java -Xmx6000000000 -jar ./plugins/org.eclipse.equinox.launcher_1.3.100.v20150511-1540.jar -data ./data --generate-csv --csv-dir ../../../releaseScripts/default/UAutomizer-linux/csv -tc ../../../trunk/examples/toolchains/AutomizerC.xml -s ../../../trunk/examples/settings/ai/eq-bench/svcomp-DerefFreeMemtrack-32bit-Automizer_Taipan+AI_EQ_imprecise.epf -i ../../../trunk/examples/svcomp/array-memsafety/cstrpbrk_unsafe_false-valid-deref.i -------------------------------------------------------------------------------- This is Ultimate 0.1.23-6b94a2f [2018-01-24 16:39:43,528 INFO L170 SettingsManager]: Resetting all preferences to default values... [2018-01-24 16:39:43,530 INFO L174 SettingsManager]: Resetting UltimateCore preferences to default values [2018-01-24 16:39:43,544 INFO L177 SettingsManager]: Ultimate Commandline Interface provides no preferences, ignoring... [2018-01-24 16:39:43,544 INFO L174 SettingsManager]: Resetting Boogie Preprocessor preferences to default values [2018-01-24 16:39:43,545 INFO L174 SettingsManager]: Resetting Boogie Procedure Inliner preferences to default values [2018-01-24 16:39:43,546 INFO L174 SettingsManager]: Resetting Abstract Interpretation preferences to default values [2018-01-24 16:39:43,548 INFO L174 SettingsManager]: Resetting LassoRanker preferences to default values [2018-01-24 16:39:43,550 INFO L174 SettingsManager]: Resetting Reaching Definitions preferences to default values [2018-01-24 16:39:43,551 INFO L174 SettingsManager]: Resetting SyntaxChecker preferences to default values [2018-01-24 16:39:43,552 INFO L177 SettingsManager]: Büchi Program Product provides no preferences, ignoring... [2018-01-24 16:39:43,552 INFO L174 SettingsManager]: Resetting LTL2Aut preferences to default values [2018-01-24 16:39:43,553 INFO L174 SettingsManager]: Resetting BlockEncodingV2 preferences to default values [2018-01-24 16:39:43,554 INFO L174 SettingsManager]: Resetting AutomataScriptInterpreter preferences to default values [2018-01-24 16:39:43,555 INFO L174 SettingsManager]: Resetting BuchiAutomizer preferences to default values [2018-01-24 16:39:43,557 INFO L174 SettingsManager]: Resetting CACSL2BoogieTranslator preferences to default values [2018-01-24 16:39:43,559 INFO L174 SettingsManager]: Resetting CodeCheck preferences to default values [2018-01-24 16:39:43,561 INFO L174 SettingsManager]: Resetting InvariantSynthesis preferences to default values [2018-01-24 16:39:43,563 INFO L174 SettingsManager]: Resetting RCFGBuilder preferences to default values [2018-01-24 16:39:43,564 INFO L174 SettingsManager]: Resetting TraceAbstraction preferences to default values [2018-01-24 16:39:43,566 INFO L177 SettingsManager]: TraceAbstractionConcurrent provides no preferences, ignoring... [2018-01-24 16:39:43,566 INFO L177 SettingsManager]: TraceAbstractionWithAFAs provides no preferences, ignoring... [2018-01-24 16:39:43,566 INFO L174 SettingsManager]: Resetting IcfgTransformer preferences to default values [2018-01-24 16:39:43,567 INFO L174 SettingsManager]: Resetting Boogie Printer preferences to default values [2018-01-24 16:39:43,568 INFO L174 SettingsManager]: Resetting Witness Printer preferences to default values [2018-01-24 16:39:43,569 INFO L177 SettingsManager]: Boogie PL CUP Parser provides no preferences, ignoring... [2018-01-24 16:39:43,570 INFO L174 SettingsManager]: Resetting CDTParser preferences to default values [2018-01-24 16:39:43,570 INFO L177 SettingsManager]: PEA to Boogie provides no preferences, ignoring... [2018-01-24 16:39:43,571 INFO L177 SettingsManager]: AutomataScriptParser provides no preferences, ignoring... [2018-01-24 16:39:43,571 INFO L174 SettingsManager]: Resetting Witness Parser preferences to default values [2018-01-24 16:39:43,571 INFO L181 SettingsManager]: Finished resetting all preferences to default values... [2018-01-24 16:39:43,571 INFO L98 SettingsManager]: Beginning loading settings from /storage/ultimate/releaseScripts/default/UAutomizer-linux/../../../trunk/examples/settings/ai/eq-bench/svcomp-DerefFreeMemtrack-32bit-Automizer_Taipan+AI_EQ_imprecise.epf [2018-01-24 16:39:43,579 INFO L110 SettingsManager]: Loading preferences was successful [2018-01-24 16:39:43,579 INFO L112 SettingsManager]: Preferences different from defaults after loading the file: [2018-01-24 16:39:43,580 INFO L131 SettingsManager]: Preferences of Boogie Procedure Inliner differ from their defaults: [2018-01-24 16:39:43,580 INFO L133 SettingsManager]: * to procedures, called more than once=true [2018-01-24 16:39:43,580 INFO L131 SettingsManager]: Preferences of Abstract Interpretation differ from their defaults: [2018-01-24 16:39:43,580 INFO L133 SettingsManager]: * Deactivate Weak Equivalences=true [2018-01-24 16:39:43,580 INFO L133 SettingsManager]: * Abstract domain for RCFG-of-the-future=VPDomain [2018-01-24 16:39:43,580 INFO L133 SettingsManager]: * Use the RCFG-of-the-future interface=true [2018-01-24 16:39:43,581 INFO L131 SettingsManager]: Preferences of CACSL2BoogieTranslator differ from their defaults: [2018-01-24 16:39:43,581 INFO L133 SettingsManager]: * sizeof long=4 [2018-01-24 16:39:43,581 INFO L133 SettingsManager]: * Check unreachability of error function in SV-COMP mode=false [2018-01-24 16:39:43,581 INFO L133 SettingsManager]: * Overapproximate operations on floating types=true [2018-01-24 16:39:43,581 INFO L133 SettingsManager]: * sizeof POINTER=4 [2018-01-24 16:39:43,581 INFO L133 SettingsManager]: * Check division by zero=IGNORE [2018-01-24 16:39:43,582 INFO L133 SettingsManager]: * Check for the main procedure if all allocated memory was freed=true [2018-01-24 16:39:43,582 INFO L133 SettingsManager]: * Bitprecise bitfields=true [2018-01-24 16:39:43,582 INFO L133 SettingsManager]: * SV-COMP memtrack compatibility mode=true [2018-01-24 16:39:43,582 INFO L133 SettingsManager]: * If two pointers are subtracted or compared they have the same base address=IGNORE [2018-01-24 16:39:43,582 INFO L133 SettingsManager]: * sizeof long double=12 [2018-01-24 16:39:43,582 INFO L131 SettingsManager]: Preferences of RCFGBuilder differ from their defaults: [2018-01-24 16:39:43,582 INFO L133 SettingsManager]: * Size of a code block=SequenceOfStatements [2018-01-24 16:39:43,582 INFO L133 SettingsManager]: * To the following directory=./dump/ [2018-01-24 16:39:43,583 INFO L133 SettingsManager]: * Add additional assume for each assert=false [2018-01-24 16:39:43,583 INFO L133 SettingsManager]: * SMT solver=External_DefaultMode [2018-01-24 16:39:43,583 INFO L133 SettingsManager]: * Command for external solver=z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in -t:2000 [2018-01-24 16:39:43,583 INFO L131 SettingsManager]: Preferences of TraceAbstraction differ from their defaults: [2018-01-24 16:39:43,583 INFO L133 SettingsManager]: * Interpolant automaton=TWOTRACK [2018-01-24 16:39:43,583 INFO L133 SettingsManager]: * Compute Interpolants along a Counterexample=FPandBP [2018-01-24 16:39:43,584 INFO L133 SettingsManager]: * Positions where we compute the Hoare Annotation=LoopsAndPotentialCycles [2018-01-24 16:39:43,584 INFO L133 SettingsManager]: * Trace refinement strategy=TAIPAN [2018-01-24 16:39:43,584 INFO L133 SettingsManager]: * SMT solver=External_ModelsAndUnsatCoreMode [2018-01-24 16:39:43,584 INFO L133 SettingsManager]: * Command for external solver=z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in [2018-01-24 16:39:43,584 INFO L133 SettingsManager]: * Compute Hoare Annotation of negated interpolant automaton, abstraction and CFG=true [2018-01-24 16:39:43,584 INFO L133 SettingsManager]: * Abstract interpretation Mode=USE_PREDICATES [2018-01-24 16:39:43,585 INFO L131 SettingsManager]: Preferences of IcfgTransformer differ from their defaults: [2018-01-24 16:39:43,585 INFO L133 SettingsManager]: * TransformationType=HEAP_SEPARATOR [2018-01-24 16:39:43,616 INFO L81 nceAwareModelManager]: Repository-Root is: /tmp [2018-01-24 16:39:43,626 INFO L266 ainManager$Toolchain]: [Toolchain 1]: Parser(s) successfully initialized [2018-01-24 16:39:43,630 INFO L222 ainManager$Toolchain]: [Toolchain 1]: Toolchain data selected. [2018-01-24 16:39:43,631 INFO L271 PluginConnector]: Initializing CDTParser... [2018-01-24 16:39:43,631 INFO L276 PluginConnector]: CDTParser initialized [2018-01-24 16:39:43,632 INFO L431 ainManager$Toolchain]: [Toolchain 1]: Parsing single file: /storage/ultimate/releaseScripts/default/UAutomizer-linux/../../../trunk/examples/svcomp/array-memsafety/cstrpbrk_unsafe_false-valid-deref.i [2018-01-24 16:39:43,785 INFO L304 ainManager$Toolchain]: ####################### [Toolchain 1] ####################### [2018-01-24 16:39:43,791 INFO L131 ToolchainWalker]: Walking toolchain with 4 elements. [2018-01-24 16:39:43,792 INFO L113 PluginConnector]: ------------------------CACSL2BoogieTranslator---------------------------- [2018-01-24 16:39:43,792 INFO L271 PluginConnector]: Initializing CACSL2BoogieTranslator... [2018-01-24 16:39:43,797 INFO L276 PluginConnector]: CACSL2BoogieTranslator initialized [2018-01-24 16:39:43,798 INFO L185 PluginConnector]: Executing the observer ACSLObjectContainerObserver from plugin CACSL2BoogieTranslator for "CDTParser AST 24.01 04:39:43" (1/1) ... [2018-01-24 16:39:43,800 INFO L205 PluginConnector]: Invalid model from CACSL2BoogieTranslator for observer de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator.ACSLObjectContainerObserver@1eaa2765 and model type de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 24.01 04:39:43, skipping insertion in model container [2018-01-24 16:39:43,801 INFO L185 PluginConnector]: Executing the observer CACSL2BoogieTranslatorObserver from plugin CACSL2BoogieTranslator for "CDTParser AST 24.01 04:39:43" (1/1) ... [2018-01-24 16:39:43,814 INFO L153 Dispatcher]: Using SV-COMP mode [2018-01-24 16:39:43,853 INFO L153 Dispatcher]: Using SV-COMP mode [2018-01-24 16:39:43,976 INFO L450 PostProcessor]: Settings: Checked method=main [2018-01-24 16:39:43,997 INFO L450 PostProcessor]: Settings: Checked method=main [2018-01-24 16:39:44,005 INFO L202 PluginConnector]: Adding new model de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 24.01 04:39:44 WrapperNode [2018-01-24 16:39:44,005 INFO L132 PluginConnector]: ------------------------ END CACSL2BoogieTranslator---------------------------- [2018-01-24 16:39:44,006 INFO L113 PluginConnector]: ------------------------Boogie Preprocessor---------------------------- [2018-01-24 16:39:44,006 INFO L271 PluginConnector]: Initializing Boogie Preprocessor... [2018-01-24 16:39:44,006 INFO L276 PluginConnector]: Boogie Preprocessor initialized [2018-01-24 16:39:44,021 INFO L185 PluginConnector]: Executing the observer EnsureBoogieModelObserver from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 24.01 04:39:44" (1/1) ... [2018-01-24 16:39:44,022 INFO L185 PluginConnector]: Executing the observer TypeChecker from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 24.01 04:39:44" (1/1) ... [2018-01-24 16:39:44,031 INFO L185 PluginConnector]: Executing the observer ConstExpander from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 24.01 04:39:44" (1/1) ... [2018-01-24 16:39:44,031 INFO L185 PluginConnector]: Executing the observer StructExpander from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 24.01 04:39:44" (1/1) ... [2018-01-24 16:39:44,036 INFO L185 PluginConnector]: Executing the observer UnstructureCode from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 24.01 04:39:44" (1/1) ... [2018-01-24 16:39:44,040 INFO L185 PluginConnector]: Executing the observer FunctionInliner from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 24.01 04:39:44" (1/1) ... [2018-01-24 16:39:44,041 INFO L185 PluginConnector]: Executing the observer BoogieSymbolTableConstructor from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 24.01 04:39:44" (1/1) ... [2018-01-24 16:39:44,043 INFO L132 PluginConnector]: ------------------------ END Boogie Preprocessor---------------------------- [2018-01-24 16:39:44,044 INFO L113 PluginConnector]: ------------------------RCFGBuilder---------------------------- [2018-01-24 16:39:44,044 INFO L271 PluginConnector]: Initializing RCFGBuilder... [2018-01-24 16:39:44,044 INFO L276 PluginConnector]: RCFGBuilder initialized [2018-01-24 16:39:44,045 INFO L185 PluginConnector]: Executing the observer RCFGBuilderObserver from plugin RCFGBuilder for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 24.01 04:39:44" (1/1) ... No working directory specified, using /storage/ultimate/releaseScripts/default/UAutomizer-linux/z3 Starting monitored process 1 with z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in -t:2000 (exit command is (exit), workingDir is null) Waiting until toolchain timeout for monitored process 1 with z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in -t:2000 [2018-01-24 16:39:44,109 INFO L136 BoogieDeclarations]: Found implementation of procedure ULTIMATE.init [2018-01-24 16:39:44,109 INFO L136 BoogieDeclarations]: Found implementation of procedure ULTIMATE.start [2018-01-24 16:39:44,109 INFO L136 BoogieDeclarations]: Found implementation of procedure build_nondet_String [2018-01-24 16:39:44,109 INFO L136 BoogieDeclarations]: Found implementation of procedure cstrpbrk [2018-01-24 16:39:44,109 INFO L136 BoogieDeclarations]: Found implementation of procedure main [2018-01-24 16:39:44,109 INFO L128 BoogieDeclarations]: Found specification of procedure write~int [2018-01-24 16:39:44,110 INFO L128 BoogieDeclarations]: Found specification of procedure read~int [2018-01-24 16:39:44,110 INFO L128 BoogieDeclarations]: Found specification of procedure ULTIMATE.free [2018-01-24 16:39:44,110 INFO L128 BoogieDeclarations]: Found specification of procedure ULTIMATE.dealloc [2018-01-24 16:39:44,110 INFO L128 BoogieDeclarations]: Found specification of procedure #Ultimate.alloc [2018-01-24 16:39:44,110 INFO L128 BoogieDeclarations]: Found specification of procedure malloc [2018-01-24 16:39:44,110 INFO L128 BoogieDeclarations]: Found specification of procedure free [2018-01-24 16:39:44,111 INFO L128 BoogieDeclarations]: Found specification of procedure __VERIFIER_nondet_int [2018-01-24 16:39:44,111 INFO L128 BoogieDeclarations]: Found specification of procedure build_nondet_String [2018-01-24 16:39:44,111 INFO L128 BoogieDeclarations]: Found specification of procedure cstrpbrk [2018-01-24 16:39:44,111 INFO L128 BoogieDeclarations]: Found specification of procedure main [2018-01-24 16:39:44,111 INFO L128 BoogieDeclarations]: Found specification of procedure ULTIMATE.init [2018-01-24 16:39:44,111 INFO L128 BoogieDeclarations]: Found specification of procedure ULTIMATE.start [2018-01-24 16:39:44,393 INFO L257 CfgBuilder]: Using the 1 location(s) as analysis (start of procedure ULTIMATE.start) [2018-01-24 16:39:44,393 INFO L202 PluginConnector]: Adding new model de.uni_freiburg.informatik.ultimate.plugins.generator.rcfgbuilder CFG 24.01 04:39:44 BoogieIcfgContainer [2018-01-24 16:39:44,393 INFO L132 PluginConnector]: ------------------------ END RCFGBuilder---------------------------- [2018-01-24 16:39:44,394 INFO L113 PluginConnector]: ------------------------TraceAbstraction---------------------------- [2018-01-24 16:39:44,394 INFO L271 PluginConnector]: Initializing TraceAbstraction... [2018-01-24 16:39:44,396 INFO L276 PluginConnector]: TraceAbstraction initialized [2018-01-24 16:39:44,396 INFO L185 PluginConnector]: Executing the observer TraceAbstractionObserver from plugin TraceAbstraction for "CDTParser AST 24.01 04:39:43" (1/3) ... [2018-01-24 16:39:44,397 INFO L205 PluginConnector]: Invalid model from TraceAbstraction for observer de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction.TraceAbstractionObserver@826fa2 and model type de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction AST 24.01 04:39:44, skipping insertion in model container [2018-01-24 16:39:44,397 INFO L185 PluginConnector]: Executing the observer TraceAbstractionObserver from plugin TraceAbstraction for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 24.01 04:39:44" (2/3) ... [2018-01-24 16:39:44,397 INFO L205 PluginConnector]: Invalid model from TraceAbstraction for observer de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction.TraceAbstractionObserver@826fa2 and model type de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction AST 24.01 04:39:44, skipping insertion in model container [2018-01-24 16:39:44,398 INFO L185 PluginConnector]: Executing the observer TraceAbstractionObserver from plugin TraceAbstraction for "de.uni_freiburg.informatik.ultimate.plugins.generator.rcfgbuilder CFG 24.01 04:39:44" (3/3) ... [2018-01-24 16:39:44,399 INFO L105 eAbstractionObserver]: Analyzing ICFG cstrpbrk_unsafe_false-valid-deref.i [2018-01-24 16:39:44,406 INFO L130 ceAbstractionStarter]: Automizer settings: Hoare:true NWA Interpolation:FPandBP Determinization: PREDICATE_ABSTRACTION [2018-01-24 16:39:44,412 INFO L142 