property-based-testing
- 作者仓库星标 0
- 作者更新于 2026年8月25日 07:09
- 作者仓库 skills
Property-Based Testing
An example test asserts one point. A property asserts a rule over the whole input domain and lets the generator hunt for the counterexample. That trade is worth making when the code has an algebraic shape — an inverse, an invariant, an oracle — and not otherwise. Code with no such shape gets example tests; saying so is a valid outcome.
Check first whether the shape is missing or merely buried. A calculation wrapped in I/O, a string built by concatenation, an in-place mutation — each has a property and no seam to assert it through. See references/refactoring.md before concluding there is nothing to assert.
Property catalog
| Property | Formula | Where it applies |
|---|---|---|
| Roundtrip | decode(encode(x)) == x |
Serialization, conversion pairs |
| Inverse | f(g(x)) == x |
encrypt/decrypt, compress/decompress |
| Oracle | new(x) == reference(x) |
Optimization, refactoring, reimplementation |
| Idempotence | f(f(x)) == f(x) |
Normalization, formatting, sorting |
| Invariant | Holds before and after | Any transformation, contract state |
| Easy to verify | is_sorted(sort(x)) |
Complex algorithms with cheap checkers |
| Commutativity | f(a, b) == f(b, a) |
Binary and set operations |
| Associativity | f(f(a,b), c) == f(a, f(b,c)) |
Combining operations |
| Identity | f(x, e) == x |
Operations with a neutral element |
Strength ordering, weakest to strongest:
no crash → type preservation → invariant → idempotence → roundtrip / oracle.
Assert the strongest property the code supports. "No crash" alone rarely justifies the dependency — if that is all you can find, either a small rearrangement exposes something stronger, or the honest report is that this code is a poor PBT candidate. Rule out the first before settling for the second.
The two ways a property test asserts nothing
- Tautology.
assert add(a, b) == a + brestates the implementation; no bug they share can fail it. Pick a property that constrains the function without recomputing it. Note the exception:f(x) == f(x)is a genuine determinism property whenfis not obviously pure — serializers over dicts or sets, hashing, anything reading the clock. - Vacuity.
assume()that filters out nearly every input passes without exercising anything, and self-contradictoryassume()passes having run zero cases. Push constraints into the strategy so the generator produces valid inputs directly.
Where to look next
Load the one that matches the task in front of you:
| Task | File |
|---|---|
| Writing new tests, designing strategies | references/generating.md |
| The code has no property to assert yet | references/refactoring.md |
| Reviewing existing property tests | references/reviewing.md |
| A property test just failed | references/interpreting-failures.md |
| Library choice, Echidna and Medusa | references/libraries.md |
Introducing PBT to a project that lacks it
If the project already uses a PBT library, just write the tests in it. If it does not, adding one is a dependency decision that belongs to the user — offer it once with the specific property you would write, and take the answer either way.
- 流狐分类
- 文档
- 作者声明 Agent
- 未找到明确声明;不据此推断已兼容或已测试
- 静态检查
- 88 / 100 · 启发式扫描,不代表运行安全
- 作者 / 版本 / 许可
- @trailofbits · 未声明 license
- 流狐 Token 估算
- 低消耗
- 流狐接入估算
- 即装即用
- 是否需要外部 API Key
- 未发现要求
- 检测到的系统要求
- 未声明
- 底层运行要求
- 未声明
- 检测到的文件与系统行为
-
- 只读
- 允许写入 / 修改
- 检测到的网络行为
- 仅限本地
- 安装命令数
- 无(仅作为资料)
档案由构建时根据 SKILL.md 与安装命令自动衍生,可能与作者实际意图存在差异。
需要注意: 未限定 allowed-tools,默认拥有全部工具权限。
作者没有在当前 SKILL.md 中定义固定输出样例。 Property · Formula · Where it applies Roundtrip · decode(encode(x)) == x · Serialization, conversion pairs Inverse · f(g(x)) == x · encrypt/decrypt, compress/decompress
Tautology. assert add(a, b) == a + b restates the implementation; no bug they share can fail it. Pick a property that constrains the function without recomputing it. Note the exception: f(x) == f(x) is a genuine determinism property when f
Load the one that matches the task in front of you: Task · File Writing new tests, designing strategies · references/generating.md
If the project already uses a PBT library, just write the tests in it. If it does not, adding one is a dependency decision that belongs to the user — offer it once with the specific property you would write, and take the answer either way.
# Property-Based Testing
An example test asserts one point. A property asserts a rule over the whole input
domain and lets the generator hunt for the counterexample. That trade is worth making
when the code has an algebraic shape — an inverse, an invariant, an oracle — and not
otherwise. Code with no such shape gets example tests; saying so is a valid outcome.
Check first whether the shape is missing or merely buried. A calculation wrapped in I/O,
a string built by concatenation, an in-place mutation — each has a property and no seam
to assert it through. See [references/refactoring.md](references/refactoring.md) before
concluding there is nothing to assert.
## Property catalog
| Property | Formula | Where it applies |
|---|---|---|
| Roundtrip | `decode(encode(x)) == x` | Serialization, conversion pairs |
| Inverse | `f(g(x)) == x` | encrypt/decrypt, compress/decompress |
| Oracle | `new(x) == reference(x)` | Optimization, refactoring, reimplementation |
| Idempotence | `f(f(x)) == f(x)` | Normalization, formatting, sorting |
| Invariant | Holds before and after | Any transformation, contract state |
| Easy to verify | `is_sorted(sort(x))` | Complex algorithms with cheap checkers |
| Commutativity | `f(a, b) == f(b, a)` | Binary and set operations |
| Associativity | `f(f(a,b), c) == f(a, f(b,c))` | Combining operations |
| Identity | `f(x, e) == x` | Operations with a neutral element |
Strength ordering, weakest to strongest:
`no crash → type preservation → invariant → idempotence → roundtrip / oracle`.
Assert the strongest property the code supports. "No crash" alone rarely justifies the
dependency — if that is all you can find, either a small rearrangement exposes something
stronger, or the honest report is that this code is a poor PBT candidate. Rule out the
… 作者原文负责流程事实;流狐只索引当前章节、要点、文件与命令。
章节 -> Property catalog → The two ways a property test asserts nothing → Where to look next → Introducing PBT to a project that lacks it
要点 -> Tautology. · Vacuity. · An example test asserts one point. · Check first whether the shape is missing or merely buried. · Strength ordering, weakest to strongest: no crash → type preservation → invariant → idempotence → roundtrip / oracle. · Assert the strongest property the code supports. · - Tautology. · If the project already uses a PBT library, just write the tests in it.
文件/命令 -> decode(encode(x)) == x · f(g(x)) == x · new(x) == reference(x) · f(f(x)) == f(x) · issorted(sort(x)) · f(a, b) == f(b, a) · f(f(a,b), c) == f(a, f(b,c)) · f(x, e) == x
内容 SHA-256 -> d99233df49df
原文结构
适用与边界
原文中的明确线索
decode(encode(x)) == x、f(g(x)) == x、new(x) == reference(x)、f(f(x)) == f(x)、issorted(sort(x))、f(a, b) == f(b, a)、f(f(a,b), c) == f(a, f(b,c))、f(x, e) == x