void abort() { }; extern int __VERIFIER_nondet_int(); /*@ requires (1); ensures ((cond != 0)); @*/ void assume_abort_if_not(int cond) { if(!cond) {abort();} } /*@ requires ((1 <= cond)) && (cond != 0); ensures ((1 <= cond)) && (1); @*/ void __VERIFIER_assert(int cond) { if (!(cond)) { ERROR: {/*@ assert(0); */;} } return; } int main() { int a, b; long long x, y, z; a = __VERIFIER_nondet_int(); assume_abort_if_not(a>=0 && a<=5); b = __VERIFIER_nondet_int(); assume_abort_if_not(b>=0 && b<=5); assume_abort_if_not(b >= 1); x = a; y = b; z = 0; /*@ loop invariant (((((((((((((z + ((__int128) y * x)) == ((long long) b * a)) && (b <= 5)) && (((long long) a * 2) == x)) && (0 <= a)) && (1 <= b)) && (a <= 5)) && (((((long long) -1 + b) >= 0) ? (((long long) -1 + b) / 2) : ((((long long) -1 + b) / 2) - 1)) == y)) || ((((((z == ((long long) b * a)) && (b <= 5)) && (0 <= a)) && (1 <= b)) && (y == 0)) && (a <= 5))) || (((((((z == 0) && (b == y)) && (0 <= a)) && (1 <= y)) && (a <= 5)) && (a == x)) && (y <= 5))) || ((((((y == 1) && (b <= 5)) && (((__int128) z + x) == ((long long) b * a))) && (0 <= a)) && (1 <= b)) && (a <= 5))) || ((((((((z == 0) && (y == ((b >= 0) ? (b / 2) : ((b / 2) - 1)))) && (b <= 5)) && (((long long) a * 2) == x)) && (0 <= a)) && (((b >= 0) ? (b % 2) : ((b % 2) + 2)) != 1)) && (1 <= y)) && (a <= 5)))); @*/ while (1) { __VERIFIER_assert(z + x * y == (long long) a * b); if (!(y != 0)) break; if (y % 2 == 1) { z = z + x; y = y - 1; } x = 2 * x; y = y / 2; } __VERIFIER_assert(z == (long long) a * b); return 0; }