examples

A collection of TLA⁺ specifications of varying complexities.

https://github.com/tlaplus/examples

Science Score: 77.0%

This score indicates how likely this project is to be science-related based on various indicators:

  • CITATION.cff file
    Found CITATION.cff file
  • codemeta.json file
    Found codemeta.json file
  • .zenodo.json file
    Found .zenodo.json file
  • DOI references
    Found 1 DOI reference(s) in README
  • Academic publication links
    Links to: acm.org
  • Committers with academic emails
    3 of 49 committers (6.1%) from academic institutions
  • Institutional organization owner
  • JOSS paper metadata
  • Scientific vocabulary similarity
    Low similarity (11.8%) to scientific vocabulary

Keywords

pluscal tlaplus
Last synced: 6 months ago · JSON representation ·

Repository

A collection of TLA⁺ specifications of varying complexities.

Basic Info
  • Host: GitHub
  • Owner: tlaplus
  • License: other
  • Language: TLA
  • Default Branch: master
  • Homepage:
  • Size: 27.2 MB
Statistics
  • Stars: 1,394
  • Watchers: 44
  • Forks: 210
  • Open Issues: 14
  • Releases: 2
Topics
pluscal tlaplus
Created almost 10 years ago · Last pushed 6 months ago
Metadata Files
Readme Contributing License Citation

README.md

TLA+ Examples

Gitpod ready-to-code Validate Specs & Models

This is a repository of TLA+ specifications and models covering applications in a variety of fields. It serves as: - a comprehensive example library demonstrating how to specify an algorithm in TLA+ - a diverse corpus facilitating development & testing of TLA+ language tools - a collection of case studies in the application of formal specification in TLA+

All TLA+ specs can be found in the specifications directory. To contribute a spec of your own, see CONTRIBUTING.md.

The table below lists all specs and indicates whether a spec is beginner-friendly, includes an additional PlusCal variant (✔), or uses PlusCal exclusively. Additionally, the table specifies which verification tool—TLC, Apalache, or TLAPS—can be used to verify each specification.

Space contraints limit the information displayed in the table; detailed spec metadata can be found in the manifest.json files in each specification's directory. You can search these files for examples exhibiting a number of features, either using the GitHub repository search or locally with the command ls specifications/*/manifest.json | xargs grep -l $keyword, where $keyword can be a value like: - pluscal, proof, or action composition (the \cdot operator) - Specs intended for trace generation (generate), simulate, or checked symbolically with Apalache (symbolic) - Models failing in interesting ways, like deadlock failure, safety failure, liveness failure, or assumption failure

It is also helpful to consult model files using specific TLC features. For this, run ls specifications/*/*.cfg | xargs grep -l $keyword, where $keyword can be a feature like SYMMETRY, VIEW, ALIAS, CONSTRAINT, or DEADLOCK.

