case	guarantee_plain	property_kind	method	assumptions_or_scope	authors	source_location	quote_or_original_cell	paper_url	source_url	model_code_proof_effort	gap
IronRSL	replicated service behaves as specified; a repeatedly submitted request eventually receives a reply	safety+liveness	Dafny implementation proof; state-machine refinement; temporal proof	liveness: live quorum, eventual bounded-time networking, minimum loop frequency, sufficient memory; safety: message integrity	Hawblitzel et al.	IronFleet §1 and §2.5	a message sent infinitely often is eventually delivered	https://www.andrew.cmu.edu/user/bparno/papers/ironfleet.pdf	https://github.com/microsoft/Ironclad/tree/main/ironfleet		spec/event loop/compiler/runtime/OS/hardware trusted
IronKV transmission	sharded store functional correctness; repeated transmission eventually delivers each message	safety+liveness	Dafny implementation proof	fair networking; host main loops execute infinitely often	Hawblitzel et al.	IronFleet §1, §2.5		https://www.andrew.cmu.edu/user/bparno/papers/ironfleet.pdf	https://github.com/microsoft/Ironclad/tree/main/ironfleet		message-delivery theorem is narrower than every client operation terminating
Verdi lock service	at most one client owns lock	safety	Coq implementation proof; extracted OCaml	network semantics vary by transformer	Wilcox et al.	Verdi §2–§4		https://homes.cs.washington.edu/~mernst/pubs/verify-distsystem-pldi2015.pdf	https://github.com/uwplse/verdi		framework paper leaves liveness for future work
Verdi Raft	completed operations behave as one sequential state-machine history	safety	Coq implementation proof; extracted OCaml	defined failure/recovery network semantics	Woos et al.	CPP 2016 abstract and invariant development	discovering and proving 90 system invariants	https://homes.cs.washington.edu/~mernst/pubs/raft-proof-cpp2016.pdf	https://github.com/uwplse/verdi-raft		separate completed proof paper; reconfiguration extensions not included
Anvil ZooKeeper controller	fixed desired state eventually reached and retained	liveness; conformance	Verus temporal-model proof + Rust-step/model-step conformance	desired state stabilizes; disruptive faults eventually stop; fair actions; modeled external API behavior	Sun et al.	Anvil §4.2, §4.3.3, §6; Table 1	1134 8352	https://www.usenix.org/system/files/osdi24-sun-xudong.pdf	https://github.com/anvil-verifier/anvil	Table 1 original Exec/Proof cells: 1134/8352; ~2.5 person-months each	trusted Kubernetes/external API model and integration shim; proof includes model code
Anvil RabbitMQ controller	fixed desired state eventually reached and retained	liveness; conformance	Verus temporal-model proof + Rust-step/model-step conformance	desired state stabilizes; disruptive faults eventually stop; fair actions; modeled external API behavior	Sun et al.	Anvil §4.2, §4.3.3, §6; Table 1	1598 7228	https://www.usenix.org/system/files/osdi24-sun-xudong.pdf	https://github.com/anvil-verifier/anvil	Table 1 original Exec/Proof cells: 1598/7228; ~2.5 person-months each	trusted Kubernetes/external API model and integration shim; proof includes model code
Anvil FluentBit controller	fixed desired state eventually reached and retained	liveness; conformance	Verus temporal-model proof + Rust-step/model-step conformance	desired state stabilizes; disruptive faults eventually stop; fair actions; modeled external API behavior	Sun et al.	Anvil §4.2, §4.3.3, §6; Table 1	1208 8395	https://www.usenix.org/system/files/osdi24-sun-xudong.pdf	https://github.com/anvil-verifier/anvil	Table 1 original Exec/Proof cells: 1208/8395; ~2.5 person-months each	trusted Kubernetes/external API model and integration shim; proof includes model code
Welder ReplicaSet controller	desired state eventually reached while compatible controllers interact; interference restrictions hold	safety+liveness+composition	Verus implementation/model conformance and compositional temporal proof	compatible rely/guarantee conditions; eventual stable desired state; environment fairness/fault conditions; acyclic liveness dependencies	Cai et al.	Welder §3, §4, §6		https://doi.org/10.1145/3830418.3843868	https://github.com/anvil-verifier/anvil		partial Kubernetes control plane; trusted environment/integration code
