./Ultimate.py --spec ../sv-benchmarks/c/properties/unreach-call.prp --file ../sv-benchmarks/c/product-lines/email_spec4_product33.cil.c --full-output -ea --architecture 32bit -------------------------------------------------------------------------------- Checking for ERROR reachability Using default analysis Version 03d7b7b3 Calling Ultimate with: /usr/bin/java -Dosgi.configuration.area=/storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/data/config -Xmx15G -Xms4m -ea -jar /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/plugins/org.eclipse.equinox.launcher_1.5.800.v20200727-1323.jar -data @noDefault -ultimatedata /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/data -tc /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/config/AutomizerReach.xml -i ../sv-benchmarks/c/product-lines/email_spec4_product33.cil.c -s /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/config/svcomp-Reach-32bit-Automizer_Default.epf --cacsl2boogietranslator.entry.function main --witnessprinter.witness.directory /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux --witnessprinter.witness.filename witness.graphml --witnessprinter.write.witness.besides.input.file false --witnessprinter.graph.data.specification CHECK( init(main()), LTL(G ! call(reach_error())) ) --witnessprinter.graph.data.producer Automizer --witnessprinter.graph.data.architecture 32bit --witnessprinter.graph.data.programhash 7d58750164873693a8e41f270259eb299f067753793be4bdf6f5449bb7376f85 --- Real Ultimate output --- This is Ultimate 0.2.2-dev-03d7b7b [2022-02-20 17:59:54,455 INFO L177 SettingsManager]: Resetting all preferences to default values... [2022-02-20 17:59:54,456 INFO L181 SettingsManager]: Resetting UltimateCore preferences to default values [2022-02-20 17:59:54,486 INFO L184 SettingsManager]: Ultimate Commandline Interface provides no preferences, ignoring... [2022-02-20 17:59:54,486 INFO L181 SettingsManager]: Resetting Boogie Preprocessor preferences to default values [2022-02-20 17:59:54,489 INFO L181 SettingsManager]: Resetting Boogie Procedure Inliner preferences to default values [2022-02-20 17:59:54,490 INFO L181 SettingsManager]: Resetting Abstract Interpretation preferences to default values [2022-02-20 17:59:54,492 INFO L181 SettingsManager]: Resetting LassoRanker preferences to default values [2022-02-20 17:59:54,493 INFO L181 SettingsManager]: Resetting Reaching Definitions preferences to default values [2022-02-20 17:59:54,497 INFO L181 SettingsManager]: Resetting SyntaxChecker preferences to default values [2022-02-20 17:59:54,498 INFO L181 SettingsManager]: Resetting Sifa preferences to default values [2022-02-20 17:59:54,499 INFO L184 SettingsManager]: Büchi Program Product provides no preferences, ignoring... [2022-02-20 17:59:54,500 INFO L181 SettingsManager]: Resetting LTL2Aut preferences to default values [2022-02-20 17:59:54,501 INFO L181 SettingsManager]: Resetting PEA to Boogie preferences to default values [2022-02-20 17:59:54,502 INFO L181 SettingsManager]: Resetting BlockEncodingV2 preferences to default values [2022-02-20 17:59:54,503 INFO L181 SettingsManager]: Resetting ChcToBoogie preferences to default values [2022-02-20 17:59:54,504 INFO L181 SettingsManager]: Resetting AutomataScriptInterpreter preferences to default values [2022-02-20 17:59:54,505 INFO L181 SettingsManager]: Resetting BuchiAutomizer preferences to default values [2022-02-20 17:59:54,509 INFO L181 SettingsManager]: Resetting CACSL2BoogieTranslator preferences to default values [2022-02-20 17:59:54,511 INFO L181 SettingsManager]: Resetting CodeCheck preferences to default values [2022-02-20 17:59:54,514 INFO L181 SettingsManager]: Resetting InvariantSynthesis preferences to default values [2022-02-20 17:59:54,515 INFO L181 SettingsManager]: Resetting RCFGBuilder preferences to default values [2022-02-20 17:59:54,516 INFO L181 SettingsManager]: Resetting Referee preferences to default values [2022-02-20 17:59:54,517 INFO L181 SettingsManager]: Resetting TraceAbstraction preferences to default values [2022-02-20 17:59:54,520 INFO L184 SettingsManager]: TraceAbstractionConcurrent provides no preferences, ignoring... [2022-02-20 17:59:54,521 INFO L184 SettingsManager]: TraceAbstractionWithAFAs provides no preferences, ignoring... [2022-02-20 17:59:54,524 INFO L181 SettingsManager]: Resetting TreeAutomizer preferences to default values [2022-02-20 17:59:54,524 INFO L181 SettingsManager]: Resetting IcfgToChc preferences to default values [2022-02-20 17:59:54,525 INFO L181 SettingsManager]: Resetting IcfgTransformer preferences to default values [2022-02-20 17:59:54,526 INFO L184 SettingsManager]: ReqToTest provides no preferences, ignoring... [2022-02-20 17:59:54,526 INFO L181 SettingsManager]: Resetting Boogie Printer preferences to default values [2022-02-20 17:59:54,527 INFO L181 SettingsManager]: Resetting ChcSmtPrinter preferences to default values [2022-02-20 17:59:54,528 INFO L181 SettingsManager]: Resetting ReqPrinter preferences to default values [2022-02-20 17:59:54,529 INFO L181 SettingsManager]: Resetting Witness Printer preferences to default values [2022-02-20 17:59:54,530 INFO L184 SettingsManager]: Boogie PL CUP Parser provides no preferences, ignoring... [2022-02-20 17:59:54,531 INFO L181 SettingsManager]: Resetting CDTParser preferences to default values [2022-02-20 17:59:54,531 INFO L184 SettingsManager]: AutomataScriptParser provides no preferences, ignoring... [2022-02-20 17:59:54,531 INFO L184 SettingsManager]: ReqParser provides no preferences, ignoring... [2022-02-20 17:59:54,532 INFO L181 SettingsManager]: Resetting SmtParser preferences to default values [2022-02-20 17:59:54,532 INFO L181 SettingsManager]: Resetting Witness Parser preferences to default values [2022-02-20 17:59:54,533 INFO L188 SettingsManager]: Finished resetting all preferences to default values... [2022-02-20 17:59:54,534 INFO L101 SettingsManager]: Beginning loading settings from /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/config/svcomp-Reach-32bit-Automizer_Default.epf [2022-02-20 17:59:54,560 INFO L113 SettingsManager]: Loading preferences was successful [2022-02-20 17:59:54,561 INFO L115 SettingsManager]: Preferences different from defaults after loading the file: [2022-02-20 17:59:54,562 INFO L136 SettingsManager]: Preferences of UltimateCore differ from their defaults: [2022-02-20 17:59:54,562 INFO L138 SettingsManager]: * Log level for class=de.uni_freiburg.informatik.ultimate.lib.smtlibutils.quantifier.QuantifierPusher=ERROR; [2022-02-20 17:59:54,562 INFO L136 SettingsManager]: Preferences of Boogie Procedure Inliner differ from their defaults: [2022-02-20 17:59:54,563 INFO L138 SettingsManager]: * Ignore calls to procedures called more than once=ONLY_FOR_SEQUENTIAL_PROGRAMS [2022-02-20 17:59:54,563 INFO L136 SettingsManager]: Preferences of BlockEncodingV2 differ from their defaults: [2022-02-20 17:59:54,563 INFO L138 SettingsManager]: * Create parallel compositions if possible=false [2022-02-20 17:59:54,563 INFO L138 SettingsManager]: * Use SBE=true [2022-02-20 17:59:54,563 INFO L136 SettingsManager]: Preferences of CACSL2BoogieTranslator differ from their defaults: [2022-02-20 17:59:54,564 INFO L138 SettingsManager]: * sizeof long=4 [2022-02-20 17:59:54,564 INFO L138 SettingsManager]: * Overapproximate operations on floating types=true [2022-02-20 17:59:54,564 INFO L138 SettingsManager]: * sizeof POINTER=4 [2022-02-20 17:59:54,565 INFO L138 SettingsManager]: * Check division by zero=IGNORE [2022-02-20 17:59:54,565 INFO L138 SettingsManager]: * Pointer to allocated memory at dereference=IGNORE [2022-02-20 17:59:54,565 INFO L138 SettingsManager]: * If two pointers are subtracted or compared they have the same base address=IGNORE [2022-02-20 17:59:54,565 INFO L138 SettingsManager]: * Check array bounds for arrays that are off heap=IGNORE [2022-02-20 17:59:54,565 INFO L138 SettingsManager]: * sizeof long double=12 [2022-02-20 17:59:54,565 INFO L138 SettingsManager]: * Check if freed pointer was valid=false [2022-02-20 17:59:54,565 INFO L138 SettingsManager]: * Use constant arrays=true [2022-02-20 17:59:54,566 INFO L138 SettingsManager]: * Pointer base address is valid at dereference=IGNORE [2022-02-20 17:59:54,566 INFO L136 SettingsManager]: Preferences of RCFGBuilder differ from their defaults: [2022-02-20 17:59:54,566 INFO L138 SettingsManager]: * Size of a code block=SequenceOfStatements [2022-02-20 17:59:54,566 INFO L138 SettingsManager]: * SMT solver=External_DefaultMode [2022-02-20 17:59:54,566 INFO L138 SettingsManager]: * Command for external solver=z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in -t:2000 [2022-02-20 17:59:54,566 INFO L136 SettingsManager]: Preferences of TraceAbstraction differ from their defaults: [2022-02-20 17:59:54,566 INFO L138 SettingsManager]: * Compute Interpolants along a Counterexample=FPandBP [2022-02-20 17:59:54,567 INFO L138 SettingsManager]: * Positions where we compute the Hoare Annotation=LoopsAndPotentialCycles [2022-02-20 17:59:54,568 INFO L138 SettingsManager]: * Trace refinement strategy=CAMEL [2022-02-20 17:59:54,568 INFO L138 SettingsManager]: * Command for external solver=z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in [2022-02-20 17:59:54,568 INFO L138 SettingsManager]: * Large block encoding in concurrent analysis=OFF [2022-02-20 17:59:54,568 INFO L138 SettingsManager]: * Automaton type used in concurrency analysis=PETRI_NET [2022-02-20 17:59:54,568 INFO L138 SettingsManager]: * Compute Hoare Annotation of negated interpolant automaton, abstraction and CFG=true [2022-02-20 17:59:54,568 INFO L138 SettingsManager]: * SMT solver=External_ModelsAndUnsatCoreMode WARNING: An illegal reflective access operation has occurred WARNING: Illegal reflective access by com.sun.xml.bind.v2.runtime.reflect.opt.Injector$1 (file:/storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/plugins/com.sun.xml.bind_2.2.0.v201505121915.jar) to method java.lang.ClassLoader.defineClass(java.lang.String,byte[],int,int) WARNING: Please consider reporting this to the maintainers of com.sun.xml.bind.v2.runtime.reflect.opt.Injector$1 WARNING: Use --illegal-access=warn to enable warnings of further illegal reflective access operations WARNING: All illegal access operations will be denied in a future release Applying setting for plugin de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator: Entry function -> main Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Witness directory -> /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Witness filename -> witness.graphml Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Write witness besides input file -> false Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Graph data specification -> CHECK( init(main()), LTL(G ! call(reach_error())) ) Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Graph data producer -> Automizer Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Graph data architecture -> 32bit Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Graph data programhash -> 7d58750164873693a8e41f270259eb299f067753793be4bdf6f5449bb7376f85 [2022-02-20 17:59:54,766 INFO L75 nceAwareModelManager]: Repository-Root is: /tmp [2022-02-20 17:59:54,785 INFO L261 ainManager$Toolchain]: [Toolchain 1]: Applicable parser(s) successfully (re)initialized [2022-02-20 17:59:54,787 INFO L217 ainManager$Toolchain]: [Toolchain 1]: Toolchain selected. [2022-02-20 17:59:54,787 INFO L271 PluginConnector]: Initializing CDTParser... [2022-02-20 17:59:54,788 INFO L275 PluginConnector]: CDTParser initialized [2022-02-20 17:59:54,789 INFO L432 ainManager$Toolchain]: [Toolchain 1]: Parsing single file: /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/../sv-benchmarks/c/product-lines/email_spec4_product33.cil.c [2022-02-20 17:59:54,831 INFO L220 CDTParser]: Created temporary CDT project at /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/data/51f071b4d/bfcaaa4d1b1249fb8c4f0dd22bfe5c9d/FLAGc8b934ff0 [2022-02-20 17:59:55,306 INFO L306 CDTParser]: Found 1 translation units. [2022-02-20 17:59:55,306 INFO L160 CDTParser]: Scanning /storage/repos/ultimate/releaseScripts/default/sv-benchmarks/c/product-lines/email_spec4_product33.cil.c [2022-02-20 17:59:55,325 INFO L349 CDTParser]: About to delete temporary CDT project at /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/data/51f071b4d/bfcaaa4d1b1249fb8c4f0dd22bfe5c9d/FLAGc8b934ff0 [2022-02-20 17:59:55,339 INFO L357 CDTParser]: Successfully deleted /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/data/51f071b4d/bfcaaa4d1b1249fb8c4f0dd22bfe5c9d [2022-02-20 17:59:55,341 INFO L299 ainManager$Toolchain]: ####################### [Toolchain 1] ####################### [2022-02-20 17:59:55,343 INFO L131 ToolchainWalker]: Walking toolchain with 6 elements. [2022-02-20 17:59:55,345 INFO L113 PluginConnector]: ------------------------CACSL2BoogieTranslator---------------------------- [2022-02-20 17:59:55,345 INFO L271 PluginConnector]: Initializing CACSL2BoogieTranslator... [2022-02-20 17:59:55,347 INFO L275 PluginConnector]: CACSL2BoogieTranslator initialized [2022-02-20 17:59:55,348 INFO L185 PluginConnector]: Executing the observer ACSLObjectContainerObserver from plugin CACSL2BoogieTranslator for "CDTParser AST 20.02 05:59:55" (1/1) ... [2022-02-20 17:59:55,349 INFO L205 PluginConnector]: Invalid model from CACSL2BoogieTranslator for observer de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator.ACSLObjectContainerObserver@214fd25 and model type de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 20.02 05:59:55, skipping insertion in model container [2022-02-20 17:59:55,349 INFO L185 PluginConnector]: Executing the observer CACSL2BoogieTranslatorObserver from plugin CACSL2BoogieTranslator for "CDTParser AST 20.02 05:59:55" (1/1) ... [2022-02-20 17:59:55,354 INFO L145 MainTranslator]: Starting translation in SV-COMP mode [2022-02-20 17:59:55,409 INFO L178 MainTranslator]: Built tables and reachable declarations [2022-02-20 17:59:55,651 WARN L230 ndardFunctionHandler]: Function reach_error is already implemented but we override the implementation for the call at /storage/repos/ultimate/releaseScripts/default/sv-benchmarks/c/product-lines/email_spec4_product33.cil.c[11229,11242] [2022-02-20 17:59:55,883 INFO L210 PostProcessor]: Analyzing one entry point: main [2022-02-20 17:59:55,904 INFO L203 MainTranslator]: Completed pre-run [2022-02-20 17:59:55,938 WARN L230 ndardFunctionHandler]: Function reach_error is already implemented but we override the implementation for the call at /storage/repos/ultimate/releaseScripts/default/sv-benchmarks/c/product-lines/email_spec4_product33.cil.c[11229,11242] [2022-02-20 17:59:56,041 INFO L210 PostProcessor]: Analyzing one entry point: main [2022-02-20 17:59:56,063 INFO L208 MainTranslator]: Completed translation [2022-02-20 17:59:56,064 INFO L202 PluginConnector]: Adding new model de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 20.02 05:59:56 WrapperNode [2022-02-20 17:59:56,064 INFO L132 PluginConnector]: ------------------------ END CACSL2BoogieTranslator---------------------------- [2022-02-20 17:59:56,064 INFO L113 PluginConnector]: ------------------------Boogie Procedure Inliner---------------------------- [2022-02-20 17:59:56,065 INFO L271 PluginConnector]: Initializing Boogie Procedure Inliner... [2022-02-20 17:59:56,065 INFO L275 PluginConnector]: Boogie Procedure Inliner initialized [2022-02-20 17:59:56,069 INFO L185 PluginConnector]: Executing the observer TypeChecker from plugin Boogie Procedure Inliner for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 20.02 05:59:56" (1/1) ... [2022-02-20 17:59:56,094 INFO L185 PluginConnector]: Executing the observer Inliner from plugin Boogie Procedure Inliner for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 20.02 05:59:56" (1/1) ... [2022-02-20 17:59:56,150 INFO L137 Inliner]: procedures = 134, calls = 228, calls flagged for inlining = 65, calls inlined = 60, statements flattened = 1070 [2022-02-20 17:59:56,151 INFO L132 PluginConnector]: ------------------------ END Boogie Procedure Inliner---------------------------- [2022-02-20 17:59:56,151 INFO L113 PluginConnector]: ------------------------Boogie Preprocessor---------------------------- [2022-02-20 17:59:56,151 INFO L271 PluginConnector]: Initializing Boogie Preprocessor... [2022-02-20 17:59:56,151 INFO L275 PluginConnector]: Boogie Preprocessor initialized [2022-02-20 17:59:56,157 INFO L185 PluginConnector]: Executing the observer EnsureBoogieModelObserver from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 20.02 05:59:56" (1/1) ... [2022-02-20 17:59:56,157 INFO L185 PluginConnector]: Executing the observer TypeChecker from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 20.02 05:59:56" (1/1) ... [2022-02-20 17:59:56,162 INFO L185 PluginConnector]: Executing the observer ConstExpander from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 20.02 05:59:56" (1/1) ... [2022-02-20 17:59:56,162 INFO L185 PluginConnector]: Executing the observer StructExpander from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 20.02 05:59:56" (1/1) ... [2022-02-20 17:59:56,176 INFO L185 PluginConnector]: Executing the observer UnstructureCode from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 20.02 05:59:56" (1/1) ... [2022-02-20 17:59:56,208 INFO L185 PluginConnector]: Executing the observer FunctionInliner from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 20.02 05:59:56" (1/1) ... [2022-02-20 17:59:56,212 INFO L185 PluginConnector]: Executing the observer BoogieSymbolTableConstructor from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 20.02 05:59:56" (1/1) ... [2022-02-20 17:59:56,218 INFO L132 PluginConnector]: ------------------------ END Boogie Preprocessor---------------------------- [2022-02-20 17:59:56,219 INFO L113 PluginConnector]: ------------------------RCFGBuilder---------------------------- [2022-02-20 17:59:56,219 INFO L271 PluginConnector]: Initializing RCFGBuilder... [2022-02-20 17:59:56,219 INFO L275 PluginConnector]: RCFGBuilder initialized [2022-02-20 17:59:56,236 INFO L185 PluginConnector]: Executing the observer RCFGBuilderObserver from plugin RCFGBuilder for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 20.02 05:59:56" (1/1) ... [2022-02-20 17:59:56,255 INFO L173 SolverBuilder]: Constructing external solver with command: z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in -t:2000 [2022-02-20 17:59:56,270 INFO L189 MonitoredProcess]: No working directory specified, using /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 [2022-02-20 17:59:56,281 INFO L229 MonitoredProcess]: Starting monitored process 1 with /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in -t:2000 (exit command is (exit), workingDir is null) [2022-02-20 17:59:56,301 INFO L327 MonitoredProcess]: [MP /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in -t:2000 (1)] Waiting until timeout for monitored process [2022-02-20 17:59:56,317 INFO L130 BoogieDeclarations]: Found specification of procedure getClientPrivateKey [2022-02-20 17:59:56,317 INFO L138 BoogieDeclarations]: Found implementation of procedure getClientPrivateKey [2022-02-20 17:59:56,317 INFO L130 BoogieDeclarations]: Found specification of procedure setEmailEncryptionKey [2022-02-20 17:59:56,317 INFO L138 BoogieDeclarations]: Found implementation of procedure setEmailEncryptionKey [2022-02-20 17:59:56,318 INFO L130 BoogieDeclarations]: Found specification of procedure getEmailEncryptionKey [2022-02-20 17:59:56,318 INFO L138 BoogieDeclarations]: Found implementation of procedure getEmailEncryptionKey [2022-02-20 17:59:56,318 INFO L130 BoogieDeclarations]: Found specification of procedure getEmailTo [2022-02-20 17:59:56,318 INFO L138 BoogieDeclarations]: Found implementation of procedure getEmailTo [2022-02-20 17:59:56,319 INFO L130 BoogieDeclarations]: Found specification of procedure setEmailFrom [2022-02-20 17:59:56,320 INFO L138 BoogieDeclarations]: Found implementation of procedure setEmailFrom [2022-02-20 17:59:56,320 INFO L130 BoogieDeclarations]: Found specification of procedure isReadable [2022-02-20 17:59:56,320 INFO L138 BoogieDeclarations]: Found implementation of procedure isReadable [2022-02-20 17:59:56,320 INFO L130 BoogieDeclarations]: Found specification of procedure createClientKeyringEntry [2022-02-20 17:59:56,320 INFO L138 BoogieDeclarations]: Found implementation of procedure createClientKeyringEntry [2022-02-20 17:59:56,321 INFO L130 BoogieDeclarations]: Found specification of procedure setEmailIsEncrypted [2022-02-20 17:59:56,321 INFO L138 BoogieDeclarations]: Found implementation of procedure setEmailIsEncrypted [2022-02-20 17:59:56,321 INFO L130 BoogieDeclarations]: Found specification of procedure getEmailSignKey [2022-02-20 17:59:56,321 INFO L138 BoogieDeclarations]: Found implementation of procedure getEmailSignKey [2022-02-20 17:59:56,321 INFO L130 BoogieDeclarations]: Found specification of procedure chuckKeyAdd [2022-02-20 17:59:56,321 INFO L138 BoogieDeclarations]: Found implementation of procedure chuckKeyAdd [2022-02-20 17:59:56,321 INFO L130 BoogieDeclarations]: Found specification of procedure puts [2022-02-20 17:59:56,321 INFO L130 BoogieDeclarations]: Found specification of procedure getEmailFrom [2022-02-20 17:59:56,322 INFO L138 BoogieDeclarations]: Found implementation of procedure getEmailFrom [2022-02-20 17:59:56,322 INFO L130 BoogieDeclarations]: Found specification of procedure queue [2022-02-20 17:59:56,322 INFO L138 BoogieDeclarations]: Found implementation of procedure queue [2022-02-20 17:59:56,322 INFO L130 BoogieDeclarations]: Found specification of procedure setClientId [2022-02-20 17:59:56,322 INFO L138 BoogieDeclarations]: Found implementation of procedure setClientId [2022-02-20 17:59:56,322 INFO L130 BoogieDeclarations]: Found specification of procedure #Ultimate.allocInit [2022-02-20 17:59:56,322 INFO L130 BoogieDeclarations]: Found specification of procedure isSigned [2022-02-20 17:59:56,322 INFO L138 BoogieDeclarations]: Found implementation of procedure isSigned [2022-02-20 17:59:56,322 INFO L130 BoogieDeclarations]: Found specification of procedure isKeyPairValid [2022-02-20 17:59:56,323 INFO L138 BoogieDeclarations]: Found implementation of procedure isKeyPairValid [2022-02-20 17:59:56,323 INFO L130 BoogieDeclarations]: Found specification of procedure setClientKeyringUser [2022-02-20 17:59:56,323 INFO L138 BoogieDeclarations]: Found implementation of procedure setClientKeyringUser [2022-02-20 17:59:56,323 INFO L130 BoogieDeclarations]: Found specification of procedure setClientKeyringPublicKey [2022-02-20 17:59:56,323 INFO L138 BoogieDeclarations]: Found implementation of procedure setClientKeyringPublicKey [2022-02-20 17:59:56,323 INFO L130 BoogieDeclarations]: Found specification of procedure outgoing [2022-02-20 17:59:56,324 INFO L138 BoogieDeclarations]: Found implementation of procedure outgoing [2022-02-20 17:59:56,324 INFO L130 BoogieDeclarations]: Found specification of procedure findPublicKey [2022-02-20 17:59:56,324 INFO L138 BoogieDeclarations]: Found implementation of procedure findPublicKey [2022-02-20 17:59:56,324 INFO L130 BoogieDeclarations]: Found specification of procedure sendEmail [2022-02-20 17:59:56,324 INFO L138 BoogieDeclarations]: Found implementation of procedure sendEmail [2022-02-20 17:59:56,324 INFO L130 BoogieDeclarations]: Found specification of procedure isEncrypted [2022-02-20 17:59:56,325 INFO L138 BoogieDeclarations]: Found implementation of procedure isEncrypted [2022-02-20 17:59:56,325 INFO L130 BoogieDeclarations]: Found specification of procedure setClientPrivateKey [2022-02-20 17:59:56,325 INFO L138 BoogieDeclarations]: Found implementation of procedure setClientPrivateKey [2022-02-20 17:59:56,325 INFO L130 BoogieDeclarations]: Found specification of procedure setEmailTo [2022-02-20 17:59:56,325 INFO L138 BoogieDeclarations]: Found implementation of procedure setEmailTo [2022-02-20 17:59:56,325 INFO L130 BoogieDeclarations]: Found specification of procedure write~init~int [2022-02-20 17:59:56,325 INFO L130 BoogieDeclarations]: Found specification of procedure generateKeyPair [2022-02-20 17:59:56,325 INFO L138 BoogieDeclarations]: Found implementation of procedure generateKeyPair [2022-02-20 17:59:56,326 INFO L130 BoogieDeclarations]: Found specification of procedure ULTIMATE.start [2022-02-20 17:59:56,326 INFO L138 BoogieDeclarations]: Found implementation of procedure ULTIMATE.start [2022-02-20 17:59:56,502 INFO L234 CfgBuilder]: Building ICFG [2022-02-20 17:59:56,508 INFO L260 CfgBuilder]: Building CFG for each procedure with an implementation [2022-02-20 17:59:57,137 INFO L275 CfgBuilder]: Performing block encoding [2022-02-20 17:59:57,145 INFO L294 CfgBuilder]: Using the 1 location(s) as analysis (start of procedure ULTIMATE.start) [2022-02-20 17:59:57,145 