java -ea -Xmx8000000000 -jar /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/plugins/org.eclipse.equinox.launcher_1.3.100.v20150511-1540.jar -data @noDefault -ultimatedata /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/data -tc ../../../trunk/examples/toolchains/AutomizerCInline_WitnessPrinter.xml -s ../../../trunk/examples/settings/default/automizer/svcomp-Reach-32bit-Automizer_Bitvector.epf -i ../../../trunk/examples/svcomp/ssh/s3_srvr.blast.08_false-unreach-call.i.cil.c -------------------------------------------------------------------------------- This is Ultimate 0.1.23-61f4311 [2018-11-23 10:58:29,040 INFO L170 SettingsManager]: Resetting all preferences to default values... [2018-11-23 10:58:29,042 INFO L174 SettingsManager]: Resetting UltimateCore preferences to default values [2018-11-23 10:58:29,056 INFO L177 SettingsManager]: Ultimate Commandline Interface provides no preferences, ignoring... [2018-11-23 10:58:29,056 INFO L174 SettingsManager]: Resetting Boogie Preprocessor preferences to default values [2018-11-23 10:58:29,057 INFO L174 SettingsManager]: Resetting Boogie Procedure Inliner preferences to default values [2018-11-23 10:58:29,058 INFO L174 SettingsManager]: Resetting Abstract Interpretation preferences to default values [2018-11-23 10:58:29,060 INFO L174 SettingsManager]: Resetting LassoRanker preferences to default values [2018-11-23 10:58:29,062 INFO L174 SettingsManager]: Resetting Reaching Definitions preferences to default values [2018-11-23 10:58:29,063 INFO L174 SettingsManager]: Resetting SyntaxChecker preferences to default values [2018-11-23 10:58:29,064 INFO L177 SettingsManager]: Büchi Program Product provides no preferences, ignoring... [2018-11-23 10:58:29,064 INFO L174 SettingsManager]: Resetting LTL2Aut preferences to default values [2018-11-23 10:58:29,065 INFO L174 SettingsManager]: Resetting PEA to Boogie preferences to default values [2018-11-23 10:58:29,066 INFO L174 SettingsManager]: Resetting BlockEncodingV2 preferences to default values [2018-11-23 10:58:29,067 INFO L174 SettingsManager]: Resetting ChcToBoogie preferences to default values [2018-11-23 10:58:29,068 INFO L174 SettingsManager]: Resetting AutomataScriptInterpreter preferences to default values [2018-11-23 10:58:29,069 INFO L174 SettingsManager]: Resetting BuchiAutomizer preferences to default values [2018-11-23 10:58:29,070 INFO L174 SettingsManager]: Resetting CACSL2BoogieTranslator preferences to default values [2018-11-23 10:58:29,073 INFO L174 SettingsManager]: Resetting CodeCheck preferences to default values [2018-11-23 10:58:29,074 INFO L174 SettingsManager]: Resetting InvariantSynthesis preferences to default values [2018-11-23 10:58:29,075 INFO L174 SettingsManager]: Resetting RCFGBuilder preferences to default values [2018-11-23 10:58:29,077 INFO L174 SettingsManager]: Resetting TraceAbstraction preferences to default values [2018-11-23 10:58:29,079 INFO L177 SettingsManager]: TraceAbstractionConcurrent provides no preferences, ignoring... [2018-11-23 10:58:29,079 INFO L177 SettingsManager]: TraceAbstractionWithAFAs provides no preferences, ignoring... [2018-11-23 10:58:29,080 INFO L174 SettingsManager]: Resetting TreeAutomizer preferences to default values [2018-11-23 10:58:29,081 INFO L174 SettingsManager]: Resetting IcfgTransformer preferences to default values [2018-11-23 10:58:29,082 INFO L174 SettingsManager]: Resetting Boogie Printer preferences to default values [2018-11-23 10:58:29,083 INFO L174 SettingsManager]: Resetting ReqPrinter preferences to default values [2018-11-23 10:58:29,083 INFO L174 SettingsManager]: Resetting Witness Printer preferences to default values [2018-11-23 10:58:29,084 INFO L177 SettingsManager]: Boogie PL CUP Parser provides no preferences, ignoring... [2018-11-23 10:58:29,085 INFO L174 SettingsManager]: Resetting CDTParser preferences to default values [2018-11-23 10:58:29,085 INFO L177 SettingsManager]: AutomataScriptParser provides no preferences, ignoring... [2018-11-23 10:58:29,086 INFO L177 SettingsManager]: ReqParser provides no preferences, ignoring... [2018-11-23 10:58:29,086 INFO L174 SettingsManager]: Resetting SmtParser preferences to default values [2018-11-23 10:58:29,087 INFO L174 SettingsManager]: Resetting Witness Parser preferences to default values [2018-11-23 10:58:29,088 INFO L181 SettingsManager]: Finished resetting all preferences to default values... [2018-11-23 10:58:29,088 INFO L98 SettingsManager]: Beginning loading settings from /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/../../../trunk/examples/settings/default/automizer/svcomp-Reach-32bit-Automizer_Bitvector.epf [2018-11-23 10:58:29,111 INFO L110 SettingsManager]: Loading preferences was successful [2018-11-23 10:58:29,112 INFO L112 SettingsManager]: Preferences different from defaults after loading the file: [2018-11-23 10:58:29,112 INFO L131 SettingsManager]: Preferences of Boogie Procedure Inliner differ from their defaults: [2018-11-23 10:58:29,115 INFO L133 SettingsManager]: * ... calls to implemented procedures=ONLY_FOR_CONCURRENT_PROGRAMS [2018-11-23 10:58:29,116 INFO L131 SettingsManager]: Preferences of BlockEncodingV2 differ from their defaults: [2018-11-23 10:58:29,116 INFO L133 SettingsManager]: * Create parallel compositions if possible=false [2018-11-23 10:58:29,116 INFO L133 SettingsManager]: * Use SBE=true [2018-11-23 10:58:29,117 INFO L131 SettingsManager]: Preferences of CACSL2BoogieTranslator differ from their defaults: [2018-11-23 10:58:29,117 INFO L133 SettingsManager]: * sizeof long=4 [2018-11-23 10:58:29,117 INFO L133 SettingsManager]: * sizeof POINTER=4 [2018-11-23 10:58:29,117 INFO L133 SettingsManager]: * Check division by zero=IGNORE [2018-11-23 10:58:29,117 INFO L133 SettingsManager]: * Pointer to allocated memory at dereference=IGNORE [2018-11-23 10:58:29,117 INFO L133 SettingsManager]: * If two pointers are subtracted or compared they have the same base address=IGNORE [2018-11-23 10:58:29,118 INFO L133 SettingsManager]: * Check array bounds for arrays that are off heap=IGNORE [2018-11-23 10:58:29,118 INFO L133 SettingsManager]: * Use bitvectors instead of ints=true [2018-11-23 10:58:29,118 INFO L133 SettingsManager]: * Memory model=HoenickeLindenmann_4ByteResolution [2018-11-23 10:58:29,118 INFO L133 SettingsManager]: * sizeof long double=12 [2018-11-23 10:58:29,118 INFO L133 SettingsManager]: * Check if freed pointer was valid=false [2018-11-23 10:58:29,119 INFO L133 SettingsManager]: * Use constant arrays=true [2018-11-23 10:58:29,120 INFO L133 SettingsManager]: * Pointer base address is valid at dereference=IGNORE [2018-11-23 10:58:29,120 INFO L131 SettingsManager]: Preferences of RCFGBuilder differ from their defaults: [2018-11-23 10:58:29,120 INFO L133 SettingsManager]: * Size of a code block=SequenceOfStatements [2018-11-23 10:58:29,120 INFO L133 SettingsManager]: * To the following directory=./dump/ [2018-11-23 10:58:29,121 INFO L133 SettingsManager]: * SMT solver=External_DefaultMode [2018-11-23 10:58:29,121 INFO L133 SettingsManager]: * Command for external solver=z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in -t:2000 [2018-11-23 10:58:29,121 INFO L131 SettingsManager]: Preferences of TraceAbstraction differ from their defaults: [2018-11-23 10:58:29,121 INFO L133 SettingsManager]: * Compute Interpolants along a Counterexample=FPandBP [2018-11-23 10:58:29,121 INFO L133 SettingsManager]: * Positions where we compute the Hoare Annotation=LoopsAndPotentialCycles [2018-11-23 10:58:29,122 INFO L133 SettingsManager]: * Trace refinement strategy=WOLF [2018-11-23 10:58:29,122 INFO L133 SettingsManager]: * SMT solver=External_ModelsAndUnsatCoreMode [2018-11-23 10:58:29,122 INFO L133 SettingsManager]: * Command for external solver=cvc4nyu --tear-down-incremental --rewrite-divk --print-success --lang smt [2018-11-23 10:58:29,123 INFO L133 SettingsManager]: * Logic for external solver=AUFBV [2018-11-23 10:58:29,123 INFO L133 SettingsManager]: * Compute Hoare Annotation of negated interpolant automaton, abstraction and CFG=true [2018-11-23 10:58:29,187 INFO L81 nceAwareModelManager]: Repository-Root is: /tmp [2018-11-23 10:58:29,202 INFO L258 ainManager$Toolchain]: [Toolchain 1]: Applicable parser(s) successfully (re)initialized [2018-11-23 10:58:29,206 INFO L214 ainManager$Toolchain]: [Toolchain 1]: Toolchain selected. [2018-11-23 10:58:29,208 INFO L271 PluginConnector]: Initializing CDTParser... [2018-11-23 10:58:29,208 INFO L276 PluginConnector]: CDTParser initialized [2018-11-23 10:58:29,209 INFO L418 ainManager$Toolchain]: [Toolchain 1]: Parsing single file: /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/../../../trunk/examples/svcomp/ssh/s3_srvr.blast.08_false-unreach-call.i.cil.c [2018-11-23 10:58:29,271 INFO L221 CDTParser]: Created temporary CDT project at /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/data/9d00603d6/5f0452271c2b40d58f4752fbc7e50d26/FLAG87c356f0b [2018-11-23 10:58:29,971 INFO L307 CDTParser]: Found 1 translation units. [2018-11-23 10:58:29,973 INFO L161 CDTParser]: Scanning /storage/repos/ultimate/trunk/examples/svcomp/ssh/s3_srvr.blast.08_false-unreach-call.i.cil.c [2018-11-23 10:58:30,012 INFO L355 CDTParser]: About to delete temporary CDT project at /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/data/9d00603d6/5f0452271c2b40d58f4752fbc7e50d26/FLAG87c356f0b [2018-11-23 10:58:30,153 INFO L363 CDTParser]: Successfully deleted /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/data/9d00603d6/5f0452271c2b40d58f4752fbc7e50d26 [2018-11-23 10:58:30,163 INFO L296 ainManager$Toolchain]: ####################### [Toolchain 1] ####################### [2018-11-23 10:58:30,164 INFO L131 ToolchainWalker]: Walking toolchain with 6 elements. [2018-11-23 10:58:30,167 INFO L113 PluginConnector]: ------------------------CACSL2BoogieTranslator---------------------------- [2018-11-23 10:58:30,167 INFO L271 PluginConnector]: Initializing CACSL2BoogieTranslator... [2018-11-23 10:58:30,171 INFO L276 PluginConnector]: CACSL2BoogieTranslator initialized [2018-11-23 10:58:30,173 INFO L185 PluginConnector]: Executing the observer ACSLObjectContainerObserver from plugin CACSL2BoogieTranslator for "CDTParser AST 23.11 10:58:30" (1/1) ... [2018-11-23 10:58:30,176 INFO L205 PluginConnector]: Invalid model from CACSL2BoogieTranslator for observer de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator.ACSLObjectContainerObserver@57a41dd6 and model type de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 23.11 10:58:30, skipping insertion in model container [2018-11-23 10:58:30,177 INFO L185 PluginConnector]: Executing the observer CACSL2BoogieTranslatorObserver from plugin CACSL2BoogieTranslator for "CDTParser AST 23.11 10:58:30" (1/1) ... [2018-11-23 10:58:30,188 INFO L145 MainTranslator]: Starting translation in SV-COMP mode [2018-11-23 10:58:30,270 INFO L176 MainTranslator]: Built tables and reachable declarations [2018-11-23 10:58:30,942 INFO L201 PostProcessor]: Analyzing one entry point: main [2018-11-23 10:58:30,978 INFO L191 MainTranslator]: Completed pre-run [2018-11-23 10:58:31,274 INFO L201 PostProcessor]: Analyzing one entry point: main [2018-11-23 10:58:31,302 INFO L195 MainTranslator]: Completed translation [2018-11-23 10:58:31,303 INFO L202 PluginConnector]: Adding new model de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 23.11 10:58:31 WrapperNode [2018-11-23 10:58:31,303 INFO L132 PluginConnector]: ------------------------ END CACSL2BoogieTranslator---------------------------- [2018-11-23 10:58:31,304 INFO L113 PluginConnector]: ------------------------Boogie Procedure Inliner---------------------------- [2018-11-23 10:58:31,305 INFO L271 PluginConnector]: Initializing Boogie Procedure Inliner... [2018-11-23 10:58:31,305 INFO L276 PluginConnector]: Boogie Procedure Inliner initialized [2018-11-23 10:58:31,316 INFO L185 PluginConnector]: Executing the observer TypeChecker from plugin Boogie Procedure Inliner for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 23.11 10:58:31" (1/1) ... [2018-11-23 10:58:31,346 INFO L185 PluginConnector]: Executing the observer Inliner from plugin Boogie Procedure Inliner for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 23.11 10:58:31" (1/1) ... [2018-11-23 10:58:31,358 INFO L132 PluginConnector]: ------------------------ END Boogie Procedure Inliner---------------------------- [2018-11-23 10:58:31,359 INFO L113 PluginConnector]: ------------------------Boogie Preprocessor---------------------------- [2018-11-23 10:58:31,359 INFO L271 PluginConnector]: Initializing Boogie Preprocessor... [2018-11-23 10:58:31,359 INFO L276 PluginConnector]: Boogie Preprocessor initialized [2018-11-23 10:58:31,372 INFO L185 PluginConnector]: Executing the observer EnsureBoogieModelObserver from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 23.11 10:58:31" (1/1) ... [2018-11-23 10:58:31,373 INFO L185 PluginConnector]: Executing the observer TypeChecker from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 23.11 10:58:31" (1/1) ... [2018-11-23 10:58:31,383 INFO L185 PluginConnector]: Executing the observer ConstExpander from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 23.11 10:58:31" (1/1) ... [2018-11-23 10:58:31,383 INFO L185 PluginConnector]: Executing the observer StructExpander from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 23.11 10:58:31" (1/1) ... [2018-11-23 10:58:31,482 INFO L185 PluginConnector]: Executing the observer UnstructureCode from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 23.11 10:58:31" (1/1) ... [2018-11-23 10:58:31,502 INFO L185 PluginConnector]: Executing the observer FunctionInliner from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 23.11 10:58:31" (1/1) ... [2018-11-23 10:58:31,508 INFO L185 PluginConnector]: Executing the observer BoogieSymbolTableConstructor from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 23.11 10:58:31" (1/1) ... [2018-11-23 10:58:31,522 INFO L132 PluginConnector]: ------------------------ END Boogie Preprocessor---------------------------- [2018-11-23 10:58:31,522 INFO L113 PluginConnector]: ------------------------RCFGBuilder---------------------------- [2018-11-23 10:58:31,523 INFO L271 PluginConnector]: Initializing RCFGBuilder... [2018-11-23 10:58:31,523 INFO L276 PluginConnector]: RCFGBuilder initialized [2018-11-23 10:58:31,524 INFO L185 PluginConnector]: Executing the observer RCFGBuilderObserver from plugin RCFGBuilder for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 23.11 10:58:31" (1/1) ... No working directory specified, using /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 Starting monitored process 1 with z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in -t:2000 (exit command is (exit), workingDir is null) Waiting until toolchain timeout for monitored process 1 with z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in -t:2000 [2018-11-23 10:58:31,602 INFO L130 BoogieDeclarations]: Found specification of procedure write~init~$Pointer$ [2018-11-23 10:58:31,602 INFO L130 BoogieDeclarations]: Found specification of procedure main [2018-11-23 10:58:31,602 INFO L138 BoogieDeclarations]: Found implementation of procedure main [2018-11-23 10:58:31,603 INFO L130 BoogieDeclarations]: Found specification of procedure write~init~intINTTYPE4 [2018-11-23 10:58:31,603 INFO L130 BoogieDeclarations]: Found specification of procedure write~$Pointer$ [2018-11-23 10:58:31,603 INFO L130 BoogieDeclarations]: Found specification of procedure #Ultimate.alloc [2018-11-23 10:58:31,603 INFO L130 BoogieDeclarations]: Found specification of procedure read~intINTTYPE4 [2018-11-23 10:58:31,603 INFO L130 BoogieDeclarations]: Found specification of procedure read~$Pointer$ [2018-11-23 10:58:31,604 INFO L130 BoogieDeclarations]: Found specification of procedure ssl3_accept [2018-11-23 10:58:31,604 INFO L138 BoogieDeclarations]: Found implementation of procedure ssl3_accept [2018-11-23 10:58:31,604 INFO L130 BoogieDeclarations]: Found specification of procedure ULTIMATE.init [2018-11-23 10:58:31,604 INFO L138 BoogieDeclarations]: Found implementation of procedure ULTIMATE.init [2018-11-23 10:58:31,604 INFO L130 BoogieDeclarations]: Found specification of procedure ULTIMATE.start [2018-11-23 10:58:31,605 INFO L138 BoogieDeclarations]: Found implementation of procedure ULTIMATE.start [2018-11-23 10:58:31,605 INFO L130 BoogieDeclarations]: Found specification of procedure write~intINTTYPE4 [2018-11-23 10:58:32,254 WARN L640 $ProcedureCfgBuilder]: Two Gotos in a row! There was dead code [2018-11-23 10:58:32,254 WARN L605 $ProcedureCfgBuilder]: Label in the middle of a codeblock. [2018-11-23 10:58:37,573 INFO L275 CfgBuilder]: Using the 1 location(s) as analysis (start of procedure ULTIMATE.start) [2018-11-23 10:58:37,574 INFO L280 CfgBuilder]: Removed 1 assue(true) statements. [2018-11-23 10:58:37,575 INFO L202 PluginConnector]: Adding new model de.uni_freiburg.informatik.ultimate.plugins.generator.rcfgbuilder CFG 23.11 10:58:37 BoogieIcfgContainer [2018-11-23 10:58:37,575 INFO L132 PluginConnector]: ------------------------ END RCFGBuilder---------------------------- [2018-11-23 10:58:37,576 INFO L113 PluginConnector]: ------------------------TraceAbstraction---------------------------- [2018-11-23 10:58:37,576 INFO L271 PluginConnector]: Initializing TraceAbstraction... [2018-11-23 10:58:37,580 INFO L276 PluginConnector]: TraceAbstraction initialized [2018-11-23 10:58:37,580 INFO L185 PluginConnector]: Executing the observer TraceAbstractionObserver from plugin TraceAbstraction for "CDTParser AST 23.11 10:58:30" (1/3) ... [2018-11-23 10:58:37,581 INFO L205 PluginConnector]: Invalid model from TraceAbstraction for observer de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction.TraceAbstractionObserver@19776763 and model type de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction AST 23.11 10:58:37, skipping insertion in model container [2018-11-23 10:58:37,581 INFO L185 PluginConnector]: Executing the observer TraceAbstractionObserver from plugin TraceAbstraction for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 23.11 10:58:31" (2/3) ... [2018-11-23 10:58:37,582 INFO L205 PluginConnector]: Invalid model from TraceAbstraction for observer de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction.TraceAbstractionObserver@19776763 and model type de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction AST 23.11 10:58:37, skipping insertion in model container [2018-11-23 10:58:37,582 INFO L185 PluginConnector]: Executing the observer TraceAbstractionObserver from plugin TraceAbstraction for "de.uni_freiburg.informatik.ultimate.plugins.generator.rcfgbuilder CFG 23.11 10:58:37" (3/3) ... [2018-11-23 10:58:37,584 INFO L112 eAbstractionObserver]: Analyzing ICFG s3_srvr.blast.08_false-unreach-call.i.cil.c [2018-11-23 10:58:37,593 INFO L156 ceAbstractionStarter]: Automizer settings: Hoare:true NWA Interpolation:FPandBP Determinization: PREDICATE_ABSTRACTION [2018-11-23 10:58:37,603 INFO L168 ceAbstractionStarter]: Appying trace abstraction to program that has 1 error locations. [2018-11-23 10:58:37,621 INFO L257 AbstractCegarLoop]: Starting to check reachability of 1 error locations. [2018-11-23 10:58:37,656 INFO L133 ementStrategyFactory]: Using default assertion order modulation [2018-11-23 10:58:37,657 INFO L382 AbstractCegarLoop]: Interprodecural is true [2018-11-23 10:58:37,657 INFO L383 AbstractCegarLoop]: Hoare is true [2018-11-23 10:58:37,657 INFO L384 AbstractCegarLoop]: Compute interpolants for FPandBP [2018-11-23 10:58:37,658 INFO L385 AbstractCegarLoop]: Backedges is STRAIGHT_LINE [2018-11-23 10:58:37,658 INFO L386 AbstractCegarLoop]: Determinization is PREDICATE_ABSTRACTION [2018-11-23 10:58:37,658 INFO L387 AbstractCegarLoop]: Difference is false [2018-11-23 10:58:37,658 INFO L388 AbstractCegarLoop]: Minimize is MINIMIZE_SEVPA [2018-11-23 10:58:37,658 INFO L393 AbstractCegarLoop]: ======== Iteration 0==of CEGAR loop == AllErrorsAtOnce======== [2018-11-23 10:58:37,683 INFO L276 IsEmpty]: Start isEmpty. Operand 157 states. [2018-11-23 10:58:37,696 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 49 [2018-11-23 10:58:37,696 INFO L394 BasicCegarLoop]: Found error trace [2018-11-23 10:58:37,697 INFO L402 BasicCegarLoop]: trace histogram [1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2018-11-23 10:58:37,703 INFO L423 AbstractCegarLoop]: === Iteration 1 === [ssl3_acceptErr0ASSERT_VIOLATIONERROR_FUNCTION]=== [2018-11-23 10:58:37,710 INFO L141 PredicateUnifier]: Initialized classic predicate unifier [2018-11-23 10:58:37,710 INFO L82 PathProgramCache]: Analyzing trace with hash 1113695275, now seen corresponding path program 1 times [2018-11-23 10:58:37,719 INFO L223 ckRefinementStrategy]: Switched to mode CVC4_FPBP [2018-11-23 10:58:37,720 INFO L69 tionRefinementEngine]: Using refinement strategy WolfRefinementStrategy No working directory specified, using /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/cvc4nyu Starting monitored process 2 with cvc4nyu --tear-down-incremental --print-success --lang smt --rewrite-divk (exit command is (exit), workingDir is null) Waiting until toolchain timeout for monitored process 2 with cvc4nyu --tear-down-incremental --print-success --lang smt --rewrite-divk [2018-11-23 10:58:37,750 INFO L103 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2018-11-23 10:58:38,019 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2018-11-23 10:58:38,103 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2018-11-23 10:58:38,109 INFO L273 TraceCheckSpWp]: Computing forward predicates... [2018-11-23 10:58:38,413 INFO L478 Elim1Store]: Elim1 did not use preprocessing eliminated variable of array dimension 2, 1 stores, 1 select indices, 1 select index equivalence classes, 0 disjoint index pairs (out of 0 index pairs), introduced 1 new quantified variables, introduced 0 case distinctions, treesize of input 23 treesize of output 20 [2018-11-23 10:58:38,456 INFO L478 Elim1Store]: Elim1 did not use preprocessing eliminated variable of array dimension 1, 1 stores, 0 select indices, 0 select index equivalence classes, 0 disjoint index pairs (out of 0 index pairs), introduced 1 new quantified variables, introduced 0 case distinctions, treesize of input 20 treesize of output 23 [2018-11-23 10:58:38,511 INFO L701 Elim1Store]: detected not equals via solver [2018-11-23 10:58:38,516 INFO L478 Elim1Store]: Elim1 did not use preprocessing eliminated variable of array dimension 1, 1 stores, 1 select indices, 1 select index equivalence classes, 1 disjoint index pairs (out of 0 index pairs), introduced 1 new quantified variables, introduced 0 case distinctions, treesize of input 23 treesize of output 33 [2018-11-23 10:58:38,579 INFO L701 Elim1Store]: detected not equals via solver [2018-11-23 10:58:38,593 INFO L478 Elim1Store]: Elim1 did not use preprocessing eliminated variable of array dimension 1, 1 stores, 2 select indices, 2 select index equivalence classes, 1 disjoint index pairs (out of 1 index pairs), introduced 0 new quantified variables, introduced 0 case distinctions, treesize of input 25 treesize of output 27 [2018-11-23 10:58:38,622 INFO L267 ElimStorePlain]: Start of recursive call 5: End of recursive call: and 1 xjuncts. [2018-11-23 10:58:38,644 INFO L267 ElimStorePlain]: Start of recursive call 4: 1 dim-1 vars, End of recursive call: and 1 xjuncts. [2018-11-23 10:58:38,654 INFO L267 ElimStorePlain]: Start of recursive call 3: 1 dim-1 vars, End of recursive call: and 1 xjuncts. [2018-11-23 10:58:38,735 INFO L267 ElimStorePlain]: Start of recursive call 2: 1 dim-1 vars, End of recursive call: and 1 xjuncts. [2018-11-23 10:58:38,764 INFO L267 ElimStorePlain]: Start of recursive call 1: 1 dim-0 vars, 1 dim-2 vars, End of recursive call: and 1 xjuncts. [2018-11-23 10:58:38,765 INFO L202 ElimStorePlain]: Needed 5 recursive calls to eliminate 2 variables, input treesize:27, output treesize:13 [2018-11-23 10:58:38,788 WARN L383 uantifierElimination]: Trying to double check SDD result, but SMT solver's response was UNKNOWN. [2018-11-23 10:58:38,789 WARN L384 uantifierElimination]: Input elimination task: ∃ [|v_#memory_int_181|, |v_ssl3_accept_#t~nondet17_3|]. (and (= (store |v_#memory_int_181| ssl3_accept_~s.base (let ((.cse0 (bvadd ssl3_accept_~s.offset (_ bv52 32)))) (store (store (store (select |v_#memory_int_181| ssl3_accept_~s.base) .cse0 (_ bv8464 32)) (bvadd ssl3_accept_~s.offset (_ bv92 32)) |v_ssl3_accept_#t~nondet17_3|) .cse0 (_ bv8464 32)))) |#memory_int|) (= ssl3_accept_~s.offset (_ bv0 32))) [2018-11-23 10:58:38,789 WARN L385 uantifierElimination]: ElimStorePlain result: ∃ []. (and (= ssl3_accept_~s.offset (_ bv0 32)) (= (_ bv8464 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32))))) [2018-11-23 10:58:38,951 INFO L701 Elim1Store]: detected not equals via solver [2018-11-23 10:58:38,953 INFO L478 Elim1Store]: Elim1 did not use preprocessing eliminated variable of array dimension 2, 1 stores, 1 select indices, 1 select index equivalence classes, 1 disjoint index pairs (out of 0 index pairs), introduced 1 new quantified variables, introduced 0 case distinctions, treesize of input 31 treesize of output 38 [2018-11-23 10:58:38,992 INFO L701 Elim1Store]: detected not equals via solver [2018-11-23 10:58:39,038 INFO L701 Elim1Store]: detected not equals via solver [2018-11-23 10:58:39,040 INFO L478 Elim1Store]: Elim1 did not use preprocessing eliminated variable of array dimension 1, 1 stores, 2 select indices, 2 select index equivalence classes, 2 disjoint index pairs (out of 1 index pairs), introduced 1 new quantified variables, introduced 0 case distinctions, treesize of input 38 treesize of output 35 [2018-11-23 10:58:39,073 INFO L267 ElimStorePlain]: Start of recursive call 3: End of recursive call: and 1 xjuncts. [2018-11-23 10:58:39,099 INFO L267 ElimStorePlain]: Start of recursive call 2: 1 dim-1 vars, End of recursive call: and 1 xjuncts. [2018-11-23 10:58:39,108 INFO L267 ElimStorePlain]: Start of recursive call 1: 1 dim-2 vars, End of recursive call: and 1 xjuncts. [2018-11-23 10:58:39,109 INFO L202 ElimStorePlain]: Needed 3 recursive calls to eliminate 1 variables, input treesize:34, output treesize:13 [2018-11-23 10:58:41,134 WARN L383 uantifierElimination]: Trying to double check SDD result, but SMT solver's response was UNKNOWN. [2018-11-23 10:58:41,134 WARN L384 uantifierElimination]: Input elimination task: ∃ [|v_#memory_int_182|]. (let ((.cse0 (select |v_#memory_int_182| ssl3_accept_~s.base))) (and (= (store |v_#memory_int_182| ssl3_accept_~s.base (let ((.cse1 (bvadd ssl3_accept_~s.offset (_ bv28 32)))) (store .cse0 .cse1 (bvadd (select .cse0 .cse1) (_ bv1 32))))) |#memory_int|) (= ssl3_accept_~s.offset (_ bv0 32)) (= (select .cse0 (bvadd ssl3_accept_~s.offset (_ bv52 32))) (_ bv8464 32)))) [2018-11-23 10:58:41,135 WARN L385 uantifierElimination]: ElimStorePlain result: ∃ []. (and (= ssl3_accept_~s.offset (_ bv0 32)) (= (_ bv8464 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32))))) [2018-11-23 10:58:41,277 INFO L478 Elim1Store]: Elim1 did not use preprocessing eliminated variable of array dimension 2, 0 stores, 1 select indices, 1 select index equivalence classes, 0 disjoint index pairs (out of 0 index pairs), introduced 1 new quantified variables, introduced 0 case distinctions, treesize of input 17 treesize of output 13 [2018-11-23 10:58:41,325 INFO L478 Elim1Store]: Elim1 did not use preprocessing eliminated variable of array dimension 1, 0 stores, 1 select indices, 1 select index equivalence classes, 0 disjoint index pairs (out of 0 index pairs), introduced 0 new quantified variables, introduced 0 case distinctions, treesize of input 13 treesize of output 5 [2018-11-23 10:58:41,326 INFO L267 ElimStorePlain]: Start of recursive call 3: End of recursive call: and 1 xjuncts. [2018-11-23 10:58:41,328 INFO L267 ElimStorePlain]: Start of recursive call 2: 1 dim-1 vars, End of recursive call: and 1 xjuncts. [2018-11-23 10:58:41,331 INFO L267 ElimStorePlain]: Start of recursive call 1: 1 dim-0 vars, 1 dim-2 vars, End of recursive call: and 1 xjuncts. [2018-11-23 10:58:41,331 INFO L202 ElimStorePlain]: Needed 3 recursive calls to eliminate 2 variables, input treesize:17, output treesize:5 [2018-11-23 10:58:41,336 WARN L383 uantifierElimination]: Trying to double check SDD result, but SMT solver's response was UNKNOWN. [2018-11-23 10:58:41,336 WARN L384 uantifierElimination]: Input elimination task: ∃ [|#memory_int|, ssl3_accept_~s.base]. (let ((.cse0 (select (select |#memory_int| ssl3_accept_~s.base) (_ bv52 32)))) (and (= (bvadd .cse0 (_ bv4294958832 32)) (_ bv0 32)) (= |ssl3_accept_#t~mem52| .cse0))) [2018-11-23 10:58:41,337 WARN L385 uantifierElimination]: ElimStorePlain result: ∃ []. (= (bvadd |ssl3_accept_#t~mem52| (_ bv4294958832 32)) (_ bv0 32)) [2018-11-23 10:58:41,394 INFO L256 TraceCheckUtils]: 0: Hoare triple {160#true} call ULTIMATE.init(); {160#true} is VALID [2018-11-23 10:58:41,398 INFO L273 TraceCheckUtils]: 1: Hoare triple {160#true} #NULL.base, #NULL.offset := 0bv32, 0bv32;#valid := #valid[0bv32 := 0bv1];~init~0 := 1bv32;call ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset := #Ultimate.alloc(100bv32);call write~init~intINTTYPE4(0bv32, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset, 4bv32);call write~init~$Pointer$(0bv32, 0bv32, ~#SSLv3_server_data~0.base, ~bvadd32(4bv32, ~#SSLv3_server_data~0.offset), 4bv32);call write~init~$Pointer$(0bv32, 0bv32, ~#SSLv3_server_data~0.base, ~bvadd32(8bv32, ~#SSLv3_server_data~0.offset), 4bv32);call write~init~$Pointer$(0bv32, 0bv32, ~#SSLv3_server_data~0.base, ~bvadd32(12bv32, ~#SSLv3_server_data~0.offset), 4bv32);call write~init~$Pointer$(0bv32, 0bv32, ~#SSLv3_server_data~0.base, ~bvadd32(16bv32, ~#SSLv3_server_data~0.offset), 4bv32);call write~init~$Pointer$(0bv32, 0bv32, ~#SSLv3_server_data~0.base, ~bvadd32(20bv32, ~#SSLv3_server_data~0.offset), 4bv32);call write~init~$Pointer$(0bv32, 0bv32, ~#SSLv3_server_data~0.base, ~bvadd32(24bv32, ~#SSLv3_server_data~0.offset), 4bv32);call write~init~$Pointer$(0bv32, 0bv32, ~#SSLv3_server_data~0.base, ~bvadd32(28bv32, ~#SSLv3_server_data~0.offset), 4bv32);call write~init~$Pointer$(0bv32, 0bv32, ~#SSLv3_server_data~0.base, ~bvadd32(32bv32, ~#SSLv3_server_data~0.offset), 4bv32);call write~init~$Pointer$(0bv32, 0bv32, ~#SSLv3_server_data~0.base, ~bvadd32(36bv32, ~#SSLv3_server_data~0.offset), 4bv32);call write~init~$Pointer$(0bv32, 0bv32, ~#SSLv3_server_data~0.base, ~bvadd32(40bv32, ~#SSLv3_server_data~0.offset), 4bv32);call write~init~$Pointer$(0bv32, 0bv32, ~#SSLv3_server_data~0.base, ~bvadd32(44bv32, ~#SSLv3_server_data~0.offset), 4bv32);call write~init~$Pointer$(0bv32, 0bv32, ~#SSLv3_server_data~0.base, ~bvadd32(48bv32, ~#SSLv3_server_data~0.offset), 4bv32);call write~init~$Pointer$(0bv32, 0bv32, ~#SSLv3_server_data~0.base, ~bvadd32(52bv32, ~#SSLv3_server_data~0.offset), 4bv32);call write~init~$Pointer$(0bv32, 0bv32, ~#SSLv3_server_data~0.base, ~bvadd32(56bv32, ~#SSLv3_server_data~0.offset), 4bv32);call write~init~$Pointer$(0bv32, 0bv32, ~#SSLv3_server_data~0.base, ~bvadd32(60bv32, ~#SSLv3_server_data~0.offset), 4bv32);call write~init~$Pointer$(0bv32, 0bv32, ~#SSLv3_server_data~0.base, ~bvadd32(64bv32, ~#SSLv3_server_data~0.offset), 4bv32);call write~init~$Pointer$(0bv32, 0bv32, ~#SSLv3_server_data~0.base, ~bvadd32(68bv32, ~#SSLv3_server_data~0.offset), 4bv32);call write~init~$Pointer$(0bv32, 0bv32, ~#SSLv3_server_data~0.base, ~bvadd32(72bv32, ~#SSLv3_server_data~0.offset), 4bv32);call write~init~$Pointer$(0bv32, 0bv32, ~#SSLv3_server_data~0.base, ~bvadd32(76bv32, ~#SSLv3_server_data~0.offset), 4bv32);call write~init~$Pointer$(0bv32, 0bv32, ~#SSLv3_server_data~0.base, ~bvadd32(80bv32, ~#SSLv3_server_data~0.offset), 4bv32);call write~init~$Pointer$(0bv32, 0bv32, ~#SSLv3_server_data~0.base, ~bvadd32(84bv32, ~#SSLv3_server_data~0.offset), 4bv32);call write~init~$Pointer$(0bv32, 0bv32, ~#SSLv3_server_data~0.base, ~bvadd32(88bv32, ~#SSLv3_server_data~0.offset), 4bv32);call write~init~$Pointer$(0bv32, 0bv32, ~#SSLv3_server_data~0.base, ~bvadd32(92bv32, ~#SSLv3_server_data~0.offset), 4bv32);call write~init~$Pointer$(0bv32, 0bv32, ~#SSLv3_server_data~0.base, ~bvadd32(96bv32, ~#SSLv3_server_data~0.offset), 4bv32); {160#true} is VALID [2018-11-23 10:58:41,399 INFO L273 TraceCheckUtils]: 2: Hoare triple {160#true} assume true; {160#true} is VALID [2018-11-23 10:58:41,400 INFO L268 TraceCheckUtils]: 3: Hoare quadruple {160#true} {160#true} #631#return; {160#true} is VALID [2018-11-23 10:58:41,400 INFO L256 TraceCheckUtils]: 4: Hoare triple {160#true} call #t~ret138 := main(); {160#true} is VALID [2018-11-23 10:58:41,402 INFO L273 TraceCheckUtils]: 5: Hoare triple {160#true} havoc ~s~0.base, ~s~0.offset;havoc ~tmp~2;call #t~malloc3.base, #t~malloc3.offset := #Ultimate.alloc(248bv32);~s~0.base, ~s~0.offset := #t~malloc3.base, #t~malloc3.offset;call #t~malloc4.base, #t~malloc4.offset := #Ultimate.alloc(899bv32);call write~$Pointer$(#t~malloc4.base, #t~malloc4.offset, ~s~0.base, ~bvadd32(84bv32, ~s~0.offset), 4bv32);call #t~malloc5.base, #t~malloc5.offset := #Ultimate.alloc(232bv32);call write~$Pointer$(#t~malloc5.base, #t~malloc5.offset, ~s~0.base, ~bvadd32(204bv32, ~s~0.offset), 4bv32);call #t~malloc6.base, #t~malloc6.offset := #Ultimate.alloc(200bv32);call write~$Pointer$(#t~malloc6.base, #t~malloc6.offset, ~s~0.base, ~bvadd32(176bv32, ~s~0.offset), 4bv32); {180#(= main_~s~0.offset (_ bv0 32))} is VALID [2018-11-23 10:58:41,403 INFO L256 TraceCheckUtils]: 6: Hoare triple {180#(= main_~s~0.offset (_ bv0 32))} call #t~ret7 := ssl3_accept(~s~0.base, ~s~0.offset); {184#(= (_ bv0 32) |ssl3_accept_#in~s.offset|)} is VALID [2018-11-23 10:58:41,408 INFO L273 TraceCheckUtils]: 7: Hoare triple {184#(= (_ bv0 32) |ssl3_accept_#in~s.offset|)} ~s.base, ~s.offset := #in~s.base, #in~s.offset;havoc ~buf~0.base, ~buf~0.offset;havoc ~l~0;havoc ~Time~0;havoc ~tmp~3;havoc ~cb~0.base, ~cb~0.offset;havoc ~num1~0;havoc ~ret~0;havoc ~new_state~0;havoc ~state~0;havoc ~skip~0;havoc ~got_new_session~0;~tmp___1~0 := #t~nondet8;havoc #t~nondet8;~tmp___2~0 := #t~nondet9;havoc #t~nondet9;~tmp___3~0 := #t~nondet10;havoc #t~nondet10;~tmp___4~0 := #t~nondet11;havoc #t~nondet11;~tmp___5~0 := #t~nondet12;havoc #t~nondet12;~tmp___6~0 := #t~nondet13;havoc #t~nondet13;havoc ~tmp___7~0;~tmp___8~0 := #t~nondet14;havoc #t~nondet14;~tmp___9~0 := #t~nondet15;havoc #t~nondet15;~tmp___10~0 := #t~nondet16;havoc #t~nondet16;havoc ~blastFlag~0;call write~intINTTYPE4(8464bv32, ~s.base, ~bvadd32(52bv32, ~s.offset), 4bv32);~blastFlag~0 := 0bv32;call write~intINTTYPE4(#t~nondet17, ~s.base, ~bvadd32(92bv32, ~s.offset), 4bv32);havoc #t~nondet17;call write~intINTTYPE4(8464bv32, ~s.base, ~bvadd32(52bv32, ~s.offset), 4bv32);~tmp~3 := #t~nondet18;havoc #t~nondet18;~Time~0 := ~tmp~3;~cb~0.base, ~cb~0.offset := 0bv32, 0bv32;~ret~0 := 4294967295bv32;~skip~0 := 0bv32;~got_new_session~0 := 0bv32;call #t~mem19.base, #t~mem19.offset := read~$Pointer$(~s.base, ~bvadd32(192bv32, ~s.offset), 4bv32); {188#(and (= ssl3_accept_~s.offset (_ bv0 32)) (= (_ bv8464 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32)))))} is VALID [2018-11-23 10:58:41,409 INFO L273 TraceCheckUtils]: 8: Hoare triple {188#(and (= ssl3_accept_~s.offset (_ bv0 32)) (= (_ bv8464 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32)))))} assume 0bv32 != ~bvadd32(#t~mem19.base, #t~mem19.offset);havoc #t~mem19.base, #t~mem19.offset;call #t~mem20.base, #t~mem20.offset := read~$Pointer$(~s.base, ~bvadd32(192bv32, ~s.offset), 4bv32);~cb~0.base, ~cb~0.offset := #t~mem20.base, #t~mem20.offset;havoc #t~mem20.base, #t~mem20.offset; {188#(and (= ssl3_accept_~s.offset (_ bv0 32)) (= (_ bv8464 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32)))))} is VALID [2018-11-23 10:58:41,418 INFO L273 TraceCheckUtils]: 9: Hoare triple {188#(and (= ssl3_accept_~s.offset (_ bv0 32)) (= (_ bv8464 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32)))))} call #t~mem21 := read~intINTTYPE4(~s.base, ~bvadd32(28bv32, ~s.offset), 4bv32);call write~intINTTYPE4(~bvadd32(1bv32, #t~mem21), ~s.base, ~bvadd32(28bv32, ~s.offset), 4bv32);havoc #t~mem21; {188#(and (= ssl3_accept_~s.offset (_ bv0 32)) (= (_ bv8464 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32)))))} is VALID [2018-11-23 10:58:41,420 INFO L273 TraceCheckUtils]: 10: Hoare triple {188#(and (= ssl3_accept_~s.offset (_ bv0 32)) (= (_ bv8464 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32)))))} assume !(0bv32 != ~bvand32(12288bv32, ~tmp___1~0)); {188#(and (= ssl3_accept_~s.offset (_ bv0 32)) (= (_ bv8464 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32)))))} is VALID [2018-11-23 10:58:41,421 INFO L273 TraceCheckUtils]: 11: Hoare triple {188#(and (= ssl3_accept_~s.offset (_ bv0 32)) (= (_ bv8464 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32)))))} call #t~mem22.base, #t~mem22.offset := read~$Pointer$(~s.base, ~bvadd32(136bv32, ~s.offset), 4bv32); {188#(and (= ssl3_accept_~s.offset (_ bv0 32)) (= (_ bv8464 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32)))))} is VALID [2018-11-23 10:58:41,421 INFO L273 TraceCheckUtils]: 12: Hoare triple {188#(and (= ssl3_accept_~s.offset (_ bv0 32)) (= (_ bv8464 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32)))))} assume !(0bv32 == ~bvadd32(#t~mem22.base, #t~mem22.offset));havoc #t~mem22.base, #t~mem22.offset; {188#(and (= ssl3_accept_~s.offset (_ bv0 32)) (= (_ bv8464 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32)))))} is VALID [2018-11-23 10:58:41,422 INFO L273 TraceCheckUtils]: 13: Hoare triple {188#(and (= ssl3_accept_~s.offset (_ bv0 32)) (= (_ bv8464 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32)))))} assume !false; {188#(and (= ssl3_accept_~s.offset (_ bv0 32)) (= (_ bv8464 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32)))))} is VALID [2018-11-23 10:58:41,423 INFO L273 TraceCheckUtils]: 14: Hoare triple {188#(and (= ssl3_accept_~s.offset (_ bv0 32)) (= (_ bv8464 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32)))))} call #t~mem23 := read~intINTTYPE4(~s.base, ~bvadd32(52bv32, ~s.offset), 4bv32);~state~0 := #t~mem23;havoc #t~mem23;call #t~mem24 := read~intINTTYPE4(~s.base, ~bvadd32(52bv32, ~s.offset), 4bv32); {188#(and (= ssl3_accept_~s.offset (_ bv0 32)) (= (_ bv8464 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32)))))} is VALID [2018-11-23 10:58:41,424 INFO L273 TraceCheckUtils]: 15: Hoare triple {188#(and (= ssl3_accept_~s.offset (_ bv0 32)) (= (_ bv8464 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32)))))} assume !(12292bv32 == #t~mem24);havoc #t~mem24;call #t~mem25 := read~intINTTYPE4(~s.base, ~bvadd32(52bv32, ~s.offset), 4bv32); {188#(and (= ssl3_accept_~s.offset (_ bv0 32)) (= (_ bv8464 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32)))))} is VALID [2018-11-23 10:58:41,425 INFO L273 TraceCheckUtils]: 16: Hoare triple {188#(and (= ssl3_accept_~s.offset (_ bv0 32)) (= (_ bv8464 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32)))))} assume !(16384bv32 == #t~mem25);havoc #t~mem25;call #t~mem26 := read~intINTTYPE4(~s.base, ~bvadd32(52bv32, ~s.offset), 4bv32); {188#(and (= ssl3_accept_~s.offset (_ bv0 32)) (= (_ bv8464 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32)))))} is VALID [2018-11-23 10:58:41,446 INFO L273 TraceCheckUtils]: 17: Hoare triple {188#(and (= ssl3_accept_~s.offset (_ bv0 32)) (= (_ bv8464 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32)))))} assume !(8192bv32 == #t~mem26);havoc #t~mem26;call #t~mem27 := read~intINTTYPE4(~s.base, ~bvadd32(52bv32, ~s.offset), 4bv32); {188#(and (= ssl3_accept_~s.offset (_ bv0 32)) (= (_ bv8464 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32)))))} is VALID [2018-11-23 10:58:41,448 INFO L273 TraceCheckUtils]: 18: Hoare triple {188#(and (= ssl3_accept_~s.offset (_ bv0 32)) (= (_ bv8464 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32)))))} assume !(24576bv32 == #t~mem27);havoc #t~mem27;call #t~mem28 := read~intINTTYPE4(~s.base, ~bvadd32(52bv32, ~s.offset), 4bv32); {188#(and (= ssl3_accept_~s.offset (_ bv0 32)) (= (_ bv8464 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32)))))} is VALID [2018-11-23 10:58:41,449 INFO L273 TraceCheckUtils]: 19: Hoare triple {188#(and (= ssl3_accept_~s.offset (_ bv0 32)) (= (_ bv8464 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32)))))} assume !(8195bv32 == #t~mem28);havoc #t~mem28;call #t~mem29 := read~intINTTYPE4(~s.base, ~bvadd32(52bv32, ~s.offset), 4bv32); {188#(and (= ssl3_accept_~s.offset (_ bv0 32)) (= (_ bv8464 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32)))))} is VALID [2018-11-23 10:58:41,450 INFO L273 TraceCheckUtils]: 20: Hoare triple {188#(and (= ssl3_accept_~s.offset (_ bv0 32)) (= (_ bv8464 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32)))))} assume !(8480bv32 == #t~mem29);havoc #t~mem29;call #t~mem30 := read~intINTTYPE4(~s.base, ~bvadd32(52bv32, ~s.offset), 4bv32); {188#(and (= ssl3_accept_~s.offset (_ bv0 32)) (= (_ bv8464 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32)))))} is VALID [2018-11-23 10:58:41,451 INFO L273 TraceCheckUtils]: 21: Hoare triple {188#(and (= ssl3_accept_~s.offset (_ bv0 32)) (= (_ bv8464 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32)))))} assume !(8481bv32 == #t~mem30);havoc #t~mem30;call #t~mem31 := read~intINTTYPE4(~s.base, ~bvadd32(52bv32, ~s.offset), 4bv32); {188#(and (= ssl3_accept_~s.offset (_ bv0 32)) (= (_ bv8464 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32)))))} is VALID [2018-11-23 10:58:41,454 INFO L273 TraceCheckUtils]: 22: Hoare triple {188#(and (= ssl3_accept_~s.offset (_ bv0 32)) (= (_ bv8464 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32)))))} assume !