java -ea -Xmx8000000000 -jar /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/plugins/org.eclipse.equinox.launcher_1.3.100.v20150511-1540.jar -data @noDefault -ultimatedata /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/data -tc ../../../trunk/examples/toolchains/AutomizerC.xml -s ../../../trunk/examples/settings/default/automizer/svcomp-Reach-32bit-Automizer_Default-Const.epf -i ../../../trunk/examples/svcomp/ssh/s3_srvr.blast.04_false-unreach-call.i.cil.c -------------------------------------------------------------------------------- This is Ultimate 0.1.23-370d6ab [2018-11-14 19:05:42,967 INFO L170 SettingsManager]: Resetting all preferences to default values... [2018-11-14 19:05:42,969 INFO L174 SettingsManager]: Resetting UltimateCore preferences to default values [2018-11-14 19:05:42,981 INFO L177 SettingsManager]: Ultimate Commandline Interface provides no preferences, ignoring... [2018-11-14 19:05:42,981 INFO L174 SettingsManager]: Resetting Boogie Preprocessor preferences to default values [2018-11-14 19:05:42,982 INFO L174 SettingsManager]: Resetting Boogie Procedure Inliner preferences to default values [2018-11-14 19:05:42,984 INFO L174 SettingsManager]: Resetting Abstract Interpretation preferences to default values [2018-11-14 19:05:42,987 INFO L174 SettingsManager]: Resetting LassoRanker preferences to default values [2018-11-14 19:05:42,989 INFO L174 SettingsManager]: Resetting Reaching Definitions preferences to default values [2018-11-14 19:05:42,992 INFO L174 SettingsManager]: Resetting SyntaxChecker preferences to default values [2018-11-14 19:05:42,993 INFO L177 SettingsManager]: Büchi Program Product provides no preferences, ignoring... [2018-11-14 19:05:42,993 INFO L174 SettingsManager]: Resetting LTL2Aut preferences to default values [2018-11-14 19:05:42,996 INFO L174 SettingsManager]: Resetting PEA to Boogie preferences to default values [2018-11-14 19:05:42,999 INFO L174 SettingsManager]: Resetting BlockEncodingV2 preferences to default values [2018-11-14 19:05:43,001 INFO L174 SettingsManager]: Resetting ChcToBoogie preferences to default values [2018-11-14 19:05:43,001 INFO L174 SettingsManager]: Resetting AutomataScriptInterpreter preferences to default values [2018-11-14 19:05:43,002 INFO L174 SettingsManager]: Resetting BuchiAutomizer preferences to default values [2018-11-14 19:05:43,012 INFO L174 SettingsManager]: Resetting CACSL2BoogieTranslator preferences to default values [2018-11-14 19:05:43,016 INFO L174 SettingsManager]: Resetting CodeCheck preferences to default values [2018-11-14 19:05:43,017 INFO L174 SettingsManager]: Resetting InvariantSynthesis preferences to default values [2018-11-14 19:05:43,021 INFO L174 SettingsManager]: Resetting RCFGBuilder preferences to default values [2018-11-14 19:05:43,022 INFO L174 SettingsManager]: Resetting TraceAbstraction preferences to default values [2018-11-14 19:05:43,026 INFO L177 SettingsManager]: TraceAbstractionConcurrent provides no preferences, ignoring... [2018-11-14 19:05:43,026 INFO L177 SettingsManager]: TraceAbstractionWithAFAs provides no preferences, ignoring... [2018-11-14 19:05:43,026 INFO L174 SettingsManager]: Resetting TreeAutomizer preferences to default values [2018-11-14 19:05:43,028 INFO L174 SettingsManager]: Resetting IcfgTransformer preferences to default values [2018-11-14 19:05:43,029 INFO L174 SettingsManager]: Resetting Boogie Printer preferences to default values [2018-11-14 19:05:43,032 INFO L174 SettingsManager]: Resetting ReqPrinter preferences to default values [2018-11-14 19:05:43,033 INFO L174 SettingsManager]: Resetting Witness Printer preferences to default values [2018-11-14 19:05:43,035 INFO L177 SettingsManager]: Boogie PL CUP Parser provides no preferences, ignoring... [2018-11-14 19:05:43,035 INFO L174 SettingsManager]: Resetting CDTParser preferences to default values [2018-11-14 19:05:43,036 INFO L177 SettingsManager]: AutomataScriptParser provides no preferences, ignoring... [2018-11-14 19:05:43,036 INFO L177 SettingsManager]: ReqParser provides no preferences, ignoring... [2018-11-14 19:05:43,038 INFO L174 SettingsManager]: Resetting SmtParser preferences to default values [2018-11-14 19:05:43,039 INFO L174 SettingsManager]: Resetting Witness Parser preferences to default values [2018-11-14 19:05:43,040 INFO L181 SettingsManager]: Finished resetting all preferences to default values... [2018-11-14 19:05:43,040 INFO L98 SettingsManager]: Beginning loading settings from /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/../../../trunk/examples/settings/default/automizer/svcomp-Reach-32bit-Automizer_Default-Const.epf [2018-11-14 19:05:43,061 INFO L110 SettingsManager]: Loading preferences was successful [2018-11-14 19:05:43,061 INFO L112 SettingsManager]: Preferences different from defaults after loading the file: [2018-11-14 19:05:43,062 INFO L131 SettingsManager]: Preferences of Boogie Procedure Inliner differ from their defaults: [2018-11-14 19:05:43,062 INFO L133 SettingsManager]: * to procedures, called more than once=true [2018-11-14 19:05:43,063 INFO L131 SettingsManager]: Preferences of BlockEncodingV2 differ from their defaults: [2018-11-14 19:05:43,063 INFO L133 SettingsManager]: * Create parallel compositions if possible=false [2018-11-14 19:05:43,063 INFO L133 SettingsManager]: * Use SBE=true [2018-11-14 19:05:43,063 INFO L131 SettingsManager]: Preferences of CACSL2BoogieTranslator differ from their defaults: [2018-11-14 19:05:43,064 INFO L133 SettingsManager]: * sizeof long=4 [2018-11-14 19:05:43,064 INFO L133 SettingsManager]: * Overapproximate operations on floating types=true [2018-11-14 19:05:43,064 INFO L133 SettingsManager]: * sizeof POINTER=4 [2018-11-14 19:05:43,064 INFO L133 SettingsManager]: * Check division by zero=IGNORE [2018-11-14 19:05:43,064 INFO L133 SettingsManager]: * Pointer to allocated memory at dereference=IGNORE [2018-11-14 19:05:43,064 INFO L133 SettingsManager]: * If two pointers are subtracted or compared they have the same base address=IGNORE [2018-11-14 19:05:43,065 INFO L133 SettingsManager]: * Check array bounds for arrays that are off heap=IGNORE [2018-11-14 19:05:43,065 INFO L133 SettingsManager]: * sizeof long double=12 [2018-11-14 19:05:43,065 INFO L133 SettingsManager]: * Check if freed pointer was valid=false [2018-11-14 19:05:43,065 INFO L133 SettingsManager]: * Use constant arrays=true [2018-11-14 19:05:43,065 INFO L133 SettingsManager]: * Pointer base address is valid at dereference=IGNORE [2018-11-14 19:05:43,066 INFO L131 SettingsManager]: Preferences of RCFGBuilder differ from their defaults: [2018-11-14 19:05:43,066 INFO L133 SettingsManager]: * Size of a code block=SequenceOfStatements [2018-11-14 19:05:43,066 INFO L133 SettingsManager]: * To the following directory=./dump/ [2018-11-14 19:05:43,066 INFO L133 SettingsManager]: * SMT solver=External_DefaultMode [2018-11-14 19:05:43,066 INFO L133 SettingsManager]: * Command for external solver=z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in -t:2000 [2018-11-14 19:05:43,067 INFO L131 SettingsManager]: Preferences of TraceAbstraction differ from their defaults: [2018-11-14 19:05:43,067 INFO L133 SettingsManager]: * Compute Interpolants along a Counterexample=FPandBP [2018-11-14 19:05:43,067 INFO L133 SettingsManager]: * Positions where we compute the Hoare Annotation=LoopsAndPotentialCycles [2018-11-14 19:05:43,067 INFO L133 SettingsManager]: * Trace refinement strategy=CAMEL [2018-11-14 19:05:43,068 INFO L133 SettingsManager]: * SMT solver=External_ModelsAndUnsatCoreMode [2018-11-14 19:05:43,068 INFO L133 SettingsManager]: * Command for external solver=z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in [2018-11-14 19:05:43,068 INFO L133 SettingsManager]: * Compute Hoare Annotation of negated interpolant automaton, abstraction and CFG=true [2018-11-14 19:05:43,112 INFO L81 nceAwareModelManager]: Repository-Root is: /tmp [2018-11-14 19:05:43,127 INFO L258 ainManager$Toolchain]: [Toolchain 1]: Applicable parser(s) successfully (re)initialized [2018-11-14 19:05:43,132 INFO L214 ainManager$Toolchain]: [Toolchain 1]: Toolchain selected. [2018-11-14 19:05:43,133 INFO L271 PluginConnector]: Initializing CDTParser... [2018-11-14 19:05:43,134 INFO L276 PluginConnector]: CDTParser initialized [2018-11-14 19:05:43,134 INFO L418 ainManager$Toolchain]: [Toolchain 1]: Parsing single file: /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/../../../trunk/examples/svcomp/ssh/s3_srvr.blast.04_false-unreach-call.i.cil.c [2018-11-14 19:05:43,201 INFO L218 CDTParser]: Created temporary CDT project at /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/data/2a5106afa/5fb3a1d46eed4f348258a086d1761717/FLAG54e2d20b5 [2018-11-14 19:05:43,776 INFO L298 CDTParser]: Found 1 translation units. [2018-11-14 19:05:43,777 INFO L158 CDTParser]: Scanning /storage/repos/ultimate/trunk/examples/svcomp/ssh/s3_srvr.blast.04_false-unreach-call.i.cil.c [2018-11-14 19:05:43,814 INFO L346 CDTParser]: About to delete temporary CDT project at /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/data/2a5106afa/5fb3a1d46eed4f348258a086d1761717/FLAG54e2d20b5 [2018-11-14 19:05:43,836 INFO L354 CDTParser]: Successfully deleted /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/data/2a5106afa/5fb3a1d46eed4f348258a086d1761717 [2018-11-14 19:05:43,848 INFO L296 ainManager$Toolchain]: ####################### [Toolchain 1] ####################### [2018-11-14 19:05:43,850 INFO L131 ToolchainWalker]: Walking toolchain with 4 elements. [2018-11-14 19:05:43,851 INFO L113 PluginConnector]: ------------------------CACSL2BoogieTranslator---------------------------- [2018-11-14 19:05:43,851 INFO L271 PluginConnector]: Initializing CACSL2BoogieTranslator... [2018-11-14 19:05:43,855 INFO L276 PluginConnector]: CACSL2BoogieTranslator initialized [2018-11-14 19:05:43,857 INFO L185 PluginConnector]: Executing the observer ACSLObjectContainerObserver from plugin CACSL2BoogieTranslator for "CDTParser AST 14.11 07:05:43" (1/1) ... [2018-11-14 19:05:43,860 INFO L205 PluginConnector]: Invalid model from CACSL2BoogieTranslator for observer de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator.ACSLObjectContainerObserver@3c274d15 and model type de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 14.11 07:05:43, skipping insertion in model container [2018-11-14 19:05:43,860 INFO L185 PluginConnector]: Executing the observer CACSL2BoogieTranslatorObserver from plugin CACSL2BoogieTranslator for "CDTParser AST 14.11 07:05:43" (1/1) ... [2018-11-14 19:05:43,871 INFO L145 MainTranslator]: Starting translation in SV-COMP mode [2018-11-14 19:05:43,963 INFO L176 MainTranslator]: Built tables and reachable declarations [2018-11-14 19:05:44,930 INFO L201 PostProcessor]: Analyzing one entry point: main [2018-11-14 19:05:44,946 INFO L191 MainTranslator]: Completed pre-run [2018-11-14 19:05:45,314 INFO L201 PostProcessor]: Analyzing one entry point: main [2018-11-14 19:05:45,338 INFO L195 MainTranslator]: Completed translation [2018-11-14 19:05:45,339 INFO L202 PluginConnector]: Adding new model de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 14.11 07:05:45 WrapperNode [2018-11-14 19:05:45,339 INFO L132 PluginConnector]: ------------------------ END CACSL2BoogieTranslator---------------------------- [2018-11-14 19:05:45,340 INFO L113 PluginConnector]: ------------------------Boogie Preprocessor---------------------------- [2018-11-14 19:05:45,340 INFO L271 PluginConnector]: Initializing Boogie Preprocessor... [2018-11-14 19:05:45,340 INFO L276 PluginConnector]: Boogie Preprocessor initialized [2018-11-14 19:05:45,355 INFO L185 PluginConnector]: Executing the observer EnsureBoogieModelObserver from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 14.11 07:05:45" (1/1) ... [2018-11-14 19:05:45,355 INFO L185 PluginConnector]: Executing the observer TypeChecker from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 14.11 07:05:45" (1/1) ... [2018-11-14 19:05:45,404 INFO L185 PluginConnector]: Executing the observer ConstExpander from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 14.11 07:05:45" (1/1) ... [2018-11-14 19:05:45,404 INFO L185 PluginConnector]: Executing the observer StructExpander from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 14.11 07:05:45" (1/1) ... [2018-11-14 19:05:45,496 INFO L185 PluginConnector]: Executing the observer UnstructureCode from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 14.11 07:05:45" (1/1) ... [2018-11-14 19:05:45,516 INFO L185 PluginConnector]: Executing the observer FunctionInliner from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 14.11 07:05:45" (1/1) ... [2018-11-14 19:05:45,523 INFO L185 PluginConnector]: Executing the observer BoogieSymbolTableConstructor from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 14.11 07:05:45" (1/1) ... [2018-11-14 19:05:45,537 INFO L132 PluginConnector]: ------------------------ END Boogie Preprocessor---------------------------- [2018-11-14 19:05:45,538 INFO L113 PluginConnector]: ------------------------RCFGBuilder---------------------------- [2018-11-14 19:05:45,538 INFO L271 PluginConnector]: Initializing RCFGBuilder... [2018-11-14 19:05:45,538 INFO L276 PluginConnector]: RCFGBuilder initialized [2018-11-14 19:05:45,544 INFO L185 PluginConnector]: Executing the observer RCFGBuilderObserver from plugin RCFGBuilder for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 14.11 07:05:45" (1/1) ... No working directory specified, using /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 Starting monitored process 1 with z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in -t:2000 (exit command is (exit), workingDir is null) Waiting until toolchain timeout for monitored process 1 with z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in -t:2000 [2018-11-14 19:05:45,616 INFO L138 BoogieDeclarations]: Found implementation of procedure ULTIMATE.init [2018-11-14 19:05:45,616 INFO L138 BoogieDeclarations]: Found implementation of procedure ULTIMATE.start [2018-11-14 19:05:45,617 INFO L138 BoogieDeclarations]: Found implementation of procedure ssl3_get_server_method [2018-11-14 19:05:45,617 INFO L138 BoogieDeclarations]: Found implementation of procedure SSLv3_server_method [2018-11-14 19:05:45,617 INFO L138 BoogieDeclarations]: Found implementation of procedure main [2018-11-14 19:05:45,617 INFO L138 BoogieDeclarations]: Found implementation of procedure ssl3_accept [2018-11-14 19:05:45,617 INFO L138 BoogieDeclarations]: Found implementation of procedure sslv3_base_method [2018-11-14 19:05:45,618 INFO L138 BoogieDeclarations]: Found implementation of procedure #Ultimate.meminit [2018-11-14 19:05:45,618 INFO L138 BoogieDeclarations]: Found implementation of procedure #Ultimate.C_memcpy [2018-11-14 19:05:45,618 INFO L130 BoogieDeclarations]: Found specification of procedure __VERIFIER_error [2018-11-14 19:05:45,618 INFO L130 BoogieDeclarations]: Found specification of procedure malloc [2018-11-14 19:05:45,618 INFO L130 BoogieDeclarations]: Found specification of procedure __VERIFIER_nondet_char [2018-11-14 19:05:45,619 INFO L130 BoogieDeclarations]: Found specification of procedure __VERIFIER_nondet_int [2018-11-14 19:05:45,619 INFO L130 BoogieDeclarations]: Found specification of procedure __VERIFIER_nondet_long [2018-11-14 19:05:45,619 INFO L130 BoogieDeclarations]: Found specification of procedure __VERIFIER_nondet_pointer [2018-11-14 19:05:45,619 INFO L130 BoogieDeclarations]: Found specification of procedure memcpy [2018-11-14 19:05:45,619 INFO L130 BoogieDeclarations]: Found specification of procedure SSLv3_server_method [2018-11-14 19:05:45,623 INFO L130 BoogieDeclarations]: Found specification of procedure sslv3_base_method [2018-11-14 19:05:45,623 INFO L130 BoogieDeclarations]: Found specification of procedure ssl3_accept [2018-11-14 19:05:45,623 INFO L130 BoogieDeclarations]: Found specification of procedure ssl3_get_server_method [2018-11-14 19:05:45,625 INFO L130 BoogieDeclarations]: Found specification of procedure #Ultimate.C_memcpy [2018-11-14 19:05:45,625 INFO L130 BoogieDeclarations]: Found specification of procedure write~$Pointer$ [2018-11-14 19:05:45,625 INFO L130 BoogieDeclarations]: Found specification of procedure main [2018-11-14 19:05:45,625 INFO L130 BoogieDeclarations]: Found specification of procedure #Ultimate.alloc [2018-11-14 19:05:45,625 INFO L130 BoogieDeclarations]: Found specification of procedure write~int [2018-11-14 19:05:45,626 INFO L130 BoogieDeclarations]: Found specification of procedure read~$Pointer$ [2018-11-14 19:05:45,626 INFO L130 BoogieDeclarations]: Found specification of procedure read~int [2018-11-14 19:05:45,626 INFO L130 BoogieDeclarations]: Found specification of procedure calloc [2018-11-14 19:05:45,626 INFO L130 BoogieDeclarations]: Found specification of procedure #Ultimate.meminit [2018-11-14 19:05:45,626 INFO L130 BoogieDeclarations]: Found specification of procedure ULTIMATE.init [2018-11-14 19:05:45,626 INFO L130 BoogieDeclarations]: Found specification of procedure write~unchecked~int [2018-11-14 19:05:45,626 INFO L130 BoogieDeclarations]: Found specification of procedure ULTIMATE.start [2018-11-14 19:05:45,627 INFO L130 BoogieDeclarations]: Found specification of procedure ULTIMATE.dealloc [2018-11-14 19:05:46,607 WARN L684 $ProcedureCfgBuilder]: Two Gotos in a row! There was dead code [2018-11-14 19:05:46,607 WARN L649 $ProcedureCfgBuilder]: Label in the middle of a codeblock. [2018-11-14 19:05:49,762 INFO L278 CfgBuilder]: Using the 1 location(s) as analysis (start of procedure ULTIMATE.start) [2018-11-14 19:05:49,763 INFO L202 PluginConnector]: Adding new model de.uni_freiburg.informatik.ultimate.plugins.generator.rcfgbuilder CFG 14.11 07:05:49 BoogieIcfgContainer [2018-11-14 19:05:49,763 INFO L132 PluginConnector]: ------------------------ END RCFGBuilder---------------------------- [2018-11-14 19:05:49,764 INFO L113 PluginConnector]: ------------------------TraceAbstraction---------------------------- [2018-11-14 19:05:49,764 INFO L271 PluginConnector]: Initializing TraceAbstraction... [2018-11-14 19:05:49,767 INFO L276 PluginConnector]: TraceAbstraction initialized [2018-11-14 19:05:49,768 INFO L185 PluginConnector]: Executing the observer TraceAbstractionObserver from plugin TraceAbstraction for "CDTParser AST 14.11 07:05:43" (1/3) ... [2018-11-14 19:05:49,769 INFO L205 PluginConnector]: Invalid model from TraceAbstraction for observer de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction.TraceAbstractionObserver@1b36a922 and model type de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction AST 14.11 07:05:49, skipping insertion in model container [2018-11-14 19:05:49,769 INFO L185 PluginConnector]: Executing the observer TraceAbstractionObserver from plugin TraceAbstraction for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 14.11 07:05:45" (2/3) ... [2018-11-14 19:05:49,769 INFO L205 PluginConnector]: Invalid model from TraceAbstraction for observer de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction.TraceAbstractionObserver@1b36a922 and model type de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction AST 14.11 07:05:49, skipping insertion in model container [2018-11-14 19:05:49,769 INFO L185 PluginConnector]: Executing the observer TraceAbstractionObserver from plugin TraceAbstraction for "de.uni_freiburg.informatik.ultimate.plugins.generator.rcfgbuilder CFG 14.11 07:05:49" (3/3) ... [2018-11-14 19:05:49,771 INFO L112 eAbstractionObserver]: Analyzing ICFG s3_srvr.blast.04_false-unreach-call.i.cil.c [2018-11-14 19:05:49,781 INFO L136 ceAbstractionStarter]: Automizer settings: Hoare:true NWA Interpolation:FPandBP Determinization: PREDICATE_ABSTRACTION [2018-11-14 19:05:49,790 INFO L148 ceAbstractionStarter]: Appying trace abstraction to program that has 1 error locations. [2018-11-14 19:05:49,808 INFO L257 AbstractCegarLoop]: Starting to check reachability of 1 error locations. [2018-11-14 19:05:49,843 INFO L133 ementStrategyFactory]: Using default assertion order modulation [2018-11-14 19:05:49,844 INFO L382 AbstractCegarLoop]: Interprodecural is true [2018-11-14 19:05:49,844 INFO L383 AbstractCegarLoop]: Hoare is true [2018-11-14 19:05:49,845 INFO L384 AbstractCegarLoop]: Compute interpolants for FPandBP [2018-11-14 19:05:49,845 INFO L385 AbstractCegarLoop]: Backedges is STRAIGHT_LINE [2018-11-14 19:05:49,845 INFO L386 AbstractCegarLoop]: Determinization is PREDICATE_ABSTRACTION [2018-11-14 19:05:49,845 INFO L387 AbstractCegarLoop]: Difference is false [2018-11-14 19:05:49,845 INFO L388 AbstractCegarLoop]: Minimize is MINIMIZE_SEVPA [2018-11-14 19:05:49,845 INFO L393 AbstractCegarLoop]: ======== Iteration 0==of CEGAR loop == AllErrorsAtOnce======== [2018-11-14 19:05:49,869 INFO L276 IsEmpty]: Start isEmpty. Operand 153 states. [2018-11-14 19:05:49,881 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 53 [2018-11-14 19:05:49,881 INFO L367 BasicCegarLoop]: Found error trace [2018-11-14 19:05:49,882 INFO L375 BasicCegarLoop]: trace histogram [1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2018-11-14 19:05:49,885 INFO L423 AbstractCegarLoop]: === Iteration 1 === [ssl3_acceptErr0ASSERT_VIOLATIONERROR_FUNCTION]=== [2018-11-14 19:05:49,891 INFO L141 PredicateUnifier]: Initialized classic predicate unifier [2018-11-14 19:05:49,892 INFO L82 PathProgramCache]: Analyzing trace with hash 1359081543, now seen corresponding path program 1 times [2018-11-14 19:05:49,894 INFO L223 ckRefinementStrategy]: Switched to mode SMTINTERPOL_TREE_INTERPOLANTS [2018-11-14 19:05:49,895 INFO L69 tionRefinementEngine]: Using refinement strategy CamelRefinementStrategy [2018-11-14 19:05:49,950 INFO L119 rtionOrderModulation]: Craig_TreeInterpolation forces the order to NOT_INCREMENTALLY [2018-11-14 19:05:49,951 INFO L103 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2018-11-14 19:05:49,951 INFO L119 rtionOrderModulation]: Craig_TreeInterpolation forces the order to NOT_INCREMENTALLY [2018-11-14 19:05:50,142 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2018-11-14 19:05:50,543 INFO L256 TraceCheckUtils]: 0: Hoare triple {156#true} call ULTIMATE.init(); {156#true} is VALID [2018-11-14 19:05:50,547 INFO L273 TraceCheckUtils]: 1: Hoare triple {156#true} #NULL.base, #NULL.offset := 0, 0;#valid := #valid[0 := 0];~init~0 := 1;call ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset := #Ultimate.alloc(100);call write~unchecked~int(0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 0, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 4, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 8, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 12, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 16, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 20, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 24, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 28, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 32, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 36, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 40, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 44, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 48, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 52, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 56, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 60, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 64, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 68, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 72, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 76, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 80, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 84, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 88, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 92, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 96, 4);call write~unchecked~int(0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 0, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 4, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 8, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 12, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 16, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 20, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 24, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 28, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 32, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 36, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 40, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 44, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 48, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 52, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 56, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 60, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 64, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 68, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 72, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 76, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 80, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 84, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 88, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 92, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 96, 4); {156#true} is VALID [2018-11-14 19:05:50,548 INFO L273 TraceCheckUtils]: 2: Hoare triple {156#true} assume true; {156#true} is VALID [2018-11-14 19:05:50,548 INFO L268 TraceCheckUtils]: 3: Hoare quadruple {156#true} {156#true} #654#return; {156#true} is VALID [2018-11-14 19:05:50,549 INFO L256 TraceCheckUtils]: 4: Hoare triple {156#true} call #t~ret138 := main(); {156#true} is VALID [2018-11-14 19:05:50,549 INFO L273 TraceCheckUtils]: 5: Hoare triple {156#true} havoc ~s~0.base, ~s~0.offset;havoc ~tmp~2;call #t~malloc3.base, #t~malloc3.offset := #Ultimate.alloc(248);~s~0.base, ~s~0.offset := #t~malloc3.base, #t~malloc3.offset;call #t~malloc4.base, #t~malloc4.offset := #Ultimate.alloc(899);call write~$Pointer$(#t~malloc4.base, #t~malloc4.offset, ~s~0.base, ~s~0.offset + 84, 4);call #t~malloc5.base, #t~malloc5.offset := #Ultimate.alloc(232);call write~$Pointer$(#t~malloc5.base, #t~malloc5.offset, ~s~0.base, ~s~0.offset + 204, 4);call #t~malloc6.base, #t~malloc6.offset := #Ultimate.alloc(200);call write~$Pointer$(#t~malloc6.base, #t~malloc6.offset, ~s~0.base, ~s~0.offset + 176, 4);call write~int(8464, ~s~0.base, ~s~0.offset + 52, 4); {156#true} is VALID [2018-11-14 19:05:50,550 INFO L256 TraceCheckUtils]: 6: Hoare triple {156#true} call #t~ret7 := ssl3_accept(~s~0.base, ~s~0.offset); {156#true} is VALID [2018-11-14 19:05:50,573 INFO L273 TraceCheckUtils]: 7: Hoare triple {156#true} ~s.base, ~s.offset := #in~s.base, #in~s.offset;havoc ~buf~0.base, ~buf~0.offset;havoc ~l~0;havoc ~Time~0;havoc ~tmp~3;havoc ~cb~0.base, ~cb~0.offset;havoc ~num1~0;havoc ~ret~0;havoc ~new_state~0;havoc ~state~0;havoc ~skip~0;havoc ~got_new_session~0;assume -2147483648 <= #t~nondet8 && #t~nondet8 <= 2147483647;~tmp___1~0 := #t~nondet8;havoc #t~nondet8;assume -2147483648 <= #t~nondet9 && #t~nondet9 <= 2147483647;~tmp___2~0 := #t~nondet9;havoc #t~nondet9;assume -2147483648 <= #t~nondet10 && #t~nondet10 <= 2147483647;~tmp___3~0 := #t~nondet10;havoc #t~nondet10;assume -2147483648 <= #t~nondet11 && #t~nondet11 <= 2147483647;~tmp___4~0 := #t~nondet11;havoc #t~nondet11;assume -2147483648 <= #t~nondet12 && #t~nondet12 <= 2147483647;~tmp___5~0 := #t~nondet12;havoc #t~nondet12;assume -2147483648 <= #t~nondet13 && #t~nondet13 <= 2147483647;~tmp___6~0 := #t~nondet13;havoc #t~nondet13;havoc ~tmp___7~0;assume -2147483648 <= #t~nondet14 && #t~nondet14 <= 2147483647;~tmp___8~0 := #t~nondet14;havoc #t~nondet14;assume -2147483648 <= #t~nondet15 && #t~nondet15 <= 2147483647;~tmp___9~0 := #t~nondet15;havoc #t~nondet15;assume -2147483648 <= #t~nondet16 && #t~nondet16 <= 2147483647;~tmp___10~0 := #t~nondet16;havoc #t~nondet16;havoc ~blastFlag~0;~blastFlag~0 := 0;assume -2147483648 <= #t~nondet17 && #t~nondet17 <= 2147483647;call write~int(#t~nondet17, ~s.base, ~s.offset + 92, 4);havoc #t~nondet17;call write~int(8464, ~s.base, ~s.offset + 52, 4);assume -2147483648 <= #t~nondet18 && #t~nondet18 <= 2147483647;~tmp~3 := #t~nondet18;havoc #t~nondet18;~Time~0 := ~tmp~3;~cb~0.base, ~cb~0.offset := 0, 0;~ret~0 := -1;~skip~0 := 0;~got_new_session~0 := 0;call #t~mem19.base, #t~mem19.offset := read~$Pointer$(~s.base, ~s.offset + 192, 4); {158#(= 8464 (select (store (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 28) (+ (select (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 28)) 1)) (+ ssl3_accept_~s.offset 52)))} is VALID [2018-11-14 19:05:50,583 INFO L273 TraceCheckUtils]: 8: Hoare triple {158#(= 8464 (select (store (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 28) (+ (select (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 28)) 1)) (+ ssl3_accept_~s.offset 52)))} assume (#t~mem19.base + #t~mem19.offset) % 4294967296 != 0;havoc #t~mem19.base, #t~mem19.offset;call #t~mem20.base, #t~mem20.offset := read~$Pointer$(~s.base, ~s.offset + 192, 4);~cb~0.base, ~cb~0.offset := #t~mem20.base, #t~mem20.offset;havoc #t~mem20.base, #t~mem20.offset; {158#(= 8464 (select (store (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 28) (+ (select (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 28)) 1)) (+ ssl3_accept_~s.offset 52)))} is VALID [2018-11-14 19:05:50,585 INFO L273 TraceCheckUtils]: 9: Hoare triple {158#(= 8464 (select (store (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 28) (+ (select (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 28)) 1)) (+ ssl3_accept_~s.offset 52)))} call #t~mem21 := read~int(~s.base, ~s.offset + 28, 4);call write~int(#t~mem21 + 1, ~s.base, ~s.offset + 28, 4);havoc #t~mem21; {158#(= 8464 (select (store (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 28) (+ (select (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 28)) 1)) (+ ssl3_accept_~s.offset 52)))} is VALID [2018-11-14 19:05:50,603 INFO L273 TraceCheckUtils]: 10: Hoare triple {158#(= 8464 (select (store (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 28) (+ (select (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 28)) 1)) (+ ssl3_accept_~s.offset 52)))} assume !(~bitwiseAnd(~tmp___1~0, 12288) != 0); {158#(= 8464 (select (store (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 28) (+ (select (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 28)) 1)) (+ ssl3_accept_~s.offset 52)))} is VALID [2018-11-14 19:05:50,618 INFO L273 TraceCheckUtils]: 11: Hoare triple {158#(= 8464 (select (store (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 28) (+ (select (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 28)) 1)) (+ ssl3_accept_~s.offset 52)))} call #t~mem22.base, #t~mem22.offset := read~$Pointer$(~s.base, ~s.offset + 136, 4); {158#(= 8464 (select (store (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 28) (+ (select (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 28)) 1)) (+ ssl3_accept_~s.offset 52)))} is VALID [2018-11-14 19:05:50,619 INFO L273 TraceCheckUtils]: 12: Hoare triple {158#(= 8464 (select (store (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 28) (+ (select (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 28)) 1)) (+ ssl3_accept_~s.offset 52)))} assume !((#t~mem22.base + #t~mem22.offset) % 4294967296 == 0);havoc #t~mem22.base, #t~mem22.offset; {158#(= 8464 (select (store (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 28) (+ (select (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 28)) 1)) (+ ssl3_accept_~s.offset 52)))} is VALID [2018-11-14 19:05:50,620 INFO L273 TraceCheckUtils]: 13: Hoare triple {158#(= 8464 (select (store (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 28) (+ (select (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 28)) 1)) (+ ssl3_accept_~s.offset 52)))} assume true; {158#(= 8464 (select (store (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 28) (+ (select (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 28)) 1)) (+ ssl3_accept_~s.offset 52)))} is VALID [2018-11-14 19:05:50,621 INFO L273 TraceCheckUtils]: 14: Hoare triple {158#(= 8464 (select (store (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 28) (+ (select (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 28)) 1)) (+ ssl3_accept_~s.offset 52)))} assume !false; {158#(= 8464 (select (store (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 28) (+ (select (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 28)) 1)) (+ ssl3_accept_~s.offset 52)))} is VALID [2018-11-14 19:05:50,622 INFO L273 TraceCheckUtils]: 15: Hoare triple {158#(= 8464 (select (store (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 28) (+ (select (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 28)) 1)) (+ ssl3_accept_~s.offset 52)))} call #t~mem23 := read~int(~s.base, ~s.offset + 52, 4);~state~0 := #t~mem23;havoc #t~mem23;call #t~mem24 := read~int(~s.base, ~s.offset + 52, 4); {158#(= 8464 (select (store (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 28) (+ (select (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 28)) 1)) (+ ssl3_accept_~s.offset 52)))} is VALID [2018-11-14 19:05:50,623 INFO L273 TraceCheckUtils]: 16: Hoare triple {158#(= 8464 (select (store (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 28) (+ (select (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 28)) 1)) (+ ssl3_accept_~s.offset 52)))} assume !(#t~mem24 == 12292);havoc #t~mem24;call #t~mem25 := read~int(~s.base, ~s.offset + 52, 4); {158#(= 8464 (select (store (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 28) (+ (select (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 28)) 1)) (+ ssl3_accept_~s.offset 52)))} is VALID [2018-11-14 19:05:50,624 INFO L273 TraceCheckUtils]: 17: Hoare triple {158#(= 8464 (select (store (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 28) (+ (select (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 28)) 1)) (+ ssl3_accept_~s.offset 52)))} assume !(#t~mem25 == 16384);havoc #t~mem25;call #t~mem26 := read~int(~s.base, ~s.offset + 52, 4); {158#(= 8464 (select (store (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 28) (+ (select (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 28)) 1)) (+ ssl3_accept_~s.offset 52)))} is VALID [2018-11-14 19:05:50,637 INFO L273 TraceCheckUtils]: 18: Hoare triple {158#(= 8464 (select (store (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 28) (+ (select (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 28)) 1)) (+ ssl3_accept_~s.offset 52)))} assume !(#t~mem26 == 8192);havoc #t~mem26;call #t~mem27 := read~int(~s.base, ~s.offset + 52, 4); {158#(= 8464 (select (store (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 28) (+ (select (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 28)) 1)) (+ ssl3_accept_~s.offset 52)))} is VALID [2018-11-14 19:05:50,650 INFO L273 TraceCheckUtils]: 19: Hoare triple {158#(= 8464 (select (store (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 28) (+ (select (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 28)) 1)) (+ ssl3_accept_~s.offset 52)))} assume !(#t~mem27 == 24576);havoc #t~mem27;call #t~mem28 := read~int(~s.base, ~s.offset + 52, 4); {158#(= 8464 (select (store (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 28) (+ (select (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 28)) 1)) (+ ssl3_accept_~s.offset 52)))} is VALID [2018-11-14 19:05:50,651 INFO L273 TraceCheckUtils]: 20: Hoare triple {158#(= 8464 (select (store (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 28) (+ (select (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 28)) 1)) (+ ssl3_accept_~s.offset 52)))} assume !(#t~mem28 == 8195);havoc #t~mem28;call #t~mem29 := read~int(~s.base, ~s.offset + 52, 4); {158#(= 8464 (select (store (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 28) (+ (select (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 28)) 1)) (+ ssl3_accept_~s.offset 52)))} is VALID [2018-11-14 19:05:50,652 INFO L273 TraceCheckUtils]: 21: Hoare triple {158#(= 8464 (select (store (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 28) (+ (select (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 28)) 1)) (+ ssl3_accept_~s.offset 52)))} assume !(#t~mem29 == 8480);havoc #t~mem29;call #t~mem30 := read~int(~s.base, ~s.offset + 52, 4); {158#(= 8464 (select (store (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 28) (+ (select (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 28)) 1)) (+ ssl3_accept_~s.offset 52)))} is VALID [2018-11-14 19:05:50,652 INFO L273 TraceCheckUtils]: 22: Hoare triple {158#(= 8464 (select (store (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 28) (+ (select (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 28)) 1)) (+ ssl3_accept_~s.offset 52)))} assume !(#t~mem30 == 8481);havoc #t~mem30;call #t~mem31 := read~int(~s.base, ~s.offset + 52, 4); {158#(= 8464 (select (store (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 28) (+ (select (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 28)) 1)) (+ ssl3_accept_~s.offset 52)))} is VALID [2018-11-14 19:05:50,655 INFO L273 TraceCheckUtils]: 23: Hoare triple {158#(= 8464 (select (store (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 28) (+ (select (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 28)) 1)) (+ ssl3_accept_~s.offset 52)))} assume !(#t~mem31 == 8482);havoc #t~mem31;call #t~mem32 := read~int(~s.base, ~s.offset + 52, 4); {159#(= 8464 |ssl3_accept_#t~mem32|)} is VALID [2018-11-14 19:05:50,656 INFO L273 TraceCheckUtils]: 24: Hoare triple {159#(= 8464 |ssl3_accept_#t~mem32|)} assume !(#t~mem32 == 8464);havoc #t~mem32;call #t~mem33 := read~int(~s.base, ~s.offset + 52, 4); {157#false} is VALID [2018-11-14 19:05:50,656 INFO L273 TraceCheckUtils]: 25: Hoare triple {157#false} assume !(#t~mem33 == 8465);havoc #t~mem33;call #t~mem34 := read~int(~s.base, ~s.offset + 52, 4); {157#false} is VALID [2018-11-14 19:05:50,657 INFO L273 TraceCheckUtils]: 26: Hoare triple {157#false} assume !(#t~mem34 == 8466);havoc #t~mem34;call #t~mem35 := read~int(~s.base, ~s.offset + 52, 4); {157#false} is VALID [2018-11-14 19:05:50,657 INFO L273 TraceCheckUtils]: 27: Hoare triple {157#false} assume !(#t~mem35 == 8496);havoc #t~mem35;call #t~mem36 := read~int(~s.base, ~s.offset + 52, 4); {157#false} is VALID [2018-11-14 19:05:50,658 INFO L273 TraceCheckUtils]: 28: Hoare triple {157#false} assume !(#t~mem36 == 8497);havoc #t~mem36;call #t~mem37 := read~int(~s.base, ~s.offset + 52, 4); {157#false} is VALID [2018-11-14 19:05:50,659 INFO L273 TraceCheckUtils]: 29: Hoare triple {157#false} assume !(#t~mem37 == 8512);havoc #t~mem37;call #t~mem38 := read~int(~s.base, ~s.offset + 52, 4); {157#false} is VALID [2018-11-14 19:05:50,659 INFO L273 TraceCheckUtils]: 30: Hoare triple {157#false} assume !(#t~mem38 == 8513);havoc #t~mem38;call #t~mem39 := read~int(~s.base, ~s.offset + 52, 4); {157#false} is VALID [2018-11-14 19:05:50,660 INFO L273 TraceCheckUtils]: 31: Hoare triple {157#false} assume !(#t~mem39 == 8528);havoc #t~mem39;call #t~mem40 := read~int(~s.base, ~s.offset + 52, 4); {157#false} is VALID [2018-11-14 19:05:50,660 INFO L273 TraceCheckUtils]: 32: Hoare triple {157#false} assume !(#t~mem40 == 8529);havoc #t~mem40;call #t~mem41 := read~int(~s.base, ~s.offset + 52, 4); {157#false} is VALID [2018-11-14 19:05:50,661 INFO L273 TraceCheckUtils]: 33: Hoare triple {157#false} assume !(#t~mem41 == 8544);havoc #t~mem41;call #t~mem42 := read~int(~s.base, ~s.offset + 52, 4); {157#false} is VALID [2018-11-14 19:05:50,661 INFO L273 TraceCheckUtils]: 34: Hoare triple {157#false} assume !(#t~mem42 == 8545);havoc #t~mem42;call #t~mem43 := read~int(~s.base, ~s.offset + 52, 4); {157#false} is VALID [2018-11-14 19:05:50,661 INFO L273 TraceCheckUtils]: 35: Hoare triple {157#false} assume !(#t~mem43 == 8560);havoc #t~mem43;call #t~mem44 := read~int(~s.base, ~s.offset + 52, 4); {157#false} is VALID [2018-11-14 19:05:50,662 INFO L273 TraceCheckUtils]: 36: Hoare triple {157#false} assume !(#t~mem44 == 8561);havoc #t~mem44;call #t~mem45 := read~int(~s.base, ~s.offset + 52, 4); {157#false} is VALID [2018-11-14 19:05:50,662 INFO L273 TraceCheckUtils]: 37: Hoare triple {157#false} assume !(#t~mem45 == 8448);havoc #t~mem45;call #t~mem46 := read~int(~s.base, ~s.offset + 52, 4); {157#false} is VALID [2018-11-14 19:05:50,662 INFO L273 TraceCheckUtils]: 38: Hoare triple {157#false} assume !(#t~mem46 == 8576);havoc #t~mem46;call #t~mem47 := read~int(~s.base, ~s.offset + 52, 4); {157#false} is VALID [2018-11-14 19:05:50,663 INFO L273 TraceCheckUtils]: 39: Hoare triple {157#false} assume !(#t~mem47 == 8577);havoc #t~mem47;call #t~mem48 := read~int(~s.base, ~s.offset + 52, 4); {157#false} is VALID [2018-11-14 19:05:50,663 INFO L273 TraceCheckUtils]: 40: Hoare triple {157#false} assume !(#t~mem48 == 8592);havoc #t~mem48;call #t~mem49 := read~int(~s.base, ~s.offset + 52, 4); {157#false} is VALID [2018-11-14 19:05:50,663 INFO L273 TraceCheckUtils]: 41: Hoare triple {157#false} assume !(#t~mem49 == 8593);havoc #t~mem49;call #t~mem50 := read~int(~s.base, ~s.offset + 52, 4); {157#false} is VALID [2018-11-14 19:05:50,664 INFO L273 TraceCheckUtils]: 42: Hoare triple {157#false} assume !(#t~mem50 == 8608);havoc #t~mem50;call #t~mem51 := read~int(~s.base, ~s.offset + 52, 4); {157#false} is VALID [2018-11-14 19:05:50,664 INFO L273 TraceCheckUtils]: 43: Hoare triple {157#false} assume !(#t~mem51 == 8609);havoc #t~mem51;call #t~mem52 := read~int(~s.base, ~s.offset + 52, 4); {157#false} is VALID [2018-11-14 19:05:50,664 INFO L273 TraceCheckUtils]: 44: Hoare triple {157#false} assume !(#t~mem52 == 8640);havoc #t~mem52;call #t~mem53 := read~int(~s.base, ~s.offset + 52, 4); {157#false} is VALID [2018-11-14 19:05:50,665 INFO L273 TraceCheckUtils]: 45: Hoare triple {157#false} assume !(#t~mem53 == 8641);havoc #t~mem53;call #t~mem54 := read~int(~s.base, ~s.offset + 52, 4); {157#false} is VALID [2018-11-14 19:05:50,665 INFO L273 TraceCheckUtils]: 46: Hoare triple {157#false} assume !(#t~mem54 == 8656);havoc #t~mem54;call #t~mem55 := read~int(~s.base, ~s.offset + 52, 4); {157#false} is VALID [2018-11-14 19:05:50,665 INFO L273 TraceCheckUtils]: 47: Hoare triple {157#false} assume !(#t~mem55 == 8657);havoc #t~mem55;call #t~mem56 := read~int(~s.base, ~s.offset + 52, 4); {157#false} is VALID [2018-11-14 19:05:50,665 INFO L273 TraceCheckUtils]: 48: Hoare triple {157#false} assume #t~mem56 == 8672;havoc #t~mem56; {157#false} is VALID [2018-11-14 19:05:50,666 INFO L273 TraceCheckUtils]: 49: Hoare triple {157#false} assume -2147483648 <= #t~nondet121 && #t~nondet121 <= 2147483647;~ret~0 := #t~nondet121;havoc #t~nondet121; {157#false} is VALID [2018-11-14 19:05:50,666 INFO L273 TraceCheckUtils]: 50: Hoare triple {157#false} assume ~blastFlag~0 == 4; {157#false} is VALID [2018-11-14 19:05:50,666 INFO L273 TraceCheckUtils]: 51: Hoare triple {157#false} assume !false; {157#false} is VALID [2018-11-14 19:05:50,684 INFO L134 CoverageAnalysis]: Checked inductivity of 0 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2018-11-14 19:05:50,687 INFO L312 seRefinementStrategy]: Constructing automaton from 1 perfect and 0 imperfect interpolant sequences. [2018-11-14 19:05:50,688 INFO L327 seRefinementStrategy]: Number of different interpolants: perfect sequences [4] imperfect sequences [] total 4 [2018-11-14 19:05:50,693 INFO L78 Accepts]: Start accepts. Automaton has 4 states. Word has length 52 [2018-11-14 19:05:50,697 INFO L84 Accepts]: Finished accepts. word is accepted. [2018-11-14 19:05:50,700 INFO L86 InductivityCheck]: Starting indutivity check of a Floyd-Hoare automaton with 4 states. [2018-11-14 19:05:51,097 INFO L119 InductivityCheck]: Floyd-Hoare automaton has 52 edges. 52 inductive. 0 not inductive. 0 times theorem prover too weak to decide inductivity. [2018-11-14 19:05:51,097 INFO L459 AbstractCegarLoop]: Interpolant automaton has 4 states [2018-11-14 19:05:51,105 INFO L142 InterpolantAutomaton]: Constructing interpolant automaton starting with 4 interpolants. [2018-11-14 19:05:51,106 INFO L144 InterpolantAutomaton]: CoverageRelationStatistics Valid=5, Invalid=7, Unknown=0, NotChecked=0, Total=12 [2018-11-14 19:05:51,108 INFO L87 Difference]: Start difference. First operand 153 states. Second operand 4 states. [2018-11-14 19:05:54,045 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2018-11-14 19:05:54,045 INFO L93 Difference]: Finished difference Result 326 states and 541 transitions. [2018-11-14 19:05:54,046 INFO L142 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 4 states. [2018-11-14 19:05:54,046 INFO L78 Accepts]: Start accepts. Automaton has 4 states. Word has length 52 [2018-11-14 19:05:54,046 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2018-11-14 19:05:54,048 INFO L82 GeneralOperation]: Start removeUnreachable. Operand 4 states. [2018-11-14 19:05:54,069 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 4 states to 4 states and 541 transitions. [2018-11-14 19:05:54,070 INFO L82 GeneralOperation]: Start removeUnreachable. Operand 4 states. [2018-11-14 19:05:54,082 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 4 states to 4 states and 541 transitions. [2018-11-14 19:05:54,082 INFO L86 InductivityCheck]: Starting indutivity check of a Floyd-Hoare automaton with 4 states and 541 transitions. [2018-11-14 19:05:55,085 INFO L119 InductivityCheck]: Floyd-Hoare automaton has 541 edges. 541 inductive. 0 not inductive. 0 times theorem prover too weak to decide inductivity. [2018-11-14 19:05:55,109 INFO L225 Difference]: With dead ends: 326 [2018-11-14 19:05:55,109 INFO L226 Difference]: Without dead ends: 166 [2018-11-14 19:05:55,114 INFO L604 BasicCegarLoop]: 0 DeclaredPredicates, 7 GetRequests, 2 SyntacticMatches, 2 SemanticMatches, 3 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 0 ImplicationChecksByTransitivity, 0.1s TimeCoverageRelationStatistics Valid=9, Invalid=11, Unknown=0, NotChecked=0, Total=20 [2018-11-14 19:05:55,137 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 166 states. [2018-11-14 19:05:55,526 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 166 to 149. [2018-11-14 19:05:55,527 INFO L214 AbstractMinimizeNwa]: Start testing correctness of minimizeSevpa [2018-11-14 19:05:55,527 INFO L82 GeneralOperation]: Start isEquivalent. First operand 166 states. Second operand 149 states. [2018-11-14 19:05:55,528 INFO L74 IsIncluded]: Start isIncluded. First operand 166 states. Second operand 149 states. [2018-11-14 19:05:55,528 INFO L87 Difference]: Start difference. First operand 166 states. Second operand 149 states. [2018-11-14 19:05:55,540 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2018-11-14 19:05:55,540 INFO L93 Difference]: Finished difference Result 166 states and 245 transitions. [2018-11-14 19:05:55,540 INFO L276 IsEmpty]: Start isEmpty. Operand 166 states and 245 transitions. [2018-11-14 19:05:55,542 INFO L282 IsEmpty]: Finished isEmpty. No accepting run. [2018-11-14 19:05:55,543 INFO L83 IsIncluded]: Finished isIncluded. Language is included [2018-11-14 19:05:55,543 INFO L74 IsIncluded]: Start isIncluded. First operand 149 states. Second operand 166 states. [2018-11-14 19:05:55,543 INFO L87 Difference]: Start difference. First operand 149 states. Second operand 166 states. [2018-11-14 19:05:55,553 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2018-11-14 19:05:55,554 INFO L93 Difference]: Finished difference Result 166 states and 245 transitions. [2018-11-14 19:05:55,554 INFO L276 IsEmpty]: Start isEmpty. Operand 166 states and 245 transitions. [2018-11-14 19:05:55,556 INFO L282 IsEmpty]: Finished isEmpty. No accepting run. [2018-11-14 19:05:55,556 INFO L83 IsIncluded]: Finished isIncluded. Language is included [2018-11-14 19:05:55,556 INFO L88 GeneralOperation]: Finished isEquivalent. [2018-11-14 19:05:55,557 INFO L221 AbstractMinimizeNwa]: Finished testing correctness of minimizeSevpa [2018-11-14 19:05:55,557 INFO L82 GeneralOperation]: Start removeUnreachable. Operand 149 states. [2018-11-14 19:05:55,565 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 149 states to 149 states and 224 transitions. [2018-11-14 19:05:55,567 INFO L78 Accepts]: Start accepts. Automaton has 149 states and 224 transitions. Word has length 52 [2018-11-14 19:05:55,567 INFO L84 Accepts]: Finished accepts. word is rejected. [2018-11-14 19:05:55,568 INFO L480 AbstractCegarLoop]: Abstraction has 149 states and 224 transitions. [2018-11-14 19:05:55,568 INFO L481 AbstractCegarLoop]: Interpolant automaton has 4 states. [2018-11-14 19:05:55,568 INFO L276 IsEmpty]: Start isEmpty. Operand 149 states and 224 transitions. [2018-11-14 19:05:55,571 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 67 [2018-11-14 19:05:55,571 INFO L367 BasicCegarLoop]: Found error trace [2018-11-14 19:05:55,571 INFO L375 BasicCegarLoop]: trace histogram [2, 2, 2, 2, 2, 2, 2, 2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2018-11-14 19:05:55,572 INFO L423 AbstractCegarLoop]: === Iteration 2 === [ssl3_acceptErr0ASSERT_VIOLATIONERROR_FUNCTION]=== [2018-11-14 19:05:55,572 INFO L141 PredicateUnifier]: Initialized classic predicate unifier [2018-11-14 19:05:55,572 INFO L82 PathProgramCache]: Analyzing trace with hash 1302332565, now seen corresponding path program 1 times [2018-11-14 19:05:55,572 INFO L223 ckRefinementStrategy]: Switched to mode SMTINTERPOL_TREE_INTERPOLANTS [2018-11-14 19:05:55,572 INFO L69 tionRefinementEngine]: Using refinement strategy CamelRefinementStrategy [2018-11-14 19:05:55,575 INFO L119 rtionOrderModulation]: Craig_TreeInterpolation forces the order to NOT_INCREMENTALLY [2018-11-14 19:05:55,575 INFO L103 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2018-11-14 19:05:55,575 INFO L119 rtionOrderModulation]: Craig_TreeInterpolation forces the order to NOT_INCREMENTALLY [2018-11-14 19:05:55,642 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2018-11-14 19:05:55,884 INFO L256 TraceCheckUtils]: 0: Hoare triple {1066#true} call ULTIMATE.init(); {1066#true} is VALID [2018-11-14 19:05:55,884 INFO L273 TraceCheckUtils]: 1: Hoare triple {1066#true} #NULL.base, #NULL.offset := 0, 0;#valid := #valid[0 := 0];~init~0 := 1;call ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset := #Ultimate.alloc(100);call write~unchecked~int(0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 0, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 4, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 8, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 12, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 16, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 20, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 24, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 28, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 32, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 36, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 40, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 44, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 48, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 52, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 56, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 60, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 64, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 68, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 72, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 76, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 80, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 84, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 88, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 92, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 96, 4);call write~unchecked~int(0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 0, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 4, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 8, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 12, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 16, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 20, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 24, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 28, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 32, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 36, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 40, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 44, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 48, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 52, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 56, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 60, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 64, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 68, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 72, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 76, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 80, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 84, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 88, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 92, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 96, 4); {1066#true} is VALID [2018-11-14 19:05:55,885 INFO L273 TraceCheckUtils]: 2: Hoare triple {1066#true} assume true; {1066#true} is VALID [2018-11-14 19:05:55,885 INFO L268 TraceCheckUtils]: 3: Hoare quadruple {1066#true} {1066#true} #654#return; {1066#true} is VALID [2018-11-14 19:05:55,886 INFO L256 TraceCheckUtils]: 4: Hoare triple {1066#true} call #t~ret138 := main(); {1066#true} is VALID [2018-11-14 19:05:55,886 INFO L273 TraceCheckUtils]: 5: Hoare triple {1066#true} havoc ~s~0.base, ~s~0.offset;havoc ~tmp~2;call #t~malloc3.base, #t~malloc3.offset := #Ultimate.alloc(248);~s~0.base, ~s~0.offset := #t~malloc3.base, #t~malloc3.offset;call #t~malloc4.base, #t~malloc4.offset := #Ultimate.alloc(899);call write~$Pointer$(#t~malloc4.base, #t~malloc4.offset, ~s~0.base, ~s~0.offset + 84, 4);call #t~malloc5.base, #t~malloc5.offset := #Ultimate.alloc(232);call write~$Pointer$(#t~malloc5.base, #t~malloc5.offset, ~s~0.base, ~s~0.offset + 204, 4);call #t~malloc6.base, #t~malloc6.offset := #Ultimate.alloc(200);call write~$Pointer$(#t~malloc6.base, #t~malloc6.offset, ~s~0.base, ~s~0.offset + 176, 4);call write~int(8464, ~s~0.base, ~s~0.offset + 52, 4); {1066#true} is VALID [2018-11-14 19:05:55,886 INFO L256 TraceCheckUtils]: 6: Hoare triple {1066#true} call #t~ret7 := ssl3_accept(~s~0.base, ~s~0.offset); {1066#true} is VALID [2018-11-14 19:05:55,888 INFO L273 TraceCheckUtils]: 7: Hoare triple {1066#true} ~s.base, ~s.offset := #in~s.base, #in~s.offset;havoc ~buf~0.base, ~buf~0.offset;havoc ~l~0;havoc ~Time~0;havoc ~tmp~3;havoc ~cb~0.base, ~cb~0.offset;havoc ~num1~0;havoc ~ret~0;havoc ~new_state~0;havoc ~state~0;havoc ~skip~0;havoc ~got_new_session~0;assume -2147483648 <= #t~nondet8 && #t~nondet8 <= 2147483647;~tmp___1~0 := #t~nondet8;havoc #t~nondet8;assume -2147483648 <= #t~nondet9 && #t~nondet9 <= 2147483647;~tmp___2~0 := #t~nondet9;havoc #t~nondet9;assume -2147483648 <= #t~nondet10 && #t~nondet10 <= 2147483647;~tmp___3~0 := #t~nondet10;havoc #t~nondet10;assume -2147483648 <= #t~nondet11 && #t~nondet11 <= 2147483647;~tmp___4~0 := #t~nondet11;havoc #t~nondet11;assume -2147483648 <= #t~nondet12 && #t~nondet12 <= 2147483647;~tmp___5~0 := #t~nondet12;havoc #t~nondet12;assume -2147483648 <= #t~nondet13 && #t~nondet13 <= 2147483647;~tmp___6~0 := #t~nondet13;havoc #t~nondet13;havoc ~tmp___7~0;assume -2147483648 <= #t~nondet14 && #t~nondet14 <= 2147483647;~tmp___8~0 := #t~nondet14;havoc #t~nondet14;assume -2147483648 <= #t~nondet15 && #t~nondet15 <= 2147483647;~tmp___9~0 := #t~nondet15;havoc #t~nondet15;assume -2147483648 <= #t~nondet16 && #t~nondet16 <= 2147483647;~tmp___10~0 := #t~nondet16;havoc #t~nondet16;havoc ~blastFlag~0;~blastFlag~0 := 0;assume -2147483648 <= #t~nondet17 && #t~nondet17 <= 2147483647;call write~int(#t~nondet17, ~s.base, ~s.offset + 92, 4);havoc #t~nondet17;call write~int(8464, ~s.base, ~s.offset + 52, 4);assume -2147483648 <= #t~nondet18 && #t~nondet18 <= 2147483647;~tmp~3 := #t~nondet18;havoc #t~nondet18;~Time~0 := ~tmp~3;~cb~0.base, ~cb~0.offset := 0, 0;~ret~0 := -1;~skip~0 := 0;~got_new_session~0 := 0;call #t~mem19.base, #t~mem19.offset := read~$Pointer$(~s.base, ~s.offset + 192, 4); {1068#(= (select (store (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 28) (+ (select (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 28)) 1)) (+ ssl3_accept_~s.offset 52)) 8464)} is VALID [2018-11-14 19:05:55,889 INFO L273 TraceCheckUtils]: 8: Hoare triple {1068#(= (select (store (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 28) (+ (select (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 28)) 1)) (+ ssl3_accept_~s.offset 52)) 8464)} assume (#t~mem19.base + #t~mem19.offset) % 4294967296 != 0;havoc #t~mem19.base, #t~mem19.offset;call #t~mem20.base, #t~mem20.offset := read~$Pointer$(~s.base, ~s.offset + 192, 4);~cb~0.base, ~cb~0.offset := #t~mem20.base, #t~mem20.offset;havoc #t~mem20.base, #t~mem20.offset; {1068#(= (select (store (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 28) (+ (select (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 28)) 1)) (+ ssl3_accept_~s.offset 52)) 8464)} is VALID [2018-11-14 19:05:55,890 INFO L273 TraceCheckUtils]: 9: Hoare triple {1068#(= (select (store (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 28) (+ (select (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 28)) 1)) (+ ssl3_accept_~s.offset 52)) 8464)} call #t~mem21 := read~int(~s.base, ~s.offset + 28, 4);call write~int(#t~mem21 + 1, ~s.base, ~s.offset + 28, 4);havoc #t~mem21; {1068#(= (select (store (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 28) (+ (select (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 28)) 1)) (+ ssl3_accept_~s.offset 52)) 8464)} is VALID [2018-11-14 19:05:55,897 INFO L273 TraceCheckUtils]: 10: Hoare triple {1068#(= (select (store (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 28) (+ (select (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 28)) 1)) (+ ssl3_accept_~s.offset 52)) 8464)} assume !(~bitwiseAnd(~tmp___1~0, 12288) != 0); {1068#(= (select (store (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 28) (+ (select (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 28)) 1)) (+ ssl3_accept_~s.offset 52)) 8464)} is VALID [2018-11-14 19:05:55,898 INFO L273 TraceCheckUtils]: 11: Hoare triple {1068#(= (select (store (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 28) (+ (select (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 28)) 1)) (+ ssl3_accept_~s.offset 52)) 8464)} call #t~mem22.base, #t~mem22.offset := read~$Pointer$(~s.base, ~s.offset + 136, 4); {1068#(= (select (store (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 28) (+ (select (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 28)) 1)) (+ ssl3_accept_~s.offset 52)) 8464)} is VALID [2018-11-14 19:05:55,899 INFO L273 TraceCheckUtils]: 12: Hoare triple {1068#(= (select (store (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 28) (+ (select (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 28)) 1)) (+ ssl3_accept_~s.offset 52)) 8464)} assume !((#t~mem22.base + #t~mem22.offset) % 4294967296 == 0);havoc #t~mem22.base, #t~mem22.offset; {1068#(= (select (store (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 28) (+ (select (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 28)) 1)) (+ ssl3_accept_~s.offset 52)) 8464)} is VALID [2018-11-14 19:05:55,899 INFO L273 TraceCheckUtils]: 13: Hoare triple {1068#(= (select (store (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 28) (+ (select (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 28)) 1)) (+ ssl3_accept_~s.offset 52)) 8464)} assume true; {1068#(= (select (store (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 28) (+ (select (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 28)) 1)) (+ ssl3_accept_~s.offset 52)) 8464)} is VALID [2018-11-14 19:05:55,900 INFO L273 TraceCheckUtils]: 14: Hoare triple {1068#(= (select (store (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 28) (+ (select (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 28)) 1)) (+ ssl3_accept_~s.offset 52)) 8464)} assume !false; {1068#(= (select (store (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 28) (+ (select (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 28)) 1)) (+ ssl3_accept_~s.offset 52)) 8464)} is VALID [2018-11-14 19:05:55,900 INFO L273 TraceCheckUtils]: 15: Hoare triple {1068#(= (select (store (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 28) (+ (select (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 28)) 1)) (+ ssl3_accept_~s.offset 52)) 8464)} call #t~mem23 := read~int(~s.base, ~s.offset + 52, 4);~state~0 := #t~mem23;havoc #t~mem23;call #t~mem24 := read~int(~s.base, ~s.offset + 52, 4); {1068#(= (select (store (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 28) (+ (select (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 28)) 1)) (+ ssl3_accept_~s.offset 52)) 8464)} is VALID [2018-11-14 19:05:55,901 INFO L273 TraceCheckUtils]: 16: Hoare triple {1068#(= (select (store (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 28) (+ (select (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 28)) 1)) (+ ssl3_accept_~s.offset 52)) 8464)} assume !(#t~mem24 == 12292);havoc #t~mem24;call #t~mem25 := read~int(~s.base, ~s.offset + 52, 4); {1068#(= (select (store (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 28) (+ (select (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 28)) 1)) (+ ssl3_accept_~s.offset 52)) 8464)} is VALID [2018-11-14 19:05:55,901 INFO L273 TraceCheckUtils]: 17: Hoare triple {1068#(= (select (store (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 28) (+ (select (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 28)) 1)) (+ ssl3_accept_~s.offset 52)) 8464)} assume !(#t~mem25 == 16384);havoc #t~mem25;call #t~mem26 := read~int(~s.base, ~s.offset + 52, 4); {1068#(= (select (store (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 28) (+ (select (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 28)) 1)) (+ ssl3_accept_~s.offset 52)) 8464)} is VALID [2018-11-14 19:05:55,902 INFO L273 TraceCheckUtils]: 18: Hoare triple {1068#(= (select (store (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 28) (+ (select (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 28)) 1)) (+ ssl3_accept_~s.offset 52)) 8464)} assume !(#t~mem26 == 8192);havoc #t~mem26;call #t~mem27 := read~int(~s.base, ~s.offset + 52, 4); {1068#(= (select (store (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 28) (+ (select (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 28)) 1)) (+ ssl3_accept_~s.offset 52)) 8464)} is VALID [2018-11-14 19:05:55,902 INFO L273 TraceCheckUtils]: 19: Hoare triple {1068#(= (select (store (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 28) (+ (select (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 28)) 1)) (+ ssl3_accept_~s.offset 52)) 8464)} assume !(#t~mem27 == 24576);havoc #t~mem27;call #t~mem28 := read~int(~s.base, ~s.offset + 52, 4); {1068#(= (select (store (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 28) (+ (select (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 28)) 1)) (+ ssl3_accept_~s.offset 52)) 8464)} is VALID [2018-11-14 19:05:55,904 INFO L273 TraceCheckUtils]: 20: Hoare triple {1068#(= (select (store (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 28) (+ (select (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 28)) 1)) (+ ssl3_accept_~s.offset 52)) 8464)} assume !(#t~mem28 == 8195);havoc #t~mem28;call #t~mem29 := read~int(~s.base, ~s.offset + 52, 4); {1069#(= |ssl3_accept_#t~mem29| 8464)} is VALID [2018-11-14 19:05:55,904 INFO L273 TraceCheckUtils]: 21: Hoare triple {1069#(= |ssl3_accept_#t~mem29| 8464)} assume #t~mem29 == 8480;havoc #t~mem29; {1067#false} is VALID [2018-11-14 19:05:55,905 INFO L273 TraceCheckUtils]: 22: Hoare triple {1067#false} call write~int(0, ~s.base, ~s.offset + 48, 4);assume -2147483648 <= #t~nondet67 && #t~nondet67 <= 2147483647;~ret~0 := #t~nondet67;havoc #t~nondet67; {1067#false} is VALID [2018-11-14 19:05:55,905 INFO L273 TraceCheckUtils]: 23: Hoare triple {1067#false} assume !(~ret~0 <= 0);call #t~mem68.base, #t~mem68.offset := read~$Pointer$(~s.base, ~s.offset + 84, 4);call write~int(8482, #t~mem68.base, #t~mem68.offset + 604 + 240, 4);havoc #t~mem68.base, #t~mem68.offset;call write~int(8448, ~s.base, ~s.offset + 52, 4);call write~int(0, ~s.base, ~s.offset + 64, 4); {1067#false} is VALID [2018-11-14 19:05:55,906 INFO L273 TraceCheckUtils]: 24: Hoare triple {1067#false} call #t~mem127.base, #t~mem127.offset := read~$Pointer$(~s.base, ~s.offset + 84, 4);call #t~mem128 := read~int(#t~mem127.base, #t~mem127.offset + 604 + 244, 4); {1067#false} is VALID [2018-11-14 19:05:55,906 INFO L273 TraceCheckUtils]: 25: Hoare triple {1067#false} assume !(#t~mem128 == 0);havoc #t~mem127.base, #t~mem127.offset;havoc #t~mem128; {1067#false} is VALID [2018-11-14 19:05:55,909 INFO L273 TraceCheckUtils]: 26: Hoare triple {1067#false} ~skip~0 := 0; {1067#false} is VALID [2018-11-14 19:05:55,909 INFO L273 TraceCheckUtils]: 27: Hoare triple {1067#false} assume true; {1067#false} is VALID [2018-11-14 19:05:55,909 INFO L273 TraceCheckUtils]: 28: Hoare triple {1067#false} assume !false; {1067#false} is VALID [2018-11-14 19:05:55,909 INFO L273 TraceCheckUtils]: 29: Hoare triple {1067#false} call #t~mem23 := read~int(~s.base, ~s.offset + 52, 4);~state~0 := #t~mem23;havoc #t~mem23;call #t~mem24 := read~int(~s.base, ~s.offset + 52, 4); {1067#false} is VALID [2018-11-14 19:05:55,910 INFO L273 TraceCheckUtils]: 30: Hoare triple {1067#false} assume !(#t~mem24 == 12292);havoc #t~mem24;call #t~mem25 := read~int(~s.base, ~s.offset + 52, 4); {1067#false} is VALID [2018-11-14 19:05:55,910 INFO L273 TraceCheckUtils]: 31: Hoare triple {1067#false} assume !(#t~mem25 == 16384);havoc #t~mem25;call #t~mem26 := read~int(~s.base, ~s.offset + 52, 4); {1067#false} is VALID [2018-11-14 19:05:55,910 INFO L273 TraceCheckUtils]: 32: Hoare triple {1067#false} assume !(#t~mem26 == 8192);havoc #t~mem26;call #t~mem27 := read~int(~s.base, ~s.offset + 52, 4); {1067#false} is VALID [2018-11-14 19:05:55,910 INFO L273 TraceCheckUtils]: 33: Hoare triple {1067#false} assume !(#t~mem27 == 24576);havoc #t~mem27;call #t~mem28 := read~int(~s.base, ~s.offset + 52, 4); {1067#false} is VALID [2018-11-14 19:05:55,910 INFO L273 TraceCheckUtils]: 34: Hoare triple {1067#false} assume !(#t~mem28 == 8195);havoc #t~mem28;call #t~mem29 := read~int(~s.base, ~s.offset + 52, 4); {1067#false} is VALID [2018-11-14 19:05:55,911 INFO L273 TraceCheckUtils]: 35: Hoare triple {1067#false} assume !(#t~mem29 == 8480);havoc #t~mem29;call #t~mem30 := read~int(~s.base, ~s.offset + 52, 4); {1067#false} is VALID [2018-11-14 19:05:55,911 INFO L273 TraceCheckUtils]: 36: Hoare triple {1067#false} assume !(#t~mem30 == 8481);havoc #t~mem30;call #t~mem31 := read~int(~s.base, ~s.offset + 52, 4); {1067#false} is VALID [2018-11-14 19:05:55,911 INFO L273 TraceCheckUtils]: 37: Hoare triple {1067#false} assume !(#t~mem31 == 8482);havoc #t~mem31;call #t~mem32 := read~int(~s.base, ~s.offset + 52, 4); {1067#false} is VALID [2018-11-14 19:05:55,912 INFO L273 TraceCheckUtils]: 38: Hoare triple {1067#false} assume !(#t~mem32 == 8464);havoc #t~mem32;call #t~mem33 := read~int(~s.base, ~s.offset + 52, 4); {1067#false} is VALID [2018-11-14 19:05:55,912 INFO L273 TraceCheckUtils]: 39: Hoare triple {1067#false} assume !(#t~mem33 == 8465);havoc #t~mem33;call #t~mem34 := read~int(~s.base, ~s.offset + 52, 4); {1067#false} is VALID [2018-11-14 19:05:55,912 INFO L273 TraceCheckUtils]: 40: Hoare triple {1067#false} assume !(#t~mem34 == 8466);havoc #t~mem34;call #t~mem35 := read~int(~s.base, ~s.offset + 52, 4); {1067#false} is VALID [2018-11-14 19:05:55,913 INFO L273 TraceCheckUtils]: 41: Hoare triple {1067#false} assume !(#t~mem35 == 8496);havoc #t~mem35;call #t~mem36 := read~int(~s.base, ~s.offset + 52, 4); {1067#false} is VALID [2018-11-14 19:05:55,913 INFO L273 TraceCheckUtils]: 42: Hoare triple {1067#false} assume !(#t~mem36 == 8497);havoc #t~mem36;call #t~mem37 := read~int(~s.base, ~s.offset + 52, 4); {1067#false} is VALID [2018-11-14 19:05:55,913 INFO L273 TraceCheckUtils]: 43: Hoare triple {1067#false} assume !(#t~mem37 == 8512);havoc #t~mem37;call #t~mem38 := read~int(~s.base, ~s.offset + 52, 4); {1067#false} is VALID [2018-11-14 19:05:55,914 INFO L273 TraceCheckUtils]: 44: Hoare triple {1067#false} assume !(#t~mem38 == 8513);havoc #t~mem38;call #t~mem39 := read~int(~s.base, ~s.offset + 52, 4); {1067#false} is VALID [2018-11-14 19:05:55,914 INFO L273 TraceCheckUtils]: 45: Hoare triple {1067#false} assume !(#t~mem39 == 8528);havoc #t~mem39;call #t~mem40 := read~int(~s.base, ~s.offset + 52, 4); {1067#false} is VALID [2018-11-14 19:05:55,914 INFO L273 TraceCheckUtils]: 46: Hoare triple {1067#false} assume !(#t~mem40 == 8529);havoc #t~mem40;call #t~mem41 := read~int(~s.base, ~s.offset + 52, 4); {1067#false} is VALID [2018-11-14 19:05:55,914 INFO L273 TraceCheckUtils]: 47: Hoare triple {1067#false} assume !(#t~mem41 == 8544);havoc #t~mem41;call #t~mem42 := read~int(~s.base, ~s.offset + 52, 4); {1067#false} is VALID [2018-11-14 19:05:55,914 INFO L273 TraceCheckUtils]: 48: Hoare triple {1067#false} assume !(#t~mem42 == 8545);havoc #t~mem42;call #t~mem43 := read~int(~s.base, ~s.offset + 52, 4); {1067#false} is VALID [2018-11-14 19:05:55,915 INFO L273 TraceCheckUtils]: 49: Hoare triple {1067#false} assume !(#t~mem43 == 8560);havoc #t~mem43;call #t~mem44 := read~int(~s.base, ~s.offset + 52, 4); {1067#false} is VALID [2018-11-14 19:05:55,915 INFO L273 TraceCheckUtils]: 50: Hoare triple {1067#false} assume !(#t~mem44 == 8561);havoc #t~mem44;call #t~mem45 := read~int(~s.base, ~s.offset + 52, 4); {1067#false} is VALID [2018-11-14 19:05:55,915 INFO L273 TraceCheckUtils]: 51: Hoare triple {1067#false} assume !(#t~mem45 == 8448);havoc #t~mem45;call #t~mem46 := read~int(~s.base, ~s.offset + 52, 4); {1067#false} is VALID [2018-11-14 19:05:55,915 INFO L273 TraceCheckUtils]: 52: Hoare triple {1067#false} assume !(#t~mem46 == 8576);havoc #t~mem46;call #t~mem47 := read~int(~s.base, ~s.offset + 52, 4); {1067#false} is VALID [2018-11-14 19:05:55,916 INFO L273 TraceCheckUtils]: 53: Hoare triple {1067#false} assume !(#t~mem47 == 8577);havoc #t~mem47;call #t~mem48 := read~int(~s.base, ~s.offset + 52, 4); {1067#false} is VALID [2018-11-14 19:05:55,916 INFO L273 TraceCheckUtils]: 54: Hoare triple {1067#false} assume !(#t~mem48 == 8592);havoc #t~mem48;call #t~mem49 := read~int(~s.base, ~s.offset + 52, 4); {1067#false} is VALID [2018-11-14 19:05:55,916 INFO L273 TraceCheckUtils]: 55: Hoare triple {1067#false} assume !(#t~mem49 == 8593);havoc #t~mem49;call #t~mem50 := read~int(~s.base, ~s.offset + 52, 4); {1067#false} is VALID [2018-11-14 19:05:55,917 INFO L273 TraceCheckUtils]: 56: Hoare triple {1067#false} assume !(#t~mem50 == 8608);havoc #t~mem50;call #t~mem51 := read~int(~s.base, ~s.offset + 52, 4); {1067#false} is VALID [2018-11-14 19:05:55,917 INFO L273 TraceCheckUtils]: 57: Hoare triple {1067#false} assume !(#t~mem51 == 8609);havoc #t~mem51;call #t~mem52 := read~int(~s.base, ~s.offset + 52, 4); {1067#false} is VALID [2018-11-14 19:05:55,917 INFO L273 TraceCheckUtils]: 58: Hoare triple {1067#false} assume !(#t~mem52 == 8640);havoc #t~mem52;call #t~mem53 := read~int(~s.base, ~s.offset + 52, 4); {1067#false} is VALID [2018-11-14 19:05:55,917 INFO L273 TraceCheckUtils]: 59: Hoare triple {1067#false} assume !(#t~mem53 == 8641);havoc #t~mem53;call #t~mem54 := read~int(~s.base, ~s.offset + 52, 4); {1067#false} is VALID [2018-11-14 19:05:55,918 INFO L273 TraceCheckUtils]: 60: Hoare triple {1067#false} assume !(#t~mem54 == 8656);havoc #t~mem54;call #t~mem55 := read~int(~s.base, ~s.offset + 52, 4); {1067#false} is VALID [2018-11-14 19:05:55,918 INFO L273 TraceCheckUtils]: 61: Hoare triple {1067#false} assume !(#t~mem55 == 8657);havoc #t~mem55;call #t~mem56 := read~int(~s.base, ~s.offset + 52, 4); {1067#false} is VALID [2018-11-14 19:05:55,918 INFO L273 TraceCheckUtils]: 62: Hoare triple {1067#false} assume #t~mem56 == 8672;havoc #t~mem56; {1067#false} is VALID [2018-11-14 19:05:55,919 INFO L273 TraceCheckUtils]: 63: Hoare triple {1067#false} assume -2147483648 <= #t~nondet121 && #t~nondet121 <= 2147483647;~ret~0 := #t~nondet121;havoc #t~nondet121; {1067#false} is VALID [2018-11-14 19:05:55,919 INFO L273 TraceCheckUtils]: 64: Hoare triple {1067#false} assume ~blastFlag~0 == 4; {1067#false} is VALID [2018-11-14 19:05:55,919 INFO L273 TraceCheckUtils]: 65: Hoare triple {1067#false} assume !false; {1067#false} is VALID [2018-11-14 19:05:55,931 INFO L134 CoverageAnalysis]: Checked inductivity of 9 backedges. 9 proven. 0 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2018-11-14 19:05:55,931 INFO L312 seRefinementStrategy]: Constructing automaton from 1 perfect and 0 imperfect interpolant sequences. [2018-11-14 19:05:55,931 INFO L327 seRefinementStrategy]: Number of different interpolants: perfect sequences [4] imperfect sequences [] total 4 [2018-11-14 19:05:55,933 INFO L78 Accepts]: Start accepts. Automaton has 4 states. Word has length 66 [2018-11-14 19:05:55,934 INFO L84 Accepts]: Finished accepts. word is accepted. [2018-11-14 19:05:55,934 INFO L86 InductivityCheck]: Starting indutivity check of a Floyd-Hoare automaton with 4 states. [2018-11-14 19:05:56,049 INFO L119 InductivityCheck]: Floyd-Hoare automaton has 66 edges. 66 inductive. 0 not inductive. 0 times theorem prover too weak to decide inductivity. [2018-11-14 19:05:56,049 INFO L459 AbstractCegarLoop]: Interpolant automaton has 4 states [2018-11-14 19:05:56,050 INFO L142 InterpolantAutomaton]: Constructing interpolant automaton starting with 4 interpolants. [2018-11-14 19:05:56,050 INFO L144 InterpolantAutomaton]: CoverageRelationStatistics Valid=5, Invalid=7, Unknown=0, NotChecked=0, Total=12 [2018-11-14 19:05:56,050 INFO L87 Difference]: Start difference. First operand 149 states and 224 transitions. Second operand 4 states. [2018-11-14 19:05:57,916 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2018-11-14 19:05:57,917 INFO L93 Difference]: Finished difference Result 289 states and 432 transitions. [2018-11-14 19:05:57,917 INFO L142 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 4 states. [2018-11-14 19:05:57,917 INFO L78 Accepts]: Start accepts. Automaton has 4 states. Word has length 66 [2018-11-14 19:05:57,917 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2018-11-14 19:05:57,917 INFO L82 GeneralOperation]: Start removeUnreachable. Operand 4 states. [2018-11-14 19:05:57,927 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 4 states to 4 states and 432 transitions. [2018-11-14 19:05:57,927 INFO L82 GeneralOperation]: Start removeUnreachable. Operand 4 states. [2018-11-14 19:05:57,933 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 4 states to 4 states and 432 transitions. [2018-11-14 19:05:57,934 INFO L86 InductivityCheck]: Starting indutivity check of a Floyd-Hoare automaton with 4 states and 432 transitions. [2018-11-14 19:05:58,421 INFO L119 InductivityCheck]: Floyd-Hoare automaton has 432 edges. 432 inductive. 0 not inductive. 0 times theorem prover too weak to decide inductivity. [2018-11-14 19:05:58,428 INFO L225 Difference]: With dead ends: 289 [2018-11-14 19:05:58,428 INFO L226 Difference]: Without dead ends: 166 [2018-11-14 19:05:58,430 INFO L604 BasicCegarLoop]: 0 DeclaredPredicates, 7 GetRequests, 2 SyntacticMatches, 2 SemanticMatches, 3 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 0 ImplicationChecksByTransitivity, 0.1s TimeCoverageRelationStatistics Valid=9, Invalid=11, Unknown=0, NotChecked=0, Total=20 [2018-11-14 19:05:58,430 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 166 states. [2018-11-14 19:05:58,560 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 166 to 149. [2018-11-14 19:05:58,560 INFO L214 AbstractMinimizeNwa]: Start testing correctness of minimizeSevpa [2018-11-14 19:05:58,560 INFO L82 GeneralOperation]: Start isEquivalent. First operand 166 states. Second operand 149 states. [2018-11-14 19:05:58,560 INFO L74 IsIncluded]: Start isIncluded. First operand 166 states. Second operand 149 states. [2018-11-14 19:05:58,560 INFO L87 Difference]: Start difference. First operand 166 states. Second operand 149 states. [2018-11-14 19:05:58,567 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2018-11-14 19:05:58,568 INFO L93 Difference]: Finished difference Result 166 states and 244 transitions. [2018-11-14 19:05:58,568 INFO L276 IsEmpty]: Start isEmpty. Operand 166 states and 244 transitions. [2018-11-14 19:05:58,569 INFO L282 IsEmpty]: Finished isEmpty. No accepting run. [2018-11-14 19:05:58,569 INFO L83 IsIncluded]: Finished isIncluded. Language is included [2018-11-14 19:05:58,569 INFO L74 IsIncluded]: Start isIncluded. First operand 149 states. Second operand 166 states. [2018-11-14 19:05:58,569 INFO L87 Difference]: Start difference. First operand 149 states. Second operand 166 states. [2018-11-14 19:05:58,576 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2018-11-14 19:05:58,576 INFO L93 Difference]: Finished difference Result 166 states and 244 transitions. [2018-11-14 19:05:58,577 INFO L276 IsEmpty]: Start isEmpty. Operand 166 states and 244 transitions. [2018-11-14 19:05:58,577 INFO L282 IsEmpty]: Finished isEmpty. No accepting run. [2018-11-14 19:05:58,578 INFO L83 IsIncluded]: Finished isIncluded. Language is included [2018-11-14 19:05:58,578 INFO L88 GeneralOperation]: Finished isEquivalent. [2018-11-14 19:05:58,578 INFO L221 AbstractMinimizeNwa]: Finished testing correctness of minimizeSevpa [2018-11-14 19:05:58,578 INFO L82 GeneralOperation]: Start removeUnreachable. Operand 149 states. [2018-11-14 19:05:58,584 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 149 states to 149 states and 223 transitions. [2018-11-14 19:05:58,584 INFO L78 Accepts]: Start accepts. Automaton has 149 states and 223 transitions. Word has length 66 [2018-11-14 19:05:58,584 INFO L84 Accepts]: Finished accepts. word is rejected. [2018-11-14 19:05:58,585 INFO L480 AbstractCegarLoop]: Abstraction has 149 states and 223 transitions. [2018-11-14 19:05:58,585 INFO L481 AbstractCegarLoop]: Interpolant automaton has 4 states. [2018-11-14 19:05:58,585 INFO L276 IsEmpty]: Start isEmpty. Operand 149 states and 223 transitions. [2018-11-14 19:05:58,587 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 68 [2018-11-14 19:05:58,587 INFO L367 BasicCegarLoop]: Found error trace [2018-11-14 19:05:58,587 INFO L375 BasicCegarLoop]: trace histogram [2, 2, 2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2018-11-14 19:05:58,587 INFO L423 AbstractCegarLoop]: === Iteration 3 === [ssl3_acceptErr0ASSERT_VIOLATIONERROR_FUNCTION]=== [2018-11-14 19:05:58,587 INFO L141 PredicateUnifier]: Initialized classic predicate unifier [2018-11-14 19:05:58,588 INFO L82 PathProgramCache]: Analyzing trace with hash 2085655191, now seen corresponding path program 1 times [2018-11-14 19:05:58,588 INFO L223 ckRefinementStrategy]: Switched to mode SMTINTERPOL_TREE_INTERPOLANTS [2018-11-14 19:05:58,588 INFO L69 tionRefinementEngine]: Using refinement strategy CamelRefinementStrategy [2018-11-14 19:05:58,589 INFO L119 rtionOrderModulation]: Craig_TreeInterpolation forces the order to NOT_INCREMENTALLY [2018-11-14 19:05:58,590 INFO L103 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2018-11-14 19:05:58,590 INFO L119 rtionOrderModulation]: Craig_TreeInterpolation forces the order to NOT_INCREMENTALLY [2018-11-14 19:05:58,613 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2018-11-14 19:05:58,829 INFO L256 TraceCheckUtils]: 0: Hoare triple {1932#true} call ULTIMATE.init(); {1932#true} is VALID [2018-11-14 19:05:58,830 INFO L273 TraceCheckUtils]: 1: Hoare triple {1932#true} #NULL.base, #NULL.offset := 0, 0;#valid := #valid[0 := 0];~init~0 := 1;call ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset := #Ultimate.alloc(100);call write~unchecked~int(0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 0, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 4, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 8, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 12, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 16, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 20, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 24, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 28, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 32, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 36, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 40, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 44, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 48, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 52, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 56, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 60, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 64, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 68, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 72, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 76, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 80, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 84, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 88, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 92, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 96, 4);call write~unchecked~int(0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 0, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 4, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 8, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 12, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 16, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 20, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 24, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 28, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 32, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 36, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 40, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 44, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 48, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 52, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 56, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 60, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 64, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 68, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 72, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 76, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 80, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 84, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 88, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 92, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 96, 4); {1932#true} is VALID [2018-11-14 19:05:58,830 INFO L273 TraceCheckUtils]: 2: Hoare triple {1932#true} assume true; {1932#true} is VALID [2018-11-14 19:05:58,831 INFO L268 TraceCheckUtils]: 3: Hoare quadruple {1932#true} {1932#true} #654#return; {1932#true} is VALID [2018-11-14 19:05:58,831 INFO L256 TraceCheckUtils]: 4: Hoare triple {1932#true} call #t~ret138 := main(); {1932#true} is VALID [2018-11-14 19:05:58,831 INFO L273 TraceCheckUtils]: 5: Hoare triple {1932#true} havoc ~s~0.base, ~s~0.offset;havoc ~tmp~2;call #t~malloc3.base, #t~malloc3.offset := #Ultimate.alloc(248);~s~0.base, ~s~0.offset := #t~malloc3.base, #t~malloc3.offset;call #t~malloc4.base, #t~malloc4.offset := #Ultimate.alloc(899);call write~$Pointer$(#t~malloc4.base, #t~malloc4.offset, ~s~0.base, ~s~0.offset + 84, 4);call #t~malloc5.base, #t~malloc5.offset := #Ultimate.alloc(232);call write~$Pointer$(#t~malloc5.base, #t~malloc5.offset, ~s~0.base, ~s~0.offset + 204, 4);call #t~malloc6.base, #t~malloc6.offset := #Ultimate.alloc(200);call write~$Pointer$(#t~malloc6.base, #t~malloc6.offset, ~s~0.base, ~s~0.offset + 176, 4);call write~int(8464, ~s~0.base, ~s~0.offset + 52, 4); {1932#true} is VALID [2018-11-14 19:05:58,831 INFO L256 TraceCheckUtils]: 6: Hoare triple {1932#true} call #t~ret7 := ssl3_accept(~s~0.base, ~s~0.offset); {1932#true} is VALID [2018-11-14 19:05:58,846 INFO L273 TraceCheckUtils]: 7: Hoare triple {1932#true} ~s.base, ~s.offset := #in~s.base, #in~s.offset;havoc ~buf~0.base, ~buf~0.offset;havoc ~l~0;havoc ~Time~0;havoc ~tmp~3;havoc ~cb~0.base, ~cb~0.offset;havoc ~num1~0;havoc ~ret~0;havoc ~new_state~0;havoc ~state~0;havoc ~skip~0;havoc ~got_new_session~0;assume -2147483648 <= #t~nondet8 && #t~nondet8 <= 2147483647;~tmp___1~0 := #t~nondet8;havoc #t~nondet8;assume -2147483648 <= #t~nondet9 && #t~nondet9 <= 2147483647;~tmp___2~0 := #t~nondet9;havoc #t~nondet9;assume -2147483648 <= #t~nondet10 && #t~nondet10 <= 2147483647;~tmp___3~0 := #t~nondet10;havoc #t~nondet10;assume -2147483648 <= #t~nondet11 && #t~nondet11 <= 2147483647;~tmp___4~0 := #t~nondet11;havoc #t~nondet11;assume -2147483648 <= #t~nondet12 && #t~nondet12 <= 2147483647;~tmp___5~0 := #t~nondet12;havoc #t~nondet12;assume -2147483648 <= #t~nondet13 && #t~nondet13 <= 2147483647;~tmp___6~0 := #t~nondet13;havoc #t~nondet13;havoc ~tmp___7~0;assume -2147483648 <= #t~nondet14 && #t~nondet14 <= 2147483647;~tmp___8~0 := #t~nondet14;havoc #t~nondet14;assume -2147483648 <= #t~nondet15 && #t~nondet15 <= 2147483647;~tmp___9~0 := #t~nondet15;havoc #t~nondet15;assume -2147483648 <= #t~nondet16 && #t~nondet16 <= 2147483647;~tmp___10~0 := #t~nondet16;havoc #t~nondet16;havoc ~blastFlag~0;~blastFlag~0 := 0;assume -2147483648 <= #t~nondet17 && #t~nondet17 <= 2147483647;call write~int(#t~nondet17, ~s.base, ~s.offset + 92, 4);havoc #t~nondet17;call write~int(8464, ~s.base, ~s.offset + 52, 4);assume -2147483648 <= #t~nondet18 && #t~nondet18 <= 2147483647;~tmp~3 := #t~nondet18;havoc #t~nondet18;~Time~0 := ~tmp~3;~cb~0.base, ~cb~0.offset := 0, 0;~ret~0 := -1;~skip~0 := 0;~got_new_session~0 := 0;call #t~mem19.base, #t~mem19.offset := read~$Pointer$(~s.base, ~s.offset + 192, 4); {1934#(= (select (store (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 28) (+ (select (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 28)) 1)) (+ ssl3_accept_~s.offset 52)) 8464)} is VALID [2018-11-14 19:05:58,847 INFO L273 TraceCheckUtils]: 8: Hoare triple {1934#(= (select (store (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 28) (+ (select (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 28)) 1)) (+ ssl3_accept_~s.offset 52)) 8464)} assume (#t~mem19.base + #t~mem19.offset) % 4294967296 != 0;havoc #t~mem19.base, #t~mem19.offset;call #t~mem20.base, #t~mem20.offset := read~$Pointer$(~s.base, ~s.offset + 192, 4);~cb~0.base, ~cb~0.offset := #t~mem20.base, #t~mem20.offset;havoc #t~mem20.base, #t~mem20.offset; {1934#(= (select (store (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 28) (+ (select (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 28)) 1)) (+ ssl3_accept_~s.offset 52)) 8464)} is VALID [2018-11-14 19:05:58,849 INFO L273 TraceCheckUtils]: 9: Hoare triple {1934#(= (select (store (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 28) (+ (select (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 28)) 1)) (+ ssl3_accept_~s.offset 52)) 8464)} call #t~mem21 := read~int(~s.base, ~s.offset + 28, 4);call write~int(#t~mem21 + 1, ~s.base, ~s.offset + 28, 4);havoc #t~mem21; {1934#(= (select (store (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 28) (+ (select (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 28)) 1)) (+ ssl3_accept_~s.offset 52)) 8464)} is VALID [2018-11-14 19:05:58,853 INFO L273 TraceCheckUtils]: 10: Hoare triple {1934#(= (select (store (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 28) (+ (select (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 28)) 1)) (+ ssl3_accept_~s.offset 52)) 8464)} assume !(~bitwiseAnd(~tmp___1~0, 12288) != 0); {1934#(= (select (store (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 28) (+ (select (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 28)) 1)) (+ ssl3_accept_~s.offset 52)) 8464)} is VALID [2018-11-14 19:05:58,853 INFO L273 TraceCheckUtils]: 11: Hoare triple {1934#(= (select (store (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 28) (+ (select (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 28)) 1)) (+ ssl3_accept_~s.offset 52)) 8464)} call #t~mem22.base, #t~mem22.offset := read~$Pointer$(~s.base, ~s.offset + 136, 4); {1934#(= (select (store (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 28) (+ (select (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 28)) 1)) (+ ssl3_accept_~s.offset 52)) 8464)} is VALID [2018-11-14 19:05:58,856 INFO L273 TraceCheckUtils]: 12: Hoare triple {1934#(= (select (store (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 28) (+ (select (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 28)) 1)) (+ ssl3_accept_~s.offset 52)) 8464)} assume !((#t~mem22.base + #t~mem22.offset) % 4294967296 == 0);havoc #t~mem22.base, #t~mem22.offset; {1934#(= (select (store (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 28) (+ (select (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 28)) 1)) (+ ssl3_accept_~s.offset 52)) 8464)} is VALID [2018-11-14 19:05:58,856 INFO L273 TraceCheckUtils]: 13: Hoare triple {1934#(= (select (store (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 28) (+ (select (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 28)) 1)) (+ ssl3_accept_~s.offset 52)) 8464)} assume true; {1934#(= (select (store (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 28) (+ (select (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 28)) 1)) (+ ssl3_accept_~s.offset 52)) 8464)} is VALID [2018-11-14 19:05:58,856 INFO L273 TraceCheckUtils]: 14: Hoare triple {1934#(= (select (store (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 28) (+ (select (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 28)) 1)) (+ ssl3_accept_~s.offset 52)) 8464)} assume !false; {1934#(= (select (store (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 28) (+ (select (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 28)) 1)) (+ ssl3_accept_~s.offset 52)) 8464)} is VALID [2018-11-14 19:05:58,857 INFO L273 TraceCheckUtils]: 15: Hoare triple {1934#(= (select (store (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 28) (+ (select (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 28)) 1)) (+ ssl3_accept_~s.offset 52)) 8464)} call #t~mem23 := read~int(~s.base, ~s.offset + 52, 4);~state~0 := #t~mem23;havoc #t~mem23;call #t~mem24 := read~int(~s.base, ~s.offset + 52, 4); {1935#(= |ssl3_accept_#t~mem24| 8464)} is VALID [2018-11-14 19:05:58,858 INFO L273 TraceCheckUtils]: 16: Hoare triple {1935#(= |ssl3_accept_#t~mem24| 8464)} assume #t~mem24 == 12292;havoc #t~mem24; {1933#false} is VALID [2018-11-14 19:05:58,858 INFO L273 TraceCheckUtils]: 17: Hoare triple {1933#false} call write~int(1, ~s.base, ~s.offset + 40, 4); {1933#false} is VALID [2018-11-14 19:05:58,858 INFO L273 TraceCheckUtils]: 18: Hoare triple {1933#false} call write~int(1, ~s.base, ~s.offset + 36, 4); {1933#false} is VALID [2018-11-14 19:05:58,858 INFO L273 TraceCheckUtils]: 19: Hoare triple {1933#false} assume (~cb~0.base + ~cb~0.offset) % 4294967296 != 0; {1933#false} is VALID [2018-11-14 19:05:58,858 INFO L273 TraceCheckUtils]: 20: Hoare triple {1933#false} call #t~mem59 := read~int(~s.base, ~s.offset + 0, 4); {1933#false} is VALID [2018-11-14 19:05:58,859 INFO L273 TraceCheckUtils]: 21: Hoare triple {1933#false} assume !