summaryrefslogtreecommitdiff
path: root/staticcheck.conf
diff options
context:
space:
mode:
authorPaul Buetow <paul@buetow.org>2026-07-06 10:15:56 +0300
committerPaul Buetow <paul@buetow.org>2026-07-06 10:15:56 +0300
commitf74812f8eda48194b622bdd318f35d3a6b6328cd (patch)
tree074784495e62f418d9ba4071e824028e8a3daf8c /staticcheck.conf
parent7aa41c07d15619512a490a0416a504e3200ebf85 (diff)
Add layered formal-verification harness
Adds four complementary layers to verify correctness, all runnable locally, weakest-but-broadest to strongest-but-narrowest: 0. Paper proofs (docs/verification.md): Hoare invariants, termination measures, and permutation arguments for every algorithm. 1. Property tests (sort/property_test.go): testing/quick asserting ordering AND permutation for every sort. Closes a real gap -- the existing tests only checked .Sorted(), so a sort dropping/duplicating elements passed. 2. make verify: go vet + staticcheck + go test -race -short, with -short gating of the large sizes in sort/search tests so the race build is quick. 3. make verify-model: TLA+/TLC model check of sleep sort (termination, deadlock-freedom, sorted permutation) -- formal/tla/. 4. make verify-formal: Gobra deductive proof (Viper+Z3) that a monomorphized insertion sort is memory-safe and sorted for all inputs -- formal/. The static layer already found a latent bug: hash() used key<<10 on a generic integer, which silently yields 0 for narrow key types (int8), degrading the hash. Tests missed it because they only use int keys. Fixed by mixing in int64; documented extensively in docs/case-study-hash-shift-bug.md. Also cleans up dead code and a blank-identifier range flagged by staticcheck. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Diffstat (limited to 'staticcheck.conf')
-rw-r--r--staticcheck.conf6
1 files changed, 6 insertions, 0 deletions
diff --git a/staticcheck.conf b/staticcheck.conf
new file mode 100644
index 0000000..939bace
--- /dev/null
+++ b/staticcheck.conf
@@ -0,0 +1,6 @@
+# The `verify` make target uses staticcheck as a correctness gate. We inherit
+# staticcheck's default analyzers (bug detection SA*, simplifications S*, unused
+# code U*) but disable ST1012, a purely cosmetic convention that error variables
+# be named ErrFoo. Renaming the package's existing NotFound/NotImplemented would
+# be lint churn unrelated to verification, so it is intentionally not enforced.
+checks = ["inherit", "-ST1012"]