ceAbstractionStarter]: Appying trace abstraction to program that has 19 error locations. [2018-01-24 16:39:44,459 INFO L322 AbstractCegarLoop]: Interprodecural is true [2018-01-24 16:39:44,460 INFO L323 AbstractCegarLoop]: Hoare is true [2018-01-24 16:39:44,460 INFO L324 AbstractCegarLoop]: Compute interpolants for FPandBP [2018-01-24 16:39:44,460 INFO L325 AbstractCegarLoop]: Backedges is TWOTRACK [2018-01-24 16:39:44,460 INFO L326 AbstractCegarLoop]: Determinization is PREDICATE_ABSTRACTION [2018-01-24 16:39:44,460 INFO L327 AbstractCegarLoop]: Difference is false [2018-01-24 16:39:44,460 INFO L328 AbstractCegarLoop]: Minimize is MINIMIZE_SEVPA [2018-01-24 16:39:44,460 INFO L333 AbstractCegarLoop]: ======== Iteration 0==of CEGAR loop == AllErrorsAtOnce======== [2018-01-24 16:39:44,461 INFO L87 2NestedWordAutomaton]: Mode: main mode - execution starts in main procedure [2018-01-24 16:39:44,483 INFO L276 IsEmpty]: Start isEmpty. Operand 65 states. [2018-01-24 16:39:44,489 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 12 [2018-01-24 16:39:44,489 INFO L314 BasicCegarLoop]: Found error trace [2018-01-24 16:39:44,490 INFO L322 BasicCegarLoop]: trace histogram [1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2018-01-24 16:39:44,491 INFO L371 AbstractCegarLoop]: === Iteration 1 === [build_nondet_StringErr0RequiresViolation, build_nondet_StringErr1RequiresViolation, cstrpbrkErr3RequiresViolation, cstrpbrkErr1RequiresViolation, cstrpbrkErr9RequiresViolation, cstrpbrkErr7RequiresViolation, cstrpbrkErr2RequiresViolation, cstrpbrkErr8RequiresViolation, cstrpbrkErr4RequiresViolation, cstrpbrkErr0RequiresViolation, cstrpbrkErr6RequiresViolation, cstrpbrkErr5RequiresViolation, mainErr5RequiresViolation, mainErr3RequiresViolation, mainErr1RequiresViolation, mainErr2RequiresViolation, mainErr4RequiresViolation, mainErr6EnsuresViolation, mainErr0RequiresViolation]=== [2018-01-24 16:39:44,496 INFO L82 PathProgramCache]: Analyzing trace with hash -1167838739, now seen corresponding path program 1 times [2018-01-24 16:39:44,498 INFO L67 tionRefinementEngine]: Using refinement strategy TaipanRefinementStrategy [2018-01-24 16:39:44,551 INFO L117 rtionOrderModulation]: Craig nested/tree interpolation forces the following order [2018-01-24 16:39:44,551 INFO L101 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2018-01-24 16:39:44,551 INFO L117 rtionOrderModulation]: Craig nested/tree interpolation forces the following order [2018-01-24 16:39:44,551 INFO L280 anRefinementStrategy]: Using traceCheck mode SMTINTERPOL with AssertCodeBlockOrder NOT_INCREMENTALLY (IT: Craig_TreeInterpolation) [2018-01-24 16:39:44,595 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2018-01-24 16:39:44,604 WARN L137 erpolLogProxyWrapper]: Using partial proofs (cut at CNF-level). Set option :produce-proofs to true to get complete proofs. [2018-01-24 16:39:44,690 INFO L134 CoverageAnalysis]: Checked inductivity of 0 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2018-01-24 16:39:44,692 INFO L320 seRefinementStrategy]: Constructing automaton from 1 perfect and 0 imperfect interpolant sequences. [2018-01-24 16:39:44,693 INFO L335 seRefinementStrategy]: Number of different interpolants: perfect sequences [3] imperfect sequences [] total 3 [2018-01-24 16:39:44,693 INFO L252 anRefinementStrategy]: Using the first perfect interpolant sequence [2018-01-24 16:39:44,695 INFO L409 AbstractCegarLoop]: Interpolant automaton has 4 states [2018-01-24 16:39:44,705 INFO L132 InterpolantAutomaton]: Constructing interpolant automaton starting with 4 interpolants. [2018-01-24 16:39:44,706 INFO L133 InterpolantAutomaton]: CoverageRelationStatistics Valid=5, Invalid=7, Unknown=0, NotChecked=0, Total=12 [2018-01-24 16:39:44,709 INFO L87 Difference]: Start difference. First operand 65 states. Second operand 4 states. [2018-01-24 16:39:44,945 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2018-01-24 16:39:44,945 INFO L93 Difference]: Finished difference Result 109 states and 121 transitions. [2018-01-24 16:39:44,946 INFO L142 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 4 states. [2018-01-24 16:39:44,947 INFO L78 Accepts]: Start accepts. Automaton has 4 states. Word has length 11 [2018-01-24 16:39:44,948 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2018-01-24 16:39:44,959 INFO L225 Difference]: With dead ends: 109 [2018-01-24 16:39:44,959 INFO L226 Difference]: Without dead ends: 61 [2018-01-24 16:39:44,963 INFO L525 BasicCegarLoop]: 0 DeclaredPredicates, 4 GetRequests, 1 SyntacticMatches, 0 SemanticMatches, 3 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 0 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=9, Invalid=11, Unknown=0, NotChecked=0, Total=20 [2018-01-24 16:39:44,982 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 61 states. [2018-01-24 16:39:45,005 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 61 to 61. [2018-01-24 16:39:45,006 INFO L82 GeneralOperation]: Start removeUnreachable. Operand 61 states. [2018-01-24 16:39:45,009 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 61 states to 61 states and 66 transitions. [2018-01-24 16:39:45,011 INFO L78 Accepts]: Start accepts. Automaton has 61 states and 66 transitions. Word has length 11 [2018-01-24 16:39:45,011 INFO L84 Accepts]: Finished accepts. word is rejected. [2018-01-24 16:39:45,011 INFO L432 AbstractCegarLoop]: Abstraction has 61 states and 66 transitions. [2018-01-24 16:39:45,011 INFO L433 AbstractCegarLoop]: Interpolant automaton has 4 states. [2018-01-24 16:39:45,012 INFO L276 IsEmpty]: Start isEmpty. Operand 61 states and 66 transitions. [2018-01-24 16:39:45,012 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 12 [2018-01-24 16:39:45,012 INFO L314 BasicCegarLoop]: Found error trace [2018-01-24 16:39:45,012 INFO L322 BasicCegarLoop]: trace histogram [1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2018-01-24 16:39:45,013 INFO L371 AbstractCegarLoop]: === Iteration 2 === [build_nondet_StringErr0RequiresViolation, build_nondet_StringErr1RequiresViolation, cstrpbrkErr3RequiresViolation, cstrpbrkErr1RequiresViolation, cstrpbrkErr9RequiresViolation, cstrpbrkErr7RequiresViolation, cstrpbrkErr2RequiresViolation, cstrpbrkErr8RequiresViolation, cstrpbrkErr4RequiresViolation, cstrpbrkErr0RequiresViolation, cstrpbrkErr6RequiresViolation, cstrpbrkErr5RequiresViolation, mainErr5RequiresViolation, mainErr3RequiresViolation, mainErr1RequiresViolation, mainErr2RequiresViolation, mainErr4RequiresViolation, mainErr6EnsuresViolation, mainErr0RequiresViolation]=== [2018-01-24 16:39:45,013 INFO L82 PathProgramCache]: Analyzing trace with hash -1167838738, now seen corresponding path program 1 times [2018-01-24 16:39:45,013 INFO L67 tionRefinementEngine]: Using refinement strategy TaipanRefinementStrategy [2018-01-24 16:39:45,014 INFO L117 rtionOrderModulation]: Craig nested/tree interpolation forces the following order [2018-01-24 16:39:45,015 INFO L101 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2018-01-24 16:39:45,015 INFO L117 rtionOrderModulation]: Craig nested/tree interpolation forces the following order [2018-01-24 16:39:45,015 INFO L280 anRefinementStrategy]: Using traceCheck mode SMTINTERPOL with AssertCodeBlockOrder NOT_INCREMENTALLY (IT: Craig_TreeInterpolation) [2018-01-24 16:39:45,035 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2018-01-24 16:39:45,036 WARN L137 erpolLogProxyWrapper]: Using partial proofs (cut at CNF-level). Set option :produce-proofs to true to get complete proofs. [2018-01-24 16:39:45,129 INFO L134 CoverageAnalysis]: Checked inductivity of 0 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2018-01-24 16:39:45,129 INFO L320 seRefinementStrategy]: Constructing automaton from 1 perfect and 0 imperfect interpolant sequences. [2018-01-24 16:39:45,129 INFO L335 seRefinementStrategy]: Number of different interpolants: perfect sequences [4] imperfect sequences [] total 4 [2018-01-24 16:39:45,129 INFO L252 anRefinementStrategy]: Using the first perfect interpolant sequence [2018-01-24 16:39:45,130 INFO L409 AbstractCegarLoop]: Interpolant automaton has 5 states [2018-01-24 16:39:45,131 INFO L132 InterpolantAutomaton]: Constructing interpolant automaton starting with 5 interpolants. [2018-01-24 16:39:45,131 INFO L133 InterpolantAutomaton]: CoverageRelationStatistics Valid=9, Invalid=11, Unknown=0, NotChecked=0, Total=20 [2018-01-24 16:39:45,131 INFO L87 Difference]: Start difference. First operand 61 states