(#t~mem59 / 256 != 3);havoc #t~mem59;call write~int(8192, ~s.base, ~s.offset + 4, 4);call #t~mem60.base, #t~mem60.offset := read~$Pointer$(~s.base, ~s.offset + 60, 4); {1933#false} is VALID [2018-11-14 19:05:58,859 INFO L273 TraceCheckUtils]: 22: Hoare triple {1933#false} assume !((#t~mem60.base + #t~mem60.offset) % 4294967296 == 0);havoc #t~mem60.base, #t~mem60.offset; {1933#false} is VALID [2018-11-14 19:05:58,859 INFO L273 TraceCheckUtils]: 23: Hoare triple {1933#false} assume !(~tmp___4~0 == 0);call write~int(0, ~s.base, ~s.offset + 64, 4);call #t~mem62 := read~int(~s.base, ~s.offset + 52, 4); {1933#false} is VALID [2018-11-14 19:05:58,859 INFO L273 TraceCheckUtils]: 24: Hoare triple {1933#false} assume !(#t~mem62 != 12292);havoc #t~mem62;call #t~mem65.base, #t~mem65.offset := read~$Pointer$(~s.base, ~s.offset + 204, 4);call #t~mem66 := read~int(#t~mem65.base, #t~mem65.offset + 60 + 16, 4);call write~int(#t~mem66 + 1, #t~mem65.base, #t~mem65.offset + 60 + 16, 4);havoc #t~mem66;havoc #t~mem65.base, #t~mem65.offset;call write~int(8480, ~s.base, ~s.offset + 52, 4); {1933#false} is VALID [2018-11-14 19:05:58,859 INFO L273 TraceCheckUtils]: 25: Hoare triple {1933#false} call #t~mem127.base, #t~mem127.offset := read~$Pointer$(~s.base, ~s.offset + 84, 4);call #t~mem128 := read~int(#t~mem127.base, #t~mem127.offset + 604 + 244, 4); {1933#false} is VALID [2018-11-14 19:05:58,860 INFO L273 TraceCheckUtils]: 26: Hoare triple {1933#false} assume !(#t~mem128 == 0);havoc #t~mem127.base, #t~mem127.offset;havoc #t~mem128; {1933#false} is VALID [2018-11-14 19:05:58,860 INFO L273 TraceCheckUtils]: 27: Hoare triple {1933#false} ~skip~0 := 0; {1933#false} is VALID [2018-11-14 19:05:58,860 INFO L273 TraceCheckUtils]: 28: Hoare triple {1933#false} assume true; {1933#false} is VALID [2018-11-14 19:05:58,860 INFO L273 TraceCheckUtils]: 29: Hoare triple {1933#false} assume !false; {1933#false} is VALID [2018-11-14 19:05:58,861 INFO L273 TraceCheckUtils]: 30: Hoare triple {1933#false} call #t~mem23 := read~int(~s.base, ~s.offset + 52, 4);~state~0 := #t~mem23;havoc #t~mem23;call #t~mem24 := read~int(~s.base, ~s.offset + 52, 4); {1933#false} is VALID [2018-11-14 19:05:58,861 INFO L273 TraceCheckUtils]: 31: Hoare triple {1933#false} assume !(#t~mem24 == 12292);havoc #t~mem24;call #t~mem25 := read~int(~s.base, ~s.offset + 52, 4); {1933#false} is VALID [2018-11-14 19:05:58,862 INFO L273 TraceCheckUtils]: 32: Hoare triple {1933#false} assume !(#t~mem25 == 16384);havoc #t~mem25;call #t~mem26 := read~int(~s.base, ~s.offset + 52, 4); {1933#false} is VALID [2018-11-14 19:05:58,862 INFO L273 TraceCheckUtils]: 33: Hoare triple {1933#false} assume !(#t~mem26 == 8192);havoc #t~mem26;call #t~mem27 := read~int(~s.base, ~s.offset + 52, 4); {1933#false} is VALID [2018-11-14 19:05:58,862 INFO L273 TraceCheckUtils]: 34: Hoare triple {1933#false} assume !(#t~mem27 == 24576);havoc #t~mem27;call #t~mem28 := read~int(~s.base, ~s.offset + 52, 4); {1933#false} is VALID [2018-11-14 19:05:58,862 INFO L273 TraceCheckUtils]: 35: Hoare triple {1933#false} assume !(#t~mem28 == 8195);havoc #t~mem28;call #t~mem29 := read~int(~s.base, ~s.offset + 52, 4); {1933#false} is VALID [2018-11-14 19:05:58,862 INFO L273 TraceCheckUtils]: 36: Hoare triple {1933#false} assume !(#t~mem29 == 8480);havoc #t~mem29;call #t~mem30 := read~int(~s.base, ~s.offset + 52, 4); {1933#false} is VALID [2018-11-14 19:05:58,863 INFO L273 TraceCheckUtils]: 37: Hoare triple {1933#false} assume !(#t~mem30 == 8481);havoc #t~mem30;call #t~mem31 := read~int(~s.base, ~s.offset + 52, 4); {1933#false} is VALID [2018-11-14 19:05:58,863 INFO L273 TraceCheckUtils]: 38: Hoare triple {1933#false} assume !(#t~mem31 == 8482);havoc #t~mem31;call #t~mem32 := read~int(~s.base, ~s.offset + 52, 4); {1933#false} is VALID [2018-11-14 19:05:58,863 INFO L273 TraceCheckUtils]: 39: Hoare triple {1933#false} assume !(#t~mem32 == 8464);havoc #t~mem32;call #t~mem33 := read~int(~s.base, ~s.offset + 52, 4); {1933#false} is VALID [2018-11-14 19:05:58,863 INFO L273 TraceCheckUtils]: 40: Hoare triple {1933#false} assume !(#t~mem33 == 8465);havoc #t~mem33;call #t~mem34 := read~int(~s.base, ~s.offset + 52, 4); {1933#false} is VALID [2018-11-14 19:05:58,863 INFO L273 TraceCheckUtils]: 41: Hoare triple {1933#false} assume !(#t~mem34 == 8466);havoc #t~mem34;call #t~mem35 := read~int(~s.base, ~s.offset + 52, 4); {1933#false} is VALID [2018-11-14 19:05:58,864 INFO L273 TraceCheckUtils]: 42: Hoare triple {1933#false} assume !(#t~mem35 == 8496);havoc #t~mem35;call #t~mem36 := read~int(~s.base, ~s.offset + 52, 4); {1933#false} is VALID [2018-11-14 19:05:58,864 INFO L273 TraceCheckUtils]: 43: Hoare triple {1933#false} assume !(#t~mem36 == 8497);havoc #t~mem36;call #t~mem37 := read~int(~s.base, ~s.offset + 52, 4); {1933#false} is VALID [2018-11-14 19:05:58,864 INFO L273 TraceCheckUtils]: 44: Hoare triple {1933#false} assume !(#t~mem37 == 8512);havoc #t~mem37;call #t~mem38 := read~int(~s.base, ~s.offset + 52, 4); {1933#false} is VALID [2018-11-14 19:05:58,864 INFO L273 TraceCheckUtils]: 45: Hoare triple {1933#false} assume !(#t~mem38 == 8513);havoc #t~mem38;call #t~mem39 := read~int(~s.base, ~s.offset + 52, 4); {1933#false} is VALID [2018-11-14 19:05:58,864 INFO L273 TraceCheckUtils]: 46: Hoare triple {1933#false} assume !(#t~mem39 == 8528);havoc #t~mem39;call #t~mem40 := read~int(~s.base, ~s.offset + 52, 4); {1933#false} is VALID [2018-11-14 19:05:58,865 INFO L273 TraceCheckUtils]: 47: Hoare triple {1933#false} assume !(#t~mem40 == 8529);havoc #t~mem40;call #t~mem41 := read~int(~s.base, ~s.offset + 52, 4); {1933#false} is VALID [2018-11-14 19:05:58,865 INFO L273 TraceCheckUtils]: 48: Hoare triple {1933#false} assume !(#t~mem41 == 8544);havoc #t~mem41;call #t~mem42 := read~int(~s.base, ~s.offset + 52, 4); {1933#false} is VALID [2018-11-14 19:05:58,865 INFO L273 TraceCheckUtils]: 49: Hoare triple {1933#false} assume !(#t~mem42 == 8545);havoc #t~mem42;call #t~mem43 := read~int(~s.base, ~s.offset + 52, 4); {1933#false} is VALID [2018-11-14 19:05:58,865 INFO L273 TraceCheckUtils]: 50: Hoare triple {1933#false} assume !(#t~mem43 == 8560);havoc #t~mem43;call #t~mem44 := read~int(~s.base, ~s.offset + 52, 4); {1933#false} is VALID [2018-11-14 19:05:58,865 INFO L273 TraceCheckUtils]: 51: Hoare triple {1933#false} assume !(#t~mem44 == 8561);havoc #t~mem44;call #t~mem45 := read~int(~s.base, ~s.offset + 52, 4); {1933#false} is VALID [2018-11-14 19:05:58,865 INFO L273 TraceCheckUtils]: 52: Hoare triple {1933#false} assume !(#t~mem45 == 8448);havoc #t~mem45;call #t~mem46 := read~int(~s.base, ~s.offset + 52, 4); {1933#false} is VALID [2018-11-14 19:05:58,866 INFO L273 TraceCheckUtils]: 53: Hoare triple {1933#false} assume !(#t~mem46 == 8576);havoc #t~mem46;call #t~mem47 := read~int(~s.base, ~s.offset + 52, 4); {1933#false} is VALID [2018-11-14 19:05:58,866 INFO L273 TraceCheckUtils]: 54: Hoare triple {1933#false} assume !(#t~mem47 == 8577);havoc #t~mem47;call #t~mem48 := read~int(~s.base, ~s.offset + 52, 4); {1933#false} is VALID [2018-11-14 19:05:58,866 INFO L273 TraceCheckUtils]: 55: Hoare triple {1933#false} assume !(#t~mem48 == 8592);havoc #t~mem48;call #t~mem49 := read~int(~s.base, ~s.offset + 52, 4); {1933#false} is VALID [2018-11-14 19:05:58,866 INFO L273 TraceCheckUtils]: 56: Hoare triple {1933#false} assume !(#t~mem49 == 8593);havoc #t~mem49;call #t~mem50 := read~int(~s.base, ~s.offset + 52, 4); {1933#false} is VALID [2018-11-14 19:05:58,866 INFO L273 TraceCheckUtils]: 57: Hoare triple {1933#false} assume !(#t~mem50 == 8608);havoc #t~mem50;call #t~mem51 := read~int(~s.base, ~s.offset + 52, 4); {1933#false} is VALID [2018-11-14 19:05:58,866 INFO L273 TraceCheckUtils]: 58: Hoare triple {1933#false} assume !(#t~mem51 == 8609);havoc #t~mem51;call #t~mem52 := read~int(~s.base, ~s.offset + 52, 4); {1933#false} is VALID [2018-11-14 19:05:58,867 INFO L273 TraceCheckUtils]: 59: Hoare triple {1933#false} assume !(#t~mem52 == 8640);havoc #t~mem52;call #t~mem53 := read~int(~s.base, ~s.offset + 52, 4); {1933#false} is VALID [2018-11-14 19:05:58,867 INFO L273 TraceCheckUtils]: 60: Hoare triple {1933#false} assume !(#t~mem53 == 8641);havoc #t~mem53;call #t~mem54 := read~int(~s.base, ~s.offset + 52, 4); {1933#false} is VALID [2018-11-14 19:05:58,867 INFO L273 TraceCheckUtils]: 61: Hoare triple {1933#false} assume !(#t~mem54 == 8656);havoc #t~mem54;call #t~mem55 := read~int(~s.base, ~s.offset + 52, 4); {1933#false} is VALID [2018-11-14 19:05:58,867 INFO L273 TraceCheckUtils]: 62: Hoare triple {1933#false} assume !(#t~mem55 == 8657);havoc #t~mem55;call #t~mem56 := read~int(~s.base, ~s.offset + 52, 4); {1933#false} is VALID [2018-11-14 19:05:58,867 INFO L273 TraceCheckUtils]: 63: Hoare triple {1933#false} assume #t~mem56 == 8672;havoc #t~mem56; {1933#false} is VALID [2018-11-14 19:05:58,868 INFO L273 TraceCheckUtils]: 64: Hoare triple {1933#false} assume -2147483648 <= #t~nondet121 && #t~nondet121 <= 2147483647;~ret~0 := #t~nondet121;havoc #t~nondet121; {1933#false} is VALID [2018-11-14 19:05:58,868 INFO L273 TraceCheckUtils]: 65: Hoare triple {1933#false} assume ~blastFlag~0 == 4; {1933#false} is VALID [2018-11-14 19:05:58,868 INFO L273 TraceCheckUtils]: 66: Hoare triple {1933#false} assume !false; {1933#false} is VALID [2018-11-14 19:05:58,872 INFO L134 CoverageAnalysis]: Checked inductivity of 4 backedges. 4 proven. 0 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2018-11-14 19:05:58,872 INFO L312 seRefinementStrategy]: Constructing automaton from 1 perfect and 0 imperfect interpolant sequences. [2018-11-14 19:05:58,872 INFO L327 seRefinementStrategy]: Number of different interpolants: perfect sequences [4] imperfect sequences [] total 4 [2018-11-14 19:05:58,873 INFO L78 Accepts]: Start accepts. Automaton has 4 states. Word has length 67 [2018-11-14 19:05:58,873 INFO L84 Accepts]: Finished accepts. word is accepted. [2018-11-14 19:05:58,873 INFO L86 InductivityCheck]: Starting indutivity check of a Floyd-Hoare automaton with 4 states. [2018-11-14 19:05:58,948 INFO L119 InductivityCheck]: Floyd-Hoare automaton has 67 edges. 67 inductive. 0 not inductive. 0 times theorem prover too weak to decide inductivity. [2018-11-14 19:05:58,948 INFO L459 AbstractCegarLoop]: Interpolant automaton has 4 states [2018-11-14 19:05:58,949 INFO L142 InterpolantAutomaton]: Constructing interpolant automaton starting with 4 interpolants. [2018-11-14 19:05:58,949 INFO L144 InterpolantAutomaton]: CoverageRelationStatistics Valid=5, Invalid=7, Unknown=0, NotChecked=0, Total=12 [2018-11-14 19:05:58,949 INFO L87 Difference]: Start difference. First operand 149 states and 223 transitions. Second operand 4 states. [2018-11-14 19:06:00,686 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2018-11-14 19:06:00,686 INFO L93 Difference]: Finished difference Result 288 states and 430 transitions. [2018-11-14 19:06:00,686 INFO L142 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 4 states. [2018-11-14 19:06:00,688 INFO L78 Accepts]: Start accepts. Automaton has 4 states. Word has length 67 [2018-11-14 19:06:00,688 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2018-11-14 19:06:00,688 INFO L82 GeneralOperation]: Start removeUnreachable. Operand 4 states. [2018-11-14 19:06:00,693 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 4 states to 4 states and 430 transitions. [2018-11-14 19:06:00,694 INFO L82 GeneralOperation]: Start removeUnreachable. Operand 4 states. [2018-11-14 19:06:00,699 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 4 states to 4 states and 430 transitions. [2018-11-14 19:06:00,699 INFO L86 InductivityCheck]: Starting indutivity check of a Floyd-Hoare automaton with 4 states and 430 transitions. [2018-11-14 19:06:01,389 INFO L119 InductivityCheck]: Floyd-Hoare automaton has 430 edges. 430 inductive. 0 not inductive. 0 times theorem prover too weak to decide inductivity. [2018-11-14 19:06:01,394 INFO L225 Difference]: With dead ends: 288 [2018-11-14 19:06:01,394 INFO L226 Difference]: Without dead ends: 165 [2018-11-14 19:06:01,395 INFO L604 BasicCegarLoop]: 0 DeclaredPredicates, 7 GetRequests, 2 SyntacticMatches, 2 SemanticMatches, 3 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 0 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=9, Invalid=11, Unknown=0, NotChecked=0, Total=20 [2018-11-14 19:06:01,396 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 165 states. [2018-11-14 19:06:01,458 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 165 to 149. [2018-11-14 19:06:01,458 INFO L214 AbstractMinimizeNwa]: Start testing correctness of minimizeSevpa [2018-11-14 19:06:01,458 INFO L82 GeneralOperation]: Start isEquivalent. First operand 165 states. Second operand 149 states. [2018-11-14 19:06:01,458 INFO L74 IsIncluded]: Start isIncluded. First operand 165 states. Second operand 149 states. [2018-11-14 19:06:01,458 INFO L87 Difference]: Start difference. First operand 165 states. Second operand 149 states. [2018-11-14 19:06:01,463 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2018-11-14 19:06:01,463 INFO L93 Difference]: Finished difference Result 165 states and 242 transitions. [2018-11-14 19:06:01,464 INFO L276 IsEmpty]: Start isEmpty. Operand 165 states and 242 transitions. [2018-11-14 19:06:01,464 INFO L282 IsEmpty]: Finished isEmpty. No accepting run. [2018-11-14 19:06:01,464 INFO L83 IsIncluded]: Finished isIncluded. Language is included [2018-11-14 19:06:01,464 INFO L74 IsIncluded]: Start isIncluded. First operand 149 states. Second operand 165 states. [2018-11-14 19:06:01,465 INFO L87 Difference]: Start difference. First operand 149 states. Second operand 165 states. [2018-11-14 19:06:01,470 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2018-11-14 19:06:01,471 INFO L93 Difference]: Finished difference Result 165 states and 242 transitions. [2018-11-14 19:06:01,471 INFO L276 IsEmpty]: Start isEmpty. Operand 165 states and 242 transitions. [2018-11-14 19:06:01,471 INFO L282 IsEmpty]: Finished isEmpty. No accepting run. [2018-11-14 19:06:01,472 INFO L83 IsIncluded]: Finished isIncluded. Language is included [2018-11-14 19:06:01,472 INFO L88 GeneralOperation]: Finished isEquivalent. [2018-11-14 19:06:01,472 INFO L221 AbstractMinimizeNwa]: Finished testing correctness of minimizeSevpa [2018-11-14 19:06:01,472 INFO L82 GeneralOperation]: Start removeUnreachable. Operand 149 states. [2018-11-14 19:06:01,477 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 149 states to 149 states and 222 transitions. [2018-11-14 19:06:01,477 INFO L78 Accepts]: Start accepts. Automaton has 149 states and 222 transitions. Word has length 67 [2018-11-14 19:06:01,477 INFO L84 Accepts]: Finished accepts. word is rejected. [2018-11-14 19:06:01,478 INFO L480 AbstractCegarLoop]: Abstraction has 149 states and 222 transitions. [2018-11-14 19:06:01,478 INFO L481 AbstractCegarLoop]: Interpolant automaton has 4 states. [2018-11-14 19:06:01,478 INFO L276 IsEmpty]: Start isEmpty. Operand 149 states and 222 transitions. [2018-11-14 19:06:01,479 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 68 [2018-11-14 19:06:01,479 INFO L367 BasicCegarLoop]: Found error trace [2018-11-14 19:06:01,479 INFO L375 BasicCegarLoop]: trace histogram [2, 2, 2, 2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2018-11-14 19:06:01,479 INFO L423 AbstractCegarLoop]: === Iteration 4 === [ssl3_acceptErr0ASSERT_VIOLATIONERROR_FUNCTION]=== [2018-11-14 19:06:01,480 INFO L141 PredicateUnifier]: Initialized classic predicate unifier [2018-11-14 19:06:01,480 INFO L82 PathProgramCache]: Analyzing trace with hash -2000781949, now seen corresponding path program 1 times [2018-11-14 19:06:01,480 INFO L223 ckRefinementStrategy]: Switched to mode SMTINTERPOL_TREE_INTERPOLANTS [2018-11-14 19:06:01,480 INFO L69 tionRefinementEngine]: Using refinement strategy CamelRefinementStrategy [2018-11-14 19:06:01,481 INFO L119 rtionOrderModulation]: Craig_TreeInterpolation forces the order to NOT_INCREMENTALLY [2018-11-14 19:06:01,481 INFO L103 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2018-11-14 19:06:01,481 INFO L119 rtionOrderModulation]: Craig_TreeInterpolation forces the order to NOT_INCREMENTALLY [2018-11-14 19:06:01,502 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2018-11-14 19:06:02,022 INFO L256 TraceCheckUtils]: 0: Hoare triple {2794#true} call ULTIMATE.init(); {2794#true} is VALID [2018-11-14 19:06:02,023 INFO L273 TraceCheckUtils]: 1: Hoare triple {2794#true} #NULL.base, #NULL.offset := 0, 0;#valid := #valid[0 := 0];~init~0 := 1;call ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset := #Ultimate.alloc(100);call write~unchecked~int(0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 0, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 4, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 8, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 12, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 16, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 20, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 24, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 28, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 32, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 36, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 40, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 44, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 48, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 52, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 56, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 60, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 64, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 68, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 72, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 76, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 80, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 84, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 88, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 92, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 96, 4);call write~unchecked~int(0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 0, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 4, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 8, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 12, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 16, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 20, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 24, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 28, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 32, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 36, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 40, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 44, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 48, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 52, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 56, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 60, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 64, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 68, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 72, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 76, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 80, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 84, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 88, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 92, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 96, 4); {2794#true} is VALID [2018-11-14 19:06:02,023 INFO L273 TraceCheckUtils]: 2: Hoare triple {2794#true} assume true; {2794#true} is VALID [2018-11-14 19:06:02,023 INFO L268 TraceCheckUtils]: 3: Hoare quadruple {2794#true} {2794#true} #654#return; {2794#true} is VALID [2018-11-14 19:06:02,023 INFO L256 TraceCheckUtils]: 4: Hoare triple {2794#true} call #t~ret138 := main(); {2794#true} is VALID [2018-11-14 19:06:02,023 INFO L273 TraceCheckUtils]: 5: Hoare triple {2794#true} havoc ~s~0.base, ~s~0.offset;havoc ~tmp~2;call #t~malloc3.base, #t~malloc3.offset := #Ultimate.alloc(248);~s~0.base, ~s~0.offset := #t~malloc3.base, #t~malloc3.offset;call #t~malloc4.base, #t~malloc4.offset := #Ultimate.alloc(899);call write~$Pointer$(#t~malloc4.base, #t~malloc4.offset, ~s~0.base, ~s~0.offset + 84, 4);call #t~malloc5.base, #t~malloc5.offset := #Ultimate.alloc(232);call write~$Pointer$(#t~malloc5.base, #t~malloc5.offset, ~s~0.base, ~s~0.offset + 204, 4);call #t~malloc6.base, #t~malloc6.offset := #Ultimate.alloc(200);call write~$Pointer$(#t~malloc6.base, #t~malloc6.offset, ~s~0.base, ~s~0.offset + 176, 4);call write~int(8464, ~s~0.base, ~s~0.offset + 52, 4); {2794#true} is VALID [2018-11-14 19:06:02,024 INFO L256 TraceCheckUtils]: 6: Hoare triple {2794#true} call #t~ret7 := ssl3_accept(~s~0.base, ~s~0.offset); {2794#true} is VALID [2018-11-14 19:06:02,037 INFO L273 TraceCheckUtils]: 7: Hoare triple {2794#true} ~s.base, ~s.offset := #in~s.base, #in~s.offset;havoc ~buf~0.base, ~buf~0.offset;havoc ~l~0;havoc ~Time~0;havoc ~tmp~3;havoc ~cb~0.base, ~cb~0.offset;havoc ~num1~0;havoc ~ret~0;havoc ~new_state~0;havoc ~state~0;havoc ~skip~0;havoc ~got_new_session~0;assume -2147483648 <= #t~nondet8 && #t~nondet8 <= 2147483647;~tmp___1~0 := #t~nondet8;havoc #t~nondet8;assume -2147483648 <= #t~nondet9 && #t~nondet9 <= 2147483647;~tmp___2~0 := #t~nondet9;havoc #t~nondet9;assume -2147483648 <= #t~nondet10 && #t~nondet10 <= 2147483647;~tmp___3~0 := #t~nondet10;havoc #t~nondet10;assume -2147483648 <= #t~nondet11 && #t~nondet11 <= 2147483647;~tmp___4~0 := #t~nondet11;havoc #t~nondet11;assume -2147483648 <= #t~nondet12 && #t~nondet12 <= 2147483647;~tmp___5~0 := #t~nondet12;havoc #t~nondet12;assume -2147483648 <= #t~nondet13 && #t~nondet13 <= 2147483647;~tmp___6~0 := #t~nondet13;havoc #t~nondet13;havoc ~tmp___7~0;assume -2147483648 <= #t~nondet14 && #t~nondet14 <= 2147483647;~tmp___8~0 := #t~nondet14;havoc #t~nondet14;assume -2147483648 <= #t~nondet15 && #t~nondet15 <= 2147483647;~tmp___9~0 := #t~nondet15;havoc #t~nondet15;assume -2147483648 <= #t~nondet16 && #t~nondet16 <= 2147483647;~tmp___10~0 := #t~nondet16;havoc #t~nondet16;havoc ~blastFlag~0;~blastFlag~0 := 0;assume -2147483648 <= #t~nondet17 && #t~nondet17 <= 2147483647;call write~int(#t~nondet17, ~s.base, ~s.offset + 92, 4);havoc #t~nondet17;call write~int(8464, ~s.base, ~s.offset + 52, 4);assume -2147483648 <= #t~nondet18 && #t~nondet18 <= 2147483647;~tmp~3 := #t~nondet18;havoc #t~nondet18;~Time~0 := ~tmp~3;~cb~0.base, ~cb~0.offset := 0, 0;~ret~0 := -1;~skip~0 := 0;~got_new_session~0 := 0;call #t~mem19.base, #t~mem19.offset := read~$Pointer$(~s.base, ~s.offset + 192, 4); {2796#(= (select (store (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 28) (+ (select (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 28)) 1)) (+ ssl3_accept_~s.offset 52)) 8464)} is VALID [2018-11-14 19:06:02,049 INFO L273 TraceCheckUtils]: 8: Hoare triple {2796#(= (select (store (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 28) (+ (select (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 28)) 1)) (+ ssl3_accept_~s.offset 52)) 8464)} assume (#t~mem19.base + #t~mem19.offset) % 4294967296 != 0;havoc #t~mem19.base, #t~mem19.offset;call #t~mem20.base, #t~mem20.offset := read~$Pointer$(~s.base, ~s.offset + 192, 4);~cb~0.base, ~cb~0.offset := #t~mem20.base, #t~mem20.offset;havoc #t~mem20.base, #t~mem20.offset; {2796#(= (select (store (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 28) (+ (select (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 28)) 1)) (+ ssl3_accept_~s.offset 52)) 8464)} is VALID [2018-11-14 19:06:02,050 INFO L273 TraceCheckUtils]: 9: Hoare triple {2796#(= (select (store (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 28) (+ (select (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 28)) 1)) (+ ssl3_accept_~s.offset 52)) 8464)} call #t~mem21 := read~int(~s.base, ~s.offset + 28, 4);call write~int(#t~mem21 + 1, ~s.base, ~s.offset + 28, 4);havoc #t~mem21; {2796#(= (select (store (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 28) (+ (select (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 28)) 1)) (+ ssl3_accept_~s.offset 52)) 8464)} is VALID [2018-11-14 19:06:02,054 INFO L273 TraceCheckUtils]: 10: Hoare triple {2796#(= (select (store (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 28) (+ (select (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 28)) 1)) (+ ssl3_accept_~s.offset 52)) 8464)} assume !(~bitwiseAnd(~tmp___1~0, 12288) != 0); {2796#(= (select (store (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 28) (+ (select (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 28)) 1)) (+ ssl3_accept_~s.offset 52)) 8464)} is VALID [2018-11-14 19:06:02,054 INFO L273 TraceCheckUtils]: 11: Hoare triple {2796#(= (select (store (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 28) (+ (select (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 28)) 1)) (+ ssl3_accept_~s.offset 52)) 8464)} call #t~mem22.base, #t~mem22.offset := read~$Pointer$(~s.base, ~s.offset + 136, 4); {2796#(= (select (store (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 28) (+ (select (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 28)) 1)) (+ ssl3_accept_~s.offset 52)) 8464)} is VALID [2018-11-14 19:06:02,056 INFO L273 TraceCheckUtils]: 12: Hoare triple {2796#(= (select (store (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 28) (+ (select (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 28)) 1)) (+ ssl3_accept_~s.offset 52)) 8464)} assume !((#t~mem22.base + #t~mem22.offset) % 4294967296 == 0);havoc #t~mem22.base, #t~mem22.offset; {2796#(= (select (store (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 28) (+ (select (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 28)) 1)) (+ ssl3_accept_~s.offset 52)) 8464)} is VALID [2018-11-14 19:06:02,056 INFO L273 TraceCheckUtils]: 13: Hoare triple {2796#(= (select (store (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 28) (+ (select (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 28)) 1)) (+ ssl3_accept_~s.offset 52)) 8464)} assume true; {2796#(= (select (store (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 28) (+ (select (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 28)) 1)) (+ ssl3_accept_~s.offset 52)) 8464)} is VALID [2018-11-14 19:06:02,056 INFO L273 TraceCheckUtils]: 14: Hoare triple {2796#(= (select (store (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 28) (+ (select (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 28)) 1)) (+ ssl3_accept_~s.offset 52)) 8464)} assume !false; {2796#(= (select (store (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 28) (+ (select (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 28)) 1)) (+ ssl3_accept_~s.offset 52)) 8464)} is VALID [2018-11-14 19:06:02,057 INFO L273 TraceCheckUtils]: 15: Hoare triple {2796#(= (select (store (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 28) (+ (select (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 28)) 1)) (+ ssl3_accept_~s.offset 52)) 8464)} call #t~mem23 := read~int(~s.base, ~s.offset + 52, 4);~state~0 := #t~mem23;havoc #t~mem23;call #t~mem24 := read~int(~s.base, ~s.offset + 52, 4); {2796#(= (select (store (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 28) (+ (select (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 28)) 1)) (+ ssl3_accept_~s.offset 52)) 8464)} is VALID [2018-11-14 19:06:02,057 INFO L273 TraceCheckUtils]: 16: Hoare triple {2796#(= (select (store (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 28) (+ (select (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 28)) 1)) (+ ssl3_accept_~s.offset 52)) 8464)} assume !(#t~mem24 == 12292);havoc #t~mem24;call #t~mem25 := read~int(~s.base, ~s.offset + 52, 4); {2797#(= |ssl3_accept_#t~mem25| 8464)} is VALID [2018-11-14 19:06:02,061 INFO L273 TraceCheckUtils]: 17: Hoare triple {2797#(= |ssl3_accept_#t~mem25| 8464)} assume #t~mem25 == 16384;havoc #t~mem25; {2795#false} is VALID [2018-11-14 19:06:02,061 INFO L273 TraceCheckUtils]: 18: Hoare triple {2795#false} call write~int(1, ~s.base, ~s.offset + 36, 4); {2795#false} is VALID [2018-11-14 19:06:02,061 INFO L273 TraceCheckUtils]: 19: Hoare triple {2795#false} assume (~cb~0.base + ~cb~0.offset) % 4294967296 != 0; {2795#false} is VALID [2018-11-14 19:06:02,061 INFO L273 TraceCheckUtils]: 20: Hoare triple {2795#false} call #t~mem59 := read~int(~s.base, ~s.offset + 0, 4); {2795#false} is VALID [2018-11-14 19:06:02,062 INFO L273 TraceCheckUtils]: 21: Hoare triple {2795#false} assume !(#t~mem59 / 256 != 3);havoc #t~mem59;call write~int(8192, ~s.base, ~s.offset + 4, 4);call #t~mem60.base, #t~mem60.offset := read~$Pointer$(~s.base, ~s.offset + 60, 4); {2795#false} is VALID [2018-11-14 19:06:02,062 INFO L273 TraceCheckUtils]: 22: Hoare triple {2795#false} assume !((#t~mem60.base + #t~mem60.offset) % 4294967296 == 0);havoc #t~mem60.base, #t~mem60.offset; {2795#false} is VALID [2018-11-14 19:06:02,062 INFO L273 TraceCheckUtils]: 23: Hoare triple {2795#false} assume !(~tmp___4~0 == 0);call write~int(0, ~s.base, ~s.offset + 64, 4);call #t~mem62 := read~int(~s.base, ~s.offset + 52, 4); {2795#false} is VALID [2018-11-14 19:06:02,062 INFO L273 TraceCheckUtils]: 24: Hoare triple {2795#false} assume !(#t~mem62 != 12292);havoc #t~mem62;call #t~mem65.base, #t~mem65.offset := read~$Pointer$(~s.base, ~s.offset + 204, 4);call #t~mem66 := read~int(#t~mem65.base, #t~mem65.offset + 60 + 16, 4);call write~int(#t~mem66 + 1, #t~mem65.base, #t~mem65.offset + 60 + 16, 4);havoc #t~mem66;havoc #t~mem65.base, #t~mem65.offset;call write~int(8480, ~s.base, ~s.offset + 52, 4); {2795#false} is VALID [2018-11-14 19:06:02,062 INFO L273 TraceCheckUtils]: 25: Hoare triple {2795#false} call #t~mem127.base, #t~mem127.offset := read~$Pointer$(~s.base, ~s.offset + 84, 4);call #t~mem128 := read~int(#t~mem127.base, #t~mem127.offset + 604 + 244, 4); {2795#false} is VALID [2018-11-14 19:06:02,063 INFO L273 TraceCheckUtils]: 26: Hoare triple {2795#false} assume !(#t~mem128 == 0);havoc #t~mem127.base, #t~mem127.offset;havoc #t~mem128; {2795#false} is VALID [2018-11-14 19:06:02,063 INFO L273 TraceCheckUtils]: 27: Hoare triple {2795#false} ~skip~0 := 0; {2795#false} is VALID [2018-11-14 19:06:02,063 INFO L273 TraceCheckUtils]: 28: Hoare triple {2795#false} assume true; {2795#false} is VALID [2018-11-14 19:06:02,063 INFO L273 TraceCheckUtils]: 29: Hoare triple {2795#false} assume !false; {2795#false} is VALID [2018-11-14 19:06:02,064 INFO L273 TraceCheckUtils]: 30: Hoare triple {2795#false} call #t~mem23 := read~int(~s.base, ~s.offset + 52, 4);~state~0 := #t~mem23;havoc #t~mem23;call #t~mem24 := read~int(~s.base, ~s.offset + 52, 4); {2795#false} is VALID [2018-11-14 19:06:02,064 INFO L273 TraceCheckUtils]: 31: Hoare triple {2795#false} assume !(#t~mem24 == 12292);havoc #t~mem24;call #t~mem25 := read~int(~s.base, ~s.offset + 52, 4); {2795#false} is VALID [2018-11-14 19:06:02,064 INFO L273 TraceCheckUtils]: 32: Hoare triple {2795#false} assume !(#t~mem25 == 16384);havoc #t~mem25;call #t~mem26 := read~int(~s.base, ~s.offset + 52, 4); {2795#false} is VALID [2018-11-14 19:06:02,064 INFO L273 TraceCheckUtils]: 33: Hoare triple {2795#false} assume !(#t~mem26 == 8192);havoc #t~mem26;call #t~mem27 := read~int(~s.base, ~s.offset + 52, 4); {2795#false} is VALID [2018-11-14 19:06:02,064 INFO L273 TraceCheckUtils]: 34: Hoare triple {2795#false} assume !(#t~mem27 == 24576);havoc #t~mem27;call #t~mem28 := read~int(~s.base, ~s.offset + 52, 4); {2795#false} is VALID [2018-11-14 19:06:02,065 INFO L273 TraceCheckUtils]: 35: Hoare triple {2795#false} assume !(#t~mem28 == 8195);havoc #t~mem28;call #t~mem29 := read~int(~s.base, ~s.offset + 52, 4); {2795#false} is VALID [2018-11-14 19:06:02,065 INFO L273 TraceCheckUtils]: 36: Hoare triple {2795#false} assume !(#t~mem29 == 8480);havoc #t~mem29;call #t~mem30 := read~int(~s.base, ~s.offset + 52, 4); {2795#false} is VALID [2018-11-14 19:06:02,065 INFO L273 TraceCheckUtils]: 37: Hoare triple {2795#false} assume !(#t~mem30 == 8481);havoc #t~mem30;call #t~mem31 := read~int(~s.base, ~s.offset + 52, 4); {2795#false} is VALID [2018-11-14 19:06:02,065 INFO L273 TraceCheckUtils]: 38: Hoare triple {2795#false} assume !(#t~mem31 == 8482);havoc #t~mem31;call #t~mem32 := read~int(~s.base, ~s.offset + 52, 4); {2795#false} is VALID [2018-11-14 19:06:02,066 INFO L273 TraceCheckUtils]: 39: Hoare triple {2795#false} assume !(#t~mem32 == 8464);havoc #t~mem32;call #t~mem33 := read~int(~s.base, ~s.offset + 52, 4); {2795#false} is VALID [2018-11-14 19:06:02,066 INFO L273 TraceCheckUtils]: 40: Hoare triple {2795#false} assume !(#t~mem33 == 8465);havoc #t~mem33;call #t~mem34 := read~int(~s.base, ~s.offset + 52, 4); {2795#false} is VALID [2018-11-14 19:06:02,066 INFO L273 TraceCheckUtils]: 41: Hoare triple {2795#false} assume !(#t~mem34 == 8466);havoc #t~mem34;call #t~mem35 := read~int(~s.base, ~s.offset + 52, 4); {2795#false} is VALID [2018-11-14 19:06:02,066 INFO L273 TraceCheckUtils]: 42: Hoare triple {2795#false} assume !(#t~mem35 == 8496);havoc #t~mem35;call #t~mem36 := read~int(~s.base, ~s.offset + 52, 4); {2795#false} is VALID [2018-11-14 19:06:02,066 INFO L273 TraceCheckUtils]: 43: Hoare triple {2795#false} assume !(#t~mem36 == 8497);havoc #t~mem36;call #t~mem37 := read~int(~s.base, ~s.offset + 52, 4); {2795#false} is VALID [2018-11-14 19:06:02,067 INFO L273 TraceCheckUtils]: 44: Hoare triple {2795#false} assume !(#t~mem37 == 8512);havoc #t~mem37;call #t~mem38 := read~int(~s.base, ~s.offset + 52, 4); {2795#false} is VALID [2018-11-14 19:06:02,067 INFO L273 TraceCheckUtils]: 45: Hoare triple {2795#false} assume !(#t~mem38 == 8513);havoc #t~mem38;call #t~mem39 := read~int(~s.base, ~s.offset + 52, 4); {2795#false} is VALID [2018-11-14 19:06:02,067 INFO L273 TraceCheckUtils]: 46: Hoare triple {2795#false} assume !(#t~mem39 == 8528);havoc #t~mem39;call #t~mem40 := read~int(~s.base, ~s.offset + 52, 4); {2795#false} is VALID [2018-11-14 19:06:02,068 INFO L273 TraceCheckUtils]: 47: Hoare triple {2795#false} assume !(#t~mem40 == 8529);havoc #t~mem40;call #t~mem41 := read~int(~s.base, ~s.offset + 52, 4); {2795#false} is VALID [2018-11-14 19:06:02,068 INFO L273 TraceCheckUtils]: 48: Hoare triple {2795#false} assume !(#t~mem41 == 8544);havoc #t~mem41;call #t~mem42 := read~int(~s.base, ~s.offset + 52, 4); {2795#false} is VALID [2018-11-14 19:06:02,068 INFO L273 TraceCheckUtils]: 49: Hoare triple {2795#false} assume !(#t~mem42 == 8545);havoc #t~mem42;call #t~mem43 := read~int(~s.base, ~s.offset + 52, 4); {2795#false} is VALID [2018-11-14 19:06:02,068 INFO L273 TraceCheckUtils]: 50: Hoare triple {2795#false} assume !(#t~mem43 == 8560);havoc #t~mem43;call #t~mem44 := read~int(~s.base, ~s.offset + 52, 4); {2795#false} is VALID [2018-11-14 19:06:02,068 INFO L273 TraceCheckUtils]: 51: Hoare triple {2795#false} assume !(#t~mem44 == 8561);havoc #t~mem44;call #t~mem45 := read~int(~s.base, ~s.offset + 52, 4); {2795#false} is VALID [2018-11-14 19:06:02,069 INFO L273 TraceCheckUtils]: 52: Hoare triple {2795#false} assume !(#t~mem45 == 8448);havoc #t~mem45;call #t~mem46 := read~int(~s.base, ~s.offset + 52, 4); {2795#false} is VALID [2018-11-14 19:06:02,069 INFO L273 TraceCheckUtils]: 53: Hoare triple {2795#false} assume !(#t~mem46 == 8576);havoc #t~mem46;call #t~mem47 := read~int(~s.base, ~s.offset + 52, 4); {2795#false} is VALID [2018-11-14 19:06:02,069 INFO L273 TraceCheckUtils]: 54: Hoare triple {2795#false} assume !(#t~mem47 == 8577);havoc #t~mem47;call #t~mem48 := read~int(~s.base, ~s.offset + 52, 4); {2795#false} is VALID [2018-11-14 19:06:02,069 INFO L273 TraceCheckUtils]: 55: Hoare triple {2795#false} assume !(#t~mem48 == 8592);havoc #t~mem48;call #t~mem49 := read~int(~s.base, ~s.offset + 52, 4); {2795#false} is VALID [2018-11-14 19:06:02,070 INFO L273 TraceCheckUtils]: 56: Hoare triple {2795#false} assume !(#t~mem49 == 8593);havoc #t~mem49;call #t~mem50 := read~int(~s.base, ~s.offset + 52, 4); {2795#false} is VALID [2018-11-14 19:06:02,070 INFO L273 TraceCheckUtils]: 57: Hoare triple {2795#false} assume !(#t~mem50 == 8608);havoc #t~mem50;call #t~mem51 := read~int(~s.base, ~s.offset + 52, 4); {2795#false} is VALID [2018-11-14 19:06:02,070 INFO L273 TraceCheckUtils]: 58: Hoare triple {2795#false} assume !(#t~mem51 == 8609);havoc #t~mem51;call #t~mem52 := read~int(~s.base, ~s.offset + 52, 4); {2795#false} is VALID [2018-11-14 19:06:02,070 INFO L273 TraceCheckUtils]: 59: Hoare triple {2795#false} assume !(#t~mem52 == 8640);havoc #t~mem52;call #t~mem53 := read~int(~s.base, ~s.offset + 52, 4); {2795#false} is VALID [2018-11-14 19:06:02,070 INFO L273 TraceCheckUtils]: 60: Hoare triple {2795#false} assume !(#t~mem53 == 8641);havoc #t~mem53;call #t~mem54 := read~int(~s.base, ~s.offset + 52, 4); {2795#false} is VALID [2018-11-14 19:06:02,071 INFO L273 TraceCheckUtils]: 61: Hoare triple {2795#false} assume !(#t~mem54 == 8656);havoc #t~mem54;call #t~mem55 := read~int(~s.base, ~s.offset + 52, 4); {2795#false} is VALID [2018-11-14 19:06:02,071 INFO L273 TraceCheckUtils]: 62: Hoare triple {2795#false} assume !(#t~mem55 == 8657);havoc #t~mem55;call #t~mem56 := read~int(~s.base, ~s.offset + 52, 4); {2795#false} is VALID [2018-11-14 19:06:02,071 INFO L273 TraceCheckUtils]: 63: Hoare triple {2795#false} assume #t~mem56 == 8672;havoc #t~mem56; {2795#false} is VALID [2018-11-14 19:06:02,071 INFO L273 TraceCheckUtils]: 64: Hoare triple {2795#false} assume -2147483648 <= #t~nondet121 && #t~nondet121 <= 2147483647;~ret~0 := #t~nondet121;havoc #t~nondet121; {2795#false} is VALID [2018-11-14 19:06:02,071 INFO L273 TraceCheckUtils]: 65: Hoare triple {2795#false} assume ~blastFlag~0 == 4; {2795#false} is VALID [2018-11-14 19:06:02,071 INFO L273 TraceCheckUtils]: 66: Hoare triple {2795#false} assume !false; {2795#false} is VALID [2018-11-14 19:06:02,075 INFO L134 CoverageAnalysis]: Checked inductivity of 5 backedges. 5 proven. 0 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2018-11-14 19:06:02,076 INFO L312 seRefinementStrategy]: Constructing automaton from 1 perfect and 0 imperfect interpolant sequences. [2018-11-14 19:06:02,076 INFO L327 seRefinementStrategy]: Number of different interpolants: perfect sequences [4] imperfect sequences [] total 4 [2018-11-14 19:06:02,076 INFO L78 Accepts]: Start accepts. Automaton has 4 states. Word has length 67 [2018-11-14 19:06:02,076 INFO L84 Accepts]: Finished accepts. word is accepted. [2018-11-14 19:06:02,076 INFO L86 InductivityCheck]: Starting indutivity check of a Floyd-Hoare automaton with 4 states. [2018-11-14 19:06:02,150 INFO L119 InductivityCheck]: Floyd-Hoare automaton has 67 edges. 67 inductive. 0 not inductive. 0 times theorem prover too weak to decide inductivity. [2018-11-14 19:06:02,150 INFO L459 AbstractCegarLoop]: Interpolant automaton has 4 states [2018-11-14 19:06:02,150 INFO L142 InterpolantAutomaton]: Constructing interpolant automaton starting with 4 interpolants. [2018-11-14 19:06:02,150 INFO L144 InterpolantAutomaton]: CoverageRelationStatistics Valid=5, Invalid=7, Unknown=0, NotChecked=0, Total=12 [2018-11-14 19:06:02,151 INFO L87 Difference]: Start difference. First operand 149 states and 222 transitions. Second operand 4 states. [2018-11-14 19:06:03,607 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2018-11-14 19:06:03,608 INFO L93 Difference]: Finished difference Result 288 states and 429 transitions. [2018-11-14 19:06:03,608 INFO L142 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 4 states. [2018-11-14 19:06:03,608 INFO L78 Accepts]: Start accepts. Automaton has 4 states. Word has length 67 [2018-11-14 19:06:03,608 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2018-11-14 19:06:03,608 INFO L82 GeneralOperation]: Start removeUnreachable. Operand 4 states. [2018-11-14 19:06:03,613 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 4 states to 4 states and 429 transitions. [2018-11-14 19:06:03,614 INFO L82 GeneralOperation]: Start removeUnreachable. Operand 4 states. [2018-11-14 19:06:03,619 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 4 states to 4 states and 429 transitions. [2018-11-14 19:06:03,619 INFO L86 InductivityCheck]: Starting indutivity check of a Floyd-Hoare automaton with 4 states and 429 transitions. [2018-11-14 19:06:04,063 INFO L119 InductivityCheck]: Floyd-Hoare automaton has 429 edges. 429 inductive. 0 not inductive. 0 times theorem prover too weak to decide inductivity. [2018-11-14 19:06:04,068 INFO L225 Difference]: With dead ends: 288 [2018-11-14 19:06:04,068 INFO L226 Difference]: Without dead ends: 165 [2018-11-14 19:06:04,069 INFO L604 BasicCegarLoop]: 0 DeclaredPredicates, 7 GetRequests, 2 SyntacticMatches, 2 SemanticMatches, 3 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 0 ImplicationChecksByTransitivity, 0.2s TimeCoverageRelationStatistics Valid=9, Invalid=11, Unknown=0, NotChecked=0, Total=20 [2018-11-14 19:06:04,069 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 165 states. [2018-11-14 19:06:04,393 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 165 to 149. [2018-11-14 19:06:04,394 INFO L214 AbstractMinimizeNwa]: Start testing correctness of minimizeSevpa [2018-11-14 19:06:04,394 INFO L82 GeneralOperation]: Start isEquivalent. First operand 165 states. Second operand 149 states. [2018-11-14 19:06:04,394 INFO L74 IsIncluded]: Start isIncluded. First operand 165 states. Second operand 149 states. [2018-11-14 19:06:04,394 INFO L87 Difference]: Start difference. First operand 165 states. Second operand 149 states. [2018-11-14 19:06:04,399 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2018-11-14 19:06:04,400 INFO L93 Difference]: Finished difference Result 165 states and 241 transitions. [2018-11-14 19:06:04,400 INFO L276 IsEmpty]: Start isEmpty. Operand 165 states and 241 transitions. [2018-11-14 19:06:04,400 INFO L282 IsEmpty]: Finished isEmpty. No accepting run. [2018-11-14 19:06:04,401 INFO L83 IsIncluded]: Finished isIncluded. Language is included [2018-11-14 19:06:04,401 INFO L74 IsIncluded]: Start isIncluded. First operand 149 states. Second operand 165 states. [2018-11-14 19:06:04,401 INFO L87 Difference]: Start difference. First operand 149 states. Second operand 165 states. [2018-11-14 19:06:04,407 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2018-11-14 19:06:04,407 INFO L93 Difference]: Finished difference Result 165 states and 241 transitions. [2018-11-14 19:06:04,407 INFO L276 IsEmpty]: Start isEmpty. Operand 165 states and 241 transitions. [2018-11-14 19:06:04,408 INFO L282 IsEmpty]: Finished isEmpty. No accepting run. [2018-11-14 19:06:04,408 INFO L83 IsIncluded]: Finished isIncluded. Language is included [2018-11-14 19:06:04,408 INFO L88 GeneralOperation]: Finished isEquivalent. [2018-11-14 19:06:04,408 INFO L221 AbstractMinimizeNwa]: Finished testing correctness of minimizeSevpa [2018-11-14 19:06:04,408 INFO L82 GeneralOperation]: Start removeUnreachable. Operand 149 states. [2018-11-14 19:06:04,413 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 149 states to 149 states and 221 transitions. [2018-11-14 19:06:04,413 INFO L78 Accepts]: Start accepts. Automaton has 149 states and 221 transitions. Word has length 67 [2018-11-14 19:06:04,414 INFO L84 Accepts]: Finished accepts. word is rejected. [2018-11-14 19:06:04,414 INFO L480 AbstractCegarLoop]: Abstraction has 149 states and 221 transitions. [2018-11-14 19:06:04,414 INFO L481 AbstractCegarLoop]: Interpolant automaton has 4 states. [2018-11-14 19:06:04,414 INFO L276 IsEmpty]: Start isEmpty. Operand 149 states and 221 transitions. [2018-11-14 19:06:04,415 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 68 [2018-11-14 19:06:04,415 INFO L367 BasicCegarLoop]: Found error trace [2018-11-14 19:06:04,415 INFO L375 BasicCegarLoop]: trace histogram [2, 2, 2, 2, 2, 2, 2, 2, 2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2018-11-14 19:06:04,415 INFO L423 AbstractCegarLoop]: === Iteration 5 === [ssl3_acceptErr0ASSERT_VIOLATIONERROR_FUNCTION]=== [2018-11-14 19:06:04,416 INFO L141 PredicateUnifier]: Initialized classic predicate unifier [2018-11-14 19:06:04,416 INFO L82 PathProgramCache]: Analyzing trace with hash -2109108564, now seen corresponding path program 1 times [2018-11-14 19:06:04,416 INFO L223 ckRefinementStrategy]: Switched to mode SMTINTERPOL_TREE_INTERPOLANTS [2018-11-14 19:06:04,416 INFO L69 tionRefinementEngine]: Using refinement strategy CamelRefinementStrategy [2018-11-14 19:06:04,417 INFO L119 rtionOrderModulation]: Craig_TreeInterpolation forces the order to NOT_INCREMENTALLY [2018-11-14 19:06:04,418 INFO L103 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2018-11-14 19:06:04,418 INFO L119 rtionOrderModulation]: Craig_TreeInterpolation forces the order to NOT_INCREMENTALLY [2018-11-14 19:06:04,436 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2018-11-14 19:06:04,803 INFO L256 TraceCheckUtils]: 0: Hoare triple {3656#true} call ULTIMATE.init(); {3656#true} is VALID [2018-11-14 19:06:04,804 INFO L273 TraceCheckUtils]: 1: Hoare triple {3656#true} #NULL.base, #NULL.offset := 0, 0;#valid := #valid[0 := 0];~init~0 := 1;call ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset := #Ultimate.alloc(100);call write~unchecked~int(0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 0, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 4, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 8, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 12, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 16, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 20, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 24, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 28, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 32, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 36, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 40, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 44, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 48, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 52, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 56, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 60, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 64, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 68, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 72, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 76, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 80, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 84, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 88, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 92, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 96, 4);call write~unchecked~int(0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 0, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 4, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 8, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 12, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 16, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 20, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 24, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 28, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 32, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 36, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 40, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 44, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 48, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 52, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 56, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 60, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 64, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 68, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 72, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 76, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 80, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 84, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 88, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 92, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 96, 4); {3656#true} is VALID [2018-11-14 19:06:04,804 INFO L273 TraceCheckUtils]: 2: Hoare triple {3656#true} assume true; {3656#true} is VALID [2018-11-14 19:06:04,804 INFO L268 TraceCheckUtils]: 3: Hoare quadruple {3656#true} {3656#true} #654#return; {3656#true} is VALID [2018-11-14 19:06:04,805 INFO L256 TraceCheckUtils]: 4: Hoare triple {3656#true} call #t~ret138 := main(); {3656#true} is VALID [2018-11-14 19:06:04,805 INFO L273 TraceCheckUtils]: 5: Hoare triple {3656#true} havoc ~s~0.base, ~s~0.offset;havoc ~tmp~2;call #t~malloc3.base, #t~malloc3.offset := #Ultimate.alloc(248);~s~0.base, ~s~0.offset := #t~malloc3.base, #t~malloc3.offset;call #t~malloc4.base, #t~malloc4.offset := #Ultimate.alloc(899);call write~$Pointer$(#t~malloc4.base, #t~malloc4.offset, ~s~0.base, ~s~0.offset + 84, 4);call #t~malloc5.base, #t~malloc5.offset := #Ultimate.alloc(232);call write~$Pointer$(#t~malloc5.base, #t~malloc5.offset, ~s~0.base, ~s~0.offset + 204, 4);call #t~malloc6.base, #t~malloc6.offset := #Ultimate.alloc(200);call write~$Pointer$(#t~malloc6.base, #t~malloc6.offset, ~s~0.base, ~s~0.offset + 176, 4);call write~int(8464, ~s~0.base, ~s~0.offset + 52, 4); {3656#true} is VALID [2018-11-14 19:06:04,805 INFO L256 TraceCheckUtils]: 6: Hoare triple {3656#true} call #t~ret7 := ssl3_accept(~s~0.base, ~s~0.offset); {3656#true} is VALID [2018-11-14 19:06:04,807 INFO L273 TraceCheckUtils]: 7: Hoare triple {3656#true} ~s.base, ~s.offset := #in~s.base, #in~s.offset;havoc ~buf~0.base, ~buf~0.offset;havoc ~l~0;havoc ~Time~0;havoc ~tmp~3;havoc ~cb~0.base, ~cb~0.offset;havoc ~num1~0;havoc ~ret~0;havoc ~new_state~0;havoc ~state~0;havoc ~skip~0;havoc ~got_new_session~0;assume -2147483648 <= #t~nondet8 && #t~nondet8 <= 2147483647;~tmp___1~0 := #t~nondet8;havoc #t~nondet8;assume -2147483648 <= #t~nondet9 && #t~nondet9 <= 2147483647;~tmp___2~0 := #t~nondet9;havoc #t~nondet9;assume -2147483648 <= #t~nondet10 && #t~nondet10 <= 2147483647;~tmp___3~0 := #t~nondet10;havoc #t~nondet10;assume -2147483648 <= #t~nondet11 && #t~nondet11 <= 2147483647;~tmp___4~0 := #t~nondet11;havoc #t~nondet11;assume -2147483648 <= #t~nondet12 && #t~nondet12 <= 2147483647;~tmp___5~0 := #t~nondet12;havoc #t~nondet12;assume -2147483648 <= #t~nondet13 && #t~nondet13 <= 2147483647;~tmp___6~0 := #t~nondet13;havoc #t~nondet13;havoc ~tmp___7~0;assume -2147483648 <= #t~nondet14 && #t~nondet14 <= 2147483647;~tmp___8~0 := #t~nondet14;havoc #t~nondet14;assume -2147483648 <= #t~nondet15 && #t~nondet15 <= 2147483647;~tmp___9~0 := #t~nondet15;havoc #t~nondet15;assume -2147483648 <= #t~nondet16 && #t~nondet16 <= 2147483647;~tmp___10~0 := #t~nondet16;havoc #t~nondet16;havoc ~blastFlag~0;~blastFlag~0 := 0;assume -2147483648 <= #t~nondet17 && #t~nondet17 <= 2147483647;call write~int(#t~nondet17, ~s.base, ~s.offset + 92, 4);havoc #t~nondet17;call write~int(8464, ~s.base, ~s.offset + 52, 4);assume -2147483648 <= #t~nondet18 && #t~nondet18 <= 2147483647;~tmp~3 := #t~nondet18;havoc #t~nondet18;~Time~0 := ~tmp~3;~cb~0.base, ~cb~0.offset := 0, 0;~ret~0 := -1;~skip~0 := 0;~got_new_session~0 := 0;call #t~mem19.base, #t~mem19.offset := read~$Pointer$(~s.base, ~s.offset + 192, 4); {3658#(= (select (store (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 28) (+ (select (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 28)) 1)) (+ ssl3_accept_~s.offset 52)) 8464)} is VALID [2018-11-14 19:06:04,808 INFO L273 TraceCheckUtils]: 8: Hoare triple {3658#(= (select (store (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 28) (+ (select (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 28)) 1)) (+ ssl3_accept_~s.offset 52)) 8464)} assume (#t~mem19.base + #t~mem19.offset) % 4294967296 != 0;havoc #t~mem19.base, #t~mem19.offset;call #t~mem20.base, #t~mem20.offset := read~$Pointer$(~s.base, ~s.offset + 192, 4);~cb~0.base, ~cb~0.offset := #t~mem20.base, #t~mem20.offset;havoc #t~mem20.base, #t~mem20.offset; {3658#(= (select (store (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 28) (+ (select (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 28)) 1)) (+ ssl3_accept_~s.offset 52)) 8464)} is VALID [2018-11-14 19:06:04,808 INFO L273 TraceCheckUtils]: 9: Hoare triple {3658#(= (select (store (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 28) (+ (select (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 28)) 1)) (+ ssl3_accept_~s.offset 52)) 8464)} call #t~mem21 := read~int(~s.base, ~s.offset + 28, 4);call write~int(#t~mem21 + 1, ~s.base, ~s.offset + 28, 4);havoc #t~mem21; {3658#(= (select (store (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 28) (+ (select (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 28)) 1)) (+ ssl3_accept_~s.offset 52)) 8464)} is VALID [2018-11-14 19:06:04,809 INFO L273 TraceCheckUtils]: 10: Hoare triple {3658#(= (select (store (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 28) (+ (select (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 28)) 1)) (+ ssl3_accept_~s.offset 52)) 8464)} assume !(~bitwiseAnd(~tmp___1~0, 12288) != 0); {3658#(= (select (store (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 28) (+ (select (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 28)) 1)) (+ ssl3_accept_~s.offset 52)) 8464)} is VALID [2018-11-14 19:06:04,809 INFO L273 TraceCheckUtils]: 11: Hoare triple {3658#(= (select (store (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 28) (+ (select (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 28)) 1)) (+ ssl3_accept_~s.offset 52)) 8464)} call #t~mem22.base, #t~mem22.offset := read~$Pointer$(~s.base, ~s.offset + 136, 4); {3658#(= (select (store (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 28) (+ (select (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 28)) 1)) (+ ssl3_accept_~s.offset 52)) 8464)} is VALID [2018-11-14 19:06:04,810 INFO L273 TraceCheckUtils]: 12: Hoare triple {3658#(= (select (store (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 28) (+ (select (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 28)) 1)) (+ ssl3_accept_~s.offset 52)) 8464)} assume !((#t~mem22.base + #t~mem22.offset) % 4294967296 == 0);havoc #t~mem22.base, #t~mem22.offset; {3658#(= (select (store (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 28) (+ (select (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 28)) 1)) (+ ssl3_accept_~s.offset 52)) 8464)} is VALID [2018-11-14 19:06:04,810 INFO L273 TraceCheckUtils]: 13: Hoare triple {3658#(= (select (store (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 28) (+ (select (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 28)) 1)) (+ ssl3_accept_~s.offset 52)) 8464)} assume true; {3658#(= (select (store (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 28) (+ (select (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 28)) 1)) (+ ssl3_accept_~s.offset 52)) 8464)} is VALID [2018-11-14 19:06:04,810 INFO L273 TraceCheckUtils]: 14: Hoare triple {3658#(= (select (store (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 28) (+ (select (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 28)) 1)) (+ ssl3_accept_~s.offset 52)) 8464)} assume !false; {3658#(= (select (store (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 28) (+ (select (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 28)) 1)) (+ ssl3_accept_~s.offset 52)) 8464)} is VALID [2018-11-14 19:06:04,811 INFO L273 TraceCheckUtils]: 15: Hoare triple {3658#(= (select (store (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 28) (+ (select (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 28)) 1)) (+ ssl3_accept_~s.offset 52)) 8464)} call #t~mem23 := read~int(~s.base, ~s.offset + 52, 4);~state~0 := #t~mem23;havoc #t~mem23;call #t~mem24 := read~int(~s.base, ~s.offset + 52, 4); {3658#(= (select (store (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 28) (+ (select (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 28)) 1)) (+ ssl3_accept_~s.offset 52)) 8464)} is VALID [2018-11-14 19:06:04,811 INFO L273 TraceCheckUtils]: 16: Hoare triple {3658#(= (select (store (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 28) (+ (select (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 28)) 1)) (+ ssl3_accept_~s.offset 52)) 8464)} assume !(#t~mem24 == 12292);havoc #t~mem24;call #t~mem25 := read~int(~s.base, ~s.offset + 52, 4); {3658#(= (select (store (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 28) (+ (select (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 28)) 1)) (+ ssl3_accept_~s.offset 52)) 8464)} is VALID [2018-11-14 19:06:04,812 INFO L273 TraceCheckUtils]: 17: Hoare triple {3658#(= (select (store (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 28) (+ (select (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 28)) 1)) (+ ssl3_accept_~s.offset 52)) 8464)} assume !(#t~mem25 == 16384);havoc #t~mem25;call #t~mem26 := read~int(~s.base, ~s.offset + 52, 4); {3658#(= (select (store (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 28) (+ (select (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 28)) 1)) (+ ssl3_accept_~s.offset 52)) 8464)} is VALID [2018-11-14 19:06:04,812 INFO L273 TraceCheckUtils]: 18: Hoare triple {3658#(= (select (store (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 28) (+ (select (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 28)) 1)) (+ ssl3_accept_~s.offset 52)) 8464)} assume !(#t~mem26 == 8192);havoc #t~mem26;call #t~mem27 := read~int(~s.base, ~s.offset + 52, 4); {3658#(= (select (store (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 28) (+ (select (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 28)) 1)) (+ ssl3_accept_~s.offset 52)) 8464)} is VALID [2018-11-14 19:06:04,813 INFO L273 TraceCheckUtils]: 19: Hoare triple {3658#(= (select (store (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 28) (+ (select (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 28)) 1)) (+ ssl3_accept_~s.offset 52)) 8464)} assume !(#t~mem27 == 24576);havoc #t~mem27;call #t~mem28 := read~int(~s.base, ~s.offset + 52, 4); {3658#(= (select (store (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 28) (+ (select (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 28)) 1)) (+ ssl3_accept_~s.offset 52)) 8464)} is VALID [2018-11-14 19:06:04,814 INFO L273 TraceCheckUtils]: 20: Hoare triple {3658#(= (select (store (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 28) (+ (select (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 28)) 1)) (+ ssl3_accept_~s.offset 52)) 8464)} assume !(#t~mem28 == 8195);havoc #t~mem28;call #t~mem29 := read~int(~s.base, ~s.offset + 52, 4); {3658#(= (select (store (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 28) (+ (select (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 28)) 1)) (+ ssl3_accept_~s.offset 52)) 8464)} is VALID [2018-11-14 19:06:04,814 INFO L273 TraceCheckUtils]: 21: Hoare triple {3658#(= (select (store (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 28) (+ (select (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 28)) 1)) (+ ssl3_accept_~s.offset 52)) 8464)} assume !(#t~mem29 == 8480);havoc #t~mem29;call #t~mem30 := read~int(~s.base, ~s.offset + 52, 4); {3659#(= |ssl3_accept_#t~mem30| 8464)} is VALID [2018-11-14 19:06:04,815 INFO L273 TraceCheckUtils]: 22: Hoare triple {3659#(= |ssl3_accept_#t~mem30| 8464)} assume #t~mem30 == 8481;havoc #t~mem30; {3657#false} is VALID [2018-11-14 19:06:04,815 INFO L273 TraceCheckUtils]: 23: Hoare triple {3657#false} call write~int(0, ~s.base, ~s.offset + 48, 4);assume -2147483648 <= #t~nondet67 && #t~nondet67 <= 2147483647;~ret~0 := #t~nondet67;havoc #t~nondet67; {3657#false} is VALID [2018-11-14 19:06:04,816 INFO L273 TraceCheckUtils]: 24: Hoare triple {3657#false} assume !(~ret~0 <= 0);call #t~mem68.base, #t~mem68.offset := read~$Pointer$(~s.base, ~s.offset + 84, 4);call write~int(8482, #t~mem68.base, #t~mem68.offset + 604 + 240, 4);havoc #t~mem68.base, #t~mem68.offset;call write~int(8448, ~s.base, ~s.offset + 52, 4);call write~int(0, ~s.base, ~s.offset + 64, 4); {3657#false} is VALID [2018-11-14 19:06:04,816 INFO L273 TraceCheckUtils]: 25: Hoare triple {3657#false} call #t~mem127.base, #t~mem127.offset := read~$Pointer$(~s.base, ~s.offset + 84, 4);call #t~mem128 := read~int(#t~mem127.base, #t~mem127.offset + 604 + 244, 4); {3657#false} is VALID [2018-11-14 19:06:04,816 INFO L273 TraceCheckUtils]: 26: Hoare triple {3657#false} assume !(#t~mem128 == 0);havoc #t~mem127.base, #t~mem127.offset;havoc #t~mem128; {3657#false} is VALID [2018-11-14 19:06:04,817 INFO L273 TraceCheckUtils]: 27: Hoare triple {3657#false} ~skip~0 := 0; {3657#false} is VALID [2018-11-14 19:06:04,817 INFO L273 TraceCheckUtils]: 28: Hoare triple {3657#false} assume true; {3657#false} is VALID [2018-11-14 19:06:04,818 INFO L273 TraceCheckUtils]: 29: Hoare triple {3657#false} assume !false; {3657#false} is VALID [2018-11-14 19:06:04,818 INFO L273 TraceCheckUtils]: 30: Hoare triple {3657#false} call #t~mem23 := read~int(~s.base, ~s.offset + 52, 4);~state~0 := #t~mem23;havoc #t~mem23;call #t~mem24 := read~int(~s.base, ~s.offset + 52, 4); {3657#false} is VALID [2018-11-14 19:06:04,818 INFO L273 TraceCheckUtils]: 31: Hoare triple {3657#false} assume !(#t~mem24 == 12292);havoc #t~mem24;call #t~mem25 := read~int(~s.base, ~s.offset + 52, 4); {3657#false} is VALID [2018-11-14 19:06:04,819 INFO L273 TraceCheckUtils]: 32: Hoare triple {3657#false} assume !(#t~mem25 == 16384);havoc #t~mem25;call #t~mem26 := read~int(~s.base, ~s.offset + 52, 4); {3657#false} is VALID [2018-11-14 19:06:04,819 INFO L273 TraceCheckUtils]: 33: Hoare triple {3657#false} assume !(#t~mem26 == 8192);havoc #t~mem26;call #t~mem27 := read~int(~s.base, ~s.offset + 52, 4); {3657#false} is VALID [2018-11-14 19:06:04,819 INFO L273 TraceCheckUtils]: 34: Hoare triple {3657#false} assume !(#t~mem27 == 24576);havoc #t~mem27;call #t~mem28 := read~int(~s.base, ~s.offset + 52, 4); {3657#false} is VALID [2018-11-14 19:06:04,820 INFO L273 TraceCheckUtils]: 35: Hoare triple {3657#false} assume !(#t~mem28 == 8195);havoc #t~mem28;call #t~mem29 := read~int(~s.base, ~s.offset + 52, 4); {3657#false} is VALID [2018-11-14 19:06:04,820 INFO L273 TraceCheckUtils]: 36: Hoare triple {3657#false} assume !(#t~mem29 == 8480);havoc #t~mem29;call #t~mem30 := read~int(~s.base, ~s.offset + 52, 4); {3657#false} is VALID [2018-11-14 19:06:04,820 INFO L273 TraceCheckUtils]: 37: Hoare triple {3657#false} assume !(#t~mem30 == 8481);havoc #t~mem30;call #t~mem31 := read~int(~s.base, ~s.offset + 52, 4); {3657#false} is VALID [2018-11-14 19:06:04,820 INFO L273 TraceCheckUtils]: 38: Hoare triple {3657#false} assume !(#t~mem31 == 8482);havoc #t~mem31;call #t~mem32 := read~int(~s.base, ~s.offset + 52, 4); {3657#false} is VALID [2018-11-14 19:06:04,820 INFO L273 TraceCheckUtils]: 39: Hoare triple {3657#false} assume !(#t~mem32 == 8464);havoc #t~mem32;call #t~mem33 := read~int(~s.base, ~s.offset + 52, 4); {3657#false} is VALID [2018-11-14 19:06:04,820 INFO L273 TraceCheckUtils]: 40: Hoare triple {3657#false} assume !(#t~mem33 == 8465);havoc #t~mem33;call #t~mem34 := read~int(~s.base, ~s.offset + 52, 4); {3657#false} is VALID [2018-11-14 19:06:04,821 INFO L273 TraceCheckUtils]: 41: Hoare triple {3657#false} assume !(#t~mem34 == 8466);havoc #t~mem34;call #t~mem35 := read~int(~s.base, ~s.offset + 52, 4); {3657#false} is VALID [2018-11-14 19:06:04,821 INFO L273 TraceCheckUtils]: 42: Hoare triple {3657#false} assume !(#t~mem35 == 8496);havoc #t~mem35;call #t~mem36 := read~int(~s.base, ~s.offset + 52, 4); {3657#false} is VALID [2018-11-14 19:06:04,821 INFO L273 TraceCheckUtils]: 43: Hoare triple {3657#false} assume !(#t~mem36 == 8497);havoc #t~mem36;call #t~mem37 := read~int(~s.base, ~s.offset + 52, 4); {3657#false} is VALID [2018-11-14 19:06:04,821 INFO L273 TraceCheckUtils]: 44: Hoare triple {3657#false} assume !(#t~mem37 == 8512);havoc #t~mem37;call #t~mem38 := read~int(~s.base, ~s.offset + 52, 4); {3657#false} is VALID [2018-11-14 19:06:04,821 INFO L273 TraceCheckUtils]: 45: Hoare triple {3657#false} assume !(#t~mem38 == 8513);havoc #t~mem38;call #t~mem39 := read~int(~s.base, ~s.offset + 52, 4); {3657#false} is VALID [2018-11-14 19:06:04,821 INFO L273 TraceCheckUtils]: 46: Hoare triple {3657#false} assume !(#t~mem39 == 8528);havoc #t~mem39;call #t~mem40 := read~int(~s.base, ~s.offset + 52, 4); {3657#false} is VALID [2018-11-14 19:06:04,822 INFO L273 TraceCheckUtils]: 47: Hoare triple {3657#false} assume !(#t~mem40 == 8529);havoc #t~mem40;call #t~mem41 := read~int(~s.base, ~s.offset + 52, 4); {3657#false} is VALID [2018-11-14 19:06:04,822 INFO L273 TraceCheckUtils]: 48: Hoare triple {3657#false} assume !(#t~mem41 == 8544);havoc #t~mem41;call #t~mem42 := read~int(~s.base, ~s.offset + 52, 4); {3657#false} is VALID [2018-11-14 19:06:04,822 INFO L273 TraceCheckUtils]: 49: Hoare triple {3657#false} assume !(#t~mem42 == 8545);havoc #t~mem42;call #t~mem43 := read~int(~s.base, ~s.offset + 52, 4); {3657#false} is VALID [2018-11-14 19:06:04,822 INFO L273 TraceCheckUtils]: 50: Hoare triple {3657#false} assume !(#t~mem43 == 8560);havoc #t~mem43;call #t~mem44 := read~int(~s.base, ~s.offset + 52, 4); {3657#false} is VALID [2018-11-14 19:06:04,822 INFO L273 TraceCheckUtils]: 51: Hoare triple {3657#false} assume !(#t~mem44 == 8561);havoc #t~mem44;call #t~mem45 := read~int(~s.base, ~s.offset + 52, 4); {3657#false} is VALID [2018-11-14 19:06:04,823 INFO L273 TraceCheckUtils]: 52: Hoare triple {3657#false} assume !(#t~mem45 == 8448);havoc #t~mem45;call #t~mem46 := read~int(~s.base, ~s.offset + 52, 4); {3657#false} is VALID [2018-11-14 19:06:04,823 INFO L273 TraceCheckUtils]: 53: Hoare triple {3657#false} assume !(#t~mem46 == 8576);havoc #t~mem46;call #t~mem47 := read~int(~s.base, ~s.offset + 52, 4); {3657#false} is VALID [2018-11-14 19:06:04,823 INFO L273 TraceCheckUtils]: 54: Hoare triple {3657#false} assume !(#t~mem47 == 8577);havoc #t~mem47;call #t~mem48 := read~int(~s.base, ~s.offset + 52, 4); {3657#false} is VALID [2018-11-14 19:06:04,823 INFO L273 TraceCheckUtils]: 55: Hoare triple {3657#false} assume !(#t~mem48 == 8592);havoc #t~mem48;call #t~mem49 := read~int(~s.base, ~s.offset + 52, 4); {3657#false} is VALID [2018-11-14 19:06:04,823 INFO L273 TraceCheckUtils]: 56: Hoare triple {3657#false} assume !(#t~mem49 == 8593);havoc #t~mem49;call #t~mem50 := read~int(~s.base, ~s.offset + 52, 4); {3657#false} is VALID [2018-11-14 19:06:04,823 INFO L273 TraceCheckUtils]: 57: Hoare triple {3657#false} assume !(#t~mem50 == 8608);havoc #t~mem50;call #t~mem51 := read~int(~s.base, ~s.offset + 52, 4); {3657#false} is VALID [2018-11-14 19:06:04,824 INFO L273 TraceCheckUtils]: 58: Hoare triple {3657#false} assume !(#t~mem51 == 8609);havoc #t~mem51;call #t~mem52 := read~int(~s.base, ~s.offset + 52, 4); {3657#false} is VALID [2018-11-14 19:06:04,824 INFO L273 TraceCheckUtils]: 59: Hoare triple {3657#false} assume !(#t~mem52 == 8640);havoc #t~mem52;call #t~mem53 := read~int(~s.base, ~s.offset + 52, 4); {3657#false} is VALID [2018-11-14 19:06:04,824 INFO L273 TraceCheckUtils]: 60: Hoare triple {3657#false} assume !(#t~mem53 == 8641);havoc #t~mem53;call #t~mem54 := read~int(~s.base, ~s.offset + 52, 4); {3657#false} is VALID [2018-11-14 19:06:04,824 INFO L273 TraceCheckUtils]: 61: Hoare triple {3657#false} assume !(#t~mem54 == 8656);havoc #t~mem54;call #t~mem55 := read~int(~s.base, ~s.offset + 52, 4); {3657#false} is VALID [2018-11-14 19:06:04,825 INFO L273 TraceCheckUtils]: 62: Hoare triple {3657#false} assume !(#t~mem55 == 8657);havoc #t~mem55;call #t~mem56 := read~int(~s.base, ~s.offset + 52, 4); {3657#false} is VALID [2018-11-14 19:06:04,825 INFO L273 TraceCheckUtils]: 63: Hoare triple {3657#false} assume #t~mem56 == 8672;havoc #t~mem56; {3657#false} is VALID [2018-11-14 19:06:04,825 INFO L273 TraceCheckUtils]: 64: Hoare triple {3657#false} assume -2147483648 <= #t~nondet121 && #t~nondet121 <= 2147483647;~ret~0 := #t~nondet121;havoc #t~nondet121; {3657#false} is VALID [2018-11-14 19:06:04,825 INFO L273 TraceCheckUtils]: 65: Hoare triple {3657#false} assume ~blastFlag~0 == 4; {3657#false} is VALID [2018-11-14 19:06:04,825 INFO L273 TraceCheckUtils]: 66: Hoare triple {3657#false} assume !false; {3657#false} is VALID [2018-11-14 19:06:04,830 INFO L134 CoverageAnalysis]: Checked inductivity of 10 backedges. 10 proven. 0 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2018-11-14 19:06:04,830 INFO L312 seRefinementStrategy]: Constructing automaton from 1 perfect and 0 imperfect interpolant sequences. [2018-11-14 19:06:04,831 INFO L327 seRefinementStrategy]: Number of different interpolants: perfect sequences [4] imperfect sequences [] total 4 [2018-11-14 19:06:04,831 INFO L78 Accepts]: Start accepts. Automaton has 4 states. Word has length 67 [2018-11-14 19:06:04,831 INFO L84 Accepts]: Finished accepts. word is accepted. [2018-11-14 19:06:04,831 INFO L86 InductivityCheck]: Starting indutivity check of a Floyd-Hoare automaton with 4 states. [2018-11-14 19:06:04,907 INFO L119 InductivityCheck]: Floyd-Hoare automaton has 67 edges. 67 inductive. 0 not inductive. 0 times theorem prover too weak to decide inductivity. [2018-11-14 19:06:04,908 INFO L459 AbstractCegarLoop]: Interpolant automaton has 4 states [2018-11-14 19:06:04,908 INFO L142 InterpolantAutomaton]: Constructing interpolant automaton starting with 4 interpolants. [2018-11-14 19:06:04,908 INFO L144 InterpolantAutomaton]: CoverageRelationStatistics Valid=5, Invalid=7, Unknown=0, NotChecked=0, Total=12 [2018-11-14 19:06:04,909 INFO L87 Difference]: Start difference. First operand 149 states and 221 transitions. Second operand 4 states. [2018-11-14 19:06:06,341 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2018-11-14 19:06:06,341 INFO L93 Difference]: Finished difference Result 286 states and 426 transitions. [2018-11-14 19:06:06,341 INFO L142 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 4 states. [2018-11-14 19:06:06,341 INFO L78 Accepts]: Start accepts. Automaton has 4 states. Word has length 67 [2018-11-14 19:06:06,342 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2018-11-14 19:06:06,342 INFO L82 GeneralOperation]: Start removeUnreachable. Operand 4 states. [2018-11-14 19:06:06,347 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 4 states to 4 states and 426 transitions. [2018-11-14 19:06:06,347 INFO L82 GeneralOperation]: Start removeUnreachable. Operand 4 states. [2018-11-14 19:06:06,351 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 4 states to 4 states and 426 transitions. [2018-11-14 19:06:06,351 INFO L86 InductivityCheck]: Starting indutivity check of a Floyd-Hoare automaton with 4 states and 426 transitions. [2018-11-14 19:06:06,930 INFO L119 InductivityCheck]: Floyd-Hoare automaton has 426 edges. 426 inductive. 0 not inductive. 0 times theorem prover too weak to decide inductivity. [2018-11-14 19:06:06,934 INFO L225 Difference]: With dead ends: 286 [2018-11-14 19:06:06,934 INFO L226 Difference]: Without dead ends: 163 [2018-11-14 19:06:06,935 INFO L604 BasicCegarLoop]: 0 DeclaredPredicates, 7 GetRequests, 2 SyntacticMatches, 2 SemanticMatches, 3 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 0 ImplicationChecksByTransitivity, 0.2s TimeCoverageRelationStatistics Valid=9, Invalid=11, Unknown=0, NotChecked=0, Total=20 [2018-11-14 19:06:06,935 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 163 states. [2018-11-14 19:06:07,109 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 163 to 149. [2018-11-14 19:06:07,109 INFO L214 AbstractMinimizeNwa]: Start testing correctness of minimizeSevpa [2018-11-14 19:06:07,109 INFO L82 GeneralOperation]: Start isEquivalent. First operand 163 states. Second operand 149 states. [2018-11-14 19:06:07,109 INFO L74 IsIncluded]: Start isIncluded. First operand 163 states. Second operand 149 states. [2018-11-14 19:06:07,109 INFO L87 Difference]: Start difference. First operand 163 states. Second operand 149 states. [2018-11-14 19:06:07,113 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2018-11-14 19:06:07,113 INFO L93 Difference]: Finished difference Result 163 states and 238 transitions. [2018-11-14 19:06:07,113 INFO L276 IsEmpty]: Start isEmpty. Operand 163 states and 238 transitions. [2018-11-14 19:06:07,114 INFO L282 IsEmpty]: Finished isEmpty. No accepting run. [2018-11-14 19:06:07,114 INFO L83 IsIncluded]: Finished isIncluded. Language is included [2018-11-14 19:06:07,114 INFO L74 IsIncluded]: Start isIncluded. First operand 149 states. Second operand 163 states. [2018-11-14 19:06:07,114 INFO L87 Difference]: Start difference. First operand 149 states. Second operand 163 states. [2018-11-14 19:06:07,117 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2018-11-14 19:06:07,118 INFO L93 Difference]: Finished difference Result 163 states and 238 transitions. [2018-11-14 19:06:07,118 INFO L276 IsEmpty]: Start isEmpty. Operand 163 states and 238 transitions. [2018-11-14 19:06:07,118 INFO L282 IsEmpty]: Finished isEmpty. No accepting run. [2018-11-14 19:06:07,119 INFO L83 IsIncluded]: Finished isIncluded. Language is included [2018-11-14 19:06:07,119 INFO L88 GeneralOperation]: Finished isEquivalent. [2018-11-14 19:06:07,119 INFO L221 AbstractMinimizeNwa]: Finished testing correctness of minimizeSevpa [2018-11-14 19:06:07,119 INFO L82 GeneralOperation]: Start removeUnreachable. Operand 149 states. [2018-11-14 19:06:07,122 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 149 states to 149 states and 220 transitions. [2018-11-14 19:06:07,123 INFO L78 Accepts]: Start accepts. Automaton has 149 states and 220 transitions. Word has length 67 [2018-11-14 19:06:07,123 INFO L84 Accepts]: Finished accepts. word is rejected. [2018-11-14 19:06:07,123 INFO L480 AbstractCegarLoop]: Abstraction has 149 states and 220 transitions. [2018-11-14 19:06:07,123 INFO L481 AbstractCegarLoop]: Interpolant automaton has 4 states. [2018-11-14 19:06:07,123 INFO L276 IsEmpty]: Start isEmpty. Operand 149 states and 220 transitions. [2018-11-14 19:06:07,124 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 68 [2018-11-14 19:06:07,124 INFO L367 BasicCegarLoop]: Found error trace [2018-11-14 19:06:07,124 INFO L375 BasicCegarLoop]: trace histogram [2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2018-11-14 19:06:07,124 INFO L423 AbstractCegarLoop]: === Iteration 6 === [ssl3_acceptErr0ASSERT_VIOLATIONERROR_FUNCTION]=== [2018-11-14 19:06:07,125 INFO L141 PredicateUnifier]: Initialized classic predicate unifier [2018-11-14 19:06:07,125 INFO L82 PathProgramCache]: Analyzing trace with hash 526186699, now seen corresponding path program 1 times [2018-11-14 19:06:07,125 INFO L223 ckRefinementStrategy]: Switched to mode SMTINTERPOL_TREE_INTERPOLANTS [2018-11-14 19:06:07,125 INFO L69 tionRefinementEngine]: Using refinement strategy CamelRefinementStrategy [2018-11-14 19:06:07,126 INFO L119 rtionOrderModulation]: Craig_TreeInterpolation forces the order to NOT_INCREMENTALLY [2018-11-14 19:06:07,126 INFO L103 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2018-11-14 19:06:07,127 INFO L119 rtionOrderModulation]: Craig_TreeInterpolation forces the order to NOT_INCREMENTALLY [2018-11-14 19:06:07,142 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2018-11-14 19:06:07,267 INFO L256 TraceCheckUtils]: 0: Hoare triple {4511#true} call ULTIMATE.init(); {4511#true} is VALID [2018-11-14 19:06:07,267 INFO L273 TraceCheckUtils]: 1: Hoare triple {4511#true} #NULL.base, #NULL.offset := 0, 0;#valid := #valid[0 := 0];~init~0 := 1;call ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset := #Ultimate.alloc(100);call write~unchecked~int(0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 0, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 4, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 8, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 12, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 16, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 20, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 24, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 28, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 32, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 36, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 40, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 44, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 48, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 52, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 56, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 60, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 64, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 68, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 72, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 76, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 80, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 84, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 88, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 92, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 96, 4);call write~unchecked~int(0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 0, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 4, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 8, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 12, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 16, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 20, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 24, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 28, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 32, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 36, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 40, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 44, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 48, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 52, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 56, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 60, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 64, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 68, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 72, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 76, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 80, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 84, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 88, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 92, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 96, 4); {4511#true} is VALID [2018-11-14 19:06:07,267 INFO L273 TraceCheckUtils]: 2: Hoare triple {4511#true} assume true; {4511#true} is VALID [2018-11-14 19:06:07,267 INFO L268 TraceCheckUtils]: 3: Hoare quadruple {4511#true} {4511#true} #654#return; {4511#true} is VALID [2018-11-14 19:06:07,268 INFO L256 TraceCheckUtils]: 4: Hoare triple {4511#true} call #t~ret138 := main(); {4511#true} is VALID [2018-11-14 19:06:07,268 INFO L273 TraceCheckUtils]: 5: Hoare triple {4511#true} havoc ~s~0.base, ~s~0.offset;havoc ~tmp~2;call #t~malloc3.base, #t~malloc3.offset := #Ultimate.alloc(248);~s~0.base, ~s~0.offset := #t~malloc3.base, #t~malloc3.offset;call #t~malloc4.base, #t~malloc4.offset := #Ultimate.alloc(899);call write~$Pointer$(#t~malloc4.base, #t~malloc4.offset, ~s~0.base, ~s~0.offset + 84, 4);call #t~malloc5.base, #t~malloc5.offset := #Ultimate.alloc(232);call write~$Pointer$(#t~malloc5.base, #t~malloc5.offset, ~s~0.base, ~s~0.offset + 204, 4);call #t~malloc6.base, #t~malloc6.offset := #Ultimate.alloc(200);call write~$Pointer$(#t~malloc6.base, #t~malloc6.offset, ~s~0.base, ~s~0.offset + 176, 4);call write~int(8464, ~s~0.base, ~s~0.offset + 52, 4); {4511#true} is VALID [2018-11-14 19:06:07,268 INFO L256 TraceCheckUtils]: 6: Hoare triple {4511#true} call #t~ret7 := ssl3_accept(~s~0.base, ~s~0.offset); {4511#true} is VALID [2018-11-14 19:06:07,270 INFO L273 TraceCheckUtils]: 7: Hoare triple {4511#true} ~s.base, ~s.offset := #in~s.base, #in~s.offset;havoc ~buf~0.base, ~buf~0.offset;havoc ~l~0;havoc ~Time~0;havoc ~tmp~3;havoc ~cb~0.base, ~cb~0.offset;havoc ~num1~0;havoc ~ret~0;havoc ~new_state~0;havoc ~state~0;havoc ~skip~0;havoc ~got_new_session~0;assume -2147483648 <= #t~nondet8 && #t~nondet8 <= 2147483647;~tmp___1~0 := #t~nondet8;havoc #t~nondet8;assume -2147483648 <= #t~nondet9 && #t~nondet9 <= 2147483647;~tmp___2~0 := #t~nondet9;havoc #t~nondet9;assume -2147483648 <= #t~nondet10 && #t~nondet10 <= 2147483647;~tmp___3~0 := #t~nondet10;havoc #t~nondet10;assume -2147483648 <= #t~nondet11 && #t~nondet11 <= 2147483647;~tmp___4~0 := #t~nondet11;havoc #t~nondet11;assume -2147483648 <= #t~nondet12 && #t~nondet12 <= 2147483647;~tmp___5~0 := #t~nondet12;havoc #t~nondet12;assume -2147483648 <= #t~nondet13 && #t~nondet13 <= 2147483647;~tmp___6~0 := #t~nondet13;havoc #t~nondet13;havoc ~tmp___7~0;assume -2147483648 <= #t~nondet14 && #t~nondet14 <= 2147483647;~tmp___8~0 := #t~nondet14;havoc #t~nondet14;assume -2147483648 <= #t~nondet15 && #t~nondet15 <= 2147483647;~tmp___9~0 := #t~nondet15;havoc #t~nondet15;assume -2147483648 <= #t~nondet16 && #t~nondet16 <= 2147483647;~tmp___10~0 := #t~nondet16;havoc #t~nondet16;havoc ~blastFlag~0;~blastFlag~0 := 0;assume -2147483648 <= #t~nondet17 && #t~nondet17 <= 2147483647;call write~int(#t~nondet17, ~s.base, ~s.offset + 92, 4);havoc #t~nondet17;call write~int(8464, ~s.base, ~s.offset + 52, 4);assume -2147483648 <= #t~nondet18 && #t~nondet18 <= 2147483647;~tmp~3 := #t~nondet18;havoc #t~nondet18;~Time~0 := ~tmp~3;~cb~0.base, ~cb~0.offset := 0, 0;~ret~0 := -1;~skip~0 := 0;~got_new_session~0 := 0;call #t~mem19.base, #t~mem19.offset := read~$Pointer$(~s.base, ~s.offset + 192, 4); {4513#(= (select (store (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 28) (+ (select (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 28)) 1)) (+ ssl3_accept_~s.offset 52)) 8464)} is VALID [2018-11-14 19:06:07,271 INFO L273 TraceCheckUtils]: 8: Hoare triple {4513#(= (select (store (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 28) (+ (select (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 28)) 1)) (+ ssl3_accept_~s.offset 52)) 8464)} assume (#t~mem19.base + #t~mem19.offset) % 4294967296 != 0;havoc #t~mem19.base, #t~mem19.offset;call #t~mem20.base, #t~mem20.offset := read~$Pointer$(~s.base, ~s.offset + 192, 4);~cb~0.base, ~cb~0.offset := #t~mem20.base, #t~mem20.offset;havoc #t~mem20.base, #t~mem20.offset; {4513#(= (select (store (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 28) (+ (select (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 28)) 1)) (+ ssl3_accept_~s.offset 52)) 8464)} is VALID [2018-11-14 19:06:07,271 INFO L273 TraceCheckUtils]: 9: Hoare triple {4513#(= (select (store (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 28) (+ (select (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 28)) 1)) (+ ssl3_accept_~s.offset 52)) 8464)} call #t~mem21 := read~int(~s.base, ~s.offset + 28, 4);call write~int(#t~mem21 + 1, ~s.base, ~s.offset + 28, 4);havoc #t~mem21; {4513#(= (select (store (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 28) (+ (select (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 28)) 1)) (+ ssl3_accept_~s.offset 52)) 8464)} is VALID [2018-11-14 19:06:07,272 INFO L273 TraceCheckUtils]: 10: Hoare triple {4513#(= (select (store (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 28) (+ (select (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 28)) 1)) (+ ssl3_accept_~s.offset 52)) 8464)} assume !(~bitwiseAnd(~tmp___1~0, 12288) != 0); {4513#(= (select (store (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 28) (+ (select (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 28)) 1)) (+ ssl3_accept_~s.offset 52)) 8464)} is VALID [2018-11-14 19:06:07,272 INFO L273 TraceCheckUtils]: 11: Hoare triple {4513#(= (select (store (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 28) (+ (select (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 28)) 1)) (+ ssl3_accept_~s.offset 52)) 8464)} call #t~mem22.base, #t~mem22.offset := read~$Pointer$(~s.base, ~s.offset + 136, 4); {4513#(= (select (store (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 28) (+ (select (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 28)) 1)) (+ ssl3_accept_~s.offset 52)) 8464)} is VALID [2018-11-14 19:06:07,273 INFO L273 TraceCheckUtils]: 12: Hoare triple {4513#(= (select (store (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 28) (+ (select (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 28)) 1)) (+ ssl3_accept_~s.offset 52)) 8464)} assume !((#t~mem22.base + #t~mem22.offset) % 4294967296 == 0);havoc #t~mem22.base, #t~mem22.offset; {4513#(= (select (store (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 28) (+ (select (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 28)) 1)) (+ ssl3_accept_~s.offset 52)) 8464)} is VALID [2018-11-14 19:06:07,274 INFO L273 TraceCheckUtils]: 13: Hoare triple {4513#(= (select (store (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 28) (+ (select (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 28)) 1)) (+ ssl3_accept_~s.offset 52)) 8464)} assume true; {4513#(= (select (store (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 28) (+ (select (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 28)) 1)) (+ ssl3_accept_~s.offset 52)) 8464)} is VALID [2018-11-14 19:06:07,274 INFO L273 TraceCheckUtils]: 14: Hoare triple {4513#(= (select (store (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 28) (+ (select (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 28)) 1)) (+ ssl3_accept_~s.offset 52)) 8464)} assume !false; {4513#(= (select (store (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 28) (+ (select (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 28)) 1)) (+ ssl3_accept_~s.offset 52)) 8464)} is VALID [2018-11-14 19:06:07,275 INFO L273 TraceCheckUtils]: 15: Hoare triple {4513#(= (select (store (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 28) (+ (select (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 28)) 1)) (+ ssl3_accept_~s.offset 52)) 8464)} call #t~mem23 := read~int(~s.base, ~s.offset + 52, 4);~state~0 := #t~mem23;havoc #t~mem23;call #t~mem24 := read~int(~s.base, ~s.offset + 52, 4); {4513#(= (select (store (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 28) (+ (select (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 28)) 1)) (+ ssl3_accept_~s.offset 52)) 8464)} is VALID [2018-11-14 19:06:07,275 INFO L273 TraceCheckUtils]: 16: Hoare triple {4513#(= (select (store (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 28) (+ (select (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 28)) 1)) (+ ssl3_accept_~s.offset 52)) 8464)} assume !(#t~mem24 == 12292);havoc #t~mem24;call #t~mem25 := read~int(~s.base, ~s.offset + 52, 4); {4513#(= (select (store (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 28) (+ (select (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 28)) 1)) (+ ssl3_accept_~s.offset 52)) 8464)} is VALID [2018-11-14 19:06:07,276 INFO L273 TraceCheckUtils]: 17: Hoare triple {4513#(= (select (store (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 28) (+ (select (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 28)) 1)) (+ ssl3_accept_~s.offset 52)) 8464)} assume !(#t~mem25 == 16384);havoc #t~mem25;call #t~mem26 := read~int(~s.base, ~s.offset + 52, 4); {4513#(= (select (store (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 28) (+ (select (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 28)) 1)) (+ ssl3_accept_~s.offset 52)) 8464)} is VALID [2018-11-14 19:06:07,277 INFO L273 TraceCheckUtils]: 18: Hoare triple {4513#(= (select (store (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 28) (+ (select (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 28)) 1)) (+ ssl3_accept_~s.offset 52)) 8464)} assume !(#t~mem26 == 8192);havoc #t~mem26;call #t~mem27 := read~int(~s.base, ~s.offset + 52, 4); {4513#(= (select (store (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 28) (+ (select (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 28)) 1)) (+ ssl3_accept_~s.offset 52)) 8464)} is VALID [2018-11-14 19:06:07,277 INFO L273 TraceCheckUtils]: 19: Hoare triple {4513#(= (select (store (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 28) (+ (select (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 28)) 1)) (+ ssl3_accept_~s.offset 52)) 8464)} assume !(#t~mem27 == 24576);havoc #t~mem27;call #t~mem28 := read~int(~s.base, ~s.offset + 52, 4); {4513#(= (select (store (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 28) (+ (select (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 28)) 1)) (+ ssl3_accept_~s.offset 52)) 8464)} is VALID [2018-11-14 19:06:07,278 INFO L273 TraceCheckUtils]: 20: Hoare triple {4513#(= (select (store (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 28) (+ (select (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 28)) 1)) (+ ssl3_accept_~s.offset 52)) 8464)} assume !(#t~mem28 == 8195);havoc #t~mem28;call #t~mem29 := read~int(~s.base, ~s.offset + 52, 4); {4513#(= (select (store (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 28) (+ (select (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 28)) 1)) (+ ssl3_accept_~s.offset 52)) 8464)} is VALID [2018-11-14 19:06:07,279 INFO L273 TraceCheckUtils]: 21: Hoare triple {4513#(= (select (store (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 28) (+ (select (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 28)) 1)) (+ ssl3_accept_~s.offset 52)) 8464)} assume !(#t~mem29 == 8480);havoc #t~mem29;call #t~mem30 := read~int(~s.base, ~s.offset + 52, 4); {4513#(= (select (store (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 28) (+ (select (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 28)) 1)) (+ ssl3_accept_~s.offset 52)) 8464)} is VALID [2018-11-14 19:06:07,279 INFO L273 TraceCheckUtils]: 22: Hoare triple {4513#(= (select (store (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 28) (+ (select (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 28)) 1)) (+ ssl3_accept_~s.offset 52)) 8464)} assume !