• @[email protected]
    link
    fedilink
    11
    edit-2
    1 year ago

    The problem with formal proofs for code is that it assumes the spec/requirements are complete and bug-free.

    I find most bugs come from missed or misinterpreted requirements.

    • @[email protected]
      link
      fedilink
      25
      edit-2
      1 year ago

      I have a feeling you are misunderstanding what is meant by “theorems for free” here. For example, one theorem that is proven by all safe Rust programs is that they don’t have data races. That should always be a requirement for functional software. This is a more pragmatic type of automatic theorem proving that doesn’t require a direct proof from the code author. The compiler does the proof for you. Otherwise the theorem would not be “free” as stated in OP.