INFO L299 CfgBuilder]: Removed 1 assume(true) statements. [2022-02-20 17:59:57,146 INFO L202 PluginConnector]: Adding new model de.uni_freiburg.informatik.ultimate.plugins.generator.rcfgbuilder CFG 20.02 05:59:57 BoogieIcfgContainer [2022-02-20 17:59:57,146 INFO L132 PluginConnector]: ------------------------ END RCFGBuilder---------------------------- [2022-02-20 17:59:57,147 INFO L113 PluginConnector]: ------------------------TraceAbstraction---------------------------- [2022-02-20 17:59:57,147 INFO L271 PluginConnector]: Initializing TraceAbstraction... [2022-02-20 17:59:57,149 INFO L275 PluginConnector]: TraceAbstraction initialized [2022-02-20 17:59:57,150 INFO L185 PluginConnector]: Executing the observer TraceAbstractionObserver from plugin TraceAbstraction for "CDTParser AST 20.02 05:59:55" (1/3) ... [2022-02-20 17:59:57,150 INFO L205 PluginConnector]: Invalid model from TraceAbstraction for observer de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction.TraceAbstractionObserver@324cfd7a and model type de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction AST 20.02 05:59:57, skipping insertion in model container [2022-02-20 17:59:57,150 INFO L185 PluginConnector]: Executing the observer TraceAbstractionObserver from plugin TraceAbstraction for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 20.02 05:59:56" (2/3) ... [2022-02-20 17:59:57,151 INFO L205 PluginConnector]: Invalid model from TraceAbstraction for observer de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction.TraceAbstractionObserver@324cfd7a and model type de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction AST 20.02 05:59:57, skipping insertion in model container [2022-02-20 17:59:57,151 INFO L185 PluginConnector]: Executing the observer TraceAbstractionObserver from plugin TraceAbstraction for "de.uni_freiburg.informatik.ultimate.plugins.generator.rcfgbuilder CFG 20.02 05:59:57" (3/3) ... [2022-02-20 17:59:57,151 INFO L111 eAbstractionObserver]: Analyzing ICFG email_spec4_product33.cil.c [2022-02-20 17:59:57,154 INFO L205 ceAbstractionStarter]: Automizer settings: Hoare:true NWA Interpolation:FPandBP Determinization: PREDICATE_ABSTRACTION [2022-02-20 17:59:57,155 INFO L164 ceAbstractionStarter]: Applying trace abstraction to program that has 1 error locations. [2022-02-20 17:59:57,184 INFO L338 AbstractCegarLoop]: ======== Iteration 0 == of CEGAR loop == AllErrorsAtOnce ======== [2022-02-20 17:59:57,189 INFO L339 AbstractCegarLoop]: Settings: SEPARATE_VIOLATION_CHECK=true, mInterprocedural=true, mMaxIterations=1000000, mWatchIteration=1000000, mArtifact=RCFG, mInterpolation=FPandBP, mInterpolantAutomaton=STRAIGHT_LINE, mDumpAutomata=false, mAutomataFormat=ATS_NUMERATE, mDumpPath=., mDeterminiation=PREDICATE_ABSTRACTION, mMinimize=MINIMIZE_SEVPA, mHoare=true, mAutomataTypeConcurrency=PETRI_NET, mHoareTripleChecks=INCREMENTAL, mHoareAnnotationPositions=LoopsAndPotentialCycles, mDumpOnlyReuseAutomata=false, mLimitTraceHistogram=0, mErrorLocTimeLimit=0, mLimitPathProgramCount=0, mCollectInterpolantStatistics=true, mHeuristicEmptinessCheck=false, mHeuristicEmptinessCheckAStarHeuristic=ZERO, mHeuristicEmptinessCheckAStarHeuristicRandomSeed=1337, mHeuristicEmptinessCheckSmtFeatureScoringMethod=DAGSIZE, mSMTFeatureExtraction=false, mSMTFeatureExtractionDumpPath=., mOverrideInterpolantAutomaton=false, mMcrInterpolantMethod=WP, mLoopAccelerationTechnique=FAST_UPR [2022-02-20 17:59:57,189 INFO L340 AbstractCegarLoop]: Starting to check reachability of 1 error locations. [2022-02-20 17:59:57,211 INFO L276 IsEmpty]: Start isEmpty. Operand has 388 states, 299 states have (on average 1.5016722408026757) internal successors, (449), 303 states have internal predecessors, (449), 63 states have call successors, (63), 24 states have call predecessors, (63), 24 states have return successors, (63), 63 states have call predecessors, (63), 63 states have call successors, (63) [2022-02-20 17:59:57,223 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 108 [2022-02-20 17:59:57,223 INFO L506 BasicCegarLoop]: Found error trace [2022-02-20 17:59:57,224 INFO L514 BasicCegarLoop]: trace histogram [3, 3, 3, 3, 3, 3, 2, 2, 2, 2, 2, 2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-02-20 17:59:57,224 INFO L402 AbstractCegarLoop]: === Iteration 1 === Targeting outgoingErr0ASSERT_VIOLATIONERROR_FUNCTION === [outgoingErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2022-02-20 17:59:57,228 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2022-02-20 17:59:57,228 INFO L85 PathProgramCache]: Analyzing trace with hash 1753391489, now seen corresponding path program 1 times [2022-02-20 17:59:57,235 INFO L126 FreeRefinementEngine]: Executing refinement strategy CAMEL [2022-02-20 17:59:57,235 INFO L338 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [449622] [2022-02-20 17:59:57,235 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-02-20 17:59:57,236 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2022-02-20 17:59:57,389 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-02-20 17:59:57,507 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 6 [2022-02-20 17:59:57,515 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-02-20 17:59:57,533 INFO L290 TraceCheckUtils]: 0: Hoare triple {451#(and (= |old(~__ste_client_idCounter0~0)| ~__ste_client_idCounter0~0) (= |old(~__ste_client_idCounter1~0)| ~__ste_client_idCounter1~0) (= |old(~__ste_client_idCounter2~0)| ~__ste_client_idCounter2~0))} ~handle := #in~handle;~value := #in~value; {391#true} is VALID [2022-02-20 17:59:57,535 INFO L290 TraceCheckUtils]: 1: Hoare triple {391#true} assume 1 == ~handle;~__ste_client_idCounter0~0 := ~value; {391#true} is VALID [2022-02-20 17:59:57,535 INFO L290 TraceCheckUtils]: 2: Hoare triple {391#true} assume true; {391#true} is VALID [2022-02-20 17:59:57,535 INFO L284 TraceCheckUtils]: 3: Hoare quadruple {391#true} {391#true} #1134#return; {391#true} is VALID [2022-02-20 17:59:57,541 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 12 [2022-02-20 17:59:57,545 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-02-20 17:59:57,549 INFO L290 TraceCheckUtils]: 0: Hoare triple {452#(and (= ~__ste_client_privateKey0~0 |old(~__ste_client_privateKey0~0)|) (= ~__ste_client_privateKey2~0 |old(~__ste_client_privateKey2~0)|) (= ~__ste_client_privateKey1~0 |old(~__ste_client_privateKey1~0)|))} ~handle := #in~handle;~value := #in~value; {391#true} is VALID [2022-02-20 17:59:57,550 INFO L290 TraceCheckUtils]: 1: Hoare triple {391#true} assume 1 == ~handle;~__ste_client_privateKey0~0 := ~value; {391#true} is VALID [2022-02-20 17:59:57,550 INFO L290 TraceCheckUtils]: 2: Hoare triple {391#true} assume true; {391#true} is VALID [2022-02-20 17:59:57,550 INFO L284 TraceCheckUtils]: 3: Hoare quadruple {391#true} {391#true} #1136#return; {391#true} is VALID [2022-02-20 17:59:57,550 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 18 [2022-02-20 17:59:57,559 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-02-20 17:59:57,579 INFO L290 TraceCheckUtils]: 0: Hoare triple {451#(and (= |old(~__ste_client_idCounter0~0)| ~__ste_client_idCounter0~0) (= |old(~__ste_client_idCounter1~0)| ~__ste_client_idCounter1~0) (= |old(~__ste_client_idCounter2~0)| ~__ste_client_idCounter2~0))} ~handle := #in~handle;~value := #in~value; {453#(= setClientId_~handle |setClientId_#in~handle|)} is VALID [2022-02-20 17:59:57,580 INFO L290 TraceCheckUtils]: 1: Hoare triple {453#(= setClientId_~handle |setClientId_#in~handle|)} assume 1 == ~handle;~__ste_client_idCounter0~0 := ~value; {454#(= |setClientId_#in~handle| 1)} is VALID [2022-02-20 17:59:57,581 INFO L290 TraceCheckUtils]: 2: Hoare triple {454#(= |setClientId_#in~handle| 1)} assume true; {454#(= |setClientId_#in~handle| 1)} is VALID [2022-02-20 17:59:57,581 INFO L284 TraceCheckUtils]: 3: Hoare quadruple {454#(= |setClientId_#in~handle| 1)} {401#(= |ULTIMATE.start_setup_rjh__wrappee__Base_~rjh___0#1| 2)} #1138#return; {392#false} is VALID [2022-02-20 17:59:57,582 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 24 [2022-02-20 17:59:57,584 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-02-20 17:59:57,590 INFO L290 TraceCheckUtils]: 0: Hoare triple {452#(and (= ~__ste_client_privateKey0~0 |old(~__ste_client_privateKey0~0)|) (= ~__ste_client_privateKey2~0 |old(~__ste_client_privateKey2~0)|) (= ~__ste_client_privateKey1~0 |old(~__ste_client_privateKey1~0)|))} ~handle := #in~handle;~value := #in~value; {391#true} is VALID [2022-02-20 17:59:57,590 INFO L290 TraceCheckUtils]: 1: Hoare triple {391#true} assume 1 == ~handle;~__ste_client_privateKey0~0 := ~value; {391#true} is VALID [2022-02-20 17:59:57,590 INFO L290 TraceCheckUtils]: 2: Hoare triple {391#true} assume true; {391#true} is VALID [2022-02-20 17:59:57,591 INFO L284 TraceCheckUtils]: 3: Hoare quadruple {391#true} {392#false} #1140#return; {392#false} is VALID [2022-02-20 17:59:57,591 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 30 [2022-02-20 17:59:57,595 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-02-20 17:59:57,606 INFO L290 TraceCheckUtils]: 0: Hoare triple {451#(and (= |old(~__ste_client_idCounter0~0)| ~__ste_client_idCounter0~0) (= |old(~__ste_client_idCounter1~0)| ~__ste_client_idCounter1~0) (= |old(~__ste_client_idCounter2~0)| ~__ste_client_idCounter2~0))} ~handle := #in~handle;~value := #in~value; {391#true} is VALID [2022-02-20 17:59:57,607 INFO L290 TraceCheckUtils]: 1: Hoare triple {391#true} assume 1 == ~handle;~__ste_client_idCounter0~0 := ~value; {391#true} is VALID [2022-02-20 17:59:57,607 INFO L290 TraceCheckUtils]: 2: Hoare triple {391#true} assume true; {391#true} is VALID [2022-02-20 17:59:57,607 INFO L284 TraceCheckUtils]: 3: Hoare quadruple {391#true} {392#false} #1142#return; {392#false} is VALID [2022-02-20 17:59:57,608 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 36 [2022-02-20 17:59:57,611 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-02-20 17:59:57,615 INFO L290 TraceCheckUtils]: 0: Hoare triple {452#(and (= ~__ste_client_privateKey0~0 |old(~__ste_client_privateKey0~0)|) (= ~__ste_client_privateKey2~0 |old(~__ste_client_privateKey2~0)|) (= ~__ste_client_privateKey1~0 |old(~__ste_client_privateKey1~0)|))} ~handle := #in~handle;~value := #in~value; {391#true} is VALID [2022-02-20 17:59:57,615 INFO L290 TraceCheckUtils]: 1: Hoare triple {391#true} assume 1 == ~handle;~__ste_client_privateKey0~0 := ~value; {391#true} is VALID [2022-02-20 17:59:57,617 INFO L290 TraceCheckUtils]: 2: Hoare triple {391#true} assume true; {391#true} is VALID [2022-02-20 17:59:57,617 INFO L284 TraceCheckUtils]: 3: Hoare quadruple {391#true} {392#false} #1144#return; {392#false} is VALID [2022-02-20 17:59:57,627 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 47 [2022-02-20 17:59:57,629 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-02-20 17:59:57,635 INFO L290 TraceCheckUtils]: 0: Hoare triple {455#(and (= |old(~__ste_email_from0~0)| ~__ste_email_from0~0) (= |old(~__ste_email_from1~0)| ~__ste_email_from1~0))} ~handle := #in~handle;~value := #in~value; {391#true} is VALID [2022-02-20 17:59:57,635 INFO L290 TraceCheckUtils]: 1: Hoare triple {391#true} assume 1 == ~handle;~__ste_email_from0~0 := ~value; {391#true} is VALID [2022-02-20 17:59:57,636 INFO L290 TraceCheckUtils]: 2: Hoare triple {391#true} assume true; {391#true} is VALID [2022-02-20 17:59:57,636 INFO L284 TraceCheckUtils]: 3: Hoare quadruple {391#true} {392#false} #1120#return; {392#false} is VALID [2022-02-20 17:59:57,643 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 52 [2022-02-20 17:59:57,645 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-02-20 17:59:57,648 INFO L290 TraceCheckUtils]: 0: Hoare triple {456#(and (= ~__ste_email_to0~0 |old(~__ste_email_to0~0)|) (= ~__ste_email_to1~0 |old(~__ste_email_to1~0)|))} ~handle := #in~handle;~value := #in~value; {391#true} is VALID [2022-02-20 17:59:57,649 INFO L290 TraceCheckUtils]: 1: Hoare triple {391#true} assume 1 == ~handle;~__ste_email_to0~0 := ~value; {391#true} is VALID [2022-02-20 17:59:57,649 INFO L290 TraceCheckUtils]: 2: Hoare triple {391#true} assume true; {391#true} is VALID [2022-02-20 17:59:57,649 INFO L284 TraceCheckUtils]: 3: Hoare quadruple {391#true} {392#false} #1122#return; {392#false} is VALID [2022-02-20 17:59:57,649 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 61 [2022-02-20 17:59:57,653 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-02-20 17:59:57,656 INFO L290 TraceCheckUtils]: 0: Hoare triple {391#true} ~handle := #in~handle;havoc ~retValue_acc~20; {391#true} is VALID [2022-02-20 17:59:57,656 INFO L290 TraceCheckUtils]: 1: Hoare triple {391#true} assume 1 == ~handle;~retValue_acc~20 := ~__ste_client_privateKey0~0;#res := ~retValue_acc~20; {391#true} is VALID [2022-02-20 17:59:57,657 INFO L290 TraceCheckUtils]: 2: Hoare triple {391#true} assume true; {391#true} is VALID [2022-02-20 17:59:57,657 INFO L284 TraceCheckUtils]: 3: Hoare quadruple {391#true} {392#false} #1054#return; {392#false} is VALID [2022-02-20 17:59:57,657 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 69 [2022-02-20 17:59:57,659 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-02-20 17:59:57,662 INFO L290 TraceCheckUtils]: 0: Hoare triple {391#true} ~handle := #in~handle;havoc ~retValue_acc~36; {391#true} is VALID [2022-02-20 17:59:57,662 INFO L290 TraceCheckUtils]: 1: Hoare triple {391#true} assume 1 == ~handle;~retValue_acc~36 := ~__ste_email_to0~0;#res := ~retValue_acc~36; {391#true} is VALID [2022-02-20 17:59:57,663 INFO L290 TraceCheckUtils]: 2: Hoare triple {391#true} assume true; {391#true} is VALID [2022-02-20 17:59:57,663 INFO L284 TraceCheckUtils]: 3: Hoare quadruple {391#true} {392#false} #1056#return; {392#false} is VALID [2022-02-20 17:59:57,663 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 75 [2022-02-20 17:59:57,666 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-02-20 17:59:57,672 INFO L290 TraceCheckUtils]: 0: Hoare triple {391#true} ~handle := #in~handle;~userid := #in~userid;havoc ~retValue_acc~25; {391#true} is VALID [2022-02-20 17:59:57,673 INFO L290 TraceCheckUtils]: 1: Hoare triple {391#true} assume 1 == ~handle; {391#true} is VALID [2022-02-20 17:59:57,673 INFO L290 TraceCheckUtils]: 2: Hoare triple {391#true} assume ~userid == ~__ste_Client_Keyring0_User0~0;~retValue_acc~25 := ~__ste_Client_Keyring0_PublicKey0~0;#res := ~retValue_acc~25; {391#true} is VALID [2022-02-20 17:59:57,673 INFO L290 TraceCheckUtils]: 3: Hoare triple {391#true} assume true; {391#true} is VALID [2022-02-20 17:59:57,673 INFO L284 TraceCheckUtils]: 4: Hoare quadruple {391#true} {392#false} #1058#return; {392#false} is VALID [2022-02-20 17:59:57,674 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 86 [2022-02-20 17:59:57,675 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-02-20 17:59:57,681 INFO L290 TraceCheckUtils]: 0: Hoare triple {455#(and (= |old(~__ste_email_from0~0)| ~__ste_email_from0~0) (= |old(~__ste_email_from1~0)| ~__ste_email_from1~0))} ~handle := #in~handle;~value := #in~value; {391#true} is VALID [2022-02-20 17:59:57,681 INFO L290 TraceCheckUtils]: 1: Hoare triple {391#true} assume 1 == ~handle;~__ste_email_from0~0 := ~value; {391#true} is VALID [2022-02-20 17:59:57,684 INFO L290 TraceCheckUtils]: 2: Hoare triple {391#true} assume true; {391#true} is VALID [2022-02-20 17:59:57,684 INFO L284 TraceCheckUtils]: 3: Hoare quadruple {391#true} {392#false} #1064#return; {392#false} is VALID [2022-02-20 17:59:57,684 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 92 [2022-02-20 17:59:57,688 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-02-20 17:59:57,695 INFO L290 TraceCheckUtils]: 0: Hoare triple {391#true} ~handle := #in~handle;havoc ~retValue_acc~41; {391#true} is VALID [2022-02-20 17:59:57,695 INFO L290 TraceCheckUtils]: 1: Hoare triple {391#true} assume 1 == ~handle;~retValue_acc~41 := ~__ste_email_isSigned0~0;#res := ~retValue_acc~41; {391#true} is VALID [2022-02-20 17:59:57,696 INFO L290 TraceCheckUtils]: 2: Hoare triple {391#true} assume true; {391#true} is VALID [2022-02-20 17:59:57,696 INFO L284 TraceCheckUtils]: 3: Hoare quadruple {391#true} {392#false} #1066#return; {392#false} is VALID [2022-02-20 17:59:57,696 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 99 [2022-02-20 17:59:57,699 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-02-20 17:59:57,704 INFO L290 TraceCheckUtils]: 0: Hoare triple {391#true} ~handle := #in~handle;havoc ~retValue_acc~20; {391#true} is VALID [2022-02-20 17:59:57,705 INFO L290 TraceCheckUtils]: 1: Hoare triple {391#true} assume 1 == ~handle;~retValue_acc~20 := ~__ste_client_privateKey0~0;#res := ~retValue_acc~20; {391#true} is VALID [2022-02-20 17:59:57,705 INFO L290 TraceCheckUtils]: 2: Hoare triple {391#true} assume true; {391#true} is VALID [2022-02-20 17:59:57,705 INFO L284 TraceCheckUtils]: 3: Hoare quadruple {391#true} {392#false} #1068#return; {392#false} is VALID [2022-02-20 17:59:57,706 INFO L290 TraceCheckUtils]: 0: Hoare triple {391#true} assume { :begin_inline_ULTIMATE.init } true;#NULL.base, #NULL.offset := 0, 0;assume 0 == #valid[0];assume 0 < #StackHeapBarrier;call #Ultimate.allocInit(2, 1);call write~init~int(48, 1, 0, 1);call write~init~int(0, 1, 1, 1);call #Ultimate.allocInit(28, 2);call #Ultimate.allocInit(12, 3);call #Ultimate.allocInit(30, 4);call #Ultimate.allocInit(9, 5);call #Ultimate.allocInit(21, 6);call #Ultimate.allocInit(30, 7);call #Ultimate.allocInit(9, 8);call #Ultimate.allocInit(21, 9);call #Ultimate.allocInit(30, 10);call #Ultimate.allocInit(9, 11);call #Ultimate.allocInit(25, 12);call #Ultimate.allocInit(30, 13);call #Ultimate.allocInit(9, 14);call #Ultimate.allocInit(25, 15);call #Ultimate.allocInit(44, 16);call #Ultimate.allocInit(44, 17);call #Ultimate.allocInit(9, 18);call #Ultimate.allocInit(9, 19);call #Ultimate.allocInit(11, 20);call #Ultimate.allocInit(19, 21);call #Ultimate.allocInit(4, 22);call write~init~int(37, 22, 0, 1);call write~init~int(100, 22, 1, 1);call write~init~int(10, 22, 2, 1);call write~init~int(0, 22, 3, 1);call #Ultimate.allocInit(4, 23);call write~init~int(37, 23, 0, 1);call write~init~int(100, 23, 1, 1);call write~init~int(10, 23, 2, 1);call write~init~int(0, 23, 3, 1);call #Ultimate.allocInit(10, 24);call #Ultimate.allocInit(16, 25);call #Ultimate.allocInit(20, 26);call #Ultimate.allocInit(22, 27);call #Ultimate.allocInit(21, 28);call #Ultimate.allocInit(10, 29);call #Ultimate.allocInit(12, 30);call #Ultimate.allocInit(10, 31);call #Ultimate.allocInit(18, 32);call #Ultimate.allocInit(16, 33);call #Ultimate.allocInit(21, 34);call #Ultimate.allocInit(13, 35);call #Ultimate.allocInit(16, 36);call #Ultimate.allocInit(25, 37);call #Ultimate.allocInit(4, 38);call write~init~int(37, 38, 0, 1);call write~init~int(115, 38, 1, 1);call write~init~int(10, 38, 2, 1);call write~init~int(0, 38, 3, 1);call #Ultimate.allocInit(13, 39);~head~0.base, ~head~0.offset := 0, 0;~__SELECTED_FEATURE_Base~0 := 0;~__SELECTED_FEATURE_Keys~0 := 0;~__SELECTED_FEATURE_Encrypt~0 := 0;~__SELECTED_FEATURE_AutoResponder~0 := 0;~__SELECTED_FEATURE_AddressBook~0 := 0;~__SELECTED_FEATURE_Sign~0 := 0;~__SELECTED_FEATURE_Forward~0 := 0;~__SELECTED_FEATURE_Verify~0 := 0;~__SELECTED_FEATURE_Decrypt~0 := 0;~__GUIDSL_ROOT_PRODUCTION~0 := 0;~__GUIDSL_NON_TERMINAL_main~0 := 0;~bob~0 := 0;~rjh~0 := 0;~chuck~0 := 0;~queue_empty~0 := 1;~queued_message~0 := 0;~queued_client~0 := 0;~__ste_Client_counter~0 := 0;~__ste_client_name0~0.base, ~__ste_client_name0~0.offset := 0, 0;~__ste_client_name1~0.base, ~__ste_client_name1~0.offset := 0, 0;~__ste_client_name2~0.base, ~__ste_client_name2~0.offset := 0, 0;~__ste_client_outbuffer0~0 := 0;~__ste_client_outbuffer1~0 := 0;~__ste_client_outbuffer2~0 := 0;~__ste_client_outbuffer3~0 := 0;~__ste_ClientAddressBook_size0~0 := 0;~__ste_ClientAddressBook_size1~0 := 0;~__ste_ClientAddressBook_size2~0 := 0;~__ste_Client_AddressBook0_Alias0~0 := 0;~__ste_Client_AddressBook0_Alias1~0 := 0;~__ste_Client_AddressBook0_Alias2~0 := 0;~__ste_Client_AddressBook1_Alias0~0 := 0;~__ste_Client_AddressBook1_Alias1~0 := 0;~__ste_Client_AddressBook1_Alias2~0 := 0;~__ste_Client_AddressBook2_Alias0~0 := 0;~__ste_Client_AddressBook2_Alias1~0 := 0;~__ste_Client_AddressBook2_Alias2~0 := 0;~__ste_Client_AddressBook0_Address0~0 := 0;~__ste_Client_AddressBook0_Address1~0 := 0;~__ste_Client_AddressBook0_Address2~0 := 0;~__ste_Client_AddressBook1_Address0~0 := 0;~__ste_Client_AddressBook1_Address1~0 := 0;~__ste_Client_AddressBook1_Address2~0 := 0;~__ste_Client_AddressBook2_Address0~0 := 0;~__ste_Client_AddressBook2_Address1~0 := 0;~__ste_Client_AddressBook2_Address2~0 := 0;~__ste_client_autoResponse0~0 := 0;~__ste_client_autoResponse1~0 := 0;~__ste_client_autoResponse2~0 := 0;~__ste_client_privateKey0~0 := 0;~__ste_client_privateKey1~0 := 0;~__ste_client_privateKey2~0 := 0;~__ste_ClientKeyring_size0~0 := 0;~__ste_ClientKeyring_size1~0 := 0;~__ste_ClientKeyring_size2~0 := 0;~__ste_Client_Keyring0_User0~0 := 0;~__ste_Client_Keyring0_User1~0 := 0;~__ste_Client_Keyring0_User2~0 := 0;~__ste_Client_Keyring1_User0~0 := 0;~__ste_Client_Keyring1_User1~0 := 0;~__ste_Client_Keyring1_User2~0 := 0;~__ste_Client_Keyring2_User0~0 := 0;~__ste_Client_Keyring2_User1~0 := 0;~__ste_Client_Keyring2_User2~0 := 0;~__ste_Client_Keyring0_PublicKey0~0 := 0;~__ste_Client_Keyring0_PublicKey1~0 := 0;~__ste_Client_Keyring0_PublicKey2~0 := 0;~__ste_Client_Keyring1_PublicKey0~0 := 0;~__ste_Client_Keyring1_PublicKey1~0 := 0;~__ste_Client_Keyring1_PublicKey2~0 := 0;~__ste_Client_Keyring2_PublicKey0~0 := 0;~__ste_Client_Keyring2_PublicKey1~0 := 0;~__ste_Client_Keyring2_PublicKey2~0 := 0;~__ste_client_forwardReceiver0~0 := 0;~__ste_client_forwardReceiver1~0 := 0;~__ste_client_forwardReceiver2~0 := 0;~__ste_client_forwardReceiver3~0 := 0;~__ste_client_idCounter0~0 := 0;~__ste_client_idCounter1~0 := 0;~__ste_client_idCounter2~0 := 0;~__ste_Email_counter~0 := 0;~__ste_email_id0~0 := 0;~__ste_email_id1~0 := 0;~__ste_email_from0~0 := 0;~__ste_email_from1~0 := 0;~__ste_email_to0~0 := 0;~__ste_email_to1~0 := 0;~__ste_email_subject0~0.base, ~__ste_email_subject0~0.offset := 0, 0;~__ste_email_subject1~0.base, ~__ste_email_subject1~0.offset := 0, 0;~__ste_email_body0~0.base, ~__ste_email_body0~0.offset := 0, 0;~__ste_email_body1~0.base, ~__ste_email_body1~0.offset := 0, 0;~__ste_email_isEncrypted0~0 := 0;~__ste_email_isEncrypted1~0 := 0;~__ste_email_encryptionKey0~0 := 0;~__ste_email_encryptionKey1~0 := 0;~__ste_email_isSigned0~0 := 0;~__ste_email_isSigned1~0 := 0;~__ste_email_signKey0~0 := 0;~__ste_email_signKey1~0 := 0;~__ste_email_isSignatureVerified0~0 := 0;~__ste_email_isSignatureVerified1~0 := 0; {391#true} is VALID [2022-02-20 17:59:57,711 INFO L290 TraceCheckUtils]: 1: Hoare triple {391#true} assume { :end_inline_ULTIMATE.init } true;assume { :begin_inline_main } true;havoc main_#res#1;havoc main_#t~ret35#1, main_~retValue_acc~3#1, main_~tmp~4#1;havoc main_~retValue_acc~3#1;havoc main_~tmp~4#1;assume { :begin_inline_select_helpers } true; {391#true} is VALID [2022-02-20 17:59:57,711 INFO L290 TraceCheckUtils]: 2: Hoare triple {391#true} assume { :end_inline_select_helpers } true;assume { :begin_inline_select_features } true; {391#true} is VALID [2022-02-20 17:59:57,712 INFO L290 TraceCheckUtils]: 3: Hoare triple {391#true} assume { :end_inline_select_features } true;assume { :begin_inline_valid_product } true;havoc valid_product_#res#1;havoc valid_product_~retValue_acc~5#1;havoc valid_product_~retValue_acc~5#1;valid_product_~retValue_acc~5#1 := 1;valid_product_#res#1 := valid_product_~retValue_acc~5#1; {391#true} is VALID [2022-02-20 17:59:57,712 INFO L290 TraceCheckUtils]: 4: Hoare triple {391#true} main_#t~ret35#1 := valid_product_#res#1;assume { :end_inline_valid_product } true;assume -2147483648 <= main_#t~ret35#1 && main_#t~ret35#1 <= 2147483647;main_~tmp~4#1 := main_#t~ret35#1;havoc main_#t~ret35#1; {391#true} is VALID [2022-02-20 17:59:57,712 INFO L290 TraceCheckUtils]: 5: Hoare triple {391#true} assume 0 != main_~tmp~4#1;assume { :begin_inline_setup } true;havoc setup_#t~nondet32#1, setup_#t~nondet33#1, setup_#t~nondet34#1, setup_~__cil_tmp1~0#1.base, setup_~__cil_tmp1~0#1.offset, setup_~__cil_tmp2~0#1.base, setup_~__cil_tmp2~0#1.offset, setup_~__cil_tmp3~0#1.base, setup_~__cil_tmp3~0#1.offset;havoc setup_~__cil_tmp1~0#1.base, setup_~__cil_tmp1~0#1.offset;havoc setup_~__cil_tmp2~0#1.base, setup_~__cil_tmp2~0#1.offset;havoc setup_~__cil_tmp3~0#1.base, setup_~__cil_tmp3~0#1.offset;~bob~0 := 1;assume { :begin_inline_setup_bob } true;setup_bob_#in~bob___0#1 := ~bob~0;havoc setup_bob_~bob___0#1;setup_bob_~bob___0#1 := setup_bob_#in~bob___0#1;assume { :begin_inline_setup_bob__wrappee__Base } true;setup_bob__wrappee__Base_#in~bob___0#1 := setup_bob_~bob___0#1;havoc setup_bob__wrappee__Base_~bob___0#1;setup_bob__wrappee__Base_~bob___0#1 := setup_bob__wrappee__Base_#in~bob___0#1; {391#true} is VALID [2022-02-20 17:59:57,715 