(#t~mem30 == 8481);havoc #t~mem30;call #t~mem31 := read~int(~s.base, ~s.offset + 52, 4); {4514#(= |ssl3_accept_#t~mem31| 8464)} is VALID [2018-11-14 19:06:07,280 INFO L273 TraceCheckUtils]: 23: Hoare triple {4514#(= |ssl3_accept_#t~mem31| 8464)} assume #t~mem31 == 8482;havoc #t~mem31; {4512#false} is VALID [2018-11-14 19:06:07,280 INFO L273 TraceCheckUtils]: 24: Hoare triple {4512#false} call write~int(3, ~s.base, ~s.offset + 52, 4); {4512#false} is VALID [2018-11-14 19:06:07,281 INFO L273 TraceCheckUtils]: 25: Hoare triple {4512#false} call #t~mem127.base, #t~mem127.offset := read~$Pointer$(~s.base, ~s.offset + 84, 4);call #t~mem128 := read~int(#t~mem127.base, #t~mem127.offset + 604 + 244, 4); {4512#false} is VALID [2018-11-14 19:06:07,281 INFO L273 TraceCheckUtils]: 26: Hoare triple {4512#false} assume !(#t~mem128 == 0);havoc #t~mem127.base, #t~mem127.offset;havoc #t~mem128; {4512#false} is VALID [2018-11-14 19:06:07,281 INFO L273 TraceCheckUtils]: 27: Hoare triple {4512#false} ~skip~0 := 0; {4512#false} is VALID [2018-11-14 19:06:07,281 INFO L273 TraceCheckUtils]: 28: Hoare triple {4512#false} assume true; {4512#false} is VALID [2018-11-14 19:06:07,282 INFO L273 TraceCheckUtils]: 29: Hoare triple {4512#false} assume !false; {4512#false} is VALID [2018-11-14 19:06:07,282 INFO L273 TraceCheckUtils]: 30: Hoare triple {4512#false} call #t~mem23 := read~int(~s.base, ~s.offset + 52, 4);~state~0 := #t~mem23;havoc #t~mem23;call #t~mem24 := read~int(~s.base, ~s.offset + 52, 4); {4512#false} is VALID [2018-11-14 19:06:07,282 INFO L273 TraceCheckUtils]: 31: Hoare triple {4512#false} assume !(#t~mem24 == 12292);havoc #t~mem24;call #t~mem25 := read~int(~s.base, ~s.offset + 52, 4); {4512#false} is VALID [2018-11-14 19:06:07,282 INFO L273 TraceCheckUtils]: 32: Hoare triple {4512#false} assume !(#t~mem25 == 16384);havoc #t~mem25;call #t~mem26 := read~int(~s.base, ~s.offset + 52, 4); {4512#false} is VALID [2018-11-14 19:06:07,283 INFO L273 TraceCheckUtils]: 33: Hoare triple {4512#false} assume !(#t~mem26 == 8192);havoc #t~mem26;call #t~mem27 := read~int(~s.base, ~s.offset + 52, 4); {4512#false} is VALID [2018-11-14 19:06:07,283 INFO L273 TraceCheckUtils]: 34: Hoare triple {4512#false} assume !(#t~mem27 == 24576);havoc #t~mem27;call #t~mem28 := read~int(~s.base, ~s.offset + 52, 4); {4512#false} is VALID [2018-11-14 19:06:07,283 INFO L273 TraceCheckUtils]: 35: Hoare triple {4512#false} assume !(#t~mem28 == 8195);havoc #t~mem28;call #t~mem29 := read~int(~s.base, ~s.offset + 52, 4); {4512#false} is VALID [2018-11-14 19:06:07,283 INFO L273 TraceCheckUtils]: 36: Hoare triple {4512#false} assume !(#t~mem29 == 8480);havoc #t~mem29;call #t~mem30 := read~int(~s.base, ~s.offset + 52, 4); {4512#false} is VALID [2018-11-14 19:06:07,283 INFO L273 TraceCheckUtils]: 37: Hoare triple {4512#false} assume !(#t~mem30 == 8481);havoc #t~mem30;call #t~mem31 := read~int(~s.base, ~s.offset + 52, 4); {4512#false} is VALID [2018-11-14 19:06:07,283 INFO L273 TraceCheckUtils]: 38: Hoare triple {4512#false} assume !(#t~mem31 == 8482);havoc #t~mem31;call #t~mem32 := read~int(~s.base, ~s.offset + 52, 4); {4512#false} is VALID [2018-11-14 19:06:07,283 INFO L273 TraceCheckUtils]: 39: Hoare triple {4512#false} assume !(#t~mem32 == 8464);havoc #t~mem32;call #t~mem33 := read~int(~s.base, ~s.offset + 52, 4); {4512#false} is VALID [2018-11-14 19:06:07,284 INFO L273 TraceCheckUtils]: 40: Hoare triple {4512#false} assume !(#t~mem33 == 8465);havoc #t~mem33;call #t~mem34 := read~int(~s.base, ~s.offset + 52, 4); {4512#false} is VALID [2018-11-14 19:06:07,284 INFO L273 TraceCheckUtils]: 41: Hoare triple {4512#false} assume !(#t~mem34 == 8466);havoc #t~mem34;call #t~mem35 := read~int(~s.base, ~s.offset + 52, 4); {4512#false} is VALID [2018-11-14 19:06:07,284 INFO L273 TraceCheckUtils]: 42: Hoare triple {4512#false} assume !(#t~mem35 == 8496);havoc #t~mem35;call #t~mem36 := read~int(~s.base, ~s.offset + 52, 4); {4512#false} is VALID [2018-11-14 19:06:07,284 INFO L273 TraceCheckUtils]: 43: Hoare triple {4512#false} assume !(#t~mem36 == 8497);havoc #t~mem36;call #t~mem37 := read~int(~s.base, ~s.offset + 52, 4); {4512#false} is VALID [2018-11-14 19:06:07,284 INFO L273 TraceCheckUtils]: 44: Hoare triple {4512#false} assume !(#t~mem37 == 8512);havoc #t~mem37;call #t~mem38 := read~int(~s.base, ~s.offset + 52, 4); {4512#false} is VALID [2018-11-14 19:06:07,284 INFO L273 TraceCheckUtils]: 45: Hoare triple {4512#false} assume !(#t~mem38 == 8513);havoc #t~mem38;call #t~mem39 := read~int(~s.base, ~s.offset + 52, 4); {4512#false} is VALID [2018-11-14 19:06:07,285 INFO L273 TraceCheckUtils]: 46: Hoare triple {4512#false} assume !(#t~mem39 == 8528);havoc #t~mem39;call #t~mem40 := read~int(~s.base, ~s.offset + 52, 4); {4512#false} is VALID [2018-11-14 19:06:07,285 INFO L273 TraceCheckUtils]: 47: Hoare triple {4512#false} assume !(#t~mem40 == 8529);havoc #t~mem40;call #t~mem41 := read~int(~s.base, ~s.offset + 52, 4); {4512#false} is VALID [2018-11-14 19:06:07,285 INFO L273 TraceCheckUtils]: 48: Hoare triple {4512#false} assume !(#t~mem41 == 8544);havoc #t~mem41;call #t~mem42 := read~int(~s.base, ~s.offset + 52, 4); {4512#false} is VALID [2018-11-14 19:06:07,285 INFO L273 TraceCheckUtils]: 49: Hoare triple {4512#false} assume !(#t~mem42 == 8545);havoc #t~mem42;call #t~mem43 := read~int(~s.base, ~s.offset + 52, 4); {4512#false} is VALID [2018-11-14 19:06:07,285 INFO L273 TraceCheckUtils]: 50: Hoare triple {4512#false} assume !(#t~mem43 == 8560);havoc #t~mem43;call #t~mem44 := read~int(~s.base, ~s.offset + 52, 4); {4512#false} is VALID [2018-11-14 19:06:07,286 INFO L273 TraceCheckUtils]: 51: Hoare triple {4512#false} assume !(#t~mem44 == 8561);havoc #t~mem44;call #t~mem45 := read~int(~s.base, ~s.offset + 52, 4); {4512#false} is VALID [2018-11-14 19:06:07,286 INFO L273 TraceCheckUtils]: 52: Hoare triple {4512#false} assume !(#t~mem45 == 8448);havoc #t~mem45;call #t~mem46 := read~int(~s.base, ~s.offset + 52, 4); {4512#false} is VALID [2018-11-14 19:06:07,286 INFO L273 TraceCheckUtils]: 53: Hoare triple {4512#false} assume !(#t~mem46 == 8576);havoc #t~mem46;call #t~mem47 := read~int(~s.base, ~s.offset + 52, 4); {4512#false} is VALID [2018-11-14 19:06:07,286 INFO L273 TraceCheckUtils]: 54: Hoare triple {4512#false} assume !(#t~mem47 == 8577);havoc #t~mem47;call #t~mem48 := read~int(~s.base, ~s.offset + 52, 4); {4512#false} is VALID [2018-11-14 19:06:07,286 INFO L273 TraceCheckUtils]: 55: Hoare triple {4512#false} assume !(#t~mem48 == 8592);havoc #t~mem48;call #t~mem49 := read~int(~s.base, ~s.offset + 52, 4); {4512#false} is VALID [2018-11-14 19:06:07,287 INFO L273 TraceCheckUtils]: 56: Hoare triple {4512#false} assume !(#t~mem49 == 8593);havoc #t~mem49;call #t~mem50 := read~int(~s.base, ~s.offset + 52, 4); {4512#false} is VALID [2018-11-14 19:06:07,287 INFO L273 TraceCheckUtils]: 57: Hoare triple {4512#false} assume !(#t~mem50 == 8608);havoc #t~mem50;call #t~mem51 := read~int(~s.base, ~s.offset + 52, 4); {4512#false} is VALID [2018-11-14 19:06:07,287 INFO L273 TraceCheckUtils]: 58: Hoare triple {4512#false} assume !(#t~mem51 == 8609);havoc #t~mem51;call #t~mem52 := read~int(~s.base, ~s.offset + 52, 4); {4512#false} is VALID [2018-11-14 19:06:07,287 INFO L273 TraceCheckUtils]: 59: Hoare triple {4512#false} assume !(#t~mem52 == 8640);havoc #t~mem52;call #t~mem53 := read~int(~s.base, ~s.offset + 52, 4); {4512#false} is VALID [2018-11-14 19:06:07,287 INFO L273 TraceCheckUtils]: 60: Hoare triple {4512#false} assume !(#t~mem53 == 8641);havoc #t~mem53;call #t~mem54 := read~int(~s.base, ~s.offset + 52, 4); {4512#false} is VALID [2018-11-14 19:06:07,288 INFO L273 TraceCheckUtils]: 61: Hoare triple {4512#false} assume !(#t~mem54 == 8656);havoc #t~mem54;call #t~mem55 := read~int(~s.base, ~s.offset + 52, 4); {4512#false} is VALID [2018-11-14 19:06:07,288 INFO L273 TraceCheckUtils]: 62: Hoare triple {4512#false} assume !(#t~mem55 == 8657);havoc #t~mem55;call #t~mem56 := read~int(~s.base, ~s.offset + 52, 4); {4512#false} is VALID [2018-11-14 19:06:07,288 INFO L273 TraceCheckUtils]: 63: Hoare triple {4512#false} assume #t~mem56 == 8672;havoc #t~mem56; {4512#false} is VALID [2018-11-14 19:06:07,288 INFO L273 TraceCheckUtils]: 64: Hoare triple {4512#false} assume -2147483648 <= #t~nondet121 && #t~nondet121 <= 2147483647;~ret~0 := #t~nondet121;havoc #t~nondet121; {4512#false} is VALID [2018-11-14 19:06:07,289 INFO L273 TraceCheckUtils]: 65: Hoare triple {4512#false} assume ~blastFlag~0 == 4; {4512#false} is VALID [2018-11-14 19:06:07,289 INFO L273 TraceCheckUtils]: 66: Hoare triple {4512#false} assume !false; {4512#false} is VALID [2018-11-14 19:06:07,295 INFO L134 CoverageAnalysis]: Checked inductivity of 11 backedges. 11 proven. 0 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2018-11-14 19:06:07,295 INFO L312 seRefinementStrategy]: Constructing automaton from 1 perfect and 0 imperfect interpolant sequences. [2018-11-14 19:06:07,295 INFO L327 seRefinementStrategy]: Number of different interpolants: perfect sequences [4] imperfect sequences [] total 4 [2018-11-14 19:06:07,296 INFO L78 Accepts]: Start accepts. Automaton has 4 states. Word has length 67 [2018-11-14 19:06:07,296 INFO L84 Accepts]: Finished accepts. word is accepted. [2018-11-14 19:06:07,296 INFO L86 InductivityCheck]: Starting indutivity check of a Floyd-Hoare automaton with 4 states. [2018-11-14 19:06:07,364 INFO L119 InductivityCheck]: Floyd-Hoare automaton has 67 edges. 67 inductive. 0 not inductive. 0 times theorem prover too weak to decide inductivity. [2018-11-14 19:06:07,364 INFO L459 AbstractCegarLoop]: Interpolant automaton has 4 states [2018-11-14 19:06:07,364 INFO L142 InterpolantAutomaton]: Constructing interpolant automaton starting with 4 interpolants. [2018-11-14 19:06:07,365 INFO L144 InterpolantAutomaton]: CoverageRelationStatistics Valid=5, Invalid=7, Unknown=0, NotChecked=0, Total=12 [2018-11-14 19:06:07,365 INFO L87 Difference]: Start difference. First operand 149 states and 220 transitions. Second operand 4 states. [2018-11-14 19:06:08,830 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2018-11-14 19:06:08,830 INFO L93 Difference]: Finished difference Result 285 states and 424 transitions. [2018-11-14 19:06:08,830 INFO L142 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 4 states. [2018-11-14 19:06:08,831 INFO L78 Accepts]: Start accepts. Automaton has 4 states. Word has length 67 [2018-11-14 19:06:08,831 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2018-11-14 19:06:08,831 INFO L82 GeneralOperation]: Start removeUnreachable. Operand 4 states. [2018-11-14 19:06:08,834 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 4 states to 4 states and 424 transitions. [2018-11-14 19:06:08,834 INFO L82 GeneralOperation]: Start removeUnreachable. Operand 4 states. [2018-11-14 19:06:08,837 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 4 states to 4 states and 424 transitions. [2018-11-14 19:06:08,838 INFO L86 InductivityCheck]: Starting indutivity check of a Floyd-Hoare automaton with 4 states and 424 transitions. [2018-11-14 19:06:09,620 INFO L119 InductivityCheck]: Floyd-Hoare automaton has 424 edges. 424 inductive. 0 not inductive. 0 times theorem prover too weak to decide inductivity. [2018-11-14 19:06:09,624 INFO L225 Difference]: With dead ends: 285 [2018-11-14 19:06:09,624 INFO L226 Difference]: Without dead ends: 162 [2018-11-14 19:06:09,625 INFO L604 BasicCegarLoop]: 0 DeclaredPredicates, 6 GetRequests, 2 SyntacticMatches, 1 SemanticMatches, 3 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 0 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=9, Invalid=11, Unknown=0, NotChecked=0, Total=20 [2018-11-14 19:06:09,625 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 162 states. [2018-11-14 19:06:09,647 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 162 to 149. [2018-11-14 19:06:09,647 INFO L214 AbstractMinimizeNwa]: Start testing correctness of minimizeSevpa [2018-11-14 19:06:09,648 INFO L82 GeneralOperation]: Start isEquivalent. First operand 162 states. Second operand 149 states. [2018-11-14 19:06:09,648 INFO L74 IsIncluded]: Start isIncluded. First operand 162 states. Second operand 149 states. [2018-11-14 19:06:09,648 INFO L87 Difference]: Start difference. First operand 162 states. Second operand 149 states. [2018-11-14 19:06:09,652 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2018-11-14 19:06:09,652 INFO L93 Difference]: Finished difference Result 162 states and 236 transitions. [2018-11-14 19:06:09,652 INFO L276 IsEmpty]: Start isEmpty. Operand 162 states and 236 transitions. [2018-11-14 19:06:09,653 INFO L282 IsEmpty]: Finished isEmpty. No accepting run. [2018-11-14 19:06:09,653 INFO L83 IsIncluded]: Finished isIncluded. Language is included [2018-11-14 19:06:09,653 INFO L74 IsIncluded]: Start isIncluded. First operand 149 states. Second operand 162 states. [2018-11-14 19:06:09,653 INFO L87 Difference]: Start difference. First operand 149 states. Second operand 162 states. [2018-11-14 19:06:09,657 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2018-11-14 19:06:09,657 INFO L93 Difference]: Finished difference Result 162 states and 236 transitions. [2018-11-14 19:06:09,658 INFO L276 IsEmpty]: Start isEmpty. Operand 162 states and 236 transitions. [2018-11-14 19:06:09,658 INFO L282 IsEmpty]: Finished isEmpty. No accepting run. [2018-11-14 19:06:09,658 INFO L83 IsIncluded]: Finished isIncluded. Language is included [2018-11-14 19:06:09,658 INFO L88 GeneralOperation]: Finished isEquivalent. [2018-11-14 19:06:09,659 INFO L221 AbstractMinimizeNwa]: Finished testing correctness of minimizeSevpa [2018-11-14 19:06:09,659 INFO L82 GeneralOperation]: Start removeUnreachable. Operand 149 states. [2018-11-14 19:06:09,663 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 149 states to 149 states and 219 transitions. [2018-11-14 19:06:09,663 INFO L78 Accepts]: Start accepts. Automaton has 149 states and 219 transitions. Word has length 67 [2018-11-14 19:06:09,663 INFO L84 Accepts]: Finished accepts. word is rejected. [2018-11-14 19:06:09,663 INFO L480 AbstractCegarLoop]: Abstraction has 149 states and 219 transitions. [2018-11-14 19:06:09,663 INFO L481 AbstractCegarLoop]: Interpolant automaton has 4 states. [2018-11-14 19:06:09,663 INFO L276 IsEmpty]: Start isEmpty. Operand 149 states and 219 transitions. [2018-11-14 19:06:09,664 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 69 [2018-11-14 19:06:09,664 INFO L367 BasicCegarLoop]: Found error trace [2018-11-14 19:06:09,665 INFO L375 BasicCegarLoop]: trace histogram [2, 2, 2, 2, 2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2018-11-14 19:06:09,665 INFO L423 AbstractCegarLoop]: === Iteration 7 === [ssl3_acceptErr0ASSERT_VIOLATIONERROR_FUNCTION]=== [2018-11-14 19:06:09,665 INFO L141 PredicateUnifier]: Initialized classic predicate unifier [2018-11-14 19:06:09,665 INFO L82 PathProgramCache]: Analyzing trace with hash -538409076, now seen corresponding path program 1 times [2018-11-14 19:06:09,665 INFO L223 ckRefinementStrategy]: Switched to mode SMTINTERPOL_TREE_INTERPOLANTS [2018-11-14 19:06:09,665 INFO L69 tionRefinementEngine]: Using refinement strategy CamelRefinementStrategy [2018-11-14 19:06:09,667 INFO L119 rtionOrderModulation]: Craig_TreeInterpolation forces the order to NOT_INCREMENTALLY [2018-11-14 19:06:09,667 INFO L103 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2018-11-14 19:06:09,667 INFO L119 rtionOrderModulation]: Craig_TreeInterpolation forces the order to NOT_INCREMENTALLY [2018-11-14 19:06:09,689 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2018-11-14 19:06:10,322 INFO L256 TraceCheckUtils]: 0: Hoare triple {5362#true} call ULTIMATE.init(); {5362#true} is VALID [2018-11-14 19:06:10,323 INFO L273 TraceCheckUtils]: 1: Hoare triple {5362#true} #NULL.base, #NULL.offset := 0, 0;#valid := #valid[0 := 0];~init~0 := 1;call ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset := #Ultimate.alloc(100);call write~unchecked~int(0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 0, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 4, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 8, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 12, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 16, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 20, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 24, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 28, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 32, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 36, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 40, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 44, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 48, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 52, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 56, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 60, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 64, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 68, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 72, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 76, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 80, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 84, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 88, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 92, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 96, 4);call write~unchecked~int(0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 0, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 4, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 8, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 12, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 16, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 20, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 24, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 28, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 32, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 36, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 40, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 44, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 48, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 52, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 56, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 60, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 64, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 68, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 72, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 76, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 80, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 84, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 88, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 92, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 96, 4); {5362#true} is VALID [2018-11-14 19:06:10,323 INFO L273 TraceCheckUtils]: 2: Hoare triple {5362#true} assume true; {5362#true} is VALID [2018-11-14 19:06:10,323 INFO L268 TraceCheckUtils]: 3: Hoare quadruple {5362#true} {5362#true} #654#return; {5362#true} is VALID [2018-11-14 19:06:10,323 INFO L256 TraceCheckUtils]: 4: Hoare triple {5362#true} call #t~ret138 := main(); {5362#true} is VALID [2018-11-14 19:06:10,323 INFO L273 TraceCheckUtils]: 5: Hoare triple {5362#true} havoc ~s~0.base, ~s~0.offset;havoc ~tmp~2;call #t~malloc3.base, #t~malloc3.offset := #Ultimate.alloc(248);~s~0.base, ~s~0.offset := #t~malloc3.base, #t~malloc3.offset;call #t~malloc4.base, #t~malloc4.offset := #Ultimate.alloc(899);call write~$Pointer$(#t~malloc4.base, #t~malloc4.offset, ~s~0.base, ~s~0.offset + 84, 4);call #t~malloc5.base, #t~malloc5.offset := #Ultimate.alloc(232);call write~$Pointer$(#t~malloc5.base, #t~malloc5.offset, ~s~0.base, ~s~0.offset + 204, 4);call #t~malloc6.base, #t~malloc6.offset := #Ultimate.alloc(200);call write~$Pointer$(#t~malloc6.base, #t~malloc6.offset, ~s~0.base, ~s~0.offset + 176, 4);call write~int(8464, ~s~0.base, ~s~0.offset + 52, 4); {5362#true} is VALID [2018-11-14 19:06:10,323 INFO L256 TraceCheckUtils]: 6: Hoare triple {5362#true} call #t~ret7 := ssl3_accept(~s~0.base, ~s~0.offset); {5362#true} is VALID [2018-11-14 19:06:10,325 INFO L273 TraceCheckUtils]: 7: Hoare triple {5362#true} ~s.base, ~s.offset := #in~s.base, #in~s.offset;havoc ~buf~0.base, ~buf~0.offset;havoc ~l~0;havoc ~Time~0;havoc ~tmp~3;havoc ~cb~0.base, ~cb~0.offset;havoc ~num1~0;havoc ~ret~0;havoc ~new_state~0;havoc ~state~0;havoc ~skip~0;havoc ~got_new_session~0;assume -2147483648 <= #t~nondet8 && #t~nondet8 <= 2147483647;~tmp___1~0 := #t~nondet8;havoc #t~nondet8;assume -2147483648 <= #t~nondet9 && #t~nondet9 <= 2147483647;~tmp___2~0 := #t~nondet9;havoc #t~nondet9;assume -2147483648 <= #t~nondet10 && #t~nondet10 <= 2147483647;~tmp___3~0 := #t~nondet10;havoc #t~nondet10;assume -2147483648 <= #t~nondet11 && #t~nondet11 <= 2147483647;~tmp___4~0 := #t~nondet11;havoc #t~nondet11;assume -2147483648 <= #t~nondet12 && #t~nondet12 <= 2147483647;~tmp___5~0 := #t~nondet12;havoc #t~nondet12;assume -2147483648 <= #t~nondet13 && #t~nondet13 <= 2147483647;~tmp___6~0 := #t~nondet13;havoc #t~nondet13;havoc ~tmp___7~0;assume -2147483648 <= #t~nondet14 && #t~nondet14 <= 2147483647;~tmp___8~0 := #t~nondet14;havoc #t~nondet14;assume -2147483648 <= #t~nondet15 && #t~nondet15 <= 2147483647;~tmp___9~0 := #t~nondet15;havoc #t~nondet15;assume -2147483648 <= #t~nondet16 && #t~nondet16 <= 2147483647;~tmp___10~0 := #t~nondet16;havoc #t~nondet16;havoc ~blastFlag~0;~blastFlag~0 := 0;assume -2147483648 <= #t~nondet17 && #t~nondet17 <= 2147483647;call write~int(#t~nondet17, ~s.base, ~s.offset + 92, 4);havoc #t~nondet17;call write~int(8464, ~s.base, ~s.offset + 52, 4);assume -2147483648 <= #t~nondet18 && #t~nondet18 <= 2147483647;~tmp~3 := #t~nondet18;havoc #t~nondet18;~Time~0 := ~tmp~3;~cb~0.base, ~cb~0.offset := 0, 0;~ret~0 := -1;~skip~0 := 0;~got_new_session~0 := 0;call #t~mem19.base, #t~mem19.offset := read~$Pointer$(~s.base, ~s.offset + 192, 4); {5364#(= (select (store (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 28) (+ (select (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 28)) 1)) (+ ssl3_accept_~s.offset 52)) 8464)} is VALID [2018-11-14 19:06:10,326 INFO L273 TraceCheckUtils]: 8: Hoare triple {5364#(= (select (store (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 28) (+ (select (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 28)) 1)) (+ ssl3_accept_~s.offset 52)) 8464)} assume (#t~mem19.base + #t~mem19.offset) % 4294967296 != 0;havoc #t~mem19.base, #t~mem19.offset;call #t~mem20.base, #t~mem20.offset := read~$Pointer$(~s.base, ~s.offset + 192, 4);~cb~0.base, ~cb~0.offset := #t~mem20.base, #t~mem20.offset;havoc #t~mem20.base, #t~mem20.offset; {5364#(= (select (store (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 28) (+ (select (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 28)) 1)) (+ ssl3_accept_~s.offset 52)) 8464)} is VALID [2018-11-14 19:06:10,326 INFO L273 TraceCheckUtils]: 9: Hoare triple {5364#(= (select (store (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 28) (+ (select (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 28)) 1)) (+ ssl3_accept_~s.offset 52)) 8464)} call #t~mem21 := read~int(~s.base, ~s.offset + 28, 4);call write~int(#t~mem21 + 1, ~s.base, ~s.offset + 28, 4);havoc #t~mem21; {5364#(= (select (store (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 28) (+ (select (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 28)) 1)) (+ ssl3_accept_~s.offset 52)) 8464)} is VALID [2018-11-14 19:06:10,327 INFO L273 TraceCheckUtils]: 10: Hoare triple {5364#(= (select (store (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 28) (+ (select (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 28)) 1)) (+ ssl3_accept_~s.offset 52)) 8464)} assume !(~bitwiseAnd(~tmp___1~0, 12288) != 0); {5364#(= (select (store (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 28) (+ (select (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 28)) 1)) (+ ssl3_accept_~s.offset 52)) 8464)} is VALID [2018-11-14 19:06:10,327 INFO L273 TraceCheckUtils]: 11: Hoare triple {5364#(= (select (store (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 28) (+ (select (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 28)) 1)) (+ ssl3_accept_~s.offset 52)) 8464)} call #t~mem22.base, #t~mem22.offset := read~$Pointer$(~s.base, ~s.offset + 136, 4); {5364#(= (select (store (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 28) (+ (select (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 28)) 1)) (+ ssl3_accept_~s.offset 52)) 8464)} is VALID [2018-11-14 19:06:10,328 INFO L273 TraceCheckUtils]: 12: Hoare triple {5364#(= (select (store (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 28) (+ (select (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 28)) 1)) (+ ssl3_accept_~s.offset 52)) 8464)} assume !((#t~mem22.base + #t~mem22.offset) % 4294967296 == 0);havoc #t~mem22.base, #t~mem22.offset; {5364#(= (select (store (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 28) (+ (select (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 28)) 1)) (+ ssl3_accept_~s.offset 52)) 8464)} is VALID [2018-11-14 19:06:10,328 INFO L273 TraceCheckUtils]: 13: Hoare triple {5364#(= (select (store (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 28) (+ (select (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 28)) 1)) (+ ssl3_accept_~s.offset 52)) 8464)} assume true; {5364#(= (select (store (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 28) (+ (select (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 28)) 1)) (+ ssl3_accept_~s.offset 52)) 8464)} is VALID [2018-11-14 19:06:10,329 INFO L273 TraceCheckUtils]: 14: Hoare triple {5364#(= (select (store (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 28) (+ (select (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 28)) 1)) (+ ssl3_accept_~s.offset 52)) 8464)} assume !false; {5364#(= (select (store (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 28) (+ (select (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 28)) 1)) (+ ssl3_accept_~s.offset 52)) 8464)} is VALID [2018-11-14 19:06:10,330 INFO L273 TraceCheckUtils]: 15: Hoare triple {5364#(= (select (store (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 28) (+ (select (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 28)) 1)) (+ ssl3_accept_~s.offset 52)) 8464)} call #t~mem23 := read~int(~s.base, ~s.offset + 52, 4);~state~0 := #t~mem23;havoc #t~mem23;call #t~mem24 := read~int(~s.base, ~s.offset + 52, 4); {5364#(= (select (store (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 28) (+ (select (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 28)) 1)) (+ ssl3_accept_~s.offset 52)) 8464)} is VALID [2018-11-14 19:06:10,330 INFO L273 TraceCheckUtils]: 16: Hoare triple {5364#(= (select (store (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 28) (+ (select (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 28)) 1)) (+ ssl3_accept_~s.offset 52)) 8464)} assume !(#t~mem24 == 12292);havoc #t~mem24;call #t~mem25 := read~int(~s.base, ~s.offset + 52, 4); {5364#(= (select (store (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 28) (+ (select (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 28)) 1)) (+ ssl3_accept_~s.offset 52)) 8464)} is VALID [2018-11-14 19:06:10,331 INFO L273 TraceCheckUtils]: 17: Hoare triple {5364#(= (select (store (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 28) (+ (select (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 28)) 1)) (+ ssl3_accept_~s.offset 52)) 8464)} assume !(#t~mem25 == 16384);havoc #t~mem25;call #t~mem26 := read~int(~s.base, ~s.offset + 52, 4); {5365#(= |ssl3_accept_#t~mem26| 8464)} is VALID [2018-11-14 19:06:10,332 INFO L273 TraceCheckUtils]: 18: Hoare triple {5365#(= |ssl3_accept_#t~mem26| 8464)} assume #t~mem26 == 8192;havoc #t~mem26; {5363#false} is VALID [2018-11-14 19:06:10,332 INFO L273 TraceCheckUtils]: 19: Hoare triple {5363#false} call write~int(1, ~s.base, ~s.offset + 36, 4); {5363#false} is VALID [2018-11-14 19:06:10,332 INFO L273 TraceCheckUtils]: 20: Hoare triple {5363#false} assume (~cb~0.base + ~cb~0.offset) % 4294967296 != 0; {5363#false} is VALID [2018-11-14 19:06:10,333 INFO L273 TraceCheckUtils]: 21: Hoare triple {5363#false} call #t~mem59 := read~int(~s.base, ~s.offset + 0, 4); {5363#false} is VALID [2018-11-14 19:06:10,333 INFO L273 TraceCheckUtils]: 22: Hoare triple {5363#false} assume !(#t~mem59 / 256 != 3);havoc #t~mem59;call write~int(8192, ~s.base, ~s.offset + 4, 4);call #t~mem60.base, #t~mem60.offset := read~$Pointer$(~s.base, ~s.offset + 60, 4); {5363#false} is VALID [2018-11-14 19:06:10,333 INFO L273 TraceCheckUtils]: 23: Hoare triple {5363#false} assume !((#t~mem60.base + #t~mem60.offset) % 4294967296 == 0);havoc #t~mem60.base, #t~mem60.offset; {5363#false} is VALID [2018-11-14 19:06:10,333 INFO L273 TraceCheckUtils]: 24: Hoare triple {5363#false} assume !(~tmp___4~0 == 0);call write~int(0, ~s.base, ~s.offset + 64, 4);call #t~mem62 := read~int(~s.base, ~s.offset + 52, 4); {5363#false} is VALID [2018-11-14 19:06:10,334 INFO L273 TraceCheckUtils]: 25: Hoare triple {5363#false} assume !(#t~mem62 != 12292);havoc #t~mem62;call #t~mem65.base, #t~mem65.offset := read~$Pointer$(~s.base, ~s.offset + 204, 4);call #t~mem66 := read~int(#t~mem65.base, #t~mem65.offset + 60 + 16, 4);call write~int(#t~mem66 + 1, #t~mem65.base, #t~mem65.offset + 60 + 16, 4);havoc #t~mem66;havoc #t~mem65.base, #t~mem65.offset;call write~int(8480, ~s.base, ~s.offset + 52, 4); {5363#false} is VALID [2018-11-14 19:06:10,334 INFO L273 TraceCheckUtils]: 26: Hoare triple {5363#false} call #t~mem127.base, #t~mem127.offset := read~$Pointer$(~s.base, ~s.offset + 84, 4);call #t~mem128 := read~int(#t~mem127.base, #t~mem127.offset + 604 + 244, 4); {5363#false} is VALID [2018-11-14 19:06:10,334 INFO L273 TraceCheckUtils]: 27: Hoare triple {5363#false} assume !(#t~mem128 == 0);havoc #t~mem127.base, #t~mem127.offset;havoc #t~mem128; {5363#false} is VALID [2018-11-14 19:06:10,334 INFO L273 TraceCheckUtils]: 28: Hoare triple {5363#false} ~skip~0 := 0; {5363#false} is VALID [2018-11-14 19:06:10,334 INFO L273 TraceCheckUtils]: 29: Hoare triple {5363#false} assume true; {5363#false} is VALID [2018-11-14 19:06:10,335 INFO L273 TraceCheckUtils]: 30: Hoare triple {5363#false} assume !false; {5363#false} is VALID [2018-11-14 19:06:10,335 INFO L273 TraceCheckUtils]: 31: Hoare triple {5363#false} call #t~mem23 := read~int(~s.base, ~s.offset + 52, 4);~state~0 := #t~mem23;havoc #t~mem23;call #t~mem24 := read~int(~s.base, ~s.offset + 52, 4); {5363#false} is VALID [2018-11-14 19:06:10,335 INFO L273 TraceCheckUtils]: 32: Hoare triple {5363#false} assume !(#t~mem24 == 12292);havoc #t~mem24;call #t~mem25 := read~int(~s.base, ~s.offset + 52, 4); {5363#false} is VALID [2018-11-14 19:06:10,335 INFO L273 TraceCheckUtils]: 33: Hoare triple {5363#false} assume !(#t~mem25 == 16384);havoc #t~mem25;call #t~mem26 := read~int(~s.base, ~s.offset + 52, 4); {5363#false} is VALID [2018-11-14 19:06:10,335 INFO L273 TraceCheckUtils]: 34: Hoare triple {5363#false} assume !(#t~mem26 == 8192);havoc #t~mem26;call #t~mem27 := read~int(~s.base, ~s.offset + 52, 4); {5363#false} is VALID [2018-11-14 19:06:10,335 INFO L273 TraceCheckUtils]: 35: Hoare triple {5363#false} assume !(#t~mem27 == 24576);havoc #t~mem27;call #t~mem28 := read~int(~s.base, ~s.offset + 52, 4); {5363#false} is VALID [2018-11-14 19:06:10,335 INFO L273 TraceCheckUtils]: 36: Hoare triple {5363#false} assume !(#t~mem28 == 8195);havoc #t~mem28;call #t~mem29 := read~int(~s.base, ~s.offset + 52, 4); {5363#false} is VALID [2018-11-14 19:06:10,336 INFO L273 TraceCheckUtils]: 37: Hoare triple {5363#false} assume !(#t~mem29 == 8480);havoc #t~mem29;call #t~mem30 := read~int(~s.base, ~s.offset + 52, 4); {5363#false} is VALID [2018-11-14 19:06:10,336 INFO L273 TraceCheckUtils]: 38: Hoare triple {5363#false} assume !(#t~mem30 == 8481);havoc #t~mem30;call #t~mem31 := read~int(~s.base, ~s.offset + 52, 4); {5363#false} is VALID [2018-11-14 19:06:10,336 INFO L273 TraceCheckUtils]: 39: Hoare triple {5363#false} assume !(#t~mem31 == 8482);havoc #t~mem31;call #t~mem32 := read~int(~s.base, ~s.offset + 52, 4); {5363#false} is VALID [2018-11-14 19:06:10,336 INFO L273 TraceCheckUtils]: 40: Hoare triple {5363#false} assume !(#t~mem32 == 8464);havoc #t~mem32;call #t~mem33 := read~int(~s.base, ~s.offset + 52, 4); {5363#false} is VALID [2018-11-14 19:06:10,336 INFO L273 TraceCheckUtils]: 41: Hoare triple {5363#false} assume !(#t~mem33 == 8465);havoc #t~mem33;call #t~mem34 := read~int(~s.base, ~s.offset + 52, 4); {5363#false} is VALID [2018-11-14 19:06:10,336 INFO L273 TraceCheckUtils]: 42: Hoare triple {5363#false} assume !(#t~mem34 == 8466);havoc #t~mem34;call #t~mem35 := read~int(~s.base, ~s.offset + 52, 4); {5363#false} is VALID [2018-11-14 19:06:10,336 INFO L273 TraceCheckUtils]: 43: Hoare triple {5363#false} assume !(#t~mem35 == 8496);havoc #t~mem35;call #t~mem36 := read~int(~s.base, ~s.offset + 52, 4); {5363#false} is VALID [2018-11-14 19:06:10,337 INFO L273 TraceCheckUtils]: 44: Hoare triple {5363#false} assume !(#t~mem36 == 8497);havoc #t~mem36;call #t~mem37 := read~int(~s.base, ~s.offset + 52, 4); {5363#false} is VALID [2018-11-14 19:06:10,337 INFO L273 TraceCheckUtils]: 45: Hoare triple {5363#false} assume !(#t~mem37 == 8512);havoc #t~mem37;call #t~mem38 := read~int(~s.base, ~s.offset + 52, 4); {5363#false} is VALID [2018-11-14 19:06:10,337 INFO L273 TraceCheckUtils]: 46: Hoare triple {5363#false} assume !(#t~mem38 == 8513);havoc #t~mem38;call #t~mem39 := read~int(~s.base, ~s.offset + 52, 4); {5363#false} is VALID [2018-11-14 19:06:10,337 INFO L273 TraceCheckUtils]: 47: Hoare triple {5363#false} assume !(#t~mem39 == 8528);havoc #t~mem39;call #t~mem40 := read~int(~s.base, ~s.offset + 52, 4); {5363#false} is VALID [2018-11-14 19:06:10,337 INFO L273 TraceCheckUtils]: 48: Hoare triple {5363#false} assume !(#t~mem40 == 8529);havoc #t~mem40;call #t~mem41 := read~int(~s.base, ~s.offset + 52, 4); {5363#false} is VALID [2018-11-14 19:06:10,337 INFO L273 TraceCheckUtils]: 49: Hoare triple {5363#false} assume !(#t~mem41 == 8544);havoc #t~mem41;call #t~mem42 := read~int(~s.base, ~s.offset + 52, 4); {5363#false} is VALID [2018-11-14 19:06:10,337 INFO L273 TraceCheckUtils]: 50: Hoare triple {5363#false} assume !(#t~mem42 == 8545);havoc #t~mem42;call #t~mem43 := read~int(~s.base, ~s.offset + 52, 4); {5363#false} is VALID [2018-11-14 19:06:10,338 INFO L273 TraceCheckUtils]: 51: Hoare triple {5363#false} assume !(#t~mem43 == 8560);havoc #t~mem43;call #t~mem44 := read~int(~s.base, ~s.offset + 52, 4); {5363#false} is VALID [2018-11-14 19:06:10,338 INFO L273 TraceCheckUtils]: 52: Hoare triple {5363#false} assume !(#t~mem44 == 8561);havoc #t~mem44;call #t~mem45 := read~int(~s.base, ~s.offset + 52, 4); {5363#false} is VALID [2018-11-14 19:06:10,338 INFO L273 TraceCheckUtils]: 53: Hoare triple {5363#false} assume !(#t~mem45 == 8448);havoc #t~mem45;call #t~mem46 := read~int(~s.base, ~s.offset + 52, 4); {5363#false} is VALID [2018-11-14 19:06:10,338 INFO L273 TraceCheckUtils]: 54: Hoare triple {5363#false} assume !(#t~mem46 == 8576);havoc #t~mem46;call #t~mem47 := read~int(~s.base, ~s.offset + 52, 4); {5363#false} is VALID [2018-11-14 19:06:10,338 INFO L273 TraceCheckUtils]: 55: Hoare triple {5363#false} assume !(#t~mem47 == 8577);havoc #t~mem47;call #t~mem48 := read~int(~s.base, ~s.offset + 52, 4); {5363#false} is VALID [2018-11-14 19:06:10,338 INFO L273 TraceCheckUtils]: 56: Hoare triple {5363#false} assume !(#t~mem48 == 8592);havoc #t~mem48;call #t~mem49 := read~int(~s.base, ~s.offset + 52, 4); {5363#false} is VALID [2018-11-14 19:06:10,339 INFO L273 TraceCheckUtils]: 57: Hoare triple {5363#false} assume !(#t~mem49 == 8593);havoc #t~mem49;call #t~mem50 := read~int(~s.base, ~s.offset + 52, 4); {5363#false} is VALID [2018-11-14 19:06:10,339 INFO L273 TraceCheckUtils]: 58: Hoare triple {5363#false} assume !(#t~mem50 == 8608);havoc #t~mem50;call #t~mem51 := read~int(~s.base, ~s.offset + 52, 4); {5363#false} is VALID [2018-11-14 19:06:10,339 INFO L273 TraceCheckUtils]: 59: Hoare triple {5363#false} assume !(#t~mem51 == 8609);havoc #t~mem51;call #t~mem52 := read~int(~s.base, ~s.offset + 52, 4); {5363#false} is VALID [2018-11-14 19:06:10,339 INFO L273 TraceCheckUtils]: 60: Hoare triple {5363#false} assume !(#t~mem52 == 8640);havoc #t~mem52;call #t~mem53 := read~int(~s.base, ~s.offset + 52, 4); {5363#false} is VALID [2018-11-14 19:06:10,339 INFO L273 TraceCheckUtils]: 61: Hoare triple {5363#false} assume !(#t~mem53 == 8641);havoc #t~mem53;call #t~mem54 := read~int(~s.base, ~s.offset + 52, 4); {5363#false} is VALID [2018-11-14 19:06:10,340 INFO L273 TraceCheckUtils]: 62: Hoare triple {5363#false} assume !(#t~mem54 == 8656);havoc #t~mem54;call #t~mem55 := read~int(~s.base, ~s.offset + 52, 4); {5363#false} is VALID [2018-11-14 19:06:10,340 INFO L273 TraceCheckUtils]: 63: Hoare triple {5363#false} assume !(#t~mem55 == 8657);havoc #t~mem55;call #t~mem56 := read~int(~s.base, ~s.offset + 52, 4); {5363#false} is VALID [2018-11-14 19:06:10,340 INFO L273 TraceCheckUtils]: 64: Hoare triple {5363#false} assume #t~mem56 == 8672;havoc #t~mem56; {5363#false} is VALID [2018-11-14 19:06:10,340 INFO L273 TraceCheckUtils]: 65: Hoare triple {5363#false} assume -2147483648 <= #t~nondet121 && #t~nondet121 <= 2147483647;~ret~0 := #t~nondet121;havoc #t~nondet121; {5363#false} is VALID [2018-11-14 19:06:10,340 INFO L273 TraceCheckUtils]: 66: Hoare triple {5363#false} assume ~blastFlag~0 == 4; {5363#false} is VALID [2018-11-14 19:06:10,341 INFO L273 TraceCheckUtils]: 67: Hoare triple {5363#false} assume !false; {5363#false} is VALID [2018-11-14 19:06:10,346 INFO L134 CoverageAnalysis]: Checked inductivity of 6 backedges. 6 proven. 0 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2018-11-14 19:06:10,346 INFO L312 seRefinementStrategy]: Constructing automaton from 1 perfect and 0 imperfect interpolant sequences. [2018-11-14 19:06:10,346 INFO L327 seRefinementStrategy]: Number of different interpolants: perfect sequences [4] imperfect sequences [] total 4 [2018-11-14 19:06:10,347 INFO L78 Accepts]: Start accepts. Automaton has 4 states. Word has length 68 [2018-11-14 19:06:10,347 INFO L84 Accepts]: Finished accepts. word is accepted. [2018-11-14 19:06:10,347 INFO L86 InductivityCheck]: Starting indutivity check of a Floyd-Hoare automaton with 4 states. [2018-11-14 19:06:10,442 INFO L119 InductivityCheck]: Floyd-Hoare automaton has 68 edges. 68 inductive. 0 not inductive. 0 times theorem prover too weak to decide inductivity. [2018-11-14 19:06:10,443 INFO L459 AbstractCegarLoop]: Interpolant automaton has 4 states [2018-11-14 19:06:10,443 INFO L142 InterpolantAutomaton]: Constructing interpolant automaton starting with 4 interpolants. [2018-11-14 19:06:10,443 INFO L144 InterpolantAutomaton]: CoverageRelationStatistics Valid=5, Invalid=7, Unknown=0, NotChecked=0, Total=12 [2018-11-14 19:06:10,443 INFO L87 Difference]: Start difference. First operand 149 states and 219 transitions. Second operand 4 states. [2018-11-14 19:06:11,932 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2018-11-14 19:06:11,932 INFO L93 Difference]: Finished difference Result 285 states and 423 transitions. [2018-11-14 19:06:11,932 INFO L142 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 4 states. [2018-11-14 19:06:11,932 INFO L78 Accepts]: Start accepts. Automaton has 4 states. Word has length 68 [2018-11-14 19:06:11,932 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2018-11-14 19:06:11,933 INFO L82 GeneralOperation]: Start removeUnreachable. Operand 4 states. [2018-11-14 19:06:11,936 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 4 states to 4 states and 423 transitions. [2018-11-14 19:06:11,936 INFO L82 GeneralOperation]: Start removeUnreachable. Operand 4 states. [2018-11-14 19:06:11,938 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 4 states to 4 states and 423 transitions. [2018-11-14 19:06:11,939 INFO L86 InductivityCheck]: Starting indutivity check of a Floyd-Hoare automaton with 4 states and 423 transitions. [2018-11-14 19:06:12,705 INFO L119 InductivityCheck]: Floyd-Hoare automaton has 423 edges. 423 inductive. 0 not inductive. 0 times theorem prover too weak to decide inductivity. [2018-11-14 19:06:12,710 INFO L225 Difference]: With dead ends: 285 [2018-11-14 19:06:12,710 INFO L226 Difference]: Without dead ends: 162 [2018-11-14 19:06:12,710 INFO L604 BasicCegarLoop]: 0 DeclaredPredicates, 7 GetRequests, 2 SyntacticMatches, 2 SemanticMatches, 3 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 0 ImplicationChecksByTransitivity, 0.4s TimeCoverageRelationStatistics Valid=9, Invalid=11, Unknown=0, NotChecked=0, Total=20 [2018-11-14 19:06:12,711 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 162 states. [2018-11-14 19:06:12,735 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 162 to 149. [2018-11-14 19:06:12,735 INFO L214 AbstractMinimizeNwa]: Start testing correctness of minimizeSevpa [2018-11-14 19:06:12,735 INFO L82 GeneralOperation]: Start isEquivalent. First operand 162 states. Second operand 149 states. [2018-11-14 19:06:12,736 INFO L74 IsIncluded]: Start isIncluded. First operand 162 states. Second operand 149 states. [2018-11-14 19:06:12,736 INFO L87 Difference]: Start difference. First operand 162 states. Second operand 149 states. [2018-11-14 19:06:12,740 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2018-11-14 19:06:12,740 INFO L93 Difference]: Finished difference Result 162 states and 235 transitions. [2018-11-14 19:06:12,741 INFO L276 IsEmpty]: Start isEmpty. Operand 162 states and 235 transitions. [2018-11-14 19:06:12,741 INFO L282 IsEmpty]: Finished isEmpty. No accepting run. [2018-11-14 19:06:12,741 INFO L83 IsIncluded]: Finished isIncluded. Language is included [2018-11-14 19:06:12,741 INFO L74 IsIncluded]: Start isIncluded. First operand 149 states. Second operand 162 states. [2018-11-14 19:06:12,742 INFO L87 Difference]: Start difference. First operand 149 states. Second operand 162 states. [2018-11-14 19:06:12,745 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2018-11-14 19:06:12,745 INFO L93 Difference]: Finished difference Result 162 states and 235 transitions. [2018-11-14 19:06:12,746 INFO L276 IsEmpty]: Start isEmpty. Operand 162 states and 235 transitions. [2018-11-14 19:06:12,746 INFO L282 IsEmpty]: Finished isEmpty. No accepting run. [2018-11-14 19:06:12,746 INFO L83 IsIncluded]: Finished isIncluded. Language is included [2018-11-14 19:06:12,746 INFO L88 GeneralOperation]: Finished isEquivalent. [2018-11-14 19:06:12,747 INFO L221 AbstractMinimizeNwa]: Finished testing correctness of minimizeSevpa [2018-11-14 19:06:12,747 INFO L82 GeneralOperation]: Start removeUnreachable. Operand 149 states. [2018-11-14 19:06:12,750 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 149 states to 149 states and 218 transitions. [2018-11-14 19:06:12,750 INFO L78 Accepts]: Start accepts. Automaton has 149 states and 218 transitions. Word has length 68 [2018-11-14 19:06:12,750 INFO L84 Accepts]: Finished accepts. word is rejected. [2018-11-14 19:06:12,750 INFO L480 AbstractCegarLoop]: Abstraction has 149 states and 218 transitions. [2018-11-14 19:06:12,751 INFO L481 AbstractCegarLoop]: Interpolant automaton has 4 states. [2018-11-14 19:06:12,751 INFO L276 IsEmpty]: Start isEmpty. Operand 149 states and 218 transitions. [2018-11-14 19:06:12,751 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 70 [2018-11-14 19:06:12,752 INFO L367 BasicCegarLoop]: Found error trace [2018-11-14 19:06:12,752 INFO L375 BasicCegarLoop]: trace histogram [2, 2, 2, 2, 2, 2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2018-11-14 19:06:12,752 INFO L423 AbstractCegarLoop]: === Iteration 8 === [ssl3_acceptErr0ASSERT_VIOLATIONERROR_FUNCTION]=== [2018-11-14 19:06:12,752 INFO L141 PredicateUnifier]: Initialized classic predicate unifier [2018-11-14 19:06:12,752 INFO L82 PathProgramCache]: Analyzing trace with hash 642776382, now seen corresponding path program 1 times [2018-11-14 19:06:12,753 INFO L223 ckRefinementStrategy]: Switched to mode SMTINTERPOL_TREE_INTERPOLANTS [2018-11-14 19:06:12,753 INFO L69 tionRefinementEngine]: Using refinement strategy CamelRefinementStrategy [2018-11-14 19:06:12,754 INFO L119 rtionOrderModulation]: Craig_TreeInterpolation forces the order to NOT_INCREMENTALLY [2018-11-14 19:06:12,754 INFO L103 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2018-11-14 19:06:12,754 INFO L119 rtionOrderModulation]: Craig_TreeInterpolation forces the order to NOT_INCREMENTALLY [2018-11-14 19:06:12,770 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2018-11-14 19:06:13,386 WARN L179 SmtUtils]: Spent 104.00 ms on a formula simplification. DAG size of input: 6 DAG size of output: 3 [2018-11-14 19:06:13,465 INFO L256 TraceCheckUtils]: 0: Hoare triple {6213#true} call ULTIMATE.init(); {6213#true} is VALID [2018-11-14 19:06:13,465 INFO L273 TraceCheckUtils]: 1: Hoare triple {6213#true} #NULL.base, #NULL.offset := 0, 0;#valid := #valid[0 := 0];~init~0 := 1;call ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset := #Ultimate.alloc(100);call write~unchecked~int(0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 0, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 4, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 8, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 12, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 16, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 20, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 24, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 28, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 32, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 36, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 40, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 44, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 48, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 52, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 56, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 60, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 64, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 68, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 72, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 76, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 80, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 84, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 88, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 92, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 96, 4);call write~unchecked~int(0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 0, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 4, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 8, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 12, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 16, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 20, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 24, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 28, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 32, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 36, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 40, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 44, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 48, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 52, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 56, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 60, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 64, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 68, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 72, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 76, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 80, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 84, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 88, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 92, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 96, 4); {6213#true} is VALID [2018-11-14 19:06:13,465 INFO L273 TraceCheckUtils]: 2: Hoare triple {6213#true} assume true; {6213#true} is VALID [2018-11-14 19:06:13,465 INFO L268 TraceCheckUtils]: 3: Hoare quadruple {6213#true} {6213#true} #654#return; {6213#true} is VALID [2018-11-14 19:06:13,466 INFO L256 TraceCheckUtils]: 4: Hoare triple {6213#true} call #t~ret138 := main(); {6213#true} is VALID [2018-11-14 19:06:13,466 INFO L273 TraceCheckUtils]: 5: Hoare triple {6213#true} havoc ~s~0.base, ~s~0.offset;havoc ~tmp~2;call #t~malloc3.base, #t~malloc3.offset := #Ultimate.alloc(248);~s~0.base, ~s~0.offset := #t~malloc3.base, #t~malloc3.offset;call #t~malloc4.base, #t~malloc4.offset := #Ultimate.alloc(899);call write~$Pointer$(#t~malloc4.base, #t~malloc4.offset, ~s~0.base, ~s~0.offset + 84, 4);call #t~malloc5.base, #t~malloc5.offset := #Ultimate.alloc(232);call write~$Pointer$(#t~malloc5.base, #t~malloc5.offset, ~s~0.base, ~s~0.offset + 204, 4);call #t~malloc6.base, #t~malloc6.offset := #Ultimate.alloc(200);call write~$Pointer$(#t~malloc6.base, #t~malloc6.offset, ~s~0.base, ~s~0.offset + 176, 4);call write~int(8464, ~s~0.base, ~s~0.offset + 52, 4); {6213#true} is VALID [2018-11-14 19:06:13,466 INFO L256 TraceCheckUtils]: 6: Hoare triple {6213#true} call #t~ret7 := ssl3_accept(~s~0.base, ~s~0.offset); {6213#true} is VALID [2018-11-14 19:06:13,468 INFO L273 TraceCheckUtils]: 7: Hoare triple {6213#true} ~s.base, ~s.offset := #in~s.base, #in~s.offset;havoc ~buf~0.base, ~buf~0.offset;havoc ~l~0;havoc ~Time~0;havoc ~tmp~3;havoc ~cb~0.base, ~cb~0.offset;havoc ~num1~0;havoc ~ret~0;havoc ~new_state~0;havoc ~state~0;havoc ~skip~0;havoc ~got_new_session~0;assume -2147483648 <= #t~nondet8 && #t~nondet8 <= 2147483647;~tmp___1~0 := #t~nondet8;havoc #t~nondet8;assume -2147483648 <= #t~nondet9 && #t~nondet9 <= 2147483647;~tmp___2~0 := #t~nondet9;havoc #t~nondet9;assume -2147483648 <= #t~nondet10 && #t~nondet10 <= 2147483647;~tmp___3~0 := #t~nondet10;havoc #t~nondet10;assume -2147483648 <= #t~nondet11 && #t~nondet11 <= 2147483647;~tmp___4~0 := #t~nondet11;havoc #t~nondet11;assume -2147483648 <= #t~nondet12 && #t~nondet12 <= 2147483647;~tmp___5~0 := #t~nondet12;havoc #t~nondet12;assume -2147483648 <= #t~nondet13 && #t~nondet13 <= 2147483647;~tmp___6~0 := #t~nondet13;havoc #t~nondet13;havoc ~tmp___7~0;assume -2147483648 <= #t~nondet14 && #t~nondet14 <= 2147483647;~tmp___8~0 := #t~nondet14;havoc #t~nondet14;assume -2147483648 <= #t~nondet15 && #t~nondet15 <= 2147483647;~tmp___9~0 := #t~nondet15;havoc #t~nondet15;assume -2147483648 <= #t~nondet16 && #t~nondet16 <= 2147483647;~tmp___10~0 := #t~nondet16;havoc #t~nondet16;havoc ~blastFlag~0;~blastFlag~0 := 0;assume -2147483648 <= #t~nondet17 && #t~nondet17 <= 2147483647;call write~int(#t~nondet17, ~s.base, ~s.offset + 92, 4);havoc #t~nondet17;call write~int(8464, ~s.base, ~s.offset + 52, 4);assume -2147483648 <= #t~nondet18 && #t~nondet18 <= 2147483647;~tmp~3 := #t~nondet18;havoc #t~nondet18;~Time~0 := ~tmp~3;~cb~0.base, ~cb~0.offset := 0, 0;~ret~0 := -1;~skip~0 := 0;~got_new_session~0 := 0;call #t~mem19.base, #t~mem19.offset := read~$Pointer$(~s.base, ~s.offset + 192, 4); {6215#(= (select (store (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 28) (+ (select (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 28)) 1)) (+ ssl3_accept_~s.offset 52)) 8464)} is VALID [2018-11-14 19:06:13,468 INFO L273 TraceCheckUtils]: 8: Hoare triple {6215#(= (select (store (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 28) (+ (select (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 28)) 1)) (+ ssl3_accept_~s.offset 52)) 8464)} assume (#t~mem19.base + #t~mem19.offset) % 4294967296 != 0;havoc #t~mem19.base, #t~mem19.offset;call #t~mem20.base, #t~mem20.offset := read~$Pointer$(~s.base, ~s.offset + 192, 4);~cb~0.base, ~cb~0.offset := #t~mem20.base, #t~mem20.offset;havoc #t~mem20.base, #t~mem20.offset; {6215#(= (select (store (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 28) (+ (select (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 28)) 1)) (+ ssl3_accept_~s.offset 52)) 8464)} is VALID [2018-11-14 19:06:13,469 INFO L273 TraceCheckUtils]: 9: Hoare triple {6215#(= (select (store (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 28) (+ (select (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 28)) 1)) (+ ssl3_accept_~s.offset 52)) 8464)} call #t~mem21 := read~int(~s.base, ~s.offset + 28, 4);call write~int(#t~mem21 + 1, ~s.base, ~s.offset + 28, 4);havoc #t~mem21; {6215#(= (select (store (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 28) (+ (select (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 28)) 1)) (+ ssl3_accept_~s.offset 52)) 8464)} is VALID [2018-11-14 19:06:13,470 INFO L273 TraceCheckUtils]: 10: Hoare triple {6215#(= (select (store (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 28) (+ (select (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 28)) 1)) (+ ssl3_accept_~s.offset 52)) 8464)} assume !(~bitwiseAnd(~tmp___1~0, 12288) != 0); {6215#(= (select (store (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 28) (+ (select (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 28)) 1)) (+ ssl3_accept_~s.offset 52)) 8464)} is VALID [2018-11-14 19:06:13,470 INFO L273 TraceCheckUtils]: 11: Hoare triple {6215#(= (select (store (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 28) (+ (select (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 28)) 1)) (+ ssl3_accept_~s.offset 52)) 8464)} call #t~mem22.base, #t~mem22.offset := read~$Pointer$(~s.base, ~s.offset + 136, 4); {6215#(= (select (store (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 28) (+ (select (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 28)) 1)) (+ ssl3_accept_~s.offset 52)) 8464)} is VALID [2018-11-14 19:06:13,471 INFO L273 TraceCheckUtils]: 12: Hoare triple {6215#(= (select (store (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 28) (+ (select (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 28)) 1)) (+ ssl3_accept_~s.offset 52)) 8464)} assume !((#t~mem22.base + #t~mem22.offset) % 4294967296 == 0);havoc #t~mem22.base, #t~mem22.offset; {6215#(= (select (store (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 28) (+ (select (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 28)) 1)) (+ ssl3_accept_~s.offset 52)) 8464)} is VALID [2018-11-14 19:06:13,471 INFO L273 TraceCheckUtils]: 13: Hoare triple {6215#(= (select (store (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 28) (+ (select (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 28)) 1)) (+ ssl3_accept_~s.offset 52)) 8464)} assume true; {6215#(= (select (store (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 28) (+ (select (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 28)) 1)) (+ ssl3_accept_~s.offset 52)) 8464)} is VALID [2018-11-14 19:06:13,472 INFO L273 TraceCheckUtils]: 14: Hoare triple {6215#(= (select (store (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 28) (+ (select (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 28)) 1)) (+ ssl3_accept_~s.offset 52)) 8464)} assume !false; {6215#(= (select (store (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 28) (+ (select (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 28)) 1)) (+ ssl3_accept_~s.offset 52)) 8464)} is VALID [2018-11-14 19:06:13,472 INFO L273 TraceCheckUtils]: 15: Hoare triple {6215#(= (select (store (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 28) (+ (select (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 28)) 1)) (+ ssl3_accept_~s.offset 52)) 8464)} call #t~mem23 := read~int(~s.base, ~s.offset + 52, 4);~state~0 := #t~mem23;havoc #t~mem23;call #t~mem24 := read~int(~s.base, ~s.offset + 52, 4); {6215#(= (select (store (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 28) (+ (select (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 28)) 1)) (+ ssl3_accept_~s.offset 52)) 8464)} is VALID [2018-11-14 19:06:13,473 INFO L273 TraceCheckUtils]: 16: Hoare triple {6215#(= (select (store (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 28) (+ (select (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 28)) 1)) (+ ssl3_accept_~s.offset 52)) 8464)} assume !(#t~mem24 == 12292);havoc #t~mem24;call #t~mem25 := read~int(~s.base, ~s.offset + 52, 4); {6215#(= (select (store (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 28) (+ (select (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 28)) 1)) (+ ssl3_accept_~s.offset 52)) 8464)} is VALID [2018-11-14 19:06:13,473 INFO L273 TraceCheckUtils]: 17: Hoare triple {6215#(= (select (store (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 28) (+ (select (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 28)) 1)) (+ ssl3_accept_~s.offset 52)) 8464)} assume !(#t~mem25 == 16384);havoc #t~mem25;call #t~mem26 := read~int(~s.base, ~s.offset + 52, 4); {6215#(= (select (store (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 28) (+ (select (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 28)) 1)) (+ ssl3_accept_~s.offset 52)) 8464)} is VALID [2018-11-14 19:06:13,474 INFO L273 TraceCheckUtils]: 18: Hoare triple {6215#(= (select (store (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 28) (+ (select (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 28)) 1)) (+ ssl3_accept_~s.offset 52)) 8464)} assume !(#t~mem26 == 8192);havoc #t~mem26;call #t~mem27 := read~int(~s.base, ~s.offset + 52, 4); {6216#(= |ssl3_accept_#t~mem27| 8464)} is VALID [2018-11-14 19:06:13,475 INFO L273 TraceCheckUtils]: 19: Hoare triple {6216#(= |ssl3_accept_#t~mem27| 8464)} assume #t~mem27 == 24576;havoc #t~mem27; {6214#false} is VALID [2018-11-14 19:06:13,475 INFO L273 TraceCheckUtils]: 20: Hoare triple {6214#false} call write~int(1, ~s.base, ~s.offset + 36, 4); {6214#false} is VALID [2018-11-14 19:06:13,475 INFO L273 TraceCheckUtils]: 21: Hoare triple {6214#false} assume (~cb~0.base + ~cb~0.offset) % 4294967296 != 0; {6214#false} is VALID [2018-11-14 19:06:13,476 INFO L273 TraceCheckUtils]: 22: Hoare triple {6214#false} call #t~mem59 := read~int(~s.base, ~s.offset + 0, 4); {6214#false} is VALID [2018-11-14 19:06:13,476 INFO L273 TraceCheckUtils]: 23: Hoare triple {6214#false} assume !(#t~mem59 / 256 != 3);havoc #t~mem59;call write~int(8192, ~s.base, ~s.offset + 4, 4);call #t~mem60.base, #t~mem60.offset := read~$Pointer$(~s.base, ~s.offset + 60, 4); {6214#false} is VALID [2018-11-14 19:06:13,476 INFO L273 TraceCheckUtils]: 24: Hoare triple {6214#false} assume !((#t~mem60.base + #t~mem60.offset) % 4294967296 == 0);havoc #t~mem60.base, #t~mem60.offset; {6214#false} is VALID [2018-11-14 19:06:13,476 INFO L273 TraceCheckUtils]: 25: Hoare triple {6214#false} assume !(~tmp___4~0 == 0);call write~int(0, ~s.base, ~s.offset + 64, 4);call #t~mem62 := read~int(~s.base, ~s.offset + 52, 4); {6214#false} is VALID [2018-11-14 19:06:13,477 INFO L273 TraceCheckUtils]: 26: Hoare triple {6214#false} assume !(#t~mem62 != 12292);havoc #t~mem62;call #t~mem65.base, #t~mem65.offset := read~$Pointer$(~s.base, ~s.offset + 204, 4);call #t~mem66 := read~int(#t~mem65.base, #t~mem65.offset + 60 + 16, 4);call write~int(#t~mem66 + 1, #t~mem65.base, #t~mem65.offset + 60 + 16, 4);havoc #t~mem66;havoc #t~mem65.base, #t~mem65.offset;call write~int(8480, ~s.base, ~s.offset + 52, 4); {6214#false} is VALID [2018-11-14 19:06:13,477 INFO L273 TraceCheckUtils]: 27: Hoare triple {6214#false} call #t~mem127.base, #t~mem127.offset := read~$Pointer$(~s.base, ~s.offset + 84, 4);call #t~mem128 := read~int(#t~mem127.base, #t~mem127.offset + 604 + 244, 4); {6214#false} is VALID [2018-11-14 19:06:13,477 INFO L273 TraceCheckUtils]: 28: Hoare triple {6214#false} assume !(#t~mem128 == 0);havoc #t~mem127.base, #t~mem127.offset;havoc #t~mem128; {6214#false} is VALID [2018-11-14 19:06:13,477 INFO L273 TraceCheckUtils]: 29: Hoare triple {6214#false} ~skip~0 := 0; {6214#false} is VALID [2018-11-14 19:06:13,477 INFO L273 TraceCheckUtils]: 30: Hoare triple {6214#false} assume true; {6214#false} is VALID [2018-11-14 19:06:13,478 INFO L273 TraceCheckUtils]: 31: Hoare triple {6214#false} assume !false; {6214#false} is VALID [2018-11-14 19:06:13,478 INFO L273 TraceCheckUtils]: 32: Hoare triple {6214#false} call #t~mem23 := read~int(~s.base, ~s.offset + 52, 4);~state~0 := #t~mem23;havoc #t~mem23;call #t~mem24 := read~int(~s.base, ~s.offset + 52, 4); {6214#false} is VALID [2018-11-14 19:06:13,478 INFO L273 TraceCheckUtils]: 33: Hoare triple {6214#false} assume !(#t~mem24 == 12292);havoc #t~mem24;call #t~mem25 := read~int(~s.base, ~s.offset + 52, 4); {6214#false} is VALID [2018-11-14 19:06:13,478 INFO L273 TraceCheckUtils]: 34: Hoare triple {6214#false} assume !(#t~mem25 == 16384);havoc #t~mem25;call #t~mem26 := read~int(~s.base, ~s.offset + 52, 4); {6214#false} is VALID [2018-11-14 19:06:13,478 INFO L273 TraceCheckUtils]: 35: Hoare triple {6214#false} assume !(#t~mem26 == 8192);havoc #t~mem26;call #t~mem27 := read~int(~s.base, ~s.offset + 52, 4); {6214#false} is VALID [2018-11-14 19:06:13,478 INFO L273 TraceCheckUtils]: 36: Hoare triple {6214#false} assume !(#t~mem27 == 24576);havoc #t~mem27;call #t~mem28 := read~int(~s.base, ~s.offset + 52, 4); {6214#false} is VALID [2018-11-14 19:06:13,478 INFO L273 TraceCheckUtils]: 37: Hoare triple {6214#false} assume !(#t~mem28 == 8195);havoc #t~mem28;call #t~mem29 := read~int(~s.base, ~s.offset + 52, 4); {6214#false} is VALID [2018-11-14 19:06:13,479 INFO L273 TraceCheckUtils]: 38: Hoare triple {6214#false} assume !(#t~mem29 == 8480);havoc #t~mem29;call #t~mem30 := read~int(~s.base, ~s.offset + 52, 4); {6214#false} is VALID [2018-11-14 19:06:13,479 INFO L273 TraceCheckUtils]: 39: Hoare triple {6214#false} assume !(#t~mem30 == 8481);havoc #t~mem30;call #t~mem31 := read~int(~s.base, ~s.offset + 52, 4); {6214#false} is VALID [2018-11-14 19:06:13,479 INFO L273 TraceCheckUtils]: 40: Hoare triple {6214#false} assume !(#t~mem31 == 8482);havoc #t~mem31;call #t~mem32 := read~int(~s.base, ~s.offset + 52, 4); {6214#false} is VALID [2018-11-14 19:06:13,479 INFO L273 TraceCheckUtils]: 41: Hoare triple {6214#false} assume !(#t~mem32 == 8464);havoc #t~mem32;call #t~mem33 := read~int(~s.base, ~s.offset + 52, 4); {6214#false} is VALID [2018-11-14 19:06:13,479 INFO L273 TraceCheckUtils]: 42: Hoare triple {6214#false} assume !(#t~mem33 == 8465);havoc #t~mem33;call #t~mem34 := read~int(~s.base, ~s.offset + 52, 4); {6214#false} is VALID [2018-11-14 19:06:13,479 INFO L273 TraceCheckUtils]: 43: Hoare triple {6214#false} assume !(#t~mem34 == 8466);havoc #t~mem34;call #t~mem35 := read~int(~s.base, ~s.offset + 52, 4); {6214#false} is VALID [2018-11-14 19:06:13,479 INFO L273 TraceCheckUtils]: 44: Hoare triple {6214#false} assume !(#t~mem35 == 8496);havoc #t~mem35;call #t~mem36 := read~int(~s.base, ~s.offset + 52, 4); {6214#false} is VALID [2018-11-14 19:06:13,480 INFO L273 TraceCheckUtils]: 45: Hoare triple {6214#false} assume !(#t~mem36 == 8497);havoc #t~mem36;call #t~mem37 := read~int(~s.base, ~s.offset + 52, 4); {6214#false} is VALID [2018-11-14 19:06:13,480 INFO L273 TraceCheckUtils]: 46: Hoare triple {6214#false} assume !(#t~mem37 == 8512);havoc #t~mem37;call #t~mem38 := read~int(~s.base, ~s.offset + 52, 4); {6214#false} is VALID [2018-11-14 19:06:13,480 INFO L273 TraceCheckUtils]: 47: Hoare triple {6214#false} assume !(#t~mem38 == 8513);havoc #t~mem38;call #t~mem39 := read~int(~s.base, ~s.offset + 52, 4); {6214#false} is VALID [2018-11-14 19:06:13,480 INFO L273 TraceCheckUtils]: 48: Hoare triple {6214#false} assume !(#t~mem39 == 8528);havoc #t~mem39;call #t~mem40 := read~int(~s.base, ~s.offset + 52, 4); {6214#false} is VALID [2018-11-14 19:06:13,480 INFO L273 TraceCheckUtils]: 49: Hoare triple {6214#false} assume !(#t~mem40 == 8529);havoc #t~mem40;call #t~mem41 := read~int(~s.base, ~s.offset + 52, 4); {6214#false} is VALID [2018-11-14 19:06:13,480 INFO L273 TraceCheckUtils]: 50: Hoare triple {6214#false} assume !(#t~mem41 == 8544);havoc #t~mem41;call #t~mem42 := read~int(~s.base, ~s.offset + 52, 4); {6214#false} is VALID [2018-11-14 19:06:13,481 INFO L273 TraceCheckUtils]: 51: Hoare triple {6214#false} assume !(#t~mem42 == 8545);havoc #t~mem42;call #t~mem43 := read~int(~s.base, ~s.offset + 52, 4); {6214#false} is VALID [2018-11-14 19:06:13,481 INFO L273 TraceCheckUtils]: 52: Hoare triple {6214#false} assume !(#t~mem43 == 8560);havoc #t~mem43;call #t~mem44 := read~int(~s.base, ~s.offset + 52, 4); {6214#false} is VALID [2018-11-14 19:06:13,481 INFO L273 TraceCheckUtils]: 53: Hoare triple {6214#false} assume !(#t~mem44 == 8561);havoc #t~mem44;call #t~mem45 := read~int(~s.base, ~s.offset + 52, 4); {6214#false} is VALID [2018-11-14 19:06:13,481 INFO L273 TraceCheckUtils]: 54: Hoare triple {6214#false} assume !(#t~mem45 == 8448);havoc #t~mem45;call #t~mem46 := read~int(~s.base, ~s.offset + 52, 4); {6214#false} is VALID [2018-11-14 19:06:13,481 INFO L273 TraceCheckUtils]: 55: Hoare triple {6214#false} assume !(#t~mem46 == 8576);havoc #t~mem46;call #t~mem47 := read~int(~s.base, ~s.offset + 52, 4); {6214#false} is VALID [2018-11-14 19:06:13,482 INFO L273 TraceCheckUtils]: 56: Hoare triple {6214#false} assume !(#t~mem47 == 8577);havoc #t~mem47;call #t~mem48 := read~int(~s.base, ~s.offset + 52, 4); {6214#false} is VALID [2018-11-14 19:06:13,482 INFO L273 TraceCheckUtils]: 57: Hoare triple {6214#false} assume !(#t~mem48 == 8592);havoc #t~mem48;call #t~mem49 := read~int(~s.base, ~s.offset + 52, 4); {6214#false} is VALID [2018-11-14 19:06:13,482 INFO L273 TraceCheckUtils]: 58: Hoare triple {6214#false} assume !(#t~mem49 == 8593);havoc #t~mem49;call #t~mem50 := read~int(~s.base, ~s.offset + 52, 4); {6214#false} is VALID [2018-11-14 19:06:13,483 INFO L273 TraceCheckUtils]: 59: Hoare triple {6214#false} assume !(#t~mem50 == 8608);havoc #t~mem50;call #t~mem51 := read~int(~s.base, ~s.offset + 52, 4); {6214#false} is VALID [2018-11-14 19:06:13,483 INFO L273 TraceCheckUtils]: 60: Hoare triple {6214#false} assume !(#t~mem51 == 8609);havoc #t~mem51;call #t~mem52 := read~int(~s.base, ~s.offset + 52, 4); {6214#false} is VALID [2018-11-14 19:06:13,483 INFO L273 TraceCheckUtils]: 61: Hoare triple {6214#false} assume !(#t~mem52 == 8640);havoc #t~mem52;call #t~mem53 := read~int(~s.base, ~s.offset + 52, 4); {6214#false} is VALID [2018-11-14 19:06:13,483 INFO L273 TraceCheckUtils]: 62: Hoare triple {6214#false} assume !(#t~mem53 == 8641);havoc #t~mem53;call #t~mem54 := read~int(~s.base, ~s.offset + 52, 4); {6214#false} is VALID [2018-11-14 19:06:13,483 INFO L273 TraceCheckUtils]: 63: Hoare triple {6214#false} assume !(#t~mem54 == 8656);havoc #t~mem54;call #t~mem55 := read~int(~s.base, ~s.offset + 52, 4); {6214#false} is VALID [2018-11-14 19:06:13,484 INFO L273 TraceCheckUtils]: 64: Hoare triple {6214#false} assume !(#t~mem55 == 8657);havoc #t~mem55;call #t~mem56 := read~int(~s.base, ~s.offset + 52, 4); {6214#false} is VALID [2018-11-14 19:06:13,484 INFO L273 TraceCheckUtils]: 65: Hoare triple {6214#false} assume #t~mem56 == 8672;havoc #t~mem56; {6214#false} is VALID [2018-11-14 19:06:13,484 INFO L273 TraceCheckUtils]: 66: Hoare triple {6214#false} assume -2147483648 <= #t~nondet121 && #t~nondet121 <= 2147483647;~ret~0 := #t~nondet121;havoc #t~nondet121; {6214#false} is VALID [2018-11-14 19:06:13,484 INFO L273 TraceCheckUtils]: 67: Hoare triple {6214#false} assume ~blastFlag~0 == 4; {6214#false} is VALID [2018-11-14 19:06:13,484 INFO L273 TraceCheckUtils]: 68: Hoare triple {6214#false} assume !false; {6214#false} is VALID [2018-11-14 19:06:13,492 INFO L134 CoverageAnalysis]: Checked inductivity of 7 backedges. 7 proven. 0 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2018-11-14 19:06:13,492 INFO L312 seRefinementStrategy]: Constructing automaton from 1 perfect and 0 imperfect interpolant sequences. [2018-11-14 19:06:13,492 INFO L327 seRefinementStrategy]: Number of different interpolants: perfect sequences [4] imperfect sequences [] total 4 [2018-11-14 19:06:13,493 INFO L78 Accepts]: Start accepts. Automaton has 4 states. Word has length 69 [2018-11-14 19:06:13,493 INFO L84 Accepts]: Finished accepts. word is accepted. [2018-11-14 19:06:13,493 INFO L86 InductivityCheck]: Starting indutivity check of a Floyd-Hoare automaton with 4 states. [2018-11-14 19:06:13,611 INFO L119 InductivityCheck]: Floyd-Hoare automaton has 69 edges. 69 inductive. 0 not inductive. 0 times theorem prover too weak to decide inductivity. [2018-11-14 19:06:13,611 INFO L459 AbstractCegarLoop]: Interpolant automaton has 4 states [2018-11-14 19:06:13,611 INFO L142 InterpolantAutomaton]: Constructing interpolant automaton starting with 4 interpolants. [2018-11-14 19:06:13,612 INFO L144 InterpolantAutomaton]: CoverageRelationStatistics Valid=5, Invalid=7, Unknown=0, NotChecked=0, Total=12 [2018-11-14 19:06:13,612 INFO L87 Difference]: Start difference. First operand 149 states and 218 transitions. Second operand 4 states. [2018-11-14 19:06:15,257 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2018-11-14 19:06:15,258 INFO L93 Difference]: Finished difference Result 285 states and 422 transitions. [2018-11-14 19:06:15,258 INFO L142 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 4 states. [2018-11-14 19:06:15,258 INFO L78 Accepts]: Start accepts. Automaton has 4 states. Word has length 69 [2018-11-14 19:06:15,258 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2018-11-14 19:06:15,258 INFO L82 GeneralOperation]: Start removeUnreachable. Operand 4 states. [2018-11-14 19:06:15,261 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 4 states to 4 states and 422 transitions. [2018-11-14 19:06:15,262 INFO L82 GeneralOperation]: Start removeUnreachable. Operand 4 states. [2018-11-14 19:06:15,265 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 4 states to 4 states and 422 transitions. [2018-11-14 19:06:15,265 INFO L86 InductivityCheck]: Starting indutivity check of a Floyd-Hoare automaton with 4 states and 422 transitions. [2018-11-14 19:06:16,298 INFO L119 InductivityCheck]: Floyd-Hoare automaton has 422 edges. 422 inductive. 0 not inductive. 0 times theorem prover too weak to decide inductivity. [2018-11-14 19:06:16,301 INFO L225 Difference]: With dead ends: 285 [2018-11-14 19:06:16,301 INFO L226 Difference]: Without dead ends: 162 [2018-11-14 19:06:16,302 INFO L604 BasicCegarLoop]: 0 DeclaredPredicates, 7 GetRequests, 2 SyntacticMatches, 2 SemanticMatches, 3 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 0 ImplicationChecksByTransitivity, 0.4s TimeCoverageRelationStatistics Valid=9, Invalid=11, Unknown=0, NotChecked=0, Total=20 [2018-11-14 19:06:16,302 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 162 states. [2018-11-14 19:06:16,320 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 162 to 149. [2018-11-14 19:06:16,321 INFO L214 AbstractMinimizeNwa]: Start testing correctness of minimizeSevpa [2018-11-14 19:06:16,321 INFO L82 GeneralOperation]: Start isEquivalent. First operand 162 states. Second operand 149 states. [2018-11-14 19:06:16,321 INFO L74 IsIncluded]: Start isIncluded. First operand 162 states. Second operand 149 states. [2018-11-14 19:06:16,321 INFO L87 Difference]: Start difference. First operand 162 states. Second operand 149 states. [2018-11-14 19:06:16,325 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2018-11-14 19:06:16,326 INFO L93 Difference]: Finished difference Result 162 states and 234 transitions. [2018-11-14 19:06:16,326 INFO L276 IsEmpty]: Start isEmpty. Operand 162 states and 234 transitions. [2018-11-14 19:06:16,326 INFO L282 IsEmpty]: Finished isEmpty. No accepting run. [2018-11-14 19:06:16,327 INFO L83 IsIncluded]: Finished isIncluded. Language is included [2018-11-14 19:06:16,327 INFO L74 IsIncluded]: Start isIncluded. First operand 149 states. Second operand 162 states. [2018-11-14 19:06:16,327 INFO L87 Difference]: Start difference. First operand 149 states. Second operand 162 states. [2018-11-14 19:06:16,331 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2018-11-14 19:06:16,331 INFO L93 Difference]: Finished difference Result 162 states and 234 transitions. [2018-11-14 19:06:16,331 INFO L276 IsEmpty]: Start isEmpty. Operand 162 states and 234 transitions. [2018-11-14 19:06:16,332 INFO L282 IsEmpty]: Finished isEmpty. No accepting run. [2018-11-14 19:06:16,332 INFO L83 IsIncluded]: Finished isIncluded. Language is included [2018-11-14 19:06:16,332 INFO L88 GeneralOperation]: Finished isEquivalent. [2018-11-14 19:06:16,332 INFO L221 AbstractMinimizeNwa]: Finished testing correctness of minimizeSevpa [2018-11-14 19:06:16,332 INFO L82 GeneralOperation]: Start removeUnreachable. Operand 149 states. [2018-11-14 19:06:16,335 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 149 states to 149 states and 217 transitions. [2018-11-14 19:06:16,335 INFO L78 Accepts]: Start accepts. Automaton has 149 states and 217 transitions. Word has length 69 [2018-11-14 19:06:16,336 INFO L84 Accepts]: Finished accepts. word is rejected. [2018-11-14 19:06:16,336 INFO L480 AbstractCegarLoop]: Abstraction has 149 states and 217 transitions. [2018-11-14 19:06:16,336 INFO L481 AbstractCegarLoop]: Interpolant automaton has 4 states. [2018-11-14 19:06:16,336 INFO L276 IsEmpty]: Start isEmpty. Operand 149 states and 217 transitions. [2018-11-14 19:06:16,337 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 71 [2018-11-14 19:06:16,337 INFO L367 BasicCegarLoop]: Found error trace [2018-11-14 19:06:16,337 INFO L375 BasicCegarLoop]: trace histogram [2, 2, 2, 2, 2, 2, 2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2018-11-14 19:06:16,337 INFO L423 AbstractCegarLoop]: === Iteration 9 === [ssl3_acceptErr0ASSERT_VIOLATIONERROR_FUNCTION]=== [2018-11-14 19:06:16,338 INFO L141 PredicateUnifier]: Initialized classic predicate unifier [2018-11-14 19:06:16,338 INFO L82 PathProgramCache]: Analyzing trace with hash 1697086567, now seen corresponding path program 1 times [2018-11-14 19:06:16,338 INFO L223 ckRefinementStrategy]: Switched to mode SMTINTERPOL_TREE_INTERPOLANTS [2018-11-14 19:06:16,338 INFO L69 tionRefinementEngine]: Using refinement strategy CamelRefinementStrategy [2018-11-14 19:06:16,339 INFO L119 rtionOrderModulation]: Craig_TreeInterpolation forces the order to NOT_INCREMENTALLY [2018-11-14 19:06:16,339 INFO L103 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2018-11-14 19:06:16,339 INFO L119 rtionOrderModulation]: Craig_TreeInterpolation forces the order to NOT_INCREMENTALLY [2018-11-14 19:06:16,356 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2018-11-14 19:06:16,861 INFO L256 TraceCheckUtils]: 0: Hoare triple {7064#true} call ULTIMATE.init(); {7064#true} is VALID [2018-11-14 19:06:16,861 INFO L273 TraceCheckUtils]: 1: Hoare triple {7064#true} #NULL.base, #NULL.offset := 0, 0;#valid := #valid[0 := 0];~init~0 := 1;call ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset := #Ultimate.alloc(100);call write~unchecked~int(0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 0, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 4, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 8, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 12, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 16, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 20, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 24, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 28, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 32, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 36, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 40, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 44, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 48, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 52, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 56, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 60, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 64, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 68, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 72, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 76, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 80, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 84, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 88, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 92, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 96, 4);call write~unchecked~int(0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 0, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 4, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 8, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 12, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 16, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 20, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 24, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 28, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 32, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 36, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 40, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 44, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 48, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 52, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 56, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 60, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 64, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 68, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 72, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 76, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 80, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 84, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 88, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 92, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 96, 4); {7064#true} is VALID [2018-11-14 19:06:16,861 INFO L273 TraceCheckUtils]: 2: Hoare triple {7064#true} assume true; {7064#true} is VALID [2018-11-14 19:06:16,862 INFO L268 TraceCheckUtils]: 3: Hoare quadruple {7064#true} {7064#true} #654#return; {7064#true} is VALID [2018-11-14 19:06:16,862 INFO L256 TraceCheckUtils]: 4: Hoare triple {7064#true} call #t~ret138 := main(); {7064#true} is VALID [2018-11-14 19:06:16,862 INFO L273 TraceCheckUtils]: 5: Hoare triple {7064#true} havoc ~s~0.base, ~s~0.offset;havoc ~tmp~2;call #t~malloc3.base, #t~malloc3.offset := #Ultimate.alloc(248);~s~0.base, ~s~0.offset := #t~malloc3.base, #t~malloc3.offset;call #t~malloc4.base, #t~malloc4.offset := #Ultimate.alloc(899);call write~$Pointer$(#t~malloc4.base, #t~malloc4.offset, ~s~0.base, ~s~0.offset + 84, 4);call #t~malloc5.base, #t~malloc5.offset := #Ultimate.alloc(232);call write~$Pointer$(#t~malloc5.base, #t~malloc5.offset, ~s~0.base, ~s~0.offset + 204, 4);call #t~malloc6.base, #t~malloc6.offset := #Ultimate.alloc(200);call write~$Pointer$(#t~malloc6.base, #t~malloc6.offset, ~s~0.base, ~s~0.offset + 176, 4);call write~int(8464, ~s~0.base, ~s~0.offset + 52, 4); {7064#true} is VALID [2018-11-14 19:06:16,862 INFO L256 TraceCheckUtils]: 6: Hoare triple {7064#true} call #t~ret7 := ssl3_accept(~s~0.base, ~s~0.offset); {7064#true} is VALID [2018-11-14 19:06:16,864 INFO L273 TraceCheckUtils]: 7: Hoare triple {7064#true} ~s.base, ~s.offset := #in~s.base, #in~s.offset;havoc ~buf~0.base, ~buf~0.offset;havoc ~l~0;havoc ~Time~0;havoc ~tmp~3;havoc ~cb~0.base, ~cb~0.offset;havoc ~num1~0;havoc ~ret~0;havoc ~new_state~0;havoc ~state~0;havoc ~skip~0;havoc ~got_new_session~0;assume -2147483648 <= #t~nondet8 && #t~nondet8 <= 2147483647;~tmp___1~0 := #t~nondet8;havoc #t~nondet8;assume -2147483648 <= #t~nondet9 && #t~nondet9 <= 2147483647;~tmp___2~0 := #t~nondet9;havoc #t~nondet9;assume -2147483648 <= #t~nondet10 && #t~nondet10 <= 2147483647;~tmp___3~0 := #t~nondet10;havoc #t~nondet10;assume -2147483648 <= #t~nondet11 && #t~nondet11 <= 2147483647;~tmp___4~0 := #t~nondet11;havoc #t~nondet11;assume -2147483648 <= #t~nondet12 && #t~nondet12 <= 2147483647;~tmp___5~0 := #t~nondet12;havoc #t~nondet12;assume -2147483648 <= #t~nondet13 && #t~nondet13 <= 2147483647;~tmp___6~0 := #t~nondet13;havoc #t~nondet13;havoc ~tmp___7~0;assume -2147483648 <= #t~nondet14 && #t~nondet14 <= 2147483647;~tmp___8~0 := #t~nondet14;havoc #t~nondet14;assume -2147483648 <= #t~nondet15 && #t~nondet15 <= 2147483647;~tmp___9~0 := #t~nondet15;havoc #t~nondet15;assume -2147483648 <= #t~nondet16 && #t~nondet16 <= 2147483647;~tmp___10~0 := #t~nondet16;havoc #t~nondet16;havoc ~blastFlag~0;~blastFlag~0 := 0;assume -2147483648 <= #t~nondet17 && #t~nondet17 <= 2147483647;call write~int(#t~nondet17, ~s.base, ~s.offset + 92, 4);havoc #t~nondet17;call write~int(8464, ~s.base, ~s.offset + 52, 4);assume -2147483648 <= #t~nondet18 && #t~nondet18 <= 2147483647;~tmp~3 := #t~nondet18;havoc #t~nondet18;~Time~0 := ~tmp~3;~cb~0.base, ~cb~0.offset := 0, 0;~ret~0 := -1;~skip~0 := 0;~got_new_session~0 := 0;call #t~mem19.base, #t~mem19.offset := read~$Pointer$(~s.base, ~s.offset + 192, 4); {7066#(= (select (store (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 28) (+ (select (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 28)) 1)) (+ ssl3_accept_~s.offset 52)) 8464)} is VALID [2018-11-14 19:06:16,864 INFO L273 TraceCheckUtils]: 8: Hoare triple {7066#(= (select (store (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 28) (+ (select (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 28)) 1)) (+ ssl3_accept_~s.offset 52)) 8464)} assume (#t~mem19.base + #t~mem19.offset) % 4294967296 != 0;havoc #t~mem19.base, #t~mem19.offset;call #t~mem20.base, #t~mem20.offset := read~$Pointer$(~s.base, ~s.offset + 192, 4);~cb~0.base, ~cb~0.offset := #t~mem20.base, #t~mem20.offset;havoc #t~mem20.base, #t~mem20.offset; {7066#(= (select (store (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 28) (+ (select (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 28)) 1)) (+ ssl3_accept_~s.offset 52)) 8464)} is VALID [2018-11-14 19:06:16,865 INFO L273 TraceCheckUtils]: 9: Hoare triple {7066#(= (select (store (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 28) (+ (select (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 28)) 1)) (+ ssl3_accept_~s.offset 52)) 8464)} call #t~mem21 := read~int(~s.base, ~s.offset + 28, 4);call write~int(#t~mem21 + 1, ~s.base, ~s.offset + 28, 4);havoc #t~mem21; {7066#(= (select (store (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 28) (+ (select (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 28)) 1)) (+ ssl3_accept_~s.offset 52)) 8464)} is VALID [2018-11-14 19:06:16,865 INFO L273 TraceCheckUtils]: 10: Hoare triple {7066#(= (select (store (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 28) (+ (select (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 28)) 1)) (+ ssl3_accept_~s.offset 52)) 8464)} assume !(~bitwiseAnd(~tmp___1~0, 12288) != 0); {7066#(= (select (store (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 28) (+ (select (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 28)) 1)) (+ ssl3_accept_~s.offset 52)) 8464)} is VALID [2018-11-14 19:06:16,865 INFO L273 TraceCheckUtils]: 11: Hoare triple {7066#(= (select (store (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 28) (+ (select (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 28)) 1)) (+ ssl3_accept_~s.offset 52)) 8464)} call #t~mem22.base, #t~mem22.offset := read~$Pointer$(~s.base, ~s.offset + 136, 4); {7066#(= (select (store (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 28) (+ (select (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 28)) 1)) (+ ssl3_accept_~s.offset 52)) 8464)} is VALID [2018-11-14 19:06:16,866 INFO L273 TraceCheckUtils]: 12: Hoare triple {7066#(= (select (store (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 28) (+ (select (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 28)) 1)) (+ ssl3_accept_~s.offset 52)) 8464)} assume !((#t~mem22.base + #t~mem22.offset) % 4294967296 == 0);havoc #t~mem22.base, #t~mem22.offset; {7066#(= (select (store (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 28) (+ (select (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 28)) 1)) (+ ssl3_accept_~s.offset 52)) 8464)} is VALID [2018-11-14 19:06:16,866 INFO L273 TraceCheckUtils]: 13: Hoare triple {7066#(= (select (store (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 28) (+ (select (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 28)) 1)) (+ ssl3_accept_~s.offset 52)) 8464)} assume true; {7066#(= (select (store (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 28) (+ (select (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 28)) 1)) (+ ssl3_accept_~s.offset 52)) 8464)} is VALID [2018-11-14 19:06:16,867 INFO L273 TraceCheckUtils]: 14: Hoare triple {7066#(= (select (store (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 28) (+ (select (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 28)) 1)) (+ ssl3_accept_~s.offset 52)) 8464)} assume !false; {7066#(= (select (store (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 28) (+ (select (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 28)) 1)) (+ ssl3_accept_~s.offset 52)) 8464)} is VALID [2018-11-14 19:06:16,867 INFO L273 TraceCheckUtils]: 15: Hoare triple {7066#(= (select (store (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 28) (+ (select (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 28)) 1)) (+ ssl3_accept_~s.offset 52)) 8464)} call #t~mem23 := read~int(~s.base, ~s.offset + 52, 4);~state~0 := #t~mem23;havoc #t~mem23;call #t~mem24 := read~int(~s.base, ~s.offset + 52, 4); {7066#(= (select (store (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 28) (+ (select (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 28)) 1)) (+ ssl3_accept_~s.offset 52)) 8464)} is VALID [2018-11-14 19:06:16,868 INFO L273 TraceCheckUtils]: 16: Hoare triple {7066#(= (select (store (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 28) (+ (select (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 28)) 1)) (+ ssl3_accept_~s.offset 52)) 8464)} assume !(#t~mem24 == 12292);havoc #t~mem24;call #t~mem25 := read~int(~s.base, ~s.offset + 52, 4); {7066#(= (select (store (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 28) (+ (select (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 28)) 1)) (+ ssl3_accept_~s.offset 52)) 8464)} is VALID [2018-11-14 19:06:16,868 INFO L273 TraceCheckUtils]: 17: Hoare triple {7066#(= (select (store (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 28) (+ (select (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 28)) 1)) (+ ssl3_accept_~s.offset 52)) 8464)} assume !(#t~mem25 == 16384);havoc #t~mem25;call #t~mem26 := read~int(~s.base, ~s.offset + 52, 4); {7066#(= (select (store (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 28) (+ (select (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 28)) 1)) (+ ssl3_accept_~s.offset 52)) 8464)} is VALID [2018-11-14 19:06:16,869 INFO L273 TraceCheckUtils]: 18: Hoare triple {7066#(= (select (store (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 28) (+ (select (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 28)) 1)) (+ ssl3_accept_~s.offset 52)) 8464)} assume !(#t~mem26 == 8192);havoc #t~mem26;call #t~mem27 := read~int(~s.base, ~s.offset + 52, 4); {7066#(= (select (store (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 28) (+ (select (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 28)) 1)) (+ ssl3_accept_~s.offset 52)) 8464)} is VALID [2018-11-14 19:06:16,870 INFO L273 TraceCheckUtils]: 19: Hoare triple {7066#(= (select (store (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 28) (+ (select (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 28)) 1)) (+ ssl3_accept_~s.offset 52)) 8464)} assume !(#t~mem27 == 24576);havoc #t~mem27;call #t~mem28 := read~int(~s.base, ~s.offset + 52, 4); {7067#(= |ssl3_accept_#t~mem28| 8464)} is VALID [2018-11-14 19:06:16,870 INFO L273 TraceCheckUtils]: 20: Hoare triple {7067#(= |ssl3_accept_#t~mem28| 8464)} assume #t~mem28 == 8195;havoc #t~mem28; {7065#false} is VALID [2018-11-14 19:06:16,871 INFO L273 TraceCheckUtils]: 21: Hoare triple {7065#false} call write~int(1, ~s.base, ~s.offset + 36, 4); {7065#false} is VALID [2018-11-14 19:06:16,871 INFO L273 TraceCheckUtils]: 22: Hoare triple {7065#false} assume (~cb~0.base + ~cb~0.offset) % 4294967296 != 0; {7065#false} is VALID [2018-11-14 19:06:16,871 INFO L273 TraceCheckUtils]: 23: Hoare triple {7065#false} call #t~mem59 := read~int(~s.base, ~s.offset + 0, 4); {7065#false} is VALID [2018-11-14 19:06:16,871 INFO L273 TraceCheckUtils]: 24: Hoare triple {7065#false} assume !(#t~mem59 / 256 != 3);havoc #t~mem59;call write~int(8192, ~s.base, ~s.offset + 4, 4);call #t~mem60.base, #t~mem60.offset := read~$Pointer$(~s.base, ~s.offset + 60, 4); {7065#false} is VALID [2018-11-14 19:06:16,871 INFO L273 TraceCheckUtils]: 25: Hoare triple {7065#false} assume !((#t~mem60.base + #t~mem60.offset) % 4294967296 == 0);havoc #t~mem60.base, #t~mem60.offset; {7065#false} is VALID [2018-11-14 19:06:16,872 INFO L273 TraceCheckUtils]: 26: Hoare triple {7065#false} assume !(~tmp___4~0 == 0);call write~int(0, ~s.base, ~s.offset + 64, 4);call #t~mem62 := read~int(~s.base, ~s.offset + 52, 4); {7065#false} is VALID [2018-11-14 19:06:16,872 INFO L273 TraceCheckUtils]: 27: Hoare triple {7065#false} assume !(#t~mem62 != 12292);havoc #t~mem62;call #t~mem65.base, #t~mem65.offset := read~$Pointer$(~s.base, ~s.offset + 204, 4);call #t~mem66 := read~int(#t~mem65.base, #t~mem65.offset + 60 + 16, 4);call write~int(#t~mem66 + 1, #t~mem65.base, #t~mem65.offset + 60 + 16, 4);havoc #t~mem66;havoc #t~mem65.base, #t~mem65.offset;call write~int(8480, ~s.base, ~s.offset + 52, 4); {7065#false} is VALID [2018-11-14 19:06:16,872 INFO L273 TraceCheckUtils]: 28: Hoare triple {7065#false} call #t~mem127.base, #t~mem127.offset := read~$Pointer$(~s.base, ~s.offset + 84, 4);call #t~mem128 := read~int(#t~mem127.base, #t~mem127.offset + 604 + 244, 4); {7065#false} is VALID [2018-11-14 19:06:16,872 INFO L273 TraceCheckUtils]: 29: Hoare triple {7065#false} assume !(#t~mem128 == 0);havoc #t~mem127.base, #t~mem127.offset;havoc #t~mem128; {7065#false} is VALID [2018-11-14 19:06:16,873 INFO L273 TraceCheckUtils]: 30: Hoare triple {7065#false} ~skip~0 := 0; {7065#false} is VALID [2018-11-14 19:06:16,873 INFO L273 TraceCheckUtils]: 31: Hoare triple {7065#false} assume true; {7065#false} is VALID [2018-11-14 19:06:16,873 INFO L273 TraceCheckUtils]: 32: Hoare triple {7065#false} assume !false; {7065#false} is VALID [2018-11-14 19:06:16,873 INFO L273 TraceCheckUtils]: 33: Hoare triple {7065#false} call #t~mem23 := read~int(~s.base, ~s.offset + 52, 4);~state~0 := #t~mem23;havoc #t~mem23;call #t~mem24 := read~int(~s.base, ~s.offset + 52, 4); {7065#false} is VALID [2018-11-14 19:06:16,873 INFO L273 TraceCheckUtils]: 34: Hoare triple {7065#false} assume !