Paper2015
How Amazon Web Services Uses Formal Methods
Newcombe et al.
Reports that TLA+ specifications found subtle bugs in production distributed systems that code review and testing had missed, an argument for verification as an everyday engineering tool.
8 pageslink checked 17 Sept 2026