Validated Examples Included Here

Here is a list of specs included in this repository which are validated by the CI, with links to the relevant directory and flags for various features: | Name | Author(s) | Beginner | TLAPS Proof | PlusCal | TLC Model | Apalache | | --------------------------------------------------------------------------------------------------- | --------------------------------------------------- | :------: | :---------: | :-----: | :-------: | :------: | | Teaching Concurrency | Leslie Lamport | ✔ | ✔ | ✔ | ✔ | | | Loop Invariance | Leslie Lamport | ✔ | ✔ | ✔ | ✔ | | | Learn TLA⁺ Proofs | Andrew Helwer | ✔ | ✔ | ✔ | ✔ | | | Boyer-Moore Majority Vote | Stephan Merz | ✔ | ✔ | | ✔ | | | Proof x+x is Even | Martin Riener | ✔ | ✔ | | ✔ | | | The N-Queens Puzzle | Stephan Merz | ✔ | | ✔ | ✔ | | | The Dining Philosophers Problem | Jeff Hemphill | ✔ | | ✔ | ✔ | | | The Car Talk Puzzle | Leslie Lamport | ✔ | | | ✔ | | | The Die Hard Problem | Leslie Lamport | ✔ | | | ✔ | | | The Prisoners & Switches Puzzle | Leslie Lamport | ✔ | | | ✔ | | | The Prisoners & Switch Puzzle | Florian Schanda | ✔ | | | ✔ | | | Specs from Specifying Systems | Leslie Lamport | ✔ | | | ✔ | | | The Tower of Hanoi Puzzle | Markus Kuppe, Alexander Niederbühl | ✔ | | | ✔ | | | Missionaries and Cannibals | Leslie Lamport | ✔ | | | ✔ | | | Stone Scale Puzzle | Leslie Lamport | ✔ | | | ✔ | | | The Coffee Can Bean Problem | Andrew Helwer | ✔ | | | ✔ | | | EWD687a: Detecting Termination in Distributed Computations | Stephan Merz, Leslie Lamport, Markus Kuppe | ✔ | | (✔) | ✔ | | | The Moving Cat Puzzle | Florian Schanda | ✔ | | | ✔ | | | The Boulangerie Algorithm | Leslie Lamport, Stephan Merz | | ✔ | ✔ | ✔ | | | Misra Reachability Algorithm | Leslie Lamport | | ✔ | ✔ | ✔ | | | Byzantizing Paxos by Refinement | Leslie Lamport | | ✔ | ✔ | ✔ | | | Barrier Synchronization | Jarod Differdange | | ✔ | ✔ | ✔ | | | Peterson Lock Refinement With Auxiliary Variables | Jarod Differdange | | ✔ | ✔ | ✔ | | | EWD840: Termination Detection in a Ring | Stephan Merz | | ✔ | | ✔ | | | EWD998: Termination Detection in a Ring with Asynchronous Message Delivery | Stephan Merz, Markus Kuppe | | ✔ | (✔) | ✔ | | | The Paxos Protocol | Leslie Lamport | | (✔) | | ✔ | | | Asynchronous Reliable Broadcast | Thanh Hai Tran, Igor Konnov, Josef Widder | | ✔ | | ✔ | | | Distributed Mutual Exclusion | Stephan Merz | | ✔ | | ✔ | | | Two-Phase Handshaking | Leslie Lamport, Stephan Merz | | ✔ | | ✔ | | | Paxos (How to Win a Turing Award) | Leslie Lamport | | (✔) | | ✔ | | | Finitizing Monotonic Systems | Andrew Helwer, Stephan Merz, Markus Kuppe | | ✔ | | ✔ | | | Dijkstra's Mutual Exclusion Algorithm | Leslie Lamport | | | ✔ | ✔ | | | The Echo Algorithm | Stephan Merz | | | ✔ | ✔ | | | The TLC Safety Checking Algorithm | Markus Kuppe | | | ✔ | ✔ | | | Transaction Commit Models | Leslie Lamport, Jim Gray, Murat Demirbas | | | ✔ | ✔ | | | The Slush Protocol | Andrew Helwer | | | ✔ | ✔ | | | Minimal Circular Substring | Andrew Helwer | | | ✔ | ✔ | | | Snapshot Key-Value Store | Andrew Helwer, Murat Demirbas | | | ✔ | ✔ | | | Chang-Roberts Algorithm for Leader Election in a Ring | Stephan Merz | | | ✔ | ✔ | | | MultiPaxos in SMR-Style | Guanzhou Hu | | | ✔ | ✔ | | | Einstein's Riddle | Isaac DeFrain, Giuliano Losa | | | | | ✔ | | Resource Allocator | Stephan Merz | | | | ✔ | | | Transitive Closure | Stephan Merz | | | | ✔ | | | Atomic Commitment Protocol | Stephan Merz | | | | ✔ | | | SWMR Shared Memory Disk Paxos | Leslie Lamport, Giuliano Losa | | | | ✔ | | | Span Tree Exercise | Leslie Lamport | | | | ✔ | | | The Knuth-Yao Method | Ron Pressler, Markus Kuppe | | | | ✔ | | | Huang's Algorithm | Markus Kuppe | | | | ✔ | | | EWD 426: Token Stabilization | Murat Demirbas, Markus Kuppe | | | | ✔ | | | Sliding Block Puzzle | Mariusz Ryndzionek | | | | ✔ | | | Single-Lane Bridge Problem | Younes Akhouayri | | | | ✔ | | | Software-Defined Perimeter | Luming Dong, Zhi Niu | | | | ✔ | | | Simplified Fast Paxos | Lim Ngian Xin Terry, Gaurav Gandhi | | | | ✔ | | | Checkpoint Coordination | Andrew Helwer | | | | ✔ | | | Multi-Car Elevator System | Andrew Helwer | | | | ✔ | | | Nano Blockchain Protocol | Andrew Helwer | | | | ✔ | | | The Readers-Writers Problem | Isaac DeFrain | | | | ✔ | | | Asynchronous Byzantine Consensus | Thanh Hai Tran, Igor Konnov, Josef Widder | | | | ✔ | | | Folklore Reliable Broadcast | Thanh Hai Tran, Igor Konnov, Josef Widder | | | | ✔ | | | The Bosco Byzantine Consensus Algorithm | Thanh Hai Tran, Igor Konnov, Josef Widder | | | | ✔ | | | Consensus in One Communication Step | Thanh Hai Tran, Igor Konnov, Josef Widder | | | | ✔ | | | One-Step Consensus with Zero-Degradation | Thanh Hai Tran, Igor Konnov, Josef Widder | | | | ✔ | | | Failure Detector | Thanh Hai Tran, Igor Konnov, Josef Widder | | | | ✔ | | | Asynchronous Non-Blocking Atomic Commit | Thanh Hai Tran, Igor Konnov, Josef Widder | | | | ✔ | | | Asynchronous Non-Blocking Atomic Commitment with Failure Detectors | Thanh Hai Tran, Igor Konnov, Josef Widder | | | | ✔ | | | Spanning Tree Broadcast Algorithm | Thanh Hai Tran, Igor Konnov, Josef Widder | | | | ✔ | | | The Cigarette Smokers Problem | Mariusz Ryndzionek | | | | ✔ | | | Conway's Game of Life | Mariusz Ryndzionek | | | | ✔ | | | Chameneos, a Concurrency Game | Mariusz Ryndzionek | | | | ✔ | | | PCR Testing for Snippets of DNA | Martin Harrison | | | | ✔ | | | RFC 3506: Voucher Transaction System | Santhosh Raju, Cherry G. Mathew, Fransisca Andriani | | | | ✔ | | | Yo-Yo Leader Election | Ludovic Yvoz, Stephan Merz | | | | ✔ | | | TCP as defined in RFC 9293 | Markus Kuppe | | | | ✔ | | | B-trees | Lorin Hochstein | | | | ✔ | | | TLA⁺ Level Checking | Leslie Lamport | | | | | | | Condition-Based Consensus | Thanh Hai Tran, Igor Konnov, Josef Widder | | | | | | | Buffered Random Access File | Calvin Loncaric | | | | ✔ | | | Disruptor | Nicholas Schultz-Møller | | | | ✔ | |