and 66 transitions. Second operand 5 states. [2018-01-24 16:39:45,171 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2018-01-24 16:39:45,171 INFO L93 Difference]: Finished difference Result 61 states and 66 transitions. [2018-01-24 16:39:45,172 INFO L142 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 5 states. [2018-01-24 16:39:45,172 INFO L78 Accepts]: Start accepts. Automaton has 5 states. Word has length 11 [2018-01-24 16:39:45,172 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2018-01-24 16:39:45,174 INFO L225 Difference]: With dead ends: 61 [2018-01-24 16:39:45,174 INFO L226 Difference]: Without dead ends: 60 [2018-01-24 16:39:45,175 INFO L525 BasicCegarLoop]: 0 DeclaredPredicates, 5 GetRequests, 1 SyntacticMatches, 0 SemanticMatches, 4 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 0 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=14, Invalid=16, Unknown=0, NotChecked=0, Total=30 [2018-01-24 16:39:45,175 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 60 states. [2018-01-24 16:39:45,180 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 60 to 60. [2018-01-24 16:39:45,181 INFO L82 GeneralOperation]: Start removeUnreachable. Operand 60 states. [2018-01-24 16:39:45,182 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 60 states to 60 states and 65 transitions. [2018-01-24 16:39:45,183 INFO L78 Accepts]: Start accepts. Automaton has 60 states and 65 transitions. Word has length 11 [2018-01-24 16:39:45,183 INFO L84 Accepts]: Finished accepts. word is rejected. [2018-01-24 16:39:45,183 INFO L432 AbstractCegarLoop]: Abstraction has 60 states and 65 transitions. [2018-01-24 16:39:45,183 INFO L433 AbstractCegarLoop]: Interpolant automaton has 5 states. [2018-01-24 16:39:45,183 INFO L276 IsEmpty]: Start isEmpty. Operand 60 states and 65 transitions. [2018-01-24 16:39:45,184 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 30 [2018-01-24 16:39:45,185 INFO L314 BasicCegarLoop]: Found error trace [2018-01-24 16:39:45,185 INFO L322 BasicCegarLoop]: trace histogram [2, 2, 2, 2, 2, 2, 2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2018-01-24 16:39:45,185 INFO L371 AbstractCegarLoop]: === Iteration 3 === [build_nondet_StringErr0RequiresViolation, build_nondet_StringErr1RequiresViolation, cstrpbrkErr3RequiresViolation, cstrpbrkErr1RequiresViolation, cstrpbrkErr9RequiresViolation, cstrpbrkErr7RequiresViolation, cstrpbrkErr2RequiresViolation, cstrpbrkErr8RequiresViolation, cstrpbrkErr4RequiresViolation, cstrpbrkErr0RequiresViolation, cstrpbrkErr6RequiresViolation, cstrpbrkErr5RequiresViolation, mainErr5RequiresViolation, mainErr3RequiresViolation, mainErr1RequiresViolation, mainErr2RequiresViolation, mainErr4RequiresViolation, mainErr6EnsuresViolation, mainErr0RequiresViolation]=== [2018-01-24 16:39:45,185 INFO L82 PathProgramCache]: Analyzing trace with hash -1764023599, now seen corresponding path program 1 times [2018-01-24 16:39:45,185 INFO L67 tionRefinementEngine]: Using refinement strategy TaipanRefinementStrategy [2018-01-24 16:39:45,187 INFO L117 rtionOrderModulation]: Craig nested/tree interpolation forces the following order [2018-01-24 16:39:45,187 INFO L101 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2018-01-24 16:39:45,187 INFO L117 rtionOrderModulation]: Craig nested/tree interpolation forces the following order [2018-01-24 16:39:45,187 INFO L280 anRefinementStrategy]: Using traceCheck mode SMTINTERPOL with AssertCodeBlockOrder NOT_INCREMENTALLY (IT: Craig_TreeInterpolation) [2018-01-24 16:39:45,213 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2018-01-24 16:39:45,214 WARN L137 erpolLogProxyWrapper]: Using partial proofs (cut at CNF-level). Set option :produce-proofs to true to get complete proofs. [2018-01-24 16:39:45,483 INFO L134 CoverageAnalysis]: Checked inductivity of 8 backedges. 5 proven. 3 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2018-01-24 16:39:45,483 INFO L308 seRefinementStrategy]: The current sequences of interpolants are not accepted, trying to find more. [2018-01-24 16:39:45,483 INFO L187 anRefinementStrategy]: Switched to InterpolantGenerator mode ABSTRACT_INTERPRETATION [2018-01-24 16:39:45,484 INFO L199 CegarAbsIntRunner]: Running AI on error trace of length 30 with the following transitions: [2018-01-24 16:39:45,485 INFO L201 CegarAbsIntRunner]: [0], [3], [7], [8], [9], [12], [13], [15], [17], [32], [33], [34], [38], [40], [95], [96], [97], [98], [99], [101], [102], [103] [2018-01-24 16:39:45,527 INFO L147 AbstractInterpreter]: Using domain VPDomain [2018-01-24 16:39:45,527 INFO L101 FixpointEngine]: Starting fixpoint engine with domain VPDomain (maxUnwinding=3, maxParallelStates=2) [2018-01-24 16:39:45,695 INFO L259 AbstractInterpreter]: Some error location(s) were reachable [2018-01-24 16:39:45,697 INFO L268 AbstractInterpreter]: Visited 22 different actions 29 times. Never merged. Never widened. Never found a fixpoint. Largest state had 23 variables. [2018-01-24 16:39:45,704 INFO L434 seRefinementStrategy]: Interpolation failed due to KNOWN_IGNORE: Unknown [2018-01-24 16:39:45,705 INFO L308 seRefinementStrategy]: The current sequences of interpolants are not accepted, trying to find more. [2018-01-24 16:39:45,705 INFO L187 anRefinementStrategy]: Switched to InterpolantGenerator mode Z3_IG No working directory specified, using /storage/ultimate/releaseScripts/default/UAutomizer-linux/z3 Starting monitored process 2 with z3 -smt2 -in SMTLIB2_COMPLIANT=true -t:12000 (exit command is (exit), workingDir is null) Waiting until toolchain timeout for monitored process 2 with z3 -smt2 -in SMTLIB2_COMPLIANT=true -t:12000 [2018-01-24 16:39:45,717 INFO L101 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2018-01-24 16:39:45,718 INFO L280 anRefinementStrategy]: Using traceCheck mode Z3_IG with AssertCodeBlockOrder NOT_INCREMENTALLY (IT: FPandBP) [2018-01-24 16:39:45,751 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2018-01-24 16:39:45,759 INFO L270 TraceCheckSpWp]: Computing forward predicates... [2018-01-24 16:39:45,864 INFO L477 Elim1Store]: Elim1 did not use preprocessing eliminated variable of array dimension 1, 1 stores, 1 select indices, 1 select index equivalence classes, 0 disjoint index pairs (out of 0 index pairs), introduced 0 new quantified variables, introduced 0 case distinctions, treesize of input 12 treesize of output 11 [2018-01-24 16:39:45,864 INFO L267 ElimStorePlain]: Start of recursive call 2: End of recursive call: and 1 xjuncts. [2018-01-24 16:39:45,869 INFO L267 ElimStorePlain]: Start of recursive call 1: 1 dim-0 vars, 1 dim-1 vars, End of recursive call: 1 dim-0 vars, and 1 xjuncts. [2018-01-24 16:39:45,870 INFO L202 ElimStorePlain]: Needed 2 recursive calls to eliminate 2 variables, input treesize:17, output treesize:11 [2018-01-24 16:39:45,894 INFO L134 CoverageAnalysis]: Checked inductivity of 8 backedges. 5 proven. 3 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2018-01-24 16:39:45,895 INFO L314 TraceCheckSpWp]: Computing backward predicates... [2018-01-24 16:39:46,158 INFO L134 CoverageAnalysis]: Checked inductivity of 8 backedges. 5 proven. 3 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2018-01-24 16:39:46,182 INFO L308 seRefinementStrategy]: The current sequences of interpolants are not accepted, trying to find more. [2018-01-24 16:39:46,182 INFO L187 anRefinementStrategy]: Switched to InterpolantGenerator mode CVC4_IG No working directory specified, using /storage/ultimate/releaseScripts/default/UAutomizer-linux/cvc4 Starting monitored process 3 with cvc4 --tear-down-incremental --print-success --lang smt --rewrite-divk --tlimit-per=12000 (exit command is (exit), workingDir is null) Waiting until toolchain timeout for monitored process 3 with cvc4 --tear-down-incremental --print-success --lang smt --rewrite-divk --tlimit-per=12000 [2018-01-24 16:39:46,193 INFO L101 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2018-01-24 16:39:46,194 INFO L280 anRefinementStrategy]: Using traceCheck mode CVC4_IG with AssertCodeBlockOrder NOT_INCREMENTALLY (IT: FPandBP) [2018-01-24 16:39:46,236 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2018-01-24 16:39:46,242 INFO L270 TraceCheckSpWp]: Computing forward predicates... [2018-01-24 16:39:46,248 INFO L477 Elim1Store]: Elim1 did not use preprocessing eliminated variable of array dimension 1, 1 stores, 0 select indices, 0 select index equivalence classes, 0 disjoint index pairs (out of 0 index pairs), introduced 0 new