java -ea -Xmx8000000000 -jar /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/plugins/org.eclipse.equinox.launcher_1.3.100.v20150511-1540.jar -data @noDefault -ultimatedata /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/data -tc ../../../trunk/examples/toolchains/AutomizerCInline_WitnessPrinter.xml -s ../../../trunk/examples/settings/default/automizer/svcomp-Reach-32bit-Automizer_Default.epf -i ../../../trunk/examples/svcomp/ntdrivers/kbfiltr_false-unreach-call.i.cil.c -------------------------------------------------------------------------------- This is Ultimate 0.1.23-61f4311 [2018-11-23 12:43:36,551 INFO L170 SettingsManager]: Resetting all preferences to default values... [2018-11-23 12:43:36,554 INFO L174 SettingsManager]: Resetting UltimateCore preferences to default values [2018-11-23 12:43:36,569 INFO L177 SettingsManager]: Ultimate Commandline Interface provides no preferences, ignoring... [2018-11-23 12:43:36,570 INFO L174 SettingsManager]: Resetting Boogie Preprocessor preferences to default values [2018-11-23 12:43:36,571 INFO L174 SettingsManager]: Resetting Boogie Procedure Inliner preferences to default values [2018-11-23 12:43:36,572 INFO L174 SettingsManager]: Resetting Abstract Interpretation preferences to default values [2018-11-23 12:43:36,574 INFO L174 SettingsManager]: Resetting LassoRanker preferences to default values [2018-11-23 12:43:36,577 INFO L174 SettingsManager]: Resetting Reaching Definitions preferences to default values [2018-11-23 12:43:36,578 INFO L174 SettingsManager]: Resetting SyntaxChecker preferences to default values [2018-11-23 12:43:36,579 INFO L177 SettingsManager]: Büchi Program Product provides no preferences, ignoring... [2018-11-23 12:43:36,579 INFO L174 SettingsManager]: Resetting LTL2Aut preferences to default values [2018-11-23 12:43:36,580 INFO L174 SettingsManager]: Resetting PEA to Boogie preferences to default values [2018-11-23 12:43:36,581 INFO L174 SettingsManager]: Resetting BlockEncodingV2 preferences to default values [2018-11-23 12:43:36,582 INFO L174 SettingsManager]: Resetting ChcToBoogie preferences to default values [2018-11-23 12:43:36,583 INFO L174 SettingsManager]: Resetting AutomataScriptInterpreter preferences to default values [2018-11-23 12:43:36,584 INFO L174 SettingsManager]: Resetting BuchiAutomizer preferences to default values [2018-11-23 12:43:36,586 INFO L174 SettingsManager]: Resetting CACSL2BoogieTranslator preferences to default values [2018-11-23 12:43:36,588 INFO L174 SettingsManager]: Resetting CodeCheck preferences to default values [2018-11-23 12:43:36,589 INFO L174 SettingsManager]: Resetting InvariantSynthesis preferences to default values [2018-11-23 12:43:36,590 INFO L174 SettingsManager]: Resetting RCFGBuilder preferences to default values [2018-11-23 12:43:36,592 INFO L174 SettingsManager]: Resetting TraceAbstraction preferences to default values [2018-11-23 12:43:36,594 INFO L177 SettingsManager]: TraceAbstractionConcurrent provides no preferences, ignoring... [2018-11-23 12:43:36,595 INFO L177 SettingsManager]: TraceAbstractionWithAFAs provides no preferences, ignoring... [2018-11-23 12:43:36,595 INFO L174 SettingsManager]: Resetting TreeAutomizer preferences to default values [2018-11-23 12:43:36,596 INFO L174 SettingsManager]: Resetting IcfgTransformer preferences to default values [2018-11-23 12:43:36,597 INFO L174 SettingsManager]: Resetting Boogie Printer preferences to default values [2018-11-23 12:43:36,598 INFO L174 SettingsManager]: Resetting ReqPrinter preferences to default values [2018-11-23 12:43:36,599 INFO L174 SettingsManager]: Resetting Witness Printer preferences to default values [2018-11-23 12:43:36,600 INFO L177 SettingsManager]: Boogie PL CUP Parser provides no preferences, ignoring... [2018-11-23 12:43:36,602 INFO L174 SettingsManager]: Resetting CDTParser preferences to default values [2018-11-23 12:43:36,603 INFO L177 SettingsManager]: AutomataScriptParser provides no preferences, ignoring... [2018-11-23 12:43:36,604 INFO L177 SettingsManager]: ReqParser provides no preferences, ignoring... [2018-11-23 12:43:36,604 INFO L174 SettingsManager]: Resetting SmtParser preferences to default values [2018-11-23 12:43:36,605 INFO L174 SettingsManager]: Resetting Witness Parser preferences to default values [2018-11-23 12:43:36,606 INFO L181 SettingsManager]: Finished resetting all preferences to default values... [2018-11-23 12:43:36,606 INFO L98 SettingsManager]: Beginning loading settings from /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/../../../trunk/examples/settings/default/automizer/svcomp-Reach-32bit-Automizer_Default.epf [2018-11-23 12:43:36,621 INFO L110 SettingsManager]: Loading preferences was successful [2018-11-23 12:43:36,621 INFO L112 SettingsManager]: Preferences different from defaults after loading the file: [2018-11-23 12:43:36,622 INFO L131 SettingsManager]: Preferences of Boogie Procedure Inliner differ from their defaults: [2018-11-23 12:43:36,623 INFO L133 SettingsManager]: * ... calls to implemented procedures=ONLY_FOR_CONCURRENT_PROGRAMS [2018-11-23 12:43:36,623 INFO L131 SettingsManager]: Preferences of BlockEncodingV2 differ from their defaults: [2018-11-23 12:43:36,623 INFO L133 SettingsManager]: * Create parallel compositions if possible=false [2018-11-23 12:43:36,624 INFO L133 SettingsManager]: * Use SBE=true [2018-11-23 12:43:36,624 INFO L131 SettingsManager]: Preferences of CACSL2BoogieTranslator differ from their defaults: [2018-11-23 12:43:36,624 INFO L133 SettingsManager]: * sizeof long=4 [2018-11-23 12:43:36,624 INFO L133 SettingsManager]: * Overapproximate operations on floating types=true [2018-11-23 12:43:36,624 INFO L133 SettingsManager]: * sizeof POINTER=4 [2018-11-23 12:43:36,625 INFO L133 SettingsManager]: * Check division by zero=IGNORE [2018-11-23 12:43:36,625 INFO L133 SettingsManager]: * Pointer to allocated memory at dereference=IGNORE [2018-11-23 12:43:36,625 INFO L133 SettingsManager]: * If two pointers are subtracted or compared they have the same base address=IGNORE [2018-11-23 12:43:36,625 INFO L133 SettingsManager]: * Check array bounds for arrays that are off heap=IGNORE [2018-11-23 12:43:36,625 INFO L133 SettingsManager]: * sizeof long double=12 [2018-11-23 12:43:36,625 INFO L133 SettingsManager]: * Check if freed pointer was valid=false [2018-11-23 12:43:36,626 INFO L133 SettingsManager]: * Use constant arrays=true [2018-11-23 12:43:36,626 INFO L133 SettingsManager]: * Pointer base address is valid at dereference=IGNORE [2018-11-23 12:43:36,626 INFO L131 SettingsManager]: Preferences of RCFGBuilder differ from their defaults: [2018-11-23 12:43:36,626 INFO L133 SettingsManager]: * Size of a code block=SequenceOfStatements [2018-11-23 12:43:36,626 INFO L133 SettingsManager]: * To the following directory=./dump/ [2018-11-23 12:43:36,627 INFO L133 SettingsManager]: * SMT solver=External_DefaultMode [2018-11-23 12:43:36,627 INFO L133 SettingsManager]: * Command for external solver=z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in -t:2000 [2018-11-23 12:43:36,627 INFO L131 SettingsManager]: Preferences of TraceAbstraction differ from their defaults: [2018-11-23 12:43:36,627 INFO L133 SettingsManager]: * Compute Interpolants along a Counterexample=FPandBP [2018-11-23 12:43:36,627 INFO L133 SettingsManager]: * Positions where we compute the Hoare Annotation=LoopsAndPotentialCycles [2018-11-23 12:43:36,628 INFO L133 SettingsManager]: * Trace refinement strategy=CAMEL [2018-11-23 12:43:36,628 INFO L133 SettingsManager]: * SMT solver=External_ModelsAndUnsatCoreMode [2018-11-23 12:43:36,628 INFO L133 SettingsManager]: * Command for external solver=z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in [2018-11-23 12:43:36,628 INFO L133 SettingsManager]: * Compute Hoare Annotation of negated interpolant automaton, abstraction and CFG=true [2018-11-23 12:43:36,677 INFO L81 nceAwareModelManager]: Repository-Root is: /tmp [2018-11-23 12:43:36,693 INFO L258 ainManager$Toolchain]: [Toolchain 1]: Applicable parser(s) successfully (re)initialized [2018-11-23 12:43:36,697 INFO L214 ainManager$Toolchain]: [Toolchain 1]: Toolchain selected. [2018-11-23 12:43:36,699 INFO L271 PluginConnector]: Initializing CDTParser... [2018-11-23 12:43:36,700 INFO L276 PluginConnector]: CDTParser initialized [2018-11-23 12:43:36,700 INFO L418 ainManager$Toolchain]: [Toolchain 1]: Parsing single file: /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/../../../trunk/examples/svcomp/ntdrivers/kbfiltr_false-unreach-call.i.cil.c [2018-11-23 12:43:36,772 INFO L221 CDTParser]: Created temporary CDT project at /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/data/ffbd5ac6d/7c335911d00049c3b01f4e17cf8520e8/FLAGab29c15c6 [2018-11-23 12:43:37,540 INFO L307 CDTParser]: Found 1 translation units. [2018-11-23 12:43:37,541 INFO L161 CDTParser]: Scanning /storage/repos/ultimate/trunk/examples/svcomp/ntdrivers/kbfiltr_false-unreach-call.i.cil.c [2018-11-23 12:43:37,578 INFO L355 CDTParser]: About to delete temporary CDT project at /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/data/ffbd5ac6d/7c335911d00049c3b01f4e17cf8520e8/FLAGab29c15c6 [2018-11-23 12:43:37,629 INFO L363 CDTParser]: Successfully deleted /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/data/ffbd5ac6d/7c335911d00049c3b01f4e17cf8520e8 [2018-11-23 12:43:37,642 INFO L296 ainManager$Toolchain]: ####################### [Toolchain 1] ####################### [2018-11-23 12:43:37,646 INFO L131 ToolchainWalker]: Walking toolchain with 6 elements. [2018-11-23 12:43:37,648 INFO L113 PluginConnector]: ------------------------CACSL2BoogieTranslator---------------------------- [2018-11-23 12:43:37,648 INFO L271 PluginConnector]: Initializing CACSL2BoogieTranslator... [2018-11-23 12:43:37,652 INFO L276 PluginConnector]: CACSL2BoogieTranslator initialized [2018-11-23 12:43:37,654 INFO L185 PluginConnector]: Executing the observer ACSLObjectContainerObserver from plugin CACSL2BoogieTranslator for "CDTParser AST 23.11 12:43:37" (1/1) ... [2018-11-23 12:43:37,657 INFO L205 PluginConnector]: Invalid model from CACSL2BoogieTranslator for observer de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator.ACSLObjectContainerObserver@289840ad and model type de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 23.11 12:43:37, skipping insertion in model container [2018-11-23 12:43:37,657 INFO L185 PluginConnector]: Executing the observer CACSL2BoogieTranslatorObserver from plugin CACSL2BoogieTranslator for "CDTParser AST 23.11 12:43:37" (1/1) ... [2018-11-23 12:43:37,669 INFO L145 MainTranslator]: Starting translation in SV-COMP mode [2018-11-23 12:43:37,772 INFO L176 MainTranslator]: Built tables and reachable declarations [2018-11-23 12:43:38,870 INFO L201 PostProcessor]: Analyzing one entry point: main [2018-11-23 12:43:38,891 INFO L191 MainTranslator]: Completed pre-run [2018-11-23 12:43:39,320 INFO L201 PostProcessor]: Analyzing one entry point: main [2018-11-23 12:43:39,389 INFO L195 MainTranslator]: Completed translation [2018-11-23 12:43:39,390 INFO L202 PluginConnector]: Adding new model de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 23.11 12:43:39 WrapperNode [2018-11-23 12:43:39,390 INFO L132 PluginConnector]: ------------------------ END CACSL2BoogieTranslator---------------------------- [2018-11-23 12:43:39,391 INFO L113 PluginConnector]: ------------------------Boogie Procedure Inliner---------------------------- [2018-11-23 12:43:39,391 INFO L271 PluginConnector]: Initializing Boogie Procedure Inliner... [2018-11-23 12:43:39,391 INFO L276 PluginConnector]: Boogie Procedure Inliner initialized [2018-11-23 12:43:39,402 INFO L185 PluginConnector]: Executing the observer TypeChecker from plugin Boogie Procedure Inliner for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 23.11 12:43:39" (1/1) ... [2018-11-23 12:43:39,483 INFO L185 PluginConnector]: Executing the observer Inliner from plugin Boogie Procedure Inliner for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 23.11 12:43:39" (1/1) ... [2018-11-23 12:43:39,517 INFO L132 PluginConnector]: ------------------------ END Boogie Procedure Inliner---------------------------- [2018-11-23 12:43:39,518 INFO L113 PluginConnector]: ------------------------Boogie Preprocessor---------------------------- [2018-11-23 12:43:39,518 INFO L271 PluginConnector]: Initializing Boogie Preprocessor... [2018-11-23 12:43:39,518 INFO L276 PluginConnector]: Boogie Preprocessor