(8482bv32 == #t~mem31);havoc #t~mem31;call #t~mem32 := read~intINTTYPE4(~s.base, ~bvadd32(52bv32, ~s.offset), 4bv32); {188#(and (= ssl3_accept_~s.offset (_ bv0 32)) (= (_ bv8464 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32)))))} is VALID [2018-11-23 10:58:41,455 INFO L273 TraceCheckUtils]: 23: Hoare triple {188#(and (= ssl3_accept_~s.offset (_ bv0 32)) (= (_ bv8464 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32)))))} assume !(8464bv32 == #t~mem32);havoc #t~mem32;call #t~mem33 := read~intINTTYPE4(~s.base, ~bvadd32(52bv32, ~s.offset), 4bv32); {188#(and (= ssl3_accept_~s.offset (_ bv0 32)) (= (_ bv8464 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32)))))} is VALID [2018-11-23 10:58:41,456 INFO L273 TraceCheckUtils]: 24: Hoare triple {188#(and (= ssl3_accept_~s.offset (_ bv0 32)) (= (_ bv8464 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32)))))} assume !(8465bv32 == #t~mem33);havoc #t~mem33;call #t~mem34 := read~intINTTYPE4(~s.base, ~bvadd32(52bv32, ~s.offset), 4bv32); {188#(and (= ssl3_accept_~s.offset (_ bv0 32)) (= (_ bv8464 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32)))))} is VALID [2018-11-23 10:58:41,460 INFO L273 TraceCheckUtils]: 25: Hoare triple {188#(and (= ssl3_accept_~s.offset (_ bv0 32)) (= (_ bv8464 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32)))))} assume !(8466bv32 == #t~mem34);havoc #t~mem34;call #t~mem35 := read~intINTTYPE4(~s.base, ~bvadd32(52bv32, ~s.offset), 4bv32); {188#(and (= ssl3_accept_~s.offset (_ bv0 32)) (= (_ bv8464 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32)))))} is VALID [2018-11-23 10:58:41,462 INFO L273 TraceCheckUtils]: 26: Hoare triple {188#(and (= ssl3_accept_~s.offset (_ bv0 32)) (= (_ bv8464 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32)))))} assume !(8496bv32 == #t~mem35);havoc #t~mem35;call #t~mem36 := read~intINTTYPE4(~s.base, ~bvadd32(52bv32, ~s.offset), 4bv32); {188#(and (= ssl3_accept_~s.offset (_ bv0 32)) (= (_ bv8464 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32)))))} is VALID [2018-11-23 10:58:41,463 INFO L273 TraceCheckUtils]: 27: Hoare triple {188#(and (= ssl3_accept_~s.offset (_ bv0 32)) (= (_ bv8464 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32)))))} assume !(8497bv32 == #t~mem36);havoc #t~mem36;call #t~mem37 := read~intINTTYPE4(~s.base, ~bvadd32(52bv32, ~s.offset), 4bv32); {188#(and (= ssl3_accept_~s.offset (_ bv0 32)) (= (_ bv8464 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32)))))} is VALID [2018-11-23 10:58:41,464 INFO L273 TraceCheckUtils]: 28: Hoare triple {188#(and (= ssl3_accept_~s.offset (_ bv0 32)) (= (_ bv8464 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32)))))} assume !(8512bv32 == #t~mem37);havoc #t~mem37;call #t~mem38 := read~intINTTYPE4(~s.base, ~bvadd32(52bv32, ~s.offset), 4bv32); {188#(and (= ssl3_accept_~s.offset (_ bv0 32)) (= (_ bv8464 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32)))))} is VALID [2018-11-23 10:58:41,466 INFO L273 TraceCheckUtils]: 29: Hoare triple {188#(and (= ssl3_accept_~s.offset (_ bv0 32)) (= (_ bv8464 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32)))))} assume !(8513bv32 == #t~mem38);havoc #t~mem38;call #t~mem39 := read~intINTTYPE4(~s.base, ~bvadd32(52bv32, ~s.offset), 4bv32); {188#(and (= ssl3_accept_~s.offset (_ bv0 32)) (= (_ bv8464 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32)))))} is VALID [2018-11-23 10:58:41,468 INFO L273 TraceCheckUtils]: 30: Hoare triple {188#(and (= ssl3_accept_~s.offset (_ bv0 32)) (= (_ bv8464 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32)))))} assume !(8528bv32 == #t~mem39);havoc #t~mem39;call #t~mem40 := read~intINTTYPE4(~s.base, ~bvadd32(52bv32, ~s.offset), 4bv32); {188#(and (= ssl3_accept_~s.offset (_ bv0 32)) (= (_ bv8464 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32)))))} is VALID [2018-11-23 10:58:41,469 INFO L273 TraceCheckUtils]: 31: Hoare triple {188#(and (= ssl3_accept_~s.offset (_ bv0 32)) (= (_ bv8464 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32)))))} assume !(8529bv32 == #t~mem40);havoc #t~mem40;call #t~mem41 := read~intINTTYPE4(~s.base, ~bvadd32(52bv32, ~s.offset), 4bv32); {188#(and (= ssl3_accept_~s.offset (_ bv0 32)) (= (_ bv8464 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32)))))} is VALID [2018-11-23 10:58:41,470 INFO L273 TraceCheckUtils]: 32: Hoare triple {188#(and (= ssl3_accept_~s.offset (_ bv0 32)) (= (_ bv8464 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32)))))} assume !(8544bv32 == #t~mem41);havoc #t~mem41;call #t~mem42 := read~intINTTYPE4(~s.base, ~bvadd32(52bv32, ~s.offset), 4bv32); {188#(and (= ssl3_accept_~s.offset (_ bv0 32)) (= (_ bv8464 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32)))))} is VALID [2018-11-23 10:58:41,471 INFO L273 TraceCheckUtils]: 33: Hoare triple {188#(and (= ssl3_accept_~s.offset (_ bv0 32)) (= (_ bv8464 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32)))))} assume !(8545bv32 == #t~mem42);havoc #t~mem42;call #t~mem43 := read~intINTTYPE4(~s.base, ~bvadd32(52bv32, ~s.offset), 4bv32); {188#(and (= ssl3_accept_~s.offset (_ bv0 32)) (= (_ bv8464 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32)))))} is VALID [2018-11-23 10:58:41,473 INFO L273 TraceCheckUtils]: 34: Hoare triple {188#(and (= ssl3_accept_~s.offset (_ bv0 32)) (= (_ bv8464 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32)))))} assume !(8560bv32 == #t~mem43);havoc #t~mem43;call #t~mem44 := read~intINTTYPE4(~s.base, ~bvadd32(52bv32, ~s.offset), 4bv32); {188#(and (= ssl3_accept_~s.offset (_ bv0 32)) (= (_ bv8464 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32)))))} is VALID [2018-11-23 10:58:41,474 INFO L273 TraceCheckUtils]: 35: Hoare triple {188#(and (= ssl3_accept_~s.offset (_ bv0 32)) (= (_ bv8464 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32)))))} assume !(8561bv32 == #t~mem44);havoc #t~mem44;call #t~mem45 := read~intINTTYPE4(~s.base, ~bvadd32(52bv32, ~s.offset), 4bv32); {188#(and (= ssl3_accept_~s.offset (_ bv0 32)) (= (_ bv8464 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32)))))} is VALID [2018-11-23 10:58:41,476 INFO L273 TraceCheckUtils]: 36: Hoare triple {188#(and (= ssl3_accept_~s.offset (_ bv0 32)) (= (_ bv8464 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32)))))} assume !(8448bv32 == #t~mem45);havoc #t~mem45;call #t~mem46 := read~intINTTYPE4(~s.base, ~bvadd32(52bv32, ~s.offset), 4bv32); {188#(and (= ssl3_accept_~s.offset (_ bv0 32)) (= (_ bv8464 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32)))))} is VALID [2018-11-23 10:58:41,477 INFO L273 TraceCheckUtils]: 37: Hoare triple {188#(and (= ssl3_accept_~s.offset (_ bv0 32)) (= (_ bv8464 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32)))))} assume !(8576bv32 == #t~mem46);havoc #t~mem46;call #t~mem47 := read~intINTTYPE4(~s.base, ~bvadd32(52bv32, ~s.offset), 4bv32); {188#(and (= ssl3_accept_~s.offset (_ bv0 32)) (= (_ bv8464 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32)))))} is VALID [2018-11-23 10:58:41,479 INFO L273 TraceCheckUtils]: 38: Hoare triple {188#(and (= ssl3_accept_~s.offset (_ bv0 32)) (= (_ bv8464 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32)))))} assume !(8577bv32 == #t~mem47);havoc #t~mem47;call #t~mem48 := read~intINTTYPE4(~s.base, ~bvadd32(52bv32, ~s.offset), 4bv32); {188#(and (= ssl3_accept_~s.offset (_ bv0 32)) (= (_ bv8464 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32)))))} is VALID [2018-11-23 10:58:41,483 INFO L273 TraceCheckUtils]: 39: Hoare triple {188#(and (= ssl3_accept_~s.offset (_ bv0 32)) (= (_ bv8464 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32)))))} assume !(8592bv32 == #t~mem48);havoc #t~mem48;call #t~mem49 := read~intINTTYPE4(~s.base, ~bvadd32(52bv32, ~s.offset), 4bv32); {188#(and (= ssl3_accept_~s.offset (_ bv0 32)) (= (_ bv8464 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32)))))} is VALID [2018-11-23 10:58:41,484 INFO L273 TraceCheckUtils]: 40: Hoare triple {188#(and (= ssl3_accept_~s.offset (_ bv0 32)) (= (_ bv8464 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32)))))} assume !(8593bv32 == #t~mem49);havoc #t~mem49;call #t~mem50 := read~intINTTYPE4(~s.base, ~bvadd32(52bv32, ~s.offset), 4bv32); {188#(and (= ssl3_accept_~s.offset (_ bv0 32)) (= (_ bv8464 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32)))))} is VALID [2018-11-23 10:58:41,487 INFO L273 TraceCheckUtils]: 41: Hoare triple {188#(and (= ssl3_accept_~s.offset (_ bv0 32)) (= (_ bv8464 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32)))))} assume !(8608bv32 == #t~mem50);havoc #t~mem50;call #t~mem51 := read~intINTTYPE4(~s.base, ~bvadd32(52bv32, ~s.offset), 4bv32); {188#(and (= ssl3_accept_~s.offset (_ bv0 32)) (= (_ bv8464 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32)))))} is VALID [2018-11-23 10:58:41,489 INFO L273 TraceCheckUtils]: 42: Hoare triple {188#(and (= ssl3_accept_~s.offset (_ bv0 32)) (= (_ bv8464 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32)))))} assume !(8609bv32 == #t~mem51);havoc #t~mem51;call #t~mem52 := read~intINTTYPE4(~s.base, ~bvadd32(52bv32, ~s.offset), 4bv32); {294#(= (bvadd |ssl3_accept_#t~mem52| (_ bv4294958832 32)) (_ bv0 32))} is VALID [2018-11-23 10:58:41,489 INFO L273 TraceCheckUtils]: 43: Hoare triple {294#(= (bvadd |ssl3_accept_#t~mem52| (_ bv4294958832 32)) (_ bv0 32))} assume 8640bv32 == #t~mem52;havoc #t~mem52; {161#false} is VALID [2018-11-23 10:58:41,490 INFO L273 TraceCheckUtils]: 44: Hoare triple {161#false} ~ret~0 := #t~nondet115;havoc #t~nondet115; {161#false} is VALID [2018-11-23 10:58:41,490 INFO L273 TraceCheckUtils]: 45: Hoare triple {161#false} assume !(4bv32 == ~blastFlag~0); {161#false} is VALID [2018-11-23 10:58:41,490 INFO L273 TraceCheckUtils]: 46: Hoare triple {161#false} assume !(7bv32 == ~blastFlag~0); {161#false} is VALID [2018-11-23 10:58:41,491 INFO L273 TraceCheckUtils]: 47: Hoare triple {161#false} assume !false; {161#false} is VALID [2018-11-23 10:58:41,508 INFO L134 CoverageAnalysis]: Checked inductivity of 0 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2018-11-23 10:58:41,509 INFO L312 TraceCheckSpWp]: Omiting computation of backward sequence because forward sequence was already perfect [2018-11-23 10:58:41,517 INFO L312 seRefinementStrategy]: Constructing automaton from 1 perfect and 0 imperfect interpolant sequences. [2018-11-23 10:58:41,518 INFO L327 seRefinementStrategy]: Number of different interpolants: perfect sequences [6] imperfect sequences [] total 6 [2018-11-23 10:58:41,523 INFO L78 Accepts]: Start accepts. Automaton has 6 states. Word has length 48 [2018-11-23 10:58:41,527 INFO L84 Accepts]: Finished accepts. word is accepted. [2018-11-23 10:58:41,531 INFO L86 InductivityCheck]: Starting indutivity check of a Floyd-Hoare automaton with 6 states. [2018-11-23 10:58:41,695 INFO L119 InductivityCheck]: Floyd-Hoare automaton has 48 edges. 48 inductive. 0 not inductive. 0 times theorem prover too weak to decide inductivity. [2018-11-23 10:58:41,696 INFO L459 AbstractCegarLoop]: Interpolant automaton has 6 states [2018-11-23 10:58:41,705 INFO L142 InterpolantAutomaton]: Constructing interpolant automaton starting with 6 interpolants. [2018-11-23 10:58:41,705 INFO L144 InterpolantAutomaton]: CoverageRelationStatistics Valid=9, Invalid=21, Unknown=0, NotChecked=0, Total=30 [2018-11-23 10:58:41,707 INFO L87 Difference]: Start difference. First operand 157 states. Second operand 6 states. [2018-11-23 10:59:04,521 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2018-11-23 10:59:04,522 INFO L93 Difference]: Finished difference Result 407 states and 686 transitions. [2018-11-23 10:59:04,522 INFO L142 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 6 states. [2018-11-23 10:59:04,522 INFO L78 Accepts]: Start accepts. Automaton has 6 states. Word has length 48 [2018-11-23 10:59:04,523 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2018-11-23 10:59:04,526 INFO L82 GeneralOperation]: Start removeUnreachable. Operand 6 states. [2018-11-23 10:59:04,561 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 6 states to 6 states and 686 transitions. [2018-11-23 10:59:04,561 INFO L82 GeneralOperation]: Start removeUnreachable. Operand 6 states. [2018-11-23 10:59:04,576 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 6 states to 6 states and 686 transitions. [2018-11-23 10:59:04,577 INFO L86 InductivityCheck]: Starting indutivity check of a Floyd-Hoare automaton with 6 states and 686 transitions. [2018-11-23 10:59:06,213 INFO L119 InductivityCheck]: Floyd-Hoare automaton has 686 edges. 686 inductive. 0 not inductive. 0 times theorem prover too weak to decide inductivity. [2018-11-23 10:59:06,242 INFO L225 Difference]: With dead ends: 407 [2018-11-23 10:59:06,242 INFO L226 Difference]: Without dead ends: 238 [2018-11-23 10:59:06,247 INFO L631 BasicCegarLoop]: 0 DeclaredPredicates, 49 GetRequests, 43 SyntacticMatches, 0 SemanticMatches, 6 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 0 ImplicationChecksByTransitivity, 0.1s TimeCoverageRelationStatistics Valid=19, Invalid=37, Unknown=0, NotChecked=0, Total=56 [2018-11-23 10:59:06,268 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 238 states. [2018-11-23 10:59:06,495 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 238 to 172. [2018-11-23 10:59:06,496 INFO L214 AbstractMinimizeNwa]: Start testing correctness of minimizeSevpa [2018-11-23 10:59:06,496 INFO L82 GeneralOperation]: Start isEquivalent. First operand 238 states. Second operand 172 states. [2018-11-23 10:59:06,497 INFO L74 IsIncluded]: Start isIncluded. First operand 238 states. Second operand 172 states. [2018-11-23 10:59:06,497 INFO L87 Difference]: Start difference. First operand 238 states. Second operand 172 states. [2018-11-23 10:59:06,510 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2018-11-23 10:59:06,511 INFO L93 Difference]: Finished difference Result 238 states and 362 transitions. [2018-11-23 10:59:06,511 INFO L276 IsEmpty]: Start isEmpty. Operand 238 states and 362 transitions. [2018-11-23 10:59:06,514 INFO L282 IsEmpty]: Finished isEmpty. No accepting run. [2018-11-23 10:59:06,514 INFO L83 IsIncluded]: Finished isIncluded. Language is included [2018-11-23 10:59:06,514 INFO L74 IsIncluded]: Start isIncluded. First operand 172 states. Second operand 238 states. [2018-11-23 10:59:06,514 INFO L87 Difference]: Start difference. First operand 172 states. Second operand 238 states. [2018-11-23 10:59:06,526 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2018-11-23 10:59:06,527 INFO L93 Difference]: Finished difference Result 238 states and 362 transitions. [2018-11-23 10:59:06,527 INFO L276 IsEmpty]: Start isEmpty. Operand 238 states and 362 transitions. [2018-11-23 10:59:06,529 INFO L282 IsEmpty]: Finished isEmpty. No accepting run. [2018-11-23 10:59:06,529 INFO L83 IsIncluded]: Finished isIncluded. Language is included [2018-11-23 10:59:06,530 INFO L88 GeneralOperation]: Finished isEquivalent. [2018-11-23 10:59:06,530 INFO L221 AbstractMinimizeNwa]: Finished testing correctness of minimizeSevpa [2018-11-23 10:59:06,530 INFO L82 GeneralOperation]: Start removeUnreachable. Operand 172 states. [2018-11-23 10:59:06,540 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 172 states to 172 states and 272 transitions. [2018-11-23 10:59:06,542 INFO L78 Accepts]: Start accepts. Automaton has 172 states and 272 transitions. Word has length 48 [2018-11-23 10:59:06,542 INFO L84 Accepts]: Finished accepts. word is rejected. [2018-11-23 10:59:06,542 INFO L480 AbstractCegarLoop]: Abstraction has 172 states and 272 transitions. [2018-11-23 10:59:06,542 INFO L481 AbstractCegarLoop]: Interpolant automaton has 6 states. [2018-11-23 10:59:06,542 INFO L276 IsEmpty]: Start isEmpty. Operand 172 states and 272 transitions. [2018-11-23 10:59:06,545 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 50 [2018-11-23 10:59:06,546 INFO L394 BasicCegarLoop]: Found error trace [2018-11-23 10:59:06,546 INFO L402 BasicCegarLoop]: trace histogram [1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2018-11-23 10:59:06,546 INFO L423 AbstractCegarLoop]: === Iteration 2 === [ssl3_acceptErr0ASSERT_VIOLATIONERROR_FUNCTION]=== [2018-11-23 10:59:06,546 INFO L141 PredicateUnifier]: Initialized classic predicate unifier [2018-11-23 10:59:06,547 INFO L82 PathProgramCache]: Analyzing trace with hash -36670049, now seen corresponding path program 1 times [2018-11-23 10:59:06,551 INFO L223 ckRefinementStrategy]: Switched to mode CVC4_FPBP [2018-11-23 10:59:06,551 INFO L69 tionRefinementEngine]: Using refinement strategy WolfRefinementStrategy No working directory specified, using /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/cvc4nyu Starting monitored process 3 with cvc4nyu --tear-down-incremental --print-success --lang smt --rewrite-divk (exit command is (exit), workingDir is null) Waiting until toolchain timeout for monitored process 3 with cvc4nyu --tear-down-incremental --print-success --lang smt --rewrite-divk [2018-11-23 10:59:06,568 INFO L103 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2018-11-23 10:59:06,774 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2018-11-23 10:59:06,832 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2018-11-23 10:59:06,835 INFO L273 TraceCheckSpWp]: Computing forward predicates... [2018-11-23 10:59:06,884 INFO L478 Elim1Store]: Elim1 did not use preprocessing eliminated variable of array dimension 2, 1 stores, 1 select indices, 1 select index equivalence classes, 0 disjoint index pairs (out of 0 index pairs), introduced 1 new quantified variables, introduced 0 case distinctions, treesize of input 23 treesize of output 20 [2018-11-23 10:59:06,889 INFO L478 Elim1Store]: Elim1 did not use preprocessing eliminated variable of array dimension 1, 1 stores, 0 select indices, 0 select index equivalence classes, 0 disjoint index pairs (out of 0 index pairs), introduced 1 new quantified variables, introduced 0 case distinctions, treesize of input 20 treesize of output 23 [2018-11-23 10:59:06,900 INFO L701 Elim1Store]: detected not equals via solver [2018-11-23 10:59:06,904 INFO L478 Elim1Store]: Elim1 did not use preprocessing eliminated variable of array dimension 1, 1 stores, 1 select indices, 1 select index equivalence classes, 1 disjoint index pairs (out of 0 index pairs), introduced 1 new quantified variables, introduced 0 case distinctions, treesize of input 23 treesize of output 33 [2018-11-23 10:59:06,914 INFO L701 Elim1Store]: detected not equals via solver [2018-11-23 10:59:06,921 INFO L478 Elim1Store]: Elim1 did not use preprocessing eliminated variable of array dimension 1, 1 stores, 2 select indices, 2 select index equivalence classes, 1 disjoint index pairs (out of 1 index pairs), introduced 0 new quantified variables, introduced 0 case distinctions, treesize of input 25 treesize of output 27 [2018-11-23 10:59:06,923 INFO L267 ElimStorePlain]: Start of recursive call 5: End of recursive call: and 1 xjuncts. [2018-11-23 10:59:06,934 INFO L267 ElimStorePlain]: Start of recursive call 4: 1 dim-1 vars, End of recursive call: and 1 xjuncts. [2018-11-23 10:59:06,944 INFO L267 ElimStorePlain]: Start of recursive call 3: 1 dim-1 vars, End of recursive call: and 1 xjuncts. [2018-11-23 10:59:06,955 INFO L267 ElimStorePlain]: Start of recursive call 2: 1 dim-1 vars, End of recursive call: and 1 xjuncts. [2018-11-23 10:59:06,970 INFO L267 ElimStorePlain]: Start of recursive call 1: 1 dim-0 vars, 1 dim-2 vars, End of recursive call: and 1 xjuncts. [2018-11-23 10:59:06,971 INFO L202 ElimStorePlain]: Needed 5 recursive calls to eliminate 2 variables, input treesize:27, output treesize:13 [2018-11-23 10:59:06,987 WARN L383 uantifierElimination]: Trying to double check SDD result, but SMT solver's response was UNKNOWN. [2018-11-23 10:59:06,987 WARN L384 uantifierElimination]: Input elimination task: ∃ [|v_#memory_int_183|, |v_ssl3_accept_#t~nondet17_4|]. (and (= (store |v_#memory_int_183| ssl3_accept_~s.base (let ((.cse0 (bvadd ssl3_accept_~s.offset (_ bv52 32)))) (store (store (store (select |v_#memory_int_183| ssl3_accept_~s.base) .cse0 (_ bv8464 32)) (bvadd ssl3_accept_~s.offset (_ bv92 32)) |v_ssl3_accept_#t~nondet17_4|) .cse0 (_ bv8464 32)))) |#memory_int|) (= ssl3_accept_~s.offset (_ bv0 32))) [2018-11-23 10:59:06,987 WARN L385 uantifierElimination]: ElimStorePlain result: ∃ []. (and (= ssl3_accept_~s.offset (_ bv0 32)) (= (_ bv8464 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32))))) [2018-11-23 10:59:07,052 INFO L701 Elim1Store]: detected not equals via solver [2018-11-23 10:59:07,053 INFO L478 Elim1Store]: Elim1 did not use preprocessing eliminated variable of array dimension 2, 1 stores, 1 select indices, 1 select index equivalence classes, 1 disjoint index pairs (out of 0 index pairs), introduced 1 new quantified variables, introduced 0 case distinctions, treesize of input 31 treesize of output 38 [2018-11-23 10:59:07,061 INFO L701 Elim1Store]: detected not equals via solver [2018-11-23 10:59:07,066 INFO L701 Elim1Store]: detected not equals via solver [2018-11-23 10:59:07,071 INFO L478 Elim1Store]: Elim1 did not use preprocessing eliminated variable of array dimension 1, 1 stores, 2 select indices, 2 select index equivalence classes, 2 disjoint index pairs (out of 1 index pairs), introduced 1 new quantified variables, introduced 0 case distinctions, treesize of input 38 treesize of output 35 [2018-11-23 10:59:07,106 INFO L267 ElimStorePlain]: Start of recursive call 3: End of recursive call: and 1 xjuncts. [2018-11-23 10:59:07,111 INFO L267 ElimStorePlain]: Start of recursive call 2: 1 dim-1 vars, End of recursive call: and 1 xjuncts. [2018-11-23 10:59:07,118 INFO L267 ElimStorePlain]: Start of recursive call 1: 1 dim-2 vars, End of recursive call: and 1 xjuncts. [2018-11-23 10:59:07,119 INFO L202 ElimStorePlain]: Needed 3 recursive calls to eliminate 1 variables, input treesize:34, output treesize:13 [2018-11-23 10:59:09,136 WARN L383 uantifierElimination]: Trying to double check SDD result, but SMT solver's response was UNKNOWN. [2018-11-23 10:59:09,137 WARN L384 uantifierElimination]: Input elimination task: ∃ [|v_#memory_int_184|]. (let ((.cse0 (select |v_#memory_int_184| ssl3_accept_~s.base))) (and (= ssl3_accept_~s.offset (_ bv0 32)) (= (_ bv8464 32) (select .cse0 (bvadd ssl3_accept_~s.offset (_ bv52 32)))) (= (store |v_#memory_int_184| ssl3_accept_~s.base (let ((.cse1 (bvadd ssl3_accept_~s.offset (_ bv28 32)))) (store .cse0 .cse1 (bvadd (select .cse0 .cse1) (_ bv1 32))))) |#memory_int|))) [2018-11-23 10:59:09,137 WARN L385 uantifierElimination]: ElimStorePlain result: ∃ []. (and (= ssl3_accept_~s.offset (_ bv0 32)) (= (_ bv8464 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32))))) [2018-11-23 10:59:09,243 INFO L478 Elim1Store]: Elim1 did not use preprocessing eliminated variable of array dimension 2, 0 stores, 1 select indices, 1 select index equivalence classes, 0 disjoint index pairs (out of 0 index pairs), introduced 1 new quantified variables, introduced 0 case distinctions, treesize of input 17 treesize of output 13 [2018-11-23 10:59:09,249 INFO L478 Elim1Store]: Elim1 did not use preprocessing eliminated variable of array dimension 1, 0 stores, 1 select indices, 1 select index equivalence classes, 0 disjoint index pairs (out of 0 index pairs), introduced 0 new quantified variables, introduced 0 case distinctions, treesize of input 13 treesize of output 5 [2018-11-23 10:59:09,250 INFO L267 ElimStorePlain]: Start of recursive call 3: End of recursive call: and 1 xjuncts. [2018-11-23 10:59:09,252 INFO L267 ElimStorePlain]: Start of recursive call 2: 1 dim-1 vars, End of recursive call: and 1 xjuncts. [2018-11-23 10:59:09,255 INFO L267 ElimStorePlain]: Start of recursive call 1: 1 dim-0 vars, 1 dim-2 vars, End of recursive call: and 1 xjuncts. [2018-11-23 10:59:09,255 INFO L202 ElimStorePlain]: Needed 3 recursive calls to eliminate 2 variables, input treesize:17, output treesize:5 [2018-11-23 10:59:09,259 WARN L383 uantifierElimination]: Trying to double check SDD result, but SMT solver's response was UNKNOWN. [2018-11-23 10:59:09,260 WARN L384 uantifierElimination]: Input elimination task: ∃ [|#memory_int|, ssl3_accept_~s.base]. (let ((.cse0 (select (select |#memory_int| ssl3_accept_~s.base) (_ bv52 32)))) (and (= (bvadd .cse0 (_ bv4294958832 32)) (_ bv0 32)) (= |ssl3_accept_#t~mem53| .cse0))) [2018-11-23 10:59:09,260 WARN L385 uantifierElimination]: ElimStorePlain result: ∃ []. (= (_ bv0 32) (bvadd |ssl3_accept_#t~mem53| (_ bv4294958832 32))) [2018-11-23 10:59:09,275 INFO L256 TraceCheckUtils]: 0: Hoare triple {1480#true} call ULTIMATE.init(); {1480#true} is VALID [2018-11-23 10:59:09,276 INFO L273 TraceCheckUtils]: 1: Hoare triple {1480#true} #NULL.base, #NULL.offset := 0bv32, 0bv32;#valid := #valid[0bv32 := 0bv1];~init~0 := 1bv32;call ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset := #Ultimate.alloc(100bv32);call write~init~intINTTYPE4(0bv32, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset, 4bv32);call write~init~$Pointer$(0bv32, 0bv32, ~#SSLv3_server_data~0.base, ~bvadd32(4bv32, ~#SSLv3_server_data~0.offset), 4bv32);call write~init~$Pointer$(0bv32, 0bv32, ~#SSLv3_server_data~0.base, ~bvadd32(8bv32, ~#SSLv3_server_data~0.offset), 4bv32);call write~init~$Pointer$(0bv32, 0bv32, ~#SSLv3_server_data~0.base, ~bvadd32(12bv32, ~#SSLv3_server_data~0.offset), 4bv32);call write~init~$Pointer$(0bv32, 0bv32, ~#SSLv3_server_data~0.base, ~bvadd32(16bv32, ~#SSLv3_server_data~0.offset), 4bv32);call write~init~$Pointer$(0bv32, 0bv32, ~#SSLv3_server_data~0.base, ~bvadd32(20bv32, ~#SSLv3_server_data~0.offset), 4bv32);call write~init~$Pointer$(0bv32, 0bv32, ~#SSLv3_server_data~0.base, ~bvadd32(24bv32, ~#SSLv3_server_data~0.offset), 4bv32);call write~init~$Pointer$(0bv32, 0bv32, ~#SSLv3_server_data~0.base, ~bvadd32(28bv32, ~#SSLv3_server_data~0.offset), 4bv32);call write~init~$Pointer$(0bv32, 0bv32, ~#SSLv3_server_data~0.base, ~bvadd32(32bv32, ~#SSLv3_server_data~0.offset), 4bv32);call write~init~$Pointer$(0bv32, 0bv32, ~#SSLv3_server_data~0.base, ~bvadd32(36bv32, ~#SSLv3_server_data~0.offset), 4bv32);call write~init~$Pointer$(0bv32, 0bv32, ~#SSLv3_server_data~0.base, ~bvadd32(40bv32, ~#SSLv3_server_data~0.offset), 4bv32);call write~init~$Pointer$(0bv32, 0bv32, ~#SSLv3_server_data~0.base, ~bvadd32(44bv32, ~#SSLv3_server_data~0.offset), 4bv32);call write~init~$Pointer$(0bv32, 0bv32, ~#SSLv3_server_data~0.base, ~bvadd32(48bv32, ~#SSLv3_server_data~0.offset), 4bv32);call write~init~$Pointer$(0bv32, 0bv32, ~#SSLv3_server_data~0.base, ~bvadd32(52bv32, ~#SSLv3_server_data~0.offset), 4bv32);call write~init~$Pointer$(0bv32, 0bv32, ~#SSLv3_server_data~0.base, ~bvadd32(56bv32, ~#SSLv3_server_data~0.offset), 4bv32);call write~init~$Pointer$(0bv32, 0bv32, ~#SSLv3_server_data~0.base, ~bvadd32(60bv32, ~#SSLv3_server_data~0.offset), 4bv32);call write~init~$Pointer$(0bv32, 0bv32, ~#SSLv3_server_data~0.base, ~bvadd32(64bv32, ~#SSLv3_server_data~0.offset), 4bv32);call write~init~$Pointer$(0bv32, 0bv32, ~#SSLv3_server_data~0.base, ~bvadd32(68bv32, ~#SSLv3_server_data~0.offset), 4bv32);call write~init~$Pointer$(0bv32, 0bv32, ~#SSLv3_server_data~0.base, ~bvadd32(72bv32, ~#SSLv3_server_data~0.offset), 4bv32);call write~init~$Pointer$(0bv32, 0bv32, ~#SSLv3_server_data~0.base, ~bvadd32(76bv32, ~#SSLv3_server_data~0.offset), 4bv32);call write~init~$Pointer$(0bv32, 0bv32, ~#SSLv3_server_data~0.base, ~bvadd32(80bv32, ~#SSLv3_server_data~0.offset), 4bv32);call write~init~$Pointer$(0bv32, 0bv32, ~#SSLv3_server_data~0.base, ~bvadd32(84bv32, ~#SSLv3_server_data~0.offset), 4bv32);call write~init~$Pointer$(0bv32, 0bv32, ~#SSLv3_server_data~0.base, ~bvadd32(88bv32, ~#SSLv3_server_data~0.offset), 4bv32);call write~init~$Pointer$(0bv32, 0bv32, ~#SSLv3_server_data~0.base, ~bvadd32(92bv32, ~#SSLv3_server_data~0.offset), 4bv32);call write~init~$Pointer$(0bv32, 0bv32, ~#SSLv3_server_data~0.base, ~bvadd32(96bv32, ~#SSLv3_server_data~0.offset), 4bv32); {1480#true} is VALID [2018-11-23 10:59:09,276 INFO L273 TraceCheckUtils]: 2: Hoare triple {1480#true} assume true; {1480#true} is VALID [2018-11-23 10:59:09,276 INFO L268 TraceCheckUtils]: 3: Hoare quadruple {1480#true} {1480#true} #631#return; {1480#true} is VALID [2018-11-23 10:59:09,276 INFO L256 TraceCheckUtils]: 4: Hoare triple {1480#true} call #t~ret138 := main(); {1480#true} is VALID [2018-11-23 10:59:09,280 INFO L273 TraceCheckUtils]: 5: Hoare triple {1480#true} havoc ~s~0.base, ~s~0.offset;havoc ~tmp~2;call #t~malloc3.base, #t~malloc3.offset := #Ultimate.alloc(248bv32);~s~0.base, ~s~0.offset := #t~malloc3.base, #t~malloc3.offset;call #t~malloc4.base, #t~malloc4.offset := #Ultimate.alloc(899bv32);call write~$Pointer$(#t~malloc4.base, #t~malloc4.offset, ~s~0.base, ~bvadd32(84bv32, ~s~0.offset), 4bv32);call #t~malloc5.base, #t~malloc5.offset := #Ultimate.alloc(232bv32);call write~$Pointer$(#t~malloc5.base, #t~malloc5.offset, ~s~0.base, ~bvadd32(204bv32, ~s~0.offset), 4bv32);call #t~malloc6.base, #t~malloc6.offset := #Ultimate.alloc(200bv32);call write~$Pointer$(#t~malloc6.base, #t~malloc6.offset, ~s~0.base, ~bvadd32(176bv32, ~s~0.offset), 4bv32); {1500#(= main_~s~0.offset (_ bv0 32))} is VALID [2018-11-23 10:59:09,281 INFO L256 TraceCheckUtils]: 6: Hoare triple {1500#(= main_~s~0.offset (_ bv0 32))} call #t~ret7 := ssl3_accept(~s~0.base, ~s~0.offset); {1504#(= (_ bv0 32) |ssl3_accept_#in~s.offset|)} is VALID [2018-11-23 10:59:09,285 INFO L273 TraceCheckUtils]: 7: Hoare triple {1504#(= (_ bv0 32) |ssl3_accept_#in~s.offset|)} ~s.base, ~s.offset := #in~s.base, #in~s.offset;havoc ~buf~0.base, ~buf~0.offset;havoc ~l~0;havoc ~Time~0;havoc ~tmp~3;havoc ~cb~0.base, ~cb~0.offset;havoc ~num1~0;havoc ~ret~0;havoc ~new_state~0;havoc ~state~0;havoc ~skip~0;havoc ~got_new_session~0;~tmp___1~0 := #t~nondet8;havoc #t~nondet8;~tmp___2~0 := #t~nondet9;havoc #t~nondet9;~tmp___3~0 := #t~nondet10;havoc #t~nondet10;~tmp___4~0 := #t~nondet11;havoc #t~nondet11;~tmp___5~0 := #t~nondet12;havoc #t~nondet12;~tmp___6~0 := #t~nondet13;havoc #t~nondet13;havoc ~tmp___7~0;~tmp___8~0 := #t~nondet14;havoc #t~nondet14;~tmp___9~0 := #t~nondet15;havoc #t~nondet15;~tmp___10~0 := #t~nondet16;havoc #t~nondet16;havoc ~blastFlag~0;call write~intINTTYPE4(8464bv32, ~s.base, ~bvadd32(52bv32, ~s.offset), 4bv32);~blastFlag~0 := 0bv32;call write~intINTTYPE4(#t~nondet17, ~s.base, ~bvadd32(92bv32, ~s.offset), 4bv32);havoc #t~nondet17;call write~intINTTYPE4(8464bv32, ~s.base, ~bvadd32(52bv32, ~s.offset), 4bv32);~tmp~3 := #t~nondet18;havoc #t~nondet18;~Time~0 := ~tmp~3;~cb~0.base, ~cb~0.offset := 0bv32, 0bv32;~ret~0 := 4294967295bv32;~skip~0 := 0bv32;~got_new_session~0 := 0bv32;call #t~mem19.base, #t~mem19.offset := read~$Pointer$(~s.base, ~bvadd32(192bv32, ~s.offset), 4bv32); {1508#(and (= ssl3_accept_~s.offset (_ bv0 32)) (= (_ bv8464 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32)))))} is VALID [2018-11-23 10:59:09,286 INFO L273 TraceCheckUtils]: 8: Hoare triple {1508#(and (= ssl3_accept_~s.offset (_ bv0 32)) (= (_ bv8464 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32)))))} assume 0bv32 != ~bvadd32(#t~mem19.base, #t~mem19.offset);havoc #t~mem19.base, #t~mem19.offset;call #t~mem20.base, #t~mem20.offset := read~$Pointer$(~s.base, ~bvadd32(192bv32, ~s.offset), 4bv32);~cb~0.base, ~cb~0.offset := #t~mem20.base, #t~mem20.offset;havoc #t~mem20.base, #t~mem20.offset; {1508#(and (= ssl3_accept_~s.offset (_ bv0 32)) (= (_ bv8464 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32)))))} is VALID [2018-11-23 10:59:09,288 INFO L273 TraceCheckUtils]: 9: Hoare triple {1508#(and (= ssl3_accept_~s.offset (_ bv0 32)) (= (_ bv8464 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32)))))} call #t~mem21 := read~intINTTYPE4(~s.base, ~bvadd32(28bv32, ~s.offset), 4bv32);call write~intINTTYPE4(~bvadd32(1bv32, #t~mem21), ~s.base, ~bvadd32(28bv32, ~s.offset), 4bv32);havoc #t~mem21; {1508#(and (= ssl3_accept_~s.offset (_ bv0 32)) (= (_ bv8464 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32)))))} is VALID [2018-11-23 10:59:09,289 INFO L273 TraceCheckUtils]: 10: Hoare triple {1508#(and (= ssl3_accept_~s.offset (_ bv0 32)) (= (_ bv8464 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32)))))} assume !(0bv32 != ~bvand32(12288bv32, ~tmp___1~0)); {1508#(and (= ssl3_accept_~s.offset (_ bv0 32)) (= (_ bv8464 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32)))))} is VALID [2018-11-23 10:59:09,290 INFO L273 TraceCheckUtils]: 11: Hoare triple {1508#(and (= ssl3_accept_~s.offset (_ bv0 32)) (= (_ bv8464 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32)))))} call #t~mem22.base, #t~mem22.offset := read~$Pointer$(~s.base, ~bvadd32(136bv32, ~s.offset), 4bv32); {1508#(and (= ssl3_accept_~s.offset (_ bv0 32)) (= (_ bv8464 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32)))))} is VALID [2018-11-23 10:59:09,290 INFO L273 TraceCheckUtils]: 12: Hoare triple {1508#(and (= ssl3_accept_~s.offset (_ bv0 32)) (= (_ bv8464 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32)))))} assume !(0bv32 == ~bvadd32(#t~mem22.base, #t~mem22.offset));havoc #t~mem22.base, #t~mem22.offset; {1508#(and (= ssl3_accept_~s.offset (_ bv0 32)) (= (_ bv8464 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32)))))} is VALID [2018-11-23 10:59:09,291 INFO L273 TraceCheckUtils]: 13: Hoare triple {1508#(and (= ssl3_accept_~s.offset (_ bv0 32)) (= (_ bv8464 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32)))))} assume !false; {1508#(and (= ssl3_accept_~s.offset (_ bv0 32)) (= (_ bv8464 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32)))))} is VALID [2018-11-23 10:59:09,293 INFO L273 TraceCheckUtils]: 14: Hoare triple {1508#(and (= ssl3_accept_~s.offset (_ bv0 32)) (= (_ bv8464 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32)))))} call #t~mem23 := read~intINTTYPE4(~s.base, ~bvadd32(52bv32, ~s.offset), 4bv32);~state~0 := #t~mem23;havoc #t~mem23;call #t~mem24 := read~intINTTYPE4(~s.base, ~bvadd32(52bv32, ~s.offset), 4bv32); {1508#(and (= ssl3_accept_~s.offset (_ bv0 32)) (= (_ bv8464 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32)))))} is VALID [2018-11-23 10:59:09,294 INFO L273 TraceCheckUtils]: 15: Hoare triple {1508#(and (= ssl3_accept_~s.offset (_ bv0 32)) (= (_ bv8464 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32)))))} assume !(12292bv32 == #t~mem24);havoc #t~mem24;call #t~mem25 := read~intINTTYPE4(~s.base, ~bvadd32(52bv32, ~s.offset), 4bv32); {1508#(and (= ssl3_accept_~s.offset (_ bv0 32)) (= (_ bv8464 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32)))))} is VALID [2018-11-23 10:59:09,294 INFO L273 TraceCheckUtils]: 16: Hoare triple {1508#(and (= ssl3_accept_~s.offset (_ bv0 32)) (= (_ bv8464 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32)))))} assume !(16384bv32 == #t~mem25);havoc #t~mem25;call #t~mem26 := read~intINTTYPE4(~s.base, ~bvadd32(52bv32, ~s.offset), 4bv32); {1508#(and (= ssl3_accept_~s.offset (_ bv0 32)) (= (_ bv8464 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32)))))} is VALID [2018-11-23 10:59:09,299 INFO L273 TraceCheckUtils]: 17: Hoare triple {1508#(and (= ssl3_accept_~s.offset (_ bv0 32)) (= (_ bv8464 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32)))))} assume !(8192bv32 == #t~mem26);havoc #t~mem26;call #t~mem27 := read~intINTTYPE4(~s.base, ~bvadd32(52bv32, ~s.offset), 4bv32); {1508#(and (= ssl3_accept_~s.offset (_ bv0 32)) (= (_ bv8464 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32)))))} is VALID [2018-11-23 10:59:09,300 INFO L273 TraceCheckUtils]: 18: Hoare triple {1508#(and (= ssl3_accept_~s.offset (_ bv0 32)) (= (_ bv8464 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32)))))} assume !(24576bv32 == #t~mem27);havoc #t~mem27;call #t~mem28 := read~intINTTYPE4(~s.base, ~bvadd32(52bv32, ~s.offset), 4bv32); {1508#(and (= ssl3_accept_~s.offset (_ bv0 32)) (= (_ bv8464 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32)))))} is VALID [2018-11-23 10:59:09,300 INFO L273 TraceCheckUtils]: 19: Hoare triple {1508#(and (= ssl3_accept_~s.offset (_ bv0 32)) (= (_ bv8464 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32)))))} assume !(8195bv32 == #t~mem28);havoc #t~mem28;call #t~mem29 := read~intINTTYPE4(~s.base, ~bvadd32(52bv32, ~s.offset), 4bv32); {1508#(and (= ssl3_accept_~s.offset (_ bv0 32)) (= (_ bv8464 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32)))))} is VALID [2018-11-23 10:59:09,301 INFO L273 TraceCheckUtils]: 20: Hoare triple {1508#(and (= ssl3_accept_~s.offset (_ bv0 32)) (= (_ bv8464 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32)))))} assume !(8480bv32 == #t~mem29);havoc #t~mem29;call #t~mem30 := read~intINTTYPE4(~s.base, ~bvadd32(52bv32, ~s.offset), 4bv32); {1508#(and (= ssl3_accept_~s.offset (_ bv0 32)) (= (_ bv8464 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32)))))} is VALID [2018-11-23 10:59:09,302 INFO L273 TraceCheckUtils]: 21: Hoare triple {1508#(and (= ssl3_accept_~s.offset (_ bv0 32)) (= (_ bv8464 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32)))))} assume !(8481bv32 == #t~mem30);havoc #t~mem30;call #t~mem31 := read~intINTTYPE4(~s.base, ~bvadd32(52bv32, ~s.offset), 4bv32); {1508#(and (= ssl3_accept_~s.offset (_ bv0 32)) (= (_ bv8464 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32)))))} is VALID [2018-11-23 10:59:09,303 INFO L273 TraceCheckUtils]: 22: Hoare triple {1508#(and (= ssl3_accept_~s.offset (_ bv0 32)) (= (_ bv8464 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32)))))} assume !(8482bv32 == #t~mem31);havoc #t~mem31;call #t~mem32 := read~intINTTYPE4(~s.base, ~bvadd32(52bv32, ~s.offset), 4bv32); {1508#(and (= ssl3_accept_~s.offset (_ bv0 32)) (= (_ bv8464 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32)))))} is VALID [2018-11-23 10:59:09,303 INFO L273 TraceCheckUtils]: 23: Hoare triple {1508#(and (= ssl3_accept_~s.offset (_ bv0 32)) (= (_ bv8464 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32)))))} assume !(8464bv32 == #t~mem32);havoc #t~mem32;call #t~mem33 := read~intINTTYPE4(~s.base, ~bvadd32(52bv32, ~s.offset), 4bv32); {1508#(and (= ssl3_accept_~s.offset (_ bv0 32)) (= (_ bv8464 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32)))))} is VALID [2018-11-23 10:59:09,304 INFO L273 TraceCheckUtils]: 24: Hoare triple {1508#(and (= ssl3_accept_~s.offset (_ bv0 32)) (= (_ bv8464 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32)))))} assume !(8465bv32 == #t~mem33);havoc #t~mem33;call #t~mem34 := read~intINTTYPE4(~s.base, ~bvadd32(52bv32, ~s.offset), 4bv32); {1508#(and (= ssl3_accept_~s.offset (_ bv0 32)) (= (_ bv8464 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32)))))} is VALID [2018-11-23 10:59:09,305 INFO L273 TraceCheckUtils]: 25: Hoare triple {1508#(and (= ssl3_accept_~s.offset (_ bv0 32)) (= (_ bv8464 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32)))))} assume !(8466bv32 == #t~mem34);havoc #t~mem34;call #t~mem35 := read~intINTTYPE4(~s.base, ~bvadd32(52bv32, ~s.offset), 4bv32); {1508#(and (= ssl3_accept_~s.offset (_ bv0 32)) (= (_ bv8464 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32)))))} is VALID [2018-11-23 10:59:09,306 INFO L273 TraceCheckUtils]: 26: Hoare triple {1508#(and (= ssl3_accept_~s.offset (_ bv0 32)) (= (_ bv8464 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32)))))} assume !(8496bv32 == #t~mem35);havoc #t~mem35;call #t~mem36 := read~intINTTYPE4(~s.base, ~bvadd32(52bv32, ~s.offset), 4bv32); {1508#(and (= ssl3_accept_~s.offset (_ bv0 32)) (= (_ bv8464 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32)))))} is VALID [2018-11-23 10:59:09,315 INFO L273 TraceCheckUtils]: 27: Hoare triple {1508#(and (= ssl3_accept_~s.offset (_ bv0 32)) (= (_ bv8464 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32)))))} assume !(8497bv32 == #t~mem36);havoc #t~mem36;call #t~mem37 := read~intINTTYPE4(~s.base, ~bvadd32(52bv32, ~s.offset), 4bv32); {1508#(and (= ssl3_accept_~s.offset (_ bv0 32)) (= (_ bv8464 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32)))))} is VALID [2018-11-23 10:59:09,316 INFO L273 TraceCheckUtils]: 28: Hoare triple {1508#(and (= ssl3_accept_~s.offset (_ bv0 32)) (= (_ bv8464 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32)))))} assume !(8512bv32 == #t~mem37);havoc #t~mem37;call #t~mem38 := read~intINTTYPE4(~s.base, ~bvadd32(52bv32, ~s.offset), 4bv32); {1508#(and (= ssl3_accept_~s.offset (_ bv0 32)) (= (_ bv8464 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32)))))} is VALID [2018-11-23 10:59:09,317 INFO L273 TraceCheckUtils]: 29: Hoare triple {1508#(and (= ssl3_accept_~s.offset (_ bv0 32)) (= (_ bv8464 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32)))))} assume !(8513bv32 == #t~mem38);havoc #t~mem38;call #t~mem39 := read~intINTTYPE4(~s.base, ~bvadd32(52bv32, ~s.offset), 4bv32); {1508#(and (= ssl3_accept_~s.offset (_ bv0 32)) (= (_ bv8464 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32)))))} is VALID [2018-11-23 10:59:09,318 INFO L273 TraceCheckUtils]: 30: Hoare triple {1508#(and (= ssl3_accept_~s.offset (_ bv0 32)) (= (_ bv8464 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32)))))} assume !(8528bv32 == #t~mem39);havoc #t~mem39;call #t~mem40 := read~intINTTYPE4(~s.base, ~bvadd32(52bv32, ~s.offset), 4bv32); {1508#(and (= ssl3_accept_~s.offset (_ bv0 32)) (= (_ bv8464 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32)))))} is VALID [2018-11-23 10:59:09,319 INFO L273 TraceCheckUtils]: 31: Hoare triple {1508#(and (= ssl3_accept_~s.offset (_ bv0 32)) (= (_ bv8464 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32)))))} assume !(8529bv32 == #t~mem40);havoc #t~mem40;call #t~mem41 := read~intINTTYPE4(~s.base, ~bvadd32(52bv32, ~s.offset), 4bv32); {1508#(and (= ssl3_accept_~s.offset (_ bv0 32)) (= (_ bv8464 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32)))))} is VALID [2018-11-23 10:59:09,320 INFO L273 TraceCheckUtils]: 32: Hoare triple {1508#(and (= ssl3_accept_~s.offset (_ bv0 32)) (= (_ bv8464 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32)))))} assume !