Welder Deployment controller	desired state eventually reached while compatible controllers interact; interference restrictions hold	safety+liveness+composition	Verus implementation/model conformance and compositional temporal proof	compatible rely/guarantee conditions; eventual stable desired state; environment fairness/fault conditions; acyclic liveness dependencies	Cai et al.	Welder §3, §4, §6		https://doi.org/10.1145/3830418.3843868	https://github.com/anvil-verifier/anvil		partial Kubernetes control plane; trusted environment/integration code
Welder StatefulSet controller	desired state eventually reached while compatible controllers interact; interference restrictions hold	safety+liveness+composition	Verus implementation/model conformance and compositional temporal proof	compatible rely/guarantee conditions; eventual stable desired state; environment fairness/fault conditions; acyclic liveness dependencies	Cai et al.	Welder §3, §4, §6		https://doi.org/10.1145/3830418.3843868	https://github.com/anvil-verifier/anvil		partial Kubernetes control plane; trusted environment/integration code
Welder RabbitMQ controller	desired state eventually reached while compatible controllers interact; interference restrictions hold	safety+liveness+composition	Verus implementation/model conformance and compositional temporal proof	compatible rely/guarantee conditions; eventual stable desired state; environment fairness/fault conditions; acyclic liveness dependencies	Cai et al.	Welder §3, §4, §6		https://doi.org/10.1145/3830418.3843868	https://github.com/anvil-verifier/anvil		partial Kubernetes control plane; trusted environment/integration code
Welder four-controller composition	the four verified controllers jointly satisfy CORE	safety+liveness	compatibility obligations and compositional theorem	Deployment depends on ReplicaSet; RabbitMQ depends on StatefulSet	Cai et al.	Welder §1 and §7.1		https://doi.org/10.1145/3830418.3843868	https://github.com/anvil-verifier/anvil		CORE is not complete feature equivalence to official controllers
Grove vKV	key-value operations behave as one sequential service despite recovery/reconfiguration	safety	Coq/Iris proof of Go components	lost/duplicated/reordered messages; independent crashes; known bounds on clock synchronization for leases	Sharma et al.	Grove §2, §3.1 and §1 limitation		https://pdos.csail.mit.edu/papers/grove:sosp23.pdf	https://github.com/mit-pdos/gokv		no progress theorem; Go/tool/runtime trust boundaries apply
Grove cachekv	lease-based cache reads respect the key-value service specification	safety	Coq/Iris proof of Go components	lost/duplicated/reordered messages; independent crashes; known bounds on clock synchronization for leases	Sharma et al.	Grove §2, §3.1 and §1 limitation		https://pdos.csail.mit.edu/papers/grove:sosp23.pdf	https://github.com/mit-pdos/gokv		no progress theorem; Go/tool/runtime trust boundaries apply
Grove distributed lock service	mutual exclusion contract available to verified clients	safety	Coq/Iris proof of Go components	lost/duplicated/reordered messages; independent crashes; known bounds on clock synchronization for leases	Sharma et al.	Grove §2, §3.1 and §1 limitation		https://pdos.csail.mit.edu/papers/grove:sosp23.pdf	https://github.com/mit-pdos/gokv		no progress theorem; Go/tool/runtime trust boundaries apply
Grove bank client	bank application meets its contract using verified key-value and lock service interfaces	safety	Coq/Iris proof of Go components	lost/duplicated/reordered messages; independent crashes; known bounds on clock synchronization for leases	Sharma et al.	Grove §2, §3.1 and §1 limitation		https://pdos.csail.mit.edu/papers/grove:sosp23.pdf	https://github.com/mit-pdos/gokv		no progress theorem; Go/tool/runtime trust boundaries apply
