot of debugging of the rules, aided by debugging codeto report what rules were being used.

The few bugs in implementing the rules were easy to catch.

Had I just written code, it would have taken me much longerand not produced formatting as good.

25

Page 208: Thinking Above the Code - microsoft.comHunting a sabre-toothed tiger. Building a house. Writing a program. 0. Why Think? It helps us do most things: Hunting a sabre-toothed tiger

Why not a formal spec?

Getting it right not that important.

It didn’t have to work on all corner cases.

There were no tools that could help me.

25

Page 209: Thinking Above the Code - microsoft.comHunting a sabre-toothed tiger. Building a house. Writing a program. 0. Why Think? It helps us do most things: Hunting a sabre-toothed tiger

Why not a formal spec?

Getting it right not that important.

It didn’t have to work on all corner cases.

There were no tools that could help me.

25

Page 210: Thinking Above the Code - microsoft.comHunting a sabre-toothed tiger. Building a house. Writing a program. 0. Why Think? It helps us do most things: Hunting a sabre-toothed tiger

Why not a formal spec?

Getting it right not that important.

It didn’t have to work on all corner cases.

There were no tools that could help me.

25

Page 211: Thinking Above the Code - microsoft.comHunting a sabre-toothed tiger. Building a house. Writing a program. 0. Why Think? It helps us do most things: Hunting a sabre-toothed tiger

Why not a formal spec?

Getting it right not that important.

It didn’t have to work on all corner cases.

There were no tools that could help me.

25

Page 212: Thinking Above the Code - microsoft.comHunting a sabre-toothed tiger. Building a house. Writing a program. 0. Why Think? It helps us do most things: Hunting a sabre-toothed tiger

What is Typical About This Spec

The spec is at a higher-level than the code.

It could have been implemented in any language.

No method or tool for writing better code would havehelped to write the spec.

No method or tool for writing better code would havemade the spec unnecessary.

It says nothing about how to write code.

You write a spec to help you think about the problembefore you think about the code. 26

Page 213: Thinking Above the Code - microsoft.comHunting a sabre-toothed tiger. Building a house. Writing a program. 0. Why Think? It helps us do most things: Hunting a sabre-toothed tiger

What is Typical About This Spec

The spec is at a higher-level than the code.

It could have been implemented in any language.

No method or tool for writing better code would havehelped to write the spec.

No method or tool for writing better code would havemade the spec unnecessary.

It says nothing about how to write code.

You write a spec to help you think about the problembefore you think about the code. 26

Page 214: Thinking Above the Code - microsoft.comHunting a sabre-toothed tiger. Building a house. Writing a program. 0. Why Think? It helps us do most things: Hunting a sabre-toothed tiger

What is Typical About This Spec

The spec is at a higher-level than the code.

It could have been implemented in any language.

No method or tool for writing better code would havehelped to write the spec.

No method or tool for writing better code would havemade the spec unnecessary.

It says nothing about how to write code.

You write a spec to help you think about the problembefore you think about the code. 26

Page 215: Thinking Above the Code - microsoft.comHunting a sabre-toothed tiger. Building a house. Writing a program. 0. Why Think? It helps us do most things: Hunting a sabre-toothed tiger

What is Typical About This Spec

The spec is at a higher-level than the code.

It could have been implemented in any language.

No method or tool for writing better code would havehelped to write the spec.

No method or tool for writing better code would havemade the spec unnecessary.

It says nothing about how to write code.

You write a spec to help you think about the problembefore you think about the code. 26

Page 216: Thinking Above the Code - microsoft.comHunting a sabre-toothed tiger. Building a house. Writing a program. 0. Why Think? It helps us do most things: Hunting a sabre-toothed tiger

What is Typical About This Spec

The spec is at a higher-level than the code.

It could have been implemented in any language.

No method or tool for writing better code would havehelped to write the spec.

No method or tool for writing better code would havemade the spec unnecessary.

It says nothing about how to write code.

You write a spec to help you think about the problembefore you think about the code. 26

Page 217: Thinking Above the Code - microsoft.comHunting a sabre-toothed tiger. Building a house. Writing a program. 0. Why Think? It helps us do most things: Hunting a sabre-toothed tiger

What is Typical About This Spec

The spec is at a higher-level than the code.

It could have been implemented in any language.

No method or tool for writing better code would havehelped to write the spec.

No method or tool for writing better code would havemade the spec unnecessary.

It says nothing about how to write code.

You write a spec to help you think about the problembefore you think about the code. 26

Page 218: Thinking Above the Code - microsoft.comHunting a sabre-toothed tiger. Building a house. Writing a program. 0. Why Think? It helps us do most things: Hunting a sabre-toothed tiger

What is Typical About This Spec

The spec is at a higher-level than the code.

It could have been implemented in any language.

No method or tool for writing better code would havehelped to write the spec.

No method or tool for writing better code would havemade the spec unnecessary.

It says nothing about how to write code.

You write a spec to help you think about the problembefore you think about the code. 26

Page 219: Thinking Above the Code - microsoft.comHunting a sabre-toothed tiger. Building a house. Writing a program. 0. Why Think? It helps us do most things: Hunting a sabre-toothed tiger

What is Not Typical About This Spec

It’s quite subtle.

95% of the code most people write requires less thought;specs that are shorter and simpler suffice.

It’s a set of rules.

A set of rules/requirements/axioms is usually a bad spec.

It’s hard to understand the consequences of a set of rules.

27

Page 220: Thinking Above the Code - microsoft.comHunting a sabre-toothed tiger. Building a house. Writing a program. 0. Why Think? It helps us do most things: Hunting a sabre-toothed tiger

What is Not Typical About This Spec

It’s quite subtle.

95% of the code most people write requires less thought;specs that are shorter and simpler suffice.

It’s a set of rules.

A set of rules/requirements/axioms is usually a bad spec.

It’s hard to understand the consequences of a set of rules.

27

Page 221: Thinking Above the Code - microsoft.comHunting a sabre-toothed tiger. Building a house. Writing a program. 0. Why Think? It helps us do most things: Hunting a sabre-toothed tiger

What is Not Typical About This Spec

It’s quite subtle.

95% of the code most people write requires less thought;specs that are shorter and simpler suffice.

It’s a set of rules.

A set of rules/requirements/axioms is usually a bad spec.

It’s hard to understand the consequences of a set of rules.

27

Page 222: Thinking Above the Code - microsoft.comHunting a sabre-toothed tiger. Building a house. Writing a program. 0. Why Think? It helps us do most things: Hunting a sabre-toothed tiger

What is Not Typical About This Spec

It’s quite subtle.

95% of the code most people write requires less thought;specs that are shorter and simpler suffice.

It’s a set of rules.

A set of rules/requirements/axioms is usually a bad spec.

It’s hard to understand the consequences of a set of rules.

27

Page 223: Thinking Above the Code - microsoft.comHunting a sabre-toothed tiger. Building a house. Writing a program. 0. Why Think? It helps us do most things: Hunting a sabre-toothed tiger

What is Not Typical About This Spec

It’s quite subtle.

95% of the code most people write requires less thought;specs that are shorter and simpler suffice.

It’s a set of rules.

A set of rules/requirements/axioms is usually a bad spec.

It’s hard to understand the consequences of a set of rules.

27

Page 224: Thinking Above the Code - microsoft.comHunting a sabre-toothed tiger. Building a house. Writing a program. 0. Why Think? It helps us do most things: Hunting a sabre-toothed tiger

What is Not Typical About This Spec

It’s quite subtle.

95% of the code most people write requires less thought;specs that are shorter and simpler suffice.

It’s a set of rules.

A set of rules/requirements/axioms is usually a bad spec.

It’s hard to understand the consequences of a set of rules.

27

Page 225: Thinking Above the Code - microsoft.comHunting a sabre-toothed tiger. Building a house. Writing a program. 0. Why Think? It helps us do most things: Hunting a sabre-toothed tiger

Specifying How to Compute a Function

Specifying what the pretty-printer should do was hard.

Implementing the spec was easy.

Specifying what a sorting program should do is easy.

Figuring out how to implement it efficiently is hard(if no one has shown you).

It requires thinking, which means writing a specification.

27

Page 226: Thinking Above the Code - microsoft.comHunting a sabre-toothed tiger. Building a house. Writing a program. 0. Why Think? It helps us do most things: Hunting a sabre-toothed tiger

Specifying How to Compute a Function

Specifying what the pretty-printer should do was hard.

Implementing the spec was easy.

Specifying what a sorting program should do is easy.

Figuring out how to implement it efficiently is hard(if no one has shown you).

It requires thinking, which means writing a specification.

27

Page 227: Thinking Above the Code - microsoft.comHunting a sabre-toothed tiger. Building a house. Writing a program. 0. Why Think? It helps us do most things: Hunting a sabre-toothed tiger

Specifying How to Compute a Function

Specifying what the pretty-printer should do was hard.

Implementing the spec was easy.

Specifying what a sorting program should do is easy.

Figuring out how to implement it efficiently is hard(if no one has shown you).

It requires thinking, which means writing a specification.

27

Page 228: Thinking Above the Code - microsoft.comHunting a sabre-toothed tiger. Building a house. Writing a program. 0. Why Think? It helps us do most things: Hunting a sabre-toothed tiger

Specifying How to Compute a Function

Specifying what the pretty-printer should do was hard.

Implementing the spec was easy.

Specifying what a sorting program should do is easy.

Figuring out how to implement it efficiently is hard(if no one has shown you).

It requires thinking, which means writing a specification.

27

Page 229: Thinking Above the Code - microsoft.comHunting a sabre-toothed tiger. Building a house. Writing a program. 0. Why Think? It helps us do most things: Hunting a sabre-toothed tiger

Specifying How to Compute a Function

Specifying what the pretty-printer should do was hard.

Implementing the spec was easy.

Specifying what a sorting program should do is easy.

Figuring out how to implement it efficiently is hard(if no one has shown you).

It requires thinking, which means writing a specification.

27

Page 230: Thinking Above the Code - microsoft.comHunting a sabre-toothed tiger. Building a house. Writing a program. 0. Why Think? It helps us do most things: Hunting a sabre-toothed tiger

Specifying How to Compute a Function

Specifying what the pretty-printer should do was hard.

