{
  "name": "Distributed protocols",
  "version": "1.0.0",
  "area": {
    "name": "Distributed protocols",
    "slug": "protocols",
    "group": "Programs & systems",
    "kind": "protocols",
    "summary": "Treat atomicity and scheduling as part of a protocol model. A small interleaving can refute a plausible safety claim.",
    "definitions": [
      {
        "term": "Atomic step",
        "definition": "An action observed as indivisible by other processes."
      },
      {
        "term": "Mutual exclusion",
        "definition": "At most one process occupies its critical section."
      },
      {
        "term": "Interleaving",
        "definition": "A sequence choosing one enabled process action at a time."
      }
    ],
    "methodology": [
      "Start all processes outside the critical section with a free lock.",
      "Explore every enabled interleaving to a complete reachable closure.",
      "Check the number of processes in the critical section at each state.",
      "For a failure, replay the provided schedule to the unsafe state."
    ],
    "complexity": "The finite state space is exponential in the number of processes; this family uses two or three one-shot processes.",
    "common_error": "Separating a lock check from acquisition allows another process to observe the same free lock.",
    "next_question": "Extend from shared-memory concurrency to bounded message queues and explicit network faults.",
    "references": [
      "https://lamport.azurewebsites.net/tla/tutorial/session6.html"
    ]
  },
  "records": [
    {
      "id": "KL-FCS-052",
      "version": "1.0.0",
      "domain": "Distributed protocols",
      "kind": "protocols",
      "title": "Atomic acquisition with two processes",
      "problem": "Check mutual exclusion over all one-shot lock-acquisition interleavings.",
      "specification": {
        "processes": 2,
        "mode": "atomic",
        "state_encoding": "process PCs, lock bit, process saved-free bits; PC 0=start, 1=checked, 2=critical, 3=done",
        "atomicity": "Atomic mode tests and acquires together; split mode tests then acquires in separate steps."
      },
      "claim": {
        "mutual_exclusion": true
      },
      "witness": {
        "method": "reachable-state enumeration"
      },
      "verification_scope": "Complete reachable interleaving graph",
      "explanation": "An atomic acquisition prevents simultaneous entry. A split acquisition can let both processes remember a free lock before either marks it occupied.",
      "limitations": "This is a shared-memory mutual-exclusion model. It does not verify a network protocol, message loss, liveness, or fairness.",
      "verification_status": "mechanically-checked",
      "review_status": "awaiting-independent-review",
      "provenance": {
        "origin": "Original Kenton Labs reference instance, authored with Codex assistance on 2026-10-11.",
        "external_dataset": null,
        "model_run": null
      },
      "references": [
        "https://lamport.azurewebsites.net/tla/tutorial/session6.html"
      ],
      "license_status": "not-yet-selected",
      "dataset": {
        "family": "protocols",
        "task": "Check mutual exclusion over all one-shot lock-acquisition interleavings.",
        "input_encoding": "Structured JSON; field meanings are stated in the specification.",
        "coverage": "Complete reachable interleaving graph",
        "acceptance": [
          "Start all processes outside the critical section with a free lock.",
          "Explore every enabled interleaving to a complete reachable closure.",
          "Check the number of processes in the critical section at each state.",
          "For a failure, replay the provided schedule to the unsafe state."
        ],
        "generation": "Deterministic finite fixture; full enumeration or witness replay as stated.",
        "split_policy": "Reference corpus for exposition and reproduction; no train/test evaluation split is claimed."
      },
      "lesson": {
        "motivation": "Treat atomicity and scheduling as part of a protocol model. A small interleaving can refute a plausible safety claim.",
        "definitions": [
          {
            "term": "Atomic step",
            "definition": "An action observed as indivisible by other processes."
          },
          {
            "term": "Mutual exclusion",
            "definition": "At most one process occupies its critical section."
          },
          {
            "term": "Interleaving",
            "definition": "A sequence choosing one enabled process action at a time."
          }
        ],
        "reasoning": [
          "Start all processes outside the critical section with a free lock.",
          "Explore every enabled interleaving to a complete reachable closure.",
          "Check the number of processes in the critical section at each state.",
          "For a failure, replay the provided schedule to the unsafe state."