Aneris load balancer	concurrent requests routed according to component contracts	safety	Coq/Iris modular implementation proof	Aneris language and network semantics; node-local contracts	Krogh-Jespersen et al.	Aneris abstract, §4 and §5		https://iris-project.org/pdfs/2020-esop-aneris-final.pdf	https://github.com/logsem/aneris		not existing production executable code
Aneris two-phase commit with replicated logging	logging client uses certified commit protocol contracts	safety	Coq/Iris modular implementation proof	Aneris language and network semantics; node-local contracts	Krogh-Jespersen et al.	Aneris abstract, §4 and §5		https://iris-project.org/pdfs/2020-esop-aneris-final.pdf	https://github.com/logsem/aneris		not existing production executable code
Trillium Paxos	Aneris program refines TLA+ Paxos model; transfers safety trace properties	safety	Coq trace refinement	Aneris distributed semantics and modeled protocol/network assumptions	Timany et al.	Trillium §5		https://iris-project.org/pdfs/2024-popl-trillium.pdf	https://github.com/logsem/trillium		general distributed liveness is future work; Fairis liveness applies to concurrent-language instantiation
Adore SRaft reconfiguration	consensus safety preserved across parameterized reconfiguration	safety	Coq protocol model refinement	quorum and reconfiguration predicates satisfy paper conditions	Honoré et al.	Adore §7 and conclusion		https://flint.cs.yale.edu/flint/publications/adore.pdf	https://doi.org/10.5281/zenodo.6321150	~13.8k total Coq; ~2.5k refinement, §7	no liveness/availability claim; protocol-level proof
Igloo leader election	elected leaders satisfy protocol safety	safety	Isabelle model refinement; VeriFast Java/Nagini Python verification	specified I/O contracts; authentication assumes cryptographic/parser abstraction	Sprenger et al.	Igloo §3–§4 and §6		https://arxiv.org/pdf/2010.04749	unresolved		safety only; source repository unresolved
Igloo primary-backup replication	implementation traces satisfy abstract replication model	safety	Isabelle model refinement; VeriFast Java/Nagini Python verification	specified I/O contracts; authentication assumes cryptographic/parser abstraction	Sprenger et al.	Igloo §3–§4 and §6		https://arxiv.org/pdf/2010.04749	unresolved		safety only; source repository unresolved
Igloo authentication protocol	injective agreement under symbolic attacker model	safety	Isabelle model refinement; VeriFast Java/Nagini Python verification	specified I/O contracts; authentication assumes cryptographic/parser abstraction	Sprenger et al.	Igloo §3–§4 and §6		https://arxiv.org/pdf/2010.04749	unresolved		safety only; source repository unresolved
Chapar store algorithm 1	a visible update never precedes updates it causally depends on	safety	Coq protocol/implementation proof; OCaml extraction	paper causal operational semantics and trusted extraction/serialization/runtime	Lesani et al.	Chapar §4–§7		https://adam.chlipala.net/papers/ChaparPOPL16/ChaparPOPL16.pdf	https://github.com/mit-plv/chapar		does not by itself prove eventual update delivery
Chapar store algorithm 2	a visible update never precedes updates it causally depends on	safety	Coq protocol/implementation proof; OCaml extraction	paper causal operational semantics and trusted extraction/serialization/runtime	Lesani et al.	Chapar §4–§7		https://adam.chlipala.net/papers/ChaparPOPL16/ChaparPOPL16.pdf	https://github.com/mit-plv/chapar		does not by itself prove eventual update delivery
Chapar photo/post client	a visible post referring to a photo has its photo visible	client safety	abstract client model checking with proof transfer to concrete stores	fuel bounds appropriate for terminating client; causal store semantics	Lesani et al.	Chapar §6		https://adam.chlipala.net/papers/ChaparPOPL16/ChaparPOPL16.pdf	https://github.com/mit-plv/chapar		finite clients, not arbitrary application liveness
Chapar Lost-Ring client	reply visibility preserves required earlier-post dependency	client safety	abstract client model checking with proof transfer to concrete stores	fuel bounds appropriate for terminating client; causal store semantics	Lesani et al.	Chapar §6		https://adam.chlipala.net/papers/ChaparPOPL16/ChaparPOPL16.pdf	https://github.com/mit-plv/chapar		finite clients, not arbitrary application liveness
