Skip to content

apalache-mc/apalache

Repository files navigation

Apalache Logo

APALACHE

A symbolic model checker for TLA+

master unstable
master badge unstable badge

Apalache translates TLA+ into the logic supported by SMT solvers such as Microsoft Z3. Apalache can check inductive invariants (for fixed or bounded parameters) and check safety of bounded executions (bounded model checking). To see the list of supported TLA+ constructs, check the supported features. In general, Apalache runs under the same assumptions as TLC.

To learn more about TLA+, visit Leslie Lamport's page on TLA+ and his Video course.

Releases

Check the releases page.

We recommend that you run the latest stable docker image apalache/mc:latest, or checkout the source code from master, which accumulates bugfixes over the latest release. For more information, see [the manual][manual-docker]. To try the latest cool features, check out the unstable branch.

Getting started

Community

Industrial examples

Talks

Performance

We are collecting apalache benchmarks. See the Apalache performance when checking inductive invariants and running bounded model checking. Versions 0.6.0 and 0.7.2 are a major improvement over version 0.5.2 (the version reported at OOPSLA19).

Academic papers

To read an academic paper about the theory behind Apalache, check our paper at OOPSLA19. Related reports and publications can be found at the Apalache page at TU Wien.