(8544bv32 == #t~mem41);havoc #t~mem41;call #t~mem42 := read~intINTTYPE4(~s.base, ~bvadd32(52bv32, ~s.offset), 4bv32); {1508#(and (= ssl3_accept_~s.offset (_ bv0 32)) (= (_ bv8464 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32)))))} is VALID [2018-11-23 10:59:09,321 INFO L273 TraceCheckUtils]: 33: Hoare triple {1508#(and (= ssl3_accept_~s.offset (_ bv0 32)) (= (_ bv8464 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32)))))} assume !(8545bv32 == #t~mem42);havoc #t~mem42;call #t~mem43 := read~intINTTYPE4(~s.base, ~bvadd32(52bv32, ~s.offset), 4bv32); {1508#(and (= ssl3_accept_~s.offset (_ bv0 32)) (= (_ bv8464 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32)))))} is VALID [2018-11-23 10:59:09,321 INFO L273 TraceCheckUtils]: 34: Hoare triple {1508#(and (= ssl3_accept_~s.offset (_ bv0 32)) (= (_ bv8464 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32)))))} assume !(8560bv32 == #t~mem43);havoc #t~mem43;call #t~mem44 := read~intINTTYPE4(~s.base, ~bvadd32(52bv32, ~s.offset), 4bv32); {1508#(and (= ssl3_accept_~s.offset (_ bv0 32)) (= (_ bv8464 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32)))))} is VALID [2018-11-23 10:59:09,322 INFO L273 TraceCheckUtils]: 35: Hoare triple {1508#(and (= ssl3_accept_~s.offset (_ bv0 32)) (= (_ bv8464 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32)))))} assume !(8561bv32 == #t~mem44);havoc #t~mem44;call #t~mem45 := read~intINTTYPE4(~s.base, ~bvadd32(52bv32, ~s.offset), 4bv32); {1508#(and (= ssl3_accept_~s.offset (_ bv0 32)) (= (_ bv8464 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32)))))} is VALID [2018-11-23 10:59:09,323 INFO L273 TraceCheckUtils]: 36: Hoare triple {1508#(and (= ssl3_accept_~s.offset (_ bv0 32)) (= (_ bv8464 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32)))))} assume !(8448bv32 == #t~mem45);havoc #t~mem45;call #t~mem46 := read~intINTTYPE4(~s.base, ~bvadd32(52bv32, ~s.offset), 4bv32); {1508#(and (= ssl3_accept_~s.offset (_ bv0 32)) (= (_ bv8464 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32)))))} is VALID [2018-11-23 10:59:09,323 INFO L273 TraceCheckUtils]: 37: Hoare triple {1508#(and (= ssl3_accept_~s.offset (_ bv0 32)) (= (_ bv8464 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32)))))} assume !(8576bv32 == #t~mem46);havoc #t~mem46;call #t~mem47 := read~intINTTYPE4(~s.base, ~bvadd32(52bv32, ~s.offset), 4bv32); {1508#(and (= ssl3_accept_~s.offset (_ bv0 32)) (= (_ bv8464 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32)))))} is VALID [2018-11-23 10:59:09,324 INFO L273 TraceCheckUtils]: 38: Hoare triple {1508#(and (= ssl3_accept_~s.offset (_ bv0 32)) (= (_ bv8464 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32)))))} assume !(8577bv32 == #t~mem47);havoc #t~mem47;call #t~mem48 := read~intINTTYPE4(~s.base, ~bvadd32(52bv32, ~s.offset), 4bv32); {1508#(and (= ssl3_accept_~s.offset (_ bv0 32)) (= (_ bv8464 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32)))))} is VALID [2018-11-23 10:59:09,325 INFO L273 TraceCheckUtils]: 39: Hoare triple {1508#(and (= ssl3_accept_~s.offset (_ bv0 32)) (= (_ bv8464 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32)))))} assume !(8592bv32 == #t~mem48);havoc #t~mem48;call #t~mem49 := read~intINTTYPE4(~s.base, ~bvadd32(52bv32, ~s.offset), 4bv32); {1508#(and (= ssl3_accept_~s.offset (_ bv0 32)) (= (_ bv8464 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32)))))} is VALID [2018-11-23 10:59:09,326 INFO L273 TraceCheckUtils]: 40: Hoare triple {1508#(and (= ssl3_accept_~s.offset (_ bv0 32)) (= (_ bv8464 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32)))))} assume !(8593bv32 == #t~mem49);havoc #t~mem49;call #t~mem50 := read~intINTTYPE4(~s.base, ~bvadd32(52bv32, ~s.offset), 4bv32); {1508#(and (= ssl3_accept_~s.offset (_ bv0 32)) (= (_ bv8464 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32)))))} is VALID [2018-11-23 10:59:09,328 INFO L273 TraceCheckUtils]: 41: Hoare triple {1508#(and (= ssl3_accept_~s.offset (_ bv0 32)) (= (_ bv8464 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32)))))} assume !(8608bv32 == #t~mem50);havoc #t~mem50;call #t~mem51 := read~intINTTYPE4(~s.base, ~bvadd32(52bv32, ~s.offset), 4bv32); {1508#(and (= ssl3_accept_~s.offset (_ bv0 32)) (= (_ bv8464 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32)))))} is VALID [2018-11-23 10:59:09,329 INFO L273 TraceCheckUtils]: 42: Hoare triple {1508#(and (= ssl3_accept_~s.offset (_ bv0 32)) (= (_ bv8464 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32)))))} assume !(8609bv32 == #t~mem51);havoc #t~mem51;call #t~mem52 := read~intINTTYPE4(~s.base, ~bvadd32(52bv32, ~s.offset), 4bv32); {1508#(and (= ssl3_accept_~s.offset (_ bv0 32)) (= (_ bv8464 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32)))))} is VALID [2018-11-23 10:59:09,329 INFO L273 TraceCheckUtils]: 43: Hoare triple {1508#(and (= ssl3_accept_~s.offset (_ bv0 32)) (= (_ bv8464 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32)))))} assume !(8640bv32 == #t~mem52);havoc #t~mem52;call #t~mem53 := read~intINTTYPE4(~s.base, ~bvadd32(52bv32, ~s.offset), 4bv32); {1617#(= (_ bv8464 32) |ssl3_accept_#t~mem53|)} is VALID [2018-11-23 10:59:09,330 INFO L273 TraceCheckUtils]: 44: Hoare triple {1617#(= (_ bv8464 32) |ssl3_accept_#t~mem53|)} assume 8641bv32 == #t~mem53;havoc #t~mem53; {1481#false} is VALID [2018-11-23 10:59:09,330 INFO L273 TraceCheckUtils]: 45: Hoare triple {1481#false} ~ret~0 := #t~nondet115;havoc #t~nondet115; {1481#false} is VALID [2018-11-23 10:59:09,330 INFO L273 TraceCheckUtils]: 46: Hoare triple {1481#false} assume !(4bv32 == ~blastFlag~0); {1481#false} is VALID [2018-11-23 10:59:09,331 INFO L273 TraceCheckUtils]: 47: Hoare triple {1481#false} assume !(7bv32 == ~blastFlag~0); {1481#false} is VALID [2018-11-23 10:59:09,331 INFO L273 TraceCheckUtils]: 48: Hoare triple {1481#false} assume !false; {1481#false} is VALID [2018-11-23 10:59:09,338 INFO L134 CoverageAnalysis]: Checked inductivity of 0 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2018-11-23 10:59:09,338 INFO L312 TraceCheckSpWp]: Omiting computation of backward sequence because forward sequence was already perfect [2018-11-23 10:59:09,340 INFO L312 seRefinementStrategy]: Constructing automaton from 1 perfect and 0 imperfect interpolant sequences. [2018-11-23 10:59:09,341 INFO L327 seRefinementStrategy]: Number of different interpolants: perfect sequences [6] imperfect sequences [] total 6 [2018-11-23 10:59:09,343 INFO L78 Accepts]: Start accepts. Automaton has 6 states. Word has length 49 [2018-11-23 10:59:09,344 INFO L84 Accepts]: Finished accepts. word is accepted. [2018-11-23 10:59:09,344 INFO L86 InductivityCheck]: Starting indutivity check of a Floyd-Hoare automaton with 6 states. [2018-11-23 10:59:09,467 INFO L119 InductivityCheck]: Floyd-Hoare automaton has 49 edges. 49 inductive. 0 not inductive. 0 times theorem prover too weak to decide inductivity. [2018-11-23 10:59:09,468 INFO L459 AbstractCegarLoop]: Interpolant automaton has 6 states [2018-11-23 10:59:09,468 INFO L142 InterpolantAutomaton]: Constructing interpolant automaton starting with 6 interpolants. [2018-11-23 10:59:09,468 INFO L144 InterpolantAutomaton]: CoverageRelationStatistics Valid=9, Invalid=21, Unknown=0, NotChecked=0, Total=30 [2018-11-23 10:59:09,469 INFO L87 Difference]: Start difference. First operand 172 states and 272 transitions. Second operand 6 states. [2018-11-23 10:59:27,820 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2018-11-23 10:59:27,821 INFO L93 Difference]: Finished difference Result 358 states and 549 transitions. [2018-11-23 10:59:27,821 INFO L142 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 6 states. [2018-11-23 10:59:27,821 INFO L78 Accepts]: Start accepts. Automaton has 6 states. Word has length 49 [2018-11-23 10:59:27,821 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2018-11-23 10:59:27,821 INFO L82 GeneralOperation]: Start removeUnreachable. Operand 6 states. [2018-11-23 10:59:27,828 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 6 states to 6 states and 549 transitions. [2018-11-23 10:59:27,828 INFO L82 GeneralOperation]: Start removeUnreachable. Operand 6 states. [2018-11-23 10:59:27,834 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 6 states to 6 states and 549 transitions. [2018-11-23 10:59:27,834 INFO L86 InductivityCheck]: Starting indutivity check of a Floyd-Hoare automaton with 6 states and 549 transitions. [2018-11-23 10:59:28,856 INFO L119 InductivityCheck]: Floyd-Hoare automaton has 549 edges. 549 inductive. 0 not inductive. 0 times theorem prover too weak to decide inductivity. [2018-11-23 10:59:28,864 INFO L225 Difference]: With dead ends: 358 [2018-11-23 10:59:28,864 INFO L226 Difference]: Without dead ends: 231 [2018-11-23 10:59:28,866 INFO L631 BasicCegarLoop]: 0 DeclaredPredicates, 50 GetRequests, 44 SyntacticMatches, 0 SemanticMatches, 6 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 0 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=19, Invalid=37, Unknown=0, NotChecked=0, Total=56 [2018-11-23 10:59:28,867 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 231 states. [2018-11-23 10:59:29,063 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 231 to 173. [2018-11-23 10:59:29,064 INFO L214 AbstractMinimizeNwa]: Start testing correctness of minimizeSevpa [2018-11-23 10:59:29,064 INFO L82 GeneralOperation]: Start isEquivalent. First operand 231 states. Second operand 173 states. [2018-11-23 10:59:29,064 INFO L74 IsIncluded]: Start isIncluded. First operand 231 states. Second operand 173 states. [2018-11-23 10:59:29,064 INFO L87 Difference]: Start difference. First operand 231 states. Second operand 173 states. [2018-11-23 10:59:29,077 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2018-11-23 10:59:29,077 INFO L93 Difference]: Finished difference Result 231 states and 352 transitions. [2018-11-23 10:59:29,078 INFO L276 IsEmpty]: Start isEmpty. Operand 231 states and 352 transitions. [2018-11-23 10:59:29,079 INFO L282 IsEmpty]: Finished isEmpty. No accepting run. [2018-11-23 10:59:29,079 INFO L83 IsIncluded]: Finished isIncluded. Language is included [2018-11-23 10:59:29,079 INFO L74 IsIncluded]: Start isIncluded. First operand 173 states. Second operand 231 states. [2018-11-23 10:59:29,079 INFO L87 Difference]: Start difference. First operand 173 states. Second operand 231 states. [2018-11-23 10:59:29,088 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2018-11-23 10:59:29,089 INFO L93 Difference]: Finished difference Result 231 states and 352 transitions. [2018-11-23 10:59:29,089 INFO L276 IsEmpty]: Start isEmpty. Operand 231 states and 352 transitions. [2018-11-23 10:59:29,090 INFO L282 IsEmpty]: Finished isEmpty. No accepting run. [2018-11-23 10:59:29,090 INFO L83 IsIncluded]: Finished isIncluded. Language is included [2018-11-23 10:59:29,090 INFO L88 GeneralOperation]: Finished isEquivalent. [2018-11-23 10:59:29,090 INFO L221 AbstractMinimizeNwa]: Finished testing correctness of minimizeSevpa [2018-11-23 10:59:29,090 INFO L82 GeneralOperation]: Start removeUnreachable. Operand 173 states. [2018-11-23 10:59:29,100 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 173 states to 173 states and 273 transitions. [2018-11-23 10:59:29,100 INFO L78 Accepts]: Start accepts. Automaton has 173 states and 273 transitions. Word has length 49 [2018-11-23 10:59:29,101 INFO L84 Accepts]: Finished accepts. word is rejected. [2018-11-23 10:59:29,101 INFO L480 AbstractCegarLoop]: Abstraction has 173 states and 273 transitions. [2018-11-23 10:59:29,101 INFO L481 AbstractCegarLoop]: Interpolant automaton has 6 states. [2018-11-23 10:59:29,101 INFO L276 IsEmpty]: Start isEmpty. Operand 173 states and 273 transitions. [2018-11-23 10:59:29,105 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 62 [2018-11-23 10:59:29,105 INFO L394 BasicCegarLoop]: Found error trace [2018-11-23 10:59:29,105 INFO L402 BasicCegarLoop]: trace histogram [2, 2, 2, 2, 2, 2, 2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2018-11-23 10:59:29,108 INFO L423 AbstractCegarLoop]: === Iteration 3 === [ssl3_acceptErr0ASSERT_VIOLATIONERROR_FUNCTION]=== [2018-11-23 10:59:29,109 INFO L141 PredicateUnifier]: Initialized classic predicate unifier [2018-11-23 10:59:29,109 INFO L82 PathProgramCache]: Analyzing trace with hash -1437939466, now seen corresponding path program 1 times [2018-11-23 10:59:29,109 INFO L223 ckRefinementStrategy]: Switched to mode CVC4_FPBP [2018-11-23 10:59:29,110 INFO L69 tionRefinementEngine]: Using refinement strategy WolfRefinementStrategy No working directory specified, using /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/cvc4nyu Starting monitored process 4 with cvc4nyu --tear-down-incremental --print-success --lang smt --rewrite-divk (exit command is (exit), workingDir is null) Waiting until toolchain timeout for monitored process 4 with cvc4nyu --tear-down-incremental --print-success --lang smt --rewrite-divk [2018-11-23 10:59:29,135 INFO L103 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2018-11-23 10:59:29,421 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2018-11-23 10:59:29,532 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2018-11-23 10:59:29,535 INFO L273 TraceCheckSpWp]: Computing forward predicates... [2018-11-23 10:59:29,583 INFO L478 Elim1Store]: Elim1 did not use preprocessing eliminated variable of array dimension 2, 1 stores, 1 select indices, 1 select index equivalence classes, 0 disjoint index pairs (out of 0 index pairs), introduced 1 new quantified variables, introduced 0 case distinctions, treesize of input 23 treesize of output 20 [2018-11-23 10:59:29,594 INFO L478 Elim1Store]: Elim1 did not use preprocessing eliminated variable of array dimension 1, 1 stores, 0 select indices, 0 select index equivalence classes, 0 disjoint index pairs (out of 0 index pairs), introduced 1 new quantified variables, introduced 0 case distinctions, treesize of input 20 treesize of output 23 [2018-11-23 10:59:29,603 INFO L701 Elim1Store]: detected not equals via solver [2018-11-23 10:59:29,607 INFO L478 Elim1Store]: Elim1 did not use preprocessing eliminated variable of array dimension 1, 1 stores, 1 select indices, 1 select index equivalence classes, 1 disjoint index pairs (out of 0 index pairs), introduced 1 new quantified variables, introduced 0 case distinctions, treesize of input 23 treesize of output 33 [2018-11-23 10:59:29,616 INFO L701 Elim1Store]: detected not equals via solver [2018-11-23 10:59:29,621 INFO L478 Elim1Store]: Elim1 did not use preprocessing eliminated variable of array dimension 1, 1 stores, 2 select indices, 2 select index equivalence classes, 1 disjoint index pairs (out of 1 index pairs), introduced 0 new quantified variables, introduced 0 case distinctions, treesize of input 25 treesize of output 27 [2018-11-23 10:59:29,624 INFO L267 ElimStorePlain]: Start of recursive call 5: End of recursive call: and 1 xjuncts. [2018-11-23 10:59:29,635 INFO L267 ElimStorePlain]: Start of recursive call 4: 1 dim-1 vars, End of recursive call: and 1 xjuncts. [2018-11-23 10:59:29,646 INFO L267 ElimStorePlain]: Start of recursive call 3: 1 dim-1 vars, End of recursive call: and 1 xjuncts. [2018-11-23 10:59:29,657 INFO L267 ElimStorePlain]: Start of recursive call 2: 1 dim-1 vars, End of recursive call: and 1 xjuncts. [2018-11-23 10:59:29,672 INFO L267 ElimStorePlain]: Start of recursive call 1: 1 dim-0 vars, 1 dim-2 vars, End of recursive call: and 1 xjuncts. [2018-11-23 10:59:29,673 INFO L202 ElimStorePlain]: Needed 5 recursive calls to eliminate 2 variables, input treesize:27, output treesize:13 [2018-11-23 10:59:29,690 WARN L383 uantifierElimination]: Trying to double check SDD result, but SMT solver's response was UNKNOWN. [2018-11-23 10:59:29,691 WARN L384 uantifierElimination]: Input elimination task: ∃ [|v_#memory_int_185|, |v_ssl3_accept_#t~nondet17_5|]. (and (= ssl3_accept_~s.offset (_ bv0 32)) (= (store |v_#memory_int_185| ssl3_accept_~s.base (let ((.cse0 (bvadd ssl3_accept_~s.offset (_ bv52 32)))) (store (store (store (select |v_#memory_int_185| ssl3_accept_~s.base) .cse0 (_ bv8464 32)) (bvadd ssl3_accept_~s.offset (_ bv92 32)) |v_ssl3_accept_#t~nondet17_5|) .cse0 (_ bv8464 32)))) |#memory_int|)) [2018-11-23 10:59:29,691 WARN L385 uantifierElimination]: ElimStorePlain result: ∃ []. (and (= ssl3_accept_~s.offset (_ bv0 32)) (= (_ bv8464 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32))))) [2018-11-23 10:59:29,739 INFO L701 Elim1Store]: detected not equals via solver [2018-11-23 10:59:29,740 INFO L478 Elim1Store]: Elim1 did not use preprocessing eliminated variable of array dimension 2, 1 stores, 1 select indices, 1 select index equivalence classes, 1 disjoint index pairs (out of 0 index pairs), introduced 1 new quantified variables, introduced 0 case distinctions, treesize of input 31 treesize of output 38 [2018-11-23 10:59:29,748 INFO L701 Elim1Store]: detected not equals via solver [2018-11-23 10:59:29,757 INFO L701 Elim1Store]: detected not equals via solver [2018-11-23 10:59:29,759 INFO L478 Elim1Store]: Elim1 did not use preprocessing eliminated variable of array dimension 1, 1 stores, 2 select indices, 2 select index equivalence classes, 2 disjoint index pairs (out of 1 index pairs), introduced 1 new quantified variables, introduced 0 case distinctions, treesize of input 38 treesize of output 35 [2018-11-23 10:59:29,774 INFO L267 ElimStorePlain]: Start of recursive call 3: End of recursive call: and 1 xjuncts. [2018-11-23 10:59:29,779 INFO L267 ElimStorePlain]: Start of recursive call 2: 1 dim-1 vars, End of recursive call: and 1 xjuncts. [2018-11-23 10:59:29,788 INFO L267 ElimStorePlain]: Start of recursive call 1: 1 dim-2 vars, End of recursive call: and 1 xjuncts. [2018-11-23 10:59:29,789 INFO L202 ElimStorePlain]: Needed 3 recursive calls to eliminate 1 variables, input treesize:34, output treesize:13 [2018-11-23 10:59:31,808 WARN L383 uantifierElimination]: Trying to double check SDD result, but SMT solver's response was UNKNOWN. [2018-11-23 10:59:31,808 WARN L384 uantifierElimination]: Input elimination task: ∃ [|v_#memory_int_186|]. (let ((.cse0 (select |v_#memory_int_186| ssl3_accept_~s.base))) (and (= ssl3_accept_~s.offset (_ bv0 32)) (= (_ bv8464 32) (select .cse0 (bvadd ssl3_accept_~s.offset (_ bv52 32)))) (= (store |v_#memory_int_186| ssl3_accept_~s.base (let ((.cse1 (bvadd ssl3_accept_~s.offset (_ bv28 32)))) (store .cse0 .cse1 (bvadd (select .cse0 .cse1) (_ bv1 32))))) |#memory_int|))) [2018-11-23 10:59:31,808 WARN L385 uantifierElimination]: ElimStorePlain result: ∃ []. (and (= ssl3_accept_~s.offset (_ bv0 32)) (= (_ bv8464 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32))))) [2018-11-23 10:59:31,852 INFO L478 Elim1Store]: Elim1 did not use preprocessing eliminated variable of array dimension 2, 0 stores, 1 select indices, 1 select index equivalence classes, 0 disjoint index pairs (out of 0 index pairs), introduced 1 new quantified variables, introduced 0 case distinctions, treesize of input 17 treesize of output 13 [2018-11-23 10:59:31,858 INFO L478 Elim1Store]: Elim1 did not use preprocessing eliminated variable of array dimension 1, 0 stores, 1 select indices, 1 select index equivalence classes, 0 disjoint index pairs (out of 0 index pairs), introduced 0 new quantified variables, introduced 0 case distinctions, treesize of input 13 treesize of output 5 [2018-11-23 10:59:31,865 INFO L267 ElimStorePlain]: Start of recursive call 3: End of recursive call: and 1 xjuncts. [2018-11-23 10:59:31,867 INFO L267 ElimStorePlain]: Start of recursive call 2: 1 dim-1 vars, End of recursive call: and 1 xjuncts. [2018-11-23 10:59:31,869 INFO L267 ElimStorePlain]: Start of recursive call 1: 1 dim-0 vars, 1 dim-2 vars, End of recursive call: and 1 xjuncts. [2018-11-23 10:59:31,870 INFO L202 ElimStorePlain]: Needed 3 recursive calls to eliminate 2 variables, input treesize:17, output treesize:5 [2018-11-23 10:59:31,873 WARN L383 uantifierElimination]: Trying to double check SDD result, but SMT solver's response was UNKNOWN. [2018-11-23 10:59:31,873 WARN L384 uantifierElimination]: Input elimination task: ∃ [|#memory_int|, ssl3_accept_~s.base]. (let ((.cse0 (select (select |#memory_int| ssl3_accept_~s.base) (_ bv52 32)))) (and (= |ssl3_accept_#t~mem29| .cse0) (= (bvadd .cse0 (_ bv4294958832 32)) (_ bv0 32)))) [2018-11-23 10:59:31,873 WARN L385 uantifierElimination]: ElimStorePlain result: ∃ []. (= (bvadd |ssl3_accept_#t~mem29| (_ bv4294958832 32)) (_ bv0 32)) [2018-11-23 10:59:31,911 INFO L256 TraceCheckUtils]: 0: Hoare triple {2730#true} call ULTIMATE.init(); {2730#true} is VALID [2018-11-23 10:59:31,912 INFO L273 TraceCheckUtils]: 1: Hoare triple {2730#true} #NULL.base, #NULL.offset := 0bv32, 0bv32;#valid := #valid[0bv32 := 0bv1];~init~0 := 1bv32;call ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset := #Ultimate.alloc(100bv32);call write~init~intINTTYPE4(0bv32, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset, 4bv32);call write~init~$Pointer$(0bv32, 0bv32, ~#SSLv3_server_data~0.base, ~bvadd32(4bv32, ~#SSLv3_server_data~0.offset), 4bv32);call write~init~$Pointer$(0bv32, 0bv32, ~#SSLv3_server_data~0.base, ~bvadd32(8bv32, ~#SSLv3_server_data~0.offset), 4bv32);call write~init~$Pointer$(0bv32, 0bv32, ~#SSLv3_server_data~0.base, ~bvadd32(12bv32, ~#SSLv3_server_data~0.offset), 4bv32);call write~init~$Pointer$(0bv32, 0bv32, ~#SSLv3_server_data~0.base, ~bvadd32(16bv32, ~#SSLv3_server_data~0.offset), 4bv32);call write~init~$Pointer$(0bv32, 0bv32, ~#SSLv3_server_data~0.base, ~bvadd32(20bv32, ~#SSLv3_server_data~0.offset), 4bv32);call write~init~$Pointer$(0bv32, 0bv32, ~#SSLv3_server_data~0.base, ~bvadd32(24bv32, ~#SSLv3_server_data~0.offset), 4bv32);call write~init~$Pointer$(0bv32, 0bv32, ~#SSLv3_server_data~0.base, ~bvadd32(28bv32, ~#SSLv3_server_data~0.offset), 4bv32);call write~init~$Pointer$(0bv32, 0bv32, ~#SSLv3_server_data~0.base, ~bvadd32(32bv32, ~#SSLv3_server_data~0.offset), 4bv32);call write~init~$Pointer$(0bv32, 0bv32, ~#SSLv3_server_data~0.base, ~bvadd32(36bv32, ~#SSLv3_server_data~0.offset), 4bv32);call write~init~$Pointer$(0bv32, 0bv32, ~#SSLv3_server_data~0.base, ~bvadd32(40bv32, ~#SSLv3_server_data~0.offset), 4bv32);call write~init~$Pointer$(0bv32, 0bv32, ~#SSLv3_server_data~0.base, ~bvadd32(44bv32, ~#SSLv3_server_data~0.offset), 4bv32);call write~init~$Pointer$(0bv32, 0bv32, ~#SSLv3_server_data~0.base, ~bvadd32(48bv32, ~#SSLv3_server_data~0.offset), 4bv32);call write~init~$Pointer$(0bv32, 0bv32, ~#SSLv3_server_data~0.base, ~bvadd32(52bv32, ~#SSLv3_server_data~0.offset), 4bv32);call write~init~$Pointer$(0bv32, 0bv32, ~#SSLv3_server_data~0.base, ~bvadd32(56bv32, ~#SSLv3_server_data~0.offset), 4bv32);call write~init~$Pointer$(0bv32, 0bv32, ~#SSLv3_server_data~0.base, ~bvadd32(60bv32, ~#SSLv3_server_data~0.offset), 4bv32);call write~init~$Pointer$(0bv32, 0bv32, ~#SSLv3_server_data~0.base, ~bvadd32(64bv32, ~#SSLv3_server_data~0.offset), 4bv32);call write~init~$Pointer$(0bv32, 0bv32, ~#SSLv3_server_data~0.base, ~bvadd32(68bv32, ~#SSLv3_server_data~0.offset), 4bv32);call write~init~$Pointer$(0bv32, 0bv32, ~#SSLv3_server_data~0.base, ~bvadd32(72bv32, ~#SSLv3_server_data~0.offset), 4bv32);call write~init~$Pointer$(0bv32, 0bv32, ~#SSLv3_server_data~0.base, ~bvadd32(76bv32, ~#SSLv3_server_data~0.offset), 4bv32);call write~init~$Pointer$(0bv32, 0bv32, ~#SSLv3_server_data~0.base, ~bvadd32(80bv32, ~#SSLv3_server_data~0.offset), 4bv32);call write~init~$Pointer$(0bv32, 0bv32, ~#SSLv3_server_data~0.base, ~bvadd32(84bv32, ~#SSLv3_server_data~0.offset), 4bv32);call write~init~$Pointer$(0bv32, 0bv32, ~#SSLv3_server_data~0.base, ~bvadd32(88bv32, ~#SSLv3_server_data~0.offset), 4bv32);call write~init~$Pointer$(0bv32, 0bv32, ~#SSLv3_server_data~0.base, ~bvadd32(92bv32, ~#SSLv3_server_data~0.offset), 4bv32);call write~init~$Pointer$(0bv32, 0bv32, ~#SSLv3_server_data~0.base, ~bvadd32(96bv32, ~#SSLv3_server_data~0.offset), 4bv32); {2730#true} is VALID [2018-11-23 10:59:31,912 INFO L273 TraceCheckUtils]: 2: Hoare triple {2730#true} assume true; {2730#true} is VALID [2018-11-23 10:59:31,912 INFO L268 TraceCheckUtils]: 3: Hoare quadruple {2730#true} {2730#true} #631#return; {2730#true} is VALID [2018-11-23 10:59:31,913 INFO L256 TraceCheckUtils]: 4: Hoare triple {2730#true} call #t~ret138 := main(); {2730#true} is VALID [2018-11-23 10:59:31,916 INFO L273 TraceCheckUtils]: 5: Hoare triple {2730#true} havoc ~s~0.base, ~s~0.offset;havoc ~tmp~2;call #t~malloc3.base, #t~malloc3.offset := #Ultimate.alloc(248bv32);~s~0.base, ~s~0.offset := #t~malloc3.base, #t~malloc3.offset;call #t~malloc4.base, #t~malloc4.offset := #Ultimate.alloc(899bv32);call write~$Pointer$(#t~malloc4.base, #t~malloc4.offset, ~s~0.base, ~bvadd32(84bv32, ~s~0.offset), 4bv32);call #t~malloc5.base, #t~malloc5.offset := #Ultimate.alloc(232bv32);call write~$Pointer$(#t~malloc5.base, #t~malloc5.offset, ~s~0.base, ~bvadd32(204bv32, ~s~0.offset), 4bv32);call #t~malloc6.base, #t~malloc6.offset := #Ultimate.alloc(200bv32);call write~$Pointer$(#t~malloc6.base, #t~malloc6.offset, ~s~0.base, ~bvadd32(176bv32, ~s~0.offset), 4bv32); {2750#(= main_~s~0.offset (_ bv0 32))} is VALID [2018-11-23 10:59:31,917 INFO L256 TraceCheckUtils]: 6: Hoare triple {2750#(= main_~s~0.offset (_ bv0 32))} call #t~ret7 := ssl3_accept(~s~0.base, ~s~0.offset); {2754#(= (_ bv0 32) |ssl3_accept_#in~s.offset|)} is VALID [2018-11-23 10:59:31,921 INFO L273 TraceCheckUtils]: 7: Hoare triple {2754#(= (_ bv0 32) |ssl3_accept_#in~s.offset|)} ~s.base, ~s.offset := #in~s.base, #in~s.offset;havoc ~buf~0.base, ~buf~0.offset;havoc ~l~0;havoc ~Time~0;havoc ~tmp~3;havoc ~cb~0.base, ~cb~0.offset;havoc ~num1~0;havoc ~ret~0;havoc ~new_state~0;havoc ~state~0;havoc ~skip~0;havoc ~got_new_session~0;~tmp___1~0 := #t~nondet8;havoc #t~nondet8;~tmp___2~0 := #t~nondet9;havoc #t~nondet9;~tmp___3~0 := #t~nondet10;havoc #t~nondet10;~tmp___4~0 := #t~nondet11;havoc #t~nondet11;~tmp___5~0 := #t~nondet12;havoc #t~nondet12;~tmp___6~0 := #t~nondet13;havoc #t~nondet13;havoc ~tmp___7~0;~tmp___8~0 := #t~nondet14;havoc #t~nondet14;~tmp___9~0 := #t~nondet15;havoc #t~nondet15;~tmp___10~0 := #t~nondet16;havoc #t~nondet16;havoc ~blastFlag~0;call write~intINTTYPE4(8464bv32, ~s.base, ~bvadd32(52bv32, ~s.offset), 4bv32);~blastFlag~0 := 0bv32;call write~intINTTYPE4(#t~nondet17, ~s.base, ~bvadd32(92bv32, ~s.offset), 4bv32);havoc #t~nondet17;call write~intINTTYPE4(8464bv32, ~s.base, ~bvadd32(52bv32, ~s.offset), 4bv32);~tmp~3 := #t~nondet18;havoc #t~nondet18;~Time~0 := ~tmp~3;~cb~0.base, ~cb~0.offset := 0bv32, 0bv32;~ret~0 := 4294967295bv32;~skip~0 := 0bv32;~got_new_session~0 := 0bv32;call #t~mem19.base, #t~mem19.offset := read~$Pointer$(~s.base, ~bvadd32(192bv32, ~s.offset), 4bv32); {2758#(and (= ssl3_accept_~s.offset (_ bv0 32)) (= (_ bv8464 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32)))))} is VALID [2018-11-23 10:59:31,923 INFO L273 TraceCheckUtils]: 8: Hoare triple {2758#(and (= ssl3_accept_~s.offset (_ bv0 32)) (= (_ bv8464 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32)))))} assume 0bv32 != ~bvadd32(#t~mem19.base, #t~mem19.offset);havoc #t~mem19.base, #t~mem19.offset;call #t~mem20.base, #t~mem20.offset := read~$Pointer$(~s.base, ~bvadd32(192bv32, ~s.offset), 4bv32);~cb~0.base, ~cb~0.offset := #t~mem20.base, #t~mem20.offset;havoc #t~mem20.base, #t~mem20.offset; {2758#(and (= ssl3_accept_~s.offset (_ bv0 32)) (= (_ bv8464 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32)))))} is VALID [2018-11-23 10:59:31,929 INFO L273 TraceCheckUtils]: 9: Hoare triple {2758#(and (= ssl3_accept_~s.offset (_ bv0 32)) (= (_ bv8464 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32)))))} call #t~mem21 := read~intINTTYPE4(~s.base, ~bvadd32(28bv32, ~s.offset), 4bv32);call write~intINTTYPE4(~bvadd32(1bv32, #t~mem21), ~s.base, ~bvadd32(28bv32, ~s.offset), 4bv32);havoc #t~mem21; {2758#(and (= ssl3_accept_~s.offset (_ bv0 32)) (= (_ bv8464 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32)))))} is VALID [2018-11-23 10:59:31,930 INFO L273 TraceCheckUtils]: 10: Hoare triple {2758#(and (= ssl3_accept_~s.offset (_ bv0 32)) (= (_ bv8464 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32)))))} assume !(0bv32 != ~bvand32(12288bv32, ~tmp___1~0)); {2758#(and (= ssl3_accept_~s.offset (_ bv0 32)) (= (_ bv8464 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32)))))} is VALID [2018-11-23 10:59:31,931 INFO L273 TraceCheckUtils]: 11: Hoare triple {2758#(and (= ssl3_accept_~s.offset (_ bv0 32)) (= (_ bv8464 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32)))))} call #t~mem22.base, #t~mem22.offset := read~$Pointer$(~s.base, ~bvadd32(136bv32, ~s.offset), 4bv32); {2758#(and (= ssl3_accept_~s.offset (_ bv0 32)) (= (_ bv8464 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32)))))} is VALID [2018-11-23 10:59:31,931 INFO L273 TraceCheckUtils]: 12: Hoare triple {2758#(and (= ssl3_accept_~s.offset (_ bv0 32)) (= (_ bv8464 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32)))))} assume !(0bv32 == ~bvadd32(#t~mem22.base, #t~mem22.offset));havoc #t~mem22.base, #t~mem22.offset; {2758#(and (= ssl3_accept_~s.offset (_ bv0 32)) (= (_ bv8464 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32)))))} is VALID [2018-11-23 10:59:31,932 INFO L273 TraceCheckUtils]: 13: Hoare triple {2758#(and (= ssl3_accept_~s.offset (_ bv0 32)) (= (_ bv8464 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32)))))} assume !false; {2758#(and (= ssl3_accept_~s.offset (_ bv0 32)) (= (_ bv8464 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32)))))} is VALID [2018-11-23 10:59:31,932 INFO L273 TraceCheckUtils]: 14: Hoare triple {2758#(and (= ssl3_accept_~s.offset (_ bv0 32)) (= (_ bv8464 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32)))))} call #t~mem23 := read~intINTTYPE4(~s.base, ~bvadd32(52bv32, ~s.offset), 4bv32);~state~0 := #t~mem23;havoc #t~mem23;call #t~mem24 := read~intINTTYPE4(~s.base, ~bvadd32(52bv32, ~s.offset), 4bv32); {2758#(and (= ssl3_accept_~s.offset (_ bv0 32)) (= (_ bv8464 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32)))))} is VALID [2018-11-23 10:59:31,933 INFO L273 TraceCheckUtils]: 15: Hoare triple {2758#(and (= ssl3_accept_~s.offset (_ bv0 32)) (= (_ bv8464 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32)))))} assume !(12292bv32 == #t~mem24);havoc #t~mem24;call #t~mem25 := read~intINTTYPE4(~s.base, ~bvadd32(52bv32, ~s.offset), 4bv32); {2758#(and (= ssl3_accept_~s.offset (_ bv0 32)) (= (_ bv8464 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32)))))} is VALID [2018-11-23 10:59:31,934 INFO L273 TraceCheckUtils]: 16: Hoare triple {2758#(and (= ssl3_accept_~s.offset (_ bv0 32)) (= (_ bv8464 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32)))))} assume !(16384bv32 == #t~mem25);havoc #t~mem25;call #t~mem26 := read~intINTTYPE4(~s.base, ~bvadd32(52bv32, ~s.offset), 4bv32); {2758#(and (= ssl3_accept_~s.offset (_ bv0 32)) (= (_ bv8464 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32)))))} is VALID [2018-11-23 10:59:31,936 INFO L273 TraceCheckUtils]: 17: Hoare triple {2758#(and (= ssl3_accept_~s.offset (_ bv0 32)) (= (_ bv8464 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32)))))} assume !(8192bv32 == #t~mem26);havoc #t~mem26;call #t~mem27 := read~intINTTYPE4(~s.base, ~bvadd32(52bv32, ~s.offset), 4bv32); {2758#(and (= ssl3_accept_~s.offset (_ bv0 32)) (= (_ bv8464 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32)))))} is VALID [2018-11-23 10:59:31,937 INFO L273 TraceCheckUtils]: 18: Hoare triple {2758#(and (= ssl3_accept_~s.offset (_ bv0 32)) (= (_ bv8464 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32)))))} assume !(24576bv32 == #t~mem27);havoc #t~mem27;call #t~mem28 := read~intINTTYPE4(~s.base, ~bvadd32(52bv32, ~s.offset), 4bv32); {2758#(and (= ssl3_accept_~s.offset (_ bv0 32)) (= (_ bv8464 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32)))))} is VALID [2018-11-23 10:59:31,938 INFO L273 TraceCheckUtils]: 19: Hoare triple {2758#(and (= ssl3_accept_~s.offset (_ bv0 32)) (= (_ bv8464 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32)))))} assume !(8195bv32 == #t~mem28);havoc #t~mem28;call #t~mem29 := read~intINTTYPE4(~s.base, ~bvadd32(52bv32, ~s.offset), 4bv32); {2795#(= (bvadd |ssl3_accept_#t~mem29| (_ bv4294958832 32)) (_ bv0 32))} is VALID [2018-11-23 10:59:31,939 INFO L273 TraceCheckUtils]: 20: Hoare triple {2795#(= (bvadd |ssl3_accept_#t~mem29| (_ bv4294958832 32)) (_ bv0 32))} assume 8480bv32 == #t~mem29;havoc #t~mem29; {2731#false} is VALID [2018-11-23 10:59:31,939 INFO L273 TraceCheckUtils]: 21: Hoare triple {2731#false} call write~intINTTYPE4(0bv32, ~s.base, ~bvadd32(48bv32, ~s.offset), 4bv32);~ret~0 := #t~nondet67;havoc #t~nondet67; {2731#false} is VALID [2018-11-23 10:59:31,940 INFO L273 TraceCheckUtils]: 22: Hoare triple {2731#false} assume !~bvsle32(~ret~0, 0bv32);call #t~mem68.base, #t~mem68.offset := read~$Pointer$(~s.base, ~bvadd32(84bv32, ~s.offset), 4bv32);call write~intINTTYPE4(8482bv32, #t~mem68.base, ~bvadd32(844bv32, #t~mem68.offset), 4bv32);havoc #t~mem68.base, #t~mem68.offset;call write~intINTTYPE4(8448bv32, ~s.base, ~bvadd32(52bv32, ~s.offset), 4bv32);call write~intINTTYPE4(0bv32, ~s.base, ~bvadd32(64bv32, ~s.offset), 4bv32); {2731#false} is VALID [2018-11-23 10:59:31,940 INFO L273 TraceCheckUtils]: 23: Hoare triple {2731#false} call #t~mem127.base, #t~mem127.offset := read~$Pointer$(~s.base, ~bvadd32(84bv32, ~s.offset), 4bv32);call #t~mem128 := read~intINTTYPE4(#t~mem127.base, ~bvadd32(848bv32, #t~mem127.offset), 4bv32); {2731#false} is VALID [2018-11-23 10:59:31,941 INFO L273 TraceCheckUtils]: 24: Hoare triple {2731#false} assume !(0bv32 == #t~mem128);havoc #t~mem127.base, #t~mem127.offset;havoc #t~mem128; {2731#false} is VALID [2018-11-23 10:59:31,941 INFO L273 TraceCheckUtils]: 25: Hoare triple {2731#false} ~skip~0 := 0bv32; {2731#false} is VALID [2018-11-23 10:59:31,942 INFO L273 TraceCheckUtils]: 26: Hoare triple {2731#false} assume !false; {2731#false} is VALID [2018-11-23 10:59:31,942 INFO L273 TraceCheckUtils]: 27: Hoare triple {2731#false} call #t~mem23 := read~intINTTYPE4(~s.base, ~bvadd32(52bv32, ~s.offset), 4bv32);~state~0 := #t~mem23;havoc #t~mem23;call #t~mem24 := read~intINTTYPE4(~s.base, ~bvadd32(52bv32, ~s.offset), 4bv32); {2731#false} is VALID [2018-11-23 10:59:31,942 INFO L273 TraceCheckUtils]: 28: Hoare triple {2731#false} assume !(12292bv32 == #t~mem24);havoc #t~mem24;call #t~mem25 := read~intINTTYPE4(~s.base, ~bvadd32(52bv32, ~s.offset), 4bv32); {2731#false} is VALID [2018-11-23 10:59:31,942 INFO L273 TraceCheckUtils]: 29: Hoare triple {2731#false} assume !(16384bv32 == #t~mem25);havoc #t~mem25;call #t~mem26 := read~intINTTYPE4(~s.base, ~bvadd32(52bv32, ~s.offset), 4bv32); {2731#false} is VALID [2018-11-23 10:59:31,943 INFO L273 TraceCheckUtils]: 30: Hoare triple {2731#false} assume !(8192bv32 == #t~mem26);havoc #t~mem26;call #t~mem27 := read~intINTTYPE4(~s.base, ~bvadd32(52bv32, ~s.offset), 4bv32); {2731#false} is VALID [2018-11-23 10:59:31,943 INFO L273 TraceCheckUtils]: 31: Hoare triple {2731#false} assume !(24576bv32 == #t~mem27);havoc #t~mem27;call #t~mem28 := read~intINTTYPE4(~s.base, ~bvadd32(52bv32, ~s.offset), 4bv32); {2731#false} is VALID [2018-11-23 10:59:31,943 INFO L273 TraceCheckUtils]: 32: Hoare triple {2731#false} assume !(8195bv32 == #t~mem28);havoc #t~mem28;call #t~mem29 := read~intINTTYPE4(~s.base, ~bvadd32(52bv32, ~s.offset), 4bv32); {2731#false} is VALID [2018-11-23 10:59:31,944 INFO L273 TraceCheckUtils]: 33: Hoare triple {2731#false} assume !(8480bv32 == #t~mem29);havoc #t~mem29;call #t~mem30 := read~intINTTYPE4(~s.base, ~bvadd32(52bv32, ~s.offset), 4bv32); {2731#false} is VALID [2018-11-23 10:59:31,944 INFO L273 TraceCheckUtils]: 34: Hoare triple {2731#false} assume !(8481bv32 == #t~mem30);havoc #t~mem30;call #t~mem31 := read~intINTTYPE4(~s.base, ~bvadd32(52bv32, ~s.offset), 4bv32); {2731#false} is VALID [2018-11-23 10:59:31,944 INFO L273 TraceCheckUtils]: 35: Hoare triple {2731#false} assume !(8482bv32 == #t~mem31);havoc #t~mem31;call #t~mem32 := read~intINTTYPE4(~s.base, ~bvadd32(52bv32, ~s.offset), 4bv32); {2731#false} is VALID [2018-11-23 10:59:31,944 INFO L273 TraceCheckUtils]: 36: Hoare triple {2731#false} assume !(8464bv32 == #t~mem32);havoc #t~mem32;call #t~mem33 := read~intINTTYPE4(~s.base, ~bvadd32(52bv32, ~s.offset), 4bv32); {2731#false} is VALID [2018-11-23 10:59:31,945 INFO L273 TraceCheckUtils]: 37: Hoare triple {2731#false} assume !(8465bv32 == #t~mem33);havoc #t~mem33;call #t~mem34 := read~intINTTYPE4(~s.base, ~bvadd32(52bv32, ~s.offset), 4bv32); {2731#false} is VALID [2018-11-23 10:59:31,945 INFO L273 TraceCheckUtils]: 38: Hoare triple {2731#false} assume !(8466bv32 == #t~mem34);havoc #t~mem34;call #t~mem35 := read~intINTTYPE4(~s.base, ~bvadd32(52bv32, ~s.offset), 4bv32); {2731#false} is VALID [2018-11-23 10:59:31,945 INFO L273 TraceCheckUtils]: 39: Hoare triple {2731#false} assume !(8496bv32 == #t~mem35);havoc #t~mem35;call #t~mem36 := read~intINTTYPE4(~s.base, ~bvadd32(52bv32, ~s.offset), 4bv32); {2731#false} is VALID [2018-11-23 10:59:31,946 INFO L273 TraceCheckUtils]: 40: Hoare triple {2731#false} assume !(8497bv32 == #t~mem36);havoc #t~mem36;call #t~mem37 := read~intINTTYPE4(~s.base, ~bvadd32(52bv32, ~s.offset), 4bv32); {2731#false} is VALID [2018-11-23 10:59:31,946 INFO L273 TraceCheckUtils]: 41: Hoare triple {2731#false} assume !(8512bv32 == #t~mem37);havoc #t~mem37;call #t~mem38 := read~intINTTYPE4(~s.base, ~bvadd32(52bv32, ~s.offset), 4bv32); {2731#false} is VALID [2018-11-23 10:59:31,946 INFO L273 TraceCheckUtils]: 42: Hoare triple {2731#false} assume !(8513bv32 == #t~mem38);havoc #t~mem38;call #t~mem39 := read~intINTTYPE4(~s.base, ~bvadd32(52bv32, ~s.offset), 4bv32); {2731#false} is VALID [2018-11-23 10:59:31,946 INFO L273 TraceCheckUtils]: 43: Hoare triple {2731#false} assume !(8528bv32 == #t~mem39);havoc #t~mem39;call #t~mem40 := read~intINTTYPE4(~s.base, ~bvadd32(52bv32, ~s.offset), 4bv32); {2731#false} is VALID [2018-11-23 10:59:31,947 INFO L273 TraceCheckUtils]: 44: Hoare triple {2731#false} assume !(8529bv32 == #t~mem40);havoc #t~mem40;call #t~mem41 := read~intINTTYPE4(~s.base, ~bvadd32(52bv32, ~s.offset), 4bv32); {2731#false} is VALID [2018-11-23 10:59:31,947 INFO L273 TraceCheckUtils]: 45: Hoare triple {2731#false} assume !(8544bv32 == #t~mem41);havoc #t~mem41;call #t~mem42 := read~intINTTYPE4(~s.base, ~bvadd32(52bv32, ~s.offset), 4bv32); {2731#false} is VALID [2018-11-23 10:59:31,947 INFO L273 TraceCheckUtils]: 46: Hoare triple {2731#false} assume !(8545bv32 == #t~mem42);havoc #t~mem42;call #t~mem43 := read~intINTTYPE4(~s.base, ~bvadd32(52bv32, ~s.offset), 4bv32); {2731#false} is VALID [2018-11-23 10:59:31,947 INFO L273 TraceCheckUtils]: 47: Hoare triple {2731#false} assume !(8560bv32 == #t~mem43);havoc #t~mem43;call #t~mem44 := read~intINTTYPE4(~s.base, ~bvadd32(52bv32, ~s.offset), 4bv32); {2731#false} is VALID [2018-11-23 10:59:31,948 INFO L273 TraceCheckUtils]: 48: Hoare triple {2731#false} assume !(8561bv32 == #t~mem44);havoc #t~mem44;call #t~mem45 := read~intINTTYPE4(~s.base, ~bvadd32(52bv32, ~s.offset), 4bv32); {2731#false} is VALID [2018-11-23 10:59:31,948 INFO L273 TraceCheckUtils]: 49: Hoare triple {2731#false} assume !(8448bv32 == #t~mem45);havoc #t~mem45;call #t~mem46 := read~intINTTYPE4(~s.base, ~bvadd32(52bv32, ~s.offset), 4bv32); {2731#false} is VALID [2018-11-23 10:59:31,948 INFO L273 TraceCheckUtils]: 50: Hoare triple {2731#false} assume !(8576bv32 == #t~mem46);havoc #t~mem46;call #t~mem47 := read~intINTTYPE4(~s.base, ~bvadd32(52bv32, ~s.offset), 4bv32); {2731#false} is VALID [2018-11-23 10:59:31,948 INFO L273 TraceCheckUtils]: 51: Hoare triple {2731#false} assume !(8577bv32 == #t~mem47);havoc #t~mem47;call #t~mem48 := read~intINTTYPE4(~s.base, ~bvadd32(52bv32, ~s.offset), 4bv32); {2731#false} is VALID [2018-11-23 10:59:31,949 INFO L273 TraceCheckUtils]: 52: Hoare triple {2731#false} assume !(8592bv32 == #t~mem48);havoc #t~mem48;call #t~mem49 := read~intINTTYPE4(~s.base, ~bvadd32(52bv32, ~s.offset), 4bv32); {2731#false} is VALID [2018-11-23 10:59:31,949 INFO L273 TraceCheckUtils]: 53: Hoare triple {2731#false} assume !(8593bv32 == #t~mem49);havoc #t~mem49;call #t~mem50 := read~intINTTYPE4(~s.base, ~bvadd32(52bv32, ~s.offset), 4bv32); {2731#false} is VALID [2018-11-23 10:59:31,949 INFO L273 TraceCheckUtils]: 54: Hoare triple {2731#false} assume !(8608bv32 == #t~mem50);havoc #t~mem50;call #t~mem51 := read~intINTTYPE4(~s.base, ~bvadd32(52bv32, ~s.offset), 4bv32); {2731#false} is VALID [2018-11-23 10:59:31,950 INFO L273 TraceCheckUtils]: 55: Hoare triple {2731#false} assume !(8609bv32 == #t~mem51);havoc #t~mem51;call #t~mem52 := read~intINTTYPE4(~s.base, ~bvadd32(52bv32, ~s.offset), 4bv32); {2731#false} is VALID [2018-11-23 10:59:31,950 INFO L273 TraceCheckUtils]: 56: Hoare triple {2731#false} assume 8640bv32 == #t~mem52;havoc #t~mem52; {2731#false} is VALID [2018-11-23 10:59:31,950 INFO L273 TraceCheckUtils]: 57: Hoare triple {2731#false} ~ret~0 := #t~nondet115;havoc #t~nondet115; {2731#false} is VALID [2018-11-23 10:59:31,950 INFO L273 TraceCheckUtils]: 58: Hoare triple {2731#false} assume !(4bv32 == ~blastFlag~0); {2731#false} is VALID [2018-11-23 10:59:31,951 INFO L273 TraceCheckUtils]: 59: Hoare triple {2731#false} assume !(7bv32 == ~blastFlag~0); {2731#false} is VALID [2018-11-23 10:59:31,951 INFO L273 TraceCheckUtils]: 60: Hoare triple {2731#false} assume !false; {2731#false} is VALID [2018-11-23 10:59:31,959 INFO L134 CoverageAnalysis]: Checked inductivity of 8 backedges. 8 proven. 