./Ultimate.py --spec ../sv-benchmarks/c/properties/unreach-call.prp --file ../sv-benchmarks/c/product-lines/email_spec1_product33.cil.c --full-output -ea --architecture 32bit -------------------------------------------------------------------------------- Checking for ERROR reachability Using default analysis Version 03d7b7b3 Calling Ultimate with: /usr/bin/java -Dosgi.configuration.area=/storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/data/config -Xmx15G -Xms4m -ea -jar /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/plugins/org.eclipse.equinox.launcher_1.5.800.v20200727-1323.jar -data @noDefault -ultimatedata /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/data -tc /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/config/AutomizerReach.xml -i ../sv-benchmarks/c/product-lines/email_spec1_product33.cil.c -s /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/config/svcomp-Reach-32bit-Automizer_Default.epf --cacsl2boogietranslator.entry.function main --witnessprinter.witness.directory /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux --witnessprinter.witness.filename witness.graphml --witnessprinter.write.witness.besides.input.file false --witnessprinter.graph.data.specification CHECK( init(main()), LTL(G ! call(reach_error())) ) --witnessprinter.graph.data.producer Automizer --witnessprinter.graph.data.architecture 32bit --witnessprinter.graph.data.programhash 00f3978296386b105e45bba586b0df56f2d34b783492fc63d6fdcb596a8910f4 --- Real Ultimate output --- This is Ultimate 0.2.2-dev-03d7b7b [2022-02-20 17:55:56,546 INFO L177 SettingsManager]: Resetting all preferences to default values... [2022-02-20 17:55:56,548 INFO L181 SettingsManager]: Resetting UltimateCore preferences to default values [2022-02-20 17:55:56,573 INFO L184 SettingsManager]: Ultimate Commandline Interface provides no preferences, ignoring... [2022-02-20 17:55:56,573 INFO L181 SettingsManager]: Resetting Boogie Preprocessor preferences to default values [2022-02-20 17:55:56,576 INFO L181 SettingsManager]: Resetting Boogie Procedure Inliner preferences to default values [2022-02-20 17:55:56,578 INFO L181 SettingsManager]: Resetting Abstract Interpretation preferences to default values [2022-02-20 17:55:56,580 INFO L181 SettingsManager]: Resetting LassoRanker preferences to default values [2022-02-20 17:55:56,581 INFO L181 SettingsManager]: Resetting Reaching Definitions preferences to default values [2022-02-20 17:55:56,584 INFO L181 SettingsManager]: Resetting SyntaxChecker preferences to default values [2022-02-20 17:55:56,584 INFO L181 SettingsManager]: Resetting Sifa preferences to default values [2022-02-20 17:55:56,585 INFO L184 SettingsManager]: Büchi Program Product provides no preferences, ignoring... [2022-02-20 17:55:56,586 INFO L181 SettingsManager]: Resetting LTL2Aut preferences to default values [2022-02-20 17:55:56,588 INFO L181 SettingsManager]: Resetting PEA to Boogie preferences to default values [2022-02-20 17:55:56,589 INFO L181 SettingsManager]: Resetting BlockEncodingV2 preferences to default values [2022-02-20 17:55:56,591 INFO L181 SettingsManager]: Resetting ChcToBoogie preferences to default values [2022-02-20 17:55:56,591 INFO L181 SettingsManager]: Resetting AutomataScriptInterpreter preferences to default values [2022-02-20 17:55:56,592 INFO L181 SettingsManager]: Resetting BuchiAutomizer preferences to default values [2022-02-20 17:55:56,593 INFO L181 SettingsManager]: Resetting CACSL2BoogieTranslator preferences to default values [2022-02-20 17:55:56,597 INFO L181 SettingsManager]: Resetting CodeCheck preferences to default values [2022-02-20 17:55:56,598 INFO L181 SettingsManager]: Resetting InvariantSynthesis preferences to default values [2022-02-20 17:55:56,599 INFO L181 SettingsManager]: Resetting RCFGBuilder preferences to default values [2022-02-20 17:55:56,600 INFO L181 SettingsManager]: Resetting Referee preferences to default values [2022-02-20 17:55:56,600 INFO L181 SettingsManager]: Resetting TraceAbstraction preferences to default values [2022-02-20 17:55:56,605 INFO L184 SettingsManager]: TraceAbstractionConcurrent provides no preferences, ignoring... [2022-02-20 17:55:56,605 INFO L184 SettingsManager]: TraceAbstractionWithAFAs provides no preferences, ignoring... [2022-02-20 17:55:56,605 INFO L181 SettingsManager]: Resetting TreeAutomizer preferences to default values [2022-02-20 17:55:56,607 INFO L181 SettingsManager]: Resetting IcfgToChc preferences to default values [2022-02-20 17:55:56,607 INFO L181 SettingsManager]: Resetting IcfgTransformer preferences to default values [2022-02-20 17:55:56,607 INFO L184 SettingsManager]: ReqToTest provides no preferences, ignoring... [2022-02-20 17:55:56,608 INFO L181 SettingsManager]: Resetting Boogie Printer preferences to default values [2022-02-20 17:55:56,609 INFO L181 SettingsManager]: Resetting ChcSmtPrinter preferences to default values [2022-02-20 17:55:56,610 INFO L181 SettingsManager]: Resetting ReqPrinter preferences to default values [2022-02-20 17:55:56,610 INFO L181 SettingsManager]: Resetting Witness Printer preferences to default values [2022-02-20 17:55:56,611 INFO L184 SettingsManager]: Boogie PL CUP Parser provides no preferences, ignoring... [2022-02-20 17:55:56,611 INFO L181 SettingsManager]: Resetting CDTParser preferences to default values [2022-02-20 17:55:56,612 INFO L184 SettingsManager]: AutomataScriptParser provides no preferences, ignoring... [2022-02-20 17:55:56,613 INFO L184 SettingsManager]: ReqParser provides no preferences, ignoring... [2022-02-20 17:55:56,613 INFO L181 SettingsManager]: Resetting SmtParser preferences to default values [2022-02-20 17:55:56,613 INFO L181 SettingsManager]: Resetting Witness Parser preferences to default values [2022-02-20 17:55:56,614 INFO L188 SettingsManager]: Finished resetting all preferences to default values... [2022-02-20 17:55:56,615 INFO L101 SettingsManager]: Beginning loading settings from /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/config/svcomp-Reach-32bit-Automizer_Default.epf [2022-02-20 17:55:56,637 INFO L113 SettingsManager]: Loading preferences was successful [2022-02-20 17:55:56,639 INFO L115 SettingsManager]: Preferences different from defaults after loading the file: [2022-02-20 17:55:56,640 INFO L136 SettingsManager]: Preferences of UltimateCore differ from their defaults: [2022-02-20 17:55:56,640 INFO L138 SettingsManager]: * Log level for class=de.uni_freiburg.informatik.ultimate.lib.smtlibutils.quantifier.QuantifierPusher=ERROR; [2022-02-20 17:55:56,641 INFO L136 SettingsManager]: Preferences of Boogie Procedure Inliner differ from their defaults: [2022-02-20 17:55:56,641 INFO L138 SettingsManager]: * Ignore calls to procedures called more than once=ONLY_FOR_SEQUENTIAL_PROGRAMS [2022-02-20 17:55:56,641 INFO L136 SettingsManager]: Preferences of BlockEncodingV2 differ from their defaults: [2022-02-20 17:55:56,641 INFO L138 SettingsManager]: * Create parallel compositions if possible=false [2022-02-20 17:55:56,641 INFO L138 SettingsManager]: * Use SBE=true [2022-02-20 17:55:56,641 INFO L136 SettingsManager]: Preferences of CACSL2BoogieTranslator differ from their defaults: [2022-02-20 17:55:56,642 INFO L138 SettingsManager]: * sizeof long=4 [2022-02-20 17:55:56,642 INFO L138 SettingsManager]: * Overapproximate operations on floating types=true [2022-02-20 17:55:56,642 INFO L138 SettingsManager]: * sizeof POINTER=4 [2022-02-20 17:55:56,642 INFO L138 SettingsManager]: * Check division by zero=IGNORE [2022-02-20 17:55:56,643 INFO L138 SettingsManager]: * Pointer to allocated memory at dereference=IGNORE [2022-02-20 17:55:56,643 INFO L138 SettingsManager]: * If two pointers are subtracted or compared they have the same base address=IGNORE [2022-02-20 17:55:56,643 INFO L138 SettingsManager]: * Check array bounds for arrays that are off heap=IGNORE [2022-02-20 17:55:56,643 INFO L138 SettingsManager]: * sizeof long double=12 [2022-02-20 17:55:56,643 INFO L138 SettingsManager]: * Check if freed pointer was valid=false [2022-02-20 17:55:56,643 INFO L138 SettingsManager]: * Use constant arrays=true [2022-02-20 17:55:56,643 INFO L138 SettingsManager]: * Pointer base address is valid at dereference=IGNORE [2022-02-20 17:55:56,644 INFO L136 SettingsManager]: Preferences of RCFGBuilder differ from their defaults: [2022-02-20 17:55:56,644 INFO L138 SettingsManager]: * Size of a code block=SequenceOfStatements [2022-02-20 17:55:56,644 INFO L138 SettingsManager]: * SMT solver=External_DefaultMode [2022-02-20 17:55:56,644 INFO L138 SettingsManager]: * Command for external solver=z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in -t:2000 [2022-02-20 17:55:56,644 INFO L136 SettingsManager]: Preferences of TraceAbstraction differ from their defaults: [2022-02-20 17:55:56,644 INFO L138 SettingsManager]: * Compute Interpolants along a Counterexample=FPandBP [2022-02-20 17:55:56,644 INFO L138 SettingsManager]: * Positions where we compute the Hoare Annotation=LoopsAndPotentialCycles [2022-02-20 17:55:56,645 INFO L138 SettingsManager]: * Trace refinement strategy=CAMEL [2022-02-20 17:55:56,645 INFO L138 SettingsManager]: * Command for external solver=z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in [2022-02-20 17:55:56,645 INFO L138 SettingsManager]: * Large block encoding in concurrent analysis=OFF [2022-02-20 17:55:56,645 INFO L138 SettingsManager]: * Automaton type used in concurrency analysis=PETRI_NET [2022-02-20 17:55:56,645 INFO L138 SettingsManager]: * Compute Hoare Annotation of negated interpolant automaton, abstraction and CFG=true [2022-02-20 17:55:56,645 INFO L138 SettingsManager]: * SMT solver=External_ModelsAndUnsatCoreMode WARNING: An illegal reflective access operation has occurred WARNING: Illegal reflective access by com.sun.xml.bind.v2.runtime.reflect.opt.Injector$1 (file:/storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/plugins/com.sun.xml.bind_2.2.0.v201505121915.jar) to method java.lang.ClassLoader.defineClass(java.lang.String,byte[],int,int) WARNING: Please consider reporting this to the maintainers of com.sun.xml.bind.v2.runtime.reflect.opt.Injector$1 WARNING: Use --illegal-access=warn to enable warnings of further illegal reflective access operations WARNING: All illegal access operations will be denied in a future release Applying setting for plugin de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator: Entry function -> main Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Witness directory -> /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Witness filename -> witness.graphml Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Write witness besides input file -> false Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Graph data specification -> CHECK( init(main()), LTL(G ! call(reach_error())) ) Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Graph data producer -> Automizer Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Graph data architecture -> 32bit Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Graph data programhash -> 00f3978296386b105e45bba586b0df56f2d34b783492fc63d6fdcb596a8910f4 [2022-02-20 17:55:56,817 INFO L75 nceAwareModelManager]: Repository-Root is: /tmp [2022-02-20 17:55:56,835 INFO L261 ainManager$Toolchain]: [Toolchain 1]: Applicable parser(s) successfully (re)initialized [2022-02-20 17:55:56,837 INFO L217 ainManager$Toolchain]: [Toolchain 1]: Toolchain selected. [2022-02-20 17:55:56,838 INFO L271 PluginConnector]: Initializing CDTParser... [2022-02-20 17:55:56,840 INFO L275 PluginConnector]: CDTParser initialized [2022-02-20 17:55:56,841 INFO L432 ainManager$Toolchain]: [Toolchain 1]: Parsing single file: /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/../sv-benchmarks/c/product-lines/email_spec1_product33.cil.c [2022-02-20 17:55:56,891 INFO L220 CDTParser]: Created temporary CDT project at /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/data/390dbae75/8d270aa266af4a10b2c076acae31c985/FLAG8de7f2708 [2022-02-20 17:55:57,339 INFO L306 CDTParser]: Found 1 translation units. [2022-02-20 17:55:57,340 INFO L160 CDTParser]: Scanning /storage/repos/ultimate/releaseScripts/default/sv-benchmarks/c/product-lines/email_spec1_product33.cil.c [2022-02-20 17:55:57,355 INFO L349 CDTParser]: About to delete temporary CDT project at /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/data/390dbae75/8d270aa266af4a10b2c076acae31c985/FLAG8de7f2708 [2022-02-20 17:55:57,682 INFO L357 CDTParser]: Successfully deleted /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/data/390dbae75/8d270aa266af4a10b2c076acae31c985 [2022-02-20 17:55:57,684 INFO L299 ainManager$Toolchain]: ####################### [Toolchain 1] ####################### [2022-02-20 17:55:57,685 INFO L131 ToolchainWalker]: Walking toolchain with 6 elements. [2022-02-20 17:55:57,687 INFO L113 PluginConnector]: ------------------------CACSL2BoogieTranslator---------------------------- [2022-02-20 17:55:57,687 INFO L271 PluginConnector]: Initializing CACSL2BoogieTranslator... [2022-02-20 17:55:57,709 INFO L275 PluginConnector]: CACSL2BoogieTranslator initialized [2022-02-20 17:55:57,710 INFO L185 PluginConnector]: Executing the observer ACSLObjectContainerObserver from plugin CACSL2BoogieTranslator for "CDTParser AST 20.02 05:55:57" (1/1) ... [2022-02-20 17:55:57,711 INFO L205 PluginConnector]: Invalid model from CACSL2BoogieTranslator for observer de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator.ACSLObjectContainerObserver@48c73cfc and model type de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 20.02 05:55:57, skipping insertion in model container [2022-02-20 17:55:57,711 INFO L185 PluginConnector]: Executing the observer CACSL2BoogieTranslatorObserver from plugin CACSL2BoogieTranslator for "CDTParser AST 20.02 05:55:57" (1/1) ... [2022-02-20 17:55:57,715 INFO L145 MainTranslator]: Starting translation in SV-COMP mode [2022-02-20 17:55:57,778 INFO L178 MainTranslator]: Built tables and reachable declarations [2022-02-20 17:55:57,902 WARN L230 ndardFunctionHandler]: Function reach_error is already implemented but we override the implementation for the call at /storage/repos/ultimate/releaseScripts/default/sv-benchmarks/c/product-lines/email_spec1_product33.cil.c[1542,1555] [2022-02-20 17:55:58,192 INFO L210 PostProcessor]: Analyzing one entry point: main [2022-02-20 17:55:58,202 INFO L203 MainTranslator]: Completed pre-run [2022-02-20 17:55:58,213 WARN L230 ndardFunctionHandler]: Function reach_error is already implemented but we override the implementation for the call at /storage/repos/ultimate/releaseScripts/default/sv-benchmarks/c/product-lines/email_spec1_product33.cil.c[1542,1555] [2022-02-20 17:55:58,305 INFO L210 PostProcessor]: Analyzing one entry point: main [2022-02-20 17:55:58,336 INFO L208 MainTranslator]: Completed translation [2022-02-20 17:55:58,337 INFO L202 PluginConnector]: Adding new model de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 20.02 05:55:58 WrapperNode [2022-02-20 17:55:58,337 INFO L132 PluginConnector]: ------------------------ END CACSL2BoogieTranslator---------------------------- [2022-02-20 17:55:58,338 INFO L113 PluginConnector]: ------------------------Boogie Procedure Inliner---------------------------- [2022-02-20 17:55:58,338 INFO L271 PluginConnector]: Initializing Boogie Procedure Inliner... [2022-02-20 17:55:58,338 INFO L275 PluginConnector]: Boogie Procedure Inliner initialized [2022-02-20 17:55:58,343 INFO L185 PluginConnector]: Executing the observer TypeChecker from plugin Boogie Procedure Inliner for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 20.02 05:55:58" (1/1) ... [2022-02-20 17:55:58,362 INFO L185 PluginConnector]: Executing the observer Inliner from plugin Boogie Procedure Inliner for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 20.02 05:55:58" (1/1) ... [2022-02-20 17:55:58,411 INFO L137 Inliner]: procedures = 134, calls = 228, calls flagged for inlining = 65, calls inlined = 60, statements flattened = 1070 [2022-02-20 17:55:58,411 INFO L132 PluginConnector]: ------------------------ END Boogie Procedure Inliner---------------------------- [2022-02-20 17:55:58,412 INFO L113 PluginConnector]: ------------------------Boogie Preprocessor---------------------------- [2022-02-20 17:55:58,412 INFO L271 PluginConnector]: Initializing Boogie Preprocessor... [2022-02-20 17:55:58,412 INFO L275 PluginConnector]: Boogie Preprocessor initialized [2022-02-20 17:55:58,417 INFO L185 PluginConnector]: Executing the observer EnsureBoogieModelObserver from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 20.02 05:55:58" (1/1) ... [2022-02-20 17:55:58,420 INFO L185 PluginConnector]: Executing the observer TypeChecker from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 20.02 05:55:58" (1/1) ... [2022-02-20 17:55:58,423 INFO L185 PluginConnector]: Executing the observer ConstExpander from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 20.02 05:55:58" (1/1) ... [2022-02-20 17:55:58,429 INFO L185 PluginConnector]: Executing the observer StructExpander from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 20.02 05:55:58" (1/1) ... [2022-02-20 17:55:58,443 INFO L185 PluginConnector]: Executing the observer UnstructureCode from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 20.02 05:55:58" (1/1) ... [2022-02-20 17:55:58,463 INFO L185 PluginConnector]: Executing the observer FunctionInliner from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 20.02 05:55:58" (1/1) ... [2022-02-20 17:55:58,467 INFO L185 PluginConnector]: Executing the observer BoogieSymbolTableConstructor from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 20.02 05:55:58" (1/1) ... [2022-02-20 17:55:58,473 INFO L132 PluginConnector]: ------------------------ END Boogie Preprocessor---------------------------- [2022-02-20 17:55:58,473 INFO L113 PluginConnector]: ------------------------RCFGBuilder---------------------------- [2022-02-20 17:55:58,473 INFO L271 PluginConnector]: Initializing RCFGBuilder... [2022-02-20 17:55:58,473 INFO L275 PluginConnector]: RCFGBuilder initialized [2022-02-20 17:55:58,474 INFO L185 PluginConnector]: Executing the observer RCFGBuilderObserver from plugin RCFGBuilder for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 20.02 05:55:58" (1/1) ... [2022-02-20 17:55:58,496 INFO L173 SolverBuilder]: Constructing external solver with command: z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in -t:2000 [2022-02-20 17:55:58,505 INFO L189 MonitoredProcess]: No working directory specified, using /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 [2022-02-20 17:55:58,525 INFO L229 MonitoredProcess]: Starting monitored process 1 with /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in -t:2000 (exit command is (exit), workingDir is null) [2022-02-20 17:55:58,527 INFO L327 MonitoredProcess]: [MP /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in -t:2000 (1)] Waiting until timeout for monitored process [2022-02-20 17:55:58,558 INFO L130 BoogieDeclarations]: Found specification of procedure getClientPrivateKey [2022-02-20 17:55:58,559 INFO L138 BoogieDeclarations]: Found implementation of procedure getClientPrivateKey [2022-02-20 17:55:58,559 INFO L130 BoogieDeclarations]: Found specification of procedure setEmailEncryptionKey [2022-02-20 17:55:58,559 INFO L138 BoogieDeclarations]: Found implementation of procedure setEmailEncryptionKey [2022-02-20 17:55:58,560 INFO L130 BoogieDeclarations]: Found specification of procedure getEmailEncryptionKey [2022-02-20 17:55:58,560 INFO L138 BoogieDeclarations]: Found implementation of procedure getEmailEncryptionKey [2022-02-20 17:55:58,560 INFO L130 BoogieDeclarations]: Found specification of procedure getEmailTo [2022-02-20 17:55:58,560 INFO L138 BoogieDeclarations]: Found implementation of procedure getEmailTo [2022-02-20 17:55:58,563 INFO L130 BoogieDeclarations]: Found specification of procedure setEmailFrom [2022-02-20 17:55:58,563 INFO L138 BoogieDeclarations]: Found implementation of procedure setEmailFrom [2022-02-20 17:55:58,563 INFO L130 BoogieDeclarations]: Found specification of procedure isReadable [2022-02-20 17:55:58,563 INFO L138 BoogieDeclarations]: Found implementation of procedure isReadable [2022-02-20 17:55:58,563 INFO L130 BoogieDeclarations]: Found specification of procedure createClientKeyringEntry [2022-02-20 17:55:58,564 INFO L138 BoogieDeclarations]: Found implementation of procedure createClientKeyringEntry [2022-02-20 17:55:58,564 INFO L130 BoogieDeclarations]: Found specification of procedure setEmailIsEncrypted [2022-02-20 17:55:58,564 INFO L138 BoogieDeclarations]: Found implementation of procedure setEmailIsEncrypted [2022-02-20 17:55:58,564 INFO L130 BoogieDeclarations]: Found specification of procedure getEmailSignKey [2022-02-20 17:55:58,564 INFO L138 BoogieDeclarations]: Found implementation of procedure getEmailSignKey [2022-02-20 17:55:58,564 INFO L130 BoogieDeclarations]: Found specification of procedure chuckKeyAdd [2022-02-20 17:55:58,564 INFO L138 BoogieDeclarations]: Found implementation of procedure chuckKeyAdd [2022-02-20 17:55:58,564 INFO L130 BoogieDeclarations]: Found specification of procedure puts [2022-02-20 17:55:58,564 INFO L130 BoogieDeclarations]: Found specification of procedure getEmailFrom [2022-02-20 17:55:58,565 INFO L138 BoogieDeclarations]: Found implementation of procedure getEmailFrom [2022-02-20 17:55:58,565 INFO L130 BoogieDeclarations]: Found specification of procedure queue [2022-02-20 17:55:58,565 INFO L138 BoogieDeclarations]: Found implementation of procedure queue [2022-02-20 17:55:58,565 INFO L130 BoogieDeclarations]: Found specification of procedure setClientId [2022-02-20 17:55:58,565 INFO L138 BoogieDeclarations]: Found implementation of procedure setClientId [2022-02-20 17:55:58,565 INFO L130 BoogieDeclarations]: Found specification of procedure #Ultimate.allocInit [2022-02-20 17:55:58,565 INFO L130 BoogieDeclarations]: Found specification of procedure isSigned [2022-02-20 17:55:58,565 INFO L138 BoogieDeclarations]: Found implementation of procedure isSigned [2022-02-20 17:55:58,566 INFO L130 BoogieDeclarations]: Found specification of procedure isKeyPairValid [2022-02-20 17:55:58,566 INFO L138 BoogieDeclarations]: Found implementation of procedure isKeyPairValid [2022-02-20 17:55:58,566 INFO L130 BoogieDeclarations]: Found specification of procedure setClientKeyringUser [2022-02-20 17:55:58,566 INFO L138 BoogieDeclarations]: Found implementation of procedure setClientKeyringUser [2022-02-20 17:55:58,566 INFO L130 BoogieDeclarations]: Found specification of procedure setClientKeyringPublicKey [2022-02-20 17:55:58,566 INFO L138 BoogieDeclarations]: Found implementation of procedure setClientKeyringPublicKey [2022-02-20 17:55:58,566 INFO L130 BoogieDeclarations]: Found specification of procedure outgoing [2022-02-20 17:55:58,566 INFO L138 BoogieDeclarations]: Found implementation of procedure outgoing [2022-02-20 17:55:58,566 INFO L130 BoogieDeclarations]: Found specification of procedure findPublicKey [2022-02-20 17:55:58,567 INFO L138 BoogieDeclarations]: Found implementation of procedure findPublicKey [2022-02-20 17:55:58,567 INFO L130 BoogieDeclarations]: Found specification of procedure sendEmail [2022-02-20 17:55:58,567 INFO L138 BoogieDeclarations]: Found implementation of procedure sendEmail [2022-02-20 17:55:58,567 INFO L130 BoogieDeclarations]: Found specification of procedure isEncrypted [2022-02-20 17:55:58,567 INFO L138 BoogieDeclarations]: Found implementation of procedure isEncrypted [2022-02-20 17:55:58,568 INFO L130 BoogieDeclarations]: Found specification of procedure setClientPrivateKey [2022-02-20 17:55:58,568 INFO L138 BoogieDeclarations]: Found implementation of procedure setClientPrivateKey [2022-02-20 17:55:58,568 INFO L130 BoogieDeclarations]: Found specification of procedure setEmailTo [2022-02-20 17:55:58,568 INFO L138 BoogieDeclarations]: Found implementation of procedure setEmailTo [2022-02-20 17:55:58,568 INFO L130 BoogieDeclarations]: Found specification of procedure write~init~int [2022-02-20 17:55:58,568 INFO L130 BoogieDeclarations]: Found specification of procedure generateKeyPair [2022-02-20 17:55:58,568 INFO L138 BoogieDeclarations]: Found implementation of procedure generateKeyPair [2022-02-20 17:55:58,569 INFO L130 BoogieDeclarations]: Found specification of procedure ULTIMATE.start [2022-02-20 17:55:58,569 INFO L138 BoogieDeclarations]: Found implementation of procedure ULTIMATE.start [2022-02-20 17:55:58,774 INFO L234 CfgBuilder]: Building ICFG [2022-02-20 17:55:58,775 INFO L260 CfgBuilder]: Building CFG for each procedure with an implementation [2022-02-20 17:55:59,502 INFO L275 CfgBuilder]: Performing block encoding [2022-02-20 17:55:59,520 INFO L294 CfgBuilder]: Using the 1 location(s) as analysis (start of procedure ULTIMATE.start) [2022-02-20 17:55:59,520 INFO L299 CfgBuilder]: Removed 1 assume(true) statements. [2022-02-20 17:55:59,522 INFO L202 PluginConnector]: Adding new model de.uni_freiburg.informatik.ultimate.plugins.generator.rcfgbuilder CFG 20.02 05:55:59 BoogieIcfgContainer [2022-02-20 17:55:59,522 INFO L132 PluginConnector]: ------------------------ END RCFGBuilder---------------------------- [2022-02-20 17:55:59,523 INFO L113 PluginConnector]: ------------------------TraceAbstraction---------------------------- [2022-02-20 17:55:59,523 INFO L271 PluginConnector]: Initializing TraceAbstraction... [2022-02-20 17:55:59,526 INFO L275 PluginConnector]: TraceAbstraction initialized [2022-02-20 17:55:59,526 INFO L185 PluginConnector]: Executing the observer TraceAbstractionObserver from plugin TraceAbstraction for "CDTParser AST 20.02 05:55:57" (1/3) ... [2022-02-20 17:55:59,526 INFO L205 PluginConnector]: Invalid model from TraceAbstraction for observer de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction.TraceAbstractionObserver@1f8779c4 and model type de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction AST 20.02 05:55:59, skipping insertion in model container [2022-02-20 17:55:59,527 INFO L185 PluginConnector]: Executing the observer TraceAbstractionObserver from plugin TraceAbstraction for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 20.02 05:55:58" (2/3) ... [2022-02-20 17:55:59,527 INFO L205 PluginConnector]: Invalid model from TraceAbstraction for observer de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction.TraceAbstractionObserver@1f8779c4 and model type de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction AST 20.02 05:55:59, skipping insertion in model container [2022-02-20 17:55:59,527 INFO L185 PluginConnector]: Executing the observer TraceAbstractionObserver from plugin TraceAbstraction for "de.uni_freiburg.informatik.ultimate.plugins.generator.rcfgbuilder CFG 20.02 05:55:59" (3/3) ... [2022-02-20 17:55:59,528 INFO L111 eAbstractionObserver]: Analyzing ICFG email_spec1_product33.cil.c [2022-02-20 17:55:59,532 INFO L205 ceAbstractionStarter]: Automizer settings: Hoare:true NWA Interpolation:FPandBP Determinization: PREDICATE_ABSTRACTION [2022-02-20 17:55:59,533 INFO L164 ceAbstractionStarter]: Applying trace abstraction to program that has 1 error locations. [2022-02-20 17:55:59,580 INFO L338 AbstractCegarLoop]: ======== Iteration 0 == of CEGAR loop == AllErrorsAtOnce ======== [2022-02-20 17:55:59,587 INFO L339 AbstractCegarLoop]: Settings: SEPARATE_VIOLATION_CHECK=true, mInterprocedural=true, mMaxIterations=1000000, mWatchIteration=1000000, mArtifact=RCFG, mInterpolation=FPandBP, mInterpolantAutomaton=STRAIGHT_LINE, mDumpAutomata=false, mAutomataFormat=ATS_NUMERATE, mDumpPath=., mDeterminiation=PREDICATE_ABSTRACTION, mMinimize=MINIMIZE_SEVPA, mHoare=true, mAutomataTypeConcurrency=PETRI_NET, mHoareTripleChecks=INCREMENTAL, mHoareAnnotationPositions=LoopsAndPotentialCycles, mDumpOnlyReuseAutomata=false, mLimitTraceHistogram=0, mErrorLocTimeLimit=0, mLimitPathProgramCount=0, mCollectInterpolantStatistics=true, mHeuristicEmptinessCheck=false, mHeuristicEmptinessCheckAStarHeuristic=ZERO, mHeuristicEmptinessCheckAStarHeuristicRandomSeed=1337, mHeuristicEmptinessCheckSmtFeatureScoringMethod=DAGSIZE, mSMTFeatureExtraction=false, mSMTFeatureExtractionDumpPath=., mOverrideInterpolantAutomaton=false, mMcrInterpolantMethod=WP, mLoopAccelerationTechnique=FAST_UPR [2022-02-20 17:55:59,588 INFO L340 AbstractCegarLoop]: Starting to check reachability of 1 error locations. [2022-02-20 17:55:59,626 INFO L276 IsEmpty]: Start isEmpty. Operand has 388 states, 299 states have (on average 1.5016722408026757) internal successors, (449), 303 states have internal predecessors, (449), 63 states have call successors, (63), 24 states have call predecessors, (63), 24 states have return successors, (63), 63 states have call predecessors, (63), 63 states have call successors, (63) [2022-02-20 17:55:59,644 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 102 [2022-02-20 17:55:59,644 INFO L506 BasicCegarLoop]: Found error trace [2022-02-20 17:55:59,645 INFO L514 BasicCegarLoop]: trace histogram [3, 3, 3, 3, 3, 3, 2, 2, 2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-02-20 17:55:59,646 INFO L402 AbstractCegarLoop]: === Iteration 1 === Targeting outgoingErr0ASSERT_VIOLATIONERROR_FUNCTION === [outgoingErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2022-02-20 17:55:59,650 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2022-02-20 17:55:59,650 INFO L85 PathProgramCache]: Analyzing trace with hash 121441317, now seen corresponding path program 1 times [2022-02-20 17:55:59,658 INFO L126 FreeRefinementEngine]: Executing refinement strategy CAMEL [2022-02-20 17:55:59,659 INFO L338 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [1866383525] [2022-02-20 17:55:59,659 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-02-20 17:55:59,660 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2022-02-20 17:55:59,789 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-02-20 17:55:59,891 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 6 [2022-02-20 17:55:59,893 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-02-20 17:55:59,900 INFO L290 TraceCheckUtils]: 0: Hoare triple {447#(and (= |old(~__ste_client_idCounter0~0)| ~__ste_client_idCounter0~0) (= |old(~__ste_client_idCounter1~0)| ~__ste_client_idCounter1~0) (= |old(~__ste_client_idCounter2~0)| ~__ste_client_idCounter2~0))} ~handle := #in~handle;~value := #in~value; {391#true} is VALID [2022-02-20 17:55:59,900 INFO L290 TraceCheckUtils]: 1: Hoare triple {391#true} assume 1 == ~handle;~__ste_client_idCounter0~0 := ~value; {391#true} is VALID [2022-02-20 17:55:59,900 INFO L290 TraceCheckUtils]: 2: Hoare triple {391#true} assume true; {391#true} is VALID [2022-02-20 17:55:59,901 INFO L284 TraceCheckUtils]: 3: Hoare quadruple {391#true} {391#true} #1133#return; {391#true} is VALID [2022-02-20 17:55:59,907 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 12 [2022-02-20 17:55:59,909 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-02-20 17:55:59,912 INFO L290 TraceCheckUtils]: 0: Hoare triple {448#(and (= ~__ste_client_privateKey0~0 |old(~__ste_client_privateKey0~0)|) (= ~__ste_client_privateKey2~0 |old(~__ste_client_privateKey2~0)|) (= ~__ste_client_privateKey1~0 |old(~__ste_client_privateKey1~0)|))} ~handle := #in~handle;~value := #in~value; {391#true} is VALID [2022-02-20 17:55:59,912 INFO L290 TraceCheckUtils]: 1: Hoare triple {391#true} assume 1 == ~handle;~__ste_client_privateKey0~0 := ~value; {391#true} is VALID [2022-02-20 17:55:59,912 INFO L290 TraceCheckUtils]: 2: Hoare triple {391#true} assume true; {391#true} is VALID [2022-02-20 17:55:59,912 INFO L284 TraceCheckUtils]: 3: Hoare quadruple {391#true} {391#true} #1135#return; {391#true} is VALID [2022-02-20 17:55:59,913 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 18 [2022-02-20 17:55:59,922 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-02-20 17:55:59,947 INFO L290 TraceCheckUtils]: 0: Hoare triple {447#(and (= |old(~__ste_client_idCounter0~0)| ~__ste_client_idCounter0~0) (= |old(~__ste_client_idCounter1~0)| ~__ste_client_idCounter1~0) (= |old(~__ste_client_idCounter2~0)| ~__ste_client_idCounter2~0))} ~handle := #in~handle;~value := #in~value; {449#(= setClientId_~handle |setClientId_#in~handle|)} is VALID [2022-02-20 17:55:59,948 INFO L290 TraceCheckUtils]: 1: Hoare triple {449#(= setClientId_~handle |setClientId_#in~handle|)} assume 1 == ~handle;~__ste_client_idCounter0~0 := ~value; {450#(= |setClientId_#in~handle| 1)} is VALID [2022-02-20 17:55:59,948 INFO L290 TraceCheckUtils]: 2: Hoare triple {450#(= |setClientId_#in~handle| 1)} assume true; {450#(= |setClientId_#in~handle| 1)} is VALID [2022-02-20 17:55:59,949 INFO L284 TraceCheckUtils]: 3: Hoare quadruple {450#(= |setClientId_#in~handle| 1)} {401#(= |ULTIMATE.start_setup_rjh__wrappee__Base_~rjh___0#1| 2)} #1137#return; {392#false} is VALID [2022-02-20 17:55:59,950 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 24 [2022-02-20 17:55:59,953 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-02-20 17:55:59,956 INFO L290 TraceCheckUtils]: 0: Hoare triple {448#(and (= ~__ste_client_privateKey0~0 |old(~__ste_client_privateKey0~0)|) (= ~__ste_client_privateKey2~0 |old(~__ste_client_privateKey2~0)|) (= ~__ste_client_privateKey1~0 |old(~__ste_client_privateKey1~0)|))} ~handle := #in~handle;~value := #in~value; {391#true} is VALID [2022-02-20 17:55:59,956 INFO L290 TraceCheckUtils]: 1: Hoare triple {391#true} assume 1 == ~handle;~__ste_client_privateKey0~0 := ~value; {391#true} is VALID [2022-02-20 17:55:59,956 INFO L290 TraceCheckUtils]: 2: Hoare triple {391#true} assume true; {391#true} is VALID [2022-02-20 17:55:59,956 INFO L284 TraceCheckUtils]: 3: Hoare quadruple {391#true} {392#false} #1139#return; {392#false} is VALID [2022-02-20 17:55:59,957 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 30 [2022-02-20 17:55:59,961 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-02-20 17:55:59,964 INFO L290 TraceCheckUtils]: 0: Hoare triple {447#(and (= |old(~__ste_client_idCounter0~0)| ~__ste_client_idCounter0~0) (= |old(~__ste_client_idCounter1~0)| ~__ste_client_idCounter1~0) (= |old(~__ste_client_idCounter2~0)| ~__ste_client_idCounter2~0))} ~handle := #in~handle;~value := #in~value; {391#true} is VALID [2022-02-20 17:55:59,965 INFO L290 TraceCheckUtils]: 1: Hoare triple {391#true} assume 1 == ~handle;~__ste_client_idCounter0~0 := ~value; {391#true} is VALID [2022-02-20 17:55:59,965 INFO L290 TraceCheckUtils]: 2: Hoare triple {391#true} assume true; {391#true} is VALID [2022-02-20 17:55:59,977 INFO L284 TraceCheckUtils]: 3: Hoare quadruple {391#true} {392#false} #1141#return; {392#false} is VALID [2022-02-20 17:55:59,978 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 36 [2022-02-20 17:55:59,983 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-02-20 17:55:59,988 INFO L290 TraceCheckUtils]: 0: Hoare triple {448#(and (= ~__ste_client_privateKey0~0 |old(~__ste_client_privateKey0~0)|) (= ~__ste_client_privateKey2~0 |old(~__ste_client_privateKey2~0)|) (= ~__ste_client_privateKey1~0 |old(~__ste_client_privateKey1~0)|))} ~handle := #in~handle;~value := #in~value; {391#true} is VALID [2022-02-20 17:55:59,989 INFO L290 TraceCheckUtils]: 1: Hoare triple {391#true} assume 1 == ~handle;~__ste_client_privateKey0~0 := ~value; {391#true} is VALID [2022-02-20 17:55:59,989 INFO L290 TraceCheckUtils]: 2: Hoare triple {391#true} assume true; {391#true} is VALID [2022-02-20 17:55:59,989 INFO L284 TraceCheckUtils]: 3: Hoare quadruple {391#true} {392#false} #1143#return; {392#false} is VALID [2022-02-20 17:55:59,996 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 47 [2022-02-20 17:56:00,002 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-02-20 17:56:00,009 INFO L290 TraceCheckUtils]: 0: Hoare triple {451#(and (= |old(~__ste_email_from0~0)| ~__ste_email_from0~0) (= |old(~__ste_email_from1~0)| ~__ste_email_from1~0))} ~handle := #in~handle;~value := #in~value; {391#true} is VALID [2022-02-20 17:56:00,010 INFO L290 TraceCheckUtils]: 1: Hoare triple {391#true} assume 1 == ~handle;~__ste_email_from0~0 := ~value; {391#true} is VALID [2022-02-20 17:56:00,013 INFO L290 TraceCheckUtils]: 2: Hoare triple {391#true} assume true; {391#true} is VALID [2022-02-20 17:56:00,013 INFO L284 TraceCheckUtils]: 3: Hoare quadruple {391#true} {392#false} #1119#return; {392#false} is VALID [2022-02-20 17:56:00,020 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 52 [2022-02-20 17:56:00,022 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-02-20 17:56:00,027 INFO L290 TraceCheckUtils]: 0: Hoare triple {452#(and (= ~__ste_email_to0~0 |old(~__ste_email_to0~0)|) (= ~__ste_email_to1~0 |old(~__ste_email_to1~0)|))} ~handle := #in~handle;~value := #in~value; {391#true} is VALID [2022-02-20 17:56:00,028 INFO L290 TraceCheckUtils]: 1: Hoare triple {391#true} assume 1 == ~handle;~__ste_email_to0~0 := ~value; {391#true} is VALID [2022-02-20 17:56:00,028 INFO L290 TraceCheckUtils]: 2: Hoare triple {391#true} assume true; {391#true} is VALID [2022-02-20 17:56:00,028 INFO L284 TraceCheckUtils]: 3: Hoare quadruple {391#true} {392#false} #1121#return; {392#false} is VALID [2022-02-20 17:56:00,028 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 61 [2022-02-20 17:56:00,029 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-02-20 17:56:00,032 INFO L290 TraceCheckUtils]: 0: Hoare triple {391#true} ~handle := #in~handle;havoc ~retValue_acc~24; {391#true} is VALID [2022-02-20 17:56:00,033 INFO L290 TraceCheckUtils]: 1: Hoare triple {391#true} assume 1 == ~handle;~retValue_acc~24 := ~__ste_client_privateKey0~0;#res := ~retValue_acc~24; {391#true} is VALID [2022-02-20 17:56:00,033 INFO L290 TraceCheckUtils]: 2: Hoare triple {391#true} assume true; {391#true} is VALID [2022-02-20 17:56:00,033 INFO L284 TraceCheckUtils]: 3: Hoare quadruple {391#true} {392#false} #1053#return; {392#false} is VALID [2022-02-20 17:56:00,033 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 69 [2022-02-20 17:56:00,035 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-02-20 17:56:00,037 INFO L290 TraceCheckUtils]: 0: Hoare triple {391#true} ~handle := #in~handle;havoc ~retValue_acc~36; {391#true} is VALID [2022-02-20 17:56:00,037 INFO L290 TraceCheckUtils]: 1: Hoare triple {391#true} assume 1 == ~handle;~retValue_acc~36 := ~__ste_email_to0~0;#res := ~retValue_acc~36; {391#true} is VALID [2022-02-20 17:56:00,037 INFO L290 TraceCheckUtils]: 2: Hoare triple {391#true} assume true; {391#true} is VALID [2022-02-20 17:56:00,037 INFO L284 TraceCheckUtils]: 3: Hoare quadruple {391#true} {392#false} #1055#return; {392#false} is VALID [2022-02-20 17:56:00,037 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 75 [2022-02-20 17:56:00,039 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-02-20 17:56:00,042 INFO L290 TraceCheckUtils]: 0: Hoare triple {391#true} ~handle := #in~handle;~userid := #in~userid;havoc ~retValue_acc~29; {391#true} is VALID [2022-02-20 17:56:00,042 INFO L290 TraceCheckUtils]: 1: Hoare triple {391#true} assume 1 == ~handle; {391#true} is VALID [2022-02-20 17:56:00,042 INFO L290 TraceCheckUtils]: 2: Hoare triple {391#true} assume ~userid == ~__ste_Client_Keyring0_User0~0;~retValue_acc~29 := ~__ste_Client_Keyring0_PublicKey0~0;#res := ~retValue_acc~29; {391#true} is VALID [2022-02-20 17:56:00,043 INFO L290 TraceCheckUtils]: 3: Hoare triple {391#true} assume true; {391#true} is VALID [2022-02-20 17:56:00,043 INFO L284 TraceCheckUtils]: 4: Hoare quadruple {391#true} {392#false} #1057#return; {392#false} is VALID [2022-02-20 17:56:00,043 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 86 [2022-02-20 17:56:00,044 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-02-20 17:56:00,047 INFO L290 TraceCheckUtils]: 0: Hoare triple {451#(and (= |old(~__ste_email_from0~0)| ~__ste_email_from0~0) (= |old(~__ste_email_from1~0)| ~__ste_email_from1~0))} ~handle := #in~handle;~value := #in~value; {391#true} is VALID [2022-02-20 17:56:00,048 INFO L290 TraceCheckUtils]: 1: Hoare triple {391#true} assume 1 == ~handle;~__ste_email_from0~0 := ~value; {391#true} is VALID [2022-02-20 17:56:00,048 INFO L290 TraceCheckUtils]: 2: Hoare triple {391#true} assume true; {391#true} is VALID [2022-02-20 17:56:00,048 INFO L284 TraceCheckUtils]: 3: Hoare quadruple {391#true} {392#false} #1063#return; {392#false} is VALID [2022-02-20 17:56:00,048 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 93 [2022-02-20 17:56:00,049 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-02-20 17:56:00,051 INFO L290 TraceCheckUtils]: 0: Hoare triple {391#true} ~handle := #in~handle;havoc ~retValue_acc~39; {391#true} is VALID [2022-02-20 17:56:00,051 INFO L290 TraceCheckUtils]: 1: Hoare triple {391#true} assume 1 == ~handle;~retValue_acc~39 := ~__ste_email_isEncrypted0~0;#res := ~retValue_acc~39; {391#true} is VALID [2022-02-20 17:56:00,052 INFO L290 TraceCheckUtils]: 2: Hoare triple {391#true} assume true; {391#true} is VALID [2022-02-20 17:56:00,052 INFO L284 TraceCheckUtils]: 3: Hoare quadruple {391#true} {392#false} #1067#return; {392#false} is VALID [2022-02-20 17:56:00,053 INFO L290 TraceCheckUtils]: 0: Hoare triple {391#true} assume { :begin_inline_ULTIMATE.init } true;#NULL.base, #NULL.offset := 0, 0;assume 0 == #valid[0];assume 0 < #StackHeapBarrier;call #Ultimate.allocInit(2, 1);call write~init~int(48, 1, 0, 1);call write~init~int(0, 1, 1, 1);call #Ultimate.allocInit(28, 2);call #Ultimate.allocInit(12, 3);call #Ultimate.allocInit(4, 4);call write~init~int(37, 4, 0, 1);call write~init~int(115, 4, 1, 1);call write~init~int(10, 4, 2, 1);call write~init~int(0, 4, 3, 1);call #Ultimate.allocInit(10, 5);call #Ultimate.allocInit(12, 6);call #Ultimate.allocInit(10, 7);call #Ultimate.allocInit(18, 8);call #Ultimate.allocInit(16, 9);call #Ultimate.allocInit(21, 10);call #Ultimate.allocInit(13, 11);call #Ultimate.allocInit(16, 12);call #Ultimate.allocInit(25, 13);call #Ultimate.allocInit(30, 14);call #Ultimate.allocInit(9, 15);call #Ultimate.allocInit(21, 16);call #Ultimate.allocInit(30, 17);call #Ultimate.allocInit(9, 18);call #Ultimate.allocInit(21, 19);call #Ultimate.allocInit(30, 20);call #Ultimate.allocInit(9, 21);call #Ultimate.allocInit(25, 22);call #Ultimate.allocInit(30, 23);call #Ultimate.allocInit(9, 24);call #Ultimate.allocInit(25, 25);call #Ultimate.allocInit(10, 26);call #Ultimate.allocInit(16, 27);call #Ultimate.allocInit(20, 28);call #Ultimate.allocInit(22, 29);call #Ultimate.allocInit(21, 30);call #Ultimate.allocInit(13, 31);call #Ultimate.allocInit(44, 32);call #Ultimate.allocInit(44, 33);call #Ultimate.allocInit(9, 34);call #Ultimate.allocInit(9, 35);call #Ultimate.allocInit(11, 36);call #Ultimate.allocInit(19, 37);call #Ultimate.allocInit(4, 38);call write~init~int(37, 38, 0, 1);call write~init~int(100, 38, 1, 1);call write~init~int(10, 38, 2, 1);call write~init~int(0, 38, 3, 1);call #Ultimate.allocInit(4, 39);call write~init~int(37, 39, 0, 1);call write~init~int(100, 39, 1, 1);call write~init~int(10, 39, 2, 1);call write~init~int(0, 39, 3, 1);~__SELECTED_FEATURE_Base~0 := 0;~__SELECTED_FEATURE_Keys~0 := 0;~__SELECTED_FEATURE_Encrypt~0 := 0;~__SELECTED_FEATURE_AutoResponder~0 := 0;~__SELECTED_FEATURE_AddressBook~0 := 0;~__SELECTED_FEATURE_Sign~0 := 0;~__SELECTED_FEATURE_Forward~0 := 0;~__SELECTED_FEATURE_Verify~0 := 0;~__SELECTED_FEATURE_Decrypt~0 := 0;~__GUIDSL_ROOT_PRODUCTION~0 := 0;~__GUIDSL_NON_TERMINAL_main~0 := 0;~head~0.base, ~head~0.offset := 0, 0;~queue_empty~0 := 1;~queued_message~0 := 0;~queued_client~0 := 0;~mail_is_sensitive~0 := -1;~__ste_Client_counter~0 := 0;~__ste_client_name0~0.base, ~__ste_client_name0~0.offset := 0, 0;~__ste_client_name1~0.base, ~__ste_client_name1~0.offset := 0, 0;~__ste_client_name2~0.base, ~__ste_client_name2~0.offset := 0, 0;~__ste_client_outbuffer0~0 := 0;~__ste_client_outbuffer1~0 := 0;~__ste_client_outbuffer2~0 := 0;~__ste_client_outbuffer3~0 := 0;~__ste_ClientAddressBook_size0~0 := 0;~__ste_ClientAddressBook_size1~0 := 0;~__ste_ClientAddressBook_size2~0 := 0;~__ste_Client_AddressBook0_Alias0~0 := 0;~__ste_Client_AddressBook0_Alias1~0 := 0;~__ste_Client_AddressBook0_Alias2~0 := 0;~__ste_Client_AddressBook1_Alias0~0 := 0;~__ste_Client_AddressBook1_Alias1~0 := 0;~__ste_Client_AddressBook1_Alias2~0 := 0;~__ste_Client_AddressBook2_Alias0~0 := 0;~__ste_Client_AddressBook2_Alias1~0 := 0;~__ste_Client_AddressBook2_Alias2~0 := 0;~__ste_Client_AddressBook0_Address0~0 := 0;~__ste_Client_AddressBook0_Address1~0 := 0;~__ste_Client_AddressBook0_Address2~0 := 0;~__ste_Client_AddressBook1_Address0~0 := 0;~__ste_Client_AddressBook1_Address1~0 := 0;~__ste_Client_AddressBook1_Address2~0 := 0;~__ste_Client_AddressBook2_Address0~0 := 0;~__ste_Client_AddressBook2_Address1~0 := 0;~__ste_Client_AddressBook2_Address2~0 := 0;~__ste_client_autoResponse0~0 := 0;~__ste_client_autoResponse1~0 := 0;~__ste_client_autoResponse2~0 := 0;~__ste_client_privateKey0~0 := 0;~__ste_client_privateKey1~0 := 0;~__ste_client_privateKey2~0 := 0;~__ste_ClientKeyring_size0~0 := 0;~__ste_ClientKeyring_size1~0 := 0;~__ste_ClientKeyring_size2~0 := 0;~__ste_Client_Keyring0_User0~0 := 0;~__ste_Client_Keyring0_User1~0 := 0;~__ste_Client_Keyring0_User2~0 := 0;~__ste_Client_Keyring1_User0~0 := 0;~__ste_Client_Keyring1_User1~0 := 0;~__ste_Client_Keyring1_User2~0 := 0;~__ste_Client_Keyring2_User0~0 := 0;~__ste_Client_Keyring2_User1~0 := 0;~__ste_Client_Keyring2_User2~0 := 0;~__ste_Client_Keyring0_PublicKey0~0 := 0;~__ste_Client_Keyring0_PublicKey1~0 := 0;~__ste_Client_Keyring0_PublicKey2~0 := 0;~__ste_Client_Keyring1_PublicKey0~0 := 0;~__ste_Client_Keyring1_PublicKey1~0 := 0;~__ste_Client_Keyring1_PublicKey2~0 := 0;~__ste_Client_Keyring2_PublicKey0~0 := 0;~__ste_Client_Keyring2_PublicKey1~0 := 0;~__ste_Client_Keyring2_PublicKey2~0 := 0;~__ste_client_forwardReceiver0~0 := 0;~__ste_client_forwardReceiver1~0 := 0;~__ste_client_forwardReceiver2~0 := 0;~__ste_client_forwardReceiver3~0 := 0;~__ste_client_idCounter0~0 := 0;~__ste_client_idCounter1~0 := 0;~__ste_client_idCounter2~0 := 0;~bob~0 := 0;~rjh~0 := 0;~chuck~0 := 0;~__ste_Email_counter~0 := 0;~__ste_email_id0~0 := 0;~__ste_email_id1~0 := 0;~__ste_email_from0~0 := 0;~__ste_email_from1~0 := 0;~__ste_email_to0~0 := 0;~__ste_email_to1~0 := 0;~__ste_email_subject0~0.base, ~__ste_email_subject0~0.offset := 0, 0;~__ste_email_subject1~0.base, ~__ste_email_subject1~0.offset := 0, 0;~__ste_email_body0~0.base, ~__ste_email_body0~0.offset := 0, 0;~__ste_email_body1~0.base, ~__ste_email_body1~0.offset := 0, 0;~__ste_email_isEncrypted0~0 := 0;~__ste_email_isEncrypted1~0 := 0;~__ste_email_encryptionKey0~0 := 0;~__ste_email_encryptionKey1~0 := 0;~__ste_email_isSigned0~0 := 0;~__ste_email_isSigned1~0 := 0;~__ste_email_signKey0~0 := 0;~__ste_email_signKey1~0 := 0;~__ste_email_isSignatureVerified0~0 := 0;~__ste_email_isSignatureVerified1~0 := 0; {391#true} is VALID [2022-02-20 17:56:00,053 INFO L290 TraceCheckUtils]: 1: Hoare triple {391#true} assume { :end_inline_ULTIMATE.init } true;assume { :begin_inline_main } true;havoc main_#res#1;havoc main_#t~ret98#1, main_~retValue_acc~32#1, main_~tmp~24#1;havoc main_~retValue_acc~32#1;havoc main_~tmp~24#1;assume { :begin_inline_select_helpers } true; {391#true} is VALID [2022-02-20 17:56:00,053 INFO L290 TraceCheckUtils]: 2: Hoare triple {391#true} assume { :end_inline_select_helpers } true;assume { :begin_inline_select_features } true; {391#true} is VALID [2022-02-20 17:56:00,053 INFO L290 TraceCheckUtils]: 3: Hoare triple {391#true} assume { :end_inline_select_features } true;assume { :begin_inline_valid_product } true;havoc valid_product_#res#1;havoc valid_product_~retValue_acc~9#1;havoc valid_product_~retValue_acc~9#1;valid_product_~retValue_acc~9#1 := 1;valid_product_#res#1 := valid_product_~retValue_acc~9#1; {391#true} is VALID [2022-02-20 17:56:00,053 INFO L290 TraceCheckUtils]: 4: Hoare triple {391#true} main_#t~ret98#1 := valid_product_#res#1;assume { :end_inline_valid_product } true;assume -2147483648 <= main_#t~ret98#1 && main_#t~ret98#1 <= 2147483647;main_~tmp~24#1 := main_#t~ret98#1;havoc main_#t~ret98#1; {391#true} is VALID [2022-02-20 17:56:00,054 INFO L290 TraceCheckUtils]: 5: Hoare triple {391#true} assume 0 != main_~tmp~24#1;assume { :begin_inline_setup } true;havoc setup_#t~nondet95#1, setup_#t~nondet96#1, setup_#t~nondet97#1, setup_~__cil_tmp1~0#1.base, setup_~__cil_tmp1~0#1.offset, setup_~__cil_tmp2~0#1.base, setup_~__cil_tmp2~0#1.offset, setup_~__cil_tmp3~2#1.base, setup_~__cil_tmp3~2#1.offset;havoc setup_~__cil_tmp1~0#1.base, setup_~__cil_tmp1~0#1.offset;havoc setup_~__cil_tmp2~0#1.base, setup_~__cil_tmp2~0#1.offset;havoc setup_~__cil_tmp3~2#1.base, setup_~__cil_tmp3~2#1.offset;~bob~0 := 1;assume { :begin_inline_setup_bob } true;setup_bob_#in~bob___0#1 := ~bob~0;havoc setup_bob_~bob___0#1;setup_bob_~bob___0#1 := setup_bob_#in~bob___0#1;assume { :begin_inline_setup_bob__wrappee__Base } true;setup_bob__wrappee__Base_#in~bob___0#1 := setup_bob_~bob___0#1;havoc setup_bob__wrappee__Base_~bob___0#1;setup_bob__wrappee__Base_~bob___0#1 := setup_bob__wrappee__Base_#in~bob___0#1; {391#true} is VALID [2022-02-20 17:56:00,054 INFO L272 TraceCheckUtils]: 6: Hoare triple {391#true} call setClientId(setup_bob__wrappee__Base_~bob___0#1, setup_bob__wrappee__Base_~bob___0#1); {447#(and (= |old(~__ste_client_idCounter0~0)| ~__ste_client_idCounter0~0) (= |old(~__ste_client_idCounter1~0)| ~__ste_client_idCounter1~0) (= |old(~__ste_client_idCounter2~0)| ~__ste_client_idCounter2~0))} is VALID [2022-02-20 17:56:00,055 INFO L290 TraceCheckUtils]: 7: Hoare triple {447#(and (= |old(~__ste_client_idCounter0~0)| ~__ste_client_idCounter0~0) (= |old(~__ste_client_idCounter1~0)| ~__ste_client_idCounter1~0) (= |old(~__ste_client_idCounter2~0)| ~__ste_client_idCounter2~0))} ~handle := #in~handle;~value := #in~value; {391#true} is VALID [2022-02-20 17:56:00,055 INFO L290 TraceCheckUtils]: 8: Hoare triple {391#true} assume 1 == ~handle;~__ste_client_idCounter0~0 := ~value; {391#true} is VALID [2022-02-20 17:56:00,055 INFO L290 TraceCheckUtils]: 9: Hoare triple {391#true} assume true; {391#true} is VALID [2022-02-20 17:56:00,055 INFO L284 TraceCheckUtils]: 10: Hoare quadruple {391#true} {391#true} #1133#return; {391#true} is VALID [2022-02-20 17:56:00,055 INFO L290 TraceCheckUtils]: 11: Hoare triple {391#true} assume { :end_inline_setup_bob__wrappee__Base } true; {391#true} is VALID [2022-02-20 17:56:00,056 INFO L272 TraceCheckUtils]: 12: Hoare triple {391#true} call setClientPrivateKey(setup_bob_~bob___0#1, 123); {448#(and (= ~__ste_client_privateKey0~0 |old(~__ste_client_privateKey0~0)|) (= ~__ste_client_privateKey2~0 |old(~__ste_client_privateKey2~0)|) (= ~__ste_client_privateKey1~0 |old(~__ste_client_privateKey1~0)|))} is VALID [2022-02-20 17:56:00,056 INFO L290 TraceCheckUtils]: 13: Hoare triple {448#(and (= ~__ste_client_privateKey0~0 |old(~__ste_client_privateKey0~0)|) (= ~__ste_client_privateKey2~0 |old(~__ste_client_privateKey2~0)|) (= ~__ste_client_privateKey1~0 |old(~__ste_client_privateKey1~0)|))} ~handle := #in~handle;~value := #in~value; {391#true} is VALID [2022-02-20 17:56:00,056 INFO L290 TraceCheckUtils]: 14: Hoare triple {391#true} assume 1 == ~handle;~__ste_client_privateKey0~0 := ~value; {391#true} is VALID [2022-02-20 17:56:00,057 INFO L290 TraceCheckUtils]: 15: Hoare triple {391#true} assume true; {391#true} is VALID [2022-02-20 17:56:00,057 INFO L284 TraceCheckUtils]: 16: Hoare quadruple {391#true} {391#true} #1135#return; {391#true} is VALID [2022-02-20 17:56:00,057 INFO L290 TraceCheckUtils]: 17: Hoare triple {391#true} assume { :end_inline_setup_bob } true;setup_~__cil_tmp1~0#1.base, setup_~__cil_tmp1~0#1.offset := 34, 0;havoc setup_#t~nondet95#1;~rjh~0 := 2;assume { :begin_inline_setup_rjh } true;setup_rjh_#in~rjh___0#1 := ~rjh~0;havoc setup_rjh_~rjh___0#1;setup_rjh_~rjh___0#1 := setup_rjh_#in~rjh___0#1;assume { :begin_inline_setup_rjh__wrappee__Base } true;setup_rjh__wrappee__Base_#in~rjh___0#1 := setup_rjh_~rjh___0#1;havoc setup_rjh__wrappee__Base_~rjh___0#1;setup_rjh__wrappee__Base_~rjh___0#1 := setup_rjh__wrappee__Base_#in~rjh___0#1; {401#(= |ULTIMATE.start_setup_rjh__wrappee__Base_~rjh___0#1| 2)} is VALID [2022-02-20 17:56:00,058 INFO L272 TraceCheckUtils]: 18: Hoare triple {401#(= |ULTIMATE.start_setup_rjh__wrappee__Base_~rjh___0#1| 2)} call setClientId(setup_rjh__wrappee__Base_~rjh___0#1, setup_rjh__wrappee__Base_~rjh___0#1); {447#(and (= |old(~__ste_client_idCounter0~0)| ~__ste_client_idCounter0~0) (= |old(~__ste_client_idCounter1~0)| ~__ste_client_idCounter1~0) (= |old(~__ste_client_idCounter2~0)| ~__ste_client_idCounter2~0))} is VALID [2022-02-20 17:56:00,058 INFO L290 TraceCheckUtils]: 19: Hoare triple {447#(and (= |old(~__ste_client_idCounter0~0)| ~__ste_client_idCounter0~0) (= |old(~__ste_client_idCounter1~0)| ~__ste_client_idCounter1~0) (= |old(~__ste_client_idCounter2~0)| ~__ste_client_idCounter2~0))} ~handle := #in~handle;~value := #in~value; {449#(= setClientId_~handle |setClientId_#in~handle|)} is VALID [2022-02-20 17:56:00,059 INFO L290 TraceCheckUtils]: 20: Hoare triple {449#(= setClientId_~handle |setClientId_#in~handle|)} assume 1 == ~handle;~__ste_client_idCounter0~0 := ~value; {450#(= |setClientId_#in~handle| 1)} is VALID [2022-02-20 17:56:00,059 INFO L290 TraceCheckUtils]: 21: Hoare triple {450#(= |setClientId_#in~handle| 1)} assume true; {450#(= |setClientId_#in~handle| 1)} is VALID [2022-02-20 17:56:00,060 INFO L284 TraceCheckUtils]: 22: Hoare quadruple {450#(= |setClientId_#in~handle| 1)} {401#(= |ULTIMATE.start_setup_rjh__wrappee__Base_~rjh___0#1| 2)} #1137#return; {392#false} is VALID [2022-02-20 17:56:00,060 INFO L290 TraceCheckUtils]: 23: Hoare triple {392#false} assume { :end_inline_setup_rjh__wrappee__Base } true; {392#false} is VALID [2022-02-20 17:56:00,060 INFO L272 TraceCheckUtils]: 24: Hoare triple {392#false} call setClientPrivateKey(setup_rjh_~rjh___0#1, 456); {448#(and (= ~__ste_client_privateKey0~0 |old(~__ste_client_privateKey0~0)|) (= ~__ste_client_privateKey2~0 |old(~__ste_client_privateKey2~0)|) (= ~__ste_client_privateKey1~0 |old(~__ste_client_privateKey1~0)|))} is VALID [2022-02-20 17:56:00,060 INFO L290 TraceCheckUtils]: 25: Hoare triple {448#(and (= ~__ste_client_privateKey0~0 |old(~__ste_client_privateKey0~0)|) (= ~__ste_client_privateKey2~0 |old(~__ste_client_privateKey2~0)|) (= ~__ste_client_privateKey1~0 |old(~__ste_client_privateKey1~0)|))} ~handle := #in~handle;~value := #in~value; {391#true} is VALID [2022-02-20 17:56:00,061 INFO L290 TraceCheckUtils]: 26: Hoare triple {391#true} assume 1 == ~handle;~__ste_client_privateKey0~0 := ~value; {391#true} is VALID [2022-02-20 17:56:00,061 INFO L290 TraceCheckUtils]: 27: Hoare triple {391#true} assume true; {391#true} is VALID [2022-02-20 17:56:00,061 INFO L284 TraceCheckUtils]: 28: Hoare quadruple {391#true} {392#false} #1139#return; {392#false} is VALID [2022-02-20 17:56:00,061 INFO L290 TraceCheckUtils]: 29: Hoare triple {392#false} assume { :end_inline_setup_rjh } true;setup_~__cil_tmp2~0#1.base, setup_~__cil_tmp2~0#1.offset := 35, 0;havoc setup_#t~nondet96#1;~chuck~0 := 3;assume { :begin_inline_setup_chuck } true;setup_chuck_#in~chuck___0#1 := ~chuck~0;havoc setup_chuck_~chuck___0#1;setup_chuck_~chuck___0#1 := setup_chuck_#in~chuck___0#1;assume { :begin_inline_setup_chuck__wrappee__Base } true;setup_chuck__wrappee__Base_#in~chuck___0#1 := setup_chuck_~chuck___0#1;havoc setup_chuck__wrappee__Base_~chuck___0#1;setup_chuck__wrappee__Base_~chuck___0#1 := setup_chuck__wrappee__Base_#in~chuck___0#1; {392#false} is VALID [2022-02-20 17:56:00,061 INFO L272 TraceCheckUtils]: 30: Hoare triple {392#false} call setClientId(setup_chuck__wrappee__Base_~chuck___0#1, setup_chuck__wrappee__Base_~chuck___0#1); {447#(and (= |old(~__ste_client_idCounter0~0)| ~__ste_client_idCounter0~0) (= |old(~__ste_client_idCounter1~0)| ~__ste_client_idCounter1~0) (= |old(~__ste_client_idCounter2~0)| ~__ste_client_idCounter2~0))} is VALID [2022-02-20 17:56:00,062 INFO L290 TraceCheckUtils]: 31: Hoare triple {447#(and (= |old(~__ste_client_idCounter0~0)| ~__ste_client_idCounter0~0) (= |old(~__ste_client_idCounter1~0)| ~__ste_client_idCounter1~0) (= |old(~__ste_client_idCounter2~0)| ~__ste_client_idCounter2~0))} ~handle := #in~handle;~value := #in~value; {391#true} is VALID [2022-02-20 17:56:00,062 INFO L290 TraceCheckUtils]: 32: Hoare triple {391#true} assume 1 == ~handle;~__ste_client_idCounter0~0 := ~value; {391#true} is VALID [2022-02-20 17:56:00,062 INFO L290 TraceCheckUtils]: 33: Hoare triple {391#true} assume true; {391#true} is VALID [2022-02-20 17:56:00,062 INFO L284 TraceCheckUtils]: 34: Hoare quadruple {391#true} {392#false} #1141#return; {392#false} is VALID [2022-02-20 17:56:00,062 INFO L290 TraceCheckUtils]: 35: Hoare triple {392#false} assume { :end_inline_setup_chuck__wrappee__Base } true; {392#false} is VALID [2022-02-20 17:56:00,062 INFO L272 TraceCheckUtils]: 36: Hoare triple {392#false} call setClientPrivateKey(setup_chuck_~chuck___0#1, 789); {448#(and (= ~__ste_client_privateKey0~0 |old(~__ste_client_privateKey0~0)|) (= ~__ste_client_privateKey2~0 |old(~__ste_client_privateKey2~0)|) (= ~__ste_client_privateKey1~0 |old(~__ste_client_privateKey1~0)|))} is VALID [2022-02-20 17:56:00,063 INFO L290 TraceCheckUtils]: 37: Hoare triple {448#(and (= ~__ste_client_privateKey0~0 |old(~__ste_client_privateKey0~0)|) (= ~__ste_client_privateKey2~0 |old(~__ste_client_privateKey2~0)|) (= ~__ste_client_privateKey1~0 |old(~__ste_client_privateKey1~0)|))} ~handle := #in~handle;~value := #in~value; {391#true} is VALID [2022-02-20 17:56:00,063 INFO L290 TraceCheckUtils]: 38: Hoare triple {391#true} assume 1 == ~handle;~__ste_client_privateKey0~0 := ~value; {391#true} is VALID [2022-02-20 17:56:00,063 INFO L290 TraceCheckUtils]: 39: Hoare triple {391#true} assume true; {391#true} is VALID [2022-02-20 17:56:00,063 INFO L284 TraceCheckUtils]: 40: Hoare quadruple {391#true} {392#false} #1143#return; {392#false} is VALID [2022-02-20 17:56:00,063 INFO L290 TraceCheckUtils]: 41: Hoare triple {392#false} assume { :end_inline_setup_chuck } true;setup_~__cil_tmp3~2#1.base, setup_~__cil_tmp3~2#1.offset := 36, 0;havoc setup_#t~nondet97#1; {392#false} is VALID [2022-02-20 17:56:00,064 INFO L290 TraceCheckUtils]: 42: Hoare triple {392#false} assume { :end_inline_setup } true;assume { :begin_inline_test } true;havoc test_#t~nondet48#1, test_#t~nondet49#1, test_#t~nondet50#1, test_#t~nondet51#1, test_#t~nondet52#1, test_#t~nondet53#1, test_#t~nondet54#1, test_#t~nondet55#1, test_#t~nondet56#1, test_#t~nondet57#1, test_#t~nondet58#1, test_~op1~0#1, test_~op2~0#1, test_~op3~0#1, test_~op4~0#1, test_~op5~0#1, test_~op6~0#1, test_~op7~0#1, test_~op8~0#1, test_~op9~0#1, test_~op10~0#1, test_~op11~0#1, test_~splverifierCounter~0#1, test_~tmp~8#1, test_~tmp___0~3#1, test_~tmp___1~1#1, test_~tmp___2~1#1, test_~tmp___3~0#1, test_~tmp___4~0#1, test_~tmp___5~0#1, test_~tmp___6~0#1, test_~tmp___7~0#1, test_~tmp___8~0#1, test_~tmp___9~0#1;havoc test_~op1~0#1;havoc test_~op2~0#1;havoc test_~op3~0#1;havoc test_~op4~0#1;havoc test_~op5~0#1;havoc test_~op6~0#1;havoc test_~op7~0#1;havoc test_~op8~0#1;havoc test_~op9~0#1;havoc test_~op10~0#1;havoc test_~op11~0#1;havoc test_~splverifierCounter~0#1;havoc test_~tmp~8#1;havoc test_~tmp___0~3#1;havoc test_~tmp___1~1#1;havoc test_~tmp___2~1#1;havoc test_~tmp___3~0#1;havoc test_~tmp___4~0#1;havoc test_~tmp___5~0#1;havoc test_~tmp___6~0#1;havoc test_~tmp___7~0#1;havoc test_~tmp___8~0#1;havoc test_~tmp___9~0#1;test_~op1~0#1 := 0;test_~op2~0#1 := 0;test_~op3~0#1 := 0;test_~op4~0#1 := 0;test_~op5~0#1 := 0;test_~op6~0#1 := 0;test_~op7~0#1 := 0;test_~op8~0#1 := 0;test_~op9~0#1 := 0;test_~op10~0#1 := 0;test_~op11~0#1 := 0;test_~splverifierCounter~0#1 := 0; {392#false} is VALID [2022-02-20 17:56:00,064 INFO L290 TraceCheckUtils]: 43: Hoare triple {392#false} assume !true; {392#false} is VALID [2022-02-20 17:56:00,064 INFO L290 TraceCheckUtils]: 44: Hoare triple {392#false} assume { :begin_inline_bobToRjh } true;havoc bobToRjh_#t~ret90#1, bobToRjh_#t~ret91#1, bobToRjh_#t~ret92#1, bobToRjh_#t~ret93#1, bobToRjh_~tmp~23#1, bobToRjh_~tmp___0~7#1, bobToRjh_~tmp___1~4#1;havoc bobToRjh_~tmp~23#1;havoc bobToRjh_~tmp___0~7#1;havoc bobToRjh_~tmp___1~4#1;call bobToRjh_#t~ret90#1 := puts(32, 0);assume -2147483648 <= bobToRjh_#t~ret90#1 && bobToRjh_#t~ret90#1 <= 2147483647;havoc bobToRjh_#t~ret90#1; {392#false} is VALID [2022-02-20 17:56:00,064 INFO L272 TraceCheckUtils]: 45: Hoare triple {392#false} call sendEmail(~bob~0, ~rjh~0); {392#false} is VALID [2022-02-20 17:56:00,064 INFO L290 TraceCheckUtils]: 46: Hoare triple {392#false} ~sender#1 := #in~sender#1;~receiver#1 := #in~receiver#1;havoc ~email~0#1;havoc ~tmp~16#1;assume { :begin_inline_createEmail } true;createEmail_#in~from#1, createEmail_#in~to#1 := 0, ~receiver#1;havoc createEmail_#res#1;havoc createEmail_~from#1, createEmail_~to#1, createEmail_~retValue_acc~4#1, createEmail_~msg~0#1;createEmail_~from#1 := createEmail_#in~from#1;createEmail_~to#1 := createEmail_#in~to#1;havoc createEmail_~retValue_acc~4#1;havoc createEmail_~msg~0#1;createEmail_~msg~0#1 := 1; {392#false} is VALID [2022-02-20 17:56:00,065 INFO L272 TraceCheckUtils]: 47: Hoare triple {392#false} call setEmailFrom(createEmail_~msg~0#1, createEmail_~from#1); {451#(and (= |old(~__ste_email_from0~0)| ~__ste_email_from0~0) (= |old(~__ste_email_from1~0)| ~__ste_email_from1~0))} is VALID [2022-02-20 17:56:00,065 INFO L290 TraceCheckUtils]: 48: Hoare triple {451#(and (= |old(~__ste_email_from0~0)| ~__ste_email_from0~0) (= |old(~__ste_email_from1~0)| ~__ste_email_from1~0))} ~handle := #in~handle;~value := #in~value; {391#true} is VALID [2022-02-20 17:56:00,065 INFO L290 TraceCheckUtils]: 49: Hoare triple {391#true} assume 1 == ~handle;~__ste_email_from0~0 := ~value; {391#true} is VALID [2022-02-20 17:56:00,065 INFO L290 TraceCheckUtils]: 50: Hoare triple {391#true} assume true; {391#true} is VALID [2022-02-20 17:56:00,065 INFO L284 TraceCheckUtils]: 51: Hoare quadruple {391#true} {392#false} #1119#return; {392#false} is VALID [2022-02-20 17:56:00,065 INFO L272 TraceCheckUtils]: 52: Hoare triple {392#false} call setEmailTo(createEmail_~msg~0#1, createEmail_~to#1); {452#(and (= ~__ste_email_to0~0 |old(~__ste_email_to0~0)|) (= ~__ste_email_to1~0 |old(~__ste_email_to1~0)|))} is VALID [2022-02-20 17:56:00,066 INFO L290 TraceCheckUtils]: 53: Hoare triple {452#(and (= ~__ste_email_to0~0 |old(~__ste_email_to0~0)|) (= ~__ste_email_to1~0 |old(~__ste_email_to1~0)|))} ~handle := #in~handle;~value := #in~value; {391#true} is VALID [2022-02-20 17:56:00,066 INFO L290 TraceCheckUtils]: 54: Hoare triple {391#true} assume 1 == ~handle;~__ste_email_to0~0 := ~value; {391#true} is VALID [2022-02-20 17:56:00,066 INFO L290 TraceCheckUtils]: 55: Hoare triple {391#true} assume true; {391#true} is VALID [2022-02-20 17:56:00,066 INFO L284 TraceCheckUtils]: 56: Hoare quadruple {391#true} {392#false} #1121#return; {392#false} is VALID [2022-02-20 17:56:00,066 INFO L290 TraceCheckUtils]: 57: Hoare triple {392#false} createEmail_~retValue_acc~4#1 := createEmail_~msg~0#1;createEmail_#res#1 := createEmail_~retValue_acc~4#1; {392#false} is VALID [2022-02-20 17:56:00,067 INFO L290 TraceCheckUtils]: 58: Hoare triple {392#false} #t~ret73#1 := createEmail_#res#1;assume { :end_inline_createEmail } true;assume -2147483648 <= #t~ret73#1 && #t~ret73#1 <= 2147483647;~tmp~16#1 := #t~ret73#1;havoc #t~ret73#1;~email~0#1 := ~tmp~16#1; {392#false} is VALID [2022-02-20 17:56:00,067 INFO L272 TraceCheckUtils]: 59: Hoare triple {392#false} call outgoing(~sender#1, ~email~0#1); {392#false} is VALID [2022-02-20 17:56:00,067 INFO L290 TraceCheckUtils]: 60: Hoare triple {392#false} ~client#1 := #in~client#1;~msg#1 := #in~msg#1;assume { :begin_inline_sign } true;sign_#in~client#1, sign_#in~msg#1 := ~client#1, ~msg#1;havoc sign_#t~ret77#1, sign_~client#1, sign_~msg#1, sign_~privkey~1#1, sign_~tmp~18#1;sign_~client#1 := sign_#in~client#1;sign_~msg#1 := sign_#in~msg#1;havoc sign_~privkey~1#1;havoc sign_~tmp~18#1; {392#false} is VALID [2022-02-20 17:56:00,068 INFO L272 TraceCheckUtils]: 61: Hoare triple {392#false} call sign_#t~ret77#1 := getClientPrivateKey(sign_~client#1); {391#true} is VALID [2022-02-20 17:56:00,069 INFO L290 TraceCheckUtils]: 62: Hoare triple {391#true} ~handle := #in~handle;havoc ~retValue_acc~24; {391#true} is VALID [2022-02-20 17:56:00,069 INFO L290 TraceCheckUtils]: 63: Hoare triple {391#true} assume 1 == ~handle;~retValue_acc~24 := ~__ste_client_privateKey0~0;#res := ~retValue_acc~24; {391#true} is VALID [2022-02-20 17:56:00,069 INFO L290 TraceCheckUtils]: 64: Hoare triple {391#true} assume true; {391#true} is VALID [2022-02-20 17:56:00,070 INFO L284 TraceCheckUtils]: 65: Hoare quadruple {391#true} {392#false} #1053#return; {392#false} is VALID [2022-02-20 17:56:00,071 INFO L290 TraceCheckUtils]: 66: Hoare triple {392#false} assume -2147483648 <= sign_#t~ret77#1 && sign_#t~ret77#1 <= 2147483647;sign_~tmp~18#1 := sign_#t~ret77#1;havoc sign_#t~ret77#1;sign_~privkey~1#1 := sign_~tmp~18#1; {392#false} is VALID [2022-02-20 17:56:00,075 INFO L290 TraceCheckUtils]: 67: Hoare triple {392#false} assume 0 == sign_~privkey~1#1; {392#false} is VALID [2022-02-20 17:56:00,075 INFO L290 TraceCheckUtils]: 68: Hoare triple {392#false} assume { :end_inline_sign } true;assume { :begin_inline_outgoing__wrappee__AutoResponder } true;outgoing__wrappee__AutoResponder_#in~client#1, outgoing__wrappee__AutoResponder_#in~msg#1 := ~client#1, ~msg#1;havoc outgoing__wrappee__AutoResponder_#t~ret63#1, outgoing__wrappee__AutoResponder_#t~ret64#1, outgoing__wrappee__AutoResponder_~client#1, outgoing__wrappee__AutoResponder_~msg#1, outgoing__wrappee__AutoResponder_~receiver~0#1, outgoing__wrappee__AutoResponder_~tmp~11#1, outgoing__wrappee__AutoResponder_~pubkey~0#1, outgoing__wrappee__AutoResponder_~tmp___0~4#1;outgoing__wrappee__AutoResponder_~client#1 := outgoing__wrappee__AutoResponder_#in~client#1;outgoing__wrappee__AutoResponder_~msg#1 := outgoing__wrappee__AutoResponder_#in~msg#1;havoc outgoing__wrappee__AutoResponder_~receiver~0#1;havoc outgoing__wrappee__AutoResponder_~tmp~11#1;havoc outgoing__wrappee__AutoResponder_~pubkey~0#1;havoc outgoing__wrappee__AutoResponder_~tmp___0~4#1; {392#false} is VALID [2022-02-20 17:56:00,075 INFO L272 TraceCheckUtils]: 69: Hoare triple {392#false} call outgoing__wrappee__AutoResponder_#t~ret63#1 := getEmailTo(outgoing__wrappee__AutoResponder_~msg#1); {391#true} is VALID [2022-02-20 17:56:00,076 INFO L290 TraceCheckUtils]: 70: Hoare triple {391#true} ~handle := #in~handle;havoc ~retValue_acc~36; {391#true} is VALID [2022-02-20 17:56:00,076 INFO L290 TraceCheckUtils]: 71: Hoare triple {391#true} assume 1 == ~handle;~retValue_acc~36 := ~__ste_email_to0~0;#res := ~retValue_acc~36; {391#true} is VALID [2022-02-20 17:56:00,076 INFO L290 TraceCheckUtils]: 72: Hoare triple {391#true} assume true; {391#true} is VALID [2022-02-20 17:56:00,076 INFO L284 TraceCheckUtils]: 73: Hoare quadruple {391#true} {392#false} #1055#return; {392#false} is VALID [2022-02-20 17:56:00,076 INFO L290 TraceCheckUtils]: 74: Hoare triple {392#false} assume -2147483648 <= outgoing__wrappee__AutoResponder_#t~ret63#1 && outgoing__wrappee__AutoResponder_#t~ret63#1 <= 2147483647;outgoing__wrappee__AutoResponder_~tmp~11#1 := outgoing__wrappee__AutoResponder_#t~ret63#1;havoc outgoing__wrappee__AutoResponder_#t~ret63#1;outgoing__wrappee__AutoResponder_~receiver~0#1 := outgoing__wrappee__AutoResponder_~tmp~11#1; {392#false} is VALID [2022-02-20 17:56:00,077 INFO L272 TraceCheckUtils]: 75: Hoare triple {392#false} call outgoing__wrappee__AutoResponder_#t~ret64#1 := findPublicKey(outgoing__wrappee__AutoResponder_~client#1, outgoing__wrappee__AutoResponder_~receiver~0#1); {391#true} is VALID [2022-02-20 17:56:00,077 INFO L290 TraceCheckUtils]: 76: Hoare triple {391#true} ~handle := #in~handle;~userid := #in~userid;havoc ~retValue_acc~29; {391#true} is VALID [2022-02-20 17:56:00,077 INFO L290 TraceCheckUtils]: 77: Hoare triple {391#true} assume 1 == ~handle; {391#true} is VALID [2022-02-20 17:56:00,077 INFO L290 TraceCheckUtils]: 78: Hoare triple {391#true} assume ~userid == ~__ste_Client_Keyring0_User0~0;~retValue_acc~29 := ~__ste_Client_Keyring0_PublicKey0~0;#res := ~retValue_acc~29; {391#true} is VALID [2022-02-20 17:56:00,077 INFO L290 TraceCheckUtils]: 79: Hoare triple {391#true} assume true; {391#true} is VALID [2022-02-20 17:56:00,077 INFO L284 TraceCheckUtils]: 80: Hoare quadruple {391#true} {392#false} #1057#return; {392#false} is VALID [2022-02-20 17:56:00,080 INFO L290 TraceCheckUtils]: 81: Hoare triple {392#false} assume -2147483648 <= outgoing__wrappee__AutoResponder_#t~ret64#1 && outgoing__wrappee__AutoResponder_#t~ret64#1 <= 2147483647;outgoing__wrappee__AutoResponder_~tmp___0~4#1 := outgoing__wrappee__AutoResponder_#t~ret64#1;havoc outgoing__wrappee__AutoResponder_#t~ret64#1;outgoing__wrappee__AutoResponder_~pubkey~0#1 := outgoing__wrappee__AutoResponder_~tmp___0~4#1; {392#false} is VALID [2022-02-20 17:56:00,080 INFO L290 TraceCheckUtils]: 82: Hoare triple {392#false} assume !(0 != outgoing__wrappee__AutoResponder_~pubkey~0#1); {392#false} is VALID [2022-02-20 17:56:00,081 INFO L290 TraceCheckUtils]: 83: Hoare triple {392#false} assume { :begin_inline_outgoing__wrappee__Keys } true;outgoing__wrappee__Keys_#in~client#1, outgoing__wrappee__Keys_#in~msg#1 := outgoing__wrappee__AutoResponder_~client#1, outgoing__wrappee__AutoResponder_~msg#1;havoc outgoing__wrappee__Keys_#t~ret62#1, outgoing__wrappee__Keys_~client#1, outgoing__wrappee__Keys_~msg#1, outgoing__wrappee__Keys_~tmp~10#1;outgoing__wrappee__Keys_~client#1 := outgoing__wrappee__Keys_#in~client#1;outgoing__wrappee__Keys_~msg#1 := outgoing__wrappee__Keys_#in~msg#1;havoc outgoing__wrappee__Keys_~tmp~10#1;assume { :begin_inline_getClientId } true;getClientId_#in~handle#1 := outgoing__wrappee__Keys_~client#1;havoc getClientId_#res#1;havoc getClientId_~handle#1, getClientId_~retValue_acc~31#1;getClientId_~handle#1 := getClientId_#in~handle#1;havoc getClientId_~retValue_acc~31#1; {392#false} is VALID [2022-02-20 17:56:00,081 INFO L290 TraceCheckUtils]: 84: Hoare triple {392#false} assume 1 == getClientId_~handle#1;getClientId_~retValue_acc~31#1 := ~__ste_client_idCounter0~0;getClientId_#res#1 := getClientId_~retValue_acc~31#1; {392#false} is VALID [2022-02-20 17:56:00,081 INFO L290 TraceCheckUtils]: 85: Hoare triple {392#false} outgoing__wrappee__Keys_#t~ret62#1 := getClientId_#res#1;assume { :end_inline_getClientId } true;assume -2147483648 <= outgoing__wrappee__Keys_#t~ret62#1 && outgoing__wrappee__Keys_#t~ret62#1 <= 2147483647;outgoing__wrappee__Keys_~tmp~10#1 := outgoing__wrappee__Keys_#t~ret62#1;havoc outgoing__wrappee__Keys_#t~ret62#1; {392#false} is VALID [2022-02-20 17:56:00,081 INFO L272 TraceCheckUtils]: 86: Hoare triple {392#false} call setEmailFrom(outgoing__wrappee__Keys_~msg#1, outgoing__wrappee__Keys_~tmp~10#1); {451#(and (= |old(~__ste_email_from0~0)| ~__ste_email_from0~0) (= |old(~__ste_email_from1~0)| ~__ste_email_from1~0))} is VALID [2022-02-20 17:56:00,081 INFO L290 TraceCheckUtils]: 87: Hoare triple {451#(and (= |old(~__ste_email_from0~0)| ~__ste_email_from0~0) (= |old(~__ste_email_from1~0)| ~__ste_email_from1~0))} ~handle := #in~handle;~value := #in~value; {391#true} is VALID [2022-02-20 17:56:00,081 INFO L290 TraceCheckUtils]: 88: Hoare triple {391#true} assume 1 == ~handle;~__ste_email_from0~0 := ~value; {391#true} is VALID [2022-02-20 17:56:00,082 INFO L290 TraceCheckUtils]: 89: Hoare triple {391#true} assume true; {391#true} is VALID [2022-02-20 17:56:00,082 INFO L284 TraceCheckUtils]: 90: Hoare quadruple {391#true} {392#false} #1063#return; {392#false} is VALID [2022-02-20 17:56:00,082 INFO L290 TraceCheckUtils]: 91: Hoare triple {392#false} assume { :begin_inline_mail } true;mail_#in~client#1, mail_#in~msg#1 := outgoing__wrappee__Keys_~client#1, outgoing__wrappee__Keys_~msg#1;havoc mail_#t~ret60#1, mail_#t~ret61#1, mail_~client#1, mail_~msg#1, mail_~__utac__ad__arg1~0#1, mail_~__utac__ad__arg2~0#1, mail_~tmp~9#1;mail_~client#1 := mail_#in~client#1;mail_~msg#1 := mail_#in~msg#1;havoc mail_~__utac__ad__arg1~0#1;havoc mail_~__utac__ad__arg2~0#1;havoc mail_~tmp~9#1;mail_~__utac__ad__arg1~0#1 := mail_~client#1;mail_~__utac__ad__arg2~0#1 := mail_~msg#1;assume { :begin_inline___utac_acc__AddressBookEncrypt_spec__1 } true;__utac_acc__AddressBookEncrypt_spec__1_#in~client#1, __utac_acc__AddressBookEncrypt_spec__1_#in~msg#1 := mail_~__utac__ad__arg1~0#1, mail_~__utac__ad__arg2~0#1;havoc __utac_acc__AddressBookEncrypt_spec__1_#t~ret85#1, __utac_acc__AddressBookEncrypt_spec__1_#t~ret86#1, __utac_acc__AddressBookEncrypt_spec__1_#t~ret87#1, __utac_acc__AddressBookEncrypt_spec__1_~client#1, __utac_acc__AddressBookEncrypt_spec__1_~msg#1, __utac_acc__AddressBookEncrypt_spec__1_~tmp~20#1;__utac_acc__AddressBookEncrypt_spec__1_~client#1 := __utac_acc__AddressBookEncrypt_spec__1_#in~client#1;__utac_acc__AddressBookEncrypt_spec__1_~msg#1 := __utac_acc__AddressBookEncrypt_spec__1_#in~msg#1;havoc __utac_acc__AddressBookEncrypt_spec__1_~tmp~20#1;call __utac_acc__AddressBookEncrypt_spec__1_#t~ret85#1 := puts(31, 0);assume -2147483648 <= __utac_acc__AddressBookEncrypt_spec__1_#t~ret85#1 && __utac_acc__AddressBookEncrypt_spec__1_#t~ret85#1 <= 2147483647;havoc __utac_acc__AddressBookEncrypt_spec__1_#t~ret85#1; {392#false} is VALID [2022-02-20 17:56:00,082 INFO L290 TraceCheckUtils]: 92: Hoare triple {392#false} assume !(-1 == ~mail_is_sensitive~0); {392#false} is VALID [2022-02-20 17:56:00,082 INFO L272 TraceCheckUtils]: 93: Hoare triple {392#false} call __utac_acc__AddressBookEncrypt_spec__1_#t~ret87#1 := isEncrypted(__utac_acc__AddressBookEncrypt_spec__1_~msg#1); {391#true} is VALID [2022-02-20 17:56:00,083 INFO L290 TraceCheckUtils]: 94: Hoare triple {391#true} ~handle := #in~handle;havoc ~retValue_acc~39; {391#true} is VALID [2022-02-20 17:56:00,083 INFO L290 TraceCheckUtils]: 95: Hoare triple {391#true} assume 1 == ~handle;~retValue_acc~39 := ~__ste_email_isEncrypted0~0;#res := ~retValue_acc~39; {391#true} is VALID [2022-02-20 17:56:00,083 INFO L290 TraceCheckUtils]: 96: Hoare triple {391#true} assume true; {391#true} is VALID [2022-02-20 17:56:00,083 INFO L284 TraceCheckUtils]: 97: Hoare quadruple {391#true} {392#false} #1067#return; {392#false} is VALID [2022-02-20 17:56:00,083 INFO L290 TraceCheckUtils]: 98: Hoare triple {392#false} assume -2147483648 <= __utac_acc__AddressBookEncrypt_spec__1_#t~ret87#1 && __utac_acc__AddressBookEncrypt_spec__1_#t~ret87#1 <= 2147483647;__utac_acc__AddressBookEncrypt_spec__1_~tmp~20#1 := __utac_acc__AddressBookEncrypt_spec__1_#t~ret87#1;havoc __utac_acc__AddressBookEncrypt_spec__1_#t~ret87#1; {392#false} is VALID [2022-02-20 17:56:00,084 INFO L290 TraceCheckUtils]: 99: Hoare triple {392#false} assume ~mail_is_sensitive~0 != __utac_acc__AddressBookEncrypt_spec__1_~tmp~20#1;assume { :begin_inline___automaton_fail } true; {392#false} is VALID [2022-02-20 17:56:00,084 INFO L290 TraceCheckUtils]: 100: Hoare triple {392#false} assume !false; {392#false} is VALID [2022-02-20 17:56:00,085 INFO L134 CoverageAnalysis]: Checked inductivity of 28 backedges. 3 proven. 3 refuted. 0 times theorem prover too weak. 22 trivial. 0 not checked. [2022-02-20 17:56:00,085 INFO L144 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2022-02-20 17:56:00,085 INFO L338 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [1866383525] [2022-02-20 17:56:00,086 INFO L165 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [1866383525] provided 0 perfect and 1 imperfect interpolant sequences [2022-02-20 17:56:00,086 INFO L338 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleZ3 [919510198] [2022-02-20 17:56:00,086 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-02-20 17:56:00,086 INFO L173 SolverBuilder]: Constructing external solver with command: z3 -smt2 -in SMTLIB2_COMPLIANT=true [2022-02-20 17:56:00,086 INFO L189 MonitoredProcess]: No working directory specified, using /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 [2022-02-20 17:56:00,088 INFO L229 MonitoredProcess]: Starting monitored process 2 with /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 -smt2 -in SMTLIB2_COMPLIANT=true (exit command is (exit), workingDir is null) [2022-02-20 17:56:00,102 INFO L327 MonitoredProcess]: [MP /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 -smt2 -in SMTLIB2_COMPLIANT=true (2)] Waiting until timeout for monitored process [2022-02-20 17:56:00,310 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-02-20 17:56:00,314 INFO L263 TraceCheckSpWp]: Trace formula consists of 1055 conjuncts, 1 conjunts are in the unsatisfiable core [2022-02-20 17:56:00,405 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-02-20 17:56:00,410 INFO L286 TraceCheckSpWp]: Computing forward predicates... [2022-02-20 17:56:00,630 INFO L290 TraceCheckUtils]: 0: Hoare triple {391#true} assume { :begin_inline_ULTIMATE.init } true;#NULL.base, #NULL.offset := 0, 0;assume 0 == #valid[0];assume 0 < #StackHeapBarrier;call #Ultimate.allocInit(2, 1);call write~init~int(48, 1, 0, 1);call write~init~int(0, 1, 1, 1);call #Ultimate.allocInit(28, 2);call #Ultimate.allocInit(12, 3);call #Ultimate.allocInit(4, 4);call write~init~int(37, 4, 0, 1);call write~init~int(115, 4, 1, 1);call write~init~int(10, 4, 2, 1);call write~init~int(0, 4, 3, 1);call #Ultimate.allocInit(10, 5);call #Ultimate.allocInit(12, 6);call #Ultimate.allocInit(10, 7);call #Ultimate.allocInit(18, 8);call #Ultimate.allocInit(16, 9);call #Ultimate.allocInit(21, 10);call #Ultimate.allocInit(13, 11);call #Ultimate.allocInit(16, 12);call #Ultimate.allocInit(25, 13);call #Ultimate.allocInit(30, 14);call #Ultimate.allocInit(9, 15);call #Ultimate.allocInit(21, 16);call #Ultimate.allocInit(30, 17);call #Ultimate.allocInit(9, 18);call #Ultimate.allocInit(21, 19);call #Ultimate.allocInit(30, 20);call #Ultimate.allocInit(9, 21);call #Ultimate.allocInit(25, 22);call #Ultimate.allocInit(30, 23);call #Ultimate.allocInit(9, 24);call #Ultimate.allocInit(25, 25);call #Ultimate.allocInit(10, 26);call #Ultimate.allocInit(16, 27);call #Ultimate.allocInit(20, 28);call #Ultimate.allocInit(22, 29);call #Ultimate.allocInit(21, 30);call #Ultimate.allocInit(13, 31);call #Ultimate.allocInit(44, 32);call #Ultimate.allocInit(44, 33);call #Ultimate.allocInit(9, 34);call #Ultimate.allocInit(9, 35);call #Ultimate.allocInit(11, 36);call #Ultimate.allocInit(19, 37);call #Ultimate.allocInit(4, 38);call write~init~int(37, 38, 0, 1);call write~init~int(100, 38, 1, 1);call write~init~int(10, 38, 2, 1);call write~init~int(0, 38, 3, 1);call #Ultimate.allocInit(4, 39);call write~init~int(37, 39, 0, 1);call write~init~int(100, 39, 1, 1);call write~init~int(10, 39, 2, 1);call write~init~int(0, 39, 3, 1);~__SELECTED_FEATURE_Base~0 := 0;~__SELECTED_FEATURE_Keys~0 := 0;~__SELECTED_FEATURE_Encrypt~0 := 0;~__SELECTED_FEATURE_AutoResponder~0 := 0;~__SELECTED_FEATURE_AddressBook~0 := 0;~__SELECTED_FEATURE_Sign~0 := 0;~__SELECTED_FEATURE_Forward~0 := 0;~__SELECTED_FEATURE_Verify~0 := 0;~__SELECTED_FEATURE_Decrypt~0 := 0;~__GUIDSL_ROOT_PRODUCTION~0 := 0;~__GUIDSL_NON_TERMINAL_main~0 := 0;~head~0.base, ~head~0.offset := 0, 0;~queue_empty~0 := 1;~queued_message~0 := 0;~queued_client~0 := 0;~mail_is_sensitive~0 := -1;~__ste_Client_counter~0 := 0;~__ste_client_name0~0.base, ~__ste_client_name0~0.offset := 0, 0;~__ste_client_name1~0.base, ~__ste_client_name1~0.offset := 0, 0;~__ste_client_name2~0.base, ~__ste_client_name2~0.offset := 0, 0;~__ste_client_outbuffer0~0 := 0;~__ste_client_outbuffer1~0 := 0;~__ste_client_outbuffer2~0 := 0;~__ste_client_outbuffer3~0 := 0;~__ste_ClientAddressBook_size0~0 := 0;~__ste_ClientAddressBook_size1~0 := 0;~__ste_ClientAddressBook_size2~0 := 0;~__ste_Client_AddressBook0_Alias0~0 := 0;~__ste_Client_AddressBook0_Alias1~0 := 0;~__ste_Client_AddressBook0_Alias2~0 := 0;~__ste_Client_AddressBook1_Alias0~0 := 0;~__ste_Client_AddressBook1_Alias1~0 := 0;~__ste_Client_AddressBook1_Alias2~0 := 0;~__ste_Client_AddressBook2_Alias0~0 := 0;~__ste_Client_AddressBook2_Alias1~0 := 0;~__ste_Client_AddressBook2_Alias2~0 := 0;~__ste_Client_AddressBook0_Address0~0 := 0;~__ste_Client_AddressBook0_Address1~0 := 0;~__ste_Client_AddressBook0_Address2~0 := 0;~__ste_Client_AddressBook1_Address0~0 := 0;~__ste_Client_AddressBook1_Address1~0 := 0;~__ste_Client_AddressBook1_Address2~0 := 0;~__ste_Client_AddressBook2_Address0~0 := 0;~__ste_Client_AddressBook2_Address1~0 := 0;~__ste_Client_AddressBook2_Address2~0 := 0;~__ste_client_autoResponse0~0 := 0;~__ste_client_autoResponse1~0 := 0;~__ste_client_autoResponse2~0 := 0;~__ste_client_privateKey0~0 := 0;~__ste_client_privateKey1~0 := 0;~__ste_client_privateKey2~0 := 0;~__ste_ClientKeyring_size0~0 := 0;~__ste_ClientKeyring_size1~0 := 0;~__ste_ClientKeyring_size2~0 := 0;~__ste_Client_Keyring0_User0~0 := 0;~__ste_Client_Keyring0_User1~0 := 0;~__ste_Client_Keyring0_User2~0 := 0;~__ste_Client_Keyring1_User0~0 := 0;~__ste_Client_Keyring1_User1~0 := 0;~__ste_Client_Keyring1_User2~0 := 0;~__ste_Client_Keyring2_User0~0 := 0;~__ste_Client_Keyring2_User1~0 := 0;~__ste_Client_Keyring2_User2~0 := 0;~__ste_Client_Keyring0_PublicKey0~0 := 0;~__ste_Client_Keyring0_PublicKey1~0 := 0;~__ste_Client_Keyring0_PublicKey2~0 := 0;~__ste_Client_Keyring1_PublicKey0~0 := 0;~__ste_Client_Keyring1_PublicKey1~0 := 0;~__ste_Client_Keyring1_PublicKey2~0 := 0;~__ste_Client_Keyring2_PublicKey0~0 := 0;~__ste_Client_Keyring2_PublicKey1~0 := 0;~__ste_Client_Keyring2_PublicKey2~0 := 0;~__ste_client_forwardReceiver0~0 := 0;~__ste_client_forwardReceiver1~0 := 0;~__ste_client_forwardReceiver2~0 := 0;~__ste_client_forwardReceiver3~0 := 0;~__ste_client_idCounter0~0 := 0;~__ste_client_idCounter1~0 := 0;~__ste_client_idCounter2~0 := 0;~bob~0 := 0;~rjh~0 := 0;~chuck~0 := 0;~__ste_Email_counter~0 := 0;~__ste_email_id0~0 := 0;~__ste_email_id1~0 := 0;~__ste_email_from0~0 := 0;~__ste_email_from1~0 := 0;~__ste_email_to0~0 := 0;~__ste_email_to1~0 := 0;~__ste_email_subject0~0.base, ~__ste_email_subject0~0.offset := 0, 0;~__ste_email_subject1~0.base, ~__ste_email_subject1~0.offset := 0, 0;~__ste_email_body0~0.base, ~__ste_email_body0~0.offset := 0, 0;~__ste_email_body1~0.base, ~__ste_email_body1~0.offset := 0, 0;~__ste_email_isEncrypted0~0 := 0;~__ste_email_isEncrypted1~0 := 0;~__ste_email_encryptionKey0~0 := 0;~__ste_email_encryptionKey1~0 := 0;~__ste_email_isSigned0~0 := 0;~__ste_email_isSigned1~0 := 0;~__ste_email_signKey0~0 := 0;~__ste_email_signKey1~0 := 0;~__ste_email_isSignatureVerified0~0 := 0;~__ste_email_isSignatureVerified1~0 := 0; {391#true} is VALID [2022-02-20 17:56:00,630 INFO L290 TraceCheckUtils]: 1: Hoare triple {391#true} assume { :end_inline_ULTIMATE.init } true;assume { :begin_inline_main } true;havoc main_#res#1;havoc main_#t~ret98#1, main_~retValue_acc~32#1, main_~tmp~24#1;havoc main_~retValue_acc~32#1;havoc main_~tmp~24#1;assume { :begin_inline_select_helpers } true; {391#true} is VALID [2022-02-20 17:56:00,630 INFO L290 TraceCheckUtils]: 2: Hoare triple {391#true} assume { :end_inline_select_helpers } true;assume { :begin_inline_select_features } true; {391#true} is VALID [2022-02-20 17:56:00,631 INFO L290 TraceCheckUtils]: 3: Hoare triple {391#true} assume { :end_inline_select_features } true;assume { :begin_inline_valid_product } true;havoc valid_product_#res#1;havoc valid_product_~retValue_acc~9#1;havoc valid_product_~retValue_acc~9#1;valid_product_~retValue_acc~9#1 := 1;valid_product_#res#1 := valid_product_~retValue_acc~9#1; {391#true} is VALID [2022-02-20 17:56:00,631 INFO L290 TraceCheckUtils]: 4: Hoare triple {391#true} main_#t~ret98#1 := valid_product_#res#1;assume { :end_inline_valid_product } true;assume -2147483648 <= main_#t~ret98#1 && main_#t~ret98#1 <= 2147483647;main_~tmp~24#1 := main_#t~ret98#1;havoc main_#t~ret98#1; {391#true} is VALID [2022-02-20 17:56:00,631 INFO L290 TraceCheckUtils]: 5: Hoare triple {391#true} assume 0 != main_~tmp~24#1;assume { :begin_inline_setup } true;havoc setup_#t~nondet95#1, setup_#t~nondet96#1, setup_#t~nondet97#1, setup_~__cil_tmp1~0#1.base, setup_~__cil_tmp1~0#1.offset, setup_~__cil_tmp2~0#1.base, setup_~__cil_tmp2~0#1.offset, setup_~__cil_tmp3~2#1.base, setup_~__cil_tmp3~2#1.offset;havoc setup_~__cil_tmp1~0#1.base, setup_~__cil_tmp1~0#1.offset;havoc setup_~__cil_tmp2~0#1.base, setup_~__cil_tmp2~0#1.offset;havoc setup_~__cil_tmp3~2#1.base, setup_~__cil_tmp3~2#1.offset;~bob~0 := 1;assume { :begin_inline_setup_bob } true;setup_bob_#in~bob___0#1 := ~bob~0;havoc setup_bob_~bob___0#1;setup_bob_~bob___0#1 := setup_bob_#in~bob___0#1;assume { :begin_inline_setup_bob__wrappee__Base } true;setup_bob__wrappee__Base_#in~bob___0#1 := setup_bob_~bob___0#1;havoc setup_bob__wrappee__Base_~bob___0#1;setup_bob__wrappee__Base_~bob___0#1 := setup_bob__wrappee__Base_#in~bob___0#1; {391#true} is VALID [2022-02-20 17:56:00,631 INFO L272 TraceCheckUtils]: 6: Hoare triple {391#true} call setClientId(setup_bob__wrappee__Base_~bob___0#1, setup_bob__wrappee__Base_~bob___0#1); {391#true} is VALID [2022-02-20 17:56:00,631 INFO L290 TraceCheckUtils]: 7: Hoare triple {391#true} ~handle := #in~handle;~value := #in~value; {391#true} is VALID [2022-02-20 17:56:00,631 INFO L290 TraceCheckUtils]: 8: Hoare triple {391#true} assume 1 == ~handle;~__ste_client_idCounter0~0 := ~value; {391#true} is VALID [2022-02-20 17:56:00,632 INFO L290 TraceCheckUtils]: 9: Hoare triple {391#true} assume true; {391#true} is VALID [2022-02-20 17:56:00,632 INFO L284 TraceCheckUtils]: 10: Hoare quadruple {391#true} {391#true} #1133#return; {391#true} is VALID [2022-02-20 17:56:00,632 INFO L290 TraceCheckUtils]: 11: Hoare triple {391#true} assume { :end_inline_setup_bob__wrappee__Base } true; {391#true} is VALID [2022-02-20 17:56:00,632 INFO L272 TraceCheckUtils]: 12: Hoare triple {391#true} call setClientPrivateKey(setup_bob_~bob___0#1, 123); {391#true} is VALID [2022-02-20 17:56:00,632 INFO L290 TraceCheckUtils]: 13: Hoare triple {391#true} ~handle := #in~handle;~value := #in~value; {391#true} is VALID [2022-02-20 17:56:00,633 INFO L290 TraceCheckUtils]: 14: Hoare triple {391#true} assume 1 == ~handle;~__ste_client_privateKey0~0 := ~value; {391#true} is VALID [2022-02-20 17:56:00,633 INFO L290 TraceCheckUtils]: 15: Hoare triple {391#true} assume true; {391#true} is VALID [2022-02-20 17:56:00,633 INFO L284 TraceCheckUtils]: 16: Hoare quadruple {391#true} {391#true} #1135#return; {391#true} is VALID [2022-02-20 17:56:00,633 INFO L290 TraceCheckUtils]: 17: Hoare triple {391#true} assume { :end_inline_setup_bob } true;setup_~__cil_tmp1~0#1.base, setup_~__cil_tmp1~0#1.offset := 34, 0;havoc setup_#t~nondet95#1;~rjh~0 := 2;assume { :begin_inline_setup_rjh } true;setup_rjh_#in~rjh___0#1 := ~rjh~0;havoc setup_rjh_~rjh___0#1;setup_rjh_~rjh___0#1 := setup_rjh_#in~rjh___0#1;assume { :begin_inline_setup_rjh__wrappee__Base } true;setup_rjh__wrappee__Base_#in~rjh___0#1 := setup_rjh_~rjh___0#1;havoc setup_rjh__wrappee__Base_~rjh___0#1;setup_rjh__wrappee__Base_~rjh___0#1 := setup_rjh__wrappee__Base_#in~rjh___0#1; {391#true} is VALID [2022-02-20 17:56:00,633 INFO L272 TraceCheckUtils]: 18: Hoare triple {391#true} call setClientId(setup_rjh__wrappee__Base_~rjh___0#1, setup_rjh__wrappee__Base_~rjh___0#1); {391#true} is VALID [2022-02-20 17:56:00,633 INFO L290 TraceCheckUtils]: 19: Hoare triple {391#true} ~handle := #in~handle;~value := #in~value; {391#true} is VALID [2022-02-20 17:56:00,634 INFO L290 TraceCheckUtils]: 20: Hoare triple {391#true} assume 1 == ~handle;~__ste_client_idCounter0~0 := ~value; {391#true} is VALID [2022-02-20 17:56:00,634 INFO L290 TraceCheckUtils]: 21: Hoare triple {391#true} assume true; {391#true} is VALID [2022-02-20 17:56:00,634 INFO L284 TraceCheckUtils]: 22: Hoare quadruple {391#true} {391#true} #1137#return; {391#true} is VALID [2022-02-20 17:56:00,634 INFO L290 TraceCheckUtils]: 23: Hoare triple {391#true} assume { :end_inline_setup_rjh__wrappee__Base } true; {391#true} is VALID [2022-02-20 17:56:00,634 INFO L272 TraceCheckUtils]: 24: Hoare triple {391#true} call setClientPrivateKey(setup_rjh_~rjh___0#1, 456); {391#true} is VALID [2022-02-20 17:56:00,634 INFO L290 TraceCheckUtils]: 25: Hoare triple {391#true} ~handle := #in~handle;~value := #in~value; {391#true} is VALID [2022-02-20 17:56:00,635 INFO L290 TraceCheckUtils]: 26: Hoare triple {391#true} assume 1 == ~handle;~__ste_client_privateKey0~0 := ~value; {391#true} is VALID [2022-02-20 17:56:00,635 INFO L290 TraceCheckUtils]: 27: Hoare triple {391#true} assume true; {391#true} is VALID [2022-02-20 17:56:00,635 INFO L284 TraceCheckUtils]: 28: Hoare quadruple {391#true} {391#true} #1139#return; {391#true} is VALID [2022-02-20 17:56:00,635 INFO L290 TraceCheckUtils]: 29: Hoare triple {391#true} assume { :end_inline_setup_rjh } true;setup_~__cil_tmp2~0#1.base, setup_~__cil_tmp2~0#1.offset := 35, 0;havoc setup_#t~nondet96#1;~chuck~0 := 3;assume { :begin_inline_setup_chuck } true;setup_chuck_#in~chuck___0#1 := ~chuck~0;havoc setup_chuck_~chuck___0#1;setup_chuck_~chuck___0#1 := setup_chuck_#in~chuck___0#1;assume { :begin_inline_setup_chuck__wrappee__Base } true;setup_chuck__wrappee__Base_#in~chuck___0#1 := setup_chuck_~chuck___0#1;havoc setup_chuck__wrappee__Base_~chuck___0#1;setup_chuck__wrappee__Base_~chuck___0#1 := setup_chuck__wrappee__Base_#in~chuck___0#1; {391#true} is VALID [2022-02-20 17:56:00,635 INFO L272 TraceCheckUtils]: 30: Hoare triple {391#true} call setClientId(setup_chuck__wrappee__Base_~chuck___0#1, setup_chuck__wrappee__Base_~chuck___0#1); {391#true} is VALID [2022-02-20 17:56:00,635 INFO L290 TraceCheckUtils]: 31: Hoare triple {391#true} ~handle := #in~handle;~value := #in~value; {391#true} is VALID [2022-02-20 17:56:00,636 INFO L290 TraceCheckUtils]: 32: Hoare triple {391#true} assume 1 == ~handle;~__ste_client_idCounter0~0 := ~value; {391#true} is VALID [2022-02-20 17:56:00,636 INFO L290 TraceCheckUtils]: 33: Hoare triple {391#true} assume true; {391#true} is VALID [2022-02-20 17:56:00,636 INFO L284 TraceCheckUtils]: 34: Hoare quadruple {391#true} {391#true} #1141#return; {391#true} is VALID [2022-02-20 17:56:00,636 INFO L290 TraceCheckUtils]: 35: Hoare triple {391#true} assume { :end_inline_setup_chuck__wrappee__Base } true; {391#true} is VALID [2022-02-20 17:56:00,636 INFO L272 TraceCheckUtils]: 36: Hoare triple {391#true} call setClientPrivateKey(setup_chuck_~chuck___0#1, 789); {391#true} is VALID [2022-02-20 17:56:00,636 INFO L290 TraceCheckUtils]: 37: Hoare triple {391#true} ~handle := #in~handle;~value := #in~value; {391#true} is VALID [2022-02-20 17:56:00,637 INFO L290 TraceCheckUtils]: 38: Hoare triple {391#true} assume 1 == ~handle;~__ste_client_privateKey0~0 := ~value; {391#true} is VALID [2022-02-20 17:56:00,637 INFO L290 TraceCheckUtils]: 39: Hoare triple {391#true} assume true; {391#true} is VALID [2022-02-20 17:56:00,637 INFO L284 TraceCheckUtils]: 40: Hoare quadruple {391#true} {391#true} #1143#return; {391#true} is VALID [2022-02-20 17:56:00,637 INFO L290 TraceCheckUtils]: 41: Hoare triple {391#true} assume { :end_inline_setup_chuck } true;setup_~__cil_tmp3~2#1.base, setup_~__cil_tmp3~2#1.offset := 36, 0;havoc setup_#t~nondet97#1; {391#true} is VALID [2022-02-20 17:56:00,637 INFO L290 TraceCheckUtils]: 42: Hoare triple {391#true} assume { :end_inline_setup } true;assume { :begin_inline_test } true;havoc test_#t~nondet48#1, test_#t~nondet49#1, test_#t~nondet50#1, test_#t~nondet51#1, test_#t~nondet52#1, test_#t~nondet53#1, test_#t~nondet54#1, test_#t~nondet55#1, test_#t~nondet56#1, test_#t~nondet57#1, test_#t~nondet58#1, test_~op1~0#1, test_~op2~0#1, test_~op3~0#1, test_~op4~0#1, test_~op5~0#1, test_~op6~0#1, test_~op7~0#1, test_~op8~0#1, test_~op9~0#1, test_~op10~0#1, test_~op11~0#1, test_~splverifierCounter~0#1, test_~tmp~8#1, test_~tmp___0~3#1, test_~tmp___1~1#1, test_~tmp___2~1#1, test_~tmp___3~0#1, test_~tmp___4~0#1, test_~tmp___5~0#1, test_~tmp___6~0#1, test_~tmp___7~0#1, test_~tmp___8~0#1, test_~tmp___9~0#1;havoc test_~op1~0#1;havoc test_~op2~0#1;havoc test_~op3~0#1;havoc test_~op4~0#1;havoc test_~op5~0#1;havoc test_~op6~0#1;havoc test_~op7~0#1;havoc test_~op8~0#1;havoc test_~op9~0#1;havoc test_~op10~0#1;havoc test_~op11~0#1;havoc test_~splverifierCounter~0#1;havoc test_~tmp~8#1;havoc test_~tmp___0~3#1;havoc test_~tmp___1~1#1;havoc test_~tmp___2~1#1;havoc test_~tmp___3~0#1;havoc test_~tmp___4~0#1;havoc test_~tmp___5~0#1;havoc test_~tmp___6~0#1;havoc test_~tmp___7~0#1;havoc test_~tmp___8~0#1;havoc test_~tmp___9~0#1;test_~op1~0#1 := 0;test_~op2~0#1 := 0;test_~op3~0#1 := 0;test_~op4~0#1 := 0;test_~op5~0#1 := 0;test_~op6~0#1 := 0;test_~op7~0#1 := 0;test_~op8~0#1 := 0;test_~op9~0#1 := 0;test_~op10~0#1 := 0;test_~op11~0#1 := 0;test_~splverifierCounter~0#1 := 0; {391#true} is VALID [2022-02-20 17:56:00,638 INFO L290 TraceCheckUtils]: 43: Hoare triple {391#true} assume !true; {392#false} is VALID [2022-02-20 17:56:00,638 INFO L290 TraceCheckUtils]: 44: Hoare triple {392#false} assume { :begin_inline_bobToRjh } true;havoc bobToRjh_#t~ret90#1, bobToRjh_#t~ret91#1, bobToRjh_#t~ret92#1, bobToRjh_#t~ret93#1, bobToRjh_~tmp~23#1, bobToRjh_~tmp___0~7#1, bobToRjh_~tmp___1~4#1;havoc bobToRjh_~tmp~23#1;havoc bobToRjh_~tmp___0~7#1;havoc bobToRjh_~tmp___1~4#1;call bobToRjh_#t~ret90#1 := puts(32, 0);assume -2147483648 <= bobToRjh_#t~ret90#1 && bobToRjh_#t~ret90#1 <= 2147483647;havoc bobToRjh_#t~ret90#1; {392#false} is VALID [2022-02-20 17:56:00,638 INFO L272 TraceCheckUtils]: 45: Hoare triple {392#false} call sendEmail(~bob~0, ~rjh~0); {392#false} is VALID [2022-02-20 17:56:00,638 INFO L290 TraceCheckUtils]: 46: Hoare triple {392#false} ~sender#1 := #in~sender#1;~receiver#1 := #in~receiver#1;havoc ~email~0#1;havoc ~tmp~16#1;assume { :begin_inline_createEmail } true;createEmail_#in~from#1, createEmail_#in~to#1 := 0, ~receiver#1;havoc createEmail_#res#1;havoc createEmail_~from#1, createEmail_~to#1, createEmail_~retValue_acc~4#1, createEmail_~msg~0#1;createEmail_~from#1 := createEmail_#in~from#1;createEmail_~to#1 := createEmail_#in~to#1;havoc createEmail_~retValue_acc~4#1;havoc createEmail_~msg~0#1;createEmail_~msg~0#1 := 1; {392#false} is VALID [2022-02-20 17:56:00,638 INFO L272 TraceCheckUtils]: 47: Hoare triple {392#false} call setEmailFrom(createEmail_~msg~0#1, createEmail_~from#1); {392#false} is VALID [2022-02-20 17:56:00,639 INFO L290 TraceCheckUtils]: 48: Hoare triple {392#false} ~handle := #in~handle;~value := #in~value; {392#false} is VALID [2022-02-20 17:56:00,639 INFO L290 TraceCheckUtils]: 49: Hoare triple {392#false} assume 1 == ~handle;~__ste_email_from0~0 := ~value; {392#false} is VALID [2022-02-20 17:56:00,639 INFO L290 TraceCheckUtils]: 50: Hoare triple {392#false} assume true; {392#false} is VALID [2022-02-20 17:56:00,639 INFO L284 TraceCheckUtils]: 51: Hoare quadruple {392#false} {392#false} #1119#return; {392#false} is VALID [2022-02-20 17:56:00,639 INFO L272 TraceCheckUtils]: 52: Hoare triple {392#false} call setEmailTo(createEmail_~msg~0#1, createEmail_~to#1); {392#false} is VALID [2022-02-20 17:56:00,639 INFO L290 TraceCheckUtils]: 53: Hoare triple {392#false} ~handle := #in~handle;~value := #in~value; {392#false} is VALID [2022-02-20 17:56:00,640 INFO L290 TraceCheckUtils]: 54: Hoare triple {392#false} assume 1 == ~handle;~__ste_email_to0~0 := ~value; {392#false} is VALID [2022-02-20 17:56:00,640 INFO L290 TraceCheckUtils]: 55: Hoare triple {392#false} assume true; {392#false} is VALID [2022-02-20 17:56:00,640 INFO L284 TraceCheckUtils]: 56: Hoare quadruple {392#false} {392#false} #1121#return; {392#false} is VALID [2022-02-20 17:56:00,640 INFO L290 TraceCheckUtils]: 57: Hoare triple {392#false} createEmail_~retValue_acc~4#1 := createEmail_~msg~0#1;createEmail_#res#1 := createEmail_~retValue_acc~4#1; {392#false} is VALID [2022-02-20 17:56:00,640 INFO L290 TraceCheckUtils]: 58: Hoare triple {392#false} #t~ret73#1 := createEmail_#res#1;assume { :end_inline_createEmail } true;assume -2147483648 <= #t~ret73#1 && #t~ret73#1 <= 2147483647;~tmp~16#1 := #t~ret73#1;havoc #t~ret73#1;~email~0#1 := ~tmp~16#1; {392#false} is VALID [2022-02-20 17:56:00,640 INFO L272 TraceCheckUtils]: 59: Hoare triple {392#false} call outgoing(~sender#1, ~email~0#1); {392#false} is VALID [2022-02-20 17:56:00,641 INFO L290 TraceCheckUtils]: 60: Hoare triple {392#false} ~client#1 := #in~client#1;~msg#1 := #in~msg#1;assume { :begin_inline_sign } true;sign_#in~client#1, sign_#in~msg#1 := ~client#1, ~msg#1;havoc sign_#t~ret77#1, sign_~client#1, sign_~msg#1, sign_~privkey~1#1, sign_~tmp~18#1;sign_~client#1 := sign_#in~client#1;sign_~msg#1 := sign_#in~msg#1;havoc sign_~privkey~1#1;havoc sign_~tmp~18#1; {392#false} is VALID [2022-02-20 17:56:00,641 INFO L272 TraceCheckUtils]: 61: Hoare triple {392#false} call sign_#t~ret77#1 := getClientPrivateKey(sign_~client#1); {392#false} is VALID [2022-02-20 17:56:00,641 INFO L290 TraceCheckUtils]: 62: Hoare triple {392#false} ~handle := #in~handle;havoc ~retValue_acc~24; {392#false} is VALID [2022-02-20 17:56:00,641 INFO L290 TraceCheckUtils]: 63: Hoare triple {392#false} assume 1 == ~handle;~retValue_acc~24 := ~__ste_client_privateKey0~0;#res := ~retValue_acc~24; {392#false} is VALID [2022-02-20 17:56:00,641 INFO L290 TraceCheckUtils]: 64: Hoare triple {392#false} assume true; {392#false} is VALID [2022-02-20 17:56:00,641 INFO L284 TraceCheckUtils]: 65: Hoare quadruple {392#false} {392#false} #1053#return; {392#false} is VALID [2022-02-20 17:56:00,642 INFO L290 TraceCheckUtils]: 66: Hoare triple {392#false} assume -2147483648 <= sign_#t~ret77#1 && sign_#t~ret77#1 <= 2147483647;sign_~tmp~18#1 := sign_#t~ret77#1;havoc sign_#t~ret77#1;sign_~privkey~1#1 := sign_~tmp~18#1; {392#false} is VALID [2022-02-20 17:56:00,642 INFO L290 TraceCheckUtils]: 67: Hoare triple {392#false} assume 0 == sign_~privkey~1#1; {392#false} is VALID [2022-02-20 17:56:00,642 INFO L290 TraceCheckUtils]: 68: Hoare triple {392#false} assume { :end_inline_sign } true;assume { :begin_inline_outgoing__wrappee__AutoResponder } true;outgoing__wrappee__AutoResponder_#in~client#1, outgoing__wrappee__AutoResponder_#in~msg#1 := ~client#1, ~msg#1;havoc outgoing__wrappee__AutoResponder_#t~ret63#1, outgoing__wrappee__AutoResponder_#t~ret64#1, outgoing__wrappee__AutoResponder_~client#1, outgoing__wrappee__AutoResponder_~msg#1, outgoing__wrappee__AutoResponder_~receiver~0#1, outgoing__wrappee__AutoResponder_~tmp~11#1, outgoing__wrappee__AutoResponder_~pubkey~0#1, outgoing__wrappee__AutoResponder_~tmp___0~4#1;outgoing__wrappee__AutoResponder_~client#1 := outgoing__wrappee__AutoResponder_#in~client#1;outgoing__wrappee__AutoResponder_~msg#1 := outgoing__wrappee__AutoResponder_#in~msg#1;havoc outgoing__wrappee__AutoResponder_~receiver~0#1;havoc outgoing__wrappee__AutoResponder_~tmp~11#1;havoc outgoing__wrappee__AutoResponder_~pubkey~0#1;havoc outgoing__wrappee__AutoResponder_~tmp___0~4#1; {392#false} is VALID [2022-02-20 17:56:00,642 INFO L272 TraceCheckUtils]: 69: Hoare triple {392#false} call outgoing__wrappee__AutoResponder_#t~ret63#1 := getEmailTo(outgoing__wrappee__AutoResponder_~msg#1); {392#false} is VALID [2022-02-20 17:56:00,642 INFO L290 TraceCheckUtils]: 70: Hoare triple {392#false} ~handle := #in~handle;havoc ~retValue_acc~36; {392#false} is VALID [2022-02-20 17:56:00,642 INFO L290 TraceCheckUtils]: 71: Hoare triple {392#false} assume 1 == ~handle;~retValue_acc~36 := ~__ste_email_to0~0;#res := ~retValue_acc~36; {392#false} is VALID [2022-02-20 17:56:00,643 INFO L290 TraceCheckUtils]: 72: Hoare triple {392#false} assume true; {392#false} is VALID [2022-02-20 17:56:00,643 INFO L284 TraceCheckUtils]: 73: Hoare quadruple {392#false} {392#false} #1055#return; {392#false} is VALID [2022-02-20 17:56:00,643 INFO L290 TraceCheckUtils]: 74: Hoare triple {392#false} assume -2147483648 <= outgoing__wrappee__AutoResponder_#t~ret63#1 && outgoing__wrappee__AutoResponder_#t~ret63#1 <= 2147483647;outgoing__wrappee__AutoResponder_~tmp~11#1 := outgoing__wrappee__AutoResponder_#t~ret63#1;havoc outgoing__wrappee__AutoResponder_#t~ret63#1;outgoing__wrappee__AutoResponder_~receiver~0#1 := outgoing__wrappee__AutoResponder_~tmp~11#1; {392#false} is VALID [2022-02-20 17:56:00,643 INFO L272 TraceCheckUtils]: 75: Hoare triple {392#false} call outgoing__wrappee__AutoResponder_#t~ret64#1 := findPublicKey(outgoing__wrappee__AutoResponder_~client#1, outgoing__wrappee__AutoResponder_~receiver~0#1); {392#false} is VALID [2022-02-20 17:56:00,643 INFO L290 TraceCheckUtils]: 76: Hoare triple {392#false} ~handle := #in~handle;~userid := #in~userid;havoc ~retValue_acc~29; {392#false} is VALID [2022-02-20 17:56:00,643 INFO L290 TraceCheckUtils]: 77: Hoare triple {392#false} assume 1 == ~handle; {392#false} is VALID [2022-02-20 17:56:00,644 INFO L290 TraceCheckUtils]: 78: Hoare triple {392#false} assume ~userid == ~__ste_Client_Keyring0_User0~0;~retValue_acc~29 := ~__ste_Client_Keyring0_PublicKey0~0;#res := ~retValue_acc~29; {392#false} is VALID [2022-02-20 17:56:00,644 INFO L290 TraceCheckUtils]: 79: Hoare triple {392#false} assume true; {392#false} is VALID [2022-02-20 17:56:00,644 INFO L284 TraceCheckUtils]: 80: Hoare quadruple {392#false} {392#false} #1057#return; {392#false} is VALID [2022-02-20 17:56:00,644 INFO L290 TraceCheckUtils]: 81: Hoare triple {392#false} assume -2147483648 <= outgoing__wrappee__AutoResponder_#t~ret64#1 && outgoing__wrappee__AutoResponder_#t~ret64#1 <= 2147483647;outgoing__wrappee__AutoResponder_~tmp___0~4#1 := outgoing__wrappee__AutoResponder_#t~ret64#1;havoc outgoing__wrappee__AutoResponder_#t~ret64#1;outgoing__wrappee__AutoResponder_~pubkey~0#1 := outgoing__wrappee__AutoResponder_~tmp___0~4#1; {392#false} is VALID [2022-02-20 17:56:00,644 INFO L290 TraceCheckUtils]: 82: Hoare triple {392#false} assume !(0 != outgoing__wrappee__AutoResponder_~pubkey~0#1); {392#false} is VALID [2022-02-20 17:56:00,644 INFO L290 TraceCheckUtils]: 83: Hoare triple {392#false} assume { :begin_inline_outgoing__wrappee__Keys } true;outgoing__wrappee__Keys_#in~client#1, outgoing__wrappee__Keys_#in~msg#1 := outgoing__wrappee__AutoResponder_~client#1, outgoing__wrappee__AutoResponder_~msg#1;havoc outgoing__wrappee__Keys_#t~ret62#1, outgoing__wrappee__Keys_~client#1, outgoing__wrappee__Keys_~msg#1, outgoing__wrappee__Keys_~tmp~10#1;outgoing__wrappee__Keys_~client#1 := outgoing__wrappee__Keys_#in~client#1;outgoing__wrappee__Keys_~msg#1 := outgoing__wrappee__Keys_#in~msg#1;havoc outgoing__wrappee__Keys_~tmp~10#1;assume { :begin_inline_getClientId } true;getClientId_#in~handle#1 := outgoing__wrappee__Keys_~client#1;havoc getClientId_#res#1;havoc getClientId_~handle#1, getClientId_~retValue_acc~31#1;getClientId_~handle#1 := getClientId_#in~handle#1;havoc getClientId_~retValue_acc~31#1; {392#false} is VALID [2022-02-20 17:56:00,645 INFO L290 TraceCheckUtils]: 84: Hoare triple {392#false} assume 1 == getClientId_~handle#1;getClientId_~retValue_acc~31#1 := ~__ste_client_idCounter0~0;getClientId_#res#1 := getClientId_~retValue_acc~31#1; {392#false} is VALID [2022-02-20 17:56:00,645 INFO L290 TraceCheckUtils]: 85: Hoare triple {392#false} outgoing__wrappee__Keys_#t~ret62#1 := getClientId_#res#1;assume { :end_inline_getClientId } true;assume -2147483648 <= outgoing__wrappee__Keys_#t~ret62#1 && outgoing__wrappee__Keys_#t~ret62#1 <= 2147483647;outgoing__wrappee__Keys_~tmp~10#1 := outgoing__wrappee__Keys_#t~ret62#1;havoc outgoing__wrappee__Keys_#t~ret62#1; {392#false} is VALID [2022-02-20 17:56:00,645 INFO L272 TraceCheckUtils]: 86: Hoare triple {392#false} call setEmailFrom(outgoing__wrappee__Keys_~msg#1, outgoing__wrappee__Keys_~tmp~10#1); {392#false} is VALID [2022-02-20 17:56:00,645 INFO L290 TraceCheckUtils]: 87: Hoare triple {392#false} ~handle := #in~handle;~value := #in~value; {392#false} is VALID [2022-02-20 17:56:00,645 INFO L290 TraceCheckUtils]: 88: Hoare triple {392#false} assume 1 == ~handle;~__ste_email_from0~0 := ~value; {392#false} is VALID [2022-02-20 17:56:00,645 INFO L290 TraceCheckUtils]: 89: Hoare triple {392#false} assume true; {392#false} is VALID [2022-02-20 17:56:00,645 INFO L284 TraceCheckUtils]: 90: Hoare quadruple {392#false} {392#false} #1063#return; {392#false} is VALID [2022-02-20 17:56:00,646 INFO L290 TraceCheckUtils]: 91: Hoare triple {392#false} assume { :begin_inline_mail } true;mail_#in~client#1, mail_#in~msg#1 := outgoing__wrappee__Keys_~client#1, outgoing__wrappee__Keys_~msg#1;havoc mail_#t~ret60#1, mail_#t~ret61#1, mail_~client#1, mail_~msg#1, mail_~__utac__ad__arg1~0#1, mail_~__utac__ad__arg2~0#1, mail_~tmp~9#1;mail_~client#1 := mail_#in~client#1;mail_~msg#1 := mail_#in~msg#1;havoc mail_~__utac__ad__arg1~0#1;havoc mail_~__utac__ad__arg2~0#1;havoc mail_~tmp~9#1;mail_~__utac__ad__arg1~0#1 := mail_~client#1;mail_~__utac__ad__arg2~0#1 := mail_~msg#1;assume { :begin_inline___utac_acc__AddressBookEncrypt_spec__1 } true;__utac_acc__AddressBookEncrypt_spec__1_#in~client#1, __utac_acc__AddressBookEncrypt_spec__1_#in~msg#1 := mail_~__utac__ad__arg1~0#1, mail_~__utac__ad__arg2~0#1;havoc __utac_acc__AddressBookEncrypt_spec__1_#t~ret85#1, __utac_acc__AddressBookEncrypt_spec__1_#t~ret86#1, __utac_acc__AddressBookEncrypt_spec__1_#t~ret87#1, __utac_acc__AddressBookEncrypt_spec__1_~client#1, __utac_acc__AddressBookEncrypt_spec__1_~msg#1, __utac_acc__AddressBookEncrypt_spec__1_~tmp~20#1;__utac_acc__AddressBookEncrypt_spec__1_~client#1 := __utac_acc__AddressBookEncrypt_spec__1_#in~client#1;__utac_acc__AddressBookEncrypt_spec__1_~msg#1 := __utac_acc__AddressBookEncrypt_spec__1_#in~msg#1;havoc __utac_acc__AddressBookEncrypt_spec__1_~tmp~20#1;call __utac_acc__AddressBookEncrypt_spec__1_#t~ret85#1 := puts(31, 0);assume -2147483648 <= __utac_acc__AddressBookEncrypt_spec__1_#t~ret85#1 && __utac_acc__AddressBookEncrypt_spec__1_#t~ret85#1 <= 2147483647;havoc __utac_acc__AddressBookEncrypt_spec__1_#t~ret85#1; {392#false} is VALID [2022-02-20 17:56:00,646 INFO L290 TraceCheckUtils]: 92: Hoare triple {392#false} assume !(-1 == ~mail_is_sensitive~0); {392#false} is VALID [2022-02-20 17:56:00,646 INFO L272 TraceCheckUtils]: 93: Hoare triple {392#false} call __utac_acc__AddressBookEncrypt_spec__1_#t~ret87#1 := isEncrypted(__utac_acc__AddressBookEncrypt_spec__1_~msg#1); {392#false} is VALID [2022-02-20 17:56:00,646 INFO L290 TraceCheckUtils]: 94: Hoare triple {392#false} ~handle := #in~handle;havoc ~retValue_acc~39; {392#false} is VALID [2022-02-20 17:56:00,646 INFO L290 TraceCheckUtils]: 95: Hoare triple {392#false} assume 1 == ~handle;~retValue_acc~39 := ~__ste_email_isEncrypted0~0;#res := ~retValue_acc~39; {392#false} is VALID [2022-02-20 17:56:00,647 INFO L290 TraceCheckUtils]: 96: Hoare triple {392#false} assume true; {392#false} is VALID [2022-02-20 17:56:00,647 INFO L284 TraceCheckUtils]: 97: Hoare quadruple {392#false} {392#false} #1067#return; {392#false} is VALID [2022-02-20 17:56:00,647 INFO L290 TraceCheckUtils]: 98: Hoare triple {392#false} assume -2147483648 <= __utac_acc__AddressBookEncrypt_spec__1_#t~ret87#1 && __utac_acc__AddressBookEncrypt_spec__1_#t~ret87#1 <= 2147483647;__utac_acc__AddressBookEncrypt_spec__1_~tmp~20#1 := __utac_acc__AddressBookEncrypt_spec__1_#t~ret87#1;havoc __utac_acc__AddressBookEncrypt_spec__1_#t~ret87#1; {392#false} is VALID [2022-02-20 17:56:00,647 INFO L290 TraceCheckUtils]: 99: Hoare triple {392#false} assume ~mail_is_sensitive~0 != __utac_acc__AddressBookEncrypt_spec__1_~tmp~20#1;assume { :begin_inline___automaton_fail } true; {392#false} is VALID [2022-02-20 17:56:00,647 INFO L290 TraceCheckUtils]: 100: Hoare triple {392#false} assume !false; {392#false} is VALID [2022-02-20 17:56:00,648 INFO L134 CoverageAnalysis]: Checked inductivity of 28 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 28 trivial. 0 not checked. [2022-02-20 17:56:00,648 INFO L324 TraceCheckSpWp]: Omiting computation of backward sequence because forward sequence was already perfect [2022-02-20 17:56:00,648 INFO L165 FreeRefinementEngine]: IpTcStrategyModuleZ3 [919510198] provided 1 perfect and 0 imperfect interpolant sequences [2022-02-20 17:56:00,648 INFO L191 FreeRefinementEngine]: Found 1 perfect and 1 imperfect interpolant sequences. [2022-02-20 17:56:00,648 INFO L204 FreeRefinementEngine]: Number of different interpolants: perfect sequences [2] imperfect sequences [9] total 9 [2022-02-20 17:56:00,650 INFO L118 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [1264525560] [2022-02-20 17:56:00,651 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2022-02-20 17:56:00,654 INFO L78 Accepts]: Start accepts. Automaton has has 2 states, 2 states have (on average 29.0) internal successors, (58), 2 states have internal predecessors, (58), 2 states have call successors, (15), 2 states have call predecessors, (15), 2 states have return successors, (13), 2 states have call predecessors, (13), 2 states have call successors, (13) Word has length 101 [2022-02-20 17:56:00,656 INFO L84 Accepts]: Finished accepts. word is accepted. [2022-02-20 17:56:00,658 INFO L86 InductivityCheck]: Starting indutivity check of a Floyd-Hoare automaton with has 2 states, 2 states have (on average 29.0) internal successors, (58), 2 states have internal predecessors, (58), 2 states have call successors, (15), 2 states have call predecessors, (15), 2 states have return successors, (13), 2 states have call predecessors, (13), 2 states have call successors, (13) [2022-02-20 17:56:00,719 INFO L122 InductivityCheck]: Floyd-Hoare automaton has 86 edges. 