You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
A configurable Z3 budget and a complete account. (#1350)
Agent-facing examples are executed, not just parsed. (#1481)
The language server will not apply an edit that loses a proof. (#1443)
Added
Every runtime check a compiled module contains is on a record, and the checks code generation can emit have one registry (#1479)
The enumerated negative-conformance-fixture lists are gated against the manifest.
The verifier's seed walk infers a generic call's type arguments inside the namespace the call is written in, so an E622 raised for a desugared pipe inside an imported module body is attributed to that module rather than to the entry file — the mirror of the scoping codegen already applies.
The burndown-header word parser rejects malformed hyphenated compounds (twenty-ten, thirty-nineteen) instead of summing them, and the diagnostic-site walker in scripts/check_diagnostic_fields.py scopes decorators, parameter defaults, annotations and base classes to the enclosing site rather than to the definition they decorate — both gaps found in review of the Stage-20 gates.
Rendered diagnostic output in docs is now replayed against live output, for a marker-annotated subset (#954)
error_code uniqueness is now a gate, not a manual audit (#682)
scripts/check_doc_counts.py now cross-checks ROADMAP's burndown header word against both its own table and KNOWN_ISSUES.md
examples/ephemeris.vera — the first floating-point example (#143)
The Z3 budget is configurable, so a verification tier stops depending on the machine (#1350)
The E001 doc example is single-sourced, so its five mirrors cannot drift by hand (#954)
A generated implementation-status appendix, and one vocabulary for obligation outcomes (#1341)
Changed
check_doc_counts.py --release runs on the pull request that raises the version, not on every pull request into main (#1536)
A commit runs the fast gates, CI runs the full suite, and the release PR sets the headline test totals.
Bugs are filed and fixed by class, not by manifestation.
A generic's type argument is now refused when it cannot be inferred, instead of being guessed (#1369)
A refined-ELEMENT position now refuses what it used to disclose (#1430)
The VS Code extension is 0.2.2.
Fixed
A @Nat operand of an @Int operation is a widening: obligated, guarded, and never read as a negative number (#1591)
An integer literal takes its type from its context when it fixes a generic's type argument (#1605)
An imported generic's decreases is proved again through the file that imports it (#1577)
A literal-arithmetic -3 bound at @Int is -3 again: every guard and every obligation reads one classifier of an integer's sign (#1544)
Every check the compiled program performs is obligated where the program evaluates it (#1222)
A match arm is checked knowing that no earlier arm matched (#1562)
A refinement narrowing over a let the verifier cannot translate is left to its guard (#1524)
A module's qualified call to its own function checks again (#1492)
An imported data type named like a prelude type can be constructed again (#1559)
Every recursive function proves it terminates or says it may not (#1492)
The measure is checked across the whole cycle, and a contract cannot call back into its own function (#1521)
A name that resolves to nothing is an error at check, so check implies compile again (#1499)