Using Penelope to assess the correctness of NASA Ada software: A demonstration of formal methods as a counterpart to testing

Carl T. Eichenlaub, C. Douglas Harper, Geoffrey R. Hird · NASA Technical Reports Server (NASA) · 1993

Life-critical applications warrant a higher level of software reliability than has yet been achieved. Since it is not certain that traditional methods alone can provide the required ultra reliability, new methods should be examined as supplements or replacements. This paper describes a mathematical counterpart to the traditional process of empirical testing. ORA's Penelope verification system is demonstrated as a tool for evaluating the correctness of Ada software. Grady Booch's Ada calendar utility package, obtained through NASA, was specified in the Larch/Ada language. Formal verification in the Penelope environment established that many of the package's subprograms met their specifications. In other subprograms, failed attempts at verification revealed several errors that had escaped detection by testing.

Read the paper · More papers on PaperTik