(#t~mem24 == 12292);havoc #t~mem24;call #t~mem25 := read~int(~s.base, ~s.offset + 52, 4); {7065#false} is VALID [2018-11-14 19:06:16,874 INFO L273 TraceCheckUtils]: 35: Hoare triple {7065#false} assume !(#t~mem25 == 16384);havoc #t~mem25;call #t~mem26 := read~int(~s.base, ~s.offset + 52, 4); {7065#false} is VALID [2018-11-14 19:06:16,874 INFO L273 TraceCheckUtils]: 36: Hoare triple {7065#false} assume !(#t~mem26 == 8192);havoc #t~mem26;call #t~mem27 := read~int(~s.base, ~s.offset + 52, 4); {7065#false} is VALID [2018-11-14 19:06:16,874 INFO L273 TraceCheckUtils]: 37: Hoare triple {7065#false} assume !(#t~mem27 == 24576);havoc #t~mem27;call #t~mem28 := read~int(~s.base, ~s.offset + 52, 4); {7065#false} is VALID [2018-11-14 19:06:16,874 INFO L273 TraceCheckUtils]: 38: Hoare triple {7065#false} assume !(#t~mem28 == 8195);havoc #t~mem28;call #t~mem29 := read~int(~s.base, ~s.offset + 52, 4); {7065#false} is VALID [2018-11-14 19:06:16,874 INFO L273 TraceCheckUtils]: 39: Hoare triple {7065#false} assume !(#t~mem29 == 8480);havoc #t~mem29;call #t~mem30 := read~int(~s.base, ~s.offset + 52, 4); {7065#false} is VALID [2018-11-14 19:06:16,874 INFO L273 TraceCheckUtils]: 40: Hoare triple {7065#false} assume !(#t~mem30 == 8481);havoc #t~mem30;call #t~mem31 := read~int(~s.base, ~s.offset + 52, 4); {7065#false} is VALID [2018-11-14 19:06:16,874 INFO L273 TraceCheckUtils]: 41: Hoare triple {7065#false} assume !(#t~mem31 == 8482);havoc #t~mem31;call #t~mem32 := read~int(~s.base, ~s.offset + 52, 4); {7065#false} is VALID [2018-11-14 19:06:16,875 INFO L273 TraceCheckUtils]: 42: Hoare triple {7065#false} assume !(#t~mem32 == 8464);havoc #t~mem32;call #t~mem33 := read~int(~s.base, ~s.offset + 52, 4); {7065#false} is VALID [2018-11-14 19:06:16,875 INFO L273 TraceCheckUtils]: 43: Hoare triple {7065#false} assume !(#t~mem33 == 8465);havoc #t~mem33;call #t~mem34 := read~int(~s.base, ~s.offset + 52, 4); {7065#false} is VALID [2018-11-14 19:06:16,875 INFO L273 TraceCheckUtils]: 44: Hoare triple {7065#false} assume !(#t~mem34 == 8466);havoc #t~mem34;call #t~mem35 := read~int(~s.base, ~s.offset + 52, 4); {7065#false} is VALID [2018-11-14 19:06:16,875 INFO L273 TraceCheckUtils]: 45: Hoare triple {7065#false} assume !(#t~mem35 == 8496);havoc #t~mem35;call #t~mem36 := read~int(~s.base, ~s.offset + 52, 4); {7065#false} is VALID [2018-11-14 19:06:16,875 INFO L273 TraceCheckUtils]: 46: Hoare triple {7065#false} assume !(#t~mem36 == 8497);havoc #t~mem36;call #t~mem37 := read~int(~s.base, ~s.offset + 52, 4); {7065#false} is VALID [2018-11-14 19:06:16,875 INFO L273 TraceCheckUtils]: 47: Hoare triple {7065#false} assume !(#t~mem37 == 8512);havoc #t~mem37;call #t~mem38 := read~int(~s.base, ~s.offset + 52, 4); {7065#false} is VALID [2018-11-14 19:06:16,875 INFO L273 TraceCheckUtils]: 48: Hoare triple {7065#false} assume !(#t~mem38 == 8513);havoc #t~mem38;call #t~mem39 := read~int(~s.base, ~s.offset + 52, 4); {7065#false} is VALID [2018-11-14 19:06:16,876 INFO L273 TraceCheckUtils]: 49: Hoare triple {7065#false} assume !(#t~mem39 == 8528);havoc #t~mem39;call #t~mem40 := read~int(~s.base, ~s.offset + 52, 4); {7065#false} is VALID [2018-11-14 19:06:16,876 INFO L273 TraceCheckUtils]: 50: Hoare triple {7065#false} assume !(#t~mem40 == 8529);havoc #t~mem40;call #t~mem41 := read~int(~s.base, ~s.offset + 52, 4); {7065#false} is VALID [2018-11-14 19:06:16,876 INFO L273 TraceCheckUtils]: 51: Hoare triple {7065#false} assume !(#t~mem41 == 8544);havoc #t~mem41;call #t~mem42 := read~int(~s.base, ~s.offset + 52, 4); {7065#false} is VALID [2018-11-14 19:06:16,876 INFO L273 TraceCheckUtils]: 52: Hoare triple {7065#false} assume !(#t~mem42 == 8545);havoc #t~mem42;call #t~mem43 := read~int(~s.base, ~s.offset + 52, 4); {7065#false} is VALID [2018-11-14 19:06:16,876 INFO L273 TraceCheckUtils]: 53: Hoare triple {7065#false} assume !(#t~mem43 == 8560);havoc #t~mem43;call #t~mem44 := read~int(~s.base, ~s.offset + 52, 4); {7065#false} is VALID [2018-11-14 19:06:16,876 INFO L273 TraceCheckUtils]: 54: Hoare triple {7065#false} assume !(#t~mem44 == 8561);havoc #t~mem44;call #t~mem45 := read~int(~s.base, ~s.offset + 52, 4); {7065#false} is VALID [2018-11-14 19:06:16,876 INFO L273 TraceCheckUtils]: 55: Hoare triple {7065#false} assume !(#t~mem45 == 8448);havoc #t~mem45;call #t~mem46 := read~int(~s.base, ~s.offset + 52, 4); {7065#false} is VALID [2018-11-14 19:06:16,876 INFO L273 TraceCheckUtils]: 56: Hoare triple {7065#false} assume !(#t~mem46 == 8576);havoc #t~mem46;call #t~mem47 := read~int(~s.base, ~s.offset + 52, 4); {7065#false} is VALID [2018-11-14 19:06:16,877 INFO L273 TraceCheckUtils]: 57: Hoare triple {7065#false} assume !(#t~mem47 == 8577);havoc #t~mem47;call #t~mem48 := read~int(~s.base, ~s.offset + 52, 4); {7065#false} is VALID [2018-11-14 19:06:16,877 INFO L273 TraceCheckUtils]: 58: Hoare triple {7065#false} assume !(#t~mem48 == 8592);havoc #t~mem48;call #t~mem49 := read~int(~s.base, ~s.offset + 52, 4); {7065#false} is VALID [2018-11-14 19:06:16,877 INFO L273 TraceCheckUtils]: 59: Hoare triple {7065#false} assume !(#t~mem49 == 8593);havoc #t~mem49;call #t~mem50 := read~int(~s.base, ~s.offset + 52, 4); {7065#false} is VALID [2018-11-14 19:06:16,877 INFO L273 TraceCheckUtils]: 60: Hoare triple {7065#false} assume !(#t~mem50 == 8608);havoc #t~mem50;call #t~mem51 := read~int(~s.base, ~s.offset + 52, 4); {7065#false} is VALID [2018-11-14 19:06:16,877 INFO L273 TraceCheckUtils]: 61: Hoare triple {7065#false} assume !(#t~mem51 == 8609);havoc #t~mem51;call #t~mem52 := read~int(~s.base, ~s.offset + 52, 4); {7065#false} is VALID [2018-11-14 19:06:16,877 INFO L273 TraceCheckUtils]: 62: Hoare triple {7065#false} assume !(#t~mem52 == 8640);havoc #t~mem52;call #t~mem53 := read~int(~s.base, ~s.offset + 52, 4); {7065#false} is VALID [2018-11-14 19:06:16,877 INFO L273 TraceCheckUtils]: 63: Hoare triple {7065#false} assume !(#t~mem53 == 8641);havoc #t~mem53;call #t~mem54 := read~int(~s.base, ~s.offset + 52, 4); {7065#false} is VALID [2018-11-14 19:06:16,878 INFO L273 TraceCheckUtils]: 64: Hoare triple {7065#false} assume !(#t~mem54 == 8656);havoc #t~mem54;call #t~mem55 := read~int(~s.base, ~s.offset + 52, 4); {7065#false} is VALID [2018-11-14 19:06:16,878 INFO L273 TraceCheckUtils]: 65: Hoare triple {7065#false} assume !(#t~mem55 == 8657);havoc #t~mem55;call #t~mem56 := read~int(~s.base, ~s.offset + 52, 4); {7065#false} is VALID [2018-11-14 19:06:16,878 INFO L273 TraceCheckUtils]: 66: Hoare triple {7065#false} assume #t~mem56 == 8672;havoc #t~mem56; {7065#false} is VALID [2018-11-14 19:06:16,878 INFO L273 TraceCheckUtils]: 67: Hoare triple {7065#false} assume -2147483648 <= #t~nondet121 && #t~nondet121 <= 2147483647;~ret~0 := #t~nondet121;havoc #t~nondet121; {7065#false} is VALID [2018-11-14 19:06:16,878 INFO L273 TraceCheckUtils]: 68: Hoare triple {7065#false} assume ~blastFlag~0 == 4; {7065#false} is VALID [2018-11-14 19:06:16,878 INFO L273 TraceCheckUtils]: 69: Hoare triple {7065#false} assume !false; {7065#false} is VALID [2018-11-14 19:06:16,884 INFO L134 CoverageAnalysis]: Checked inductivity of 8 backedges. 8 proven. 0 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2018-11-14 19:06:16,885 INFO L312 seRefinementStrategy]: Constructing automaton from 1 perfect and 0 imperfect interpolant sequences. [2018-11-14 19:06:16,885 INFO L327 seRefinementStrategy]: Number of different interpolants: perfect sequences [4] imperfect sequences [] total 4 [2018-11-14 19:06:16,885 INFO L78 Accepts]: Start accepts. Automaton has 4 states. Word has length 70 [2018-11-14 19:06:16,885 INFO L84 Accepts]: Finished accepts. word is accepted. [2018-11-14 19:06:16,885 INFO L86 InductivityCheck]: Starting indutivity check of a Floyd-Hoare automaton with 4 states. [2018-11-14 19:06:17,051 INFO L119 InductivityCheck]: Floyd-Hoare automaton has 70 edges. 70 inductive. 0 not inductive. 0 times theorem prover too weak to decide inductivity. [2018-11-14 19:06:17,051 INFO L459 AbstractCegarLoop]: Interpolant automaton has 4 states [2018-11-14 19:06:17,051 INFO L142 InterpolantAutomaton]: Constructing interpolant automaton starting with 4 interpolants. [2018-11-14 19:06:17,052 INFO L144 InterpolantAutomaton]: CoverageRelationStatistics Valid=5, Invalid=7, Unknown=0, NotChecked=0, Total=12 [2018-11-14 19:06:17,052 INFO L87 Difference]: Start difference. First operand 149 states and 217 transitions. Second operand 4 states. [2018-11-14 19:06:18,646 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2018-11-14 19:06:18,647 INFO L93 Difference]: Finished difference Result 275 states and 408 transitions. [2018-11-14 19:06:18,647 INFO L142 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 4 states. [2018-11-14 19:06:18,647 INFO L78 Accepts]: Start accepts. Automaton has 4 states. Word has length 70 [2018-11-14 19:06:18,647 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2018-11-14 19:06:18,647 INFO L82 GeneralOperation]: Start removeUnreachable. Operand 4 states. [2018-11-14 19:06:18,650 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 4 states to 4 states and 408 transitions. [2018-11-14 19:06:18,651 INFO L82 GeneralOperation]: Start removeUnreachable. Operand 4 states. [2018-11-14 19:06:18,654 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 4 states to 4 states and 408 transitions. [2018-11-14 19:06:18,654 INFO L86 InductivityCheck]: Starting indutivity check of a Floyd-Hoare automaton with 4 states and 408 transitions. [2018-11-14 19:06:19,679 INFO L119 InductivityCheck]: Floyd-Hoare automaton has 408 edges. 408 inductive. 0 not inductive. 0 times theorem prover too weak to decide inductivity. [2018-11-14 19:06:19,682 INFO L225 Difference]: With dead ends: 275 [2018-11-14 19:06:19,682 INFO L226 Difference]: Without dead ends: 152 [2018-11-14 19:06:19,683 INFO L604 BasicCegarLoop]: 0 DeclaredPredicates, 7 GetRequests, 2 SyntacticMatches, 2 SemanticMatches, 3 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 0 ImplicationChecksByTransitivity, 0.2s TimeCoverageRelationStatistics Valid=9, Invalid=11, Unknown=0, NotChecked=0, Total=20 [2018-11-14 19:06:19,683 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 152 states. [2018-11-14 19:06:19,706 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 152 to 149. [2018-11-14 19:06:19,706 INFO L214 AbstractMinimizeNwa]: Start testing correctness of minimizeSevpa [2018-11-14 19:06:19,706 INFO L82 GeneralOperation]: Start isEquivalent. First operand 152 states. Second operand 149 states. [2018-11-14 19:06:19,706 INFO L74 IsIncluded]: Start isIncluded. First operand 152 states. Second operand 149 states. [2018-11-14 19:06:19,707 INFO L87 Difference]: Start difference. First operand 152 states. Second operand 149 states. [2018-11-14 19:06:19,711 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2018-11-14 19:06:19,711 INFO L93 Difference]: Finished difference Result 152 states and 220 transitions. [2018-11-14 19:06:19,712 INFO L276 IsEmpty]: Start isEmpty. Operand 152 states and 220 transitions. [2018-11-14 19:06:19,712 INFO L282 IsEmpty]: Finished isEmpty. No accepting run. [2018-11-14 19:06:19,712 INFO L83 IsIncluded]: Finished isIncluded. Language is included [2018-11-14 19:06:19,712 INFO L74 IsIncluded]: Start isIncluded. First operand 149 states. Second operand 152 states. [2018-11-14 19:06:19,713 INFO L87 Difference]: Start difference. First operand 149 states. Second operand 152 states. [2018-11-14 19:06:19,715 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2018-11-14 19:06:19,716 INFO L93 Difference]: Finished difference Result 152 states and 220 transitions. [2018-11-14 19:06:19,716 INFO L276 IsEmpty]: Start isEmpty. Operand 152 states and 220 transitions. [2018-11-14 19:06:19,716 INFO L282 IsEmpty]: Finished isEmpty. No accepting run. [2018-11-14 19:06:19,716 INFO L83 IsIncluded]: Finished isIncluded. Language is included [2018-11-14 19:06:19,717 INFO L88 GeneralOperation]: Finished isEquivalent. [2018-11-14 19:06:19,717 INFO L221 AbstractMinimizeNwa]: Finished testing correctness of minimizeSevpa [2018-11-14 19:06:19,717 INFO L82 GeneralOperation]: Start removeUnreachable. Operand 149 states. [2018-11-14 19:06:19,719 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 149 states to 149 states and 216 transitions. [2018-11-14 19:06:19,720 INFO L78 Accepts]: Start accepts. Automaton has 149 states and 216 transitions. Word has length 70 [2018-11-14 19:06:19,720 INFO L84 Accepts]: Finished accepts. word is rejected. [2018-11-14 19:06:19,720 INFO L480 AbstractCegarLoop]: Abstraction has 149 states and 216 transitions. [2018-11-14 19:06:19,720 INFO L481 AbstractCegarLoop]: Interpolant automaton has 4 states. [2018-11-14 19:06:19,720 INFO L276 IsEmpty]: Start isEmpty. Operand 149 states and 216 transitions. [2018-11-14 19:06:19,721 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 71 [2018-11-14 19:06:19,721 INFO L367 BasicCegarLoop]: Found error trace [2018-11-14 19:06:19,721 INFO L375 BasicCegarLoop]: trace histogram [2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2018-11-14 19:06:19,721 INFO L423 AbstractCegarLoop]: === Iteration 10 === [ssl3_acceptErr0ASSERT_VIOLATIONERROR_FUNCTION]=== [2018-11-14 19:06:19,722 INFO L141 PredicateUnifier]: Initialized classic predicate unifier [2018-11-14 19:06:19,722 INFO L82 PathProgramCache]: Analyzing trace with hash 33530782, now seen corresponding path program 1 times [2018-11-14 19:06:19,722 INFO L223 ckRefinementStrategy]: Switched to mode SMTINTERPOL_TREE_INTERPOLANTS [2018-11-14 19:06:19,722 INFO L69 tionRefinementEngine]: Using refinement strategy CamelRefinementStrategy [2018-11-14 19:06:19,723 INFO L119 rtionOrderModulation]: Craig_TreeInterpolation forces the order to NOT_INCREMENTALLY [2018-11-14 19:06:19,723 INFO L103 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2018-11-14 19:06:19,723 INFO L119 rtionOrderModulation]: Craig_TreeInterpolation forces the order to NOT_INCREMENTALLY [2018-11-14 19:06:19,740 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2018-11-14 19:06:19,855 INFO L256 TraceCheckUtils]: 0: Hoare triple {7884#true} call ULTIMATE.init(); {7884#true} is VALID [2018-11-14 19:06:19,855 INFO L273 TraceCheckUtils]: 1: Hoare triple {7884#true} #NULL.base, #NULL.offset := 0, 0;#valid := #valid[0 := 0];~init~0 := 1;call ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset := #Ultimate.alloc(100);call write~unchecked~int(0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 0, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 4, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 8, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 12, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 16, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 20, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 24, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 28, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 32, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 36, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 40, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 44, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 48, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 52, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 56, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 60, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 64, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 68, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 72, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 76, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 80, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 84, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 88, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 92, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 96, 4);call write~unchecked~int(0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 0, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 4, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 8, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 12, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 16, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 20, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 24, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 28, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 32, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 36, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 40, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 44, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 48, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 52, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 56, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 60, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 64, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 68, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 72, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 76, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 80, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 84, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 88, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 92, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 96, 4); {7884#true} is VALID [2018-11-14 19:06:19,855 INFO L273 TraceCheckUtils]: 2: Hoare triple {7884#true} assume true; {7884#true} is VALID [2018-11-14 19:06:19,855 INFO L268 TraceCheckUtils]: 3: Hoare quadruple {7884#true} {7884#true} #654#return; {7884#true} is VALID [2018-11-14 19:06:19,855 INFO L256 TraceCheckUtils]: 4: Hoare triple {7884#true} call #t~ret138 := main(); {7884#true} is VALID [2018-11-14 19:06:19,856 INFO L273 TraceCheckUtils]: 5: Hoare triple {7884#true} havoc ~s~0.base, ~s~0.offset;havoc ~tmp~2;call #t~malloc3.base, #t~malloc3.offset := #Ultimate.alloc(248);~s~0.base, ~s~0.offset := #t~malloc3.base, #t~malloc3.offset;call #t~malloc4.base, #t~malloc4.offset := #Ultimate.alloc(899);call write~$Pointer$(#t~malloc4.base, #t~malloc4.offset, ~s~0.base, ~s~0.offset + 84, 4);call #t~malloc5.base, #t~malloc5.offset := #Ultimate.alloc(232);call write~$Pointer$(#t~malloc5.base, #t~malloc5.offset, ~s~0.base, ~s~0.offset + 204, 4);call #t~malloc6.base, #t~malloc6.offset := #Ultimate.alloc(200);call write~$Pointer$(#t~malloc6.base, #t~malloc6.offset, ~s~0.base, ~s~0.offset + 176, 4);call write~int(8464, ~s~0.base, ~s~0.offset + 52, 4); {7884#true} is VALID [2018-11-14 19:06:19,856 INFO L256 TraceCheckUtils]: 6: Hoare triple {7884#true} call #t~ret7 := ssl3_accept(~s~0.base, ~s~0.offset); {7884#true} is VALID [2018-11-14 19:06:19,856 INFO L273 TraceCheckUtils]: 7: Hoare triple {7884#true} ~s.base, ~s.offset := #in~s.base, #in~s.offset;havoc ~buf~0.base, ~buf~0.offset;havoc ~l~0;havoc ~Time~0;havoc ~tmp~3;havoc ~cb~0.base, ~cb~0.offset;havoc ~num1~0;havoc ~ret~0;havoc ~new_state~0;havoc ~state~0;havoc ~skip~0;havoc ~got_new_session~0;assume -2147483648 <= #t~nondet8 && #t~nondet8 <= 2147483647;~tmp___1~0 := #t~nondet8;havoc #t~nondet8;assume -2147483648 <= #t~nondet9 && #t~nondet9 <= 2147483647;~tmp___2~0 := #t~nondet9;havoc #t~nondet9;assume -2147483648 <= #t~nondet10 && #t~nondet10 <= 2147483647;~tmp___3~0 := #t~nondet10;havoc #t~nondet10;assume -2147483648 <= #t~nondet11 && #t~nondet11 <= 2147483647;~tmp___4~0 := #t~nondet11;havoc #t~nondet11;assume -2147483648 <= #t~nondet12 && #t~nondet12 <= 2147483647;~tmp___5~0 := #t~nondet12;havoc #t~nondet12;assume -2147483648 <= #t~nondet13 && #t~nondet13 <= 2147483647;~tmp___6~0 := #t~nondet13;havoc #t~nondet13;havoc ~tmp___7~0;assume -2147483648 <= #t~nondet14 && #t~nondet14 <= 2147483647;~tmp___8~0 := #t~nondet14;havoc #t~nondet14;assume -2147483648 <= #t~nondet15 && #t~nondet15 <= 2147483647;~tmp___9~0 := #t~nondet15;havoc #t~nondet15;assume -2147483648 <= #t~nondet16 && #t~nondet16 <= 2147483647;~tmp___10~0 := #t~nondet16;havoc #t~nondet16;havoc ~blastFlag~0;~blastFlag~0 := 0;assume -2147483648 <= #t~nondet17 && #t~nondet17 <= 2147483647;call write~int(#t~nondet17, ~s.base, ~s.offset + 92, 4);havoc #t~nondet17;call write~int(8464, ~s.base, ~s.offset + 52, 4);assume -2147483648 <= #t~nondet18 && #t~nondet18 <= 2147483647;~tmp~3 := #t~nondet18;havoc #t~nondet18;~Time~0 := ~tmp~3;~cb~0.base, ~cb~0.offset := 0, 0;~ret~0 := -1;~skip~0 := 0;~got_new_session~0 := 0;call #t~mem19.base, #t~mem19.offset := read~$Pointer$(~s.base, ~s.offset + 192, 4); {7884#true} is VALID [2018-11-14 19:06:19,856 INFO L273 TraceCheckUtils]: 8: Hoare triple {7884#true} assume (#t~mem19.base + #t~mem19.offset) % 4294967296 != 0;havoc #t~mem19.base, #t~mem19.offset;call #t~mem20.base, #t~mem20.offset := read~$Pointer$(~s.base, ~s.offset + 192, 4);~cb~0.base, ~cb~0.offset := #t~mem20.base, #t~mem20.offset;havoc #t~mem20.base, #t~mem20.offset; {7884#true} is VALID [2018-11-14 19:06:19,856 INFO L273 TraceCheckUtils]: 9: Hoare triple {7884#true} call #t~mem21 := read~int(~s.base, ~s.offset + 28, 4);call write~int(#t~mem21 + 1, ~s.base, ~s.offset + 28, 4);havoc #t~mem21; {7884#true} is VALID [2018-11-14 19:06:19,856 INFO L273 TraceCheckUtils]: 10: Hoare triple {7884#true} assume !(~bitwiseAnd(~tmp___1~0, 12288) != 0); {7884#true} is VALID [2018-11-14 19:06:19,856 INFO L273 TraceCheckUtils]: 11: Hoare triple {7884#true} call #t~mem22.base, #t~mem22.offset := read~$Pointer$(~s.base, ~s.offset + 136, 4); {7884#true} is VALID [2018-11-14 19:06:19,857 INFO L273 TraceCheckUtils]: 12: Hoare triple {7884#true} assume !((#t~mem22.base + #t~mem22.offset) % 4294967296 == 0);havoc #t~mem22.base, #t~mem22.offset; {7884#true} is VALID [2018-11-14 19:06:19,857 INFO L273 TraceCheckUtils]: 13: Hoare triple {7884#true} assume true; {7884#true} is VALID [2018-11-14 19:06:19,857 INFO L273 TraceCheckUtils]: 14: Hoare triple {7884#true} assume !false; {7884#true} is VALID [2018-11-14 19:06:19,857 INFO L273 TraceCheckUtils]: 15: Hoare triple {7884#true} call #t~mem23 := read~int(~s.base, ~s.offset + 52, 4);~state~0 := #t~mem23;havoc #t~mem23;call #t~mem24 := read~int(~s.base, ~s.offset + 52, 4); {7884#true} is VALID [2018-11-14 19:06:19,857 INFO L273 TraceCheckUtils]: 16: Hoare triple {7884#true} assume !(#t~mem24 == 12292);havoc #t~mem24;call #t~mem25 := read~int(~s.base, ~s.offset + 52, 4); {7884#true} is VALID [2018-11-14 19:06:19,857 INFO L273 TraceCheckUtils]: 17: Hoare triple {7884#true} assume !(#t~mem25 == 16384);havoc #t~mem25;call #t~mem26 := read~int(~s.base, ~s.offset + 52, 4); {7884#true} is VALID [2018-11-14 19:06:19,857 INFO L273 TraceCheckUtils]: 18: Hoare triple {7884#true} assume !(#t~mem26 == 8192);havoc #t~mem26;call #t~mem27 := read~int(~s.base, ~s.offset + 52, 4); {7884#true} is VALID [2018-11-14 19:06:19,857 INFO L273 TraceCheckUtils]: 19: Hoare triple {7884#true} assume !(#t~mem27 == 24576);havoc #t~mem27;call #t~mem28 := read~int(~s.base, ~s.offset + 52, 4); {7884#true} is VALID [2018-11-14 19:06:19,858 INFO L273 TraceCheckUtils]: 20: Hoare triple {7884#true} assume !(#t~mem28 == 8195);havoc #t~mem28;call #t~mem29 := read~int(~s.base, ~s.offset + 52, 4); {7884#true} is VALID [2018-11-14 19:06:19,858 INFO L273 TraceCheckUtils]: 21: Hoare triple {7884#true} assume !(#t~mem29 == 8480);havoc #t~mem29;call #t~mem30 := read~int(~s.base, ~s.offset + 52, 4); {7884#true} is VALID [2018-11-14 19:06:19,858 INFO L273 TraceCheckUtils]: 22: Hoare triple {7884#true} assume !(#t~mem30 == 8481);havoc #t~mem30;call #t~mem31 := read~int(~s.base, ~s.offset + 52, 4); {7884#true} is VALID [2018-11-14 19:06:19,858 INFO L273 TraceCheckUtils]: 23: Hoare triple {7884#true} assume !(#t~mem31 == 8482);havoc #t~mem31;call #t~mem32 := read~int(~s.base, ~s.offset + 52, 4); {7884#true} is VALID [2018-11-14 19:06:19,858 INFO L273 TraceCheckUtils]: 24: Hoare triple {7884#true} assume #t~mem32 == 8464;havoc #t~mem32; {7884#true} is VALID [2018-11-14 19:06:19,858 INFO L273 TraceCheckUtils]: 25: Hoare triple {7884#true} call write~int(0, ~s.base, ~s.offset + 48, 4);assume -2147483648 <= #t~nondet69 && #t~nondet69 <= 2147483647;~ret~0 := #t~nondet69;havoc #t~nondet69; {7884#true} is VALID [2018-11-14 19:06:19,858 INFO L273 TraceCheckUtils]: 26: Hoare triple {7884#true} assume ~blastFlag~0 == 0;~blastFlag~0 := 1; {7884#true} is VALID [2018-11-14 19:06:19,859 INFO L273 TraceCheckUtils]: 27: Hoare triple {7884#true} assume !(~ret~0 <= 0);~got_new_session~0 := 1;call write~int(8496, ~s.base, ~s.offset + 52, 4);call write~int(0, ~s.base, ~s.offset + 64, 4); {7886#(= 8496 (select (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 52)))} is VALID [2018-11-14 19:06:19,860 INFO L273 TraceCheckUtils]: 28: Hoare triple {7886#(= 8496 (select (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 52)))} call #t~mem127.base, #t~mem127.offset := read~$Pointer$(~s.base, ~s.offset + 84, 4);call #t~mem128 := read~int(#t~mem127.base, #t~mem127.offset + 604 + 244, 4); {7886#(= 8496 (select (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 52)))} is VALID [2018-11-14 19:06:19,860 INFO L273 TraceCheckUtils]: 29: Hoare triple {7886#(= 8496 (select (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 52)))} assume !(#t~mem128 == 0);havoc #t~mem127.base, #t~mem127.offset;havoc #t~mem128; {7886#(= 8496 (select (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 52)))} is VALID [2018-11-14 19:06:19,860 INFO L273 TraceCheckUtils]: 30: Hoare triple {7886#(= 8496 (select (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 52)))} ~skip~0 := 0; {7886#(= 8496 (select (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 52)))} is VALID [2018-11-14 19:06:19,861 INFO L273 TraceCheckUtils]: 31: Hoare triple {7886#(= 8496 (select (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 52)))} assume true; {7886#(= 8496 (select (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 52)))} is VALID [2018-11-14 19:06:19,861 INFO L273 TraceCheckUtils]: 32: Hoare triple {7886#(= 8496 (select (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 52)))} assume !false; {7886#(= 8496 (select (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 52)))} is VALID [2018-11-14 19:06:19,861 INFO L273 TraceCheckUtils]: 33: Hoare triple {7886#(= 8496 (select (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 52)))} call #t~mem23 := read~int(~s.base, ~s.offset + 52, 4);~state~0 := #t~mem23;havoc #t~mem23;call #t~mem24 := read~int(~s.base, ~s.offset + 52, 4); {7886#(= 8496 (select (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 52)))} is VALID [2018-11-14 19:06:19,861 INFO L273 TraceCheckUtils]: 34: Hoare triple {7886#(= 8496 (select (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 52)))} assume !(#t~mem24 == 12292);havoc #t~mem24;call #t~mem25 := read~int(~s.base, ~s.offset + 52, 4); {7886#(= 8496 (select (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 52)))} is VALID [2018-11-14 19:06:19,862 INFO L273 TraceCheckUtils]: 35: Hoare triple {7886#(= 8496 (select (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 52)))} assume !(#t~mem25 == 16384);havoc #t~mem25;call #t~mem26 := read~int(~s.base, ~s.offset + 52, 4); {7886#(= 8496 (select (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 52)))} is VALID [2018-11-14 19:06:19,862 INFO L273 TraceCheckUtils]: 36: Hoare triple {7886#(= 8496 (select (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 52)))} assume !(#t~mem26 == 8192);havoc #t~mem26;call #t~mem27 := read~int(~s.base, ~s.offset + 52, 4); {7886#(= 8496 (select (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 52)))} is VALID [2018-11-14 19:06:19,863 INFO L273 TraceCheckUtils]: 37: Hoare triple {7886#(= 8496 (select (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 52)))} assume !(#t~mem27 == 24576);havoc #t~mem27;call #t~mem28 := read~int(~s.base, ~s.offset + 52, 4); {7886#(= 8496 (select (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 52)))} is VALID [2018-11-14 19:06:19,863 INFO L273 TraceCheckUtils]: 38: Hoare triple {7886#(= 8496 (select (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 52)))} assume !(#t~mem28 == 8195);havoc #t~mem28;call #t~mem29 := read~int(~s.base, ~s.offset + 52, 4); {7886#(= 8496 (select (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 52)))} is VALID [2018-11-14 19:06:19,864 INFO L273 TraceCheckUtils]: 39: Hoare triple {7886#(= 8496 (select (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 52)))} assume !(#t~mem29 == 8480);havoc #t~mem29;call #t~mem30 := read~int(~s.base, ~s.offset + 52, 4); {7886#(= 8496 (select (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 52)))} is VALID [2018-11-14 19:06:19,864 INFO L273 TraceCheckUtils]: 40: Hoare triple {7886#(= 8496 (select (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 52)))} assume !(#t~mem30 == 8481);havoc #t~mem30;call #t~mem31 := read~int(~s.base, ~s.offset + 52, 4); {7886#(= 8496 (select (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 52)))} is VALID [2018-11-14 19:06:19,865 INFO L273 TraceCheckUtils]: 41: Hoare triple {7886#(= 8496 (select (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 52)))} assume !(#t~mem31 == 8482);havoc #t~mem31;call #t~mem32 := read~int(~s.base, ~s.offset + 52, 4); {7886#(= 8496 (select (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 52)))} is VALID [2018-11-14 19:06:19,865 INFO L273 TraceCheckUtils]: 42: Hoare triple {7886#(= 8496 (select (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 52)))} assume !(#t~mem32 == 8464);havoc #t~mem32;call #t~mem33 := read~int(~s.base, ~s.offset + 52, 4); {7886#(= 8496 (select (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 52)))} is VALID [2018-11-14 19:06:19,883 INFO L273 TraceCheckUtils]: 43: Hoare triple {7886#(= 8496 (select (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 52)))} assume !(#t~mem33 == 8465);havoc #t~mem33;call #t~mem34 := read~int(~s.base, ~s.offset + 52, 4); {7886#(= 8496 (select (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 52)))} is VALID [2018-11-14 19:06:19,892 INFO L273 TraceCheckUtils]: 44: Hoare triple {7886#(= 8496 (select (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 52)))} assume !(#t~mem34 == 8466);havoc #t~mem34;call #t~mem35 := read~int(~s.base, ~s.offset + 52, 4); {7887#(= 8496 |ssl3_accept_#t~mem35|)} is VALID [2018-11-14 19:06:19,906 INFO L273 TraceCheckUtils]: 45: Hoare triple {7887#(= 8496 |ssl3_accept_#t~mem35|)} assume !(#t~mem35 == 8496);havoc #t~mem35;call #t~mem36 := read~int(~s.base, ~s.offset + 52, 4); {7885#false} is VALID [2018-11-14 19:06:19,906 INFO L273 TraceCheckUtils]: 46: Hoare triple {7885#false} assume !(#t~mem36 == 8497);havoc #t~mem36;call #t~mem37 := read~int(~s.base, ~s.offset + 52, 4); {7885#false} is VALID [2018-11-14 19:06:19,907 INFO L273 TraceCheckUtils]: 47: Hoare triple {7885#false} assume !(#t~mem37 == 8512);havoc #t~mem37;call #t~mem38 := read~int(~s.base, ~s.offset + 52, 4); {7885#false} is VALID [2018-11-14 19:06:19,907 INFO L273 TraceCheckUtils]: 48: Hoare triple {7885#false} assume !(#t~mem38 == 8513);havoc #t~mem38;call #t~mem39 := read~int(~s.base, ~s.offset + 52, 4); {7885#false} is VALID [2018-11-14 19:06:19,907 INFO L273 TraceCheckUtils]: 49: Hoare triple {7885#false} assume !(#t~mem39 == 8528);havoc #t~mem39;call #t~mem40 := read~int(~s.base, ~s.offset + 52, 4); {7885#false} is VALID [2018-11-14 19:06:19,907 INFO L273 TraceCheckUtils]: 50: Hoare triple {7885#false} assume !(#t~mem40 == 8529);havoc #t~mem40;call #t~mem41 := read~int(~s.base, ~s.offset + 52, 4); {7885#false} is VALID [2018-11-14 19:06:19,907 INFO L273 TraceCheckUtils]: 51: Hoare triple {7885#false} assume !(#t~mem41 == 8544);havoc #t~mem41;call #t~mem42 := read~int(~s.base, ~s.offset + 52, 4); {7885#false} is VALID [2018-11-14 19:06:19,907 INFO L273 TraceCheckUtils]: 52: Hoare triple {7885#false} assume !(#t~mem42 == 8545);havoc #t~mem42;call #t~mem43 := read~int(~s.base, ~s.offset + 52, 4); {7885#false} is VALID [2018-11-14 19:06:19,908 INFO L273 TraceCheckUtils]: 53: Hoare triple {7885#false} assume !(#t~mem43 == 8560);havoc #t~mem43;call #t~mem44 := read~int(~s.base, ~s.offset + 52, 4); {7885#false} is VALID [2018-11-14 19:06:19,908 INFO L273 TraceCheckUtils]: 54: Hoare triple {7885#false} assume !(#t~mem44 == 8561);havoc #t~mem44;call #t~mem45 := read~int(~s.base, ~s.offset + 52, 4); {7885#false} is VALID [2018-11-14 19:06:19,908 INFO L273 TraceCheckUtils]: 55: Hoare triple {7885#false} assume !(#t~mem45 == 8448);havoc #t~mem45;call #t~mem46 := read~int(~s.base, ~s.offset + 52, 4); {7885#false} is VALID [2018-11-14 19:06:19,908 INFO L273 TraceCheckUtils]: 56: Hoare triple {7885#false} assume !(#t~mem46 == 8576);havoc #t~mem46;call #t~mem47 := read~int(~s.base, ~s.offset + 52, 4); {7885#false} is VALID [2018-11-14 19:06:19,908 INFO L273 TraceCheckUtils]: 57: Hoare triple {7885#false} assume !(#t~mem47 == 8577);havoc #t~mem47;call #t~mem48 := read~int(~s.base, ~s.offset + 52, 4); {7885#false} is VALID [2018-11-14 19:06:19,909 INFO L273 TraceCheckUtils]: 58: Hoare triple {7885#false} assume !(#t~mem48 == 8592);havoc #t~mem48;call #t~mem49 := read~int(~s.base, ~s.offset + 52, 4); {7885#false} is VALID [2018-11-14 19:06:19,909 INFO L273 TraceCheckUtils]: 59: Hoare triple {7885#false} assume !(#t~mem49 == 8593);havoc #t~mem49;call #t~mem50 := read~int(~s.base, ~s.offset + 52, 4); {7885#false} is VALID [2018-11-14 19:06:19,909 INFO L273 TraceCheckUtils]: 60: Hoare triple {7885#false} assume !(#t~mem50 == 8608);havoc #t~mem50;call #t~mem51 := read~int(~s.base, ~s.offset + 52, 4); {7885#false} is VALID [2018-11-14 19:06:19,909 INFO L273 TraceCheckUtils]: 61: Hoare triple {7885#false} assume !(#t~mem51 == 8609);havoc #t~mem51;call #t~mem52 := read~int(~s.base, ~s.offset + 52, 4); {7885#false} is VALID [2018-11-14 19:06:19,909 INFO L273 TraceCheckUtils]: 62: Hoare triple {7885#false} assume !(#t~mem52 == 8640);havoc #t~mem52;call #t~mem53 := read~int(~s.base, ~s.offset + 52, 4); {7885#false} is VALID [2018-11-14 19:06:19,910 INFO L273 TraceCheckUtils]: 63: Hoare triple {7885#false} assume !(#t~mem53 == 8641);havoc #t~mem53;call #t~mem54 := read~int(~s.base, ~s.offset + 52, 4); {7885#false} is VALID [2018-11-14 19:06:19,910 INFO L273 TraceCheckUtils]: 64: Hoare triple {7885#false} assume !(#t~mem54 == 8656);havoc #t~mem54;call #t~mem55 := read~int(~s.base, ~s.offset + 52, 4); {7885#false} is VALID [2018-11-14 19:06:19,910 INFO L273 TraceCheckUtils]: 65: Hoare triple {7885#false} assume !(#t~mem55 == 8657);havoc #t~mem55;call #t~mem56 := read~int(~s.base, ~s.offset + 52, 4); {7885#false} is VALID [2018-11-14 19:06:19,910 INFO L273 TraceCheckUtils]: 66: Hoare triple {7885#false} assume #t~mem56 == 8672;havoc #t~mem56; {7885#false} is VALID [2018-11-14 19:06:19,910 INFO L273 TraceCheckUtils]: 67: Hoare triple {7885#false} assume -2147483648 <= #t~nondet121 && #t~nondet121 <= 2147483647;~ret~0 := #t~nondet121;havoc #t~nondet121; {7885#false} is VALID [2018-11-14 19:06:19,911 INFO L273 TraceCheckUtils]: 68: Hoare triple {7885#false} assume ~blastFlag~0 == 4; {7885#false} is VALID [2018-11-14 19:06:19,911 INFO L273 TraceCheckUtils]: 69: Hoare triple {7885#false} assume !false; {7885#false} is VALID [2018-11-14 19:06:19,915 INFO L134 CoverageAnalysis]: Checked inductivity of 12 backedges. 12 proven. 0 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2018-11-14 19:06:19,916 INFO L312 seRefinementStrategy]: Constructing automaton from 1 perfect and 0 imperfect interpolant sequences. [2018-11-14 19:06:19,916 INFO L327 seRefinementStrategy]: Number of different interpolants: perfect sequences [4] imperfect sequences [] total 4 [2018-11-14 19:06:19,916 INFO L78 Accepts]: Start accepts. Automaton has 4 states. Word has length 70 [2018-11-14 19:06:19,916 INFO L84 Accepts]: Finished accepts. word is accepted. [2018-11-14 19:06:19,917 INFO L86 InductivityCheck]: Starting indutivity check of a Floyd-Hoare automaton with 4 states. [2018-11-14 19:06:19,990 INFO L119 InductivityCheck]: Floyd-Hoare automaton has 70 edges. 70 inductive. 0 not inductive. 0 times theorem prover too weak to decide inductivity. [2018-11-14 19:06:19,991 INFO L459 AbstractCegarLoop]: Interpolant automaton has 4 states [2018-11-14 19:06:19,991 INFO L142 InterpolantAutomaton]: Constructing interpolant automaton starting with 4 interpolants. [2018-11-14 19:06:19,991 INFO L144 InterpolantAutomaton]: CoverageRelationStatistics Valid=5, Invalid=7, Unknown=0, NotChecked=0, Total=12 [2018-11-14 19:06:19,991 INFO L87 Difference]: Start difference. First operand 149 states and 216 transitions. Second operand 4 states. [2018-11-14 19:06:21,897 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2018-11-14 19:06:21,897 INFO L93 Difference]: Finished difference Result 316 states and 470 transitions. [2018-11-14 19:06:21,897 INFO L142 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 4 states. [2018-11-14 19:06:21,897 INFO L78 Accepts]: Start accepts. Automaton has 4 states. Word has length 70 [2018-11-14 19:06:21,897 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2018-11-14 19:06:21,898 INFO L82 GeneralOperation]: Start removeUnreachable. Operand 4 states. [2018-11-14 19:06:21,901 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 4 states to 4 states and 458 transitions. [2018-11-14 19:06:21,901 INFO L82 GeneralOperation]: Start removeUnreachable. Operand 4 states. [2018-11-14 19:06:21,904 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 4 states to 4 states and 458 transitions. [2018-11-14 19:06:21,904 INFO L86 InductivityCheck]: Starting indutivity check of a Floyd-Hoare automaton with 4 states and 458 transitions. [2018-11-14 19:06:22,466 INFO L119 InductivityCheck]: Floyd-Hoare automaton has 458 edges. 458 inductive. 0 not inductive. 0 times theorem prover too weak to decide inductivity. [2018-11-14 19:06:22,470 INFO L225 Difference]: With dead ends: 316 [2018-11-14 19:06:22,470 INFO L226 Difference]: Without dead ends: 193 [2018-11-14 19:06:22,471 INFO L604 BasicCegarLoop]: 0 DeclaredPredicates, 6 GetRequests, 2 SyntacticMatches, 1 SemanticMatches, 3 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 0 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=9, Invalid=11, Unknown=0, NotChecked=0, Total=20 [2018-11-14 19:06:22,471 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 193 states. [2018-11-14 19:06:22,515 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 193 to 172. [2018-11-14 19:06:22,515 INFO L214 AbstractMinimizeNwa]: Start testing correctness of minimizeSevpa [2018-11-14 19:06:22,515 INFO L82 GeneralOperation]: Start isEquivalent. First operand 193 states. Second operand 172 states. [2018-11-14 19:06:22,516 INFO L74 IsIncluded]: Start isIncluded. First operand 193 states. Second operand 172 states. [2018-11-14 19:06:22,516 INFO L87 Difference]: Start difference. First operand 193 states. Second operand 172 states. [2018-11-14 19:06:22,520 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2018-11-14 19:06:22,520 INFO L93 Difference]: Finished difference Result 193 states and 282 transitions. [2018-11-14 19:06:22,520 INFO L276 IsEmpty]: Start isEmpty. Operand 193 states and 282 transitions. [2018-11-14 19:06:22,521 INFO L282 IsEmpty]: Finished isEmpty. No accepting run. [2018-11-14 19:06:22,521 INFO L83 IsIncluded]: Finished isIncluded. Language is included [2018-11-14 19:06:22,521 INFO L74 IsIncluded]: Start isIncluded. First operand 172 states. Second operand 193 states. [2018-11-14 19:06:22,521 INFO L87 Difference]: Start difference. First operand 172 states. Second operand 193 states. [2018-11-14 19:06:22,525 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2018-11-14 19:06:22,526 INFO L93 Difference]: Finished difference Result 193 states and 282 transitions. [2018-11-14 19:06:22,526 INFO L276 IsEmpty]: Start isEmpty. Operand 193 states and 282 transitions. [2018-11-14 19:06:22,526 INFO L282 IsEmpty]: Finished isEmpty. No accepting run. [2018-11-14 19:06:22,527 INFO L83 IsIncluded]: Finished isIncluded. Language is included [2018-11-14 19:06:22,527 INFO L88 GeneralOperation]: Finished isEquivalent. [2018-11-14 19:06:22,527 INFO L221 AbstractMinimizeNwa]: Finished testing correctness of minimizeSevpa [2018-11-14 19:06:22,527 INFO L82 GeneralOperation]: Start removeUnreachable. Operand 172 states. [2018-11-14 19:06:22,530 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 172 states to 172 states and 255 transitions. [2018-11-14 19:06:22,530 INFO L78 Accepts]: Start accepts. Automaton has 172 states and 255 transitions. Word has length 70 [2018-11-14 19:06:22,531 INFO L84 Accepts]: Finished accepts. word is rejected. [2018-11-14 19:06:22,531 INFO L480 AbstractCegarLoop]: Abstraction has 172 states and 255 transitions. [2018-11-14 19:06:22,531 INFO L481 AbstractCegarLoop]: Interpolant automaton has 4 states. [2018-11-14 19:06:22,531 INFO L276 IsEmpty]: Start isEmpty. Operand 172 states and 255 transitions. [2018-11-14 19:06:22,532 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 85 [2018-11-14 19:06:22,532 INFO L367 BasicCegarLoop]: Found error trace [2018-11-14 19:06:22,532 INFO L375 BasicCegarLoop]: trace histogram [3, 3, 3, 3, 3, 3, 3, 3, 2, 2, 2, 2, 2, 2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2018-11-14 19:06:22,532 INFO L423 AbstractCegarLoop]: === Iteration 11 === [ssl3_acceptErr0ASSERT_VIOLATIONERROR_FUNCTION]=== [2018-11-14 19:06:22,533 INFO L141 PredicateUnifier]: Initialized classic predicate unifier [2018-11-14 19:06:22,533 INFO L82 PathProgramCache]: Analyzing trace with hash -189164628, now seen corresponding path program 1 times [2018-11-14 19:06:22,533 INFO L223 ckRefinementStrategy]: Switched to mode SMTINTERPOL_TREE_INTERPOLANTS [2018-11-14 19:06:22,533 INFO L69 tionRefinementEngine]: Using refinement strategy CamelRefinementStrategy [2018-11-14 19:06:22,534 INFO L119 rtionOrderModulation]: Craig_TreeInterpolation forces the order to NOT_INCREMENTALLY [2018-11-14 19:06:22,534 INFO L103 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2018-11-14 19:06:22,534 INFO L119 rtionOrderModulation]: Craig_TreeInterpolation forces the order to NOT_INCREMENTALLY [2018-11-14 19:06:22,552 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2018-11-14 19:06:22,750 INFO L256 TraceCheckUtils]: 0: Hoare triple {8859#true} call ULTIMATE.init(); {8859#true} is VALID [2018-11-14 19:06:22,751 INFO L273 TraceCheckUtils]: 1: Hoare triple {8859#true} #NULL.base, #NULL.offset := 0, 0;#valid := #valid[0 := 0];~init~0 := 1;call ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset := #Ultimate.alloc(100);call write~unchecked~int(0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 0, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 4, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 8, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 12, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 16, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 20, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 24, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 28, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 32, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 36, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 40, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 44, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 48, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 52, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 56, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 60, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 64, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 68, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 72, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 76, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 80, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 84, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 88, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 92, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 96, 4);call write~unchecked~int(0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 0, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 4, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 8, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 12, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 16, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 20, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 24, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 28, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 32, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 36, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 40, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 44, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 48, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 52, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 56, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 60, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 64, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 68, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 72, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 76, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 80, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 84, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 88, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 92, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 96, 4); {8859#true} is VALID [2018-11-14 19:06:22,751 INFO L273 TraceCheckUtils]: 2: Hoare triple {8859#true} assume true; {8859#true} is VALID [2018-11-14 19:06:22,752 INFO L268 TraceCheckUtils]: 3: Hoare quadruple {8859#true} {8859#true} #654#return; {8859#true} is VALID [2018-11-14 19:06:22,752 INFO L256 TraceCheckUtils]: 4: Hoare triple {8859#true} call #t~ret138 := main(); {8859#true} is VALID [2018-11-14 19:06:22,752 INFO L273 TraceCheckUtils]: 5: Hoare triple {8859#true} havoc ~s~0.base, ~s~0.offset;havoc ~tmp~2;call #t~malloc3.base, #t~malloc3.offset := #Ultimate.alloc(248);~s~0.base, ~s~0.offset := #t~malloc3.base, #t~malloc3.offset;call #t~malloc4.base, #t~malloc4.offset := #Ultimate.alloc(899);call write~$Pointer$(#t~malloc4.base, #t~malloc4.offset, ~s~0.base, ~s~0.offset + 84, 4);call #t~malloc5.base, #t~malloc5.offset := #Ultimate.alloc(232);call write~$Pointer$(#t~malloc5.base, #t~malloc5.offset, ~s~0.base, ~s~0.offset + 204, 4);call #t~malloc6.base, #t~malloc6.offset := #Ultimate.alloc(200);call write~$Pointer$(#t~malloc6.base, #t~malloc6.offset, ~s~0.base, ~s~0.offset + 176, 4);call write~int(8464, ~s~0.base, ~s~0.offset + 52, 4); {8859#true} is VALID [2018-11-14 19:06:22,753 INFO L256 TraceCheckUtils]: 6: Hoare triple {8859#true} call #t~ret7 := ssl3_accept(~s~0.base, ~s~0.offset); {8859#true} is VALID [2018-11-14 19:06:22,753 INFO L273 TraceCheckUtils]: 7: Hoare triple {8859#true} ~s.base, ~s.offset := #in~s.base, #in~s.offset;havoc ~buf~0.base, ~buf~0.offset;havoc ~l~0;havoc ~Time~0;havoc ~tmp~3;havoc ~cb~0.base, ~cb~0.offset;havoc ~num1~0;havoc ~ret~0;havoc ~new_state~0;havoc ~state~0;havoc ~skip~0;havoc ~got_new_session~0;assume -2147483648 <= #t~nondet8 && #t~nondet8 <= 2147483647;~tmp___1~0 := #t~nondet8;havoc #t~nondet8;assume -2147483648 <= #t~nondet9 && #t~nondet9 <= 2147483647;~tmp___2~0 := #t~nondet9;havoc #t~nondet9;assume -2147483648 <= #t~nondet10 && #t~nondet10 <= 2147483647;~tmp___3~0 := #t~nondet10;havoc #t~nondet10;assume -2147483648 <= #t~nondet11 && #t~nondet11 <= 2147483647;~tmp___4~0 := #t~nondet11;havoc #t~nondet11;assume -2147483648 <= #t~nondet12 && #t~nondet12 <= 2147483647;~tmp___5~0 := #t~nondet12;havoc #t~nondet12;assume -2147483648 <= #t~nondet13 && #t~nondet13 <= 2147483647;~tmp___6~0 := #t~nondet13;havoc #t~nondet13;havoc ~tmp___7~0;assume -2147483648 <= #t~nondet14 && #t~nondet14 <= 2147483647;~tmp___8~0 := #t~nondet14;havoc #t~nondet14;assume -2147483648 <= #t~nondet15 && #t~nondet15 <= 2147483647;~tmp___9~0 := #t~nondet15;havoc #t~nondet15;assume -2147483648 <= #t~nondet16 && #t~nondet16 <= 2147483647;~tmp___10~0 := #t~nondet16;havoc #t~nondet16;havoc ~blastFlag~0;~blastFlag~0 := 0;assume -2147483648 <= #t~nondet17 && #t~nondet17 <= 2147483647;call write~int(#t~nondet17, ~s.base, ~s.offset + 92, 4);havoc #t~nondet17;call write~int(8464, ~s.base, ~s.offset + 52, 4);assume -2147483648 <= #t~nondet18 && #t~nondet18 <= 2147483647;~tmp~3 := #t~nondet18;havoc #t~nondet18;~Time~0 := ~tmp~3;~cb~0.base, ~cb~0.offset := 0, 0;~ret~0 := -1;~skip~0 := 0;~got_new_session~0 := 0;call #t~mem19.base, #t~mem19.offset := read~$Pointer$(~s.base, ~s.offset + 192, 4); {8859#true} is VALID [2018-11-14 19:06:22,753 INFO L273 TraceCheckUtils]: 8: Hoare triple {8859#true} assume (#t~mem19.base + #t~mem19.offset) % 4294967296 != 0;havoc #t~mem19.base, #t~mem19.offset;call #t~mem20.base, #t~mem20.offset := read~$Pointer$(~s.base, ~s.offset + 192, 4);~cb~0.base, ~cb~0.offset := #t~mem20.base, #t~mem20.offset;havoc #t~mem20.base, #t~mem20.offset; {8859#true} is VALID [2018-11-14 19:06:22,753 INFO L273 TraceCheckUtils]: 9: Hoare triple {8859#true} call #t~mem21 := read~int(~s.base, ~s.offset + 28, 4);call write~int(#t~mem21 + 1, ~s.base, ~s.offset + 28, 4);havoc #t~mem21; {8859#true} is VALID [2018-11-14 19:06:22,753 INFO L273 TraceCheckUtils]: 10: Hoare triple {8859#true} assume !(~bitwiseAnd(~tmp___1~0, 12288) != 0); {8859#true} is VALID [2018-11-14 19:06:22,754 INFO L273 TraceCheckUtils]: 11: Hoare triple {8859#true} call #t~mem22.base, #t~mem22.offset := read~$Pointer$(~s.base, ~s.offset + 136, 4); {8859#true} is VALID [2018-11-14 19:06:22,754 INFO L273 TraceCheckUtils]: 12: Hoare triple {8859#true} assume !((#t~mem22.base + #t~mem22.offset) % 4294967296 == 0);havoc #t~mem22.base, #t~mem22.offset; {8859#true} is VALID [2018-11-14 19:06:22,754 INFO L273 TraceCheckUtils]: 13: Hoare triple {8859#true} assume true; {8859#true} is VALID [2018-11-14 19:06:22,754 INFO L273 TraceCheckUtils]: 14: Hoare triple {8859#true} assume !false; {8859#true} is VALID [2018-11-14 19:06:22,754 INFO L273 TraceCheckUtils]: 15: Hoare triple {8859#true} call #t~mem23 := read~int(~s.base, ~s.offset + 52, 4);~state~0 := #t~mem23;havoc #t~mem23;call #t~mem24 := read~int(~s.base, ~s.offset + 52, 4); {8859#true} is VALID [2018-11-14 19:06:22,755 INFO L273 TraceCheckUtils]: 16: Hoare triple {8859#true} assume !(#t~mem24 == 12292);havoc #t~mem24;call #t~mem25 := read~int(~s.base, ~s.offset + 52, 4); {8859#true} is VALID [2018-11-14 19:06:22,755 INFO L273 TraceCheckUtils]: 17: Hoare triple {8859#true} assume !(#t~mem25 == 16384);havoc #t~mem25;call #t~mem26 := read~int(~s.base, ~s.offset + 52, 4); {8859#true} is VALID [2018-11-14 19:06:22,755 INFO L273 TraceCheckUtils]: 18: Hoare triple {8859#true} assume !(#t~mem26 == 8192);havoc #t~mem26;call #t~mem27 := read~int(~s.base, ~s.offset + 52, 4); {8859#true} is VALID [2018-11-14 19:06:22,755 INFO L273 TraceCheckUtils]: 19: Hoare triple {8859#true} assume !(#t~mem27 == 24576);havoc #t~mem27;call #t~mem28 := read~int(~s.base, ~s.offset + 52, 4); {8859#true} is VALID [2018-11-14 19:06:22,755 INFO L273 TraceCheckUtils]: 20: Hoare triple {8859#true} assume !(#t~mem28 == 8195);havoc #t~mem28;call #t~mem29 := read~int(~s.base, ~s.offset + 52, 4); {8859#true} is VALID [2018-11-14 19:06:22,755 INFO L273 TraceCheckUtils]: 21: Hoare triple {8859#true} assume !(#t~mem29 == 8480);havoc #t~mem29;call #t~mem30 := read~int(~s.base, ~s.offset + 52, 4); {8859#true} is VALID [2018-11-14 19:06:22,756 INFO L273 TraceCheckUtils]: 22: Hoare triple {8859#true} assume !(#t~mem30 == 8481);havoc #t~mem30;call #t~mem31 := read~int(~s.base, ~s.offset + 52, 4); {8859#true} is VALID [2018-11-14 19:06:22,756 INFO L273 TraceCheckUtils]: 23: Hoare triple {8859#true} assume !(#t~mem31 == 8482);havoc #t~mem31;call #t~mem32 := read~int(~s.base, ~s.offset + 52, 4); {8859#true} is VALID [2018-11-14 19:06:22,756 INFO L273 TraceCheckUtils]: 24: Hoare triple {8859#true} assume #t~mem32 == 8464;havoc #t~mem32; {8859#true} is VALID [2018-11-14 19:06:22,756 INFO L273 TraceCheckUtils]: 25: Hoare triple {8859#true} call write~int(0, ~s.base, ~s.offset + 48, 4);assume -2147483648 <= #t~nondet69 && #t~nondet69 <= 2147483647;~ret~0 := #t~nondet69;havoc #t~nondet69; {8859#true} is VALID [2018-11-14 19:06:22,756 INFO L273 TraceCheckUtils]: 26: Hoare triple {8859#true} assume ~blastFlag~0 == 0;~blastFlag~0 := 1; {8859#true} is VALID [2018-11-14 19:06:22,774 INFO L273 TraceCheckUtils]: 27: Hoare triple {8859#true} assume !(~ret~0 <= 0);~got_new_session~0 := 1;call write~int(8496, ~s.base, ~s.offset + 52, 4);call write~int(0, ~s.base, ~s.offset + 64, 4); {8861#(= (select (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 52)) 8496)} is VALID [2018-11-14 19:06:22,778 INFO L273 TraceCheckUtils]: 28: Hoare triple {8861#(= (select (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 52)) 8496)} call #t~mem127.base, #t~mem127.offset := read~$Pointer$(~s.base, ~s.offset + 84, 4);call #t~mem128 := read~int(#t~mem127.base, #t~mem127.offset + 604 + 244, 4); {8861#(= (select (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 52)) 8496)} is VALID [2018-11-14 19:06:22,778 INFO L273 TraceCheckUtils]: 29: Hoare triple {8861#(= (select (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 52)) 8496)} assume !(#t~mem128 == 0);havoc #t~mem127.base, #t~mem127.offset;havoc #t~mem128; {8861#(= (select (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 52)) 8496)} is VALID [2018-11-14 19:06:22,778 INFO L273 TraceCheckUtils]: 30: Hoare triple {8861#(= (select (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 52)) 8496)} ~skip~0 := 0; {8861#(= (select (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 52)) 8496)} is VALID [2018-11-14 19:06:22,779 INFO L273 TraceCheckUtils]: 31: Hoare triple {8861#(= (select (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 52)) 8496)} assume true; {8861#(= (select (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 52)) 8496)} is VALID [2018-11-14 19:06:22,779 INFO L273 TraceCheckUtils]: 32: Hoare triple {8861#(= (select (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 52)) 8496)} assume !false; {8861#(= (select (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 52)) 8496)} is VALID [2018-11-14 19:06:22,779 INFO L273 TraceCheckUtils]: 33: Hoare triple {8861#(= (select (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 52)) 8496)} call #t~mem23 := read~int(~s.base, ~s.offset + 52, 4);~state~0 := #t~mem23;havoc #t~mem23;call #t~mem24 := read~int(~s.base, ~s.offset + 52, 4); {8861#(= (select (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 52)) 8496)} is VALID [2018-11-14 19:06:22,780 INFO L273 TraceCheckUtils]: 34: Hoare triple {8861#(= (select (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 52)) 8496)} assume !(#t~mem24 == 12292);havoc #t~mem24;call #t~mem25 := read~int(~s.base, ~s.offset + 52, 4); {8861#(= (select (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 52)) 8496)} is VALID [2018-11-14 19:06:22,780 INFO L273 TraceCheckUtils]: 35: Hoare triple {8861#(= (select (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 52)) 8496)} assume !(#t~mem25 == 16384);havoc #t~mem25;call #t~mem26 := read~int(~s.base, ~s.offset + 52, 4); {8861#(= (select (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 52)) 8496)} is VALID [2018-11-14 19:06:22,780 INFO L273 TraceCheckUtils]: 36: Hoare triple {8861#(= (select (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 52)) 8496)} assume !(#t~mem26 == 8192);havoc #t~mem26;call #t~mem27 := read~int(~s.base, ~s.offset + 52, 4); {8861#(= (select (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 52)) 8496)} is VALID [2018-11-14 19:06:22,781 INFO L273 TraceCheckUtils]: 37: Hoare triple {8861#(= (select (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 52)) 8496)} assume !(#t~mem27 == 24576);havoc #t~mem27;call #t~mem28 := read~int(~s.base, ~s.offset + 52, 4); {8861#(= (select (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 52)) 8496)} is VALID [2018-11-14 19:06:22,781 INFO L273 TraceCheckUtils]: 38: Hoare triple {8861#(= (select (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 52)) 8496)} assume !(#t~mem28 == 8195);havoc #t~mem28;call #t~mem29 := read~int(~s.base, ~s.offset + 52, 4); {8862#(= |ssl3_accept_#t~mem29| 8496)} is VALID [2018-11-14 19:06:22,781 INFO L273 TraceCheckUtils]: 39: Hoare triple {8862#(= |ssl3_accept_#t~mem29| 8496)} assume #t~mem29 == 8480;havoc #t~mem29; {8860#false} is VALID [2018-11-14 19:06:22,782 INFO L273 TraceCheckUtils]: 40: Hoare triple {8860#false} call write~int(0, ~s.base, ~s.offset + 48, 4);assume -2147483648 <= #t~nondet67 && #t~nondet67 <= 2147483647;~ret~0 := #t~nondet67;havoc #t~nondet67; {8860#false} is VALID [2018-11-14 19:06:22,782 INFO L273 TraceCheckUtils]: 41: Hoare triple {8860#false} assume !(~ret~0 <= 0);call #t~mem68.base, #t~mem68.offset := read~$Pointer$(~s.base, ~s.offset + 84, 4);call write~int(8482, #t~mem68.base, #t~mem68.offset + 604 + 240, 4);havoc #t~mem68.base, #t~mem68.offset;call write~int(8448, ~s.base, ~s.offset + 52, 4);call write~int(0, ~s.base, ~s.offset + 64, 4); {8860#false} is VALID [2018-11-14 19:06:22,782 INFO L273 TraceCheckUtils]: 42: Hoare triple {8860#false} call #t~mem127.base, #t~mem127.offset := read~$Pointer$(~s.base, ~s.offset + 84, 4);call #t~mem128 := read~int(#t~mem127.base, #t~mem127.offset + 604 + 244, 4); {8860#false} is VALID [2018-11-14 19:06:22,782 INFO L273 TraceCheckUtils]: 43: Hoare triple {8860#false} assume !(#t~mem128 == 0);havoc #t~mem127.base, #t~mem127.offset;havoc #t~mem128; {8860#false} is VALID [2018-11-14 19:06:22,782 INFO L273 TraceCheckUtils]: 44: Hoare triple {8860#false} ~skip~0 := 0; {8860#false} is VALID [2018-11-14 19:06:22,783 INFO L273 TraceCheckUtils]: 45: Hoare triple {8860#false} assume true; {8860#false} is VALID [2018-11-14 19:06:22,783 INFO L273 TraceCheckUtils]: 46: Hoare triple {8860#false} assume !false; {8860#false} is VALID [2018-11-14 19:06:22,783 INFO L273 TraceCheckUtils]: 47: Hoare triple {8860#false} call #t~mem23 := read~int(~s.base, ~s.offset + 52, 4);~state~0 := #t~mem23;havoc #t~mem23;call #t~mem24 := read~int(~s.base, ~s.offset + 52, 4); {8860#false} is VALID [2018-11-14 19:06:22,783 INFO L273 TraceCheckUtils]: 48: Hoare triple {8860#false} assume !(#t~mem24 == 12292);havoc #t~mem24;call #t~mem25 := read~int(~s.base, ~s.offset + 52, 4); {8860#false} is VALID [2018-11-14 19:06:22,783 INFO L273 TraceCheckUtils]: 49: Hoare triple {8860#false} assume !(#t~mem25 == 16384);havoc #t~mem25;call #t~mem26 := read~int(~s.base, ~s.offset + 52, 4); {8860#false} is VALID [2018-11-14 19:06:22,784 INFO L273 TraceCheckUtils]: 50: Hoare triple {8860#false} assume !(#t~mem26 == 8192);havoc #t~mem26;call #t~mem27 := read~int(~s.base, ~s.offset + 52, 4); {8860#false} is VALID [2018-11-14 19:06:22,784 INFO L273 TraceCheckUtils]: 51: Hoare triple {8860#false} assume !(#t~mem27 == 24576);havoc #t~mem27;call #t~mem28 := read~int(~s.base, ~s.offset + 52, 4); {8860#false} is VALID [2018-11-14 19:06:22,784 INFO L273 TraceCheckUtils]: 52: Hoare triple {8860#false} assume !(#t~mem28 == 8195);havoc #t~mem28;call #t~mem29 := read~int(~s.base, ~s.offset + 52, 4); {8860#false} is VALID [2018-11-14 19:06:22,784 INFO L273 TraceCheckUtils]: 53: Hoare triple {8860#false} assume !(#t~mem29 == 8480);havoc #t~mem29;call #t~mem30 := read~int(~s.base, ~s.offset + 52, 4); {8860#false} is VALID [2018-11-14 19:06:22,784 INFO L273 TraceCheckUtils]: 54: Hoare triple {8860#false} assume !(#t~mem30 == 8481);havoc #t~mem30;call #t~mem31 := read~int(~s.base, ~s.offset + 52, 4); {8860#false} is VALID [2018-11-14 19:06:22,785 INFO L273 TraceCheckUtils]: 55: Hoare triple {8860#false} assume !(#t~mem31 == 8482);havoc #t~mem31;call #t~mem32 := read~int(~s.base, ~s.offset + 52, 4); {8860#false} is VALID [2018-11-14 19:06:22,785 INFO L273 TraceCheckUtils]: 56: Hoare triple {8860#false} assume !(#t~mem32 == 8464);havoc #t~mem32;call #t~mem33 := read~int(~s.base, ~s.offset + 52, 4); {8860#false} is VALID [2018-11-14 19:06:22,785 INFO L273 TraceCheckUtils]: 57: Hoare triple {8860#false} assume !(#t~mem33 == 8465);havoc #t~mem33;call #t~mem34 := read~int(~s.base, ~s.offset + 52, 4); {8860#false} is VALID [2018-11-14 19:06:22,785 INFO L273 TraceCheckUtils]: 58: Hoare triple {8860#false} assume !(#t~mem34 == 8466);havoc #t~mem34;call #t~mem35 := read~int(~s.base, ~s.offset + 52, 4); {8860#false} is VALID [2018-11-14 19:06:22,785 INFO L273 TraceCheckUtils]: 59: Hoare triple {8860#false} assume !(#t~mem35 == 8496);havoc #t~mem35;call #t~mem36 := read~int(~s.base, ~s.offset + 52, 4); {8860#false} is VALID [2018-11-14 19:06:22,786 INFO L273 TraceCheckUtils]: 60: Hoare triple {8860#false} assume !(#t~mem36 == 8497);havoc #t~mem36;call #t~mem37 := read~int(~s.base, ~s.offset + 52, 4); {8860#false} is VALID [2018-11-14 19:06:22,786 INFO L273 TraceCheckUtils]: 61: Hoare triple {8860#false} assume !(#t~mem37 == 8512);havoc #t~mem37;call #t~mem38 := read~int(~s.base, ~s.offset + 52, 4); {8860#false} is VALID [2018-11-14 19:06:22,786 INFO L273 TraceCheckUtils]: 62: Hoare triple {8860#false} assume !(#t~mem38 == 8513);havoc #t~mem38;call #t~mem39 := read~int(~s.base, ~s.offset + 52, 4); {8860#false} is VALID [2018-11-14 19:06:22,786 INFO L273 TraceCheckUtils]: 63: Hoare triple {8860#false} assume !(#t~mem39 == 8528);havoc #t~mem39;call #t~mem40 := read~int(~s.base, ~s.offset + 52, 4); {8860#false} is VALID [2018-11-14 19:06:22,786 INFO L273 TraceCheckUtils]: 64: Hoare triple {8860#false} assume !(#t~mem40 == 8529);havoc #t~mem40;call #t~mem41 := read~int(~s.base, ~s.offset + 52, 4); {8860#false} is VALID [2018-11-14 19:06:22,787 INFO L273 TraceCheckUtils]: 65: Hoare triple {8860#false} assume !(#t~mem41 == 8544);havoc #t~mem41;call #t~mem42 := read~int(~s.base, ~s.offset + 52, 4); {8860#false} is VALID [2018-11-14 19:06:22,787 INFO L273 TraceCheckUtils]: 66: Hoare triple {8860#false} assume !(#t~mem42 == 8545);havoc #t~mem42;call #t~mem43 := read~int(~s.base, ~s.offset + 52, 4); {8860#false} is VALID [2018-11-14 19:06:22,787 INFO L273 TraceCheckUtils]: 67: Hoare triple {8860#false} assume !(#t~mem43 == 8560);havoc #t~mem43;call #t~mem44 := read~int(~s.base, ~s.offset + 52, 4); {8860#false} is VALID [2018-11-14 19:06:22,787 INFO L273 TraceCheckUtils]: 68: Hoare triple {8860#false} assume !(#t~mem44 == 8561);havoc #t~mem44;call #t~mem45 := read~int(~s.base, ~s.offset + 52, 4); {8860#false} is VALID [2018-11-14 19:06:22,787 INFO L273 TraceCheckUtils]: 69: Hoare triple {8860#false} assume !(#t~mem45 == 8448);havoc #t~mem45;call #t~mem46 := read~int(~s.base, ~s.offset + 52, 4); {8860#false} is VALID [2018-11-14 19:06:22,788 INFO L273 TraceCheckUtils]: 70: Hoare triple {8860#false} assume !(#t~mem46 == 8576);havoc #t~mem46;call #t~mem47 := read~int(~s.base, ~s.offset + 52, 4); {8860#false} is VALID [2018-11-14 19:06:22,788 INFO L273 TraceCheckUtils]: 71: Hoare triple {8860#false} assume !(#t~mem47 == 8577);havoc #t~mem47;call #t~mem48 := read~int(~s.base, ~s.offset + 52, 4); {8860#false} is VALID [2018-11-14 19:06:22,788 INFO L273 TraceCheckUtils]: 72: Hoare triple {8860#false} assume !(#t~mem48 == 8592);havoc #t~mem48;call #t~mem49 := read~int(~s.base, ~s.offset + 52, 4); {8860#false} is VALID [2018-11-14 19:06:22,788 INFO L273 TraceCheckUtils]: 73: Hoare triple {8860#false} assume !(#t~mem49 == 8593);havoc #t~mem49;call #t~mem50 := read~int(~s.base, ~s.offset + 52, 4); {8860#false} is VALID [2018-11-14 19:06:22,788 INFO L273 TraceCheckUtils]: 74: Hoare triple {8860#false} assume !(#t~mem50 == 8608);havoc #t~mem50;call #t~mem51 := read~int(~s.base, ~s.offset + 52, 4); {8860#false} is VALID [2018-11-14 19:06:22,788 INFO L273 TraceCheckUtils]: 75: Hoare triple {8860#false} assume !(#t~mem51 == 8609);havoc #t~mem51;call #t~mem52 := read~int(~s.base, ~s.offset + 52, 4); {8860#false} is VALID [2018-11-14 19:06:22,789 INFO L273 TraceCheckUtils]: 76: Hoare triple {8860#false} assume !(#t~mem52 == 8640);havoc #t~mem52;call #t~mem53 := read~int(~s.base, ~s.offset + 52, 4); {8860#false} is VALID [2018-11-14 19:06:22,789 INFO L273 TraceCheckUtils]: 77: Hoare triple {8860#false} assume !(#t~mem53 == 8641);havoc #t~mem53;call #t~mem54 := read~int(~s.base, ~s.offset + 52, 4); {8860#false} is VALID [2018-11-14 19:06:22,789 INFO L273 TraceCheckUtils]: 78: Hoare triple {8860#false} assume !(#t~mem54 == 8656);havoc #t~mem54;call #t~mem55 := read~int(~s.base, ~s.offset + 52, 4); {8860#false} is VALID [2018-11-14 19:06:22,789 INFO L273 TraceCheckUtils]: 79: Hoare triple {8860#false} assume !(#t~mem55 == 8657);havoc #t~mem55;call #t~mem56 := read~int(~s.base, ~s.offset + 52, 4); {8860#false} is VALID [2018-11-14 19:06:22,789 INFO L273 TraceCheckUtils]: 80: Hoare triple {8860#false} assume #t~mem56 == 8672;havoc #t~mem56; {8860#false} is VALID [2018-11-14 19:06:22,790 INFO L273 TraceCheckUtils]: 81: Hoare triple {8860#false} assume -2147483648 <= #t~nondet121 && #t~nondet121 <= 2147483647;~ret~0 := #t~nondet121;havoc #t~nondet121; {8860#false} is VALID [2018-11-14 19:06:22,790 INFO L273 TraceCheckUtils]: 82: Hoare triple {8860#false} assume ~blastFlag~0 == 4; {8860#false} is VALID [2018-11-14 19:06:22,790 INFO L273 TraceCheckUtils]: 83: Hoare triple {8860#false} assume !false; {8860#false} is VALID [2018-11-14 19:06:22,795 INFO L134 CoverageAnalysis]: Checked inductivity of 33 backedges. 33 proven. 0 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2018-11-14 19:06:22,795 INFO L312 seRefinementStrategy]: Constructing automaton from 1 perfect and 0 imperfect interpolant sequences. [2018-11-14 19:06:22,796 INFO L327 seRefinementStrategy]: Number of different interpolants: perfect sequences [4] imperfect sequences [] total 4 [2018-11-14 19:06:22,796 INFO L78 Accepts]: Start accepts. Automaton has 4 states. Word has length 84 [2018-11-14 19:06:22,796 INFO L84 Accepts]: Finished accepts. word is accepted. [2018-11-14 19:06:22,796 INFO L86 InductivityCheck]: Starting indutivity check of a Floyd-Hoare automaton with 4 states. [2018-11-14 19:06:22,913 INFO L119 InductivityCheck]: Floyd-Hoare automaton has 84 edges. 84 inductive. 0 not inductive. 0 times theorem prover too weak to decide inductivity. [2018-11-14 19:06:22,913 INFO L459 AbstractCegarLoop]: Interpolant automaton has 4 states [2018-11-14 19:06:22,914 INFO L142 InterpolantAutomaton]: Constructing interpolant automaton starting with 4 interpolants. [2018-11-14 19:06:22,914 INFO L144 InterpolantAutomaton]: CoverageRelationStatistics Valid=5, Invalid=7, Unknown=0, NotChecked=0, Total=12 [2018-11-14 19:06:22,914 INFO L87 Difference]: Start difference. First operand 172 states and 255 transitions. Second operand 4 states. [2018-11-14 19:06:24,364 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2018-11-14 19:06:24,364 INFO L93 Difference]: Finished difference Result 339 states and 508 transitions. [2018-11-14 19:06:24,365 INFO L142 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 4 states. [2018-11-14 19:06:24,365 INFO L78 Accepts]: Start accepts. Automaton has 4 states. Word has length 84 [2018-11-14 19:06:24,365 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2018-11-14 19:06:24,365 INFO L82 GeneralOperation]: Start removeUnreachable. Operand 4 states. [2018-11-14 19:06:24,367 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 4 states to 4 states and 457 transitions. [2018-11-14 19:06:24,368 INFO L82 GeneralOperation]: Start removeUnreachable. Operand 4 states. [2018-11-14 19:06:24,370 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 4 states to 4 states and 457 transitions. [2018-11-14 19:06:24,370 INFO L86 InductivityCheck]: Starting indutivity check of a Floyd-Hoare automaton with 4 states and 457 transitions. [2018-11-14 19:06:24,793 INFO L119 InductivityCheck]: Floyd-Hoare automaton has 457 edges. 457 inductive. 0 not inductive. 0 times theorem prover too weak to decide inductivity. [2018-11-14 19:06:24,798 INFO L225 Difference]: With dead ends: 339 [2018-11-14 19:06:24,798 INFO L226 Difference]: Without dead ends: 193 [2018-11-14 19:06:24,799 INFO L604 BasicCegarLoop]: 0 DeclaredPredicates, 6 GetRequests, 2 SyntacticMatches, 1 SemanticMatches, 3 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 0 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=9, Invalid=11, Unknown=0, NotChecked=0, Total=20 [2018-11-14 19:06:24,800 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 193 states. [2018-11-14 19:06:24,832 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 193 to 172. [2018-11-14 19:06:24,832 INFO L214 AbstractMinimizeNwa]: Start testing correctness of minimizeSevpa [2018-11-14 19:06:24,832 INFO L82 GeneralOperation]: Start isEquivalent. First operand 193 states. Second operand 172 states. [2018-11-14 19:06:24,832 INFO L74 IsIncluded]: Start isIncluded. First operand 193 states. Second operand 172 states. [2018-11-14 19:06:24,832 INFO L87 Difference]: Start difference. First operand 193 states. Second operand 172 states. [2018-11-14 19:06:24,835 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2018-11-14 19:06:24,836 INFO L93 Difference]: Finished difference Result 193 states and 281 transitions. [2018-11-14 19:06:24,836 INFO L276 IsEmpty]: Start isEmpty. Operand 193 states and 281 transitions. [2018-11-14 19:06:24,836 INFO L282 IsEmpty]: Finished isEmpty. No accepting run. [2018-11-14 19:06:24,836 INFO L83 IsIncluded]: Finished isIncluded. Language is included [2018-11-14 19:06:24,836 INFO L74 IsIncluded]: Start isIncluded. First operand 172 states. Second operand 193 states. [2018-11-14 19:06:24,836 INFO L87 Difference]: Start difference. First operand 172 states. Second operand 193 states. [2018-11-14 19:06:24,839 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2018-11-14 19:06:24,840 INFO L93 Difference]: Finished difference Result 193 states and 281 transitions. [2018-11-14 19:06:24,840 INFO L276 IsEmpty]: Start isEmpty. Operand 193 states and 281 transitions. [2018-11-14 19:06:24,840 INFO L282 IsEmpty]: Finished isEmpty. No accepting run. [2018-11-14 19:06:24,840 INFO L83 IsIncluded]: Finished isIncluded. Language is included [2018-11-14 19:06:24,840 INFO L88 GeneralOperation]: Finished isEquivalent. [2018-11-14 19:06:24,841 INFO L221 AbstractMinimizeNwa]: Finished testing correctness of minimizeSevpa [2018-11-14 19:06:24,841 INFO L82 GeneralOperation]: Start removeUnreachable. Operand 172 states. [2018-11-14 19:06:24,844 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 172 states to 172 states and 254 transitions. [2018-11-14 19:06:24,844 INFO L78 Accepts]: Start accepts. Automaton has 172 states and 254 transitions. Word has length 84 [2018-11-14 19:06:24,844 INFO L84 Accepts]: Finished accepts. word is rejected. [2018-11-14 19:06:24,844 INFO L480 AbstractCegarLoop]: Abstraction has 172 states and 254 transitions. [2018-11-14 19:06:24,844 INFO L481 AbstractCegarLoop]: Interpolant automaton has 4 states. [2018-11-14 19:06:24,844 INFO L276 IsEmpty]: Start isEmpty. Operand 172 states and 254 transitions. [2018-11-14 19:06:24,845 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 86 [2018-11-14 19:06:24,845 INFO L367 BasicCegarLoop]: Found error trace [2018-11-14 19:06:24,846 INFO L375 BasicCegarLoop]: trace histogram [3, 3, 3, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2018-11-14 19:06:24,846 INFO L423 AbstractCegarLoop]: === Iteration 12 === [ssl3_acceptErr0ASSERT_VIOLATIONERROR_FUNCTION]=== [2018-11-14 19:06:24,846 INFO L141 PredicateUnifier]: Initialized classic predicate unifier [2018-11-14 19:06:24,846 INFO L82 PathProgramCache]: Analyzing trace with hash -1201084832, now seen corresponding path program 1 times [2018-11-14 19:06:24,846 INFO L223 ckRefinementStrategy]: Switched to mode SMTINTERPOL_TREE_INTERPOLANTS [2018-11-14 19:06:24,846 INFO L69 tionRefinementEngine]: Using refinement strategy CamelRefinementStrategy [2018-11-14 19:06:24,847 INFO L119 rtionOrderModulation]: Craig_TreeInterpolation forces the order to NOT_INCREMENTALLY [2018-11-14 19:06:24,847 INFO L103 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2018-11-14 19:06:24,848 INFO L119 rtionOrderModulation]: Craig_TreeInterpolation forces the order to NOT_INCREMENTALLY [2018-11-14 19:06:24,869 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2018-11-14 19:06:25,083 INFO L256 TraceCheckUtils]: 0: Hoare triple {9859#true} call ULTIMATE.init(); {9859#true} is VALID [2018-11-14 19:06:25,084 INFO L273 TraceCheckUtils]: 1: Hoare triple {9859#true} #NULL.base, #NULL.offset := 0, 0;#valid := #valid[0 := 0];~init~0 := 1;call ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset := #Ultimate.alloc(100);call write~unchecked~int(0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 0, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 4, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 8, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 12, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 16, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 20, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 24, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 28, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 32, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 36, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 40, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 44, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 48, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 52, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 56, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 60, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 64, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 68, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 72, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 76, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 80, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 84, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 88, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 92, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 96, 4);call write~unchecked~int(0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 0, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 4, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 8, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 12, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 16, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 20, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 24, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 28, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 32, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 36, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 40, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 44, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 48, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 52, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 56, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 60, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 64, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 68, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 72, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 76, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 80, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 84, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 88, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 92, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 96, 4); {9859#true} is VALID [2018-11-14 19:06:25,084 INFO L273 TraceCheckUtils]: 2: Hoare triple {9859#true} assume true; {9859#true} is VALID [2018-11-14 19:06:25,084 INFO L268 TraceCheckUtils]: 3: Hoare quadruple {9859#true} {9859#true} #654#return; {9859#true} is VALID [2018-11-14 19:06:25,085 INFO L256 TraceCheckUtils]: 4: Hoare triple {9859#true} call #t~ret138 := main(); {9859#true} is VALID [2018-11-14 19:06:25,085 INFO L273 TraceCheckUtils]: 5: Hoare triple {9859#true} havoc ~s~0.base, ~s~0.offset;havoc ~tmp~2;call #t~malloc3.base, #t~malloc3.offset := #Ultimate.alloc(248);~s~0.base, ~s~0.offset := #t~malloc3.base, #t~malloc3.offset;call #t~malloc4.base, #t~malloc4.offset := #Ultimate.alloc(899);call write~$Pointer$(#t~malloc4.base, #t~malloc4.offset, ~s~0.base, ~s~0.offset + 84, 4);call #t~malloc5.base, #t~malloc5.offset := #Ultimate.alloc(232);call write~$Pointer$(#t~malloc5.base, #t~malloc5.offset, ~s~0.base, ~s~0.offset + 204, 4);call #t~malloc6.base, #t~malloc6.offset := #Ultimate.alloc(200);call write~$Pointer$(#t~malloc6.base, #t~malloc6.offset, ~s~0.base, ~s~0.offset + 176, 4);call write~int(8464, ~s~0.base, ~s~0.offset + 52, 4); {9859#true} is VALID [2018-11-14 19:06:25,085 INFO L256 TraceCheckUtils]: 6: Hoare triple {9859#true} call #t~ret7 := ssl3_accept(~s~0.base, ~s~0.offset); {9859#true} is VALID [2018-11-14 19:06:25,085 INFO L273 TraceCheckUtils]: 7: Hoare triple {9859#true} ~s.base, ~s.offset := #in~s.base, #in~s.offset;havoc ~buf~0.base, ~buf~0.offset;havoc ~l~0;havoc ~Time~0;havoc ~tmp~3;havoc ~cb~0.base, ~cb~0.offset;havoc ~num1~0;havoc ~ret~0;havoc ~new_state~0;havoc ~state~0;havoc ~skip~0;havoc ~got_new_session~0;assume -2147483648 <= #t~nondet8 && #t~nondet8 <= 2147483647;~tmp___1~0 := #t~nondet8;havoc #t~nondet8;assume -2147483648 <= #t~nondet9 && #t~nondet9 <= 2147483647;~tmp___2~0 := #t~nondet9;havoc #t~nondet9;assume -2147483648 <= #t~nondet10 && #t~nondet10 <= 2147483647;~tmp___3~0 := #t~nondet10;havoc #t~nondet10;assume -2147483648 <= #t~nondet11 && #t~nondet11 <= 2147483647;~tmp___4~0 := #t~nondet11;havoc #t~nondet11;assume -2147483648 <= #t~nondet12 && #t~nondet12 <= 2147483647;~tmp___5~0 := #t~nondet12;havoc #t~nondet12;assume -2147483648 <= #t~nondet13 && #t~nondet13 <= 2147483647;~tmp___6~0 := #t~nondet13;havoc #t~nondet13;havoc ~tmp___7~0;assume -2147483648 <= #t~nondet14 && #t~nondet14 <= 2147483647;~tmp___8~0 := #t~nondet14;havoc #t~nondet14;assume -2147483648 <= #t~nondet15 && #t~nondet15 <= 2147483647;~tmp___9~0 := #t~nondet15;havoc #t~nondet15;assume -2147483648 <= #t~nondet16 && #t~nondet16 <= 2147483647;~tmp___10~0 := #t~nondet16;havoc #t~nondet16;havoc ~blastFlag~0;~blastFlag~0 := 0;assume -2147483648 <= #t~nondet17 && #t~nondet17 <= 2147483647;call write~int(#t~nondet17, ~s.base, ~s.offset + 92, 4);havoc #t~nondet17;call write~int(8464, ~s.base, ~s.offset + 52, 4);assume -2147483648 <= #t~nondet18 && #t~nondet18 <= 2147483647;~tmp~3 := #t~nondet18;havoc #t~nondet18;~Time~0 := ~tmp~3;~cb~0.base, ~cb~0.offset := 0, 0;~ret~0 := -1;~skip~0 := 0;~got_new_session~0 := 0;call #t~mem19.base, #t~mem19.offset := read~$Pointer$(~s.base, ~s.offset + 192, 4); {9859#true} is VALID [2018-11-14 19:06:25,085 INFO L273 TraceCheckUtils]: 8: Hoare triple {9859#true} assume (#t~mem19.base + #t~mem19.offset) % 4294967296 != 0;havoc #t~mem19.base, #t~mem19.offset;call #t~mem20.base, #t~mem20.offset := read~$Pointer$(~s.base, ~s.offset + 192, 4);~cb~0.base, ~cb~0.offset := #t~mem20.base, #t~mem20.offset;havoc #t~mem20.base, #t~mem20.offset; {9859#true} is VALID [2018-11-14 19:06:25,085 INFO L273 TraceCheckUtils]: 9: Hoare triple {9859#true} call #t~mem21 := read~int(~s.base, ~s.offset + 28, 4);call write~int(#t~mem21 + 1, ~s.base, ~s.offset + 28, 4);havoc #t~mem21; {9859#true} is VALID [2018-11-14 19:06:25,086 INFO L273 TraceCheckUtils]: 10: Hoare triple {9859#true} assume !(~bitwiseAnd(~tmp___1~0, 12288) != 0); {9859#true} is VALID [2018-11-14 19:06:25,086 INFO L273 TraceCheckUtils]: 11: Hoare triple {9859#true} call #t~mem22.base, #t~mem22.offset := read~$Pointer$(~s.base, ~s.offset + 136, 4); {9859#true} is VALID [2018-11-14 19:06:25,086 INFO L273 TraceCheckUtils]: 12: Hoare triple {9859#true} assume !((#t~mem22.base + #t~mem22.offset) % 4294967296 == 0);havoc #t~mem22.base, #t~mem22.offset; {9859#true} is VALID [2018-11-14 19:06:25,086 INFO L273 TraceCheckUtils]: 13: Hoare triple {9859#true} assume true; {9859#true} is VALID [2018-11-14 19:06:25,086 INFO L273 TraceCheckUtils]: 14: Hoare triple {9859#true} assume !false; {9859#true} is VALID [2018-11-14 19:06:25,086 INFO L273 TraceCheckUtils]: 15: Hoare triple {9859#true} call #t~mem23 := read~int(~s.base, ~s.offset + 52, 4);~state~0 := #t~mem23;havoc #t~mem23;call #t~mem24 := read~int(~s.base, ~s.offset + 52, 4); {9859#true} is VALID [2018-11-14 19:06:25,086 INFO L273 TraceCheckUtils]: 16: Hoare triple {9859#true} assume !(#t~mem24 == 12292);havoc #t~mem24;call #t~mem25 := read~int(~s.base, ~s.offset + 52, 4); {9859#true} is VALID [2018-11-14 19:06:25,086 INFO L273 TraceCheckUtils]: 17: Hoare triple {9859#true} assume !(#t~mem25 == 16384);havoc #t~mem25;call #t~mem26 := read~int(~s.base, ~s.offset + 52, 4); {9859#true} is VALID [2018-11-14 19:06:25,087 INFO L273 TraceCheckUtils]: 18: Hoare triple {9859#true} assume !(#t~mem26 == 8192);havoc #t~mem26;call #t~mem27 := read~int(~s.base, ~s.offset + 52, 4); {9859#true} is VALID [2018-11-14 19:06:25,087 INFO L273 TraceCheckUtils]: 19: Hoare triple {9859#true} assume !(#t~mem27 == 24576);havoc #t~mem27;call #t~mem28 := read~int(~s.base, ~s.offset + 52, 4); {9859#true} is VALID [2018-11-14 19:06:25,087 INFO L273 TraceCheckUtils]: 20: Hoare triple {9859#true} assume !(#t~mem28 == 8195);havoc #t~mem28;call #t~mem29 := read~int(~s.base, ~s.offset + 52, 4); {9859#true} is VALID [2018-11-14 19:06:25,087 INFO L273 TraceCheckUtils]: 21: Hoare triple {9859#true} assume !(#t~mem29 == 8480);havoc #t~mem29;call #t~mem30 := read~int(~s.base, ~s.offset + 52, 4); {9859#true} is VALID [2018-11-14 19:06:25,087 INFO L273 TraceCheckUtils]: 22: Hoare triple {9859#true} assume !(#t~mem30 == 8481);havoc #t~mem30;call #t~mem31 := read~int(~s.base, ~s.offset + 52, 4); {9859#true} is VALID [2018-11-14 19:06:25,087 INFO L273 TraceCheckUtils]: 23: Hoare triple {9859#true} assume !(#t~mem31 == 8482);havoc #t~mem31;call #t~mem32 := read~int(~s.base, ~s.offset + 52, 4); {9859#true} is VALID [2018-11-14 19:06:25,087 INFO L273 TraceCheckUtils]: 24: Hoare triple {9859#true} assume #t~mem32 == 8464;havoc #t~mem32; {9859#true} is VALID [2018-11-14 19:06:25,087 INFO L273 TraceCheckUtils]: 25: Hoare triple {9859#true} call write~int(0, ~s.base, ~s.offset + 48, 4);assume -2147483648 <= #t~nondet69 && #t~nondet69 <= 2147483647;~ret~0 := #t~nondet69;havoc #t~nondet69; {9859#true} is VALID [2018-11-14 19:06:25,088 INFO L273 TraceCheckUtils]: 26: Hoare triple {9859#true} assume ~blastFlag~0 == 0;~blastFlag~0 := 1; {9859#true} is VALID [2018-11-14 19:06:25,088 INFO L273 TraceCheckUtils]: 27: Hoare triple {9859#true} assume !(~ret~0 <= 0);~got_new_session~0 := 1;call write~int(8496, ~s.base, ~s.offset + 52, 4);call write~int(0, ~s.base, ~s.offset + 64, 4); {9859#true} is VALID [2018-11-14 19:06:25,088 INFO L273 TraceCheckUtils]: 28: Hoare triple {9859#true} call #t~mem127.base, #t~mem127.offset := read~$Pointer$(~s.base, ~s.offset + 84, 4);call #t~mem128 := read~int(#t~mem127.base, #t~mem127.offset + 604 + 244, 4); {9859#true} is VALID [2018-11-14 19:06:25,088 INFO L273 TraceCheckUtils]: 29: Hoare triple {9859#true} assume !(#t~mem128 == 0);havoc #t~mem127.base, #t~mem127.offset;havoc #t~mem128; {9859#true} is VALID [2018-11-14 19:06:25,088 INFO L273 TraceCheckUtils]: 30: Hoare triple {9859#true} ~skip~0 := 0; {9859#true} is VALID [2018-11-14 19:06:25,088 INFO L273 TraceCheckUtils]: 31: Hoare triple {9859#true} assume true; {9859#true} is VALID [2018-11-14 19:06:25,088 INFO L273 TraceCheckUtils]: 32: Hoare triple {9859#true} assume !false; {9859#true} is VALID [2018-11-14 19:06:25,088 INFO L273 TraceCheckUtils]: 33: Hoare triple {9859#true} call #t~mem23 := read~int(~s.base, ~s.offset + 52, 4);~state~0 := #t~mem23;havoc #t~mem23;call #t~mem24 := read~int(~s.base, ~s.offset + 52, 4); {9859#true} is VALID [2018-11-14 19:06:25,089 INFO L273 TraceCheckUtils]: 34: Hoare triple {9859#true} assume #t~mem24 == 12292;havoc #t~mem24; {9859#true} is VALID [2018-11-14 19:06:25,089 INFO L273 TraceCheckUtils]: 35: Hoare triple {9859#true} call write~int(1, ~s.base, ~s.offset + 40, 4); {9859#true} is VALID [2018-11-14 19:06:25,089 INFO L273 TraceCheckUtils]: 36: Hoare triple {9859#true} call write~int(1, ~s.base, ~s.offset + 36, 4); {9859#true} is VALID [2018-11-14 19:06:25,089 INFO L273 TraceCheckUtils]: 37: Hoare triple {9859#true} assume (~cb~0.base + ~cb~0.offset) % 4294967296 != 0; {9859#true} is VALID [2018-11-14 19:06:25,089 INFO L273 TraceCheckUtils]: 38: Hoare triple {9859#true} call #t~mem59 := read~int(~s.base, ~s.offset + 0, 4); {9859#true} is VALID [2018-11-14 19:06:25,089 INFO L273 TraceCheckUtils]: 39: Hoare triple {9859#true} assume !(#t~mem59 / 256 != 3);havoc #t~mem59;call write~int(8192, ~s.base, ~s.offset + 4, 4);call #t~mem60.base, #t~mem60.offset := read~$Pointer$(~s.base, ~s.offset + 60, 4); {9859#true} is VALID [2018-11-14 19:06:25,090 INFO L273 TraceCheckUtils]: 40: Hoare triple {9859#true} assume !((#t~mem60.base + #t~mem60.offset) % 4294967296 == 0);havoc #t~mem60.base, #t~mem60.offset; {9859#true} is VALID [2018-11-14 19:06:25,090 INFO L273 TraceCheckUtils]: 41: Hoare triple {9859#true} assume !(~tmp___4~0 == 0);call write~int(0, ~s.base, ~s.offset + 64, 4);call #t~mem62 := read~int(~s.base, ~s.offset + 52, 4); {9859#true} is VALID [2018-11-14 19:06:25,106 INFO L273 TraceCheckUtils]: 42: Hoare triple {9859#true} assume !(#t~mem62 != 12292);havoc #t~mem62;call #t~mem65.base, #t~mem65.offset := read~$Pointer$(~s.base, ~s.offset + 204, 4);call #t~mem66 := read~int(#t~mem65.base, #t~mem65.offset + 60 + 16, 4);call write~int(#t~mem66 + 1, #t~mem65.base, #t~mem65.offset + 60 + 16, 4);havoc #t~mem66;havoc #t~mem65.base, #t~mem65.offset;call write~int(8480, ~s.base, ~s.offset + 52, 4); {9861#(= 8480 (select (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 52)))} is VALID [2018-11-14 19:06:25,115 INFO L273 TraceCheckUtils]: 43: Hoare triple {9861#(= 8480 (select (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 52)))} call #t~mem127.base, #t~mem127.offset := read~$Pointer$(~s.base, ~s.offset + 84, 4);call #t~mem128 := read~int(#t~mem127.base, #t~mem127.offset + 604 + 244, 4); {9861#(= 8480 (select (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 52)))} is VALID [2018-11-14 19:06:25,129 INFO L273 TraceCheckUtils]: 44: Hoare triple {9861#(= 8480 (select (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 52)))} assume !(#t~mem128 == 0);havoc #t~mem127.base, #t~mem127.offset;havoc #t~mem128; {9861#(= 8480 (select (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 52)))} is VALID [2018-11-14 19:06:25,138 INFO L273 TraceCheckUtils]: 45: Hoare triple {9861#(= 8480 (select (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 52)))} ~skip~0 := 0; {9861#(= 8480 (select (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 52)))} is VALID [2018-11-14 19:06:25,151 INFO L273 TraceCheckUtils]: 46: Hoare triple {9861#(= 8480 (select (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 52)))} assume true; {9861#(= 8480 (select (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 52)))} is VALID [2018-11-14 19:06:25,159 INFO L273 TraceCheckUtils]: 47: Hoare triple {9861#(= 8480 (select (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 52)))} assume !false; {9861#(= 8480 (select (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 52)))} is VALID [2018-11-14 19:06:25,173 INFO L273 TraceCheckUtils]: 48: Hoare triple {9861#(= 8480 (select (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 52)))} call #t~mem23 := read~int(~s.base, ~s.offset + 52, 4);~state~0 := #t~mem23;havoc #t~mem23;call #t~mem24 := read~int(~s.base, ~s.offset + 52, 4); {9861#(= 8480 (select (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 52)))} is VALID [2018-11-14 19:06:25,182 INFO L273 TraceCheckUtils]: 49: Hoare triple {9861#(= 8480 (select (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 52)))} assume !(#t~mem24 == 12292);havoc #t~mem24;call #t~mem25 := read~int(~s.base, ~s.offset + 52, 4); {9861#(= 8480 (select (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 52)))} is VALID [2018-11-14 19:06:25,195 INFO L273 TraceCheckUtils]: 50: Hoare triple {9861#(= 8480 (select (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 52)))} assume !(#t~mem25 == 16384);havoc #t~mem25;call #t~mem26 := read~int(~s.base, ~s.offset + 52, 4); {9861#(= 8480 (select (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 52)))} is VALID [2018-11-14 19:06:25,196 INFO L273 TraceCheckUtils]: 51: Hoare triple {9861#(= 8480 (select (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 52)))} assume !(#t~mem26 == 8192);havoc #t~mem26;call #t~mem27 := read~int(~s.base, ~s.offset + 52, 4); {9861#(= 8480 (select (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 52)))} is VALID [2018-11-14 19:06:25,196 INFO L273 TraceCheckUtils]: 52: Hoare triple {9861#(= 8480 (select (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 52)))} assume !(#t~mem27 == 24576);havoc #t~mem27;call #t~mem28 := read~int(~s.base, ~s.offset + 52, 4); {9861#(= 8480 (select (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 52)))} is VALID [2018-11-14 19:06:25,197 INFO L273 TraceCheckUtils]: 53: Hoare triple {9861#(= 8480 (select (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 52)))} assume !(#t~mem28 == 8195);havoc #t~mem28;call #t~mem29 := read~int(~s.base, ~s.offset + 52, 4); {9862#(= 8480 |ssl3_accept_#t~mem29|)} is VALID [2018-11-14 19:06:25,197 INFO L273 TraceCheckUtils]: 54: Hoare triple {9862#(= 8480 |ssl3_accept_#t~mem29|)} assume !(#t~mem29 == 8480);havoc #t~mem29;call #t~mem30 := read~int(~s.base, ~s.offset + 52, 4); {9860#false} is VALID [2018-11-14 19:06:25,197 INFO L273 TraceCheckUtils]: 55: Hoare triple {9860#false} assume !(#t~mem30 == 8481);havoc #t~mem30;call #t~mem31 := read~int(~s.base, ~s.offset + 52, 4); {9860#false} is VALID [2018-11-14 19:06:25,197 INFO L273 TraceCheckUtils]: 56: Hoare triple {9860#false} assume !(#t~mem31 == 8482);havoc #t~mem31;call #t~mem32 := read~int(~s.base, ~s.offset + 52, 4); {9860#false} is VALID [2018-11-14 19:06:25,197 INFO L273 TraceCheckUtils]: 57: Hoare triple {9860#false} assume !(#t~mem32 == 8464);havoc #t~mem32;call #t~mem33 := read~int(~s.base, ~s.offset + 52, 4); {9860#false} is VALID [2018-11-14 19:06:25,197 INFO L273 TraceCheckUtils]: 58: Hoare triple {9860#false} assume !(#t~mem33 == 8465);havoc #t~mem33;call #t~mem34 := read~int(~s.base, ~s.offset + 52, 4); {9860#false} is VALID [2018-11-14 19:06:25,198 INFO L273 TraceCheckUtils]: 59: Hoare triple {9860#false} assume !(#t~mem34 == 8466);havoc #t~mem34;call #t~mem35 := read~int(~s.base, ~s.offset + 52, 4); {9860#false} is VALID [2018-11-14 19:06:25,198 INFO L273 TraceCheckUtils]: 60: Hoare triple {9860#false} assume !(#t~mem35 == 8496);havoc #t~mem35;call #t~mem36 := read~int(~s.base, ~s.offset + 52, 4); {9860#false} is VALID [2018-11-14 19:06:25,198 INFO L273 TraceCheckUtils]: 61: Hoare triple {9860#false} assume !(#t~mem36 == 8497);havoc #t~mem36;call #t~mem37 := read~int(~s.base, ~s.offset + 52, 4); {9860#false} is VALID [2018-11-14 19:06:25,198 INFO L273 TraceCheckUtils]: 62: Hoare triple {9860#false} assume !