toolly
登录/注册
返回

property-based-testing

🔒 测试与安全
访问 GitHub

通过生成随机输入验证代码在各类边界条件下的行为一致性,适用于序列化、解析、归一化及纯函数等场景,能有效发现隐含缺陷并提升测试覆盖率,尤其适合需要高可靠性的算法与智能合约验证。

简介

通过生成随机输入验证代码在各类边界条件下的行为一致性,适用于序列化、解析、归一化及纯函数等场景,能有效发现隐含缺陷并提升测试覆盖率,尤其适合需要高可靠性的算法与智能合约验证。

核心能力速览
✓所属分类:🔒 测试与安全
✓通过 Agent Skills 协议,将「能力」封装为可复用、可安装的 AI 组件
✓支持按需加载领域知识与工具,让通用模型转变为特定任务的专家
适用场景

适用于「🔒 测试与安全」相关场景,可作为可复用的 AI 能力组件,接入支持 Agent Skills 的 AI 客户端(如 Claude、Cursor、Cline 等),按需调用以扩展模型能力。

Skills.MD
nameproperty-based-testing
effortlow
descriptionWrites, reviews, and debugs property-based tests — Hypothesis, fast-check, proptest, jqwik, rapid, and Echidna or Medusa for Solidity invariants. Use whenever tests should cover a whole input domain instead of a hand-picked list of examples: encode/decode and serialize/deserialize pairs, parsers, canonicalizers and normalizers, validators, numeric and Decimal types, comparators and sort order, data structures, and smart-contract state invariants. Also use when adding cases to an existing @given, fast-check, or proptest suite, when judging whether existing property tests assert anything real, and when a generator has shrunk a counterexample and you need to tell a wrong property from a genuine bug. Not for coverage-guided binary fuzzing (libFuzzer, AFL), mutation-testing campaigns, static analysis, benchmarking, or end-to-end UI tests.

Property-Based Testing

An example test asserts one point. A property asserts a rule over the whole input domain and lets the generator hunt for the counterexample. That trade is worth making when the code has an algebraic shape — an inverse, an invariant, an oracle — and not otherwise. Code with no such shape gets example tests; saying so is a valid outcome.

Check first whether the shape is missing or merely buried. A calculation wrapped in I/O, a string built by concatenation, an in-place mutation — each has a property and no seam to assert it through. See references/refactoring.md before concluding there is nothing to assert.

Property catalog

Property Formula Where it applies
Roundtrip decode(encode(x)) == x Serialization, conversion pairs
Inverse f(g(x)) == x encrypt/decrypt, compress/decompress
Oracle new(x) == reference(x) Optimization, refactoring, reimplementation
Idempotence f(f(x)) == f(x) Normalization, formatting, sorting
Invariant Holds before and after Any transformation, contract state
Easy to verify is_sorted(sort(x)) Complex algorithms with cheap checkers
Commutativity f(a, b) == f(b, a) Binary and set operations
Associativity f(f(a,b), c) == f(a, f(b,c)) Combining operations
Identity f(x, e) == x Operations with a neutral element

Strength ordering, weakest to strongest: no crash → type preservation → invariant → idempotence → roundtrip / oracle.

Assert the strongest property the code supports. "No crash" alone rarely justifies the dependency — if that is all you can find, either a small rearrangement exposes something stronger, or the honest report is that this code is a poor PBT candidate. Rule out the first before settling for the second.

The two ways a property test asserts nothing

  • Tautology. assert add(a, b) == a + b restates the implementation; no bug they share can fail it. Pick a property that constrains the function without recomputing it. Note the exception: f(x) == f(x) is a genuine determinism property when f is not obviously pure — serializers over dicts or sets, hashing, anything reading the clock.
  • Vacuity. assume() that filters out nearly every input passes without exercising anything, and self-contradictory assume() passes having run zero cases. Push constraints into the strategy so the generator produces valid inputs directly.

Where to look next

Load the one that matches the task in front of you:

Task File
Writing new tests, designing strategies references/generating.md
The code has no property to assert yet references/refactoring.md
Reviewing existing property tests references/reviewing.md
A property test just failed references/interpreting-failures.md
Library choice, Echidna and Medusa references/libraries.md

Introducing PBT to a project that lacks it

If the project already uses a PBT library, just write the tests in it. If it does not, adding one is a dependency decision that belongs to the user — offer it once with the specific property you would write, and take the answer either way.

快捷安装

在终端执行以下命令,即可将本 Skill 安装到本地 AI 客户端:

npx skills add trailofbits/skills

相关推荐