proving-change-safety
Find what a change could break beyond the diff, then prove the one fact it is safe because of by running real code. Apply when the user asks what a change could break, whether a small diff is safe to merge, or to prove a safety fact before shipping. Use subsystem-walkthrough for how it works. Use design-rationale for motivation. Use dissect for a system-wide entity audit.
Pinned to revision 7c3a5e04075f, so it is the text this page describes rather than whatever the author pushed since.
Files
Every link opens the file at its source, pinned to the revision this page describes.