(#t~mem37 == 8512);havoc #t~mem37;call #t~mem38 := read~int(~s.base, ~s.offset + 52, 4); {9860#false} is VALID [2018-11-14 19:06:25,198 INFO L273 TraceCheckUtils]: 63: Hoare triple {9860#false} assume !(#t~mem38 == 8513);havoc #t~mem38;call #t~mem39 := read~int(~s.base, ~s.offset + 52, 4); {9860#false} is VALID [2018-11-14 19:06:25,198 INFO L273 TraceCheckUtils]: 64: Hoare triple {9860#false} assume !(#t~mem39 == 8528);havoc #t~mem39;call #t~mem40 := read~int(~s.base, ~s.offset + 52, 4); {9860#false} is VALID [2018-11-14 19:06:25,198 INFO L273 TraceCheckUtils]: 65: Hoare triple {9860#false} assume !(#t~mem40 == 8529);havoc #t~mem40;call #t~mem41 := read~int(~s.base, ~s.offset + 52, 4); {9860#false} is VALID [2018-11-14 19:06:25,198 INFO L273 TraceCheckUtils]: 66: Hoare triple {9860#false} assume !(#t~mem41 == 8544);havoc #t~mem41;call #t~mem42 := read~int(~s.base, ~s.offset + 52, 4); {9860#false} is VALID [2018-11-14 19:06:25,199 INFO L273 TraceCheckUtils]: 67: Hoare triple {9860#false} assume !(#t~mem42 == 8545);havoc #t~mem42;call #t~mem43 := read~int(~s.base, ~s.offset + 52, 4); {9860#false} is VALID [2018-11-14 19:06:25,199 INFO L273 TraceCheckUtils]: 68: Hoare triple {9860#false} assume !(#t~mem43 == 8560);havoc #t~mem43;call #t~mem44 := read~int(~s.base, ~s.offset + 52, 4); {9860#false} is VALID [2018-11-14 19:06:25,199 INFO L273 TraceCheckUtils]: 69: Hoare triple {9860#false} assume !(#t~mem44 == 8561);havoc #t~mem44;call #t~mem45 := read~int(~s.base, ~s.offset + 52, 4); {9860#false} is VALID [2018-11-14 19:06:25,199 INFO L273 TraceCheckUtils]: 70: Hoare triple {9860#false} assume !(#t~mem45 == 8448);havoc #t~mem45;call #t~mem46 := read~int(~s.base, ~s.offset + 52, 4); {9860#false} is VALID [2018-11-14 19:06:25,199 INFO L273 TraceCheckUtils]: 71: Hoare triple {9860#false} assume !(#t~mem46 == 8576);havoc #t~mem46;call #t~mem47 := read~int(~s.base, ~s.offset + 52, 4); {9860#false} is VALID [2018-11-14 19:06:25,199 INFO L273 TraceCheckUtils]: 72: Hoare triple {9860#false} assume !(#t~mem47 == 8577);havoc #t~mem47;call #t~mem48 := read~int(~s.base, ~s.offset + 52, 4); {9860#false} is VALID [2018-11-14 19:06:25,199 INFO L273 TraceCheckUtils]: 73: Hoare triple {9860#false} assume !(#t~mem48 == 8592);havoc #t~mem48;call #t~mem49 := read~int(~s.base, ~s.offset + 52, 4); {9860#false} is VALID [2018-11-14 19:06:25,199 INFO L273 TraceCheckUtils]: 74: Hoare triple {9860#false} assume !(#t~mem49 == 8593);havoc #t~mem49;call #t~mem50 := read~int(~s.base, ~s.offset + 52, 4); {9860#false} is VALID [2018-11-14 19:06:25,199 INFO L273 TraceCheckUtils]: 75: Hoare triple {9860#false} assume !(#t~mem50 == 8608);havoc #t~mem50;call #t~mem51 := read~int(~s.base, ~s.offset + 52, 4); {9860#false} is VALID [2018-11-14 19:06:25,200 INFO L273 TraceCheckUtils]: 76: Hoare triple {9860#false} assume !(#t~mem51 == 8609);havoc #t~mem51;call #t~mem52 := read~int(~s.base, ~s.offset + 52, 4); {9860#false} is VALID [2018-11-14 19:06:25,200 INFO L273 TraceCheckUtils]: 77: Hoare triple {9860#false} assume !(#t~mem52 == 8640);havoc #t~mem52;call #t~mem53 := read~int(~s.base, ~s.offset + 52, 4); {9860#false} is VALID [2018-11-14 19:06:25,200 INFO L273 TraceCheckUtils]: 78: Hoare triple {9860#false} assume !(#t~mem53 == 8641);havoc #t~mem53;call #t~mem54 := read~int(~s.base, ~s.offset + 52, 4); {9860#false} is VALID [2018-11-14 19:06:25,200 INFO L273 TraceCheckUtils]: 79: Hoare triple {9860#false} assume !(#t~mem54 == 8656);havoc #t~mem54;call #t~mem55 := read~int(~s.base, ~s.offset + 52, 4); {9860#false} is VALID [2018-11-14 19:06:25,200 INFO L273 TraceCheckUtils]: 80: Hoare triple {9860#false} assume !(#t~mem55 == 8657);havoc #t~mem55;call #t~mem56 := read~int(~s.base, ~s.offset + 52, 4); {9860#false} is VALID [2018-11-14 19:06:25,200 INFO L273 TraceCheckUtils]: 81: Hoare triple {9860#false} assume #t~mem56 == 8672;havoc #t~mem56; {9860#false} is VALID [2018-11-14 19:06:25,200 INFO L273 TraceCheckUtils]: 82: Hoare triple {9860#false} assume -2147483648 <= #t~nondet121 && #t~nondet121 <= 2147483647;~ret~0 := #t~nondet121;havoc #t~nondet121; {9860#false} is VALID [2018-11-14 19:06:25,200 INFO L273 TraceCheckUtils]: 83: Hoare triple {9860#false} assume ~blastFlag~0 == 4; {9860#false} is VALID [2018-11-14 19:06:25,200 INFO L273 TraceCheckUtils]: 84: Hoare triple {9860#false} assume !false; {9860#false} is VALID [2018-11-14 19:06:25,205 INFO L134 CoverageAnalysis]: Checked inductivity of 23 backedges. 19 proven. 0 refuted. 0 times theorem prover too weak. 4 trivial. 0 not checked. [2018-11-14 19:06:25,205 INFO L312 seRefinementStrategy]: Constructing automaton from 1 perfect and 0 imperfect interpolant sequences. [2018-11-14 19:06:25,205 INFO L327 seRefinementStrategy]: Number of different interpolants: perfect sequences [4] imperfect sequences [] total 4 [2018-11-14 19:06:25,206 INFO L78 Accepts]: Start accepts. Automaton has 4 states. Word has length 85 [2018-11-14 19:06:25,206 INFO L84 Accepts]: Finished accepts. word is accepted. [2018-11-14 19:06:25,206 INFO L86 InductivityCheck]: Starting indutivity check of a Floyd-Hoare automaton with 4 states. [2018-11-14 19:06:25,287 INFO L119 InductivityCheck]: Floyd-Hoare automaton has 82 edges. 82 inductive. 0 not inductive. 0 times theorem prover too weak to decide inductivity. [2018-11-14 19:06:25,287 INFO L459 AbstractCegarLoop]: Interpolant automaton has 4 states [2018-11-14 19:06:25,287 INFO L142 InterpolantAutomaton]: Constructing interpolant automaton starting with 4 interpolants. [2018-11-14 19:06:25,287 INFO L144 InterpolantAutomaton]: CoverageRelationStatistics Valid=5, Invalid=7, Unknown=0, NotChecked=0, Total=12 [2018-11-14 19:06:25,288 INFO L87 Difference]: Start difference. First operand 172 states and 254 transitions. Second operand 4 states. [2018-11-14 19:06:26,713 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2018-11-14 19:06:26,713 INFO L93 Difference]: Finished difference Result 348 states and 523 transitions. [2018-11-14 19:06:26,714 INFO L142 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 4 states. [2018-11-14 19:06:26,714 INFO L78 Accepts]: Start accepts. Automaton has 4 states. Word has length 85 [2018-11-14 19:06:26,714 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2018-11-14 19:06:26,714 INFO L82 GeneralOperation]: Start removeUnreachable. Operand 4 states. [2018-11-14 19:06:26,716 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 4 states to 4 states and 435 transitions. [2018-11-14 19:06:26,716 INFO L82 GeneralOperation]: Start removeUnreachable. Operand 4 states. [2018-11-14 19:06:26,718 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 4 states to 4 states and 435 transitions. [2018-11-14 19:06:26,718 INFO L86 InductivityCheck]: Starting indutivity check of a Floyd-Hoare automaton with 4 states and 435 transitions. [2018-11-14 19:06:27,202 INFO L119 InductivityCheck]: Floyd-Hoare automaton has 435 edges. 435 inductive. 0 not inductive. 0 times theorem prover too weak to decide inductivity. [2018-11-14 19:06:27,206 INFO L225 Difference]: With dead ends: 348 [2018-11-14 19:06:27,207 INFO L226 Difference]: Without dead ends: 202 [2018-11-14 19:06:27,207 INFO L604 BasicCegarLoop]: 0 DeclaredPredicates, 6 GetRequests, 2 SyntacticMatches, 1 SemanticMatches, 3 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 0 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=9, Invalid=11, Unknown=0, NotChecked=0, Total=20 [2018-11-14 19:06:27,207 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 202 states. [2018-11-14 19:06:27,230 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 202 to 189. [2018-11-14 19:06:27,230 INFO L214 AbstractMinimizeNwa]: Start testing correctness of minimizeSevpa [2018-11-14 19:06:27,230 INFO L82 GeneralOperation]: Start isEquivalent. First operand 202 states. Second operand 189 states. [2018-11-14 19:06:27,230 INFO L74 IsIncluded]: Start isIncluded. First operand 202 states. Second operand 189 states. [2018-11-14 19:06:27,230 INFO L87 Difference]: Start difference. First operand 202 states. Second operand 189 states. [2018-11-14 19:06:27,234 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2018-11-14 19:06:27,234 INFO L93 Difference]: Finished difference Result 202 states and 297 transitions. [2018-11-14 19:06:27,234 INFO L276 IsEmpty]: Start isEmpty. Operand 202 states and 297 transitions. [2018-11-14 19:06:27,235 INFO L282 IsEmpty]: Finished isEmpty. No accepting run. [2018-11-14 19:06:27,235 INFO L83 IsIncluded]: Finished isIncluded. Language is included [2018-11-14 19:06:27,235 INFO L74 IsIncluded]: Start isIncluded. First operand 189 states. Second operand 202 states. [2018-11-14 19:06:27,235 INFO L87 Difference]: Start difference. First operand 189 states. Second operand 202 states. [2018-11-14 19:06:27,239 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2018-11-14 19:06:27,240 INFO L93 Difference]: Finished difference Result 202 states and 297 transitions. [2018-11-14 19:06:27,240 INFO L276 IsEmpty]: Start isEmpty. Operand 202 states and 297 transitions. [2018-11-14 19:06:27,240 INFO L282 IsEmpty]: Finished isEmpty. No accepting run. [2018-11-14 19:06:27,240 INFO L83 IsIncluded]: Finished isIncluded. Language is included [2018-11-14 19:06:27,241 INFO L88 GeneralOperation]: Finished isEquivalent. [2018-11-14 19:06:27,241 INFO L221 AbstractMinimizeNwa]: Finished testing correctness of minimizeSevpa [2018-11-14 19:06:27,241 INFO L82 GeneralOperation]: Start removeUnreachable. Operand 189 states. [2018-11-14 19:06:27,244 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 189 states to 189 states and 281 transitions. [2018-11-14 19:06:27,245 INFO L78 Accepts]: Start accepts. Automaton has 189 states and 281 transitions. Word has length 85 [2018-11-14 19:06:27,245 INFO L84 Accepts]: Finished accepts. word is rejected. [2018-11-14 19:06:27,245 INFO L480 AbstractCegarLoop]: Abstraction has 189 states and 281 transitions. [2018-11-14 19:06:27,245 INFO L481 AbstractCegarLoop]: Interpolant automaton has 4 states. [2018-11-14 19:06:27,245 INFO L276 IsEmpty]: Start isEmpty. Operand 189 states and 281 transitions. [2018-11-14 19:06:27,246 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 86 [2018-11-14 19:06:27,246 INFO L367 BasicCegarLoop]: Found error trace [2018-11-14 19:06:27,246 INFO L375 BasicCegarLoop]: trace histogram [3, 3, 3, 3, 3, 3, 3, 3, 3, 2, 2, 2, 2, 2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2018-11-14 19:06:27,246 INFO L423 AbstractCegarLoop]: === Iteration 13 === [ssl3_acceptErr0ASSERT_VIOLATIONERROR_FUNCTION]=== [2018-11-14 19:06:27,247 INFO L141 PredicateUnifier]: Initialized classic predicate unifier [2018-11-14 19:06:27,247 INFO L82 PathProgramCache]: Analyzing trace with hash -1100881291, now seen corresponding path program 1 times [2018-11-14 19:06:27,247 INFO L223 ckRefinementStrategy]: Switched to mode SMTINTERPOL_TREE_INTERPOLANTS [2018-11-14 19:06:27,247 INFO L69 tionRefinementEngine]: Using refinement strategy CamelRefinementStrategy [2018-11-14 19:06:27,248 INFO L119 rtionOrderModulation]: Craig_TreeInterpolation forces the order to NOT_INCREMENTALLY [2018-11-14 19:06:27,248 INFO L103 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2018-11-14 19:06:27,248 INFO L119 rtionOrderModulation]: Craig_TreeInterpolation forces the order to NOT_INCREMENTALLY [2018-11-14 19:06:27,265 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2018-11-14 19:06:27,791 INFO L256 TraceCheckUtils]: 0: Hoare triple {10904#true} call ULTIMATE.init(); {10904#true} is VALID [2018-11-14 19:06:27,792 INFO L273 TraceCheckUtils]: 1: Hoare triple {10904#true} #NULL.base, #NULL.offset := 0, 0;#valid := #valid[0 := 0];~init~0 := 1;call ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset := #Ultimate.alloc(100);call write~unchecked~int(0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 0, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 4, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 8, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 12, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 16, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 20, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 24, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 28, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 32, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 36, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 40, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 44, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 48, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 52, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 56, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 60, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 64, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 68, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 72, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 76, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 80, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 84, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 88, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 92, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 96, 4);call write~unchecked~int(0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 0, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 4, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 8, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 12, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 16, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 20, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 24, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 28, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 32, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 36, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 40, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 44, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 48, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 52, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 56, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 60, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 64, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 68, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 72, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 76, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 80, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 84, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 88, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 92, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 96, 4); {10904#true} is VALID [2018-11-14 19:06:27,792 INFO L273 TraceCheckUtils]: 2: Hoare triple {10904#true} assume true; {10904#true} is VALID [2018-11-14 19:06:27,792 INFO L268 TraceCheckUtils]: 3: Hoare quadruple {10904#true} {10904#true} #654#return; {10904#true} is VALID [2018-11-14 19:06:27,792 INFO L256 TraceCheckUtils]: 4: Hoare triple {10904#true} call #t~ret138 := main(); {10904#true} is VALID [2018-11-14 19:06:27,792 INFO L273 TraceCheckUtils]: 5: Hoare triple {10904#true} havoc ~s~0.base, ~s~0.offset;havoc ~tmp~2;call #t~malloc3.base, #t~malloc3.offset := #Ultimate.alloc(248);~s~0.base, ~s~0.offset := #t~malloc3.base, #t~malloc3.offset;call #t~malloc4.base, #t~malloc4.offset := #Ultimate.alloc(899);call write~$Pointer$(#t~malloc4.base, #t~malloc4.offset, ~s~0.base, ~s~0.offset + 84, 4);call #t~malloc5.base, #t~malloc5.offset := #Ultimate.alloc(232);call write~$Pointer$(#t~malloc5.base, #t~malloc5.offset, ~s~0.base, ~s~0.offset + 204, 4);call #t~malloc6.base, #t~malloc6.offset := #Ultimate.alloc(200);call write~$Pointer$(#t~malloc6.base, #t~malloc6.offset, ~s~0.base, ~s~0.offset + 176, 4);call write~int(8464, ~s~0.base, ~s~0.offset + 52, 4); {10904#true} is VALID [2018-11-14 19:06:27,792 INFO L256 TraceCheckUtils]: 6: Hoare triple {10904#true} call #t~ret7 := ssl3_accept(~s~0.base, ~s~0.offset); {10904#true} is VALID [2018-11-14 19:06:27,792 INFO L273 TraceCheckUtils]: 7: Hoare triple {10904#true} ~s.base, ~s.offset := #in~s.base, #in~s.offset;havoc ~buf~0.base, ~buf~0.offset;havoc ~l~0;havoc ~Time~0;havoc ~tmp~3;havoc ~cb~0.base, ~cb~0.offset;havoc ~num1~0;havoc ~ret~0;havoc ~new_state~0;havoc ~state~0;havoc ~skip~0;havoc ~got_new_session~0;assume -2147483648 <= #t~nondet8 && #t~nondet8 <= 2147483647;~tmp___1~0 := #t~nondet8;havoc #t~nondet8;assume -2147483648 <= #t~nondet9 && #t~nondet9 <= 2147483647;~tmp___2~0 := #t~nondet9;havoc #t~nondet9;assume -2147483648 <= #t~nondet10 && #t~nondet10 <= 2147483647;~tmp___3~0 := #t~nondet10;havoc #t~nondet10;assume -2147483648 <= #t~nondet11 && #t~nondet11 <= 2147483647;~tmp___4~0 := #t~nondet11;havoc #t~nondet11;assume -2147483648 <= #t~nondet12 && #t~nondet12 <= 2147483647;~tmp___5~0 := #t~nondet12;havoc #t~nondet12;assume -2147483648 <= #t~nondet13 && #t~nondet13 <= 2147483647;~tmp___6~0 := #t~nondet13;havoc #t~nondet13;havoc ~tmp___7~0;assume -2147483648 <= #t~nondet14 && #t~nondet14 <= 2147483647;~tmp___8~0 := #t~nondet14;havoc #t~nondet14;assume -2147483648 <= #t~nondet15 && #t~nondet15 <= 2147483647;~tmp___9~0 := #t~nondet15;havoc #t~nondet15;assume -2147483648 <= #t~nondet16 && #t~nondet16 <= 2147483647;~tmp___10~0 := #t~nondet16;havoc #t~nondet16;havoc ~blastFlag~0;~blastFlag~0 := 0;assume -2147483648 <= #t~nondet17 && #t~nondet17 <= 2147483647;call write~int(#t~nondet17, ~s.base, ~s.offset + 92, 4);havoc #t~nondet17;call write~int(8464, ~s.base, ~s.offset + 52, 4);assume -2147483648 <= #t~nondet18 && #t~nondet18 <= 2147483647;~tmp~3 := #t~nondet18;havoc #t~nondet18;~Time~0 := ~tmp~3;~cb~0.base, ~cb~0.offset := 0, 0;~ret~0 := -1;~skip~0 := 0;~got_new_session~0 := 0;call #t~mem19.base, #t~mem19.offset := read~$Pointer$(~s.base, ~s.offset + 192, 4); {10904#true} is VALID [2018-11-14 19:06:27,793 INFO L273 TraceCheckUtils]: 8: Hoare triple {10904#true} assume (#t~mem19.base + #t~mem19.offset) % 4294967296 != 0;havoc #t~mem19.base, #t~mem19.offset;call #t~mem20.base, #t~mem20.offset := read~$Pointer$(~s.base, ~s.offset + 192, 4);~cb~0.base, ~cb~0.offset := #t~mem20.base, #t~mem20.offset;havoc #t~mem20.base, #t~mem20.offset; {10904#true} is VALID [2018-11-14 19:06:27,793 INFO L273 TraceCheckUtils]: 9: Hoare triple {10904#true} call #t~mem21 := read~int(~s.base, ~s.offset + 28, 4);call write~int(#t~mem21 + 1, ~s.base, ~s.offset + 28, 4);havoc #t~mem21; {10904#true} is VALID [2018-11-14 19:06:27,793 INFO L273 TraceCheckUtils]: 10: Hoare triple {10904#true} assume !(~bitwiseAnd(~tmp___1~0, 12288) != 0); {10904#true} is VALID [2018-11-14 19:06:27,793 INFO L273 TraceCheckUtils]: 11: Hoare triple {10904#true} call #t~mem22.base, #t~mem22.offset := read~$Pointer$(~s.base, ~s.offset + 136, 4); {10904#true} is VALID [2018-11-14 19:06:27,793 INFO L273 TraceCheckUtils]: 12: Hoare triple {10904#true} assume !((#t~mem22.base + #t~mem22.offset) % 4294967296 == 0);havoc #t~mem22.base, #t~mem22.offset; {10904#true} is VALID [2018-11-14 19:06:27,793 INFO L273 TraceCheckUtils]: 13: Hoare triple {10904#true} assume true; {10904#true} is VALID [2018-11-14 19:06:27,793 INFO L273 TraceCheckUtils]: 14: Hoare triple {10904#true} assume !false; {10904#true} is VALID [2018-11-14 19:06:27,793 INFO L273 TraceCheckUtils]: 15: Hoare triple {10904#true} call #t~mem23 := read~int(~s.base, ~s.offset + 52, 4);~state~0 := #t~mem23;havoc #t~mem23;call #t~mem24 := read~int(~s.base, ~s.offset + 52, 4); {10904#true} is VALID [2018-11-14 19:06:27,793 INFO L273 TraceCheckUtils]: 16: Hoare triple {10904#true} assume !(#t~mem24 == 12292);havoc #t~mem24;call #t~mem25 := read~int(~s.base, ~s.offset + 52, 4); {10904#true} is VALID [2018-11-14 19:06:27,794 INFO L273 TraceCheckUtils]: 17: Hoare triple {10904#true} assume !(#t~mem25 == 16384);havoc #t~mem25;call #t~mem26 := read~int(~s.base, ~s.offset + 52, 4); {10904#true} is VALID [2018-11-14 19:06:27,794 INFO L273 TraceCheckUtils]: 18: Hoare triple {10904#true} assume !(#t~mem26 == 8192);havoc #t~mem26;call #t~mem27 := read~int(~s.base, ~s.offset + 52, 4); {10904#true} is VALID [2018-11-14 19:06:27,794 INFO L273 TraceCheckUtils]: 19: Hoare triple {10904#true} assume !(#t~mem27 == 24576);havoc #t~mem27;call #t~mem28 := read~int(~s.base, ~s.offset + 52, 4); {10904#true} is VALID [2018-11-14 19:06:27,794 INFO L273 TraceCheckUtils]: 20: Hoare triple {10904#true} assume !(#t~mem28 == 8195);havoc #t~mem28;call #t~mem29 := read~int(~s.base, ~s.offset + 52, 4); {10904#true} is VALID [2018-11-14 19:06:27,794 INFO L273 TraceCheckUtils]: 21: Hoare triple {10904#true} assume !(#t~mem29 == 8480);havoc #t~mem29;call #t~mem30 := read~int(~s.base, ~s.offset + 52, 4); {10904#true} is VALID [2018-11-14 19:06:27,794 INFO L273 TraceCheckUtils]: 22: Hoare triple {10904#true} assume !(#t~mem30 == 8481);havoc #t~mem30;call #t~mem31 := read~int(~s.base, ~s.offset + 52, 4); {10904#true} is VALID [2018-11-14 19:06:27,794 INFO L273 TraceCheckUtils]: 23: Hoare triple {10904#true} assume !(#t~mem31 == 8482);havoc #t~mem31;call #t~mem32 := read~int(~s.base, ~s.offset + 52, 4); {10904#true} is VALID [2018-11-14 19:06:27,794 INFO L273 TraceCheckUtils]: 24: Hoare triple {10904#true} assume #t~mem32 == 8464;havoc #t~mem32; {10904#true} is VALID [2018-11-14 19:06:27,794 INFO L273 TraceCheckUtils]: 25: Hoare triple {10904#true} call write~int(0, ~s.base, ~s.offset + 48, 4);assume -2147483648 <= #t~nondet69 && #t~nondet69 <= 2147483647;~ret~0 := #t~nondet69;havoc #t~nondet69; {10904#true} is VALID [2018-11-14 19:06:27,795 INFO L273 TraceCheckUtils]: 26: Hoare triple {10904#true} assume ~blastFlag~0 == 0;~blastFlag~0 := 1; {10904#true} is VALID [2018-11-14 19:06:27,795 INFO L273 TraceCheckUtils]: 27: Hoare triple {10904#true} assume !(~ret~0 <= 0);~got_new_session~0 := 1;call write~int(8496, ~s.base, ~s.offset + 52, 4);call write~int(0, ~s.base, ~s.offset + 64, 4); {10906#(= (select (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 52)) 8496)} is VALID [2018-11-14 19:06:27,797 INFO L273 TraceCheckUtils]: 28: Hoare triple {10906#(= (select (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 52)) 8496)} call #t~mem127.base, #t~mem127.offset := read~$Pointer$(~s.base, ~s.offset + 84, 4);call #t~mem128 := read~int(#t~mem127.base, #t~mem127.offset + 604 + 244, 4); {10906#(= (select (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 52)) 8496)} is VALID [2018-11-14 19:06:27,797 INFO L273 TraceCheckUtils]: 29: Hoare triple {10906#(= (select (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 52)) 8496)} assume !(#t~mem128 == 0);havoc #t~mem127.base, #t~mem127.offset;havoc #t~mem128; {10906#(= (select (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 52)) 8496)} is VALID [2018-11-14 19:06:27,800 INFO L273 TraceCheckUtils]: 30: Hoare triple {10906#(= (select (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 52)) 8496)} ~skip~0 := 0; {10906#(= (select (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 52)) 8496)} is VALID [2018-11-14 19:06:27,800 INFO L273 TraceCheckUtils]: 31: Hoare triple {10906#(= (select (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 52)) 8496)} assume true; {10906#(= (select (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 52)) 8496)} is VALID [2018-11-14 19:06:27,803 INFO L273 TraceCheckUtils]: 32: Hoare triple {10906#(= (select (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 52)) 8496)} assume !false; {10906#(= (select (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 52)) 8496)} is VALID [2018-11-14 19:06:27,803 INFO L273 TraceCheckUtils]: 33: Hoare triple {10906#(= (select (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 52)) 8496)} call #t~mem23 := read~int(~s.base, ~s.offset + 52, 4);~state~0 := #t~mem23;havoc #t~mem23;call #t~mem24 := read~int(~s.base, ~s.offset + 52, 4); {10906#(= (select (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 52)) 8496)} is VALID [2018-11-14 19:06:27,803 INFO L273 TraceCheckUtils]: 34: Hoare triple {10906#(= (select (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 52)) 8496)} assume !(#t~mem24 == 12292);havoc #t~mem24;call #t~mem25 := read~int(~s.base, ~s.offset + 52, 4); {10906#(= (select (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 52)) 8496)} is VALID [2018-11-14 19:06:27,804 INFO L273 TraceCheckUtils]: 35: Hoare triple {10906#(= (select (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 52)) 8496)} assume !(#t~mem25 == 16384);havoc #t~mem25;call #t~mem26 := read~int(~s.base, ~s.offset + 52, 4); {10906#(= (select (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 52)) 8496)} is VALID [2018-11-14 19:06:27,804 INFO L273 TraceCheckUtils]: 36: Hoare triple {10906#(= (select (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 52)) 8496)} assume !(#t~mem26 == 8192);havoc #t~mem26;call #t~mem27 := read~int(~s.base, ~s.offset + 52, 4); {10906#(= (select (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 52)) 8496)} is VALID [2018-11-14 19:06:27,804 INFO L273 TraceCheckUtils]: 37: Hoare triple {10906#(= (select (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 52)) 8496)} assume !(#t~mem27 == 24576);havoc #t~mem27;call #t~mem28 := read~int(~s.base, ~s.offset + 52, 4); {10906#(= (select (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 52)) 8496)} is VALID [2018-11-14 19:06:27,804 INFO L273 TraceCheckUtils]: 38: Hoare triple {10906#(= (select (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 52)) 8496)} assume !(#t~mem28 == 8195);havoc #t~mem28;call #t~mem29 := read~int(~s.base, ~s.offset + 52, 4); {10906#(= (select (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 52)) 8496)} is VALID [2018-11-14 19:06:27,805 INFO L273 TraceCheckUtils]: 39: Hoare triple {10906#(= (select (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 52)) 8496)} assume !(#t~mem29 == 8480);havoc #t~mem29;call #t~mem30 := read~int(~s.base, ~s.offset + 52, 4); {10907#(= |ssl3_accept_#t~mem30| 8496)} is VALID [2018-11-14 19:06:27,805 INFO L273 TraceCheckUtils]: 40: Hoare triple {10907#(= |ssl3_accept_#t~mem30| 8496)} assume #t~mem30 == 8481;havoc #t~mem30; {10905#false} is VALID [2018-11-14 19:06:27,805 INFO L273 TraceCheckUtils]: 41: Hoare triple {10905#false} call write~int(0, ~s.base, ~s.offset + 48, 4);assume -2147483648 <= #t~nondet67 && #t~nondet67 <= 2147483647;~ret~0 := #t~nondet67;havoc #t~nondet67; {10905#false} is VALID [2018-11-14 19:06:27,806 INFO L273 TraceCheckUtils]: 42: Hoare triple {10905#false} assume !(~ret~0 <= 0);call #t~mem68.base, #t~mem68.offset := read~$Pointer$(~s.base, ~s.offset + 84, 4);call write~int(8482, #t~mem68.base, #t~mem68.offset + 604 + 240, 4);havoc #t~mem68.base, #t~mem68.offset;call write~int(8448, ~s.base, ~s.offset + 52, 4);call write~int(0, ~s.base, ~s.offset + 64, 4); {10905#false} is VALID [2018-11-14 19:06:27,806 INFO L273 TraceCheckUtils]: 43: Hoare triple {10905#false} call #t~mem127.base, #t~mem127.offset := read~$Pointer$(~s.base, ~s.offset + 84, 4);call #t~mem128 := read~int(#t~mem127.base, #t~mem127.offset + 604 + 244, 4); {10905#false} is VALID [2018-11-14 19:06:27,806 INFO L273 TraceCheckUtils]: 44: Hoare triple {10905#false} assume !(#t~mem128 == 0);havoc #t~mem127.base, #t~mem127.offset;havoc #t~mem128; {10905#false} is VALID [2018-11-14 19:06:27,806 INFO L273 TraceCheckUtils]: 45: Hoare triple {10905#false} ~skip~0 := 0; {10905#false} is VALID [2018-11-14 19:06:27,806 INFO L273 TraceCheckUtils]: 46: Hoare triple {10905#false} assume true; {10905#false} is VALID [2018-11-14 19:06:27,806 INFO L273 TraceCheckUtils]: 47: Hoare triple {10905#false} assume !false; {10905#false} is VALID [2018-11-14 19:06:27,806 INFO L273 TraceCheckUtils]: 48: Hoare triple {10905#false} call #t~mem23 := read~int(~s.base, ~s.offset + 52, 4);~state~0 := #t~mem23;havoc #t~mem23;call #t~mem24 := read~int(~s.base, ~s.offset + 52, 4); {10905#false} is VALID [2018-11-14 19:06:27,806 INFO L273 TraceCheckUtils]: 49: Hoare triple {10905#false} assume !(#t~mem24 == 12292);havoc #t~mem24;call #t~mem25 := read~int(~s.base, ~s.offset + 52, 4); {10905#false} is VALID [2018-11-14 19:06:27,806 INFO L273 TraceCheckUtils]: 50: Hoare triple {10905#false} assume !(#t~mem25 == 16384);havoc #t~mem25;call #t~mem26 := read~int(~s.base, ~s.offset + 52, 4); {10905#false} is VALID [2018-11-14 19:06:27,807 INFO L273 TraceCheckUtils]: 51: Hoare triple {10905#false} assume !(#t~mem26 == 8192);havoc #t~mem26;call #t~mem27 := read~int(~s.base, ~s.offset + 52, 4); {10905#false} is VALID [2018-11-14 19:06:27,807 INFO L273 TraceCheckUtils]: 52: Hoare triple {10905#false} assume !(#t~mem27 == 24576);havoc #t~mem27;call #t~mem28 := read~int(~s.base, ~s.offset + 52, 4); {10905#false} is VALID [2018-11-14 19:06:27,807 INFO L273 TraceCheckUtils]: 53: Hoare triple {10905#false} assume !(#t~mem28 == 8195);havoc #t~mem28;call #t~mem29 := read~int(~s.base, ~s.offset + 52, 4); {10905#false} is VALID [2018-11-14 19:06:27,807 INFO L273 TraceCheckUtils]: 54: Hoare triple {10905#false} assume !(#t~mem29 == 8480);havoc #t~mem29;call #t~mem30 := read~int(~s.base, ~s.offset + 52, 4); {10905#false} is VALID [2018-11-14 19:06:27,807 INFO L273 TraceCheckUtils]: 55: Hoare triple {10905#false} assume !(#t~mem30 == 8481);havoc #t~mem30;call #t~mem31 := read~int(~s.base, ~s.offset + 52, 4); {10905#false} is VALID [2018-11-14 19:06:27,807 INFO L273 TraceCheckUtils]: 56: Hoare triple {10905#false} assume !(#t~mem31 == 8482);havoc #t~mem31;call #t~mem32 := read~int(~s.base, ~s.offset + 52, 4); {10905#false} is VALID [2018-11-14 19:06:27,807 INFO L273 TraceCheckUtils]: 57: Hoare triple {10905#false} assume !(#t~mem32 == 8464);havoc #t~mem32;call #t~mem33 := read~int(~s.base, ~s.offset + 52, 4); {10905#false} is VALID [2018-11-14 19:06:27,807 INFO L273 TraceCheckUtils]: 58: Hoare triple {10905#false} assume !(#t~mem33 == 8465);havoc #t~mem33;call #t~mem34 := read~int(~s.base, ~s.offset + 52, 4); {10905#false} is VALID [2018-11-14 19:06:27,807 INFO L273 TraceCheckUtils]: 59: Hoare triple {10905#false} assume !(#t~mem34 == 8466);havoc #t~mem34;call #t~mem35 := read~int(~s.base, ~s.offset + 52, 4); {10905#false} is VALID [2018-11-14 19:06:27,808 INFO L273 TraceCheckUtils]: 60: Hoare triple {10905#false} assume !(#t~mem35 == 8496);havoc #t~mem35;call #t~mem36 := read~int(~s.base, ~s.offset + 52, 4); {10905#false} is VALID [2018-11-14 19:06:27,808 INFO L273 TraceCheckUtils]: 61: Hoare triple {10905#false} assume !(#t~mem36 == 8497);havoc #t~mem36;call #t~mem37 := read~int(~s.base, ~s.offset + 52, 4); {10905#false} is VALID [2018-11-14 19:06:27,808 INFO L273 TraceCheckUtils]: 62: Hoare triple {10905#false} assume !(#t~mem37 == 8512);havoc #t~mem37;call #t~mem38 := read~int(~s.base, ~s.offset + 52, 4); {10905#false} is VALID [2018-11-14 19:06:27,808 INFO L273 TraceCheckUtils]: 63: Hoare triple {10905#false} assume !(#t~mem38 == 8513);havoc #t~mem38;call #t~mem39 := read~int(~s.base, ~s.offset + 52, 4); {10905#false} is VALID [2018-11-14 19:06:27,808 INFO L273 TraceCheckUtils]: 64: Hoare triple {10905#false} assume !(#t~mem39 == 8528);havoc #t~mem39;call #t~mem40 := read~int(~s.base, ~s.offset + 52, 4); {10905#false} is VALID [2018-11-14 19:06:27,808 INFO L273 TraceCheckUtils]: 65: Hoare triple {10905#false} assume !(#t~mem40 == 8529);havoc #t~mem40;call #t~mem41 := read~int(~s.base, ~s.offset + 52, 4); {10905#false} is VALID [2018-11-14 19:06:27,808 INFO L273 TraceCheckUtils]: 66: Hoare triple {10905#false} assume !(#t~mem41 == 8544);havoc #t~mem41;call #t~mem42 := read~int(~s.base, ~s.offset + 52, 4); {10905#false} is VALID [2018-11-14 19:06:27,808 INFO L273 TraceCheckUtils]: 67: Hoare triple {10905#false} assume !(#t~mem42 == 8545);havoc #t~mem42;call #t~mem43 := read~int(~s.base, ~s.offset + 52, 4); {10905#false} is VALID [2018-11-14 19:06:27,809 INFO L273 TraceCheckUtils]: 68: Hoare triple {10905#false} assume !(#t~mem43 == 8560);havoc #t~mem43;call #t~mem44 := read~int(~s.base, ~s.offset + 52, 4); {10905#false} is VALID [2018-11-14 19:06:27,809 INFO L273 TraceCheckUtils]: 69: Hoare triple {10905#false} assume !(#t~mem44 == 8561);havoc #t~mem44;call #t~mem45 := read~int(~s.base, ~s.offset + 52, 4); {10905#false} is VALID [2018-11-14 19:06:27,809 INFO L273 TraceCheckUtils]: 70: Hoare triple {10905#false} assume !(#t~mem45 == 8448);havoc #t~mem45;call #t~mem46 := read~int(~s.base, ~s.offset + 52, 4); {10905#false} is VALID [2018-11-14 19:06:27,809 INFO L273 TraceCheckUtils]: 71: Hoare triple {10905#false} assume !(#t~mem46 == 8576);havoc #t~mem46;call #t~mem47 := read~int(~s.base, ~s.offset + 52, 4); {10905#false} is VALID [2018-11-14 19:06:27,809 INFO L273 TraceCheckUtils]: 72: Hoare triple {10905#false} assume !(#t~mem47 == 8577);havoc #t~mem47;call #t~mem48 := read~int(~s.base, ~s.offset + 52, 4); {10905#false} is VALID [2018-11-14 19:06:27,809 INFO L273 TraceCheckUtils]: 73: Hoare triple {10905#false} assume !(#t~mem48 == 8592);havoc #t~mem48;call #t~mem49 := read~int(~s.base, ~s.offset + 52, 4); {10905#false} is VALID [2018-11-14 19:06:27,809 INFO L273 TraceCheckUtils]: 74: Hoare triple {10905#false} assume !(#t~mem49 == 8593);havoc #t~mem49;call #t~mem50 := read~int(~s.base, ~s.offset + 52, 4); {10905#false} is VALID [2018-11-14 19:06:27,809 INFO L273 TraceCheckUtils]: 75: Hoare triple {10905#false} assume !(#t~mem50 == 8608);havoc #t~mem50;call #t~mem51 := read~int(~s.base, ~s.offset + 52, 4); {10905#false} is VALID [2018-11-14 19:06:27,809 INFO L273 TraceCheckUtils]: 76: Hoare triple {10905#false} assume !(#t~mem51 == 8609);havoc #t~mem51;call #t~mem52 := read~int(~s.base, ~s.offset + 52, 4); {10905#false} is VALID [2018-11-14 19:06:27,810 INFO L273 TraceCheckUtils]: 77: Hoare triple {10905#false} assume !(#t~mem52 == 8640);havoc #t~mem52;call #t~mem53 := read~int(~s.base, ~s.offset + 52, 4); {10905#false} is VALID [2018-11-14 19:06:27,810 INFO L273 TraceCheckUtils]: 78: Hoare triple {10905#false} assume !(#t~mem53 == 8641);havoc #t~mem53;call #t~mem54 := read~int(~s.base, ~s.offset + 52, 4); {10905#false} is VALID [2018-11-14 19:06:27,810 INFO L273 TraceCheckUtils]: 79: Hoare triple {10905#false} assume !(#t~mem54 == 8656);havoc #t~mem54;call #t~mem55 := read~int(~s.base, ~s.offset + 52, 4); {10905#false} is VALID [2018-11-14 19:06:27,810 INFO L273 TraceCheckUtils]: 80: Hoare triple {10905#false} assume !(#t~mem55 == 8657);havoc #t~mem55;call #t~mem56 := read~int(~s.base, ~s.offset + 52, 4); {10905#false} is VALID [2018-11-14 19:06:27,810 INFO L273 TraceCheckUtils]: 81: Hoare triple {10905#false} assume #t~mem56 == 8672;havoc #t~mem56; {10905#false} is VALID [2018-11-14 19:06:27,810 INFO L273 TraceCheckUtils]: 82: Hoare triple {10905#false} assume -2147483648 <= #t~nondet121 && #t~nondet121 <= 2147483647;~ret~0 := #t~nondet121;havoc #t~nondet121; {10905#false} is VALID [2018-11-14 19:06:27,810 INFO L273 TraceCheckUtils]: 83: Hoare triple {10905#false} assume ~blastFlag~0 == 4; {10905#false} is VALID [2018-11-14 19:06:27,810 INFO L273 TraceCheckUtils]: 84: Hoare triple {10905#false} assume !false; {10905#false} is VALID [2018-11-14 19:06:27,814 INFO L134 CoverageAnalysis]: Checked inductivity of 35 backedges. 35 proven. 0 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2018-11-14 19:06:27,815 INFO L312 seRefinementStrategy]: Constructing automaton from 1 perfect and 0 imperfect interpolant sequences. [2018-11-14 19:06:27,815 INFO L327 seRefinementStrategy]: Number of different interpolants: perfect sequences [4] imperfect sequences [] total 4 [2018-11-14 19:06:27,815 INFO L78 Accepts]: Start accepts. Automaton has 4 states. Word has length 85 [2018-11-14 19:06:27,815 INFO L84 Accepts]: Finished accepts. word is accepted. [2018-11-14 19:06:27,815 INFO L86 InductivityCheck]: Starting indutivity check of a Floyd-Hoare automaton with 4 states. [2018-11-14 19:06:27,897 INFO L119 InductivityCheck]: Floyd-Hoare automaton has 85 edges. 85 inductive. 0 not inductive. 0 times theorem prover too weak to decide inductivity. [2018-11-14 19:06:27,898 INFO L459 AbstractCegarLoop]: Interpolant automaton has 4 states [2018-11-14 19:06:27,898 INFO L142 InterpolantAutomaton]: Constructing interpolant automaton starting with 4 interpolants. [2018-11-14 19:06:27,898 INFO L144 InterpolantAutomaton]: CoverageRelationStatistics Valid=5, Invalid=7, Unknown=0, NotChecked=0, Total=12 [2018-11-14 19:06:27,898 INFO L87 Difference]: Start difference. First operand 189 states and 281 transitions. Second operand 4 states. [2018-11-14 19:06:29,623 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2018-11-14 19:06:29,623 INFO L93 Difference]: Finished difference Result 371 states and 558 transitions. [2018-11-14 19:06:29,623 INFO L142 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 4 states. [2018-11-14 19:06:29,623 INFO L78 Accepts]: Start accepts. Automaton has 4 states. Word has length 85 [2018-11-14 19:06:29,624 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2018-11-14 19:06:29,624 INFO L82 GeneralOperation]: Start removeUnreachable. Operand 4 states. [2018-11-14 19:06:29,626 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 4 states to 4 states and 454 transitions. [2018-11-14 19:06:29,626 INFO L82 GeneralOperation]: Start removeUnreachable. Operand 4 states. [2018-11-14 19:06:29,628 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 4 states to 4 states and 454 transitions. [2018-11-14 19:06:29,628 INFO L86 InductivityCheck]: Starting indutivity check of a Floyd-Hoare automaton with 4 states and 454 transitions. [2018-11-14 19:06:30,049 INFO L119 InductivityCheck]: Floyd-Hoare automaton has 454 edges. 454 inductive. 0 not inductive. 0 times theorem prover too weak to decide inductivity. [2018-11-14 19:06:30,055 INFO L225 Difference]: With dead ends: 371 [2018-11-14 19:06:30,055 INFO L226 Difference]: Without dead ends: 208 [2018-11-14 19:06:30,055 INFO L604 BasicCegarLoop]: 0 DeclaredPredicates, 6 GetRequests, 2 SyntacticMatches, 1 SemanticMatches, 3 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 0 ImplicationChecksByTransitivity, 0.3s TimeCoverageRelationStatistics Valid=9, Invalid=11, Unknown=0, NotChecked=0, Total=20 [2018-11-14 19:06:30,056 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 208 states. [2018-11-14 19:06:30,077 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 208 to 189. [2018-11-14 19:06:30,078 INFO L214 AbstractMinimizeNwa]: Start testing correctness of minimizeSevpa [2018-11-14 19:06:30,078 INFO L82 GeneralOperation]: Start isEquivalent. First operand 208 states. Second operand 189 states. [2018-11-14 19:06:30,078 INFO L74 IsIncluded]: Start isIncluded. First operand 208 states. Second operand 189 states. [2018-11-14 19:06:30,078 INFO L87 Difference]: Start difference. First operand 208 states. Second operand 189 states. [2018-11-14 19:06:30,083 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2018-11-14 19:06:30,083 INFO L93 Difference]: Finished difference Result 208 states and 305 transitions. [2018-11-14 19:06:30,083 INFO L276 IsEmpty]: Start isEmpty. Operand 208 states and 305 transitions. [2018-11-14 19:06:30,084 INFO L282 IsEmpty]: Finished isEmpty. No accepting run. [2018-11-14 19:06:30,084 INFO L83 IsIncluded]: Finished isIncluded. Language is included [2018-11-14 19:06:30,084 INFO L74 IsIncluded]: Start isIncluded. First operand 189 states. Second operand 208 states. [2018-11-14 19:06:30,084 INFO L87 Difference]: Start difference. First operand 189 states. Second operand 208 states. [2018-11-14 19:06:30,088 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2018-11-14 19:06:30,088 INFO L93 Difference]: Finished difference Result 208 states and 305 transitions. [2018-11-14 19:06:30,089 INFO L276 IsEmpty]: Start isEmpty. Operand 208 states and 305 transitions. [2018-11-14 19:06:30,089 INFO L282 IsEmpty]: Finished isEmpty. No accepting run. [2018-11-14 19:06:30,089 INFO L83 IsIncluded]: Finished isIncluded. Language is included [2018-11-14 19:06:30,089 INFO L88 GeneralOperation]: Finished isEquivalent. [2018-11-14 19:06:30,089 INFO L221 AbstractMinimizeNwa]: Finished testing correctness of minimizeSevpa [2018-11-14 19:06:30,090 INFO L82 GeneralOperation]: Start removeUnreachable. Operand 189 states. [2018-11-14 19:06:30,092 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 189 states to 189 states and 280 transitions. [2018-11-14 19:06:30,092 INFO L78 Accepts]: Start accepts. Automaton has 189 states and 280 transitions. Word has length 85 [2018-11-14 19:06:30,093 INFO L84 Accepts]: Finished accepts. word is rejected. [2018-11-14 19:06:30,093 INFO L480 AbstractCegarLoop]: Abstraction has 189 states and 280 transitions. [2018-11-14 19:06:30,093 INFO L481 AbstractCegarLoop]: Interpolant automaton has 4 states. [2018-11-14 19:06:30,093 INFO L276 IsEmpty]: Start isEmpty. Operand 189 states and 280 transitions. [2018-11-14 19:06:30,094 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 86 [2018-11-14 19:06:30,094 INFO L367 BasicCegarLoop]: Found error trace [2018-11-14 19:06:30,094 INFO L375 BasicCegarLoop]: trace histogram [3, 3, 3, 3, 3, 3, 3, 3, 3, 3, 2, 2, 2, 2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2018-11-14 19:06:30,094 INFO L423 AbstractCegarLoop]: === Iteration 14 === [ssl3_acceptErr0ASSERT_VIOLATIONERROR_FUNCTION]=== [2018-11-14 19:06:30,094 INFO L141 PredicateUnifier]: Initialized classic predicate unifier [2018-11-14 19:06:30,094 INFO L82 PathProgramCache]: Analyzing trace with hash 1534413972, now seen corresponding path program 1 times [2018-11-14 19:06:30,095 INFO L223 ckRefinementStrategy]: Switched to mode SMTINTERPOL_TREE_INTERPOLANTS [2018-11-14 19:06:30,095 INFO L69 tionRefinementEngine]: Using refinement strategy CamelRefinementStrategy [2018-11-14 19:06:30,095 INFO L119 rtionOrderModulation]: Craig_TreeInterpolation forces the order to NOT_INCREMENTALLY [2018-11-14 19:06:30,096 INFO L103 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2018-11-14 19:06:30,096 INFO L119 rtionOrderModulation]: Craig_TreeInterpolation forces the order to NOT_INCREMENTALLY [2018-11-14 19:06:30,111 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2018-11-14 19:06:30,360 WARN L179 SmtUtils]: Spent 100.00 ms on a formula simplification. DAG size of input: 12 DAG size of output: 9 [2018-11-14 19:06:30,418 INFO L256 TraceCheckUtils]: 0: Hoare triple {11988#true} call ULTIMATE.init(); {11988#true} is VALID [2018-11-14 19:06:30,418 INFO L273 TraceCheckUtils]: 1: Hoare triple {11988#true} #NULL.base, #NULL.offset := 0, 0;#valid := #valid[0 := 0];~init~0 := 1;call ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset := #Ultimate.alloc(100);call write~unchecked~int(0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 0, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 4, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 8, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 12, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 16, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 20, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 24, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 28, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 32, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 36, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 40, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 44, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 48, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 52, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 56, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 60, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 64, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 68, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 72, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 76, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 80, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 84, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 88, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 92, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 96, 4);call write~unchecked~int(0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 0, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 4, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 8, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 12, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 16, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 20, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 24, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 28, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 32, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 36, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 40, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 44, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 48, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 52, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 56, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 60, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 64, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 68, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 72, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 76, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 80, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 84, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 88, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 92, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 96, 4); {11988#true} is VALID [2018-11-14 19:06:30,418 INFO L273 TraceCheckUtils]: 2: Hoare triple {11988#true} assume true; {11988#true} is VALID [2018-11-14 19:06:30,418 INFO L268 TraceCheckUtils]: 3: Hoare quadruple {11988#true} {11988#true} #654#return; {11988#true} is VALID [2018-11-14 19:06:30,419 INFO L256 TraceCheckUtils]: 4: Hoare triple {11988#true} call #t~ret138 := main(); {11988#true} is VALID [2018-11-14 19:06:30,419 INFO L273 TraceCheckUtils]: 5: Hoare triple {11988#true} havoc ~s~0.base, ~s~0.offset;havoc ~tmp~2;call #t~malloc3.base, #t~malloc3.offset := #Ultimate.alloc(248);~s~0.base, ~s~0.offset := #t~malloc3.base, #t~malloc3.offset;call #t~malloc4.base, #t~malloc4.offset := #Ultimate.alloc(899);call write~$Pointer$(#t~malloc4.base, #t~malloc4.offset, ~s~0.base, ~s~0.offset + 84, 4);call #t~malloc5.base, #t~malloc5.offset := #Ultimate.alloc(232);call write~$Pointer$(#t~malloc5.base, #t~malloc5.offset, ~s~0.base, ~s~0.offset + 204, 4);call #t~malloc6.base, #t~malloc6.offset := #Ultimate.alloc(200);call write~$Pointer$(#t~malloc6.base, #t~malloc6.offset, ~s~0.base, ~s~0.offset + 176, 4);call write~int(8464, ~s~0.base, ~s~0.offset + 52, 4); {11988#true} is VALID [2018-11-14 19:06:30,419 INFO L256 TraceCheckUtils]: 6: Hoare triple {11988#true} call #t~ret7 := ssl3_accept(~s~0.base, ~s~0.offset); {11988#true} is VALID [2018-11-14 19:06:30,419 INFO L273 TraceCheckUtils]: 7: Hoare triple {11988#true} ~s.base, ~s.offset := #in~s.base, #in~s.offset;havoc ~buf~0.base, ~buf~0.offset;havoc ~l~0;havoc ~Time~0;havoc ~tmp~3;havoc ~cb~0.base, ~cb~0.offset;havoc ~num1~0;havoc ~ret~0;havoc ~new_state~0;havoc ~state~0;havoc ~skip~0;havoc ~got_new_session~0;assume -2147483648 <= #t~nondet8 && #t~nondet8 <= 2147483647;~tmp___1~0 := #t~nondet8;havoc #t~nondet8;assume -2147483648 <= #t~nondet9 && #t~nondet9 <= 2147483647;~tmp___2~0 := #t~nondet9;havoc #t~nondet9;assume -2147483648 <= #t~nondet10 && #t~nondet10 <= 2147483647;~tmp___3~0 := #t~nondet10;havoc #t~nondet10;assume -2147483648 <= #t~nondet11 && #t~nondet11 <= 2147483647;~tmp___4~0 := #t~nondet11;havoc #t~nondet11;assume -2147483648 <= #t~nondet12 && #t~nondet12 <= 2147483647;~tmp___5~0 := #t~nondet12;havoc #t~nondet12;assume -2147483648 <= #t~nondet13 && #t~nondet13 <= 2147483647;~tmp___6~0 := #t~nondet13;havoc #t~nondet13;havoc ~tmp___7~0;assume -2147483648 <= #t~nondet14 && #t~nondet14 <= 2147483647;~tmp___8~0 := #t~nondet14;havoc #t~nondet14;assume -2147483648 <= #t~nondet15 && #t~nondet15 <= 2147483647;~tmp___9~0 := #t~nondet15;havoc #t~nondet15;assume -2147483648 <= #t~nondet16 && #t~nondet16 <= 2147483647;~tmp___10~0 := #t~nondet16;havoc #t~nondet16;havoc ~blastFlag~0;~blastFlag~0 := 0;assume -2147483648 <= #t~nondet17 && #t~nondet17 <= 2147483647;call write~int(#t~nondet17, ~s.base, ~s.offset + 92, 4);havoc #t~nondet17;call write~int(8464, ~s.base, ~s.offset + 52, 4);assume -2147483648 <= #t~nondet18 && #t~nondet18 <= 2147483647;~tmp~3 := #t~nondet18;havoc #t~nondet18;~Time~0 := ~tmp~3;~cb~0.base, ~cb~0.offset := 0, 0;~ret~0 := -1;~skip~0 := 0;~got_new_session~0 := 0;call #t~mem19.base, #t~mem19.offset := read~$Pointer$(~s.base, ~s.offset + 192, 4); {11988#true} is VALID [2018-11-14 19:06:30,419 INFO L273 TraceCheckUtils]: 8: Hoare triple {11988#true} assume (#t~mem19.base + #t~mem19.offset) % 4294967296 != 0;havoc #t~mem19.base, #t~mem19.offset;call #t~mem20.base, #t~mem20.offset := read~$Pointer$(~s.base, ~s.offset + 192, 4);~cb~0.base, ~cb~0.offset := #t~mem20.base, #t~mem20.offset;havoc #t~mem20.base, #t~mem20.offset; {11988#true} is VALID [2018-11-14 19:06:30,419 INFO L273 TraceCheckUtils]: 9: Hoare triple {11988#true} call #t~mem21 := read~int(~s.base, ~s.offset + 28, 4);call write~int(#t~mem21 + 1, ~s.base, ~s.offset + 28, 4);havoc #t~mem21; {11988#true} is VALID [2018-11-14 19:06:30,420 INFO L273 TraceCheckUtils]: 10: Hoare triple {11988#true} assume !(~bitwiseAnd(~tmp___1~0, 12288) != 0); {11988#true} is VALID [2018-11-14 19:06:30,420 INFO L273 TraceCheckUtils]: 11: Hoare triple {11988#true} call #t~mem22.base, #t~mem22.offset := read~$Pointer$(~s.base, ~s.offset + 136, 4); {11988#true} is VALID [2018-11-14 19:06:30,420 INFO L273 TraceCheckUtils]: 12: Hoare triple {11988#true} assume !((#t~mem22.base + #t~mem22.offset) % 4294967296 == 0);havoc #t~mem22.base, #t~mem22.offset; {11988#true} is VALID [2018-11-14 19:06:30,420 INFO L273 TraceCheckUtils]: 13: Hoare triple {11988#true} assume true; {11988#true} is VALID [2018-11-14 19:06:30,420 INFO L273 TraceCheckUtils]: 14: Hoare triple {11988#true} assume !false; {11988#true} is VALID [2018-11-14 19:06:30,420 INFO L273 TraceCheckUtils]: 15: Hoare triple {11988#true} call #t~mem23 := read~int(~s.base, ~s.offset + 52, 4);~state~0 := #t~mem23;havoc #t~mem23;call #t~mem24 := read~int(~s.base, ~s.offset + 52, 4); {11988#true} is VALID [2018-11-14 19:06:30,420 INFO L273 TraceCheckUtils]: 16: Hoare triple {11988#true} assume !(#t~mem24 == 12292);havoc #t~mem24;call #t~mem25 := read~int(~s.base, ~s.offset + 52, 4); {11988#true} is VALID [2018-11-14 19:06:30,420 INFO L273 TraceCheckUtils]: 17: Hoare triple {11988#true} assume !(#t~mem25 == 16384);havoc #t~mem25;call #t~mem26 := read~int(~s.base, ~s.offset + 52, 4); {11988#true} is VALID [2018-11-14 19:06:30,420 INFO L273 TraceCheckUtils]: 18: Hoare triple {11988#true} assume !(#t~mem26 == 8192);havoc #t~mem26;call #t~mem27 := read~int(~s.base, ~s.offset + 52, 4); {11988#true} is VALID [2018-11-14 19:06:30,421 INFO L273 TraceCheckUtils]: 19: Hoare triple {11988#true} assume !(#t~mem27 == 24576);havoc #t~mem27;call #t~mem28 := read~int(~s.base, ~s.offset + 52, 4); {11988#true} is VALID [2018-11-14 19:06:30,421 INFO L273 TraceCheckUtils]: 20: Hoare triple {11988#true} assume !(#t~mem28 == 8195);havoc #t~mem28;call #t~mem29 := read~int(~s.base, ~s.offset + 52, 4); {11988#true} is VALID [2018-11-14 19:06:30,421 INFO L273 TraceCheckUtils]: 21: Hoare triple {11988#true} assume !(#t~mem29 == 8480);havoc #t~mem29;call #t~mem30 := read~int(~s.base, ~s.offset + 52, 4); {11988#true} is VALID [2018-11-14 19:06:30,421 INFO L273 TraceCheckUtils]: 22: Hoare triple {11988#true} assume !(#t~mem30 == 8481);havoc #t~mem30;call #t~mem31 := read~int(~s.base, ~s.offset + 52, 4); {11988#true} is VALID [2018-11-14 19:06:30,421 INFO L273 TraceCheckUtils]: 23: Hoare triple {11988#true} assume !(#t~mem31 == 8482);havoc #t~mem31;call #t~mem32 := read~int(~s.base, ~s.offset + 52, 4); {11988#true} is VALID [2018-11-14 19:06:30,421 INFO L273 TraceCheckUtils]: 24: Hoare triple {11988#true} assume #t~mem32 == 8464;havoc #t~mem32; {11988#true} is VALID [2018-11-14 19:06:30,421 INFO L273 TraceCheckUtils]: 25: Hoare triple {11988#true} call write~int(0, ~s.base, ~s.offset + 48, 4);assume -2147483648 <= #t~nondet69 && #t~nondet69 <= 2147483647;~ret~0 := #t~nondet69;havoc #t~nondet69; {11988#true} is VALID [2018-11-14 19:06:30,421 INFO L273 TraceCheckUtils]: 26: Hoare triple {11988#true} assume ~blastFlag~0 == 0;~blastFlag~0 := 1; {11988#true} is VALID [2018-11-14 19:06:30,422 INFO L273 TraceCheckUtils]: 27: Hoare triple {11988#true} assume !(~ret~0 <= 0);~got_new_session~0 := 1;call write~int(8496, ~s.base, ~s.offset + 52, 4);call write~int(0, ~s.base, ~s.offset + 64, 4); {11990#(= (select (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 52)) 8496)} is VALID [2018-11-14 19:06:30,422 INFO L273 TraceCheckUtils]: 28: Hoare triple {11990#(= (select (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 52)) 8496)} call #t~mem127.base, #t~mem127.offset := read~$Pointer$(~s.base, ~s.offset + 84, 4);call #t~mem128 := read~int(#t~mem127.base, #t~mem127.offset + 604 + 244, 4); {11990#(= (select (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 52)) 8496)} is VALID [2018-11-14 19:06:30,423 INFO L273 TraceCheckUtils]: 29: Hoare triple {11990#(= (select (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 52)) 8496)} assume !(#t~mem128 == 0);havoc #t~mem127.base, #t~mem127.offset;havoc #t~mem128; {11990#(= (select (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 52)) 8496)} is VALID [2018-11-14 19:06:30,423 INFO L273 TraceCheckUtils]: 30: Hoare triple {11990#(= (select (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 52)) 8496)} ~skip~0 := 0; {11990#(= (select (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 52)) 8496)} is VALID [2018-11-14 19:06:30,423 INFO L273 TraceCheckUtils]: 31: Hoare triple {11990#(= (select (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 52)) 8496)} assume true; {11990#(= (select (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 52)) 8496)} is VALID [2018-11-14 19:06:30,424 INFO L273 TraceCheckUtils]: 32: Hoare triple {11990#(= (select (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 52)) 8496)} assume !false; {11990#(= (select (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 52)) 8496)} is VALID [2018-11-14 19:06:30,424 INFO L273 TraceCheckUtils]: 33: Hoare triple {11990#(= (select (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 52)) 8496)} call #t~mem23 := read~int(~s.base, ~s.offset + 52, 4);~state~0 := #t~mem23;havoc #t~mem23;call #t~mem24 := read~int(~s.base, ~s.offset + 52, 4); {11990#(= (select (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 52)) 8496)} is VALID [2018-11-14 19:06:30,424 INFO L273 TraceCheckUtils]: 34: Hoare triple {11990#(= (select (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 52)) 8496)} assume !(#t~mem24 == 12292);havoc #t~mem24;call #t~mem25 := read~int(~s.base, ~s.offset + 52, 4); {11990#(= (select (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 52)) 8496)} is VALID [2018-11-14 19:06:30,425 INFO L273 TraceCheckUtils]: 35: Hoare triple {11990#(= (select (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 52)) 8496)} assume !(#t~mem25 == 16384);havoc #t~mem25;call #t~mem26 := read~int(~s.base, ~s.offset + 52, 4); {11990#(= (select (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 52)) 8496)} is VALID [2018-11-14 19:06:30,425 INFO L273 TraceCheckUtils]: 36: Hoare triple {11990#(= (select (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 52)) 8496)} assume !(#t~mem26 == 8192);havoc #t~mem26;call #t~mem27 := read~int(~s.base, ~s.offset + 52, 4); {11990#(= (select (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 52)) 8496)} is VALID [2018-11-14 19:06:30,425 INFO L273 TraceCheckUtils]: 37: Hoare triple {11990#(= (select (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 52)) 8496)} assume !(#t~mem27 == 24576);havoc #t~mem27;call #t~mem28 := read~int(~s.base, ~s.offset + 52, 4); {11990#(= (select (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 52)) 8496)} is VALID [2018-11-14 19:06:30,426 INFO L273 TraceCheckUtils]: 38: Hoare triple {11990#(= (select (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 52)) 8496)} assume !(#t~mem28 == 8195);havoc #t~mem28;call #t~mem29 := read~int(~s.base, ~s.offset + 52, 4); {11990#(= (select (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 52)) 8496)} is VALID [2018-11-14 19:06:30,426 INFO L273 TraceCheckUtils]: 39: Hoare triple {11990#(= (select (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 52)) 8496)} assume !(#t~mem29 == 8480);havoc #t~mem29;call #t~mem30 := read~int(~s.base, ~s.offset + 52, 4); {11990#(= (select (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 52)) 8496)} is VALID [2018-11-14 19:06:30,427 INFO L273 TraceCheckUtils]: 40: Hoare triple {11990#(= (select (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 52)) 8496)} assume !(#t~mem30 == 8481);havoc #t~mem30;call #t~mem31 := read~int(~s.base, ~s.offset + 52, 4); {11991#(= |ssl3_accept_#t~mem31| 8496)} is VALID [2018-11-14 19:06:30,427 INFO L273 TraceCheckUtils]: 41: Hoare triple {11991#(= |ssl3_accept_#t~mem31| 8496)} assume #t~mem31 == 8482;havoc #t~mem31; {11989#false} is VALID [2018-11-14 19:06:30,428 INFO L273 TraceCheckUtils]: 42: Hoare triple {11989#false} call write~int(3, ~s.base, ~s.offset + 52, 4); {11989#false} is VALID [2018-11-14 19:06:30,428 INFO L273 TraceCheckUtils]: 43: Hoare triple {11989#false} call #t~mem127.base, #t~mem127.offset := read~$Pointer$(~s.base, ~s.offset + 84, 4);call #t~mem128 := read~int(#t~mem127.base, #t~mem127.offset + 604 + 244, 4); {11989#false} is VALID [2018-11-14 19:06:30,428 INFO L273 TraceCheckUtils]: 44: Hoare triple {11989#false} assume !(#t~mem128 == 0);havoc #t~mem127.base, #t~mem127.offset;havoc #t~mem128; {11989#false} is VALID [2018-11-14 19:06:30,428 INFO L273 TraceCheckUtils]: 45: Hoare triple {11989#false} ~skip~0 := 0; {11989#false} is VALID [2018-11-14 19:06:30,428 INFO L273 TraceCheckUtils]: 46: Hoare triple {11989#false} assume true; {11989#false} is VALID [2018-11-14 19:06:30,428 INFO L273 TraceCheckUtils]: 47: Hoare triple {11989#false} assume !false; {11989#false} is VALID [2018-11-14 19:06:30,429 INFO L273 TraceCheckUtils]: 48: Hoare triple {11989#false} call #t~mem23 := read~int(~s.base, ~s.offset + 52, 4);~state~0 := #t~mem23;havoc #t~mem23;call #t~mem24 := read~int(~s.base, ~s.offset + 52, 4); {11989#false} is VALID [2018-11-14 19:06:30,429 INFO L273 TraceCheckUtils]: 49: Hoare triple {11989#false} assume !(#t~mem24 == 12292);havoc #t~mem24;call #t~mem25 := read~int(~s.base, ~s.offset + 52, 4); {11989#false} is VALID [2018-11-14 19:06:30,429 INFO L273 TraceCheckUtils]: 50: Hoare triple {11989#false} assume !(#t~mem25 == 16384);havoc #t~mem25;call #t~mem26 := read~int(~s.base, ~s.offset + 52, 4); {11989#false} is VALID [2018-11-14 19:06:30,429 INFO L273 TraceCheckUtils]: 51: Hoare triple {11989#false} assume !(#t~mem26 == 8192);havoc #t~mem26;call #t~mem27 := read~int(~s.base, ~s.offset + 52, 4); {11989#false} is VALID [2018-11-14 19:06:30,429 INFO L273 TraceCheckUtils]: 52: Hoare triple {11989#false} assume !(#t~mem27 == 24576);havoc #t~mem27;call #t~mem28 := read~int(~s.base, ~s.offset + 52, 4); {11989#false} is VALID [2018-11-14 19:06:30,430 INFO L273 TraceCheckUtils]: 53: Hoare triple {11989#false} assume !(#t~mem28 == 8195);havoc #t~mem28;call #t~mem29 := read~int(~s.base, ~s.offset + 52, 4); {11989#false} is VALID [2018-11-14 19:06:30,430 INFO L273 TraceCheckUtils]: 54: Hoare triple {11989#false} assume !(#t~mem29 == 8480);havoc #t~mem29;call #t~mem30 := read~int(~s.base, ~s.offset + 52, 4); {11989#false} is VALID [2018-11-14 19:06:30,430 INFO L273 TraceCheckUtils]: 55: Hoare triple {11989#false} assume !(#t~mem30 == 8481);havoc #t~mem30;call #t~mem31 := read~int(~s.base, ~s.offset + 52, 4); {11989#false} is VALID [2018-11-14 19:06:30,430 INFO L273 TraceCheckUtils]: 56: Hoare triple {11989#false} assume !(#t~mem31 == 8482);havoc #t~mem31;call #t~mem32 := read~int(~s.base, ~s.offset + 52, 4); {11989#false} is VALID [2018-11-14 19:06:30,430 INFO L273 TraceCheckUtils]: 57: Hoare triple {11989#false} assume !(#t~mem32 == 8464);havoc #t~mem32;call #t~mem33 := read~int(~s.base, ~s.offset + 52, 4); {11989#false} is VALID [2018-11-14 19:06:30,430 INFO L273 TraceCheckUtils]: 58: Hoare triple {11989#false} assume !(#t~mem33 == 8465);havoc #t~mem33;call #t~mem34 := read~int(~s.base, ~s.offset + 52, 4); {11989#false} is VALID [2018-11-14 19:06:30,431 INFO L273 TraceCheckUtils]: 59: Hoare triple {11989#false} assume !(#t~mem34 == 8466);havoc #t~mem34;call #t~mem35 := read~int(~s.base, ~s.offset + 52, 4); {11989#false} is VALID [2018-11-14 19:06:30,431 INFO L273 TraceCheckUtils]: 60: Hoare triple {11989#false} assume !(#t~mem35 == 8496);havoc #t~mem35;call #t~mem36 := read~int(~s.base, ~s.offset + 52, 4); {11989#false} is VALID [2018-11-14 19:06:30,431 INFO L273 TraceCheckUtils]: 61: Hoare triple {11989#false} assume !(#t~mem36 == 8497);havoc #t~mem36;call #t~mem37 := read~int(~s.base, ~s.offset + 52, 4); {11989#false} is VALID [2018-11-14 19:06:30,431 INFO L273 TraceCheckUtils]: 62: Hoare triple {11989#false} assume !(#t~mem37 == 8512);havoc #t~mem37;call #t~mem38 := read~int(~s.base, ~s.offset + 52, 4); {11989#false} is VALID [2018-11-14 19:06:30,431 INFO L273 TraceCheckUtils]: 63: Hoare triple {11989#false} assume !(#t~mem38 == 8513);havoc #t~mem38;call #t~mem39 := read~int(~s.base, ~s.offset + 52, 4); {11989#false} is VALID [2018-11-14 19:06:30,431 INFO L273 TraceCheckUtils]: 64: Hoare triple {11989#false} assume !(#t~mem39 == 8528);havoc #t~mem39;call #t~mem40 := read~int(~s.base, ~s.offset + 52, 4); {11989#false} is VALID [2018-11-14 19:06:30,431 INFO L273 TraceCheckUtils]: 65: Hoare triple {11989#false} assume !(#t~mem40 == 8529);havoc #t~mem40;call #t~mem41 := read~int(~s.base, ~s.offset + 52, 4); {11989#false} is VALID [2018-11-14 19:06:30,431 INFO L273 TraceCheckUtils]: 66: Hoare triple {11989#false} assume !(#t~mem41 == 8544);havoc #t~mem41;call #t~mem42 := read~int(~s.base, ~s.offset + 52, 4); {11989#false} is VALID [2018-11-14 19:06:30,431 INFO L273 TraceCheckUtils]: 67: Hoare triple {11989#false} assume !(#t~mem42 == 8545);havoc #t~mem42;call #t~mem43 := read~int(~s.base, ~s.offset + 52, 4); {11989#false} is VALID [2018-11-14 19:06:30,432 INFO L273 TraceCheckUtils]: 68: Hoare triple {11989#false} assume !(#t~mem43 == 8560);havoc #t~mem43;call #t~mem44 := read~int(~s.base, ~s.offset + 52, 4); {11989#false} is VALID [2018-11-14 19:06:30,432 INFO L273 TraceCheckUtils]: 69: Hoare triple {11989#false} assume !(#t~mem44 == 8561);havoc #t~mem44;call #t~mem45 := read~int(~s.base, ~s.offset + 52, 4); {11989#false} is VALID [2018-11-14 19:06:30,432 INFO L273 TraceCheckUtils]: 70: Hoare triple {11989#false} assume !(#t~mem45 == 8448);havoc #t~mem45;call #t~mem46 := read~int(~s.base, ~s.offset + 52, 4); {11989#false} is VALID [2018-11-14 19:06:30,432 INFO L273 TraceCheckUtils]: 71: Hoare triple {11989#false} assume !(#t~mem46 == 8576);havoc #t~mem46;call #t~mem47 := read~int(~s.base, ~s.offset + 52, 4); {11989#false} is VALID [2018-11-14 19:06:30,432 INFO L273 TraceCheckUtils]: 72: Hoare triple {11989#false} assume !(#t~mem47 == 8577);havoc #t~mem47;call #t~mem48 := read~int(~s.base, ~s.offset + 52, 4); {11989#false} is VALID [2018-11-14 19:06:30,432 INFO L273 TraceCheckUtils]: 73: Hoare triple {11989#false} assume !(#t~mem48 == 8592);havoc #t~mem48;call #t~mem49 := read~int(~s.base, ~s.offset + 52, 4); {11989#false} is VALID [2018-11-14 19:06:30,432 INFO L273 TraceCheckUtils]: 74: Hoare triple {11989#false} assume !(#t~mem49 == 8593);havoc #t~mem49;call #t~mem50 := read~int(~s.base, ~s.offset + 52, 4); {11989#false} is VALID [2018-11-14 19:06:30,432 INFO L273 TraceCheckUtils]: 75: Hoare triple {11989#false} assume !(#t~mem50 == 8608);havoc #t~mem50;call #t~mem51 := read~int(~s.base, ~s.offset + 52, 4); {11989#false} is VALID [2018-11-14 19:06:30,432 INFO L273 TraceCheckUtils]: 76: Hoare triple {11989#false} assume !(#t~mem51 == 8609);havoc #t~mem51;call #t~mem52 := read~int(~s.base, ~s.offset + 52, 4); {11989#false} is VALID [2018-11-14 19:06:30,433 INFO L273 TraceCheckUtils]: 77: Hoare triple {11989#false} assume !(#t~mem52 == 8640);havoc #t~mem52;call #t~mem53 := read~int(~s.base, ~s.offset + 52, 4); {11989#false} is VALID [2018-11-14 19:06:30,433 INFO L273 TraceCheckUtils]: 78: Hoare triple {11989#false} assume !(#t~mem53 == 8641);havoc #t~mem53;call #t~mem54 := read~int(~s.base, ~s.offset + 52, 4); {11989#false} is VALID [2018-11-14 19:06:30,433 INFO L273 TraceCheckUtils]: 79: Hoare triple {11989#false} assume !(#t~mem54 == 8656);havoc #t~mem54;call #t~mem55 := read~int(~s.base, ~s.offset + 52, 4); {11989#false} is VALID [2018-11-14 19:06:30,433 INFO L273 TraceCheckUtils]: 80: Hoare triple {11989#false} assume !(#t~mem55 == 8657);havoc #t~mem55;call #t~mem56 := read~int(~s.base, ~s.offset + 52, 4); {11989#false} is VALID [2018-11-14 19:06:30,433 INFO L273 TraceCheckUtils]: 81: Hoare triple {11989#false} assume #t~mem56 == 8672;havoc #t~mem56; {11989#false} is VALID [2018-11-14 19:06:30,433 INFO L273 TraceCheckUtils]: 82: Hoare triple {11989#false} assume -2147483648 <= #t~nondet121 && #t~nondet121 <= 2147483647;~ret~0 := #t~nondet121;havoc #t~nondet121; {11989#false} is VALID [2018-11-14 19:06:30,433 INFO L273 TraceCheckUtils]: 83: Hoare triple {11989#false} assume ~blastFlag~0 == 4; {11989#false} is VALID [2018-11-14 19:06:30,433 INFO L273 TraceCheckUtils]: 84: Hoare triple {11989#false} assume !false; {11989#false} is VALID [2018-11-14 19:06:30,438 INFO L134 CoverageAnalysis]: Checked inductivity of 37 backedges. 37 proven. 0 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2018-11-14 19:06:30,438 INFO L312 seRefinementStrategy]: Constructing automaton from 1 perfect and 0 imperfect interpolant sequences. [2018-11-14 19:06:30,438 INFO L327 seRefinementStrategy]: Number of different interpolants: perfect sequences [4] imperfect sequences [] total 4 [2018-11-14 19:06:30,439 INFO L78 Accepts]: Start accepts. Automaton has 4 states. Word has length 85 [2018-11-14 19:06:30,439 INFO L84 Accepts]: Finished accepts. word is accepted. [2018-11-14 19:06:30,439 INFO L86 InductivityCheck]: Starting indutivity check of a Floyd-Hoare automaton with 4 states. [2018-11-14 19:06:30,514 INFO L119 InductivityCheck]: Floyd-Hoare automaton has 85 edges. 85 inductive. 0 not inductive. 0 times theorem prover too weak to decide inductivity. [2018-11-14 19:06:30,514 INFO L459 AbstractCegarLoop]: Interpolant automaton has 4 states [2018-11-14 19:06:30,515 INFO L142 InterpolantAutomaton]: Constructing interpolant automaton starting with 4 interpolants. [2018-11-14 19:06:30,515 INFO L144 InterpolantAutomaton]: CoverageRelationStatistics Valid=5, Invalid=7, Unknown=0, NotChecked=0, Total=12 [2018-11-14 19:06:30,515 INFO L87 Difference]: Start difference. First operand 189 states and 280 transitions. Second operand 4 states. [2018-11-14 19:06:31,778 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2018-11-14 19:06:31,778 INFO L93 Difference]: Finished difference Result 370 states and 555 transitions. [2018-11-14 19:06:31,778 INFO L142 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 4 states. [2018-11-14 19:06:31,778 INFO L78 Accepts]: Start accepts. Automaton has 4 states. Word has length 85 [2018-11-14 19:06:31,778 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2018-11-14 19:06:31,778 INFO L82 GeneralOperation]: Start removeUnreachable. Operand 4 states. [2018-11-14 19:06:31,780 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 4 states to 4 states and 452 transitions. [2018-11-14 19:06:31,780 INFO L82 GeneralOperation]: Start removeUnreachable. Operand 4 states. [2018-11-14 19:06:31,782 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 4 states to 4 states and 452 transitions. [2018-11-14 19:06:31,782 INFO L86 InductivityCheck]: Starting indutivity check of a Floyd-Hoare automaton with 4 states and 452 transitions. [2018-11-14 19:06:32,312 INFO L119 InductivityCheck]: Floyd-Hoare automaton has 452 edges. 452 inductive. 0 not inductive. 0 times theorem prover too weak to decide inductivity. [2018-11-14 19:06:32,316 INFO L225 Difference]: With dead ends: 370 [2018-11-14 19:06:32,316 INFO L226 Difference]: Without dead ends: 207 [2018-11-14 19:06:32,317 INFO L604 BasicCegarLoop]: 0 DeclaredPredicates, 6 GetRequests, 2 SyntacticMatches, 1 SemanticMatches, 3 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 0 ImplicationChecksByTransitivity, 0.1s TimeCoverageRelationStatistics Valid=9, Invalid=11, Unknown=0, NotChecked=0, Total=20 [2018-11-14 19:06:32,317 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 207 states. [2018-11-14 19:06:32,381 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 207 to 189. [2018-11-14 19:06:32,381 INFO L214 AbstractMinimizeNwa]: Start testing correctness of minimizeSevpa [2018-11-14 19:06:32,381 INFO L82 GeneralOperation]: Start isEquivalent. First operand 207 states. Second operand 189 states. [2018-11-14 19:06:32,381 INFO L74 IsIncluded]: Start isIncluded. First operand 207 states. Second operand 189 states. [2018-11-14 19:06:32,381 INFO L87 Difference]: Start difference. First operand 207 states. Second operand 189 states. [2018-11-14 19:06:32,387 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2018-11-14 19:06:32,387 INFO L93 Difference]: Finished difference Result 207 states and 303 transitions. [2018-11-14 19:06:32,387 INFO L276 IsEmpty]: Start isEmpty. Operand 207 states and 303 transitions. [2018-11-14 19:06:32,388 INFO L282 IsEmpty]: Finished isEmpty. No accepting run. [2018-11-14 19:06:32,388 INFO L83 IsIncluded]: Finished isIncluded. Language is included [2018-11-14 19:06:32,388 INFO L74 IsIncluded]: Start isIncluded. First operand 189 states. Second operand 207 states. [2018-11-14 19:06:32,388 INFO L87 Difference]: Start difference. First operand 189 states. Second operand 207 states. [2018-11-14 19:06:32,392 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2018-11-14 19:06:32,393 INFO L93 Difference]: Finished difference Result 207 states and 303 transitions. [2018-11-14 19:06:32,393 INFO L276 IsEmpty]: Start isEmpty. Operand 207 states and 303 transitions. [2018-11-14 19:06:32,393 INFO L282 IsEmpty]: Finished isEmpty. No accepting run. [2018-11-14 19:06:32,394 INFO L83 IsIncluded]: Finished isIncluded. Language is included [2018-11-14 19:06:32,394 INFO L88 GeneralOperation]: Finished isEquivalent. [2018-11-14 19:06:32,394 INFO L221 AbstractMinimizeNwa]: Finished testing correctness of minimizeSevpa [2018-11-14 19:06:32,394 INFO L82 GeneralOperation]: Start removeUnreachable. Operand 189 states. [2018-11-14 19:06:32,397 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 189 states to 189 states and 279 transitions. [2018-11-14 19:06:32,398 INFO L78 Accepts]: Start accepts. Automaton has 189 states and 279 transitions. Word has length 85 [2018-11-14 19:06:32,398 INFO L84 Accepts]: Finished accepts. word is rejected. [2018-11-14 19:06:32,398 INFO L480 AbstractCegarLoop]: Abstraction has 189 states and 279 transitions. [2018-11-14 19:06:32,398 INFO L481 AbstractCegarLoop]: Interpolant automaton has 4 states. [2018-11-14 19:06:32,398 INFO L276 IsEmpty]: Start isEmpty. Operand 189 states and 279 transitions. [2018-11-14 19:06:32,399 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 87 [2018-11-14 19:06:32,399 INFO L367 BasicCegarLoop]: Found error trace [2018-11-14 19:06:32,399 INFO L375 BasicCegarLoop]: trace histogram [3, 3, 3, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2018-11-14 19:06:32,400 INFO L423 AbstractCegarLoop]: === Iteration 15 === [ssl3_acceptErr0ASSERT_VIOLATIONERROR_FUNCTION]=== [2018-11-14 19:06:32,400 INFO L141 PredicateUnifier]: Initialized classic predicate unifier [2018-11-14 19:06:32,400 INFO L82 PathProgramCache]: Analyzing trace with hash 2077787515, now seen corresponding path program 1 times [2018-11-14 19:06:32,400 INFO L223 ckRefinementStrategy]: Switched to mode SMTINTERPOL_TREE_INTERPOLANTS [2018-11-14 19:06:32,400 INFO L69 tionRefinementEngine]: Using refinement strategy CamelRefinementStrategy [2018-11-14 19:06:32,401 INFO L119 rtionOrderModulation]: Craig_TreeInterpolation forces the order to NOT_INCREMENTALLY [2018-11-14 19:06:32,401 INFO L103 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2018-11-14 19:06:32,401 INFO L119 rtionOrderModulation]: Craig_TreeInterpolation forces the order to NOT_INCREMENTALLY [2018-11-14 19:06:32,417 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2018-11-14 19:06:32,590 INFO L256 TraceCheckUtils]: 0: Hoare triple {13068#true} call ULTIMATE.init(); {13068#true} is VALID [2018-11-14 19:06:32,590 INFO L273 TraceCheckUtils]: 1: Hoare triple {13068#true} #NULL.base, #NULL.offset := 0, 0;#valid := #valid[0 := 0];~init~0 := 1;call ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset := #Ultimate.alloc(100);call write~unchecked~int(0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 0, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 4, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 8, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 12, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 16, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 20, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 24, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 28, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 32, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 36, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 40, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 44, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 48, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 52, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 56, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 60, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 64, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 68, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 72, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 76, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 80, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 84, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 88, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 92, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 96, 4);call write~unchecked~int(0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 0, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 4, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 8, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 12, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 16, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 20, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 24, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 28, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 32, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 36, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 40, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 44, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 48, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 52, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 56, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 60, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 64, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 68, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 72, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 76, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 80, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 84, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 88, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 92, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 96, 4); {13068#true} is VALID [2018-11-14 19:06:32,591 INFO L273 TraceCheckUtils]: 2: Hoare triple {13068#true} assume true; {13068#true} is VALID [2018-11-14 19:06:32,591 INFO L268 TraceCheckUtils]: 3: Hoare quadruple {13068#true} {13068#true} #654#return; {13068#true} is VALID [2018-11-14 19:06:32,591 INFO L256 TraceCheckUtils]: 4: Hoare triple {13068#true} call #t~ret138 := main(); {13068#true} is VALID [2018-11-14 19:06:32,591 INFO L273 TraceCheckUtils]: 5: Hoare triple {13068#true} havoc ~s~0.base, ~s~0.offset;havoc ~tmp~2;call #t~malloc3.base, #t~malloc3.offset := #Ultimate.alloc(248);~s~0.base, ~s~0.offset := #t~malloc3.base, #t~malloc3.offset;call #t~malloc4.base, #t~malloc4.offset := #Ultimate.alloc(899);call write~$Pointer$(#t~malloc4.base, #t~malloc4.offset, ~s~0.base, ~s~0.offset + 84, 4);call #t~malloc5.base, #t~malloc5.offset := #Ultimate.alloc(232);call write~$Pointer$(#t~malloc5.base, #t~malloc5.offset, ~s~0.base, ~s~0.offset + 204, 4);call #t~malloc6.base, #t~malloc6.offset := #Ultimate.alloc(200);call write~$Pointer$(#t~malloc6.base, #t~malloc6.offset, ~s~0.base, ~s~0.offset + 176, 4);call write~int(8464, ~s~0.base, ~s~0.offset + 52, 4); {13068#true} is VALID [2018-11-14 19:06:32,592 INFO L256 TraceCheckUtils]: 6: Hoare triple {13068#true} call #t~ret7 := ssl3_accept(~s~0.base, ~s~0.offset); {13068#true} is VALID [2018-11-14 19:06:32,592 INFO L273 TraceCheckUtils]: 7: Hoare triple {13068#true} ~s.base, ~s.offset := #in~s.base, #in~s.offset;havoc ~buf~0.base, ~buf~0.offset;havoc ~l~0;havoc ~Time~0;havoc ~tmp~3;havoc ~cb~0.base, ~cb~0.offset;havoc ~num1~0;havoc ~ret~0;havoc ~new_state~0;havoc ~state~0;havoc ~skip~0;havoc ~got_new_session~0;assume -2147483648 <= #t~nondet8 && #t~nondet8 <= 2147483647;~tmp___1~0 := #t~nondet8;havoc #t~nondet8;assume -2147483648 <= #t~nondet9 && #t~nondet9 <= 2147483647;~tmp___2~0 := #t~nondet9;havoc #t~nondet9;assume -2147483648 <= #t~nondet10 && #t~nondet10 <= 2147483647;~tmp___3~0 := #t~nondet10;havoc #t~nondet10;assume -2147483648 <= #t~nondet11 && #t~nondet11 <= 2147483647;~tmp___4~0 := #t~nondet11;havoc #t~nondet11;assume -2147483648 <= #t~nondet12 && #t~nondet12 <= 2147483647;~tmp___5~0 := #t~nondet12;havoc #t~nondet12;assume -2147483648 <= #t~nondet13 && #t~nondet13 <= 2147483647;~tmp___6~0 := #t~nondet13;havoc #t~nondet13;havoc ~tmp___7~0;assume -2147483648 <= #t~nondet14 && #t~nondet14 <= 2147483647;~tmp___8~0 := #t~nondet14;havoc #t~nondet14;assume -2147483648 <= #t~nondet15 && #t~nondet15 <= 2147483647;~tmp___9~0 := #t~nondet15;havoc #t~nondet15;assume -2147483648 <= #t~nondet16 && #t~nondet16 <= 2147483647;~tmp___10~0 := #t~nondet16;havoc #t~nondet16;havoc ~blastFlag~0;~blastFlag~0 := 0;assume -2147483648 <= #t~nondet17 && #t~nondet17 <= 2147483647;call write~int(#t~nondet17, ~s.base, ~s.offset + 92, 4);havoc #t~nondet17;call write~int(8464, ~s.base, ~s.offset + 52, 4);assume -2147483648 <= #t~nondet18 && #t~nondet18 <= 2147483647;~tmp~3 := #t~nondet18;havoc #t~nondet18;~Time~0 := ~tmp~3;~cb~0.base, ~cb~0.offset := 0, 0;~ret~0 := -1;~skip~0 := 0;~got_new_session~0 := 0;call #t~mem19.base, #t~mem19.offset := read~$Pointer$(~s.base, ~s.offset + 192, 4); {13068#true} is VALID [2018-11-14 19:06:32,592 INFO L273 TraceCheckUtils]: 8: Hoare triple {13068#true} assume (#t~mem19.base + #t~mem19.offset) % 4294967296 != 0;havoc #t~mem19.base, #t~mem19.offset;call #t~mem20.base, #t~mem20.offset := read~$Pointer$(~s.base, ~s.offset + 192, 4);~cb~0.base, ~cb~0.offset := #t~mem20.base, #t~mem20.offset;havoc #t~mem20.base, #t~mem20.offset; {13068#true} is VALID [2018-11-14 19:06:32,592 INFO L273 TraceCheckUtils]: 9: Hoare triple {13068#true} call #t~mem21 := read~int(~s.base, ~s.offset + 28, 4);call write~int(#t~mem21 + 1, ~s.base, ~s.offset + 28, 4);havoc #t~mem21; {13068#true} is VALID [2018-11-14 19:06:32,592 INFO L273 TraceCheckUtils]: 10: Hoare triple {13068#true} assume !(~bitwiseAnd(~tmp___1~0, 12288) != 0); {13068#true} is VALID [2018-11-14 19:06:32,592 INFO L273 TraceCheckUtils]: 11: Hoare triple {13068#true} call #t~mem22.base, #t~mem22.offset := read~$Pointer$(~s.base, ~s.offset + 136, 4); {13068#true} is VALID [2018-11-14 19:06:32,593 INFO L273 TraceCheckUtils]: 12: Hoare triple {13068#true} assume !((#t~mem22.base + #t~mem22.offset) % 4294967296 == 0);havoc #t~mem22.base, #t~mem22.offset; {13068#true} is VALID [2018-11-14 19:06:32,593 INFO L273 TraceCheckUtils]: 13: Hoare triple {13068#true} assume true; {13068#true} is VALID [2018-11-14 19:06:32,593 INFO L273 TraceCheckUtils]: 14: Hoare triple {13068#true} assume !false; {13068#true} is VALID [2018-11-14 19:06:32,593 INFO L273 TraceCheckUtils]: 15: Hoare triple {13068#true} call #t~mem23 := read~int(~s.base, ~s.offset + 52, 4);~state~0 := #t~mem23;havoc #t~mem23;call #t~mem24 := read~int(~s.base, ~s.offset + 52, 4); {13068#true} is VALID [2018-11-14 19:06:32,593 INFO L273 TraceCheckUtils]: 16: Hoare triple {13068#true} assume !(#t~mem24 == 12292);havoc #t~mem24;call #t~mem25 := read~int(~s.base, ~s.offset + 52, 4); {13068#true} is VALID [2018-11-14 19:06:32,593 INFO L273 TraceCheckUtils]: 17: Hoare triple {13068#true} assume !(#t~mem25 == 16384);havoc #t~mem25;call #t~mem26 := read~int(~s.base, ~s.offset + 52, 4); {13068#true} is VALID [2018-11-14 19:06:32,593 INFO L273 TraceCheckUtils]: 18: Hoare triple {13068#true} assume !(#t~mem26 == 8192);havoc #t~mem26;call #t~mem27 := read~int(~s.base, ~s.offset + 52, 4); {13068#true} is VALID [2018-11-14 19:06:32,593 INFO L273 TraceCheckUtils]: 19: Hoare triple {13068#true} assume !(#t~mem27 == 24576);havoc #t~mem27;call #t~mem28 := read~int(~s.base, ~s.offset + 52, 4); {13068#true} is VALID [2018-11-14 19:06:32,594 INFO L273 TraceCheckUtils]: 20: Hoare triple {13068#true} assume !(#t~mem28 == 8195);havoc #t~mem28;call #t~mem29 := read~int(~s.base, ~s.offset + 52, 4); {13068#true} is VALID [2018-11-14 19:06:32,594 INFO L273 TraceCheckUtils]: 21: Hoare triple {13068#true} assume !(#t~mem29 == 8480);havoc #t~mem29;call #t~mem30 := read~int(~s.base, ~s.offset + 52, 4); {13068#true} is VALID [2018-11-14 19:06:32,594 INFO L273 TraceCheckUtils]: 22: Hoare triple {13068#true} assume !(#t~mem30 == 8481);havoc #t~mem30;call #t~mem31 := read~int(~s.base, ~s.offset + 52, 4); {13068#true} is VALID [2018-11-14 19:06:32,594 INFO L273 TraceCheckUtils]: 23: Hoare triple {13068#true} assume !(#t~mem31 == 8482);havoc #t~mem31;call #t~mem32 := read~int(~s.base, ~s.offset + 52, 4); {13068#true} is VALID [2018-11-14 19:06:32,594 INFO L273 TraceCheckUtils]: 24: Hoare triple {13068#true} assume #t~mem32 == 8464;havoc #t~mem32; {13068#true} is VALID [2018-11-14 19:06:32,594 INFO L273 TraceCheckUtils]: 25: Hoare triple {13068#true} call write~int(0, ~s.base, ~s.offset + 48, 4);assume -2147483648 <= #t~nondet69 && #t~nondet69 <= 2147483647;~ret~0 := #t~nondet69;havoc #t~nondet69; {13068#true} is VALID [2018-11-14 19:06:32,594 INFO L273 TraceCheckUtils]: 26: Hoare triple {13068#true} assume ~blastFlag~0 == 0;~blastFlag~0 := 1; {13068#true} is VALID [2018-11-14 19:06:32,594 INFO L273 TraceCheckUtils]: 27: Hoare triple {13068#true} assume !(~ret~0 <= 0);~got_new_session~0 := 1;call write~int(8496, ~s.base, ~s.offset + 52, 4);call write~int(0, ~s.base, ~s.offset + 64, 4); {13068#true} is VALID [2018-11-14 19:06:32,594 INFO L273 TraceCheckUtils]: 28: Hoare triple {13068#true} call #t~mem127.base, #t~mem127.offset := read~$Pointer$(~s.base, ~s.offset + 84, 4);call #t~mem128 := read~int(#t~mem127.base, #t~mem127.offset + 604 + 244, 4); {13068#true} is VALID [2018-11-14 19:06:32,595 INFO L273 TraceCheckUtils]: 29: Hoare triple {13068#true} assume !(#t~mem128 == 0);havoc #t~mem127.base, #t~mem127.offset;havoc #t~mem128; {13068#true} is VALID [2018-11-14 19:06:32,595 INFO L273 TraceCheckUtils]: 30: Hoare triple {13068#true} ~skip~0 := 0; {13068#true} is VALID [2018-11-14 19:06:32,595 INFO L273 TraceCheckUtils]: 31: Hoare triple {13068#true} assume true; {13068#true} is VALID [2018-11-14 19:06:32,595 INFO L273 TraceCheckUtils]: 32: Hoare triple {13068#true} assume !false; {13068#true} is VALID [2018-11-14 19:06:32,595 INFO L273 TraceCheckUtils]: 33: Hoare triple {13068#true} call #t~mem23 := read~int(~s.base, ~s.offset + 52, 4);~state~0 := #t~mem23;havoc #t~mem23;call #t~mem24 := read~int(~s.base, ~s.offset + 52, 4); {13070#(= (select (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 52)) |ssl3_accept_#t~mem24|)} is VALID [2018-11-14 19:06:32,596 INFO L273 TraceCheckUtils]: 34: Hoare triple {13070#(= (select (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 52)) |ssl3_accept_#t~mem24|)} assume #t~mem24 == 12292;havoc #t~mem24; {13071#(= 12292 (select (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 52)))} is VALID [2018-11-14 19:06:32,596 INFO L273 TraceCheckUtils]: 35: Hoare triple {13071#(= 12292 (select (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 52)))} call write~int(1, ~s.base, ~s.offset + 40, 4); {13071#(= 12292 (select (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 52)))} is VALID [2018-11-14 19:06:32,597 INFO L273 TraceCheckUtils]: 36: Hoare triple {13071#(= 12292 (select (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 52)))} call write~int(1, ~s.base, ~s.offset + 36, 4); {13071#(= 12292 (select (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 52)))} is VALID [2018-11-14 19:06:32,600 INFO L273 TraceCheckUtils]: 37: Hoare triple {13071#(= 12292 (select (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 52)))} assume (~cb~0.base + ~cb~0.offset) % 4294967296 != 0; {13071#(= 12292 (select (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 52)))} is VALID [2018-11-14 19:06:32,601 INFO L273 TraceCheckUtils]: 38: Hoare triple {13071#(= 12292 (select (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 52)))} call #t~mem59 := read~int(~s.base, ~s.offset + 0, 4); {13071#(= 12292 (select (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 52)))} is VALID [2018-11-14 19:06:32,601 INFO L273 TraceCheckUtils]: 39: Hoare triple {13071#(= 12292 (select (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 52)))} assume !(#t~mem59 / 256 != 3);havoc #t~mem59;call write~int(8192, ~s.base, ~s.offset + 4, 4);call #t~mem60.base, #t~mem60.offset := read~$Pointer$(~s.base, ~s.offset + 60, 4); {13071#(= 12292 (select (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 52)))} is VALID [2018-11-14 19:06:32,602 INFO L273 TraceCheckUtils]: 40: Hoare triple {13071#(= 12292 (select (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 52)))} assume !((#t~mem60.base + #t~mem60.offset) % 4294967296 == 0);havoc #t~mem60.base, #t~mem60.offset; {13071#(= 12292 (select (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 52)))} is VALID [2018-11-14 19:06:32,602 INFO L273 TraceCheckUtils]: 41: Hoare triple {13071#(= 12292 (select (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 52)))} assume !(~tmp___4~0 == 0);call write~int(0, ~s.base, ~s.offset + 64, 4);call #t~mem62 := read~int(~s.base, ~s.offset + 52, 4); {13072#(= 12292 |ssl3_accept_#t~mem62|)} is VALID [2018-11-14 19:06:32,603 INFO L273 TraceCheckUtils]: 42: Hoare triple {13072#(= 12292 |ssl3_accept_#t~mem62|)} assume #t~mem62 != 12292;havoc #t~mem62; {13069#false} is VALID [2018-11-14 19:06:32,603 INFO L273 TraceCheckUtils]: 43: Hoare triple {13069#false} assume !(~tmp___5~0 == 0);call write~int(8464, ~s.base, ~s.offset + 52, 4);call #t~mem63.base, #t~mem63.offset := read~$Pointer$(~s.base, ~s.offset + 204, 4);call #t~mem64 := read~int(#t~mem63.base, #t~mem63.offset + 60 + 12, 4);call write~int(#t~mem64 + 1, #t~mem63.base, #t~mem63.offset + 60 + 12, 4);havoc #t~mem64;havoc #t~mem63.base, #t~mem63.offset; {13069#false} is VALID [2018-11-14 19:06:32,603 INFO L273 TraceCheckUtils]: 44: Hoare triple {13069#false} call #t~mem127.base, #t~mem127.offset := read~$Pointer$(~s.base, ~s.offset + 84, 4);call #t~mem128 := read~int(#t~mem127.base, #t~mem127.offset + 604 + 244, 4); {13069#false} is VALID [2018-11-14 19:06:32,603 INFO L273 TraceCheckUtils]: 45: Hoare triple {13069#false} assume !(#t~mem128 == 0);havoc #t~mem127.base, #t~mem127.offset;havoc #t~mem128; {13069#false} is VALID [2018-11-14 19:06:32,603 INFO L273 TraceCheckUtils]: 46: Hoare triple {13069#false} ~skip~0 := 0; {13069#false} is VALID [2018-11-14 19:06:32,603 INFO L273 TraceCheckUtils]: 47: Hoare triple {13069#false} assume true; {13069#false} is VALID [2018-11-14 19:06:32,604 INFO L273 TraceCheckUtils]: 48: Hoare triple {13069#false} assume !false; {13069#false} is VALID [2018-11-14 19:06:32,604 INFO L273 TraceCheckUtils]: 49: Hoare triple {13069#false} call #t~mem23 := read~int(~s.base, ~s.offset + 52, 4);~state~0 := #t~mem23;havoc #t~mem23;call #t~mem24 := read~int(~s.base, ~s.offset + 52, 4); {13069#false} is VALID [2018-11-14 19:06:32,604 INFO L273 TraceCheckUtils]: 50: Hoare triple {13069#false} assume !(#t~mem24 == 12292);havoc #t~mem24;call #t~mem25 := read~int(~s.base, ~s.offset + 52, 4); {13069#false} is VALID [2018-11-14 19:06:32,604 INFO L273 TraceCheckUtils]: 51: Hoare triple {13069#false} assume !(#t~mem25 == 16384);havoc #t~mem25;call #t~mem26 := read~int(~s.base, ~s.offset + 52, 4); {13069#false} is VALID [2018-11-14 19:06:32,604 INFO L273 TraceCheckUtils]: 52: Hoare triple {13069#false} assume !(#t~mem26 == 8192);havoc #t~mem26;call #t~mem27 := read~int(~s.base, ~s.offset + 52, 4); {13069#false} is VALID [2018-11-14 19:06:32,605 INFO L273 TraceCheckUtils]: 53: Hoare triple {13069#false} assume !(#t~mem27 == 24576);havoc #t~mem27;call #t~mem28 := read~int(~s.base, ~s.offset + 52, 4); {13069#false} is VALID [2018-11-14 19:06:32,605 INFO L273 TraceCheckUtils]: 54: Hoare triple {13069#false} assume !(#t~mem28 == 8195);havoc #t~mem28;call #t~mem29 := read~int(~s.base, ~s.offset + 52, 4); {13069#false} is VALID [2018-11-14 19:06:32,605 INFO L273 TraceCheckUtils]: 55: Hoare triple {13069#false} assume !(#t~mem29 == 8480);havoc #t~mem29;call #t~mem30 := read~int(~s.base, ~s.offset + 52, 4); {13069#false} is VALID [2018-11-14 19:06:32,605 INFO L273 TraceCheckUtils]: 56: Hoare triple {13069#false} assume !(#t~mem30 == 8481);havoc #t~mem30;call #t~mem31 := read~int(~s.base, ~s.offset + 52, 4); {13069#false} is VALID [2018-11-14 19:06:32,605 INFO L273 TraceCheckUtils]: 57: Hoare triple {13069#false} assume !(#t~mem31 == 8482);havoc #t~mem31;call #t~mem32 := read~int(~s.base, ~s.offset + 52, 4); {13069#false} is VALID [2018-11-14 19:06:32,606 INFO L273 TraceCheckUtils]: 58: Hoare triple {13069#false} assume !(#t~mem32 == 8464);havoc #t~mem32;call #t~mem33 := read~int(~s.base, ~s.offset + 52, 4); {13069#false} is VALID [2018-11-14 19:06:32,606 INFO L273 TraceCheckUtils]: 59: Hoare triple {13069#false} assume !(#t~mem33 == 8465);havoc #t~mem33;call #t~mem34 := read~int(~s.base, ~s.offset + 52, 4); {13069#false} is VALID [2018-11-14 19:06:32,606 INFO L273 TraceCheckUtils]: 60: Hoare triple {13069#false} assume !(#t~mem34 == 8466);havoc #t~mem34;call #t~mem35 := read~int(~s.base, ~s.offset + 52, 4); {13069#false} is VALID [2018-11-14 19:06:32,606 INFO L273 TraceCheckUtils]: 61: Hoare triple {13069#false} assume !