Other Examples

Here is a list of specs stored in locations outside this repository or not validated by the CI, such as submodules. Since these specs are not covered by CI testing it is possible they contain errors, the reported details are incorrect, or they are no longer available. Ideally these will be moved into this repo over time. | Spec | Details | Author(s) | Beginner | TLAPS Proof | TLC Model | PlusCal | Apalache | | --------------------------------------------------------------------------------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------- | :------: | :---------: | :-------: | :-----: | :------: | | Blocking Queue | BlockingQueue | Markus Kuppe | ✔ | ✔ | ✔ | (✔) | | | IEEE 802.16 WiMAX Protocols | 2006, paper, specs | Prasad Narayana, Ruiming Chen, Yao Zhao, Yan Chen, Zhi (Judy) Fu, Hai Zhou | | | | | | | On the diversity of asynchronous communication | 2016, paper, specs | Florent Chevrou, Aurélie Hurault, Philippe Quéinnec | | | | | | | Caesar | Multi-leader generalized consensus protocol (Arun et al., 2017) | Giuliano Losa | | | ✔ | ✔ | | | CASPaxos | An extension of the single-decree Paxos algorithm to a compare-and-swap type register (Rystsov) | Tobias Schottdorf | | | ✔ | | | | DataPort | Dataport protocal 505.89PT, only PDF files (Biggs & Noriaki, 2016) | Geoffrey Biggs, Noriaki Ando | | | | | | | egalitarian-paxos | Leaderless replication protocol based on Paxos (Moraru et al., 2013) | Iulian Moraru | | | ✔ | | | | fastpaxos | An extension of the classic Paxos algorithm, only PDF files (Lamport, 2006) | Leslie Lamport | | | | | | | fpaxos | A variant of Paxos with flexible quorums (Howard et al., 2017) | Heidi Howard | | | ✔ | | | | HLC | Hybrid logical clocks and hybrid vector clocks (Demirbas et al., 2014) | Murat Demirbas | | | ✔ | ✔ | | | L1 | Data center network L1 switch protocol, only PDF files (Thacker) | Tom Rodeheffer | | | | | | | leaderless | Leaderless generalized-consensus algorithms (Losa, 2016) | Giuliano Losa | | | ✔ | ✔ | | | losa_ap | The assignment problem, a variant of the allocation problem (Delporte-Gallet, 2018) | Giuliano Losa | | | ✔ | ✔ | | | losa_rda | Applying peculative linearizability to fault-tolerant message-passing algorithms and shared-memory consensus, only PDF files (Losa, 2014) | Giuliano Losa | | | | | | | m2paxos | Multi-leader consensus protocols (Peluso et al., 2016) | Giuliano Losa | | | ✔ | | | | mongo-repl-tla | A simplified part of Raft in MongoDB (Ongaro, 2014) | Siyuan Zhou | | | ✔ | | | | MultiPaxos | The abstract specification of Generalized Paxos (Lamport, 2004) | Giuliano Losa | | | ✔ | | | | naiad | Naiad clock protocol, only PDF files (Murray et al., 2013) | Tom Rodeheffer | | | ✔ | | | | nfc04 | Non-functional properties of component-based software systems (Zschaler, 2010) | Steffen Zschaler | | | ✔ | | | | raft | Raft consensus algorithm (Ongaro, 2014) | Diego Ongaro | | | ✔ | | | | SnapshotIsolation | Serializable snapshot isolation (Cahill et al., 2010) | Michael J. Cahill, Uwe Röhm, Alan D. Fekete | | | ✔ | | | | SyncConsensus | Synchronized round consensus algorithm (Demirbas) | Murat Demirbas | | | ✔ | ✔ | | | Termination | Channel-counting algorithm (Kumar, 1985) | Giuliano Losa | | ✔ | ✔ | ✔ | ✔ | | Tla-tortoise-hare | Robert Floyd's cycle detection algorithm | Lorin Hochstein | | | ✔ | ✔ | | | VoldemortKV | Voldemort distributed key value store | Murat Demirbas | | | ✔ | ✔ | | | Tencent-Paxos | PaxosStore: high-availability storage made practical in WeChat. Proceedings of the VLDB Endowment(Zheng et al., 2017) | Xingchen Yi, Hengfeng Wei | | ✔ | ✔ | | | | Paxos | Paxos | | | | ✔ | | | | Lock-Free Set | PlusCal spec of a lock-Free set used by TLC | Markus Kuppe | | | ✔ | ✔ | | | ParallelRaft | A variant of Raft | Xiaosong Gu, Hengfeng Wei, Yu Huang | | | ✔ | | | | CRDT-Bug | CRDT algorithm with defect and fixed version | Alexander Niederbühl | | | ✔ | | | | asyncio-lock | Bugs from old versions of Python's asyncio lock | Alexander Niederbühl | | | ✔ | | | | Raft (with cluster changes) | Raft with cluster changes, and a version with Apalache type annotations but no cluster changes | George Pîrlea, Darius Foom, Brandon Amos, Huanchen Zhang, Daniel Ricketts | | | ✔ | | ✔ | | MET for CRDT-Redis | Model-check the CRDT designs, then generate test cases to test CRDT implementations | Yuqi Zhang | | | ✔ | ✔ | | | Parallel increment | Parallel threads incrementing a shared variable. Demonstrates invariants, liveness, fairness and symmetry | Chris Jensen | | | ✔ | | | | The Streamlet consensus algorithm | Specification and model-checking of both safety and liveness properties of Streamlet with TLC | Giuliano Losa | | | ✔ | ✔ | | | Petri Nets | Instantiable Petri Nets with liveness properties | Eugene Huang | | | ✔ | | | | CRDT | Specifying and Verifying CRDT Protocols | Ye Ji, Hengfeng Wei | | | ✔ | | | | Azure Cosmos DB | Consistency models provided by Azure Cosmos DB | Dharma Shukla, Ailidani Ailijiang, Murat Demirbas, Markus Kuppe | | | ✔ | ✔ | | | Simple Microwave Oven | Spec of a microwave oven | Konstantin Läufer, George K. Thiruvathukal | ✔ | | | ✔ | | |