Implementing the spec was easy.

Specifying what a sorting program should do is easy.

Figuring out how to implement it efficiently is hard(if no one has shown you).

It requires thinking, which means writing a specification.

27

Page 231: Thinking Above the Code - microsoft.comHunting a sabre-toothed tiger. Building a house. Writing a program. 0. Why Think? It helps us do most things: Hunting a sabre-toothed tiger

An example: Quicksort

A divide-and-conquer algorithm for sorting an arrayA[0], . . . , A[N − 1].

For simplicity, assume the A[i ] are numbers.

27

Page 232: Thinking Above the Code - microsoft.comHunting a sabre-toothed tiger. Building a house. Writing a program. 0. Why Think? It helps us do most things: Hunting a sabre-toothed tiger

An example: Quicksort

A divide-and-conquer algorithm for sorting an arrayA[0], . . . , A[N − 1].

For simplicity, assume the A[i ] are numbers.

27

Page 233: Thinking Above the Code - microsoft.comHunting a sabre-toothed tiger. Building a house. Writing a program. 0. Why Think? It helps us do most things: Hunting a sabre-toothed tiger

An example: Quicksort

A divide-and-conquer algorithm for sorting an arrayA[0], . . . , A[N − 1].

For simplicity, assume the A[i ] are numbers.

27

Page 234: Thinking Above the Code - microsoft.comHunting a sabre-toothed tiger. Building a house. Writing a program. 0. Why Think? It helps us do most things: Hunting a sabre-toothed tiger

It uses a procedure Partition(lo, hi).

It chooses pivot in lo . . . (hi − 1), permutes A[lo], . . . ,A[hi ]

to make A[lo], . . . ,A[pivot ] ≤ A[pivot + 1], . . . ,A[hi ],and returns pivot .

For this example, we don’t care how this procedureis implemented.

28

Page 235: Thinking Above the Code - microsoft.comHunting a sabre-toothed tiger. Building a house. Writing a program. 0. Why Think? It helps us do most things: Hunting a sabre-toothed tiger

It uses a procedure Partition(lo, hi).

It chooses pivot in lo . . . (hi − 1), permutes A[lo], . . . ,A[hi ]

to make A[lo], . . . ,A[pivot ] ≤ A[pivot + 1], . . . ,A[hi ],and returns pivot .

For this example, we don’t care how this procedureis implemented.

28

Page 236: Thinking Above the Code - microsoft.comHunting a sabre-toothed tiger. Building a house. Writing a program. 0. Why Think? It helps us do most things: Hunting a sabre-toothed tiger

It uses a procedure Partition(lo, hi).

It chooses pivot in lo . . . (hi − 1), permutes A[lo], . . . ,A[hi ]

to make A[lo], . . . ,A[pivot ] ≤ A[pivot + 1], . . . ,A[hi ],and returns pivot .

For this example, we don’t care how this procedureis implemented.

28

Page 237: Thinking Above the Code - microsoft.comHunting a sabre-toothed tiger. Building a house. Writing a program. 0. Why Think? It helps us do most things: Hunting a sabre-toothed tiger

Let’s specify Quicksort in pseudo-code.

procedure Partition(lo, hi) {

Pick pivot in lo . . . (hi − 1);

Permute A[lo], . . . ,A[hi ] to makeA[lo], . . . ,A[pivot ] ≤ A[pivot + 1], . . . ,A[hi ];

return pivot ; }

procedure QS (lo, hi) { if (lo < hi ) { p := Partition(lo, hi);QS (lo, p);QS (p + 1, hi); } }

main { QS (0,N − 1) ; }

But is it really Quicksort?

29

Page 238: Thinking Above the Code - microsoft.comHunting a sabre-toothed tiger. Building a house. Writing a program. 0. Why Think? It helps us do most things: Hunting a sabre-toothed tiger

procedure Partition(lo, hi) {

Pick pivot in lo . . . (hi − 1);

Permute A[lo], . . . ,A[hi ] to makeA[lo], . . . ,A[pivot ] ≤ A[pivot + 1], . . . ,A[hi ];

return pivot ; }

procedure QS (lo, hi) { if (lo < hi ) { p := Partition(lo, hi);QS (lo, p);QS (p + 1, hi); } }

main { QS (0,N − 1) ; }

But is it really Quicksort?

29

Page 239: Thinking Above the Code - microsoft.comHunting a sabre-toothed tiger. Building a house. Writing a program. 0. Why Think? It helps us do most things: Hunting a sabre-toothed tiger

procedure Partition(lo, hi) {

Pick pivot in lo . . . (hi − 1);

Permute A[lo], . . . ,A[hi ] to makeA[lo], . . . ,A[pivot ] ≤ A[pivot + 1], . . . ,A[hi ];

return pivot ; }

procedure QS (lo, hi) { if (lo < hi ) { p := Partition(lo, hi);QS (lo, p);QS (p + 1, hi); } }

main { QS (0,N − 1) ; }

But is it really Quicksort?

29

Page 240: Thinking Above the Code - microsoft.comHunting a sabre-toothed tiger. Building a house. Writing a program. 0. Why Think? It helps us do most things: Hunting a sabre-toothed tiger

procedure Partition(lo, hi) {

Pick pivot in lo . . . (hi − 1);

Permute A[lo], . . . ,A[hi ] to makeA[lo], . . . ,A[pivot ] ≤ A[pivot + 1], . . . ,A[hi ];

return pivot ; }

procedure QS (lo, hi) { if (lo < hi ) { p := Partition(lo, hi);QS (lo, p);QS (p + 1, hi); } }

main { QS (0,N − 1) ; }

But is it really Quicksort?

29

Page 241: Thinking Above the Code - microsoft.comHunting a sabre-toothed tiger. Building a house. Writing a program. 0. Why Think? It helps us do most things: Hunting a sabre-toothed tiger

procedure Partition(lo, hi) {

Pick pivot in lo . . . (hi − 1);

Permute A[lo], . . . ,A[hi ] to makeA[lo], . . . ,A[pivot ] ≤ A[pivot + 1], . . . ,A[hi ];

return pivot ; }

procedure QS (lo, hi) { if (lo < hi ) { p := Partition(lo, hi);QS (lo, p);QS (p + 1, hi); } }

main { QS (0,N − 1) ; }

But is it really Quicksort?

29

Page 242: Thinking Above the Code - microsoft.comHunting a sabre-toothed tiger. Building a house. Writing a program. 0. Why Think? It helps us do most things: Hunting a sabre-toothed tiger

procedure Partition(lo, hi) {

Pick pivot in lo . . . (hi − 1);

Permute A[lo], . . . ,A[hi ] to makeA[lo], . . . ,A[pivot ] ≤ A[pivot + 1], . . . ,A[hi ];

return pivot ; }

procedure QS (lo, hi) { if (lo < hi ) { p := Partition(lo, hi);QS (lo, p);QS (p + 1, hi); } }

main { QS (0,N − 1) ; }

Informal: no formal syntax, no declarations, . . .

Easy to understand.

But is it really Quicksort?29

Page 243: Thinking Above the Code - microsoft.comHunting a sabre-toothed tiger. Building a house. Writing a program. 0. Why Think? It helps us do most things: Hunting a sabre-toothed tiger

procedure Partition(lo, hi) {

Pick pivot in lo . . . (hi − 1);

Permute A[lo], . . . ,A[hi ] to makeA[lo], . . . ,A[pivot ] ≤ A[pivot + 1], . . . ,A[hi ];

return pivot ; }

procedure QS (lo, hi) { if (lo < hi ) { p := Partition(lo, hi);QS (lo, p);QS (p + 1, hi); } }

main { QS (0,N − 1) ; }

Informal: no formal syntax, no declarations, . . .

Easy to understand.

But is it really Quicksort?29

Page 244: Thinking Above the Code - microsoft.comHunting a sabre-toothed tiger. Building a house. Writing a program. 0. Why Think? It helps us do most things: Hunting a sabre-toothed tiger

procedure Partition(lo, hi) {

Pick pivot in lo . . . (hi − 1);

Permute A[lo], . . . ,A[hi ] to makeA[lo], . . . ,A[pivot ] ≤ A[pivot + 1], . . . ,A[hi ];

return pivot ; }

procedure QS (lo, hi) { if (lo < hi ) { p := Partition(lo, hi);QS (lo, p);QS (p + 1, hi); } }

main { QS (0,N − 1) ; }

But is it really Quicksort?

29

Page 245: Thinking Above the Code - microsoft.comHunting a sabre-toothed tiger. Building a house. Writing a program. 0. Why Think? It helps us do most things: Hunting a sabre-toothed tiger

It’s the way Quicksort is almost always described.

But recursion is not a fundamental part of Quicksort.

It’s just one way of implementing divide-and-conquer.

It’s probably not the best way for parallel execution.

30

Page 246: Thinking Above the Code - microsoft.comHunting a sabre-toothed tiger. Building a house. Writing a program. 0. Why Think? It helps us do most things: Hunting a sabre-toothed tiger

It’s the way Quicksort is almost always described.

But recursion is not a fundamental part of Quicksort.

It’s just one way of implementing divide-and-conquer.

It’s probably not the best way for parallel execution.

30

Page 247: Thinking Above the Code - microsoft.comHunting a sabre-toothed tiger. Building a house. Writing a program. 0. Why Think? It helps us do most things: Hunting a sabre-toothed tiger

It’s the way Quicksort is almost always described.

But recursion is not a fundamental part of Quicksort.

It’s just one way of implementing divide-and-conquer.

It’s probably not the best way for parallel execution.

30

Page 248: Thinking Above the Code - microsoft.comHunting a sabre-toothed tiger. Building a house. Writing a program. 0. Why Think? It helps us do most things: Hunting a sabre-toothed tiger

It’s the way Quicksort is almost always described.

But recursion is not a fundamental part of Quicksort.

It’s just one way of implementing divide-and-conquer.

It’s probably not the best way for parallel execution.

30

Page 249: Thinking Above the Code - microsoft.comHunting a sabre-toothed tiger. Building a house. Writing a program. 0. Why Think? It helps us do most things: Hunting a sabre-toothed tiger

Problem: Write a non-recursive version of Quicksort.

