π€ AI Summary
Verifying structured concurrent programs featuring procedure calls and parallel composition remains a key challenge in commutativity-based reasoning. This work proposes a novel reduction method that, for the first time, unifies and flexibly combines two fundamental strategies: safely replacing parallel composition with sequential composition, and generalizing Liptonβs reduction to support atomic blocks containing (recursive) procedure calls. The approach significantly broadens the applicability of reduction-based reasoning while preserving the original concurrency semantics. We implement this technique in Civl and successfully verify several challenging benchmarks, including snapshot objects, fault-tolerant linearizable registers, the FLASH cache coherence protocol, and a complex two-phase commit protocol.
π Abstract
Commutativity reasoning based on Lipton's movers is a powerful technique for verification of concurrent programs. The idea is to define a program transformation that preserves a subset of the initial set of interleavings, which is sound modulo reorderings of commutative actions. Scaling commutativity reasoning to routinely-used features in software systems, such as procedures and parallel composition, remains a significant challenge. In this work, we introduce a novel reduction technique for structured concurrent programs that unifies two key advances. First, we present a reduction strategy that soundly replaces parallel composition with sequential composition. Second, we generalize Lipton's reduction to support atomic sections containing (potentially recursive) procedure calls. Crucially, these two foundational strategies can be composed arbitrarily, greatly expanding the scope and flexibility of reduction-based reasoning. We implemented this technique in Civl and demonstrated its effectiveness on a number of challenging case studies, including a snapshot object, a fault-tolerant and linearizable register, the FLASH cache coherence protocol, and a non-trivial variant of Two-Phase Commit.