INFO L272 TraceCheckUtils]: 6: Hoare triple {391#true} call setClientId(setup_bob__wrappee__Base_~bob___0#1, setup_bob__wrappee__Base_~bob___0#1); {451#(and (= |old(~__ste_client_idCounter0~0)| ~__ste_client_idCounter0~0) (= |old(~__ste_client_idCounter1~0)| ~__ste_client_idCounter1~0) (= |old(~__ste_client_idCounter2~0)| ~__ste_client_idCounter2~0))} is VALID [2022-02-20 17:59:57,716 INFO L290 TraceCheckUtils]: 7: Hoare triple {451#(and (= |old(~__ste_client_idCounter0~0)| ~__ste_client_idCounter0~0) (= |old(~__ste_client_idCounter1~0)| ~__ste_client_idCounter1~0) (= |old(~__ste_client_idCounter2~0)| ~__ste_client_idCounter2~0))} ~handle := #in~handle;~value := #in~value; {391#true} is VALID [2022-02-20 17:59:57,716 INFO L290 TraceCheckUtils]: 8: Hoare triple {391#true} assume 1 == ~handle;~__ste_client_idCounter0~0 := ~value; {391#true} is VALID [2022-02-20 17:59:57,716 INFO L290 TraceCheckUtils]: 9: Hoare triple {391#true} assume true; {391#true} is VALID [2022-02-20 17:59:57,716 INFO L284 TraceCheckUtils]: 10: Hoare quadruple {391#true} {391#true} #1134#return; {391#true} is VALID [2022-02-20 17:59:57,716 INFO L290 TraceCheckUtils]: 11: Hoare triple {391#true} assume { :end_inline_setup_bob__wrappee__Base } true; {391#true} is VALID [2022-02-20 17:59:57,717 INFO L272 TraceCheckUtils]: 12: Hoare triple {391#true} call setClientPrivateKey(setup_bob_~bob___0#1, 123); {452#(and (= ~__ste_client_privateKey0~0 |old(~__ste_client_privateKey0~0)|) (= ~__ste_client_privateKey2~0 |old(~__ste_client_privateKey2~0)|) (= ~__ste_client_privateKey1~0 |old(~__ste_client_privateKey1~0)|))} is VALID [2022-02-20 17:59:57,718 INFO L290 TraceCheckUtils]: 13: Hoare triple {452#(and (= ~__ste_client_privateKey0~0 |old(~__ste_client_privateKey0~0)|) (= ~__ste_client_privateKey2~0 |old(~__ste_client_privateKey2~0)|) (= ~__ste_client_privateKey1~0 |old(~__ste_client_privateKey1~0)|))} ~handle := #in~handle;~value := #in~value; {391#true} is VALID [2022-02-20 17:59:57,718 INFO L290 TraceCheckUtils]: 14: Hoare triple {391#true} assume 1 == ~handle;~__ste_client_privateKey0~0 := ~value; {391#true} is VALID [2022-02-20 17:59:57,718 INFO L290 TraceCheckUtils]: 15: Hoare triple {391#true} assume true; {391#true} is VALID [2022-02-20 17:59:57,718 INFO L284 TraceCheckUtils]: 16: Hoare quadruple {391#true} {391#true} #1136#return; {391#true} is VALID [2022-02-20 17:59:57,719 INFO L290 TraceCheckUtils]: 17: Hoare triple {391#true} assume { :end_inline_setup_bob } true;setup_~__cil_tmp1~0#1.base, setup_~__cil_tmp1~0#1.offset := 18, 0;havoc setup_#t~nondet32#1;~rjh~0 := 2;assume { :begin_inline_setup_rjh } true;setup_rjh_#in~rjh___0#1 := ~rjh~0;havoc setup_rjh_~rjh___0#1;setup_rjh_~rjh___0#1 := setup_rjh_#in~rjh___0#1;assume { :begin_inline_setup_rjh__wrappee__Base } true;setup_rjh__wrappee__Base_#in~rjh___0#1 := setup_rjh_~rjh___0#1;havoc setup_rjh__wrappee__Base_~rjh___0#1;setup_rjh__wrappee__Base_~rjh___0#1 := setup_rjh__wrappee__Base_#in~rjh___0#1; {401#(= |ULTIMATE.start_setup_rjh__wrappee__Base_~rjh___0#1| 2)} is VALID [2022-02-20 17:59:57,720 INFO L272 TraceCheckUtils]: 18: Hoare triple {401#(= |ULTIMATE.start_setup_rjh__wrappee__Base_~rjh___0#1| 2)} call setClientId(setup_rjh__wrappee__Base_~rjh___0#1, setup_rjh__wrappee__Base_~rjh___0#1); {451#(and (= |old(~__ste_client_idCounter0~0)| ~__ste_client_idCounter0~0) (= |old(~__ste_client_idCounter1~0)| ~__ste_client_idCounter1~0) (= |old(~__ste_client_idCounter2~0)| ~__ste_client_idCounter2~0))} is VALID [2022-02-20 17:59:57,722 INFO L290 TraceCheckUtils]: 19: Hoare triple {451#(and (= |old(~__ste_client_idCounter0~0)| ~__ste_client_idCounter0~0) (= |old(~__ste_client_idCounter1~0)| ~__ste_client_idCounter1~0) (= |old(~__ste_client_idCounter2~0)| ~__ste_client_idCounter2~0))} ~handle := #in~handle;~value := #in~value; {453#(= setClientId_~handle |setClientId_#in~handle|)} is VALID [2022-02-20 17:59:57,723 INFO L290 TraceCheckUtils]: 20: Hoare triple {453#(= setClientId_~handle |setClientId_#in~handle|)} assume 1 == ~handle;~__ste_client_idCounter0~0 := ~value; {454#(= |setClientId_#in~handle| 1)} is VALID [2022-02-20 17:59:57,723 INFO L290 TraceCheckUtils]: 21: Hoare triple {454#(= |setClientId_#in~handle| 1)} assume true; {454#(= |setClientId_#in~handle| 1)} is VALID [2022-02-20 17:59:57,725 INFO L284 TraceCheckUtils]: 22: Hoare quadruple {454#(= |setClientId_#in~handle| 1)} {401#(= |ULTIMATE.start_setup_rjh__wrappee__Base_~rjh___0#1| 2)} #1138#return; {392#false} is VALID [2022-02-20 17:59:57,725 INFO L290 TraceCheckUtils]: 23: Hoare triple {392#false} assume { :end_inline_setup_rjh__wrappee__Base } true; {392#false} is VALID [2022-02-20 17:59:57,725 INFO L272 TraceCheckUtils]: 24: Hoare triple {392#false} call setClientPrivateKey(setup_rjh_~rjh___0#1, 456); {452#(and (= ~__ste_client_privateKey0~0 |old(~__ste_client_privateKey0~0)|) (= ~__ste_client_privateKey2~0 |old(~__ste_client_privateKey2~0)|) (= ~__ste_client_privateKey1~0 |old(~__ste_client_privateKey1~0)|))} is VALID [2022-02-20 17:59:57,726 INFO L290 TraceCheckUtils]: 25: Hoare triple {452#(and (= ~__ste_client_privateKey0~0 |old(~__ste_client_privateKey0~0)|) (= ~__ste_client_privateKey2~0 |old(~__ste_client_privateKey2~0)|) (= ~__ste_client_privateKey1~0 |old(~__ste_client_privateKey1~0)|))} ~handle := #in~handle;~value := #in~value; {391#true} is VALID [2022-02-20 17:59:57,726 INFO L290 TraceCheckUtils]: 26: Hoare triple {391#true} assume 1 == ~handle;~__ste_client_privateKey0~0 := ~value; {391#true} is VALID [2022-02-20 17:59:57,726 INFO L290 TraceCheckUtils]: 27: Hoare triple {391#true} assume true; {391#true} is VALID [2022-02-20 17:59:57,727 INFO L284 TraceCheckUtils]: 28: Hoare quadruple {391#true} {392#false} #1140#return; {392#false} is VALID [2022-02-20 17:59:57,729 INFO L290 TraceCheckUtils]: 29: Hoare triple {392#false} assume { :end_inline_setup_rjh } true;setup_~__cil_tmp2~0#1.base, setup_~__cil_tmp2~0#1.offset := 19, 0;havoc setup_#t~nondet33#1;~chuck~0 := 3;assume { :begin_inline_setup_chuck } true;setup_chuck_#in~chuck___0#1 := ~chuck~0;havoc setup_chuck_~chuck___0#1;setup_chuck_~chuck___0#1 := setup_chuck_#in~chuck___0#1;assume { :begin_inline_setup_chuck__wrappee__Base } true;setup_chuck__wrappee__Base_#in~chuck___0#1 := setup_chuck_~chuck___0#1;havoc setup_chuck__wrappee__Base_~chuck___0#1;setup_chuck__wrappee__Base_~chuck___0#1 := setup_chuck__wrappee__Base_#in~chuck___0#1; {392#false} is VALID [2022-02-20 17:59:57,729 INFO L272 TraceCheckUtils]: 30: Hoare triple {392#false} call setClientId(setup_chuck__wrappee__Base_~chuck___0#1, setup_chuck__wrappee__Base_~chuck___0#1); {451#(and (= |old(~__ste_client_idCounter0~0)| ~__ste_client_idCounter0~0) (= |old(~__ste_client_idCounter1~0)| ~__ste_client_idCounter1~0) (= |old(~__ste_client_idCounter2~0)| ~__ste_client_idCounter2~0))} is VALID [2022-02-20 17:59:57,729 INFO L290 TraceCheckUtils]: 31: Hoare triple {451#(and (= |old(~__ste_client_idCounter0~0)| ~__ste_client_idCounter0~0) (= |old(~__ste_client_idCounter1~0)| ~__ste_client_idCounter1~0) (= |old(~__ste_client_idCounter2~0)| ~__ste_client_idCounter2~0))} ~handle := #in~handle;~value := #in~value; {391#true} is VALID [2022-02-20 17:59:57,729 INFO L290 TraceCheckUtils]: 32: Hoare triple {391#true} assume 1 == ~handle;~__ste_client_idCounter0~0 := ~value; {391#true} is VALID [2022-02-20 17:59:57,730 INFO L290 TraceCheckUtils]: 33: Hoare triple {391#true} assume true; {391#true} is VALID [2022-02-20 17:59:57,730 INFO L284 TraceCheckUtils]: 34: Hoare quadruple {391#true} {392#false} #1142#return; {392#false} is VALID [2022-02-20 17:59:57,730 INFO L290 TraceCheckUtils]: 35: Hoare triple {392#false} assume { :end_inline_setup_chuck__wrappee__Base } true; {392#false} is VALID [2022-02-20 17:59:57,730 INFO L272 TraceCheckUtils]: 36: Hoare triple {392#false} call setClientPrivateKey(setup_chuck_~chuck___0#1, 789); {452#(and (= ~__ste_client_privateKey0~0 |old(~__ste_client_privateKey0~0)|) (= ~__ste_client_privateKey2~0 |old(~__ste_client_privateKey2~0)|) (= ~__ste_client_privateKey1~0 |old(~__ste_client_privateKey1~0)|))} is VALID [2022-02-20 17:59:57,730 INFO L290 TraceCheckUtils]: 37: Hoare triple {452#(and (= ~__ste_client_privateKey0~0 |old(~__ste_client_privateKey0~0)|) (= ~__ste_client_privateKey2~0 |old(~__ste_client_privateKey2~0)|) (= ~__ste_client_privateKey1~0 |old(~__ste_client_privateKey1~0)|))} ~handle := #in~handle;~value := #in~value; {391#true} is VALID [2022-02-20 17:59:57,730 INFO L290 TraceCheckUtils]: 38: Hoare triple {391#true} assume 1 == ~handle;~__ste_client_privateKey0~0 := ~value; {391#true} is VALID [2022-02-20 17:59:57,731 INFO L290 TraceCheckUtils]: 39: Hoare triple {391#true} assume true; {391#true} is VALID [2022-02-20 17:59:57,731 INFO L284 TraceCheckUtils]: 40: Hoare quadruple {391#true} {392#false} #1144#return; {392#false} is VALID [2022-02-20 17:59:57,731 INFO L290 TraceCheckUtils]: 41: Hoare triple {392#false} assume { :end_inline_setup_chuck } true;setup_~__cil_tmp3~0#1.base, setup_~__cil_tmp3~0#1.offset := 20, 0;havoc setup_#t~nondet34#1; {392#false} is VALID [2022-02-20 17:59:57,732 INFO L290 TraceCheckUtils]: 42: Hoare triple {392#false} assume { :end_inline_setup } true;assume { :begin_inline_test } true;havoc test_#t~nondet47#1, test_#t~nondet48#1, test_#t~nondet49#1, test_#t~nondet50#1, test_#t~nondet51#1, test_#t~nondet52#1, test_#t~nondet53#1, test_#t~nondet54#1, test_#t~nondet55#1, test_#t~nondet56#1, test_#t~nondet57#1, test_~op1~0#1, test_~op2~0#1, test_~op3~0#1, test_~op4~0#1, test_~op5~0#1, test_~op6~0#1, test_~op7~0#1, test_~op8~0#1, test_~op9~0#1, test_~op10~0#1, test_~op11~0#1, test_~splverifierCounter~0#1, test_~tmp~6#1, test_~tmp___0~2#1, test_~tmp___1~1#1, test_~tmp___2~0#1, test_~tmp___3~0#1, test_~tmp___4~0#1, test_~tmp___5~0#1, test_~tmp___6~0#1, test_~tmp___7~0#1, test_~tmp___8~0#1, test_~tmp___9~0#1;havoc test_~op1~0#1;havoc test_~op2~0#1;havoc test_~op3~0#1;havoc test_~op4~0#1;havoc test_~op5~0#1;havoc test_~op6~0#1;havoc test_~op7~0#1;havoc test_~op8~0#1;havoc test_~op9~0#1;havoc test_~op10~0#1;havoc test_~op11~0#1;havoc test_~splverifierCounter~0#1;havoc test_~tmp~6#1;havoc test_~tmp___0~2#1;havoc test_~tmp___1~1#1;havoc test_~tmp___2~0#1;havoc test_~tmp___3~0#1;havoc test_~tmp___4~0#1;havoc test_~tmp___5~0#1;havoc test_~tmp___6~0#1;havoc test_~tmp___7~0#1;havoc test_~tmp___8~0#1;havoc test_~tmp___9~0#1;test_~op1~0#1 := 0;test_~op2~0#1 := 0;test_~op3~0#1 := 0;test_~op4~0#1 := 0;test_~op5~0#1 := 0;test_~op6~0#1 := 0;test_~op7~0#1 := 0;test_~op8~0#1 := 0;test_~op9~0#1 := 0;test_~op10~0#1 := 0;test_~op11~0#1 := 0;test_~splverifierCounter~0#1 := 0; {392#false} is VALID [2022-02-20 17:59:57,732 INFO L290 TraceCheckUtils]: 43: Hoare triple {392#false} assume !true; {392#false} is VALID [2022-02-20 17:59:57,734 INFO L290 TraceCheckUtils]: 44: Hoare triple {392#false} assume { :begin_inline_bobToRjh } true;havoc bobToRjh_#t~ret27#1, bobToRjh_#t~ret28#1, bobToRjh_#t~ret29#1, bobToRjh_#t~ret30#1, bobToRjh_~tmp~3#1, bobToRjh_~tmp___0~0#1, bobToRjh_~tmp___1~0#1;havoc bobToRjh_~tmp~3#1;havoc bobToRjh_~tmp___0~0#1;havoc bobToRjh_~tmp___1~0#1;call bobToRjh_#t~ret27#1 := puts(16, 0);assume -2147483648 <= bobToRjh_#t~ret27#1 && bobToRjh_#t~ret27#1 <= 2147483647;havoc bobToRjh_#t~ret27#1; {392#false} is VALID [2022-02-20 17:59:57,734 INFO L272 TraceCheckUtils]: 45: Hoare triple {392#false} call sendEmail(~bob~0, ~rjh~0); {392#false} is VALID [2022-02-20 17:59:57,735 INFO L290 TraceCheckUtils]: 46: Hoare triple {392#false} ~sender#1 := #in~sender#1;~receiver#1 := #in~receiver#1;havoc ~email~0#1;havoc ~tmp~14#1;assume { :begin_inline_createEmail } true;createEmail_#in~from#1, createEmail_#in~to#1 := 0, ~receiver#1;havoc createEmail_#res#1;havoc createEmail_~from#1, createEmail_~to#1, createEmail_~retValue_acc~31#1, createEmail_~msg~0#1;createEmail_~from#1 := createEmail_#in~from#1;createEmail_~to#1 := createEmail_#in~to#1;havoc createEmail_~retValue_acc~31#1;havoc createEmail_~msg~0#1;createEmail_~msg~0#1 := 1; {392#false} is VALID [2022-02-20 17:59:57,735 INFO L272 TraceCheckUtils]: 47: Hoare triple {392#false} call setEmailFrom(createEmail_~msg~0#1, createEmail_~from#1); {455#(and (= |old(~__ste_email_from0~0)| ~__ste_email_from0~0) (= |old(~__ste_email_from1~0)| ~__ste_email_from1~0))} is VALID [2022-02-20 17:59:57,735 INFO L290 TraceCheckUtils]: 48: Hoare triple {455#(and (= |old(~__ste_email_from0~0)| ~__ste_email_from0~0) (= |old(~__ste_email_from1~0)| ~__ste_email_from1~0))} ~handle := #in~handle;~value := #in~value; {391#true} is VALID [2022-02-20 17:59:57,735 INFO L290 TraceCheckUtils]: 49: Hoare triple {391#true} assume 1 == ~handle;~__ste_email_from0~0 := ~value; {391#true} is VALID [2022-02-20 17:59:57,735 INFO L290 TraceCheckUtils]: 50: Hoare triple {391#true} assume true; {391#true} is VALID [2022-02-20 17:59:57,735 INFO L284 TraceCheckUtils]: 51: Hoare quadruple {391#true} {392#false} #1120#return; {392#false} is VALID [2022-02-20 17:59:57,736 INFO L272 TraceCheckUtils]: 52: Hoare triple {392#false} call setEmailTo(createEmail_~msg~0#1, createEmail_~to#1); {456#(and (= ~__ste_email_to0~0 |old(~__ste_email_to0~0)|) (= ~__ste_email_to1~0 |old(~__ste_email_to1~0)|))} is VALID [2022-02-20 17:59:57,736 INFO L290 TraceCheckUtils]: 53: Hoare triple {456#(and (= ~__ste_email_to0~0 |old(~__ste_email_to0~0)|) (= ~__ste_email_to1~0 |old(~__ste_email_to1~0)|))} ~handle := #in~handle;~value := #in~value; {391#true} is VALID [2022-02-20 17:59:57,736 INFO L290 TraceCheckUtils]: 54: Hoare triple {391#true} assume 1 == ~handle;~__ste_email_to0~0 := ~value; {391#true} is VALID [2022-02-20 17:59:57,736 INFO L290 TraceCheckUtils]: 55: Hoare triple {391#true} assume true; {391#true} is VALID [2022-02-20 17:59:57,736 INFO L284 TraceCheckUtils]: 56: Hoare quadruple {391#true} {392#false} #1122#return; {392#false} is VALID [2022-02-20 17:59:57,737 INFO L290 TraceCheckUtils]: 57: Hoare triple {392#false} createEmail_~retValue_acc~31#1 := createEmail_~msg~0#1;createEmail_#res#1 := createEmail_~retValue_acc~31#1; {392#false} is VALID [2022-02-20 17:59:57,738 INFO L290 TraceCheckUtils]: 58: Hoare triple {392#false} #t~ret72#1 := createEmail_#res#1;assume { :end_inline_createEmail } true;assume -2147483648 <= #t~ret72#1 && #t~ret72#1 <= 2147483647;~tmp~14#1 := #t~ret72#1;havoc #t~ret72#1;~email~0#1 := ~tmp~14#1; {392#false} is VALID [2022-02-20 17:59:57,738 INFO L272 TraceCheckUtils]: 59: Hoare triple {392#false} call outgoing(~sender#1, ~email~0#1); {392#false} is VALID [2022-02-20 17:59:57,739 INFO L290 TraceCheckUtils]: 60: Hoare triple {392#false} ~client#1 := #in~client#1;~msg#1 := #in~msg#1;assume { :begin_inline_sign } true;sign_#in~client#1, sign_#in~msg#1 := ~client#1, ~msg#1;havoc sign_#t~ret76#1, sign_~client#1, sign_~msg#1, sign_~privkey~1#1, sign_~tmp~16#1;sign_~client#1 := sign_#in~client#1;sign_~msg#1 := sign_#in~msg#1;havoc sign_~privkey~1#1;havoc sign_~tmp~16#1; {392#false} is VALID [2022-02-20 17:59:57,739 INFO L272 TraceCheckUtils]: 61: Hoare triple {392#false} call sign_#t~ret76#1 := getClientPrivateKey(sign_~client#1); {391#true} is VALID [2022-02-20 17:59:57,739 INFO L290 TraceCheckUtils]: 62: Hoare triple {391#true} ~handle := #in~handle;havoc ~retValue_acc~20; {391#true} is VALID [2022-02-20 17:59:57,739 INFO L290 TraceCheckUtils]: 63: Hoare triple {391#true} assume 1 == ~handle;~retValue_acc~20 := ~__ste_client_privateKey0~0;#res := ~retValue_acc~20; {391#true} is VALID [2022-02-20 17:59:57,739 INFO L290 TraceCheckUtils]: 64: Hoare triple {391#true} assume true; {391#true} is VALID [2022-02-20 17:59:57,740 INFO L284 TraceCheckUtils]: 65: Hoare quadruple {391#true} {392#false} #1054#return; {392#false} is VALID [2022-02-20 17:59:57,740 INFO L290 TraceCheckUtils]: 66: Hoare triple {392#false} assume -2147483648 <= sign_#t~ret76#1 && sign_#t~ret76#1 <= 2147483647;sign_~tmp~16#1 := sign_#t~ret76#1;havoc sign_#t~ret76#1;sign_~privkey~1#1 := sign_~tmp~16#1; {392#false} is VALID [2022-02-20 17:59:57,740 INFO L290 TraceCheckUtils]: 67: Hoare triple {392#false} assume 0 == sign_~privkey~1#1; {392#false} is VALID [2022-02-20 17:59:57,741 INFO L290 TraceCheckUtils]: 68: Hoare triple {392#false} assume { :end_inline_sign } true;assume { :begin_inline_outgoing__wrappee__AutoResponder } true;outgoing__wrappee__AutoResponder_#in~client#1, outgoing__wrappee__AutoResponder_#in~msg#1 := ~client#1, ~msg#1;havoc outgoing__wrappee__AutoResponder_#t~ret62#1, outgoing__wrappee__AutoResponder_#t~ret63#1, outgoing__wrappee__AutoResponder_~client#1, outgoing__wrappee__AutoResponder_~msg#1, outgoing__wrappee__AutoResponder_~receiver~0#1, outgoing__wrappee__AutoResponder_~tmp~9#1, outgoing__wrappee__AutoResponder_~pubkey~0#1, outgoing__wrappee__AutoResponder_~tmp___0~3#1;outgoing__wrappee__AutoResponder_~client#1 := outgoing__wrappee__AutoResponder_#in~client#1;outgoing__wrappee__AutoResponder_~msg#1 := outgoing__wrappee__AutoResponder_#in~msg#1;havoc outgoing__wrappee__AutoResponder_~receiver~0#1;havoc outgoing__wrappee__AutoResponder_~tmp~9#1;havoc outgoing__wrappee__AutoResponder_~pubkey~0#1;havoc outgoing__wrappee__AutoResponder_~tmp___0~3#1; {392#false} is VALID [2022-02-20 17:59:57,751 INFO L272 TraceCheckUtils]: 69: Hoare triple {392#false} call outgoing__wrappee__AutoResponder_#t~ret62#1 := getEmailTo(outgoing__wrappee__AutoResponder_~msg#1); {391#true} is VALID [2022-02-20 17:59:57,752 INFO L290 TraceCheckUtils]: 70: Hoare triple {391#true} ~handle := #in~handle;havoc ~retValue_acc~36; {391#true} is VALID [2022-02-20 17:59:57,752 INFO L290 TraceCheckUtils]: 71: Hoare triple {391#true} assume 1 == ~handle;~retValue_acc~36 := ~__ste_email_to0~0;#res := ~retValue_acc~36; {391#true} is VALID [2022-02-20 17:59:57,752 INFO L290 TraceCheckUtils]: 72: Hoare triple {391#true} assume true; {391#true} is VALID [2022-02-20 17:59:57,752 INFO L284 TraceCheckUtils]: 73: Hoare quadruple {391#true} {392#false} #1056#return; {392#false} is VALID [2022-02-20 17:59:57,752 INFO L290 TraceCheckUtils]: 74: Hoare triple {392#false} assume -2147483648 <= outgoing__wrappee__AutoResponder_#t~ret62#1 && outgoing__wrappee__AutoResponder_#t~ret62#1 <= 2147483647;outgoing__wrappee__AutoResponder_~tmp~9#1 := outgoing__wrappee__AutoResponder_#t~ret62#1;havoc outgoing__wrappee__AutoResponder_#t~ret62#1;outgoing__wrappee__AutoResponder_~receiver~0#1 := outgoing__wrappee__AutoResponder_~tmp~9#1; {392#false} is VALID [2022-02-20 17:59:57,753 INFO L272 TraceCheckUtils]: 75: Hoare triple {392#false} call outgoing__wrappee__AutoResponder_#t~ret63#1 := findPublicKey(outgoing__wrappee__AutoResponder_~client#1, outgoing__wrappee__AutoResponder_~receiver~0#1); {391#true} is VALID [2022-02-20 17:59:57,753 INFO L290 TraceCheckUtils]: 76: Hoare triple {391#true} ~handle := #in~handle;~userid := #in~userid;havoc ~retValue_acc~25; {391#true} is VALID [2022-02-20 17:59:57,753 INFO L290 TraceCheckUtils]: 77: Hoare triple {391#true} assume 1 == ~handle; {391#true} is VALID [2022-02-20 17:59:57,753 INFO L290 TraceCheckUtils]: 78: Hoare triple {391#true} assume ~userid == ~__ste_Client_Keyring0_User0~0;~retValue_acc~25 := ~__ste_Client_Keyring0_PublicKey0~0;#res := ~retValue_acc~25; {391#true} is VALID [2022-02-20 17:59:57,753 INFO L290 TraceCheckUtils]: 79: Hoare triple {391#true} assume true; {391#true} is VALID [2022-02-20 17:59:57,753 INFO L284 TraceCheckUtils]: 80: Hoare quadruple {391#true} {392#false} #1058#return; {392#false} is VALID [2022-02-20 17:59:57,754 INFO L290 TraceCheckUtils]: 81: Hoare triple {392#false} assume -2147483648 <= outgoing__wrappee__AutoResponder_#t~ret63#1 && outgoing__wrappee__AutoResponder_#t~ret63#1 <= 2147483647;outgoing__wrappee__AutoResponder_~tmp___0~3#1 := outgoing__wrappee__AutoResponder_#t~ret63#1;havoc outgoing__wrappee__AutoResponder_#t~ret63#1;outgoing__wrappee__AutoResponder_~pubkey~0#1 := outgoing__wrappee__AutoResponder_~tmp___0~3#1; {392#false} is VALID [2022-02-20 17:59:57,754 INFO L290 TraceCheckUtils]: 82: Hoare triple {392#false} assume !(0 != outgoing__wrappee__AutoResponder_~pubkey~0#1); {392#false} is VALID [2022-02-20 17:59:57,754 INFO L290 TraceCheckUtils]: 83: Hoare triple {392#false} assume { :begin_inline_outgoing__wrappee__Keys } true;outgoing__wrappee__Keys_#in~client#1, outgoing__wrappee__Keys_#in~msg#1 := outgoing__wrappee__AutoResponder_~client#1, outgoing__wrappee__AutoResponder_~msg#1;havoc outgoing__wrappee__Keys_#t~ret61#1, outgoing__wrappee__Keys_~client#1, outgoing__wrappee__Keys_~msg#1, outgoing__wrappee__Keys_~tmp~8#1;outgoing__wrappee__Keys_~client#1 := outgoing__wrappee__Keys_#in~client#1;outgoing__wrappee__Keys_~msg#1 := outgoing__wrappee__Keys_#in~msg#1;havoc outgoing__wrappee__Keys_~tmp~8#1;assume { :begin_inline_getClientId } true;getClientId_#in~handle#1 := outgoing__wrappee__Keys_~client#1;havoc getClientId_#res#1;havoc getClientId_~handle#1, getClientId_~retValue_acc~27#1;getClientId_~handle#1 := getClientId_#in~handle#1;havoc getClientId_~retValue_acc~27#1; {392#false} is VALID [2022-02-20 17:59:57,754 INFO L290 TraceCheckUtils]: 84: Hoare triple {392#false} assume 1 == getClientId_~handle#1;getClientId_~retValue_acc~27#1 := ~__ste_client_idCounter0~0;getClientId_#res#1 := getClientId_~retValue_acc~27#1; {392#false} is VALID [2022-02-20 17:59:57,754 INFO L290 TraceCheckUtils]: 85: Hoare triple {392#false} outgoing__wrappee__Keys_#t~ret61#1 := getClientId_#res#1;assume { :end_inline_getClientId } true;assume -2147483648 <= outgoing__wrappee__Keys_#t~ret61#1 && outgoing__wrappee__Keys_#t~ret61#1 <= 2147483647;outgoing__wrappee__Keys_~tmp~8#1 := outgoing__wrappee__Keys_#t~ret61#1;havoc outgoing__wrappee__Keys_#t~ret61#1; {392#false} is VALID [2022-02-20 17:59:57,754 INFO L272 TraceCheckUtils]: 86: Hoare triple {392#false} call setEmailFrom(outgoing__wrappee__Keys_~msg#1, outgoing__wrappee__Keys_~tmp~8#1); {455#(and (= |old(~__ste_email_from0~0)| ~__ste_email_from0~0) (= |old(~__ste_email_from1~0)| ~__ste_email_from1~0))} is VALID [2022-02-20 17:59:57,755 INFO L290 TraceCheckUtils]: 87: Hoare triple {455#(and (= |old(~__ste_email_from0~0)| ~__ste_email_from0~0) (= |old(~__ste_email_from1~0)| ~__ste_email_from1~0))} ~handle := #in~handle;~value := #in~value; {391#true} is VALID [2022-02-20 17:59:57,755 INFO L290 TraceCheckUtils]: 88: Hoare triple {391#true} assume 1 == ~handle;~__ste_email_from0~0 := ~value; {391#true} is VALID [2022-02-20 17:59:57,755 INFO L290 TraceCheckUtils]: 89: Hoare triple {391#true} assume true; {391#true} is VALID [2022-02-20 17:59:57,755 INFO L284 TraceCheckUtils]: 90: Hoare quadruple {391#true} {392#false} #1064#return; {392#false} is VALID [2022-02-20 17:59:57,755 INFO L290 TraceCheckUtils]: 91: Hoare triple {392#false} assume { :begin_inline_mail } true;mail_#in~client#1, mail_#in~msg#1 := outgoing__wrappee__Keys_~client#1, outgoing__wrappee__Keys_~msg#1;havoc mail_#t~ret59#1, mail_#t~ret60#1, mail_~client#1, mail_~msg#1, mail_~__utac__ad__arg1~0#1, mail_~__utac__ad__arg2~0#1, mail_~tmp~7#1;mail_~client#1 := mail_#in~client#1;mail_~msg#1 := mail_#in~msg#1;havoc mail_~__utac__ad__arg1~0#1;havoc mail_~__utac__ad__arg2~0#1;havoc mail_~tmp~7#1;mail_~__utac__ad__arg1~0#1 := mail_~client#1;mail_~__utac__ad__arg2~0#1 := mail_~msg#1;assume { :begin_inline___utac_acc__SignForward_spec__1 } true;__utac_acc__SignForward_spec__1_#in~client#1, __utac_acc__SignForward_spec__1_#in~msg#1 := mail_~__utac__ad__arg1~0#1, mail_~__utac__ad__arg2~0#1;havoc __utac_acc__SignForward_spec__1_#t~ret107#1, __utac_acc__SignForward_spec__1_#t~ret108#1, __utac_acc__SignForward_spec__1_#t~ret109#1, __utac_acc__SignForward_spec__1_~client#1, __utac_acc__SignForward_spec__1_~msg#1, __utac_acc__SignForward_spec__1_~tmp~25#1, __utac_acc__SignForward_spec__1_~tmp___0~9#1;__utac_acc__SignForward_spec__1_~client#1 := __utac_acc__SignForward_spec__1_#in~client#1;__utac_acc__SignForward_spec__1_~msg#1 := __utac_acc__SignForward_spec__1_#in~msg#1;havoc __utac_acc__SignForward_spec__1_~tmp~25#1;havoc __utac_acc__SignForward_spec__1_~tmp___0~9#1;call __utac_acc__SignForward_spec__1_#t~ret107#1 := puts(39, 0);assume -2147483648 <= __utac_acc__SignForward_spec__1_#t~ret107#1 && __utac_acc__SignForward_spec__1_#t~ret107#1 <= 2147483647;havoc __utac_acc__SignForward_spec__1_#t~ret107#1; {392#false} is VALID [2022-02-20 17:59:57,756 INFO L272 TraceCheckUtils]: 92: Hoare triple {392#false} call __utac_acc__SignForward_spec__1_#t~ret108#1 := isSigned(__utac_acc__SignForward_spec__1_~msg#1); {391#true} is VALID [2022-02-20 17:59:57,756 INFO L290 TraceCheckUtils]: 93: Hoare triple {391#true} ~handle := #in~handle;havoc ~retValue_acc~41; {391#true} is VALID [2022-02-20 17:59:57,756 INFO L290 TraceCheckUtils]: 94: Hoare triple {391#true} assume 1 == ~handle;~retValue_acc~41 := ~__ste_email_isSigned0~0;#res := ~retValue_acc~41; {391#true} is VALID [2022-02-20 17:59:57,756 INFO L290 TraceCheckUtils]: 95: Hoare triple {391#true} assume true; {391#true} is VALID [2022-02-20 17:59:57,756 INFO L284 TraceCheckUtils]: 96: Hoare quadruple {391#true} {392#false} #1066#return; {392#false} is VALID [2022-02-20 17:59:57,756 INFO L290 TraceCheckUtils]: 97: Hoare triple {392#false} assume -2147483648 <= __utac_acc__SignForward_spec__1_#t~ret108#1 && __utac_acc__SignForward_spec__1_#t~ret108#1 <= 2147483647;__utac_acc__SignForward_spec__1_~tmp___0~9#1 := __utac_acc__SignForward_spec__1_#t~ret108#1;havoc __utac_acc__SignForward_spec__1_#t~ret108#1; {392#false} is VALID [2022-02-20 17:59:57,757 INFO L290 TraceCheckUtils]: 98: Hoare triple {392#false} assume 0 != __utac_acc__SignForward_spec__1_~tmp___0~9#1; {392#false} is VALID [2022-02-20 17:59:57,780 INFO L272 TraceCheckUtils]: 99: Hoare triple {392#false} call __utac_acc__SignForward_spec__1_#t~ret109#1 := getClientPrivateKey(__utac_acc__SignForward_spec__1_~client#1); {391#true} is VALID [2022-02-20 17:59:57,780 INFO L290 TraceCheckUtils]: 100: Hoare triple {391#true} ~handle := #in~handle;havoc ~retValue_acc~20; {391#true} is VALID [2022-02-20 17:59:57,780 INFO L290 TraceCheckUtils]: 101: Hoare triple {391#true} assume 1 == ~handle;~retValue_acc~20 := ~__ste_client_privateKey0~0;#res := ~retValue_acc~20; {391#true} is VALID [2022-02-20 17:59:57,781 INFO L290 TraceCheckUtils]: 102: Hoare triple {391#true} assume true; {391#true} is VALID [2022-02-20 17:59:57,781 INFO L284 TraceCheckUtils]: 103: Hoare quadruple {391#true} {392#false} #1068#return; {392#false} is VALID [2022-02-20 17:59:57,781 INFO L290 TraceCheckUtils]: 104: Hoare triple {392#false} assume -2147483648 <= __utac_acc__SignForward_spec__1_#t~ret109#1 && __utac_acc__SignForward_spec__1_#t~ret109#1 <= 2147483647;__utac_acc__SignForward_spec__1_~tmp~25#1 := __utac_acc__SignForward_spec__1_#t~ret109#1;havoc __utac_acc__SignForward_spec__1_#t~ret109#1; {392#false} is VALID [2022-02-20 17:59:57,781 INFO L290 TraceCheckUtils]: 105: Hoare triple {392#false} assume 0 == __utac_acc__SignForward_spec__1_~tmp~25#1;assume { :begin_inline___automaton_fail } true; {392#false} is VALID [2022-02-20 17:59:57,781 INFO L290 TraceCheckUtils]: 106: Hoare triple {392#false} assume !false; {392#false} is VALID [2022-02-20 17:59:57,782 INFO L134 CoverageAnalysis]: Checked inductivity of 32 backedges. 