Adding Change Impact Analysis to the Formal Verification of C Programs Serge Autexier and Christoph Lüth? Deutsches Forschungszentrum für Künstliche Intelligenz (DFKI), Enrique-Schmidt-Str. 5, 28359 Bremen, Germany
[email protected],
[email protected] Abstract. Handling changes to programs and specifications efficiently is a particular challenge in formal software verification. Change impact analysis is an approach to this challenge where the effects of changes made to a document (such as a program or specification) are described in terms of rules on a semantic representation of the document. This allows to describe and delimit the effects of syntactic changes semantically. This paper presents an application of generic change impact analysis to formal software verification, using the GMoC and SAMS tools. We adapt the GMoC tool for generic change impact analysis to the SAMS verification framework for the formal verification of C programs, and show how a few simple rules are sufficient to capture the essence of change management. 1 Introduction Software verification has come of age, and a lot of viable approaches to verifying the correctness of an implementation with respect to a given specification exist. However, the real challenge in software verification is to cope with changes — real software is never finished, the requirements may change, the implementa- tion may change, or the underlying hardware may change (particularly in the embedded domain, where hardware is a major cost factor). Here, many existing approaches show weaknesses; it is not untypical to handle changes by rerunning the verification and see where it fails (though there exist more sophisticated approaches [1, 5], cf.