What TLA+ can and can't check

· Hillel Wayne · Sept. 30, 2026, 1:47 p.m.
Summary
This post by Hillel Wayne discusses the capabilities and limitations of TLA+, a formal verification method, in checking properties of software systems. While TLA+ excels at verifying safety properties, it struggles with defining complex behaviors and certain reachability properties. Wayne challenges the recent enthusiasm for formal verification, highlighting that it cannot guarantee correct code from correct designs and points out specific properties that TLA+ cannot express, emphasizing the need for users to understand its boundaries for effective use.
AUTHOR
BLOG POST FEATURED ON

Add this plugin to your blog