Deep specification and proof preservation for the CoqTL transformation language

被引:0
作者
Cheng, Zheng [1 ]
Tisi, Massimo [2 ]
机构
[1] Univ Lorraine, INRIA, LORIA, CNRS, Nancy, France
[2] IMT Atlantique, LS2N UMR CNRS 6004, Nantes, France
关键词
MDE; Model transformation; Programming language implementation; Certification; Theorem proving; Coq; MODEL; VERIFICATION; ATL;
D O I
10.1007/s10270-022-01004-1
中图分类号
TP31 [计算机软件];
学科分类号
081202 ; 0835 ;
摘要
Executable engines for relational model-transformation languages evolve continuously because of language extension, performance improvement and bug fixes. While new versions generally change the engine semantics, end-users expect to get backward-compatibility guarantees, so that existing transformations do not need to be adapted at every engine update. The CoqTL model-transformation language allows users to define model transformations, theorems on their behavior and machine-checked proofs of these theorems in Coq. Backward-compatibility for CoqTL involves also the preservation of these proofs. However, proof preservation is challenging, as proofs are easily broken even by small refactorings of the code they verify. In this paper, we present the solution we designed for the evolution of CoqTL. We provide a deep specification of the transformation engine, including a set of theorems that must hold against the engine implementation. Then, at each milestone in the engine development, we certify the new version of the engine against this specification, by providing proofs of the impacted theorems. The certification formally guarantees end-users that all the proofs they write using the provided theorems will be preserved through engine updates. We illustrate the structure of the deep specification theorems, we produce a machine-checked certification of three versions of CoqTL against it, and we show examples of user proofs that leverage this specification and are thus preserved through the updates. Finally, we discuss the evolution of the deep specification by an extension mechanism, we present an evolution that introduces trace links in the specification, and we show which user proofs are preserved through specification evolutions.
引用
收藏
页码:1831 / 1852
页数:22
相关论文
共 51 条
[1]   A survey of approaches for verifying model transformations [J].
Ab Rahim, Lukman ;
Whittle, Jon .
SOFTWARE AND SYSTEMS MODELING, 2015, 14 (02) :1003-1028
[2]   Position paper: the science of deep specification [J].
Appel, Andrew W. ;
Beringer, Lennart ;
Chlipala, Adam ;
Pierce, Benjamin C. ;
Shao, Zhong ;
Weirich, Stephanie ;
Zdancewic, Steve .
PHILOSOPHICAL TRANSACTIONS OF THE ROYAL SOCIETY A-MATHEMATICAL PHYSICAL AND ENGINEERING SCIENCES, 2017, 375 (2104)
[3]  
ATLAS Group, 2005, Technical Report
[4]   Barriers to Systematic Model Transformation Testing [J].
Baudry, Benoit ;
Ghosh, Sudipto ;
Fleurey, Franck ;
France, Robert ;
Le Traon, Yves ;
Mottu, Jean-Marie .
COMMUNICATIONS OF THE ACM, 2010, 53 (06) :139-143
[5]  
Benzaken V., 2018, 9 INT C INT THEOR PR, P88107
[6]  
Benzaken V., 2019, 8 ACM SIGPLAN INT C
[7]  
Berry, 2008, 12 INT WORKSH FORM M, P22
[8]  
Bodin M., 2014, 41 ACM SIGPLAN SIGAC, P87100
[9]   Experimentation with a Big-Step Semantics for ATL Model Transformations [J].
Boronat, Artur .
THEORY AND PRACTICE OF MODEL TRANSFORMATION, 2017, 10374 :3-18
[10]  
Bttner F., 2012, 15 INT C MOD DRIV EN