initialized [2018-11-23 12:43:39,530 INFO L185 PluginConnector]: Executing the observer EnsureBoogieModelObserver from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 23.11 12:43:39" (1/1) ... [2018-11-23 12:43:39,531 INFO L185 PluginConnector]: Executing the observer TypeChecker from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 23.11 12:43:39" (1/1) ... [2018-11-23 12:43:39,553 INFO L185 PluginConnector]: Executing the observer ConstExpander from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 23.11 12:43:39" (1/1) ... [2018-11-23 12:43:39,555 INFO L185 PluginConnector]: Executing the observer StructExpander from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 23.11 12:43:39" (1/1) ... [2018-11-23 12:43:39,756 INFO L185 PluginConnector]: Executing the observer UnstructureCode from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 23.11 12:43:39" (1/1) ... [2018-11-23 12:43:39,780 INFO L185 PluginConnector]: Executing the observer FunctionInliner from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 23.11 12:43:39" (1/1) ... [2018-11-23 12:43:39,801 INFO L185 PluginConnector]: Executing the observer BoogieSymbolTableConstructor from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 23.11 12:43:39" (1/1) ... [2018-11-23 12:43:39,843 INFO L132 PluginConnector]: ------------------------ END Boogie Preprocessor---------------------------- [2018-11-23 12:43:39,844 INFO L113 PluginConnector]: ------------------------RCFGBuilder---------------------------- [2018-11-23 12:43:39,844 INFO L271 PluginConnector]: Initializing RCFGBuilder... [2018-11-23 12:43:39,844 INFO L276 PluginConnector]: RCFGBuilder initialized [2018-11-23 12:43:39,846 INFO L185 PluginConnector]: Executing the observer RCFGBuilderObserver from plugin RCFGBuilder for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 23.11 12:43:39" (1/1) ... No working directory specified, using /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 Starting monitored process 1 with z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in -t:2000 (exit command is (exit), workingDir is null) Waiting until toolchain timeout for monitored process 1 with z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in -t:2000 [2018-11-23 12:43:39,924 INFO L130 BoogieDeclarations]: Found specification of procedure IoAttachDeviceToDeviceStack [2018-11-23 12:43:39,924 INFO L138 BoogieDeclarations]: Found implementation of procedure IoAttachDeviceToDeviceStack [2018-11-23 12:43:39,924 INFO L130 BoogieDeclarations]: Found specification of procedure KbFilter_Complete [2018-11-23 12:43:39,925 INFO L138 BoogieDeclarations]: Found implementation of procedure KbFilter_Complete [2018-11-23 12:43:39,925 INFO L130 BoogieDeclarations]: Found specification of procedure _BLAST_init [2018-11-23 12:43:39,925 INFO L138 BoogieDeclarations]: Found implementation of procedure _BLAST_init [2018-11-23 12:43:39,925 INFO L130 BoogieDeclarations]: Found specification of procedure write~unchecked~int [2018-11-23 12:43:39,925 INFO L130 BoogieDeclarations]: Found specification of procedure #Ultimate.alloc [2018-11-23 12:43:39,926 INFO L130 BoogieDeclarations]: Found specification of procedure read~int [2018-11-23 12:43:39,926 INFO L130 BoogieDeclarations]: Found specification of procedure KbFilter_AddDevice [2018-11-23 12:43:39,926 INFO L138 BoogieDeclarations]: Found implementation of procedure KbFilter_AddDevice [2018-11-23 12:43:39,926 INFO L130 BoogieDeclarations]: Found specification of procedure IoCreateDevice [2018-11-23 12:43:39,927 INFO L138 BoogieDeclarations]: Found implementation of procedure IoCreateDevice [2018-11-23 12:43:39,929 INFO L130 BoogieDeclarations]: Found specification of procedure errorFn [2018-11-23 12:43:39,929 INFO L138 BoogieDeclarations]: Found implementation of procedure errorFn [2018-11-23 12:43:39,930 INFO L130 BoogieDeclarations]: Found specification of procedure InterlockedDecrement [2018-11-23 12:43:39,930 INFO L138 BoogieDeclarations]: Found implementation of procedure InterlockedDecrement [2018-11-23 12:43:39,930 INFO L130 BoogieDeclarations]: Found specification of procedure write~int [2018-11-23 12:43:39,930 INFO L130 BoogieDeclarations]: Found specification of procedure IofCompleteRequest [2018-11-23 12:43:39,931 INFO L138 BoogieDeclarations]: Found implementation of procedure IofCompleteRequest [2018-11-23 12:43:39,931 INFO L130 BoogieDeclarations]: Found specification of procedure KbFilter_PnP [2018-11-23 12:43:39,931 INFO L138 BoogieDeclarations]: Found implementation of procedure KbFilter_PnP [2018-11-23 12:43:39,931 INFO L130 BoogieDeclarations]: Found specification of procedure #Ultimate.C_memset [2018-11-23 12:43:39,932 INFO L138 BoogieDeclarations]: Found implementation of procedure #Ultimate.C_memset [2018-11-23 12:43:39,932 INFO L130 BoogieDeclarations]: Found specification of procedure IofCallDriver [2018-11-23 12:43:39,932 INFO L138 BoogieDeclarations]: Found implementation of procedure IofCallDriver [2018-11-23 12:43:39,932 INFO L130 BoogieDeclarations]: Found specification of procedure ULTIMATE.init [2018-11-23 12:43:39,932 INFO L138 BoogieDeclarations]: Found implementation of procedure ULTIMATE.init [2018-11-23 12:43:39,933 INFO L130 BoogieDeclarations]: Found specification of procedure main [2018-11-23 12:43:39,934 INFO L138 BoogieDeclarations]: Found implementation of procedure main [2018-11-23 12:43:39,934 INFO L130 BoogieDeclarations]: Found specification of procedure write~$Pointer$ [2018-11-23 12:43:39,934 INFO L130 BoogieDeclarations]: Found specification of procedure stubMoreProcessingRequired [2018-11-23 12:43:39,934 INFO L138 BoogieDeclarations]: Found implementation of procedure stubMoreProcessingRequired [2018-11-23 12:43:39,934 INFO L130 BoogieDeclarations]: Found specification of procedure KbFilter_CreateClose [2018-11-23 12:43:39,934 INFO L138 BoogieDeclarations]: Found implementation of procedure KbFilter_CreateClose [2018-11-23 12:43:39,935 INFO L130 BoogieDeclarations]: Found specification of procedure KbFilter_InternIoCtl [2018-11-23 12:43:39,935 INFO L138 BoogieDeclarations]: Found implementation of procedure KbFilter_InternIoCtl [2018-11-23 12:43:39,935 INFO L130 BoogieDeclarations]: Found specification of procedure read~$Pointer$ [2018-11-23 12:43:39,935 INFO L130 BoogieDeclarations]: Found specification of procedure KeSetEvent [2018-11-23 12:43:39,935 INFO L138 BoogieDeclarations]: Found implementation of procedure KeSetEvent [2018-11-23 12:43:39,935 INFO L130 BoogieDeclarations]: Found specification of procedure stub_driver_init [2018-11-23 12:43:39,936 INFO L138 BoogieDeclarations]: Found implementation of procedure stub_driver_init [2018-11-23 12:43:39,936 INFO L130 BoogieDeclarations]: Found specification of procedure DriverEntry [2018-11-23 12:43:39,936 INFO L138 BoogieDeclarations]: Found implementation of procedure DriverEntry [2018-11-23 12:43:39,936 INFO L130 BoogieDeclarations]: Found specification of procedure KbFilter_IoCtl [2018-11-23 12:43:39,936 INFO L138 BoogieDeclarations]: Found implementation of procedure KbFilter_IoCtl [2018-11-23 12:43:39,936 INFO L130 BoogieDeclarations]: Found specification of procedure ULTIMATE.dealloc [2018-11-23 12:43:39,937 INFO L130 BoogieDeclarations]: Found specification of procedure PoCallDriver [2018-11-23 12:43:39,937 INFO L138 BoogieDeclarations]: Found implementation of procedure PoCallDriver [2018-11-23 12:43:39,937 INFO L130 BoogieDeclarations]: Found specification of procedure InterlockedIncrement [2018-11-23 12:43:39,937 INFO L138 BoogieDeclarations]: Found implementation of procedure InterlockedIncrement [2018-11-23 12:43:39,937 INFO L130 BoogieDeclarations]: Found specification of procedure KeWaitForSingleObject [2018-11-23 12:43:39,937 INFO L138 BoogieDeclarations]: Found implementation of procedure KeWaitForSingleObject [2018-11-23 12:43:39,938 INFO L130 BoogieDeclarations]: Found specification of procedure #Ultimate.C_memmove [2018-11-23 12:43:39,938 INFO L138 BoogieDeclarations]: Found implementation of procedure #Ultimate.C_memmove [2018-11-23 12:43:39,938 INFO L130 BoogieDeclarations]: Found specification of procedure KbFilter_Power [2018-11-23 12:43:39,939 INFO L138 BoogieDeclarations]: Found implementation of procedure KbFilter_Power [2018-11-23 12:43:39,939 INFO L130 BoogieDeclarations]: Found specification of procedure ULTIMATE.start [2018-11-23 12:43:39,939 INFO L138 BoogieDeclarations]: Found implementation of procedure ULTIMATE.start [2018-11-23 12:43:39,939 INFO L130 BoogieDeclarations]: Found specification of procedure KbFilter_DispatchPassThrough [2018-11-23 12:43:39,939 INFO L138 BoogieDeclarations]: Found implementation of procedure KbFilter_DispatchPassThrough [2018-11-23 12:43:40,952 WARN L640 $ProcedureCfgBuilder]: Two Gotos in a row! There was dead code [2018-11-23 12:43:40,955 WARN L605 $ProcedureCfgBuilder]: Label in the middle of a codeblock. [2018-11-23 12:43:41,201 WARN L640 $ProcedureCfgBuilder]: Two Gotos in a row! There was dead code [2018-11-23 12:43:41,201 WARN L605 $ProcedureCfgBuilder]: Label in the middle of a codeblock. [2018-11-23 12:43:42,856 WARN L640 $ProcedureCfgBuilder]: Two Gotos in a row! There was dead code [2018-11-23 12:43:42,857 WARN L605 $ProcedureCfgBuilder]: Label in the middle of a codeblock. [2018-11-23 12:43:53,275 WARN L640 $ProcedureCfgBuilder]: Two Gotos in a row! There was dead code [2018-11-23 12:43:53,276 WARN L605 $ProcedureCfgBuilder]: Label in the middle of a codeblock. [2018-11-23 12:43:53,598 WARN L640 $ProcedureCfgBuilder]: Two Gotos in a row! There was dead code [2018-11-23 12:43:53,598 WARN L605 $ProcedureCfgBuilder]: Label in the middle of a codeblock. [2018-11-23 12:44:00,792 WARN L640 $ProcedureCfgBuilder]: Two Gotos in a row! There was dead code [2018-11-23 12:44:00,792 WARN L605 $ProcedureCfgBuilder]: Label in the middle of a codeblock. [2018-11-23 12:44:00,845 WARN L640 $ProcedureCfgBuilder]: Two Gotos in a row! There was dead code [2018-11-23 12:44:00,845 WARN L605 $ProcedureCfgBuilder]: Label in the middle of a codeblock. [2018-11-23 12:44:03,621 WARN L640 $ProcedureCfgBuilder]: Two Gotos in a row! There was dead code [2018-11-23 12:44:03,621 WARN L605 $ProcedureCfgBuilder]: Label in the middle of a codeblock. [2018-11-23 12:44:06,023 INFO L275 CfgBuilder]: Using the 1 location(s) as analysis (start of procedure ULTIMATE.start) [2018-11-23 12:44:06,024 INFO L280 CfgBuilder]: Removed 0 assue(true) statements. [2018-11-23 12:44:06,024 INFO L202 PluginConnector]: Adding new model de.uni_freiburg.informatik.ultimate.plugins.generator.rcfgbuilder CFG 23.11 12:44:06 BoogieIcfgContainer [2018-11-23 12:44:06,024 INFO L132 PluginConnector]: ------------------------ END RCFGBuilder---------------------------- [2018-11-23 12:44:06,025 INFO L113 PluginConnector]: ------------------------TraceAbstraction---------------------------- [2018-11-23 12:44:06,025 INFO L271 PluginConnector]: Initializing TraceAbstraction... [2018-11-23 12:44:06,029 INFO L276 PluginConnector]: TraceAbstraction initialized [2018-11-23 12:44:06,030 INFO L185 PluginConnector]: Executing the observer TraceAbstractionObserver from plugin TraceAbstraction for "CDTParser AST 23.11 12:43:37" (1/3) ... [2018-11-23 12:44:06,031 INFO L205 PluginConnector]: Invalid model from TraceAbstraction for observer de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction.TraceAbstractionObserver@71866abb and model type de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction AST 23.11 12:44:06, skipping insertion in model container [2018-11-23 12:44:06,032 INFO L185 PluginConnector]: Executing the observer TraceAbstractionObserver from plugin TraceAbstraction for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 23.11 12:43:39" (2/3) ... [2018-11-23 12:44:06,032 INFO L205 PluginConnector]: Invalid model from TraceAbstraction for observer de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction.TraceAbstractionObserver@71866abb and model type de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction AST 23.11 12:44:06, skipping insertion in model container [2018-11-23 12:44:06,032 INFO L185 PluginConnector]: Executing the observer TraceAbstractionObserver from plugin TraceAbstraction for "de.uni_freiburg.informatik.ultimate.plugins.generator.rcfgbuilder CFG 23.11 12:44:06" (3/3) ... [2018-11-23 12:44:06,035 INFO L112 eAbstractionObserver]: Analyzing ICFG kbfiltr_false-unreach-call.i.cil.c [2018-11-23 12:44:06,045 INFO L156 ceAbstractionStarter]: Automizer