Chapar concurrent linked-list client	construction/traversal assertions hold under causal storage	client safety	abstract client model checking with proof transfer to concrete stores	fuel bounds appropriate for terminating client; causal store semantics	Lesani et al.	Chapar §6		https://adam.chlipala.net/papers/ChaparPOPL16/ChaparPOPL16.pdf	https://github.com/mit-plv/chapar		finite clients, not arbitrary application liveness
OpLib Grow-only Counter	replica state equals the data-type interpretation of its delivered causal operations	safety; convergence for same delivered operations	Aneris/Coq modular implementation proof	causal broadcast library contract; serializable values; operations satisfy datatype-specific commutation conditions	Nieto et al.	Op-based CRDTs §5.3, §6, Table 3		https://iris-project.org/pdfs/2022-oopsla-crdts.pdf	https://github.com/logsem/aneris		eventual message delivery not proved; two compound map uses omitted from individual rows
OpLib Positive-Negative Counter	replica state equals the data-type interpretation of its delivered causal operations	safety; convergence for same delivered operations	Aneris/Coq modular implementation proof	causal broadcast library contract; serializable values; operations satisfy datatype-specific commutation conditions	Nieto et al.	Op-based CRDTs §5.3, §6, Table 3		https://iris-project.org/pdfs/2022-oopsla-crdts.pdf	https://github.com/logsem/aneris		eventual message delivery not proved; two compound map uses omitted from individual rows
OpLib Grow-Only Set	replica state equals the data-type interpretation of its delivered causal operations	safety; convergence for same delivered operations	Aneris/Coq modular implementation proof	causal broadcast library contract; serializable values; operations satisfy datatype-specific commutation conditions	Nieto et al.	Op-based CRDTs §5.3, §6, Table 3		https://iris-project.org/pdfs/2022-oopsla-crdts.pdf	https://github.com/logsem/aneris		eventual message delivery not proved; two compound map uses omitted from individual rows
OpLib Add-Wins Set	replica state equals the data-type interpretation of its delivered causal operations	safety; convergence for same delivered operations	Aneris/Coq modular implementation proof	causal broadcast library contract; serializable values; operations satisfy datatype-specific commutation conditions	Nieto et al.	Op-based CRDTs §5.3, §6, Table 3		https://iris-project.org/pdfs/2022-oopsla-crdts.pdf	https://github.com/logsem/aneris		eventual message delivery not proved; two compound map uses omitted from individual rows
OpLib Remove-Wins Set	replica state equals the data-type interpretation of its delivered causal operations	safety; convergence for same delivered operations	Aneris/Coq modular implementation proof	causal broadcast library contract; serializable values; operations satisfy datatype-specific commutation conditions	Nieto et al.	Op-based CRDTs §5.3, §6, Table 3		https://iris-project.org/pdfs/2022-oopsla-crdts.pdf	https://github.com/logsem/aneris		eventual message delivery not proved; two compound map uses omitted from individual rows
OpLib Two-Part Set	replica state equals the data-type interpretation of its delivered causal operations	safety; convergence for same delivered operations	Aneris/Coq modular implementation proof	causal broadcast library contract; serializable values; operations satisfy datatype-specific commutation conditions	Nieto et al.	Op-based CRDTs §5.3, §6, Table 3		https://iris-project.org/pdfs/2022-oopsla-crdts.pdf	https://github.com/logsem/aneris		eventual message delivery not proved; two compound map uses omitted from individual rows
OpLib Multi-Valued Register	replica state equals the data-type interpretation of its delivered causal operations	safety; convergence for same delivered operations	Aneris/Coq modular implementation proof	causal broadcast library contract; serializable values; operations satisfy datatype-specific commutation conditions	Nieto et al.	Op-based CRDTs §5.3, §6, Table 3		https://iris-project.org/pdfs/2022-oopsla-crdts.pdf	https://github.com/logsem/aneris		eventual message delivery not proved; two compound map uses omitted from individual rows
