{
  "name": "Model checking",
  "version": "1.0.0",
  "area": {
    "name": "Model checking",
    "slug": "model-checking",
    "group": "Programs & systems",
    "kind": "model-checking",
    "summary": "Explore the states actually reachable from an initial condition, and evaluate safety on that closure.",
    "definitions": [
      {
        "term": "Reachability",
        "definition": "The least set containing all initial states and closed under transitions."
      },
      {
        "term": "Safety invariant",
        "definition": "A predicate true at every reachable state."
      },
      {
        "term": "Unreachable state",
        "definition": "A declared state that no allowed execution from an initial state reaches."
      }
    ],
    "methodology": [
      "Initialize the frontier with every initial state.",
      "Follow all transitions, deduplicating visited states.",
      "Compare the supplied reachable-state certificate with the computed closure.",
      "Check whether every reachable state lies in the declared safe set."
    ],
    "complexity": "Breadth-first exploration is O(V+E) for an explicit finite graph; implicit system state spaces can grow exponentially.",
    "common_error": "Ignoring an enabled transition can make an unsafe system appear safe.",
    "next_question": "Add counterexample paths, temporal properties, and fairness-aware liveness checks.",
    "references": [
      "https://www.prismmodelchecker.org/doc/whatsinprism.php"
    ]
  },
  "records": [
    {
      "id": "KL-FCS-008",
      "version": "1.0.0",
      "domain": "Model checking",
      "kind": "model-checking",
      "title": "A reachable-state safety invariant",
      "problem": "Check that every reachable state is in {0, 1, 2}.",
      "specification": {
        "initial": [
          0
        ],
        "transitions": {
          "0": [
            0,
            1
          ],
          "1": [
            2
          ],
          "2": [
            0
          ],
          "3": [
            3
          ]
        },
        "safe": [
          0,
          1,
          2
        ]
      },
      "claim": {
        "invariant_holds": true
      },
      "witness": {
        "reachable": [
          0,
          1,
          2
        ]
      },
      "verification_scope": "Complete reachability · 3 states",
      "explanation": "Breadth-first exploration reaches exactly 0, 1, and 2. State 3 exists in the model but is unreachable from the initial state.",
      "limitations": "Safety for this finite transition system only; no fairness, liveness, or real-device behavior claim.",
      "verification_status": "mechanically-checked",
      "review_status": "awaiting-independent-review",
      "provenance": {
        "origin": "Original Kenton Labs reference instance, authored with Codex assistance on 2026-10-11.",
        "external_dataset": null,
        "model_run": null
      },
      "references": [
        "https://www.prismmodelchecker.org/doc/whatsinprism.php"
      ],
      "license_status": "not-yet-selected",
      "dataset": {
        "family": "model-checking",
        "task": "Check that every reachable state is in {0, 1, 2}.",
        "input_encoding": "Structured JSON; field meanings are stated in the specification.",
        "coverage": "Complete reachability · 3 states",
        "acceptance": [
          "Initialize the frontier with every initial state.",
          "Follow all transitions, deduplicating visited states.",
          "Compare the supplied reachable-state certificate with the computed closure.",
          "Check whether every reachable state lies in the declared safe set."
        ],
        "generation": "Deterministic finite fixture; full enumeration or witness replay as stated.",
        "split_policy": "Reference corpus for exposition and reproduction; no train/test evaluation split is claimed."
      },
      "lesson": {
        "motivation": "Explore the states actually reachable from an initial condition, and evaluate safety on that closure.",
        "definitions": [
          {
            "term": "Reachability",
            "definition": "The least set containing all initial states and closed under transitions."
          },
          {
            "term": "Safety invariant",
            "definition": "A predicate true at every reachable state."
          },
          {
            "term": "Unreachable state",
            "definition": "A declared state that no allowed execution from an initial state reaches."