settings: Hoare:true NWA Interpolation:FPandBP Determinization: PREDICATE_ABSTRACTION [2018-11-23 12:44:06,055 INFO L168 ceAbstractionStarter]: Appying trace abstraction to program that has 1 error locations. [2018-11-23 12:44:06,073 INFO L257 AbstractCegarLoop]: Starting to check reachability of 1 error locations. [2018-11-23 12:44:06,110 INFO L133 ementStrategyFactory]: Using default assertion order modulation [2018-11-23 12:44:06,110 INFO L382 AbstractCegarLoop]: Interprodecural is true [2018-11-23 12:44:06,111 INFO L383 AbstractCegarLoop]: Hoare is true [2018-11-23 12:44:06,111 INFO L384 AbstractCegarLoop]: Compute interpolants for FPandBP [2018-11-23 12:44:06,111 INFO L385 AbstractCegarLoop]: Backedges is STRAIGHT_LINE [2018-11-23 12:44:06,111 INFO L386 AbstractCegarLoop]: Determinization is PREDICATE_ABSTRACTION [2018-11-23 12:44:06,111 INFO L387 AbstractCegarLoop]: Difference is false [2018-11-23 12:44:06,111 INFO L388 AbstractCegarLoop]: Minimize is MINIMIZE_SEVPA [2018-11-23 12:44:06,111 INFO L393 AbstractCegarLoop]: ======== Iteration 0==of CEGAR loop == AllErrorsAtOnce======== [2018-11-23 12:44:06,143 INFO L276 IsEmpty]: Start isEmpty. Operand 301 states. [2018-11-23 12:44:06,151 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 26 [2018-11-23 12:44:06,151 INFO L394 BasicCegarLoop]: Found error trace [2018-11-23 12:44:06,153 INFO L402 BasicCegarLoop]: trace histogram [1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2018-11-23 12:44:06,155 INFO L423 AbstractCegarLoop]: === Iteration 1 === [errorFnErr0ASSERT_VIOLATIONERROR_FUNCTION]=== [2018-11-23 12:44:06,161 INFO L141 PredicateUnifier]: Initialized classic predicate unifier [2018-11-23 12:44:06,162 INFO L82 PathProgramCache]: Analyzing trace with hash 529823455, now seen corresponding path program 1 times [2018-11-23 12:44:06,164 INFO L223 ckRefinementStrategy]: Switched to mode SMTINTERPOL_TREE_INTERPOLANTS [2018-11-23 12:44:06,164 INFO L69 tionRefinementEngine]: Using refinement strategy CamelRefinementStrategy [2018-11-23 12:44:06,281 INFO L119 rtionOrderModulation]: Craig_TreeInterpolation forces the order to NOT_INCREMENTALLY [2018-11-23 12:44:06,282 INFO L103 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2018-11-23 12:44:06,282 INFO L119 rtionOrderModulation]: Craig_TreeInterpolation forces the order to NOT_INCREMENTALLY [2018-11-23 12:44:06,502 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2018-11-23 12:44:07,089 INFO L256 TraceCheckUtils]: 0: Hoare triple {304#true} call ULTIMATE.init(); {304#true} is VALID [2018-11-23 12:44:07,090 INFO L273 TraceCheckUtils]: 1: Hoare triple {304#true} #NULL.base, #NULL.offset := 0, 0;#valid := #valid[0 := 0];~s~0 := 0;~UNLOADED~0 := 0;~NP~0 := 0;~DC~0 := 0;~SKIP1~0 := 0;~SKIP2~0 := 0;~MPR1~0 := 0;~MPR3~0 := 0;~IPC~0 := 0;~pended~0 := 0;~compRegistered~0 := 0;~lowerDriverReturn~0 := 0;~setEventCalled~0 := 0;~customIrp~0 := 0;~myStatus~0 := 0;~_SLAM_alloc_dummy~0 := 0;~compFptr~0.base, ~compFptr~0.offset := 0, 0;~pirp~0.base, ~pirp~0.offset := 0, 0; {304#true} is VALID [2018-11-23 12:44:07,091 INFO L273 TraceCheckUtils]: 2: Hoare triple {304#true} assume true; {304#true} is VALID [2018-11-23 12:44:07,091 INFO L268 TraceCheckUtils]: 3: Hoare quadruple {304#true} {304#true} #905#return; {304#true} is VALID [2018-11-23 12:44:07,092 INFO L256 TraceCheckUtils]: 4: Hoare triple {304#true} call #t~ret331 := main(); {304#true} is VALID [2018-11-23 12:44:07,092 INFO L273 TraceCheckUtils]: 5: Hoare triple {304#true} call ~#d~0.base, ~#d~0.offset := #Ultimate.alloc(168);call ~#u~0.base, ~#u~0.offset := #Ultimate.alloc(8);havoc ~status~5;assume -2147483648 <= #t~nondet270 && #t~nondet270 <= 2147483647;~we_should_unload~0 := #t~nondet270;havoc #t~nondet270;call ~#irp~0.base, ~#irp~0.offset := #Ultimate.alloc(111);assume -2147483648 <= #t~nondet271 && #t~nondet271 <= 2147483647;~__BLAST_NONDET~0 := #t~nondet271;havoc #t~nondet271;assume -2147483648 <= #t~nondet272 && #t~nondet272 <= 2147483647;~irp_choice~0 := #t~nondet272;havoc #t~nondet272;call ~#devext~0.base, ~#devext~0.offset := #Ultimate.alloc(55);call ~#devobj~0.base, ~#devobj~0.offset := #Ultimate.alloc(175);call write~$Pointer$(~#devext~0.base, ~#devext~0.offset, ~#devobj~0.base, 40 + ~#devobj~0.offset, 4);call ~#ext~0.base, ~#ext~0.offset := #Ultimate.alloc(20);call write~$Pointer$(~#ext~0.base, ~#ext~0.offset, ~#d~0.base, 24 + ~#d~0.offset, 4);call ~#hookkb~0.base, ~#hookkb~0.offset := #Ultimate.alloc(24);call ~#stack~0.base, ~#stack~0.offset := #Ultimate.alloc(108);call write~int(#t~nondet273, ~#stack~0.base, ~#stack~0.offset, 1);havoc #t~nondet273;call write~int(#t~nondet274, ~#stack~0.base, 36 + ~#stack~0.offset, 1);havoc #t~nondet274;call write~int(#t~nondet275, ~#stack~0.base, 72 + ~#stack~0.offset, 1);havoc #t~nondet275;call write~int(#t~nondet276, ~#stack~0.base, 1 + ~#stack~0.offset, 1);havoc #t~nondet276;call write~int(#t~nondet277, ~#stack~0.base, 37 + ~#stack~0.offset, 1);havoc #t~nondet277;call write~int(#t~nondet278, ~#stack~0.base, 73 + ~#stack~0.offset, 1);havoc #t~nondet278;call write~$Pointer$(~#hookkb~0.base, ~#hookkb~0.offset, ~#stack~0.base, 16 + ~#stack~0.offset, 4);call write~$Pointer$(~#hookkb~0.base, ~#hookkb~0.offset, ~#stack~0.base, 52 + ~#stack~0.offset, 4);call write~$Pointer$(~#hookkb~0.base, ~#hookkb~0.offset, ~#stack~0.base, 88 + ~#stack~0.offset, 4);call write~int(#t~nondet279, ~#stack~0.base, 8 + ~#stack~0.offset, 4);havoc #t~nondet279;call write~int(#t~nondet280, ~#stack~0.base, 44 + ~#stack~0.offset, 4);havoc #t~nondet280;call write~int(#t~nondet281, ~#stack~0.base, 80 + ~#stack~0.offset, 4);havoc #t~nondet281;call write~int(#t~nondet282, ~#stack~0.base, 12 + ~#stack~0.offset, 4);havoc #t~nondet282;call write~int(#t~nondet283, ~#stack~0.base, 48 + ~#stack~0.offset, 4);havoc #t~nondet283;call write~int(#t~nondet284, ~#stack~0.base, 84 + ~#stack~0.offset, 4);havoc #t~nondet284;call write~$Pointer$(~#stack~0.base, 36 + ~#stack~0.offset, ~#irp~0.base, 96 + ~#irp~0.offset, 4);~pirp~0.base, ~pirp~0.offset := ~#irp~0.base, ~#irp~0.offset; {304#true} is VALID [2018-11-23 12:44:07,093 INFO L256 TraceCheckUtils]: 6: Hoare triple {304#true} call _BLAST_init(); {304#true} is VALID [2018-11-23 12:44:07,093 INFO L273 TraceCheckUtils]: 7: Hoare triple {304#true} ~UNLOADED~0 := 0;~NP~0 := 1;~DC~0 := 2;~SKIP1~0 := 3;~SKIP2~0 := 4;~MPR1~0 := 5;~MPR3~0 := 6;~IPC~0 := 7;~s~0 := ~UNLOADED~0;~pended~0 := 0;~compFptr~0.base, ~compFptr~0.offset := 0, 0;~compRegistered~0 := 0;~lowerDriverReturn~0 := 0;~setEventCalled~0 := 0;~customIrp~0 := 0; {304#true} is VALID [2018-11-23 12:44:07,094 INFO L273 TraceCheckUtils]: 8: Hoare triple {304#true} assume true; {304#true} is VALID [2018-11-23 12:44:07,094 INFO L268 TraceCheckUtils]: 9: Hoare quadruple {304#true} {304#true} #819#return; {304#true} is VALID [2018-11-23 12:44:07,094 INFO L256 TraceCheckUtils]: 10: Hoare triple {304#true} call #t~ret285 := DriverEntry(~#d~0.base, ~#d~0.offset, ~#u~0.base, ~#u~0.offset); {304#true} is VALID [2018-11-23 12:44:07,106 INFO L273 TraceCheckUtils]: 11: Hoare triple {304#true} ~DriverObject.base, ~DriverObject.offset := #in~DriverObject.base, #in~DriverObject.offset;~RegistryPath.base, ~RegistryPath.offset := #in~RegistryPath.base, #in~RegistryPath.offset;assume -2147483648 <= #t~nondet17 && #t~nondet17 <= 2147483647;~i~0 := #t~nondet17;havoc #t~nondet17;assume 0 != (if ~i~0 % 4294967296 < 28 then 1 else 0);call write~$Pointer$(#funAddr~KbFilter_DispatchPassThrough.base, #funAddr~KbFilter_DispatchPassThrough.offset, ~DriverObject.base, 56 + ~DriverObject.offset + 4 * (if ~i~0 % 4294967296 % 4294967296 <= 2147483647 then ~i~0 % 4294967296 % 4294967296 else ~i~0 % 4294967296 % 4294967296 - 4294967296), 4);call write~$Pointer$(#funAddr~KbFilter_CreateClose.base, #funAddr~KbFilter_CreateClose.offset, ~DriverObject.base, 56 + ~DriverObject.offset, 4);call write~$Pointer$(#funAddr~KbFilter_CreateClose.base, #funAddr~KbFilter_CreateClose.offset, ~DriverObject.base, 64 + ~DriverObject.offset, 4);call write~$Pointer$(#funAddr~KbFilter_PnP.base, #funAddr~KbFilter_PnP.offset, ~DriverObject.base, 164 + ~DriverObject.offset, 4);call write~$Pointer$(#funAddr~KbFilter_Power.base, #funAddr~KbFilter_Power.offset, ~DriverObject.base, 144 + ~DriverObject.offset, 4);call write~$Pointer$(#funAddr~KbFilter_InternIoCtl.base, #funAddr~KbFilter_InternIoCtl.offset, ~DriverObject.base, 116 + ~DriverObject.offset, 4);call write~$Pointer$(#funAddr~KbFilter_Unload.base, #funAddr~KbFilter_Unload.offset, ~DriverObject.base, 52 + ~DriverObject.offset, 4);call #t~mem18.base, #t~mem18.offset := read~$Pointer$(~DriverObject.base, 24 + ~DriverObject.offset, 4);call write~$Pointer$(#funAddr~KbFilter_AddDevice.base, #funAddr~KbFilter_AddDevice.offset, #t~mem18.base, 4 + #t~mem18.offset, 4);havoc #t~mem18.base, #t~mem18.offset;#res := 0; {306#(= 0 |DriverEntry_#res|)} is VALID [2018-11-23 12:44:07,116 INFO L273 TraceCheckUtils]: 12: Hoare triple {306#(= 0 |DriverEntry_#res|)} assume true; {306#(= 0 |DriverEntry_#res|)} is VALID [2018-11-23 12:44:07,125 INFO L268 TraceCheckUtils]: 13: Hoare quadruple {306#(= 0 |DriverEntry_#res|)} {304#true} #821#return; {307#(= 0 |main_#t~ret285|)} is VALID [2018-11-23 12:44:07,126 INFO L273 TraceCheckUtils]: 14: Hoare triple {307#(= 0 |main_#t~ret285|)} assume -2147483648 <= #t~ret285 && #t~ret285 <= 2147483647;~status~5 := #t~ret285;havoc #t~ret285; {308#(= main_~status~5 0)} is VALID [2018-11-23 12:44:07,127 INFO L273 TraceCheckUtils]: 15: Hoare triple {308#(= main_~status~5 0)} assume !(~status~5 >= 0); {305#false} is VALID [2018-11-23 12:44:07,127 INFO L273 TraceCheckUtils]: 16: Hoare triple {305#false} assume !(1 == ~pended~0); {305#false} is VALID [2018-11-23 12:44:07,127 INFO L273 TraceCheckUtils]: 17: Hoare triple {305#false} assume !(1 == ~pended~0); {305#false} is VALID [2018-11-23 12:44:07,128 INFO L273 TraceCheckUtils]: 18: Hoare triple {305#false} assume !(~s~0 == ~UNLOADED~0); {305#false} is VALID [2018-11-23 12:44:07,128 INFO L273 TraceCheckUtils]: 19: Hoare triple {305#false} assume !(-1 == ~status~5); {305#false} is VALID [2018-11-23 12:44:07,128 INFO L273 TraceCheckUtils]: 20: Hoare triple {305#false} assume !(~s~0 != ~SKIP2~0); {305#false} is VALID [2018-11-23 12:44:07,129 INFO L273 TraceCheckUtils]: 21: Hoare triple {305#false} assume 1 == ~pended~0; {305#false} is VALID [2018-11-23 12:44:07,129 INFO L273 TraceCheckUtils]: 22: Hoare triple {305#false} assume 259 != ~status~5; {305#false} is VALID [2018-11-23 12:44:07,129 INFO L256 TraceCheckUtils]: 23: Hoare triple {305#false} call errorFn(); {305#false} is VALID [2018-11-23 12:44:07,130 INFO L273 TraceCheckUtils]: 24: Hoare triple {305#false} assume !false; {305#false} is VALID [2018-11-23 12:44:07,135 INFO L134 CoverageAnalysis]: Checked inductivity of 0 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2018-11-23 12:44:07,138 INFO L312 seRefinementStrategy]: Constructing automaton from 1 perfect and 0 imperfect interpolant sequences. [2018-11-23 12:44:07,138 INFO L327 seRefinementStrategy]: Number of different interpolants: perfect sequences [5] imperfect sequences [] total 5 [2018-11-23 12:44:07,144 INFO L78 Accepts]: Start accepts. Automaton has 5 states. Word has length 25 [2018-11-23 12:44:07,147 INFO L84 Accepts]: Finished accepts. word is accepted. [2018-11-23 12:44:07,151 INFO L86 InductivityCheck]: Starting indutivity check of a Floyd-Hoare automaton with 5 states. [2018-11-23 12:44:07,390 INFO L119 InductivityCheck]: Floyd-Hoare automaton has 25 edges. 25 inductive. 0 not inductive. 0 times theorem prover too weak to decide inductivity. [2018-11-23 12:44:07,391 INFO L459 AbstractCegarLoop]: Interpolant automaton has 5 states [2018-11-23 12:44:07,398 INFO L142 InterpolantAutomaton]: Constructing interpolant automaton starting with 5 interpolants. [2018-11-23 12:44:07,399 INFO L144 InterpolantAutomaton]: CoverageRelationStatistics Valid=7, Invalid=13, Unknown=0, NotChecked=0, Total=20 [2018-11-23 12:44:07,402 INFO L87 Difference]: Start difference. First operand 301 states. Second operand 5 states. [2018-11-23 12:45:30,354 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2018-11-23 12:45:30,354 INFO L93 Difference]: Finished difference Result 454 states and 663 transitions. [2018-11-23 12:45:30,354 INFO L142 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 5 states. [2018-11-23 12:45:30,355 INFO L78 Accepts]: Start accepts. Automaton has 5 states. Word has length 25 [2018-11-23 12:45:30,355 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2018-11-23 12:45:30,357 INFO L82 GeneralOperation]: Start removeUnreachable. Operand 5 states. [2018-11-23 12:45:30,396 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 5 states to 5 states and 663 transitions. [2018-11-23 12:45:30,396 INFO L82 GeneralOperation]: Start removeUnreachable. Operand 5 states. [2018-11-23 12:45:30,421 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 5 states to 5 states and 663 transitions. [2018-11-23 12:45:30,421 INFO L86 InductivityCheck]: Starting indutivity check of a Floyd-Hoare automaton with 5 states and 663 transitions. [2018-11-23 12:45:31,801 INFO L119 InductivityCheck]: Floyd-Hoare automaton has 663 edges. 