86 inductive. 0 not inductive. 0 times theorem prover too weak to decide inductivity. [2022-02-20 17:56:00,719 INFO L546 AbstractCegarLoop]: INTERPOLANT automaton has 2 states [2022-02-20 17:56:00,720 INFO L108 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2022-02-20 17:56:00,742 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 2 interpolants. [2022-02-20 17:56:00,743 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=15, Invalid=57, Unknown=0, NotChecked=0, Total=72 [2022-02-20 17:56:00,747 INFO L87 Difference]: Start difference. First operand has 388 states, 299 states have (on average 1.5016722408026757) internal successors, (449), 303 states have internal predecessors, (449), 63 states have call successors, (63), 24 states have call predecessors, (63), 24 states have return successors, (63), 63 states have call predecessors, (63), 63 states have call successors, (63) Second operand has 2 states, 2 states have (on average 29.0) internal successors, (58), 2 states have internal predecessors, (58), 2 states have call successors, (15), 2 states have call predecessors, (15), 2 states have return successors, (13), 2 states have call predecessors, (13), 2 states have call successors, (13) [2022-02-20 17:56:01,083 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-02-20 17:56:01,084 INFO L93 Difference]: Finished difference Result 617 states and 896 transitions. [2022-02-20 17:56:01,084 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 2 states. [2022-02-20 17:56:01,085 INFO L78 Accepts]: Start accepts. Automaton has has 2 states, 2 states have (on average 29.0) internal successors, (58), 2 states have internal predecessors, (58), 2 states have call successors, (15), 2 states have call predecessors, (15), 2 states have return successors, (13), 2 states have call predecessors, (13), 2 states have call successors, (13) Word has length 101 [2022-02-20 17:56:01,085 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2022-02-20 17:56:01,086 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 2 states, 2 states have (on average 29.0) internal successors, (58), 2 states have internal predecessors, (58), 2 states have call successors, (15), 2 states have call predecessors, (15), 2 states have return successors, (13), 2 states have call predecessors, (13), 2 states have call successors, (13) [2022-02-20 17:56:01,109 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 2 states to 2 states and 896 transitions. [2022-02-20 17:56:01,110 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 2 states, 2 states have (on average 29.0) internal successors, (58), 2 states have internal predecessors, (58), 2 states have call successors, (15), 2 states have call predecessors, (15), 2 states have return successors, (13), 2 states have call predecessors, (13), 2 states have call successors, (13) [2022-02-20 17:56:01,123 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 2 states to 2 states and 896 transitions. [2022-02-20 17:56:01,124 INFO L86 InductivityCheck]: Starting indutivity check of a Floyd-Hoare automaton with 2 states and 896 transitions. [2022-02-20 17:56:01,775 INFO L122 InductivityCheck]: Floyd-Hoare automaton has 896 edges. 896 inductive. 0 not inductive. 0 times theorem prover too weak to decide inductivity. [2022-02-20 17:56:01,796 INFO L225 Difference]: With dead ends: 617 [2022-02-20 17:56:01,796 INFO L226 Difference]: Without dead ends: 381 [2022-02-20 17:56:01,800 INFO L932 BasicCegarLoop]: 0 DeclaredPredicates, 130 GetRequests, 123 SyntacticMatches, 0 SemanticMatches, 7 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 0 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=15, Invalid=57, Unknown=0, NotChecked=0, Total=72 [2022-02-20 17:56:01,802 INFO L933 BasicCegarLoop]: 571 mSDtfsCounter, 0 mSDsluCounter, 0 mSDsCounter, 0 mSdLazyCounter, 0 mSolverCounterSat, 0 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.0s Time, 0 mProtectedPredicate, 0 mProtectedAction, 0 SdHoareTripleChecker+Valid, 571 SdHoareTripleChecker+Invalid, 0 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 0 IncrementalHoareTripleChecker+Valid, 0 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.0s IncrementalHoareTripleChecker+Time [2022-02-20 17:56:01,803 INFO L934 BasicCegarLoop]: SdHoareTripleChecker [0 Valid, 571 Invalid, 0 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [0 Valid, 0 Invalid, 0 Unknown, 0 Unchecked, 0.0s Time] [2022-02-20 17:56:01,815 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 381 states. [2022-02-20 17:56:01,836 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 381 to 381. [2022-02-20 17:56:01,837 INFO L214 AbstractMinimizeNwa]: Start testing correctness of minimizeSevpa [2022-02-20 17:56:01,839 INFO L82 GeneralOperation]: Start isEquivalent. First operand 381 states. Second operand has 381 states, 293 states have (on average 1.4948805460750854) internal successors, (438), 296 states have internal predecessors, (438), 63 states have call successors, (63), 24 states have call predecessors, (63), 24 states have return successors, (62), 62 states have call predecessors, (62), 62 states have call successors, (62) [2022-02-20 17:56:01,843 INFO L74 IsIncluded]: Start isIncluded. First operand 381 states. Second operand has 381 states, 293 states have (on average 1.4948805460750854) internal successors, (438), 296 states have internal predecessors, (438), 63 states have call successors, (63), 24 states have call predecessors, (63), 24 states have return successors, (62), 62 states have call predecessors, (62), 62 states have call successors, (62) [2022-02-20 17:56:01,845 INFO L87 Difference]: Start difference. First operand 381 states. Second operand has 381 states, 293 states have (on average 1.4948805460750854) internal successors, (438), 296 states have internal predecessors, (438), 63 states have call successors, (63), 24 states have call predecessors, (63), 24 states have return successors, (62), 62 states have call predecessors, (62), 62 states have call successors, (62) [2022-02-20 17:56:01,867 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-02-20 17:56:01,867 INFO L93 Difference]: Finished difference Result 381 states and 563 transitions. [2022-02-20 17:56:01,867 INFO L276 IsEmpty]: Start isEmpty. Operand 381 states and 563 transitions. [2022-02-20 17:56:01,870 INFO L282 IsEmpty]: Finished isEmpty. No accepting run. [2022-02-20 17:56:01,870 INFO L83 IsIncluded]: Finished isIncluded. Language is included [2022-02-20 17:56:01,872 INFO L74 IsIncluded]: Start isIncluded. First operand has 381 states, 293 states have (on average 1.4948805460750854) internal successors, (438), 296 states have internal predecessors, (438), 63 states have call successors, (63), 24 states have call predecessors, (63), 24 states have return successors, (62), 62 states have call predecessors, (62), 62 states have call successors, (62) Second operand 381 states. [2022-02-20 17:56:01,874 INFO L87 Difference]: Start difference. First operand has 381 states, 293 states have (on average 1.4948805460750854) internal successors, (438), 296 states have internal predecessors, (438), 63 states have call successors, (63), 24 states have call predecessors, (63), 24 states have return successors, (62), 62 states have call predecessors, (62), 62 states have call successors, (62) Second operand 381 states. [2022-02-20 17:56:01,892 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-02-20 17:56:01,893 INFO L93 Difference]: Finished difference Result 381 states and 563 transitions. [2022-02-20 17:56:01,893 INFO L276 IsEmpty]: Start isEmpty. Operand 381 states and 563 transitions. [2022-02-20 17:56:01,894 INFO L282 IsEmpty]: Finished isEmpty. No accepting run. [2022-02-20 17:56:01,894 INFO L83 IsIncluded]: Finished isIncluded. Language is included [2022-02-20 17:56:01,894 INFO L88 GeneralOperation]: Finished isEquivalent. [2022-02-20 17:56:01,894 INFO L221 AbstractMinimizeNwa]: Finished testing correctness of minimizeSevpa [2022-02-20 17:56:01,896 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 381 states, 293 states have (on average 1.4948805460750854) internal successors, (438), 296 states have internal predecessors, (438), 63 states have call successors, (63), 24 states have call predecessors, (63), 24 states have return successors, (62), 62 states have call predecessors, (62), 62 states have call successors, (62) [2022-02-20 17:56:01,913 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 381 states to 381 states and 563 transitions. [2022-02-20 17:56:01,914 INFO L78 Accepts]: Start accepts. Automaton has 381 states and 563 transitions. Word has length 101 [2022-02-20 17:56:01,915 INFO L84 Accepts]: Finished accepts. word is rejected. [2022-02-20 17:56:01,915 INFO L470 AbstractCegarLoop]: Abstraction has 381 states and 563 transitions. [2022-02-20 17:56:01,916 INFO L471 AbstractCegarLoop]: INTERPOLANT automaton has has 2 states, 2 states have (on average 29.0) internal successors, (58), 2 states have internal predecessors, (58), 2 states have call successors, (15), 2 states have call predecessors, (15), 2 states have return successors, (13), 2 states have call predecessors, (13), 2 states have call successors, (13) [2022-02-20 17:56:01,916 INFO L276 IsEmpty]: Start isEmpty. Operand 381 states and 563 transitions. [2022-02-20 17:56:01,919 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 103 [2022-02-20 17:56:01,920 INFO L506 BasicCegarLoop]: Found error trace [2022-02-20 17:56:01,920 INFO L514 BasicCegarLoop]: trace histogram [3, 3, 3, 3, 3, 3, 2, 2, 2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-02-20 17:56:01,956 INFO L540 MonitoredProcess]: [MP /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 -smt2 -in SMTLIB2_COMPLIANT=true (2)] Forceful destruction successful, exit code 0 [2022-02-20 17:56:02,158 WARN L452 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: 2 /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 -smt2 -in SMTLIB2_COMPLIANT=true,SelfDestructingSolverStorable0 [2022-02-20 17:56:02,158 INFO L402 AbstractCegarLoop]: === Iteration 2 === Targeting outgoingErr0ASSERT_VIOLATIONERROR_FUNCTION === [outgoingErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2022-02-20 17:56:02,159 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2022-02-20 17:56:02,159 INFO L85 PathProgramCache]: Analyzing trace with hash 1629824209, now seen corresponding path program 1 times [2022-02-20 17:56:02,159 INFO L126 FreeRefinementEngine]: Executing refinement strategy CAMEL [2022-02-20 17:56:02,159 INFO L338 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [2078182810] [2022-02-20 17:56:02,159 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-02-20 17:56:02,159 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2022-02-20 17:56:02,187 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-02-20 17:56:02,215 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 6 [2022-02-20 17:56:02,217 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-02-20 17:56:02,219 INFO L290 TraceCheckUtils]: 0: Hoare triple {2972#(and (= |old(~__ste_client_idCounter0~0)| ~__ste_client_idCounter0~0) (= |old(~__ste_client_idCounter1~0)| ~__ste_client_idCounter1~0) (= |old(~__ste_client_idCounter2~0)| ~__ste_client_idCounter2~0))} ~handle := #in~handle;~value := #in~value; {2916#true} is VALID [2022-02-20 17:56:02,219 INFO L290 TraceCheckUtils]: 1: Hoare triple {2916#true} assume 1 == ~handle;~__ste_client_idCounter0~0 := ~value; {2916#true} is VALID [2022-02-20 17:56:02,219 INFO L290 TraceCheckUtils]: 2: Hoare triple {2916#true} assume true; {2916#true} is VALID [2022-02-20 17:56:02,219 INFO L284 TraceCheckUtils]: 3: Hoare quadruple {2916#true} {2916#true} #1133#return; {2916#true} is VALID [2022-02-20 17:56:02,224 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 12 [2022-02-20 17:56:02,225 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-02-20 17:56:02,227 INFO L290 TraceCheckUtils]: 0: Hoare triple {2973#(and (= ~__ste_client_privateKey0~0 |old(~__ste_client_privateKey0~0)|) (= ~__ste_client_privateKey2~0 |old(~__ste_client_privateKey2~0)|) (= ~__ste_client_privateKey1~0 |old(~__ste_client_privateKey1~0)|))} ~handle := #in~handle;~value := #in~value; {2916#true} is VALID [2022-02-20 17:56:02,228 INFO L290 TraceCheckUtils]: 1: Hoare triple {2916#true} assume 1 == ~handle;~__ste_client_privateKey0~0 := ~value; {2916#true} is VALID [2022-02-20 17:56:02,228 INFO L290 TraceCheckUtils]: 2: Hoare triple {2916#true} assume true; {2916#true} is VALID [2022-02-20 17:56:02,228 INFO L284 TraceCheckUtils]: 3: Hoare quadruple {2916#true} {2916#true} #1135#return; {2916#true} is VALID [2022-02-20 17:56:02,228 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 18 [2022-02-20 17:56:02,230 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-02-20 17:56:02,253 INFO L290 TraceCheckUtils]: 0: Hoare triple {2972#(and (= |old(~__ste_client_idCounter0~0)| ~__ste_client_idCounter0~0) (= |old(~__ste_client_idCounter1~0)| ~__ste_client_idCounter1~0) (= |old(~__ste_client_idCounter2~0)| ~__ste_client_idCounter2~0))} ~handle := #in~handle;~value := #in~value; {2974#(= setClientId_~handle |setClientId_#in~handle|)} is VALID [2022-02-20 17:56:02,254 INFO L290 TraceCheckUtils]: 1: Hoare triple {2974#(= setClientId_~handle |setClientId_#in~handle|)} assume 1 == ~handle;~__ste_client_idCounter0~0 := ~value; {2975#(= |setClientId_#in~handle| 1)} is VALID [2022-02-20 17:56:02,254 INFO L290 TraceCheckUtils]: 2: Hoare triple {2975#(= |setClientId_#in~handle| 1)} assume true; {2975#(= |setClientId_#in~handle| 1)} is VALID [2022-02-20 17:56:02,254 INFO L284 TraceCheckUtils]: 3: Hoare quadruple {2975#(= |setClientId_#in~handle| 1)} {2926#(= |ULTIMATE.start_setup_rjh__wrappee__Base_~rjh___0#1| 2)} #1137#return; {2917#false} is VALID [2022-02-20 17:56:02,255 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 24 [2022-02-20 17:56:02,256 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-02-20 17:56:02,269 INFO L290 TraceCheckUtils]: 0: Hoare triple {2973#(and (= ~__ste_client_privateKey0~0 |old(~__ste_client_privateKey0~0)|) (= ~__ste_client_privateKey2~0 |old(~__ste_client_privateKey2~0)|) (= ~__ste_client_privateKey1~0 |old(~__ste_client_privateKey1~0)|))} ~handle := #in~handle;~value := #in~value; {2916#true} is VALID [2022-02-20 17:56:02,269 INFO L290 TraceCheckUtils]: 1: Hoare triple {2916#true} assume 1 == ~handle;~__ste_client_privateKey0~0 := ~value; {2916#true} is VALID [2022-02-20 17:56:02,269 INFO L290 TraceCheckUtils]: 2: Hoare triple {2916#true} assume true; {2916#true} is VALID [2022-02-20 17:56:02,269 INFO L284 TraceCheckUtils]: 3: Hoare quadruple {2916#true} {2917#false} #1139#return; {2917#false} is VALID [2022-02-20 17:56:02,270 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 30 [2022-02-20 17:56:02,272 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-02-20 17:56:02,274 INFO L290 TraceCheckUtils]: 0: Hoare triple {2972#(and (= |old(~__ste_client_idCounter0~0)| ~__ste_client_idCounter0~0) (= |old(~__ste_client_idCounter1~0)| ~__ste_client_idCounter1~0) (= |old(~__ste_client_idCounter2~0)| ~__ste_client_idCounter2~0))} ~handle := #in~handle;~value := #in~value; {2916#true} is VALID [2022-02-20 17:56:02,274 INFO L290 TraceCheckUtils]: 1: Hoare triple {2916#true} assume 1 == ~handle;~__ste_client_idCounter0~0 := ~value; {2916#true} is VALID [2022-02-20 17:56:02,274 INFO L290 TraceCheckUtils]: 2: Hoare triple {2916#true} assume true; {2916#true} is VALID [2022-02-20 17:56:02,274 INFO L284 TraceCheckUtils]: 3: Hoare quadruple {2916#true} {2917#false} #1141#return; {2917#false} is VALID [2022-02-20 17:56:02,275 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 36 [2022-02-20 17:56:02,276 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-02-20 17:56:02,278 INFO L290 TraceCheckUtils]: 0: Hoare triple {2973#(and (= ~__ste_client_privateKey0~0 |old(~__ste_client_privateKey0~0)|) (= ~__ste_client_privateKey2~0 |old(~__ste_client_privateKey2~0)|) (= ~__ste_client_privateKey1~0 |old(~__ste_client_privateKey1~0)|))} ~handle := #in~handle;~value := #in~value; {2916#true} is VALID [2022-02-20 17:56:02,278 INFO L290 TraceCheckUtils]: 1: Hoare triple {2916#true} assume 1 == ~handle;~__ste_client_privateKey0~0 := ~value; {2916#true} is VALID [2022-02-20 17:56:02,278 INFO L290 TraceCheckUtils]: 2: Hoare triple {2916#true} assume true; {2916#true} is VALID [2022-02-20 17:56:02,278 INFO L284 TraceCheckUtils]: 3: Hoare quadruple {2916#true} {2917#false} #1143#return; {2917#false} is VALID [2022-02-20 17:56:02,284 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 48 [2022-02-20 17:56:02,285 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-02-20 17:56:02,287 INFO L290 TraceCheckUtils]: 0: Hoare triple {2976#(and (= |old(~__ste_email_from0~0)| ~__ste_email_from0~0) (= |old(~__ste_email_from1~0)| ~__ste_email_from1~0))} ~handle := #in~handle;~value := #in~value; {2916#true} is VALID [2022-02-20 17:56:02,287 INFO L290 TraceCheckUtils]: 1: Hoare triple {2916#true} assume 1 == ~handle;~__ste_email_from0~0 := ~value; {2916#true} is VALID [2022-02-20 17:56:02,287 INFO L290 TraceCheckUtils]: 2: Hoare triple {2916#true} assume true; {2916#true} is VALID [2022-02-20 17:56:02,287 INFO L284 TraceCheckUtils]: 3: Hoare quadruple {2916#true} {2917#false} #1119#return; {2917#false} is VALID [2022-02-20 17:56:02,293 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 53 [2022-02-20 17:56:02,294 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-02-20 17:56:02,296 INFO L290 TraceCheckUtils]: 0: Hoare triple {2977#(and (= ~__ste_email_to0~0 |old(~__ste_email_to0~0)|) (= ~__ste_email_to1~0 |old(~__ste_email_to1~0)|))} ~handle := #in~handle;~value := #in~value; {2916#true} is VALID [2022-02-20 17:56:02,296 INFO L290 TraceCheckUtils]: 1: Hoare triple {2916#true} assume 1 == ~handle;~__ste_email_to0~0 := ~value; {2916#true} is VALID [2022-02-20 17:56:02,296 INFO L290 TraceCheckUtils]: 2: Hoare triple {2916#true} assume true; {2916#true} is VALID [2022-02-20 17:56:02,296 INFO L284 TraceCheckUtils]: 3: Hoare quadruple {2916#true} {2917#false} #1121#return; {2917#false} is VALID [2022-02-20 17:56:02,296 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 62 [2022-02-20 17:56:02,297 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-02-20 17:56:02,299 INFO L290 TraceCheckUtils]: 0: Hoare triple {2916#true} ~handle := #in~handle;havoc ~retValue_acc~24; {2916#true} is VALID [2022-02-20 17:56:02,299 INFO L290 TraceCheckUtils]: 1: Hoare triple {2916#true} assume 1 == ~handle;~retValue_acc~24 := ~__ste_client_privateKey0~0;#res := ~retValue_acc~24; {2916#true} is VALID [2022-02-20 17:56:02,299 INFO L290 TraceCheckUtils]: 2: Hoare triple {2916#true} assume true; {2916#true} is VALID [2022-02-20 17:56:02,299 INFO L284 TraceCheckUtils]: 3: Hoare quadruple {2916#true} {2917#false} #1053#return; {2917#false} is VALID [2022-02-20 17:56:02,299 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 70 [2022-02-20 17:56:02,300 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-02-20 17:56:02,301 INFO L290 TraceCheckUtils]: 0: Hoare triple {2916#true} ~handle := #in~handle;havoc ~retValue_acc~36; {2916#true} is VALID [2022-02-20 17:56:02,302 INFO L290 TraceCheckUtils]: 1: Hoare triple {2916#true} assume 1 == ~handle;~retValue_acc~36 := ~__ste_email_to0~0;#res := ~retValue_acc~36; {2916#true} is VALID [2022-02-20 17:56:02,302 INFO L290 TraceCheckUtils]: 2: Hoare triple {2916#true} assume true; {2916#true} is VALID [2022-02-20 17:56:02,302 INFO L284 TraceCheckUtils]: 3: Hoare quadruple {2916#true} {2917#false} #1055#return; {2917#false} is VALID [2022-02-20 17:56:02,302 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 76 [2022-02-20 17:56:02,303 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-02-20 17:56:02,304 INFO L290 TraceCheckUtils]: 0: Hoare triple {2916#true} ~handle := #in~handle;~userid := #in~userid;havoc ~retValue_acc~29; {2916#true} is VALID [2022-02-20 17:56:02,305 INFO L290 TraceCheckUtils]: 1: Hoare triple {2916#true} assume 1 == ~handle; {2916#true} is VALID [2022-02-20 17:56:02,305 INFO L290 TraceCheckUtils]: 2: Hoare triple {2916#true} assume ~userid == ~__ste_Client_Keyring0_User0~0;~retValue_acc~29 := ~__ste_Client_Keyring0_PublicKey0~0;#res := ~retValue_acc~29; {2916#true} is VALID [2022-02-20 17:56:02,305 INFO L290 TraceCheckUtils]: 3: Hoare triple {2916#true} assume true; {2916#true} is VALID [2022-02-20 17:56:02,305 INFO L284 TraceCheckUtils]: 4: Hoare quadruple {2916#true} {2917#false} #1057#return; {2917#false} is VALID [2022-02-20 17:56:02,305 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 87 [2022-02-20 17:56:02,306 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-02-20 17:56:02,315 INFO L290 TraceCheckUtils]: 0: Hoare triple {2976#(and (= |old(~__ste_email_from0~0)| ~__ste_email_from0~0) (= |old(~__ste_email_from1~0)| ~__ste_email_from1~0))} ~handle := #in~handle;~value := #in~value; {2916#true} is VALID [2022-02-20 17:56:02,315 INFO L290 TraceCheckUtils]: 1: Hoare triple {2916#true} assume 1 == ~handle;~__ste_email_from0~0 := ~value; {2916#true} is VALID [2022-02-20 17:56:02,315 INFO L290 TraceCheckUtils]: 2: Hoare triple {2916#true} assume true; {2916#true} is VALID [2022-02-20 17:56:02,315 INFO L284 TraceCheckUtils]: 3: Hoare quadruple {2916#true} {2917#false} #1063#return; {2917#false} is VALID [2022-02-20 17:56:02,315 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 94 [2022-02-20 17:56:02,316 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-02-20 17:56:02,319 INFO L290 TraceCheckUtils]: 0: Hoare triple {2916#true} ~handle := #in~handle;havoc ~retValue_acc~39; {2916#true} is VALID [2022-02-20 17:56:02,319 INFO L290 TraceCheckUtils]: 1: Hoare triple {2916#true} assume 1 == ~handle;~retValue_acc~39 := ~__ste_email_isEncrypted0~0;#res := ~retValue_acc~39; {2916#true} is VALID [2022-02-20 17:56:02,319 INFO L290 TraceCheckUtils]: 2: Hoare triple {2916#true} assume true; {2916#true} is VALID [2022-02-20 17:56:02,319 INFO L284 TraceCheckUtils]: 3: Hoare quadruple {2916#true} {2917#false} #1067#return; {2917#false} is VALID [2022-02-20 17:56:02,319 INFO L290 TraceCheckUtils]: 0: Hoare triple {2916#true} assume { :begin_inline_ULTIMATE.init } true;#NULL.base, #NULL.offset := 0, 0;assume 0 == #valid[0];assume 0 < #StackHeapBarrier;call #Ultimate.allocInit(2, 1);call write~init~int(48, 1, 0, 1);call write~init~int(0, 1, 1, 1);call #Ultimate.allocInit(28, 2);call #Ultimate.allocInit(12, 3);call #Ultimate.allocInit(4, 4);call write~init~int(37, 4, 0, 1);call write~init~int(115, 4, 1, 1);call write~init~int(10, 4, 2, 1);call write~init~int(0, 4, 3, 1);call #Ultimate.allocInit(10, 5);call #Ultimate.allocInit(12, 6);call #Ultimate.allocInit(10, 7);call #Ultimate.allocInit(18, 8);call #Ultimate.allocInit(16, 9);call #Ultimate.allocInit(21, 10);call #Ultimate.allocInit(13, 11);call #Ultimate.allocInit(16, 12);call #Ultimate.allocInit(25, 13);call #Ultimate.allocInit(30, 14);call #Ultimate.allocInit(9, 15);call #Ultimate.allocInit(21, 16);call #Ultimate.allocInit(30, 17);call #Ultimate.allocInit(9, 18);call #Ultimate.allocInit(21, 19);call #Ultimate.allocInit(30, 20);call #Ultimate.allocInit(9, 21);call #Ultimate.allocInit(25, 22);call #Ultimate.allocInit(30, 23);call #Ultimate.allocInit(9, 24);call #Ultimate.allocInit(25, 25);call #Ultimate.allocInit(10, 26);call #Ultimate.allocInit(16, 27);call #Ultimate.allocInit(20, 28);call #Ultimate.allocInit(22, 29);call #Ultimate.allocInit(21, 30);call #Ultimate.allocInit(13, 31);call #Ultimate.allocInit(44, 32);call #Ultimate.allocInit(44, 33);call #Ultimate.allocInit(9, 34);call #Ultimate.allocInit(9, 35);call #Ultimate.allocInit(11, 36);call #Ultimate.allocInit(19, 37);call #Ultimate.allocInit(4, 38);call write~init~int(37, 38, 0, 1);call write~init~int(100, 38, 1, 1);call write~init~int(10, 38, 2, 1);call write~init~int(0, 38, 3, 1);call #Ultimate.allocInit(4, 39);call write~init~int(37, 39, 0, 1);call write~init~int(100, 39, 1, 1);call write~init~int(10, 39, 2, 1);call write~init~int(0, 39, 3, 1);~__SELECTED_FEATURE_Base~0 := 0;~__SELECTED_FEATURE_Keys~0 := 0;~__SELECTED_FEATURE_Encrypt~0 := 0;~__SELECTED_FEATURE_AutoResponder~0 := 0;~__SELECTED_FEATURE_AddressBook~0 := 0;~__SELECTED_FEATURE_Sign~0 := 0;~__SELECTED_FEATURE_Forward~0 := 0;~__SELECTED_FEATURE_Verify~0 := 0;~__SELECTED_FEATURE_Decrypt~0 := 0;~__GUIDSL_ROOT_PRODUCTION~0 := 0;~__GUIDSL_NON_TERMINAL_main~0 := 0;~head~0.base, ~head~0.offset := 0, 0;~queue_empty~0 := 1;~queued_message~0 := 0;~queued_client~0 := 0;~mail_is_sensitive~0 := -1;~__ste_Client_counter~0 := 0;~__ste_client_name0~0.base, ~__ste_client_name0~0.offset := 0, 0;~__ste_client_name1~0.base, ~__ste_client_name1~0.offset := 0, 0;~__ste_client_name2~0.base, ~__ste_client_name2~0.offset := 0, 0;~__ste_client_outbuffer0~0 := 0;~__ste_client_outbuffer1~0 := 0;~__ste_client_outbuffer2~0 := 0;~__ste_client_outbuffer3~0 := 0;~__ste_ClientAddressBook_size0~0 := 0;~__ste_ClientAddressBook_size1~0 := 0;~__ste_ClientAddressBook_size2~0 := 0;~__ste_Client_AddressBook0_Alias0~0 := 0;~__ste_Client_AddressBook0_Alias1~0 := 0;~__ste_Client_AddressBook0_Alias2~0 := 0;~__ste_Client_AddressBook1_Alias0~0 := 0;~__ste_Client_AddressBook1_Alias1~0 := 0;~__ste_Client_AddressBook1_Alias2~0 := 0;~__ste_Client_AddressBook2_Alias0~0 := 0;~__ste_Client_AddressBook2_Alias1~0 := 0;~__ste_Client_AddressBook2_Alias2~0 := 0;~__ste_Client_AddressBook0_Address0~0 := 0;~__ste_Client_AddressBook0_Address1~0 := 0;~__ste_Client_AddressBook0_Address2~0 := 0;~__ste_Client_AddressBook1_Address0~0 := 0;~__ste_Client_AddressBook1_Address1~0 := 0;~__ste_Client_AddressBook1_Address2~0 := 0;~__ste_Client_AddressBook2_Address0~0 := 0;~__ste_Client_AddressBook2_Address1~0 := 0;~__ste_Client_AddressBook2_Address2~0 := 0;~__ste_client_autoResponse0~0 := 0;~__ste_client_autoResponse1~0 := 0;~__ste_client_autoResponse2~0 := 0;~__ste_client_privateKey0~0 := 0;~__ste_client_privateKey1~0 := 0;~__ste_client_privateKey2~0 := 0;~__ste_ClientKeyring_size0~0 := 0;~__ste_ClientKeyring_size1~0 := 0;~__ste_ClientKeyring_size2~0 := 0;~__ste_Client_Keyring0_User0~0 := 0;~__ste_Client_Keyring0_User1~0 := 0;~__ste_Client_Keyring0_User2~0 := 0;~__ste_Client_Keyring1_User0~0 := 0;~__ste_Client_Keyring1_User1~0 := 0;~__ste_Client_Keyring1_User2~0 := 0;~__ste_Client_Keyring2_User0~0 := 0;~__ste_Client_Keyring2_User1~0 := 0;~__ste_Client_Keyring2_User2~0 := 0;~__ste_Client_Keyring0_PublicKey0~0 := 0;~__ste_Client_Keyring0_PublicKey1~0 := 0;~__ste_Client_Keyring0_PublicKey2~0 := 0;~__ste_Client_Keyring1_PublicKey0~0 := 0;~__ste_Client_Keyring1_PublicKey1~0 := 0;~__ste_Client_Keyring1_PublicKey2~0 := 0;~__ste_Client_Keyring2_PublicKey0~0 := 0;~__ste_Client_Keyring2_PublicKey1~0 := 0;~__ste_Client_Keyring2_PublicKey2~0 := 0;~__ste_client_forwardReceiver0~0 := 0;~__ste_client_forwardReceiver1~0 := 0;~__ste_client_forwardReceiver2~0 := 0;~__ste_client_forwardReceiver3~0 := 0;~__ste_client_idCounter0~0 := 0;~__ste_client_idCounter1~0 := 0;~__ste_client_idCounter2~0 := 0;~bob~0 := 0;~rjh~0 := 0;~chuck~0 := 0;~__ste_Email_counter~0 := 0;~__ste_email_id0~0 := 0;~__ste_email_id1~0 := 0;~__ste_email_from0~0 := 0;~__ste_email_from1~0 := 0;~__ste_email_to0~0 := 0;~__ste_email_to1~0 := 0;~__ste_email_subject0~0.base, ~__ste_email_subject0~0.offset := 0, 0;~__ste_email_subject1~0.base, ~__ste_email_subject1~0.offset := 0, 0;~__ste_email_body0~0.base, ~__ste_email_body0~0.offset := 0, 0;~__ste_email_body1~0.base, ~__ste_email_body1~0.offset := 0, 0;~__ste_email_isEncrypted0~0 := 0;~__ste_email_isEncrypted1~0 := 0;~__ste_email_encryptionKey0~0 := 0;~__ste_email_encryptionKey1~0 := 0;~__ste_email_isSigned0~0 := 0;~__ste_email_isSigned1~0 := 0;~__ste_email_signKey0~0 := 0;~__ste_email_signKey1~0 := 0;~__ste_email_isSignatureVerified0~0 := 0;~__ste_email_isSignatureVerified1~0 := 0; {2916#true} is VALID [2022-02-20 17:56:02,319 INFO L290 TraceCheckUtils]: 1: Hoare triple {2916#true} assume { :end_inline_ULTIMATE.init } true;assume { :begin_inline_main } true;havoc main_#res#1;havoc main_#t~ret98#1, main_~retValue_acc~32#1, main_~tmp~24#1;havoc main_~retValue_acc~32#1;havoc main_~tmp~24#1;assume { :begin_inline_select_helpers } true; {2916#true} is VALID [2022-02-20 17:56:02,320 INFO L290 TraceCheckUtils]: 2: Hoare triple {2916#true} assume { :end_inline_select_helpers } true;assume { :begin_inline_select_features } true; {2916#true} is VALID [2022-02-20 17:56:02,320 INFO L290 TraceCheckUtils]: 3: Hoare triple {2916#true} assume { :end_inline_select_features } true;assume { :begin_inline_valid_product } true;havoc valid_product_#res#1;havoc valid_product_~retValue_acc~9#1;havoc valid_product_~retValue_acc~9#1;valid_product_~retValue_acc~9#1 := 1;valid_product_#res#1 := valid_product_~retValue_acc~9#1; {2916#true} is VALID [2022-02-20 17:56:02,320 INFO L290 TraceCheckUtils]: 4: Hoare triple {2916#true} main_#t~ret98#1 := valid_product_#res#1;assume { :end_inline_valid_product } true;assume -2147483648 <= main_#t~ret98#1 && main_#t~ret98#1 <= 2147483647;main_~tmp~24#1 := main_#t~ret98#1;havoc main_#t~ret98#1; {2916#true} is VALID [2022-02-20 17:56:02,320 INFO L290 TraceCheckUtils]: 5: Hoare triple {2916#true} assume 0 != main_~tmp~24#1;assume { :begin_inline_setup } true;havoc setup_#t~nondet95#1, setup_#t~nondet96#1, setup_#t~nondet97#1, setup_~__cil_tmp1~0#1.base, setup_~__cil_tmp1~0#1.offset, setup_~__cil_tmp2~0#1.base, setup_~__cil_tmp2~0#1.offset, setup_~__cil_tmp3~2#1.base, setup_~__cil_tmp3~2#1.offset;havoc setup_~__cil_tmp1~0#1.base, setup_~__cil_tmp1~0#1.offset;havoc setup_~__cil_tmp2~0#1.base, setup_~__cil_tmp2~0#1.offset;havoc setup_~__cil_tmp3~2#1.base, setup_~__cil_tmp3~2#1.offset;~bob~0 := 1;assume { :begin_inline_setup_bob } true;setup_bob_#in~bob___0#1 := ~bob~0;havoc setup_bob_~bob___0#1;setup_bob_~bob___0#1 := setup_bob_#in~bob___0#1;assume { :begin_inline_setup_bob__wrappee__Base } true;setup_bob__wrappee__Base_#in~bob___0#1 := setup_bob_~bob___0#1;havoc setup_bob__wrappee__Base_~bob___0#1;setup_bob__wrappee__Base_~bob___0#1 := setup_bob__wrappee__Base_#in~bob___0#1; {2916#true} is VALID [2022-02-20 17:56:02,320 INFO L272 TraceCheckUtils]: 6: Hoare triple {2916#true} call setClientId(setup_bob__wrappee__Base_~bob___0#1, setup_bob__wrappee__Base_~bob___0#1); {2972#(and (= |old(~__ste_client_idCounter0~0)| ~__ste_client_idCounter0~0) (= |old(~__ste_client_idCounter1~0)| ~__ste_client_idCounter1~0) (= |old(~__ste_client_idCounter2~0)| ~__ste_client_idCounter2~0))} is VALID [2022-02-20 17:56:02,320 INFO L290 TraceCheckUtils]: 7: Hoare triple {2972#(and (= |old(~__ste_client_idCounter0~0)| ~__ste_client_idCounter0~0) (= |old(~__ste_client_idCounter1~0)| ~__ste_client_idCounter1~0) (= |old(~__ste_client_idCounter2~0)| ~__ste_client_idCounter2~0))} ~handle := #in~handle;~value := #in~value; {2916#true} is VALID [2022-02-20 17:56:02,320 INFO L290 TraceCheckUtils]: 8: Hoare triple {2916#true} assume 1 == ~handle;~__ste_client_idCounter0~0 := ~value; {2916#true} is VALID [2022-02-20 17:56:02,321 INFO L290 TraceCheckUtils]: 9: Hoare triple {2916#true} assume true; {2916#true} is VALID [2022-02-20 17:56:02,321 INFO L284 TraceCheckUtils]: 10: Hoare quadruple {2916#true} {2916#true} #1133#return; {2916#true} is VALID [2022-02-20 17:56:02,321 INFO L290 TraceCheckUtils]: 11: Hoare triple {2916#true} assume { :end_inline_setup_bob__wrappee__Base } true; {2916#true} is VALID [2022-02-20 17:56:02,321 INFO L272 TraceCheckUtils]: 12: Hoare triple {2916#true} call setClientPrivateKey(setup_bob_~bob___0#1, 123); {2973#(and (= ~__ste_client_privateKey0~0 |old(~__ste_client_privateKey0~0)|) (= ~__ste_client_privateKey2~0 |old(~__ste_client_privateKey2~0)|) (= ~__ste_client_privateKey1~0 |old(~__ste_client_privateKey1~0)|))} is VALID [2022-02-20 17:56:02,321 INFO L290 TraceCheckUtils]: 13: Hoare triple {2973#(and (= ~__ste_client_privateKey0~0 |old(~__ste_client_privateKey0~0)|) (= ~__ste_client_privateKey2~0 |old(~__ste_client_privateKey2~0)|) (= ~__ste_client_privateKey1~0 |old(~__ste_client_privateKey1~0)|))} ~handle := #in~handle;~value := #in~value; {2916#true} is VALID [2022-02-20 17:56:02,321 INFO L290 TraceCheckUtils]: 14: Hoare triple {2916#true} assume 1 == ~handle;~__ste_client_privateKey0~0 := ~value; {2916#true} is VALID [2022-02-20 17:56:02,321 INFO L290 TraceCheckUtils]: 15: Hoare triple {2916#true} assume true; {2916#true} is VALID [2022-02-20 17:56:02,321 INFO L284 TraceCheckUtils]: 16: Hoare quadruple {2916#true} {2916#true} #1135#return; {2916#true} is VALID [2022-02-20 17:56:02,322 INFO L290 TraceCheckUtils]: 17: Hoare triple {2916#true} assume { :end_inline_setup_bob } true;setup_~__cil_tmp1~0#1.base, setup_~__cil_tmp1~0#1.offset := 34, 0;havoc setup_#t~nondet95#1;~rjh~0 := 2;assume { :begin_inline_setup_rjh } true;setup_rjh_#in~rjh___0#1 := ~rjh~0;havoc setup_rjh_~rjh___0#1;setup_rjh_~rjh___0#1 := setup_rjh_#in~rjh___0#1;assume { :begin_inline_setup_rjh__wrappee__Base } true;setup_rjh__wrappee__Base_#in~rjh___0#1 := setup_rjh_~rjh___0#1;havoc setup_rjh__wrappee__Base_~rjh___0#1;setup_rjh__wrappee__Base_~rjh___0#1 := setup_rjh__wrappee__Base_#in~rjh___0#1; {2926#(= |ULTIMATE.start_setup_rjh__wrappee__Base_~rjh___0#1| 2)} is VALID [2022-02-20 17:56:02,322 INFO L272 TraceCheckUtils]: 18: Hoare triple {2926#(= |ULTIMATE.start_setup_rjh__wrappee__Base_~rjh___0#1| 2)} call setClientId(setup_rjh__wrappee__Base_~rjh___0#1, setup_rjh__wrappee__Base_~rjh___0#1); {2972#(and (= |old(~__ste_client_idCounter0~0)| ~__ste_client_idCounter0~0) (= |old(~__ste_client_idCounter1~0)| ~__ste_client_idCounter1~0) (= |old(~__ste_client_idCounter2~0)| ~__ste_client_idCounter2~0))} is VALID [2022-02-20 17:56:02,323 INFO L290 TraceCheckUtils]: 19: Hoare triple {2972#(and (= |old(~__ste_client_idCounter0~0)| ~__ste_client_idCounter0~0) (= |old(~__ste_client_idCounter1~0)| ~__ste_client_idCounter1~0) (= |old(~__ste_client_idCounter2~0)| ~__ste_client_idCounter2~0))} ~handle := #in~handle;~value := #in~value; {2974#(= setClientId_~handle |setClientId_#in~handle|)} is VALID [2022-02-20 17:56:02,323 INFO L290 TraceCheckUtils]: 20: Hoare triple {2974#(= setClientId_~handle |setClientId_#in~handle|)} assume 1 == ~handle;~__ste_client_idCounter0~0 := ~value; {2975#(= |setClientId_#in~handle| 1)} is VALID [2022-02-20 17:56:02,323 INFO L290 TraceCheckUtils]: 21: Hoare triple {2975#(= |setClientId_#in~handle| 1)} assume true; {2975#(= |setClientId_#in~handle| 1)} is VALID [2022-02-20 17:56:02,324 INFO L284 TraceCheckUtils]: 22: Hoare quadruple {2975#(= |setClientId_#in~handle| 1)} {2926#(= |ULTIMATE.start_setup_rjh__wrappee__Base_~rjh___0#1| 2)} #1137#return; {2917#false} is VALID [2022-02-20 17:56:02,324 INFO L290 TraceCheckUtils]: 23: Hoare triple {2917#false} assume { :end_inline_setup_rjh__wrappee__Base } true; {2917#false} is VALID [2022-02-20 17:56:02,324 INFO L272 TraceCheckUtils]: 24: Hoare triple {2917#false} call setClientPrivateKey(setup_rjh_~rjh___0#1, 456); {2973#(and (= ~__ste_client_privateKey0~0 |old(~__ste_client_privateKey0~0)|) (= ~__ste_client_privateKey2~0 |old(~__ste_client_privateKey2~0)|) (= ~__ste_client_privateKey1~0 |old(~__ste_client_privateKey1~0)|))} is VALID [2022-02-20 17:56:02,324 INFO L290 TraceCheckUtils]: 25: Hoare triple {2973#(and (= ~__ste_client_privateKey0~0 |old(~__ste_client_privateKey0~0)|) (= ~__ste_client_privateKey2~0 |old(~__ste_client_privateKey2~0)|) (= ~__ste_client_privateKey1~0 |old(~__ste_client_privateKey1~0)|))} ~handle := #in~handle;~value := #in~value; {2916#true} is VALID [2022-02-20 17:56:02,324 INFO L290 TraceCheckUtils]: 26: Hoare triple {2916#true} assume 1 == ~handle;~__ste_client_privateKey0~0 := ~value; {2916#true} is VALID [2022-02-20 17:56:02,324 INFO L290 TraceCheckUtils]: 27: Hoare triple {2916#true} assume true; {2916#true} is VALID [2022-02-20 17:56:02,324 INFO L284 TraceCheckUtils]: 28: Hoare quadruple {2916#true} {2917#false} #1139#return; {2917#false} is VALID [2022-02-20 17:56:02,324 INFO L290 TraceCheckUtils]: 29: Hoare triple {2917#false} assume { :end_inline_setup_rjh } true;setup_~__cil_tmp2~0#1.base, setup_~__cil_tmp2~0#1.offset := 35, 0;havoc setup_#t~nondet96#1;~chuck~0 := 3;assume { :begin_inline_setup_chuck } true;setup_chuck_#in~chuck___0#1 := ~chuck~0;havoc setup_chuck_~chuck___0#1;setup_chuck_~chuck___0#1 := setup_chuck_#in~chuck___0#1;assume { :begin_inline_setup_chuck__wrappee__Base } true;setup_chuck__wrappee__Base_#in~chuck___0#1 := setup_chuck_~chuck___0#1;havoc setup_chuck__wrappee__Base_~chuck___0#1;setup_chuck__wrappee__Base_~chuck___0#1 := setup_chuck__wrappee__Base_#in~chuck___0#1; {2917#false} is VALID [2022-02-20 17:56:02,324 INFO L272 TraceCheckUtils]: 30: Hoare triple {2917#false} call setClientId(setup_chuck__wrappee__Base_~chuck___0#1, setup_chuck__wrappee__Base_~chuck___0#1); {2972#(and (= |old(~__ste_client_idCounter0~0)| ~__ste_client_idCounter0~0) (= |old(~__ste_client_idCounter1~0)| ~__ste_client_idCounter1~0) (= |old(~__ste_client_idCounter2~0)| ~__ste_client_idCounter2~0))} is VALID [2022-02-20 17:56:02,325 INFO L290 TraceCheckUtils]: 31: Hoare triple {2972#(and (= |old(~__ste_client_idCounter0~0)| ~__ste_client_idCounter0~0) (= |old(~__ste_client_idCounter1~0)| ~__ste_client_idCounter1~0) (= |old(~__ste_client_idCounter2~0)| ~__ste_client_idCounter2~0))} ~handle := #in~handle;~value := #in~value; {2916#true} is VALID [2022-02-20 17:56:02,325 INFO L290 TraceCheckUtils]: 32: Hoare triple {2916#true} assume 1 == ~handle;~__ste_client_idCounter0~0 := ~value; {2916#true} is VALID [2022-02-20 17:56:02,325 INFO L290 TraceCheckUtils]: 33: Hoare triple {2916#true} assume true; {2916#true} is VALID [2022-02-20 17:56:02,325 INFO L284 TraceCheckUtils]: 34: Hoare quadruple {2916#true} {2917#false} #1141#return; {2917#false} is VALID [2022-02-20 17:56:02,325 INFO L290 TraceCheckUtils]: 35: Hoare triple {2917#false} assume { :end_inline_setup_chuck__wrappee__Base } true; {2917#false} is VALID [2022-02-20 17:56:02,325 INFO L272 TraceCheckUtils]: 36: Hoare triple {2917#false} call setClientPrivateKey(setup_chuck_~chuck___0#1, 789); {2973#(and (= ~__ste_client_privateKey0~0 |old(~__ste_client_privateKey0~0)|) (= ~__ste_client_privateKey2~0 |old(~__ste_client_privateKey2~0)|) (= ~__ste_client_privateKey1~0 |old(~__ste_client_privateKey1~0)|))} is VALID [2022-02-20 17:56:02,325 INFO L290 TraceCheckUtils]: 37: Hoare triple {2973#(and (= ~__ste_client_privateKey0~0 |old(~__ste_client_privateKey0~0)|) (= ~__ste_client_privateKey2~0 |old(~__ste_client_privateKey2~0)|) (= ~__ste_client_privateKey1~0 |old(~__ste_client_privateKey1~0)|))} ~handle := #in~handle;~value := #in~value; {2916#true} is VALID [2022-02-20 17:56:02,325 INFO L290 TraceCheckUtils]: 38: Hoare triple {2916#true} assume 1 == ~handle;~__ste_client_privateKey0~0 := ~value; {2916#true} is VALID [2022-02-20 17:56:02,325 INFO L290 TraceCheckUtils]: 39: Hoare triple {2916#true} assume true; {2916#true} is VALID [2022-02-20 17:56:02,325 INFO L284 TraceCheckUtils]: 40: Hoare quadruple {2916#true} {2917#false} #1143#return; {2917#false} is VALID [2022-02-20 17:56:02,325 INFO L290 TraceCheckUtils]: 41: Hoare triple {2917#false} assume { :end_inline_setup_chuck } true;setup_~__cil_tmp3~2#1.base, setup_~__cil_tmp3~2#1.offset := 36, 0;havoc setup_#t~nondet97#1; {2917#false} is VALID [2022-02-20 17:56:02,325 INFO L290 TraceCheckUtils]: 42: Hoare triple {2917#false} assume { :end_inline_setup } true;assume { :begin_inline_test } true;havoc test_#t~nondet48#1, test_#t~nondet49#1, test_#t~nondet50#1, test_#t~nondet51#1, test_#t~nondet52#1, test_#t~nondet53#1, test_#t~nondet54#1, test_#t~nondet55#1, test_#t~nondet56#1, test_#t~nondet57#1, test_#t~nondet58#1, test_~op1~0#1, test_~op2~0#1, test_~op3~0#1, test_~op4~0#1, test_~op5~0#1, test_~op6~0#1, test_~op7~0#1, test_~op8~0#1, test_~op9~0#1, test_~op10~0#1, test_~op11~0#1, test_~splverifierCounter~0#1, test_~tmp~8#1, test_~tmp___0~3#1, test_~tmp___1~1#1, test_~tmp___2~1#1, test_~tmp___3~0#1, test_~tmp___4~0#1, test_~tmp___5~0#1, test_~tmp___6~0#1, test_~tmp___7~0#1, test_~tmp___8~0#1, test_~tmp___9~0#1;havoc test_~op1~0#1;havoc test_~op2~0#1;havoc test_~op3~0#1;havoc test_~op4~0#1;havoc test_~op5~0#1;havoc test_~op6~0#1;havoc test_~op7~0#1;havoc test_~op8~0#1;havoc test_~op9~0#1;havoc test_~op10~0#1;havoc test_~op11~0#1;havoc test_~splverifierCounter~0#1;havoc test_~tmp~8#1;havoc test_~tmp___0~3#1;havoc test_~tmp___1~1#1;havoc test_~tmp___2~1#1;havoc test_~tmp___3~0#1;havoc test_~tmp___4~0#1;havoc test_~tmp___5~0#1;havoc test_~tmp___6~0#1;havoc test_~tmp___7~0#1;havoc test_~tmp___8~0#1;havoc test_~tmp___9~0#1;test_~op1~0#1 := 0;test_~op2~0#1 := 0;test_~op3~0#1 := 0;test_~op4~0#1 := 0;test_~op5~0#1 := 0;test_~op6~0#1 := 0;test_~op7~0#1 := 0;test_~op8~0#1 := 0;test_~op9~0#1 := 0;test_~op10~0#1 := 0;test_~op11~0#1 := 0;test_~splverifierCounter~0#1 := 0; {2917#false} is VALID [2022-02-20 17:56:02,325 INFO L290 TraceCheckUtils]: 43: Hoare triple {2917#false} assume !false; {2917#false} is VALID [2022-02-20 17:56:02,325 INFO L290 TraceCheckUtils]: 44: Hoare triple {2917#false} assume !(test_~splverifierCounter~0#1 < 4); {2917#false} is VALID [2022-02-20 17:56:02,339 INFO L290 TraceCheckUtils]: 45: Hoare triple {2917#false} assume { :begin_inline_bobToRjh } true;havoc bobToRjh_#t~ret90#1, bobToRjh_#t~ret91#1, bobToRjh_#t~ret92#1, bobToRjh_#t~ret93#1, bobToRjh_~tmp~23#1, bobToRjh_~tmp___0~7#1, bobToRjh_~tmp___1~4#1;havoc bobToRjh_~tmp~23#1;havoc bobToRjh_~tmp___0~7#1;havoc bobToRjh_~tmp___1~4#1;call bobToRjh_#t~ret90#1 := puts(32, 0);assume -2147483648 <= bobToRjh_#t~ret90#1 && bobToRjh_#t~ret90#1 <= 2147483647;havoc bobToRjh_#t~ret90#1; {2917#false} is VALID [2022-02-20 17:56:02,339 INFO L272 TraceCheckUtils]: 46: Hoare triple {2917#false} call sendEmail(~bob~0, ~rjh~0); {2917#false} is VALID [2022-02-20 17:56:02,339 INFO L290 TraceCheckUtils]: 47: Hoare triple {2917#false} ~sender#1 := #in~sender#1;~receiver#1 := #in~receiver#1;havoc ~email~0#1;havoc ~tmp~16#1;assume { :begin_inline_createEmail } true;createEmail_#in~from#1, createEmail_#in~to#1 := 0, ~receiver#1;havoc createEmail_#res#1;havoc createEmail_~from#1, createEmail_~to#1, createEmail_~retValue_acc~4#1, createEmail_~msg~0#1;createEmail_~from#1 := createEmail_#in~from#1;createEmail_~to#1 := createEmail_#in~to#1;havoc createEmail_~retValue_acc~4#1;havoc createEmail_~msg~0#1;createEmail_~msg~0#1 := 1; {2917#false} is VALID [2022-02-20 17:56:02,339 INFO L272 TraceCheckUtils]: 48: Hoare triple {2917#false} call setEmailFrom(createEmail_~msg~0#1, createEmail_~from#1); {2976#(and (= |old(~__ste_email_from0~0)| ~__ste_email_from0~0) (= |old(~__ste_email_from1~0)| ~__ste_email_from1~0))} is VALID [2022-02-20 17:56:02,339 INFO L290 TraceCheckUtils]: 49: Hoare triple {2976#(and (= |old(~__ste_email_from0~0)| ~__ste_email_from0~0) (= |old(~__ste_email_from1~0)| ~__ste_email_from1~0))} ~handle := #in~handle;~value := #in~value; {2916#true} is VALID [2022-02-20 17:56:02,340 INFO L290 TraceCheckUtils]: 50: Hoare triple {2916#true} assume 1 == ~handle;~__ste_email_from0~0 := ~value; {2916#true} is VALID [2022-02-20 17:56:02,340 INFO L290 TraceCheckUtils]: 51: Hoare triple {2916#true} assume true; {2916#true} is VALID [2022-02-20 17:56:02,340 INFO L284 TraceCheckUtils]: 52: Hoare quadruple {2916#true} {2917#false} #1119#return; {2917#false} is VALID [2022-02-20 17:56:02,340 INFO L272 TraceCheckUtils]: 53: Hoare triple {2917#false} call setEmailTo(createEmail_~msg~0#1, createEmail_~to#1); {2977#(and (= ~__ste_email_to0~0 |old(~__ste_email_to0~0)|) (= ~__ste_email_to1~0 |old(~__ste_email_to1~0)|))} is VALID [2022-02-20 17:56:02,340 INFO L290 TraceCheckUtils]: 54: Hoare triple {2977#(and (= ~__ste_email_to0~0 |old(~__ste_email_to0~0)|) (= ~__ste_email_to1~0 |old(~__ste_email_to1~0)|))} ~handle := #in~handle;~value := #in~value; {2916#true} is VALID [2022-02-20 17:56:02,340 INFO L290 TraceCheckUtils]: 55: Hoare triple {2916#true} assume 1 == ~handle;~__ste_email_to0~0 := ~value; {2916#true} is VALID [2022-02-20 17:56:02,340 INFO L290 TraceCheckUtils]: 56: Hoare triple {2916#true} assume true; {2916#true} is VALID [2022-02-20 17:56:02,340 INFO L284 TraceCheckUtils]: 57: Hoare quadruple {2916#true} {2917#false} #1121#return; {2917#false} is VALID [2022-02-20 17:56:02,340 INFO L290 TraceCheckUtils]: 58: Hoare triple {2917#false} createEmail_~retValue_acc~4#1 := createEmail_~msg~0#1;createEmail_#res#1 := createEmail_~retValue_acc~4#1; {2917#false} is VALID [2022-02-20 17:56:02,341 INFO L290 TraceCheckUtils]: 59: Hoare triple {2917#false} #t~ret73#1 := createEmail_#res#1;assume { :end_inline_createEmail } true;assume -2147483648 <= #t~ret73#1 && #t~ret73#1 <= 2147483647;~tmp~16#1 := #t~ret73#1;havoc #t~ret73#1;~email~0#1 := ~tmp~16#1; {2917#false} is VALID [2022-02-20 17:56:02,341 INFO L272 TraceCheckUtils]: 60: Hoare triple {2917#false} call outgoing(~sender#1, ~email~0#1); {2917#false} is VALID [2022-02-20 17:56:02,341 INFO L290 TraceCheckUtils]: 61: Hoare triple {2917#false} ~client#1 := #in~client#1;~msg#1 := #in~msg#1;assume { :begin_inline_sign } true;sign_#in~client#1, sign_#in~msg#1 := ~client#1, ~msg#1;havoc sign_#t~ret77#1, sign_~client#1, sign_~msg#1, sign_~privkey~1#1, sign_~tmp~18#1;sign_~client#1 := sign_#in~client#1;sign_~msg#1 := sign_#in~msg#1;havoc sign_~privkey~1#1;havoc sign_~tmp~18#1; {2917#false} is VALID [2022-02-20 17:56:02,341 INFO L272 TraceCheckUtils]: 62: Hoare triple {2917#false} call sign_#t~ret77#1 := getClientPrivateKey(sign_~client#1); {2916#true} is VALID [2022-02-20 17:56:02,341 INFO L290 TraceCheckUtils]: 63: Hoare triple {2916#true} ~handle := #in~handle;havoc ~retValue_acc~24; {2916#true} is VALID [2022-02-20 17:56:02,341 INFO L290 TraceCheckUtils]: 64: Hoare triple {2916#true} assume 1 == ~handle;~retValue_acc~24 := ~__ste_client_privateKey0~0;#res := ~retValue_acc~24; {2916#true} is VALID [2022-02-20 17:56:02,341 INFO L290 TraceCheckUtils]: 65: Hoare triple {2916#true} assume true; {2916#true} is VALID [2022-02-20 17:56:02,344 INFO L284 TraceCheckUtils]: 66: Hoare quadruple {2916#true} {2917#false} #1053#return; {2917#false} is VALID [2022-02-20 17:56:02,346 INFO L290 TraceCheckUtils]: 67: Hoare triple {2917#false} assume -2147483648 <= sign_#t~ret77#1 && sign_#t~ret77#1 <= 2147483647;sign_~tmp~18#1 := sign_#t~ret77#1;havoc sign_#t~ret77#1;sign_~privkey~1#1 := sign_~tmp~18#1; {2917#false} is VALID [2022-02-20 17:56:02,347 INFO L290 TraceCheckUtils]: 68: Hoare triple {2917#false} assume 0 == sign_~privkey~1#1; {2917#false} is VALID [2022-02-20 17:56:02,352 INFO L290 TraceCheckUtils]: 69: Hoare triple {2917#false} assume { :end_inline_sign } true;assume { :begin_inline_outgoing__wrappee__AutoResponder } true;outgoing__wrappee__AutoResponder_#in~client#1, outgoing__wrappee__AutoResponder_#in~msg#1 := ~client#1, ~msg#1;havoc outgoing__wrappee__AutoResponder_#t~ret63#1, outgoing__wrappee__AutoResponder_#t~ret64#1, outgoing__wrappee__AutoResponder_~client#1, outgoing__wrappee__AutoResponder_~msg#1, outgoing__wrappee__AutoResponder_~receiver~0#1, outgoing__wrappee__AutoResponder_~tmp~11#1, outgoing__wrappee__AutoResponder_~pubkey~0#1, outgoing__wrappee__AutoResponder_~tmp___0~4#1;outgoing__wrappee__AutoResponder_~client#1 := outgoing__wrappee__AutoResponder_#in~client#1;outgoing__wrappee__AutoResponder_~msg#1 := outgoing__wrappee__AutoResponder_#in~msg#1;havoc outgoing__wrappee__AutoResponder_~receiver~0#1;havoc outgoing__wrappee__AutoResponder_~tmp~11#1;havoc outgoing__wrappee__AutoResponder_~pubkey~0#1;havoc outgoing__wrappee__AutoResponder_~tmp___0~4#1; {2917#false} is VALID [2022-02-20 17:56:02,352 INFO L272 TraceCheckUtils]: 70: Hoare triple {2917#false} call outgoing__wrappee__AutoResponder_#t~ret63#1 := getEmailTo(outgoing__wrappee__AutoResponder_~msg#1); {2916#true} is VALID [2022-02-20 17:56:02,352 INFO L290 TraceCheckUtils]: 71: Hoare triple {2916#true} ~handle := #in~handle;havoc ~retValue_acc~36; {2916#true} is VALID [2022-02-20 17:56:02,352 INFO L290 TraceCheckUtils]: 72: Hoare triple {2916#true} assume 1 == ~handle;~retValue_acc~36 := ~__ste_email_to0~0;#res := ~retValue_acc~36; {2916#true} is VALID [2022-02-20 17:56:02,353 INFO L290 TraceCheckUtils]: 73: Hoare triple {2916#true} assume true; {2916#true} is VALID [2022-02-20 17:56:02,353 INFO L284 TraceCheckUtils]: 74: Hoare quadruple {2916#true} {2917#false} #1055#return; {2917#false} is VALID [2022-02-20 17:56:02,354 INFO L290 TraceCheckUtils]: 75: Hoare triple {2917#false} assume -2147483648 <= outgoing__wrappee__AutoResponder_#t~ret63#1 && outgoing__wrappee__AutoResponder_#t~ret63#1 <= 2147483647;outgoing__wrappee__AutoResponder_~tmp~11#1 := outgoing__wrappee__AutoResponder_#t~ret63#1;havoc outgoing__wrappee__AutoResponder_#t~ret63#1;outgoing__wrappee__AutoResponder_~receiver~0#1 := outgoing__wrappee__AutoResponder_~tmp~11#1; {2917#false} is VALID [2022-02-20 17:56:02,354 INFO L272 TraceCheckUtils]: 76: Hoare triple {2917#false} call outgoing__wrappee__AutoResponder_#t~ret64#1 := findPublicKey(outgoing__wrappee__AutoResponder_~client#1, outgoing__wrappee__AutoResponder_~receiver~0#1); {2916#true} is VALID [2022-02-20 17:56:02,354 INFO L290 TraceCheckUtils]: 77: Hoare triple {2916#true} ~handle := #in~handle;~userid := #in~userid;havoc ~retValue_acc~29; {2916#true} is VALID [2022-02-20 17:56:02,354 INFO L290 TraceCheckUtils]: 78: Hoare triple {2916#true} assume 1 == ~handle; {2916#true} is VALID [2022-02-20 17:56:02,354 INFO L290 TraceCheckUtils]: 79: Hoare triple {2916#true} assume ~userid == ~__ste_Client_Keyring0_User0~0;~retValue_acc~29 := ~__ste_Client_Keyring0_PublicKey0~0;#res := ~retValue_acc~29; {2916#true} is VALID [2022-02-20 17:56:02,354 INFO L290 TraceCheckUtils]: 80: Hoare triple {2916#true} assume true; {2916#true} is VALID [2022-02-20 17:56:02,355 INFO L284 TraceCheckUtils]: 81: Hoare quadruple {2916#true} {2917#false} #1057#return; {2917#false} is VALID [2022-02-20 17:56:02,355 INFO L290 TraceCheckUtils]: 82: Hoare triple {2917#false} assume -2147483648 <= outgoing__wrappee__AutoResponder_#t~ret64#1 && outgoing__wrappee__AutoResponder_#t~ret64#1 <= 2147483647;outgoing__wrappee__AutoResponder_~tmp___0~4#1 := outgoing__wrappee__AutoResponder_#t~ret64#1;havoc outgoing__wrappee__AutoResponder_#t~ret64#1;outgoing__wrappee__AutoResponder_~pubkey~0#1 := outgoing__wrappee__AutoResponder_~tmp___0~4#1; {2917#false} is VALID [2022-02-20 17:56:02,355 INFO L290 TraceCheckUtils]: 83: Hoare triple {2917#false} assume !(0 != outgoing__wrappee__AutoResponder_~pubkey~0#1); {2917#false} is VALID [2022-02-20 17:56:02,355 INFO L290 TraceCheckUtils]: 84: Hoare triple {2917#false} assume { :begin_inline_outgoing__wrappee__Keys } true;outgoing__wrappee__Keys_#in~client#1, outgoing__wrappee__Keys_#in~msg#1 := outgoing__wrappee__AutoResponder_~client#1, outgoing__wrappee__AutoResponder_~msg#1;havoc outgoing__wrappee__Keys_#t~ret62#1, outgoing__wrappee__Keys_~client#1, outgoing__wrappee__Keys_~msg#1, outgoing__wrappee__Keys_~tmp~10#1;outgoing__wrappee__Keys_~client#1 := outgoing__wrappee__Keys_#in~client#1;outgoing__wrappee__Keys_~msg#1 := outgoing__wrappee__Keys_#in~msg#1;havoc outgoing__wrappee__Keys_~tmp~10#1;assume { :begin_inline_getClientId } true;getClientId_#in~handle#1 := outgoing__wrappee__Keys_~client#1;havoc getClientId_#res#1;havoc getClientId_~handle#1, getClientId_~retValue_acc~31#1;getClientId_~handle#1 := getClientId_#in~handle#1;havoc getClientId_~retValue_acc~31#1; {2917#false} is VALID [2022-02-20 17:56:02,355 INFO L290 TraceCheckUtils]: 85: Hoare triple {2917#false} assume 1 == getClientId_~handle#1;getClientId_~retValue_acc~31#1 := ~__ste_client_idCounter0~0;getClientId_#res#1 := getClientId_~retValue_acc~31#1; {2917#false} is VALID [2022-02-20 17:56:02,355 INFO L290 TraceCheckUtils]: 86: Hoare triple {2917#false} outgoing__wrappee__Keys_#t~ret62#1 := getClientId_#res#1;assume { :end_inline_getClientId } true;assume -2147483648 <= outgoing__wrappee__Keys_#t~ret62#1 && outgoing__wrappee__Keys_#t~ret62#1 <= 2147483647;outgoing__wrappee__Keys_~tmp~10#1 := outgoing__wrappee__Keys_#t~ret62#1;havoc outgoing__wrappee__Keys_#t~ret62#1; {2917#false} is VALID [2022-02-20 17:56:02,355 INFO L272 TraceCheckUtils]: 87: Hoare triple {2917#false} call setEmailFrom(outgoing__wrappee__Keys_~msg#1, outgoing__wrappee__Keys_~tmp~10#1); {2976#(and (= |old(~__ste_email_from0~0)| ~__ste_email_from0~0) (= |old(~__ste_email_from1~0)| ~__ste_email_from1~0))} is VALID [2022-02-20 17:56:02,355 INFO L290 TraceCheckUtils]: 88: Hoare triple {2976#(and (= |old(~__ste_email_from0~0)| ~__ste_email_from0~0) (= |old(~__ste_email_from1~0)| ~__ste_email_from1~0))} ~handle := #in~handle;~value := #in~value; {2916#true} is VALID [2022-02-20 17:56:02,356 INFO L290 TraceCheckUtils]: 89: Hoare triple {2916#true} assume 1 == ~handle;~__ste_email_from0~0 := ~value; {2916#true} is VALID [2022-02-20 17:56:02,356 INFO L290 TraceCheckUtils]: 90: Hoare triple {2916#true} assume true; {2916#true} is VALID [2022-02-20 17:56:02,356 INFO L284 TraceCheckUtils]: 91: Hoare quadruple {2916#true} {2917#false} #1063#return; {2917#false} is VALID [2022-02-20 17:56:02,356 INFO L290 TraceCheckUtils]: 92: Hoare triple {2917#false} assume { :begin_inline_mail } true;mail_#in~client#1, mail_#in~msg#1 := outgoing__wrappee__Keys_~client#1, outgoing__wrappee__Keys_~msg#1;havoc mail_#t~ret60#1, mail_#t~ret61#1, mail_~client#1, mail_~msg#1, mail_~__utac__ad__arg1~0#1, mail_~__utac__ad__arg2~0#1, mail_~tmp~9#1;mail_~client#1 := mail_#in~client#1;mail_~msg#1 := mail_#in~msg#1;havoc mail_~__utac__ad__arg1~0#1;havoc mail_~__utac__ad__arg2~0#1;havoc mail_~tmp~9#1;mail_~__utac__ad__arg1~0#1 := mail_~client#1;mail_~__utac__ad__arg2~0#1 := mail_~msg#1;assume { :begin_inline___utac_acc__AddressBookEncrypt_spec__1 } true;__utac_acc__AddressBookEncrypt_spec__1_#in~client#1, __utac_acc__AddressBookEncrypt_spec__1_#in~msg#1 := mail_~__utac__ad__arg1~0#1, mail_~__utac__ad__arg2~0#1;havoc __utac_acc__AddressBookEncrypt_spec__1_#t~ret85#1, __utac_acc__AddressBookEncrypt_spec__1_#t~ret86#1, __utac_acc__AddressBookEncrypt_spec__1_#t~ret87#1, __utac_acc__AddressBookEncrypt_spec__1_~client#1, __utac_acc__AddressBookEncrypt_spec__1_~msg#1, __utac_acc__AddressBookEncrypt_spec__1_~tmp~20#1;__utac_acc__AddressBookEncrypt_spec__1_~client#1 := __utac_acc__AddressBookEncrypt_spec__1_#in~client#1;__utac_acc__AddressBookEncrypt_spec__1_~msg#1 := __utac_acc__AddressBookEncrypt_spec__1_#in~msg#1;havoc __utac_acc__AddressBookEncrypt_spec__1_~tmp~20#1;call __utac_acc__AddressBookEncrypt_spec__1_#t~ret85#1 := puts(31, 0);assume -2147483648 <= __utac_acc__AddressBookEncrypt_spec__1_#t~ret85#1 && __utac_acc__AddressBookEncrypt_spec__1_#t~ret85#1 <= 2147483647;havoc __utac_acc__AddressBookEncrypt_spec__1_#t~ret85#1; {2917#false} is VALID [2022-02-20 17:56:02,356 INFO L290 TraceCheckUtils]: 93: Hoare triple {2917#false} assume !(-1 == ~mail_is_sensitive~0); {2917#false} is VALID [2022-02-20 17:56:02,356 INFO L272 TraceCheckUtils]: 94: Hoare triple {2917#false} call __utac_acc__AddressBookEncrypt_spec__1_#t~ret87#1 := isEncrypted(__utac_acc__AddressBookEncrypt_spec__1_~msg#1); {2916#true} is VALID [2022-02-20 17:56:02,356 INFO L290 TraceCheckUtils]: 95: Hoare triple {2916#true} ~handle := #in~handle;havoc ~retValue_acc~39; {2916#true} is VALID [2022-02-20 17:56:02,356 INFO L290 TraceCheckUtils]: 96: Hoare triple {2916#true} assume 1 == ~handle;~retValue_acc~39 := ~__ste_email_isEncrypted0~0;#res := ~retValue_acc~39; {2916#true} is VALID [2022-02-20 17:56:02,357 INFO L290 TraceCheckUtils]: 97: Hoare triple {2916#true} assume true; {2916#true} is VALID [2022-02-20 17:56:02,357 INFO L284 TraceCheckUtils]: 98: Hoare quadruple {2916#true} {2917#false} #1067#return; {2917#false} is VALID [2022-02-20 17:56:02,357 INFO L290 TraceCheckUtils]: 99: Hoare triple {2917#false} assume -2147483648 <= __utac_acc__AddressBookEncrypt_spec__1_#t~ret87#1 && __utac_acc__AddressBookEncrypt_spec__1_#t~ret87#1 <= 2147483647;__utac_acc__AddressBookEncrypt_spec__1_~tmp~20#1 := __utac_acc__AddressBookEncrypt_spec__1_#t~ret87#1;havoc __utac_acc__AddressBookEncrypt_spec__1_#t~ret87#1; {2917#false} is VALID [2022-02-20 17:56:02,357 INFO L290 TraceCheckUtils]: 100: Hoare triple {2917#false} assume ~mail_is_sensitive~0 != __utac_acc__AddressBookEncrypt_spec__1_~tmp~20#1;assume { :begin_inline___automaton_fail } true; {2917#false} is VALID [2022-02-20 17:56:02,358 INFO L290 TraceCheckUtils]: 101: Hoare triple {2917#false} assume !false; {2917#false} is VALID [2022-02-20 17:56:02,358 INFO L134 CoverageAnalysis]: Checked inductivity of 28 backedges. 3 proven. 3 refuted. 0 times theorem prover too weak. 22 trivial. 0 not checked. [2022-02-20 17:56:02,359 INFO L144 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2022-02-20 17:56:02,359 INFO L338 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [2078182810] [2022-02-20 17:56:02,359 INFO L165 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [2078182810] provided 0 perfect and 1 imperfect interpolant sequences [2022-02-20 17:56:02,360 INFO L338 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleZ3 [1876732126] [2022-02-20 17:56:02,360 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-02-20 17:56:02,361 INFO L173 SolverBuilder]: Constructing external solver with command: z3 -smt2 -in SMTLIB2_COMPLIANT=true [2022-02-20 17:56:02,361 INFO L189 MonitoredProcess]: No working directory specified, using /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 [2022-02-20 17:56:02,362 INFO L229 MonitoredProcess]: Starting monitored process 3 with /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 -smt2 -in SMTLIB2_COMPLIANT=true (exit command is (exit), workingDir is null) [2022-02-20 17:56:02,363 INFO L327 MonitoredProcess]: [MP /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 -smt2 -in SMTLIB2_COMPLIANT=true (3)] Waiting until timeout for monitored process [2022-02-20 17:56:02,591 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-02-20 17:56:02,594 INFO L263 TraceCheckSpWp]: Trace formula consists of 1056 conjuncts, 2 conjunts are in the unsatisfiable core [2022-02-20 17:56:02,636 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-02-20 17:56:02,638 INFO L286 TraceCheckSpWp]: Computing forward predicates... [2022-02-20 17:56:02,837 INFO L290 TraceCheckUtils]: 0: Hoare triple {2916#true} assume { :begin_inline_ULTIMATE.init } true;#NULL.base, #NULL.offset := 0, 0;assume 0 == #valid[0];assume 0 < #StackHeapBarrier;call #Ultimate.allocInit(2, 1);call write~init~int(48, 1, 0, 1);call write~init~int(0, 1, 1, 1);call #Ultimate.allocInit(28, 2);call #Ultimate.allocInit(12, 3);call #Ultimate.allocInit(4, 4);call write~init~int(37, 4, 0, 1);call write~init~int(115, 4, 1, 1);call write~init~int(10, 4, 2, 1);call write~init~int(0, 4, 3, 1);call #Ultimate.allocInit(10, 5);call #Ultimate.allocInit(12, 6);call #Ultimate.allocInit(10, 7);call #Ultimate.allocInit(18, 8);call #Ultimate.allocInit(16, 9);call #Ultimate.allocInit(21, 10);call #Ultimate.allocInit(13, 11);call #Ultimate.allocInit(16, 12);call #Ultimate.allocInit(25, 13);call #Ultimate.allocInit(30, 14);call #Ultimate.allocInit(9, 15);call #Ultimate.allocInit(21, 16);call #Ultimate.allocInit(30, 17);call #Ultimate.allocInit(9, 18);call #Ultimate.allocInit(21, 19);call #Ultimate.allocInit(30, 20);call #Ultimate.allocInit(9, 21);call #Ultimate.allocInit(25, 22);call #Ultimate.allocInit(30, 23);call #Ultimate.allocInit(9, 24);call #Ultimate.allocInit(25, 25);call #Ultimate.allocInit(10, 26);call #Ultimate.allocInit(16, 27);call #Ultimate.allocInit(20, 28);call #Ultimate.allocInit(22, 29);call #Ultimate.allocInit(21, 30);call #Ultimate.allocInit(13, 31);call #Ultimate.allocInit(44, 32);call #Ultimate.allocInit(44, 33);call #Ultimate.allocInit(9, 34);call #Ultimate.allocInit(9, 35);call #Ultimate.allocInit(11, 36);call #Ultimate.allocInit(19, 37);call #Ultimate.allocInit(4, 38);call write~init~int(37, 38, 0, 1);call write~init~int(100, 38, 1, 1);call write~init~int(10, 38, 2, 1);call write~init~int(0, 38, 3, 1);call #Ultimate.allocInit(4, 39);call write~init~int(37, 39, 0, 1);call write~init~int(100, 39, 1, 1);call write~init~int(10, 39, 2, 1);call write~init~int(0, 39, 3, 1);~__SELECTED_FEATURE_Base~0 := 0;~__SELECTED_FEATURE_Keys~0 := 0;~__SELECTED_FEATURE_Encrypt~0 := 0;~__SELECTED_FEATURE_AutoResponder~0 := 0;~__SELECTED_FEATURE_AddressBook~0 := 0;~__SELECTED_FEATURE_Sign~0 := 0;~__SELECTED_FEATURE_Forward~0 := 0;~__SELECTED_FEATURE_Verify~0 := 0;~__SELECTED_FEATURE_Decrypt~0 := 0;~__GUIDSL_ROOT_PRODUCTION~0 := 0;~__GUIDSL_NON_TERMINAL_main~0 := 0;~head~0.base, ~head~0.offset := 0, 0;~queue_empty~0 := 1;~queued_message~0 := 0;~queued_client~0 := 0;~mail_is_sensitive~0 := -1;~__ste_Client_counter~0 := 0;~__ste_client_name0~0.base, ~__ste_client_name0~0.offset := 0, 0;~__ste_client_name1~0.base, ~__ste_client_name1~0.offset := 0, 0;~__ste_client_name2~0.base, ~__ste_client_name2~0.offset := 0, 0;~__ste_client_outbuffer0~0 := 0;~__ste_client_outbuffer1~0 := 0;~__ste_client_outbuffer2~0 := 0;~__ste_client_outbuffer3~0 := 0;~__ste_ClientAddressBook_size0~0 := 0;~__ste_ClientAddressBook_size1~0 := 0;~__ste_ClientAddressBook_size2~0 := 0;~__ste_Client_AddressBook0_Alias0~0 := 0;~__ste_Client_AddressBook0_Alias1~0 := 0;~__ste_Client_AddressBook0_Alias2~0 := 0;~__ste_Client_AddressBook1_Alias0~0 := 0;~__ste_Client_AddressBook1_Alias1~0 := 0;~__ste_Client_AddressBook1_Alias2~0 := 0;~__ste_Client_AddressBook2_Alias0~0 := 0;~__ste_Client_AddressBook2_Alias1~0 := 0;~__ste_Client_AddressBook2_Alias2~0 := 0;~__ste_Client_AddressBook0_Address0~0 := 0;~__ste_Client_AddressBook0_Address1~0 := 0;~__ste_Client_AddressBook0_Address2~0 := 0;~__ste_Client_AddressBook1_Address0~0 := 0;~__ste_Client_AddressBook1_Address1~0 := 0;~__ste_Client_AddressBook1_Address2~0 := 0;~__ste_Client_AddressBook2_Address0~0 := 0;~__ste_Client_AddressBook2_Address1~0 := 0;~__ste_Client_AddressBook2_Address2~0 := 0;~__ste_client_autoResponse0~0 := 0;~__ste_client_autoResponse1~0 := 0;~__ste_client_autoResponse2~0 := 0;~__ste_client_privateKey0~0 := 0;~__ste_client_privateKey1~0 := 0;~__ste_client_privateKey2~0 := 0;~__ste_ClientKeyring_size0~0 := 0;~__ste_ClientKeyring_size1~0 := 0;~__ste_ClientKeyring_size2~0 := 0;~__ste_Client_Keyring0_User0~0 := 0;~__ste_Client_Keyring0_User1~0 := 0;~__ste_Client_Keyring0_User2~0 := 0;~__ste_Client_Keyring1_User0~0 := 0;~__ste_Client_Keyring1_User1~0 := 0;~__ste_Client_Keyring1_User2~0 := 0;~__ste_Client_Keyring2_User0~0 := 0;~__ste_Client_Keyring2_User1~0 := 0;~__ste_Client_Keyring2_User2~0 := 0;~__ste_Client_Keyring0_PublicKey0~0 := 0;~__ste_Client_Keyring0_PublicKey1~0 := 0;~__ste_Client_Keyring0_PublicKey2~0 := 0;~__ste_Client_Keyring1_PublicKey0~0 := 0;~__ste_Client_Keyring1_PublicKey1~0 := 0;~__ste_Client_Keyring1_PublicKey2~0 := 0;~__ste_Client_Keyring2_PublicKey0~0 := 0;~__ste_Client_Keyring2_PublicKey1~0 := 0;~__ste_Client_Keyring2_PublicKey2~0 := 0;~__ste_client_forwardReceiver0~0 := 0;~__ste_client_forwardReceiver1~0 := 0;~__ste_client_forwardReceiver2~0 := 0;~__ste_client_forwardReceiver3~0 := 0;~__ste_client_idCounter0~0 := 0;~__ste_client_idCounter1~0 := 0;~__ste_client_idCounter2~0 := 0;~bob~0 := 0;~rjh~0 := 0;~chuck~0 := 0;~__ste_Email_counter~0 := 0;~__ste_email_id0~0 := 0;~__ste_email_id1~0 := 0;~__ste_email_from0~0 := 0;~__ste_email_from1~0 := 0;~__ste_email_to0~0 := 0;~__ste_email_to1~0 := 0;~__ste_email_subject0~0.base, ~__ste_email_subject0~0.offset := 0, 0;~__ste_email_subject1~0.base, ~__ste_email_subject1~0.offset := 0, 0;~__ste_email_body0~0.base, ~__ste_email_body0~0.offset := 0, 0;~__ste_email_body1~0.base, ~__ste_email_body1~0.offset := 0, 0;~__ste_email_isEncrypted0~0 := 0;~__ste_email_isEncrypted1~0 := 0;~__ste_email_encryptionKey0~0 := 0;~__ste_email_encryptionKey1~0 := 0;~__ste_email_isSigned0~0 := 0;~__ste_email_isSigned1~0 := 0;~__ste_email_signKey0~0 := 0;~__ste_email_signKey1~0 := 0;~__ste_email_isSignatureVerified0~0 := 0;~__ste_email_isSignatureVerified1~0 := 0; {2916#true} is VALID [2022-02-20 17:56:02,837 INFO L290 TraceCheckUtils]: 1: Hoare triple {2916#true} assume { :end_inline_ULTIMATE.init } true;assume { :begin_inline_main } true;havoc main_#res#1;havoc main_#t~ret98#1, main_~retValue_acc~32#1, main_~tmp~24#1;havoc main_~retValue_acc~32#1;havoc main_~tmp~24#1;assume { :begin_inline_select_helpers } true; {2916#true} is VALID [2022-02-20 17:56:02,837 INFO L290 TraceCheckUtils]: 2: Hoare triple {2916#true} assume { :end_inline_select_helpers } true;assume { :begin_inline_select_features } true; {2916#true} is VALID [2022-02-20 17:56:02,837 INFO L290 TraceCheckUtils]: 3: Hoare triple {2916#true} assume { :end_inline_select_features } true;assume { :begin_inline_valid_product } true;havoc valid_product_#res#1;havoc valid_product_~retValue_acc~9#1;havoc valid_product_~retValue_acc~9#1;valid_product_~retValue_acc~9#1 := 1;valid_product_#res#1 := valid_product_~retValue_acc~9#1; {2916#true} is VALID [2022-02-20 17:56:02,837 INFO L290 TraceCheckUtils]: 4: Hoare triple {2916#true} main_#t~ret98#1 := valid_product_#res#1;assume { :end_inline_valid_product } true;assume -2147483648 <= main_#t~ret98#1 && main_#t~ret98#1 <= 2147483647;main_~tmp~24#1 := main_#t~ret98#1;havoc main_#t~ret98#1; {2916#true} is VALID [2022-02-20 17:56:02,837 INFO L290 TraceCheckUtils]: 5: Hoare triple {2916#true} assume 0 != main_~tmp~24#1;assume { :begin_inline_setup } true;havoc setup_#t~nondet95#1, setup_#t~nondet96#1, setup_#t~nondet97#1, setup_~__cil_tmp1~0#1.base, setup_~__cil_tmp1~0#1.offset, setup_~__cil_tmp2~0#1.base, setup_~__cil_tmp2~0#1.offset, setup_~__cil_tmp3~2#1.base, setup_~__cil_tmp3~2#1.offset;havoc setup_~__cil_tmp1~0#1.base, setup_~__cil_tmp1~0#1.offset;havoc setup_~__cil_tmp2~0#1.base, setup_~__cil_tmp2~0#1.offset;havoc setup_~__cil_tmp3~2#1.base, setup_~__cil_tmp3~2#1.offset;~bob~0 := 1;assume { :begin_inline_setup_bob } true;setup_bob_#in~bob___0#1 := ~bob~0;havoc setup_bob_~bob___0#1;setup_bob_~bob___0#1 := setup_bob_#in~bob___0#1;assume { :begin_inline_setup_bob__wrappee__Base } true;setup_bob__wrappee__Base_#in~bob___0#1 := setup_bob_~bob___0#1;havoc setup_bob__wrappee__Base_~bob___0#1;setup_bob__wrappee__Base_~bob___0#1 := setup_bob__wrappee__Base_#in~bob___0#1; {2916#true} is VALID [2022-02-20 17:56:02,837 INFO L272 TraceCheckUtils]: 6: Hoare triple {2916#true} call setClientId(setup_bob__wrappee__Base_~bob___0#1, setup_bob__wrappee__Base_~bob___0#1); {2916#true} is VALID [2022-02-20 17:56:02,837 INFO L290 TraceCheckUtils]: 7: Hoare triple {2916#true} ~handle := #in~handle;~value := #in~value; {2916#true} is VALID [2022-02-20 17:56:02,837 INFO L290 TraceCheckUtils]: 8: Hoare triple {2916#true} assume 1 == ~handle;~__ste_client_idCounter0~0 := ~value; {2916#true} is VALID [2022-02-20 17:56:02,837 INFO L290 TraceCheckUtils]: 9: Hoare triple {2916#true} assume true; {2916#true} is VALID [2022-02-20 17:56:02,837 INFO L284 TraceCheckUtils]: 10: Hoare quadruple {2916#true} {2916#true} #1133#return; {2916#true} is VALID [2022-02-20 17:56:02,838 INFO L290 TraceCheckUtils]: 11: Hoare triple {2916#true} assume { :end_inline_setup_bob__wrappee__Base } true; {2916#true} is VALID [2022-02-20 17:56:02,838 INFO L272 TraceCheckUtils]: 12: Hoare triple {2916#true} call setClientPrivateKey(setup_bob_~bob___0#1, 123); {2916#true} is VALID [2022-02-20 17:56:02,838 INFO L290 TraceCheckUtils]: 13: Hoare triple {2916#true} ~handle := #in~handle;~value := #in~value; {2916#true} is VALID [2022-02-20 17:56:02,838 INFO L290 TraceCheckUtils]: 14: Hoare triple {2916#true} assume 1 == ~handle;~__ste_client_privateKey0~0 := ~value; {2916#true} is VALID [2022-02-20 17:56:02,838 INFO L290 TraceCheckUtils]: 15: Hoare triple {2916#true} assume true; {2916#true} is VALID [2022-02-20 17:56:02,838 INFO L284 TraceCheckUtils]: 16: Hoare quadruple {2916#true} {2916#true} #1135#return; {2916#true} is VALID [2022-02-20 17:56:02,838 INFO L290 TraceCheckUtils]: 17: Hoare triple {2916#true} assume { :end_inline_setup_bob } true;setup_~__cil_tmp1~0#1.base, setup_~__cil_tmp1~0#1.offset := 34, 0;havoc setup_#t~nondet95#1;~rjh~0 := 2;assume { :begin_inline_setup_rjh } true;setup_rjh_#in~rjh___0#1 := ~rjh~0;havoc setup_rjh_~rjh___0#1;setup_rjh_~rjh___0#1 := setup_rjh_#in~rjh___0#1;assume { :begin_inline_setup_rjh__wrappee__Base } true;setup_rjh__wrappee__Base_#in~rjh___0#1 := setup_rjh_~rjh___0#1;havoc setup_rjh__wrappee__Base_~rjh___0#1;setup_rjh__wrappee__Base_~rjh___0#1 := setup_rjh__wrappee__Base_#in~rjh___0#1; {2916#true} is VALID [2022-02-20 17:56:02,838 INFO L272 TraceCheckUtils]: 18: Hoare triple {2916#true} call setClientId(setup_rjh__wrappee__Base_~rjh___0#1, setup_rjh__wrappee__Base_~rjh___0#1); {2916#true} is VALID [2022-02-20 17:56:02,838 INFO L290 TraceCheckUtils]: 19: Hoare triple {2916#true} ~handle := #in~handle;~value := #in~value; {2916#true} is VALID [2022-02-20 17:56:02,838 INFO L290 TraceCheckUtils]: 20: Hoare triple {2916#true} assume 1 == ~handle;~__ste_client_idCounter0~0 := ~value; {2916#true} is VALID [2022-02-20 17:56:02,838 INFO L290 TraceCheckUtils]: 21: Hoare triple {2916#true} assume true; {2916#true} is VALID [2022-02-20 17:56:02,838 INFO L284 TraceCheckUtils]: 22: Hoare quadruple {2916#true} {2916#true} #1137#return; {2916#true} is VALID [2022-02-20 17:56:02,838 INFO L290 TraceCheckUtils]: 23: Hoare triple {2916#true} assume { :end_inline_setup_rjh__wrappee__Base } true; {2916#true} is VALID [2022-02-20 17:56:02,838 INFO L272 TraceCheckUtils]: 24: Hoare triple {2916#true} call setClientPrivateKey(setup_rjh_~rjh___0#1, 456); {2916#true} is VALID [2022-02-20 17:56:02,838 INFO L290 TraceCheckUtils]: 25: Hoare triple {2916#true} ~handle := #in~handle;~value := #in~value; {2916#true} is VALID [2022-02-20 17:56:02,838 INFO L290 TraceCheckUtils]: 26: Hoare triple {2916#true} assume 1 == ~handle;~__ste_client_privateKey0~0 := ~value; {2916#true} is VALID [2022-02-20 17:56:02,838 INFO L290 TraceCheckUtils]: 27: Hoare triple {2916#true} assume true; {2916#true} is VALID [2022-02-20 17:56:02,838 INFO L284 TraceCheckUtils]: 28: Hoare quadruple {2916#true} {2916#true} #1139#return; {2916#true} is VALID [2022-02-20 17:56:02,838 INFO L290 TraceCheckUtils]: 29: Hoare triple {2916#true} assume { :end_inline_setup_rjh } true;setup_~__cil_tmp2~0#1.base, setup_~__cil_tmp2~0#1.offset := 35, 0;havoc setup_#t~nondet96#1;~chuck~0 := 3;assume { :begin_inline_setup_chuck } true;setup_chuck_#in~chuck___0#1 := ~chuck~0;havoc setup_chuck_~chuck___0#1;setup_chuck_~chuck___0#1 := setup_chuck_#in~chuck___0#1;assume { :begin_inline_setup_chuck__wrappee__Base } true;setup_chuck__wrappee__Base_#in~chuck___0#1 := setup_chuck_~chuck___0#1;havoc setup_chuck__wrappee__Base_~chuck___0#1;setup_chuck__wrappee__Base_~chuck___0#1 := setup_chuck__wrappee__Base_#in~chuck___0#1; {2916#true} is VALID [2022-02-20 17:56:02,839 INFO L272 TraceCheckUtils]: 30: Hoare triple {2916#true} call setClientId(setup_chuck__wrappee__Base_~chuck___0#1, setup_chuck__wrappee__Base_~chuck___0#1); {2916#true} is VALID [2022-02-20 17:56:02,839 INFO L290 TraceCheckUtils]: 31: Hoare triple {2916#true} ~handle := #in~handle;~value := #in~value; {2916#true} is VALID [2022-02-20 17:56:02,839 INFO L290 TraceCheckUtils]: 32: Hoare triple {2916#true} assume 1 == ~handle;~__ste_client_idCounter0~0 := ~value; {2916#true} is VALID [2022-02-20 17:56:02,839 INFO L290 TraceCheckUtils]: 33: Hoare triple {2916#true} assume true; {2916#true} is VALID [2022-02-20 17:56:02,839 INFO L284 TraceCheckUtils]: 34: Hoare quadruple {2916#true} {2916#true} #1141#return; {2916#true} is VALID [2022-02-20 17:56:02,839 INFO L290 TraceCheckUtils]: 35: Hoare triple {2916#true} assume { :end_inline_setup_chuck__wrappee__Base } true; {2916#true} is VALID [2022-02-20 17:56:02,839 INFO L272 TraceCheckUtils]: 36: Hoare triple {2916#true} call setClientPrivateKey(setup_chuck_~chuck___0#1, 789); {2916#true} is VALID [2022-02-20 17:56:02,839 INFO L290 TraceCheckUtils]: 37: Hoare triple {2916#true} ~handle := #in~handle;~value := #in~value; {2916#true} is VALID [2022-02-20 17:56:02,839 INFO L290 TraceCheckUtils]: 38: Hoare triple {2916#true} assume 1 == ~handle;~__ste_client_privateKey0~0 := ~value; {2916#true} is VALID [2022-02-20 17:56:02,839 INFO L290 TraceCheckUtils]: 39: Hoare triple {2916#true} assume true; {2916#true} is VALID [2022-02-20 17:56:02,839 INFO L284 TraceCheckUtils]: 40: Hoare quadruple {2916#true} {2916#true} #1143#return; {2916#true} is VALID [2022-02-20 17:56:02,839 INFO L290 TraceCheckUtils]: 41: Hoare triple {2916#true} assume { :end_inline_setup_chuck } true;setup_~__cil_tmp3~2#1.base, setup_~__cil_tmp3~2#1.offset := 36, 0;havoc setup_#t~nondet97#1; {2916#true} is VALID [2022-02-20 17:56:02,840 INFO L290 TraceCheckUtils]: 42: Hoare triple {2916#true} assume { :end_inline_setup } true;assume { :begin_inline_test } true;havoc test_#t~nondet48#1, test_#t~nondet49#1, test_#t~nondet50#1, test_#t~nondet51#1, test_#t~nondet52#1, test_#t~nondet53#1, test_#t~nondet54#1, test_#t~nondet55#1, test_#t~nondet56#1, test_#t~nondet57#1, test_#t~nondet58#1, test_~op1~0#1, test_~op2~0#1, test_~op3~0#1, test_~op4~0#1, test_~op5~0#1, test_~op6~0#1, test_~op7~0#1, test_~op8~0#1, test_~op9~0#1, test_~op10~0#1, test_~op11~0#1, test_~splverifierCounter~0#1, test_~tmp~8#1, test_~tmp___0~3#1, test_~tmp___1~1#1, test_~tmp___2~1#1, test_~tmp___3~0#1, test_~tmp___4~0#1, test_~tmp___5~0#1, test_~tmp___6~0#1, test_~tmp___7~0#1, test_~tmp___8~0#1, test_~tmp___9~0#1;havoc test_~op1~0#1;havoc test_~op2~0#1;havoc test_~op3~0#1;havoc test_~op4~0#1;havoc test_~op5~0#1;havoc test_~op6~0#1;havoc test_~op7~0#1;havoc test_~op8~0#1;havoc test_~op9~0#1;havoc test_~op10~0#1;havoc test_~op11~0#1;havoc test_~splverifierCounter~0#1;havoc test_~tmp~8#1;havoc test_~tmp___0~3#1;havoc test_~tmp___1~1#1;havoc test_~tmp___2~1#1;havoc test_~tmp___3~0#1;havoc test_~tmp___4~0#1;havoc test_~tmp___5~0#1;havoc test_~tmp___6~0#1;havoc test_~tmp___7~0#1;havoc test_~tmp___8~0#1;havoc test_~tmp___9~0#1;test_~op1~0#1 := 0;test_~op2~0#1 := 0;test_~op3~0#1 := 0;test_~op4~0#1 := 0;test_~op5~0#1 := 0;test_~op6~0#1 := 0;test_~op7~0#1 := 0;test_~op8~0#1 := 0;test_~op9~0#1 := 0;test_~op10~0#1 := 0;test_~op11~0#1 := 0;test_~splverifierCounter~0#1 := 0; {3107#(<= |ULTIMATE.start_test_~splverifierCounter~0#1| 0)} is VALID [2022-02-20 17:56:02,840 INFO L290 TraceCheckUtils]: 43: Hoare triple {3107#(<= |ULTIMATE.start_test_~splverifierCounter~0#1| 0)} assume !false; {3107#(<= |ULTIMATE.start_test_~splverifierCounter~0#1| 0)} is VALID [2022-02-20 17:56:02,841 INFO L290 TraceCheckUtils]: 44: Hoare triple {3107#(<= |ULTIMATE.start_test_~splverifierCounter~0#1| 0)} assume !(test_~splverifierCounter~0#1 < 4); {2917#false} is VALID [2022-02-20 17:56:02,841 INFO L290 TraceCheckUtils]: 45: Hoare triple {2917#false} assume { :begin_inline_bobToRjh } true;havoc bobToRjh_#t~ret90#1, bobToRjh_#t~ret91#1, bobToRjh_#t~ret92#1, bobToRjh_#t~ret93#1, bobToRjh_~tmp~23#1, bobToRjh_~tmp___0~7#1, bobToRjh_~tmp___1~4#1;havoc bobToRjh_~tmp~23#1;havoc bobToRjh_~tmp___0~7#1;havoc bobToRjh_~tmp___1~4#1;call bobToRjh_#t~ret90#1 := puts(32, 0);assume -2147483648 <= bobToRjh_#t~ret90#1 && bobToRjh_#t~ret90#1 <= 2147483647;havoc bobToRjh_#t~ret90#1; {2917#false} is VALID [2022-02-20 17:56:02,841 INFO L272 TraceCheckUtils]: 46: Hoare triple {2917#false} call sendEmail(~bob~0, ~rjh~0); {2917#false} is VALID [2022-02-20 17:56:02,841 INFO L290 TraceCheckUtils]: 47: Hoare triple {2917#false} ~sender#1 := #in~sender#1;~receiver#1 := #in~receiver#1;havoc ~email~0#1;havoc ~tmp~16#1;assume { :begin_inline_createEmail } true;createEmail_#in~from#1, createEmail_#in~to#1 := 0, ~receiver#1;havoc createEmail_#res#1;havoc createEmail_~from#1, createEmail_~to#1, createEmail_~retValue_acc~4#1, createEmail_~msg~0#1;createEmail_~from#1 := createEmail_#in~from#1;createEmail_~to#1 := createEmail_#in~to#1;havoc createEmail_~retValue_acc~4#1;havoc createEmail_~msg~0#1;createEmail_~msg~0#1 := 1; {2917#false} is VALID [2022-02-20 17:56:02,841 INFO L272 TraceCheckUtils]: 48: Hoare triple {2917#false} call setEmailFrom(createEmail_~msg~0#1, createEmail_~from#1); {2917#false} is VALID [2022-02-20 17:56:02,841 INFO L290 TraceCheckUtils]: 49: Hoare triple {2917#false} ~handle := #in~handle;~value := #in~value; {2917#false} is VALID [2022-02-20 17:56:02,841 INFO L290 TraceCheckUtils]: 50: Hoare triple {2917#false} assume 1 == ~handle;~__ste_email_from0~0 := ~value; {2917#false} is VALID [2022-02-20 17:56:02,841 INFO L290 TraceCheckUtils]: 51: Hoare triple {2917#false} assume true; {2917#false} is VALID [2022-02-20 17:56:02,841 INFO L284 TraceCheckUtils]: 52: Hoare quadruple {2917#false} {2917#false} #1119#return; {2917#false} is VALID [2022-02-20 17:56:02,841 INFO L272 TraceCheckUtils]: 53: Hoare triple {2917#false} call setEmailTo(createEmail_~msg~0#1, createEmail_~to#1); {2917#false} is VALID [2022-02-20 17:56:02,841 INFO L290 TraceCheckUtils]: 54: Hoare triple {2917#false} ~handle := #in~handle;~value := #in~value; {2917#false} is VALID [2022-02-20 17:56:02,841 INFO L290 TraceCheckUtils]: 55: Hoare triple {2917#false} assume 1 == ~handle;~__ste_email_to0~0 := ~value; {2917#false} is VALID [2022-02-20 17:56:02,841 INFO L290 TraceCheckUtils]: 56: Hoare triple {2917#false} assume true; {2917#false} is VALID [2022-02-20 17:56:02,841 INFO L284 TraceCheckUtils]: 57: Hoare quadruple {2917#false} {2917#false} #1121#return; {2917#false} is VALID [2022-02-20 17:56:02,841 INFO L290 TraceCheckUtils]: 58: Hoare triple {2917#false} createEmail_~retValue_acc~4#1 := createEmail_~msg~0#1;createEmail_#res#1 := createEmail_~retValue_acc~4#1; {2917#false} is VALID [2022-02-20 17:56:02,841 INFO L290 TraceCheckUtils]: 59: Hoare triple {2917#false} #t~ret73#1 := createEmail_#res#1;assume { :end_inline_createEmail } true;assume -2147483648 <= #t~ret73#1 && #t~ret73#1 <= 2147483647;~tmp~16#1 := #t~ret73#1;havoc #t~ret73#1;~email~0#1 := ~tmp~16#1; {2917#false} is VALID [2022-02-20 17:56:02,842 INFO L272 TraceCheckUtils]: 60: Hoare triple {2917#false} call outgoing(~sender#1, ~email~0#1); {2917#false} is VALID [2022-02-20 17:56:02,842 INFO L290 TraceCheckUtils]: 61: Hoare triple {2917#false} ~client#1 := #in~client#1;~msg#1 := #in~msg#1;assume { :begin_inline_sign } true;sign_#in~client#1, sign_#in~msg#1 := ~client#1, ~msg#1;havoc sign_#t~ret77#1, sign_~client#1, sign_~msg#1, sign_~privkey~1#1, sign_~tmp~18#1;sign_~client#1 := sign_#in~client#1;sign_~msg#1 := sign_#in~msg#1;havoc sign_~privkey~1#1;havoc sign_~tmp~18#1; {2917#false} is VALID [2022-02-20 17:56:02,842 INFO L272 TraceCheckUtils]: 62: Hoare triple {2917#false} call sign_#t~ret77#1 := getClientPrivateKey(sign_~client#1); {2917#false} is VALID [2022-02-20 17:56:02,842 INFO L290 TraceCheckUtils]: 63: Hoare triple {2917#false} ~handle := #in~handle;havoc ~retValue_acc~24; {2917#false} is VALID [2022-02-20 17:56:02,842 INFO L290 TraceCheckUtils]: 64: Hoare triple {2917#false} assume 1 == ~handle;~retValue_acc~24 := ~__ste_client_privateKey0~0;#res := ~retValue_acc~24; {2917#false} is VALID [2022-02-20 17:56:02,842 INFO L290 TraceCheckUtils]: 65: Hoare triple {2917#false} assume true; {2917#false} is VALID [2022-02-20 17:56:02,842 INFO L284 TraceCheckUtils]: 66: Hoare quadruple {2917#false} {2917#false} #1053#return; {2917#false} is VALID [2022-02-20 17:56:02,842 INFO L290 TraceCheckUtils]: 67: Hoare triple {2917#false} assume -2147483648 <= sign_#t~ret77#1 && sign_#t~ret77#1 <= 2147483647;sign_~tmp~18#1 := sign_#t~ret77#1;havoc sign_#t~ret77#1;sign_~privkey~1#1 := sign_~tmp~18#1; {2917#false} is VALID [2022-02-20 17:56:02,842 INFO L290 TraceCheckUtils]: 68: Hoare triple {2917#false} assume 0 == sign_~privkey~1#1; {2917#false} is VALID [2022-02-20 17:56:02,842 INFO L290 TraceCheckUtils]: 69: Hoare triple {2917#false} assume { :end_inline_sign } true;assume { :begin_inline_outgoing__wrappee__AutoResponder } true;outgoing__wrappee__AutoResponder_#in~client#1, outgoing__wrappee__AutoResponder_#in~msg#1 := ~client#1, ~msg#1;havoc outgoing__wrappee__AutoResponder_#t~ret63#1, outgoing__wrappee__AutoResponder_#t~ret64#1, outgoing__wrappee__AutoResponder_~client#1, outgoing__wrappee__AutoResponder_~msg#1, outgoing__wrappee__AutoResponder_~receiver~0#1, outgoing__wrappee__AutoResponder_~tmp~11#1, outgoing__wrappee__AutoResponder_~pubkey~0#1, outgoing__wrappee__AutoResponder_~tmp___0~4#1;outgoing__wrappee__AutoResponder_~client#1 := outgoing__wrappee__AutoResponder_#in~client#1;outgoing__wrappee__AutoResponder_~msg#1 := outgoing__wrappee__AutoResponder_#in~msg#1;havoc outgoing__wrappee__AutoResponder_~receiver~0#1;havoc outgoing__wrappee__AutoResponder_~tmp~11#1;havoc outgoing__wrappee__AutoResponder_~pubkey~0#1;havoc outgoing__wrappee__AutoResponder_~tmp___0~4#1; {2917#false} is VALID [2022-02-20 17:56:02,842 INFO L272 TraceCheckUtils]: 70: Hoare triple {2917#false} call outgoing__wrappee__AutoResponder_#t~ret63#1 := getEmailTo(outgoing__wrappee__AutoResponder_~msg#1); {2917#false} is VALID [2022-02-20 17:56:02,842 INFO L290 TraceCheckUtils]: 71: Hoare triple {2917#false} ~handle := #in~handle;havoc ~retValue_acc~36; {2917#false} is VALID [2022-02-20 17:56:02,842 INFO L290 TraceCheckUtils]: 72: Hoare triple {2917#false} assume 1 == ~handle;~retValue_acc~36 := ~__ste_email_to0~0;#res := ~retValue_acc~36; {2917#false} is VALID [2022-02-20 17:56:02,842 INFO L290 TraceCheckUtils]: 73: Hoare triple {2917#false} assume true; {2917#false} is VALID [2022-02-20 17:56:02,842 INFO L284 TraceCheckUtils]: 74: Hoare quadruple {2917#false} {2917#false} #1055#return; {2917#false} is VALID [2022-02-20 17:56:02,842 INFO L290 TraceCheckUtils]: 75: Hoare triple {2917#false} assume -2147483648 <= outgoing__wrappee__AutoResponder_#t~ret63#1 && outgoing__wrappee__AutoResponder_#t~ret63#1 <= 2147483647;outgoing__wrappee__AutoResponder_~tmp~11#1 := outgoing__wrappee__AutoResponder_#t~ret63#1;havoc outgoing__wrappee__AutoResponder_#t~ret63#1;outgoing__wrappee__AutoResponder_~receiver~0#1 := outgoing__wrappee__AutoResponder_~tmp~11#1; {2917#false} is VALID [2022-02-20 17:56:02,843 INFO L272 TraceCheckUtils]: 76: Hoare triple {2917#false} call outgoing__wrappee__AutoResponder_#t~ret64#1 := findPublicKey(outgoing__wrappee__AutoResponder_~client#1, outgoing__wrappee__AutoResponder_~receiver~0#1); {2917#false} is VALID [2022-02-20 17:56:02,843 INFO L290 TraceCheckUtils]: 77: Hoare triple {2917#false} ~handle := #in~handle;~userid := #in~userid;havoc ~retValue_acc~29; {2917#false} is VALID [2022-02-20 17:56:02,843 INFO L290 TraceCheckUtils]: 78: Hoare triple {2917#false} assume 1 == ~handle; {2917#false} is VALID [2022-02-20 17:56:02,843 INFO L290 TraceCheckUtils]: 79: Hoare triple {2917#false} assume ~userid == ~__ste_Client_Keyring0_User0~0;~retValue_acc~29 := ~__ste_Client_Keyring0_PublicKey0~0;#res := ~retValue_acc~29; {2917#false} is VALID [2022-02-20 17:56:02,843 INFO L290 TraceCheckUtils]: 80: Hoare triple {2917#false} assume true; {2917#false} is VALID [2022-02-20 17:56:02,843 INFO L284 TraceCheckUtils]: 81: Hoare quadruple {2917#false} {2917#false} #1057#return; {2917#false} is VALID [2022-02-20 17:56:02,843 INFO L290 TraceCheckUtils]: 82: Hoare triple {2917#false} assume -2147483648 <= outgoing__wrappee__AutoResponder_#t~ret64#1 && outgoing__wrappee__AutoResponder_#t~ret64#1 <= 2147483647;outgoing__wrappee__AutoResponder_~tmp___0~4#1 := outgoing__wrappee__AutoResponder_#t~ret64#1;havoc outgoing__wrappee__AutoResponder_#t~ret64#1;outgoing__wrappee__AutoResponder_~pubkey~0#1 := outgoing__wrappee__AutoResponder_~tmp___0~4#1; {2917#false} is VALID [2022-02-20 17:56:02,843 INFO L290 TraceCheckUtils]: 83: Hoare triple {2917#false} assume !(0 != outgoing__wrappee__AutoResponder_~pubkey~0#1); {2917#false} is VALID [2022-02-20 17:56:02,843 INFO L290 TraceCheckUtils]: 84: Hoare triple {2917#false} assume { :begin_inline_outgoing__wrappee__Keys } true;outgoing__wrappee__Keys_#in~client#1, outgoing__wrappee__Keys_#in~msg#1 := outgoing__wrappee__AutoResponder_~client#1, outgoing__wrappee__AutoResponder_~msg#1;havoc outgoing__wrappee__Keys_#t~ret62#1, outgoing__wrappee__Keys_~client#1, outgoing__wrappee__Keys_~msg#1, outgoing__wrappee__Keys_~tmp~10#1;outgoing__wrappee__Keys_~client#1 := outgoing__wrappee__Keys_#in~client#1;outgoing__wrappee__Keys_~msg#1 := outgoing__wrappee__Keys_#in~msg#1;havoc outgoing__wrappee__Keys_~tmp~10#1;assume { :begin_inline_getClientId } true;getClientId_#in~handle#1 := outgoing__wrappee__Keys_~client#1;havoc getClientId_#res#1;havoc getClientId_~handle#1, getClientId_~retValue_acc~31#1;getClientId_~handle#1 := getClientId_#in~handle#1;havoc getClientId_~retValue_acc~31#1; {2917#false} is VALID [2022-02-20 17:56:02,843 INFO L290 TraceCheckUtils]: 85: Hoare triple {2917#false} assume 1 == getClientId_~handle#1;getClientId_~retValue_acc~31#1 := ~__ste_client_idCounter0~0;getClientId_#res#1 := getClientId_~retValue_acc~31#1; {2917#false} is VALID [2022-02-20 17:56:02,843 INFO L290 TraceCheckUtils]: 86: Hoare triple {2917#false} outgoing__wrappee__Keys_#t~ret62#1 := getClientId_#res#1;assume { :end_inline_getClientId } true;assume -2147483648 <= outgoing__wrappee__Keys_#t~ret62#1 && outgoing__wrappee__Keys_#t~ret62#1 <= 2147483647;outgoing__wrappee__Keys_~tmp~10#1 := outgoing__wrappee__Keys_#t~ret62#1;havoc outgoing__wrappee__Keys_#t~ret62#1; {2917#false} is VALID [2022-02-20 17:56:02,843 INFO L272 TraceCheckUtils]: 87: Hoare triple {2917#false} call setEmailFrom(outgoing__wrappee__Keys_~msg#1, outgoing__wrappee__Keys_~tmp~10#1); {2917#false} is VALID [2022-02-20 17:56:02,843 INFO L290 TraceCheckUtils]: 88: Hoare triple {2917#false} ~handle := #in~handle;~value := #in~value; {2917#false} is VALID [2022-02-20 17:56:02,843 INFO L290 TraceCheckUtils]: 89: Hoare triple {2917#false} assume 1 == ~handle;~__ste_email_from0~0 := ~value; {2917#false} is VALID [2022-02-20 17:56:02,843 INFO L290 TraceCheckUtils]: 90: Hoare triple {2917#false} assume true; {2917#false} is VALID [2022-02-20 17:56:02,843 INFO L284 TraceCheckUtils]: 91: Hoare quadruple {2917#false} {2917#false} #1063#return; {2917#false} is VALID [2022-02-20 17:56:02,843 INFO L290 TraceCheckUtils]: 92: Hoare triple {2917#false} assume { :begin_inline_mail } true;mail_#in~client#1, mail_#in~msg#1 := outgoing__wrappee__Keys_~client#1, outgoing__wrappee__Keys_~msg#1;havoc mail_#t~ret60#1, mail_#t~ret61#1, mail_~client#1, mail_~msg#1, mail_~__utac__ad__arg1~0#1, mail_~__utac__ad__arg2~0#1, mail_~tmp~9#1;mail_~client#1 := mail_#in~client#1;mail_~msg#1 := mail_#in~msg#1;havoc mail_~__utac__ad__arg1~0#1;havoc mail_~__utac__ad__arg2~0#1;havoc mail_~tmp~9#1;mail_~__utac__ad__arg1~0#1 := mail_~client#1;mail_~__utac__ad__arg2~0#1 := mail_~msg#1;assume { :begin_inline___utac_acc__AddressBookEncrypt_spec__1 } true;__utac_acc__AddressBookEncrypt_spec__1_#in~client#1, __utac_acc__AddressBookEncrypt_spec__1_#in~msg#1 := mail_~__utac__ad__arg1~0#1, mail_~__utac__ad__arg2~0#1;havoc __utac_acc__AddressBookEncrypt_spec__1_#t~ret85#1, __utac_acc__AddressBookEncrypt_spec__1_#t~ret86#1, __utac_acc__AddressBookEncrypt_spec__1_#t~ret87#1, __utac_acc__AddressBookEncrypt_spec__1_~client#1, __utac_acc__AddressBookEncrypt_spec__1_~msg#1, __utac_acc__AddressBookEncrypt_spec__1_~tmp~20#1;__utac_acc__AddressBookEncrypt_spec__1_~client#1 := __utac_acc__AddressBookEncrypt_spec__1_#in~client#1;__utac_acc__AddressBookEncrypt_spec__1_~msg#1 := __utac_acc__AddressBookEncrypt_spec__1_#in~msg#1;havoc __utac_acc__AddressBookEncrypt_spec__1_~tmp~20#1;call __utac_acc__AddressBookEncrypt_spec__1_#t~ret85#1 := puts(31, 0);assume -2147483648 <= __utac_acc__AddressBookEncrypt_spec__1_#t~ret85#1 && __utac_acc__AddressBookEncrypt_spec__1_#t~ret85#1 <= 2147483647;havoc __utac_acc__AddressBookEncrypt_spec__1_#t~ret85#1; {2917#false} is VALID [2022-02-20 17:56:02,843 INFO L290 TraceCheckUtils]: 93: Hoare triple {2917#false} assume !(-1 == ~mail_is_sensitive~0); {2917#false} is VALID [2022-02-20 17:56:02,844 INFO L272 TraceCheckUtils]: 94: Hoare triple {2917#false} call __utac_acc__AddressBookEncrypt_spec__1_#t~ret87#1 := isEncrypted(__utac_acc__AddressBookEncrypt_spec__1_~msg#1); {2917#false} is VALID [2022-02-20 17:56:02,844 INFO L290 TraceCheckUtils]: 95: Hoare triple {2917#false} ~handle := #in~handle;havoc ~retValue_acc~39; {2917#false} is VALID [2022-02-20 17:56:02,844 INFO L290 TraceCheckUtils]: 96: Hoare triple {2917#false} assume 1 == ~handle;~retValue_acc~39 := ~__ste_email_isEncrypted0~0;#res := ~retValue_acc~39; {2917#false} is VALID [2022-02-20 17:56:02,844 INFO L290 TraceCheckUtils]: 97: Hoare triple {2917#false} assume true; {2917#false} is VALID [2022-02-20 17:56:02,844 INFO L284 TraceCheckUtils]: 98: Hoare quadruple {2917#false} {2917#false} #1067#return; {2917#false} is VALID [2022-02-20 17:56:02,844 INFO L290 TraceCheckUtils]: 99: Hoare triple {2917#false} assume -2147483648 <= __utac_acc__AddressBookEncrypt_spec__1_#t~ret87#1 && __utac_acc__AddressBookEncrypt_spec__1_#t~ret87#1 <= 2147483647;__utac_acc__AddressBookEncrypt_spec__1_~tmp~20#1 := __utac_acc__AddressBookEncrypt_spec__1_#t~ret87#1;havoc __utac_acc__AddressBookEncrypt_spec__1_#t~ret87#1; {2917#false} is VALID [2022-02-20 17:56:02,844 INFO L290 TraceCheckUtils]: 100: Hoare triple {2917#false} assume ~mail_is_sensitive~0 != __utac_acc__AddressBookEncrypt_spec__1_~tmp~20#1;assume { :begin_inline___automaton_fail } true; {2917#false} is VALID [2022-02-20 17:56:02,844 INFO L290 TraceCheckUtils]: 101: Hoare triple {2917#false} assume !false; {2917#false} is VALID [2022-02-20 17:56:02,844 INFO L134 CoverageAnalysis]: Checked inductivity of 28 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 28 trivial. 0 not checked. [2022-02-20 17:56:02,844 INFO L324 TraceCheckSpWp]: Omiting computation of backward sequence because forward sequence was already perfect [2022-02-20 17:56:02,844 INFO L165 FreeRefinementEngine]: IpTcStrategyModuleZ3 [1876732126] provided 1 perfect and 0 imperfect interpolant sequences [2022-02-20 17:56:02,847 INFO L191 FreeRefinementEngine]: Found 1 perfect and 1 imperfect interpolant sequences. [2022-02-20 17:56:02,857 INFO L204 FreeRefinementEngine]: Number of different interpolants: perfect sequences [3] imperfect sequences [9] total 10 [2022-02-20 17:56:02,857 INFO L118 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [1000537097] [2022-02-20 17:56:02,857 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2022-02-20 17:56:02,858 INFO L78 Accepts]: Start accepts. Automaton has has 3 states, 3 states have (on average 19.666666666666668) internal successors, (59), 3 states have internal predecessors, (59), 2 states have call successors, (15), 2 states have call predecessors, (15), 2 states have return successors, (13), 2 states have call predecessors, (13), 2 states have call successors, (13) Word has length 102 [2022-02-20 17:56:02,858 INFO L84 Accepts]: Finished accepts. word is accepted. [2022-02-20 17:56:02,858 INFO L86 InductivityCheck]: Starting indutivity check of a Floyd-Hoare automaton with has 3 states, 3 states have (on average 19.666666666666668) internal successors, (59), 3 states have internal predecessors, (59), 2 states have call successors, (15), 2 states have call predecessors, (15), 2 states have return successors, (13), 2 states have call predecessors, (13), 2 states have call successors, (13) [2022-02-20 17:56:02,923 INFO L122 InductivityCheck]: Floyd-Hoare automaton has 87 edges. 87 inductive. 0 not inductive. 0 times theorem prover too weak to decide inductivity. [2022-02-20 17:56:02,923 INFO L546 AbstractCegarLoop]: INTERPOLANT automaton has 3 states [2022-02-20 17:56:02,923 INFO L108 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2022-02-20 17:56:02,923 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 3 interpolants. [2022-02-20 17:56:02,924 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=17, Invalid=73, Unknown=0, NotChecked=0, Total=90 [2022-02-20 17:56:02,924 INFO L87 Difference]: Start difference. First operand 381 states and 563 transitions. Second operand has 3 states, 3 states have (on average 19.666666666666668) internal successors, (59), 3 states have internal predecessors, (59), 2 states have call successors, (15), 2 states have call predecessors, (15), 2 states have return successors, (13), 2 states have call predecessors, (13), 2 states have call successors, (13) [2022-02-20 17:56:03,360 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-02-20 17:56:03,360 INFO L93 Difference]: Finished difference Result 607 states and 877 transitions. [2022-02-20 17:56:03,360 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 3 states. [2022-02-20 17:56:03,361 INFO L78 Accepts]: Start accepts. Automaton has has 3 states, 3 states have (on average 19.666666666666668) internal successors, (59), 3 states have internal predecessors, (59), 2 states have call successors, (15), 2 states have call predecessors, (15), 2 states have return successors, (13), 2 states have call predecessors, (13), 2 states have call successors, (13) Word has length 102 [2022-02-20 17:56:03,361 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2022-02-20 17:56:03,361 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 3 states, 3 states have (on average 19.666666666666668) internal successors, (59), 3 states have internal predecessors, (59), 2 states have call successors, (15), 2 states have call predecessors, (15), 2 states have return successors, (13), 2 states have call predecessors, (13), 2 states have call successors, (13) [2022-02-20 17:56:03,370 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 3 states to 3 states and 877 transitions. [2022-02-20 17:56:03,370 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 3 states, 3 states have (on average 19.666666666666668) internal successors, (59), 3 states have internal predecessors, (59), 2 states have call successors, (15), 2 states have call predecessors, (15), 2 states have return successors, (13), 2 states have call predecessors, (13), 2 states have call successors, (13) [2022-02-20 17:56:03,378 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 3 states to 3 states and 877 transitions. [2022-02-20 17:56:03,379 INFO L86 InductivityCheck]: Starting indutivity check of a Floyd-Hoare automaton with 3 states and 877 transitions. [2022-02-20 17:56:03,935 INFO L122 InductivityCheck]: Floyd-Hoare automaton has 877 edges. 877 inductive. 0 not inductive. 