Designing a Producer-driven Stream Protocol by Formal Refinement

πŸ“… 2026-09-27
πŸ“ˆ Citations: 0
✨ Influential: 0
πŸ“„ PDF
πŸ€– AI Summary
This study addresses the cumbersome nature of Python coroutine pipelines and the ambiguous specifications of JavaScript push-stream protocols by proposing a producer-driven streaming protocol based on formal refinement. Methodologically, the TLA+ specification language and the TLC model checker are employed to ensure design correctness through stepwise refinement verification. The proposed protocol seamlessly integrates synchronous and asynchronous modules, achieving unbounded buffered flow control and graceful termination. Furthermore, it supports independent termination of intermediate modules with explicit reporting of environmental suspension states, thereby avoiding error recovery mechanisms and eliminating the need for dynamic heap allocation. Experimental results demonstrate that the protocol’s critical properties fully satisfy the formal specification. It can express a superset of JavaScript streaming semantics and significantly outperforms existing Python-based solutions.
πŸ“ Abstract
The coroutine has broadly diffused in the practice of concurrent programming in the form of generators and asynchronous functions as well as processes communicating through pipes. We wanted to use coroutines in Python to create single-threaded Unix-style pipelines. Unfortunately, available solutions in Python are cumbersome to use. The JavaScript push-stream protocol appeared to be a good alternative. However, its specification is incomplete and ambiguous. We have used TLA$^{+}$ and the TLC model checker to re-derive the protocol and obtain protocol-specific verification tools. In this paper, we present a formal specification of a push-stream protocol that 1) seamlessly combines synchronous and asynchronous modules, encapsulating the choice within each module; 2) provides flow control without using bounded buffers; 3) gracefully and unambiguously terminates; 4) does not require dynamic allocation of objects on the heap. In addition to completely describing expected behaviours, our specification improves on the original design by 1) allowing the input and output of intermediate pipeline modules to terminate independently and 2) explicitly reporting when a module is pending on the execution environment, to avoid incorrect resuming. We specify the protocol as a sequence of refinement steps and derive by equivalence a specification of what an abstract module may do. We then refine the latter into a module checker that can verify concrete module specifications for conformity. We have verified the key properties of all specifications and the validity of refinement steps with TLC. In supplemental material, we provide all TLA$^{+}$ specifications, show that the protocol is sufficiently expressive to implement a superset of all original JavaScript modules, as well as a performance comparison with Python alternatives and Unix pipes.
Problem

Research questions and friction points this paper is trying to address.

push-stream protocol
coroutine
formal specification
pipeline
flow control
Innovation

Methods, ideas, or system contributions that make the work stand out.

Formal Refinement
Push-Stream Protocol
TLA+
Model Checking
Coroutine
πŸ”Ž Similar Papers
No similar papers found.
πŸ’Ό Related Jobs
No related jobs found.
E
Erick Lavoie
Department of Mathematics and Informatics, University of Basel, Switzerland