Almost no one can do it in 10 minutes.

They try to “compile” the recursive version.

30

Page 250: Thinking Above the Code - microsoft.comHunting a sabre-toothed tiger. Building a house. Writing a program. 0. Why Think? It helps us do most things: Hunting a sabre-toothed tiger

Problem: Write a non-recursive version of Quicksort.

Almost no one can do it in 10 minutes.

They try to “compile” the recursive version.

30

Page 251: Thinking Above the Code - microsoft.comHunting a sabre-toothed tiger. Building a house. Writing a program. 0. Why Think? It helps us do most things: Hunting a sabre-toothed tiger

Problem: Write a non-recursive version of Quicksort.

Almost no one can do it in 10 minutes.

They try to “compile” the recursive version.

30

Page 252: Thinking Above the Code - microsoft.comHunting a sabre-toothed tiger. Building a house. Writing a program. 0. Why Think? It helps us do most things: Hunting a sabre-toothed tiger

Solution:

Maintain a set U of index ranges on whichPartition needs to be called.

Initially, U equals {〈0,N − 1〉}

We could write it in pseudo-code,but it’s better to simply write Init and Next directly.

31

Page 253: Thinking Above the Code - microsoft.comHunting a sabre-toothed tiger. Building a house. Writing a program. 0. Why Think? It helps us do most things: Hunting a sabre-toothed tiger

Solution:

Maintain a set U of index ranges on whichPartition needs to be called.

Initially, U equals {〈0,N − 1〉}

We could write it in pseudo-code,but it’s better to simply write Init and Next directly.

31

Page 254: Thinking Above the Code - microsoft.comHunting a sabre-toothed tiger. Building a house. Writing a program. 0. Why Think? It helps us do most things: Hunting a sabre-toothed tiger

Solution:

Maintain a set U of index ranges on whichPartition needs to be called.

Initially, U equals {〈0,N − 1〉}

We could write it in pseudo-code,but it’s better to simply write Init and Next directly.

31

Page 255: Thinking Above the Code - microsoft.comHunting a sabre-toothed tiger. Building a house. Writing a program. 0. Why Think? It helps us do most things: Hunting a sabre-toothed tiger

Solution:

Maintain a set U of index ranges on whichPartition needs to be called.

Initially, U equals {〈0,N − 1〉}

We could write it in pseudo-code,but it’s better to simply write Init and Next directly.

31

Page 256: Thinking Above the Code - microsoft.comHunting a sabre-toothed tiger. Building a house. Writing a program. 0. Why Think? It helps us do most things: Hunting a sabre-toothed tiger

Init : A = any array of numbers of length N

∧ U = {〈0,N − 1〉}

Before writing Next , let’s make a definition:

Partitions(B , pivot , lo, hi)∆=

the set of arrays obtained from B by permutingB [lo], . . . , B [hi ] such that . . .

Next :

A relation between old values of A, Uand new values A′, U ′.

32

Page 257: Thinking Above the Code - microsoft.comHunting a sabre-toothed tiger. Building a house. Writing a program. 0. Why Think? It helps us do most things: Hunting a sabre-toothed tiger

Init : A = any array of numbers of length N

∧ U = {〈0,N − 1〉}

Before writing Next , let’s make a definition:

Partitions(B , pivot , lo, hi)∆=

the set of arrays obtained from B by permutingB [lo], . . . , B [hi ] such that . . .

Next :

A relation between old values of A, Uand new values A′, U ′.

32

Page 258: Thinking Above the Code - microsoft.comHunting a sabre-toothed tiger. Building a house. Writing a program. 0. Why Think? It helps us do most things: Hunting a sabre-toothed tiger

Init : A = any array of numbers of length N

∧ U = {〈0,N − 1〉}

Before writing Next , let’s make a definition:

Partitions(B , pivot , lo, hi)∆=

the set of arrays obtained from B by permutingB [lo], . . . , B [hi ] such that . . .

Next :

A relation between old values of A, Uand new values A′, U ′.

32

Page 259: Thinking Above the Code - microsoft.comHunting a sabre-toothed tiger. Building a house. Writing a program. 0. Why Think? It helps us do most things: Hunting a sabre-toothed tiger

Init : A = any array of numbers of length N

∧ U = {〈0,N − 1〉}

Before writing Next , let’s make a definition:

Partitions(B , pivot , lo, hi)∆=

the set of arrays obtained from B by permutingB [lo], . . . , B [hi ] such that . . .

Next :

A relation between old values of A, Uand new values A′, U ′.

32

Page 260: Thinking Above the Code - microsoft.comHunting a sabre-toothed tiger. Building a house. Writing a program. 0. Why Think? It helps us do most things: Hunting a sabre-toothed tiger

Next :U 6= {}

∧ Pick any 〈b, t〉 in U :IF b 6= t

THEN Pick any p in b . . (t−1) :A′ = Any element of Partitions(A, p, b, t)

∧ U ′ = U with 〈b, t〉 removed and〈b, p〉 and 〈p+1, t〉 added

ELSE A′ = A

∧ U ′ = U with 〈b, t〉 removed

34

Page 261: Thinking Above the Code - microsoft.comHunting a sabre-toothed tiger. Building a house. Writing a program. 0. Why Think? It helps us do most things: Hunting a sabre-toothed tiger

Next :U 6= {} Stop if U = {}

∧ Pick any 〈b, t〉 in U :IF b 6= t

THEN Pick any p in b . . (t−1) :A′ = Any element of Partitions(A, p, b, t)

∧ U ′ = U with 〈b, t〉 removed and〈b, p〉 and 〈p+1, t〉 added

ELSE A′ = A

∧ U ′ = U with 〈b, t〉 removed

34

Page 262: Thinking Above the Code - microsoft.comHunting a sabre-toothed tiger. Building a house. Writing a program. 0. Why Think? It helps us do most things: Hunting a sabre-toothed tiger

Next :U 6= {}

∧ Pick any 〈b, t〉 in U :IF b 6= t

THEN Pick any p in b . . (t−1) :A′ = Any element of Partitions(A, p, b, t)

∧ U ′ = U with 〈b, t〉 removed and〈b, p〉 and 〈p+1, t〉 added

ELSE A′ = A

∧ U ′ = U with 〈b, t〉 removed

34

Page 263: Thinking Above the Code - microsoft.comHunting a sabre-toothed tiger. Building a house. Writing a program. 0. Why Think? It helps us do most things: Hunting a sabre-toothed tiger

Next :U 6= {}

∧ Pick any 〈b, t〉 in U :IF b 6= t

THEN Pick any p in b . . (t−1) :A′ = Any element of Partitions(A, p, b, t)

∧ U ′ = U with 〈b, t〉 removed and〈b, p〉 and 〈p+1, t〉 added

ELSE A′ = A

∧ U ′ = U with 〈b, t〉 removed

34

Page 264: Thinking Above the Code - microsoft.comHunting a sabre-toothed tiger. Building a house. Writing a program. 0. Why Think? It helps us do most things: Hunting a sabre-toothed tiger

Next :U 6= {}

∧ Pick any 〈b, t〉 in U :IF b 6= t

THEN Pick any p in b . . (t−1) :A′ = Any element of Partitions(A, p, b, t)

∧ U ′ = U with 〈b, t〉 removed and〈b, p〉 and 〈p+1, t〉 added

ELSE A′ = A

∧ U ′ = U with 〈b, t〉 removed

34

Page 265: Thinking Above the Code - microsoft.comHunting a sabre-toothed tiger. Building a house. Writing a program. 0. Why Think? It helps us do most things: Hunting a sabre-toothed tiger

Next :U 6= {}

∧ Pick any 〈b, t〉 in U :IF b 6= t

THEN Pick any p in b . . (t−1) :A′ = Any element of Partitions(A, p, b, t)

∧ U ′ = U with 〈b, t〉 removed and〈b, p〉 and 〈p+1, t〉 added

ELSE A′ = A

∧ U ′ = U with 〈b, t〉 removed

34

Page 266: Thinking Above the Code - microsoft.comHunting a sabre-toothed tiger. Building a house. Writing a program. 0. Why Think? It helps us do most things: Hunting a sabre-toothed tiger

Next :U 6= {}

∧ Pick any 〈b, t〉 in U :IF b 6= t

THEN Pick any p in b . . (t−1) :A′ = Any element of Partitions(A, p, b, t)

∧ U ′ = U with 〈b, t〉 removed and〈b, p〉 and 〈p+1, t〉 added

ELSE A′ = A

∧ U ′ = U with 〈b, t〉 removed

34

Page 267: Thinking Above the Code - microsoft.comHunting a sabre-toothed tiger. Building a house. Writing a program. 0. Why Think? It helps us do most things: Hunting a sabre-toothed tiger

Next :U 6= {}

∧ Pick any 〈b, t〉 in U :IF b 6= t

THEN Pick any p in b . . (t−1) :A′ = Any element of Partitions(A, p, b, t)

∧ U ′ = U with 〈b, t〉 removed and〈b, p〉 and 〈p+1, t〉 added

ELSE A′ = A

∧ U ′ = U with 〈b, t〉 removed

34

Page 268: Thinking Above the Code - microsoft.comHunting a sabre-toothed tiger. Building a house. Writing a program. 0. Why Think? It helps us do most things: Hunting a sabre-toothed tiger

Next :U 6= {}

∧ Pick any 〈b, t〉 in U :IF b 6= t

THEN Pick any p in b . . (t−1) :A′ = Any element of Partitions(A, p, b, t)

∧ U ′ = U with 〈b, t〉 removed and〈b, p〉 and 〈p+1, t〉 added

ELSE A′ = A

∧ U ′ = U with 〈b, t〉 removed

34

Page 269: Thinking Above the Code - microsoft.comHunting a sabre-toothed tiger. Building a house. Writing a program. 0. Why Think? It helps us do most things: Hunting a sabre-toothed tiger

Why can (almost) no one find this version of Quicksort?

Their minds are stuck in code.

They can’t think at a higher level.

34

Page 270: Thinking Above the Code - microsoft.comHunting a sabre-toothed tiger. Building a house. Writing a program. 0. Why Think? It helps us do most things: Hunting a sabre-toothed tiger

Why can (almost) no one find this version of Quicksort?

