III FASE FASE-1: Specifications

TAPSOFT '97: Theory and Practice of Software Development

Volume 1214 of the series Lecture Notes in Computer Science pp 520-534


Protective interface specifications

  • Gary T. LeavensAffiliated withDepartment of Computer Science, Iowa State University
  • , Jeannette M. WingAffiliated withComputer Science Department, Carnegie Mellon University


The interface specification of a procedure describes the procedure's behavior using pre- and postconditions. These pre- and postconditions are written using various functions. If some of these functions are partial, or underspecified, then the procedure specification may not be well-defined.

We show how to write pre- and postcondition specifications that avoid such problems, by having the precondition “protect” the postcondition from the effects of partiality and underspecification. We formalize the notion of protection from partiality in the context of specification languages like VDM-SL and COLD-K. We also formalize the notion of protection from underspecification for the Larch family of specification languages, and for Larch show how one can prove that a procedure specification is protected from the effects of underspecification.