          }
        ],
        "reasoning": [
          "Initialize the frontier with every initial state.",
          "Follow all transitions, deduplicating visited states.",
          "Compare the supplied reachable-state certificate with the computed closure.",
          "Check whether every reachable state lies in the declared safe set."
        ],
        "worked_example": "Breadth-first exploration reaches exactly 0, 1, and 2. State 3 exists in the model but is unreachable from the initial state.",
        "complexity": "Breadth-first exploration is O(V+E) for an explicit finite graph; implicit system state spaces can grow exponentially.",
        "common_error": "Ignoring an enabled transition can make an unsafe system appear safe.",
        "further_work": "Add counterexample paths, temporal properties, and fairness-aware liveness checks."
      },
      "related_ids": [
        "KL-FCS-020",
        "KL-FCS-021"
      ]
    },
    {
      "id": "KL-FCS-020",
      "version": "1.0.0",
      "domain": "Model checking",
      "kind": "model-checking",
      "title": "A reachable unsafe state",
      "problem": "Explore the complete transition graph from state 0.",
      "specification": {
        "initial": [
          0
        ],
        "transitions": {
          "0": [
            1
          ],
          "1": [
            2
          ],
          "2": [
            3
          ],
          "3": [
            0
          ]
        },
        "safe": [
          0,
          1,
          2
        ]
      },
      "claim": {
        "invariant_holds": false
      },
      "witness": {
        "reachable": [
          0,
          1,
          2,
          3
        ]
      },
      "verification_scope": "Complete four-state reachability",
      "explanation": "Every successor is included in the closure. The safe-set comparison identifies whether the property holds across all reachable executions.",
      "limitations": "This is a finite safety check; no liveness or fairness statement is included.",
      "verification_status": "mechanically-checked",
      "review_status": "awaiting-independent-review",
      "provenance": {
        "origin": "Original Kenton Labs reference instance, authored with Codex assistance on 2026-10-11.",
        "external_dataset": null,
        "model_run": null
      },
      "references": [
        "https://www.prismmodelchecker.org/doc/whatsinprism.php"
      ],
      "license_status": "not-yet-selected",
      "dataset": {
        "family": "model-checking",
        "task": "Explore the complete transition graph from state 0.",
        "input_encoding": "Structured JSON; field meanings are stated in the specification.",
        "coverage": "Complete four-state reachability",
        "acceptance": [
          "Initialize the frontier with every initial state.",
          "Follow all transitions, deduplicating visited states.",
          "Compare the supplied reachable-state certificate with the computed closure.",
          "Check whether every reachable state lies in the declared safe set."
        ],
        "generation": "Deterministic finite fixture; full enumeration or witness replay as stated.",
        "split_policy": "Reference corpus for exposition and reproduction; no train/test evaluation split is claimed."
      },
      "lesson": {
        "motivation": "Explore the states actually reachable from an initial condition, and evaluate safety on that closure.",
        "definitions": [
          {
            "term": "Reachability",
            "definition": "The least set containing all initial states and closed under transitions."
          },
          {
            "term": "Safety invariant",
            "definition": "A predicate true at every reachable state."
          },
          {
            "term": "Unreachable state",
            "definition": "A declared state that no allowed execution from an initial state reaches."
          }
        ],
        "reasoning": [
          "Initialize the frontier with every initial state.",
          "Follow all transitions, deduplicating visited states.",
          "Compare the supplied reachable-state certificate with the computed closure.",
          "Check whether every reachable state lies in the declared safe set."
        ],
        "worked_example": "Every successor is included in the closure. The safe-set comparison identifies whether the property holds across all reachable executions.",
        "complexity": "Breadth-first exploration is O(V+E) for an explicit finite graph; implicit system state spaces can grow exponentially.",
        "common_error": "Ignoring an enabled transition can make an unsafe system appear safe.",
        "further_work": "Add counterexample paths, temporal properties, and fairness-aware liveness checks."