quantified variables, introduced 0 case distinctions, treesize of input 6 treesize of output 5 [2018-01-24 16:39:46,249 INFO L267 ElimStorePlain]: Start of recursive call 2: End of recursive call: and 1 xjuncts. [2018-01-24 16:39:46,258 INFO L267 ElimStorePlain]: Start of recursive call 1: 1 dim-1 vars, End of recursive call: and 1 xjuncts. [2018-01-24 16:39:46,258 INFO L202 ElimStorePlain]: Needed 2 recursive calls to eliminate 1 variables, input treesize:6, output treesize:5 [2018-01-24 16:39:46,298 WARN L1029 $PredicateComparison]: unable to prove that (exists ((|build_nondet_String_#t~malloc1.base| Int)) (= |c_#valid| (store |c_old(#valid)| |build_nondet_String_#t~malloc1.base| 1))) is different from true [2018-01-24 16:39:46,306 INFO L477 Elim1Store]: Elim1 did not use preprocessing eliminated variable of array dimension 1, 1 stores, 1 select indices, 1 select index equivalence classes, 0 disjoint index pairs (out of 0 index pairs), introduced 0 new quantified variables, introduced 0 case distinctions, treesize of input 12 treesize of output 11 [2018-01-24 16:39:46,306 INFO L267 ElimStorePlain]: Start of recursive call 2: End of recursive call: and 1 xjuncts. [2018-01-24 16:39:46,309 INFO L267 ElimStorePlain]: Start of recursive call 1: 1 dim-0 vars, 1 dim-1 vars, End of recursive call: 1 dim-0 vars, and 1 xjuncts. [2018-01-24 16:39:46,310 INFO L202 ElimStorePlain]: Needed 2 recursive calls to eliminate 2 variables, input treesize:12, output treesize:11 [2018-01-24 16:39:46,324 INFO L134 CoverageAnalysis]: Checked inductivity of 8 backedges. 3 proven. 0 refuted. 0 times theorem prover too weak. 0 trivial. 5 not checked. [2018-01-24 16:39:46,325 INFO L314 TraceCheckSpWp]: Computing backward predicates... [2018-01-24 16:39:46,427 INFO L134 CoverageAnalysis]: Checked inductivity of 8 backedges. 3 proven. 5 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2018-01-24 16:39:46,429 INFO L320 seRefinementStrategy]: Constructing automaton from 0 perfect and 5 imperfect interpolant sequences. [2018-01-24 16:39:46,429 INFO L335 seRefinementStrategy]: Number of different interpolants: perfect sequences [] imperfect sequences [11, 11, 10, 10, 9] total 19 [2018-01-24 16:39:46,429 INFO L247 anRefinementStrategy]: Using the first two imperfect interpolant sequences [2018-01-24 16:39:46,430 INFO L409 AbstractCegarLoop]: Interpolant automaton has 15 states [2018-01-24 16:39:46,430 INFO L132 InterpolantAutomaton]: Constructing interpolant automaton starting with 15 interpolants. [2018-01-24 16:39:46,430 INFO L133 InterpolantAutomaton]: CoverageRelationStatistics Valid=68, Invalid=271, Unknown=7, NotChecked=34, Total=380 [2018-01-24 16:39:46,430 INFO L87 Difference]: Start difference. First operand 60 states and 65 transitions. Second operand 15 states. [2018-01-24 16:39:46,717 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2018-01-24 16:39:46,717 INFO L93 Difference]: Finished difference Result 63 states and 69 transitions. [2018-01-24 16:39:46,717 INFO L142 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 12 states. [2018-01-24 16:39:46,717 INFO L78 Accepts]: Start accepts. Automaton has 15 states. Word has length 29 [2018-01-24 16:39:46,718 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2018-01-24 16:39:46,718 INFO L225 Difference]: With dead ends: 63 [2018-01-24 16:39:46,719 INFO L226 Difference]: Without dead ends: 60 [2018-01-24 16:39:46,719 INFO L525 BasicCegarLoop]: 0 DeclaredPredicates, 135 GetRequests, 91 SyntacticMatches, 19 SemanticMatches, 25 ConstructedPredicates, 1 IntricatePredicates, 0 DeprecatedPredicates, 141 ImplicationChecksByTransitivity, 0.6s TimeCoverageRelationStatistics Valid=148, Invalid=499, Unknown=7, NotChecked=48, Total=702 [2018-01-24 16:39:46,719 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 60 states. [2018-01-24 16:39:46,723 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 60 to 57. [2018-01-24 16:39:46,723 INFO L82 GeneralOperation]: Start removeUnreachable. Operand 57 states. [2018-01-24 16:39:46,724 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 57 states to 57 states and 62 transitions. [2018-01-24 16:39:46,724 INFO L78 Accepts]: Start accepts. Automaton has 57 states and 62 transitions. Word has length 29 [2018-01-24 16:39:46,726 INFO L84 Accepts]: Finished accepts. word is rejected. [2018-01-24 16:39:46,726 INFO L432 AbstractCegarLoop]: Abstraction has 57 states and 62 transitions. [2018-01-24 16:39:46,726 INFO L433 AbstractCegarLoop]: Interpolant automaton has 15 states. [2018-01-24 16:39:46,726 INFO L276 IsEmpty]: Start isEmpty. Operand 57 states and 62 transitions. [2018-01-24 16:39:46,727 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 30 [2018-01-24 16:39:46,727 INFO L314 BasicCegarLoop]: Found error trace [2018-01-24 16:39:46,727 INFO L322 BasicCegarLoop]: trace histogram [2, 2, 2, 2, 2, 2, 2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2018-01-24 16:39:46,727 INFO L371 AbstractCegarLoop]: === Iteration 4 === [build_nondet_StringErr0RequiresViolation, build_nondet_StringErr1RequiresViolation, cstrpbrkErr3RequiresViolation, cstrpbrkErr1RequiresViolation, cstrpbrkErr9RequiresViolation, cstrpbrkErr7RequiresViolation, cstrpbrkErr2RequiresViolation, cstrpbrkErr8RequiresViolation, cstrpbrkErr4RequiresViolation, cstrpbrkErr0RequiresViolation, cstrpbrkErr6RequiresViolation, cstrpbrkErr5RequiresViolation, mainErr5RequiresViolation, mainErr3RequiresViolation, mainErr1RequiresViolation, mainErr2RequiresViolation, mainErr4RequiresViolation, mainErr6EnsuresViolation, mainErr0RequiresViolation]=== [2018-01-24 16:39:46,727 INFO L82 PathProgramCache]: Analyzing trace with hash -1764023598, now seen corresponding path program 1 times [2018-01-24 16:39:46,727 INFO L67 tionRefinementEngine]: Using refinement strategy TaipanRefinementStrategy [2018-01-24 16:39:46,728 INFO L117 rtionOrderModulation]: Craig nested/tree interpolation forces the following order [2018-01-24 16:39:46,728 INFO L101 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2018-01-24 16:39:46,728 INFO L117 rtionOrderModulation]: Craig nested/tree interpolation forces the following order [2018-01-24 16:39:46,728 INFO L280 anRefinementStrategy]: Using traceCheck mode SMTINTERPOL with AssertCodeBlockOrder NOT_INCREMENTALLY (IT: Craig_TreeInterpolation) [2018-01-24 16:39:46,743 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2018-01-24 16:39:46,744 WARN L137 erpolLogProxyWrapper]: Using partial proofs (cut at CNF-level). Set option :produce-proofs to true to get complete proofs. [2018-01-24 16:39:46,964 INFO L134 CoverageAnalysis]: Checked inductivity of 8 backedges. 2 proven. 6 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2018-01-24 16:39:46,964 INFO L308 seRefinementStrategy]: The current sequences of interpolants are not accepted, trying to find more. [2018-01-24 16:39:46,964 INFO L187 anRefinementStrategy]: Switched to InterpolantGenerator mode ABSTRACT_INTERPRETATION [2018-01-24 16:39:46,964 INFO L199 CegarAbsIntRunner]: Running AI on error trace of length 30 with the following transitions: [2018-01-24 16:39:46,964 INFO L201 CegarAbsIntRunner]: [0], [3], [7], [8], [9], [12], [13], [15], [17], [32], [33], [34], [38], [41], [95], [96], [97], [98], [99], [101], [102], [103] [2018-01-24 16:39:46,966 INFO L147 AbstractInterpreter]: Using domain VPDomain [2018-01-24 16:39:46,966 INFO L101 FixpointEngine]: Starting fixpoint engine with domain VPDomain (maxUnwinding=3, maxParallelStates=2) [2018-01-24 16:39:47,064 INFO L259 AbstractInterpreter]: Some error location(s) were reachable [2018-01-24 16:39:47,064 INFO L268 AbstractInterpreter]: Visited 22 different actions 29 times. Never merged. Never widened. Never found a fixpoint. Largest state had 23 variables. [2018-01-24 16:39:47,077 INFO L434 seRefinementStrategy]: Interpolation failed due to KNOWN_IGNORE: Unknown [2018-01-24 16:39:47,077 INFO L308 seRefinementStrategy]: The current sequences of interpolants are not accepted, trying to find more. [2018-01-24 16:39:47,078 INFO L187 anRefinementStrategy]: Switched to InterpolantGenerator mode Z3_IG No working directory specified, using /storage/ultimate/releaseScripts/default/UAutomizer-linux/z3 Starting monitored process 4 with z3 -smt2 -in SMTLIB2_COMPLIANT=true -t:12000 (exit command is (exit), workingDir is null) Waiting until toolchain timeout for monitored process 4 with z3 -smt2 -in SMTLIB2_COMPLIANT=true -t:12000 [2018-01-24 16:39:47,092 INFO L101 