0 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2018-11-23 10:59:31,960 INFO L312 TraceCheckSpWp]: Omiting computation of backward sequence because forward sequence was already perfect [2018-11-23 10:59:31,964 INFO L312 seRefinementStrategy]: Constructing automaton from 1 perfect and 0 imperfect interpolant sequences. [2018-11-23 10:59:31,964 INFO L327 seRefinementStrategy]: Number of different interpolants: perfect sequences [6] imperfect sequences [] total 6 [2018-11-23 10:59:31,965 INFO L78 Accepts]: Start accepts. Automaton has 6 states. Word has length 61 [2018-11-23 10:59:31,965 INFO L84 Accepts]: Finished accepts. word is accepted. [2018-11-23 10:59:31,965 INFO L86 InductivityCheck]: Starting indutivity check of a Floyd-Hoare automaton with 6 states. [2018-11-23 10:59:32,099 INFO L119 InductivityCheck]: Floyd-Hoare automaton has 61 edges. 61 inductive. 0 not inductive. 0 times theorem prover too weak to decide inductivity. [2018-11-23 10:59:32,099 INFO L459 AbstractCegarLoop]: Interpolant automaton has 6 states [2018-11-23 10:59:32,100 INFO L142 InterpolantAutomaton]: Constructing interpolant automaton starting with 6 interpolants. [2018-11-23 10:59:32,100 INFO L144 InterpolantAutomaton]: CoverageRelationStatistics Valid=9, Invalid=21, Unknown=0, NotChecked=0, Total=30 [2018-11-23 10:59:32,100 INFO L87 Difference]: Start difference. First operand 173 states and 273 transitions. Second operand 6 states. [2018-11-23 10:59:50,116 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2018-11-23 10:59:50,116 INFO L93 Difference]: Finished difference Result 358 states and 548 transitions. [2018-11-23 10:59:50,117 INFO L142 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 6 states. [2018-11-23 10:59:50,117 INFO L78 Accepts]: Start accepts. Automaton has 6 states. Word has length 61 [2018-11-23 10:59:50,117 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2018-11-23 10:59:50,117 INFO L82 GeneralOperation]: Start removeUnreachable. Operand 6 states. [2018-11-23 10:59:50,123 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 6 states to 6 states and 548 transitions. [2018-11-23 10:59:50,123 INFO L82 GeneralOperation]: Start removeUnreachable. Operand 6 states. [2018-11-23 10:59:50,129 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 6 states to 6 states and 548 transitions. [2018-11-23 10:59:50,129 INFO L86 InductivityCheck]: Starting indutivity check of a Floyd-Hoare automaton with 6 states and 548 transitions. [2018-11-23 10:59:51,023 INFO L119 InductivityCheck]: Floyd-Hoare automaton has 548 edges. 548 inductive. 0 not inductive. 0 times theorem prover too weak to decide inductivity. [2018-11-23 10:59:51,035 INFO L225 Difference]: With dead ends: 358 [2018-11-23 10:59:51,035 INFO L226 Difference]: Without dead ends: 231 [2018-11-23 10:59:51,036 INFO L631 BasicCegarLoop]: 0 DeclaredPredicates, 62 GetRequests, 56 SyntacticMatches, 0 SemanticMatches, 6 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 0 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=19, Invalid=37, Unknown=0, NotChecked=0, Total=56 [2018-11-23 10:59:51,037 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 231 states. [2018-11-23 10:59:51,147 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 231 to 173. [2018-11-23 10:59:51,147 INFO L214 AbstractMinimizeNwa]: Start testing correctness of minimizeSevpa [2018-11-23 10:59:51,147 INFO L82 GeneralOperation]: Start isEquivalent. First operand 231 states. Second operand 173 states. [2018-11-23 10:59:51,148 INFO L74 IsIncluded]: Start isIncluded. First operand 231 states. Second operand 173 states. [2018-11-23 10:59:51,148 INFO L87 Difference]: Start difference. First operand 231 states. Second operand 173 states. [2018-11-23 10:59:51,158 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2018-11-23 10:59:51,158 INFO L93 Difference]: Finished difference Result 231 states and 351 transitions. [2018-11-23 10:59:51,158 INFO L276 IsEmpty]: Start isEmpty. Operand 231 states and 351 transitions. [2018-11-23 10:59:51,159 INFO L282 IsEmpty]: Finished isEmpty. No accepting run. [2018-11-23 10:59:51,159 INFO L83 IsIncluded]: Finished isIncluded. Language is included [2018-11-23 10:59:51,159 INFO L74 IsIncluded]: Start isIncluded. First operand 173 states. Second operand 231 states. [2018-11-23 10:59:51,159 INFO L87 Difference]: Start difference. First operand 173 states. Second operand 231 states. [2018-11-23 10:59:51,167 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2018-11-23 10:59:51,167 INFO L93 Difference]: Finished difference Result 231 states and 351 transitions. [2018-11-23 10:59:51,167 INFO L276 IsEmpty]: Start isEmpty. Operand 231 states and 351 transitions. [2018-11-23 10:59:51,168 INFO L282 IsEmpty]: Finished isEmpty. No accepting run. [2018-11-23 10:59:51,168 INFO L83 IsIncluded]: Finished isIncluded. Language is included [2018-11-23 10:59:51,168 INFO L88 GeneralOperation]: Finished isEquivalent. [2018-11-23 10:59:51,169 INFO L221 AbstractMinimizeNwa]: Finished testing correctness of minimizeSevpa [2018-11-23 10:59:51,169 INFO L82 GeneralOperation]: Start removeUnreachable. Operand 173 states. [2018-11-23 10:59:51,174 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 173 states to 173 states and 272 transitions. [2018-11-23 10:59:51,174 INFO L78 Accepts]: Start accepts. Automaton has 173 states and 272 transitions. Word has length 61 [2018-11-23 10:59:51,174 INFO L84 Accepts]: Finished accepts. word is rejected. [2018-11-23 10:59:51,174 INFO L480 AbstractCegarLoop]: Abstraction has 173 states and 272 transitions. [2018-11-23 10:59:51,174 INFO L481 AbstractCegarLoop]: Interpolant automaton has 6 states. [2018-11-23 10:59:51,174 INFO L276 IsEmpty]: Start isEmpty. Operand 173 states and 272 transitions. [2018-11-23 10:59:51,175 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 63 [2018-11-23 10:59:51,175 INFO L394 BasicCegarLoop]: Found error trace [2018-11-23 10:59:51,176 INFO L402 BasicCegarLoop]: trace histogram [2, 2, 2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2018-11-23 10:59:51,176 INFO L423 AbstractCegarLoop]: === Iteration 4 === [ssl3_acceptErr0ASSERT_VIOLATIONERROR_FUNCTION]=== [2018-11-23 10:59:51,176 INFO L141 PredicateUnifier]: Initialized classic predicate unifier [2018-11-23 10:59:51,176 INFO L82 PathProgramCache]: Analyzing trace with hash 1890092254, now seen corresponding path program 1 times [2018-11-23 10:59:51,177 INFO L223 ckRefinementStrategy]: Switched to mode CVC4_FPBP [2018-11-23 10:59:51,177 INFO L69 tionRefinementEngine]: Using refinement strategy WolfRefinementStrategy No working directory specified, using /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/cvc4nyu Starting monitored process 5 with cvc4nyu --tear-down-incremental --print-success --lang smt --rewrite-divk (exit command is (exit), workingDir is null) Waiting until toolchain timeout for monitored process 5 with cvc4nyu --tear-down-incremental --print-success --lang smt --rewrite-divk [2018-11-23 10:59:51,193 INFO L103 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2018-11-23 10:59:51,372 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2018-11-23 10:59:51,458 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2018-11-23 10:59:51,461 INFO L273 TraceCheckSpWp]: Computing forward predicates... [2018-11-23 10:59:51,567 INFO L478 Elim1Store]: Elim1 did not use preprocessing eliminated variable of array dimension 2, 0 stores, 1 select indices, 1 select index equivalence classes, 0 disjoint index pairs (out of 0 index pairs), introduced 1 new quantified variables, introduced 0 case distinctions, treesize of input 109 treesize of output 97 [2018-11-23 10:59:51,579 INFO L478 Elim1Store]: Elim1 did not use preprocessing eliminated variable of array dimension 1, 0 stores, 1 select indices, 1 select index equivalence classes, 0 disjoint index pairs (out of 0 index pairs), introduced 1 new quantified variables, introduced 0 case distinctions, treesize of input 97 treesize of output 73 [2018-11-23 10:59:51,582 INFO L267 ElimStorePlain]: Start of recursive call 3: 1 dim-0 vars, End of recursive call: 1 dim-0 vars, and 1 xjuncts. [2018-11-23 10:59:51,597 INFO L267 ElimStorePlain]: Start of recursive call 2: 1 dim-1 vars, End of recursive call: 1 dim-0 vars, and 1 xjuncts. [2018-11-23 10:59:51,623 INFO L701 Elim1Store]: detected not equals via solver [2018-11-23 10:59:51,625 INFO L478 Elim1Store]: Elim1 did not use preprocessing eliminated variable of array dimension 2, 1 stores, 1 select indices, 1 select index equivalence classes, 1 disjoint index pairs (out of 0 index pairs), introduced 2 new quantified variables, introduced 0 case distinctions, treesize of input 73 treesize of output 68 [2018-11-23 10:59:51,639 INFO L701 Elim1Store]: detected not equals via solver [2018-11-23 10:59:51,641 INFO L478 Elim1Store]: Elim1 did not use preprocessing eliminated variable of array dimension 1, 1 stores, 1 select indices, 1 select index equivalence classes, 1 disjoint index pairs (out of 0 index pairs), introduced 1 new quantified variables, introduced 0 case distinctions, treesize of input 55 treesize of output 24 [2018-11-23 10:59:51,660 INFO L267 ElimStorePlain]: Start of recursive call 5: End of recursive call: and 1 xjuncts. [2018-11-23 10:59:51,673 INFO L478 Elim1Store]: Elim1 did not use preprocessing eliminated variable of array dimension 2, 1 stores, 1 select indices, 1 select index equivalence classes, 0 disjoint index pairs (out of 0 index pairs), introduced 1 new quantified variables, introduced 0 case distinctions, treesize of input 13 treesize of output 10 [2018-11-23 10:59:51,685 INFO L478 Elim1Store]: Elim1 did not use preprocessing eliminated variable of array dimension 1, 1 stores, 0 select indices, 0 select index equivalence classes, 0 disjoint index pairs (out of 0 index pairs), introduced 0 new quantified variables, introduced 0 case distinctions, treesize of input 10 treesize of output 9 [2018-11-23 10:59:51,686 INFO L267 ElimStorePlain]: Start of recursive call 7: End of recursive call: and 1 xjuncts. [2018-11-23 10:59:51,690 INFO L267 ElimStorePlain]: Start of recursive call 6: 1 dim-1 vars, End of recursive call: and 1 xjuncts. [2018-11-23 10:59:51,694 INFO L267 ElimStorePlain]: Start of recursive call 4: 1 dim-1 vars, 1 dim-2 vars, End of recursive call: and 1 xjuncts. [2018-11-23 10:59:51,705 INFO L267 ElimStorePlain]: Start of recursive call 1: 3 dim-2 vars, End of recursive call: and 1 xjuncts. [2018-11-23 10:59:51,706 INFO L202 ElimStorePlain]: Needed 7 recursive calls to eliminate 3 variables, input treesize:109, output treesize:9 [2018-11-23 10:59:54,151 WARN L383 uantifierElimination]: Trying to double check SDD result, but SMT solver's response was UNKNOWN. [2018-11-23 10:59:54,151 WARN L384 uantifierElimination]: Input elimination task: ∃ [|v_#memory_$Pointer$.base_162|, |v_#memory_int_187|, |v_#memory_$Pointer$.offset_162|]. (= (let ((.cse0 (let ((.cse4 (bvadd ssl3_accept_~s.offset (_ bv204 32)))) (let ((.cse1 (select (select |v_#memory_$Pointer$.base_162| ssl3_accept_~s.base) .cse4))) (store |v_#memory_int_187| .cse1 (let ((.cse2 (select |v_#memory_int_187| .cse1)) (.cse3 (bvadd (select (select |v_#memory_$Pointer$.offset_162| ssl3_accept_~s.base) .cse4) (_ bv76 32)))) (store .cse2 .cse3 (bvadd (select .cse2 .cse3) (_ bv1 32))))))))) (store .cse0 ssl3_accept_~s.base (store (select .cse0 ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32)) (_ bv8480 32)))) |#memory_int|) [2018-11-23 10:59:54,151 WARN L385 uantifierElimination]: ElimStorePlain result: ∃ []. (= (_ bv8480 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32)))) [2018-11-23 10:59:54,274 INFO L478 Elim1Store]: Elim1 did not use preprocessing eliminated variable of array dimension 2, 0 stores, 1 select indices, 1 select index equivalence classes, 0 disjoint index pairs (out of 0 index pairs), introduced 1 new quantified variables, introduced 0 case distinctions, treesize of input 19 treesize of output 15 [2018-11-23 10:59:54,280 INFO L478 Elim1Store]: Elim1 did not use preprocessing eliminated variable of array dimension 1, 0 stores, 1 select indices, 1 select index equivalence classes, 0 disjoint index pairs (out of 0 index pairs), introduced 0 new quantified variables, introduced 0 case distinctions, treesize of input 15 treesize of output 3 [2018-11-23 10:59:54,281 INFO L267 ElimStorePlain]: Start of recursive call 3: End of recursive call: and 1 xjuncts. [2018-11-23 10:59:54,286 INFO L267 ElimStorePlain]: Start of recursive call 2: 1 dim-1 vars, End of recursive call: and 1 xjuncts. [2018-11-23 10:59:54,288 INFO L267 ElimStorePlain]: Start of recursive call 1: 2 dim-0 vars, 1 dim-2 vars, End of recursive call: and 1 xjuncts. [2018-11-23 10:59:54,288 INFO L202 ElimStorePlain]: Needed 3 recursive calls to eliminate 3 variables, input treesize:19, output treesize:3 [2018-11-23 10:59:54,295 WARN L383 uantifierElimination]: Trying to double check SDD result, but SMT solver's response was UNKNOWN. [2018-11-23 10:59:54,295 WARN L384 uantifierElimination]: Input elimination task: ∃ [|#memory_int|, ssl3_accept_~s.base, ssl3_accept_~s.offset]. (let ((.cse0 (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32))))) (and (= (_ bv8480 32) .cse0) (= |ssl3_accept_#t~mem52| .cse0))) [2018-11-23 10:59:54,296 WARN L385 uantifierElimination]: ElimStorePlain result: ∃ []. (= |ssl3_accept_#t~mem52| (_ bv8480 32)) [2018-11-23 10:59:54,307 INFO L256 TraceCheckUtils]: 0: Hoare triple {4016#true} call ULTIMATE.init(); {4016#true} is VALID [2018-11-23 10:59:54,307 INFO L273 TraceCheckUtils]: 1: Hoare triple {4016#true} #NULL.base, #NULL.offset := 0bv32, 0bv32;#valid := #valid[0bv32 := 0bv1];~init~0 := 1bv32;call ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset := #Ultimate.alloc(100bv32);call write~init~intINTTYPE4(0bv32, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset, 4bv32);call write~init~$Pointer$(0bv32, 0bv32, ~#SSLv3_server_data~0.base, ~bvadd32(4bv32, ~#SSLv3_server_data~0.offset), 4bv32);call write~init~$Pointer$(0bv32, 0bv32, ~#SSLv3_server_data~0.base, ~bvadd32(8bv32, ~#SSLv3_server_data~0.offset), 4bv32);call write~init~$Pointer$(0bv32, 0bv32, ~#SSLv3_server_data~0.base, ~bvadd32(12bv32, ~#SSLv3_server_data~0.offset), 4bv32);call write~init~$Pointer$(0bv32, 0bv32, ~#SSLv3_server_data~0.base, ~bvadd32(16bv32, ~#SSLv3_server_data~0.offset), 4bv32);call write~init~$Pointer$(0bv32, 0bv32, ~#SSLv3_server_data~0.base, ~bvadd32(20bv32, ~#SSLv3_server_data~0.offset), 4bv32);call write~init~$Pointer$(0bv32, 0bv32, ~#SSLv3_server_data~0.base, ~bvadd32(24bv32, ~#SSLv3_server_data~0.offset), 4bv32);call write~init~$Pointer$(0bv32, 0bv32, ~#SSLv3_server_data~0.base, ~bvadd32(28bv32, ~#SSLv3_server_data~0.offset), 4bv32);call write~init~$Pointer$(0bv32, 0bv32, ~#SSLv3_server_data~0.base, ~bvadd32(32bv32, ~#SSLv3_server_data~0.offset), 4bv32);call write~init~$Pointer$(0bv32, 0bv32, ~#SSLv3_server_data~0.base, ~bvadd32(36bv32, ~#SSLv3_server_data~0.offset), 4bv32);call write~init~$Pointer$(0bv32, 0bv32, ~#SSLv3_server_data~0.base, ~bvadd32(40bv32, ~#SSLv3_server_data~0.offset), 4bv32);call write~init~$Pointer$(0bv32, 0bv32, ~#SSLv3_server_data~0.base, ~bvadd32(44bv32, ~#SSLv3_server_data~0.offset), 4bv32);call write~init~$Pointer$(0bv32, 0bv32, ~#SSLv3_server_data~0.base, ~bvadd32(48bv32, ~#SSLv3_server_data~0.offset), 4bv32);call write~init~$Pointer$(0bv32, 0bv32, ~#SSLv3_server_data~0.base, ~bvadd32(52bv32, ~#SSLv3_server_data~0.offset), 4bv32);call write~init~$Pointer$(0bv32, 0bv32, ~#SSLv3_server_data~0.base, ~bvadd32(56bv32, ~#SSLv3_server_data~0.offset), 4bv32);call write~init~$Pointer$(0bv32, 0bv32, ~#SSLv3_server_data~0.base, ~bvadd32(60bv32, ~#SSLv3_server_data~0.offset), 4bv32);call write~init~$Pointer$(0bv32, 0bv32, ~#SSLv3_server_data~0.base, ~bvadd32(64bv32, ~#SSLv3_server_data~0.offset), 4bv32);call write~init~$Pointer$(0bv32, 0bv32, ~#SSLv3_server_data~0.base, ~bvadd32(68bv32, ~#SSLv3_server_data~0.offset), 4bv32);call write~init~$Pointer$(0bv32, 0bv32, ~#SSLv3_server_data~0.base, ~bvadd32(72bv32, ~#SSLv3_server_data~0.offset), 4bv32);call write~init~$Pointer$(0bv32, 0bv32, ~#SSLv3_server_data~0.base, ~bvadd32(76bv32, ~#SSLv3_server_data~0.offset), 4bv32);call write~init~$Pointer$(0bv32, 0bv32, ~#SSLv3_server_data~0.base, ~bvadd32(80bv32, ~#SSLv3_server_data~0.offset), 4bv32);call write~init~$Pointer$(0bv32, 0bv32, ~#SSLv3_server_data~0.base, ~bvadd32(84bv32, ~#SSLv3_server_data~0.offset), 4bv32);call write~init~$Pointer$(0bv32, 0bv32, ~#SSLv3_server_data~0.base, ~bvadd32(88bv32, ~#SSLv3_server_data~0.offset), 4bv32);call write~init~$Pointer$(0bv32, 0bv32, ~#SSLv3_server_data~0.base, ~bvadd32(92bv32, ~#SSLv3_server_data~0.offset), 4bv32);call write~init~$Pointer$(0bv32, 0bv32, ~#SSLv3_server_data~0.base, ~bvadd32(96bv32, ~#SSLv3_server_data~0.offset), 4bv32); {4016#true} is VALID [2018-11-23 10:59:54,308 INFO L273 TraceCheckUtils]: 2: Hoare triple {4016#true} assume true; {4016#true} is VALID [2018-11-23 10:59:54,308 INFO L268 TraceCheckUtils]: 3: Hoare quadruple {4016#true} {4016#true} #631#return; {4016#true} is VALID [2018-11-23 10:59:54,309 INFO L256 TraceCheckUtils]: 4: Hoare triple {4016#true} call #t~ret138 := main(); {4016#true} is VALID [2018-11-23 10:59:54,309 INFO L273 TraceCheckUtils]: 5: Hoare triple {4016#true} havoc ~s~0.base, ~s~0.offset;havoc ~tmp~2;call #t~malloc3.base, #t~malloc3.offset := #Ultimate.alloc(248bv32);~s~0.base, ~s~0.offset := #t~malloc3.base, #t~malloc3.offset;call #t~malloc4.base, #t~malloc4.offset := #Ultimate.alloc(899bv32);call write~$Pointer$(#t~malloc4.base, #t~malloc4.offset, ~s~0.base, ~bvadd32(84bv32, ~s~0.offset), 4bv32);call #t~malloc5.base, #t~malloc5.offset := #Ultimate.alloc(232bv32);call write~$Pointer$(#t~malloc5.base, #t~malloc5.offset, ~s~0.base, ~bvadd32(204bv32, ~s~0.offset), 4bv32);call #t~malloc6.base, #t~malloc6.offset := #Ultimate.alloc(200bv32);call write~$Pointer$(#t~malloc6.base, #t~malloc6.offset, ~s~0.base, ~bvadd32(176bv32, ~s~0.offset), 4bv32); {4016#true} is VALID [2018-11-23 10:59:54,309 INFO L256 TraceCheckUtils]: 6: Hoare triple {4016#true} call #t~ret7 := ssl3_accept(~s~0.base, ~s~0.offset); {4016#true} is VALID [2018-11-23 10:59:54,310 INFO L273 TraceCheckUtils]: 7: Hoare triple {4016#true} ~s.base, ~s.offset := #in~s.base, #in~s.offset;havoc ~buf~0.base, ~buf~0.offset;havoc ~l~0;havoc ~Time~0;havoc ~tmp~3;havoc ~cb~0.base, ~cb~0.offset;havoc ~num1~0;havoc ~ret~0;havoc ~new_state~0;havoc ~state~0;havoc ~skip~0;havoc ~got_new_session~0;~tmp___1~0 := #t~nondet8;havoc #t~nondet8;~tmp___2~0 := #t~nondet9;havoc #t~nondet9;~tmp___3~0 := #t~nondet10;havoc #t~nondet10;~tmp___4~0 := #t~nondet11;havoc #t~nondet11;~tmp___5~0 := #t~nondet12;havoc #t~nondet12;~tmp___6~0 := #t~nondet13;havoc #t~nondet13;havoc ~tmp___7~0;~tmp___8~0 := #t~nondet14;havoc #t~nondet14;~tmp___9~0 := #t~nondet15;havoc #t~nondet15;~tmp___10~0 := #t~nondet16;havoc #t~nondet16;havoc ~blastFlag~0;call write~intINTTYPE4(8464bv32, ~s.base, ~bvadd32(52bv32, ~s.offset), 4bv32);~blastFlag~0 := 0bv32;call write~intINTTYPE4(#t~nondet17, ~s.base, ~bvadd32(92bv32, ~s.offset), 4bv32);havoc #t~nondet17;call write~intINTTYPE4(8464bv32, ~s.base, ~bvadd32(52bv32, ~s.offset), 4bv32);~tmp~3 := #t~nondet18;havoc #t~nondet18;~Time~0 := ~tmp~3;~cb~0.base, ~cb~0.offset := 0bv32, 0bv32;~ret~0 := 4294967295bv32;~skip~0 := 0bv32;~got_new_session~0 := 0bv32;call #t~mem19.base, #t~mem19.offset := read~$Pointer$(~s.base, ~bvadd32(192bv32, ~s.offset), 4bv32); {4016#true} is VALID [2018-11-23 10:59:54,310 INFO L273 TraceCheckUtils]: 8: Hoare triple {4016#true} assume 0bv32 != ~bvadd32(#t~mem19.base, #t~mem19.offset);havoc #t~mem19.base, #t~mem19.offset;call #t~mem20.base, #t~mem20.offset := read~$Pointer$(~s.base, ~bvadd32(192bv32, ~s.offset), 4bv32);~cb~0.base, ~cb~0.offset := #t~mem20.base, #t~mem20.offset;havoc #t~mem20.base, #t~mem20.offset; {4016#true} is VALID [2018-11-23 10:59:54,310 INFO L273 TraceCheckUtils]: 9: Hoare triple {4016#true} call #t~mem21 := read~intINTTYPE4(~s.base, ~bvadd32(28bv32, ~s.offset), 4bv32);call write~intINTTYPE4(~bvadd32(1bv32, #t~mem21), ~s.base, ~bvadd32(28bv32, ~s.offset), 4bv32);havoc #t~mem21; {4016#true} is VALID [2018-11-23 10:59:54,310 INFO L273 TraceCheckUtils]: 10: Hoare triple {4016#true} assume !(0bv32 != ~bvand32(12288bv32, ~tmp___1~0)); {4016#true} is VALID [2018-11-23 10:59:54,311 INFO L273 TraceCheckUtils]: 11: Hoare triple {4016#true} call #t~mem22.base, #t~mem22.offset := read~$Pointer$(~s.base, ~bvadd32(136bv32, ~s.offset), 4bv32); {4016#true} is VALID [2018-11-23 10:59:54,311 INFO L273 TraceCheckUtils]: 12: Hoare triple {4016#true} assume !(0bv32 == ~bvadd32(#t~mem22.base, #t~mem22.offset));havoc #t~mem22.base, #t~mem22.offset; {4016#true} is VALID [2018-11-23 10:59:54,311 INFO L273 TraceCheckUtils]: 13: Hoare triple {4016#true} assume !false; {4016#true} is VALID [2018-11-23 10:59:54,311 INFO L273 TraceCheckUtils]: 14: Hoare triple {4016#true} call #t~mem23 := read~intINTTYPE4(~s.base, ~bvadd32(52bv32, ~s.offset), 4bv32);~state~0 := #t~mem23;havoc #t~mem23;call #t~mem24 := read~intINTTYPE4(~s.base, ~bvadd32(52bv32, ~s.offset), 4bv32); {4016#true} is VALID [2018-11-23 10:59:54,312 INFO L273 TraceCheckUtils]: 15: Hoare triple {4016#true} assume !(12292bv32 == #t~mem24);havoc #t~mem24;call #t~mem25 := read~intINTTYPE4(~s.base, ~bvadd32(52bv32, ~s.offset), 4bv32); {4016#true} is VALID [2018-11-23 10:59:54,312 INFO L273 TraceCheckUtils]: 16: Hoare triple {4016#true} assume 16384bv32 == #t~mem25;havoc #t~mem25; {4016#true} is VALID [2018-11-23 10:59:54,312 INFO L273 TraceCheckUtils]: 17: Hoare triple {4016#true} call write~intINTTYPE4(1bv32, ~s.base, ~bvadd32(36bv32, ~s.offset), 4bv32); {4016#true} is VALID [2018-11-23 10:59:54,312 INFO L273 TraceCheckUtils]: 18: Hoare triple {4016#true} assume 0bv32 != ~bvadd32(~cb~0.base, ~cb~0.offset); {4016#true} is VALID [2018-11-23 10:59:54,313 INFO L273 TraceCheckUtils]: 19: Hoare triple {4016#true} call #t~mem59 := read~intINTTYPE4(~s.base, ~s.offset, 4bv32); {4016#true} is VALID [2018-11-23 10:59:54,313 INFO L273 TraceCheckUtils]: 20: Hoare triple {4016#true} assume !(3bv32 != ~bvashr32(#t~mem59, 8bv32));havoc #t~mem59;call write~intINTTYPE4(8192bv32, ~s.base, ~bvadd32(4bv32, ~s.offset), 4bv32);call #t~mem60.base, #t~mem60.offset := read~$Pointer$(~s.base, ~bvadd32(60bv32, ~s.offset), 4bv32); {4016#true} is VALID [2018-11-23 10:59:54,313 INFO L273 TraceCheckUtils]: 21: Hoare triple {4016#true} assume !(0bv32 == ~bvadd32(#t~mem60.base, #t~mem60.offset));havoc #t~mem60.base, #t~mem60.offset; {4016#true} is VALID [2018-11-23 10:59:54,313 INFO L273 TraceCheckUtils]: 22: Hoare triple {4016#true} assume !(0bv32 == ~tmp___4~0);call write~intINTTYPE4(0bv32, ~s.base, ~bvadd32(64bv32, ~s.offset), 4bv32);call #t~mem62 := read~intINTTYPE4(~s.base, ~bvadd32(52bv32, ~s.offset), 4bv32); {4016#true} is VALID [2018-11-23 10:59:54,328 INFO L273 TraceCheckUtils]: 23: Hoare triple {4016#true} assume !(12292bv32 != #t~mem62);havoc #t~mem62;call #t~mem65.base, #t~mem65.offset := read~$Pointer$(~s.base, ~bvadd32(204bv32, ~s.offset), 4bv32);call #t~mem66 := read~intINTTYPE4(#t~mem65.base, ~bvadd32(76bv32, #t~mem65.offset), 4bv32);call write~intINTTYPE4(~bvadd32(1bv32, #t~mem66), #t~mem65.base, ~bvadd32(76bv32, #t~mem65.offset), 4bv32);havoc #t~mem65.base, #t~mem65.offset;havoc #t~mem66;call write~intINTTYPE4(8480bv32, ~s.base, ~bvadd32(52bv32, ~s.offset), 4bv32); {4090#(= (_ bv8480 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32))))} is VALID [2018-11-23 10:59:54,343 INFO L273 TraceCheckUtils]: 24: Hoare triple {4090#(= (_ bv8480 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32))))} call #t~mem127.base, #t~mem127.offset := read~$Pointer$(~s.base, ~bvadd32(84bv32, ~s.offset), 4bv32);call #t~mem128 := read~intINTTYPE4(#t~mem127.base, ~bvadd32(848bv32, #t~mem127.offset), 4bv32); {4090#(= (_ bv8480 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32))))} is VALID [2018-11-23 10:59:54,351 INFO L273 TraceCheckUtils]: 25: Hoare triple {4090#(= (_ bv8480 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32))))} assume !(0bv32 == #t~mem128);havoc #t~mem127.base, #t~mem127.offset;havoc #t~mem128; {4090#(= (_ bv8480 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32))))} is VALID [2018-11-23 10:59:54,352 INFO L273 TraceCheckUtils]: 26: Hoare triple {4090#(= (_ bv8480 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32))))} ~skip~0 := 0bv32; {4090#(= (_ bv8480 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32))))} is VALID [2018-11-23 10:59:54,353 INFO L273 TraceCheckUtils]: 27: Hoare triple {4090#(= (_ bv8480 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32))))} assume !false; {4090#(= (_ bv8480 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32))))} is VALID [2018-11-23 10:59:54,353 INFO L273 TraceCheckUtils]: 28: Hoare triple {4090#(= (_ bv8480 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32))))} call #t~mem23 := read~intINTTYPE4(~s.base, ~bvadd32(52bv32, ~s.offset), 4bv32);~state~0 := #t~mem23;havoc #t~mem23;call #t~mem24 := read~intINTTYPE4(~s.base, ~bvadd32(52bv32, ~s.offset), 4bv32); {4090#(= (_ bv8480 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32))))} is VALID [2018-11-23 10:59:54,354 INFO L273 TraceCheckUtils]: 29: Hoare triple {4090#(= (_ bv8480 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32))))} assume !(12292bv32 == #t~mem24);havoc #t~mem24;call #t~mem25 := read~intINTTYPE4(~s.base, ~bvadd32(52bv32, ~s.offset), 4bv32); {4090#(= (_ bv8480 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32))))} is VALID [2018-11-23 10:59:54,355 INFO L273 TraceCheckUtils]: 30: Hoare triple {4090#(= (_ bv8480 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32))))} assume !(16384bv32 == #t~mem25);havoc #t~mem25;call #t~mem26 := read~intINTTYPE4(~s.base, ~bvadd32(52bv32, ~s.offset), 4bv32); {4090#(= (_ bv8480 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32))))} is VALID [2018-11-23 10:59:54,355 INFO L273 TraceCheckUtils]: 31: Hoare triple {4090#(= (_ bv8480 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32))))} assume !(8192bv32 == #t~mem26);havoc #t~mem26;call #t~mem27 := read~intINTTYPE4(~s.base, ~bvadd32(52bv32, ~s.offset), 4bv32); {4090#(= (_ bv8480 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32))))} is VALID [2018-11-23 10:59:54,357 INFO L273 TraceCheckUtils]: 32: Hoare triple {4090#(= (_ bv8480 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32))))} assume !(24576bv32 == #t~mem27);havoc #t~mem27;call #t~mem28 := read~intINTTYPE4(~s.base, ~bvadd32(52bv32, ~s.offset), 4bv32); {4090#(= (_ bv8480 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32))))} is VALID [2018-11-23 10:59:54,357 INFO L273 TraceCheckUtils]: 33: Hoare triple {4090#(= (_ bv8480 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32))))} assume !(8195bv32 == #t~mem28);havoc #t~mem28;call #t~mem29 := read~intINTTYPE4(~s.base, ~bvadd32(52bv32, ~s.offset), 4bv32); {4090#(= (_ bv8480 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32))))} is VALID [2018-11-23 10:59:54,362 INFO L273 TraceCheckUtils]: 34: Hoare triple {4090#(= (_ bv8480 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32))))} assume !(8480bv32 == #t~mem29);havoc #t~mem29;call #t~mem30 := read~intINTTYPE4(~s.base, ~bvadd32(52bv32, ~s.offset), 4bv32); {4090#(= (_ bv8480 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32))))} is VALID [2018-11-23 10:59:54,362 INFO L273 TraceCheckUtils]: 35: Hoare triple {4090#(= (_ bv8480 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32))))} assume !(8481bv32 == #t~mem30);havoc #t~mem30;call #t~mem31 := read~intINTTYPE4(~s.base, ~bvadd32(52bv32, ~s.offset), 4bv32); {4090#(= (_ bv8480 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32))))} is VALID [2018-11-23 10:59:54,364 INFO L273 TraceCheckUtils]: 36: Hoare triple {4090#(= (_ bv8480 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32))))} assume !(8482bv32 == #t~mem31);havoc #t~mem31;call #t~mem32 := read~intINTTYPE4(~s.base, ~bvadd32(52bv32, ~s.offset), 4bv32); {4090#(= (_ bv8480 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32))))} is VALID [2018-11-23 10:59:54,364 INFO L273 TraceCheckUtils]: 37: Hoare triple {4090#(= (_ bv8480 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32))))} assume !(8464bv32 == #t~mem32);havoc #t~mem32;call #t~mem33 := read~intINTTYPE4(~s.base, ~bvadd32(52bv32, ~s.offset), 4bv32); {4090#(= (_ bv8480 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32))))} is VALID [2018-11-23 10:59:54,365 INFO L273 TraceCheckUtils]: 38: Hoare triple {4090#(= (_ bv8480 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32))))} assume !(8465bv32 == #t~mem33);havoc #t~mem33;call #t~mem34 := read~intINTTYPE4(~s.base, ~bvadd32(52bv32, ~s.offset), 4bv32); {4090#(= (_ bv8480 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32))))} is VALID [2018-11-23 10:59:54,365 INFO L273 TraceCheckUtils]: 39: Hoare triple {4090#(= (_ bv8480 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32))))} assume !(8466bv32 == #t~mem34);havoc #t~mem34;call #t~mem35 := read~intINTTYPE4(~s.base, ~bvadd32(52bv32, ~s.offset), 4bv32); {4090#(= (_ bv8480 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32))))} is VALID [2018-11-23 10:59:54,365 INFO L273 TraceCheckUtils]: 40: Hoare triple {4090#(= (_ bv8480 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32))))} assume !(8496bv32 == #t~mem35);havoc #t~mem35;call #t~mem36 := read~intINTTYPE4(~s.base, ~bvadd32(52bv32, ~s.offset), 4bv32); {4090#(= (_ bv8480 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32))))} is VALID [2018-11-23 10:59:54,366 INFO L273 TraceCheckUtils]: 41: Hoare triple {4090#(= (_ bv8480 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32))))} assume !(8497bv32 == #t~mem36);havoc #t~mem36;call #t~mem37 := read~intINTTYPE4(~s.base, ~bvadd32(52bv32, ~s.offset), 4bv32); {4090#(= (_ bv8480 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32))))} is VALID [2018-11-23 10:59:54,367 INFO L273 TraceCheckUtils]: 42: Hoare triple {4090#(= (_ bv8480 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32))))} assume !(8512bv32 == #t~mem37);havoc #t~mem37;call #t~mem38 := read~intINTTYPE4(~s.base, ~bvadd32(52bv32, ~s.offset), 4bv32); {4090#(= (_ bv8480 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32))))} is VALID [2018-11-23 10:59:54,376 INFO L273 TraceCheckUtils]: 43: Hoare triple {4090#(= (_ bv8480 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32))))} assume !(8513bv32 == #t~mem38);havoc #t~mem38;call #t~mem39 := read~intINTTYPE4(~s.base, ~bvadd32(52bv32, ~s.offset), 4bv32); {4090#(= (_ bv8480 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32))))} is VALID [2018-11-23 10:59:54,385 INFO L273 TraceCheckUtils]: 44: Hoare triple {4090#(= (_ bv8480 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32))))} assume !(8528bv32 == #t~mem39);havoc #t~mem39;call #t~mem40 := read~intINTTYPE4(~s.base, ~bvadd32(52bv32, ~s.offset), 4bv32); {4090#(= (_ bv8480 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32))))} is VALID [2018-11-23 10:59:54,394 INFO L273 TraceCheckUtils]: 45: Hoare triple {4090#(= (_ bv8480 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32))))} assume !(8529bv32 == #t~mem40);havoc #t~mem40;call #t~mem41 := read~intINTTYPE4(~s.base, ~bvadd32(52bv32, ~s.offset), 4bv32); {4090#(= (_ bv8480 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32))))} is VALID [2018-11-23 10:59:54,407 INFO L273 TraceCheckUtils]: 46: Hoare triple {4090#(= (_ bv8480 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32))))} assume !(8544bv32 == #t~mem41);havoc #t~mem41;call #t~mem42 := read~intINTTYPE4(~s.base, ~bvadd32(52bv32, ~s.offset), 4bv32); {4090#(= (_ bv8480 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32))))} is VALID [2018-11-23 10:59:54,421 INFO L273 TraceCheckUtils]: 47: Hoare triple {4090#(= (_ bv8480 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32))))} assume !(8545bv32 == #t~mem42);havoc #t~mem42;call #t~mem43 := read~intINTTYPE4(~s.base, ~bvadd32(52bv32, ~s.offset), 4bv32); {4090#(= (_ bv8480 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32))))} is VALID [2018-11-23 10:59:54,437 INFO L273 TraceCheckUtils]: 48: Hoare triple {4090#(= (_ bv8480 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32))))} assume !(8560bv32 == #t~mem43);havoc #t~mem43;call #t~mem44 := read~intINTTYPE4(~s.base, ~bvadd32(52bv32, ~s.offset), 4bv32); {4090#(= (_ bv8480 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32))))} is VALID [2018-11-23 10:59:54,453 INFO L273 TraceCheckUtils]: 49: Hoare triple {4090#(= (_ bv8480 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32))))} assume !(8561bv32 == #t~mem44);havoc #t~mem44;call #t~mem45 := read~intINTTYPE4(~s.base, ~bvadd32(52bv32, ~s.offset), 4bv32); {4090#(= (_ bv8480 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32))))} is VALID [2018-11-23 10:59:54,462 INFO L273 TraceCheckUtils]: 50: Hoare triple {4090#(= (_ bv8480 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32))))} assume !(8448bv32 == #t~mem45);havoc #t~mem45;call #t~mem46 := read~intINTTYPE4(~s.base, ~bvadd32(52bv32, ~s.offset), 4bv32); {4090#(= (_ bv8480 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32))))} is VALID [2018-11-23 10:59:54,474 INFO L273 TraceCheckUtils]: 51: Hoare triple {4090#(= (_ bv8480 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32))))} assume !(8576bv32 == #t~mem46);havoc #t~mem46;call #t~mem47 := read~intINTTYPE4(~s.base, ~bvadd32(52bv32, ~s.offset), 4bv32); {4090#(= (_ bv8480 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32))))} is VALID [2018-11-23 10:59:54,476 INFO L273 TraceCheckUtils]: 52: Hoare triple {4090#(= (_ bv8480 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32))))} assume !(8577bv32 == #t~mem47);havoc #t~mem47;call #t~mem48 := read~intINTTYPE4(~s.base, ~bvadd32(52bv32, ~s.offset), 4bv32); {4090#(= (_ bv8480 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32))))} is VALID [2018-11-23 10:59:54,476 INFO L273 TraceCheckUtils]: 53: Hoare triple {4090#(= (_ bv8480 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32))))} assume !(8592bv32 == #t~mem48);havoc #t~mem48;call #t~mem49 := read~intINTTYPE4(~s.base, ~bvadd32(52bv32, ~s.offset), 4bv32); {4090#(= (_ bv8480 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32))))} is VALID [2018-11-23 10:59:54,478 INFO L273 TraceCheckUtils]: 54: Hoare triple {4090#(= (_ bv8480 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32))))} assume !(8593bv32 == #t~mem49);havoc #t~mem49;call #t~mem50 := read~intINTTYPE4(~s.base, ~bvadd32(52bv32, ~s.offset), 4bv32); {4090#(= (_ bv8480 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32))))} is VALID [2018-11-23 10:59:54,478 INFO L273 TraceCheckUtils]: 55: Hoare triple {4090#(= (_ bv8480 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32))))} assume !(8608bv32 == #t~mem50);havoc #t~mem50;call #t~mem51 := read~intINTTYPE4(~s.base, ~bvadd32(52bv32, ~s.offset), 4bv32); {4090#(= (_ bv8480 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32))))} is VALID [2018-11-23 10:59:54,480 INFO L273 TraceCheckUtils]: 56: Hoare triple {4090#(= (_ bv8480 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32))))} assume !(8609bv32 == #t~mem51);havoc #t~mem51;call #t~mem52 := read~intINTTYPE4(~s.base, ~bvadd32(52bv32, ~s.offset), 4bv32); {4190#(= (bvadd |ssl3_accept_#t~mem52| (_ bv4294958816 32)) (_ bv0 32))} is VALID [2018-11-23 10:59:54,480 INFO L273 TraceCheckUtils]: 57: Hoare triple {4190#(= (bvadd |ssl3_accept_#t~mem52| (_ bv4294958816 32)) (_ bv0 32))} assume 8640bv32 == #t~mem52;havoc #t~mem52; {4017#false} is VALID [2018-11-23 10:59:54,480 INFO L273 TraceCheckUtils]: 58: Hoare triple {4017#false} ~ret~0 := #t~nondet115;havoc #t~nondet115; {4017#false} is VALID [2018-11-23 10:59:54,480 INFO L273 TraceCheckUtils]: 59: Hoare triple {4017#false} assume !(4bv32 == ~blastFlag~0); {4017#false} is VALID [2018-11-23 10:59:54,481 INFO L273 TraceCheckUtils]: 60: Hoare triple {4017#false} assume !(7bv32 == ~blastFlag~0); {4017#false} is VALID [2018-11-23 10:59:54,481 INFO L273 TraceCheckUtils]: 61: Hoare triple {4017#false} assume !false; {4017#false} is VALID [2018-11-23 10:59:54,488 INFO L134 CoverageAnalysis]: Checked inductivity of 4 backedges. 4 proven. 0 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2018-11-23 10:59:54,488 INFO L312 TraceCheckSpWp]: Omiting computation of backward sequence because forward sequence was already perfect [2018-11-23 10:59:54,492 INFO L312 seRefinementStrategy]: Constructing automaton from 1 perfect and 0 imperfect interpolant sequences. [2018-11-23 10:59:54,492 INFO L327 seRefinementStrategy]: Number of different interpolants: perfect sequences [4] imperfect sequences [] total 4 [2018-11-23 10:59:54,493 INFO L78 Accepts]: Start accepts. Automaton has 4 states. Word has length 62 [2018-11-23 10:59:54,494 INFO L84 Accepts]: Finished accepts. word is accepted. [2018-11-23 10:59:54,494 INFO L86 InductivityCheck]: Starting indutivity check of a Floyd-Hoare automaton with 4 states. [2018-11-23 10:59:54,619 INFO L119 InductivityCheck]: Floyd-Hoare automaton has 62 edges. 62 inductive. 0 not inductive. 0 times theorem prover too weak to decide inductivity. [2018-11-23 10:59:54,619 INFO L459 AbstractCegarLoop]: Interpolant automaton has 4 states [2018-11-23 10:59:54,619 INFO L142 InterpolantAutomaton]: Constructing interpolant automaton starting with 4 interpolants. [2018-11-23 10:59:54,619 INFO L144 InterpolantAutomaton]: CoverageRelationStatistics Valid=5, Invalid=7, Unknown=0, NotChecked=0, Total=12 [2018-11-23 10:59:54,620 INFO L87 Difference]: Start difference. First operand 173 states and 272 transitions. Second operand 4 states. [2018-11-23 11:00:17,246 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2018-11-23 11:00:17,246 INFO L93 Difference]: Finished difference Result 405 states and 631 transitions. [2018-11-23 11:00:17,246 INFO L142 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 4 states. [2018-11-23 11:00:17,246 INFO L78 Accepts]: Start accepts. Automaton has 4 states. Word has length 62 [2018-11-23 11:00:17,247 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2018-11-23 11:00:17,247 INFO L82 GeneralOperation]: Start removeUnreachable. Operand 4 states. [2018-11-23 11:00:17,251 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 4 states to 4 states and 572 transitions. [2018-11-23 11:00:17,252 INFO L82 GeneralOperation]: Start removeUnreachable. Operand 4 states. [2018-11-23 11:00:17,255 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 4 states to 4 states and 572 transitions. [2018-11-23 11:00:17,256 INFO L86 InductivityCheck]: Starting indutivity check of a Floyd-Hoare automaton with 4 states and 572 transitions. [2018-11-23 11:00:18,587 INFO L119 InductivityCheck]: Floyd-Hoare automaton has 572 edges. 572 inductive. 0 not inductive. 