Their minds are stuck in code.

They can’t think at a higher level.

34

Page 271: Thinking Above the Code - microsoft.comHunting a sabre-toothed tiger. Building a house. Writing a program. 0. Why Think? It helps us do most things: Hunting a sabre-toothed tiger

Why can (almost) no one find this version of Quicksort?

Their minds are stuck in code.

They can’t think at a higher level.

34

Page 272: Thinking Above the Code - microsoft.comHunting a sabre-toothed tiger. Building a house. Writing a program. 0. Why Think? It helps us do most things: Hunting a sabre-toothed tiger

Next :U 6= {}

∧ Pick any 〈b, t〉 in U :IF b 6= t

THEN Pick any p in b . . (t−1) :A′ = Any element of Partitions(A, p, b, t)

∧ U ′ = U with 〈b, t〉 removed and〈b, p〉 and 〈p+1, t〉 added

ELSE A′ = A

∧ U ′ = U with 〈b, t〉 removed

Easy to write this as a formula.

35

Page 273: Thinking Above the Code - microsoft.comHunting a sabre-toothed tiger. Building a house. Writing a program. 0. Why Think? It helps us do most things: Hunting a sabre-toothed tiger

Next :U 6= {}

∧ Pick any 〈b, t〉 in U :IF b 6= t

THEN Pick any p in b . . (t−1) :A′ = Any element of Partitions(A, p, b, t)

∧ U ′ = U with 〈b, t〉 removed and〈b, p〉 and 〈p+1, t〉 added

ELSE A′ = A

∧ U ′ = U with 〈b, t〉 removed

Pick an arbitrary value

35

Page 274: Thinking Above the Code - microsoft.comHunting a sabre-toothed tiger. Building a house. Writing a program. 0. Why Think? It helps us do most things: Hunting a sabre-toothed tiger

Next :U 6= {}

∧ ∃ 〈b, t〉 ∈ U :

IF b 6= t

THEN Pick any p in b . . (t−1) :A′ = Any element of Partitions(A, p, b, t)

∧ U ′ = U with 〈b, t〉 removed and〈b, p〉 and 〈p+1, t〉 added

ELSE A′ = A

∧ U ′ = U with 〈b, t〉 removed

Pick an arbitrary value is existential quantification.

35

Page 275: Thinking Above the Code - microsoft.comHunting a sabre-toothed tiger. Building a house. Writing a program. 0. Why Think? It helps us do most things: Hunting a sabre-toothed tiger

Next :U 6= {}

∧ ∃ 〈b, t〉 ∈ U :

IF b 6= t

THEN Pick any p in b . . (t−1) :A′ = Any element of Partitions(A, p, b, t)

∧ U ′ = U with 〈b, t〉 removed and〈b, p〉 and 〈p+1, t〉 added

ELSE A′ = A

∧ U ′ = U with 〈b, t〉 removed

Pick an arbitrary value is existential quantification.

35

Page 276: Thinking Above the Code - microsoft.comHunting a sabre-toothed tiger. Building a house. Writing a program. 0. Why Think? It helps us do most things: Hunting a sabre-toothed tiger

Next :U 6= {}

∧ ∃ 〈b, t〉 ∈ U :

IF b 6= t

THEN ∃ p ∈ b . . (t−1) :A′ = Any element of Partitions(A, p, b, t)

∧ U ′ = U with 〈b, t〉 removed and〈b, p〉 and 〈p+1, t〉 added

ELSE A′ = A

∧ U ′ = U with 〈b, t〉 removed

Pick an arbitrary value is existential quantification.

35

Page 277: Thinking Above the Code - microsoft.comHunting a sabre-toothed tiger. Building a house. Writing a program. 0. Why Think? It helps us do most things: Hunting a sabre-toothed tiger

Next :U 6= {}

∧ ∃ 〈b, t〉 ∈ U :

IF b 6= t

THEN ∃ p ∈ b . . (t−1) :A′ = Any element of Partitions(A, p, b, t)

∧ U ′ = U with 〈b, t〉 removed and〈b, p〉 and 〈p+1, t〉 added

ELSE A′ = A

∧ U ′ = U with 〈b, t〉 removed

Or sometimes

35

Page 278: Thinking Above the Code - microsoft.comHunting a sabre-toothed tiger. Building a house. Writing a program. 0. Why Think? It helps us do most things: Hunting a sabre-toothed tiger

Next :U 6= {}

∧ ∃ 〈b, t〉 ∈ U :

IF b 6= t

THEN ∃ p ∈ b . . (t−1) :A′ ∈ Partitions(A, p, b, t)

∧ U ′ = U with 〈b, t〉 removed and〈b, p〉 and 〈p+1, t〉 added

ELSE A′ = A

∧ U ′ = U with 〈b, t〉 removed

Or sometimes even simpler.

35

Page 279: Thinking Above the Code - microsoft.comHunting a sabre-toothed tiger. Building a house. Writing a program. 0. Why Think? It helps us do most things: Hunting a sabre-toothed tiger

Next :U 6= {}

∧ ∃ 〈b, t〉 ∈ U :

IF b 6= t

THEN ∃ p ∈ b . . (t−1) :A′ ∈ Partitions(A, p, b, t)

∧ U ′ = U with 〈b, t〉 removed and

ELSE A′ = A

∧ U ′ = U with 〈b, t〉 removed

And so on.

35

Page 280: Thinking Above the Code - microsoft.comHunting a sabre-toothed tiger. Building a house. Writing a program. 0. Why Think? It helps us do most things: Hunting a sabre-toothed tiger

Next :U 6= {}

∧ ∃ 〈b, t〉 ∈ U :

IF b 6= t

THEN ∃ p ∈ b . . (t−1) :A′ ∈ Partitions(A, p, b, t)

∧ U ′ = (U \ {〈b, t〉}) ∪ {〈b, p〉, 〈p+1, t〉}

ELSE A′ = A

∧ U ′ = U \ {〈b, t〉}

And so on.

35

Page 281: Thinking Above the Code - microsoft.comHunting a sabre-toothed tiger. Building a house. Writing a program. 0. Why Think? It helps us do most things: Hunting a sabre-toothed tiger

Next :U 6= {}

∧ ∃ 〈b, t〉 ∈ U :

IF b 6= t

THEN ∃ p ∈ b . . (t−1) :A′ ∈ Partitions(A, p, b, t)

∧ U ′ = (U \ {〈b, t〉}) ∪ {〈b, p〉, 〈p+1, t〉}

ELSE A′ = A

∧ U ′ = U \ {〈b, t〉}

A TLA+ formula.

35

Page 282: Thinking Above the Code - microsoft.comHunting a sabre-toothed tiger. Building a house. Writing a program. 0. Why Think? It helps us do most things: Hunting a sabre-toothed tiger

Next :U 6= {}

∧ ∃ 〈b, t〉 ∈ U :

IF b 6= t

THEN ∃ p ∈ b . . (t−1) :A′ ∈ Partitions(A, p, b, t)

∧ U ′ = (U \ {〈b, t〉}) ∪ {〈b, p〉, 〈p+1, t〉}

ELSE A′ = A

∧ U ′ = U \ {〈b, t〉}

If you prefer pseudo-code. . .

35

Page 283: Thinking Above the Code - microsoft.comHunting a sabre-toothed tiger. Building a house. Writing a program. 0. Why Think? It helps us do most things: Hunting a sabre-toothed tiger

PlusCal

Like a toy programming language.

Algorithm appears in a comment in a TLA+ module.

An expression can be any TLA+ expression.

Constructs for nondeterminism.

Compiled to an easy to understand TLA+ spec.

Can apply TLA+ tools.

36

Page 284: Thinking Above the Code - microsoft.comHunting a sabre-toothed tiger. Building a house. Writing a program. 0. Why Think? It helps us do most things: Hunting a sabre-toothed tiger

PlusCal

Like a toy programming language.

Algorithm appears in a comment in a TLA+ module.

An expression can be any TLA+ expression.

Constructs for nondeterminism.

Compiled to an easy to understand TLA+ spec.

Can apply TLA+ tools.

36

Page 285: Thinking Above the Code - microsoft.comHunting a sabre-toothed tiger. Building a house. Writing a program. 0. Why Think? It helps us do most things: Hunting a sabre-toothed tiger

PlusCal

Like a toy programming language.

Algorithm appears in a comment in a TLA+ module.

An expression can be any TLA+ expression.

Constructs for nondeterminism.

Compiled to an easy to understand TLA+ spec.

Can apply TLA+ tools.

36

Page 286: Thinking Above the Code - microsoft.comHunting a sabre-toothed tiger. Building a house. Writing a program. 0. Why Think? It helps us do most things: Hunting a sabre-toothed tiger

PlusCal

Like a toy programming language.

Algorithm appears in a comment in a TLA+ module.

An expression can be any TLA+ expression.

Constructs for nondeterminism.

Compiled to an easy to understand TLA+ spec.

Can apply TLA+ tools.

36

Page 287: Thinking Above the Code - microsoft.comHunting a sabre-toothed tiger. Building a house. Writing a program. 0. Why Think? It helps us do most things: Hunting a sabre-toothed tiger

PlusCal

Like a toy programming language.

Algorithm appears in a comment in a TLA+ module.

An expression can be any TLA+ expression.

Constructs for nondeterminism.

Compiled to an easy to understand TLA+ spec.

Can apply TLA+ tools.

36

Page 288: Thinking Above the Code - microsoft.comHunting a sabre-toothed tiger. Building a house. Writing a program. 0. Why Think? It helps us do most things: Hunting a sabre-toothed tiger

PlusCal

Like a toy programming language.

Algorithm appears in a comment in a TLA+ module.

An expression can be any TLA+ expression.

Constructs for nondeterminism.

Compiled to an easy to understand TLA+ spec.

Can apply TLA+ tools.

36

Page 289: Thinking Above the Code - microsoft.comHunting a sabre-toothed tiger. Building a house. Writing a program. 0. Why Think? It helps us do most things: Hunting a sabre-toothed tiger

PlusCal

Like a toy programming language.