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2018-01-24 16:39:47,093 INFO L280 anRefinementStrategy]: Using traceCheck mode Z3_IG with AssertCodeBlockOrder NOT_INCREMENTALLY (IT: FPandBP) [2018-01-24 16:39:47,110 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2018-01-24 16:39:47,113 INFO L270 TraceCheckSpWp]: Computing forward predicates... [2018-01-24 16:39:47,127 INFO L477 Elim1Store]: Elim1 did not use preprocessing eliminated variable of array dimension 1, 1 stores, 0 select indices, 0 select index equivalence classes, 0 disjoint index pairs (out of 0 index pairs), introduced 0 new quantified variables, introduced 0 case distinctions, treesize of input 6 treesize of output 5 [2018-01-24 16:39:47,127 INFO L267 ElimStorePlain]: Start of recursive call 2: End of recursive call: and 1 xjuncts. [2018-01-24 16:39:47,131 INFO L267 ElimStorePlain]: Start of recursive call 1: 1 dim-1 vars, End of recursive call: and 1 xjuncts. [2018-01-24 16:39:47,131 INFO L202 ElimStorePlain]: Needed 2 recursive calls to eliminate 1 variables, input treesize:13, output treesize:12 [2018-01-24 16:39:47,422 WARN L1029 $PredicateComparison]: unable to prove that (exists ((|build_nondet_String_#t~malloc1.base| Int)) (= (store |c_old(#length)| |build_nondet_String_#t~malloc1.base| 1) |c_#length|)) is different from true [2018-01-24 16:39:47,427 INFO L477 Elim1Store]: Elim1 did not use preprocessing eliminated variable of array dimension 1, 1 stores, 1 select indices, 1 select index equivalence classes, 0 disjoint index pairs (out of 0 index pairs), introduced 0 new quantified variables, introduced 0 case distinctions, treesize of input 12 treesize of output 11 [2018-01-24 16:39:47,435 INFO L267 ElimStorePlain]: Start of recursive call 2: End of recursive call: and 1 xjuncts. [2018-01-24 16:39:47,440 INFO L267 ElimStorePlain]: Start of recursive call 1: 1 dim-0 vars, 1 dim-1 vars, End of recursive call: 1 dim-0 vars, and 1 xjuncts. [2018-01-24 16:39:47,440 INFO L202 ElimStorePlain]: Needed 2 recursive calls to eliminate 2 variables, input treesize:18, output treesize:17 [2018-01-24 16:39:47,497 INFO L134 CoverageAnalysis]: Checked inductivity of 8 backedges. 3 proven. 1 refuted. 0 times theorem prover too weak. 0 trivial. 4 not checked. [2018-01-24 16:39:47,497 INFO L314 TraceCheckSpWp]: Computing backward predicates... [2018-01-24 16:39:47,878 INFO L134 CoverageAnalysis]: Checked inductivity of 8 backedges. 2 proven. 6 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2018-01-24 16:39:47,899 INFO L308 seRefinementStrategy]: The current sequences of interpolants are not accepted, trying to find more. [2018-01-24 16:39:47,899 INFO L187 anRefinementStrategy]: Switched to InterpolantGenerator mode CVC4_IG No working directory specified, using /storage/ultimate/releaseScripts/default/UAutomizer-linux/cvc4 Starting monitored process 5 with cvc4 --tear-down-incremental --print-success --lang smt --rewrite-divk --tlimit-per=12000 (exit command is (exit), workingDir is null) Waiting until toolchain timeout for monitored process 5 with cvc4 --tear-down-incremental --print-success --lang smt --rewrite-divk --tlimit-per=12000 [2018-01-24 16:39:47,902 INFO L101 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2018-01-24 16:39:47,902 INFO L280 anRefinementStrategy]: Using traceCheck mode CVC4_IG with AssertCodeBlockOrder NOT_INCREMENTALLY (IT: FPandBP) [2018-01-24 16:39:47,938 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2018-01-24 16:39:47,943 INFO L270 TraceCheckSpWp]: Computing forward predicates... [2018-01-24 16:39:47,948 INFO L477 Elim1Store]: Elim1 did not use preprocessing eliminated variable of array dimension 1, 1 stores, 0 select indices, 0 select index equivalence classes, 0 disjoint index pairs (out of 0 index pairs), introduced 0 new quantified variables, introduced 0 case distinctions, treesize of input 6 treesize of output 5 [2018-01-24 16:39:47,948 INFO L267 ElimStorePlain]: Start of recursive call 2: End of recursive call: and 1 xjuncts. [2018-01-24 16:39:47,955 INFO L477 Elim1Store]: Elim1 did not use preprocessing eliminated variable of array dimension 1, 1 stores, 0 select indices, 0 select index equivalence classes, 0 disjoint index pairs (out of 0 index pairs), introduced 0 new quantified variables, introduced 0 case distinctions, treesize of input 6 treesize of output 5 [2018-01-24 16:39:47,956 INFO L267 ElimStorePlain]: Start of recursive call 3: End of recursive call: and 1 xjuncts. [2018-01-24 16:39:47,962 INFO L267 ElimStorePlain]: Start of recursive call 1: 2 dim-1 vars, End of recursive call: and 1 xjuncts. [2018-01-24 16:39:47,963 INFO L202 ElimStorePlain]: Needed 3 recursive calls to eliminate 2 variables, input treesize:16, output treesize:14 [2018-01-24 16:39:48,245 WARN L1029 $PredicateComparison]: unable to prove that (exists ((|build_nondet_String_#t~malloc1.base| Int) (build_nondet_String_~length~4 Int)) (and (= (store |c_old(#length)| |build_nondet_String_#t~malloc1.base| build_nondet_String_~length~4) |c_#length|) (= 0 (select |c_old(#valid)| |build_nondet_String_#t~malloc1.base|)))) is different from true [2018-01-24 16:39:48,255 INFO L700 Elim1Store]: detected not equals via solver [2018-01-24 16:39:48,257 INFO L477 Elim1Store]: Elim1 did not use preprocessing eliminated variable of array dimension 1, 1 stores, 1 select indices, 1 select index equivalence classes, 1 disjoint index pairs (out of 0 index pairs), introduced 0 new quantified variables, introduced 0 case distinctions, treesize of input 12 treesize of output 15 [2018-01-24 16:39:48,257 INFO L267 ElimStorePlain]: Start of recursive call 2: End of recursive call: and 1 xjuncts. [2018-01-24 16:39:48,265 INFO L700 Elim1Store]: detected not equals via solver [2018-01-24 16:39:48,266 INFO L700 Elim1Store]: detected not equals via solver [2018-01-24 16:39:48,266 INFO L477 Elim1Store]: Elim1 did not use preprocessing eliminated variable of array dimension 1, 0 stores, 2 select indices, 2 select index equivalence classes, 2 disjoint index pairs (out of 1 index pairs), introduced 0 new quantified variables, introduced 0 case distinctions, treesize of input 11 treesize of output 4 [2018-01-24 16:39:48,266 INFO L267 ElimStorePlain]: Start of recursive call 3: End of recursive call: and 1 xjuncts. [2018-01-24 16:39:48,271 INFO L267 ElimStorePlain]: Start of recursive call 1: 2 dim-0 vars, 2 dim-1 vars, End of recursive call: and 1 xjuncts. [2018-01-24 16:39:48,271 INFO L202 ElimStorePlain]: Needed 3 recursive calls to eliminate 4 variables, input treesize:25, output treesize:9 [2018-01-24 16:39:48,289 INFO L134 CoverageAnalysis]: Checked inductivity of 8 backedges. 2 proven. 1 refuted. 0 times theorem prover too weak. 0 trivial. 5 not checked. [2018-01-24 16:39:48,289 INFO L314 TraceCheckSpWp]: Computing backward predicates... [2018-01-24 16:39:48,378 WARN L130 XnfTransformerHelper]: expecting exponential blowup for input size 27 [2018-01-24 16:39:48,995 INFO L477 Elim1Store]: Elim1 did not use preprocessing eliminated variable of array dimension 1, 0 stores, 1 select indices, 1 select index equivalence classes, 1 disjoint index pairs (out of 0 index pairs), introduced 0 new quantified variables, introduced 0 case distinctions, treesize of input 10 treesize of output 3 [2018-01-24 16:39:48,995 INFO L267 ElimStorePlain]: Start of recursive call 2: End of recursive call: and 1 xjuncts. [2018-01-24 16:39:48,999 INFO L477 Elim1Store]: Elim1 did not use preprocessing eliminated variable of array dimension 1, 1 stores, 0 select indices, 0 select index equivalence classes, 1 disjoint index pairs (out of 0 index pairs), introduced 1 new quantified variables, introduced 0 case distinctions, treesize of input 11 treesize of output 15 [2018-01-24 16:39:49,007 WARN L307 Elim1Store]: Array PQE input equivalent to true [2018-01-24 16:39:49,007 INFO L267 ElimStorePlain]: Start of recursive call 4: End of recursive call: and 1 xjuncts. [2018-01-24 16:39:49,008 INFO L477 Elim1Store]: Elim1 did not use preprocessing eliminated variable of array dimension 1, 0 stores, 1 select indices, 1 select index equivalence classes, 1 disjoint index pairs (out of 0 index pairs), introduced 0 new quantified variables, introduced 0 case distinctions, treesize of input 12 treesize of output 3 [2018-01-24 16:39:49,009 INFO L267 ElimStorePlain]: Start of recursive call 5: End of recursive call: and 1 xjuncts. [2018-01-24 16:39:49,011 INFO L267 ElimStorePlain]: Start of recursive call 3: 1 dim-1 vars, End of recursive call: and 1 xjuncts. [2018-01-24 16:39:49,016 INFO L267 ElimStorePlain]: Start of recursive call 1: 3 dim-0 vars, 2 dim-1 vars, End of recursive call: and 1 xjuncts. [2018-01-24 16:39:49,016 INFO L202 ElimStorePlain]: Needed 5 recursive calls to eliminate 5 variables, input treesize:21, output treesize:3 [2018-01-24 16:39:49,022 INFO L134 CoverageAnalysis]: Checked inductivity of 8 backedges. 