        ],
        "worked_example": "An atomic acquisition prevents simultaneous entry. A split acquisition can let both processes remember a free lock before either marks it occupied.",
        "complexity": "The finite state space is exponential in the number of processes; this family uses two or three one-shot processes.",
        "common_error": "Separating a lock check from acquisition allows another process to observe the same free lock.",
        "further_work": "Extend from shared-memory concurrency to bounded message queues and explicit network faults."
      },
      "related_ids": [
        "KL-FCS-053",
        "KL-FCS-054"
      ]
    },
    {
      "id": "KL-FCS-053",
      "version": "1.0.0",
      "domain": "Distributed protocols",
      "kind": "protocols",
      "title": "A race between check and acquisition",
      "problem": "Check mutual exclusion over all one-shot lock-acquisition interleavings.",
      "specification": {
        "processes": 2,
        "mode": "split",
        "state_encoding": "process PCs, lock bit, process saved-free bits; PC 0=start, 1=checked, 2=critical, 3=done",
        "atomicity": "Atomic mode tests and acquires together; split mode tests then acquires in separate steps."
      },
      "claim": {
        "mutual_exclusion": false
      },
      "witness": {
        "counterexample": [
          [
            0,
            0,
            0,
            0,
            0
          ],
          [
            1,
            0,
            0,
            1,
            0
          ],
          [
            1,
            1,
            0,
            1,
            1
          ],
          [
            2,
            1,
            1,
            1,
            1
          ],
          [
            2,
            2,
            1,
            1,
            1
          ]
        ]
      },
      "verification_scope": "Complete reachable interleaving graph",
      "explanation": "An atomic acquisition prevents simultaneous entry. A split acquisition can let both processes remember a free lock before either marks it occupied.",
      "limitations": "This is a shared-memory mutual-exclusion model. It does not verify a network protocol, message loss, liveness, or fairness.",
      "verification_status": "mechanically-checked",
      "review_status": "awaiting-independent-review",
      "provenance": {
        "origin": "Original Kenton Labs reference instance, authored with Codex assistance on 2026-10-11.",
        "external_dataset": null,
        "model_run": null
      },
      "references": [
        "https://lamport.azurewebsites.net/tla/tutorial/session6.html"
      ],
      "license_status": "not-yet-selected",
      "dataset": {
        "family": "protocols",
        "task": "Check mutual exclusion over all one-shot lock-acquisition interleavings.",
        "input_encoding": "Structured JSON; field meanings are stated in the specification.",
        "coverage": "Complete reachable interleaving graph",
        "acceptance": [
          "Start all processes outside the critical section with a free lock.",
          "Explore every enabled interleaving to a complete reachable closure.",
          "Check the number of processes in the critical section at each state.",
          "For a failure, replay the provided schedule to the unsafe state."
        ],
        "generation": "Deterministic finite fixture; full enumeration or witness replay as stated.",
        "split_policy": "Reference corpus for exposition and reproduction; no train/test evaluation split is claimed."
      },
      "lesson": {
        "motivation": "Treat atomicity and scheduling as part of a protocol model. A small interleaving can refute a plausible safety claim.",
        "definitions": [
          {
            "term": "Atomic step",
            "definition": "An action observed as indivisible by other processes."
          },
          {
            "term": "Mutual exclusion",
            "definition": "At most one process occupies its critical section."
          },
          {
            "term": "Interleaving",
            "definition": "A sequence choosing one enabled process action at a time."
          }
        ],
        "reasoning": [
          "Start all processes outside the critical section with a free lock.",
          "Explore every enabled interleaving to a complete reachable closure.",
          "Check the number of processes in the critical section at each state.",
          "For a failure, replay the provided schedule to the unsafe state."
        ],
        "worked_example": "An atomic acquisition prevents simultaneous entry. A split acquisition can let both processes remember a free lock before either marks it occupied.",
        "complexity": "The finite state space is exponential in the number of processes; this family uses two or three one-shot processes.",
        "common_error": "Separating a lock check from acquisition allows another process to observe the same free lock.",
        "further_work": "Extend from shared-memory concurrency to bounded message queues and explicit network faults."