3 proven. 3 refuted. 0 times theorem prover too weak. 26 trivial. 0 not checked. [2022-02-20 17:59:57,782 INFO L144 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2022-02-20 17:59:57,782 INFO L338 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [449622] [2022-02-20 17:59:57,783 INFO L165 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [449622] provided 0 perfect and 1 imperfect interpolant sequences [2022-02-20 17:59:57,783 INFO L338 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleZ3 [1361955889] [2022-02-20 17:59:57,783 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-02-20 17:59:57,783 INFO L173 SolverBuilder]: Constructing external solver with command: z3 -smt2 -in SMTLIB2_COMPLIANT=true [2022-02-20 17:59:57,783 INFO L189 MonitoredProcess]: No working directory specified, using /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 [2022-02-20 17:59:57,808 INFO L229 MonitoredProcess]: Starting monitored process 2 with /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 -smt2 -in SMTLIB2_COMPLIANT=true (exit command is (exit), workingDir is null) [2022-02-20 17:59:57,812 INFO L327 MonitoredProcess]: [MP /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 -smt2 -in SMTLIB2_COMPLIANT=true (2)] Waiting until timeout for monitored process [2022-02-20 17:59:58,041 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-02-20 17:59:58,046 INFO L263 TraceCheckSpWp]: Trace formula consists of 1065 conjuncts, 1 conjunts are in the unsatisfiable core [2022-02-20 17:59:58,094 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-02-20 17:59:58,100 INFO L286 TraceCheckSpWp]: Computing forward predicates... [2022-02-20 17:59:58,274 INFO L290 TraceCheckUtils]: 0: Hoare triple {391#true} assume { :begin_inline_ULTIMATE.init } true;#NULL.base, #NULL.offset := 0, 0;assume 0 == #valid[0];assume 0 < #StackHeapBarrier;call #Ultimate.allocInit(2, 1);call write~init~int(48, 1, 0, 1);call write~init~int(0, 1, 1, 1);call #Ultimate.allocInit(28, 2);call #Ultimate.allocInit(12, 3);call #Ultimate.allocInit(30, 4);call #Ultimate.allocInit(9, 5);call #Ultimate.allocInit(21, 6);call #Ultimate.allocInit(30, 7);call #Ultimate.allocInit(9, 8);call #Ultimate.allocInit(21, 9);call #Ultimate.allocInit(30, 10);call #Ultimate.allocInit(9, 11);call #Ultimate.allocInit(25, 12);call #Ultimate.allocInit(30, 13);call #Ultimate.allocInit(9, 14);call #Ultimate.allocInit(25, 15);call #Ultimate.allocInit(44, 16);call #Ultimate.allocInit(44, 17);call #Ultimate.allocInit(9, 18);call #Ultimate.allocInit(9, 19);call #Ultimate.allocInit(11, 20);call #Ultimate.allocInit(19, 21);call #Ultimate.allocInit(4, 22);call write~init~int(37, 22, 0, 1);call write~init~int(100, 22, 1, 1);call write~init~int(10, 22, 2, 1);call write~init~int(0, 22, 3, 1);call #Ultimate.allocInit(4, 23);call write~init~int(37, 23, 0, 1);call write~init~int(100, 23, 1, 1);call write~init~int(10, 23, 2, 1);call write~init~int(0, 23, 3, 1);call #Ultimate.allocInit(10, 24);call #Ultimate.allocInit(16, 25);call #Ultimate.allocInit(20, 26);call #Ultimate.allocInit(22, 27);call #Ultimate.allocInit(21, 28);call #Ultimate.allocInit(10, 29);call #Ultimate.allocInit(12, 30);call #Ultimate.allocInit(10, 31);call #Ultimate.allocInit(18, 32);call #Ultimate.allocInit(16, 33);call #Ultimate.allocInit(21, 34);call #Ultimate.allocInit(13, 35);call #Ultimate.allocInit(16, 36);call #Ultimate.allocInit(25, 37);call #Ultimate.allocInit(4, 38);call write~init~int(37, 38, 0, 1);call write~init~int(115, 38, 1, 1);call write~init~int(10, 38, 2, 1);call write~init~int(0, 38, 3, 1);call #Ultimate.allocInit(13, 39);~head~0.base, ~head~0.offset := 0, 0;~__SELECTED_FEATURE_Base~0 := 0;~__SELECTED_FEATURE_Keys~0 := 0;~__SELECTED_FEATURE_Encrypt~0 := 0;~__SELECTED_FEATURE_AutoResponder~0 := 0;~__SELECTED_FEATURE_AddressBook~0 := 0;~__SELECTED_FEATURE_Sign~0 := 0;~__SELECTED_FEATURE_Forward~0 := 0;~__SELECTED_FEATURE_Verify~0 := 0;~__SELECTED_FEATURE_Decrypt~0 := 0;~__GUIDSL_ROOT_PRODUCTION~0 := 0;~__GUIDSL_NON_TERMINAL_main~0 := 0;~bob~0 := 0;~rjh~0 := 0;~chuck~0 := 0;~queue_empty~0 := 1;~queued_message~0 := 0;~queued_client~0 := 0;~__ste_Client_counter~0 := 0;~__ste_client_name0~0.base, ~__ste_client_name0~0.offset := 0, 0;~__ste_client_name1~0.base, ~__ste_client_name1~0.offset := 0, 0;~__ste_client_name2~0.base, ~__ste_client_name2~0.offset := 0, 0;~__ste_client_outbuffer0~0 := 0;~__ste_client_outbuffer1~0 := 0;~__ste_client_outbuffer2~0 := 0;~__ste_client_outbuffer3~0 := 0;~__ste_ClientAddressBook_size0~0 := 0;~__ste_ClientAddressBook_size1~0 := 0;~__ste_ClientAddressBook_size2~0 := 0;~__ste_Client_AddressBook0_Alias0~0 := 0;~__ste_Client_AddressBook0_Alias1~0 := 0;~__ste_Client_AddressBook0_Alias2~0 := 0;~__ste_Client_AddressBook1_Alias0~0 := 0;~__ste_Client_AddressBook1_Alias1~0 := 0;~__ste_Client_AddressBook1_Alias2~0 := 0;~__ste_Client_AddressBook2_Alias0~0 := 0;~__ste_Client_AddressBook2_Alias1~0 := 0;~__ste_Client_AddressBook2_Alias2~0 := 0;~__ste_Client_AddressBook0_Address0~0 := 0;~__ste_Client_AddressBook0_Address1~0 := 0;~__ste_Client_AddressBook0_Address2~0 := 0;~__ste_Client_AddressBook1_Address0~0 := 0;~__ste_Client_AddressBook1_Address1~0 := 0;~__ste_Client_AddressBook1_Address2~0 := 0;~__ste_Client_AddressBook2_Address0~0 := 0;~__ste_Client_AddressBook2_Address1~0 := 0;~__ste_Client_AddressBook2_Address2~0 := 0;~__ste_client_autoResponse0~0 := 0;~__ste_client_autoResponse1~0 := 0;~__ste_client_autoResponse2~0 := 0;~__ste_client_privateKey0~0 := 0;~__ste_client_privateKey1~0 := 0;~__ste_client_privateKey2~0 := 0;~__ste_ClientKeyring_size0~0 := 0;~__ste_ClientKeyring_size1~0 := 0;~__ste_ClientKeyring_size2~0 := 0;~__ste_Client_Keyring0_User0~0 := 0;~__ste_Client_Keyring0_User1~0 := 0;~__ste_Client_Keyring0_User2~0 := 0;~__ste_Client_Keyring1_User0~0 := 0;~__ste_Client_Keyring1_User1~0 := 0;~__ste_Client_Keyring1_User2~0 := 0;~__ste_Client_Keyring2_User0~0 := 0;~__ste_Client_Keyring2_User1~0 := 0;~__ste_Client_Keyring2_User2~0 := 0;~__ste_Client_Keyring0_PublicKey0~0 := 0;~__ste_Client_Keyring0_PublicKey1~0 := 0;~__ste_Client_Keyring0_PublicKey2~0 := 0;~__ste_Client_Keyring1_PublicKey0~0 := 0;~__ste_Client_Keyring1_PublicKey1~0 := 0;~__ste_Client_Keyring1_PublicKey2~0 := 0;~__ste_Client_Keyring2_PublicKey0~0 := 0;~__ste_Client_Keyring2_PublicKey1~0 := 0;~__ste_Client_Keyring2_PublicKey2~0 := 0;~__ste_client_forwardReceiver0~0 := 0;~__ste_client_forwardReceiver1~0 := 0;~__ste_client_forwardReceiver2~0 := 0;~__ste_client_forwardReceiver3~0 := 0;~__ste_client_idCounter0~0 := 0;~__ste_client_idCounter1~0 := 0;~__ste_client_idCounter2~0 := 0;~__ste_Email_counter~0 := 0;~__ste_email_id0~0 := 0;~__ste_email_id1~0 := 0;~__ste_email_from0~0 := 0;~__ste_email_from1~0 := 0;~__ste_email_to0~0 := 0;~__ste_email_to1~0 := 0;~__ste_email_subject0~0.base, ~__ste_email_subject0~0.offset := 0, 0;~__ste_email_subject1~0.base, ~__ste_email_subject1~0.offset := 0, 0;~__ste_email_body0~0.base, ~__ste_email_body0~0.offset := 0, 0;~__ste_email_body1~0.base, ~__ste_email_body1~0.offset := 0, 0;~__ste_email_isEncrypted0~0 := 0;~__ste_email_isEncrypted1~0 := 0;~__ste_email_encryptionKey0~0 := 0;~__ste_email_encryptionKey1~0 := 0;~__ste_email_isSigned0~0 := 0;~__ste_email_isSigned1~0 := 0;~__ste_email_signKey0~0 := 0;~__ste_email_signKey1~0 := 0;~__ste_email_isSignatureVerified0~0 := 0;~__ste_email_isSignatureVerified1~0 := 0; {391#true} is VALID [2022-02-20 17:59:58,275 INFO L290 TraceCheckUtils]: 1: Hoare triple {391#true} assume { :end_inline_ULTIMATE.init } true;assume { :begin_inline_main } true;havoc main_#res#1;havoc main_#t~ret35#1, main_~retValue_acc~3#1, main_~tmp~4#1;havoc main_~retValue_acc~3#1;havoc main_~tmp~4#1;assume { :begin_inline_select_helpers } true; {391#true} is VALID [2022-02-20 17:59:58,275 INFO L290 TraceCheckUtils]: 2: Hoare triple {391#true} assume { :end_inline_select_helpers } true;assume { :begin_inline_select_features } true; {391#true} is VALID [2022-02-20 17:59:58,275 INFO L290 TraceCheckUtils]: 3: Hoare triple {391#true} assume { :end_inline_select_features } true;assume { :begin_inline_valid_product } true;havoc valid_product_#res#1;havoc valid_product_~retValue_acc~5#1;havoc valid_product_~retValue_acc~5#1;valid_product_~retValue_acc~5#1 := 1;valid_product_#res#1 := valid_product_~retValue_acc~5#1; {391#true} is VALID [2022-02-20 17:59:58,275 INFO L290 TraceCheckUtils]: 4: Hoare triple {391#true} main_#t~ret35#1 := valid_product_#res#1;assume { :end_inline_valid_product } true;assume -2147483648 <= main_#t~ret35#1 && main_#t~ret35#1 <= 2147483647;main_~tmp~4#1 := main_#t~ret35#1;havoc main_#t~ret35#1; {391#true} is VALID [2022-02-20 17:59:58,275 INFO L290 TraceCheckUtils]: 5: Hoare triple {391#true} assume 0 != main_~tmp~4#1;assume { :begin_inline_setup } true;havoc setup_#t~nondet32#1, setup_#t~nondet33#1, setup_#t~nondet34#1, setup_~__cil_tmp1~0#1.base, setup_~__cil_tmp1~0#1.offset, setup_~__cil_tmp2~0#1.base, setup_~__cil_tmp2~0#1.offset, setup_~__cil_tmp3~0#1.base, setup_~__cil_tmp3~0#1.offset;havoc setup_~__cil_tmp1~0#1.base, setup_~__cil_tmp1~0#1.offset;havoc setup_~__cil_tmp2~0#1.base, setup_~__cil_tmp2~0#1.offset;havoc setup_~__cil_tmp3~0#1.base, setup_~__cil_tmp3~0#1.offset;~bob~0 := 1;assume { :begin_inline_setup_bob } true;setup_bob_#in~bob___0#1 := ~bob~0;havoc setup_bob_~bob___0#1;setup_bob_~bob___0#1 := setup_bob_#in~bob___0#1;assume { :begin_inline_setup_bob__wrappee__Base } true;setup_bob__wrappee__Base_#in~bob___0#1 := setup_bob_~bob___0#1;havoc setup_bob__wrappee__Base_~bob___0#1;setup_bob__wrappee__Base_~bob___0#1 := setup_bob__wrappee__Base_#in~bob___0#1; {391#true} is VALID [2022-02-20 17:59:58,277 INFO L272 TraceCheckUtils]: 6: Hoare triple {391#true} call setClientId(setup_bob__wrappee__Base_~bob___0#1, setup_bob__wrappee__Base_~bob___0#1); {391#true} is VALID [2022-02-20 17:59:58,277 INFO L290 TraceCheckUtils]: 7: Hoare triple {391#true} ~handle := #in~handle;~value := #in~value; {391#true} is VALID [2022-02-20 17:59:58,278 INFO L290 TraceCheckUtils]: 8: Hoare triple {391#true} assume 1 == ~handle;~__ste_client_idCounter0~0 := ~value; {391#true} is VALID [2022-02-20 17:59:58,278 INFO L290 TraceCheckUtils]: 9: Hoare triple {391#true} assume true; {391#true} is VALID [2022-02-20 17:59:58,278 INFO L284 TraceCheckUtils]: 10: Hoare quadruple {391#true} {391#true} #1134#return; {391#true} is VALID [2022-02-20 17:59:58,279 INFO L290 TraceCheckUtils]: 11: Hoare triple {391#true} assume { :end_inline_setup_bob__wrappee__Base } true; {391#true} is VALID [2022-02-20 17:59:58,279 INFO L272 TraceCheckUtils]: 12: Hoare triple {391#true} call setClientPrivateKey(setup_bob_~bob___0#1, 123); {391#true} is VALID [2022-02-20 17:59:58,279 INFO L290 TraceCheckUtils]: 13: Hoare triple {391#true} ~handle := #in~handle;~value := #in~value; {391#true} is VALID [2022-02-20 17:59:58,280 INFO L290 TraceCheckUtils]: 14: Hoare triple {391#true} assume 1 == ~handle;~__ste_client_privateKey0~0 := ~value; {391#true} is VALID [2022-02-20 17:59:58,280 INFO L290 TraceCheckUtils]: 15: Hoare triple {391#true} assume true; {391#true} is VALID [2022-02-20 17:59:58,280 INFO L284 TraceCheckUtils]: 16: Hoare quadruple {391#true} {391#true} #1136#return; {391#true} is VALID [2022-02-20 17:59:58,282 INFO L290 TraceCheckUtils]: 17: Hoare triple {391#true} assume { :end_inline_setup_bob } true;setup_~__cil_tmp1~0#1.base, setup_~__cil_tmp1~0#1.offset := 18, 0;havoc setup_#t~nondet32#1;~rjh~0 := 2;assume { :begin_inline_setup_rjh } true;setup_rjh_#in~rjh___0#1 := ~rjh~0;havoc setup_rjh_~rjh___0#1;setup_rjh_~rjh___0#1 := setup_rjh_#in~rjh___0#1;assume { :begin_inline_setup_rjh__wrappee__Base } true;setup_rjh__wrappee__Base_#in~rjh___0#1 := setup_rjh_~rjh___0#1;havoc setup_rjh__wrappee__Base_~rjh___0#1;setup_rjh__wrappee__Base_~rjh___0#1 := setup_rjh__wrappee__Base_#in~rjh___0#1; {391#true} is VALID [2022-02-20 17:59:58,282 INFO L272 TraceCheckUtils]: 18: Hoare triple {391#true} call setClientId(setup_rjh__wrappee__Base_~rjh___0#1, setup_rjh__wrappee__Base_~rjh___0#1); {391#true} is VALID [2022-02-20 17:59:58,283 INFO L290 TraceCheckUtils]: 19: Hoare triple {391#true} ~handle := #in~handle;~value := #in~value; {391#true} is VALID [2022-02-20 17:59:58,283 INFO L290 TraceCheckUtils]: 20: Hoare triple {391#true} assume 1 == ~handle;~__ste_client_idCounter0~0 := ~value; {391#true} is VALID [2022-02-20 17:59:58,283 INFO L290 TraceCheckUtils]: 21: Hoare triple {391#true} assume true; {391#true} is VALID [2022-02-20 17:59:58,283 INFO L284 TraceCheckUtils]: 22: Hoare quadruple {391#true} {391#true} #1138#return; {391#true} is VALID [2022-02-20 17:59:58,284 INFO L290 TraceCheckUtils]: 23: Hoare triple {391#true} assume { :end_inline_setup_rjh__wrappee__Base } true; {391#true} is VALID [2022-02-20 17:59:58,284 INFO L272 TraceCheckUtils]: 24: Hoare triple {391#true} call setClientPrivateKey(setup_rjh_~rjh___0#1, 456); {391#true} is VALID [2022-02-20 17:59:58,284 INFO L290 TraceCheckUtils]: 25: Hoare triple {391#true} ~handle := #in~handle;~value := #in~value; {391#true} is VALID [2022-02-20 17:59:58,284 INFO L290 TraceCheckUtils]: 26: Hoare triple {391#true} assume 1 == ~handle;~__ste_client_privateKey0~0 := ~value; {391#true} is VALID [2022-02-20 17:59:58,284 INFO L290 TraceCheckUtils]: 27: Hoare triple {391#true} assume true; {391#true} is VALID [2022-02-20 17:59:58,284 INFO L284 TraceCheckUtils]: 28: Hoare quadruple {391#true} {391#true} #1140#return; {391#true} is VALID [2022-02-20 17:59:58,285 INFO L290 TraceCheckUtils]: 29: Hoare triple {391#true} assume { :end_inline_setup_rjh } true;setup_~__cil_tmp2~0#1.base, setup_~__cil_tmp2~0#1.offset := 19, 0;havoc setup_#t~nondet33#1;~chuck~0 := 3;assume { :begin_inline_setup_chuck } true;setup_chuck_#in~chuck___0#1 := ~chuck~0;havoc setup_chuck_~chuck___0#1;setup_chuck_~chuck___0#1 := setup_chuck_#in~chuck___0#1;assume { :begin_inline_setup_chuck__wrappee__Base } true;setup_chuck__wrappee__Base_#in~chuck___0#1 := setup_chuck_~chuck___0#1;havoc setup_chuck__wrappee__Base_~chuck___0#1;setup_chuck__wrappee__Base_~chuck___0#1 := setup_chuck__wrappee__Base_#in~chuck___0#1; {391#true} is VALID [2022-02-20 17:59:58,285 INFO L272 TraceCheckUtils]: 30: Hoare triple {391#true} call setClientId(setup_chuck__wrappee__Base_~chuck___0#1, setup_chuck__wrappee__Base_~chuck___0#1); {391#true} is VALID [2022-02-20 17:59:58,285 INFO L290 TraceCheckUtils]: 31: Hoare triple {391#true} ~handle := #in~handle;~value := #in~value; {391#true} is VALID [2022-02-20 17:59:58,285 INFO L290 TraceCheckUtils]: 32: Hoare triple {391#true} assume 1 == ~handle;~__ste_client_idCounter0~0 := ~value; {391#true} is VALID [2022-02-20 17:59:58,288 INFO L290 TraceCheckUtils]: 33: Hoare triple {391#true} assume true; {391#true} is VALID [2022-02-20 17:59:58,288 INFO L284 TraceCheckUtils]: 34: Hoare quadruple {391#true} {391#true} #1142#return; {391#true} is VALID [2022-02-20 17:59:58,289 INFO L290 TraceCheckUtils]: 35: Hoare triple {391#true} assume { :end_inline_setup_chuck__wrappee__Base } true; {391#true} is VALID [2022-02-20 17:59:58,289 INFO L272 TraceCheckUtils]: 36: Hoare triple {391#true} call setClientPrivateKey(setup_chuck_~chuck___0#1, 789); {391#true} is VALID [2022-02-20 17:59:58,289 INFO L290 TraceCheckUtils]: 37: Hoare triple {391#true} ~handle := #in~handle;~value := #in~value; {391#true} is VALID [2022-02-20 17:59:58,289 INFO L290 TraceCheckUtils]: 38: Hoare triple {391#true} assume 1 == ~handle;~__ste_client_privateKey0~0 := ~value; {391#true} is VALID [2022-02-20 17:59:58,289 INFO L290 TraceCheckUtils]: 39: Hoare triple {391#true} assume true; {391#true} is VALID [2022-02-20 17:59:58,290 INFO L284 TraceCheckUtils]: 40: Hoare quadruple {391#true} {391#true} #1144#return; {391#true} is VALID [2022-02-20 17:59:58,290 INFO L290 TraceCheckUtils]: 41: Hoare triple {391#true} assume { :end_inline_setup_chuck } true;setup_~__cil_tmp3~0#1.base, setup_~__cil_tmp3~0#1.offset := 20, 0;havoc setup_#t~nondet34#1; {391#true} is VALID [2022-02-20 17:59:58,290 INFO L290 TraceCheckUtils]: 42: Hoare triple {391#true} assume { :end_inline_setup } true;assume { :begin_inline_test } true;havoc test_#t~nondet47#1, test_#t~nondet48#1, test_#t~nondet49#1, test_#t~nondet50#1, test_#t~nondet51#1, test_#t~nondet52#1, test_#t~nondet53#1, test_#t~nondet54#1, test_#t~nondet55#1, test_#t~nondet56#1, test_#t~nondet57#1, test_~op1~0#1, test_~op2~0#1, test_~op3~0#1, test_~op4~0#1, test_~op5~0#1, test_~op6~0#1, test_~op7~0#1, test_~op8~0#1, test_~op9~0#1, test_~op10~0#1, test_~op11~0#1, test_~splverifierCounter~0#1, test_~tmp~6#1, test_~tmp___0~2#1, test_~tmp___1~1#1, test_~tmp___2~0#1, test_~tmp___3~0#1, test_~tmp___4~0#1, test_~tmp___5~0#1, test_~tmp___6~0#1, test_~tmp___7~0#1, test_~tmp___8~0#1, test_~tmp___9~0#1;havoc test_~op1~0#1;havoc test_~op2~0#1;havoc test_~op3~0#1;havoc test_~op4~0#1;havoc test_~op5~0#1;havoc test_~op6~0#1;havoc test_~op7~0#1;havoc test_~op8~0#1;havoc test_~op9~0#1;havoc test_~op10~0#1;havoc test_~op11~0#1;havoc test_~splverifierCounter~0#1;havoc test_~tmp~6#1;havoc test_~tmp___0~2#1;havoc test_~tmp___1~1#1;havoc test_~tmp___2~0#1;havoc test_~tmp___3~0#1;havoc test_~tmp___4~0#1;havoc test_~tmp___5~0#1;havoc test_~tmp___6~0#1;havoc test_~tmp___7~0#1;havoc test_~tmp___8~0#1;havoc test_~tmp___9~0#1;test_~op1~0#1 := 0;test_~op2~0#1 := 0;test_~op3~0#1 := 0;test_~op4~0#1 := 0;test_~op5~0#1 := 0;test_~op6~0#1 := 0;test_~op7~0#1 := 0;test_~op8~0#1 := 0;test_~op9~0#1 := 0;test_~op10~0#1 := 0;test_~op11~0#1 := 0;test_~splverifierCounter~0#1 := 0; {391#true} is VALID [2022-02-20 17:59:58,290 INFO L290 TraceCheckUtils]: 43: Hoare triple {391#true} assume !true; {392#false} is VALID [2022-02-20 17:59:58,291 INFO L290 TraceCheckUtils]: 44: Hoare triple {392#false} assume { :begin_inline_bobToRjh } true;havoc bobToRjh_#t~ret27#1, bobToRjh_#t~ret28#1, bobToRjh_#t~ret29#1, bobToRjh_#t~ret30#1, bobToRjh_~tmp~3#1, bobToRjh_~tmp___0~0#1, bobToRjh_~tmp___1~0#1;havoc bobToRjh_~tmp~3#1;havoc bobToRjh_~tmp___0~0#1;havoc bobToRjh_~tmp___1~0#1;call bobToRjh_#t~ret27#1 := puts(16, 0);assume -2147483648 <= bobToRjh_#t~ret27#1 && bobToRjh_#t~ret27#1 <= 2147483647;havoc bobToRjh_#t~ret27#1; {392#false} is VALID [2022-02-20 17:59:58,291 INFO L272 TraceCheckUtils]: 45: Hoare triple {392#false} call sendEmail(~bob~0, ~rjh~0); {392#false} is VALID [2022-02-20 17:59:58,291 INFO L290 TraceCheckUtils]: 46: Hoare triple {392#false} ~sender#1 := #in~sender#1;~receiver#1 := #in~receiver#1;havoc ~email~0#1;havoc ~tmp~14#1;assume { :begin_inline_createEmail } true;createEmail_#in~from#1, createEmail_#in~to#1 := 0, ~receiver#1;havoc createEmail_#res#1;havoc createEmail_~from#1, createEmail_~to#1, createEmail_~retValue_acc~31#1, createEmail_~msg~0#1;createEmail_~from#1 := createEmail_#in~from#1;createEmail_~to#1 := createEmail_#in~to#1;havoc createEmail_~retValue_acc~31#1;havoc createEmail_~msg~0#1;createEmail_~msg~0#1 := 1; {392#false} is VALID [2022-02-20 17:59:58,291 INFO L272 TraceCheckUtils]: 47: Hoare triple {392#false} call setEmailFrom(createEmail_~msg~0#1, createEmail_~from#1); {392#false} is VALID [2022-02-20 17:59:58,291 INFO L290 TraceCheckUtils]: 48: Hoare triple {392#false} ~handle := #in~handle;~value := #in~value; {392#false} is VALID [2022-02-20 17:59:58,291 INFO L290 TraceCheckUtils]: 49: Hoare triple {392#false} assume 1 == ~handle;~__ste_email_from0~0 := ~value; {392#false} is VALID [2022-02-20 17:59:58,292 INFO L290 TraceCheckUtils]: 50: Hoare triple {392#false} assume true; {392#false} is VALID [2022-02-20 17:59:58,292 INFO L284 TraceCheckUtils]: 51: Hoare quadruple {392#false} {392#false} #1120#return; {392#false} is VALID [2022-02-20 17:59:58,292 INFO L272 TraceCheckUtils]: 52: Hoare triple {392#false} call setEmailTo(createEmail_~msg~0#1, createEmail_~to#1); {392#false} is VALID [2022-02-20 17:59:58,292 INFO L290 TraceCheckUtils]: 53: Hoare triple {392#false} ~handle := #in~handle;~value := #in~value; {392#false} is VALID [2022-02-20 17:59:58,292 INFO L290 TraceCheckUtils]: 54: Hoare triple {392#false} assume 1 == ~handle;~__ste_email_to0~0 := ~value; {392#false} is VALID [2022-02-20 17:59:58,292 INFO L290 TraceCheckUtils]: 55: Hoare triple {392#false} assume true; {392#false} is VALID [2022-02-20 17:59:58,292 INFO L284 TraceCheckUtils]: 56: Hoare quadruple {392#false} {392#false} #1122#return; {392#false} is VALID [2022-02-20 17:59:58,293 INFO L290 TraceCheckUtils]: 57: Hoare triple {392#false} createEmail_~retValue_acc~31#1 := createEmail_~msg~0#1;createEmail_#res#1 := createEmail_~retValue_acc~31#1; {392#false} is VALID [2022-02-20 17:59:58,293 INFO L290 TraceCheckUtils]: 58: Hoare triple {392#false} #t~ret72#1 := createEmail_#res#1;assume { :end_inline_createEmail } true;assume -2147483648 <= #t~ret72#1 && #t~ret72#1 <= 2147483647;~tmp~14#1 := #t~ret72#1;havoc #t~ret72#1;~email~0#1 := ~tmp~14#1; {392#false} is VALID [2022-02-20 17:59:58,293 INFO L272 TraceCheckUtils]: 59: Hoare triple {392#false} call outgoing(~sender#1, ~email~0#1); {392#false} is VALID [2022-02-20 17:59:58,293 INFO L290 TraceCheckUtils]: 60: Hoare triple {392#false} ~client#1 := #in~client#1;~msg#1 := #in~msg#1;assume { :begin_inline_sign } true;sign_#in~client#1, sign_#in~msg#1 := ~client#1, ~msg#1;havoc sign_#t~ret76#1, sign_~client#1, sign_~msg#1, sign_~privkey~1#1, sign_~tmp~16#1;sign_~client#1 := sign_#in~client#1;sign_~msg#1 := sign_#in~msg#1;havoc sign_~privkey~1#1;havoc sign_~tmp~16#1; {392#false} is VALID [2022-02-20 17:59:58,293 INFO L272 TraceCheckUtils]: 61: Hoare triple {392#false} call sign_#t~ret76#1 := getClientPrivateKey(sign_~client#1); {392#false} is VALID [2022-02-20 17:59:58,293 INFO L290 TraceCheckUtils]: 62: Hoare triple {392#false} ~handle := #in~handle;havoc ~retValue_acc~20; {392#false} is VALID [2022-02-20 17:59:58,294 INFO L290 TraceCheckUtils]: 63: Hoare triple {392#false} assume 1 == ~handle;~retValue_acc~20 := ~__ste_client_privateKey0~0;#res := ~retValue_acc~20; {392#false} is VALID [2022-02-20 17:59:58,294 INFO L290 TraceCheckUtils]: 64: Hoare triple {392#false} assume true; {392#false} is VALID [2022-02-20 17:59:58,294 INFO L284 TraceCheckUtils]: 65: Hoare quadruple {392#false} {392#false} #1054#return; {392#false} is VALID [2022-02-20 17:59:58,294 INFO L290 TraceCheckUtils]: 66: Hoare triple {392#false} assume -2147483648 <= sign_#t~ret76#1 && sign_#t~ret76#1 <= 2147483647;sign_~tmp~16#1 := sign_#t~ret76#1;havoc sign_#t~ret76#1;sign_~privkey~1#1 := sign_~tmp~16#1; {392#false} is VALID [2022-02-20 17:59:58,294 INFO L290 TraceCheckUtils]: 67: Hoare triple {392#false} assume 0 == sign_~privkey~1#1; {392#false} is VALID [2022-02-20 17:59:58,295 INFO L290 TraceCheckUtils]: 68: Hoare triple {392#false} assume { :end_inline_sign } true;assume { :begin_inline_outgoing__wrappee__AutoResponder } true;outgoing__wrappee__AutoResponder_#in~client#1, outgoing__wrappee__AutoResponder_#in~msg#1 := ~client#1, ~msg#1;havoc outgoing__wrappee__AutoResponder_#t~ret62#1, outgoing__wrappee__AutoResponder_#t~ret63#1, outgoing__wrappee__AutoResponder_~client#1, outgoing__wrappee__AutoResponder_~msg#1, outgoing__wrappee__AutoResponder_~receiver~0#1, outgoing__wrappee__AutoResponder_~tmp~9#1, outgoing__wrappee__AutoResponder_~pubkey~0#1, outgoing__wrappee__AutoResponder_~tmp___0~3#1;outgoing__wrappee__AutoResponder_~client#1 := outgoing__wrappee__AutoResponder_#in~client#1;outgoing__wrappee__AutoResponder_~msg#1 := outgoing__wrappee__AutoResponder_#in~msg#1;havoc outgoing__wrappee__AutoResponder_~receiver~0#1;havoc outgoing__wrappee__AutoResponder_~tmp~9#1;havoc outgoing__wrappee__AutoResponder_~pubkey~0#1;havoc outgoing__wrappee__AutoResponder_~tmp___0~3#1; {392#false} is VALID [2022-02-20 17:59:58,295 INFO L272 TraceCheckUtils]: 69: Hoare triple {392#false} call outgoing__wrappee__AutoResponder_#t~ret62#1 := getEmailTo(outgoing__wrappee__AutoResponder_~msg#1); {392#false} is VALID [2022-02-20 17:59:58,295 INFO L290 TraceCheckUtils]: 70: Hoare triple {392#false} ~handle := #in~handle;havoc ~retValue_acc~36; {392#false} is VALID [2022-02-20 17:59:58,295 INFO L290 TraceCheckUtils]: 71: Hoare triple {392#false} assume 1 == ~handle;~retValue_acc~36 := ~__ste_email_to0~0;#res := ~retValue_acc~36; {392#false} is VALID [2022-02-20 17:59:58,295 INFO L290 TraceCheckUtils]: 72: Hoare triple {392#false} assume true; {392#false} is VALID [2022-02-20 17:59:58,295 INFO L284 TraceCheckUtils]: 73: Hoare quadruple {392#false} {392#false} #1056#return; {392#false} is VALID [2022-02-20 17:59:58,296 INFO L290 TraceCheckUtils]: 74: Hoare triple {392#false} assume -2147483648 <= outgoing__wrappee__AutoResponder_#t~ret62#1 && outgoing__wrappee__AutoResponder_#t~ret62#1 <= 2147483647;outgoing__wrappee__AutoResponder_~tmp~9#1 := outgoing__wrappee__AutoResponder_#t~ret62#1;havoc outgoing__wrappee__AutoResponder_#t~ret62#1;outgoing__wrappee__AutoResponder_~receiver~0#1 := outgoing__wrappee__AutoResponder_~tmp~9#1; {392#false} is VALID [2022-02-20 17:59:58,300 INFO L272 TraceCheckUtils]: 75: Hoare triple {392#false} call outgoing__wrappee__AutoResponder_#t~ret63#1 := findPublicKey(outgoing__wrappee__AutoResponder_~client#1, outgoing__wrappee__AutoResponder_~receiver~0#1); {392#false} is VALID [2022-02-20 17:59:58,300 INFO L290 TraceCheckUtils]: 76: Hoare triple {392#false} ~handle := #in~handle;~userid := #in~userid;havoc ~retValue_acc~25; {392#false} is VALID [2022-02-20 17:59:58,301 INFO L290 TraceCheckUtils]: 77: Hoare triple {392#false} assume 1 == ~handle; {392#false} is VALID [2022-02-20 17:59:58,302 INFO L290 TraceCheckUtils]: 78: Hoare triple {392#false} assume ~userid == ~__ste_Client_Keyring0_User0~0;~retValue_acc~25 := ~__ste_Client_Keyring0_PublicKey0~0;#res := ~retValue_acc~25; {392#false} is VALID [2022-02-20 17:59:58,304 INFO L290 TraceCheckUtils]: 79: Hoare triple {392#false} assume true; {392#false} is VALID [2022-02-20 17:59:58,305 INFO L284 TraceCheckUtils]: 80: Hoare quadruple {392#false} {392#false} #1058#return; {392#false} is VALID [2022-02-20 17:59:58,306 INFO L290 TraceCheckUtils]: 81: Hoare triple {392#false} assume -2147483648 <= outgoing__wrappee__AutoResponder_#t~ret63#1 && outgoing__wrappee__AutoResponder_#t~ret63#1 <= 2147483647;outgoing__wrappee__AutoResponder_~tmp___0~3#1 := outgoing__wrappee__AutoResponder_#t~ret63#1;havoc outgoing__wrappee__AutoResponder_#t~ret63#1;outgoing__wrappee__AutoResponder_~pubkey~0#1 := outgoing__wrappee__AutoResponder_~tmp___0~3#1; {392#false} is VALID [2022-02-20 17:59:58,307 INFO L290 TraceCheckUtils]: 82: Hoare triple {392#false} assume !(0 != outgoing__wrappee__AutoResponder_~pubkey~0#1); {392#false} is VALID [2022-02-20 17:59:58,307 INFO L290 TraceCheckUtils]: 83: Hoare triple {392#false} assume { :begin_inline_outgoing__wrappee__Keys } true;outgoing__wrappee__Keys_#in~client#1, outgoing__wrappee__Keys_#in~msg#1 := outgoing__wrappee__AutoResponder_~client#1, outgoing__wrappee__AutoResponder_~msg#1;havoc outgoing__wrappee__Keys_#t~ret61#1, outgoing__wrappee__Keys_~client#1, outgoing__wrappee__Keys_~msg#1, outgoing__wrappee__Keys_~tmp~8#1;outgoing__wrappee__Keys_~client#1 := outgoing__wrappee__Keys_#in~client#1;outgoing__wrappee__Keys_~msg#1 := outgoing__wrappee__Keys_#in~msg#1;havoc outgoing__wrappee__Keys_~tmp~8#1;assume { :begin_inline_getClientId } true;getClientId_#in~handle#1 := outgoing__wrappee__Keys_~client#1;havoc getClientId_#res#1;havoc getClientId_~handle#1, getClientId_~retValue_acc~27#1;getClientId_~handle#1 := getClientId_#in~handle#1;havoc getClientId_~retValue_acc~27#1; {392#false} is VALID [2022-02-20 17:59:58,307 INFO L290 TraceCheckUtils]: 84: Hoare triple {392#false} assume 1 == getClientId_~handle#1;getClientId_~retValue_acc~27#1 := ~__ste_client_idCounter0~0;getClientId_#res#1 := getClientId_~retValue_acc~27#1; {392#false} is VALID [2022-02-20 17:59:58,309 INFO L290 TraceCheckUtils]: 85: Hoare triple {392#false} outgoing__wrappee__Keys_#t~ret61#1 := getClientId_#res#1;assume { :end_inline_getClientId } true;assume -2147483648 <= outgoing__wrappee__Keys_#t~ret61#1 && outgoing__wrappee__Keys_#t~ret61#1 <= 2147483647;outgoing__wrappee__Keys_~tmp~8#1 := outgoing__wrappee__Keys_#t~ret61#1;havoc outgoing__wrappee__Keys_#t~ret61#1; {392#false} is VALID [2022-02-20 17:59:58,310 INFO L272 TraceCheckUtils]: 86: Hoare triple {392#false} call setEmailFrom(outgoing__wrappee__Keys_~msg#1, outgoing__wrappee__Keys_~tmp~8#1); {392#false} is VALID [2022-02-20 17:59:58,310 INFO L290 TraceCheckUtils]: 87: Hoare triple {392#false} ~handle := #in~handle;~value := #in~value; {392#false} is VALID [2022-02-20 17:59:58,310 INFO L290 TraceCheckUtils]: 88: Hoare triple {392#false} assume 1 == ~handle;~__ste_email_from0~0 := ~value; {392#false} is VALID [2022-02-20 17:59:58,311 INFO L290 TraceCheckUtils]: 89: Hoare triple {392#false} assume true; {392#false} is VALID [2022-02-20 17:59:58,314 INFO L284 TraceCheckUtils]: 90: Hoare quadruple {392#false} {392#false} #1064#return; {392#false} is VALID [2022-02-20 17:59:58,314 INFO L290 TraceCheckUtils]: 91: Hoare triple {392#false} assume { :begin_inline_mail } true;mail_#in~client#1, mail_#in~msg#1 := outgoing__wrappee__Keys_~client#1, outgoing__wrappee__Keys_~msg#1;havoc mail_#t~ret59#1, mail_#t~ret60#1, mail_~client#1, mail_~msg#1, mail_~__utac__ad__arg1~0#1, mail_~__utac__ad__arg2~0#1, mail_~tmp~7#1;mail_~client#1 := mail_#in~client#1;mail_~msg#1 := mail_#in~msg#1;havoc mail_~__utac__ad__arg1~0#1;havoc mail_~__utac__ad__arg2~0#1;havoc mail_~tmp~7#1;mail_~__utac__ad__arg1~0#1 := mail_~client#1;mail_~__utac__ad__arg2~0#1 := mail_~msg#1;assume { :begin_inline___utac_acc__SignForward_spec__1 } true;__utac_acc__SignForward_spec__1_#in~client#1, __utac_acc__SignForward_spec__1_#in~msg#1 := mail_~__utac__ad__arg1~0#1, mail_~__utac__ad__arg2~0#1;havoc __utac_acc__SignForward_spec__1_#t~ret107#1, __utac_acc__SignForward_spec__1_#t~ret108#1, __utac_acc__SignForward_spec__1_#t~ret109#1, __utac_acc__SignForward_spec__1_~client#1, __utac_acc__SignForward_spec__1_~msg#1, __utac_acc__SignForward_spec__1_~tmp~25#1, __utac_acc__SignForward_spec__1_~tmp___0~9#1;__utac_acc__SignForward_spec__1_~client#1 := __utac_acc__SignForward_spec__1_#in~client#1;__utac_acc__SignForward_spec__1_~msg#1 := __utac_acc__SignForward_spec__1_#in~msg#1;havoc __utac_acc__SignForward_spec__1_~tmp~25#1;havoc __utac_acc__SignForward_spec__1_~tmp___0~9#1;call __utac_acc__SignForward_spec__1_#t~ret107#1 := puts(39, 0);assume -2147483648 <= __utac_acc__SignForward_spec__1_#t~ret107#1 && __utac_acc__SignForward_spec__1_#t~ret107#1 <= 2147483647;havoc __utac_acc__SignForward_spec__1_#t~ret107#1; {392#false} is VALID [2022-02-20 17:59:58,315 INFO L272 TraceCheckUtils]: 92: Hoare triple {392#false} call __utac_acc__SignForward_spec__1_#t~ret108#1 := isSigned(__utac_acc__SignForward_spec__1_~msg#1); {392#false} is VALID [2022-02-20 17:59:58,315 INFO L290 TraceCheckUtils]: 93: Hoare triple {392#false} ~handle := #in~handle;havoc ~retValue_acc~41; {392#false} is VALID [2022-02-20 17:59:58,315 INFO L290 TraceCheckUtils]: 94: Hoare triple {392#false} assume 1 == ~handle;~retValue_acc~41 := ~__ste_email_isSigned0~0;#res := ~retValue_acc~41; {392#false} is VALID [2022-02-20 17:59:58,315 INFO L290 TraceCheckUtils]: 95: Hoare triple {392#false} assume true; {392#false} is VALID [2022-02-20 17:59:58,318 INFO L284 TraceCheckUtils]: 96: Hoare quadruple {392#false} {392#false} #1066#return; {392#false} is VALID [2022-02-20 17:59:58,318 INFO L290 TraceCheckUtils]: 97: Hoare triple {392#false} assume -2147483648 <= __utac_acc__SignForward_spec__1_#t~ret108#1 && __utac_acc__SignForward_spec__1_#t~ret108#1 <= 2147483647;__utac_acc__SignForward_spec__1_~tmp___0~9#1 := __utac_acc__SignForward_spec__1_#t~ret108#1;havoc __utac_acc__SignForward_spec__1_#t~ret108#1; {392#false} is VALID [2022-02-20 17:59:58,318 INFO L290 TraceCheckUtils]: 98: Hoare triple {392#false} assume 0 != __utac_acc__SignForward_spec__1_~tmp___0~9#1; {392#false} is VALID [2022-02-20 17:59:58,318 INFO L272 TraceCheckUtils]: 99: Hoare triple {392#false} call __utac_acc__SignForward_spec__1_#t~ret109#1 := getClientPrivateKey(__utac_acc__SignForward_spec__1_~client#1); {392#false} is VALID [2022-02-20 17:59:58,318 INFO L290 TraceCheckUtils]: 100: Hoare triple {392#false} ~handle := #in~handle;havoc ~retValue_acc~20; {392#false} is VALID [2022-02-20 17:59:58,319 INFO L290 TraceCheckUtils]: 101: Hoare triple {392#false} assume 1 == ~handle;~retValue_acc~20 := ~__ste_client_privateKey0~0;#res := ~retValue_acc~20; {392#false} is VALID [2022-02-20 17:59:58,319 INFO L290 TraceCheckUtils]: 102: Hoare triple {392#false} assume true; {392#false} is VALID [2022-02-20 17:59:58,319 INFO L284 TraceCheckUtils]: 103: Hoare quadruple {392#false} {392#false} #1068#return; {392#false} is VALID [2022-02-20 17:59:58,319 INFO L290 TraceCheckUtils]: 104: Hoare triple {392#false} assume -2147483648 <= __utac_acc__SignForward_spec__1_#t~ret109#1 && __utac_acc__SignForward_spec__1_#t~ret109#1 <= 2147483647;__utac_acc__SignForward_spec__1_~tmp~25#1 := __utac_acc__SignForward_spec__1_#t~ret109#1;havoc __utac_acc__SignForward_spec__1_#t~ret109#1; {392#false} is VALID [2022-02-20 17:59:58,319 INFO L290 TraceCheckUtils]: 105: Hoare triple {392#false} assume 0 == __utac_acc__SignForward_spec__1_~tmp~25#1;assume { :begin_inline___automaton_fail } true; {392#false} is VALID [2022-02-20 17:59:58,319 INFO L290 TraceCheckUtils]: 106: Hoare triple {392#false} assume !false; {392#false} is VALID [2022-02-20 17:59:58,320 INFO L134 CoverageAnalysis]: Checked inductivity of 32 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 32 trivial. 0 not checked. [2022-02-20 17:59:58,320 INFO L324 TraceCheckSpWp]: Omiting computation of backward sequence because forward sequence was already perfect [2022-02-20 17:59:58,320 INFO L165 FreeRefinementEngine]: IpTcStrategyModuleZ3 [1361955889] provided 1 perfect and 0 imperfect interpolant sequences [2022-02-20 17:59:58,320 INFO L191 FreeRefinementEngine]: Found 1 perfect and 1 imperfect interpolant sequences. [2022-02-20 17:59:58,321 INFO L204 FreeRefinementEngine]: Number of different interpolants: perfect sequences [2] imperfect sequences [9] total 9 [2022-02-20 17:59:58,323 INFO L118 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [1101102646] [2022-02-20 17:59:58,323 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2022-02-20 17:59:58,326 INFO L78 Accepts]: Start accepts. Automaton has has 2 states, 2 states have (on average 29.5) internal successors, (59), 2 states have internal predecessors, (59), 2 states have call successors, (16), 2 states have call predecessors, (16), 2 states have return successors, (14), 2 states have call predecessors, (14), 2 states have call successors, (14) Word has length 107 [2022-02-20 17:59:58,328 INFO L84 Accepts]: Finished accepts. word is accepted. [2022-02-20 17:59:58,332 INFO L86 InductivityCheck]: Starting indutivity check of a Floyd-Hoare automaton with has 2 states, 2 states have (on average 29.5) internal successors, (59), 2 states have internal predecessors, (59), 2 states have call successors, (16), 2 states have call predecessors, (16), 2 states have return successors, (14), 2 states have call predecessors, (14), 2 states have call successors, (14) [2022-02-20 17:59:58,402 INFO L122 InductivityCheck]: Floyd-Hoare automaton has 89 edges. 89 inductive. 0 not inductive. 0 times theorem prover too weak to decide inductivity. [2022-02-20 17:59:58,402 INFO L546 AbstractCegarLoop]: INTERPOLANT automaton has 2 states [2022-02-20 17:59:58,402 INFO L108 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2022-02-20 17:59:58,414 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 2 interpolants. [2022-02-20 17:59:58,415 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=15, Invalid=57, Unknown=0, NotChecked=0, Total=72 [2022-02-20 17:59:58,418 INFO L87 Difference]: Start difference. First operand has 388 states, 299 states have (on average 1.5016722408026757) internal successors, (449), 303 states have internal predecessors, (449), 63 states have call successors, (63), 24 states have call predecessors, (63), 24 states have return successors, (63), 63 states have call predecessors, (63), 63 states have call successors, (63) Second operand has 2 states, 2 states have (on average 29.5) internal successors, (59), 2 states have internal predecessors, (59), 2 states have call successors, (16), 2 states have call predecessors, (16), 2 states have return successors, (14), 2 states have call predecessors, (14), 2 states have call successors, (14) [2022-02-20 17:59:58,770 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-02-20 17:59:58,770 INFO L93 Difference]: Finished difference Result 617 states and 896 transitions. [2022-02-20 17:59:58,770 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 2 states. [2022-02-20 17:59:58,771 INFO L78 Accepts]: Start accepts. Automaton has has 2 states, 2 states have (on average 29.5) internal successors, (59), 2 states have internal predecessors, (59), 2 states have call successors, (16), 2 states have call predecessors, (16), 2 states have return successors, (14), 2 states have call predecessors, (14), 2 states have call successors, (14) Word has length 107 [2022-02-20 17:59:58,771 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2022-02-20 17:59:58,772 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 2 states, 2 states have (on average 29.5) internal successors, (59), 2 states have internal predecessors, (59), 2 states have call successors, (16), 2 states have call predecessors, (16), 2 states have return successors, (14), 2 states have call predecessors, (14), 2 states have call successors, (14) [2022-02-20 17:59:58,790 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 2 states to 2 states and 896 transitions. [2022-02-20 17:59:58,790 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 2 states, 2 states have (on average 29.5) internal successors, (59), 2 states have internal predecessors, (59), 2 states have call successors, (16), 2 states have call predecessors, (16), 2 states have return successors, (14), 2 states have call predecessors, (14), 2 states have call successors, (14) [2022-02-20 17:59:58,803 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 2 states to 2 states and 896 transitions. [2022-02-20 17:59:58,804 INFO L86 InductivityCheck]: Starting indutivity check of a Floyd-Hoare automaton with 2 states and 896 transitions. [2022-02-20 17:59:59,367 INFO L122 InductivityCheck]: Floyd-Hoare automaton has 896 edges. 896 inductive. 0 not inductive. 0 times theorem prover too weak to decide inductivity. [2022-02-20 17:59:59,390 INFO L225 Difference]: With dead ends: 617 [2022-02-20 17:59:59,390 INFO L226 Difference]: Without dead ends: 381 [2022-02-20 17:59:59,394 INFO L932 BasicCegarLoop]: 0 DeclaredPredicates, 138 GetRequests, 131 SyntacticMatches, 0 SemanticMatches, 7 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 0 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=15, Invalid=57, Unknown=0, NotChecked=0, Total=72 [2022-02-20 17:59:59,396 INFO L933 BasicCegarLoop]: 571 mSDtfsCounter, 0 mSDsluCounter, 0 mSDsCounter, 0 mSdLazyCounter, 0 mSolverCounterSat, 0 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.0s Time, 0 mProtectedPredicate, 0 mProtectedAction, 0 SdHoareTripleChecker+Valid, 571 SdHoareTripleChecker+Invalid, 0 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 0 IncrementalHoareTripleChecker+Valid, 0 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.0s IncrementalHoareTripleChecker+Time [2022-02-20 17:59:59,397 INFO L934 BasicCegarLoop]: SdHoareTripleChecker [0 Valid, 571 Invalid, 0 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [0 Valid, 0 Invalid, 0 Unknown, 0 Unchecked, 0.0s Time] [2022-02-20 17:59:59,408 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 381 states. [2022-02-20 17:59:59,431 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 381 to 381. [2022-02-20 17:59:59,431 INFO L214 AbstractMinimizeNwa]: Start testing correctness of minimizeSevpa [2022-02-20 17:59:59,433 INFO L82 GeneralOperation]: Start isEquivalent. First operand 381 states. Second operand has 381 states, 293 states have (on average 1.4948805460750854) internal successors, (438), 296 states have internal predecessors, (438), 63 states have call successors, (63), 24 states have call predecessors, (63), 24 states have return successors, (62), 62 states have call predecessors, (62), 62 states have call successors, (62) [2022-02-20 17:59:59,435 INFO L74 IsIncluded]: Start isIncluded. First operand 381 states. Second operand has 381 states, 293 states have (on average 1.4948805460750854) internal successors, (438), 296 states have internal predecessors, (438), 63 states have call successors, (63), 24 states have call predecessors, (63), 24 states have return successors, (62), 62 states have call predecessors, (62), 62 states have call successors, (62) [2022-02-20 17:59:59,436 INFO L87 Difference]: Start difference. First operand 381 states. Second operand has 381 states, 293 states have (on average 1.4948805460750854) internal successors, (438), 296 states have internal predecessors, (438), 63 states have call successors, (63), 24 states have call predecessors, (63), 24 states have return successors, (62), 62 states have call predecessors, (62), 62 states have call successors, (62) [2022-02-20 17:59:59,454 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-02-20 17:59:59,454 INFO L93 Difference]: Finished difference Result 381 states and 563 transitions. [2022-02-20 17:59:59,454 INFO L276 IsEmpty]: Start isEmpty. Operand 381 states and 563 transitions. [2022-02-20 17:59:59,457 INFO L282 IsEmpty]: Finished isEmpty. No accepting run. [2022-02-20 17:59:59,457 INFO L83 IsIncluded]: Finished isIncluded. Language is included [2022-02-20 17:59:59,458 INFO L74 IsIncluded]: Start isIncluded. First operand has 381 states, 293 states have (on average 1.4948805460750854) internal successors, (438), 296 states have internal predecessors, (438), 63 states have call successors, (63), 24 states have call predecessors, (63), 24 states have return successors, (62), 62 states have call predecessors, (62), 62 states have call successors, (62) Second operand 381 states. [2022-02-20 17:59:59,459 INFO L87 Difference]: Start difference. First operand has 381 states, 293 states have (on average 1.4948805460750854) internal successors, (438), 296 states have internal predecessors, (438), 63 states have call successors, (63), 24 states have call predecessors, (63), 24 states have return successors, (62), 62 states have call predecessors, (62), 62 states have call successors, (62) Second operand 381 states. [2022-02-20 17:59:59,476 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-02-20 17:59:59,477 INFO L93 Difference]: Finished difference Result 381 states and 563 transitions. [2022-02-20 17:59:59,477 INFO L276 IsEmpty]: Start isEmpty. Operand 381 states and 563 transitions. [2022-02-20 17:59:59,478 INFO L282 IsEmpty]: Finished isEmpty. No accepting run. [2022-02-20 17:59:59,478 INFO L83 IsIncluded]: Finished isIncluded. Language is included [2022-02-20 17:59:59,478 INFO L88 GeneralOperation]: Finished isEquivalent. [2022-02-20 17:59:59,479 INFO L221 AbstractMinimizeNwa]: Finished testing correctness of minimizeSevpa [2022-02-20 17:59:59,480 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 381 states, 293 states have (on average 1.4948805460750854) internal successors, (438), 296 states have internal predecessors, (438), 63 states have call successors, (63), 24 states have call predecessors, (63), 24 states have return successors, (62), 62 states have call predecessors, (62), 62 states have call successors, (62) [2022-02-20 17:59:59,494 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 381 states to 381 states and 563 transitions. [2022-02-20 17:59:59,496 INFO L78 Accepts]: Start accepts. Automaton has 381 states and 563 transitions. Word has length 107 [2022-02-20 17:59:59,496 INFO L84 Accepts]: Finished accepts. word is rejected. [2022-02-20 17:59:59,496 INFO L470 AbstractCegarLoop]: Abstraction has 381 states and 563 transitions. [2022-02-20 17:59:59,497 INFO L471 AbstractCegarLoop]: INTERPOLANT automaton has has 2 states, 2 states have (on average 29.5) internal successors, (59), 2 states have internal predecessors, (59), 2 states have call successors, (16), 2 states have call predecessors, (16), 2 states have return successors, (14), 2 states have call predecessors, (14), 2 states have call successors, (14) [2022-02-20 17:59:59,497 INFO L276 IsEmpty]: Start isEmpty. Operand 381 states and 563 transitions. [2022-02-20 17:59:59,498 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 109 [2022-02-20 17:59:59,499 INFO L506 BasicCegarLoop]: Found error trace [2022-02-20 17:59:59,499 INFO L514 BasicCegarLoop]: trace histogram [3, 3, 3, 3, 3, 3, 2, 2, 2, 2, 2, 2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-02-20 17:59:59,519 INFO L552 MonitoredProcess]: [MP /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 -smt2 -in SMTLIB2_COMPLIANT=true (2)] Ended with exit code 0 [2022-02-20 17:59:59,716 WARN L452 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: 2 /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 -smt2 -in SMTLIB2_COMPLIANT=true,SelfDestructingSolverStorable0 [2022-02-20 17:59:59,717 INFO L402 AbstractCegarLoop]: === Iteration 2 === Targeting outgoingErr0ASSERT_VIOLATIONERROR_FUNCTION === [outgoingErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2022-02-20 17:59:59,717 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2022-02-20 17:59:59,717 INFO L85 PathProgramCache]: Analyzing trace with hash -1713735028, now seen corresponding path program 1 times [2022-02-20 17:59:59,718 INFO L126 FreeRefinementEngine]: Executing refinement strategy CAMEL [2022-02-20 17:59:59,718 INFO L338 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [216991103] [2022-02-20 17:59:59,718 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-02-20 17:59:59,718 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2022-02-20 17:59:59,745 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-02-20 17:59:59,775 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 6 [2022-02-20 17:59:59,777 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-02-20 17:59:59,782 INFO L290 TraceCheckUtils]: 0: Hoare triple {2998#(and (= |old(~__ste_client_idCounter0~0)| ~__ste_client_idCounter0~0) (= |old(~__ste_client_idCounter1~0)| ~__ste_client_idCounter1~0) (= |old(~__ste_client_idCounter2~0)| ~__ste_client_idCounter2~0))} ~handle := #in~handle;~value := #in~value; {2938#true} is VALID [2022-02-20 17:59:59,782 INFO L290 TraceCheckUtils]: 1: Hoare triple {2938#true} assume 1 == ~handle;~__ste_client_idCounter0~0 := ~value; {2938#true} is VALID [2022-02-20 17:59:59,782 INFO L290 TraceCheckUtils]: 2: Hoare triple {2938#true} assume true; {2938#true} is VALID [2022-02-20 17:59:59,782 INFO L284 TraceCheckUtils]: 3: Hoare quadruple {2938#true} {2938#true} #1134#return; {2938#true} is VALID [2022-02-20 17:59:59,789 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 12 [2022-02-20 17:59:59,791 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-02-20 17:59:59,793 INFO L290 TraceCheckUtils]: 0: Hoare triple {2999#(and (= ~__ste_client_privateKey0~0 |old(~__ste_client_privateKey0~0)|) (= ~__ste_client_privateKey2~0 |old(~__ste_client_privateKey2~0)|) (= ~__ste_client_privateKey1~0 |old(~__ste_client_privateKey1~0)|))} ~handle := #in~handle;~value := #in~value; {2938#true} is VALID [2022-02-20 17:59:59,793 INFO L290 TraceCheckUtils]: 1: Hoare triple {2938#true} assume 1 == ~handle;~__ste_client_privateKey0~0 := ~value; {2938#true} is