OpLib Last-Writer-Wins Register	replica state equals the data-type interpretation of its delivered causal operations	safety; convergence for same delivered operations	Aneris/Coq modular implementation proof	causal broadcast library contract; serializable values; operations satisfy datatype-specific commutation conditions	Nieto et al.	Op-based CRDTs §5.3, §6, Table 3		https://iris-project.org/pdfs/2022-oopsla-crdts.pdf	https://github.com/logsem/aneris		eventual message delivery not proved; two compound map uses omitted from individual rows
OpLib Product Combinator	replica state equals the data-type interpretation of its delivered causal operations	safety; convergence for same delivered operations	Aneris/Coq modular implementation proof	causal broadcast library contract; serializable values; operations satisfy datatype-specific commutation conditions	Nieto et al.	Op-based CRDTs §5.3, §6, Table 3		https://iris-project.org/pdfs/2022-oopsla-crdts.pdf	https://github.com/logsem/aneris		eventual message delivery not proved; two compound map uses omitted from individual rows
OpLib Map Combinator	replica state equals the data-type interpretation of its delivered causal operations	safety; convergence for same delivered operations	Aneris/Coq modular implementation proof	causal broadcast library contract; serializable values; operations satisfy datatype-specific commutation conditions	Nieto et al.	Op-based CRDTs §5.3, §6, Table 3		https://iris-project.org/pdfs/2022-oopsla-crdts.pdf	https://github.com/logsem/aneris		eventual message delivery not proved; two compound map uses omitted from individual rows
DaisyNFS	file operations and recovery satisfy filesystem specification despite concurrency/crashes	safety+crash consistency	Coq transaction proof + Dafny sequential verification transfer	GoTxn transaction semantics; trusted layers listed in paper	Chajed et al.	DaisyNFS §3–§4	only 2× as many lines of proof as code	https://pdos.csail.mit.edu/papers/daisy-nfs:osdi22.pdf	https://github.com/mit-pdos/daisy-nfsd		single NFS server storage proof; no multiserver consensus theorem
IronSync Node Replication	concurrent NUMA replication is linearizable	safety	Dafny ownership + localized transition systems	trusted framework encoding; paper memory model	Hance et al.	IronSync §1, §5.1		https://www.andrew.cmu.edu/user/bparno/papers/ironsync.pdf	unresolved		shared memory; no liveness/termination/deadlock theorem
IronSync SplinterCache	concurrent page cache satisfies its data/logical correctness contract	safety	Dafny ownership and global transition proof	trusted framework encoding and supported memory consistency model	Hance et al.	IronSync §1, §5.2		https://www.andrew.cmu.edu/user/bparno/papers/ironsync.pdf	unresolved		shared memory/storage example; source repo not independently checked
Shipwright PBFT	PBFT subprotocol proof development; end-to-end proof unfinished	partial safety/liveness	Dafny partial subprotocol proofs; unfinished system refinement	unforgeable signatures; honest runtime behavior; progress of time/timeouts/network; PBFT fault threshold must be extracted from theorem	Leung et al.	Shipwright §5	progress and are not yet complete. We have not yet proven	https://arxiv.org/abs/2507.14080	unresolved		top-level composed safety/liveness proof unfinished; trusted Go runtime; source repo unresolved
PGo Raft protocol	five Raft safety properties	safety	TLC bounded-instance model checking + compilation to Go	paper checked configuration; compiler/glue/runtime/environment resources trusted; liveness scheduler assumptions need deployment justification	Hackett et al.	PGo Table 2 and §2.1		https://doi.org/10.1145/3575693.3575695	https://github.com/DistCompiler/pgo	Table 2: 22 person-days; 771 MPCal SLOC; 676 glue Go SLOC	not verified compiler; bounded model check is not general implementation proof
