Formal Verification · All levels

Safety vs Liveness, Strong vs Weak: Worked Example

Worked Example for Safety vs Liveness, Strong vs Weak.

Worked example

Worked Example for Safety vs Liveness, Strong vs Weak is anchored on non-vacuous closure rate, counterexample turnaround, and residual-risk trend by requirement class. Convert outcomes into assumption-aware, evidence-backed actions.

A regression appears in non-vacuous closure rate, counterexample turnaround, and residual-risk trend by requirement class. Strong closure isolates first divergence, proves mechanism, applies one reversible fix, and validates blast radius before signoff.

Execution lens

diagram
FORMAL EXECUTION FLOW - Safety vs Liveness, Strong vs Weak

requirement intent and risk class
      |
      v
property and assumption modeling
      |
      v
proof engine exploration and trace extraction
      |
      v
counterexample classification and fix hypothesis
      |
      v
re-proof, coverage audit, and signoff decision

Decision matrix

diagram
EVIDENCE MATRIX - Safety vs Liveness, Strong vs Weak

+-----------------------------+--------------------------------+--------------------------------+---------------------------+
| Evidence                    | Tells you                      | Does not prove                 | Next action               |
+-----------------------------+--------------------------------+--------------------------------+---------------------------+
| property status by class    | closure shape by requirement   | model realism                  | pair with cover reachability |
| vacuity and trigger checks  | assertion meaningfulness       | full legal-path exploration    | inspect assumptions       |
| counterexample traces       | concrete divergence path       | complete bug-space closure     | classify and replay       |
| assumption audit trail      | model boundary confidence      | implementation correctness     | review spec traceability  |
| before/after trend packet   | mitigation movement quality    | long-window stability          | run broader matrix        |
+-----------------------------+--------------------------------+--------------------------------+---------------------------+

Formal deep dive

SVA scales when temporal intent, clock sampling, and reset gating are precise enough to be replayed and reviewed.

Concept diagram

diagram
SVA INTENT CHAIN

timing contract -> sequence composition -> property implication -> sampled failure trace

Metric graph

diagram
ASSERTION QUALITY SIGNALS

non-vacuous hit rate    ████████
clock/reset mismatches  ████
false-positive churn    ███

Metrics and artifacts to collect

  • assertion trigger hit-rate

  • implication timing mismatch bucket

  • reset-window noise ratio

  • assertion decomposition quality score

Mini case study

A protocol failure vanished after correcting `|->` vs `|=>` semantics and reset masking boundaries.

Debug branches

  • Confirm antecedent trigger at sampled clock edges.

  • Verify implication operator matches protocol timing contract.

  • Split monolithic properties into stage-local checks.

Senior review question

Ask: which requirement intent is proven, under which assumptions, and what residual risk remains?

Key takeaways

  • Tie each proof claim to assumption boundaries and reachability evidence.

  • Prefer minimal reversible fixes and preserve legal behavior visibility.

Common pitfalls

  • Treating runtime reduction as proof-quality improvement without audits.

  • Declaring closure while critical covers remain unreachable.

  • Using broad waivers instead of first-divergence root-cause ownership.

Worked-example reasoning

Start from requirement intent and map every trace event back to modeled obligations.

Close with smallest fix that preserves legal scenario reachability.