0 times theorem prover too weak to decide inductivity. [2022-02-20 17:56:03,944 INFO L225 Difference]: With dead ends: 607 [2022-02-20 17:56:03,945 INFO L226 Difference]: Without dead ends: 384 [2022-02-20 17:56:03,945 INFO L932 BasicCegarLoop]: 0 DeclaredPredicates, 131 GetRequests, 123 SyntacticMatches, 0 SemanticMatches, 8 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 0 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=17, Invalid=73, Unknown=0, NotChecked=0, Total=90 [2022-02-20 17:56:03,946 INFO L933 BasicCegarLoop]: 561 mSDtfsCounter, 1 mSDsluCounter, 559 mSDsCounter, 0 mSdLazyCounter, 5 mSolverCounterSat, 0 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.0s Time, 0 mProtectedPredicate, 0 mProtectedAction, 1 SdHoareTripleChecker+Valid, 1120 SdHoareTripleChecker+Invalid, 5 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 0 IncrementalHoareTripleChecker+Valid, 5 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.0s IncrementalHoareTripleChecker+Time [2022-02-20 17:56:03,946 INFO L934 BasicCegarLoop]: SdHoareTripleChecker [1 Valid, 1120 Invalid, 5 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [0 Valid, 5 Invalid, 0 Unknown, 0 Unchecked, 0.0s Time] [2022-02-20 17:56:03,947 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 384 states. [2022-02-20 17:56:03,958 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 384 to 383. [2022-02-20 17:56:03,958 INFO L214 AbstractMinimizeNwa]: Start testing correctness of minimizeSevpa [2022-02-20 17:56:03,959 INFO L82 GeneralOperation]: Start isEquivalent. First operand 384 states. Second operand has 383 states, 295 states have (on average 1.4915254237288136) internal successors, (440), 298 states have internal predecessors, (440), 63 states have call successors, (63), 24 states have call predecessors, (63), 24 states have return successors, (62), 62 states have call predecessors, (62), 62 states have call successors, (62) [2022-02-20 17:56:03,960 INFO L74 IsIncluded]: Start isIncluded. First operand 384 states. Second operand has 383 states, 295 states have (on average 1.4915254237288136) internal successors, (440), 298 states have internal predecessors, (440), 63 states have call successors, (63), 24 states have call predecessors, (63), 24 states have return successors, (62), 62 states have call predecessors, (62), 62 states have call successors, (62) [2022-02-20 17:56:03,960 INFO L87 Difference]: Start difference. First operand 384 states. Second operand has 383 states, 295 states have (on average 1.4915254237288136) internal successors, (440), 298 states have internal predecessors, (440), 63 states have call successors, (63), 24 states have call predecessors, (63), 24 states have return successors, (62), 62 states have call predecessors, (62), 62 states have call successors, (62) [2022-02-20 17:56:03,971 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-02-20 17:56:03,971 INFO L93 Difference]: Finished difference Result 384 states and 566 transitions. [2022-02-20 17:56:03,971 INFO L276 IsEmpty]: Start isEmpty. Operand 384 states and 566 transitions. [2022-02-20 17:56:03,972 INFO L282 IsEmpty]: Finished isEmpty. No accepting run. [2022-02-20 17:56:03,972 INFO L83 IsIncluded]: Finished isIncluded. Language is included [2022-02-20 17:56:03,973 INFO L74 IsIncluded]: Start isIncluded. First operand has 383 states, 295 states have (on average 1.4915254237288136) internal successors, (440), 298 states have internal predecessors, (440), 63 states have call successors, (63), 24 states have call predecessors, (63), 24 states have return successors, (62), 62 states have call predecessors, (62), 62 states have call successors, (62) Second operand 384 states. [2022-02-20 17:56:03,974 INFO L87 Difference]: Start difference. First operand has 383 states, 295 states have (on average 1.4915254237288136) internal successors, (440), 298 states have internal predecessors, (440), 63 states have call successors, (63), 24 states have call predecessors, (63), 24 states have return successors, (62), 62 states have call predecessors, (62), 62 states have call successors, (62) Second operand 384 states. [2022-02-20 17:56:03,984 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-02-20 17:56:03,984 INFO L93 Difference]: Finished difference Result 384 states and 566 transitions. [2022-02-20 17:56:03,984 INFO L276 IsEmpty]: Start isEmpty. Operand 384 states and 566 transitions. [2022-02-20 17:56:03,986 INFO L282 IsEmpty]: Finished isEmpty. No accepting run. [2022-02-20 17:56:03,986 INFO L83 IsIncluded]: Finished isIncluded. Language is included [2022-02-20 17:56:03,986 INFO L88 GeneralOperation]: Finished isEquivalent. [2022-02-20 17:56:03,986 INFO L221 AbstractMinimizeNwa]: Finished testing correctness of minimizeSevpa [2022-02-20 17:56:03,987 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 383 states, 295 states have (on average 1.4915254237288136) internal successors, (440), 298 states have internal predecessors, (440), 63 states have call successors, (63), 24 states have call predecessors, (63), 24 states have return successors, (62), 62 states have call predecessors, (62), 62 states have call successors, (62) [2022-02-20 17:56:03,998 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 383 states to 383 states and 565 transitions. [2022-02-20 17:56:03,998 INFO L78 Accepts]: Start accepts. Automaton has 383 states and 565 transitions. Word has length 102 [2022-02-20 17:56:03,998 INFO L84 Accepts]: Finished accepts. word is rejected. [2022-02-20 17:56:03,998 INFO L470 AbstractCegarLoop]: Abstraction has 383 states and 565 transitions. [2022-02-20 17:56:03,999 INFO L471 AbstractCegarLoop]: INTERPOLANT automaton has has 3 states, 3 states have (on average 19.666666666666668) internal successors, (59), 3 states have internal predecessors, (59), 2 states have call successors, (15), 2 states have call predecessors, (15), 2 states have return successors, (13), 2 states have call predecessors, (13), 2 states have call successors, (13) [2022-02-20 17:56:03,999 INFO L276 IsEmpty]: Start isEmpty. Operand 383 states and 565 transitions. [2022-02-20 17:56:04,000 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 112 [2022-02-20 17:56:04,000 INFO L506 BasicCegarLoop]: Found error trace [2022-02-20 17:56:04,000 INFO L514 BasicCegarLoop]: trace histogram [3, 3, 3, 3, 3, 3, 2, 2, 2, 2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-02-20 17:56:04,020 INFO L552 MonitoredProcess]: [MP /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 -smt2 -in SMTLIB2_COMPLIANT=true (3)] Ended with exit code 0 [2022-02-20 17:56:04,215 WARN L452 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: 3 /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 -smt2 -in SMTLIB2_COMPLIANT=true,SelfDestructingSolverStorable1 [2022-02-20 17:56:04,216 INFO L402 AbstractCegarLoop]: === Iteration 3 === Targeting outgoingErr0ASSERT_VIOLATIONERROR_FUNCTION === [outgoingErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2022-02-20 17:56:04,216 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2022-02-20 17:56:04,216 INFO L85 PathProgramCache]: Analyzing trace with hash 782710886, now seen corresponding path program 1 times [2022-02-20 17:56:04,216 INFO L126 FreeRefinementEngine]: Executing refinement strategy CAMEL [2022-02-20 17:56:04,216 INFO L338 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [524105579] [2022-02-20 17:56:04,216 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-02-20 17:56:04,216 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2022-02-20 17:56:04,255 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-02-20 17:56:04,293 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 6 [2022-02-20 17:56:04,295 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-02-20 17:56:04,298 INFO L290 TraceCheckUtils]: 0: Hoare triple {5494#(and (= |old(~__ste_client_idCounter0~0)| ~__ste_client_idCounter0~0) (= |old(~__ste_client_idCounter1~0)| ~__ste_client_idCounter1~0) (= |old(~__ste_client_idCounter2~0)| ~__ste_client_idCounter2~0))} ~handle := #in~handle;~value := #in~value; {5438#true} is VALID [2022-02-20 17:56:04,298 INFO L290 TraceCheckUtils]: 1: Hoare triple {5438#true} assume 1 == ~handle;~__ste_client_idCounter0~0 := ~value; {5438#true} is VALID [2022-02-20 17:56:04,298 INFO L290 TraceCheckUtils]: 2: Hoare triple {5438#true} assume true; {5438#true} is VALID [2022-02-20 17:56:04,298 INFO L284 TraceCheckUtils]: 3: Hoare quadruple {5438#true} {5438#true} #1133#return; {5438#true} is VALID [2022-02-20 17:56:04,303 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 12 [2022-02-20 17:56:04,304 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-02-20 17:56:04,307 INFO L290 TraceCheckUtils]: 0: Hoare triple {5495#(and (= ~__ste_client_privateKey0~0 |old(~__ste_client_privateKey0~0)|) (= ~__ste_client_privateKey2~0 |old(~__ste_client_privateKey2~0)|) (= ~__ste_client_privateKey1~0 |old(~__ste_client_privateKey1~0)|))} ~handle := #in~handle;~value := #in~value; {5438#true} is VALID [2022-02-20 17:56:04,307 INFO L290 TraceCheckUtils]: 1: Hoare triple {5438#true} assume 1 == ~handle;~__ste_client_privateKey0~0 := ~value; {5438#true} is VALID [2022-02-20 17:56:04,307 INFO L290 TraceCheckUtils]: 2: Hoare triple {5438#true} assume true; {5438#true} is VALID [2022-02-20 17:56:04,307 INFO L284 TraceCheckUtils]: 3: Hoare quadruple {5438#true} {5438#true} #1135#return; {5438#true} is VALID [2022-02-20 17:56:04,308 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 18 [2022-02-20 17:56:04,309 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-02-20 17:56:04,321 INFO L290 TraceCheckUtils]: 0: Hoare triple {5494#(and (= |old(~__ste_client_idCounter0~0)| ~__ste_client_idCounter0~0) (= |old(~__ste_client_idCounter1~0)| ~__ste_client_idCounter1~0) (= |old(~__ste_client_idCounter2~0)| ~__ste_client_idCounter2~0))} ~handle := #in~handle;~value := #in~value; {5496#(= setClientId_~handle |setClientId_#in~handle|)} is VALID [2022-02-20 17:56:04,322 INFO L290 TraceCheckUtils]: 1: Hoare triple {5496#(= setClientId_~handle |setClientId_#in~handle|)} assume 1 == ~handle;~__ste_client_idCounter0~0 := ~value; {5497#(= |setClientId_#in~handle| 1)} is VALID [2022-02-20 17:56:04,322 INFO L290 TraceCheckUtils]: 2: Hoare triple {5497#(= |setClientId_#in~handle| 1)} assume true; {5497#(= |setClientId_#in~handle| 1)} is VALID [2022-02-20 17:56:04,322 INFO L284 TraceCheckUtils]: 3: Hoare quadruple {5497#(= |setClientId_#in~handle| 1)} {5448#(= |ULTIMATE.start_setup_rjh__wrappee__Base_~rjh___0#1| 2)} #1137#return; {5439#false} is VALID [2022-02-20 17:56:04,323 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 24 [2022-02-20 17:56:04,324 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-02-20 17:56:04,327 INFO L290 TraceCheckUtils]: 0: Hoare triple {5495#(and (= ~__ste_client_privateKey0~0 |old(~__ste_client_privateKey0~0)|) (= ~__ste_client_privateKey2~0 |old(~__ste_client_privateKey2~0)|) (= ~__ste_client_privateKey1~0 |old(~__ste_client_privateKey1~0)|))} ~handle := #in~handle;~value := #in~value; {5438#true} is VALID [2022-02-20 17:56:04,327 INFO L290 TraceCheckUtils]: 1: Hoare triple {5438#true} assume 1 == ~handle;~__ste_client_privateKey0~0 := ~value; {5438#true} is VALID [2022-02-20 17:56:04,327 INFO L290 TraceCheckUtils]: 2: Hoare triple {5438#true} assume true; {5438#true} is VALID [2022-02-20 17:56:04,327 INFO L284 TraceCheckUtils]: 3: Hoare quadruple {5438#true} {5439#false} #1139#return; {5439#false} is VALID [2022-02-20 17:56:04,327 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 30 [2022-02-20 17:56:04,329 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-02-20 17:56:04,331 INFO L290 TraceCheckUtils]: 0: Hoare triple {5494#(and (= |old(~__ste_client_idCounter0~0)| ~__ste_client_idCounter0~0) (= |old(~__ste_client_idCounter1~0)| ~__ste_client_idCounter1~0) (= |old(~__ste_client_idCounter2~0)| ~__ste_client_idCounter2~0))} ~handle := #in~handle;~value := #in~value; {5438#true} is VALID [2022-02-20 17:56:04,331 INFO L290 TraceCheckUtils]: 1: Hoare triple {5438#true} assume 1 == ~handle;~__ste_client_idCounter0~0 := ~value; {5438#true} is VALID [2022-02-20 17:56:04,331 INFO L290 TraceCheckUtils]: 2: Hoare triple {5438#true} assume true; {5438#true} is VALID [2022-02-20 17:56:04,331 INFO L284 TraceCheckUtils]: 3: Hoare quadruple {5438#true} {5439#false} #1141#return; {5439#false} is VALID [2022-02-20 17:56:04,332 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 36 [2022-02-20 17:56:04,333 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-02-20 17:56:04,336 INFO L290 TraceCheckUtils]: 0: Hoare triple {5495#(and (= ~__ste_client_privateKey0~0 |old(~__ste_client_privateKey0~0)|) (= ~__ste_client_privateKey2~0 |old(~__ste_client_privateKey2~0)|) (= ~__ste_client_privateKey1~0 |old(~__ste_client_privateKey1~0)|))} ~handle := #in~handle;~value := #in~value; {5438#true} is VALID [2022-02-20 17:56:04,336 INFO L290 TraceCheckUtils]: 1: Hoare triple {5438#true} assume 1 == ~handle;~__ste_client_privateKey0~0 := ~value; {5438#true} is VALID [2022-02-20 17:56:04,336 INFO L290 TraceCheckUtils]: 2: Hoare triple {5438#true} assume true; {5438#true} is VALID [2022-02-20 17:56:04,336 INFO L284 TraceCheckUtils]: 3: Hoare quadruple {5438#true} {5439#false} #1143#return; {5439#false} is VALID [2022-02-20 17:56:04,342 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 57 [2022-02-20 17:56:04,344 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-02-20 17:56:04,346 INFO L290 TraceCheckUtils]: 0: Hoare triple {5498#(and (= |old(~__ste_email_from0~0)| ~__ste_email_from0~0) (= |old(~__ste_email_from1~0)| ~__ste_email_from1~0))} ~handle := #in~handle;~value := #in~value; {5438#true} is VALID [2022-02-20 17:56:04,346 INFO L290 TraceCheckUtils]: 1: Hoare triple {5438#true} assume 1 == ~handle;~__ste_email_from0~0 := ~value; {5438#true} is VALID [2022-02-20 17:56:04,346 INFO L290 TraceCheckUtils]: 2: Hoare triple {5438#true} assume true; {5438#true} is VALID [2022-02-20 17:56:04,346 INFO L284 TraceCheckUtils]: 3: Hoare quadruple {5438#true} {5439#false} #1119#return; {5439#false} is VALID [2022-02-20 17:56:04,352 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 62 [2022-02-20 17:56:04,354 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-02-20 17:56:04,356 INFO L290 TraceCheckUtils]: 0: Hoare triple {5499#(and (= ~__ste_email_to0~0 |old(~__ste_email_to0~0)|) (= ~__ste_email_to1~0 |old(~__ste_email_to1~0)|))} ~handle := #in~handle;~value := #in~value; {5438#true} is VALID [2022-02-20 17:56:04,356 INFO L290 TraceCheckUtils]: 1: Hoare triple {5438#true} assume 1 == ~handle;~__ste_email_to0~0 := ~value; {5438#true} is VALID [2022-02-20 17:56:04,356 INFO L290 TraceCheckUtils]: 2: Hoare triple {5438#true} assume true; {5438#true} is VALID [2022-02-20 17:56:04,356 INFO L284 TraceCheckUtils]: 3: Hoare quadruple {5438#true} {5439#false} #1121#return; {5439#false} is VALID [2022-02-20 17:56:04,357 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 71 [2022-02-20 17:56:04,357 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-02-20 17:56:04,359 INFO L290 TraceCheckUtils]: 0: Hoare triple {5438#true} ~handle := #in~handle;havoc ~retValue_acc~24; {5438#true} is VALID [2022-02-20 17:56:04,359 INFO L290 TraceCheckUtils]: 1: Hoare triple {5438#true} assume 1 == ~handle;~retValue_acc~24 := ~__ste_client_privateKey0~0;#res := ~retValue_acc~24; {5438#true} is VALID [2022-02-20 17:56:04,359 INFO L290 TraceCheckUtils]: 2: Hoare triple {5438#true} assume true; {5438#true} is VALID [2022-02-20 17:56:04,359 INFO L284 TraceCheckUtils]: 3: Hoare quadruple {5438#true} {5439#false} #1053#return; {5439#false} is VALID [2022-02-20 17:56:04,360 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 79 [2022-02-20 17:56:04,360 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-02-20 17:56:04,362 INFO L290 TraceCheckUtils]: 0: Hoare triple {5438#true} ~handle := #in~handle;havoc ~retValue_acc~36; {5438#true} is VALID [2022-02-20 17:56:04,362 INFO L290 TraceCheckUtils]: 1: Hoare triple {5438#true} assume 1 == ~handle;~retValue_acc~36 := ~__ste_email_to0~0;#res := ~retValue_acc~36; {5438#true} is VALID [2022-02-20 17:56:04,362 INFO L290 TraceCheckUtils]: 2: Hoare triple {5438#true} assume true; {5438#true} is VALID [2022-02-20 17:56:04,362 INFO L284 TraceCheckUtils]: 3: Hoare quadruple {5438#true} {5439#false} #1055#return; {5439#false} is VALID [2022-02-20 17:56:04,362 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 85 [2022-02-20 17:56:04,363 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-02-20 17:56:04,364 INFO L290 TraceCheckUtils]: 0: Hoare triple {5438#true} ~handle := #in~handle;~userid := #in~userid;havoc ~retValue_acc~29; {5438#true} is VALID [2022-02-20 17:56:04,365 INFO L290 TraceCheckUtils]: 1: Hoare triple {5438#true} assume 1 == ~handle; {5438#true} is VALID [2022-02-20 17:56:04,365 INFO L290 TraceCheckUtils]: 2: Hoare triple {5438#true} assume ~userid == ~__ste_Client_Keyring0_User0~0;~retValue_acc~29 := ~__ste_Client_Keyring0_PublicKey0~0;#res := ~retValue_acc~29; {5438#true} is VALID [2022-02-20 17:56:04,365 INFO L290 TraceCheckUtils]: 3: Hoare triple {5438#true} assume true; {5438#true} is VALID [2022-02-20 17:56:04,365 INFO L284 TraceCheckUtils]: 4: Hoare quadruple {5438#true} {5439#false} #1057#return; {5439#false} is VALID [2022-02-20 17:56:04,365 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 96 [2022-02-20 17:56:04,366 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-02-20 17:56:04,369 INFO L290 TraceCheckUtils]: 0: Hoare triple {5498#(and (= |old(~__ste_email_from0~0)| ~__ste_email_from0~0) (= |old(~__ste_email_from1~0)| ~__ste_email_from1~0))} ~handle := #in~handle;~value := #in~value; {5438#true} is VALID [2022-02-20 17:56:04,369 INFO L290 TraceCheckUtils]: 1: Hoare triple {5438#true} assume 1 == ~handle;~__ste_email_from0~0 := ~value; {5438#true} is VALID [2022-02-20 17:56:04,369 INFO L290 TraceCheckUtils]: 2: Hoare triple {5438#true} assume true; {5438#true} is VALID [2022-02-20 17:56:04,370 INFO L284 TraceCheckUtils]: 3: Hoare quadruple {5438#true} {5439#false} #1063#return; {5439#false} is VALID [2022-02-20 17:56:04,370 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 103 [2022-02-20 17:56:04,371 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-02-20 17:56:04,374 INFO L290 TraceCheckUtils]: 0: Hoare triple {5438#true} ~handle := #in~handle;havoc ~retValue_acc~39; {5438#true} is VALID [2022-02-20 17:56:04,374 INFO L290 TraceCheckUtils]: 1: Hoare triple {5438#true} assume 1 == ~handle;~retValue_acc~39 := ~__ste_email_isEncrypted0~0;#res := ~retValue_acc~39; {5438#true} is VALID [2022-02-20 17:56:04,374 INFO L290 TraceCheckUtils]: 2: Hoare triple {5438#true} assume true; {5438#true} is VALID [2022-02-20 17:56:04,374 INFO L284 TraceCheckUtils]: 3: Hoare quadruple {5438#true} {5439#false} #1067#return; {5439#false} is VALID [2022-02-20 17:56:04,374 INFO L290 TraceCheckUtils]: 0: Hoare triple {5438#true} assume { :begin_inline_ULTIMATE.init } true;#NULL.base, #NULL.offset := 0, 0;assume 0 == #valid[0];assume 0 < #StackHeapBarrier;call #Ultimate.allocInit(2, 1);call write~init~int(48, 1, 0, 1);call write~init~int(0, 1, 1, 1);call #Ultimate.allocInit(28, 2);call #Ultimate.allocInit(12, 3);call #Ultimate.allocInit(4, 4);call write~init~int(37, 4, 0, 1);call write~init~int(115, 4, 1, 1);call write~init~int(10, 4, 2, 1);call write~init~int(0, 4, 3, 1);call #Ultimate.allocInit(10, 5);call #Ultimate.allocInit(12, 6);call #Ultimate.allocInit(10, 7);call #Ultimate.allocInit(18, 8);call #Ultimate.allocInit(16, 9);call #Ultimate.allocInit(21, 10);call #Ultimate.allocInit(13, 11);call #Ultimate.allocInit(16, 12);call #Ultimate.allocInit(25, 13);call #Ultimate.allocInit(30, 14);call #Ultimate.allocInit(9, 15);call #Ultimate.allocInit(21, 16);call #Ultimate.allocInit(30, 17);call #Ultimate.allocInit(9, 18);call #Ultimate.allocInit(21, 19);call #Ultimate.allocInit(30, 20);call #Ultimate.allocInit(9, 21);call #Ultimate.allocInit(25, 22);call #Ultimate.allocInit(30, 23);call #Ultimate.allocInit(9, 24);call #Ultimate.allocInit(25, 25);call #Ultimate.allocInit(10, 26);call #Ultimate.allocInit(16, 27);call #Ultimate.allocInit(20, 28);call #Ultimate.allocInit(22, 29);call #Ultimate.allocInit(21, 30);call #Ultimate.allocInit(13, 31);call #Ultimate.allocInit(44, 32);call #Ultimate.allocInit(44, 33);call #Ultimate.allocInit(9, 34);call #Ultimate.allocInit(9, 35);call #Ultimate.allocInit(11, 36);call #Ultimate.allocInit(19, 37);call #Ultimate.allocInit(4, 38);call write~init~int(37, 38, 0, 1);call write~init~int(100, 38, 1, 1);call write~init~int(10, 38, 2, 1);call write~init~int(0, 38, 3, 1);call #Ultimate.allocInit(4, 39);call write~init~int(37, 39, 0, 1);call write~init~int(100, 39, 1, 1);call write~init~int(10, 39, 2, 1);call write~init~int(0, 39, 3, 1);~__SELECTED_FEATURE_Base~0 := 0;~__SELECTED_FEATURE_Keys~0 := 0;~__SELECTED_FEATURE_Encrypt~0 := 0;~__SELECTED_FEATURE_AutoResponder~0 := 0;~__SELECTED_FEATURE_AddressBook~0 := 0;~__SELECTED_FEATURE_Sign~0 := 0;~__SELECTED_FEATURE_Forward~0 := 0;~__SELECTED_FEATURE_Verify~0 := 0;~__SELECTED_FEATURE_Decrypt~0 := 0;~__GUIDSL_ROOT_PRODUCTION~0 := 0;~__GUIDSL_NON_TERMINAL_main~0 := 0;~head~0.base, ~head~0.offset := 0, 0;~queue_empty~0 := 1;~queued_message~0 := 0;~queued_client~0 := 0;~mail_is_sensitive~0 := -1;~__ste_Client_counter~0 := 0;~__ste_client_name0~0.base, ~__ste_client_name0~0.offset := 0, 0;~__ste_client_name1~0.base, ~__ste_client_name1~0.offset := 0, 0;~__ste_client_name2~0.base, ~__ste_client_name2~0.offset := 0, 0;~__ste_client_outbuffer0~0 := 0;~__ste_client_outbuffer1~0 := 0;~__ste_client_outbuffer2~0 := 0;~__ste_client_outbuffer3~0 := 0;~__ste_ClientAddressBook_size0~0 := 0;~__ste_ClientAddressBook_size1~0 := 0;~__ste_ClientAddressBook_size2~0 := 0;~__ste_Client_AddressBook0_Alias0~0 := 0;~__ste_Client_AddressBook0_Alias1~0 := 0;~__ste_Client_AddressBook0_Alias2~0 := 0;~__ste_Client_AddressBook1_Alias0~0 := 0;~__ste_Client_AddressBook1_Alias1~0 := 0;~__ste_Client_AddressBook1_Alias2~0 := 0;~__ste_Client_AddressBook2_Alias0~0 := 0;~__ste_Client_AddressBook2_Alias1~0 := 0;~__ste_Client_AddressBook2_Alias2~0 := 0;~__ste_Client_AddressBook0_Address0~0 := 0;~__ste_Client_AddressBook0_Address1~0 := 0;~__ste_Client_AddressBook0_Address2~0 := 0;~__ste_Client_AddressBook1_Address0~0 := 0;~__ste_Client_AddressBook1_Address1~0 := 0;~__ste_Client_AddressBook1_Address2~0 := 0;~__ste_Client_AddressBook2_Address0~0 := 0;~__ste_Client_AddressBook2_Address1~0 := 0;~__ste_Client_AddressBook2_Address2~0 := 0;~__ste_client_autoResponse0~0 := 0;~__ste_client_autoResponse1~0 := 0;~__ste_client_autoResponse2~0 := 0;~__ste_client_privateKey0~0 := 0;~__ste_client_privateKey1~0 := 0;~__ste_client_privateKey2~0 := 0;~__ste_ClientKeyring_size0~0 := 0;~__ste_ClientKeyring_size1~0 := 0;~__ste_ClientKeyring_size2~0 := 0;~__ste_Client_Keyring0_User0~0 := 0;~__ste_Client_Keyring0_User1~0 := 0;~__ste_Client_Keyring0_User2~0 := 0;~__ste_Client_Keyring1_User0~0 := 0;~__ste_Client_Keyring1_User1~0 := 0;~__ste_Client_Keyring1_User2~0 := 0;~__ste_Client_Keyring2_User0~0 := 0;~__ste_Client_Keyring2_User1~0 := 0;~__ste_Client_Keyring2_User2~0 := 0;~__ste_Client_Keyring0_PublicKey0~0 := 0;~__ste_Client_Keyring0_PublicKey1~0 := 0;~__ste_Client_Keyring0_PublicKey2~0 := 0;~__ste_Client_Keyring1_PublicKey0~0 := 0;~__ste_Client_Keyring1_PublicKey1~0 := 0;~__ste_Client_Keyring1_PublicKey2~0 := 0;~__ste_Client_Keyring2_PublicKey0~0 := 0;~__ste_Client_Keyring2_PublicKey1~0 := 0;~__ste_Client_Keyring2_PublicKey2~0 := 0;~__ste_client_forwardReceiver0~0 := 0;~__ste_client_forwardReceiver1~0 := 0;~__ste_client_forwardReceiver2~0 := 0;~__ste_client_forwardReceiver3~0 := 0;~__ste_client_idCounter0~0 := 0;~__ste_client_idCounter1~0 := 0;~__ste_client_idCounter2~0 := 0;~bob~0 := 0;~rjh~0 := 0;~chuck~0 := 0;~__ste_Email_counter~0 := 0;~__ste_email_id0~0 := 0;~__ste_email_id1~0 := 0;~__ste_email_from0~0 := 0;~__ste_email_from1~0 := 0;~__ste_email_to0~0 := 0;~__ste_email_to1~0 := 0;~__ste_email_subject0~0.base, ~__ste_email_subject0~0.offset := 0, 0;~__ste_email_subject1~0.base, ~__ste_email_subject1~0.offset := 0, 0;~__ste_email_body0~0.base, ~__ste_email_body0~0.offset := 0, 0;~__ste_email_body1~0.base, ~__ste_email_body1~0.offset := 0, 0;~__ste_email_isEncrypted0~0 := 0;~__ste_email_isEncrypted1~0 := 0;~__ste_email_encryptionKey0~0 := 0;~__ste_email_encryptionKey1~0 := 0;~__ste_email_isSigned0~0 := 0;~__ste_email_isSigned1~0 := 0;~__ste_email_signKey0~0 := 0;~__ste_email_signKey1~0 := 0;~__ste_email_isSignatureVerified0~0 := 0;~__ste_email_isSignatureVerified1~0 := 0; {5438#true} is VALID [2022-02-20 17:56:04,374 INFO L290 TraceCheckUtils]: 1: Hoare triple {5438#true} assume { :end_inline_ULTIMATE.init } true;assume { :begin_inline_main } true;havoc main_#res#1;havoc main_#t~ret98#1, main_~retValue_acc~32#1, main_~tmp~24#1;havoc main_~retValue_acc~32#1;havoc main_~tmp~24#1;assume { :begin_inline_select_helpers } true; {5438#true} is VALID [2022-02-20 17:56:04,374 INFO L290 TraceCheckUtils]: 2: Hoare triple {5438#true} assume { :end_inline_select_helpers } true;assume { :begin_inline_select_features } true; {5438#true} is VALID [2022-02-20 17:56:04,374 INFO L290 TraceCheckUtils]: 3: Hoare triple {5438#true} assume { :end_inline_select_features } true;assume { :begin_inline_valid_product } true;havoc valid_product_#res#1;havoc valid_product_~retValue_acc~9#1;havoc valid_product_~retValue_acc~9#1;valid_product_~retValue_acc~9#1 := 1;valid_product_#res#1 := valid_product_~retValue_acc~9#1; {5438#true} is VALID [2022-02-20 17:56:04,375 INFO L290 TraceCheckUtils]: 4: Hoare triple {5438#true} main_#t~ret98#1 := valid_product_#res#1;assume { :end_inline_valid_product } true;assume -2147483648 <= main_#t~ret98#1 && main_#t~ret98#1 <= 2147483647;main_~tmp~24#1 := main_#t~ret98#1;havoc main_#t~ret98#1; {5438#true} is VALID [2022-02-20 17:56:04,375 INFO L290 TraceCheckUtils]: 5: Hoare triple {5438#true} assume 0 != main_~tmp~24#1;assume { :begin_inline_setup } true;havoc setup_#t~nondet95#1, setup_#t~nondet96#1, setup_#t~nondet97#1, setup_~__cil_tmp1~0#1.base, setup_~__cil_tmp1~0#1.offset, setup_~__cil_tmp2~0#1.base, setup_~__cil_tmp2~0#1.offset, setup_~__cil_tmp3~2#1.base, setup_~__cil_tmp3~2#1.offset;havoc setup_~__cil_tmp1~0#1.base, setup_~__cil_tmp1~0#1.offset;havoc setup_~__cil_tmp2~0#1.base, setup_~__cil_tmp2~0#1.offset;havoc setup_~__cil_tmp3~2#1.base, setup_~__cil_tmp3~2#1.offset;~bob~0 := 1;assume { :begin_inline_setup_bob } true;setup_bob_#in~bob___0#1 := ~bob~0;havoc setup_bob_~bob___0#1;setup_bob_~bob___0#1 := setup_bob_#in~bob___0#1;assume { :begin_inline_setup_bob__wrappee__Base } true;setup_bob__wrappee__Base_#in~bob___0#1 := setup_bob_~bob___0#1;havoc setup_bob__wrappee__Base_~bob___0#1;setup_bob__wrappee__Base_~bob___0#1 := setup_bob__wrappee__Base_#in~bob___0#1; {5438#true} is VALID [2022-02-20 17:56:04,375 INFO L272 TraceCheckUtils]: 6: Hoare triple {5438#true} call setClientId(setup_bob__wrappee__Base_~bob___0#1, setup_bob__wrappee__Base_~bob___0#1); {5494#(and (= |old(~__ste_client_idCounter0~0)| ~__ste_client_idCounter0~0) (= |old(~__ste_client_idCounter1~0)| ~__ste_client_idCounter1~0) (= |old(~__ste_client_idCounter2~0)| ~__ste_client_idCounter2~0))} is VALID [2022-02-20 17:56:04,375 INFO L290 TraceCheckUtils]: 7: Hoare triple {5494#(and (= |old(~__ste_client_idCounter0~0)| ~__ste_client_idCounter0~0) (= |old(~__ste_client_idCounter1~0)| ~__ste_client_idCounter1~0) (= |old(~__ste_client_idCounter2~0)| ~__ste_client_idCounter2~0))} ~handle := #in~handle;~value := #in~value; {5438#true} is VALID [2022-02-20 17:56:04,375 INFO L290 TraceCheckUtils]: 8: Hoare triple {5438#true} assume 1 == ~handle;~__ste_client_idCounter0~0 := ~value; {5438#true} is VALID [2022-02-20 17:56:04,375 INFO L290 TraceCheckUtils]: 9: Hoare triple {5438#true} assume true; {5438#true} is VALID [2022-02-20 17:56:04,375 INFO L284 TraceCheckUtils]: 10: Hoare quadruple {5438#true} {5438#true} #1133#return; {5438#true} is VALID [2022-02-20 17:56:04,376 INFO L290 TraceCheckUtils]: 11: Hoare triple {5438#true} assume { :end_inline_setup_bob__wrappee__Base } true; {5438#true} is VALID [2022-02-20 17:56:04,376 INFO L272 TraceCheckUtils]: 12: Hoare triple {5438#true} call setClientPrivateKey(setup_bob_~bob___0#1, 123); {5495#(and (= ~__ste_client_privateKey0~0 |old(~__ste_client_privateKey0~0)|) (= ~__ste_client_privateKey2~0 |old(~__ste_client_privateKey2~0)|) (= ~__ste_client_privateKey1~0 |old(~__ste_client_privateKey1~0)|))} is VALID [2022-02-20 17:56:04,376 INFO L290 TraceCheckUtils]: 13: Hoare triple {5495#(and (= ~__ste_client_privateKey0~0 |old(~__ste_client_privateKey0~0)|) (= ~__ste_client_privateKey2~0 |old(~__ste_client_privateKey2~0)|) (= ~__ste_client_privateKey1~0 |old(~__ste_client_privateKey1~0)|))} ~handle := #in~handle;~value := #in~value; {5438#true} is VALID [2022-02-20 17:56:04,376 INFO L290 TraceCheckUtils]: 14: Hoare triple {5438#true} assume 1 == ~handle;~__ste_client_privateKey0~0 := ~value; {5438#true} is VALID [2022-02-20 17:56:04,376 INFO L290 TraceCheckUtils]: 15: Hoare triple {5438#true} assume true; {5438#true} is VALID [2022-02-20 17:56:04,376 INFO L284 TraceCheckUtils]: 16: Hoare quadruple {5438#true} {5438#true} #1135#return; {5438#true} is VALID [2022-02-20 17:56:04,377 INFO L290 TraceCheckUtils]: 17: Hoare triple {5438#true} assume { :end_inline_setup_bob } true;setup_~__cil_tmp1~0#1.base, setup_~__cil_tmp1~0#1.offset := 34, 0;havoc setup_#t~nondet95#1;~rjh~0 := 2;assume { :begin_inline_setup_rjh } true;setup_rjh_#in~rjh___0#1 := ~rjh~0;havoc setup_rjh_~rjh___0#1;setup_rjh_~rjh___0#1 := setup_rjh_#in~rjh___0#1;assume { :begin_inline_setup_rjh__wrappee__Base } true;setup_rjh__wrappee__Base_#in~rjh___0#1 := setup_rjh_~rjh___0#1;havoc setup_rjh__wrappee__Base_~rjh___0#1;setup_rjh__wrappee__Base_~rjh___0#1 := setup_rjh__wrappee__Base_#in~rjh___0#1; {5448#(= |ULTIMATE.start_setup_rjh__wrappee__Base_~rjh___0#1| 2)} is VALID [2022-02-20 17:56:04,377 INFO L272 TraceCheckUtils]: 18: Hoare triple {5448#(= |ULTIMATE.start_setup_rjh__wrappee__Base_~rjh___0#1| 2)} call setClientId(setup_rjh__wrappee__Base_~rjh___0#1, setup_rjh__wrappee__Base_~rjh___0#1); {5494#(and (= |old(~__ste_client_idCounter0~0)| ~__ste_client_idCounter0~0) (= |old(~__ste_client_idCounter1~0)| ~__ste_client_idCounter1~0) (= |old(~__ste_client_idCounter2~0)| ~__ste_client_idCounter2~0))} is VALID [2022-02-20 17:56:04,377 INFO L290 TraceCheckUtils]: 19: Hoare triple {5494#(and (= |old(~__ste_client_idCounter0~0)| ~__ste_client_idCounter0~0) (= |old(~__ste_client_idCounter1~0)| ~__ste_client_idCounter1~0) (= |old(~__ste_client_idCounter2~0)| ~__ste_client_idCounter2~0))} ~handle := #in~handle;~value := #in~value; {5496#(= setClientId_~handle |setClientId_#in~handle|)} is VALID [2022-02-20 17:56:04,378 INFO L290 TraceCheckUtils]: 20: Hoare triple {5496#(= setClientId_~handle |setClientId_#in~handle|)} assume 1 == ~handle;~__ste_client_idCounter0~0 := ~value; {5497#(= |setClientId_#in~handle| 1)} is VALID [2022-02-20 17:56:04,378 INFO L290 TraceCheckUtils]: 21: Hoare triple {5497#(= |setClientId_#in~handle| 1)} assume true; {5497#(= |setClientId_#in~handle| 1)} is VALID [2022-02-20 17:56:04,378 INFO L284 TraceCheckUtils]: 22: Hoare quadruple {5497#(= |setClientId_#in~handle| 1)} {5448#(= |ULTIMATE.start_setup_rjh__wrappee__Base_~rjh___0#1| 2)} #1137#return; {5439#false} is VALID [2022-02-20 17:56:04,379 INFO L290 TraceCheckUtils]: 23: Hoare triple {5439#false} assume { :end_inline_setup_rjh__wrappee__Base } true; {5439#false} is VALID [2022-02-20 17:56:04,379 INFO L272 TraceCheckUtils]: 24: Hoare triple {5439#false} call setClientPrivateKey(setup_rjh_~rjh___0#1, 456); {5495#(and (= ~__ste_client_privateKey0~0 |old(~__ste_client_privateKey0~0)|) (= ~__ste_client_privateKey2~0 |old(~__ste_client_privateKey2~0)|) (= ~__ste_client_privateKey1~0 |old(~__ste_client_privateKey1~0)|))} is VALID [2022-02-20 17:56:04,379 INFO L290 TraceCheckUtils]: 25: Hoare triple {5495#(and (= ~__ste_client_privateKey0~0 |old(~__ste_client_privateKey0~0)|) (= ~__ste_client_privateKey2~0 |old(~__ste_client_privateKey2~0)|) (= ~__ste_client_privateKey1~0 |old(~__ste_client_privateKey1~0)|))} ~handle := #in~handle;~value := #in~value; {5438#true} is VALID [2022-02-20 17:56:04,379 INFO L290 TraceCheckUtils]: 26: Hoare triple {5438#true} assume 1 == ~handle;~__ste_client_privateKey0~0 := ~value; {5438#true} is VALID [2022-02-20 17:56:04,379 INFO L290 TraceCheckUtils]: 27: Hoare triple {5438#true} assume true; {5438#true} is VALID [2022-02-20 17:56:04,379 INFO L284 TraceCheckUtils]: 28: Hoare quadruple {5438#true} {5439#false} #1139#return; {5439#false} is VALID [2022-02-20 17:56:04,379 INFO L290 TraceCheckUtils]: 29: Hoare triple {5439#false} assume { :end_inline_setup_rjh } true;setup_~__cil_tmp2~0#1.base, setup_~__cil_tmp2~0#1.offset := 35, 0;havoc setup_#t~nondet96#1;~chuck~0 := 3;assume { :begin_inline_setup_chuck } true;setup_chuck_#in~chuck___0#1 := ~chuck~0;havoc setup_chuck_~chuck___0#1;setup_chuck_~chuck___0#1 := setup_chuck_#in~chuck___0#1;assume { :begin_inline_setup_chuck__wrappee__Base } true;setup_chuck__wrappee__Base_#in~chuck___0#1 := setup_chuck_~chuck___0#1;havoc setup_chuck__wrappee__Base_~chuck___0#1;setup_chuck__wrappee__Base_~chuck___0#1 := setup_chuck__wrappee__Base_#in~chuck___0#1; {5439#false} is VALID [2022-02-20 17:56:04,379 INFO L272 TraceCheckUtils]: 30: Hoare triple {5439#false} call setClientId(setup_chuck__wrappee__Base_~chuck___0#1, setup_chuck__wrappee__Base_~chuck___0#1); {5494#(and (= |old(~__ste_client_idCounter0~0)| ~__ste_client_idCounter0~0) (= |old(~__ste_client_idCounter1~0)| ~__ste_client_idCounter1~0) (= |old(~__ste_client_idCounter2~0)| ~__ste_client_idCounter2~0))} is VALID [2022-02-20 17:56:04,379 INFO L290 TraceCheckUtils]: 31: Hoare triple {5494#(and (= |old(~__ste_client_idCounter0~0)| ~__ste_client_idCounter0~0) (= |old(~__ste_client_idCounter1~0)| ~__ste_client_idCounter1~0) (= |old(~__ste_client_idCounter2~0)| ~__ste_client_idCounter2~0))} ~handle := #in~handle;~value := #in~value; {5438#true} is VALID [2022-02-20 17:56:04,379 INFO L290 TraceCheckUtils]: 32: Hoare triple {5438#true} assume 1 == ~handle;~__ste_client_idCounter0~0 := ~value; {5438#true} is VALID [2022-02-20 17:56:04,379 INFO L290 TraceCheckUtils]: 33: Hoare triple {5438#true} assume true; {5438#true} is VALID [2022-02-20 17:56:04,379 INFO L284 TraceCheckUtils]: 34: Hoare quadruple {5438#true} {5439#false} #1141#return; {5439#false} is VALID [2022-02-20 17:56:04,379 INFO L290 TraceCheckUtils]: 35: Hoare triple {5439#false} assume { :end_inline_setup_chuck__wrappee__Base } true; {5439#false} is VALID [2022-02-20 17:56:04,379 INFO L272 TraceCheckUtils]: 36: Hoare triple {5439#false} call setClientPrivateKey(setup_chuck_~chuck___0#1, 789); {5495#(and (= ~__ste_client_privateKey0~0 |old(~__ste_client_privateKey0~0)|) (= ~__ste_client_privateKey2~0 |old(~__ste_client_privateKey2~0)|) (= ~__ste_client_privateKey1~0 |old(~__ste_client_privateKey1~0)|))} is VALID [2022-02-20 17:56:04,379 INFO L290 TraceCheckUtils]: 37: Hoare triple {5495#(and (= ~__ste_client_privateKey0~0 |old(~__ste_client_privateKey0~0)|) (= ~__ste_client_privateKey2~0 |old(~__ste_client_privateKey2~0)|) (= ~__ste_client_privateKey1~0 |old(~__ste_client_privateKey1~0)|))} ~handle := #in~handle;~value := #in~value; {5438#true} is VALID [2022-02-20 17:56:04,379 INFO L290 TraceCheckUtils]: 38: Hoare triple {5438#true} assume 1 == ~handle;~__ste_client_privateKey0~0 := ~value; {5438#true} is VALID [2022-02-20 17:56:04,379 INFO L290 TraceCheckUtils]: 39: Hoare triple {5438#true} assume true; {5438#true} is VALID [2022-02-20 17:56:04,379 INFO L284 TraceCheckUtils]: 40: Hoare quadruple {5438#true} {5439#false} #1143#return; {5439#false} is VALID [2022-02-20 17:56:04,379 INFO L290 TraceCheckUtils]: 41: Hoare triple {5439#false} assume { :end_inline_setup_chuck } true;setup_~__cil_tmp3~2#1.base, setup_~__cil_tmp3~2#1.offset := 36, 0;havoc setup_#t~nondet97#1; {5439#false} is VALID [2022-02-20 17:56:04,379 INFO L290 TraceCheckUtils]: 42: Hoare triple {5439#false} assume { :end_inline_setup } true;assume { :begin_inline_test } true;havoc test_#t~nondet48#1, test_#t~nondet49#1, test_#t~nondet50#1, test_#t~nondet51#1, test_#t~nondet52#1, test_#t~nondet53#1, test_#t~nondet54#1, test_#t~nondet55#1, test_#t~nondet56#1, test_#t~nondet57#1, test_#t~nondet58#1, test_~op1~0#1, test_~op2~0#1, test_~op3~0#1, test_~op4~0#1, test_~op5~0#1, test_~op6~0#1, test_~op7~0#1, test_~op8~0#1, test_~op9~0#1, test_~op10~0#1, test_~op11~0#1, test_~splverifierCounter~0#1, test_~tmp~8#1, test_~tmp___0~3#1, test_~tmp___1~1#1, test_~tmp___2~1#1, test_~tmp___3~0#1, test_~tmp___4~0#1, test_~tmp___5~0#1, test_~tmp___6~0#1, test_~tmp___7~0#1, test_~tmp___8~0#1, test_~tmp___9~0#1;havoc test_~op1~0#1;havoc test_~op2~0#1;havoc test_~op3~0#1;havoc test_~op4~0#1;havoc test_~op5~0#1;havoc test_~op6~0#1;havoc test_~op7~0#1;havoc test_~op8~0#1;havoc test_~op9~0#1;havoc test_~op10~0#1;havoc test_~op11~0#1;havoc test_~splverifierCounter~0#1;havoc test_~tmp~8#1;havoc test_~tmp___0~3#1;havoc test_~tmp___1~1#1;havoc test_~tmp___2~1#1;havoc test_~tmp___3~0#1;havoc test_~tmp___4~0#1;havoc test_~tmp___5~0#1;havoc test_~tmp___6~0#1;havoc test_~tmp___7~0#1;havoc test_~tmp___8~0#1;havoc test_~tmp___9~0#1;test_~op1~0#1 := 0;test_~op2~0#1 := 0;test_~op3~0#1 := 0;test_~op4~0#1 := 0;test_~op5~0#1 := 0;test_~op6~0#1 := 0;test_~op7~0#1 := 0;test_~op8~0#1 := 0;test_~op9~0#1 := 0;test_~op10~0#1 := 0;test_~op11~0#1 := 0;test_~splverifierCounter~0#1 := 0; {5439#false} is VALID [2022-02-20 17:56:04,380 INFO L290 TraceCheckUtils]: 43: Hoare triple {5439#false} assume !false; {5439#false} is VALID [2022-02-20 17:56:04,380 INFO L290 TraceCheckUtils]: 44: Hoare triple {5439#false} assume test_~splverifierCounter~0#1 < 4; {5439#false} is VALID [2022-02-20 17:56:04,380 INFO L290 TraceCheckUtils]: 45: Hoare triple {5439#false} test_~splverifierCounter~0#1 := 1 + test_~splverifierCounter~0#1; {5439#false} is VALID [2022-02-20 17:56:04,380 INFO L290 TraceCheckUtils]: 46: Hoare triple {5439#false} assume !(0 == test_~op1~0#1); {5439#false} is VALID [2022-02-20 17:56:04,380 INFO L290 TraceCheckUtils]: 47: Hoare triple {5439#false} assume 0 == test_~op2~0#1;assume -2147483648 <= test_#t~nondet49#1 && test_#t~nondet49#1 <= 2147483647;test_~tmp___8~0#1 := test_#t~nondet49#1;havoc test_#t~nondet49#1; {5439#false} is VALID [2022-02-20 17:56:04,380 INFO L290 TraceCheckUtils]: 48: Hoare triple {5439#false} assume 0 != test_~tmp___8~0#1;assume { :begin_inline_rjhSetAutoRespond } true;assume { :begin_inline_setClientAutoResponse } true;setClientAutoResponse_#in~handle#1, setClientAutoResponse_#in~value#1 := ~rjh~0, 1;havoc setClientAutoResponse_~handle#1, setClientAutoResponse_~value#1;setClientAutoResponse_~handle#1 := setClientAutoResponse_#in~handle#1;setClientAutoResponse_~value#1 := setClientAutoResponse_#in~value#1; {5439#false} is VALID [2022-02-20 17:56:04,380 INFO L290 TraceCheckUtils]: 49: Hoare triple {5439#false} assume 1 == setClientAutoResponse_~handle#1;~__ste_client_autoResponse0~0 := setClientAutoResponse_~value#1; {5439#false} is VALID [2022-02-20 17:56:04,380 INFO L290 TraceCheckUtils]: 50: Hoare triple {5439#false} assume { :end_inline_setClientAutoResponse } true; {5439#false} is VALID [2022-02-20 17:56:04,380 INFO L290 TraceCheckUtils]: 51: Hoare triple {5439#false} assume { :end_inline_rjhSetAutoRespond } true;test_~op2~0#1 := 1; {5439#false} is VALID [2022-02-20 17:56:04,380 INFO L290 TraceCheckUtils]: 52: Hoare triple {5439#false} assume !false; {5439#false} is VALID [2022-02-20 17:56:04,380 INFO L290 TraceCheckUtils]: 53: Hoare triple {5439#false} assume !(test_~splverifierCounter~0#1 < 4); {5439#false} is VALID [2022-02-20 17:56:04,380 INFO L290 TraceCheckUtils]: 54: Hoare triple {5439#false} assume { :begin_inline_bobToRjh } true;havoc bobToRjh_#t~ret90#1, bobToRjh_#t~ret91#1, bobToRjh_#t~ret92#1, bobToRjh_#t~ret93#1, bobToRjh_~tmp~23#1, bobToRjh_~tmp___0~7#1, bobToRjh_~tmp___1~4#1;havoc bobToRjh_~tmp~23#1;havoc bobToRjh_~tmp___0~7#1;havoc bobToRjh_~tmp___1~4#1;call bobToRjh_#t~ret90#1 := puts(32, 0);assume -2147483648 <= bobToRjh_#t~ret90#1 && bobToRjh_#t~ret90#1 <= 2147483647;havoc bobToRjh_#t~ret90#1; {5439#false} is VALID [2022-02-20 17:56:04,380 INFO L272 TraceCheckUtils]: 55: Hoare triple {5439#false} call sendEmail(~bob~0, ~rjh~0); {5439#false} is VALID [2022-02-20 17:56:04,380 INFO L290 TraceCheckUtils]: 56: Hoare triple {5439#false} ~sender#1 := #in~sender#1;~receiver#1 := #in~receiver#1;havoc ~email~0#1;havoc ~tmp~16#1;assume { :begin_inline_createEmail } true;createEmail_#in~from#1, createEmail_#in~to#1 := 0, ~receiver#1;havoc createEmail_#res#1;havoc createEmail_~from#1, createEmail_~to#1, createEmail_~retValue_acc~4#1, createEmail_~msg~0#1;createEmail_~from#1 := createEmail_#in~from#1;createEmail_~to#1 := createEmail_#in~to#1;havoc createEmail_~retValue_acc~4#1;havoc createEmail_~msg~0#1;createEmail_~msg~0#1 := 1; {5439#false} is VALID [2022-02-20 17:56:04,380 INFO L272 TraceCheckUtils]: 57: Hoare triple {5439#false} call setEmailFrom(createEmail_~msg~0#1, createEmail_~from#1); {5498#(and (= |old(~__ste_email_from0~0)| ~__ste_email_from0~0) (= |old(~__ste_email_from1~0)| ~__ste_email_from1~0))} is VALID [2022-02-20 17:56:04,380 INFO L290 TraceCheckUtils]: 58: Hoare triple {5498#(and (= |old(~__ste_email_from0~0)| ~__ste_email_from0~0) (= |old(~__ste_email_from1~0)| ~__ste_email_from1~0))} ~handle := #in~handle;~value := #in~value; {5438#true} is VALID [2022-02-20 17:56:04,380 INFO L290 TraceCheckUtils]: 59: Hoare triple {5438#true} assume 1 == ~handle;~__ste_email_from0~0 := ~value; {5438#true} is VALID [2022-02-20 17:56:04,380 INFO L290 TraceCheckUtils]: 60: Hoare triple {5438#true} assume true; {5438#true} is VALID [2022-02-20 17:56:04,380 INFO L284 TraceCheckUtils]: 61: Hoare quadruple {5438#true} {5439#false} #1119#return; {5439#false} is VALID [2022-02-20 17:56:04,381 INFO L272 TraceCheckUtils]: 62: Hoare triple {5439#false} call setEmailTo(createEmail_~msg~0#1, createEmail_~to#1); {5499#(and (= ~__ste_email_to0~0 |old(~__ste_email_to0~0)|) (= ~__ste_email_to1~0 |old(~__ste_email_to1~0)|))} is VALID [2022-02-20 17:56:04,381 INFO L290 TraceCheckUtils]: 63: Hoare triple {5499#(and (= ~__ste_email_to0~0 |old(~__ste_email_to0~0)|) (= ~__ste_email_to1~0 |old(~__ste_email_to1~0)|))} ~handle := #in~handle;~value := #in~value; {5438#true} is VALID [2022-02-20 17:56:04,381 INFO L290 TraceCheckUtils]: 64: Hoare triple {5438#true} assume 1 == ~handle;~__ste_email_to0~0 := ~value; {5438#true} is VALID [2022-02-20 17:56:04,381 INFO L290 TraceCheckUtils]: 65: Hoare triple {5438#true} assume true; {5438#true} is VALID [2022-02-20 17:56:04,381 INFO L284 TraceCheckUtils]: 66: Hoare quadruple {5438#true} {5439#false} #1121#return; {5439#false} is VALID [2022-02-20 17:56:04,381 INFO L290 TraceCheckUtils]: 67: Hoare triple {5439#false} createEmail_~retValue_acc~4#1 := createEmail_~msg~0#1;createEmail_#res#1 := createEmail_~retValue_acc~4#1; {5439#false} is VALID [2022-02-20 17:56:04,381 INFO L290 TraceCheckUtils]: 68: Hoare triple {5439#false} #t~ret73#1 := createEmail_#res#1;assume { :end_inline_createEmail } true;assume -2147483648 <= #t~ret73#1 && #t~ret73#1 <= 2147483647;~tmp~16#1 := #t~ret73#1;havoc #t~ret73#1;~email~0#1 := ~tmp~16#1; {5439#false} is VALID [2022-02-20 17:56:04,381 INFO L272 TraceCheckUtils]: 69: Hoare triple {5439#false} call outgoing(~sender#1, ~email~0#1); {5439#false} is VALID [2022-02-20 17:56:04,381 INFO L290 TraceCheckUtils]: 70: Hoare triple {5439#false} ~client#1 := #in~client#1;~msg#1 := #in~msg#1;assume { :begin_inline_sign } true;sign_#in~client#1, sign_#in~msg#1 := ~client#1, ~msg#1;havoc sign_#t~ret77#1, sign_~client#1, sign_~msg#1, sign_~privkey~1#1, sign_~tmp~18#1;sign_~client#1 := sign_#in~client#1;sign_~msg#1 := sign_#in~msg#1;havoc sign_~privkey~1#1;havoc sign_~tmp~18#1; {5439#false} is VALID [2022-02-20 17:56:04,381 INFO L272 TraceCheckUtils]: 71: Hoare triple {5439#false} call sign_#t~ret77#1 := getClientPrivateKey(sign_~client#1); {5438#true} is VALID [2022-02-20 17:56:04,381 INFO L290 TraceCheckUtils]: 72: Hoare triple {5438#true} ~handle := #in~handle;havoc ~retValue_acc~24; {5438#true} is VALID [2022-02-20 17:56:04,381 INFO L290 TraceCheckUtils]: 73: Hoare triple {5438#true} assume 1 == ~handle;~retValue_acc~24 := ~__ste_client_privateKey0~0;#res := ~retValue_acc~24; {5438#true} is VALID [2022-02-20 17:56:04,381 INFO L290 TraceCheckUtils]: 74: Hoare triple {5438#true} assume true; {5438#true} is VALID [2022-02-20 17:56:04,381 INFO L284 TraceCheckUtils]: 75: Hoare quadruple {5438#true} {5439#false} #1053#return; {5439#false} is VALID [2022-02-20 17:56:04,381 INFO L290 TraceCheckUtils]: 76: Hoare triple {5439#false} assume -2147483648 <= sign_#t~ret77#1 && sign_#t~ret77#1 <= 2147483647;sign_~tmp~18#1 := sign_#t~ret77#1;havoc sign_#t~ret77#1;sign_~privkey~1#1 := sign_~tmp~18#1; {5439#false} is VALID [2022-02-20 17:56:04,381 INFO L290 TraceCheckUtils]: 77: Hoare triple {5439#false} assume 0 == sign_~privkey~1#1; {5439#false} is VALID [2022-02-20 17:56:04,381 INFO L290 TraceCheckUtils]: 78: Hoare triple {5439#false} assume { :end_inline_sign } true;assume { :begin_inline_outgoing__wrappee__AutoResponder } true;outgoing__wrappee__AutoResponder_#in~client#1, outgoing__wrappee__AutoResponder_#in~msg#1 := ~client#1, ~msg#1;havoc outgoing__wrappee__AutoResponder_#t~ret63#1, outgoing__wrappee__AutoResponder_#t~ret64#1, outgoing__wrappee__AutoResponder_~client#1, outgoing__wrappee__AutoResponder_~msg#1, outgoing__wrappee__AutoResponder_~receiver~0#1, outgoing__wrappee__AutoResponder_~tmp~11#1, outgoing__wrappee__AutoResponder_~pubkey~0#1, outgoing__wrappee__AutoResponder_~tmp___0~4#1;outgoing__wrappee__AutoResponder_~client#1 := outgoing__wrappee__AutoResponder_#in~client#1;outgoing__wrappee__AutoResponder_~msg#1 := outgoing__wrappee__AutoResponder_#in~msg#1;havoc outgoing__wrappee__AutoResponder_~receiver~0#1;havoc outgoing__wrappee__AutoResponder_~tmp~11#1;havoc outgoing__wrappee__AutoResponder_~pubkey~0#1;havoc outgoing__wrappee__AutoResponder_~tmp___0~4#1; {5439#false} is VALID [2022-02-20 17:56:04,381 INFO L272 TraceCheckUtils]: 79: Hoare triple {5439#false} call outgoing__wrappee__AutoResponder_#t~ret63#1 := getEmailTo(outgoing__wrappee__AutoResponder_~msg#1); {5438#true} is VALID [2022-02-20 17:56:04,381 INFO L290 TraceCheckUtils]: 80: Hoare triple {5438#true} ~handle := #in~handle;havoc ~retValue_acc~36; {5438#true} is VALID [2022-02-20 17:56:04,381 INFO L290 TraceCheckUtils]: 81: Hoare triple {5438#true} assume 1 == ~handle;~retValue_acc~36 := ~__ste_email_to0~0;#res := ~retValue_acc~36; {5438#true} is VALID [2022-02-20 17:56:04,381 INFO L290 TraceCheckUtils]: 82: Hoare triple {5438#true} assume true; {5438#true} is VALID [2022-02-20 17:56:04,381 INFO L284 TraceCheckUtils]: 83: Hoare quadruple {5438#true} {5439#false} #1055#return; {5439#false} is VALID [2022-02-20 17:56:04,382 INFO L290 TraceCheckUtils]: 84: Hoare triple {5439#false} assume -2147483648 <= outgoing__wrappee__AutoResponder_#t~ret63#1 && outgoing__wrappee__AutoResponder_#t~ret63#1 <= 2147483647;outgoing__wrappee__AutoResponder_~tmp~11#1 := outgoing__wrappee__AutoResponder_#t~ret63#1;havoc outgoing__wrappee__AutoResponder_#t~ret63#1;outgoing__wrappee__AutoResponder_~receiver~0#1 := outgoing__wrappee__AutoResponder_~tmp~11#1; {5439#false} is VALID [2022-02-20 17:56:04,382 INFO L272 TraceCheckUtils]: 85: Hoare triple {5439#false} call outgoing__wrappee__AutoResponder_#t~ret64#1 := findPublicKey(outgoing__wrappee__AutoResponder_~client#1, outgoing__wrappee__AutoResponder_~receiver~0#1); {5438#true} is VALID [2022-02-20 17:56:04,382 INFO L290 TraceCheckUtils]: 86: Hoare triple {5438#true} ~handle := #in~handle;~userid := #in~userid;havoc ~retValue_acc~29; {5438#true} is VALID [2022-02-20 17:56:04,382 INFO L290 TraceCheckUtils]: 87: Hoare triple {5438#true} assume 1 == ~handle; {5438#true} is VALID [2022-02-20 17:56:04,382 INFO L290 TraceCheckUtils]: 88: Hoare triple {5438#true} assume ~userid == ~__ste_Client_Keyring0_User0~0;~retValue_acc~29 := ~__ste_Client_Keyring0_PublicKey0~0;#res := ~retValue_acc~29; {5438#true} is VALID [2022-02-20 17:56:04,382 INFO L290 TraceCheckUtils]: 89: Hoare triple {5438#true} assume true; {5438#true} is VALID [2022-02-20 17:56:04,382 INFO L284 TraceCheckUtils]: 90: Hoare quadruple {5438#true} {5439#false} #1057#return; {5439#false} is VALID [2022-02-20 17:56:04,382 INFO L290 TraceCheckUtils]: 91: Hoare triple {5439#false} assume -2147483648 <= outgoing__wrappee__AutoResponder_#t~ret64#1 && outgoing__wrappee__AutoResponder_#t~ret64#1 <= 2147483647;outgoing__wrappee__AutoResponder_~tmp___0~4#1 := outgoing__wrappee__AutoResponder_#t~ret64#1;havoc outgoing__wrappee__AutoResponder_#t~ret64#1;outgoing__wrappee__AutoResponder_~pubkey~0#1 := outgoing__wrappee__AutoResponder_~tmp___0~4#1; {5439#false} is VALID [2022-02-20 17:56:04,382 INFO L290 TraceCheckUtils]: 92: Hoare triple {5439#false} assume !(0 != outgoing__wrappee__AutoResponder_~pubkey~0#1); {5439#false} is VALID [2022-02-20 17:56:04,382 INFO L290 TraceCheckUtils]: 93: Hoare triple {5439#false} assume { :begin_inline_outgoing__wrappee__Keys } true;outgoing__wrappee__Keys_#in~client#1, outgoing__wrappee__Keys_#in~msg#1 := outgoing__wrappee__AutoResponder_~client#1, outgoing__wrappee__AutoResponder_~msg#1;havoc outgoing__wrappee__Keys_#t~ret62#1, outgoing__wrappee__Keys_~client#1, outgoing__wrappee__Keys_~msg#1, outgoing__wrappee__Keys_~tmp~10#1;outgoing__wrappee__Keys_~client#1 := outgoing__wrappee__Keys_#in~client#1;outgoing__wrappee__Keys_~msg#1 := outgoing__wrappee__Keys_#in~msg#1;havoc outgoing__wrappee__Keys_~tmp~10#1;assume { :begin_inline_getClientId } true;getClientId_#in~handle#1 := outgoing__wrappee__Keys_~client#1;havoc getClientId_#res#1;havoc getClientId_~handle#1, getClientId_~retValue_acc~31#1;getClientId_~handle#1 := getClientId_#in~handle#1;havoc getClientId_~retValue_acc~31#1; {5439#false} is VALID [2022-02-20 17:56:04,382 INFO L290 TraceCheckUtils]: 94: Hoare triple {5439#false} assume 1 == getClientId_~handle#1;getClientId_~retValue_acc~31#1 := ~__ste_client_idCounter0~0;getClientId_#res#1 := getClientId_~retValue_acc~31#1; {5439#false} is VALID [2022-02-20 17:56:04,382 INFO L290 TraceCheckUtils]: 95: Hoare triple {5439#false} outgoing__wrappee__Keys_#t~ret62#1 := getClientId_#res#1;assume { :end_inline_getClientId } true;assume -2147483648 <= outgoing__wrappee__Keys_#t~ret62#1 && outgoing__wrappee__Keys_#t~ret62#1 <= 2147483647;outgoing__wrappee__Keys_~tmp~10#1 := outgoing__wrappee__Keys_#t~ret62#1;havoc outgoing__wrappee__Keys_#t~ret62#1; {5439#false} is VALID [2022-02-20 17:56:04,382 INFO L272 TraceCheckUtils]: 96: Hoare triple {5439#false} call setEmailFrom(outgoing__wrappee__Keys_~msg#1, outgoing__wrappee__Keys_~tmp~10#1); {5498#(and (= |old(~__ste_email_from0~0)| ~__ste_email_from0~0) (= |old(~__ste_email_from1~0)| ~__ste_email_from1~0))} is VALID [2022-02-20 17:56:04,382 INFO L290 TraceCheckUtils]: 97: Hoare triple {5498#(and (= |old(~__ste_email_from0~0)| ~__ste_email_from0~0) (= |old(~__ste_email_from1~0)| ~__ste_email_from1~0))} ~handle := #in~handle;~value := #in~value; {5438#true} is VALID [2022-02-20 17:56:04,382 INFO L290 TraceCheckUtils]: 98: Hoare triple {5438#true} assume 1 == ~handle;~__ste_email_from0~0 := ~value; {5438#true} is VALID [2022-02-20 17:56:04,382 INFO L290 TraceCheckUtils]: 99: Hoare triple {5438#true} assume true; {5438#true} is VALID [2022-02-20 17:56:04,382 INFO L284 TraceCheckUtils]: 100: Hoare quadruple {5438#true} {5439#false} #1063#return; {5439#false} is VALID [2022-02-20 17:56:04,382 INFO L290 TraceCheckUtils]: 101: Hoare triple {5439#false} assume { :begin_inline_mail } true;mail_#in~client#1, mail_#in~msg#1 := outgoing__wrappee__Keys_~client#1, outgoing__wrappee__Keys_~msg#1;havoc mail_#t~ret60#1, mail_#t~ret61#1, mail_~client#1, mail_~msg#1, mail_~__utac__ad__arg1~0#1, mail_~__utac__ad__arg2~0#1, mail_~tmp~9#1;mail_~client#1 := mail_#in~client#1;mail_~msg#1 := mail_#in~msg#1;havoc mail_~__utac__ad__arg1~0#1;havoc mail_~__utac__ad__arg2~0#1;havoc mail_~tmp~9#1;mail_~__utac__ad__arg1~0#1 := mail_~client#1;mail_~__utac__ad__arg2~0#1 := mail_~msg#1;assume { :begin_inline___utac_acc__AddressBookEncrypt_spec__1 } true;__utac_acc__AddressBookEncrypt_spec__1_#in~client#1, __utac_acc__AddressBookEncrypt_spec__1_#in~msg#1 := mail_~__utac__ad__arg1~0#1, mail_~__utac__ad__arg2~0#1;havoc __utac_acc__AddressBookEncrypt_spec__1_#t~ret85#1, __utac_acc__AddressBookEncrypt_spec__1_#t~ret86#1, __utac_acc__AddressBookEncrypt_spec__1_#t~ret87#1, __utac_acc__AddressBookEncrypt_spec__1_~client#1, __utac_acc__AddressBookEncrypt_spec__1_~msg#1, __utac_acc__AddressBookEncrypt_spec__1_~tmp~20#1;__utac_acc__AddressBookEncrypt_spec__1_~client#1 := __utac_acc__AddressBookEncrypt_spec__1_#in~client#1;__utac_acc__AddressBookEncrypt_spec__1_~msg#1 := __utac_acc__AddressBookEncrypt_spec__1_#in~msg#1;havoc __utac_acc__AddressBookEncrypt_spec__1_~tmp~20#1;call __utac_acc__AddressBookEncrypt_spec__1_#t~ret85#1 := puts(31, 0);assume -2147483648 <= __utac_acc__AddressBookEncrypt_spec__1_#t~ret85#1 && __utac_acc__AddressBookEncrypt_spec__1_#t~ret85#1 <= 2147483647;havoc __utac_acc__AddressBookEncrypt_spec__1_#t~ret85#1; {5439#false} is VALID [2022-02-20 17:56:04,382 INFO L290 TraceCheckUtils]: 102: Hoare triple {5439#false} assume !(-1 == ~mail_is_sensitive~0); {5439#false} is VALID [2022-02-20 17:56:04,382 INFO L272 TraceCheckUtils]: 103: Hoare triple {5439#false} call __utac_acc__AddressBookEncrypt_spec__1_#t~ret87#1 := isEncrypted(__utac_acc__AddressBookEncrypt_spec__1_~msg#1); {5438#true} is VALID [2022-02-20 17:56:04,382 INFO L290 TraceCheckUtils]: 104: Hoare triple {5438#true} ~handle := #in~handle;havoc ~retValue_acc~39; {5438#true} is VALID [2022-02-20 17:56:04,383 INFO L290 TraceCheckUtils]: 105: Hoare triple {5438#true} assume 1 == ~handle;~retValue_acc~39 := ~__ste_email_isEncrypted0~0;#res := ~retValue_acc~39; {5438#true} is VALID [2022-02-20 17:56:04,383 INFO L290 TraceCheckUtils]: 106: Hoare triple {5438#true} assume true; {5438#true} is VALID [2022-02-20 17:56:04,383 INFO L284 TraceCheckUtils]: 107: Hoare quadruple {5438#true} {5439#false} #1067#return; {5439#false} is VALID [2022-02-20 17:56:04,383 INFO L290 TraceCheckUtils]: 108: Hoare triple {5439#false} assume -2147483648 <= __utac_acc__AddressBookEncrypt_spec__1_#t~ret87#1 && __utac_acc__AddressBookEncrypt_spec__1_#t~ret87#1 <= 2147483647;__utac_acc__AddressBookEncrypt_spec__1_~tmp~20#1 := __utac_acc__AddressBookEncrypt_spec__1_#t~ret87#1;havoc __utac_acc__AddressBookEncrypt_spec__1_#t~ret87#1; {5439#false} is VALID [2022-02-20 17:56:04,383 INFO L290 TraceCheckUtils]: 109: Hoare triple {5439#false} assume ~mail_is_sensitive~0 != __utac_acc__AddressBookEncrypt_spec__1_~tmp~20#1;assume { :begin_inline___automaton_fail } true; {5439#false} is VALID [2022-02-20 17:56:04,383 INFO L290 TraceCheckUtils]: 110: Hoare triple {5439#false} assume !false; {5439#false} is VALID [2022-02-20 17:56:04,384 INFO L134 CoverageAnalysis]: Checked inductivity of 30 backedges. 3 proven. 3 refuted. 0 times theorem prover too weak. 24 trivial. 0 not checked. [2022-02-20 17:56:04,384 INFO L144 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2022-02-20 17:56:04,385 INFO L338 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [524105579] [2022-02-20 17:56:04,385 INFO L165 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [524105579] provided 0 perfect and 1 imperfect interpolant sequences [2022-02-20 17:56:04,385 INFO L338 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleZ3 [1788630232] [2022-02-20 17:56:04,385 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-02-20 17:56:04,385 INFO L173 SolverBuilder]: Constructing external solver with command: z3 -smt2 -in SMTLIB2_COMPLIANT=true [2022-02-20 17:56:04,385 INFO L189 MonitoredProcess]: No working directory specified, using /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 [2022-02-20 17:56:04,386 INFO L229 MonitoredProcess]: Starting monitored process 4 with /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 -smt2 -in SMTLIB2_COMPLIANT=true (exit command is (exit), workingDir is null) [2022-02-20 17:56:04,418 INFO L327 MonitoredProcess]: [MP /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 -smt2 -in SMTLIB2_COMPLIANT=true (4)] Waiting until timeout for monitored process [2022-02-20 17:56:04,606 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-02-20 17:56:04,610 INFO L263 TraceCheckSpWp]: Trace formula consists of 1083 conjuncts, 3 conjunts are in the unsatisfiable core [2022-02-20 17:56:04,647 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-02-20 17:56:04,649 INFO L286 TraceCheckSpWp]: Computing forward predicates... [2022-02-20 17:56:04,838 INFO L290 TraceCheckUtils]: 0: Hoare triple {5438#true} assume { :begin_inline_ULTIMATE.init } true;#NULL.base, #NULL.offset := 0, 0;assume 0 == #valid[0];assume 0 < #StackHeapBarrier;call #Ultimate.allocInit(2, 1);call write~init~int(48, 1, 0, 1);call write~init~int(0, 1, 1, 1);call #Ultimate.allocInit(28, 2);call #Ultimate.allocInit(12, 3);call #Ultimate.allocInit(4, 4);call write~init~int(37, 4, 0, 1);call write~init~int(115, 4, 1, 1);call write~init~int(10, 4, 2, 1);call write~init~int(0, 4, 3, 1);call #Ultimate.allocInit(10, 5);call #Ultimate.allocInit(12, 6);call #Ultimate.allocInit(10, 7);call #Ultimate.allocInit(18, 8);call #Ultimate.allocInit(16, 9);call #Ultimate.allocInit(21, 10);call #Ultimate.allocInit(13, 11);call #Ultimate.allocInit(16, 12);call #Ultimate.allocInit(25, 13);call #Ultimate.allocInit(30, 14);call #Ultimate.allocInit(9, 15);call #Ultimate.allocInit(21, 16);call #Ultimate.allocInit(30, 17);call #Ultimate.allocInit(9, 18);call #Ultimate.allocInit(21, 19);call #Ultimate.allocInit(30, 20);call #Ultimate.allocInit(9, 21);call #Ultimate.allocInit(25, 22);call #Ultimate.allocInit(30, 23);call #Ultimate.allocInit(9, 24);call #Ultimate.allocInit(25, 25);call #Ultimate.allocInit(10, 26);call #Ultimate.allocInit(16, 27);call #Ultimate.allocInit(20, 28);call #Ultimate.allocInit(22, 29);call #Ultimate.allocInit(21, 30);call #Ultimate.allocInit(13, 31);call #Ultimate.allocInit(44, 32);call #Ultimate.allocInit(44, 33);call #Ultimate.allocInit(9, 34);call #Ultimate.allocInit(9, 35);call #Ultimate.allocInit(11, 36);call #Ultimate.allocInit(19, 37);call #Ultimate.allocInit(4, 38);call write~init~int(37, 38, 0, 1);call write~init~int(100, 38, 1, 1);call write~init~int(10, 38, 2, 1);call write~init~int(0, 38, 3, 1);call #Ultimate.allocInit(4, 39);call write~init~int(37, 39, 0, 1);call write~init~int(100, 39, 1, 1);call write~init~int(10, 39, 2, 1);call write~init~int(0, 39, 3, 1);~__SELECTED_FEATURE_Base~0 := 0;~__SELECTED_FEATURE_Keys~0 := 0;~__SELECTED_FEATURE_Encrypt~0 := 0;~__SELECTED_FEATURE_AutoResponder~0 := 0;~__SELECTED_FEATURE_AddressBook~0 := 0;~__SELECTED_FEATURE_Sign~0 := 0;~__SELECTED_FEATURE_Forward~0 := 0;~__SELECTED_FEATURE_Verify~0 := 0;~__SELECTED_FEATURE_Decrypt~0 := 0;~__GUIDSL_ROOT_PRODUCTION~0 := 0;~__GUIDSL_NON_TERMINAL_main~0 := 0;~head~0.base, ~head~0.offset := 0, 0;~queue_empty~0 := 1;~queued_message~0 := 0;~queued_client~0 := 0;~mail_is_sensitive~0 := -1;~__ste_Client_counter~0 := 0;~__ste_client_name0~0.base, ~__ste_client_name0~0.offset := 0, 0;~__ste_client_name1~0.base, ~__ste_client_name1~0.offset := 0, 0;~__ste_client_name2~0.base, ~__ste_client_name2~0.offset := 0, 0;~__ste_client_outbuffer0~0 := 0;~__ste_client_outbuffer1~0 := 0;~__ste_client_outbuffer2~0 := 0;~__ste_client_outbuffer3~0 := 0;~__ste_ClientAddressBook_size0~0 := 0;~__ste_ClientAddressBook_size1~0 := 0;~__ste_ClientAddressBook_size2~0 := 0;~__ste_Client_AddressBook0_Alias0~0 := 0;~__ste_Client_AddressBook0_Alias1~0 := 0;~__ste_Client_AddressBook0_Alias2~0 := 0;~__ste_Client_AddressBook1_Alias0~0 := 0;~__ste_Client_AddressBook1_Alias1~0 := 0;~__ste_Client_AddressBook1_Alias2~0 := 0;~__ste_Client_AddressBook2_Alias0~0 := 0;~__ste_Client_AddressBook2_Alias1~0 := 0;~__ste_Client_AddressBook2_Alias2~0 := 0;~__ste_Client_AddressBook0_Address0~0 := 0;~__ste_Client_AddressBook0_Address1~0 := 0;~__ste_Client_AddressBook0_Address2~0 := 0;~__ste_Client_AddressBook1_Address0~0 := 0;~__ste_Client_AddressBook1_Address1~0 := 0;~__ste_Client_AddressBook1_Address2~0 := 0;~__ste_Client_AddressBook2_Address0~0 := 0;~__ste_Client_AddressBook2_Address1~0 := 0;~__ste_Client_AddressBook2_Address2~0 := 0;~__ste_client_autoResponse0~0 := 0;~__ste_client_autoResponse1~0 := 0;~__ste_client_autoResponse2~0 := 0;~__ste_client_privateKey0~0 := 0;~__ste_client_privateKey1~0 := 0;~__ste_client_privateKey2~0 := 0;~__ste_ClientKeyring_size0~0 := 0;~__ste_ClientKeyring_size1~0 := 0;~__ste_ClientKeyring_size2~0 := 0;~__ste_Client_Keyring0_User0~0 := 0;~__ste_Client_Keyring0_User1~0 := 0;~__ste_Client_Keyring0_User2~0 := 0;~__ste_Client_Keyring1_User0~0 := 0;~__ste_Client_Keyring1_User1~0 := 0;~__ste_Client_Keyring1_User2~0 := 0;~__ste_Client_Keyring2_User0~0 := 0;~__ste_Client_Keyring2_User1~0 := 0;~__ste_Client_Keyring2_User2~0 := 0;~__ste_Client_Keyring0_PublicKey0~0 := 0;~__ste_Client_Keyring0_PublicKey1~0 := 0;~__ste_Client_Keyring0_PublicKey2~0 := 0;~__ste_Client_Keyring1_PublicKey0~0 := 0;~__ste_Client_Keyring1_PublicKey1~0 := 0;~__ste_Client_Keyring1_PublicKey2~0 := 0;~__ste_Client_Keyring2_PublicKey0~0 := 0;~__ste_Client_Keyring2_PublicKey1~0 := 0;~__ste_Client_Keyring2_PublicKey2~0 := 0;~__ste_client_forwardReceiver0~0 := 0;~__ste_client_forwardReceiver1~0 := 0;~__ste_client_forwardReceiver2~0 := 0;~__ste_client_forwardReceiver3~0 := 0;~__ste_client_idCounter0~0 := 0;~__ste_client_idCounter1~0 := 0;~__ste_client_idCounter2~0 := 0;~bob~0 := 0;~rjh~0 := 0;~chuck~0 := 0;~__ste_Email_counter~0 := 0;~__ste_email_id0~0 := 0;~__ste_email_id1~0 := 0;~__ste_email_from0~0 := 0;~__ste_email_from1~0 := 0;~__ste_email_to0~0 := 0;~__ste_email_to1~0 := 0;~__ste_email_subject0~0.base, ~__ste_email_subject0~0.offset := 0, 0;~__ste_email_subject1~0.base, ~__ste_email_subject1~0.offset := 0, 0;~__ste_email_body0~0.base, ~__ste_email_body0~0.offset := 0, 0;~__ste_email_body1~0.base, ~__ste_email_body1~0.offset := 0, 0;~__ste_email_isEncrypted0~0 := 0;~__ste_email_isEncrypted1~0 := 0;~__ste_email_encryptionKey0~0 := 0;~__ste_email_encryptionKey1~0 := 0;~__ste_email_isSigned0~0 := 0;~__ste_email_isSigned1~0 := 0;~__ste_email_signKey0~0 := 0;~__ste_email_signKey1~0 := 0;~__ste_email_isSignatureVerified0~0 := 0;~__ste_email_isSignatureVerified1~0 := 0; {5438#true} is VALID [2022-02-20 17:56:04,838 INFO L290 TraceCheckUtils]: 1: Hoare triple {5438#true} assume { :end_inline_ULTIMATE.init } true;assume { :begin_inline_main } true;havoc main_#res#1;havoc main_#t~ret98#1, main_~retValue_acc~32#1, main_~tmp~24#1;havoc main_~retValue_acc~32#1;havoc main_~tmp~24#1;assume { :begin_inline_select_helpers } true; {5438#true} is VALID [2022-02-20 17:56:04,838 INFO L290 TraceCheckUtils]: 2: Hoare triple {5438#true} assume { :end_inline_select_helpers } true;assume { :begin_inline_select_features } true; {5438#true} is VALID [2022-02-20 17:56:04,838 INFO L290 TraceCheckUtils]: 3: Hoare triple {5438#true} assume { :end_inline_select_features } true;assume { :begin_inline_valid_product } true;havoc valid_product_#res#1;havoc valid_product_~retValue_acc~9#1;havoc valid_product_~retValue_acc~9#1;valid_product_~retValue_acc~9#1 := 1;valid_product_#res#1 := valid_product_~retValue_acc~9#1; {5438#true} is VALID [2022-02-20 17:56:04,838 INFO L290 TraceCheckUtils]: 4: Hoare triple {5438#true} main_#t~ret98#1 := valid_product_#res#1;assume { :end_inline_valid_product } true;assume -2147483648 <= main_#t~ret98#1 && main_#t~ret98#1 <= 2147483647;main_~tmp~24#1 := main_#t~ret98#1;havoc main_#t~ret98#1; {5438#true} is VALID [2022-02-20 17:56:04,838 INFO L290 TraceCheckUtils]: 5: Hoare triple {5438#true} assume 0 != main_~tmp~24#1;assume { :begin_inline_setup } true;havoc setup_#t~nondet95#1, setup_#t~nondet96#1, setup_#t~nondet97#1, setup_~__cil_tmp1~0#1.base, setup_~__cil_tmp1~0#1.offset, setup_~__cil_tmp2~0#1.base, setup_~__cil_tmp2~0#1.offset, setup_~__cil_tmp3~2#1.base, setup_~__cil_tmp3~2#1.offset;havoc setup_~__cil_tmp1~0#1.base, setup_~__cil_tmp1~0#1.offset;havoc setup_~__cil_tmp2~0#1.base, setup_~__cil_tmp2~0#1.offset;havoc setup_~__cil_tmp3~2#1.base, setup_~__cil_tmp3~2#1.offset;~bob~0 := 1;assume { :begin_inline_setup_bob } true;setup_bob_#in~bob___0#1 := ~bob~0;havoc setup_bob_~bob___0#1;setup_bob_~bob___0#1 := setup_bob_#in~bob___0#1;assume { :begin_inline_setup_bob__wrappee__Base } true;setup_bob__wrappee__Base_#in~bob___0#1 := setup_bob_~bob___0#1;havoc setup_bob__wrappee__Base_~bob___0#1;setup_bob__wrappee__Base_~bob___0#1 := setup_bob__wrappee__Base_#in~bob___0#1; {5438#true} is VALID [2022-02-20 17:56:04,838 INFO L272 TraceCheckUtils]: 6: Hoare triple {5438#true} call setClientId(setup_bob__wrappee__Base_~bob___0#1, setup_bob__wrappee__Base_~bob___0#1); {5438#true} is VALID [2022-02-20 17:56:04,838 INFO L290 TraceCheckUtils]: 7: Hoare triple {5438#true} ~handle := #in~handle;~value := #in~value; {5438#true} is VALID [2022-02-20 17:56:04,838 INFO L290 TraceCheckUtils]: 8: Hoare triple {5438#true} assume 1 == ~handle;~__ste_client_idCounter0~0 := ~value; {5438#true} is VALID [2022-02-20 17:56:04,838 INFO L290 TraceCheckUtils]: 9: Hoare triple {5438#true} assume true; {5438#true} is VALID [2022-02-20 17:56:04,838 INFO L284 TraceCheckUtils]: 10: Hoare quadruple {5438#true} {5438#true} #1133#return; {5438#true} is VALID [2022-02-20 17:56:04,839 INFO L290 TraceCheckUtils]: 11: Hoare triple {5438#true} assume { :end_inline_setup_bob__wrappee__Base } true; {5438#true} is VALID [2022-02-20 17:56:04,839 INFO L272 TraceCheckUtils]: 12: Hoare triple {5438#true} call setClientPrivateKey(setup_bob_~bob___0#1, 123); {5438#true} is VALID [2022-02-20 17:56:04,839 INFO L290 TraceCheckUtils]: 13: Hoare triple {5438#true} ~handle := #in~handle;~value := #in~value; {5438#true} is VALID [2022-02-20 17:56:04,839 INFO L290 TraceCheckUtils]: 14: Hoare triple {5438#true} assume 1 == ~handle;~__ste_client_privateKey0~0 := ~value; {5438#true} is VALID [2022-02-20 17:56:04,839 INFO L290 TraceCheckUtils]: 15: Hoare triple {5438#true} assume true; {5438#true} is VALID [2022-02-20 17:56:04,839 INFO L284 TraceCheckUtils]: 16: Hoare quadruple {5438#true} {5438#true} #1135#return; {5438#true} is VALID [2022-02-20 17:56:04,839 INFO L290 TraceCheckUtils]: 17: Hoare triple {5438#true} assume { :end_inline_setup_bob } true;setup_~__cil_tmp1~0#1.base, setup_~__cil_tmp1~0#1.offset := 34, 0;havoc setup_#t~nondet95#1;~rjh~0 := 2;assume { :begin_inline_setup_rjh } true;setup_rjh_#in~rjh___0#1 := ~rjh~0;havoc setup_rjh_~rjh___0#1;setup_rjh_~rjh___0#1 := setup_rjh_#in~rjh___0#1;assume { :begin_inline_setup_rjh__wrappee__Base } true;setup_rjh__wrappee__Base_#in~rjh___0#1 := setup_rjh_~rjh___0#1;havoc setup_rjh__wrappee__Base_~rjh___0#1;setup_rjh__wrappee__Base_~rjh___0#1 := setup_rjh__wrappee__Base_#in~rjh___0#1; {5438#true} is VALID [2022-02-20 17:56:04,839 INFO L272 TraceCheckUtils]: 18: Hoare triple {5438#true} call setClientId(setup_rjh__wrappee__Base_~rjh___0#1, setup_rjh__wrappee__Base_~rjh___0#1); {5438#true} is VALID [2022-02-20 17:56:04,839 INFO L290 TraceCheckUtils]: 19: Hoare triple {5438#true} ~handle := #in~handle;~value := #in~value; {5438#true} is VALID [2022-02-20 17:56:04,839 INFO L290 TraceCheckUtils]: 20: Hoare triple {5438#true} assume 1 == ~handle;~__ste_client_idCounter0~0 := ~value; {5438#true} is VALID [2022-02-20 17:56:04,839 INFO L290 TraceCheckUtils]: 21: Hoare triple {5438#true} assume true; {5438#true} is VALID [2022-02-20 17:56:04,839 INFO L284 TraceCheckUtils]: 22: Hoare quadruple {5438#true} {5438#true} #1137#return; {5438#true} is VALID [2022-02-20 17:56:04,839 INFO L290 TraceCheckUtils]: 23: Hoare triple {5438#true} assume { :end_inline_setup_rjh__wrappee__Base } true; {5438#true} is VALID [2022-02-20 17:56:04,839 INFO L272 TraceCheckUtils]: 24: Hoare triple {5438#true} call setClientPrivateKey(setup_rjh_~rjh___0#1, 456); {5438#true} is VALID [2022-02-20 17:56:04,839 INFO L290 TraceCheckUtils]: 25: Hoare triple {5438#true} ~handle := #in~handle;~value := #in~value; {5438#true} is VALID [2022-02-20 17:56:04,839 INFO L290 TraceCheckUtils]: 26: Hoare triple {5438#true} assume 1 == ~handle;~__ste_client_privateKey0~0 := ~value; {5438#true} is VALID [2022-02-20 17:56:04,839 INFO L290 TraceCheckUtils]: 27: Hoare triple {5438#true} assume true; {5438#true} is VALID [2022-02-20 17:56:04,839 INFO L284 TraceCheckUtils]: 28: Hoare quadruple {5438#true} {5438#true} #1139#return; {5438#true} is VALID [2022-02-20 17:56:04,839 INFO L290 TraceCheckUtils]: 29: Hoare triple {5438#true} assume { :end_inline_setup_rjh } true;setup_~__cil_tmp2~0#1.base, setup_~__cil_tmp2~0#1.offset := 35, 0;havoc setup_#t~nondet96#1;~chuck~0 := 3;assume { :begin_inline_setup_chuck } true;setup_chuck_#in~chuck___0#1 := ~chuck~0;havoc setup_chuck_~chuck___0#1;setup_chuck_~chuck___0#1 := setup_chuck_#in~chuck___0#1;assume { :begin_inline_setup_chuck__wrappee__Base } true;setup_chuck__wrappee__Base_#in~chuck___0#1 := setup_chuck_~chuck___0#1;havoc setup_chuck__wrappee__Base_~chuck___0#1;setup_chuck__wrappee__Base_~chuck___0#1 := setup_chuck__wrappee__Base_#in~chuck___0#1; {5438#true} is VALID [2022-02-20 17:56:04,839 INFO L272 TraceCheckUtils]: 30: Hoare triple {5438#true} call setClientId(setup_chuck__wrappee__Base_~chuck___0#1, setup_chuck__wrappee__Base_~chuck___0#1); {5438#true} is VALID [2022-02-20 17:56:04,839 INFO L290 TraceCheckUtils]: 31: Hoare triple {5438#true} ~handle := #in~handle;~value := #in~value; {5438#true} is VALID [2022-02-20 17:56:04,840 INFO L290 TraceCheckUtils]: 32: Hoare triple {5438#true} assume 1 == ~handle;~__ste_client_idCounter0~0 := ~value; {5438#true} is VALID [2022-02-20 17:56:04,840 INFO L290 TraceCheckUtils]: 33: Hoare triple {5438#true} assume true; {5438#true} is VALID [2022-02-20 17:56:04,840 INFO L284 TraceCheckUtils]: 34: Hoare quadruple {5438#true} {5438#true} #1141#return; {5438#true} is VALID [2022-02-20 17:56:04,840 INFO L290 TraceCheckUtils]: 35: Hoare triple {5438#true} assume { :end_inline_setup_chuck__wrappee__Base } true; {5438#true} is VALID [2022-02-20 17:56:04,840 INFO L272 TraceCheckUtils]: 36: Hoare triple {5438#true} call setClientPrivateKey(setup_chuck_~chuck___0#1, 789); {5438#true} is VALID [2022-02-20 17:56:04,840 INFO L290 TraceCheckUtils]: 37: Hoare triple {5438#true} ~handle := #in~handle;~value := #in~value; {5438#true} is VALID [2022-02-20 17:56:04,840 INFO L290 TraceCheckUtils]: 38: Hoare triple {5438#true} assume 1 == ~handle;~__ste_client_privateKey0~0 := ~value; {5438#true} is VALID [2022-02-20 17:56:04,840 INFO L290 TraceCheckUtils]: 39: Hoare triple {5438#true} assume true; {5438#true} is VALID [2022-02-20 17:56:04,840 INFO L284 TraceCheckUtils]: 40: Hoare quadruple {5438#true} {5438#true} #1143#return; {5438#true} is VALID [2022-02-20 17:56:04,840 INFO L290 TraceCheckUtils]: 41: Hoare triple {5438#true} assume { :end_inline_setup_chuck } true;setup_~__cil_tmp3~2#1.base, setup_~__cil_tmp3~2#1.offset := 36, 0;havoc setup_#t~nondet97#1; {5438#true} is VALID [2022-02-20 17:56:04,840 INFO L290 TraceCheckUtils]: 42: Hoare triple {5438#true} assume { :end_inline_setup } true;assume { :begin_inline_test } true;havoc test_#t~nondet48#1, test_#t~nondet49#1, test_#t~nondet50#1, test_#t~nondet51#1, test_#t~nondet52#1, test_#t~nondet53#1, test_#t~nondet54#1, test_#t~nondet55#1, test_#t~nondet56#1, test_#t~nondet57#1, test_#t~nondet58#1, test_~op1~0#1, test_~op2~0#1, test_~op3~0#1, test_~op4~0#1, test_~op5~0#1, test_~op6~0#1, test_~op7~0#1, test_~op8~0#1, test_~op9~0#1, test_~op10~0#1, test_~op11~0#1, test_~splverifierCounter~0#1, test_~tmp~8#1, test_~tmp___0~3#1, test_~tmp___1~1#1, test_~tmp___2~1#1, test_~tmp___3~0#1, test_~tmp___4~0#1, test_~tmp___5~0#1, test_~tmp___6~0#1, test_~tmp___7~0#1, test_~tmp___8~0#1, test_~tmp___9~0#1;havoc test_~op1~0#1;havoc test_~op2~0#1;havoc test_~op3~0#1;havoc test_~op4~0#1;havoc test_~op5~0#1;havoc test_~op6~0#1;havoc test_~op7~0#1;havoc test_~op8~0#1;havoc test_~op9~0#1;havoc test_~op10~0#1;havoc test_~op11~0#1;havoc test_~splverifierCounter~0#1;havoc test_~tmp~8#1;havoc test_~tmp___0~3#1;havoc test_~tmp___1~1#1;havoc test_~tmp___2~1#1;havoc test_~tmp___3~0#1;havoc test_~tmp___4~0#1;havoc test_~tmp___5~0#1;havoc test_~tmp___6~0#1;havoc test_~tmp___7~0#1;havoc test_~tmp___8~0#1;havoc test_~tmp___9~0#1;test_~op1~0#1 := 0;test_~op2~0#1 := 0;test_~op3~0#1 := 0;test_~op4~0#1 := 0;test_~op5~0#1 := 0;test_~op6~0#1 := 0;test_~op7~0#1 := 0;test_~op8~0#1 := 0;test_~op9~0#1 := 0;test_~op10~0#1 := 0;test_~op11~0#1 := 0;test_~splverifierCounter~0#1 := 0; {5629#(= |ULTIMATE.start_test_~op1~0#1| 0)} is VALID [2022-02-20 17:56:04,847 INFO L290 TraceCheckUtils]: 43: Hoare triple {5629#(= |ULTIMATE.start_test_~op1~0#1| 0)} assume !false; {5629#(= |ULTIMATE.start_test_~op1~0#1| 0)} is VALID [2022-02-20 17:56:04,847 INFO L290 TraceCheckUtils]: 44: Hoare triple {5629#(= |ULTIMATE.start_test_~op1~0#1| 0)} assume test_~splverifierCounter~0#1 < 4; {5629#(= |ULTIMATE.start_test_~op1~0#1| 0)} is VALID [2022-02-20 17:56:04,848 INFO L290 TraceCheckUtils]: 45: Hoare triple {5629#(= |ULTIMATE.start_test_~op1~0#1| 0)} test_~splverifierCounter~0#1 := 1 + test_~splverifierCounter~0#1; {5629#(= |ULTIMATE.start_test_~op1~0#1| 0)} is VALID [2022-02-20 17:56:04,848 INFO L290 TraceCheckUtils]: 46: Hoare triple {5629#(= |ULTIMATE.start_test_~op1~0#1| 0)} assume !(0 == test_~op1~0#1); {5439#false} is VALID [2022-02-20 17:56:04,848 INFO L290 TraceCheckUtils]: 47: Hoare triple {5439#false} assume 0 == test_~op2~0#1;assume -2147483648 <= test_#t~nondet49#1 && test_#t~nondet49#1 <= 2147483647;test_~tmp___8~0#1 := test_#t~nondet49#1;havoc test_#t~nondet49#1; {5439#false} is VALID [2022-02-20 17:56:04,848 INFO L290 TraceCheckUtils]: 48: Hoare triple {5439#false} assume 0 != test_~tmp___8~0#1;assume { :begin_inline_rjhSetAutoRespond } true;assume { :begin_inline_setClientAutoResponse } true;setClientAutoResponse_#in~handle#1, setClientAutoResponse_#in~value#1 := ~rjh~0, 1;havoc setClientAutoResponse_~handle#1, setClientAutoResponse_~value#1;setClientAutoResponse_~handle#1 := setClientAutoResponse_#in~handle#1;setClientAutoResponse_~value#1 := setClientAutoResponse_#in~value#1; {5439#false} is VALID [2022-02-20 17:56:04,848 INFO L290 TraceCheckUtils]: 49: Hoare triple {5439#false} assume 1 == setClientAutoResponse_~handle#1;~__ste_client_autoResponse0~0 := setClientAutoResponse_~value#1; {5439#false} is VALID [2022-02-20 17:56:04,848 INFO L290 TraceCheckUtils]: 50: Hoare triple {5439#false} assume { :end_inline_setClientAutoResponse } true; {5439#false} is VALID [2022-02-20 17:56:04,848 INFO L290 TraceCheckUtils]: 51: Hoare triple {5439#false} assume { :end_inline_rjhSetAutoRespond } true;test_~op2~0#1 := 1; {5439#false} is VALID [2022-02-20 17:56:04,848 INFO L290 TraceCheckUtils]: 52: Hoare triple {5439#false} assume !false; {5439#false} is VALID [2022-02-20 17:56:04,848 INFO L290 TraceCheckUtils]: 53: Hoare triple {5439#false} assume !(test_~splverifierCounter~0#1 < 4); {5439#false} is VALID [2022-02-20 17:56:04,848 INFO L290 TraceCheckUtils]: 54: Hoare triple {5439#false} assume { :begin_inline_bobToRjh } true;havoc bobToRjh_#t~ret90#1, bobToRjh_#t~ret91#1, bobToRjh_#t~ret92#1, bobToRjh_#t~ret93#1, bobToRjh_~tmp~23#1, bobToRjh_~tmp___0~7#1, bobToRjh_~tmp___1~4#1;havoc bobToRjh_~tmp~23#1;havoc bobToRjh_~tmp___0~7#1;havoc bobToRjh_~tmp___1~4#1;call bobToRjh_#t~ret90#1 := puts(32, 0);assume -2147483648 <= bobToRjh_#t~ret90#1 && bobToRjh_#t~ret90#1 <= 2147483647;havoc bobToRjh_#t~ret90#1; {5439#false} is VALID [2022-02-20 17:56:04,848 INFO L272 TraceCheckUtils]: 55: Hoare triple {5439#false} call sendEmail(~bob~0, ~rjh~0); {5439#false} is VALID [2022-02-20 17:56:04,848 INFO L290 TraceCheckUtils]: 56: Hoare triple {5439#false} ~sender#1 := #in~sender#1;~receiver#1 := #in~receiver#1;havoc ~email~0#1;havoc ~tmp~16#1;assume { :begin_inline_createEmail } true;createEmail_#in~from#1, createEmail_#in~to#1 := 0, ~receiver#1;havoc createEmail_#res#1;havoc createEmail_~from#1, createEmail_~to#1, createEmail_~retValue_acc~4#1, createEmail_~msg~0#1;createEmail_~from#1 := createEmail_#in~from#1;createEmail_~to#1 := createEmail_#in~to#1;havoc createEmail_~retValue_acc~4#1;havoc createEmail_~msg~0#1;createEmail_~msg~0#1 := 1; {5439#false} is VALID [2022-02-20 17:56:04,849 INFO L272 TraceCheckUtils]: 57: Hoare triple {5439#false} call setEmailFrom(createEmail_~msg~0#1, createEmail_~from#1); {5439#false} is VALID [2022-02-20 17:56:04,849 INFO L290 TraceCheckUtils]: 58: Hoare triple {5439#false} ~handle := #in~handle;~value := #in~value; {5439#false} is VALID [2022-02-20 17:56:04,849 INFO L290 TraceCheckUtils]: 59: Hoare triple {5439#false} assume 1 == ~handle;~__ste_email_from0~0 := ~value; {5439#false} is VALID [2022-02-20 17:56:04,849 INFO L290 TraceCheckUtils]: 60: Hoare triple {5439#false} assume true; {5439#false} is VALID [2022-02-20 17:56:04,849 INFO L284 TraceCheckUtils]: 61: Hoare quadruple {5439#false} {5439#false} #1119#return; {5439#false} is VALID [2022-02-20 17:56:04,849 INFO L272 TraceCheckUtils]: 62: Hoare triple {5439#false} call setEmailTo(createEmail_~msg~0#1, createEmail_~to#1); {5439#false} is VALID [2022-02-20 17:56:04,849 INFO L290 TraceCheckUtils]: 63: Hoare triple {5439#false} ~handle := #in~handle;~value := #in~value; {5439#false} is VALID [2022-02-20 17:56:04,849 INFO L290 TraceCheckUtils]: 64: Hoare triple {5439#false} assume 1 == ~handle;~__ste_email_to0~0 := ~value; {5439#false} is VALID [2022-02-20 17:56:04,849 INFO L290 TraceCheckUtils]: 65: Hoare triple {5439#false} assume true; {5439#false} is VALID [2022-02-20 17:56:04,849 INFO L284 TraceCheckUtils]: 66: Hoare quadruple {5439#false} {5439#false} #1121#return; {5439#false} is VALID [2022-02-20 17:56:04,849 INFO L290 TraceCheckUtils]: 67: Hoare triple {5439#false} createEmail_~retValue_acc~4#1 := createEmail_~msg~0#1;createEmail_#res#1 := createEmail_~retValue_acc~4#1; {5439#false} is VALID [2022-02-20 17:56:04,849 INFO L290 TraceCheckUtils]: 68: Hoare triple {5439#false} #t~ret73#1 := createEmail_#res#1;assume { :end_inline_createEmail } true;assume -2147483648 <= #t~ret73#1 && #t~ret73#1 <= 2147483647;~tmp~16#1 := #t~ret73#1;havoc #t~ret73#1;~email~0#1 := ~tmp~16#1; {5439#false} is VALID [2022-02-20 17:56:04,849 INFO L272 TraceCheckUtils]: 69: Hoare triple {5439#false} call outgoing(~sender#1, ~email~0#1); {5439#false} is VALID [2022-02-20 17:56:04,849 INFO L290 TraceCheckUtils]: 70: Hoare triple {5439#false} ~client#1 := #in~client#1;~msg#1 := #in~msg#1;assume { :begin_inline_sign } true;sign_#in~client#1, sign_#in~msg#1 := ~client#1, ~msg#1;havoc sign_#t~ret77#1, sign_~client#1, sign_~msg#1, sign_~privkey~1#1, sign_~tmp~18#1;sign_~client#1 := sign_#in~client#1;sign_~msg#1 := sign_#in~msg#1;havoc sign_~privkey~1#1;havoc sign_~tmp~18#1; {5439#false} is VALID [2022-02-20 17:56:04,849 INFO L272 TraceCheckUtils]: 71: Hoare triple {5439#false} call sign_#t~ret77#1 := getClientPrivateKey(sign_~client#1); {5439#false} is VALID [2022-02-20 17:56:04,849 INFO L290 TraceCheckUtils]: 72: Hoare triple {5439#false} ~handle := #in~handle;havoc ~retValue_acc~24; {5439#false} is VALID [2022-02-20 17:56:04,849 INFO L290 TraceCheckUtils]: 73: Hoare triple {5439#false} assume 1 == ~handle;~retValue_acc~24 := ~__ste_client_privateKey0~0;#res := ~retValue_acc~24; {5439#false} is VALID [2022-02-20 17:56:04,849 INFO L290 TraceCheckUtils]: 74: Hoare triple {5439#false} assume true; {5439#false} is VALID [2022-02-20 17:56:04,849 INFO L284 TraceCheckUtils]: 75: Hoare quadruple {5439#false} {5439#false} #1053#return; {5439#false} is VALID [2022-02-20 17:56:04,849 INFO L290 TraceCheckUtils]: 76: Hoare triple {5439#false} assume -2147483648 <= sign_#t~ret77#1 && sign_#t~ret77#1 <= 2147483647;sign_~tmp~18#1 := sign_#t~ret77#1;havoc sign_#t~ret77#1;sign_~privkey~1#1 := sign_~tmp~18#1; {5439#false} is VALID [2022-02-20 17:56:04,850 INFO L290 TraceCheckUtils]: 77: Hoare triple {5439#false} assume 0 == sign_~privkey~1#1; {5439#false} is VALID [2022-02-20 17:56:04,850 INFO L290 TraceCheckUtils]: 78: Hoare triple {5439#false} assume { :end_inline_sign } true;assume { :begin_inline_outgoing__wrappee__AutoResponder } true;outgoing__wrappee__AutoResponder_#in~client#1, outgoing__wrappee__AutoResponder_#in~msg#1 := ~client#1, ~msg#1;havoc outgoing__wrappee__AutoResponder_#t~ret63#1, outgoing__wrappee__AutoResponder_#t~ret64#1, outgoing__wrappee__AutoResponder_~client#1, outgoing__wrappee__AutoResponder_~msg#1, outgoing__wrappee__AutoResponder_~receiver~0#1, outgoing__wrappee__AutoResponder_~tmp~11#1, outgoing__wrappee__AutoResponder_~pubkey~0#1, outgoing__wrappee__AutoResponder_~tmp___0~4#1;outgoing__wrappee__AutoResponder_~client#1 := outgoing__wrappee__AutoResponder_#in~client#1;outgoing__wrappee__AutoResponder_~msg#1 := outgoing__wrappee__AutoResponder_#in~msg#1;havoc outgoing__wrappee__AutoResponder_~receiver~0#1;havoc outgoing__wrappee__AutoResponder_~tmp~11#1;havoc outgoing__wrappee__AutoResponder_~pubkey~0#1;havoc outgoing__wrappee__AutoResponder_~tmp___0~4#1; {5439#false} is VALID [2022-02-20 17:56:04,850 INFO L272 TraceCheckUtils]: 79: Hoare triple {5439#false} call outgoing__wrappee__AutoResponder_#t~ret63#1 := getEmailTo(outgoing__wrappee__AutoResponder_~msg#1); {5439#false} is VALID [2022-02-20 17:56:04,850 INFO L290 TraceCheckUtils]: 80: Hoare triple {5439#false} ~handle := #in~handle;havoc ~retValue_acc~36; {5439#false} is VALID [2022-02-20 17:56:04,850 INFO L290 TraceCheckUtils]: 81: Hoare triple {5439#false} assume 1 == ~handle;~retValue_acc~36 := ~__ste_email_to0~0;#res := ~retValue_acc~36; {5439#false} is VALID [2022-02-20 17:56:04,850 INFO L290 TraceCheckUtils]: 82: Hoare triple {5439#false} assume true; {5439#false} is VALID [2022-02-20 17:56:04,850 INFO L284 TraceCheckUtils]: 83: Hoare quadruple {5439#false} {5439#false} #1055#return; {5439#false} is VALID [2022-02-20 17:56:04,850 INFO L290 TraceCheckUtils]: 84: Hoare triple {5439#false} assume -2147483648 <= outgoing__wrappee__AutoResponder_#t~ret63#1 && outgoing__wrappee__AutoResponder_#t~ret63#1 <= 2147483647;outgoing__wrappee__AutoResponder_~tmp~11#1 := outgoing__wrappee__AutoResponder_#t~ret63#1;havoc outgoing__wrappee__AutoResponder_#t~ret63#1;outgoing__wrappee__AutoResponder_~receiver~0#1 := outgoing__wrappee__AutoResponder_~tmp~11#1; {5439#false} is VALID [2022-02-20 17:56:04,850 INFO L272 TraceCheckUtils]: 85: Hoare triple {5439#false} call outgoing__wrappee__AutoResponder_#t~ret64#1 := findPublicKey(outgoing__wrappee__AutoResponder_~client#1, outgoing__wrappee__AutoResponder_~receiver~0#1); {5439#false} is VALID [2022-02-20 17:56:04,850 INFO L290 TraceCheckUtils]: 86: Hoare triple {5439#false} ~handle := #in~handle;~userid := #in~userid;havoc ~retValue_acc~29; {5439#false} is VALID [2022-02-20 17:56:04,850 INFO L290 TraceCheckUtils]: 87: Hoare triple {5439#false} assume 1 == ~handle; {5439#false} is VALID [2022-02-20 17:56:04,850 INFO L290 TraceCheckUtils]: 88: Hoare triple {5439#false} assume ~userid == ~__ste_Client_Keyring0_User0~0;~retValue_acc~29 := ~__ste_Client_Keyring0_PublicKey0~0;#res := ~retValue_acc~29; {5439#false} is VALID [2022-02-20 17:56:04,850 INFO L290 TraceCheckUtils]: 89: Hoare triple {5439#false} assume true; {5439#false} is VALID [2022-02-20 17:56:04,850 INFO L284 TraceCheckUtils]: 90: Hoare quadruple {5439#false} {5439#false} #1057#return; {5439#false} is VALID [2022-02-20 17:56:04,850 INFO L290 TraceCheckUtils]: 91: Hoare triple {5439#false} assume -2147483648 <= outgoing__wrappee__AutoResponder_#t~ret64#1 && outgoing__wrappee__AutoResponder_#t~ret64#1 <= 2147483647;outgoing__wrappee__AutoResponder_~tmp___0~4#1 := outgoing__wrappee__AutoResponder_#t~ret64#1;havoc outgoing__wrappee__AutoResponder_#t~ret64#1;outgoing__wrappee__AutoResponder_~pubkey~0#1 := outgoing__wrappee__AutoResponder_~tmp___0~4#1; {5439#false} is VALID [2022-02-20 17:56:04,850 INFO L290 TraceCheckUtils]: 92: Hoare triple {5439#false} assume !(0 != outgoing__wrappee__AutoResponder_~pubkey~0#1); {5439#false} is VALID [2022-02-20 17:56:04,850 INFO L290 TraceCheckUtils]: 93: Hoare triple {5439#false} assume { :begin_inline_outgoing__wrappee__Keys } true;outgoing__wrappee__Keys_#in~client#1, outgoing__wrappee__Keys_#in~msg#1 := outgoing__wrappee__AutoResponder_~client#1, outgoing__wrappee__AutoResponder_~msg#1;havoc outgoing__wrappee__Keys_#t~ret62#1, outgoing__wrappee__Keys_~client#1, outgoing__wrappee__Keys_~msg#1, outgoing__wrappee__Keys_~tmp~10#1;outgoing__wrappee__Keys_~client#1 := outgoing__wrappee__Keys_#in~client#1;outgoing__wrappee__Keys_~msg#1 := outgoing__wrappee__Keys_#in~msg#1;havoc outgoing__wrappee__Keys_~tmp~10#1;assume { :begin_inline_getClientId } true;getClientId_#in~handle#1 := outgoing__wrappee__Keys_~client#1;havoc getClientId_#res#1;havoc getClientId_~handle#1, getClientId_~retValue_acc~31#1;getClientId_~handle#1 := getClientId_#in~handle#1;havoc getClientId_~retValue_acc~31#1; {5439#false} is VALID [2022-02-20 17:56:04,850 INFO L290 TraceCheckUtils]: 94: Hoare triple {5439#false} assume 1 == getClientId_~handle#1;getClientId_~retValue_acc~31#1 := ~__ste_client_idCounter0~0;getClientId_#res#1 := getClientId_~retValue_acc~31#1; {5439#false} is VALID [2022-02-20 17:56:04,850 INFO L290 TraceCheckUtils]: 95: Hoare triple {5439#false} outgoing__wrappee__Keys_#t~ret62#1 := getClientId_#res#1;assume { :end_inline_getClientId } true;assume -2147483648 <= outgoing__wrappee__Keys_#t~ret62#1 && outgoing__wrappee__Keys_#t~ret62#1 <= 2147483647;outgoing__wrappee__Keys_~tmp~10#1 := outgoing__wrappee__Keys_#t~ret62#1;havoc outgoing__wrappee__Keys_#t~ret62#1; {5439#false} is VALID [2022-02-20 17:56:04,850 INFO L272 TraceCheckUtils]: 96: Hoare triple {5439#false} call setEmailFrom(outgoing__wrappee__Keys_~msg#1, outgoing__wrappee__Keys_~tmp~10#1); {5439#false} is VALID [2022-02-20 17:56:04,850 INFO L290 TraceCheckUtils]: 97: Hoare triple {5439#false} ~handle := #in~handle;~value := #in~value; {5439#false} is VALID [2022-02-20 17:56:04,851 INFO L290 TraceCheckUtils]: 98: Hoare triple {5439#false} assume 1 == ~handle;~__ste_email_from0~0 := ~value; {5439#false} is VALID [2022-02-20 17:56:04,851 INFO L290 TraceCheckUtils]: 99: Hoare triple {5439#false} assume true; {5439#false} is VALID [2022-02-20 17:56:04,851 INFO L284 TraceCheckUtils]: 100: Hoare quadruple {5439#false} {5439#false} #1063#return; {5439#false} is VALID [2022-02-20 17:56:04,851 INFO L290 TraceCheckUtils]: 101: Hoare triple {5439#false} assume { :begin_inline_mail } true;mail_#in~client#1, mail_#in~msg#1 := outgoing__wrappee__Keys_~client#1, outgoing__wrappee__Keys_~msg#1;havoc mail_#t~ret60#1, mail_#t~ret61#1, mail_~client#1, mail_~msg#1, mail_~__utac__ad__arg1~0#1, mail_~__utac__ad__arg2~0#1, mail_~tmp~9#1;mail_~client#1 := mail_#in~client#1;mail_~msg#1 := mail_#in~msg#1;havoc mail_~__utac__ad__arg1~0#1;havoc mail_~__utac__ad__arg2~0#1;havoc mail_~tmp~9#1;mail_~__utac__ad__arg1~0#1 := mail_~client#1;mail_~__utac__ad__arg2~0#1 := mail_~msg#1;assume { :begin_inline___utac_acc__AddressBookEncrypt_spec__1 } true;__utac_acc__AddressBookEncrypt_spec__1_#in~client#1, __utac_acc__AddressBookEncrypt_spec__1_#in~msg#1 := mail_~__utac__ad__arg1~0#1, mail_~__utac__ad__arg2~0#1;havoc __utac_acc__AddressBookEncrypt_spec__1_#t~ret85#1, __utac_acc__AddressBookEncrypt_spec__1_#t~ret86#1, __utac_acc__AddressBookEncrypt_spec__1_#t~ret87#1, __utac_acc__AddressBookEncrypt_spec__1_~client#1, __utac_acc__AddressBookEncrypt_spec__1_~msg#1, __utac_acc__AddressBookEncrypt_spec__1_~tmp~20#1;__utac_acc__AddressBookEncrypt_spec__1_~client#1 := __utac_acc__AddressBookEncrypt_spec__1_#in~client#1;__utac_acc__AddressBookEncrypt_spec__1_~msg#1 := __utac_acc__AddressBookEncrypt_spec__1_#in~msg#1;havoc __utac_acc__AddressBookEncrypt_spec__1_~tmp~20#1;call __utac_acc__AddressBookEncrypt_spec__1_#t~ret85#1 := puts(31, 0);assume -2147483648 <= __utac_acc__AddressBookEncrypt_spec__1_#t~ret85#1 && __utac_acc__AddressBookEncrypt_spec__1_#t~ret85#1 <= 2147483647;havoc __utac_acc__AddressBookEncrypt_spec__1_#t~ret85#1; {5439#false} is VALID [2022-02-20 17:56:04,851 INFO L290 TraceCheckUtils]: 102: Hoare triple {5439#false} assume !(-1 == ~mail_is_sensitive~0); {5439#false} is VALID [2022-02-20 17:56:04,851 INFO L272 TraceCheckUtils]: 103: Hoare triple {5439#false} call __utac_acc__AddressBookEncrypt_spec__1_#t~ret87#1 := isEncrypted(__utac_acc__AddressBookEncrypt_spec__1_~msg#1); {5439#false} is VALID [2022-02-20 17:56:04,851 INFO L290 TraceCheckUtils]: 104: Hoare triple {5439#false} ~handle := #in~handle;havoc ~retValue_acc~39; {5439#false} is VALID [2022-02-20 17:56:04,851 INFO L290 TraceCheckUtils]: 105: Hoare triple {5439#false} assume 1 == ~handle;~retValue_acc~39 := ~__ste_email_isEncrypted0~0;#res := ~retValue_acc~39; {5439#false} is VALID [2022-02-20 17:56:04,851 INFO L290 TraceCheckUtils]: 106: Hoare triple {5439#false} assume true; {5439#false} is VALID [2022-02-20 17:56:04,851 INFO L284 TraceCheckUtils]: 107: Hoare quadruple {5439#false} {5439#false} #1067#return; {5439#false} is VALID [2022-02-20 17:56:04,851 INFO L290 TraceCheckUtils]: 108: Hoare triple {5439#false} assume -2147483648 <= __utac_acc__AddressBookEncrypt_spec__1_#t~ret87#1 && __utac_acc__AddressBookEncrypt_spec__1_#t~ret87#1 <= 2147483647;__utac_acc__AddressBookEncrypt_spec__1_~tmp~20#1 := __utac_acc__AddressBookEncrypt_spec__1_#t~ret87#1;havoc __utac_acc__AddressBookEncrypt_spec__1_#t~ret87#1; {5439#false} is VALID [2022-02-20 17:56:04,851 INFO L290 TraceCheckUtils]: 109: Hoare triple {5439#false} assume ~mail_is_sensitive~0 != __utac_acc__AddressBookEncrypt_spec__1_~tmp~20#1;assume { :begin_inline___automaton_fail } true; {5439#false} is VALID [2022-02-20 17:56:04,851 INFO L290 TraceCheckUtils]: 110: Hoare triple {5439#false} assume !false; {5439#false} is VALID [2022-02-20 17:56:04,851 INFO L134 CoverageAnalysis]: Checked inductivity of 30 backedges. 2 proven. 0 refuted. 0 times theorem prover too weak. 28 trivial. 0 not checked. [2022-02-20 17:56:04,851 INFO L324 TraceCheckSpWp]: Omiting computation of backward sequence because forward sequence was already perfect [2022-02-20 17:56:04,852 INFO L165 FreeRefinementEngine]: IpTcStrategyModuleZ3 [1788630232] provided 1 perfect and 0 imperfect interpolant sequences [2022-02-20 17:56:04,852 INFO L191 FreeRefinementEngine]: Found 1 perfect and 1 imperfect interpolant sequences. [2022-02-20 17:56:04,852 INFO L204 FreeRefinementEngine]: Number of different interpolants: perfect sequences [3] imperfect sequences [9] total 10 [2022-02-20 17:56:04,852 INFO L118 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [1444677284] [2022-02-20 17:56:04,852 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2022-02-20 17:56:04,852 INFO L78 Accepts]: Start accepts. Automaton has has 3 states, 3 states have (on average 22.666666666666668) internal successors, (68), 3 states have internal predecessors, (68), 2 states have call successors, (15), 2 states have call predecessors, (15), 2 states have return successors, (13), 2 states have call predecessors, (13), 2 states have call successors, (13) Word has length 111 [2022-02-20 17:56:04,853 INFO L84 Accepts]: Finished accepts. word is accepted. [2022-02-20 17:56:04,853 INFO L86 InductivityCheck]: Starting indutivity check of a Floyd-Hoare automaton with has 3 states, 3 states have (on average 22.666666666666668) internal successors, (68), 3 states have internal predecessors, (68), 2 states have call successors, (15), 2 states have call predecessors, (15), 2 states have return successors, (13), 2 states have call predecessors, (13), 2 states have call successors, (13) [2022-02-20 17:56:04,912 INFO L122 InductivityCheck]: Floyd-Hoare automaton has 96 edges. 96 inductive. 0 not inductive. 0 times theorem prover too weak to decide inductivity. [2022-02-20 17:56:04,912 INFO L546 AbstractCegarLoop]: INTERPOLANT automaton has 3 states [2022-02-20 17:56:04,912 INFO L108 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2022-02-20 17:56:04,912 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 3 interpolants. [2022-02-20 17:56:04,912 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=17, Invalid=73, Unknown=0, NotChecked=0, Total=90 [2022-02-20 17:56:04,913 INFO L87 Difference]: Start difference. First operand 383 states and 565 transitions. Second operand has 3 states, 3 states have (on average 22.666666666666668) internal successors, (68), 3 states have internal predecessors, (68), 2 states have call successors, (15), 2 states have call predecessors, (15), 2 states have return successors, (13), 2 states have call predecessors, (13), 2 states have call successors, (13) [2022-02-20 17:56:05,400 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-02-20 17:56:05,401 INFO L93 Difference]: Finished difference Result 801 states and 1197 transitions. [2022-02-20 17:56:05,401 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 3 states. [2022-02-20 17:56:05,401 INFO L78 Accepts]: Start accepts. Automaton has has 3 states, 3 states have (on average 22.666666666666668) internal successors, (68), 3 states have internal predecessors, (68), 2 states have call successors, (15), 2 states have call predecessors, (15), 2 states have return successors, (13), 2 states have call predecessors, (13), 2 states have call successors, (13) Word has length 111 [2022-02-20 17:56:05,401 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2022-02-20 17:56:05,401 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 3 states, 3 states have (on average 22.666666666666668) internal successors, (68), 3 states have internal predecessors, (68), 2 states have call successors, (15), 2 states have call predecessors, (15), 2 states have return successors, (13), 2 states have call predecessors, (13), 2 states have call successors, (13) [2022-02-20 17:56:05,410 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 3 states to 3 states and 1195 transitions. [2022-02-20 17:56:05,411 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 3 states, 3 states have (on average 22.666666666666668) internal successors, (68), 3 states have internal predecessors, (68), 2 states have call successors, (15), 2 states have call predecessors, (15), 2 states have return successors, (13), 2 states have call predecessors, (13), 2 states have call successors, (13) [2022-02-20 17:56:05,419 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 3 states to 3 states and 1195 transitions. [2022-02-20 17:56:05,420 INFO L86 InductivityCheck]: Starting indutivity check of a Floyd-Hoare automaton with 3 states and 1195 transitions. [2022-02-20 17:56:06,137 INFO L122 InductivityCheck]: Floyd-Hoare automaton has 1195 edges. 1195 inductive. 0 not inductive. 0 times theorem prover too weak to decide inductivity. [2022-02-20 17:56:06,148 INFO L225 Difference]: With dead ends: 801 [2022-02-20 17:56:06,148 INFO L226 Difference]: Without dead ends: 445 [2022-02-20 17:56:06,149 INFO L932 BasicCegarLoop]: 0 DeclaredPredicates, 140 GetRequests, 132 SyntacticMatches, 0 SemanticMatches, 8 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 0 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=17, Invalid=73, Unknown=0, NotChecked=0, Total=90 [2022-02-20 17:56:06,150 INFO L933 BasicCegarLoop]: 576 mSDtfsCounter, 115 mSDsluCounter, 515 mSDsCounter, 0 mSdLazyCounter, 3 mSolverCounterSat, 1 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.0s Time, 0 mProtectedPredicate, 0 mProtectedAction, 130 SdHoareTripleChecker+Valid, 1091 SdHoareTripleChecker+Invalid, 4 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 1 IncrementalHoareTripleChecker+Valid, 3 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.0s IncrementalHoareTripleChecker+Time [2022-02-20 17:56:06,150 INFO L934 BasicCegarLoop]: SdHoareTripleChecker [130 Valid, 1091 Invalid, 4 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [1 Valid, 3 Invalid, 0 Unknown, 0 Unchecked, 0.0s Time] [2022-02-20 17:56:06,151 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 445 states. [2022-02-20 17:56:06,162 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 445 to 437. [2022-02-20 17:56:06,162 INFO L214 AbstractMinimizeNwa]: Start testing correctness of minimizeSevpa [2022-02-20 17:56:06,163 INFO L82 GeneralOperation]: Start isEquivalent. First operand 445 states. Second operand has 437 states, 338 states have (on average 1.5088757396449703) internal successors, (510), 341 states have internal predecessors, (510), 74 states have call successors, (74), 24 states have call predecessors, (74), 24 states have return successors, (73), 73 states have call predecessors, (73), 73 states have call successors, (73) [2022-02-20 17:56:06,164 INFO L74 IsIncluded]: Start isIncluded. First operand 445 states. Second operand has 437 states, 338 states have (on average 1.5088757396449703) internal successors, (510), 341 states have internal predecessors, (510), 74 states have call successors, (74), 24 states have call predecessors, (74), 24 states have return successors, (73), 73 states have call predecessors, (73), 73 states have call successors, (73) [2022-02-20 17:56:06,165 INFO L87 Difference]: Start difference. First operand 445 states. Second operand has 437 states, 338 states have (on average 1.5088757396449703) internal successors, (510), 341 states have internal predecessors, (510), 74 states have call successors, (74), 24 states have call predecessors, (74), 24 states have return successors, (73), 73 states have call predecessors, (73), 73 states have call successors, (73) [2022-02-20 17:56:06,175 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-02-20 17:56:06,175 INFO L93 Difference]: Finished difference Result 445 states and 666 transitions. [2022-02-20 17:56:06,175 INFO L276 IsEmpty]: Start isEmpty. Operand 445 states and 666 transitions. [2022-02-20 17:56:06,176 INFO L282 IsEmpty]: Finished isEmpty. No accepting run. [2022-02-20 17:56:06,176 INFO L83 IsIncluded]: Finished isIncluded. Language is included [2022-02-20 17:56:06,178 INFO L74 IsIncluded]: Start isIncluded. First operand has 437 states, 338 states have (on average 1.5088757396449703) internal successors, (510), 341 states have internal predecessors, (510), 74 states have call successors, (74), 24 states have call predecessors, (74), 24 states have return successors, (73), 73 states have call predecessors, (73), 73 states have call successors, (73) Second operand 445 states. [2022-02-20 17:56:06,179 INFO L87 Difference]: Start difference. First operand has 437 states, 338 states have (on average 1.5088757396449703) internal successors, (510), 341 states have internal predecessors, (510), 74 states have call successors, (74), 24 states have call predecessors, (74), 24 states have return successors, (73), 73 states have call predecessors, (73), 73 states have call successors, (73) Second operand 445 states. [2022-02-20 17:56:06,190 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-02-20 17:56:06,190 INFO L93 Difference]: Finished difference Result 445 states and 666 transitions. [2022-02-20 17:56:06,190 INFO L276 IsEmpty]: Start isEmpty. Operand 445 states and 666 transitions. [2022-02-20 17:56:06,192 INFO L282 IsEmpty]: Finished isEmpty. No accepting run. [2022-02-20 17:56:06,192 INFO L83 IsIncluded]: Finished isIncluded. Language is included [2022-02-20 17:56:06,192 INFO L88 GeneralOperation]: Finished isEquivalent. [2022-02-20 17:56:06,192 INFO L221 AbstractMinimizeNwa]: Finished testing correctness of minimizeSevpa [2022-02-20 17:56:06,193 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 437 states, 338 states have (on average 1.5088757396449703) internal successors, (510), 341 states have internal predecessors, (510), 74 states have call successors, (74), 24 states have call predecessors, (74), 24 states have return successors, (73), 73 states have call predecessors, (73), 73 states have call successors, (73) [2022-02-20 17:56:06,205 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 437 states to 437 states and 657 transitions. [2022-02-20 17:56:06,205 INFO L78 Accepts]: Start accepts. Automaton has 437 states and 657 transitions. Word has length 111 [2022-02-20 17:56:06,205 INFO L84 Accepts]: Finished accepts. word is rejected. [2022-02-20 17:56:06,205 INFO L470 AbstractCegarLoop]: Abstraction has 437 states and 657 transitions. [2022-02-20 17:56:06,206 INFO L471 AbstractCegarLoop]: INTERPOLANT automaton has has 3 states, 3 states have (on average 22.666666666666668) internal successors, (68), 3 states have internal predecessors, (68), 2 states have call successors, (15), 2 states have call predecessors, (15), 2 states have return successors, (13), 2 states have call predecessors, (13), 2 states have call successors, (13) [2022-02-20 17:56:06,206 INFO L276 IsEmpty]: Start isEmpty. Operand 437 states and 657 transitions. [2022-02-20 17:56:06,207 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 113 [2022-02-20 17:56:06,207 INFO L506 BasicCegarLoop]: Found error trace [2022-02-20 17:56:06,207 INFO L514 BasicCegarLoop]: trace histogram [3, 3, 3, 3, 3, 3, 2, 2, 2, 2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-02-20 17:56:06,227 INFO L540 MonitoredProcess]: [MP /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 -smt2 -in SMTLIB2_COMPLIANT=true (4)] Forceful destruction successful, exit code 0 [2022-02-20 17:56:06,423 WARN L452 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable2,4 /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 -smt2 -in SMTLIB2_COMPLIANT=true [2022-02-20 17:56:06,423 INFO L402 AbstractCegarLoop]: === Iteration 4 === Targeting outgoingErr0ASSERT_VIOLATIONERROR_FUNCTION === [outgoingErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2022-02-20 17:56:06,424 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2022-02-20 17:56:06,424 INFO L85 PathProgramCache]: Analyzing trace with hash -2134428930, now seen corresponding path program 1 times [2022-02-20 17:56:06,424 INFO L126 FreeRefinementEngine]: Executing refinement strategy CAMEL [2022-02-20 17:56:06,424 INFO L338 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [933747117] [2022-02-20 17:56:06,424 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-02-20 17:56:06,424 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2022-02-20 17:56:06,453 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-02-20 17:56:06,481 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 6 [2022-02-20 17:56:06,482 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-02-20 17:56:06,484 INFO L290 TraceCheckUtils]: 0: Hoare triple {8529#(and (= |old(~__ste_client_idCounter0~0)| ~__ste_client_idCounter0~0) (= |old(~__ste_client_idCounter1~0)| ~__ste_client_idCounter1~0) (= |old(~__ste_client_idCounter2~0)| ~__ste_client_idCounter2~0))} ~handle := #in~handle;~value := #in~value; {8473#true} is VALID [2022-02-20 17:56:06,484 INFO L290 TraceCheckUtils]: 1: Hoare triple {8473#true} assume 1 == ~handle;~__ste_client_idCounter0~0 := ~value; {8473#true} is VALID [2022-02-20 17:56:06,484 INFO L290 TraceCheckUtils]: 2: Hoare triple {8473#true} assume true; {8473#true} is VALID [2022-02-20 17:56:06,484 INFO L284 TraceCheckUtils]: 3: Hoare quadruple {8473#true} {8473#true} #1133#return; {8473#true} is VALID [2022-02-20 17:56:06,488 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 12 [2022-02-20 17:56:06,489 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-02-20 17:56:06,491 INFO L290 TraceCheckUtils]: 0: Hoare triple {8530#(and (= ~__ste_client_privateKey0~0 |old(~__ste_client_privateKey0~0)|) (= ~__ste_client_privateKey2~0 |old(~__ste_client_privateKey2~0)|) (= ~__ste_client_privateKey1~0 |old(~__ste_client_privateKey1~0)|))} ~handle := #in~handle;~value := #in~value; {8473#true} is VALID [2022-02-20 17:56:06,491 INFO L290 TraceCheckUtils]: 1: Hoare triple {8473#true} assume 1 == ~handle;~__ste_client_privateKey0~0 := ~value; {8473#true} is VALID [2022-02-20 17:56:06,491 INFO L290 TraceCheckUtils]: 2: Hoare triple {8473#true} assume true; {8473#true} is VALID [2022-02-20 17:56:06,491 INFO L284 TraceCheckUtils]: 3: Hoare quadruple {8473#true} {8473#true} #1135#return; {8473#true} is VALID [2022-02-20 17:56:06,491 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 18 [2022-02-20 17:56:06,494 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-02-20 17:56:06,510 INFO L290 TraceCheckUtils]: 0: Hoare triple {8529#(and (= |old(~__ste_client_idCounter0~0)| ~__ste_client_idCounter0~0) (= |old(~__ste_client_idCounter1~0)| ~__ste_client_idCounter1~0) (= |old(~__ste_client_idCounter2~0)| ~__ste_client_idCounter2~0))} ~handle := #in~handle;~value := #in~value; {8531#(= setClientId_~handle |setClientId_#in~handle|)} is VALID [2022-02-20 17:56:06,510 INFO L290 TraceCheckUtils]: 1: Hoare triple {8531#(= setClientId_~handle |setClientId_#in~handle|)} assume 1 == ~handle;~__ste_client_idCounter0~0 := ~value; {8532#(= |setClientId_#in~handle| 1)} is VALID [2022-02-20 17:56:06,510 INFO L290 TraceCheckUtils]: 2: Hoare triple {8532#(= |setClientId_#in~handle| 1)} assume true; {8532#(= |setClientId_#in~handle| 1)} is VALID [2022-02-20 17:56:06,511 INFO L284 TraceCheckUtils]: 3: Hoare quadruple {8532#(= |setClientId_#in~handle| 1)} {8483#(= |ULTIMATE.start_setup_rjh__wrappee__Base_~rjh___0#1| 2)} #1137#return; {8474#false} is VALID [2022-02-20 17:56:06,511 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 24 [2022-02-20 17:56:06,512 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-02-20 17:56:06,514 INFO L290 TraceCheckUtils]: 0: Hoare triple {8530#(and (= ~__ste_client_privateKey0~0 |old(~__ste_client_privateKey0~0)|) (= ~__ste_client_privateKey2~0 |old(~__ste_client_privateKey2~0)|) (= ~__ste_client_privateKey1~0 |old(~__ste_client_privateKey1~0)|))} ~handle := #in~handle;~value := #in~value; {8473#true} is VALID [2022-02-20 17:56:06,514 INFO L290 TraceCheckUtils]: 1: Hoare triple {8473#true} assume 1 == ~handle;~__ste_client_privateKey0~0 := ~value; {8473#true} is VALID [2022-02-20 17:56:06,514 INFO L290 TraceCheckUtils]: 2: Hoare triple {8473#true} assume true; {8473#true} is VALID [2022-02-20 17:56:06,515 INFO L284 TraceCheckUtils]: 3: Hoare quadruple {8473#true} {8474#false} #1139#return; {8474#false} is VALID [2022-02-20 17:56:06,515 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 30 [2022-02-20 17:56:06,517 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-02-20 17:56:06,519 INFO L290 TraceCheckUtils]: 0: Hoare triple {8529#(and (= |old(~__ste_client_idCounter0~0)| ~__ste_client_idCounter0~0) (= |old(~__ste_client_idCounter1~0)| ~__ste_client_idCounter1~0) (= |old(~__ste_client_idCounter2~0)| ~__ste_client_idCounter2~0))} ~handle := #in~handle;~value := #in~value; {8473#true} is VALID [2022-02-20 17:56:06,519 INFO L290 TraceCheckUtils]: 1: Hoare triple {8473#true} assume 1 == ~handle;~__ste_client_idCounter0~0 := ~value; {8473#true} is VALID [2022-02-20 17:56:06,519 INFO L290 TraceCheckUtils]: 2: Hoare triple {8473#true} assume true; {8473#true} is VALID [2022-02-20 17:56:06,519 INFO L284 TraceCheckUtils]: 3: Hoare quadruple {8473#true} {8474#false} #1141#return; {8474#false} is VALID [2022-02-20 17:56:06,520 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 36 [2022-02-20 17:56:06,523 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-02-20 17:56:06,525 INFO L290 TraceCheckUtils]: 0: Hoare triple {8530#(and (= ~__ste_client_privateKey0~0 |old(~__ste_client_privateKey0~0)|) (= ~__ste_client_privateKey2~0 |old(~__ste_client_privateKey2~0)|) (= ~__ste_client_privateKey1~0 |old(~__ste_client_privateKey1~0)|))} ~handle := #in~handle;~value := #in~value; {8473#true} is VALID [2022-02-20 17:56:06,525 INFO L290 TraceCheckUtils]: 1: Hoare triple {8473#true} assume 1 == ~handle;~__ste_client_privateKey0~0 := ~value; {8473#true} is VALID [2022-02-20 17:56:06,526 INFO L290 TraceCheckUtils]: 2: Hoare triple {8473#true} assume true; {8473#true} is VALID [2022-02-20 17:56:06,526 INFO L284 TraceCheckUtils]: 3: Hoare quadruple {8473#true} {8474#false} #1143#return; {8474#false} is VALID [2022-02-20 17:56:06,530 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 58 [2022-02-20 17:56:06,532 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-02-20 17:56:06,534 INFO L290 TraceCheckUtils]: 0: Hoare triple {8533#(and (= |old(~__ste_email_from0~0)| ~__ste_email_from0~0) (= |old(~__ste_email_from1~0)| ~__ste_email_from1~0))} ~handle := #in~handle;~value := #in~value; {8473#true} is VALID [2022-02-20 17:56:06,534 INFO L290 TraceCheckUtils]: 1: Hoare triple {8473#true} assume 1 == ~handle;~__ste_email_from0~0 := ~value; {8473#true} is VALID [2022-02-20 17:56:06,534 INFO L290 TraceCheckUtils]: 2: Hoare triple {8473#true} assume true; {8473#true} is VALID [2022-02-20 17:56:06,534 INFO L284 TraceCheckUtils]: 3: Hoare quadruple {8473#true} {8474#false} #1119#return; {8474#false} is VALID [2022-02-20 17:56:06,540 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 63 [2022-02-20 17:56:06,543 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-02-20 17:56:06,545 INFO L290 TraceCheckUtils]: 0: Hoare triple {8534#(and (= ~__ste_email_to0~0 |old(~__ste_email_to0~0)|) (= ~__ste_email_to1~0 |old(~__ste_email_to1~0)|))} ~handle := #in~handle;~value := #in~value; {8473#true} is VALID [2022-02-20 17:56:06,545 INFO L290 TraceCheckUtils]: 1: Hoare triple {8473#true} assume 1 == ~handle;~__ste_email_to0~0 := ~value; {8473#true} is VALID [2022-02-20 17:56:06,545 INFO L290 TraceCheckUtils]: 2: Hoare triple {8473#true} assume true; {8473#true} is VALID [2022-02-20 17:56:06,545 INFO L284 TraceCheckUtils]: 3: Hoare quadruple {8473#true} {8474#false} #1121#return; {8474#false} is VALID [2022-02-20 17:56:06,545 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 72 [2022-02-20 17:56:06,546 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-02-20 17:56:06,548 INFO L290 TraceCheckUtils]: 0: Hoare triple {8473#true} ~handle := #in~handle;havoc ~retValue_acc~24; {8473#true} is VALID [2022-02-20 17:56:06,548 INFO L290 TraceCheckUtils]: 1: Hoare triple {8473#true} assume 1 == ~handle;~retValue_acc~24 := ~__ste_client_privateKey0~0;#res := ~retValue_acc~24; {8473#true} is VALID [2022-02-20 17:56:06,548 INFO L290 TraceCheckUtils]: 2: Hoare triple {8473#true} assume true; {8473#true} is VALID [2022-02-20 17:56:06,548 INFO L284 TraceCheckUtils]: 3: Hoare quadruple {8473#true} {8474#false} #1053#return; {8474#false} is VALID [2022-02-20 17:56:06,548 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 80 [2022-02-20 17:56:06,549 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-02-20 17:56:06,550 INFO L290 TraceCheckUtils]: 0: Hoare triple {8473#true} ~handle := #in~handle;havoc ~retValue_acc~36; {8473#true} is VALID [2022-02-20 17:56:06,550 INFO L290 TraceCheckUtils]: 1: Hoare triple {8473#true} assume 1 == ~handle;~retValue_acc~36 := ~__ste_email_to0~0;#res := ~retValue_acc~36; {8473#true} is VALID [2022-02-20 17:56:06,550 INFO L290 TraceCheckUtils]: 2: Hoare triple {8473#true} assume true; {8473#true} is VALID [2022-02-20 17:56:06,551 INFO L284 TraceCheckUtils]: 3: Hoare quadruple {8473#true} {8474#false} #1055#return; {8474#false} is VALID [2022-02-20 17:56:06,551 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 86 [2022-02-20 17:56:06,551 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-02-20 17:56:06,553 INFO L290 TraceCheckUtils]: 0: Hoare triple {8473#true} ~handle := #in~handle;~userid := #in~userid;havoc ~retValue_acc~29; {8473#true} is VALID [2022-02-20 17:56:06,553 INFO L290 TraceCheckUtils]: 1: Hoare triple {8473#true} assume 1 == ~handle; {8473#true} is VALID [2022-02-20 17:56:06,553 INFO L290 TraceCheckUtils]: 2: Hoare triple {8473#true} assume ~userid == ~__ste_Client_Keyring0_User0~0;~retValue_acc~29 := ~__ste_Client_Keyring0_PublicKey0~0;#res := ~retValue_acc~29; {8473#true} is VALID [2022-02-20 17:56:06,553 INFO L290 TraceCheckUtils]: 3: Hoare triple {8473#true} assume true; {8473#true} is VALID [2022-02-20 17:56:06,553 INFO L284 TraceCheckUtils]: 4: Hoare quadruple {8473#true} {8474#false} #1057#return; {8474#false} is VALID [2022-02-20 17:56:06,553 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 97 [2022-02-20 17:56:06,554 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-02-20 17:56:06,555 INFO L290 TraceCheckUtils]: 0: Hoare triple {8533#(and (= |old(~__ste_email_from0~0)| ~__ste_email_from0~0) (= |old(~__ste_email_from1~0)| ~__ste_email_from1~0))} ~handle := #in~handle;~value := #in~value; {8473#true} is VALID [2022-02-20 17:56:06,555 INFO L290 TraceCheckUtils]: 1: Hoare triple {8473#true} assume 1 == ~handle;~__ste_email_from0~0 := ~value; {8473#true} is VALID [2022-02-20 17:56:06,555 INFO L290 TraceCheckUtils]: 2: Hoare triple {8473#true} assume true; {8473#true} is VALID [2022-02-20 17:56:06,555 INFO L284 TraceCheckUtils]: 3: Hoare quadruple {8473#true} {8474#false} #1063#return; {8474#false} is VALID [2022-02-20 17:56:06,556 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 104 [2022-02-20 17:56:06,556 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-02-20 17:56:06,558 INFO L290 TraceCheckUtils]: 0: Hoare triple {8473#true} ~handle := #in~handle;havoc ~retValue_acc~39; {8473#true} is VALID [2022-02-20 17:56:06,558 INFO L290 TraceCheckUtils]: 1: Hoare triple {8473#true} assume 1 == ~handle;~retValue_acc~39 := ~__ste_email_isEncrypted0~0;#res := ~retValue_acc~39; {8473#true} is VALID [2022-02-20 17:56:06,558 INFO L290 TraceCheckUtils]: 2: Hoare triple {8473#true} assume true; {8473#true} is VALID [2022-02-20 17:56:06,558 INFO L284 TraceCheckUtils]: 3: Hoare quadruple {8473#true} {8474#false} #1067#return; {8474#false} is VALID [2022-02-20 17:56:06,558 INFO L290 TraceCheckUtils]: 0: Hoare triple {8473#true} assume { :begin_inline_ULTIMATE.init } true;#NULL.base, #NULL.offset := 0, 0;assume 0 == #valid[0];assume 0 < #StackHeapBarrier;call #Ultimate.allocInit(2, 1);call write~init~int(48, 1, 0, 1);call write~init~int(0, 1, 1, 1);call #Ultimate.allocInit(28, 2);call #Ultimate.allocInit(12, 3);call #Ultimate.allocInit(4, 4);call write~init~int(37, 4, 0, 1);call write~init~int(115, 4, 1, 1);call write~init~int(10, 4, 2, 1);call write~init~int(0, 4, 3, 1);call #Ultimate.allocInit(10, 5);call #Ultimate.allocInit(12, 6);call #Ultimate.allocInit(10, 7);call #Ultimate.allocInit(18, 8);call #Ultimate.allocInit(16, 9);call #Ultimate.allocInit(21, 10);call #Ultimate.allocInit(13, 11);call #Ultimate.allocInit(16, 12);call #Ultimate.allocInit(25, 13);call #Ultimate.allocInit(30, 14);call #Ultimate.allocInit(9, 15);call #Ultimate.allocInit(21, 16);call #Ultimate.allocInit(30, 17);call #Ultimate.allocInit(9, 18);call #Ultimate.allocInit(21, 19);call #Ultimate.allocInit(30, 20);call #Ultimate.allocInit(9, 21);call #Ultimate.allocInit(25, 22);call #Ultimate.allocInit(30, 23);call #Ultimate.allocInit(9, 24);call #Ultimate.allocInit(25, 25);call #Ultimate.allocInit(10, 26);call #Ultimate.allocInit(16, 27);call #Ultimate.allocInit(20, 28);call #Ultimate.allocInit(22, 29);call #Ultimate.allocInit(21, 30);call #Ultimate.allocInit(13, 31);call #Ultimate.allocInit(44, 32);call #Ultimate.allocInit(44, 33);call #Ultimate.allocInit(9, 34);call #Ultimate.allocInit(9, 35);call #Ultimate.allocInit(11, 36);call #Ultimate.allocInit(19, 37);call #Ultimate.allocInit(4, 38);call write~init~int(37, 38, 0, 1);call write~init~int(100, 38, 1, 1);call write~init~int(10, 38, 2, 1);call write~init~int(0, 38, 3, 1);call #Ultimate.allocInit(4, 39);call write~init~int(37, 39, 0, 1);call write~init~int(100, 39, 1, 1);call write~init~int(10, 39, 2, 1);call write~init~int(0, 39, 3, 1);~__SELECTED_FEATURE_Base~0 := 0;~__SELECTED_FEATURE_Keys~0 := 0;~__SELECTED_FEATURE_Encrypt~0 := 0;~__SELECTED_FEATURE_AutoResponder~0 := 0;~__SELECTED_FEATURE_AddressBook~0 := 0;~__SELECTED_FEATURE_Sign~0 := 0;~__SELECTED_FEATURE_Forward~0 := 0;~__SELECTED_FEATURE_Verify~0 := 0;~__SELECTED_FEATURE_Decrypt~0 := 0;~__GUIDSL_ROOT_PRODUCTION~0 := 0;~__GUIDSL_NON_TERMINAL_main~0 := 0;~head~0.base, ~head~0.offset := 0, 0;~queue_empty~0 := 1;~queued_message~0 := 0;~queued_client~0 := 0;~mail_is_sensitive~0 := -1;~__ste_Client_counter~0 := 0;~__ste_client_name0~0.base, ~__ste_client_name0~0.offset := 0, 0;~__ste_client_name1~0.base, ~__ste_client_name1~0.offset := 0, 0;~__ste_client_name2~0.base, ~__ste_client_name2~0.offset := 0, 0;~__ste_client_outbuffer0~0 := 0;~__ste_client_outbuffer1~0 := 0;~__ste_client_outbuffer2~0 := 0;~__ste_client_outbuffer3~0 := 0;~__ste_ClientAddressBook_size0~0 := 0;~__ste_ClientAddressBook_size1~0 := 0;~__ste_ClientAddressBook_size2~0 := 0;~__ste_Client_AddressBook0_Alias0~0 := 0;~__ste_Client_AddressBook0_Alias1~0 := 0;~__ste_Client_AddressBook0_Alias2~0 := 0;~__ste_Client_AddressBook1_Alias0~0 := 0;~__ste_Client_AddressBook1_Alias1~0 := 0;~__ste_Client_AddressBook1_Alias2~0 := 0;~__ste_Client_AddressBook2_Alias0~0 := 0;~__ste_Client_AddressBook2_Alias1~0 := 0;~__ste_Client_AddressBook2_Alias2~0 := 0;~__ste_Client_AddressBook0_Address0~0 := 0;~__ste_Client_AddressBook0_Address1~0 := 0;~__ste_Client_AddressBook0_Address2~0 := 0;~__ste_Client_AddressBook1_Address0~0 := 0;~__ste_Client_AddressBook1_Address1~0 := 0;~__ste_Client_AddressBook1_Address2~0 := 0;~__ste_Client_AddressBook2_Address0~0 := 0;~__ste_Client_AddressBook2_Address1~0 := 0;~__ste_Client_AddressBook2_Address2~0 := 0;~__ste_client_autoResponse0~0 := 0;~__ste_client_autoResponse1~0 := 0;~__ste_client_autoResponse2~0 := 0;~__ste_client_privateKey0~0 := 0;~__ste_client_privateKey1~0 := 0;~__ste_client_privateKey2~0 := 0;~__ste_ClientKeyring_size0~0 := 0;~__ste_ClientKeyring_size1~0 := 0;~__ste_ClientKeyring_size2~0 := 0;~__ste_Client_Keyring0_User0~0 := 0;~__ste_Client_Keyring0_User1~0 := 0;~__ste_Client_Keyring0_User2~0 := 0;~__ste_Client_Keyring1_User0~0 := 0;~__ste_Client_Keyring1_User1~0 := 0;~__ste_Client_Keyring1_User2~0 := 0;~__ste_Client_Keyring2_User0~0 := 0;~__ste_Client_Keyring2_User1~0 := 0;~__ste_Client_Keyring2_User2~0 := 0;~__ste_Client_Keyring0_PublicKey0~0 := 0;~__ste_Client_Keyring0_PublicKey1~0 := 0;~__ste_Client_Keyring0_PublicKey2~0 := 0;~__ste_Client_Keyring1_PublicKey0~0 := 0;~__ste_Client_Keyring1_PublicKey1~0 := 0;~__ste_Client_Keyring1_PublicKey2~0 := 0;~__ste_Client_Keyring2_PublicKey0~0 := 0;~__ste_Client_Keyring2_PublicKey1~0 := 0;~__ste_Client_Keyring2_PublicKey2~0 := 0;~__ste_client_forwardReceiver0~0 := 0;~__ste_client_forwardReceiver1~0 := 0;~__ste_client_forwardReceiver2~0 := 0;~__ste_client_forwardReceiver3~0 := 0;~__ste_client_idCounter0~0 := 0;~__ste_client_idCounter1~0 := 0;~__ste_client_idCounter2~0 := 0;~bob~0 := 0;~rjh~0 := 0;~chuck~0 := 0;~__ste_Email_counter~0 := 0;~__ste_email_id0~0 := 0;~__ste_email_id1~0 := 0;~__ste_email_from0~0 := 0;~__ste_email_from1~0 := 0;~__ste_email_to0~0 := 0;~__ste_email_to1~0 := 0;~__ste_email_subject0~0.base, ~__ste_email_subject0~0.offset := 0, 0;~__ste_email_subject1~0.base, ~__ste_email_subject1~0.offset := 0, 0;~__ste_email_body0~0.base, ~__ste_email_body0~0.offset := 0, 0;~__ste_email_body1~0.base, ~__ste_email_body1~0.offset := 0, 0;~__ste_email_isEncrypted0~0 := 0;~__ste_email_isEncrypted1~0 := 0;~__ste_email_encryptionKey0~0 := 0;~__ste_email_encryptionKey1~0 := 0;~__ste_email_isSigned0~0 := 0;~__ste_email_isSigned1~0 := 0;~__ste_email_signKey0~0 := 0;~__ste_email_signKey1~0 := 0;~__ste_email_isSignatureVerified0~0 := 0;~__ste_email_isSignatureVerified1~0 := 0; {8473#true} is VALID [2022-02-20 17:56:06,558 INFO L290 TraceCheckUtils]: 1: Hoare triple {8473#true} assume { :end_inline_ULTIMATE.init } true;assume { :begin_inline_main } true;havoc main_#res#1;havoc main_#t~ret98#1, main_~retValue_acc~32#1, main_~tmp~24#1;havoc main_~retValue_acc~32#1;havoc main_~tmp~24#1;assume { :begin_inline_select_helpers } true; {8473#true} is VALID [2022-02-20 17:56:06,558 INFO L290 TraceCheckUtils]: 2: Hoare triple {8473#true} assume { :end_inline_select_helpers } true;assume { :begin_inline_select_features } true; {8473#true} is VALID [2022-02-20 17:56:06,558 INFO L290 TraceCheckUtils]: 3: Hoare triple {8473#true} assume { :end_inline_select_features } true;assume { :begin_inline_valid_product } true;havoc valid_product_#res#1;havoc valid_product_~retValue_acc~9#1;havoc valid_product_~retValue_acc~9#1;valid_product_~retValue_acc~9#1 := 1;valid_product_#res#1 := valid_product_~retValue_acc~9#1; {8473#true} is VALID [2022-02-20 17:56:06,558 INFO L290 TraceCheckUtils]: 4: Hoare triple {8473#true} main_#t~ret98#1 := valid_product_#res#1;assume { :end_inline_valid_product } true;assume -2147483648 <= main_#t~ret98#1 && main_#t~ret98#1 <= 2147483647;main_~tmp~24#1 := main_#t~ret98#1;havoc main_#t~ret98#1; {8473#true} is VALID [2022-02-20 17:56:06,558 INFO L290 TraceCheckUtils]: 5: Hoare triple {8473#true} assume 0 != main_~tmp~24#1;assume { :begin_inline_setup } true;havoc setup_#t~nondet95#1, setup_#t~nondet96#1, setup_#t~nondet97#1, setup_~__cil_tmp1~0#1.base, setup_~__cil_tmp1~0#1.offset, setup_~__cil_tmp2~0#1.base, setup_~__cil_tmp2~0#1.offset, setup_~__cil_tmp3~2#1.base, setup_~__cil_tmp3~2#1.offset;havoc setup_~__cil_tmp1~0#1.base, setup_~__cil_tmp1~0#1.offset;havoc setup_~__cil_tmp2~0#1.base, setup_~__cil_tmp2~0#1.offset;havoc setup_~__cil_tmp3~2#1.base, setup_~__cil_tmp3~2#1.offset;~bob~0 := 1;assume { :begin_inline_setup_bob } true;setup_bob_#in~bob___0#1 := ~bob~0;havoc setup_bob_~bob___0#1;setup_bob_~bob___0#1 := setup_bob_#in~bob___0#1;assume { :begin_inline_setup_bob__wrappee__Base } true;setup_bob__wrappee__Base_#in~bob___0#1 := setup_bob_~bob___0#1;havoc setup_bob__wrappee__Base_~bob___0#1;setup_bob__wrappee__Base_~bob___0#1 := setup_bob__wrappee__Base_#in~bob___0#1; {8473#true} is VALID [2022-02-20 17:56:06,559 INFO L272 TraceCheckUtils]: 6: Hoare triple {8473#true} call setClientId(setup_bob__wrappee__Base_~bob___0#1, setup_bob__wrappee__Base_~bob___0#1); {8529#(and (= |old(~__ste_client_idCounter0~0)| ~__ste_client_idCounter0~0) (= |old(~__ste_client_idCounter1~0)| ~__ste_client_idCounter1~0) (= |old(~__ste_client_idCounter2~0)| ~__ste_client_idCounter2~0))} is VALID [2022-02-20 17:56:06,559 INFO L290 TraceCheckUtils]: 7: Hoare triple {8529#(and (= |old(~__ste_client_idCounter0~0)| ~__ste_client_idCounter0~0) (= |old(~__ste_client_idCounter1~0)| ~__ste_client_idCounter1~0) (= |old(~__ste_client_idCounter2~0)| ~__ste_client_idCounter2~0))} ~handle := #in~handle;~value := #in~value; {8473#true} is VALID [2022-02-20 17:56:06,559 INFO L290 TraceCheckUtils]: 8: Hoare triple {8473#true} assume 1 == ~handle;~__ste_client_idCounter0~0 := ~value; {8473#true} is VALID [2022-02-20 17:56:06,559 INFO L290 TraceCheckUtils]: 9: Hoare triple {8473#true} assume true; {8473#true} is VALID [2022-02-20 17:56:06,559 INFO L284 TraceCheckUtils]: 10: Hoare quadruple {8473#true} {8473#true} #1133#return; {8473#true} is VALID [2022-02-20 17:56:06,560 INFO L290 TraceCheckUtils]: 11: Hoare triple {8473#true} assume { :end_inline_setup_bob__wrappee__Base } true; {8473#true} is VALID [2022-02-20 17:56:06,560 INFO L272 TraceCheckUtils]: 12: Hoare triple {8473#true} call setClientPrivateKey(setup_bob_~bob___0#1, 123); {8530#(and (= ~__ste_client_privateKey0~0 |old(~__ste_client_privateKey0~0)|) (= ~__ste_client_privateKey2~0 |old(~__ste_client_privateKey2~0)|) (= ~__ste_client_privateKey1~0 |old(~__ste_client_privateKey1~0)|))} is VALID [2022-02-20 17:56:06,560 INFO L290 TraceCheckUtils]: 13: Hoare triple {8530#(and (= ~__ste_client_privateKey0~0 |old(~__ste_client_privateKey0~0)|) (= ~__ste_client_privateKey2~0 |old(~__ste_client_privateKey2~0)|) (= ~__ste_client_privateKey1~0 |old(~__ste_client_privateKey1~0)|))} ~handle := #in~handle;~value := #in~value; {8473#true} is VALID [2022-02-20 17:56:06,560 INFO L290 TraceCheckUtils]: 14: Hoare triple {8473#true} assume 1 == ~handle;~__ste_client_privateKey0~0 := ~value; {8473#true} is VALID [2022-02-20 17:56:06,560 INFO L290 TraceCheckUtils]: 15: Hoare triple {8473#true} assume true; {8473#true} is VALID [2022-02-20 17:56:06,560 INFO L284 TraceCheckUtils]: 16: Hoare quadruple {8473#true} {8473#true} #1135#return; {8473#true} is VALID [2022-02-20 17:56:06,561 INFO L290 TraceCheckUtils]: 17: Hoare triple {8473#true} assume { :end_inline_setup_bob } true;setup_~__cil_tmp1~0#1.base, setup_~__cil_tmp1~0#1.offset := 34, 0;havoc setup_#t~nondet95#1;~rjh~0 := 2;assume { :begin_inline_setup_rjh } true;setup_rjh_#in~rjh___0#1 := ~rjh~0;havoc setup_rjh_~rjh___0#1;setup_rjh_~rjh___0#1 := setup_rjh_#in~rjh___0#1;assume { :begin_inline_setup_rjh__wrappee__Base } true;setup_rjh__wrappee__Base_#in~rjh___0#1 := setup_rjh_~rjh___0#1;havoc setup_rjh__wrappee__Base_~rjh___0#1;setup_rjh__wrappee__Base_~rjh___0#1 := setup_rjh__wrappee__Base_#in~rjh___0#1; {8483#(= |ULTIMATE.start_setup_rjh__wrappee__Base_~rjh___0#1| 2)} is VALID [2022-02-20 17:56:06,561 INFO L272 TraceCheckUtils]: 18: Hoare triple {8483#(= |ULTIMATE.start_setup_rjh__wrappee__Base_~rjh___0#1| 2)} call setClientId(setup_rjh__wrappee__Base_~rjh___0#1, setup_rjh__wrappee__Base_~rjh___0#1); {8529#(and (= |old(~__ste_client_idCounter0~0)| ~__ste_client_idCounter0~0) (= |old(~__ste_client_idCounter1~0)| ~__ste_client_idCounter1~0) (= |old(~__ste_client_idCounter2~0)| ~__ste_client_idCounter2~0))} is VALID [2022-02-20 17:56:06,562 INFO L290 TraceCheckUtils]: 19: Hoare triple {8529#(and (= |old(~__ste_client_idCounter0~0)| ~__ste_client_idCounter0~0) (= |old(~__ste_client_idCounter1~0)| ~__ste_client_idCounter1~0) (= |old(~__ste_client_idCounter2~0)| ~__ste_client_idCounter2~0))} ~handle := #in~handle;~value := #in~value; {8531#(= setClientId_~handle |setClientId_#in~handle|)} is VALID [2022-02-20 17:56:06,562 INFO L290 TraceCheckUtils]: 20: Hoare triple {8531#(= setClientId_~handle |setClientId_#in~handle|)} assume 1 == ~handle;~__ste_client_idCounter0~0 := ~value; {8532#(= |setClientId_#in~handle| 1)} is VALID [2022-02-20 17:56:06,562 INFO L290 TraceCheckUtils]: 21: Hoare triple {8532#(= |setClientId_#in~handle| 1)} assume true; {8532#(= |setClientId_#in~handle| 1)} is VALID [2022-02-20 17:56:06,563 INFO L284 TraceCheckUtils]: 22: Hoare quadruple {8532#(= |setClientId_#in~handle| 1)} {8483#(= |ULTIMATE.start_setup_rjh__wrappee__Base_~rjh___0#1| 2)} #1137#return; {8474#false} is VALID [2022-02-20 17:56:06,563 INFO L290 TraceCheckUtils]: 23: Hoare triple {8474#false} assume { :end_inline_setup_rjh__wrappee__Base } true; {8474#false} is VALID [2022-02-20 17:56:06,563 INFO L272 TraceCheckUtils]: 24: Hoare triple {8474#false} call setClientPrivateKey(setup_rjh_~rjh___0#1, 456); {8530#(and (= ~__ste_client_privateKey0~0 |old(~__ste_client_privateKey0~0)|) (= ~__ste_client_privateKey2~0 |old(~__ste_client_privateKey2~0)|) (= ~__ste_client_privateKey1~0 |old(~__ste_client_privateKey1~0)|))} is VALID [2022-02-20 17:56:06,563 INFO L290 TraceCheckUtils]: 25: Hoare triple {8530#(and (= ~__ste_client_privateKey0~0 |old(~__ste_client_privateKey0~0)|) (= ~__ste_client_privateKey2~0 |old(~__ste_client_privateKey2~0)|) (= ~__ste_client_privateKey1~0 |old(~__ste_client_privateKey1~0)|))} ~handle := #in~handle;~value := #in~value; {8473#true} is VALID [2022-02-20 17:56:06,563 INFO L290 TraceCheckUtils]: 26: Hoare triple {8473#true} assume 1 == ~handle;~__ste_client_privateKey0~0 := ~value; {8473#true} is VALID [2022-02-20 17:56:06,563 INFO L290 TraceCheckUtils]: 27: Hoare triple {8473#true} assume true; {8473#true} is VALID [2022-02-20 17:56:06,563 INFO L284 TraceCheckUtils]: 28: Hoare quadruple {8473#true} {8474#false} #1139#return; {8474#false} is VALID [2022-02-20 17:56:06,563 INFO L290 TraceCheckUtils]: 29: Hoare triple {8474#false} assume { :end_inline_setup_rjh } true;setup_~__cil_tmp2~0#1.base, setup_~__cil_tmp2~0#1.offset := 35, 0;havoc setup_#t~nondet96#1;~chuck~0 := 3;assume { :begin_inline_setup_chuck } true;setup_chuck_#in~chuck___0#1 := ~chuck~0;havoc setup_chuck_~chuck___0#1;setup_chuck_~chuck___0#1 := setup_chuck_#in~chuck___0#1;assume { :begin_inline_setup_chuck__wrappee__Base } true;setup_chuck__wrappee__Base_#in~chuck___0#1 := setup_chuck_~chuck___0#1;havoc setup_chuck__wrappee__Base_~chuck___0#1;setup_chuck__wrappee__Base_~chuck___0#1 := setup_chuck__wrappee__Base_#in~chuck___0#1; {8474#false} is VALID [2022-02-20 17:56:06,563 INFO L272 TraceCheckUtils]: 30: Hoare triple {8474#false} call setClientId(setup_chuck__wrappee__Base_~chuck___0#1, setup_chuck__wrappee__Base_~chuck___0#1); {8529#(and (= |old(~__ste_client_idCounter0~0)| ~__ste_client_idCounter0~0) (= |old(~__ste_client_idCounter1~0)| ~__ste_client_idCounter1~0) (= |old(~__ste_client_idCounter2~0)| ~__ste_client_idCounter2~0))} is VALID [2022-02-20 17:56:06,564 INFO L290 TraceCheckUtils]: 31: Hoare triple {8529#(and (= |old(~__ste_client_idCounter0~0)| ~__ste_client_idCounter0~0) (= |old(~__ste_client_idCounter1~0)| ~__ste_client_idCounter1~0) (= |old(~__ste_client_idCounter2~0)| ~__ste_client_idCounter2~0))} ~handle := #in~handle;~value := #in~value; {8473#true} is VALID [2022-02-20 17:56:06,564 INFO L290 TraceCheckUtils]: 32: Hoare triple {8473#true} assume 1 == ~handle;~__ste_client_idCounter0~0 := ~value; {8473#true} is VALID [2022-02-20 17:56:06,564 INFO L290 TraceCheckUtils]: 33: Hoare triple {8473#true} assume true; {8473#true} is VALID [2022-02-20 17:56:06,564 INFO L284 TraceCheckUtils]: 34: Hoare quadruple {8473#true} {8474#false} #1141#return; {8474#false} is VALID [2022-02-20 17:56:06,564 INFO L290 TraceCheckUtils]: 35: Hoare triple {8474#false} assume { :end_inline_setup_chuck__wrappee__Base } true; {8474#false} is VALID [2022-02-20 17:56:06,564 INFO L272 TraceCheckUtils]: 36: Hoare triple {8474#false} call setClientPrivateKey(setup_chuck_~chuck___0#1, 789); {8530#(and (= ~__ste_client_privateKey0~0 |old(~__ste_client_privateKey0~0)|) (= ~__ste_client_privateKey2~0 |old(~__ste_client_privateKey2~0)|) (= ~__ste_client_privateKey1~0 |old(~__ste_client_privateKey1~0)|))} is VALID [2022-02-20 17:56:06,564 INFO L290 TraceCheckUtils]: 37: Hoare triple {8530#(and (= ~__ste_client_privateKey0~0 |old(~__ste_client_privateKey0~0)|) (= ~__ste_client_privateKey2~0 |old(~__ste_client_privateKey2~0)|) (= ~__ste_client_privateKey1~0 |old(~__ste_client_privateKey1~0)|))} ~handle := #in~handle;~value := #in~value; {8473#true} is VALID [2022-02-20 17:56:06,564 INFO L290 TraceCheckUtils]: 38: Hoare triple {8473#true} assume 1 == ~handle;~__ste_client_privateKey0~0 := ~value; {8473#true} is VALID [2022-02-20 17:56:06,564 INFO L290 TraceCheckUtils]: 39: Hoare triple {8473#true} assume true; {8473#true} is VALID [2022-02-20 17:56:06,565 INFO L284 TraceCheckUtils]: 40: Hoare quadruple {8473#true} {8474#false} #1143#return; {8474#false} is VALID [2022-02-20 17:56:06,565 INFO L290 TraceCheckUtils]: 41: Hoare triple {8474#false} assume { :end_inline_setup_chuck } true;setup_~__cil_tmp3~2#1.base, setup_~__cil_tmp3~2#1.offset := 36, 0;havoc setup_#t~nondet97#1; {8474#false} is VALID [2022-02-20 17:56:06,565 INFO L290 TraceCheckUtils]: 42: Hoare triple {8474#false} assume { :end_inline_setup } true;assume { :begin_inline_test } true;havoc test_#t~nondet48#1, test_#t~nondet49#1, test_#t~nondet50#1, test_#t~nondet51#1, test_#t~nondet52#1, test_#t~nondet53#1, test_#t~nondet54#1, test_#t~nondet55#1, test_#t~nondet56#1, test_#t~nondet57#1, test_#t~nondet58#1, test_~op1~0#1, test_~op2~0#1, test_~op3~0#1, test_~op4~0#1, test_~op5~0#1, test_~op6~0#1, test_~op7~0#1, test_~op8~0#1, test_~op9~0#1, test_~op10~0#1, test_~op11~0#1, test_~splverifierCounter~0#1, test_~tmp~8#1, test_~tmp___0~3#1, test_~tmp___1~1#1, test_~tmp___2~1#1, test_~tmp___3~0#1, test_~tmp___4~0#1, test_~tmp___5~0#1, test_~tmp___6~0#1, test_~tmp___7~0#1, test_~tmp___8~0#1, test_~tmp___9~0#1;havoc test_~op1~0#1;havoc test_~op2~0#1;havoc test_~op3~0#1;havoc test_~op4~0#1;havoc test_~op5~0#1;havoc test_~op6~0#1;havoc test_~op7~0#1;havoc test_~op8~0#1;havoc test_~op9~0#1;havoc test_~op10~0#1;havoc test_~op11~0#1;havoc test_~splverifierCounter~0#1;havoc test_~tmp~8#1;havoc test_~tmp___0~3#1;havoc test_~tmp___1~1#1;havoc test_~tmp___2~1#1;havoc test_~tmp___3~0#1;havoc test_~tmp___4~0#1;havoc test_~tmp___5~0#1;havoc test_~tmp___6~0#1;havoc test_~tmp___7~0#1;havoc test_~tmp___8~0#1;havoc test_~tmp___9~0#1;test_~op1~0#1 := 0;test_~op2~0#1 := 0;test_~op3~0#1 := 0;test_~op4~0#1 := 0;test_~op5~0#1 := 0;test_~op6~0#1 := 0;test_~op7~0#1 := 0;test_~op8~0#1 := 0;test_~op9~0#1 := 0;test_~op10~0#1 := 0;test_~op11~0#1 := 0;test_~splverifierCounter~0#1 := 0; {8474#false} is VALID [2022-02-20 17:56:06,565 INFO L290 TraceCheckUtils]: 43: Hoare triple {8474#false} assume !false; {8474#false} is VALID [2022-02-20 17:56:06,565 INFO L290 TraceCheckUtils]: 44: Hoare triple {8474#false} assume test_~splverifierCounter~0#1 < 4; {8474#false} is VALID [2022-02-20 17:56:06,565 INFO L290 TraceCheckUtils]: 45: Hoare triple {8474#false} test_~splverifierCounter~0#1 := 1 + test_~splverifierCounter~0#1; {8474#false} is VALID [2022-02-20 17:56:06,565 INFO L290 TraceCheckUtils]: 46: Hoare triple {8474#false} assume 0 == test_~op1~0#1;assume -2147483648 <= test_#t~nondet48#1 && test_#t~nondet48#1 <= 2147483647;test_~tmp___9~0#1 := test_#t~nondet48#1;havoc test_#t~nondet48#1; {8474#false} is VALID [2022-02-20 17:56:06,565 INFO L290 TraceCheckUtils]: 47: Hoare triple {8474#false} assume !