summaryrefslogtreecommitdiff
path: root/search
diff options
context:
space:
mode:
authorPaul Buetow <paul@buetow.org>2026-07-06 10:15:56 +0300
committerPaul Buetow <paul@buetow.org>2026-07-06 10:15:56 +0300
commitf74812f8eda48194b622bdd318f35d3a6b6328cd (patch)
tree074784495e62f418d9ba4071e824028e8a3daf8c /search
parent7aa41c07d15619512a490a0416a504e3200ebf85 (diff)
Add layered formal-verification harness
Adds four complementary layers to verify correctness, all runnable locally, weakest-but-broadest to strongest-but-narrowest: 0. Paper proofs (docs/verification.md): Hoare invariants, termination measures, and permutation arguments for every algorithm. 1. Property tests (sort/property_test.go): testing/quick asserting ordering AND permutation for every sort. Closes a real gap -- the existing tests only checked .Sorted(), so a sort dropping/duplicating elements passed. 2. make verify: go vet + staticcheck + go test -race -short, with -short gating of the large sizes in sort/search tests so the race build is quick. 3. make verify-model: TLA+/TLC model check of sleep sort (termination, deadlock-freedom, sorted permutation) -- formal/tla/. 4. make verify-formal: Gobra deductive proof (Viper+Z3) that a monomorphized insertion sort is memory-safe and sorted for all inputs -- formal/. The static layer already found a latent bug: hash() used key<<10 on a generic integer, which silently yields 0 for narrow key types (int8), degrading the hash. Tests missed it because they only use int keys. Fixed by mixing in int64; documented extensively in docs/case-study-hash-shift-bug.md. Also cleans up dead code and a blank-identifier range flagged by staticcheck. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Diffstat (limited to 'search')
-rw-r--r--search/hash.go9
-rw-r--r--search/search_test.go8
2 files changed, 16 insertions, 1 deletions
diff --git a/search/hash.go b/search/hash.go
index 0b41b6b..7302d1a 100644
--- a/search/hash.go
+++ b/search/hash.go
@@ -26,7 +26,14 @@ func (h *Hash[K,V]) Size() int {
}
func (h *Hash[K,V]) hash(key K) int {
- i := key + key*2 + key<<10 + key>>2
+ // Mix the key in a full-width int64 rather than in K. K is any ds.Integer,
+ // so for a narrow type (e.g. int8) the "key<<10" term would shift past the
+ // type width and vanish to 0, destroying the intended high-bit mixing (and
+ // go vet rightly flags it). Widening to int64 first keeps the result
+ // identical for 64-bit int keys while making the mix well-defined for every
+ // integer width.
+ i := int64(key)
+ i = i + i*2 + i<<10 + i>>2
if i < 0 {
i = -i
}
diff --git a/search/search_test.go b/search/search_test.go
index 36ef4bf..b2c167a 100644
--- a/search/search_test.go
+++ b/search/search_test.go
@@ -45,7 +45,15 @@ func TestGoMap(t *testing.T) {
}
}
+// shortMaxLength caps the largest input size exercised under `go test -short`
+// (used by `make verify`, which runs under the race detector). The full range
+// still runs in a plain `make test`.
+const shortMaxLength int = 1000
+
func test[K ds.Integer, V ds.Number](s Set[K,V], l int, t *testing.T) {
+ if testing.Short() && l > shortMaxLength {
+ t.Skipf("skipping size %d in -short mode", l)
+ }
keys := ds.NewRandomArrayList[K](l, l)
randoms := ds.NewRandomArrayList[V](l, -1)
mapping := make(map[K]V, l)