      },
      "related_ids": [
        "KL-FCS-052",
        "KL-FCS-054"
      ]
    },
    {
      "id": "KL-FCS-054",
      "version": "1.0.0",
      "domain": "Distributed protocols",
      "kind": "protocols",
      "title": "Atomic acquisition with three processes",
      "problem": "Check mutual exclusion over all one-shot lock-acquisition interleavings.",
      "specification": {
        "processes": 3,
        "mode": "atomic",
        "state_encoding": "process PCs, lock bit, process saved-free bits; PC 0=start, 1=checked, 2=critical, 3=done",
        "atomicity": "Atomic mode tests and acquires together; split mode tests then acquires in separate steps."
      },
      "claim": {
        "mutual_exclusion": true
      },
      "witness": {
        "method": "reachable-state enumeration"
      },
      "verification_scope": "Complete reachable interleaving graph",
      "explanation": "An atomic acquisition prevents simultaneous entry. A split acquisition can let both processes remember a free lock before either marks it occupied.",
      "limitations": "This is a shared-memory mutual-exclusion model. It does not verify a network protocol, message loss, liveness, or fairness.",
      "verification_status": "mechanically-checked",
      "review_status": "awaiting-independent-review",
      "provenance": {
        "origin": "Original Kenton Labs reference instance, authored with Codex assistance on 2026-10-11.",
        "external_dataset": null,
        "model_run": null
      },
      "references": [
        "https://lamport.azurewebsites.net/tla/tutorial/session6.html"
      ],
      "license_status": "not-yet-selected",
      "dataset": {
        "family": "protocols",
        "task": "Check mutual exclusion over all one-shot lock-acquisition interleavings.",
        "input_encoding": "Structured JSON; field meanings are stated in the specification.",
        "coverage": "Complete reachable interleaving graph",
        "acceptance": [
          "Start all processes outside the critical section with a free lock.",
          "Explore every enabled interleaving to a complete reachable closure.",
          "Check the number of processes in the critical section at each state.",
          "For a failure, replay the provided schedule to the unsafe state."
        ],
        "generation": "Deterministic finite fixture; full enumeration or witness replay as stated.",
        "split_policy": "Reference corpus for exposition and reproduction; no train/test evaluation split is claimed."
      },
      "lesson": {
        "motivation": "Treat atomicity and scheduling as part of a protocol model. A small interleaving can refute a plausible safety claim.",
        "definitions": [
          {
            "term": "Atomic step",
            "definition": "An action observed as indivisible by other processes."
          },
          {
            "term": "Mutual exclusion",
            "definition": "At most one process occupies its critical section."
          },
          {
            "term": "Interleaving",
            "definition": "A sequence choosing one enabled process action at a time."
          }
        ],
        "reasoning": [
          "Start all processes outside the critical section with a free lock.",
          "Explore every enabled interleaving to a complete reachable closure.",
          "Check the number of processes in the critical section at each state.",
          "For a failure, replay the provided schedule to the unsafe state."
        ],
        "worked_example": "An atomic acquisition prevents simultaneous entry. A split acquisition can let both processes remember a free lock before either marks it occupied.",
        "complexity": "The finite state space is exponential in the number of processes; this family uses two or three one-shot processes.",
        "common_error": "Separating a lock check from acquisition allows another process to observe the same free lock.",
        "further_work": "Extend from shared-memory concurrency to bounded message queues and explicit network faults."
      },
      "related_ids": [
        "KL-FCS-052",
        "KL-FCS-053"
      ]
    }
  ],
  "verification": [
    {
      "id": "KL-FCS-052",
      "status": "mechanically-checked",
      "check_units": 8,
      "scope": "Complete reachable interleaving graph",
      "review_status": "awaiting-independent-review"
    },
    {
      "id": "KL-FCS-053",
      "status": "mechanically-checked",
      "check_units": 26,
      "scope": "Complete reachable interleaving graph",
      "review_status": "awaiting-independent-review"
    },
    {
      "id": "KL-FCS-054",
      "status": "mechanically-checked",
      "check_units": 20,
      "scope": "Complete reachable interleaving graph",
      "review_status": "awaiting-independent-review"
    }
  ]
}