(#t~mem35 == 8496);havoc #t~mem35;call #t~mem36 := read~int(~s.base, ~s.offset + 52, 4); {13069#false} is VALID [2018-11-14 19:06:32,606 INFO L273 TraceCheckUtils]: 62: Hoare triple {13069#false} assume !(#t~mem36 == 8497);havoc #t~mem36;call #t~mem37 := read~int(~s.base, ~s.offset + 52, 4); {13069#false} is VALID [2018-11-14 19:06:32,606 INFO L273 TraceCheckUtils]: 63: Hoare triple {13069#false} assume !(#t~mem37 == 8512);havoc #t~mem37;call #t~mem38 := read~int(~s.base, ~s.offset + 52, 4); {13069#false} is VALID [2018-11-14 19:06:32,607 INFO L273 TraceCheckUtils]: 64: Hoare triple {13069#false} assume !(#t~mem38 == 8513);havoc #t~mem38;call #t~mem39 := read~int(~s.base, ~s.offset + 52, 4); {13069#false} is VALID [2018-11-14 19:06:32,607 INFO L273 TraceCheckUtils]: 65: Hoare triple {13069#false} assume !(#t~mem39 == 8528);havoc #t~mem39;call #t~mem40 := read~int(~s.base, ~s.offset + 52, 4); {13069#false} is VALID [2018-11-14 19:06:32,607 INFO L273 TraceCheckUtils]: 66: Hoare triple {13069#false} assume !(#t~mem40 == 8529);havoc #t~mem40;call #t~mem41 := read~int(~s.base, ~s.offset + 52, 4); {13069#false} is VALID [2018-11-14 19:06:32,607 INFO L273 TraceCheckUtils]: 67: Hoare triple {13069#false} assume !(#t~mem41 == 8544);havoc #t~mem41;call #t~mem42 := read~int(~s.base, ~s.offset + 52, 4); {13069#false} is VALID [2018-11-14 19:06:32,607 INFO L273 TraceCheckUtils]: 68: Hoare triple {13069#false} assume !(#t~mem42 == 8545);havoc #t~mem42;call #t~mem43 := read~int(~s.base, ~s.offset + 52, 4); {13069#false} is VALID [2018-11-14 19:06:32,608 INFO L273 TraceCheckUtils]: 69: Hoare triple {13069#false} assume !(#t~mem43 == 8560);havoc #t~mem43;call #t~mem44 := read~int(~s.base, ~s.offset + 52, 4); {13069#false} is VALID [2018-11-14 19:06:32,608 INFO L273 TraceCheckUtils]: 70: Hoare triple {13069#false} assume !(#t~mem44 == 8561);havoc #t~mem44;call #t~mem45 := read~int(~s.base, ~s.offset + 52, 4); {13069#false} is VALID [2018-11-14 19:06:32,608 INFO L273 TraceCheckUtils]: 71: Hoare triple {13069#false} assume !(#t~mem45 == 8448);havoc #t~mem45;call #t~mem46 := read~int(~s.base, ~s.offset + 52, 4); {13069#false} is VALID [2018-11-14 19:06:32,608 INFO L273 TraceCheckUtils]: 72: Hoare triple {13069#false} assume !(#t~mem46 == 8576);havoc #t~mem46;call #t~mem47 := read~int(~s.base, ~s.offset + 52, 4); {13069#false} is VALID [2018-11-14 19:06:32,608 INFO L273 TraceCheckUtils]: 73: Hoare triple {13069#false} assume !(#t~mem47 == 8577);havoc #t~mem47;call #t~mem48 := read~int(~s.base, ~s.offset + 52, 4); {13069#false} is VALID [2018-11-14 19:06:32,608 INFO L273 TraceCheckUtils]: 74: Hoare triple {13069#false} assume !(#t~mem48 == 8592);havoc #t~mem48;call #t~mem49 := read~int(~s.base, ~s.offset + 52, 4); {13069#false} is VALID [2018-11-14 19:06:32,608 INFO L273 TraceCheckUtils]: 75: Hoare triple {13069#false} assume !(#t~mem49 == 8593);havoc #t~mem49;call #t~mem50 := read~int(~s.base, ~s.offset + 52, 4); {13069#false} is VALID [2018-11-14 19:06:32,608 INFO L273 TraceCheckUtils]: 76: Hoare triple {13069#false} assume !(#t~mem50 == 8608);havoc #t~mem50;call #t~mem51 := read~int(~s.base, ~s.offset + 52, 4); {13069#false} is VALID [2018-11-14 19:06:32,608 INFO L273 TraceCheckUtils]: 77: Hoare triple {13069#false} assume !(#t~mem51 == 8609);havoc #t~mem51;call #t~mem52 := read~int(~s.base, ~s.offset + 52, 4); {13069#false} is VALID [2018-11-14 19:06:32,609 INFO L273 TraceCheckUtils]: 78: Hoare triple {13069#false} assume !(#t~mem52 == 8640);havoc #t~mem52;call #t~mem53 := read~int(~s.base, ~s.offset + 52, 4); {13069#false} is VALID [2018-11-14 19:06:32,609 INFO L273 TraceCheckUtils]: 79: Hoare triple {13069#false} assume !(#t~mem53 == 8641);havoc #t~mem53;call #t~mem54 := read~int(~s.base, ~s.offset + 52, 4); {13069#false} is VALID [2018-11-14 19:06:32,609 INFO L273 TraceCheckUtils]: 80: Hoare triple {13069#false} assume !(#t~mem54 == 8656);havoc #t~mem54;call #t~mem55 := read~int(~s.base, ~s.offset + 52, 4); {13069#false} is VALID [2018-11-14 19:06:32,609 INFO L273 TraceCheckUtils]: 81: Hoare triple {13069#false} assume !(#t~mem55 == 8657);havoc #t~mem55;call #t~mem56 := read~int(~s.base, ~s.offset + 52, 4); {13069#false} is VALID [2018-11-14 19:06:32,609 INFO L273 TraceCheckUtils]: 82: Hoare triple {13069#false} assume #t~mem56 == 8672;havoc #t~mem56; {13069#false} is VALID [2018-11-14 19:06:32,609 INFO L273 TraceCheckUtils]: 83: Hoare triple {13069#false} assume -2147483648 <= #t~nondet121 && #t~nondet121 <= 2147483647;~ret~0 := #t~nondet121;havoc #t~nondet121; {13069#false} is VALID [2018-11-14 19:06:32,609 INFO L273 TraceCheckUtils]: 84: Hoare triple {13069#false} assume ~blastFlag~0 == 4; {13069#false} is VALID [2018-11-14 19:06:32,609 INFO L273 TraceCheckUtils]: 85: Hoare triple {13069#false} assume !false; {13069#false} is VALID [2018-11-14 19:06:32,614 INFO L134 CoverageAnalysis]: Checked inductivity of 23 backedges. 20 proven. 0 refuted. 0 times theorem prover too weak. 3 trivial. 0 not checked. [2018-11-14 19:06:32,614 INFO L312 seRefinementStrategy]: Constructing automaton from 1 perfect and 0 imperfect interpolant sequences. [2018-11-14 19:06:32,614 INFO L327 seRefinementStrategy]: Number of different interpolants: perfect sequences [5] imperfect sequences [] total 5 [2018-11-14 19:06:32,614 INFO L78 Accepts]: Start accepts. Automaton has 5 states. Word has length 86 [2018-11-14 19:06:32,615 INFO L84 Accepts]: Finished accepts. word is accepted. [2018-11-14 19:06:32,615 INFO L86 InductivityCheck]: Starting indutivity check of a Floyd-Hoare automaton with 5 states. [2018-11-14 19:06:32,692 INFO L119 InductivityCheck]: Floyd-Hoare automaton has 84 edges. 84 inductive. 0 not inductive. 0 times theorem prover too weak to decide inductivity. [2018-11-14 19:06:32,692 INFO L459 AbstractCegarLoop]: Interpolant automaton has 5 states [2018-11-14 19:06:32,693 INFO L142 InterpolantAutomaton]: Constructing interpolant automaton starting with 5 interpolants. [2018-11-14 19:06:32,693 INFO L144 InterpolantAutomaton]: CoverageRelationStatistics Valid=7, Invalid=13, Unknown=0, NotChecked=0, Total=20 [2018-11-14 19:06:32,693 INFO L87 Difference]: Start difference. First operand 189 states and 279 transitions. Second operand 5 states. [2018-11-14 19:06:34,447 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2018-11-14 19:06:34,447 INFO L93 Difference]: Finished difference Result 361 states and 541 transitions. [2018-11-14 19:06:34,447 INFO L142 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 5 states. [2018-11-14 19:06:34,448 INFO L78 Accepts]: Start accepts. Automaton has 5 states. Word has length 86 [2018-11-14 19:06:34,448 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2018-11-14 19:06:34,448 INFO L82 GeneralOperation]: Start removeUnreachable. Operand 5 states. [2018-11-14 19:06:34,450 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 5 states to 5 states and 403 transitions. [2018-11-14 19:06:34,450 INFO L82 GeneralOperation]: Start removeUnreachable. Operand 5 states. [2018-11-14 19:06:34,452 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 5 states to 5 states and 403 transitions. [2018-11-14 19:06:34,452 INFO L86 InductivityCheck]: Starting indutivity check of a Floyd-Hoare automaton with 5 states and 403 transitions. [2018-11-14 19:06:34,839 INFO L119 InductivityCheck]: Floyd-Hoare automaton has 403 edges. 403 inductive. 0 not inductive. 0 times theorem prover too weak to decide inductivity. [2018-11-14 19:06:34,843 INFO L225 Difference]: With dead ends: 361 [2018-11-14 19:06:34,843 INFO L226 Difference]: Without dead ends: 198 [2018-11-14 19:06:34,844 INFO L604 BasicCegarLoop]: 0 DeclaredPredicates, 10 GetRequests, 2 SyntacticMatches, 4 SemanticMatches, 4 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 0 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=11, Invalid=19, Unknown=0, NotChecked=0, Total=30 [2018-11-14 19:06:34,844 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 198 states. [2018-11-14 19:06:34,866 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 198 to 198. [2018-11-14 19:06:34,866 INFO L214 AbstractMinimizeNwa]: Start testing correctness of minimizeSevpa [2018-11-14 19:06:34,866 INFO L82 GeneralOperation]: Start isEquivalent. First operand 198 states. Second operand 198 states. [2018-11-14 19:06:34,866 INFO L74 IsIncluded]: Start isIncluded. First operand 198 states. Second operand 198 states. [2018-11-14 19:06:34,866 INFO L87 Difference]: Start difference. First operand 198 states. Second operand 198 states. [2018-11-14 19:06:34,871 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2018-11-14 19:06:34,871 INFO L93 Difference]: Finished difference Result 198 states and 290 transitions. [2018-11-14 19:06:34,871 INFO L276 IsEmpty]: Start isEmpty. Operand 198 states and 290 transitions. [2018-11-14 19:06:34,872 INFO L282 IsEmpty]: Finished isEmpty. No accepting run. [2018-11-14 19:06:34,872 INFO L83 IsIncluded]: Finished isIncluded. Language is included [2018-11-14 19:06:34,872 INFO L74 IsIncluded]: Start isIncluded. First operand 198 states. Second operand 198 states. [2018-11-14 19:06:34,872 INFO L87 Difference]: Start difference. First operand 198 states. Second operand 198 states. [2018-11-14 19:06:34,876 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2018-11-14 19:06:34,876 INFO L93 Difference]: Finished difference Result 198 states and 290 transitions. [2018-11-14 19:06:34,876 INFO L276 IsEmpty]: Start isEmpty. Operand 198 states and 290 transitions. [2018-11-14 19:06:34,877 INFO L282 IsEmpty]: Finished isEmpty. No accepting run. [2018-11-14 19:06:34,877 INFO L83 IsIncluded]: Finished isIncluded. Language is included [2018-11-14 19:06:34,877 INFO L88 GeneralOperation]: Finished isEquivalent. [2018-11-14 19:06:34,877 INFO L221 AbstractMinimizeNwa]: Finished testing correctness of minimizeSevpa [2018-11-14 19:06:34,877 INFO L82 GeneralOperation]: Start removeUnreachable. Operand 198 states. [2018-11-14 19:06:34,881 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 198 states to 198 states and 290 transitions. [2018-11-14 19:06:34,881 INFO L78 Accepts]: Start accepts. Automaton has 198 states and 290 transitions. Word has length 86 [2018-11-14 19:06:34,882 INFO L84 Accepts]: Finished accepts. word is rejected. [2018-11-14 19:06:34,882 INFO L480 AbstractCegarLoop]: Abstraction has 198 states and 290 transitions. [2018-11-14 19:06:34,882 INFO L481 AbstractCegarLoop]: Interpolant automaton has 5 states. [2018-11-14 19:06:34,882 INFO L276 IsEmpty]: Start isEmpty. Operand 198 states and 290 transitions. [2018-11-14 19:06:34,883 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 87 [2018-11-14 19:06:34,883 INFO L367 BasicCegarLoop]: Found error trace [2018-11-14 19:06:34,883 INFO L375 BasicCegarLoop]: trace histogram [3, 3, 3, 3, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2018-11-14 19:06:34,884 INFO L423 AbstractCegarLoop]: === Iteration 16 === [ssl3_acceptErr0ASSERT_VIOLATIONERROR_FUNCTION]=== [2018-11-14 19:06:34,884 INFO L141 PredicateUnifier]: Initialized classic predicate unifier [2018-11-14 19:06:34,884 INFO L82 PathProgramCache]: Analyzing trace with hash -47712241, now seen corresponding path program 1 times [2018-11-14 19:06:34,884 INFO L223 ckRefinementStrategy]: Switched to mode SMTINTERPOL_TREE_INTERPOLANTS [2018-11-14 19:06:34,884 INFO L69 tionRefinementEngine]: Using refinement strategy CamelRefinementStrategy [2018-11-14 19:06:34,885 INFO L119 rtionOrderModulation]: Craig_TreeInterpolation forces the order to NOT_INCREMENTALLY [2018-11-14 19:06:34,885 INFO L103 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2018-11-14 19:06:34,885 INFO L119 rtionOrderModulation]: Craig_TreeInterpolation forces the order to NOT_INCREMENTALLY [2018-11-14 19:06:34,901 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2018-11-14 19:06:35,164 INFO L256 TraceCheckUtils]: 0: Hoare triple {14129#true} call ULTIMATE.init(); {14129#true} is VALID [2018-11-14 19:06:35,165 INFO L273 TraceCheckUtils]: 1: Hoare triple {14129#true} #NULL.base, #NULL.offset := 0, 0;#valid := #valid[0 := 0];~init~0 := 1;call ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset := #Ultimate.alloc(100);call write~unchecked~int(0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 0, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 4, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 8, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 12, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 16, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 20, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 24, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 28, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 32, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 36, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 40, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 44, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 48, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 52, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 56, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 60, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 64, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 68, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 72, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 76, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 80, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 84, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 88, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 92, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 96, 4);call write~unchecked~int(0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 0, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 4, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 8, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 12, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 16, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 20, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 24, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 28, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 32, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 36, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 40, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 44, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 48, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 52, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 56, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 60, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 64, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 68, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 72, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 76, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 80, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 84, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 88, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 92, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 96, 4); {14129#true} is VALID [2018-11-14 19:06:35,165 INFO L273 TraceCheckUtils]: 2: Hoare triple {14129#true} assume true; {14129#true} is VALID [2018-11-14 19:06:35,165 INFO L268 TraceCheckUtils]: 3: Hoare quadruple {14129#true} {14129#true} #654#return; {14129#true} is VALID [2018-11-14 19:06:35,165 INFO L256 TraceCheckUtils]: 4: Hoare triple {14129#true} call #t~ret138 := main(); {14129#true} is VALID [2018-11-14 19:06:35,166 INFO L273 TraceCheckUtils]: 5: Hoare triple {14129#true} havoc ~s~0.base, ~s~0.offset;havoc ~tmp~2;call #t~malloc3.base, #t~malloc3.offset := #Ultimate.alloc(248);~s~0.base, ~s~0.offset := #t~malloc3.base, #t~malloc3.offset;call #t~malloc4.base, #t~malloc4.offset := #Ultimate.alloc(899);call write~$Pointer$(#t~malloc4.base, #t~malloc4.offset, ~s~0.base, ~s~0.offset + 84, 4);call #t~malloc5.base, #t~malloc5.offset := #Ultimate.alloc(232);call write~$Pointer$(#t~malloc5.base, #t~malloc5.offset, ~s~0.base, ~s~0.offset + 204, 4);call #t~malloc6.base, #t~malloc6.offset := #Ultimate.alloc(200);call write~$Pointer$(#t~malloc6.base, #t~malloc6.offset, ~s~0.base, ~s~0.offset + 176, 4);call write~int(8464, ~s~0.base, ~s~0.offset + 52, 4); {14129#true} is VALID [2018-11-14 19:06:35,166 INFO L256 TraceCheckUtils]: 6: Hoare triple {14129#true} call #t~ret7 := ssl3_accept(~s~0.base, ~s~0.offset); {14129#true} is VALID [2018-11-14 19:06:35,166 INFO L273 TraceCheckUtils]: 7: Hoare triple {14129#true} ~s.base, ~s.offset := #in~s.base, #in~s.offset;havoc ~buf~0.base, ~buf~0.offset;havoc ~l~0;havoc ~Time~0;havoc ~tmp~3;havoc ~cb~0.base, ~cb~0.offset;havoc ~num1~0;havoc ~ret~0;havoc ~new_state~0;havoc ~state~0;havoc ~skip~0;havoc ~got_new_session~0;assume -2147483648 <= #t~nondet8 && #t~nondet8 <= 2147483647;~tmp___1~0 := #t~nondet8;havoc #t~nondet8;assume -2147483648 <= #t~nondet9 && #t~nondet9 <= 2147483647;~tmp___2~0 := #t~nondet9;havoc #t~nondet9;assume -2147483648 <= #t~nondet10 && #t~nondet10 <= 2147483647;~tmp___3~0 := #t~nondet10;havoc #t~nondet10;assume -2147483648 <= #t~nondet11 && #t~nondet11 <= 2147483647;~tmp___4~0 := #t~nondet11;havoc #t~nondet11;assume -2147483648 <= #t~nondet12 && #t~nondet12 <= 2147483647;~tmp___5~0 := #t~nondet12;havoc #t~nondet12;assume -2147483648 <= #t~nondet13 && #t~nondet13 <= 2147483647;~tmp___6~0 := #t~nondet13;havoc #t~nondet13;havoc ~tmp___7~0;assume -2147483648 <= #t~nondet14 && #t~nondet14 <= 2147483647;~tmp___8~0 := #t~nondet14;havoc #t~nondet14;assume -2147483648 <= #t~nondet15 && #t~nondet15 <= 2147483647;~tmp___9~0 := #t~nondet15;havoc #t~nondet15;assume -2147483648 <= #t~nondet16 && #t~nondet16 <= 2147483647;~tmp___10~0 := #t~nondet16;havoc #t~nondet16;havoc ~blastFlag~0;~blastFlag~0 := 0;assume -2147483648 <= #t~nondet17 && #t~nondet17 <= 2147483647;call write~int(#t~nondet17, ~s.base, ~s.offset + 92, 4);havoc #t~nondet17;call write~int(8464, ~s.base, ~s.offset + 52, 4);assume -2147483648 <= #t~nondet18 && #t~nondet18 <= 2147483647;~tmp~3 := #t~nondet18;havoc #t~nondet18;~Time~0 := ~tmp~3;~cb~0.base, ~cb~0.offset := 0, 0;~ret~0 := -1;~skip~0 := 0;~got_new_session~0 := 0;call #t~mem19.base, #t~mem19.offset := read~$Pointer$(~s.base, ~s.offset + 192, 4); {14129#true} is VALID [2018-11-14 19:06:35,166 INFO L273 TraceCheckUtils]: 8: Hoare triple {14129#true} assume (#t~mem19.base + #t~mem19.offset) % 4294967296 != 0;havoc #t~mem19.base, #t~mem19.offset;call #t~mem20.base, #t~mem20.offset := read~$Pointer$(~s.base, ~s.offset + 192, 4);~cb~0.base, ~cb~0.offset := #t~mem20.base, #t~mem20.offset;havoc #t~mem20.base, #t~mem20.offset; {14129#true} is VALID [2018-11-14 19:06:35,166 INFO L273 TraceCheckUtils]: 9: Hoare triple {14129#true} call #t~mem21 := read~int(~s.base, ~s.offset + 28, 4);call write~int(#t~mem21 + 1, ~s.base, ~s.offset + 28, 4);havoc #t~mem21; {14129#true} is VALID [2018-11-14 19:06:35,167 INFO L273 TraceCheckUtils]: 10: Hoare triple {14129#true} assume !(~bitwiseAnd(~tmp___1~0, 12288) != 0); {14129#true} is VALID [2018-11-14 19:06:35,167 INFO L273 TraceCheckUtils]: 11: Hoare triple {14129#true} call #t~mem22.base, #t~mem22.offset := read~$Pointer$(~s.base, ~s.offset + 136, 4); {14129#true} is VALID [2018-11-14 19:06:35,167 INFO L273 TraceCheckUtils]: 12: Hoare triple {14129#true} assume !((#t~mem22.base + #t~mem22.offset) % 4294967296 == 0);havoc #t~mem22.base, #t~mem22.offset; {14129#true} is VALID [2018-11-14 19:06:35,167 INFO L273 TraceCheckUtils]: 13: Hoare triple {14129#true} assume true; {14129#true} is VALID [2018-11-14 19:06:35,167 INFO L273 TraceCheckUtils]: 14: Hoare triple {14129#true} assume !false; {14129#true} is VALID [2018-11-14 19:06:35,167 INFO L273 TraceCheckUtils]: 15: Hoare triple {14129#true} call #t~mem23 := read~int(~s.base, ~s.offset + 52, 4);~state~0 := #t~mem23;havoc #t~mem23;call #t~mem24 := read~int(~s.base, ~s.offset + 52, 4); {14129#true} is VALID [2018-11-14 19:06:35,168 INFO L273 TraceCheckUtils]: 16: Hoare triple {14129#true} assume !(#t~mem24 == 12292);havoc #t~mem24;call #t~mem25 := read~int(~s.base, ~s.offset + 52, 4); {14129#true} is VALID [2018-11-14 19:06:35,168 INFO L273 TraceCheckUtils]: 17: Hoare triple {14129#true} assume !(#t~mem25 == 16384);havoc #t~mem25;call #t~mem26 := read~int(~s.base, ~s.offset + 52, 4); {14129#true} is VALID [2018-11-14 19:06:35,168 INFO L273 TraceCheckUtils]: 18: Hoare triple {14129#true} assume !(#t~mem26 == 8192);havoc #t~mem26;call #t~mem27 := read~int(~s.base, ~s.offset + 52, 4); {14129#true} is VALID [2018-11-14 19:06:35,168 INFO L273 TraceCheckUtils]: 19: Hoare triple {14129#true} assume !(#t~mem27 == 24576);havoc #t~mem27;call #t~mem28 := read~int(~s.base, ~s.offset + 52, 4); {14129#true} is VALID [2018-11-14 19:06:35,168 INFO L273 TraceCheckUtils]: 20: Hoare triple {14129#true} assume !(#t~mem28 == 8195);havoc #t~mem28;call #t~mem29 := read~int(~s.base, ~s.offset + 52, 4); {14129#true} is VALID [2018-11-14 19:06:35,168 INFO L273 TraceCheckUtils]: 21: Hoare triple {14129#true} assume !(#t~mem29 == 8480);havoc #t~mem29;call #t~mem30 := read~int(~s.base, ~s.offset + 52, 4); {14129#true} is VALID [2018-11-14 19:06:35,169 INFO L273 TraceCheckUtils]: 22: Hoare triple {14129#true} assume !(#t~mem30 == 8481);havoc #t~mem30;call #t~mem31 := read~int(~s.base, ~s.offset + 52, 4); {14129#true} is VALID [2018-11-14 19:06:35,169 INFO L273 TraceCheckUtils]: 23: Hoare triple {14129#true} assume !(#t~mem31 == 8482);havoc #t~mem31;call #t~mem32 := read~int(~s.base, ~s.offset + 52, 4); {14129#true} is VALID [2018-11-14 19:06:35,169 INFO L273 TraceCheckUtils]: 24: Hoare triple {14129#true} assume #t~mem32 == 8464;havoc #t~mem32; {14129#true} is VALID [2018-11-14 19:06:35,169 INFO L273 TraceCheckUtils]: 25: Hoare triple {14129#true} call write~int(0, ~s.base, ~s.offset + 48, 4);assume -2147483648 <= #t~nondet69 && #t~nondet69 <= 2147483647;~ret~0 := #t~nondet69;havoc #t~nondet69; {14129#true} is VALID [2018-11-14 19:06:35,169 INFO L273 TraceCheckUtils]: 26: Hoare triple {14129#true} assume ~blastFlag~0 == 0;~blastFlag~0 := 1; {14129#true} is VALID [2018-11-14 19:06:35,170 INFO L273 TraceCheckUtils]: 27: Hoare triple {14129#true} assume !(~ret~0 <= 0);~got_new_session~0 := 1;call write~int(8496, ~s.base, ~s.offset + 52, 4);call write~int(0, ~s.base, ~s.offset + 64, 4); {14131#(= (select (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 52)) 8496)} is VALID [2018-11-14 19:06:35,170 INFO L273 TraceCheckUtils]: 28: Hoare triple {14131#(= (select (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 52)) 8496)} call #t~mem127.base, #t~mem127.offset := read~$Pointer$(~s.base, ~s.offset + 84, 4);call #t~mem128 := read~int(#t~mem127.base, #t~mem127.offset + 604 + 244, 4); {14131#(= (select (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 52)) 8496)} is VALID [2018-11-14 19:06:35,170 INFO L273 TraceCheckUtils]: 29: Hoare triple {14131#(= (select (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 52)) 8496)} assume !(#t~mem128 == 0);havoc #t~mem127.base, #t~mem127.offset;havoc #t~mem128; {14131#(= (select (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 52)) 8496)} is VALID [2018-11-14 19:06:35,171 INFO L273 TraceCheckUtils]: 30: Hoare triple {14131#(= (select (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 52)) 8496)} ~skip~0 := 0; {14131#(= (select (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 52)) 8496)} is VALID [2018-11-14 19:06:35,171 INFO L273 TraceCheckUtils]: 31: Hoare triple {14131#(= (select (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 52)) 8496)} assume true; {14131#(= (select (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 52)) 8496)} is VALID [2018-11-14 19:06:35,171 INFO L273 TraceCheckUtils]: 32: Hoare triple {14131#(= (select (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 52)) 8496)} assume !false; {14131#(= (select (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 52)) 8496)} is VALID [2018-11-14 19:06:35,172 INFO L273 TraceCheckUtils]: 33: Hoare triple {14131#(= (select (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 52)) 8496)} call #t~mem23 := read~int(~s.base, ~s.offset + 52, 4);~state~0 := #t~mem23;havoc #t~mem23;call #t~mem24 := read~int(~s.base, ~s.offset + 52, 4); {14131#(= (select (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 52)) 8496)} is VALID [2018-11-14 19:06:35,172 INFO L273 TraceCheckUtils]: 34: Hoare triple {14131#(= (select (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 52)) 8496)} assume !(#t~mem24 == 12292);havoc #t~mem24;call #t~mem25 := read~int(~s.base, ~s.offset + 52, 4); {14132#(= |ssl3_accept_#t~mem25| 8496)} is VALID [2018-11-14 19:06:35,172 INFO L273 TraceCheckUtils]: 35: Hoare triple {14132#(= |ssl3_accept_#t~mem25| 8496)} assume #t~mem25 == 16384;havoc #t~mem25; {14130#false} is VALID [2018-11-14 19:06:35,173 INFO L273 TraceCheckUtils]: 36: Hoare triple {14130#false} call write~int(1, ~s.base, ~s.offset + 36, 4); {14130#false} is VALID [2018-11-14 19:06:35,173 INFO L273 TraceCheckUtils]: 37: Hoare triple {14130#false} assume (~cb~0.base + ~cb~0.offset) % 4294967296 != 0; {14130#false} is VALID [2018-11-14 19:06:35,173 INFO L273 TraceCheckUtils]: 38: Hoare triple {14130#false} call #t~mem59 := read~int(~s.base, ~s.offset + 0, 4); {14130#false} is VALID [2018-11-14 19:06:35,173 INFO L273 TraceCheckUtils]: 39: Hoare triple {14130#false} assume !(#t~mem59 / 256 != 3);havoc #t~mem59;call write~int(8192, ~s.base, ~s.offset + 4, 4);call #t~mem60.base, #t~mem60.offset := read~$Pointer$(~s.base, ~s.offset + 60, 4); {14130#false} is VALID [2018-11-14 19:06:35,173 INFO L273 TraceCheckUtils]: 40: Hoare triple {14130#false} assume !((#t~mem60.base + #t~mem60.offset) % 4294967296 == 0);havoc #t~mem60.base, #t~mem60.offset; {14130#false} is VALID [2018-11-14 19:06:35,173 INFO L273 TraceCheckUtils]: 41: Hoare triple {14130#false} assume !(~tmp___4~0 == 0);call write~int(0, ~s.base, ~s.offset + 64, 4);call #t~mem62 := read~int(~s.base, ~s.offset + 52, 4); {14130#false} is VALID [2018-11-14 19:06:35,173 INFO L273 TraceCheckUtils]: 42: Hoare triple {14130#false} assume #t~mem62 != 12292;havoc #t~mem62; {14130#false} is VALID [2018-11-14 19:06:35,173 INFO L273 TraceCheckUtils]: 43: Hoare triple {14130#false} assume !(~tmp___5~0 == 0);call write~int(8464, ~s.base, ~s.offset + 52, 4);call #t~mem63.base, #t~mem63.offset := read~$Pointer$(~s.base, ~s.offset + 204, 4);call #t~mem64 := read~int(#t~mem63.base, #t~mem63.offset + 60 + 12, 4);call write~int(#t~mem64 + 1, #t~mem63.base, #t~mem63.offset + 60 + 12, 4);havoc #t~mem64;havoc #t~mem63.base, #t~mem63.offset; {14130#false} is VALID [2018-11-14 19:06:35,174 INFO L273 TraceCheckUtils]: 44: Hoare triple {14130#false} call #t~mem127.base, #t~mem127.offset := read~$Pointer$(~s.base, ~s.offset + 84, 4);call #t~mem128 := read~int(#t~mem127.base, #t~mem127.offset + 604 + 244, 4); {14130#false} is VALID [2018-11-14 19:06:35,174 INFO L273 TraceCheckUtils]: 45: Hoare triple {14130#false} assume !(#t~mem128 == 0);havoc #t~mem127.base, #t~mem127.offset;havoc #t~mem128; {14130#false} is VALID [2018-11-14 19:06:35,174 INFO L273 TraceCheckUtils]: 46: Hoare triple {14130#false} ~skip~0 := 0; {14130#false} is VALID [2018-11-14 19:06:35,174 INFO L273 TraceCheckUtils]: 47: Hoare triple {14130#false} assume true; {14130#false} is VALID [2018-11-14 19:06:35,174 INFO L273 TraceCheckUtils]: 48: Hoare triple {14130#false} assume !false; {14130#false} is VALID [2018-11-14 19:06:35,175 INFO L273 TraceCheckUtils]: 49: Hoare triple {14130#false} call #t~mem23 := read~int(~s.base, ~s.offset + 52, 4);~state~0 := #t~mem23;havoc #t~mem23;call #t~mem24 := read~int(~s.base, ~s.offset + 52, 4); {14130#false} is VALID [2018-11-14 19:06:35,175 INFO L273 TraceCheckUtils]: 50: Hoare triple {14130#false} assume !(#t~mem24 == 12292);havoc #t~mem24;call #t~mem25 := read~int(~s.base, ~s.offset + 52, 4); {14130#false} is VALID [2018-11-14 19:06:35,175 INFO L273 TraceCheckUtils]: 51: Hoare triple {14130#false} assume !(#t~mem25 == 16384);havoc #t~mem25;call #t~mem26 := read~int(~s.base, ~s.offset + 52, 4); {14130#false} is VALID [2018-11-14 19:06:35,175 INFO L273 TraceCheckUtils]: 52: Hoare triple {14130#false} assume !(#t~mem26 == 8192);havoc #t~mem26;call #t~mem27 := read~int(~s.base, ~s.offset + 52, 4); {14130#false} is VALID [2018-11-14 19:06:35,175 INFO L273 TraceCheckUtils]: 53: Hoare triple {14130#false} assume !(#t~mem27 == 24576);havoc #t~mem27;call #t~mem28 := read~int(~s.base, ~s.offset + 52, 4); {14130#false} is VALID [2018-11-14 19:06:35,175 INFO L273 TraceCheckUtils]: 54: Hoare triple {14130#false} assume !(#t~mem28 == 8195);havoc #t~mem28;call #t~mem29 := read~int(~s.base, ~s.offset + 52, 4); {14130#false} is VALID [2018-11-14 19:06:35,176 INFO L273 TraceCheckUtils]: 55: Hoare triple {14130#false} assume !(#t~mem29 == 8480);havoc #t~mem29;call #t~mem30 := read~int(~s.base, ~s.offset + 52, 4); {14130#false} is VALID [2018-11-14 19:06:35,176 INFO L273 TraceCheckUtils]: 56: Hoare triple {14130#false} assume !(#t~mem30 == 8481);havoc #t~mem30;call #t~mem31 := read~int(~s.base, ~s.offset + 52, 4); {14130#false} is VALID [2018-11-14 19:06:35,176 INFO L273 TraceCheckUtils]: 57: Hoare triple {14130#false} assume !(#t~mem31 == 8482);havoc #t~mem31;call #t~mem32 := read~int(~s.base, ~s.offset + 52, 4); {14130#false} is VALID [2018-11-14 19:06:35,176 INFO L273 TraceCheckUtils]: 58: Hoare triple {14130#false} assume !(#t~mem32 == 8464);havoc #t~mem32;call #t~mem33 := read~int(~s.base, ~s.offset + 52, 4); {14130#false} is VALID [2018-11-14 19:06:35,176 INFO L273 TraceCheckUtils]: 59: Hoare triple {14130#false} assume !(#t~mem33 == 8465);havoc #t~mem33;call #t~mem34 := read~int(~s.base, ~s.offset + 52, 4); {14130#false} is VALID [2018-11-14 19:06:35,177 INFO L273 TraceCheckUtils]: 60: Hoare triple {14130#false} assume !(#t~mem34 == 8466);havoc #t~mem34;call #t~mem35 := read~int(~s.base, ~s.offset + 52, 4); {14130#false} is VALID [2018-11-14 19:06:35,177 INFO L273 TraceCheckUtils]: 61: Hoare triple {14130#false} assume !(#t~mem35 == 8496);havoc #t~mem35;call #t~mem36 := read~int(~s.base, ~s.offset + 52, 4); {14130#false} is VALID [2018-11-14 19:06:35,177 INFO L273 TraceCheckUtils]: 62: Hoare triple {14130#false} assume !(#t~mem36 == 8497);havoc #t~mem36;call #t~mem37 := read~int(~s.base, ~s.offset + 52, 4); {14130#false} is VALID [2018-11-14 19:06:35,177 INFO L273 TraceCheckUtils]: 63: Hoare triple {14130#false} assume !(#t~mem37 == 8512);havoc #t~mem37;call #t~mem38 := read~int(~s.base, ~s.offset + 52, 4); {14130#false} is VALID [2018-11-14 19:06:35,177 INFO L273 TraceCheckUtils]: 64: Hoare triple {14130#false} assume !(#t~mem38 == 8513);havoc #t~mem38;call #t~mem39 := read~int(~s.base, ~s.offset + 52, 4); {14130#false} is VALID [2018-11-14 19:06:35,177 INFO L273 TraceCheckUtils]: 65: Hoare triple {14130#false} assume !(#t~mem39 == 8528);havoc #t~mem39;call #t~mem40 := read~int(~s.base, ~s.offset + 52, 4); {14130#false} is VALID [2018-11-14 19:06:35,177 INFO L273 TraceCheckUtils]: 66: Hoare triple {14130#false} assume !(#t~mem40 == 8529);havoc #t~mem40;call #t~mem41 := read~int(~s.base, ~s.offset + 52, 4); {14130#false} is VALID [2018-11-14 19:06:35,177 INFO L273 TraceCheckUtils]: 67: Hoare triple {14130#false} assume !(#t~mem41 == 8544);havoc #t~mem41;call #t~mem42 := read~int(~s.base, ~s.offset + 52, 4); {14130#false} is VALID [2018-11-14 19:06:35,177 INFO L273 TraceCheckUtils]: 68: Hoare triple {14130#false} assume !(#t~mem42 == 8545);havoc #t~mem42;call #t~mem43 := read~int(~s.base, ~s.offset + 52, 4); {14130#false} is VALID [2018-11-14 19:06:35,178 INFO L273 TraceCheckUtils]: 69: Hoare triple {14130#false} assume !(#t~mem43 == 8560);havoc #t~mem43;call #t~mem44 := read~int(~s.base, ~s.offset + 52, 4); {14130#false} is VALID [2018-11-14 19:06:35,178 INFO L273 TraceCheckUtils]: 70: Hoare triple {14130#false} assume !(#t~mem44 == 8561);havoc #t~mem44;call #t~mem45 := read~int(~s.base, ~s.offset + 52, 4); {14130#false} is VALID [2018-11-14 19:06:35,178 INFO L273 TraceCheckUtils]: 71: Hoare triple {14130#false} assume !(#t~mem45 == 8448);havoc #t~mem45;call #t~mem46 := read~int(~s.base, ~s.offset + 52, 4); {14130#false} is VALID [2018-11-14 19:06:35,178 INFO L273 TraceCheckUtils]: 72: Hoare triple {14130#false} assume !(#t~mem46 == 8576);havoc #t~mem46;call #t~mem47 := read~int(~s.base, ~s.offset + 52, 4); {14130#false} is VALID [2018-11-14 19:06:35,178 INFO L273 TraceCheckUtils]: 73: Hoare triple {14130#false} assume !(#t~mem47 == 8577);havoc #t~mem47;call #t~mem48 := read~int(~s.base, ~s.offset + 52, 4); {14130#false} is VALID [2018-11-14 19:06:35,178 INFO L273 TraceCheckUtils]: 74: Hoare triple {14130#false} assume !(#t~mem48 == 8592);havoc #t~mem48;call #t~mem49 := read~int(~s.base, ~s.offset + 52, 4); {14130#false} is VALID [2018-11-14 19:06:35,178 INFO L273 TraceCheckUtils]: 75: Hoare triple {14130#false} assume !(#t~mem49 == 8593);havoc #t~mem49;call #t~mem50 := read~int(~s.base, ~s.offset + 52, 4); {14130#false} is VALID [2018-11-14 19:06:35,178 INFO L273 TraceCheckUtils]: 76: Hoare triple {14130#false} assume !(#t~mem50 == 8608);havoc #t~mem50;call #t~mem51 := read~int(~s.base, ~s.offset + 52, 4); {14130#false} is VALID [2018-11-14 19:06:35,178 INFO L273 TraceCheckUtils]: 77: Hoare triple {14130#false} assume !(#t~mem51 == 8609);havoc #t~mem51;call #t~mem52 := read~int(~s.base, ~s.offset + 52, 4); {14130#false} is VALID [2018-11-14 19:06:35,179 INFO L273 TraceCheckUtils]: 78: Hoare triple {14130#false} assume !(#t~mem52 == 8640);havoc #t~mem52;call #t~mem53 := read~int(~s.base, ~s.offset + 52, 4); {14130#false} is VALID [2018-11-14 19:06:35,179 INFO L273 TraceCheckUtils]: 79: Hoare triple {14130#false} assume !(#t~mem53 == 8641);havoc #t~mem53;call #t~mem54 := read~int(~s.base, ~s.offset + 52, 4); {14130#false} is VALID [2018-11-14 19:06:35,179 INFO L273 TraceCheckUtils]: 80: Hoare triple {14130#false} assume !(#t~mem54 == 8656);havoc #t~mem54;call #t~mem55 := read~int(~s.base, ~s.offset + 52, 4); {14130#false} is VALID [2018-11-14 19:06:35,179 INFO L273 TraceCheckUtils]: 81: Hoare triple {14130#false} assume !(#t~mem55 == 8657);havoc #t~mem55;call #t~mem56 := read~int(~s.base, ~s.offset + 52, 4); {14130#false} is VALID [2018-11-14 19:06:35,179 INFO L273 TraceCheckUtils]: 82: Hoare triple {14130#false} assume #t~mem56 == 8672;havoc #t~mem56; {14130#false} is VALID [2018-11-14 19:06:35,179 INFO L273 TraceCheckUtils]: 83: Hoare triple {14130#false} assume -2147483648 <= #t~nondet121 && #t~nondet121 <= 2147483647;~ret~0 := #t~nondet121;havoc #t~nondet121; {14130#false} is VALID [2018-11-14 19:06:35,179 INFO L273 TraceCheckUtils]: 84: Hoare triple {14130#false} assume ~blastFlag~0 == 4; {14130#false} is VALID [2018-11-14 19:06:35,179 INFO L273 TraceCheckUtils]: 85: Hoare triple {14130#false} assume !false; {14130#false} is VALID [2018-11-14 19:06:35,183 INFO L134 CoverageAnalysis]: Checked inductivity of 25 backedges. 25 proven. 0 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2018-11-14 19:06:35,183 INFO L312 seRefinementStrategy]: Constructing automaton from 1 perfect and 0 imperfect interpolant sequences. [2018-11-14 19:06:35,183 INFO L327 seRefinementStrategy]: Number of different interpolants: perfect sequences [4] imperfect sequences [] total 4 [2018-11-14 19:06:35,184 INFO L78 Accepts]: Start accepts. Automaton has 4 states. Word has length 86 [2018-11-14 19:06:35,184 INFO L84 Accepts]: Finished accepts. word is accepted. [2018-11-14 19:06:35,184 INFO L86 InductivityCheck]: Starting indutivity check of a Floyd-Hoare automaton with 4 states. [2018-11-14 19:06:35,270 INFO L119 InductivityCheck]: Floyd-Hoare automaton has 86 edges. 86 inductive. 0 not inductive. 0 times theorem prover too weak to decide inductivity. [2018-11-14 19:06:35,270 INFO L459 AbstractCegarLoop]: Interpolant automaton has 4 states [2018-11-14 19:06:35,270 INFO L142 InterpolantAutomaton]: Constructing interpolant automaton starting with 4 interpolants. [2018-11-14 19:06:35,270 INFO L144 InterpolantAutomaton]: CoverageRelationStatistics Valid=5, Invalid=7, Unknown=0, NotChecked=0, Total=12 [2018-11-14 19:06:35,271 INFO L87 Difference]: Start difference. First operand 198 states and 290 transitions. Second operand 4 states. [2018-11-14 19:06:36,817 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2018-11-14 19:06:36,817 INFO L93 Difference]: Finished difference Result 397 states and 586 transitions. [2018-11-14 19:06:36,817 INFO L142 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 4 states. [2018-11-14 19:06:36,817 INFO L78 Accepts]: Start accepts. Automaton has 4 states. Word has length 86 [2018-11-14 19:06:36,817 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2018-11-14 19:06:36,818 INFO L82 GeneralOperation]: Start removeUnreachable. Operand 4 states. [2018-11-14 19:06:36,819 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 4 states to 4 states and 451 transitions. [2018-11-14 19:06:36,820 INFO L82 GeneralOperation]: Start removeUnreachable. Operand 4 states. [2018-11-14 19:06:36,821 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 4 states to 4 states and 451 transitions. [2018-11-14 19:06:36,821 INFO L86 InductivityCheck]: Starting indutivity check of a Floyd-Hoare automaton with 4 states and 451 transitions. [2018-11-14 19:06:37,316 INFO L119 InductivityCheck]: Floyd-Hoare automaton has 451 edges. 451 inductive. 0 not inductive. 0 times theorem prover too weak to decide inductivity. [2018-11-14 19:06:37,321 INFO L225 Difference]: With dead ends: 397 [2018-11-14 19:06:37,321 INFO L226 Difference]: Without dead ends: 225 [2018-11-14 19:06:37,321 INFO L604 BasicCegarLoop]: 0 DeclaredPredicates, 6 GetRequests, 2 SyntacticMatches, 1 SemanticMatches, 3 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 0 ImplicationChecksByTransitivity, 0.1s TimeCoverageRelationStatistics Valid=9, Invalid=11, Unknown=0, NotChecked=0, Total=20 [2018-11-14 19:06:37,322 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 225 states. [2018-11-14 19:06:37,408 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 225 to 198. [2018-11-14 19:06:37,409 INFO L214 AbstractMinimizeNwa]: Start testing correctness of minimizeSevpa [2018-11-14 19:06:37,409 INFO L82 GeneralOperation]: Start isEquivalent. First operand 225 states. Second operand 198 states. [2018-11-14 19:06:37,409 INFO L74 IsIncluded]: Start isIncluded. First operand 225 states. Second operand 198 states. [2018-11-14 19:06:37,409 INFO L87 Difference]: Start difference. First operand 225 states. Second operand 198 states. [2018-11-14 19:06:37,412 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2018-11-14 19:06:37,413 INFO L93 Difference]: Finished difference Result 225 states and 324 transitions. [2018-11-14 19:06:37,413 INFO L276 IsEmpty]: Start isEmpty. Operand 225 states and 324 transitions. [2018-11-14 19:06:37,413 INFO L282 IsEmpty]: Finished isEmpty. No accepting run. [2018-11-14 19:06:37,413 INFO L83 IsIncluded]: Finished isIncluded. Language is included [2018-11-14 19:06:37,413 INFO L74 IsIncluded]: Start isIncluded. First operand 198 states. Second operand 225 states. [2018-11-14 19:06:37,413 INFO L87 Difference]: Start difference. First operand 198 states. Second operand 225 states. [2018-11-14 19:06:37,417 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2018-11-14 19:06:37,417 INFO L93 Difference]: Finished difference Result 225 states and 324 transitions. [2018-11-14 19:06:37,417 INFO L276 IsEmpty]: Start isEmpty. Operand 225 states and 324 transitions. [2018-11-14 19:06:37,417 INFO L282 IsEmpty]: Finished isEmpty. No accepting run. [2018-11-14 19:06:37,418 INFO L83 IsIncluded]: Finished isIncluded. Language is included [2018-11-14 19:06:37,418 INFO L88 GeneralOperation]: Finished isEquivalent. [2018-11-14 19:06:37,418 INFO L221 AbstractMinimizeNwa]: Finished testing correctness of minimizeSevpa [2018-11-14 19:06:37,418 INFO L82 GeneralOperation]: Start removeUnreachable. Operand 198 states. [2018-11-14 19:06:37,421 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 198 states to 198 states and 289 transitions. [2018-11-14 19:06:37,421 INFO L78 Accepts]: Start accepts. Automaton has 198 states and 289 transitions. Word has length 86 [2018-11-14 19:06:37,421 INFO L84 Accepts]: Finished accepts. word is rejected. [2018-11-14 19:06:37,421 INFO L480 AbstractCegarLoop]: Abstraction has 198 states and 289 transitions. [2018-11-14 19:06:37,421 INFO L481 AbstractCegarLoop]: Interpolant automaton has 4 states. [2018-11-14 19:06:37,421 INFO L276 IsEmpty]: Start isEmpty. Operand 198 states and 289 transitions. [2018-11-14 19:06:37,422 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 88 [2018-11-14 19:06:37,422 INFO L367 BasicCegarLoop]: Found error trace [2018-11-14 19:06:37,422 INFO L375 BasicCegarLoop]: trace histogram [3, 3, 3, 3, 3, 2, 2, 2, 2, 2, 2, 2, 2, 2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2018-11-14 19:06:37,422 INFO L423 AbstractCegarLoop]: === Iteration 17 === [ssl3_acceptErr0ASSERT_VIOLATIONERROR_FUNCTION]=== [2018-11-14 19:06:37,423 INFO L141 PredicateUnifier]: Initialized classic predicate unifier [2018-11-14 19:06:37,423 INFO L82 PathProgramCache]: Analyzing trace with hash -610300072, now seen corresponding path program 1 times [2018-11-14 19:06:37,423 INFO L223 ckRefinementStrategy]: Switched to mode SMTINTERPOL_TREE_INTERPOLANTS [2018-11-14 19:06:37,423 INFO L69 tionRefinementEngine]: Using refinement strategy CamelRefinementStrategy [2018-11-14 19:06:37,424 INFO L119 rtionOrderModulation]: Craig_TreeInterpolation forces the order to NOT_INCREMENTALLY [2018-11-14 19:06:37,424 INFO L103 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2018-11-14 19:06:37,424 INFO L119 rtionOrderModulation]: Craig_TreeInterpolation forces the order to NOT_INCREMENTALLY [2018-11-14 19:06:37,439 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2018-11-14 19:06:37,885 INFO L256 TraceCheckUtils]: 0: Hoare triple {15285#true} call ULTIMATE.init(); {15285#true} is VALID [2018-11-14 19:06:37,886 INFO L273 TraceCheckUtils]: 1: Hoare triple {15285#true} #NULL.base, #NULL.offset := 0, 0;#valid := #valid[0 := 0];~init~0 := 1;call ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset := #Ultimate.alloc(100);call write~unchecked~int(0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 0, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 4, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 8, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 12, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 16, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 20, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 24, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 28, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 32, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 36, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 40, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 44, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 48, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 52, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 56, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 60, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 64, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 68, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 72, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 76, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 80, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 84, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 88, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 92, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 96, 4);call write~unchecked~int(0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 0, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 4, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 8, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 12, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 16, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 20, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 24, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 28, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 32, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 36, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 40, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 44, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 48, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 52, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 56, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 60, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 64, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 68, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 72, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 76, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 80, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 84, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 88, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 92, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 96, 4); {15285#true} is VALID [2018-11-14 19:06:37,886 INFO L273 TraceCheckUtils]: 2: Hoare triple {15285#true} assume true; {15285#true} is VALID [2018-11-14 19:06:37,886 INFO L268 TraceCheckUtils]: 3: Hoare quadruple {15285#true} {15285#true} #654#return; {15285#true} is VALID [2018-11-14 19:06:37,886 INFO L256 TraceCheckUtils]: 4: Hoare triple {15285#true} call #t~ret138 := main(); {15285#true} is VALID [2018-11-14 19:06:37,887 INFO L273 TraceCheckUtils]: 5: Hoare triple {15285#true} havoc ~s~0.base, ~s~0.offset;havoc ~tmp~2;call #t~malloc3.base, #t~malloc3.offset := #Ultimate.alloc(248);~s~0.base, ~s~0.offset := #t~malloc3.base, #t~malloc3.offset;call #t~malloc4.base, #t~malloc4.offset := #Ultimate.alloc(899);call write~$Pointer$(#t~malloc4.base, #t~malloc4.offset, ~s~0.base, ~s~0.offset + 84, 4);call #t~malloc5.base, #t~malloc5.offset := #Ultimate.alloc(232);call write~$Pointer$(#t~malloc5.base, #t~malloc5.offset, ~s~0.base, ~s~0.offset + 204, 4);call #t~malloc6.base, #t~malloc6.offset := #Ultimate.alloc(200);call write~$Pointer$(#t~malloc6.base, #t~malloc6.offset, ~s~0.base, ~s~0.offset + 176, 4);call write~int(8464, ~s~0.base, ~s~0.offset + 52, 4); {15285#true} is VALID [2018-11-14 19:06:37,887 INFO L256 TraceCheckUtils]: 6: Hoare triple {15285#true} call #t~ret7 := ssl3_accept(~s~0.base, ~s~0.offset); {15285#true} is VALID [2018-11-14 19:06:37,887 INFO L273 TraceCheckUtils]: 7: Hoare triple {15285#true} ~s.base, ~s.offset := #in~s.base, #in~s.offset;havoc ~buf~0.base, ~buf~0.offset;havoc ~l~0;havoc ~Time~0;havoc ~tmp~3;havoc ~cb~0.base, ~cb~0.offset;havoc ~num1~0;havoc ~ret~0;havoc ~new_state~0;havoc ~state~0;havoc ~skip~0;havoc ~got_new_session~0;assume -2147483648 <= #t~nondet8 && #t~nondet8 <= 2147483647;~tmp___1~0 := #t~nondet8;havoc #t~nondet8;assume -2147483648 <= #t~nondet9 && #t~nondet9 <= 2147483647;~tmp___2~0 := #t~nondet9;havoc #t~nondet9;assume -2147483648 <= #t~nondet10 && #t~nondet10 <= 2147483647;~tmp___3~0 := #t~nondet10;havoc #t~nondet10;assume -2147483648 <= #t~nondet11 && #t~nondet11 <= 2147483647;~tmp___4~0 := #t~nondet11;havoc #t~nondet11;assume -2147483648 <= #t~nondet12 && #t~nondet12 <= 2147483647;~tmp___5~0 := #t~nondet12;havoc #t~nondet12;assume -2147483648 <= #t~nondet13 && #t~nondet13 <= 2147483647;~tmp___6~0 := #t~nondet13;havoc #t~nondet13;havoc ~tmp___7~0;assume -2147483648 <= #t~nondet14 && #t~nondet14 <= 2147483647;~tmp___8~0 := #t~nondet14;havoc #t~nondet14;assume -2147483648 <= #t~nondet15 && #t~nondet15 <= 2147483647;~tmp___9~0 := #t~nondet15;havoc #t~nondet15;assume -2147483648 <= #t~nondet16 && #t~nondet16 <= 2147483647;~tmp___10~0 := #t~nondet16;havoc #t~nondet16;havoc ~blastFlag~0;~blastFlag~0 := 0;assume -2147483648 <= #t~nondet17 && #t~nondet17 <= 2147483647;call write~int(#t~nondet17, ~s.base, ~s.offset + 92, 4);havoc #t~nondet17;call write~int(8464, ~s.base, ~s.offset + 52, 4);assume -2147483648 <= #t~nondet18 && #t~nondet18 <= 2147483647;~tmp~3 := #t~nondet18;havoc #t~nondet18;~Time~0 := ~tmp~3;~cb~0.base, ~cb~0.offset := 0, 0;~ret~0 := -1;~skip~0 := 0;~got_new_session~0 := 0;call #t~mem19.base, #t~mem19.offset := read~$Pointer$(~s.base, ~s.offset + 192, 4); {15285#true} is VALID [2018-11-14 19:06:37,887 INFO L273 TraceCheckUtils]: 8: Hoare triple {15285#true} assume (#t~mem19.base + #t~mem19.offset) % 4294967296 != 0;havoc #t~mem19.base, #t~mem19.offset;call #t~mem20.base, #t~mem20.offset := read~$Pointer$(~s.base, ~s.offset + 192, 4);~cb~0.base, ~cb~0.offset := #t~mem20.base, #t~mem20.offset;havoc #t~mem20.base, #t~mem20.offset; {15285#true} is VALID [2018-11-14 19:06:37,887 INFO L273 TraceCheckUtils]: 9: Hoare triple {15285#true} call #t~mem21 := read~int(~s.base, ~s.offset + 28, 4);call write~int(#t~mem21 + 1, ~s.base, ~s.offset + 28, 4);havoc #t~mem21; {15285#true} is VALID [2018-11-14 19:06:37,888 INFO L273 TraceCheckUtils]: 10: Hoare triple {15285#true} assume !(~bitwiseAnd(~tmp___1~0, 12288) != 0); {15285#true} is VALID [2018-11-14 19:06:37,888 INFO L273 TraceCheckUtils]: 11: Hoare triple {15285#true} call #t~mem22.base, #t~mem22.offset := read~$Pointer$(~s.base, ~s.offset + 136, 4); {15285#true} is VALID [2018-11-14 19:06:37,888 INFO L273 TraceCheckUtils]: 12: Hoare triple {15285#true} assume !((#t~mem22.base + #t~mem22.offset) % 4294967296 == 0);havoc #t~mem22.base, #t~mem22.offset; {15285#true} is VALID [2018-11-14 19:06:37,888 INFO L273 TraceCheckUtils]: 13: Hoare triple {15285#true} assume true; {15285#true} is VALID [2018-11-14 19:06:37,888 INFO L273 TraceCheckUtils]: 14: Hoare triple {15285#true} assume !false; {15285#true} is VALID [2018-11-14 19:06:37,889 INFO L273 TraceCheckUtils]: 15: Hoare triple {15285#true} call #t~mem23 := read~int(~s.base, ~s.offset + 52, 4);~state~0 := #t~mem23;havoc #t~mem23;call #t~mem24 := read~int(~s.base, ~s.offset + 52, 4); {15285#true} is VALID [2018-11-14 19:06:37,889 INFO L273 TraceCheckUtils]: 16: Hoare triple {15285#true} assume !(#t~mem24 == 12292);havoc #t~mem24;call #t~mem25 := read~int(~s.base, ~s.offset + 52, 4); {15285#true} is VALID [2018-11-14 19:06:37,889 INFO L273 TraceCheckUtils]: 17: Hoare triple {15285#true} assume !(#t~mem25 == 16384);havoc #t~mem25;call #t~mem26 := read~int(~s.base, ~s.offset + 52, 4); {15285#true} is VALID [2018-11-14 19:06:37,889 INFO L273 TraceCheckUtils]: 18: Hoare triple {15285#true} assume !(#t~mem26 == 8192);havoc #t~mem26;call #t~mem27 := read~int(~s.base, ~s.offset + 52, 4); {15285#true} is VALID [2018-11-14 19:06:37,889 INFO L273 TraceCheckUtils]: 19: Hoare triple {15285#true} assume !(#t~mem27 == 24576);havoc #t~mem27;call #t~mem28 := read~int(~s.base, ~s.offset + 52, 4); {15285#true} is VALID [2018-11-14 19:06:37,890 INFO L273 TraceCheckUtils]: 20: Hoare triple {15285#true} assume !(#t~mem28 == 8195);havoc #t~mem28;call #t~mem29 := read~int(~s.base, ~s.offset + 52, 4); {15285#true} is VALID [2018-11-14 19:06:37,890 INFO L273 TraceCheckUtils]: 21: Hoare triple {15285#true} assume !(#t~mem29 == 8480);havoc #t~mem29;call #t~mem30 := read~int(~s.base, ~s.offset + 52, 4); {15285#true} is VALID [2018-11-14 19:06:37,890 INFO L273 TraceCheckUtils]: 22: Hoare triple {15285#true} assume !(#t~mem30 == 8481);havoc #t~mem30;call #t~mem31 := read~int(~s.base, ~s.offset + 52, 4); {15285#true} is VALID [2018-11-14 19:06:37,890 INFO L273 TraceCheckUtils]: 23: Hoare triple {15285#true} assume !(#t~mem31 == 8482);havoc #t~mem31;call #t~mem32 := read~int(~s.base, ~s.offset + 52, 4); {15285#true} is VALID [2018-11-14 19:06:37,890 INFO L273 TraceCheckUtils]: 24: Hoare triple {15285#true} assume #t~mem32 == 8464;havoc #t~mem32; {15285#true} is VALID [2018-11-14 19:06:37,891 INFO L273 TraceCheckUtils]: 25: Hoare triple {15285#true} call write~int(0, ~s.base, ~s.offset + 48, 4);assume -2147483648 <= #t~nondet69 && #t~nondet69 <= 2147483647;~ret~0 := #t~nondet69;havoc #t~nondet69; {15285#true} is VALID [2018-11-14 19:06:37,891 INFO L273 TraceCheckUtils]: 26: Hoare triple {15285#true} assume ~blastFlag~0 == 0;~blastFlag~0 := 1; {15285#true} is VALID [2018-11-14 19:06:37,892 INFO L273 TraceCheckUtils]: 27: Hoare triple {15285#true} assume !(~ret~0 <= 0);~got_new_session~0 := 1;call write~int(8496, ~s.base, ~s.offset + 52, 4);call write~int(0, ~s.base, ~s.offset + 64, 4); {15287#(= (select (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 52)) 8496)} is VALID [2018-11-14 19:06:37,892 INFO L273 TraceCheckUtils]: 28: Hoare triple {15287#(= (select (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 52)) 8496)} call #t~mem127.base, #t~mem127.offset := read~$Pointer$(~s.base, ~s.offset + 84, 4);call #t~mem128 := read~int(#t~mem127.base, #t~mem127.offset + 604 + 244, 4); {15287#(= (select (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 52)) 8496)} is VALID [2018-11-14 19:06:37,892 INFO L273 TraceCheckUtils]: 29: Hoare triple {15287#(= (select (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 52)) 8496)} assume !(#t~mem128 == 0);havoc #t~mem127.base, #t~mem127.offset;havoc #t~mem128; {15287#(= (select (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 52)) 8496)} is VALID [2018-11-14 19:06:37,893 INFO L273 TraceCheckUtils]: 30: Hoare triple {15287#(= (select (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 52)) 8496)} ~skip~0 := 0; {15287#(= (select (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 52)) 8496)} is VALID [2018-11-14 19:06:37,893 INFO L273 TraceCheckUtils]: 31: Hoare triple {15287#(= (select (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 52)) 8496)} assume true; {15287#(= (select (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 52)) 8496)} is VALID [2018-11-14 19:06:37,894 INFO L273 TraceCheckUtils]: 32: Hoare triple {15287#(= (select (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 52)) 8496)} assume !false; {15287#(= (select (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 52)) 8496)} is VALID [2018-11-14 19:06:37,894 INFO L273 TraceCheckUtils]: 33: Hoare triple {15287#(= (select (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 52)) 8496)} call #t~mem23 := read~int(~s.base, ~s.offset + 52, 4);~state~0 := #t~mem23;havoc #t~mem23;call #t~mem24 := read~int(~s.base, ~s.offset + 52, 4); {15287#(= (select (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 52)) 8496)} is VALID [2018-11-14 19:06:37,895 INFO L273 TraceCheckUtils]: 34: Hoare triple {15287#(= (select (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 52)) 8496)} assume !(#t~mem24 == 12292);havoc #t~mem24;call #t~mem25 := read~int(~s.base, ~s.offset + 52, 4); {15287#(= (select (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 52)) 8496)} is VALID [2018-11-14 19:06:37,896 INFO L273 TraceCheckUtils]: 35: Hoare triple {15287#(= (select (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 52)) 8496)} assume !(#t~mem25 == 16384);havoc #t~mem25;call #t~mem26 := read~int(~s.base, ~s.offset + 52, 4); {15288#(= |ssl3_accept_#t~mem26| 8496)} is VALID [2018-11-14 19:06:37,896 INFO L273 TraceCheckUtils]: 36: Hoare triple {15288#(= |ssl3_accept_#t~mem26| 8496)} assume #t~mem26 == 8192;havoc #t~mem26; {15286#false} is VALID [2018-11-14 19:06:37,896 INFO L273 TraceCheckUtils]: 37: Hoare triple {15286#false} call write~int(1, ~s.base, ~s.offset + 36, 4); {15286#false} is VALID [2018-11-14 19:06:37,897 INFO L273 TraceCheckUtils]: 38: Hoare triple {15286#false} assume (~cb~0.base + ~cb~0.offset) % 4294967296 != 0; {15286#false} is VALID [2018-11-14 19:06:37,897 INFO L273 TraceCheckUtils]: 39: Hoare triple {15286#false} call #t~mem59 := read~int(~s.base, ~s.offset + 0, 4); {15286#false} is VALID [2018-11-14 19:06:37,897 INFO L273 TraceCheckUtils]: 40: Hoare triple {15286#false} assume !(#t~mem59 / 256 != 3);havoc #t~mem59;call write~int(8192, ~s.base, ~s.offset + 4, 4);call #t~mem60.base, #t~mem60.offset := read~$Pointer$(~s.base, ~s.offset + 60, 4); {15286#false} is VALID [2018-11-14 19:06:37,897 INFO L273 TraceCheckUtils]: 41: Hoare triple {15286#false} assume !((#t~mem60.base + #t~mem60.offset) % 4294967296 == 0);havoc #t~mem60.base, #t~mem60.offset; {15286#false} is VALID [2018-11-14 19:06:37,897 INFO L273 TraceCheckUtils]: 42: Hoare triple {15286#false} assume !(~tmp___4~0 == 0);call write~int(0, ~s.base, ~s.offset + 64, 4);call #t~mem62 := read~int(~s.base, ~s.offset + 52, 4); {15286#false} is VALID [2018-11-14 19:06:37,897 INFO L273 TraceCheckUtils]: 43: Hoare triple {15286#false} assume #t~mem62 != 12292;havoc #t~mem62; {15286#false} is VALID [2018-11-14 19:06:37,898 INFO L273 TraceCheckUtils]: 44: Hoare triple {15286#false} assume !(~tmp___5~0 == 0);call write~int(8464, ~s.base, ~s.offset + 52, 4);call #t~mem63.base, #t~mem63.offset := read~$Pointer$(~s.base, ~s.offset + 204, 4);call #t~mem64 := read~int(#t~mem63.base, #t~mem63.offset + 60 + 12, 4);call write~int(#t~mem64 + 1, #t~mem63.base, #t~mem63.offset + 60 + 12, 4);havoc #t~mem64;havoc #t~mem63.base, #t~mem63.offset; {15286#false} is VALID [2018-11-14 19:06:37,898 INFO L273 TraceCheckUtils]: 45: Hoare triple {15286#false} call #t~mem127.base, #t~mem127.offset := read~$Pointer$(~s.base, ~s.offset + 84, 4);call #t~mem128 := read~int(#t~mem127.base, #t~mem127.offset + 604 + 244, 4); {15286#false} is VALID [2018-11-14 19:06:37,898 INFO L273 TraceCheckUtils]: 46: Hoare triple {15286#false} assume !(#t~mem128 == 0);havoc #t~mem127.base, #t~mem127.offset;havoc #t~mem128; {15286#false} is VALID [2018-11-14 19:06:37,898 INFO L273 TraceCheckUtils]: 47: Hoare triple {15286#false} ~skip~0 := 0; {15286#false} is VALID [2018-11-14 19:06:37,898 INFO L273 TraceCheckUtils]: 48: Hoare triple {15286#false} assume true; {15286#false} is VALID [2018-11-14 19:06:37,899 INFO L273 TraceCheckUtils]: 49: Hoare triple {15286#false} assume !false; {15286#false} is VALID [2018-11-14 19:06:37,899 INFO L273 TraceCheckUtils]: 50: Hoare triple {15286#false} call #t~mem23 := read~int(~s.base, ~s.offset + 52, 4);~state~0 := #t~mem23;havoc #t~mem23;call #t~mem24 := read~int(~s.base, ~s.offset + 52, 4); {15286#false} is VALID [2018-11-14 19:06:37,899 INFO L273 TraceCheckUtils]: 51: Hoare triple {15286#false} assume !(#t~mem24 == 12292);havoc #t~mem24;call #t~mem25 := read~int(~s.base, ~s.offset + 52, 4); {15286#false} is VALID [2018-11-14 19:06:37,899 INFO L273 TraceCheckUtils]: 52: Hoare triple {15286#false} assume !(#t~mem25 == 16384);havoc #t~mem25;call #t~mem26 := read~int(~s.base, ~s.offset + 52, 4); {15286#false} is VALID [2018-11-14 19:06:37,899 INFO L273 TraceCheckUtils]: 53: Hoare triple {15286#false} assume !(#t~mem26 == 8192);havoc #t~mem26;call #t~mem27 := read~int(~s.base, ~s.offset + 52, 4); {15286#false} is VALID [2018-11-14 19:06:37,900 INFO L273 TraceCheckUtils]: 54: Hoare triple {15286#false} assume !(#t~mem27 == 24576);havoc #t~mem27;call #t~mem28 := read~int(~s.base, ~s.offset + 52, 4); {15286#false} is VALID [2018-11-14 19:06:37,900 INFO L273 TraceCheckUtils]: 55: Hoare triple {15286#false} assume !(#t~mem28 == 8195);havoc #t~mem28;call #t~mem29 := read~int(~s.base, ~s.offset + 52, 4); {15286#false} is VALID [2018-11-14 19:06:37,900 INFO L273 TraceCheckUtils]: 56: Hoare triple {15286#false} assume !(#t~mem29 == 8480);havoc #t~mem29;call #t~mem30 := read~int(~s.base, ~s.offset + 52, 4); {15286#false} is VALID [2018-11-14 19:06:37,900 INFO L273 TraceCheckUtils]: 57: Hoare triple {15286#false} assume !(#t~mem30 == 8481);havoc #t~mem30;call #t~mem31 := read~int(~s.base, ~s.offset + 52, 4); {15286#false} is VALID [2018-11-14 19:06:37,900 INFO L273 TraceCheckUtils]: 58: Hoare triple {15286#false} assume !(#t~mem31 == 8482);havoc #t~mem31;call #t~mem32 := read~int(~s.base, ~s.offset + 52, 4); {15286#false} is VALID [2018-11-14 19:06:37,901 INFO L273 TraceCheckUtils]: 59: Hoare triple {15286#false} assume !(#t~mem32 == 8464);havoc #t~mem32;call #t~mem33 := read~int(~s.base, ~s.offset + 52, 4); {15286#false} is VALID [2018-11-14 19:06:37,901 INFO L273 TraceCheckUtils]: 60: Hoare triple {15286#false} assume !(#t~mem33 == 8465);havoc #t~mem33;call #t~mem34 := read~int(~s.base, ~s.offset + 52, 4); {15286#false} is VALID [2018-11-14 19:06:37,901 INFO L273 TraceCheckUtils]: 61: Hoare triple {15286#false} assume !(#t~mem34 == 8466);havoc #t~mem34;call #t~mem35 := read~int(~s.base, ~s.offset + 52, 4); {15286#false} is VALID [2018-11-14 19:06:37,901 INFO L273 TraceCheckUtils]: 62: Hoare triple {15286#false} assume !(#t~mem35 == 8496);havoc #t~mem35;call #t~mem36 := read~int(~s.base, ~s.offset + 52, 4); {15286#false} is VALID [2018-11-14 19:06:37,901 INFO L273 TraceCheckUtils]: 63: Hoare triple {15286#false} assume !(#t~mem36 == 8497);havoc #t~mem36;call #t~mem37 := read~int(~s.base, ~s.offset + 52, 4); {15286#false} is VALID [2018-11-14 19:06:37,901 INFO L273 TraceCheckUtils]: 64: Hoare triple {15286#false} assume !(#t~mem37 == 8512);havoc #t~mem37;call #t~mem38 := read~int(~s.base, ~s.offset + 52, 4); {15286#false} is VALID [2018-11-14 19:06:37,902 INFO L273 TraceCheckUtils]: 65: Hoare triple {15286#false} assume !(#t~mem38 == 8513);havoc #t~mem38;call #t~mem39 := read~int(~s.base, ~s.offset + 52, 4); {15286#false} is VALID [2018-11-14 19:06:37,902 INFO L273 TraceCheckUtils]: 66: Hoare triple {15286#false} assume !(#t~mem39 == 8528);havoc #t~mem39;call #t~mem40 := read~int(~s.base, ~s.offset + 52, 4); {15286#false} is VALID [2018-11-14 19:06:37,902 INFO L273 TraceCheckUtils]: 67: Hoare triple {15286#false} assume !(#t~mem40 == 8529);havoc #t~mem40;call #t~mem41 := read~int(~s.base, ~s.offset + 52, 4); {15286#false} is VALID [2018-11-14 19:06:37,902 INFO L273 TraceCheckUtils]: 68: Hoare triple {15286#false} assume !(#t~mem41 == 8544);havoc #t~mem41;call #t~mem42 := read~int(~s.base, ~s.offset + 52, 4); {15286#false} is VALID [2018-11-14 19:06:37,902 INFO L273 TraceCheckUtils]: 69: Hoare triple {15286#false} assume !(#t~mem42 == 8545);havoc #t~mem42;call #t~mem43 := read~int(~s.base, ~s.offset + 52, 4); {15286#false} is VALID [2018-11-14 19:06:37,902 INFO L273 TraceCheckUtils]: 70: Hoare triple {15286#false} assume !(#t~mem43 == 8560);havoc #t~mem43;call #t~mem44 := read~int(~s.base, ~s.offset + 52, 4); {15286#false} is VALID [2018-11-14 19:06:37,902 INFO L273 TraceCheckUtils]: 71: Hoare triple {15286#false} assume !(#t~mem44 == 8561);havoc #t~mem44;call #t~mem45 := read~int(~s.base, ~s.offset + 52, 4); {15286#false} is VALID [2018-11-14 19:06:37,902 INFO L273 TraceCheckUtils]: 72: Hoare triple {15286#false} assume !(#t~mem45 == 8448);havoc #t~mem45;call #t~mem46 := read~int(~s.base, ~s.offset + 52, 4); {15286#false} is VALID [2018-11-14 19:06:37,903 INFO L273 TraceCheckUtils]: 73: Hoare triple {15286#false} assume !(#t~mem46 == 8576);havoc #t~mem46;call #t~mem47 := read~int(~s.base, ~s.offset + 52, 4); {15286#false} is VALID [2018-11-14 19:06:37,903 INFO L273 TraceCheckUtils]: 74: Hoare triple {15286#false} assume !(#t~mem47 == 8577);havoc #t~mem47;call #t~mem48 := read~int(~s.base, ~s.offset + 52, 4); {15286#false} is VALID [2018-11-14 19:06:37,903 INFO L273 TraceCheckUtils]: 75: Hoare triple {15286#false} assume !(#t~mem48 == 8592);havoc #t~mem48;call #t~mem49 := read~int(~s.base, ~s.offset + 52, 4); {15286#false} is VALID [2018-11-14 19:06:37,903 INFO L273 TraceCheckUtils]: 76: Hoare triple {15286#false} assume !(#t~mem49 == 8593);havoc #t~mem49;call #t~mem50 := read~int(~s.base, ~s.offset + 52, 4); {15286#false} is VALID [2018-11-14 19:06:37,903 INFO L273 TraceCheckUtils]: 77: Hoare triple {15286#false} assume !(#t~mem50 == 8608);havoc #t~mem50;call #t~mem51 := read~int(~s.base, ~s.offset + 52, 4); {15286#false} is VALID [2018-11-14 19:06:37,903 INFO L273 TraceCheckUtils]: 78: Hoare triple {15286#false} assume !(#t~mem51 == 8609);havoc #t~mem51;call #t~mem52 := read~int(~s.base, ~s.offset + 52, 4); {15286#false} is VALID [2018-11-14 19:06:37,903 INFO L273 TraceCheckUtils]: 79: Hoare triple {15286#false} assume !(#t~mem52 == 8640);havoc #t~mem52;call #t~mem53 := read~int(~s.base, ~s.offset + 52, 4); {15286#false} is VALID [2018-11-14 19:06:37,903 INFO L273 TraceCheckUtils]: 80: Hoare triple {15286#false} assume !(#t~mem53 == 8641);havoc #t~mem53;call #t~mem54 := read~int(~s.base, ~s.offset + 52, 4); {15286#false} is VALID [2018-11-14 19:06:37,903 INFO L273 TraceCheckUtils]: 81: Hoare triple {15286#false} assume !(#t~mem54 == 8656);havoc #t~mem54;call #t~mem55 := read~int(~s.base, ~s.offset + 52, 4); {15286#false} is VALID [2018-11-14 19:06:37,904 INFO L273 TraceCheckUtils]: 82: Hoare triple {15286#false} assume !(#t~mem55 == 8657);havoc #t~mem55;call #t~mem56 := read~int(~s.base, ~s.offset + 52, 4); {15286#false} is VALID [2018-11-14 19:06:37,904 INFO L273 TraceCheckUtils]: 83: Hoare triple {15286#false} assume #t~mem56 == 8672;havoc #t~mem56; {15286#false} is VALID [2018-11-14 19:06:37,904 INFO L273 TraceCheckUtils]: 84: Hoare triple {15286#false} assume -2147483648 <= #t~nondet121 && #t~nondet121 <= 2147483647;~ret~0 := #t~nondet121;havoc #t~nondet121; {15286#false} is VALID [2018-11-14 19:06:37,904 INFO L273 TraceCheckUtils]: 85: Hoare triple {15286#false} assume ~blastFlag~0 == 4; {15286#false} is VALID [2018-11-14 19:06:37,904 INFO L273 TraceCheckUtils]: 86: Hoare triple {15286#false} assume !false; {15286#false} is VALID [2018-11-14 19:06:37,908 INFO L134 CoverageAnalysis]: Checked inductivity of 27 backedges. 27 proven. 0 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2018-11-14 19:06:37,908 INFO L312 seRefinementStrategy]: Constructing automaton from 1 perfect and 0 imperfect interpolant sequences. [2018-11-14 19:06:37,908 INFO L327 seRefinementStrategy]: Number of different interpolants: perfect sequences [4] imperfect sequences [] total 4 [2018-11-14 19:06:37,909 INFO L78 Accepts]: Start accepts. Automaton has 4 states. Word has length 87 [2018-11-14 19:06:37,909 INFO L84 Accepts]: Finished accepts. word is accepted. [2018-11-14 19:06:37,909 INFO L86 InductivityCheck]: Starting indutivity check of a Floyd-Hoare automaton with 4 states. [2018-11-14 19:06:37,988 INFO L119 InductivityCheck]: Floyd-Hoare automaton has 87 edges. 87 inductive. 0 not inductive. 0 times theorem prover too weak to decide inductivity. [2018-11-14 19:06:37,988 INFO L459 AbstractCegarLoop]: Interpolant automaton has 4 states [2018-11-14 19:06:37,989 INFO L142 InterpolantAutomaton]: Constructing interpolant automaton starting with 4 interpolants. [2018-11-14 19:06:37,989 INFO L144 InterpolantAutomaton]: CoverageRelationStatistics Valid=5, Invalid=7, Unknown=0, NotChecked=0, Total=12 [2018-11-14 19:06:37,989 INFO L87 Difference]: Start difference. First operand 198 states and 289 transitions. Second operand 4 states. [2018-11-14 19:06:39,604 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2018-11-14 19:06:39,604 INFO L93 Difference]: Finished difference Result 397 states and 584 transitions. [2018-11-14 19:06:39,604 INFO L142 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 4 states. [2018-11-14 19:06:39,604 INFO L78 Accepts]: Start accepts. Automaton has 4 states. Word has length 87 [2018-11-14 19:06:39,605 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2018-11-14 19:06:39,605 INFO L82 GeneralOperation]: Start removeUnreachable. Operand 4 states. [2018-11-14 19:06:39,607 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 4 states to 4 states and 450 transitions. [2018-11-14 19:06:39,607 INFO L82 GeneralOperation]: Start removeUnreachable. Operand 4 states. [2018-11-14 19:06:39,610 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 4 states to 4 states and 450 transitions. [2018-11-14 19:06:39,610 INFO L86 InductivityCheck]: Starting indutivity check of a Floyd-Hoare automaton with 4 states and 450 transitions. [2018-11-14 19:06:40,080 INFO L119 InductivityCheck]: Floyd-Hoare automaton has 450 edges. 450 inductive. 0 not inductive. 0 times theorem prover too weak to decide inductivity. [2018-11-14 19:06:40,085 INFO L225 Difference]: With dead ends: 397 [2018-11-14 19:06:40,085 INFO L226 Difference]: Without dead ends: 225 [2018-11-14 19:06:40,085 INFO L604 BasicCegarLoop]: 0 DeclaredPredicates, 6 GetRequests, 2 SyntacticMatches, 1 SemanticMatches, 3 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 0 ImplicationChecksByTransitivity, 0.2s TimeCoverageRelationStatistics Valid=9, Invalid=11, Unknown=0, NotChecked=0, Total=20 [2018-11-14 19:06:40,086 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 225 states. [2018-11-14 19:06:40,419 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 225 to 198. [2018-11-14 19:06:40,419 INFO L214 AbstractMinimizeNwa]: Start testing correctness of minimizeSevpa [2018-11-14 19:06:40,419 INFO L82 GeneralOperation]: Start isEquivalent. First operand 225 states. Second operand 198 states. [2018-11-14 19:06:40,420 INFO L74 IsIncluded]: Start isIncluded. First operand 225 states. Second operand 198 states. [2018-11-14 19:06:40,420 INFO L87 Difference]: Start difference. First operand 225 states. Second operand 198 states. [2018-11-14 19:06:40,424 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2018-11-14 19:06:40,424 INFO L93 Difference]: Finished difference Result 225 states and 323 transitions. [2018-11-14 19:06:40,424 INFO L276 IsEmpty]: Start isEmpty. Operand 225 states and 323 transitions. [2018-11-14 19:06:40,425 INFO L282 IsEmpty]: Finished isEmpty. No accepting run. [2018-11-14 19:06:40,425 INFO L83 IsIncluded]: Finished isIncluded. Language is included [2018-11-14 19:06:40,425 INFO L74 IsIncluded]: Start isIncluded. First operand 198 states. Second operand 225 states. [2018-11-14 19:06:40,425 INFO L87 Difference]: Start difference. First operand 198 states. Second operand 225 states. [2018-11-14 19:06:40,430 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2018-11-14 19:06:40,430 INFO L93 Difference]: Finished difference Result 225 states and 323 transitions. [2018-11-14 19:06:40,430 INFO L276 IsEmpty]: Start isEmpty. Operand 225 states and 323 transitions. [2018-11-14 19:06:40,431 INFO L282 IsEmpty]: Finished isEmpty. No accepting run. [2018-11-14 19:06:40,431 INFO L83 IsIncluded]: Finished isIncluded. Language is included [2018-11-14 19:06:40,431 INFO L88 GeneralOperation]: Finished isEquivalent. [2018-11-14 19:06:40,431 INFO L221 AbstractMinimizeNwa]: Finished testing correctness of minimizeSevpa [2018-11-14 19:06:40,431 INFO L82 GeneralOperation]: Start removeUnreachable. Operand 198 states. [2018-11-14 19:06:40,435 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 198 states to 198 states and 288 transitions. [2018-11-14 19:06:40,435 INFO L78 Accepts]: Start accepts. Automaton has 198 states and 288 transitions. Word has length 87 [2018-11-14 19:06:40,435 INFO L84 Accepts]: Finished accepts. word is rejected. [2018-11-14 19:06:40,435 INFO L480 AbstractCegarLoop]: Abstraction has 198 states and 288 transitions. [2018-11-14 19:06:40,435 INFO L481 AbstractCegarLoop]: Interpolant automaton has 4 states. [2018-11-14 19:06:40,435 INFO L276 IsEmpty]: Start isEmpty. Operand 198 states and 288 transitions. [2018-11-14 19:06:40,436 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 89 [2018-11-14 19:06:40,436 INFO L367 BasicCegarLoop]: Found error trace [2018-11-14 19:06:40,436 INFO L375 BasicCegarLoop]: trace histogram [3, 3, 3, 3, 3, 3, 2, 2, 2, 2, 2, 2, 2, 2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2018-11-14 19:06:40,437 INFO L423 AbstractCegarLoop]: === Iteration 18 === [ssl3_acceptErr0ASSERT_VIOLATIONERROR_FUNCTION]=== [2018-11-14 19:06:40,437 INFO L141 PredicateUnifier]: Initialized classic predicate unifier [2018-11-14 19:06:40,437 INFO L82 PathProgramCache]: Analyzing trace with hash 500332020, now seen corresponding path program 1 times [2018-11-14 19:06:40,437 INFO L223 ckRefinementStrategy]: Switched to mode SMTINTERPOL_TREE_INTERPOLANTS [2018-11-14 19:06:40,437 INFO L69 tionRefinementEngine]: Using refinement strategy CamelRefinementStrategy [2018-11-14 19:06:40,438 INFO L119 rtionOrderModulation]: Craig_TreeInterpolation forces the order to NOT_INCREMENTALLY [2018-11-14 19:06:40,438 INFO L103 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2018-11-14 19:06:40,438 INFO L119 rtionOrderModulation]: Craig_TreeInterpolation forces the order to NOT_INCREMENTALLY [2018-11-14 19:06:40,453 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2018-11-14 19:06:40,842 INFO L256 TraceCheckUtils]: 0: Hoare triple {16441#true} call ULTIMATE.init(); {16441#true} is VALID [2018-11-14 19:06:40,842 INFO L273 TraceCheckUtils]: 1: Hoare triple {16441#true} #NULL.base, #NULL.offset := 0, 0;#valid := #valid[0 := 0];~init~0 := 1;call ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset := #Ultimate.alloc(100);call write~unchecked~int(0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 0, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 4, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 8, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 12, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 16, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 20, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 24, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 28, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 32, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 36, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 40, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 44, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 48, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 52, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 56, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 60, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 64, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 68, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 72, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 76, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 80, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 84, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 88, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 92, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 96, 4);call write~unchecked~int(0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 0, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 4, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 8, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 12, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 16, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 20, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 24, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 28, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 32, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 36, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 40, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 44, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 48, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 52, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 56, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 60, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 64, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 68, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 72, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 76, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 80, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 84, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 88, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 92, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 96, 4); {16441#true} is VALID [2018-11-14 19:06:40,842 INFO L273 TraceCheckUtils]: 2: Hoare triple {16441#true} assume true; {16441#true} is VALID [2018-11-14 19:06:40,842 INFO L268 TraceCheckUtils]: 3: Hoare quadruple {16441#true} {16441#true} #654#return; {16441#true} is VALID [2018-11-14 19:06:40,842 INFO L256 TraceCheckUtils]: 4: Hoare triple {16441#true} call #t~ret138 := main(); {16441#true} is VALID [2018-11-14 19:06:40,843 INFO L273 TraceCheckUtils]: 5: Hoare triple {16441#true} havoc ~s~0.base, ~s~0.offset;havoc ~tmp~2;call #t~malloc3.base, #t~malloc3.offset := #Ultimate.alloc(248);~s~0.base, ~s~0.offset := #t~malloc3.base, #t~malloc3.offset;call #t~malloc4.base, #t~malloc4.offset := #Ultimate.alloc(899);call write~$Pointer$(#t~malloc4.base, #t~malloc4.offset, ~s~0.base, ~s~0.offset + 84, 4);call #t~malloc5.base, #t~malloc5.offset := #Ultimate.alloc(232);call write~$Pointer$(#t~malloc5.base, #t~malloc5.offset, ~s~0.base, ~s~0.offset + 204, 4);call #t~malloc6.base, #t~malloc6.offset := #Ultimate.alloc(200);call write~$Pointer$(#t~malloc6.base, #t~malloc6.offset, ~s~0.base, ~s~0.offset + 176, 4);call write~int(8464, ~s~0.base, ~s~0.offset + 52, 4); {16441#true} is VALID [2018-11-14 19:06:40,843 INFO L256 TraceCheckUtils]: 6: Hoare triple {16441#true} call #t~ret7 := ssl3_accept(~s~0.base, ~s~0.offset); {16441#true} is VALID [2018-11-14 19:06:40,843 INFO L273 TraceCheckUtils]: 7: Hoare triple {16441#true} ~s.base, ~s.offset := #in~s.base, #in~s.offset;havoc ~buf~0.base, ~buf~0.offset;havoc ~l~0;havoc ~Time~0;havoc ~tmp~3;havoc ~cb~0.base, ~cb~0.offset;havoc ~num1~0;havoc ~ret~0;havoc ~new_state~0;havoc ~state~0;havoc ~skip~0;havoc ~got_new_session~0;assume -2147483648 <= #t~nondet8 && #t~nondet8 <= 2147483647;~tmp___1~0 := #t~nondet8;havoc #t~nondet8;assume -2147483648 <= #t~nondet9 && #t~nondet9 <= 2147483647;~tmp___2~0 := #t~nondet9;havoc #t~nondet9;assume -2147483648 <= #t~nondet10 && #t~nondet10 <= 2147483647;~tmp___3~0 := #t~nondet10;havoc #t~nondet10;assume -2147483648 <= #t~nondet11 && #t~nondet11 <= 2147483647;~tmp___4~0 := #t~nondet11;havoc #t~nondet11;assume -2147483648 <= #t~nondet12 && #t~nondet12 <= 2147483647;~tmp___5~0 := #t~nondet12;havoc #t~nondet12;assume -2147483648 <= #t~nondet13 && #t~nondet13 <= 2147483647;~tmp___6~0 := #t~nondet13;havoc #t~nondet13;havoc ~tmp___7~0;assume -2147483648 <= #t~nondet14 && #t~nondet14 <= 2147483647;~tmp___8~0 := #t~nondet14;havoc #t~nondet14;assume -2147483648 <= #t~nondet15 && #t~nondet15 <= 2147483647;~tmp___9~0 := #t~nondet15;havoc #t~nondet15;assume -2147483648 <= #t~nondet16 && #t~nondet16 <= 2147483647;~tmp___10~0 := #t~nondet16;havoc #t~nondet16;havoc ~blastFlag~0;~blastFlag~0 := 0;assume -2147483648 <= #t~nondet17 && #t~nondet17 <= 2147483647;call write~int(#t~nondet17, ~s.base, ~s.offset + 92, 4);havoc #t~nondet17;call write~int(8464, ~s.base, ~s.offset + 52, 4);assume -2147483648 <= #t~nondet18 && #t~nondet18 <= 2147483647;~tmp~3 := #t~nondet18;havoc #t~nondet18;~Time~0 := ~tmp~3;~cb~0.base, ~cb~0.offset := 0, 0;~ret~0 := -1;~skip~0 := 0;~got_new_session~0 := 0;call #t~mem19.base, #t~mem19.offset := read~$Pointer$(~s.base, ~s.offset + 192, 4); {16441#true} is VALID [2018-11-14 19:06:40,843 INFO L273 TraceCheckUtils]: 8: Hoare triple {16441#true} assume (#t~mem19.base + #t~mem19.offset) % 4294967296 != 0;havoc #t~mem19.base, #t~mem19.offset;call #t~mem20.base, #t~mem20.offset := read~$Pointer$(~s.base, ~s.offset + 192, 4);~cb~0.base, ~cb~0.offset := #t~mem20.base, #t~mem20.offset;havoc #t~mem20.base, #t~mem20.offset; {16441#true} is VALID [2018-11-14 19:06:40,843 INFO L273 TraceCheckUtils]: 9: Hoare triple {16441#true} call #t~mem21 := read~int(~s.base, ~s.offset + 28, 4);call write~int(#t~mem21 + 1, ~s.base, ~s.offset + 28, 4);havoc #t~mem21; {16441#true} is VALID [2018-11-14 19:06:40,844 INFO L273 TraceCheckUtils]: 10: Hoare triple {16441#true} assume !(~bitwiseAnd(~tmp___1~0, 12288) != 0); {16441#true} is VALID [2018-11-14 19:06:40,844 INFO L273 TraceCheckUtils]: 11: Hoare triple {16441#true} call #t~mem22.base, #t~mem22.offset := read~$Pointer$(~s.base, ~s.offset + 136, 4); {16441#true} is VALID [2018-11-14 19:06:40,844 INFO L273 TraceCheckUtils]: 12: Hoare triple {16441#true} assume !((#t~mem22.base + #t~mem22.offset) % 4294967296 == 0);havoc #t~mem22.base, #t~mem22.offset; {16441#true} is VALID [2018-11-14 19:06:40,844 INFO L273 TraceCheckUtils]: 13: Hoare triple {16441#true} assume true; {16441#true} is VALID [2018-11-14 19:06:40,844 INFO L273 TraceCheckUtils]: 14: Hoare triple {16441#true} assume !false; {16441#true} is VALID [2018-11-14 19:06:40,845 INFO L273 TraceCheckUtils]: 15: Hoare triple {16441#true} call #t~mem23 := read~int(~s.base, ~s.offset + 52, 4);~state~0 := #t~mem23;havoc #t~mem23;call #t~mem24 := read~int(~s.base, ~s.offset + 52, 4); {16441#true} is VALID [2018-11-14 19:06:40,845 INFO L273 TraceCheckUtils]: 16: Hoare triple {16441#true} assume !(#t~mem24 == 12292);havoc #t~mem24;call #t~mem25 := read~int(~s.base, ~s.offset + 52, 4); {16441#true} is VALID [2018-11-14 19:06:40,845 INFO L273 TraceCheckUtils]: 17: Hoare triple {16441#true} assume !(#t~mem25 == 16384);havoc #t~mem25;call #t~mem26 := read~int(~s.base, ~s.offset + 52, 4); {16441#true} is VALID [2018-11-14 19:06:40,845 INFO L273 TraceCheckUtils]: 18: Hoare triple {16441#true} assume !(#t~mem26 == 8192);havoc #t~mem26;call #t~mem27 := read~int(~s.base, ~s.offset + 52, 4); {16441#true} is VALID [2018-11-14 19:06:40,845 INFO L273 TraceCheckUtils]: 19: Hoare triple {16441#true} assume !(#t~mem27 == 24576);havoc #t~mem27;call #t~mem28 := read~int(~s.base, ~s.offset + 52, 4); {16441#true} is VALID [2018-11-14 19:06:40,845 INFO L273 TraceCheckUtils]: 20: Hoare triple {16441#true} assume !(#t~mem28 == 8195);havoc #t~mem28;call #t~mem29 := read~int(~s.base, ~s.offset + 52, 4); {16441#true} is VALID [2018-11-14 19:06:40,846 INFO L273 TraceCheckUtils]: 21: Hoare triple {16441#true} assume !(#t~mem29 == 8480);havoc #t~mem29;call #t~mem30 := read~int(~s.base, ~s.offset + 52, 4); {16441#true} is VALID [2018-11-14 19:06:40,846 INFO L273 TraceCheckUtils]: 22: Hoare triple {16441#true} assume !(#t~mem30 == 8481);havoc #t~mem30;call #t~mem31 := read~int(~s.base, ~s.offset + 52, 4); {16441#true} is VALID [2018-11-14 19:06:40,846 INFO L273 TraceCheckUtils]: 23: Hoare triple {16441#true} assume !(#t~mem31 == 8482);havoc #t~mem31;call #t~mem32 := read~int(~s.base, ~s.offset + 52, 4); {16441#true} is VALID [2018-11-14 19:06:40,846 INFO L273 TraceCheckUtils]: 24: Hoare triple {16441#true} assume #t~mem32 == 8464;havoc #t~mem32; {16441#true} is VALID [2018-11-14 19:06:40,846 INFO L273 TraceCheckUtils]: 25: Hoare triple {16441#true} call write~int(0, ~s.base, ~s.offset + 48, 4);assume -2147483648 <= #t~nondet69 && #t~nondet69 <= 2147483647;~ret~0 := #t~nondet69;havoc #t~nondet69; {16441#true} is VALID [2018-11-14 19:06:40,846 INFO L273 TraceCheckUtils]: 26: Hoare triple {16441#true} assume ~blastFlag~0 == 0;~blastFlag~0 := 1; {16441#true} is VALID [2018-11-14 19:06:40,847 INFO L273 TraceCheckUtils]: 27: Hoare triple {16441#true} assume !(~ret~0 <= 0);~got_new_session~0 := 1;call write~int(8496, ~s.base, ~s.offset + 52, 4);call write~int(0, ~s.base, ~s.offset + 64, 4); {16443#(= (select (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 52)) 8496)} is VALID [2018-11-14 19:06:40,847 INFO L273 TraceCheckUtils]: 28: Hoare triple {16443#(= (select (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 52)) 8496)} call #t~mem127.base, #t~mem127.offset := read~$Pointer$(~s.base, ~s.offset + 84, 4);call #t~mem128 := read~int(#t~mem127.base, #t~mem127.offset + 604 + 244, 4); {16443#(= (select (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 52)) 8496)} is VALID [2018-11-14 19:06:40,848 INFO L273 TraceCheckUtils]: 29: Hoare triple {16443#(= (select (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 52)) 8496)} assume !(#t~mem128 == 0);havoc #t~mem127.base, #t~mem127.offset;havoc #t~mem128; {16443#(= (select (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 52)) 8496)} is VALID [2018-11-14 19:06:40,848 INFO L273 TraceCheckUtils]: 30: Hoare triple {16443#(= (select (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 52)) 8496)} ~skip~0 := 0; {16443#(= (select (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 52)) 8496)} is VALID [2018-11-14 19:06:40,848 INFO L273 TraceCheckUtils]: 31: Hoare triple {16443#(= (select (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 52)) 8496)} assume true; {16443#(= (select (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 52)) 8496)} is VALID [2018-11-14 19:06:40,849 INFO L273 TraceCheckUtils]: 32: Hoare triple {16443#(= (select (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 52)) 8496)} assume !false; {16443#(= (select (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 52)) 8496)} is VALID [2018-11-14 19:06:40,849 INFO L273 TraceCheckUtils]: 33: Hoare triple {16443#(= (select (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 52)) 8496)} call #t~mem23 := read~int(~s.base, ~s.offset + 52, 4);~state~0 := #t~mem23;havoc #t~mem23;call #t~mem24 := read~int(~s.base, ~s.offset + 52, 4); {16443#(= (select (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 52)) 8496)} is VALID [2018-11-14 19:06:40,849 INFO L273 TraceCheckUtils]: 34: Hoare triple {16443#(= (select (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 52)) 8496)} assume !(#t~mem24 == 12292);havoc #t~mem24;call #t~mem25 := read~int(~s.base, ~s.offset + 52, 4); {16443#(= (select (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 52)) 8496)} is VALID [2018-11-14 19:06:40,850 INFO L273 TraceCheckUtils]: 35: Hoare triple {16443#(= (select (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 52)) 8496)} assume !(#t~mem25 == 16384);havoc #t~mem25;call #t~mem26 := read~int(~s.base, ~s.offset + 52, 4); {16443#(= (select (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 52)) 8496)} is VALID [2018-11-14 19:06:40,850 INFO L273 TraceCheckUtils]: 36: Hoare triple {16443#(= (select (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 52)) 8496)} assume !(#t~mem26 == 8192);havoc #t~mem26;call #t~mem27 := read~int(~s.base, ~s.offset + 52, 4); {16444#(= |ssl3_accept_#t~mem27| 8496)} is VALID [2018-11-14 19:06:40,851 INFO L273 TraceCheckUtils]: 37: Hoare triple {16444#(= |ssl3_accept_#t~mem27| 8496)} assume #t~mem27 == 24576;havoc #t~mem27; {16442#false} is VALID [2018-11-14 19:06:40,851 INFO L273 TraceCheckUtils]: 38: Hoare triple {16442#false} call write~int(1, ~s.base, ~s.offset + 36, 4); {16442#false} is VALID [2018-11-14 19:06:40,851 INFO L273 TraceCheckUtils]: 39: Hoare triple {16442#false} assume (~cb~0.base + ~cb~0.offset) % 4294967296 != 0; {16442#false} is VALID [2018-11-14 19:06:40,851 INFO L273 TraceCheckUtils]: 40: Hoare triple {16442#false} call #t~mem59 := read~int(~s.base, ~s.offset + 0, 4); {16442#false} is VALID [2018-11-14 19:06:40,851 INFO L273 TraceCheckUtils]: 41: Hoare triple {16442#false} assume !(#t~mem59 / 256 != 3);havoc #t~mem59;call write~int(8192, ~s.base, ~s.offset + 4, 4);call #t~mem60.base, #t~mem60.offset := read~$Pointer$(~s.base, ~s.offset + 60, 4); {16442#false} is VALID [2018-11-14 19:06:40,852 INFO L273 TraceCheckUtils]: 42: Hoare triple {16442#false} assume !((#t~mem60.base + #t~mem60.offset) % 4294967296 == 0);havoc #t~mem60.base, #t~mem60.offset; {16442#false} is VALID [2018-11-14 19:06:40,852 INFO L273 TraceCheckUtils]: 43: Hoare triple {16442#false} assume !(~tmp___4~0 == 0);call write~int(0, ~s.base, ~s.offset + 64, 4);call #t~mem62 := read~int(~s.base, ~s.offset + 52, 4); {16442#false} is VALID [2018-11-14 19:06:40,852 INFO L273 TraceCheckUtils]: 44: Hoare triple {16442#false} assume #t~mem62 != 12292;havoc #t~mem62; {16442#false} is VALID [2018-11-14 19:06:40,852 INFO L273 TraceCheckUtils]: 45: Hoare triple {16442#false} assume !(~tmp___5~0 == 0);call write~int(8464, ~s.base, ~s.offset + 52, 4);call #t~mem63.base, #t~mem63.offset := read~$Pointer$(~s.base, ~s.offset + 204, 4);call #t~mem64 := read~int(#t~mem63.base, #t~mem63.offset + 60 + 12, 4);call write~int(#t~mem64 + 1, #t~mem63.base, #t~mem63.offset + 60 + 12, 4);havoc #t~mem64;havoc #t~mem63.base, #t~mem63.offset; {16442#false} is VALID [2018-11-14 19:06:40,852 INFO L273 TraceCheckUtils]: 46: Hoare triple {16442#false} call #t~mem127.base, #t~mem127.offset := read~$Pointer$(~s.base, ~s.offset + 84, 4);call #t~mem128 := read~int(#t~mem127.base, #t~mem127.offset + 604 + 244, 4); {16442#false} is VALID [2018-11-14 19:06:40,853 INFO L273 TraceCheckUtils]: 47: Hoare triple {16442#false} assume !(#t~mem128 == 0);havoc #t~mem127.base, #t~mem127.offset;havoc #t~mem128; {16442#false} is VALID [2018-11-14 19:06:40,853 INFO L273 TraceCheckUtils]: 48: Hoare triple {16442#false} ~skip~0 := 0; {16442#false} is VALID [2018-11-14 19:06:40,853 INFO L273 TraceCheckUtils]: 49: Hoare triple {16442#false} assume true; {16442#false} is VALID [2018-11-14 19:06:40,853 INFO L273 TraceCheckUtils]: 50: Hoare triple {16442#false} assume !false; {16442#false} is VALID [2018-11-14 19:06:40,853 INFO L273 TraceCheckUtils]: 51: Hoare triple {16442#false} call #t~mem23 := read~int(~s.base, ~s.offset + 52, 4);~state~0 := #t~mem23;havoc #t~mem23;call #t~mem24 := read~int(~s.base, ~s.offset + 52, 4); {16442#false} is VALID [2018-11-14 19:06:40,854 INFO L273 TraceCheckUtils]: 52: Hoare triple {16442#false} assume !(#t~mem24 == 12292);havoc #t~mem24;call #t~mem25 := read~int(~s.base, ~s.offset + 52, 4); {16442#false} is VALID [2018-11-14 19:06:40,854 INFO L273 TraceCheckUtils]: 53: Hoare triple {16442#false} assume !(#t~mem25 == 16384);havoc #t~mem25;call #t~mem26 := read~int(~s.base, ~s.offset + 52, 4); {16442#false} is VALID [2018-11-14 19:06:40,854 INFO L273 TraceCheckUtils]: 54: Hoare triple {16442#false} assume !(#t~mem26 == 8192);havoc #t~mem26;call #t~mem27 := read~int(~s.base, ~s.offset + 52, 4); {16442#false} is VALID [2018-11-14 19:06:40,854 INFO L273 TraceCheckUtils]: 55: Hoare triple {16442#false} assume !(#t~mem27 == 24576);havoc #t~mem27;call #t~mem28 := read~int(~s.base, ~s.offset + 52, 4); {16442#false} is VALID [2018-11-14 19:06:40,854 INFO L273 TraceCheckUtils]: 56: Hoare triple {16442#false} assume !(#t~mem28 == 8195);havoc #t~mem28;call #t~mem29 := read~int(~s.base, ~s.offset + 52, 4); {16442#false} is VALID [2018-11-14 19:06:40,854 INFO L273 TraceCheckUtils]: 57: Hoare triple {16442#false} assume !(#t~mem29 == 8480);havoc #t~mem29;call #t~mem30 := read~int(~s.base, ~s.offset + 52, 4); {16442#false} is VALID [2018-11-14 19:06:40,854 INFO L273 TraceCheckUtils]: 58: Hoare triple {16442#false} assume !(#t~mem30 == 8481);havoc #t~mem30;call #t~mem31 := read~int(~s.base, ~s.offset + 52, 4); {16442#false} is VALID [2018-11-14 19:06:40,855 INFO L273 TraceCheckUtils]: 59: Hoare triple {16442#false} assume !(#t~mem31 == 8482);havoc #t~mem31;call #t~mem32 := read~int(~s.base, ~s.offset + 52, 4); {16442#false} is VALID [2018-11-14 19:06:40,855 INFO L273 TraceCheckUtils]: 60: Hoare triple {16442#false} assume !(#t~mem32 == 8464);havoc #t~mem32;call #t~mem33 := read~int(~s.base, ~s.offset + 52, 4); {16442#false} is VALID [2018-11-14 19:06:40,855 INFO L273 TraceCheckUtils]: 61: Hoare triple {16442#false} assume !