663 inductive. 0 not inductive. 0 times theorem prover too weak to decide inductivity. [2018-11-23 12:45:31,842 INFO L225 Difference]: With dead ends: 454 [2018-11-23 12:45:31,843 INFO L226 Difference]: Without dead ends: 292 [2018-11-23 12:45:31,850 INFO L631 BasicCegarLoop]: 0 DeclaredPredicates, 6 GetRequests, 2 SyntacticMatches, 1 SemanticMatches, 3 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 0 ImplicationChecksByTransitivity, 0.1s TimeCoverageRelationStatistics Valid=7, Invalid=13, Unknown=0, NotChecked=0, Total=20 [2018-11-23 12:45:31,872 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 292 states. [2018-11-23 12:45:32,068 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 292 to 292. [2018-11-23 12:45:32,069 INFO L214 AbstractMinimizeNwa]: Start testing correctness of minimizeSevpa [2018-11-23 12:45:32,069 INFO L82 GeneralOperation]: Start isEquivalent. First operand 292 states. Second operand 292 states. [2018-11-23 12:45:32,070 INFO L74 IsIncluded]: Start isIncluded. First operand 292 states. Second operand 292 states. [2018-11-23 12:45:32,070 INFO L87 Difference]: Start difference. First operand 292 states. Second operand 292 states. [2018-11-23 12:45:32,090 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2018-11-23 12:45:32,090 INFO L93 Difference]: Finished difference Result 292 states and 398 transitions. [2018-11-23 12:45:32,091 INFO L276 IsEmpty]: Start isEmpty. Operand 292 states and 398 transitions. [2018-11-23 12:45:32,096 INFO L282 IsEmpty]: Finished isEmpty. No accepting run. [2018-11-23 12:45:32,096 INFO L83 IsIncluded]: Finished isIncluded. Language is included [2018-11-23 12:45:32,096 INFO L74 IsIncluded]: Start isIncluded. First operand 292 states. Second operand 292 states. [2018-11-23 12:45:32,097 INFO L87 Difference]: Start difference. First operand 292 states. Second operand 292 states. [2018-11-23 12:45:32,114 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2018-11-23 12:45:32,115 INFO L93 Difference]: Finished difference Result 292 states and 398 transitions. [2018-11-23 12:45:32,115 INFO L276 IsEmpty]: Start isEmpty. Operand 292 states and 398 transitions. [2018-11-23 12:45:32,118 INFO L282 IsEmpty]: Finished isEmpty. No accepting run. [2018-11-23 12:45:32,118 INFO L83 IsIncluded]: Finished isIncluded. Language is included [2018-11-23 12:45:32,119 INFO L88 GeneralOperation]: Finished isEquivalent. [2018-11-23 12:45:32,119 INFO L221 AbstractMinimizeNwa]: Finished testing correctness of minimizeSevpa [2018-11-23 12:45:32,119 INFO L82 GeneralOperation]: Start removeUnreachable. Operand 292 states. [2018-11-23 12:45:32,135 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 292 states to 292 states and 398 transitions. [2018-11-23 12:45:32,138 INFO L78 Accepts]: Start accepts. Automaton has 292 states and 398 transitions. Word has length 25 [2018-11-23 12:45:32,138 INFO L84 Accepts]: Finished accepts. word is rejected. [2018-11-23 12:45:32,139 INFO L480 AbstractCegarLoop]: Abstraction has 292 states and 398 transitions. [2018-11-23 12:45:32,139 INFO L481 AbstractCegarLoop]: Interpolant automaton has 5 states. [2018-11-23 12:45:32,139 INFO L276 IsEmpty]: Start isEmpty. Operand 292 states and 398 transitions. [2018-11-23 12:45:32,141 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 48 [2018-11-23 12:45:32,141 INFO L394 BasicCegarLoop]: Found error trace [2018-11-23 12:45:32,141 INFO L402 BasicCegarLoop]: trace histogram [1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2018-11-23 12:45:32,142 INFO L423 AbstractCegarLoop]: === Iteration 2 === [errorFnErr0ASSERT_VIOLATIONERROR_FUNCTION]=== [2018-11-23 12:45:32,142 INFO L141 PredicateUnifier]: Initialized classic predicate unifier [2018-11-23 12:45:32,142 INFO L82 PathProgramCache]: Analyzing trace with hash 1383359001, now seen corresponding path program 1 times [2018-11-23 12:45:32,142 INFO L223 ckRefinementStrategy]: Switched to mode SMTINTERPOL_TREE_INTERPOLANTS [2018-11-23 12:45:32,143 INFO L69 tionRefinementEngine]: Using refinement strategy CamelRefinementStrategy [2018-11-23 12:45:32,153 INFO L119 rtionOrderModulation]: Craig_TreeInterpolation forces the order to NOT_INCREMENTALLY [2018-11-23 12:45:32,154 INFO L103 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2018-11-23 12:45:32,154 INFO L119 rtionOrderModulation]: Craig_TreeInterpolation forces the order to NOT_INCREMENTALLY [2018-11-23 12:45:32,243 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2018-11-23 12:45:32,762 INFO L256 TraceCheckUtils]: 0: Hoare triple {1913#true} call ULTIMATE.init(); {1913#true} is VALID [2018-11-23 12:45:32,763 INFO L273 TraceCheckUtils]: 1: Hoare triple {1913#true} #NULL.base, #NULL.offset := 0, 0;#valid := #valid[0 := 0];~s~0 := 0;~UNLOADED~0 := 0;~NP~0 := 0;~DC~0 := 0;~SKIP1~0 := 0;~SKIP2~0 := 0;~MPR1~0 := 0;~MPR3~0 := 0;~IPC~0 := 0;~pended~0 := 0;~compRegistered~0 := 0;~lowerDriverReturn~0 := 0;~setEventCalled~0 := 0;~customIrp~0 := 0;~myStatus~0 := 0;~_SLAM_alloc_dummy~0 := 0;~compFptr~0.base, ~compFptr~0.offset := 0, 0;~pirp~0.base, ~pirp~0.offset := 0, 0; {1913#true} is VALID [2018-11-23 12:45:32,763 INFO L273 TraceCheckUtils]: 2: Hoare triple {1913#true} assume true; {1913#true} is VALID [2018-11-23 12:45:32,764 INFO L268 TraceCheckUtils]: 3: Hoare quadruple {1913#true} {1913#true} #905#return; {1913#true} is VALID [2018-11-23 12:45:32,764 INFO L256 TraceCheckUtils]: 4: Hoare triple {1913#true} call #t~ret331 := main(); {1913#true} is VALID [2018-11-23 12:45:32,764 INFO L273 TraceCheckUtils]: 5: Hoare triple {1913#true} call ~#d~0.base, ~#d~0.offset := #Ultimate.alloc(168);call ~#u~0.base, ~#u~0.offset := #Ultimate.alloc(8);havoc ~status~5;assume -2147483648 <= #t~nondet270 && #t~nondet270 <= 2147483647;~we_should_unload~0 := #t~nondet270;havoc #t~nondet270;call ~#irp~0.base, ~#irp~0.offset := #Ultimate.alloc(111);assume -2147483648 <= #t~nondet271 && #t~nondet271 <= 2147483647;~__BLAST_NONDET~0 := #t~nondet271;havoc #t~nondet271;assume -2147483648 <= #t~nondet272 && #t~nondet272 <= 2147483647;~irp_choice~0 := #t~nondet272;havoc #t~nondet272;call ~#devext~0.base, ~#devext~0.offset := #Ultimate.alloc(55);call ~#devobj~0.base, ~#devobj~0.offset := #Ultimate.alloc(175);call write~$Pointer$(~#devext~0.base, ~#devext~0.offset, ~#devobj~0.base, 40 + ~#devobj~0.offset, 4);call ~#ext~0.base, ~#ext~0.offset := #Ultimate.alloc(20);call write~$Pointer$(~#ext~0.base, ~#ext~0.offset, ~#d~0.base, 24 + ~#d~0.offset, 4);call ~#hookkb~0.base, ~#hookkb~0.offset := #Ultimate.alloc(24);call ~#stack~0.base, ~#stack~0.offset := #Ultimate.alloc(108);call write~int(#t~nondet273, ~#stack~0.base, ~#stack~0.offset, 1);havoc #t~nondet273;call write~int(#t~nondet274, ~#stack~0.base, 36 + ~#stack~0.offset, 1);havoc #t~nondet274;call write~int(#t~nondet275, ~#stack~0.base, 72 + ~#stack~0.offset, 1);havoc #t~nondet275;call write~int(#t~nondet276, ~#stack~0.base, 1 + ~#stack~0.offset, 1);havoc #t~nondet276;call write~int(#t~nondet277, ~#stack~0.base, 37 + ~#stack~0.offset, 1);havoc #t~nondet277;call write~int(#t~nondet278, ~#stack~0.base, 73 + ~#stack~0.offset, 1);havoc #t~nondet278;call write~$Pointer$(~#hookkb~0.base, ~#hookkb~0.offset, ~#stack~0.base, 16 + ~#stack~0.offset, 4);call write~$Pointer$(~#hookkb~0.base, ~#hookkb~0.offset, ~#stack~0.base, 52 + ~#stack~0.offset, 4);call write~$Pointer$(~#hookkb~0.base, ~#hookkb~0.offset, ~#stack~0.base, 88 + ~#stack~0.offset, 4);call write~int(#t~nondet279, ~#stack~0.base, 8 + ~#stack~0.offset, 4);havoc #t~nondet279;call write~int(#t~nondet280, ~#stack~0.base, 44 + ~#stack~0.offset, 4);havoc #t~nondet280;call write~int(#t~nondet281, ~#stack~0.base, 80 + ~#stack~0.offset, 4);havoc #t~nondet281;call write~int(#t~nondet282, ~#stack~0.base, 12 + ~#stack~0.offset, 4);havoc #t~nondet282;call write~int(#t~nondet283, ~#stack~0.base, 48 + ~#stack~0.offset, 4);havoc #t~nondet283;call write~int(#t~nondet284, ~#stack~0.base, 84 + ~#stack~0.offset, 4);havoc #t~nondet284;call write~$Pointer$(~#stack~0.base, 36 + ~#stack~0.offset, ~#irp~0.base, 96 + ~#irp~0.offset, 4);~pirp~0.base, ~pirp~0.offset := ~#irp~0.base, ~#irp~0.offset; {1913#true} is VALID [2018-11-23 12:45:32,764 INFO L256 TraceCheckUtils]: 6: Hoare triple {1913#true} call _BLAST_init(); {1913#true} is VALID [2018-11-23 12:45:32,765 INFO L273 TraceCheckUtils]: 7: Hoare triple {1913#true} ~UNLOADED~0 := 0;~NP~0 := 1;~DC~0 := 2;~SKIP1~0 := 3;~SKIP2~0 := 4;~MPR1~0 := 5;~MPR3~0 := 6;~IPC~0 := 7;~s~0 := ~UNLOADED~0;~pended~0 := 0;~compFptr~0.base, ~compFptr~0.offset := 0, 0;~compRegistered~0 := 0;~lowerDriverReturn~0 := 0;~setEventCalled~0 := 0;~customIrp~0 := 0; {1913#true} is VALID [2018-11-23 12:45:32,765 INFO L273 TraceCheckUtils]: 8: Hoare triple {1913#true} assume true; {1913#true} is VALID [2018-11-23 12:45:32,765 INFO L268 TraceCheckUtils]: 9: Hoare quadruple {1913#true} {1913#true} #819#return; {1913#true} is VALID [2018-11-23 12:45:32,765 INFO L256 TraceCheckUtils]: 10: Hoare triple {1913#true} call #t~ret285 := DriverEntry(~#d~0.base, ~#d~0.offset, ~#u~0.base, ~#u~0.offset); {1913#true} is VALID [2018-11-23 12:45:32,766 INFO L273 TraceCheckUtils]: 11: Hoare triple {1913#true} ~DriverObject.base, ~DriverObject.offset := #in~DriverObject.base, #in~DriverObject.offset;~RegistryPath.base, ~RegistryPath.offset := #in~RegistryPath.base, #in~RegistryPath.offset;assume -2147483648 <= #t~nondet17 && #t~nondet17 <= 2147483647;~i~0 := #t~nondet17;havoc #t~nondet17;assume 0 != (if ~i~0 % 4294967296 < 28 then 1 else 0);call write~$Pointer$(#funAddr~KbFilter_DispatchPassThrough.base, #funAddr~KbFilter_DispatchPassThrough.offset, ~DriverObject.base, 56 + ~DriverObject.offset + 4 * (if ~i~0 % 4294967296 % 4294967296 <= 2147483647 then ~i~0 % 4294967296 % 4294967296 else ~i~0 % 4294967296 % 4294967296 - 4294967296), 4);call write~$Pointer$(#funAddr~KbFilter_CreateClose.base, #funAddr~KbFilter_CreateClose.offset, ~DriverObject.base, 56 + ~DriverObject.offset, 4);call write~$Pointer$(#funAddr~KbFilter_CreateClose.base, #funAddr~KbFilter_CreateClose.offset, ~DriverObject.base, 64 + ~DriverObject.offset, 4);call write~$Pointer$(#funAddr~KbFilter_PnP.base, #funAddr~KbFilter_PnP.offset, ~DriverObject.base, 164 + ~DriverObject.offset, 4);call write~$Pointer$(#funAddr~KbFilter_Power.base, #funAddr~KbFilter_Power.offset, ~DriverObject.base, 144 + ~DriverObject.offset, 4);call write~$Pointer$(#funAddr~KbFilter_InternIoCtl.base, #funAddr~KbFilter_InternIoCtl.offset, ~DriverObject.base, 116 + ~DriverObject.offset, 4);call write~$Pointer$(#funAddr~KbFilter_Unload.base, #funAddr~KbFilter_Unload.offset, ~DriverObject.base, 52 + ~DriverObject.offset, 4);call #t~mem18.base, #t~mem18.offset := read~$Pointer$(~DriverObject.base, 24 + ~DriverObject.offset, 4);call write~$Pointer$(#funAddr~KbFilter_AddDevice.base, #funAddr~KbFilter_AddDevice.offset, #t~mem18.base, 4 + #t~mem18.offset, 4);havoc #t~mem18.base, #t~mem18.offset;#res := 0; {1913#true} is VALID [2018-11-23 12:45:32,766 INFO L273 TraceCheckUtils]: 12: Hoare triple {1913#true} assume true; {1913#true} is VALID [2018-11-23 12:45:32,766 INFO L268 TraceCheckUtils]: 13: Hoare quadruple {1913#true} {1913#true} #821#return; {1913#true} is VALID [2018-11-23 12:45:32,767 INFO L273 TraceCheckUtils]: 14: Hoare triple {1913#true} assume -2147483648 <= #t~ret285 && #t~ret285 <= 2147483647;~status~5 := #t~ret285;havoc #t~ret285; {1913#true} is VALID [2018-11-23 12:45:32,767 INFO L273 TraceCheckUtils]: 15: Hoare triple {1913#true} assume ~status~5 >= 0;~s~0 := ~NP~0;~customIrp~0 := 0;~setEventCalled~0 := ~customIrp~0;~lowerDriverReturn~0 := ~setEventCalled~0;~compRegistered~0 := ~lowerDriverReturn~0;~compFptr~0.base, ~compFptr~0.offset := 0, ~compRegistered~0;~pended~0 := ~compFptr~0.base + ~compFptr~0.offset;call write~int(0, ~pirp~0.base, 24 + ~pirp~0.offset, 4);~myStatus~0 := 