java -ea -Xmx8000000000 -Xss4m -jar ./plugins/org.eclipse.equinox.launcher_1.3.100.v20150511-1540.jar -data @noDefault -ultimatedata ./data -tc ../../../trunk/examples/toolchains/AbstractInterpretationInline.xml -s ../../../trunk/examples/settings/ai/array-bench/reach_32bit_array_oct.epf -i ../../../trunk/examples/programs/toy/tooDifficultLoopInvariant/PointerIncrement-simplified01.bpl -------------------------------------------------------------------------------- This is Ultimate 0.1.24-1377b90 [2019-01-07 16:15:03,278 INFO L170 SettingsManager]: Resetting all preferences to default values... [2019-01-07 16:15:03,281 INFO L174 SettingsManager]: Resetting UltimateCore preferences to default values [2019-01-07 16:15:03,297 INFO L177 SettingsManager]: Ultimate Commandline Interface provides no preferences, ignoring... [2019-01-07 16:15:03,298 INFO L174 SettingsManager]: Resetting Boogie Preprocessor preferences to default values [2019-01-07 16:15:03,299 INFO L174 SettingsManager]: Resetting Boogie Procedure Inliner preferences to default values [2019-01-07 16:15:03,300 INFO L174 SettingsManager]: Resetting Abstract Interpretation preferences to default values [2019-01-07 16:15:03,302 INFO L174 SettingsManager]: Resetting LassoRanker preferences to default values [2019-01-07 16:15:03,303 INFO L174 SettingsManager]: Resetting Reaching Definitions preferences to default values [2019-01-07 16:15:03,304 INFO L174 SettingsManager]: Resetting SyntaxChecker preferences to default values [2019-01-07 16:15:03,306 INFO L177 SettingsManager]: Büchi Program Product provides no preferences, ignoring... [2019-01-07 16:15:03,306 INFO L174 SettingsManager]: Resetting LTL2Aut preferences to default values [2019-01-07 16:15:03,307 INFO L174 SettingsManager]: Resetting PEA to Boogie preferences to default values [2019-01-07 16:15:03,308 INFO L174 SettingsManager]: Resetting BlockEncodingV2 preferences to default values [2019-01-07 16:15:03,309 INFO L174 SettingsManager]: Resetting ChcToBoogie preferences to default values [2019-01-07 16:15:03,310 INFO L174 SettingsManager]: Resetting AutomataScriptInterpreter preferences to default values [2019-01-07 16:15:03,311 INFO L174 SettingsManager]: Resetting BuchiAutomizer preferences to default values [2019-01-07 16:15:03,312 INFO L174 SettingsManager]: Resetting CACSL2BoogieTranslator preferences to default values [2019-01-07 16:15:03,314 INFO L174 SettingsManager]: Resetting CodeCheck preferences to default values [2019-01-07 16:15:03,316 INFO L174 SettingsManager]: Resetting InvariantSynthesis preferences to default values [2019-01-07 16:15:03,317 INFO L174 SettingsManager]: Resetting RCFGBuilder preferences to default values [2019-01-07 16:15:03,318 INFO L174 SettingsManager]: Resetting TraceAbstraction preferences to default values [2019-01-07 16:15:03,321 INFO L177 SettingsManager]: TraceAbstractionConcurrent provides no preferences, ignoring... [2019-01-07 16:15:03,321 INFO L177 SettingsManager]: TraceAbstractionWithAFAs provides no preferences, ignoring... [2019-01-07 16:15:03,321 INFO L174 SettingsManager]: Resetting TreeAutomizer preferences to default values [2019-01-07 16:15:03,322 INFO L174 SettingsManager]: Resetting IcfgTransformer preferences to default values [2019-01-07 16:15:03,323 INFO L174 SettingsManager]: Resetting Boogie Printer preferences to default values [2019-01-07 16:15:03,324 