0 times theorem prover too weak to decide inductivity. [2018-11-23 11:00:18,595 INFO L225 Difference]: With dead ends: 405 [2018-11-23 11:00:18,595 INFO L226 Difference]: Without dead ends: 278 [2018-11-23 11:00:18,596 INFO L631 BasicCegarLoop]: 0 DeclaredPredicates, 62 GetRequests, 59 SyntacticMatches, 0 SemanticMatches, 3 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 0 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=9, Invalid=11, Unknown=0, NotChecked=0, Total=20 [2018-11-23 11:00:18,597 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 278 states. [2018-11-23 11:00:18,699 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 278 to 212. [2018-11-23 11:00:18,699 INFO L214 AbstractMinimizeNwa]: Start testing correctness of minimizeSevpa [2018-11-23 11:00:18,699 INFO L82 GeneralOperation]: Start isEquivalent. First operand 278 states. Second operand 212 states. [2018-11-23 11:00:18,699 INFO L74 IsIncluded]: Start isIncluded. First operand 278 states. Second operand 212 states. [2018-11-23 11:00:18,699 INFO L87 Difference]: Start difference. First operand 278 states. Second operand 212 states. [2018-11-23 11:00:18,708 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2018-11-23 11:00:18,708 INFO L93 Difference]: Finished difference Result 278 states and 434 transitions. [2018-11-23 11:00:18,708 INFO L276 IsEmpty]: Start isEmpty. Operand 278 states and 434 transitions. [2018-11-23 11:00:18,709 INFO L282 IsEmpty]: Finished isEmpty. No accepting run. [2018-11-23 11:00:18,709 INFO L83 IsIncluded]: Finished isIncluded. Language is included [2018-11-23 11:00:18,710 INFO L74 IsIncluded]: Start isIncluded. First operand 212 states. Second operand 278 states. [2018-11-23 11:00:18,710 INFO L87 Difference]: Start difference. First operand 212 states. Second operand 278 states. [2018-11-23 11:00:18,718 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2018-11-23 11:00:18,718 INFO L93 Difference]: Finished difference Result 278 states and 434 transitions. [2018-11-23 11:00:18,718 INFO L276 IsEmpty]: Start isEmpty. Operand 278 states and 434 transitions. [2018-11-23 11:00:18,719 INFO L282 IsEmpty]: Finished isEmpty. No accepting run. [2018-11-23 11:00:18,719 INFO L83 IsIncluded]: Finished isIncluded. Language is included [2018-11-23 11:00:18,719 INFO L88 GeneralOperation]: Finished isEquivalent. [2018-11-23 11:00:18,719 INFO L221 AbstractMinimizeNwa]: Finished testing correctness of minimizeSevpa [2018-11-23 11:00:18,720 INFO L82 GeneralOperation]: Start removeUnreachable. Operand 212 states. [2018-11-23 11:00:18,726 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 212 states to 212 states and 344 transitions. [2018-11-23 11:00:18,726 INFO L78 Accepts]: Start accepts. Automaton has 212 states and 344 transitions. Word has length 62 [2018-11-23 11:00:18,726 INFO L84 Accepts]: Finished accepts. word is rejected. [2018-11-23 11:00:18,726 INFO L480 AbstractCegarLoop]: Abstraction has 212 states and 344 transitions. [2018-11-23 11:00:18,726 INFO L481 AbstractCegarLoop]: Interpolant automaton has 4 states. [2018-11-23 11:00:18,727 INFO L276 IsEmpty]: Start isEmpty. Operand 212 states and 344 transitions. [2018-11-23 11:00:18,728 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 63 [2018-11-23 11:00:18,728 INFO L394 BasicCegarLoop]: Found error trace [2018-11-23 11:00:18,728 INFO L402 BasicCegarLoop]: trace histogram [2, 2, 2, 2, 2, 2, 2, 2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2018-11-23 11:00:18,728 INFO L423 AbstractCegarLoop]: === Iteration 5 === [ssl3_acceptErr0ASSERT_VIOLATIONERROR_FUNCTION]=== [2018-11-23 11:00:18,728 INFO L141 PredicateUnifier]: Initialized classic predicate unifier [2018-11-23 11:00:18,729 INFO L82 PathProgramCache]: Analyzing trace with hash 263492231, now seen corresponding path program 1 times [2018-11-23 11:00:18,729 INFO L223 ckRefinementStrategy]: Switched to mode CVC4_FPBP [2018-11-23 11:00:18,729 INFO L69 tionRefinementEngine]: Using refinement strategy WolfRefinementStrategy No working directory specified, using /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/cvc4nyu Starting monitored process 6 with cvc4nyu --tear-down-incremental --print-success --lang smt --rewrite-divk (exit command is (exit), workingDir is null) Waiting until toolchain timeout for monitored process 6 with cvc4nyu --tear-down-incremental --print-success --lang smt --rewrite-divk [2018-11-23 11:00:18,759 INFO L103 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2018-11-23 11:00:19,129 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2018-11-23 11:00:19,279 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2018-11-23 11:00:19,284 INFO L273 TraceCheckSpWp]: Computing forward predicates... [2018-11-23 11:00:19,849 INFO L478 Elim1Store]: Elim1 did not use preprocessing eliminated variable of array dimension 2, 1 stores, 1 select indices, 1 select index equivalence classes, 0 disjoint index pairs (out of 0 index pairs), introduced 1 new quantified variables, introduced 0 case distinctions, treesize of input 23 treesize of output 20 [2018-11-23 11:00:19,890 INFO L478 Elim1Store]: Elim1 did not use preprocessing eliminated variable of array dimension 1, 1 stores, 0 select indices, 0 select index equivalence classes, 0 disjoint index pairs (out of 0 index pairs), introduced 1 new quantified variables, introduced 0 case distinctions, treesize of input 20 treesize of output 23 [2018-11-23 11:00:19,967 INFO L701 Elim1Store]: detected not equals via solver [2018-11-23 11:00:19,993 INFO L478 Elim1Store]: Elim1 did not use preprocessing eliminated variable of array dimension 1, 1 stores, 1 select indices, 1 select index equivalence classes, 1 disjoint index pairs (out of 0 index pairs), introduced 1 new quantified variables, introduced 0 case distinctions, treesize of input 23 treesize of output 33 [2018-11-23 11:00:20,082 INFO L701 Elim1Store]: detected not equals via solver [2018-11-23 11:00:20,129 INFO L478 Elim1Store]: Elim1 did not use preprocessing eliminated variable of array dimension 1, 1 stores, 2 select indices, 2 select index equivalence classes, 1 disjoint index pairs (out of 1 index pairs), introduced 0 new quantified variables, introduced 0 case distinctions, treesize of input 25 treesize of output 27 [2018-11-23 11:00:20,134 INFO L267 ElimStorePlain]: Start of recursive call 5: End of recursive call: and 1 xjuncts. [2018-11-23 11:00:20,146 INFO L267 ElimStorePlain]: Start of recursive call 4: 1 dim-1 vars, End of recursive call: and 1 xjuncts. [2018-11-23 11:00:20,156 INFO L267 ElimStorePlain]: Start of recursive call 3: 1 dim-1 vars, End of recursive call: and 1 xjuncts. [2018-11-23 11:00:20,171 INFO L267 ElimStorePlain]: Start of recursive call 2: 1 dim-1 vars, End of recursive call: and 1 xjuncts. [2018-11-23 11:00:20,187 INFO L267 ElimStorePlain]: Start of recursive call 1: 1 dim-0 vars, 1 dim-2 vars, End of recursive call: and 1 xjuncts. [2018-11-23 11:00:20,187 INFO L202 ElimStorePlain]: Needed 5 recursive calls to eliminate 2 variables, input treesize:27, output treesize:13 [2018-11-23 11:00:20,208 WARN L383 uantifierElimination]: Trying to double check SDD result, but SMT solver's response was UNKNOWN. [2018-11-23 11:00:20,209 WARN L384 uantifierElimination]: Input elimination task: ∃ [|v_#memory_int_188|, |v_ssl3_accept_#t~nondet17_6|]. (and (= ssl3_accept_~s.offset (_ bv0 32)) (= (store |v_#memory_int_188| ssl3_accept_~s.base (let ((.cse0 (bvadd ssl3_accept_~s.offset (_ bv52 32)))) (store (store (store (select |v_#memory_int_188| ssl3_accept_~s.base) .cse0 (_ bv8464 32)) (bvadd ssl3_accept_~s.offset (_ bv92 32)) |v_ssl3_accept_#t~nondet17_6|) .cse0 (_ bv8464 32)))) |#memory_int|)) [2018-11-23 11:00:20,209 WARN L385 uantifierElimination]: ElimStorePlain result: ∃ []. (and (= ssl3_accept_~s.offset (_ bv0 32)) (= (_ bv8464 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32))))) [2018-11-23 11:00:20,320 INFO L701 Elim1Store]: detected not equals via solver [2018-11-23 11:00:20,322 INFO L478 Elim1Store]: Elim1 did not use preprocessing eliminated variable of array dimension 2, 1 stores, 1 select indices, 1 select index equivalence classes, 1 disjoint index pairs (out of 0 index pairs), introduced 1 new quantified variables, introduced 0 case distinctions, treesize of input 31 treesize of output 38 [2018-11-23 11:00:20,334 INFO L701 Elim1Store]: detected not equals via solver [2018-11-23 11:00:20,341 INFO L701 Elim1Store]: detected not equals via solver [2018-11-23 11:00:20,348 INFO L478 Elim1Store]: Elim1 did not use preprocessing eliminated variable of array dimension 1, 1 stores, 2 select indices, 2 select index equivalence classes, 2 disjoint index pairs (out of 1 index pairs), introduced 1 new quantified variables, introduced 0 case distinctions, treesize of input 38 treesize of output 35 [2018-11-23 11:00:20,387 INFO L267 ElimStorePlain]: Start of recursive call 3: End of recursive call: and 1 xjuncts. [2018-11-23 11:00:20,395 INFO L267 ElimStorePlain]: Start of recursive call 2: 1 dim-1 vars, End of recursive call: and 1 xjuncts. [2018-11-23 11:00:20,411 INFO L267 ElimStorePlain]: Start of recursive call 1: 1 dim-2 vars, End of recursive call: and 1 xjuncts. [2018-11-23 11:00:20,411 INFO L202 ElimStorePlain]: Needed 3 recursive calls to eliminate 1 variables, input treesize:34, output treesize:13 [2018-11-23 11:00:22,429 WARN L383 uantifierElimination]: Trying to double check SDD result, but SMT solver's response was UNKNOWN. [2018-11-23 11:00:22,429 WARN L384 uantifierElimination]: Input elimination task: ∃ [|v_#memory_int_189|]. (let ((.cse0 (select |v_#memory_int_189| ssl3_accept_~s.base))) (and (= (select .cse0 (bvadd ssl3_accept_~s.offset (_ bv52 32))) (_ bv8464 32)) (= ssl3_accept_~s.offset (_ bv0 32)) (= (store |v_#memory_int_189| ssl3_accept_~s.base (let ((.cse1 (bvadd ssl3_accept_~s.offset (_ bv28 32)))) (store .cse0 .cse1 (bvadd (select .cse0 .cse1) (_ bv1 32))))) |#memory_int|))) [2018-11-23 11:00:22,430 WARN L385 uantifierElimination]: ElimStorePlain result: ∃ []. (and (= ssl3_accept_~s.offset (_ bv0 32)) (= (_ bv8464 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32))))) [2018-11-23 11:00:22,467 INFO L478 Elim1Store]: Elim1 did not use preprocessing eliminated variable of array dimension 2, 0 stores, 1 select indices, 1 select index equivalence classes, 0 disjoint index pairs (out of 0 index pairs), introduced 1 new quantified variables, introduced 0 case distinctions, treesize of input 17 treesize of output 13 [2018-11-23 11:00:22,473 INFO L478 Elim1Store]: Elim1 did not use preprocessing eliminated variable of array dimension 1, 0 stores, 1 select indices, 1 select index equivalence classes, 0 disjoint index pairs (out of 0 index pairs), introduced 0 new quantified variables, introduced 0 case distinctions, treesize of input 13 treesize of output 5 [2018-11-23 11:00:22,478 INFO L267 ElimStorePlain]: Start of recursive call 3: End of recursive call: and 1 xjuncts. [2018-11-23 11:00:22,480 INFO L267 ElimStorePlain]: Start of recursive call 2: 1 dim-1 vars, End of recursive call: and 1 xjuncts. [2018-11-23 11:00:22,482 INFO L267 ElimStorePlain]: Start of recursive call 1: 1 dim-0 vars, 1 dim-2 vars, End of recursive call: and 1 xjuncts. [2018-11-23 11:00:22,483 INFO L202 ElimStorePlain]: Needed 3 recursive calls to eliminate 2 variables, input treesize:17, output treesize:5 [2018-11-23 11:00:22,486 WARN L383 uantifierElimination]: Trying to double check SDD result, but SMT solver's response was UNKNOWN. [2018-11-23 11:00:22,487 WARN L384 uantifierElimination]: Input elimination task: ∃ [|#memory_int|, ssl3_accept_~s.base]. (let ((.cse0 (select (select |#memory_int| ssl3_accept_~s.base) (_ bv52 32)))) (and (= |ssl3_accept_#t~mem30| .cse0) (= (bvadd .cse0 (_ bv4294958832 32)) (_ bv0 32)))) [2018-11-23 11:00:22,487 WARN L385 uantifierElimination]: ElimStorePlain result: ∃ []. (= (_ bv0 32) (bvadd |ssl3_accept_#t~mem30| (_ bv4294958832 32))) [2018-11-23 11:00:22,546 INFO L256 TraceCheckUtils]: 0: Hoare triple {5487#true} call ULTIMATE.init(); {5487#true} is VALID [2018-11-23 11:00:22,547 INFO L273 TraceCheckUtils]: 1: Hoare triple {5487#true} #NULL.base, #NULL.offset := 0bv32, 0bv32;#valid := #valid[0bv32 := 0bv1];~init~0 := 1bv32;call ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset := #Ultimate.alloc(100bv32);call write~init~intINTTYPE4(0bv32, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset, 4bv32);call write~init~$Pointer$(0bv32, 0bv32, ~#SSLv3_server_data~0.base, ~bvadd32(4bv32, ~#SSLv3_server_data~0.offset), 4bv32);call write~init~$Pointer$(0bv32, 0bv32, ~#SSLv3_server_data~0.base, ~bvadd32(8bv32, ~#SSLv3_server_data~0.offset), 4bv32);call write~init~$Pointer$(0bv32, 0bv32, ~#SSLv3_server_data~0.base, ~bvadd32(12bv32, ~#SSLv3_server_data~0.offset), 4bv32);call write~init~$Pointer$(0bv32, 0bv32, ~#SSLv3_server_data~0.base, ~bvadd32(16bv32, ~#SSLv3_server_data~0.offset), 4bv32);call write~init~$Pointer$(0bv32, 0bv32, ~#SSLv3_server_data~0.base, ~bvadd32(20bv32, ~#SSLv3_server_data~0.offset), 4bv32);call write~init~$Pointer$(0bv32, 0bv32, ~#SSLv3_server_data~0.base, ~bvadd32(24bv32, ~#SSLv3_server_data~0.offset), 4bv32);call write~init~$Pointer$(0bv32, 0bv32, ~#SSLv3_server_data~0.base, ~bvadd32(28bv32, ~#SSLv3_server_data~0.offset), 4bv32);call write~init~$Pointer$(0bv32, 0bv32, ~#SSLv3_server_data~0.base, ~bvadd32(32bv32, ~#SSLv3_server_data~0.offset), 4bv32);call write~init~$Pointer$(0bv32, 0bv32, ~#SSLv3_server_data~0.base, ~bvadd32(36bv32, ~#SSLv3_server_data~0.offset), 4bv32);call write~init~$Pointer$(0bv32, 0bv32, ~#SSLv3_server_data~0.base, ~bvadd32(40bv32, ~#SSLv3_server_data~0.offset), 4bv32);call write~init~$Pointer$(0bv32, 0bv32, ~#SSLv3_server_data~0.base, ~bvadd32(44bv32, ~#SSLv3_server_data~0.offset), 4bv32);call write~init~$Pointer$(0bv32, 0bv32, ~#SSLv3_server_data~0.base, ~bvadd32(48bv32, ~#SSLv3_server_data~0.offset), 4bv32);call write~init~$Pointer$(0bv32, 0bv32, ~#SSLv3_server_data~0.base, ~bvadd32(52bv32, ~#SSLv3_server_data~0.offset), 4bv32);call write~init~$Pointer$(0bv32, 0bv32, ~#SSLv3_server_data~0.base, ~bvadd32(56bv32, ~#SSLv3_server_data~0.offset), 4bv32);call write~init~$Pointer$(0bv32, 0bv32, ~#SSLv3_server_data~0.base, ~bvadd32(60bv32, ~#SSLv3_server_data~0.offset), 4bv32);call write~init~$Pointer$(0bv32, 0bv32, ~#SSLv3_server_data~0.base, ~bvadd32(64bv32, ~#SSLv3_server_data~0.offset), 4bv32);call write~init~$Pointer$(0bv32, 0bv32, ~#SSLv3_server_data~0.base, ~bvadd32(68bv32, ~#SSLv3_server_data~0.offset), 4bv32);call write~init~$Pointer$(0bv32, 0bv32, ~#SSLv3_server_data~0.base, ~bvadd32(72bv32, ~#SSLv3_server_data~0.offset), 4bv32);call write~init~$Pointer$(0bv32, 0bv32, ~#SSLv3_server_data~0.base, ~bvadd32(76bv32, ~#SSLv3_server_data~0.offset), 4bv32);call write~init~$Pointer$(0bv32, 0bv32, ~#SSLv3_server_data~0.base, ~bvadd32(80bv32, ~#SSLv3_server_data~0.offset), 4bv32);call write~init~$Pointer$(0bv32, 0bv32, ~#SSLv3_server_data~0.base, ~bvadd32(84bv32, ~#SSLv3_server_data~0.offset), 4bv32);call write~init~$Pointer$(0bv32, 0bv32, ~#SSLv3_server_data~0.base, ~bvadd32(88bv32, ~#SSLv3_server_data~0.offset), 4bv32);call write~init~$Pointer$(0bv32, 0bv32, ~#SSLv3_server_data~0.base, ~bvadd32(92bv32, ~#SSLv3_server_data~0.offset), 4bv32);call write~init~$Pointer$(0bv32, 0bv32, ~#SSLv3_server_data~0.base, ~bvadd32(96bv32, ~#SSLv3_server_data~0.offset), 4bv32); {5487#true} is VALID [2018-11-23 11:00:22,547 INFO L273 TraceCheckUtils]: 2: Hoare triple {5487#true} assume true; {5487#true} is VALID [2018-11-23 11:00:22,547 INFO L268 TraceCheckUtils]: 3: Hoare quadruple {5487#true} {5487#true} #631#return; {5487#true} is VALID [2018-11-23 11:00:22,547 INFO L256 TraceCheckUtils]: 4: Hoare triple {5487#true} call #t~ret138 := main(); {5487#true} is VALID [2018-11-23 11:00:22,549 INFO L273 TraceCheckUtils]: 5: Hoare triple {5487#true} havoc ~s~0.base, ~s~0.offset;havoc ~tmp~2;call #t~malloc3.base, #t~malloc3.offset := #Ultimate.alloc(248bv32);~s~0.base, ~s~0.offset := #t~malloc3.base, #t~malloc3.offset;call #t~malloc4.base, #t~malloc4.offset := #Ultimate.alloc(899bv32);call write~$Pointer$(#t~malloc4.base, #t~malloc4.offset, ~s~0.base, ~bvadd32(84bv32, ~s~0.offset), 4bv32);call #t~malloc5.base, #t~malloc5.offset := #Ultimate.alloc(232bv32);call write~$Pointer$(#t~malloc5.base, #t~malloc5.offset, ~s~0.base, ~bvadd32(204bv32, ~s~0.offset), 4bv32);call #t~malloc6.base, #t~malloc6.offset := #Ultimate.alloc(200bv32);call write~$Pointer$(#t~malloc6.base, #t~malloc6.offset, ~s~0.base, ~bvadd32(176bv32, ~s~0.offset), 4bv32); {5507#(= main_~s~0.offset (_ bv0 32))} is VALID [2018-11-23 11:00:22,550 INFO L256 TraceCheckUtils]: 6: Hoare triple {5507#(= main_~s~0.offset (_ bv0 32))} call #t~ret7 := ssl3_accept(~s~0.base, ~s~0.offset); {5511#(= (_ bv0 32) |ssl3_accept_#in~s.offset|)} is VALID [2018-11-23 11:00:22,555 INFO L273 TraceCheckUtils]: 7: Hoare triple {5511#(= (_ bv0 32) |ssl3_accept_#in~s.offset|)} ~s.base, ~s.offset := #in~s.base, #in~s.offset;havoc ~buf~0.base, ~buf~0.offset;havoc ~l~0;havoc ~Time~0;havoc ~tmp~3;havoc ~cb~0.base, ~cb~0.offset;havoc ~num1~0;havoc ~ret~0;havoc ~new_state~0;havoc ~state~0;havoc ~skip~0;havoc ~got_new_session~0;~tmp___1~0 := #t~nondet8;havoc #t~nondet8;~tmp___2~0 := #t~nondet9;havoc #t~nondet9;~tmp___3~0 := #t~nondet10;havoc #t~nondet10;~tmp___4~0 := #t~nondet11;havoc #t~nondet11;~tmp___5~0 := #t~nondet12;havoc #t~nondet12;~tmp___6~0 := #t~nondet13;havoc #t~nondet13;havoc ~tmp___7~0;~tmp___8~0 := #t~nondet14;havoc #t~nondet14;~tmp___9~0 := #t~nondet15;havoc #t~nondet15;~tmp___10~0 := #t~nondet16;havoc #t~nondet16;havoc ~blastFlag~0;call write~intINTTYPE4(8464bv32, ~s.base, ~bvadd32(52bv32, ~s.offset), 4bv32);~blastFlag~0 := 0bv32;call write~intINTTYPE4(#t~nondet17, ~s.base, ~bvadd32(92bv32, ~s.offset), 4bv32);havoc #t~nondet17;call write~intINTTYPE4(8464bv32, ~s.base, ~bvadd32(52bv32, ~s.offset), 4bv32);~tmp~3 := #t~nondet18;havoc #t~nondet18;~Time~0 := ~tmp~3;~cb~0.base, ~cb~0.offset := 0bv32, 0bv32;~ret~0 := 4294967295bv32;~skip~0 := 0bv32;~got_new_session~0 := 0bv32;call #t~mem19.base, #t~mem19.offset := read~$Pointer$(~s.base, ~bvadd32(192bv32, ~s.offset), 4bv32); {5515#(and (= ssl3_accept_~s.offset (_ bv0 32)) (= (_ bv8464 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32)))))} is VALID [2018-11-23 11:00:22,556 INFO L273 TraceCheckUtils]: 8: Hoare triple {5515#(and (= ssl3_accept_~s.offset (_ bv0 32)) (= (_ bv8464 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32)))))} assume 0bv32 != ~bvadd32(#t~mem19.base, #t~mem19.offset);havoc #t~mem19.base, #t~mem19.offset;call #t~mem20.base, #t~mem20.offset := read~$Pointer$(~s.base, ~bvadd32(192bv32, ~s.offset), 4bv32);~cb~0.base, ~cb~0.offset := #t~mem20.base, #t~mem20.offset;havoc #t~mem20.base, #t~mem20.offset; {5515#(and (= ssl3_accept_~s.offset (_ bv0 32)) (= (_ bv8464 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32)))))} is VALID [2018-11-23 11:00:22,558 INFO L273 TraceCheckUtils]: 9: Hoare triple {5515#(and (= ssl3_accept_~s.offset (_ bv0 32)) (= (_ bv8464 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32)))))} call #t~mem21 := read~intINTTYPE4(~s.base, ~bvadd32(28bv32, ~s.offset), 4bv32);call write~intINTTYPE4(~bvadd32(1bv32, #t~mem21), ~s.base, ~bvadd32(28bv32, ~s.offset), 4bv32);havoc #t~mem21; {5515#(and (= ssl3_accept_~s.offset (_ bv0 32)) (= (_ bv8464 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32)))))} is VALID [2018-11-23 11:00:22,559 INFO L273 TraceCheckUtils]: 10: Hoare triple {5515#(and (= ssl3_accept_~s.offset (_ bv0 32)) (= (_ bv8464 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32)))))} assume !(0bv32 != ~bvand32(12288bv32, ~tmp___1~0)); {5515#(and (= ssl3_accept_~s.offset (_ bv0 32)) (= (_ bv8464 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32)))))} is VALID [2018-11-23 11:00:22,560 INFO L273 TraceCheckUtils]: 11: Hoare triple {5515#(and (= ssl3_accept_~s.offset (_ bv0 32)) (= (_ bv8464 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32)))))} call #t~mem22.base, #t~mem22.offset := read~$Pointer$(~s.base, ~bvadd32(136bv32, ~s.offset), 4bv32); {5515#(and (= ssl3_accept_~s.offset (_ bv0 32)) (= (_ bv8464 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32)))))} is VALID [2018-11-23 11:00:22,561 INFO L273 TraceCheckUtils]: 12: Hoare triple {5515#(and (= ssl3_accept_~s.offset (_ bv0 32)) (= (_ bv8464 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32)))))} assume !(0bv32 == ~bvadd32(#t~mem22.base, #t~mem22.offset));havoc #t~mem22.base, #t~mem22.offset; {5515#(and (= ssl3_accept_~s.offset (_ bv0 32)) (= (_ bv8464 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32)))))} is VALID [2018-11-23 11:00:22,562 INFO L273 TraceCheckUtils]: 13: Hoare triple {5515#(and (= ssl3_accept_~s.offset (_ bv0 32)) (= (_ bv8464 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32)))))} assume !false; {5515#(and (= ssl3_accept_~s.offset (_ bv0 32)) (= (_ bv8464 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32)))))} is VALID [2018-11-23 11:00:22,562 INFO L273 TraceCheckUtils]: 14: Hoare triple {5515#(and (= ssl3_accept_~s.offset (_ bv0 32)) (= (_ bv8464 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32)))))} call #t~mem23 := read~intINTTYPE4(~s.base, ~bvadd32(52bv32, ~s.offset), 4bv32);~state~0 := #t~mem23;havoc #t~mem23;call #t~mem24 := read~intINTTYPE4(~s.base, ~bvadd32(52bv32, ~s.offset), 4bv32); {5515#(and (= ssl3_accept_~s.offset (_ bv0 32)) (= (_ bv8464 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32)))))} is VALID [2018-11-23 11:00:22,563 INFO L273 TraceCheckUtils]: 15: Hoare triple {5515#(and (= ssl3_accept_~s.offset (_ bv0 32)) (= (_ bv8464 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32)))))} assume !(12292bv32 == #t~mem24);havoc #t~mem24;call #t~mem25 := read~intINTTYPE4(~s.base, ~bvadd32(52bv32, ~s.offset), 4bv32); {5515#(and (= ssl3_accept_~s.offset (_ bv0 32)) (= (_ bv8464 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32)))))} is VALID [2018-11-23 11:00:22,564 INFO L273 TraceCheckUtils]: 16: Hoare triple {5515#(and (= ssl3_accept_~s.offset (_ bv0 32)) (= (_ bv8464 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32)))))} assume !(16384bv32 == #t~mem25);havoc #t~mem25;call #t~mem26 := read~intINTTYPE4(~s.base, ~bvadd32(52bv32, ~s.offset), 4bv32); {5515#(and (= ssl3_accept_~s.offset (_ bv0 32)) (= (_ bv8464 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32)))))} is VALID [2018-11-23 11:00:22,565 INFO L273 TraceCheckUtils]: 17: Hoare triple {5515#(and (= ssl3_accept_~s.offset (_ bv0 32)) (= (_ bv8464 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32)))))} assume !(8192bv32 == #t~mem26);havoc #t~mem26;call #t~mem27 := read~intINTTYPE4(~s.base, ~bvadd32(52bv32, ~s.offset), 4bv32); {5515#(and (= ssl3_accept_~s.offset (_ bv0 32)) (= (_ bv8464 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32)))))} is VALID [2018-11-23 11:00:22,566 INFO L273 TraceCheckUtils]: 18: Hoare triple {5515#(and (= ssl3_accept_~s.offset (_ bv0 32)) (= (_ bv8464 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32)))))} assume !(24576bv32 == #t~mem27);havoc #t~mem27;call #t~mem28 := read~intINTTYPE4(~s.base, ~bvadd32(52bv32, ~s.offset), 4bv32); {5515#(and (= ssl3_accept_~s.offset (_ bv0 32)) (= (_ bv8464 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32)))))} is VALID [2018-11-23 11:00:22,567 INFO L273 TraceCheckUtils]: 19: Hoare triple {5515#(and (= ssl3_accept_~s.offset (_ bv0 32)) (= (_ bv8464 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32)))))} assume !(8195bv32 == #t~mem28);havoc #t~mem28;call #t~mem29 := read~intINTTYPE4(~s.base, ~bvadd32(52bv32, ~s.offset), 4bv32); {5515#(and (= ssl3_accept_~s.offset (_ bv0 32)) (= (_ bv8464 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32)))))} is VALID [2018-11-23 11:00:22,568 INFO L273 TraceCheckUtils]: 20: Hoare triple {5515#(and (= ssl3_accept_~s.offset (_ bv0 32)) (= (_ bv8464 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32)))))} assume !(8480bv32 == #t~mem29);havoc #t~mem29;call #t~mem30 := read~intINTTYPE4(~s.base, ~bvadd32(52bv32, ~s.offset), 4bv32); {5555#(= (_ bv8464 32) |ssl3_accept_#t~mem30|)} is VALID [2018-11-23 11:00:22,569 INFO L273 TraceCheckUtils]: 21: Hoare triple {5555#(= (_ bv8464 32) |ssl3_accept_#t~mem30|)} assume 8481bv32 == #t~mem30;havoc #t~mem30; {5488#false} is VALID [2018-11-23 11:00:22,569 INFO L273 TraceCheckUtils]: 22: Hoare triple {5488#false} call write~intINTTYPE4(0bv32, ~s.base, ~bvadd32(48bv32, ~s.offset), 4bv32);~ret~0 := #t~nondet67;havoc #t~nondet67; {5488#false} is VALID [2018-11-23 11:00:22,570 INFO L273 TraceCheckUtils]: 23: Hoare triple {5488#false} assume !~bvsle32(~ret~0, 0bv32);call #t~mem68.base, #t~mem68.offset := read~$Pointer$(~s.base, ~bvadd32(84bv32, ~s.offset), 4bv32);call write~intINTTYPE4(8482bv32, #t~mem68.base, ~bvadd32(844bv32, #t~mem68.offset), 4bv32);havoc #t~mem68.base, #t~mem68.offset;call write~intINTTYPE4(8448bv32, ~s.base, ~bvadd32(52bv32, ~s.offset), 4bv32);call write~intINTTYPE4(0bv32, ~s.base, ~bvadd32(64bv32, ~s.offset), 4bv32); {5488#false} is VALID [2018-11-23 11:00:22,570 INFO L273 TraceCheckUtils]: 24: Hoare triple {5488#false} call #t~mem127.base, #t~mem127.offset := read~$Pointer$(~s.base, ~bvadd32(84bv32, ~s.offset), 4bv32);call #t~mem128 := read~intINTTYPE4(#t~mem127.base, ~bvadd32(848bv32, #t~mem127.offset), 4bv32); {5488#false} is VALID [2018-11-23 11:00:22,570 INFO L273 TraceCheckUtils]: 25: Hoare triple {5488#false} assume !(0bv32 == #t~mem128);havoc #t~mem127.base, #t~mem127.offset;havoc #t~mem128; {5488#false} is VALID [2018-11-23 11:00:22,571 INFO L273 TraceCheckUtils]: 26: Hoare triple {5488#false} ~skip~0 := 0bv32; {5488#false} is VALID [2018-11-23 11:00:22,571 INFO L273 TraceCheckUtils]: 27: Hoare triple {5488#false} assume !false; {5488#false} is VALID [2018-11-23 11:00:22,571 INFO L273 TraceCheckUtils]: 28: Hoare triple {5488#false} call #t~mem23 := read~intINTTYPE4(~s.base, ~bvadd32(52bv32, ~s.offset), 4bv32);~state~0 := #t~mem23;havoc #t~mem23;call #t~mem24 := read~intINTTYPE4(~s.base, ~bvadd32(52bv32, ~s.offset), 4bv32); {5488#false} is VALID [2018-11-23 11:00:22,572 INFO L273 TraceCheckUtils]: 29: Hoare triple {5488#false} assume !(12292bv32 == #t~mem24);havoc #t~mem24;call #t~mem25 := read~intINTTYPE4(~s.base, ~bvadd32(52bv32, ~s.offset), 4bv32); {5488#false} is VALID [2018-11-23 11:00:22,572 INFO L273 TraceCheckUtils]: 30: Hoare triple {5488#false} assume !(16384bv32 == #t~mem25);havoc #t~mem25;call #t~mem26 := read~intINTTYPE4(~s.base, ~bvadd32(52bv32, ~s.offset), 4bv32); {5488#false} is VALID [2018-11-23 11:00:22,572 INFO L273 TraceCheckUtils]: 31: Hoare triple {5488#false} assume !(8192bv32 == #t~mem26);havoc #t~mem26;call #t~mem27 := read~intINTTYPE4(~s.base, ~bvadd32(52bv32, ~s.offset), 4bv32); {5488#false} is VALID [2018-11-23 11:00:22,573 INFO L273 TraceCheckUtils]: 32: Hoare triple {5488#false} assume !(24576bv32 == #t~mem27);havoc #t~mem27;call #t~mem28 := read~intINTTYPE4(~s.base, ~bvadd32(52bv32, ~s.offset), 4bv32); {5488#false} is VALID [2018-11-23 11:00:22,573 INFO L273 TraceCheckUtils]: 33: Hoare triple {5488#false} assume !(8195bv32 == #t~mem28);havoc #t~mem28;call #t~mem29 := read~intINTTYPE4(~s.base, ~bvadd32(52bv32, ~s.offset), 4bv32); {5488#false} is VALID [2018-11-23 11:00:22,573 INFO L273 TraceCheckUtils]: 34: Hoare triple {5488#false} assume !(8480bv32 == #t~mem29);havoc #t~mem29;call #t~mem30 := read~intINTTYPE4(~s.base, ~bvadd32(52bv32, ~s.offset), 4bv32); {5488#false} is VALID [2018-11-23 11:00:22,574 INFO L273 TraceCheckUtils]: 35: Hoare triple {5488#false} assume !(8481bv32 == #t~mem30);havoc #t~mem30;call #t~mem31 := read~intINTTYPE4(~s.base, ~bvadd32(52bv32, ~s.offset), 4bv32); {5488#false} is VALID [2018-11-23 11:00:22,574 INFO L273 TraceCheckUtils]: 36: Hoare triple {5488#false} assume !(8482bv32 == #t~mem31);havoc #t~mem31;call #t~mem32 := read~intINTTYPE4(~s.base, ~bvadd32(52bv32, ~s.offset), 4bv32); {5488#false} is VALID [2018-11-23 11:00:22,574 INFO L273 TraceCheckUtils]: 37: Hoare triple {5488#false} assume !(8464bv32 == #t~mem32);havoc #t~mem32;call #t~mem33 := read~intINTTYPE4(~s.base, ~bvadd32(52bv32, ~s.offset), 4bv32); {5488#false} is VALID [2018-11-23 11:00:22,574 INFO L273 TraceCheckUtils]: 38: Hoare triple {5488#false} assume !(8465bv32 == #t~mem33);havoc #t~mem33;call #t~mem34 := read~intINTTYPE4(~s.base, ~bvadd32(52bv32, ~s.offset), 4bv32); {5488#false} is VALID [2018-11-23 11:00:22,575 INFO L273 TraceCheckUtils]: 39: Hoare triple {5488#false} assume !(8466bv32 == #t~mem34);havoc #t~mem34;call #t~mem35 := read~intINTTYPE4(~s.base, ~bvadd32(52bv32, ~s.offset), 4bv32); {5488#false} is VALID [2018-11-23 11:00:22,575 INFO L273 TraceCheckUtils]: 40: Hoare triple {5488#false} assume !(8496bv32 == #t~mem35);havoc #t~mem35;call #t~mem36 := read~intINTTYPE4(~s.base, ~bvadd32(52bv32, ~s.offset), 4bv32); {5488#false} is VALID [2018-11-23 11:00:22,575 INFO L273 TraceCheckUtils]: 41: Hoare triple {5488#false} assume !(8497bv32 == #t~mem36);havoc #t~mem36;call #t~mem37 := read~intINTTYPE4(~s.base, ~bvadd32(52bv32, ~s.offset), 4bv32); {5488#false} is VALID [2018-11-23 11:00:22,575 INFO L273 TraceCheckUtils]: 42: Hoare triple {5488#false} assume !(8512bv32 == #t~mem37);havoc #t~mem37;call #t~mem38 := read~intINTTYPE4(~s.base, ~bvadd32(52bv32, ~s.offset), 4bv32); {5488#false} is VALID [2018-11-23 11:00:22,575 INFO L273 TraceCheckUtils]: 43: Hoare triple {5488#false} assume !(8513bv32 == #t~mem38);havoc #t~mem38;call #t~mem39 := read~intINTTYPE4(~s.base, ~bvadd32(52bv32, ~s.offset), 4bv32); {5488#false} is VALID [2018-11-23 11:00:22,576 INFO L273 TraceCheckUtils]: 44: Hoare triple {5488#false} assume !(8528bv32 == #t~mem39);havoc #t~mem39;call #t~mem40 := read~intINTTYPE4(~s.base, ~bvadd32(52bv32, ~s.offset), 4bv32); {5488#false} is VALID [2018-11-23 11:00:22,576 INFO L273 TraceCheckUtils]: 45: Hoare triple {5488#false} assume !(8529bv32 == #t~mem40);havoc #t~mem40;call #t~mem41 := read~intINTTYPE4(~s.base, ~bvadd32(52bv32, ~s.offset), 4bv32); {5488#false} is VALID [2018-11-23 11:00:22,576 INFO L273 TraceCheckUtils]: 46: Hoare triple {5488#false} assume !(8544bv32 == #t~mem41);havoc #t~mem41;call #t~mem42 := read~intINTTYPE4(~s.base, ~bvadd32(52bv32, ~s.offset), 4bv32); {5488#false} is VALID [2018-11-23 11:00:22,576 INFO L273 TraceCheckUtils]: 47: Hoare triple {5488#false} assume !(8545bv32 == #t~mem42);havoc #t~mem42;call #t~mem43 := read~intINTTYPE4(~s.base, ~bvadd32(52bv32, ~s.offset), 4bv32); {5488#false} is VALID [2018-11-23 11:00:22,576 INFO L273 TraceCheckUtils]: 48: Hoare triple {5488#false} assume !(8560bv32 == #t~mem43);havoc #t~mem43;call #t~mem44 := read~intINTTYPE4(~s.base, ~bvadd32(52bv32, ~s.offset), 4bv32); {5488#false} is VALID [2018-11-23 11:00:22,576 INFO L273 TraceCheckUtils]: 49: Hoare triple {5488#false} assume !(8561bv32 == #t~mem44);havoc #t~mem44;call #t~mem45 := read~intINTTYPE4(~s.base, ~bvadd32(52bv32, ~s.offset), 4bv32); {5488#false} is VALID [2018-11-23 11:00:22,578 INFO L273 TraceCheckUtils]: 50: Hoare triple {5488#false} assume !(8448bv32 == #t~mem45);havoc #t~mem45;call #t~mem46 := read~intINTTYPE4(~s.base, ~bvadd32(52bv32, ~s.offset), 4bv32); {5488#false} is VALID [2018-11-23 11:00:22,578 INFO L273 TraceCheckUtils]: 51: Hoare triple {5488#false} assume !(8576bv32 == #t~mem46);havoc #t~mem46;call #t~mem47 := read~intINTTYPE4(~s.base, ~bvadd32(52bv32, ~s.offset), 4bv32); {5488#false} is VALID [2018-11-23 11:00:22,578 INFO L273 TraceCheckUtils]: 52: Hoare triple {5488#false} assume !(8577bv32 == #t~mem47);havoc #t~mem47;call #t~mem48 := read~intINTTYPE4(~s.base, ~bvadd32(52bv32, ~s.offset), 4bv32); {5488#false} is VALID [2018-11-23 11:00:22,578 INFO L273 TraceCheckUtils]: 53: Hoare triple {5488#false} assume !(8592bv32 == #t~mem48);havoc #t~mem48;call #t~mem49 := read~intINTTYPE4(~s.base, ~bvadd32(52bv32, ~s.offset), 4bv32); {5488#false} is VALID [2018-11-23 11:00:22,578 INFO L273 TraceCheckUtils]: 54: Hoare triple {5488#false} assume !(8593bv32 == #t~mem49);havoc #t~mem49;call #t~mem50 := read~intINTTYPE4(~s.base, ~bvadd32(52bv32, ~s.offset), 4bv32); {5488#false} is VALID [2018-11-23 11:00:22,579 INFO L273 TraceCheckUtils]: 55: Hoare triple {5488#false} assume !(8608bv32 == #t~mem50);havoc #t~mem50;call #t~mem51 := read~intINTTYPE4(~s.base, ~bvadd32(52bv32, ~s.offset), 4bv32); {5488#false} is VALID [2018-11-23 11:00:22,579 INFO L273 TraceCheckUtils]: 56: Hoare triple {5488#false} assume !(8609bv32 == #t~mem51);havoc #t~mem51;call #t~mem52 := read~intINTTYPE4(~s.base, ~bvadd32(52bv32, ~s.offset), 4bv32); {5488#false} is VALID [2018-11-23 11:00:22,579 INFO L273 TraceCheckUtils]: 57: Hoare triple {5488#false} assume 8640bv32 == #t~mem52;havoc #t~mem52; {5488#false} is VALID [2018-11-23 11:00:22,579 INFO L273 TraceCheckUtils]: 58: Hoare triple {5488#false} ~ret~0 := #t~nondet115;havoc #t~nondet115; {5488#false} is VALID [2018-11-23 11:00:22,579 INFO L273 TraceCheckUtils]: 59: Hoare triple {5488#false} assume !(4bv32 == ~blastFlag~0); {5488#false} is VALID [2018-11-23 11:00:22,580 INFO L273 TraceCheckUtils]: 60: Hoare triple {5488#false} assume !(7bv32 == ~blastFlag~0); {5488#false} is VALID [2018-11-23 11:00:22,580 INFO L273 TraceCheckUtils]: 61: Hoare triple {5488#false} assume !false; {5488#false} is VALID [2018-11-23 11:00:22,586 INFO L134 CoverageAnalysis]: Checked inductivity of 9 backedges. 9 proven. 0 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2018-11-23 11:00:22,586 INFO L312 TraceCheckSpWp]: Omiting computation of backward sequence because forward sequence was already perfect [2018-11-23 11:00:22,588 INFO L312 seRefinementStrategy]: Constructing automaton from 1 perfect and 0 imperfect interpolant sequences. [2018-11-23 11:00:22,588 INFO L327 seRefinementStrategy]: Number of different interpolants: perfect sequences [6] imperfect sequences [] total 6 [2018-11-23 11:00:22,589 INFO L78 Accepts]: Start accepts. Automaton has 6 states. Word has length 62 [2018-11-23 11:00:22,589 INFO L84 Accepts]: Finished accepts. word is accepted. [2018-11-23 11:00:22,589 INFO L86 InductivityCheck]: Starting indutivity check of a Floyd-Hoare automaton with 6 states. [2018-11-23 11:00:22,709 INFO L119 InductivityCheck]: Floyd-Hoare automaton has 62 edges. 62 inductive. 0 not inductive. 0 times theorem prover too weak to decide inductivity. [2018-11-23 11:00:22,709 INFO L459 AbstractCegarLoop]: Interpolant automaton has 6 states [2018-11-23 11:00:22,709 INFO L142 InterpolantAutomaton]: Constructing interpolant automaton starting with 6 interpolants. [2018-11-23 11:00:22,710 INFO L144 InterpolantAutomaton]: CoverageRelationStatistics Valid=9, Invalid=21, Unknown=0, NotChecked=0, Total=30 [2018-11-23 11:00:22,710 INFO L87 Difference]: Start difference. First operand 212 states and 344 transitions. Second operand 6 states. [2018-11-23 11:00:42,638 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2018-11-23 11:00:42,638 INFO L93 Difference]: Finished difference Result 434 states and 689 transitions. [2018-11-23 11:00:42,638 INFO L142 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 6 states. [2018-11-23 11:00:42,638 INFO L78 Accepts]: Start accepts. Automaton has 6 states. Word has length 62 [2018-11-23 11:00:42,638 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2018-11-23 11:00:42,639 INFO L82 GeneralOperation]: Start removeUnreachable. Operand 6 states. [2018-11-23 11:00:42,642 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 6 states to 6 states and 545 transitions. [2018-11-23 11:00:42,642 INFO L82 GeneralOperation]: Start removeUnreachable. Operand 6 states. [2018-11-23 11:00:42,646 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 6 states to 6 states and 545 transitions. [2018-11-23 11:00:42,646 INFO L86 InductivityCheck]: Starting indutivity check of a Floyd-Hoare automaton with 6 states and 545 transitions. [2018-11-23 11:00:43,995 INFO L119 InductivityCheck]: Floyd-Hoare automaton has 545 edges. 545 inductive. 0 not inductive. 0 times theorem prover too weak to decide inductivity. [2018-11-23 11:00:44,002 INFO L225 Difference]: With dead ends: 434 [2018-11-23 11:00:44,003 INFO L226 Difference]: Without dead ends: 268 [2018-11-23 11:00:44,003 INFO L631 BasicCegarLoop]: 0 DeclaredPredicates, 63 GetRequests, 57 SyntacticMatches, 0 SemanticMatches, 6 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 0 ImplicationChecksByTransitivity, 0.3s TimeCoverageRelationStatistics Valid=19, Invalid=37, Unknown=0, NotChecked=0, Total=56 [2018-11-23 11:00:44,004 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 268 states. [2018-11-23 11:00:44,136 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 268 to 212. [2018-11-23 11:00:44,136 INFO L214 AbstractMinimizeNwa]: Start testing correctness of minimizeSevpa [2018-11-23 11:00:44,136 INFO L82 GeneralOperation]: Start isEquivalent. First operand 268 states. Second operand 212 states. [2018-11-23 11:00:44,137 INFO L74 IsIncluded]: Start isIncluded. First operand 268 states. Second operand 212 states. [2018-11-23 11:00:44,137 INFO L87 Difference]: Start difference. First operand 268 states. Second operand 212 states. [2018-11-23 11:00:44,145 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2018-11-23 11:00:44,145 INFO L93 Difference]: Finished difference Result 268 states and 420 transitions. [2018-11-23 11:00:44,146 INFO L276 IsEmpty]: Start isEmpty. Operand 268 states and 420 transitions. [2018-11-23 11:00:44,146 INFO L282 IsEmpty]: Finished isEmpty. No accepting run. [2018-11-23 11:00:44,146 INFO L83 IsIncluded]: Finished isIncluded. Language is included [2018-11-23 11:00:44,147 INFO L74 IsIncluded]: Start isIncluded. First operand 212 states. Second operand 268 states. [2018-11-23 11:00:44,147 INFO L87 Difference]: Start difference. First operand 212 states. Second operand 268 states. [2018-11-23 11:00:44,155 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2018-11-23 11:00:44,155 INFO L93 Difference]: Finished difference Result 268 states and 420 transitions. [2018-11-23 11:00:44,155 INFO L276 IsEmpty]: Start isEmpty. Operand 268 states and 420 transitions. [2018-11-23 11:00:44,156 INFO L282 IsEmpty]: Finished isEmpty. No accepting run. [2018-11-23 11:00:44,156 INFO L83 IsIncluded]: Finished isIncluded. Language is included [2018-11-23 11:00:44,156 INFO L88 GeneralOperation]: Finished isEquivalent. [2018-11-23 11:00:44,156 INFO L221 AbstractMinimizeNwa]: Finished testing correctness of minimizeSevpa [2018-11-23 11:00:44,157 INFO L82 GeneralOperation]: Start removeUnreachable. Operand 212 states. [2018-11-23 11:00:44,162 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 212 states to 212 states and 343 transitions. [2018-11-23 11:00:44,162 INFO L78 Accepts]: Start accepts. Automaton has 212 states and 343 transitions. Word has length 62 [2018-11-23 11:00:44,162 INFO L84 Accepts]: Finished accepts. word is rejected. [2018-11-23 11:00:44,163 INFO L480 AbstractCegarLoop]: Abstraction has 212 states and 343 transitions. [2018-11-23 11:00:44,163 INFO L481 AbstractCegarLoop]: Interpolant automaton has 6 states. [2018-11-23 11:00:44,163 INFO L276 IsEmpty]: Start isEmpty. Operand 212 states and 343 transitions. [2018-11-23 11:00:44,164 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 63 [2018-11-23 11:00:44,164 INFO L394 BasicCegarLoop]: Found error trace [2018-11-23 11:00:44,164 INFO L402 BasicCegarLoop]: trace histogram [2, 2, 2, 2, 2, 2, 2, 2, 2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2018-11-23 11:00:44,164 INFO L423 AbstractCegarLoop]: === Iteration 6 === [ssl3_acceptErr0ASSERT_VIOLATIONERROR_FUNCTION]=== [2018-11-23 11:00:44,165 INFO L141 PredicateUnifier]: Initialized classic predicate unifier [2018-11-23 11:00:44,165 INFO L82 PathProgramCache]: Analyzing trace with hash 404218918, now seen corresponding path program 1 times [2018-11-23 11:00:44,165 INFO L223 ckRefinementStrategy]: Switched to mode CVC4_FPBP [2018-11-23 11:00:44,166 INFO L69 tionRefinementEngine]: Using refinement strategy WolfRefinementStrategy No working directory specified, using /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/cvc4nyu Starting monitored process 7 with cvc4nyu --tear-down-incremental --print-success --lang smt --rewrite-divk (exit command is (exit), workingDir is null) Waiting until toolchain timeout for monitored process 7 with cvc4nyu --tear-down-incremental --print-success --lang smt --rewrite-divk [2018-11-23 11:00:44,195 INFO L103 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2018-11-23 11:00:44,370 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2018-11-23 11:00:44,436 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2018-11-23 11:00:44,439 INFO L273 TraceCheckSpWp]: Computing forward predicates... [2018-11-23 11:00:44,786 INFO L478 Elim1Store]: Elim1 did not use preprocessing eliminated variable of array dimension 2, 1 stores, 1 select indices, 1 select index equivalence classes, 0 disjoint index pairs (out of 0 index pairs), introduced 1 new quantified variables, introduced 0 case distinctions, treesize of input 13 treesize of output 10 [2018-11-23 11:00:44,792 INFO L478 Elim1Store]: Elim1 did not use preprocessing eliminated variable of array dimension 1, 1 stores, 0 select indices, 0 select index equivalence classes, 0 disjoint index pairs (out of 0 index pairs), introduced 0 new quantified variables, introduced 0 case distinctions, treesize of input 10 treesize of output 9 [2018-11-23 11:00:44,793 INFO L267 ElimStorePlain]: Start of recursive call 3: End of recursive call: and 1 xjuncts. [2018-11-23 11:00:44,798 INFO L267 ElimStorePlain]: Start of recursive call 2: 1 dim-1 vars, End of recursive call: and 1 xjuncts. [2018-11-23 11:00:44,802 INFO L267 ElimStorePlain]: Start of recursive call 1: 1 dim-2 vars, End of recursive call: and 1 xjuncts. [2018-11-23 11:00:44,803 INFO L202 ElimStorePlain]: Needed 3 recursive calls to eliminate 1 variables, input treesize:13, output treesize:9 [2018-11-23 11:00:44,886 INFO L478 Elim1Store]: Elim1 did not use preprocessing eliminated variable of array dimension 2, 0 stores, 1 select indices, 1 select index equivalence classes, 0 disjoint index pairs (out of 0 index pairs), introduced 1 new quantified variables, introduced 0 case distinctions, treesize of input 19 treesize of output 15 [2018-11-23 11:00:44,909 INFO L478 Elim1Store]: Elim1 did not use preprocessing eliminated variable of array dimension 1, 0 stores, 1 select indices, 1 select index equivalence classes, 0 disjoint index pairs (out of 0 index pairs), introduced 0 new quantified variables, introduced 0 case distinctions, treesize of input 15 treesize of output 3 [2018-11-23 11:00:44,910 INFO L267 ElimStorePlain]: Start of recursive call 3: End of recursive call: and 1 xjuncts. [2018-11-23 11:00:44,911 INFO L267 ElimStorePlain]: Start of recursive call 2: 1 dim-1 vars, End of recursive call: and 1 xjuncts. [2018-11-23 11:00:44,914 INFO L267 ElimStorePlain]: Start of recursive call 1: 2 dim-0 vars, 1 dim-2 vars, End of recursive call: and 1 xjuncts. [2018-11-23 11:00:44,914 INFO L202 ElimStorePlain]: Needed 3 recursive calls to eliminate 3 variables, input treesize:19, output treesize:3 [2018-11-23 11:00:44,918 WARN L383 uantifierElimination]: Trying to double check SDD result, but SMT solver's response was UNKNOWN. [2018-11-23 11:00:44,919 WARN L384 uantifierElimination]: Input elimination task: ∃ [|#memory_int|, ssl3_accept_~s.base, ssl3_accept_~s.offset]. (let ((.cse0 (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32))))) (and (= |ssl3_accept_#t~mem52| .cse0) (= (_ bv3 32) .cse0))) [2018-11-23 11:00:44,919 WARN L385 uantifierElimination]: ElimStorePlain result: ∃ []. (= |ssl3_accept_#t~mem52| (_ bv3 32)) [2018-11-23 11:00:44,929 INFO L256 TraceCheckUtils]: 0: Hoare triple {6970#true} call ULTIMATE.init(); {6970#true} is VALID [2018-11-23 11:00:44,930 INFO L273 TraceCheckUtils]: 1: Hoare triple {6970#true} #NULL.base, #NULL.offset := 0bv32, 0bv32;#valid := #valid[0bv32 := 0bv1];~init~0 := 1bv32;call ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset := #Ultimate.alloc(100bv32);call write~init~intINTTYPE4(0bv32, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset, 4bv32);call write~init~$Pointer$(0bv32, 0bv32, ~#SSLv3_server_data~0.base, ~bvadd32(4bv32, ~#SSLv3_server_data~0.offset), 4bv32);call write~init~$Pointer$(0bv32, 0bv32, ~#SSLv3_server_data~0.base, ~bvadd32(8bv32, ~#SSLv3_server_data~0.offset), 4bv32);call write~init~$Pointer$(0bv32, 0bv32, ~#SSLv3_server_data~0.base, ~bvadd32(12bv32, ~#SSLv3_server_data~0.offset), 4bv32);call write~init~$Pointer$(0bv32, 0bv32, ~#SSLv3_server_data~0.base, ~bvadd32(16bv32, ~#SSLv3_server_data~0.offset), 4bv32);call write~init~$Pointer$(0bv32, 0bv32, ~#SSLv3_server_data~0.base, ~bvadd32(20bv32, ~#SSLv3_server_data~0.offset), 4bv32);call write~init~$Pointer$(0bv32, 0bv32, ~#SSLv3_server_data~0.base, ~bvadd32(24bv32, ~#SSLv3_server_data~0.offset), 4bv32);call write~init~$Pointer$(0bv32, 0bv32, ~#SSLv3_server_data~0.base, ~bvadd32(28bv32, ~#SSLv3_server_data~0.offset), 4bv32);call write~init~$Pointer$(0bv32, 0bv32, ~#SSLv3_server_data~0.base, ~bvadd32(32bv32, ~#SSLv3_server_data~0.offset), 4bv32);call write~init~$Pointer$(0bv32, 0bv32, ~#SSLv3_server_data~0.base, ~bvadd32(36bv32, ~#SSLv3_server_data~0.offset), 4bv32);call write~init~$Pointer$(0bv32, 0bv32, ~#SSLv3_server_data~0.base, ~bvadd32(40bv32, ~#SSLv3_server_data~0.offset), 4bv32);call write~init~$Pointer$(0bv32, 0bv32, ~#SSLv3_server_data~0.base, ~bvadd32(44bv32, ~#SSLv3_server_data~0.offset), 4bv32);call write~init~$Pointer$(0bv32, 0bv32, ~#SSLv3_server_data~0.base, ~bvadd32(48bv32, ~#SSLv3_server_data~0.offset), 4bv32);call write~init~$Pointer$(0bv32, 0bv32, ~#SSLv3_server_data~0.base, ~bvadd32(52bv32, ~#SSLv3_server_data~0.offset), 4bv32);call write~init~$Pointer$(0bv32, 0bv32, ~#SSLv3_server_data~0.base, ~bvadd32(56bv32, ~#SSLv3_server_data~0.offset), 4bv32);call write~init~$Pointer$(0bv32, 0bv32, ~#SSLv3_server_data~0.base, ~bvadd32(60bv32, ~#SSLv3_server_data~0.offset), 4bv32);call write~init~$Pointer$(0bv32, 0bv32, ~#SSLv3_server_data~0.base, ~bvadd32(64bv32, ~#SSLv3_server_data~0.offset), 4bv32);call write~init~$Pointer$(0bv32, 0bv32, ~#SSLv3_server_data~0.base, ~bvadd32(68bv32, ~#SSLv3_server_data~0.offset), 4bv32);call write~init~$Pointer$(0bv32, 0bv32, ~#SSLv3_server_data~0.base, ~bvadd32(72bv32, ~#SSLv3_server_data~0.offset), 4bv32);call write~init~$Pointer$(0bv32, 0bv32, ~#SSLv3_server_data~0.base, ~bvadd32(76bv32, ~#SSLv3_server_data~0.offset), 4bv32);call write~init~$Pointer$(0bv32, 0bv32, ~#SSLv3_server_data~0.base, ~bvadd32(80bv32, ~#SSLv3_server_data~0.offset), 4bv32);call write~init~$Pointer$(0bv32, 0bv32, ~#SSLv3_server_data~0.base, ~bvadd32(84bv32, ~#SSLv3_server_data~0.offset), 4bv32);call write~init~$Pointer$(0bv32, 0bv32, ~#SSLv3_server_data~0.base, ~bvadd32(88bv32, ~#SSLv3_server_data~0.offset), 4bv32);call write~init~$Pointer$(0bv32, 0bv32, ~#SSLv3_server_data~0.base, ~bvadd32(92bv32, ~#SSLv3_server_data~0.offset), 4bv32);call write~init~$Pointer$(0bv32, 0bv32, ~#SSLv3_server_data~0.base, ~bvadd32(96bv32, ~#SSLv3_server_data~0.offset), 4bv32); {6970#true} is VALID [2018-11-23 11:00:44,930 INFO L273 TraceCheckUtils]: 2: Hoare triple {6970#true} assume true; {6970#true} is VALID [2018-11-23 11:00:44,930 INFO L268 TraceCheckUtils]: 3: Hoare quadruple {6970#true} {6970#true} #631#return; {6970#true} is VALID [2018-11-23 11:00:44,930 INFO L256 TraceCheckUtils]: 4: Hoare triple {6970#true} call #t~ret138 := main(); {6970#true} is VALID [2018-11-23 11:00:44,930 INFO L273 TraceCheckUtils]: 5: Hoare triple {6970#true} havoc ~s~0.base, ~s~0.offset;havoc ~tmp~2;call #t~malloc3.base, #t~malloc3.offset := #Ultimate.alloc(248bv32);~s~0.base, ~s~0.offset := #t~malloc3.base, #t~malloc3.offset;call #t~malloc4.base, #t~malloc4.offset := #Ultimate.alloc(899bv32);call write~$Pointer$(#t~malloc4.base, #t~malloc4.offset, ~s~0.base, ~bvadd32(84bv32, ~s~0.offset), 4bv32);call #t~malloc5.base, #t~malloc5.offset := #Ultimate.alloc(232bv32);call write~$Pointer$(#t~malloc5.base, #t~malloc5.offset, ~s~0.base, ~bvadd32(204bv32, ~s~0.offset), 4bv32);call #t~malloc6.base, #t~malloc6.offset := #Ultimate.alloc(200bv32);call write~$Pointer$(#t~malloc6.base, #t~malloc6.offset, ~s~0.base, ~bvadd32(176bv32, ~s~0.offset), 4bv32); {6970#true} is VALID [2018-11-23 11:00:44,931 INFO L256 TraceCheckUtils]: 6: Hoare triple {6970#true} call #t~ret7 := ssl3_accept(~s~0.base, ~s~0.offset); {6970#true} is VALID [2018-11-23 11:00:44,931 INFO L273 TraceCheckUtils]: 7: Hoare triple {6970#true} ~s.base, ~s.offset := #in~s.base, #in~s.offset;havoc ~buf~0.base, ~buf~0.offset;havoc ~l~0;havoc ~Time~0;havoc ~tmp~3;havoc ~cb~0.base, ~cb~0.offset;havoc ~num1~0;havoc ~ret~0;havoc ~new_state~0;havoc ~state~0;havoc ~skip~0;havoc ~got_new_session~0;~tmp___1~0 := #t~nondet8;havoc #t~nondet8;~tmp___2~0 := #t~nondet9;havoc #t~nondet9;~tmp___3~0 := #t~nondet10;havoc #t~nondet10;~tmp___4~0 := #t~nondet11;havoc #t~nondet11;~tmp___5~0 := #t~nondet12;havoc #t~nondet12;~tmp___6~0 := #t~nondet13;havoc #t~nondet13;havoc ~tmp___7~0;~tmp___8~0 := #t~nondet14;havoc #t~nondet14;~tmp___9~0 := #t~nondet15;havoc #t~nondet15;~tmp___10~0 := #t~nondet16;havoc #t~nondet16;havoc ~blastFlag~0;call write~intINTTYPE4(8464bv32, ~s.base, ~bvadd32(52bv32, ~s.offset), 4bv32);~blastFlag~0 := 0bv32;call write~intINTTYPE4(#t~nondet17, ~s.base, ~bvadd32(92bv32, ~s.offset), 4bv32);havoc #t~nondet17;call write~intINTTYPE4(8464bv32, ~s.base, ~bvadd32(52bv32, ~s.offset), 4bv32);~tmp~3 := #t~nondet18;havoc #t~nondet18;~Time~0 := ~tmp~3;~cb~0.base, ~cb~0.offset := 0bv32, 0bv32;~ret~0 := 4294967295bv32;~skip~0 := 0bv32;~got_new_session~0 := 0bv32;call #t~mem19.base, #t~mem19.offset := read~$Pointer$(~s.base, ~bvadd32(192bv32, ~s.offset), 4bv32); {6970#true} is VALID [2018-11-23 11:00:44,931 INFO L273 TraceCheckUtils]: 8: Hoare triple {6970#true} assume 0bv32 != ~bvadd32(#t~mem19.base, #t~mem19.offset);havoc #t~mem19.base, #t~mem19.offset;call #t~mem20.base, #t~mem20.offset := read~$Pointer$(~s.base, ~bvadd32(192bv32, ~s.offset), 4bv32);~cb~0.base, ~cb~0.offset := #t~mem20.base, #t~mem20.offset;havoc #t~mem20.base, #t~mem20.offset; {6970#true} is VALID [2018-11-23 11:00:44,931 INFO L273 TraceCheckUtils]: 9: Hoare triple {6970#true} call #t~mem21 := read~intINTTYPE4(~s.base, ~bvadd32(28bv32, ~s.offset), 4bv32);call write~intINTTYPE4(~bvadd32(1bv32, #t~mem21), ~s.base, ~bvadd32(28bv32, ~s.offset), 4bv32);havoc #t~mem21; {6970#true} is VALID [2018-11-23 11:00:44,932 INFO L273 TraceCheckUtils]: 10: Hoare triple {6970#true} assume !