VALID [2022-02-20 17:59:59,793 INFO L290 TraceCheckUtils]: 2: Hoare triple {2938#true} assume true; {2938#true} is VALID [2022-02-20 17:59:59,793 INFO L284 TraceCheckUtils]: 3: Hoare quadruple {2938#true} {2938#true} #1136#return; {2938#true} is VALID [2022-02-20 17:59:59,793 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 18 [2022-02-20 17:59:59,795 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-02-20 17:59:59,806 INFO L290 TraceCheckUtils]: 0: Hoare triple {2998#(and (= |old(~__ste_client_idCounter0~0)| ~__ste_client_idCounter0~0) (= |old(~__ste_client_idCounter1~0)| ~__ste_client_idCounter1~0) (= |old(~__ste_client_idCounter2~0)| ~__ste_client_idCounter2~0))} ~handle := #in~handle;~value := #in~value; {3000#(= setClientId_~handle |setClientId_#in~handle|)} is VALID [2022-02-20 17:59:59,807 INFO L290 TraceCheckUtils]: 1: Hoare triple {3000#(= setClientId_~handle |setClientId_#in~handle|)} assume 1 == ~handle;~__ste_client_idCounter0~0 := ~value; {3001#(= |setClientId_#in~handle| 1)} is VALID [2022-02-20 17:59:59,807 INFO L290 TraceCheckUtils]: 2: Hoare triple {3001#(= |setClientId_#in~handle| 1)} assume true; {3001#(= |setClientId_#in~handle| 1)} is VALID [2022-02-20 17:59:59,808 INFO L284 TraceCheckUtils]: 3: Hoare quadruple {3001#(= |setClientId_#in~handle| 1)} {2948#(= |ULTIMATE.start_setup_rjh__wrappee__Base_~rjh___0#1| 2)} #1138#return; {2939#false} is VALID [2022-02-20 17:59:59,808 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 24 [2022-02-20 17:59:59,809 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-02-20 17:59:59,811 INFO L290 TraceCheckUtils]: 0: Hoare triple {2999#(and (= ~__ste_client_privateKey0~0 |old(~__ste_client_privateKey0~0)|) (= ~__ste_client_privateKey2~0 |old(~__ste_client_privateKey2~0)|) (= ~__ste_client_privateKey1~0 |old(~__ste_client_privateKey1~0)|))} ~handle := #in~handle;~value := #in~value; {2938#true} is VALID [2022-02-20 17:59:59,812 INFO L290 TraceCheckUtils]: 1: Hoare triple {2938#true} assume 1 == ~handle;~__ste_client_privateKey0~0 := ~value; {2938#true} is VALID [2022-02-20 17:59:59,812 INFO L290 TraceCheckUtils]: 2: Hoare triple {2938#true} assume true; {2938#true} is VALID [2022-02-20 17:59:59,812 INFO L284 TraceCheckUtils]: 3: Hoare quadruple {2938#true} {2939#false} #1140#return; {2939#false} is VALID [2022-02-20 17:59:59,812 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 30 [2022-02-20 17:59:59,814 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-02-20 17:59:59,816 INFO L290 TraceCheckUtils]: 0: Hoare triple {2998#(and (= |old(~__ste_client_idCounter0~0)| ~__ste_client_idCounter0~0) (= |old(~__ste_client_idCounter1~0)| ~__ste_client_idCounter1~0) (= |old(~__ste_client_idCounter2~0)| ~__ste_client_idCounter2~0))} ~handle := #in~handle;~value := #in~value; {2938#true} is VALID [2022-02-20 17:59:59,816 INFO L290 TraceCheckUtils]: 1: Hoare triple {2938#true} assume 1 == ~handle;~__ste_client_idCounter0~0 := ~value; {2938#true} is VALID [2022-02-20 17:59:59,816 INFO L290 TraceCheckUtils]: 2: Hoare triple {2938#true} assume true; {2938#true} is VALID [2022-02-20 17:59:59,816 INFO L284 TraceCheckUtils]: 3: Hoare quadruple {2938#true} {2939#false} #1142#return; {2939#false} is VALID [2022-02-20 17:59:59,816 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 36 [2022-02-20 17:59:59,818 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-02-20 17:59:59,820 INFO L290 TraceCheckUtils]: 0: Hoare triple {2999#(and (= ~__ste_client_privateKey0~0 |old(~__ste_client_privateKey0~0)|) (= ~__ste_client_privateKey2~0 |old(~__ste_client_privateKey2~0)|) (= ~__ste_client_privateKey1~0 |old(~__ste_client_privateKey1~0)|))} ~handle := #in~handle;~value := #in~value; {2938#true} is VALID [2022-02-20 17:59:59,820 INFO L290 TraceCheckUtils]: 1: Hoare triple {2938#true} assume 1 == ~handle;~__ste_client_privateKey0~0 := ~value; {2938#true} is VALID [2022-02-20 17:59:59,820 INFO L290 TraceCheckUtils]: 2: Hoare triple {2938#true} assume true; {2938#true} is VALID [2022-02-20 17:59:59,820 INFO L284 TraceCheckUtils]: 3: Hoare quadruple {2938#true} {2939#false} #1144#return; {2939#false} is VALID [2022-02-20 17:59:59,825 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 48 [2022-02-20 17:59:59,826 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-02-20 17:59:59,828 INFO L290 TraceCheckUtils]: 0: Hoare triple {3002#(and (= |old(~__ste_email_from0~0)| ~__ste_email_from0~0) (= |old(~__ste_email_from1~0)| ~__ste_email_from1~0))} ~handle := #in~handle;~value := #in~value; {2938#true} is VALID [2022-02-20 17:59:59,828 INFO L290 TraceCheckUtils]: 1: Hoare triple {2938#true} assume 1 == ~handle;~__ste_email_from0~0 := ~value; {2938#true} is VALID [2022-02-20 17:59:59,828 INFO L290 TraceCheckUtils]: 2: Hoare triple {2938#true} assume true; {2938#true} is VALID [2022-02-20 17:59:59,829 INFO L284 TraceCheckUtils]: 3: Hoare quadruple {2938#true} {2939#false} #1120#return; {2939#false} is VALID [2022-02-20 17:59:59,834 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 53 [2022-02-20 17:59:59,835 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-02-20 17:59:59,837 INFO L290 TraceCheckUtils]: 0: Hoare triple {3003#(and (= ~__ste_email_to0~0 |old(~__ste_email_to0~0)|) (= ~__ste_email_to1~0 |old(~__ste_email_to1~0)|))} ~handle := #in~handle;~value := #in~value; {2938#true} is VALID [2022-02-20 17:59:59,837 INFO L290 TraceCheckUtils]: 1: Hoare triple {2938#true} assume 1 == ~handle;~__ste_email_to0~0 := ~value; {2938#true} is VALID [2022-02-20 17:59:59,837 INFO L290 TraceCheckUtils]: 2: Hoare triple {2938#true} assume true; {2938#true} is VALID [2022-02-20 17:59:59,837 INFO L284 TraceCheckUtils]: 3: Hoare quadruple {2938#true} {2939#false} #1122#return; {2939#false} is VALID [2022-02-20 17:59:59,838 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 62 [2022-02-20 17:59:59,838 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-02-20 17:59:59,844 INFO L290 TraceCheckUtils]: 0: Hoare triple {2938#true} ~handle := #in~handle;havoc ~retValue_acc~20; {2938#true} is VALID [2022-02-20 17:59:59,844 INFO L290 TraceCheckUtils]: 1: Hoare triple {2938#true} assume 1 == ~handle;~retValue_acc~20 := ~__ste_client_privateKey0~0;#res := ~retValue_acc~20; {2938#true} is VALID [2022-02-20 17:59:59,844 INFO L290 TraceCheckUtils]: 2: Hoare triple {2938#true} assume true; {2938#true} is VALID [2022-02-20 17:59:59,844 INFO L284 TraceCheckUtils]: 3: Hoare quadruple {2938#true} {2939#false} #1054#return; {2939#false} is VALID [2022-02-20 17:59:59,844 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 70 [2022-02-20 17:59:59,845 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-02-20 17:59:59,848 INFO L290 TraceCheckUtils]: 0: Hoare triple {2938#true} ~handle := #in~handle;havoc ~retValue_acc~36; {2938#true} is VALID [2022-02-20 17:59:59,848 INFO L290 TraceCheckUtils]: 1: Hoare triple {2938#true} assume 1 == ~handle;~retValue_acc~36 := ~__ste_email_to0~0;#res := ~retValue_acc~36; {2938#true} is VALID [2022-02-20 17:59:59,848 INFO L290 TraceCheckUtils]: 2: Hoare triple {2938#true} assume true; {2938#true} is VALID [2022-02-20 17:59:59,848 INFO L284 TraceCheckUtils]: 3: Hoare quadruple {2938#true} {2939#false} #1056#return; {2939#false} is VALID [2022-02-20 17:59:59,848 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 76 [2022-02-20 17:59:59,849 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-02-20 17:59:59,851 INFO L290 TraceCheckUtils]: 0: Hoare triple {2938#true} ~handle := #in~handle;~userid := #in~userid;havoc ~retValue_acc~25; {2938#true} is VALID [2022-02-20 17:59:59,851 INFO L290 TraceCheckUtils]: 1: Hoare triple {2938#true} assume 1 == ~handle; {2938#true} is VALID [2022-02-20 17:59:59,851 INFO L290 TraceCheckUtils]: 2: Hoare triple {2938#true} assume ~userid == ~__ste_Client_Keyring0_User0~0;~retValue_acc~25 := ~__ste_Client_Keyring0_PublicKey0~0;#res := ~retValue_acc~25; {2938#true} is VALID [2022-02-20 17:59:59,851 INFO L290 TraceCheckUtils]: 3: Hoare triple {2938#true} assume true; {2938#true} is VALID [2022-02-20 17:59:59,851 INFO L284 TraceCheckUtils]: 4: Hoare quadruple {2938#true} {2939#false} #1058#return; {2939#false} is VALID [2022-02-20 17:59:59,851 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 87 [2022-02-20 17:59:59,852 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-02-20 17:59:59,854 INFO L290 TraceCheckUtils]: 0: Hoare triple {3002#(and (= |old(~__ste_email_from0~0)| ~__ste_email_from0~0) (= |old(~__ste_email_from1~0)| ~__ste_email_from1~0))} ~handle := #in~handle;~value := #in~value; {2938#true} is VALID [2022-02-20 17:59:59,854 INFO L290 TraceCheckUtils]: 1: Hoare triple {2938#true} assume 1 == ~handle;~__ste_email_from0~0 := ~value; {2938#true} is VALID [2022-02-20 17:59:59,854 INFO L290 TraceCheckUtils]: 2: Hoare triple {2938#true} assume true; {2938#true} is VALID [2022-02-20 17:59:59,855 INFO L284 TraceCheckUtils]: 3: Hoare quadruple {2938#true} {2939#false} #1064#return; {2939#false} is VALID [2022-02-20 17:59:59,855 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 93 [2022-02-20 17:59:59,856 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-02-20 17:59:59,858 INFO L290 TraceCheckUtils]: 0: Hoare triple {2938#true} ~handle := #in~handle;havoc ~retValue_acc~41; {2938#true} is VALID [2022-02-20 17:59:59,858 INFO L290 TraceCheckUtils]: 1: Hoare triple {2938#true} assume 1 == ~handle;~retValue_acc~41 := ~__ste_email_isSigned0~0;#res := ~retValue_acc~41; {2938#true} is VALID [2022-02-20 17:59:59,858 INFO L290 TraceCheckUtils]: 2: Hoare triple {2938#true} assume true; {2938#true} is VALID [2022-02-20 17:59:59,858 INFO L284 TraceCheckUtils]: 3: Hoare quadruple {2938#true} {2939#false} #1066#return; {2939#false} is VALID [2022-02-20 17:59:59,858 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 100 [2022-02-20 17:59:59,859 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-02-20 17:59:59,861 INFO L290 TraceCheckUtils]: 0: Hoare triple {2938#true} ~handle := #in~handle;havoc ~retValue_acc~20; {2938#true} is VALID [2022-02-20 17:59:59,861 INFO L290 TraceCheckUtils]: 1: Hoare triple {2938#true} assume 1 == ~handle;~retValue_acc~20 := ~__ste_client_privateKey0~0;#res := ~retValue_acc~20; {2938#true} is VALID [2022-02-20 17:59:59,861 INFO L290 TraceCheckUtils]: 2: Hoare triple {2938#true} assume true; {2938#true} is VALID [2022-02-20 17:59:59,861 INFO L284 TraceCheckUtils]: 3: Hoare quadruple {2938#true} {2939#false} #1068#return; {2939#false} is VALID [2022-02-20 17:59:59,862 INFO L290 TraceCheckUtils]: 0: Hoare triple {2938#true} assume { :begin_inline_ULTIMATE.init } true;#NULL.base, #NULL.offset := 0, 0;assume 0 == #valid[0];assume 0 < #StackHeapBarrier;call #Ultimate.allocInit(2, 1);call write~init~int(48, 1, 0, 1);call write~init~int(0, 1, 1, 1);call #Ultimate.allocInit(28, 2);call #Ultimate.allocInit(12, 3);call #Ultimate.allocInit(30, 4);call #Ultimate.allocInit(9, 5);call #Ultimate.allocInit(21, 6);call #Ultimate.allocInit(30, 7);call #Ultimate.allocInit(9, 8);call #Ultimate.allocInit(21, 9);call #Ultimate.allocInit(30, 10);call #Ultimate.allocInit(9, 11);call #Ultimate.allocInit(25, 12);call #Ultimate.allocInit(30, 13);call #Ultimate.allocInit(9, 14);call #Ultimate.allocInit(25, 15);call #Ultimate.allocInit(44, 16);call #Ultimate.allocInit(44, 17);call #Ultimate.allocInit(9, 18);call #Ultimate.allocInit(9, 19);call #Ultimate.allocInit(11, 20);call #Ultimate.allocInit(19, 21);call #Ultimate.allocInit(4, 22);call write~init~int(37, 22, 0, 1);call write~init~int(100, 22, 1, 1);call write~init~int(10, 22, 2, 1);call write~init~int(0, 22, 3, 1);call #Ultimate.allocInit(4, 23);call write~init~int(37, 23, 0, 1);call write~init~int(100, 23, 1, 1);call write~init~int(10, 23, 2, 1);call write~init~int(0, 23, 3, 1);call #Ultimate.allocInit(10, 24);call #Ultimate.allocInit(16, 25);call #Ultimate.allocInit(20, 26);call #Ultimate.allocInit(22, 27);call #Ultimate.allocInit(21, 28);call #Ultimate.allocInit(10, 29);call #Ultimate.allocInit(12, 30);call #Ultimate.allocInit(10, 31);call #Ultimate.allocInit(18, 32);call #Ultimate.allocInit(16, 33);call #Ultimate.allocInit(21, 34);call #Ultimate.allocInit(13, 35);call #Ultimate.allocInit(16, 36);call #Ultimate.allocInit(25, 37);call #Ultimate.allocInit(4, 38);call write~init~int(37, 38, 0, 1);call write~init~int(115, 38, 1, 1);call write~init~int(10, 38, 2, 1);call write~init~int(0, 38, 3, 1);call #Ultimate.allocInit(13, 39);~head~0.base, ~head~0.offset := 0, 0;~__SELECTED_FEATURE_Base~0 := 0;~__SELECTED_FEATURE_Keys~0 := 0;~__SELECTED_FEATURE_Encrypt~0 := 0;~__SELECTED_FEATURE_AutoResponder~0 := 0;~__SELECTED_FEATURE_AddressBook~0 := 0;~__SELECTED_FEATURE_Sign~0 := 0;~__SELECTED_FEATURE_Forward~0 := 0;~__SELECTED_FEATURE_Verify~0 := 0;~__SELECTED_FEATURE_Decrypt~0 := 0;~__GUIDSL_ROOT_PRODUCTION~0 := 0;~__GUIDSL_NON_TERMINAL_main~0 := 0;~bob~0 := 0;~rjh~0 := 0;~chuck~0 := 0;~queue_empty~0 := 1;~queued_message~0 := 0;~queued_client~0 := 0;~__ste_Client_counter~0 := 0;~__ste_client_name0~0.base, ~__ste_client_name0~0.offset := 0, 0;~__ste_client_name1~0.base, ~__ste_client_name1~0.offset := 0, 0;~__ste_client_name2~0.base, ~__ste_client_name2~0.offset := 0, 0;~__ste_client_outbuffer0~0 := 0;~__ste_client_outbuffer1~0 := 0;~__ste_client_outbuffer2~0 := 0;~__ste_client_outbuffer3~0 := 0;~__ste_ClientAddressBook_size0~0 := 0;~__ste_ClientAddressBook_size1~0 := 0;~__ste_ClientAddressBook_size2~0 := 0;~__ste_Client_AddressBook0_Alias0~0 := 0;~__ste_Client_AddressBook0_Alias1~0 := 0;~__ste_Client_AddressBook0_Alias2~0 := 0;~__ste_Client_AddressBook1_Alias0~0 := 0;~__ste_Client_AddressBook1_Alias1~0 := 0;~__ste_Client_AddressBook1_Alias2~0 := 0;~__ste_Client_AddressBook2_Alias0~0 := 0;~__ste_Client_AddressBook2_Alias1~0 := 0;~__ste_Client_AddressBook2_Alias2~0 := 0;~__ste_Client_AddressBook0_Address0~0 := 0;~__ste_Client_AddressBook0_Address1~0 := 0;~__ste_Client_AddressBook0_Address2~0 := 0;~__ste_Client_AddressBook1_Address0~0 := 0;~__ste_Client_AddressBook1_Address1~0 := 0;~__ste_Client_AddressBook1_Address2~0 := 0;~__ste_Client_AddressBook2_Address0~0 := 0;~__ste_Client_AddressBook2_Address1~0 := 0;~__ste_Client_AddressBook2_Address2~0 := 0;~__ste_client_autoResponse0~0 := 0;~__ste_client_autoResponse1~0 := 0;~__ste_client_autoResponse2~0 := 0;~__ste_client_privateKey0~0 := 0;~__ste_client_privateKey1~0 := 0;~__ste_client_privateKey2~0 := 0;~__ste_ClientKeyring_size0~0 := 0;~__ste_ClientKeyring_size1~0 := 0;~__ste_ClientKeyring_size2~0 := 0;~__ste_Client_Keyring0_User0~0 := 0;~__ste_Client_Keyring0_User1~0 := 0;~__ste_Client_Keyring0_User2~0 := 0;~__ste_Client_Keyring1_User0~0 := 0;~__ste_Client_Keyring1_User1~0 := 0;~__ste_Client_Keyring1_User2~0 := 0;~__ste_Client_Keyring2_User0~0 := 0;~__ste_Client_Keyring2_User1~0 := 0;~__ste_Client_Keyring2_User2~0 := 0;~__ste_Client_Keyring0_PublicKey0~0 := 0;~__ste_Client_Keyring0_PublicKey1~0 := 0;~__ste_Client_Keyring0_PublicKey2~0 := 0;~__ste_Client_Keyring1_PublicKey0~0 := 0;~__ste_Client_Keyring1_PublicKey1~0 := 0;~__ste_Client_Keyring1_PublicKey2~0 := 0;~__ste_Client_Keyring2_PublicKey0~0 := 0;~__ste_Client_Keyring2_PublicKey1~0 := 0;~__ste_Client_Keyring2_PublicKey2~0 := 0;~__ste_client_forwardReceiver0~0 := 0;~__ste_client_forwardReceiver1~0 := 0;~__ste_client_forwardReceiver2~0 := 0;~__ste_client_forwardReceiver3~0 := 0;~__ste_client_idCounter0~0 := 0;~__ste_client_idCounter1~0 := 0;~__ste_client_idCounter2~0 := 0;~__ste_Email_counter~0 := 0;~__ste_email_id0~0 := 0;~__ste_email_id1~0 := 0;~__ste_email_from0~0 := 0;~__ste_email_from1~0 := 0;~__ste_email_to0~0 := 0;~__ste_email_to1~0 := 0;~__ste_email_subject0~0.base, ~__ste_email_subject0~0.offset := 0, 0;~__ste_email_subject1~0.base, ~__ste_email_subject1~0.offset := 0, 0;~__ste_email_body0~0.base, ~__ste_email_body0~0.offset := 0, 0;~__ste_email_body1~0.base, ~__ste_email_body1~0.offset := 0, 0;~__ste_email_isEncrypted0~0 := 0;~__ste_email_isEncrypted1~0 := 0;~__ste_email_encryptionKey0~0 := 0;~__ste_email_encryptionKey1~0 := 0;~__ste_email_isSigned0~0 := 0;~__ste_email_isSigned1~0 := 0;~__ste_email_signKey0~0 := 0;~__ste_email_signKey1~0 := 0;~__ste_email_isSignatureVerified0~0 := 0;~__ste_email_isSignatureVerified1~0 := 0; {2938#true} is VALID [2022-02-20 17:59:59,862 INFO L290 TraceCheckUtils]: 1: Hoare triple {2938#true} assume { :end_inline_ULTIMATE.init } true;assume { :begin_inline_main } true;havoc main_#res#1;havoc main_#t~ret35#1, main_~retValue_acc~3#1, main_~tmp~4#1;havoc main_~retValue_acc~3#1;havoc main_~tmp~4#1;assume { :begin_inline_select_helpers } true; {2938#true} is VALID [2022-02-20 17:59:59,862 INFO L290 TraceCheckUtils]: 2: Hoare triple {2938#true} assume { :end_inline_select_helpers } true;assume { :begin_inline_select_features } true; {2938#true} is VALID [2022-02-20 17:59:59,862 INFO L290 TraceCheckUtils]: 3: Hoare triple {2938#true} assume { :end_inline_select_features } true;assume { :begin_inline_valid_product } true;havoc valid_product_#res#1;havoc valid_product_~retValue_acc~5#1;havoc valid_product_~retValue_acc~5#1;valid_product_~retValue_acc~5#1 := 1;valid_product_#res#1 := valid_product_~retValue_acc~5#1; {2938#true} is VALID [2022-02-20 17:59:59,862 INFO L290 TraceCheckUtils]: 4: Hoare triple {2938#true} main_#t~ret35#1 := valid_product_#res#1;assume { :end_inline_valid_product } true;assume -2147483648 <= main_#t~ret35#1 && main_#t~ret35#1 <= 2147483647;main_~tmp~4#1 := main_#t~ret35#1;havoc main_#t~ret35#1; {2938#true} is VALID [2022-02-20 17:59:59,862 INFO L290 TraceCheckUtils]: 5: Hoare triple {2938#true} assume 0 != main_~tmp~4#1;assume { :begin_inline_setup } true;havoc setup_#t~nondet32#1, setup_#t~nondet33#1, setup_#t~nondet34#1, setup_~__cil_tmp1~0#1.base, setup_~__cil_tmp1~0#1.offset, setup_~__cil_tmp2~0#1.base, setup_~__cil_tmp2~0#1.offset, setup_~__cil_tmp3~0#1.base, setup_~__cil_tmp3~0#1.offset;havoc setup_~__cil_tmp1~0#1.base, setup_~__cil_tmp1~0#1.offset;havoc setup_~__cil_tmp2~0#1.base, setup_~__cil_tmp2~0#1.offset;havoc setup_~__cil_tmp3~0#1.base, setup_~__cil_tmp3~0#1.offset;~bob~0 := 1;assume { :begin_inline_setup_bob } true;setup_bob_#in~bob___0#1 := ~bob~0;havoc setup_bob_~bob___0#1;setup_bob_~bob___0#1 := setup_bob_#in~bob___0#1;assume { :begin_inline_setup_bob__wrappee__Base } true;setup_bob__wrappee__Base_#in~bob___0#1 := setup_bob_~bob___0#1;havoc setup_bob__wrappee__Base_~bob___0#1;setup_bob__wrappee__Base_~bob___0#1 := setup_bob__wrappee__Base_#in~bob___0#1; {2938#true} is VALID [2022-02-20 17:59:59,863 INFO L272 TraceCheckUtils]: 6: Hoare triple {2938#true} call setClientId(setup_bob__wrappee__Base_~bob___0#1, setup_bob__wrappee__Base_~bob___0#1); {2998#(and (= |old(~__ste_client_idCounter0~0)| ~__ste_client_idCounter0~0) (= |old(~__ste_client_idCounter1~0)| ~__ste_client_idCounter1~0) (= |old(~__ste_client_idCounter2~0)| ~__ste_client_idCounter2~0))} is VALID [2022-02-20 17:59:59,863 INFO L290 TraceCheckUtils]: 7: Hoare triple {2998#(and (= |old(~__ste_client_idCounter0~0)| ~__ste_client_idCounter0~0) (= |old(~__ste_client_idCounter1~0)| ~__ste_client_idCounter1~0) (= |old(~__ste_client_idCounter2~0)| ~__ste_client_idCounter2~0))} ~handle := #in~handle;~value := #in~value; {2938#true} is VALID [2022-02-20 17:59:59,863 INFO L290 TraceCheckUtils]: 8: Hoare triple {2938#true} assume 1 == ~handle;~__ste_client_idCounter0~0 := ~value; {2938#true} is VALID [2022-02-20 17:59:59,863 INFO L290 TraceCheckUtils]: 9: Hoare triple {2938#true} assume true; {2938#true} is VALID [2022-02-20 17:59:59,863 INFO L284 TraceCheckUtils]: 10: Hoare quadruple {2938#true} {2938#true} #1134#return; {2938#true} is VALID [2022-02-20 17:59:59,864 INFO L290 TraceCheckUtils]: 11: Hoare triple {2938#true} assume { :end_inline_setup_bob__wrappee__Base } true; {2938#true} is VALID [2022-02-20 17:59:59,864 INFO L272 TraceCheckUtils]: 12: Hoare triple {2938#true} call setClientPrivateKey(setup_bob_~bob___0#1, 123); {2999#(and (= ~__ste_client_privateKey0~0 |old(~__ste_client_privateKey0~0)|) (= ~__ste_client_privateKey2~0 |old(~__ste_client_privateKey2~0)|) (= ~__ste_client_privateKey1~0 |old(~__ste_client_privateKey1~0)|))} is VALID [2022-02-20 17:59:59,864 INFO L290 TraceCheckUtils]: 13: Hoare triple {2999#(and (= ~__ste_client_privateKey0~0 |old(~__ste_client_privateKey0~0)|) (= ~__ste_client_privateKey2~0 |old(~__ste_client_privateKey2~0)|) (= ~__ste_client_privateKey1~0 |old(~__ste_client_privateKey1~0)|))} ~handle := #in~handle;~value := #in~value; {2938#true} is VALID [2022-02-20 17:59:59,864 INFO L290 TraceCheckUtils]: 14: Hoare triple {2938#true} assume 1 == ~handle;~__ste_client_privateKey0~0 := ~value; {2938#true} is VALID [2022-02-20 17:59:59,865 INFO L290 TraceCheckUtils]: 15: Hoare triple {2938#true} assume true; {2938#true} is VALID [2022-02-20 17:59:59,865 INFO L284 TraceCheckUtils]: 16: Hoare quadruple {2938#true} {2938#true} #1136#return; {2938#true} is VALID [2022-02-20 17:59:59,865 INFO L290 TraceCheckUtils]: 17: Hoare triple {2938#true} assume { :end_inline_setup_bob } true;setup_~__cil_tmp1~0#1.base, setup_~__cil_tmp1~0#1.offset := 18, 0;havoc setup_#t~nondet32#1;~rjh~0 := 2;assume { :begin_inline_setup_rjh } true;setup_rjh_#in~rjh___0#1 := ~rjh~0;havoc setup_rjh_~rjh___0#1;setup_rjh_~rjh___0#1 := setup_rjh_#in~rjh___0#1;assume { :begin_inline_setup_rjh__wrappee__Base } true;setup_rjh__wrappee__Base_#in~rjh___0#1 := setup_rjh_~rjh___0#1;havoc setup_rjh__wrappee__Base_~rjh___0#1;setup_rjh__wrappee__Base_~rjh___0#1 := setup_rjh__wrappee__Base_#in~rjh___0#1; {2948#(= |ULTIMATE.start_setup_rjh__wrappee__Base_~rjh___0#1| 2)} is VALID [2022-02-20 17:59:59,866 INFO L272 TraceCheckUtils]: 18: Hoare triple {2948#(= |ULTIMATE.start_setup_rjh__wrappee__Base_~rjh___0#1| 2)} call setClientId(setup_rjh__wrappee__Base_~rjh___0#1, setup_rjh__wrappee__Base_~rjh___0#1); {2998#(and (= |old(~__ste_client_idCounter0~0)| ~__ste_client_idCounter0~0) (= |old(~__ste_client_idCounter1~0)| ~__ste_client_idCounter1~0) (= |old(~__ste_client_idCounter2~0)| ~__ste_client_idCounter2~0))} is VALID [2022-02-20 17:59:59,866 INFO L290 TraceCheckUtils]: 19: Hoare triple {2998#(and (= |old(~__ste_client_idCounter0~0)| ~__ste_client_idCounter0~0) (= |old(~__ste_client_idCounter1~0)| ~__ste_client_idCounter1~0) (= |old(~__ste_client_idCounter2~0)| ~__ste_client_idCounter2~0))} ~handle := #in~handle;~value := #in~value; {3000#(= setClientId_~handle |setClientId_#in~handle|)} is VALID [2022-02-20 17:59:59,866 INFO L290 TraceCheckUtils]: 20: Hoare triple {3000#(= setClientId_~handle |setClientId_#in~handle|)} assume 1 == ~handle;~__ste_client_idCounter0~0 := ~value; {3001#(= |setClientId_#in~handle| 1)} is VALID [2022-02-20 17:59:59,867 INFO L290 TraceCheckUtils]: 21: Hoare triple {3001#(= |setClientId_#in~handle| 1)} assume true; {3001#(= |setClientId_#in~handle| 1)} is VALID [2022-02-20 17:59:59,868 INFO L284 TraceCheckUtils]: 22: Hoare quadruple {3001#(= |setClientId_#in~handle| 1)} {2948#(= |ULTIMATE.start_setup_rjh__wrappee__Base_~rjh___0#1| 2)} #1138#return; {2939#false} is VALID [2022-02-20 17:59:59,868 INFO L290 TraceCheckUtils]: 23: Hoare triple {2939#false} assume { :end_inline_setup_rjh__wrappee__Base } true; {2939#false} is VALID [2022-02-20 17:59:59,868 INFO L272 TraceCheckUtils]: 24: Hoare triple {2939#false} call setClientPrivateKey(setup_rjh_~rjh___0#1, 456); {2999#(and (= ~__ste_client_privateKey0~0 |old(~__ste_client_privateKey0~0)|) (= ~__ste_client_privateKey2~0 |old(~__ste_client_privateKey2~0)|) (= ~__ste_client_privateKey1~0 |old(~__ste_client_privateKey1~0)|))} is VALID [2022-02-20 17:59:59,868 INFO L290 TraceCheckUtils]: 25: Hoare triple {2999#(and (= ~__ste_client_privateKey0~0 |old(~__ste_client_privateKey0~0)|) (= ~__ste_client_privateKey2~0 |old(~__ste_client_privateKey2~0)|) (= ~__ste_client_privateKey1~0 |old(~__ste_client_privateKey1~0)|))} ~handle := #in~handle;~value := #in~value; {2938#true} is VALID [2022-02-20 17:59:59,868 INFO L290 TraceCheckUtils]: 26: Hoare triple {2938#true} assume 1 == ~handle;~__ste_client_privateKey0~0 := ~value; {2938#true} is VALID [2022-02-20 17:59:59,868 INFO L290 TraceCheckUtils]: 27: Hoare triple {2938#true} assume true; {2938#true} is VALID [2022-02-20 17:59:59,868 INFO L284 TraceCheckUtils]: 28: Hoare quadruple {2938#true} {2939#false} #1140#return; {2939#false} is VALID [2022-02-20 17:59:59,869 INFO L290 TraceCheckUtils]: 29: Hoare triple {2939#false} assume { :end_inline_setup_rjh } true;setup_~__cil_tmp2~0#1.base, setup_~__cil_tmp2~0#1.offset := 19, 0;havoc setup_#t~nondet33#1;~chuck~0 := 3;assume { :begin_inline_setup_chuck } true;setup_chuck_#in~chuck___0#1 := ~chuck~0;havoc setup_chuck_~chuck___0#1;setup_chuck_~chuck___0#1 := setup_chuck_#in~chuck___0#1;assume { :begin_inline_setup_chuck__wrappee__Base } true;setup_chuck__wrappee__Base_#in~chuck___0#1 := setup_chuck_~chuck___0#1;havoc setup_chuck__wrappee__Base_~chuck___0#1;setup_chuck__wrappee__Base_~chuck___0#1 := setup_chuck__wrappee__Base_#in~chuck___0#1; {2939#false} is