INFO L174 SettingsManager]: Resetting ReqPrinter preferences to default values [2019-01-07 16:15:03,325 INFO L174 SettingsManager]: Resetting Witness Printer preferences to default values [2019-01-07 16:15:03,326 INFO L177 SettingsManager]: Boogie PL CUP Parser provides no preferences, ignoring... [2019-01-07 16:15:03,326 INFO L174 SettingsManager]: Resetting CDTParser preferences to default values [2019-01-07 16:15:03,327 INFO L177 SettingsManager]: AutomataScriptParser provides no preferences, ignoring... [2019-01-07 16:15:03,327 INFO L177 SettingsManager]: ReqParser provides no preferences, ignoring... [2019-01-07 16:15:03,327 INFO L174 SettingsManager]: Resetting SmtParser preferences to default values [2019-01-07 16:15:03,328 INFO L174 SettingsManager]: Resetting Witness Parser preferences to default values [2019-01-07 16:15:03,329 INFO L181 SettingsManager]: Finished resetting all preferences to default values... [2019-01-07 16:15:03,329 INFO L98 SettingsManager]: Beginning loading settings from /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/../../../trunk/examples/settings/ai/array-bench/reach_32bit_array_oct.epf [2019-01-07 16:15:03,348 INFO L110 SettingsManager]: Loading preferences was successful [2019-01-07 16:15:03,348 INFO L112 SettingsManager]: Preferences different from defaults after loading the file: [2019-01-07 16:15:03,349 INFO L131 SettingsManager]: Preferences of Boogie Preprocessor differ from their defaults: [2019-01-07 16:15:03,349 INFO L133 SettingsManager]: * Show backtranslation warnings=false [2019-01-07 16:15:03,350 INFO L131 SettingsManager]: Preferences of Boogie Procedure Inliner differ from their defaults: [2019-01-07 16:15:03,350 INFO L133 SettingsManager]: * User list type=DISABLED [2019-01-07 16:15:03,350 INFO L133 SettingsManager]: * Inline calls to unimplemented procedures=true [2019-01-07 16:15:03,350 INFO L131 SettingsManager]: Preferences of Abstract Interpretation differ from their defaults: [2019-01-07 16:15:03,350 INFO L133 SettingsManager]: * Abstract domain for RCFG-of-the-future=PoormanAbstractDomain [2019-01-07 16:15:03,351 INFO L133 SettingsManager]: * Underlying domain=OctagonDomain [2019-01-07 16:15:03,351 INFO L133 SettingsManager]: * Abstract domain=ArrayDomain [2019-01-07 16:15:03,351 INFO L133 SettingsManager]: * Check feasibility of abstract posts with an SMT solver=true [2019-01-07 16:15:03,351 INFO L133 SettingsManager]: * Interval Domain=false [2019-01-07 16:15:03,352 INFO L131 SettingsManager]: Preferences of BlockEncodingV2 differ from their defaults: [2019-01-07 16:15:03,352 INFO L133 SettingsManager]: * Create parallel compositions if possible=false [2019-01-07 16:15:03,352 INFO L133 SettingsManager]: * Use SBE=true [2019-01-07 16:15:03,352 INFO L131 SettingsManager]: Preferences of CACSL2BoogieTranslator differ from their defaults: [2019-01-07 16:15:03,353 INFO L133 SettingsManager]: * sizeof long=4 [2019-01-07 16:15:03,353 INFO L133 SettingsManager]: * Overapproximate operations on floating types=true [2019-01-07 16:15:03,353 INFO L133 SettingsManager]: * sizeof POINTER=4 [2019-01-07 16:15:03,353 INFO L133 SettingsManager]: * Check division by zero=IGNORE [2019-01-07 16:15:03,353 INFO L133 SettingsManager]: * Pointer to allocated memory at dereference=IGNORE [2019-01-07 16:15:03,353 INFO L133 SettingsManager]: * If two pointers are subtracted or compared they