0; {1913#true} is VALID [2018-11-23 12:45:32,767 INFO L273 TraceCheckUtils]: 16: Hoare triple {1913#true} assume 0 == ~irp_choice~0;call write~int(-1073741637, ~pirp~0.base, 24 + ~pirp~0.offset, 4);~myStatus~0 := -1073741637; {1913#true} is VALID [2018-11-23 12:45:32,768 INFO L256 TraceCheckUtils]: 17: Hoare triple {1913#true} call #t~ret286 := KbFilter_AddDevice(~#d~0.base, ~#d~0.offset, ~#devobj~0.base, ~#devobj~0.offset); {1913#true} is VALID [2018-11-23 12:45:32,768 INFO L273 TraceCheckUtils]: 18: Hoare triple {1913#true} ~Driver.base, ~Driver.offset := #in~Driver.base, #in~Driver.offset;~PDO.base, ~PDO.offset := #in~PDO.base, #in~PDO.offset;havoc ~devExt~0.base, ~devExt~0.offset;call ~#device~0.base, ~#device~0.offset := #Ultimate.alloc(4);havoc ~status~0;~status~0 := 0; {1913#true} is VALID [2018-11-23 12:45:32,768 INFO L256 TraceCheckUtils]: 19: Hoare triple {1913#true} call #t~ret19 := IoCreateDevice(~Driver.base, ~Driver.offset, 55, 0, 0, 11, 0, 0, ~#device~0.base, ~#device~0.offset); {1913#true} is VALID [2018-11-23 12:45:32,768 INFO L273 TraceCheckUtils]: 20: Hoare triple {1913#true} ~DriverObject.base, ~DriverObject.offset := #in~DriverObject.base, #in~DriverObject.offset;~DeviceExtensionSize := #in~DeviceExtensionSize;~DeviceName.base, ~DeviceName.offset := #in~DeviceName.base, #in~DeviceName.offset;~DeviceType := #in~DeviceType;~DeviceCharacteristics := #in~DeviceCharacteristics;~Exclusive := #in~Exclusive;~DeviceObject.base, ~DeviceObject.offset := #in~DeviceObject.base, #in~DeviceObject.offset;assume -2147483648 <= #t~nondet301 && #t~nondet301 <= 2147483647;~__BLAST_NONDET~5 := #t~nondet301;havoc #t~nondet301;havoc ~tmp~8.base, ~tmp~8.offset; {1913#true} is VALID [2018-11-23 12:45:32,769 INFO L273 TraceCheckUtils]: 21: Hoare triple {1913#true} assume 0 == ~__BLAST_NONDET~5; {1913#true} is VALID [2018-11-23 12:45:32,780 INFO L273 TraceCheckUtils]: 22: Hoare triple {1913#true} call #t~malloc302.base, #t~malloc302.offset := #Ultimate.alloc(175);~tmp~8.base, ~tmp~8.offset := #t~malloc302.base, #t~malloc302.offset;call write~$Pointer$(~tmp~8.base, ~tmp~8.offset, ~DeviceObject.base, ~DeviceObject.offset, 4);call #t~mem303.base, #t~mem303.offset := read~$Pointer$(~DeviceObject.base, ~DeviceObject.offset, 4);call #t~malloc304.base, #t~malloc304.offset := #Ultimate.alloc(~DeviceExtensionSize);call write~$Pointer$(#t~malloc304.base, #t~malloc304.offset, #t~mem303.base, 40 + #t~mem303.offset, 4);havoc #t~mem303.base, #t~mem303.offset;#res := 0; {1915#(= 0 |IoCreateDevice_#res|)} is VALID [2018-11-23 12:45:32,781 INFO L273 TraceCheckUtils]: 23: Hoare triple {1915#(= 0 |IoCreateDevice_#res|)} assume true; {1915#(= 0 |IoCreateDevice_#res|)} is VALID [2018-11-23 12:45:32,783 INFO L268 TraceCheckUtils]: 24: Hoare quadruple {1915#(= 0 |IoCreateDevice_#res|)} {1913#true} #865#return; {1916#(= 0 |KbFilter_AddDevice_#t~ret19|)} is VALID [2018-11-23 12:45:32,791 INFO L273 TraceCheckUtils]: 25: Hoare triple {1916#(= 0 |KbFilter_AddDevice_#t~ret19|)} assume -2147483648 <= #t~ret19 && #t~ret19 <= 2147483647;~status~0 := #t~ret19;havoc #t~ret19; {1917#(= KbFilter_AddDevice_~status~0 0)} is VALID [2018-11-23 12:45:32,792 INFO L273 TraceCheckUtils]: 26: Hoare triple {1917#(= KbFilter_AddDevice_~status~0 0)} assume !(~status~0 >= 0);#res := ~status~0;call ULTIMATE.dealloc(~#device~0.base, ~#device~0.offset);havoc ~#device~0.base, ~#device~0.offset; {1914#false} is VALID [2018-11-23 12:45:32,792 INFO L273 TraceCheckUtils]: 27: Hoare triple {1914#false} assume true; {1914#false} is VALID [2018-11-23 12:45:32,792 INFO L268 TraceCheckUtils]: 28: Hoare quadruple {1914#false} {1913#true} #823#return; {1914#false} is VALID [2018-11-23 12:45:32,792 INFO L273 TraceCheckUtils]: 29: Hoare triple {1914#false} assume -2147483648 <= #t~ret286 && #t~ret286 <= 2147483647;~status~5 := #t~ret286;havoc #t~ret286; {1914#false} is VALID [2018-11-23 12:45:32,793 INFO L256 TraceCheckUtils]: 30: Hoare triple {1914#false} call stub_driver_init(); {1913#true} is VALID [2018-11-23 12:45:32,793 INFO L273 TraceCheckUtils]: 31: Hoare triple {1913#true} ~s~0 := ~NP~0;~pended~0 := 0;~compFptr~0.base, ~compFptr~0.offset := 0, 0;~compRegistered~0 := 0;~lowerDriverReturn~0 := 0;~setEventCalled~0 := 0;~customIrp~0 := 0; {1913#true} is VALID [2018-11-23 12:45:32,793 INFO L273 TraceCheckUtils]: 32: Hoare triple {1913#true} assume true; {1913#true} is VALID [2018-11-23 12:45:32,793 INFO L268 TraceCheckUtils]: 33: Hoare quadruple {1913#true} {1914#false} #825#return; {1914#false} is VALID [2018-11-23 12:45:32,793 INFO L273 TraceCheckUtils]: 34: Hoare triple {1914#false} assume !!(~status~5 >= 0); {1914#false} is VALID [2018-11-23 12:45:32,794 INFO L273 TraceCheckUtils]: 35: Hoare triple {1914#false} assume 0 == ~__BLAST_NONDET~0; {1914#false} is VALID [2018-11-23 12:45:32,794 INFO L256 TraceCheckUtils]: 36: Hoare triple {1914#false} call #t~ret287 := KbFilter_CreateClose(~#devobj~0.base, ~#devobj~0.offset, ~pirp~0.base, ~pirp~0.offset); {1914#false} is VALID [2018-11-23 12:45:32,794 INFO L273 TraceCheckUtils]: 37: Hoare triple {1914#false} ~DeviceObject.base, ~DeviceObject.offset := #in~DeviceObject.base, #in~DeviceObject.offset;~Irp.base, ~Irp.offset := #in~Irp.base, #in~Irp.offset;havoc ~irpStack~0.base, ~irpStack~0.offset;havoc ~status~1;havoc ~devExt~1.base, ~devExt~1.offset;havoc ~tmp~0;havoc ~tmp___0~0;havoc ~tmp___1~0;call #t~mem33.base, #t~mem33.offset := read~$Pointer$(~Irp.base, 96 + ~Irp.offset, 4);~irpStack~0.base, ~irpStack~0.offset := #t~mem33.base, #t~mem33.offset;call write~int(#t~union34.Type, ~Irp.base, 64 + ~Irp.offset, 2);call write~int(#t~union34.Size, ~Irp.base, 66 + ~Irp.offset, 2);call write~int(#t~union34.Spare0, ~Irp.base, 68 + ~Irp.offset, 4);call write~$Pointer$(#t~union34.Thread.base, #t~union34.Thread.offset, ~Irp.base, 72 + ~Irp.offset, 4);call write~$Pointer$(#t~union34.ApcListEntry.Flink.base, #t~union34.ApcListEntry.Flink.offset, ~Irp.base, 76 + ~Irp.offset, 4);call write~$Pointer$(#t~union34.ApcListEntry.Blink.base, #t~union34.ApcListEntry.Blink.offset, ~Irp.base, 80 + ~Irp.offset, 4);call write~$Pointer$(#t~union34.KernelRoutine.base, #t~union34.KernelRoutine.offset, ~Irp.base, 84 + ~Irp.offset, 4);call write~$Pointer$(#t~union34.RundownRoutine.base, #t~union34.RundownRoutine.offset, ~Irp.base, 88 + ~Irp.offset, 4);call write~$Pointer$(#t~union34.NormalRoutine.base, #t~union34.NormalRoutine.offset, ~Irp.base, 92 + ~Irp.offset, 4);call write~$Pointer$(#t~union34.NormalContext.base, #t~union34.NormalContext.offset, ~Irp.base, 96 + ~Irp.offset, 4);call write~$Pointer$(#t~union34.SystemArgument1.base, #t~union34.SystemArgument1.offset, ~Irp.base, 100 + ~Irp.offset, 4);call write~$Pointer$(#t~union34.SystemArgument2.base, #t~union34.SystemArgument2.offset, ~Irp.base, 104 + ~Irp.offset, 4);call write~int(#t~union34.ApcStateIndex, ~Irp.base, 108 + ~Irp.offset, 1);call write~int(#t~union34.ApcMode, ~Irp.base, 109 + ~Irp.offset, 1);call write~int(#t~union34.Inserted, ~Irp.base, 110 + ~Irp.offset, 1);call write~$Pointer$(#t~union35.base, #t~union35.offset, ~Irp.base, 64 + ~Irp.offset, 4);call write~int(#t~union36.Type, ~Irp.base, 64 + ~Irp.offset, 2);call write~int(#t~union36.Size, ~Irp.base, 66 + ~Irp.offset, 2);call write~int(#t~union36.Spare0, ~Irp.base, 68 + ~Irp.offset, 4);call write~$Pointer$(#t~union36.Thread.base, #t~union36.Thread.offset, ~Irp.base, 72 + ~Irp.offset, 4);call write~$Pointer$(#t~union36.ApcListEntry.Flink.base, #t~union36.ApcListEntry.Flink.offset, ~Irp.base, 76 + ~Irp.offset, 4);call write~$Pointer$(#t~union36.ApcListEntry.Blink.base, #t~union36.ApcListEntry.Blink.offset, ~Irp.base, 80 + ~Irp.offset, 4);call write~$Pointer$(#t~union36.KernelRoutine.base, #t~union36.KernelRoutine.offset, ~Irp.base, 84 + ~Irp.offset, 4);call write~$Pointer$(#t~union36.RundownRoutine.base, #t~union36.RundownRoutine.offset, ~Irp.base, 88 + ~Irp.offset, 4);call write~$Pointer$(#t~union36.NormalRoutine.base, #t~union36.NormalRoutine.offset, ~Irp.base, 92 + ~Irp.offset, 4);call write~$Pointer$(#t~union36.NormalContext.base, #t~union36.NormalContext.offset, ~Irp.base, 96 + ~Irp.offset, 4);call write~$Pointer$(#t~union36.SystemArgument1.base, #t~union36.SystemArgument1.offset, ~Irp.base, 100 + ~Irp.offset, 4);call write~$Pointer$(#t~union36.SystemArgument2.base, #t~union36.SystemArgument2.offset, ~Irp.base, 104 + ~Irp.offset, 4);call write~int(#t~union36.ApcStateIndex, ~Irp.base, 108 + ~Irp.offset, 1);call write~int(#t~union36.ApcMode, ~Irp.base, 109 + ~Irp.offset, 1);call write~int(#t~union36.Inserted, ~Irp.base, 110 + ~Irp.offset, 1);call write~$Pointer$(#t~union37.base, #t~union37.offset, ~Irp.base, 64 + ~Irp.offset, 4);call write~int(#t~union38, ~Irp.base, 96 + ~Irp.offset, 4);havoc #t~union36.Type, #t~union36.Size, #t~union36.Spare0, #t~union36.Thread.base, #t~union36.Thread.offset, #t~union36.ApcListEntry.Flink.base, #t~union36.ApcListEntry.Flink.offset, #t~union36.ApcListEntry.Blink.base, #t~union36.ApcListEntry.Blink.offset, #t~union36.KernelRoutine.base, #t~union36.KernelRoutine.offset, #t~union36.RundownRoutine.base, #t~union36.RundownRoutine.offset, #t~union36.NormalRoutine.base, #t~union36.NormalRoutine.offset, #t~union36.NormalContext.base, #t~union36.NormalContext.offset, #t~union36.SystemArgument1.base, #t~union36.SystemArgument1.offset, #t~union36.SystemArgument2.base, #t~union36.SystemArgument2.offset, #t~union36.ApcStateIndex, #t~union36.ApcMode, #t~union36.Inserted;havoc #t~union37.base, #t~union37.offset;havoc #t~union38;havoc #t~union34.Type, #t~union34.Size, #t~union34.Spare0, #t~union34.Thread.base, #t~union34.Thread.offset, #t~union34.ApcListEntry.Flink.base, #t~union34.ApcListEntry.Flink.offset, #t~union34.ApcListEntry.Blink.base, #t~union34.ApcListEntry.Blink.offset, #t~union34.KernelRoutine.base, #t~union34.KernelRoutine.offset, #t~union34.RundownRoutine.base, #t~union34.RundownRoutine.offset, #t~union34.NormalRoutine.base, #t~union34.NormalRoutine.offset, #t~union34.NormalContext.base, #t~union34.NormalContext.offset, #t~union34.SystemArgument1.base, #t~union34.SystemArgument1.offset, #t~union34.SystemArgument2.base, #t~union34.SystemArgument2.offset, #t~union34.ApcStateIndex, #t~union34.ApcMode, #t~union34.Inserted;havoc #t~mem33.base, #t~mem33.offset;havoc #t~union35.base, #t~union35.offset;call #t~mem39.base, #t~mem39.offset := read~$Pointer$(~DeviceObject.base, 40 + ~DeviceObject.offset, 4);~devExt~1.base, ~devExt~1.offset := #t~mem39.base, #t~mem39.offset;havoc #t~mem39.base, #t~mem39.offset;call #t~mem40 := read~int(~Irp.base, 24 + ~Irp.offset, 4);~status~1 := #t~mem40;call write~$Pointer$(#t~union41.base, #t~union41.offset, ~Irp.base, 24 + ~Irp.offset, 4);havoc #t~mem40;havoc #t~union41.base, #t~union41.offset;~status~1 := ~myStatus~0;call #t~mem42 := read~int(~irpStack~0.base, ~irpStack~0.offset, 1); {1914#false} is VALID [2018-11-23 12:45:32,795 INFO L273 TraceCheckUtils]: 38: Hoare triple {1914#false} assume 0 == #t~mem42 % 256;havoc #t~mem42; {1914#false} is VALID [2018-11-23 12:45:32,795 INFO L273 TraceCheckUtils]: 39: Hoare triple {1914#false} call #t~mem44.base, #t~mem44.offset := read~$Pointer$(~devExt~1.base, 20 + ~devExt~1.offset, 4); {1914#false} is VALID [2018-11-23 12:45:32,795 INFO L273 TraceCheckUtils]: 40: Hoare triple {1914#false} assume 0 == (#t~mem44.base + #t~mem44.offset) % 4294967296;havoc #t~mem44.base, #t~mem44.offset;~status~1 := -1073741436; {1914#false} is VALID [2018-11-23 12:45:32,796 INFO L273 TraceCheckUtils]: 41: Hoare triple {1914#false} call write~int(~status~1, ~Irp.base, 24 + ~Irp.offset, 4);~myStatus~0 := ~status~1; {1914#false} is VALID [2018-11-23 12:45:32,796 INFO L256 TraceCheckUtils]: 42: Hoare triple {1914#false} call #t~ret47 := KbFilter_DispatchPassThrough(~DeviceObject.base, ~DeviceObject.offset, ~Irp.base, ~Irp.offset); {1914#false} is VALID [2018-11-23 12:45:32,796 INFO L273 TraceCheckUtils]: 43: Hoare triple {1914#false} ~DeviceObject.base, ~DeviceObject.offset := #in~DeviceObject.base, #in~DeviceObject.offset;~Irp.base, ~Irp.offset := #in~Irp.base, #in~Irp.offset;havoc ~irpStack~1.base, ~irpStack~1.offset;havoc ~tmp~1;call #t~mem48.base, #t~mem48.offset := read~$Pointer$(~Irp.base, 96 + ~Irp.offset, 4);~irpStack~1.base, ~irpStack~1.offset := #t~mem48.base, #t~mem48.offset;call write~int(#t~union49.Type, ~Irp.base, 64 + ~Irp.offset, 2);call write~int(#t~union49.Size, ~Irp.base, 66 + ~Irp.offset, 2);call write~int(#t~union49.Spare0, ~Irp.base, 68 + ~Irp.offset, 4);call