infinite amount of symbolic paths a program can have, so we bound exploration • We must additionally keep track of initial shape of structure for test generation of input • A model finder converts the symbolic paths into concretely executable test cases
and Cardinality Encoding operations in solver using native theory of sets Strong Field Updates Lazy init. separating reasoning about shapes from aliasing First-class handling of containment links Lazy iteration over symbolic sets Deep containment constraints IMPORTANT OPTIMIZATIONS THAT MAKE OUR TECHNIQUE WORK IN PRACTICE
• Easy to extend to support more complex properties • Possible to use for verification • Currently allows k-bounded reachability property checking • Over-approximation of loops would further allow checking universal properties EFFECTIVENESS AND EXTENSIBILITY