(0bv32 != ~bvand32(12288bv32, ~tmp___1~0)); {6970#true} is VALID [2018-11-23 11:00:44,932 INFO L273 TraceCheckUtils]: 11: Hoare triple {6970#true} call #t~mem22.base, #t~mem22.offset := read~$Pointer$(~s.base, ~bvadd32(136bv32, ~s.offset), 4bv32); {6970#true} is VALID [2018-11-23 11:00:44,932 INFO L273 TraceCheckUtils]: 12: Hoare triple {6970#true} assume !(0bv32 == ~bvadd32(#t~mem22.base, #t~mem22.offset));havoc #t~mem22.base, #t~mem22.offset; {6970#true} is VALID [2018-11-23 11:00:44,932 INFO L273 TraceCheckUtils]: 13: Hoare triple {6970#true} assume !false; {6970#true} is VALID [2018-11-23 11:00:44,932 INFO L273 TraceCheckUtils]: 14: Hoare triple {6970#true} call #t~mem23 := read~intINTTYPE4(~s.base, ~bvadd32(52bv32, ~s.offset), 4bv32);~state~0 := #t~mem23;havoc #t~mem23;call #t~mem24 := read~intINTTYPE4(~s.base, ~bvadd32(52bv32, ~s.offset), 4bv32); {6970#true} is VALID [2018-11-23 11:00:44,933 INFO L273 TraceCheckUtils]: 15: Hoare triple {6970#true} assume !(12292bv32 == #t~mem24);havoc #t~mem24;call #t~mem25 := read~intINTTYPE4(~s.base, ~bvadd32(52bv32, ~s.offset), 4bv32); {6970#true} is VALID [2018-11-23 11:00:44,933 INFO L273 TraceCheckUtils]: 16: Hoare triple {6970#true} assume !(16384bv32 == #t~mem25);havoc #t~mem25;call #t~mem26 := read~intINTTYPE4(~s.base, ~bvadd32(52bv32, ~s.offset), 4bv32); {6970#true} is VALID [2018-11-23 11:00:44,933 INFO L273 TraceCheckUtils]: 17: Hoare triple {6970#true} assume !(8192bv32 == #t~mem26);havoc #t~mem26;call #t~mem27 := read~intINTTYPE4(~s.base, ~bvadd32(52bv32, ~s.offset), 4bv32); {6970#true} is VALID [2018-11-23 11:00:44,933 INFO L273 TraceCheckUtils]: 18: Hoare triple {6970#true} assume !(24576bv32 == #t~mem27);havoc #t~mem27;call #t~mem28 := read~intINTTYPE4(~s.base, ~bvadd32(52bv32, ~s.offset), 4bv32); {6970#true} is VALID [2018-11-23 11:00:44,933 INFO L273 TraceCheckUtils]: 19: Hoare triple {6970#true} assume !(8195bv32 == #t~mem28);havoc #t~mem28;call #t~mem29 := read~intINTTYPE4(~s.base, ~bvadd32(52bv32, ~s.offset), 4bv32); {6970#true} is VALID [2018-11-23 11:00:44,934 INFO L273 TraceCheckUtils]: 20: Hoare triple {6970#true} assume !(8480bv32 == #t~mem29);havoc #t~mem29;call #t~mem30 := read~intINTTYPE4(~s.base, ~bvadd32(52bv32, ~s.offset), 4bv32); {6970#true} is VALID [2018-11-23 11:00:44,934 INFO L273 TraceCheckUtils]: 21: Hoare triple {6970#true} assume !(8481bv32 == #t~mem30);havoc #t~mem30;call #t~mem31 := read~intINTTYPE4(~s.base, ~bvadd32(52bv32, ~s.offset), 4bv32); {6970#true} is VALID [2018-11-23 11:00:44,934 INFO L273 TraceCheckUtils]: 22: Hoare triple {6970#true} assume 8482bv32 == #t~mem31;havoc #t~mem31; {6970#true} is VALID [2018-11-23 11:00:44,939 INFO L273 TraceCheckUtils]: 23: Hoare triple {6970#true} call write~intINTTYPE4(3bv32, ~s.base, ~bvadd32(52bv32, ~s.offset), 4bv32); {7044#(= (_ bv3 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32))))} is VALID [2018-11-23 11:00:44,939 INFO L273 TraceCheckUtils]: 24: Hoare triple {7044#(= (_ bv3 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32))))} call #t~mem127.base, #t~mem127.offset := read~$Pointer$(~s.base, ~bvadd32(84bv32, ~s.offset), 4bv32);call #t~mem128 := read~intINTTYPE4(#t~mem127.base, ~bvadd32(848bv32, #t~mem127.offset), 4bv32); {7044#(= (_ bv3 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32))))} is VALID [2018-11-23 11:00:44,940 INFO L273 TraceCheckUtils]: 25: Hoare triple {7044#(= (_ bv3 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32))))} assume !(0bv32 == #t~mem128);havoc #t~mem127.base, #t~mem127.offset;havoc #t~mem128; {7044#(= (_ bv3 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32))))} is VALID [2018-11-23 11:00:44,940 INFO L273 TraceCheckUtils]: 26: Hoare triple {7044#(= (_ bv3 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32))))} ~skip~0 := 0bv32; {7044#(= (_ bv3 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32))))} is VALID [2018-11-23 11:00:44,943 INFO L273 TraceCheckUtils]: 27: Hoare triple {7044#(= (_ bv3 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32))))} assume !false; {7044#(= (_ bv3 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32))))} is VALID [2018-11-23 11:00:44,943 INFO L273 TraceCheckUtils]: 28: Hoare triple {7044#(= (_ bv3 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32))))} call #t~mem23 := read~intINTTYPE4(~s.base, ~bvadd32(52bv32, ~s.offset), 4bv32);~state~0 := #t~mem23;havoc #t~mem23;call #t~mem24 := read~intINTTYPE4(~s.base, ~bvadd32(52bv32, ~s.offset), 4bv32); {7044#(= (_ bv3 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32))))} is VALID [2018-11-23 11:00:44,944 INFO L273 TraceCheckUtils]: 29: Hoare triple {7044#(= (_ bv3 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32))))} assume !(12292bv32 == #t~mem24);havoc #t~mem24;call #t~mem25 := read~intINTTYPE4(~s.base, ~bvadd32(52bv32, ~s.offset), 4bv32); {7044#(= (_ bv3 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32))))} is VALID [2018-11-23 11:00:44,944 INFO L273 TraceCheckUtils]: 30: Hoare triple {7044#(= (_ bv3 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32))))} assume !(16384bv32 == #t~mem25);havoc #t~mem25;call #t~mem26 := read~intINTTYPE4(~s.base, ~bvadd32(52bv32, ~s.offset), 4bv32); {7044#(= (_ bv3 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32))))} is VALID [2018-11-23 11:00:44,944 INFO L273 TraceCheckUtils]: 31: Hoare triple {7044#(= (_ bv3 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32))))} assume !(8192bv32 == #t~mem26);havoc #t~mem26;call #t~mem27 := read~intINTTYPE4(~s.base, ~bvadd32(52bv32, ~s.offset), 4bv32); {7044#(= (_ bv3 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32))))} is VALID [2018-11-23 11:00:44,945 INFO L273 TraceCheckUtils]: 32: Hoare triple {7044#(= (_ bv3 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32))))} assume !(24576bv32 == #t~mem27);havoc #t~mem27;call #t~mem28 := read~intINTTYPE4(~s.base, ~bvadd32(52bv32, ~s.offset), 4bv32); {7044#(= (_ bv3 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32))))} is VALID [2018-11-23 11:00:44,945 INFO L273 TraceCheckUtils]: 33: Hoare triple {7044#(= (_ bv3 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32))))} assume !(8195bv32 == #t~mem28);havoc #t~mem28;call #t~mem29 := read~intINTTYPE4(~s.base, ~bvadd32(52bv32, ~s.offset), 4bv32); {7044#(= (_ bv3 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32))))} is VALID [2018-11-23 11:00:44,945 INFO L273 TraceCheckUtils]: 34: Hoare triple {7044#(= (_ bv3 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32))))} assume !(8480bv32 == #t~mem29);havoc #t~mem29;call #t~mem30 := read~intINTTYPE4(~s.base, ~bvadd32(52bv32, ~s.offset), 4bv32); {7044#(= (_ bv3 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32))))} is VALID [2018-11-23 11:00:44,946 INFO L273 TraceCheckUtils]: 35: Hoare triple {7044#(= (_ bv3 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32))))} assume !(8481bv32 == #t~mem30);havoc #t~mem30;call #t~mem31 := read~intINTTYPE4(~s.base, ~bvadd32(52bv32, ~s.offset), 4bv32); {7044#(= (_ bv3 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32))))} is VALID [2018-11-23 11:00:44,946 INFO L273 TraceCheckUtils]: 36: Hoare triple {7044#(= (_ bv3 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32))))} assume !(8482bv32 == #t~mem31);havoc #t~mem31;call #t~mem32 := read~intINTTYPE4(~s.base, ~bvadd32(52bv32, ~s.offset), 4bv32); {7044#(= (_ bv3 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32))))} is VALID [2018-11-23 11:00:44,946 INFO L273 TraceCheckUtils]: 37: Hoare triple {7044#(= (_ bv3 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32))))} assume !(8464bv32 == #t~mem32);havoc #t~mem32;call #t~mem33 := read~intINTTYPE4(~s.base, ~bvadd32(52bv32, ~s.offset), 4bv32); {7044#(= (_ bv3 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32))))} is VALID [2018-11-23 11:00:44,947 INFO L273 TraceCheckUtils]: 38: Hoare triple {7044#(= (_ bv3 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32))))} assume !(8465bv32 == #t~mem33);havoc #t~mem33;call #t~mem34 := read~intINTTYPE4(~s.base, ~bvadd32(52bv32, ~s.offset), 4bv32); {7044#(= (_ bv3 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32))))} is VALID [2018-11-23 11:00:44,947 INFO L273 TraceCheckUtils]: 39: Hoare triple {7044#(= (_ bv3 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32))))} assume !(8466bv32 == #t~mem34);havoc #t~mem34;call #t~mem35 := read~intINTTYPE4(~s.base, ~bvadd32(52bv32, ~s.offset), 4bv32); {7044#(= (_ bv3 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32))))} is VALID [2018-11-23 11:00:44,947 INFO L273 TraceCheckUtils]: 40: Hoare triple {7044#(= (_ bv3 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32))))} assume !(8496bv32 == #t~mem35);havoc #t~mem35;call #t~mem36 := read~intINTTYPE4(~s.base, ~bvadd32(52bv32, ~s.offset), 4bv32); {7044#(= (_ bv3 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32))))} is VALID [2018-11-23 11:00:44,948 INFO L273 TraceCheckUtils]: 41: Hoare triple {7044#(= (_ bv3 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32))))} assume !(8497bv32 == #t~mem36);havoc #t~mem36;call #t~mem37 := read~intINTTYPE4(~s.base, ~bvadd32(52bv32, ~s.offset), 4bv32); {7044#(= (_ bv3 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32))))} is VALID [2018-11-23 11:00:44,948 INFO L273 TraceCheckUtils]: 42: Hoare triple {7044#(= (_ bv3 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32))))} assume !(8512bv32 == #t~mem37);havoc #t~mem37;call #t~mem38 := read~intINTTYPE4(~s.base, ~bvadd32(52bv32, ~s.offset), 4bv32); {7044#(= (_ bv3 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32))))} is VALID [2018-11-23 11:00:44,949 INFO L273 TraceCheckUtils]: 43: Hoare triple {7044#(= (_ bv3 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32))))} assume !(8513bv32 == #t~mem38);havoc #t~mem38;call #t~mem39 := read~intINTTYPE4(~s.base, ~bvadd32(52bv32, ~s.offset), 4bv32); {7044#(= (_ bv3 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32))))} is VALID [2018-11-23 11:00:44,950 INFO L273 TraceCheckUtils]: 44: Hoare triple {7044#(= (_ bv3 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32))))} assume !(8528bv32 == #t~mem39);havoc #t~mem39;call #t~mem40 := read~intINTTYPE4(~s.base, ~bvadd32(52bv32, ~s.offset), 4bv32); {7044#(= (_ bv3 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32))))} is VALID [2018-11-23 11:00:44,950 INFO L273 TraceCheckUtils]: 45: Hoare triple {7044#(= (_ bv3 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32))))} assume !(8529bv32 == #t~mem40);havoc #t~mem40;call #t~mem41 := read~intINTTYPE4(~s.base, ~bvadd32(52bv32, ~s.offset), 4bv32); {7044#(= (_ bv3 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32))))} is VALID [2018-11-23 11:00:44,951 INFO L273 TraceCheckUtils]: 46: Hoare triple {7044#(= (_ bv3 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32))))} assume !(8544bv32 == #t~mem41);havoc #t~mem41;call #t~mem42 := read~intINTTYPE4(~s.base, ~bvadd32(52bv32, ~s.offset), 4bv32); {7044#(= (_ bv3 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32))))} is VALID [2018-11-23 11:00:44,951 INFO L273 TraceCheckUtils]: 47: Hoare triple {7044#(= (_ bv3 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32))))} assume !(8545bv32 == #t~mem42);havoc #t~mem42;call #t~mem43 := read~intINTTYPE4(~s.base, ~bvadd32(52bv32, ~s.offset), 4bv32); {7044#(= (_ bv3 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32))))} is VALID [2018-11-23 11:00:44,952 INFO L273 TraceCheckUtils]: 48: Hoare triple {7044#(= (_ bv3 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32))))} assume !(8560bv32 == #t~mem43);havoc #t~mem43;call #t~mem44 := read~intINTTYPE4(~s.base, ~bvadd32(52bv32, ~s.offset), 4bv32); {7044#(= (_ bv3 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32))))} is VALID [2018-11-23 11:00:44,952 INFO L273 TraceCheckUtils]: 49: Hoare triple {7044#(= (_ bv3 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32))))} assume !(8561bv32 == #t~mem44);havoc #t~mem44;call #t~mem45 := read~intINTTYPE4(~s.base, ~bvadd32(52bv32, ~s.offset), 4bv32); {7044#(= (_ bv3 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32))))} is VALID [2018-11-23 11:00:44,953 INFO L273 TraceCheckUtils]: 50: Hoare triple {7044#(= (_ bv3 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32))))} assume !(8448bv32 == #t~mem45);havoc #t~mem45;call #t~mem46 := read~intINTTYPE4(~s.base, ~bvadd32(52bv32, ~s.offset), 4bv32); {7044#(= (_ bv3 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32))))} is VALID [2018-11-23 11:00:44,954 INFO L273 TraceCheckUtils]: 51: Hoare triple {7044#(= (_ bv3 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32))))} assume !(8576bv32 == #t~mem46);havoc #t~mem46;call #t~mem47 := read~intINTTYPE4(~s.base, ~bvadd32(52bv32, ~s.offset), 4bv32); {7044#(= (_ bv3 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32))))} is VALID [2018-11-23 11:00:44,954 INFO L273 TraceCheckUtils]: 52: Hoare triple {7044#(= (_ bv3 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32))))} assume !(8577bv32 == #t~mem47);havoc #t~mem47;call #t~mem48 := read~intINTTYPE4(~s.base, ~bvadd32(52bv32, ~s.offset), 4bv32); {7044#(= (_ bv3 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32))))} is VALID [2018-11-23 11:00:44,955 INFO L273 TraceCheckUtils]: 53: Hoare triple {7044#(= (_ bv3 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32))))} assume !(8592bv32 == #t~mem48);havoc #t~mem48;call #t~mem49 := read~intINTTYPE4(~s.base, ~bvadd32(52bv32, ~s.offset), 4bv32); {7044#(= (_ bv3 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32))))} is VALID [2018-11-23 11:00:44,955 INFO L273 TraceCheckUtils]: 54: Hoare triple {7044#(= (_ bv3 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32))))} assume !(8593bv32 == #t~mem49);havoc #t~mem49;call #t~mem50 := read~intINTTYPE4(~s.base, ~bvadd32(52bv32, ~s.offset), 4bv32); {7044#(= (_ bv3 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32))))} is VALID [2018-11-23 11:00:44,956 INFO L273 TraceCheckUtils]: 55: Hoare triple {7044#(= (_ bv3 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32))))} assume !(8608bv32 == #t~mem50);havoc #t~mem50;call #t~mem51 := read~intINTTYPE4(~s.base, ~bvadd32(52bv32, ~s.offset), 4bv32); {7044#(= (_ bv3 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32))))} is VALID [2018-11-23 11:00:44,957 INFO L273 TraceCheckUtils]: 56: Hoare triple {7044#(= (_ bv3 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32))))} assume !(8609bv32 == #t~mem51);havoc #t~mem51;call #t~mem52 := read~intINTTYPE4(~s.base, ~bvadd32(52bv32, ~s.offset), 4bv32); {7144#(= (bvadd |ssl3_accept_#t~mem52| (_ bv4294967293 32)) (_ bv0 32))} is VALID [2018-11-23 11:00:44,957 INFO L273 TraceCheckUtils]: 57: Hoare triple {7144#(= (bvadd |ssl3_accept_#t~mem52| (_ bv4294967293 32)) (_ bv0 32))} assume 8640bv32 == #t~mem52;havoc #t~mem52; {6971#false} is VALID [2018-11-23 11:00:44,958 INFO L273 TraceCheckUtils]: 58: Hoare triple {6971#false} ~ret~0 := #t~nondet115;havoc #t~nondet115; {6971#false} is VALID [2018-11-23 11:00:44,958 INFO L273 TraceCheckUtils]: 59: Hoare triple {6971#false} assume !(4bv32 == ~blastFlag~0); {6971#false} is VALID [2018-11-23 11:00:44,958 INFO L273 TraceCheckUtils]: 60: Hoare triple {6971#false} assume !(7bv32 == ~blastFlag~0); {6971#false} is VALID [2018-11-23 11:00:44,959 INFO L273 TraceCheckUtils]: 61: Hoare triple {6971#false} assume !false; {6971#false} is VALID [2018-11-23 11:00:44,965 INFO L134 CoverageAnalysis]: Checked inductivity of 10 backedges. 10 proven. 0 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2018-11-23 11:00:44,965 INFO L312 TraceCheckSpWp]: Omiting computation of backward sequence because forward sequence was already perfect [2018-11-23 11:00:44,967 INFO L312 seRefinementStrategy]: Constructing automaton from 1 perfect and 0 imperfect interpolant sequences. [2018-11-23 11:00:44,967 INFO L327 seRefinementStrategy]: Number of different interpolants: perfect sequences [4] imperfect sequences [] total 4 [2018-11-23 11:00:44,968 INFO L78 Accepts]: Start accepts. Automaton has 4 states. Word has length 62 [2018-11-23 11:00:44,968 INFO L84 Accepts]: Finished accepts. word is accepted. [2018-11-23 11:00:44,969 INFO L86 InductivityCheck]: Starting indutivity check of a Floyd-Hoare automaton with 4 states. [2018-11-23 11:00:45,081 INFO L119 InductivityCheck]: Floyd-Hoare automaton has 62 edges. 62 inductive. 0 not inductive. 0 times theorem prover too weak to decide inductivity. [2018-11-23 11:00:45,082 INFO L459 AbstractCegarLoop]: Interpolant automaton has 4 states [2018-11-23 11:00:45,082 INFO L142 InterpolantAutomaton]: Constructing interpolant automaton starting with 4 interpolants. [2018-11-23 11:00:45,082 INFO L144 InterpolantAutomaton]: CoverageRelationStatistics Valid=5, Invalid=7, Unknown=0, NotChecked=0, Total=12 [2018-11-23 11:00:45,083 INFO L87 Difference]: Start difference. First operand 212 states and 343 transitions. Second operand 4 states. [2018-11-23 11:01:06,425 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2018-11-23 11:01:06,425 INFO L93 Difference]: Finished difference Result 484 states and 775 transitions. [2018-11-23 11:01:06,425 INFO L142 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 4 states. [2018-11-23 11:01:06,425 INFO L78 Accepts]: Start accepts. Automaton has 4 states. Word has length 62 [2018-11-23 11:01:06,426 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2018-11-23 11:01:06,426 INFO L82 GeneralOperation]: Start removeUnreachable. Operand 4 states. [2018-11-23 11:01:06,431 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 4 states to 4 states and 573 transitions. [2018-11-23 11:01:06,431 INFO L82 GeneralOperation]: Start removeUnreachable. Operand 4 states. [2018-11-23 11:01:06,434 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 4 states to 4 states and 573 transitions. [2018-11-23 11:01:06,435 INFO L86 InductivityCheck]: Starting indutivity check of a Floyd-Hoare automaton with 4 states and 573 transitions. [2018-11-23 11:01:08,878 INFO L119 InductivityCheck]: Floyd-Hoare automaton has 573 edges. 573 inductive. 0 not inductive. 0 times theorem prover too weak to decide inductivity. [2018-11-23 11:01:08,888 INFO L225 Difference]: With dead ends: 484 [2018-11-23 11:01:08,888 INFO L226 Difference]: Without dead ends: 318 [2018-11-23 11:01:08,889 INFO L631 BasicCegarLoop]: 0 DeclaredPredicates, 62 GetRequests, 59 SyntacticMatches, 0 SemanticMatches, 3 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 0 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=9, Invalid=11, Unknown=0, NotChecked=0, Total=20 [2018-11-23 11:01:08,890 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 318 states. [2018-11-23 11:01:09,897 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 318 to 213. [2018-11-23 11:01:09,897 INFO L214 AbstractMinimizeNwa]: Start testing correctness of minimizeSevpa [2018-11-23 11:01:09,898 INFO L82 GeneralOperation]: Start isEquivalent. First operand 318 states. Second operand 213 states. [2018-11-23 11:01:09,898 INFO L74 IsIncluded]: Start isIncluded. First operand 318 states. Second operand 213 states. [2018-11-23 11:01:09,898 INFO L87 Difference]: Start difference. First operand 318 states. Second operand 213 states. [2018-11-23 11:01:09,907 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2018-11-23 11:01:09,907 INFO L93 Difference]: Finished difference Result 318 states and 506 transitions. [2018-11-23 11:01:09,908 INFO L276 IsEmpty]: Start isEmpty. Operand 318 states and 506 transitions. [2018-11-23 11:01:09,909 INFO L282 IsEmpty]: Finished isEmpty. No accepting run. [2018-11-23 11:01:09,909 INFO L83 IsIncluded]: Finished isIncluded. Language is included [2018-11-23 11:01:09,909 INFO L74 IsIncluded]: Start isIncluded. First operand 213 states. Second operand 318 states. [2018-11-23 11:01:09,909 INFO L87 Difference]: Start difference. First operand 213 states. Second operand 318 states. [2018-11-23 11:01:09,917 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2018-11-23 11:01:09,917 INFO L93 Difference]: Finished difference Result 318 states and 506 transitions. [2018-11-23 11:01:09,918 INFO L276 IsEmpty]: Start isEmpty. Operand 318 states and 506 transitions. [2018-11-23 11:01:09,918 INFO L282 IsEmpty]: Finished isEmpty. No accepting run. [2018-11-23 11:01:09,919 INFO L83 IsIncluded]: Finished isIncluded. Language is included [2018-11-23 11:01:09,919 INFO L88 GeneralOperation]: Finished isEquivalent. [2018-11-23 11:01:09,919 INFO L221 AbstractMinimizeNwa]: Finished testing correctness of minimizeSevpa [2018-11-23 11:01:09,919 INFO L82 GeneralOperation]: Start removeUnreachable. Operand 213 states. [2018-11-23 11:01:09,924 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 213 states to 213 states and 344 transitions. [2018-11-23 11:01:09,924 INFO L78 Accepts]: Start accepts. Automaton has 213 states and 344 transitions. Word has length 62 [2018-11-23 11:01:09,924 INFO L84 Accepts]: Finished accepts. word is rejected. [2018-11-23 11:01:09,924 INFO L480 AbstractCegarLoop]: Abstraction has 213 states and 344 transitions. [2018-11-23 11:01:09,924 INFO L481 AbstractCegarLoop]: Interpolant automaton has 4 states. [2018-11-23 11:01:09,924 INFO L276 IsEmpty]: Start isEmpty. Operand 213 states and 344 transitions. [2018-11-23 11:01:09,925 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 64 [2018-11-23 11:01:09,925 INFO L394 BasicCegarLoop]: Found error trace [2018-11-23 11:01:09,926 INFO L402 BasicCegarLoop]: trace histogram [2, 2, 2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2018-11-23 11:01:09,926 INFO L423 AbstractCegarLoop]: === Iteration 7 === [ssl3_acceptErr0ASSERT_VIOLATIONERROR_FUNCTION]=== [2018-11-23 11:01:09,926 INFO L141 PredicateUnifier]: Initialized classic predicate unifier [2018-11-23 11:01:09,926 INFO L82 PathProgramCache]: Analyzing trace with hash -165765159, now seen corresponding path program 1 times [2018-11-23 11:01:09,927 INFO L223 ckRefinementStrategy]: Switched to mode CVC4_FPBP [2018-11-23 11:01:09,927 INFO L69 tionRefinementEngine]: Using refinement strategy WolfRefinementStrategy No working directory specified, using /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/cvc4nyu Starting monitored process 8 with cvc4nyu --tear-down-incremental --print-success --lang smt --rewrite-divk (exit command is (exit), workingDir is null) Waiting until toolchain timeout for monitored process 8 with cvc4nyu --tear-down-incremental --print-success --lang smt --rewrite-divk [2018-11-23 11:01:09,959 INFO L103 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2018-11-23 11:01:10,216 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2018-11-23 11:01:10,299 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2018-11-23 11:01:10,301 INFO L273 TraceCheckSpWp]: Computing forward predicates... [2018-11-23 11:01:10,348 INFO L478 Elim1Store]: Elim1 did not use preprocessing eliminated variable of array dimension 2, 1 stores, 1 select indices, 1 select index equivalence classes, 0 disjoint index pairs (out of 0 index pairs), introduced 1 new quantified variables, introduced 0 case distinctions, treesize of input 23 treesize of output 20 [2018-11-23 11:01:10,357 INFO L478 Elim1Store]: Elim1 did not use preprocessing eliminated variable of array dimension 1, 1 stores, 0 select indices, 0 select index equivalence classes, 0 disjoint index pairs (out of 0 index pairs), introduced 1 new quantified variables, introduced 0 case distinctions, treesize of input 20 treesize of output 23 [2018-11-23 11:01:10,418 INFO L701 Elim1Store]: detected not equals via solver [2018-11-23 11:01:10,447 INFO L478 Elim1Store]: Elim1 did not use preprocessing eliminated variable of array dimension 1, 1 stores, 1 select indices, 1 select index equivalence classes, 1 disjoint index pairs (out of 0 index pairs), introduced 1 new quantified variables, introduced 0 case distinctions, treesize of input 23 treesize of output 33 [2018-11-23 11:01:10,493 INFO L701 Elim1Store]: detected not equals via solver [2018-11-23 11:01:10,500 INFO L478 Elim1Store]: Elim1 did not use preprocessing eliminated variable of array dimension 1, 1 stores, 2 select indices, 2 select index equivalence classes, 1 disjoint index pairs (out of 1 index pairs), introduced 0 new quantified variables, introduced 0 case distinctions, treesize of input 25 treesize of output 27 [2018-11-23 11:01:10,504 INFO L267 ElimStorePlain]: Start of recursive call 5: End of recursive call: and 1 xjuncts. [2018-11-23 11:01:10,516 INFO L267 ElimStorePlain]: Start of recursive call 4: 1 dim-1 vars, End of recursive call: and 1 xjuncts. [2018-11-23 11:01:10,526 INFO L267 ElimStorePlain]: Start of recursive call 3: 1 dim-1 vars, End of recursive call: and 1 xjuncts. [2018-11-23 11:01:10,538 INFO L267 ElimStorePlain]: Start of recursive call 2: 1 dim-1 vars, End of recursive call: and 1 xjuncts. [2018-11-23 11:01:10,553 INFO L267 ElimStorePlain]: Start of recursive call 1: 1 dim-0 vars, 1 dim-2 vars, End of recursive call: and 1 xjuncts. [2018-11-23 11:01:10,553 INFO L202 ElimStorePlain]: Needed 5 recursive calls to eliminate 2 variables, input treesize:27, output treesize:13 [2018-11-23 11:01:10,572 WARN L383 uantifierElimination]: Trying to double check SDD result, but SMT solver's response was UNKNOWN. [2018-11-23 11:01:10,572 WARN L384 uantifierElimination]: Input elimination task: ∃ [|v_#memory_int_191|, |v_ssl3_accept_#t~nondet17_7|]. (and (= ssl3_accept_~s.offset (_ bv0 32)) (= (store |v_#memory_int_191| ssl3_accept_~s.base (let ((.cse0 (bvadd ssl3_accept_~s.offset (_ bv52 32)))) (store (store (store (select |v_#memory_int_191| ssl3_accept_~s.base) .cse0 (_ bv8464 32)) (bvadd ssl3_accept_~s.offset (_ bv92 32)) |v_ssl3_accept_#t~nondet17_7|) .cse0 (_ bv8464 32)))) |#memory_int|)) [2018-11-23 11:01:10,573 WARN L385 uantifierElimination]: ElimStorePlain result: ∃ []. (and (= ssl3_accept_~s.offset (_ bv0 32)) (= (_ bv8464 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32))))) [2018-11-23 11:01:10,616 INFO L701 Elim1Store]: detected not equals via solver [2018-11-23 11:01:10,617 INFO L478 Elim1Store]: Elim1 did not use preprocessing eliminated variable of array dimension 2, 1 stores, 1 select indices, 1 select index equivalence classes, 1 disjoint index pairs (out of 0 index pairs), introduced 1 new quantified variables, introduced 0 case distinctions, treesize of input 31 treesize of output 38 [2018-11-23 11:01:10,626 INFO L701 Elim1Store]: detected not equals via solver [2018-11-23 11:01:10,629 INFO L701 Elim1Store]: detected not equals via solver [2018-11-23 11:01:10,633 INFO L478 Elim1Store]: Elim1 did not use preprocessing eliminated variable of array dimension 1, 1 stores, 2 select indices, 2 select index equivalence classes, 2 disjoint index pairs (out of 1 index pairs), introduced 1 new quantified variables, introduced 0 case distinctions, treesize of input 38 treesize of output 35 [2018-11-23 11:01:10,660 INFO L267 ElimStorePlain]: Start of recursive call 3: End of recursive call: and 1 xjuncts. [2018-11-23 11:01:10,666 INFO L267 ElimStorePlain]: Start of recursive call 2: 1 dim-1 vars, End of recursive call: and 1 xjuncts. [2018-11-23 11:01:10,674 INFO L267 ElimStorePlain]: Start of recursive call 1: 1 dim-2 vars, End of recursive call: and 1 xjuncts. [2018-11-23 11:01:10,675 INFO L202 ElimStorePlain]: Needed 3 recursive calls to eliminate 1 variables, input treesize:34, output treesize:13 [2018-11-23 11:01:12,690 WARN L383 uantifierElimination]: Trying to double check SDD result, but SMT solver's response was UNKNOWN. [2018-11-23 11:01:12,691 WARN L384 uantifierElimination]: Input elimination task: ∃ [|v_#memory_int_192|]. (let ((.cse0 (select |v_#memory_int_192| ssl3_accept_~s.base))) (and (= ssl3_accept_~s.offset (_ bv0 32)) (= (_ bv8464 32) (select .cse0 (bvadd ssl3_accept_~s.offset (_ bv52 32)))) (= (store |v_#memory_int_192| ssl3_accept_~s.base (let ((.cse1 (bvadd ssl3_accept_~s.offset (_ bv28 32)))) (store .cse0 .cse1 (bvadd (select .cse0 .cse1) (_ bv1 32))))) |#memory_int|))) [2018-11-23 11:01:12,691 WARN L385 uantifierElimination]: ElimStorePlain result: ∃ []. (and (= ssl3_accept_~s.offset (_ bv0 32)) (= (_ bv8464 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32))))) [2018-11-23 11:01:12,711 INFO L478 Elim1Store]: Elim1 did not use preprocessing eliminated variable of array dimension 2, 0 stores, 1 select indices, 1 select index equivalence classes, 0 disjoint index pairs (out of 0 index pairs), introduced 1 new quantified variables, introduced 0 case distinctions, treesize of input 17 treesize of output 13 [2018-11-23 11:01:12,715 INFO L478 Elim1Store]: Elim1 did not use preprocessing eliminated variable of array dimension 1, 0 stores, 1 select indices, 1 select index equivalence classes, 0 disjoint index pairs (out of 0 index pairs), introduced 0 new quantified variables, introduced 0 case distinctions, treesize of input 13 treesize of output 5 [2018-11-23 11:01:12,717 INFO L267 ElimStorePlain]: Start of recursive call 3: End of recursive call: and 1 xjuncts. [2018-11-23 11:01:12,720 INFO L267 ElimStorePlain]: Start of recursive call 2: 1 dim-1 vars, End of recursive call: and 1 xjuncts. [2018-11-23 11:01:12,722 INFO L267 ElimStorePlain]: Start of recursive call 1: 1 dim-0 vars, 1 dim-2 vars, End of recursive call: and 1 xjuncts. [2018-11-23 11:01:12,722 INFO L202 ElimStorePlain]: Needed 3 recursive calls to eliminate 2 variables, input treesize:17, output treesize:5 [2018-11-23 11:01:12,727 WARN L383 uantifierElimination]: Trying to double check SDD result, but SMT solver's response was UNKNOWN. [2018-11-23 11:01:12,727 WARN L384 uantifierElimination]: Input elimination task: ∃ [|#memory_int|, ssl3_accept_~s.base]. (let ((.cse0 (select (select |#memory_int| ssl3_accept_~s.base) (_ bv52 32)))) (and (= |ssl3_accept_#t~mem25| .cse0) (= (bvadd .cse0 (_ bv4294958832 32)) (_ bv0 32)))) [2018-11-23 11:01:12,727 WARN L385 uantifierElimination]: ElimStorePlain result: ∃ []. (= (_ bv0 32) (bvadd |ssl3_accept_#t~mem25| (_ bv4294958832 32))) [2018-11-23 11:01:12,799 INFO L256 TraceCheckUtils]: 0: Hoare triple {8605#true} call ULTIMATE.init(); {8605#true} is VALID [2018-11-23 11:01:12,800 INFO L273 TraceCheckUtils]: 1: Hoare triple {8605#true} #NULL.base, #NULL.offset := 0bv32, 0bv32;#valid := #valid[0bv32 := 0bv1];~init~0 := 1bv32;call ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset := #Ultimate.alloc(100bv32);call write~init~intINTTYPE4(0bv32, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset, 4bv32);call write~init~$Pointer$(0bv32, 0bv32, ~#SSLv3_server_data~0.base, ~bvadd32(4bv32, ~#SSLv3_server_data~0.offset), 4bv32);call write~init~$Pointer$(0bv32, 0bv32, ~#SSLv3_server_data~0.base, ~bvadd32(8bv32, ~#SSLv3_server_data~0.offset), 4bv32);call write~init~$Pointer$(0bv32, 0bv32, ~#SSLv3_server_data~0.base, ~bvadd32(12bv32, ~#SSLv3_server_data~0.offset), 4bv32);call write~init~$Pointer$(0bv32, 0bv32, ~#SSLv3_server_data~0.base, ~bvadd32(16bv32, ~#SSLv3_server_data~0.offset), 4bv32);call write~init~$Pointer$(0bv32, 0bv32, ~#SSLv3_server_data~0.base, ~bvadd32(20bv32, ~#SSLv3_server_data~0.offset), 4bv32);call write~init~$Pointer$(0bv32, 0bv32, ~#SSLv3_server_data~0.base, ~bvadd32(24bv32, ~#SSLv3_server_data~0.offset), 4bv32);call write~init~$Pointer$(0bv32, 0bv32, ~#SSLv3_server_data~0.base, ~bvadd32(28bv32, ~#SSLv3_server_data~0.offset), 4bv32);call write~init~$Pointer$(0bv32, 0bv32, ~#SSLv3_server_data~0.base, ~bvadd32(32bv32, ~#SSLv3_server_data~0.offset), 4bv32);call write~init~$Pointer$(0bv32, 0bv32, ~#SSLv3_server_data~0.base, ~bvadd32(36bv32, ~#SSLv3_server_data~0.offset), 4bv32);call write~init~$Pointer$(0bv32, 0bv32, ~#SSLv3_server_data~0.base, ~bvadd32(40bv32, ~#SSLv3_server_data~0.offset), 4bv32);call write~init~$Pointer$(0bv32, 0bv32, ~#SSLv3_server_data~0.base, ~bvadd32(44bv32, ~#SSLv3_server_data~0.offset), 4bv32);call write~init~$Pointer$(0bv32, 0bv32, ~#SSLv3_server_data~0.base, ~bvadd32(48bv32, ~#SSLv3_server_data~0.offset), 4bv32);call write~init~$Pointer$(0bv32, 0bv32, ~#SSLv3_server_data~0.base, ~bvadd32(52bv32, ~#SSLv3_server_data~0.offset), 4bv32);call write~init~$Pointer$(0bv32, 0bv32, ~#SSLv3_server_data~0.base, ~bvadd32(56bv32, ~#SSLv3_server_data~0.offset), 4bv32);call write~init~$Pointer$(0bv32, 0bv32, ~#SSLv3_server_data~0.base, ~bvadd32(60bv32, ~#SSLv3_server_data~0.offset), 4bv32);call write~init~$Pointer$(0bv32, 0bv32, ~#SSLv3_server_data~0.base, ~bvadd32(64bv32, ~#SSLv3_server_data~0.offset), 4bv32);call write~init~$Pointer$(0bv32, 0bv32, ~#SSLv3_server_data~0.base, ~bvadd32(68bv32, ~#SSLv3_server_data~0.offset), 4bv32);call write~init~$Pointer$(0bv32, 0bv32, ~#SSLv3_server_data~0.base, ~bvadd32(72bv32, ~#SSLv3_server_data~0.offset), 4bv32);call write~init~$Pointer$(0bv32, 0bv32, ~#SSLv3_server_data~0.base, ~bvadd32(76bv32, ~#SSLv3_server_data~0.offset), 4bv32);call write~init~$Pointer$(0bv32, 0bv32, ~#SSLv3_server_data~0.base, ~bvadd32(80bv32, ~#SSLv3_server_data~0.offset), 4bv32);call write~init~$Pointer$(0bv32, 0bv32, ~#SSLv3_server_data~0.base, ~bvadd32(84bv32, ~#SSLv3_server_data~0.offset), 4bv32);call write~init~$Pointer$(0bv32, 0bv32, ~#SSLv3_server_data~0.base, ~bvadd32(88bv32, ~#SSLv3_server_data~0.offset), 4bv32);call write~init~$Pointer$(0bv32, 0bv32, ~#SSLv3_server_data~0.base, ~bvadd32(92bv32, ~#SSLv3_server_data~0.offset), 4bv32);call write~init~$Pointer$(0bv32, 0bv32, ~#SSLv3_server_data~0.base, ~bvadd32(96bv32, ~#SSLv3_server_data~0.offset), 4bv32); {8605#true} is VALID [2018-11-23 11:01:12,800 INFO L273 TraceCheckUtils]: 2: Hoare triple {8605#true} assume true; {8605#true} is VALID [2018-11-23 11:01:12,800 INFO L268 TraceCheckUtils]: 3: Hoare quadruple {8605#true} {8605#true} #631#return; {8605#true} is VALID [2018-11-23 11:01:12,800 INFO L256 TraceCheckUtils]: 4: Hoare triple {8605#true} call #t~ret138 := main(); {8605#true} is VALID [2018-11-23 11:01:12,802 INFO L273 TraceCheckUtils]: 5: Hoare triple {8605#true} havoc ~s~0.base, ~s~0.offset;havoc ~tmp~2;call #t~malloc3.base, #t~malloc3.offset := #Ultimate.alloc(248bv32);~s~0.base, ~s~0.offset := #t~malloc3.base, #t~malloc3.offset;call #t~malloc4.base, #t~malloc4.offset := #Ultimate.alloc(899bv32);call write~$Pointer$(#t~malloc4.base, #t~malloc4.offset, ~s~0.base, ~bvadd32(84bv32, ~s~0.offset), 4bv32);call #t~malloc5.base, #t~malloc5.offset := #Ultimate.alloc(232bv32);call write~$Pointer$(#t~malloc5.base, #t~malloc5.offset, ~s~0.base, ~bvadd32(204bv32, ~s~0.offset), 4bv32);call #t~malloc6.base, #t~malloc6.offset := #Ultimate.alloc(200bv32);call write~$Pointer$(#t~malloc6.base, #t~malloc6.offset, ~s~0.base, ~bvadd32(176bv32, ~s~0.offset), 4bv32); {8625#(= main_~s~0.offset (_ bv0 32))} is VALID [2018-11-23 11:01:12,803 INFO L256 TraceCheckUtils]: 6: Hoare triple {8625#(= main_~s~0.offset (_ bv0 32))} call #t~ret7 := ssl3_accept(~s~0.base, ~s~0.offset); {8629#(= (_ bv0 32) |ssl3_accept_#in~s.offset|)} is VALID [2018-11-23 11:01:12,810 INFO L273 TraceCheckUtils]: 7: Hoare triple {8629#(= (_ bv0 32) |ssl3_accept_#in~s.offset|)} ~s.base, ~s.offset := #in~s.base, #in~s.offset;havoc ~buf~0.base, ~buf~0.offset;havoc ~l~0;havoc ~Time~0;havoc ~tmp~3;havoc ~cb~0.base, ~cb~0.offset;havoc ~num1~0;havoc ~ret~0;havoc ~new_state~0;havoc ~state~0;havoc ~skip~0;havoc ~got_new_session~0;~tmp___1~0 := #t~nondet8;havoc #t~nondet8;~tmp___2~0 := #t~nondet9;havoc #t~nondet9;~tmp___3~0 := #t~nondet10;havoc #t~nondet10;~tmp___4~0 := #t~nondet11;havoc #t~nondet11;~tmp___5~0 := #t~nondet12;havoc #t~nondet12;~tmp___6~0 := #t~nondet13;havoc #t~nondet13;havoc ~tmp___7~0;~tmp___8~0 := #t~nondet14;havoc #t~nondet14;~tmp___9~0 := #t~nondet15;havoc #t~nondet15;~tmp___10~0 := #t~nondet16;havoc #t~nondet16;havoc ~blastFlag~0;call write~intINTTYPE4(8464bv32, ~s.base, ~bvadd32(52bv32, ~s.offset), 4bv32);~blastFlag~0 := 0bv32;call write~intINTTYPE4(#t~nondet17, ~s.base, ~bvadd32(92bv32, ~s.offset), 4bv32);havoc #t~nondet17;call write~intINTTYPE4(8464bv32, ~s.base, ~bvadd32(52bv32, ~s.offset), 4bv32);~tmp~3 := #t~nondet18;havoc #t~nondet18;~Time~0 := ~tmp~3;~cb~0.base, ~cb~0.offset := 0bv32, 0bv32;~ret~0 := 4294967295bv32;~skip~0 := 0bv32;~got_new_session~0 := 0bv32;call #t~mem19.base, #t~mem19.offset := read~$Pointer$(~s.base, ~bvadd32(192bv32, ~s.offset), 4bv32); {8633#(and (= ssl3_accept_~s.offset (_ bv0 32)) (= (_ bv8464 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32)))))} is VALID [2018-11-23 11:01:12,811 INFO L273 TraceCheckUtils]: 8: Hoare triple {8633#(and (= ssl3_accept_~s.offset (_ bv0 32)) (= (_ bv8464 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32)))))} assume 0bv32 != ~bvadd32(#t~mem19.base, #t~mem19.offset);havoc #t~mem19.base, #t~mem19.offset;call #t~mem20.base, #t~mem20.offset := read~$Pointer$(~s.base, ~bvadd32(192bv32, ~s.offset), 4bv32);~cb~0.base, ~cb~0.offset := #t~mem20.base, #t~mem20.offset;havoc #t~mem20.base, #t~mem20.offset; {8633#(and (= ssl3_accept_~s.offset (_ bv0 32)) (= (_ bv8464 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32)))))} is VALID [2018-11-23 11:01:12,813 INFO L273 TraceCheckUtils]: 9: Hoare triple {8633#(and (= ssl3_accept_~s.offset (_ bv0 32)) (= (_ bv8464 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32)))))} call #t~mem21 := read~intINTTYPE4(~s.base, ~bvadd32(28bv32, ~s.offset), 4bv32);call write~intINTTYPE4(~bvadd32(1bv32, #t~mem21), ~s.base, ~bvadd32(28bv32, ~s.offset), 4bv32);havoc #t~mem21; {8633#(and (= ssl3_accept_~s.offset (_ bv0 32)) (= (_ bv8464 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32)))))} is VALID [2018-11-23 11:01:12,814 INFO L273 TraceCheckUtils]: 10: Hoare triple {8633#(and (= ssl3_accept_~s.offset (_ bv0 32)) (= (_ bv8464 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32)))))} assume !