Contributing a Spec

See CONTRIBUTING.md for instructions.

License

The repository is under the MIT license and you are encouraged to publish your spec under a similarly-permissive license. However, your spec can be included in this repo along with your own license if you wish.

Support or Contact

Do you have any questions or comments? Please open an issue or send an email to the TLA⁺ mailing list.

Owner

  • Name: TLA+
  • Login: tlaplus
  • Kind: organization
  • Email: tlaplus@googlegroups.com

TLA+ is a formal specification language developed to design, model, document, and verify concurrent systems.

Citation (CITATION.cff)

cff-version: 1.2.0
title: TLA+ Examples
message: Please cite this software using these metadata.
type: software
authors:
  - given-names: Leslie
    affiliation: Microsoft
    family-names: Lamport
  - given-names: Markus
    name-particle: A.
    affiliation: Microsoft
    family-names: Kuppe
  - given-names: Stephan
    family-names: Merz
    affiliation: Inria
  - given-names: Andrew
    family-names: Helwer
  - given-names: William
    family-names: Schultz
  - given-names: Jeff
    family-names: Hemphill
  - given-names: Mariusz
    family-names: Ryndzionek
  - given-names: Igor
    family-names: Konnov
  - given-names: Thanh Hai
    family-names: Tran
  - given-names: Josef
    family-names: Widder
  - given-names: Jim
    family-names: Gray
  - given-names: Murat
    family-names: Demirbas
  - given-names: Guanzhou
    family-names: Hu
  - given-names: Giuliano
    family-names: Losa
  - given-names: Ron
    family-names: Pressler
  - given-names: Younes
    family-names: Akhouayri
  - given-names: Luming
    family-names: Dong
  - given-names: Zhi
    family-names: Niu
  - given-names: Lim Ngian Xin
    family-names: Terry
  - given-names: Gaurav
    family-names: Gandhi
  - given-names: Isaac
    family-names: DeFrain
  - given-names: Martin
    family-names: Harrison
  - given-names: Santhosh
    family-names: Raju
  - given-names: Cherry G. 
    family-names: Mathew
  - given-names: Fransisca
    family-names: Andriani
  - given-names: Ludovic
    family-names: Yvoz
version: 1.0.0
url: "https://github.com/tlaplus/Examples"

GitHub Events

Total
  • Issues event: 4
  • Watch event: 106
  • Delete event: 6
  • Issue comment event: 86
  • Push event: 70
  • Pull request review comment event: 79
  • Pull request review event: 76
  • Pull request event: 56
  • Fork event: 12
  • Create event: 8
Last Year
  • Issues event: 4
  • Watch event: 106
  • Delete event: 6
  • Issue comment event: 86
  • Push event: 70
  • Pull request review comment event: 79
  • Pull request review event: 76
  • Pull request event: 56
  • Fork event: 12
  • Create event: 8