(0 != test_~tmp___9~0#1); {8474#false} is VALID [2022-02-20 17:56:06,565 INFO L290 TraceCheckUtils]: 48: Hoare triple {8474#false} assume 0 == test_~op2~0#1;assume -2147483648 <= test_#t~nondet49#1 && test_#t~nondet49#1 <= 2147483647;test_~tmp___8~0#1 := test_#t~nondet49#1;havoc test_#t~nondet49#1; {8474#false} is VALID [2022-02-20 17:56:06,566 INFO L290 TraceCheckUtils]: 49: Hoare triple {8474#false} assume 0 != test_~tmp___8~0#1;assume { :begin_inline_rjhSetAutoRespond } true;assume { :begin_inline_setClientAutoResponse } true;setClientAutoResponse_#in~handle#1, setClientAutoResponse_#in~value#1 := ~rjh~0, 1;havoc setClientAutoResponse_~handle#1, setClientAutoResponse_~value#1;setClientAutoResponse_~handle#1 := setClientAutoResponse_#in~handle#1;setClientAutoResponse_~value#1 := setClientAutoResponse_#in~value#1; {8474#false} is VALID [2022-02-20 17:56:06,566 INFO L290 TraceCheckUtils]: 50: Hoare triple {8474#false} assume 1 == setClientAutoResponse_~handle#1;~__ste_client_autoResponse0~0 := setClientAutoResponse_~value#1; {8474#false} is VALID [2022-02-20 17:56:06,566 INFO L290 TraceCheckUtils]: 51: Hoare triple {8474#false} assume { :end_inline_setClientAutoResponse } true; {8474#false} is VALID [2022-02-20 17:56:06,566 INFO L290 TraceCheckUtils]: 52: Hoare triple {8474#false} assume { :end_inline_rjhSetAutoRespond } true;test_~op2~0#1 := 1; {8474#false} is VALID [2022-02-20 17:56:06,566 INFO L290 TraceCheckUtils]: 53: Hoare triple {8474#false} assume !false; {8474#false} is VALID [2022-02-20 17:56:06,566 INFO L290 TraceCheckUtils]: 54: Hoare triple {8474#false} assume !(test_~splverifierCounter~0#1 < 4); {8474#false} is VALID [2022-02-20 17:56:06,566 INFO L290 TraceCheckUtils]: 55: Hoare triple {8474#false} assume { :begin_inline_bobToRjh } true;havoc bobToRjh_#t~ret90#1, bobToRjh_#t~ret91#1, bobToRjh_#t~ret92#1, bobToRjh_#t~ret93#1, bobToRjh_~tmp~23#1, bobToRjh_~tmp___0~7#1, bobToRjh_~tmp___1~4#1;havoc bobToRjh_~tmp~23#1;havoc bobToRjh_~tmp___0~7#1;havoc bobToRjh_~tmp___1~4#1;call bobToRjh_#t~ret90#1 := puts(32, 0);assume -2147483648 <= bobToRjh_#t~ret90#1 && bobToRjh_#t~ret90#1 <= 2147483647;havoc bobToRjh_#t~ret90#1; {8474#false} is VALID [2022-02-20 17:56:06,566 INFO L272 TraceCheckUtils]: 56: Hoare triple {8474#false} call sendEmail(~bob~0, ~rjh~0); {8474#false} is VALID [2022-02-20 17:56:06,566 INFO L290 TraceCheckUtils]: 57: Hoare triple {8474#false} ~sender#1 := #in~sender#1;~receiver#1 := #in~receiver#1;havoc ~email~0#1;havoc ~tmp~16#1;assume { :begin_inline_createEmail } true;createEmail_#in~from#1, createEmail_#in~to#1 := 0, ~receiver#1;havoc createEmail_#res#1;havoc createEmail_~from#1, createEmail_~to#1, createEmail_~retValue_acc~4#1, createEmail_~msg~0#1;createEmail_~from#1 := createEmail_#in~from#1;createEmail_~to#1 := createEmail_#in~to#1;havoc createEmail_~retValue_acc~4#1;havoc createEmail_~msg~0#1;createEmail_~msg~0#1 := 1; {8474#false} is VALID [2022-02-20 17:56:06,567 INFO L272 TraceCheckUtils]: 58: Hoare triple {8474#false} call setEmailFrom(createEmail_~msg~0#1, createEmail_~from#1); {8533#(and (= |old(~__ste_email_from0~0)| ~__ste_email_from0~0) (= |old(~__ste_email_from1~0)| ~__ste_email_from1~0))} is VALID [2022-02-20 17:56:06,567 INFO L290 TraceCheckUtils]: 59: Hoare triple {8533#(and (= |old(~__ste_email_from0~0)| ~__ste_email_from0~0) (= |old(~__ste_email_from1~0)| ~__ste_email_from1~0))} ~handle := #in~handle;~value := #in~value; {8473#true} is VALID [2022-02-20 17:56:06,567 INFO L290 TraceCheckUtils]: 60: Hoare triple {8473#true} assume 1 == ~handle;~__ste_email_from0~0 := ~value; {8473#true} is VALID [2022-02-20 17:56:06,567 INFO L290 TraceCheckUtils]: 61: Hoare triple {8473#true} assume true; {8473#true} is VALID [2022-02-20 17:56:06,567 INFO L284 TraceCheckUtils]: 62: Hoare quadruple {8473#true} {8474#false} #1119#return; {8474#false} is VALID [2022-02-20 17:56:06,567 INFO L272 TraceCheckUtils]: 63: Hoare triple {8474#false} call setEmailTo(createEmail_~msg~0#1, createEmail_~to#1); {8534#(and (= ~__ste_email_to0~0 |old(~__ste_email_to0~0)|) (= ~__ste_email_to1~0 |old(~__ste_email_to1~0)|))} is VALID [2022-02-20 17:56:06,567 INFO L290 TraceCheckUtils]: 64: Hoare triple {8534#(and (= ~__ste_email_to0~0 |old(~__ste_email_to0~0)|) (= ~__ste_email_to1~0 |old(~__ste_email_to1~0)|))} ~handle := #in~handle;~value := #in~value; {8473#true} is VALID [2022-02-20 17:56:06,567 INFO L290 TraceCheckUtils]: 65: Hoare triple {8473#true} assume 1 == ~handle;~__ste_email_to0~0 := ~value; {8473#true} is VALID [2022-02-20 17:56:06,567 INFO L290 TraceCheckUtils]: 66: Hoare triple {8473#true} assume true; {8473#true} is VALID [2022-02-20 17:56:06,567 INFO L284 TraceCheckUtils]: 67: Hoare quadruple {8473#true} {8474#false} #1121#return; {8474#false} is VALID [2022-02-20 17:56:06,568 INFO L290 TraceCheckUtils]: 68: Hoare triple {8474#false} createEmail_~retValue_acc~4#1 := createEmail_~msg~0#1;createEmail_#res#1 := createEmail_~retValue_acc~4#1; {8474#false} is VALID [2022-02-20 17:56:06,568 INFO L290 TraceCheckUtils]: 69: Hoare triple {8474#false} #t~ret73#1 := createEmail_#res#1;assume { :end_inline_createEmail } true;assume -2147483648 <= #t~ret73#1 && #t~ret73#1 <= 2147483647;~tmp~16#1 := #t~ret73#1;havoc #t~ret73#1;~email~0#1 := ~tmp~16#1; {8474#false} is VALID [2022-02-20 17:56:06,568 INFO L272 TraceCheckUtils]: 70: Hoare triple {8474#false} call outgoing(~sender#1, ~email~0#1); {8474#false} is VALID [2022-02-20 17:56:06,569 INFO L290 TraceCheckUtils]: 71: Hoare triple {8474#false} ~client#1 := #in~client#1;~msg#1 := #in~msg#1;assume { :begin_inline_sign } true;sign_#in~client#1, sign_#in~msg#1 := ~client#1, ~msg#1;havoc sign_#t~ret77#1, sign_~client#1, sign_~msg#1, sign_~privkey~1#1, sign_~tmp~18#1;sign_~client#1 := sign_#in~client#1;sign_~msg#1 := sign_#in~msg#1;havoc sign_~privkey~1#1;havoc sign_~tmp~18#1; {8474#false} is VALID [2022-02-20 17:56:06,569 INFO L272 TraceCheckUtils]: 72: Hoare triple {8474#false} call sign_#t~ret77#1 := getClientPrivateKey(sign_~client#1); {8473#true} is VALID [2022-02-20 17:56:06,569 INFO L290 TraceCheckUtils]: 73: Hoare triple {8473#true} ~handle := #in~handle;havoc ~retValue_acc~24; {8473#true} is VALID [2022-02-20 17:56:06,569 INFO L290 TraceCheckUtils]: 74: Hoare triple {8473#true} assume 1 == ~handle;~retValue_acc~24 := ~__ste_client_privateKey0~0;#res := ~retValue_acc~24; {8473#true} is VALID [2022-02-20 17:56:06,569 INFO L290 TraceCheckUtils]: 75: Hoare triple {8473#true} assume true; {8473#true} is VALID [2022-02-20 17:56:06,577 INFO L284 TraceCheckUtils]: 76: Hoare quadruple {8473#true} {8474#false} #1053#return; {8474#false} is VALID [2022-02-20 17:56:06,577 INFO L290 TraceCheckUtils]: 77: Hoare triple {8474#false} assume -2147483648 <= sign_#t~ret77#1 && sign_#t~ret77#1 <= 2147483647;sign_~tmp~18#1 := sign_#t~ret77#1;havoc sign_#t~ret77#1;sign_~privkey~1#1 := sign_~tmp~18#1; {8474#false} is VALID [2022-02-20 17:56:06,577 INFO L290 TraceCheckUtils]: 78: Hoare triple {8474#false} assume 0 == sign_~privkey~1#1; {8474#false} is VALID [2022-02-20 17:56:06,577 INFO L290 TraceCheckUtils]: 79: Hoare triple {8474#false} assume { :end_inline_sign } true;assume { :begin_inline_outgoing__wrappee__AutoResponder } true;outgoing__wrappee__AutoResponder_#in~client#1, outgoing__wrappee__AutoResponder_#in~msg#1 := ~client#1, ~msg#1;havoc outgoing__wrappee__AutoResponder_#t~ret63#1, outgoing__wrappee__AutoResponder_#t~ret64#1, outgoing__wrappee__AutoResponder_~client#1, outgoing__wrappee__AutoResponder_~msg#1, outgoing__wrappee__AutoResponder_~receiver~0#1, outgoing__wrappee__AutoResponder_~tmp~11#1, outgoing__wrappee__AutoResponder_~pubkey~0#1, outgoing__wrappee__AutoResponder_~tmp___0~4#1;outgoing__wrappee__AutoResponder_~client#1 := outgoing__wrappee__AutoResponder_#in~client#1;outgoing__wrappee__AutoResponder_~msg#1 := outgoing__wrappee__AutoResponder_#in~msg#1;havoc outgoing__wrappee__AutoResponder_~receiver~0#1;havoc outgoing__wrappee__AutoResponder_~tmp~11#1;havoc outgoing__wrappee__AutoResponder_~pubkey~0#1;havoc outgoing__wrappee__AutoResponder_~tmp___0~4#1; {8474#false} is VALID [2022-02-20 17:56:06,577 INFO L272 TraceCheckUtils]: 80: Hoare triple {8474#false} call outgoing__wrappee__AutoResponder_#t~ret63#1 := getEmailTo(outgoing__wrappee__AutoResponder_~msg#1); {8473#true} is VALID [2022-02-20 17:56:06,577 INFO L290 TraceCheckUtils]: 81: Hoare triple {8473#true} ~handle := #in~handle;havoc ~retValue_acc~36; {8473#true} is VALID [2022-02-20 17:56:06,578 INFO L290 TraceCheckUtils]: 82: Hoare triple {8473#true} assume 1 == ~handle;~retValue_acc~36 := ~__ste_email_to0~0;#res := ~retValue_acc~36; {8473#true} is VALID [2022-02-20 17:56:06,578 INFO L290 TraceCheckUtils]: 83: Hoare triple {8473#true} assume true; {8473#true} is VALID [2022-02-20 17:56:06,578 INFO L284 TraceCheckUtils]: 84: Hoare quadruple {8473#true} {8474#false} #1055#return; {8474#false} is VALID [2022-02-20 17:56:06,578 INFO L290 TraceCheckUtils]: 85: Hoare triple {8474#false} assume -2147483648 <= outgoing__wrappee__AutoResponder_#t~ret63#1 && outgoing__wrappee__AutoResponder_#t~ret63#1 <= 2147483647;outgoing__wrappee__AutoResponder_~tmp~11#1 := outgoing__wrappee__AutoResponder_#t~ret63#1;havoc outgoing__wrappee__AutoResponder_#t~ret63#1;outgoing__wrappee__AutoResponder_~receiver~0#1 := outgoing__wrappee__AutoResponder_~tmp~11#1; {8474#false} is VALID [2022-02-20 17:56:06,578 INFO L272 TraceCheckUtils]: 86: Hoare triple {8474#false} call outgoing__wrappee__AutoResponder_#t~ret64#1 := findPublicKey(outgoing__wrappee__AutoResponder_~client#1, outgoing__wrappee__AutoResponder_~receiver~0#1); {8473#true} is VALID [2022-02-20 17:56:06,578 INFO L290 TraceCheckUtils]: 87: Hoare triple {8473#true} ~handle := #in~handle;~userid := #in~userid;havoc ~retValue_acc~29; {8473#true} is VALID [2022-02-20 17:56:06,578 INFO L290 TraceCheckUtils]: 88: Hoare triple {8473#true} assume 1 == ~handle; {8473#true} is VALID [2022-02-20 17:56:06,578 INFO L290 TraceCheckUtils]: 89: Hoare triple {8473#true} assume ~userid == ~__ste_Client_Keyring0_User0~0;~retValue_acc~29 := ~__ste_Client_Keyring0_PublicKey0~0;#res := ~retValue_acc~29; {8473#true} is VALID [2022-02-20 17:56:06,578 INFO L290 TraceCheckUtils]: 90: Hoare triple {8473#true} assume true; {8473#true} is VALID [2022-02-20 17:56:06,578 INFO L284 TraceCheckUtils]: 91: Hoare quadruple {8473#true} {8474#false} #1057#return; {8474#false} is VALID [2022-02-20 17:56:06,579 INFO L290 TraceCheckUtils]: 92: Hoare triple {8474#false} assume -2147483648 <= outgoing__wrappee__AutoResponder_#t~ret64#1 && outgoing__wrappee__AutoResponder_#t~ret64#1 <= 2147483647;outgoing__wrappee__AutoResponder_~tmp___0~4#1 := outgoing__wrappee__AutoResponder_#t~ret64#1;havoc outgoing__wrappee__AutoResponder_#t~ret64#1;outgoing__wrappee__AutoResponder_~pubkey~0#1 := outgoing__wrappee__AutoResponder_~tmp___0~4#1; {8474#false} is VALID [2022-02-20 17:56:06,579 INFO L290 TraceCheckUtils]: 93: Hoare triple {8474#false} assume !(0 != outgoing__wrappee__AutoResponder_~pubkey~0#1); {8474#false} is VALID [2022-02-20 17:56:06,579 INFO L290 TraceCheckUtils]: 94: Hoare triple {8474#false} assume { :begin_inline_outgoing__wrappee__Keys } true;outgoing__wrappee__Keys_#in~client#1, outgoing__wrappee__Keys_#in~msg#1 := outgoing__wrappee__AutoResponder_~client#1, outgoing__wrappee__AutoResponder_~msg#1;havoc outgoing__wrappee__Keys_#t~ret62#1, outgoing__wrappee__Keys_~client#1, outgoing__wrappee__Keys_~msg#1, outgoing__wrappee__Keys_~tmp~10#1;outgoing__wrappee__Keys_~client#1 := outgoing__wrappee__Keys_#in~client#1;outgoing__wrappee__Keys_~msg#1 := outgoing__wrappee__Keys_#in~msg#1;havoc outgoing__wrappee__Keys_~tmp~10#1;assume { :begin_inline_getClientId } true;getClientId_#in~handle#1 := outgoing__wrappee__Keys_~client#1;havoc getClientId_#res#1;havoc getClientId_~handle#1, getClientId_~retValue_acc~31#1;getClientId_~handle#1 := getClientId_#in~handle#1;havoc getClientId_~retValue_acc~31#1; {8474#false} is VALID [2022-02-20 17:56:06,579 INFO L290 TraceCheckUtils]: 95: Hoare triple {8474#false} assume 1 == getClientId_~handle#1;getClientId_~retValue_acc~31#1 := ~__ste_client_idCounter0~0;getClientId_#res#1 := getClientId_~retValue_acc~31#1; {8474#false} is VALID [2022-02-20 17:56:06,579 INFO L290 TraceCheckUtils]: 96: Hoare triple {8474#false} outgoing__wrappee__Keys_#t~ret62#1 := getClientId_#res#1;assume { :end_inline_getClientId } true;assume -2147483648 <= outgoing__wrappee__Keys_#t~ret62#1 && outgoing__wrappee__Keys_#t~ret62#1 <= 2147483647;outgoing__wrappee__Keys_~tmp~10#1 := outgoing__wrappee__Keys_#t~ret62#1;havoc outgoing__wrappee__Keys_#t~ret62#1; {8474#false} is VALID [2022-02-20 17:56:06,579 INFO L272 TraceCheckUtils]: 97: Hoare triple {8474#false} call setEmailFrom(outgoing__wrappee__Keys_~msg#1, outgoing__wrappee__Keys_~tmp~10#1); {8533#(and (= |old(~__ste_email_from0~0)| ~__ste_email_from0~0) (= |old(~__ste_email_from1~0)| ~__ste_email_from1~0))} is VALID [2022-02-20 17:56:06,579 INFO L290 TraceCheckUtils]: 98: Hoare triple {8533#(and (= |old(~__ste_email_from0~0)| ~__ste_email_from0~0) (= |old(~__ste_email_from1~0)| ~__ste_email_from1~0))} ~handle := #in~handle;~value := #in~value; {8473#true} is VALID [2022-02-20 17:56:06,579 INFO L290 TraceCheckUtils]: 99: Hoare triple {8473#true} assume 1 == ~handle;~__ste_email_from0~0 := ~value; {8473#true} is VALID [2022-02-20 17:56:06,579 INFO L290 TraceCheckUtils]: 100: Hoare triple {8473#true} assume true; {8473#true} is VALID [2022-02-20 17:56:06,580 INFO L284 TraceCheckUtils]: 101: Hoare quadruple {8473#true} {8474#false} #1063#return; {8474#false} is VALID [2022-02-20 17:56:06,580 INFO L290 TraceCheckUtils]: 102: Hoare triple {8474#false} assume { :begin_inline_mail } true;mail_#in~client#1, mail_#in~msg#1 := outgoing__wrappee__Keys_~client#1, outgoing__wrappee__Keys_~msg#1;havoc mail_#t~ret60#1, mail_#t~ret61#1, mail_~client#1, mail_~msg#1, mail_~__utac__ad__arg1~0#1, mail_~__utac__ad__arg2~0#1, mail_~tmp~9#1;mail_~client#1 := mail_#in~client#1;mail_~msg#1 := mail_#in~msg#1;havoc mail_~__utac__ad__arg1~0#1;havoc mail_~__utac__ad__arg2~0#1;havoc mail_~tmp~9#1;mail_~__utac__ad__arg1~0#1 := mail_~client#1;mail_~__utac__ad__arg2~0#1 := mail_~msg#1;assume { :begin_inline___utac_acc__AddressBookEncrypt_spec__1 } true;__utac_acc__AddressBookEncrypt_spec__1_#in~client#1, __utac_acc__AddressBookEncrypt_spec__1_#in~msg#1 := mail_~__utac__ad__arg1~0#1, mail_~__utac__ad__arg2~0#1;havoc __utac_acc__AddressBookEncrypt_spec__1_#t~ret85#1, __utac_acc__AddressBookEncrypt_spec__1_#t~ret86#1, __utac_acc__AddressBookEncrypt_spec__1_#t~ret87#1, __utac_acc__AddressBookEncrypt_spec__1_~client#1, __utac_acc__AddressBookEncrypt_spec__1_~msg#1, __utac_acc__AddressBookEncrypt_spec__1_~tmp~20#1;__utac_acc__AddressBookEncrypt_spec__1_~client#1 := __utac_acc__AddressBookEncrypt_spec__1_#in~client#1;__utac_acc__AddressBookEncrypt_spec__1_~msg#1 := __utac_acc__AddressBookEncrypt_spec__1_#in~msg#1;havoc __utac_acc__AddressBookEncrypt_spec__1_~tmp~20#1;call __utac_acc__AddressBookEncrypt_spec__1_#t~ret85#1 := puts(31, 0);assume -2147483648 <= __utac_acc__AddressBookEncrypt_spec__1_#t~ret85#1 && __utac_acc__AddressBookEncrypt_spec__1_#t~ret85#1 <= 2147483647;havoc __utac_acc__AddressBookEncrypt_spec__1_#t~ret85#1; {8474#false} is VALID [2022-02-20 17:56:06,580 INFO L290 TraceCheckUtils]: 103: Hoare triple {8474#false} assume !(-1 == ~mail_is_sensitive~0); {8474#false} is VALID [2022-02-20 17:56:06,580 INFO L272 TraceCheckUtils]: 104: Hoare triple {8474#false} call __utac_acc__AddressBookEncrypt_spec__1_#t~ret87#1 := isEncrypted(__utac_acc__AddressBookEncrypt_spec__1_~msg#1); {8473#true} is VALID [2022-02-20 17:56:06,580 INFO L290 TraceCheckUtils]: 105: Hoare triple {8473#true} ~handle := #in~handle;havoc ~retValue_acc~39; {8473#true} is VALID [2022-02-20 17:56:06,580 INFO L290 TraceCheckUtils]: 106: Hoare triple {8473#true} assume 1 == ~handle;~retValue_acc~39 := ~__ste_email_isEncrypted0~0;#res := ~retValue_acc~39; {8473#true} is VALID [2022-02-20 17:56:06,580 INFO L290 TraceCheckUtils]: 107: Hoare triple {8473#true} assume true; {8473#true} is VALID [2022-02-20 17:56:06,580 INFO L284 TraceCheckUtils]: 108: Hoare quadruple {8473#true} {8474#false} #1067#return; {8474#false} is VALID [2022-02-20 17:56:06,580 INFO L290 TraceCheckUtils]: 109: Hoare triple {8474#false} assume -2147483648 <= __utac_acc__AddressBookEncrypt_spec__1_#t~ret87#1 && __utac_acc__AddressBookEncrypt_spec__1_#t~ret87#1 <= 2147483647;__utac_acc__AddressBookEncrypt_spec__1_~tmp~20#1 := __utac_acc__AddressBookEncrypt_spec__1_#t~ret87#1;havoc __utac_acc__AddressBookEncrypt_spec__1_#t~ret87#1; {8474#false} is VALID [2022-02-20 17:56:06,581 INFO L290 TraceCheckUtils]: 110: Hoare triple {8474#false} assume ~mail_is_sensitive~0 != __utac_acc__AddressBookEncrypt_spec__1_~tmp~20#1;assume { :begin_inline___automaton_fail } true; {8474#false} is VALID [2022-02-20 17:56:06,581 INFO L290 TraceCheckUtils]: 111: Hoare triple {8474#false} assume !false; {8474#false} is VALID [2022-02-20 17:56:06,581 INFO L134 CoverageAnalysis]: Checked inductivity of 30 backedges. 3 proven. 3 refuted. 0 times theorem prover too weak. 24 trivial. 0 not checked. [2022-02-20 17:56:06,584 INFO L144 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2022-02-20 17:56:06,584 INFO L338 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [933747117] [2022-02-20 17:56:06,584 INFO L165 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [933747117] provided 0 perfect and 1 imperfect interpolant sequences [2022-02-20 17:56:06,585 INFO L338 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleZ3 [596554799] [2022-02-20 17:56:06,585 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-02-20 17:56:06,585 INFO L173 SolverBuilder]: Constructing external solver with command: z3 -smt2 -in SMTLIB2_COMPLIANT=true [2022-02-20 17:56:06,585 INFO L189 MonitoredProcess]: No working directory specified, using /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 [2022-02-20 17:56:06,586 INFO L229 MonitoredProcess]: Starting monitored process 5 with /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 -smt2 -in SMTLIB2_COMPLIANT=true (exit command is (exit), workingDir is null) [2022-02-20 17:56:06,587 INFO L327 MonitoredProcess]: [MP /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 -smt2 -in SMTLIB2_COMPLIANT=true (5)] Waiting until timeout for monitored process [2022-02-20 17:56:06,780 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-02-20 17:56:06,783 INFO L263 TraceCheckSpWp]: Trace formula consists of 1090 conjuncts, 8 conjunts are in the unsatisfiable core [2022-02-20 17:56:06,831 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-02-20 17:56:06,833 INFO L286 TraceCheckSpWp]: Computing forward predicates... [2022-02-20 17:56:07,141 INFO L290 TraceCheckUtils]: 0: Hoare triple {8473#true} assume { :begin_inline_ULTIMATE.init } true;#NULL.base, #NULL.offset := 0, 0;assume 0 == #valid[0];assume 0 < #StackHeapBarrier;call #Ultimate.allocInit(2, 1);call write~init~int(48, 1, 0, 1);call write~init~int(0, 1, 1, 1);call #Ultimate.allocInit(28, 2);call #Ultimate.allocInit(12, 3);call #Ultimate.allocInit(4, 4);call write~init~int(37, 4, 0, 1);call write~init~int(115, 4, 1, 1);call write~init~int(10, 4, 2, 1);call write~init~int(0, 4, 3, 1);call #Ultimate.allocInit(10, 5);call #Ultimate.allocInit(12, 6);call #Ultimate.allocInit(10, 7);call #Ultimate.allocInit(18, 8);call #Ultimate.allocInit(16, 9);call #Ultimate.allocInit(21, 10);call #Ultimate.allocInit(13, 11);call #Ultimate.allocInit(16, 12);call #Ultimate.allocInit(25, 13);call #Ultimate.allocInit(30, 14);call #Ultimate.allocInit(9, 15);call #Ultimate.allocInit(21, 16);call #Ultimate.allocInit(30, 17);call #Ultimate.allocInit(9, 18);call #Ultimate.allocInit(21, 19);call #Ultimate.allocInit(30, 20);call #Ultimate.allocInit(9, 21);call #Ultimate.allocInit(25, 22);call #Ultimate.allocInit(30, 23);call #Ultimate.allocInit(9, 24);call #Ultimate.allocInit(25, 25);call #Ultimate.allocInit(10, 26);call #Ultimate.allocInit(16, 27);call #Ultimate.allocInit(20, 28);call #Ultimate.allocInit(22, 29);call #Ultimate.allocInit(21, 30);call #Ultimate.allocInit(13, 31);call #Ultimate.allocInit(44, 32);call #Ultimate.allocInit(44, 33);call #Ultimate.allocInit(9, 34);call #Ultimate.allocInit(9, 35);call #Ultimate.allocInit(11, 36);call #Ultimate.allocInit(19, 37);call #Ultimate.allocInit(4, 38);call write~init~int(37, 38, 0, 1);call write~init~int(100, 38, 1, 1);call write~init~int(10, 38, 2, 1);call write~init~int(0, 38, 3, 1);call #Ultimate.allocInit(4, 39);call write~init~int(37, 39, 0, 1);call write~init~int(100, 39, 1, 1);call write~init~int(10, 39, 2, 1);call write~init~int(0, 39, 3, 1);~__SELECTED_FEATURE_Base~0 := 0;~__SELECTED_FEATURE_Keys~0 := 0;~__SELECTED_FEATURE_Encrypt~0 := 0;~__SELECTED_FEATURE_AutoResponder~0 := 0;~__SELECTED_FEATURE_AddressBook~0 := 0;~__SELECTED_FEATURE_Sign~0 := 0;~__SELECTED_FEATURE_Forward~0 := 0;~__SELECTED_FEATURE_Verify~0 := 0;~__SELECTED_FEATURE_Decrypt~0 := 0;~__GUIDSL_ROOT_PRODUCTION~0 := 0;~__GUIDSL_NON_TERMINAL_main~0 := 0;~head~0.base, ~head~0.offset := 0, 0;~queue_empty~0 := 1;~queued_message~0 := 0;~queued_client~0 := 0;~mail_is_sensitive~0 := -1;~__ste_Client_counter~0 := 0;~__ste_client_name0~0.base, ~__ste_client_name0~0.offset := 0, 0;~__ste_client_name1~0.base, ~__ste_client_name1~0.offset := 0, 0;~__ste_client_name2~0.base, ~__ste_client_name2~0.offset := 0, 0;~__ste_client_outbuffer0~0 := 0;~__ste_client_outbuffer1~0 := 0;~__ste_client_outbuffer2~0 := 0;~__ste_client_outbuffer3~0 := 0;~__ste_ClientAddressBook_size0~0 := 0;~__ste_ClientAddressBook_size1~0 := 0;~__ste_ClientAddressBook_size2~0 := 0;~__ste_Client_AddressBook0_Alias0~0 := 0;~__ste_Client_AddressBook0_Alias1~0 := 0;~__ste_Client_AddressBook0_Alias2~0 := 0;~__ste_Client_AddressBook1_Alias0~0 := 0;~__ste_Client_AddressBook1_Alias1~0 := 0;~__ste_Client_AddressBook1_Alias2~0 := 0;~__ste_Client_AddressBook2_Alias0~0 := 0;~__ste_Client_AddressBook2_Alias1~0 := 0;~__ste_Client_AddressBook2_Alias2~0 := 0;~__ste_Client_AddressBook0_Address0~0 := 0;~__ste_Client_AddressBook0_Address1~0 := 0;~__ste_Client_AddressBook0_Address2~0 := 0;~__ste_Client_AddressBook1_Address0~0 := 0;~__ste_Client_AddressBook1_Address1~0 := 0;~__ste_Client_AddressBook1_Address2~0 := 0;~__ste_Client_AddressBook2_Address0~0 := 0;~__ste_Client_AddressBook2_Address1~0 := 0;~__ste_Client_AddressBook2_Address2~0 := 0;~__ste_client_autoResponse0~0 := 0;~__ste_client_autoResponse1~0 := 0;~__ste_client_autoResponse2~0 := 0;~__ste_client_privateKey0~0 := 0;~__ste_client_privateKey1~0 := 0;~__ste_client_privateKey2~0 := 0;~__ste_ClientKeyring_size0~0 := 0;~__ste_ClientKeyring_size1~0 := 0;~__ste_ClientKeyring_size2~0 := 0;~__ste_Client_Keyring0_User0~0 := 0;~__ste_Client_Keyring0_User1~0 := 0;~__ste_Client_Keyring0_User2~0 := 0;~__ste_Client_Keyring1_User0~0 := 0;~__ste_Client_Keyring1_User1~0 := 0;~__ste_Client_Keyring1_User2~0 := 0;~__ste_Client_Keyring2_User0~0 := 0;~__ste_Client_Keyring2_User1~0 := 0;~__ste_Client_Keyring2_User2~0 := 0;~__ste_Client_Keyring0_PublicKey0~0 := 0;~__ste_Client_Keyring0_PublicKey1~0 := 0;~__ste_Client_Keyring0_PublicKey2~0 := 0;~__ste_Client_Keyring1_PublicKey0~0 := 0;~__ste_Client_Keyring1_PublicKey1~0 := 0;~__ste_Client_Keyring1_PublicKey2~0 := 0;~__ste_Client_Keyring2_PublicKey0~0 := 0;~__ste_Client_Keyring2_PublicKey1~0 := 0;~__ste_Client_Keyring2_PublicKey2~0 := 0;~__ste_client_forwardReceiver0~0 := 0;~__ste_client_forwardReceiver1~0 := 0;~__ste_client_forwardReceiver2~0 := 0;~__ste_client_forwardReceiver3~0 := 0;~__ste_client_idCounter0~0 := 0;~__ste_client_idCounter1~0 := 0;~__ste_client_idCounter2~0 := 0;~bob~0 := 0;~rjh~0 := 0;~chuck~0 := 0;~__ste_Email_counter~0 := 0;~__ste_email_id0~0 := 0;~__ste_email_id1~0 := 0;~__ste_email_from0~0 := 0;~__ste_email_from1~0 := 0;~__ste_email_to0~0 := 0;~__ste_email_to1~0 := 0;~__ste_email_subject0~0.base, ~__ste_email_subject0~0.offset := 0, 0;~__ste_email_subject1~0.base, ~__ste_email_subject1~0.offset := 0, 0;~__ste_email_body0~0.base, ~__ste_email_body0~0.offset := 0, 0;~__ste_email_body1~0.base, ~__ste_email_body1~0.offset := 0, 0;~__ste_email_isEncrypted0~0 := 0;~__ste_email_isEncrypted1~0 := 0;~__ste_email_encryptionKey0~0 := 0;~__ste_email_encryptionKey1~0 := 0;~__ste_email_isSigned0~0 := 0;~__ste_email_isSigned1~0 := 0;~__ste_email_signKey0~0 := 0;~__ste_email_signKey1~0 := 0;~__ste_email_isSignatureVerified0~0 := 0;~__ste_email_isSignatureVerified1~0 := 0; {8473#true} is VALID [2022-02-20 17:56:07,142 INFO L290 TraceCheckUtils]: 1: Hoare triple {8473#true} assume { :end_inline_ULTIMATE.init } true;assume { :begin_inline_main } true;havoc main_#res#1;havoc main_#t~ret98#1, main_~retValue_acc~32#1, main_~tmp~24#1;havoc main_~retValue_acc~32#1;havoc main_~tmp~24#1;assume { :begin_inline_select_helpers } true; {8473#true} is VALID [2022-02-20 17:56:07,142 INFO L290 TraceCheckUtils]: 2: Hoare triple {8473#true} assume { :end_inline_select_helpers } true;assume { :begin_inline_select_features } true; {8473#true} is VALID [2022-02-20 17:56:07,142 INFO L290 TraceCheckUtils]: 3: Hoare triple {8473#true} assume { :end_inline_select_features } true;assume { :begin_inline_valid_product } true;havoc valid_product_#res#1;havoc valid_product_~retValue_acc~9#1;havoc valid_product_~retValue_acc~9#1;valid_product_~retValue_acc~9#1 := 1;valid_product_#res#1 := valid_product_~retValue_acc~9#1; {8473#true} is VALID [2022-02-20 17:56:07,142 INFO L290 TraceCheckUtils]: 4: Hoare triple {8473#true} main_#t~ret98#1 := valid_product_#res#1;assume { :end_inline_valid_product } true;assume -2147483648 <= main_#t~ret98#1 && main_#t~ret98#1 <= 2147483647;main_~tmp~24#1 := main_#t~ret98#1;havoc main_#t~ret98#1; {8473#true} is VALID [2022-02-20 17:56:07,142 INFO L290 TraceCheckUtils]: 5: Hoare triple {8473#true} assume 0 != main_~tmp~24#1;assume { :begin_inline_setup } true;havoc setup_#t~nondet95#1, setup_#t~nondet96#1, setup_#t~nondet97#1, setup_~__cil_tmp1~0#1.base, setup_~__cil_tmp1~0#1.offset, setup_~__cil_tmp2~0#1.base, setup_~__cil_tmp2~0#1.offset, setup_~__cil_tmp3~2#1.base, setup_~__cil_tmp3~2#1.offset;havoc setup_~__cil_tmp1~0#1.base, setup_~__cil_tmp1~0#1.offset;havoc setup_~__cil_tmp2~0#1.base, setup_~__cil_tmp2~0#1.offset;havoc setup_~__cil_tmp3~2#1.base, setup_~__cil_tmp3~2#1.offset;~bob~0 := 1;assume { :begin_inline_setup_bob } true;setup_bob_#in~bob___0#1 := ~bob~0;havoc setup_bob_~bob___0#1;setup_bob_~bob___0#1 := setup_bob_#in~bob___0#1;assume { :begin_inline_setup_bob__wrappee__Base } true;setup_bob__wrappee__Base_#in~bob___0#1 := setup_bob_~bob___0#1;havoc setup_bob__wrappee__Base_~bob___0#1;setup_bob__wrappee__Base_~bob___0#1 := setup_bob__wrappee__Base_#in~bob___0#1; {8473#true} is VALID [2022-02-20 17:56:07,142 INFO L272 TraceCheckUtils]: 6: Hoare triple {8473#true} call setClientId(setup_bob__wrappee__Base_~bob___0#1, setup_bob__wrappee__Base_~bob___0#1); {8473#true} is VALID [2022-02-20 17:56:07,142 INFO L290 TraceCheckUtils]: 7: Hoare triple {8473#true} ~handle := #in~handle;~value := #in~value; {8473#true} is VALID [2022-02-20 17:56:07,142 INFO L290 TraceCheckUtils]: 8: Hoare triple {8473#true} assume 1 == ~handle;~__ste_client_idCounter0~0 := ~value; {8473#true} is VALID [2022-02-20 17:56:07,142 INFO L290 TraceCheckUtils]: 9: Hoare triple {8473#true} assume true; {8473#true} is VALID [2022-02-20 17:56:07,142 INFO L284 TraceCheckUtils]: 10: Hoare quadruple {8473#true} {8473#true} #1133#return; {8473#true} is VALID [2022-02-20 17:56:07,142 INFO L290 TraceCheckUtils]: 11: Hoare triple {8473#true} assume { :end_inline_setup_bob__wrappee__Base } true; {8473#true} is VALID [2022-02-20 17:56:07,142 INFO L272 TraceCheckUtils]: 12: Hoare triple {8473#true} call setClientPrivateKey(setup_bob_~bob___0#1, 123); {8473#true} is VALID [2022-02-20 17:56:07,142 INFO L290 TraceCheckUtils]: 13: Hoare triple {8473#true} ~handle := #in~handle;~value := #in~value; {8473#true} is VALID [2022-02-20 17:56:07,142 INFO L290 TraceCheckUtils]: 14: Hoare triple {8473#true} assume 1 == ~handle;~__ste_client_privateKey0~0 := ~value; {8473#true} is VALID [2022-02-20 17:56:07,142 INFO L290 TraceCheckUtils]: 15: Hoare triple {8473#true} assume true; {8473#true} is VALID [2022-02-20 17:56:07,142 INFO L284 TraceCheckUtils]: 16: Hoare quadruple {8473#true} {8473#true} #1135#return; {8473#true} is VALID [2022-02-20 17:56:07,143 INFO L290 TraceCheckUtils]: 17: Hoare triple {8473#true} assume { :end_inline_setup_bob } true;setup_~__cil_tmp1~0#1.base, setup_~__cil_tmp1~0#1.offset := 34, 0;havoc setup_#t~nondet95#1;~rjh~0 := 2;assume { :begin_inline_setup_rjh } true;setup_rjh_#in~rjh___0#1 := ~rjh~0;havoc setup_rjh_~rjh___0#1;setup_rjh_~rjh___0#1 := setup_rjh_#in~rjh___0#1;assume { :begin_inline_setup_rjh__wrappee__Base } true;setup_rjh__wrappee__Base_#in~rjh___0#1 := setup_rjh_~rjh___0#1;havoc setup_rjh__wrappee__Base_~rjh___0#1;setup_rjh__wrappee__Base_~rjh___0#1 := setup_rjh__wrappee__Base_#in~rjh___0#1; {8589#(<= 2 |ULTIMATE.start_setup_rjh__wrappee__Base_~rjh___0#1|)} is VALID [2022-02-20 17:56:07,143 INFO L272 TraceCheckUtils]: 18: Hoare triple {8589#(<= 2 |ULTIMATE.start_setup_rjh__wrappee__Base_~rjh___0#1|)} call setClientId(setup_rjh__wrappee__Base_~rjh___0#1, setup_rjh__wrappee__Base_~rjh___0#1); {8473#true} is VALID [2022-02-20 17:56:07,143 INFO L290 TraceCheckUtils]: 19: Hoare triple {8473#true} ~handle := #in~handle;~value := #in~value; {8596#(<= |setClientId_#in~handle| setClientId_~handle)} is VALID [2022-02-20 17:56:07,144 INFO L290 TraceCheckUtils]: 20: Hoare triple {8596#(<= |setClientId_#in~handle| setClientId_~handle)} assume 1 == ~handle;~__ste_client_idCounter0~0 := ~value; {8600#(<= |setClientId_#in~handle| 1)} is VALID [2022-02-20 17:56:07,144 INFO L290 TraceCheckUtils]: 21: Hoare triple {8600#(<= |setClientId_#in~handle| 1)} assume true; {8600#(<= |setClientId_#in~handle| 1)} is VALID [2022-02-20 17:56:07,144 INFO L284 TraceCheckUtils]: 22: Hoare quadruple {8600#(<= |setClientId_#in~handle| 1)} {8589#(<= 2 |ULTIMATE.start_setup_rjh__wrappee__Base_~rjh___0#1|)} #1137#return; {8474#false} is VALID [2022-02-20 17:56:07,144 INFO L290 TraceCheckUtils]: 23: Hoare triple {8474#false} assume { :end_inline_setup_rjh__wrappee__Base } true; {8474#false} is VALID [2022-02-20 17:56:07,144 INFO L272 TraceCheckUtils]: 24: Hoare triple {8474#false} call setClientPrivateKey(setup_rjh_~rjh___0#1, 456); {8474#false} is VALID [2022-02-20 17:56:07,144 INFO L290 TraceCheckUtils]: 25: Hoare triple {8474#false} ~handle := #in~handle;~value := #in~value; {8474#false} is VALID [2022-02-20 17:56:07,149 INFO L290 TraceCheckUtils]: 26: Hoare triple {8474#false} assume 1 == ~handle;~__ste_client_privateKey0~0 := ~value; {8474#false} is VALID [2022-02-20 17:56:07,149 INFO L290 TraceCheckUtils]: 27: Hoare triple {8474#false} assume true; {8474#false} is VALID [2022-02-20 17:56:07,149 INFO L284 TraceCheckUtils]: 28: Hoare quadruple {8474#false} {8474#false} #1139#return; {8474#false} is VALID [2022-02-20 17:56:07,149 INFO L290 TraceCheckUtils]: 29: Hoare triple {8474#false} assume { :end_inline_setup_rjh } true;setup_~__cil_tmp2~0#1.base, setup_~__cil_tmp2~0#1.offset := 35, 0;havoc setup_#t~nondet96#1;~chuck~0 := 3;assume { :begin_inline_setup_chuck } true;setup_chuck_#in~chuck___0#1 := ~chuck~0;havoc setup_chuck_~chuck___0#1;setup_chuck_~chuck___0#1 := setup_chuck_#in~chuck___0#1;assume { :begin_inline_setup_chuck__wrappee__Base } true;setup_chuck__wrappee__Base_#in~chuck___0#1 := setup_chuck_~chuck___0#1;havoc setup_chuck__wrappee__Base_~chuck___0#1;setup_chuck__wrappee__Base_~chuck___0#1 := setup_chuck__wrappee__Base_#in~chuck___0#1; {8474#false} is VALID [2022-02-20 17:56:07,149 INFO L272 TraceCheckUtils]: 30: Hoare triple {8474#false} call setClientId(setup_chuck__wrappee__Base_~chuck___0#1, setup_chuck__wrappee__Base_~chuck___0#1); {8474#false} is VALID [2022-02-20 17:56:07,149 INFO L290 TraceCheckUtils]: 31: Hoare triple {8474#false} ~handle := #in~handle;~value := #in~value; {8474#false} is VALID [2022-02-20 17:56:07,149 INFO L290 TraceCheckUtils]: 32: Hoare triple {8474#false} assume 1 == ~handle;~__ste_client_idCounter0~0 := ~value; {8474#false} is VALID [2022-02-20 17:56:07,149 INFO L290 TraceCheckUtils]: 33: Hoare triple {8474#false} assume true; {8474#false} is VALID [2022-02-20 17:56:07,150 INFO L284 TraceCheckUtils]: 34: Hoare quadruple {8474#false} {8474#false} #1141#return; {8474#false} is VALID [2022-02-20 17:56:07,150 INFO L290 TraceCheckUtils]: 35: Hoare triple {8474#false} assume { :end_inline_setup_chuck__wrappee__Base } true; {8474#false} is VALID [2022-02-20 17:56:07,150 INFO L272 TraceCheckUtils]: 36: Hoare triple {8474#false} call setClientPrivateKey(setup_chuck_~chuck___0#1, 789); {8474#false} is VALID [2022-02-20 17:56:07,150 INFO L290 TraceCheckUtils]: 37: Hoare triple {8474#false} ~handle := #in~handle;~value := #in~value; {8474#false} is VALID [2022-02-20 17:56:07,150 INFO L290 TraceCheckUtils]: 38: Hoare triple {8474#false} assume 1 == ~handle;~__ste_client_privateKey0~0 := ~value; {8474#false} is VALID [2022-02-20 17:56:07,150 INFO L290 TraceCheckUtils]: 39: Hoare triple {8474#false} assume true; {8474#false} is VALID [2022-02-20 17:56:07,150 INFO L284 TraceCheckUtils]: 40: Hoare quadruple {8474#false} {8474#false} #1143#return; {8474#false} is VALID [2022-02-20 17:56:07,150 INFO L290 TraceCheckUtils]: 41: Hoare triple {8474#false} assume { :end_inline_setup_chuck } true;setup_~__cil_tmp3~2#1.base, setup_~__cil_tmp3~2#1.offset := 36, 0;havoc setup_#t~nondet97#1; {8474#false} is VALID [2022-02-20 17:56:07,150 INFO L290 TraceCheckUtils]: 42: Hoare triple {8474#false} assume { :end_inline_setup } true;assume { :begin_inline_test } true;havoc test_#t~nondet48#1, test_#t~nondet49#1, test_#t~nondet50#1, test_#t~nondet51#1, test_#t~nondet52#1, test_#t~nondet53#1, test_#t~nondet54#1, test_#t~nondet55#1, test_#t~nondet56#1, test_#t~nondet57#1, test_#t~nondet58#1, test_~op1~0#1, test_~op2~0#1, test_~op3~0#1, test_~op4~0#1, test_~op5~0#1, test_~op6~0#1, test_~op7~0#1, test_~op8~0#1, test_~op9~0#1, test_~op10~0#1, test_~op11~0#1, test_~splverifierCounter~0#1, test_~tmp~8#1, test_~tmp___0~3#1, test_~tmp___1~1#1, test_~tmp___2~1#1, test_~tmp___3~0#1, test_~tmp___4~0#1, test_~tmp___5~0#1, test_~tmp___6~0#1, test_~tmp___7~0#1, test_~tmp___8~0#1, test_~tmp___9~0#1;havoc test_~op1~0#1;havoc test_~op2~0#1;havoc test_~op3~0#1;havoc test_~op4~0#1;havoc test_~op5~0#1;havoc test_~op6~0#1;havoc test_~op7~0#1;havoc test_~op8~0#1;havoc test_~op9~0#1;havoc test_~op10~0#1;havoc test_~op11~0#1;havoc test_~splverifierCounter~0#1;havoc test_~tmp~8#1;havoc test_~tmp___0~3#1;havoc test_~tmp___1~1#1;havoc test_~tmp___2~1#1;havoc test_~tmp___3~0#1;havoc test_~tmp___4~0#1;havoc test_~tmp___5~0#1;havoc test_~tmp___6~0#1;havoc test_~tmp___7~0#1;havoc test_~tmp___8~0#1;havoc test_~tmp___9~0#1;test_~op1~0#1 := 0;test_~op2~0#1 := 0;test_~op3~0#1 := 0;test_~op4~0#1 := 0;test_~op5~0#1 := 0;test_~op6~0#1 := 0;test_~op7~0#1 := 0;test_~op8~0#1 := 0;test_~op9~0#1 := 0;test_~op10~0#1 := 0;test_~op11~0#1 := 0;test_~splverifierCounter~0#1 := 0; {8474#false} is VALID [2022-02-20 17:56:07,150 INFO L290 TraceCheckUtils]: 43: Hoare triple {8474#false} assume !false; {8474#false} is VALID [2022-02-20 17:56:07,151 INFO L290 TraceCheckUtils]: 44: Hoare triple {8474#false} assume test_~splverifierCounter~0#1 < 4; {8474#false} is VALID [2022-02-20 17:56:07,151 INFO L290 TraceCheckUtils]: 45: Hoare triple {8474#false} test_~splverifierCounter~0#1 := 1 + test_~splverifierCounter~0#1; {8474#false} is VALID [2022-02-20 17:56:07,151 INFO L290 TraceCheckUtils]: 46: Hoare triple {8474#false} assume 0 == test_~op1~0#1;assume -2147483648 <= test_#t~nondet48#1 && test_#t~nondet48#1 <= 2147483647;test_~tmp___9~0#1 := test_#t~nondet48#1;havoc test_#t~nondet48#1; {8474#false} is VALID [2022-02-20 17:56:07,151 INFO L290 TraceCheckUtils]: 47: Hoare triple {8474#false} assume !(0 != test_~tmp___9~0#1); {8474#false} is VALID [2022-02-20 17:56:07,151 INFO L290 TraceCheckUtils]: 48: Hoare triple {8474#false} assume 0 == test_~op2~0#1;assume -2147483648 <= test_#t~nondet49#1 && test_#t~nondet49#1 <= 2147483647;test_~tmp___8~0#1 := test_#t~nondet49#1;havoc test_#t~nondet49#1; {8474#false} is VALID [2022-02-20 17:56:07,151 INFO L290 TraceCheckUtils]: 49: Hoare triple {8474#false} assume 0 != test_~tmp___8~0#1;assume { :begin_inline_rjhSetAutoRespond } true;assume { :begin_inline_setClientAutoResponse } true;setClientAutoResponse_#in~handle#1, setClientAutoResponse_#in~value#1 := ~rjh~0, 1;havoc setClientAutoResponse_~handle#1, setClientAutoResponse_~value#1;setClientAutoResponse_~handle#1 := setClientAutoResponse_#in~handle#1;setClientAutoResponse_~value#1 := setClientAutoResponse_#in~value#1; {8474#false} is VALID [2022-02-20 17:56:07,151 INFO L290 TraceCheckUtils]: 50: Hoare triple {8474#false} assume 1 == setClientAutoResponse_~handle#1;~__ste_client_autoResponse0~0 := setClientAutoResponse_~value#1; {8474#false} is VALID [2022-02-20 17:56:07,151 INFO L290 TraceCheckUtils]: 51: Hoare triple {8474#false} assume { :end_inline_setClientAutoResponse } true; {8474#false} is VALID [2022-02-20 17:56:07,151 INFO L290 TraceCheckUtils]: 52: Hoare triple {8474#false} assume { :end_inline_rjhSetAutoRespond } true;test_~op2~0#1 := 1; {8474#false} is VALID [2022-02-20 17:56:07,152 INFO L290 TraceCheckUtils]: 53: Hoare triple {8474#false} assume !false; {8474#false} is VALID [2022-02-20 17:56:07,152 INFO L290 TraceCheckUtils]: 54: Hoare triple {8474#false} assume !(test_~splverifierCounter~0#1 < 4); {8474#false} is VALID [2022-02-20 17:56:07,152 INFO L290 TraceCheckUtils]: 55: Hoare triple {8474#false} assume { :begin_inline_bobToRjh } true;havoc bobToRjh_#t~ret90#1, bobToRjh_#t~ret91#1, bobToRjh_#t~ret92#1, bobToRjh_#t~ret93#1, bobToRjh_~tmp~23#1, bobToRjh_~tmp___0~7#1, bobToRjh_~tmp___1~4#1;havoc bobToRjh_~tmp~23#1;havoc bobToRjh_~tmp___0~7#1;havoc bobToRjh_~tmp___1~4#1;call bobToRjh_#t~ret90#1 := puts(32, 0);assume -2147483648 <= bobToRjh_#t~ret90#1 && bobToRjh_#t~ret90#1 <= 2147483647;havoc bobToRjh_#t~ret90#1; {8474#false} is VALID [2022-02-20 17:56:07,152 INFO L272 TraceCheckUtils]: 56: Hoare triple {8474#false} call sendEmail(~bob~0, ~rjh~0); {8474#false} is VALID [2022-02-20 17:56:07,152 INFO L290 TraceCheckUtils]: 57: Hoare triple {8474#false} ~sender#1 := #in~sender#1;~receiver#1 := #in~receiver#1;havoc ~email~0#1;havoc ~tmp~16#1;assume { :begin_inline_createEmail } true;createEmail_#in~from#1, createEmail_#in~to#1 := 0, ~receiver#1;havoc createEmail_#res#1;havoc createEmail_~from#1, createEmail_~to#1, createEmail_~retValue_acc~4#1, createEmail_~msg~0#1;createEmail_~from#1 := createEmail_#in~from#1;createEmail_~to#1 := createEmail_#in~to#1;havoc createEmail_~retValue_acc~4#1;havoc createEmail_~msg~0#1;createEmail_~msg~0#1 := 1; {8474#false} is VALID [2022-02-20 17:56:07,152 INFO L272 TraceCheckUtils]: 58: Hoare triple {8474#false} call setEmailFrom(createEmail_~msg~0#1, createEmail_~from#1); {8474#false} is VALID [2022-02-20 17:56:07,152 INFO L290 TraceCheckUtils]: 59: Hoare triple {8474#false} ~handle := #in~handle;~value := #in~value; {8474#false} is VALID [2022-02-20 17:56:07,153 INFO L290 TraceCheckUtils]: 60: Hoare triple {8474#false} assume 1 == ~handle;~__ste_email_from0~0 := ~value; {8474#false} is VALID [2022-02-20 17:56:07,154 INFO L290 TraceCheckUtils]: 61: Hoare triple {8474#false} assume true; {8474#false} is VALID [2022-02-20 17:56:07,154 INFO L284 TraceCheckUtils]: 62: Hoare quadruple {8474#false} {8474#false} #1119#return; {8474#false} is VALID [2022-02-20 17:56:07,154 INFO L272 TraceCheckUtils]: 63: Hoare triple {8474#false} call setEmailTo(createEmail_~msg~0#1, createEmail_~to#1); {8474#false} is VALID [2022-02-20 17:56:07,154 INFO L290 TraceCheckUtils]: 64: Hoare triple {8474#false} ~handle := #in~handle;~value := #in~value; {8474#false} is VALID [2022-02-20 17:56:07,154 INFO L290 TraceCheckUtils]: 65: Hoare triple {8474#false} assume 1 == ~handle;~__ste_email_to0~0 := ~value; {8474#false} is VALID [2022-02-20 17:56:07,154 INFO L290 TraceCheckUtils]: 66: Hoare triple {8474#false} assume true; {8474#false} is VALID [2022-02-20 17:56:07,154 INFO L284 TraceCheckUtils]: 67: Hoare quadruple {8474#false} {8474#false} #1121#return; {8474#false} is VALID [2022-02-20 17:56:07,154 INFO L290 TraceCheckUtils]: 68: Hoare triple {8474#false} createEmail_~retValue_acc~4#1 := createEmail_~msg~0#1;createEmail_#res#1 := createEmail_~retValue_acc~4#1; {8474#false} is VALID [2022-02-20 17:56:07,154 INFO L290 TraceCheckUtils]: 69: Hoare triple {8474#false} #t~ret73#1 := createEmail_#res#1;assume { :end_inline_createEmail } true;assume -2147483648 <= #t~ret73#1 && #t~ret73#1 <= 2147483647;~tmp~16#1 := #t~ret73#1;havoc #t~ret73#1;~email~0#1 := ~tmp~16#1; {8474#false} is VALID [2022-02-20 17:56:07,154 INFO L272 TraceCheckUtils]: 70: Hoare triple {8474#false} call outgoing(~sender#1, ~email~0#1); {8474#false} is VALID [2022-02-20 17:56:07,155 INFO L290 TraceCheckUtils]: 71: Hoare triple {8474#false} ~client#1 := #in~client#1;~msg#1 := #in~msg#1;assume { :begin_inline_sign } true;sign_#in~client#1, sign_#in~msg#1 := ~client#1, ~msg#1;havoc sign_#t~ret77#1, sign_~client#1, sign_~msg#1, sign_~privkey~1#1, sign_~tmp~18#1;sign_~client#1 := sign_#in~client#1;sign_~msg#1 := sign_#in~msg#1;havoc sign_~privkey~1#1;havoc sign_~tmp~18#1; {8474#false} is VALID [2022-02-20 17:56:07,155 INFO L272 TraceCheckUtils]: 72: Hoare triple {8474#false} call sign_#t~ret77#1 := getClientPrivateKey(sign_~client#1); {8474#false} is VALID [2022-02-20 17:56:07,155 INFO L290 TraceCheckUtils]: 73: Hoare triple {8474#false} ~handle := #in~handle;havoc ~retValue_acc~24; {8474#false} is VALID [2022-02-20 17:56:07,155 INFO L290 TraceCheckUtils]: 74: Hoare triple {8474#false} assume 1 == ~handle;~retValue_acc~24 := ~__ste_client_privateKey0~0;#res := ~retValue_acc~24; {8474#false} is VALID [2022-02-20 17:56:07,155 INFO L290 TraceCheckUtils]: 75: Hoare triple {8474#false} assume true; {8474#false} is VALID [2022-02-20 17:56:07,155 INFO L284 TraceCheckUtils]: 76: Hoare quadruple {8474#false} {8474#false} #1053#return; {8474#false} is VALID [2022-02-20 17:56:07,155 INFO L290 TraceCheckUtils]: 77: Hoare triple {8474#false} assume -2147483648 <= sign_#t~ret77#1 && sign_#t~ret77#1 <= 2147483647;sign_~tmp~18#1 := sign_#t~ret77#1;havoc sign_#t~ret77#1;sign_~privkey~1#1 := sign_~tmp~18#1; {8474#false} is VALID [2022-02-20 17:56:07,155 INFO L290 TraceCheckUtils]: 78: Hoare triple {8474#false} assume 0 == sign_~privkey~1#1; {8474#false} is VALID [2022-02-20 17:56:07,155 INFO L290 TraceCheckUtils]: 79: Hoare triple {8474#false} assume { :end_inline_sign } true;assume { :begin_inline_outgoing__wrappee__AutoResponder } true;outgoing__wrappee__AutoResponder_#in~client#1, outgoing__wrappee__AutoResponder_#in~msg#1 := ~client#1, ~msg#1;havoc outgoing__wrappee__AutoResponder_#t~ret63#1, outgoing__wrappee__AutoResponder_#t~ret64#1, outgoing__wrappee__AutoResponder_~client#1, outgoing__wrappee__AutoResponder_~msg#1, outgoing__wrappee__AutoResponder_~receiver~0#1, outgoing__wrappee__AutoResponder_~tmp~11#1, outgoing__wrappee__AutoResponder_~pubkey~0#1, outgoing__wrappee__AutoResponder_~tmp___0~4#1;outgoing__wrappee__AutoResponder_~client#1 := outgoing__wrappee__AutoResponder_#in~client#1;outgoing__wrappee__AutoResponder_~msg#1 := outgoing__wrappee__AutoResponder_#in~msg#1;havoc outgoing__wrappee__AutoResponder_~receiver~0#1;havoc outgoing__wrappee__AutoResponder_~tmp~11#1;havoc outgoing__wrappee__AutoResponder_~pubkey~0#1;havoc outgoing__wrappee__AutoResponder_~tmp___0~4#1; {8474#false} is VALID [2022-02-20 17:56:07,156 INFO L272 TraceCheckUtils]: 80: Hoare triple {8474#false} call outgoing__wrappee__AutoResponder_#t~ret63#1 := getEmailTo(outgoing__wrappee__AutoResponder_~msg#1); {8474#false} is VALID [2022-02-20 17:56:07,156 INFO L290 TraceCheckUtils]: 81: Hoare triple {8474#false} ~handle := #in~handle;havoc ~retValue_acc~36; {8474#false} is VALID [2022-02-20 17:56:07,156 INFO L290 TraceCheckUtils]: 82: Hoare triple {8474#false} assume 1 == ~handle;~retValue_acc~36 := ~__ste_email_to0~0;#res := ~retValue_acc~36; {8474#false} is VALID [2022-02-20 17:56:07,156 INFO L290 TraceCheckUtils]: 83: Hoare triple {8474#false} assume true; {8474#false} is VALID [2022-02-20 17:56:07,156 INFO L284 TraceCheckUtils]: 84: Hoare quadruple {8474#false} {8474#false} #1055#return; {8474#false} is VALID [2022-02-20 17:56:07,156 INFO L290 TraceCheckUtils]: 85: Hoare triple {8474#false} assume -2147483648 <= outgoing__wrappee__AutoResponder_#t~ret63#1 && outgoing__wrappee__AutoResponder_#t~ret63#1 <= 2147483647;outgoing__wrappee__AutoResponder_~tmp~11#1 := outgoing__wrappee__AutoResponder_#t~ret63#1;havoc outgoing__wrappee__AutoResponder_#t~ret63#1;outgoing__wrappee__AutoResponder_~receiver~0#1 := outgoing__wrappee__AutoResponder_~tmp~11#1; {8474#false} is VALID [2022-02-20 17:56:07,156 INFO L272 TraceCheckUtils]: 86: Hoare triple {8474#false} call outgoing__wrappee__AutoResponder_#t~ret64#1 := findPublicKey(outgoing__wrappee__AutoResponder_~client#1, outgoing__wrappee__AutoResponder_~receiver~0#1); {8474#false} is VALID [2022-02-20 17:56:07,156 INFO L290 TraceCheckUtils]: 87: Hoare triple {8474#false} ~handle := #in~handle;~userid := #in~userid;havoc ~retValue_acc~29; {8474#false} is VALID [2022-02-20 17:56:07,156 INFO L290 TraceCheckUtils]: 88: Hoare triple {8474#false} assume 1 == ~handle; {8474#false} is VALID [2022-02-20 17:56:07,156 INFO L290 TraceCheckUtils]: 89: Hoare triple {8474#false} assume ~userid == ~__ste_Client_Keyring0_User0~0;~retValue_acc~29 := ~__ste_Client_Keyring0_PublicKey0~0;#res := ~retValue_acc~29; {8474#false} is VALID [2022-02-20 17:56:07,157 INFO L290 TraceCheckUtils]: 90: Hoare triple {8474#false} assume true; {8474#false} is VALID [2022-02-20 17:56:07,157 INFO L284 TraceCheckUtils]: 91: Hoare quadruple {8474#false} {8474#false} #1057#return; {8474#false} is VALID [2022-02-20 17:56:07,157 INFO L290 TraceCheckUtils]: 92: Hoare triple {8474#false} assume -2147483648 <= outgoing__wrappee__AutoResponder_#t~ret64#1 && outgoing__wrappee__AutoResponder_#t~ret64#1 <= 2147483647;outgoing__wrappee__AutoResponder_~tmp___0~4#1 := outgoing__wrappee__AutoResponder_#t~ret64#1;havoc outgoing__wrappee__AutoResponder_#t~ret64#1;outgoing__wrappee__AutoResponder_~pubkey~0#1 := outgoing__wrappee__AutoResponder_~tmp___0~4#1; {8474#false} is VALID [2022-02-20 17:56:07,157 INFO L290 TraceCheckUtils]: 93: Hoare triple {8474#false} assume !(0 != outgoing__wrappee__AutoResponder_~pubkey~0#1); {8474#false} is VALID [2022-02-20 17:56:07,157 INFO L290 TraceCheckUtils]: 94: Hoare triple {8474#false} assume { :begin_inline_outgoing__wrappee__Keys } true;outgoing__wrappee__Keys_#in~client#1, outgoing__wrappee__Keys_#in~msg#1 := outgoing__wrappee__AutoResponder_~client#1, outgoing__wrappee__AutoResponder_~msg#1;havoc outgoing__wrappee__Keys_#t~ret62#1, outgoing__wrappee__Keys_~client#1, outgoing__wrappee__Keys_~msg#1, outgoing__wrappee__Keys_~tmp~10#1;outgoing__wrappee__Keys_~client#1 := outgoing__wrappee__Keys_#in~client#1;outgoing__wrappee__Keys_~msg#1 := outgoing__wrappee__Keys_#in~msg#1;havoc outgoing__wrappee__Keys_~tmp~10#1;assume { :begin_inline_getClientId } true;getClientId_#in~handle#1 := outgoing__wrappee__Keys_~client#1;havoc getClientId_#res#1;havoc getClientId_~handle#1, getClientId_~retValue_acc~31#1;getClientId_~handle#1 := getClientId_#in~handle#1;havoc getClientId_~retValue_acc~31#1; {8474#false} is VALID [2022-02-20 17:56:07,157 INFO L290 TraceCheckUtils]: 95: Hoare triple {8474#false} assume 1 == getClientId_~handle#1;getClientId_~retValue_acc~31#1 := ~__ste_client_idCounter0~0;getClientId_#res#1 := getClientId_~retValue_acc~31#1; {8474#false} is VALID [2022-02-20 17:56:07,157 INFO L290 TraceCheckUtils]: 96: Hoare triple {8474#false} outgoing__wrappee__Keys_#t~ret62#1 := getClientId_#res#1;assume { :end_inline_getClientId } true;assume -2147483648 <= outgoing__wrappee__Keys_#t~ret62#1 && outgoing__wrappee__Keys_#t~ret62#1 <= 2147483647;outgoing__wrappee__Keys_~tmp~10#1 := outgoing__wrappee__Keys_#t~ret62#1;havoc outgoing__wrappee__Keys_#t~ret62#1; {8474#false} is VALID [2022-02-20 17:56:07,157 INFO L272 TraceCheckUtils]: 97: Hoare triple {8474#false} call setEmailFrom(outgoing__wrappee__Keys_~msg#1, outgoing__wrappee__Keys_~tmp~10#1); {8474#false} is VALID [2022-02-20 17:56:07,157 INFO L290 TraceCheckUtils]: 98: Hoare triple {8474#false} ~handle := #in~handle;~value := #in~value; {8474#false} is VALID [2022-02-20 17:56:07,157 INFO L290 TraceCheckUtils]: 99: Hoare triple {8474#false} assume 1 == ~handle;~__ste_email_from0~0 := ~value; {8474#false} is VALID [2022-02-20 17:56:07,157 INFO L290 TraceCheckUtils]: 100: Hoare triple {8474#false} assume true; {8474#false} is VALID [2022-02-20 17:56:07,157 INFO L284 TraceCheckUtils]: 101: Hoare quadruple {8474#false} {8474#false} #1063#return; {8474#false} is VALID [2022-02-20 17:56:07,157 INFO L290 TraceCheckUtils]: 102: Hoare triple {8474#false} assume { :begin_inline_mail } true;mail_#in~client#1, mail_#in~msg#1 := outgoing__wrappee__Keys_~client#1, outgoing__wrappee__Keys_~msg#1;havoc mail_#t~ret60#1, mail_#t~ret61#1, mail_~client#1, mail_~msg#1, mail_~__utac__ad__arg1~0#1, mail_~__utac__ad__arg2~0#1, mail_~tmp~9#1;mail_~client#1 := mail_#in~client#1;mail_~msg#1 := mail_#in~msg#1;havoc mail_~__utac__ad__arg1~0#1;havoc mail_~__utac__ad__arg2~0#1;havoc mail_~tmp~9#1;mail_~__utac__ad__arg1~0#1 := mail_~client#1;mail_~__utac__ad__arg2~0#1 := mail_~msg#1;assume { :begin_inline___utac_acc__AddressBookEncrypt_spec__1 } true;__utac_acc__AddressBookEncrypt_spec__1_#in~client#1, __utac_acc__AddressBookEncrypt_spec__1_#in~msg#1 := mail_~__utac__ad__arg1~0#1, mail_~__utac__ad__arg2~0#1;havoc __utac_acc__AddressBookEncrypt_spec__1_#t~ret85#1, __utac_acc__AddressBookEncrypt_spec__1_#t~ret86#1, __utac_acc__AddressBookEncrypt_spec__1_#t~ret87#1, __utac_acc__AddressBookEncrypt_spec__1_~client#1, __utac_acc__AddressBookEncrypt_spec__1_~msg#1, __utac_acc__AddressBookEncrypt_spec__1_~tmp~20#1;__utac_acc__AddressBookEncrypt_spec__1_~client#1 := __utac_acc__AddressBookEncrypt_spec__1_#in~client#1;__utac_acc__AddressBookEncrypt_spec__1_~msg#1 := __utac_acc__AddressBookEncrypt_spec__1_#in~msg#1;havoc __utac_acc__AddressBookEncrypt_spec__1_~tmp~20#1;call __utac_acc__AddressBookEncrypt_spec__1_#t~ret85#1 := puts(31, 0);assume -2147483648 <= __utac_acc__AddressBookEncrypt_spec__1_#t~ret85#1 && __utac_acc__AddressBookEncrypt_spec__1_#t~ret85#1 <= 2147483647;havoc __utac_acc__AddressBookEncrypt_spec__1_#t~ret85#1; {8474#false} is VALID [2022-02-20 17:56:07,157 INFO L290 TraceCheckUtils]: 103: Hoare triple {8474#false} assume !(-1 == ~mail_is_sensitive~0); {8474#false} is VALID [2022-02-20 17:56:07,157 INFO L272 TraceCheckUtils]: 104: Hoare triple {8474#false} call __utac_acc__AddressBookEncrypt_spec__1_#t~ret87#1 := isEncrypted(__utac_acc__AddressBookEncrypt_spec__1_~msg#1); {8474#false} is VALID [2022-02-20 17:56:07,158 INFO L290 TraceCheckUtils]: 105: Hoare triple {8474#false} ~handle := #in~handle;havoc ~retValue_acc~39; {8474#false} is VALID [2022-02-20 17:56:07,158 INFO L290 TraceCheckUtils]: 106: Hoare triple {8474#false} assume 1 == ~handle;~retValue_acc~39 := ~__ste_email_isEncrypted0~0;#res := ~retValue_acc~39; {8474#false} is VALID [2022-02-20 17:56:07,158 INFO L290 TraceCheckUtils]: 107: Hoare triple {8474#false} assume true; {8474#false} is VALID [2022-02-20 17:56:07,158 INFO L284 TraceCheckUtils]: 108: Hoare quadruple {8474#false} {8474#false} #1067#return; {8474#false} is VALID [2022-02-20 17:56:07,158 INFO L290 TraceCheckUtils]: 109: Hoare triple {8474#false} assume -2147483648 <= __utac_acc__AddressBookEncrypt_spec__1_#t~ret87#1 && __utac_acc__AddressBookEncrypt_spec__1_#t~ret87#1 <= 2147483647;__utac_acc__AddressBookEncrypt_spec__1_~tmp~20#1 := __utac_acc__AddressBookEncrypt_spec__1_#t~ret87#1;havoc __utac_acc__AddressBookEncrypt_spec__1_#t~ret87#1; {8474#false} is VALID [2022-02-20 17:56:07,158 INFO L290 TraceCheckUtils]: 110: Hoare triple {8474#false} assume ~mail_is_sensitive~0 != __utac_acc__AddressBookEncrypt_spec__1_~tmp~20#1;assume { :begin_inline___automaton_fail } true; {8474#false} is VALID [2022-02-20 17:56:07,158 INFO L290 TraceCheckUtils]: 111: Hoare triple {8474#false} assume !false; {8474#false} is VALID [2022-02-20 17:56:07,158 INFO L134 CoverageAnalysis]: Checked inductivity of 30 backedges. 19 proven. 0 refuted. 0 times theorem prover too weak. 11 trivial. 0 not checked. [2022-02-20 17:56:07,158 INFO L324 TraceCheckSpWp]: Omiting computation of backward sequence because forward sequence was already perfect [2022-02-20 17:56:07,158 INFO L165 FreeRefinementEngine]: IpTcStrategyModuleZ3 [596554799] provided 1 perfect and 0 imperfect interpolant sequences [2022-02-20 17:56:07,159 INFO L191 FreeRefinementEngine]: Found 1 perfect and 1 imperfect interpolant sequences. [2022-02-20 17:56:07,159 INFO L204 FreeRefinementEngine]: Number of different interpolants: perfect sequences [5] imperfect sequences [9] total 12 [2022-02-20 17:56:07,159 INFO L118 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [1271640061] [2022-02-20 17:56:07,159 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2022-02-20 17:56:07,160 INFO L78 Accepts]: Start accepts. Automaton has has 5 states, 4 states have (on average 19.25) internal successors, (77), 5 states have internal predecessors, (77), 3 states have call successors, (15), 2 states have call predecessors, (15), 3 states have return successors, (13), 2 states have call predecessors, (13), 3 states have call successors, (13) Word has length 112 [2022-02-20 17:56:07,160 INFO L84 Accepts]: Finished accepts. word is accepted. [2022-02-20 17:56:07,160 INFO L86 InductivityCheck]: Starting indutivity check of a Floyd-Hoare automaton with has 5 states, 4 states have (on average 19.25) internal successors, (77), 5 states have internal predecessors, (77), 3 states have call successors, (15), 2 states have call predecessors, (15), 3 states have return successors, (13), 2 states have call predecessors, (13), 3 states have call successors, (13) [2022-02-20 17:56:07,243 INFO L122 InductivityCheck]: Floyd-Hoare automaton has 105 edges. 105 inductive. 0 not inductive. 0 times theorem prover too weak to decide inductivity. [2022-02-20 17:56:07,243 INFO L546 AbstractCegarLoop]: INTERPOLANT automaton has 5 states [2022-02-20 17:56:07,243 INFO L108 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2022-02-20 17:56:07,244 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 5 interpolants. [2022-02-20 17:56:07,244 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=24, Invalid=108, Unknown=0, NotChecked=0, Total=132 [2022-02-20 17:56:07,244 INFO L87 Difference]: Start difference. First operand 437 states and 657 transitions. Second operand has 5 states, 4 states have (on average 19.25) internal successors, (77), 5 states have internal predecessors, (77), 3 states have call successors, (15), 2 states have call predecessors, (15), 3 states have return successors, (13), 2 states have call predecessors, (13), 3 states have call successors, (13) [2022-02-20 17:56:08,177 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-02-20 17:56:08,178 INFO L93 Difference]: Finished difference Result 865 states and 1304 transitions. [2022-02-20 17:56:08,178 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 5 states. [2022-02-20 17:56:08,178 INFO L78 Accepts]: Start accepts. Automaton has has 5 states, 4 states have (on average 19.25) internal successors, (77), 5 states have internal predecessors, (77), 3 states have call successors, (15), 2 states have call predecessors, (15), 3 states have return successors, (13), 2 states have call predecessors, (13), 3 states have call successors, (13) Word has length 112 [2022-02-20 17:56:08,179 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2022-02-20 17:56:08,179 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 5 states, 4 states have (on average 19.25) internal successors, (77), 5 states have internal predecessors, (77), 3 states have call successors, (15), 2 states have call predecessors, (15), 3 states have return successors, (13), 2 states have call predecessors, (13), 3 states have call successors, (13) [2022-02-20 17:56:08,186 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 5 states to 5 states and 1116 transitions. [2022-02-20 17:56:08,187 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 5 states, 4 states have (on average 19.25) internal successors, (77), 5 states have internal predecessors, (77), 3 states have call successors, (15), 2 states have call predecessors, (15), 3 states have return successors, (13), 2 states have call predecessors, (13), 3 states have call successors, (13) [2022-02-20 17:56:08,194 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 5 states to 5 states and 1116 transitions. [2022-02-20 17:56:08,194 INFO L86 InductivityCheck]: Starting indutivity check of a Floyd-Hoare automaton with 5 states and 1116 transitions. [2022-02-20 17:56:08,812 INFO L122 InductivityCheck]: Floyd-Hoare automaton has 1116 edges. 1116 inductive. 0 not inductive. 0 times theorem prover too weak to decide inductivity. [2022-02-20 17:56:08,830 INFO L225 Difference]: With dead ends: 865 [2022-02-20 17:56:08,831 INFO L226 Difference]: Without dead ends: 439 [2022-02-20 17:56:08,832 INFO L932 BasicCegarLoop]: 0 DeclaredPredicates, 142 GetRequests, 131 SyntacticMatches, 0 SemanticMatches, 11 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 3 ImplicationChecksByTransitivity, 0.1s TimeCoverageRelationStatistics Valid=28, Invalid=128, Unknown=0, NotChecked=0, Total=156 [2022-02-20 17:56:08,833 INFO L933 BasicCegarLoop]: 554 mSDtfsCounter, 133 mSDsluCounter, 1510 mSDsCounter, 0 mSdLazyCounter, 34 mSolverCounterSat, 0 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.0s Time, 0 mProtectedPredicate, 0 mProtectedAction, 153 SdHoareTripleChecker+Valid, 2064 SdHoareTripleChecker+Invalid, 34 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 0 IncrementalHoareTripleChecker+Valid, 34 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.0s IncrementalHoareTripleChecker+Time [2022-02-20 17:56:08,833 INFO L934 BasicCegarLoop]: SdHoareTripleChecker [153 Valid, 2064 Invalid, 34 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [0 Valid, 34 Invalid, 0 Unknown, 0 Unchecked, 0.0s Time] [2022-02-20 17:56:08,834 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 439 states. [2022-02-20 17:56:08,889 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 439 to 439. [2022-02-20 17:56:08,889 INFO L214 AbstractMinimizeNwa]: Start testing correctness of minimizeSevpa [2022-02-20 17:56:08,892 INFO L82 GeneralOperation]: Start isEquivalent. First operand 439 states. Second operand has 439 states, 339 states have (on average 1.5073746312684366) internal successors, (511), 343 states have internal predecessors, (511), 74 states have call successors, (74), 24 states have call predecessors, (74), 25 states have return successors, (75), 73 states have call predecessors, (75), 73 states have call successors, (75) [2022-02-20 17:56:08,893 INFO L74 IsIncluded]: Start isIncluded. First operand 439 states. Second operand has 439 states, 339 states have (on average 1.5073746312684366) internal successors, (511), 343 states have internal predecessors, (511), 74 states have call successors, (74), 24 states have call predecessors, (74), 25 states have return successors, (75), 73 states have call predecessors, (75), 73 states have call successors, (75) [2022-02-20 17:56:08,895 INFO L87 Difference]: Start difference. First operand 439 states. Second operand has 439 states, 339 states have (on average 1.5073746312684366) internal successors, (511), 343 states have internal predecessors, (511), 74 states have call successors, (74), 24 states have call predecessors, (74), 25 states have return successors, (75), 73 states have call predecessors, (75), 73 states have call successors, (75) [2022-02-20 17:56:08,910 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-02-20 17:56:08,911 INFO L93 Difference]: Finished difference Result 439 states and 660 transitions. [2022-02-20 17:56:08,911 INFO L276 IsEmpty]: Start isEmpty. Operand 439 states and 660 transitions. [2022-02-20 17:56:08,912 INFO L282 IsEmpty]: Finished isEmpty. No accepting run. [2022-02-20 17:56:08,912 INFO L83 IsIncluded]: Finished isIncluded. Language is included [2022-02-20 17:56:08,913 INFO L74 IsIncluded]: Start isIncluded. First operand has 439 states, 339 states have (on average 1.5073746312684366) internal successors, (511), 343 states have internal predecessors, (511), 74 states have call successors, (74), 24 states have call predecessors, (74), 25 states have return successors, (75), 73 states have call predecessors, (75), 73 states have call successors, (75) Second operand 439 states. [2022-02-20 17:56:08,914 INFO L87 Difference]: Start difference. First operand has 439 states, 339 states have (on average 1.5073746312684366) internal successors, (511), 343 states have internal predecessors, (511), 74 states have call successors, (74), 24 states have call predecessors, (74), 25 states have return successors, (75), 73 states have call predecessors, (75), 73 states have call successors, (75) Second operand 439 states. [2022-02-20 17:56:08,925 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-02-20 17:56:08,926 INFO L93 Difference]: Finished difference Result 439 states and 660 transitions. [2022-02-20 17:56:08,926 INFO L276 IsEmpty]: Start isEmpty. Operand 439 states and 660 transitions. [2022-02-20 17:56:08,927 INFO L282 IsEmpty]: Finished isEmpty. No accepting run. [2022-02-20 17:56:08,927 INFO L83 IsIncluded]: Finished isIncluded. Language is included [2022-02-20 17:56:08,927 INFO L88 GeneralOperation]: Finished isEquivalent. [2022-02-20 17:56:08,927 INFO L221 AbstractMinimizeNwa]: Finished testing correctness of minimizeSevpa [2022-02-20 17:56:08,928 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 439 states, 339 states have (on average 1.5073746312684366) internal successors, (511), 343 states have internal predecessors, (511), 74 states have call successors, (74), 24 states have call predecessors, (74), 25 states have return successors, (75), 73 states have call predecessors, (75), 73 states have call successors, (75) [2022-02-20 17:56:08,940 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 439 states to 439 states and 660 transitions. [2022-02-20 17:56:08,940 INFO L78 Accepts]: Start accepts. Automaton has 439 states and 660 transitions. Word has length 112 [2022-02-20 17:56:08,940 INFO L84 Accepts]: Finished accepts. word is rejected. [2022-02-20 17:56:08,940 INFO L470 AbstractCegarLoop]: Abstraction has 439 states and 660 transitions. [2022-02-20 17:56:08,941 INFO L471 AbstractCegarLoop]: INTERPOLANT automaton has has 5 states, 4 states have (on average 19.25) internal successors, (77), 5 states have internal predecessors, (77), 3 states have call successors, (15), 2 states have call predecessors, (15), 3 states have return successors, (13), 2 states have call predecessors, (13), 3 states have call successors, (13) [2022-02-20 17:56:08,941 INFO L276 IsEmpty]: Start isEmpty. Operand 439 states and 660 transitions. [2022-02-20 17:56:08,942 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 114 [2022-02-20 17:56:08,942 INFO L506 BasicCegarLoop]: Found error trace [2022-02-20 17:56:08,942 INFO L514 BasicCegarLoop]: trace histogram [3, 3, 3, 3, 3, 2, 2, 2, 2, 2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-02-20 17:56:08,974 INFO L540 MonitoredProcess]: [MP /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 -smt2 -in SMTLIB2_COMPLIANT=true (5)] Forceful destruction successful, exit code 0 [2022-02-20 17:56:09,174 WARN L452 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable3,5 /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 -smt2 -in SMTLIB2_COMPLIANT=true [2022-02-20 17:56:09,174 INFO L402 AbstractCegarLoop]: === Iteration 5 === Targeting outgoingErr0ASSERT_VIOLATIONERROR_FUNCTION === [outgoingErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2022-02-20 17:56:09,175 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2022-02-20 17:56:09,175 INFO L85 PathProgramCache]: Analyzing trace with hash 32125176, now seen corresponding path program 1 times [2022-02-20 17:56:09,175 INFO L126 FreeRefinementEngine]: Executing refinement strategy CAMEL [2022-02-20 17:56:09,175 INFO L338 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [560374175] [2022-02-20 17:56:09,175 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-02-20 17:56:09,175 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2022-02-20 17:56:09,214 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-02-20 17:56:09,244 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 6 [2022-02-20 17:56:09,245 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-02-20 17:56:09,247 INFO L290 TraceCheckUtils]: 0: Hoare triple {11662#(and (= |old(~__ste_client_idCounter0~0)| ~__ste_client_idCounter0~0) (= |old(~__ste_client_idCounter1~0)| ~__ste_client_idCounter1~0) (= |old(~__ste_client_idCounter2~0)| ~__ste_client_idCounter2~0))} ~handle := #in~handle;~value := #in~value; {11604#true} is VALID [2022-02-20 17:56:09,247 INFO L290 TraceCheckUtils]: 1: Hoare triple {11604#true} assume 1 == ~handle;~__ste_client_idCounter0~0 := ~value; {11604#true} is VALID [2022-02-20 17:56:09,247 INFO L290 TraceCheckUtils]: 2: Hoare triple {11604#true} assume true; {11604#true} is VALID [2022-02-20 17:56:09,247 INFO L284 TraceCheckUtils]: 3: Hoare quadruple {11604#true} {11604#true} #1133#return; {11604#true} is VALID [2022-02-20 17:56:09,252 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 12 [2022-02-20 17:56:09,254 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-02-20 17:56:09,255 INFO L290 TraceCheckUtils]: 0: Hoare triple {11663#(and (= ~__ste_client_privateKey0~0 |old(~__ste_client_privateKey0~0)|) (= ~__ste_client_privateKey2~0 |old(~__ste_client_privateKey2~0)|) (= ~__ste_client_privateKey1~0 |old(~__ste_client_privateKey1~0)|))} ~handle := #in~handle;~value := #in~value; {11604#true} is VALID [2022-02-20 17:56:09,255 INFO L290 TraceCheckUtils]: 1: Hoare triple {11604#true} assume 1 == ~handle;~__ste_client_privateKey0~0 := ~value; {11604#true} is VALID [2022-02-20 17:56:09,255 INFO L290 TraceCheckUtils]: 2: Hoare triple {11604#true} assume true; {11604#true} is VALID [2022-02-20 17:56:09,255 INFO L284 TraceCheckUtils]: 3: Hoare quadruple {11604#true} {11604#true} #1135#return; {11604#true} is VALID [2022-02-20 17:56:09,255 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 18 [2022-02-20 17:56:09,257 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-02-20 17:56:09,271 INFO L290 TraceCheckUtils]: 0: Hoare triple {11662#(and (= |old(~__ste_client_idCounter0~0)| ~__ste_client_idCounter0~0) (= |old(~__ste_client_idCounter1~0)| ~__ste_client_idCounter1~0) (= |old(~__ste_client_idCounter2~0)| ~__ste_client_idCounter2~0))} ~handle := #in~handle;~value := #in~value; {11664#(= setClientId_~handle |setClientId_#in~handle|)} is VALID [2022-02-20 17:56:09,271 INFO L290 TraceCheckUtils]: 1: Hoare triple {11664#(= setClientId_~handle |setClientId_#in~handle|)} assume !(1 == ~handle); {11664#(= setClientId_~handle |setClientId_#in~handle|)} is VALID [2022-02-20 17:56:09,271 INFO L290 TraceCheckUtils]: 2: Hoare triple {11664#(= setClientId_~handle |setClientId_#in~handle|)} assume 2 == ~handle;~__ste_client_idCounter1~0 := ~value; {11665#(= 2 |setClientId_#in~handle|)} is VALID [2022-02-20 17:56:09,272 INFO L290 TraceCheckUtils]: 3: Hoare triple {11665#(= 2 |setClientId_#in~handle|)} assume true; {11665#(= 2 |setClientId_#in~handle|)} is VALID [2022-02-20 17:56:09,272 INFO L284 TraceCheckUtils]: 4: Hoare quadruple {11665#(= 2 |setClientId_#in~handle|)} {11614#(= |ULTIMATE.start_setup_rjh_~rjh___0#1| |ULTIMATE.start_setup_rjh__wrappee__Base_~rjh___0#1|)} #1137#return; {11620#(not (= |ULTIMATE.start_setup_rjh_~rjh___0#1| 1))} is VALID [2022-02-20 17:56:09,273 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 25 [2022-02-20 17:56:09,275 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-02-20 17:56:09,289 INFO L290 TraceCheckUtils]: 0: Hoare triple {11663#(and (= ~__ste_client_privateKey0~0 |old(~__ste_client_privateKey0~0)|) (= ~__ste_client_privateKey2~0 |old(~__ste_client_privateKey2~0)|) (= ~__ste_client_privateKey1~0 |old(~__ste_client_privateKey1~0)|))} ~handle := #in~handle;~value := #in~value; {11666#(= setClientPrivateKey_~handle |setClientPrivateKey_#in~handle|)} is VALID [2022-02-20 17:56:09,289 INFO L290 TraceCheckUtils]: 1: Hoare triple {11666#(= setClientPrivateKey_~handle |setClientPrivateKey_#in~handle|)} assume 1 == ~handle;~__ste_client_privateKey0~0 := ~value; {11667#(= |setClientPrivateKey_#in~handle| 1)} is VALID [2022-02-20 17:56:09,290 INFO L290 TraceCheckUtils]: 2: Hoare triple {11667#(= |setClientPrivateKey_#in~handle| 1)} assume true; {11667#(= |setClientPrivateKey_#in~handle| 1)} is VALID [2022-02-20 17:56:09,290 INFO L284 TraceCheckUtils]: 3: Hoare quadruple {11667#(= |setClientPrivateKey_#in~handle| 1)} {11620#(not (= |ULTIMATE.start_setup_rjh_~rjh___0#1| 1))} #1139#return; {11605#false} is VALID [2022-02-20 17:56:09,290 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 31 [2022-02-20 17:56:09,292 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-02-20 17:56:09,293 INFO L290 TraceCheckUtils]: 0: Hoare triple {11662#(and (= |old(~__ste_client_idCounter0~0)| ~__ste_client_idCounter0~0) (= |old(~__ste_client_idCounter1~0)| ~__ste_client_idCounter1~0) (= |old(~__ste_client_idCounter2~0)| ~__ste_client_idCounter2~0))} ~handle := #in~handle;~value := #in~value; {11604#true} is VALID [2022-02-20 17:56:09,293 INFO L290 TraceCheckUtils]: 1: Hoare triple {11604#true} assume 1 == ~handle;~__ste_client_idCounter0~0 := ~value; {11604#true} is VALID [2022-02-20 17:56:09,293 INFO L290 TraceCheckUtils]: 2: Hoare triple {11604#true} assume true; {11604#true} is VALID [2022-02-20 17:56:09,294 INFO L284 TraceCheckUtils]: 3: Hoare quadruple {11604#true} {11605#false} #1141#return; {11605#false} is VALID [2022-02-20 17:56:09,294 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 37 [2022-02-20 17:56:09,295 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-02-20 17:56:09,296 INFO L290 TraceCheckUtils]: 0: Hoare triple {11663#(and (= ~__ste_client_privateKey0~0 |old(~__ste_client_privateKey0~0)|) (= ~__ste_client_privateKey2~0 |old(~__ste_client_privateKey2~0)|) (= ~__ste_client_privateKey1~0 |old(~__ste_client_privateKey1~0)|))} ~handle := #in~handle;~value := #in~value; {11604#true} is VALID [2022-02-20 17:56:09,297 INFO L290 TraceCheckUtils]: 1: Hoare triple {11604#true} assume 1 == ~handle;~__ste_client_privateKey0~0 := ~value; {11604#true} is VALID [2022-02-20 17:56:09,297 INFO L290 TraceCheckUtils]: 2: Hoare triple {11604#true} assume true; {11604#true} is VALID [2022-02-20 17:56:09,297 INFO L284 TraceCheckUtils]: 3: Hoare quadruple {11604#true} {11605#false} #1143#return; {11605#false} is VALID [2022-02-20 17:56:09,304 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 59 [2022-02-20 17:56:09,306 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-02-20 17:56:09,307 INFO L290 TraceCheckUtils]: 0: Hoare triple {11668#(and (= |old(~__ste_email_from0~0)| ~__ste_email_from0~0) (= |old(~__ste_email_from1~0)| ~__ste_email_from1~0))} ~handle := #in~handle;~value := #in~value; {11604#true} is VALID [2022-02-20 17:56:09,307 INFO L290 TraceCheckUtils]: 1: Hoare triple {11604#true} assume 1 == ~handle;~__ste_email_from0~0 := ~value; {11604#true} is VALID [2022-02-20 17:56:09,307 INFO L290 TraceCheckUtils]: 2: Hoare triple {11604#true} assume true; {11604#true} is VALID [2022-02-20 17:56:09,307 INFO L284 TraceCheckUtils]: 3: Hoare quadruple {11604#true} {11605#false} #1119#return; {11605#false} is VALID [2022-02-20 17:56:09,314 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 64 [2022-02-20 17:56:09,315 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-02-20 17:56:09,317 INFO L290 TraceCheckUtils]: 0: Hoare triple {11669#(and (= ~__ste_email_to0~0 |old(~__ste_email_to0~0)|) (= ~__ste_email_to1~0 |old(~__ste_email_to1~0)|))} ~handle := #in~handle;~value := #in~value; {11604#true} is VALID [2022-02-20 17:56:09,317 INFO L290 TraceCheckUtils]: 1: Hoare triple {11604#true} assume 1 == ~handle;~__ste_email_to0~0 := ~value; {11604#true} is VALID [2022-02-20 17:56:09,317 INFO L290 TraceCheckUtils]: 2: Hoare triple {11604#true} assume true; {11604#true} is VALID [2022-02-20 17:56:09,317 INFO L284 TraceCheckUtils]: 3: Hoare quadruple {11604#true} {11605#false} #1121#return; {11605#false} is VALID [2022-02-20 17:56:09,317 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 73 [2022-02-20 17:56:09,318 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-02-20 17:56:09,323 INFO L290 TraceCheckUtils]: 0: Hoare triple {11604#true} ~handle := #in~handle;havoc ~retValue_acc~24; {11604#true} is VALID [2022-02-20 17:56:09,323 INFO L290 TraceCheckUtils]: 1: Hoare triple {11604#true} assume 1 == ~handle;~retValue_acc~24 := ~__ste_client_privateKey0~0;#res := ~retValue_acc~24; {11604#true} is VALID [2022-02-20 17:56:09,323 INFO L290 TraceCheckUtils]: 2: Hoare triple {11604#true} assume true; {11604#true} is VALID [2022-02-20 17:56:09,324 INFO L284 TraceCheckUtils]: 3: Hoare quadruple {11604#true} {11605#false} #1053#return; {11605#false} is VALID [2022-02-20 17:56:09,324 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 81 [2022-02-20 17:56:09,324 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-02-20 17:56:09,326 INFO L290 TraceCheckUtils]: 0: Hoare triple {11604#true} ~handle := #in~handle;havoc ~retValue_acc~36; {11604#true} is VALID [2022-02-20 17:56:09,326 INFO L290 TraceCheckUtils]: 1: Hoare triple {11604#true} assume 1 == ~handle;~retValue_acc~36 := ~__ste_email_to0~0;#res := ~retValue_acc~36; {11604#true} is VALID [2022-02-20 17:56:09,326 INFO L290 TraceCheckUtils]: 2: Hoare triple {11604#true} assume true; {11604#true} is VALID [2022-02-20 17:56:09,326 INFO L284 TraceCheckUtils]: 3: Hoare quadruple {11604#true} {11605#false} #1055#return; {11605#false} is VALID [2022-02-20 17:56:09,326 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 87 [2022-02-20 17:56:09,327 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-02-20 17:56:09,328 INFO L290 TraceCheckUtils]: 0: Hoare triple {11604#true} ~handle := #in~handle;~userid := #in~userid;havoc ~retValue_acc~29; {11604#true} is VALID [2022-02-20 17:56:09,328 INFO L290 TraceCheckUtils]: 1: Hoare triple {11604#true} assume 1 == ~handle; {11604#true} is VALID [2022-02-20 17:56:09,329 INFO L290 TraceCheckUtils]: 2: Hoare triple {11604#true} assume ~userid == ~__ste_Client_Keyring0_User0~0;~retValue_acc~29 := ~__ste_Client_Keyring0_PublicKey0~0;#res := ~retValue_acc~29; {11604#true} is VALID [2022-02-20 17:56:09,329 INFO L290 TraceCheckUtils]: 3: Hoare triple {11604#true} assume true; {11604#true} is VALID [2022-02-20 17:56:09,329 INFO L284 TraceCheckUtils]: 4: Hoare quadruple {11604#true} {11605#false} #1057#return; {11605#false} is VALID [2022-02-20 17:56:09,329 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 98 [2022-02-20 17:56:09,331 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-02-20 17:56:09,336 INFO L290 TraceCheckUtils]: 0: Hoare triple {11668#(and (= |old(~__ste_email_from0~0)| ~__ste_email_from0~0) (= |old(~__ste_email_from1~0)| ~__ste_email_from1~0))} ~handle := #in~handle;~value := #in~value; {11604#true} is VALID [2022-02-20 17:56:09,336 INFO L290 TraceCheckUtils]: 1: Hoare triple {11604#true} assume 1 == ~handle;~__ste_email_from0~0 := ~value; {11604#true} is VALID [2022-02-20 17:56:09,336 INFO L290 TraceCheckUtils]: 2: Hoare triple {11604#true} assume true; {11604#true} is VALID [2022-02-20 17:56:09,336 INFO L284 TraceCheckUtils]: 3: Hoare quadruple {11604#true} {11605#false} #1063#return; {11605#false} is VALID [2022-02-20 17:56:09,337 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 105 [2022-02-20 17:56:09,337 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-02-20 17:56:09,339 INFO L290 TraceCheckUtils]: 0: Hoare triple {11604#true} ~handle := #in~handle;havoc ~retValue_acc~39; {11604#true} is VALID [2022-02-20 17:56:09,339 INFO L290 TraceCheckUtils]: 1: Hoare triple {11604#true} assume 1 == ~handle;~retValue_acc~39 := ~__ste_email_isEncrypted0~0;#res := ~retValue_acc~39; {11604#true} is VALID [2022-02-20 17:56:09,339 INFO L290 TraceCheckUtils]: 2: Hoare triple {11604#true} assume true; {11604#true} is VALID [2022-02-20 17:56:09,339 INFO L284 TraceCheckUtils]: 3: Hoare quadruple {11604#true} {11605#false} #1067#return; {11605#false} is VALID [2022-02-20 17:56:09,339 INFO L290 TraceCheckUtils]: 0: Hoare triple {11604#true} assume { :begin_inline_ULTIMATE.init } true;#NULL.base, #NULL.offset := 0, 0;assume 0 == #valid[0];assume 0 < #StackHeapBarrier;call #Ultimate.allocInit(2, 1);call write~init~int(48, 1, 0, 1);call write~init~int(0, 1, 1, 1);call #Ultimate.allocInit(28, 2);call #Ultimate.allocInit(12, 3);call #Ultimate.allocInit(4, 4);call write~init~int(37, 4, 0, 1);call write~init~int(115, 4, 1, 1);call write~init~int(10, 4, 2, 1);call write~init~int(0, 4, 3, 1);call #Ultimate.allocInit(10, 5);call #Ultimate.allocInit(12, 6);call #Ultimate.allocInit(10, 7);call #Ultimate.allocInit(18, 8);call #Ultimate.allocInit(16, 9);call #Ultimate.allocInit(21, 10);call #Ultimate.allocInit(13, 11);call #Ultimate.allocInit(16, 12);call #Ultimate.allocInit(25, 13);call #Ultimate.allocInit(30, 14);call #Ultimate.allocInit(9, 15);call #Ultimate.allocInit(21, 16);call #Ultimate.allocInit(30, 17);call #Ultimate.allocInit(9, 18);call #Ultimate.allocInit(21, 19);call #Ultimate.allocInit(30, 20);call #Ultimate.allocInit(9, 21);call #Ultimate.allocInit(25, 22);call #Ultimate.allocInit(30, 23);call #Ultimate.allocInit(9, 24);call #Ultimate.allocInit(25, 25);call #Ultimate.allocInit(10, 26);call #Ultimate.allocInit(16, 27);call #Ultimate.allocInit(20, 28);call #Ultimate.allocInit(22, 29);call #Ultimate.allocInit(21, 30);call #Ultimate.allocInit(13, 31);call #Ultimate.allocInit(44, 32);call #Ultimate.allocInit(44, 33);call #Ultimate.allocInit(9, 34);call #Ultimate.allocInit(9, 35);call #Ultimate.allocInit(11, 36);call #Ultimate.allocInit(19, 37);call #Ultimate.allocInit(4, 38);call write~init~int(37, 38, 0, 1);call write~init~int(100, 38, 1, 1);call write~init~int(10, 38, 2, 1);call write~init~int(0, 38, 3, 1);call #Ultimate.allocInit(4, 39);call write~init~int(37, 39, 0, 1);call write~init~int(100, 39, 1, 1);call write~init~int(10, 39, 2, 1);call write~init~int(0, 39, 3, 1);~__SELECTED_FEATURE_Base~0 := 0;~__SELECTED_FEATURE_Keys~0 := 0;~__SELECTED_FEATURE_Encrypt~0 := 0;~__SELECTED_FEATURE_AutoResponder~0 := 0;~__SELECTED_FEATURE_AddressBook~0 := 0;~__SELECTED_FEATURE_Sign~0 := 0;~__SELECTED_FEATURE_Forward~0 := 0;~__SELECTED_FEATURE_Verify~0 := 0;~__SELECTED_FEATURE_Decrypt~0 := 0;~__GUIDSL_ROOT_PRODUCTION~0 := 0;~__GUIDSL_NON_TERMINAL_main~0 := 0;~head~0.base, ~head~0.offset := 0, 0;~queue_empty~0 := 1;~queued_message~0 := 0;~queued_client~0 := 0;~mail_is_sensitive~0 := -1;~__ste_Client_counter~0 := 0;~__ste_client_name0~0.base, ~__ste_client_name0~0.offset := 0, 0;~__ste_client_name1~0.base, ~__ste_client_name1~0.offset := 0, 0;~__ste_client_name2~0.base, ~__ste_client_name2~0.offset := 0, 0;~__ste_client_outbuffer0~0 := 0;~__ste_client_outbuffer1~0 := 0;~__ste_client_outbuffer2~0 := 0;~__ste_client_outbuffer3~0 := 0;~__ste_ClientAddressBook_size0~0 := 0;~__ste_ClientAddressBook_size1~0 := 0;~__ste_ClientAddressBook_size2~0 := 0;~__ste_Client_AddressBook0_Alias0~0 := 0;~__ste_Client_AddressBook0_Alias1~0 := 0;~__ste_Client_AddressBook0_Alias2~0 := 0;~__ste_Client_AddressBook1_Alias0~0 := 0;~__ste_Client_AddressBook1_Alias1~0 := 0;~__ste_Client_AddressBook1_Alias2~0 := 0;~__ste_Client_AddressBook2_Alias0~0 := 0;~__ste_Client_AddressBook2_Alias1~0 := 0;~__ste_Client_AddressBook2_Alias2~0 := 0;~__ste_Client_AddressBook0_Address0~0 := 0;~__ste_Client_AddressBook0_Address1~0 := 0;~__ste_Client_AddressBook0_Address2~0 := 0;~__ste_Client_AddressBook1_Address0~0 := 0;~__ste_Client_AddressBook1_Address1~0 := 0;~__ste_Client_AddressBook1_Address2~0 := 0;~__ste_Client_AddressBook2_Address0~0 := 0;~__ste_Client_AddressBook2_Address1~0 := 0;~__ste_Client_AddressBook2_Address2~0 := 0;~__ste_client_autoResponse0~0 := 0;~__ste_client_autoResponse1~0 := 0;~__ste_client_autoResponse2~0 := 0;~__ste_client_privateKey0~0 := 0;~__ste_client_privateKey1~0 := 0;~__ste_client_privateKey2~0 := 0;~__ste_ClientKeyring_size0~0 := 0;~__ste_ClientKeyring_size1~0 := 0;~__ste_ClientKeyring_size2~0 := 0;~__ste_Client_Keyring0_User0~0 := 0;~__ste_Client_Keyring0_User1~0 := 0;~__ste_Client_Keyring0_User2~0 := 0;~__ste_Client_Keyring1_User0~0 := 0;~__ste_Client_Keyring1_User1~0 := 0;~__ste_Client_Keyring1_User2~0 := 0;~__ste_Client_Keyring2_User0~0 := 0;~__ste_Client_Keyring2_User1~0 := 0;~__ste_Client_Keyring2_User2~0 := 0;~__ste_Client_Keyring0_PublicKey0~0 := 0;~__ste_Client_Keyring0_PublicKey1~0 := 0;~__ste_Client_Keyring0_PublicKey2~0 := 0;~__ste_Client_Keyring1_PublicKey0~0 := 0;~__ste_Client_Keyring1_PublicKey1~0 := 0;~__ste_Client_Keyring1_PublicKey2~0 := 0;~__ste_Client_Keyring2_PublicKey0~0 := 0;~__ste_Client_Keyring2_PublicKey1~0 := 0;~__ste_Client_Keyring2_PublicKey2~0 := 0;~__ste_client_forwardReceiver0~0 := 0;~__ste_client_forwardReceiver1~0 := 0;~__ste_client_forwardReceiver2~0 := 0;~__ste_client_forwardReceiver3~0 := 0;~__ste_client_idCounter0~0 := 0;~__ste_client_idCounter1~0 := 0;~__ste_client_idCounter2~0 := 0;~bob~0 := 0;~rjh~0 := 0;~chuck~0 := 0;~__ste_Email_counter~0 := 0;~__ste_email_id0~0 := 0;~__ste_email_id1~0 := 0;~__ste_email_from0~0 := 0;~__ste_email_from1~0 := 0;~__ste_email_to0~0 := 0;~__ste_email_to1~0 := 0;~__ste_email_subject0~0.base, ~__ste_email_subject0~0.offset := 0, 0;~__ste_email_subject1~0.base, ~__ste_email_subject1~0.offset := 0, 0;~__ste_email_body0~0.base, ~__ste_email_body0~0.offset := 0, 0;~__ste_email_body1~0.base, ~__ste_email_body1~0.offset := 0, 0;~__ste_email_isEncrypted0~0 := 0;~__ste_email_isEncrypted1~0 := 0;~__ste_email_encryptionKey0~0 := 0;~__ste_email_encryptionKey1~0 := 0;~__ste_email_isSigned0~0 := 0;~__ste_email_isSigned1~0 := 0;~__ste_email_signKey0~0 := 0;~__ste_email_signKey1~0 := 0;~__ste_email_isSignatureVerified0~0 := 0;~__ste_email_isSignatureVerified1~0 := 0; {11604#true} is VALID [2022-02-20 17:56:09,339 INFO L290 TraceCheckUtils]: 1: Hoare triple {11604#true} assume { :end_inline_ULTIMATE.init } true;assume { :begin_inline_main } true;havoc main_#res#1;havoc main_#t~ret98#1, main_~retValue_acc~32#1, main_~tmp~24#1;havoc main_~retValue_acc~32#1;havoc main_~tmp~24#1;assume { :begin_inline_select_helpers } true; {11604#true} is VALID [2022-02-20 17:56:09,339 INFO L290 TraceCheckUtils]: 2: Hoare triple {11604#true} assume { :end_inline_select_helpers } true;assume { :begin_inline_select_features } true; {11604#true} is VALID [2022-02-20 17:56:09,340 INFO L290 TraceCheckUtils]: 3: Hoare triple {11604#true} assume { :end_inline_select_features } true;assume { :begin_inline_valid_product } true;havoc valid_product_#res#1;havoc valid_product_~retValue_acc~9#1;havoc valid_product_~retValue_acc~9#1;valid_product_~retValue_acc~9#1 := 1;valid_product_#res#1 := valid_product_~retValue_acc~9#1; {11604#true} is VALID [2022-02-20 17:56:09,340 INFO L290 TraceCheckUtils]: 4: Hoare triple {11604#true} main_#t~ret98#1 := valid_product_#res#1;assume { :end_inline_valid_product } true;assume -2147483648 <= main_#t~ret98#1 && main_#t~ret98#1 <= 2147483647;main_~tmp~24#1 := main_#t~ret98#1;havoc main_#t~ret98#1; {11604#true} is VALID [2022-02-20 17:56:09,340 INFO L290 TraceCheckUtils]: 5: Hoare triple {11604#true} assume 0 != main_~tmp~24#1;assume { :begin_inline_setup } true;havoc setup_#t~nondet95#1, setup_#t~nondet96#1, setup_#t~nondet97#1, setup_~__cil_tmp1~0#1.base, setup_~__cil_tmp1~0#1.offset, setup_~__cil_tmp2~0#1.base, setup_~__cil_tmp2~0#1.offset, setup_~__cil_tmp3~2#1.base, setup_~__cil_tmp3~2#1.offset;havoc setup_~__cil_tmp1~0#1.base, setup_~__cil_tmp1~0#1.offset;havoc setup_~__cil_tmp2~0#1.base, setup_~__cil_tmp2~0#1.offset;havoc setup_~__cil_tmp3~2#1.base, setup_~__cil_tmp3~2#1.offset;~bob~0 := 1;assume { :begin_inline_setup_bob } true;setup_bob_#in~bob___0#1 := ~bob~0;havoc setup_bob_~bob___0#1;setup_bob_~bob___0#1 := setup_bob_#in~bob___0#1;assume { :begin_inline_setup_bob__wrappee__Base } true;setup_bob__wrappee__Base_#in~bob___0#1 := setup_bob_~bob___0#1;havoc setup_bob__wrappee__Base_~bob___0#1;setup_bob__wrappee__Base_~bob___0#1 := setup_bob__wrappee__Base_#in~bob___0#1; {11604#true} is VALID [2022-02-20 17:56:09,340 INFO L272 TraceCheckUtils]: 6: Hoare triple {11604#true} call setClientId(setup_bob__wrappee__Base_~bob___0#1, setup_bob__wrappee__Base_~bob___0#1); {11662#(and (= |old(~__ste_client_idCounter0~0)| ~__ste_client_idCounter0~0) (= |old(~__ste_client_idCounter1~0)| ~__ste_client_idCounter1~0) (= |old(~__ste_client_idCounter2~0)| ~__ste_client_idCounter2~0))} is VALID [2022-02-20 17:56:09,340 INFO L290 TraceCheckUtils]: 7: Hoare triple {11662#(and (= |old(~__ste_client_idCounter0~0)| ~__ste_client_idCounter0~0) (= |old(~__ste_client_idCounter1~0)| ~__ste_client_idCounter1~0) (= |old(~__ste_client_idCounter2~0)| ~__ste_client_idCounter2~0))} ~handle := #in~handle;~value := #in~value; {11604#true} is VALID [2022-02-20 17:56:09,341 INFO L290 TraceCheckUtils]: 8: Hoare triple {11604#true} assume 1 == ~handle;~__ste_client_idCounter0~0 := ~value; {11604#true} is VALID [2022-02-20 17:56:09,341 INFO L290 TraceCheckUtils]: 9: Hoare triple {11604#true} assume true; {11604#true} is VALID [2022-02-20 17:56:09,341 INFO L284 TraceCheckUtils]: 10: Hoare quadruple {11604#true} {11604#true} #1133#return; {11604#true} is VALID [2022-02-20 17:56:09,341 INFO L290 TraceCheckUtils]: 11: Hoare triple {11604#true} assume { :end_inline_setup_bob__wrappee__Base } true; {11604#true} is VALID [2022-02-20 17:56:09,341 INFO L272 TraceCheckUtils]: 12: Hoare triple {11604#true} call setClientPrivateKey(setup_bob_~bob___0#1, 123); {11663#(and (= ~__ste_client_privateKey0~0 |old(~__ste_client_privateKey0~0)|) (= ~__ste_client_privateKey2~0 |old(~__ste_client_privateKey2~0)|) (= ~__ste_client_privateKey1~0 |old(~__ste_client_privateKey1~0)|))} is VALID [2022-02-20 17:56:09,341 INFO L290 TraceCheckUtils]: 13: Hoare triple {11663#(and (= ~__ste_client_privateKey0~0 |old(~__ste_client_privateKey0~0)|) (= ~__ste_client_privateKey2~0 |old(~__ste_client_privateKey2~0)|) (= ~__ste_client_privateKey1~0 |old(~__ste_client_privateKey1~0)|))} ~handle := #in~handle;~value := #in~value; {11604#true} is VALID [2022-02-20 17:56:09,342 INFO L290 TraceCheckUtils]: 14: Hoare triple {11604#true} assume 1 == ~handle;~__ste_client_privateKey0~0 := ~value; {11604#true} is VALID [2022-02-20 17:56:09,342 INFO L290 TraceCheckUtils]: 15: Hoare triple {11604#true} assume true; {11604#true} is VALID [2022-02-20 17:56:09,342 INFO L284 TraceCheckUtils]: 16: Hoare quadruple {11604#true} {11604#true} #1135#return; {11604#true} is VALID [2022-02-20 17:56:09,342 INFO L290 TraceCheckUtils]: 17: Hoare triple {11604#true} assume { :end_inline_setup_bob } true;setup_~__cil_tmp1~0#1.base, setup_~__cil_tmp1~0#1.offset := 34, 0;havoc setup_#t~nondet95#1;~rjh~0 := 2;assume { :begin_inline_setup_rjh } true;setup_rjh_#in~rjh___0#1 := ~rjh~0;havoc setup_rjh_~rjh___0#1;setup_rjh_~rjh___0#1 := setup_rjh_#in~rjh___0#1;assume { :begin_inline_setup_rjh__wrappee__Base } true;setup_rjh__wrappee__Base_#in~rjh___0#1 := setup_rjh_~rjh___0#1;havoc setup_rjh__wrappee__Base_~rjh___0#1;setup_rjh__wrappee__Base_~rjh___0#1 := setup_rjh__wrappee__Base_#in~rjh___0#1; {11614#(= |ULTIMATE.start_setup_rjh_~rjh___0#1| |ULTIMATE.start_setup_rjh__wrappee__Base_~rjh___0#1|)} is VALID [2022-02-20 17:56:09,343 INFO L272 TraceCheckUtils]: 18: Hoare triple {11614#(= |ULTIMATE.start_setup_rjh_~rjh___0#1| |ULTIMATE.start_setup_rjh__wrappee__Base_~rjh___0#1|)} call setClientId(setup_rjh__wrappee__Base_~rjh___0#1, setup_rjh__wrappee__Base_~rjh___0#1); {11662#(and (= |old(~__ste_client_idCounter0~0)| ~__ste_client_idCounter0~0) (= |old(~__ste_client_idCounter1~0)| ~__ste_client_idCounter1~0) (= |old(~__ste_client_idCounter2~0)| ~__ste_client_idCounter2~0))} is VALID [2022-02-20 17:56:09,343 INFO L290 TraceCheckUtils]: 19: Hoare triple {11662#(and (= |old(~__ste_client_idCounter0~0)| ~__ste_client_idCounter0~0) (= |old(~__ste_client_idCounter1~0)| ~__ste_client_idCounter1~0) (= |old(~__ste_client_idCounter2~0)| ~__ste_client_idCounter2~0))} ~handle := #in~handle;~value := #in~value; {11664#(= setClientId_~handle |setClientId_#in~handle|)} is VALID [2022-02-20 17:56:09,343 INFO L290 TraceCheckUtils]: 20: Hoare triple {11664#(= setClientId_~handle |setClientId_#in~handle|)} assume !(1 == ~handle); {11664#(= setClientId_~handle |setClientId_#in~handle|)} is VALID [2022-02-20 17:56:09,343 INFO L290 TraceCheckUtils]: 21: Hoare triple {11664#(= setClientId_~handle |setClientId_#in~handle|)} assume 2 == ~handle;~__ste_client_idCounter1~0 := ~value; {11665#(= 2 |setClientId_#in~handle|)} is VALID [2022-02-20 17:56:09,344 INFO L290 TraceCheckUtils]: 22: Hoare triple {11665#(= 2 |setClientId_#in~handle|)} assume true; {11665#(= 2 |setClientId_#in~handle|)} is VALID [2022-02-20 17:56:09,344 INFO L284 TraceCheckUtils]: 23: Hoare quadruple {11665#(= 2 |setClientId_#in~handle|)} {11614#(= |ULTIMATE.start_setup_rjh_~rjh___0#1| |ULTIMATE.start_setup_rjh__wrappee__Base_~rjh___0#1|)} #1137#return; {11620#(not (= |ULTIMATE.start_setup_rjh_~rjh___0#1| 1))} is VALID [2022-02-20 17:56:09,344 INFO L290 TraceCheckUtils]: 24: Hoare triple {11620#(not (= |ULTIMATE.start_setup_rjh_~rjh___0#1| 1))} assume { :end_inline_setup_rjh__wrappee__Base } true; {11620#(not (= |ULTIMATE.start_setup_rjh_~rjh___0#1| 1))} is VALID [2022-02-20 17:56:09,345 INFO L272 TraceCheckUtils]: 25: Hoare triple {11620#(not (= |ULTIMATE.start_setup_rjh_~rjh___0#1| 1))} call setClientPrivateKey(setup_rjh_~rjh___0#1, 456); {11663#(and (= ~__ste_client_privateKey0~0 |old(~__ste_client_privateKey0~0)|) (= ~__ste_client_privateKey2~0 |old(~__ste_client_privateKey2~0)|) (= ~__ste_client_privateKey1~0 |old(~__ste_client_privateKey1~0)|))} is VALID [2022-02-20 17:56:09,345 INFO L290 TraceCheckUtils]: 26: Hoare triple {11663#(and (= ~__ste_client_privateKey0~0 |old(~__ste_client_privateKey0~0)|) (= ~__ste_client_privateKey2~0 |old(~__ste_client_privateKey2~0)|) (= ~__ste_client_privateKey1~0 |old(~__ste_client_privateKey1~0)|))} ~handle := #in~handle;~value := #in~value; {11666#(= setClientPrivateKey_~handle |setClientPrivateKey_#in~handle|)} is VALID [2022-02-20 17:56:09,345 INFO L290 TraceCheckUtils]: 27: Hoare triple {11666#(= setClientPrivateKey_~handle |setClientPrivateKey_#in~handle|)} assume 1 == ~handle;~__ste_client_privateKey0~0 := ~value; {11667#(= |setClientPrivateKey_#in~handle| 1)} is VALID [2022-02-20 17:56:09,346 INFO L290 TraceCheckUtils]: 28: Hoare triple {11667#(= |setClientPrivateKey_#in~handle| 1)} assume true; {11667#(= |setClientPrivateKey_#in~handle| 1)} is VALID [2022-02-20 17:56:09,346 INFO L284 TraceCheckUtils]: 29: Hoare quadruple {11667#(= |setClientPrivateKey_#in~handle| 1)} {11620#(not (= |ULTIMATE.start_setup_rjh_~rjh___0#1| 1))} #1139#return; {11605#false} is VALID [2022-02-20 17:56:09,346 INFO L290 TraceCheckUtils]: 30: Hoare triple {11605#false} assume { :end_inline_setup_rjh } true;setup_~__cil_tmp2~0#1.base, setup_~__cil_tmp2~0#1.offset := 35, 0;havoc setup_#t~nondet96#1;~chuck~0 := 3;assume { :begin_inline_setup_chuck } true;setup_chuck_#in~chuck___0#1 := ~chuck~0;havoc setup_chuck_~chuck___0#1;setup_chuck_~chuck___0#1 := setup_chuck_#in~chuck___0#1;assume { :begin_inline_setup_chuck__wrappee__Base } true;setup_chuck__wrappee__Base_#in~chuck___0#1 := setup_chuck_~chuck___0#1;havoc setup_chuck__wrappee__Base_~chuck___0#1;setup_chuck__wrappee__Base_~chuck___0#1 := setup_chuck__wrappee__Base_#in~chuck___0#1; {11605#false} is VALID [2022-02-20 17:56:09,346 INFO L272 TraceCheckUtils]: 31: Hoare triple {11605#false} call setClientId(setup_chuck__wrappee__Base_~chuck___0#1, setup_chuck__wrappee__Base_~chuck___0#1); {11662#(and (= |old(~__ste_client_idCounter0~0)| ~__ste_client_idCounter0~0) (= |old(~__ste_client_idCounter1~0)| ~__ste_client_idCounter1~0) (= |old(~__ste_client_idCounter2~0)| ~__ste_client_idCounter2~0))} is VALID [2022-02-20 17:56:09,346 INFO L290 TraceCheckUtils]: 32: Hoare triple {11662#(and (= |old(~__ste_client_idCounter0~0)| ~__ste_client_idCounter0~0) (= |old(~__ste_client_idCounter1~0)| ~__ste_client_idCounter1~0) (= |old(~__ste_client_idCounter2~0)| ~__ste_client_idCounter2~0))} ~handle := #in~handle;~value := #in~value; {11604#true} is VALID [2022-02-20 17:56:09,347 INFO L290 TraceCheckUtils]: 33: Hoare triple {11604#true} assume 1 == ~handle;~__ste_client_idCounter0~0 := ~value; {11604#true} is VALID [2022-02-20 17:56:09,347 INFO L290 TraceCheckUtils]: 34: Hoare triple {11604#true} assume true; {11604#true} is VALID [2022-02-20 17:56:09,347 INFO L284 TraceCheckUtils]: 35: Hoare quadruple {11604#true} {11605#false} #1141#return; {11605#false} is VALID [2022-02-20 17:56:09,347 INFO L290 TraceCheckUtils]: 36: Hoare triple {11605#false} assume { :end_inline_setup_chuck__wrappee__Base } true; {11605#false} is VALID [2022-02-20 17:56:09,347 INFO L272 TraceCheckUtils]: 37: Hoare triple {11605#false} call setClientPrivateKey(setup_chuck_~chuck___0#1, 789); {11663#(and (= ~__ste_client_privateKey0~0 |old(~__ste_client_privateKey0~0)|) (= ~__ste_client_privateKey2~0 |old(~__ste_client_privateKey2~0)|) (= ~__ste_client_privateKey1~0 |old(~__ste_client_privateKey1~0)|))} is VALID [2022-02-20 17:56:09,347 INFO L290 TraceCheckUtils]: 38: Hoare triple {11663#(and (= ~__ste_client_privateKey0~0 |old(~__ste_client_privateKey0~0)|) (= ~__ste_client_privateKey2~0 |old(~__ste_client_privateKey2~0)|) (= ~__ste_client_privateKey1~0 |old(~__ste_client_privateKey1~0)|))} ~handle := #in~handle;~value := #in~value; {11604#true} is VALID [2022-02-20 17:56:09,347 INFO L290 TraceCheckUtils]: 39: Hoare triple {11604#true} assume 1 == ~handle;~__ste_client_privateKey0~0 := ~value; {11604#true} is VALID [2022-02-20 17:56:09,347 INFO L290 TraceCheckUtils]: 40: Hoare triple {11604#true} assume true; {11604#true} is VALID [2022-02-20 17:56:09,347 INFO L284 TraceCheckUtils]: 41: Hoare quadruple {11604#true} {11605#false} #1143#return; {11605#false} is VALID [2022-02-20 17:56:09,347 INFO L290 TraceCheckUtils]: 42: Hoare triple {11605#false} assume { :end_inline_setup_chuck } true;setup_~__cil_tmp3~2#1.base, setup_~__cil_tmp3~2#1.offset := 36, 0;havoc setup_#t~nondet97#1; {11605#false} is VALID [2022-02-20 17:56:09,348 INFO L290 TraceCheckUtils]: 43: Hoare triple {11605#false} assume { :end_inline_setup } true;assume { :begin_inline_test } true;havoc test_#t~nondet48#1, test_#t~nondet49#1, test_#t~nondet50#1, test_#t~nondet51#1, test_#t~nondet52#1, test_#t~nondet53#1, test_#t~nondet54#1, test_#t~nondet55#1, test_#t~nondet56#1, test_#t~nondet57#1, test_#t~nondet58#1, test_~op1~0#1, test_~op2~0#1, test_~op3~0#1, test_~op4~0#1, test_~op5~0#1, test_~op6~0#1, test_~op7~0#1, test_~op8~0#1, test_~op9~0#1, test_~op10~0#1, test_~op11~0#1, test_~splverifierCounter~0#1, test_~tmp~8#1, test_~tmp___0~3#1, test_~tmp___1~1#1, test_~tmp___2~1#1, test_~tmp___3~0#1, test_~tmp___4~0#1, test_~tmp___5~0#1, test_~tmp___6~0#1, test_~tmp___7~0#1, test_~tmp___8~0#1, test_~tmp___9~0#1;havoc test_~op1~0#1;havoc test_~op2~0#1;havoc test_~op3~0#1;havoc test_~op4~0#1;havoc test_~op5~0#1;havoc test_~op6~0#1;havoc test_~op7~0#1;havoc test_~op8~0#1;havoc test_~op9~0#1;havoc test_~op10~0#1;havoc test_~op11~0#1;havoc test_~splverifierCounter~0#1;havoc test_~tmp~8#1;havoc test_~tmp___0~3#1;havoc test_~tmp___1~1#1;havoc test_~tmp___2~1#1;havoc test_~tmp___3~0#1;havoc test_~tmp___4~0#1;havoc test_~tmp___5~0#1;havoc test_~tmp___6~0#1;havoc test_~tmp___7~0#1;havoc test_~tmp___8~0#1;havoc test_~tmp___9~0#1;test_~op1~0#1 := 0;test_~op2~0#1 := 0;test_~op3~0#1 := 0;test_~op4~0#1 := 0;test_~op5~0#1 := 0;test_~op6~0#1 := 0;test_~op7~0#1 := 0;test_~op8~0#1 := 0;test_~op9~0#1 := 0;test_~op10~0#1 := 0;test_~op11~0#1 := 0;test_~splverifierCounter~0#1 := 0; {11605#false} is VALID [2022-02-20 17:56:09,348 INFO L290 TraceCheckUtils]: 44: Hoare triple {11605#false} assume !false; {11605#false} is VALID [2022-02-20 17:56:09,348 INFO L290 TraceCheckUtils]: 45: Hoare triple {11605#false} assume test_~splverifierCounter~0#1 < 4; {11605#false} is VALID [2022-02-20 17:56:09,348 INFO L290 TraceCheckUtils]: 46: Hoare triple {11605#false} test_~splverifierCounter~0#1 := 1 + test_~splverifierCounter~0#1; {11605#false} is VALID [2022-02-20 17:56:09,348 INFO L290 TraceCheckUtils]: 47: Hoare triple {11605#false} assume 0 == test_~op1~0#1;assume -2147483648 <= test_#t~nondet48#1 && test_#t~nondet48#1 <= 2147483647;test_~tmp___9~0#1 := test_#t~nondet48#1;havoc test_#t~nondet48#1; {11605#false} is VALID [2022-02-20 17:56:09,348 INFO L290 TraceCheckUtils]: 48: Hoare triple {11605#false} assume !(0 != test_~tmp___9~0#1); {11605#false} is VALID [2022-02-20 17:56:09,348 INFO L290 TraceCheckUtils]: 49: Hoare triple {11605#false} assume 0 == test_~op2~0#1;assume -2147483648 <= test_#t~nondet49#1 && test_#t~nondet49#1 <= 2147483647;test_~tmp___8~0#1 := test_#t~nondet49#1;havoc test_#t~nondet49#1; {11605#false} is VALID [2022-02-20 17:56:09,348 INFO L290 TraceCheckUtils]: 50: Hoare triple {11605#false} assume 0 != test_~tmp___8~0#1;assume { :begin_inline_rjhSetAutoRespond } true;assume { :begin_inline_setClientAutoResponse } true;setClientAutoResponse_#in~handle#1, setClientAutoResponse_#in~value#1 := ~rjh~0, 1;havoc setClientAutoResponse_~handle#1, setClientAutoResponse_~value#1;setClientAutoResponse_~handle#1 := setClientAutoResponse_#in~handle#1;setClientAutoResponse_~value#1 := setClientAutoResponse_#in~value#1; {11605#false} is VALID [2022-02-20 17:56:09,348 INFO L290 TraceCheckUtils]: 51: Hoare triple {11605#false} assume 1 == setClientAutoResponse_~handle#1;~__ste_client_autoResponse0~0 := setClientAutoResponse_~value#1; {11605#false} is VALID [2022-02-20 17:56:09,348 INFO L290 TraceCheckUtils]: 52: Hoare triple {11605#false} assume { :end_inline_setClientAutoResponse } true; {11605#false} is VALID [2022-02-20 17:56:09,349 INFO L290 TraceCheckUtils]: 53: Hoare triple {11605#false} assume { :end_inline_rjhSetAutoRespond } true;test_~op2~0#1 := 1; {11605#false} is VALID [2022-02-20 17:56:09,349 INFO L290 TraceCheckUtils]: 54: Hoare triple {11605#false} assume !false; {11605#false} is VALID [2022-02-20 17:56:09,349 INFO L290 TraceCheckUtils]: 55: Hoare triple {11605#false} assume !