(0bv32 != ~bvand32(12288bv32, ~tmp___1~0)); {8633#(and (= ssl3_accept_~s.offset (_ bv0 32)) (= (_ bv8464 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32)))))} is VALID [2018-11-23 11:01:12,815 INFO L273 TraceCheckUtils]: 11: Hoare triple {8633#(and (= ssl3_accept_~s.offset (_ bv0 32)) (= (_ bv8464 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32)))))} call #t~mem22.base, #t~mem22.offset := read~$Pointer$(~s.base, ~bvadd32(136bv32, ~s.offset), 4bv32); {8633#(and (= ssl3_accept_~s.offset (_ bv0 32)) (= (_ bv8464 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32)))))} is VALID [2018-11-23 11:01:12,815 INFO L273 TraceCheckUtils]: 12: Hoare triple {8633#(and (= ssl3_accept_~s.offset (_ bv0 32)) (= (_ bv8464 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32)))))} assume !(0bv32 == ~bvadd32(#t~mem22.base, #t~mem22.offset));havoc #t~mem22.base, #t~mem22.offset; {8633#(and (= ssl3_accept_~s.offset (_ bv0 32)) (= (_ bv8464 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32)))))} is VALID [2018-11-23 11:01:12,816 INFO L273 TraceCheckUtils]: 13: Hoare triple {8633#(and (= ssl3_accept_~s.offset (_ bv0 32)) (= (_ bv8464 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32)))))} assume !false; {8633#(and (= ssl3_accept_~s.offset (_ bv0 32)) (= (_ bv8464 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32)))))} is VALID [2018-11-23 11:01:12,816 INFO L273 TraceCheckUtils]: 14: Hoare triple {8633#(and (= ssl3_accept_~s.offset (_ bv0 32)) (= (_ bv8464 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32)))))} call #t~mem23 := read~intINTTYPE4(~s.base, ~bvadd32(52bv32, ~s.offset), 4bv32);~state~0 := #t~mem23;havoc #t~mem23;call #t~mem24 := read~intINTTYPE4(~s.base, ~bvadd32(52bv32, ~s.offset), 4bv32); {8633#(and (= ssl3_accept_~s.offset (_ bv0 32)) (= (_ bv8464 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32)))))} is VALID [2018-11-23 11:01:12,817 INFO L273 TraceCheckUtils]: 15: Hoare triple {8633#(and (= ssl3_accept_~s.offset (_ bv0 32)) (= (_ bv8464 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32)))))} assume !(12292bv32 == #t~mem24);havoc #t~mem24;call #t~mem25 := read~intINTTYPE4(~s.base, ~bvadd32(52bv32, ~s.offset), 4bv32); {8658#(= (_ bv8464 32) |ssl3_accept_#t~mem25|)} is VALID [2018-11-23 11:01:12,817 INFO L273 TraceCheckUtils]: 16: Hoare triple {8658#(= (_ bv8464 32) |ssl3_accept_#t~mem25|)} assume 16384bv32 == #t~mem25;havoc #t~mem25; {8606#false} is VALID [2018-11-23 11:01:12,818 INFO L273 TraceCheckUtils]: 17: Hoare triple {8606#false} call write~intINTTYPE4(1bv32, ~s.base, ~bvadd32(36bv32, ~s.offset), 4bv32); {8606#false} is VALID [2018-11-23 11:01:12,818 INFO L273 TraceCheckUtils]: 18: Hoare triple {8606#false} assume 0bv32 != ~bvadd32(~cb~0.base, ~cb~0.offset); {8606#false} is VALID [2018-11-23 11:01:12,818 INFO L273 TraceCheckUtils]: 19: Hoare triple {8606#false} call #t~mem59 := read~intINTTYPE4(~s.base, ~s.offset, 4bv32); {8606#false} is VALID [2018-11-23 11:01:12,818 INFO L273 TraceCheckUtils]: 20: Hoare triple {8606#false} assume !(3bv32 != ~bvashr32(#t~mem59, 8bv32));havoc #t~mem59;call write~intINTTYPE4(8192bv32, ~s.base, ~bvadd32(4bv32, ~s.offset), 4bv32);call #t~mem60.base, #t~mem60.offset := read~$Pointer$(~s.base, ~bvadd32(60bv32, ~s.offset), 4bv32); {8606#false} is VALID [2018-11-23 11:01:12,819 INFO L273 TraceCheckUtils]: 21: Hoare triple {8606#false} assume !(0bv32 == ~bvadd32(#t~mem60.base, #t~mem60.offset));havoc #t~mem60.base, #t~mem60.offset; {8606#false} is VALID [2018-11-23 11:01:12,819 INFO L273 TraceCheckUtils]: 22: Hoare triple {8606#false} assume !(0bv32 == ~tmp___4~0);call write~intINTTYPE4(0bv32, ~s.base, ~bvadd32(64bv32, ~s.offset), 4bv32);call #t~mem62 := read~intINTTYPE4(~s.base, ~bvadd32(52bv32, ~s.offset), 4bv32); {8606#false} is VALID [2018-11-23 11:01:12,819 INFO L273 TraceCheckUtils]: 23: Hoare triple {8606#false} assume 12292bv32 != #t~mem62;havoc #t~mem62; {8606#false} is VALID [2018-11-23 11:01:12,819 INFO L273 TraceCheckUtils]: 24: Hoare triple {8606#false} assume !(0bv32 == ~tmp___5~0);call write~intINTTYPE4(8464bv32, ~s.base, ~bvadd32(52bv32, ~s.offset), 4bv32);call #t~mem63.base, #t~mem63.offset := read~$Pointer$(~s.base, ~bvadd32(204bv32, ~s.offset), 4bv32);call #t~mem64 := read~intINTTYPE4(#t~mem63.base, ~bvadd32(72bv32, #t~mem63.offset), 4bv32);call write~intINTTYPE4(~bvadd32(1bv32, #t~mem64), #t~mem63.base, ~bvadd32(72bv32, #t~mem63.offset), 4bv32);havoc #t~mem63.base, #t~mem63.offset;havoc #t~mem64; {8606#false} is VALID [2018-11-23 11:01:12,820 INFO L273 TraceCheckUtils]: 25: Hoare triple {8606#false} call #t~mem127.base, #t~mem127.offset := read~$Pointer$(~s.base, ~bvadd32(84bv32, ~s.offset), 4bv32);call #t~mem128 := read~intINTTYPE4(#t~mem127.base, ~bvadd32(848bv32, #t~mem127.offset), 4bv32); {8606#false} is VALID [2018-11-23 11:01:12,820 INFO L273 TraceCheckUtils]: 26: Hoare triple {8606#false} assume !(0bv32 == #t~mem128);havoc #t~mem127.base, #t~mem127.offset;havoc #t~mem128; {8606#false} is VALID [2018-11-23 11:01:12,820 INFO L273 TraceCheckUtils]: 27: Hoare triple {8606#false} ~skip~0 := 0bv32; {8606#false} is VALID [2018-11-23 11:01:12,820 INFO L273 TraceCheckUtils]: 28: Hoare triple {8606#false} assume !false; {8606#false} is VALID [2018-11-23 11:01:12,820 INFO L273 TraceCheckUtils]: 29: Hoare triple {8606#false} call #t~mem23 := read~intINTTYPE4(~s.base, ~bvadd32(52bv32, ~s.offset), 4bv32);~state~0 := #t~mem23;havoc #t~mem23;call #t~mem24 := read~intINTTYPE4(~s.base, ~bvadd32(52bv32, ~s.offset), 4bv32); {8606#false} is VALID [2018-11-23 11:01:12,821 INFO L273 TraceCheckUtils]: 30: Hoare triple {8606#false} assume !(12292bv32 == #t~mem24);havoc #t~mem24;call #t~mem25 := read~intINTTYPE4(~s.base, ~bvadd32(52bv32, ~s.offset), 4bv32); {8606#false} is VALID [2018-11-23 11:01:12,821 INFO L273 TraceCheckUtils]: 31: Hoare triple {8606#false} assume !(16384bv32 == #t~mem25);havoc #t~mem25;call #t~mem26 := read~intINTTYPE4(~s.base, ~bvadd32(52bv32, ~s.offset), 4bv32); {8606#false} is VALID [2018-11-23 11:01:12,821 INFO L273 TraceCheckUtils]: 32: Hoare triple {8606#false} assume !(8192bv32 == #t~mem26);havoc #t~mem26;call #t~mem27 := read~intINTTYPE4(~s.base, ~bvadd32(52bv32, ~s.offset), 4bv32); {8606#false} is VALID [2018-11-23 11:01:12,821 INFO L273 TraceCheckUtils]: 33: Hoare triple {8606#false} assume !(24576bv32 == #t~mem27);havoc #t~mem27;call #t~mem28 := read~intINTTYPE4(~s.base, ~bvadd32(52bv32, ~s.offset), 4bv32); {8606#false} is VALID [2018-11-23 11:01:12,821 INFO L273 TraceCheckUtils]: 34: Hoare triple {8606#false} assume !(8195bv32 == #t~mem28);havoc #t~mem28;call #t~mem29 := read~intINTTYPE4(~s.base, ~bvadd32(52bv32, ~s.offset), 4bv32); {8606#false} is VALID [2018-11-23 11:01:12,821 INFO L273 TraceCheckUtils]: 35: Hoare triple {8606#false} assume !(8480bv32 == #t~mem29);havoc #t~mem29;call #t~mem30 := read~intINTTYPE4(~s.base, ~bvadd32(52bv32, ~s.offset), 4bv32); {8606#false} is VALID [2018-11-23 11:01:12,821 INFO L273 TraceCheckUtils]: 36: Hoare triple {8606#false} assume !(8481bv32 == #t~mem30);havoc #t~mem30;call #t~mem31 := read~intINTTYPE4(~s.base, ~bvadd32(52bv32, ~s.offset), 4bv32); {8606#false} is VALID [2018-11-23 11:01:12,822 INFO L273 TraceCheckUtils]: 37: Hoare triple {8606#false} assume !(8482bv32 == #t~mem31);havoc #t~mem31;call #t~mem32 := read~intINTTYPE4(~s.base, ~bvadd32(52bv32, ~s.offset), 4bv32); {8606#false} is VALID [2018-11-23 11:01:12,822 INFO L273 TraceCheckUtils]: 38: Hoare triple {8606#false} assume !(8464bv32 == #t~mem32);havoc #t~mem32;call #t~mem33 := read~intINTTYPE4(~s.base, ~bvadd32(52bv32, ~s.offset), 4bv32); {8606#false} is VALID [2018-11-23 11:01:12,822 INFO L273 TraceCheckUtils]: 39: Hoare triple {8606#false} assume !(8465bv32 == #t~mem33);havoc #t~mem33;call #t~mem34 := read~intINTTYPE4(~s.base, ~bvadd32(52bv32, ~s.offset), 4bv32); {8606#false} is VALID [2018-11-23 11:01:12,822 INFO L273 TraceCheckUtils]: 40: Hoare triple {8606#false} assume !(8466bv32 == #t~mem34);havoc #t~mem34;call #t~mem35 := read~intINTTYPE4(~s.base, ~bvadd32(52bv32, ~s.offset), 4bv32); {8606#false} is VALID [2018-11-23 11:01:12,822 INFO L273 TraceCheckUtils]: 41: Hoare triple {8606#false} assume !(8496bv32 == #t~mem35);havoc #t~mem35;call #t~mem36 := read~intINTTYPE4(~s.base, ~bvadd32(52bv32, ~s.offset), 4bv32); {8606#false} is VALID [2018-11-23 11:01:12,823 INFO L273 TraceCheckUtils]: 42: Hoare triple {8606#false} assume !(8497bv32 == #t~mem36);havoc #t~mem36;call #t~mem37 := read~intINTTYPE4(~s.base, ~bvadd32(52bv32, ~s.offset), 4bv32); {8606#false} is VALID [2018-11-23 11:01:12,823 INFO L273 TraceCheckUtils]: 43: Hoare triple {8606#false} assume !(8512bv32 == #t~mem37);havoc #t~mem37;call #t~mem38 := read~intINTTYPE4(~s.base, ~bvadd32(52bv32, ~s.offset), 4bv32); {8606#false} is VALID [2018-11-23 11:01:12,823 INFO L273 TraceCheckUtils]: 44: Hoare triple {8606#false} assume !(8513bv32 == #t~mem38);havoc #t~mem38;call #t~mem39 := read~intINTTYPE4(~s.base, ~bvadd32(52bv32, ~s.offset), 4bv32); {8606#false} is VALID [2018-11-23 11:01:12,823 INFO L273 TraceCheckUtils]: 45: Hoare triple {8606#false} assume !(8528bv32 == #t~mem39);havoc #t~mem39;call #t~mem40 := read~intINTTYPE4(~s.base, ~bvadd32(52bv32, ~s.offset), 4bv32); {8606#false} is VALID [2018-11-23 11:01:12,824 INFO L273 TraceCheckUtils]: 46: Hoare triple {8606#false} assume !(8529bv32 == #t~mem40);havoc #t~mem40;call #t~mem41 := read~intINTTYPE4(~s.base, ~bvadd32(52bv32, ~s.offset), 4bv32); {8606#false} is VALID [2018-11-23 11:01:12,824 INFO L273 TraceCheckUtils]: 47: Hoare triple {8606#false} assume !(8544bv32 == #t~mem41);havoc #t~mem41;call #t~mem42 := read~intINTTYPE4(~s.base, ~bvadd32(52bv32, ~s.offset), 4bv32); {8606#false} is VALID [2018-11-23 11:01:12,824 INFO L273 TraceCheckUtils]: 48: Hoare triple {8606#false} assume !(8545bv32 == #t~mem42);havoc #t~mem42;call #t~mem43 := read~intINTTYPE4(~s.base, ~bvadd32(52bv32, ~s.offset), 4bv32); {8606#false} is VALID [2018-11-23 11:01:12,824 INFO L273 TraceCheckUtils]: 49: Hoare triple {8606#false} assume !(8560bv32 == #t~mem43);havoc #t~mem43;call #t~mem44 := read~intINTTYPE4(~s.base, ~bvadd32(52bv32, ~s.offset), 4bv32); {8606#false} is VALID [2018-11-23 11:01:12,824 INFO L273 TraceCheckUtils]: 50: Hoare triple {8606#false} assume !(8561bv32 == #t~mem44);havoc #t~mem44;call #t~mem45 := read~intINTTYPE4(~s.base, ~bvadd32(52bv32, ~s.offset), 4bv32); {8606#false} is VALID [2018-11-23 11:01:12,825 INFO L273 TraceCheckUtils]: 51: Hoare triple {8606#false} assume !(8448bv32 == #t~mem45);havoc #t~mem45;call #t~mem46 := read~intINTTYPE4(~s.base, ~bvadd32(52bv32, ~s.offset), 4bv32); {8606#false} is VALID [2018-11-23 11:01:12,825 INFO L273 TraceCheckUtils]: 52: Hoare triple {8606#false} assume !(8576bv32 == #t~mem46);havoc #t~mem46;call #t~mem47 := read~intINTTYPE4(~s.base, ~bvadd32(52bv32, ~s.offset), 4bv32); {8606#false} is VALID [2018-11-23 11:01:12,825 INFO L273 TraceCheckUtils]: 53: Hoare triple {8606#false} assume !(8577bv32 == #t~mem47);havoc #t~mem47;call #t~mem48 := read~intINTTYPE4(~s.base, ~bvadd32(52bv32, ~s.offset), 4bv32); {8606#false} is VALID [2018-11-23 11:01:12,825 INFO L273 TraceCheckUtils]: 54: Hoare triple {8606#false} assume !(8592bv32 == #t~mem48);havoc #t~mem48;call #t~mem49 := read~intINTTYPE4(~s.base, ~bvadd32(52bv32, ~s.offset), 4bv32); {8606#false} is VALID [2018-11-23 11:01:12,825 INFO L273 TraceCheckUtils]: 55: Hoare triple {8606#false} assume !(8593bv32 == #t~mem49);havoc #t~mem49;call #t~mem50 := read~intINTTYPE4(~s.base, ~bvadd32(52bv32, ~s.offset), 4bv32); {8606#false} is VALID [2018-11-23 11:01:12,826 INFO L273 TraceCheckUtils]: 56: Hoare triple {8606#false} assume !(8608bv32 == #t~mem50);havoc #t~mem50;call #t~mem51 := read~intINTTYPE4(~s.base, ~bvadd32(52bv32, ~s.offset), 4bv32); {8606#false} is VALID [2018-11-23 11:01:12,826 INFO L273 TraceCheckUtils]: 57: Hoare triple {8606#false} assume !(8609bv32 == #t~mem51);havoc #t~mem51;call #t~mem52 := read~intINTTYPE4(~s.base, ~bvadd32(52bv32, ~s.offset), 4bv32); {8606#false} is VALID [2018-11-23 11:01:12,826 INFO L273 TraceCheckUtils]: 58: Hoare triple {8606#false} assume 8640bv32 == #t~mem52;havoc #t~mem52; {8606#false} is VALID [2018-11-23 11:01:12,826 INFO L273 TraceCheckUtils]: 59: Hoare triple {8606#false} ~ret~0 := #t~nondet115;havoc #t~nondet115; {8606#false} is VALID [2018-11-23 11:01:12,826 INFO L273 TraceCheckUtils]: 60: Hoare triple {8606#false} assume !(4bv32 == ~blastFlag~0); {8606#false} is VALID [2018-11-23 11:01:12,827 INFO L273 TraceCheckUtils]: 61: Hoare triple {8606#false} assume !(7bv32 == ~blastFlag~0); {8606#false} is VALID [2018-11-23 11:01:12,827 INFO L273 TraceCheckUtils]: 62: Hoare triple {8606#false} assume !false; {8606#false} is VALID [2018-11-23 11:01:12,830 INFO L134 CoverageAnalysis]: Checked inductivity of 4 backedges. 4 proven. 0 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2018-11-23 11:01:12,831 INFO L312 TraceCheckSpWp]: Omiting computation of backward sequence because forward sequence was already perfect [2018-11-23 11:01:12,833 INFO L312 seRefinementStrategy]: Constructing automaton from 1 perfect and 0 imperfect interpolant sequences. [2018-11-23 11:01:12,835 INFO L327 seRefinementStrategy]: Number of different interpolants: perfect sequences [6] imperfect sequences [] total 6 [2018-11-23 11:01:12,835 INFO L78 Accepts]: Start accepts. Automaton has 6 states. Word has length 63 [2018-11-23 11:01:12,835 INFO L84 Accepts]: Finished accepts. word is accepted. [2018-11-23 11:01:12,836 INFO L86 InductivityCheck]: Starting indutivity check of a Floyd-Hoare automaton with 6 states. [2018-11-23 11:01:12,949 INFO L119 InductivityCheck]: Floyd-Hoare automaton has 63 edges. 63 inductive. 0 not inductive. 0 times theorem prover too weak to decide inductivity. [2018-11-23 11:01:12,949 INFO L459 AbstractCegarLoop]: Interpolant automaton has 6 states [2018-11-23 11:01:12,950 INFO L142 InterpolantAutomaton]: Constructing interpolant automaton starting with 6 interpolants. [2018-11-23 11:01:12,950 INFO L144 InterpolantAutomaton]: CoverageRelationStatistics Valid=9, Invalid=21, Unknown=0, NotChecked=0, Total=30 [2018-11-23 11:01:12,950 INFO L87 Difference]: Start difference. First operand 213 states and 344 transitions. Second operand 6 states. [2018-11-23 11:01:31,639 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2018-11-23 11:01:31,640 INFO L93 Difference]: Finished difference Result 436 states and 690 transitions. [2018-11-23 11:01:31,640 INFO L142 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 6 states. [2018-11-23 11:01:31,640 INFO L78 Accepts]: Start accepts. Automaton has 6 states. Word has length 63 [2018-11-23 11:01:31,640 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2018-11-23 11:01:31,640 INFO L82 GeneralOperation]: Start removeUnreachable. Operand 6 states. [2018-11-23 11:01:31,644 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 6 states to 6 states and 544 transitions. [2018-11-23 11:01:31,644 INFO L82 GeneralOperation]: Start removeUnreachable. Operand 6 states. [2018-11-23 11:01:31,647 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 6 states to 6 states and 544 transitions. [2018-11-23 11:01:31,647 INFO L86 InductivityCheck]: Starting indutivity check of a Floyd-Hoare automaton with 6 states and 544 transitions. [2018-11-23 11:01:32,652 INFO L119 InductivityCheck]: Floyd-Hoare automaton has 544 edges. 544 inductive. 0 not inductive. 0 times theorem prover too weak to decide inductivity. [2018-11-23 11:01:32,660 INFO L225 Difference]: With dead ends: 436 [2018-11-23 11:01:32,660 INFO L226 Difference]: Without dead ends: 269 [2018-11-23 11:01:32,661 INFO L631 BasicCegarLoop]: 0 DeclaredPredicates, 64 GetRequests, 58 SyntacticMatches, 0 SemanticMatches, 6 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 0 ImplicationChecksByTransitivity, 0.1s TimeCoverageRelationStatistics Valid=19, Invalid=37, Unknown=0, NotChecked=0, Total=56 [2018-11-23 11:01:32,661 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 269 states. [2018-11-23 11:01:32,878 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 269 to 213. [2018-11-23 11:01:32,879 INFO L214 AbstractMinimizeNwa]: Start testing correctness of minimizeSevpa [2018-11-23 11:01:32,879 INFO L82 GeneralOperation]: Start isEquivalent. First operand 269 states. Second operand 213 states. [2018-11-23 11:01:32,879 INFO L74 IsIncluded]: Start isIncluded. First operand 269 states. Second operand 213 states. [2018-11-23 11:01:32,879 INFO L87 Difference]: Start difference. First operand 269 states. Second operand 213 states. [2018-11-23 11:01:32,885 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2018-11-23 11:01:32,885 INFO L93 Difference]: Finished difference Result 269 states and 420 transitions. [2018-11-23 11:01:32,885 INFO L276 IsEmpty]: Start isEmpty. Operand 269 states and 420 transitions. [2018-11-23 11:01:32,886 INFO L282 IsEmpty]: Finished isEmpty. No accepting run. [2018-11-23 11:01:32,886 INFO L83 IsIncluded]: Finished isIncluded. Language is included [2018-11-23 11:01:32,887 INFO L74 IsIncluded]: Start isIncluded. First operand 213 states. Second operand 269 states. [2018-11-23 11:01:32,887 INFO L87 Difference]: Start difference. First operand 213 states. Second operand 269 states. [2018-11-23 11:01:32,893 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2018-11-23 11:01:32,894 INFO L93 Difference]: Finished difference Result 269 states and 420 transitions. [2018-11-23 11:01:32,894 INFO L276 IsEmpty]: Start isEmpty. Operand 269 states and 420 transitions. [2018-11-23 11:01:32,895 INFO L282 IsEmpty]: Finished isEmpty. No accepting run. [2018-11-23 11:01:32,895 INFO L83 IsIncluded]: Finished isIncluded. Language is included [2018-11-23 11:01:32,895 INFO L88 GeneralOperation]: Finished isEquivalent. [2018-11-23 11:01:32,895 INFO L221 AbstractMinimizeNwa]: Finished testing correctness of minimizeSevpa [2018-11-23 11:01:32,895 INFO L82 GeneralOperation]: Start removeUnreachable. Operand 213 states. [2018-11-23 11:01:32,900 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 213 states to 213 states and 343 transitions. [2018-11-23 11:01:32,900 INFO L78 Accepts]: Start accepts. Automaton has 213 states and 343 transitions. Word has length 63 [2018-11-23 11:01:32,900 INFO L84 Accepts]: Finished accepts. word is rejected. [2018-11-23 11:01:32,901 INFO L480 AbstractCegarLoop]: Abstraction has 213 states and 343 transitions. [2018-11-23 11:01:32,901 INFO L481 AbstractCegarLoop]: Interpolant automaton has 6 states. [2018-11-23 11:01:32,901 INFO L276 IsEmpty]: Start isEmpty. Operand 213 states and 343 transitions. [2018-11-23 11:01:32,902 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 64 [2018-11-23 11:01:32,902 INFO L394 BasicCegarLoop]: Found error trace [2018-11-23 11:01:32,902 INFO L402 BasicCegarLoop]: trace histogram [2, 2, 2, 2, 2, 2, 2, 2, 2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2018-11-23 11:01:32,902 INFO L423 AbstractCegarLoop]: === Iteration 8 === [ssl3_acceptErr0ASSERT_VIOLATIONERROR_FUNCTION]=== [2018-11-23 11:01:32,902 INFO L141 PredicateUnifier]: Initialized classic predicate unifier [2018-11-23 11:01:32,903 INFO L82 PathProgramCache]: Analyzing trace with hash -555600636, now seen corresponding path program 1 times [2018-11-23 11:01:32,903 INFO L223 ckRefinementStrategy]: Switched to mode CVC4_FPBP [2018-11-23 11:01:32,903 INFO L69 tionRefinementEngine]: Using refinement strategy WolfRefinementStrategy No working directory specified, using /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/cvc4nyu Starting monitored process 9 with cvc4nyu --tear-down-incremental --print-success --lang smt --rewrite-divk (exit command is (exit), workingDir is null) Waiting until toolchain timeout for monitored process 9 with cvc4nyu --tear-down-incremental --print-success --lang smt --rewrite-divk [2018-11-23 11:01:32,933 INFO L103 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2018-11-23 11:01:33,098 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2018-11-23 11:01:33,140 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2018-11-23 11:01:33,143 INFO L273 TraceCheckSpWp]: Computing forward predicates... [2018-11-23 11:01:33,190 INFO L478 Elim1Store]: Elim1 did not use preprocessing eliminated variable of array dimension 2, 1 stores, 1 select indices, 1 select index equivalence classes, 0 disjoint index pairs (out of 0 index pairs), introduced 1 new quantified variables, introduced 0 case distinctions, treesize of input 13 treesize of output 10 [2018-11-23 11:01:33,196 INFO L478 Elim1Store]: Elim1 did not use preprocessing eliminated variable of array dimension 1, 1 stores, 0 select indices, 0 select index equivalence classes, 0 disjoint index pairs (out of 0 index pairs), introduced 0 new quantified variables, introduced 0 case distinctions, treesize of input 10 treesize of output 9 [2018-11-23 11:01:33,198 INFO L267 ElimStorePlain]: Start of recursive call 3: End of recursive call: and 1 xjuncts. [2018-11-23 11:01:33,203 INFO L267 ElimStorePlain]: Start of recursive call 2: 1 dim-1 vars, End of recursive call: and 1 xjuncts. [2018-11-23 11:01:33,209 INFO L267 ElimStorePlain]: Start of recursive call 1: 1 dim-2 vars, End of recursive call: and 1 xjuncts. [2018-11-23 11:01:33,209 INFO L202 ElimStorePlain]: Needed 3 recursive calls to eliminate 1 variables, input treesize:13, output treesize:9 [2018-11-23 11:01:33,274 INFO L478 Elim1Store]: Elim1 did not use preprocessing eliminated variable of array dimension 2, 0 stores, 1 select indices, 1 select index equivalence classes, 0 disjoint index pairs (out of 0 index pairs), introduced 1 new quantified variables, introduced 0 case distinctions, treesize of input 19 treesize of output 15 [2018-11-23 11:01:33,281 INFO L478 Elim1Store]: Elim1 did not use preprocessing eliminated variable of array dimension 1, 0 stores, 1 select indices, 1 select index equivalence classes, 0 disjoint index pairs (out of 0 index pairs), introduced 0 new quantified variables, introduced 0 case distinctions, treesize of input 15 treesize of output 3 [2018-11-23 11:01:33,282 INFO L267 ElimStorePlain]: Start of recursive call 3: End of recursive call: and 1 xjuncts. [2018-11-23 11:01:33,283 INFO L267 ElimStorePlain]: Start of recursive call 2: 1 dim-1 vars, End of recursive call: and 1 xjuncts. [2018-11-23 11:01:33,286 INFO L267 ElimStorePlain]: Start of recursive call 1: 2 dim-0 vars, 1 dim-2 vars, End of recursive call: and 1 xjuncts. [2018-11-23 11:01:33,286 INFO L202 ElimStorePlain]: Needed 3 recursive calls to eliminate 3 variables, input treesize:19, output treesize:3 [2018-11-23 11:01:33,291 WARN L383 uantifierElimination]: Trying to double check SDD result, but SMT solver's response was UNKNOWN. [2018-11-23 11:01:33,291 WARN L384 uantifierElimination]: Input elimination task: ∃ [|#memory_int|, ssl3_accept_~s.base, ssl3_accept_~s.offset]. (let ((.cse0 (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32))))) (and (= |ssl3_accept_#t~mem53| .cse0) (= (_ bv3 32) .cse0))) [2018-11-23 11:01:33,291 WARN L385 uantifierElimination]: ElimStorePlain result: ∃ []. (= |ssl3_accept_#t~mem53| (_ bv3 32)) [2018-11-23 11:01:33,300 INFO L256 TraceCheckUtils]: 0: Hoare triple {10096#true} call ULTIMATE.init(); {10096#true} is VALID [2018-11-23 11:01:33,301 INFO L273 TraceCheckUtils]: 1: Hoare triple {10096#true} #NULL.base, #NULL.offset := 0bv32, 0bv32;#valid := #valid[0bv32 := 0bv1];~init~0 := 1bv32;call ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset := #Ultimate.alloc(100bv32);call write~init~intINTTYPE4(0bv32, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset, 4bv32);call write~init~$Pointer$(0bv32, 0bv32, ~#SSLv3_server_data~0.base, ~bvadd32(4bv32, ~#SSLv3_server_data~0.offset), 4bv32);call write~init~$Pointer$(0bv32, 0bv32, ~#SSLv3_server_data~0.base, ~bvadd32(8bv32, ~#SSLv3_server_data~0.offset), 4bv32);call write~init~$Pointer$(0bv32, 0bv32, ~#SSLv3_server_data~0.base, ~bvadd32(12bv32, ~#SSLv3_server_data~0.offset), 4bv32);call write~init~$Pointer$(0bv32, 0bv32, ~#SSLv3_server_data~0.base, ~bvadd32(16bv32, ~#SSLv3_server_data~0.offset), 4bv32);call write~init~$Pointer$(0bv32, 0bv32, ~#SSLv3_server_data~0.base, ~bvadd32(20bv32, ~#SSLv3_server_data~0.offset), 4bv32);call write~init~$Pointer$(0bv32, 0bv32, ~#SSLv3_server_data~0.base, ~bvadd32(24bv32, ~#SSLv3_server_data~0.offset), 4bv32);call write~init~$Pointer$(0bv32, 0bv32, ~#SSLv3_server_data~0.base, ~bvadd32(28bv32, ~#SSLv3_server_data~0.offset), 4bv32);call write~init~$Pointer$(0bv32, 0bv32, ~#SSLv3_server_data~0.base, ~bvadd32(32bv32, ~#SSLv3_server_data~0.offset), 4bv32);call write~init~$Pointer$(0bv32, 0bv32, ~#SSLv3_server_data~0.base, ~bvadd32(36bv32, ~#SSLv3_server_data~0.offset), 4bv32);call write~init~$Pointer$(0bv32, 0bv32, ~#SSLv3_server_data~0.base, ~bvadd32(40bv32, ~#SSLv3_server_data~0.offset), 4bv32);call write~init~$Pointer$(0bv32, 0bv32, ~#SSLv3_server_data~0.base, ~bvadd32(44bv32, ~#SSLv3_server_data~0.offset), 4bv32);call write~init~$Pointer$(0bv32, 0bv32, ~#SSLv3_server_data~0.base, ~bvadd32(48bv32, ~#SSLv3_server_data~0.offset), 4bv32);call write~init~$Pointer$(0bv32, 0bv32, ~#SSLv3_server_data~0.base, ~bvadd32(52bv32, ~#SSLv3_server_data~0.offset), 4bv32);call write~init~$Pointer$(0bv32, 0bv32, ~#SSLv3_server_data~0.base, ~bvadd32(56bv32, ~#SSLv3_server_data~0.offset), 4bv32);call write~init~$Pointer$(0bv32, 0bv32, ~#SSLv3_server_data~0.base, ~bvadd32(60bv32, ~#SSLv3_server_data~0.offset), 4bv32);call write~init~$Pointer$(0bv32, 0bv32, ~#SSLv3_server_data~0.base, ~bvadd32(64bv32, ~#SSLv3_server_data~0.offset), 4bv32);call write~init~$Pointer$(0bv32, 0bv32, ~#SSLv3_server_data~0.base, ~bvadd32(68bv32, ~#SSLv3_server_data~0.offset), 4bv32);call write~init~$Pointer$(0bv32, 0bv32, ~#SSLv3_server_data~0.base, ~bvadd32(72bv32, ~#SSLv3_server_data~0.offset), 4bv32);call write~init~$Pointer$(0bv32, 0bv32, ~#SSLv3_server_data~0.base, ~bvadd32(76bv32, ~#SSLv3_server_data~0.offset), 4bv32);call write~init~$Pointer$(0bv32, 0bv32, ~#SSLv3_server_data~0.base, ~bvadd32(80bv32, ~#SSLv3_server_data~0.offset), 4bv32);call write~init~$Pointer$(0bv32, 0bv32, ~#SSLv3_server_data~0.base, ~bvadd32(84bv32, ~#SSLv3_server_data~0.offset), 4bv32);call write~init~$Pointer$(0bv32, 0bv32, ~#SSLv3_server_data~0.base, ~bvadd32(88bv32, ~#SSLv3_server_data~0.offset), 4bv32);call write~init~$Pointer$(0bv32, 0bv32, ~#SSLv3_server_data~0.base, ~bvadd32(92bv32, ~#SSLv3_server_data~0.offset), 4bv32);call write~init~$Pointer$(0bv32, 0bv32, ~#SSLv3_server_data~0.base, ~bvadd32(96bv32, ~#SSLv3_server_data~0.offset), 4bv32); {10096#true} is VALID [2018-11-23 11:01:33,301 INFO L273 TraceCheckUtils]: 2: Hoare triple {10096#true} assume true; {10096#true} is VALID [2018-11-23 11:01:33,302 INFO L268 TraceCheckUtils]: 3: Hoare quadruple {10096#true} {10096#true} #631#return; {10096#true} is VALID [2018-11-23 11:01:33,302 INFO L256 TraceCheckUtils]: 4: Hoare triple {10096#true} call #t~ret138 := main(); {10096#true} is VALID [2018-11-23 11:01:33,302 INFO L273 TraceCheckUtils]: 5: Hoare triple {10096#true} havoc ~s~0.base, ~s~0.offset;havoc ~tmp~2;call #t~malloc3.base, #t~malloc3.offset := #Ultimate.alloc(248bv32);~s~0.base, ~s~0.offset := #t~malloc3.base, #t~malloc3.offset;call #t~malloc4.base, #t~malloc4.offset := #Ultimate.alloc(899bv32);call write~$Pointer$(#t~malloc4.base, #t~malloc4.offset, ~s~0.base, ~bvadd32(84bv32, ~s~0.offset), 4bv32);call #t~malloc5.base, #t~malloc5.offset := #Ultimate.alloc(232bv32);call write~$Pointer$(#t~malloc5.base, #t~malloc5.offset, ~s~0.base, ~bvadd32(204bv32, ~s~0.offset), 4bv32);call #t~malloc6.base, #t~malloc6.offset := #Ultimate.alloc(200bv32);call write~$Pointer$(#t~malloc6.base, #t~malloc6.offset, ~s~0.base, ~bvadd32(176bv32, ~s~0.offset), 4bv32); {10096#true} is VALID [2018-11-23 11:01:33,303 INFO L256 TraceCheckUtils]: 6: Hoare triple {10096#true} call #t~ret7 := ssl3_accept(~s~0.base, ~s~0.offset); {10096#true} is VALID [2018-11-23 11:01:33,303 INFO L273 TraceCheckUtils]: 7: Hoare triple {10096#true} ~s.base, ~s.offset := #in~s.base, #in~s.offset;havoc ~buf~0.base, ~buf~0.offset;havoc ~l~0;havoc ~Time~0;havoc ~tmp~3;havoc ~cb~0.base, ~cb~0.offset;havoc ~num1~0;havoc ~ret~0;havoc ~new_state~0;havoc ~state~0;havoc ~skip~0;havoc ~got_new_session~0;~tmp___1~0 := #t~nondet8;havoc #t~nondet8;~tmp___2~0 := #t~nondet9;havoc #t~nondet9;~tmp___3~0 := #t~nondet10;havoc #t~nondet10;~tmp___4~0 := #t~nondet11;havoc #t~nondet11;~tmp___5~0 := #t~nondet12;havoc #t~nondet12;~tmp___6~0 := #t~nondet13;havoc #t~nondet13;havoc ~tmp___7~0;~tmp___8~0 := #t~nondet14;havoc #t~nondet14;~tmp___9~0 := #t~nondet15;havoc #t~nondet15;~tmp___10~0 := #t~nondet16;havoc #t~nondet16;havoc ~blastFlag~0;call write~intINTTYPE4(8464bv32, ~s.base, ~bvadd32(52bv32, ~s.offset), 4bv32);~blastFlag~0 := 0bv32;call write~intINTTYPE4(#t~nondet17, ~s.base, ~bvadd32(92bv32, ~s.offset), 4bv32);havoc #t~nondet17;call write~intINTTYPE4(8464bv32, ~s.base, ~bvadd32(52bv32, ~s.offset), 4bv32);~tmp~3 := #t~nondet18;havoc #t~nondet18;~Time~0 := ~tmp~3;~cb~0.base, ~cb~0.offset := 0bv32, 0bv32;~ret~0 := 4294967295bv32;~skip~0 := 0bv32;~got_new_session~0 := 0bv32;call #t~mem19.base, #t~mem19.offset := read~$Pointer$(~s.base, ~bvadd32(192bv32, ~s.offset), 4bv32); {10096#true} is VALID [2018-11-23 11:01:33,303 INFO L273 TraceCheckUtils]: 8: Hoare triple {10096#true} assume 0bv32 != ~bvadd32(#t~mem19.base, #t~mem19.offset);havoc #t~mem19.base, #t~mem19.offset;call #t~mem20.base, #t~mem20.offset := read~$Pointer$(~s.base, ~bvadd32(192bv32, ~s.offset), 4bv32);~cb~0.base, ~cb~0.offset := #t~mem20.base, #t~mem20.offset;havoc #t~mem20.base, #t~mem20.offset; {10096#true} is VALID [2018-11-23 11:01:33,303 INFO L273 TraceCheckUtils]: 9: Hoare triple {10096#true} call #t~mem21 := read~intINTTYPE4(~s.base, ~bvadd32(28bv32, ~s.offset), 4bv32);call write~intINTTYPE4(~bvadd32(1bv32, #t~mem21), ~s.base, ~bvadd32(28bv32, ~s.offset), 4bv32);havoc #t~mem21; {10096#true} is VALID [2018-11-23 11:01:33,304 INFO L273 TraceCheckUtils]: 10: Hoare triple {10096#true} assume !(0bv32 != ~bvand32(12288bv32, ~tmp___1~0)); {10096#true} is VALID [2018-11-23 11:01:33,304 INFO L273 TraceCheckUtils]: 11: Hoare triple {10096#true} call #t~mem22.base, #t~mem22.offset := read~$Pointer$(~s.base, ~bvadd32(136bv32, ~s.offset), 4bv32); {10096#true} is VALID [2018-11-23 11:01:33,304 INFO L273 TraceCheckUtils]: 12: Hoare triple {10096#true} assume !(0bv32 == ~bvadd32(#t~mem22.base, #t~mem22.offset));havoc #t~mem22.base, #t~mem22.offset; {10096#true} is VALID [2018-11-23 11:01:33,304 INFO L273 TraceCheckUtils]: 13: Hoare triple {10096#true} assume !false; {10096#true} is VALID [2018-11-23 11:01:33,304 INFO L273 TraceCheckUtils]: 14: Hoare triple {10096#true} call #t~mem23 := read~intINTTYPE4(~s.base, ~bvadd32(52bv32, ~s.offset), 4bv32);~state~0 := #t~mem23;havoc #t~mem23;call #t~mem24 := read~intINTTYPE4(~s.base, ~bvadd32(52bv32, ~s.offset), 4bv32); {10096#true} is VALID [2018-11-23 11:01:33,305 INFO L273 TraceCheckUtils]: 15: Hoare triple {10096#true} assume !(12292bv32 == #t~mem24);havoc #t~mem24;call #t~mem25 := read~intINTTYPE4(~s.base, ~bvadd32(52bv32, ~s.offset), 4bv32); {10096#true} is VALID [2018-11-23 11:01:33,305 INFO L273 TraceCheckUtils]: 16: Hoare triple {10096#true} assume !(16384bv32 == #t~mem25);havoc #t~mem25;call #t~mem26 := read~intINTTYPE4(~s.base, ~bvadd32(52bv32, ~s.offset), 4bv32); {10096#true} is VALID [2018-11-23 11:01:33,305 INFO L273 TraceCheckUtils]: 17: Hoare triple {10096#true} assume !(8192bv32 == #t~mem26);havoc #t~mem26;call #t~mem27 := read~intINTTYPE4(~s.base, ~bvadd32(52bv32, ~s.offset), 4bv32); {10096#true} is VALID [2018-11-23 11:01:33,305 INFO L273 TraceCheckUtils]: 18: Hoare triple {10096#true} assume !(24576bv32 == #t~mem27);havoc #t~mem27;call #t~mem28 := read~intINTTYPE4(~s.base, ~bvadd32(52bv32, ~s.offset), 4bv32); {10096#true} is VALID [2018-11-23 11:01:33,305 INFO L273 TraceCheckUtils]: 19: Hoare triple {10096#true} assume !(8195bv32 == #t~mem28);havoc #t~mem28;call #t~mem29 := read~intINTTYPE4(~s.base, ~bvadd32(52bv32, ~s.offset), 4bv32); {10096#true} is VALID [2018-11-23 11:01:33,306 INFO L273 TraceCheckUtils]: 20: Hoare triple {10096#true} assume !(8480bv32 == #t~mem29);havoc #t~mem29;call #t~mem30 := read~intINTTYPE4(~s.base, ~bvadd32(52bv32, ~s.offset), 4bv32); {10096#true} is VALID [2018-11-23 11:01:33,306 INFO L273 TraceCheckUtils]: 21: Hoare triple {10096#true} assume !(8481bv32 == #t~mem30);havoc #t~mem30;call #t~mem31 := read~intINTTYPE4(~s.base, ~bvadd32(52bv32, ~s.offset), 4bv32); {10096#true} is VALID [2018-11-23 11:01:33,306 INFO L273 TraceCheckUtils]: 22: Hoare triple {10096#true} assume 8482bv32 == #t~mem31;havoc #t~mem31; {10096#true} is VALID [2018-11-23 11:01:33,310 INFO L273 TraceCheckUtils]: 23: Hoare triple {10096#true} call write~intINTTYPE4(3bv32, ~s.base, ~bvadd32(52bv32, ~s.offset), 4bv32); {10170#(= (_ bv3 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32))))} is VALID [2018-11-23 11:01:33,310 INFO L273 TraceCheckUtils]: 24: Hoare triple {10170#(= (_ bv3 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32))))} call #t~mem127.base, #t~mem127.offset := read~$Pointer$(~s.base, ~bvadd32(84bv32, ~s.offset), 4bv32);call #t~mem128 := read~intINTTYPE4(#t~mem127.base, ~bvadd32(848bv32, #t~mem127.offset), 4bv32); {10170#(= (_ bv3 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32))))} is VALID [2018-11-23 11:01:33,311 INFO L273 TraceCheckUtils]: 25: Hoare triple {10170#(= (_ bv3 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32))))} assume !(0bv32 == #t~mem128);havoc #t~mem127.base, #t~mem127.offset;havoc #t~mem128; {10170#(= (_ bv3 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32))))} is VALID [2018-11-23 11:01:33,311 INFO L273 TraceCheckUtils]: 26: Hoare triple {10170#(= (_ bv3 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32))))} ~skip~0 := 0bv32; {10170#(= (_ bv3 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32))))} is VALID [2018-11-23 11:01:33,311 INFO L273 TraceCheckUtils]: 27: Hoare triple {10170#(= (_ bv3 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32))))} assume !false; {10170#(= (_ bv3 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32))))} is VALID [2018-11-23 11:01:33,312 INFO L273 TraceCheckUtils]: 28: Hoare triple {10170#(= (_ bv3 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32))))} call #t~mem23 := read~intINTTYPE4(~s.base, ~bvadd32(52bv32, ~s.offset), 4bv32);~state~0 := #t~mem23;havoc #t~mem23;call #t~mem24 := read~intINTTYPE4(~s.base, ~bvadd32(52bv32, ~s.offset), 4bv32); {10170#(= (_ bv3 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32))))} is VALID [2018-11-23 11:01:33,312 INFO L273 TraceCheckUtils]: 29: Hoare triple {10170#(= (_ bv3 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32))))} assume !(12292bv32 == #t~mem24);havoc #t~mem24;call #t~mem25 := read~intINTTYPE4(~s.base, ~bvadd32(52bv32, ~s.offset), 4bv32); {10170#(= (_ bv3 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32))))} is VALID [2018-11-23 11:01:33,313 INFO L273 TraceCheckUtils]: 30: Hoare triple {10170#(= (_ bv3 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32))))} assume !(16384bv32 == #t~mem25);havoc #t~mem25;call #t~mem26 := read~intINTTYPE4(~s.base, ~bvadd32(52bv32, ~s.offset), 4bv32); {10170#(= (_ bv3 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32))))} is VALID [2018-11-23 11:01:33,314 INFO L273 TraceCheckUtils]: 31: Hoare triple {10170#(= (_ bv3 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32))))} assume !(8192bv32 == #t~mem26);havoc #t~mem26;call #t~mem27 := read~intINTTYPE4(~s.base, ~bvadd32(52bv32, ~s.offset), 4bv32); {10170#(= (_ bv3 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32))))} is VALID [2018-11-23 11:01:33,314 INFO L273 TraceCheckUtils]: 32: Hoare triple {10170#(= (_ bv3 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32))))} assume !(24576bv32 == #t~mem27);havoc #t~mem27;call #t~mem28 := read~intINTTYPE4(~s.base, ~bvadd32(52bv32, ~s.offset), 4bv32); {10170#(= (_ bv3 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32))))} is VALID [2018-11-23 11:01:33,315 INFO L273 TraceCheckUtils]: 33: Hoare triple {10170#(= (_ bv3 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32))))} assume !(8195bv32 == #t~mem28);havoc #t~mem28;call #t~mem29 := read~intINTTYPE4(~s.base, ~bvadd32(52bv32, ~s.offset), 4bv32); {10170#(= (_ bv3 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32))))} is VALID [2018-11-23 11:01:33,315 INFO L273 TraceCheckUtils]: 34: Hoare triple {10170#(= (_ bv3 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32))))} assume !(8480bv32 == #t~mem29);havoc #t~mem29;call #t~mem30 := read~intINTTYPE4(~s.base, ~bvadd32(52bv32, ~s.offset), 4bv32); {10170#(= (_ bv3 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32))))} is VALID [2018-11-23 11:01:33,316 INFO L273 TraceCheckUtils]: 35: Hoare triple {10170#(= (_ bv3 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32))))} assume !(8481bv32 == #t~mem30);havoc #t~mem30;call #t~mem31 := read~intINTTYPE4(~s.base, ~bvadd32(52bv32, ~s.offset), 4bv32); {10170#(= (_ bv3 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32))))} is VALID [2018-11-23 11:01:33,316 INFO L273 TraceCheckUtils]: 36: Hoare triple {10170#(= (_ bv3 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32))))} assume !(8482bv32 == #t~mem31);havoc #t~mem31;call #t~mem32 := read~intINTTYPE4(~s.base, ~bvadd32(52bv32, ~s.offset), 4bv32); {10170#(= (_ bv3 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32))))} is VALID [2018-11-23 11:01:33,317 INFO L273 TraceCheckUtils]: 37: Hoare triple {10170#(= (_ bv3 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32))))} assume !(8464bv32 == #t~mem32);havoc #t~mem32;call #t~mem33 := read~intINTTYPE4(~s.base, ~bvadd32(52bv32, ~s.offset), 4bv32); {10170#(= (_ bv3 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32))))} is VALID [2018-11-23 11:01:33,318 INFO L273 TraceCheckUtils]: 38: Hoare triple {10170#(= (_ bv3 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32))))} assume !(8465bv32 == #t~mem33);havoc #t~mem33;call #t~mem34 := read~intINTTYPE4(~s.base, ~bvadd32(52bv32, ~s.offset), 4bv32); {10170#(= (_ bv3 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32))))} is VALID [2018-11-23 11:01:33,318 INFO L273 TraceCheckUtils]: 39: Hoare triple {10170#(= (_ bv3 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32))))} assume !(8466bv32 == #t~mem34);havoc #t~mem34;call #t~mem35 := read~intINTTYPE4(~s.base, ~bvadd32(52bv32, ~s.offset), 4bv32); {10170#(= (_ bv3 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32))))} is VALID [2018-11-23 11:01:33,319 INFO L273 TraceCheckUtils]: 40: Hoare triple {10170#(= (_ bv3 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32))))} assume !(8496bv32 == #t~mem35);havoc #t~mem35;call #t~mem36 := read~intINTTYPE4(~s.base, ~bvadd32(52bv32, ~s.offset), 4bv32); {10170#(= (_ bv3 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32))))} is VALID [2018-11-23 11:01:33,319 INFO L273 TraceCheckUtils]: 41: Hoare triple {10170#(= (_ bv3 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32))))} assume !(8497bv32 == #t~mem36);havoc #t~mem36;call #t~mem37 := read~intINTTYPE4(~s.base, ~bvadd32(52bv32, ~s.offset), 4bv32); {10170#(= (_ bv3 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32))))} is VALID [2018-11-23 11:01:33,325 INFO L273 TraceCheckUtils]: 42: Hoare triple {10170#(= (_ bv3 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32))))} assume !(8512bv32 == #t~mem37);havoc #t~mem37;call #t~mem38 := read~intINTTYPE4(~s.base, ~bvadd32(52bv32, ~s.offset), 4bv32); {10170#(= (_ bv3 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32))))} is VALID [2018-11-23 11:01:33,326 INFO L273 TraceCheckUtils]: 43: Hoare triple {10170#(= (_ bv3 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32))))} assume !(8513bv32 == #t~mem38);havoc #t~mem38;call #t~mem39 := read~intINTTYPE4(~s.base, ~bvadd32(52bv32, ~s.offset), 4bv32); {10170#(= (_ bv3 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32))))} is VALID [2018-11-23 11:01:33,326 INFO L273 TraceCheckUtils]: 44: Hoare triple {10170#(= (_ bv3 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32))))} assume !(8528bv32 == #t~mem39);havoc #t~mem39;call #t~mem40 := read~intINTTYPE4(~s.base, ~bvadd32(52bv32, ~s.offset), 4bv32); {10170#(= (_ bv3 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32))))} is VALID [2018-11-23 11:01:33,326 INFO L273 TraceCheckUtils]: 45: Hoare triple {10170#(= (_ bv3 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32))))} assume !