Upgrade to Pro
— share decks privately, control downloads, hide ads and more …
Speaker Deck
Sign up for free
Menu
Search
Features
All features
Private URLs
Password Protection
Custom URLS
Scheduled publishing
Remove Branding
Restrict embedding
Deck Collections
Notes
Features
All features
Private URLs
Password Protection
Custom URLS
Scheduled publishing
Remove Branding
Restrict embedding
Deck Collections
Notes
Explore
Featured decks
Featured speakers
Programming
Technology
Storyboards
Explore
Featured decks
Featured speakers
Programming
Technology
Storyboards
Pricing
Search
Sign in
Sign up for free
introducing-formal-methods
Search
rrreeeyyy
June 09, 2016
Technology
280
0
Share
Embed
Copy iframe code
Copy JS code
Copy link
Start on current slide
introducing-formal-methods
hbstyle-2016-06-09
rrreeeyyy
June 09, 2016
More Decks by rrreeeyyy
See All by rrreeeyyy
もう一度考える SRE チームの作り方・育て方 / Rethinking SRE #1: Building and Growing SRE Teams
rrreeeyyy
6
1.2k
Reliability in the Age of AI: Engineering for AI Velocity
rrreeeyyy
0
210
Rethinking Incident Response: Context-Aware AI in Practice - Incident Buddy Edition -
rrreeeyyy
0
280
Rethinking Incident Response: Context-Aware AI in Practice
rrreeeyyy
3
2.6k
Incident Response Practices: Waroom's Features and Future Challenges
rrreeeyyy
0
340
An Efficient Incident Response Training with AI / SRE NEXT 2024 Sponsor Session
rrreeeyyy
1
6.3k
カンファレンスから見る SRE トレンド 2024 / SRE Trends from Conferences in 2024 #SRE_Findy
rrreeeyyy
4
2.7k
信頼性の育て方 / mackerel-meetup-15
rrreeeyyy
10
3k
SRE の歩き方・進め方 / sre-walk-through-procedure
rrreeeyyy
0
9.1k
Other Decks in Technology
See All in Technology
ログラスのマルチプロダクトを 支える認証基盤 〜テナントごとに異なる統制とどう向き合うか〜
dada4386
3
250
IR Today: Theory, Practice, and Agents
dtunkelang
0
270
スキルを作る、その前に!複数人で使われるスキルを 作るためのプロセス
junkifurukawa
1
110
spanner-autoscalerに学ぶ CRD設計パターン 〜自動化と緊急時対応を両立する Kubernetesコントローラーの作り方〜
tkuchiki
0
210
AIに賢く動いてもらうためのコンテキスト〜Snowflake女子会 vol.8
snowwmn0824
0
200
【ゲームメーカーズスクランブル2026】『Shadowverse: Worlds Beyond』UIとアニメーションで実現する最高のユーザー体験を叶えるプロトタイピング
cygames
PRO
1
700
GitHub Agentic Workflows を触ってみる
htkym
2
880
Confitura 2026
logico_jp
0
110
Amazon Bedrock Agents ClassicからAmazon Bedrock AgentCoreへ移行した際、ガードレール設定が2箇所に割れた話
matsunobu
0
160
20260929_AmazonGuardDutyの検出通知メールにAWS DevOpsAgentの調査結果を追加する
yhana
1
380
Oracle Cloud Infrastructure(OCI):Onboarding Session(はじめてのOCI/Oracle Supportご利⽤ガイド)
oracle4engineer
PRO