(test_~splverifierCounter~0#1 < 4); {11605#false} is VALID [2022-02-20 17:56:09,349 INFO L290 TraceCheckUtils]: 56: Hoare triple {11605#false} assume { :begin_inline_bobToRjh } true;havoc bobToRjh_#t~ret90#1, bobToRjh_#t~ret91#1, bobToRjh_#t~ret92#1, bobToRjh_#t~ret93#1, bobToRjh_~tmp~23#1, bobToRjh_~tmp___0~7#1, bobToRjh_~tmp___1~4#1;havoc bobToRjh_~tmp~23#1;havoc bobToRjh_~tmp___0~7#1;havoc bobToRjh_~tmp___1~4#1;call bobToRjh_#t~ret90#1 := puts(32, 0);assume -2147483648 <= bobToRjh_#t~ret90#1 && bobToRjh_#t~ret90#1 <= 2147483647;havoc bobToRjh_#t~ret90#1; {11605#false} is VALID [2022-02-20 17:56:09,349 INFO L272 TraceCheckUtils]: 57: Hoare triple {11605#false} call sendEmail(~bob~0, ~rjh~0); {11605#false} is VALID [2022-02-20 17:56:09,349 INFO L290 TraceCheckUtils]: 58: Hoare triple {11605#false} ~sender#1 := #in~sender#1;~receiver#1 := #in~receiver#1;havoc ~email~0#1;havoc ~tmp~16#1;assume { :begin_inline_createEmail } true;createEmail_#in~from#1, createEmail_#in~to#1 := 0, ~receiver#1;havoc createEmail_#res#1;havoc createEmail_~from#1, createEmail_~to#1, createEmail_~retValue_acc~4#1, createEmail_~msg~0#1;createEmail_~from#1 := createEmail_#in~from#1;createEmail_~to#1 := createEmail_#in~to#1;havoc createEmail_~retValue_acc~4#1;havoc createEmail_~msg~0#1;createEmail_~msg~0#1 := 1; {11605#false} is VALID [2022-02-20 17:56:09,349 INFO L272 TraceCheckUtils]: 59: Hoare triple {11605#false} call setEmailFrom(createEmail_~msg~0#1, createEmail_~from#1); {11668#(and (= |old(~__ste_email_from0~0)| ~__ste_email_from0~0) (= |old(~__ste_email_from1~0)| ~__ste_email_from1~0))} is VALID [2022-02-20 17:56:09,349 INFO L290 TraceCheckUtils]: 60: Hoare triple {11668#(and (= |old(~__ste_email_from0~0)| ~__ste_email_from0~0) (= |old(~__ste_email_from1~0)| ~__ste_email_from1~0))} ~handle := #in~handle;~value := #in~value; {11604#true} is VALID [2022-02-20 17:56:09,349 INFO L290 TraceCheckUtils]: 61: Hoare triple {11604#true} assume 1 == ~handle;~__ste_email_from0~0 := ~value; {11604#true} is VALID [2022-02-20 17:56:09,349 INFO L290 TraceCheckUtils]: 62: Hoare triple {11604#true} assume true; {11604#true} is VALID [2022-02-20 17:56:09,350 INFO L284 TraceCheckUtils]: 63: Hoare quadruple {11604#true} {11605#false} #1119#return; {11605#false} is VALID [2022-02-20 17:56:09,350 INFO L272 TraceCheckUtils]: 64: Hoare triple {11605#false} call setEmailTo(createEmail_~msg~0#1, createEmail_~to#1); {11669#(and (= ~__ste_email_to0~0 |old(~__ste_email_to0~0)|) (= ~__ste_email_to1~0 |old(~__ste_email_to1~0)|))} is VALID [2022-02-20 17:56:09,350 INFO L290 TraceCheckUtils]: 65: Hoare triple {11669#(and (= ~__ste_email_to0~0 |old(~__ste_email_to0~0)|) (= ~__ste_email_to1~0 |old(~__ste_email_to1~0)|))} ~handle := #in~handle;~value := #in~value; {11604#true} is VALID [2022-02-20 17:56:09,350 INFO L290 TraceCheckUtils]: 66: Hoare triple {11604#true} assume 1 == ~handle;~__ste_email_to0~0 := ~value; {11604#true} is VALID [2022-02-20 17:56:09,350 INFO L290 TraceCheckUtils]: 67: Hoare triple {11604#true} assume true; {11604#true} is VALID [2022-02-20 17:56:09,350 INFO L284 TraceCheckUtils]: 68: Hoare quadruple {11604#true} {11605#false} #1121#return; {11605#false} is VALID [2022-02-20 17:56:09,350 INFO L290 TraceCheckUtils]: 69: Hoare triple {11605#false} createEmail_~retValue_acc~4#1 := createEmail_~msg~0#1;createEmail_#res#1 := createEmail_~retValue_acc~4#1; {11605#false} is VALID [2022-02-20 17:56:09,350 INFO L290 TraceCheckUtils]: 70: Hoare triple {11605#false} #t~ret73#1 := createEmail_#res#1;assume { :end_inline_createEmail } true;assume -2147483648 <= #t~ret73#1 && #t~ret73#1 <= 2147483647;~tmp~16#1 := #t~ret73#1;havoc #t~ret73#1;~email~0#1 := ~tmp~16#1; {11605#false} is VALID [2022-02-20 17:56:09,350 INFO L272 TraceCheckUtils]: 71: Hoare triple {11605#false} call outgoing(~sender#1, ~email~0#1); {11605#false} is VALID [2022-02-20 17:56:09,350 INFO L290 TraceCheckUtils]: 72: Hoare triple {11605#false} ~client#1 := #in~client#1;~msg#1 := #in~msg#1;assume { :begin_inline_sign } true;sign_#in~client#1, sign_#in~msg#1 := ~client#1, ~msg#1;havoc sign_#t~ret77#1, sign_~client#1, sign_~msg#1, sign_~privkey~1#1, sign_~tmp~18#1;sign_~client#1 := sign_#in~client#1;sign_~msg#1 := sign_#in~msg#1;havoc sign_~privkey~1#1;havoc sign_~tmp~18#1; {11605#false} is VALID [2022-02-20 17:56:09,351 INFO L272 TraceCheckUtils]: 73: Hoare triple {11605#false} call sign_#t~ret77#1 := getClientPrivateKey(sign_~client#1); {11604#true} is VALID [2022-02-20 17:56:09,351 INFO L290 TraceCheckUtils]: 74: Hoare triple {11604#true} ~handle := #in~handle;havoc ~retValue_acc~24; {11604#true} is VALID [2022-02-20 17:56:09,351 INFO L290 TraceCheckUtils]: 75: Hoare triple {11604#true} assume 1 == ~handle;~retValue_acc~24 := ~__ste_client_privateKey0~0;#res := ~retValue_acc~24; {11604#true} is VALID [2022-02-20 17:56:09,351 INFO L290 TraceCheckUtils]: 76: Hoare triple {11604#true} assume true; {11604#true} is VALID [2022-02-20 17:56:09,351 INFO L284 TraceCheckUtils]: 77: Hoare quadruple {11604#true} {11605#false} #1053#return; {11605#false} is VALID [2022-02-20 17:56:09,351 INFO L290 TraceCheckUtils]: 78: Hoare triple {11605#false} assume -2147483648 <= sign_#t~ret77#1 && sign_#t~ret77#1 <= 2147483647;sign_~tmp~18#1 := sign_#t~ret77#1;havoc sign_#t~ret77#1;sign_~privkey~1#1 := sign_~tmp~18#1; {11605#false} is VALID [2022-02-20 17:56:09,351 INFO L290 TraceCheckUtils]: 79: Hoare triple {11605#false} assume 0 == sign_~privkey~1#1; {11605#false} is VALID [2022-02-20 17:56:09,351 INFO L290 TraceCheckUtils]: 80: Hoare triple {11605#false} assume { :end_inline_sign } true;assume { :begin_inline_outgoing__wrappee__AutoResponder } true;outgoing__wrappee__AutoResponder_#in~client#1, outgoing__wrappee__AutoResponder_#in~msg#1 := ~client#1, ~msg#1;havoc outgoing__wrappee__AutoResponder_#t~ret63#1, outgoing__wrappee__AutoResponder_#t~ret64#1, outgoing__wrappee__AutoResponder_~client#1, outgoing__wrappee__AutoResponder_~msg#1, outgoing__wrappee__AutoResponder_~receiver~0#1, outgoing__wrappee__AutoResponder_~tmp~11#1, outgoing__wrappee__AutoResponder_~pubkey~0#1, outgoing__wrappee__AutoResponder_~tmp___0~4#1;outgoing__wrappee__AutoResponder_~client#1 := outgoing__wrappee__AutoResponder_#in~client#1;outgoing__wrappee__AutoResponder_~msg#1 := outgoing__wrappee__AutoResponder_#in~msg#1;havoc outgoing__wrappee__AutoResponder_~receiver~0#1;havoc outgoing__wrappee__AutoResponder_~tmp~11#1;havoc outgoing__wrappee__AutoResponder_~pubkey~0#1;havoc outgoing__wrappee__AutoResponder_~tmp___0~4#1; {11605#false} is VALID [2022-02-20 17:56:09,351 INFO L272 TraceCheckUtils]: 81: Hoare triple {11605#false} call outgoing__wrappee__AutoResponder_#t~ret63#1 := getEmailTo(outgoing__wrappee__AutoResponder_~msg#1); {11604#true} is VALID [2022-02-20 17:56:09,352 INFO L290 TraceCheckUtils]: 82: Hoare triple {11604#true} ~handle := #in~handle;havoc ~retValue_acc~36; {11604#true} is VALID [2022-02-20 17:56:09,352 INFO L290 TraceCheckUtils]: 83: Hoare triple {11604#true} assume 1 == ~handle;~retValue_acc~36 := ~__ste_email_to0~0;#res := ~retValue_acc~36; {11604#true} is VALID [2022-02-20 17:56:09,352 INFO L290 TraceCheckUtils]: 84: Hoare triple {11604#true} assume true; {11604#true} is VALID [2022-02-20 17:56:09,352 INFO L284 TraceCheckUtils]: 85: Hoare quadruple {11604#true} {11605#false} #1055#return; {11605#false} is VALID [2022-02-20 17:56:09,352 INFO L290 TraceCheckUtils]: 86: Hoare triple {11605#false} assume -2147483648 <= outgoing__wrappee__AutoResponder_#t~ret63#1 && outgoing__wrappee__AutoResponder_#t~ret63#1 <= 2147483647;outgoing__wrappee__AutoResponder_~tmp~11#1 := outgoing__wrappee__AutoResponder_#t~ret63#1;havoc outgoing__wrappee__AutoResponder_#t~ret63#1;outgoing__wrappee__AutoResponder_~receiver~0#1 := outgoing__wrappee__AutoResponder_~tmp~11#1; {11605#false} is VALID [2022-02-20 17:56:09,352 INFO L272 TraceCheckUtils]: 87: Hoare triple {11605#false} call outgoing__wrappee__AutoResponder_#t~ret64#1 := findPublicKey(outgoing__wrappee__AutoResponder_~client#1, outgoing__wrappee__AutoResponder_~receiver~0#1); {11604#true} is VALID [2022-02-20 17:56:09,352 INFO L290 TraceCheckUtils]: 88: Hoare triple {11604#true} ~handle := #in~handle;~userid := #in~userid;havoc ~retValue_acc~29; {11604#true} is VALID [2022-02-20 17:56:09,352 INFO L290 TraceCheckUtils]: 89: Hoare triple {11604#true} assume 1 == ~handle; {11604#true} is VALID [2022-02-20 17:56:09,352 INFO L290 TraceCheckUtils]: 90: Hoare triple {11604#true} assume ~userid == ~__ste_Client_Keyring0_User0~0;~retValue_acc~29 := ~__ste_Client_Keyring0_PublicKey0~0;#res := ~retValue_acc~29; {11604#true} is VALID [2022-02-20 17:56:09,352 INFO L290 TraceCheckUtils]: 91: Hoare triple {11604#true} assume true; {11604#true} is VALID [2022-02-20 17:56:09,353 INFO L284 TraceCheckUtils]: 92: Hoare quadruple {11604#true} {11605#false} #1057#return; {11605#false} is VALID [2022-02-20 17:56:09,353 INFO L290 TraceCheckUtils]: 93: Hoare triple {11605#false} assume -2147483648 <= outgoing__wrappee__AutoResponder_#t~ret64#1 && outgoing__wrappee__AutoResponder_#t~ret64#1 <= 2147483647;outgoing__wrappee__AutoResponder_~tmp___0~4#1 := outgoing__wrappee__AutoResponder_#t~ret64#1;havoc outgoing__wrappee__AutoResponder_#t~ret64#1;outgoing__wrappee__AutoResponder_~pubkey~0#1 := outgoing__wrappee__AutoResponder_~tmp___0~4#1; {11605#false} is VALID [2022-02-20 17:56:09,353 INFO L290 TraceCheckUtils]: 94: Hoare triple {11605#false} assume !(0 != outgoing__wrappee__AutoResponder_~pubkey~0#1); {11605#false} is VALID [2022-02-20 17:56:09,353 INFO L290 TraceCheckUtils]: 95: Hoare triple {11605#false} assume { :begin_inline_outgoing__wrappee__Keys } true;outgoing__wrappee__Keys_#in~client#1, outgoing__wrappee__Keys_#in~msg#1 := outgoing__wrappee__AutoResponder_~client#1, outgoing__wrappee__AutoResponder_~msg#1;havoc outgoing__wrappee__Keys_#t~ret62#1, outgoing__wrappee__Keys_~client#1, outgoing__wrappee__Keys_~msg#1, outgoing__wrappee__Keys_~tmp~10#1;outgoing__wrappee__Keys_~client#1 := outgoing__wrappee__Keys_#in~client#1;outgoing__wrappee__Keys_~msg#1 := outgoing__wrappee__Keys_#in~msg#1;havoc outgoing__wrappee__Keys_~tmp~10#1;assume { :begin_inline_getClientId } true;getClientId_#in~handle#1 := outgoing__wrappee__Keys_~client#1;havoc getClientId_#res#1;havoc getClientId_~handle#1, getClientId_~retValue_acc~31#1;getClientId_~handle#1 := getClientId_#in~handle#1;havoc getClientId_~retValue_acc~31#1; {11605#false} is VALID [2022-02-20 17:56:09,353 INFO L290 TraceCheckUtils]: 96: Hoare triple {11605#false} assume 1 == getClientId_~handle#1;getClientId_~retValue_acc~31#1 := ~__ste_client_idCounter0~0;getClientId_#res#1 := getClientId_~retValue_acc~31#1; {11605#false} is VALID [2022-02-20 17:56:09,353 INFO L290 TraceCheckUtils]: 97: Hoare triple {11605#false} outgoing__wrappee__Keys_#t~ret62#1 := getClientId_#res#1;assume { :end_inline_getClientId } true;assume -2147483648 <= outgoing__wrappee__Keys_#t~ret62#1 && outgoing__wrappee__Keys_#t~ret62#1 <= 2147483647;outgoing__wrappee__Keys_~tmp~10#1 := outgoing__wrappee__Keys_#t~ret62#1;havoc outgoing__wrappee__Keys_#t~ret62#1; {11605#false} is VALID [2022-02-20 17:56:09,353 INFO L272 TraceCheckUtils]: 98: Hoare triple {11605#false} call setEmailFrom(outgoing__wrappee__Keys_~msg#1, outgoing__wrappee__Keys_~tmp~10#1); {11668#(and (= |old(~__ste_email_from0~0)| ~__ste_email_from0~0) (= |old(~__ste_email_from1~0)| ~__ste_email_from1~0))} is VALID [2022-02-20 17:56:09,353 INFO L290 TraceCheckUtils]: 99: Hoare triple {11668#(and (= |old(~__ste_email_from0~0)| ~__ste_email_from0~0) (= |old(~__ste_email_from1~0)| ~__ste_email_from1~0))} ~handle := #in~handle;~value := #in~value; {11604#true} is VALID [2022-02-20 17:56:09,353 INFO L290 TraceCheckUtils]: 100: Hoare triple {11604#true} assume 1 == ~handle;~__ste_email_from0~0 := ~value; {11604#true} is VALID [2022-02-20 17:56:09,353 INFO L290 TraceCheckUtils]: 101: Hoare triple {11604#true} assume true; {11604#true} is VALID [2022-02-20 17:56:09,354 INFO L284 TraceCheckUtils]: 102: Hoare quadruple {11604#true} {11605#false} #1063#return; {11605#false} is VALID [2022-02-20 17:56:09,354 INFO L290 TraceCheckUtils]: 103: Hoare triple {11605#false} assume { :begin_inline_mail } true;mail_#in~client#1, mail_#in~msg#1 := outgoing__wrappee__Keys_~client#1, outgoing__wrappee__Keys_~msg#1;havoc mail_#t~ret60#1, mail_#t~ret61#1, mail_~client#1, mail_~msg#1, mail_~__utac__ad__arg1~0#1, mail_~__utac__ad__arg2~0#1, mail_~tmp~9#1;mail_~client#1 := mail_#in~client#1;mail_~msg#1 := mail_#in~msg#1;havoc mail_~__utac__ad__arg1~0#1;havoc mail_~__utac__ad__arg2~0#1;havoc mail_~tmp~9#1;mail_~__utac__ad__arg1~0#1 := mail_~client#1;mail_~__utac__ad__arg2~0#1 := mail_~msg#1;assume { :begin_inline___utac_acc__AddressBookEncrypt_spec__1 } true;__utac_acc__AddressBookEncrypt_spec__1_#in~client#1, __utac_acc__AddressBookEncrypt_spec__1_#in~msg#1 := mail_~__utac__ad__arg1~0#1, mail_~__utac__ad__arg2~0#1;havoc __utac_acc__AddressBookEncrypt_spec__1_#t~ret85#1, __utac_acc__AddressBookEncrypt_spec__1_#t~ret86#1, __utac_acc__AddressBookEncrypt_spec__1_#t~ret87#1, __utac_acc__AddressBookEncrypt_spec__1_~client#1, __utac_acc__AddressBookEncrypt_spec__1_~msg#1, __utac_acc__AddressBookEncrypt_spec__1_~tmp~20#1;__utac_acc__AddressBookEncrypt_spec__1_~client#1 := __utac_acc__AddressBookEncrypt_spec__1_#in~client#1;__utac_acc__AddressBookEncrypt_spec__1_~msg#1 := __utac_acc__AddressBookEncrypt_spec__1_#in~msg#1;havoc __utac_acc__AddressBookEncrypt_spec__1_~tmp~20#1;call __utac_acc__AddressBookEncrypt_spec__1_#t~ret85#1 := puts(31, 0);assume -2147483648 <= __utac_acc__AddressBookEncrypt_spec__1_#t~ret85#1 && __utac_acc__AddressBookEncrypt_spec__1_#t~ret85#1 <= 2147483647;havoc __utac_acc__AddressBookEncrypt_spec__1_#t~ret85#1; {11605#false} is VALID [2022-02-20 17:56:09,354 INFO L290 TraceCheckUtils]: 104: Hoare triple {11605#false} assume !(-1 == ~mail_is_sensitive~0); {11605#false} is VALID [2022-02-20 17:56:09,354 INFO L272 TraceCheckUtils]: 105: Hoare triple {11605#false} call __utac_acc__AddressBookEncrypt_spec__1_#t~ret87#1 := isEncrypted(__utac_acc__AddressBookEncrypt_spec__1_~msg#1); {11604#true} is VALID [2022-02-20 17:56:09,354 INFO L290 TraceCheckUtils]: 106: Hoare triple {11604#true} ~handle := #in~handle;havoc ~retValue_acc~39; {11604#true} is VALID [2022-02-20 17:56:09,354 INFO L290 TraceCheckUtils]: 107: Hoare triple {11604#true} assume 1 == ~handle;~retValue_acc~39 := ~__ste_email_isEncrypted0~0;#res := ~retValue_acc~39; {11604#true} is VALID [2022-02-20 17:56:09,354 INFO L290 TraceCheckUtils]: 108: Hoare triple {11604#true} assume true; {11604#true} is VALID [2022-02-20 17:56:09,354 INFO L284 TraceCheckUtils]: 109: Hoare quadruple {11604#true} {11605#false} #1067#return; {11605#false} is VALID [2022-02-20 17:56:09,354 INFO L290 TraceCheckUtils]: 110: Hoare triple {11605#false} assume -2147483648 <= __utac_acc__AddressBookEncrypt_spec__1_#t~ret87#1 && __utac_acc__AddressBookEncrypt_spec__1_#t~ret87#1 <= 2147483647;__utac_acc__AddressBookEncrypt_spec__1_~tmp~20#1 := __utac_acc__AddressBookEncrypt_spec__1_#t~ret87#1;havoc __utac_acc__AddressBookEncrypt_spec__1_#t~ret87#1; {11605#false} is VALID [2022-02-20 17:56:09,355 INFO L290 TraceCheckUtils]: 111: Hoare triple {11605#false} assume ~mail_is_sensitive~0 != __utac_acc__AddressBookEncrypt_spec__1_~tmp~20#1;assume { :begin_inline___automaton_fail } true; {11605#false} is VALID [2022-02-20 17:56:09,355 INFO L290 TraceCheckUtils]: 112: Hoare triple {11605#false} assume !false; {11605#false} is VALID [2022-02-20 17:56:09,355 INFO L134 CoverageAnalysis]: Checked inductivity of 30 backedges. 6 proven. 6 refuted. 0 times theorem prover too weak. 18 trivial. 0 not checked. [2022-02-20 17:56:09,355 INFO L144 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2022-02-20 17:56:09,355 INFO L338 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [560374175] [2022-02-20 17:56:09,355 INFO L165 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [560374175] provided 0 perfect and 1 imperfect interpolant sequences [2022-02-20 17:56:09,355 INFO L338 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleZ3 [549942372] [2022-02-20 17:56:09,356 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-02-20 17:56:09,356 INFO L173 SolverBuilder]: Constructing external solver with command: z3 -smt2 -in SMTLIB2_COMPLIANT=true [2022-02-20 17:56:09,356 INFO L189 MonitoredProcess]: No working directory specified, using /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 [2022-02-20 17:56:09,357 INFO L229 MonitoredProcess]: Starting monitored process 6 with /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 -smt2 -in SMTLIB2_COMPLIANT=true (exit command is (exit), workingDir is null) [2022-02-20 17:56:09,379 INFO L327 MonitoredProcess]: [MP /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 -smt2 -in SMTLIB2_COMPLIANT=true (6)] Waiting until timeout for monitored process [2022-02-20 17:56:09,562 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-02-20 17:56:09,566 INFO L263 TraceCheckSpWp]: Trace formula consists of 1091 conjuncts, 6 conjunts are in the unsatisfiable core [2022-02-20 17:56:09,594 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-02-20 17:56:09,598 INFO L286 TraceCheckSpWp]: Computing forward predicates... [2022-02-20 17:56:09,860 INFO L290 TraceCheckUtils]: 0: Hoare triple {11604#true} assume { :begin_inline_ULTIMATE.init } true;#NULL.base, #NULL.offset := 0, 0;assume 0 == #valid[0];assume 0 < #StackHeapBarrier;call #Ultimate.allocInit(2, 1);call write~init~int(48, 1, 0, 1);call write~init~int(0, 1, 1, 1);call #Ultimate.allocInit(28, 2);call #Ultimate.allocInit(12, 3);call #Ultimate.allocInit(4, 4);call write~init~int(37, 4, 0, 1);call write~init~int(115, 4, 1, 1);call write~init~int(10, 4, 2, 1);call write~init~int(0, 4, 3, 1);call #Ultimate.allocInit(10, 5);call #Ultimate.allocInit(12, 6);call #Ultimate.allocInit(10, 7);call #Ultimate.allocInit(18, 8);call #Ultimate.allocInit(16, 9);call #Ultimate.allocInit(21, 10);call #Ultimate.allocInit(13, 11);call #Ultimate.allocInit(16, 12);call #Ultimate.allocInit(25, 13);call #Ultimate.allocInit(30, 14);call #Ultimate.allocInit(9, 15);call #Ultimate.allocInit(21, 16);call #Ultimate.allocInit(30, 17);call #Ultimate.allocInit(9, 18);call #Ultimate.allocInit(21, 19);call #Ultimate.allocInit(30, 20);call #Ultimate.allocInit(9, 21);call #Ultimate.allocInit(25, 22);call #Ultimate.allocInit(30, 23);call #Ultimate.allocInit(9, 24);call #Ultimate.allocInit(25, 25);call #Ultimate.allocInit(10, 26);call #Ultimate.allocInit(16, 27);call #Ultimate.allocInit(20, 28);call #Ultimate.allocInit(22, 29);call #Ultimate.allocInit(21, 30);call #Ultimate.allocInit(13, 31);call #Ultimate.allocInit(44, 32);call #Ultimate.allocInit(44, 33);call #Ultimate.allocInit(9, 34);call #Ultimate.allocInit(9, 35);call #Ultimate.allocInit(11, 36);call #Ultimate.allocInit(19, 37);call #Ultimate.allocInit(4, 38);call write~init~int(37, 38, 0, 1);call write~init~int(100, 38, 1, 1);call write~init~int(10, 38, 2, 1);call write~init~int(0, 38, 3, 1);call #Ultimate.allocInit(4, 39);call write~init~int(37, 39, 0, 1);call write~init~int(100, 39, 1, 1);call write~init~int(10, 39, 2, 1);call write~init~int(0, 39, 3, 1);~__SELECTED_FEATURE_Base~0 := 0;~__SELECTED_FEATURE_Keys~0 := 0;~__SELECTED_FEATURE_Encrypt~0 := 0;~__SELECTED_FEATURE_AutoResponder~0 := 0;~__SELECTED_FEATURE_AddressBook~0 := 0;~__SELECTED_FEATURE_Sign~0 := 0;~__SELECTED_FEATURE_Forward~0 := 0;~__SELECTED_FEATURE_Verify~0 := 0;~__SELECTED_FEATURE_Decrypt~0 := 0;~__GUIDSL_ROOT_PRODUCTION~0 := 0;~__GUIDSL_NON_TERMINAL_main~0 := 0;~head~0.base, ~head~0.offset := 0, 0;~queue_empty~0 := 1;~queued_message~0 := 0;~queued_client~0 := 0;~mail_is_sensitive~0 := -1;~__ste_Client_counter~0 := 0;~__ste_client_name0~0.base, ~__ste_client_name0~0.offset := 0, 0;~__ste_client_name1~0.base, ~__ste_client_name1~0.offset := 0, 0;~__ste_client_name2~0.base, ~__ste_client_name2~0.offset := 0, 0;~__ste_client_outbuffer0~0 := 0;~__ste_client_outbuffer1~0 := 0;~__ste_client_outbuffer2~0 := 0;~__ste_client_outbuffer3~0 := 0;~__ste_ClientAddressBook_size0~0 := 0;~__ste_ClientAddressBook_size1~0 := 0;~__ste_ClientAddressBook_size2~0 := 0;~__ste_Client_AddressBook0_Alias0~0 := 0;~__ste_Client_AddressBook0_Alias1~0 := 0;~__ste_Client_AddressBook0_Alias2~0 := 0;~__ste_Client_AddressBook1_Alias0~0 := 0;~__ste_Client_AddressBook1_Alias1~0 := 0;~__ste_Client_AddressBook1_Alias2~0 := 0;~__ste_Client_AddressBook2_Alias0~0 := 0;~__ste_Client_AddressBook2_Alias1~0 := 0;~__ste_Client_AddressBook2_Alias2~0 := 0;~__ste_Client_AddressBook0_Address0~0 := 0;~__ste_Client_AddressBook0_Address1~0 := 0;~__ste_Client_AddressBook0_Address2~0 := 0;~__ste_Client_AddressBook1_Address0~0 := 0;~__ste_Client_AddressBook1_Address1~0 := 0;~__ste_Client_AddressBook1_Address2~0 := 0;~__ste_Client_AddressBook2_Address0~0 := 0;~__ste_Client_AddressBook2_Address1~0 := 0;~__ste_Client_AddressBook2_Address2~0 := 0;~__ste_client_autoResponse0~0 := 0;~__ste_client_autoResponse1~0 := 0;~__ste_client_autoResponse2~0 := 0;~__ste_client_privateKey0~0 := 0;~__ste_client_privateKey1~0 := 0;~__ste_client_privateKey2~0 := 0;~__ste_ClientKeyring_size0~0 := 0;~__ste_ClientKeyring_size1~0 := 0;~__ste_ClientKeyring_size2~0 := 0;~__ste_Client_Keyring0_User0~0 := 0;~__ste_Client_Keyring0_User1~0 := 0;~__ste_Client_Keyring0_User2~0 := 0;~__ste_Client_Keyring1_User0~0 := 0;~__ste_Client_Keyring1_User1~0 := 0;~__ste_Client_Keyring1_User2~0 := 0;~__ste_Client_Keyring2_User0~0 := 0;~__ste_Client_Keyring2_User1~0 := 0;~__ste_Client_Keyring2_User2~0 := 0;~__ste_Client_Keyring0_PublicKey0~0 := 0;~__ste_Client_Keyring0_PublicKey1~0 := 0;~__ste_Client_Keyring0_PublicKey2~0 := 0;~__ste_Client_Keyring1_PublicKey0~0 := 0;~__ste_Client_Keyring1_PublicKey1~0 := 0;~__ste_Client_Keyring1_PublicKey2~0 := 0;~__ste_Client_Keyring2_PublicKey0~0 := 0;~__ste_Client_Keyring2_PublicKey1~0 := 0;~__ste_Client_Keyring2_PublicKey2~0 := 0;~__ste_client_forwardReceiver0~0 := 0;~__ste_client_forwardReceiver1~0 := 0;~__ste_client_forwardReceiver2~0 := 0;~__ste_client_forwardReceiver3~0 := 0;~__ste_client_idCounter0~0 := 0;~__ste_client_idCounter1~0 := 0;~__ste_client_idCounter2~0 := 0;~bob~0 := 0;~rjh~0 := 0;~chuck~0 := 0;~__ste_Email_counter~0 := 0;~__ste_email_id0~0 := 0;~__ste_email_id1~0 := 0;~__ste_email_from0~0 := 0;~__ste_email_from1~0 := 0;~__ste_email_to0~0 := 0;~__ste_email_to1~0 := 0;~__ste_email_subject0~0.base, ~__ste_email_subject0~0.offset := 0, 0;~__ste_email_subject1~0.base, ~__ste_email_subject1~0.offset := 0, 0;~__ste_email_body0~0.base, ~__ste_email_body0~0.offset := 0, 0;~__ste_email_body1~0.base, ~__ste_email_body1~0.offset := 0, 0;~__ste_email_isEncrypted0~0 := 0;~__ste_email_isEncrypted1~0 := 0;~__ste_email_encryptionKey0~0 := 0;~__ste_email_encryptionKey1~0 := 0;~__ste_email_isSigned0~0 := 0;~__ste_email_isSigned1~0 := 0;~__ste_email_signKey0~0 := 0;~__ste_email_signKey1~0 := 0;~__ste_email_isSignatureVerified0~0 := 0;~__ste_email_isSignatureVerified1~0 := 0; {11604#true} is VALID [2022-02-20 17:56:09,860 INFO L290 TraceCheckUtils]: 1: Hoare triple {11604#true} assume { :end_inline_ULTIMATE.init } true;assume { :begin_inline_main } true;havoc main_#res#1;havoc main_#t~ret98#1, main_~retValue_acc~32#1, main_~tmp~24#1;havoc main_~retValue_acc~32#1;havoc main_~tmp~24#1;assume { :begin_inline_select_helpers } true; {11604#true} is VALID [2022-02-20 17:56:09,860 INFO L290 TraceCheckUtils]: 2: Hoare triple {11604#true} assume { :end_inline_select_helpers } true;assume { :begin_inline_select_features } true; {11604#true} is VALID [2022-02-20 17:56:09,860 INFO L290 TraceCheckUtils]: 3: Hoare triple {11604#true} assume { :end_inline_select_features } true;assume { :begin_inline_valid_product } true;havoc valid_product_#res#1;havoc valid_product_~retValue_acc~9#1;havoc valid_product_~retValue_acc~9#1;valid_product_~retValue_acc~9#1 := 1;valid_product_#res#1 := valid_product_~retValue_acc~9#1; {11604#true} is VALID [2022-02-20 17:56:09,860 INFO L290 TraceCheckUtils]: 4: Hoare triple {11604#true} main_#t~ret98#1 := valid_product_#res#1;assume { :end_inline_valid_product } true;assume -2147483648 <= main_#t~ret98#1 && main_#t~ret98#1 <= 2147483647;main_~tmp~24#1 := main_#t~ret98#1;havoc main_#t~ret98#1; {11604#true} is VALID [2022-02-20 17:56:09,860 INFO L290 TraceCheckUtils]: 5: Hoare triple {11604#true} assume 0 != main_~tmp~24#1;assume { :begin_inline_setup } true;havoc setup_#t~nondet95#1, setup_#t~nondet96#1, setup_#t~nondet97#1, setup_~__cil_tmp1~0#1.base, setup_~__cil_tmp1~0#1.offset, setup_~__cil_tmp2~0#1.base, setup_~__cil_tmp2~0#1.offset, setup_~__cil_tmp3~2#1.base, setup_~__cil_tmp3~2#1.offset;havoc setup_~__cil_tmp1~0#1.base, setup_~__cil_tmp1~0#1.offset;havoc setup_~__cil_tmp2~0#1.base, setup_~__cil_tmp2~0#1.offset;havoc setup_~__cil_tmp3~2#1.base, setup_~__cil_tmp3~2#1.offset;~bob~0 := 1;assume { :begin_inline_setup_bob } true;setup_bob_#in~bob___0#1 := ~bob~0;havoc setup_bob_~bob___0#1;setup_bob_~bob___0#1 := setup_bob_#in~bob___0#1;assume { :begin_inline_setup_bob__wrappee__Base } true;setup_bob__wrappee__Base_#in~bob___0#1 := setup_bob_~bob___0#1;havoc setup_bob__wrappee__Base_~bob___0#1;setup_bob__wrappee__Base_~bob___0#1 := setup_bob__wrappee__Base_#in~bob___0#1; {11604#true} is VALID [2022-02-20 17:56:09,860 INFO L272 TraceCheckUtils]: 6: Hoare triple {11604#true} call setClientId(setup_bob__wrappee__Base_~bob___0#1, setup_bob__wrappee__Base_~bob___0#1); {11604#true} is VALID [2022-02-20 17:56:09,860 INFO L290 TraceCheckUtils]: 7: Hoare triple {11604#true} ~handle := #in~handle;~value := #in~value; {11604#true} is VALID [2022-02-20 17:56:09,860 INFO L290 TraceCheckUtils]: 8: Hoare triple {11604#true} assume 1 == ~handle;~__ste_client_idCounter0~0 := ~value; {11604#true} is VALID [2022-02-20 17:56:09,860 INFO L290 TraceCheckUtils]: 9: Hoare triple {11604#true} assume true; {11604#true} is VALID [2022-02-20 17:56:09,861 INFO L284 TraceCheckUtils]: 10: Hoare quadruple {11604#true} {11604#true} #1133#return; {11604#true} is VALID [2022-02-20 17:56:09,861 INFO L290 TraceCheckUtils]: 11: Hoare triple {11604#true} assume { :end_inline_setup_bob__wrappee__Base } true; {11604#true} is VALID [2022-02-20 17:56:09,861 INFO L272 TraceCheckUtils]: 12: Hoare triple {11604#true} call setClientPrivateKey(setup_bob_~bob___0#1, 123); {11604#true} is VALID [2022-02-20 17:56:09,861 INFO L290 TraceCheckUtils]: 13: Hoare triple {11604#true} ~handle := #in~handle;~value := #in~value; {11604#true} is VALID [2022-02-20 17:56:09,861 INFO L290 TraceCheckUtils]: 14: Hoare triple {11604#true} assume 1 == ~handle;~__ste_client_privateKey0~0 := ~value; {11604#true} is VALID [2022-02-20 17:56:09,861 INFO L290 TraceCheckUtils]: 15: Hoare triple {11604#true} assume true; {11604#true} is VALID [2022-02-20 17:56:09,861 INFO L284 TraceCheckUtils]: 16: Hoare quadruple {11604#true} {11604#true} #1135#return; {11604#true} is VALID [2022-02-20 17:56:09,861 INFO L290 TraceCheckUtils]: 17: Hoare triple {11604#true} assume { :end_inline_setup_bob } true;setup_~__cil_tmp1~0#1.base, setup_~__cil_tmp1~0#1.offset := 34, 0;havoc setup_#t~nondet95#1;~rjh~0 := 2;assume { :begin_inline_setup_rjh } true;setup_rjh_#in~rjh___0#1 := ~rjh~0;havoc setup_rjh_~rjh___0#1;setup_rjh_~rjh___0#1 := setup_rjh_#in~rjh___0#1;assume { :begin_inline_setup_rjh__wrappee__Base } true;setup_rjh__wrappee__Base_#in~rjh___0#1 := setup_rjh_~rjh___0#1;havoc setup_rjh__wrappee__Base_~rjh___0#1;setup_rjh__wrappee__Base_~rjh___0#1 := setup_rjh__wrappee__Base_#in~rjh___0#1; {11724#(<= 2 |ULTIMATE.start_setup_rjh_~rjh___0#1|)} is VALID [2022-02-20 17:56:09,861 INFO L272 TraceCheckUtils]: 18: Hoare triple {11724#(<= 2 |ULTIMATE.start_setup_rjh_~rjh___0#1|)} call setClientId(setup_rjh__wrappee__Base_~rjh___0#1, setup_rjh__wrappee__Base_~rjh___0#1); {11604#true} is VALID [2022-02-20 17:56:09,861 INFO L290 TraceCheckUtils]: 19: Hoare triple {11604#true} ~handle := #in~handle;~value := #in~value; {11604#true} is VALID [2022-02-20 17:56:09,861 INFO L290 TraceCheckUtils]: 20: Hoare triple {11604#true} assume !(1 == ~handle); {11604#true} is VALID [2022-02-20 17:56:09,861 INFO L290 TraceCheckUtils]: 21: Hoare triple {11604#true} assume 2 == ~handle;~__ste_client_idCounter1~0 := ~value; {11604#true} is VALID [2022-02-20 17:56:09,861 INFO L290 TraceCheckUtils]: 22: Hoare triple {11604#true} assume true; {11604#true} is VALID [2022-02-20 17:56:09,862 INFO L284 TraceCheckUtils]: 23: Hoare quadruple {11604#true} {11724#(<= 2 |ULTIMATE.start_setup_rjh_~rjh___0#1|)} #1137#return; {11724#(<= 2 |ULTIMATE.start_setup_rjh_~rjh___0#1|)} is VALID [2022-02-20 17:56:09,862 INFO L290 TraceCheckUtils]: 24: Hoare triple {11724#(<= 2 |ULTIMATE.start_setup_rjh_~rjh___0#1|)} assume { :end_inline_setup_rjh__wrappee__Base } true; {11724#(<= 2 |ULTIMATE.start_setup_rjh_~rjh___0#1|)} is VALID [2022-02-20 17:56:09,862 INFO L272 TraceCheckUtils]: 25: Hoare triple {11724#(<= 2 |ULTIMATE.start_setup_rjh_~rjh___0#1|)} call setClientPrivateKey(setup_rjh_~rjh___0#1, 456); {11604#true} is VALID [2022-02-20 17:56:09,863 INFO L290 TraceCheckUtils]: 26: Hoare triple {11604#true} ~handle := #in~handle;~value := #in~value; {11752#(<= |setClientPrivateKey_#in~handle| setClientPrivateKey_~handle)} is VALID [2022-02-20 17:56:09,863 INFO L290 TraceCheckUtils]: 27: Hoare triple {11752#(<= |setClientPrivateKey_#in~handle| setClientPrivateKey_~handle)} assume 1 == ~handle;~__ste_client_privateKey0~0 := ~value; {11756#(<= |setClientPrivateKey_#in~handle| 1)} is VALID [2022-02-20 17:56:09,864 INFO L290 TraceCheckUtils]: 28: Hoare triple {11756#(<= |setClientPrivateKey_#in~handle| 1)} assume true; {11756#(<= |setClientPrivateKey_#in~handle| 1)} is VALID [2022-02-20 17:56:09,864 INFO L284 TraceCheckUtils]: 29: Hoare quadruple {11756#(<= |setClientPrivateKey_#in~handle| 1)} {11724#(<= 2 |ULTIMATE.start_setup_rjh_~rjh___0#1|)} #1139#return; {11605#false} is VALID [2022-02-20 17:56:09,864 INFO L290 TraceCheckUtils]: 30: Hoare triple {11605#false} assume { :end_inline_setup_rjh } true;setup_~__cil_tmp2~0#1.base, setup_~__cil_tmp2~0#1.offset := 35, 0;havoc setup_#t~nondet96#1;~chuck~0 := 3;assume { :begin_inline_setup_chuck } true;setup_chuck_#in~chuck___0#1 := ~chuck~0;havoc setup_chuck_~chuck___0#1;setup_chuck_~chuck___0#1 := setup_chuck_#in~chuck___0#1;assume { :begin_inline_setup_chuck__wrappee__Base } true;setup_chuck__wrappee__Base_#in~chuck___0#1 := setup_chuck_~chuck___0#1;havoc setup_chuck__wrappee__Base_~chuck___0#1;setup_chuck__wrappee__Base_~chuck___0#1 := setup_chuck__wrappee__Base_#in~chuck___0#1; {11605#false} is VALID [2022-02-20 17:56:09,864 INFO L272 TraceCheckUtils]: 31: Hoare triple {11605#false} call setClientId(setup_chuck__wrappee__Base_~chuck___0#1, setup_chuck__wrappee__Base_~chuck___0#1); {11605#false} is VALID [2022-02-20 17:56:09,864 INFO L290 TraceCheckUtils]: 32: Hoare triple {11605#false} ~handle := #in~handle;~value := #in~value; {11605#false} is VALID [2022-02-20 17:56:09,864 INFO L290 TraceCheckUtils]: 33: Hoare triple {11605#false} assume 1 == ~handle;~__ste_client_idCounter0~0 := ~value; {11605#false} is VALID [2022-02-20 17:56:09,864 INFO L290 TraceCheckUtils]: 34: Hoare triple {11605#false} assume true; {11605#false} is VALID [2022-02-20 17:56:09,864 INFO L284 TraceCheckUtils]: 35: Hoare quadruple {11605#false} {11605#false} #1141#return; {11605#false} is VALID [2022-02-20 17:56:09,864 INFO L290 TraceCheckUtils]: 36: Hoare triple {11605#false} assume { :end_inline_setup_chuck__wrappee__Base } true; {11605#false} is VALID [2022-02-20 17:56:09,864 INFO L272 TraceCheckUtils]: 37: Hoare triple {11605#false} call setClientPrivateKey(setup_chuck_~chuck___0#1, 789); {11605#false} is VALID [2022-02-20 17:56:09,864 INFO L290 TraceCheckUtils]: 38: Hoare triple {11605#false} ~handle := #in~handle;~value := #in~value; {11605#false} is VALID [2022-02-20 17:56:09,865 INFO L290 TraceCheckUtils]: 39: Hoare triple {11605#false} assume 1 == ~handle;~__ste_client_privateKey0~0 := ~value; {11605#false} is VALID [2022-02-20 17:56:09,865 INFO L290 TraceCheckUtils]: 40: Hoare triple {11605#false} assume true; {11605#false} is VALID [2022-02-20 17:56:09,865 INFO L284 TraceCheckUtils]: 41: Hoare quadruple {11605#false} {11605#false} #1143#return; {11605#false} is VALID [2022-02-20 17:56:09,865 INFO L290 TraceCheckUtils]: 42: Hoare triple {11605#false} assume { :end_inline_setup_chuck } true;setup_~__cil_tmp3~2#1.base, setup_~__cil_tmp3~2#1.offset := 36, 0;havoc setup_#t~nondet97#1; {11605#false} is VALID [2022-02-20 17:56:09,865 INFO L290 TraceCheckUtils]: 43: Hoare triple {11605#false} assume { :end_inline_setup } true;assume { :begin_inline_test } true;havoc test_#t~nondet48#1, test_#t~nondet49#1, test_#t~nondet50#1, test_#t~nondet51#1, test_#t~nondet52#1, test_#t~nondet53#1, test_#t~nondet54#1, test_#t~nondet55#1, test_#t~nondet56#1, test_#t~nondet57#1, test_#t~nondet58#1, test_~op1~0#1, test_~op2~0#1, test_~op3~0#1, test_~op4~0#1, test_~op5~0#1, test_~op6~0#1, test_~op7~0#1, test_~op8~0#1, test_~op9~0#1, test_~op10~0#1, test_~op11~0#1, test_~splverifierCounter~0#1, test_~tmp~8#1, test_~tmp___0~3#1, test_~tmp___1~1#1, test_~tmp___2~1#1, test_~tmp___3~0#1, test_~tmp___4~0#1, test_~tmp___5~0#1, test_~tmp___6~0#1, test_~tmp___7~0#1, test_~tmp___8~0#1, test_~tmp___9~0#1;havoc test_~op1~0#1;havoc test_~op2~0#1;havoc test_~op3~0#1;havoc test_~op4~0#1;havoc test_~op5~0#1;havoc test_~op6~0#1;havoc test_~op7~0#1;havoc test_~op8~0#1;havoc test_~op9~0#1;havoc test_~op10~0#1;havoc test_~op11~0#1;havoc test_~splverifierCounter~0#1;havoc test_~tmp~8#1;havoc test_~tmp___0~3#1;havoc test_~tmp___1~1#1;havoc test_~tmp___2~1#1;havoc test_~tmp___3~0#1;havoc test_~tmp___4~0#1;havoc test_~tmp___5~0#1;havoc test_~tmp___6~0#1;havoc test_~tmp___7~0#1;havoc test_~tmp___8~0#1;havoc test_~tmp___9~0#1;test_~op1~0#1 := 0;test_~op2~0#1 := 0;test_~op3~0#1 := 0;test_~op4~0#1 := 0;test_~op5~0#1 := 0;test_~op6~0#1 := 0;test_~op7~0#1 := 0;test_~op8~0#1 := 0;test_~op9~0#1 := 0;test_~op10~0#1 := 0;test_~op11~0#1 := 0;test_~splverifierCounter~0#1 := 0; {11605#false} is VALID [2022-02-20 17:56:09,865 INFO L290 TraceCheckUtils]: 44: Hoare triple {11605#false} assume !false; {11605#false} is VALID [2022-02-20 17:56:09,865 INFO L290 TraceCheckUtils]: 45: Hoare triple {11605#false} assume test_~splverifierCounter~0#1 < 4; {11605#false} is VALID [2022-02-20 17:56:09,865 INFO L290 TraceCheckUtils]: 46: Hoare triple {11605#false} test_~splverifierCounter~0#1 := 1 + test_~splverifierCounter~0#1; {11605#false} is VALID [2022-02-20 17:56:09,865 INFO L290 TraceCheckUtils]: 47: Hoare triple {11605#false} assume 0 == test_~op1~0#1;assume -2147483648 <= test_#t~nondet48#1 && test_#t~nondet48#1 <= 2147483647;test_~tmp___9~0#1 := test_#t~nondet48#1;havoc test_#t~nondet48#1; {11605#false} is VALID [2022-02-20 17:56:09,865 INFO L290 TraceCheckUtils]: 48: Hoare triple {11605#false} assume !(0 != test_~tmp___9~0#1); {11605#false} is VALID [2022-02-20 17:56:09,865 INFO L290 TraceCheckUtils]: 49: Hoare triple {11605#false} assume 0 == test_~op2~0#1;assume -2147483648 <= test_#t~nondet49#1 && test_#t~nondet49#1 <= 2147483647;test_~tmp___8~0#1 := test_#t~nondet49#1;havoc test_#t~nondet49#1; {11605#false} is VALID [2022-02-20 17:56:09,865 INFO L290 TraceCheckUtils]: 50: Hoare triple {11605#false} assume 0 != test_~tmp___8~0#1;assume { :begin_inline_rjhSetAutoRespond } true;assume { :begin_inline_setClientAutoResponse } true;setClientAutoResponse_#in~handle#1, setClientAutoResponse_#in~value#1 := ~rjh~0, 1;havoc setClientAutoResponse_~handle#1, setClientAutoResponse_~value#1;setClientAutoResponse_~handle#1 := setClientAutoResponse_#in~handle#1;setClientAutoResponse_~value#1 := setClientAutoResponse_#in~value#1; {11605#false} is VALID [2022-02-20 17:56:09,865 INFO L290 TraceCheckUtils]: 51: Hoare triple {11605#false} assume 1 == setClientAutoResponse_~handle#1;~__ste_client_autoResponse0~0 := setClientAutoResponse_~value#1; {11605#false} is VALID [2022-02-20 17:56:09,866 INFO L290 TraceCheckUtils]: 52: Hoare triple {11605#false} assume { :end_inline_setClientAutoResponse } true; {11605#false} is VALID [2022-02-20 17:56:09,866 INFO L290 TraceCheckUtils]: 53: Hoare triple {11605#false} assume { :end_inline_rjhSetAutoRespond } true;test_~op2~0#1 := 1; {11605#false} is VALID [2022-02-20 17:56:09,866 INFO L290 TraceCheckUtils]: 54: Hoare triple {11605#false} assume !false; {11605#false} is VALID [2022-02-20 17:56:09,866 INFO L290 TraceCheckUtils]: 55: Hoare triple {11605#false} assume !(test_~splverifierCounter~0#1 < 4); {11605#false} is VALID [2022-02-20 17:56:09,866 INFO L290 TraceCheckUtils]: 56: Hoare triple {11605#false} assume { :begin_inline_bobToRjh } true;havoc bobToRjh_#t~ret90#1, bobToRjh_#t~ret91#1, bobToRjh_#t~ret92#1, bobToRjh_#t~ret93#1, bobToRjh_~tmp~23#1, bobToRjh_~tmp___0~7#1, bobToRjh_~tmp___1~4#1;havoc bobToRjh_~tmp~23#1;havoc bobToRjh_~tmp___0~7#1;havoc bobToRjh_~tmp___1~4#1;call bobToRjh_#t~ret90#1 := puts(32, 0);assume -2147483648 <= bobToRjh_#t~ret90#1 && bobToRjh_#t~ret90#1 <= 2147483647;havoc bobToRjh_#t~ret90#1; {11605#false} is VALID [2022-02-20 17:56:09,866 INFO L272 TraceCheckUtils]: 57: Hoare triple {11605#false} call sendEmail(~bob~0, ~rjh~0); {11605#false} is VALID [2022-02-20 17:56:09,866 INFO L290 TraceCheckUtils]: 58: Hoare triple {11605#false} ~sender#1 := #in~sender#1;~receiver#1 := #in~receiver#1;havoc ~email~0#1;havoc ~tmp~16#1;assume { :begin_inline_createEmail } true;createEmail_#in~from#1, createEmail_#in~to#1 := 0, ~receiver#1;havoc createEmail_#res#1;havoc createEmail_~from#1, createEmail_~to#1, createEmail_~retValue_acc~4#1, createEmail_~msg~0#1;createEmail_~from#1 := createEmail_#in~from#1;createEmail_~to#1 := createEmail_#in~to#1;havoc createEmail_~retValue_acc~4#1;havoc createEmail_~msg~0#1;createEmail_~msg~0#1 := 1; {11605#false} is VALID [2022-02-20 17:56:09,866 INFO L272 TraceCheckUtils]: 59: Hoare triple {11605#false} call setEmailFrom(createEmail_~msg~0#1, createEmail_~from#1); {11605#false} is VALID [2022-02-20 17:56:09,866 INFO L290 TraceCheckUtils]: 60: Hoare triple {11605#false} ~handle := #in~handle;~value := #in~value; {11605#false} is VALID [2022-02-20 17:56:09,866 INFO L290 TraceCheckUtils]: 61: Hoare triple {11605#false} assume 1 == ~handle;~__ste_email_from0~0 := ~value; {11605#false} is VALID [2022-02-20 17:56:09,867 INFO L290 TraceCheckUtils]: 62: Hoare triple {11605#false} assume true; {11605#false} is VALID [2022-02-20 17:56:09,867 INFO L284 TraceCheckUtils]: 63: Hoare quadruple {11605#false} {11605#false} #1119#return; {11605#false} is VALID [2022-02-20 17:56:09,867 INFO L272 TraceCheckUtils]: 64: Hoare triple {11605#false} call setEmailTo(createEmail_~msg~0#1, createEmail_~to#1); {11605#false} is VALID [2022-02-20 17:56:09,867 INFO L290 TraceCheckUtils]: 65: Hoare triple {11605#false} ~handle := #in~handle;~value := #in~value; {11605#false} is VALID [2022-02-20 17:56:09,867 INFO L290 TraceCheckUtils]: 66: Hoare triple {11605#false} assume 1 == ~handle;~__ste_email_to0~0 := ~value; {11605#false} is VALID [2022-02-20 17:56:09,867 INFO L290 TraceCheckUtils]: 67: Hoare triple {11605#false} assume true; {11605#false} is VALID [2022-02-20 17:56:09,867 INFO L284 TraceCheckUtils]: 68: Hoare quadruple {11605#false} {11605#false} #1121#return; {11605#false} is VALID [2022-02-20 17:56:09,867 INFO L290 TraceCheckUtils]: 69: Hoare triple {11605#false} createEmail_~retValue_acc~4#1 := createEmail_~msg~0#1;createEmail_#res#1 := createEmail_~retValue_acc~4#1; {11605#false} is VALID [2022-02-20 17:56:09,867 INFO L290 TraceCheckUtils]: 70: Hoare triple {11605#false} #t~ret73#1 := createEmail_#res#1;assume { :end_inline_createEmail } true;assume -2147483648 <= #t~ret73#1 && #t~ret73#1 <= 2147483647;~tmp~16#1 := #t~ret73#1;havoc #t~ret73#1;~email~0#1 := ~tmp~16#1; {11605#false} is VALID [2022-02-20 17:56:09,868 INFO L272 TraceCheckUtils]: 71: Hoare triple {11605#false} call outgoing(~sender#1, ~email~0#1); {11605#false} is VALID [2022-02-20 17:56:09,868 INFO L290 TraceCheckUtils]: 72: Hoare triple {11605#false} ~client#1 := #in~client#1;~msg#1 := #in~msg#1;assume { :begin_inline_sign } true;sign_#in~client#1, sign_#in~msg#1 := ~client#1, ~msg#1;havoc sign_#t~ret77#1, sign_~client#1, sign_~msg#1, sign_~privkey~1#1, sign_~tmp~18#1;sign_~client#1 := sign_#in~client#1;sign_~msg#1 := sign_#in~msg#1;havoc sign_~privkey~1#1;havoc sign_~tmp~18#1; {11605#false} is VALID [2022-02-20 17:56:09,868 INFO L272 TraceCheckUtils]: 73: Hoare triple {11605#false} call sign_#t~ret77#1 := getClientPrivateKey(sign_~client#1); {11605#false} is VALID [2022-02-20 17:56:09,868 INFO L290 TraceCheckUtils]: 74: Hoare triple {11605#false} ~handle := #in~handle;havoc ~retValue_acc~24; {11605#false} is VALID [2022-02-20 17:56:09,868 INFO L290 TraceCheckUtils]: 75: Hoare triple {11605#false} assume 1 == ~handle;~retValue_acc~24 := ~__ste_client_privateKey0~0;#res := ~retValue_acc~24; {11605#false} is VALID [2022-02-20 17:56:09,868 INFO L290 TraceCheckUtils]: 76: Hoare triple {11605#false} assume true; {11605#false} is VALID [2022-02-20 17:56:09,868 INFO L284 TraceCheckUtils]: 77: Hoare quadruple {11605#false} {11605#false} #1053#return; {11605#false} is VALID [2022-02-20 17:56:09,868 INFO L290 TraceCheckUtils]: 78: Hoare triple {11605#false} assume -2147483648 <= sign_#t~ret77#1 && sign_#t~ret77#1 <= 2147483647;sign_~tmp~18#1 := sign_#t~ret77#1;havoc sign_#t~ret77#1;sign_~privkey~1#1 := sign_~tmp~18#1; {11605#false} is VALID [2022-02-20 17:56:09,868 INFO L290 TraceCheckUtils]: 79: Hoare triple {11605#false} assume 0 == sign_~privkey~1#1; {11605#false} is VALID [2022-02-20 17:56:09,868 INFO L290 TraceCheckUtils]: 80: Hoare triple {11605#false} assume { :end_inline_sign } true;assume { :begin_inline_outgoing__wrappee__AutoResponder } true;outgoing__wrappee__AutoResponder_#in~client#1, outgoing__wrappee__AutoResponder_#in~msg#1 := ~client#1, ~msg#1;havoc outgoing__wrappee__AutoResponder_#t~ret63#1, outgoing__wrappee__AutoResponder_#t~ret64#1, outgoing__wrappee__AutoResponder_~client#1, outgoing__wrappee__AutoResponder_~msg#1, outgoing__wrappee__AutoResponder_~receiver~0#1, outgoing__wrappee__AutoResponder_~tmp~11#1, outgoing__wrappee__AutoResponder_~pubkey~0#1, outgoing__wrappee__AutoResponder_~tmp___0~4#1;outgoing__wrappee__AutoResponder_~client#1 := outgoing__wrappee__AutoResponder_#in~client#1;outgoing__wrappee__AutoResponder_~msg#1 := outgoing__wrappee__AutoResponder_#in~msg#1;havoc outgoing__wrappee__AutoResponder_~receiver~0#1;havoc outgoing__wrappee__AutoResponder_~tmp~11#1;havoc outgoing__wrappee__AutoResponder_~pubkey~0#1;havoc outgoing__wrappee__AutoResponder_~tmp___0~4#1; {11605#false} is VALID [2022-02-20 17:56:09,869 INFO L272 TraceCheckUtils]: 81: Hoare triple {11605#false} call outgoing__wrappee__AutoResponder_#t~ret63#1 := getEmailTo(outgoing__wrappee__AutoResponder_~msg#1); {11605#false} is VALID [2022-02-20 17:56:09,869 INFO L290 TraceCheckUtils]: 82: Hoare triple {11605#false} ~handle := #in~handle;havoc ~retValue_acc~36; {11605#false} is VALID [2022-02-20 17:56:09,869 INFO L290 TraceCheckUtils]: 83: Hoare triple {11605#false} assume 1 == ~handle;~retValue_acc~36 := ~__ste_email_to0~0;#res := ~retValue_acc~36; {11605#false} is VALID [2022-02-20 17:56:09,869 INFO L290 TraceCheckUtils]: 84: Hoare triple {11605#false} assume true; {11605#false} is VALID [2022-02-20 17:56:09,869 INFO L284 TraceCheckUtils]: 85: Hoare quadruple {11605#false} {11605#false} #1055#return; {11605#false} is VALID [2022-02-20 17:56:09,869 INFO L290 TraceCheckUtils]: 86: Hoare triple {11605#false} assume -2147483648 <= outgoing__wrappee__AutoResponder_#t~ret63#1 && outgoing__wrappee__AutoResponder_#t~ret63#1 <= 2147483647;outgoing__wrappee__AutoResponder_~tmp~11#1 := outgoing__wrappee__AutoResponder_#t~ret63#1;havoc outgoing__wrappee__AutoResponder_#t~ret63#1;outgoing__wrappee__AutoResponder_~receiver~0#1 := outgoing__wrappee__AutoResponder_~tmp~11#1; {11605#false} is VALID [2022-02-20 17:56:09,869 INFO L272 TraceCheckUtils]: 87: Hoare triple {11605#false} call outgoing__wrappee__AutoResponder_#t~ret64#1 := findPublicKey(outgoing__wrappee__AutoResponder_~client#1, outgoing__wrappee__AutoResponder_~receiver~0#1); {11605#false} is VALID [2022-02-20 17:56:09,869 INFO L290 TraceCheckUtils]: 88: Hoare triple {11605#false} ~handle := #in~handle;~userid := #in~userid;havoc ~retValue_acc~29; {11605#false} is VALID [2022-02-20 17:56:09,869 INFO L290 TraceCheckUtils]: 89: Hoare triple {11605#false} assume 1 == ~handle; {11605#false} is VALID [2022-02-20 17:56:09,870 INFO L290 TraceCheckUtils]: 90: Hoare triple {11605#false} assume ~userid == ~__ste_Client_Keyring0_User0~0;~retValue_acc~29 := ~__ste_Client_Keyring0_PublicKey0~0;#res := ~retValue_acc~29; {11605#false} is VALID [2022-02-20 17:56:09,870 INFO L290 TraceCheckUtils]: 91: Hoare triple {11605#false} assume true; {11605#false} is VALID [2022-02-20 17:56:09,870 INFO L284 TraceCheckUtils]: 92: Hoare quadruple {11605#false} {11605#false} #1057#return; {11605#false} is VALID [2022-02-20 17:56:09,870 INFO L290 TraceCheckUtils]: 93: Hoare triple {11605#false} assume -2147483648 <= outgoing__wrappee__AutoResponder_#t~ret64#1 && outgoing__wrappee__AutoResponder_#t~ret64#1 <= 2147483647;outgoing__wrappee__AutoResponder_~tmp___0~4#1 := outgoing__wrappee__AutoResponder_#t~ret64#1;havoc outgoing__wrappee__AutoResponder_#t~ret64#1;outgoing__wrappee__AutoResponder_~pubkey~0#1 := outgoing__wrappee__AutoResponder_~tmp___0~4#1; {11605#false} is VALID [2022-02-20 17:56:09,870 INFO L290 TraceCheckUtils]: 94: Hoare triple {11605#false} assume !(0 != outgoing__wrappee__AutoResponder_~pubkey~0#1); {11605#false} is VALID [2022-02-20 17:56:09,870 INFO L290 TraceCheckUtils]: 95: Hoare triple {11605#false} assume { :begin_inline_outgoing__wrappee__Keys } true;outgoing__wrappee__Keys_#in~client#1, outgoing__wrappee__Keys_#in~msg#1 := outgoing__wrappee__AutoResponder_~client#1, outgoing__wrappee__AutoResponder_~msg#1;havoc outgoing__wrappee__Keys_#t~ret62#1, outgoing__wrappee__Keys_~client#1, outgoing__wrappee__Keys_~msg#1, outgoing__wrappee__Keys_~tmp~10#1;outgoing__wrappee__Keys_~client#1 := outgoing__wrappee__Keys_#in~client#1;outgoing__wrappee__Keys_~msg#1 := outgoing__wrappee__Keys_#in~msg#1;havoc outgoing__wrappee__Keys_~tmp~10#1;assume { :begin_inline_getClientId } true;getClientId_#in~handle#1 := outgoing__wrappee__Keys_~client#1;havoc getClientId_#res#1;havoc getClientId_~handle#1, getClientId_~retValue_acc~31#1;getClientId_~handle#1 := getClientId_#in~handle#1;havoc getClientId_~retValue_acc~31#1; {11605#false} is VALID [2022-02-20 17:56:09,870 INFO L290 TraceCheckUtils]: 96: Hoare triple {11605#false} assume 1 == getClientId_~handle#1;getClientId_~retValue_acc~31#1 := ~__ste_client_idCounter0~0;getClientId_#res#1 := getClientId_~retValue_acc~31#1; {11605#false} is VALID [2022-02-20 17:56:09,870 INFO L290 TraceCheckUtils]: 97: Hoare triple {11605#false} outgoing__wrappee__Keys_#t~ret62#1 := getClientId_#res#1;assume { :end_inline_getClientId } true;assume -2147483648 <= outgoing__wrappee__Keys_#t~ret62#1 && outgoing__wrappee__Keys_#t~ret62#1 <= 2147483647;outgoing__wrappee__Keys_~tmp~10#1 := outgoing__wrappee__Keys_#t~ret62#1;havoc outgoing__wrappee__Keys_#t~ret62#1; {11605#false} is VALID [2022-02-20 17:56:09,870 INFO L272 TraceCheckUtils]: 98: Hoare triple {11605#false} call setEmailFrom(outgoing__wrappee__Keys_~msg#1, outgoing__wrappee__Keys_~tmp~10#1); {11605#false} is VALID [2022-02-20 17:56:09,870 INFO L290 TraceCheckUtils]: 99: Hoare triple {11605#false} ~handle := #in~handle;~value := #in~value; {11605#false} is VALID [2022-02-20 17:56:09,871 INFO L290 TraceCheckUtils]: 100: Hoare triple {11605#false} assume 1 == ~handle;~__ste_email_from0~0 := ~value; {11605#false} is VALID [2022-02-20 17:56:09,871 INFO L290 TraceCheckUtils]: 101: Hoare triple {11605#false} assume true; {11605#false} is VALID [2022-02-20 17:56:09,871 INFO L284 TraceCheckUtils]: 102: Hoare quadruple {11605#false} {11605#false} #1063#return; {11605#false} is VALID [2022-02-20 17:56:09,871 INFO L290 TraceCheckUtils]: 103: Hoare triple {11605#false} assume { :begin_inline_mail } true;mail_#in~client#1, mail_#in~msg#1 := outgoing__wrappee__Keys_~client#1, outgoing__wrappee__Keys_~msg#1;havoc mail_#t~ret60#1, mail_#t~ret61#1, mail_~client#1, mail_~msg#1, mail_~__utac__ad__arg1~0#1, mail_~__utac__ad__arg2~0#1, mail_~tmp~9#1;mail_~client#1 := mail_#in~client#1;mail_~msg#1 := mail_#in~msg#1;havoc mail_~__utac__ad__arg1~0#1;havoc mail_~__utac__ad__arg2~0#1;havoc mail_~tmp~9#1;mail_~__utac__ad__arg1~0#1 := mail_~client#1;mail_~__utac__ad__arg2~0#1 := mail_~msg#1;assume { :begin_inline___utac_acc__AddressBookEncrypt_spec__1 } true;__utac_acc__AddressBookEncrypt_spec__1_#in~client#1, __utac_acc__AddressBookEncrypt_spec__1_#in~msg#1 := mail_~__utac__ad__arg1~0#1, mail_~__utac__ad__arg2~0#1;havoc __utac_acc__AddressBookEncrypt_spec__1_#t~ret85#1, __utac_acc__AddressBookEncrypt_spec__1_#t~ret86#1, __utac_acc__AddressBookEncrypt_spec__1_#t~ret87#1, __utac_acc__AddressBookEncrypt_spec__1_~client#1, __utac_acc__AddressBookEncrypt_spec__1_~msg#1, __utac_acc__AddressBookEncrypt_spec__1_~tmp~20#1;__utac_acc__AddressBookEncrypt_spec__1_~client#1 := __utac_acc__AddressBookEncrypt_spec__1_#in~client#1;__utac_acc__AddressBookEncrypt_spec__1_~msg#1 := __utac_acc__AddressBookEncrypt_spec__1_#in~msg#1;havoc __utac_acc__AddressBookEncrypt_spec__1_~tmp~20#1;call __utac_acc__AddressBookEncrypt_spec__1_#t~ret85#1 := puts(31, 0);assume -2147483648 <= __utac_acc__AddressBookEncrypt_spec__1_#t~ret85#1 && __utac_acc__AddressBookEncrypt_spec__1_#t~ret85#1 <= 2147483647;havoc __utac_acc__AddressBookEncrypt_spec__1_#t~ret85#1; {11605#false} is VALID [2022-02-20 17:56:09,871 INFO L290 TraceCheckUtils]: 104: Hoare triple {11605#false} assume !(-1 == ~mail_is_sensitive~0); {11605#false} is VALID [2022-02-20 17:56:09,871 INFO L272 TraceCheckUtils]: 105: Hoare triple {11605#false} call __utac_acc__AddressBookEncrypt_spec__1_#t~ret87#1 := isEncrypted(__utac_acc__AddressBookEncrypt_spec__1_~msg#1); {11605#false} is VALID [2022-02-20 17:56:09,871 INFO L290 TraceCheckUtils]: 106: Hoare triple {11605#false} ~handle := #in~handle;havoc ~retValue_acc~39; {11605#false} is VALID [2022-02-20 17:56:09,871 INFO L290 TraceCheckUtils]: 107: Hoare triple {11605#false} assume 1 == ~handle;~retValue_acc~39 := ~__ste_email_isEncrypted0~0;#res := ~retValue_acc~39; {11605#false} is VALID [2022-02-20 17:56:09,872 INFO L290 TraceCheckUtils]: 108: Hoare triple {11605#false} assume true; {11605#false} is VALID [2022-02-20 17:56:09,872 INFO L284 TraceCheckUtils]: 109: Hoare quadruple {11605#false} {11605#false} #1067#return; {11605#false} is VALID [2022-02-20 17:56:09,872 INFO L290 TraceCheckUtils]: 110: Hoare triple {11605#false} assume -2147483648 <= __utac_acc__AddressBookEncrypt_spec__1_#t~ret87#1 && __utac_acc__AddressBookEncrypt_spec__1_#t~ret87#1 <= 2147483647;__utac_acc__AddressBookEncrypt_spec__1_~tmp~20#1 := __utac_acc__AddressBookEncrypt_spec__1_#t~ret87#1;havoc __utac_acc__AddressBookEncrypt_spec__1_#t~ret87#1; {11605#false} is VALID [2022-02-20 17:56:09,872 INFO L290 TraceCheckUtils]: 111: Hoare triple {11605#false} assume ~mail_is_sensitive~0 != __utac_acc__AddressBookEncrypt_spec__1_~tmp~20#1;assume { :begin_inline___automaton_fail } true; {11605#false} is VALID [2022-02-20 17:56:09,872 INFO L290 TraceCheckUtils]: 112: Hoare triple {11605#false} assume !false; {11605#false} is VALID [2022-02-20 17:56:09,872 INFO L134 CoverageAnalysis]: Checked inductivity of 30 backedges. 19 proven. 0 refuted. 0 times theorem prover too weak. 11 trivial. 0 not checked. [2022-02-20 17:56:09,872 INFO L324 TraceCheckSpWp]: Omiting computation of backward sequence because forward sequence was already perfect [2022-02-20 17:56:09,873 INFO L165 FreeRefinementEngine]: IpTcStrategyModuleZ3 [549942372] provided 1 perfect and 0 imperfect interpolant sequences [2022-02-20 17:56:09,873 INFO L191 FreeRefinementEngine]: Found 1 perfect and 1 imperfect interpolant sequences. [2022-02-20 17:56:09,873 INFO L204 FreeRefinementEngine]: Number of different interpolants: perfect sequences [5] imperfect sequences [12] total 15 [2022-02-20 17:56:09,873 INFO L118 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [1290701544] [2022-02-20 17:56:09,873 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2022-02-20 17:56:09,874 INFO L78 Accepts]: Start accepts. Automaton has has 5 states, 5 states have (on average 15.8) internal successors, (79), 5 states have internal predecessors, (79), 3 states have call successors, (15), 2 states have call predecessors, (15), 3 states have return successors, (13), 3 states have call predecessors, (13), 3 states have call successors, (13) Word has length 113 [2022-02-20 17:56:09,874 INFO L84 Accepts]: Finished accepts. word is accepted. [2022-02-20 17:56:09,874 INFO L86 InductivityCheck]: Starting indutivity check of a Floyd-Hoare automaton with has 5 states, 5 states have (on average 15.8) internal successors, (79), 5 states have internal predecessors, (79), 3 states have call successors, (15), 2 states have call predecessors, (15), 3 states have return successors, (13), 3 states have call predecessors, (13), 3 states have call successors, (13) [2022-02-20 17:56:09,964 INFO L122 InductivityCheck]: Floyd-Hoare automaton has 107 edges. 107 inductive. 0 not inductive. 0 times theorem prover too weak to decide inductivity. [2022-02-20 17:56:09,964 INFO L546 AbstractCegarLoop]: INTERPOLANT automaton has 5 states [2022-02-20 17:56:09,964 INFO L108 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2022-02-20 17:56:09,964 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 5 interpolants. [2022-02-20 17:56:09,965 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=30, Invalid=180, Unknown=0, NotChecked=0, Total=210 [2022-02-20 17:56:09,965 INFO L87 Difference]: Start difference. First operand 439 states and 660 transitions. Second operand has 5 states, 5 states have (on average 15.8) internal successors, (79), 5 states have internal predecessors, (79), 3 states have call successors, (15), 2 states have call predecessors, (15), 3 states have return successors, (13), 3 states have call predecessors, (13), 3 states have call successors, (13) [2022-02-20 17:56:10,915 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-02-20 17:56:10,915 INFO L93 Difference]: Finished difference Result 867 states and 1309 transitions. [2022-02-20 17:56:10,915 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 5 states. [2022-02-20 17:56:10,916 INFO L78 Accepts]: Start accepts. Automaton has has 5 states, 5 states have (on average 15.8) internal successors, (79), 5 states have internal predecessors, (79), 3 states have call successors, (15), 2 states have call predecessors, (15), 3 states have return successors, (13), 3 states have call predecessors, (13), 3 states have call successors, (13) Word has length 113 [2022-02-20 17:56:10,916 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2022-02-20 17:56:10,916 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 5 states, 5 states have (on average 15.8) internal successors, (79), 5 states have internal predecessors, (79), 3 states have call successors, (15), 2 states have call predecessors, (15), 3 states have return successors, (13), 3 states have call predecessors, (13), 3 states have call successors, (13) [2022-02-20 17:56:10,923 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 5 states to 5 states and 1115 transitions. [2022-02-20 17:56:10,924 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 5 states, 5 states have (on average 15.8) internal successors, (79), 5 states have internal predecessors, (79), 3 states have call successors, (15), 2 states have call predecessors, (15), 3 states have return successors, (13), 3 states have call predecessors, (13), 3 states have call successors, (13) [2022-02-20 17:56:10,931 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 5 states to 5 states and 1115 transitions. [2022-02-20 17:56:10,931 INFO L86 InductivityCheck]: Starting indutivity check of a Floyd-Hoare automaton with 5 states and 1115 transitions. [2022-02-20 17:56:11,594 INFO L122 InductivityCheck]: Floyd-Hoare automaton has 1115 edges. 1115 inductive. 0 not inductive. 0 times theorem prover too weak to decide inductivity. [2022-02-20 17:56:11,604 INFO L225 Difference]: With dead ends: 867 [2022-02-20 17:56:11,604 INFO L226 Difference]: Without dead ends: 441 [2022-02-20 17:56:11,605 INFO L932 BasicCegarLoop]: 0 DeclaredPredicates, 145 GetRequests, 131 SyntacticMatches, 0 SemanticMatches, 14 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 4 ImplicationChecksByTransitivity, 0.1s TimeCoverageRelationStatistics Valid=34, Invalid=206, Unknown=0, NotChecked=0, Total=240 [2022-02-20 17:56:11,606 INFO L933 BasicCegarLoop]: 552 mSDtfsCounter, 132 mSDsluCounter, 1501 mSDsCounter, 0 mSdLazyCounter, 45 mSolverCounterSat, 0 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.0s Time, 0 mProtectedPredicate, 0 mProtectedAction, 152 SdHoareTripleChecker+Valid, 2053 SdHoareTripleChecker+Invalid, 45 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 0 IncrementalHoareTripleChecker+Valid, 45 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.0s IncrementalHoareTripleChecker+Time [2022-02-20 17:56:11,606 INFO L934 BasicCegarLoop]: SdHoareTripleChecker [152 Valid, 2053 Invalid, 45 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [0 Valid, 45 Invalid, 0 Unknown, 0 Unchecked, 0.0s Time] [2022-02-20 17:56:11,607 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 441 states. [2022-02-20 17:56:11,697 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 441 to 441. [2022-02-20 17:56:11,697 INFO L214 AbstractMinimizeNwa]: Start testing correctness of minimizeSevpa [2022-02-20 17:56:11,698 INFO L82 GeneralOperation]: Start isEquivalent. First operand 441 states. Second operand has 441 states, 340 states have (on average 1.5058823529411764) internal successors, (512), 345 states have internal predecessors, (512), 74 states have call successors, (74), 24 states have call predecessors, (74), 26 states have return successors, (80), 73 states have call predecessors, (80), 73 states have call successors, (80) [2022-02-20 17:56:11,699 INFO L74 IsIncluded]: Start isIncluded. First operand 441 states. Second operand has 441 states, 340 states have (on average 1.5058823529411764) internal successors, (512), 345 states have internal predecessors, (512), 74 states have call successors, (74), 24 states have call predecessors, (74), 26 states have return successors, (80), 73 states have call predecessors, (80), 73 states have call successors, (80) [2022-02-20 17:56:11,699 INFO L87 Difference]: Start difference. First operand 441 states. Second operand has 441 states, 340 states have (on average 1.5058823529411764) internal successors, (512), 345 states have internal predecessors, (512), 74 states have call successors, (74), 24 states have call predecessors, (74), 26 states have return successors, (80), 73 states have call predecessors, (80), 73 states have call successors, (80) [2022-02-20 17:56:11,710 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-02-20 17:56:11,711 INFO L93 Difference]: Finished difference Result 441 states and 666 transitions. [2022-02-20 17:56:11,711 INFO L276 IsEmpty]: Start isEmpty. Operand 441 states and 666 transitions. [2022-02-20 17:56:11,712 INFO L282 IsEmpty]: Finished isEmpty. No accepting run. [2022-02-20 17:56:11,712 INFO L83 IsIncluded]: Finished isIncluded. Language is included [2022-02-20 17:56:11,713 INFO L74 IsIncluded]: Start isIncluded. First operand has 441 states, 340 states have (on average 1.5058823529411764) internal successors, (512), 345 states have internal predecessors, (512), 74 states have call successors, (74), 24 states have call predecessors, (74), 26 states have return successors, (80), 73 states have call predecessors, (80), 73 states have call successors, (80) Second operand 441 states. [2022-02-20 17:56:11,714 INFO L87 Difference]: Start difference. First operand has 441 states, 340 states have (on average 1.5058823529411764) internal successors, (512), 345 states have internal predecessors, (512), 74 states have call successors, (74), 24 states have call predecessors, (74), 26 states have return successors, (80), 73 states have call predecessors, (80), 73 states have call successors, (80) Second operand 441 states. [2022-02-20 17:56:11,723 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-02-20 17:56:11,723 INFO L93 Difference]: Finished difference Result 441 states and 666 transitions. [2022-02-20 17:56:11,723 INFO L276 IsEmpty]: Start isEmpty. Operand 441 states and 666 transitions. [2022-02-20 17:56:11,725 INFO L282 IsEmpty]: Finished isEmpty. No accepting run. [2022-02-20 17:56:11,725 INFO L83 IsIncluded]: Finished isIncluded. Language is included [2022-02-20 17:56:11,725 INFO L88 GeneralOperation]: Finished isEquivalent. [2022-02-20 17:56:11,725 INFO L221 AbstractMinimizeNwa]: Finished testing correctness of minimizeSevpa [2022-02-20 17:56:11,726 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 441 states, 340 states have (on average 1.5058823529411764) internal successors, (512), 345 states have internal predecessors, (512), 74 states have call successors, (74), 24 states have call predecessors, (74), 26 states have return successors, (80), 73 states have call predecessors, (80), 73 states have call successors, (80) [2022-02-20 17:56:11,738 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 441 states to 441 states and 666 transitions. [2022-02-20 17:56:11,739 INFO L78 Accepts]: Start accepts. Automaton has 441 states and 666 transitions. Word has length 113 [2022-02-20 17:56:11,739 INFO L84 Accepts]: Finished accepts. word is rejected. [2022-02-20 17:56:11,739 INFO L470 AbstractCegarLoop]: Abstraction has 441 states and 666 transitions. [2022-02-20 17:56:11,739 INFO L471 AbstractCegarLoop]: INTERPOLANT automaton has has 5 states, 5 states have (on average 15.8) internal successors, (79), 5 states have internal predecessors, (79), 3 states have call successors, (15), 2 states have call predecessors, (15), 3 states have return successors, (13), 3 states have call predecessors, (13), 3 states have call successors, (13) [2022-02-20 17:56:11,739 INFO L276 IsEmpty]: Start isEmpty. Operand 441 states and 666 transitions. [2022-02-20 17:56:11,742 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 115 [2022-02-20 17:56:11,742 INFO L506 BasicCegarLoop]: Found error trace [2022-02-20 17:56:11,743 INFO L514 BasicCegarLoop]: trace histogram [3, 3, 3, 3, 2, 2, 2, 2, 2, 2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-02-20 17:56:11,760 INFO L552 MonitoredProcess]: [MP /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 -smt2 -in SMTLIB2_COMPLIANT=true (6)] Ended with exit code 0 [2022-02-20 17:56:11,960 WARN L452 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable4,6 /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 -smt2 -in SMTLIB2_COMPLIANT=true [2022-02-20 17:56:11,960 INFO L402 AbstractCegarLoop]: === Iteration 6 === Targeting outgoingErr0ASSERT_VIOLATIONERROR_FUNCTION === [outgoingErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2022-02-20 17:56:11,960 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2022-02-20 17:56:11,960 INFO L85 PathProgramCache]: Analyzing trace with hash 1135016271, now seen corresponding path program 1 times [2022-02-20 17:56:11,961 INFO L126 FreeRefinementEngine]: Executing refinement strategy CAMEL [2022-02-20 17:56:11,961 INFO L338 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [997791432] [2022-02-20 17:56:11,961 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-02-20 17:56:11,961 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2022-02-20 17:56:11,983 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-02-20 17:56:12,007 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 6 [2022-02-20 17:56:12,009 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-02-20 17:56:12,010 INFO L290 TraceCheckUtils]: 0: Hoare triple {14806#(and (= |old(~__ste_client_idCounter0~0)| ~__ste_client_idCounter0~0) (= |old(~__ste_client_idCounter1~0)| ~__ste_client_idCounter1~0) (= |old(~__ste_client_idCounter2~0)| ~__ste_client_idCounter2~0))} ~handle := #in~handle;~value := #in~value; {14748#true} is VALID [2022-02-20 17:56:12,011 INFO L290 TraceCheckUtils]: 1: Hoare triple {14748#true} assume 1 == ~handle;~__ste_client_idCounter0~0 := ~value; {14748#true} is VALID [2022-02-20 17:56:12,011 INFO L290 TraceCheckUtils]: 2: Hoare triple {14748#true} assume true; {14748#true} is VALID [2022-02-20 17:56:12,011 INFO L284 TraceCheckUtils]: 3: Hoare quadruple {14748#true} {14748#true} #1133#return; {14748#true} is VALID [2022-02-20 17:56:12,015 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 12 [2022-02-20 17:56:12,017 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-02-20 17:56:12,019 INFO L290 TraceCheckUtils]: 0: Hoare triple {14807#(and (= ~__ste_client_privateKey0~0 |old(~__ste_client_privateKey0~0)|) (= ~__ste_client_privateKey2~0 |old(~__ste_client_privateKey2~0)|) (= ~__ste_client_privateKey1~0 |old(~__ste_client_privateKey1~0)|))} ~handle := #in~handle;~value := #in~value; {14748#true} is VALID [2022-02-20 17:56:12,019 INFO L290 TraceCheckUtils]: 1: Hoare triple {14748#true} assume 1 == ~handle;~__ste_client_privateKey0~0 := ~value; {14748#true} is VALID [2022-02-20 17:56:12,019 INFO L290 TraceCheckUtils]: 2: Hoare triple {14748#true} assume true; {14748#true} is VALID [2022-02-20 17:56:12,019 INFO L284 TraceCheckUtils]: 3: Hoare quadruple {14748#true} {14748#true} #1135#return; {14748#true} is VALID [2022-02-20 17:56:12,019 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 18 [2022-02-20 17:56:12,021 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-02-20 17:56:12,023 INFO L290 TraceCheckUtils]: 0: Hoare triple {14806#(and (= |old(~__ste_client_idCounter0~0)| ~__ste_client_idCounter0~0) (= |old(~__ste_client_idCounter1~0)| ~__ste_client_idCounter1~0) (= |old(~__ste_client_idCounter2~0)| ~__ste_client_idCounter2~0))} ~handle := #in~handle;~value := #in~value; {14748#true} is VALID [2022-02-20 17:56:12,023 INFO L290 TraceCheckUtils]: 1: Hoare triple {14748#true} assume !(1 == ~handle); {14748#true} is VALID [2022-02-20 17:56:12,023 INFO L290 TraceCheckUtils]: 2: Hoare triple {14748#true} assume 2 == ~handle;~__ste_client_idCounter1~0 := ~value; {14748#true} is VALID [2022-02-20 17:56:12,023 INFO L290 TraceCheckUtils]: 3: Hoare triple {14748#true} assume true; {14748#true} is VALID [2022-02-20 17:56:12,023 INFO L284 TraceCheckUtils]: 4: Hoare quadruple {14748#true} {14748#true} #1137#return; {14748#true} is VALID [2022-02-20 17:56:12,023 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 25 [2022-02-20 17:56:12,025 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-02-20 17:56:12,026 INFO L290 TraceCheckUtils]: 0: Hoare triple {14807#(and (= ~__ste_client_privateKey0~0 |old(~__ste_client_privateKey0~0)|) (= ~__ste_client_privateKey2~0 |old(~__ste_client_privateKey2~0)|) (= ~__ste_client_privateKey1~0 |old(~__ste_client_privateKey1~0)|))} ~handle := #in~handle;~value := #in~value; {14748#true} is VALID [2022-02-20 17:56:12,026 INFO L290 TraceCheckUtils]: 1: Hoare triple {14748#true} assume !(1 == ~handle); {14748#true} is VALID [2022-02-20 17:56:12,027 INFO L290 TraceCheckUtils]: 2: Hoare triple {14748#true} assume 2 == ~handle;~__ste_client_privateKey1~0 := ~value; {14748#true} is VALID [2022-02-20 17:56:12,027 INFO L290 TraceCheckUtils]: 3: Hoare triple {14748#true} assume true; {14748#true} is VALID [2022-02-20 17:56:12,027 INFO L284 TraceCheckUtils]: 4: Hoare quadruple {14748#true} {14748#true} #1139#return; {14748#true} is VALID [2022-02-20 17:56:12,027 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 32 [2022-02-20 17:56:12,029 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-02-20 17:56:12,040 INFO L290 TraceCheckUtils]: 0: Hoare triple {14806#(and (= |old(~__ste_client_idCounter0~0)| ~__ste_client_idCounter0~0) (= |old(~__ste_client_idCounter1~0)| ~__ste_client_idCounter1~0) (= |old(~__ste_client_idCounter2~0)| ~__ste_client_idCounter2~0))} ~handle := #in~handle;~value := #in~value; {14808#(= setClientId_~handle |setClientId_#in~handle|)} is VALID [2022-02-20 17:56:12,040 INFO L290 TraceCheckUtils]: 1: Hoare triple {14808#(= setClientId_~handle |setClientId_#in~handle|)} assume 1 == ~handle;~__ste_client_idCounter0~0 := ~value; {14809#(= |setClientId_#in~handle| 1)} is VALID [2022-02-20 17:56:12,040 INFO L290 TraceCheckUtils]: 2: Hoare triple {14809#(= |setClientId_#in~handle| 1)} assume true; {14809#(= |setClientId_#in~handle| 1)} is VALID [2022-02-20 17:56:12,041 INFO L284 TraceCheckUtils]: 3: Hoare quadruple {14809#(= |setClientId_#in~handle| 1)} {14768#(= 3 |ULTIMATE.start_setup_chuck__wrappee__Base_~chuck___0#1|)} #1141#return; {14749#false} is VALID [2022-02-20 17:56:12,041 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 38 [2022-02-20 17:56:12,042 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-02-20 17:56:12,043 INFO L290 TraceCheckUtils]: 0: Hoare triple {14807#(and (= ~__ste_client_privateKey0~0 |old(~__ste_client_privateKey0~0)|) (= ~__ste_client_privateKey2~0 |old(~__ste_client_privateKey2~0)|) (= ~__ste_client_privateKey1~0 |old(~__ste_client_privateKey1~0)|))} ~handle := #in~handle;~value := #in~value; {14748#true} is VALID [2022-02-20 17:56:12,044 INFO L290 TraceCheckUtils]: 1: Hoare triple {14748#true} assume 1 == ~handle;~__ste_client_privateKey0~0 := ~value; {14748#true} is VALID [2022-02-20 17:56:12,044 INFO L290 TraceCheckUtils]: 2: Hoare triple {14748#true} assume true; {14748#true} is VALID [2022-02-20 17:56:12,044 INFO L284 TraceCheckUtils]: 3: Hoare quadruple {14748#true} {14749#false} #1143#return; {14749#false} is VALID [2022-02-20 17:56:12,049 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 60 [2022-02-20 17:56:12,051 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-02-20 17:56:12,053 INFO L290 TraceCheckUtils]: 0: Hoare triple {14810#(and (= |old(~__ste_email_from0~0)| ~__ste_email_from0~0) (= |old(~__ste_email_from1~0)| ~__ste_email_from1~0))} ~handle := #in~handle;~value := #in~value; {14748#true} is VALID [2022-02-20 17:56:12,053 INFO L290 TraceCheckUtils]: 1: Hoare triple {14748#true} assume 1 == ~handle;~__ste_email_from0~0 := ~value; {14748#true} is VALID [2022-02-20 17:56:12,053 INFO L290 TraceCheckUtils]: 2: Hoare triple {14748#true} assume true; {14748#true} is VALID [2022-02-20 17:56:12,053 INFO L284 TraceCheckUtils]: 3: Hoare quadruple {14748#true} {14749#false} #1119#return; {14749#false} is VALID [2022-02-20 17:56:12,059 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 65 [2022-02-20 17:56:12,060 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-02-20 17:56:12,065 INFO L290 TraceCheckUtils]: 0: Hoare triple {14811#(and (= ~__ste_email_to0~0 |old(~__ste_email_to0~0)|) (= ~__ste_email_to1~0 |old(~__ste_email_to1~0)|))} ~handle := #in~handle;~value := #in~value; {14748#true} is VALID [2022-02-20 17:56:12,065 INFO L290 TraceCheckUtils]: 1: Hoare triple {14748#true} assume 1 == ~handle;~__ste_email_to0~0 := ~value; {14748#true} is VALID [2022-02-20 17:56:12,065 INFO L290 TraceCheckUtils]: 2: Hoare triple {14748#true} assume true; {14748#true} is VALID [2022-02-20 17:56:12,066 INFO L284 TraceCheckUtils]: 3: Hoare quadruple {14748#true} {14749#false} #1121#return; {14749#false} is VALID [2022-02-20 17:56:12,066 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 74 [2022-02-20 17:56:12,068 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-02-20 17:56:12,070 INFO L290 TraceCheckUtils]: 0: Hoare triple {14748#true} ~handle := #in~handle;havoc ~retValue_acc~24; {14748#true} is VALID [2022-02-20 17:56:12,070 INFO L290 TraceCheckUtils]: 1: Hoare triple {14748#true} assume 1 == ~handle;~retValue_acc~24 := ~__ste_client_privateKey0~0;#res := ~retValue_acc~24; {14748#true} is VALID [2022-02-20 17:56:12,070 INFO L290 TraceCheckUtils]: 2: Hoare triple {14748#true} assume true; {14748#true} is VALID [2022-02-20 17:56:12,070 INFO L284 TraceCheckUtils]: 3: Hoare quadruple {14748#true} {14749#false} #1053#return; {14749#false} is VALID [2022-02-20 17:56:12,070 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 82 [2022-02-20 17:56:12,073 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-02-20 17:56:12,075 INFO L290 TraceCheckUtils]: 0: Hoare triple {14748#true} ~handle := #in~handle;havoc ~retValue_acc~36; {14748#true} is VALID [2022-02-20 17:56:12,075 INFO L290 TraceCheckUtils]: 1: Hoare triple {14748#true} assume 1 == ~handle;~retValue_acc~36 := ~__ste_email_to0~0;#res := ~retValue_acc~36; {14748#true} is VALID [2022-02-20 17:56:12,075 INFO L290 TraceCheckUtils]: 2: Hoare triple {14748#true} assume true; {14748#true} is VALID [2022-02-20 17:56:12,075 INFO L284 TraceCheckUtils]: 3: Hoare quadruple {14748#true} {14749#false} #1055#return; {14749#false} is VALID [2022-02-20 17:56:12,076 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 88 [2022-02-20 17:56:12,076 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-02-20 17:56:12,079 INFO L290 TraceCheckUtils]: 0: Hoare triple {14748#true} ~handle := #in~handle;~userid := #in~userid;havoc ~retValue_acc~29; {14748#true} is VALID [2022-02-20 17:56:12,079 INFO L290 TraceCheckUtils]: 1: Hoare triple {14748#true} assume 1 == ~handle; {14748#true} is VALID [2022-02-20 17:56:12,079 INFO L290 TraceCheckUtils]: 2: Hoare triple {14748#true} assume ~userid == ~__ste_Client_Keyring0_User0~0;~retValue_acc~29 := ~__ste_Client_Keyring0_PublicKey0~0;#res := ~retValue_acc~29; {14748#true} is VALID [2022-02-20 17:56:12,080 INFO L290 TraceCheckUtils]: 3: Hoare triple {14748#true} assume true; {14748#true} is VALID [2022-02-20 17:56:12,080 INFO L284 TraceCheckUtils]: 4: Hoare quadruple {14748#true} {14749#false} #1057#return; {14749#false} is VALID [2022-02-20 17:56:12,080 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 99 [2022-02-20 17:56:12,083 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-02-20 17:56:12,098 INFO L290 TraceCheckUtils]: 0: Hoare triple {14810#(and (= |old(~__ste_email_from0~0)| ~__ste_email_from0~0) (= |old(~__ste_email_from1~0)| ~__ste_email_from1~0))} ~handle := #in~handle;~value := #in~value; {14748#true} is VALID [2022-02-20 17:56:12,098 INFO L290 TraceCheckUtils]: 1: Hoare triple {14748#true} assume 1 == ~handle;~__ste_email_from0~0 := ~value; {14748#true} is VALID [2022-02-20 17:56:12,098 INFO L290 TraceCheckUtils]: 2: Hoare triple {14748#true} assume true; {14748#true} is VALID [2022-02-20 17:56:12,098 INFO L284 TraceCheckUtils]: 3: Hoare quadruple {14748#true} {14749#false} #1063#return; {14749#false} is VALID [2022-02-20 17:56:12,098 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 106 [2022-02-20 17:56:12,099 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-02-20 17:56:12,102 INFO L290 TraceCheckUtils]: 0: Hoare triple {14748#true} ~handle := #in~handle;havoc ~retValue_acc~39; {14748#true} is VALID [2022-02-20 17:56:12,102 INFO L290 TraceCheckUtils]: 1: Hoare triple {14748#true} assume 1 == ~handle;~retValue_acc~39 := ~__ste_email_isEncrypted0~0;#res := ~retValue_acc~39; {14748#true} is VALID [2022-02-20 17:56:12,103 INFO L290 TraceCheckUtils]: 2: Hoare triple {14748#true} assume true; {14748#true} is VALID [2022-02-20 17:56:12,103 INFO L284 TraceCheckUtils]: 3: Hoare quadruple {14748#true} {14749#false} #1067#return; {14749#false} is VALID [2022-02-20 17:56:12,103 INFO L290 TraceCheckUtils]: 0: Hoare triple {14748#true} assume { :begin_inline_ULTIMATE.init } true;#NULL.base, #NULL.offset := 0, 0;assume 0 == #valid[0];assume 0 < #StackHeapBarrier;call #Ultimate.allocInit(2, 1);call write~init~int(48, 1, 0, 1);call write~init~int(0, 1, 1, 1);call #Ultimate.allocInit(28, 2);call #Ultimate.allocInit(12, 3);call #Ultimate.allocInit(4, 4);call write~init~int(37, 4, 0, 1);call write~init~int(115, 4, 1, 1);call write~init~int(10, 4, 2, 1);call write~init~int(0, 4, 3, 1);call #Ultimate.allocInit(10, 5);call #Ultimate.allocInit(12, 6);call #Ultimate.allocInit(10, 7);call #Ultimate.allocInit(18, 8);call #Ultimate.allocInit(16, 9);call #Ultimate.allocInit(21, 10);call #Ultimate.allocInit(13, 11);call #Ultimate.allocInit(16, 12);call #Ultimate.allocInit(25, 13);call #Ultimate.allocInit(30, 14);call #Ultimate.allocInit(9, 15);call #Ultimate.allocInit(21, 16);call #Ultimate.allocInit(30, 17);call #Ultimate.allocInit(9, 18);call #Ultimate.allocInit(21, 19);call #Ultimate.allocInit(30, 20);call #Ultimate.allocInit(9, 21);call #Ultimate.allocInit(25, 22);call #Ultimate.allocInit(30, 23);call #Ultimate.allocInit(9, 24);call #Ultimate.allocInit(25, 25);call #Ultimate.allocInit(10, 26);call #Ultimate.allocInit(16, 27);call #Ultimate.allocInit(20, 28);call #Ultimate.allocInit(22, 29);call #Ultimate.allocInit(21, 30);call #Ultimate.allocInit(13, 31);call #Ultimate.allocInit(44, 32);call #Ultimate.allocInit(44, 33);call #Ultimate.allocInit(9, 34);call #Ultimate.allocInit(9, 35);call #Ultimate.allocInit(11, 36);call #Ultimate.allocInit(19, 37);call #Ultimate.allocInit(4, 38);call write~init~int(37, 38, 0, 1);call write~init~int(100, 38, 1, 1);call write~init~int(10, 38, 2, 1);call write~init~int(0, 38, 3, 1);call #Ultimate.allocInit(4, 39);call write~init~int(37, 39, 0, 1);call write~init~int(100, 39, 1, 1);call write~init~int(10, 39, 2, 1);call write~init~int(0, 39, 3, 1);~__SELECTED_FEATURE_Base~0 := 0;~__SELECTED_FEATURE_Keys~0 := 0;~__SELECTED_FEATURE_Encrypt~0 := 0;~__SELECTED_FEATURE_AutoResponder~0 := 0;~__SELECTED_FEATURE_AddressBook~0 := 0;~__SELECTED_FEATURE_Sign~0 := 0;~__SELECTED_FEATURE_Forward~0 := 0;~__SELECTED_FEATURE_Verify~0 := 0;~__SELECTED_FEATURE_Decrypt~0 := 0;~__GUIDSL_ROOT_PRODUCTION~0 := 0;~__GUIDSL_NON_TERMINAL_main~0 := 0;~head~0.base, ~head~0.offset := 0, 0;~queue_empty~0 := 1;~queued_message~0 := 0;~queued_client~0 := 0;~mail_is_sensitive~0 := -1;~__ste_Client_counter~0 := 0;~__ste_client_name0~0.base, ~__ste_client_name0~0.offset := 0, 0;~__ste_client_name1~0.base, ~__ste_client_name1~0.offset := 0, 0;~__ste_client_name2~0.base, ~__ste_client_name2~0.offset := 0, 0;~__ste_client_outbuffer0~0 := 0;~__ste_client_outbuffer1~0 := 0;~__ste_client_outbuffer2~0 := 0;~__ste_client_outbuffer3~0 := 0;~__ste_ClientAddressBook_size0~0 := 0;~__ste_ClientAddressBook_size1~0 := 0;~__ste_ClientAddressBook_size2~0 := 0;~__ste_Client_AddressBook0_Alias0~0 := 0;~__ste_Client_AddressBook0_Alias1~0 := 0;~__ste_Client_AddressBook0_Alias2~0 := 0;~__ste_Client_AddressBook1_Alias0~0 := 0;~__ste_Client_AddressBook1_Alias1~0 := 0;~__ste_Client_AddressBook1_Alias2~0 := 0;~__ste_Client_AddressBook2_Alias0~0 := 0;~__ste_Client_AddressBook2_Alias1~0 := 0;~__ste_Client_AddressBook2_Alias2~0 := 0;~__ste_Client_AddressBook0_Address0~0 := 0;~__ste_Client_AddressBook0_Address1~0 := 0;~__ste_Client_AddressBook0_Address2~0 := 0;~__ste_Client_AddressBook1_Address0~0 := 0;~__ste_Client_AddressBook1_Address1~0 := 0;~__ste_Client_AddressBook1_Address2~0 := 0;~__ste_Client_AddressBook2_Address0~0 := 0;~__ste_Client_AddressBook2_Address1~0 := 0;~__ste_Client_AddressBook2_Address2~0 := 0;~__ste_client_autoResponse0~0 := 0;~__ste_client_autoResponse1~0 := 0;~__ste_client_autoResponse2~0 := 0;~__ste_client_privateKey0~0 := 0;~__ste_client_privateKey1~0 := 0;~__ste_client_privateKey2~0 := 0;~__ste_ClientKeyring_size0~0 := 0;~__ste_ClientKeyring_size1~0 := 0;~__ste_ClientKeyring_size2~0 := 0;~__ste_Client_Keyring0_User0~0 := 0;~__ste_Client_Keyring0_User1~0 := 0;~__ste_Client_Keyring0_User2~0 := 0;~__ste_Client_Keyring1_User0~0 := 0;~__ste_Client_Keyring1_User1~0 := 0;~__ste_Client_Keyring1_User2~0 := 0;~__ste_Client_Keyring2_User0~0 := 0;~__ste_Client_Keyring2_User1~0 := 0;~__ste_Client_Keyring2_User2~0 := 0;~__ste_Client_Keyring0_PublicKey0~0 := 0;~__ste_Client_Keyring0_PublicKey1~0 := 0;~__ste_Client_Keyring0_PublicKey2~0 := 0;~__ste_Client_Keyring1_PublicKey0~0 := 0;~__ste_Client_Keyring1_PublicKey1~0 := 0;~__ste_Client_Keyring1_PublicKey2~0 := 0;~__ste_Client_Keyring2_PublicKey0~0 := 0;~__ste_Client_Keyring2_PublicKey1~0 := 0;~__ste_Client_Keyring2_PublicKey2~0 := 0;~__ste_client_forwardReceiver0~0 := 0;~__ste_client_forwardReceiver1~0 := 0;~__ste_client_forwardReceiver2~0 := 0;~__ste_client_forwardReceiver3~0 := 0;~__ste_client_idCounter0~0 := 0;~__ste_client_idCounter1~0 := 0;~__ste_client_idCounter2~0 := 0;~bob~0 := 0;~rjh~0 := 0;~chuck~0 := 0;~__ste_Email_counter~0 := 0;~__ste_email_id0~0 := 0;~__ste_email_id1~0 := 0;~__ste_email_from0~0 := 0;~__ste_email_from1~0 := 0;~__ste_email_to0~0 := 0;~__ste_email_to1~0 := 0;~__ste_email_subject0~0.base, ~__ste_email_subject0~0.offset := 0, 0;~__ste_email_subject1~0.base, ~__ste_email_subject1~0.offset := 0, 0;~__ste_email_body0~0.base, ~__ste_email_body0~0.offset := 0, 0;~__ste_email_body1~0.base, ~__ste_email_body1~0.offset := 0, 0;~__ste_email_isEncrypted0~0 := 0;~__ste_email_isEncrypted1~0 := 0;~__ste_email_encryptionKey0~0 := 0;~__ste_email_encryptionKey1~0 := 0;~__ste_email_isSigned0~0 := 0;~__ste_email_isSigned1~0 := 0;~__ste_email_signKey0~0 := 0;~__ste_email_signKey1~0 := 0;~__ste_email_isSignatureVerified0~0 := 0;~__ste_email_isSignatureVerified1~0 := 0; {14748#true} is VALID [2022-02-20 17:56:12,103 INFO L290 TraceCheckUtils]: 1: Hoare triple {14748#true} assume { :end_inline_ULTIMATE.init } true;assume { :begin_inline_main } true;havoc main_#res#1;havoc main_#t~ret98#1, main_~retValue_acc~32#1, main_~tmp~24#1;havoc main_~retValue_acc~32#1;havoc main_~tmp~24#1;assume { :begin_inline_select_helpers } true; {14748#true} is VALID [2022-02-20 17:56:12,103 INFO L290 TraceCheckUtils]: 2: Hoare triple {14748#true} assume { :end_inline_select_helpers } true;assume { :begin_inline_select_features } true; {14748#true} is VALID [2022-02-20 17:56:12,103 INFO L290 TraceCheckUtils]: 3: Hoare triple {14748#true} assume { :end_inline_select_features } true;assume { :begin_inline_valid_product } true;havoc valid_product_#res#1;havoc valid_product_~retValue_acc~9#1;havoc valid_product_~retValue_acc~9#1;valid_product_~retValue_acc~9#1 := 1;valid_product_#res#1 := valid_product_~retValue_acc~9#1; {14748#true} is VALID [2022-02-20 17:56:12,103 INFO L290 TraceCheckUtils]: 4: Hoare triple {14748#true} main_#t~ret98#1 := valid_product_#res#1;assume { :end_inline_valid_product } true;assume -2147483648 <= main_#t~ret98#1 && main_#t~ret98#1 <= 2147483647;main_~tmp~24#1 := main_#t~ret98#1;havoc main_#t~ret98#1; {14748#true} is VALID [2022-02-20 17:56:12,104 INFO L290 TraceCheckUtils]: 5: Hoare triple {14748#true} assume 0 != main_~tmp~24#1;assume { :begin_inline_setup } true;havoc setup_#t~nondet95#1, setup_#t~nondet96#1, setup_#t~nondet97#1, setup_~__cil_tmp1~0#1.base, setup_~__cil_tmp1~0#1.offset, setup_~__cil_tmp2~0#1.base, setup_~__cil_tmp2~0#1.offset, setup_~__cil_tmp3~2#1.base, setup_~__cil_tmp3~2#1.offset;havoc setup_~__cil_tmp1~0#1.base, setup_~__cil_tmp1~0#1.offset;havoc setup_~__cil_tmp2~0#1.base, setup_~__cil_tmp2~0#1.offset;havoc setup_~__cil_tmp3~2#1.base, setup_~__cil_tmp3~2#1.offset;~bob~0 := 1;assume { :begin_inline_setup_bob } true;setup_bob_#in~bob___0#1 := ~bob~0;havoc setup_bob_~bob___0#1;setup_bob_~bob___0#1 := setup_bob_#in~bob___0#1;assume { :begin_inline_setup_bob__wrappee__Base } true;setup_bob__wrappee__Base_#in~bob___0#1 := setup_bob_~bob___0#1;havoc setup_bob__wrappee__Base_~bob___0#1;setup_bob__wrappee__Base_~bob___0#1 := setup_bob__wrappee__Base_#in~bob___0#1; {14748#true} is VALID [2022-02-20 17:56:12,104 INFO L272 TraceCheckUtils]: 6: Hoare triple {14748#true} call setClientId(setup_bob__wrappee__Base_~bob___0#1, setup_bob__wrappee__Base_~bob___0#1); {14806#(and (= |old(~__ste_client_idCounter0~0)| ~__ste_client_idCounter0~0) (= |old(~__ste_client_idCounter1~0)| ~__ste_client_idCounter1~0) (= |old(~__ste_client_idCounter2~0)| ~__ste_client_idCounter2~0))} is VALID [2022-02-20 17:56:12,104 INFO L290 TraceCheckUtils]: 7: Hoare triple {14806#(and (= |old(~__ste_client_idCounter0~0)| ~__ste_client_idCounter0~0) (= |old(~__ste_client_idCounter1~0)| ~__ste_client_idCounter1~0) (= |old(~__ste_client_idCounter2~0)| ~__ste_client_idCounter2~0))} ~handle := #in~handle;~value := #in~value; {14748#true} is VALID [2022-02-20 17:56:12,104 INFO L290 TraceCheckUtils]: 8: Hoare triple {14748#true} assume 1 == ~handle;~__ste_client_idCounter0~0 := ~value; {14748#true} is VALID [2022-02-20 17:56:12,104 INFO L290 TraceCheckUtils]: 9: Hoare triple {14748#true} assume true; {14748#true} is VALID [2022-02-20 17:56:12,105 INFO L284 TraceCheckUtils]: 10: Hoare quadruple {14748#true} {14748#true} #1133#return; {14748#true} is VALID [2022-02-20 17:56:12,105 INFO L290 TraceCheckUtils]: 11: Hoare triple {14748#true} assume { :end_inline_setup_bob__wrappee__Base } true; {14748#true} is VALID [2022-02-20 17:56:12,106 INFO L272 TraceCheckUtils]: 12: Hoare triple {14748#true} call setClientPrivateKey(setup_bob_~bob___0#1, 123); {14807#(and (= ~__ste_client_privateKey0~0 |old(~__ste_client_privateKey0~0)|) (= ~__ste_client_privateKey2~0 |old(~__ste_client_privateKey2~0)|) (= ~__ste_client_privateKey1~0 |old(~__ste_client_privateKey1~0)|))} is VALID [2022-02-20 17:56:12,106 INFO L290 TraceCheckUtils]: 13: Hoare triple {14807#(and (= ~__ste_client_privateKey0~0 |old(~__ste_client_privateKey0~0)|) (= ~__ste_client_privateKey2~0 |old(~__ste_client_privateKey2~0)|) (= ~__ste_client_privateKey1~0 |old(~__ste_client_privateKey1~0)|))} ~handle := #in~handle;~value := #in~value; {14748#true} is VALID [2022-02-20 17:56:12,106 INFO L290 TraceCheckUtils]: 14: Hoare triple {14748#true} assume 1 == ~handle;~__ste_client_privateKey0~0 := ~value; {14748#true} is VALID [2022-02-20 17:56:12,106 INFO L290 TraceCheckUtils]: 15: Hoare triple {14748#true} assume true; {14748#true} is VALID [2022-02-20 17:56:12,106 INFO L284 TraceCheckUtils]: 16: Hoare quadruple {14748#true} {14748#true} #1135#return; {14748#true} is VALID [2022-02-20 17:56:12,106 INFO L290 TraceCheckUtils]: 17: Hoare triple {14748#true} assume { :end_inline_setup_bob } true;setup_~__cil_tmp1~0#1.base, setup_~__cil_tmp1~0#1.offset := 34, 0;havoc setup_#t~nondet95#1;~rjh~0 := 2;assume { :begin_inline_setup_rjh } true;setup_rjh_#in~rjh___0#1 := ~rjh~0;havoc setup_rjh_~rjh___0#1;setup_rjh_~rjh___0#1 := setup_rjh_#in~rjh___0#1;assume { :begin_inline_setup_rjh__wrappee__Base } true;setup_rjh__wrappee__Base_#in~rjh___0#1 := setup_rjh_~rjh___0#1;havoc setup_rjh__wrappee__Base_~rjh___0#1;setup_rjh__wrappee__Base_~rjh___0#1 := setup_rjh__wrappee__Base_#in~rjh___0#1; {14748#true} is VALID [2022-02-20 17:56:12,107 INFO L272 TraceCheckUtils]: 18: Hoare triple {14748#true} call setClientId(setup_rjh__wrappee__Base_~rjh___0#1, setup_rjh__wrappee__Base_~rjh___0#1); {14806#(and (= |old(~__ste_client_idCounter0~0)| ~__ste_client_idCounter0~0) (= |old(~__ste_client_idCounter1~0)| ~__ste_client_idCounter1~0) (= |old(~__ste_client_idCounter2~0)| ~__ste_client_idCounter2~0))} is VALID [2022-02-20 17:56:12,107 INFO L290 TraceCheckUtils]: 19: Hoare triple {14806#(and (= |old(~__ste_client_idCounter0~0)| ~__ste_client_idCounter0~0) (= |old(~__ste_client_idCounter1~0)| ~__ste_client_idCounter1~0) (= |old(~__ste_client_idCounter2~0)| ~__ste_client_idCounter2~0))} ~handle := #in~handle;~value := #in~value; {14748#true} is VALID [2022-02-20 17:56:12,107 INFO L290 TraceCheckUtils]: 20: Hoare triple {14748#true} assume !(1 == ~handle); {14748#true} is VALID [2022-02-20 17:56:12,107 INFO L290 TraceCheckUtils]: 21: Hoare triple {14748#true} assume 2 == ~handle;~__ste_client_idCounter1~0 := ~value; {14748#true} is VALID [2022-02-20 17:56:12,107 INFO L290 TraceCheckUtils]: 22: Hoare triple {14748#true} assume true; {14748#true} is VALID [2022-02-20 17:56:12,107 INFO L284 TraceCheckUtils]: 23: Hoare quadruple {14748#true} {14748#true} #1137#return; {14748#true} is VALID [2022-02-20 17:56:12,107 INFO L290 TraceCheckUtils]: 24: Hoare triple {14748#true} assume { :end_inline_setup_rjh__wrappee__Base } true; {14748#true} is VALID [2022-02-20 17:56:12,108 INFO L272 TraceCheckUtils]: 25: Hoare triple {14748#true} call setClientPrivateKey(setup_rjh_~rjh___0#1, 456); {14807#(and (= ~__ste_client_privateKey0~0 |old(~__ste_client_privateKey0~0)|) (= ~__ste_client_privateKey2~0 |old(~__ste_client_privateKey2~0)|) (= ~__ste_client_privateKey1~0 |old(~__ste_client_privateKey1~0)|))} is VALID [2022-02-20 17:56:12,108 INFO L290 TraceCheckUtils]: 26: Hoare triple {14807#(and (= ~__ste_client_privateKey0~0 |old(~__ste_client_privateKey0~0)|) (= ~__ste_client_privateKey2~0 |old(~__ste_client_privateKey2~0)|) (= ~__ste_client_privateKey1~0 |old(~__ste_client_privateKey1~0)|))} ~handle := #in~handle;~value := #in~value; {14748#true} is VALID [2022-02-20 17:56:12,108 INFO L290 TraceCheckUtils]: 27: Hoare triple {14748#true} assume !(1 == ~handle); {14748#true} is VALID [2022-02-20 17:56:12,108 INFO L290 TraceCheckUtils]: 28: Hoare triple {14748#true} assume 2 == ~handle;~__ste_client_privateKey1~0 := ~value; {14748#true} is VALID [2022-02-20 17:56:12,108 INFO L290 TraceCheckUtils]: 29: Hoare triple {14748#true} assume true; {14748#true} is VALID [2022-02-20 17:56:12,108 INFO L284 TraceCheckUtils]: 30: Hoare quadruple {14748#true} {14748#true} #1139#return; {14748#true} is VALID [2022-02-20 17:56:12,108 INFO L290 TraceCheckUtils]: 31: Hoare triple {14748#true} assume { :end_inline_setup_rjh } true;setup_~__cil_tmp2~0#1.base, setup_~__cil_tmp2~0#1.offset := 35, 0;havoc setup_#t~nondet96#1;~chuck~0 := 3;assume { :begin_inline_setup_chuck } true;setup_chuck_#in~chuck___0#1 := ~chuck~0;havoc setup_chuck_~chuck___0#1;setup_chuck_~chuck___0#1 := setup_chuck_#in~chuck___0#1;assume { :begin_inline_setup_chuck__wrappee__Base } true;setup_chuck__wrappee__Base_#in~chuck___0#1 := setup_chuck_~chuck___0#1;havoc setup_chuck__wrappee__Base_~chuck___0#1;setup_chuck__wrappee__Base_~chuck___0#1 := setup_chuck__wrappee__Base_#in~chuck___0#1; {14768#(= 3 |ULTIMATE.start_setup_chuck__wrappee__Base_~chuck___0#1|)} is VALID [2022-02-20 17:56:12,119 INFO L272 TraceCheckUtils]: 32: Hoare triple {14768#(= 3 |ULTIMATE.start_setup_chuck__wrappee__Base_~chuck___0#1|)} call setClientId(setup_chuck__wrappee__Base_~chuck___0#1, setup_chuck__wrappee__Base_~chuck___0#1); {14806#(and (= |old(~__ste_client_idCounter0~0)| ~__ste_client_idCounter0~0) (= |old(~__ste_client_idCounter1~0)| ~__ste_client_idCounter1~0) (= |old(~__ste_client_idCounter2~0)| ~__ste_client_idCounter2~0))} is VALID [2022-02-20 17:56:12,120 INFO L290 TraceCheckUtils]: 33: Hoare triple {14806#(and (= |old(~__ste_client_idCounter0~0)| ~__ste_client_idCounter0~0) (= |old(~__ste_client_idCounter1~0)| ~__ste_client_idCounter1~0) (= |old(~__ste_client_idCounter2~0)| ~__ste_client_idCounter2~0))} ~handle := #in~handle;~value := #in~value; {14808#(= setClientId_~handle |setClientId_#in~handle|)} is VALID [2022-02-20 17:56:12,120 INFO L290 TraceCheckUtils]: 34: Hoare triple {14808#(= setClientId_~handle |setClientId_#in~handle|)} assume 1 == ~handle;~__ste_client_idCounter0~0 := ~value; {14809#(= |setClientId_#in~handle| 1)} is VALID [2022-02-20 17:56:12,120 INFO L290 TraceCheckUtils]: 35: Hoare triple {14809#(= |setClientId_#in~handle| 1)} assume true; {14809#(= |setClientId_#in~handle| 1)} is VALID [2022-02-20 17:56:12,121 INFO L284 TraceCheckUtils]: 36: Hoare quadruple {14809#(= |setClientId_#in~handle| 1)} {14768#(= 3 |ULTIMATE.start_setup_chuck__wrappee__Base_~chuck___0#1|)} #1141#return; {14749#false} is VALID [2022-02-20 17:56:12,121 INFO L290 TraceCheckUtils]: 37: Hoare triple {14749#false} assume { :end_inline_setup_chuck__wrappee__Base } true; {14749#false} is VALID [2022-02-20 17:56:12,121 INFO L272 TraceCheckUtils]: 38: Hoare triple {14749#false} call setClientPrivateKey(setup_chuck_~chuck___0#1, 789); {14807#(and (= ~__ste_client_privateKey0~0 |old(~__ste_client_privateKey0~0)|) (= ~__ste_client_privateKey2~0 |old(~__ste_client_privateKey2~0)|) (= ~__ste_client_privateKey1~0 |old(~__ste_client_privateKey1~0)|))} is VALID [2022-02-20 17:56:12,121 INFO L290 TraceCheckUtils]: 39: Hoare triple {14807#(and (= ~__ste_client_privateKey0~0 |old(~__ste_client_privateKey0~0)|) (= ~__ste_client_privateKey2~0 |old(~__ste_client_privateKey2~0)|) (= ~__ste_client_privateKey1~0 |old(~__ste_client_privateKey1~0)|))} ~handle := #in~handle;~value := #in~value; {14748#true} is VALID [2022-02-20 17:56:12,121 INFO L290 TraceCheckUtils]: 40: Hoare triple {14748#true} assume 1 == ~handle;~__ste_client_privateKey0~0 := ~value; {14748#true} is VALID [2022-02-20 17:56:12,121 INFO L290 TraceCheckUtils]: 41: Hoare triple {14748#true} assume true; {14748#true} is VALID [2022-02-20 17:56:12,121 INFO L284 TraceCheckUtils]: 42: Hoare quadruple {14748#true} {14749#false} #1143#return; {14749#false} is VALID [2022-02-20 17:56:12,121 INFO L290 TraceCheckUtils]: 43: Hoare triple {14749#false} assume { :end_inline_setup_chuck } true;setup_~__cil_tmp3~2#1.base, setup_~__cil_tmp3~2#1.offset := 36, 0;havoc setup_#t~nondet97#1; {14749#false} is VALID [2022-02-20 17:56:12,121 INFO L290 TraceCheckUtils]: 44: Hoare triple {14749#false} assume { :end_inline_setup } true;assume { :begin_inline_test } true;havoc test_#t~nondet48#1, test_#t~nondet49#1, test_#t~nondet50#1, test_#t~nondet51#1, test_#t~nondet52#1, test_#t~nondet53#1, test_#t~nondet54#1, test_#t~nondet55#1, test_#t~nondet56#1, test_#t~nondet57#1, test_#t~nondet58#1, test_~op1~0#1, test_~op2~0#1, test_~op3~0#1, test_~op4~0#1, test_~op5~0#1, test_~op6~0#1, test_~op7~0#1, test_~op8~0#1, test_~op9~0#1, test_~op10~0#1, test_~op11~0#1, test_~splverifierCounter~0#1, test_~tmp~8#1, test_~tmp___0~3#1, test_~tmp___1~1#1, test_~tmp___2~1#1, test_~tmp___3~0#1, test_~tmp___4~0#1, test_~tmp___5~0#1, test_~tmp___6~0#1, test_~tmp___7~0#1, test_~tmp___8~0#1, test_~tmp___9~0#1;havoc test_~op1~0#1;havoc test_~op2~0#1;havoc test_~op3~0#1;havoc test_~op4~0#1;havoc test_~op5~0#1;havoc test_~op6~0#1;havoc test_~op7~0#1;havoc test_~op8~0#1;havoc test_~op9~0#1;havoc test_~op10~0#1;havoc test_~op11~0#1;havoc test_~splverifierCounter~0#1;havoc test_~tmp~8#1;havoc test_~tmp___0~3#1;havoc test_~tmp___1~1#1;havoc test_~tmp___2~1#1;havoc test_~tmp___3~0#1;havoc test_~tmp___4~0#1;havoc test_~tmp___5~0#1;havoc test_~tmp___6~0#1;havoc test_~tmp___7~0#1;havoc test_~tmp___8~0#1;havoc test_~tmp___9~0#1;test_~op1~0#1 := 0;test_~op2~0#1 := 0;test_~op3~0#1 := 0;test_~op4~0#1 := 0;test_~op5~0#1 := 0;test_~op6~0#1 := 0;test_~op7~0#1 := 0;test_~op8~0#1 := 0;test_~op9~0#1 := 0;test_~op10~0#1 := 0;test_~op11~0#1 := 0;test_~splverifierCounter~0#1 := 0; {14749#false} is VALID [2022-02-20 17:56:12,121 INFO L290 TraceCheckUtils]: 45: Hoare triple {14749#false} assume !false; {14749#false} is VALID [2022-02-20 17:56:12,121 INFO L290 TraceCheckUtils]: 46: Hoare triple {14749#false} assume test_~splverifierCounter~0#1 < 4; {14749#false} is VALID [2022-02-20 17:56:12,121 INFO L290 TraceCheckUtils]: 47: Hoare triple {14749#false} test_~splverifierCounter~0#1 := 1 + test_~splverifierCounter~0#1; {14749#false} is VALID [2022-02-20 17:56:12,121 INFO L290 TraceCheckUtils]: 48: Hoare triple {14749#false} assume 0 == test_~op1~0#1;assume -2147483648 <= test_#t~nondet48#1 && test_#t~nondet48#1 <= 2147483647;test_~tmp___9~0#1 := test_#t~nondet48#1;havoc test_#t~nondet48#1; {14749#false} is VALID [2022-02-20 17:56:12,121 INFO L290 TraceCheckUtils]: 49: Hoare triple {14749#false} assume !(0 != test_~tmp___9~0#1); {14749#false} is VALID [2022-02-20 17:56:12,121 INFO L290 TraceCheckUtils]: 50: Hoare triple {14749#false} assume 0 == test_~op2~0#1;assume -2147483648 <= test_#t~nondet49#1 && test_#t~nondet49#1 <= 2147483647;test_~tmp___8~0#1 := test_#t~nondet49#1;havoc test_#t~nondet49#1; {14749#false} is VALID [2022-02-20 17:56:12,122 INFO L290 TraceCheckUtils]: 51: Hoare triple {14749#false} assume 0 != test_~tmp___8~0#1;assume { :begin_inline_rjhSetAutoRespond } true;assume { :begin_inline_setClientAutoResponse } true;setClientAutoResponse_#in~handle#1, setClientAutoResponse_#in~value#1 := ~rjh~0, 1;havoc setClientAutoResponse_~handle#1, setClientAutoResponse_~value#1;setClientAutoResponse_~handle#1 := setClientAutoResponse_#in~handle#1;setClientAutoResponse_~value#1 := setClientAutoResponse_#in~value#1; {14749#false} is VALID [2022-02-20 17:56:12,122 INFO L290 TraceCheckUtils]: 52: Hoare triple {14749#false} assume 1 == setClientAutoResponse_~handle#1;~__ste_client_autoResponse0~0 := setClientAutoResponse_~value#1; {14749#false} is VALID [2022-02-20 17:56:12,122 INFO L290 TraceCheckUtils]: 53: Hoare triple {14749#false} assume { :end_inline_setClientAutoResponse } true; {14749#false} is VALID [2022-02-20 17:56:12,122 INFO L290 TraceCheckUtils]: 54: Hoare triple {14749#false} assume { :end_inline_rjhSetAutoRespond } true;test_~op2~0#1 := 1; {14749#false} is VALID [2022-02-20 17:56:12,122 INFO L290 TraceCheckUtils]: 55: Hoare triple {14749#false} assume !false; {14749#false} is VALID [2022-02-20 17:56:12,122 INFO L290 TraceCheckUtils]: 56: Hoare triple {14749#false} assume !(test_~splverifierCounter~0#1 < 4); {14749#false} is VALID [2022-02-20 17:56:12,122 INFO L290 TraceCheckUtils]: 57: Hoare triple {14749#false} assume { :begin_inline_bobToRjh } true;havoc bobToRjh_#t~ret90#1, bobToRjh_#t~ret91#1, bobToRjh_#t~ret92#1, bobToRjh_#t~ret93#1, bobToRjh_~tmp~23#1, bobToRjh_~tmp___0~7#1, bobToRjh_~tmp___1~4#1;havoc bobToRjh_~tmp~23#1;havoc bobToRjh_~tmp___0~7#1;havoc bobToRjh_~tmp___1~4#1;call bobToRjh_#t~ret90#1 := puts(32, 0);assume -2147483648 <= bobToRjh_#t~ret90#1 && bobToRjh_#t~ret90#1 <= 2147483647;havoc bobToRjh_#t~ret90#1; {14749#false} is VALID [2022-02-20 17:56:12,122 INFO L272 TraceCheckUtils]: 58: Hoare triple {14749#false} call sendEmail(~bob~0, ~rjh~0); {14749#false} is VALID [2022-02-20 17:56:12,122 INFO L290 TraceCheckUtils]: 59: Hoare triple {14749#false} ~sender#1 := #in~sender#1;~receiver#1 := #in~receiver#1;havoc ~email~0#1;havoc ~tmp~16#1;assume { :begin_inline_createEmail } true;createEmail_#in~from#1, createEmail_#in~to#1 := 0, ~receiver#1;havoc createEmail_#res#1;havoc createEmail_~from#1, createEmail_~to#1, createEmail_~retValue_acc~4#1, createEmail_~msg~0#1;createEmail_~from#1 := createEmail_#in~from#1;createEmail_~to#1 := createEmail_#in~to#1;havoc createEmail_~retValue_acc~4#1;havoc createEmail_~msg~0#1;createEmail_~msg~0#1 := 1; {14749#false} is VALID [2022-02-20 17:56:12,122 INFO L272 TraceCheckUtils]: 60: Hoare triple {14749#false} call setEmailFrom(createEmail_~msg~0#1, createEmail_~from#1); {14810#(and (= |old(~__ste_email_from0~0)| ~__ste_email_from0~0) (= |old(~__ste_email_from1~0)| ~__ste_email_from1~0))} is VALID [2022-02-20 17:56:12,123 INFO L290 TraceCheckUtils]: 61: Hoare triple {14810#(and (= |old(~__ste_email_from0~0)| ~__ste_email_from0~0) (= |old(~__ste_email_from1~0)| ~__ste_email_from1~0))} ~handle := #in~handle;~value := #in~value; {14748#true} is VALID [2022-02-20 17:56:12,123 INFO L290 TraceCheckUtils]: 62: Hoare triple {14748#true} assume 1 == ~handle;~__ste_email_from0~0 := ~value; {14748#true} is VALID [2022-02-20 17:56:12,123 INFO L290 TraceCheckUtils]: 63: Hoare triple {14748#true} assume true; {14748#true} is VALID [2022-02-20 17:56:12,123 INFO L284 TraceCheckUtils]: 64: Hoare quadruple {14748#true} {14749#false} #1119#return; {14749#false} is VALID [2022-02-20 17:56:12,123 INFO L272 TraceCheckUtils]: 65: Hoare triple {14749#false} call setEmailTo(createEmail_~msg~0#1, createEmail_~to#1); {14811#(and (= ~__ste_email_to0~0 |old(~__ste_email_to0~0)|) (= ~__ste_email_to1~0 |old(~__ste_email_to1~0)|))} is VALID [2022-02-20 17:56:12,123 INFO L290 TraceCheckUtils]: 66: Hoare triple {14811#(and (= ~__ste_email_to0~0 |old(~__ste_email_to0~0)|) (= ~__ste_email_to1~0 |old(~__ste_email_to1~0)|))} ~handle := #in~handle;~value := #in~value; {14748#true} is VALID [2022-02-20 17:56:12,123 INFO L290 TraceCheckUtils]: 67: Hoare triple {14748#true} assume 1 == ~handle;~__ste_email_to0~0 := ~value; {14748#true} is VALID [2022-02-20 17:56:12,123 INFO L290 TraceCheckUtils]: 68: Hoare triple {14748#true} assume true; {14748#true} is VALID [2022-02-20 17:56:12,123 INFO L284 TraceCheckUtils]: 69: Hoare quadruple {14748#true} {14749#false} #1121#return; {14749#false} is VALID [2022-02-20 17:56:12,123 INFO L290 TraceCheckUtils]: 70: Hoare triple {14749#false} createEmail_~retValue_acc~4#1 := createEmail_~msg~0#1;createEmail_#res#1 := createEmail_~retValue_acc~4#1; {14749#false} is VALID [2022-02-20 17:56:12,124 INFO L290 TraceCheckUtils]: 71: Hoare triple {14749#false} #t~ret73#1 := createEmail_#res#1;assume { :end_inline_createEmail } true;assume -2147483648 <= #t~ret73#1 && #t~ret73#1 <= 2147483647;~tmp~16#1 := #t~ret73#1;havoc #t~ret73#1;~email~0#1 := ~tmp~16#1; {14749#false} is VALID [2022-02-20 17:56:12,124 INFO L272 TraceCheckUtils]: 72: Hoare triple {14749#false} call outgoing(~sender#1, ~email~0#1); {14749#false} is VALID [2022-02-20 17:56:12,124 INFO L290 TraceCheckUtils]: 73: Hoare triple {14749#false} ~client#1 := #in~client#1;~msg#1 := #in~msg#1;assume { :begin_inline_sign } true;sign_#in~client#1, sign_#in~msg#1 := ~client#1, ~msg#1;havoc sign_#t~ret77#1, sign_~client#1, sign_~msg#1, sign_~privkey~1#1, sign_~tmp~18#1;sign_~client#1 := sign_#in~client#1;sign_~msg#1 := sign_#in~msg#1;havoc sign_~privkey~1#1;havoc sign_~tmp~18#1; {14749#false} is VALID [2022-02-20 17:56:12,124 INFO L272 TraceCheckUtils]: 74: Hoare triple {14749#false} call sign_#t~ret77#1 := getClientPrivateKey(sign_~client#1); {14748#true} is VALID [2022-02-20 17:56:12,124 INFO L290 TraceCheckUtils]: 75: Hoare triple {14748#true} ~handle := #in~handle;havoc ~retValue_acc~24; {14748#true} is VALID [2022-02-20 17:56:12,124 INFO L290 TraceCheckUtils]: 76: Hoare triple {14748#true} assume 1 == ~handle;~retValue_acc~24 := ~__ste_client_privateKey0~0;#res := ~retValue_acc~24; {14748#true} is VALID [2022-02-20 17:56:12,124 INFO L290 TraceCheckUtils]: 77: Hoare triple {14748#true} assume true; {14748#true} is VALID [2022-02-20 17:56:12,124 INFO L284 TraceCheckUtils]: 78: Hoare quadruple {14748#true} {14749#false} #1053#return; {14749#false} is VALID [2022-02-20 17:56:12,124 INFO L290 TraceCheckUtils]: 79: Hoare triple {14749#false} assume -2147483648 <= sign_#t~ret77#1 && sign_#t~ret77#1 <= 2147483647;sign_~tmp~18#1 := sign_#t~ret77#1;havoc sign_#t~ret77#1;sign_~privkey~1#1 := sign_~tmp~18#1; {14749#false} is VALID [2022-02-20 17:56:12,124 INFO L290 TraceCheckUtils]: 80: Hoare triple {14749#false} assume 0 == sign_~privkey~1#1; {14749#false} is VALID [2022-02-20 17:56:12,125 INFO L290 TraceCheckUtils]: 81: Hoare triple {14749#false} assume { :end_inline_sign } true;assume { :begin_inline_outgoing__wrappee__AutoResponder } true;outgoing__wrappee__AutoResponder_#in~client#1, outgoing__wrappee__AutoResponder_#in~msg#1 := ~client#1, ~msg#1;havoc outgoing__wrappee__AutoResponder_#t~ret63#1, outgoing__wrappee__AutoResponder_#t~ret64#1, outgoing__wrappee__AutoResponder_~client#1, outgoing__wrappee__AutoResponder_~msg#1, outgoing__wrappee__AutoResponder_~receiver~0#1, outgoing__wrappee__AutoResponder_~tmp~11#1, outgoing__wrappee__AutoResponder_~pubkey~0#1, outgoing__wrappee__AutoResponder_~tmp___0~4#1;outgoing__wrappee__AutoResponder_~client#1 := outgoing__wrappee__AutoResponder_#in~client#1;outgoing__wrappee__AutoResponder_~msg#1 := outgoing__wrappee__AutoResponder_#in~msg#1;havoc outgoing__wrappee__AutoResponder_~receiver~0#1;havoc outgoing__wrappee__AutoResponder_~tmp~11#1;havoc outgoing__wrappee__AutoResponder_~pubkey~0#1;havoc outgoing__wrappee__AutoResponder_~tmp___0~4#1; {14749#false} is VALID [2022-02-20 17:56:12,125 INFO L272 TraceCheckUtils]: 82: Hoare triple {14749#false} call outgoing__wrappee__AutoResponder_#t~ret63#1 := getEmailTo(outgoing__wrappee__AutoResponder_~msg#1); {14748#true} is VALID [2022-02-20 17:56:12,125 INFO L290 TraceCheckUtils]: 83: Hoare triple {14748#true} ~handle := #in~handle;havoc ~retValue_acc~36; {14748#true} is VALID [2022-02-20 17:56:12,125 INFO L290 TraceCheckUtils]: 84: Hoare triple {14748#true} assume 1 == ~handle;~retValue_acc~36 := ~__ste_email_to0~0;#res := ~retValue_acc~36; {14748#true} is VALID [2022-02-20 17:56:12,138 INFO L290 TraceCheckUtils]: 85: Hoare triple {14748#true} assume true; {14748#true} is VALID [2022-02-20 17:56:12,138 INFO L284 TraceCheckUtils]: 86: Hoare quadruple {14748#true} {14749#false} #1055#return; {14749#false} is VALID [2022-02-20 17:56:12,138 INFO L290 TraceCheckUtils]: 87: Hoare triple {14749#false} assume -2147483648 <= outgoing__wrappee__AutoResponder_#t~ret63#1 && outgoing__wrappee__AutoResponder_#t~ret63#1 <= 2147483647;outgoing__wrappee__AutoResponder_~tmp~11#1 := outgoing__wrappee__AutoResponder_#t~ret63#1;havoc outgoing__wrappee__AutoResponder_#t~ret63#1;outgoing__wrappee__AutoResponder_~receiver~0#1 := outgoing__wrappee__AutoResponder_~tmp~11#1; {14749#false} is VALID [2022-02-20 17:56:12,139 INFO L272 TraceCheckUtils]: 88: Hoare triple {14749#false} call outgoing__wrappee__AutoResponder_#t~ret64#1 := findPublicKey(outgoing__wrappee__AutoResponder_~client#1, outgoing__wrappee__AutoResponder_~receiver~0#1); {14748#true} is VALID [2022-02-20 17:56:12,139 INFO L290 TraceCheckUtils]: 89: Hoare triple {14748#true} ~handle := #in~handle;~userid := #in~userid;havoc ~retValue_acc~29; {14748#true} is VALID [2022-02-20 17:56:12,139 INFO L290 TraceCheckUtils]: 90: Hoare triple {14748#true} assume 1 == ~handle; {14748#true} is VALID [2022-02-20 17:56:12,139 INFO L290 TraceCheckUtils]: 91: Hoare triple {14748#true} assume ~userid == ~__ste_Client_Keyring0_User0~0;~retValue_acc~29 := ~__ste_Client_Keyring0_PublicKey0~0;#res := ~retValue_acc~29; {14748#true} is VALID [2022-02-20 17:56:12,139 INFO L290 TraceCheckUtils]: 92: Hoare triple {14748#true} assume true; {14748#true} is VALID [2022-02-20 17:56:12,139 INFO L284 TraceCheckUtils]: 93: Hoare quadruple {14748#true} {14749#false} #1057#return; {14749#false} is VALID [2022-02-20 17:56:12,139 INFO L290 TraceCheckUtils]: 94: Hoare triple {14749#false} assume -2147483648 <= outgoing__wrappee__AutoResponder_#t~ret64#1 && outgoing__wrappee__AutoResponder_#t~ret64#1 <= 2147483647;outgoing__wrappee__AutoResponder_~tmp___0~4#1 := outgoing__wrappee__AutoResponder_#t~ret64#1;havoc outgoing__wrappee__AutoResponder_#t~ret64#1;outgoing__wrappee__AutoResponder_~pubkey~0#1 := outgoing__wrappee__AutoResponder_~tmp___0~4#1; {14749#false} is VALID [2022-02-20 17:56:12,139 INFO L290 TraceCheckUtils]: 95: Hoare triple {14749#false} assume !(0 != outgoing__wrappee__AutoResponder_~pubkey~0#1); {14749#false} is VALID [2022-02-20 17:56:12,140 INFO L290 TraceCheckUtils]: 96: Hoare triple {14749#false} assume { :begin_inline_outgoing__wrappee__Keys } true;outgoing__wrappee__Keys_#in~client#1, outgoing__wrappee__Keys_#in~msg#1 := outgoing__wrappee__AutoResponder_~client#1, outgoing__wrappee__AutoResponder_~msg#1;havoc outgoing__wrappee__Keys_#t~ret62#1, outgoing__wrappee__Keys_~client#1, outgoing__wrappee__Keys_~msg#1, outgoing__wrappee__Keys_~tmp~10#1;outgoing__wrappee__Keys_~client#1 := outgoing__wrappee__Keys_#in~client#1;outgoing__wrappee__Keys_~msg#1 := outgoing__wrappee__Keys_#in~msg#1;havoc outgoing__wrappee__Keys_~tmp~10#1;assume { :begin_inline_getClientId } true;getClientId_#in~handle#1 := outgoing__wrappee__Keys_~client#1;havoc getClientId_#res#1;havoc getClientId_~handle#1, getClientId_~retValue_acc~31#1;getClientId_~handle#1 := getClientId_#in~handle#1;havoc getClientId_~retValue_acc~31#1; {14749#false} is VALID [2022-02-20 17:56:12,140 INFO L290 TraceCheckUtils]: 97: Hoare triple {14749#false} assume 1 == getClientId_~handle#1;getClientId_~retValue_acc~31#1 := ~__ste_client_idCounter0~0;getClientId_#res#1 := getClientId_~retValue_acc~31#1; {14749#false} is VALID [2022-02-20 17:56:12,140 INFO L290 TraceCheckUtils]: 98: Hoare triple {14749#false} outgoing__wrappee__Keys_#t~ret62#1 := getClientId_#res#1;assume { :end_inline_getClientId } true;assume -2147483648 <= outgoing__wrappee__Keys_#t~ret62#1 && outgoing__wrappee__Keys_#t~ret62#1 <= 2147483647;outgoing__wrappee__Keys_~tmp~10#1 := outgoing__wrappee__Keys_#t~ret62#1;havoc outgoing__wrappee__Keys_#t~ret62#1; {14749#false} is VALID [2022-02-20 17:56:12,140 INFO L272 TraceCheckUtils]: 99: Hoare triple {14749#false} call setEmailFrom(outgoing__wrappee__Keys_~msg#1, outgoing__wrappee__Keys_~tmp~10#1); {14810#(and (= |old(~__ste_email_from0~0)| ~__ste_email_from0~0) (= |old(~__ste_email_from1~0)| ~__ste_email_from1~0))} is VALID [2022-02-20 17:56:12,140 INFO L290 TraceCheckUtils]: 100: Hoare triple {14810#(and (= |old(~__ste_email_from0~0)| ~__ste_email_from0~0) (= |old(~__ste_email_from1~0)| ~__ste_email_from1~0))} ~handle := #in~handle;~value := #in~value; {14748#true} is VALID [2022-02-20 17:56:12,140 INFO L290 TraceCheckUtils]: 101: Hoare triple {14748#true} assume 1 == ~handle;~__ste_email_from0~0 := ~value; {14748#true} is VALID [2022-02-20 17:56:12,140 INFO L290 TraceCheckUtils]: 102: Hoare triple {14748#true} assume true; {14748#true} is VALID [2022-02-20 17:56:12,140 INFO L284 TraceCheckUtils]: 103: Hoare quadruple {14748#true} {14749#false} #1063#return; {14749#false} is VALID [2022-02-20 17:56:12,141 INFO L290 TraceCheckUtils]: 104: Hoare triple {14749#false} assume { :begin_inline_mail } true;mail_#in~client#1, mail_#in~msg#1 := outgoing__wrappee__Keys_~client#1, outgoing__wrappee__Keys_~msg#1;havoc mail_#t~ret60#1, mail_#t~ret61#1, mail_~client#1, mail_~msg#1, mail_~__utac__ad__arg1~0#1, mail_~__utac__ad__arg2~0#1, mail_~tmp~9#1;mail_~client#1 := mail_#in~client#1;mail_~msg#1 := mail_#in~msg#1;havoc mail_~__utac__ad__arg1~0#1;havoc mail_~__utac__ad__arg2~0#1;havoc mail_~tmp~9#1;mail_~__utac__ad__arg1~0#1 := mail_~client#1;mail_~__utac__ad__arg2~0#1 := mail_~msg#1;assume { :begin_inline___utac_acc__AddressBookEncrypt_spec__1 } true;__utac_acc__AddressBookEncrypt_spec__1_#in~client#1, __utac_acc__AddressBookEncrypt_spec__1_#in~msg#1 := mail_~__utac__ad__arg1~0#1, mail_~__utac__ad__arg2~0#1;havoc __utac_acc__AddressBookEncrypt_spec__1_#t~ret85#1, __utac_acc__AddressBookEncrypt_spec__1_#t~ret86#1, __utac_acc__AddressBookEncrypt_spec__1_#t~ret87#1, __utac_acc__AddressBookEncrypt_spec__1_~client#1, __utac_acc__AddressBookEncrypt_spec__1_~msg#1, __utac_acc__AddressBookEncrypt_spec__1_~tmp~20#1;__utac_acc__AddressBookEncrypt_spec__1_~client#1 := __utac_acc__AddressBookEncrypt_spec__1_#in~client#1;__utac_acc__AddressBookEncrypt_spec__1_~msg#1 := __utac_acc__AddressBookEncrypt_spec__1_#in~msg#1;havoc __utac_acc__AddressBookEncrypt_spec__1_~tmp~20#1;call __utac_acc__AddressBookEncrypt_spec__1_#t~ret85#1 := puts(31, 0);assume -2147483648 <= __utac_acc__AddressBookEncrypt_spec__1_#t~ret85#1 && __utac_acc__AddressBookEncrypt_spec__1_#t~ret85#1 <= 2147483647;havoc __utac_acc__AddressBookEncrypt_spec__1_#t~ret85#1; {14749#false} is VALID [2022-02-20 17:56:12,141 INFO L290 TraceCheckUtils]: 105: Hoare triple {14749#false} assume !