TLA+: Whence, Wherefore, and Whither
The evolution of my ideas on specification and verification, and how they led to the TLA+ specification language. What is good and bad about TLA+. A brief description of the next version of TLA+ and its tools. E.
Lamport, Leslie↗