write~$Pointer$(#t~union49.Thread.base, #t~union49.Thread.offset, ~Irp.base, 72 + ~Irp.offset, 4);call write~$Pointer$(#t~union49.ApcListEntry.Flink.base, #t~union49.ApcListEntry.Flink.offset, ~Irp.base, 76 + ~Irp.offset, 4);call write~$Pointer$(#t~union49.ApcListEntry.Blink.base, #t~union49.ApcListEntry.Blink.offset, ~Irp.base, 80 + ~Irp.offset, 4);call write~$Pointer$(#t~union49.KernelRoutine.base, #t~union49.KernelRoutine.offset, ~Irp.base, 84 + ~Irp.offset, 4);call write~$Pointer$(#t~union49.RundownRoutine.base, #t~union49.RundownRoutine.offset, ~Irp.base, 88 + ~Irp.offset, 4);call write~$Pointer$(#t~union49.NormalRoutine.base, #t~union49.NormalRoutine.offset, ~Irp.base, 92 + ~Irp.offset, 4);call write~$Pointer$(#t~union49.NormalContext.base, #t~union49.NormalContext.offset, ~Irp.base, 96 + ~Irp.offset, 4);call write~$Pointer$(#t~union49.SystemArgument1.base, #t~union49.SystemArgument1.offset, ~Irp.base, 100 + ~Irp.offset, 4);call write~$Pointer$(#t~union49.SystemArgument2.base, #t~union49.SystemArgument2.offset, ~Irp.base, 104 + ~Irp.offset, 4);call write~int(#t~union49.ApcStateIndex, ~Irp.base, 108 + ~Irp.offset, 1);call write~int(#t~union49.ApcMode, ~Irp.base, 109 + ~Irp.offset, 1);call write~int(#t~union49.Inserted, ~Irp.base, 110 + ~Irp.offset, 1);call write~$Pointer$(#t~union50.base, #t~union50.offset, ~Irp.base, 64 + ~Irp.offset, 4);call write~int(#t~union51.Type, ~Irp.base, 64 + ~Irp.offset, 2);call write~int(#t~union51.Size, ~Irp.base, 66 + ~Irp.offset, 2);call write~int(#t~union51.Spare0, ~Irp.base, 68 + ~Irp.offset, 4);call write~$Pointer$(#t~union51.Thread.base, #t~union51.Thread.offset, ~Irp.base, 72 + ~Irp.offset, 4);call write~$Pointer$(#t~union51.ApcListEntry.Flink.base, #t~union51.ApcListEntry.Flink.offset, ~Irp.base, 76 + ~Irp.offset, 4);call write~$Pointer$(#t~union51.ApcListEntry.Blink.base, #t~union51.ApcListEntry.Blink.offset, ~Irp.base, 80 + ~Irp.offset, 4);call write~$Pointer$(#t~union51.KernelRoutine.base, #t~union51.KernelRoutine.offset, ~Irp.base, 84 + ~Irp.offset, 4);call write~$Pointer$(#t~union51.RundownRoutine.base, #t~union51.RundownRoutine.offset, ~Irp.base, 88 + ~Irp.offset, 4);call write~$Pointer$(#t~union51.NormalRoutine.base, #t~union51.NormalRoutine.offset, ~Irp.base, 92 + ~Irp.offset, 4);call write~$Pointer$(#t~union51.NormalContext.base, #t~union51.NormalContext.offset, ~Irp.base, 96 + ~Irp.offset, 4);call write~$Pointer$(#t~union51.SystemArgument1.base, #t~union51.SystemArgument1.offset, ~Irp.base, 100 + ~Irp.offset, 4);call write~$Pointer$(#t~union51.SystemArgument2.base, #t~union51.SystemArgument2.offset, ~Irp.base, 104 + ~Irp.offset, 4);call write~int(#t~union51.ApcStateIndex, ~Irp.base, 108 + ~Irp.offset, 1);call write~int(#t~union51.ApcMode, ~Irp.base, 109 + ~Irp.offset, 1);call write~int(#t~union51.Inserted, ~Irp.base, 110 + ~Irp.offset, 1);call write~$Pointer$(#t~union52.base, #t~union52.offset, ~Irp.base, 64 + ~Irp.offset, 4);call write~int(#t~union53, ~Irp.base, 96 + ~Irp.offset, 4);havoc #t~union51.Type, #t~union51.Size, #t~union51.Spare0, #t~union51.Thread.base, #t~union51.Thread.offset, #t~union51.ApcListEntry.Flink.base, #t~union51.ApcListEntry.Flink.offset, #t~union51.ApcListEntry.Blink.base, #t~union51.ApcListEntry.Blink.offset, #t~union51.KernelRoutine.base, #t~union51.KernelRoutine.offset, #t~union51.RundownRoutine.base, #t~union51.RundownRoutine.offset, #t~union51.NormalRoutine.base, #t~union51.NormalRoutine.offset, #t~union51.NormalContext.base, #t~union51.NormalContext.offset, #t~union51.SystemArgument1.base, #t~union51.SystemArgument1.offset, #t~union51.SystemArgument2.base, #t~union51.SystemArgument2.offset, #t~union51.ApcStateIndex, #t~union51.ApcMode, #t~union51.Inserted;havoc #t~union50.base, #t~union50.offset;havoc #t~mem48.base, #t~mem48.offset;havoc #t~union53;havoc #t~union49.Type, #t~union49.Size, #t~union49.Spare0, #t~union49.Thread.base, #t~union49.Thread.offset, #t~union49.ApcListEntry.Flink.base, #t~union49.ApcListEntry.Flink.offset, #t~union49.ApcListEntry.Blink.base, #t~union49.ApcListEntry.Blink.offset, #t~union49.KernelRoutine.base, #t~union49.KernelRoutine.offset, #t~union49.RundownRoutine.base, #t~union49.RundownRoutine.offset, #t~union49.NormalRoutine.base, #t~union49.NormalRoutine.offset, #t~union49.NormalContext.base, #t~union49.NormalContext.offset, #t~union49.SystemArgument1.base, #t~union49.SystemArgument1.offset, #t~union49.SystemArgument2.base, #t~union49.SystemArgument2.offset, #t~union49.ApcStateIndex, #t~union49.ApcMode, #t~union49.Inserted;havoc #t~union52.base, #t~union52.offset; {1914#false} is VALID [2018-11-23 12:45:32,797 INFO L273 TraceCheckUtils]: 44: Hoare triple {1914#false} assume !(~s~0 == ~NP~0); {1914#false} is VALID [2018-11-23 12:45:32,797 INFO L256 TraceCheckUtils]: 45: Hoare triple {1914#false} call errorFn(); {1914#false} is VALID [2018-11-23 12:45:32,797 INFO L273 TraceCheckUtils]: 46: Hoare triple {1914#false} assume !false; {1914#false} is VALID [2018-11-23 12:45:32,800 INFO L134 CoverageAnalysis]: Checked inductivity of 0 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2018-11-23 12:45:32,800 INFO L312 seRefinementStrategy]: Constructing automaton from 1 perfect and 0 imperfect interpolant sequences. [2018-11-23 12:45:32,800 INFO L327 seRefinementStrategy]: Number of different interpolants: perfect sequences [5] imperfect sequences [] total 5 [2018-11-23 12:45:32,802 INFO L78 Accepts]: Start accepts. Automaton has 5 states. Word has length 47 [2018-11-23 12:45:32,802 INFO L84 Accepts]: Finished accepts. word is accepted. [2018-11-23 12:45:32,802 INFO L86 InductivityCheck]: Starting indutivity check of a Floyd-Hoare automaton with 5 states. [2018-11-23 12:45:32,888 INFO L119 InductivityCheck]: Floyd-Hoare automaton has 47 edges. 47 inductive. 0 not inductive. 0 times theorem prover too weak to decide inductivity. [2018-11-23 12:45:32,888 INFO L459 AbstractCegarLoop]: Interpolant automaton has 5 states [2018-11-23 12:45:32,888 INFO L142 InterpolantAutomaton]: Constructing interpolant automaton starting with 5 interpolants. [2018-11-23 12:45:32,889 INFO L144 InterpolantAutomaton]: CoverageRelationStatistics Valid=7, Invalid=13, Unknown=0, NotChecked=0, Total=20 [2018-11-23 12:45:32,889 INFO L87 Difference]: Start difference. First operand 292 states and 398 transitions. Second operand 5 states. [2018-11-23 12:46:54,863 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2018-11-23 12:46:54,863 INFO L93 Difference]: Finished difference Result 552 states and 762 transitions. [2018-11-23 12:46:54,863 INFO L142 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 5 states. [2018-11-23 12:46:54,863 INFO L78 Accepts]: Start accepts. Automaton has 5 states. Word has length 47 [2018-11-23 12:46:54,864 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2018-11-23 12:46:54,864 INFO L82 GeneralOperation]: Start removeUnreachable. Operand 5 states. [2018-11-23 12:46:54,876 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 5 states to 5 states and 762 transitions. [2018-11-23 12:46:54,883 INFO L82 GeneralOperation]: Start removeUnreachable. Operand 5 states. [2018-11-23 12:46:54,899 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 5 states to 5 states and 762 transitions. [2018-11-23 12:46:54,899 INFO L86 InductivityCheck]: Starting indutivity check of a Floyd-Hoare automaton with 5 states and 762 transitions. [2018-11-23 12:46:56,204 INFO L119 InductivityCheck]: Floyd-Hoare automaton has 762 edges. 762 inductive. 0 not inductive. 0 times theorem prover too weak to decide inductivity. [2018-11-23 12:46:56,217 INFO L225 Difference]: With dead ends: 552 [2018-11-23 12:46:56,218 INFO L226 Difference]: Without dead ends: 302 [2018-11-23 12:46:56,221 INFO L631 BasicCegarLoop]: 0 DeclaredPredicates, 6 GetRequests, 2 SyntacticMatches, 0 SemanticMatches, 4 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 0 ImplicationChecksByTransitivity, 0.3s TimeCoverageRelationStatistics Valid=11, Invalid=19, Unknown=0, NotChecked=0, Total=30 [2018-11-23 12:46:56,222 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 302 states. [2018-11-23 12:46:56,511 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 302 to 296. [2018-11-23 12:46:56,511 INFO L214 AbstractMinimizeNwa]: Start testing correctness of minimizeSevpa [2018-11-23 12:46:56,511 INFO L82 GeneralOperation]: Start isEquivalent. First operand 302 states. Second operand 296 states. [2018-11-23 12:46:56,512 INFO L74 IsIncluded]: Start isIncluded. First operand 302 states. Second operand 296 states. [2018-11-23 12:46:56,512 INFO L87 Difference]: Start difference. First operand 302 states. Second operand 296 states. [2018-11-23 12:46:56,528 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2018-11-23 12:46:56,528 INFO L93 Difference]: Finished difference Result 302 states and 410 transitions. [2018-11-23 12:46:56,528 INFO L276 IsEmpty]: Start isEmpty. Operand 302 states and 410 transitions. [2018-11-23 12:46:56,530 INFO L282 IsEmpty]: Finished isEmpty. No accepting run. [2018-11-23 12:46:56,531 INFO L83 IsIncluded]: Finished isIncluded. Language is included [2018-11-23 12:46:56,531 INFO L74 IsIncluded]: Start isIncluded. First operand 296 states. Second operand 302 states. [2018-11-23 12:46:56,531 INFO L87 Difference]: Start difference. First operand 296 states. Second operand 302 states. [2018-11-23 12:46:56,552 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2018-11-23 12:46:56,552 INFO L93 Difference]: Finished difference Result 302 states and 410 transitions. [2018-11-23 12:46:56,552 INFO L276 IsEmpty]: Start isEmpty. Operand 302 states and 410 transitions. [2018-11-23 12:46:56,554 INFO L282 IsEmpty]: Finished isEmpty. No accepting run. [2018-11-23 12:46:56,554 INFO L83 IsIncluded]: Finished isIncluded. Language is included [2018-11-23 12:46:56,554 INFO L88 GeneralOperation]: Finished isEquivalent. [2018-11-23 12:46:56,554 INFO L221 AbstractMinimizeNwa]: Finished testing correctness of minimizeSevpa [2018-11-23 12:46:56,555 INFO L82 GeneralOperation]: Start removeUnreachable. Operand 296 states. [2018-11-23 12:46:56,571 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 296 states to 296 states and 402 transitions. [2018-11-23 12:46:56,571 INFO L78 Accepts]: Start accepts. Automaton has 296 states and 402 transitions. Word has length 47 [2018-11-23 12:46:56,572 INFO L84 Accepts]: Finished accepts. word is rejected. [2018-11-23 12:46:56,572 INFO L480 AbstractCegarLoop]: Abstraction has 296 states and 402 transitions. [2018-11-23 12:46:56,572 INFO L481 AbstractCegarLoop]: Interpolant automaton has 5 states. [2018-11-23 12:46:56,572 INFO L276 IsEmpty]: Start isEmpty. Operand 296 states and 402 transitions. [2018-11-23 12:46:56,574 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 48 [2018-11-23 12:46:56,574 INFO L394 BasicCegarLoop]: Found error trace [2018-11-23 12:46:56,574 INFO L402 BasicCegarLoop]: trace histogram [1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2018-11-23 12:46:56,575 INFO L423 AbstractCegarLoop]: === Iteration 3 === [errorFnErr0ASSERT_VIOLATIONERROR_FUNCTION]=== [2018-11-23 12:46:56,575 INFO L141 PredicateUnifier]: Initialized classic predicate unifier [2018-11-23 12:46:56,575 INFO L82 PathProgramCache]: Analyzing trace with hash -631810728, now seen corresponding path program 1 times [2018-11-23 12:46:56,575 INFO L223 ckRefinementStrategy]: Switched to mode SMTINTERPOL_TREE_INTERPOLANTS [2018-11-23 12:46:56,575 INFO L69 tionRefinementEngine]: Using refinement strategy CamelRefinementStrategy [2018-11-23 12:46:56,585 INFO L119 rtionOrderModulation]: Craig_TreeInterpolation forces the order to NOT_INCREMENTALLY [2018-11-23 12:46:56,585 INFO L103 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2018-11-23 12:46:56,586 INFO L119 rtionOrderModulation]: Craig_TreeInterpolation forces the order to NOT_INCREMENTALLY [2018-11-23 12:46:56,669 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2018-11-23 12:46:57,171 INFO L256 TraceCheckUtils]: 0: Hoare triple {3679#true} call ULTIMATE.init(); {3679#true} is VALID [2018-11-23 12:46:57,172 INFO L273 TraceCheckUtils]: 1: Hoare triple {3679#true} #NULL.base, #NULL.offset := 0, 0;#valid := #valid[0 := 0];~s~0 := 0;~UNLOADED~0 := 0;~NP~0 := 0;~DC~0 := 0;~SKIP1~0 := 0;~SKIP2~0 := 0;~MPR1~0 := 0;~MPR3~0 := 0;~IPC~0 := 0;~pended~0 := 0;~compRegistered~0 := 0;~lowerDriverReturn~0 := 0;~setEventCalled~0 := 0;~customIrp~0 := 0;~myStatus~0 := 0;~_SLAM_alloc_dummy~0 := 0;~compFptr~0.base, ~compFptr~0.offset := 0, 0;~pirp~0.base, ~pirp~0.offset := 0, 