have the same base address=IGNORE [2019-01-07 16:15:03,354 INFO L133 SettingsManager]: * Check array bounds for arrays that are off heap=IGNORE [2019-01-07 16:15:03,354 INFO L133 SettingsManager]: * sizeof long double=12 [2019-01-07 16:15:03,354 INFO L133 SettingsManager]: * Check if freed pointer was valid=false [2019-01-07 16:15:03,354 INFO L133 SettingsManager]: * Pointer base address is valid at dereference=IGNORE [2019-01-07 16:15:03,354 INFO L131 SettingsManager]: Preferences of RCFGBuilder differ from their defaults: [2019-01-07 16:15:03,355 INFO L133 SettingsManager]: * Size of a code block=SequenceOfStatements [2019-01-07 16:15:03,355 INFO L133 SettingsManager]: * SMT solver=External_DefaultMode [2019-01-07 16:15:03,355 INFO L133 SettingsManager]: * Command for external solver=z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in -t:2000 [2019-01-07 16:15:03,355 INFO L131 SettingsManager]: Preferences of TraceAbstraction differ from their defaults: [2019-01-07 16:15:03,356 INFO L133 SettingsManager]: * Compute Interpolants along a Counterexample=FPandBP [2019-01-07 16:15:03,356 INFO L133 SettingsManager]: * Positions where we compute the Hoare Annotation=LoopsAndPotentialCycles [2019-01-07 16:15:03,356 INFO L133 SettingsManager]: * Trace refinement strategy=TAIPAN [2019-01-07 16:15:03,356 INFO L133 SettingsManager]: * SMT solver=External_ModelsAndUnsatCoreMode [2019-01-07 16:15:03,356 INFO L133 SettingsManager]: * Command for external solver=z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in [2019-01-07 16:15:03,356 INFO L133 SettingsManager]: * Compute Hoare Annotation of negated interpolant automaton, abstraction and CFG=true [2019-01-07 16:15:03,357 INFO L133 SettingsManager]: * Abstract interpretation Mode=USE_PREDICATES [2019-01-07 16:15:03,405 INFO L81 nceAwareModelManager]: Repository-Root is: /tmp [2019-01-07 16:15:03,421 INFO L258 ainManager$Toolchain]: [Toolchain 1]: Applicable parser(s) successfully (re)initialized [2019-01-07 16:15:03,424 INFO L214 ainManager$Toolchain]: [Toolchain 1]: Toolchain selected. [2019-01-07 16:15:03,426 INFO L271 PluginConnector]: Initializing Boogie PL CUP Parser... [2019-01-07 16:15:03,427 INFO L276 PluginConnector]: Boogie PL CUP Parser initialized [2019-01-07 16:15:03,427 INFO L418 ainManager$Toolchain]: [Toolchain 1]: Parsing single file: /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/../../../trunk/examples/programs/toy/tooDifficultLoopInvariant/PointerIncrement-simplified01.bpl [2019-01-07 16:15:03,428 INFO L111 BoogieParser]: Parsing: '/storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/../../../trunk/examples/programs/toy/tooDifficultLoopInvariant/PointerIncrement-simplified01.bpl' [2019-01-07 16:15:03,476 INFO L296 ainManager$Toolchain]: ####################### [Toolchain 1] ####################### [2019-01-07 16:15:03,479 INFO L131 ToolchainWalker]: Walking toolchain with 4 elements. [2019-01-07 16:15:03,480 INFO L113 PluginConnector]: ------------------------Boogie Procedure Inliner---------------------------- [2019-01-07 16:15:03,480 INFO L271 PluginConnector]: Initializing Boogie Procedure Inliner... [2019-01-07 16:15:03,480 INFO L276 PluginConnector]: Boogie Procedure Inliner initialized [2019-01-07 16:15:03,498 INFO L185 PluginConnector]: Executing the observer TypeChecker from plugin Boogie Procedure Inliner for "PointerIncrement-simplified01.bpl