State of the art formal verification is based on methods and its goal proving given correctness properties. For example, a PSTM scheduler was modeled in CSP order to prove deadlock-freeness starvation-freeness. However, as this paper shows, using solely not sufficient. Therefore, we propose complete trustworthy software, which jointly uses model testing. As an first test previous transaction by...