(#t~mem33 == 8465);havoc #t~mem33;call #t~mem34 := read~int(~s.base, ~s.offset + 52, 4); {16442#false} is VALID [2018-11-14 19:06:40,855 INFO L273 TraceCheckUtils]: 62: Hoare triple {16442#false} assume !(#t~mem34 == 8466);havoc #t~mem34;call #t~mem35 := read~int(~s.base, ~s.offset + 52, 4); {16442#false} is VALID [2018-11-14 19:06:40,855 INFO L273 TraceCheckUtils]: 63: Hoare triple {16442#false} assume !(#t~mem35 == 8496);havoc #t~mem35;call #t~mem36 := read~int(~s.base, ~s.offset + 52, 4); {16442#false} is VALID [2018-11-14 19:06:40,855 INFO L273 TraceCheckUtils]: 64: Hoare triple {16442#false} assume !(#t~mem36 == 8497);havoc #t~mem36;call #t~mem37 := read~int(~s.base, ~s.offset + 52, 4); {16442#false} is VALID [2018-11-14 19:06:40,855 INFO L273 TraceCheckUtils]: 65: Hoare triple {16442#false} assume !(#t~mem37 == 8512);havoc #t~mem37;call #t~mem38 := read~int(~s.base, ~s.offset + 52, 4); {16442#false} is VALID [2018-11-14 19:06:40,855 INFO L273 TraceCheckUtils]: 66: Hoare triple {16442#false} assume !(#t~mem38 == 8513);havoc #t~mem38;call #t~mem39 := read~int(~s.base, ~s.offset + 52, 4); {16442#false} is VALID [2018-11-14 19:06:40,856 INFO L273 TraceCheckUtils]: 67: Hoare triple {16442#false} assume !(#t~mem39 == 8528);havoc #t~mem39;call #t~mem40 := read~int(~s.base, ~s.offset + 52, 4); {16442#false} is VALID [2018-11-14 19:06:40,856 INFO L273 TraceCheckUtils]: 68: Hoare triple {16442#false} assume !(#t~mem40 == 8529);havoc #t~mem40;call #t~mem41 := read~int(~s.base, ~s.offset + 52, 4); {16442#false} is VALID [2018-11-14 19:06:40,856 INFO L273 TraceCheckUtils]: 69: Hoare triple {16442#false} assume !(#t~mem41 == 8544);havoc #t~mem41;call #t~mem42 := read~int(~s.base, ~s.offset + 52, 4); {16442#false} is VALID [2018-11-14 19:06:40,856 INFO L273 TraceCheckUtils]: 70: Hoare triple {16442#false} assume !(#t~mem42 == 8545);havoc #t~mem42;call #t~mem43 := read~int(~s.base, ~s.offset + 52, 4); {16442#false} is VALID [2018-11-14 19:06:40,856 INFO L273 TraceCheckUtils]: 71: Hoare triple {16442#false} assume !(#t~mem43 == 8560);havoc #t~mem43;call #t~mem44 := read~int(~s.base, ~s.offset + 52, 4); {16442#false} is VALID [2018-11-14 19:06:40,856 INFO L273 TraceCheckUtils]: 72: Hoare triple {16442#false} assume !(#t~mem44 == 8561);havoc #t~mem44;call #t~mem45 := read~int(~s.base, ~s.offset + 52, 4); {16442#false} is VALID [2018-11-14 19:06:40,856 INFO L273 TraceCheckUtils]: 73: Hoare triple {16442#false} assume !(#t~mem45 == 8448);havoc #t~mem45;call #t~mem46 := read~int(~s.base, ~s.offset + 52, 4); {16442#false} is VALID [2018-11-14 19:06:40,857 INFO L273 TraceCheckUtils]: 74: Hoare triple {16442#false} assume !(#t~mem46 == 8576);havoc #t~mem46;call #t~mem47 := read~int(~s.base, ~s.offset + 52, 4); {16442#false} is VALID [2018-11-14 19:06:40,857 INFO L273 TraceCheckUtils]: 75: Hoare triple {16442#false} assume !(#t~mem47 == 8577);havoc #t~mem47;call #t~mem48 := read~int(~s.base, ~s.offset + 52, 4); {16442#false} is VALID [2018-11-14 19:06:40,857 INFO L273 TraceCheckUtils]: 76: Hoare triple {16442#false} assume !(#t~mem48 == 8592);havoc #t~mem48;call #t~mem49 := read~int(~s.base, ~s.offset + 52, 4); {16442#false} is VALID [2018-11-14 19:06:40,857 INFO L273 TraceCheckUtils]: 77: Hoare triple {16442#false} assume !(#t~mem49 == 8593);havoc #t~mem49;call #t~mem50 := read~int(~s.base, ~s.offset + 52, 4); {16442#false} is VALID [2018-11-14 19:06:40,857 INFO L273 TraceCheckUtils]: 78: Hoare triple {16442#false} assume !(#t~mem50 == 8608);havoc #t~mem50;call #t~mem51 := read~int(~s.base, ~s.offset + 52, 4); {16442#false} is VALID [2018-11-14 19:06:40,857 INFO L273 TraceCheckUtils]: 79: Hoare triple {16442#false} assume !(#t~mem51 == 8609);havoc #t~mem51;call #t~mem52 := read~int(~s.base, ~s.offset + 52, 4); {16442#false} is VALID [2018-11-14 19:06:40,857 INFO L273 TraceCheckUtils]: 80: Hoare triple {16442#false} assume !(#t~mem52 == 8640);havoc #t~mem52;call #t~mem53 := read~int(~s.base, ~s.offset + 52, 4); {16442#false} is VALID [2018-11-14 19:06:40,857 INFO L273 TraceCheckUtils]: 81: Hoare triple {16442#false} assume !(#t~mem53 == 8641);havoc #t~mem53;call #t~mem54 := read~int(~s.base, ~s.offset + 52, 4); {16442#false} is VALID [2018-11-14 19:06:40,858 INFO L273 TraceCheckUtils]: 82: Hoare triple {16442#false} assume !(#t~mem54 == 8656);havoc #t~mem54;call #t~mem55 := read~int(~s.base, ~s.offset + 52, 4); {16442#false} is VALID [2018-11-14 19:06:40,858 INFO L273 TraceCheckUtils]: 83: Hoare triple {16442#false} assume !(#t~mem55 == 8657);havoc #t~mem55;call #t~mem56 := read~int(~s.base, ~s.offset + 52, 4); {16442#false} is VALID [2018-11-14 19:06:40,858 INFO L273 TraceCheckUtils]: 84: Hoare triple {16442#false} assume #t~mem56 == 8672;havoc #t~mem56; {16442#false} is VALID [2018-11-14 19:06:40,858 INFO L273 TraceCheckUtils]: 85: Hoare triple {16442#false} assume -2147483648 <= #t~nondet121 && #t~nondet121 <= 2147483647;~ret~0 := #t~nondet121;havoc #t~nondet121; {16442#false} is VALID [2018-11-14 19:06:40,858 INFO L273 TraceCheckUtils]: 86: Hoare triple {16442#false} assume ~blastFlag~0 == 4; {16442#false} is VALID [2018-11-14 19:06:40,858 INFO L273 TraceCheckUtils]: 87: Hoare triple {16442#false} assume !false; {16442#false} is VALID [2018-11-14 19:06:40,863 INFO L134 CoverageAnalysis]: Checked inductivity of 29 backedges. 29 proven. 0 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2018-11-14 19:06:40,864 INFO L312 seRefinementStrategy]: Constructing automaton from 1 perfect and 0 imperfect interpolant sequences. [2018-11-14 19:06:40,864 INFO L327 seRefinementStrategy]: Number of different interpolants: perfect sequences [4] imperfect sequences [] total 4 [2018-11-14 19:06:40,864 INFO L78 Accepts]: Start accepts. Automaton has 4 states. Word has length 88 [2018-11-14 19:06:40,864 INFO L84 Accepts]: Finished accepts. word is accepted. [2018-11-14 19:06:40,865 INFO L86 InductivityCheck]: Starting indutivity check of a Floyd-Hoare automaton with 4 states. [2018-11-14 19:06:40,980 INFO L119 InductivityCheck]: Floyd-Hoare automaton has 88 edges. 88 inductive. 0 not inductive. 0 times theorem prover too weak to decide inductivity. [2018-11-14 19:06:40,981 INFO L459 AbstractCegarLoop]: Interpolant automaton has 4 states [2018-11-14 19:06:40,981 INFO L142 InterpolantAutomaton]: Constructing interpolant automaton starting with 4 interpolants. [2018-11-14 19:06:40,981 INFO L144 InterpolantAutomaton]: CoverageRelationStatistics Valid=5, Invalid=7, Unknown=0, NotChecked=0, Total=12 [2018-11-14 19:06:40,982 INFO L87 Difference]: Start difference. First operand 198 states and 288 transitions. Second operand 4 states. [2018-11-14 19:06:42,918 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2018-11-14 19:06:42,918 INFO L93 Difference]: Finished difference Result 397 states and 582 transitions. [2018-11-14 19:06:42,919 INFO L142 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 4 states. [2018-11-14 19:06:42,919 INFO L78 Accepts]: Start accepts. Automaton has 4 states. Word has length 88 [2018-11-14 19:06:42,919 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2018-11-14 19:06:42,919 INFO L82 GeneralOperation]: Start removeUnreachable. Operand 4 states. [2018-11-14 19:06:42,921 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 4 states to 4 states and 449 transitions. [2018-11-14 19:06:42,921 INFO L82 GeneralOperation]: Start removeUnreachable. Operand 4 states. [2018-11-14 19:06:42,923 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 4 states to 4 states and 449 transitions. [2018-11-14 19:06:42,923 INFO L86 InductivityCheck]: Starting indutivity check of a Floyd-Hoare automaton with 4 states and 449 transitions. [2018-11-14 19:06:43,331 INFO L119 InductivityCheck]: Floyd-Hoare automaton has 449 edges. 449 inductive. 0 not inductive. 0 times theorem prover too weak to decide inductivity. [2018-11-14 19:06:43,336 INFO L225 Difference]: With dead ends: 397 [2018-11-14 19:06:43,336 INFO L226 Difference]: Without dead ends: 225 [2018-11-14 19:06:43,336 INFO L604 BasicCegarLoop]: 0 DeclaredPredicates, 6 GetRequests, 2 SyntacticMatches, 1 SemanticMatches, 3 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 0 ImplicationChecksByTransitivity, 0.2s TimeCoverageRelationStatistics Valid=9, Invalid=11, Unknown=0, NotChecked=0, Total=20 [2018-11-14 19:06:43,337 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 225 states. [2018-11-14 19:06:43,361 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 225 to 198. [2018-11-14 19:06:43,361 INFO L214 AbstractMinimizeNwa]: Start testing correctness of minimizeSevpa [2018-11-14 19:06:43,361 INFO L82 GeneralOperation]: Start isEquivalent. First operand 225 states. Second operand 198 states. [2018-11-14 19:06:43,361 INFO L74 IsIncluded]: Start isIncluded. First operand 225 states. Second operand 198 states. [2018-11-14 19:06:43,362 INFO L87 Difference]: Start difference. First operand 225 states. Second operand 198 states. [2018-11-14 19:06:43,366 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2018-11-14 19:06:43,366 INFO L93 Difference]: Finished difference Result 225 states and 322 transitions. [2018-11-14 19:06:43,366 INFO L276 IsEmpty]: Start isEmpty. Operand 225 states and 322 transitions. [2018-11-14 19:06:43,367 INFO L282 IsEmpty]: Finished isEmpty. No accepting run. [2018-11-14 19:06:43,367 INFO L83 IsIncluded]: Finished isIncluded. Language is included [2018-11-14 19:06:43,367 INFO L74 IsIncluded]: Start isIncluded. First operand 198 states. Second operand 225 states. [2018-11-14 19:06:43,367 INFO L87 Difference]: Start difference. First operand 198 states. Second operand 225 states. [2018-11-14 19:06:43,370 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2018-11-14 19:06:43,370 INFO L93 Difference]: Finished difference Result 225 states and 322 transitions. [2018-11-14 19:06:43,371 INFO L276 IsEmpty]: Start isEmpty. Operand 225 states and 322 transitions. [2018-11-14 19:06:43,371 INFO L282 IsEmpty]: Finished isEmpty. No accepting run. [2018-11-14 19:06:43,371 INFO L83 IsIncluded]: Finished isIncluded. Language is included [2018-11-14 19:06:43,371 INFO L88 GeneralOperation]: Finished isEquivalent. [2018-11-14 19:06:43,371 INFO L221 AbstractMinimizeNwa]: Finished testing correctness of minimizeSevpa [2018-11-14 19:06:43,371 INFO L82 GeneralOperation]: Start removeUnreachable. Operand 198 states. [2018-11-14 19:06:43,374 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 198 states to 198 states and 287 transitions. [2018-11-14 19:06:43,374 INFO L78 Accepts]: Start accepts. Automaton has 198 states and 287 transitions. Word has length 88 [2018-11-14 19:06:43,374 INFO L84 Accepts]: Finished accepts. word is rejected. [2018-11-14 19:06:43,374 INFO L480 AbstractCegarLoop]: Abstraction has 198 states and 287 transitions. [2018-11-14 19:06:43,374 INFO L481 AbstractCegarLoop]: Interpolant automaton has 4 states. [2018-11-14 19:06:43,374 INFO L276 IsEmpty]: Start isEmpty. Operand 198 states and 287 transitions. [2018-11-14 19:06:43,375 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 90 [2018-11-14 19:06:43,375 INFO L367 BasicCegarLoop]: Found error trace [2018-11-14 19:06:43,375 INFO L375 BasicCegarLoop]: trace histogram [3, 3, 3, 3, 3, 3, 3, 2, 2, 2, 2, 2, 2, 2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2018-11-14 19:06:43,376 INFO L423 AbstractCegarLoop]: === Iteration 19 === [ssl3_acceptErr0ASSERT_VIOLATIONERROR_FUNCTION]=== [2018-11-14 19:06:43,376 INFO L141 PredicateUnifier]: Initialized classic predicate unifier [2018-11-14 19:06:43,376 INFO L82 PathProgramCache]: Analyzing trace with hash 1941174173, now seen corresponding path program 1 times [2018-11-14 19:06:43,376 INFO L223 ckRefinementStrategy]: Switched to mode SMTINTERPOL_TREE_INTERPOLANTS [2018-11-14 19:06:43,376 INFO L69 tionRefinementEngine]: Using refinement strategy CamelRefinementStrategy [2018-11-14 19:06:43,377 INFO L119 rtionOrderModulation]: Craig_TreeInterpolation forces the order to NOT_INCREMENTALLY [2018-11-14 19:06:43,377 INFO L103 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2018-11-14 19:06:43,377 INFO L119 rtionOrderModulation]: Craig_TreeInterpolation forces the order to NOT_INCREMENTALLY [2018-11-14 19:06:43,391 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2018-11-14 19:06:44,003 INFO L256 TraceCheckUtils]: 0: Hoare triple {17597#true} call ULTIMATE.init(); {17597#true} is VALID [2018-11-14 19:06:44,003 INFO L273 TraceCheckUtils]: 1: Hoare triple {17597#true} #NULL.base, #NULL.offset := 0, 0;#valid := #valid[0 := 0];~init~0 := 1;call ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset := #Ultimate.alloc(100);call write~unchecked~int(0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 0, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 4, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 8, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 12, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 16, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 20, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 24, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 28, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 32, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 36, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 40, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 44, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 48, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 52, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 56, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 60, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 64, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 68, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 72, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 76, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 80, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 84, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 88, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 92, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 96, 4);call write~unchecked~int(0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 0, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 4, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 8, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 12, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 16, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 20, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 24, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 28, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 32, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 36, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 40, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 44, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 48, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 52, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 56, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 60, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 64, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 68, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 72, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 76, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 80, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 84, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 88, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 92, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 96, 4); {17597#true} is VALID [2018-11-14 19:06:44,004 INFO L273 TraceCheckUtils]: 2: Hoare triple {17597#true} assume true; {17597#true} is VALID [2018-11-14 19:06:44,004 INFO L268 TraceCheckUtils]: 3: Hoare quadruple {17597#true} {17597#true} #654#return; {17597#true} is VALID [2018-11-14 19:06:44,004 INFO L256 TraceCheckUtils]: 4: Hoare triple {17597#true} call #t~ret138 := main(); {17597#true} is VALID [2018-11-14 19:06:44,004 INFO L273 TraceCheckUtils]: 5: Hoare triple {17597#true} havoc ~s~0.base, ~s~0.offset;havoc ~tmp~2;call #t~malloc3.base, #t~malloc3.offset := #Ultimate.alloc(248);~s~0.base, ~s~0.offset := #t~malloc3.base, #t~malloc3.offset;call #t~malloc4.base, #t~malloc4.offset := #Ultimate.alloc(899);call write~$Pointer$(#t~malloc4.base, #t~malloc4.offset, ~s~0.base, ~s~0.offset + 84, 4);call #t~malloc5.base, #t~malloc5.offset := #Ultimate.alloc(232);call write~$Pointer$(#t~malloc5.base, #t~malloc5.offset, ~s~0.base, ~s~0.offset + 204, 4);call #t~malloc6.base, #t~malloc6.offset := #Ultimate.alloc(200);call write~$Pointer$(#t~malloc6.base, #t~malloc6.offset, ~s~0.base, ~s~0.offset + 176, 4);call write~int(8464, ~s~0.base, ~s~0.offset + 52, 4); {17597#true} is VALID [2018-11-14 19:06:44,004 INFO L256 TraceCheckUtils]: 6: Hoare triple {17597#true} call #t~ret7 := ssl3_accept(~s~0.base, ~s~0.offset); {17597#true} is VALID [2018-11-14 19:06:44,004 INFO L273 TraceCheckUtils]: 7: Hoare triple {17597#true} ~s.base, ~s.offset := #in~s.base, #in~s.offset;havoc ~buf~0.base, ~buf~0.offset;havoc ~l~0;havoc ~Time~0;havoc ~tmp~3;havoc ~cb~0.base, ~cb~0.offset;havoc ~num1~0;havoc ~ret~0;havoc ~new_state~0;havoc ~state~0;havoc ~skip~0;havoc ~got_new_session~0;assume -2147483648 <= #t~nondet8 && #t~nondet8 <= 2147483647;~tmp___1~0 := #t~nondet8;havoc #t~nondet8;assume -2147483648 <= #t~nondet9 && #t~nondet9 <= 2147483647;~tmp___2~0 := #t~nondet9;havoc #t~nondet9;assume -2147483648 <= #t~nondet10 && #t~nondet10 <= 2147483647;~tmp___3~0 := #t~nondet10;havoc #t~nondet10;assume -2147483648 <= #t~nondet11 && #t~nondet11 <= 2147483647;~tmp___4~0 := #t~nondet11;havoc #t~nondet11;assume -2147483648 <= #t~nondet12 && #t~nondet12 <= 2147483647;~tmp___5~0 := #t~nondet12;havoc #t~nondet12;assume -2147483648 <= #t~nondet13 && #t~nondet13 <= 2147483647;~tmp___6~0 := #t~nondet13;havoc #t~nondet13;havoc ~tmp___7~0;assume -2147483648 <= #t~nondet14 && #t~nondet14 <= 2147483647;~tmp___8~0 := #t~nondet14;havoc #t~nondet14;assume -2147483648 <= #t~nondet15 && #t~nondet15 <= 2147483647;~tmp___9~0 := #t~nondet15;havoc #t~nondet15;assume -2147483648 <= #t~nondet16 && #t~nondet16 <= 2147483647;~tmp___10~0 := #t~nondet16;havoc #t~nondet16;havoc ~blastFlag~0;~blastFlag~0 := 0;assume -2147483648 <= #t~nondet17 && #t~nondet17 <= 2147483647;call write~int(#t~nondet17, ~s.base, ~s.offset + 92, 4);havoc #t~nondet17;call write~int(8464, ~s.base, ~s.offset + 52, 4);assume -2147483648 <= #t~nondet18 && #t~nondet18 <= 2147483647;~tmp~3 := #t~nondet18;havoc #t~nondet18;~Time~0 := ~tmp~3;~cb~0.base, ~cb~0.offset := 0, 0;~ret~0 := -1;~skip~0 := 0;~got_new_session~0 := 0;call #t~mem19.base, #t~mem19.offset := read~$Pointer$(~s.base, ~s.offset + 192, 4); {17597#true} is VALID [2018-11-14 19:06:44,005 INFO L273 TraceCheckUtils]: 8: Hoare triple {17597#true} assume (#t~mem19.base + #t~mem19.offset) % 4294967296 != 0;havoc #t~mem19.base, #t~mem19.offset;call #t~mem20.base, #t~mem20.offset := read~$Pointer$(~s.base, ~s.offset + 192, 4);~cb~0.base, ~cb~0.offset := #t~mem20.base, #t~mem20.offset;havoc #t~mem20.base, #t~mem20.offset; {17597#true} is VALID [2018-11-14 19:06:44,005 INFO L273 TraceCheckUtils]: 9: Hoare triple {17597#true} call #t~mem21 := read~int(~s.base, ~s.offset + 28, 4);call write~int(#t~mem21 + 1, ~s.base, ~s.offset + 28, 4);havoc #t~mem21; {17597#true} is VALID [2018-11-14 19:06:44,005 INFO L273 TraceCheckUtils]: 10: Hoare triple {17597#true} assume !(~bitwiseAnd(~tmp___1~0, 12288) != 0); {17597#true} is VALID [2018-11-14 19:06:44,005 INFO L273 TraceCheckUtils]: 11: Hoare triple {17597#true} call #t~mem22.base, #t~mem22.offset := read~$Pointer$(~s.base, ~s.offset + 136, 4); {17597#true} is VALID [2018-11-14 19:06:44,005 INFO L273 TraceCheckUtils]: 12: Hoare triple {17597#true} assume !((#t~mem22.base + #t~mem22.offset) % 4294967296 == 0);havoc #t~mem22.base, #t~mem22.offset; {17597#true} is VALID [2018-11-14 19:06:44,006 INFO L273 TraceCheckUtils]: 13: Hoare triple {17597#true} assume true; {17597#true} is VALID [2018-11-14 19:06:44,006 INFO L273 TraceCheckUtils]: 14: Hoare triple {17597#true} assume !false; {17597#true} is VALID [2018-11-14 19:06:44,006 INFO L273 TraceCheckUtils]: 15: Hoare triple {17597#true} call #t~mem23 := read~int(~s.base, ~s.offset + 52, 4);~state~0 := #t~mem23;havoc #t~mem23;call #t~mem24 := read~int(~s.base, ~s.offset + 52, 4); {17597#true} is VALID [2018-11-14 19:06:44,006 INFO L273 TraceCheckUtils]: 16: Hoare triple {17597#true} assume !(#t~mem24 == 12292);havoc #t~mem24;call #t~mem25 := read~int(~s.base, ~s.offset + 52, 4); {17597#true} is VALID [2018-11-14 19:06:44,006 INFO L273 TraceCheckUtils]: 17: Hoare triple {17597#true} assume !(#t~mem25 == 16384);havoc #t~mem25;call #t~mem26 := read~int(~s.base, ~s.offset + 52, 4); {17597#true} is VALID [2018-11-14 19:06:44,007 INFO L273 TraceCheckUtils]: 18: Hoare triple {17597#true} assume !(#t~mem26 == 8192);havoc #t~mem26;call #t~mem27 := read~int(~s.base, ~s.offset + 52, 4); {17597#true} is VALID [2018-11-14 19:06:44,007 INFO L273 TraceCheckUtils]: 19: Hoare triple {17597#true} assume !(#t~mem27 == 24576);havoc #t~mem27;call #t~mem28 := read~int(~s.base, ~s.offset + 52, 4); {17597#true} is VALID [2018-11-14 19:06:44,007 INFO L273 TraceCheckUtils]: 20: Hoare triple {17597#true} assume !(#t~mem28 == 8195);havoc #t~mem28;call #t~mem29 := read~int(~s.base, ~s.offset + 52, 4); {17597#true} is VALID [2018-11-14 19:06:44,007 INFO L273 TraceCheckUtils]: 21: Hoare triple {17597#true} assume !(#t~mem29 == 8480);havoc #t~mem29;call #t~mem30 := read~int(~s.base, ~s.offset + 52, 4); {17597#true} is VALID [2018-11-14 19:06:44,007 INFO L273 TraceCheckUtils]: 22: Hoare triple {17597#true} assume !(#t~mem30 == 8481);havoc #t~mem30;call #t~mem31 := read~int(~s.base, ~s.offset + 52, 4); {17597#true} is VALID [2018-11-14 19:06:44,008 INFO L273 TraceCheckUtils]: 23: Hoare triple {17597#true} assume !(#t~mem31 == 8482);havoc #t~mem31;call #t~mem32 := read~int(~s.base, ~s.offset + 52, 4); {17597#true} is VALID [2018-11-14 19:06:44,008 INFO L273 TraceCheckUtils]: 24: Hoare triple {17597#true} assume #t~mem32 == 8464;havoc #t~mem32; {17597#true} is VALID [2018-11-14 19:06:44,008 INFO L273 TraceCheckUtils]: 25: Hoare triple {17597#true} call write~int(0, ~s.base, ~s.offset + 48, 4);assume -2147483648 <= #t~nondet69 && #t~nondet69 <= 2147483647;~ret~0 := #t~nondet69;havoc #t~nondet69; {17597#true} is VALID [2018-11-14 19:06:44,008 INFO L273 TraceCheckUtils]: 26: Hoare triple {17597#true} assume ~blastFlag~0 == 0;~blastFlag~0 := 1; {17597#true} is VALID [2018-11-14 19:06:44,026 INFO L273 TraceCheckUtils]: 27: Hoare triple {17597#true} assume !(~ret~0 <= 0);~got_new_session~0 := 1;call write~int(8496, ~s.base, ~s.offset + 52, 4);call write~int(0, ~s.base, ~s.offset + 64, 4); {17599#(= (select (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 52)) 8496)} is VALID [2018-11-14 19:06:44,035 INFO L273 TraceCheckUtils]: 28: Hoare triple {17599#(= (select (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 52)) 8496)} call #t~mem127.base, #t~mem127.offset := read~$Pointer$(~s.base, ~s.offset + 84, 4);call #t~mem128 := read~int(#t~mem127.base, #t~mem127.offset + 604 + 244, 4); {17599#(= (select (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 52)) 8496)} is VALID [2018-11-14 19:06:44,047 INFO L273 TraceCheckUtils]: 29: Hoare triple {17599#(= (select (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 52)) 8496)} assume !(#t~mem128 == 0);havoc #t~mem127.base, #t~mem127.offset;havoc #t~mem128; {17599#(= (select (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 52)) 8496)} is VALID [2018-11-14 19:06:44,059 INFO L273 TraceCheckUtils]: 30: Hoare triple {17599#(= (select (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 52)) 8496)} ~skip~0 := 0; {17599#(= (select (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 52)) 8496)} is VALID [2018-11-14 19:06:44,072 INFO L273 TraceCheckUtils]: 31: Hoare triple {17599#(= (select (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 52)) 8496)} assume true; {17599#(= (select (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 52)) 8496)} is VALID [2018-11-14 19:06:44,089 INFO L273 TraceCheckUtils]: 32: Hoare triple {17599#(= (select (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 52)) 8496)} assume !false; {17599#(= (select (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 52)) 8496)} is VALID [2018-11-14 19:06:44,097 INFO L273 TraceCheckUtils]: 33: Hoare triple {17599#(= (select (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 52)) 8496)} call #t~mem23 := read~int(~s.base, ~s.offset + 52, 4);~state~0 := #t~mem23;havoc #t~mem23;call #t~mem24 := read~int(~s.base, ~s.offset + 52, 4); {17599#(= (select (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 52)) 8496)} is VALID [2018-11-14 19:06:44,107 INFO L273 TraceCheckUtils]: 34: Hoare triple {17599#(= (select (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 52)) 8496)} assume !(#t~mem24 == 12292);havoc #t~mem24;call #t~mem25 := read~int(~s.base, ~s.offset + 52, 4); {17599#(= (select (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 52)) 8496)} is VALID [2018-11-14 19:06:44,115 INFO L273 TraceCheckUtils]: 35: Hoare triple {17599#(= (select (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 52)) 8496)} assume !(#t~mem25 == 16384);havoc #t~mem25;call #t~mem26 := read~int(~s.base, ~s.offset + 52, 4); {17599#(= (select (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 52)) 8496)} is VALID [2018-11-14 19:06:44,128 INFO L273 TraceCheckUtils]: 36: Hoare triple {17599#(= (select (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 52)) 8496)} assume !(#t~mem26 == 8192);havoc #t~mem26;call #t~mem27 := read~int(~s.base, ~s.offset + 52, 4); {17599#(= (select (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 52)) 8496)} is VALID [2018-11-14 19:06:44,142 INFO L273 TraceCheckUtils]: 37: Hoare triple {17599#(= (select (select |#memory_int| ssl3_accept_~s.base) (+ ssl3_accept_~s.offset 52)) 8496)} assume !(#t~mem27 == 24576);havoc #t~mem27;call #t~mem28 := read~int(~s.base, ~s.offset + 52, 4); {17600#(= |ssl3_accept_#t~mem28| 8496)} is VALID [2018-11-14 19:06:44,150 INFO L273 TraceCheckUtils]: 38: Hoare triple {17600#(= |ssl3_accept_#t~mem28| 8496)} assume #t~mem28 == 8195;havoc #t~mem28; {17598#false} is VALID [2018-11-14 19:06:44,151 INFO L273 TraceCheckUtils]: 39: Hoare triple {17598#false} call write~int(1, ~s.base, ~s.offset + 36, 4); {17598#false} is VALID [2018-11-14 19:06:44,151 INFO L273 TraceCheckUtils]: 40: Hoare triple {17598#false} assume (~cb~0.base + ~cb~0.offset) % 4294967296 != 0; {17598#false} is VALID [2018-11-14 19:06:44,151 INFO L273 TraceCheckUtils]: 41: Hoare triple {17598#false} call #t~mem59 := read~int(~s.base, ~s.offset + 0, 4); {17598#false} is VALID [2018-11-14 19:06:44,151 INFO L273 TraceCheckUtils]: 42: Hoare triple {17598#false} assume !(#t~mem59 / 256 != 3);havoc #t~mem59;call write~int(8192, ~s.base, ~s.offset + 4, 4);call #t~mem60.base, #t~mem60.offset := read~$Pointer$(~s.base, ~s.offset + 60, 4); {17598#false} is VALID [2018-11-14 19:06:44,151 INFO L273 TraceCheckUtils]: 43: Hoare triple {17598#false} assume !((#t~mem60.base + #t~mem60.offset) % 4294967296 == 0);havoc #t~mem60.base, #t~mem60.offset; {17598#false} is VALID [2018-11-14 19:06:44,152 INFO L273 TraceCheckUtils]: 44: Hoare triple {17598#false} assume !(~tmp___4~0 == 0);call write~int(0, ~s.base, ~s.offset + 64, 4);call #t~mem62 := read~int(~s.base, ~s.offset + 52, 4); {17598#false} is VALID [2018-11-14 19:06:44,152 INFO L273 TraceCheckUtils]: 45: Hoare triple {17598#false} assume #t~mem62 != 12292;havoc #t~mem62; {17598#false} is VALID [2018-11-14 19:06:44,152 INFO L273 TraceCheckUtils]: 46: Hoare triple {17598#false} assume !(~tmp___5~0 == 0);call write~int(8464, ~s.base, ~s.offset + 52, 4);call #t~mem63.base, #t~mem63.offset := read~$Pointer$(~s.base, ~s.offset + 204, 4);call #t~mem64 := read~int(#t~mem63.base, #t~mem63.offset + 60 + 12, 4);call write~int(#t~mem64 + 1, #t~mem63.base, #t~mem63.offset + 60 + 12, 4);havoc #t~mem64;havoc #t~mem63.base, #t~mem63.offset; {17598#false} is VALID [2018-11-14 19:06:44,152 INFO L273 TraceCheckUtils]: 47: Hoare triple {17598#false} call #t~mem127.base, #t~mem127.offset := read~$Pointer$(~s.base, ~s.offset + 84, 4);call #t~mem128 := read~int(#t~mem127.base, #t~mem127.offset + 604 + 244, 4); {17598#false} is VALID [2018-11-14 19:06:44,152 INFO L273 TraceCheckUtils]: 48: Hoare triple {17598#false} assume !(#t~mem128 == 0);havoc #t~mem127.base, #t~mem127.offset;havoc #t~mem128; {17598#false} is VALID [2018-11-14 19:06:44,153 INFO L273 TraceCheckUtils]: 49: Hoare triple {17598#false} ~skip~0 := 0; {17598#false} is VALID [2018-11-14 19:06:44,153 INFO L273 TraceCheckUtils]: 50: Hoare triple {17598#false} assume true; {17598#false} is VALID [2018-11-14 19:06:44,153 INFO L273 TraceCheckUtils]: 51: Hoare triple {17598#false} assume !false; {17598#false} is VALID [2018-11-14 19:06:44,153 INFO L273 TraceCheckUtils]: 52: Hoare triple {17598#false} call #t~mem23 := read~int(~s.base, ~s.offset + 52, 4);~state~0 := #t~mem23;havoc #t~mem23;call #t~mem24 := read~int(~s.base, ~s.offset + 52, 4); {17598#false} is VALID [2018-11-14 19:06:44,153 INFO L273 TraceCheckUtils]: 53: Hoare triple {17598#false} assume !(#t~mem24 == 12292);havoc #t~mem24;call #t~mem25 := read~int(~s.base, ~s.offset + 52, 4); {17598#false} is VALID [2018-11-14 19:06:44,153 INFO L273 TraceCheckUtils]: 54: Hoare triple {17598#false} assume !(#t~mem25 == 16384);havoc #t~mem25;call #t~mem26 := read~int(~s.base, ~s.offset + 52, 4); {17598#false} is VALID [2018-11-14 19:06:44,154 INFO L273 TraceCheckUtils]: 55: Hoare triple {17598#false} assume !(#t~mem26 == 8192);havoc #t~mem26;call #t~mem27 := read~int(~s.base, ~s.offset + 52, 4); {17598#false} is VALID [2018-11-14 19:06:44,154 INFO L273 TraceCheckUtils]: 56: Hoare triple {17598#false} assume !(#t~mem27 == 24576);havoc #t~mem27;call #t~mem28 := read~int(~s.base, ~s.offset + 52, 4); {17598#false} is VALID [2018-11-14 19:06:44,154 INFO L273 TraceCheckUtils]: 57: Hoare triple {17598#false} assume !(#t~mem28 == 8195);havoc #t~mem28;call #t~mem29 := read~int(~s.base, ~s.offset + 52, 4); {17598#false} is VALID [2018-11-14 19:06:44,154 INFO L273 TraceCheckUtils]: 58: Hoare triple {17598#false} assume !(#t~mem29 == 8480);havoc #t~mem29;call #t~mem30 := read~int(~s.base, ~s.offset + 52, 4); {17598#false} is VALID [2018-11-14 19:06:44,154 INFO L273 TraceCheckUtils]: 59: Hoare triple {17598#false} assume !(#t~mem30 == 8481);havoc #t~mem30;call #t~mem31 := read~int(~s.base, ~s.offset + 52, 4); {17598#false} is VALID [2018-11-14 19:06:44,154 INFO L273 TraceCheckUtils]: 60: Hoare triple {17598#false} assume !(#t~mem31 == 8482);havoc #t~mem31;call #t~mem32 := read~int(~s.base, ~s.offset + 52, 4); {17598#false} is VALID [2018-11-14 19:06:44,155 INFO L273 TraceCheckUtils]: 61: Hoare triple {17598#false} assume !(#t~mem32 == 8464);havoc #t~mem32;call #t~mem33 := read~int(~s.base, ~s.offset + 52, 4); {17598#false} is VALID [2018-11-14 19:06:44,155 INFO L273 TraceCheckUtils]: 62: Hoare triple {17598#false} assume !(#t~mem33 == 8465);havoc #t~mem33;call #t~mem34 := read~int(~s.base, ~s.offset + 52, 4); {17598#false} is VALID [2018-11-14 19:06:44,155 INFO L273 TraceCheckUtils]: 63: Hoare triple {17598#false} assume !(#t~mem34 == 8466);havoc #t~mem34;call #t~mem35 := read~int(~s.base, ~s.offset + 52, 4); {17598#false} is VALID [2018-11-14 19:06:44,155 INFO L273 TraceCheckUtils]: 64: Hoare triple {17598#false} assume !(#t~mem35 == 8496);havoc #t~mem35;call #t~mem36 := read~int(~s.base, ~s.offset + 52, 4); {17598#false} is VALID [2018-11-14 19:06:44,155 INFO L273 TraceCheckUtils]: 65: Hoare triple {17598#false} assume !(#t~mem36 == 8497);havoc #t~mem36;call #t~mem37 := read~int(~s.base, ~s.offset + 52, 4); {17598#false} is VALID [2018-11-14 19:06:44,155 INFO L273 TraceCheckUtils]: 66: Hoare triple {17598#false} assume !(#t~mem37 == 8512);havoc #t~mem37;call #t~mem38 := read~int(~s.base, ~s.offset + 52, 4); {17598#false} is VALID [2018-11-14 19:06:44,156 INFO L273 TraceCheckUtils]: 67: Hoare triple {17598#false} assume !(#t~mem38 == 8513);havoc #t~mem38;call #t~mem39 := read~int(~s.base, ~s.offset + 52, 4); {17598#false} is VALID [2018-11-14 19:06:44,156 INFO L273 TraceCheckUtils]: 68: Hoare triple {17598#false} assume !(#t~mem39 == 8528);havoc #t~mem39;call #t~mem40 := read~int(~s.base, ~s.offset + 52, 4); {17598#false} is VALID [2018-11-14 19:06:44,156 INFO L273 TraceCheckUtils]: 69: Hoare triple {17598#false} assume !(#t~mem40 == 8529);havoc #t~mem40;call #t~mem41 := read~int(~s.base, ~s.offset + 52, 4); {17598#false} is VALID [2018-11-14 19:06:44,156 INFO L273 TraceCheckUtils]: 70: Hoare triple {17598#false} assume !(#t~mem41 == 8544);havoc #t~mem41;call #t~mem42 := read~int(~s.base, ~s.offset + 52, 4); {17598#false} is VALID [2018-11-14 19:06:44,156 INFO L273 TraceCheckUtils]: 71: Hoare triple {17598#false} assume !(#t~mem42 == 8545);havoc #t~mem42;call #t~mem43 := read~int(~s.base, ~s.offset + 52, 4); {17598#false} is VALID [2018-11-14 19:06:44,156 INFO L273 TraceCheckUtils]: 72: Hoare triple {17598#false} assume !(#t~mem43 == 8560);havoc #t~mem43;call #t~mem44 := read~int(~s.base, ~s.offset + 52, 4); {17598#false} is VALID [2018-11-14 19:06:44,157 INFO L273 TraceCheckUtils]: 73: Hoare triple {17598#false} assume !(#t~mem44 == 8561);havoc #t~mem44;call #t~mem45 := read~int(~s.base, ~s.offset + 52, 4); {17598#false} is VALID [2018-11-14 19:06:44,157 INFO L273 TraceCheckUtils]: 74: Hoare triple {17598#false} assume !(#t~mem45 == 8448);havoc #t~mem45;call #t~mem46 := read~int(~s.base, ~s.offset + 52, 4); {17598#false} is VALID [2018-11-14 19:06:44,157 INFO L273 TraceCheckUtils]: 75: Hoare triple {17598#false} assume !(#t~mem46 == 8576);havoc #t~mem46;call #t~mem47 := read~int(~s.base, ~s.offset + 52, 4); {17598#false} is VALID [2018-11-14 19:06:44,157 INFO L273 TraceCheckUtils]: 76: Hoare triple {17598#false} assume !(#t~mem47 == 8577);havoc #t~mem47;call #t~mem48 := read~int(~s.base, ~s.offset + 52, 4); {17598#false} is VALID [2018-11-14 19:06:44,157 INFO L273 TraceCheckUtils]: 77: Hoare triple {17598#false} assume !(#t~mem48 == 8592);havoc #t~mem48;call #t~mem49 := read~int(~s.base, ~s.offset + 52, 4); {17598#false} is VALID [2018-11-14 19:06:44,157 INFO L273 TraceCheckUtils]: 78: Hoare triple {17598#false} assume !(#t~mem49 == 8593);havoc #t~mem49;call #t~mem50 := read~int(~s.base, ~s.offset + 52, 4); {17598#false} is VALID [2018-11-14 19:06:44,158 INFO L273 TraceCheckUtils]: 79: Hoare triple {17598#false} assume !(#t~mem50 == 8608);havoc #t~mem50;call #t~mem51 := read~int(~s.base, ~s.offset + 52, 4); {17598#false} is VALID [2018-11-14 19:06:44,158 INFO L273 TraceCheckUtils]: 80: Hoare triple {17598#false} assume !(#t~mem51 == 8609);havoc #t~mem51;call #t~mem52 := read~int(~s.base, ~s.offset + 52, 4); {17598#false} is VALID [2018-11-14 19:06:44,158 INFO L273 TraceCheckUtils]: 81: Hoare triple {17598#false} assume !(#t~mem52 == 8640);havoc #t~mem52;call #t~mem53 := read~int(~s.base, ~s.offset + 52, 4); {17598#false} is VALID [2018-11-14 19:06:44,158 INFO L273 TraceCheckUtils]: 82: Hoare triple {17598#false} assume !(#t~mem53 == 8641);havoc #t~mem53;call #t~mem54 := read~int(~s.base, ~s.offset + 52, 4); {17598#false} is VALID [2018-11-14 19:06:44,158 INFO L273 TraceCheckUtils]: 83: Hoare triple {17598#false} assume !(#t~mem54 == 8656);havoc #t~mem54;call #t~mem55 := read~int(~s.base, ~s.offset + 52, 4); {17598#false} is VALID [2018-11-14 19:06:44,158 INFO L273 TraceCheckUtils]: 84: Hoare triple {17598#false} assume !(#t~mem55 == 8657);havoc #t~mem55;call #t~mem56 := read~int(~s.base, ~s.offset + 52, 4); {17598#false} is VALID [2018-11-14 19:06:44,159 INFO L273 TraceCheckUtils]: 85: Hoare triple {17598#false} assume #t~mem56 == 8672;havoc #t~mem56; {17598#false} is VALID [2018-11-14 19:06:44,159 INFO L273 TraceCheckUtils]: 86: Hoare triple {17598#false} assume -2147483648 <= #t~nondet121 && #t~nondet121 <= 2147483647;~ret~0 := #t~nondet121;havoc #t~nondet121; {17598#false} is VALID [2018-11-14 19:06:44,159 INFO L273 TraceCheckUtils]: 87: Hoare triple {17598#false} assume ~blastFlag~0 == 4; {17598#false} is VALID [2018-11-14 19:06:44,159 INFO L273 TraceCheckUtils]: 88: Hoare triple {17598#false} assume !false; {17598#false} is VALID [2018-11-14 19:06:44,165 INFO L134 CoverageAnalysis]: Checked inductivity of 31 backedges. 31 proven. 0 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2018-11-14 19:06:44,165 INFO L312 seRefinementStrategy]: Constructing automaton from 1 perfect and 0 imperfect interpolant sequences. [2018-11-14 19:06:44,166 INFO L327 seRefinementStrategy]: Number of different interpolants: perfect sequences [4] imperfect sequences [] total 4 [2018-11-14 19:06:44,166 INFO L78 Accepts]: Start accepts. Automaton has 4 states. Word has length 89 [2018-11-14 19:06:44,166 INFO L84 Accepts]: Finished accepts. word is accepted. [2018-11-14 19:06:44,166 INFO L86 InductivityCheck]: Starting indutivity check of a Floyd-Hoare automaton with 4 states. [2018-11-14 19:06:44,411 INFO L119 InductivityCheck]: Floyd-Hoare automaton has 89 edges. 89 inductive. 0 not inductive. 0 times theorem prover too weak to decide inductivity. [2018-11-14 19:06:44,412 INFO L459 AbstractCegarLoop]: Interpolant automaton has 4 states [2018-11-14 19:06:44,412 INFO L142 InterpolantAutomaton]: Constructing interpolant automaton starting with 4 interpolants. [2018-11-14 19:06:44,412 INFO L144 InterpolantAutomaton]: CoverageRelationStatistics Valid=5, Invalid=7, Unknown=0, NotChecked=0, Total=12 [2018-11-14 19:06:44,412 INFO L87 Difference]: Start difference. First operand 198 states and 287 transitions. Second operand 4 states. [2018-11-14 19:06:45,744 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2018-11-14 19:06:45,744 INFO L93 Difference]: Finished difference Result 387 states and 567 transitions. [2018-11-14 19:06:45,744 INFO L142 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 4 states. [2018-11-14 19:06:45,744 INFO L78 Accepts]: Start accepts. Automaton has 4 states. Word has length 89 [2018-11-14 19:06:45,745 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2018-11-14 19:06:45,745 INFO L82 GeneralOperation]: Start removeUnreachable. Operand 4 states. [2018-11-14 19:06:45,747 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 4 states to 4 states and 446 transitions. [2018-11-14 19:06:45,747 INFO L82 GeneralOperation]: Start removeUnreachable. Operand 4 states. [2018-11-14 19:06:45,750 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 4 states to 4 states and 446 transitions. [2018-11-14 19:06:45,750 INFO L86 InductivityCheck]: Starting indutivity check of a Floyd-Hoare automaton with 4 states and 446 transitions. [2018-11-14 19:06:46,142 INFO L119 InductivityCheck]: Floyd-Hoare automaton has 446 edges. 446 inductive. 0 not inductive. 0 times theorem prover too weak to decide inductivity. [2018-11-14 19:06:46,147 INFO L225 Difference]: With dead ends: 387 [2018-11-14 19:06:46,147 INFO L226 Difference]: Without dead ends: 215 [2018-11-14 19:06:46,148 INFO L604 BasicCegarLoop]: 0 DeclaredPredicates, 6 GetRequests, 2 SyntacticMatches, 1 SemanticMatches, 3 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 0 ImplicationChecksByTransitivity, 0.3s TimeCoverageRelationStatistics Valid=9, Invalid=11, Unknown=0, NotChecked=0, Total=20 [2018-11-14 19:06:46,148 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 215 states. [2018-11-14 19:06:46,172 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 215 to 198. [2018-11-14 19:06:46,172 INFO L214 AbstractMinimizeNwa]: Start testing correctness of minimizeSevpa [2018-11-14 19:06:46,172 INFO L82 GeneralOperation]: Start isEquivalent. First operand 215 states. Second operand 198 states. [2018-11-14 19:06:46,172 INFO L74 IsIncluded]: Start isIncluded. First operand 215 states. Second operand 198 states. [2018-11-14 19:06:46,173 INFO L87 Difference]: Start difference. First operand 215 states. Second operand 198 states. [2018-11-14 19:06:46,177 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2018-11-14 19:06:46,177 INFO L93 Difference]: Finished difference Result 215 states and 308 transitions. [2018-11-14 19:06:46,177 INFO L276 IsEmpty]: Start isEmpty. Operand 215 states and 308 transitions. [2018-11-14 19:06:46,177 INFO L282 IsEmpty]: Finished isEmpty. No accepting run. [2018-11-14 19:06:46,177 INFO L83 IsIncluded]: Finished isIncluded. Language is included [2018-11-14 19:06:46,177 INFO L74 IsIncluded]: Start isIncluded. First operand 198 states. Second operand 215 states. [2018-11-14 19:06:46,177 INFO L87 Difference]: Start difference. First operand 198 states. Second operand 215 states. [2018-11-14 19:06:46,181 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2018-11-14 19:06:46,181 INFO L93 Difference]: Finished difference Result 215 states and 308 transitions. [2018-11-14 19:06:46,182 INFO L276 IsEmpty]: Start isEmpty. Operand 215 states and 308 transitions. [2018-11-14 19:06:46,182 INFO L282 IsEmpty]: Finished isEmpty. No accepting run. [2018-11-14 19:06:46,182 INFO L83 IsIncluded]: Finished isIncluded. Language is included [2018-11-14 19:06:46,182 INFO L88 GeneralOperation]: Finished isEquivalent. [2018-11-14 19:06:46,182 INFO L221 AbstractMinimizeNwa]: Finished testing correctness of minimizeSevpa [2018-11-14 19:06:46,183 INFO L82 GeneralOperation]: Start removeUnreachable. Operand 198 states. [2018-11-14 19:06:46,186 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 198 states to 198 states and 286 transitions. [2018-11-14 19:06:46,186 INFO L78 Accepts]: Start accepts. Automaton has 198 states and 286 transitions. Word has length 89 [2018-11-14 19:06:46,186 INFO L84 Accepts]: Finished accepts. word is rejected. [2018-11-14 19:06:46,187 INFO L480 AbstractCegarLoop]: Abstraction has 198 states and 286 transitions. [2018-11-14 19:06:46,187 INFO L481 AbstractCegarLoop]: Interpolant automaton has 4 states. [2018-11-14 19:06:46,187 INFO L276 IsEmpty]: Start isEmpty. Operand 198 states and 286 transitions. [2018-11-14 19:06:46,187 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 94 [2018-11-14 19:06:46,188 INFO L367 BasicCegarLoop]: Found error trace [2018-11-14 19:06:46,188 INFO L375 BasicCegarLoop]: trace histogram [3, 3, 3, 3, 3, 3, 3, 3, 3, 3, 3, 2, 2, 2, 2, 2, 2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2018-11-14 19:06:46,188 INFO L423 AbstractCegarLoop]: === Iteration 20 === [ssl3_acceptErr0ASSERT_VIOLATIONERROR_FUNCTION]=== [2018-11-14 19:06:46,188 INFO L141 PredicateUnifier]: Initialized classic predicate unifier [2018-11-14 19:06:46,188 INFO L82 PathProgramCache]: Analyzing trace with hash -167912189, now seen corresponding path program 1 times [2018-11-14 19:06:46,188 INFO L223 ckRefinementStrategy]: Switched to mode SMTINTERPOL_TREE_INTERPOLANTS [2018-11-14 19:06:46,189 INFO L69 tionRefinementEngine]: Using refinement strategy CamelRefinementStrategy [2018-11-14 19:06:46,189 INFO L119 rtionOrderModulation]: Craig_TreeInterpolation forces the order to NOT_INCREMENTALLY [2018-11-14 19:06:46,189 INFO L103 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2018-11-14 19:06:46,190 INFO L119 rtionOrderModulation]: Craig_TreeInterpolation forces the order to NOT_INCREMENTALLY [2018-11-14 19:06:46,202 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2018-11-14 19:06:46,347 INFO L256 TraceCheckUtils]: 0: Hoare triple {18722#true} call ULTIMATE.init(); {18722#true} is VALID [2018-11-14 19:06:46,347 INFO L273 TraceCheckUtils]: 1: Hoare triple {18722#true} #NULL.base, #NULL.offset := 0, 0;#valid := #valid[0 := 0];~init~0 := 1;call ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset := #Ultimate.alloc(100);call write~unchecked~int(0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 0, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 4, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 8, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 12, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 16, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 20, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 24, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 28, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 32, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 36, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 40, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 44, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 48, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 52, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 56, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 60, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 64, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 68, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 72, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 76, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 80, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 84, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 88, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 92, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 96, 4);call write~unchecked~int(0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 0, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 4, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 8, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 12, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 16, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 20, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 24, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 28, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 32, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 36, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 40, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 44, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 48, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 52, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 56, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 60, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 64, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 68, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 72, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 76, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 80, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 84, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 88, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 92, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 96, 4); {18722#true} is VALID [2018-11-14 19:06:46,348 INFO L273 TraceCheckUtils]: 2: Hoare triple {18722#true} assume true; {18722#true} is VALID [2018-11-14 19:06:46,348 INFO L268 TraceCheckUtils]: 3: Hoare quadruple {18722#true} {18722#true} #654#return; {18722#true} is VALID [2018-11-14 19:06:46,348 INFO L256 TraceCheckUtils]: 4: Hoare triple {18722#true} call #t~ret138 := main(); {18722#true} is VALID [2018-11-14 19:06:46,348 INFO L273 TraceCheckUtils]: 5: Hoare triple {18722#true} havoc ~s~0.base, ~s~0.offset;havoc ~tmp~2;call #t~malloc3.base, #t~malloc3.offset := #Ultimate.alloc(248);~s~0.base, ~s~0.offset := #t~malloc3.base, #t~malloc3.offset;call #t~malloc4.base, #t~malloc4.offset := #Ultimate.alloc(899);call write~$Pointer$(#t~malloc4.base, #t~malloc4.offset, ~s~0.base, ~s~0.offset + 84, 4);call #t~malloc5.base, #t~malloc5.offset := #Ultimate.alloc(232);call write~$Pointer$(#t~malloc5.base, #t~malloc5.offset, ~s~0.base, ~s~0.offset + 204, 4);call #t~malloc6.base, #t~malloc6.offset := #Ultimate.alloc(200);call write~$Pointer$(#t~malloc6.base, #t~malloc6.offset, ~s~0.base, ~s~0.offset + 176, 4);call write~int(8464, ~s~0.base, ~s~0.offset + 52, 4); {18722#true} is VALID [2018-11-14 19:06:46,348 INFO L256 TraceCheckUtils]: 6: Hoare triple {18722#true} call #t~ret7 := ssl3_accept(~s~0.base, ~s~0.offset); {18722#true} is VALID [2018-11-14 19:06:46,348 INFO L273 TraceCheckUtils]: 7: Hoare triple {18722#true} ~s.base, ~s.offset := #in~s.base, #in~s.offset;havoc ~buf~0.base, ~buf~0.offset;havoc ~l~0;havoc ~Time~0;havoc ~tmp~3;havoc ~cb~0.base, ~cb~0.offset;havoc ~num1~0;havoc ~ret~0;havoc ~new_state~0;havoc ~state~0;havoc ~skip~0;havoc ~got_new_session~0;assume -2147483648 <= #t~nondet8 && #t~nondet8 <= 2147483647;~tmp___1~0 := #t~nondet8;havoc #t~nondet8;assume -2147483648 <= #t~nondet9 && #t~nondet9 <= 2147483647;~tmp___2~0 := #t~nondet9;havoc #t~nondet9;assume -2147483648 <= #t~nondet10 && #t~nondet10 <= 2147483647;~tmp___3~0 := #t~nondet10;havoc #t~nondet10;assume -2147483648 <= #t~nondet11 && #t~nondet11 <= 2147483647;~tmp___4~0 := #t~nondet11;havoc #t~nondet11;assume -2147483648 <= #t~nondet12 && #t~nondet12 <= 2147483647;~tmp___5~0 := #t~nondet12;havoc #t~nondet12;assume -2147483648 <= #t~nondet13 && #t~nondet13 <= 2147483647;~tmp___6~0 := #t~nondet13;havoc #t~nondet13;havoc ~tmp___7~0;assume -2147483648 <= #t~nondet14 && #t~nondet14 <= 2147483647;~tmp___8~0 := #t~nondet14;havoc #t~nondet14;assume -2147483648 <= #t~nondet15 && #t~nondet15 <= 2147483647;~tmp___9~0 := #t~nondet15;havoc #t~nondet15;assume -2147483648 <= #t~nondet16 && #t~nondet16 <= 2147483647;~tmp___10~0 := #t~nondet16;havoc #t~nondet16;havoc ~blastFlag~0;~blastFlag~0 := 0;assume -2147483648 <= #t~nondet17 && #t~nondet17 <= 2147483647;call write~int(#t~nondet17, ~s.base, ~s.offset + 92, 4);havoc #t~nondet17;call write~int(8464, ~s.base, ~s.offset + 52, 4);assume -2147483648 <= #t~nondet18 && #t~nondet18 <= 2147483647;~tmp~3 := #t~nondet18;havoc #t~nondet18;~Time~0 := ~tmp~3;~cb~0.base, ~cb~0.offset := 0, 0;~ret~0 := -1;~skip~0 := 0;~got_new_session~0 := 0;call #t~mem19.base, #t~mem19.offset := read~$Pointer$(~s.base, ~s.offset + 192, 4); {18722#true} is VALID [2018-11-14 19:06:46,348 INFO L273 TraceCheckUtils]: 8: Hoare triple {18722#true} assume (#t~mem19.base + #t~mem19.offset) % 4294967296 != 0;havoc #t~mem19.base, #t~mem19.offset;call #t~mem20.base, #t~mem20.offset := read~$Pointer$(~s.base, ~s.offset + 192, 4);~cb~0.base, ~cb~0.offset := #t~mem20.base, #t~mem20.offset;havoc #t~mem20.base, #t~mem20.offset; {18722#true} is VALID [2018-11-14 19:06:46,348 INFO L273 TraceCheckUtils]: 9: Hoare triple {18722#true} call #t~mem21 := read~int(~s.base, ~s.offset + 28, 4);call write~int(#t~mem21 + 1, ~s.base, ~s.offset + 28, 4);havoc #t~mem21; {18722#true} is VALID [2018-11-14 19:06:46,349 INFO L273 TraceCheckUtils]: 10: Hoare triple {18722#true} assume !(~bitwiseAnd(~tmp___1~0, 12288) != 0); {18722#true} is VALID [2018-11-14 19:06:46,349 INFO L273 TraceCheckUtils]: 11: Hoare triple {18722#true} call #t~mem22.base, #t~mem22.offset := read~$Pointer$(~s.base, ~s.offset + 136, 4); {18722#true} is VALID [2018-11-14 19:06:46,349 INFO L273 TraceCheckUtils]: 12: Hoare triple {18722#true} assume !((#t~mem22.base + #t~mem22.offset) % 4294967296 == 0);havoc #t~mem22.base, #t~mem22.offset; {18722#true} is VALID [2018-11-14 19:06:46,349 INFO L273 TraceCheckUtils]: 13: Hoare triple {18722#true} assume true; {18722#true} is VALID [2018-11-14 19:06:46,349 INFO L273 TraceCheckUtils]: 14: Hoare triple {18722#true} assume !false; {18722#true} is VALID [2018-11-14 19:06:46,349 INFO L273 TraceCheckUtils]: 15: Hoare triple {18722#true} call #t~mem23 := read~int(~s.base, ~s.offset + 52, 4);~state~0 := #t~mem23;havoc #t~mem23;call #t~mem24 := read~int(~s.base, ~s.offset + 52, 4); {18722#true} is VALID [2018-11-14 19:06:46,350 INFO L273 TraceCheckUtils]: 16: Hoare triple {18722#true} assume !(#t~mem24 == 12292);havoc #t~mem24;call #t~mem25 := read~int(~s.base, ~s.offset + 52, 4); {18722#true} is VALID [2018-11-14 19:06:46,350 INFO L273 TraceCheckUtils]: 17: Hoare triple {18722#true} assume !(#t~mem25 == 16384);havoc #t~mem25;call #t~mem26 := read~int(~s.base, ~s.offset + 52, 4); {18722#true} is VALID [2018-11-14 19:06:46,350 INFO L273 TraceCheckUtils]: 18: Hoare triple {18722#true} assume !(#t~mem26 == 8192);havoc #t~mem26;call #t~mem27 := read~int(~s.base, ~s.offset + 52, 4); {18722#true} is VALID [2018-11-14 19:06:46,350 INFO L273 TraceCheckUtils]: 19: Hoare triple {18722#true} assume !(#t~mem27 == 24576);havoc #t~mem27;call #t~mem28 := read~int(~s.base, ~s.offset + 52, 4); {18722#true} is VALID [2018-11-14 19:06:46,350 INFO L273 TraceCheckUtils]: 20: Hoare triple {18722#true} assume !(#t~mem28 == 8195);havoc #t~mem28;call #t~mem29 := read~int(~s.base, ~s.offset + 52, 4); {18722#true} is VALID [2018-11-14 19:06:46,350 INFO L273 TraceCheckUtils]: 21: Hoare triple {18722#true} assume !(#t~mem29 == 8480);havoc #t~mem29;call #t~mem30 := read~int(~s.base, ~s.offset + 52, 4); {18722#true} is VALID [2018-11-14 19:06:46,350 INFO L273 TraceCheckUtils]: 22: Hoare triple {18722#true} assume !(#t~mem30 == 8481);havoc #t~mem30;call #t~mem31 := read~int(~s.base, ~s.offset + 52, 4); {18722#true} is VALID [2018-11-14 19:06:46,350 INFO L273 TraceCheckUtils]: 23: Hoare triple {18722#true} assume !(#t~mem31 == 8482);havoc #t~mem31;call #t~mem32 := read~int(~s.base, ~s.offset + 52, 4); {18722#true} is VALID [2018-11-14 19:06:46,350 INFO L273 TraceCheckUtils]: 24: Hoare triple {18722#true} assume #t~mem32 == 8464;havoc #t~mem32; {18722#true} is VALID [2018-11-14 19:06:46,351 INFO L273 TraceCheckUtils]: 25: Hoare triple {18722#true} call write~int(0, ~s.base, ~s.offset + 48, 4);assume -2147483648 <= #t~nondet69 && #t~nondet69 <= 2147483647;~ret~0 := #t~nondet69;havoc #t~nondet69; {18722#true} is VALID [2018-11-14 19:06:46,352 INFO L273 TraceCheckUtils]: 26: Hoare triple {18722#true} assume ~blastFlag~0 == 0;~blastFlag~0 := 1; {18724#(= ssl3_accept_~blastFlag~0 1)} is VALID [2018-11-14 19:06:46,352 INFO L273 TraceCheckUtils]: 27: Hoare triple {18724#(= ssl3_accept_~blastFlag~0 1)} assume !(~ret~0 <= 0);~got_new_session~0 := 1;call write~int(8496, ~s.base, ~s.offset + 52, 4);call write~int(0, ~s.base, ~s.offset + 64, 4); {18724#(= ssl3_accept_~blastFlag~0 1)} is VALID [2018-11-14 19:06:46,355 INFO L273 TraceCheckUtils]: 28: Hoare triple {18724#(= ssl3_accept_~blastFlag~0 1)} call #t~mem127.base, #t~mem127.offset := read~$Pointer$(~s.base, ~s.offset + 84, 4);call #t~mem128 := read~int(#t~mem127.base, #t~mem127.offset + 604 + 244, 4); {18724#(= ssl3_accept_~blastFlag~0 1)} is VALID [2018-11-14 19:06:46,355 INFO L273 TraceCheckUtils]: 29: Hoare triple {18724#(= ssl3_accept_~blastFlag~0 1)} assume !(#t~mem128 == 0);havoc #t~mem127.base, #t~mem127.offset;havoc #t~mem128; {18724#(= ssl3_accept_~blastFlag~0 1)} is VALID [2018-11-14 19:06:46,358 INFO L273 TraceCheckUtils]: 30: Hoare triple {18724#(= ssl3_accept_~blastFlag~0 1)} ~skip~0 := 0; {18724#(= ssl3_accept_~blastFlag~0 1)} is VALID [2018-11-14 19:06:46,358 INFO L273 TraceCheckUtils]: 31: Hoare triple {18724#(= ssl3_accept_~blastFlag~0 1)} assume true; {18724#(= ssl3_accept_~blastFlag~0 1)} is VALID [2018-11-14 19:06:46,358 INFO L273 TraceCheckUtils]: 32: Hoare triple {18724#(= ssl3_accept_~blastFlag~0 1)} assume !false; {18724#(= ssl3_accept_~blastFlag~0 1)} is VALID [2018-11-14 19:06:46,359 INFO L273 TraceCheckUtils]: 33: Hoare triple {18724#(= ssl3_accept_~blastFlag~0 1)} call #t~mem23 := read~int(~s.base, ~s.offset + 52, 4);~state~0 := #t~mem23;havoc #t~mem23;call #t~mem24 := read~int(~s.base, ~s.offset + 52, 4); {18724#(= ssl3_accept_~blastFlag~0 1)} is VALID [2018-11-14 19:06:46,359 INFO L273 TraceCheckUtils]: 34: Hoare triple {18724#(= ssl3_accept_~blastFlag~0 1)} assume !(#t~mem24 == 12292);havoc #t~mem24;call #t~mem25 := read~int(~s.base, ~s.offset + 52, 4); {18724#(= ssl3_accept_~blastFlag~0 1)} is VALID [2018-11-14 19:06:46,359 INFO L273 TraceCheckUtils]: 35: Hoare triple {18724#(= ssl3_accept_~blastFlag~0 1)} assume !(#t~mem25 == 16384);havoc #t~mem25;call #t~mem26 := read~int(~s.base, ~s.offset + 52, 4); {18724#(= ssl3_accept_~blastFlag~0 1)} is VALID [2018-11-14 19:06:46,359 INFO L273 TraceCheckUtils]: 36: Hoare triple {18724#(= ssl3_accept_~blastFlag~0 1)} assume !(#t~mem26 == 8192);havoc #t~mem26;call #t~mem27 := read~int(~s.base, ~s.offset + 52, 4); {18724#(= ssl3_accept_~blastFlag~0 1)} is VALID [2018-11-14 19:06:46,360 INFO L273 TraceCheckUtils]: 37: Hoare triple {18724#(= ssl3_accept_~blastFlag~0 1)} assume !(#t~mem27 == 24576);havoc #t~mem27;call #t~mem28 := read~int(~s.base, ~s.offset + 52, 4); {18724#(= ssl3_accept_~blastFlag~0 1)} is VALID [2018-11-14 19:06:46,360 INFO L273 TraceCheckUtils]: 38: Hoare triple {18724#(= ssl3_accept_~blastFlag~0 1)} assume !(#t~mem28 == 8195);havoc #t~mem28;call #t~mem29 := read~int(~s.base, ~s.offset + 52, 4); {18724#(= ssl3_accept_~blastFlag~0 1)} is VALID [2018-11-14 19:06:46,360 INFO L273 TraceCheckUtils]: 39: Hoare triple {18724#(= ssl3_accept_~blastFlag~0 1)} assume !(#t~mem29 == 8480);havoc #t~mem29;call #t~mem30 := read~int(~s.base, ~s.offset + 52, 4); {18724#(= ssl3_accept_~blastFlag~0 1)} is VALID [2018-11-14 19:06:46,361 INFO L273 TraceCheckUtils]: 40: Hoare triple {18724#(= ssl3_accept_~blastFlag~0 1)} assume !(#t~mem30 == 8481);havoc #t~mem30;call #t~mem31 := read~int(~s.base, ~s.offset + 52, 4); {18724#(= ssl3_accept_~blastFlag~0 1)} is VALID [2018-11-14 19:06:46,361 INFO L273 TraceCheckUtils]: 41: Hoare triple {18724#(= ssl3_accept_~blastFlag~0 1)} assume !(#t~mem31 == 8482);havoc #t~mem31;call #t~mem32 := read~int(~s.base, ~s.offset + 52, 4); {18724#(= ssl3_accept_~blastFlag~0 1)} is VALID [2018-11-14 19:06:46,362 INFO L273 TraceCheckUtils]: 42: Hoare triple {18724#(= ssl3_accept_~blastFlag~0 1)} assume !(#t~mem32 == 8464);havoc #t~mem32;call #t~mem33 := read~int(~s.base, ~s.offset + 52, 4); {18724#(= ssl3_accept_~blastFlag~0 1)} is VALID [2018-11-14 19:06:46,362 INFO L273 TraceCheckUtils]: 43: Hoare triple {18724#(= ssl3_accept_~blastFlag~0 1)} assume !(#t~mem33 == 8465);havoc #t~mem33;call #t~mem34 := read~int(~s.base, ~s.offset + 52, 4); {18724#(= ssl3_accept_~blastFlag~0 1)} is VALID [2018-11-14 19:06:46,363 INFO L273 TraceCheckUtils]: 44: Hoare triple {18724#(= ssl3_accept_~blastFlag~0 1)} assume !(#t~mem34 == 8466);havoc #t~mem34;call #t~mem35 := read~int(~s.base, ~s.offset + 52, 4); {18724#(= ssl3_accept_~blastFlag~0 1)} is VALID [2018-11-14 19:06:46,363 INFO L273 TraceCheckUtils]: 45: Hoare triple {18724#(= ssl3_accept_~blastFlag~0 1)} assume #t~mem35 == 8496;havoc #t~mem35; {18724#(= ssl3_accept_~blastFlag~0 1)} is VALID [2018-11-14 19:06:46,364 INFO L273 TraceCheckUtils]: 46: Hoare triple {18724#(= ssl3_accept_~blastFlag~0 1)} assume -2147483648 <= #t~nondet70 && #t~nondet70 <= 2147483647;~ret~0 := #t~nondet70;havoc #t~nondet70; {18724#(= ssl3_accept_~blastFlag~0 1)} is VALID [2018-11-14 19:06:46,364 INFO L273 TraceCheckUtils]: 47: Hoare triple {18724#(= ssl3_accept_~blastFlag~0 1)} assume !(~blastFlag~0 == 1); {18723#false} is VALID [2018-11-14 19:06:46,365 INFO L273 TraceCheckUtils]: 48: Hoare triple {18723#false} assume !(~ret~0 <= 0);call #t~mem71 := read~int(~s.base, ~s.offset + 92, 4); {18723#false} is VALID [2018-11-14 19:06:46,365 INFO L273 TraceCheckUtils]: 49: Hoare triple {18723#false} assume #t~mem71 != 0;havoc #t~mem71;call write~int(8656, ~s.base, ~s.offset + 52, 4); {18723#false} is VALID [2018-11-14 19:06:46,365 INFO L273 TraceCheckUtils]: 50: Hoare triple {18723#false} call write~int(0, ~s.base, ~s.offset + 64, 4); {18723#false} is VALID [2018-11-14 19:06:46,365 INFO L273 TraceCheckUtils]: 51: Hoare triple {18723#false} call #t~mem127.base, #t~mem127.offset := read~$Pointer$(~s.base, ~s.offset + 84, 4);call #t~mem128 := read~int(#t~mem127.base, #t~mem127.offset + 604 + 244, 4); {18723#false} is VALID [2018-11-14 19:06:46,365 INFO L273 TraceCheckUtils]: 52: Hoare triple {18723#false} assume !(#t~mem128 == 0);havoc #t~mem127.base, #t~mem127.offset;havoc #t~mem128; {18723#false} is VALID [2018-11-14 19:06:46,366 INFO L273 TraceCheckUtils]: 53: Hoare triple {18723#false} ~skip~0 := 0; {18723#false} is VALID [2018-11-14 19:06:46,366 INFO L273 TraceCheckUtils]: 54: Hoare triple {18723#false} assume true; {18723#false} is VALID [2018-11-14 19:06:46,366 INFO L273 TraceCheckUtils]: 55: Hoare triple {18723#false} assume !false; {18723#false} is VALID [2018-11-14 19:06:46,366 INFO L273 TraceCheckUtils]: 56: Hoare triple {18723#false} call #t~mem23 := read~int(~s.base, ~s.offset + 52, 4);~state~0 := #t~mem23;havoc #t~mem23;call #t~mem24 := read~int(~s.base, ~s.offset + 52, 4); {18723#false} is VALID [2018-11-14 19:06:46,366 INFO L273 TraceCheckUtils]: 57: Hoare triple {18723#false} assume !(#t~mem24 == 12292);havoc #t~mem24;call #t~mem25 := read~int(~s.base, ~s.offset + 52, 4); {18723#false} is VALID [2018-11-14 19:06:46,366 INFO L273 TraceCheckUtils]: 58: Hoare triple {18723#false} assume !(#t~mem25 == 16384);havoc #t~mem25;call #t~mem26 := read~int(~s.base, ~s.offset + 52, 4); {18723#false} is VALID [2018-11-14 19:06:46,367 INFO L273 TraceCheckUtils]: 59: Hoare triple {18723#false} assume !(#t~mem26 == 8192);havoc #t~mem26;call #t~mem27 := read~int(~s.base, ~s.offset + 52, 4); {18723#false} is VALID [2018-11-14 19:06:46,367 INFO L273 TraceCheckUtils]: 60: Hoare triple {18723#false} assume !(#t~mem27 == 24576);havoc #t~mem27;call #t~mem28 := read~int(~s.base, ~s.offset + 52, 4); {18723#false} is VALID [2018-11-14 19:06:46,367 INFO L273 TraceCheckUtils]: 61: Hoare triple {18723#false} assume !(#t~mem28 == 8195);havoc #t~mem28;call #t~mem29 := read~int(~s.base, ~s.offset + 52, 4); {18723#false} is VALID [2018-11-14 19:06:46,367 INFO L273 TraceCheckUtils]: 62: Hoare triple {18723#false} assume !(#t~mem29 == 8480);havoc #t~mem29;call #t~mem30 := read~int(~s.base, ~s.offset + 52, 4); {18723#false} is VALID [2018-11-14 19:06:46,367 INFO L273 TraceCheckUtils]: 63: Hoare triple {18723#false} assume !(#t~mem30 == 8481);havoc #t~mem30;call #t~mem31 := read~int(~s.base, ~s.offset + 52, 4); {18723#false} is VALID [2018-11-14 19:06:46,368 INFO L273 TraceCheckUtils]: 64: Hoare triple {18723#false} assume !(#t~mem31 == 8482);havoc #t~mem31;call #t~mem32 := read~int(~s.base, ~s.offset + 52, 4); {18723#false} is VALID [2018-11-14 19:06:46,368 INFO L273 TraceCheckUtils]: 65: Hoare triple {18723#false} assume !(#t~mem32 == 8464);havoc #t~mem32;call #t~mem33 := read~int(~s.base, ~s.offset + 52, 4); {18723#false} is VALID [2018-11-14 19:06:46,368 INFO L273 TraceCheckUtils]: 66: Hoare triple {18723#false} assume !(#t~mem33 == 8465);havoc #t~mem33;call #t~mem34 := read~int(~s.base, ~s.offset + 52, 4); {18723#false} is VALID [2018-11-14 19:06:46,368 INFO L273 TraceCheckUtils]: 67: Hoare triple {18723#false} assume !(#t~mem34 == 8466);havoc #t~mem34;call #t~mem35 := read~int(~s.base, ~s.offset + 52, 4); {18723#false} is VALID [2018-11-14 19:06:46,368 INFO L273 TraceCheckUtils]: 68: Hoare triple {18723#false} assume !(#t~mem35 == 8496);havoc #t~mem35;call #t~mem36 := read~int(~s.base, ~s.offset + 52, 4); {18723#false} is VALID [2018-11-14 19:06:46,368 INFO L273 TraceCheckUtils]: 69: Hoare triple {18723#false} assume !(#t~mem36 == 8497);havoc #t~mem36;call #t~mem37 := read~int(~s.base, ~s.offset + 52, 4); {18723#false} is VALID [2018-11-14 19:06:46,369 INFO L273 TraceCheckUtils]: 70: Hoare triple {18723#false} assume !(#t~mem37 == 8512);havoc #t~mem37;call #t~mem38 := read~int(~s.base, ~s.offset + 52, 4); {18723#false} is VALID [2018-11-14 19:06:46,369 INFO L273 TraceCheckUtils]: 71: Hoare triple {18723#false} assume !(#t~mem38 == 8513);havoc #t~mem38;call #t~mem39 := read~int(~s.base, ~s.offset + 52, 4); {18723#false} is VALID [2018-11-14 19:06:46,369 INFO L273 TraceCheckUtils]: 72: Hoare triple {18723#false} assume !(#t~mem39 == 8528);havoc #t~mem39;call #t~mem40 := read~int(~s.base, ~s.offset + 52, 4); {18723#false} is VALID [2018-11-14 19:06:46,369 INFO L273 TraceCheckUtils]: 73: Hoare triple {18723#false} assume !(#t~mem40 == 8529);havoc #t~mem40;call #t~mem41 := read~int(~s.base, ~s.offset + 52, 4); {18723#false} is VALID [2018-11-14 19:06:46,369 INFO L273 TraceCheckUtils]: 74: Hoare triple {18723#false} assume !(#t~mem41 == 8544);havoc #t~mem41;call #t~mem42 := read~int(~s.base, ~s.offset + 52, 4); {18723#false} is VALID [2018-11-14 19:06:46,370 INFO L273 TraceCheckUtils]: 75: Hoare triple {18723#false} assume !(#t~mem42 == 8545);havoc #t~mem42;call #t~mem43 := read~int(~s.base, ~s.offset + 52, 4); {18723#false} is VALID [2018-11-14 19:06:46,370 INFO L273 TraceCheckUtils]: 76: Hoare triple {18723#false} assume !(#t~mem43 == 8560);havoc #t~mem43;call #t~mem44 := read~int(~s.base, ~s.offset + 52, 4); {18723#false} is VALID [2018-11-14 19:06:46,370 INFO L273 TraceCheckUtils]: 77: Hoare triple {18723#false} assume !(#t~mem44 == 8561);havoc #t~mem44;call #t~mem45 := read~int(~s.base, ~s.offset + 52, 4); {18723#false} is VALID [2018-11-14 19:06:46,370 INFO L273 TraceCheckUtils]: 78: Hoare triple {18723#false} assume !(#t~mem45 == 8448);havoc #t~mem45;call #t~mem46 := read~int(~s.base, ~s.offset + 52, 4); {18723#false} is VALID [2018-11-14 19:06:46,370 INFO L273 TraceCheckUtils]: 79: Hoare triple {18723#false} assume !(#t~mem46 == 8576);havoc #t~mem46;call #t~mem47 := read~int(~s.base, ~s.offset + 52, 4); {18723#false} is VALID [2018-11-14 19:06:46,370 INFO L273 TraceCheckUtils]: 80: Hoare triple {18723#false} assume !(#t~mem47 == 8577);havoc #t~mem47;call #t~mem48 := read~int(~s.base, ~s.offset + 52, 4); {18723#false} is VALID [2018-11-14 19:06:46,370 INFO L273 TraceCheckUtils]: 81: Hoare triple {18723#false} assume !(#t~mem48 == 8592);havoc #t~mem48;call #t~mem49 := read~int(~s.base, ~s.offset + 52, 4); {18723#false} is VALID [2018-11-14 19:06:46,370 INFO L273 TraceCheckUtils]: 82: Hoare triple {18723#false} assume !(#t~mem49 == 8593);havoc #t~mem49;call #t~mem50 := read~int(~s.base, ~s.offset + 52, 4); {18723#false} is VALID [2018-11-14 19:06:46,370 INFO L273 TraceCheckUtils]: 83: Hoare triple {18723#false} assume !(#t~mem50 == 8608);havoc #t~mem50;call #t~mem51 := read~int(~s.base, ~s.offset + 52, 4); {18723#false} is VALID [2018-11-14 19:06:46,371 INFO L273 TraceCheckUtils]: 84: Hoare triple {18723#false} assume !(#t~mem51 == 8609);havoc #t~mem51;call #t~mem52 := read~int(~s.base, ~s.offset + 52, 4); {18723#false} is VALID [2018-11-14 19:06:46,371 INFO L273 TraceCheckUtils]: 85: Hoare triple {18723#false} assume !(#t~mem52 == 8640);havoc #t~mem52;call #t~mem53 := read~int(~s.base, ~s.offset + 52, 4); {18723#false} is VALID [2018-11-14 19:06:46,371 INFO L273 TraceCheckUtils]: 86: Hoare triple {18723#false} assume !(#t~mem53 == 8641);havoc #t~mem53;call #t~mem54 := read~int(~s.base, ~s.offset + 52, 4); {18723#false} is VALID [2018-11-14 19:06:46,371 INFO L273 TraceCheckUtils]: 87: Hoare triple {18723#false} assume !(#t~mem54 == 8656);havoc #t~mem54;call #t~mem55 := read~int(~s.base, ~s.offset + 52, 4); {18723#false} is VALID [2018-11-14 19:06:46,371 INFO L273 TraceCheckUtils]: 88: Hoare triple {18723#false} assume !(#t~mem55 == 8657);havoc #t~mem55;call #t~mem56 := read~int(~s.base, ~s.offset + 52, 4); {18723#false} is VALID [2018-11-14 19:06:46,371 INFO L273 TraceCheckUtils]: 89: Hoare triple {18723#false} assume #t~mem56 == 8672;havoc #t~mem56; {18723#false} is VALID [2018-11-14 19:06:46,371 INFO L273 TraceCheckUtils]: 90: Hoare triple {18723#false} assume -2147483648 <= #t~nondet121 && #t~nondet121 <= 2147483647;~ret~0 := #t~nondet121;havoc #t~nondet121; {18723#false} is VALID [2018-11-14 19:06:46,371 INFO L273 TraceCheckUtils]: 91: Hoare triple {18723#false} assume ~blastFlag~0 == 4; {18723#false} is VALID [2018-11-14 19:06:46,371 INFO L273 TraceCheckUtils]: 92: Hoare triple {18723#false} assume !false; {18723#false} is VALID [2018-11-14 19:06:46,375 INFO L134 CoverageAnalysis]: Checked inductivity of 42 backedges. 42 proven. 0 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2018-11-14 19:06:46,375 INFO L312 seRefinementStrategy]: Constructing automaton from 1 perfect and 0 imperfect interpolant sequences. [2018-11-14 19:06:46,375 INFO L327 seRefinementStrategy]: Number of different interpolants: perfect sequences [3] imperfect sequences [] total 3 [2018-11-14 19:06:46,376 INFO L78 Accepts]: Start accepts. Automaton has 3 states. Word has length 93 [2018-11-14 19:06:46,376 INFO L84 Accepts]: Finished accepts. word is accepted. [2018-11-14 19:06:46,376 INFO L86 InductivityCheck]: Starting indutivity check of a Floyd-Hoare automaton with 3 states. [2018-11-14 19:06:46,460 INFO L119 InductivityCheck]: Floyd-Hoare automaton has 93 edges. 93 inductive. 0 not inductive. 0 times theorem prover too weak to decide inductivity. [2018-11-14 19:06:46,460 INFO L459 AbstractCegarLoop]: Interpolant automaton has 3 states [2018-11-14 19:06:46,460 INFO L142 InterpolantAutomaton]: Constructing interpolant automaton starting with 3 interpolants. [2018-11-14 19:06:46,461 INFO L144 InterpolantAutomaton]: CoverageRelationStatistics Valid=3, Invalid=3, Unknown=0, NotChecked=0, Total=6 [2018-11-14 19:06:46,461 INFO L87 Difference]: Start difference. First operand 198 states and 286 transitions. Second operand 3 states. [2018-11-14 19:06:47,411 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2018-11-14 19:06:47,411 INFO L93 Difference]: Finished difference Result 537 states and 795 transitions. [2018-11-14 19:06:47,411 INFO L142 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 3 states. [2018-11-14 19:06:47,411 INFO L78 Accepts]: Start accepts. Automaton has 3 states. Word has length 93 [2018-11-14 19:06:47,411 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2018-11-14 19:06:47,412 INFO L82 GeneralOperation]: Start removeUnreachable. Operand 3 states. [2018-11-14 19:06:47,414 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 3 states to 3 states and 573 transitions. [2018-11-14 19:06:47,414 INFO L82 GeneralOperation]: Start removeUnreachable. Operand 3 states. [2018-11-14 19:06:47,416 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 3 states to 3 states and 573 transitions. [2018-11-14 19:06:47,416 INFO L86 InductivityCheck]: Starting indutivity check of a Floyd-Hoare automaton with 3 states and 573 transitions. [2018-11-14 19:06:48,029 INFO L119 InductivityCheck]: Floyd-Hoare automaton has 573 edges. 573 inductive. 0 not inductive. 0 times theorem prover too weak to decide inductivity. [2018-11-14 19:06:48,040 INFO L225 Difference]: With dead ends: 537 [2018-11-14 19:06:48,041 INFO L226 Difference]: Without dead ends: 365 [2018-11-14 19:06:48,041 INFO L604 BasicCegarLoop]: 0 DeclaredPredicates, 3 GetRequests, 2 SyntacticMatches, 0 SemanticMatches, 1 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 0 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=3, Invalid=3, Unknown=0, NotChecked=0, Total=6 [2018-11-14 19:06:48,042 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 365 states. [2018-11-14 19:06:48,098 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 365 to 365. [2018-11-14 19:06:48,098 INFO L214 AbstractMinimizeNwa]: Start testing correctness of minimizeSevpa [2018-11-14 19:06:48,098 INFO L82 GeneralOperation]: Start isEquivalent. First operand 365 states. Second operand 365 states. [2018-11-14 19:06:48,098 INFO L74 IsIncluded]: Start isIncluded. First operand 365 states. Second operand 365 states. [2018-11-14 19:06:48,099 INFO L87 Difference]: Start difference. First operand 365 states. Second operand 365 states. [2018-11-14 19:06:48,107 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2018-11-14 19:06:48,107 INFO L93 Difference]: Finished difference Result 365 states and 533 transitions. [2018-11-14 19:06:48,107 INFO L276 IsEmpty]: Start isEmpty. Operand 365 states and 533 transitions. [2018-11-14 19:06:48,108 INFO L282 IsEmpty]: Finished isEmpty. No accepting run. [2018-11-14 19:06:48,108 INFO L83 IsIncluded]: Finished isIncluded. Language is included [2018-11-14 19:06:48,108 INFO L74 IsIncluded]: Start isIncluded. First operand 365 states. Second operand 365 states. [2018-11-14 19:06:48,108 INFO L87 Difference]: Start difference. First operand 365 states. Second operand 365 states. [2018-11-14 19:06:48,116 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2018-11-14 19:06:48,117 INFO L93 Difference]: Finished difference Result 365 states and 533 transitions. [2018-11-14 19:06:48,117 INFO L276 IsEmpty]: Start isEmpty. Operand 365 states and 533 transitions. [2018-11-14 19:06:48,118 INFO L282 IsEmpty]: Finished isEmpty. No accepting run. [2018-11-14 19:06:48,118 INFO L83 IsIncluded]: Finished isIncluded. Language is included [2018-11-14 19:06:48,118 INFO L88 GeneralOperation]: Finished isEquivalent. [2018-11-14 19:06:48,118 INFO L221 AbstractMinimizeNwa]: Finished testing correctness of minimizeSevpa [2018-11-14 19:06:48,118 INFO L82 GeneralOperation]: Start removeUnreachable. Operand 365 states. [2018-11-14 19:06:48,127 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 365 states to 365 states and 533 transitions. [2018-11-14 19:06:48,127 INFO L78 Accepts]: Start accepts. Automaton has 365 states and 533 transitions. Word has length 93 [2018-11-14 19:06:48,127 INFO L84 Accepts]: Finished accepts. word is rejected. [2018-11-14 19:06:48,127 INFO L480 AbstractCegarLoop]: Abstraction has 365 states and 533 transitions. [2018-11-14 19:06:48,127 INFO L481 AbstractCegarLoop]: Interpolant automaton has 3 states. [2018-11-14 19:06:48,127 INFO L276 IsEmpty]: Start isEmpty. Operand 365 states and 533 transitions. [2018-11-14 19:06:48,128 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 94 [2018-11-14 19:06:48,128 INFO L367 BasicCegarLoop]: Found error trace [2018-11-14 19:06:48,129 INFO L375 BasicCegarLoop]: trace histogram [3, 3, 3, 3, 3, 3, 3, 3, 3, 3, 3, 2, 2, 2, 2, 2, 2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2018-11-14 19:06:48,129 INFO L423 AbstractCegarLoop]: === Iteration 21 === [ssl3_acceptErr0ASSERT_VIOLATIONERROR_FUNCTION]=== [2018-11-14 19:06:48,129 INFO L141 PredicateUnifier]: Initialized classic predicate unifier [2018-11-14 19:06:48,129 INFO L82 PathProgramCache]: Analyzing trace with hash -2096184891, now seen corresponding path program 1 times [2018-11-14 19:06:48,129 INFO L223 ckRefinementStrategy]: Switched to mode SMTINTERPOL_TREE_INTERPOLANTS [2018-11-14 19:06:48,129 INFO L69 tionRefinementEngine]: Using refinement strategy CamelRefinementStrategy [2018-11-14 19:06:48,130 INFO L119 rtionOrderModulation]: Craig_TreeInterpolation forces the order to NOT_INCREMENTALLY [2018-11-14 19:06:48,130 INFO L103 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2018-11-14 19:06:48,130 INFO L119 rtionOrderModulation]: Craig_TreeInterpolation forces the order to NOT_INCREMENTALLY [2018-11-14 19:06:48,145 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2018-11-14 19:06:48,360 INFO L256 TraceCheckUtils]: 0: Hoare triple {20511#true} call ULTIMATE.init(); {20511#true} is VALID [2018-11-14 19:06:48,360 INFO L273 TraceCheckUtils]: 1: Hoare triple {20511#true} #NULL.base, #NULL.offset := 0, 0;#valid := #valid[0 := 0];~init~0 := 1;call ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset := #Ultimate.alloc(100);call write~unchecked~int(0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 0, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 4, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 8, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 12, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 16, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 20, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 24, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 28, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 32, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 36, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 40, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 44, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 48, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 52, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 56, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 60, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 64, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 68, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 72, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 76, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 80, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 84, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 88, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 92, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 96, 4);call write~unchecked~int(0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 0, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 4, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 8, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 12, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 16, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 20, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 24, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 28, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 32, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 36, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 40, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 44, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 48, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 52, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 56, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 60, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 64, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 68, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 72, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 76, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 80, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 84, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 88, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 92, 4);call write~$Pointer$(0, 0, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset + 96, 4); {20511#true} is VALID [2018-11-14 19:06:48,360 INFO L273 TraceCheckUtils]: 2: Hoare triple {20511#true} assume true; {20511#true} is VALID [2018-11-14 19:06:48,360 INFO L268 TraceCheckUtils]: 3: Hoare quadruple {20511#true} {20511#true} #654#return; {20511#true} is VALID [2018-11-14 19:06:48,361 INFO L256 TraceCheckUtils]: 4: Hoare triple {20511#true} call #t~ret138 := main(); {20511#true} is VALID [2018-11-14 19:06:48,361 INFO L273 TraceCheckUtils]: 5: Hoare triple {20511#true} havoc ~s~0.base, ~s~0.offset;havoc ~tmp~2;call #t~malloc3.base, #t~malloc3.offset := #Ultimate.alloc(248);~s~0.base, ~s~0.offset := #t~malloc3.base, #t~malloc3.offset;call #t~malloc4.base, #t~malloc4.offset := #Ultimate.alloc(899);call write~$Pointer$(#t~malloc4.base, #t~malloc4.offset, ~s~0.base, ~s~0.offset + 84, 4);call #t~malloc5.base, #t~malloc5.offset := #Ultimate.alloc(232);call write~$Pointer$(#t~malloc5.base, #t~malloc5.offset, ~s~0.base, ~s~0.offset + 204, 4);call #t~malloc6.base, #t~malloc6.offset := #Ultimate.alloc(200);call write~$Pointer$(#t~malloc6.base, #t~malloc6.offset, ~s~0.base, ~s~0.offset + 176, 4);call write~int(8464, ~s~0.base, ~s~0.offset + 52, 4); {20511#true} is VALID [2018-11-14 19:06:48,361 INFO L256 TraceCheckUtils]: 6: Hoare triple {20511#true} call #t~ret7 := ssl3_accept(~s~0.base, ~s~0.offset); {20511#true} is VALID [2018-11-14 19:06:48,361 INFO L273 TraceCheckUtils]: 7: Hoare triple {20511#true} ~s.base, ~s.offset := #in~s.base, #in~s.offset;havoc ~buf~0.base, ~buf~0.offset;havoc ~l~0;havoc ~Time~0;havoc ~tmp~3;havoc ~cb~0.base, ~cb~0.offset;havoc ~num1~0;havoc ~ret~0;havoc ~new_state~0;havoc ~state~0;havoc ~skip~0;havoc ~got_new_session~0;assume -2147483648 <= #t~nondet8 && #t~nondet8 <= 2147483647;~tmp___1~0 := #t~nondet8;havoc #t~nondet8;assume -2147483648 <= #t~nondet9 && #t~nondet9 <= 2147483647;~tmp___2~0 := #t~nondet9;havoc #t~nondet9;assume -2147483648 <= #t~nondet10 && #t~nondet10 <= 2147483647;~tmp___3~0 := #t~nondet10;havoc #t~nondet10;assume -2147483648 <= #t~nondet11 && #t~nondet11 <= 2147483647;~tmp___4~0 := #t~nondet11;havoc #t~nondet11;assume -2147483648 <= #t~nondet12 && #t~nondet12 <= 2147483647;~tmp___5~0 := #t~nondet12;havoc #t~nondet12;assume -2147483648 <= #t~nondet13 && #t~nondet13 <= 2147483647;~tmp___6~0 := #t~nondet13;havoc #t~nondet13;havoc ~tmp___7~0;assume -2147483648 <= #t~nondet14 && #t~nondet14 <= 2147483647;~tmp___8~0 := #t~nondet14;havoc #t~nondet14;assume -2147483648 <= #t~nondet15 && #t~nondet15 <= 2147483647;~tmp___9~0 := #t~nondet15;havoc #t~nondet15;assume -2147483648 <= #t~nondet16 && #t~nondet16 <= 2147483647;~tmp___10~0 := #t~nondet16;havoc #t~nondet16;havoc ~blastFlag~0;~blastFlag~0 := 0;assume -2147483648 <= #t~nondet17 && #t~nondet17 <= 2147483647;call write~int(#t~nondet17, ~s.base, ~s.offset + 92, 4);havoc #t~nondet17;call write~int(8464, ~s.base, ~s.offset + 52, 4);assume -2147483648 <= #t~nondet18 && #t~nondet18 <= 2147483647;~tmp~3 := #t~nondet18;havoc #t~nondet18;~Time~0 := ~tmp~3;~cb~0.base, ~cb~0.offset := 0, 0;~ret~0 := -1;~skip~0 := 0;~got_new_session~0 := 0;call #t~mem19.base, #t~mem19.offset := read~$Pointer$(~s.base, ~s.offset + 192, 4); {20511#true} is VALID [2018-11-14 19:06:48,361 INFO L273 TraceCheckUtils]: 8: Hoare triple {20511#true} assume (#t~mem19.base + #t~mem19.offset) % 4294967296 != 0;havoc #t~mem19.base, #t~mem19.offset;call #t~mem20.base, #t~mem20.offset := read~$Pointer$(~s.base, ~s.offset + 192, 4);~cb~0.base, ~cb~0.offset := #t~mem20.base, #t~mem20.offset;havoc #t~mem20.base, #t~mem20.offset; {20511#true} is VALID [2018-11-14 19:06:48,361 INFO L273 TraceCheckUtils]: 9: Hoare triple {20511#true} call #t~mem21 := read~int(~s.base, ~s.offset + 28, 4);call write~int(#t~mem21 + 1, ~s.base, ~s.offset + 28, 4);havoc #t~mem21; {20511#true} is VALID [2018-11-14 19:06:48,361 INFO L273 TraceCheckUtils]: 10: Hoare triple {20511#true} assume !(~bitwiseAnd(~tmp___1~0, 12288) != 0); {20511#true} is VALID [2018-11-14 19:06:48,362 INFO L273 TraceCheckUtils]: 11: Hoare triple {20511#true} call #t~mem22.base, #t~mem22.offset := read~$Pointer$(~s.base, ~s.offset + 136, 4); {20511#true} is VALID [2018-11-14 19:06:48,362 INFO L273 TraceCheckUtils]: 12: Hoare triple {20511#true} assume !((#t~mem22.base + #t~mem22.offset) % 4294967296 == 0);havoc #t~mem22.base, #t~mem22.offset; {20511#true} is VALID [2018-11-14 19:06:48,362 INFO L273 TraceCheckUtils]: 13: Hoare triple {20511#true} assume true; {20511#true} is VALID [2018-11-14 19:06:48,362 INFO L273 TraceCheckUtils]: 14: Hoare triple {20511#true} assume !false; {20511#true} is VALID [2018-11-14 19:06:48,362 INFO L273 TraceCheckUtils]: 15: Hoare triple {20511#true} call #t~mem23 := read~int(~s.base, ~s.offset + 52, 4);~state~0 := #t~mem23;havoc #t~mem23;call #t~mem24 := read~int(~s.base, ~s.offset + 52, 4); {20511#true} is VALID [2018-11-14 19:06:48,362 INFO L273 TraceCheckUtils]: 16: Hoare triple {20511#true} assume !(#t~mem24 == 12292);havoc #t~mem24;call #t~mem25 := read~int(~s.base, ~s.offset + 52, 4); {20511#true} is VALID [2018-11-14 19:06:48,362 INFO L273 TraceCheckUtils]: 17: Hoare triple {20511#true} assume !(#t~mem25 == 16384);havoc #t~mem25;call #t~mem26 := read~int(~s.base, ~s.offset + 52, 4); {20511#true} is VALID [2018-11-14 19:06:48,362 INFO L273 TraceCheckUtils]: 18: Hoare triple {20511#true} assume !(#t~mem26 == 8192);havoc #t~mem26;call #t~mem27 := read~int(~s.base, ~s.offset + 52, 4); {20511#true} is VALID [2018-11-14 19:06:48,362 INFO L273 TraceCheckUtils]: 19: Hoare triple {20511#true} assume !(#t~mem27 == 24576);havoc #t~mem27;call #t~mem28 := read~int(~s.base, ~s.offset + 52, 4); {20511#true} is VALID [2018-11-14 19:06:48,363 INFO L273 TraceCheckUtils]: 20: Hoare triple {20511#true} assume !(#t~mem28 == 8195);havoc #t~mem28;call #t~mem29 := read~int(~s.base, ~s.offset + 52, 4); {20511#true} is VALID [2018-11-14 19:06:48,363 INFO L273 TraceCheckUtils]: 21: Hoare triple {20511#true} assume !(#t~mem29 == 8480);havoc #t~mem29;call #t~mem30 := read~int(~s.base, ~s.offset + 52, 4); {20511#true} is VALID [2018-11-14 19:06:48,363 INFO L273 TraceCheckUtils]: 22: Hoare triple {20511#true} assume !(#t~mem30 == 8481);havoc #t~mem30;call #t~mem31 := read~int(~s.base, ~s.offset + 52, 4); {20511#true} is VALID [2018-11-14 19:06:48,363 INFO L273 TraceCheckUtils]: 23: Hoare triple {20511#true} assume !(#t~mem31 == 8482);havoc #t~mem31;call #t~mem32 := read~int(~s.base, ~s.offset + 52, 4); {20511#true} is VALID [2018-11-14 19:06:48,363 INFO L273 TraceCheckUtils]: 24: Hoare triple {20511#true} assume #t~mem32 == 8464;havoc #t~mem32; {20511#true} is VALID [2018-11-14 19:06:48,363 INFO L273 TraceCheckUtils]: 25: Hoare triple {20511#true} call write~int(0, ~s.base, ~s.offset + 48, 4);assume -2147483648 <= #t~nondet69 && #t~nondet69 <= 2147483647;~ret~0 := #t~nondet69;havoc #t~nondet69; {20511#true} is VALID [2018-11-14 19:06:48,363 INFO L273 TraceCheckUtils]: 26: Hoare triple {20511#true} assume ~blastFlag~0 == 0;~blastFlag~0 := 1; {20511#true} is VALID [2018-11-14 19:06:48,363 INFO L273 TraceCheckUtils]: 27: Hoare triple {20511#true} assume !(~ret~0 <= 0);~got_new_session~0 := 1;call write~int(8496, ~s.base, ~s.offset + 52, 4);call write~int(0, ~s.base, ~s.offset + 64, 4); {20511#true} is VALID [2018-11-14 19:06:48,364 INFO L273 TraceCheckUtils]: 28: Hoare triple {20511#true} call #t~mem127.base, #t~mem127.offset := read~$Pointer$(~s.base, ~s.offset + 84, 4);call #t~mem128 := read~int(#t~mem127.base, #t~mem127.offset + 604 + 244, 4); {20511#true} is VALID [2018-11-14 19:06:48,364 INFO L273 TraceCheckUtils]: 29: Hoare triple {20511#true} assume !(#t~mem128 == 0);havoc #t~mem127.base, #t~mem127.offset;havoc #t~mem128; {20511#true} is VALID [2018-11-14 19:06:48,364 INFO L273 TraceCheckUtils]: 30: Hoare triple {20511#true} ~skip~0 := 0; {20511#true} is VALID [2018-11-14 19:06:48,364 INFO L273 TraceCheckUtils]: 31: Hoare triple {20511#true} assume true; {20511#true} is VALID [2018-11-14 19:06:48,364 INFO L273 TraceCheckUtils]: 32: Hoare triple {20511#true} assume !false; {20511#true} is VALID [2018-11-14 19:06:48,364 INFO L273 TraceCheckUtils]: 33: Hoare triple {20511#true} call #t~mem23 := read~int(~s.base, ~s.offset + 52, 4);~state~0 := #t~mem23;havoc #t~mem23;call #t~mem24 := read~int(~s.base, ~s.offset + 52, 4); {20511#true} is VALID [2018-11-14 19:06:48,364 INFO L273 TraceCheckUtils]: 34: Hoare triple {20511#true} assume !(#t~mem24 == 12292);havoc #t~mem24;call #t~mem25 := read~int(~s.base, ~s.offset + 52, 4); {20511#true} is VALID [2018-11-14 19:06:48,364 INFO L273 TraceCheckUtils]: 35: Hoare triple {20511#true} assume !(#t~mem25 == 16384);havoc #t~mem25;call #t~mem26 := read~int(~s.base, ~s.offset + 52, 4); {20511#true} is VALID [2018-11-14 19:06:48,364 INFO L273 TraceCheckUtils]: 36: Hoare triple {20511#true} assume !(#t~mem26 == 8192);havoc #t~mem26;call #t~mem27 := read~int(~s.base, ~s.offset + 52, 4); {20511#true} is VALID [2018-11-14 19:06:48,365 INFO L273 TraceCheckUtils]: 37: Hoare triple {20511#true} assume !(#t~mem27 == 24576);havoc #t~mem27;call #t~mem28 := read~int(~s.base, ~s.offset + 52, 4); {20511#true} is VALID [2018-11-14 19:06:48,365 INFO L273 TraceCheckUtils]: 38: Hoare triple {20511#true} assume !(#t~mem28 == 8195);havoc #t~mem28;call #t~mem29 := read~int(~s.base, ~s.offset + 52, 4); {20511#true} is VALID [2018-11-14 19:06:48,365 INFO L273 TraceCheckUtils]: 39: Hoare triple {20511#true} assume !(#t~mem29 == 8480);havoc #t~mem29;call #t~mem30 := read~int(~s.base, ~s.offset + 52, 4); {20511#true} is VALID [2018-11-14 19:06:48,365 INFO L273 TraceCheckUtils]: 40: Hoare triple {20511#true} assume !(#t~mem30 == 8481);havoc #t~mem30;call #t~mem31 := read~int(~s.base, ~s.offset + 52, 4); {20511#true} is VALID [2018-11-14 19:06:48,365 INFO L273 TraceCheckUtils]: 41: Hoare triple {20511#true} assume !(#t~mem31 == 8482);havoc #t~mem31;call #t~mem32 := read~int(~s.base, ~s.offset + 52, 4); {20511#true} is VALID [2018-11-14 19:06:48,365 INFO L273 TraceCheckUtils]: 42: Hoare triple {20511#true} assume !(#t~mem32 == 8464);havoc #t~mem32;call #t~mem33 := read~int(~s.base, ~s.offset + 52, 4); {20511#true} is VALID [2018-11-14 19:06:48,365 INFO L273 TraceCheckUtils]: 43: Hoare triple {20511#true} assume !(#t~mem33 == 8465);havoc #t~mem33;call #t~mem34 := read~int(~s.base, ~s.offset + 52, 4); {20511#true} is VALID [2018-11-14 19:06:48,365 INFO L273 TraceCheckUtils]: 44: Hoare triple {20511#true} assume !(#t~mem34 == 8466);havoc #t~mem34;call #t~mem35 := read~int(~s.base, ~s.offset + 52, 4); {20511#true} is VALID [2018-11-14 19:06:48,365 INFO L273 TraceCheckUtils]: 45: Hoare triple {20511#true} assume #t~mem35 == 8496;havoc #t~mem35; {20511#true} is VALID [2018-11-14 19:06:48,366 INFO L273 TraceCheckUtils]: 46: Hoare triple {20511#true} assume -2147483648 <= #t~nondet70 && #t~nondet70 <= 2147483647;~ret~0 := #t~nondet70;havoc #t~nondet70; {20511#true} is VALID [2018-11-14 19:06:48,366 INFO L273 TraceCheckUtils]: 47: Hoare triple {20511#true} assume ~blastFlag~0 == 1;~blastFlag~0 := 2; {20513#(<= ssl3_accept_~blastFlag~0 2)} is VALID [2018-11-14 19:06:48,366 INFO L273 TraceCheckUtils]: 48: Hoare triple {20513#(<= ssl3_accept_~blastFlag~0 2)} assume !(~ret~0 <= 0);call #t~mem71 := read~int(~s.base, ~s.offset + 92, 4); {20513#(<= ssl3_accept_~blastFlag~0 2)} is VALID [2018-11-14 19:06:48,371 INFO L273 TraceCheckUtils]: 49: Hoare triple {20513#(<= ssl3_accept_~blastFlag~0 2)} assume #t~mem71 != 0;havoc #t~mem71;call write~int(8656, ~s.base, ~s.offset + 52, 4); {20513#(<= ssl3_accept_~blastFlag~0 2)} is VALID [2018-11-14 19:06:48,373 INFO L273 TraceCheckUtils]: 50: Hoare triple {20513#(<= ssl3_accept_~blastFlag~0 2)} call write~int(0, ~s.base, ~s.offset + 64, 4); {20513#(<= ssl3_accept_~blastFlag~0 2)} is VALID [2018-11-14 19:06:48,373 INFO L273 TraceCheckUtils]: 51: Hoare triple {20513#(<= ssl3_accept_~blastFlag~0 2)} call #t~mem127.base, #t~mem127.offset := read~$Pointer$(~s.base, ~s.offset + 84, 4);call #t~mem128 := read~int(#t~mem127.base, #t~mem127.offset + 604 + 244, 4); {20513#(<= ssl3_accept_~blastFlag~0 2)} is VALID [2018-11-14 19:06:48,375 INFO L273 TraceCheckUtils]: 52: Hoare triple {20513#(<= ssl3_accept_~blastFlag~0 2)} assume !(#t~mem128 == 0);havoc #t~mem127.base, #t~mem127.offset;havoc #t~mem128; {20513#(<= ssl3_accept_~blastFlag~0 2)} is VALID [2018-11-14 19:06:48,375 INFO L273 TraceCheckUtils]: 53: Hoare triple {20513#(<= ssl3_accept_~blastFlag~0 2)} ~skip~0 := 0; {20513#(<= ssl3_accept_~blastFlag~0 2)} is VALID [2018-11-14 19:06:48,377 INFO L273 TraceCheckUtils]: 54: Hoare triple {20513#(<= ssl3_accept_~blastFlag~0 2)} assume true; {20513#(<= ssl3_accept_~blastFlag~0 2)} is VALID [2018-11-14 19:06:48,377 INFO L273 TraceCheckUtils]: 55: Hoare triple {20513#(<= ssl3_accept_~blastFlag~0 2)} assume !false; {20513#(<= ssl3_accept_~blastFlag~0 2)} is VALID [2018-11-14 19:06:48,377 INFO L273 TraceCheckUtils]: 56: Hoare triple {20513#(<= ssl3_accept_~blastFlag~0 2)} call #t~mem23 := read~int(~s.base, ~s.offset + 52, 4);~state~0 := #t~mem23;havoc #t~mem23;call #t~mem24 := read~int(~s.base, ~s.offset + 52, 4); {20513#(<= ssl3_accept_~blastFlag~0 2)} is VALID [2018-11-14 19:06:48,378 INFO L273 TraceCheckUtils]: 57: Hoare triple {20513#(<= ssl3_accept_~blastFlag~0 2)} assume !