de.uni_freiburg.informatik.ultimate.boogie.parser AST 07.01 04:15:03" (1/1) ... [2019-01-07 16:15:03,512 INFO L185 PluginConnector]: Executing the observer Inliner from plugin Boogie Procedure Inliner for "PointerIncrement-simplified01.bpl de.uni_freiburg.informatik.ultimate.boogie.parser AST 07.01 04:15:03" (1/1) ... [2019-01-07 16:15:03,525 WARN L165 Inliner]: Program contained no entry procedure! [2019-01-07 16:15:03,525 WARN L168 Inliner]: Missing entry procedures: [ULTIMATE.start] [2019-01-07 16:15:03,526 WARN L175 Inliner]: Fallback enabled. All procedures will be processed. [2019-01-07 16:15:03,550 INFO L132 PluginConnector]: ------------------------ END Boogie Procedure Inliner---------------------------- [2019-01-07 16:15:03,551 INFO L113 PluginConnector]: ------------------------Boogie Preprocessor---------------------------- [2019-01-07 16:15:03,552 INFO L271 PluginConnector]: Initializing Boogie Preprocessor... [2019-01-07 16:15:03,552 INFO L276 PluginConnector]: Boogie Preprocessor initialized [2019-01-07 16:15:03,564 INFO L185 PluginConnector]: Executing the observer EnsureBoogieModelObserver from plugin Boogie Preprocessor for "PointerIncrement-simplified01.bpl de.uni_freiburg.informatik.ultimate.boogie.parser AST 07.01 04:15:03" (1/1) ... [2019-01-07 16:15:03,565 INFO L185 PluginConnector]: Executing the observer TypeChecker from plugin Boogie Preprocessor for "PointerIncrement-simplified01.bpl de.uni_freiburg.informatik.ultimate.boogie.parser AST 07.01 04:15:03" (1/1) ... [2019-01-07 16:15:03,566 INFO L185 PluginConnector]: Executing the observer ConstExpander from plugin Boogie Preprocessor for "PointerIncrement-simplified01.bpl de.uni_freiburg.informatik.ultimate.boogie.parser AST 07.01 04:15:03" (1/1) ... [2019-01-07 16:15:03,567 INFO L185 PluginConnector]: Executing the observer StructExpander from plugin Boogie Preprocessor for "PointerIncrement-simplified01.bpl de.uni_freiburg.informatik.ultimate.boogie.parser AST 07.01 04:15:03" (1/1) ... [2019-01-07 16:15:03,573 INFO L185 PluginConnector]: Executing the observer UnstructureCode from plugin Boogie Preprocessor for "PointerIncrement-simplified01.bpl de.uni_freiburg.informatik.ultimate.boogie.parser AST 07.01 04:15:03" (1/1) ... [2019-01-07 16:15:03,578 INFO L185 PluginConnector]: Executing the observer FunctionInliner from plugin Boogie Preprocessor for "PointerIncrement-simplified01.bpl de.uni_freiburg.informatik.ultimate.boogie.parser AST 07.01 04:15:03" (1/1) ... [2019-01-07 16:15:03,579 INFO L185 PluginConnector]: Executing the observer BoogieSymbolTableConstructor from plugin Boogie Preprocessor for "PointerIncrement-simplified01.bpl de.uni_freiburg.informatik.ultimate.boogie.parser AST 07.01 04:15:03" (1/1) ... [2019-01-07 16:15:03,581 INFO L132 PluginConnector]: ------------------------ END Boogie Preprocessor---------------------------- [2019-01-07 16:15:03,582 INFO L113 PluginConnector]: ------------------------RCFGBuilder---------------------------- [2019-01-07 16:15:03,582 INFO L271 PluginConnector]: Initializing RCFGBuilder... [2019-01-07 16:15:03,582 INFO L276 PluginConnector]: RCFGBuilder initialized [2019-01-07 16:15:03,583 INFO L185 PluginConnector]: Executing the observer RCFGBuilderObserver from plugin RCFGBuilder for "PointerIncrement-simplified01.bpl de.uni_freiburg.informatik.ultimate.boogie.parser AST 07.01 04:15:03" (1/1) ... No