NivaarExam PrepOfficial exam papers ↗

25-Comp-B11 Advanced Software Design · May 2014

Question 10 of 25: Design by Contract

Nivaar worked solution (AI-drafted; not reviewed by a licensed engineer)

Notes on this paper

98-Comp-B11 Advanced Software Design — National Exams, May 2014. 3 hours, open book, no calculator permitted. The paper is organized into five parts, and candidates were instructed to answer any three (3) questions in Part I, any four (4) in Part II, any three (3) in Part III, any one (1) in Part IV, and any one (1) in Part V — only the first questions answered, in each part, as they appear in the answer book are marked. All questions carry equal weight, so the 12 questions actually marked (3+4+3+1+1 of 25) each count for 100/12 ≈ 8.3% of the paper. All 25 questions are answered below for completeness.

Reference texts: Sommerville, Software Engineering (10th ed., Pearson) — software processes, requirements engineering, agile methods, design principles; Pressman, Software Engineering: A Practitioner's Approach (9th ed.) — supplementary process and quality coverage; Gamma, Helm, Johnson & Vlissides (GoF), Design Patterns: Elements of Reusable Object-Oriented Software — structural/behavioural pattern catalogue (Proxy, Bridge, Strategy, Observer, Template Method, Composite, etc.); Sebesta, Concepts of Programming Languages (12th ed.) — polymorphism, dynamic binding, inheritance and language-level object semantics (also underpins the Java/C++ discussion in Part V). Bertrand Meyer's Object-Oriented Software Construction is cited by name where the paper's own vocabulary (design by contract, open–closed principle) originates there; Barbara Liskov's 1987 substitutability paper is likewise cited by name for Question 11.

PART I — General Principles (answer any 3 of 5)

Question 10: Design by Contract (Part II)

Question text not reproduced: the examination questions are © Engineers and Geoscientists BC. Open the official past paper (linked at the top of this page) to read the question, then follow the worked solution below.

Definition. Design by Contract (DbC, Bertrand Meyer, originating in the Eiffel language) formalizes a class operation's obligations as an explicit CONTRACT between a supplier (the class) and its clients (callers), stated as a precondition (an obligation on the CALLER, which must hold before the call for the operation's guarantee to apply), a postcondition (an obligation on the SUPPLIER, guaranteed to hold after the call returns, provided the precondition held), and a class invariant (a condition on the object's state that must hold before and after every public operation).

Example. A Stack.pop() operation: precondition — !isEmpty(); postcondition — the stack's size decreases by exactly 1 and the returned value is the element that was previously on top; invariant — size ≥ 0 at all times. If a caller violates the precondition (calls pop() on an empty stack), the fault is unambiguously the CALLER'S; if the postcondition or invariant fails despite a satisfied precondition, the fault is unambiguously the SUPPLIER'S implementation.

Benefits. Contracts document each operation's real behaviour precisely and unambiguously (far more precisely than prose comments), and in languages with runtime assertion support they can be MACHINE-CHECKED. They sharply localize fault assignment when something goes wrong (caller vs. supplier), which speeds debugging. They also justify omitting redundant defensive checks inside the supplier — if the precondition already guarantees a non-empty stack, pop() need not re-check emptiness defensively, since a violated precondition is the caller's bug by contract, not a case the supplier must recover from gracefully.

Challenges. Writing and maintaining contracts alongside the code is extra effort, and runtime assertion checking has a real performance cost, often leading teams to strip it from production builds — removing exactly the safety net most useful for catching real violations. Many mainstream languages (historically Java, C++) lack first-class contract syntax, requiring library or annotation workarounds (assert, JML) rather than a language-enforced mechanism. Stating precise, correct contracts for complex, stateful, or concurrent operations (e.g., invariants spanning multiple collaborating objects) can become nearly as hard as writing the implementation itself, and a wrong contract only formalizes a wrong assumption rather than catching it — DbC complements testing, it does not replace it.