(-1 == ~mail_is_sensitive~0); {14749#false} is VALID [2022-02-20 17:56:12,141 INFO L272 TraceCheckUtils]: 106: Hoare triple {14749#false} call __utac_acc__AddressBookEncrypt_spec__1_#t~ret87#1 := isEncrypted(__utac_acc__AddressBookEncrypt_spec__1_~msg#1); {14748#true} is VALID [2022-02-20 17:56:12,141 INFO L290 TraceCheckUtils]: 107: Hoare triple {14748#true} ~handle := #in~handle;havoc ~retValue_acc~39; {14748#true} is VALID [2022-02-20 17:56:12,141 INFO L290 TraceCheckUtils]: 108: Hoare triple {14748#true} assume 1 == ~handle;~retValue_acc~39 := ~__ste_email_isEncrypted0~0;#res := ~retValue_acc~39; {14748#true} is VALID [2022-02-20 17:56:12,141 INFO L290 TraceCheckUtils]: 109: Hoare triple {14748#true} assume true; {14748#true} is VALID [2022-02-20 17:56:12,141 INFO L284 TraceCheckUtils]: 110: Hoare quadruple {14748#true} {14749#false} #1067#return; {14749#false} is VALID [2022-02-20 17:56:12,141 INFO L290 TraceCheckUtils]: 111: Hoare triple {14749#false} assume -2147483648 <= __utac_acc__AddressBookEncrypt_spec__1_#t~ret87#1 && __utac_acc__AddressBookEncrypt_spec__1_#t~ret87#1 <= 2147483647;__utac_acc__AddressBookEncrypt_spec__1_~tmp~20#1 := __utac_acc__AddressBookEncrypt_spec__1_#t~ret87#1;havoc __utac_acc__AddressBookEncrypt_spec__1_#t~ret87#1; {14749#false} is VALID [2022-02-20 17:56:12,142 INFO L290 TraceCheckUtils]: 112: Hoare triple {14749#false} assume ~mail_is_sensitive~0 != __utac_acc__AddressBookEncrypt_spec__1_~tmp~20#1;assume { :begin_inline___automaton_fail } true; {14749#false} is VALID [2022-02-20 17:56:12,142 INFO L290 TraceCheckUtils]: 113: Hoare triple {14749#false} assume !false; {14749#false} is VALID [2022-02-20 17:56:12,142 INFO L134 CoverageAnalysis]: Checked inductivity of 30 backedges. 6 proven. 0 refuted. 0 times theorem prover too weak. 24 trivial. 0 not checked. [2022-02-20 17:56:12,142 INFO L144 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2022-02-20 17:56:12,142 INFO L338 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [997791432] [2022-02-20 17:56:12,143 INFO L165 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [997791432] provided 1 perfect and 0 imperfect interpolant sequences [2022-02-20 17:56:12,143 INFO L191 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2022-02-20 17:56:12,143 INFO L204 FreeRefinementEngine]: Number of different interpolants: perfect sequences [9] imperfect sequences [] total 9 [2022-02-20 17:56:12,143 INFO L118 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [313742302] [2022-02-20 17:56:12,143 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2022-02-20 17:56:12,144 INFO L78 Accepts]: Start accepts. Automaton has has 9 states, 8 states have (on average 9.375) internal successors, (75), 5 states have internal predecessors, (75), 3 states have call successors, (15), 6 states have call predecessors, (15), 2 states have return successors, (13), 2 states have call predecessors, (13), 3 states have call successors, (13) Word has length 114 [2022-02-20 17:56:12,144 INFO L84 Accepts]: Finished accepts. word is accepted. [2022-02-20 17:56:12,144 INFO L86 InductivityCheck]: Starting indutivity check of a Floyd-Hoare automaton with has 9 states, 8 states have (on average 9.375) internal successors, (75), 5 states have internal predecessors, (75), 3 states have call successors, (15), 6 states have call predecessors, (15), 2 states have return successors, (13), 2 states have call predecessors, (13), 3 states have call successors, (13) [2022-02-20 17:56:12,201 INFO L122 InductivityCheck]: Floyd-Hoare automaton has 103 edges. 103 inductive. 0 not inductive. 0 times theorem prover too weak to decide inductivity. [2022-02-20 17:56:12,202 INFO L546 AbstractCegarLoop]: INTERPOLANT automaton has 9 states [2022-02-20 17:56:12,202 INFO L108 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2022-02-20 17:56:12,202 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 9 interpolants. [2022-02-20 17:56:12,202 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=15, Invalid=57, Unknown=0, NotChecked=0, Total=72 [2022-02-20 17:56:12,202 INFO L87 Difference]: Start difference. First operand 441 states and 666 transitions. Second operand has 9 states, 8 states have (on average 9.375) internal successors, (75), 5 states have internal predecessors, (75), 3 states have call successors, (15), 6 states have call predecessors, (15), 2 states have return successors, (13), 2 states have call predecessors, (13), 3 states have call successors, (13) [2022-02-20 17:56:19,804 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-02-20 17:56:19,804 INFO L93 Difference]: Finished difference Result 1073 states and 1630 transitions. [2022-02-20 17:56:19,804 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 11 states. [2022-02-20 17:56:19,805 INFO L78 Accepts]: Start accepts. Automaton has has 9 states, 8 states have (on average 9.375) internal successors, (75), 5 states have internal predecessors, (75), 3 states have call successors, (15), 6 states have call predecessors, (15), 2 states have return successors, (13), 2 states have call predecessors, (13), 3 states have call successors, (13) Word has length 114 [2022-02-20 17:56:19,805 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2022-02-20 17:56:19,805 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 9 states, 8 states have (on average 9.375) internal successors, (75), 5 states have internal predecessors, (75), 3 states have call successors, (15), 6 states have call predecessors, (15), 2 states have return successors, (13), 2 states have call predecessors, (13), 3 states have call successors, (13) [2022-02-20 17:56:19,819 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 11 states to 11 states and 1428 transitions. [2022-02-20 17:56:19,819 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 9 states, 8 states have (on average 9.375) internal successors, (75), 5 states have internal predecessors, (75), 3 states have call successors, (15), 6 states have call predecessors, (15), 2 states have return successors, (13), 2 states have call predecessors, (13), 3 states have call successors, (13) [2022-02-20 17:56:19,841 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 11 states to 11 states and 1428 transitions. [2022-02-20 17:56:19,841 INFO L86 InductivityCheck]: Starting indutivity check of a Floyd-Hoare automaton with 11 states and 1428 transitions. [2022-02-20 17:56:20,937 INFO L122 InductivityCheck]: Floyd-Hoare automaton has 1428 edges. 1428 inductive. 0 not inductive. 0 times theorem prover too weak to decide inductivity. [2022-02-20 17:56:20,958 INFO L225 Difference]: With dead ends: 1073 [2022-02-20 17:56:20,958 INFO L226 Difference]: Without dead ends: 655 [2022-02-20 17:56:20,959 INFO L932 BasicCegarLoop]: 0 DeclaredPredicates, 44 GetRequests, 29 SyntacticMatches, 0 SemanticMatches, 15 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 31 ImplicationChecksByTransitivity, 0.1s TimeCoverageRelationStatistics Valid=73, Invalid=199, Unknown=0, NotChecked=0, Total=272 [2022-02-20 17:56:20,960 INFO L933 BasicCegarLoop]: 717 mSDtfsCounter, 1383 mSDsluCounter, 863 mSDsCounter, 0 mSdLazyCounter, 2612 mSolverCounterSat, 589 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 3.5s Time, 0 mProtectedPredicate, 0 mProtectedAction, 1400 SdHoareTripleChecker+Valid, 1580 SdHoareTripleChecker+Invalid, 3201 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 589 IncrementalHoareTripleChecker+Valid, 2612 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 3.5s IncrementalHoareTripleChecker+Time [2022-02-20 17:56:20,960 INFO L934 BasicCegarLoop]: SdHoareTripleChecker [1400 Valid, 1580 Invalid, 3201 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [589 Valid, 2612 Invalid, 0 Unknown, 0 Unchecked, 3.5s Time] [2022-02-20 17:56:20,961 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 655 states. [2022-02-20 17:56:21,067 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 655 to 441. [2022-02-20 17:56:21,067 INFO L214 AbstractMinimizeNwa]: Start testing correctness of minimizeSevpa [2022-02-20 17:56:21,068 INFO L82 GeneralOperation]: Start isEquivalent. First operand 655 states. Second operand has 441 states, 340 states have (on average 1.5058823529411764) internal successors, (512), 345 states have internal predecessors, (512), 74 states have call successors, (74), 24 states have call predecessors, (74), 26 states have return successors, (79), 73 states have call predecessors, (79), 73 states have call successors, (79) [2022-02-20 17:56:21,069 INFO L74 IsIncluded]: Start isIncluded. First operand 655 states. Second operand has 441 states, 340 states have (on average 1.5058823529411764) internal successors, (512), 345 states have internal predecessors, (512), 74 states have call successors, (74), 24 states have call predecessors, (74), 26 states have return successors, (79), 73 states have call predecessors, (79), 73 states have call successors, (79) [2022-02-20 17:56:21,070 INFO L87 Difference]: Start difference. First operand 655 states. Second operand has 441 states, 340 states have (on average 1.5058823529411764) internal successors, (512), 345 states have internal predecessors, (512), 74 states have call successors, (74), 24 states have call predecessors, (74), 26 states have return successors, (79), 73 states have call predecessors, (79), 73 states have call successors, (79) [2022-02-20 17:56:21,087 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-02-20 17:56:21,088 INFO L93 Difference]: Finished difference Result 655 states and 995 transitions. [2022-02-20 17:56:21,088 INFO L276 IsEmpty]: Start isEmpty. Operand 655 states and 995 transitions. [2022-02-20 17:56:21,090 INFO L282 IsEmpty]: Finished isEmpty. No accepting run. [2022-02-20 17:56:21,091 INFO L83 IsIncluded]: Finished isIncluded. Language is included [2022-02-20 17:56:21,092 INFO L74 IsIncluded]: Start isIncluded. First operand has 441 states, 340 states have (on average 1.5058823529411764) internal successors, (512), 345 states have internal predecessors, (512), 74 states have call successors, (74), 24 states have call predecessors, (74), 26 states have return successors, (79), 73 states have call predecessors, (79), 73 states have call successors, (79) Second operand 655 states. [2022-02-20 17:56:21,092 INFO L87 Difference]: Start difference. First operand has 441 states, 340 states have (on average 1.5058823529411764) internal successors, (512), 345 states have internal predecessors, (512), 74 states have call successors, (74), 24 states have call predecessors, (74), 26 states have return successors, (79), 73 states have call predecessors, (79), 73 states have call successors, (79) Second operand 655 states. [2022-02-20 17:56:21,109 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-02-20 17:56:21,110 INFO L93 Difference]: Finished difference Result 655 states and 995 transitions. [2022-02-20 17:56:21,110 INFO L276 IsEmpty]: Start isEmpty. Operand 655 states and 995 transitions. [2022-02-20 17:56:21,112 INFO L282 IsEmpty]: Finished isEmpty. No accepting run. [2022-02-20 17:56:21,113 INFO L83 IsIncluded]: Finished isIncluded. Language is included [2022-02-20 17:56:21,113 INFO L88 GeneralOperation]: Finished isEquivalent. [2022-02-20 17:56:21,113 INFO L221 AbstractMinimizeNwa]: Finished testing correctness of minimizeSevpa [2022-02-20 17:56:21,114 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 441 states, 340 states have (on average 1.5058823529411764) internal successors, (512), 345 states have internal predecessors, (512), 74 states have call successors, (74), 24 states have call predecessors, (74), 26 states have return successors, (79), 73 states have call predecessors, (79), 73 states have call successors, (79) [2022-02-20 17:56:21,125 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 441 states to 441 states and 665 transitions. [2022-02-20 17:56:21,126 INFO L78 Accepts]: Start accepts. Automaton has 441 states and 665 transitions. Word has length 114 [2022-02-20 17:56:21,126 INFO L84 Accepts]: Finished accepts. word is rejected. [2022-02-20 17:56:21,126 INFO L470 AbstractCegarLoop]: Abstraction has 441 states and 665 transitions. [2022-02-20 17:56:21,126 INFO L471 AbstractCegarLoop]: INTERPOLANT automaton has has 9 states, 8 states have (on average 9.375) internal successors, (75), 5 states have internal predecessors, (75), 3 states have call successors, (15), 6 states have call predecessors, (15), 2 states have return successors, (13), 2 states have call predecessors, (13), 3 states have call successors, (13) [2022-02-20 17:56:21,126 INFO L276 IsEmpty]: Start isEmpty. Operand 441 states and 665 transitions. [2022-02-20 17:56:21,127 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 116 [2022-02-20 17:56:21,128 INFO L506 BasicCegarLoop]: Found error trace [2022-02-20 17:56:21,128 INFO L514 BasicCegarLoop]: trace histogram [3, 3, 3, 3, 2, 2, 2, 2, 2, 2, 2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-02-20 17:56:21,128 WARN L452 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable5 [2022-02-20 17:56:21,128 INFO L402 AbstractCegarLoop]: === Iteration 7 === Targeting outgoingErr0ASSERT_VIOLATIONERROR_FUNCTION === [outgoingErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2022-02-20 17:56:21,128 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2022-02-20 17:56:21,128 INFO L85 PathProgramCache]: Analyzing trace with hash -30350357, now seen corresponding path program 2 times [2022-02-20 17:56:21,129 INFO L126 FreeRefinementEngine]: Executing refinement strategy CAMEL [2022-02-20 17:56:21,129 INFO L338 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [1454409004] [2022-02-20 17:56:21,129 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-02-20 17:56:21,129 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2022-02-20 17:56:21,153 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-02-20 17:56:21,173 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 6 [2022-02-20 17:56:21,174 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-02-20 17:56:21,175 INFO L290 TraceCheckUtils]: 0: Hoare triple {18369#(and (= |old(~__ste_client_idCounter0~0)| ~__ste_client_idCounter0~0) (= |old(~__ste_client_idCounter1~0)| ~__ste_client_idCounter1~0) (= |old(~__ste_client_idCounter2~0)| ~__ste_client_idCounter2~0))} ~handle := #in~handle;~value := #in~value; {18310#true} is VALID [2022-02-20 17:56:21,176 INFO L290 TraceCheckUtils]: 1: Hoare triple {18310#true} assume 1 == ~handle;~__ste_client_idCounter0~0 := ~value; {18310#true} is VALID [2022-02-20 17:56:21,176 INFO L290 TraceCheckUtils]: 2: Hoare triple {18310#true} assume true; {18310#true} is VALID [2022-02-20 17:56:21,176 INFO L284 TraceCheckUtils]: 3: Hoare quadruple {18310#true} {18310#true} #1133#return; {18310#true} is VALID [2022-02-20 17:56:21,180 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 12 [2022-02-20 17:56:21,181 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-02-20 17:56:21,183 INFO L290 TraceCheckUtils]: 0: Hoare triple {18370#(and (= ~__ste_client_privateKey0~0 |old(~__ste_client_privateKey0~0)|) (= ~__ste_client_privateKey2~0 |old(~__ste_client_privateKey2~0)|) (= ~__ste_client_privateKey1~0 |old(~__ste_client_privateKey1~0)|))} ~handle := #in~handle;~value := #in~value; {18310#true} is VALID [2022-02-20 17:56:21,183 INFO L290 TraceCheckUtils]: 1: Hoare triple {18310#true} assume 1 == ~handle;~__ste_client_privateKey0~0 := ~value; {18310#true} is VALID [2022-02-20 17:56:21,183 INFO L290 TraceCheckUtils]: 2: Hoare triple {18310#true} assume true; {18310#true} is VALID [2022-02-20 17:56:21,184 INFO L284 TraceCheckUtils]: 3: Hoare quadruple {18310#true} {18310#true} #1135#return; {18310#true} is VALID [2022-02-20 17:56:21,184 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 18 [2022-02-20 17:56:21,185 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-02-20 17:56:21,187 INFO L290 TraceCheckUtils]: 0: Hoare triple {18369#(and (= |old(~__ste_client_idCounter0~0)| ~__ste_client_idCounter0~0) (= |old(~__ste_client_idCounter1~0)| ~__ste_client_idCounter1~0) (= |old(~__ste_client_idCounter2~0)| ~__ste_client_idCounter2~0))} ~handle := #in~handle;~value := #in~value; {18310#true} is VALID [2022-02-20 17:56:21,187 INFO L290 TraceCheckUtils]: 1: Hoare triple {18310#true} assume !(1 == ~handle); {18310#true} is VALID [2022-02-20 17:56:21,187 INFO L290 TraceCheckUtils]: 2: Hoare triple {18310#true} assume 2 == ~handle;~__ste_client_idCounter1~0 := ~value; {18310#true} is VALID [2022-02-20 17:56:21,187 INFO L290 TraceCheckUtils]: 3: Hoare triple {18310#true} assume true; {18310#true} is VALID [2022-02-20 17:56:21,187 INFO L284 TraceCheckUtils]: 4: Hoare quadruple {18310#true} {18310#true} #1137#return; {18310#true} is VALID [2022-02-20 17:56:21,187 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 25 [2022-02-20 17:56:21,188 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-02-20 17:56:21,191 INFO L290 TraceCheckUtils]: 0: Hoare triple {18370#(and (= ~__ste_client_privateKey0~0 |old(~__ste_client_privateKey0~0)|) (= ~__ste_client_privateKey2~0 |old(~__ste_client_privateKey2~0)|) (= ~__ste_client_privateKey1~0 |old(~__ste_client_privateKey1~0)|))} ~handle := #in~handle;~value := #in~value; {18310#true} is VALID [2022-02-20 17:56:21,191 INFO L290 TraceCheckUtils]: 1: Hoare triple {18310#true} assume !(1 == ~handle); {18310#true} is VALID [2022-02-20 17:56:21,191 INFO L290 TraceCheckUtils]: 2: Hoare triple {18310#true} assume 2 == ~handle;~__ste_client_privateKey1~0 := ~value; {18310#true} is VALID [2022-02-20 17:56:21,191 INFO L290 TraceCheckUtils]: 3: Hoare triple {18310#true} assume true; {18310#true} is VALID [2022-02-20 17:56:21,191 INFO L284 TraceCheckUtils]: 4: Hoare quadruple {18310#true} {18310#true} #1139#return; {18310#true} is VALID [2022-02-20 17:56:21,191 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 32 [2022-02-20 17:56:21,193 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-02-20 17:56:21,204 INFO L290 TraceCheckUtils]: 0: Hoare triple {18369#(and (= |old(~__ste_client_idCounter0~0)| ~__ste_client_idCounter0~0) (= |old(~__ste_client_idCounter1~0)| ~__ste_client_idCounter1~0) (= |old(~__ste_client_idCounter2~0)| ~__ste_client_idCounter2~0))} ~handle := #in~handle;~value := #in~value; {18371#(= setClientId_~handle |setClientId_#in~handle|)} is VALID [2022-02-20 17:56:21,204 INFO L290 TraceCheckUtils]: 1: Hoare triple {18371#(= setClientId_~handle |setClientId_#in~handle|)} assume !(1 == ~handle); {18371#(= setClientId_~handle |setClientId_#in~handle|)} is VALID [2022-02-20 17:56:21,205 INFO L290 TraceCheckUtils]: 2: Hoare triple {18371#(= setClientId_~handle |setClientId_#in~handle|)} assume 2 == ~handle;~__ste_client_idCounter1~0 := ~value; {18372#(= 2 |setClientId_#in~handle|)} is VALID [2022-02-20 17:56:21,205 INFO L290 TraceCheckUtils]: 3: Hoare triple {18372#(= 2 |setClientId_#in~handle|)} assume true; {18372#(= 2 |setClientId_#in~handle|)} is VALID [2022-02-20 17:56:21,205 INFO L284 TraceCheckUtils]: 4: Hoare quadruple {18372#(= 2 |setClientId_#in~handle|)} {18330#(= 3 |ULTIMATE.start_setup_chuck__wrappee__Base_~chuck___0#1|)} #1141#return; {18311#false} is VALID [2022-02-20 17:56:21,206 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 39 [2022-02-20 17:56:21,207 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-02-20 17:56:21,209 INFO L290 TraceCheckUtils]: 0: Hoare triple {18370#(and (= ~__ste_client_privateKey0~0 |old(~__ste_client_privateKey0~0)|) (= ~__ste_client_privateKey2~0 |old(~__ste_client_privateKey2~0)|) (= ~__ste_client_privateKey1~0 |old(~__ste_client_privateKey1~0)|))} ~handle := #in~handle;~value := #in~value; {18310#true} is VALID [2022-02-20 17:56:21,209 INFO L290 TraceCheckUtils]: 1: Hoare triple {18310#true} assume 1 == ~handle;~__ste_client_privateKey0~0 := ~value; {18310#true} is VALID [2022-02-20 17:56:21,209 INFO L290 TraceCheckUtils]: 2: Hoare triple {18310#true} assume true; {18310#true} is VALID [2022-02-20 17:56:21,209 INFO L284 TraceCheckUtils]: 3: Hoare quadruple {18310#true} {18311#false} #1143#return; {18311#false} is VALID [2022-02-20 17:56:21,214 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 61 [2022-02-20 17:56:21,215 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-02-20 17:56:21,217 INFO L290 TraceCheckUtils]: 0: Hoare triple {18373#(and (= |old(~__ste_email_from0~0)| ~__ste_email_from0~0) (= |old(~__ste_email_from1~0)| ~__ste_email_from1~0))} ~handle := #in~handle;~value := #in~value; {18310#true} is VALID [2022-02-20 17:56:21,217 INFO L290 TraceCheckUtils]: 1: Hoare triple {18310#true} assume 1 == ~handle;~__ste_email_from0~0 := ~value; {18310#true} is VALID [2022-02-20 17:56:21,217 INFO L290 TraceCheckUtils]: 2: Hoare triple {18310#true} assume true; {18310#true} is VALID [2022-02-20 17:56:21,217 INFO L284 TraceCheckUtils]: 3: Hoare quadruple {18310#true} {18311#false} #1119#return; {18311#false} is VALID [2022-02-20 17:56:21,222 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 66 [2022-02-20 17:56:21,223 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-02-20 17:56:21,225 INFO L290 TraceCheckUtils]: 0: Hoare triple {18374#(and (= ~__ste_email_to0~0 |old(~__ste_email_to0~0)|) (= ~__ste_email_to1~0 |old(~__ste_email_to1~0)|))} ~handle := #in~handle;~value := #in~value; {18310#true} is VALID [2022-02-20 17:56:21,226 INFO L290 TraceCheckUtils]: 1: Hoare triple {18310#true} assume 1 == ~handle;~__ste_email_to0~0 := ~value; {18310#true} is VALID [2022-02-20 17:56:21,226 INFO L290 TraceCheckUtils]: 2: Hoare triple {18310#true} assume true; {18310#true} is VALID [2022-02-20 17:56:21,226 INFO L284 TraceCheckUtils]: 3: Hoare quadruple {18310#true} {18311#false} #1121#return; {18311#false} is VALID [2022-02-20 17:56:21,226 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 75 [2022-02-20 17:56:21,227 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-02-20 17:56:21,229 INFO L290 TraceCheckUtils]: 0: Hoare triple {18310#true} ~handle := #in~handle;havoc ~retValue_acc~24; {18310#true} is VALID [2022-02-20 17:56:21,229 INFO L290 TraceCheckUtils]: 1: Hoare triple {18310#true} assume 1 == ~handle;~retValue_acc~24 := ~__ste_client_privateKey0~0;#res := ~retValue_acc~24; {18310#true} is VALID [2022-02-20 17:56:21,229 INFO L290 TraceCheckUtils]: 2: Hoare triple {18310#true} assume true; {18310#true} is VALID [2022-02-20 17:56:21,229 INFO L284 TraceCheckUtils]: 3: Hoare quadruple {18310#true} {18311#false} #1053#return; {18311#false} is VALID [2022-02-20 17:56:21,230 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 83 [2022-02-20 17:56:21,230 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-02-20 17:56:21,232 INFO L290 TraceCheckUtils]: 0: Hoare triple {18310#true} ~handle := #in~handle;havoc ~retValue_acc~36; {18310#true} is VALID [2022-02-20 17:56:21,232 INFO L290 TraceCheckUtils]: 1: Hoare triple {18310#true} assume 1 == ~handle;~retValue_acc~36 := ~__ste_email_to0~0;#res := ~retValue_acc~36; {18310#true} is VALID [2022-02-20 17:56:21,232 INFO L290 TraceCheckUtils]: 2: Hoare triple {18310#true} assume true; {18310#true} is VALID [2022-02-20 17:56:21,232 INFO L284 TraceCheckUtils]: 3: Hoare quadruple {18310#true} {18311#false} #1055#return; {18311#false} is VALID [2022-02-20 17:56:21,232 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 89 [2022-02-20 17:56:21,233 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-02-20 17:56:21,234 INFO L290 TraceCheckUtils]: 0: Hoare triple {18310#true} ~handle := #in~handle;~userid := #in~userid;havoc ~retValue_acc~29; {18310#true} is VALID [2022-02-20 17:56:21,234 INFO L290 TraceCheckUtils]: 1: Hoare triple {18310#true} assume 1 == ~handle; {18310#true} is VALID [2022-02-20 17:56:21,235 INFO L290 TraceCheckUtils]: 2: Hoare triple {18310#true} assume ~userid == ~__ste_Client_Keyring0_User0~0;~retValue_acc~29 := ~__ste_Client_Keyring0_PublicKey0~0;#res := ~retValue_acc~29; {18310#true} is VALID [2022-02-20 17:56:21,235 INFO L290 TraceCheckUtils]: 3: Hoare triple {18310#true} assume true; {18310#true} is VALID [2022-02-20 17:56:21,235 INFO L284 TraceCheckUtils]: 4: Hoare quadruple {18310#true} {18311#false} #1057#return; {18311#false} is VALID [2022-02-20 17:56:21,235 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 100 [2022-02-20 17:56:21,240 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-02-20 17:56:21,243 INFO L290 TraceCheckUtils]: 0: Hoare triple {18373#(and (= |old(~__ste_email_from0~0)| ~__ste_email_from0~0) (= |old(~__ste_email_from1~0)| ~__ste_email_from1~0))} ~handle := #in~handle;~value := #in~value; {18310#true} is VALID [2022-02-20 17:56:21,243 INFO L290 TraceCheckUtils]: 1: Hoare triple {18310#true} assume 1 == ~handle;~__ste_email_from0~0 := ~value; {18310#true} is VALID [2022-02-20 17:56:21,243 INFO L290 TraceCheckUtils]: 2: Hoare triple {18310#true} assume true; {18310#true} is VALID [2022-02-20 17:56:21,243 INFO L284 TraceCheckUtils]: 3: Hoare quadruple {18310#true} {18311#false} #1063#return; {18311#false} is VALID [2022-02-20 17:56:21,243 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 107 [2022-02-20 17:56:21,244 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-02-20 17:56:21,245 INFO L290 TraceCheckUtils]: 0: Hoare triple {18310#true} ~handle := #in~handle;havoc ~retValue_acc~39; {18310#true} is VALID [2022-02-20 17:56:21,246 INFO L290 TraceCheckUtils]: 1: Hoare triple {18310#true} assume 1 == ~handle;~retValue_acc~39 := ~__ste_email_isEncrypted0~0;#res := ~retValue_acc~39; {18310#true} is VALID [2022-02-20 17:56:21,246 INFO L290 TraceCheckUtils]: 2: Hoare triple {18310#true} assume true; {18310#true} is VALID [2022-02-20 17:56:21,246 INFO L284 TraceCheckUtils]: 3: Hoare quadruple {18310#true} {18311#false} #1067#return; {18311#false} is VALID [2022-02-20 17:56:21,246 INFO L290 TraceCheckUtils]: 0: Hoare triple {18310#true} assume { :begin_inline_ULTIMATE.init } true;#NULL.base, #NULL.offset := 0, 0;assume 0 == #valid[0];assume 0 < #StackHeapBarrier;call #Ultimate.allocInit(2, 1);call write~init~int(48, 1, 0, 1);call write~init~int(0, 1, 1, 1);call #Ultimate.allocInit(28, 2);call #Ultimate.allocInit(12, 3);call #Ultimate.allocInit(4, 4);call write~init~int(37, 4, 0, 1);call write~init~int(115, 4, 1, 1);call write~init~int(10, 4, 2, 1);call write~init~int(0, 4, 3, 1);call #Ultimate.allocInit(10, 5);call #Ultimate.allocInit(12, 6);call #Ultimate.allocInit(10, 7);call #Ultimate.allocInit(18, 8);call #Ultimate.allocInit(16, 9);call #Ultimate.allocInit(21, 10);call #Ultimate.allocInit(13, 11);call #Ultimate.allocInit(16, 12);call #Ultimate.allocInit(25, 13);call #Ultimate.allocInit(30, 14);call #Ultimate.allocInit(9, 15);call #Ultimate.allocInit(21, 16);call #Ultimate.allocInit(30, 17);call #Ultimate.allocInit(9, 18);call #Ultimate.allocInit(21, 19);call #Ultimate.allocInit(30, 20);call #Ultimate.allocInit(9, 21);call #Ultimate.allocInit(25, 22);call #Ultimate.allocInit(30, 23);call #Ultimate.allocInit(9, 24);call #Ultimate.allocInit(25, 25);call #Ultimate.allocInit(10, 26);call #Ultimate.allocInit(16, 27);call #Ultimate.allocInit(20, 28);call #Ultimate.allocInit(22, 29);call #Ultimate.allocInit(21, 30);call #Ultimate.allocInit(13, 31);call #Ultimate.allocInit(44, 32);call #Ultimate.allocInit(44, 33);call #Ultimate.allocInit(9, 34);call #Ultimate.allocInit(9, 35);call #Ultimate.allocInit(11, 36);call #Ultimate.allocInit(19, 37);call #Ultimate.allocInit(4, 38);call write~init~int(37, 38, 0, 1);call write~init~int(100, 38, 1, 1);call write~init~int(10, 38, 2, 1);call write~init~int(0, 38, 3, 1);call #Ultimate.allocInit(4, 39);call write~init~int(37, 39, 0, 1);call write~init~int(100, 39, 1, 1);call write~init~int(10, 39, 2, 1);call write~init~int(0, 39, 3, 1);~__SELECTED_FEATURE_Base~0 := 0;~__SELECTED_FEATURE_Keys~0 := 0;~__SELECTED_FEATURE_Encrypt~0 := 0;~__SELECTED_FEATURE_AutoResponder~0 := 0;~__SELECTED_FEATURE_AddressBook~0 := 0;~__SELECTED_FEATURE_Sign~0 := 0;~__SELECTED_FEATURE_Forward~0 := 0;~__SELECTED_FEATURE_Verify~0 := 0;~__SELECTED_FEATURE_Decrypt~0 := 0;~__GUIDSL_ROOT_PRODUCTION~0 := 0;~__GUIDSL_NON_TERMINAL_main~0 := 0;~head~0.base, ~head~0.offset := 0, 0;~queue_empty~0 := 1;~queued_message~0 := 0;~queued_client~0 := 0;~mail_is_sensitive~0 := -1;~__ste_Client_counter~0 := 0;~__ste_client_name0~0.base, ~__ste_client_name0~0.offset := 0, 0;~__ste_client_name1~0.base, ~__ste_client_name1~0.offset := 0, 0;~__ste_client_name2~0.base, ~__ste_client_name2~0.offset := 0, 0;~__ste_client_outbuffer0~0 := 0;~__ste_client_outbuffer1~0 := 0;~__ste_client_outbuffer2~0 := 0;~__ste_client_outbuffer3~0 := 0;~__ste_ClientAddressBook_size0~0 := 0;~__ste_ClientAddressBook_size1~0 := 0;~__ste_ClientAddressBook_size2~0 := 0;~__ste_Client_AddressBook0_Alias0~0 := 0;~__ste_Client_AddressBook0_Alias1~0 := 0;~__ste_Client_AddressBook0_Alias2~0 := 0;~__ste_Client_AddressBook1_Alias0~0 := 0;~__ste_Client_AddressBook1_Alias1~0 := 0;~__ste_Client_AddressBook1_Alias2~0 := 0;~__ste_Client_AddressBook2_Alias0~0 := 0;~__ste_Client_AddressBook2_Alias1~0 := 0;~__ste_Client_AddressBook2_Alias2~0 := 0;~__ste_Client_AddressBook0_Address0~0 := 0;~__ste_Client_AddressBook0_Address1~0 := 0;~__ste_Client_AddressBook0_Address2~0 := 0;~__ste_Client_AddressBook1_Address0~0 := 0;~__ste_Client_AddressBook1_Address1~0 := 0;~__ste_Client_AddressBook1_Address2~0 := 0;~__ste_Client_AddressBook2_Address0~0 := 0;~__ste_Client_AddressBook2_Address1~0 := 0;~__ste_Client_AddressBook2_Address2~0 := 0;~__ste_client_autoResponse0~0 := 0;~__ste_client_autoResponse1~0 := 0;~__ste_client_autoResponse2~0 := 0;~__ste_client_privateKey0~0 := 0;~__ste_client_privateKey1~0 := 0;~__ste_client_privateKey2~0 := 0;~__ste_ClientKeyring_size0~0 := 0;~__ste_ClientKeyring_size1~0 := 0;~__ste_ClientKeyring_size2~0 := 0;~__ste_Client_Keyring0_User0~0 := 0;~__ste_Client_Keyring0_User1~0 := 0;~__ste_Client_Keyring0_User2~0 := 0;~__ste_Client_Keyring1_User0~0 := 0;~__ste_Client_Keyring1_User1~0 := 0;~__ste_Client_Keyring1_User2~0 := 0;~__ste_Client_Keyring2_User0~0 := 0;~__ste_Client_Keyring2_User1~0 := 0;~__ste_Client_Keyring2_User2~0 := 0;~__ste_Client_Keyring0_PublicKey0~0 := 0;~__ste_Client_Keyring0_PublicKey1~0 := 0;~__ste_Client_Keyring0_PublicKey2~0 := 0;~__ste_Client_Keyring1_PublicKey0~0 := 0;~__ste_Client_Keyring1_PublicKey1~0 := 0;~__ste_Client_Keyring1_PublicKey2~0 := 0;~__ste_Client_Keyring2_PublicKey0~0 := 0;~__ste_Client_Keyring2_PublicKey1~0 := 0;~__ste_Client_Keyring2_PublicKey2~0 := 0;~__ste_client_forwardReceiver0~0 := 0;~__ste_client_forwardReceiver1~0 := 0;~__ste_client_forwardReceiver2~0 := 0;~__ste_client_forwardReceiver3~0 := 0;~__ste_client_idCounter0~0 := 0;~__ste_client_idCounter1~0 := 0;~__ste_client_idCounter2~0 := 0;~bob~0 := 0;~rjh~0 := 0;~chuck~0 := 0;~__ste_Email_counter~0 := 0;~__ste_email_id0~0 := 0;~__ste_email_id1~0 := 0;~__ste_email_from0~0 := 0;~__ste_email_from1~0 := 0;~__ste_email_to0~0 := 0;~__ste_email_to1~0 := 0;~__ste_email_subject0~0.base, ~__ste_email_subject0~0.offset := 0, 0;~__ste_email_subject1~0.base, ~__ste_email_subject1~0.offset := 0, 0;~__ste_email_body0~0.base, ~__ste_email_body0~0.offset := 0, 0;~__ste_email_body1~0.base, ~__ste_email_body1~0.offset := 0, 0;~__ste_email_isEncrypted0~0 := 0;~__ste_email_isEncrypted1~0 := 0;~__ste_email_encryptionKey0~0 := 0;~__ste_email_encryptionKey1~0 := 0;~__ste_email_isSigned0~0 := 0;~__ste_email_isSigned1~0 := 0;~__ste_email_signKey0~0 := 0;~__ste_email_signKey1~0 := 0;~__ste_email_isSignatureVerified0~0 := 0;~__ste_email_isSignatureVerified1~0 := 0; {18310#true} is VALID [2022-02-20 17:56:21,246 INFO L290 TraceCheckUtils]: 1: Hoare triple {18310#true} assume { :end_inline_ULTIMATE.init } true;assume { :begin_inline_main } true;havoc main_#res#1;havoc main_#t~ret98#1, main_~retValue_acc~32#1, main_~tmp~24#1;havoc main_~retValue_acc~32#1;havoc main_~tmp~24#1;assume { :begin_inline_select_helpers } true; {18310#true} is VALID [2022-02-20 17:56:21,246 INFO L290 TraceCheckUtils]: 2: Hoare triple {18310#true} assume { :end_inline_select_helpers } true;assume { :begin_inline_select_features } true; {18310#true} is VALID [2022-02-20 17:56:21,246 INFO L290 TraceCheckUtils]: 3: Hoare triple {18310#true} assume { :end_inline_select_features } true;assume { :begin_inline_valid_product } true;havoc valid_product_#res#1;havoc valid_product_~retValue_acc~9#1;havoc valid_product_~retValue_acc~9#1;valid_product_~retValue_acc~9#1 := 1;valid_product_#res#1 := valid_product_~retValue_acc~9#1; {18310#true} is VALID [2022-02-20 17:56:21,246 INFO L290 TraceCheckUtils]: 4: Hoare triple {18310#true} main_#t~ret98#1 := valid_product_#res#1;assume { :end_inline_valid_product } true;assume -2147483648 <= main_#t~ret98#1 && main_#t~ret98#1 <= 2147483647;main_~tmp~24#1 := main_#t~ret98#1;havoc main_#t~ret98#1; {18310#true} is VALID [2022-02-20 17:56:21,246 INFO L290 TraceCheckUtils]: 5: Hoare triple {18310#true} assume 0 != main_~tmp~24#1;assume { :begin_inline_setup } true;havoc setup_#t~nondet95#1, setup_#t~nondet96#1, setup_#t~nondet97#1, setup_~__cil_tmp1~0#1.base, setup_~__cil_tmp1~0#1.offset, setup_~__cil_tmp2~0#1.base, setup_~__cil_tmp2~0#1.offset, setup_~__cil_tmp3~2#1.base, setup_~__cil_tmp3~2#1.offset;havoc setup_~__cil_tmp1~0#1.base, setup_~__cil_tmp1~0#1.offset;havoc setup_~__cil_tmp2~0#1.base, setup_~__cil_tmp2~0#1.offset;havoc setup_~__cil_tmp3~2#1.base, setup_~__cil_tmp3~2#1.offset;~bob~0 := 1;assume { :begin_inline_setup_bob } true;setup_bob_#in~bob___0#1 := ~bob~0;havoc setup_bob_~bob___0#1;setup_bob_~bob___0#1 := setup_bob_#in~bob___0#1;assume { :begin_inline_setup_bob__wrappee__Base } true;setup_bob__wrappee__Base_#in~bob___0#1 := setup_bob_~bob___0#1;havoc setup_bob__wrappee__Base_~bob___0#1;setup_bob__wrappee__Base_~bob___0#1 := setup_bob__wrappee__Base_#in~bob___0#1; {18310#true} is VALID [2022-02-20 17:56:21,247 INFO L272 TraceCheckUtils]: 6: Hoare triple {18310#true} call setClientId(setup_bob__wrappee__Base_~bob___0#1, setup_bob__wrappee__Base_~bob___0#1); {18369#(and (= |old(~__ste_client_idCounter0~0)| ~__ste_client_idCounter0~0) (= |old(~__ste_client_idCounter1~0)| ~__ste_client_idCounter1~0) (= |old(~__ste_client_idCounter2~0)| ~__ste_client_idCounter2~0))} is VALID [2022-02-20 17:56:21,247 INFO L290 TraceCheckUtils]: 7: Hoare triple {18369#(and (= |old(~__ste_client_idCounter0~0)| ~__ste_client_idCounter0~0) (= |old(~__ste_client_idCounter1~0)| ~__ste_client_idCounter1~0) (= |old(~__ste_client_idCounter2~0)| ~__ste_client_idCounter2~0))} ~handle := #in~handle;~value := #in~value; {18310#true} is VALID [2022-02-20 17:56:21,247 INFO L290 TraceCheckUtils]: 8: Hoare triple {18310#true} assume 1 == ~handle;~__ste_client_idCounter0~0 := ~value; {18310#true} is VALID [2022-02-20 17:56:21,247 INFO L290 TraceCheckUtils]: 9: Hoare triple {18310#true} assume true; {18310#true} is VALID [2022-02-20 17:56:21,247 INFO L284 TraceCheckUtils]: 10: Hoare quadruple {18310#true} {18310#true} #1133#return; {18310#true} is VALID [2022-02-20 17:56:21,247 INFO L290 TraceCheckUtils]: 11: Hoare triple {18310#true} assume { :end_inline_setup_bob__wrappee__Base } true; {18310#true} is VALID [2022-02-20 17:56:21,248 INFO L272 TraceCheckUtils]: 12: Hoare triple {18310#true} call setClientPrivateKey(setup_bob_~bob___0#1, 123); {18370#(and (= ~__ste_client_privateKey0~0 |old(~__ste_client_privateKey0~0)|) (= ~__ste_client_privateKey2~0 |old(~__ste_client_privateKey2~0)|) (= ~__ste_client_privateKey1~0 |old(~__ste_client_privateKey1~0)|))} is VALID [2022-02-20 17:56:21,248 INFO L290 TraceCheckUtils]: 13: Hoare triple {18370#(and (= ~__ste_client_privateKey0~0 |old(~__ste_client_privateKey0~0)|) (= ~__ste_client_privateKey2~0 |old(~__ste_client_privateKey2~0)|) (= ~__ste_client_privateKey1~0 |old(~__ste_client_privateKey1~0)|))} ~handle := #in~handle;~value := #in~value; {18310#true} is VALID [2022-02-20 17:56:21,248 INFO L290 TraceCheckUtils]: 14: Hoare triple {18310#true} assume 1 == ~handle;~__ste_client_privateKey0~0 := ~value; {18310#true} is VALID [2022-02-20 17:56:21,248 INFO L290 TraceCheckUtils]: 15: Hoare triple {18310#true} assume true; {18310#true} is VALID [2022-02-20 17:56:21,248 INFO L284 TraceCheckUtils]: 16: Hoare quadruple {18310#true} {18310#true} #1135#return; {18310#true} is VALID [2022-02-20 17:56:21,248 INFO L290 TraceCheckUtils]: 17: Hoare triple {18310#true} assume { :end_inline_setup_bob } true;setup_~__cil_tmp1~0#1.base, setup_~__cil_tmp1~0#1.offset := 34, 0;havoc setup_#t~nondet95#1;~rjh~0 := 2;assume { :begin_inline_setup_rjh } true;setup_rjh_#in~rjh___0#1 := ~rjh~0;havoc setup_rjh_~rjh___0#1;setup_rjh_~rjh___0#1 := setup_rjh_#in~rjh___0#1;assume { :begin_inline_setup_rjh__wrappee__Base } true;setup_rjh__wrappee__Base_#in~rjh___0#1 := setup_rjh_~rjh___0#1;havoc setup_rjh__wrappee__Base_~rjh___0#1;setup_rjh__wrappee__Base_~rjh___0#1 := setup_rjh__wrappee__Base_#in~rjh___0#1; {18310#true} is VALID [2022-02-20 17:56:21,249 INFO L272 TraceCheckUtils]: 18: Hoare triple {18310#true} call setClientId(setup_rjh__wrappee__Base_~rjh___0#1, setup_rjh__wrappee__Base_~rjh___0#1); {18369#(and (= |old(~__ste_client_idCounter0~0)| ~__ste_client_idCounter0~0) (= |old(~__ste_client_idCounter1~0)| ~__ste_client_idCounter1~0) (= |old(~__ste_client_idCounter2~0)| ~__ste_client_idCounter2~0))} is VALID [2022-02-20 17:56:21,249 INFO L290 TraceCheckUtils]: 19: Hoare triple {18369#(and (= |old(~__ste_client_idCounter0~0)| ~__ste_client_idCounter0~0) (= |old(~__ste_client_idCounter1~0)| ~__ste_client_idCounter1~0) (= |old(~__ste_client_idCounter2~0)| ~__ste_client_idCounter2~0))} ~handle := #in~handle;~value := #in~value; {18310#true} is VALID [2022-02-20 17:56:21,249 INFO L290 TraceCheckUtils]: 20: Hoare triple {18310#true} assume !(1 == ~handle); {18310#true} is VALID [2022-02-20 17:56:21,249 INFO L290 TraceCheckUtils]: 21: Hoare triple {18310#true} assume 2 == ~handle;~__ste_client_idCounter1~0 := ~value; {18310#true} is VALID [2022-02-20 17:56:21,249 INFO L290 TraceCheckUtils]: 22: Hoare triple {18310#true} assume true; {18310#true} is VALID [2022-02-20 17:56:21,249 INFO L284 TraceCheckUtils]: 23: Hoare quadruple {18310#true} {18310#true} #1137#return; {18310#true} is VALID [2022-02-20 17:56:21,250 INFO L290 TraceCheckUtils]: 24: Hoare triple {18310#true} assume { :end_inline_setup_rjh__wrappee__Base } true; {18310#true} is VALID [2022-02-20 17:56:21,250 INFO L272 TraceCheckUtils]: 25: Hoare triple {18310#true} call setClientPrivateKey(setup_rjh_~rjh___0#1, 456); {18370#(and (= ~__ste_client_privateKey0~0 |old(~__ste_client_privateKey0~0)|) (= ~__ste_client_privateKey2~0 |old(~__ste_client_privateKey2~0)|) (= ~__ste_client_privateKey1~0 |old(~__ste_client_privateKey1~0)|))} is VALID [2022-02-20 17:56:21,250 INFO L290 TraceCheckUtils]: 26: Hoare triple {18370#(and (= ~__ste_client_privateKey0~0 |old(~__ste_client_privateKey0~0)|) (= ~__ste_client_privateKey2~0 |old(~__ste_client_privateKey2~0)|) (= ~__ste_client_privateKey1~0 |old(~__ste_client_privateKey1~0)|))} ~handle := #in~handle;~value := #in~value; {18310#true} is VALID [2022-02-20 17:56:21,250 INFO L290 TraceCheckUtils]: 27: Hoare triple {18310#true} assume !(1 == ~handle); {18310#true} is VALID [2022-02-20 17:56:21,250 INFO L290 TraceCheckUtils]: 28: Hoare triple {18310#true} assume 2 == ~handle;~__ste_client_privateKey1~0 := ~value; {18310#true} is VALID [2022-02-20 17:56:21,251 INFO L290 TraceCheckUtils]: 29: Hoare triple {18310#true} assume true; {18310#true} is VALID [2022-02-20 17:56:21,251 INFO L284 TraceCheckUtils]: 30: Hoare quadruple {18310#true} {18310#true} #1139#return; {18310#true} is VALID [2022-02-20 17:56:21,251 INFO L290 TraceCheckUtils]: 31: Hoare triple {18310#true} assume { :end_inline_setup_rjh } true;setup_~__cil_tmp2~0#1.base, setup_~__cil_tmp2~0#1.offset := 35, 0;havoc setup_#t~nondet96#1;~chuck~0 := 3;assume { :begin_inline_setup_chuck } true;setup_chuck_#in~chuck___0#1 := ~chuck~0;havoc setup_chuck_~chuck___0#1;setup_chuck_~chuck___0#1 := setup_chuck_#in~chuck___0#1;assume { :begin_inline_setup_chuck__wrappee__Base } true;setup_chuck__wrappee__Base_#in~chuck___0#1 := setup_chuck_~chuck___0#1;havoc setup_chuck__wrappee__Base_~chuck___0#1;setup_chuck__wrappee__Base_~chuck___0#1 := setup_chuck__wrappee__Base_#in~chuck___0#1; {18330#(= 3 |ULTIMATE.start_setup_chuck__wrappee__Base_~chuck___0#1|)} is VALID [2022-02-20 17:56:21,252 INFO L272 TraceCheckUtils]: 32: Hoare triple {18330#(= 3 |ULTIMATE.start_setup_chuck__wrappee__Base_~chuck___0#1|)} call setClientId(setup_chuck__wrappee__Base_~chuck___0#1, setup_chuck__wrappee__Base_~chuck___0#1); {18369#(and (= |old(~__ste_client_idCounter0~0)| ~__ste_client_idCounter0~0) (= |old(~__ste_client_idCounter1~0)| ~__ste_client_idCounter1~0) (= |old(~__ste_client_idCounter2~0)| ~__ste_client_idCounter2~0))} is VALID [2022-02-20 17:56:21,252 INFO L290 TraceCheckUtils]: 33: Hoare triple {18369#(and (= |old(~__ste_client_idCounter0~0)| ~__ste_client_idCounter0~0) (= |old(~__ste_client_idCounter1~0)| ~__ste_client_idCounter1~0) (= |old(~__ste_client_idCounter2~0)| ~__ste_client_idCounter2~0))} ~handle := #in~handle;~value := #in~value; {18371#(= setClientId_~handle |setClientId_#in~handle|)} is VALID [2022-02-20 17:56:21,252 INFO L290 TraceCheckUtils]: 34: Hoare triple {18371#(= setClientId_~handle |setClientId_#in~handle|)} assume !(1 == ~handle); {18371#(= setClientId_~handle |setClientId_#in~handle|)} is VALID [2022-02-20 17:56:21,252 INFO L290 TraceCheckUtils]: 35: Hoare triple {18371#(= setClientId_~handle |setClientId_#in~handle|)} assume 2 == ~handle;~__ste_client_idCounter1~0 := ~value; {18372#(= 2 |setClientId_#in~handle|)} is VALID [2022-02-20 17:56:21,253 INFO L290 TraceCheckUtils]: 36: Hoare triple {18372#(= 2 |setClientId_#in~handle|)} assume true; {18372#(= 2 |setClientId_#in~handle|)} is VALID [2022-02-20 17:56:21,253 INFO L284 TraceCheckUtils]: 37: Hoare quadruple {18372#(= 2 |setClientId_#in~handle|)} {18330#(= 3 |ULTIMATE.start_setup_chuck__wrappee__Base_~chuck___0#1|)} #1141#return; {18311#false} is VALID [2022-02-20 17:56:21,253 INFO L290 TraceCheckUtils]: 38: Hoare triple {18311#false} assume { :end_inline_setup_chuck__wrappee__Base } true; {18311#false} is VALID [2022-02-20 17:56:21,253 INFO L272 TraceCheckUtils]: 39: Hoare triple {18311#false} call setClientPrivateKey(setup_chuck_~chuck___0#1, 789); {18370#(and (= ~__ste_client_privateKey0~0 |old(~__ste_client_privateKey0~0)|) (= ~__ste_client_privateKey2~0 |old(~__ste_client_privateKey2~0)|) (= ~__ste_client_privateKey1~0 |old(~__ste_client_privateKey1~0)|))} is VALID [2022-02-20 17:56:21,253 INFO L290 TraceCheckUtils]: 40: Hoare triple {18370#(and (= ~__ste_client_privateKey0~0 |old(~__ste_client_privateKey0~0)|) (= ~__ste_client_privateKey2~0 |old(~__ste_client_privateKey2~0)|) (= ~__ste_client_privateKey1~0 |old(~__ste_client_privateKey1~0)|))} ~handle := #in~handle;~value := #in~value; {18310#true} is VALID [2022-02-20 17:56:21,253 INFO L290 TraceCheckUtils]: 41: Hoare triple {18310#true} assume 1 == ~handle;~__ste_client_privateKey0~0 := ~value; {18310#true} is VALID [2022-02-20 17:56:21,253 INFO L290 TraceCheckUtils]: 42: Hoare triple {18310#true} assume true; {18310#true} is VALID [2022-02-20 17:56:21,254 INFO L284 TraceCheckUtils]: 43: Hoare quadruple {18310#true} {18311#false} #1143#return; {18311#false} is VALID [2022-02-20 17:56:21,254 INFO L290 TraceCheckUtils]: 44: Hoare triple {18311#false} assume { :end_inline_setup_chuck } true;setup_~__cil_tmp3~2#1.base, setup_~__cil_tmp3~2#1.offset := 36, 0;havoc setup_#t~nondet97#1; {18311#false} is VALID [2022-02-20 17:56:21,254 INFO L290 TraceCheckUtils]: 45: Hoare triple {18311#false} assume { :end_inline_setup } true;assume { :begin_inline_test } true;havoc test_#t~nondet48#1, test_#t~nondet49#1, test_#t~nondet50#1, test_#t~nondet51#1, test_#t~nondet52#1, test_#t~nondet53#1, test_#t~nondet54#1, test_#t~nondet55#1, test_#t~nondet56#1, test_#t~nondet57#1, test_#t~nondet58#1, test_~op1~0#1, test_~op2~0#1, test_~op3~0#1, test_~op4~0#1, test_~op5~0#1, test_~op6~0#1, test_~op7~0#1, test_~op8~0#1, test_~op9~0#1, test_~op10~0#1, test_~op11~0#1, test_~splverifierCounter~0#1, test_~tmp~8#1, test_~tmp___0~3#1, test_~tmp___1~1#1, test_~tmp___2~1#1, test_~tmp___3~0#1, test_~tmp___4~0#1, test_~tmp___5~0#1, test_~tmp___6~0#1, test_~tmp___7~0#1, test_~tmp___8~0#1, test_~tmp___9~0#1;havoc test_~op1~0#1;havoc test_~op2~0#1;havoc test_~op3~0#1;havoc test_~op4~0#1;havoc test_~op5~0#1;havoc test_~op6~0#1;havoc test_~op7~0#1;havoc test_~op8~0#1;havoc test_~op9~0#1;havoc test_~op10~0#1;havoc test_~op11~0#1;havoc test_~splverifierCounter~0#1;havoc test_~tmp~8#1;havoc test_~tmp___0~3#1;havoc test_~tmp___1~1#1;havoc test_~tmp___2~1#1;havoc test_~tmp___3~0#1;havoc test_~tmp___4~0#1;havoc test_~tmp___5~0#1;havoc test_~tmp___6~0#1;havoc test_~tmp___7~0#1;havoc test_~tmp___8~0#1;havoc test_~tmp___9~0#1;test_~op1~0#1 := 0;test_~op2~0#1 := 0;test_~op3~0#1 := 0;test_~op4~0#1 := 0;test_~op5~0#1 := 0;test_~op6~0#1 := 0;test_~op7~0#1 := 0;test_~op8~0#1 := 0;test_~op9~0#1 := 0;test_~op10~0#1 := 0;test_~op11~0#1 := 0;test_~splverifierCounter~0#1 := 0; {18311#false} is VALID [2022-02-20 17:56:21,254 INFO L290 TraceCheckUtils]: 46: Hoare triple {18311#false} assume !false; {18311#false} is VALID [2022-02-20 17:56:21,254 INFO L290 TraceCheckUtils]: 47: Hoare triple {18311#false} assume test_~splverifierCounter~0#1 < 4; {18311#false} is VALID [2022-02-20 17:56:21,254 INFO L290 TraceCheckUtils]: 48: Hoare triple {18311#false} test_~splverifierCounter~0#1 := 1 + test_~splverifierCounter~0#1; {18311#false} is VALID [2022-02-20 17:56:21,254 INFO L290 TraceCheckUtils]: 49: Hoare triple {18311#false} assume 0 == test_~op1~0#1;assume -2147483648 <= test_#t~nondet48#1 && test_#t~nondet48#1 <= 2147483647;test_~tmp___9~0#1 := test_#t~nondet48#1;havoc test_#t~nondet48#1; {18311#false} is VALID [2022-02-20 17:56:21,254 INFO L290 TraceCheckUtils]: 50: Hoare triple {18311#false} assume !(0 != test_~tmp___9~0#1); {18311#false} is VALID [2022-02-20 17:56:21,254 INFO L290 TraceCheckUtils]: 51: Hoare triple {18311#false} assume 0 == test_~op2~0#1;assume -2147483648 <= test_#t~nondet49#1 && test_#t~nondet49#1 <= 2147483647;test_~tmp___8~0#1 := test_#t~nondet49#1;havoc test_#t~nondet49#1; {18311#false} is VALID [2022-02-20 17:56:21,254 INFO L290 TraceCheckUtils]: 52: Hoare triple {18311#false} assume 0 != test_~tmp___8~0#1;assume { :begin_inline_rjhSetAutoRespond } true;assume { :begin_inline_setClientAutoResponse } true;setClientAutoResponse_#in~handle#1, setClientAutoResponse_#in~value#1 := ~rjh~0, 1;havoc setClientAutoResponse_~handle#1, setClientAutoResponse_~value#1;setClientAutoResponse_~handle#1 := setClientAutoResponse_#in~handle#1;setClientAutoResponse_~value#1 := setClientAutoResponse_#in~value#1; {18311#false} is VALID [2022-02-20 17:56:21,255 INFO L290 TraceCheckUtils]: 53: Hoare triple {18311#false} assume 1 == setClientAutoResponse_~handle#1;~__ste_client_autoResponse0~0 := setClientAutoResponse_~value#1; {18311#false} is VALID [2022-02-20 17:56:21,255 INFO L290 TraceCheckUtils]: 54: Hoare triple {18311#false} assume { :end_inline_setClientAutoResponse } true; {18311#false} is VALID [2022-02-20 17:56:21,255 INFO L290 TraceCheckUtils]: 55: Hoare triple {18311#false} assume { :end_inline_rjhSetAutoRespond } true;test_~op2~0#1 := 1; {18311#false} is VALID [2022-02-20 17:56:21,255 INFO L290 TraceCheckUtils]: 56: Hoare triple {18311#false} assume !false; {18311#false} is VALID [2022-02-20 17:56:21,255 INFO L290 TraceCheckUtils]: 57: Hoare triple {18311#false} assume !(test_~splverifierCounter~0#1 < 4); {18311#false} is VALID [2022-02-20 17:56:21,255 INFO L290 TraceCheckUtils]: 58: Hoare triple {18311#false} assume { :begin_inline_bobToRjh } true;havoc bobToRjh_#t~ret90#1, bobToRjh_#t~ret91#1, bobToRjh_#t~ret92#1, bobToRjh_#t~ret93#1, bobToRjh_~tmp~23#1, bobToRjh_~tmp___0~7#1, bobToRjh_~tmp___1~4#1;havoc bobToRjh_~tmp~23#1;havoc bobToRjh_~tmp___0~7#1;havoc bobToRjh_~tmp___1~4#1;call bobToRjh_#t~ret90#1 := puts(32, 0);assume -2147483648 <= bobToRjh_#t~ret90#1 && bobToRjh_#t~ret90#1 <= 2147483647;havoc bobToRjh_#t~ret90#1; {18311#false} is VALID [2022-02-20 17:56:21,255 INFO L272 TraceCheckUtils]: 59: Hoare triple {18311#false} call sendEmail(~bob~0, ~rjh~0); {18311#false} is VALID [2022-02-20 17:56:21,255 INFO L290 TraceCheckUtils]: 60: Hoare triple {18311#false} ~sender#1 := #in~sender#1;~receiver#1 := #in~receiver#1;havoc ~email~0#1;havoc ~tmp~16#1;assume { :begin_inline_createEmail } true;createEmail_#in~from#1, createEmail_#in~to#1 := 0, ~receiver#1;havoc createEmail_#res#1;havoc createEmail_~from#1, createEmail_~to#1, createEmail_~retValue_acc~4#1, createEmail_~msg~0#1;createEmail_~from#1 := createEmail_#in~from#1;createEmail_~to#1 := createEmail_#in~to#1;havoc createEmail_~retValue_acc~4#1;havoc createEmail_~msg~0#1;createEmail_~msg~0#1 := 1; {18311#false} is VALID [2022-02-20 17:56:21,255 INFO L272 TraceCheckUtils]: 61: Hoare triple {18311#false} call setEmailFrom(createEmail_~msg~0#1, createEmail_~from#1); {18373#(and (= |old(~__ste_email_from0~0)| ~__ste_email_from0~0) (= |old(~__ste_email_from1~0)| ~__ste_email_from1~0))} is VALID [2022-02-20 17:56:21,255 INFO L290 TraceCheckUtils]: 62: Hoare triple {18373#(and (= |old(~__ste_email_from0~0)| ~__ste_email_from0~0) (= |old(~__ste_email_from1~0)| ~__ste_email_from1~0))} ~handle := #in~handle;~value := #in~value; {18310#true} is VALID [2022-02-20 17:56:21,256 INFO L290 TraceCheckUtils]: 63: Hoare triple {18310#true} assume 1 == ~handle;~__ste_email_from0~0 := ~value; {18310#true} is VALID [2022-02-20 17:56:21,256 INFO L290 TraceCheckUtils]: 64: Hoare triple {18310#true} assume true; {18310#true} is VALID [2022-02-20 17:56:21,256 INFO L284 TraceCheckUtils]: 65: Hoare quadruple {18310#true} {18311#false} #1119#return; {18311#false} is VALID [2022-02-20 17:56:21,256 INFO L272 TraceCheckUtils]: 66: Hoare triple {18311#false} call setEmailTo(createEmail_~msg~0#1, createEmail_~to#1); {18374#(and (= ~__ste_email_to0~0 |old(~__ste_email_to0~0)|) (= ~__ste_email_to1~0 |old(~__ste_email_to1~0)|))} is VALID [2022-02-20 17:56:21,256 INFO L290 TraceCheckUtils]: 67: Hoare triple {18374#(and (= ~__ste_email_to0~0 |old(~__ste_email_to0~0)|) (= ~__ste_email_to1~0 |old(~__ste_email_to1~0)|))} ~handle := #in~handle;~value := #in~value; {18310#true} is VALID [2022-02-20 17:56:21,256 INFO L290 TraceCheckUtils]: 68: Hoare triple {18310#true} assume 1 == ~handle;~__ste_email_to0~0 := ~value; {18310#true} is VALID [2022-02-20 17:56:21,256 INFO L290 TraceCheckUtils]: 69: Hoare triple {18310#true} assume true; {18310#true} is VALID [2022-02-20 17:56:21,256 INFO L284 TraceCheckUtils]: 70: Hoare quadruple {18310#true} {18311#false} #1121#return; {18311#false} is VALID [2022-02-20 17:56:21,256 INFO L290 TraceCheckUtils]: 71: Hoare triple {18311#false} createEmail_~retValue_acc~4#1 := createEmail_~msg~0#1;createEmail_#res#1 := createEmail_~retValue_acc~4#1; {18311#false} is VALID [2022-02-20 17:56:21,256 INFO L290 TraceCheckUtils]: 72: Hoare triple {18311#false} #t~ret73#1 := createEmail_#res#1;assume { :end_inline_createEmail } true;assume -2147483648 <= #t~ret73#1 && #t~ret73#1 <= 2147483647;~tmp~16#1 := #t~ret73#1;havoc #t~ret73#1;~email~0#1 := ~tmp~16#1; {18311#false} is VALID [2022-02-20 17:56:21,257 INFO L272 TraceCheckUtils]: 73: Hoare triple {18311#false} call outgoing(~sender#1, ~email~0#1); {18311#false} is VALID [2022-02-20 17:56:21,257 INFO L290 TraceCheckUtils]: 74: Hoare triple {18311#false} ~client#1 := #in~client#1;~msg#1 := #in~msg#1;assume { :begin_inline_sign } true;sign_#in~client#1, sign_#in~msg#1 := ~client#1, ~msg#1;havoc sign_#t~ret77#1, sign_~client#1, sign_~msg#1, sign_~privkey~1#1, sign_~tmp~18#1;sign_~client#1 := sign_#in~client#1;sign_~msg#1 := sign_#in~msg#1;havoc sign_~privkey~1#1;havoc sign_~tmp~18#1; {18311#false} is VALID [2022-02-20 17:56:21,257 INFO L272 TraceCheckUtils]: 75: Hoare triple {18311#false} call sign_#t~ret77#1 := getClientPrivateKey(sign_~client#1); {18310#true} is VALID [2022-02-20 17:56:21,257 INFO L290 TraceCheckUtils]: 76: Hoare triple {18310#true} ~handle := #in~handle;havoc ~retValue_acc~24; {18310#true} is VALID [2022-02-20 17:56:21,257 INFO L290 TraceCheckUtils]: 77: Hoare triple {18310#true} assume 1 == ~handle;~retValue_acc~24 := ~__ste_client_privateKey0~0;#res := ~retValue_acc~24; {18310#true} is VALID [2022-02-20 17:56:21,257 INFO L290 TraceCheckUtils]: 78: Hoare triple {18310#true} assume true; {18310#true} is VALID [2022-02-20 17:56:21,257 INFO L284 TraceCheckUtils]: 79: Hoare quadruple {18310#true} {18311#false} #1053#return; {18311#false} is VALID [2022-02-20 17:56:21,257 INFO L290 TraceCheckUtils]: 80: Hoare triple {18311#false} assume -2147483648 <= sign_#t~ret77#1 && sign_#t~ret77#1 <= 2147483647;sign_~tmp~18#1 := sign_#t~ret77#1;havoc sign_#t~ret77#1;sign_~privkey~1#1 := sign_~tmp~18#1; {18311#false} is VALID [2022-02-20 17:56:21,257 INFO L290 TraceCheckUtils]: 81: Hoare triple {18311#false} assume 0 == sign_~privkey~1#1; {18311#false} is VALID [2022-02-20 17:56:21,257 INFO L290 TraceCheckUtils]: 82: Hoare triple {18311#false} assume { :end_inline_sign } true;assume { :begin_inline_outgoing__wrappee__AutoResponder } true;outgoing__wrappee__AutoResponder_#in~client#1, outgoing__wrappee__AutoResponder_#in~msg#1 := ~client#1, ~msg#1;havoc outgoing__wrappee__AutoResponder_#t~ret63#1, outgoing__wrappee__AutoResponder_#t~ret64#1, outgoing__wrappee__AutoResponder_~client#1, outgoing__wrappee__AutoResponder_~msg#1, outgoing__wrappee__AutoResponder_~receiver~0#1, outgoing__wrappee__AutoResponder_~tmp~11#1, outgoing__wrappee__AutoResponder_~pubkey~0#1, outgoing__wrappee__AutoResponder_~tmp___0~4#1;outgoing__wrappee__AutoResponder_~client#1 := outgoing__wrappee__AutoResponder_#in~client#1;outgoing__wrappee__AutoResponder_~msg#1 := outgoing__wrappee__AutoResponder_#in~msg#1;havoc outgoing__wrappee__AutoResponder_~receiver~0#1;havoc outgoing__wrappee__AutoResponder_~tmp~11#1;havoc outgoing__wrappee__AutoResponder_~pubkey~0#1;havoc outgoing__wrappee__AutoResponder_~tmp___0~4#1; {18311#false} is VALID [2022-02-20 17:56:21,258 INFO L272 TraceCheckUtils]: 83: Hoare triple {18311#false} call outgoing__wrappee__AutoResponder_#t~ret63#1 := getEmailTo(outgoing__wrappee__AutoResponder_~msg#1); {18310#true} is VALID [2022-02-20 17:56:21,258 INFO L290 TraceCheckUtils]: 84: Hoare triple {18310#true} ~handle := #in~handle;havoc ~retValue_acc~36; {18310#true} is VALID [2022-02-20 17:56:21,258 INFO L290 TraceCheckUtils]: 85: Hoare triple {18310#true} assume 1 == ~handle;~retValue_acc~36 := ~__ste_email_to0~0;#res := ~retValue_acc~36; {18310#true} is VALID [2022-02-20 17:56:21,258 INFO L290 TraceCheckUtils]: 86: Hoare triple {18310#true} assume true; {18310#true} is VALID [2022-02-20 17:56:21,258 INFO L284 TraceCheckUtils]: 87: Hoare quadruple {18310#true} {18311#false} #1055#return; {18311#false} is VALID [2022-02-20 17:56:21,258 INFO L290 TraceCheckUtils]: 88: Hoare triple {18311#false} assume -2147483648 <= outgoing__wrappee__AutoResponder_#t~ret63#1 && outgoing__wrappee__AutoResponder_#t~ret63#1 <= 2147483647;outgoing__wrappee__AutoResponder_~tmp~11#1 := outgoing__wrappee__AutoResponder_#t~ret63#1;havoc outgoing__wrappee__AutoResponder_#t~ret63#1;outgoing__wrappee__AutoResponder_~receiver~0#1 := outgoing__wrappee__AutoResponder_~tmp~11#1; {18311#false} is VALID [2022-02-20 17:56:21,258 INFO L272 TraceCheckUtils]: 89: Hoare triple {18311#false} call outgoing__wrappee__AutoResponder_#t~ret64#1 := findPublicKey(outgoing__wrappee__AutoResponder_~client#1, outgoing__wrappee__AutoResponder_~receiver~0#1); {18310#true} is VALID [2022-02-20 17:56:21,258 INFO L290 TraceCheckUtils]: 90: Hoare triple {18310#true} ~handle := #in~handle;~userid := #in~userid;havoc ~retValue_acc~29; {18310#true} is VALID [2022-02-20 17:56:21,258 INFO L290 TraceCheckUtils]: 91: Hoare triple {18310#true} assume 1 == ~handle; {18310#true} is VALID [2022-02-20 17:56:21,258 INFO L290 TraceCheckUtils]: 92: Hoare triple {18310#true} assume ~userid == ~__ste_Client_Keyring0_User0~0;~retValue_acc~29 := ~__ste_Client_Keyring0_PublicKey0~0;#res := ~retValue_acc~29; {18310#true} is VALID [2022-02-20 17:56:21,259 INFO L290 TraceCheckUtils]: 93: Hoare triple {18310#true} assume true; {18310#true} is VALID [2022-02-20 17:56:21,259 INFO L284 TraceCheckUtils]: 94: Hoare quadruple {18310#true} {18311#false} #1057#return; {18311#false} is VALID [2022-02-20 17:56:21,259 INFO L290 TraceCheckUtils]: 95: Hoare triple {18311#false} assume -2147483648 <= outgoing__wrappee__AutoResponder_#t~ret64#1 && outgoing__wrappee__AutoResponder_#t~ret64#1 <= 2147483647;outgoing__wrappee__AutoResponder_~tmp___0~4#1 := outgoing__wrappee__AutoResponder_#t~ret64#1;havoc outgoing__wrappee__AutoResponder_#t~ret64#1;outgoing__wrappee__AutoResponder_~pubkey~0#1 := outgoing__wrappee__AutoResponder_~tmp___0~4#1; {18311#false} is VALID [2022-02-20 17:56:21,259 INFO L290 TraceCheckUtils]: 96: Hoare triple {18311#false} assume !(0 != outgoing__wrappee__AutoResponder_~pubkey~0#1); {18311#false} is VALID [2022-02-20 17:56:21,259 INFO L290 TraceCheckUtils]: 97: Hoare triple {18311#false} assume { :begin_inline_outgoing__wrappee__Keys } true;outgoing__wrappee__Keys_#in~client#1, outgoing__wrappee__Keys_#in~msg#1 := outgoing__wrappee__AutoResponder_~client#1, outgoing__wrappee__AutoResponder_~msg#1;havoc outgoing__wrappee__Keys_#t~ret62#1, outgoing__wrappee__Keys_~client#1, outgoing__wrappee__Keys_~msg#1, outgoing__wrappee__Keys_~tmp~10#1;outgoing__wrappee__Keys_~client#1 := outgoing__wrappee__Keys_#in~client#1;outgoing__wrappee__Keys_~msg#1 := outgoing__wrappee__Keys_#in~msg#1;havoc outgoing__wrappee__Keys_~tmp~10#1;assume { :begin_inline_getClientId } true;getClientId_#in~handle#1 := outgoing__wrappee__Keys_~client#1;havoc getClientId_#res#1;havoc getClientId_~handle#1, getClientId_~retValue_acc~31#1;getClientId_~handle#1 := getClientId_#in~handle#1;havoc getClientId_~retValue_acc~31#1; {18311#false} is VALID [2022-02-20 17:56:21,259 INFO L290 TraceCheckUtils]: 98: Hoare triple {18311#false} assume 1 == getClientId_~handle#1;getClientId_~retValue_acc~31#1 := ~__ste_client_idCounter0~0;getClientId_#res#1 := getClientId_~retValue_acc~31#1; {18311#false} is VALID [2022-02-20 17:56:21,259 INFO L290 TraceCheckUtils]: 99: Hoare triple {18311#false} outgoing__wrappee__Keys_#t~ret62#1 := getClientId_#res#1;assume { :end_inline_getClientId } true;assume -2147483648 <= outgoing__wrappee__Keys_#t~ret62#1 && outgoing__wrappee__Keys_#t~ret62#1 <= 2147483647;outgoing__wrappee__Keys_~tmp~10#1 := outgoing__wrappee__Keys_#t~ret62#1;havoc outgoing__wrappee__Keys_#t~ret62#1; {18311#false} is VALID [2022-02-20 17:56:21,259 INFO L272 TraceCheckUtils]: 100: Hoare triple {18311#false} call setEmailFrom(outgoing__wrappee__Keys_~msg#1, outgoing__wrappee__Keys_~tmp~10#1); {18373#(and (= |old(~__ste_email_from0~0)| ~__ste_email_from0~0) (= |old(~__ste_email_from1~0)| ~__ste_email_from1~0))} is VALID [2022-02-20 17:56:21,259 INFO L290 TraceCheckUtils]: 101: Hoare triple {18373#(and (= |old(~__ste_email_from0~0)| ~__ste_email_from0~0) (= |old(~__ste_email_from1~0)| ~__ste_email_from1~0))} ~handle := #in~handle;~value := #in~value; {18310#true} is VALID [2022-02-20 17:56:21,259 INFO L290 TraceCheckUtils]: 102: Hoare triple {18310#true} assume 1 == ~handle;~__ste_email_from0~0 := ~value; {18310#true} is VALID [2022-02-20 17:56:21,260 INFO L290 TraceCheckUtils]: 103: Hoare triple {18310#true} assume true; {18310#true} is VALID [2022-02-20 17:56:21,260 INFO L284 TraceCheckUtils]: 104: Hoare quadruple {18310#true} {18311#false} #1063#return; {18311#false} is VALID [2022-02-20 17:56:21,260 INFO L290 TraceCheckUtils]: 105: Hoare triple {18311#false} assume { :begin_inline_mail } true;mail_#in~client#1, mail_#in~msg#1 := outgoing__wrappee__Keys_~client#1, outgoing__wrappee__Keys_~msg#1;havoc mail_#t~ret60#1, mail_#t~ret61#1, mail_~client#1, mail_~msg#1, mail_~__utac__ad__arg1~0#1, mail_~__utac__ad__arg2~0#1, mail_~tmp~9#1;mail_~client#1 := mail_#in~client#1;mail_~msg#1 := mail_#in~msg#1;havoc mail_~__utac__ad__arg1~0#1;havoc mail_~__utac__ad__arg2~0#1;havoc mail_~tmp~9#1;mail_~__utac__ad__arg1~0#1 := mail_~client#1;mail_~__utac__ad__arg2~0#1 := mail_~msg#1;assume { :begin_inline___utac_acc__AddressBookEncrypt_spec__1 } true;__utac_acc__AddressBookEncrypt_spec__1_#in~client#1, __utac_acc__AddressBookEncrypt_spec__1_#in~msg#1 := mail_~__utac__ad__arg1~0#1, mail_~__utac__ad__arg2~0#1;havoc __utac_acc__AddressBookEncrypt_spec__1_#t~ret85#1, __utac_acc__AddressBookEncrypt_spec__1_#t~ret86#1, __utac_acc__AddressBookEncrypt_spec__1_#t~ret87#1, __utac_acc__AddressBookEncrypt_spec__1_~client#1, __utac_acc__AddressBookEncrypt_spec__1_~msg#1, __utac_acc__AddressBookEncrypt_spec__1_~tmp~20#1;__utac_acc__AddressBookEncrypt_spec__1_~client#1 := __utac_acc__AddressBookEncrypt_spec__1_#in~client#1;__utac_acc__AddressBookEncrypt_spec__1_~msg#1 := __utac_acc__AddressBookEncrypt_spec__1_#in~msg#1;havoc __utac_acc__AddressBookEncrypt_spec__1_~tmp~20#1;call __utac_acc__AddressBookEncrypt_spec__1_#t~ret85#1 := puts(31, 0);assume -2147483648 <= __utac_acc__AddressBookEncrypt_spec__1_#t~ret85#1 && __utac_acc__AddressBookEncrypt_spec__1_#t~ret85#1 <= 2147483647;havoc __utac_acc__AddressBookEncrypt_spec__1_#t~ret85#1; {18311#false} is VALID [2022-02-20 17:56:21,260 INFO L290 TraceCheckUtils]: 106: Hoare triple {18311#false} assume !(-1 == ~mail_is_sensitive~0); {18311#false} is VALID [2022-02-20 17:56:21,260 INFO L272 TraceCheckUtils]: 107: Hoare triple {18311#false} call __utac_acc__AddressBookEncrypt_spec__1_#t~ret87#1 := isEncrypted(__utac_acc__AddressBookEncrypt_spec__1_~msg#1); {18310#true} is VALID [2022-02-20 17:56:21,260 INFO L290 TraceCheckUtils]: 108: Hoare triple {18310#true} ~handle := #in~handle;havoc ~retValue_acc~39; {18310#true} is VALID [2022-02-20 17:56:21,260 INFO L290 TraceCheckUtils]: 109: Hoare triple {18310#true} assume 1 == ~handle;~retValue_acc~39 := ~__ste_email_isEncrypted0~0;#res := ~retValue_acc~39; {18310#true} is VALID [2022-02-20 17:56:21,260 INFO L290 TraceCheckUtils]: 110: Hoare triple {18310#true} assume true; {18310#true} is VALID [2022-02-20 17:56:21,260 INFO L284 TraceCheckUtils]: 111: Hoare quadruple {18310#true} {18311#false} #1067#return; {18311#false} is VALID [2022-02-20 17:56:21,260 INFO L290 TraceCheckUtils]: 112: Hoare triple {18311#false} assume -2147483648 <= __utac_acc__AddressBookEncrypt_spec__1_#t~ret87#1 && __utac_acc__AddressBookEncrypt_spec__1_#t~ret87#1 <= 2147483647;__utac_acc__AddressBookEncrypt_spec__1_~tmp~20#1 := __utac_acc__AddressBookEncrypt_spec__1_#t~ret87#1;havoc __utac_acc__AddressBookEncrypt_spec__1_#t~ret87#1; {18311#false} is VALID [2022-02-20 17:56:21,261 INFO L290 TraceCheckUtils]: 113: Hoare triple {18311#false} assume ~mail_is_sensitive~0 != __utac_acc__AddressBookEncrypt_spec__1_~tmp~20#1;assume { :begin_inline___automaton_fail } true; {18311#false} is VALID [2022-02-20 17:56:21,261 INFO L290 TraceCheckUtils]: 114: Hoare triple {18311#false} assume !false; {18311#false} is VALID [2022-02-20 17:56:21,261 INFO L134 CoverageAnalysis]: Checked inductivity of 31 backedges. 7 proven. 0 refuted. 0 times theorem prover too weak. 24 trivial. 0 not checked. [2022-02-20 17:56:21,261 INFO L144 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2022-02-20 17:56:21,261 INFO L338 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [1454409004] [2022-02-20 17:56:21,261 INFO L165 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [1454409004] provided 1 perfect and 0 imperfect interpolant sequences [2022-02-20 17:56:21,261 INFO L191 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2022-02-20 17:56:21,262 INFO L204 FreeRefinementEngine]: Number of different interpolants: perfect sequences [9] imperfect sequences [] total 9 [2022-02-20 17:56:21,262 INFO L118 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [1966765863] [2022-02-20 17:56:21,262 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2022-02-20 17:56:21,263 INFO L78 Accepts]: Start accepts. Automaton has has 9 states, 8 states have (on average 9.5) internal successors, (76), 5 states have internal predecessors, (76), 3 states have call successors, (15), 6 states have call predecessors, (15), 2 states have return successors, (13), 2 states have call predecessors, (13), 3 states have call successors, (13) Word has length 115 [2022-02-20 17:56:21,263 INFO L84 Accepts]: Finished accepts. word is accepted. [2022-02-20 17:56:21,264 INFO L86 InductivityCheck]: Starting indutivity check of a Floyd-Hoare automaton with has 9 states, 8 states have (on average 9.5) internal successors, (76), 5 states have internal predecessors, (76), 3 states have call successors, (15), 6 states have call predecessors, (15), 2 states have return successors, (13), 2 states have call predecessors, (13), 3 states have call successors, (13) [2022-02-20 17:56:21,320 INFO L122 InductivityCheck]: Floyd-Hoare automaton has 104 edges. 104 inductive. 0 not inductive. 0 times theorem prover too weak to decide inductivity. [2022-02-20 17:56:21,320 INFO L546 AbstractCegarLoop]: INTERPOLANT automaton has 9 states [2022-02-20 17:56:21,320 INFO L108 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2022-02-20 17:56:21,321 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 9 interpolants. [2022-02-20 17:56:21,321 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=15, Invalid=57, Unknown=0, NotChecked=0, Total=72 [2022-02-20 17:56:21,321 INFO L87 Difference]: Start difference. First operand 441 states and 665 transitions. Second operand has 9 states, 8 states have (on average 9.5) internal successors, (76), 5 states have internal predecessors, (76), 3 states have call successors, (15), 6 states have call predecessors, (15), 2 states have return successors, (13), 2 states have call predecessors, (13), 3 states have call successors, (13) [2022-02-20 17:56:28,470 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-02-20 17:56:28,470 INFO L93 Difference]: Finished difference Result 1075 states and 1633 transitions. [2022-02-20 17:56:28,470 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 11 states. [2022-02-20 17:56:28,470 INFO L78 Accepts]: Start accepts. Automaton has has 9 states, 8 states have (on average 9.5) internal successors, (76), 5 states have internal predecessors, (76), 3 states have call successors, (15), 6 states have call predecessors, (15), 2 states have return successors, (13), 2 states have call predecessors, (13), 3 states have call successors, (13) Word has length 115 [2022-02-20 17:56:28,471 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2022-02-20 17:56:28,471 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 9 states, 8 states have (on average 9.5) internal successors, (76), 5 states have internal predecessors, (76), 3 states have call successors, (15), 6 states have call predecessors, (15), 2 states have return successors, (13), 2 states have call predecessors, (13), 3 states have call successors, (13) [2022-02-20 17:56:28,481 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 11 states to 11 states and 1429 transitions. [2022-02-20 17:56:28,482 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 9 states, 8 states have (on average 9.5) internal successors, (76), 5 states have internal predecessors, (76), 3 states have call successors, (15), 6 states have call predecessors, (15), 2 states have return successors, (13), 2 states have call predecessors, (13), 3 states have call successors, (13) [2022-02-20 17:56:28,492 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 11 states to 11 states and 1429 transitions. [2022-02-20 17:56:28,492 INFO L86 InductivityCheck]: Starting indutivity check of a Floyd-Hoare automaton with 11 states and 1429 transitions. [2022-02-20 17:56:29,605 INFO L122 InductivityCheck]: Floyd-Hoare automaton has 1429 edges. 1429 inductive. 0 not inductive. 0 times theorem prover too weak to decide inductivity. [2022-02-20 17:56:29,627 INFO L225 Difference]: With dead ends: 1075 [2022-02-20 17:56:29,627 INFO L226 Difference]: Without dead ends: 657 [2022-02-20 17:56:29,628 INFO L932 BasicCegarLoop]: 0 DeclaredPredicates, 44 GetRequests, 29 SyntacticMatches, 0 SemanticMatches, 15 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 30 ImplicationChecksByTransitivity, 0.1s TimeCoverageRelationStatistics Valid=73, Invalid=199, Unknown=0, NotChecked=0, Total=272 [2022-02-20 17:56:29,629 INFO L933 BasicCegarLoop]: 718 mSDtfsCounter, 1378 mSDsluCounter, 863 mSDsCounter, 0 mSdLazyCounter, 2622 mSolverCounterSat, 589 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 3.3s Time, 0 mProtectedPredicate, 0 mProtectedAction, 1395 SdHoareTripleChecker+Valid, 1581 SdHoareTripleChecker+Invalid, 3211 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 589 IncrementalHoareTripleChecker+Valid, 2622 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 3.3s IncrementalHoareTripleChecker+Time [2022-02-20 17:56:29,629 INFO L934 BasicCegarLoop]: SdHoareTripleChecker [1395 Valid, 1581 Invalid, 3211 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [589 Valid, 2622 Invalid, 0 Unknown, 0 Unchecked, 3.3s Time] [2022-02-20 17:56:29,630 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 657 states. [2022-02-20 17:56:29,707 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 657 to 443. [2022-02-20 17:56:29,707 INFO L214 AbstractMinimizeNwa]: Start testing correctness of minimizeSevpa [2022-02-20 17:56:29,708 INFO L82 GeneralOperation]: Start isEquivalent. First operand 657 states. Second operand has 443 states, 341 states have (on average 1.5043988269794721) internal successors, (513), 347 states have internal predecessors, (513), 74 states have call successors, (74), 24 states have call predecessors, (74), 27 states have return successors, (81), 73 states have call predecessors, (81), 73 states have call successors, (81) [2022-02-20 17:56:29,709 INFO L74 IsIncluded]: Start isIncluded. First operand 657 states. Second operand has 443 states, 341 states have (on average 1.5043988269794721) internal successors, (513), 347 states have internal predecessors, (513), 74 states have call successors, (74), 24 states have call predecessors, (74), 27 states have return successors, (81), 73 states have call predecessors, (81), 73 states have call successors, (81) [2022-02-20 17:56:29,710 INFO L87 Difference]: Start difference. First operand 657 states. Second operand has 443 states, 341 states have (on average 1.5043988269794721) internal successors, (513), 347 states have internal predecessors, (513), 74 states have call successors, (74), 24 states have call predecessors, (74), 27 states have return successors, (81), 73 states have call predecessors, (81), 73 states have call successors, (81) [2022-02-20 17:56:29,727 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-02-20 17:56:29,727 INFO L93 Difference]: Finished difference Result 657 states and 998 transitions. [2022-02-20 17:56:29,727 INFO L276 IsEmpty]: Start isEmpty. Operand 657 states and 998 transitions. [2022-02-20 17:56:29,731 INFO L282 IsEmpty]: Finished isEmpty. No accepting run. [2022-02-20 17:56:29,731 INFO L83 IsIncluded]: Finished isIncluded. Language is included [2022-02-20 17:56:29,733 INFO L74 IsIncluded]: Start isIncluded. First operand has 443 states, 341 states have (on average 1.5043988269794721) internal successors, (513), 347 states have internal predecessors, (513), 74 states have call successors, (74), 24 states have call predecessors, (74), 27 states have return successors, (81), 73 states have call predecessors, (81), 73 states have call successors, (81) Second operand 657 states. [2022-02-20 17:56:29,734 INFO L87 Difference]: Start difference. First operand has 443 states, 341 states have (on average 1.5043988269794721) internal successors, (513), 347 states have internal predecessors, (513), 74 states have call successors, (74), 24 states have call predecessors, (74), 27 states have return successors, (81), 73 states have call predecessors, (81), 73 states have call successors, (81) Second operand 657 states. [2022-02-20 17:56:29,751 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-02-20 17:56:29,751 INFO L93 Difference]: Finished difference Result 657 states and 998 transitions. [2022-02-20 17:56:29,751 INFO L276 IsEmpty]: Start isEmpty. Operand 657 states and 998 transitions. [2022-02-20 17:56:29,754 INFO L282 IsEmpty]: Finished isEmpty. No accepting run. [2022-02-20 17:56:29,755 INFO L83 IsIncluded]: Finished isIncluded. Language is included [2022-02-20 17:56:29,755 INFO L88 GeneralOperation]: Finished isEquivalent. [2022-02-20 17:56:29,755 INFO L221 AbstractMinimizeNwa]: Finished testing correctness of minimizeSevpa [2022-02-20 17:56:29,756 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 443 states, 341 states have (on average 1.5043988269794721) internal successors, (513), 347 states have internal predecessors, (513), 74 states have call successors, (74), 24 states have call predecessors, (74), 27 states have return successors, (81), 73 states have call predecessors, (81), 73 states have call successors, (81) [2022-02-20 17:56:29,767 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 443 states to 443 states and 668 transitions. [2022-02-20 17:56:29,767 INFO L78 Accepts]: Start accepts. Automaton has 443 states and 668 transitions. Word has length 115 [2022-02-20 17:56:29,767 INFO L84 Accepts]: Finished accepts. word is rejected. [2022-02-20 17:56:29,768 INFO L470 AbstractCegarLoop]: Abstraction has 443 states and 668 transitions. [2022-02-20 17:56:29,768 INFO L471 AbstractCegarLoop]: INTERPOLANT automaton has has 9 states, 8 states have (on average 9.5) internal successors, (76), 5 states have internal predecessors, (76), 3 states have call successors, (15), 6 states have call predecessors, (15), 2 states have return successors, (13), 2 states have call predecessors, (13), 3 states have call successors, (13) [2022-02-20 17:56:29,768 INFO L276 IsEmpty]: Start isEmpty. Operand 443 states and 668 transitions. [2022-02-20 17:56:29,769 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 117 [2022-02-20 17:56:29,770 INFO L506 BasicCegarLoop]: Found error trace [2022-02-20 17:56:29,770 INFO L514 BasicCegarLoop]: trace histogram [3, 3, 3, 3, 2, 2, 2, 2, 2, 2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-02-20 17:56:29,770 WARN L452 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable6 [2022-02-20 17:56:29,770 INFO L402 AbstractCegarLoop]: === Iteration 8 === Targeting outgoingErr0ASSERT_VIOLATIONERROR_FUNCTION === [outgoingErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2022-02-20 17:56:29,771 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2022-02-20 17:56:29,771 INFO L85 PathProgramCache]: Analyzing trace with hash -358266326, now seen corresponding path program 1 times [2022-02-20 17:56:29,771 INFO L126 FreeRefinementEngine]: Executing refinement strategy CAMEL [2022-02-20 17:56:29,771 INFO L338 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [714484407] [2022-02-20 17:56:29,771 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-02-20 17:56:29,771 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2022-02-20 17:56:29,797 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-02-20 17:56:29,824 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 6 [2022-02-20 17:56:29,825 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-02-20 17:56:29,827 INFO L290 TraceCheckUtils]: 0: Hoare triple {21942#(and (= |old(~__ste_client_idCounter0~0)| ~__ste_client_idCounter0~0) (= |old(~__ste_client_idCounter1~0)| ~__ste_client_idCounter1~0) (= |old(~__ste_client_idCounter2~0)| ~__ste_client_idCounter2~0))} ~handle := #in~handle;~value := #in~value; {21881#true} is VALID [2022-02-20 17:56:29,827 INFO L290 TraceCheckUtils]: 1: Hoare triple {21881#true} assume 1 == ~handle;~__ste_client_idCounter0~0 := ~value; {21881#true} is VALID [2022-02-20 17:56:29,827 INFO L290 TraceCheckUtils]: 2: Hoare triple {21881#true} assume true; {21881#true} is VALID [2022-02-20 17:56:29,828 INFO L284 TraceCheckUtils]: 3: Hoare quadruple {21881#true} {21881#true} #1133#return; {21881#true} is VALID [2022-02-20 17:56:29,832 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 12 [2022-02-20 17:56:29,834 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-02-20 17:56:29,835 INFO L290 TraceCheckUtils]: 0: Hoare triple {21943#(and (= ~__ste_client_privateKey0~0 |old(~__ste_client_privateKey0~0)|) (= ~__ste_client_privateKey2~0 |old(~__ste_client_privateKey2~0)|) (= ~__ste_client_privateKey1~0 |old(~__ste_client_privateKey1~0)|))} ~handle := #in~handle;~value := #in~value; {21881#true} is VALID [2022-02-20 17:56:29,836 INFO L290 TraceCheckUtils]: 1: Hoare triple {21881#true} assume 1 == ~handle;~__ste_client_privateKey0~0 := ~value; {21881#true} is VALID [2022-02-20 17:56:29,836 INFO L290 TraceCheckUtils]: 2: Hoare triple {21881#true} assume true; {21881#true} is VALID [2022-02-20 17:56:29,836 INFO L284 TraceCheckUtils]: 3: Hoare quadruple {21881#true} {21881#true} #1135#return; {21881#true} is VALID [2022-02-20 17:56:29,836 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 18 [2022-02-20 17:56:29,837 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-02-20 17:56:29,839 INFO L290 TraceCheckUtils]: 0: Hoare triple {21942#(and (= |old(~__ste_client_idCounter0~0)| ~__ste_client_idCounter0~0) (= |old(~__ste_client_idCounter1~0)| ~__ste_client_idCounter1~0) (= |old(~__ste_client_idCounter2~0)| ~__ste_client_idCounter2~0))} ~handle := #in~handle;~value := #in~value; {21881#true} is VALID [2022-02-20 17:56:29,839 INFO L290 TraceCheckUtils]: 1: Hoare triple {21881#true} assume !(1 == ~handle); {21881#true} is VALID [2022-02-20 17:56:29,839 INFO L290 TraceCheckUtils]: 2: Hoare triple {21881#true} assume 2 == ~handle;~__ste_client_idCounter1~0 := ~value; {21881#true} is VALID [2022-02-20 17:56:29,839 INFO L290 TraceCheckUtils]: 3: Hoare triple {21881#true} assume true; {21881#true} is VALID [2022-02-20 17:56:29,839 INFO L284 TraceCheckUtils]: 4: Hoare quadruple {21881#true} {21881#true} #1137#return; {21881#true} is VALID [2022-02-20 17:56:29,839 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 25 [2022-02-20 17:56:29,841 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-02-20 17:56:29,843 INFO L290 TraceCheckUtils]: 0: Hoare triple {21943#(and (= ~__ste_client_privateKey0~0 |old(~__ste_client_privateKey0~0)|) (= ~__ste_client_privateKey2~0 |old(~__ste_client_privateKey2~0)|) (= ~__ste_client_privateKey1~0 |old(~__ste_client_privateKey1~0)|))} ~handle := #in~handle;~value := #in~value; {21881#true} is VALID [2022-02-20 17:56:29,843 INFO L290 TraceCheckUtils]: 1: Hoare triple {21881#true} assume !(1 == ~handle); {21881#true} is VALID [2022-02-20 17:56:29,843 INFO L290 TraceCheckUtils]: 2: Hoare triple {21881#true} assume 2 == ~handle;~__ste_client_privateKey1~0 := ~value; {21881#true} is VALID [2022-02-20 17:56:29,843 INFO L290 TraceCheckUtils]: 3: Hoare triple {21881#true} assume true; {21881#true} is VALID [2022-02-20 17:56:29,843 INFO L284 TraceCheckUtils]: 4: Hoare quadruple {21881#true} {21881#true} #1139#return; {21881#true} is VALID [2022-02-20 17:56:29,844 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 32 [2022-02-20 17:56:29,852 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-02-20 17:56:29,865 INFO L290 TraceCheckUtils]: 0: Hoare triple {21942#(and (= |old(~__ste_client_idCounter0~0)| ~__ste_client_idCounter0~0) (= |old(~__ste_client_idCounter1~0)| ~__ste_client_idCounter1~0) (= |old(~__ste_client_idCounter2~0)| ~__ste_client_idCounter2~0))} ~handle := #in~handle;~value := #in~value; {21944#(= setClientId_~handle |setClientId_#in~handle|)} is VALID [2022-02-20 17:56:29,865 INFO L290 TraceCheckUtils]: 1: Hoare triple {21944#(= setClientId_~handle |setClientId_#in~handle|)} assume !(1 == ~handle); {21944#(= setClientId_~handle |setClientId_#in~handle|)} is VALID [2022-02-20 17:56:29,866 INFO L290 TraceCheckUtils]: 2: Hoare triple {21944#(= setClientId_~handle |setClientId_#in~handle|)} assume !(2 == ~handle); {21944#(= setClientId_~handle |setClientId_#in~handle|)} is VALID [2022-02-20 17:56:29,866 INFO L290 TraceCheckUtils]: 3: Hoare triple {21944#(= setClientId_~handle |setClientId_#in~handle|)} assume 3 == ~handle;~__ste_client_idCounter2~0 := ~value; {21945#(= 3 |setClientId_#in~handle|)} is VALID [2022-02-20 17:56:29,866 INFO L290 TraceCheckUtils]: 4: Hoare triple {21945#(= 3 |setClientId_#in~handle|)} assume true; {21945#(= 3 |setClientId_#in~handle|)} is VALID [2022-02-20 17:56:29,867 INFO L284 TraceCheckUtils]: 5: Hoare quadruple {21945#(= 3 |setClientId_#in~handle|)} {21901#(= |ULTIMATE.start_setup_chuck_~chuck___0#1| |ULTIMATE.start_setup_chuck__wrappee__Base_~chuck___0#1|)} #1141#return; {21908#(not (= |ULTIMATE.start_setup_chuck_~chuck___0#1| 1))} is VALID [2022-02-20 17:56:29,867 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 40 [2022-02-20 17:56:29,868 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-02-20 17:56:29,882 INFO L290 TraceCheckUtils]: 0: Hoare triple {21943#(and (= ~__ste_client_privateKey0~0 |old(~__ste_client_privateKey0~0)|) (= ~__ste_client_privateKey2~0 |old(~__ste_client_privateKey2~0)|) (= ~__ste_client_privateKey1~0 |old(~__ste_client_privateKey1~0)|))} ~handle := #in~handle;~value := #in~value; {21946#(= setClientPrivateKey_~handle |setClientPrivateKey_#in~handle|)} is VALID [2022-02-20 17:56:29,883 INFO L290 TraceCheckUtils]: 1: Hoare triple {21946#(= setClientPrivateKey_~handle |setClientPrivateKey_#in~handle|)} assume 1 == ~handle;~__ste_client_privateKey0~0 := ~value; {21947#(= |setClientPrivateKey_#in~handle| 1)} is VALID [2022-02-20 17:56:29,883 INFO L290 TraceCheckUtils]: 2: Hoare triple {21947#(= |setClientPrivateKey_#in~handle| 1)} assume true; {21947#(= |setClientPrivateKey_#in~handle| 1)} is VALID [2022-02-20 17:56:29,883 INFO L284 TraceCheckUtils]: 3: Hoare quadruple {21947#(= |setClientPrivateKey_#in~handle| 1)} {21908#(not (= |ULTIMATE.start_setup_chuck_~chuck___0#1| 1))} #1143#return; {21882#false} is VALID [2022-02-20 17:56:29,891 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 62 [2022-02-20 17:56:29,892 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-02-20 17:56:29,893 INFO L290 TraceCheckUtils]: 0: Hoare triple {21948#(and (= |old(~__ste_email_from0~0)| ~__ste_email_from0~0) (= |old(~__ste_email_from1~0)| ~__ste_email_from1~0))} ~handle := #in~handle;~value := #in~value; {21881#true} is VALID [2022-02-20 17:56:29,894 INFO L290 TraceCheckUtils]: 1: Hoare triple {21881#true} assume 1 == ~handle;~__ste_email_from0~0 := ~value; {21881#true} is VALID [2022-02-20 17:56:29,894 INFO L290 TraceCheckUtils]: 2: Hoare triple {21881#true} assume true; {21881#true} is VALID [2022-02-20 17:56:29,894 INFO L284 TraceCheckUtils]: 3: Hoare quadruple {21881#true} {21882#false} #1119#return; {21882#false} is VALID [2022-02-20 17:56:29,902 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 67 [2022-02-20 17:56:29,903 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-02-20 17:56:29,905 INFO L290 TraceCheckUtils]: 0: Hoare triple {21949#(and (= ~__ste_email_to0~0 |old(~__ste_email_to0~0)|) (= ~__ste_email_to1~0 |old(~__ste_email_to1~0)|))} ~handle := #in~handle;~value := #in~value; {21881#true} is VALID [2022-02-20 17:56:29,905 INFO L290 TraceCheckUtils]: 1: Hoare triple {21881#true} assume 1 == ~handle;~__ste_email_to0~0 := ~value; {21881#true} is VALID [2022-02-20 17:56:29,905 INFO L290 TraceCheckUtils]: 2: Hoare triple {21881#true} assume true; {21881#true} is VALID [2022-02-20 17:56:29,905 INFO L284 TraceCheckUtils]: 3: Hoare quadruple {21881#true} {21882#false} #1121#return; {21882#false} is VALID [2022-02-20 17:56:29,905 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 76 [2022-02-20 17:56:29,906 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-02-20 17:56:29,908 INFO L290 TraceCheckUtils]: 0: Hoare triple {21881#true} ~handle := #in~handle;havoc ~retValue_acc~24; {21881#true} is VALID [2022-02-20 17:56:29,908 INFO L290 TraceCheckUtils]: 1: Hoare triple {21881#true} assume 1 == ~handle;~retValue_acc~24 := ~__ste_client_privateKey0~0;#res := ~retValue_acc~24; {21881#true} is VALID [2022-02-20 17:56:29,908 INFO L290 TraceCheckUtils]: 2: Hoare triple {21881#true} assume true; {21881#true} is VALID [2022-02-20 17:56:29,908 INFO L284 TraceCheckUtils]: 3: Hoare quadruple {21881#true} {21882#false} #1053#return; {21882#false} is VALID [2022-02-20 17:56:29,908 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 84 [2022-02-20 17:56:29,909 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-02-20 17:56:29,911 INFO L290 TraceCheckUtils]: 0: Hoare triple {21881#true} ~handle := #in~handle;havoc ~retValue_acc~36; {21881#true} is VALID [2022-02-20 17:56:29,911 INFO L290 TraceCheckUtils]: 1: Hoare triple {21881#true} assume 1 == ~handle;~retValue_acc~36 := ~__ste_email_to0~0;#res := ~retValue_acc~36; {21881#true} is VALID [2022-02-20 17:56:29,911 INFO L290 TraceCheckUtils]: 2: Hoare triple {21881#true} assume true; {21881#true} is VALID [2022-02-20 17:56:29,911 INFO L284 TraceCheckUtils]: 3: Hoare quadruple {21881#true} {21882#false} #1055#return; {21882#false} is VALID [2022-02-20 17:56:29,911 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 90 [2022-02-20 17:56:29,912 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-02-20 17:56:29,914 INFO L290 TraceCheckUtils]: 0: Hoare triple {21881#true} ~handle := #in~handle;~userid := #in~userid;havoc ~retValue_acc~29; {21881#true} is VALID [2022-02-20 17:56:29,914 INFO L290 TraceCheckUtils]: 1: Hoare triple {21881#true} assume 1 == ~handle; {21881#true} is VALID [2022-02-20 17:56:29,914 INFO L290 TraceCheckUtils]: 2: Hoare triple {21881#true} assume ~userid == ~__ste_Client_Keyring0_User0~0;~retValue_acc~29 := ~__ste_Client_Keyring0_PublicKey0~0;#res := ~retValue_acc~29; {21881#true} is VALID [2022-02-20 17:56:29,914 INFO L290 TraceCheckUtils]: 3: Hoare triple {21881#true} assume true; {21881#true} is VALID [2022-02-20 17:56:29,914 INFO L284 TraceCheckUtils]: 4: Hoare quadruple {21881#true} {21882#false} #1057#return; {21882#false} is VALID [2022-02-20 17:56:29,915 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 101 [2022-02-20 17:56:29,915 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-02-20 17:56:29,917 INFO L290 TraceCheckUtils]: 0: Hoare triple {21948#(and (= |old(~__ste_email_from0~0)| ~__ste_email_from0~0) (= |old(~__ste_email_from1~0)| ~__ste_email_from1~0))} ~handle := #in~handle;~value := #in~value; {21881#true} is VALID [2022-02-20 17:56:29,917 INFO L290 TraceCheckUtils]: 1: Hoare triple {21881#true} assume 1 == ~handle;~__ste_email_from0~0 := ~value; {21881#true} is VALID [2022-02-20 17:56:29,917 INFO L290 TraceCheckUtils]: 2: Hoare triple {21881#true} assume true; {21881#true} is VALID [2022-02-20 17:56:29,917 INFO L284 TraceCheckUtils]: 3: Hoare quadruple {21881#true} {21882#false} #1063#return; {21882#false} is VALID [2022-02-20 17:56:29,917 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 108 [2022-02-20 17:56:29,918 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-02-20 17:56:29,920 INFO L290 TraceCheckUtils]: 0: Hoare triple {21881#true} ~handle := #in~handle;havoc ~retValue_acc~39; {21881#true} is VALID [2022-02-20 17:56:29,920 INFO L290 TraceCheckUtils]: 1: Hoare triple {21881#true} assume 1 == ~handle;~retValue_acc~39 := ~__ste_email_isEncrypted0~0;#res := ~retValue_acc~39; {21881#true} is VALID [2022-02-20 17:56:29,920 INFO L290 TraceCheckUtils]: 2: Hoare triple {21881#true} assume true; {21881#true} is VALID [2022-02-20 17:56:29,920 INFO L284 TraceCheckUtils]: 3: Hoare quadruple {21881#true} {21882#false} #1067#return; {21882#false} is VALID [2022-02-20 17:56:29,920 INFO L290 TraceCheckUtils]: 0: Hoare triple {21881#true} assume { :begin_inline_ULTIMATE.init } true;#NULL.base, #NULL.offset := 0, 0;assume 0 == #valid[0];assume 0 < #StackHeapBarrier;call #Ultimate.allocInit(2, 1);call write~init~int(48, 1, 0, 1);call write~init~int(0, 1, 1, 1);call #Ultimate.allocInit(28, 2);call #Ultimate.allocInit(12, 3);call #Ultimate.allocInit(4, 4);call write~init~int(37, 4, 0, 1);call write~init~int(115, 4, 1, 1);call write~init~int(10, 4, 2, 1);call write~init~int(0, 4, 3, 1);call #Ultimate.allocInit(10, 5);call #Ultimate.allocInit(12, 6);call #Ultimate.allocInit(10, 7);call #Ultimate.allocInit(18, 8);call #Ultimate.allocInit(16, 9);call #Ultimate.allocInit(21, 10);call #Ultimate.allocInit(13, 11);call #Ultimate.allocInit(16, 12);call #Ultimate.allocInit(25, 13);call #Ultimate.allocInit(30, 14);call #Ultimate.allocInit(9, 15);call #Ultimate.allocInit(21, 16);call #Ultimate.allocInit(30, 17);call #Ultimate.allocInit(9, 18);call #Ultimate.allocInit(21, 19);call #Ultimate.allocInit(30, 20);call #Ultimate.allocInit(9, 21);call #Ultimate.allocInit(25, 22);call #Ultimate.allocInit(30, 23);call #Ultimate.allocInit(9, 24);call #Ultimate.allocInit(25, 25);call #Ultimate.allocInit(10, 26);call #Ultimate.allocInit(16, 27);call #Ultimate.allocInit(20, 28);call #Ultimate.allocInit(22, 29);call #Ultimate.allocInit(21, 30);call #Ultimate.allocInit(13, 31);call #Ultimate.allocInit(44, 32);call #Ultimate.allocInit(44, 33);call #Ultimate.allocInit(9, 34);call #Ultimate.allocInit(9, 35);call #Ultimate.allocInit(11, 36);call #Ultimate.allocInit(19, 37);call #Ultimate.allocInit(4, 38);call write~init~int(37, 38, 0, 1);call write~init~int(100, 38, 1, 1);call write~init~int(10, 38, 2, 1);call write~init~int(0, 38, 3, 1);call #Ultimate.allocInit(4, 39);call write~init~int(37, 39, 0, 1);call write~init~int(100, 39, 1, 1);call write~init~int(10, 39, 2, 1);call write~init~int(0, 39, 3, 1);~__SELECTED_FEATURE_Base~0 := 0;~__SELECTED_FEATURE_Keys~0 := 0;~__SELECTED_FEATURE_Encrypt~0 := 0;~__SELECTED_FEATURE_AutoResponder~0 := 0;~__SELECTED_FEATURE_AddressBook~0 := 0;~__SELECTED_FEATURE_Sign~0 := 0;~__SELECTED_FEATURE_Forward~0 := 0;~__SELECTED_FEATURE_Verify~0 := 0;~__SELECTED_FEATURE_Decrypt~0 := 0;~__GUIDSL_ROOT_PRODUCTION~0 := 0;~__GUIDSL_NON_TERMINAL_main~0 := 0;~head~0.base, ~head~0.offset := 0, 0;~queue_empty~0 := 1;~queued_message~0 := 0;~queued_client~0 := 0;~mail_is_sensitive~0 := -1;~__ste_Client_counter~0 := 0;~__ste_client_name0~0.base, ~__ste_client_name0~0.offset := 0, 0;~__ste_client_name1~0.base, ~__ste_client_name1~0.offset := 0, 0;~__ste_client_name2~0.base, ~__ste_client_name2~0.offset := 0, 0;~__ste_client_outbuffer0~0 := 0;~__ste_client_outbuffer1~0 := 0;~__ste_client_outbuffer2~0 := 0;~__ste_client_outbuffer3~0 := 0;~__ste_ClientAddressBook_size0~0 := 0;~__ste_ClientAddressBook_size1~0 := 0;~__ste_ClientAddressBook_size2~0 := 0;~__ste_Client_AddressBook0_Alias0~0 := 0;~__ste_Client_AddressBook0_Alias1~0 := 0;~__ste_Client_AddressBook0_Alias2~0 := 0;~__ste_Client_AddressBook1_Alias0~0 := 0;~__ste_Client_AddressBook1_Alias1~0 := 0;~__ste_Client_AddressBook1_Alias2~0 := 0;~__ste_Client_AddressBook2_Alias0~0 := 0;~__ste_Client_AddressBook2_Alias1~0 := 0;~__ste_Client_AddressBook2_Alias2~0 := 0;~__ste_Client_AddressBook0_Address0~0 := 0;~__ste_Client_AddressBook0_Address1~0 := 0;~__ste_Client_AddressBook0_Address2~0 := 0;~__ste_Client_AddressBook1_Address0~0 := 0;~__ste_Client_AddressBook1_Address1~0 := 0;~__ste_Client_AddressBook1_Address2~0 := 0;~__ste_Client_AddressBook2_Address0~0 := 0;~__ste_Client_AddressBook2_Address1~0 := 0;~__ste_Client_AddressBook2_Address2~0 := 0;~__ste_client_autoResponse0~0 := 0;~__ste_client_autoResponse1~0 := 0;~__ste_client_autoResponse2~0 := 0;~__ste_client_privateKey0~0 := 0;~__ste_client_privateKey1~0 := 0;~__ste_client_privateKey2~0 := 0;~__ste_ClientKeyring_size0~0 := 0;~__ste_ClientKeyring_size1~0 := 0;~__ste_ClientKeyring_size2~0 := 0;~__ste_Client_Keyring0_User0~0 := 0;~__ste_Client_Keyring0_User1~0 := 0;~__ste_Client_Keyring0_User2~0 := 0;~__ste_Client_Keyring1_User0~0 := 0;~__ste_Client_Keyring1_User1~0 := 0;~__ste_Client_Keyring1_User2~0 := 0;~__ste_Client_Keyring2_User0~0 := 0;~__ste_Client_Keyring2_User1~0 := 0;~__ste_Client_Keyring2_User2~0 := 0;~__ste_Client_Keyring0_PublicKey0~0 := 0;~__ste_Client_Keyring0_PublicKey1~0 := 0;~__ste_Client_Keyring0_PublicKey2~0 := 0;~__ste_Client_Keyring1_PublicKey0~0 := 0;~__ste_Client_Keyring1_PublicKey1~0 := 0;~__ste_Client_Keyring1_PublicKey2~0 := 0;~__ste_Client_Keyring2_PublicKey0~0 := 0;~__ste_Client_Keyring2_PublicKey1~0 := 0;~__ste_Client_Keyring2_PublicKey2~0 := 0;~__ste_client_forwardReceiver0~0 := 0;~__ste_client_forwardReceiver1~0 := 0;~__ste_client_forwardReceiver2~0 := 0;~__ste_client_forwardReceiver3~0 := 0;~__ste_client_idCounter0~0 := 0;~__ste_client_idCounter1~0 := 0;~__ste_client_idCounter2~0 := 0;~bob~0 := 0;~rjh~0 := 0;~chuck~0 := 0;~__ste_Email_counter~0 := 0;~__ste_email_id0~0 := 0;~__ste_email_id1~0 := 0;~__ste_email_from0~0 := 0;~__ste_email_from1~0 := 0;~__ste_email_to0~0 := 0;~__ste_email_to1~0 := 0;~__ste_email_subject0~0.base, ~__ste_email_subject0~0.offset := 0, 0;~__ste_email_subject1~0.base, ~__ste_email_subject1~0.offset := 0, 0;~__ste_email_body0~0.base, ~__ste_email_body0~0.offset := 0, 0;~__ste_email_body1~0.base, ~__ste_email_body1~0.offset := 0, 0;~__ste_email_isEncrypted0~0 := 0;~__ste_email_isEncrypted1~0 := 0;~__ste_email_encryptionKey0~0 := 0;~__ste_email_encryptionKey1~0 := 0;~__ste_email_isSigned0~0 := 0;~__ste_email_isSigned1~0 := 0;~__ste_email_signKey0~0 := 0;~__ste_email_signKey1~0 := 0;~__ste_email_isSignatureVerified0~0 := 0;~__ste_email_isSignatureVerified1~0 := 0; {21881#true} is VALID [2022-02-20 17:56:29,920 INFO L290 TraceCheckUtils]: 1: Hoare triple {21881#true} assume { :end_inline_ULTIMATE.init } true;assume { :begin_inline_main } true;havoc main_#res#1;havoc main_#t~ret98#1, main_~retValue_acc~32#1, main_~tmp~24#1;havoc main_~retValue_acc~32#1;havoc main_~tmp~24#1;assume { :begin_inline_select_helpers } true; {21881#true} is VALID [2022-02-20 17:56:29,920 INFO L290 TraceCheckUtils]: 2: Hoare triple {21881#true} assume { :end_inline_select_helpers } true;assume { :begin_inline_select_features } true; {21881#true} is VALID [2022-02-20 17:56:29,921 INFO L290 TraceCheckUtils]: 3: Hoare triple {21881#true} assume { :end_inline_select_features } true;assume { :begin_inline_valid_product } true;havoc valid_product_#res#1;havoc valid_product_~retValue_acc~9#1;havoc valid_product_~retValue_acc~9#1;valid_product_~retValue_acc~9#1 := 1;valid_product_#res#1 := valid_product_~retValue_acc~9#1; {21881#true} is VALID [2022-02-20 17:56:29,921 INFO L290 TraceCheckUtils]: 4: Hoare triple {21881#true} main_#t~ret98#1 := valid_product_#res#1;assume { :end_inline_valid_product } true;assume -2147483648 <= main_#t~ret98#1 && main_#t~ret98#1 <= 2147483647;main_~tmp~24#1 := main_#t~ret98#1;havoc main_#t~ret98#1; {21881#true} is VALID [2022-02-20 17:56:29,921 INFO L290 TraceCheckUtils]: 5: Hoare triple {21881#true} assume 0 != main_~tmp~24#1;assume { :begin_inline_setup } true;havoc setup_#t~nondet95#1, setup_#t~nondet96#1, setup_#t~nondet97#1, setup_~__cil_tmp1~0#1.base, setup_~__cil_tmp1~0#1.offset, setup_~__cil_tmp2~0#1.base, setup_~__cil_tmp2~0#1.offset, setup_~__cil_tmp3~2#1.base, setup_~__cil_tmp3~2#1.offset;havoc setup_~__cil_tmp1~0#1.base, setup_~__cil_tmp1~0#1.offset;havoc setup_~__cil_tmp2~0#1.base, setup_~__cil_tmp2~0#1.offset;havoc setup_~__cil_tmp3~2#1.base, setup_~__cil_tmp3~2#1.offset;~bob~0 := 1;assume { :begin_inline_setup_bob } true;setup_bob_#in~bob___0#1 := ~bob~0;havoc setup_bob_~bob___0#1;setup_bob_~bob___0#1 := setup_bob_#in~bob___0#1;assume { :begin_inline_setup_bob__wrappee__Base } true;setup_bob__wrappee__Base_#in~bob___0#1 := setup_bob_~bob___0#1;havoc setup_bob__wrappee__Base_~bob___0#1;setup_bob__wrappee__Base_~bob___0#1 := setup_bob__wrappee__Base_#in~bob___0#1; {21881#true} is VALID [2022-02-20 17:56:29,921 INFO L272 TraceCheckUtils]: 6: Hoare triple {21881#true} call setClientId(setup_bob__wrappee__Base_~bob___0#1, setup_bob__wrappee__Base_~bob___0#1); {21942#(and (= |old(~__ste_client_idCounter0~0)| ~__ste_client_idCounter0~0) (= |old(~__ste_client_idCounter1~0)| ~__ste_client_idCounter1~0) (= |old(~__ste_client_idCounter2~0)| ~__ste_client_idCounter2~0))} is VALID [2022-02-20 17:56:29,921 INFO L290 TraceCheckUtils]: 7: Hoare triple {21942#(and (= |old(~__ste_client_idCounter0~0)| ~__ste_client_idCounter0~0) (= |old(~__ste_client_idCounter1~0)| ~__ste_client_idCounter1~0) (= |old(~__ste_client_idCounter2~0)| ~__ste_client_idCounter2~0))} ~handle := #in~handle;~value := #in~value; {21881#true} is VALID [2022-02-20 17:56:29,922 INFO L290 TraceCheckUtils]: 8: Hoare triple {21881#true} assume 1 == ~handle;~__ste_client_idCounter0~0 := ~value; {21881#true} is VALID [2022-02-20 17:56:29,922 INFO L290 TraceCheckUtils]: 9: Hoare triple {21881#true} assume true; {21881#true} is VALID [2022-02-20 17:56:29,922 INFO L284 TraceCheckUtils]: 10: Hoare quadruple {21881#true} {21881#true} #1133#return; {21881#true} is VALID [2022-02-20 17:56:29,922 INFO L290 TraceCheckUtils]: 11: Hoare triple {21881#true} assume { :end_inline_setup_bob__wrappee__Base } true; {21881#true} is VALID [2022-02-20 17:56:29,922 INFO L272 TraceCheckUtils]: 12: Hoare triple {21881#true} call setClientPrivateKey(setup_bob_~bob___0#1, 123); {21943#(and (= ~__ste_client_privateKey0~0 |old(~__ste_client_privateKey0~0)|) (= ~__ste_client_privateKey2~0 |old(~__ste_client_privateKey2~0)|) (= ~__ste_client_privateKey1~0 |old(~__ste_client_privateKey1~0)|))} is VALID [2022-02-20 17:56:29,923 INFO L290 TraceCheckUtils]: 13: Hoare triple {21943#(and (= ~__ste_client_privateKey0~0 |old(~__ste_client_privateKey0~0)|) (= ~__ste_client_privateKey2~0 |old(~__ste_client_privateKey2~0)|) (= ~__ste_client_privateKey1~0 |old(~__ste_client_privateKey1~0)|))} ~handle := #in~handle;~value := #in~value; {21881#true} is VALID [2022-02-20 17:56:29,923 INFO L290 TraceCheckUtils]: 14: Hoare triple {21881#true} assume 1 == ~handle;~__ste_client_privateKey0~0 := ~value; {21881#true} is VALID [2022-02-20 17:56:29,923 INFO L290 TraceCheckUtils]: 15: Hoare triple {21881#true} assume true; {21881#true} is VALID [2022-02-20 17:56:29,923 INFO L284 TraceCheckUtils]: 16: Hoare quadruple {21881#true} {21881#true} #1135#return; {21881#true} is VALID [2022-02-20 17:56:29,923 INFO L290 TraceCheckUtils]: 17: Hoare triple {21881#true} assume { :end_inline_setup_bob } true;setup_~__cil_tmp1~0#1.base, setup_~__cil_tmp1~0#1.offset := 34, 0;havoc setup_#t~nondet95#1;~rjh~0 := 2;assume { :begin_inline_setup_rjh } true;setup_rjh_#in~rjh___0#1 := ~rjh~0;havoc setup_rjh_~rjh___0#1;setup_rjh_~rjh___0#1 := setup_rjh_#in~rjh___0#1;assume { :begin_inline_setup_rjh__wrappee__Base } true;setup_rjh__wrappee__Base_#in~rjh___0#1 := setup_rjh_~rjh___0#1;havoc setup_rjh__wrappee__Base_~rjh___0#1;setup_rjh__wrappee__Base_~rjh___0#1 := setup_rjh__wrappee__Base_#in~rjh___0#1; {21881#true} is VALID [2022-02-20 17:56:29,924 INFO L272 TraceCheckUtils]: 18: Hoare triple {21881#true} call setClientId(setup_rjh__wrappee__Base_~rjh___0#1, setup_rjh__wrappee__Base_~rjh___0#1); {21942#(and (= |old(~__ste_client_idCounter0~0)| ~__ste_client_idCounter0~0) (= |old(~__ste_client_idCounter1~0)| ~__ste_client_idCounter1~0) (= |old(~__ste_client_idCounter2~0)| ~__ste_client_idCounter2~0))} is VALID [2022-02-20 17:56:29,924 INFO L290 TraceCheckUtils]: 19: Hoare triple {21942#(and (= |old(~__ste_client_idCounter0~0)| ~__ste_client_idCounter0~0) (= |old(~__ste_client_idCounter1~0)| ~__ste_client_idCounter1~0) (= |old(~__ste_client_idCounter2~0)| ~__ste_client_idCounter2~0))} ~handle := #in~handle;~value := #in~value; {21881#true} is VALID [2022-02-20 17:56:29,924 INFO L290 TraceCheckUtils]: 20: Hoare triple {21881#true} assume !(1 == ~handle); {21881#true} is VALID [2022-02-20 17:56:29,924 INFO L290 TraceCheckUtils]: 21: Hoare triple {21881#true} assume 2 == ~handle;~__ste_client_idCounter1~0 := ~value; {21881#true} is VALID [2022-02-20 17:56:29,924 INFO L290 TraceCheckUtils]: 22: Hoare triple {21881#true} assume true; {21881#true} is VALID [2022-02-20 17:56:29,924 INFO L284 TraceCheckUtils]: 23: Hoare quadruple {21881#true} {21881#true} #1137#return; {21881#true} is VALID [2022-02-20 17:56:29,924 INFO L290 TraceCheckUtils]: 24: Hoare triple {21881#true} assume { :end_inline_setup_rjh__wrappee__Base } true; {21881#true} is VALID [2022-02-20 17:56:29,925 INFO L272 TraceCheckUtils]: 25: Hoare triple {21881#true} call setClientPrivateKey(setup_rjh_~rjh___0#1, 456); {21943#(and (= ~__ste_client_privateKey0~0 |old(~__ste_client_privateKey0~0)|) (= ~__ste_client_privateKey2~0 |old(~__ste_client_privateKey2~0)|) (= ~__ste_client_privateKey1~0 |old(~__ste_client_privateKey1~0)|))} is VALID [2022-02-20 17:56:29,925 INFO L290 TraceCheckUtils]: 26: Hoare triple {21943#(and (= ~__ste_client_privateKey0~0 |old(~__ste_client_privateKey0~0)|) (= ~__ste_client_privateKey2~0 |old(~__ste_client_privateKey2~0)|) (= ~__ste_client_privateKey1~0 |old(~__ste_client_privateKey1~0)|))} ~handle := #in~handle;~value := #in~value; {21881#true} is VALID [2022-02-20 17:56:29,925 INFO L290 TraceCheckUtils]: 27: Hoare triple {21881#true} assume !(1 == ~handle); {21881#true} is VALID [2022-02-20 17:56:29,925 INFO L290 TraceCheckUtils]: 28: Hoare triple {21881#true} assume 2 == ~handle;~__ste_client_privateKey1~0 := ~value; {21881#true} is VALID [2022-02-20 17:56:29,925 INFO L290 TraceCheckUtils]: 29: Hoare triple {21881#true} assume true; {21881#true} is VALID [2022-02-20 17:56:29,925 INFO L284 TraceCheckUtils]: 30: Hoare quadruple {21881#true} {21881#true} #1139#return; {21881#true} is VALID [2022-02-20 17:56:29,926 INFO L290 TraceCheckUtils]: 31: Hoare triple {21881#true} assume { :end_inline_setup_rjh } true;setup_~__cil_tmp2~0#1.base, setup_~__cil_tmp2~0#1.offset := 35, 0;havoc setup_#t~nondet96#1;~chuck~0 := 3;assume { :begin_inline_setup_chuck } true;setup_chuck_#in~chuck___0#1 := ~chuck~0;havoc setup_chuck_~chuck___0#1;setup_chuck_~chuck___0#1 := setup_chuck_#in~chuck___0#1;assume { :begin_inline_setup_chuck__wrappee__Base } true;setup_chuck__wrappee__Base_#in~chuck___0#1 := setup_chuck_~chuck___0#1;havoc setup_chuck__wrappee__Base_~chuck___0#1;setup_chuck__wrappee__Base_~chuck___0#1 := setup_chuck__wrappee__Base_#in~chuck___0#1; {21901#(= |ULTIMATE.start_setup_chuck_~chuck___0#1| |ULTIMATE.start_setup_chuck__wrappee__Base_~chuck___0#1|)} is VALID [2022-02-20 17:56:29,926 INFO L272 TraceCheckUtils]: 32: Hoare triple {21901#(= |ULTIMATE.start_setup_chuck_~chuck___0#1| |ULTIMATE.start_setup_chuck__wrappee__Base_~chuck___0#1|)} call setClientId(setup_chuck__wrappee__Base_~chuck___0#1, setup_chuck__wrappee__Base_~chuck___0#1); {21942#(and (= |old(~__ste_client_idCounter0~0)| ~__ste_client_idCounter0~0) (= |old(~__ste_client_idCounter1~0)| ~__ste_client_idCounter1~0) (= |old(~__ste_client_idCounter2~0)| ~__ste_client_idCounter2~0))} is VALID [2022-02-20 17:56:29,927 INFO L290 TraceCheckUtils]: 33: Hoare triple {21942#(and (= |old(~__ste_client_idCounter0~0)| ~__ste_client_idCounter0~0) (= |old(~__ste_client_idCounter1~0)| ~__ste_client_idCounter1~0) (= |old(~__ste_client_idCounter2~0)| ~__ste_client_idCounter2~0))} ~handle := #in~handle;~value := #in~value; {21944#(= setClientId_~handle |setClientId_#in~handle|)} is VALID [2022-02-20 17:56:29,927 INFO L290 TraceCheckUtils]: 34: Hoare triple {21944#(= setClientId_~handle |setClientId_#in~handle|)} assume !(1 == ~handle); {21944#(= setClientId_~handle |setClientId_#in~handle|)} is VALID [2022-02-20 17:56:29,927 INFO L290 TraceCheckUtils]: 35: Hoare triple {21944#(= setClientId_~handle |setClientId_#in~handle|)} assume !(2 == ~handle); {21944#(= setClientId_~handle |setClientId_#in~handle|)} is VALID [2022-02-20 17:56:29,927 INFO L290 TraceCheckUtils]: 36: Hoare triple {21944#(= setClientId_~handle |setClientId_#in~handle|)} assume 3 == ~handle;~__ste_client_idCounter2~0 := ~value; {21945#(= 3 |setClientId_#in~handle|)} is VALID [2022-02-20 17:56:29,928 INFO L290 TraceCheckUtils]: 37: Hoare triple {21945#(= 3 |setClientId_#in~handle|)} assume true; {21945#(= 3 |setClientId_#in~handle|)} is VALID [2022-02-20 17:56:29,928 INFO L284 TraceCheckUtils]: 38: Hoare quadruple {21945#(= 3 |setClientId_#in~handle|)} {21901#(= |ULTIMATE.start_setup_chuck_~chuck___0#1| |ULTIMATE.start_setup_chuck__wrappee__Base_~chuck___0#1|)} #1141#return; {21908#(not (= |ULTIMATE.start_setup_chuck_~chuck___0#1| 1))} is VALID [2022-02-20 17:56:29,928 INFO L290 TraceCheckUtils]: 39: Hoare triple {21908#(not (= |ULTIMATE.start_setup_chuck_~chuck___0#1| 1))} assume { :end_inline_setup_chuck__wrappee__Base } true; {21908#(not (= |ULTIMATE.start_setup_chuck_~chuck___0#1| 1))} is VALID [2022-02-20 17:56:29,929 INFO L272 TraceCheckUtils]: 40: Hoare triple {21908#(not (= |ULTIMATE.start_setup_chuck_~chuck___0#1| 1))} call setClientPrivateKey(setup_chuck_~chuck___0#1, 789); {21943#(and (= ~__ste_client_privateKey0~0 |old(~__ste_client_privateKey0~0)|) (= ~__ste_client_privateKey2~0 |old(~__ste_client_privateKey2~0)|) (= ~__ste_client_privateKey1~0 |old(~__ste_client_privateKey1~0)|))} is VALID [2022-02-20 17:56:29,929 INFO L290 TraceCheckUtils]: 41: Hoare triple {21943#(and (= ~__ste_client_privateKey0~0 |old(~__ste_client_privateKey0~0)|) (= ~__ste_client_privateKey2~0 |old(~__ste_client_privateKey2~0)|) (= ~__ste_client_privateKey1~0 |old(~__ste_client_privateKey1~0)|))} ~handle := #in~handle;~value := #in~value; {21946#(= setClientPrivateKey_~handle |setClientPrivateKey_#in~handle|)} is VALID [2022-02-20 17:56:29,930 INFO L290 TraceCheckUtils]: 42: Hoare triple {21946#(= setClientPrivateKey_~handle |setClientPrivateKey_#in~handle|)} assume 1 == ~handle;~__ste_client_privateKey0~0 := ~value; {21947#(= |setClientPrivateKey_#in~handle| 1)} is VALID [2022-02-20 17:56:29,930 INFO L290 TraceCheckUtils]: 43: Hoare triple {21947#(= |setClientPrivateKey_#in~handle| 1)} assume true; {21947#(= |setClientPrivateKey_#in~handle| 1)} is VALID [2022-02-20 17:56:29,930 INFO L284 TraceCheckUtils]: 44: Hoare quadruple {21947#(= |setClientPrivateKey_#in~handle| 1)} {21908#(not (= |ULTIMATE.start_setup_chuck_~chuck___0#1| 1))} #1143#return; {21882#false} is VALID [2022-02-20 17:56:29,931 INFO L290 TraceCheckUtils]: 45: Hoare triple {21882#false} assume { :end_inline_setup_chuck } true;setup_~__cil_tmp3~2#1.base, setup_~__cil_tmp3~2#1.offset := 36, 0;havoc setup_#t~nondet97#1; {21882#false} is VALID [2022-02-20 17:56:29,931 INFO L290 TraceCheckUtils]: 46: Hoare triple {21882#false} assume { :end_inline_setup } true;assume { :begin_inline_test } true;havoc test_#t~nondet48#1, test_#t~nondet49#1, test_#t~nondet50#1, test_#t~nondet51#1, test_#t~nondet52#1, test_#t~nondet53#1, test_#t~nondet54#1, test_#t~nondet55#1, test_#t~nondet56#1, test_#t~nondet57#1, test_#t~nondet58#1, test_~op1~0#1, test_~op2~0#1, test_~op3~0#1, test_~op4~0#1, test_~op5~0#1, test_~op6~0#1, test_~op7~0#1, test_~op8~0#1, test_~op9~0#1, test_~op10~0#1, test_~op11~0#1, test_~splverifierCounter~0#1, test_~tmp~8#1, test_~tmp___0~3#1, test_~tmp___1~1#1, test_~tmp___2~1#1, test_~tmp___3~0#1, test_~tmp___4~0#1, test_~tmp___5~0#1, test_~tmp___6~0#1, test_~tmp___7~0#1, test_~tmp___8~0#1, test_~tmp___9~0#1;havoc test_~op1~0#1;havoc test_~op2~0#1;havoc test_~op3~0#1;havoc test_~op4~0#1;havoc test_~op5~0#1;havoc test_~op6~0#1;havoc test_~op7~0#1;havoc test_~op8~0#1;havoc test_~op9~0#1;havoc test_~op10~0#1;havoc test_~op11~0#1;havoc test_~splverifierCounter~0#1;havoc test_~tmp~8#1;havoc test_~tmp___0~3#1;havoc test_~tmp___1~1#1;havoc test_~tmp___2~1#1;havoc test_~tmp___3~0#1;havoc test_~tmp___4~0#1;havoc test_~tmp___5~0#1;havoc test_~tmp___6~0#1;havoc test_~tmp___7~0#1;havoc test_~tmp___8~0#1;havoc test_~tmp___9~0#1;test_~op1~0#1 := 0;test_~op2~0#1 := 0;test_~op3~0#1 := 0;test_~op4~0#1 := 0;test_~op5~0#1 := 0;test_~op6~0#1 := 0;test_~op7~0#1 := 0;test_~op8~0#1 := 0;test_~op9~0#1 := 0;test_~op10~0#1 := 0;test_~op11~0#1 := 0;test_~splverifierCounter~0#1 := 0; {21882#false} is VALID [2022-02-20 17:56:29,931 INFO L290 TraceCheckUtils]: 47: Hoare triple {21882#false} assume !false; {21882#false} is VALID [2022-02-20 17:56:29,931 INFO L290 TraceCheckUtils]: 48: Hoare triple {21882#false} assume test_~splverifierCounter~0#1 < 4; {21882#false} is VALID [2022-02-20 17:56:29,931 INFO L290 TraceCheckUtils]: 49: Hoare triple {21882#false} test_~splverifierCounter~0#1 := 1 + test_~splverifierCounter~0#1; {21882#false} is VALID [2022-02-20 17:56:29,931 INFO L290 TraceCheckUtils]: 50: Hoare triple {21882#false} assume 0 == test_~op1~0#1;assume -2147483648 <= test_#t~nondet48#1 && test_#t~nondet48#1 <= 2147483647;test_~tmp___9~0#1 := test_#t~nondet48#1;havoc test_#t~nondet48#1; {21882#false} is VALID [2022-02-20 17:56:29,931 INFO L290 TraceCheckUtils]: 51: Hoare triple {21882#false} assume !