working directory specified, using /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 Starting monitored process 1 with z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in -t:2000 (exit command is (exit), workingDir is null) Waiting until toolchain timeout for monitored process 1 with z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in -t:2000 [2019-01-07 16:15:03,653 INFO L130 BoogieDeclarations]: Found specification of procedure read~int [2019-01-07 16:15:03,653 INFO L130 BoogieDeclarations]: Found specification of procedure main [2019-01-07 16:15:03,654 INFO L138 BoogieDeclarations]: Found implementation of procedure main [2019-01-07 16:15:03,654 INFO L130 BoogieDeclarations]: Found specification of procedure ~malloc [2019-01-07 16:15:04,232 INFO L278 CfgBuilder]: Using library mode [2019-01-07 16:15:04,232 INFO L286 CfgBuilder]: Removed 5 assue(true) statements. [2019-01-07 16:15:04,233 INFO L202 PluginConnector]: Adding new model PointerIncrement-simplified01.bpl de.uni_freiburg.informatik.ultimate.plugins.generator.rcfgbuilder CFG 07.01 04:15:04 BoogieIcfgContainer [2019-01-07 16:15:04,234 INFO L132 PluginConnector]: ------------------------ END RCFGBuilder---------------------------- [2019-01-07 16:15:04,234 INFO L113 PluginConnector]: ------------------------Abstract Interpretation---------------------------- [2019-01-07 16:15:04,235 INFO L271 PluginConnector]: Initializing Abstract Interpretation... [2019-01-07 16:15:04,235 INFO L276 PluginConnector]: Abstract Interpretation initialized [2019-01-07 16:15:04,236 INFO L185 PluginConnector]: Executing the observer AbstractInterpretationRcfgObserver from plugin Abstract Interpretation for "PointerIncrement-simplified01.bpl de.uni_freiburg.informatik.ultimate.plugins.generator.rcfgbuilder CFG 07.01 04:15:04" (1/1) ... [2019-01-07 16:15:04,296 INFO L101 FixpointEngine]: Starting fixpoint engine with domain ArrayDomain (maxUnwinding=3, maxParallelStates=2) [2019-01-07 16:15:05,328 WARN L212 ngHoareTripleChecker]: Soundness check inconclusive for the following hoare triple [2019-01-07 16:15:05,328 WARN L217 ngHoareTripleChecker]: Expected: VALID Actual: UNKNOWN [2019-01-07 16:15:05,330 WARN L219 ngHoareTripleChecker]: Solver was "Z3" in version "4.8.3" [2019-01-07 16:15:05,331 WARN L223 ngHoareTripleChecker]: -- [2019-01-07 16:15:05,331 WARN L224 ngHoareTripleChecker]: Pre: {2147483647#(forall ((v_idx_7 Int) (v_idx_8 Int) (v_idx_9 Int) (v_idx_3 Int) (v_idx_10 Int) (v_idx_4 Int) (v_idx_5 Int) (v_idx_6 Int) (v_idx_1 Int) (v_idx_2 Int)) (exists ((v_v_8_1 Int) (v_v_3_1 Bool) (v_v_4_1 Bool) (v_v_7_1 (Array Int Int)) (v_v_0_1 Int) (v_v_1_1 Int) (v_v_5_1 (Array Int Int)) (v_v_9_1 Bool) (v_v_2_1 Int) (v_v_6_1 Int)) (and (= v_v_1_1 (select |c_#length| v_idx_7)) (= (select |c_old(#valid)| v_idx_3) v_v_4_1) (= v_v_5_1 (select |c_#memory_int| v_idx_5)) (= v_v_7_1 (select |c_old(#memory_int)| v_idx_6)) (= v_v_0_1 (select |c_main_~malloc_old_#length| v_idx_1)) (= v_v_8_1 (select v_v_7_1 v_idx_4)) (= (select |c_#valid| v_idx_2) v_v_3_1) (= v_v_6_1 (select v_v_5_1 v_idx_9)) (= v_v_9_1 (select |c_main_~malloc_old_#valid| v_idx_10)) (= (select |c_old(#length)| v_idx_8) v_v_2_1))))} [2019-01-07 16:15:05,335 WARN L228 ngHoareTripleChecker]: Action: ~malloc_old_#length, ~malloc_old_#valid := #length, #valid;~malloc_~size := 400;havoc ~malloc_#res.base, ~malloc_#res.offset;havoc #valid, #length;assume ~malloc_old_#valid[~malloc_#res.base] == false;assume #valid == ~malloc_old_#valid[~malloc_#res.base := true];assume ~malloc_#res.offset == 0;assume ~malloc_#res.base != 0;assume #length == ~malloc_old_#length[~malloc_#res.base := ~malloc_~size];#t~malloc0.base, #t~malloc0.offset := ~malloc_#res.base, ~malloc_#res.offset;~p~1.base, ~p~1.offset := #t~malloc0.base, #t~malloc0.offset;~q~1.base, ~q~1.offset := ~p~1.base, ~p~1.offset; [2019-01-07 16:15:05,336 WARN L184 hOps$ForEachOp$OfRef]: ActionStr: (and (not (select |c_main_~malloc_old_#valid_primed| |c_main_~malloc_#res.base_primed|)) (= |c_main_#t~malloc0.offset_primed| |c_main_~malloc_#res.offset_primed|) (= (store |c_main_~malloc_old_#length_primed| |c_main_~malloc_#res.base_primed| c_main_~malloc_~size_primed) |c_#length_primed|) (= |c_main_~malloc_old_#valid_primed| |c_#valid|) (= |c_main_~malloc_old_#length_primed| |c_#length|) (= (store |c_main_~malloc_old_#valid_primed| |c_main_~malloc_#res.base_primed| true) |c_#valid_primed|) (= c_main_~q~1.offset_primed c_main_~p~1.offset_primed) (= 0 |c_main_~malloc_#res.offset_primed|) (= |c_main_#t~malloc0.base_primed| |c_main_~malloc_#res.base_primed|) (= c_main_~p~1.base_primed |c_main_#t~malloc0.base_primed|) (= c_main_~q~1.base_primed c_main_~p~1.base_primed) (= c_main_~malloc_~size_primed 400) (= c_main_~p~1.offset_primed |c_main_#t~malloc0.offset_primed|) (not (= |c_main_~malloc_#res.base_primed| 0))) [2019-01-07 16:15:05,338 WARN L230 ngHoareTripleChecker]: Post: {2147483646#(forall ((v_idx_14 Int) (v_idx_15 Int) (v_idx_23 Int) (v_idx_12 Int) (v_idx_24 Int) (v_idx_13 Int) (v_idx_21 Int) (v_idx_22 Int) (v_idx_11 Int) (v_idx_20 Int) (v_idx_18 Int) (v_idx_19 Int) (v_idx_16 Int) (v_idx_17 Int)) (exists ((v_v_24_1 Int) (v_v_25_1 Int) (v_b_4_1 Int) (v_b_5_1 Int) (v_b_8_1 Int) (v_b_9_1 Int) (v_v_4_1 Bool) (v_v_26_1 Int) (v_v_8_1 Int) (v_v_19_1 Bool) (v_v_18_1 Bool) (v_v_12_1 Bool) (v_v_7_1 (Array Int Int)) (v_v_1_1 Int) (v_v_5_1 (Array Int Int)) (v_v_2_1 Int) (v_v_6_1 Int) (v_v_20_1 Bool)) (and (<= (- (- |c_main_#t~malloc0.offset|) (- v_v_25_1)) 400) (<= (- (- |c_main_#t~malloc0.offset|) c_main_~q~1.offset) 0) (<= (- |c_main_#t~malloc0.offset| (- c_main_~malloc_~size)) 400) (= (select v_v_5_1 v_idx_23) v_v_6_1) (<= (- (- c_main_~malloc_~size) v_v_25_1) (- 800)) (<= (- (- c_main_~malloc_~size) (- c_main_~p~1.offset)) (- 400)) (<= (- (- |c_main_~malloc_#res.offset|) (- c_main_~q~1.offset)) 0) (= v_b_9_1 (+ v_b_8_1 1)) (<= (- |c_main_#t~malloc0.offset| (- |c_main_~malloc_#res.offset|)) 0) (<= (- (- |c_main_~malloc_#res.offset|) c_main_~malloc_~size) (- 400)) v_v_19_1 (<= (- (- v_b_4_1) (- |c_main_~malloc_#res.base|)) 0) (or (= (select |c_#length| v_idx_20) v_v_24_1) (<= v_b_8_1 v_idx_20)) (<= (- (- c_main_~q~1.offset) (- v_v_25_1)) 400) (<= (- (- c_main_~malloc_~size) c_main_~p~1.offset) (- 400)) (<= (- (- |c_main_~malloc_#res.offset|) (- c_main_~p~1.offset)) 0) (= v_v_5_1 (select |c_#memory_int| v_idx_17)) (<= (- (- v_b_5_1) (- |c_main_~malloc_#res.base|)) (- 1)) (<= (- (- v_b_9_1) (- |c_main_~malloc_#res.base|)) (- 1)) (<= (- (- |c_main_#t~malloc0.offset|) c_main_~p~1.offset) 0) (<= (- v_b_8_1 v_b_9_1) (- 1)) (<= (- (- |c_main_~malloc_#res.offset|) (- c_main_~malloc_~size)) 400) (<= (- v_b_9_1 |c_main_~malloc_#res.base|) 1) (<= (- |c_main_~malloc_#res.offset| (- v_v_25_1)) 400) (= (+ v_b_8_1 1) (+ v_b_4_1 1)) (= (select |c_main_~malloc_old_#valid| v_idx_24) v_v_12_1) (= (select |c_old(#length)| v_idx_19) v_v_2_1) (or (< v_idx_21 v_b_8_1) (= (select |c_#length| v_idx_21) v_v_25_1) (<= v_b_9_1 v_idx_21)) (<= (- (- c_main_~p~1.offset) v_v_25_1) (- 400)) (<= (- v_b_8_1 |c_main_~malloc_#res.base|) 0) (<= (- c_main_~malloc_~size (- c_main_~p~1.offset)) 400) (= v_b_5_1 (+ v_b_8_1 1)) (<= (- |c_main_#t~malloc0.offset| |c_main_~malloc_#res.offset|) 0) (= (+ v_b_5_1 (- 1)) (+ v_b_9_1 (- 1))) (<= (- |c_main_#t~malloc0.offset| (- c_main_~p~1.offset)) 0) (<= (- |c_main_~malloc_#res.offset| (- c_main_~q~1.offset)) 0) (= |c_main_~malloc_#res.base| (+ v_b_9_1 (- 1))) (<= (- |c_main_#t~malloc0.offset| (- |c_main_#t~malloc0.offset|)) 0) (<= (- v_v_25_1 (- v_v_25_1)) 800) (= (+ v_b_9_1 (- 1)) v_b_8_1) (<= (- c_main_~malloc_~size (- c_main_~malloc_~size)) 800) (<= (- |c_main_#t~malloc0.offset| (- v_v_25_1)) 400) (or (= (select |c_#valid| v_idx_15) v_v_19_1) (< v_idx_15 v_b_4_1) (<= v_b_5_1 v_idx_15)) (<= (- (- |c_main_#t~malloc0.offset|) (- c_main_~p~1.offset)) 0) (<= (- |c_main_#t~malloc0.offset| c_main_~p~1.offset) 0) (<= (- (- v_v_25_1) v_v_25_1) (- 800)) (= (select v_v_7_1 v_idx_13) v_v_8_1) (<= (- c_main_~p~1.offset v_v_25_1) (- 400)) (<= (- (- c_main_~p~1.offset) c_main_~p~1.offset) 0) (<= (- (- |c_main_#t~malloc0.offset|) c_main_~malloc_~size) (- 400)) (<= (- c_main_~malloc_~size v_v_25_1) 0) (<= (- v_b_5_1 v_b_9_1) 0) (<= (- |c_main_#t~malloc0.offset| c_main_~q~1.offset) 0) (<= (- c_main_~q~1.offset v_v_25_1) (- 400)) (= (select |c_old(#valid)| v_idx_12) v_v_4_1) (<= (- c_main_~malloc_~size (- v_v_25_1)) 800) (<= (- (- c_main_~malloc_~size) (- v_v_25_1)) 0) (<= (- c_main_~malloc_~size c_main_~q~1.offset) 400) (<= (- (- v_b_8_1) (- |c_main_~malloc_#res.base|)) 0) (<= (- c_main_~malloc_~size (- c_main_~q~1.offset)) 400) (<= (- |c_main_#t~malloc0.offset| c_main_~malloc_~size) (- 400)) (<= (- c_main_~p~1.offset c_main_~q~1.offset) 0) (<= (- |c_main_~malloc_#res.offset| (- c_main_~malloc_~size)) 400) (= (+ |c_main_~malloc_#res.base| 1) (+ v_b_8_1 1)) (<= (- (- |c_main_#t~malloc0.offset|) (- c_main_~q~1.offset)) 0) (<= (- c_main_~p~1.offset (- c_main_~q~1.offset)) 0) (= (select |c_main_~malloc_old_#length| v_idx_11) v_v_1_1) (<= (- (- c_main_~p~1.offset) (- c_main_~q~1.offset)) 0) (<= (- (- c_main_~malloc_~size) c_main_~q~1.offset) (- 400)) (<= (- v_b_4_1 v_b_9_1) (- 1)) (<= (- (- c_main_~malloc_~size) (- c_main_~q~1.offset)) (- 400)) (<= (- (- v_b_4_1) (- v_b_5_1)) 1) (<= (- c_main_~q~1.offset (- v_v_25_1)) 400) (= (select |c_old(#memory_int)| v_idx_18) v_v_7_1) (<= (- (- |c_main_#t~malloc0.offset|) v_v_25_1) (- 400)) (<= (- v_b_4_1 v_b_5_1) (- 1)) (<= (- (- |c_main_#t~malloc0.offset|) |c_main_~malloc_#res.offset|) 0) (<= (- (- c_main_~q~1.offset) v_v_25_1) (- 400)) (or (< v_idx_22 v_b_9_1) (= (select |c_#length| v_idx_22) v_v_26_1)) (<= (- |c_main_~malloc_#res.offset| v_v_25_1) (- 400)) (<= (- (- |c_main_~malloc_#res.offset|) (- v_v_25_1)) 400) (or (< v_idx_16 v_b_5_1) (= (select |c_#valid| v_idx_16) v_v_20_1)) (<= (- |c_main_~malloc_#res.offset| c_main_~malloc_~size) (- 400)) (<= (- |c_main_~malloc_#res.offset| c_main_~q~1.offset) 0) (<= (- |c_main_#t~malloc0.offset| (- c_main_~q~1.offset)) 0) (<= (- (- |c_main_#t~malloc0.offset|) (- |c_main_~malloc_#res.offset|)) 0) (<= (- (- |c_main_~malloc_#res.offset|) |c_main_~malloc_#res.offset|) 