Algorithm appears in a comment in a TLA+ module.

An expression can be any TLA+ expression.

Constructs for nondeterminism.

Compiled to an easy to understand TLA+ spec.

Can apply TLA+ tools.

36

Page 290: Thinking Above the Code - microsoft.comHunting a sabre-toothed tiger. Building a house. Writing a program. 0. Why Think? It helps us do most things: Hunting a sabre-toothed tiger

Programs that Run Forever

I’ve been talking about programs that compute a function.

Programs that run forever usually involve concurrency:

– Operating systems.

– Distributed systems.

Few people can get them right by just thinking (and writing).

I’m not one of them.

We need tools to check what we do.

Use TLA+/ PlusCal.

37

Page 291: Thinking Above the Code - microsoft.comHunting a sabre-toothed tiger. Building a house. Writing a program. 0. Why Think? It helps us do most things: Hunting a sabre-toothed tiger

Programs that Run Forever

I’ve been talking about programs that compute a function.

Programs that run forever usually involve concurrency:

– Operating systems.

– Distributed systems.

Few people can get them right by just thinking (and writing).

I’m not one of them.

We need tools to check what we do.

Use TLA+/ PlusCal.

37

Page 292: Thinking Above the Code - microsoft.comHunting a sabre-toothed tiger. Building a house. Writing a program. 0. Why Think? It helps us do most things: Hunting a sabre-toothed tiger

Programs that Run Forever

I’ve been talking about programs that compute a function.

Programs that run forever usually involve concurrency:

– Operating systems.

– Distributed systems.

Few people can get them right by just thinking (and writing).

I’m not one of them.

We need tools to check what we do.

Use TLA+/ PlusCal.

37

Page 293: Thinking Above the Code - microsoft.comHunting a sabre-toothed tiger. Building a house. Writing a program. 0. Why Think? It helps us do most things: Hunting a sabre-toothed tiger

Programs that Run Forever

I’ve been talking about programs that compute a function.

Programs that run forever usually involve concurrency:

– Operating systems.

– Distributed systems.

Few people can get them right by just thinking (and writing).

I’m not one of them.

We need tools to check what we do.

Use TLA+/ PlusCal.

37

Page 294: Thinking Above the Code - microsoft.comHunting a sabre-toothed tiger. Building a house. Writing a program. 0. Why Think? It helps us do most things: Hunting a sabre-toothed tiger

Programs that Run Forever

I’ve been talking about programs that compute a function.

Programs that run forever usually involve concurrency:

– Operating systems.

– Distributed systems.

Few people can get them right by just thinking (and writing).

I’m not one of them.

We need tools to check what we do.

Use TLA+/ PlusCal.

37

Page 295: Thinking Above the Code - microsoft.comHunting a sabre-toothed tiger. Building a house. Writing a program. 0. Why Think? It helps us do most things: Hunting a sabre-toothed tiger

Programs that Run Forever

I’ve been talking about programs that compute a function.

Programs that run forever usually involve concurrency:

– Operating systems.

– Distributed systems.

Few people can get them right by just thinking (and writing).

I’m not one of them.

We need tools to check what we do.

Use TLA+/ PlusCal.

37

Page 296: Thinking Above the Code - microsoft.comHunting a sabre-toothed tiger. Building a house. Writing a program. 0. Why Think? It helps us do most things: Hunting a sabre-toothed tiger

Programs that Run Forever

I’ve been talking about programs that compute a function.

Programs that run forever usually involve concurrency:

– Operating systems.

– Distributed systems.

Few people can get them right by just thinking (and writing).

I’m not one of them.

We need tools to check what we do.

Use TLA+/ PlusCal.

37

Page 297: Thinking Above the Code - microsoft.comHunting a sabre-toothed tiger. Building a house. Writing a program. 0. Why Think? It helps us do most things: Hunting a sabre-toothed tiger

Programs that Run Forever

I’ve been talking about programs that compute a function.

Programs that run forever usually involve concurrency:

– Operating systems.

– Distributed systems.

Few people can get them right by just thinking (and writing).

I’m not one of them.

We need tools to check what we do.

Use TLA+/ PlusCal.

37

Page 298: Thinking Above the Code - microsoft.comHunting a sabre-toothed tiger. Building a house. Writing a program. 0. Why Think? It helps us do most things: Hunting a sabre-toothed tiger

Programs that Run Forever

I’ve been talking about programs that compute a function.

Programs that run forever usually involve concurrency:

– Operating systems.

– Distributed systems.

Few people can get them right by just thinking (and writing).

I’m not one of them.

We need tools to check what we do.

Use TLA+/ PlusCal.

37

Page 299: Thinking Above the Code - microsoft.comHunting a sabre-toothed tiger. Building a house. Writing a program. 0. Why Think? It helps us do most things: Hunting a sabre-toothed tiger

The Other 95%

Prose

Most code is really simple.

38

Page 300: Thinking Above the Code - microsoft.comHunting a sabre-toothed tiger. Building a house. Writing a program. 0. Why Think? It helps us do most things: Hunting a sabre-toothed tiger

The Other 95%

/************************************************************ CLASS ResourceFileReader ** ** A ResourceFileReader returns an object for reading a ** resource file, which is a file kept in the same ** directory as the tlatex.Token class. The constructor ** takes a file name as argument. The object’s two public ** methods are ** ** getLine() : Returns the next line of the file as a ** string. Returns null after the last line. ** ** close() : Closes the file. ************************************************************/

38

Page 301: Thinking Above the Code - microsoft.comHunting a sabre-toothed tiger. Building a house. Writing a program. 0. Why Think? It helps us do most things: Hunting a sabre-toothed tiger

Why did I write that spec?

To be sure I knew what the code should do before writing it.

Without writing a spec, I only thought I knew what it should do.

Later, I didn’t have to read the code to know what it did.

General rule:A spec of what the code does should say everythingthat anyone needs to know to use the code.

39

Page 302: Thinking Above the Code - microsoft.comHunting a sabre-toothed tiger. Building a house. Writing a program. 0. Why Think? It helps us do most things: Hunting a sabre-toothed tiger

Why did I write that spec?

To be sure I knew what the code should do before writing it.

Without writing a spec, I only thought I knew what it should do.

Later, I didn’t have to read the code to know what it did.

General rule:A spec of what the code does should say everythingthat anyone needs to know to use the code.

39

Page 303: Thinking Above the Code - microsoft.comHunting a sabre-toothed tiger. Building a house. Writing a program. 0. Why Think? It helps us do most things: Hunting a sabre-toothed tiger

Why did I write that spec?

To be sure I knew what the code should do before writing it.

Without writing a spec, I only thought I knew what it should do.

Later, I didn’t have to read the code to know what it did.

General rule:A spec of what the code does should say everythingthat anyone needs to know to use the code.

39

Page 304: Thinking Above the Code - microsoft.comHunting a sabre-toothed tiger. Building a house. Writing a program. 0. Why Think? It helps us do most things: Hunting a sabre-toothed tiger

Why did I write that spec?

To be sure I knew what the code should do before writing it.

Without writing a spec, I only thought I knew what it should do.

Later, I didn’t have to read the code to know what it did.

General rule:A spec of what the code does should say everythingthat anyone needs to know to use the code.

39

Page 305: Thinking Above the Code - microsoft.comHunting a sabre-toothed tiger. Building a house. Writing a program. 0. Why Think? It helps us do most things: Hunting a sabre-toothed tiger

Why did I write that spec?

To be sure I knew what the code should do before writing it.

Without writing a spec, I only thought I knew what it should do.

Later, I didn’t have to read the code to know what it did.

General rule:A spec of what the code does should say everythingthat anyone needs to know to use the code.

39

Page 306: Thinking Above the Code - microsoft.comHunting a sabre-toothed tiger. Building a house. Writing a program. 0. Why Think? It helps us do most things: Hunting a sabre-toothed tiger

Why did I write that spec?

To be sure I knew what the code should do before writing it.

Without writing a spec, I only thought I knew what it should do.

Later, I didn’t have to read the code to know what it did.

How the code worked was too simple to require a spec.

39

Page 307: Thinking Above the Code - microsoft.comHunting a sabre-toothed tiger. Building a house. Writing a program. 0. Why Think? It helps us do most things: Hunting a sabre-toothed tiger

What programmers should know about thinking.

Everyone thinks they think.

If you don’t write down your thoughts,you’re fooling yourself.

39

Page 308: Thinking Above the Code - microsoft.comHunting a sabre-toothed tiger. Building a house. Writing a program. 0. Why Think? It helps us do most things: Hunting a sabre-toothed tiger

What everyone should know about thinking.

Everyone thinks they think.

If you don’t write down your thoughts,you’re fooling yourself.

39

Page 309: Thinking Above the Code - microsoft.comHunting a sabre-toothed tiger. Building a house. Writing a program. 0. Why Think? It helps us do most things: Hunting a sabre-toothed tiger

What everyone should know about thinking.

Everyone thinks they think.

If you don’t write down your thoughts,you’re fooling yourself.

39

Page 310: Thinking Above the Code - microsoft.comHunting a sabre-toothed tiger. Building a house. Writing a program. 0. Why Think? It helps us do most things: Hunting a sabre-toothed tiger

What everyone should know about thinking.

Everyone thinks they think.

If you don’t write down your thoughts,you’re fooling yourself.

39

Page 311: Thinking Above the Code - microsoft.comHunting a sabre-toothed tiger. Building a house. Writing a program. 0. Why Think? It helps us do most things: Hunting a sabre-toothed tiger

What programmers should know about thinking.

You should think before you code.

A spec is simply what you write before coding.

40

Page 312: Thinking Above the Code - microsoft.comHunting a sabre-toothed tiger. Building a house. Writing a program. 0. Why Think? It helps us do most things: Hunting a sabre-toothed tiger

What programmers should know about thinking.

You should think before you code.

A spec is simply what you write before coding.

40

Page 313: Thinking Above the Code - microsoft.comHunting a sabre-toothed tiger. Building a house. Writing a program. 0. Why Think? It helps us do most things: Hunting a sabre-toothed tiger

What programmers should know about thinking.

You should write before you code.

A spec is simply what you write before coding.