2 proven. 6 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2018-01-24 16:39:49,024 INFO L320 seRefinementStrategy]: Constructing automaton from 0 perfect and 5 imperfect interpolant sequences. [2018-01-24 16:39:49,024 INFO L335 seRefinementStrategy]: Number of different interpolants: perfect sequences [] imperfect sequences [14, 14, 13, 12, 12] total 50 [2018-01-24 16:39:49,024 INFO L247 anRefinementStrategy]: Using the first two imperfect interpolant sequences [2018-01-24 16:39:49,024 INFO L409 AbstractCegarLoop]: Interpolant automaton has 28 states [2018-01-24 16:39:49,025 INFO L132 InterpolantAutomaton]: Constructing interpolant automaton starting with 28 interpolants. [2018-01-24 16:39:49,026 INFO L133 InterpolantAutomaton]: CoverageRelationStatistics Valid=170, Invalid=2186, Unknown=4, NotChecked=190, Total=2550 [2018-01-24 16:39:49,026 INFO L87 Difference]: Start difference. First operand 57 states and 62 transitions. Second operand 28 states. [2018-01-24 16:39:50,419 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2018-01-24 16:39:50,419 INFO L93 Difference]: Finished difference Result 155 states and 177 transitions. [2018-01-24 16:39:50,420 INFO L142 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 24 states. [2018-01-24 16:39:50,420 INFO L78 Accepts]: Start accepts. Automaton has 28 states. Word has length 29 [2018-01-24 16:39:50,420 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2018-01-24 16:39:50,423 INFO L225 Difference]: With dead ends: 155 [2018-01-24 16:39:50,424 INFO L226 Difference]: Without dead ends: 152 [2018-01-24 16:39:50,426 INFO L525 BasicCegarLoop]: 0 DeclaredPredicates, 146 GetRequests, 75 SyntacticMatches, 4 SemanticMatches, 67 ConstructedPredicates, 2 IntricatePredicates, 0 DeprecatedPredicates, 1024 ImplicationChecksByTransitivity, 2.4s TimeCoverageRelationStatistics Valid=427, Invalid=3999, Unknown=4, NotChecked=262, Total=4692 [2018-01-24 16:39:50,426 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 152 states. [2018-01-24 16:39:50,436 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 152 to 60. [2018-01-24 16:39:50,436 INFO L82 GeneralOperation]: Start removeUnreachable. Operand 60 states. [2018-01-24 16:39:50,438 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 60 states to 60 states and 66 transitions. [2018-01-24 16:39:50,438 INFO L78 Accepts]: Start accepts. Automaton has 60 states and 66 transitions. Word has length 29 [2018-01-24 16:39:50,438 INFO L84 Accepts]: Finished accepts. word is rejected. [2018-01-24 16:39:50,438 INFO L432 AbstractCegarLoop]: Abstraction has 60 states and 66 transitions. [2018-01-24 16:39:50,439 INFO L433 AbstractCegarLoop]: Interpolant automaton has 28 states. [2018-01-24 16:39:50,439 INFO L276 IsEmpty]: Start isEmpty. Operand 60 states and 66 transitions. [2018-01-24 16:39:50,440 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 35 [2018-01-24 16:39:50,440 INFO L314 BasicCegarLoop]: Found error trace [2018-01-24 16:39:50,440 INFO L322 BasicCegarLoop]: trace histogram [2, 2, 2, 2, 2, 2, 2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2018-01-24 16:39:50,440 INFO L371 AbstractCegarLoop]: === Iteration 5 === [build_nondet_StringErr0RequiresViolation, build_nondet_StringErr1RequiresViolation, cstrpbrkErr3RequiresViolation, cstrpbrkErr1RequiresViolation, cstrpbrkErr9RequiresViolation, cstrpbrkErr7RequiresViolation, cstrpbrkErr2RequiresViolation, cstrpbrkErr8RequiresViolation, cstrpbrkErr4RequiresViolation, cstrpbrkErr0RequiresViolation, cstrpbrkErr6RequiresViolation, cstrpbrkErr5RequiresViolation, mainErr5RequiresViolation, mainErr3RequiresViolation, mainErr1RequiresViolation, mainErr2RequiresViolation, mainErr4RequiresViolation, mainErr6EnsuresViolation, mainErr0RequiresViolation]=== [2018-01-24 16:39:50,440 INFO L82 PathProgramCache]: Analyzing trace with hash -464489331, now seen corresponding path program 1 times [2018-01-24 16:39:50,440 INFO L67 tionRefinementEngine]: Using refinement strategy TaipanRefinementStrategy [2018-01-24 16:39:50,441 INFO L117 rtionOrderModulation]: Craig nested/tree interpolation forces the following order [2018-01-24 16:39:50,442 INFO L101 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2018-01-24 16:39:50,442 INFO L117 rtionOrderModulation]: Craig nested/tree interpolation forces the following order [2018-01-24 16:39:50,442 INFO L280 anRefinementStrategy]: Using traceCheck mode SMTINTERPOL with AssertCodeBlockOrder NOT_INCREMENTALLY (IT: Craig_TreeInterpolation) [2018-01-24 16:39:50,472 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is sat [2018-01-24 16:39:50,493 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is sat [2018-01-24 16:39:50,512 INFO L381 BasicCegarLoop]: Counterexample might be feasible [2018-01-24 16:39:50,544 INFO L202 PluginConnector]: Adding new model de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction CFG 24.01 04:39:50 BoogieIcfgContainer [2018-01-24 16:39:50,544 INFO L132 PluginConnector]: ------------------------ END TraceAbstraction---------------------------- [2018-01-24 16:39:50,545 INFO L168 Benchmark]: Toolchain (without parser) took 6758.91 ms. Allocated memory was 301.5 MB in the beginning and 544.2 MB in the end (delta: 242.7 MB). Free memory was 261.5 MB in the beginning and 510.4 MB in the end (delta: -248.9 MB). There was no memory consumed. Max. memory is 5.3 GB. [2018-01-24 16:39:50,545 INFO L168 Benchmark]: CDTParser took 0.20 ms. Allocated memory is still 301.5 MB. Free memory is still 267.5 MB. There was no memory consumed. Max. memory is 5.3 GB. [2018-01-24 16:39:50,545 INFO L168 Benchmark]: CACSL2BoogieTranslator took 213.98 ms. Allocated memory is still 301.5 MB. Free memory was 260.5 MB in the beginning and 250.3 MB in the end (delta: 10.2 MB). Peak memory consumption was 10.2 MB. Max. memory is 5.3 GB. [2018-01-24 16:39:50,545 INFO L168 Benchmark]: Boogie Preprocessor took 37.55 ms. Allocated memory is still 301.5 MB. Free memory was 250.3 MB in the beginning and 248.3 MB in the end (delta: 2.0 MB). Peak memory consumption was 2.0 MB. Max. memory is 5.3 GB. [2018-01-24 16:39:50,546 INFO L168 Benchmark]: RCFGBuilder took 349.55 ms. Allocated memory is still 301.5 MB. Free memory was 248.3 MB in the beginning and 227.7 MB in the end (delta: 20.6 MB). Peak memory consumption was 20.6 MB. Max. memory is 5.3 GB. [2018-01-24 16:39:50,546 INFO L168 Benchmark]: TraceAbstraction took 6149.98 ms. Allocated memory was 301.5 MB in the beginning and 544.2 MB in the end (delta: 242.7 MB). Free memory was 227.7 MB in the beginning and 510.4 MB in the end (delta: -282.7 MB). There was no memory consumed. Max. memory is 5.3 GB. [2018-01-24 16:39:50,548 INFO L344 ainManager$Toolchain]: ####################### End [Toolchain 1] ####################### --- Results --- * Results from de.uni_freiburg.informatik.ultimate.core: - StatisticsResult: Toolchain Benchmarks Benchmark results are: * CDTParser took 0.20 ms. Allocated memory is still 301.5 MB. Free memory is still 267.5 MB. There was no memory consumed. Max. memory is 5.3 GB. * CACSL2BoogieTranslator took 213.98 ms. Allocated memory is still 301.5 MB. Free memory was 260.5 MB in the beginning and 250.3 MB in the end (delta: 10.2 MB). Peak memory consumption was 10.2 MB. Max. memory is 5.3 GB. * Boogie Preprocessor took 37.55 ms. Allocated memory is still 301.5 MB. Free memory was 250.3 MB in the beginning and 248.3 MB in the end (delta: 2.0 MB). Peak memory consumption was 2.0 MB. Max. memory is 5.3 GB. * RCFGBuilder took 349.55 ms. Allocated memory is still 301.5 MB. Free memory was 248.3 MB in the beginning and 227.7 MB in the end (delta: 20.6 MB). Peak memory consumption was 20.6 MB. Max. memory is 5.3 GB. * TraceAbstraction took 6149.98 ms. Allocated memory was 301.5 MB in the beginning and 544.2 MB in the end (delta: 242.7 MB). Free memory was 227.7 MB in the beginning and 510.4 MB in the end (delta: -282.7 MB). There was no memory consumed. Max. memory is 5.3 GB. * Results from de.uni_freiburg.informatik.ultimate.plugins.analysis.abstractinterpretationv2: - StatisticsResult: ArrayEqualityDomainStatistics #Locations : 21 LocStat_MAX_WEQGRAPH_SIZE : 0 LocStat_MAX_SIZEOF_WEQEDGELABEL : 0 LocStat_NO_SUPPORTING_EQUALITIES : 153 LocStat_NO_SUPPORTING_DISEQUALITIES : 36 LocStat_NO_DISJUNCTIONS : -42 LocStat_MAX_NO_DISJUNCTIONS : -1 #Transitions : 30 TransStat_MAX_WEQGRAPH_SIZE : 0 TransStat_MAX_SIZEOF_WEQEDGELABEL : 0 TransStat_NO_SUPPORTING_EQUALITIES : 51 TransStat_NO_SUPPORTING_DISEQUALITIES : 3 TransStat_NO_DISJUNCTIONS : 30 TransStat_MAX_NO_DISJUNCTIONS : 1 - StatisticsResult: EqConstraintFactoryStatistics CONJOIN_DISJUNCTIVE(MILLISECONDS) : 0.812396 RENAME_VARIABLES(MILLISECONDS) : 0.242776 UNFREEZE(MILLISECONDS) : 0.000000 CONJOIN(MILLISECONDS) : 0.753614 PROJECTAWAY(MILLISECONDS) : 0.184296 ADD_WEAK_EQUALITY(MILLISECONDS) : 0.001722 DISJOIN(MILLISECONDS) : 0.345023 RENAME_VARIABLES_DISJUNCTIVE(MILLISECONDS) : 0.340779 ADD_EQUALITY(MILLISECONDS) : 0.037793 DISJOIN_DISJUNCTIVE(MILLISECONDS) : 0.000000 ADD_DISEQUALITY(MILLISECONDS) : 0.048724 #CONJOIN_DISJUNCTIVE : 48 #RENAME_VARIABLES : 77 #UNFREEZE : 0 #CONJOIN : 90 #PROJECTAWAY : 73 #ADD_WEAK_EQUALITY : 5 #DISJOIN : 8 #RENAME_VARIABLES_DISJUNCTIVE : 77 #ADD_EQUALITY : 52 #DISJOIN_DISJUNCTIVE : 0 #ADD_DISEQUALITY : 2 - StatisticsResult: ArrayEqualityDomainStatistics #Locations : 21 LocStat_MAX_WEQGRAPH_SIZE : 0 LocStat_MAX_SIZEOF_WEQEDGELABEL : 0 LocStat_NO_SUPPORTING_EQUALITIES : 153 LocStat_NO_SUPPORTING_DISEQUALITIES : 35 LocStat_NO_DISJUNCTIONS : -42 LocStat_MAX_NO_DISJUNCTIONS : -1 #Transitions : 30 TransStat_MAX_WEQGRAPH_SIZE : 0 TransStat_MAX_SIZEOF_WEQEDGELABEL : 0 TransStat_NO_SUPPORTING_EQUALITIES : 53 TransStat_NO_SUPPORTING_DISEQUALITIES : 2 TransStat_NO_DISJUNCTIONS : 31 TransStat_MAX_NO_DISJUNCTIONS : 2 - StatisticsResult: EqConstraintFactoryStatistics CONJOIN_DISJUNCTIVE(MILLISECONDS) : 0.855768 RENAME_VARIABLES(MILLISECONDS) : 0.182528 UNFREEZE(MILLISECONDS) : 0.000000 CONJOIN(MILLISECONDS) : 0.347475 PROJECTAWAY(MILLISECONDS) : 0.083023 ADD_WEAK_EQUALITY(MILLISECONDS) : 0.001425 DISJOIN(MILLISECONDS) : 0.243870 RENAME_VARIABLES_DISJUNCTIVE(MILLISECONDS) : 0.216465 ADD_EQUALITY(MILLISECONDS) : 0.032998 DISJOIN_DISJUNCTIVE(MILLISECONDS) : 0.000000 ADD_DISEQUALITY(MILLISECONDS) : 0.020077 #CONJOIN_DISJUNCTIVE : 48 #RENAME_VARIABLES : 78 #UNFREEZE : 0 #CONJOIN : 91 #PROJECTAWAY : 75 #ADD_WEAK_EQUALITY : 5 #DISJOIN : 9 #RENAME_VARIABLES_DISJUNCTIVE : 77 #ADD_EQUALITY : 54 #DISJOIN_DISJUNCTIVE : 0 #ADD_DISEQUALITY : 1 * Results from de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction: - CounterExampleResult [Line: 1]: pointer dereference may fail pointer dereference may fail We found a FailurePath: [L565] CALL, EXPR build_nondet_String() [L541] int length = __VERIFIER_nondet_int(); [L542] COND TRUE length < 1 [L543] length = 1 VAL [length=1] [L545] EXPR, FCALL malloc(length * sizeof(char)) VAL [length=1, malloc(length * sizeof(char))={3:0}] [L545] char* nondetString = (char*) malloc(length * sizeof(char)); VAL [length=1, malloc(length * sizeof(char))={3:0}, nondetString={3:0}] [L546] FCALL nondetString[length-1] = '\0' VAL [length=1, malloc(length * sizeof(char))={3:0}, nondetString={3:0}] [L547] RET return nondetString; VAL [\result={3:0}, length=1, malloc(length * sizeof(char))={3:0}, nondetString={3:0}] [L565] EXPR build_nondet_String() VAL [build_nondet_String()={3:0}] [L565] char* s1 = build_nondet_String(); [L566] CALL, EXPR build_nondet_String() [L541] int length = __VERIFIER_nondet_int(); [L542] COND TRUE length < 1 [L543] length = 1 VAL [length=1] [L545] EXPR, FCALL malloc(length * sizeof(char)) VAL [length=1, malloc(length * sizeof(char))={5:0}] [L545] char* nondetString = (char*) malloc(length * sizeof(char)); VAL [length=1, malloc(length * sizeof(char))={5:0}, nondetString={5:0}] [L546] FCALL nondetString[length-1] = '\0' VAL [length=1, malloc(length * sizeof(char))={5:0}, nondetString={5:0}] [L547] RET return nondetString; VAL [\result={5:0}, length=1, malloc(length * sizeof(char))={5:0}, nondetString={5:0}] [L566] EXPR build_nondet_String() VAL [build_nondet_String()={5:0}, s1={3:0}] [L566] char* s2 = build_nondet_String(); [L567] CALL cstrpbrk(s1,s2) VAL [s1={3:0}, s2={5:0}] [L551] const char *sc1; [L552] const char *s; [L553] int c; [L554] sc1 = s1 VAL [s1={3:0}, s1={3:0}, s2={5:0}, s2={5:0}, sc1={3:0}] [L554] EXPR, FCALL \read(*sc1) VAL [\read(*sc1)=0, s1={3:0}, s1={3:0}, s2={5:0}, s2={5:0}, sc1={3:0}] [L554] COND FALSE !(*sc1 != '\0') [L562] RET return 0; VAL [\result={0:0}, s1={3:0}, s1={3:0}, s2={5:0}, s2={5:0}, sc1={3:0}] [L567] cstrpbrk(s1,s2) VAL [cstrpbrk(s1,s2)={0:0}, s1={3:0}, s2={5:0}] [L567] FCALL cstrpbrk(s1,s2) VAL [cstrpbrk(s1,s2)={0:0}, s1={3:0}, s2={5:0}] - StatisticsResult: Ultimate Automizer benchmark data CFG has 5 procedures, 65 locations, 19 error locations. UNSAFE Result, 6.0s OverallTime, 5 OverallIterations, 2 TraceHistogramMax, 1.9s AutomataDifference, 0.0s DeadEndRemovalTime, 0.0s HoareAnnotationTime, HoareTripleCheckerStatistics: 199 SDtfs, 620 SDslu, 510 SDs, 0 SdLazy, 1287 SolverSat, 59 SolverUnsat, 0 SolverUnknown, 0 SolverNotchecked, 0.7s Time, PredicateUnifierStatistics: 0 DeclaredPredicates, 290 GetRequests, 168 SyntacticMatches, 23 SemanticMatches, 99 ConstructedPredicates, 3 IntricatePredicates, 0 DeprecatedPredicates, 1165 ImplicationChecksByTransitivity, 3.1s Time, 0.0s BasicInterpolantAutomatonTime, BiggestAbstraction: size=65occurred in iteration=0, traceCheckStatistics: No data available, InterpolantConsolidationStatistics: No data available, PathInvariantsStatistics: No data available, 0/0 InterpolantCoveringCapability, TotalInterpolationStatistics: No data available, 0.3s AbstIntTime, 2 AbstIntIterations, 0 AbstIntStrong, NaN AbsIntWeakeningRatio, NaN AbsIntAvgWeakeningVarsNumRemoved, NaN AbsIntAvgWeakenedConjuncts, AutomataMinimizationStatistics: 0.0s AutomataMinimizationTime, 4 MinimizatonAttempts, 95 StatesRemovedByMinimization, 2 NontrivialMinimizations, HoareAnnotationStatistics: No data available, RefinementEngineStatistics: TraceCheckStatistics: 0.0s SsaConstructionTime, 0.2s SatisfiabilityAnalysisTime, 3.1s InterpolantComputationTime, 230 NumberOfCodeBlocks, 230 NumberOfCodeBlocksAsserted, 9 NumberOfCheckSat, 300 ConstructedInterpolants, 56 QuantifiedInterpolants, 65396 SizeOfPredicates, 39 NumberOfNonLiveVariables, 548 ConjunctsInSsa, 123 ConjunctsInUnsatCore, 12 InterpolantComputations, 2 PerfectInterpolantSequences, 32/80 InterpolantCoveringCapability, InvariantSynthesisStatistics: No data available, InterpolantConsolidationStatistics: No data available, REUSE_STATISTICS: No data available RESULT: Ultimate proved your program to be incorrect! Written .csv to /storage/ultimate/releaseScripts/default/UAutomizer-linux/../../../releaseScripts/default/UAutomizer-linux/csv/cstrpbrk_unsafe_false-valid-deref.i_svcomp-DerefFreeMemtrack-32bit-Automizer_Taipan+AI_EQ_imprecise.epf_AutomizerC.xml/Csv-Benchmark-0-2018-01-24_16-39-50-557.csv Written .csv to /storage/ultimate/releaseScripts/default/UAutomizer-linux/../../../releaseScripts/default/UAutomizer-linux/csv/cstrpbrk_unsafe_false-valid-deref.i_svcomp-DerefFreeMemtrack-32bit-Automizer_Taipan+AI_EQ_imprecise.epf_AutomizerC.xml/Csv-VPDomainBenchmark-0-2018-01-24_16-39-50-557.csv Written .csv to /storage/ultimate/releaseScripts/default/UAutomizer-linux/../../../releaseScripts/default/UAutomizer-linux/csv/cstrpbrk_unsafe_false-valid-deref.i_svcomp-DerefFreeMemtrack-32bit-Automizer_Taipan+AI_EQ_imprecise.epf_AutomizerC.xml/Csv-BenchmarkWithCounters-0-2018-01-24_16-39-50-557.csv Written .csv to /storage/ultimate/releaseScripts/default/UAutomizer-linux/../../../releaseScripts/default/UAutomizer-linux/csv/cstrpbrk_unsafe_false-valid-deref.i_svcomp-DerefFreeMemtrack-32bit-Automizer_Taipan+AI_EQ_imprecise.epf_AutomizerC.xml/Csv-VPDomainBenchmark-1-2018-01-24_16-39-50-557.csv Written .csv to /storage/ultimate/releaseScripts/default/UAutomizer-linux/../../../releaseScripts/default/UAutomizer-linux/csv/cstrpbrk_unsafe_false-valid-deref.i_svcomp-DerefFreeMemtrack-32bit-Automizer_Taipan+AI_EQ_imprecise.epf_AutomizerC.xml/Csv-BenchmarkWithCounters-1-2018-01-24_16-39-50-557.csv Written .csv to /storage/ultimate/releaseScripts/default/UAutomizer-linux/../../../releaseScripts/default/UAutomizer-linux/csv/cstrpbrk_unsafe_false-valid-deref.i_svcomp-DerefFreeMemtrack-32bit-Automizer_Taipan+AI_EQ_imprecise.epf_AutomizerC.xml/Csv-TraceAbstractionBenchmarks-0-2018-01-24_16-39-50-557.csv Received shutdown request...