0) (<= (- |c_main_~malloc_#res.offset| c_main_~p~1.offset) 0) (<= (- (- c_main_~p~1.offset) (- v_v_25_1)) 400) (<= (- (- v_b_5_1) (- v_b_9_1)) 0) (<= (- (- c_main_~q~1.offset) c_main_~q~1.offset) 0) (<= (- (- v_b_4_1) (- v_b_9_1)) 1) (<= (- |c_main_~malloc_#res.offset| (- c_main_~p~1.offset)) 0) (<= (- v_b_5_1 v_b_8_1) 1) (<= (- c_main_~malloc_~size c_main_~p~1.offset) 400) (<= (- (- c_main_~malloc_~size) c_main_~malloc_~size) (- 800)) (<= (- (- |c_main_#t~malloc0.offset|) |c_main_#t~malloc0.offset|) 0) (<= (- (- v_b_4_1) (- v_b_8_1)) 0) (<= (- (- |c_main_~malloc_#res.offset|) c_main_~q~1.offset) 0) (<= (- (- |c_main_~malloc_#res.offset|) v_v_25_1) (- 400)) (<= (- (- |c_main_~malloc_#res.offset|) c_main_~p~1.offset) 0) (<= (- c_main_~p~1.offset (- v_v_25_1)) 400) (<= (- |c_main_~malloc_#res.offset| (- |c_main_~malloc_#res.offset|)) 0) (<= (- |c_main_#t~malloc0.offset| v_v_25_1) (- 400)) (<= (- (- v_b_5_1) (- v_b_8_1)) (- 1)) (<= (- c_main_~q~1.offset (- c_main_~q~1.offset)) 0) (<= (- (- |c_main_#t~malloc0.offset|) (- c_main_~malloc_~size)) 400) (<= (- (- v_b_8_1) (- v_b_9_1)) 1) (or (= v_v_18_1 (select |c_#valid| v_idx_14)) (<= v_b_4_1 v_idx_14)) (<= (- v_b_4_1 |c_main_~malloc_#res.base|) 0) (= (+ v_b_9_1 (- 1)) v_b_4_1) (<= (- c_main_~p~1.offset (- c_main_~p~1.offset)) 0) (<= (- (- c_main_~p~1.offset) c_main_~q~1.offset) 0) (<= (- v_b_4_1 v_b_8_1) 0) (<= (- v_b_5_1 |c_main_~malloc_#res.base|) 1))))} [2019-01-07 16:15:05,338 WARN L263 ngHoareTripleChecker]: unsat core / model generation is disabled, enable it to get more details [2019-01-07 16:15:05,340 WARN L268 ngHoareTripleChecker]: -- [2019-01-07 16:15:05,340 WARN L269 ngHoareTripleChecker]: Simplified triple [2019-01-07 16:15:05,399 WARN L270 ngHoareTripleChecker]: Pre: {2147483647#true} [2019-01-07 16:15:05,400 WARN L274 ngHoareTripleChecker]: Action: ~malloc_old_#length, ~malloc_old_#valid := #length, #valid;~malloc_~size := 400;havoc ~malloc_#res.base, ~malloc_#res.offset;havoc #valid, #length;assume ~malloc_old_#valid[~malloc_#res.base] == false;assume #valid == ~malloc_old_#valid[~malloc_#res.base := true];assume ~malloc_#res.offset == 0;assume ~malloc_#res.base != 0;assume #length == ~malloc_old_#length[~malloc_#res.base := ~malloc_~size];#t~malloc0.base, #t~malloc0.offset := ~malloc_#res.base, ~malloc_#res.offset;~p~1.base, ~p~1.offset := #t~malloc0.base, #t~malloc0.offset;~q~1.base, ~q~1.offset := ~p~1.base, ~p~1.offset; [2019-01-07 16:15:05,401 WARN L184 hOps$ForEachOp$OfRef]: ActionStr: (and (not (select |c_main_~malloc_old_#valid_primed| |c_main_~malloc_#res.base_primed|)) (= |c_main_#t~malloc0.offset_primed| |c_main_~malloc_#res.offset_primed|) (= (store |c_main_~malloc_old_#length_primed| |c_main_~malloc_#res.base_primed| c_main_~malloc_~size_primed) |c_#length_primed|) (= |c_main_~malloc_old_#valid_primed| |c_#valid|) (= |c_main_~malloc_old_#length_primed| |c_#length|) (= (store |c_main_~malloc_old_#valid_primed| |c_main_~malloc_#res.base_primed| true) |c_#valid_primed|) (= c_main_~q~1.offset_primed c_main_~p~1.offset_primed) (= 0 |c_main_~malloc_#res.offset_primed|) (= |c_main_#t~malloc0.base_primed| |c_main_~malloc_#res.base_primed|) (= c_main_~p~1.base_primed |c_main_#t~malloc0.base_primed|) (= c_main_~q~1.base_primed c_main_~p~1.base_primed) (= c_main_~malloc_~size_primed 400) (= c_main_~p~1.offset_primed |c_main_#t~malloc0.offset_primed|) (not (= |c_main_~malloc_#res.base_primed| 0)))