PGo Distributed KV	client interaction and consistency	safety	TLC bounded-instance model checking + compilation to Go	paper checked configuration; compiler/glue/runtime/environment resources trusted; liveness scheduler assumptions need deployment justification	Hackett et al.	PGo Table 2 and §2.1		https://doi.org/10.1145/3575693.3575695	https://github.com/DistCompiler/pgo	Table 2: 3 person-days; 256 MPCal SLOC; 383 glue Go SLOC	not verified compiler; bounded model check is not general implementation proof
PGo RaftKV monolithic	client interaction plus Raft properties	safety	TLC bounded-instance model checking + compilation to Go	paper checked configuration; compiler/glue/runtime/environment resources trusted; liveness scheduler assumptions need deployment justification	Hackett et al.	PGo Table 2 and §2.1		https://doi.org/10.1145/3575693.3575695	https://github.com/DistCompiler/pgo	Table 2: 25 person-days; 758 MPCal SLOC; 1099 glue Go SLOC	not verified compiler; bounded model check is not general implementation proof
PGo Lock service	mutual exclusion and liveness	safety+liveness	TLC bounded-instance model checking + compilation to Go	paper checked configuration; compiler/glue/runtime/environment resources trusted; liveness scheduler assumptions need deployment justification	Hackett et al.	PGo Table 2 and §2.1		https://doi.org/10.1145/3575693.3575695	https://github.com/DistCompiler/pgo	Table 2: 2 person-days; 67 MPCal SLOC; 87 glue Go SLOC	not verified compiler; bounded model check is not general implementation proof
PGo PBKV	strong consistency	safety	TLC bounded-instance model checking + compilation to Go	paper checked configuration; compiler/glue/runtime/environment resources trusted; liveness scheduler assumptions need deployment justification	Hackett et al.	PGo Table 2 and §2.1		https://doi.org/10.1145/3575693.3575695	https://github.com/DistCompiler/pgo	Table 2: 10 person-days; 420 MPCal SLOC; 270 glue Go SLOC	not verified compiler; bounded model check is not general implementation proof
PGo CRDT	convergence and termination	safety+liveness	TLC bounded-instance model checking + compilation to Go	paper checked configuration; compiler/glue/runtime/environment resources trusted; liveness scheduler assumptions need deployment justification	Hackett et al.	PGo Table 2 and §2.1		https://doi.org/10.1145/3575693.3575695	https://github.com/DistCompiler/pgo	Table 2: 10 person-days; 160 MPCal SLOC; 185 glue Go SLOC	not verified compiler; bounded model check is not general implementation proof
PGo RaftKV modular	Raft and distributed-KV components checked separately	component safety	separate TLC checks + compiled composition	compatibility of components and glue trusted	Hackett et al.	PGo Table 2 and §2.1		https://doi.org/10.1145/3575693.3575695	https://github.com/DistCompiler/pgo	Table 2: 25 person-days; 1059 glue Go SLOC	Table 2 contains no model-check result for combined modular system
ZooKeeper multi-grained specifications	selected ZooKeeper/Zab invariants checked and discovered bug fixes validated	safety	TLC model checking + model/code conformance	scenario-specific mixed-granularity models and finite checking scope	Ouyang et al.	EuroSys 2025 abstract and §3–§5	six severe bugs that violate five types of invariants	https://arxiv.org/abs/2409.14301	unresolved		not universal Java implementation proof
CCF consensus and client consistency	production consensus and custom client-consistency behaviors checked against TLA+	safety	TLC + model-based and trace conformance testing in CI	modeled protocol and tested executions; CCF confidentiality/integrity boundary is separate	Howard et al.	NSDI 2025 §1 and verification workflow		https://www.usenix.org/conference/nsdi25/presentation/howard	https://github.com/microsoft/CCF		hybrid validation, not universal C++ proof
ShardStore	Rust storage API behavior, crash consistency, and foreground/background concurrency checked	safety+crash consistency	property-based testing + stateless model checking	reference-model scope and harness-controlled schedules/crashes	Bornholt et al.	SOSP 2021 §1 and validation sections	weaker correctness guarantees than full formal verification	https://doi.org/10.1145/3477132.3483540	not public		storage node only; not full distributed S3 proof
