|
|
|
|
|
by auggierose
21 days ago
|
|
I wouldn’t split it like that. Formal verification is useful in the case that the spec is simpler than the implementation. That’s it. Coming up with simple specs is not necessarily easy. You could say that is kind of what math is about. That’s how we actually make progress: find those cases where simple specs are possible and build upon them. That’s the kind of library made for eternity. |
|