      },
      "related_ids": [
        "KL-FCS-008",
        "KL-FCS-021"
      ]
    },
    {
      "id": "KL-FCS-021",
      "version": "1.0.0",
      "domain": "Model checking",
      "kind": "model-checking",
      "title": "Branching safety closure",
      "problem": "Explore the complete transition graph from state 0.",
      "specification": {
        "initial": [
          0
        ],
        "transitions": {
          "0": [
            1,
            2
          ],
          "1": [
            3
          ],
          "2": [
            3
          ],
          "3": [
            3
          ]
        },
        "safe": [
          0,
          1,
          2,
          3
        ]
      },
      "claim": {
        "invariant_holds": true
      },
      "witness": {
        "reachable": [
          0,
          1,
          2,
          3
        ]
      },
      "verification_scope": "Complete four-state reachability",
      "explanation": "Every successor is included in the closure. The safe-set comparison identifies whether the property holds across all reachable executions.",
      "limitations": "This is a finite safety check; no liveness or fairness statement is included.",
      "verification_status": "mechanically-checked",
      "review_status": "awaiting-independent-review",
      "provenance": {
        "origin": "Original Kenton Labs reference instance, authored with Codex assistance on 2026-10-11.",
        "external_dataset": null,
        "model_run": null
      },
      "references": [
        "https://www.prismmodelchecker.org/doc/whatsinprism.php"
      ],
      "license_status": "not-yet-selected",
      "dataset": {
        "family": "model-checking",
        "task": "Explore the complete transition graph from state 0.",
        "input_encoding": "Structured JSON; field meanings are stated in the specification.",
        "coverage": "Complete four-state reachability",
        "acceptance": [
          "Initialize the frontier with every initial state.",
          "Follow all transitions, deduplicating visited states.",
          "Compare the supplied reachable-state certificate with the computed closure.",
          "Check whether every reachable state lies in the declared safe set."
        ],
        "generation": "Deterministic finite fixture; full enumeration or witness replay as stated.",
        "split_policy": "Reference corpus for exposition and reproduction; no train/test evaluation split is claimed."
      },
      "lesson": {
        "motivation": "Explore the states actually reachable from an initial condition, and evaluate safety on that closure.",
        "definitions": [
          {
            "term": "Reachability",
            "definition": "The least set containing all initial states and closed under transitions."
          },
          {
            "term": "Safety invariant",
            "definition": "A predicate true at every reachable state."
          },
          {
            "term": "Unreachable state",
            "definition": "A declared state that no allowed execution from an initial state reaches."
          }
        ],
        "reasoning": [
          "Initialize the frontier with every initial state.",
          "Follow all transitions, deduplicating visited states.",
          "Compare the supplied reachable-state certificate with the computed closure.",
          "Check whether every reachable state lies in the declared safe set."
        ],
        "worked_example": "Every successor is included in the closure. The safe-set comparison identifies whether the property holds across all reachable executions.",
        "complexity": "Breadth-first exploration is O(V+E) for an explicit finite graph; implicit system state spaces can grow exponentially.",
        "common_error": "Ignoring an enabled transition can make an unsafe system appear safe.",
        "further_work": "Add counterexample paths, temporal properties, and fairness-aware liveness checks."
      },
      "related_ids": [
        "KL-FCS-008",
        "KL-FCS-020"
      ]
    }
  ],
  "verification": [
    {
      "id": "KL-FCS-008",
      "status": "mechanically-checked",
      "check_units": 3,
      "scope": "Complete reachability · 3 states",
      "review_status": "awaiting-independent-review"
    },
    {
      "id": "KL-FCS-020",
      "status": "mechanically-checked",
      "check_units": 4,
      "scope": "Complete four-state reachability",
      "review_status": "awaiting-independent-review"
    },
    {
      "id": "KL-FCS-021",
      "status": "mechanically-checked",
      "check_units": 4,
      "scope": "Complete four-state reachability",
      "review_status": "awaiting-independent-review"
    }
  ]
}