40

Page 314: Thinking Above the Code - microsoft.comHunting a sabre-toothed tiger. Building a house. Writing a program. 0. Why Think? It helps us do most things: Hunting a sabre-toothed tiger

What programmers should know about thinking.

You should write before you code.

A spec is simply what you write before coding.

40

Page 315: Thinking Above the Code - microsoft.comHunting a sabre-toothed tiger. Building a house. Writing a program. 0. Why Think? It helps us do most things: Hunting a sabre-toothed tiger

What code should you specify?

Any piece of code that someone else might want touse or modify.

It could be:

An entire program or system.

A class.

A method.

A tricky piece of code in a method.

40

Page 316: Thinking Above the Code - microsoft.comHunting a sabre-toothed tiger. Building a house. Writing a program. 0. Why Think? It helps us do most things: Hunting a sabre-toothed tiger

What code should you specify?

Any piece of code that someone else might want touse or modify.

It could be:

An entire program or system.

A class.

A method.

A tricky piece of code in a method.

40

Page 317: Thinking Above the Code - microsoft.comHunting a sabre-toothed tiger. Building a house. Writing a program. 0. Why Think? It helps us do most things: Hunting a sabre-toothed tiger

What code should you specify?

Any piece of code that someone elseyou

might want touse or modify in a month.

It could be:

An entire program or system.

A class.

A method.

A tricky piece of code in a method.

40

Page 318: Thinking Above the Code - microsoft.comHunting a sabre-toothed tiger. Building a house. Writing a program. 0. Why Think? It helps us do most things: Hunting a sabre-toothed tiger

What code should you specify?

Any piece of code that someone elseyou

might want touse or modify in a month.

It could be:

An entire program or system.

A class.

A method.

A tricky piece of code in a method.

40

Page 319: Thinking Above the Code - microsoft.comHunting a sabre-toothed tiger. Building a house. Writing a program. 0. Why Think? It helps us do most things: Hunting a sabre-toothed tiger

What code should you specify?

Any piece of code that someone elseyou

might want touse or modify in a month.

It could be:

An entire program or system.

A class.

A method.

A tricky piece of code in a method.

40

Page 320: Thinking Above the Code - microsoft.comHunting a sabre-toothed tiger. Building a house. Writing a program. 0. Why Think? It helps us do most things: Hunting a sabre-toothed tiger

What code should you specify?

Any piece of code that someone elseyou

might want touse or modify in a month.

It could be:

An entire program or system.

A class.

A method.

A tricky piece of code in a method.

40

Page 321: Thinking Above the Code - microsoft.comHunting a sabre-toothed tiger. Building a house. Writing a program. 0. Why Think? It helps us do most things: Hunting a sabre-toothed tiger

What code should you specify?

Any piece of code that someone elseyou

might want touse or modify in a month.

It could be:

An entire program or system.

A class.

A method.

A tricky piece of code in a method.

40

Page 322: Thinking Above the Code - microsoft.comHunting a sabre-toothed tiger. Building a house. Writing a program. 0. Why Think? It helps us do most things: Hunting a sabre-toothed tiger

What code should you specify?

Any piece of code that someone elseyou

might want touse or modify in a month.

It could be:

An entire program or system.

A class.

A method.

A tricky piece of code in a method.

40

Page 323: Thinking Above the Code - microsoft.comHunting a sabre-toothed tiger. Building a house. Writing a program. 0. Why Think? It helps us do most things: Hunting a sabre-toothed tiger

What should you specify about the code?

What it does.

Everything anyone needs to know to use it.

Maybe: how it does it.

The algorithm / high-level design.

41

Page 324: Thinking Above the Code - microsoft.comHunting a sabre-toothed tiger. Building a house. Writing a program. 0. Why Think? It helps us do most things: Hunting a sabre-toothed tiger

What should you specify about the code?

What it does.

Everything anyone needs to know to use it.

Maybe: how it does it.

The algorithm / high-level design.

41

Page 325: Thinking Above the Code - microsoft.comHunting a sabre-toothed tiger. Building a house. Writing a program. 0. Why Think? It helps us do most things: Hunting a sabre-toothed tiger

What should you specify about the code?

What it does.

Everything anyone needs to know to use it.

Maybe: how it does it.

The algorithm / high-level design.

41

Page 326: Thinking Above the Code - microsoft.comHunting a sabre-toothed tiger. Building a house. Writing a program. 0. Why Think? It helps us do most things: Hunting a sabre-toothed tiger

What should you specify about the code?

What it does.

Everything anyone needs to know to use it.

Maybe: how it does it.

The algorithm / high-level design.

41

Page 327: Thinking Above the Code - microsoft.comHunting a sabre-toothed tiger. Building a house. Writing a program. 0. Why Think? It helps us do most things: Hunting a sabre-toothed tiger

What should you specify about the code?

What it does.

Everything anyone needs to know to use it.

Maybe: how it does it.

The algorithm / high-level design.

41

Page 328: Thinking Above the Code - microsoft.comHunting a sabre-toothed tiger. Building a house. Writing a program. 0. Why Think? It helps us do most things: Hunting a sabre-toothed tiger

How should you think about / specify the code?

Above the code level.

In terms of states and behaviors.

Mathematically, as rigorously / formally as necessary.

Perhaps with pseudo-code or PlusCal if specifying how.

41

Page 329: Thinking Above the Code - microsoft.comHunting a sabre-toothed tiger. Building a house. Writing a program. 0. Why Think? It helps us do most things: Hunting a sabre-toothed tiger

How should you think about / specify the code?

Above the code level.

In terms of states and behaviors.

Mathematically, as rigorously / formally as necessary.

Perhaps with pseudo-code or PlusCal if specifying how.

41

Page 330: Thinking Above the Code - microsoft.comHunting a sabre-toothed tiger. Building a house. Writing a program. 0. Why Think? It helps us do most things: Hunting a sabre-toothed tiger

How should you think about / specify the code?

Above the code level.

In terms of states and behaviors.

Mathematically, as rigorously / formally as necessary.

Perhaps with pseudo-code or PlusCal if specifying how.

41

Page 331: Thinking Above the Code - microsoft.comHunting a sabre-toothed tiger. Building a house. Writing a program. 0. Why Think? It helps us do most things: Hunting a sabre-toothed tiger

How should you think about / specify the code?

Above the code level.

In terms of states and behaviors.

Mathematically, as rigorously / formally as necessary.

Perhaps with pseudo-code or PlusCal if specifying how.

41

Page 332: Thinking Above the Code - microsoft.comHunting a sabre-toothed tiger. Building a house. Writing a program. 0. Why Think? It helps us do most things: Hunting a sabre-toothed tiger

How should you think about / specify the code?

Above the code level.

In terms of states and behaviors.

Mathematically, as rigorously / formally as necessary.

Perhaps with pseudo-code or PlusCal if specifying how.

41

Page 333: Thinking Above the Code - microsoft.comHunting a sabre-toothed tiger. Building a house. Writing a program. 0. Why Think? It helps us do most things: Hunting a sabre-toothed tiger

How do you learn to write specs?

By writing formal specs.

41

Page 334: Thinking Above the Code - microsoft.comHunting a sabre-toothed tiger. Building a house. Writing a program. 0. Why Think? It helps us do most things: Hunting a sabre-toothed tiger

How do you learn to write specs?

By writing formal specs.

41

Page 335: Thinking Above the Code - microsoft.comHunting a sabre-toothed tiger. Building a house. Writing a program. 0. Why Think? It helps us do most things: Hunting a sabre-toothed tiger

How do you learn to write formal specs?

You learned to write programs by writing them,running them, and correcting your errors.

You can learn to write formal specs by writingthem, “running” them with a model checker,and correcting your errors.

TLA+ may not be the best language for your formalspecification needs.

But it’s great for learning learning to think mathematically.

42

Page 336: Thinking Above the Code - microsoft.comHunting a sabre-toothed tiger. Building a house. Writing a program. 0. Why Think? It helps us do most things: Hunting a sabre-toothed tiger

How do you learn to write formal specs?

You learned to write programs by writing them,running them, and correcting your errors.

You can learn to write formal specs by writingthem, “running” them with a model checker,and correcting your errors.

TLA+ may not be the best language for your formalspecification needs.

But it’s great for learning learning to think mathematically.

42

Page 337: Thinking Above the Code - microsoft.comHunting a sabre-toothed tiger. Building a house. Writing a program. 0. Why Think? It helps us do most things: Hunting a sabre-toothed tiger

How do you learn to write formal specs?

You learned to write programs by writing them,running them, and correcting your errors.

You can learn to write formal specs by writingthem, “running” them with a model checker,and correcting your errors.

TLA+ may not be the best language for your formalspecification needs.

But it’s great for learning learning to think mathematically.

42

Page 338: Thinking Above the Code - microsoft.comHunting a sabre-toothed tiger. Building a house. Writing a program. 0. Why Think? It helps us do most things: Hunting a sabre-toothed tiger

How do you learn to write formal specs?

You learned to write programs by writing them,running them, and correcting your errors.

You can learn to write formal specs by writingthem, “running” them with a model checker,and correcting your errors.

TLA+ may not be the best language for your formalspecification needs.

But it’s great for learning learning to think mathematically.

42

Page 339: Thinking Above the Code - microsoft.comHunting a sabre-toothed tiger. Building a house. Writing a program. 0. Why Think? It helps us do most things: Hunting a sabre-toothed tiger

How do you learn to write formal specs?

You learned to write programs by writing them,running them, and correcting your errors.

You can learn to write formal specs by writingthem, “running” them with a model checker,and correcting your errors.

TLA+ may not be the best language for your formalspecification needs.

But it’s great for learning learning to think mathematically.

42

Page 340: Thinking Above the Code - microsoft.comHunting a sabre-toothed tiger. Building a house. Writing a program. 0. Why Think? It helps us do most things: Hunting a sabre-toothed tiger

How do you connect the spec to the code?

Comments connecting mathematical concepts and theirimplementation.

Example:

Mathematical concept: graph

Implementation: array of node objects & array of link objects

43

Page 341: Thinking Above the Code - microsoft.comHunting a sabre-toothed tiger. Building a house. Writing a program. 0. Why Think? It helps us do most things: Hunting a sabre-toothed tiger

How do you connect the spec to the code?

