TLA+ is considered to be exhaustively-testable pseudocode, and its use likened to drawing blueprints for software systems; TLA is an acronym for Temporal Logic of Actions.
(from TLA+ - Wikipedia)
Leslie is a shallow embedding of the Temporal Logic of Actions (TLA) in Lean 4. It provides a framework for specifying and verifying concurrent and distributed systems with machine-checked proofs.
The library includes:
- Refinement mappings (Abadi-Lamport) with stuttering and invariants
- Multi-action specifications (
ActionSpec) with gated atomic actions - CIVL-style layered refinement with mover types and Lipton reduction
- Round-based distributed algorithms using the Heard-Of (HO) model, with proof rules for round invariants, process-local invariants, and round refinement
- Cutoff theorems for symmetric threshold protocols, reducing parameterized verification (all n) to finite model checking (n β€ K)
- Random simulation for testing invariants before formal verification
Requires elan with Lean 4 v4.27.0.
lake build
Add this project into your lakefile.lean and then:
import LeslieSee MANUAL.md for a complete user guide covering specifications, invariants, refinement, and layered verification.
See docs/round-based-tutorial.md for a tutorial on round-based algorithms, the Heard-Of model, and cutoff reasoning.
Leslie/
βββ Basic.lean Core TLA definitions, syntax, and operators
βββ Refinement.lean Spec structure and refinement mapping theorems
βββ Action.lean GatedAction, ActionSpec (multi-action specs)
βββ Layers.lean CIVL-style layers, mover types, Lipton reduction
βββ Round.lean Round-based algorithms (HO model), proof rules
βββ Cutoff.lean Cutoff theorems for symmetric threshold protocols
βββ Simulate.lean Random trace simulation for testing
βββ Rust/
β βββ CoreSemantics.lean Lean-side semantics for the Rust protocol core
β βββ RuntimeSemantics.lean Lean-side semantics for the Rust runtime contract
βββ Rules/
β βββ Basic.lean Core TLA rules (always, eventually, until, etc.)
β βββ StatePred.lean State predicate rules, init_invariant
β βββ LeadsTo.lean Leads-to reasoning (transitivity, consequence)
β βββ BigOp.lean Big conjunction/disjunction operators
β βββ WF.lean Weak fairness (WF1 rule)
βββ Tactics/
β βββ Basic.lean tla_unfold, tla_merge_always, etc.
β βββ Modality.lean Modal operator tactics
β βββ Structural.lean tla_intros
β βββ StateFinite.lean simp_finite_exec_goal
βββ Gadgets/
β βββ TheoremLifting.lean #tla_lift command
β βββ TheoremDeriving.lean @[tla_derive] attribute
βββ Examples/
β βββ CounterRefinement.lean Simple refinement with stuttering
β βββ TwoPhaseCommit.lean 2PC with refinement proof
β βββ TicketLock.lean Layered refinement + mover proofs
β βββ KVStore.lean Key-value store, 3 safety properties
β βββ Paxos.lean Single-decree Paxos (14 actions)
β βββ LeaderBroadcast.lean Round-based leader broadcast
β βββ FloodMin.lean Flood-min consensus with refinement
β βββ BallotLeader.lean Leader election (general n, pigeonhole)
β βββ OneThirdRule.lean OTR consensus (agreement + validity)
β βββ OneThirdRuleCutoff.lean OTR via cutoff (config-level lock inv)
β βββ VRViewChange.lean VR view change safety
βββ rust/
β βββ Cargo.toml Rust crate for communication, protocol, and driver code
β βββ src/
β βββ comm.rs Round-based communication abstractions
β βββ protocol.rs Pure protocol trait
β βββ driver.rs Runs a protocol over a communication object
βββ docs/
βββ round-based-tutorial.md Tutorial: HO model and cutoff reasoning
βββ mc-tactic-plan.md Plan: model-checking tactic
βββ zero-one-rule.md Plan: value domain reduction
βββ communication-contract.md Runtime contract for tag-based inbox collection
βββ rust-verification-v2.md Revised Rust verification architecture
βββ rust-verification-plan-v2.md Revised implementation plan
| Example | What it demonstrates | Status |
|---|---|---|
| CounterRefinement | Basic refinement with stuttering | Complete |
| TwoPhaseCommit | Refinement with invariant (10 actions) | Complete |
| TicketLock | Layered refinement, mover types | Complete |
| KVStore | Key-value store, 3 safety properties | Complete |
| Paxos | Quorum intersection, 14 actions | Spec complete, 2 sorry |
| Example | What it demonstrates | Status |
|---|---|---|
| LeaderBroadcast | Leader-follower agreement (2 processes) | Complete |
| FloodMin | Flood-min consensus + refinement to consensus spec | Complete |
| BallotLeader | Leader election for general n (majority pigeonhole) | Complete |
| OneThirdRule | Agreement (lock invariant) + validity, general n | Complete |
| OneThirdRuleCutoff | Lock invariant via cutoff, reliable + unreliable comm | Complete |
| VRViewChange | Viewstamped Replication view change safety | 1 sorry |
-
Agreement for OneThirdRule (
OneThirdRule.lean): Fully machine-checked proof that the OneThirdRule consensus algorithm satisfies agreement for any number of processes n, under the 2/3-communication predicate. The proof uses a lock invariant (super-majorities persist once established) and pigeonhole (two super-majorities can't coexist). Also proves validity: any decided value was an initial value. -
Cutoff theorem (
Cutoff.lean): For symmetric threshold protocols with communication closure, safety at all n reduces to checking n β€ K where K = βkΒ·Ξ±_den/(Ξ±_denβΞ±_num)β+1. Fully proved including the scaling lemma, partition sum, and weighted partition sum. -
Unreliable communication (
OneThirdRuleCutoff.lean): The lock invariant is preserved under any valid nondeterministic successor constrained by the HO communication predicate β not just the deterministic reliable case.
- MANUAL.md β Complete user manual: specifications, proofs, refinement, CIVL layers, tactic reference
- docs/round-based-tutorial.md β Tutorial on the Heard-Of model, communication closure, and cutoff reasoning
- docs/mc-tactic-plan.md β Design for a
model-checking tactic using
native_decide - docs/zero-one-rule.md β Design for reducing unbounded value domains to binary
Leslie is ported from the 'Lentil'
implementation, which came out of the
coq-tla library.