{
  "name": "Program verification",
  "version": "1.0.0",
  "area": {
    "name": "Program verification",
    "slug": "program-verification",
    "group": "Programs & systems",
    "kind": "hoare",
    "summary": "Connect preconditions, invariants, variants, and postconditions in a completely specified bounded program family.",
    "definitions": [
      {
        "term": "Loop invariant",
        "definition": "A property maintained at every loop boundary."
      },
      {
        "term": "Variant",
        "definition": "A value in a well-founded domain that strictly decreases while the loop runs."
      },
      {
        "term": "Postcondition",
        "definition": "The property required when execution exits."
      }
    ],
    "methodology": [
      "Enumerate every admitted bound n.",
      "Start with i=0 and total=0.",
      "Check 2·total=i(i+1) and the decreasing variant n−i.",
      "Replay the sample trace and require total=n(n+1)/2 at exit."
    ],
    "complexity": "The family runs Σ n loop iterations for n=0…N, so total replay is O(N²).",
    "common_error": "A postcondition on one execution is weaker than an invariant and a declared input domain.",
    "next_question": "Add inductive proof obligations and externally checked Hoare derivations.",
    "references": [
      "https://dafny.org/latest/OnlineTutorial/guide"
    ]
  },
  "records": [
    {
      "id": "KL-FCS-040",
      "version": "1.0.0",
      "domain": "Program verification",
      "kind": "hoare",
      "title": "Sum-loop obligations for n ≤ 5",
      "problem": "Verify a loop that increments i and then adds i to total, starting from zero.",
      "specification": {
        "program": "sum-first-n",
        "max_n": 5,
        "sample_n": 3,
        "precondition": "n ≥ 0; i=0; total=0",
        "invariant": "2*total = i*(i+1) and 0 ≤ i ≤ n",
        "variant": "n-i"
      },
      "claim": {
        "postcondition_holds": true,
        "variant_decreases": true
      },
      "witness": {
        "trace": [
          [
            0,
            0
          ],
          [
            1,
            1
          ],
          [
            2,
            3
          ],
          [
            3,
            6
          ]
        ]
      },
      "verification_scope": "Complete bounded program family · 6 inputs",
      "explanation": "The invariant explains the partial sum at each boundary. The remaining iteration count strictly decreases, and the exit condition turns the invariant into the postcondition.",
      "limitations": "This replay checks n through the stated bound; it does not constitute an unrestricted deductive proof.",
      "verification_status": "mechanically-checked",
      "review_status": "awaiting-independent-review",
      "provenance": {
        "origin": "Original Kenton Labs reference instance, authored with Codex assistance on 2026-10-11.",
        "external_dataset": null,
        "model_run": null
      },
      "references": [
        "https://dafny.org/latest/OnlineTutorial/guide"
      ],
      "license_status": "not-yet-selected",
      "dataset": {
        "family": "program-verification",
        "task": "Verify a loop that increments i and then adds i to total, starting from zero.",
        "input_encoding": "Structured JSON; field meanings are stated in the specification.",
        "coverage": "Complete bounded program family · 6 inputs",
        "acceptance": [
          "Enumerate every admitted bound n.",
          "Start with i=0 and total=0.",
          "Check 2·total=i(i+1) and the decreasing variant n−i.",
          "Replay the sample trace and require total=n(n+1)/2 at exit."
        ],
        "generation": "Deterministic finite fixture; full enumeration or witness replay as stated.",
        "split_policy": "Reference corpus for exposition and reproduction; no train/test evaluation split is claimed."
      },
      "lesson": {
        "motivation": "Connect preconditions, invariants, variants, and postconditions in a completely specified bounded program family.",
        "definitions": [
          {
            "term": "Loop invariant",
            "definition": "A property maintained at every loop boundary."
          },
          {
            "term": "Variant",
            "definition": "A value in a well-founded domain that strictly decreases while the loop runs."
          },
          {
            "term": "Postcondition",
            "definition": "The property required when execution exits."
          }
        ],
        "reasoning": [
          "Enumerate every admitted bound n.",
          "Start with i=0 and total=0.",
          "Check 2·total=i(i+1) and the decreasing variant n−i.",
          "Replay the sample trace and require total=n(n+1)/2 at exit."
