Question 10 of 27: Precondition, Postcondition, and Class Invariant
Nivaar worked solution (AI-drafted; not reviewed by a licensed engineer)
Notes on this paper
98-Comp-B11 Advanced Software Design — National Exams, May 2015. 3 hours, closed book exam with one aid sheet allowed (written on both sides), no calculator permitted. The paper is organized into five parts, and candidates were instructed to answer any four (4) questions in Part I, any three (3) in Part II, any three (3) in Part III, any two (2) in Part IV, and any four (4) in Part V — only the first questions answered, in each part, as they appear in the answer book are marked. All questions carry equal weight, so the 16 questions actually marked (4+3+3+2+4 of 27) each count for 100/16 ≈ 6.25% of the paper. All 27 questions are answered below for completeness.
Reference texts: Sommerville, Software Engineering (10th ed., Pearson) — software processes, requirements engineering, agile methods, design principles, dependability; Pressman, Software Engineering: A Practitioner's Approach (9th ed.) — supplementary process and quality coverage; Gamma, Helm, Johnson & Vlissides (GoF), Design Patterns: Elements of Reusable Object-Oriented Software — structural/behavioural pattern catalogue (Adapter, Bridge, Strategy, Observer, Template Method, Composite, etc.); Sebesta, Concepts of Programming Languages (12th ed.) — polymorphism, dynamic binding, inheritance and language-level object semantics; Bertrand Meyer, Object-Oriented Software Construction — design by contract, preconditions/postconditions/invariants, the open–closed principle; Barbara Liskov's 1987 substitutability paper for Question 11; Rogers, Sharp & Preece, Interaction Design, and Nielsen, Usability Engineering, for Question 21's HMI-specific non-functional requirements.
PART I — General Principles (answer any 4 of 7)
Question 10: Precondition, Postcondition, and Class Invariant (Part II)
Precondition. A condition that must be TRUE before an operation is invoked, for the operation's guarantee (its postcondition) to apply. It is an obligation on the CALLER — e.g., for withdraw(amount) on a bank account: amount > 0 AND amount ≤ balance.
Postcondition. A condition GUARANTEED to be true immediately after an operation completes, PROVIDED its precondition held on entry. It is an obligation/guarantee of the SUPPLIER — e.g., for the same withdraw(amount): balance_new = balance_old − amount.
Class invariant. A condition on an object's internal state that must hold TRUE whenever the object is in a stable, externally-observable state — that is, immediately before and immediately after every public operation (it may be temporarily violated part-way through a method body, as long as it is restored before control returns to the caller). For a bank account: balance ≥ 0, always.
Together the triad defines a class's full behavioural contract (Question 8): a client may call an operation only when its precondition holds; in return, the supplier guarantees the postcondition and preserves the class invariant. This is the exact vocabulary used to reason about Question 11's substitutability rule and Question 12's invariant-inheritance question below.