Comments connecting mathematical concepts and theirimplementation.

Example:

Mathematical concept: graph

Implementation: array of node objects & array of link objects

43

Page 342: Thinking Above the Code - microsoft.comHunting a sabre-toothed tiger. Building a house. Writing a program. 0. Why Think? It helps us do most things: Hunting a sabre-toothed tiger

How do you connect the spec to the code?

Comments connecting mathematical concepts and theirimplementation.

Example:

Mathematical concept: graph

Implementation: array of node objects & array of link objects

43

Page 343: Thinking Above the Code - microsoft.comHunting a sabre-toothed tiger. Building a house. Writing a program. 0. Why Think? It helps us do most things: Hunting a sabre-toothed tiger

How do you connect the spec to the code?

Comments connecting mathematical concepts and theirimplementation.

Example:

Mathematical concept: graph

Implementation: array of node objects & array of link objects

43

Page 344: Thinking Above the Code - microsoft.comHunting a sabre-toothed tiger. Building a house. Writing a program. 0. Why Think? It helps us do most things: Hunting a sabre-toothed tiger

What about coding?

Nothing I have said implies anything abouthow you should code.

You still have to think while you code.

What you write while coding is code.

I have nothing to say about how you should code.

Use any programming language you want.

Use any coding methodology you want:test-driven development, agile programming, . . .

43

Page 345: Thinking Above the Code - microsoft.comHunting a sabre-toothed tiger. Building a house. Writing a program. 0. Why Think? It helps us do most things: Hunting a sabre-toothed tiger

What about coding?

Nothing I have said implies anything abouthow you should code.

You still have to think while you code.

What you write while coding is code.

I have nothing to say about how you should code.

Use any programming language you want.

Use any coding methodology you want:test-driven development, agile programming, . . .

43

Page 346: Thinking Above the Code - microsoft.comHunting a sabre-toothed tiger. Building a house. Writing a program. 0. Why Think? It helps us do most things: Hunting a sabre-toothed tiger

What about coding?

Nothing I have said implies anything abouthow you should code.

You still have to think while you code.

What you write while coding is code.

I have nothing to say about how you should code.

Use any programming language you want.

Use any coding methodology you want:test-driven development, agile programming, . . .

43

Page 347: Thinking Above the Code - microsoft.comHunting a sabre-toothed tiger. Building a house. Writing a program. 0. Why Think? It helps us do most things: Hunting a sabre-toothed tiger

What about coding?

Nothing I have said implies anything abouthow you should code.

You still have to think while you code.

What you write while coding is code.

I have nothing to say about how you should code.

Use any programming language you want.

Use any coding methodology you want:test-driven development, agile programming, . . .

43

Page 348: Thinking Above the Code - microsoft.comHunting a sabre-toothed tiger. Building a house. Writing a program. 0. Why Think? It helps us do most things: Hunting a sabre-toothed tiger

What about coding?

Nothing I have said implies anything abouthow you should code.

You still have to think while you code.

What you write while coding is code.

I have nothing to say about how you should code.

Use any programming language you want.

Use any coding methodology you want:test-driven development, agile programming, . . .

43

Page 349: Thinking Above the Code - microsoft.comHunting a sabre-toothed tiger. Building a house. Writing a program. 0. Why Think? It helps us do most things: Hunting a sabre-toothed tiger

What about coding?

Nothing I have said implies anything abouthow you should code.

You still have to think while you code.

What you write while coding is code.

I have nothing to say about how you should code.

Use any programming language you want.

Use any coding methodology you want:test-driven development, agile programming, . . .

43

Page 350: Thinking Above the Code - microsoft.comHunting a sabre-toothed tiger. Building a house. Writing a program. 0. Why Think? It helps us do most things: Hunting a sabre-toothed tiger

What about coding?

Nothing I have said implies anything abouthow you should code.

You still have to think while you code.

What you write while coding is code.

I have nothing to say about how you should code.

Use any programming language you want.

Use any coding methodology you want:test-driven development, agile programming, . . .

43

Page 351: Thinking Above the Code - microsoft.comHunting a sabre-toothed tiger. Building a house. Writing a program. 0. Why Think? It helps us do most things: Hunting a sabre-toothed tiger

You’ll still have to test and debug.

Writing specs is an additional step.

It may save time by catching errors early,when they’re easier to correct.

It will improve your programming,so you write better programs.

44

Page 352: Thinking Above the Code - microsoft.comHunting a sabre-toothed tiger. Building a house. Writing a program. 0. Why Think? It helps us do most things: Hunting a sabre-toothed tiger

You’ll still have to test and debug.

Writing specs is an additional step.

It may save time by catching errors early,when they’re easier to correct.

It will improve your programming,so you write better programs.

44

Page 353: Thinking Above the Code - microsoft.comHunting a sabre-toothed tiger. Building a house. Writing a program. 0. Why Think? It helps us do most things: Hunting a sabre-toothed tiger

You’ll still have to test and debug.

Writing specs is an additional step.

It may save time by catching errors early,when they’re easier to correct.

It will improve your programming,so you write better programs.

44

Page 354: Thinking Above the Code - microsoft.comHunting a sabre-toothed tiger. Building a house. Writing a program. 0. Why Think? It helps us do most things: Hunting a sabre-toothed tiger

You’ll still have to test and debug.

Writing specs is an additional step.

It may save time by catching errors early,when they’re easier to correct.

It will improve your programming,so you write better programs.

44

Page 355: Thinking Above the Code - microsoft.comHunting a sabre-toothed tiger. Building a house. Writing a program. 0. Why Think? It helps us do most things: Hunting a sabre-toothed tiger

Why are programmers reluctant to write specs?

Writing is hard.

44

Page 356: Thinking Above the Code - microsoft.comHunting a sabre-toothed tiger. Building a house. Writing a program. 0. Why Think? It helps us do most things: Hunting a sabre-toothed tiger

Why are programmers reluctant to write specs?

Writing is hard.

44

Page 357: Thinking Above the Code - microsoft.comHunting a sabre-toothed tiger. Building a house. Writing a program. 0. Why Think? It helps us do most things: Hunting a sabre-toothed tiger

Why is writing hard?

Writing requires thinking.

Thinking is hard.

It’s easier to think your thinking.

Writing is like running.

The less you do it, the slower you are.

You have to strengthen your writing muscles.

It takes practice.

It’s easier to find an excuse not to.

44

Page 358: Thinking Above the Code - microsoft.comHunting a sabre-toothed tiger. Building a house. Writing a program. 0. Why Think? It helps us do most things: Hunting a sabre-toothed tiger

Why is writing hard?

Writing requires thinking.

Thinking is hard.

It’s easier to think your thinking.

Writing is like running.

The less you do it, the slower you are.

You have to strengthen your writing muscles.

It takes practice.

It’s easier to find an excuse not to.

44

Page 359: Thinking Above the Code - microsoft.comHunting a sabre-toothed tiger. Building a house. Writing a program. 0. Why Think? It helps us do most things: Hunting a sabre-toothed tiger

Why is writing hard?

Writing requires thinking.

Thinking is hard.

It’s easier to think your thinking.

Writing is like running.

The less you do it, the slower you are.

You have to strengthen your writing muscles.

It takes practice.

It’s easier to find an excuse not to.

44

Page 360: Thinking Above the Code - microsoft.comHunting a sabre-toothed tiger. Building a house. Writing a program. 0. Why Think? It helps us do most things: Hunting a sabre-toothed tiger

Why is writing hard?

Writing requires thinking.

Thinking is hard.

It’s easier to think your thinking.

Writing is like running.

The less you do it, the slower you are.

You have to strengthen your writing muscles.

It takes practice.

It’s easier to find an excuse not to.

44

Page 361: Thinking Above the Code - microsoft.comHunting a sabre-toothed tiger. Building a house. Writing a program. 0. Why Think? It helps us do most things: Hunting a sabre-toothed tiger

Why is writing hard?

Writing requires thinking.

Thinking is hard.

It’s easier to think your thinking.

Writing is like running.

The less you do it, the slower you are.

You have to strengthen your writing muscles.

It takes practice.

It’s easier to find an excuse not to.

44

Page 362: Thinking Above the Code - microsoft.comHunting a sabre-toothed tiger. Building a house. Writing a program. 0. Why Think? It helps us do most things: Hunting a sabre-toothed tiger

Why is writing hard?

Writing requires thinking.

Thinking is hard.

It’s easier to think your thinking.

Writing is like running.

The less you do it, the slower you are.

You have to strengthen your writing muscles.

It takes practice.

It’s easier to find an excuse not to.

44

Page 363: Thinking Above the Code - microsoft.comHunting a sabre-toothed tiger. Building a house. Writing a program. 0. Why Think? It helps us do most things: Hunting a sabre-toothed tiger

Why is writing hard?

Writing requires thinking.

Thinking is hard.

It’s easier to think your thinking.

Writing is like running.

The less you do it, the slower you are.

You have to strengthen your writing muscles.

It takes practice.

It’s easier to find an excuse not to.

44

Page 364: Thinking Above the Code - microsoft.comHunting a sabre-toothed tiger. Building a house. Writing a program. 0. Why Think? It helps us do most things: Hunting a sabre-toothed tiger

Why is writing hard?

Writing requires thinking.

Thinking is hard.

It’s easier to think your thinking.

Writing is like running.

The less you do it, the slower you are.

You have to strengthen your writing muscles.

It takes practice.

It’s easier to find an excuse not to.

44

Page 365: Thinking Above the Code - microsoft.comHunting a sabre-toothed tiger. Building a house. Writing a program. 0. Why Think? It helps us do most things: Hunting a sabre-toothed tiger

Why is writing hard?

Writing requires thinking.

Thinking is hard.

It’s easier to think your thinking.

Writing is like running.

The less you do it, the slower you are.

You have to strengthen your writing muscles.

It takes practice.

It’s easier to find an excuse not to.

44

Page 366: Thinking Above the Code - microsoft.comHunting a sabre-toothed tiger. Building a house. Writing a program. 0. Why Think? It helps us do most things: Hunting a sabre-toothed tiger

What if the spec is wrong?