0; {3679#true} is VALID [2018-11-23 12:46:57,172 INFO L273 TraceCheckUtils]: 2: Hoare triple {3679#true} assume true; {3679#true} is VALID [2018-11-23 12:46:57,172 INFO L268 TraceCheckUtils]: 3: Hoare quadruple {3679#true} {3679#true} #905#return; {3679#true} is VALID [2018-11-23 12:46:57,172 INFO L256 TraceCheckUtils]: 4: Hoare triple {3679#true} call #t~ret331 := main(); {3679#true} is VALID [2018-11-23 12:46:57,173 INFO L273 TraceCheckUtils]: 5: Hoare triple {3679#true} call ~#d~0.base, ~#d~0.offset := #Ultimate.alloc(168);call ~#u~0.base, ~#u~0.offset := #Ultimate.alloc(8);havoc ~status~5;assume -2147483648 <= #t~nondet270 && #t~nondet270 <= 2147483647;~we_should_unload~0 := #t~nondet270;havoc #t~nondet270;call ~#irp~0.base, ~#irp~0.offset := #Ultimate.alloc(111);assume -2147483648 <= #t~nondet271 && #t~nondet271 <= 2147483647;~__BLAST_NONDET~0 := #t~nondet271;havoc #t~nondet271;assume -2147483648 <= #t~nondet272 && #t~nondet272 <= 2147483647;~irp_choice~0 := #t~nondet272;havoc #t~nondet272;call ~#devext~0.base, ~#devext~0.offset := #Ultimate.alloc(55);call ~#devobj~0.base, ~#devobj~0.offset := #Ultimate.alloc(175);call write~$Pointer$(~#devext~0.base, ~#devext~0.offset, ~#devobj~0.base, 40 + ~#devobj~0.offset, 4);call ~#ext~0.base, ~#ext~0.offset := #Ultimate.alloc(20);call write~$Pointer$(~#ext~0.base, ~#ext~0.offset, ~#d~0.base, 24 + ~#d~0.offset, 4);call ~#hookkb~0.base, ~#hookkb~0.offset := #Ultimate.alloc(24);call ~#stack~0.base, ~#stack~0.offset := #Ultimate.alloc(108);call write~int(#t~nondet273, ~#stack~0.base, ~#stack~0.offset, 1);havoc #t~nondet273;call write~int(#t~nondet274, ~#stack~0.base, 36 + ~#stack~0.offset, 1);havoc #t~nondet274;call write~int(#t~nondet275, ~#stack~0.base, 72 + ~#stack~0.offset, 1);havoc #t~nondet275;call write~int(#t~nondet276, ~#stack~0.base, 1 + ~#stack~0.offset, 1);havoc #t~nondet276;call write~int(#t~nondet277, ~#stack~0.base, 37 + ~#stack~0.offset, 1);havoc #t~nondet277;call write~int(#t~nondet278, ~#stack~0.base, 73 + ~#stack~0.offset, 1);havoc #t~nondet278;call write~$Pointer$(~#hookkb~0.base, ~#hookkb~0.offset, ~#stack~0.base, 16 + ~#stack~0.offset, 4);call write~$Pointer$(~#hookkb~0.base, ~#hookkb~0.offset, ~#stack~0.base, 52 + ~#stack~0.offset, 4);call write~$Pointer$(~#hookkb~0.base, ~#hookkb~0.offset, ~#stack~0.base, 88 + ~#stack~0.offset, 4);call write~int(#t~nondet279, ~#stack~0.base, 8 + ~#stack~0.offset, 4);havoc #t~nondet279;call write~int(#t~nondet280, ~#stack~0.base, 44 + ~#stack~0.offset, 4);havoc #t~nondet280;call write~int(#t~nondet281, ~#stack~0.base, 80 + ~#stack~0.offset, 4);havoc #t~nondet281;call write~int(#t~nondet282, ~#stack~0.base, 12 + ~#stack~0.offset, 4);havoc #t~nondet282;call write~int(#t~nondet283, ~#stack~0.base, 48 + ~#stack~0.offset, 4);havoc #t~nondet283;call write~int(#t~nondet284, ~#stack~0.base, 84 + ~#stack~0.offset, 4);havoc #t~nondet284;call write~$Pointer$(~#stack~0.base, 36 + ~#stack~0.offset, ~#irp~0.base, 96 + ~#irp~0.offset, 4);~pirp~0.base, ~pirp~0.offset := ~#irp~0.base, ~#irp~0.offset; {3679#true} is VALID [2018-11-23 12:46:57,173 INFO L256 TraceCheckUtils]: 6: Hoare triple {3679#true} call _BLAST_init(); {3679#true} is VALID [2018-11-23 12:46:57,174 INFO L273 TraceCheckUtils]: 7: Hoare triple {3679#true} ~UNLOADED~0 := 0;~NP~0 := 1;~DC~0 := 2;~SKIP1~0 := 3;~SKIP2~0 := 4;~MPR1~0 := 5;~MPR3~0 := 6;~IPC~0 := 7;~s~0 := ~UNLOADED~0;~pended~0 := 0;~compFptr~0.base, ~compFptr~0.offset := 0, 0;~compRegistered~0 := 0;~lowerDriverReturn~0 := 0;~setEventCalled~0 := 0;~customIrp~0 := 0; {3679#true} is VALID [2018-11-23 12:46:57,174 INFO L273 TraceCheckUtils]: 8: Hoare triple {3679#true} assume true; {3679#true} is VALID [2018-11-23 12:46:57,174 INFO L268 TraceCheckUtils]: 9: Hoare quadruple {3679#true} {3679#true} #819#return; {3679#true} is VALID [2018-11-23 12:46:57,174 INFO L256 TraceCheckUtils]: 10: Hoare triple {3679#true} call #t~ret285 := DriverEntry(~#d~0.base, ~#d~0.offset, ~#u~0.base, ~#u~0.offset); {3679#true} is VALID [2018-11-23 12:46:57,175 INFO L273 TraceCheckUtils]: 11: Hoare triple {3679#true} ~DriverObject.base, ~DriverObject.offset := #in~DriverObject.base, #in~DriverObject.offset;~RegistryPath.base, ~RegistryPath.offset := #in~RegistryPath.base, #in~RegistryPath.offset;assume -2147483648 <= #t~nondet17 && #t~nondet17 <= 2147483647;~i~0 := #t~nondet17;havoc #t~nondet17;assume 0 != (if ~i~0 % 4294967296 < 28 then 1 else 0);call write~$Pointer$(#funAddr~KbFilter_DispatchPassThrough.base, #funAddr~KbFilter_DispatchPassThrough.offset, ~DriverObject.base, 56 + ~DriverObject.offset + 4 * (if ~i~0 % 4294967296 % 4294967296 <= 2147483647 then ~i~0 % 4294967296 % 4294967296 else ~i~0 % 4294967296 % 4294967296 - 4294967296), 4);call write~$Pointer$(#funAddr~KbFilter_CreateClose.base, #funAddr~KbFilter_CreateClose.offset, ~DriverObject.base, 56 + ~DriverObject.offset, 4);call write~$Pointer$(#funAddr~KbFilter_CreateClose.base, #funAddr~KbFilter_CreateClose.offset, ~DriverObject.base, 64 + ~DriverObject.offset, 4);call write~$Pointer$(#funAddr~KbFilter_PnP.base, #funAddr~KbFilter_PnP.offset, ~DriverObject.base, 164 + ~DriverObject.offset, 4);call write~$Pointer$(#funAddr~KbFilter_Power.base, #funAddr~KbFilter_Power.offset, ~DriverObject.base, 144 + ~DriverObject.offset, 4);call write~$Pointer$(#funAddr~KbFilter_InternIoCtl.base, #funAddr~KbFilter_InternIoCtl.offset, ~DriverObject.base, 116 + ~DriverObject.offset, 4);call write~$Pointer$(#funAddr~KbFilter_Unload.base, #funAddr~KbFilter_Unload.offset, ~DriverObject.base, 52 + ~DriverObject.offset, 4);call #t~mem18.base, #t~mem18.offset := read~$Pointer$(~DriverObject.base, 24 + ~DriverObject.offset, 4);call write~$Pointer$(#funAddr~KbFilter_AddDevice.base, #funAddr~KbFilter_AddDevice.offset, #t~mem18.base, 4 + #t~mem18.offset, 4);havoc #t~mem18.base, #t~mem18.offset;#res := 0; {3679#true} is VALID [2018-11-23 12:46:57,175 INFO L273 TraceCheckUtils]: 12: Hoare triple {3679#true} assume true; {3679#true} is VALID [2018-11-23 12:46:57,175 INFO L268 TraceCheckUtils]: 13: Hoare quadruple {3679#true} {3679#true} #821#return; {3679#true} is VALID [2018-11-23 12:46:57,176 INFO L273 TraceCheckUtils]: 14: Hoare triple {3679#true} assume -2147483648 <= #t~ret285 && #t~ret285 <= 2147483647;~status~5 := #t~ret285;havoc #t~ret285; {3679#true} is VALID [2018-11-23 12:46:57,176 INFO L273 TraceCheckUtils]: 15: Hoare triple {3679#true} assume ~status~5 >= 0;~s~0 := ~NP~0;~customIrp~0 := 0;~setEventCalled~0 := ~customIrp~0;~lowerDriverReturn~0 := ~setEventCalled~0;~compRegistered~0 := ~lowerDriverReturn~0;~compFptr~0.base, ~compFptr~0.offset := 0, ~compRegistered~0;~pended~0 := ~compFptr~0.base + ~compFptr~0.offset;call write~int(0, ~pirp~0.base, 24 + ~pirp~0.offset, 4);~myStatus~0 := 0; {3679#true} is VALID [2018-11-23 12:46:57,176 INFO L273 TraceCheckUtils]: 16: Hoare triple {3679#true} assume 0 == ~irp_choice~0;call write~int(-1073741637, ~pirp~0.base, 24 + ~pirp~0.offset, 4);~myStatus~0 := -1073741637; {3679#true} is VALID [2018-11-23 12:46:57,176 INFO L256 TraceCheckUtils]: 17: Hoare triple {3679#true} call #t~ret286 := KbFilter_AddDevice(~#d~0.base, ~#d~0.offset, ~#devobj~0.base, ~#devobj~0.offset); {3679#true} is VALID [2018-11-23 12:46:57,177 INFO L273 TraceCheckUtils]: 18: Hoare triple {3679#true} ~Driver.base, ~Driver.offset := #in~Driver.base, #in~Driver.offset;~PDO.base, ~PDO.offset := #in~PDO.base, #in~PDO.offset;havoc ~devExt~0.base, ~devExt~0.offset;call ~#device~0.base, ~#device~0.offset := #Ultimate.alloc(4);havoc ~status~0;~status~0 := 0; {3679#true} is VALID [2018-11-23 12:46:57,177 INFO L256 TraceCheckUtils]: 19: Hoare triple {3679#true} call #t~ret19 := IoCreateDevice(~Driver.base, ~Driver.offset, 55, 0, 0, 11, 0, 0, ~#device~0.base, ~#device~0.offset); {3679#true} is VALID [2018-11-23 12:46:57,177 INFO L273 TraceCheckUtils]: 20: Hoare triple {3679#true} ~DriverObject.base, ~DriverObject.offset := #in~DriverObject.base, #in~DriverObject.offset;~DeviceExtensionSize := #in~DeviceExtensionSize;~DeviceName.base, ~DeviceName.offset := #in~DeviceName.base, #in~DeviceName.offset;~DeviceType := #in~DeviceType;~DeviceCharacteristics := #in~DeviceCharacteristics;~Exclusive := #in~Exclusive;~DeviceObject.base, ~DeviceObject.offset := #in~DeviceObject.base, #in~DeviceObject.offset;assume -2147483648 <= #t~nondet301 && #t~nondet301 <= 2147483647;~__BLAST_NONDET~5 := #t~nondet301;havoc #t~nondet301;havoc ~tmp~8.base, ~tmp~8.offset; {3679#true} is VALID [2018-11-23 12:46:57,177 INFO L273 TraceCheckUtils]: 21: Hoare triple {3679#true} assume !(0 == ~__BLAST_NONDET~5); {3679#true} is VALID [2018-11-23 12:46:57,178 INFO L273 TraceCheckUtils]: 22: Hoare triple {3679#true} #res := -1073741823; {3679#true} is VALID [2018-11-23 12:46:57,178 INFO L273 TraceCheckUtils]: 23: Hoare triple {3679#true} assume true; {3679#true} is VALID [2018-11-23 12:46:57,178 INFO L268 TraceCheckUtils]: 24: Hoare quadruple {3679#true} {3679#true} #865#return; {3679#true} is VALID [2018-11-23 12:46:57,179 INFO L273 TraceCheckUtils]: 25: Hoare triple {3679#true} assume -2147483648 <= #t~ret19 && #t~ret19 <= 2147483647;~status~0 := #t~ret19;havoc #t~ret19; {3679#true} is VALID [2018-11-23 12:46:57,179 INFO L273 TraceCheckUtils]: 26: Hoare triple {3679#true} assume !(~status~0 >= 0);#res := ~status~0;call ULTIMATE.dealloc(~#device~0.base, ~#device~0.offset);havoc ~#device~0.base, ~#device~0.offset; {3679#true} is VALID [2018-11-23 12:46:57,179 INFO L273 TraceCheckUtils]: 27: Hoare triple {3679#true} assume true; {3679#true} is VALID [2018-11-23 12:46:57,180 INFO L268 TraceCheckUtils]: 28: Hoare quadruple {3679#true} {3679#true} #823#return; {3679#true} is VALID [2018-11-23 12:46:57,180 INFO L273 TraceCheckUtils]: 29: Hoare triple {3679#true} assume -2147483648 <= #t~ret286 && #t~ret286 <= 2147483647;~status~5 := #t~ret286;havoc #t~ret286; {3679#true} is VALID [2018-11-23 12:46:57,180 INFO L256 TraceCheckUtils]: 30: Hoare triple {3679#true} call stub_driver_init(); {3679#true} is VALID [2018-11-23 12:46:57,193 INFO L273 TraceCheckUtils]: 31: Hoare triple {3679#true} ~s~0 := ~NP~0;~pended~0 := 0;~compFptr~0.base, ~compFptr~0.offset := 0, 0;~compRegistered~0 := 0;~lowerDriverReturn~0 := 0;~setEventCalled~0 := 0;~customIrp~0 := 0; {3681#(= ~NP~0 ~s~0)} is VALID [2018-11-23 12:46:57,206 INFO L273 TraceCheckUtils]: 32: Hoare triple {3681#(= ~NP~0 ~s~0)} assume true; {3681#(= ~NP~0 ~s~0)} is VALID [2018-11-23 12:46:57,219 INFO L268 TraceCheckUtils]: 33: Hoare quadruple {3681#(= ~NP~0 ~s~0)} {3679#true} #825#return; {3681#(= ~NP~0 ~s~0)} is VALID [2018-11-23 12:46:57,232 INFO L273 TraceCheckUtils]: 34: Hoare triple {3681#(= ~NP~0 ~s~0)} assume !!