        ],
        "worked_example": "The invariant explains the partial sum at each boundary. The remaining iteration count strictly decreases, and the exit condition turns the invariant into the postcondition.",
        "complexity": "The family runs Σ n loop iterations for n=0…N, so total replay is O(N²).",
        "common_error": "A postcondition on one execution is weaker than an invariant and a declared input domain.",
        "further_work": "Add inductive proof obligations and externally checked Hoare derivations."
      },
      "related_ids": [
        "KL-FCS-041",
        "KL-FCS-042"
      ]
    },
    {
      "id": "KL-FCS-041",
      "version": "1.0.0",
      "domain": "Program verification",
      "kind": "hoare",
      "title": "Sum-loop obligations for n ≤ 10",
      "problem": "Verify a loop that increments i and then adds i to total, starting from zero.",
      "specification": {
        "program": "sum-first-n",
        "max_n": 10,
        "sample_n": 5,
        "precondition": "n ≥ 0; i=0; total=0",
        "invariant": "2*total = i*(i+1) and 0 ≤ i ≤ n",
        "variant": "n-i"
      },
      "claim": {
        "postcondition_holds": true,
        "variant_decreases": true
      },
      "witness": {
        "trace": [
          [
            0,
            0
          ],
          [
            1,
            1
          ],
          [
            2,
            3
          ],
          [
            3,
            6
          ],
          [
            4,
            10
          ],
          [
            5,
            15
          ]
        ]
      },
      "verification_scope": "Complete bounded program family · 11 inputs",
      "explanation": "The invariant explains the partial sum at each boundary. The remaining iteration count strictly decreases, and the exit condition turns the invariant into the postcondition.",
      "limitations": "This replay checks n through the stated bound; it does not constitute an unrestricted deductive proof.",
      "verification_status": "mechanically-checked",
      "review_status": "awaiting-independent-review",
      "provenance": {
        "origin": "Original Kenton Labs reference instance, authored with Codex assistance on 2026-10-11.",
        "external_dataset": null,
        "model_run": null
      },
      "references": [
        "https://dafny.org/latest/OnlineTutorial/guide"
      ],
      "license_status": "not-yet-selected",
      "dataset": {
        "family": "program-verification",
        "task": "Verify a loop that increments i and then adds i to total, starting from zero.",
        "input_encoding": "Structured JSON; field meanings are stated in the specification.",
        "coverage": "Complete bounded program family · 11 inputs",
        "acceptance": [
          "Enumerate every admitted bound n.",
          "Start with i=0 and total=0.",
          "Check 2·total=i(i+1) and the decreasing variant n−i.",
          "Replay the sample trace and require total=n(n+1)/2 at exit."
        ],
        "generation": "Deterministic finite fixture; full enumeration or witness replay as stated.",
        "split_policy": "Reference corpus for exposition and reproduction; no train/test evaluation split is claimed."
      },
      "lesson": {
        "motivation": "Connect preconditions, invariants, variants, and postconditions in a completely specified bounded program family.",
        "definitions": [
          {
            "term": "Loop invariant",
            "definition": "A property maintained at every loop boundary."
          },
          {
            "term": "Variant",
            "definition": "A value in a well-founded domain that strictly decreases while the loop runs."
          },
          {
            "term": "Postcondition",
            "definition": "The property required when execution exits."
          }
        ],
        "reasoning": [
          "Enumerate every admitted bound n.",
          "Start with i=0 and total=0.",
          "Check 2·total=i(i+1) and the decreasing variant n−i.",
          "Replay the sample trace and require total=n(n+1)/2 at exit."
        ],
        "worked_example": "The invariant explains the partial sum at each boundary. The remaining iteration count strictly decreases, and the exit condition turns the invariant into the postcondition.",
        "complexity": "The family runs Σ n loop iterations for n=0…N, so total replay is O(N²).",
        "common_error": "A postcondition on one execution is weaker than an invariant and a declared input domain.",
        "further_work": "Add inductive proof obligations and externally checked Hoare derivations."
