跳到主要内容
知仓学习社ZHICANG

property-based-testing

Writes, reviews, and debugs property-based tests — Hypothesis, fast-check, proptest, jqwik, rapid, and Echidna or Medusa for Solidity invariants. Us…

不碰外部(只输出文字)无严重或高危命中trailofbits/skills

它会碰到什么

扫了多少8 个文本文件,35 KB
它会碰到什么不碰外部(只输出文字)
命中总数2 处
命中统计严重 0 · 高 0 · 中 0 · 低 0

这一栏是扫描器报的事实,不是结论。命中多不等于有毒(安全工具、规则库、示例脚本本来就会包含危险写法),命中少也不等于干净。它和你手上的凭据、文件、网络有什么关系,需要你自己看。

技能内容

Property-Based Testing

An example test asserts one point. A property asserts a rule over the whole input

domain and lets the generator hunt for the counterexample. That trade is worth making

when the code has an algebraic shape — an inverse, an invariant, an oracle — and not

otherwise. Code with no such shape gets example tests; saying so is a valid outcome.

Check first whether the shape is missing or merely buried. A calculation wrapped in I/O,

a string built by concatenation, an in-place mutation — each has a property and no seam

to assert it through. See [references/refactoring.md](references/refactoring.md) before

concluding there is nothing to assert.

Property catalog

| Property | Formula | Where it applies |

|---|---|---|

| Roundtrip | decode(encode(x)) == x | Serialization, conversion pairs |

| Inverse | f(g(x)) == x | encrypt/decrypt, compress/decompress |

| Oracle | new(x) == reference(x) | Optimization, refactoring, reimplementation |

| Idempotence | f(f(x)) == f(x) | Normalization, formatting, sorting |

| Invariant | Holds before and after | Any transformation, contract state |

| Easy to verify | is_sorted(sort(x)) | Complex algorithms with cheap checkers |

| Commutativity | f(a, b) == f(b, a) | Binary and set operations |

| Associativity | f(f(a,b), c) == f(a, f(b,c)) | Combining operations |

| Identity | f(x, e) == x | Operations with a neutral element |

Strength ordering, weakest to strongest:

no crash → type preservation → invariant → idempotence → roundtrip / oracle.

Assert the strongest property the code supports. "No crash" alone rarely justifies the

dependency — if that is all you can find, either a small rearrangement exposes something

stronger, or the honest report is that this code is a poor PBT candidate. Rule out the

first before settling for the second.

The two ways a property test asserts nothing

  • Tautology. assert add(a, b) == a + b restates the implementation; no bug they

share can fail it. Pick a property that constrains the function without recomputing

it. Note the exception: f(x) == f(x) is a genuine determinism property when f

is not obviously pure — serializers over dicts or sets, hashing, anything reading

the clock.

  • Vacuity. assume() that filters out nearly every input passes without

exercising anything, and self-contradictory assume() passes having run zero cases.

Push constraints into the strategy so the generator produces valid inputs directly.

Where to look next

Load the one that matches the task in front of you:

| Task | File |

|---|---|

| Writing new tests, designing strategies | [references/generating.md](references/generating.md) |

| The code has no property to assert yet | [references/refactoring.md](references/refactoring.md) |

| Reviewing existing property tests | [references/reviewing.md](references/reviewing.md) |

| A property test just failed | [references/interpreting-failures.md](references/interpreting-failures.md) |

| Library choice, Echidna and Medusa | [references/libraries.md](references/libraries.md) |

Introducing PBT to a project that lacks it

If the project already uses a PBT library, just write the tests in it. If it does not,

adding one is a dependency decision that belongs to the user — offer it once with the

specific property you would write, and take the answer either way.

想直接用这个技能?

本站把开放许可(MIT / Apache 等)的技能按仓库打包整理到网盘,点一下转存到你自己的网盘,不用一个个从 GitHub 拉。许可未声明的技能只给原始仓库链接,不打包。