(~status~5 >= 0); {3681#(= ~NP~0 ~s~0)} is VALID [2018-11-23 12:46:57,250 INFO L273 TraceCheckUtils]: 35: Hoare triple {3681#(= ~NP~0 ~s~0)} assume 0 == ~__BLAST_NONDET~0; {3681#(= ~NP~0 ~s~0)} is VALID [2018-11-23 12:46:57,260 INFO L256 TraceCheckUtils]: 36: Hoare triple {3681#(= ~NP~0 ~s~0)} call #t~ret287 := KbFilter_CreateClose(~#devobj~0.base, ~#devobj~0.offset, ~pirp~0.base, ~pirp~0.offset); {3681#(= ~NP~0 ~s~0)} is VALID [2018-11-23 12:46:57,270 INFO L273 TraceCheckUtils]: 37: Hoare triple {3681#(= ~NP~0 ~s~0)} ~DeviceObject.base, ~DeviceObject.offset := #in~DeviceObject.base, #in~DeviceObject.offset;~Irp.base, ~Irp.offset := #in~Irp.base, #in~Irp.offset;havoc ~irpStack~0.base, ~irpStack~0.offset;havoc ~status~1;havoc ~devExt~1.base, ~devExt~1.offset;havoc ~tmp~0;havoc ~tmp___0~0;havoc ~tmp___1~0;call #t~mem33.base, #t~mem33.offset := read~$Pointer$(~Irp.base, 96 + ~Irp.offset, 4);~irpStack~0.base, ~irpStack~0.offset := #t~mem33.base, #t~mem33.offset;call write~int(#t~union34.Type, ~Irp.base, 64 + ~Irp.offset, 2);call write~int(#t~union34.Size, ~Irp.base, 66 + ~Irp.offset, 2);call write~int(#t~union34.Spare0, ~Irp.base, 68 + ~Irp.offset, 4);call write~$Pointer$(#t~union34.Thread.base, #t~union34.Thread.offset, ~Irp.base, 72 + ~Irp.offset, 4);call write~$Pointer$(#t~union34.ApcListEntry.Flink.base, #t~union34.ApcListEntry.Flink.offset, ~Irp.base, 76 + ~Irp.offset, 4);call write~$Pointer$(#t~union34.ApcListEntry.Blink.base, #t~union34.ApcListEntry.Blink.offset, ~Irp.base, 80 + ~Irp.offset, 4);call write~$Pointer$(#t~union34.KernelRoutine.base, #t~union34.KernelRoutine.offset, ~Irp.base, 84 + ~Irp.offset, 4);call write~$Pointer$(#t~union34.RundownRoutine.base, #t~union34.RundownRoutine.offset, ~Irp.base, 88 + ~Irp.offset, 4);call write~$Pointer$(#t~union34.NormalRoutine.base, #t~union34.NormalRoutine.offset, ~Irp.base, 92 + ~Irp.offset, 4);call write~$Pointer$(#t~union34.NormalContext.base, #t~union34.NormalContext.offset, ~Irp.base, 96 + ~Irp.offset, 4);call write~$Pointer$(#t~union34.SystemArgument1.base, #t~union34.SystemArgument1.offset, ~Irp.base, 100 + ~Irp.offset, 4);call write~$Pointer$(#t~union34.SystemArgument2.base, #t~union34.SystemArgument2.offset, ~Irp.base, 104 + ~Irp.offset, 4);call write~int(#t~union34.ApcStateIndex, ~Irp.base, 108 + ~Irp.offset, 1);call write~int(#t~union34.ApcMode, ~Irp.base, 109 + ~Irp.offset, 1);call write~int(#t~union34.Inserted, ~Irp.base, 110 + ~Irp.offset, 1);call write~$Pointer$(#t~union35.base, #t~union35.offset, ~Irp.base, 64 + ~Irp.offset, 4);call write~int(#t~union36.Type, ~Irp.base, 64 + ~Irp.offset, 2);call write~int(#t~union36.Size, ~Irp.base, 66 + ~Irp.offset, 2);call write~int(#t~union36.Spare0, ~Irp.base, 68 + ~Irp.offset, 4);call write~$Pointer$(#t~union36.Thread.base, #t~union36.Thread.offset, ~Irp.base, 72 + ~Irp.offset, 4);call write~$Pointer$(#t~union36.ApcListEntry.Flink.base, #t~union36.ApcListEntry.Flink.offset, ~Irp.base, 76 + ~Irp.offset, 4);call write~$Pointer$(#t~union36.ApcListEntry.Blink.base, #t~union36.ApcListEntry.Blink.offset, ~Irp.base, 80 + ~Irp.offset, 4);call write~$Pointer$(#t~union36.KernelRoutine.base, #t~union36.KernelRoutine.offset, ~Irp.base, 84 + ~Irp.offset, 4);call write~$Pointer$(#t~union36.RundownRoutine.base, #t~union36.RundownRoutine.offset, ~Irp.base, 88 + ~Irp.offset, 4);call write~$Pointer$(#t~union36.NormalRoutine.base, #t~union36.NormalRoutine.offset, ~Irp.base, 92 + ~Irp.offset, 4);call write~$Pointer$(#t~union36.NormalContext.base, #t~union36.NormalContext.offset, ~Irp.base, 96 + ~Irp.offset, 4);call write~$Pointer$(#t~union36.SystemArgument1.base, #t~union36.SystemArgument1.offset, ~Irp.base, 100 + ~Irp.offset, 4);call write~$Pointer$(#t~union36.SystemArgument2.base, #t~union36.SystemArgument2.offset, ~Irp.base, 104 + ~Irp.offset, 4);call write~int(#t~union36.ApcStateIndex, ~Irp.base, 108 + ~Irp.offset, 1);call write~int(#t~union36.ApcMode, ~Irp.base, 109 + ~Irp.offset, 1);call write~int(#t~union36.Inserted, ~Irp.base, 110 + ~Irp.offset, 1);call write~$Pointer$(#t~union37.base, #t~union37.offset, ~Irp.base, 64 + ~Irp.offset, 4);call write~int(#t~union38, ~Irp.base, 96 + ~Irp.offset, 4);havoc #t~union36.Type, #t~union36.Size, #t~union36.Spare0, #t~union36.Thread.base, #t~union36.Thread.offset, #t~union36.ApcListEntry.Flink.base, #t~union36.ApcListEntry.Flink.offset, #t~union36.ApcListEntry.Blink.base, #t~union36.ApcListEntry.Blink.offset, #t~union36.KernelRoutine.base, #t~union36.KernelRoutine.offset, #t~union36.RundownRoutine.base, #t~union36.RundownRoutine.offset, #t~union36.NormalRoutine.base, #t~union36.NormalRoutine.offset, #t~union36.NormalContext.base, #t~union36.NormalContext.offset, #t~union36.SystemArgument1.base, #t~union36.SystemArgument1.offset, #t~union36.SystemArgument2.base, #t~union36.SystemArgument2.offset, #t~union36.ApcStateIndex, #t~union36.ApcMode, #t~union36.Inserted;havoc #t~union37.base, #t~union37.offset;havoc #t~union38;havoc #t~union34.Type, #t~union34.Size, #t~union34.Spare0, #t~union34.Thread.base, #t~union34.Thread.offset, #t~union34.ApcListEntry.Flink.base, #t~union34.ApcListEntry.Flink.offset, #t~union34.ApcListEntry.Blink.base, #t~union34.ApcListEntry.Blink.offset, #t~union34.KernelRoutine.base, #t~union34.KernelRoutine.offset, #t~union34.RundownRoutine.base, #t~union34.RundownRoutine.offset, #t~union34.NormalRoutine.base, #t~union34.NormalRoutine.offset, #t~union34.NormalContext.base, #t~union34.NormalContext.offset, #t~union34.SystemArgument1.base, #t~union34.SystemArgument1.offset, #t~union34.SystemArgument2.base, #t~union34.SystemArgument2.offset, #t~union34.ApcStateIndex, #t~union34.ApcMode, #t~union34.Inserted;havoc #t~mem33.base, #t~mem33.offset;havoc #t~union35.base, #t~union35.offset;call #t~mem39.base, #t~mem39.offset := read~$Pointer$(~DeviceObject.base, 40 + ~DeviceObject.offset, 4);~devExt~1.base, ~devExt~1.offset := #t~mem39.base, #t~mem39.offset;havoc #t~mem39.base, #t~mem39.offset;call #t~mem40 := read~int(~Irp.base, 24 + ~Irp.offset, 4);~status~1 := #t~mem40;call write~$Pointer$(#t~union41.base, #t~union41.offset, ~Irp.base, 24 + ~Irp.offset, 4);havoc #t~mem40;havoc #t~union41.base, #t~union41.offset;~status~1 := ~myStatus~0;call #t~mem42 := read~int(~irpStack~0.base, ~irpStack~0.offset, 1); {3681#(= ~NP~0 ~s~0)} is VALID [2018-11-23 12:46:57,279 INFO L273 TraceCheckUtils]: 38: Hoare triple {3681#(= ~NP~0 ~s~0)} assume 0 == #t~mem42 % 256;havoc #t~mem42; {3681#(= ~NP~0 ~s~0)} is VALID [2018-11-23 12:46:57,292 INFO L273 TraceCheckUtils]: 39: Hoare triple {3681#(= ~NP~0 ~s~0)} call #t~mem44.base, #t~mem44.offset := read~$Pointer$(~devExt~1.base, 20 + ~devExt~1.offset, 4); {3681#(= ~NP~0 ~s~0)} is VALID [2018-11-23 12:46:57,310 INFO L273 TraceCheckUtils]: 40: Hoare triple {3681#(= ~NP~0 ~s~0)} assume 0 == (#t~mem44.base + #t~mem44.offset) % 4294967296;havoc #t~mem44.base, #t~mem44.offset;~status~1 := -1073741436; {3681#(= ~NP~0 ~s~0)} is VALID [2018-11-23 12:46:57,319 INFO L273 TraceCheckUtils]: 41: Hoare triple {3681#(= ~NP~0 ~s~0)} call write~int(~status~1, ~Irp.base, 24 + ~Irp.offset, 4);~myStatus~0 := ~status~1; {3681#(= ~NP~0 ~s~0)} is VALID [2018-11-23 12:46:57,332 INFO L256 TraceCheckUtils]: 42: Hoare triple {3681#(= ~NP~0 ~s~0)} call #t~ret47 := KbFilter_DispatchPassThrough(~DeviceObject.base, ~DeviceObject.offset, ~Irp.base, ~Irp.offset); {3681#(= ~NP~0 ~s~0)} is VALID [2018-11-23 12:46:57,345 INFO L273 TraceCheckUtils]: 43: Hoare triple {3681#(= ~NP~0 ~s~0)} ~DeviceObject.base, ~DeviceObject.offset := #in~DeviceObject.base, #in~DeviceObject.offset;~Irp.base, ~Irp.offset := #in~Irp.base, #in~Irp.offset;havoc ~irpStack~1.base, ~irpStack~1.offset;havoc ~tmp~1;call #t~mem48.base, #t~mem48.offset := read~$Pointer$(~Irp.base, 96 + ~Irp.offset, 4);~irpStack~1.base, ~irpStack~1.offset := #t~mem48.base, #t~mem48.offset;call write~int(#t~union49.Type, ~Irp.base, 64 + ~Irp.offset, 2);call write~int(#t~union49.Size, ~Irp.base, 66 + ~Irp.offset, 2);call write~int(#t~union49.Spare0, ~Irp.base, 68 + ~Irp.offset, 4);call write~$Pointer$(#t~union49.Thread.base, #t~union49.Thread.offset, ~Irp.base, 72 + ~Irp.offset, 4);call write~$Pointer$(#t~union49.ApcListEntry.Flink.base, #t~union49.ApcListEntry.Flink.offset, ~Irp.base, 76 + ~Irp.offset, 4);call write~$Pointer$(#t~union49.ApcListEntry.Blink.base, #t~union49.ApcListEntry.Blink.offset, ~Irp.base, 80 + ~Irp.offset, 4);call write~$Pointer$(#t~union49.KernelRoutine.base, #t~union49.KernelRoutine.offset, ~Irp.base, 84 + ~Irp.offset, 4);call write~$Pointer$(#t~union49.RundownRoutine.base, #t~union49.RundownRoutine.offset, ~Irp.base, 88 + ~Irp.offset, 4);call write~$Pointer$(#t~union49.NormalRoutine.base, #t~union49.NormalRoutine.offset, ~Irp.base, 92 + ~Irp.offset, 4);call write~$Pointer$(#t~union49.NormalContext.base, #t~union49.NormalContext.offset, ~Irp.base, 96 + ~Irp.offset, 4);call write~$Pointer$(#t~union49.SystemArgument1.base, #t~union49.SystemArgument1.offset, ~Irp.base, 100 + ~Irp.offset, 4);call write~$Pointer$(#t~union49.SystemArgument2.base, #t~union49.SystemArgument2.offset, ~Irp.base, 104 + ~Irp.offset, 4);call write~int(#t~union49.ApcStateIndex, ~Irp.base, 108 + ~Irp.offset, 1);call write~int(#t~union49.ApcMode, ~Irp.base, 109 + ~Irp.offset, 1);call write~int(#t~union49.Inserted, ~Irp.base, 110 + ~Irp.offset, 1);call write~$Pointer$(#t~union50.base, #t~union50.offset, ~Irp.base, 64 + ~Irp.offset, 4);call write~int(#t~union51.Type, ~Irp.base, 64 + ~Irp.offset, 2);call write~int(#t~union51.Size, ~Irp.base, 66 + ~Irp.offset, 2);call write~int(#t~union51.Spare0, ~Irp.base, 68 + ~Irp.offset, 4);call write~$Pointer$(#t~union51.Thread.base, #t~union51.Thread.offset, ~Irp.base, 72 + ~Irp.offset, 4);call write~$Pointer$(#t~union51.ApcListEntry.Flink.base, #t~union51.ApcListEntry.Flink.offset, ~Irp.base, 76 + ~Irp.offset, 4);call write~$Pointer$(#t~union51.ApcListEntry.Blink.base, #t~union51.ApcListEntry.Blink.offset, ~Irp.base, 80 + ~Irp.offset, 4);call write~$Pointer$(#t~union51.KernelRoutine.base, #t~union51.KernelRoutine.offset, ~Irp.base, 84 + ~Irp.offset, 4);call write~$Pointer$(#t~union51.RundownRoutine.base, #t~union51.RundownRoutine.offset, ~Irp.base, 88 + ~Irp.offset, 4);call write~$Pointer$(#t~union51.NormalRoutine.base, #t~union51.NormalRoutine.offset, ~Irp.base, 92 + ~Irp.offset, 4);call write~$Pointer$(#t~union51.NormalContext.base, #t~union51.NormalContext.offset, ~Irp.base, 96 + ~Irp.offset, 4);call write~$Pointer$(#t~union51.SystemArgument1.base, #t~union51.SystemArgument1.offset, ~Irp.base, 100 + ~Irp.offset, 4);call write~$Pointer$(#t~union51.SystemArgument2.base, #t~union51.SystemArgument2.offset, ~Irp.base, 104 + ~Irp.offset, 4);call write~int(#t~union51.ApcStateIndex, ~Irp.base, 108 + ~Irp.offset, 1);call write~int(#t~union51.ApcMode, ~Irp.base, 109 + ~Irp.offset, 1);call write~int(#t~union51.Inserted, ~Irp.base, 110 + ~Irp.offset, 1);call write~$Pointer$(#t~union52.base, #t~union52.offset, ~Irp.base, 64 + ~Irp.offset, 4);call write~int(#t~union53, ~Irp.base, 96 + ~Irp.offset, 4);havoc #t~union51.Type, #t~union51.Size, #t~union51.Spare0, #t~union51.Thread.base, #t~union51.Thread.offset, #t~union51.ApcListEntry.Flink.base, #t~union51.ApcListEntry.Flink.offset, #t~union51.ApcListEntry.Blink.base, #t~union51.ApcListEntry.Blink.offset, #t~union51.KernelRoutine.base, #t~union51.KernelRoutine.offset, #t~union51.RundownRoutine.base, #t~union51.RundownRoutine.offset, #t~union51.NormalRoutine.base, #t~union51.NormalRoutine.offset, #t~union51.NormalContext.base, #t~union51.NormalContext.offset, #t~union51.SystemArgument1.base, #t~union51.SystemArgument1.offset, #t~union51.SystemArgument2.base, #t~union51.SystemArgument2.offset, #t~union51.ApcStateIndex, #t~union51.ApcMode, #t~union51.Inserted;havoc #t~union50.base, #t~union50.offset;havoc #t~mem48.base, #t~mem48.offset;havoc #t~union53;havoc #t~union49.Type, #t~union49.Size, #t~union49.Spare0, #t~union49.Thread.base, #t~union49.Thread.offset, #t~union49.ApcListEntry.Flink.base, #t~union49.ApcListEntry.Flink.offset, #t~union49.ApcListEntry.Blink.base, #t~union49.ApcListEntry.Blink.offset, #t~union49.KernelRoutine.base, #t~union49.KernelRoutine.offset, #t~union49.RundownRoutine.base, #t~union49.RundownRoutine.offset, #t~union49.NormalRoutine.base, #t~union49.NormalRoutine.offset, #t~union49.NormalContext.base, #t~union49.NormalContext.offset, #t~union49.SystemArgument1.base, #t~union49.SystemArgument1.offset, #t~union49.SystemArgument2.base, #t~union49.SystemArgument2.offset, #t~union49.ApcStateIndex, #t~union49.ApcMode, #t~union49.Inserted;havoc #t~union52.base, #t~union52.offset; {3681#(= ~NP~0 ~s~0)} is VALID [2018-11-23 12:46:57,358 INFO L273 TraceCheckUtils]: 44: Hoare triple {3681#(= ~NP~0 ~s~0)} assume !(~s~0 == ~NP~0); {3680#false} is VALID [2018-11-23 12:46:57,359 INFO L256 TraceCheckUtils]: 45: Hoare triple {3680#false} call errorFn(); {3680#false} is VALID [2018-11-23 12:46:57,359 INFO L273 TraceCheckUtils]: 46: Hoare triple {3680#false} assume !false; {3680#false} is VALID [2018-11-23 12:46:57,362 INFO L134 CoverageAnalysis]: Checked inductivity of 0 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2018-11-23 12:46:57,362 INFO L312 seRefinementStrategy]: Constructing automaton from 1 perfect and 0 imperfect interpolant sequences. [2018-11-23 12:46:57,362 INFO L327 seRefinementStrategy]: Number of different interpolants: perfect sequences [3] imperfect sequences [] total 3 [2018-11-23 12:46:57,363 INFO L78 Accepts]: Start accepts. Automaton has 3 states. Word has length 47 [2018-11-23 12:46:57,363 INFO L84 Accepts]: Finished accepts. word is accepted. [2018-11-23 12:46:57,363 INFO L86 InductivityCheck]: Starting indutivity check of a Floyd-Hoare automaton with 3 states. [2018-11-23 12:46:57,583 INFO L119 InductivityCheck]: Floyd-Hoare automaton has 47 edges. 47 inductive. 0 not inductive. 0 times theorem prover too weak to decide inductivity. [2018-11-23 12:46:57,583 INFO L459 AbstractCegarLoop]: Interpolant automaton has 3 states [2018-11-23 12:46:57,583 INFO L142 InterpolantAutomaton]: Constructing interpolant automaton starting with 3 interpolants. [2018-11-23 12:46:57,583 INFO L144 InterpolantAutomaton]: CoverageRelationStatistics Valid=3, Invalid=3, Unknown=0, NotChecked=0, Total=6 [2018-11-23 12:46:57,584 INFO L87 Difference]: Start difference. First operand 296 states and 402 transitions. Second operand 3 states.