3
21k
いちAWSエンジニアのAI活用を振り返る #devio2026 / devio osaka 2026 kawahara
masahirokawahara
1
290
Featured
See All Featured
Lessons Learnt from Crawling 1000+ Websites
charlesmeaden
PRO
1
1.6k
HDC tutorial
michielstock
2
930
Designing Powerful Visuals for Engaging Learning
tmiket
1
580
Gemini Prompt Engineering: Practical Techniques for Tangible AI Outcomes
mfonobong
2
560
The AI Search Optimization Roadmap by Aleyda Solis
aleyda
1
6.3k
Responsive Adventures: Dirty Tricks From The Dark Corners of Front-End
smashingmag
254
22k
Navigating the Design Leadership Dip - Product Design Week Design Leaders+ Conference 2024
apolaine
2
450
Hiding What from Whom? A Critical Review of the History of Programming languages for Music
tomoyanonymous
3
1.3k
Optimizing for Happiness
mojombo
378
71k
Design and Strategy: How to Deal with People Who Don’t "Get" Design
morganepeng
133
20k
End of SEO as We Know It (SMX Advanced Version)
ipullrank
3
4.4k
JAMstack: Web Apps at Ludicrous Speed - All Things Open 2022
reverentgeek
1
620
Transcript
ܗࣜख๏(formal-methods)ೖ hbstyle 2016/06/09 - Yoshikawa Ryota ( @rrreeeyyy ) 1
ܗࣜख๏(formal-methods) • ֶΛج൫ͱͨ͠ιϑτΣΞͷ༷هड़ɾ։ൃɾݕূͷٕज़ • ଞͷֶ(ػցֶͱ͔Ͷ)ಉ༷ʹֶతղੳΛใֶͰग़དྷΔʁ • ઃܭͷ৴པੑɾݎ࿚ੑͷ্Λతͱ͍ͯ͠Δ • ܗࣜݴޠɾཧཧֶɾܕγεςϜɾతσʔλܕͳͲΛ༻ •
͜ͷลͷ͜ͱʹڵຯ͕͋Δ • ֶ෦࣌ʹ TaPL 1 ͱ͍͏ຊΛྠಡͨ͠ܦݧΑΓ • ݎ࿚Ͱґଘੑͷඇৗʹߴ͍γεςϜ(ۜߦͱ͔ߤۭػͱ͔ϩέοτͱ͔)ͰΑ͘༻͍ΒΕΔ • NASA/AWS/FeliCa/TradeOne(ূ݊)/SHOLIS(ߤۭ) [^2] • ۙͳͱ͜ΖͰݴ͑ CCS Injection(OpenSSL) ͷ੬ऑੑͳΜ͔ 1 https://www.cis.upenn.edu/~bcpierce/tapl/ [^2]: http://www.ipa.go.jp/files/000026875.pdf hbstyle 2016/06/09 - Yoshikawa Ryota ( @rrreeeyyy ) 2
ܗࣜख๏ͷछྨ • Ͳͷਫ४ͰΔ͔ɺͱ͍͏ͷ͕େ͖͚ͯ͘ 3 ͭ • ܗ༷ࣜهड़ (Formal specification) •
ܗࣜత։ൃ͓Αͼݕূ (Formal development and formal verification) • ࣗಈݕূ (Theorem provers) • Ξϓϩʔν͕େ͖͚ͯ͘ 2 ͭ • ఆཧূ໌ (Explicit Model Checker) • Ϟσϧݕࠪ (Symbolic Model Checker) hbstyle 2016/06/09 - Yoshikawa Ryota ( @rrreeeyyy ) 3
ܗࣜख๏ͷਫ४ • ܗ༷ࣜهड़ (Formal specification) • ܗࣜख๏Λ༻͍༷ͯΛهड़͢Δ • ϓϩάϥϜͷ։ൃࣗମܗࣜख๏ͱরΒ͠߹Θͤͳ͕Βߦ͏ •
ܗࣜత։ൃ͓Αͼݕূ (Formal development and formal verification) • ܗࣜख๏Λ༻͍༷ͯΛهड़͢Δ(B-method3 ͳͲ) • هड़༷ͨ͠ΛߋʹৄࡉԽ͍͖ͯ͠ϓϩάϥϜΛ࡞͢ΔͳͲ • ࣗಈݕূ (Theorem provers) • ࣗಈఆཧূ໌ʹͯػցతͳূ໌Λߦ͏ • ఆཧΛ༩͑ΔͱϓϩάϥϜ͕ؤுͬͯূ໌ͯ͘͠ΕΔΑ͏ͳͷ 3 ύϦͷϝτϩ 14 ߸ઢͳͲͰΘΕ͍ͯΔΒ͍͠ hbstyle 2016/06/09 - Yoshikawa Ryota ( @rrreeeyyy ) 4
ܗࣜख๏ͷΞϓϩʔν • ఆཧূ໌ • γεςϜΛཧࣜͷू߹ͱͯ͠هड़͢Δ • ཧࣜΛެཧͱਪنଇʹͱ͍ͮͯূ໌͍ͯ͘͠ • େମͷ߹ͰࣗಈͰূ໌Ͱ͖ͳ͍ͷͰਓ͕ؒࢧԉ͠ͳ͕Βূ໌͢Δ •
B-method ͳͲ͕༗໊ • Ϟσϧݕࠪ • ରͱ͢ΔγεςϜΛঢ়ଶભҠਤͰϞσϧԽ • ࣌૬ཧࣜ4ͱݺΕΔࣜͰੑ࣭Λهड़ • ঢ়ଶભҠͷঢ়ଶΛཏ୳ࡧͯ࣌͠૬ཧࣜΛຬ͔ͨ͢ݕࠪ͢Δ • SPIN ͳͲ͕༗໊ 4 ࣌ؒͱͷؔͰมԽ͢Δঢ়ଶΛهड़͢Δཧࣜͷ͜ͱ hbstyle 2016/06/09 - Yoshikawa Ryota ( @rrreeeyyy ) 5
