Handle indeterminate-order multiple operation calls
Develop a method for generating proof obligations for expressions containing multiple operation calls whose evaluation order cannot be determined statically.
References
In addition, as noted in Section~\ref{sec:returns}, we cannot yet deal with multiple operation calls in an expression where the order of those calls cannot be statically determined.
— Further Progress Towards Operation Proof Obligation Generation for VDM
(2608.19848 - Battle et al., 20 Aug 2026) in Section 6, Future Work; see also Section 4.2, “Return Values”
Furthermore, Section \ref{sec:opcalls} noted that inter-module calls cannot yet determine how local state is updated, leading to under-qualified POs.
— Further Progress Towards Operation Proof Obligation Generation for VDM
(2608.19848 - Battle et al., 20 Aug 2026) in Section 6, Future Work; see also Section 4.1, “Simple Calls”