(0 != test_~tmp___9~0#1); {21882#false} is VALID [2022-02-20 17:56:29,931 INFO L290 TraceCheckUtils]: 52: Hoare triple {21882#false} assume 0 == test_~op2~0#1;assume -2147483648 <= test_#t~nondet49#1 && test_#t~nondet49#1 <= 2147483647;test_~tmp___8~0#1 := test_#t~nondet49#1;havoc test_#t~nondet49#1; {21882#false} is VALID [2022-02-20 17:56:29,931 INFO L290 TraceCheckUtils]: 53: Hoare triple {21882#false} assume 0 != test_~tmp___8~0#1;assume { :begin_inline_rjhSetAutoRespond } true;assume { :begin_inline_setClientAutoResponse } true;setClientAutoResponse_#in~handle#1, setClientAutoResponse_#in~value#1 := ~rjh~0, 1;havoc setClientAutoResponse_~handle#1, setClientAutoResponse_~value#1;setClientAutoResponse_~handle#1 := setClientAutoResponse_#in~handle#1;setClientAutoResponse_~value#1 := setClientAutoResponse_#in~value#1; {21882#false} is VALID [2022-02-20 17:56:29,931 INFO L290 TraceCheckUtils]: 54: Hoare triple {21882#false} assume 1 == setClientAutoResponse_~handle#1;~__ste_client_autoResponse0~0 := setClientAutoResponse_~value#1; {21882#false} is VALID [2022-02-20 17:56:29,932 INFO L290 TraceCheckUtils]: 55: Hoare triple {21882#false} assume { :end_inline_setClientAutoResponse } true; {21882#false} is VALID [2022-02-20 17:56:29,932 INFO L290 TraceCheckUtils]: 56: Hoare triple {21882#false} assume { :end_inline_rjhSetAutoRespond } true;test_~op2~0#1 := 1; {21882#false} is VALID [2022-02-20 17:56:29,932 INFO L290 TraceCheckUtils]: 57: Hoare triple {21882#false} assume !false; {21882#false} is VALID [2022-02-20 17:56:29,932 INFO L290 TraceCheckUtils]: 58: Hoare triple {21882#false} assume !(test_~splverifierCounter~0#1 < 4); {21882#false} is VALID [2022-02-20 17:56:29,932 INFO L290 TraceCheckUtils]: 59: Hoare triple {21882#false} assume { :begin_inline_bobToRjh } true;havoc bobToRjh_#t~ret90#1, bobToRjh_#t~ret91#1, bobToRjh_#t~ret92#1, bobToRjh_#t~ret93#1, bobToRjh_~tmp~23#1, bobToRjh_~tmp___0~7#1, bobToRjh_~tmp___1~4#1;havoc bobToRjh_~tmp~23#1;havoc bobToRjh_~tmp___0~7#1;havoc bobToRjh_~tmp___1~4#1;call bobToRjh_#t~ret90#1 := puts(32, 0);assume -2147483648 <= bobToRjh_#t~ret90#1 && bobToRjh_#t~ret90#1 <= 2147483647;havoc bobToRjh_#t~ret90#1; {21882#false} is VALID [2022-02-20 17:56:29,932 INFO L272 TraceCheckUtils]: 60: Hoare triple {21882#false} call sendEmail(~bob~0, ~rjh~0); {21882#false} is VALID [2022-02-20 17:56:29,932 INFO L290 TraceCheckUtils]: 61: Hoare triple {21882#false} ~sender#1 := #in~sender#1;~receiver#1 := #in~receiver#1;havoc ~email~0#1;havoc ~tmp~16#1;assume { :begin_inline_createEmail } true;createEmail_#in~from#1, createEmail_#in~to#1 := 0, ~receiver#1;havoc createEmail_#res#1;havoc createEmail_~from#1, createEmail_~to#1, createEmail_~retValue_acc~4#1, createEmail_~msg~0#1;createEmail_~from#1 := createEmail_#in~from#1;createEmail_~to#1 := createEmail_#in~to#1;havoc createEmail_~retValue_acc~4#1;havoc createEmail_~msg~0#1;createEmail_~msg~0#1 := 1; {21882#false} is VALID [2022-02-20 17:56:29,932 INFO L272 TraceCheckUtils]: 62: Hoare triple {21882#false} call setEmailFrom(createEmail_~msg~0#1, createEmail_~from#1); {21948#(and (= |old(~__ste_email_from0~0)| ~__ste_email_from0~0) (= |old(~__ste_email_from1~0)| ~__ste_email_from1~0))} is VALID [2022-02-20 17:56:29,932 INFO L290 TraceCheckUtils]: 63: Hoare triple {21948#(and (= |old(~__ste_email_from0~0)| ~__ste_email_from0~0) (= |old(~__ste_email_from1~0)| ~__ste_email_from1~0))} ~handle := #in~handle;~value := #in~value; {21881#true} is VALID [2022-02-20 17:56:29,932 INFO L290 TraceCheckUtils]: 64: Hoare triple {21881#true} assume 1 == ~handle;~__ste_email_from0~0 := ~value; {21881#true} is VALID [2022-02-20 17:56:29,933 INFO L290 TraceCheckUtils]: 65: Hoare triple {21881#true} assume true; {21881#true} is VALID [2022-02-20 17:56:29,933 INFO L284 TraceCheckUtils]: 66: Hoare quadruple {21881#true} {21882#false} #1119#return; {21882#false} is VALID [2022-02-20 17:56:29,933 INFO L272 TraceCheckUtils]: 67: Hoare triple {21882#false} call setEmailTo(createEmail_~msg~0#1, createEmail_~to#1); {21949#(and (= ~__ste_email_to0~0 |old(~__ste_email_to0~0)|) (= ~__ste_email_to1~0 |old(~__ste_email_to1~0)|))} is VALID [2022-02-20 17:56:29,933 INFO L290 TraceCheckUtils]: 68: Hoare triple {21949#(and (= ~__ste_email_to0~0 |old(~__ste_email_to0~0)|) (= ~__ste_email_to1~0 |old(~__ste_email_to1~0)|))} ~handle := #in~handle;~value := #in~value; {21881#true} is VALID [2022-02-20 17:56:29,933 INFO L290 TraceCheckUtils]: 69: Hoare triple {21881#true} assume 1 == ~handle;~__ste_email_to0~0 := ~value; {21881#true} is VALID [2022-02-20 17:56:29,933 INFO L290 TraceCheckUtils]: 70: Hoare triple {21881#true} assume true; {21881#true} is VALID [2022-02-20 17:56:29,933 INFO L284 TraceCheckUtils]: 71: Hoare quadruple {21881#true} {21882#false} #1121#return; {21882#false} is VALID [2022-02-20 17:56:29,933 INFO L290 TraceCheckUtils]: 72: Hoare triple {21882#false} createEmail_~retValue_acc~4#1 := createEmail_~msg~0#1;createEmail_#res#1 := createEmail_~retValue_acc~4#1; {21882#false} is VALID [2022-02-20 17:56:29,933 INFO L290 TraceCheckUtils]: 73: Hoare triple {21882#false} #t~ret73#1 := createEmail_#res#1;assume { :end_inline_createEmail } true;assume -2147483648 <= #t~ret73#1 && #t~ret73#1 <= 2147483647;~tmp~16#1 := #t~ret73#1;havoc #t~ret73#1;~email~0#1 := ~tmp~16#1; {21882#false} is VALID [2022-02-20 17:56:29,933 INFO L272 TraceCheckUtils]: 74: Hoare triple {21882#false} call outgoing(~sender#1, ~email~0#1); {21882#false} is VALID [2022-02-20 17:56:29,934 INFO L290 TraceCheckUtils]: 75: Hoare triple {21882#false} ~client#1 := #in~client#1;~msg#1 := #in~msg#1;assume { :begin_inline_sign } true;sign_#in~client#1, sign_#in~msg#1 := ~client#1, ~msg#1;havoc sign_#t~ret77#1, sign_~client#1, sign_~msg#1, sign_~privkey~1#1, sign_~tmp~18#1;sign_~client#1 := sign_#in~client#1;sign_~msg#1 := sign_#in~msg#1;havoc sign_~privkey~1#1;havoc sign_~tmp~18#1; {21882#false} is VALID [2022-02-20 17:56:29,934 INFO L272 TraceCheckUtils]: 76: Hoare triple {21882#false} call sign_#t~ret77#1 := getClientPrivateKey(sign_~client#1); {21881#true} is VALID [2022-02-20 17:56:29,934 INFO L290 TraceCheckUtils]: 77: Hoare triple {21881#true} ~handle := #in~handle;havoc ~retValue_acc~24; {21881#true} is VALID [2022-02-20 17:56:29,934 INFO L290 TraceCheckUtils]: 78: Hoare triple {21881#true} assume 1 == ~handle;~retValue_acc~24 := ~__ste_client_privateKey0~0;#res := ~retValue_acc~24; {21881#true} is VALID [2022-02-20 17:56:29,934 INFO L290 TraceCheckUtils]: 79: Hoare triple {21881#true} assume true; {21881#true} is VALID [2022-02-20 17:56:29,934 INFO L284 TraceCheckUtils]: 80: Hoare quadruple {21881#true} {21882#false} #1053#return; {21882#false} is VALID [2022-02-20 17:56:29,934 INFO L290 TraceCheckUtils]: 81: Hoare triple {21882#false} assume -2147483648 <= sign_#t~ret77#1 && sign_#t~ret77#1 <= 2147483647;sign_~tmp~18#1 := sign_#t~ret77#1;havoc sign_#t~ret77#1;sign_~privkey~1#1 := sign_~tmp~18#1; {21882#false} is VALID [2022-02-20 17:56:29,934 INFO L290 TraceCheckUtils]: 82: Hoare triple {21882#false} assume 0 == sign_~privkey~1#1; {21882#false} is VALID [2022-02-20 17:56:29,934 INFO L290 TraceCheckUtils]: 83: Hoare triple {21882#false} assume { :end_inline_sign } true;assume { :begin_inline_outgoing__wrappee__AutoResponder } true;outgoing__wrappee__AutoResponder_#in~client#1, outgoing__wrappee__AutoResponder_#in~msg#1 := ~client#1, ~msg#1;havoc outgoing__wrappee__AutoResponder_#t~ret63#1, outgoing__wrappee__AutoResponder_#t~ret64#1, outgoing__wrappee__AutoResponder_~client#1, outgoing__wrappee__AutoResponder_~msg#1, outgoing__wrappee__AutoResponder_~receiver~0#1, outgoing__wrappee__AutoResponder_~tmp~11#1, outgoing__wrappee__AutoResponder_~pubkey~0#1, outgoing__wrappee__AutoResponder_~tmp___0~4#1;outgoing__wrappee__AutoResponder_~client#1 := outgoing__wrappee__AutoResponder_#in~client#1;outgoing__wrappee__AutoResponder_~msg#1 := outgoing__wrappee__AutoResponder_#in~msg#1;havoc outgoing__wrappee__AutoResponder_~receiver~0#1;havoc outgoing__wrappee__AutoResponder_~tmp~11#1;havoc outgoing__wrappee__AutoResponder_~pubkey~0#1;havoc outgoing__wrappee__AutoResponder_~tmp___0~4#1; {21882#false} is VALID [2022-02-20 17:56:29,934 INFO L272 TraceCheckUtils]: 84: Hoare triple {21882#false} call outgoing__wrappee__AutoResponder_#t~ret63#1 := getEmailTo(outgoing__wrappee__AutoResponder_~msg#1); {21881#true} is VALID [2022-02-20 17:56:29,935 INFO L290 TraceCheckUtils]: 85: Hoare triple {21881#true} ~handle := #in~handle;havoc ~retValue_acc~36; {21881#true} is VALID [2022-02-20 17:56:29,935 INFO L290 TraceCheckUtils]: 86: Hoare triple {21881#true} assume 1 == ~handle;~retValue_acc~36 := ~__ste_email_to0~0;#res := ~retValue_acc~36; {21881#true} is VALID [2022-02-20 17:56:29,935 INFO L290 TraceCheckUtils]: 87: Hoare triple {21881#true} assume true; {21881#true} is VALID [2022-02-20 17:56:29,935 INFO L284 TraceCheckUtils]: 88: Hoare quadruple {21881#true} {21882#false} #1055#return; {21882#false} is VALID [2022-02-20 17:56:29,935 INFO L290 TraceCheckUtils]: 89: Hoare triple {21882#false} assume -2147483648 <= outgoing__wrappee__AutoResponder_#t~ret63#1 && outgoing__wrappee__AutoResponder_#t~ret63#1 <= 2147483647;outgoing__wrappee__AutoResponder_~tmp~11#1 := outgoing__wrappee__AutoResponder_#t~ret63#1;havoc outgoing__wrappee__AutoResponder_#t~ret63#1;outgoing__wrappee__AutoResponder_~receiver~0#1 := outgoing__wrappee__AutoResponder_~tmp~11#1; {21882#false} is VALID [2022-02-20 17:56:29,935 INFO L272 TraceCheckUtils]: 90: Hoare triple {21882#false} call outgoing__wrappee__AutoResponder_#t~ret64#1 := findPublicKey(outgoing__wrappee__AutoResponder_~client#1, outgoing__wrappee__AutoResponder_~receiver~0#1); {21881#true} is VALID [2022-02-20 17:56:29,935 INFO L290 TraceCheckUtils]: 91: Hoare triple {21881#true} ~handle := #in~handle;~userid := #in~userid;havoc ~retValue_acc~29; {21881#true} is VALID [2022-02-20 17:56:29,935 INFO L290 TraceCheckUtils]: 92: Hoare triple {21881#true} assume 1 == ~handle; {21881#true} is VALID [2022-02-20 17:56:29,935 INFO L290 TraceCheckUtils]: 93: Hoare triple {21881#true} assume ~userid == ~__ste_Client_Keyring0_User0~0;~retValue_acc~29 := ~__ste_Client_Keyring0_PublicKey0~0;#res := ~retValue_acc~29; {21881#true} is VALID [2022-02-20 17:56:29,935 INFO L290 TraceCheckUtils]: 94: Hoare triple {21881#true} assume true; {21881#true} is VALID [2022-02-20 17:56:29,936 INFO L284 TraceCheckUtils]: 95: Hoare quadruple {21881#true} {21882#false} #1057#return; {21882#false} is VALID [2022-02-20 17:56:29,936 INFO L290 TraceCheckUtils]: 96: Hoare triple {21882#false} assume -2147483648 <= outgoing__wrappee__AutoResponder_#t~ret64#1 && outgoing__wrappee__AutoResponder_#t~ret64#1 <= 2147483647;outgoing__wrappee__AutoResponder_~tmp___0~4#1 := outgoing__wrappee__AutoResponder_#t~ret64#1;havoc outgoing__wrappee__AutoResponder_#t~ret64#1;outgoing__wrappee__AutoResponder_~pubkey~0#1 := outgoing__wrappee__AutoResponder_~tmp___0~4#1; {21882#false} is VALID [2022-02-20 17:56:29,936 INFO L290 TraceCheckUtils]: 97: Hoare triple {21882#false} assume !(0 != outgoing__wrappee__AutoResponder_~pubkey~0#1); {21882#false} is VALID [2022-02-20 17:56:29,936 INFO L290 TraceCheckUtils]: 98: Hoare triple {21882#false} assume { :begin_inline_outgoing__wrappee__Keys } true;outgoing__wrappee__Keys_#in~client#1, outgoing__wrappee__Keys_#in~msg#1 := outgoing__wrappee__AutoResponder_~client#1, outgoing__wrappee__AutoResponder_~msg#1;havoc outgoing__wrappee__Keys_#t~ret62#1, outgoing__wrappee__Keys_~client#1, outgoing__wrappee__Keys_~msg#1, outgoing__wrappee__Keys_~tmp~10#1;outgoing__wrappee__Keys_~client#1 := outgoing__wrappee__Keys_#in~client#1;outgoing__wrappee__Keys_~msg#1 := outgoing__wrappee__Keys_#in~msg#1;havoc outgoing__wrappee__Keys_~tmp~10#1;assume { :begin_inline_getClientId } true;getClientId_#in~handle#1 := outgoing__wrappee__Keys_~client#1;havoc getClientId_#res#1;havoc getClientId_~handle#1, getClientId_~retValue_acc~31#1;getClientId_~handle#1 := getClientId_#in~handle#1;havoc getClientId_~retValue_acc~31#1; {21882#false} is VALID [2022-02-20 17:56:29,936 INFO L290 TraceCheckUtils]: 99: Hoare triple {21882#false} assume 1 == getClientId_~handle#1;getClientId_~retValue_acc~31#1 := ~__ste_client_idCounter0~0;getClientId_#res#1 := getClientId_~retValue_acc~31#1; {21882#false} is VALID [2022-02-20 17:56:29,936 INFO L290 TraceCheckUtils]: 100: Hoare triple {21882#false} outgoing__wrappee__Keys_#t~ret62#1 := getClientId_#res#1;assume { :end_inline_getClientId } true;assume -2147483648 <= outgoing__wrappee__Keys_#t~ret62#1 && outgoing__wrappee__Keys_#t~ret62#1 <= 2147483647;outgoing__wrappee__Keys_~tmp~10#1 := outgoing__wrappee__Keys_#t~ret62#1;havoc outgoing__wrappee__Keys_#t~ret62#1; {21882#false} is VALID [2022-02-20 17:56:29,936 INFO L272 TraceCheckUtils]: 101: Hoare triple {21882#false} call setEmailFrom(outgoing__wrappee__Keys_~msg#1, outgoing__wrappee__Keys_~tmp~10#1); {21948#(and (= |old(~__ste_email_from0~0)| ~__ste_email_from0~0) (= |old(~__ste_email_from1~0)| ~__ste_email_from1~0))} is VALID [2022-02-20 17:56:29,936 INFO L290 TraceCheckUtils]: 102: Hoare triple {21948#(and (= |old(~__ste_email_from0~0)| ~__ste_email_from0~0) (= |old(~__ste_email_from1~0)| ~__ste_email_from1~0))} ~handle := #in~handle;~value := #in~value; {21881#true} is VALID [2022-02-20 17:56:29,936 INFO L290 TraceCheckUtils]: 103: Hoare triple {21881#true} assume 1 == ~handle;~__ste_email_from0~0 := ~value; {21881#true} is VALID [2022-02-20 17:56:29,936 INFO L290 TraceCheckUtils]: 104: Hoare triple {21881#true} assume true; {21881#true} is VALID [2022-02-20 17:56:29,937 INFO L284 TraceCheckUtils]: 105: Hoare quadruple {21881#true} {21882#false} #1063#return; {21882#false} is VALID [2022-02-20 17:56:29,937 INFO L290 TraceCheckUtils]: 106: Hoare triple {21882#false} assume { :begin_inline_mail } true;mail_#in~client#1, mail_#in~msg#1 := outgoing__wrappee__Keys_~client#1, outgoing__wrappee__Keys_~msg#1;havoc mail_#t~ret60#1, mail_#t~ret61#1, mail_~client#1, mail_~msg#1, mail_~__utac__ad__arg1~0#1, mail_~__utac__ad__arg2~0#1, mail_~tmp~9#1;mail_~client#1 := mail_#in~client#1;mail_~msg#1 := mail_#in~msg#1;havoc mail_~__utac__ad__arg1~0#1;havoc mail_~__utac__ad__arg2~0#1;havoc mail_~tmp~9#1;mail_~__utac__ad__arg1~0#1 := mail_~client#1;mail_~__utac__ad__arg2~0#1 := mail_~msg#1;assume { :begin_inline___utac_acc__AddressBookEncrypt_spec__1 } true;__utac_acc__AddressBookEncrypt_spec__1_#in~client#1, __utac_acc__AddressBookEncrypt_spec__1_#in~msg#1 := mail_~__utac__ad__arg1~0#1, mail_~__utac__ad__arg2~0#1;havoc __utac_acc__AddressBookEncrypt_spec__1_#t~ret85#1, __utac_acc__AddressBookEncrypt_spec__1_#t~ret86#1, __utac_acc__AddressBookEncrypt_spec__1_#t~ret87#1, __utac_acc__AddressBookEncrypt_spec__1_~client#1, __utac_acc__AddressBookEncrypt_spec__1_~msg#1, __utac_acc__AddressBookEncrypt_spec__1_~tmp~20#1;__utac_acc__AddressBookEncrypt_spec__1_~client#1 := __utac_acc__AddressBookEncrypt_spec__1_#in~client#1;__utac_acc__AddressBookEncrypt_spec__1_~msg#1 := __utac_acc__AddressBookEncrypt_spec__1_#in~msg#1;havoc __utac_acc__AddressBookEncrypt_spec__1_~tmp~20#1;call __utac_acc__AddressBookEncrypt_spec__1_#t~ret85#1 := puts(31, 0);assume -2147483648 <= __utac_acc__AddressBookEncrypt_spec__1_#t~ret85#1 && __utac_acc__AddressBookEncrypt_spec__1_#t~ret85#1 <= 2147483647;havoc __utac_acc__AddressBookEncrypt_spec__1_#t~ret85#1; {21882#false} is VALID [2022-02-20 17:56:29,937 INFO L290 TraceCheckUtils]: 107: Hoare triple {21882#false} assume !(-1 == ~mail_is_sensitive~0); {21882#false} is VALID [2022-02-20 17:56:29,937 INFO L272 TraceCheckUtils]: 108: Hoare triple {21882#false} call __utac_acc__AddressBookEncrypt_spec__1_#t~ret87#1 := isEncrypted(__utac_acc__AddressBookEncrypt_spec__1_~msg#1); {21881#true} is VALID [2022-02-20 17:56:29,937 INFO L290 TraceCheckUtils]: 109: Hoare triple {21881#true} ~handle := #in~handle;havoc ~retValue_acc~39; {21881#true} is VALID [2022-02-20 17:56:29,937 INFO L290 TraceCheckUtils]: 110: Hoare triple {21881#true} assume 1 == ~handle;~retValue_acc~39 := ~__ste_email_isEncrypted0~0;#res := ~retValue_acc~39; {21881#true} is VALID [2022-02-20 17:56:29,937 INFO L290 TraceCheckUtils]: 111: Hoare triple {21881#true} assume true; {21881#true} is VALID [2022-02-20 17:56:29,937 INFO L284 TraceCheckUtils]: 112: Hoare quadruple {21881#true} {21882#false} #1067#return; {21882#false} is VALID [2022-02-20 17:56:29,937 INFO L290 TraceCheckUtils]: 113: Hoare triple {21882#false} assume -2147483648 <= __utac_acc__AddressBookEncrypt_spec__1_#t~ret87#1 && __utac_acc__AddressBookEncrypt_spec__1_#t~ret87#1 <= 2147483647;__utac_acc__AddressBookEncrypt_spec__1_~tmp~20#1 := __utac_acc__AddressBookEncrypt_spec__1_#t~ret87#1;havoc __utac_acc__AddressBookEncrypt_spec__1_#t~ret87#1; {21882#false} is VALID [2022-02-20 17:56:29,937 INFO L290 TraceCheckUtils]: 114: Hoare triple {21882#false} assume ~mail_is_sensitive~0 != __utac_acc__AddressBookEncrypt_spec__1_~tmp~20#1;assume { :begin_inline___automaton_fail } true; {21882#false} is VALID [2022-02-20 17:56:29,938 INFO L290 TraceCheckUtils]: 115: Hoare triple {21882#false} assume !false; {21882#false} is VALID [2022-02-20 17:56:29,938 INFO L134 CoverageAnalysis]: Checked inductivity of 31 backedges. 13 proven. 0 refuted. 0 times theorem prover too weak. 18 trivial. 0 not checked. [2022-02-20 17:56:29,938 INFO L144 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2022-02-20 17:56:29,938 INFO L338 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [714484407] [2022-02-20 17:56:29,938 INFO L165 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [714484407] provided 1 perfect and 0 imperfect interpolant sequences [2022-02-20 17:56:29,938 INFO L191 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2022-02-20 17:56:29,938 INFO L204 FreeRefinementEngine]: Number of different interpolants: perfect sequences [12] imperfect sequences [] total 12 [2022-02-20 17:56:29,939 INFO L118 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [121846111] [2022-02-20 17:56:29,939 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2022-02-20 17:56:29,939 INFO L78 Accepts]: Start accepts. Automaton has has 12 states, 11 states have (on average 7.2727272727272725) internal successors, (80), 8 states have internal predecessors, (80), 4 states have call successors, (15), 6 states have call predecessors, (15), 3 states have return successors, (13), 3 states have call predecessors, (13), 4 states have call successors, (13) Word has length 116 [2022-02-20 17:56:29,940 INFO L84 Accepts]: Finished accepts. word is accepted. [2022-02-20 17:56:29,940 INFO L86 InductivityCheck]: Starting indutivity check of a Floyd-Hoare automaton with has 12 states, 11 states have (on average 7.2727272727272725) internal successors, (80), 8 states have internal predecessors, (80), 4 states have call successors, (15), 6 states have call predecessors, (15), 3 states have return successors, (13), 3 states have call predecessors, (13), 4 states have call successors, (13) [2022-02-20 17:56:30,001 INFO L122 InductivityCheck]: Floyd-Hoare automaton has 108 edges. 108 inductive. 0 not inductive. 0 times theorem prover too weak to decide inductivity. [2022-02-20 17:56:30,002 INFO L546 AbstractCegarLoop]: INTERPOLANT automaton has 12 states [2022-02-20 17:56:30,002 INFO L108 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2022-02-20 17:56:30,002 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 12 interpolants. [2022-02-20 17:56:30,002 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=21, Invalid=111, Unknown=0, NotChecked=0, Total=132 [2022-02-20 17:56:30,003 INFO L87 Difference]: Start difference. First operand 443 states and 668 transitions. Second operand has 12 states, 11 states have (on average 7.2727272727272725) internal successors, (80), 8 states have internal predecessors, (80), 4 states have call successors, (15), 6 states have call predecessors, (15), 3 states have return successors, (13), 3 states have call predecessors, (13), 4 states have call successors, (13) [2022-02-20 17:56:40,972 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-02-20 17:56:40,972 INFO L93 Difference]: Finished difference Result 1073 states and 1628 transitions. [2022-02-20 17:56:40,972 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 14 states. [2022-02-20 17:56:40,972 INFO L78 Accepts]: Start accepts. Automaton has has 12 states, 11 states have (on average 7.2727272727272725) internal successors, (80), 8 states have internal predecessors, (80), 4 states have call successors, (15), 6 states have call predecessors, (15), 3 states have return successors, (13), 3 states have call predecessors, (13), 4 states have call successors, (13) Word has length 116 [2022-02-20 17:56:40,973 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2022-02-20 17:56:40,973 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 12 states, 11 states have (on average 7.2727272727272725) internal successors, (80), 8 states have internal predecessors, (80), 4 states have call successors, (15), 6 states have call predecessors, (15), 3 states have return successors, (13), 3 states have call predecessors, (13), 4 states have call successors, (13) [2022-02-20 17:56:40,983 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 14 states to 14 states and 1430 transitions. [2022-02-20 17:56:40,983 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 12 states, 11 states have (on average 7.2727272727272725) internal successors, (80), 8 states have internal predecessors, (80), 4 states have call successors, (15), 6 states have call predecessors, (15), 3 states have return successors, (13), 3 states have call predecessors, (13), 4 states have call successors, (13) [2022-02-20 17:56:41,001 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 14 states to 14 states and 1430 transitions. [2022-02-20 17:56:41,001 INFO L86 InductivityCheck]: Starting indutivity check of a Floyd-Hoare automaton with 14 states and 1430 transitions. [2022-02-20 17:56:42,086 INFO L122 InductivityCheck]: Floyd-Hoare automaton has 1430 edges. 1430 inductive. 0 not inductive. 0 times theorem prover too weak to decide inductivity. [2022-02-20 17:56:42,107 INFO L225 Difference]: With dead ends: 1073 [2022-02-20 17:56:42,107 INFO L226 Difference]: Without dead ends: 657 [2022-02-20 17:56:42,109 INFO L932 BasicCegarLoop]: 0 DeclaredPredicates, 51 GetRequests, 29 SyntacticMatches, 0 SemanticMatches, 22 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 71 ImplicationChecksByTransitivity, 0.2s TimeCoverageRelationStatistics Valid=112, Invalid=440, Unknown=0, NotChecked=0, Total=552 [2022-02-20 17:56:42,109 INFO L933 BasicCegarLoop]: 698 mSDtfsCounter, 1504 mSDsluCounter, 1196 mSDsCounter, 0 mSdLazyCounter, 4672 mSolverCounterSat, 635 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 5.1s Time, 0 mProtectedPredicate, 0 mProtectedAction, 1504 SdHoareTripleChecker+Valid, 1894 SdHoareTripleChecker+Invalid, 5307 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 635 IncrementalHoareTripleChecker+Valid, 4672 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 5.1s IncrementalHoareTripleChecker+Time [2022-02-20 17:56:42,110 INFO L934 BasicCegarLoop]: SdHoareTripleChecker [1504 Valid, 1894 Invalid, 5307 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [635 Valid, 4672 Invalid, 0 Unknown, 0 Unchecked, 5.1s Time] [2022-02-20 17:56:42,110 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 657 states. [2022-02-20 17:56:42,196 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 657 to 443. [2022-02-20 17:56:42,196 INFO L214 AbstractMinimizeNwa]: Start testing correctness of minimizeSevpa [2022-02-20 17:56:42,197 INFO L82 GeneralOperation]: Start isEquivalent. First operand 657 states. Second operand has 443 states, 341 states have (on average 1.5043988269794721) internal successors, (513), 347 states have internal predecessors, (513), 74 states have call successors, (74), 24 states have call predecessors, (74), 27 states have return successors, (80), 73 states have call predecessors, (80), 73 states have call successors, (80) [2022-02-20 17:56:42,197 INFO L74 IsIncluded]: Start isIncluded. First operand 657 states. Second operand has 443 states, 341 states have (on average 1.5043988269794721) internal successors, (513), 347 states have internal predecessors, (513), 74 states have call successors, (74), 24 states have call predecessors, (74), 27 states have return successors, (80), 73 states have call predecessors, (80), 73 states have call successors, (80) [2022-02-20 17:56:42,198 INFO L87 Difference]: Start difference. First operand 657 states. Second operand has 443 states, 341 states have (on average 1.5043988269794721) internal successors, (513), 347 states have internal predecessors, (513), 74 states have call successors, (74), 24 states have call predecessors, (74), 27 states have return successors, (80), 73 states have call predecessors, (80), 73 states have call successors, (80) [2022-02-20 17:56:42,215 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-02-20 17:56:42,215 INFO L93 Difference]: Finished difference Result 657 states and 997 transitions. [2022-02-20 17:56:42,215 INFO L276 IsEmpty]: Start isEmpty. Operand 657 states and 997 transitions. [2022-02-20 17:56:42,218 INFO L282 IsEmpty]: Finished isEmpty. No accepting run. [2022-02-20 17:56:42,218 INFO L83 IsIncluded]: Finished isIncluded. Language is included [2022-02-20 17:56:42,219 INFO L74 IsIncluded]: Start isIncluded. First operand has 443 states, 341 states have (on average 1.5043988269794721) internal successors, (513), 347 states have internal predecessors, (513), 74 states have call successors, (74), 24 states have call predecessors, (74), 27 states have return successors, (80), 73 states have call predecessors, (80), 73 states have call successors, (80) Second operand 657 states. [2022-02-20 17:56:42,220 INFO L87 Difference]: Start difference. First operand has 443 states, 341 states have (on average 1.5043988269794721) internal successors, (513), 347 states have internal predecessors, (513), 74 states have call successors, (74), 24 states have call predecessors, (74), 27 states have return successors, (80), 73 states have call predecessors, (80), 73 states have call successors, (80) Second operand 657 states. [2022-02-20 17:56:42,237 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-02-20 17:56:42,237 INFO L93 Difference]: Finished difference Result 657 states and 997 transitions. [2022-02-20 17:56:42,237 INFO L276 IsEmpty]: Start isEmpty. Operand 657 states and 997 transitions. [2022-02-20 17:56:42,240 INFO L282 IsEmpty]: Finished isEmpty. No accepting run. [2022-02-20 17:56:42,240 INFO L83 IsIncluded]: Finished isIncluded. Language is included [2022-02-20 17:56:42,240 INFO L88 GeneralOperation]: Finished isEquivalent. [2022-02-20 17:56:42,240 INFO L221 AbstractMinimizeNwa]: Finished testing correctness of minimizeSevpa [2022-02-20 17:56:42,241 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 443 states, 341 states have (on average 1.5043988269794721) internal successors, (513), 347 states have internal predecessors, (513), 74 states have call successors, (74), 24 states have call predecessors, (74), 27 states have return successors, (80), 73 states have call predecessors, (80), 73 states have call successors, (80) [2022-02-20 17:56:42,252 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 443 states to 443 states and 667 transitions. [2022-02-20 17:56:42,252 INFO L78 Accepts]: Start accepts. Automaton has 443 states and 667 transitions. Word has length 116 [2022-02-20 17:56:42,253 INFO L84 Accepts]: Finished accepts. word is rejected. [2022-02-20 17:56:42,253 INFO L470 AbstractCegarLoop]: Abstraction has 443 states and 667 transitions. [2022-02-20 17:56:42,253 INFO L471 AbstractCegarLoop]: INTERPOLANT automaton has has 12 states, 11 states have (on average 7.2727272727272725) internal successors, (80), 8 states have internal predecessors, (80), 4 states have call successors, (15), 6 states have call predecessors, (15), 3 states have return successors, (13), 3 states have call predecessors, (13), 4 states have call successors, (13) [2022-02-20 17:56:42,253 INFO L276 IsEmpty]: Start isEmpty. Operand 443 states and 667 transitions. [2022-02-20 17:56:42,255 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 118 [2022-02-20 17:56:42,255 INFO L506 BasicCegarLoop]: Found error trace [2022-02-20 17:56:42,255 INFO L514 BasicCegarLoop]: trace histogram [3, 3, 3, 3, 2, 2, 2, 2, 2, 2, 2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-02-20 17:56:42,256 WARN L452 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable7 [2022-02-20 17:56:42,256 INFO L402 AbstractCegarLoop]: === Iteration 9 === Targeting outgoingErr0ASSERT_VIOLATIONERROR_FUNCTION === [outgoingErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2022-02-20 17:56:42,256 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2022-02-20 17:56:42,256 INFO L85 PathProgramCache]: Analyzing trace with hash -482967355, now seen corresponding path program 2 times [2022-02-20 17:56:42,256 INFO L126 FreeRefinementEngine]: Executing refinement strategy CAMEL [2022-02-20 17:56:42,256 INFO L338 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [1919812849] [2022-02-20 17:56:42,257 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-02-20 17:56:42,257 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2022-02-20 17:56:42,278 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-02-20 17:56:42,306 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 6 [2022-02-20 17:56:42,308 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-02-20 17:56:42,309 INFO L290 TraceCheckUtils]: 0: Hoare triple {25523#(and (= |old(~__ste_client_idCounter0~0)| ~__ste_client_idCounter0~0) (= |old(~__ste_client_idCounter1~0)| ~__ste_client_idCounter1~0) (= |old(~__ste_client_idCounter2~0)| ~__ste_client_idCounter2~0))} ~handle := #in~handle;~value := #in~value; {25461#true} is VALID [2022-02-20 17:56:42,310 INFO L290 TraceCheckUtils]: 1: Hoare triple {25461#true} assume 1 == ~handle;~__ste_client_idCounter0~0 := ~value; {25461#true} is VALID [2022-02-20 17:56:42,310 INFO L290 TraceCheckUtils]: 2: Hoare triple {25461#true} assume true; {25461#true} is VALID [2022-02-20 17:56:42,310 INFO L284 TraceCheckUtils]: 3: Hoare quadruple {25461#true} {25461#true} #1133#return; {25461#true} is VALID [2022-02-20 17:56:42,315 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 12 [2022-02-20 17:56:42,318 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-02-20 17:56:42,321 INFO L290 TraceCheckUtils]: 0: Hoare triple {25524#(and (= ~__ste_client_privateKey0~0 |old(~__ste_client_privateKey0~0)|) (= ~__ste_client_privateKey2~0 |old(~__ste_client_privateKey2~0)|) (= ~__ste_client_privateKey1~0 |old(~__ste_client_privateKey1~0)|))} ~handle := #in~handle;~value := #in~value; {25461#true} is VALID [2022-02-20 17:56:42,321 INFO L290 TraceCheckUtils]: 1: Hoare triple {25461#true} assume 1 == ~handle;~__ste_client_privateKey0~0 := ~value; {25461#true} is VALID [2022-02-20 17:56:42,321 INFO L290 TraceCheckUtils]: 2: Hoare triple {25461#true} assume true; {25461#true} is VALID [2022-02-20 17:56:42,321 INFO L284 TraceCheckUtils]: 3: Hoare quadruple {25461#true} {25461#true} #1135#return; {25461#true} is VALID [2022-02-20 17:56:42,321 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 18 [2022-02-20 17:56:42,322 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-02-20 17:56:42,324 INFO L290 TraceCheckUtils]: 0: Hoare triple {25523#(and (= |old(~__ste_client_idCounter0~0)| ~__ste_client_idCounter0~0) (= |old(~__ste_client_idCounter1~0)| ~__ste_client_idCounter1~0) (= |old(~__ste_client_idCounter2~0)| ~__ste_client_idCounter2~0))} ~handle := #in~handle;~value := #in~value; {25461#true} is VALID [2022-02-20 17:56:42,324 INFO L290 TraceCheckUtils]: 1: Hoare triple {25461#true} assume !(1 == ~handle); {25461#true} is VALID [2022-02-20 17:56:42,324 INFO L290 TraceCheckUtils]: 2: Hoare triple {25461#true} assume 2 == ~handle;~__ste_client_idCounter1~0 := ~value; {25461#true} is VALID [2022-02-20 17:56:42,324 INFO L290 TraceCheckUtils]: 3: Hoare triple {25461#true} assume true; {25461#true} is VALID [2022-02-20 17:56:42,324 INFO L284 TraceCheckUtils]: 4: Hoare quadruple {25461#true} {25461#true} #1137#return; {25461#true} is VALID [2022-02-20 17:56:42,325 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 25 [2022-02-20 17:56:42,326 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-02-20 17:56:42,329 INFO L290 TraceCheckUtils]: 0: Hoare triple {25524#(and (= ~__ste_client_privateKey0~0 |old(~__ste_client_privateKey0~0)|) (= ~__ste_client_privateKey2~0 |old(~__ste_client_privateKey2~0)|) (= ~__ste_client_privateKey1~0 |old(~__ste_client_privateKey1~0)|))} ~handle := #in~handle;~value := #in~value; {25461#true} is VALID [2022-02-20 17:56:42,329 INFO L290 TraceCheckUtils]: 1: Hoare triple {25461#true} assume !(1 == ~handle); {25461#true} is VALID [2022-02-20 17:56:42,329 INFO L290 TraceCheckUtils]: 2: Hoare triple {25461#true} assume 2 == ~handle;~__ste_client_privateKey1~0 := ~value; {25461#true} is VALID [2022-02-20 17:56:42,329 INFO L290 TraceCheckUtils]: 3: Hoare triple {25461#true} assume true; {25461#true} is VALID [2022-02-20 17:56:42,329 INFO L284 TraceCheckUtils]: 4: Hoare quadruple {25461#true} {25461#true} #1139#return; {25461#true} is VALID [2022-02-20 17:56:42,329 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 32 [2022-02-20 17:56:42,338 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-02-20 17:56:42,351 INFO L290 TraceCheckUtils]: 0: Hoare triple {25523#(and (= |old(~__ste_client_idCounter0~0)| ~__ste_client_idCounter0~0) (= |old(~__ste_client_idCounter1~0)| ~__ste_client_idCounter1~0) (= |old(~__ste_client_idCounter2~0)| ~__ste_client_idCounter2~0))} ~handle := #in~handle;~value := #in~value; {25525#(= setClientId_~handle |setClientId_#in~handle|)} is VALID [2022-02-20 17:56:42,351 INFO L290 TraceCheckUtils]: 1: Hoare triple {25525#(= setClientId_~handle |setClientId_#in~handle|)} assume !(1 == ~handle); {25525#(= setClientId_~handle |setClientId_#in~handle|)} is VALID [2022-02-20 17:56:42,352 INFO L290 TraceCheckUtils]: 2: Hoare triple {25525#(= setClientId_~handle |setClientId_#in~handle|)} assume !(2 == ~handle); {25525#(= setClientId_~handle |setClientId_#in~handle|)} is VALID [2022-02-20 17:56:42,352 INFO L290 TraceCheckUtils]: 3: Hoare triple {25525#(= setClientId_~handle |setClientId_#in~handle|)} assume 3 == ~handle;~__ste_client_idCounter2~0 := ~value; {25526#(= 3 |setClientId_#in~handle|)} is VALID [2022-02-20 17:56:42,352 INFO L290 TraceCheckUtils]: 4: Hoare triple {25526#(= 3 |setClientId_#in~handle|)} assume true; {25526#(= 3 |setClientId_#in~handle|)} is VALID [2022-02-20 17:56:42,353 INFO L284 TraceCheckUtils]: 5: Hoare quadruple {25526#(= 3 |setClientId_#in~handle|)} {25481#(= |ULTIMATE.start_setup_chuck_~chuck___0#1| |ULTIMATE.start_setup_chuck__wrappee__Base_~chuck___0#1|)} #1141#return; {25488#(not (= |ULTIMATE.start_setup_chuck_~chuck___0#1| 2))} is VALID [2022-02-20 17:56:42,353 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 40 [2022-02-20 17:56:42,355 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-02-20 17:56:42,369 INFO L290 TraceCheckUtils]: 0: Hoare triple {25524#(and (= ~__ste_client_privateKey0~0 |old(~__ste_client_privateKey0~0)|) (= ~__ste_client_privateKey2~0 |old(~__ste_client_privateKey2~0)|) (= ~__ste_client_privateKey1~0 |old(~__ste_client_privateKey1~0)|))} ~handle := #in~handle;~value := #in~value; {25527#(= setClientPrivateKey_~handle |setClientPrivateKey_#in~handle|)} is VALID [2022-02-20 17:56:42,370 INFO L290 TraceCheckUtils]: 1: Hoare triple {25527#(= setClientPrivateKey_~handle |setClientPrivateKey_#in~handle|)} assume !(1 == ~handle); {25527#(= setClientPrivateKey_~handle |setClientPrivateKey_#in~handle|)} is VALID [2022-02-20 17:56:42,370 INFO L290 TraceCheckUtils]: 2: Hoare triple {25527#(= setClientPrivateKey_~handle |setClientPrivateKey_#in~handle|)} assume 2 == ~handle;~__ste_client_privateKey1~0 := ~value; {25528#(= 2 |setClientPrivateKey_#in~handle|)} is VALID [2022-02-20 17:56:42,370 INFO L290 TraceCheckUtils]: 3: Hoare triple {25528#(= 2 |setClientPrivateKey_#in~handle|)} assume true; {25528#(= 2 |setClientPrivateKey_#in~handle|)} is VALID [2022-02-20 17:56:42,371 INFO L284 TraceCheckUtils]: 4: Hoare quadruple {25528#(= 2 |setClientPrivateKey_#in~handle|)} {25488#(not (= |ULTIMATE.start_setup_chuck_~chuck___0#1| 2))} #1143#return; {25462#false} is VALID [2022-02-20 17:56:42,377 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 63 [2022-02-20 17:56:42,379 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-02-20 17:56:42,380 INFO L290 TraceCheckUtils]: 0: Hoare triple {25529#(and (= |old(~__ste_email_from0~0)| ~__ste_email_from0~0) (= |old(~__ste_email_from1~0)| ~__ste_email_from1~0))} ~handle := #in~handle;~value := #in~value; {25461#true} is VALID [2022-02-20 17:56:42,380 INFO L290 TraceCheckUtils]: 1: Hoare triple {25461#true} assume 1 == ~handle;~__ste_email_from0~0 := ~value; {25461#true} is VALID [2022-02-20 17:56:42,381 INFO L290 TraceCheckUtils]: 2: Hoare triple {25461#true} assume true; {25461#true} is VALID [2022-02-20 17:56:42,381 INFO L284 TraceCheckUtils]: 3: Hoare quadruple {25461#true} {25462#false} #1119#return; {25462#false} is VALID [2022-02-20 17:56:42,388 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 68 [2022-02-20 17:56:42,389 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-02-20 17:56:42,393 INFO L290 TraceCheckUtils]: 0: Hoare triple {25530#(and (= ~__ste_email_to0~0 |old(~__ste_email_to0~0)|) (= ~__ste_email_to1~0 |old(~__ste_email_to1~0)|))} ~handle := #in~handle;~value := #in~value; {25461#true} is VALID [2022-02-20 17:56:42,393 INFO L290 TraceCheckUtils]: 1: Hoare triple {25461#true} assume 1 == ~handle;~__ste_email_to0~0 := ~value; {25461#true} is VALID [2022-02-20 17:56:42,393 INFO L290 TraceCheckUtils]: 2: Hoare triple {25461#true} assume true; {25461#true} is VALID [2022-02-20 17:56:42,393 INFO L284 TraceCheckUtils]: 3: Hoare quadruple {25461#true} {25462#false} #1121#return; {25462#false} is VALID [2022-02-20 17:56:42,393 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 77 [2022-02-20 17:56:42,394 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-02-20 17:56:42,396 INFO L290 TraceCheckUtils]: 0: Hoare triple {25461#true} ~handle := #in~handle;havoc ~retValue_acc~24; {25461#true} is VALID [2022-02-20 17:56:42,396 INFO L290 TraceCheckUtils]: 1: Hoare triple {25461#true} assume 1 == ~handle;~retValue_acc~24 := ~__ste_client_privateKey0~0;#res := ~retValue_acc~24; {25461#true} is VALID [2022-02-20 17:56:42,396 INFO L290 TraceCheckUtils]: 2: Hoare triple {25461#true} assume true; {25461#true} is VALID [2022-02-20 17:56:42,396 INFO L284 TraceCheckUtils]: 3: Hoare quadruple {25461#true} {25462#false} #1053#return; {25462#false} is VALID [2022-02-20 17:56:42,396 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 85 [2022-02-20 17:56:42,397 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-02-20 17:56:42,398 INFO L290 TraceCheckUtils]: 0: Hoare triple {25461#true} ~handle := #in~handle;havoc ~retValue_acc~36; {25461#true} is VALID [2022-02-20 17:56:42,398 INFO L290 TraceCheckUtils]: 1: Hoare triple {25461#true} assume 1 == ~handle;~retValue_acc~36 := ~__ste_email_to0~0;#res := ~retValue_acc~36; {25461#true} is VALID [2022-02-20 17:56:42,398 INFO L290 TraceCheckUtils]: 2: Hoare triple {25461#true} assume true; {25461#true} is VALID [2022-02-20 17:56:42,398 INFO L284 TraceCheckUtils]: 3: Hoare quadruple {25461#true} {25462#false} #1055#return; {25462#false} is VALID [2022-02-20 17:56:42,398 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 91 [2022-02-20 17:56:42,399 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-02-20 17:56:42,401 INFO L290 TraceCheckUtils]: 0: Hoare triple {25461#true} ~handle := #in~handle;~userid := #in~userid;havoc ~retValue_acc~29; {25461#true} is VALID [2022-02-20 17:56:42,401 INFO L290 TraceCheckUtils]: 1: Hoare triple {25461#true} assume 1 == ~handle; {25461#true} is VALID [2022-02-20 17:56:42,401 INFO L290 TraceCheckUtils]: 2: Hoare triple {25461#true} assume ~userid == ~__ste_Client_Keyring0_User0~0;~retValue_acc~29 := ~__ste_Client_Keyring0_PublicKey0~0;#res := ~retValue_acc~29; {25461#true} is VALID [2022-02-20 17:56:42,401 INFO L290 TraceCheckUtils]: 3: Hoare triple {25461#true} assume true; {25461#true} is VALID [2022-02-20 17:56:42,401 INFO L284 TraceCheckUtils]: 4: Hoare quadruple {25461#true} {25462#false} #1057#return; {25462#false} is VALID [2022-02-20 17:56:42,401 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 102 [2022-02-20 17:56:42,402 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-02-20 17:56:42,405 INFO L290 TraceCheckUtils]: 0: Hoare triple {25529#(and (= |old(~__ste_email_from0~0)| ~__ste_email_from0~0) (= |old(~__ste_email_from1~0)| ~__ste_email_from1~0))} ~handle := #in~handle;~value := #in~value; {25461#true} is VALID [2022-02-20 17:56:42,405 INFO L290 TraceCheckUtils]: 1: Hoare triple {25461#true} assume 1 == ~handle;~__ste_email_from0~0 := ~value; {25461#true} is VALID [2022-02-20 17:56:42,405 INFO L290 TraceCheckUtils]: 2: Hoare triple {25461#true} assume true; {25461#true} is VALID [2022-02-20 17:56:42,405 INFO L284 TraceCheckUtils]: 3: Hoare quadruple {25461#true} {25462#false} #1063#return; {25462#false} is VALID [2022-02-20 17:56:42,405 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 109 [2022-02-20 17:56:42,406 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-02-20 17:56:42,408 INFO L290 TraceCheckUtils]: 0: Hoare triple {25461#true} ~handle := #in~handle;havoc ~retValue_acc~39; {25461#true} is VALID [2022-02-20 17:56:42,408 INFO L290 TraceCheckUtils]: 1: Hoare triple {25461#true} assume 1 == ~handle;~retValue_acc~39 := ~__ste_email_isEncrypted0~0;#res := ~retValue_acc~39; {25461#true} is VALID [2022-02-20 17:56:42,408 INFO L290 TraceCheckUtils]: 2: Hoare triple {25461#true} assume true; {25461#true} is VALID [2022-02-20 17:56:42,408 INFO L284 TraceCheckUtils]: 3: Hoare quadruple {25461#true} {25462#false} #1067#return; {25462#false} is VALID [2022-02-20 17:56:42,408 INFO L290 TraceCheckUtils]: 0: Hoare triple {25461#true} assume { :begin_inline_ULTIMATE.init } true;#NULL.base, #NULL.offset := 0, 0;assume 0 == #valid[0];assume 0 < #StackHeapBarrier;call #Ultimate.allocInit(2, 1);call write~init~int(48, 1, 0, 1);call write~init~int(0, 1, 1, 1);call #Ultimate.allocInit(28, 2);call #Ultimate.allocInit(12, 3);call #Ultimate.allocInit(4, 4);call write~init~int(37, 4, 0, 1);call write~init~int(115, 4, 1, 1);call write~init~int(10, 4, 2, 1);call write~init~int(0, 4, 3, 1);call #Ultimate.allocInit(10, 5);call #Ultimate.allocInit(12, 6);call #Ultimate.allocInit(10, 7);call #Ultimate.allocInit(18, 8);call #Ultimate.allocInit(16, 9);call #Ultimate.allocInit(21, 10);call #Ultimate.allocInit(13, 11);call #Ultimate.allocInit(16, 12);call #Ultimate.allocInit(25, 13);call #Ultimate.allocInit(30, 14);call #Ultimate.allocInit(9, 15);call #Ultimate.allocInit(21, 16);call #Ultimate.allocInit(30, 17);call #Ultimate.allocInit(9, 18);call #Ultimate.allocInit(21, 19);call #Ultimate.allocInit(30, 20);call #Ultimate.allocInit(9, 21);call #Ultimate.allocInit(25, 22);call #Ultimate.allocInit(30, 23);call #Ultimate.allocInit(9, 24);call #Ultimate.allocInit(25, 25);call #Ultimate.allocInit(10, 26);call #Ultimate.allocInit(16, 27);call #Ultimate.allocInit(20, 28);call #Ultimate.allocInit(22, 29);call #Ultimate.allocInit(21, 30);call #Ultimate.allocInit(13, 31);call #Ultimate.allocInit(44, 32);call #Ultimate.allocInit(44, 33);call #Ultimate.allocInit(9, 34);call #Ultimate.allocInit(9, 35);call #Ultimate.allocInit(11, 36);call #Ultimate.allocInit(19, 37);call #Ultimate.allocInit(4, 38);call write~init~int(37, 38, 0, 1);call write~init~int(100, 38, 1, 1);call write~init~int(10, 38, 2, 1);call write~init~int(0, 38, 3, 1);call #Ultimate.allocInit(4, 39);call write~init~int(37, 39, 0, 1);call write~init~int(100, 39, 1, 1);call write~init~int(10, 39, 2, 1);call write~init~int(0, 39, 3, 1);~__SELECTED_FEATURE_Base~0 := 0;~__SELECTED_FEATURE_Keys~0 := 0;~__SELECTED_FEATURE_Encrypt~0 := 0;~__SELECTED_FEATURE_AutoResponder~0 := 0;~__SELECTED_FEATURE_AddressBook~0 := 0;~__SELECTED_FEATURE_Sign~0 := 0;~__SELECTED_FEATURE_Forward~0 := 0;~__SELECTED_FEATURE_Verify~0 := 0;~__SELECTED_FEATURE_Decrypt~0 := 0;~__GUIDSL_ROOT_PRODUCTION~0 := 0;~__GUIDSL_NON_TERMINAL_main~0 := 0;~head~0.base, ~head~0.offset := 0, 0;~queue_empty~0 := 1;~queued_message~0 := 0;~queued_client~0 := 0;~mail_is_sensitive~0 := -1;~__ste_Client_counter~0 := 0;~__ste_client_name0~0.base, ~__ste_client_name0~0.offset := 0, 0;~__ste_client_name1~0.base, ~__ste_client_name1~0.offset := 0, 0;~__ste_client_name2~0.base, ~__ste_client_name2~0.offset := 0, 0;~__ste_client_outbuffer0~0 := 0;~__ste_client_outbuffer1~0 := 0;~__ste_client_outbuffer2~0 := 0;~__ste_client_outbuffer3~0 := 0;~__ste_ClientAddressBook_size0~0 := 0;~__ste_ClientAddressBook_size1~0 := 0;~__ste_ClientAddressBook_size2~0 := 0;~__ste_Client_AddressBook0_Alias0~0 := 0;~__ste_Client_AddressBook0_Alias1~0 := 0;~__ste_Client_AddressBook0_Alias2~0 := 0;~__ste_Client_AddressBook1_Alias0~0 := 0;~__ste_Client_AddressBook1_Alias1~0 := 0;~__ste_Client_AddressBook1_Alias2~0 := 0;~__ste_Client_AddressBook2_Alias0~0 := 0;~__ste_Client_AddressBook2_Alias1~0 := 0;~__ste_Client_AddressBook2_Alias2~0 := 0;~__ste_Client_AddressBook0_Address0~0 := 0;~__ste_Client_AddressBook0_Address1~0 := 0;~__ste_Client_AddressBook0_Address2~0 := 0;~__ste_Client_AddressBook1_Address0~0 := 0;~__ste_Client_AddressBook1_Address1~0 := 0;~__ste_Client_AddressBook1_Address2~0 := 0;~__ste_Client_AddressBook2_Address0~0 := 0;~__ste_Client_AddressBook2_Address1~0 := 0;~__ste_Client_AddressBook2_Address2~0 := 0;~__ste_client_autoResponse0~0 := 0;~__ste_client_autoResponse1~0 := 0;~__ste_client_autoResponse2~0 := 0;~__ste_client_privateKey0~0 := 0;~__ste_client_privateKey1~0 := 0;~__ste_client_privateKey2~0 := 0;~__ste_ClientKeyring_size0~0 := 0;~__ste_ClientKeyring_size1~0 := 0;~__ste_ClientKeyring_size2~0 := 0;~__ste_Client_Keyring0_User0~0 := 0;~__ste_Client_Keyring0_User1~0 := 0;~__ste_Client_Keyring0_User2~0 := 0;~__ste_Client_Keyring1_User0~0 := 0;~__ste_Client_Keyring1_User1~0 := 0;~__ste_Client_Keyring1_User2~0 := 0;~__ste_Client_Keyring2_User0~0 := 0;~__ste_Client_Keyring2_User1~0 := 0;~__ste_Client_Keyring2_User2~0 := 0;~__ste_Client_Keyring0_PublicKey0~0 := 0;~__ste_Client_Keyring0_PublicKey1~0 := 0;~__ste_Client_Keyring0_PublicKey2~0 := 0;~__ste_Client_Keyring1_PublicKey0~0 := 0;~__ste_Client_Keyring1_PublicKey1~0 := 0;~__ste_Client_Keyring1_PublicKey2~0 := 0;~__ste_Client_Keyring2_PublicKey0~0 := 0;~__ste_Client_Keyring2_PublicKey1~0 := 0;~__ste_Client_Keyring2_PublicKey2~0 := 0;~__ste_client_forwardReceiver0~0 := 0;~__ste_client_forwardReceiver1~0 := 0;~__ste_client_forwardReceiver2~0 := 0;~__ste_client_forwardReceiver3~0 := 0;~__ste_client_idCounter0~0 := 0;~__ste_client_idCounter1~0 := 0;~__ste_client_idCounter2~0 := 0;~bob~0 := 0;~rjh~0 := 0;~chuck~0 := 0;~__ste_Email_counter~0 := 0;~__ste_email_id0~0 := 0;~__ste_email_id1~0 := 0;~__ste_email_from0~0 := 0;~__ste_email_from1~0 := 0;~__ste_email_to0~0 := 0;~__ste_email_to1~0 := 0;~__ste_email_subject0~0.base, ~__ste_email_subject0~0.offset := 0, 0;~__ste_email_subject1~0.base, ~__ste_email_subject1~0.offset := 0, 0;~__ste_email_body0~0.base, ~__ste_email_body0~0.offset := 0, 0;~__ste_email_body1~0.base, ~__ste_email_body1~0.offset := 0, 0;~__ste_email_isEncrypted0~0 := 0;~__ste_email_isEncrypted1~0 := 0;~__ste_email_encryptionKey0~0 := 0;~__ste_email_encryptionKey1~0 := 0;~__ste_email_isSigned0~0 := 0;~__ste_email_isSigned1~0 := 0;~__ste_email_signKey0~0 := 0;~__ste_email_signKey1~0 := 0;~__ste_email_isSignatureVerified0~0 := 0;~__ste_email_isSignatureVerified1~0 := 0; {25461#true} is VALID [2022-02-20 17:56:42,408 INFO L290 TraceCheckUtils]: 1: Hoare triple {25461#true} assume { :end_inline_ULTIMATE.init } true;assume { :begin_inline_main } true;havoc main_#res#1;havoc main_#t~ret98#1, main_~retValue_acc~32#1, main_~tmp~24#1;havoc main_~retValue_acc~32#1;havoc main_~tmp~24#1;assume { :begin_inline_select_helpers } true; {25461#true} is VALID [2022-02-20 17:56:42,408 INFO L290 TraceCheckUtils]: 2: Hoare triple {25461#true} assume { :end_inline_select_helpers } true;assume { :begin_inline_select_features } true; {25461#true} is VALID [2022-02-20 17:56:42,409 INFO L290 TraceCheckUtils]: 3: Hoare triple {25461#true} assume { :end_inline_select_features } true;assume { :begin_inline_valid_product } true;havoc valid_product_#res#1;havoc valid_product_~retValue_acc~9#1;havoc valid_product_~retValue_acc~9#1;valid_product_~retValue_acc~9#1 := 1;valid_product_#res#1 := valid_product_~retValue_acc~9#1; {25461#true} is VALID [2022-02-20 17:56:42,409 INFO L290 TraceCheckUtils]: 4: Hoare triple {25461#true} main_#t~ret98#1 := valid_product_#res#1;assume { :end_inline_valid_product } true;assume -2147483648 <= main_#t~ret98#1 && main_#t~ret98#1 <= 2147483647;main_~tmp~24#1 := main_#t~ret98#1;havoc main_#t~ret98#1; {25461#true} is VALID [2022-02-20 17:56:42,409 INFO L290 TraceCheckUtils]: 5: Hoare triple {25461#true} assume 0 != main_~tmp~24#1;assume { :begin_inline_setup } true;havoc setup_#t~nondet95#1, setup_#t~nondet96#1, setup_#t~nondet97#1, setup_~__cil_tmp1~0#1.base, setup_~__cil_tmp1~0#1.offset, setup_~__cil_tmp2~0#1.base, setup_~__cil_tmp2~0#1.offset, setup_~__cil_tmp3~2#1.base, setup_~__cil_tmp3~2#1.offset;havoc setup_~__cil_tmp1~0#1.base, setup_~__cil_tmp1~0#1.offset;havoc setup_~__cil_tmp2~0#1.base, setup_~__cil_tmp2~0#1.offset;havoc setup_~__cil_tmp3~2#1.base, setup_~__cil_tmp3~2#1.offset;~bob~0 := 1;assume { :begin_inline_setup_bob } true;setup_bob_#in~bob___0#1 := ~bob~0;havoc setup_bob_~bob___0#1;setup_bob_~bob___0#1 := setup_bob_#in~bob___0#1;assume { :begin_inline_setup_bob__wrappee__Base } true;setup_bob__wrappee__Base_#in~bob___0#1 := setup_bob_~bob___0#1;havoc setup_bob__wrappee__Base_~bob___0#1;setup_bob__wrappee__Base_~bob___0#1 := setup_bob__wrappee__Base_#in~bob___0#1; {25461#true} is VALID [2022-02-20 17:56:42,409 INFO L272 TraceCheckUtils]: 6: Hoare triple {25461#true} call setClientId(setup_bob__wrappee__Base_~bob___0#1, setup_bob__wrappee__Base_~bob___0#1); {25523#(and (= |old(~__ste_client_idCounter0~0)| ~__ste_client_idCounter0~0) (= |old(~__ste_client_idCounter1~0)| ~__ste_client_idCounter1~0) (= |old(~__ste_client_idCounter2~0)| ~__ste_client_idCounter2~0))} is VALID [2022-02-20 17:56:42,409 INFO L290 TraceCheckUtils]: 7: Hoare triple {25523#(and (= |old(~__ste_client_idCounter0~0)| ~__ste_client_idCounter0~0) (= |old(~__ste_client_idCounter1~0)| ~__ste_client_idCounter1~0) (= |old(~__ste_client_idCounter2~0)| ~__ste_client_idCounter2~0))} ~handle := #in~handle;~value := #in~value; {25461#true} is VALID [2022-02-20 17:56:42,410 INFO L290 TraceCheckUtils]: 8: Hoare triple {25461#true} assume 1 == ~handle;~__ste_client_idCounter0~0 := ~value; {25461#true} is VALID [2022-02-20 17:56:42,410 INFO L290 TraceCheckUtils]: 9: Hoare triple {25461#true} assume true; {25461#true} is VALID [2022-02-20 17:56:42,410 INFO L284 TraceCheckUtils]: 10: Hoare quadruple {25461#true} {25461#true} #1133#return; {25461#true} is VALID [2022-02-20 17:56:42,410 INFO L290 TraceCheckUtils]: 11: Hoare triple {25461#true} assume { :end_inline_setup_bob__wrappee__Base } true; {25461#true} is VALID [2022-02-20 17:56:42,410 INFO L272 TraceCheckUtils]: 12: Hoare triple {25461#true} call setClientPrivateKey(setup_bob_~bob___0#1, 123); {25524#(and (= ~__ste_client_privateKey0~0 |old(~__ste_client_privateKey0~0)|) (= ~__ste_client_privateKey2~0 |old(~__ste_client_privateKey2~0)|) (= ~__ste_client_privateKey1~0 |old(~__ste_client_privateKey1~0)|))} is VALID [2022-02-20 17:56:42,410 INFO L290 TraceCheckUtils]: 13: Hoare triple {25524#(and (= ~__ste_client_privateKey0~0 |old(~__ste_client_privateKey0~0)|) (= ~__ste_client_privateKey2~0 |old(~__ste_client_privateKey2~0)|) (= ~__ste_client_privateKey1~0 |old(~__ste_client_privateKey1~0)|))} ~handle := #in~handle;~value := #in~value; {25461#true} is VALID [2022-02-20 17:56:42,411 INFO L290 TraceCheckUtils]: 14: Hoare triple {25461#true} assume 1 == ~handle;~__ste_client_privateKey0~0 := ~value; {25461#true} is VALID [2022-02-20 17:56:42,411 INFO L290 TraceCheckUtils]: 15: Hoare triple {25461#true} assume true; {25461#true} is VALID [2022-02-20 17:56:42,411 INFO L284 TraceCheckUtils]: 16: Hoare quadruple {25461#true} {25461#true} #1135#return; {25461#true} is VALID [2022-02-20 17:56:42,411 INFO L290 TraceCheckUtils]: 17: Hoare triple {25461#true} assume { :end_inline_setup_bob } true;setup_~__cil_tmp1~0#1.base, setup_~__cil_tmp1~0#1.offset := 34, 0;havoc setup_#t~nondet95#1;~rjh~0 := 2;assume { :begin_inline_setup_rjh } true;setup_rjh_#in~rjh___0#1 := ~rjh~0;havoc setup_rjh_~rjh___0#1;setup_rjh_~rjh___0#1 := setup_rjh_#in~rjh___0#1;assume { :begin_inline_setup_rjh__wrappee__Base } true;setup_rjh__wrappee__Base_#in~rjh___0#1 := setup_rjh_~rjh___0#1;havoc setup_rjh__wrappee__Base_~rjh___0#1;setup_rjh__wrappee__Base_~rjh___0#1 := setup_rjh__wrappee__Base_#in~rjh___0#1; {25461#true} is VALID [2022-02-20 17:56:42,411 INFO L272 TraceCheckUtils]: 18: Hoare triple {25461#true} call setClientId(setup_rjh__wrappee__Base_~rjh___0#1, setup_rjh__wrappee__Base_~rjh___0#1); {25523#(and (= |old(~__ste_client_idCounter0~0)| ~__ste_client_idCounter0~0) (= |old(~__ste_client_idCounter1~0)| ~__ste_client_idCounter1~0) (= |old(~__ste_client_idCounter2~0)| ~__ste_client_idCounter2~0))} is VALID [2022-02-20 17:56:42,411 INFO L290 TraceCheckUtils]: 19: Hoare triple {25523#(and (= |old(~__ste_client_idCounter0~0)| ~__ste_client_idCounter0~0) (= |old(~__ste_client_idCounter1~0)| ~__ste_client_idCounter1~0) (= |old(~__ste_client_idCounter2~0)| ~__ste_client_idCounter2~0))} ~handle := #in~handle;~value := #in~value; {25461#true} is VALID [2022-02-20 17:56:42,412 INFO L290 TraceCheckUtils]: 20: Hoare triple {25461#true} assume !(1 == ~handle); {25461#true} is VALID [2022-02-20 17:56:42,412 INFO L290 TraceCheckUtils]: 21: Hoare triple {25461#true} assume 2 == ~handle;~__ste_client_idCounter1~0 := ~value; {25461#true} is VALID [2022-02-20 17:56:42,412 INFO L290 TraceCheckUtils]: 22: Hoare triple {25461#true} assume true; {25461#true} is VALID [2022-02-20 17:56:42,412 INFO L284 TraceCheckUtils]: 23: Hoare quadruple {25461#true} {25461#true} #1137#return; {25461#true} is VALID [2022-02-20 17:56:42,412 INFO L290 TraceCheckUtils]: 24: Hoare triple {25461#true} assume { :end_inline_setup_rjh__wrappee__Base } true; {25461#true} is VALID [2022-02-20 17:56:42,412 INFO L272 TraceCheckUtils]: 25: Hoare triple {25461#true} call setClientPrivateKey(setup_rjh_~rjh___0#1, 456); {25524#(and (= ~__ste_client_privateKey0~0 |old(~__ste_client_privateKey0~0)|) (= ~__ste_client_privateKey2~0 |old(~__ste_client_privateKey2~0)|) (= ~__ste_client_privateKey1~0 |old(~__ste_client_privateKey1~0)|))} is VALID [2022-02-20 17:56:42,413 INFO L290 TraceCheckUtils]: 26: Hoare triple {25524#(and (= ~__ste_client_privateKey0~0 |old(~__ste_client_privateKey0~0)|) (= ~__ste_client_privateKey2~0 |old(~__ste_client_privateKey2~0)|) (= ~__ste_client_privateKey1~0 |old(~__ste_client_privateKey1~0)|))} ~handle := #in~handle;~value := #in~value; {25461#true} is VALID [2022-02-20 17:56:42,413 INFO L290 TraceCheckUtils]: 27: Hoare triple {25461#true} assume !(1 == ~handle); {25461#true} is VALID [2022-02-20 17:56:42,413 INFO L290 TraceCheckUtils]: 28: Hoare triple {25461#true} assume 2 == ~handle;~__ste_client_privateKey1~0 := ~value; {25461#true} is VALID [2022-02-20 17:56:42,413 INFO L290 TraceCheckUtils]: 29: Hoare triple {25461#true} assume true; {25461#true} is VALID [2022-02-20 17:56:42,413 INFO L284 TraceCheckUtils]: 30: Hoare quadruple {25461#true} {25461#true} #1139#return; {25461#true} is VALID [2022-02-20 17:56:42,413 INFO L290 TraceCheckUtils]: 31: Hoare triple {25461#true} assume { :end_inline_setup_rjh } true;setup_~__cil_tmp2~0#1.base, setup_~__cil_tmp2~0#1.offset := 35, 0;havoc setup_#t~nondet96#1;~chuck~0 := 3;assume { :begin_inline_setup_chuck } true;setup_chuck_#in~chuck___0#1 := ~chuck~0;havoc setup_chuck_~chuck___0#1;setup_chuck_~chuck___0#1 := setup_chuck_#in~chuck___0#1;assume { :begin_inline_setup_chuck__wrappee__Base } true;setup_chuck__wrappee__Base_#in~chuck___0#1 := setup_chuck_~chuck___0#1;havoc setup_chuck__wrappee__Base_~chuck___0#1;setup_chuck__wrappee__Base_~chuck___0#1 := setup_chuck__wrappee__Base_#in~chuck___0#1; {25481#(= |ULTIMATE.start_setup_chuck_~chuck___0#1| |ULTIMATE.start_setup_chuck__wrappee__Base_~chuck___0#1|)} is VALID [2022-02-20 17:56:42,414 INFO L272 TraceCheckUtils]: 32: Hoare triple {25481#(= |ULTIMATE.start_setup_chuck_~chuck___0#1| |ULTIMATE.start_setup_chuck__wrappee__Base_~chuck___0#1|)} call setClientId(setup_chuck__wrappee__Base_~chuck___0#1, setup_chuck__wrappee__Base_~chuck___0#1); {25523#(and (= |old(~__ste_client_idCounter0~0)| ~__ste_client_idCounter0~0) (= |old(~__ste_client_idCounter1~0)| ~__ste_client_idCounter1~0) (= |old(~__ste_client_idCounter2~0)| ~__ste_client_idCounter2~0))} is VALID [2022-02-20 17:56:42,414 INFO L290 TraceCheckUtils]: 33: Hoare triple {25523#(and (= |old(~__ste_client_idCounter0~0)| ~__ste_client_idCounter0~0) (= |old(~__ste_client_idCounter1~0)| ~__ste_client_idCounter1~0) (= |old(~__ste_client_idCounter2~0)| ~__ste_client_idCounter2~0))} ~handle := #in~handle;~value := #in~value; {25525#(= setClientId_~handle |setClientId_#in~handle|)} is VALID [2022-02-20 17:56:42,414 INFO L290 TraceCheckUtils]: 34: Hoare triple {25525#(= setClientId_~handle |setClientId_#in~handle|)} assume !(1 == ~handle); {25525#(= setClientId_~handle |setClientId_#in~handle|)} is VALID [2022-02-20 17:56:42,415 INFO L290 TraceCheckUtils]: 35: Hoare triple {25525#(= setClientId_~handle |setClientId_#in~handle|)} assume !(2 == ~handle); {25525#(= setClientId_~handle |setClientId_#in~handle|)} is VALID [2022-02-20 17:56:42,415 INFO L290 TraceCheckUtils]: 36: Hoare triple {25525#(= setClientId_~handle |setClientId_#in~handle|)} assume 3 == ~handle;~__ste_client_idCounter2~0 := ~value; {25526#(= 3 |setClientId_#in~handle|)} is VALID [2022-02-20 17:56:42,415 INFO L290 TraceCheckUtils]: 37: Hoare triple {25526#(= 3 |setClientId_#in~handle|)} assume true; {25526#(= 3 |setClientId_#in~handle|)} is VALID [2022-02-20 17:56:42,416 INFO L284 TraceCheckUtils]: 38: Hoare quadruple {25526#(= 3 |setClientId_#in~handle|)} {25481#(= |ULTIMATE.start_setup_chuck_~chuck___0#1| |ULTIMATE.start_setup_chuck__wrappee__Base_~chuck___0#1|)} #1141#return; {25488#(not (= |ULTIMATE.start_setup_chuck_~chuck___0#1| 2))} is VALID [2022-02-20 17:56:42,416 INFO L290 TraceCheckUtils]: 39: Hoare triple {25488#(not (= |ULTIMATE.start_setup_chuck_~chuck___0#1| 2))} assume { :end_inline_setup_chuck__wrappee__Base } true; {25488#(not (= |ULTIMATE.start_setup_chuck_~chuck___0#1| 2))} is VALID [2022-02-20 17:56:42,416 INFO L272 TraceCheckUtils]: 40: Hoare triple {25488#(not (= |ULTIMATE.start_setup_chuck_~chuck___0#1| 2))} call setClientPrivateKey(setup_chuck_~chuck___0#1, 789); {25524#(and (= ~__ste_client_privateKey0~0 |old(~__ste_client_privateKey0~0)|) (= ~__ste_client_privateKey2~0 |old(~__ste_client_privateKey2~0)|) (= ~__ste_client_privateKey1~0 |old(~__ste_client_privateKey1~0)|))} is VALID [2022-02-20 17:56:42,417 INFO L290 TraceCheckUtils]: 41: Hoare triple {25524#(and (= ~__ste_client_privateKey0~0 |old(~__ste_client_privateKey0~0)|) (= ~__ste_client_privateKey2~0 |old(~__ste_client_privateKey2~0)|) (= ~__ste_client_privateKey1~0 |old(~__ste_client_privateKey1~0)|))} ~handle := #in~handle;~value := #in~value; {25527#(= setClientPrivateKey_~handle |setClientPrivateKey_#in~handle|)} is VALID [2022-02-20 17:56:42,417 INFO L290 TraceCheckUtils]: 42: Hoare triple {25527#(= setClientPrivateKey_~handle |setClientPrivateKey_#in~handle|)} assume !(1 == ~handle); {25527#(= setClientPrivateKey_~handle |setClientPrivateKey_#in~handle|)} is VALID [2022-02-20 17:56:42,417 INFO L290 TraceCheckUtils]: 43: Hoare triple {25527#(= setClientPrivateKey_~handle |setClientPrivateKey_#in~handle|)} assume 2 == ~handle;~__ste_client_privateKey1~0 := ~value; {25528#(= 2 |setClientPrivateKey_#in~handle|)} is VALID [2022-02-20 17:56:42,417 INFO L290 TraceCheckUtils]: 44: Hoare triple {25528#(= 2 |setClientPrivateKey_#in~handle|)} assume true; {25528#(= 2 |setClientPrivateKey_#in~handle|)} is VALID [2022-02-20 17:56:42,418 INFO L284 TraceCheckUtils]: 45: Hoare quadruple {25528#(= 2 |setClientPrivateKey_#in~handle|)} {25488#(not (= |ULTIMATE.start_setup_chuck_~chuck___0#1| 2))} #1143#return; {25462#false} is VALID [2022-02-20 17:56:42,418 INFO L290 TraceCheckUtils]: 46: Hoare triple {25462#false} assume { :end_inline_setup_chuck } true;setup_~__cil_tmp3~2#1.base, setup_~__cil_tmp3~2#1.offset := 36, 0;havoc setup_#t~nondet97#1; {25462#false} is VALID [2022-02-20 17:56:42,418 INFO L290 TraceCheckUtils]: 47: Hoare triple {25462#false} assume { :end_inline_setup } true;assume { :begin_inline_test } true;havoc test_#t~nondet48#1, test_#t~nondet49#1, test_#t~nondet50#1, test_#t~nondet51#1, test_#t~nondet52#1, test_#t~nondet53#1, test_#t~nondet54#1, test_#t~nondet55#1, test_#t~nondet56#1, test_#t~nondet57#1, test_#t~nondet58#1, test_~op1~0#1, test_~op2~0#1, test_~op3~0#1, test_~op4~0#1, test_~op5~0#1, test_~op6~0#1, test_~op7~0#1, test_~op8~0#1, test_~op9~0#1, test_~op10~0#1, test_~op11~0#1, test_~splverifierCounter~0#1, test_~tmp~8#1, test_~tmp___0~3#1, test_~tmp___1~1#1, test_~tmp___2~1#1, test_~tmp___3~0#1, test_~tmp___4~0#1, test_~tmp___5~0#1, test_~tmp___6~0#1, test_~tmp___7~0#1, test_~tmp___8~0#1, test_~tmp___9~0#1;havoc test_~op1~0#1;havoc test_~op2~0#1;havoc test_~op3~0#1;havoc test_~op4~0#1;havoc test_~op5~0#1;havoc test_~op6~0#1;havoc test_~op7~0#1;havoc test_~op8~0#1;havoc test_~op9~0#1;havoc test_~op10~0#1;havoc test_~op11~0#1;havoc test_~splverifierCounter~0#1;havoc test_~tmp~8#1;havoc test_~tmp___0~3#1;havoc test_~tmp___1~1#1;havoc test_~tmp___2~1#1;havoc test_~tmp___3~0#1;havoc test_~tmp___4~0#1;havoc test_~tmp___5~0#1;havoc test_~tmp___6~0#1;havoc test_~tmp___7~0#1;havoc test_~tmp___8~0#1;havoc test_~tmp___9~0#1;test_~op1~0#1 := 0;test_~op2~0#1 := 0;test_~op3~0#1 := 0;test_~op4~0#1 := 0;test_~op5~0#1 := 0;test_~op6~0#1 := 0;test_~op7~0#1 := 0;test_~op8~0#1 := 0;test_~op9~0#1 := 0;test_~op10~0#1 := 0;test_~op11~0#1 := 0;test_~splverifierCounter~0#1 := 0; {25462#false} is VALID [2022-02-20 17:56:42,418 INFO L290 TraceCheckUtils]: 48: Hoare triple {25462#false} assume !false; {25462#false} is VALID [2022-02-20 17:56:42,418 INFO L290 TraceCheckUtils]: 49: Hoare triple {25462#false} assume test_~splverifierCounter~0#1 < 4; {25462#false} is VALID [2022-02-20 17:56:42,418 INFO L290 TraceCheckUtils]: 50: Hoare triple {25462#false} test_~splverifierCounter~0#1 := 1 + test_~splverifierCounter~0#1; {25462#false} is VALID [2022-02-20 17:56:42,418 INFO L290 TraceCheckUtils]: 51: Hoare triple {25462#false} assume 0 == test_~op1~0#1;assume -2147483648 <= test_#t~nondet48#1 && test_#t~nondet48#1 <= 2147483647;test_~tmp___9~0#1 := test_#t~nondet48#1;havoc test_#t~nondet48#1; {25462#false} is VALID [2022-02-20 17:56:42,419 INFO L290 TraceCheckUtils]: 52: Hoare triple {25462#false} assume !(0 != test_~tmp___9~0#1); {25462#false} is VALID [2022-02-20 17:56:42,419 INFO L290 TraceCheckUtils]: 53: Hoare triple {25462#false} assume 0 == test_~op2~0#1;assume -2147483648 <= test_#t~nondet49#1 && test_#t~nondet49#1 <= 2147483647;test_~tmp___8~0#1 := test_#t~nondet49#1;havoc test_#t~nondet49#1; {25462#false} is VALID [2022-02-20 17:56:42,419 INFO L290 TraceCheckUtils]: 54: Hoare triple {25462#false} assume 0 != test_~tmp___8~0#1;assume { :begin_inline_rjhSetAutoRespond } true;assume { :begin_inline_setClientAutoResponse } true;setClientAutoResponse_#in~handle#1, setClientAutoResponse_#in~value#1 := ~rjh~0, 1;havoc setClientAutoResponse_~handle#1, setClientAutoResponse_~value#1;setClientAutoResponse_~handle#1 := setClientAutoResponse_#in~handle#1;setClientAutoResponse_~value#1 := setClientAutoResponse_#in~value#1; {25462#false} is VALID [2022-02-20 17:56:42,419 INFO L290 TraceCheckUtils]: 55: Hoare triple {25462#false} assume 1 == setClientAutoResponse_~handle#1;~__ste_client_autoResponse0~0 := setClientAutoResponse_~value#1; {25462#false} is VALID [2022-02-20 17:56:42,419 INFO L290 TraceCheckUtils]: 56: Hoare triple {25462#false} assume { :end_inline_setClientAutoResponse } true; {25462#false} is VALID [2022-02-20 17:56:42,419 INFO L290 TraceCheckUtils]: 57: Hoare triple {25462#false} assume { :end_inline_rjhSetAutoRespond } true;test_~op2~0#1 := 1; {25462#false} is VALID [2022-02-20 17:56:42,419 INFO L290 TraceCheckUtils]: 58: Hoare triple {25462#false} assume !false; {25462#false} is VALID [2022-02-20 17:56:42,419 INFO L290 TraceCheckUtils]: 59: Hoare triple {25462#false} assume !(test_~splverifierCounter~0#1 < 4); {25462#false} is VALID [2022-02-20 17:56:42,419 INFO L290 TraceCheckUtils]: 60: Hoare triple {25462#false} assume { :begin_inline_bobToRjh } true;havoc bobToRjh_#t~ret90#1, bobToRjh_#t~ret91#1, bobToRjh_#t~ret92#1, bobToRjh_#t~ret93#1, bobToRjh_~tmp~23#1, bobToRjh_~tmp___0~7#1, bobToRjh_~tmp___1~4#1;havoc bobToRjh_~tmp~23#1;havoc bobToRjh_~tmp___0~7#1;havoc bobToRjh_~tmp___1~4#1;call bobToRjh_#t~ret90#1 := puts(32, 0);assume -2147483648 <= bobToRjh_#t~ret90#1 && bobToRjh_#t~ret90#1 <= 2147483647;havoc bobToRjh_#t~ret90#1; {25462#false} is VALID [2022-02-20 17:56:42,419 INFO L272 TraceCheckUtils]: 61: Hoare triple {25462#false} call sendEmail(~bob~0, ~rjh~0); {25462#false} is VALID [2022-02-20 17:56:42,420 INFO L290 TraceCheckUtils]: 62: Hoare triple {25462#false} ~sender#1 := #in~sender#1;~receiver#1 := #in~receiver#1;havoc ~email~0#1;havoc ~tmp~16#1;assume { :begin_inline_createEmail } true;createEmail_#in~from#1, createEmail_#in~to#1 := 0, ~receiver#1;havoc createEmail_#res#1;havoc createEmail_~from#1, createEmail_~to#1, createEmail_~retValue_acc~4#1, createEmail_~msg~0#1;createEmail_~from#1 := createEmail_#in~from#1;createEmail_~to#1 := createEmail_#in~to#1;havoc createEmail_~retValue_acc~4#1;havoc createEmail_~msg~0#1;createEmail_~msg~0#1 := 1; {25462#false} is VALID [2022-02-20 17:56:42,420 INFO L272 TraceCheckUtils]: 63: Hoare triple {25462#false} call setEmailFrom(createEmail_~msg~0#1, createEmail_~from#1); {25529#(and (= |old(~__ste_email_from0~0)| ~__ste_email_from0~0) (= |old(~__ste_email_from1~0)| ~__ste_email_from1~0))} is VALID [2022-02-20 17:56:42,420 INFO L290 TraceCheckUtils]: 64: Hoare triple {25529#(and (= |old(~__ste_email_from0~0)| ~__ste_email_from0~0) (= |old(~__ste_email_from1~0)| ~__ste_email_from1~0))} ~handle := #in~handle;~value := #in~value; {25461#true} is VALID [2022-02-20 17:56:42,420 INFO L290 TraceCheckUtils]: 65: Hoare triple {25461#true} assume 1 == ~handle;~__ste_email_from0~0 := ~value; {25461#true} is VALID [2022-02-20 17:56:42,420 INFO L290 TraceCheckUtils]: 66: Hoare triple {25461#true} assume true; {25461#true} is VALID [2022-02-20 17:56:42,420 INFO L284 TraceCheckUtils]: 67: Hoare quadruple {25461#true} {25462#false} #1119#return; {25462#false} is VALID [2022-02-20 17:56:42,420 INFO L272 TraceCheckUtils]: 68: Hoare triple {25462#false} call setEmailTo(createEmail_~msg~0#1, createEmail_~to#1); {25530#(and (= ~__ste_email_to0~0 |old(~__ste_email_to0~0)|) (= ~__ste_email_to1~0 |old(~__ste_email_to1~0)|))} is VALID [2022-02-20 17:56:42,420 INFO L290 TraceCheckUtils]: 69: Hoare triple {25530#(and (= ~__ste_email_to0~0 |old(~__ste_email_to0~0)|) (= ~__ste_email_to1~0 |old(~__ste_email_to1~0)|))} ~handle := #in~handle;~value := #in~value; {25461#true} is VALID [2022-02-20 17:56:42,420 INFO L290 TraceCheckUtils]: 70: Hoare triple {25461#true} assume 1 == ~handle;~__ste_email_to0~0 := ~value; {25461#true} is VALID [2022-02-20 17:56:42,420 INFO L290 TraceCheckUtils]: 71: Hoare triple {25461#true} assume true; {25461#true} is VALID [2022-02-20 17:56:42,421 INFO L284 TraceCheckUtils]: 72: Hoare quadruple {25461#true} {25462#false} #1121#return; {25462#false} is VALID [2022-02-20 17:56:42,421 INFO L290 TraceCheckUtils]: 73: Hoare triple {25462#false} createEmail_~retValue_acc~4#1 := createEmail_~msg~0#1;createEmail_#res#1 := createEmail_~retValue_acc~4#1; {25462#false} is VALID [2022-02-20 17:56:42,421 INFO L290 TraceCheckUtils]: 74: Hoare triple {25462#false} #t~ret73#1 := createEmail_#res#1;assume { :end_inline_createEmail } true;assume -2147483648 <= #t~ret73#1 && #t~ret73#1 <= 2147483647;~tmp~16#1 := #t~ret73#1;havoc #t~ret73#1;~email~0#1 := ~tmp~16#1; {25462#false} is VALID [2022-02-20 17:56:42,421 INFO L272 TraceCheckUtils]: 75: Hoare triple {25462#false} call outgoing(~sender#1, ~email~0#1); {25462#false} is VALID [2022-02-20 17:56:42,421 INFO L290 TraceCheckUtils]: 76: Hoare triple {25462#false} ~client#1 := #in~client#1;~msg#1 := #in~msg#1;assume { :begin_inline_sign } true;sign_#in~client#1, sign_#in~msg#1 := ~client#1, ~msg#1;havoc sign_#t~ret77#1, sign_~client#1, sign_~msg#1, sign_~privkey~1#1, sign_~tmp~18#1;sign_~client#1 := sign_#in~client#1;sign_~msg#1 := sign_#in~msg#1;havoc sign_~privkey~1#1;havoc sign_~tmp~18#1; {25462#false} is VALID [2022-02-20 17:56:42,421 INFO L272 TraceCheckUtils]: 77: Hoare triple {25462#false} call sign_#t~ret77#1 := getClientPrivateKey(sign_~client#1); {25461#true} is VALID [2022-02-20 17:56:42,421 INFO L290 TraceCheckUtils]: 78: Hoare triple {25461#true} ~handle := #in~handle;havoc ~retValue_acc~24; {25461#true} is VALID [2022-02-20 17:56:42,421 INFO L290 TraceCheckUtils]: 79: Hoare triple {25461#true} assume 1 == ~handle;~retValue_acc~24 := ~__ste_client_privateKey0~0;#res := ~retValue_acc~24; {25461#true} is VALID [2022-02-20 17:56:42,421 INFO L290 TraceCheckUtils]: 80: Hoare triple {25461#true} assume true; {25461#true} is VALID [2022-02-20 17:56:42,421 INFO L284 TraceCheckUtils]: 81: Hoare quadruple {25461#true} {25462#false} #1053#return; {25462#false} is VALID [2022-02-20 17:56:42,422 INFO L290 TraceCheckUtils]: 82: Hoare triple {25462#false} assume -2147483648 <= sign_#t~ret77#1 && sign_#t~ret77#1 <= 2147483647;sign_~tmp~18#1 := sign_#t~ret77#1;havoc sign_#t~ret77#1;sign_~privkey~1#1 := sign_~tmp~18#1; {25462#false} is VALID [2022-02-20 17:56:42,422 INFO L290 TraceCheckUtils]: 83: Hoare triple {25462#false} assume 0 == sign_~privkey~1#1; {25462#false} is VALID [2022-02-20 17:56:42,422 INFO L290 TraceCheckUtils]: 84: Hoare triple {25462#false} assume { :end_inline_sign } true;assume { :begin_inline_outgoing__wrappee__AutoResponder } true;outgoing__wrappee__AutoResponder_#in~client#1, outgoing__wrappee__AutoResponder_#in~msg#1 := ~client#1, ~msg#1;havoc outgoing__wrappee__AutoResponder_#t~ret63#1, outgoing__wrappee__AutoResponder_#t~ret64#1, outgoing__wrappee__AutoResponder_~client#1, outgoing__wrappee__AutoResponder_~msg#1, outgoing__wrappee__AutoResponder_~receiver~0#1, outgoing__wrappee__AutoResponder_~tmp~11#1, outgoing__wrappee__AutoResponder_~pubkey~0#1, outgoing__wrappee__AutoResponder_~tmp___0~4#1;outgoing__wrappee__AutoResponder_~client#1 := outgoing__wrappee__AutoResponder_#in~client#1;outgoing__wrappee__AutoResponder_~msg#1 := outgoing__wrappee__AutoResponder_#in~msg#1;havoc outgoing__wrappee__AutoResponder_~receiver~0#1;havoc outgoing__wrappee__AutoResponder_~tmp~11#1;havoc outgoing__wrappee__AutoResponder_~pubkey~0#1;havoc outgoing__wrappee__AutoResponder_~tmp___0~4#1; {25462#false} is VALID [2022-02-20 17:56:42,422 INFO L272 TraceCheckUtils]: 85: Hoare triple {25462#false} call outgoing__wrappee__AutoResponder_#t~ret63#1 := getEmailTo(outgoing__wrappee__AutoResponder_~msg#1); {25461#true} is VALID [2022-02-20 17:56:42,422 INFO L290 TraceCheckUtils]: 86: Hoare triple {25461#true} ~handle := #in~handle;havoc ~retValue_acc~36; {25461#true} is VALID [2022-02-20 17:56:42,422 INFO L290 TraceCheckUtils]: 87: Hoare triple {25461#true} assume 1 == ~handle;~retValue_acc~36 := ~__ste_email_to0~0;#res := ~retValue_acc~36; {25461#true} is VALID [2022-02-20 17:56:42,422 INFO L290 TraceCheckUtils]: 88: Hoare triple {25461#true} assume true; {25461#true} is VALID [2022-02-20 17:56:42,422 INFO L284 TraceCheckUtils]: 89: Hoare quadruple {25461#true} {25462#false} #1055#return; {25462#false} is VALID [2022-02-20 17:56:42,422 INFO L290 TraceCheckUtils]: 90: Hoare triple {25462#false} assume -2147483648 <= outgoing__wrappee__AutoResponder_#t~ret63#1 && outgoing__wrappee__AutoResponder_#t~ret63#1 <= 2147483647;outgoing__wrappee__AutoResponder_~tmp~11#1 := outgoing__wrappee__AutoResponder_#t~ret63#1;havoc outgoing__wrappee__AutoResponder_#t~ret63#1;outgoing__wrappee__AutoResponder_~receiver~0#1 := outgoing__wrappee__AutoResponder_~tmp~11#1; {25462#false} is VALID [2022-02-20 17:56:42,422 INFO L272 TraceCheckUtils]: 91: Hoare triple {25462#false} call outgoing__wrappee__AutoResponder_#t~ret64#1 := findPublicKey(outgoing__wrappee__AutoResponder_~client#1, outgoing__wrappee__AutoResponder_~receiver~0#1); {25461#true} is VALID [2022-02-20 17:56:42,423 INFO L290 TraceCheckUtils]: 92: Hoare triple {25461#true} ~handle := #in~handle;~userid := #in~userid;havoc ~retValue_acc~29; {25461#true} is VALID [2022-02-20 17:56:42,423 INFO L290 TraceCheckUtils]: 93: Hoare triple {25461#true} assume 1 == ~handle; {25461#true} is VALID [2022-02-20 17:56:42,423 INFO L290 TraceCheckUtils]: 94: Hoare triple {25461#true} assume ~userid == ~__ste_Client_Keyring0_User0~0;~retValue_acc~29 := ~__ste_Client_Keyring0_PublicKey0~0;#res := ~retValue_acc~29; {25461#true} is VALID [2022-02-20 17:56:42,423 INFO L290 TraceCheckUtils]: 95: Hoare triple {25461#true} assume true; {25461#true} is VALID [2022-02-20 17:56:42,423 INFO L284 TraceCheckUtils]: 96: Hoare quadruple {25461#true} {25462#false} #1057#return; {25462#false} is VALID [2022-02-20 17:56:42,423 INFO L290 TraceCheckUtils]: 97: Hoare triple {25462#false} assume -2147483648 <= outgoing__wrappee__AutoResponder_#t~ret64#1 && outgoing__wrappee__AutoResponder_#t~ret64#1 <= 2147483647;outgoing__wrappee__AutoResponder_~tmp___0~4#1 := outgoing__wrappee__AutoResponder_#t~ret64#1;havoc outgoing__wrappee__AutoResponder_#t~ret64#1;outgoing__wrappee__AutoResponder_~pubkey~0#1 := outgoing__wrappee__AutoResponder_~tmp___0~4#1; {25462#false} is VALID [2022-02-20 17:56:42,423 INFO L290 TraceCheckUtils]: 98: Hoare triple {25462#false} assume !(0 != outgoing__wrappee__AutoResponder_~pubkey~0#1); {25462#false} is VALID [2022-02-20 17:56:42,423 INFO L290 TraceCheckUtils]: 99: Hoare triple {25462#false} assume { :begin_inline_outgoing__wrappee__Keys } true;outgoing__wrappee__Keys_#in~client#1, outgoing__wrappee__Keys_#in~msg#1 := outgoing__wrappee__AutoResponder_~client#1, outgoing__wrappee__AutoResponder_~msg#1;havoc outgoing__wrappee__Keys_#t~ret62#1, outgoing__wrappee__Keys_~client#1, outgoing__wrappee__Keys_~msg#1, outgoing__wrappee__Keys_~tmp~10#1;outgoing__wrappee__Keys_~client#1 := outgoing__wrappee__Keys_#in~client#1;outgoing__wrappee__Keys_~msg#1 := outgoing__wrappee__Keys_#in~msg#1;havoc outgoing__wrappee__Keys_~tmp~10#1;assume { :begin_inline_getClientId } true;getClientId_#in~handle#1 := outgoing__wrappee__Keys_~client#1;havoc getClientId_#res#1;havoc getClientId_~handle#1, getClientId_~retValue_acc~31#1;getClientId_~handle#1 := getClientId_#in~handle#1;havoc getClientId_~retValue_acc~31#1; {25462#false} is VALID [2022-02-20 17:56:42,423 INFO L290 TraceCheckUtils]: 100: Hoare triple {25462#false} assume 1 == getClientId_~handle#1;getClientId_~retValue_acc~31#1 := ~__ste_client_idCounter0~0;getClientId_#res#1 := getClientId_~retValue_acc~31#1; {25462#false} is VALID [2022-02-20 17:56:42,424 INFO L290 TraceCheckUtils]: 101: Hoare triple {25462#false} outgoing__wrappee__Keys_#t~ret62#1 := getClientId_#res#1;assume { :end_inline_getClientId } true;assume -2147483648 <= outgoing__wrappee__Keys_#t~ret62#1 && outgoing__wrappee__Keys_#t~ret62#1 <= 2147483647;outgoing__wrappee__Keys_~tmp~10#1 := outgoing__wrappee__Keys_#t~ret62#1;havoc outgoing__wrappee__Keys_#t~ret62#1; {25462#false} is VALID [2022-02-20 17:56:42,424 INFO L272 TraceCheckUtils]: 102: Hoare triple {25462#false} call setEmailFrom(outgoing__wrappee__Keys_~msg#1, outgoing__wrappee__Keys_~tmp~10#1); {25529#(and (= |old(~__ste_email_from0~0)| ~__ste_email_from0~0) (= |old(~__ste_email_from1~0)| ~__ste_email_from1~0))} is VALID [2022-02-20 17:56:42,424 INFO L290 TraceCheckUtils]: 103: Hoare triple {25529#(and (= |old(~__ste_email_from0~0)| ~__ste_email_from0~0) (= |old(~__ste_email_from1~0)| ~__ste_email_from1~0))} ~handle := #in~handle;~value := #in~value; {25461#true} is VALID [2022-02-20 17:56:42,424 INFO L290 TraceCheckUtils]: 104: Hoare triple {25461#true} assume 1 == ~handle;~__ste_email_from0~0 := ~value; {25461#true} is VALID [2022-02-20 17:56:42,424 INFO L290 TraceCheckUtils]: 105: Hoare triple {25461#true} assume true; {25461#true} is VALID [2022-02-20 17:56:42,424 INFO L284 TraceCheckUtils]: 106: Hoare quadruple {25461#true} {25462#false} #1063#return; {25462#false} is VALID [2022-02-20 17:56:42,424 INFO L290 TraceCheckUtils]: 107: Hoare triple {25462#false} assume { :begin_inline_mail } true;mail_#in~client#1, mail_#in~msg#1 := outgoing__wrappee__Keys_~client#1, outgoing__wrappee__Keys_~msg#1;havoc mail_#t~ret60#1, mail_#t~ret61#1, mail_~client#1, mail_~msg#1, mail_~__utac__ad__arg1~0#1, mail_~__utac__ad__arg2~0#1, mail_~tmp~9#1;mail_~client#1 := mail_#in~client#1;mail_~msg#1 := mail_#in~msg#1;havoc mail_~__utac__ad__arg1~0#1;havoc mail_~__utac__ad__arg2~0#1;havoc mail_~tmp~9#1;mail_~__utac__ad__arg1~0#1 := mail_~client#1;mail_~__utac__ad__arg2~0#1 := mail_~msg#1;assume { :begin_inline___utac_acc__AddressBookEncrypt_spec__1 } true;__utac_acc__AddressBookEncrypt_spec__1_#in~client#1, __utac_acc__AddressBookEncrypt_spec__1_#in~msg#1 := mail_~__utac__ad__arg1~0#1, mail_~__utac__ad__arg2~0#1;havoc __utac_acc__AddressBookEncrypt_spec__1_#t~ret85#1, __utac_acc__AddressBookEncrypt_spec__1_#t~ret86#1, __utac_acc__AddressBookEncrypt_spec__1_#t~ret87#1, __utac_acc__AddressBookEncrypt_spec__1_~client#1, __utac_acc__AddressBookEncrypt_spec__1_~msg#1, __utac_acc__AddressBookEncrypt_spec__1_~tmp~20#1;__utac_acc__AddressBookEncrypt_spec__1_~client#1 := __utac_acc__AddressBookEncrypt_spec__1_#in~client#1;__utac_acc__AddressBookEncrypt_spec__1_~msg#1 := __utac_acc__AddressBookEncrypt_spec__1_#in~msg#1;havoc __utac_acc__AddressBookEncrypt_spec__1_~tmp~20#1;call __utac_acc__AddressBookEncrypt_spec__1_#t~ret85#1 := puts(31, 0);assume -2147483648 <= __utac_acc__AddressBookEncrypt_spec__1_#t~ret85#1 && __utac_acc__AddressBookEncrypt_spec__1_#t~ret85#1 <= 2147483647;havoc __utac_acc__AddressBookEncrypt_spec__1_#t~ret85#1; {25462#false} is VALID [2022-02-20 17:56:42,424 INFO L290 TraceCheckUtils]: 108: Hoare triple {25462#false} assume !(-1 == ~mail_is_sensitive~0); {25462#false} is VALID [2022-02-20 17:56:42,424 INFO L272 TraceCheckUtils]: 109: Hoare triple {25462#false} call __utac_acc__AddressBookEncrypt_spec__1_#t~ret87#1 := isEncrypted(__utac_acc__AddressBookEncrypt_spec__1_~msg#1); {25461#true} is VALID [2022-02-20 17:56:42,424 INFO L290 TraceCheckUtils]: 110: Hoare triple {25461#true} ~handle := #in~handle;havoc ~retValue_acc~39; {25461#true} is VALID [2022-02-20 17:56:42,425 INFO L290 TraceCheckUtils]: 111: Hoare triple {25461#true} assume 1 == ~handle;~retValue_acc~39 := ~__ste_email_isEncrypted0~0;#res := ~retValue_acc~39; {25461#true} is VALID [2022-02-20 17:56:42,425 INFO L290 TraceCheckUtils]: 112: Hoare triple {25461#true} assume true; {25461#true} is VALID [2022-02-20 17:56:42,425 INFO L284 TraceCheckUtils]: 113: Hoare quadruple {25461#true} {25462#false} #1067#return; {25462#false} is VALID [2022-02-20 17:56:42,425 INFO L290 TraceCheckUtils]: 114: Hoare triple {25462#false} assume -2147483648 <= __utac_acc__AddressBookEncrypt_spec__1_#t~ret87#1 && __utac_acc__AddressBookEncrypt_spec__1_#t~ret87#1 <= 2147483647;__utac_acc__AddressBookEncrypt_spec__1_~tmp~20#1 := __utac_acc__AddressBookEncrypt_spec__1_#t~ret87#1;havoc __utac_acc__AddressBookEncrypt_spec__1_#t~ret87#1; {25462#false} is VALID [2022-02-20 17:56:42,425 INFO L290 TraceCheckUtils]: 115: Hoare triple {25462#false} assume ~mail_is_sensitive~0 != __utac_acc__AddressBookEncrypt_spec__1_~tmp~20#1;assume { :begin_inline___automaton_fail } true; {25462#false} is VALID [2022-02-20 17:56:42,425 INFO L290 TraceCheckUtils]: 116: Hoare triple {25462#false} assume !false; {25462#false} is VALID [2022-02-20 17:56:42,425 INFO L134 CoverageAnalysis]: Checked inductivity of 32 backedges. 14 proven. 0 refuted. 0 times theorem prover too weak. 18 trivial. 0 not checked. [2022-02-20 17:56:42,426 INFO L144 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2022-02-20 17:56:42,426 INFO L338 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [1919812849] [2022-02-20 17:56:42,426 INFO L165 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [1919812849] provided 1 perfect and 0 imperfect interpolant sequences [2022-02-20 17:56:42,426 INFO L191 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2022-02-20 17:56:42,426 INFO L204 FreeRefinementEngine]: Number of different interpolants: perfect sequences [12] imperfect sequences [] total 12 [2022-02-20 17:56:42,426 INFO L118 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [386236159] [2022-02-20 17:56:42,426 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2022-02-20 17:56:42,427 INFO L78 Accepts]: Start accepts. Automaton has has 12 states, 11 states have (on average 7.363636363636363) internal successors, (81), 8 states have internal predecessors, (81), 4 states have call successors, (15), 6 states have call predecessors, (15), 3 states have return successors, (13), 3 states have call predecessors, (13), 4 states have call successors, (13) Word has length 117 [2022-02-20 17:56:42,427 INFO L84 Accepts]: Finished accepts. word is accepted. [2022-02-20 17:56:42,427 INFO L86 InductivityCheck]: Starting indutivity check of a Floyd-Hoare automaton with has 12 states, 11 states have (on average 7.363636363636363) internal successors, (81), 8 states have internal predecessors, (81), 4 states have call successors, (15), 6 states have call predecessors, (15), 3 states have return successors, (13), 3 states have call predecessors, (13), 4 states have call successors, (13) [2022-02-20 17:56:42,486 INFO L122 InductivityCheck]: Floyd-Hoare automaton has 109 edges. 109 inductive. 0 not inductive. 0 times theorem prover too weak to decide inductivity. [2022-02-20 17:56:42,486 INFO L546 AbstractCegarLoop]: INTERPOLANT automaton has 12 states [2022-02-20 17:56:42,487 INFO L108 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2022-02-20 17:56:42,487 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 12 interpolants. [2022-02-20 17:56:42,487 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=21, Invalid=111, Unknown=0, NotChecked=0, Total=132 [2022-02-20 17:56:42,487 INFO L87 Difference]: Start difference. First operand 443 states and 667 transitions. Second operand has 12 states, 11 states have (on average 7.363636363636363) internal successors, (81), 8 states have internal predecessors, (81), 4 states have call successors, (15), 6 states have call predecessors, (15), 3 states have return successors, (13), 3 states have call predecessors, (13), 4 states have call successors, (13) [2022-02-20 17:56:53,592 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-02-20 17:56:53,592 INFO L93 Difference]: Finished difference Result 1075 states and 1634 transitions. [2022-02-20 17:56:53,592 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 14 states. [2022-02-20 17:56:53,592 INFO L78 Accepts]: Start accepts. Automaton has has 12 states, 11 states have (on average 7.363636363636363) internal successors, (81), 8 states have internal predecessors, (81), 4 states have call successors, (15), 6 states have call predecessors, (15), 3 states have return successors, (13), 3 states have call predecessors, (13), 4 states have call successors, (13) Word has length 117 [2022-02-20 17:56:53,592 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2022-02-20 17:56:53,593 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 12 states, 11 states have (on average 7.363636363636363) internal successors, (81), 8 states have internal predecessors, (81), 4 states have call successors, (15), 6 states have call predecessors, (15), 3 states have return successors, (13), 3 states have call predecessors, (13), 4 states have call successors, (13) [2022-02-20 17:56:53,602 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 14 states to 14 states and 1431 transitions. [2022-02-20 17:56:53,603 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 12 states, 11 states have (on average 7.363636363636363) internal successors, (81), 8 states have internal predecessors, (81), 4 states have call successors, (15), 6 states have call predecessors, (15), 3 states have return successors, (13), 3 states have call predecessors, (13), 4 states have call successors, (13) [2022-02-20 17:56:53,612 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 14 states to 14 states and 1431 transitions. [2022-02-20 17:56:53,613 INFO L86 InductivityCheck]: Starting indutivity check of a Floyd-Hoare automaton with 14 states and 1431 transitions. [2022-02-20 17:56:54,709 INFO L122 InductivityCheck]: Floyd-Hoare automaton has 1431 edges. 1431 inductive. 0 not inductive. 0 times theorem prover too weak to decide inductivity. [2022-02-20 17:56:54,730 INFO L225 Difference]: With dead ends: 1075 [2022-02-20 17:56:54,730 INFO L226 Difference]: Without dead ends: 659 [2022-02-20 17:56:54,732 INFO L932 BasicCegarLoop]: 0 DeclaredPredicates, 51 GetRequests, 29 SyntacticMatches, 0 SemanticMatches, 22 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 71 ImplicationChecksByTransitivity, 0.2s TimeCoverageRelationStatistics Valid=112, Invalid=440, Unknown=0, NotChecked=0, Total=552 [2022-02-20 17:56:54,734 INFO L933 BasicCegarLoop]: 699 mSDtfsCounter, 1499 mSDsluCounter, 1196 mSDsCounter, 0 mSdLazyCounter, 4688 mSolverCounterSat, 640 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 5.3s Time, 0 mProtectedPredicate, 0 mProtectedAction, 1499 SdHoareTripleChecker+Valid, 1895 SdHoareTripleChecker+Invalid, 5328 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 640 IncrementalHoareTripleChecker+Valid, 4688 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 5.3s IncrementalHoareTripleChecker+Time [2022-02-20 17:56:54,734 INFO L934 BasicCegarLoop]: SdHoareTripleChecker [1499 Valid, 1895 Invalid, 5328 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [640 Valid, 4688 Invalid, 0 Unknown, 0 Unchecked, 5.3s Time] [2022-02-20 17:56:54,735 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 659 states. [2022-02-20 17:56:54,829 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 659 to 445. [2022-02-20 17:56:54,829 INFO L214 AbstractMinimizeNwa]: Start testing correctness of minimizeSevpa [2022-02-20 17:56:54,830 INFO L82 GeneralOperation]: Start isEquivalent. First operand 659 states. Second operand has 445 states, 342 states have (on average 1.5029239766081872) internal successors, (514), 349 states have internal predecessors, (514), 74 states have call successors, (74), 24 states have call predecessors, (74), 28 states have return successors, (85), 73 states have call predecessors, (85), 73 states have call successors, (85) [2022-02-20 17:56:54,830 INFO L74 IsIncluded]: Start isIncluded. First operand 659 states. Second operand has 445 states, 342 states have (on average 1.5029239766081872) internal successors, (514), 349 states have internal predecessors, (514), 74 states have call successors, (74), 24 states have call predecessors, (74), 28 states have return successors, (85), 73 states have call predecessors, (85), 73 states have call successors, (85) [2022-02-20 17:56:54,831 INFO L87 Difference]: Start difference. First operand 659 states. Second operand has 445 states, 342 states have (on average 1.5029239766081872) internal successors, (514), 349 states have internal predecessors, (514), 74 states have call successors, (74), 24 states have call predecessors, (74), 28 states have return successors, (85), 73 states have call predecessors, (85), 73 states have call successors, (85) [2022-02-20 17:56:54,846 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-02-20 17:56:54,847 INFO L93 Difference]: Finished difference Result 659 states and 1003 transitions. [2022-02-20 17:56:54,847 INFO L276 IsEmpty]: Start isEmpty. Operand 659 states and 1003 transitions. [2022-02-20 17:56:54,849 INFO L282 IsEmpty]: Finished isEmpty. No accepting run. [2022-02-20 17:56:54,849 INFO L83 IsIncluded]: Finished isIncluded. Language is included [2022-02-20 17:56:54,850 INFO L74 IsIncluded]: Start isIncluded. First operand has 445 states, 342 states have (on average 1.5029239766081872) internal successors, (514), 349 states have internal predecessors, (514), 74 states have call successors, (74), 24 states have call predecessors, (74), 28 states have return successors, (85), 73 states have call predecessors, (85), 73 states have call successors, (85) Second operand 659 states. [2022-02-20 17:56:54,850 INFO L87 Difference]: Start difference. First operand has 445 states, 342 states have (on average 1.5029239766081872) internal successors, (514), 349 states have internal predecessors, (514), 74 states have call successors, (74), 24 states have call predecessors, (74), 28 states have return successors, (85), 73 states have call predecessors, (85), 73 states have call successors, (85) Second operand 659 states. [2022-02-20 17:56:54,866 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-02-20 17:56:54,867 INFO L93 Difference]: Finished difference Result 659 states and 1003 transitions. [2022-02-20 17:56:54,867 INFO L276 IsEmpty]: Start isEmpty. Operand 659 states and 1003 transitions. [2022-02-20 17:56:54,869 INFO L282 IsEmpty]: Finished isEmpty. No accepting run. [2022-02-20 17:56:54,869 INFO L83 IsIncluded]: Finished isIncluded. Language is included [2022-02-20 17:56:54,869 INFO L88 GeneralOperation]: Finished isEquivalent. [2022-02-20 17:56:54,869 INFO L221 AbstractMinimizeNwa]: Finished testing correctness of minimizeSevpa [2022-02-20 17:56:54,870 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 445 states, 342 states have (on average 1.5029239766081872) internal successors, (514), 349 states have internal predecessors, (514), 74 states have call successors, (74), 24 states have call predecessors, (74), 28 states have return successors, (85), 73 states have call predecessors, (85), 73 states have call successors, (85) [2022-02-20 17:56:54,880 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 445 states to 445 states and 673 transitions. [2022-02-20 17:56:54,881 INFO L78 Accepts]: Start accepts. Automaton has 445 states and 673 transitions. Word has length 117 [2022-02-20 17:56:54,881 INFO L84 Accepts]: Finished accepts. word is rejected. [2022-02-20 17:56:54,881 INFO L470 AbstractCegarLoop]: Abstraction has 445 states and 673 transitions. [2022-02-20 17:56:54,881 INFO L471 AbstractCegarLoop]: INTERPOLANT automaton has has 12 states, 11 states have (on average 7.363636363636363) internal successors, (81), 8 states have internal predecessors, (81), 4 states have call successors, (15), 6 states have call predecessors, (15), 3 states have return successors, (13), 3 states have call predecessors, (13), 4 states have call successors, (13) [2022-02-20 17:56:54,881 INFO L276 IsEmpty]: Start isEmpty. Operand 445 states and 673 transitions. [2022-02-20 17:56:54,883 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 119 [2022-02-20 17:56:54,884 INFO L506 BasicCegarLoop]: Found error trace [2022-02-20 17:56:54,884 INFO L514 BasicCegarLoop]: trace histogram [3, 3, 3, 3, 2, 2, 2, 2, 2, 2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-02-20 17:56:54,884 WARN L452 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable8 [2022-02-20 17:56:54,884 INFO L402 AbstractCegarLoop]: === Iteration 10 === Targeting outgoingErr0ASSERT_VIOLATIONERROR_FUNCTION === [outgoingErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2022-02-20 17:56:54,884 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2022-02-20 17:56:54,884 INFO L85 PathProgramCache]: Analyzing trace with hash -2130642139, now seen corresponding path program 1 times [2022-02-20 17:56:54,884 INFO L126 FreeRefinementEngine]: Executing refinement strategy CAMEL [2022-02-20 17:56:54,885 INFO L338 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [1028010484] [2022-02-20 17:56:54,885 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-02-20 17:56:54,885 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2022-02-20 17:56:54,922 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-02-20 17:56:54,952 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 6 [2022-02-20 17:56:54,953 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-02-20 17:56:54,957 INFO L290 TraceCheckUtils]: 0: Hoare triple {29114#(and (= |old(~__ste_client_idCounter0~0)| ~__ste_client_idCounter0~0) (= |old(~__ste_client_idCounter1~0)| ~__ste_client_idCounter1~0) (= |old(~__ste_client_idCounter2~0)| ~__ste_client_idCounter2~0))} ~handle := #in~handle;~value := #in~value; {29050#true} is VALID [2022-02-20 17:56:54,957 INFO L290 TraceCheckUtils]: 1: Hoare triple {29050#true} assume 1 == ~handle;~__ste_client_idCounter0~0 := ~value; {29050#true} is VALID [2022-02-20 17:56:54,957 INFO L290 TraceCheckUtils]: 2: Hoare triple {29050#true} assume true; {29050#true} is VALID [2022-02-20 17:56:54,957 INFO L284 TraceCheckUtils]: 3: Hoare quadruple {29050#true} {29050#true} #1133#return; {29050#true} is VALID [2022-02-20 17:56:54,963 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 12 [2022-02-20 17:56:54,964 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-02-20 17:56:54,966 INFO L290 TraceCheckUtils]: 0: Hoare triple {29115#(and (= ~__ste_client_privateKey0~0 |old(~__ste_client_privateKey0~0)|) (= ~__ste_client_privateKey2~0 |old(~__ste_client_privateKey2~0)|) (= ~__ste_client_privateKey1~0 |old(~__ste_client_privateKey1~0)|))} ~handle := #in~handle;~value := #in~value; {29050#true} is VALID [2022-02-20 17:56:54,966 INFO L290 TraceCheckUtils]: 1: Hoare triple {29050#true} assume 1 == ~handle;~__ste_client_privateKey0~0 := ~value; {29050#true} is VALID [2022-02-20 17:56:54,966 INFO L290 TraceCheckUtils]: 2: Hoare triple {29050#true} assume true; {29050#true} is VALID [2022-02-20 17:56:54,966 INFO L284 TraceCheckUtils]: 3: Hoare quadruple {29050#true} {29050#true} #1135#return; {29050#true} is VALID [2022-02-20 17:56:54,967 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 18 [2022-02-20 17:56:54,969 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-02-20 17:56:54,982 INFO L290 TraceCheckUtils]: 0: Hoare triple {29114#(and (= |old(~__ste_client_idCounter0~0)| ~__ste_client_idCounter0~0) (= |old(~__ste_client_idCounter1~0)| ~__ste_client_idCounter1~0) (= |old(~__ste_client_idCounter2~0)| ~__ste_client_idCounter2~0))} ~handle := #in~handle;~value := #in~value; {29116#(= setClientId_~handle |setClientId_#in~handle|)} is VALID [2022-02-20 17:56:54,982 INFO L290 TraceCheckUtils]: 1: Hoare triple {29116#(= setClientId_~handle |setClientId_#in~handle|)} assume !(1 == ~handle); {29116#(= setClientId_~handle |setClientId_#in~handle|)} is VALID [2022-02-20 17:56:54,983 INFO L290 TraceCheckUtils]: 2: Hoare triple {29116#(= setClientId_~handle |setClientId_#in~handle|)} assume 2 == ~handle;~__ste_client_idCounter1~0 := ~value; {29117#(= 2 |setClientId_#in~handle|)} is VALID [2022-02-20 17:56:54,983 INFO L290 TraceCheckUtils]: 3: Hoare triple {29117#(= 2 |setClientId_#in~handle|)} assume true; {29117#(= 2 |setClientId_#in~handle|)} is VALID [2022-02-20 17:56:54,983 INFO L284 TraceCheckUtils]: 4: Hoare quadruple {29117#(= 2 |setClientId_#in~handle|)} {29060#(= ~rjh~0 |ULTIMATE.start_setup_rjh__wrappee__Base_~rjh___0#1|)} #1137#return; {29066#(not (= ~rjh~0 1))} is VALID [2022-02-20 17:56:54,984 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 25 [2022-02-20 17:56:54,985 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-02-20 17:56:54,988 INFO L290 TraceCheckUtils]: 0: Hoare triple {29115#(and (= ~__ste_client_privateKey0~0 |old(~__ste_client_privateKey0~0)|) (= ~__ste_client_privateKey2~0 |old(~__ste_client_privateKey2~0)|) (= ~__ste_client_privateKey1~0 |old(~__ste_client_privateKey1~0)|))} ~handle := #in~handle;~value := #in~value; {29050#true} is VALID [2022-02-20 17:56:54,988 INFO L290 TraceCheckUtils]: 1: Hoare triple {29050#true} assume !(1 == ~handle); {29050#true} is VALID [2022-02-20 17:56:54,989 INFO L290 TraceCheckUtils]: 2: Hoare triple {29050#true} assume 2 == ~handle;~__ste_client_privateKey1~0 := ~value; {29050#true} is VALID [2022-02-20 17:56:54,989 INFO L290 TraceCheckUtils]: 3: Hoare triple {29050#true} assume true; {29050#true} is VALID [2022-02-20 17:56:54,989 INFO L284 TraceCheckUtils]: 4: Hoare quadruple {29050#true} {29066#(not (= ~rjh~0 1))} #1139#return; {29066#(not (= ~rjh~0 1))} is VALID [2022-02-20 17:56:54,989 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 32 [2022-02-20 17:56:54,991 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-02-20 17:56:54,994 INFO L290 TraceCheckUtils]: 0: Hoare triple {29114#(and (= |old(~__ste_client_idCounter0~0)| ~__ste_client_idCounter0~0) (= |old(~__ste_client_idCounter1~0)| ~__ste_client_idCounter1~0) (= |old(~__ste_client_idCounter2~0)| ~__ste_client_idCounter2~0))} ~handle := #in~handle;~value := #in~value; {29050#true} is VALID [2022-02-20 17:56:54,994 INFO L290 TraceCheckUtils]: 1: Hoare triple {29050#true} assume !(1 == ~handle); {29050#true} is VALID [2022-02-20 17:56:54,994 INFO L290 TraceCheckUtils]: 2: Hoare triple {29050#true} assume !(2 == ~handle); {29050#true} is VALID [2022-02-20 17:56:55,003 INFO L290 TraceCheckUtils]: 3: Hoare triple {29050#true} assume 3 == ~handle;~__ste_client_idCounter2~0 := ~value; {29050#true} is VALID [2022-02-20 17:56:55,004 INFO L290 TraceCheckUtils]: 4: Hoare triple {29050#true} assume true; {29050#true} is VALID [2022-02-20 17:56:55,004 INFO L284 TraceCheckUtils]: 5: Hoare quadruple {29050#true} {29066#(not (= ~rjh~0 1))} #1141#return; {29066#(not (= ~rjh~0 1))} is VALID [2022-02-20 17:56:55,005 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 40 [2022-02-20 17:56:55,006 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-02-20 17:56:55,008 INFO L290 TraceCheckUtils]: 0: Hoare triple {29115#(and (= ~__ste_client_privateKey0~0 |old(~__ste_client_privateKey0~0)|) (= ~__ste_client_privateKey2~0 |old(~__ste_client_privateKey2~0)|) (= ~__ste_client_privateKey1~0 |old(~__ste_client_privateKey1~0)|))} ~handle := #in~handle;~value := #in~value; {29050#true} is VALID [2022-02-20 17:56:55,008 INFO L290 TraceCheckUtils]: 1: Hoare triple {29050#true} assume !(1 == ~handle); {29050#true} is VALID [2022-02-20 17:56:55,009 INFO L290 TraceCheckUtils]: 2: Hoare triple {29050#true} assume !(2 == ~handle); {29050#true} is VALID [2022-02-20 17:56:55,009 INFO L290 TraceCheckUtils]: 3: Hoare triple {29050#true} assume 3 == ~handle;~__ste_client_privateKey2~0 := ~value; {29050#true} is VALID [2022-02-20 17:56:55,009 INFO L290 TraceCheckUtils]: 4: Hoare triple {29050#true} assume true; {29050#true} is VALID [2022-02-20 17:56:55,009 INFO L284 TraceCheckUtils]: 5: Hoare quadruple {29050#true} {29066#(not (= ~rjh~0 1))} #1143#return; {29066#(not (= ~rjh~0 1))} is VALID [2022-02-20 17:56:55,016 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 64 [2022-02-20 17:56:55,016 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-02-20 17:56:55,018 INFO L290 TraceCheckUtils]: 0: Hoare triple {29118#(and (= |old(~__ste_email_from0~0)| ~__ste_email_from0~0) (= |old(~__ste_email_from1~0)| ~__ste_email_from1~0))} ~handle := #in~handle;~value := #in~value; {29050#true} is VALID [2022-02-20 17:56:55,018 INFO L290 TraceCheckUtils]: 1: Hoare triple {29050#true} assume 1 == ~handle;~__ste_email_from0~0 := ~value; {29050#true} is VALID [2022-02-20 17:56:55,018 INFO L290 TraceCheckUtils]: 2: Hoare triple {29050#true} assume true; {29050#true} is VALID [2022-02-20 17:56:55,018 INFO L284 TraceCheckUtils]: 3: Hoare quadruple {29050#true} {29051#false} #1119#return; {29051#false} is VALID [2022-02-20 17:56:55,025 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 69 [2022-02-20 17:56:55,026 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-02-20 17:56:55,028 INFO L290 TraceCheckUtils]: 0: Hoare triple {29119#(and (= ~__ste_email_to0~0 |old(~__ste_email_to0~0)|) (= ~__ste_email_to1~0 |old(~__ste_email_to1~0)|))} ~handle := #in~handle;~value := #in~value; {29050#true} is VALID [2022-02-20 17:56:55,028 INFO L290 TraceCheckUtils]: 1: Hoare triple {29050#true} assume 1 == ~handle;~__ste_email_to0~0 := ~value; {29050#true} is VALID [2022-02-20 17:56:55,028 INFO L290 TraceCheckUtils]: 2: Hoare triple {29050#true} assume true; {29050#true} is VALID [2022-02-20 17:56:55,028 INFO L284 TraceCheckUtils]: 3: Hoare quadruple {29050#true} {29051#false} #1121#return; {29051#false} is VALID [2022-02-20 17:56:55,028 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 78 [2022-02-20 17:56:55,029 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-02-20 17:56:55,030 INFO L290 TraceCheckUtils]: 0: Hoare triple {29050#true} ~handle := #in~handle;havoc ~retValue_acc~24; {29050#true} is VALID [2022-02-20 17:56:55,030 INFO L290 TraceCheckUtils]: 1: Hoare triple {29050#true} assume 1 == ~handle;~retValue_acc~24 := ~__ste_client_privateKey0~0;#res := ~retValue_acc~24; {29050#true} is VALID [2022-02-20 17:56:55,030 INFO L290 TraceCheckUtils]: 2: Hoare triple {29050#true} assume true; {29050#true} is VALID [2022-02-20 17:56:55,030 INFO L284 TraceCheckUtils]: 3: Hoare quadruple {29050#true} {29051#false} #1053#return; {29051#false} is VALID [2022-02-20 17:56:55,031 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 86 [2022-02-20 17:56:55,031 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-02-20 17:56:55,033 INFO L290 TraceCheckUtils]: 0: Hoare triple {29050#true} ~handle := #in~handle;havoc ~retValue_acc~36; {29050#true} is VALID [2022-02-20 17:56:55,033 INFO L290 TraceCheckUtils]: 1: Hoare triple {29050#true} assume 1 == ~handle;~retValue_acc~36 := ~__ste_email_to0~0;#res := ~retValue_acc~36; {29050#true} is VALID [2022-02-20 17:56:55,033 INFO L290 TraceCheckUtils]: 2: Hoare triple {29050#true} assume true; {29050#true} is VALID [2022-02-20 17:56:55,033 INFO L284 TraceCheckUtils]: 3: Hoare quadruple {29050#true} {29051#false} #1055#return; {29051#false} is VALID [2022-02-20 17:56:55,033 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 92 [2022-02-20 17:56:55,034 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-02-20 17:56:55,036 INFO L290 TraceCheckUtils]: 0: Hoare triple {29050#true} ~handle := #in~handle;~userid := #in~userid;havoc ~retValue_acc~29; {29050#true} is VALID [2022-02-20 17:56:55,037 INFO L290 TraceCheckUtils]: 1: Hoare triple {29050#true} assume 1 == ~handle; {29050#true} is VALID [2022-02-20 17:56:55,037 INFO L290 TraceCheckUtils]: 2: Hoare triple {29050#true} assume ~userid == ~__ste_Client_Keyring0_User0~0;~retValue_acc~29 := ~__ste_Client_Keyring0_PublicKey0~0;#res := ~retValue_acc~29; {29050#true} is VALID [2022-02-20 17:56:55,037 INFO L290 TraceCheckUtils]: 3: Hoare triple {29050#true} assume true; {29050#true} is VALID [2022-02-20 17:56:55,037 INFO L284 TraceCheckUtils]: 4: Hoare quadruple {29050#true} {29051#false} #1057#return; {29051#false} is VALID [2022-02-20 17:56:55,037 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 103 [2022-02-20 17:56:55,038 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-02-20 17:56:55,039 INFO L290 TraceCheckUtils]: 0: Hoare triple {29118#(and (= |old(~__ste_email_from0~0)| ~__ste_email_from0~0) (= |old(~__ste_email_from1~0)| ~__ste_email_from1~0))} ~handle := #in~handle;~value := #in~value; {29050#true} is VALID [2022-02-20 17:56:55,039 INFO L290 TraceCheckUtils]: 1: Hoare triple {29050#true} assume 1 == ~handle;~__ste_email_from0~0 := ~value; {29050#true} is VALID [2022-02-20 17:56:55,039 INFO L290 TraceCheckUtils]: 2: Hoare triple {29050#true} assume true; {29050#true} is VALID [2022-02-20 17:56:55,040 INFO L284 TraceCheckUtils]: 3: Hoare quadruple {29050#true} {29051#false} #1063#return; {29051#false} is VALID [2022-02-20 17:56:55,040 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 110 [2022-02-20 17:56:55,040 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-02-20 17:56:55,042 INFO L290 TraceCheckUtils]: 0: Hoare triple {29050#true} ~handle := #in~handle;havoc ~retValue_acc~39; {29050#true} is VALID [2022-02-20 17:56:55,042 INFO L290 TraceCheckUtils]: 1: Hoare triple {29050#true} assume 1 == ~handle;~retValue_acc~39 := ~__ste_email_isEncrypted0~0;#res := ~retValue_acc~39; {29050#true} is VALID [2022-02-20 17:56:55,042 INFO L290 TraceCheckUtils]: 2: Hoare triple {29050#true} assume true; {29050#true} is VALID [2022-02-20 17:56:55,042 INFO L284 TraceCheckUtils]: 3: Hoare quadruple {29050#true} {29051#false} #1067#return; {29051#false} is VALID [2022-02-20 17:56:55,042 INFO L290 TraceCheckUtils]: 0: Hoare triple {29050#true} assume { :begin_inline_ULTIMATE.init } true;#NULL.base, #NULL.offset := 0, 0;assume 0 == #valid[0];assume 0 < #StackHeapBarrier;call #Ultimate.allocInit(2, 1);call write~init~int(48, 1, 0, 1);call write~init~int(0, 1, 1, 1);call #Ultimate.allocInit(28, 2);call #Ultimate.allocInit(12, 3);call #Ultimate.allocInit(4, 4);call write~init~int(37, 4, 0, 1);call write~init~int(115, 4, 1, 1);call write~init~int(10, 4, 2, 1);call write~init~int(0, 4, 3, 1);call #Ultimate.allocInit(10, 5);call #Ultimate.allocInit(12, 6);call #Ultimate.allocInit(10, 7);call #Ultimate.allocInit(18, 8);call #Ultimate.allocInit(16, 9);call #Ultimate.allocInit(21, 10);call #Ultimate.allocInit(13, 11);call #Ultimate.allocInit(16, 12);call #Ultimate.allocInit(25, 13);call #Ultimate.allocInit(30, 14);call #Ultimate.allocInit(9, 15);call #Ultimate.allocInit(21, 16);call #Ultimate.allocInit(30, 17);call #Ultimate.allocInit(9, 18);call #Ultimate.allocInit(21, 19);call #Ultimate.allocInit(30, 20);call #Ultimate.allocInit(9, 21);call #Ultimate.allocInit(25, 22);call #Ultimate.allocInit(30, 23);call #Ultimate.allocInit(9, 24);call #Ultimate.allocInit(25, 25);call #Ultimate.allocInit(10, 26);call #Ultimate.allocInit(16, 27);call #Ultimate.allocInit(20, 28);call #Ultimate.allocInit(22, 29);call #Ultimate.allocInit(21, 30);call #Ultimate.allocInit(13, 31);call #Ultimate.allocInit(44, 32);call #Ultimate.allocInit(44, 33);call #Ultimate.allocInit(9, 34);call #Ultimate.allocInit(9, 35);call #Ultimate.allocInit(11, 36);call #Ultimate.allocInit(19, 37);call #Ultimate.allocInit(4, 38);call write~init~int(37, 38, 0, 1);call write~init~int(100, 38, 1, 1);call write~init~int(10, 38, 2, 1);call write~init~int(0, 38, 3, 1);call #Ultimate.allocInit(4, 39);call write~init~int(37, 39, 0, 1);call write~init~int(100, 39, 1, 1);call write~init~int(10, 39, 2, 1);call write~init~int(0, 39, 3, 1);~__SELECTED_FEATURE_Base~0 := 0;~__SELECTED_FEATURE_Keys~0 := 0;~__SELECTED_FEATURE_Encrypt~0 := 0;~__SELECTED_FEATURE_AutoResponder~0 := 0;~__SELECTED_FEATURE_AddressBook~0 := 0;~__SELECTED_FEATURE_Sign~0 := 0;~__SELECTED_FEATURE_Forward~0 := 0;~__SELECTED_FEATURE_Verify~0 := 0;~__SELECTED_FEATURE_Decrypt~0 := 0;~__GUIDSL_ROOT_PRODUCTION~0 := 0;~__GUIDSL_NON_TERMINAL_main~0 := 0;~head~0.base, ~head~0.offset := 0, 0;~queue_empty~0 := 1;~queued_message~0 := 0;~queued_client~0 := 0;~mail_is_sensitive~0 := -1;~__ste_Client_counter~0 := 0;~__ste_client_name0~0.base, ~__ste_client_name0~0.offset := 0, 0;~__ste_client_name1~0.base, ~__ste_client_name1~0.offset := 0, 0;~__ste_client_name2~0.base, ~__ste_client_name2~0.offset := 0, 0;~__ste_client_outbuffer0~0 := 0;~__ste_client_outbuffer1~0 := 0;~__ste_client_outbuffer2~0 := 0;~__ste_client_outbuffer3~0 := 0;~__ste_ClientAddressBook_size0~0 := 0;~__ste_ClientAddressBook_size1~0 := 0;~__ste_ClientAddressBook_size2~0 := 0;~__ste_Client_AddressBook0_Alias0~0 := 0;~__ste_Client_AddressBook0_Alias1~0 := 0;~__ste_Client_AddressBook0_Alias2~0 := 0;~__ste_Client_AddressBook1_Alias0~0 := 0;~__ste_Client_AddressBook1_Alias1~0 := 0;~__ste_Client_AddressBook1_Alias2~0 := 0;~__ste_Client_AddressBook2_Alias0~0 := 0;~__ste_Client_AddressBook2_Alias1~0 := 0;~__ste_Client_AddressBook2_Alias2~0 := 0;~__ste_Client_AddressBook0_Address0~0 := 0;~__ste_Client_AddressBook0_Address1~0 := 0;~__ste_Client_AddressBook0_Address2~0 := 0;~__ste_Client_AddressBook1_Address0~0 := 0;~__ste_Client_AddressBook1_Address1~0 := 0;~__ste_Client_AddressBook1_Address2~0 := 0;~__ste_Client_AddressBook2_Address0~0 := 0;~__ste_Client_AddressBook2_Address1~0 := 0;~__ste_Client_AddressBook2_Address2~0 := 0;~__ste_client_autoResponse0~0 := 0;~__ste_client_autoResponse1~0 := 0;~__ste_client_autoResponse2~0 := 0;~__ste_client_privateKey0~0 := 0;~__ste_client_privateKey1~0 := 0;~__ste_client_privateKey2~0 := 0;~__ste_ClientKeyring_size0~0 := 0;~__ste_ClientKeyring_size1~0 := 0;~__ste_ClientKeyring_size2~0 := 0;~__ste_Client_Keyring0_User0~0 := 0;~__ste_Client_Keyring0_User1~0 := 0;~__ste_Client_Keyring0_User2~0 := 0;~__ste_Client_Keyring1_User0~0 := 0;~__ste_Client_Keyring1_User1~0 := 0;~__ste_Client_Keyring1_User2~0 := 0;~__ste_Client_Keyring2_User0~0 := 0;~__ste_Client_Keyring2_User1~0 := 0;~__ste_Client_Keyring2_User2~0 := 0;~__ste_Client_Keyring0_PublicKey0~0 := 0;~__ste_Client_Keyring0_PublicKey1~0 := 0;~__ste_Client_Keyring0_PublicKey2~0 := 0;~__ste_Client_Keyring1_PublicKey0~0 := 0;~__ste_Client_Keyring1_PublicKey1~0 := 0;~__ste_Client_Keyring1_PublicKey2~0 := 0;~__ste_Client_Keyring2_PublicKey0~0 := 0;~__ste_Client_Keyring2_PublicKey1~0 := 0;~__ste_Client_Keyring2_PublicKey2~0 := 0;~__ste_client_forwardReceiver0~0 := 0;~__ste_client_forwardReceiver1~0 := 0;~__ste_client_forwardReceiver2~0 := 0;~__ste_client_forwardReceiver3~0 := 0;~__ste_client_idCounter0~0 := 0;~__ste_client_idCounter1~0 := 0;~__ste_client_idCounter2~0 := 0;~bob~0 := 0;~rjh~0 := 0;~chuck~0 := 0;~__ste_Email_counter~0 := 0;~__ste_email_id0~0 := 0;~__ste_email_id1~0 := 0;~__ste_email_from0~0 := 0;~__ste_email_from1~0 := 0;~__ste_email_to0~0 := 0;~__ste_email_to1~0 := 0;~__ste_email_subject0~0.base, ~__ste_email_subject0~0.offset := 0, 0;~__ste_email_subject1~0.base, ~__ste_email_subject1~0.offset := 0, 0;~__ste_email_body0~0.base, ~__ste_email_body0~0.offset := 0, 0;~__ste_email_body1~0.base, ~__ste_email_body1~0.offset := 0, 0;~__ste_email_isEncrypted0~0 := 0;~__ste_email_isEncrypted1~0 := 0;~__ste_email_encryptionKey0~0 := 0;~__ste_email_encryptionKey1~0 := 0;~__ste_email_isSigned0~0 := 0;~__ste_email_isSigned1~0 := 0;~__ste_email_signKey0~0 := 0;~__ste_email_signKey1~0 := 0;~__ste_email_isSignatureVerified0~0 := 0;~__ste_email_isSignatureVerified1~0 := 0; {29050#true} is VALID [2022-02-20 17:56:55,042 INFO L290 TraceCheckUtils]: 1: Hoare triple {29050#true} assume { :end_inline_ULTIMATE.init } true;assume { :begin_inline_main } true;havoc main_#res#1;havoc main_#t~ret98#1, main_~retValue_acc~32#1, main_~tmp~24#1;havoc main_~retValue_acc~32#1;havoc main_~tmp~24#1;assume { :begin_inline_select_helpers } true; {29050#true} is VALID [2022-02-20 17:56:55,042 INFO L290 TraceCheckUtils]: 2: Hoare triple {29050#true} assume { :end_inline_select_helpers } true;assume { :begin_inline_select_features } true; {29050#true} is VALID [2022-02-20 17:56:55,042 INFO L290 TraceCheckUtils]: 3: Hoare triple {29050#true} assume { :end_inline_select_features } true;assume { :begin_inline_valid_product } true;havoc valid_product_#res#1;havoc valid_product_~retValue_acc~9#1;havoc valid_product_~retValue_acc~9#1;valid_product_~retValue_acc~9#1 := 1;valid_product_#res#1 := valid_product_~retValue_acc~9#1; {29050#true} is VALID [2022-02-20 17:56:55,042 INFO L290 TraceCheckUtils]: 4: Hoare triple {29050#true} main_#t~ret98#1 := valid_product_#res#1;assume { :end_inline_valid_product } true;assume -2147483648 <= main_#t~ret98#1 && main_#t~ret98#1 <= 2147483647;main_~tmp~24#1 := main_#t~ret98#1;havoc main_#t~ret98#1; {29050#true} is VALID [2022-02-20 17:56:55,043 INFO L290 TraceCheckUtils]: 5: Hoare triple {29050#true} assume 0 != main_~tmp~24#1;assume { :begin_inline_setup } true;havoc setup_#t~nondet95#1, setup_#t~nondet96#1, setup_#t~nondet97#1, setup_~__cil_tmp1~0#1.base, setup_~__cil_tmp1~0#1.offset, setup_~__cil_tmp2~0#1.base, setup_~__cil_tmp2~0#1.offset, setup_~__cil_tmp3~2#1.base, setup_~__cil_tmp3~2#1.offset;havoc setup_~__cil_tmp1~0#1.base, setup_~__cil_tmp1~0#1.offset;havoc setup_~__cil_tmp2~0#1.base, setup_~__cil_tmp2~0#1.offset;havoc setup_~__cil_tmp3~2#1.base, setup_~__cil_tmp3~2#1.offset;~bob~0 := 1;assume { :begin_inline_setup_bob } true;setup_bob_#in~bob___0#1 := ~bob~0;havoc setup_bob_~bob___0#1;setup_bob_~bob___0#1 := setup_bob_#in~bob___0#1;assume { :begin_inline_setup_bob__wrappee__Base } true;setup_bob__wrappee__Base_#in~bob___0#1 := setup_bob_~bob___0#1;havoc setup_bob__wrappee__Base_~bob___0#1;setup_bob__wrappee__Base_~bob___0#1 := setup_bob__wrappee__Base_#in~bob___0#1; {29050#true} is VALID [2022-02-20 17:56:55,043 INFO L272 TraceCheckUtils]: 6: Hoare triple {29050#true} call setClientId(setup_bob__wrappee__Base_~bob___0#1, setup_bob__wrappee__Base_~bob___0#1); {29114#(and (= |old(~__ste_client_idCounter0~0)| ~__ste_client_idCounter0~0) (= |old(~__ste_client_idCounter1~0)| ~__ste_client_idCounter1~0) (= |old(~__ste_client_idCounter2~0)| ~__ste_client_idCounter2~0))} is VALID [2022-02-20 17:56:55,043 INFO L290 TraceCheckUtils]: 7: Hoare triple {29114#(and (= |old(~__ste_client_idCounter0~0)| ~__ste_client_idCounter0~0) (= |old(~__ste_client_idCounter1~0)| ~__ste_client_idCounter1~0) (= |old(~__ste_client_idCounter2~0)| ~__ste_client_idCounter2~0))} ~handle := #in~handle;~value := #in~value; {29050#true} is VALID [2022-02-20 17:56:55,043 INFO L290 TraceCheckUtils]: 8: Hoare triple {29050#true} assume 1 == ~handle;~__ste_client_idCounter0~0 := ~value; {29050#true} is VALID [2022-02-20 17:56:55,043 INFO L290 TraceCheckUtils]: 9: Hoare triple {29050#true} assume true; {29050#true} is VALID [2022-02-20 17:56:55,044 INFO L284 TraceCheckUtils]: 10: Hoare quadruple {29050#true} {29050#true} #1133#return; {29050#true} is VALID [2022-02-20 17:56:55,044 INFO L290 TraceCheckUtils]: 11: Hoare triple {29050#true} assume { :end_inline_setup_bob__wrappee__Base } true; {29050#true} is VALID [2022-02-20 17:56:55,044 INFO L272 TraceCheckUtils]: 12: Hoare triple {29050#true} call setClientPrivateKey(setup_bob_~bob___0#1, 123); {29115#(and (= ~__ste_client_privateKey0~0 |old(~__ste_client_privateKey0~0)|) (= ~__ste_client_privateKey2~0 |old(~__ste_client_privateKey2~0)|) (= ~__ste_client_privateKey1~0 |old(~__ste_client_privateKey1~0)|))} is VALID [2022-02-20 17:56:55,044 INFO L290 TraceCheckUtils]: 13: Hoare triple {29115#(and (= ~__ste_client_privateKey0~0 |old(~__ste_client_privateKey0~0)|) (= ~__ste_client_privateKey2~0 |old(~__ste_client_privateKey2~0)|) (= ~__ste_client_privateKey1~0 |old(~__ste_client_privateKey1~0)|))} ~handle := #in~handle;~value := #in~value; {29050#true} is VALID [2022-02-20 17:56:55,044 INFO L290 TraceCheckUtils]: 14: Hoare triple {29050#true} assume 1 == ~handle;~__ste_client_privateKey0~0 := ~value; {29050#true} is VALID [2022-02-20 17:56:55,044 INFO L290 TraceCheckUtils]: 15: Hoare triple {29050#true} assume true; {29050#true} is VALID [2022-02-20 17:56:55,045 INFO L284 TraceCheckUtils]: 16: Hoare quadruple {29050#true} {29050#true} #1135#return; {29050#true} is VALID [2022-02-20 17:56:55,045 INFO L290 TraceCheckUtils]: 17: Hoare triple {29050#true} assume { :end_inline_setup_bob } true;setup_~__cil_tmp1~0#1.base, setup_~__cil_tmp1~0#1.offset := 34, 0;havoc setup_#t~nondet95#1;~rjh~0 := 2;assume { :begin_inline_setup_rjh } true;setup_rjh_#in~rjh___0#1 := ~rjh~0;havoc setup_rjh_~rjh___0#1;setup_rjh_~rjh___0#1 := setup_rjh_#in~rjh___0#1;assume { :begin_inline_setup_rjh__wrappee__Base } true;setup_rjh__wrappee__Base_#in~rjh___0#1 := setup_rjh_~rjh___0#1;havoc setup_rjh__wrappee__Base_~rjh___0#1;setup_rjh__wrappee__Base_~rjh___0#1 := setup_rjh__wrappee__Base_#in~rjh___0#1; {29060#(= ~rjh~0 |ULTIMATE.start_setup_rjh__wrappee__Base_~rjh___0#1|)} is VALID [2022-02-20 17:56:55,046 INFO L272 TraceCheckUtils]: 18: Hoare triple {29060#(= ~rjh~0 |ULTIMATE.start_setup_rjh__wrappee__Base_~rjh___0#1|)} call setClientId(setup_rjh__wrappee__Base_~rjh___0#1, setup_rjh__wrappee__Base_~rjh___0#1); {29114#(and (= |old(~__ste_client_idCounter0~0)| ~__ste_client_idCounter0~0) (= |old(~__ste_client_idCounter1~0)| ~__ste_client_idCounter1~0) (= |old(~__ste_client_idCounter2~0)| ~__ste_client_idCounter2~0))} is VALID [2022-02-20 17:56:55,046 INFO L290 TraceCheckUtils]: 19: Hoare triple {29114#(and (= |old(~__ste_client_idCounter0~0)| ~__ste_client_idCounter0~0) (= |old(~__ste_client_idCounter1~0)| ~__ste_client_idCounter1~0) (= |old(~__ste_client_idCounter2~0)| ~__ste_client_idCounter2~0))} ~handle := #in~handle;~value := #in~value; {29116#(= setClientId_~handle |setClientId_#in~handle|)} is VALID [2022-02-20 17:56:55,046 INFO L290 TraceCheckUtils]: 20: Hoare triple {29116#(= setClientId_~handle |setClientId_#in~handle|)} assume !