Maybe you made a mistake.

Maybe the requirements change,or an enhancement is needed.

The code will have to be changed,maybe even before the program is finished.

This eventually happens to all useful programs.

45

Page 367: Thinking Above the Code - microsoft.comHunting a sabre-toothed tiger. Building a house. Writing a program. 0. Why Think? It helps us do most things: Hunting a sabre-toothed tiger

What if the spec is wrong?

Maybe you made a mistake.

Maybe the requirements change,or an enhancement is needed.

The code will have to be changed,maybe even before the program is finished.

This eventually happens to all useful programs.

45

Page 368: Thinking Above the Code - microsoft.comHunting a sabre-toothed tiger. Building a house. Writing a program. 0. Why Think? It helps us do most things: Hunting a sabre-toothed tiger

What if the spec is wrong?

Maybe you made a mistake.

Maybe the requirements change,or an enhancement is needed.

The code will have to be changed,maybe even before the program is finished.

This eventually happens to all useful programs.

45

Page 369: Thinking Above the Code - microsoft.comHunting a sabre-toothed tiger. Building a house. Writing a program. 0. Why Think? It helps us do most things: Hunting a sabre-toothed tiger

What if the spec is wrong?

Maybe you made a mistake.

Maybe the requirements change,or an enhancement is needed.

The code will have to be changed,maybe even before the program is finished.

This eventually happens to all useful programs.

45

Page 370: Thinking Above the Code - microsoft.comHunting a sabre-toothed tiger. Building a house. Writing a program. 0. Why Think? It helps us do most things: Hunting a sabre-toothed tiger

What if the spec is wrong?

Maybe you made a mistake.

Maybe the requirements change,or an enhancement is needed.

The code will have to be changed,maybe even before the program is finished.

This eventually happens to all useful programs.

45

Page 371: Thinking Above the Code - microsoft.comHunting a sabre-toothed tiger. Building a house. Writing a program. 0. Why Think? It helps us do most things: Hunting a sabre-toothed tiger

In an ideal world, a new spec would be writtenand the code completely rewritten.

In the real world, the code is patchedand maybe the spec is updated.

If this is inevitable, why write specs?

45

Page 372: Thinking Above the Code - microsoft.comHunting a sabre-toothed tiger. Building a house. Writing a program. 0. Why Think? It helps us do most things: Hunting a sabre-toothed tiger

In an ideal world, a new spec would be writtenand the code completely rewritten.

In the real world, the code is patchedand maybe the spec is updated.

If this is inevitable, why write specs?

45

Page 373: Thinking Above the Code - microsoft.comHunting a sabre-toothed tiger. Building a house. Writing a program. 0. Why Think? It helps us do most things: Hunting a sabre-toothed tiger

In an ideal world, a new spec would be writtenand the code completely rewritten.

In the real world, the code is patchedand maybe the spec is updated.

If this is inevitable, why write specs?

45

Page 374: Thinking Above the Code - microsoft.comHunting a sabre-toothed tiger. Building a house. Writing a program. 0. Why Think? It helps us do most things: Hunting a sabre-toothed tiger

Reason 1

Whoever has to modify the code will be grateful forevery word or formula of spec you write.

And “whoever” may be you.

That’s why you should update the spec whenchanging the code.

45

Page 375: Thinking Above the Code - microsoft.comHunting a sabre-toothed tiger. Building a house. Writing a program. 0. Why Think? It helps us do most things: Hunting a sabre-toothed tiger

Reason 1

Whoever has to modify the code will be grateful forevery word or formula of spec you write.

And “whoever” may be you.

That’s why you should update the spec whenchanging the code.

45

Page 376: Thinking Above the Code - microsoft.comHunting a sabre-toothed tiger. Building a house. Writing a program. 0. Why Think? It helps us do most things: Hunting a sabre-toothed tiger

Reason 1

Whoever has to modify the code will be grateful forevery word or formula of spec you write.

And “whoever” may be you.

That’s why you should update the spec whenchanging the code.

45

Page 377: Thinking Above the Code - microsoft.comHunting a sabre-toothed tiger. Building a house. Writing a program. 0. Why Think? It helps us do most things: Hunting a sabre-toothed tiger

Reason 1

Whoever has to modify the code will be grateful forevery word or formula of spec you write.

And “whoever” may be you.

That’s why you should update the spec whenchanging the code.

45

Page 378: Thinking Above the Code - microsoft.comHunting a sabre-toothed tiger. Building a house. Writing a program. 0. Why Think? It helps us do most things: Hunting a sabre-toothed tiger

Reason 2

Every time code is patched, it becomes a little uglier,harder to understand, and harder to maintain.

If you don’t start with a spec, every piece of the codeyou write is a patch.

The program starts out ugly, hard to understand,and hard to maintain.

“No battle was ever won according to plan,but no battle was ever won without one.”

Dwight D. Eisenhower

46

Page 379: Thinking Above the Code - microsoft.comHunting a sabre-toothed tiger. Building a house. Writing a program. 0. Why Think? It helps us do most things: Hunting a sabre-toothed tiger

Reason 2

Every time code is patched, it becomes a little uglier,harder to understand, and harder to maintain.

If you don’t start with a spec, every piece of the codeyou write is a patch.

The program starts out ugly, hard to understand,and hard to maintain.

“No battle was ever won according to plan,but no battle was ever won without one.”

Dwight D. Eisenhower

46

Page 380: Thinking Above the Code - microsoft.comHunting a sabre-toothed tiger. Building a house. Writing a program. 0. Why Think? It helps us do most things: Hunting a sabre-toothed tiger

Reason 2

Every time code is patched, it becomes a little uglier,harder to understand, and harder to maintain.

If you don’t start with a spec, every piece of the codeyou write is a patch.

The program starts out ugly, hard to understand,and hard to maintain.

“No battle was ever won according to plan,but no battle was ever won without one.”

Dwight D. Eisenhower

46

Page 381: Thinking Above the Code - microsoft.comHunting a sabre-toothed tiger. Building a house. Writing a program. 0. Why Think? It helps us do most things: Hunting a sabre-toothed tiger

Reason 2

Every time code is patched, it becomes a little uglier,harder to understand, and harder to maintain.

If you don’t start with a spec, every piece of the codeyou write is a patch.

The program starts out ugly, hard to understand,and hard to maintain.

“No battle was ever won according to plan,but no battle was ever won without one.”

Dwight D. Eisenhower

46

Page 382: Thinking Above the Code - microsoft.comHunting a sabre-toothed tiger. Building a house. Writing a program. 0. Why Think? It helps us do most things: Hunting a sabre-toothed tiger

Reason 2

Every time code is patched, it becomes a little uglier,harder to understand, and harder to maintain.

If you don’t start with a spec, every piece of the codeyou write is a patch.

The program starts out ugly, hard to understand,and hard to maintain.

“No battle was ever won according to plan,but no battle was ever won without one.”

Dwight D. Eisenhower

46

Page 383: Thinking Above the Code - microsoft.comHunting a sabre-toothed tiger. Building a house. Writing a program. 0. Why Think? It helps us do most things: Hunting a sabre-toothed tiger

Reason 2

Every time code is patched, it becomes a little uglier,harder to understand, and harder to maintain.

If you don’t start with a spec, every piece of the codeyou write is a patch.

The program starts out ugly, hard to understand,and hard to maintain.

“No battle was ever won according to plan,but no battle was ever won without one.”

Dwight D. Eisenhower

46

Page 384: Thinking Above the Code - microsoft.comHunting a sabre-toothed tiger. Building a house. Writing a program. 0. Why Think? It helps us do most things: Hunting a sabre-toothed tiger

Some people will tell you that writing specs is a waste of time.

In some situations it is. Sometimes there’s no need to thinkabout what you’re doing.

But remember: when they’re telling you not to write a spec,they’re really telling you not to think.

47

Page 385: Thinking Above the Code - microsoft.comHunting a sabre-toothed tiger. Building a house. Writing a program. 0. Why Think? It helps us do most things: Hunting a sabre-toothed tiger

Some people will tell you that writing specs is a waste of time.

In some situations it is. Sometimes there’s no need to thinkabout what you’re doing.

But remember: when they’re telling you not to write a spec,they’re really telling you not to think.

47

Page 386: Thinking Above the Code - microsoft.comHunting a sabre-toothed tiger. Building a house. Writing a program. 0. Why Think? It helps us do most things: Hunting a sabre-toothed tiger

Some people will tell you that writing specs is a waste of time.

In some situations it is. Sometimes there’s no need to thinkabout what you’re doing.

But remember: when they’re telling you not to write a spec,they’re really telling you not to think.

47

Page 387: Thinking Above the Code - microsoft.comHunting a sabre-toothed tiger. Building a house. Writing a program. 0. Why Think? It helps us do most things: Hunting a sabre-toothed tiger

Some people will tell you that writing specs is a waste of time.

In some situations it is. Sometimes there’s no need to thinkabout what you’re doing.

But remember: when they’re telling you not to write a spec,they’re really telling you not to think.

47

Page 388: Thinking Above the Code - microsoft.comHunting a sabre-toothed tiger. Building a house. Writing a program. 0. Why Think? It helps us do most things: Hunting a sabre-toothed tiger

Thinking doesn’t guarantee that you won’t make mistakes.

Not thinking usually guarantees that you will.

47

Page 389: Thinking Above the Code - microsoft.comHunting a sabre-toothed tiger. Building a house. Writing a program. 0. Why Think? It helps us do most things: Hunting a sabre-toothed tiger

Thinking doesn’t guarantee that you won’t make mistakes.

Not thinking usually guarantees that you will.

47

Page 390: Thinking Above the Code - microsoft.comHunting a sabre-toothed tiger. Building a house. Writing a program. 0. Why Think? It helps us do most things: Hunting a sabre-toothed tiger

To find out more about TLA+, go to my homepage and click on:

The TLA Web Page

47

Page 391: Thinking Above the Code - microsoft.comHunting a sabre-toothed tiger. Building a house. Writing a program. 0. Why Think? It helps us do most things: Hunting a sabre-toothed tiger

To find out more about TLA+, go to my homepage and click on:

The TLA Web Page

Thank You

47