25-Comp-B11 Advanced Software Design · December 2019
Question 11 of 28: Class Invariant — Definition, Example, and Role in Design-by-Contract
Nivaar worked solution (AI-drafted; not reviewed by a licensed engineer)
Notes on this paper
17-Comp-B11 Advanced Software Design — National Exams, December 2019. 3 hours, closed book exam with one aid sheet allowed (written on both sides), no calculator permitted. The paper is organized into five parts, and candidates were instructed to answer any five (5) questions in Part I, any three (3) in Part II, any four (4) in Part III, any two (2) in Part IV, and any five (5) in Part V — only the first questions answered, in each part, as they appear in the answer book are marked. All questions carry equal weight, so the 19 questions actually marked (5+3+4+2+5 of 28) each count for 100/19 ≈ 5.26% of the paper. All 28 questions are answered below for completeness.
Reference texts: Sommerville, Software Engineering (10th ed., Pearson) — software processes, requirements engineering, design principles, testing, dependability; Pressman, Software Engineering: A Practitioner's Approach (9th ed.) — supplementary process and quality coverage; Gamma, Helm, Johnson & Vlissides (GoF), Design Patterns: Elements of Reusable Object-Oriented Software — creational/structural/behavioural pattern catalogue and the "program to an interface, not an implementation" / "favor object composition over class inheritance" principles; Sebesta, Concepts of Programming Languages (12th ed.) — polymorphism, dynamic binding, visibility, and multiple inheritance semantics; Bertrand Meyer, Object-Oriented Software Construction — design by contract, preconditions/postconditions/class invariants; Barbara Liskov's 1987 substitutability paper for Question 12; Karl Wiegers, Software Requirements (3rd ed.); Myers, The Art of Software Testing, for Question 6.
PART I — General Principles (answer any 5 of 7)
Question 11: Class Invariant — Definition, Example, and Role in Design-by-Contract (Part II)
A class invariant is a condition on a class's internal state that must be true for EVERY instance at every point the object is externally observable — specifically, immediately after construction and immediately before and after every public method call (it MAY be temporarily broken during a method's execution, as long as it is restored before the method returns).
Example.BankAccount with a single invariant: balance ≥ 0 (no overdraft permitted). Every public method that can change balance must preserve it: withdraw(amount) is only allowed to proceed if amount ≤ balance, since any implementation that let it proceed otherwise would leave the object in a state violating its own invariant.
Role in design-by-contract. The class invariant is effectively an IMPLICIT clause automatically added to the precondition and postcondition of every public method of the class: it is assumed true on entry (as part of the precondition) and must be re-established on exit (as part of the postcondition), on top of whatever that specific method's own explicit pre/postcondition states. Where a method's individual precondition/postcondition (Question 10) governs one call, the invariant governs the object's consistency across its ENTIRE lifetime, protecting it against any sequence of otherwise-individually-valid calls that would together corrupt it.