(8529bv32 == #t~mem40);havoc #t~mem40;call #t~mem41 := read~intINTTYPE4(~s.base, ~bvadd32(52bv32, ~s.offset), 4bv32); {10170#(= (_ bv3 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32))))} is VALID [2018-11-23 11:01:33,327 INFO L273 TraceCheckUtils]: 46: Hoare triple {10170#(= (_ bv3 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32))))} assume !(8544bv32 == #t~mem41);havoc #t~mem41;call #t~mem42 := read~intINTTYPE4(~s.base, ~bvadd32(52bv32, ~s.offset), 4bv32); {10170#(= (_ bv3 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32))))} is VALID [2018-11-23 11:01:33,327 INFO L273 TraceCheckUtils]: 47: Hoare triple {10170#(= (_ bv3 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32))))} assume !(8545bv32 == #t~mem42);havoc #t~mem42;call #t~mem43 := read~intINTTYPE4(~s.base, ~bvadd32(52bv32, ~s.offset), 4bv32); {10170#(= (_ bv3 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32))))} is VALID [2018-11-23 11:01:33,327 INFO L273 TraceCheckUtils]: 48: Hoare triple {10170#(= (_ bv3 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32))))} assume !(8560bv32 == #t~mem43);havoc #t~mem43;call #t~mem44 := read~intINTTYPE4(~s.base, ~bvadd32(52bv32, ~s.offset), 4bv32); {10170#(= (_ bv3 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32))))} is VALID [2018-11-23 11:01:33,328 INFO L273 TraceCheckUtils]: 49: Hoare triple {10170#(= (_ bv3 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32))))} assume !(8561bv32 == #t~mem44);havoc #t~mem44;call #t~mem45 := read~intINTTYPE4(~s.base, ~bvadd32(52bv32, ~s.offset), 4bv32); {10170#(= (_ bv3 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32))))} is VALID [2018-11-23 11:01:33,328 INFO L273 TraceCheckUtils]: 50: Hoare triple {10170#(= (_ bv3 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32))))} assume !(8448bv32 == #t~mem45);havoc #t~mem45;call #t~mem46 := read~intINTTYPE4(~s.base, ~bvadd32(52bv32, ~s.offset), 4bv32); {10170#(= (_ bv3 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32))))} is VALID [2018-11-23 11:01:33,328 INFO L273 TraceCheckUtils]: 51: Hoare triple {10170#(= (_ bv3 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32))))} assume !(8576bv32 == #t~mem46);havoc #t~mem46;call #t~mem47 := read~intINTTYPE4(~s.base, ~bvadd32(52bv32, ~s.offset), 4bv32); {10170#(= (_ bv3 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32))))} is VALID [2018-11-23 11:01:33,329 INFO L273 TraceCheckUtils]: 52: Hoare triple {10170#(= (_ bv3 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32))))} assume !(8577bv32 == #t~mem47);havoc #t~mem47;call #t~mem48 := read~intINTTYPE4(~s.base, ~bvadd32(52bv32, ~s.offset), 4bv32); {10170#(= (_ bv3 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32))))} is VALID [2018-11-23 11:01:33,329 INFO L273 TraceCheckUtils]: 53: Hoare triple {10170#(= (_ bv3 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32))))} assume !(8592bv32 == #t~mem48);havoc #t~mem48;call #t~mem49 := read~intINTTYPE4(~s.base, ~bvadd32(52bv32, ~s.offset), 4bv32); {10170#(= (_ bv3 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32))))} is VALID [2018-11-23 11:01:33,330 INFO L273 TraceCheckUtils]: 54: Hoare triple {10170#(= (_ bv3 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32))))} assume !(8593bv32 == #t~mem49);havoc #t~mem49;call #t~mem50 := read~intINTTYPE4(~s.base, ~bvadd32(52bv32, ~s.offset), 4bv32); {10170#(= (_ bv3 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32))))} is VALID [2018-11-23 11:01:33,330 INFO L273 TraceCheckUtils]: 55: Hoare triple {10170#(= (_ bv3 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32))))} assume !(8608bv32 == #t~mem50);havoc #t~mem50;call #t~mem51 := read~intINTTYPE4(~s.base, ~bvadd32(52bv32, ~s.offset), 4bv32); {10170#(= (_ bv3 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32))))} is VALID [2018-11-23 11:01:33,331 INFO L273 TraceCheckUtils]: 56: Hoare triple {10170#(= (_ bv3 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32))))} assume !(8609bv32 == #t~mem51);havoc #t~mem51;call #t~mem52 := read~intINTTYPE4(~s.base, ~bvadd32(52bv32, ~s.offset), 4bv32); {10170#(= (_ bv3 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32))))} is VALID [2018-11-23 11:01:33,332 INFO L273 TraceCheckUtils]: 57: Hoare triple {10170#(= (_ bv3 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32))))} assume !(8640bv32 == #t~mem52);havoc #t~mem52;call #t~mem53 := read~intINTTYPE4(~s.base, ~bvadd32(52bv32, ~s.offset), 4bv32); {10273#(= (bvadd |ssl3_accept_#t~mem53| (_ bv4294967293 32)) (_ bv0 32))} is VALID [2018-11-23 11:01:33,332 INFO L273 TraceCheckUtils]: 58: Hoare triple {10273#(= (bvadd |ssl3_accept_#t~mem53| (_ bv4294967293 32)) (_ bv0 32))} assume 8641bv32 == #t~mem53;havoc #t~mem53; {10097#false} is VALID [2018-11-23 11:01:33,332 INFO L273 TraceCheckUtils]: 59: Hoare triple {10097#false} ~ret~0 := #t~nondet115;havoc #t~nondet115; {10097#false} is VALID [2018-11-23 11:01:33,333 INFO L273 TraceCheckUtils]: 60: Hoare triple {10097#false} assume !(4bv32 == ~blastFlag~0); {10097#false} is VALID [2018-11-23 11:01:33,333 INFO L273 TraceCheckUtils]: 61: Hoare triple {10097#false} assume !(7bv32 == ~blastFlag~0); {10097#false} is VALID [2018-11-23 11:01:33,333 INFO L273 TraceCheckUtils]: 62: Hoare triple {10097#false} assume !false; {10097#false} is VALID [2018-11-23 11:01:33,339 INFO L134 CoverageAnalysis]: Checked inductivity of 10 backedges. 10 proven. 0 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2018-11-23 11:01:33,339 INFO L312 TraceCheckSpWp]: Omiting computation of backward sequence because forward sequence was already perfect [2018-11-23 11:01:33,341 INFO L312 seRefinementStrategy]: Constructing automaton from 1 perfect and 0 imperfect interpolant sequences. [2018-11-23 11:01:33,341 INFO L327 seRefinementStrategy]: Number of different interpolants: perfect sequences [4] imperfect sequences [] total 4 [2018-11-23 11:01:33,342 INFO L78 Accepts]: Start accepts. Automaton has 4 states. Word has length 63 [2018-11-23 11:01:33,342 INFO L84 Accepts]: Finished accepts. word is accepted. [2018-11-23 11:01:33,342 INFO L86 InductivityCheck]: Starting indutivity check of a Floyd-Hoare automaton with 4 states. [2018-11-23 11:01:33,451 INFO L119 InductivityCheck]: Floyd-Hoare automaton has 63 edges. 63 inductive. 0 not inductive. 0 times theorem prover too weak to decide inductivity. [2018-11-23 11:01:33,452 INFO L459 AbstractCegarLoop]: Interpolant automaton has 4 states [2018-11-23 11:01:33,452 INFO L142 InterpolantAutomaton]: Constructing interpolant automaton starting with 4 interpolants. [2018-11-23 11:01:33,452 INFO L144 InterpolantAutomaton]: CoverageRelationStatistics Valid=5, Invalid=7, Unknown=0, NotChecked=0, Total=12 [2018-11-23 11:01:33,452 INFO L87 Difference]: Start difference. First operand 213 states and 343 transitions. Second operand 4 states. [2018-11-23 11:01:54,510 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2018-11-23 11:01:54,511 INFO L93 Difference]: Finished difference Result 478 states and 765 transitions. [2018-11-23 11:01:54,511 INFO L142 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 4 states. [2018-11-23 11:01:54,511 INFO L78 Accepts]: Start accepts. Automaton has 4 states. Word has length 63 [2018-11-23 11:01:54,511 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2018-11-23 11:01:54,512 INFO L82 GeneralOperation]: Start removeUnreachable. Operand 4 states. [2018-11-23 11:01:54,516 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 4 states to 4 states and 563 transitions. [2018-11-23 11:01:54,516 INFO L82 GeneralOperation]: Start removeUnreachable. Operand 4 states. [2018-11-23 11:01:54,520 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 4 states to 4 states and 563 transitions. [2018-11-23 11:01:54,520 INFO L86 InductivityCheck]: Starting indutivity check of a Floyd-Hoare automaton with 4 states and 563 transitions. [2018-11-23 11:01:55,770 INFO L119 InductivityCheck]: Floyd-Hoare automaton has 563 edges. 563 inductive. 0 not inductive. 0 times theorem prover too weak to decide inductivity. [2018-11-23 11:01:55,777 INFO L225 Difference]: With dead ends: 478 [2018-11-23 11:01:55,777 INFO L226 Difference]: Without dead ends: 311 [2018-11-23 11:01:55,778 INFO L631 BasicCegarLoop]: 0 DeclaredPredicates, 63 GetRequests, 60 SyntacticMatches, 0 SemanticMatches, 3 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 0 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=9, Invalid=11, Unknown=0, NotChecked=0, Total=20 [2018-11-23 11:01:55,778 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 311 states. [2018-11-23 11:01:55,912 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 311 to 230. [2018-11-23 11:01:55,913 INFO L214 AbstractMinimizeNwa]: Start testing correctness of minimizeSevpa [2018-11-23 11:01:55,913 INFO L82 GeneralOperation]: Start isEquivalent. First operand 311 states. Second operand 230 states. [2018-11-23 11:01:55,913 INFO L74 IsIncluded]: Start isIncluded. First operand 311 states. Second operand 230 states. [2018-11-23 11:01:55,913 INFO L87 Difference]: Start difference. First operand 311 states. Second operand 230 states. [2018-11-23 11:01:55,920 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2018-11-23 11:01:55,921 INFO L93 Difference]: Finished difference Result 311 states and 495 transitions. [2018-11-23 11:01:55,921 INFO L276 IsEmpty]: Start isEmpty. Operand 311 states and 495 transitions. [2018-11-23 11:01:55,922 INFO L282 IsEmpty]: Finished isEmpty. No accepting run. [2018-11-23 11:01:55,922 INFO L83 IsIncluded]: Finished isIncluded. Language is included [2018-11-23 11:01:55,922 INFO L74 IsIncluded]: Start isIncluded. First operand 230 states. Second operand 311 states. [2018-11-23 11:01:55,922 INFO L87 Difference]: Start difference. First operand 230 states. Second operand 311 states. [2018-11-23 11:01:55,930 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2018-11-23 11:01:55,930 INFO L93 Difference]: Finished difference Result 311 states and 495 transitions. [2018-11-23 11:01:55,931 INFO L276 IsEmpty]: Start isEmpty. Operand 311 states and 495 transitions. [2018-11-23 11:01:55,931 INFO L282 IsEmpty]: Finished isEmpty. No accepting run. [2018-11-23 11:01:55,932 INFO L83 IsIncluded]: Finished isIncluded. Language is included [2018-11-23 11:01:55,932 INFO L88 GeneralOperation]: Finished isEquivalent. [2018-11-23 11:01:55,932 INFO L221 AbstractMinimizeNwa]: Finished testing correctness of minimizeSevpa [2018-11-23 11:01:55,932 INFO L82 GeneralOperation]: Start removeUnreachable. Operand 230 states. [2018-11-23 11:01:55,937 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 230 states to 230 states and 372 transitions. [2018-11-23 11:01:55,937 INFO L78 Accepts]: Start accepts. Automaton has 230 states and 372 transitions. Word has length 63 [2018-11-23 11:01:55,937 INFO L84 Accepts]: Finished accepts. word is rejected. [2018-11-23 11:01:55,937 INFO L480 AbstractCegarLoop]: Abstraction has 230 states and 372 transitions. [2018-11-23 11:01:55,937 INFO L481 AbstractCegarLoop]: Interpolant automaton has 4 states. [2018-11-23 11:01:55,938 INFO L276 IsEmpty]: Start isEmpty. Operand 230 states and 372 transitions. [2018-11-23 11:01:55,938 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 64 [2018-11-23 11:01:55,939 INFO L394 BasicCegarLoop]: Found error trace [2018-11-23 11:01:55,939 INFO L402 BasicCegarLoop]: trace histogram [2, 2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2018-11-23 11:01:55,939 INFO L423 AbstractCegarLoop]: === Iteration 9 === [ssl3_acceptErr0ASSERT_VIOLATIONERROR_FUNCTION]=== [2018-11-23 11:01:55,939 INFO L141 PredicateUnifier]: Initialized classic predicate unifier [2018-11-23 11:01:55,939 INFO L82 PathProgramCache]: Analyzing trace with hash -2052668603, now seen corresponding path program 1 times [2018-11-23 11:01:55,940 INFO L223 ckRefinementStrategy]: Switched to mode CVC4_FPBP [2018-11-23 11:01:55,940 INFO L69 tionRefinementEngine]: Using refinement strategy WolfRefinementStrategy No working directory specified, using /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/cvc4nyu Starting monitored process 10 with cvc4nyu --tear-down-incremental --print-success --lang smt --rewrite-divk (exit command is (exit), workingDir is null) Waiting until toolchain timeout for monitored process 10 with cvc4nyu --tear-down-incremental --print-success --lang smt --rewrite-divk [2018-11-23 11:01:55,968 INFO L103 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2018-11-23 11:01:56,202 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2018-11-23 11:01:56,278 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2018-11-23 11:01:56,279 INFO L273 TraceCheckSpWp]: Computing forward predicates... [2018-11-23 11:01:56,324 INFO L478 Elim1Store]: Elim1 did not use preprocessing eliminated variable of array dimension 2, 1 stores, 1 select indices, 1 select index equivalence classes, 0 disjoint index pairs (out of 0 index pairs), introduced 1 new quantified variables, introduced 0 case distinctions, treesize of input 23 treesize of output 20 [2018-11-23 11:01:56,331 INFO L478 Elim1Store]: Elim1 did not use preprocessing eliminated variable of array dimension 1, 1 stores, 0 select indices, 0 select index equivalence classes, 0 disjoint index pairs (out of 0 index pairs), introduced 1 new quantified variables, introduced 0 case distinctions, treesize of input 20 treesize of output 23 [2018-11-23 11:01:56,342 INFO L701 Elim1Store]: detected not equals via solver [2018-11-23 11:01:56,347 INFO L478 Elim1Store]: Elim1 did not use preprocessing eliminated variable of array dimension 1, 1 stores, 1 select indices, 1 select index equivalence classes, 1 disjoint index pairs (out of 0 index pairs), introduced 1 new quantified variables, introduced 0 case distinctions, treesize of input 23 treesize of output 33 [2018-11-23 11:01:56,357 INFO L701 Elim1Store]: detected not equals via solver [2018-11-23 11:01:56,364 INFO L478 Elim1Store]: Elim1 did not use preprocessing eliminated variable of array dimension 1, 1 stores, 2 select indices, 2 select index equivalence classes, 1 disjoint index pairs (out of 1 index pairs), introduced 0 new quantified variables, introduced 0 case distinctions, treesize of input 25 treesize of output 27 [2018-11-23 11:01:56,368 INFO L267 ElimStorePlain]: Start of recursive call 5: End of recursive call: and 1 xjuncts. [2018-11-23 11:01:56,381 INFO L267 ElimStorePlain]: Start of recursive call 4: 1 dim-1 vars, End of recursive call: and 1 xjuncts. [2018-11-23 11:01:56,391 INFO L267 ElimStorePlain]: Start of recursive call 3: 1 dim-1 vars, End of recursive call: and 1 xjuncts. [2018-11-23 11:01:56,401 INFO L267 ElimStorePlain]: Start of recursive call 2: 1 dim-1 vars, End of recursive call: and 1 xjuncts. [2018-11-23 11:01:56,417 INFO L267 ElimStorePlain]: Start of recursive call 1: 1 dim-0 vars, 1 dim-2 vars, End of recursive call: and 1 xjuncts. [2018-11-23 11:01:56,418 INFO L202 ElimStorePlain]: Needed 5 recursive calls to eliminate 2 variables, input treesize:27, output treesize:13 [2018-11-23 11:01:56,434 WARN L383 uantifierElimination]: Trying to double check SDD result, but SMT solver's response was UNKNOWN. [2018-11-23 11:01:56,435 WARN L384 uantifierElimination]: Input elimination task: ∃ [|v_#memory_int_194|, |v_ssl3_accept_#t~nondet17_8|]. (and (= (store |v_#memory_int_194| ssl3_accept_~s.base (let ((.cse0 (bvadd ssl3_accept_~s.offset (_ bv52 32)))) (store (store (store (select |v_#memory_int_194| ssl3_accept_~s.base) .cse0 (_ bv8464 32)) (bvadd ssl3_accept_~s.offset (_ bv92 32)) |v_ssl3_accept_#t~nondet17_8|) .cse0 (_ bv8464 32)))) |#memory_int|) (= ssl3_accept_~s.offset (_ bv0 32))) [2018-11-23 11:01:56,435 WARN L385 uantifierElimination]: ElimStorePlain result: ∃ []. (and (= ssl3_accept_~s.offset (_ bv0 32)) (= (_ bv8464 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32))))) [2018-11-23 11:01:56,475 INFO L701 Elim1Store]: detected not equals via solver [2018-11-23 11:01:56,477 INFO L478 Elim1Store]: Elim1 did not use preprocessing eliminated variable of array dimension 2, 1 stores, 1 select indices, 1 select index equivalence classes, 1 disjoint index pairs (out of 0 index pairs), introduced 1 new quantified variables, introduced 0 case distinctions, treesize of input 31 treesize of output 38 [2018-11-23 11:01:56,488 INFO L701 Elim1Store]: detected not equals via solver [2018-11-23 11:01:56,493 INFO L701 Elim1Store]: detected not equals via solver [2018-11-23 11:01:56,497 INFO L478 Elim1Store]: Elim1 did not use preprocessing eliminated variable of array dimension 1, 1 stores, 2 select indices, 2 select index equivalence classes, 2 disjoint index pairs (out of 1 index pairs), introduced 1 new quantified variables, introduced 0 case distinctions, treesize of input 38 treesize of output 35 [2018-11-23 11:01:56,525 INFO L267 ElimStorePlain]: Start of recursive call 3: End of recursive call: and 1 xjuncts. [2018-11-23 11:01:56,531 INFO L267 ElimStorePlain]: Start of recursive call 2: 1 dim-1 vars, End of recursive call: and 1 xjuncts. [2018-11-23 11:01:56,544 INFO L267 ElimStorePlain]: Start of recursive call 1: 1 dim-2 vars, End of recursive call: and 1 xjuncts. [2018-11-23 11:01:56,544 INFO L202 ElimStorePlain]: Needed 3 recursive calls to eliminate 1 variables, input treesize:34, output treesize:13 [2018-11-23 11:01:58,567 WARN L383 uantifierElimination]: Trying to double check SDD result, but SMT solver's response was UNKNOWN. [2018-11-23 11:01:58,567 WARN L384 uantifierElimination]: Input elimination task: ∃ [|v_#memory_int_195|]. (let ((.cse0 (select |v_#memory_int_195| ssl3_accept_~s.base))) (and (= (select .cse0 (bvadd ssl3_accept_~s.offset (_ bv52 32))) (_ bv8464 32)) (= ssl3_accept_~s.offset (_ bv0 32)) (= (store |v_#memory_int_195| ssl3_accept_~s.base (let ((.cse1 (bvadd ssl3_accept_~s.offset (_ bv28 32)))) (store .cse0 .cse1 (bvadd (select .cse0 .cse1) (_ bv1 32))))) |#memory_int|))) [2018-11-23 11:01:58,567 WARN L385 uantifierElimination]: ElimStorePlain result: ∃ []. (and (= ssl3_accept_~s.offset (_ bv0 32)) (= (_ bv8464 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32))))) [2018-11-23 11:01:58,583 INFO L478 Elim1Store]: Elim1 did not use preprocessing eliminated variable of array dimension 2, 0 stores, 1 select indices, 1 select index equivalence classes, 0 disjoint index pairs (out of 0 index pairs), introduced 1 new quantified variables, introduced 0 case distinctions, treesize of input 17 treesize of output 13 [2018-11-23 11:01:58,587 INFO L478 Elim1Store]: Elim1 did not use preprocessing eliminated variable of array dimension 1, 0 stores, 1 select indices, 1 select index equivalence classes, 0 disjoint index pairs (out of 0 index pairs), introduced 0 new quantified variables, introduced 0 case distinctions, treesize of input 13 treesize of output 5 [2018-11-23 11:01:58,594 INFO L267 ElimStorePlain]: Start of recursive call 3: End of recursive call: and 1 xjuncts. [2018-11-23 11:01:58,596 INFO L267 ElimStorePlain]: Start of recursive call 2: 1 dim-1 vars, End of recursive call: and 1 xjuncts. [2018-11-23 11:01:58,597 INFO L267 ElimStorePlain]: Start of recursive call 1: 1 dim-0 vars, 1 dim-2 vars, End of recursive call: and 1 xjuncts. [2018-11-23 11:01:58,598 INFO L202 ElimStorePlain]: Needed 3 recursive calls to eliminate 2 variables, input treesize:17, output treesize:5 [2018-11-23 11:01:58,601 WARN L383 uantifierElimination]: Trying to double check SDD result, but SMT solver's response was UNKNOWN. [2018-11-23 11:01:58,601 WARN L384 uantifierElimination]: Input elimination task: ∃ [|#memory_int|, ssl3_accept_~s.base]. (let ((.cse0 (select (select |#memory_int| ssl3_accept_~s.base) (_ bv52 32)))) (and (= (bvadd .cse0 (_ bv4294958832 32)) (_ bv0 32)) (= |ssl3_accept_#t~mem24| .cse0))) [2018-11-23 11:01:58,601 WARN L385 uantifierElimination]: ElimStorePlain result: ∃ []. (= (_ bv0 32) (bvadd |ssl3_accept_#t~mem24| (_ bv4294958832 32))) [2018-11-23 11:01:58,641 INFO L256 TraceCheckUtils]: 0: Hoare triple {11731#true} call ULTIMATE.init(); {11731#true} is VALID [2018-11-23 11:01:58,642 INFO L273 TraceCheckUtils]: 1: Hoare triple {11731#true} #NULL.base, #NULL.offset := 0bv32, 0bv32;#valid := #valid[0bv32 := 0bv1];~init~0 := 1bv32;call ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset := #Ultimate.alloc(100bv32);call write~init~intINTTYPE4(0bv32, ~#SSLv3_server_data~0.base, ~#SSLv3_server_data~0.offset, 4bv32);call write~init~$Pointer$(0bv32, 0bv32, ~#SSLv3_server_data~0.base, ~bvadd32(4bv32, ~#SSLv3_server_data~0.offset), 4bv32);call write~init~$Pointer$(0bv32, 0bv32, ~#SSLv3_server_data~0.base, ~bvadd32(8bv32, ~#SSLv3_server_data~0.offset), 4bv32);call write~init~$Pointer$(0bv32, 0bv32, ~#SSLv3_server_data~0.base, ~bvadd32(12bv32, ~#SSLv3_server_data~0.offset), 4bv32);call write~init~$Pointer$(0bv32, 0bv32, ~#SSLv3_server_data~0.base, ~bvadd32(16bv32, ~#SSLv3_server_data~0.offset), 4bv32);call write~init~$Pointer$(0bv32, 0bv32, ~#SSLv3_server_data~0.base, ~bvadd32(20bv32, ~#SSLv3_server_data~0.offset), 4bv32);call write~init~$Pointer$(0bv32, 0bv32, ~#SSLv3_server_data~0.base, ~bvadd32(24bv32, ~#SSLv3_server_data~0.offset), 4bv32);call write~init~$Pointer$(0bv32, 0bv32, ~#SSLv3_server_data~0.base, ~bvadd32(28bv32, ~#SSLv3_server_data~0.offset), 4bv32);call write~init~$Pointer$(0bv32, 0bv32, ~#SSLv3_server_data~0.base, ~bvadd32(32bv32, ~#SSLv3_server_data~0.offset), 4bv32);call write~init~$Pointer$(0bv32, 0bv32, ~#SSLv3_server_data~0.base, ~bvadd32(36bv32, ~#SSLv3_server_data~0.offset), 4bv32);call write~init~$Pointer$(0bv32, 0bv32, ~#SSLv3_server_data~0.base, ~bvadd32(40bv32, ~#SSLv3_server_data~0.offset), 4bv32);call write~init~$Pointer$(0bv32, 0bv32, ~#SSLv3_server_data~0.base, ~bvadd32(44bv32, ~#SSLv3_server_data~0.offset), 4bv32);call write~init~$Pointer$(0bv32, 0bv32, ~#SSLv3_server_data~0.base, ~bvadd32(48bv32, ~#SSLv3_server_data~0.offset), 4bv32);call write~init~$Pointer$(0bv32, 0bv32, ~#SSLv3_server_data~0.base, ~bvadd32(52bv32, ~#SSLv3_server_data~0.offset), 4bv32);call write~init~$Pointer$(0bv32, 0bv32, ~#SSLv3_server_data~0.base, ~bvadd32(56bv32, ~#SSLv3_server_data~0.offset), 4bv32);call write~init~$Pointer$(0bv32, 0bv32, ~#SSLv3_server_data~0.base, ~bvadd32(60bv32, ~#SSLv3_server_data~0.offset), 4bv32);call write~init~$Pointer$(0bv32, 0bv32, ~#SSLv3_server_data~0.base, ~bvadd32(64bv32, ~#SSLv3_server_data~0.offset), 4bv32);call write~init~$Pointer$(0bv32, 0bv32, ~#SSLv3_server_data~0.base, ~bvadd32(68bv32, ~#SSLv3_server_data~0.offset), 4bv32);call write~init~$Pointer$(0bv32, 0bv32, ~#SSLv3_server_data~0.base, ~bvadd32(72bv32, ~#SSLv3_server_data~0.offset), 4bv32);call write~init~$Pointer$(0bv32, 0bv32, ~#SSLv3_server_data~0.base, ~bvadd32(76bv32, ~#SSLv3_server_data~0.offset), 4bv32);call write~init~$Pointer$(0bv32, 0bv32, ~#SSLv3_server_data~0.base, ~bvadd32(80bv32, ~#SSLv3_server_data~0.offset), 4bv32);call write~init~$Pointer$(0bv32, 0bv32, ~#SSLv3_server_data~0.base, ~bvadd32(84bv32, ~#SSLv3_server_data~0.offset), 4bv32);call write~init~$Pointer$(0bv32, 0bv32, ~#SSLv3_server_data~0.base, ~bvadd32(88bv32, ~#SSLv3_server_data~0.offset), 4bv32);call write~init~$Pointer$(0bv32, 0bv32, ~#SSLv3_server_data~0.base, ~bvadd32(92bv32, ~#SSLv3_server_data~0.offset), 4bv32);call write~init~$Pointer$(0bv32, 0bv32, ~#SSLv3_server_data~0.base, ~bvadd32(96bv32, ~#SSLv3_server_data~0.offset), 4bv32); {11731#true} is VALID [2018-11-23 11:01:58,642 INFO L273 TraceCheckUtils]: 2: Hoare triple {11731#true} assume true; {11731#true} is VALID [2018-11-23 11:01:58,642 INFO L268 TraceCheckUtils]: 3: Hoare quadruple {11731#true} {11731#true} #631#return; {11731#true} is VALID [2018-11-23 11:01:58,642 INFO L256 TraceCheckUtils]: 4: Hoare triple {11731#true} call #t~ret138 := main(); {11731#true} is VALID [2018-11-23 11:01:58,644 INFO L273 TraceCheckUtils]: 5: Hoare triple {11731#true} havoc ~s~0.base, ~s~0.offset;havoc ~tmp~2;call #t~malloc3.base, #t~malloc3.offset := #Ultimate.alloc(248bv32);~s~0.base, ~s~0.offset := #t~malloc3.base, #t~malloc3.offset;call #t~malloc4.base, #t~malloc4.offset := #Ultimate.alloc(899bv32);call write~$Pointer$(#t~malloc4.base, #t~malloc4.offset, ~s~0.base, ~bvadd32(84bv32, ~s~0.offset), 4bv32);call #t~malloc5.base, #t~malloc5.offset := #Ultimate.alloc(232bv32);call write~$Pointer$(#t~malloc5.base, #t~malloc5.offset, ~s~0.base, ~bvadd32(204bv32, ~s~0.offset), 4bv32);call #t~malloc6.base, #t~malloc6.offset := #Ultimate.alloc(200bv32);call write~$Pointer$(#t~malloc6.base, #t~malloc6.offset, ~s~0.base, ~bvadd32(176bv32, ~s~0.offset), 4bv32); {11751#(= main_~s~0.offset (_ bv0 32))} is VALID [2018-11-23 11:01:58,662 INFO L256 TraceCheckUtils]: 6: Hoare triple {11751#(= main_~s~0.offset (_ bv0 32))} call #t~ret7 := ssl3_accept(~s~0.base, ~s~0.offset); {11755#(= (_ bv0 32) |ssl3_accept_#in~s.offset|)} is VALID [2018-11-23 11:01:58,667 INFO L273 TraceCheckUtils]: 7: Hoare triple {11755#(= (_ bv0 32) |ssl3_accept_#in~s.offset|)} ~s.base, ~s.offset := #in~s.base, #in~s.offset;havoc ~buf~0.base, ~buf~0.offset;havoc ~l~0;havoc ~Time~0;havoc ~tmp~3;havoc ~cb~0.base, ~cb~0.offset;havoc ~num1~0;havoc ~ret~0;havoc ~new_state~0;havoc ~state~0;havoc ~skip~0;havoc ~got_new_session~0;~tmp___1~0 := #t~nondet8;havoc #t~nondet8;~tmp___2~0 := #t~nondet9;havoc #t~nondet9;~tmp___3~0 := #t~nondet10;havoc #t~nondet10;~tmp___4~0 := #t~nondet11;havoc #t~nondet11;~tmp___5~0 := #t~nondet12;havoc #t~nondet12;~tmp___6~0 := #t~nondet13;havoc #t~nondet13;havoc ~tmp___7~0;~tmp___8~0 := #t~nondet14;havoc #t~nondet14;~tmp___9~0 := #t~nondet15;havoc #t~nondet15;~tmp___10~0 := #t~nondet16;havoc #t~nondet16;havoc ~blastFlag~0;call write~intINTTYPE4(8464bv32, ~s.base, ~bvadd32(52bv32, ~s.offset), 4bv32);~blastFlag~0 := 0bv32;call write~intINTTYPE4(#t~nondet17, ~s.base, ~bvadd32(92bv32, ~s.offset), 4bv32);havoc #t~nondet17;call write~intINTTYPE4(8464bv32, ~s.base, ~bvadd32(52bv32, ~s.offset), 4bv32);~tmp~3 := #t~nondet18;havoc #t~nondet18;~Time~0 := ~tmp~3;~cb~0.base, ~cb~0.offset := 0bv32, 0bv32;~ret~0 := 4294967295bv32;~skip~0 := 0bv32;~got_new_session~0 := 0bv32;call #t~mem19.base, #t~mem19.offset := read~$Pointer$(~s.base, ~bvadd32(192bv32, ~s.offset), 4bv32); {11759#(and (= ssl3_accept_~s.offset (_ bv0 32)) (= (_ bv8464 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32)))))} is VALID [2018-11-23 11:01:58,668 INFO L273 TraceCheckUtils]: 8: Hoare triple {11759#(and (= ssl3_accept_~s.offset (_ bv0 32)) (= (_ bv8464 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32)))))} assume 0bv32 != ~bvadd32(#t~mem19.base, #t~mem19.offset);havoc #t~mem19.base, #t~mem19.offset;call #t~mem20.base, #t~mem20.offset := read~$Pointer$(~s.base, ~bvadd32(192bv32, ~s.offset), 4bv32);~cb~0.base, ~cb~0.offset := #t~mem20.base, #t~mem20.offset;havoc #t~mem20.base, #t~mem20.offset; {11759#(and (= ssl3_accept_~s.offset (_ bv0 32)) (= (_ bv8464 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32)))))} is VALID [2018-11-23 11:01:58,670 INFO L273 TraceCheckUtils]: 9: Hoare triple {11759#(and (= ssl3_accept_~s.offset (_ bv0 32)) (= (_ bv8464 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32)))))} call #t~mem21 := read~intINTTYPE4(~s.base, ~bvadd32(28bv32, ~s.offset), 4bv32);call write~intINTTYPE4(~bvadd32(1bv32, #t~mem21), ~s.base, ~bvadd32(28bv32, ~s.offset), 4bv32);havoc #t~mem21; {11759#(and (= ssl3_accept_~s.offset (_ bv0 32)) (= (_ bv8464 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32)))))} is VALID [2018-11-23 11:01:58,671 INFO L273 TraceCheckUtils]: 10: Hoare triple {11759#(and (= ssl3_accept_~s.offset (_ bv0 32)) (= (_ bv8464 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32)))))} assume !(0bv32 != ~bvand32(12288bv32, ~tmp___1~0)); {11759#(and (= ssl3_accept_~s.offset (_ bv0 32)) (= (_ bv8464 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32)))))} is VALID [2018-11-23 11:01:58,672 INFO L273 TraceCheckUtils]: 11: Hoare triple {11759#(and (= ssl3_accept_~s.offset (_ bv0 32)) (= (_ bv8464 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32)))))} call #t~mem22.base, #t~mem22.offset := read~$Pointer$(~s.base, ~bvadd32(136bv32, ~s.offset), 4bv32); {11759#(and (= ssl3_accept_~s.offset (_ bv0 32)) (= (_ bv8464 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32)))))} is VALID [2018-11-23 11:01:58,673 INFO L273 TraceCheckUtils]: 12: Hoare triple {11759#(and (= ssl3_accept_~s.offset (_ bv0 32)) (= (_ bv8464 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32)))))} assume !(0bv32 == ~bvadd32(#t~mem22.base, #t~mem22.offset));havoc #t~mem22.base, #t~mem22.offset; {11759#(and (= ssl3_accept_~s.offset (_ bv0 32)) (= (_ bv8464 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32)))))} is VALID [2018-11-23 11:01:58,683 INFO L273 TraceCheckUtils]: 13: Hoare triple {11759#(and (= ssl3_accept_~s.offset (_ bv0 32)) (= (_ bv8464 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32)))))} assume !false; {11759#(and (= ssl3_accept_~s.offset (_ bv0 32)) (= (_ bv8464 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32)))))} is VALID [2018-11-23 11:01:58,683 INFO L273 TraceCheckUtils]: 14: Hoare triple {11759#(and (= ssl3_accept_~s.offset (_ bv0 32)) (= (_ bv8464 32) (select (select |#memory_int| ssl3_accept_~s.base) (bvadd ssl3_accept_~s.offset (_ bv52 32)))))} call #t~mem23 := read~intINTTYPE4(~s.base, ~bvadd32(52bv32, ~s.offset), 4bv32);~state~0 := #t~mem23;havoc #t~mem23;call #t~mem24 := read~intINTTYPE4(~s.base, ~bvadd32(52bv32, ~s.offset), 4bv32); {11781#(= (_ bv8464 32) |ssl3_accept_#t~mem24|)} is VALID [2018-11-23 11:01:58,684 INFO L273 TraceCheckUtils]: 15: Hoare triple {11781#(= (_ bv8464 32) |ssl3_accept_#t~mem24|)} assume 12292bv32 == #t~mem24;havoc #t~mem24; {11732#false} is VALID [2018-11-23 11:01:58,684 INFO L273 TraceCheckUtils]: 16: Hoare triple {11732#false} call write~intINTTYPE4(1bv32, ~s.base, ~bvadd32(40bv32, ~s.offset), 4bv32); {11732#false} is VALID [2018-11-23 11:01:58,684 INFO L273 TraceCheckUtils]: 17: Hoare triple {11732#false} call write~intINTTYPE4(1bv32, ~s.base, ~bvadd32(36bv32, ~s.offset), 4bv32); {11732#false} is VALID [2018-11-23 11:01:58,684 INFO L273 TraceCheckUtils]: 18: Hoare triple {11732#false} assume 0bv32 != ~bvadd32(~cb~0.base, ~cb~0.offset); {11732#false} is VALID [2018-11-23 11:01:58,685 INFO L273 TraceCheckUtils]: 19: Hoare triple {11732#false} call #t~mem59 := read~intINTTYPE4(~s.base, ~s.offset, 4bv32); {11732#false} is VALID [2018-11-23 11:01:58,685 INFO L273 TraceCheckUtils]: 20: Hoare triple {11732#false} assume !(3bv32 != ~bvashr32(#t~mem59, 8bv32));havoc #t~mem59;call write~intINTTYPE4(8192bv32, ~s.base, ~bvadd32(4bv32, ~s.offset), 4bv32);call #t~mem60.base, #t~mem60.offset := read~$Pointer$(~s.base, ~bvadd32(60bv32, ~s.offset), 4bv32); {11732#false} is VALID [2018-11-23 11:01:58,685 INFO L273 TraceCheckUtils]: 21: Hoare triple {11732#false} assume !(0bv32 == ~bvadd32(#t~mem60.base, #t~mem60.offset));havoc #t~mem60.base, #t~mem60.offset; {11732#false} is VALID [2018-11-23 11:01:58,685 INFO L273 TraceCheckUtils]: 22: Hoare triple {11732#false} assume !(0bv32 == ~tmp___4~0);call write~intINTTYPE4(0bv32, ~s.base, ~bvadd32(64bv32, ~s.offset), 4bv32);call #t~mem62 := read~intINTTYPE4(~s.base, ~bvadd32(52bv32, ~s.offset), 4bv32); {11732#false} is VALID [2018-11-23 11:01:58,685 INFO L273 TraceCheckUtils]: 23: Hoare triple {11732#false} assume 12292bv32 != #t~mem62;havoc #t~mem62; {11732#false} is VALID [2018-11-23 11:01:58,686 INFO L273 TraceCheckUtils]: 24: Hoare triple {11732#false} assume !(0bv32 == ~tmp___5~0);call write~intINTTYPE4(8464bv32, ~s.base, ~bvadd32(52bv32, ~s.offset), 4bv32);call #t~mem63.base, #t~mem63.offset := read~$Pointer$(~s.base, ~bvadd32(204bv32, ~s.offset), 4bv32);call #t~mem64 := read~intINTTYPE4(#t~mem63.base, ~bvadd32(72bv32, #t~mem63.offset), 4bv32);call write~intINTTYPE4(~bvadd32(1bv32, #t~mem64), #t~mem63.base, ~bvadd32(72bv32, #t~mem63.offset), 4bv32);havoc #t~mem63.base, #t~mem63.offset;havoc #t~mem64; {11732#false} is VALID [2018-11-23 11:01:58,686 INFO L273 TraceCheckUtils]: 25: Hoare triple {11732#false} call #t~mem127.base, #t~mem127.offset := read~$Pointer$(~s.base, ~bvadd32(84bv32, ~s.offset), 4bv32);call #t~mem128 := read~intINTTYPE4(#t~mem127.base, ~bvadd32(848bv32, #t~mem127.offset), 4bv32); {11732#false} is VALID [2018-11-23 11:01:58,686 INFO L273 TraceCheckUtils]: 26: Hoare triple {11732#false} assume !(0bv32 == #t~mem128);havoc #t~mem127.base, #t~mem127.offset;havoc #t~mem128; {11732#false} is VALID [2018-11-23 11:01:58,686 INFO L273 TraceCheckUtils]: 27: Hoare triple {11732#false} ~skip~0 := 0bv32; {11732#false} is VALID [2018-11-23 11:01:58,686 INFO L273 TraceCheckUtils]: 28: Hoare triple {11732#false} assume !false; {11732#false} is VALID [2018-11-23 11:01:58,686 INFO L273 TraceCheckUtils]: 29: Hoare triple {11732#false} call #t~mem23 := read~intINTTYPE4(~s.base, ~bvadd32(52bv32, ~s.offset), 4bv32);~state~0 := #t~mem23;havoc #t~mem23;call #t~mem24 := read~intINTTYPE4(~s.base, ~bvadd32(52bv32, ~s.offset), 4bv32); {11732#false} is VALID [2018-11-23 11:01:58,686 INFO L273 TraceCheckUtils]: 30: Hoare triple {11732#false} assume !(12292bv32 == #t~mem24);havoc #t~mem24;call #t~mem25 := read~intINTTYPE4(~s.base, ~bvadd32(52bv32, ~s.offset), 4bv32); {11732#false} is VALID [2018-11-23 11:01:58,686 INFO L273 TraceCheckUtils]: 31: Hoare triple {11732#false} assume !(16384bv32 == #t~mem25);havoc #t~mem25;call #t~mem26 := read~intINTTYPE4(~s.base, ~bvadd32(52bv32, ~s.offset), 4bv32); {11732#false} is VALID [2018-11-23 11:01:58,687 INFO L273 TraceCheckUtils]: 32: Hoare triple {11732#false} assume !(8192bv32 == #t~mem26);havoc #t~mem26;call #t~mem27 := read~intINTTYPE4(~s.base, ~bvadd32(52bv32, ~s.offset), 4bv32); {11732#false} is VALID [2018-11-23 11:01:58,687 INFO L273 TraceCheckUtils]: 33: Hoare triple {11732#false} assume !(24576bv32 == #t~mem27);havoc #t~mem27;call #t~mem28 := read~intINTTYPE4(~s.base, ~bvadd32(52bv32, ~s.offset), 4bv32); {11732#false} is VALID [2018-11-23 11:01:58,687 INFO L273 TraceCheckUtils]: 34: Hoare triple {11732#false} assume !(8195bv32 == #t~mem28);havoc #t~mem28;call #t~mem29 := read~intINTTYPE4(~s.base, ~bvadd32(52bv32, ~s.offset), 4bv32); {11732#false} is VALID [2018-11-23 11:01:58,687 INFO L273 TraceCheckUtils]: 35: Hoare triple {11732#false} assume !(8480bv32 == #t~mem29);havoc #t~mem29;call #t~mem30 := read~intINTTYPE4(~s.base, ~bvadd32(52bv32, ~s.offset), 4bv32); {11732#false} is VALID [2018-11-23 11:01:58,687 INFO L273 TraceCheckUtils]: 36: Hoare triple {11732#false} assume !(8481bv32 == #t~mem30);havoc #t~mem30;call #t~mem31 := read~intINTTYPE4(~s.base, ~bvadd32(52bv32, ~s.offset), 4bv32); {11732#false} is VALID [2018-11-23 11:01:58,687 INFO L273 TraceCheckUtils]: 37: Hoare triple {11732#false} assume !(8482bv32 == #t~mem31);havoc #t~mem31;call #t~mem32 := read~intINTTYPE4(~s.base, ~bvadd32(52bv32, ~s.offset), 4bv32); {11732#false} is VALID [2018-11-23 11:01:58,687 INFO L273 TraceCheckUtils]: 38: Hoare triple {11732#false} assume !(8464bv32 == #t~mem32);havoc #t~mem32;call #t~mem33 := read~intINTTYPE4(~s.base, ~bvadd32(52bv32, ~s.offset), 4bv32); {11732#false} is VALID [2018-11-23 11:01:58,688 INFO L273 TraceCheckUtils]: 39: Hoare triple {11732#false} assume !(8465bv32 == #t~mem33);havoc #t~mem33;call #t~mem34 := read~intINTTYPE4(~s.base, ~bvadd32(52bv32, ~s.offset), 4bv32); {11732#false} is VALID [2018-11-23 11:01:58,688 INFO L273 TraceCheckUtils]: 40: Hoare triple {11732#false} assume !(8466bv32 == #t~mem34);havoc #t~mem34;call #t~mem35 := read~intINTTYPE4(~s.base, ~bvadd32(52bv32, ~s.offset), 4bv32); {11732#false} is VALID [2018-11-23 11:01:58,688 INFO L273 TraceCheckUtils]: 41: Hoare triple {11732#false} assume !(8496bv32 == #t~mem35);havoc #t~mem35;call #t~mem36 := read~intINTTYPE4(~s.base, ~bvadd32(52bv32, ~s.offset), 4bv32); {11732#false} is VALID [2018-11-23 11:01:58,688 INFO L273 TraceCheckUtils]: 42: Hoare triple {11732#false} assume !(8497bv32 == #t~mem36);havoc #t~mem36;call #t~mem37 := read~intINTTYPE4(~s.base, ~bvadd32(52bv32, ~s.offset), 4bv32); {11732#false} is VALID [2018-11-23 11:01:58,689 INFO L273 TraceCheckUtils]: 43: Hoare triple {11732#false} assume !(8512bv32 == #t~mem37);havoc #t~mem37;call #t~mem38 := read~intINTTYPE4(~s.base, ~bvadd32(52bv32, ~s.offset), 4bv32); {11732#false} is VALID [2018-11-23 11:01:58,689 INFO L273 TraceCheckUtils]: 44: Hoare triple {11732#false} assume !(8513bv32 == #t~mem38);havoc #t~mem38;call #t~mem39 := read~intINTTYPE4(~s.base, ~bvadd32(52bv32, ~s.offset), 4bv32); {11732#false} is VALID [2018-11-23 11:01:58,689 INFO L273 TraceCheckUtils]: 45: Hoare triple {11732#false} assume !(8528bv32 == #t~mem39);havoc #t~mem39;call #t~mem40 := read~intINTTYPE4(~s.base, ~bvadd32(52bv32, ~s.offset), 4bv32); {11732#false} is VALID [2018-11-23 11:01:58,689 INFO L273 TraceCheckUtils]: 46: Hoare triple {11732#false} assume !(8529bv32 == #t~mem40);havoc #t~mem40;call #t~mem41 := read~intINTTYPE4(~s.base, ~bvadd32(52bv32, ~s.offset), 4bv32); {11732#false} is VALID [2018-11-23 11:01:58,689 INFO L273 TraceCheckUtils]: 47: Hoare triple {11732#false} assume !(8544bv32 == #t~mem41);havoc #t~mem41;call #t~mem42 := read~intINTTYPE4(~s.base, ~bvadd32(52bv32, ~s.offset), 4bv32); {11732#false} is VALID [2018-11-23 11:01:58,690 INFO L273 TraceCheckUtils]: 48: Hoare triple {11732#false} assume !(8545bv32 == #t~mem42);havoc #t~mem42;call #t~mem43 := read~intINTTYPE4(~s.base, ~bvadd32(52bv32, ~s.offset), 4bv32); {11732#false} is VALID [2018-11-23 11:01:58,690 INFO L273 TraceCheckUtils]: 49: Hoare triple {11732#false} assume !(8560bv32 == #t~mem43);havoc #t~mem43;call #t~mem44 := read~intINTTYPE4(~s.base, ~bvadd32(52bv32, ~s.offset), 4bv32); {11732#false} is VALID [2018-11-23 11:01:58,690 INFO L273 TraceCheckUtils]: 50: Hoare triple {11732#false} assume !(8561bv32 == #t~mem44);havoc #t~mem44;call #t~mem45 := read~intINTTYPE4(~s.base, ~bvadd32(52bv32, ~s.offset), 4bv32); {11732#false} is VALID [2018-11-23 11:01:58,690 INFO L273 TraceCheckUtils]: 51: Hoare triple {11732#false} assume !(8448bv32 == #t~mem45);havoc #t~mem45;call #t~mem46 := read~intINTTYPE4(~s.base, ~bvadd32(52bv32, ~s.offset), 4bv32); {11732#false} is VALID [2018-11-23 11:01:58,690 INFO L273 TraceCheckUtils]: 52: Hoare triple {11732#false} assume !(8576bv32 == #t~mem46);havoc #t~mem46;call #t~mem47 := read~intINTTYPE4(~s.base, ~bvadd32(52bv32, ~s.offset), 4bv32); {11732#false} is VALID [2018-11-23 11:01:58,691 INFO L273 TraceCheckUtils]: 53: Hoare triple {11732#false} assume !(8577bv32 == #t~mem47);havoc #t~mem47;call #t~mem48 := read~intINTTYPE4(~s.base, ~bvadd32(52bv32, ~s.offset), 4bv32); {11732#false} is VALID [2018-11-23 11:01:58,691 INFO L273 TraceCheckUtils]: 54: Hoare triple {11732#false} assume !(8592bv32 == #t~mem48);havoc #t~mem48;call #t~mem49 := read~intINTTYPE4(~s.base, ~bvadd32(52bv32, ~s.offset), 4bv32); {11732#false} is VALID [2018-11-23 11:01:58,691 INFO L273 TraceCheckUtils]: 55: Hoare triple {11732#false} assume !(8593bv32 == #t~mem49);havoc #t~mem49;call #t~mem50 := read~intINTTYPE4(~s.base, ~bvadd32(52bv32, ~s.offset), 4bv32); {11732#false} is VALID [2018-11-23 11:01:58,691 INFO L273 TraceCheckUtils]: 56: Hoare triple {11732#false} assume !(8608bv32 == #t~mem50);havoc #t~mem50;call #t~mem51 := read~intINTTYPE4(~s.base, ~bvadd32(52bv32, ~s.offset), 4bv32); {11732#false} is VALID [2018-11-23 11:01:58,691 INFO L273 TraceCheckUtils]: 57: Hoare triple {11732#false} assume !(8609bv32 == #t~mem51);havoc #t~mem51;call #t~mem52 := read~intINTTYPE4(~s.base, ~bvadd32(52bv32, ~s.offset), 4bv32); {11732#false} is VALID [2018-11-23 11:01:58,692 INFO L273 TraceCheckUtils]: 58: Hoare triple {11732#false} assume 8640bv32 == #t~mem52;havoc #t~mem52; {11732#false} is VALID [2018-11-23 11:01:58,692 INFO L273 TraceCheckUtils]: 59: Hoare triple {11732#false} ~ret~0 := #t~nondet115;havoc #t~nondet115; {11732#false} is VALID [2018-11-23 11:01:58,692 INFO L273 TraceCheckUtils]: 60: Hoare triple {11732#false} assume !(4bv32 == ~blastFlag~0); {11732#false} is VALID [2018-11-23 11:01:58,692 INFO L273 TraceCheckUtils]: 61: Hoare triple {11732#false} assume !(7bv32 == ~blastFlag~0); {11732#false} is VALID [2018-11-23 11:01:58,692 INFO L273 TraceCheckUtils]: 62: Hoare triple {11732#false} assume !false; {11732#false} is VALID [2018-11-23 11:01:58,695 INFO L134 CoverageAnalysis]: Checked inductivity of 3 backedges. 3 proven. 0 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2018-11-23 11:01:58,695 INFO L312 TraceCheckSpWp]: Omiting computation of backward sequence because forward sequence was already perfect [2018-11-23 11:01:58,697 INFO L312 seRefinementStrategy]: Constructing automaton from 1 perfect and 0 imperfect interpolant sequences. [2018-11-23 11:01:58,697 INFO L327 seRefinementStrategy]: Number of different interpolants: perfect sequences [6] imperfect sequences [] total 6 [2018-11-23 11:01:58,697 INFO L78 Accepts]: Start accepts. Automaton has 6 states. Word has length 63 [2018-11-23 11:01:58,698 INFO L84 Accepts]: Finished accepts. word is accepted. [2018-11-23 11:01:58,698 INFO L86 InductivityCheck]: Starting indutivity check of a Floyd-Hoare automaton with 6 states. [2018-11-23 11:01:58,808 INFO L119 InductivityCheck]: Floyd-Hoare automaton has 63 edges. 63 inductive. 0 not inductive. 0 times theorem prover too weak to decide inductivity. [2018-11-23 11:01:58,808 INFO L459 AbstractCegarLoop]: Interpolant automaton has 6 states [2018-11-23 11:01:58,808 INFO L142 InterpolantAutomaton]: Constructing interpolant automaton starting with 6 interpolants. [2018-11-23 11:01:58,808 INFO L144 InterpolantAutomaton]: CoverageRelationStatistics Valid=9, Invalid=21, Unknown=0, NotChecked=0, Total=30 [2018-11-23 11:01:58,809 INFO L87 Difference]: Start difference. First operand 230 states and 372 transitions. Second operand 6 states.