Formal Verification · All levels
BMC vs Unbounded Proof Strategies: Debug Playbook
Debug Playbook for BMC vs Unbounded Proof Strategies.
Debug playbook
Debug Playbook for BMC vs Unbounded Proof Strategies is anchored on Bound depth achieved, k-induction success rate, and ratio of bug-find to full-proof properties.. Convert outcomes into assumption-aware, evidence-backed actions.
Freeze assumptions, RTL hash, and engine metadata.
Locate first divergence cycle and classify source.
Classify mechanism: model mismatch, weak property, setup issue, or RTL defect.
Apply one focused reproducer and one bounded fix.
Re-run sibling properties and critical covers before closure.
Review memo template
FORMAL REVIEW MEMO - Proof Engines & Convergence / BMC vs Unbounded Proof Strategies
1. Symptom
- Failing metric: Bound depth achieved, k-induction success rate, and ratio of bug-find to full-proof properties.
- Trigger context: <mode/reset/env assumptions>
- First divergence boundary: <model/property/rtl>
2. Mechanism hypothesis
- Candidate mechanism: Bounded model checking (BMC) searches for counterexamples up to depth k and is excellent for quickly finding shallow bugs, initialization escapes, and protocol startup issues. Unbounded proof attempts establish correctness for all time, typically through induction, interpolation, IC3/PDR-style fixed-point reasoning, or hybrid engine orchestration. K-induction bridges these worlds by proving a base case and inductive step, but it often needs strengthening invariants and helper assertions before convergence. Teams should classify properties early into bug-hunting, bounded-signoff, or unbounded-signoff intent so runtime budgets and expectations stay realistic.
- Competing hypotheses: weak property, over-constraint, setup mismatch, rtl bug
- Missing evidence: <trace, vacuity report, cover status>
3. Proposed action
- Smallest reversible change: <assumption/property/rtl>
- Expected movement: <closure quality, runtime, bug isolation>
- Regression risk: hidden legal behavior, false pass, schedule churn
4. Signoff
- Required artifact: Proof intent matrix mapping each property to BMC depth goals, unbounded targets, and escalation criteria.
- Required owners: formal verification owner, microarchitecture owner, verification lead, quality/signoff owner
- Final decision: close, bounded closure, rollback, or escalateFormal deep dive
Convergence requires engine strategy, invariant quality, and model realism to move together with measurable progress.
Concept diagram
CONVERGENCE DECISION FLOW
property bucket -> engine strategy -> helper invariants -> convergence audit -> closureMetric graph
CONVERGENCE BURNDOWN
open hard properties ███████
inconclusive aging █████
closed with audit ████████Metrics and artifacts to collect
engine effectiveness by property class
induction and helper-lemma success ratio
stalled-property aging dashboard
runtime vs closure-quality movement
Mini case study
A stalled set closed only after case-splitting by mode and auditing fairness assumptions for realism.
Debug branches
Bucket properties by structure and intent before tuning.
Inspect proof core stability, not runtime alone.
Reject speed gains that reduce legal reachability.
Senior review question
Ask: which requirement intent is proven, under which assumptions, and what residual risk remains?
Key takeaways
Tie each proof claim to assumption boundaries and reachability evidence.
Prefer minimal reversible fixes and preserve legal behavior visibility.
Common pitfalls
Treating runtime reduction as proof-quality improvement without audits.
Declaring closure while critical covers remain unreachable.
Using broad waivers instead of first-divergence root-cause ownership.
Debug ladder
Sequence: reproduce -> classify -> isolate first divergence -> patch -> revalidate sibling properties.
Avoid mixing assumption and RTL fixes in the same experiment.