Committers

Last synced: 7 months ago

All Time
  • Total Commits: 434
  • Total Committers: 49
  • Avg Commits per committer: 8.857
  • Development Distribution Score (DDS): 0.528
Past Year
  • Commits: 46
  • Committers: 6
  • Avg Commits per committer: 7.667
  • Development Distribution Score (DDS): 0.522
Top Committers
Name Email Commits
Markus Alexander Kuppe g****m@l****e 205
Andrew Helwer 2****f@m****m 94
merz s****z@l****r 40
Thanh Hai Tran t****2@g****m 13
Giuliano Losa g****o@l****r 6
Martin m****y@l****t 5
Mariusz Ryndzionek m****k@g****m 4
stary s****i@q****m 4
Martin r****k@g****m 4
lamport l****t@f****m 4
Leslie Lamport l****t@f****b 3
Andrei Tonkikh a****h@g****m 3
Konstantin Läufer l****r@c****u 3
HappyCS-Gu 1****3@1****m 3
Murat Demirbas m****b@a****m 2
Igor Konnov k****v 2
Murat Demirbas m****s@g****m 2
Alexander Niederbühl a****l@g****m 2
Quantifier 4****n 2
Florian Schanda f****a@n****m 2
Nicholas Schultz-Møller n****m@g****m 2
xxyzzn x****n 2
postmasters n****n@g****m 1
neoschizomer 6****r 1
melhindi m****i 1
Leslie Lamport f****n@t****b 1
Martin Langhaus m****n@e****t 1
TypeDefinition l****y@g****m 1
Vasily Kuznetsov v****v@t****u 1
Younes d****v@y****o 1
and 19 more...

Issues and Pull Requests

Last synced: 6 months ago

All Time
  • Total issues: 34
  • Total pull requests: 128
  • Average time to close issues: 6 months
  • Average time to close pull requests: about 1 month
  • Total issue authors: 13
  • Total pull request authors: 42
  • Average comments per issue: 4.32
  • Average comments per pull request: 2.93
  • Merged pull requests: 97
  • Bot issues: 0
  • Bot pull requests: 0
Past Year
  • Issues: 4
  • Pull requests: 52
  • Average time to close issues: about 5 hours
  • Average time to close pull requests: 7 days
  • Issue authors: 4
  • Pull request authors: 7
  • Average comments per issue: 2.0
  • Average comments per pull request: 2.38
  • Merged pull requests: 40
  • Bot issues: 0
  • Bot pull requests: 0
Top Authors
Issue Authors
  • ahelwer (19)
  • lemmy (13)
  • muenchnerkindl (1)
  • sayyadabdi (1)
  • Cjen1 (1)
  • senniraf (1)
  • JordyMoos (1)
  • 10227694 (1)
  • zeonglow (1)
  • nrinaudo (1)
  • fmdepaul (1)
  • hwayne (1)
  • ajrouvoet (1)
  • lduranovic (1)
Pull Request Authors
  • ahelwer (68)
  • muenchnerkindl (15)
  • lemmy (13)
  • nano-o (7)
  • nicholassm (4)
  • florianschanda (4)
  • Starydark (3)
  • Isaac-DeFrain (3)
  • 10227694 (3)
  • muratdem (3)
  • banhday (2)
  • klaeufer (2)
  • wrobell (2)
  • Alexander-N (2)
  • xosmig (2)
Top Labels
Issue Labels
enhancement (12) question (3) bug (2) help wanted (1)
Pull Request Labels
enhancement (13) bug (1)

Dependencies

.github/workflows/CI.yml actions
  • actions/checkout v2 composite
  • actions/setup-java v3 composite
  • actions/setup-python v4 composite
  • msys2/setup-msys2 v2 composite
.github/scripts/requirements.txt pypi
  • jsonschema ==4.17.3
  • tree-sitter ==0.20.1
specifications/LeastCircularSubstring/requirements.txt pypi
  • hypothesis ==6.70.0
  • pytest ==7.2.2
.github/workflows/TLAi.yml actions
  • actions/checkout v4 composite
  • actions/setup-node v4 composite
  • github/codeql-action/upload-sarif v3 composite
.github/workflows/ewd998.yml actions
  • actions/checkout v1 composite
  • actions/upload-artifact v3 composite