formal-methods 2 A Type System Is a Search Oracle Sep 1, 2026 Provenance Is Not Correctness Aug 14, 2026