(1 == ~handle); {29116#(= setClientId_~handle |setClientId_#in~handle|)} is VALID [2022-02-20 17:56:55,046 INFO L290 TraceCheckUtils]: 21: Hoare triple {29116#(= setClientId_~handle |setClientId_#in~handle|)} assume 2 == ~handle;~__ste_client_idCounter1~0 := ~value; {29117#(= 2 |setClientId_#in~handle|)} is VALID [2022-02-20 17:56:55,047 INFO L290 TraceCheckUtils]: 22: Hoare triple {29117#(= 2 |setClientId_#in~handle|)} assume true; {29117#(= 2 |setClientId_#in~handle|)} is VALID [2022-02-20 17:56:55,047 INFO L284 TraceCheckUtils]: 23: Hoare quadruple {29117#(= 2 |setClientId_#in~handle|)} {29060#(= ~rjh~0 |ULTIMATE.start_setup_rjh__wrappee__Base_~rjh___0#1|)} #1137#return; {29066#(not (= ~rjh~0 1))} is VALID [2022-02-20 17:56:55,047 INFO L290 TraceCheckUtils]: 24: Hoare triple {29066#(not (= ~rjh~0 1))} assume { :end_inline_setup_rjh__wrappee__Base } true; {29066#(not (= ~rjh~0 1))} is VALID [2022-02-20 17:56:55,048 INFO L272 TraceCheckUtils]: 25: Hoare triple {29066#(not (= ~rjh~0 1))} call setClientPrivateKey(setup_rjh_~rjh___0#1, 456); {29115#(and (= ~__ste_client_privateKey0~0 |old(~__ste_client_privateKey0~0)|) (= ~__ste_client_privateKey2~0 |old(~__ste_client_privateKey2~0)|) (= ~__ste_client_privateKey1~0 |old(~__ste_client_privateKey1~0)|))} is VALID [2022-02-20 17:56:55,048 INFO L290 TraceCheckUtils]: 26: Hoare triple {29115#(and (= ~__ste_client_privateKey0~0 |old(~__ste_client_privateKey0~0)|) (= ~__ste_client_privateKey2~0 |old(~__ste_client_privateKey2~0)|) (= ~__ste_client_privateKey1~0 |old(~__ste_client_privateKey1~0)|))} ~handle := #in~handle;~value := #in~value; {29050#true} is VALID [2022-02-20 17:56:55,048 INFO L290 TraceCheckUtils]: 27: Hoare triple {29050#true} assume !(1 == ~handle); {29050#true} is VALID [2022-02-20 17:56:55,048 INFO L290 TraceCheckUtils]: 28: Hoare triple {29050#true} assume 2 == ~handle;~__ste_client_privateKey1~0 := ~value; {29050#true} is VALID [2022-02-20 17:56:55,048 INFO L290 TraceCheckUtils]: 29: Hoare triple {29050#true} assume true; {29050#true} is VALID [2022-02-20 17:56:55,049 INFO L284 TraceCheckUtils]: 30: Hoare quadruple {29050#true} {29066#(not (= ~rjh~0 1))} #1139#return; {29066#(not (= ~rjh~0 1))} is VALID [2022-02-20 17:56:55,049 INFO L290 TraceCheckUtils]: 31: Hoare triple {29066#(not (= ~rjh~0 1))} assume { :end_inline_setup_rjh } true;setup_~__cil_tmp2~0#1.base, setup_~__cil_tmp2~0#1.offset := 35, 0;havoc setup_#t~nondet96#1;~chuck~0 := 3;assume { :begin_inline_setup_chuck } true;setup_chuck_#in~chuck___0#1 := ~chuck~0;havoc setup_chuck_~chuck___0#1;setup_chuck_~chuck___0#1 := setup_chuck_#in~chuck___0#1;assume { :begin_inline_setup_chuck__wrappee__Base } true;setup_chuck__wrappee__Base_#in~chuck___0#1 := setup_chuck_~chuck___0#1;havoc setup_chuck__wrappee__Base_~chuck___0#1;setup_chuck__wrappee__Base_~chuck___0#1 := setup_chuck__wrappee__Base_#in~chuck___0#1; {29066#(not (= ~rjh~0 1))} is VALID [2022-02-20 17:56:55,050 INFO L272 TraceCheckUtils]: 32: Hoare triple {29066#(not (= ~rjh~0 1))} call setClientId(setup_chuck__wrappee__Base_~chuck___0#1, setup_chuck__wrappee__Base_~chuck___0#1); {29114#(and (= |old(~__ste_client_idCounter0~0)| ~__ste_client_idCounter0~0) (= |old(~__ste_client_idCounter1~0)| ~__ste_client_idCounter1~0) (= |old(~__ste_client_idCounter2~0)| ~__ste_client_idCounter2~0))} is VALID [2022-02-20 17:56:55,050 INFO L290 TraceCheckUtils]: 33: Hoare triple {29114#(and (= |old(~__ste_client_idCounter0~0)| ~__ste_client_idCounter0~0) (= |old(~__ste_client_idCounter1~0)| ~__ste_client_idCounter1~0) (= |old(~__ste_client_idCounter2~0)| ~__ste_client_idCounter2~0))} ~handle := #in~handle;~value := #in~value; {29050#true} is VALID [2022-02-20 17:56:55,050 INFO L290 TraceCheckUtils]: 34: Hoare triple {29050#true} assume !(1 == ~handle); {29050#true} is VALID [2022-02-20 17:56:55,050 INFO L290 TraceCheckUtils]: 35: Hoare triple {29050#true} assume !(2 == ~handle); {29050#true} is VALID [2022-02-20 17:56:55,050 INFO L290 TraceCheckUtils]: 36: Hoare triple {29050#true} assume 3 == ~handle;~__ste_client_idCounter2~0 := ~value; {29050#true} is VALID [2022-02-20 17:56:55,050 INFO L290 TraceCheckUtils]: 37: Hoare triple {29050#true} assume true; {29050#true} is VALID [2022-02-20 17:56:55,051 INFO L284 TraceCheckUtils]: 38: Hoare quadruple {29050#true} {29066#(not (= ~rjh~0 1))} #1141#return; {29066#(not (= ~rjh~0 1))} is VALID [2022-02-20 17:56:55,051 INFO L290 TraceCheckUtils]: 39: Hoare triple {29066#(not (= ~rjh~0 1))} assume { :end_inline_setup_chuck__wrappee__Base } true; {29066#(not (= ~rjh~0 1))} is VALID [2022-02-20 17:56:55,051 INFO L272 TraceCheckUtils]: 40: Hoare triple {29066#(not (= ~rjh~0 1))} call setClientPrivateKey(setup_chuck_~chuck___0#1, 789); {29115#(and (= ~__ste_client_privateKey0~0 |old(~__ste_client_privateKey0~0)|) (= ~__ste_client_privateKey2~0 |old(~__ste_client_privateKey2~0)|) (= ~__ste_client_privateKey1~0 |old(~__ste_client_privateKey1~0)|))} is VALID [2022-02-20 17:56:55,051 INFO L290 TraceCheckUtils]: 41: Hoare triple {29115#(and (= ~__ste_client_privateKey0~0 |old(~__ste_client_privateKey0~0)|) (= ~__ste_client_privateKey2~0 |old(~__ste_client_privateKey2~0)|) (= ~__ste_client_privateKey1~0 |old(~__ste_client_privateKey1~0)|))} ~handle := #in~handle;~value := #in~value; {29050#true} is VALID [2022-02-20 17:56:55,052 INFO L290 TraceCheckUtils]: 42: Hoare triple {29050#true} assume !(1 == ~handle); {29050#true} is VALID [2022-02-20 17:56:55,052 INFO L290 TraceCheckUtils]: 43: Hoare triple {29050#true} assume !(2 == ~handle); {29050#true} is VALID [2022-02-20 17:56:55,052 INFO L290 TraceCheckUtils]: 44: Hoare triple {29050#true} assume 3 == ~handle;~__ste_client_privateKey2~0 := ~value; {29050#true} is VALID [2022-02-20 17:56:55,052 INFO L290 TraceCheckUtils]: 45: Hoare triple {29050#true} assume true; {29050#true} is VALID [2022-02-20 17:56:55,052 INFO L284 TraceCheckUtils]: 46: Hoare quadruple {29050#true} {29066#(not (= ~rjh~0 1))} #1143#return; {29066#(not (= ~rjh~0 1))} is VALID [2022-02-20 17:56:55,053 INFO L290 TraceCheckUtils]: 47: Hoare triple {29066#(not (= ~rjh~0 1))} assume { :end_inline_setup_chuck } true;setup_~__cil_tmp3~2#1.base, setup_~__cil_tmp3~2#1.offset := 36, 0;havoc setup_#t~nondet97#1; {29066#(not (= ~rjh~0 1))} is VALID [2022-02-20 17:56:55,053 INFO L290 TraceCheckUtils]: 48: Hoare triple {29066#(not (= ~rjh~0 1))} assume { :end_inline_setup } true;assume { :begin_inline_test } true;havoc test_#t~nondet48#1, test_#t~nondet49#1, test_#t~nondet50#1, test_#t~nondet51#1, test_#t~nondet52#1, test_#t~nondet53#1, test_#t~nondet54#1, test_#t~nondet55#1, test_#t~nondet56#1, test_#t~nondet57#1, test_#t~nondet58#1, test_~op1~0#1, test_~op2~0#1, test_~op3~0#1, test_~op4~0#1, test_~op5~0#1, test_~op6~0#1, test_~op7~0#1, test_~op8~0#1, test_~op9~0#1, test_~op10~0#1, test_~op11~0#1, test_~splverifierCounter~0#1, test_~tmp~8#1, test_~tmp___0~3#1, test_~tmp___1~1#1, test_~tmp___2~1#1, test_~tmp___3~0#1, test_~tmp___4~0#1, test_~tmp___5~0#1, test_~tmp___6~0#1, test_~tmp___7~0#1, test_~tmp___8~0#1, test_~tmp___9~0#1;havoc test_~op1~0#1;havoc test_~op2~0#1;havoc test_~op3~0#1;havoc test_~op4~0#1;havoc test_~op5~0#1;havoc test_~op6~0#1;havoc test_~op7~0#1;havoc test_~op8~0#1;havoc test_~op9~0#1;havoc test_~op10~0#1;havoc test_~op11~0#1;havoc test_~splverifierCounter~0#1;havoc test_~tmp~8#1;havoc test_~tmp___0~3#1;havoc test_~tmp___1~1#1;havoc test_~tmp___2~1#1;havoc test_~tmp___3~0#1;havoc test_~tmp___4~0#1;havoc test_~tmp___5~0#1;havoc test_~tmp___6~0#1;havoc test_~tmp___7~0#1;havoc test_~tmp___8~0#1;havoc test_~tmp___9~0#1;test_~op1~0#1 := 0;test_~op2~0#1 := 0;test_~op3~0#1 := 0;test_~op4~0#1 := 0;test_~op5~0#1 := 0;test_~op6~0#1 := 0;test_~op7~0#1 := 0;test_~op8~0#1 := 0;test_~op9~0#1 := 0;test_~op10~0#1 := 0;test_~op11~0#1 := 0;test_~splverifierCounter~0#1 := 0; {29066#(not (= ~rjh~0 1))} is VALID [2022-02-20 17:56:55,053 INFO L290 TraceCheckUtils]: 49: Hoare triple {29066#(not (= ~rjh~0 1))} assume !false; {29066#(not (= ~rjh~0 1))} is VALID [2022-02-20 17:56:55,053 INFO L290 TraceCheckUtils]: 50: Hoare triple {29066#(not (= ~rjh~0 1))} assume test_~splverifierCounter~0#1 < 4; {29066#(not (= ~rjh~0 1))} is VALID [2022-02-20 17:56:55,054 INFO L290 TraceCheckUtils]: 51: Hoare triple {29066#(not (= ~rjh~0 1))} test_~splverifierCounter~0#1 := 1 + test_~splverifierCounter~0#1; {29066#(not (= ~rjh~0 1))} is VALID [2022-02-20 17:56:55,054 INFO L290 TraceCheckUtils]: 52: Hoare triple {29066#(not (= ~rjh~0 1))} assume 0 == test_~op1~0#1;assume -2147483648 <= test_#t~nondet48#1 && test_#t~nondet48#1 <= 2147483647;test_~tmp___9~0#1 := test_#t~nondet48#1;havoc test_#t~nondet48#1; {29066#(not (= ~rjh~0 1))} is VALID [2022-02-20 17:56:55,054 INFO L290 TraceCheckUtils]: 53: Hoare triple {29066#(not (= ~rjh~0 1))} assume !(0 != test_~tmp___9~0#1); {29066#(not (= ~rjh~0 1))} is VALID [2022-02-20 17:56:55,054 INFO L290 TraceCheckUtils]: 54: Hoare triple {29066#(not (= ~rjh~0 1))} assume 0 == test_~op2~0#1;assume -2147483648 <= test_#t~nondet49#1 && test_#t~nondet49#1 <= 2147483647;test_~tmp___8~0#1 := test_#t~nondet49#1;havoc test_#t~nondet49#1; {29066#(not (= ~rjh~0 1))} is VALID [2022-02-20 17:56:55,055 INFO L290 TraceCheckUtils]: 55: Hoare triple {29066#(not (= ~rjh~0 1))} assume 0 != test_~tmp___8~0#1;assume { :begin_inline_rjhSetAutoRespond } true;assume { :begin_inline_setClientAutoResponse } true;setClientAutoResponse_#in~handle#1, setClientAutoResponse_#in~value#1 := ~rjh~0, 1;havoc setClientAutoResponse_~handle#1, setClientAutoResponse_~value#1;setClientAutoResponse_~handle#1 := setClientAutoResponse_#in~handle#1;setClientAutoResponse_~value#1 := setClientAutoResponse_#in~value#1; {29084#(not (= |ULTIMATE.start_setClientAutoResponse_~handle#1| 1))} is VALID [2022-02-20 17:56:55,055 INFO L290 TraceCheckUtils]: 56: Hoare triple {29084#(not (= |ULTIMATE.start_setClientAutoResponse_~handle#1| 1))} assume 1 == setClientAutoResponse_~handle#1;~__ste_client_autoResponse0~0 := setClientAutoResponse_~value#1; {29051#false} is VALID [2022-02-20 17:56:55,055 INFO L290 TraceCheckUtils]: 57: Hoare triple {29051#false} assume { :end_inline_setClientAutoResponse } true; {29051#false} is VALID [2022-02-20 17:56:55,055 INFO L290 TraceCheckUtils]: 58: Hoare triple {29051#false} assume { :end_inline_rjhSetAutoRespond } true;test_~op2~0#1 := 1; {29051#false} is VALID [2022-02-20 17:56:55,055 INFO L290 TraceCheckUtils]: 59: Hoare triple {29051#false} assume !false; {29051#false} is VALID [2022-02-20 17:56:55,055 INFO L290 TraceCheckUtils]: 60: Hoare triple {29051#false} assume !(test_~splverifierCounter~0#1 < 4); {29051#false} is VALID [2022-02-20 17:56:55,055 INFO L290 TraceCheckUtils]: 61: Hoare triple {29051#false} assume { :begin_inline_bobToRjh } true;havoc bobToRjh_#t~ret90#1, bobToRjh_#t~ret91#1, bobToRjh_#t~ret92#1, bobToRjh_#t~ret93#1, bobToRjh_~tmp~23#1, bobToRjh_~tmp___0~7#1, bobToRjh_~tmp___1~4#1;havoc bobToRjh_~tmp~23#1;havoc bobToRjh_~tmp___0~7#1;havoc bobToRjh_~tmp___1~4#1;call bobToRjh_#t~ret90#1 := puts(32, 0);assume -2147483648 <= bobToRjh_#t~ret90#1 && bobToRjh_#t~ret90#1 <= 2147483647;havoc bobToRjh_#t~ret90#1; {29051#false} is VALID [2022-02-20 17:56:55,056 INFO L272 TraceCheckUtils]: 62: Hoare triple {29051#false} call sendEmail(~bob~0, ~rjh~0); {29051#false} is VALID [2022-02-20 17:56:55,056 INFO L290 TraceCheckUtils]: 63: Hoare triple {29051#false} ~sender#1 := #in~sender#1;~receiver#1 := #in~receiver#1;havoc ~email~0#1;havoc ~tmp~16#1;assume { :begin_inline_createEmail } true;createEmail_#in~from#1, createEmail_#in~to#1 := 0, ~receiver#1;havoc createEmail_#res#1;havoc createEmail_~from#1, createEmail_~to#1, createEmail_~retValue_acc~4#1, createEmail_~msg~0#1;createEmail_~from#1 := createEmail_#in~from#1;createEmail_~to#1 := createEmail_#in~to#1;havoc createEmail_~retValue_acc~4#1;havoc createEmail_~msg~0#1;createEmail_~msg~0#1 := 1; {29051#false} is VALID [2022-02-20 17:56:55,056 INFO L272 TraceCheckUtils]: 64: Hoare triple {29051#false} call setEmailFrom(createEmail_~msg~0#1, createEmail_~from#1); {29118#(and (= |old(~__ste_email_from0~0)| ~__ste_email_from0~0) (= |old(~__ste_email_from1~0)| ~__ste_email_from1~0))} is VALID [2022-02-20 17:56:55,056 INFO L290 TraceCheckUtils]: 65: Hoare triple {29118#(and (= |old(~__ste_email_from0~0)| ~__ste_email_from0~0) (= |old(~__ste_email_from1~0)| ~__ste_email_from1~0))} ~handle := #in~handle;~value := #in~value; {29050#true} is VALID [2022-02-20 17:56:55,056 INFO L290 TraceCheckUtils]: 66: Hoare triple {29050#true} assume 1 == ~handle;~__ste_email_from0~0 := ~value; {29050#true} is VALID [2022-02-20 17:56:55,056 INFO L290 TraceCheckUtils]: 67: Hoare triple {29050#true} assume true; {29050#true} is VALID [2022-02-20 17:56:55,056 INFO L284 TraceCheckUtils]: 68: Hoare quadruple {29050#true} {29051#false} #1119#return; {29051#false} is VALID [2022-02-20 17:56:55,056 INFO L272 TraceCheckUtils]: 69: Hoare triple {29051#false} call setEmailTo(createEmail_~msg~0#1, createEmail_~to#1); {29119#(and (= ~__ste_email_to0~0 |old(~__ste_email_to0~0)|) (= ~__ste_email_to1~0 |old(~__ste_email_to1~0)|))} is VALID [2022-02-20 17:56:55,056 INFO L290 TraceCheckUtils]: 70: Hoare triple {29119#(and (= ~__ste_email_to0~0 |old(~__ste_email_to0~0)|) (= ~__ste_email_to1~0 |old(~__ste_email_to1~0)|))} ~handle := #in~handle;~value := #in~value; {29050#true} is VALID [2022-02-20 17:56:55,057 INFO L290 TraceCheckUtils]: 71: Hoare triple {29050#true} assume 1 == ~handle;~__ste_email_to0~0 := ~value; {29050#true} is VALID [2022-02-20 17:56:55,057 INFO L290 TraceCheckUtils]: 72: Hoare triple {29050#true} assume true; {29050#true} is VALID [2022-02-20 17:56:55,057 INFO L284 TraceCheckUtils]: 73: Hoare quadruple {29050#true} {29051#false} #1121#return; {29051#false} is VALID [2022-02-20 17:56:55,057 INFO L290 TraceCheckUtils]: 74: Hoare triple {29051#false} createEmail_~retValue_acc~4#1 := createEmail_~msg~0#1;createEmail_#res#1 := createEmail_~retValue_acc~4#1; {29051#false} is VALID [2022-02-20 17:56:55,057 INFO L290 TraceCheckUtils]: 75: Hoare triple {29051#false} #t~ret73#1 := createEmail_#res#1;assume { :end_inline_createEmail } true;assume -2147483648 <= #t~ret73#1 && #t~ret73#1 <= 2147483647;~tmp~16#1 := #t~ret73#1;havoc #t~ret73#1;~email~0#1 := ~tmp~16#1; {29051#false} is VALID [2022-02-20 17:56:55,057 INFO L272 TraceCheckUtils]: 76: Hoare triple {29051#false} call outgoing(~sender#1, ~email~0#1); {29051#false} is VALID [2022-02-20 17:56:55,057 INFO L290 TraceCheckUtils]: 77: Hoare triple {29051#false} ~client#1 := #in~client#1;~msg#1 := #in~msg#1;assume { :begin_inline_sign } true;sign_#in~client#1, sign_#in~msg#1 := ~client#1, ~msg#1;havoc sign_#t~ret77#1, sign_~client#1, sign_~msg#1, sign_~privkey~1#1, sign_~tmp~18#1;sign_~client#1 := sign_#in~client#1;sign_~msg#1 := sign_#in~msg#1;havoc sign_~privkey~1#1;havoc sign_~tmp~18#1; {29051#false} is VALID [2022-02-20 17:56:55,057 INFO L272 TraceCheckUtils]: 78: Hoare triple {29051#false} call sign_#t~ret77#1 := getClientPrivateKey(sign_~client#1); {29050#true} is VALID [2022-02-20 17:56:55,057 INFO L290 TraceCheckUtils]: 79: Hoare triple {29050#true} ~handle := #in~handle;havoc ~retValue_acc~24; {29050#true} is VALID [2022-02-20 17:56:55,057 INFO L290 TraceCheckUtils]: 80: Hoare triple {29050#true} assume 1 == ~handle;~retValue_acc~24 := ~__ste_client_privateKey0~0;#res := ~retValue_acc~24; {29050#true} is VALID [2022-02-20 17:56:55,058 INFO L290 TraceCheckUtils]: 81: Hoare triple {29050#true} assume true; {29050#true} is VALID [2022-02-20 17:56:55,058 INFO L284 TraceCheckUtils]: 82: Hoare quadruple {29050#true} {29051#false} #1053#return; {29051#false} is VALID [2022-02-20 17:56:55,058 INFO L290 TraceCheckUtils]: 83: Hoare triple {29051#false} assume -2147483648 <= sign_#t~ret77#1 && sign_#t~ret77#1 <= 2147483647;sign_~tmp~18#1 := sign_#t~ret77#1;havoc sign_#t~ret77#1;sign_~privkey~1#1 := sign_~tmp~18#1; {29051#false} is VALID [2022-02-20 17:56:55,058 INFO L290 TraceCheckUtils]: 84: Hoare triple {29051#false} assume 0 == sign_~privkey~1#1; {29051#false} is VALID [2022-02-20 17:56:55,058 INFO L290 TraceCheckUtils]: 85: Hoare triple {29051#false} assume { :end_inline_sign } true;assume { :begin_inline_outgoing__wrappee__AutoResponder } true;outgoing__wrappee__AutoResponder_#in~client#1, outgoing__wrappee__AutoResponder_#in~msg#1 := ~client#1, ~msg#1;havoc outgoing__wrappee__AutoResponder_#t~ret63#1, outgoing__wrappee__AutoResponder_#t~ret64#1, outgoing__wrappee__AutoResponder_~client#1, outgoing__wrappee__AutoResponder_~msg#1, outgoing__wrappee__AutoResponder_~receiver~0#1, outgoing__wrappee__AutoResponder_~tmp~11#1, outgoing__wrappee__AutoResponder_~pubkey~0#1, outgoing__wrappee__AutoResponder_~tmp___0~4#1;outgoing__wrappee__AutoResponder_~client#1 := outgoing__wrappee__AutoResponder_#in~client#1;outgoing__wrappee__AutoResponder_~msg#1 := outgoing__wrappee__AutoResponder_#in~msg#1;havoc outgoing__wrappee__AutoResponder_~receiver~0#1;havoc outgoing__wrappee__AutoResponder_~tmp~11#1;havoc outgoing__wrappee__AutoResponder_~pubkey~0#1;havoc outgoing__wrappee__AutoResponder_~tmp___0~4#1; {29051#false} is VALID [2022-02-20 17:56:55,058 INFO L272 TraceCheckUtils]: 86: Hoare triple {29051#false} call outgoing__wrappee__AutoResponder_#t~ret63#1 := getEmailTo(outgoing__wrappee__AutoResponder_~msg#1); {29050#true} is VALID [2022-02-20 17:56:55,058 INFO L290 TraceCheckUtils]: 87: Hoare triple {29050#true} ~handle := #in~handle;havoc ~retValue_acc~36; {29050#true} is VALID [2022-02-20 17:56:55,058 INFO L290 TraceCheckUtils]: 88: Hoare triple {29050#true} assume 1 == ~handle;~retValue_acc~36 := ~__ste_email_to0~0;#res := ~retValue_acc~36; {29050#true} is VALID [2022-02-20 17:56:55,058 INFO L290 TraceCheckUtils]: 89: Hoare triple {29050#true} assume true; {29050#true} is VALID [2022-02-20 17:56:55,058 INFO L284 TraceCheckUtils]: 90: Hoare quadruple {29050#true} {29051#false} #1055#return; {29051#false} is VALID [2022-02-20 17:56:55,058 INFO L290 TraceCheckUtils]: 91: Hoare triple {29051#false} assume -2147483648 <= outgoing__wrappee__AutoResponder_#t~ret63#1 && outgoing__wrappee__AutoResponder_#t~ret63#1 <= 2147483647;outgoing__wrappee__AutoResponder_~tmp~11#1 := outgoing__wrappee__AutoResponder_#t~ret63#1;havoc outgoing__wrappee__AutoResponder_#t~ret63#1;outgoing__wrappee__AutoResponder_~receiver~0#1 := outgoing__wrappee__AutoResponder_~tmp~11#1; {29051#false} is VALID [2022-02-20 17:56:55,059 INFO L272 TraceCheckUtils]: 92: Hoare triple {29051#false} call outgoing__wrappee__AutoResponder_#t~ret64#1 := findPublicKey(outgoing__wrappee__AutoResponder_~client#1, outgoing__wrappee__AutoResponder_~receiver~0#1); {29050#true} is VALID [2022-02-20 17:56:55,059 INFO L290 TraceCheckUtils]: 93: Hoare triple {29050#true} ~handle := #in~handle;~userid := #in~userid;havoc ~retValue_acc~29; {29050#true} is VALID [2022-02-20 17:56:55,059 INFO L290 TraceCheckUtils]: 94: Hoare triple {29050#true} assume 1 == ~handle; {29050#true} is VALID [2022-02-20 17:56:55,059 INFO L290 TraceCheckUtils]: 95: Hoare triple {29050#true} assume ~userid == ~__ste_Client_Keyring0_User0~0;~retValue_acc~29 := ~__ste_Client_Keyring0_PublicKey0~0;#res := ~retValue_acc~29; {29050#true} is VALID [2022-02-20 17:56:55,059 INFO L290 TraceCheckUtils]: 96: Hoare triple {29050#true} assume true; {29050#true} is VALID [2022-02-20 17:56:55,059 INFO L284 TraceCheckUtils]: 97: Hoare quadruple {29050#true} {29051#false} #1057#return; {29051#false} is VALID [2022-02-20 17:56:55,059 INFO L290 TraceCheckUtils]: 98: Hoare triple {29051#false} assume -2147483648 <= outgoing__wrappee__AutoResponder_#t~ret64#1 && outgoing__wrappee__AutoResponder_#t~ret64#1 <= 2147483647;outgoing__wrappee__AutoResponder_~tmp___0~4#1 := outgoing__wrappee__AutoResponder_#t~ret64#1;havoc outgoing__wrappee__AutoResponder_#t~ret64#1;outgoing__wrappee__AutoResponder_~pubkey~0#1 := outgoing__wrappee__AutoResponder_~tmp___0~4#1; {29051#false} is VALID [2022-02-20 17:56:55,059 INFO L290 TraceCheckUtils]: 99: Hoare triple {29051#false} assume !(0 != outgoing__wrappee__AutoResponder_~pubkey~0#1); {29051#false} is VALID [2022-02-20 17:56:55,059 INFO L290 TraceCheckUtils]: 100: Hoare triple {29051#false} assume { :begin_inline_outgoing__wrappee__Keys } true;outgoing__wrappee__Keys_#in~client#1, outgoing__wrappee__Keys_#in~msg#1 := outgoing__wrappee__AutoResponder_~client#1, outgoing__wrappee__AutoResponder_~msg#1;havoc outgoing__wrappee__Keys_#t~ret62#1, outgoing__wrappee__Keys_~client#1, outgoing__wrappee__Keys_~msg#1, outgoing__wrappee__Keys_~tmp~10#1;outgoing__wrappee__Keys_~client#1 := outgoing__wrappee__Keys_#in~client#1;outgoing__wrappee__Keys_~msg#1 := outgoing__wrappee__Keys_#in~msg#1;havoc outgoing__wrappee__Keys_~tmp~10#1;assume { :begin_inline_getClientId } true;getClientId_#in~handle#1 := outgoing__wrappee__Keys_~client#1;havoc getClientId_#res#1;havoc getClientId_~handle#1, getClientId_~retValue_acc~31#1;getClientId_~handle#1 := getClientId_#in~handle#1;havoc getClientId_~retValue_acc~31#1; {29051#false} is VALID [2022-02-20 17:56:55,060 INFO L290 TraceCheckUtils]: 101: Hoare triple {29051#false} assume 1 == getClientId_~handle#1;getClientId_~retValue_acc~31#1 := ~__ste_client_idCounter0~0;getClientId_#res#1 := getClientId_~retValue_acc~31#1; {29051#false} is VALID [2022-02-20 17:56:55,060 INFO L290 TraceCheckUtils]: 102: Hoare triple {29051#false} outgoing__wrappee__Keys_#t~ret62#1 := getClientId_#res#1;assume { :end_inline_getClientId } true;assume -2147483648 <= outgoing__wrappee__Keys_#t~ret62#1 && outgoing__wrappee__Keys_#t~ret62#1 <= 2147483647;outgoing__wrappee__Keys_~tmp~10#1 := outgoing__wrappee__Keys_#t~ret62#1;havoc outgoing__wrappee__Keys_#t~ret62#1; {29051#false} is VALID [2022-02-20 17:56:55,060 INFO L272 TraceCheckUtils]: 103: Hoare triple {29051#false} call setEmailFrom(outgoing__wrappee__Keys_~msg#1, outgoing__wrappee__Keys_~tmp~10#1); {29118#(and (= |old(~__ste_email_from0~0)| ~__ste_email_from0~0) (= |old(~__ste_email_from1~0)| ~__ste_email_from1~0))} is VALID [2022-02-20 17:56:55,060 INFO L290 TraceCheckUtils]: 104: Hoare triple {29118#(and (= |old(~__ste_email_from0~0)| ~__ste_email_from0~0) (= |old(~__ste_email_from1~0)| ~__ste_email_from1~0))} ~handle := #in~handle;~value := #in~value; {29050#true} is VALID [2022-02-20 17:56:55,060 INFO L290 TraceCheckUtils]: 105: Hoare triple {29050#true} assume 1 == ~handle;~__ste_email_from0~0 := ~value; {29050#true} is VALID [2022-02-20 17:56:55,060 INFO L290 TraceCheckUtils]: 106: Hoare triple {29050#true} assume true; {29050#true} is VALID [2022-02-20 17:56:55,060 INFO L284 TraceCheckUtils]: 107: Hoare quadruple {29050#true} {29051#false} #1063#return; {29051#false} is VALID [2022-02-20 17:56:55,060 INFO L290 TraceCheckUtils]: 108: Hoare triple {29051#false} assume { :begin_inline_mail } true;mail_#in~client#1, mail_#in~msg#1 := outgoing__wrappee__Keys_~client#1, outgoing__wrappee__Keys_~msg#1;havoc mail_#t~ret60#1, mail_#t~ret61#1, mail_~client#1, mail_~msg#1, mail_~__utac__ad__arg1~0#1, mail_~__utac__ad__arg2~0#1, mail_~tmp~9#1;mail_~client#1 := mail_#in~client#1;mail_~msg#1 := mail_#in~msg#1;havoc mail_~__utac__ad__arg1~0#1;havoc mail_~__utac__ad__arg2~0#1;havoc mail_~tmp~9#1;mail_~__utac__ad__arg1~0#1 := mail_~client#1;mail_~__utac__ad__arg2~0#1 := mail_~msg#1;assume { :begin_inline___utac_acc__AddressBookEncrypt_spec__1 } true;__utac_acc__AddressBookEncrypt_spec__1_#in~client#1, __utac_acc__AddressBookEncrypt_spec__1_#in~msg#1 := mail_~__utac__ad__arg1~0#1, mail_~__utac__ad__arg2~0#1;havoc __utac_acc__AddressBookEncrypt_spec__1_#t~ret85#1, __utac_acc__AddressBookEncrypt_spec__1_#t~ret86#1, __utac_acc__AddressBookEncrypt_spec__1_#t~ret87#1, __utac_acc__AddressBookEncrypt_spec__1_~client#1, __utac_acc__AddressBookEncrypt_spec__1_~msg#1, __utac_acc__AddressBookEncrypt_spec__1_~tmp~20#1;__utac_acc__AddressBookEncrypt_spec__1_~client#1 := __utac_acc__AddressBookEncrypt_spec__1_#in~client#1;__utac_acc__AddressBookEncrypt_spec__1_~msg#1 := __utac_acc__AddressBookEncrypt_spec__1_#in~msg#1;havoc __utac_acc__AddressBookEncrypt_spec__1_~tmp~20#1;call __utac_acc__AddressBookEncrypt_spec__1_#t~ret85#1 := puts(31, 0);assume -2147483648 <= __utac_acc__AddressBookEncrypt_spec__1_#t~ret85#1 && __utac_acc__AddressBookEncrypt_spec__1_#t~ret85#1 <= 2147483647;havoc __utac_acc__AddressBookEncrypt_spec__1_#t~ret85#1; {29051#false} is VALID [2022-02-20 17:56:55,060 INFO L290 TraceCheckUtils]: 109: Hoare triple {29051#false} assume !(-1 == ~mail_is_sensitive~0); {29051#false} is VALID [2022-02-20 17:56:55,060 INFO L272 TraceCheckUtils]: 110: Hoare triple {29051#false} call __utac_acc__AddressBookEncrypt_spec__1_#t~ret87#1 := isEncrypted(__utac_acc__AddressBookEncrypt_spec__1_~msg#1); {29050#true} is VALID [2022-02-20 17:56:55,061 INFO L290 TraceCheckUtils]: 111: Hoare triple {29050#true} ~handle := #in~handle;havoc ~retValue_acc~39; {29050#true} is VALID [2022-02-20 17:56:55,061 INFO L290 TraceCheckUtils]: 112: Hoare triple {29050#true} assume 1 == ~handle;~retValue_acc~39 := ~__ste_email_isEncrypted0~0;#res := ~retValue_acc~39; {29050#true} is VALID [2022-02-20 17:56:55,061 INFO L290 TraceCheckUtils]: 113: Hoare triple {29050#true} assume true; {29050#true} is VALID [2022-02-20 17:56:55,061 INFO L284 TraceCheckUtils]: 114: Hoare quadruple {29050#true} {29051#false} #1067#return; {29051#false} is VALID [2022-02-20 17:56:55,061 INFO L290 TraceCheckUtils]: 115: Hoare triple {29051#false} assume -2147483648 <= __utac_acc__AddressBookEncrypt_spec__1_#t~ret87#1 && __utac_acc__AddressBookEncrypt_spec__1_#t~ret87#1 <= 2147483647;__utac_acc__AddressBookEncrypt_spec__1_~tmp~20#1 := __utac_acc__AddressBookEncrypt_spec__1_#t~ret87#1;havoc __utac_acc__AddressBookEncrypt_spec__1_#t~ret87#1; {29051#false} is VALID [2022-02-20 17:56:55,061 INFO L290 TraceCheckUtils]: 116: Hoare triple {29051#false} assume ~mail_is_sensitive~0 != __utac_acc__AddressBookEncrypt_spec__1_~tmp~20#1;assume { :begin_inline___automaton_fail } true; {29051#false} is VALID [2022-02-20 17:56:55,061 INFO L290 TraceCheckUtils]: 117: Hoare triple {29051#false} assume !false; {29051#false} is VALID [2022-02-20 17:56:55,062 INFO L134 CoverageAnalysis]: Checked inductivity of 32 backedges. 5 proven. 4 refuted. 0 times theorem prover too weak. 23 trivial. 0 not checked. [2022-02-20 17:56:55,062 INFO L144 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2022-02-20 17:56:55,062 INFO L338 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [1028010484] [2022-02-20 17:56:55,062 INFO L165 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [1028010484] provided 0 perfect and 1 imperfect interpolant sequences [2022-02-20 17:56:55,063 INFO L338 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleZ3 [504328400] [2022-02-20 17:56:55,063 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-02-20 17:56:55,063 INFO L173 SolverBuilder]: Constructing external solver with command: z3 -smt2 -in SMTLIB2_COMPLIANT=true [2022-02-20 17:56:55,063 INFO L189 MonitoredProcess]: No working directory specified, using /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 [2022-02-20 17:56:55,064 INFO L229 MonitoredProcess]: Starting monitored process 7 with /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 -smt2 -in SMTLIB2_COMPLIANT=true (exit command is (exit), workingDir is null) [2022-02-20 17:56:55,065 INFO L327 MonitoredProcess]: [MP /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 -smt2 -in SMTLIB2_COMPLIANT=true (7)] Waiting until timeout for monitored process [2022-02-20 17:56:55,273 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-02-20 17:56:55,277 INFO L263 TraceCheckSpWp]: Trace formula consists of 1096 conjuncts, 3 conjunts are in the unsatisfiable core [2022-02-20 17:56:55,315 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-02-20 17:56:55,317 INFO L286 TraceCheckSpWp]: Computing forward predicates... [2022-02-20 17:56:55,568 INFO L290 TraceCheckUtils]: 0: Hoare triple {29050#true} assume { :begin_inline_ULTIMATE.init } true;#NULL.base, #NULL.offset := 0, 0;assume 0 == #valid[0];assume 0 < #StackHeapBarrier;call #Ultimate.allocInit(2, 1);call write~init~int(48, 1, 0, 1);call write~init~int(0, 1, 1, 1);call #Ultimate.allocInit(28, 2);call #Ultimate.allocInit(12, 3);call #Ultimate.allocInit(4, 4);call write~init~int(37, 4, 0, 1);call write~init~int(115, 4, 1, 1);call write~init~int(10, 4, 2, 1);call write~init~int(0, 4, 3, 1);call #Ultimate.allocInit(10, 5);call #Ultimate.allocInit(12, 6);call #Ultimate.allocInit(10, 7);call #Ultimate.allocInit(18, 8);call #Ultimate.allocInit(16, 9);call #Ultimate.allocInit(21, 10);call #Ultimate.allocInit(13, 11);call #Ultimate.allocInit(16, 12);call #Ultimate.allocInit(25, 13);call #Ultimate.allocInit(30, 14);call #Ultimate.allocInit(9, 15);call #Ultimate.allocInit(21, 16);call #Ultimate.allocInit(30, 17);call #Ultimate.allocInit(9, 18);call #Ultimate.allocInit(21, 19);call #Ultimate.allocInit(30, 20);call #Ultimate.allocInit(9, 21);call #Ultimate.allocInit(25, 22);call #Ultimate.allocInit(30, 23);call #Ultimate.allocInit(9, 24);call #Ultimate.allocInit(25, 25);call #Ultimate.allocInit(10, 26);call #Ultimate.allocInit(16, 27);call #Ultimate.allocInit(20, 28);call #Ultimate.allocInit(22, 29);call #Ultimate.allocInit(21, 30);call #Ultimate.allocInit(13, 31);call #Ultimate.allocInit(44, 32);call #Ultimate.allocInit(44, 33);call #Ultimate.allocInit(9, 34);call #Ultimate.allocInit(9, 35);call #Ultimate.allocInit(11, 36);call #Ultimate.allocInit(19, 37);call #Ultimate.allocInit(4, 38);call write~init~int(37, 38, 0, 1);call write~init~int(100, 38, 1, 1);call write~init~int(10, 38, 2, 1);call write~init~int(0, 38, 3, 1);call #Ultimate.allocInit(4, 39);call write~init~int(37, 39, 0, 1);call write~init~int(100, 39, 1, 1);call write~init~int(10, 39, 2, 1);call write~init~int(0, 39, 3, 1);~__SELECTED_FEATURE_Base~0 := 0;~__SELECTED_FEATURE_Keys~0 := 0;~__SELECTED_FEATURE_Encrypt~0 := 0;~__SELECTED_FEATURE_AutoResponder~0 := 0;~__SELECTED_FEATURE_AddressBook~0 := 0;~__SELECTED_FEATURE_Sign~0 := 0;~__SELECTED_FEATURE_Forward~0 := 0;~__SELECTED_FEATURE_Verify~0 := 0;~__SELECTED_FEATURE_Decrypt~0 := 0;~__GUIDSL_ROOT_PRODUCTION~0 := 0;~__GUIDSL_NON_TERMINAL_main~0 := 0;~head~0.base, ~head~0.offset := 0, 0;~queue_empty~0 := 1;~queued_message~0 := 0;~queued_client~0 := 0;~mail_is_sensitive~0 := -1;~__ste_Client_counter~0 := 0;~__ste_client_name0~0.base, ~__ste_client_name0~0.offset := 0, 0;~__ste_client_name1~0.base, ~__ste_client_name1~0.offset := 0, 0;~__ste_client_name2~0.base, ~__ste_client_name2~0.offset := 0, 0;~__ste_client_outbuffer0~0 := 0;~__ste_client_outbuffer1~0 := 0;~__ste_client_outbuffer2~0 := 0;~__ste_client_outbuffer3~0 := 0;~__ste_ClientAddressBook_size0~0 := 0;~__ste_ClientAddressBook_size1~0 := 0;~__ste_ClientAddressBook_size2~0 := 0;~__ste_Client_AddressBook0_Alias0~0 := 0;~__ste_Client_AddressBook0_Alias1~0 := 0;~__ste_Client_AddressBook0_Alias2~0 := 0;~__ste_Client_AddressBook1_Alias0~0 := 0;~__ste_Client_AddressBook1_Alias1~0 := 0;~__ste_Client_AddressBook1_Alias2~0 := 0;~__ste_Client_AddressBook2_Alias0~0 := 0;~__ste_Client_AddressBook2_Alias1~0 := 0;~__ste_Client_AddressBook2_Alias2~0 := 0;~__ste_Client_AddressBook0_Address0~0 := 0;~__ste_Client_AddressBook0_Address1~0 := 0;~__ste_Client_AddressBook0_Address2~0 := 0;~__ste_Client_AddressBook1_Address0~0 := 0;~__ste_Client_AddressBook1_Address1~0 := 0;~__ste_Client_AddressBook1_Address2~0 := 0;~__ste_Client_AddressBook2_Address0~0 := 0;~__ste_Client_AddressBook2_Address1~0 := 0;~__ste_Client_AddressBook2_Address2~0 := 0;~__ste_client_autoResponse0~0 := 0;~__ste_client_autoResponse1~0 := 0;~__ste_client_autoResponse2~0 := 0;~__ste_client_privateKey0~0 := 0;~__ste_client_privateKey1~0 := 0;~__ste_client_privateKey2~0 := 0;~__ste_ClientKeyring_size0~0 := 0;~__ste_ClientKeyring_size1~0 := 0;~__ste_ClientKeyring_size2~0 := 0;~__ste_Client_Keyring0_User0~0 := 0;~__ste_Client_Keyring0_User1~0 := 0;~__ste_Client_Keyring0_User2~0 := 0;~__ste_Client_Keyring1_User0~0 := 0;~__ste_Client_Keyring1_User1~0 := 0;~__ste_Client_Keyring1_User2~0 := 0;~__ste_Client_Keyring2_User0~0 := 0;~__ste_Client_Keyring2_User1~0 := 0;~__ste_Client_Keyring2_User2~0 := 0;~__ste_Client_Keyring0_PublicKey0~0 := 0;~__ste_Client_Keyring0_PublicKey1~0 := 0;~__ste_Client_Keyring0_PublicKey2~0 := 0;~__ste_Client_Keyring1_PublicKey0~0 := 0;~__ste_Client_Keyring1_PublicKey1~0 := 0;~__ste_Client_Keyring1_PublicKey2~0 := 0;~__ste_Client_Keyring2_PublicKey0~0 := 0;~__ste_Client_Keyring2_PublicKey1~0 := 0;~__ste_Client_Keyring2_PublicKey2~0 := 0;~__ste_client_forwardReceiver0~0 := 0;~__ste_client_forwardReceiver1~0 := 0;~__ste_client_forwardReceiver2~0 := 0;~__ste_client_forwardReceiver3~0 := 0;~__ste_client_idCounter0~0 := 0;~__ste_client_idCounter1~0 := 0;~__ste_client_idCounter2~0 := 0;~bob~0 := 0;~rjh~0 := 0;~chuck~0 := 0;~__ste_Email_counter~0 := 0;~__ste_email_id0~0 := 0;~__ste_email_id1~0 := 0;~__ste_email_from0~0 := 0;~__ste_email_from1~0 := 0;~__ste_email_to0~0 := 0;~__ste_email_to1~0 := 0;~__ste_email_subject0~0.base, ~__ste_email_subject0~0.offset := 0, 0;~__ste_email_subject1~0.base, ~__ste_email_subject1~0.offset := 0, 0;~__ste_email_body0~0.base, ~__ste_email_body0~0.offset := 0, 0;~__ste_email_body1~0.base, ~__ste_email_body1~0.offset := 0, 0;~__ste_email_isEncrypted0~0 := 0;~__ste_email_isEncrypted1~0 := 0;~__ste_email_encryptionKey0~0 := 0;~__ste_email_encryptionKey1~0 := 0;~__ste_email_isSigned0~0 := 0;~__ste_email_isSigned1~0 := 0;~__ste_email_signKey0~0 := 0;~__ste_email_signKey1~0 := 0;~__ste_email_isSignatureVerified0~0 := 0;~__ste_email_isSignatureVerified1~0 := 0; {29050#true} is VALID [2022-02-20 17:56:55,569 INFO L290 TraceCheckUtils]: 1: Hoare triple {29050#true} assume { :end_inline_ULTIMATE.init } true;assume { :begin_inline_main } true;havoc main_#res#1;havoc main_#t~ret98#1, main_~retValue_acc~32#1, main_~tmp~24#1;havoc main_~retValue_acc~32#1;havoc main_~tmp~24#1;assume { :begin_inline_select_helpers } true; {29050#true} is VALID [2022-02-20 17:56:55,569 INFO L290 TraceCheckUtils]: 2: Hoare triple {29050#true} assume { :end_inline_select_helpers } true;assume { :begin_inline_select_features } true; {29050#true} is VALID [2022-02-20 17:56:55,569 INFO L290 TraceCheckUtils]: 3: Hoare triple {29050#true} assume { :end_inline_select_features } true;assume { :begin_inline_valid_product } true;havoc valid_product_#res#1;havoc valid_product_~retValue_acc~9#1;havoc valid_product_~retValue_acc~9#1;valid_product_~retValue_acc~9#1 := 1;valid_product_#res#1 := valid_product_~retValue_acc~9#1; {29050#true} is VALID [2022-02-20 17:56:55,569 INFO L290 TraceCheckUtils]: 4: Hoare triple {29050#true} main_#t~ret98#1 := valid_product_#res#1;assume { :end_inline_valid_product } true;assume -2147483648 <= main_#t~ret98#1 && main_#t~ret98#1 <= 2147483647;main_~tmp~24#1 := main_#t~ret98#1;havoc main_#t~ret98#1; {29050#true} is VALID [2022-02-20 17:56:55,569 INFO L290 TraceCheckUtils]: 5: Hoare triple {29050#true} assume 0 != main_~tmp~24#1;assume { :begin_inline_setup } true;havoc setup_#t~nondet95#1, setup_#t~nondet96#1, setup_#t~nondet97#1, setup_~__cil_tmp1~0#1.base, setup_~__cil_tmp1~0#1.offset, setup_~__cil_tmp2~0#1.base, setup_~__cil_tmp2~0#1.offset, setup_~__cil_tmp3~2#1.base, setup_~__cil_tmp3~2#1.offset;havoc setup_~__cil_tmp1~0#1.base, setup_~__cil_tmp1~0#1.offset;havoc setup_~__cil_tmp2~0#1.base, setup_~__cil_tmp2~0#1.offset;havoc setup_~__cil_tmp3~2#1.base, setup_~__cil_tmp3~2#1.offset;~bob~0 := 1;assume { :begin_inline_setup_bob } true;setup_bob_#in~bob___0#1 := ~bob~0;havoc setup_bob_~bob___0#1;setup_bob_~bob___0#1 := setup_bob_#in~bob___0#1;assume { :begin_inline_setup_bob__wrappee__Base } true;setup_bob__wrappee__Base_#in~bob___0#1 := setup_bob_~bob___0#1;havoc setup_bob__wrappee__Base_~bob___0#1;setup_bob__wrappee__Base_~bob___0#1 := setup_bob__wrappee__Base_#in~bob___0#1; {29050#true} is VALID [2022-02-20 17:56:55,569 INFO L272 TraceCheckUtils]: 6: Hoare triple {29050#true} call setClientId(setup_bob__wrappee__Base_~bob___0#1, setup_bob__wrappee__Base_~bob___0#1); {29050#true} is VALID [2022-02-20 17:56:55,569 INFO L290 TraceCheckUtils]: 7: Hoare triple {29050#true} ~handle := #in~handle;~value := #in~value; {29050#true} is VALID [2022-02-20 17:56:55,569 INFO L290 TraceCheckUtils]: 8: Hoare triple {29050#true} assume 1 == ~handle;~__ste_client_idCounter0~0 := ~value; {29050#true} is VALID [2022-02-20 17:56:55,569 INFO L290 TraceCheckUtils]: 9: Hoare triple {29050#true} assume true; {29050#true} is VALID [2022-02-20 17:56:55,569 INFO L284 TraceCheckUtils]: 10: Hoare quadruple {29050#true} {29050#true} #1133#return; {29050#true} is VALID [2022-02-20 17:56:55,569 INFO L290 TraceCheckUtils]: 11: Hoare triple {29050#true} assume { :end_inline_setup_bob__wrappee__Base } true; {29050#true} is VALID [2022-02-20 17:56:55,569 INFO L272 TraceCheckUtils]: 12: Hoare triple {29050#true} call setClientPrivateKey(setup_bob_~bob___0#1, 123); {29050#true} is VALID [2022-02-20 17:56:55,569 INFO L290 TraceCheckUtils]: 13: Hoare triple {29050#true} ~handle := #in~handle;~value := #in~value; {29050#true} is VALID [2022-02-20 17:56:55,569 INFO L290 TraceCheckUtils]: 14: Hoare triple {29050#true} assume 1 == ~handle;~__ste_client_privateKey0~0 := ~value; {29050#true} is VALID [2022-02-20 17:56:55,569 INFO L290 TraceCheckUtils]: 15: Hoare triple {29050#true} assume true; {29050#true} is VALID [2022-02-20 17:56:55,569 INFO L284 TraceCheckUtils]: 16: Hoare quadruple {29050#true} {29050#true} #1135#return; {29050#true} is VALID [2022-02-20 17:56:55,569 INFO L290 TraceCheckUtils]: 17: Hoare triple {29050#true} assume { :end_inline_setup_bob } true;setup_~__cil_tmp1~0#1.base, setup_~__cil_tmp1~0#1.offset := 34, 0;havoc setup_#t~nondet95#1;~rjh~0 := 2;assume { :begin_inline_setup_rjh } true;setup_rjh_#in~rjh___0#1 := ~rjh~0;havoc setup_rjh_~rjh___0#1;setup_rjh_~rjh___0#1 := setup_rjh_#in~rjh___0#1;assume { :begin_inline_setup_rjh__wrappee__Base } true;setup_rjh__wrappee__Base_#in~rjh___0#1 := setup_rjh_~rjh___0#1;havoc setup_rjh__wrappee__Base_~rjh___0#1;setup_rjh__wrappee__Base_~rjh___0#1 := setup_rjh__wrappee__Base_#in~rjh___0#1; {29050#true} is VALID [2022-02-20 17:56:55,569 INFO L272 TraceCheckUtils]: 18: Hoare triple {29050#true} call setClientId(setup_rjh__wrappee__Base_~rjh___0#1, setup_rjh__wrappee__Base_~rjh___0#1); {29050#true} is VALID [2022-02-20 17:56:55,569 INFO L290 TraceCheckUtils]: 19: Hoare triple {29050#true} ~handle := #in~handle;~value := #in~value; {29050#true} is VALID [2022-02-20 17:56:55,569 INFO L290 TraceCheckUtils]: 20: Hoare triple {29050#true} assume !(1 == ~handle); {29050#true} is VALID [2022-02-20 17:56:55,570 INFO L290 TraceCheckUtils]: 21: Hoare triple {29050#true} assume 2 == ~handle;~__ste_client_idCounter1~0 := ~value; {29050#true} is VALID [2022-02-20 17:56:55,570 INFO L290 TraceCheckUtils]: 22: Hoare triple {29050#true} assume true; {29050#true} is VALID [2022-02-20 17:56:55,570 INFO L284 TraceCheckUtils]: 23: Hoare quadruple {29050#true} {29050#true} #1137#return; {29050#true} is VALID [2022-02-20 17:56:55,570 INFO L290 TraceCheckUtils]: 24: Hoare triple {29050#true} assume { :end_inline_setup_rjh__wrappee__Base } true; {29050#true} is VALID [2022-02-20 17:56:55,570 INFO L272 TraceCheckUtils]: 25: Hoare triple {29050#true} call setClientPrivateKey(setup_rjh_~rjh___0#1, 456); {29050#true} is VALID [2022-02-20 17:56:55,570 INFO L290 TraceCheckUtils]: 26: Hoare triple {29050#true} ~handle := #in~handle;~value := #in~value; {29050#true} is VALID [2022-02-20 17:56:55,570 INFO L290 TraceCheckUtils]: 27: Hoare triple {29050#true} assume !(1 == ~handle); {29050#true} is VALID [2022-02-20 17:56:55,570 INFO L290 TraceCheckUtils]: 28: Hoare triple {29050#true} assume 2 == ~handle;~__ste_client_privateKey1~0 := ~value; {29050#true} is VALID [2022-02-20 17:56:55,570 INFO L290 TraceCheckUtils]: 29: Hoare triple {29050#true} assume true; {29050#true} is VALID [2022-02-20 17:56:55,570 INFO L284 TraceCheckUtils]: 30: Hoare quadruple {29050#true} {29050#true} #1139#return; {29050#true} is VALID [2022-02-20 17:56:55,570 INFO L290 TraceCheckUtils]: 31: Hoare triple {29050#true} assume { :end_inline_setup_rjh } true;setup_~__cil_tmp2~0#1.base, setup_~__cil_tmp2~0#1.offset := 35, 0;havoc setup_#t~nondet96#1;~chuck~0 := 3;assume { :begin_inline_setup_chuck } true;setup_chuck_#in~chuck___0#1 := ~chuck~0;havoc setup_chuck_~chuck___0#1;setup_chuck_~chuck___0#1 := setup_chuck_#in~chuck___0#1;assume { :begin_inline_setup_chuck__wrappee__Base } true;setup_chuck__wrappee__Base_#in~chuck___0#1 := setup_chuck_~chuck___0#1;havoc setup_chuck__wrappee__Base_~chuck___0#1;setup_chuck__wrappee__Base_~chuck___0#1 := setup_chuck__wrappee__Base_#in~chuck___0#1; {29050#true} is VALID [2022-02-20 17:56:55,570 INFO L272 TraceCheckUtils]: 32: Hoare triple {29050#true} call setClientId(setup_chuck__wrappee__Base_~chuck___0#1, setup_chuck__wrappee__Base_~chuck___0#1); {29050#true} is VALID [2022-02-20 17:56:55,570 INFO L290 TraceCheckUtils]: 33: Hoare triple {29050#true} ~handle := #in~handle;~value := #in~value; {29050#true} is VALID [2022-02-20 17:56:55,570 INFO L290 TraceCheckUtils]: 34: Hoare triple {29050#true} assume !(1 == ~handle); {29050#true} is VALID [2022-02-20 17:56:55,570 INFO L290 TraceCheckUtils]: 35: Hoare triple {29050#true} assume !(2 == ~handle); {29050#true} is VALID [2022-02-20 17:56:55,570 INFO L290 TraceCheckUtils]: 36: Hoare triple {29050#true} assume 3 == ~handle;~__ste_client_idCounter2~0 := ~value; {29050#true} is VALID [2022-02-20 17:56:55,570 INFO L290 TraceCheckUtils]: 37: Hoare triple {29050#true} assume true; {29050#true} is VALID [2022-02-20 17:56:55,570 INFO L284 TraceCheckUtils]: 38: Hoare quadruple {29050#true} {29050#true} #1141#return; {29050#true} is VALID [2022-02-20 17:56:55,570 INFO L290 TraceCheckUtils]: 39: Hoare triple {29050#true} assume { :end_inline_setup_chuck__wrappee__Base } true; {29050#true} is VALID [2022-02-20 17:56:55,570 INFO L272 TraceCheckUtils]: 40: Hoare triple {29050#true} call setClientPrivateKey(setup_chuck_~chuck___0#1, 789); {29050#true} is VALID [2022-02-20 17:56:55,570 INFO L290 TraceCheckUtils]: 41: Hoare triple {29050#true} ~handle := #in~handle;~value := #in~value; {29050#true} is VALID [2022-02-20 17:56:55,570 INFO L290 TraceCheckUtils]: 42: Hoare triple {29050#true} assume !(1 == ~handle); {29050#true} is VALID [2022-02-20 17:56:55,570 INFO L290 TraceCheckUtils]: 43: Hoare triple {29050#true} assume !(2 == ~handle); {29050#true} is VALID [2022-02-20 17:56:55,571 INFO L290 TraceCheckUtils]: 44: Hoare triple {29050#true} assume 3 == ~handle;~__ste_client_privateKey2~0 := ~value; {29050#true} is VALID [2022-02-20 17:56:55,571 INFO L290 TraceCheckUtils]: 45: Hoare triple {29050#true} assume true; {29050#true} is VALID [2022-02-20 17:56:55,571 INFO L284 TraceCheckUtils]: 46: Hoare quadruple {29050#true} {29050#true} #1143#return; {29050#true} is VALID [2022-02-20 17:56:55,571 INFO L290 TraceCheckUtils]: 47: Hoare triple {29050#true} assume { :end_inline_setup_chuck } true;setup_~__cil_tmp3~2#1.base, setup_~__cil_tmp3~2#1.offset := 36, 0;havoc setup_#t~nondet97#1; {29050#true} is VALID [2022-02-20 17:56:55,571 INFO L290 TraceCheckUtils]: 48: Hoare triple {29050#true} assume { :end_inline_setup } true;assume { :begin_inline_test } true;havoc test_#t~nondet48#1, test_#t~nondet49#1, test_#t~nondet50#1, test_#t~nondet51#1, test_#t~nondet52#1, test_#t~nondet53#1, test_#t~nondet54#1, test_#t~nondet55#1, test_#t~nondet56#1, test_#t~nondet57#1, test_#t~nondet58#1, test_~op1~0#1, test_~op2~0#1, test_~op3~0#1, test_~op4~0#1, test_~op5~0#1, test_~op6~0#1, test_~op7~0#1, test_~op8~0#1, test_~op9~0#1, test_~op10~0#1, test_~op11~0#1, test_~splverifierCounter~0#1, test_~tmp~8#1, test_~tmp___0~3#1, test_~tmp___1~1#1, test_~tmp___2~1#1, test_~tmp___3~0#1, test_~tmp___4~0#1, test_~tmp___5~0#1, test_~tmp___6~0#1, test_~tmp___7~0#1, test_~tmp___8~0#1, test_~tmp___9~0#1;havoc test_~op1~0#1;havoc test_~op2~0#1;havoc test_~op3~0#1;havoc test_~op4~0#1;havoc test_~op5~0#1;havoc test_~op6~0#1;havoc test_~op7~0#1;havoc test_~op8~0#1;havoc test_~op9~0#1;havoc test_~op10~0#1;havoc test_~op11~0#1;havoc test_~splverifierCounter~0#1;havoc test_~tmp~8#1;havoc test_~tmp___0~3#1;havoc test_~tmp___1~1#1;havoc test_~tmp___2~1#1;havoc test_~tmp___3~0#1;havoc test_~tmp___4~0#1;havoc test_~tmp___5~0#1;havoc test_~tmp___6~0#1;havoc test_~tmp___7~0#1;havoc test_~tmp___8~0#1;havoc test_~tmp___9~0#1;test_~op1~0#1 := 0;test_~op2~0#1 := 0;test_~op3~0#1 := 0;test_~op4~0#1 := 0;test_~op5~0#1 := 0;test_~op6~0#1 := 0;test_~op7~0#1 := 0;test_~op8~0#1 := 0;test_~op9~0#1 := 0;test_~op10~0#1 := 0;test_~op11~0#1 := 0;test_~splverifierCounter~0#1 := 0; {29267#(<= |ULTIMATE.start_test_~splverifierCounter~0#1| 0)} is VALID [2022-02-20 17:56:55,571 INFO L290 TraceCheckUtils]: 49: Hoare triple {29267#(<= |ULTIMATE.start_test_~splverifierCounter~0#1| 0)} assume !false; {29267#(<= |ULTIMATE.start_test_~splverifierCounter~0#1| 0)} is VALID [2022-02-20 17:56:55,572 INFO L290 TraceCheckUtils]: 50: Hoare triple {29267#(<= |ULTIMATE.start_test_~splverifierCounter~0#1| 0)} assume test_~splverifierCounter~0#1 < 4; {29267#(<= |ULTIMATE.start_test_~splverifierCounter~0#1| 0)} is VALID [2022-02-20 17:56:55,572 INFO L290 TraceCheckUtils]: 51: Hoare triple {29267#(<= |ULTIMATE.start_test_~splverifierCounter~0#1| 0)} test_~splverifierCounter~0#1 := 1 + test_~splverifierCounter~0#1; {29277#(<= |ULTIMATE.start_test_~splverifierCounter~0#1| 1)} is VALID [2022-02-20 17:56:55,572 INFO L290 TraceCheckUtils]: 52: Hoare triple {29277#(<= |ULTIMATE.start_test_~splverifierCounter~0#1| 1)} assume 0 == test_~op1~0#1;assume -2147483648 <= test_#t~nondet48#1 && test_#t~nondet48#1 <= 2147483647;test_~tmp___9~0#1 := test_#t~nondet48#1;havoc test_#t~nondet48#1; {29277#(<= |ULTIMATE.start_test_~splverifierCounter~0#1| 1)} is VALID [2022-02-20 17:56:55,572 INFO L290 TraceCheckUtils]: 53: Hoare triple {29277#(<= |ULTIMATE.start_test_~splverifierCounter~0#1| 1)} assume !(0 != test_~tmp___9~0#1); {29277#(<= |ULTIMATE.start_test_~splverifierCounter~0#1| 1)} is VALID [2022-02-20 17:56:55,573 INFO L290 TraceCheckUtils]: 54: Hoare triple {29277#(<= |ULTIMATE.start_test_~splverifierCounter~0#1| 1)} assume 0 == test_~op2~0#1;assume -2147483648 <= test_#t~nondet49#1 && test_#t~nondet49#1 <= 2147483647;test_~tmp___8~0#1 := test_#t~nondet49#1;havoc test_#t~nondet49#1; {29277#(<= |ULTIMATE.start_test_~splverifierCounter~0#1| 1)} is VALID [2022-02-20 17:56:55,573 INFO L290 TraceCheckUtils]: 55: Hoare triple {29277#(<= |ULTIMATE.start_test_~splverifierCounter~0#1| 1)} assume 0 != test_~tmp___8~0#1;assume { :begin_inline_rjhSetAutoRespond } true;assume { :begin_inline_setClientAutoResponse } true;setClientAutoResponse_#in~handle#1, setClientAutoResponse_#in~value#1 := ~rjh~0, 1;havoc setClientAutoResponse_~handle#1, setClientAutoResponse_~value#1;setClientAutoResponse_~handle#1 := setClientAutoResponse_#in~handle#1;setClientAutoResponse_~value#1 := setClientAutoResponse_#in~value#1; {29277#(<= |ULTIMATE.start_test_~splverifierCounter~0#1| 1)} is VALID [2022-02-20 17:56:55,573 INFO L290 TraceCheckUtils]: 56: Hoare triple {29277#(<= |ULTIMATE.start_test_~splverifierCounter~0#1| 1)} assume 1 == setClientAutoResponse_~handle#1;~__ste_client_autoResponse0~0 := setClientAutoResponse_~value#1; {29277#(<= |ULTIMATE.start_test_~splverifierCounter~0#1| 1)} is VALID [2022-02-20 17:56:55,573 INFO L290 TraceCheckUtils]: 57: Hoare triple {29277#(<= |ULTIMATE.start_test_~splverifierCounter~0#1| 1)} assume { :end_inline_setClientAutoResponse } true; {29277#(<= |ULTIMATE.start_test_~splverifierCounter~0#1| 1)} is VALID [2022-02-20 17:56:55,574 INFO L290 TraceCheckUtils]: 58: Hoare triple {29277#(<= |ULTIMATE.start_test_~splverifierCounter~0#1| 1)} assume { :end_inline_rjhSetAutoRespond } true;test_~op2~0#1 := 1; {29277#(<= |ULTIMATE.start_test_~splverifierCounter~0#1| 1)} is VALID [2022-02-20 17:56:55,574 INFO L290 TraceCheckUtils]: 59: Hoare triple {29277#(<= |ULTIMATE.start_test_~splverifierCounter~0#1| 1)} assume !false; {29277#(<= |ULTIMATE.start_test_~splverifierCounter~0#1| 1)} is VALID [2022-02-20 17:56:55,574 INFO L290 TraceCheckUtils]: 60: Hoare triple {29277#(<= |ULTIMATE.start_test_~splverifierCounter~0#1| 1)} assume !(test_~splverifierCounter~0#1 < 4); {29051#false} is VALID [2022-02-20 17:56:55,574 INFO L290 TraceCheckUtils]: 61: Hoare triple {29051#false} assume { :begin_inline_bobToRjh } true;havoc bobToRjh_#t~ret90#1, bobToRjh_#t~ret91#1, bobToRjh_#t~ret92#1, bobToRjh_#t~ret93#1, bobToRjh_~tmp~23#1, bobToRjh_~tmp___0~7#1, bobToRjh_~tmp___1~4#1;havoc bobToRjh_~tmp~23#1;havoc bobToRjh_~tmp___0~7#1;havoc bobToRjh_~tmp___1~4#1;call bobToRjh_#t~ret90#1 := puts(32, 0);assume -2147483648 <= bobToRjh_#t~ret90#1 && bobToRjh_#t~ret90#1 <= 2147483647;havoc bobToRjh_#t~ret90#1; {29051#false} is VALID [2022-02-20 17:56:55,574 INFO L272 TraceCheckUtils]: 62: Hoare triple {29051#false} call sendEmail(~bob~0, ~rjh~0); {29051#false} is VALID [2022-02-20 17:56:55,574 INFO L290 TraceCheckUtils]: 63: Hoare triple {29051#false} ~sender#1 := #in~sender#1;~receiver#1 := #in~receiver#1;havoc ~email~0#1;havoc ~tmp~16#1;assume { :begin_inline_createEmail } true;createEmail_#in~from#1, createEmail_#in~to#1 := 0, ~receiver#1;havoc createEmail_#res#1;havoc createEmail_~from#1, createEmail_~to#1, createEmail_~retValue_acc~4#1, createEmail_~msg~0#1;createEmail_~from#1 := createEmail_#in~from#1;createEmail_~to#1 := createEmail_#in~to#1;havoc createEmail_~retValue_acc~4#1;havoc createEmail_~msg~0#1;createEmail_~msg~0#1 := 1; {29051#false} is VALID [2022-02-20 17:56:55,574 INFO L272 TraceCheckUtils]: 64: Hoare triple {29051#false} call setEmailFrom(createEmail_~msg~0#1, createEmail_~from#1); {29051#false} is VALID [2022-02-20 17:56:55,574 INFO L290 TraceCheckUtils]: 65: Hoare triple {29051#false} ~handle := #in~handle;~value := #in~value; {29051#false} is VALID [2022-02-20 17:56:55,575 INFO L290 TraceCheckUtils]: 66: Hoare triple {29051#false} assume 1 == ~handle;~__ste_email_from0~0 := ~value; {29051#false} is VALID [2022-02-20 17:56:55,575 INFO L290 TraceCheckUtils]: 67: Hoare triple {29051#false} assume true; {29051#false} is VALID [2022-02-20 17:56:55,575 INFO L284 TraceCheckUtils]: 68: Hoare quadruple {29051#false} {29051#false} #1119#return; {29051#false} is VALID [2022-02-20 17:56:55,575 INFO L272 TraceCheckUtils]: 69: Hoare triple {29051#false} call setEmailTo(createEmail_~msg~0#1, createEmail_~to#1); {29051#false} is VALID [2022-02-20 17:56:55,575 INFO L290 TraceCheckUtils]: 70: Hoare triple {29051#false} ~handle := #in~handle;~value := #in~value; {29051#false} is VALID [2022-02-20 17:56:55,575 INFO L290 TraceCheckUtils]: 71: Hoare triple {29051#false} assume 1 == ~handle;~__ste_email_to0~0 := ~value; {29051#false} is VALID [2022-02-20 17:56:55,575 INFO L290 TraceCheckUtils]: 72: Hoare triple {29051#false} assume true; {29051#false} is VALID [2022-02-20 17:56:55,575 INFO L284 TraceCheckUtils]: 73: Hoare quadruple {29051#false} {29051#false} #1121#return; {29051#false} is VALID [2022-02-20 17:56:55,575 INFO L290 TraceCheckUtils]: 74: Hoare triple {29051#false} createEmail_~retValue_acc~4#1 := createEmail_~msg~0#1;createEmail_#res#1 := createEmail_~retValue_acc~4#1; {29051#false} is VALID [2022-02-20 17:56:55,575 INFO L290 TraceCheckUtils]: 75: Hoare triple {29051#false} #t~ret73#1 := createEmail_#res#1;assume { :end_inline_createEmail } true;assume -2147483648 <= #t~ret73#1 && #t~ret73#1 <= 2147483647;~tmp~16#1 := #t~ret73#1;havoc #t~ret73#1;~email~0#1 := ~tmp~16#1; {29051#false} is VALID [2022-02-20 17:56:55,575 INFO L272 TraceCheckUtils]: 76: Hoare triple {29051#false} call outgoing(~sender#1, ~email~0#1); {29051#false} is VALID [2022-02-20 17:56:55,575 INFO L290 TraceCheckUtils]: 77: Hoare triple {29051#false} ~client#1 := #in~client#1;~msg#1 := #in~msg#1;assume { :begin_inline_sign } true;sign_#in~client#1, sign_#in~msg#1 := ~client#1, ~msg#1;havoc sign_#t~ret77#1, sign_~client#1, sign_~msg#1, sign_~privkey~1#1, sign_~tmp~18#1;sign_~client#1 := sign_#in~client#1;sign_~msg#1 := sign_#in~msg#1;havoc sign_~privkey~1#1;havoc sign_~tmp~18#1; {29051#false} is VALID [2022-02-20 17:56:55,575 INFO L272 TraceCheckUtils]: 78: Hoare triple {29051#false} call sign_#t~ret77#1 := getClientPrivateKey(sign_~client#1); {29051#false} is VALID [2022-02-20 17:56:55,575 INFO L290 TraceCheckUtils]: 79: Hoare triple {29051#false} ~handle := #in~handle;havoc ~retValue_acc~24; {29051#false} is VALID [2022-02-20 17:56:55,575 INFO L290 TraceCheckUtils]: 80: Hoare triple {29051#false} assume 1 == ~handle;~retValue_acc~24 := ~__ste_client_privateKey0~0;#res := ~retValue_acc~24; {29051#false} is VALID [2022-02-20 17:56:55,575 INFO L290 TraceCheckUtils]: 81: Hoare triple {29051#false} assume true; {29051#false} is VALID [2022-02-20 17:56:55,575 INFO L284 TraceCheckUtils]: 82: Hoare quadruple {29051#false} {29051#false} #1053#return; {29051#false} is VALID [2022-02-20 17:56:55,575 INFO L290 TraceCheckUtils]: 83: Hoare triple {29051#false} assume -2147483648 <= sign_#t~ret77#1 && sign_#t~ret77#1 <= 2147483647;sign_~tmp~18#1 := sign_#t~ret77#1;havoc sign_#t~ret77#1;sign_~privkey~1#1 := sign_~tmp~18#1; {29051#false} is VALID [2022-02-20 17:56:55,575 INFO L290 TraceCheckUtils]: 84: Hoare triple {29051#false} assume 0 == sign_~privkey~1#1; {29051#false} is VALID [2022-02-20 17:56:55,575 INFO L290 TraceCheckUtils]: 85: Hoare triple {29051#false} assume { :end_inline_sign } true;assume { :begin_inline_outgoing__wrappee__AutoResponder } true;outgoing__wrappee__AutoResponder_#in~client#1, outgoing__wrappee__AutoResponder_#in~msg#1 := ~client#1, ~msg#1;havoc outgoing__wrappee__AutoResponder_#t~ret63#1, outgoing__wrappee__AutoResponder_#t~ret64#1, outgoing__wrappee__AutoResponder_~client#1, outgoing__wrappee__AutoResponder_~msg#1, outgoing__wrappee__AutoResponder_~receiver~0#1, outgoing__wrappee__AutoResponder_~tmp~11#1, outgoing__wrappee__AutoResponder_~pubkey~0#1, outgoing__wrappee__AutoResponder_~tmp___0~4#1;outgoing__wrappee__AutoResponder_~client#1 := outgoing__wrappee__AutoResponder_#in~client#1;outgoing__wrappee__AutoResponder_~msg#1 := outgoing__wrappee__AutoResponder_#in~msg#1;havoc outgoing__wrappee__AutoResponder_~receiver~0#1;havoc outgoing__wrappee__AutoResponder_~tmp~11#1;havoc outgoing__wrappee__AutoResponder_~pubkey~0#1;havoc outgoing__wrappee__AutoResponder_~tmp___0~4#1; {29051#false} is VALID [2022-02-20 17:56:55,575 INFO L272 TraceCheckUtils]: 86: Hoare triple {29051#false} call outgoing__wrappee__AutoResponder_#t~ret63#1 := getEmailTo(outgoing__wrappee__AutoResponder_~msg#1); {29051#false} is VALID [2022-02-20 17:56:55,575 INFO L290 TraceCheckUtils]: 87: Hoare triple {29051#false} ~handle := #in~handle;havoc ~retValue_acc~36; {29051#false} is VALID [2022-02-20 17:56:55,575 INFO L290 TraceCheckUtils]: 88: Hoare triple {29051#false} assume 1 == ~handle;~retValue_acc~36 := ~__ste_email_to0~0;#res := ~retValue_acc~36; {29051#false} is VALID [2022-02-20 17:56:55,576 INFO L290 TraceCheckUtils]: 89: Hoare triple {29051#false} assume true; {29051#false} is VALID [2022-02-20 17:56:55,576 INFO L284 TraceCheckUtils]: 90: Hoare quadruple {29051#false} {29051#false} #1055#return; {29051#false} is VALID [2022-02-20 17:56:55,576 INFO L290 TraceCheckUtils]: 91: Hoare triple {29051#false} assume -2147483648 <= outgoing__wrappee__AutoResponder_#t~ret63#1 && outgoing__wrappee__AutoResponder_#t~ret63#1 <= 2147483647;outgoing__wrappee__AutoResponder_~tmp~11#1 := outgoing__wrappee__AutoResponder_#t~ret63#1;havoc outgoing__wrappee__AutoResponder_#t~ret63#1;outgoing__wrappee__AutoResponder_~receiver~0#1 := outgoing__wrappee__AutoResponder_~tmp~11#1; {29051#false} is VALID [2022-02-20 17:56:55,576 INFO L272 TraceCheckUtils]: 92: Hoare triple {29051#false} call outgoing__wrappee__AutoResponder_#t~ret64#1 := findPublicKey(outgoing__wrappee__AutoResponder_~client#1, outgoing__wrappee__AutoResponder_~receiver~0#1); {29051#false} is VALID [2022-02-20 17:56:55,576 INFO L290 TraceCheckUtils]: 93: Hoare triple {29051#false} ~handle := #in~handle;~userid := #in~userid;havoc ~retValue_acc~29; {29051#false} is VALID [2022-02-20 17:56:55,576 INFO L290 TraceCheckUtils]: 94: Hoare triple {29051#false} assume 1 == ~handle; {29051#false} is VALID [2022-02-20 17:56:55,576 INFO L290 TraceCheckUtils]: 95: Hoare triple {29051#false} assume ~userid == ~__ste_Client_Keyring0_User0~0;~retValue_acc~29 := ~__ste_Client_Keyring0_PublicKey0~0;#res := ~retValue_acc~29; {29051#false} is VALID [2022-02-20 17:56:55,576 INFO L290 TraceCheckUtils]: 96: Hoare triple {29051#false} assume true; {29051#false} is VALID [2022-02-20 17:56:55,576 INFO L284 TraceCheckUtils]: 97: Hoare quadruple {29051#false} {29051#false} #1057#return; {29051#false} is VALID [2022-02-20 17:56:55,576 INFO L290 TraceCheckUtils]: 98: Hoare triple {29051#false} assume -2147483648 <= outgoing__wrappee__AutoResponder_#t~ret64#1 && outgoing__wrappee__AutoResponder_#t~ret64#1 <= 2147483647;outgoing__wrappee__AutoResponder_~tmp___0~4#1 := outgoing__wrappee__AutoResponder_#t~ret64#1;havoc outgoing__wrappee__AutoResponder_#t~ret64#1;outgoing__wrappee__AutoResponder_~pubkey~0#1 := outgoing__wrappee__AutoResponder_~tmp___0~4#1; {29051#false} is VALID [2022-02-20 17:56:55,576 INFO L290 TraceCheckUtils]: 99: Hoare triple {29051#false} assume !(0 != outgoing__wrappee__AutoResponder_~pubkey~0#1); {29051#false} is VALID [2022-02-20 17:56:55,577 INFO L290 TraceCheckUtils]: 100: Hoare triple {29051#false} assume { :begin_inline_outgoing__wrappee__Keys } true;outgoing__wrappee__Keys_#in~client#1, outgoing__wrappee__Keys_#in~msg#1 := outgoing__wrappee__AutoResponder_~client#1, outgoing__wrappee__AutoResponder_~msg#1;havoc outgoing__wrappee__Keys_#t~ret62#1, outgoing__wrappee__Keys_~client#1, outgoing__wrappee__Keys_~msg#1, outgoing__wrappee__Keys_~tmp~10#1;outgoing__wrappee__Keys_~client#1 := outgoing__wrappee__Keys_#in~client#1;outgoing__wrappee__Keys_~msg#1 := outgoing__wrappee__Keys_#in~msg#1;havoc outgoing__wrappee__Keys_~tmp~10#1;assume { :begin_inline_getClientId } true;getClientId_#in~handle#1 := outgoing__wrappee__Keys_~client#1;havoc getClientId_#res#1;havoc getClientId_~handle#1, getClientId_~retValue_acc~31#1;getClientId_~handle#1 := getClientId_#in~handle#1;havoc getClientId_~retValue_acc~31#1; {29051#false} is VALID [2022-02-20 17:56:55,577 INFO L290 TraceCheckUtils]: 101: Hoare triple {29051#false} assume 1 == getClientId_~handle#1;getClientId_~retValue_acc~31#1 := ~__ste_client_idCounter0~0;getClientId_#res#1 := getClientId_~retValue_acc~31#1; {29051#false} is VALID [2022-02-20 17:56:55,577 INFO L290 TraceCheckUtils]: 102: Hoare triple {29051#false} outgoing__wrappee__Keys_#t~ret62#1 := getClientId_#res#1;assume { :end_inline_getClientId } true;assume -2147483648 <= outgoing__wrappee__Keys_#t~ret62#1 && outgoing__wrappee__Keys_#t~ret62#1 <= 2147483647;outgoing__wrappee__Keys_~tmp~10#1 := outgoing__wrappee__Keys_#t~ret62#1;havoc outgoing__wrappee__Keys_#t~ret62#1; {29051#false} is VALID [2022-02-20 17:56:55,577 INFO L272 TraceCheckUtils]: 103: Hoare triple {29051#false} call setEmailFrom(outgoing__wrappee__Keys_~msg#1, outgoing__wrappee__Keys_~tmp~10#1); {29051#false} is VALID [2022-02-20 17:56:55,577 INFO L290 TraceCheckUtils]: 104: Hoare triple {29051#false} ~handle := #in~handle;~value := #in~value; {29051#false} is VALID [2022-02-20 17:56:55,577 INFO L290 TraceCheckUtils]: 105: Hoare triple {29051#false} assume 1 == ~handle;~__ste_email_from0~0 := ~value; {29051#false} is VALID [2022-02-20 17:56:55,577 INFO L290 TraceCheckUtils]: 106: Hoare triple {29051#false} assume true; {29051#false} is VALID [2022-02-20 17:56:55,577 INFO L284 TraceCheckUtils]: 107: Hoare quadruple {29051#false} {29051#false} #1063#return; {29051#false} is VALID [2022-02-20 17:56:55,577 INFO L290 TraceCheckUtils]: 108: Hoare triple {29051#false} assume { :begin_inline_mail } true;mail_#in~client#1, mail_#in~msg#1 := outgoing__wrappee__Keys_~client#1, outgoing__wrappee__Keys_~msg#1;havoc mail_#t~ret60#1, mail_#t~ret61#1, mail_~client#1, mail_~msg#1, mail_~__utac__ad__arg1~0#1, mail_~__utac__ad__arg2~0#1, mail_~tmp~9#1;mail_~client#1 := mail_#in~client#1;mail_~msg#1 := mail_#in~msg#1;havoc mail_~__utac__ad__arg1~0#1;havoc mail_~__utac__ad__arg2~0#1;havoc mail_~tmp~9#1;mail_~__utac__ad__arg1~0#1 := mail_~client#1;mail_~__utac__ad__arg2~0#1 := mail_~msg#1;assume { :begin_inline___utac_acc__AddressBookEncrypt_spec__1 } true;__utac_acc__AddressBookEncrypt_spec__1_#in~client#1, __utac_acc__AddressBookEncrypt_spec__1_#in~msg#1 := mail_~__utac__ad__arg1~0#1, mail_~__utac__ad__arg2~0#1;havoc __utac_acc__AddressBookEncrypt_spec__1_#t~ret85#1, __utac_acc__AddressBookEncrypt_spec__1_#t~ret86#1, __utac_acc__AddressBookEncrypt_spec__1_#t~ret87#1, __utac_acc__AddressBookEncrypt_spec__1_~client#1, __utac_acc__AddressBookEncrypt_spec__1_~msg#1, __utac_acc__AddressBookEncrypt_spec__1_~tmp~20#1;__utac_acc__AddressBookEncrypt_spec__1_~client#1 := __utac_acc__AddressBookEncrypt_spec__1_#in~client#1;__utac_acc__AddressBookEncrypt_spec__1_~msg#1 := __utac_acc__AddressBookEncrypt_spec__1_#in~msg#1;havoc __utac_acc__AddressBookEncrypt_spec__1_~tmp~20#1;call __utac_acc__AddressBookEncrypt_spec__1_#t~ret85#1 := puts(31, 0);assume -2147483648 <= __utac_acc__AddressBookEncrypt_spec__1_#t~ret85#1 && __utac_acc__AddressBookEncrypt_spec__1_#t~ret85#1 <= 2147483647;havoc __utac_acc__AddressBookEncrypt_spec__1_#t~ret85#1; {29051#false} is VALID [2022-02-20 17:56:55,577 INFO L290 TraceCheckUtils]: 109: Hoare triple {29051#false} assume !(-1 == ~mail_is_sensitive~0); {29051#false} is VALID [2022-02-20 17:56:55,578 INFO L272 TraceCheckUtils]: 110: Hoare triple {29051#false} call __utac_acc__AddressBookEncrypt_spec__1_#t~ret87#1 := isEncrypted(__utac_acc__AddressBookEncrypt_spec__1_~msg#1); {29051#false} is VALID [2022-02-20 17:56:55,578 INFO L290 TraceCheckUtils]: 111: Hoare triple {29051#false} ~handle := #in~handle;havoc ~retValue_acc~39; {29051#false} is VALID [2022-02-20 17:56:55,578 INFO L290 TraceCheckUtils]: 112: Hoare triple {29051#false} assume 1 == ~handle;~retValue_acc~39 := ~__ste_email_isEncrypted0~0;#res := ~retValue_acc~39; {29051#false} is VALID [2022-02-20 17:56:55,578 INFO L290 TraceCheckUtils]: 113: Hoare triple {29051#false} assume true; {29051#false} is VALID [2022-02-20 17:56:55,578 INFO L284 TraceCheckUtils]: 114: Hoare quadruple {29051#false} {29051#false} #1067#return; {29051#false} is VALID [2022-02-20 17:56:55,578 INFO L290 TraceCheckUtils]: 115: Hoare triple {29051#false} assume -2147483648 <= __utac_acc__AddressBookEncrypt_spec__1_#t~ret87#1 && __utac_acc__AddressBookEncrypt_spec__1_#t~ret87#1 <= 2147483647;__utac_acc__AddressBookEncrypt_spec__1_~tmp~20#1 := __utac_acc__AddressBookEncrypt_spec__1_#t~ret87#1;havoc __utac_acc__AddressBookEncrypt_spec__1_#t~ret87#1; {29051#false} is VALID [2022-02-20 17:56:55,578 INFO L290 TraceCheckUtils]: 116: Hoare triple {29051#false} assume ~mail_is_sensitive~0 != __utac_acc__AddressBookEncrypt_spec__1_~tmp~20#1;assume { :begin_inline___automaton_fail } true; {29051#false} is VALID [2022-02-20 17:56:55,578 INFO L290 TraceCheckUtils]: 117: Hoare triple {29051#false} assume !false; {29051#false} is VALID [2022-02-20 17:56:55,579 INFO L134 CoverageAnalysis]: Checked inductivity of 32 backedges. 0 proven. 2 refuted. 0 times theorem prover too weak. 30 trivial. 0 not checked. [2022-02-20 17:56:55,579 INFO L328 TraceCheckSpWp]: Computing backward predicates... [2022-02-20 17:56:55,849 INFO L290 TraceCheckUtils]: 117: Hoare triple {29051#false} assume !false; {29051#false} is VALID [2022-02-20 17:56:55,849 INFO L290 TraceCheckUtils]: 116: Hoare triple {29051#false} assume ~mail_is_sensitive~0 != __utac_acc__AddressBookEncrypt_spec__1_~tmp~20#1;assume { :begin_inline___automaton_fail } true; {29051#false} is VALID [2022-02-20 17:56:55,849 INFO L290 TraceCheckUtils]: 115: Hoare triple {29051#false} assume -2147483648 <= __utac_acc__AddressBookEncrypt_spec__1_#t~ret87#1 && __utac_acc__AddressBookEncrypt_spec__1_#t~ret87#1 <= 2147483647;__utac_acc__AddressBookEncrypt_spec__1_~tmp~20#1 := __utac_acc__AddressBookEncrypt_spec__1_#t~ret87#1;havoc __utac_acc__AddressBookEncrypt_spec__1_#t~ret87#1; {29051#false} is VALID [2022-02-20 17:56:55,849 INFO L284 TraceCheckUtils]: 114: Hoare quadruple {29050#true} {29051#false} #1067#return; {29051#false} is VALID [2022-02-20 17:56:55,849 INFO L290 TraceCheckUtils]: 113: Hoare triple {29050#true} assume true; {29050#true} is VALID [2022-02-20 17:56:55,849 INFO L290 TraceCheckUtils]: 112: Hoare triple {29050#true} assume 1 == ~handle;~retValue_acc~39 := ~__ste_email_isEncrypted0~0;#res := ~retValue_acc~39; {29050#true} is VALID [2022-02-20 17:56:55,849 INFO L290 TraceCheckUtils]: 111: Hoare triple {29050#true} ~handle := #in~handle;havoc ~retValue_acc~39; {29050#true} is VALID [2022-02-20 17:56:55,849 INFO L272 TraceCheckUtils]: 110: Hoare triple {29051#false} call __utac_acc__AddressBookEncrypt_spec__1_#t~ret87#1 := isEncrypted(__utac_acc__AddressBookEncrypt_spec__1_~msg#1); {29050#true} is VALID [2022-02-20 17:56:55,849 INFO L290 TraceCheckUtils]: 109: Hoare triple {29051#false} assume !(-1 == ~mail_is_sensitive~0); {29051#false} is VALID [2022-02-20 17:56:55,849 INFO L290 TraceCheckUtils]: 108: Hoare triple {29051#false} assume { :begin_inline_mail } true;mail_#in~client#1, mail_#in~msg#1 := outgoing__wrappee__Keys_~client#1, outgoing__wrappee__Keys_~msg#1;havoc mail_#t~ret60#1, mail_#t~ret61#1, mail_~client#1, mail_~msg#1, mail_~__utac__ad__arg1~0#1, mail_~__utac__ad__arg2~0#1, mail_~tmp~9#1;mail_~client#1 := mail_#in~client#1;mail_~msg#1 := mail_#in~msg#1;havoc mail_~__utac__ad__arg1~0#1;havoc mail_~__utac__ad__arg2~0#1;havoc mail_~tmp~9#1;mail_~__utac__ad__arg1~0#1 := mail_~client#1;mail_~__utac__ad__arg2~0#1 := mail_~msg#1;assume { :begin_inline___utac_acc__AddressBookEncrypt_spec__1 } true;__utac_acc__AddressBookEncrypt_spec__1_#in~client#1, __utac_acc__AddressBookEncrypt_spec__1_#in~msg#1 := mail_~__utac__ad__arg1~0#1, mail_~__utac__ad__arg2~0#1;havoc __utac_acc__AddressBookEncrypt_spec__1_#t~ret85#1, __utac_acc__AddressBookEncrypt_spec__1_#t~ret86#1, __utac_acc__AddressBookEncrypt_spec__1_#t~ret87#1, __utac_acc__AddressBookEncrypt_spec__1_~client#1, __utac_acc__AddressBookEncrypt_spec__1_~msg#1, __utac_acc__AddressBookEncrypt_spec__1_~tmp~20#1;__utac_acc__AddressBookEncrypt_spec__1_~client#1 := __utac_acc__AddressBookEncrypt_spec__1_#in~client#1;__utac_acc__AddressBookEncrypt_spec__1_~msg#1 := __utac_acc__AddressBookEncrypt_spec__1_#in~msg#1;havoc __utac_acc__AddressBookEncrypt_spec__1_~tmp~20#1;call __utac_acc__AddressBookEncrypt_spec__1_#t~ret85#1 := puts(31, 0);assume -2147483648 <= __utac_acc__AddressBookEncrypt_spec__1_#t~ret85#1 && __utac_acc__AddressBookEncrypt_spec__1_#t~ret85#1 <= 2147483647;havoc __utac_acc__AddressBookEncrypt_spec__1_#t~ret85#1; {29051#false} is VALID [2022-02-20 17:56:55,849 INFO L284 TraceCheckUtils]: 107: Hoare quadruple {29050#true} {29051#false} #1063#return; {29051#false} is VALID [2022-02-20 17:56:55,849 INFO L290 TraceCheckUtils]: 106: Hoare triple {29050#true} assume true; {29050#true} is VALID [2022-02-20 17:56:55,849 INFO L290 TraceCheckUtils]: 105: Hoare triple {29050#true} assume 1 == ~handle;~__ste_email_from0~0 := ~value; {29050#true} is VALID [2022-02-20 17:56:55,849 INFO L290 TraceCheckUtils]: 104: Hoare triple {29050#true} ~handle := #in~handle;~value := #in~value; {29050#true} is VALID [2022-02-20 17:56:55,849 INFO L272 TraceCheckUtils]: 103: Hoare triple {29051#false} call setEmailFrom(outgoing__wrappee__Keys_~msg#1, outgoing__wrappee__Keys_~tmp~10#1); {29050#true} is VALID [2022-02-20 17:56:55,849 INFO L290 TraceCheckUtils]: 102: Hoare triple {29051#false} outgoing__wrappee__Keys_#t~ret62#1 := getClientId_#res#1;assume { :end_inline_getClientId } true;assume -2147483648 <= outgoing__wrappee__Keys_#t~ret62#1 && outgoing__wrappee__Keys_#t~ret62#1 <= 2147483647;outgoing__wrappee__Keys_~tmp~10#1 := outgoing__wrappee__Keys_#t~ret62#1;havoc outgoing__wrappee__Keys_#t~ret62#1; {29051#false} is VALID [2022-02-20 17:56:55,849 INFO L290 TraceCheckUtils]: 101: Hoare triple {29051#false} assume 1 == getClientId_~handle#1;getClientId_~retValue_acc~31#1 := ~__ste_client_idCounter0~0;getClientId_#res#1 := getClientId_~retValue_acc~31#1; {29051#false} is VALID [2022-02-20 17:56:55,850 INFO L290 TraceCheckUtils]: 100: Hoare triple {29051#false} assume { :begin_inline_outgoing__wrappee__Keys } true;outgoing__wrappee__Keys_#in~client#1, outgoing__wrappee__Keys_#in~msg#1 := outgoing__wrappee__AutoResponder_~client#1, outgoing__wrappee__AutoResponder_~msg#1;havoc outgoing__wrappee__Keys_#t~ret62#1, outgoing__wrappee__Keys_~client#1, outgoing__wrappee__Keys_~msg#1, outgoing__wrappee__Keys_~tmp~10#1;outgoing__wrappee__Keys_~client#1 := outgoing__wrappee__Keys_#in~client#1;outgoing__wrappee__Keys_~msg#1 := outgoing__wrappee__Keys_#in~msg#1;havoc outgoing__wrappee__Keys_~tmp~10#1;assume { :begin_inline_getClientId } true;getClientId_#in~handle#1 := outgoing__wrappee__Keys_~client#1;havoc getClientId_#res#1;havoc getClientId_~handle#1, getClientId_~retValue_acc~31#1;getClientId_~handle#1 := getClientId_#in~handle#1;havoc getClientId_~retValue_acc~31#1; {29051#false} is VALID [2022-02-20 17:56:55,850 INFO L290 TraceCheckUtils]: 99: Hoare triple {29051#false} assume !(0 != outgoing__wrappee__AutoResponder_~pubkey~0#1); {29051#false} is VALID [2022-02-20 17:56:55,850 INFO L290 TraceCheckUtils]: 98: Hoare triple {29051#false} assume -2147483648 <= outgoing__wrappee__AutoResponder_#t~ret64#1 && outgoing__wrappee__AutoResponder_#t~ret64#1 <= 2147483647;outgoing__wrappee__AutoResponder_~tmp___0~4#1 := outgoing__wrappee__AutoResponder_#t~ret64#1;havoc outgoing__wrappee__AutoResponder_#t~ret64#1;outgoing__wrappee__AutoResponder_~pubkey~0#1 := outgoing__wrappee__AutoResponder_~tmp___0~4#1; {29051#false} is VALID [2022-02-20 17:56:55,850 INFO L284 TraceCheckUtils]: 97: Hoare quadruple {29050#true} {29051#false} #1057#return; {29051#false} is VALID [2022-02-20 17:56:55,850 INFO L290 TraceCheckUtils]: 96: Hoare triple {29050#true} assume true; {29050#true} is VALID [2022-02-20 17:56:55,850 INFO L290 TraceCheckUtils]: 95: Hoare triple {29050#true} assume ~userid == ~__ste_Client_Keyring0_User0~0;~retValue_acc~29 := ~__ste_Client_Keyring0_PublicKey0~0;#res := ~retValue_acc~29; {29050#true} is VALID [2022-02-20 17:56:55,850 INFO L290 TraceCheckUtils]: 94: Hoare triple {29050#true} assume 1 == ~handle; {29050#true} is VALID [2022-02-20 17:56:55,850 INFO L290 TraceCheckUtils]: 93: Hoare triple {29050#true} ~handle := #in~handle;~userid := #in~userid;havoc ~retValue_acc~29; {29050#true} is VALID [2022-02-20 17:56:55,850 INFO L272 TraceCheckUtils]: 92: Hoare triple {29051#false} call outgoing__wrappee__AutoResponder_#t~ret64#1 := findPublicKey(outgoing__wrappee__AutoResponder_~client#1, outgoing__wrappee__AutoResponder_~receiver~0#1); {29050#true} is VALID [2022-02-20 17:56:55,850 INFO L290 TraceCheckUtils]: 91: Hoare triple {29051#false} assume -2147483648 <= outgoing__wrappee__AutoResponder_#t~ret63#1 && outgoing__wrappee__AutoResponder_#t~ret63#1 <= 2147483647;outgoing__wrappee__AutoResponder_~tmp~11#1 := outgoing__wrappee__AutoResponder_#t~ret63#1;havoc outgoing__wrappee__AutoResponder_#t~ret63#1;outgoing__wrappee__AutoResponder_~receiver~0#1 := outgoing__wrappee__AutoResponder_~tmp~11#1; {29051#false} is VALID [2022-02-20 17:56:55,850 INFO L284 TraceCheckUtils]: 90: Hoare quadruple {29050#true} {29051#false} #1055#return; {29051#false} is VALID [2022-02-20 17:56:55,851 INFO L290 TraceCheckUtils]: 89: Hoare triple {29050#true} assume true; {29050#true} is VALID [2022-02-20 17:56:55,851 INFO L290 TraceCheckUtils]: 88: Hoare triple {29050#true} assume 1 == ~handle;~retValue_acc~36 := ~__ste_email_to0~0;#res := ~retValue_acc~36; {29050#true} is VALID [2022-02-20 17:56:55,851 INFO L290 TraceCheckUtils]: 87: Hoare triple {29050#true} ~handle := #in~handle;havoc ~retValue_acc~36; {29050#true} is VALID [2022-02-20 17:56:55,851 INFO L272 TraceCheckUtils]: 86: Hoare triple {29051#false} call outgoing__wrappee__AutoResponder_#t~ret63#1 := getEmailTo(outgoing__wrappee__AutoResponder_~msg#1); {29050#true} is VALID [2022-02-20 17:56:55,851 INFO L290 TraceCheckUtils]: 85: Hoare triple {29051#false} assume { :end_inline_sign } true;assume { :begin_inline_outgoing__wrappee__AutoResponder } true;outgoing__wrappee__AutoResponder_#in~client#1, outgoing__wrappee__AutoResponder_#in~msg#1 := ~client#1, ~msg#1;havoc outgoing__wrappee__AutoResponder_#t~ret63#1, outgoing__wrappee__AutoResponder_#t~ret64#1, outgoing__wrappee__AutoResponder_~client#1, outgoing__wrappee__AutoResponder_~msg#1, outgoing__wrappee__AutoResponder_~receiver~0#1, outgoing__wrappee__AutoResponder_~tmp~11#1, outgoing__wrappee__AutoResponder_~pubkey~0#1, outgoing__wrappee__AutoResponder_~tmp___0~4#1;outgoing__wrappee__AutoResponder_~client#1 := outgoing__wrappee__AutoResponder_#in~client#1;outgoing__wrappee__AutoResponder_~msg#1 := outgoing__wrappee__AutoResponder_#in~msg#1;havoc outgoing__wrappee__AutoResponder_~receiver~0#1;havoc outgoing__wrappee__AutoResponder_~tmp~11#1;havoc outgoing__wrappee__AutoResponder_~pubkey~0#1;havoc outgoing__wrappee__AutoResponder_~tmp___0~4#1; {29051#false} is VALID [2022-02-20 17:56:55,851 INFO L290 TraceCheckUtils]: 84: Hoare triple {29051#false} assume 0 == sign_~privkey~1#1; {29051#false} is VALID [2022-02-20 17:56:55,851 INFO L290 TraceCheckUtils]: 83: Hoare triple {29051#false} assume -2147483648 <= sign_#t~ret77#1 && sign_#t~ret77#1 <= 2147483647;sign_~tmp~18#1 := sign_#t~ret77#1;havoc sign_#t~ret77#1;sign_~privkey~1#1 := sign_~tmp~18#1; {29051#false} is VALID [2022-02-20 17:56:55,851 INFO L284 TraceCheckUtils]: 82: Hoare quadruple {29050#true} {29051#false} #1053#return; {29051#false} is VALID [2022-02-20 17:56:55,851 INFO L290 TraceCheckUtils]: 81: Hoare triple {29050#true} assume true; {29050#true} is VALID [2022-02-20 17:56:55,851 INFO L290 TraceCheckUtils]: 80: Hoare triple {29050#true} assume 1 == ~handle;~retValue_acc~24 := ~__ste_client_privateKey0~0;#res := ~retValue_acc~24; {29050#true} is VALID [2022-02-20 17:56:55,851 INFO L290 TraceCheckUtils]: 79: Hoare triple {29050#true} ~handle := #in~handle;havoc ~retValue_acc~24; {29050#true} is VALID [2022-02-20 17:56:55,851 INFO L272 TraceCheckUtils]: 78: Hoare triple {29051#false} call sign_#t~ret77#1 := getClientPrivateKey(sign_~client#1); {29050#true} is VALID [2022-02-20 17:56:55,851 INFO L290 TraceCheckUtils]: 77: Hoare triple {29051#false} ~client#1 := #in~client#1;~msg#1 := #in~msg#1;assume { :begin_inline_sign } true;sign_#in~client#1, sign_#in~msg#1 := ~client#1, ~msg#1;havoc sign_#t~ret77#1, sign_~client#1, sign_~msg#1, sign_~privkey~1#1, sign_~tmp~18#1;sign_~client#1 := sign_#in~client#1;sign_~msg#1 := sign_#in~msg#1;havoc sign_~privkey~1#1;havoc sign_~tmp~18#1; {29051#false} is VALID [2022-02-20 17:56:55,851 INFO L272 TraceCheckUtils]: 76: Hoare triple {29051#false} call outgoing(~sender#1, ~email~0#1); {29051#false} is VALID [2022-02-20 17:56:55,851 INFO L290 TraceCheckUtils]: 75: Hoare triple {29051#false} #t~ret73#1 := createEmail_#res#1;assume { :end_inline_createEmail } true;assume -2147483648 <= #t~ret73#1 && #t~ret73#1 <= 2147483647;~tmp~16#1 := #t~ret73#1;havoc #t~ret73#1;~email~0#1 := ~tmp~16#1; {29051#false} is VALID [2022-02-20 17:56:55,851 INFO L290 TraceCheckUtils]: 74: Hoare triple {29051#false} createEmail_~retValue_acc~4#1 := createEmail_~msg~0#1;createEmail_#res#1 := createEmail_~retValue_acc~4#1; {29051#false} is VALID [2022-02-20 17:56:55,851 INFO L284 TraceCheckUtils]: 73: Hoare quadruple {29050#true} {29051#false} #1121#return; {29051#false} is VALID [2022-02-20 17:56:55,851 INFO L290 TraceCheckUtils]: 72: Hoare triple {29050#true} assume true; {29050#true} is VALID [2022-02-20 17:56:55,851 INFO L290 TraceCheckUtils]: 71: Hoare triple {29050#true} assume 1 == ~handle;~__ste_email_to0~0 := ~value; {29050#true} is VALID [2022-02-20 17:56:55,851 INFO L290 TraceCheckUtils]: 70: Hoare triple {29050#true} ~handle := #in~handle;~value := #in~value; {29050#true} is VALID [2022-02-20 17:56:55,851 INFO L272 TraceCheckUtils]: 69: Hoare triple {29051#false} call setEmailTo(createEmail_~msg~0#1, createEmail_~to#1); {29050#true} is VALID [2022-02-20 17:56:55,851 INFO L284 TraceCheckUtils]: 68: Hoare quadruple {29050#true} {29051#false} #1119#return; {29051#false} is VALID [2022-02-20 17:56:55,851 INFO L290 TraceCheckUtils]: 67: Hoare triple {29050#true} assume true; {29050#true} is VALID [2022-02-20 17:56:55,852 INFO L290 TraceCheckUtils]: 66: Hoare triple {29050#true} assume 1 == ~handle;~__ste_email_from0~0 := ~value; {29050#true} is VALID [2022-02-20 17:56:55,852 INFO L290 TraceCheckUtils]: 65: Hoare triple {29050#true} ~handle := #in~handle;~value := #in~value; {29050#true} is VALID [2022-02-20 17:56:55,852 INFO L272 TraceCheckUtils]: 64: Hoare triple {29051#false} call setEmailFrom(createEmail_~msg~0#1, createEmail_~from#1); {29050#true} is VALID [2022-02-20 17:56:55,852 INFO L290 TraceCheckUtils]: 63: Hoare triple {29051#false} ~sender#1 := #in~sender#1;~receiver#1 := #in~receiver#1;havoc ~email~0#1;havoc ~tmp~16#1;assume { :begin_inline_createEmail } true;createEmail_#in~from#1, createEmail_#in~to#1 := 0, ~receiver#1;havoc createEmail_#res#1;havoc createEmail_~from#1, createEmail_~to#1, createEmail_~retValue_acc~4#1, createEmail_~msg~0#1;createEmail_~from#1 := createEmail_#in~from#1;createEmail_~to#1 := createEmail_#in~to#1;havoc createEmail_~retValue_acc~4#1;havoc createEmail_~msg~0#1;createEmail_~msg~0#1 := 1; {29051#false} is VALID [2022-02-20 17:56:55,852 INFO L272 TraceCheckUtils]: 62: Hoare triple {29051#false} call sendEmail(~bob~0, ~rjh~0); {29051#false} is VALID [2022-02-20 17:56:55,852 INFO L290 TraceCheckUtils]: 61: Hoare triple {29051#false} assume { :begin_inline_bobToRjh } true;havoc bobToRjh_#t~ret90#1, bobToRjh_#t~ret91#1, bobToRjh_#t~ret92#1, bobToRjh_#t~ret93#1, bobToRjh_~tmp~23#1, bobToRjh_~tmp___0~7#1, bobToRjh_~tmp___1~4#1;havoc bobToRjh_~tmp~23#1;havoc bobToRjh_~tmp___0~7#1;havoc bobToRjh_~tmp___1~4#1;call bobToRjh_#t~ret90#1 := puts(32, 0);assume -2147483648 <= bobToRjh_#t~ret90#1 && bobToRjh_#t~ret90#1 <= 2147483647;havoc bobToRjh_#t~ret90#1; {29051#false} is VALID [2022-02-20 17:56:55,852 INFO L290 TraceCheckUtils]: 60: Hoare triple {29647#(< |ULTIMATE.start_test_~splverifierCounter~0#1| 4)} assume !(test_~splverifierCounter~0#1 < 4); {29051#false} is VALID [2022-02-20 17:56:55,852 INFO L290 TraceCheckUtils]: 59: Hoare triple {29647#(< |ULTIMATE.start_test_~splverifierCounter~0#1| 4)} assume !false; {29647#(< |ULTIMATE.start_test_~splverifierCounter~0#1| 4)} is VALID [2022-02-20 17:56:55,852 INFO L290 TraceCheckUtils]: 58: Hoare triple {29647#(< |ULTIMATE.start_test_~splverifierCounter~0#1| 4)} assume { :end_inline_rjhSetAutoRespond } true;test_~op2~0#1 := 1; {29647#(< |ULTIMATE.start_test_~splverifierCounter~0#1| 4)} is VALID [2022-02-20 17:56:55,853 INFO L290 TraceCheckUtils]: 57: Hoare triple {29647#(< |ULTIMATE.start_test_~splverifierCounter~0#1| 4)} assume { :end_inline_setClientAutoResponse } true; {29647#(< |ULTIMATE.start_test_~splverifierCounter~0#1| 4)} is VALID [2022-02-20 17:56:55,853 INFO L290 TraceCheckUtils]: 56: Hoare triple {29647#(< |ULTIMATE.start_test_~splverifierCounter~0#1| 4)} assume 1 == setClientAutoResponse_~handle#1;~__ste_client_autoResponse0~0 := setClientAutoResponse_~value#1; {29647#(< |ULTIMATE.start_test_~splverifierCounter~0#1| 4)} is VALID [2022-02-20 17:56:55,853 INFO L290 TraceCheckUtils]: 55: Hoare triple {29647#(< |ULTIMATE.start_test_~splverifierCounter~0#1| 4)} assume 0 != test_~tmp___8~0#1;assume { :begin_inline_rjhSetAutoRespond } true;assume { :begin_inline_setClientAutoResponse } true;setClientAutoResponse_#in~handle#1, setClientAutoResponse_#in~value#1 := ~rjh~0, 1;havoc setClientAutoResponse_~handle#1, setClientAutoResponse_~value#1;setClientAutoResponse_~handle#1 := setClientAutoResponse_#in~handle#1;setClientAutoResponse_~value#1 := setClientAutoResponse_#in~value#1; {29647#(< |ULTIMATE.start_test_~splverifierCounter~0#1| 4)} is VALID [2022-02-20 17:56:55,853 INFO L290 TraceCheckUtils]: 54: Hoare triple {29647#(< |ULTIMATE.start_test_~splverifierCounter~0#1| 4)} assume 0 == test_~op2~0#1;assume -2147483648 <= test_#t~nondet49#1 && test_#t~nondet49#1 <= 2147483647;test_~tmp___8~0#1 := test_#t~nondet49#1;havoc test_#t~nondet49#1; {29647#(< |ULTIMATE.start_test_~splverifierCounter~0#1| 4)} is VALID [2022-02-20 17:56:55,854 INFO L290 TraceCheckUtils]: 53: Hoare triple {29647#(< |ULTIMATE.start_test_~splverifierCounter~0#1| 4)} assume !(0 != test_~tmp___9~0#1); {29647#(< |ULTIMATE.start_test_~splverifierCounter~0#1| 4)} is VALID [2022-02-20 17:56:55,854 INFO L290 TraceCheckUtils]: 52: Hoare triple {29647#(< |ULTIMATE.start_test_~splverifierCounter~0#1| 4)} assume 0 == test_~op1~0#1;assume -2147483648 <= test_#t~nondet48#1 && test_#t~nondet48#1 <= 2147483647;test_~tmp___9~0#1 := test_#t~nondet48#1;havoc test_#t~nondet48#1; {29647#(< |ULTIMATE.start_test_~splverifierCounter~0#1| 4)} is VALID [2022-02-20 17:56:55,854 INFO L290 TraceCheckUtils]: 51: Hoare triple {29675#(< |ULTIMATE.start_test_~splverifierCounter~0#1| 3)} test_~splverifierCounter~0#1 := 1 + test_~splverifierCounter~0#1; {29647#(< |ULTIMATE.start_test_~splverifierCounter~0#1| 4)} is VALID [2022-02-20 17:56:55,855 INFO L290 TraceCheckUtils]: 50: Hoare triple {29675#(< |ULTIMATE.start_test_~splverifierCounter~0#1| 3)} assume test_~splverifierCounter~0#1 < 4; {29675#(< |ULTIMATE.start_test_~splverifierCounter~0#1| 3)} is VALID [2022-02-20 17:56:55,855 INFO L290 TraceCheckUtils]: 49: Hoare triple {29675#(< |ULTIMATE.start_test_~splverifierCounter~0#1| 3)} assume !false; {29675#(< |ULTIMATE.start_test_~splverifierCounter~0#1| 3)} is VALID [2022-02-20 17:56:55,855 INFO L290 TraceCheckUtils]: 48: Hoare triple {29050#true} assume { :end_inline_setup } true;assume { :begin_inline_test } true;havoc test_#t~nondet48#1, test_#t~nondet49#1, test_#t~nondet50#1, test_#t~nondet51#1, test_#t~nondet52#1, test_#t~nondet53#1, test_#t~nondet54#1, test_#t~nondet55#1, test_#t~nondet56#1, test_#t~nondet57#1, test_#t~nondet58#1, test_~op1~0#1, test_~op2~0#1, test_~op3~0#1, test_~op4~0#1, test_~op5~0#1, test_~op6~0#1, test_~op7~0#1, test_~op8~0#1, test_~op9~0#1, test_~op10~0#1, test_~op11~0#1, test_~splverifierCounter~0#1, test_~tmp~8#1, test_~tmp___0~3#1, test_~tmp___1~1#1, test_~tmp___2~1#1, test_~tmp___3~0#1, test_~tmp___4~0#1, test_~tmp___5~0#1, test_~tmp___6~0#1, test_~tmp___7~0#1, test_~tmp___8~0#1, test_~tmp___9~0#1;havoc test_~op1~0#1;havoc test_~op2~0#1;havoc test_~op3~0#1;havoc test_~op4~0#1;havoc test_~op5~0#1;havoc test_~op6~0#1;havoc test_~op7~0#1;havoc test_~op8~0#1;havoc test_~op9~0#1;havoc test_~op10~0#1;havoc test_~op11~0#1;havoc test_~splverifierCounter~0#1;havoc test_~tmp~8#1;havoc test_~tmp___0~3#1;havoc test_~tmp___1~1#1;havoc test_~tmp___2~1#1;havoc test_~tmp___3~0#1;havoc test_~tmp___4~0#1;havoc test_~tmp___5~0#1;havoc test_~tmp___6~0#1;havoc test_~tmp___7~0#1;havoc test_~tmp___8~0#1;havoc test_~tmp___9~0#1;test_~op1~0#1 := 0;test_~op2~0#1 := 0;test_~op3~0#1 := 0;test_~op4~0#1 := 0;test_~op5~0#1 := 0;test_~op6~0#1 := 0;test_~op7~0#1 := 0;test_~op8~0#1 := 0;test_~op9~0#1 := 0;test_~op10~0#1 := 0;test_~op11~0#1 := 0;test_~splverifierCounter~0#1 := 0; {29675#(< |ULTIMATE.start_test_~splverifierCounter~0#1| 3)} is VALID [2022-02-20 17:56:55,855 INFO L290 TraceCheckUtils]: 47: Hoare triple {29050#true} assume { :end_inline_setup_chuck } true;setup_~__cil_tmp3~2#1.base, setup_~__cil_tmp3~2#1.offset := 36, 0;havoc setup_#t~nondet97#1; {29050#true} is VALID [2022-02-20 17:56:55,855 INFO L284 TraceCheckUtils]: 46: Hoare quadruple {29050#true} {29050#true} #1143#return; {29050#true} is VALID [2022-02-20 17:56:55,855 INFO L290 TraceCheckUtils]: 45: Hoare triple {29050#true} assume true; {29050#true} is VALID [2022-02-20 17:56:55,855 INFO L290 TraceCheckUtils]: 44: Hoare triple {29050#true} assume 3 == ~handle;~__ste_client_privateKey2~0 := ~value; {29050#true} is VALID [2022-02-20 17:56:55,856 INFO L290 TraceCheckUtils]: 43: Hoare triple {29050#true} assume !(2 == ~handle); {29050#true} is VALID [2022-02-20 17:56:55,856 INFO L290 TraceCheckUtils]: 42: Hoare triple {29050#true} assume !(1 == ~handle); {29050#true} is VALID [2022-02-20 17:56:55,856 INFO L290 TraceCheckUtils]: 41: Hoare triple {29050#true} ~handle := #in~handle;~value := #in~value; {29050#true} is VALID [2022-02-20 17:56:55,856 INFO L272 TraceCheckUtils]: 40: Hoare triple {29050#true} call setClientPrivateKey(setup_chuck_~chuck___0#1, 789); {29050#true} is VALID [2022-02-20 17:56:55,856 INFO L290 TraceCheckUtils]: 39: Hoare triple {29050#true} assume { :end_inline_setup_chuck__wrappee__Base } true; {29050#true} is VALID [2022-02-20 17:56:55,856 INFO L284 TraceCheckUtils]: 38: Hoare quadruple {29050#true} {29050#true} #1141#return; {29050#true} is VALID [2022-02-20 17:56:55,856 INFO L290 TraceCheckUtils]: 37: Hoare triple {29050#true} assume true; {29050#true} is VALID [2022-02-20 17:56:55,856 INFO L290 TraceCheckUtils]: 36: Hoare triple {29050#true} assume 3 == ~handle;~__ste_client_idCounter2~0 := ~value; {29050#true} is VALID [2022-02-20 17:56:55,856 INFO L290 TraceCheckUtils]: 35: Hoare triple {29050#true} assume !(2 == ~handle); {29050#true} is VALID [2022-02-20 17:56:55,856 INFO L290 TraceCheckUtils]: 34: Hoare triple {29050#true} assume !(1 == ~handle); {29050#true} is VALID [2022-02-20 17:56:55,856 INFO L290 TraceCheckUtils]: 33: Hoare triple {29050#true} ~handle := #in~handle;~value := #in~value; {29050#true} is VALID [2022-02-20 17:56:55,856 INFO L272 TraceCheckUtils]: 32: Hoare triple {29050#true} call setClientId(setup_chuck__wrappee__Base_~chuck___0#1, setup_chuck__wrappee__Base_~chuck___0#1); {29050#true} is VALID [2022-02-20 17:56:55,856 INFO L290 TraceCheckUtils]: 31: Hoare triple {29050#true} assume { :end_inline_setup_rjh } true;setup_~__cil_tmp2~0#1.base, setup_~__cil_tmp2~0#1.offset := 35, 0;havoc setup_#t~nondet96#1;~chuck~0 := 3;assume { :begin_inline_setup_chuck } true;setup_chuck_#in~chuck___0#1 := ~chuck~0;havoc setup_chuck_~chuck___0#1;setup_chuck_~chuck___0#1 := setup_chuck_#in~chuck___0#1;assume { :begin_inline_setup_chuck__wrappee__Base } true;setup_chuck__wrappee__Base_#in~chuck___0#1 := setup_chuck_~chuck___0#1;havoc setup_chuck__wrappee__Base_~chuck___0#1;setup_chuck__wrappee__Base_~chuck___0#1 := setup_chuck__wrappee__Base_#in~chuck___0#1; {29050#true} is VALID [2022-02-20 17:56:55,856 INFO L284 TraceCheckUtils]: 30: Hoare quadruple {29050#true} {29050#true} #1139#return; {29050#true} is VALID [2022-02-20 17:56:55,856 INFO L290 TraceCheckUtils]: 29: Hoare triple {29050#true} assume true; {29050#true} is VALID [2022-02-20 17:56:55,856 INFO L290 TraceCheckUtils]: 28: Hoare triple {29050#true} assume 2 == ~handle;~__ste_client_privateKey1~0 := ~value; {29050#true} is VALID [2022-02-20 17:56:55,856 INFO L290 TraceCheckUtils]: 27: Hoare triple {29050#true} assume !(1 == ~handle); {29050#true} is VALID [2022-02-20 17:56:55,856 INFO L290 TraceCheckUtils]: 26: Hoare triple {29050#true} ~handle := #in~handle;~value := #in~value; {29050#true} is VALID [2022-02-20 17:56:55,856 INFO L272 TraceCheckUtils]: 25: Hoare triple {29050#true} call setClientPrivateKey(setup_rjh_~rjh___0#1, 456); {29050#true} is VALID [2022-02-20 17:56:55,856 INFO L290 TraceCheckUtils]: 24: Hoare triple {29050#true} assume { :end_inline_setup_rjh__wrappee__Base } true; {29050#true} is VALID [2022-02-20 17:56:55,856 INFO L284 TraceCheckUtils]: 23: Hoare quadruple {29050#true} {29050#true} #1137#return; {29050#true} is VALID [2022-02-20 17:56:55,856 INFO L290 TraceCheckUtils]: 22: Hoare triple {29050#true} assume true; {29050#true} is VALID [2022-02-20 17:56:55,857 INFO L290 TraceCheckUtils]: 21: Hoare triple {29050#true} assume 2 == ~handle;~__ste_client_idCounter1~0 := ~value; {29050#true} is VALID [2022-02-20 17:56:55,857 INFO L290 TraceCheckUtils]: 20: Hoare triple {29050#true} assume !(1 == ~handle); {29050#true} is VALID [2022-02-20 17:56:55,857 INFO L290 TraceCheckUtils]: 19: Hoare triple {29050#true} ~handle := #in~handle;~value := #in~value; {29050#true} is VALID [2022-02-20 17:56:55,857 INFO L272 TraceCheckUtils]: 18: Hoare triple {29050#true} call setClientId(setup_rjh__wrappee__Base_~rjh___0#1, setup_rjh__wrappee__Base_~rjh___0#1); {29050#true} is VALID [2022-02-20 17:56:55,857 INFO L290 TraceCheckUtils]: 17: Hoare triple {29050#true} assume { :end_inline_setup_bob } true;setup_~__cil_tmp1~0#1.base, setup_~__cil_tmp1~0#1.offset := 34, 0;havoc setup_#t~nondet95#1;~rjh~0 := 2;assume { :begin_inline_setup_rjh } true;setup_rjh_#in~rjh___0#1 := ~rjh~0;havoc setup_rjh_~rjh___0#1;setup_rjh_~rjh___0#1 := setup_rjh_#in~rjh___0#1;assume { :begin_inline_setup_rjh__wrappee__Base } true;setup_rjh__wrappee__Base_#in~rjh___0#1 := setup_rjh_~rjh___0#1;havoc setup_rjh__wrappee__Base_~rjh___0#1;setup_rjh__wrappee__Base_~rjh___0#1 := setup_rjh__wrappee__Base_#in~rjh___0#1; {29050#true} is VALID [2022-02-20 17:56:55,857 INFO L284 TraceCheckUtils]: 16: Hoare quadruple {29050#true} {29050#true} #1135#return; {29050#true} is VALID [2022-02-20 17:56:55,857 INFO L290 TraceCheckUtils]: 15: Hoare triple {29050#true} assume true; {29050#true} is VALID [2022-02-20 17:56:55,857 INFO L290 TraceCheckUtils]: 14: Hoare triple {29050#true} assume 1 == ~handle;~__ste_client_privateKey0~0 := ~value; {29050#true} is VALID [2022-02-20 17:56:55,857 INFO L290 TraceCheckUtils]: 13: Hoare triple {29050#true} ~handle := #in~handle;~value := #in~value; {29050#true} is VALID [2022-02-20 17:56:55,857 INFO L272 TraceCheckUtils]: 12: Hoare triple {29050#true} call setClientPrivateKey(setup_bob_~bob___0#1, 123); {29050#true} is VALID [2022-02-20 17:56:55,857 INFO L290 TraceCheckUtils]: 11: Hoare triple {29050#true} assume { :end_inline_setup_bob__wrappee__Base } true; {29050#true} is VALID [2022-02-20 17:56:55,857 INFO L284 TraceCheckUtils]: 10: Hoare quadruple {29050#true} {29050#true} #1133#return; {29050#true} is VALID [2022-02-20 17:56:55,857 INFO L290 TraceCheckUtils]: 9: Hoare triple {29050#true} assume true; {29050#true} is VALID [2022-02-20 17:56:55,857 INFO L290 TraceCheckUtils]: 8: Hoare triple {29050#true} assume 1 == ~handle;~__ste_client_idCounter0~0 := ~value; {29050#true} is VALID [2022-02-20 17:56:55,857 INFO L290 TraceCheckUtils]: 7: Hoare triple {29050#true} ~handle := #in~handle;~value := #in~value; {29050#true} is VALID [2022-02-20 17:56:55,857 INFO L272 TraceCheckUtils]: 6: Hoare triple {29050#true} call setClientId(setup_bob__wrappee__Base_~bob___0#1, setup_bob__wrappee__Base_~bob___0#1); {29050#true} is VALID [2022-02-20 17:56:55,857 INFO L290 TraceCheckUtils]: 5: Hoare triple {29050#true} assume 0 != main_~tmp~24#1;assume { :begin_inline_setup } true;havoc setup_#t~nondet95#1, setup_#t~nondet96#1, setup_#t~nondet97#1, setup_~__cil_tmp1~0#1.base, setup_~__cil_tmp1~0#1.offset, setup_~__cil_tmp2~0#1.base, setup_~__cil_tmp2~0#1.offset, setup_~__cil_tmp3~2#1.base, setup_~__cil_tmp3~2#1.offset;havoc setup_~__cil_tmp1~0#1.base, setup_~__cil_tmp1~0#1.offset;havoc setup_~__cil_tmp2~0#1.base, setup_~__cil_tmp2~0#1.offset;havoc setup_~__cil_tmp3~2#1.base, setup_~__cil_tmp3~2#1.offset;~bob~0 := 1;assume { :begin_inline_setup_bob } true;setup_bob_#in~bob___0#1 := ~bob~0;havoc setup_bob_~bob___0#1;setup_bob_~bob___0#1 := setup_bob_#in~bob___0#1;assume { :begin_inline_setup_bob__wrappee__Base } true;setup_bob__wrappee__Base_#in~bob___0#1 := setup_bob_~bob___0#1;havoc setup_bob__wrappee__Base_~bob___0#1;setup_bob__wrappee__Base_~bob___0#1 := setup_bob__wrappee__Base_#in~bob___0#1; {29050#true} is VALID [2022-02-20 17:56:55,857 INFO L290 TraceCheckUtils]: 4: Hoare triple {29050#true} main_#t~ret98#1 := valid_product_#res#1;assume { :end_inline_valid_product } true;assume -2147483648 <= main_#t~ret98#1 && main_#t~ret98#1 <= 2147483647;main_~tmp~24#1 := main_#t~ret98#1;havoc main_#t~ret98#1; {29050#true} is VALID [2022-02-20 17:56:55,857 INFO L290 TraceCheckUtils]: 3: Hoare triple {29050#true} assume { :end_inline_select_features } true;assume { :begin_inline_valid_product } true;havoc valid_product_#res#1;havoc valid_product_~retValue_acc~9#1;havoc valid_product_~retValue_acc~9#1;valid_product_~retValue_acc~9#1 := 1;valid_product_#res#1 := valid_product_~retValue_acc~9#1; {29050#true} is VALID [2022-02-20 17:56:55,857 INFO L290 TraceCheckUtils]: 2: Hoare triple {29050#true} assume { :end_inline_select_helpers } true;assume { :begin_inline_select_features } true; {29050#true} is VALID [2022-02-20 17:56:55,857 INFO L290 TraceCheckUtils]: 1: Hoare triple {29050#true} assume { :end_inline_ULTIMATE.init } true;assume { :begin_inline_main } true;havoc main_#res#1;havoc main_#t~ret98#1, main_~retValue_acc~32#1, main_~tmp~24#1;havoc main_~retValue_acc~32#1;havoc main_~tmp~24#1;assume { :begin_inline_select_helpers } true; {29050#true} is VALID [2022-02-20 17:56:55,857 INFO L290 TraceCheckUtils]: 0: Hoare triple {29050#true} assume { :begin_inline_ULTIMATE.init } true;#NULL.base, #NULL.offset := 0, 0;assume 0 == #valid[0];assume 0 < #StackHeapBarrier;call #Ultimate.allocInit(2, 1);call write~init~int(48, 1, 0, 1);call write~init~int(0, 1, 1, 1);call #Ultimate.allocInit(28, 2);call #Ultimate.allocInit(12, 3);call #Ultimate.allocInit(4, 4);call write~init~int(37, 4, 0, 1);call write~init~int(115, 4, 1, 1);call write~init~int(10, 4, 2, 1);call write~init~int(0, 4, 3, 1);call #Ultimate.allocInit(10, 5);call #Ultimate.allocInit(12, 6);call #Ultimate.allocInit(10, 7);call #Ultimate.allocInit(18, 8);call #Ultimate.allocInit(16, 9);call #Ultimate.allocInit(21, 10);call #Ultimate.allocInit(13, 11);call #Ultimate.allocInit(16, 12);call #Ultimate.allocInit(25, 13);call #Ultimate.allocInit(30, 14);call #Ultimate.allocInit(9, 15);call #Ultimate.allocInit(21, 16);call #Ultimate.allocInit(30, 17);call #Ultimate.allocInit(9, 18);call #Ultimate.allocInit(21, 19);call #Ultimate.allocInit(30, 20);call #Ultimate.allocInit(9, 21);call #Ultimate.allocInit(25, 22);call #Ultimate.allocInit(30, 23);call #Ultimate.allocInit(9, 24);call #Ultimate.allocInit(25, 25);call #Ultimate.allocInit(10, 26);call #Ultimate.allocInit(16, 27);call #Ultimate.allocInit(20, 28);call #Ultimate.allocInit(22, 29);call #Ultimate.allocInit(21, 30);call #Ultimate.allocInit(13, 31);call #Ultimate.allocInit(44, 32);call #Ultimate.allocInit(44, 33);call #Ultimate.allocInit(9, 34);call #Ultimate.allocInit(9, 35);call #Ultimate.allocInit(11, 36);call #Ultimate.allocInit(19, 37);call #Ultimate.allocInit(4, 38);call write~init~int(37, 38, 0, 1);call write~init~int(100, 38, 1, 1);call write~init~int(10, 38, 2, 1);call write~init~int(0, 38, 3, 1);call #Ultimate.allocInit(4, 39);call write~init~int(37, 39, 0, 1);call write~init~int(100, 39, 1, 1);call write~init~int(10, 39, 2, 1);call write~init~int(0, 39, 3, 1);~__SELECTED_FEATURE_Base~0 := 0;~__SELECTED_FEATURE_Keys~0 := 0;~__SELECTED_FEATURE_Encrypt~0 := 0;~__SELECTED_FEATURE_AutoResponder~0 := 0;~__SELECTED_FEATURE_AddressBook~0 := 0;~__SELECTED_FEATURE_Sign~0 := 0;~__SELECTED_FEATURE_Forward~0 := 0;~__SELECTED_FEATURE_Verify~0 := 0;~__SELECTED_FEATURE_Decrypt~0 := 0;~__GUIDSL_ROOT_PRODUCTION~0 := 0;~__GUIDSL_NON_TERMINAL_main~0 := 0;~head~0.base, ~head~0.offset := 0, 0;~queue_empty~0 := 1;~queued_message~0 := 0;~queued_client~0 := 0;~mail_is_sensitive~0 := -1;~__ste_Client_counter~0 := 0;~__ste_client_name0~0.base, ~__ste_client_name0~0.offset := 0, 0;~__ste_client_name1~0.base, ~__ste_client_name1~0.offset := 0, 0;~__ste_client_name2~0.base, ~__ste_client_name2~0.offset := 0, 0;~__ste_client_outbuffer0~0 := 0;~__ste_client_outbuffer1~0 := 0;~__ste_client_outbuffer2~0 := 0;~__ste_client_outbuffer3~0 := 0;~__ste_ClientAddressBook_size0~0 := 0;~__ste_ClientAddressBook_size1~0 := 0;~__ste_ClientAddressBook_size2~0 := 0;~__ste_Client_AddressBook0_Alias0~0 := 0;~__ste_Client_AddressBook0_Alias1~0 := 0;~__ste_Client_AddressBook0_Alias2~0 := 0;~__ste_Client_AddressBook1_Alias0~0 := 0;~__ste_Client_AddressBook1_Alias1~0 := 0;~__ste_Client_AddressBook1_Alias2~0 := 0;~__ste_Client_AddressBook2_Alias0~0 := 0;~__ste_Client_AddressBook2_Alias1~0 := 0;~__ste_Client_AddressBook2_Alias2~0 := 0;~__ste_Client_AddressBook0_Address0~0 := 0;~__ste_Client_AddressBook0_Address1~0 := 0;~__ste_Client_AddressBook0_Address2~0 := 0;~__ste_Client_AddressBook1_Address0~0 := 0;~__ste_Client_AddressBook1_Address1~0 := 0;~__ste_Client_AddressBook1_Address2~0 := 0;~__ste_Client_AddressBook2_Address0~0 := 0;~__ste_Client_AddressBook2_Address1~0 := 0;~__ste_Client_AddressBook2_Address2~0 := 0;~__ste_client_autoResponse0~0 := 0;~__ste_client_autoResponse1~0 := 0;~__ste_client_autoResponse2~0 := 0;~__ste_client_privateKey0~0 := 0;~__ste_client_privateKey1~0 := 0;~__ste_client_privateKey2~0 := 0;~__ste_ClientKeyring_size0~0 := 0;~__ste_ClientKeyring_size1~0 := 0;~__ste_ClientKeyring_size2~0 := 0;~__ste_Client_Keyring0_User0~0 := 0;~__ste_Client_Keyring0_User1~0 := 0;~__ste_Client_Keyring0_User2~0 := 0;~__ste_Client_Keyring1_User0~0 := 0;~__ste_Client_Keyring1_User1~0 := 0;~__ste_Client_Keyring1_User2~0 := 0;~__ste_Client_Keyring2_User0~0 := 0;~__ste_Client_Keyring2_User1~0 := 0;~__ste_Client_Keyring2_User2~0 := 0;~__ste_Client_Keyring0_PublicKey0~0 := 0;~__ste_Client_Keyring0_PublicKey1~0 := 0;~__ste_Client_Keyring0_PublicKey2~0 := 0;~__ste_Client_Keyring1_PublicKey0~0 := 0;~__ste_Client_Keyring1_PublicKey1~0 := 0;~__ste_Client_Keyring1_PublicKey2~0 := 0;~__ste_Client_Keyring2_PublicKey0~0 := 0;~__ste_Client_Keyring2_PublicKey1~0 := 0;~__ste_Client_Keyring2_PublicKey2~0 := 0;~__ste_client_forwardReceiver0~0 := 0;~__ste_client_forwardReceiver1~0 := 0;~__ste_client_forwardReceiver2~0 := 0;~__ste_client_forwardReceiver3~0 := 0;~__ste_client_idCounter0~0 := 0;~__ste_client_idCounter1~0 := 0;~__ste_client_idCounter2~0 := 0;~bob~0 := 0;~rjh~0 := 0;~chuck~0 := 0;~__ste_Email_counter~0 := 0;~__ste_email_id0~0 := 0;~__ste_email_id1~0 := 0;~__ste_email_from0~0 := 0;~__ste_email_from1~0 := 0;~__ste_email_to0~0 := 0;~__ste_email_to1~0 := 0;~__ste_email_subject0~0.base, ~__ste_email_subject0~0.offset := 0, 0;~__ste_email_subject1~0.base, ~__ste_email_subject1~0.offset := 0, 0;~__ste_email_body0~0.base, ~__ste_email_body0~0.offset := 0, 0;~__ste_email_body1~0.base, ~__ste_email_body1~0.offset := 0, 0;~__ste_email_isEncrypted0~0 := 0;~__ste_email_isEncrypted1~0 := 0;~__ste_email_encryptionKey0~0 := 0;~__ste_email_encryptionKey1~0 := 0;~__ste_email_isSigned0~0 := 0;~__ste_email_isSigned1~0 := 0;~__ste_email_signKey0~0 := 0;~__ste_email_signKey1~0 := 0;~__ste_email_isSignatureVerified0~0 := 0;~__ste_email_isSignatureVerified1~0 := 0; {29050#true} is VALID [2022-02-20 17:56:55,858 INFO L134 CoverageAnalysis]: Checked inductivity of 32 backedges. 0 proven. 2 refuted. 0 times theorem prover too weak. 30 trivial. 0 not checked. [2022-02-20 17:56:55,858 INFO L165 FreeRefinementEngine]: IpTcStrategyModuleZ3 [504328400] provided 0 perfect and 2 imperfect interpolant sequences [2022-02-20 17:56:55,858 INFO L191 FreeRefinementEngine]: Found 0 perfect and 3 imperfect interpolant sequences. [2022-02-20 17:56:55,858 INFO L204 FreeRefinementEngine]: Number of different interpolants: perfect sequences [] imperfect sequences [11, 4, 4] total 15 [2022-02-20 17:56:55,858 INFO L118 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [1763346905] [2022-02-20 17:56:55,858 INFO L85 oduleStraightlineAll]: Using 3 imperfect interpolants to construct interpolant automaton [2022-02-20 17:56:55,860 INFO L78 Accepts]: Start accepts. Automaton has has 15 states, 14 states have (on average 9.642857142857142) internal successors, (135), 11 states have internal predecessors, (135), 4 states have call successors, (31), 6 states have call predecessors, (31), 3 states have return successors, (24), 3 states have call predecessors, (24), 4 states have call successors, (24) Word has length 118 [2022-02-20 17:56:55,914 INFO L84 Accepts]: Finished accepts. word is accepted. [2022-02-20 17:56:55,915 INFO L86 InductivityCheck]: Starting indutivity check of a Floyd-Hoare automaton with has 15 states, 14 states have (on average 9.642857142857142) internal successors, (135), 11 states have internal predecessors, (135), 4 states have call successors, (31), 6 states have call predecessors, (31), 3 states have return successors, (24), 3 states have call predecessors, (24), 4 states have call successors, (24) [2022-02-20 17:56:56,021 INFO L122 InductivityCheck]: Floyd-Hoare automaton has 190 edges. 190 inductive. 0 not inductive. 0 times theorem prover too weak to decide inductivity. [2022-02-20 17:56:56,021 INFO L546 AbstractCegarLoop]: INTERPOLANT automaton has 15 states [2022-02-20 17:56:56,021 INFO L108 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2022-02-20 17:56:56,022 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 15 interpolants. [2022-02-20 17:56:56,022 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=33, Invalid=177, Unknown=0, NotChecked=0, Total=210 [2022-02-20 17:56:56,022 INFO L87 Difference]: Start difference. First operand 445 states and 673 transitions. Second operand has 15 states, 14 states have (on average 9.642857142857142) internal successors, (135), 11 states have internal predecessors, (135), 4 states have call successors, (31), 6 states have call predecessors, (31), 3 states have return successors, (24), 3 states have call predecessors, (24), 4 states have call successors, (24)