ܰྔͳܗࣜख๏ • ܗࣜख๏͍͠ • ϞσϧݕࠪΈ߹Θͤരൃ͕ى͖Δ • ఆཧূ໌େମͷ߹ͰࣗಈͰূ໌Ͱ͖ͳ͍ • ιϑτΣΞͷҰ෦ͷঢ়ଶΛཏతʹݕࠪ͢Δ •
΄ͱΜͲͷܽؕɺখ͍͞୳ࡧൣғͰ͋ͬͯྫͱͯ͠ൃݟ͞ΕΔ (Small Scope Hypothesis) • ࠷ܽؕͷى͖ͦ͏ͳॴΛूதతʹݕࠪ͢Δͷ͕ྑ͍ͩΖ͏ͱ͍͏ൃ (Daniel Jackson) • Alloy Analyzer ͳͲ͕༗໊ • ΠϯϑϥߏͰܗࣜख๏ΛऔΓೖΕΑ͏ͱ͢Δਓ͍Δ 5 5 http://ccvanishing.hateblo.jp/entry/2016/06/06/051120 hbstyle 2016/06/09 - Yoshikawa Ryota ( @rrreeeyyy ) 6
AWS ͷྫ • AWS Ͱ 2011 ͔Βܗࣜख๏Λ࠾༻͍ͯ͠Δ 6 • ࢄγεςϜͷΞϧΰϦζϜઃܭͳͲ
• DynamoDB/S3/EBS ͳͲ • AWS Ͱ TLA+ ͱ͍͏ͷΛͬͯܗࣜख๏Λѻ͍ͬͯΔ • ࠷ॳʹ༗༻ੑ͕࣮ূ͞Εͨͷ DynamoDB • େମೋि͙ؒΒ͍Ͱ TLA+ ͰΞϧΰϦζϜ͕ॻ͚ͨΒ͍͠ • ݕূ༷ͯ͠ʑͳোύλʔϯͷચ͍ग़͠ʹޭ • DynamoDB ͷޭΛड͚ͯ S3/EBS ͳͲͰܗࣜख๏͕औΓೖΕΒΕΔ 6 How Amazon web services uses formal methods: http://dl.acm.org/citation.cfm?id=2749359.2699417 hbstyle 2016/06/09 - Yoshikawa Ryota ( @rrreeeyyy ) 7
Raft Λ TLA+ Ͱهड़ͨ͠ྫ • https://github.com/ongardie/raft.tla/blob/master/raft.tla CONSTANTS RequestVoteRequest, RequestVoteResponse, AppendEntriesRequest,
AppendEntriesResponse Quorum == {i \in SUBSET(Server) : Cardinality(i) * 2 > Cardinality(Server)} InitHistoryVars == /\ elections = {} /\ allLogs = {} /\ voterLog = [i \in Server |-> [j \in {} |-> <<>>]] InitServerVars == /\ currentTerm = [i \in Server |-> 1] /\ state = [i \in Server |-> Follower] /\ votedFor = [i \in Server |-> Nil] InitCandidateVars == /\ votesResponded = [i \in Server |-> {}] /\ votesGranted = [i \in Server |-> {}] hbstyle 2016/06/09 - Yoshikawa Ryota ( @rrreeeyyy ) 8
ܕγεςϜฒྻॲཧͱ͔ͷྫ • ܕγεςϜ: ू߹ͱͯ͠ߟ͑Δ • ܕ(Int ͱ͔)ू߹ɾͦͷܕʹॴଐ͢Δมू߹ཁૉ • ܭࢉϞσϧ: ϥϜμܭࢉͱ͍͏ܭࢉܕΛ͏
• (͜Ε Python ͷ lambda x: x ͷҙຯ) • ฒߦܭࢉϞσϧ: πܭࢉͳͲͷܭࢉܕΛ͏ • (͜Ενϟωϧ x ʹ ΛૹΔͱ͍͏ҙຯ) hbstyle 2016/06/09 - Yoshikawa Ryota ( @rrreeeyyy ) 9
·ͱΊ • ܗࣜख๏ʹೖͨ͠ • ΑΓ҆શͰݎ࿚ͳιϑτΣΞΛ࡞Δʹܗࣜख๏͕༗ޮͰ͋Δ • ݱঢ়͗͢͠Δ͕ʑͷۀͳͲʹద༻Ͱ͖ΔͷͰʁ • ιϑτΣΞςετͰঢ়ଶΛͯ͢ཏ͢Δͷ͍͠ •
ܕγεςϜϥϜμܭࢉπܭࢉීஈͷϓϩάϥϛϯάͱؔ࿈͍ͯͯ͠໘ന͍ • ͳͥ Rust ܕ҆શͱ͞Ε͍ͯΔͷ͔ʁͳͥ C ܕ҆શͰͳ͍ͷ͔ʁ • ͬͱܗࣜख๏͕؆୯ʹͳΕ͍͍ͳ͋ͱࢥ͍ͬͯΔ hbstyle 2016/06/09 - Yoshikawa Ryota ( @rrreeeyyy ) 10
ࢀߟࢿྉ • http://dl.acm.org/citation.cfm?id=2749359.2699417 • http://research.microsoft.com/en-us/um/people/lamport/tla/ amazon.html • https://brooker.co.za/blog/2014/08/09/formal-methods.html • http://brooker.co.za/blog/2015/03/29/formal.html
• https://www.infoq.com/presentations/aws-testing-tla • http://perspectives.mvdirona.com/2014/07/challenges-in-designing- at-scale-formal-methods-in-building-robust-distributed-systems/ hbstyle 2016/06/09 - Yoshikawa Ryota ( @rrreeeyyy ) 11