      },
      "related_ids": [
        "KL-FCS-040",
        "KL-FCS-042"
      ]
    },
    {
      "id": "KL-FCS-042",
      "version": "1.0.0",
      "domain": "Program verification",
      "kind": "hoare",
      "title": "Sum-loop obligations for n ≤ 20",
      "problem": "Verify a loop that increments i and then adds i to total, starting from zero.",
      "specification": {
        "program": "sum-first-n",
        "max_n": 20,
        "sample_n": 8,
        "precondition": "n ≥ 0; i=0; total=0",
        "invariant": "2*total = i*(i+1) and 0 ≤ i ≤ n",
        "variant": "n-i"
      },
      "claim": {
        "postcondition_holds": true,
        "variant_decreases": true
      },
      "witness": {
        "trace": [
          [
            0,
            0
          ],
          [
            1,
            1
          ],
          [
            2,
            3
          ],
          [
            3,
            6
          ],
          [
            4,
            10
          ],
          [
            5,
            15
          ],
          [
            6,
            21
          ],
          [
            7,
            28
          ],
          [
            8,
            36
          ]
        ]
      },
      "verification_scope": "Complete bounded program family · 21 inputs",
      "explanation": "The invariant explains the partial sum at each boundary. The remaining iteration count strictly decreases, and the exit condition turns the invariant into the postcondition.",
      "limitations": "This replay checks n through the stated bound; it does not constitute an unrestricted deductive proof.",
      "verification_status": "mechanically-checked",
      "review_status": "awaiting-independent-review",
      "provenance": {
        "origin": "Original Kenton Labs reference instance, authored with Codex assistance on 2026-10-11.",
        "external_dataset": null,
        "model_run": null
      },
      "references": [
        "https://dafny.org/latest/OnlineTutorial/guide"
      ],
      "license_status": "not-yet-selected",
      "dataset": {
        "family": "program-verification",
        "task": "Verify a loop that increments i and then adds i to total, starting from zero.",
        "input_encoding": "Structured JSON; field meanings are stated in the specification.",
        "coverage": "Complete bounded program family · 21 inputs",
        "acceptance": [
          "Enumerate every admitted bound n.",
          "Start with i=0 and total=0.",
          "Check 2·total=i(i+1) and the decreasing variant n−i.",
          "Replay the sample trace and require total=n(n+1)/2 at exit."
        ],
        "generation": "Deterministic finite fixture; full enumeration or witness replay as stated.",
        "split_policy": "Reference corpus for exposition and reproduction; no train/test evaluation split is claimed."
      },
      "lesson": {
        "motivation": "Connect preconditions, invariants, variants, and postconditions in a completely specified bounded program family.",
        "definitions": [
          {
            "term": "Loop invariant",
            "definition": "A property maintained at every loop boundary."
          },
          {
            "term": "Variant",
            "definition": "A value in a well-founded domain that strictly decreases while the loop runs."
          },
          {
            "term": "Postcondition",
            "definition": "The property required when execution exits."
          }
        ],
        "reasoning": [
          "Enumerate every admitted bound n.",
          "Start with i=0 and total=0.",
          "Check 2·total=i(i+1) and the decreasing variant n−i.",
          "Replay the sample trace and require total=n(n+1)/2 at exit."
        ],
        "worked_example": "The invariant explains the partial sum at each boundary. The remaining iteration count strictly decreases, and the exit condition turns the invariant into the postcondition.",
        "complexity": "The family runs Σ n loop iterations for n=0…N, so total replay is O(N²).",
        "common_error": "A postcondition on one execution is weaker than an invariant and a declared input domain.",
        "further_work": "Add inductive proof obligations and externally checked Hoare derivations."
      },
      "related_ids": [
        "KL-FCS-040",
        "KL-FCS-041"
      ]
    }
  ],
  "verification": [
    {
      "id": "KL-FCS-040",
      "status": "mechanically-checked",
      "check_units": 6,
      "scope": "Complete bounded program family · 6 inputs",
      "review_status": "awaiting-independent-review"
    },
    {
      "id": "KL-FCS-041",
      "status": "mechanically-checked",
      "check_units": 11,
      "scope": "Complete bounded program family · 11 inputs",
      "review_status": "awaiting-independent-review"
    },
    {
      "id": "KL-FCS-042",
      "status": "mechanically-checked",
      "check_units": 21,
      "scope": "Complete bounded program family · 21 inputs",
      "review_status": "awaiting-independent-review"
    }
  ]
}