(#t~mem24 == 12292);havoc #t~mem24;call #t~mem25 := read~int(~s.base, ~s.offset + 52, 4); {20513#(<= ssl3_accept_~blastFlag~0 2)} is VALID [2018-11-14 19:06:48,378 INFO L273 TraceCheckUtils]: 58: Hoare triple {20513#(<= ssl3_accept_~blastFlag~0 2)} assume !(#t~mem25 == 16384);havoc #t~mem25;call #t~mem26 := read~int(~s.base, ~s.offset + 52, 4); {20513#(<= ssl3_accept_~blastFlag~0 2)} is VALID [2018-11-14 19:06:48,378 INFO L273 TraceCheckUtils]: 59: Hoare triple {20513#(<= ssl3_accept_~blastFlag~0 2)} assume !(#t~mem26 == 8192);havoc #t~mem26;call #t~mem27 := read~int(~s.base, ~s.offset + 52, 4); {20513#(<= ssl3_accept_~blastFlag~0 2)} is VALID [2018-11-14 19:06:48,378 INFO L273 TraceCheckUtils]: 60: Hoare triple {20513#(<= ssl3_accept_~blastFlag~0 2)} assume !(#t~mem27 == 24576);havoc #t~mem27;call #t~mem28 := read~int(~s.base, ~s.offset + 52, 4); {20513#(<= ssl3_accept_~blastFlag~0 2)} is VALID [2018-11-14 19:06:48,379 INFO L273 TraceCheckUtils]: 61: Hoare triple {20513#(<= ssl3_accept_~blastFlag~0 2)} assume !(#t~mem28 == 8195);havoc #t~mem28;call #t~mem29 := read~int(~s.base, ~s.offset + 52, 4); {20513#(<= ssl3_accept_~blastFlag~0 2)} is VALID [2018-11-14 19:06:48,379 INFO L273 TraceCheckUtils]: 62: Hoare triple {20513#(<= ssl3_accept_~blastFlag~0 2)} assume !(#t~mem29 == 8480);havoc #t~mem29;call #t~mem30 := read~int(~s.base, ~s.offset + 52, 4); {20513#(<= ssl3_accept_~blastFlag~0 2)} is VALID [2018-11-14 19:06:48,379 INFO L273 TraceCheckUtils]: 63: Hoare triple {20513#(<= ssl3_accept_~blastFlag~0 2)} assume !(#t~mem30 == 8481);havoc #t~mem30;call #t~mem31 := read~int(~s.base, ~s.offset + 52, 4); {20513#(<= ssl3_accept_~blastFlag~0 2)} is VALID [2018-11-14 19:06:48,380 INFO L273 TraceCheckUtils]: 64: Hoare triple {20513#(<= ssl3_accept_~blastFlag~0 2)} assume !(#t~mem31 == 8482);havoc #t~mem31;call #t~mem32 := read~int(~s.base, ~s.offset + 52, 4); {20513#(<= ssl3_accept_~blastFlag~0 2)} is VALID [2018-11-14 19:06:48,380 INFO L273 TraceCheckUtils]: 65: Hoare triple {20513#(<= ssl3_accept_~blastFlag~0 2)} assume !(#t~mem32 == 8464);havoc #t~mem32;call #t~mem33 := read~int(~s.base, ~s.offset + 52, 4); {20513#(<= ssl3_accept_~blastFlag~0 2)} is VALID [2018-11-14 19:06:48,380 INFO L273 TraceCheckUtils]: 66: Hoare triple {20513#(<= ssl3_accept_~blastFlag~0 2)} assume !(#t~mem33 == 8465);havoc #t~mem33;call #t~mem34 := read~int(~s.base, ~s.offset + 52, 4); {20513#(<= ssl3_accept_~blastFlag~0 2)} is VALID [2018-11-14 19:06:48,381 INFO L273 TraceCheckUtils]: 67: Hoare triple {20513#(<= ssl3_accept_~blastFlag~0 2)} assume !(#t~mem34 == 8466);havoc #t~mem34;call #t~mem35 := read~int(~s.base, ~s.offset + 52, 4); {20513#(<= ssl3_accept_~blastFlag~0 2)} is VALID [2018-11-14 19:06:48,381 INFO L273 TraceCheckUtils]: 68: Hoare triple {20513#(<= ssl3_accept_~blastFlag~0 2)} assume !(#t~mem35 == 8496);havoc #t~mem35;call #t~mem36 := read~int(~s.base, ~s.offset + 52, 4); {20513#(<= ssl3_accept_~blastFlag~0 2)} is VALID [2018-11-14 19:06:48,382 INFO L273 TraceCheckUtils]: 69: Hoare triple {20513#(<= ssl3_accept_~blastFlag~0 2)} assume !(#t~mem36 == 8497);havoc #t~mem36;call #t~mem37 := read~int(~s.base, ~s.offset + 52, 4); {20513#(<= ssl3_accept_~blastFlag~0 2)} is VALID [2018-11-14 19:06:48,382 INFO L273 TraceCheckUtils]: 70: Hoare triple {20513#(<= ssl3_accept_~blastFlag~0 2)} assume !(#t~mem37 == 8512);havoc #t~mem37;call #t~mem38 := read~int(~s.base, ~s.offset + 52, 4); {20513#(<= ssl3_accept_~blastFlag~0 2)} is VALID [2018-11-14 19:06:48,383 INFO L273 TraceCheckUtils]: 71: Hoare triple {20513#(<= ssl3_accept_~blastFlag~0 2)} assume !(#t~mem38 == 8513);havoc #t~mem38;call #t~mem39 := read~int(~s.base, ~s.offset + 52, 4); {20513#(<= ssl3_accept_~blastFlag~0 2)} is VALID [2018-11-14 19:06:48,383 INFO L273 TraceCheckUtils]: 72: Hoare triple {20513#(<= ssl3_accept_~blastFlag~0 2)} assume !(#t~mem39 == 8528);havoc #t~mem39;call #t~mem40 := read~int(~s.base, ~s.offset + 52, 4); {20513#(<= ssl3_accept_~blastFlag~0 2)} is VALID [2018-11-14 19:06:48,384 INFO L273 TraceCheckUtils]: 73: Hoare triple {20513#(<= ssl3_accept_~blastFlag~0 2)} assume !(#t~mem40 == 8529);havoc #t~mem40;call #t~mem41 := read~int(~s.base, ~s.offset + 52, 4); {20513#(<= ssl3_accept_~blastFlag~0 2)} is VALID [2018-11-14 19:06:48,384 INFO L273 TraceCheckUtils]: 74: Hoare triple {20513#(<= ssl3_accept_~blastFlag~0 2)} assume !(#t~mem41 == 8544);havoc #t~mem41;call #t~mem42 := read~int(~s.base, ~s.offset + 52, 4); {20513#(<= ssl3_accept_~blastFlag~0 2)} is VALID [2018-11-14 19:06:48,385 INFO L273 TraceCheckUtils]: 75: Hoare triple {20513#(<= ssl3_accept_~blastFlag~0 2)} assume !(#t~mem42 == 8545);havoc #t~mem42;call #t~mem43 := read~int(~s.base, ~s.offset + 52, 4); {20513#(<= ssl3_accept_~blastFlag~0 2)} is VALID [2018-11-14 19:06:48,385 INFO L273 TraceCheckUtils]: 76: Hoare triple {20513#(<= ssl3_accept_~blastFlag~0 2)} assume !(#t~mem43 == 8560);havoc #t~mem43;call #t~mem44 := read~int(~s.base, ~s.offset + 52, 4); {20513#(<= ssl3_accept_~blastFlag~0 2)} is VALID [2018-11-14 19:06:48,386 INFO L273 TraceCheckUtils]: 77: Hoare triple {20513#(<= ssl3_accept_~blastFlag~0 2)} assume !(#t~mem44 == 8561);havoc #t~mem44;call #t~mem45 := read~int(~s.base, ~s.offset + 52, 4); {20513#(<= ssl3_accept_~blastFlag~0 2)} is VALID [2018-11-14 19:06:48,386 INFO L273 TraceCheckUtils]: 78: Hoare triple {20513#(<= ssl3_accept_~blastFlag~0 2)} assume !(#t~mem45 == 8448);havoc #t~mem45;call #t~mem46 := read~int(~s.base, ~s.offset + 52, 4); {20513#(<= ssl3_accept_~blastFlag~0 2)} is VALID [2018-11-14 19:06:48,387 INFO L273 TraceCheckUtils]: 79: Hoare triple {20513#(<= ssl3_accept_~blastFlag~0 2)} assume !(#t~mem46 == 8576);havoc #t~mem46;call #t~mem47 := read~int(~s.base, ~s.offset + 52, 4); {20513#(<= ssl3_accept_~blastFlag~0 2)} is VALID [2018-11-14 19:06:48,387 INFO L273 TraceCheckUtils]: 80: Hoare triple {20513#(<= ssl3_accept_~blastFlag~0 2)} assume !(#t~mem47 == 8577);havoc #t~mem47;call #t~mem48 := read~int(~s.base, ~s.offset + 52, 4); {20513#(<= ssl3_accept_~blastFlag~0 2)} is VALID [2018-11-14 19:06:48,388 INFO L273 TraceCheckUtils]: 81: Hoare triple {20513#(<= ssl3_accept_~blastFlag~0 2)} assume !(#t~mem48 == 8592);havoc #t~mem48;call #t~mem49 := read~int(~s.base, ~s.offset + 52, 4); {20513#(<= ssl3_accept_~blastFlag~0 2)} is VALID [2018-11-14 19:06:48,388 INFO L273 TraceCheckUtils]: 82: Hoare triple {20513#(<= ssl3_accept_~blastFlag~0 2)} assume !(#t~mem49 == 8593);havoc #t~mem49;call #t~mem50 := read~int(~s.base, ~s.offset + 52, 4); {20513#(<= ssl3_accept_~blastFlag~0 2)} is VALID [2018-11-14 19:06:48,389 INFO L273 TraceCheckUtils]: 83: Hoare triple {20513#(<= ssl3_accept_~blastFlag~0 2)} assume !(#t~mem50 == 8608);havoc #t~mem50;call #t~mem51 := read~int(~s.base, ~s.offset + 52, 4); {20513#(<= ssl3_accept_~blastFlag~0 2)} is VALID [2018-11-14 19:06:48,389 INFO L273 TraceCheckUtils]: 84: Hoare triple {20513#(<= ssl3_accept_~blastFlag~0 2)} assume !(#t~mem51 == 8609);havoc #t~mem51;call #t~mem52 := read~int(~s.base, ~s.offset + 52, 4); {20513#(<= ssl3_accept_~blastFlag~0 2)} is VALID [2018-11-14 19:06:48,389 INFO L273 TraceCheckUtils]: 85: Hoare triple {20513#(<= ssl3_accept_~blastFlag~0 2)} assume !(#t~mem52 == 8640);havoc #t~mem52;call #t~mem53 := read~int(~s.base, ~s.offset + 52, 4); {20513#(<= ssl3_accept_~blastFlag~0 2)} is VALID [2018-11-14 19:06:48,390 INFO L273 TraceCheckUtils]: 86: Hoare triple {20513#(<= ssl3_accept_~blastFlag~0 2)} assume !(#t~mem53 == 8641);havoc #t~mem53;call #t~mem54 := read~int(~s.base, ~s.offset + 52, 4); {20513#(<= ssl3_accept_~blastFlag~0 2)} is VALID [2018-11-14 19:06:48,390 INFO L273 TraceCheckUtils]: 87: Hoare triple {20513#(<= ssl3_accept_~blastFlag~0 2)} assume !(#t~mem54 == 8656);havoc #t~mem54;call #t~mem55 := read~int(~s.base, ~s.offset + 52, 4); {20513#(<= ssl3_accept_~blastFlag~0 2)} is VALID [2018-11-14 19:06:48,391 INFO L273 TraceCheckUtils]: 88: Hoare triple {20513#(<= ssl3_accept_~blastFlag~0 2)} assume !(#t~mem55 == 8657);havoc #t~mem55;call #t~mem56 := read~int(~s.base, ~s.offset + 52, 4); {20513#(<= ssl3_accept_~blastFlag~0 2)} is VALID [2018-11-14 19:06:48,391 INFO L273 TraceCheckUtils]: 89: Hoare triple {20513#(<= ssl3_accept_~blastFlag~0 2)} assume #t~mem56 == 8672;havoc #t~mem56; {20513#(<= ssl3_accept_~blastFlag~0 2)} is VALID [2018-11-14 19:06:48,392 INFO L273 TraceCheckUtils]: 90: Hoare triple {20513#(<= ssl3_accept_~blastFlag~0 2)} assume -2147483648 <= #t~nondet121 && #t~nondet121 <= 2147483647;~ret~0 := #t~nondet121;havoc #t~nondet121; {20513#(<= ssl3_accept_~blastFlag~0 2)} is VALID [2018-11-14 19:06:48,392 INFO L273 TraceCheckUtils]: 91: Hoare triple {20513#(<= ssl3_accept_~blastFlag~0 2)} assume ~blastFlag~0 == 4; {20512#false} is VALID [2018-11-14 19:06:48,393 INFO L273 TraceCheckUtils]: 92: Hoare triple {20512#false} assume !false; {20512#false} is VALID [2018-11-14 19:06:48,399 INFO L134 CoverageAnalysis]: Checked inductivity of 42 backedges. 30 proven. 0 refuted. 0 times theorem prover too weak. 12 trivial. 0 not checked. [2018-11-14 19:06:48,399 INFO L312 seRefinementStrategy]: Constructing automaton from 1 perfect and 0 imperfect interpolant sequences. [2018-11-14 19:06:48,399 INFO L327 seRefinementStrategy]: Number of different interpolants: perfect sequences [3] imperfect sequences [] total 3 [2018-11-14 19:06:48,400 INFO L78 Accepts]: Start accepts. Automaton has 3 states. Word has length 93 [2018-11-14 19:06:48,400 INFO L84 Accepts]: Finished accepts. word is accepted. [2018-11-14 19:06:48,400 INFO L86 InductivityCheck]: Starting indutivity check of a Floyd-Hoare automaton with 3 states. [2018-11-14 19:06:48,496 INFO L119 InductivityCheck]: Floyd-Hoare automaton has 82 edges. 82 inductive. 0 not inductive. 0 times theorem prover too weak to decide inductivity. [2018-11-14 19:06:48,496 INFO L459 AbstractCegarLoop]: Interpolant automaton has 3 states [2018-11-14 19:06:48,496 INFO L142 InterpolantAutomaton]: Constructing interpolant automaton starting with 3 interpolants. [2018-11-14 19:06:48,496 INFO L144 InterpolantAutomaton]: CoverageRelationStatistics Valid=3, Invalid=3, Unknown=0, NotChecked=0, Total=6 [2018-11-14 19:06:48,497 INFO L87 Difference]: Start difference. First operand 365 states and 533 transitions. Second operand 3 states. [2018-11-14 19:06:49,158 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2018-11-14 19:06:49,158 INFO L93 Difference]: Finished difference Result 874 states and 1293 transitions. [2018-11-14 19:06:49,158 INFO L142 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 3 states. [2018-11-14 19:06:49,158 INFO L78 Accepts]: Start accepts. Automaton has 3 states. Word has length 93 [2018-11-14 19:06:49,158 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2018-11-14 19:06:49,159 INFO L82 GeneralOperation]: Start removeUnreachable. Operand 3 states. [2018-11-14 19:06:49,161 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 3 states to 3 states and 577 transitions. [2018-11-14 19:06:49,161 INFO L82 GeneralOperation]: Start removeUnreachable. Operand 3 states. [2018-11-14 19:06:49,163 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 3 states to 3 states and 577 transitions. [2018-11-14 19:06:49,163 INFO L86 InductivityCheck]: Starting indutivity check of a Floyd-Hoare automaton with 3 states and 577 transitions. [2018-11-14 19:06:49,679 INFO L119 InductivityCheck]: Floyd-Hoare automaton has 577 edges. 577 inductive. 0 not inductive. 0 times theorem prover too weak to decide inductivity. [2018-11-14 19:06:49,694 INFO L225 Difference]: With dead ends: 874 [2018-11-14 19:06:49,694 INFO L226 Difference]: Without dead ends: 535 [2018-11-14 19:06:49,695 INFO L604 BasicCegarLoop]: 0 DeclaredPredicates, 3 GetRequests, 2 SyntacticMatches, 0 SemanticMatches, 1 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 0 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=3, Invalid=3, Unknown=0, NotChecked=0, Total=6 [2018-11-14 19:06:49,695 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 535 states. [2018-11-14 19:06:49,830 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 535 to 535. [2018-11-14 19:06:49,830 INFO L214 AbstractMinimizeNwa]: Start testing correctness of minimizeSevpa [2018-11-14 19:06:49,830 INFO L82 GeneralOperation]: Start isEquivalent. First operand 535 states. Second operand 535 states. [2018-11-14 19:06:49,830 INFO L74 IsIncluded]: Start isIncluded. First operand 535 states. Second operand 535 states. [2018-11-14 19:06:49,830 INFO L87 Difference]: Start difference. First operand 535 states. Second operand 535 states. [2018-11-14 19:06:49,844 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2018-11-14 19:06:49,844 INFO L93 Difference]: Finished difference Result 535 states and 787 transitions. [2018-11-14 19:06:49,844 INFO L276 IsEmpty]: Start isEmpty. Operand 535 states and 787 transitions. [2018-11-14 19:06:49,845 INFO L282 IsEmpty]: Finished isEmpty. No accepting run. [2018-11-14 19:06:49,845 INFO L83 IsIncluded]: Finished isIncluded. Language is included [2018-11-14 19:06:49,845 INFO L74 IsIncluded]: Start isIncluded. First operand 535 states. Second operand 535 states. [2018-11-14 19:06:49,845 INFO L87 Difference]: Start difference. First operand 535 states. Second operand 535 states. [2018-11-14 19:06:49,862 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2018-11-14 19:06:49,863 INFO L93 Difference]: Finished difference Result 535 states and 787 transitions. [2018-11-14 19:06:49,863 INFO L276 IsEmpty]: Start isEmpty. Operand 535 states and 787 transitions. [2018-11-14 19:06:49,864 INFO L282 IsEmpty]: Finished isEmpty. No accepting run. [2018-11-14 19:06:49,864 INFO L83 IsIncluded]: Finished isIncluded. Language is included [2018-11-14 19:06:49,864 INFO L88 GeneralOperation]: Finished isEquivalent. [2018-11-14 19:06:49,864 INFO L221 AbstractMinimizeNwa]: Finished testing correctness of minimizeSevpa [2018-11-14 19:06:49,865 INFO L82 GeneralOperation]: Start removeUnreachable. Operand 535 states. [2018-11-14 19:06:49,882 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 535 states to 535 states and 787 transitions. [2018-11-14 19:06:49,883 INFO L78 Accepts]: Start accepts. Automaton has 535 states and 787 transitions. Word has length 93 [2018-11-14 19:06:49,883 INFO L84 Accepts]: Finished accepts. word is rejected. [2018-11-14 19:06:49,883 INFO L480 AbstractCegarLoop]: Abstraction has 535 states and 787 transitions. [2018-11-14 19:06:49,883 INFO L481 AbstractCegarLoop]: Interpolant automaton has 3 states. [2018-11-14 19:06:49,883 INFO L276 IsEmpty]: Start isEmpty. Operand 535 states and 787 transitions. [2018-11-14 19:06:49,884 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 136 [2018-11-14 19:06:49,884 INFO L367 BasicCegarLoop]: Found error trace [2018-11-14 19:06:49,884 INFO L375 BasicCegarLoop]: trace histogram [4, 4, 4, 4, 4, 4, 4, 4, 4, 4, 4, 3, 3, 3, 3, 3, 3, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2018-11-14 19:06:49,885 INFO L423 AbstractCegarLoop]: === Iteration 22 === [ssl3_acceptErr0ASSERT_VIOLATIONERROR_FUNCTION]=== [2018-11-14 19:06:49,885 INFO L141 PredicateUnifier]: Initialized classic predicate unifier [2018-11-14 19:06:49,885 INFO L82 PathProgramCache]: Analyzing trace with hash -2091830027, now seen corresponding path program 1 times [2018-11-14 19:06:49,885 INFO L223 ckRefinementStrategy]: Switched to mode SMTINTERPOL_TREE_INTERPOLANTS [2018-11-14 19:06:49,885 INFO L69 tionRefinementEngine]: Using refinement strategy CamelRefinementStrategy [2018-11-14 19:06:49,886 INFO L119 rtionOrderModulation]: Craig_TreeInterpolation forces the order to NOT_INCREMENTALLY [2018-11-14 19:06:49,886 INFO L103 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2018-11-14 19:06:49,886 INFO L119 rtionOrderModulation]: Craig_TreeInterpolation forces the order to NOT_INCREMENTALLY [2018-11-14 19:06:50,063 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is sat [2018-11-14 19:06:50,114 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is sat [2018-11-14 19:06:50,196 INFO L442 BasicCegarLoop]: Counterexample might be feasible [2018-11-14 19:06:50,268 WARN L1239 BoogieBacktranslator]: Unfinished Backtranslation: IntegerLiteral 24586 could not be translated for associated CType STRUCT~~ssl_method_st?version~INT?ssl_new~*((*~SSL~0 ) : INT)?ssl_clear~*((*~SSL~0 ) : VOID)?ssl_free~*((*~SSL~0 ) : VOID)?ssl_accept~*((*~SSL~0 ) : INT)?ssl_connect~*((*~SSL~0 ) : INT)?ssl_read~*((*~SSL~0 *VOID INT ) : INT)?ssl_peek~*((*~SSL~0 *VOID INT ) : INT)?ssl_write~*((*~SSL~0 *VOID INT ) : INT)?ssl_shutdown~*((*~SSL~0 ) : INT)?ssl_renegotiate~*((*~SSL~0 ) : INT)?ssl_renegotiate_check~*((*~SSL~0 ) : INT)?ssl_ctrl~*((*~SSL~0 INT LONG *CHAR ) : LONG)?ssl_ctx_ctrl~*((*~SSL_CTX~0 INT LONG *CHAR ) : LONG)?get_cipher_by_char~*((*UCHAR ) : *~SSL_CIPHER~0)?put_cipher_by_char~*((*~SSL_CIPHER~0 *UCHAR ) : INT)?ssl_pending~*((*~SSL~0 ) : INT)?num_ciphers~*(() : INT)?get_cipher~*((UINT ) : *~SSL_CIPHER~0)?get_ssl_method~*((INT ) : *ssl_method_st)?get_timeout~*(() : LONG)?ssl3_enc~*ssl3_enc_method?ssl_version~*(() : INT)?ssl_callback_ctrl~*((*~SSL~0 INT *(() : VOID) ) : LONG)?ssl_ctx_callback_ctrl~*((*~SSL_CTX~0 INT *(() : VOID) ) : LONG)# [2018-11-14 19:06:50,270 WARN L1239 BoogieBacktranslator]: Unfinished Backtranslation: IntegerLiteral 24589 could not be translated for associated CType STRUCT~~ssl_method_st?version~INT?ssl_new~*((*~SSL~0 ) : INT)?ssl_clear~*((*~SSL~0 ) : VOID)?ssl_free~*((*~SSL~0 ) : VOID)?ssl_accept~*((*~SSL~0 ) : INT)?ssl_connect~*((*~SSL~0 ) : INT)?ssl_read~*((*~SSL~0 *VOID INT ) : INT)?ssl_peek~*((*~SSL~0 *VOID INT ) : INT)?ssl_write~*((*~SSL~0 *VOID INT ) : INT)?ssl_shutdown~*((*~SSL~0 ) : INT)?ssl_renegotiate~*((*~SSL~0 ) : INT)?ssl_renegotiate_check~*((*~SSL~0 ) : INT)?ssl_ctrl~*((*~SSL~0 INT LONG *CHAR ) : LONG)?ssl_ctx_ctrl~*((*~SSL_CTX~0 INT LONG *CHAR ) : LONG)?get_cipher_by_char~*((*UCHAR ) : *~SSL_CIPHER~0)?put_cipher_by_char~*((*~SSL_CIPHER~0 *UCHAR ) : INT)?ssl_pending~*((*~SSL~0 ) : INT)?num_ciphers~*(() : INT)?get_cipher~*((UINT ) : *~SSL_CIPHER~0)?get_ssl_method~*((INT ) : *ssl_method_st)?get_timeout~*(() : LONG)?ssl3_enc~*ssl3_enc_method?ssl_version~*(() : INT)?ssl_callback_ctrl~*((*~SSL~0 INT *(() : VOID) ) : LONG)?ssl_ctx_callback_ctrl~*((*~SSL_CTX~0 INT *(() : VOID) ) : LONG)# [2018-11-14 19:06:50,371 WARN L170 areAnnotationChecker]: SSLv3_server_methodENTRY has no Hoare annotation [2018-11-14 19:06:50,371 WARN L170 areAnnotationChecker]: ULTIMATE.initENTRY has no Hoare annotation [2018-11-14 19:06:50,372 WARN L170 areAnnotationChecker]: ULTIMATE.startENTRY has no Hoare annotation [2018-11-14 19:06:50,372 WARN L170 areAnnotationChecker]: ULTIMATE.startENTRY has no Hoare annotation [2018-11-14 19:06:50,372 WARN L170 areAnnotationChecker]: mainENTRY has no Hoare annotation [2018-11-14 19:06:50,372 WARN L170 areAnnotationChecker]: #Ultimate.C_memcpyENTRY has no Hoare annotation [2018-11-14 19:06:50,372 WARN L170 areAnnotationChecker]: sslv3_base_methodENTRY has no Hoare annotation [2018-11-14 19:06:50,372 WARN L170 areAnnotationChecker]: #Ultimate.meminitENTRY has no Hoare annotation [2018-11-14 19:06:50,372 WARN L170 areAnnotationChecker]: ssl3_acceptENTRY has no Hoare annotation [2018-11-14 19:06:50,372 WARN L170 areAnnotationChecker]: ssl3_get_server_methodENTRY has no Hoare annotation [2018-11-14 19:06:50,372 WARN L170 areAnnotationChecker]: L1049 has no Hoare annotation [2018-11-14 19:06:50,372 WARN L170 areAnnotationChecker]: L1049 has no Hoare annotation [2018-11-14 19:06:50,372 WARN L170 areAnnotationChecker]: ULTIMATE.initFINAL has no Hoare annotation [2018-11-14 19:06:50,373 WARN L170 areAnnotationChecker]: L-1 has no Hoare annotation [2018-11-14 19:06:50,373 WARN L170 areAnnotationChecker]: L-1 has no Hoare annotation [2018-11-14 19:06:50,373 WARN L170 areAnnotationChecker]: L1075 has no Hoare annotation [2018-11-14 19:06:50,373 WARN L170 areAnnotationChecker]: L1075 has no Hoare annotation [2018-11-14 19:06:50,373 WARN L170 areAnnotationChecker]: L-1-1 has no Hoare annotation [2018-11-14 19:06:50,373 WARN L170 areAnnotationChecker]: L-1-1 has no Hoare annotation [2018-11-14 19:06:50,373 WARN L170 areAnnotationChecker]: L1712 has no Hoare annotation [2018-11-14 19:06:50,373 WARN L170 areAnnotationChecker]: L1712 has no Hoare annotation [2018-11-14 19:06:50,373 WARN L170 areAnnotationChecker]: L-1-1 has no Hoare annotation [2018-11-14 19:06:50,374 WARN L170 areAnnotationChecker]: L-1-1 has no Hoare annotation [2018-11-14 19:06:50,374 WARN L170 areAnnotationChecker]: L1115 has no Hoare annotation [2018-11-14 19:06:50,374 WARN L170 areAnnotationChecker]: L1115 has no Hoare annotation [2018-11-14 19:06:50,374 WARN L170 areAnnotationChecker]: L1032 has no Hoare annotation [2018-11-14 19:06:50,374 WARN L170 areAnnotationChecker]: L1032 has no Hoare annotation [2018-11-14 19:06:50,374 WARN L170 areAnnotationChecker]: L1051 has no Hoare annotation [2018-11-14 19:06:50,374 WARN L170 areAnnotationChecker]: L1051 has no Hoare annotation [2018-11-14 19:06:50,374 WARN L170 areAnnotationChecker]: L1049-2 has no Hoare annotation [2018-11-14 19:06:50,374 WARN L170 areAnnotationChecker]: ULTIMATE.initEXIT has no Hoare annotation [2018-11-14 19:06:50,374 WARN L170 areAnnotationChecker]: ULTIMATE.startFINAL has no Hoare annotation [2018-11-14 19:06:50,374 WARN L170 areAnnotationChecker]: L1075-1 has no Hoare annotation [2018-11-14 19:06:50,375 WARN L170 areAnnotationChecker]: #Ultimate.C_memcpyFINAL has no Hoare annotation [2018-11-14 19:06:50,375 WARN L170 areAnnotationChecker]: L1712-1 has no Hoare annotation [2018-11-14 19:06:50,375 WARN L170 areAnnotationChecker]: #Ultimate.meminitFINAL has no Hoare annotation [2018-11-14 19:06:50,375 WARN L170 areAnnotationChecker]: L1115-2 has no Hoare annotation [2018-11-14 19:06:50,375 WARN L170 areAnnotationChecker]: L1034 has no Hoare annotation [2018-11-14 19:06:50,375 WARN L170 areAnnotationChecker]: L1034 has no Hoare annotation [2018-11-14 19:06:50,375 WARN L170 areAnnotationChecker]: ssl3_get_server_methodFINAL has no Hoare annotation [2018-11-14 19:06:50,375 WARN L170 areAnnotationChecker]: L1051-1 has no Hoare annotation [2018-11-14 19:06:50,375 WARN L170 areAnnotationChecker]: SSLv3_server_methodFINAL has no Hoare annotation [2018-11-14 19:06:50,375 WARN L170 areAnnotationChecker]: mainFINAL has no Hoare annotation [2018-11-14 19:06:50,376 WARN L170 areAnnotationChecker]: #Ultimate.C_memcpyEXIT has no Hoare annotation [2018-11-14 19:06:50,376 WARN L170 areAnnotationChecker]: sslv3_base_methodFINAL has no Hoare annotation [2018-11-14 19:06:50,376 WARN L170 areAnnotationChecker]: #Ultimate.meminitEXIT has no Hoare annotation [2018-11-14 19:06:50,376 WARN L170 areAnnotationChecker]: L1121 has no Hoare annotation [2018-11-14 19:06:50,376 WARN L170 areAnnotationChecker]: L1121 has no Hoare annotation [2018-11-14 19:06:50,376 WARN L170 areAnnotationChecker]: L1034-1 has no Hoare annotation [2018-11-14 19:06:50,376 WARN L170 areAnnotationChecker]: L1053 has no Hoare annotation [2018-11-14 19:06:50,376 WARN L170 areAnnotationChecker]: L1053 has no Hoare annotation [2018-11-14 19:06:50,376 WARN L170 areAnnotationChecker]: SSLv3_server_methodEXIT has no Hoare annotation [2018-11-14 19:06:50,376 WARN L170 areAnnotationChecker]: mainEXIT has no Hoare annotation [2018-11-14 19:06:50,377 WARN L170 areAnnotationChecker]: L1053-1 has no Hoare annotation [2018-11-14 19:06:50,377 WARN L170 areAnnotationChecker]: sslv3_base_methodEXIT has no Hoare annotation [2018-11-14 19:06:50,377 WARN L170 areAnnotationChecker]: L1122 has no Hoare annotation [2018-11-14 19:06:50,377 WARN L170 areAnnotationChecker]: L1122 has no Hoare annotation [2018-11-14 19:06:50,377 WARN L170 areAnnotationChecker]: L1121-1 has no Hoare annotation [2018-11-14 19:06:50,377 WARN L170 areAnnotationChecker]: L1130 has no Hoare annotation [2018-11-14 19:06:50,377 WARN L170 areAnnotationChecker]: L1130 has no Hoare annotation [2018-11-14 19:06:50,377 WARN L170 areAnnotationChecker]: ssl3_acceptFINAL has no Hoare annotation [2018-11-14 19:06:50,377 WARN L170 areAnnotationChecker]: L1136-3 has no Hoare annotation [2018-11-14 19:06:50,377 WARN L170 areAnnotationChecker]: L1136-3 has no Hoare annotation [2018-11-14 19:06:50,378 WARN L170 areAnnotationChecker]: ssl3_acceptEXIT has no Hoare annotation [2018-11-14 19:06:50,378 WARN L170 areAnnotationChecker]: L1136-1 has no Hoare annotation [2018-11-14 19:06:50,378 WARN L170 areAnnotationChecker]: L1136-1 has no Hoare annotation [2018-11-14 19:06:50,378 WARN L170 areAnnotationChecker]: L1692 has no Hoare annotation [2018-11-14 19:06:50,378 WARN L170 areAnnotationChecker]: L1137 has no Hoare annotation [2018-11-14 19:06:50,378 WARN L170 areAnnotationChecker]: L1696 has no Hoare annotation [2018-11-14 19:06:50,378 WARN L170 areAnnotationChecker]: L1696 has no Hoare annotation [2018-11-14 19:06:50,378 WARN L170 areAnnotationChecker]: L1139 has no Hoare annotation [2018-11-14 19:06:50,378 WARN L170 areAnnotationChecker]: L1139 has no Hoare annotation [2018-11-14 19:06:50,378 WARN L170 areAnnotationChecker]: L1696-2 has no Hoare annotation [2018-11-14 19:06:50,379 WARN L170 areAnnotationChecker]: L1140 has no Hoare annotation [2018-11-14 19:06:50,379 WARN L170 areAnnotationChecker]: L1142 has no Hoare annotation [2018-11-14 19:06:50,379 WARN L170 areAnnotationChecker]: L1142 has no Hoare annotation [2018-11-14 19:06:50,379 WARN L170 areAnnotationChecker]: L1249 has no Hoare annotation [2018-11-14 19:06:50,379 WARN L170 areAnnotationChecker]: L1145 has no Hoare annotation [2018-11-14 19:06:50,379 WARN L170 areAnnotationChecker]: L1145 has no Hoare annotation [2018-11-14 19:06:50,379 WARN L170 areAnnotationChecker]: L1254 has no Hoare annotation [2018-11-14 19:06:50,379 WARN L170 areAnnotationChecker]: L1254 has no Hoare annotation [2018-11-14 19:06:50,379 WARN L170 areAnnotationChecker]: L1148 has no Hoare annotation [2018-11-14 19:06:50,379 WARN L170 areAnnotationChecker]: L1148 has no Hoare annotation [2018-11-14 19:06:50,380 WARN L170 areAnnotationChecker]: L1254-2 has no Hoare annotation [2018-11-14 19:06:50,380 WARN L170 areAnnotationChecker]: L1151 has no Hoare annotation [2018-11-14 19:06:50,380 WARN L170 areAnnotationChecker]: L1151 has no Hoare annotation [2018-11-14 19:06:50,380 WARN L170 areAnnotationChecker]: L1259 has no Hoare annotation [2018-11-14 19:06:50,380 WARN L170 areAnnotationChecker]: L1259 has no Hoare annotation [2018-11-14 19:06:50,380 WARN L170 areAnnotationChecker]: L1154 has no Hoare annotation [2018-11-14 19:06:50,380 WARN L170 areAnnotationChecker]: L1154 has no Hoare annotation [2018-11-14 19:06:50,380 WARN L170 areAnnotationChecker]: L1265 has no Hoare annotation [2018-11-14 19:06:50,380 WARN L170 areAnnotationChecker]: L1265 has no Hoare annotation [2018-11-14 19:06:50,380 WARN L170 areAnnotationChecker]: L1158 has no Hoare annotation [2018-11-14 19:06:50,380 WARN L170 areAnnotationChecker]: L1157 has no Hoare annotation [2018-11-14 19:06:50,381 WARN L170 areAnnotationChecker]: L1157 has no Hoare annotation [2018-11-14 19:06:50,381 WARN L170 areAnnotationChecker]: L1267 has no Hoare annotation [2018-11-14 19:06:50,381 WARN L170 areAnnotationChecker]: L1267 has no Hoare annotation [2018-11-14 19:06:50,381 WARN L170 areAnnotationChecker]: L1265-2 has no Hoare annotation [2018-11-14 19:06:50,381 WARN L170 areAnnotationChecker]: L1265-2 has no Hoare annotation [2018-11-14 19:06:50,381 WARN L170 areAnnotationChecker]: L1308 has no Hoare annotation [2018-11-14 19:06:50,381 WARN L170 areAnnotationChecker]: L1308 has no Hoare annotation [2018-11-14 19:06:50,381 WARN L170 areAnnotationChecker]: L1160 has no Hoare annotation [2018-11-14 19:06:50,381 WARN L170 areAnnotationChecker]: L1160 has no Hoare annotation [2018-11-14 19:06:50,381 WARN L170 areAnnotationChecker]: L1273 has no Hoare annotation [2018-11-14 19:06:50,381 WARN L170 areAnnotationChecker]: L1273 has no Hoare annotation [2018-11-14 19:06:50,382 WARN L170 areAnnotationChecker]: L1290 has no Hoare annotation [2018-11-14 19:06:50,382 WARN L170 areAnnotationChecker]: L1290 has no Hoare annotation [2018-11-14 19:06:50,382 WARN L170 areAnnotationChecker]: L1623 has no Hoare annotation [2018-11-14 19:06:50,382 WARN L170 areAnnotationChecker]: L1161 has no Hoare annotation [2018-11-14 19:06:50,382 WARN L170 areAnnotationChecker]: L1163 has no Hoare annotation [2018-11-14 19:06:50,382 WARN L170 areAnnotationChecker]: L1163 has no Hoare annotation [2018-11-14 19:06:50,382 WARN L170 areAnnotationChecker]: L1291 has no Hoare annotation [2018-11-14 19:06:50,382 WARN L170 areAnnotationChecker]: L1291 has no Hoare annotation [2018-11-14 19:06:50,382 WARN L170 areAnnotationChecker]: L1661 has no Hoare annotation [2018-11-14 19:06:50,382 WARN L170 areAnnotationChecker]: L1661 has no Hoare annotation [2018-11-14 19:06:50,383 WARN L170 areAnnotationChecker]: L1170 has no Hoare annotation [2018-11-14 19:06:50,383 WARN L170 areAnnotationChecker]: L1166 has no Hoare annotation [2018-11-14 19:06:50,383 WARN L170 areAnnotationChecker]: L1166 has no Hoare annotation [2018-11-14 19:06:50,383 WARN L170 areAnnotationChecker]: L1662 has no Hoare annotation [2018-11-14 19:06:50,383 WARN L170 areAnnotationChecker]: L1662 has no Hoare annotation [2018-11-14 19:06:50,383 WARN L170 areAnnotationChecker]: L1661-1 has no Hoare annotation [2018-11-14 19:06:50,383 WARN L170 areAnnotationChecker]: L1325 has no Hoare annotation [2018-11-14 19:06:50,383 WARN L170 areAnnotationChecker]: L1325 has no Hoare annotation [2018-11-14 19:06:50,383 WARN L170 areAnnotationChecker]: L1169 has no Hoare annotation [2018-11-14 19:06:50,383 WARN L170 areAnnotationChecker]: L1169 has no Hoare annotation [2018-11-14 19:06:50,383 WARN L170 areAnnotationChecker]: L1663 has no Hoare annotation [2018-11-14 19:06:50,384 WARN L170 areAnnotationChecker]: L1663 has no Hoare annotation [2018-11-14 19:06:50,384 WARN L170 areAnnotationChecker]: L1325-2 has no Hoare annotation [2018-11-14 19:06:50,384 WARN L170 areAnnotationChecker]: L1325-2 has no Hoare annotation [2018-11-14 19:06:50,384 WARN L170 areAnnotationChecker]: L1172 has no Hoare annotation [2018-11-14 19:06:50,384 WARN L170 areAnnotationChecker]: L1172 has no Hoare annotation [2018-11-14 19:06:50,384 WARN L170 areAnnotationChecker]: L1665 has no Hoare annotation [2018-11-14 19:06:50,384 WARN L170 areAnnotationChecker]: L1665 has no Hoare annotation [2018-11-14 19:06:50,384 WARN L170 areAnnotationChecker]: L1663-2 has no Hoare annotation [2018-11-14 19:06:50,384 WARN L170 areAnnotationChecker]: L1663-2 has no Hoare annotation [2018-11-14 19:06:50,384 WARN L170 areAnnotationChecker]: L1176 has no Hoare annotation [2018-11-14 19:06:50,384 WARN L170 areAnnotationChecker]: L1175 has no Hoare annotation [2018-11-14 19:06:50,385 WARN L170 areAnnotationChecker]: L1175 has no Hoare annotation [2018-11-14 19:06:50,385 WARN L170 areAnnotationChecker]: L1674 has no Hoare annotation [2018-11-14 19:06:50,385 WARN L170 areAnnotationChecker]: L1674 has no Hoare annotation [2018-11-14 19:06:50,385 WARN L170 areAnnotationChecker]: L1342 has no Hoare annotation [2018-11-14 19:06:50,385 WARN L170 areAnnotationChecker]: L1342 has no Hoare annotation [2018-11-14 19:06:50,385 WARN L170 areAnnotationChecker]: L1178 has no Hoare annotation [2018-11-14 19:06:50,385 WARN L170 areAnnotationChecker]: L1178 has no Hoare annotation [2018-11-14 19:06:50,385 WARN L170 areAnnotationChecker]: L1342-2 has no Hoare annotation [2018-11-14 19:06:50,385 WARN L170 areAnnotationChecker]: L1342-2 has no Hoare annotation [2018-11-14 19:06:50,385 WARN L170 areAnnotationChecker]: L1182 has no Hoare annotation [2018-11-14 19:06:50,386 WARN L170 areAnnotationChecker]: L1181 has no Hoare annotation [2018-11-14 19:06:50,386 WARN L170 areAnnotationChecker]: L1181 has no Hoare annotation [2018-11-14 19:06:50,386 WARN L170 areAnnotationChecker]: L1352 has no Hoare annotation [2018-11-14 19:06:50,386 WARN L170 areAnnotationChecker]: L1352 has no Hoare annotation [2018-11-14 19:06:50,386 WARN L170 areAnnotationChecker]: L1361 has no Hoare annotation [2018-11-14 19:06:50,386 WARN L170 areAnnotationChecker]: L1361 has no Hoare annotation [2018-11-14 19:06:50,386 WARN L170 areAnnotationChecker]: L1184 has no Hoare annotation [2018-11-14 19:06:50,386 WARN L170 areAnnotationChecker]: L1184 has no Hoare annotation [2018-11-14 19:06:50,386 WARN L170 areAnnotationChecker]: L1352-2 has no Hoare annotation [2018-11-14 19:06:50,386 WARN L170 areAnnotationChecker]: L1361-2 has no Hoare annotation [2018-11-14 19:06:50,386 WARN L170 areAnnotationChecker]: L1365 has no Hoare annotation [2018-11-14 19:06:50,387 WARN L170 areAnnotationChecker]: L1365 has no Hoare annotation [2018-11-14 19:06:50,387 WARN L170 areAnnotationChecker]: L1188 has no Hoare annotation [2018-11-14 19:06:50,387 WARN L170 areAnnotationChecker]: L1187 has no Hoare annotation [2018-11-14 19:06:50,387 WARN L170 areAnnotationChecker]: L1187 has no Hoare annotation [2018-11-14 19:06:50,387 WARN L170 areAnnotationChecker]: L1377 has no Hoare annotation [2018-11-14 19:06:50,387 WARN L170 areAnnotationChecker]: L1377 has no Hoare annotation [2018-11-14 19:06:50,387 WARN L170 areAnnotationChecker]: L1190 has no Hoare annotation [2018-11-14 19:06:50,387 WARN L170 areAnnotationChecker]: L1190 has no Hoare annotation [2018-11-14 19:06:50,387 WARN L170 areAnnotationChecker]: L1377-2 has no Hoare annotation [2018-11-14 19:06:50,387 WARN L170 areAnnotationChecker]: L1194 has no Hoare annotation [2018-11-14 19:06:50,388 WARN L170 areAnnotationChecker]: L1193 has no Hoare annotation [2018-11-14 19:06:50,388 WARN L170 areAnnotationChecker]: L1193 has no Hoare annotation [2018-11-14 19:06:50,388 WARN L170 areAnnotationChecker]: L1382 has no Hoare annotation [2018-11-14 19:06:50,388 WARN L170 areAnnotationChecker]: L1382 has no Hoare annotation [2018-11-14 19:06:50,388 WARN L170 areAnnotationChecker]: L1423 has no Hoare annotation [2018-11-14 19:06:50,388 WARN L170 areAnnotationChecker]: L1423 has no Hoare annotation [2018-11-14 19:06:50,388 WARN L170 areAnnotationChecker]: L1196 has no Hoare annotation [2018-11-14 19:06:50,388 WARN L170 areAnnotationChecker]: L1196 has no Hoare annotation [2018-11-14 19:06:50,388 WARN L170 areAnnotationChecker]: L1399 has no Hoare annotation [2018-11-14 19:06:50,388 WARN L170 areAnnotationChecker]: L1385 has no Hoare annotation [2018-11-14 19:06:50,388 WARN L170 areAnnotationChecker]: L1385 has no Hoare annotation [2018-11-14 19:06:50,389 WARN L170 areAnnotationChecker]: L1424 has no Hoare annotation [2018-11-14 19:06:50,389 WARN L170 areAnnotationChecker]: L1424 has no Hoare annotation [2018-11-14 19:06:50,389 WARN L170 areAnnotationChecker]: L1200 has no Hoare annotation [2018-11-14 19:06:50,389 WARN L170 areAnnotationChecker]: L1199 has no Hoare annotation [2018-11-14 19:06:50,389 WARN L170 areAnnotationChecker]: L1199 has no Hoare annotation [2018-11-14 19:06:50,389 WARN L170 areAnnotationChecker]: L1401 has no Hoare annotation [2018-11-14 19:06:50,389 WARN L170 areAnnotationChecker]: L1401 has no Hoare annotation [2018-11-14 19:06:50,389 WARN L170 areAnnotationChecker]: L1388 has no Hoare annotation [2018-11-14 19:06:50,389 WARN L170 areAnnotationChecker]: L1388 has no Hoare annotation [2018-11-14 19:06:50,389 WARN L170 areAnnotationChecker]: L1425 has no Hoare annotation [2018-11-14 19:06:50,390 WARN L170 areAnnotationChecker]: L1425 has no Hoare annotation [2018-11-14 19:06:50,390 WARN L170 areAnnotationChecker]: L1433 has no Hoare annotation [2018-11-14 19:06:50,390 WARN L170 areAnnotationChecker]: L1465 has no Hoare annotation [2018-11-14 19:06:50,390 WARN L170 areAnnotationChecker]: L1465 has no Hoare annotation [2018-11-14 19:06:50,390 WARN L170 areAnnotationChecker]: L1202 has no Hoare annotation [2018-11-14 19:06:50,390 WARN L170 areAnnotationChecker]: L1202 has no Hoare annotation [2018-11-14 19:06:50,390 WARN L170 areAnnotationChecker]: L1388-1 has no Hoare annotation [2018-11-14 19:06:50,390 WARN L170 areAnnotationChecker]: L1389 has no Hoare annotation [2018-11-14 19:06:50,390 WARN L170 areAnnotationChecker]: L1389 has no Hoare annotation [2018-11-14 19:06:50,390 WARN L170 areAnnotationChecker]: L1434 has no Hoare annotation [2018-11-14 19:06:50,390 WARN L170 areAnnotationChecker]: L1434 has no Hoare annotation [2018-11-14 19:06:50,391 WARN L170 areAnnotationChecker]: L1203 has no Hoare annotation [2018-11-14 19:06:50,391 WARN L170 areAnnotationChecker]: L1203 has no Hoare annotation [2018-11-14 19:06:50,391 WARN L170 areAnnotationChecker]: L1205 has no Hoare annotation [2018-11-14 19:06:50,391 WARN L170 areAnnotationChecker]: L1205 has no Hoare annotation [2018-11-14 19:06:50,391 WARN L170 areAnnotationChecker]: L1392 has no Hoare annotation [2018-11-14 19:06:50,391 WARN L170 areAnnotationChecker]: L1392 has no Hoare annotation [2018-11-14 19:06:50,391 WARN L170 areAnnotationChecker]: L1435 has no Hoare annotation [2018-11-14 19:06:50,391 WARN L170 areAnnotationChecker]: L1435 has no Hoare annotation [2018-11-14 19:06:50,391 WARN L170 areAnnotationChecker]: L1443 has no Hoare annotation [2018-11-14 19:06:50,391 WARN L170 areAnnotationChecker]: L1478 has no Hoare annotation [2018-11-14 19:06:50,392 WARN L170 areAnnotationChecker]: L1478 has no Hoare annotation [2018-11-14 19:06:50,392 WARN L170 areAnnotationChecker]: L1475-1 has no Hoare annotation [2018-11-14 19:06:50,392 WARN L170 areAnnotationChecker]: L1209 has no Hoare annotation [2018-11-14 19:06:50,392 WARN L170 areAnnotationChecker]: L1208 has no Hoare annotation [2018-11-14 19:06:50,392 WARN L170 areAnnotationChecker]: L1208 has no Hoare annotation [2018-11-14 19:06:50,392 WARN L170 areAnnotationChecker]: L1393 has no Hoare annotation [2018-11-14 19:06:50,392 WARN L170 areAnnotationChecker]: L1393 has no Hoare annotation [2018-11-14 19:06:50,392 WARN L170 areAnnotationChecker]: L1446 has no Hoare annotation [2018-11-14 19:06:50,392 WARN L170 areAnnotationChecker]: L1446 has no Hoare annotation [2018-11-14 19:06:50,392 WARN L170 areAnnotationChecker]: L1493 has no Hoare annotation [2018-11-14 19:06:50,392 WARN L170 areAnnotationChecker]: L1493 has no Hoare annotation [2018-11-14 19:06:50,393 WARN L170 areAnnotationChecker]: L1211 has no Hoare annotation [2018-11-14 19:06:50,393 WARN L170 areAnnotationChecker]: L1211 has no Hoare annotation [2018-11-14 19:06:50,393 WARN L170 areAnnotationChecker]: L1393-2 has no Hoare annotation [2018-11-14 19:06:50,393 WARN L170 areAnnotationChecker]: L1393-2 has no Hoare annotation [2018-11-14 19:06:50,393 WARN L170 areAnnotationChecker]: L1498 has no Hoare annotation [2018-11-14 19:06:50,393 WARN L170 areAnnotationChecker]: L1498 has no Hoare annotation [2018-11-14 19:06:50,393 WARN L170 areAnnotationChecker]: L1215 has no Hoare annotation [2018-11-14 19:06:50,393 WARN L170 areAnnotationChecker]: L1214 has no Hoare annotation [2018-11-14 19:06:50,393 WARN L170 areAnnotationChecker]: L1214 has no Hoare annotation [2018-11-14 19:06:50,393 WARN L170 areAnnotationChecker]: L1502 has no Hoare annotation [2018-11-14 19:06:50,393 WARN L170 areAnnotationChecker]: L1502 has no Hoare annotation [2018-11-14 19:06:50,394 WARN L170 areAnnotationChecker]: L1514 has no Hoare annotation [2018-11-14 19:06:50,394 WARN L170 areAnnotationChecker]: L1514 has no Hoare annotation [2018-11-14 19:06:50,394 WARN L170 areAnnotationChecker]: L1217 has no Hoare annotation [2018-11-14 19:06:50,394 WARN L170 areAnnotationChecker]: L1217 has no Hoare annotation [2018-11-14 19:06:50,394 WARN L170 areAnnotationChecker]: L1221 has no Hoare annotation [2018-11-14 19:06:50,394 WARN L170 areAnnotationChecker]: L1220 has no Hoare annotation [2018-11-14 19:06:50,394 WARN L170 areAnnotationChecker]: L1220 has no Hoare annotation [2018-11-14 19:06:50,394 WARN L170 areAnnotationChecker]: L1525 has no Hoare annotation [2018-11-14 19:06:50,394 WARN L170 areAnnotationChecker]: L1525 has no Hoare annotation [2018-11-14 19:06:50,394 WARN L170 areAnnotationChecker]: L1223 has no Hoare annotation [2018-11-14 19:06:50,395 WARN L170 areAnnotationChecker]: L1223 has no Hoare annotation [2018-11-14 19:06:50,395 WARN L170 areAnnotationChecker]: L1227 has no Hoare annotation [2018-11-14 19:06:50,395 WARN L170 areAnnotationChecker]: L1226 has no Hoare annotation [2018-11-14 19:06:50,395 WARN L170 areAnnotationChecker]: L1226 has no Hoare annotation [2018-11-14 19:06:50,395 WARN L170 areAnnotationChecker]: L1536 has no Hoare annotation [2018-11-14 19:06:50,395 WARN L170 areAnnotationChecker]: L1536 has no Hoare annotation [2018-11-14 19:06:50,395 WARN L170 areAnnotationChecker]: L1229 has no Hoare annotation [2018-11-14 19:06:50,395 WARN L170 areAnnotationChecker]: L1229 has no Hoare annotation [2018-11-14 19:06:50,395 WARN L170 areAnnotationChecker]: L1541 has no Hoare annotation [2018-11-14 19:06:50,395 WARN L170 areAnnotationChecker]: L1541 has no Hoare annotation [2018-11-14 19:06:50,396 WARN L170 areAnnotationChecker]: L1233 has no Hoare annotation [2018-11-14 19:06:50,396 WARN L170 areAnnotationChecker]: L1232 has no Hoare annotation [2018-11-14 19:06:50,396 WARN L170 areAnnotationChecker]: L1232 has no Hoare annotation [2018-11-14 19:06:50,396 WARN L170 areAnnotationChecker]: L1541-2 has no Hoare annotation [2018-11-14 19:06:50,396 WARN L170 areAnnotationChecker]: L1551 has no Hoare annotation [2018-11-14 19:06:50,396 WARN L170 areAnnotationChecker]: L1551 has no Hoare annotation [2018-11-14 19:06:50,396 WARN L170 areAnnotationChecker]: L1235 has no Hoare annotation [2018-11-14 19:06:50,396 WARN L170 areAnnotationChecker]: L1235 has no Hoare annotation [2018-11-14 19:06:50,396 WARN L170 areAnnotationChecker]: L1558 has no Hoare annotation [2018-11-14 19:06:50,396 WARN L170 areAnnotationChecker]: L1558 has no Hoare annotation [2018-11-14 19:06:50,397 WARN L170 areAnnotationChecker]: L1239 has no Hoare annotation [2018-11-14 19:06:50,398 WARN L170 areAnnotationChecker]: L1238 has no Hoare annotation [2018-11-14 19:06:50,398 WARN L170 areAnnotationChecker]: L1238 has no Hoare annotation [2018-11-14 19:06:50,398 WARN L170 areAnnotationChecker]: L1561-2 has no Hoare annotation [2018-11-14 19:06:50,398 WARN L170 areAnnotationChecker]: L1561-2 has no Hoare annotation [2018-11-14 19:06:50,398 WARN L170 areAnnotationChecker]: L1561 has no Hoare annotation [2018-11-14 19:06:50,398 WARN L170 areAnnotationChecker]: L1561 has no Hoare annotation [2018-11-14 19:06:50,398 WARN L170 areAnnotationChecker]: L1584 has no Hoare annotation [2018-11-14 19:06:50,398 WARN L170 areAnnotationChecker]: L1584 has no Hoare annotation [2018-11-14 19:06:50,398 WARN L170 areAnnotationChecker]: L1241 has no Hoare annotation [2018-11-14 19:06:50,398 WARN L170 areAnnotationChecker]: L1241 has no Hoare annotation [2018-11-14 19:06:50,399 WARN L170 areAnnotationChecker]: L1574 has no Hoare annotation [2018-11-14 19:06:50,399 WARN L170 areAnnotationChecker]: L1574 has no Hoare annotation [2018-11-14 19:06:50,399 WARN L170 areAnnotationChecker]: L1585 has no Hoare annotation [2018-11-14 19:06:50,399 WARN L170 areAnnotationChecker]: L1585 has no Hoare annotation [2018-11-14 19:06:50,399 WARN L170 areAnnotationChecker]: L1589 has no Hoare annotation [2018-11-14 19:06:50,399 WARN L170 areAnnotationChecker]: L1589 has no Hoare annotation [2018-11-14 19:06:50,399 WARN L170 areAnnotationChecker]: L1242 has no Hoare annotation [2018-11-14 19:06:50,399 WARN L170 areAnnotationChecker]: L1245 has no Hoare annotation [2018-11-14 19:06:50,399 WARN L170 areAnnotationChecker]: L1595 has no Hoare annotation [2018-11-14 19:06:50,399 WARN L170 areAnnotationChecker]: L1595 has no Hoare annotation [2018-11-14 19:06:50,400 WARN L170 areAnnotationChecker]: L1605 has no Hoare annotation [2018-11-14 19:06:50,400 WARN L170 areAnnotationChecker]: L1605 has no Hoare annotation [2018-11-14 19:06:50,400 WARN L170 areAnnotationChecker]: L1595-2 has no Hoare annotation [2018-11-14 19:06:50,400 WARN L170 areAnnotationChecker]: L1609 has no Hoare annotation [2018-11-14 19:06:50,400 WARN L170 areAnnotationChecker]: L1609 has no Hoare annotation [2018-11-14 19:06:50,400 WARN L170 areAnnotationChecker]: L1605-1 has no Hoare annotation [2018-11-14 19:06:50,400 INFO L163 areAnnotationChecker]: CFG has 0 edges. 0 inductive. 0 not inductive. 0 times theorem prover too weak to decide inductivity. 0 times interpolants missing. [2018-11-14 19:06:50,406 INFO L202 PluginConnector]: Adding new model de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction CFG 14.11 07:06:50 BoogieIcfgContainer [2018-11-14 19:06:50,406 INFO L132 PluginConnector]: ------------------------ END TraceAbstraction---------------------------- [2018-11-14 19:06:50,407 INFO L168 Benchmark]: Toolchain (without parser) took 66557.98 ms. Allocated memory was 1.5 GB in the beginning and 2.8 GB in the end (delta: 1.3 GB). Free memory was 1.4 GB in the beginning and 2.7 GB in the end (delta: -1.3 GB). Peak memory consumption was 4.1 MB. Max. memory is 7.1 GB. [2018-11-14 19:06:50,408 INFO L168 Benchmark]: CDTParser took 0.19 ms. Allocated memory is still 1.5 GB. Free memory is still 1.4 GB. There was no memory consumed. Max. memory is 7.1 GB. [2018-11-14 19:06:50,408 INFO L168 Benchmark]: CACSL2BoogieTranslator took 1488.46 ms. Allocated memory was 1.5 GB in the beginning and 2.2 GB in the end (delta: 684.2 MB). Free memory was 1.4 GB in the beginning and 2.0 GB in the end (delta: -641.6 MB). Peak memory consumption was 104.6 MB. Max. memory is 7.1 GB. [2018-11-14 19:06:50,410 INFO L168 Benchmark]: Boogie Preprocessor took 197.61 ms. Allocated memory is still 2.2 GB. Free memory is still 2.0 GB. There was no memory consumed. Max. memory is 7.1 GB. [2018-11-14 19:06:50,410 INFO L168 Benchmark]: RCFGBuilder took 4225.22 ms. Allocated memory is still 2.2 GB. Free memory was 2.0 GB in the beginning and 1.9 GB in the end (delta: 166.7 MB). Peak memory consumption was 166.7 MB. Max. memory is 7.1 GB. [2018-11-14 19:06:50,411 INFO L168 Benchmark]: TraceAbstraction took 60641.94 ms. Allocated memory was 2.2 GB in the beginning and 2.8 GB in the end (delta: 577.2 MB). Free memory was 1.9 GB in the beginning and 2.7 GB in the end (delta: -782.5 MB). There was no memory consumed. Max. memory is 7.1 GB. [2018-11-14 19:06:50,416 INFO L336 ainManager$Toolchain]: ####################### End [Toolchain 1] ####################### --- Results --- * Results from de.uni_freiburg.informatik.ultimate.core: - GenericResult: Assertions are enabled Assertions are enabled - StatisticsResult: Toolchain Benchmarks Benchmark results are: * CDTParser took 0.19 ms. Allocated memory is still 1.5 GB. Free memory is still 1.4 GB. There was no memory consumed. Max. memory is 7.1 GB. * CACSL2BoogieTranslator took 1488.46 ms. Allocated memory was 1.5 GB in the beginning and 2.2 GB in the end (delta: 684.2 MB). Free memory was 1.4 GB in the beginning and 2.0 GB in the end (delta: -641.6 MB). Peak memory consumption was 104.6 MB. Max. memory is 7.1 GB. * Boogie Preprocessor took 197.61 ms. Allocated memory is still 2.2 GB. Free memory is still 2.0 GB. There was no memory consumed. Max. memory is 7.1 GB. * RCFGBuilder took 4225.22 ms. Allocated memory is still 2.2 GB. Free memory was 2.0 GB in the beginning and 1.9 GB in the end (delta: 166.7 MB). Peak memory consumption was 166.7 MB. Max. memory is 7.1 GB. * TraceAbstraction took 60641.94 ms. Allocated memory was 2.2 GB in the beginning and 2.8 GB in the end (delta: 577.2 MB). Free memory was 1.9 GB in the beginning and 2.7 GB in the end (delta: -782.5 MB). There was no memory consumed. Max. memory is 7.1 GB. * Results from de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator: - GenericResult: Unfinished Backtranslation Unfinished Backtranslation: IntegerLiteral 24586 could not be translated for associated CType STRUCT~~ssl_method_st?version~INT?ssl_new~*((*~SSL~0 ) : INT)?ssl_clear~*((*~SSL~0 ) : VOID)?ssl_free~*((*~SSL~0 ) : VOID)?ssl_accept~*((*~SSL~0 ) : INT)?ssl_connect~*((*~SSL~0 ) : INT)?ssl_read~*((*~SSL~0 *VOID INT ) : INT)?ssl_peek~*((*~SSL~0 *VOID INT ) : INT)?ssl_write~*((*~SSL~0 *VOID INT ) : INT)?ssl_shutdown~*((*~SSL~0 ) : INT)?ssl_renegotiate~*((*~SSL~0 ) : INT)?ssl_renegotiate_check~*((*~SSL~0 ) : INT)?ssl_ctrl~*((*~SSL~0 INT LONG *CHAR ) : LONG)?ssl_ctx_ctrl~*((*~SSL_CTX~0 INT LONG *CHAR ) : LONG)?get_cipher_by_char~*((*UCHAR ) : *~SSL_CIPHER~0)?put_cipher_by_char~*((*~SSL_CIPHER~0 *UCHAR ) : INT)?ssl_pending~*((*~SSL~0 ) : INT)?num_ciphers~*(() : INT)?get_cipher~*((UINT ) : *~SSL_CIPHER~0)?get_ssl_method~*((INT ) : *ssl_method_st)?get_timeout~*(() : LONG)?ssl3_enc~*ssl3_enc_method?ssl_version~*(() : INT)?ssl_callback_ctrl~*((*~SSL~0 INT *(() : VOID) ) : LONG)?ssl_ctx_callback_ctrl~*((*~SSL_CTX~0 INT *(() : VOID) ) : LONG)# - GenericResult: Unfinished Backtranslation Unfinished Backtranslation: IntegerLiteral 24589 could not be translated for associated CType STRUCT~~ssl_method_st?version~INT?ssl_new~*((*~SSL~0 ) : INT)?ssl_clear~*((*~SSL~0 ) : VOID)?ssl_free~*((*~SSL~0 ) : VOID)?ssl_accept~*((*~SSL~0 ) : INT)?ssl_connect~*((*~SSL~0 ) : INT)?ssl_read~*((*~SSL~0 *VOID INT ) : INT)?ssl_peek~*((*~SSL~0 *VOID INT ) : INT)?ssl_write~*((*~SSL~0 *VOID INT ) : INT)?ssl_shutdown~*((*~SSL~0 ) : INT)?ssl_renegotiate~*((*~SSL~0 ) : INT)?ssl_renegotiate_check~*((*~SSL~0 ) : INT)?ssl_ctrl~*((*~SSL~0 INT LONG *CHAR ) : LONG)?ssl_ctx_ctrl~*((*~SSL_CTX~0 INT LONG *CHAR ) : LONG)?get_cipher_by_char~*((*UCHAR ) : *~SSL_CIPHER~0)?put_cipher_by_char~*((*~SSL_CIPHER~0 *UCHAR ) : INT)?ssl_pending~*((*~SSL~0 ) : INT)?num_ciphers~*(() : INT)?get_cipher~*((UINT ) : *~SSL_CIPHER~0)?get_ssl_method~*((INT ) : *ssl_method_st)?get_timeout~*(() : LONG)?ssl3_enc~*ssl3_enc_method?ssl_version~*(() : INT)?ssl_callback_ctrl~*((*~SSL~0 INT *(() : VOID) ) : LONG)?ssl_ctx_callback_ctrl~*((*~SSL_CTX~0 INT *(() : VOID) ) : LONG)# * Results from de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction: - UnprovableResult [Line: 1702]: Unable to prove that call of __VERIFIER_error() unreachable Unable to prove that call of __VERIFIER_error() unreachable Reason: overapproximation of bitwiseAnd at line 1121. Possible FailurePath: [L1042] static int init = 1; [L1043] FCALL static SSL_METHOD SSLv3_server_data ; VAL [\old(init)=24584, \old(SSLv3_server_data)=null, \old(SSLv3_server_data)=null, init=1, SSLv3_server_data={24587:0}] [L1065] SSL *s ; [L1066] int tmp ; [L1070] EXPR, FCALL malloc(sizeof(SSL)) [L1070] s = malloc(sizeof(SSL)) [L1071] EXPR, FCALL malloc(sizeof(struct ssl3_state_st)) [L1071] FCALL s->s3 = malloc(sizeof(struct ssl3_state_st)) [L1072] EXPR, FCALL malloc(sizeof(SSL_CTX)) [L1072] FCALL s->ctx = malloc(sizeof(SSL_CTX)) [L1073] EXPR, FCALL malloc(sizeof(SSL_SESSION)) [L1073] FCALL s->session = malloc(sizeof(SSL_SESSION)) [L1074] FCALL s->state = 8464 VAL [init=1, malloc(sizeof(SSL))={24578:0}, malloc(sizeof(SSL_CTX))={24585:0}, malloc(sizeof(SSL_SESSION))={24580:0}, malloc(sizeof(struct ssl3_state_st))={24583:0}, s={24578:0}, SSLv3_server_data={24587:0}] [L1075] CALL ssl3_accept(s) VAL [init=1, s={24578:0}, SSLv3_server_data={24587:0}] [L1081] BUF_MEM *buf ; [L1082] unsigned long l ; [L1083] unsigned long Time ; [L1084] unsigned long tmp ; [L1085] void (*cb)() ; [L1086] long num1 ; [L1087] int ret ; [L1088] int new_state ; [L1089] int state ; [L1090] int skip ; [L1091] int got_new_session ; [L1092] int tmp___1 = __VERIFIER_nondet_int() ; [L1093] int tmp___2 = __VERIFIER_nondet_int() ; [L1094] int tmp___3 = __VERIFIER_nondet_int() ; [L1095] int tmp___4 = __VERIFIER_nondet_int() ; [L1096] int tmp___5 = __VERIFIER_nondet_int() ; [L1097] int tmp___6 = __VERIFIER_nondet_int() ; [L1098] int tmp___7 ; [L1099] long tmp___8 = __VERIFIER_nondet_long() ; [L1100] int tmp___9 = __VERIFIER_nondet_int() ; [L1101] int tmp___10 = __VERIFIER_nondet_int() ; [L1102] int blastFlag ; [L1106] blastFlag = 0 [L1107] FCALL s->hit=__VERIFIER_nondet_int () [L1108] FCALL s->state = 8464 [L1109] tmp = __VERIFIER_nondet_int() [L1110] Time = tmp [L1111] cb = (void (*)())((void *)0) [L1112] ret = -1 [L1113] skip = 0 [L1114] got_new_session = 0 [L1115] EXPR, FCALL s->info_callback VAL [={0:0}, blastFlag=0, got_new_session=0, init=1, ret=-1, s={24578:0}, s={24578:0}, s->info_callback={2:-1}, skip=0, SSLv3_server_data={24587:0}, Time=0, tmp=0, tmp___1=0, tmp___10=1, tmp___2=0, tmp___3=0, tmp___4=0, tmp___5=0, tmp___6=0, tmp___8=0, tmp___9=1] [L1115] COND TRUE (unsigned long )s->info_callback != (unsigned long )((void *)0) [L1116] EXPR, FCALL s->info_callback [L1116] cb = s->info_callback [L1120] EXPR, FCALL s->in_handshake [L1120] FCALL s->in_handshake += 1 [L1121] COND FALSE !(tmp___1 & 12288) VAL [={2:-1}, blastFlag=0, got_new_session=0, init=1, ret=-1, s={24578:0}, s={24578:0}, skip=0, SSLv3_server_data={24587:0}, Time=0, tmp=0, tmp___1=0, tmp___10=1, tmp___2=0, tmp___3=0, tmp___4=0, tmp___5=0, tmp___6=0, tmp___8=0, tmp___9=1] [L1130] EXPR, FCALL s->cert VAL [={2:-1}, blastFlag=0, got_new_session=0, init=1, ret=-1, s={24578:0}, s={24578:0}, s->cert={3:-2}, skip=0, SSLv3_server_data={24587:0}, Time=0, tmp=0, tmp___1=0, tmp___10=1, tmp___2=0, tmp___3=0, tmp___4=0, tmp___5=0, tmp___6=0, tmp___8=0, tmp___9=1] [L1130] COND FALSE !((unsigned long )s->cert == (unsigned long )((void *)0)) [L1136] COND TRUE 1 VAL [={2:-1}, blastFlag=0, got_new_session=0, init=1, ret=-1, s={24578:0}, s={24578:0}, skip=0, SSLv3_server_data={24587:0}, Time=0, tmp=0, tmp___1=0, tmp___10=1, tmp___2=0, tmp___3=0, tmp___4=0, tmp___5=0, tmp___6=0, tmp___8=0, tmp___9=1] [L1138] EXPR, FCALL s->state [L1138] state = s->state [L1139] EXPR, FCALL s->state VAL [={2:-1}, blastFlag=0, got_new_session=0, init=1, ret=-1, s={24578:0}, s={24578:0}, s->state=8464, skip=0, SSLv3_server_data={24587:0}, state=8464, Time=0, tmp=0, tmp___1=0, tmp___10=1, tmp___2=0, tmp___3=0, tmp___4=0, tmp___5=0, tmp___6=0, tmp___8=0, tmp___9=1] [L1139] COND FALSE !(s->state == 12292) [L1142] EXPR, FCALL s->state VAL [={2:-1}, blastFlag=0, got_new_session=0, init=1, ret=-1, s={24578:0}, s={24578:0}, s->state=8464, skip=0, SSLv3_server_data={24587:0}, state=8464, Time=0, tmp=0, tmp___1=0, tmp___10=1, tmp___2=0, tmp___3=0, tmp___4=0, tmp___5=0, tmp___6=0, tmp___8=0, tmp___9=1] [L1142] COND FALSE !(s->state == 16384) [L1145] EXPR, FCALL s->state VAL [={2:-1}, blastFlag=0, got_new_session=0, init=1, ret=-1, s={24578:0}, s={24578:0}, s->state=8464, skip=0, SSLv3_server_data={24587:0}, state=8464, Time=0, tmp=0, tmp___1=0, tmp___10=1, tmp___2=0, tmp___3=0, tmp___4=0, tmp___5=0, tmp___6=0, tmp___8=0, tmp___9=1] [L1145] COND FALSE !(s->state == 8192) [L1148] EXPR, FCALL s->state VAL [={2:-1}, blastFlag=0, got_new_session=0, init=1, ret=-1, s={24578:0}, s={24578:0}, s->state=8464, skip=0, SSLv3_server_data={24587:0}, state=8464, Time=0, tmp=0, tmp___1=0, tmp___10=1, tmp___2=0, tmp___3=0, tmp___4=0, tmp___5=0, tmp___6=0, tmp___8=0, tmp___9=1] [L1148] COND FALSE !(s->state == 24576) [L1151] EXPR, FCALL s->state VAL [={2:-1}, blastFlag=0, got_new_session=0, init=1, ret=-1, s={24578:0}, s={24578:0}, s->state=8464, skip=0, SSLv3_server_data={24587:0}, state=8464, Time=0, tmp=0, tmp___1=0, tmp___10=1, tmp___2=0, tmp___3=0, tmp___4=0, tmp___5=0, tmp___6=0, tmp___8=0, tmp___9=1] [L1151] COND FALSE !(s->state == 8195) [L1154] EXPR, FCALL s->state VAL [={2:-1}, blastFlag=0, got_new_session=0, init=1, ret=-1, s={24578:0}, s={24578:0}, s->state=8464, skip=0, SSLv3_server_data={24587:0}, state=8464, Time=0, tmp=0, tmp___1=0, tmp___10=1, tmp___2=0, tmp___3=0, tmp___4=0, tmp___5=0, tmp___6=0, tmp___8=0, tmp___9=1] [L1154] COND FALSE !(s->state == 8480) [L1157] EXPR, FCALL s->state VAL [={2:-1}, blastFlag=0, got_new_session=0, init=1, ret=-1, s={24578:0}, s={24578:0}, s->state=8464, skip=0, SSLv3_server_data={24587:0}, state=8464, Time=0, tmp=0, tmp___1=0, tmp___10=1, tmp___2=0, tmp___3=0, tmp___4=0, tmp___5=0, tmp___6=0, tmp___8=0, tmp___9=1] [L1157] COND FALSE !(s->state == 8481) [L1160] EXPR, FCALL s->state VAL [={2:-1}, blastFlag=0, got_new_session=0, init=1, ret=-1, s={24578:0}, s={24578:0}, s->state=8464, skip=0, SSLv3_server_data={24587:0}, state=8464, Time=0, tmp=0, tmp___1=0, tmp___10=1, tmp___2=0, tmp___3=0, tmp___4=0, tmp___5=0, tmp___6=0, tmp___8=0, tmp___9=1] [L1160] COND FALSE !(s->state == 8482) [L1163] EXPR, FCALL s->state VAL [={2:-1}, blastFlag=0, got_new_session=0, init=1, ret=-1, s={24578:0}, s={24578:0}, s->state=8464, skip=0, SSLv3_server_data={24587:0}, state=8464, Time=0, tmp=0, tmp___1=0, tmp___10=1, tmp___2=0, tmp___3=0, tmp___4=0, tmp___5=0, tmp___6=0, tmp___8=0, tmp___9=1] [L1163] COND TRUE s->state == 8464 [L1323] FCALL s->shutdown = 0 [L1324] ret = __VERIFIER_nondet_int() [L1325] COND TRUE blastFlag == 0 [L1326] blastFlag = 1 VAL [={2:-1}, blastFlag=1, got_new_session=0, init=1, ret=1, s={24578:0}, s={24578:0}, skip=0, SSLv3_server_data={24587:0}, state=8464, Time=0, tmp=0, tmp___1=0, tmp___10=1, tmp___2=0, tmp___3=0, tmp___4=0, tmp___5=0, tmp___6=0, tmp___8=0, tmp___9=1] [L1330] COND FALSE !(ret <= 0) [L1335] got_new_session = 1 [L1336] FCALL s->state = 8496 [L1337] FCALL s->init_num = 0 VAL [={2:-1}, blastFlag=1, got_new_session=1, init=1, ret=1, s={24578:0}, s={24578:0}, skip=0, SSLv3_server_data={24587:0}, state=8464, Time=0, tmp=0, tmp___1=0, tmp___10=1, tmp___2=0, tmp___3=0, tmp___4=0, tmp___5=0, tmp___6=0, tmp___8=0, tmp___9=1] [L1661] EXPR, FCALL s->s3 [L1661] EXPR, FCALL (s->s3)->tmp.reuse_message VAL [={2:-1}, (s->s3)->tmp.reuse_message=24579, blastFlag=1, got_new_session=1, init=1, ret=1, s={24578:0}, s={24578:0}, s->s3={24583:0}, skip=0, SSLv3_server_data={24587:0}, state=8464, Time=0, tmp=0, tmp___1=0, tmp___10=1, tmp___2=0, tmp___3=0, tmp___4=0, tmp___5=0, tmp___6=0, tmp___8=0, tmp___9=1] [L1661] COND FALSE !(! (s->s3)->tmp.reuse_message) [L1690] skip = 0 VAL [={2:-1}, blastFlag=1, got_new_session=1, init=1, ret=1, s={24578:0}, s={24578:0}, skip=0, SSLv3_server_data={24587:0}, state=8464, Time=0, tmp=0, tmp___1=0, tmp___10=1, tmp___2=0, tmp___3=0, tmp___4=0, tmp___5=0, tmp___6=0, tmp___8=0, tmp___9=1] [L1136] COND TRUE 1 VAL [={2:-1}, blastFlag=1, got_new_session=1, init=1, ret=1, s={24578:0}, s={24578:0}, skip=0, SSLv3_server_data={24587:0}, state=8464, Time=0, tmp=0, tmp___1=0, tmp___10=1, tmp___2=0, tmp___3=0, tmp___4=0, tmp___5=0, tmp___6=0, tmp___8=0, tmp___9=1] [L1138] EXPR, FCALL s->state [L1138] state = s->state [L1139] EXPR, FCALL s->state VAL [={2:-1}, blastFlag=1, got_new_session=1, init=1, ret=1, s={24578:0}, s={24578:0}, s->state=8496, skip=0, SSLv3_server_data={24587:0}, state=8496, Time=0, tmp=0, tmp___1=0, tmp___10=1, tmp___2=0, tmp___3=0, tmp___4=0, tmp___5=0, tmp___6=0, tmp___8=0, tmp___9=1] [L1139] COND FALSE !(s->state == 12292) [L1142] EXPR, FCALL s->state VAL [={2:-1}, blastFlag=1, got_new_session=1, init=1, ret=1, s={24578:0}, s={24578:0}, s->state=8496, skip=0, SSLv3_server_data={24587:0}, state=8496, Time=0, tmp=0, tmp___1=0, tmp___10=1, tmp___2=0, tmp___3=0, tmp___4=0, tmp___5=0, tmp___6=0, tmp___8=0, tmp___9=1] [L1142] COND FALSE !(s->state == 16384) [L1145] EXPR, FCALL s->state VAL [={2:-1}, blastFlag=1, got_new_session=1, init=1, ret=1, s={24578:0}, s={24578:0}, s->state=8496, skip=0, SSLv3_server_data={24587:0}, state=8496, Time=0, tmp=0, tmp___1=0, tmp___10=1, tmp___2=0, tmp___3=0, tmp___4=0, tmp___5=0, tmp___6=0, tmp___8=0, tmp___9=1] [L1145] COND FALSE !(s->state == 8192) [L1148] EXPR, FCALL s->state VAL [={2:-1}, blastFlag=1, got_new_session=1, init=1, ret=1, s={24578:0}, s={24578:0}, s->state=8496, skip=0, SSLv3_server_data={24587:0}, state=8496, Time=0, tmp=0, tmp___1=0, tmp___10=1, tmp___2=0, tmp___3=0, tmp___4=0, tmp___5=0, tmp___6=0, tmp___8=0, tmp___9=1] [L1148] COND FALSE !(s->state == 24576) [L1151] EXPR, FCALL s->state VAL [={2:-1}, blastFlag=1, got_new_session=1, init=1, ret=1, s={24578:0}, s={24578:0}, s->state=8496, skip=0, SSLv3_server_data={24587:0}, state=8496, Time=0, tmp=0, tmp___1=0, tmp___10=1, tmp___2=0, tmp___3=0, tmp___4=0, tmp___5=0, tmp___6=0, tmp___8=0, tmp___9=1] [L1151] COND FALSE !(s->state == 8195) [L1154] EXPR, FCALL s->state VAL [={2:-1}, blastFlag=1, got_new_session=1, init=1, ret=1, s={24578:0}, s={24578:0}, s->state=8496, skip=0, SSLv3_server_data={24587:0}, state=8496, Time=0, tmp=0, tmp___1=0, tmp___10=1, tmp___2=0, tmp___3=0, tmp___4=0, tmp___5=0, tmp___6=0, tmp___8=0, tmp___9=1] [L1154] COND FALSE !(s->state == 8480) [L1157] EXPR, FCALL s->state VAL [={2:-1}, blastFlag=1, got_new_session=1, init=1, ret=1, s={24578:0}, s={24578:0}, s->state=8496, skip=0, SSLv3_server_data={24587:0}, state=8496, Time=0, tmp=0, tmp___1=0, tmp___10=1, tmp___2=0, tmp___3=0, tmp___4=0, tmp___5=0, tmp___6=0, tmp___8=0, tmp___9=1] [L1157] COND FALSE !(s->state == 8481) [L1160] EXPR, FCALL s->state VAL [={2:-1}, blastFlag=1, got_new_session=1, init=1, ret=1, s={24578:0}, s={24578:0}, s->state=8496, skip=0, SSLv3_server_data={24587:0}, state=8496, Time=0, tmp=0, tmp___1=0, tmp___10=1, tmp___2=0, tmp___3=0, tmp___4=0, tmp___5=0, tmp___6=0, tmp___8=0, tmp___9=1] [L1160] COND FALSE !(s->state == 8482) [L1163] EXPR, FCALL s->state VAL [={2:-1}, blastFlag=1, got_new_session=1, init=1, ret=1, s={24578:0}, s={24578:0}, s->state=8496, skip=0, SSLv3_server_data={24587:0}, state=8496, Time=0, tmp=0, tmp___1=0, tmp___10=1, tmp___2=0, tmp___3=0, tmp___4=0, tmp___5=0, tmp___6=0, tmp___8=0, tmp___9=1] [L1163] COND FALSE !(s->state == 8464) [L1166] EXPR, FCALL s->state VAL [={2:-1}, blastFlag=1, got_new_session=1, init=1, ret=1, s={24578:0}, s={24578:0}, s->state=8496, skip=0, SSLv3_server_data={24587:0}, state=8496, Time=0, tmp=0, tmp___1=0, tmp___10=1, tmp___2=0, tmp___3=0, tmp___4=0, tmp___5=0, tmp___6=0, tmp___8=0, tmp___9=1] [L1166] COND FALSE !(s->state == 8465) [L1169] EXPR, FCALL s->state VAL [={2:-1}, blastFlag=1, got_new_session=1, init=1, ret=1, s={24578:0}, s={24578:0}, s->state=8496, skip=0, SSLv3_server_data={24587:0}, state=8496, Time=0, tmp=0, tmp___1=0, tmp___10=1, tmp___2=0, tmp___3=0, tmp___4=0, tmp___5=0, tmp___6=0, tmp___8=0, tmp___9=1] [L1169] COND FALSE !(s->state == 8466) [L1172] EXPR, FCALL s->state VAL [={2:-1}, blastFlag=1, got_new_session=1, init=1, ret=1, s={24578:0}, s={24578:0}, s->state=8496, skip=0, SSLv3_server_data={24587:0}, state=8496, Time=0, tmp=0, tmp___1=0, tmp___10=1, tmp___2=0, tmp___3=0, tmp___4=0, tmp___5=0, tmp___6=0, tmp___8=0, tmp___9=1] [L1172] COND TRUE s->state == 8496 [L1341] ret = __VERIFIER_nondet_int() [L1342] COND TRUE blastFlag == 1 [L1343] blastFlag = 2 VAL [={2:-1}, blastFlag=2, got_new_session=1, init=1, ret=1, s={24578:0}, s={24578:0}, skip=0, SSLv3_server_data={24587:0}, state=8496, Time=0, tmp=0, tmp___1=0, tmp___10=1, tmp___2=0, tmp___3=0, tmp___4=0, tmp___5=0, tmp___6=0, tmp___8=0, tmp___9=1] [L1347] COND FALSE !(ret <= 0) [L1352] FCALL s->hit VAL [={2:-1}, blastFlag=2, got_new_session=1, init=1, ret=1, s={24578:0}, s={24578:0}, s->hit=1, skip=0, SSLv3_server_data={24587:0}, state=8496, Time=0, tmp=0, tmp___1=0, tmp___10=1, tmp___2=0, tmp___3=0, tmp___4=0, tmp___5=0, tmp___6=0, tmp___8=0, tmp___9=1] [L1352] COND TRUE s->hit [L1353] FCALL s->state = 8656 VAL [={2:-1}, blastFlag=2, got_new_session=1, init=1, ret=1, s={24578:0}, s={24578:0}, skip=0, SSLv3_server_data={24587:0}, state=8496, Time=0, tmp=0, tmp___1=0, tmp___10=1, tmp___2=0, tmp___3=0, tmp___4=0, tmp___5=0, tmp___6=0, tmp___8=0, tmp___9=1] [L1357] FCALL s->init_num = 0 VAL [={2:-1}, blastFlag=2, got_new_session=1, init=1, ret=1, s={24578:0}, s={24578:0}, skip=0, SSLv3_server_data={24587:0}, state=8496, Time=0, tmp=0, tmp___1=0, tmp___10=1, tmp___2=0, tmp___3=0, tmp___4=0, tmp___5=0, tmp___6=0, tmp___8=0, tmp___9=1] [L1661] EXPR, FCALL s->s3 [L1661] EXPR, FCALL (s->s3)->tmp.reuse_message VAL [={2:-1}, (s->s3)->tmp.reuse_message=24579, blastFlag=2, got_new_session=1, init=1, ret=1, s={24578:0}, s={24578:0}, s->s3={24583:0}, skip=0, SSLv3_server_data={24587:0}, state=8496, Time=0, tmp=0, tmp___1=0, tmp___10=1, tmp___2=0, tmp___3=0, tmp___4=0, tmp___5=0, tmp___6=0, tmp___8=0, tmp___9=1] [L1661] COND FALSE !(! (s->s3)->tmp.reuse_message) [L1690] skip = 0 VAL [={2:-1}, blastFlag=2, got_new_session=1, init=1, ret=1, s={24578:0}, s={24578:0}, skip=0, SSLv3_server_data={24587:0}, state=8496, Time=0, tmp=0, tmp___1=0, tmp___10=1, tmp___2=0, tmp___3=0, tmp___4=0, tmp___5=0, tmp___6=0, tmp___8=0, tmp___9=1] [L1136] COND TRUE 1 VAL [={2:-1}, blastFlag=2, got_new_session=1, init=1, ret=1, s={24578:0}, s={24578:0}, skip=0, SSLv3_server_data={24587:0}, state=8496, Time=0, tmp=0, tmp___1=0, tmp___10=1, tmp___2=0, tmp___3=0, tmp___4=0, tmp___5=0, tmp___6=0, tmp___8=0, tmp___9=1] [L1138] EXPR, FCALL s->state [L1138] state = s->state [L1139] EXPR, FCALL s->state VAL [={2:-1}, blastFlag=2, got_new_session=1, init=1, ret=1, s={24578:0}, s={24578:0}, s->state=8656, skip=0, SSLv3_server_data={24587:0}, state=8656, Time=0, tmp=0, tmp___1=0, tmp___10=1, tmp___2=0, tmp___3=0, tmp___4=0, tmp___5=0, tmp___6=0, tmp___8=0, tmp___9=1] [L1139] COND FALSE !(s->state == 12292) [L1142] EXPR, FCALL s->state VAL [={2:-1}, blastFlag=2, got_new_session=1, init=1, ret=1, s={24578:0}, s={24578:0}, s->state=8656, skip=0, SSLv3_server_data={24587:0}, state=8656, Time=0, tmp=0, tmp___1=0, tmp___10=1, tmp___2=0, tmp___3=0, tmp___4=0, tmp___5=0, tmp___6=0, tmp___8=0, tmp___9=1] [L1142] COND FALSE !(s->state == 16384) [L1145] EXPR, FCALL s->state VAL [={2:-1}, blastFlag=2, got_new_session=1, init=1, ret=1, s={24578:0}, s={24578:0}, s->state=8656, skip=0, SSLv3_server_data={24587:0}, state=8656, Time=0, tmp=0, tmp___1=0, tmp___10=1, tmp___2=0, tmp___3=0, tmp___4=0, tmp___5=0, tmp___6=0, tmp___8=0, tmp___9=1] [L1145] COND FALSE !(s->state == 8192) [L1148] EXPR, FCALL s->state VAL [={2:-1}, blastFlag=2, got_new_session=1, init=1, ret=1, s={24578:0}, s={24578:0}, s->state=8656, skip=0, SSLv3_server_data={24587:0}, state=8656, Time=0, tmp=0, tmp___1=0, tmp___10=1, tmp___2=0, tmp___3=0, tmp___4=0, tmp___5=0, tmp___6=0, tmp___8=0, tmp___9=1] [L1148] COND FALSE !(s->state == 24576) [L1151] EXPR, FCALL s->state VAL [={2:-1}, blastFlag=2, got_new_session=1, init=1, ret=1, s={24578:0}, s={24578:0}, s->state=8656, skip=0, SSLv3_server_data={24587:0}, state=8656, Time=0, tmp=0, tmp___1=0, tmp___10=1, tmp___2=0, tmp___3=0, tmp___4=0, tmp___5=0, tmp___6=0, tmp___8=0, tmp___9=1] [L1151] COND FALSE !(s->state == 8195) [L1154] EXPR, FCALL s->state VAL [={2:-1}, blastFlag=2, got_new_session=1, init=1, ret=1, s={24578:0}, s={24578:0}, s->state=8656, skip=0, SSLv3_server_data={24587:0}, state=8656, Time=0, tmp=0, tmp___1=0, tmp___10=1, tmp___2=0, tmp___3=0, tmp___4=0, tmp___5=0, tmp___6=0, tmp___8=0, tmp___9=1] [L1154] COND FALSE !(s->state == 8480) [L1157] EXPR, FCALL s->state VAL [={2:-1}, blastFlag=2, got_new_session=1, init=1, ret=1, s={24578:0}, s={24578:0}, s->state=8656, skip=0, SSLv3_server_data={24587:0}, state=8656, Time=0, tmp=0, tmp___1=0, tmp___10=1, tmp___2=0, tmp___3=0, tmp___4=0, tmp___5=0, tmp___6=0, tmp___8=0, tmp___9=1] [L1157] COND FALSE !(s->state == 8481) [L1160] EXPR, FCALL s->state VAL [={2:-1}, blastFlag=2, got_new_session=1, init=1, ret=1, s={24578:0}, s={24578:0}, s->state=8656, skip=0, SSLv3_server_data={24587:0}, state=8656, Time=0, tmp=0, tmp___1=0, tmp___10=1, tmp___2=0, tmp___3=0, tmp___4=0, tmp___5=0, tmp___6=0, tmp___8=0, tmp___9=1] [L1160] COND FALSE !(s->state == 8482) [L1163] EXPR, FCALL s->state VAL [={2:-1}, blastFlag=2, got_new_session=1, init=1, ret=1, s={24578:0}, s={24578:0}, s->state=8656, skip=0, SSLv3_server_data={24587:0}, state=8656, Time=0, tmp=0, tmp___1=0, tmp___10=1, tmp___2=0, tmp___3=0, tmp___4=0, tmp___5=0, tmp___6=0, tmp___8=0, tmp___9=1] [L1163] COND FALSE !(s->state == 8464) [L1166] EXPR, FCALL s->state VAL [={2:-1}, blastFlag=2, got_new_session=1, init=1, ret=1, s={24578:0}, s={24578:0}, s->state=8656, skip=0, SSLv3_server_data={24587:0}, state=8656, Time=0, tmp=0, tmp___1=0, tmp___10=1, tmp___2=0, tmp___3=0, tmp___4=0, tmp___5=0, tmp___6=0, tmp___8=0, tmp___9=1] [L1166] COND FALSE !(s->state == 8465) [L1169] EXPR, FCALL s->state VAL [={2:-1}, blastFlag=2, got_new_session=1, init=1, ret=1, s={24578:0}, s={24578:0}, s->state=8656, skip=0, SSLv3_server_data={24587:0}, state=8656, Time=0, tmp=0, tmp___1=0, tmp___10=1, tmp___2=0, tmp___3=0, tmp___4=0, tmp___5=0, tmp___6=0, tmp___8=0, tmp___9=1] [L1169] COND FALSE !(s->state == 8466) [L1172] EXPR, FCALL s->state VAL [={2:-1}, blastFlag=2, got_new_session=1, init=1, ret=1, s={24578:0}, s={24578:0}, s->state=8656, skip=0, SSLv3_server_data={24587:0}, state=8656, Time=0, tmp=0, tmp___1=0, tmp___10=1, tmp___2=0, tmp___3=0, tmp___4=0, tmp___5=0, tmp___6=0, tmp___8=0, tmp___9=1] [L1172] COND FALSE !(s->state == 8496) [L1175] EXPR, FCALL s->state VAL [={2:-1}, blastFlag=2, got_new_session=1, init=1, ret=1, s={24578:0}, s={24578:0}, s->state=8656, skip=0, SSLv3_server_data={24587:0}, state=8656, Time=0, tmp=0, tmp___1=0, tmp___10=1, tmp___2=0, tmp___3=0, tmp___4=0, tmp___5=0, tmp___6=0, tmp___8=0, tmp___9=1] [L1175] COND FALSE !(s->state == 8497) [L1178] EXPR, FCALL s->state VAL [={2:-1}, blastFlag=2, got_new_session=1, init=1, ret=1, s={24578:0}, s={24578:0}, s->state=8656, skip=0, SSLv3_server_data={24587:0}, state=8656, Time=0, tmp=0, tmp___1=0, tmp___10=1, tmp___2=0, tmp___3=0, tmp___4=0, tmp___5=0, tmp___6=0, tmp___8=0, tmp___9=1] [L1178] COND FALSE !(s->state == 8512) [L1181] EXPR, FCALL s->state VAL [={2:-1}, blastFlag=2, got_new_session=1, init=1, ret=1, s={24578:0}, s={24578:0}, s->state=8656, skip=0, SSLv3_server_data={24587:0}, state=8656, Time=0, tmp=0, tmp___1=0, tmp___10=1, tmp___2=0, tmp___3=0, tmp___4=0, tmp___5=0, tmp___6=0, tmp___8=0, tmp___9=1] [L1181] COND FALSE !(s->state == 8513) [L1184] EXPR, FCALL s->state VAL [={2:-1}, blastFlag=2, got_new_session=1, init=1, ret=1, s={24578:0}, s={24578:0}, s->state=8656, skip=0, SSLv3_server_data={24587:0}, state=8656, Time=0, tmp=0, tmp___1=0, tmp___10=1, tmp___2=0, tmp___3=0, tmp___4=0, tmp___5=0, tmp___6=0, tmp___8=0, tmp___9=1] [L1184] COND FALSE !(s->state == 8528) [L1187] EXPR, FCALL s->state VAL [={2:-1}, blastFlag=2, got_new_session=1, init=1, ret=1, s={24578:0}, s={24578:0}, s->state=8656, skip=0, SSLv3_server_data={24587:0}, state=8656, Time=0, tmp=0, tmp___1=0, tmp___10=1, tmp___2=0, tmp___3=0, tmp___4=0, tmp___5=0, tmp___6=0, tmp___8=0, tmp___9=1] [L1187] COND FALSE !(s->state == 8529) [L1190] EXPR, FCALL s->state VAL [={2:-1}, blastFlag=2, got_new_session=1, init=1, ret=1, s={24578:0}, s={24578:0}, s->state=8656, skip=0, SSLv3_server_data={24587:0}, state=8656, Time=0, tmp=0, tmp___1=0, tmp___10=1, tmp___2=0, tmp___3=0, tmp___4=0, tmp___5=0, tmp___6=0, tmp___8=0, tmp___9=1] [L1190] COND FALSE !(s->state == 8544) [L1193] EXPR, FCALL s->state VAL [={2:-1}, blastFlag=2, got_new_session=1, init=1, ret=1, s={24578:0}, s={24578:0}, s->state=8656, skip=0, SSLv3_server_data={24587:0}, state=8656, Time=0, tmp=0, tmp___1=0, tmp___10=1, tmp___2=0, tmp___3=0, tmp___4=0, tmp___5=0, tmp___6=0, tmp___8=0, tmp___9=1] [L1193] COND FALSE !(s->state == 8545) [L1196] EXPR, FCALL s->state VAL [={2:-1}, blastFlag=2, got_new_session=1, init=1, ret=1, s={24578:0}, s={24578:0}, s->state=8656, skip=0, SSLv3_server_data={24587:0}, state=8656, Time=0, tmp=0, tmp___1=0, tmp___10=1, tmp___2=0, tmp___3=0, tmp___4=0, tmp___5=0, tmp___6=0, tmp___8=0, tmp___9=1] [L1196] COND FALSE !(s->state == 8560) [L1199] EXPR, FCALL s->state VAL [={2:-1}, blastFlag=2, got_new_session=1, init=1, ret=1, s={24578:0}, s={24578:0}, s->state=8656, skip=0, SSLv3_server_data={24587:0}, state=8656, Time=0, tmp=0, tmp___1=0, tmp___10=1, tmp___2=0, tmp___3=0, tmp___4=0, tmp___5=0, tmp___6=0, tmp___8=0, tmp___9=1] [L1199] COND FALSE !(s->state == 8561) [L1202] EXPR, FCALL s->state VAL [={2:-1}, blastFlag=2, got_new_session=1, init=1, ret=1, s={24578:0}, s={24578:0}, s->state=8656, skip=0, SSLv3_server_data={24587:0}, state=8656, Time=0, tmp=0, tmp___1=0, tmp___10=1, tmp___2=0, tmp___3=0, tmp___4=0, tmp___5=0, tmp___6=0, tmp___8=0, tmp___9=1] [L1202] COND FALSE !(s->state == 8448) [L1205] EXPR, FCALL s->state VAL [={2:-1}, blastFlag=2, got_new_session=1, init=1, ret=1, s={24578:0}, s={24578:0}, s->state=8656, skip=0, SSLv3_server_data={24587:0}, state=8656, Time=0, tmp=0, tmp___1=0, tmp___10=1, tmp___2=0, tmp___3=0, tmp___4=0, tmp___5=0, tmp___6=0, tmp___8=0, tmp___9=1] [L1205] COND FALSE !(s->state == 8576) [L1208] EXPR, FCALL s->state VAL [={2:-1}, blastFlag=2, got_new_session=1, init=1, ret=1, s={24578:0}, s={24578:0}, s->state=8656, skip=0, SSLv3_server_data={24587:0}, state=8656, Time=0, tmp=0, tmp___1=0, tmp___10=1, tmp___2=0, tmp___3=0, tmp___4=0, tmp___5=0, tmp___6=0, tmp___8=0, tmp___9=1] [L1208] COND FALSE !(s->state == 8577) [L1211] EXPR, FCALL s->state VAL [={2:-1}, blastFlag=2, got_new_session=1, init=1, ret=1, s={24578:0}, s={24578:0}, s->state=8656, skip=0, SSLv3_server_data={24587:0}, state=8656, Time=0, tmp=0, tmp___1=0, tmp___10=1, tmp___2=0, tmp___3=0, tmp___4=0, tmp___5=0, tmp___6=0, tmp___8=0, tmp___9=1] [L1211] COND FALSE !(s->state == 8592) [L1214] EXPR, FCALL s->state VAL [={2:-1}, blastFlag=2, got_new_session=1, init=1, ret=1, s={24578:0}, s={24578:0}, s->state=8656, skip=0, SSLv3_server_data={24587:0}, state=8656, Time=0, tmp=0, tmp___1=0, tmp___10=1, tmp___2=0, tmp___3=0, tmp___4=0, tmp___5=0, tmp___6=0, tmp___8=0, tmp___9=1] [L1214] COND FALSE !(s->state == 8593) [L1217] EXPR, FCALL s->state VAL [={2:-1}, blastFlag=2, got_new_session=1, init=1, ret=1, s={24578:0}, s={24578:0}, s->state=8656, skip=0, SSLv3_server_data={24587:0}, state=8656, Time=0, tmp=0, tmp___1=0, tmp___10=1, tmp___2=0, tmp___3=0, tmp___4=0, tmp___5=0, tmp___6=0, tmp___8=0, tmp___9=1] [L1217] COND FALSE !(s->state == 8608) [L1220] EXPR, FCALL s->state VAL [={2:-1}, blastFlag=2, got_new_session=1, init=1, ret=1, s={24578:0}, s={24578:0}, s->state=8656, skip=0, SSLv3_server_data={24587:0}, state=8656, Time=0, tmp=0, tmp___1=0, tmp___10=1, tmp___2=0, tmp___3=0, tmp___4=0, tmp___5=0, tmp___6=0, tmp___8=0, tmp___9=1] [L1220] COND FALSE !(s->state == 8609) [L1223] EXPR, FCALL s->state VAL [={2:-1}, blastFlag=2, got_new_session=1, init=1, ret=1, s={24578:0}, s={24578:0}, s->state=8656, skip=0, SSLv3_server_data={24587:0}, state=8656, Time=0, tmp=0, tmp___1=0, tmp___10=1, tmp___2=0, tmp___3=0, tmp___4=0, tmp___5=0, tmp___6=0, tmp___8=0, tmp___9=1] [L1223] COND FALSE !(s->state == 8640) [L1226] EXPR, FCALL s->state VAL [={2:-1}, blastFlag=2, got_new_session=1, init=1, ret=1, s={24578:0}, s={24578:0}, s->state=8656, skip=0, SSLv3_server_data={24587:0}, state=8656, Time=0, tmp=0, tmp___1=0, tmp___10=1, tmp___2=0, tmp___3=0, tmp___4=0, tmp___5=0, tmp___6=0, tmp___8=0, tmp___9=1] [L1226] COND FALSE !(s->state == 8641) [L1229] EXPR, FCALL s->state VAL [={2:-1}, blastFlag=2, got_new_session=1, init=1, ret=1, s={24578:0}, s={24578:0}, s->state=8656, skip=0, SSLv3_server_data={24587:0}, state=8656, Time=0, tmp=0, tmp___1=0, tmp___10=1, tmp___2=0, tmp___3=0, tmp___4=0, tmp___5=0, tmp___6=0, tmp___8=0, tmp___9=1] [L1229] COND TRUE s->state == 8656 [L1550] EXPR, FCALL s->session [L1550] EXPR, FCALL s->s3 [L1550] EXPR, FCALL (s->s3)->tmp.new_cipher [L1550] FCALL (s->session)->cipher = (s->s3)->tmp.new_cipher [L1551] COND FALSE !(! tmp___9) [L1557] ret = __VERIFIER_nondet_int() [L1558] COND TRUE blastFlag == 2 [L1559] blastFlag = 4 VAL [={2:-1}, blastFlag=4, got_new_session=1, init=1, ret=1, s={24578:0}, s={24578:0}, skip=0, SSLv3_server_data={24587:0}, state=8656, Time=0, tmp=0, tmp___1=0, tmp___10=1, tmp___2=0, tmp___3=0, tmp___4=0, tmp___5=0, tmp___6=0, tmp___8=0, tmp___9=1] [L1567] COND FALSE !(ret <= 0) [L1572] FCALL s->state = 8672 [L1573] FCALL s->init_num = 0 VAL [={2:-1}, blastFlag=4, got_new_session=1, init=1, ret=1, s={24578:0}, s={24578:0}, skip=0, SSLv3_server_data={24587:0}, state=8656, Time=0, tmp=0, tmp___1=0, tmp___10=1, tmp___2=0, tmp___3=0, tmp___4=0, tmp___5=0, tmp___6=0, tmp___8=0, tmp___9=1] [L1574] COND FALSE !(! tmp___10) VAL [={2:-1}, blastFlag=4, got_new_session=1, init=1, ret=1, s={24578:0}, s={24578:0}, skip=0, SSLv3_server_data={24587:0}, state=8656, Time=0, tmp=0, tmp___1=0, tmp___10=1, tmp___2=0, tmp___3=0, tmp___4=0, tmp___5=0, tmp___6=0, tmp___8=0, tmp___9=1] [L1661] EXPR, FCALL s->s3 [L1661] EXPR, FCALL (s->s3)->tmp.reuse_message VAL [={2:-1}, (s->s3)->tmp.reuse_message=24579, blastFlag=4, got_new_session=1, init=1, ret=1, s={24578:0}, s={24578:0}, s->s3={24583:0}, skip=0, SSLv3_server_data={24587:0}, state=8656, Time=0, tmp=0, tmp___1=0, tmp___10=1, tmp___2=0, tmp___3=0, tmp___4=0, tmp___5=0, tmp___6=0, tmp___8=0, tmp___9=1] [L1661] COND FALSE !(! (s->s3)->tmp.reuse_message) [L1690] skip = 0 VAL [={2:-1}, blastFlag=4, got_new_session=1, init=1, ret=1, s={24578:0}, s={24578:0}, skip=0, SSLv3_server_data={24587:0}, state=8656, Time=0, tmp=0, tmp___1=0, tmp___10=1, tmp___2=0, tmp___3=0, tmp___4=0, tmp___5=0, tmp___6=0, tmp___8=0, tmp___9=1] [L1136] COND TRUE 1 VAL [={2:-1}, blastFlag=4, got_new_session=1, init=1, ret=1, s={24578:0}, s={24578:0}, skip=0, SSLv3_server_data={24587:0}, state=8656, Time=0, tmp=0, tmp___1=0, tmp___10=1, tmp___2=0, tmp___3=0, tmp___4=0, tmp___5=0, tmp___6=0, tmp___8=0, tmp___9=1] [L1138] EXPR, FCALL s->state [L1138] state = s->state [L1139] EXPR, FCALL s->state VAL [={2:-1}, blastFlag=4, got_new_session=1, init=1, ret=1, s={24578:0}, s={24578:0}, s->state=8672, skip=0, SSLv3_server_data={24587:0}, state=8672, Time=0, tmp=0, tmp___1=0, tmp___10=1, tmp___2=0, tmp___3=0, tmp___4=0, tmp___5=0, tmp___6=0, tmp___8=0, tmp___9=1] [L1139] COND FALSE !(s->state == 12292) [L1142] EXPR, FCALL s->state VAL [={2:-1}, blastFlag=4, got_new_session=1, init=1, ret=1, s={24578:0}, s={24578:0}, s->state=8672, skip=0, SSLv3_server_data={24587:0}, state=8672, Time=0, tmp=0, tmp___1=0, tmp___10=1, tmp___2=0, tmp___3=0, tmp___4=0, tmp___5=0, tmp___6=0, tmp___8=0, tmp___9=1] [L1142] COND FALSE !(s->state == 16384) [L1145] EXPR, FCALL s->state VAL [={2:-1}, blastFlag=4, got_new_session=1, init=1, ret=1, s={24578:0}, s={24578:0}, s->state=8672, skip=0, SSLv3_server_data={24587:0}, state=8672, Time=0, tmp=0, tmp___1=0, tmp___10=1, tmp___2=0, tmp___3=0, tmp___4=0, tmp___5=0, tmp___6=0, tmp___8=0, tmp___9=1] [L1145] COND FALSE !(s->state == 8192) [L1148] EXPR, FCALL s->state VAL [={2:-1}, blastFlag=4, got_new_session=1, init=1, ret=1, s={24578:0}, s={24578:0}, s->state=8672, skip=0, SSLv3_server_data={24587:0}, state=8672, Time=0, tmp=0, tmp___1=0, tmp___10=1, tmp___2=0, tmp___3=0, tmp___4=0, tmp___5=0, tmp___6=0, tmp___8=0, tmp___9=1] [L1148] COND FALSE !(s->state == 24576) [L1151] EXPR, FCALL s->state VAL [={2:-1}, blastFlag=4, got_new_session=1, init=1, ret=1, s={24578:0}, s={24578:0}, s->state=8672, skip=0, SSLv3_server_data={24587:0}, state=8672, Time=0, tmp=0, tmp___1=0, tmp___10=1, tmp___2=0, tmp___3=0, tmp___4=0, tmp___5=0, tmp___6=0, tmp___8=0, tmp___9=1] [L1151] COND FALSE !(s->state == 8195) [L1154] EXPR, FCALL s->state VAL [={2:-1}, blastFlag=4, got_new_session=1, init=1, ret=1, s={24578:0}, s={24578:0}, s->state=8672, skip=0, SSLv3_server_data={24587:0}, state=8672, Time=0, tmp=0, tmp___1=0, tmp___10=1, tmp___2=0, tmp___3=0, tmp___4=0, tmp___5=0, tmp___6=0, tmp___8=0, tmp___9=1] [L1154] COND FALSE !(s->state == 8480) [L1157] EXPR, FCALL s->state VAL [={2:-1}, blastFlag=4, got_new_session=1, init=1, ret=1, s={24578:0}, s={24578:0}, s->state=8672, skip=0, SSLv3_server_data={24587:0}, state=8672, Time=0, tmp=0, tmp___1=0, tmp___10=1, tmp___2=0, tmp___3=0, tmp___4=0, tmp___5=0, tmp___6=0, tmp___8=0, tmp___9=1] [L1157] COND FALSE !(s->state == 8481) [L1160] EXPR, FCALL s->state VAL [={2:-1}, blastFlag=4, got_new_session=1, init=1, ret=1, s={24578:0}, s={24578:0}, s->state=8672, skip=0, SSLv3_server_data={24587:0}, state=8672, Time=0, tmp=0, tmp___1=0, tmp___10=1, tmp___2=0, tmp___3=0, tmp___4=0, tmp___5=0, tmp___6=0, tmp___8=0, tmp___9=1] [L1160] COND FALSE !(s->state == 8482) [L1163] EXPR, FCALL s->state VAL [={2:-1}, blastFlag=4, got_new_session=1, init=1, ret=1, s={24578:0}, s={24578:0}, s->state=8672, skip=0, SSLv3_server_data={24587:0}, state=8672, Time=0, tmp=0, tmp___1=0, tmp___10=1, tmp___2=0, tmp___3=0, tmp___4=0, tmp___5=0, tmp___6=0, tmp___8=0, tmp___9=1] [L1163] COND FALSE !(s->state == 8464) [L1166] EXPR, FCALL s->state VAL [={2:-1}, blastFlag=4, got_new_session=1, init=1, ret=1, s={24578:0}, s={24578:0}, s->state=8672, skip=0, SSLv3_server_data={24587:0}, state=8672, Time=0, tmp=0, tmp___1=0, tmp___10=1, tmp___2=0, tmp___3=0, tmp___4=0, tmp___5=0, tmp___6=0, tmp___8=0, tmp___9=1] [L1166] COND FALSE !(s->state == 8465) [L1169] EXPR, FCALL s->state VAL [={2:-1}, blastFlag=4, got_new_session=1, init=1, ret=1, s={24578:0}, s={24578:0}, s->state=8672, skip=0, SSLv3_server_data={24587:0}, state=8672, Time=0, tmp=0, tmp___1=0, tmp___10=1, tmp___2=0, tmp___3=0, tmp___4=0, tmp___5=0, tmp___6=0, tmp___8=0, tmp___9=1] [L1169] COND FALSE !(s->state == 8466) [L1172] EXPR, FCALL s->state VAL [={2:-1}, blastFlag=4, got_new_session=1, init=1, ret=1, s={24578:0}, s={24578:0}, s->state=8672, skip=0, SSLv3_server_data={24587:0}, state=8672, Time=0, tmp=0, tmp___1=0, tmp___10=1, tmp___2=0, tmp___3=0, tmp___4=0, tmp___5=0, tmp___6=0, tmp___8=0, tmp___9=1] [L1172] COND FALSE !(s->state == 8496) [L1175] EXPR, FCALL s->state VAL [={2:-1}, blastFlag=4, got_new_session=1, init=1, ret=1, s={24578:0}, s={24578:0}, s->state=8672, skip=0, SSLv3_server_data={24587:0}, state=8672, Time=0, tmp=0, tmp___1=0, tmp___10=1, tmp___2=0, tmp___3=0, tmp___4=0, tmp___5=0, tmp___6=0, tmp___8=0, tmp___9=1] [L1175] COND FALSE !(s->state == 8497) [L1178] EXPR, FCALL s->state VAL [={2:-1}, blastFlag=4, got_new_session=1, init=1, ret=1, s={24578:0}, s={24578:0}, s->state=8672, skip=0, SSLv3_server_data={24587:0}, state=8672, Time=0, tmp=0, tmp___1=0, tmp___10=1, tmp___2=0, tmp___3=0, tmp___4=0, tmp___5=0, tmp___6=0, tmp___8=0, tmp___9=1] [L1178] COND FALSE !(s->state == 8512) [L1181] EXPR, FCALL s->state VAL [={2:-1}, blastFlag=4, got_new_session=1, init=1, ret=1, s={24578:0}, s={24578:0}, s->state=8672, skip=0, SSLv3_server_data={24587:0}, state=8672, Time=0, tmp=0, tmp___1=0, tmp___10=1, tmp___2=0, tmp___3=0, tmp___4=0, tmp___5=0, tmp___6=0, tmp___8=0, tmp___9=1] [L1181] COND FALSE !(s->state == 8513) [L1184] EXPR, FCALL s->state VAL [={2:-1}, blastFlag=4, got_new_session=1, init=1, ret=1, s={24578:0}, s={24578:0}, s->state=8672, skip=0, SSLv3_server_data={24587:0}, state=8672, Time=0, tmp=0, tmp___1=0, tmp___10=1, tmp___2=0, tmp___3=0, tmp___4=0, tmp___5=0, tmp___6=0, tmp___8=0, tmp___9=1] [L1184] COND FALSE !(s->state == 8528) [L1187] EXPR, FCALL s->state VAL [={2:-1}, blastFlag=4, got_new_session=1, init=1, ret=1, s={24578:0}, s={24578:0}, s->state=8672, skip=0, SSLv3_server_data={24587:0}, state=8672, Time=0, tmp=0, tmp___1=0, tmp___10=1, tmp___2=0, tmp___3=0, tmp___4=0, tmp___5=0, tmp___6=0, tmp___8=0, tmp___9=1] [L1187] COND FALSE !(s->state == 8529) [L1190] EXPR, FCALL s->state VAL [={2:-1}, blastFlag=4, got_new_session=1, init=1, ret=1, s={24578:0}, s={24578:0}, s->state=8672, skip=0, SSLv3_server_data={24587:0}, state=8672, Time=0, tmp=0, tmp___1=0, tmp___10=1, tmp___2=0, tmp___3=0, tmp___4=0, tmp___5=0, tmp___6=0, tmp___8=0, tmp___9=1] [L1190] COND FALSE !(s->state == 8544) [L1193] EXPR, FCALL s->state VAL [={2:-1}, blastFlag=4, got_new_session=1, init=1, ret=1, s={24578:0}, s={24578:0}, s->state=8672, skip=0, SSLv3_server_data={24587:0}, state=8672, Time=0, tmp=0, tmp___1=0, tmp___10=1, tmp___2=0, tmp___3=0, tmp___4=0, tmp___5=0, tmp___6=0, tmp___8=0, tmp___9=1] [L1193] COND FALSE !(s->state == 8545) [L1196] EXPR, FCALL s->state VAL [={2:-1}, blastFlag=4, got_new_session=1, init=1, ret=1, s={24578:0}, s={24578:0}, s->state=8672, skip=0, SSLv3_server_data={24587:0}, state=8672, Time=0, tmp=0, tmp___1=0, tmp___10=1, tmp___2=0, tmp___3=0, tmp___4=0, tmp___5=0, tmp___6=0, tmp___8=0, tmp___9=1] [L1196] COND FALSE !(s->state == 8560) [L1199] EXPR, FCALL s->state VAL [={2:-1}, blastFlag=4, got_new_session=1, init=1, ret=1, s={24578:0}, s={24578:0}, s->state=8672, skip=0, SSLv3_server_data={24587:0}, state=8672, Time=0, tmp=0, tmp___1=0, tmp___10=1, tmp___2=0, tmp___3=0, tmp___4=0, tmp___5=0, tmp___6=0, tmp___8=0, tmp___9=1] [L1199] COND FALSE !(s->state == 8561) [L1202] EXPR, FCALL s->state VAL [={2:-1}, blastFlag=4, got_new_session=1, init=1, ret=1, s={24578:0}, s={24578:0}, s->state=8672, skip=0, SSLv3_server_data={24587:0}, state=8672, Time=0, tmp=0, tmp___1=0, tmp___10=1, tmp___2=0, tmp___3=0, tmp___4=0, tmp___5=0, tmp___6=0, tmp___8=0, tmp___9=1] [L1202] COND FALSE !(s->state == 8448) [L1205] EXPR, FCALL s->state VAL [={2:-1}, blastFlag=4, got_new_session=1, init=1, ret=1, s={24578:0}, s={24578:0}, s->state=8672, skip=0, SSLv3_server_data={24587:0}, state=8672, Time=0, tmp=0, tmp___1=0, tmp___10=1, tmp___2=0, tmp___3=0, tmp___4=0, tmp___5=0, tmp___6=0, tmp___8=0, tmp___9=1] [L1205] COND FALSE !(s->state == 8576) [L1208] EXPR, FCALL s->state VAL [={2:-1}, blastFlag=4, got_new_session=1, init=1, ret=1, s={24578:0}, s={24578:0}, s->state=8672, skip=0, SSLv3_server_data={24587:0}, state=8672, Time=0, tmp=0, tmp___1=0, tmp___10=1, tmp___2=0, tmp___3=0, tmp___4=0, tmp___5=0, tmp___6=0, tmp___8=0, tmp___9=1] [L1208] COND FALSE !(s->state == 8577) [L1211] EXPR, FCALL s->state VAL [={2:-1}, blastFlag=4, got_new_session=1, init=1, ret=1, s={24578:0}, s={24578:0}, s->state=8672, skip=0, SSLv3_server_data={24587:0}, state=8672, Time=0, tmp=0, tmp___1=0, tmp___10=1, tmp___2=0, tmp___3=0, tmp___4=0, tmp___5=0, tmp___6=0, tmp___8=0, tmp___9=1] [L1211] COND FALSE !(s->state == 8592) [L1214] EXPR, FCALL s->state VAL [={2:-1}, blastFlag=4, got_new_session=1, init=1, ret=1, s={24578:0}, s={24578:0}, s->state=8672, skip=0, SSLv3_server_data={24587:0}, state=8672, Time=0, tmp=0, tmp___1=0, tmp___10=1, tmp___2=0, tmp___3=0, tmp___4=0, tmp___5=0, tmp___6=0, tmp___8=0, tmp___9=1] [L1214] COND FALSE !(s->state == 8593) [L1217] EXPR, FCALL s->state VAL [={2:-1}, blastFlag=4, got_new_session=1, init=1, ret=1, s={24578:0}, s={24578:0}, s->state=8672, skip=0, SSLv3_server_data={24587:0}, state=8672, Time=0, tmp=0, tmp___1=0, tmp___10=1, tmp___2=0, tmp___3=0, tmp___4=0, tmp___5=0, tmp___6=0, tmp___8=0, tmp___9=1] [L1217] COND FALSE !(s->state == 8608) [L1220] EXPR, FCALL s->state VAL [={2:-1}, blastFlag=4, got_new_session=1, init=1, ret=1, s={24578:0}, s={24578:0}, s->state=8672, skip=0, SSLv3_server_data={24587:0}, state=8672, Time=0, tmp=0, tmp___1=0, tmp___10=1, tmp___2=0, tmp___3=0, tmp___4=0, tmp___5=0, tmp___6=0, tmp___8=0, tmp___9=1] [L1220] COND FALSE !(s->state == 8609) [L1223] EXPR, FCALL s->state VAL [={2:-1}, blastFlag=4, got_new_session=1, init=1, ret=1, s={24578:0}, s={24578:0}, s->state=8672, skip=0, SSLv3_server_data={24587:0}, state=8672, Time=0, tmp=0, tmp___1=0, tmp___10=1, tmp___2=0, tmp___3=0, tmp___4=0, tmp___5=0, tmp___6=0, tmp___8=0, tmp___9=1] [L1223] COND FALSE !(s->state == 8640) [L1226] EXPR, FCALL s->state VAL [={2:-1}, blastFlag=4, got_new_session=1, init=1, ret=1, s={24578:0}, s={24578:0}, s->state=8672, skip=0, SSLv3_server_data={24587:0}, state=8672, Time=0, tmp=0, tmp___1=0, tmp___10=1, tmp___2=0, tmp___3=0, tmp___4=0, tmp___5=0, tmp___6=0, tmp___8=0, tmp___9=1] [L1226] COND FALSE !(s->state == 8641) [L1229] EXPR, FCALL s->state VAL [={2:-1}, blastFlag=4, got_new_session=1, init=1, ret=1, s={24578:0}, s={24578:0}, s->state=8672, skip=0, SSLv3_server_data={24587:0}, state=8672, Time=0, tmp=0, tmp___1=0, tmp___10=1, tmp___2=0, tmp___3=0, tmp___4=0, tmp___5=0, tmp___6=0, tmp___8=0, tmp___9=1] [L1229] COND FALSE !(s->state == 8656) [L1232] EXPR, FCALL s->state VAL [={2:-1}, blastFlag=4, got_new_session=1, init=1, ret=1, s={24578:0}, s={24578:0}, s->state=8672, skip=0, SSLv3_server_data={24587:0}, state=8672, Time=0, tmp=0, tmp___1=0, tmp___10=1, tmp___2=0, tmp___3=0, tmp___4=0, tmp___5=0, tmp___6=0, tmp___8=0, tmp___9=1] [L1232] COND FALSE !(s->state == 8657) [L1235] EXPR, FCALL s->state VAL [={2:-1}, blastFlag=4, got_new_session=1, init=1, ret=1, s={24578:0}, s={24578:0}, s->state=8672, skip=0, SSLv3_server_data={24587:0}, state=8672, Time=0, tmp=0, tmp___1=0, tmp___10=1, tmp___2=0, tmp___3=0, tmp___4=0, tmp___5=0, tmp___6=0, tmp___8=0, tmp___9=1] [L1235] COND TRUE s->state == 8672 [L1583] ret = __VERIFIER_nondet_int() [L1584] COND TRUE blastFlag == 4 VAL [={2:-1}, blastFlag=4, got_new_session=1, init=1, ret=0, s={24578:0}, s={24578:0}, skip=0, SSLv3_server_data={24587:0}, state=8672, Time=0, tmp=0, tmp___1=0, tmp___10=1, tmp___2=0, tmp___3=0, tmp___4=0, tmp___5=0, tmp___6=0, tmp___8=0, tmp___9=1] [L1702] __VERIFIER_error() VAL [={2:-1}, blastFlag=4, got_new_session=1, init=1, ret=0, s={24578:0}, s={24578:0}, skip=0, SSLv3_server_data={24587:0}, state=8672, Time=0, tmp=0, tmp___1=0, tmp___10=1, tmp___2=0, tmp___3=0, tmp___4=0, tmp___5=0, tmp___6=0, tmp___8=0, tmp___9=1] - StatisticsResult: Ultimate Automizer benchmark data CFG has 9 procedures, 183 locations, 1 error locations. UNSAFE Result, 60.5s OverallTime, 22 OverallIterations, 4 TraceHistogramMax, 46.0s AutomataDifference, 0.0s DeadEndRemovalTime, 0.0s HoareAnnotationTime, HoareTripleCheckerStatistics: 4152 SDtfs, 841 SDslu, 6047 SDs, 0 SdLazy, 2934 SolverSat, 123 SolverUnsat, 0 SolverUnknown, 0 SolverNotchecked, 7.1s Time, PredicateUnifierStatistics: 0 DeclaredPredicates, 132 GetRequests, 42 SyntacticMatches, 30 SemanticMatches, 60 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 0 ImplicationChecksByTransitivity, 4.0s Time, 0.0s BasicInterpolantAutomatonTime, BiggestAbstraction: size=535occurred in iteration=21, traceCheckStatistics: No data available, InterpolantConsolidationStatistics: No data available, PathInvariantsStatistics: No data available, 0/0 InterpolantCoveringCapability, TotalInterpolationStatistics: No data available, 0.0s AbstIntTime, 0 AbstIntIterations, 0 AbstIntStrong, NaN AbsIntWeakeningRatio, NaN AbsIntAvgWeakeningVarsNumRemoved, NaN AbsIntAvgWeakenedConjuncts, 0.0s DumpTime, AutomataMinimizationStatistics: 2.4s AutomataMinimizationTime, 21 MinimizatonAttempts, 312 StatesRemovedByMinimization, 18 NontrivialMinimizations, HoareAnnotationStatistics: No data available, RefinementEngineStatistics: TraceCheckStatistics: 0.1s SsaConstructionTime, 0.6s SatisfiabilityAnalysisTime, 8.1s InterpolantComputationTime, 1759 NumberOfCodeBlocks, 1759 NumberOfCodeBlocksAsserted, 22 NumberOfCheckSat, 1603 ConstructedInterpolants, 0 QuantifiedInterpolants, 355518 SizeOfPredicates, 0 NumberOfNonLiveVariables, 0 ConjunctsInSsa, 0 ConjunctsInUnsatCore, 21 InterpolantComputations, 21 PerfectInterpolantSequences, 419/419 InterpolantCoveringCapability, InvariantSynthesisStatistics: No data available, InterpolantConsolidationStatistics: No data available, ReuseStatistics: No data available RESULT: Ultimate could not prove your program: unable to determine feasibility of some traces Received shutdown request...