VALID [2022-02-20 17:59:59,869 INFO L272 TraceCheckUtils]: 30: Hoare triple {2939#false} call setClientId(setup_chuck__wrappee__Base_~chuck___0#1, setup_chuck__wrappee__Base_~chuck___0#1); {2998#(and (= |old(~__ste_client_idCounter0~0)| ~__ste_client_idCounter0~0) (= |old(~__ste_client_idCounter1~0)| ~__ste_client_idCounter1~0) (= |old(~__ste_client_idCounter2~0)| ~__ste_client_idCounter2~0))} is VALID [2022-02-20 17:59:59,869 INFO L290 TraceCheckUtils]: 31: Hoare triple {2998#(and (= |old(~__ste_client_idCounter0~0)| ~__ste_client_idCounter0~0) (= |old(~__ste_client_idCounter1~0)| ~__ste_client_idCounter1~0) (= |old(~__ste_client_idCounter2~0)| ~__ste_client_idCounter2~0))} ~handle := #in~handle;~value := #in~value; {2938#true} is VALID [2022-02-20 17:59:59,869 INFO L290 TraceCheckUtils]: 32: Hoare triple {2938#true} assume 1 == ~handle;~__ste_client_idCounter0~0 := ~value; {2938#true} is VALID [2022-02-20 17:59:59,869 INFO L290 TraceCheckUtils]: 33: Hoare triple {2938#true} assume true; {2938#true} is VALID [2022-02-20 17:59:59,869 INFO L284 TraceCheckUtils]: 34: Hoare quadruple {2938#true} {2939#false} #1142#return; {2939#false} is VALID [2022-02-20 17:59:59,869 INFO L290 TraceCheckUtils]: 35: Hoare triple {2939#false} assume { :end_inline_setup_chuck__wrappee__Base } true; {2939#false} is VALID [2022-02-20 17:59:59,869 INFO L272 TraceCheckUtils]: 36: Hoare triple {2939#false} call setClientPrivateKey(setup_chuck_~chuck___0#1, 789); {2999#(and (= ~__ste_client_privateKey0~0 |old(~__ste_client_privateKey0~0)|) (= ~__ste_client_privateKey2~0 |old(~__ste_client_privateKey2~0)|) (= ~__ste_client_privateKey1~0 |old(~__ste_client_privateKey1~0)|))} is VALID [2022-02-20 17:59:59,870 INFO L290 TraceCheckUtils]: 37: Hoare triple {2999#(and (= ~__ste_client_privateKey0~0 |old(~__ste_client_privateKey0~0)|) (= ~__ste_client_privateKey2~0 |old(~__ste_client_privateKey2~0)|) (= ~__ste_client_privateKey1~0 |old(~__ste_client_privateKey1~0)|))} ~handle := #in~handle;~value := #in~value; {2938#true} is VALID [2022-02-20 17:59:59,870 INFO L290 TraceCheckUtils]: 38: Hoare triple {2938#true} assume 1 == ~handle;~__ste_client_privateKey0~0 := ~value; {2938#true} is VALID [2022-02-20 17:59:59,870 INFO L290 TraceCheckUtils]: 39: Hoare triple {2938#true} assume true; {2938#true} is VALID [2022-02-20 17:59:59,870 INFO L284 TraceCheckUtils]: 40: Hoare quadruple {2938#true} {2939#false} #1144#return; {2939#false} is VALID [2022-02-20 17:59:59,870 INFO L290 TraceCheckUtils]: 41: Hoare triple {2939#false} assume { :end_inline_setup_chuck } true;setup_~__cil_tmp3~0#1.base, setup_~__cil_tmp3~0#1.offset := 20, 0;havoc setup_#t~nondet34#1; {2939#false} is VALID [2022-02-20 17:59:59,870 INFO L290 TraceCheckUtils]: 42: Hoare triple {2939#false} assume { :end_inline_setup } true;assume { :begin_inline_test } true;havoc test_#t~nondet47#1, test_#t~nondet48#1, test_#t~nondet49#1, test_#t~nondet50#1, test_#t~nondet51#1, test_#t~nondet52#1, test_#t~nondet53#1, test_#t~nondet54#1, test_#t~nondet55#1, test_#t~nondet56#1, test_#t~nondet57#1, test_~op1~0#1, test_~op2~0#1, test_~op3~0#1, test_~op4~0#1, test_~op5~0#1, test_~op6~0#1, test_~op7~0#1, test_~op8~0#1, test_~op9~0#1, test_~op10~0#1, test_~op11~0#1, test_~splverifierCounter~0#1, test_~tmp~6#1, test_~tmp___0~2#1, test_~tmp___1~1#1, test_~tmp___2~0#1, test_~tmp___3~0#1, test_~tmp___4~0#1, test_~tmp___5~0#1, test_~tmp___6~0#1, test_~tmp___7~0#1, test_~tmp___8~0#1, test_~tmp___9~0#1;havoc test_~op1~0#1;havoc test_~op2~0#1;havoc test_~op3~0#1;havoc test_~op4~0#1;havoc test_~op5~0#1;havoc test_~op6~0#1;havoc test_~op7~0#1;havoc test_~op8~0#1;havoc test_~op9~0#1;havoc test_~op10~0#1;havoc test_~op11~0#1;havoc test_~splverifierCounter~0#1;havoc test_~tmp~6#1;havoc test_~tmp___0~2#1;havoc test_~tmp___1~1#1;havoc test_~tmp___2~0#1;havoc test_~tmp___3~0#1;havoc test_~tmp___4~0#1;havoc test_~tmp___5~0#1;havoc test_~tmp___6~0#1;havoc test_~tmp___7~0#1;havoc test_~tmp___8~0#1;havoc test_~tmp___9~0#1;test_~op1~0#1 := 0;test_~op2~0#1 := 0;test_~op3~0#1 := 0;test_~op4~0#1 := 0;test_~op5~0#1 := 0;test_~op6~0#1 := 0;test_~op7~0#1 := 0;test_~op8~0#1 := 0;test_~op9~0#1 := 0;test_~op10~0#1 := 0;test_~op11~0#1 := 0;test_~splverifierCounter~0#1 := 0; {2939#false} is VALID [2022-02-20 17:59:59,870 INFO L290 TraceCheckUtils]: 43: Hoare triple {2939#false} assume !false; {2939#false} is VALID [2022-02-20 17:59:59,871 INFO L290 TraceCheckUtils]: 44: Hoare triple {2939#false} assume !(test_~splverifierCounter~0#1 < 4); {2939#false} is VALID [2022-02-20 17:59:59,871 INFO L290 TraceCheckUtils]: 45: Hoare triple {2939#false} assume { :begin_inline_bobToRjh } true;havoc bobToRjh_#t~ret27#1, bobToRjh_#t~ret28#1, bobToRjh_#t~ret29#1, bobToRjh_#t~ret30#1, bobToRjh_~tmp~3#1, bobToRjh_~tmp___0~0#1, bobToRjh_~tmp___1~0#1;havoc bobToRjh_~tmp~3#1;havoc bobToRjh_~tmp___0~0#1;havoc bobToRjh_~tmp___1~0#1;call bobToRjh_#t~ret27#1 := puts(16, 0);assume -2147483648 <= bobToRjh_#t~ret27#1 && bobToRjh_#t~ret27#1 <= 2147483647;havoc bobToRjh_#t~ret27#1; {2939#false} is VALID [2022-02-20 17:59:59,871 INFO L272 TraceCheckUtils]: 46: Hoare triple {2939#false} call sendEmail(~bob~0, ~rjh~0); {2939#false} is VALID [2022-02-20 17:59:59,871 INFO L290 TraceCheckUtils]: 47: Hoare triple {2939#false} ~sender#1 := #in~sender#1;~receiver#1 := #in~receiver#1;havoc ~email~0#1;havoc ~tmp~14#1;assume { :begin_inline_createEmail } true;createEmail_#in~from#1, createEmail_#in~to#1 := 0, ~receiver#1;havoc createEmail_#res#1;havoc createEmail_~from#1, createEmail_~to#1, createEmail_~retValue_acc~31#1, createEmail_~msg~0#1;createEmail_~from#1 := createEmail_#in~from#1;createEmail_~to#1 := createEmail_#in~to#1;havoc createEmail_~retValue_acc~31#1;havoc createEmail_~msg~0#1;createEmail_~msg~0#1 := 1; {2939#false} is VALID [2022-02-20 17:59:59,871 INFO L272 TraceCheckUtils]: 48: Hoare triple {2939#false} call setEmailFrom(createEmail_~msg~0#1, createEmail_~from#1); {3002#(and (= |old(~__ste_email_from0~0)| ~__ste_email_from0~0) (= |old(~__ste_email_from1~0)| ~__ste_email_from1~0))} is VALID [2022-02-20 17:59:59,871 INFO L290 TraceCheckUtils]: 49: Hoare triple {3002#(and (= |old(~__ste_email_from0~0)| ~__ste_email_from0~0) (= |old(~__ste_email_from1~0)| ~__ste_email_from1~0))} ~handle := #in~handle;~value := #in~value; {2938#true} is VALID [2022-02-20 17:59:59,871 INFO L290 TraceCheckUtils]: 50: Hoare triple {2938#true} assume 1 == ~handle;~__ste_email_from0~0 := ~value; {2938#true} is VALID [2022-02-20 17:59:59,872 INFO L290 TraceCheckUtils]: 51: Hoare triple {2938#true} assume true; {2938#true} is VALID [2022-02-20 17:59:59,872 INFO L284 TraceCheckUtils]: 52: Hoare quadruple {2938#true} {2939#false} #1120#return; {2939#false} is VALID [2022-02-20 17:59:59,872 INFO L272 TraceCheckUtils]: 53: Hoare triple {2939#false} call setEmailTo(createEmail_~msg~0#1, createEmail_~to#1); {3003#(and (= ~__ste_email_to0~0 |old(~__ste_email_to0~0)|) (= ~__ste_email_to1~0 |old(~__ste_email_to1~0)|))} is VALID [2022-02-20 17:59:59,872 INFO L290 TraceCheckUtils]: 54: Hoare triple {3003#(and (= ~__ste_email_to0~0 |old(~__ste_email_to0~0)|) (= ~__ste_email_to1~0 |old(~__ste_email_to1~0)|))} ~handle := #in~handle;~value := #in~value; {2938#true} is VALID [2022-02-20 17:59:59,872 INFO L290 TraceCheckUtils]: 55: Hoare triple {2938#true} assume 1 == ~handle;~__ste_email_to0~0 := ~value; {2938#true} is VALID [2022-02-20 17:59:59,872 INFO L290 TraceCheckUtils]: 56: Hoare triple {2938#true} assume true; {2938#true} is VALID [2022-02-20 17:59:59,872 INFO L284 TraceCheckUtils]: 57: Hoare quadruple {2938#true} {2939#false} #1122#return; {2939#false} is VALID [2022-02-20 17:59:59,872 INFO L290 TraceCheckUtils]: 58: Hoare triple {2939#false} createEmail_~retValue_acc~31#1 := createEmail_~msg~0#1;createEmail_#res#1 := createEmail_~retValue_acc~31#1; {2939#false} is VALID [2022-02-20 17:59:59,873 INFO L290 TraceCheckUtils]: 59: Hoare triple {2939#false} #t~ret72#1 := createEmail_#res#1;assume { :end_inline_createEmail } true;assume -2147483648 <= #t~ret72#1 && #t~ret72#1 <= 2147483647;~tmp~14#1 := #t~ret72#1;havoc #t~ret72#1;~email~0#1 := ~tmp~14#1; {2939#false} is VALID [2022-02-20 17:59:59,873 INFO L272 TraceCheckUtils]: 60: Hoare triple {2939#false} call outgoing(~sender#1, ~email~0#1); {2939#false} is VALID [2022-02-20 17:59:59,873 INFO L290 TraceCheckUtils]: 61: Hoare triple {2939#false} ~client#1 := #in~client#1;~msg#1 := #in~msg#1;assume { :begin_inline_sign } true;sign_#in~client#1, sign_#in~msg#1 := ~client#1, ~msg#1;havoc sign_#t~ret76#1, sign_~client#1, sign_~msg#1, sign_~privkey~1#1, sign_~tmp~16#1;sign_~client#1 := sign_#in~client#1;sign_~msg#1 := sign_#in~msg#1;havoc sign_~privkey~1#1;havoc sign_~tmp~16#1; {2939#false} is VALID [2022-02-20 17:59:59,873 INFO L272 TraceCheckUtils]: 62: Hoare triple {2939#false} call sign_#t~ret76#1 := getClientPrivateKey(sign_~client#1); {2938#true} is VALID [2022-02-20 17:59:59,873 INFO L290 TraceCheckUtils]: 63: Hoare triple {2938#true} ~handle := #in~handle;havoc ~retValue_acc~20; {2938#true} is VALID [2022-02-20 17:59:59,873 INFO L290 TraceCheckUtils]: 64: Hoare triple {2938#true} assume 1 == ~handle;~retValue_acc~20 := ~__ste_client_privateKey0~0;#res := ~retValue_acc~20; {2938#true} is VALID [2022-02-20 17:59:59,873 INFO L290 TraceCheckUtils]: 65: Hoare triple {2938#true} assume true; {2938#true} is VALID [2022-02-20 17:59:59,873 INFO L284 TraceCheckUtils]: 66: Hoare quadruple {2938#true} {2939#false} #1054#return; {2939#false} is VALID [2022-02-20 17:59:59,873 INFO L290 TraceCheckUtils]: 67: Hoare triple {2939#false} assume -2147483648 <= sign_#t~ret76#1 && sign_#t~ret76#1 <= 2147483647;sign_~tmp~16#1 := sign_#t~ret76#1;havoc sign_#t~ret76#1;sign_~privkey~1#1 := sign_~tmp~16#1; {2939#false} is VALID [2022-02-20 17:59:59,874 INFO L290 TraceCheckUtils]: 68: Hoare triple {2939#false} assume 0 == sign_~privkey~1#1; {2939#false} is VALID [2022-02-20 17:59:59,874 INFO L290 TraceCheckUtils]: 69: Hoare triple {2939#false} assume { :end_inline_sign } true;assume { :begin_inline_outgoing__wrappee__AutoResponder } true;outgoing__wrappee__AutoResponder_#in~client#1, outgoing__wrappee__AutoResponder_#in~msg#1 := ~client#1, ~msg#1;havoc outgoing__wrappee__AutoResponder_#t~ret62#1, outgoing__wrappee__AutoResponder_#t~ret63#1, outgoing__wrappee__AutoResponder_~client#1, outgoing__wrappee__AutoResponder_~msg#1, outgoing__wrappee__AutoResponder_~receiver~0#1, outgoing__wrappee__AutoResponder_~tmp~9#1, outgoing__wrappee__AutoResponder_~pubkey~0#1, outgoing__wrappee__AutoResponder_~tmp___0~3#1;outgoing__wrappee__AutoResponder_~client#1 := outgoing__wrappee__AutoResponder_#in~client#1;outgoing__wrappee__AutoResponder_~msg#1 := outgoing__wrappee__AutoResponder_#in~msg#1;havoc outgoing__wrappee__AutoResponder_~receiver~0#1;havoc outgoing__wrappee__AutoResponder_~tmp~9#1;havoc outgoing__wrappee__AutoResponder_~pubkey~0#1;havoc outgoing__wrappee__AutoResponder_~tmp___0~3#1; {2939#false} is VALID [2022-02-20 17:59:59,874 INFO L272 TraceCheckUtils]: 70: Hoare triple {2939#false} call outgoing__wrappee__AutoResponder_#t~ret62#1 := getEmailTo(outgoing__wrappee__AutoResponder_~msg#1); {2938#true} is VALID [2022-02-20 17:59:59,874 INFO L290 TraceCheckUtils]: 71: Hoare triple {2938#true} ~handle := #in~handle;havoc ~retValue_acc~36; {2938#true} is VALID [2022-02-20 17:59:59,874 INFO L290 TraceCheckUtils]: 72: Hoare triple {2938#true} assume 1 == ~handle;~retValue_acc~36 := ~__ste_email_to0~0;#res := ~retValue_acc~36; {2938#true} is VALID [2022-02-20 17:59:59,874 INFO L290 TraceCheckUtils]: 73: Hoare triple {2938#true} assume true; {2938#true} is VALID [2022-02-20 17:59:59,874 INFO L284 TraceCheckUtils]: 74: Hoare quadruple {2938#true} {2939#false} #1056#return; {2939#false} is VALID [2022-02-20 17:59:59,874 INFO L290 TraceCheckUtils]: 75: Hoare triple {2939#false} assume -2147483648 <= outgoing__wrappee__AutoResponder_#t~ret62#1 && outgoing__wrappee__AutoResponder_#t~ret62#1 <= 2147483647;outgoing__wrappee__AutoResponder_~tmp~9#1 := outgoing__wrappee__AutoResponder_#t~ret62#1;havoc outgoing__wrappee__AutoResponder_#t~ret62#1;outgoing__wrappee__AutoResponder_~receiver~0#1 := outgoing__wrappee__AutoResponder_~tmp~9#1; {2939#false} is VALID [2022-02-20 17:59:59,875 INFO L272 TraceCheckUtils]: 76: Hoare triple {2939#false} call outgoing__wrappee__AutoResponder_#t~ret63#1 := findPublicKey(outgoing__wrappee__AutoResponder_~client#1, outgoing__wrappee__AutoResponder_~receiver~0#1); {2938#true} is VALID [2022-02-20 17:59:59,875 INFO L290 TraceCheckUtils]: 77: Hoare triple {2938#true} ~handle := #in~handle;~userid := #in~userid;havoc ~retValue_acc~25; {2938#true} is VALID [2022-02-20 17:59:59,875 INFO L290 TraceCheckUtils]: 78: Hoare triple {2938#true} assume 1 == ~handle; {2938#true} is VALID [2022-02-20 17:59:59,875 INFO L290 TraceCheckUtils]: 79: Hoare triple {2938#true} assume ~userid == ~__ste_Client_Keyring0_User0~0;~retValue_acc~25 := ~__ste_Client_Keyring0_PublicKey0~0;#res := ~retValue_acc~25; {2938#true} is VALID [2022-02-20 17:59:59,875 INFO L290 TraceCheckUtils]: 80: Hoare triple {2938#true} assume true; {2938#true} is VALID [2022-02-20 17:59:59,875 INFO L284 TraceCheckUtils]: 81: Hoare quadruple {2938#true} {2939#false} #1058#return; {2939#false} is VALID [2022-02-20 17:59:59,875 INFO L290 TraceCheckUtils]: 82: Hoare triple {2939#false} assume -2147483648 <= outgoing__wrappee__AutoResponder_#t~ret63#1 && outgoing__wrappee__AutoResponder_#t~ret63#1 <= 2147483647;outgoing__wrappee__AutoResponder_~tmp___0~3#1 := outgoing__wrappee__AutoResponder_#t~ret63#1;havoc outgoing__wrappee__AutoResponder_#t~ret63#1;outgoing__wrappee__AutoResponder_~pubkey~0#1 := outgoing__wrappee__AutoResponder_~tmp___0~3#1; {2939#false} is VALID [2022-02-20 17:59:59,875 INFO L290 TraceCheckUtils]: 83: Hoare triple {2939#false} assume !(0 != outgoing__wrappee__AutoResponder_~pubkey~0#1); {2939#false} is VALID [2022-02-20 17:59:59,876 INFO L290 TraceCheckUtils]: 84: Hoare triple {2939#false} assume { :begin_inline_outgoing__wrappee__Keys } true;outgoing__wrappee__Keys_#in~client#1, outgoing__wrappee__Keys_#in~msg#1 := outgoing__wrappee__AutoResponder_~client#1, outgoing__wrappee__AutoResponder_~msg#1;havoc outgoing__wrappee__Keys_#t~ret61#1, outgoing__wrappee__Keys_~client#1, outgoing__wrappee__Keys_~msg#1, outgoing__wrappee__Keys_~tmp~8#1;outgoing__wrappee__Keys_~client#1 := outgoing__wrappee__Keys_#in~client#1;outgoing__wrappee__Keys_~msg#1 := outgoing__wrappee__Keys_#in~msg#1;havoc outgoing__wrappee__Keys_~tmp~8#1;assume { :begin_inline_getClientId } true;getClientId_#in~handle#1 := outgoing__wrappee__Keys_~client#1;havoc getClientId_#res#1;havoc getClientId_~handle#1, getClientId_~retValue_acc~27#1;getClientId_~handle#1 := getClientId_#in~handle#1;havoc getClientId_~retValue_acc~27#1; {2939#false} is VALID [2022-02-20 17:59:59,876 INFO L290 TraceCheckUtils]: 85: Hoare triple {2939#false} assume 1 == getClientId_~handle#1;getClientId_~retValue_acc~27#1 := ~__ste_client_idCounter0~0;getClientId_#res#1 := getClientId_~retValue_acc~27#1; {2939#false} is VALID [2022-02-20 17:59:59,876 INFO L290 TraceCheckUtils]: 86: Hoare triple {2939#false} outgoing__wrappee__Keys_#t~ret61#1 := getClientId_#res#1;assume { :end_inline_getClientId } true;assume -2147483648 <= outgoing__wrappee__Keys_#t~ret61#1 && outgoing__wrappee__Keys_#t~ret61#1 <= 2147483647;outgoing__wrappee__Keys_~tmp~8#1 := outgoing__wrappee__Keys_#t~ret61#1;havoc outgoing__wrappee__Keys_#t~ret61#1; {2939#false} is VALID [2022-02-20 17:59:59,876 INFO L272 TraceCheckUtils]: 87: Hoare triple {2939#false} call setEmailFrom(outgoing__wrappee__Keys_~msg#1, outgoing__wrappee__Keys_~tmp~8#1); {3002#(and (= |old(~__ste_email_from0~0)| ~__ste_email_from0~0) (= |old(~__ste_email_from1~0)| ~__ste_email_from1~0))} is VALID [2022-02-20 17:59:59,876 INFO L290 TraceCheckUtils]: 88: Hoare triple {3002#(and (= |old(~__ste_email_from0~0)| ~__ste_email_from0~0) (= |old(~__ste_email_from1~0)| ~__ste_email_from1~0))} ~handle := #in~handle;~value := #in~value; {2938#true} is VALID [2022-02-20 17:59:59,876 INFO L290 TraceCheckUtils]: 89: Hoare triple {2938#true} assume 1 == ~handle;~__ste_email_from0~0 := ~value; {2938#true} is VALID [2022-02-20 17:59:59,876 INFO L290 TraceCheckUtils]: 90: Hoare triple {2938#true} assume true; {2938#true} is VALID [2022-02-20 17:59:59,876 INFO L284 TraceCheckUtils]: 91: Hoare quadruple {2938#true} {2939#false} #1064#return; {2939#false} is VALID [2022-02-20 17:59:59,877 INFO L290 TraceCheckUtils]: 92: Hoare triple {2939#false} assume { :begin_inline_mail } true;mail_#in~client#1, mail_#in~msg#1 := outgoing__wrappee__Keys_~client#1, outgoing__wrappee__Keys_~msg#1;havoc mail_#t~ret59#1, mail_#t~ret60#1, mail_~client#1, mail_~msg#1, mail_~__utac__ad__arg1~0#1, mail_~__utac__ad__arg2~0#1, mail_~tmp~7#1;mail_~client#1 := mail_#in~client#1;mail_~msg#1 := mail_#in~msg#1;havoc mail_~__utac__ad__arg1~0#1;havoc mail_~__utac__ad__arg2~0#1;havoc mail_~tmp~7#1;mail_~__utac__ad__arg1~0#1 := mail_~client#1;mail_~__utac__ad__arg2~0#1 := mail_~msg#1;assume { :begin_inline___utac_acc__SignForward_spec__1 } true;__utac_acc__SignForward_spec__1_#in~client#1, __utac_acc__SignForward_spec__1_#in~msg#1 := mail_~__utac__ad__arg1~0#1, mail_~__utac__ad__arg2~0#1;havoc __utac_acc__SignForward_spec__1_#t~ret107#1, __utac_acc__SignForward_spec__1_#t~ret108#1, __utac_acc__SignForward_spec__1_#t~ret109#1, __utac_acc__SignForward_spec__1_~client#1, __utac_acc__SignForward_spec__1_~msg#1, __utac_acc__SignForward_spec__1_~tmp~25#1, __utac_acc__SignForward_spec__1_~tmp___0~9#1;__utac_acc__SignForward_spec__1_~client#1 := __utac_acc__SignForward_spec__1_#in~client#1;__utac_acc__SignForward_spec__1_~msg#1 := __utac_acc__SignForward_spec__1_#in~msg#1;havoc __utac_acc__SignForward_spec__1_~tmp~25#1;havoc __utac_acc__SignForward_spec__1_~tmp___0~9#1;call __utac_acc__SignForward_spec__1_#t~ret107#1 := puts(39, 0);assume -2147483648 <= __utac_acc__SignForward_spec__1_#t~ret107#1 && __utac_acc__SignForward_spec__1_#t~ret107#1 <= 2147483647;havoc __utac_acc__SignForward_spec__1_#t~ret107#1; {2939#false} is VALID [2022-02-20 17:59:59,877 INFO L272 TraceCheckUtils]: 93: Hoare triple {2939#false} call __utac_acc__SignForward_spec__1_#t~ret108#1 := isSigned(__utac_acc__SignForward_spec__1_~msg#1); {2938#true} is VALID [2022-02-20 17:59:59,877 INFO L290 TraceCheckUtils]: 94: Hoare triple {2938#true} ~handle := #in~handle;havoc ~retValue_acc~41; {2938#true} is VALID [2022-02-20 17:59:59,877 INFO L290 TraceCheckUtils]: 95: Hoare triple {2938#true} assume 1 == ~handle;~retValue_acc~41 := ~__ste_email_isSigned0~0;#res := ~retValue_acc~41; {2938#true} is VALID [2022-02-20 17:59:59,877 INFO L290 TraceCheckUtils]: 96: Hoare triple {2938#true} assume true; {2938#true} is VALID [2022-02-20 17:59:59,877 INFO L284 TraceCheckUtils]: 97: Hoare quadruple {2938#true} {2939#false} #1066#return; {2939#false} is VALID [2022-02-20 17:59:59,877 INFO L290 TraceCheckUtils]: 98: Hoare triple {2939#false} assume -2147483648 <= __utac_acc__SignForward_spec__1_#t~ret108#1 && __utac_acc__SignForward_spec__1_#t~ret108#1 <= 2147483647;__utac_acc__SignForward_spec__1_~tmp___0~9#1 := __utac_acc__SignForward_spec__1_#t~ret108#1;havoc __utac_acc__SignForward_spec__1_#t~ret108#1; {2939#false} is VALID [2022-02-20 17:59:59,877 INFO L290 TraceCheckUtils]: 99: Hoare triple {2939#false} assume 0 != __utac_acc__SignForward_spec__1_~tmp___0~9#1; {2939#false} is VALID [2022-02-20 17:59:59,877 INFO L272 TraceCheckUtils]: 100: Hoare triple {2939#false} call __utac_acc__SignForward_spec__1_#t~ret109#1 := getClientPrivateKey(__utac_acc__SignForward_spec__1_~client#1); {2938#true} is VALID [2022-02-20 17:59:59,878 INFO L290 TraceCheckUtils]: 101: Hoare triple {2938#true} ~handle := #in~handle;havoc ~retValue_acc~20; {2938#true} is VALID [2022-02-20 17:59:59,878 INFO L290 TraceCheckUtils]: 102: Hoare triple {2938#true} assume 1 == ~handle;~retValue_acc~20 := ~__ste_client_privateKey0~0;#res := ~retValue_acc~20; {2938#true} is VALID [2022-02-20 17:59:59,878 INFO L290 TraceCheckUtils]: 103: Hoare triple {2938#true} assume true; {2938#true} is VALID [2022-02-20 17:59:59,878 INFO L284 TraceCheckUtils]: 104: Hoare quadruple {2938#true} {2939#false} #1068#return; {2939#false} is VALID [2022-02-20 17:59:59,878 INFO L290 TraceCheckUtils]: 105: Hoare triple {2939#false} assume -2147483648 <= __utac_acc__SignForward_spec__1_#t~ret109#1 && __utac_acc__SignForward_spec__1_#t~ret109#1 <= 2147483647;__utac_acc__SignForward_spec__1_~tmp~25#1 := __utac_acc__SignForward_spec__1_#t~ret109#1;havoc __utac_acc__SignForward_spec__1_#t~ret109#1; {2939#false} is VALID [2022-02-20 17:59:59,878 INFO L290 TraceCheckUtils]: 106: Hoare triple {2939#false} assume 0 == __utac_acc__SignForward_spec__1_~tmp~25#1;assume { :begin_inline___automaton_fail } true; {2939#false} is VALID [2022-02-20 17:59:59,878 INFO L290 TraceCheckUtils]: 107: Hoare triple {2939#false} assume !false; {2939#false} is VALID [2022-02-20 17:59:59,879 INFO L134 CoverageAnalysis]: Checked inductivity of 32 backedges. 3 proven. 3 refuted. 0 times theorem prover too weak. 26 trivial. 0 not checked. [2022-02-20 17:59:59,879 INFO L144 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2022-02-20 17:59:59,879 INFO L338 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [216991103] [2022-02-20 17:59:59,879 INFO L165 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [216991103] provided 0 perfect and 1 imperfect interpolant sequences [2022-02-20 17:59:59,879 INFO L338 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleZ3 [657611898] [2022-02-20 17:59:59,879 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-02-20 17:59:59,880 INFO L173 SolverBuilder]: Constructing external solver with command: z3 -smt2 -in SMTLIB2_COMPLIANT=true [2022-02-20 17:59:59,880 INFO L189 MonitoredProcess]: No working directory specified, using /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 [2022-02-20 17:59:59,881 INFO L229 MonitoredProcess]: Starting monitored process 3 with /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 -smt2 -in SMTLIB2_COMPLIANT=true (exit command is (exit), workingDir is null) [2022-02-20 17:59:59,882 INFO L327 MonitoredProcess]: [MP /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 -smt2 -in SMTLIB2_COMPLIANT=true (3)] Waiting until timeout for monitored process [2022-02-20 18:00:00,096 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-02-20 18:00:00,100 INFO L263 TraceCheckSpWp]: Trace formula consists of 1066 conjuncts, 2 conjunts are in the unsatisfiable core [2022-02-20 18:00:00,145 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-02-20 18:00:00,147 INFO L286 TraceCheckSpWp]: Computing forward predicates... [2022-02-20 18:00:00,360 INFO L290 TraceCheckUtils]: 0: Hoare triple {2938#true} assume { :begin_inline_ULTIMATE.init } true;#NULL.base, #NULL.offset := 0, 0;assume 0 == #valid[0];assume 0 < #StackHeapBarrier;call #Ultimate.allocInit(2, 1);call write~init~int(48, 1, 0, 1);call write~init~int(0, 1, 1, 1);call #Ultimate.allocInit(28, 2);call #Ultimate.allocInit(12, 3);call #Ultimate.allocInit(30, 4);call #Ultimate.allocInit(9, 5);call #Ultimate.allocInit(21, 6);call #Ultimate.allocInit(30, 7);call #Ultimate.allocInit(9, 8);call #Ultimate.allocInit(21, 9);call #Ultimate.allocInit(30, 10);call #Ultimate.allocInit(9, 11);call #Ultimate.allocInit(25, 12);call #Ultimate.allocInit(30, 13);call #Ultimate.allocInit(9, 14);call #Ultimate.allocInit(25, 15);call #Ultimate.allocInit(44, 16);call #Ultimate.allocInit(44, 17);call #Ultimate.allocInit(9, 18);call #Ultimate.allocInit(9, 19);call #Ultimate.allocInit(11, 20);call #Ultimate.allocInit(19, 21);call #Ultimate.allocInit(4, 22);call write~init~int(37, 22, 0, 1);call write~init~int(100, 22, 1, 1);call write~init~int(10, 22, 2, 1);call write~init~int(0, 22, 3, 1);call #Ultimate.allocInit(4, 23);call write~init~int(37, 23, 0, 1);call write~init~int(100, 23, 1, 1);call write~init~int(10, 23, 2, 1);call write~init~int(0, 23, 3, 1);call #Ultimate.allocInit(10, 24);call #Ultimate.allocInit(16, 25);call #Ultimate.allocInit(20, 26);call #Ultimate.allocInit(22, 27);call #Ultimate.allocInit(21, 28);call #Ultimate.allocInit(10, 29);call #Ultimate.allocInit(12, 30);call #Ultimate.allocInit(10, 31);call #Ultimate.allocInit(18, 32);call #Ultimate.allocInit(16, 33);call #Ultimate.allocInit(21, 34);call #Ultimate.allocInit(13, 35);call #Ultimate.allocInit(16, 36);call #Ultimate.allocInit(25, 37);call #Ultimate.allocInit(4, 38);call write~init~int(37, 38, 0, 1);call write~init~int(115, 38, 1, 1);call write~init~int(10, 38, 2, 1);call write~init~int(0, 38, 3, 1);call #Ultimate.allocInit(13, 39);~head~0.base, ~head~0.offset := 0, 0;~__SELECTED_FEATURE_Base~0 := 0;~__SELECTED_FEATURE_Keys~0 := 0;~__SELECTED_FEATURE_Encrypt~0 := 0;~__SELECTED_FEATURE_AutoResponder~0 := 0;~__SELECTED_FEATURE_AddressBook~0 := 0;~__SELECTED_FEATURE_Sign~0 := 0;~__SELECTED_FEATURE_Forward~0 := 0;~__SELECTED_FEATURE_Verify~0 := 0;~__SELECTED_FEATURE_Decrypt~0 := 0;~__GUIDSL_ROOT_PRODUCTION~0 := 0;~__GUIDSL_NON_TERMINAL_main~0 := 0;~bob~0 := 0;~rjh~0 := 0;~chuck~0 := 0;~queue_empty~0 := 1;~queued_message~0 := 0;~queued_client~0 := 0;~__ste_Client_counter~0 := 0;~__ste_client_name0~0.base, ~__ste_client_name0~0.offset := 0, 0;~__ste_client_name1~0.base, ~__ste_client_name1~0.offset := 0, 0;~__ste_client_name2~0.base, ~__ste_client_name2~0.offset := 0, 0;~__ste_client_outbuffer0~0 := 0;~__ste_client_outbuffer1~0 := 0;~__ste_client_outbuffer2~0 := 0;~__ste_client_outbuffer3~0 := 0;~__ste_ClientAddressBook_size0~0 := 0;~__ste_ClientAddressBook_size1~0 := 0;~__ste_ClientAddressBook_size2~0 := 0;~__ste_Client_AddressBook0_Alias0~0 := 0;~__ste_Client_AddressBook0_Alias1~0 := 0;~__ste_Client_AddressBook0_Alias2~0 := 0;~__ste_Client_AddressBook1_Alias0~0 := 0;~__ste_Client_AddressBook1_Alias1~0 := 0;~__ste_Client_AddressBook1_Alias2~0 := 0;~__ste_Client_AddressBook2_Alias0~0 := 0;~__ste_Client_AddressBook2_Alias1~0 := 0;~__ste_Client_AddressBook2_Alias2~0 := 0;~__ste_Client_AddressBook0_Address0~0 := 0;~__ste_Client_AddressBook0_Address1~0 := 0;~__ste_Client_AddressBook0_Address2~0 := 0;~__ste_Client_AddressBook1_Address0~0 := 0;~__ste_Client_AddressBook1_Address1~0 := 0;~__ste_Client_AddressBook1_Address2~0 := 0;~__ste_Client_AddressBook2_Address0~0 := 0;~__ste_Client_AddressBook2_Address1~0 := 0;~__ste_Client_AddressBook2_Address2~0 := 0;~__ste_client_autoResponse0~0 := 0;~__ste_client_autoResponse1~0 := 0;~__ste_client_autoResponse2~0 := 0;~__ste_client_privateKey0~0 := 0;~__ste_client_privateKey1~0 := 0;~__ste_client_privateKey2~0 := 0;~__ste_ClientKeyring_size0~0 := 0;~__ste_ClientKeyring_size1~0 := 0;~__ste_ClientKeyring_size2~0 := 0;~__ste_Client_Keyring0_User0~0 := 0;~__ste_Client_Keyring0_User1~0 := 0;~__ste_Client_Keyring0_User2~0 := 0;~__ste_Client_Keyring1_User0~0 := 0;~__ste_Client_Keyring1_User1~0 := 0;~__ste_Client_Keyring1_User2~0 := 0;~__ste_Client_Keyring2_User0~0 := 0;~__ste_Client_Keyring2_User1~0 := 0;~__ste_Client_Keyring2_User2~0 := 0;~__ste_Client_Keyring0_PublicKey0~0 := 0;~__ste_Client_Keyring0_PublicKey1~0 := 0;~__ste_Client_Keyring0_PublicKey2~0 := 0;~__ste_Client_Keyring1_PublicKey0~0 := 0;~__ste_Client_Keyring1_PublicKey1~0 := 0;~__ste_Client_Keyring1_PublicKey2~0 := 0;~__ste_Client_Keyring2_PublicKey0~0 := 0;~__ste_Client_Keyring2_PublicKey1~0 := 0;~__ste_Client_Keyring2_PublicKey2~0 := 0;~__ste_client_forwardReceiver0~0 := 0;~__ste_client_forwardReceiver1~0 := 0;~__ste_client_forwardReceiver2~0 := 0;~__ste_client_forwardReceiver3~0 := 0;~__ste_client_idCounter0~0 := 0;~__ste_client_idCounter1~0 := 0;~__ste_client_idCounter2~0 := 0;~__ste_Email_counter~0 := 0;~__ste_email_id0~0 := 0;~__ste_email_id1~0 := 0;~__ste_email_from0~0 := 0;~__ste_email_from1~0 := 0;~__ste_email_to0~0 := 0;~__ste_email_to1~0 := 0;~__ste_email_subject0~0.base, ~__ste_email_subject0~0.offset := 0, 0;~__ste_email_subject1~0.base, ~__ste_email_subject1~0.offset := 0, 0;~__ste_email_body0~0.base, ~__ste_email_body0~0.offset := 0, 0;~__ste_email_body1~0.base, ~__ste_email_body1~0.offset := 0, 0;~__ste_email_isEncrypted0~0 := 0;~__ste_email_isEncrypted1~0 := 0;~__ste_email_encryptionKey0~0 := 0;~__ste_email_encryptionKey1~0 := 0;~__ste_email_isSigned0~0 := 0;~__ste_email_isSigned1~0 := 0;~__ste_email_signKey0~0 := 0;~__ste_email_signKey1~0 := 0;~__ste_email_isSignatureVerified0~0 := 0;~__ste_email_isSignatureVerified1~0 := 0; {2938#true} is VALID [2022-02-20 18:00:00,360 INFO L290 TraceCheckUtils]: 1: Hoare triple {2938#true} assume { :end_inline_ULTIMATE.init } true;assume { :begin_inline_main } true;havoc main_#res#1;havoc main_#t~ret35#1, main_~retValue_acc~3#1, main_~tmp~4#1;havoc main_~retValue_acc~3#1;havoc main_~tmp~4#1;assume { :begin_inline_select_helpers } true; {2938#true} is VALID [2022-02-20 18:00:00,360 INFO L290 TraceCheckUtils]: 2: Hoare triple {2938#true} assume { :end_inline_select_helpers } true;assume { :begin_inline_select_features } true; {2938#true} is VALID [2022-02-20 18:00:00,360 INFO L290 TraceCheckUtils]: 3: Hoare triple {2938#true} assume { :end_inline_select_features } true;assume { :begin_inline_valid_product } true;havoc valid_product_#res#1;havoc valid_product_~retValue_acc~5#1;havoc valid_product_~retValue_acc~5#1;valid_product_~retValue_acc~5#1 := 1;valid_product_#res#1 := valid_product_~retValue_acc~5#1; {2938#true} is VALID [2022-02-20 18:00:00,360 INFO L290 TraceCheckUtils]: 4: Hoare triple {2938#true} main_#t~ret35#1 := valid_product_#res#1;assume { :end_inline_valid_product } true;assume -2147483648 <= main_#t~ret35#1 && main_#t~ret35#1 <= 2147483647;main_~tmp~4#1 := main_#t~ret35#1;havoc main_#t~ret35#1; {2938#true} is VALID [2022-02-20 18:00:00,360 INFO L290 TraceCheckUtils]: 5: Hoare triple {2938#true} assume 0 != main_~tmp~4#1;assume { :begin_inline_setup } true;havoc setup_#t~nondet32#1, setup_#t~nondet33#1, setup_#t~nondet34#1, setup_~__cil_tmp1~0#1.base, setup_~__cil_tmp1~0#1.offset, setup_~__cil_tmp2~0#1.base, setup_~__cil_tmp2~0#1.offset, setup_~__cil_tmp3~0#1.base, setup_~__cil_tmp3~0#1.offset;havoc setup_~__cil_tmp1~0#1.base, setup_~__cil_tmp1~0#1.offset;havoc setup_~__cil_tmp2~0#1.base, setup_~__cil_tmp2~0#1.offset;havoc setup_~__cil_tmp3~0#1.base, setup_~__cil_tmp3~0#1.offset;~bob~0 := 1;assume { :begin_inline_setup_bob } true;setup_bob_#in~bob___0#1 := ~bob~0;havoc setup_bob_~bob___0#1;setup_bob_~bob___0#1 := setup_bob_#in~bob___0#1;assume { :begin_inline_setup_bob__wrappee__Base } true;setup_bob__wrappee__Base_#in~bob___0#1 := setup_bob_~bob___0#1;havoc setup_bob__wrappee__Base_~bob___0#1;setup_bob__wrappee__Base_~bob___0#1 := setup_bob__wrappee__Base_#in~bob___0#1; {2938#true} is VALID [2022-02-20 18:00:00,361 INFO L272 TraceCheckUtils]: 6: Hoare triple {2938#true} call setClientId(setup_bob__wrappee__Base_~bob___0#1, setup_bob__wrappee__Base_~bob___0#1); {2938#true} is VALID [2022-02-20 18:00:00,361 INFO L290 TraceCheckUtils]: 7: Hoare triple {2938#true} ~handle := #in~handle;~value := #in~value; {2938#true} is VALID [2022-02-20 18:00:00,361 INFO L290 TraceCheckUtils]: 8: Hoare triple {2938#true} assume 1 == ~handle;~__ste_client_idCounter0~0 := ~value; {2938#true} is VALID [2022-02-20 18:00:00,361 INFO L290 TraceCheckUtils]: 9: Hoare triple {2938#true} assume true; {2938#true} is VALID [2022-02-20 18:00:00,362 INFO L284 TraceCheckUtils]: 10: Hoare quadruple {2938#true} {2938#true} #1134#return; {2938#true} is VALID [2022-02-20 18:00:00,362 INFO L290 TraceCheckUtils]: 11: Hoare triple {2938#true} assume { :end_inline_setup_bob__wrappee__Base } true; {2938#true} is VALID [2022-02-20 18:00:00,362 INFO L272 TraceCheckUtils]: 12: Hoare triple {2938#true} call setClientPrivateKey(setup_bob_~bob___0#1, 123); {2938#true} is VALID [2022-02-20 18:00:00,362 INFO L290 TraceCheckUtils]: 13: Hoare triple {2938#true} ~handle := #in~handle;~value := #in~value; {2938#true} is VALID [2022-02-20 18:00:00,362 INFO L290 TraceCheckUtils]: 14: Hoare triple {2938#true} assume 1 == ~handle;~__ste_client_privateKey0~0 := ~value; {2938#true} is VALID [2022-02-20 18:00:00,362 INFO L290 TraceCheckUtils]: 15: Hoare triple {2938#true} assume true; {2938#true} is VALID [2022-02-20 18:00:00,363 INFO L284 TraceCheckUtils]: 16: Hoare quadruple {2938#true} {2938#true} #1136#return; {2938#true} is VALID [2022-02-20 18:00:00,363 INFO L290 TraceCheckUtils]: 17: Hoare triple {2938#true} assume { :end_inline_setup_bob } true;setup_~__cil_tmp1~0#1.base, setup_~__cil_tmp1~0#1.offset := 18, 0;havoc setup_#t~nondet32#1;~rjh~0 := 2;assume { :begin_inline_setup_rjh } true;setup_rjh_#in~rjh___0#1 := ~rjh~0;havoc setup_rjh_~rjh___0#1;setup_rjh_~rjh___0#1 := setup_rjh_#in~rjh___0#1;assume { :begin_inline_setup_rjh__wrappee__Base } true;setup_rjh__wrappee__Base_#in~rjh___0#1 := setup_rjh_~rjh___0#1;havoc setup_rjh__wrappee__Base_~rjh___0#1;setup_rjh__wrappee__Base_~rjh___0#1 := setup_rjh__wrappee__Base_#in~rjh___0#1; {2938#true} is VALID [2022-02-20 18:00:00,363 INFO L272 TraceCheckUtils]: 18: Hoare triple {2938#true} call setClientId(setup_rjh__wrappee__Base_~rjh___0#1, setup_rjh__wrappee__Base_~rjh___0#1); {2938#true} is VALID [2022-02-20 18:00:00,363 INFO L290 TraceCheckUtils]: 19: Hoare triple {2938#true} ~handle := #in~handle;~value := #in~value; {2938#true} is VALID [2022-02-20 18:00:00,364 INFO L290 TraceCheckUtils]: 20: Hoare triple {2938#true} assume 1 == ~handle;~__ste_client_idCounter0~0 := ~value; {2938#true} is VALID [2022-02-20 18:00:00,364 INFO L290 TraceCheckUtils]: 21: Hoare triple {2938#true} assume true; {2938#true} is VALID [2022-02-20 18:00:00,364 INFO L284 TraceCheckUtils]: 22: Hoare quadruple {2938#true} {2938#true} #1138#return; {2938#true} is VALID [2022-02-20 18:00:00,364 INFO L290 TraceCheckUtils]: 23: Hoare triple {2938#true} assume { :end_inline_setup_rjh__wrappee__Base } true; {2938#true} is VALID [2022-02-20 18:00:00,364 INFO L272 TraceCheckUtils]: 24: Hoare triple {2938#true} call setClientPrivateKey(setup_rjh_~rjh___0#1, 456); {2938#true} is VALID [2022-02-20 18:00:00,364 INFO L290 TraceCheckUtils]: 25: Hoare triple {2938#true} ~handle := #in~handle;~value := #in~value; {2938#true} is VALID [2022-02-20 18:00:00,364 INFO L290 TraceCheckUtils]: 26: Hoare triple {2938#true} assume 1 == ~handle;~__ste_client_privateKey0~0 := ~value; {2938#true} is VALID [2022-02-20 18:00:00,364 INFO L290 TraceCheckUtils]: 27: Hoare triple {2938#true} assume true; {2938#true} is VALID [2022-02-20 18:00:00,364 INFO L284 TraceCheckUtils]: 28: Hoare quadruple {2938#true} {2938#true} #1140#return; {2938#true} is VALID [2022-02-20 18:00:00,364 INFO L290 TraceCheckUtils]: 29: Hoare triple {2938#true} assume { :end_inline_setup_rjh } true;setup_~__cil_tmp2~0#1.base, setup_~__cil_tmp2~0#1.offset := 19, 0;havoc setup_#t~nondet33#1;~chuck~0 := 3;assume { :begin_inline_setup_chuck } true;setup_chuck_#in~chuck___0#1 := ~chuck~0;havoc setup_chuck_~chuck___0#1;setup_chuck_~chuck___0#1 := setup_chuck_#in~chuck___0#1;assume { :begin_inline_setup_chuck__wrappee__Base } true;setup_chuck__wrappee__Base_#in~chuck___0#1 := setup_chuck_~chuck___0#1;havoc setup_chuck__wrappee__Base_~chuck___0#1;setup_chuck__wrappee__Base_~chuck___0#1 := setup_chuck__wrappee__Base_#in~chuck___0#1; {2938#true} is VALID [2022-02-20 18:00:00,365 INFO L272 TraceCheckUtils]: 30: Hoare triple {2938#true} call setClientId(setup_chuck__wrappee__Base_~chuck___0#1, setup_chuck__wrappee__Base_~chuck___0#1); {2938#true} is VALID [2022-02-20 18:00:00,365 INFO L290 TraceCheckUtils]: 31: Hoare triple {2938#true} ~handle := #in~handle;~value := #in~value; {2938#true} is VALID [2022-02-20 18:00:00,365 INFO L290 TraceCheckUtils]: 32: Hoare triple {2938#true} assume 1 == ~handle;~__ste_client_idCounter0~0 := ~value; {2938#true} is VALID [2022-02-20 18:00:00,365 INFO L290 TraceCheckUtils]: 33: Hoare triple {2938#true} assume true; {2938#true} is VALID [2022-02-20 18:00:00,365 INFO L284 TraceCheckUtils]: 34: Hoare quadruple {2938#true} {2938#true} #1142#return; {2938#true} is VALID [2022-02-20 18:00:00,365 INFO L290 TraceCheckUtils]: 35: Hoare triple {2938#true} assume { :end_inline_setup_chuck__wrappee__Base } true; {2938#true} is VALID [2022-02-20 18:00:00,365 INFO L272 TraceCheckUtils]: 36: Hoare triple {2938#true} call setClientPrivateKey(setup_chuck_~chuck___0#1, 789); {2938#true} is VALID [2022-02-20 18:00:00,365 INFO L290 TraceCheckUtils]: 37: Hoare triple {2938#true} ~handle := #in~handle;~value := #in~value; {2938#true} is VALID [2022-02-20 18:00:00,365 INFO L290 TraceCheckUtils]: 38: Hoare triple {2938#true} assume 1 == ~handle;~__ste_client_privateKey0~0 := ~value; {2938#true} is VALID [2022-02-20 18:00:00,366 INFO L290 TraceCheckUtils]: 39: Hoare triple {2938#true} assume true; {2938#true} is VALID [2022-02-20 18:00:00,366 INFO L284 TraceCheckUtils]: 40: Hoare quadruple {2938#true} {2938#true} #1144#return; {2938#true} is VALID [2022-02-20 18:00:00,366 INFO L290 TraceCheckUtils]: 41: Hoare triple {2938#true} assume { :end_inline_setup_chuck } true;setup_~__cil_tmp3~0#1.base, setup_~__cil_tmp3~0#1.offset := 20, 0;havoc setup_#t~nondet34#1; {2938#true} is VALID [2022-02-20 18:00:00,366 INFO L290 TraceCheckUtils]: 42: Hoare triple {2938#true} assume { :end_inline_setup } true;assume { :begin_inline_test } true;havoc test_#t~nondet47#1, test_#t~nondet48#1, test_#t~nondet49#1, test_#t~nondet50#1, test_#t~nondet51#1, test_#t~nondet52#1, test_#t~nondet53#1, test_#t~nondet54#1, test_#t~nondet55#1, test_#t~nondet56#1, test_#t~nondet57#1, test_~op1~0#1, test_~op2~0#1, test_~op3~0#1, test_~op4~0#1, test_~op5~0#1, test_~op6~0#1, test_~op7~0#1, test_~op8~0#1, test_~op9~0#1, test_~op10~0#1, test_~op11~0#1, test_~splverifierCounter~0#1, test_~tmp~6#1, test_~tmp___0~2#1, test_~tmp___1~1#1, test_~tmp___2~0#1, test_~tmp___3~0#1, test_~tmp___4~0#1, test_~tmp___5~0#1, test_~tmp___6~0#1, test_~tmp___7~0#1, test_~tmp___8~0#1, test_~tmp___9~0#1;havoc test_~op1~0#1;havoc test_~op2~0#1;havoc test_~op3~0#1;havoc test_~op4~0#1;havoc test_~op5~0#1;havoc test_~op6~0#1;havoc test_~op7~0#1;havoc test_~op8~0#1;havoc test_~op9~0#1;havoc test_~op10~0#1;havoc test_~op11~0#1;havoc test_~splverifierCounter~0#1;havoc test_~tmp~6#1;havoc test_~tmp___0~2#1;havoc test_~tmp___1~1#1;havoc test_~tmp___2~0#1;havoc test_~tmp___3~0#1;havoc test_~tmp___4~0#1;havoc test_~tmp___5~0#1;havoc test_~tmp___6~0#1;havoc test_~tmp___7~0#1;havoc test_~tmp___8~0#1;havoc test_~tmp___9~0#1;test_~op1~0#1 := 0;test_~op2~0#1 := 0;test_~op3~0#1 := 0;test_~op4~0#1 := 0;test_~op5~0#1 := 0;test_~op6~0#1 := 0;test_~op7~0#1 := 0;test_~op8~0#1 := 0;test_~op9~0#1 := 0;test_~op10~0#1 := 0;test_~op11~0#1 := 0;test_~splverifierCounter~0#1 := 0; {3133#(<= |ULTIMATE.start_test_~splverifierCounter~0#1| 0)} is VALID [2022-02-20 18:00:00,367 INFO L290 TraceCheckUtils]: 43: Hoare triple {3133#(<= |ULTIMATE.start_test_~splverifierCounter~0#1| 0)} assume !false; {3133#(<= |ULTIMATE.start_test_~splverifierCounter~0#1| 0)} is VALID [2022-02-20 18:00:00,367 INFO L290 TraceCheckUtils]: 44: Hoare triple {3133#(<= |ULTIMATE.start_test_~splverifierCounter~0#1| 0)} assume !(test_~splverifierCounter~0#1 < 4); {2939#false} is VALID [2022-02-20 18:00:00,367 INFO L290 TraceCheckUtils]: 45: Hoare triple {2939#false} assume { :begin_inline_bobToRjh } true;havoc bobToRjh_#t~ret27#1, bobToRjh_#t~ret28#1, bobToRjh_#t~ret29#1, bobToRjh_#t~ret30#1, bobToRjh_~tmp~3#1, bobToRjh_~tmp___0~0#1, bobToRjh_~tmp___1~0#1;havoc bobToRjh_~tmp~3#1;havoc bobToRjh_~tmp___0~0#1;havoc bobToRjh_~tmp___1~0#1;call bobToRjh_#t~ret27#1 := puts(16, 0);assume -2147483648 <= bobToRjh_#t~ret27#1 && bobToRjh_#t~ret27#1 <= 2147483647;havoc bobToRjh_#t~ret27#1; {2939#false} is VALID [2022-02-20 18:00:00,367 INFO L272 TraceCheckUtils]: 46: Hoare triple {2939#false} call sendEmail(~bob~0, ~rjh~0); {2939#false} is VALID [2022-02-20 18:00:00,367 INFO L290 TraceCheckUtils]: 47: Hoare triple {2939#false} ~sender#1 := #in~sender#1;~receiver#1 := #in~receiver#1;havoc ~email~0#1;havoc ~tmp~14#1;assume { :begin_inline_createEmail } true;createEmail_#in~from#1, createEmail_#in~to#1 := 0, ~receiver#1;havoc createEmail_#res#1;havoc createEmail_~from#1, createEmail_~to#1, createEmail_~retValue_acc~31#1, createEmail_~msg~0#1;createEmail_~from#1 := createEmail_#in~from#1;createEmail_~to#1 := createEmail_#in~to#1;havoc createEmail_~retValue_acc~31#1;havoc createEmail_~msg~0#1;createEmail_~msg~0#1 := 1; {2939#false} is VALID [2022-02-20 18:00:00,367 INFO L272 TraceCheckUtils]: 48: Hoare triple {2939#false} call setEmailFrom(createEmail_~msg~0#1, createEmail_~from#1); {2939#false} is VALID [2022-02-20 18:00:00,368 INFO L290 TraceCheckUtils]: 49: Hoare triple {2939#false} ~handle := #in~handle;~value := #in~value; {2939#false} is VALID [2022-02-20 18:00:00,368 INFO L290 TraceCheckUtils]: 50: Hoare triple {2939#false} assume 1 == ~handle;~__ste_email_from0~0 := ~value; {2939#false} is VALID [2022-02-20 18:00:00,368 INFO L290 TraceCheckUtils]: 51: Hoare triple {2939#false} assume true; {2939#false} is VALID [2022-02-20 18:00:00,368 INFO L284 TraceCheckUtils]: 52: Hoare quadruple {2939#false} {2939#false} #1120#return; {2939#false} is VALID [2022-02-20 18:00:00,368 INFO L272 TraceCheckUtils]: 53: Hoare triple {2939#false} call setEmailTo(createEmail_~msg~0#1, createEmail_~to#1); {2939#false} is VALID [2022-02-20 18:00:00,368 INFO L290 TraceCheckUtils]: 54: Hoare triple {2939#false} ~handle := #in~handle;~value := #in~value; {2939#false} is VALID [2022-02-20 18:00:00,368 INFO L290 TraceCheckUtils]: 55: Hoare triple {2939#false} assume 1 == ~handle;~__ste_email_to0~0 := ~value; {2939#false} is VALID [2022-02-20 18:00:00,368 INFO L290 TraceCheckUtils]: 56: Hoare triple {2939#false} assume true; {2939#false} is VALID [2022-02-20 18:00:00,368 INFO L284 TraceCheckUtils]: 57: Hoare quadruple {2939#false} {2939#false} #1122#return; {2939#false} is VALID [2022-02-20 18:00:00,369 INFO L290 TraceCheckUtils]: 58: Hoare triple {2939#false} createEmail_~retValue_acc~31#1 := createEmail_~msg~0#1;createEmail_#res#1 := createEmail_~retValue_acc~31#1; {2939#false} is VALID [2022-02-20 18:00:00,369 INFO L290 TraceCheckUtils]: 59: Hoare triple {2939#false} #t~ret72#1 := createEmail_#res#1;assume { :end_inline_createEmail } true;assume -2147483648 <= #t~ret72#1 && #t~ret72#1 <= 2147483647;~tmp~14#1 := #t~ret72#1;havoc #t~ret72#1;~email~0#1 := ~tmp~14#1; {2939#false} is VALID [2022-02-20 18:00:00,369 INFO L272 TraceCheckUtils]: 60: Hoare triple {2939#false} call outgoing(~sender#1, ~email~0#1); {2939#false} is VALID [2022-02-20 18:00:00,369 INFO L290 TraceCheckUtils]: 61: Hoare triple {2939#false} ~client#1 := #in~client#1;~msg#1 := #in~msg#1;assume { :begin_inline_sign } true;sign_#in~client#1, sign_#in~msg#1 := ~client#1, ~msg#1;havoc sign_#t~ret76#1, sign_~client#1, sign_~msg#1, sign_~privkey~1#1, sign_~tmp~16#1;sign_~client#1 := sign_#in~client#1;sign_~msg#1 := sign_#in~msg#1;havoc sign_~privkey~1#1;havoc sign_~tmp~16#1; {2939#false} is VALID [2022-02-20 18:00:00,369 INFO L272 TraceCheckUtils]: 62: Hoare triple {2939#false} call sign_#t~ret76#1 := getClientPrivateKey(sign_~client#1); {2939#false} is VALID [2022-02-20 18:00:00,369 INFO L290 TraceCheckUtils]: 63: Hoare triple {2939#false} ~handle := #in~handle;havoc ~retValue_acc~20; {2939#false} is VALID [2022-02-20 18:00:00,369 INFO L290 TraceCheckUtils]: 64: Hoare triple {2939#false} assume 1 == ~handle;~retValue_acc~20 := ~__ste_client_privateKey0~0;#res := ~retValue_acc~20; {2939#false} is VALID [2022-02-20 18:00:00,369 INFO L290 TraceCheckUtils]: 65: Hoare triple {2939#false} assume true; {2939#false} is VALID [2022-02-20 18:00:00,369 INFO L284 TraceCheckUtils]: 66: Hoare quadruple {2939#false} {2939#false} #1054#return; {2939#false} is VALID [2022-02-20 18:00:00,370 INFO L290 TraceCheckUtils]: 67: Hoare triple {2939#false} assume -2147483648 <= sign_#t~ret76#1 && sign_#t~ret76#1 <= 2147483647;sign_~tmp~16#1 := sign_#t~ret76#1;havoc sign_#t~ret76#1;sign_~privkey~1#1 := sign_~tmp~16#1; {2939#false} is VALID [2022-02-20 18:00:00,370 INFO L290 TraceCheckUtils]: 68: Hoare triple {2939#false} assume 0 == sign_~privkey~1#1; {2939#false} is VALID [2022-02-20 18:00:00,370 INFO L290 TraceCheckUtils]: 69: Hoare triple {2939#false} assume { :end_inline_sign } true;assume { :begin_inline_outgoing__wrappee__AutoResponder } true;outgoing__wrappee__AutoResponder_#in~client#1, outgoing__wrappee__AutoResponder_#in~msg#1 := ~client#1, ~msg#1;havoc outgoing__wrappee__AutoResponder_#t~ret62#1, outgoing__wrappee__AutoResponder_#t~ret63#1, outgoing__wrappee__AutoResponder_~client#1, outgoing__wrappee__AutoResponder_~msg#1, outgoing__wrappee__AutoResponder_~receiver~0#1, outgoing__wrappee__AutoResponder_~tmp~9#1, outgoing__wrappee__AutoResponder_~pubkey~0#1, outgoing__wrappee__AutoResponder_~tmp___0~3#1;outgoing__wrappee__AutoResponder_~client#1 := outgoing__wrappee__AutoResponder_#in~client#1;outgoing__wrappee__AutoResponder_~msg#1 := outgoing__wrappee__AutoResponder_#in~msg#1;havoc outgoing__wrappee__AutoResponder_~receiver~0#1;havoc outgoing__wrappee__AutoResponder_~tmp~9#1;havoc outgoing__wrappee__AutoResponder_~pubkey~0#1;havoc outgoing__wrappee__AutoResponder_~tmp___0~3#1; {2939#false} is VALID [2022-02-20 18:00:00,370 INFO L272 TraceCheckUtils]: 70: Hoare triple {2939#false} call outgoing__wrappee__AutoResponder_#t~ret62#1 := getEmailTo(outgoing__wrappee__AutoResponder_~msg#1); {2939#false} is VALID [2022-02-20 18:00:00,370 INFO L290 TraceCheckUtils]: 71: Hoare triple {2939#false} ~handle := #in~handle;havoc ~retValue_acc~36; {2939#false} is VALID [2022-02-20 18:00:00,370 INFO L290 TraceCheckUtils]: 72: Hoare triple {2939#false} assume 1 == ~handle;~retValue_acc~36 := ~__ste_email_to0~0;#res := ~retValue_acc~36; {2939#false} is VALID [2022-02-20 18:00:00,371 INFO L290 TraceCheckUtils]: 73: Hoare triple {2939#false} assume true; {2939#false} is VALID [2022-02-20 18:00:00,371 INFO L284 TraceCheckUtils]: 74: Hoare quadruple {2939#false} {2939#false} #1056#return; {2939#false} is VALID [2022-02-20 18:00:00,371 INFO L290 TraceCheckUtils]: 75: Hoare triple {2939#false} assume -2147483648 <= outgoing__wrappee__AutoResponder_#t~ret62#1 && outgoing__wrappee__AutoResponder_#t~ret62#1 <= 2147483647;outgoing__wrappee__AutoResponder_~tmp~9#1 := outgoing__wrappee__AutoResponder_#t~ret62#1;havoc outgoing__wrappee__AutoResponder_#t~ret62#1;outgoing__wrappee__AutoResponder_~receiver~0#1 := outgoing__wrappee__AutoResponder_~tmp~9#1; {2939#false} is VALID [2022-02-20 18:00:00,372 INFO L272 TraceCheckUtils]: 76: Hoare triple {2939#false} call outgoing__wrappee__AutoResponder_#t~ret63#1 := findPublicKey(outgoing__wrappee__AutoResponder_~client#1, outgoing__wrappee__AutoResponder_~receiver~0#1); {2939#false} is VALID [2022-02-20 18:00:00,372 INFO L290 TraceCheckUtils]: 77: Hoare triple {2939#false} ~handle := #in~handle;~userid := #in~userid;havoc ~retValue_acc~25; {2939#false} is VALID [2022-02-20 18:00:00,372 INFO L290 TraceCheckUtils]: 78: Hoare triple {2939#false} assume 1 == ~handle; {2939#false} is VALID [2022-02-20 18:00:00,372 INFO L290 TraceCheckUtils]: 79: Hoare triple {2939#false} assume ~userid == ~__ste_Client_Keyring0_User0~0;~retValue_acc~25 := ~__ste_Client_Keyring0_PublicKey0~0;#res := ~retValue_acc~25; {2939#false} is VALID [2022-02-20 18:00:00,372 INFO L290 TraceCheckUtils]: 80: Hoare triple {2939#false} assume true; {2939#false} is VALID [2022-02-20 18:00:00,372 INFO L284 TraceCheckUtils]: 81: Hoare quadruple {2939#false} {2939#false} #1058#return; {2939#false} is VALID [2022-02-20 18:00:00,372 INFO L290 TraceCheckUtils]: 82: Hoare triple {2939#false} assume -2147483648 <= outgoing__wrappee__AutoResponder_#t~ret63#1 && outgoing__wrappee__AutoResponder_#t~ret63#1 <= 2147483647;outgoing__wrappee__AutoResponder_~tmp___0~3#1 := outgoing__wrappee__AutoResponder_#t~ret63#1;havoc outgoing__wrappee__AutoResponder_#t~ret63#1;outgoing__wrappee__AutoResponder_~pubkey~0#1 := outgoing__wrappee__AutoResponder_~tmp___0~3#1; {2939#false} is VALID [2022-02-20 18:00:00,372 INFO L290 TraceCheckUtils]: 83: Hoare triple {2939#false} assume !(0 != outgoing__wrappee__AutoResponder_~pubkey~0#1); {2939#false} is VALID [2022-02-20 18:00:00,372 INFO L290 TraceCheckUtils]: 84: Hoare triple {2939#false} assume { :begin_inline_outgoing__wrappee__Keys } true;outgoing__wrappee__Keys_#in~client#1, outgoing__wrappee__Keys_#in~msg#1 := outgoing__wrappee__AutoResponder_~client#1, outgoing__wrappee__AutoResponder_~msg#1;havoc outgoing__wrappee__Keys_#t~ret61#1, outgoing__wrappee__Keys_~client#1, outgoing__wrappee__Keys_~msg#1, outgoing__wrappee__Keys_~tmp~8#1;outgoing__wrappee__Keys_~client#1 := outgoing__wrappee__Keys_#in~client#1;outgoing__wrappee__Keys_~msg#1 := outgoing__wrappee__Keys_#in~msg#1;havoc outgoing__wrappee__Keys_~tmp~8#1;assume { :begin_inline_getClientId } true;getClientId_#in~handle#1 := outgoing__wrappee__Keys_~client#1;havoc getClientId_#res#1;havoc getClientId_~handle#1, getClientId_~retValue_acc~27#1;getClientId_~handle#1 := getClientId_#in~handle#1;havoc getClientId_~retValue_acc~27#1; {2939#false} is VALID [2022-02-20 18:00:00,373 INFO L290 TraceCheckUtils]: 85: Hoare triple {2939#false} assume 1 == getClientId_~handle#1;getClientId_~retValue_acc~27#1 := ~__ste_client_idCounter0~0;getClientId_#res#1 := getClientId_~retValue_acc~27#1; {2939#false} is VALID [2022-02-20 18:00:00,373 INFO L290 TraceCheckUtils]: 86: Hoare triple {2939#false} outgoing__wrappee__Keys_#t~ret61#1 := getClientId_#res#1;assume { :end_inline_getClientId } true;assume -2147483648 <= outgoing__wrappee__Keys_#t~ret61#1 && outgoing__wrappee__Keys_#t~ret61#1 <= 2147483647;outgoing__wrappee__Keys_~tmp~8#1 := outgoing__wrappee__Keys_#t~ret61#1;havoc outgoing__wrappee__Keys_#t~ret61#1; {2939#false} is VALID [2022-02-20 18:00:00,373 INFO L272 TraceCheckUtils]: 87: Hoare triple {2939#false} call setEmailFrom(outgoing__wrappee__Keys_~msg#1, outgoing__wrappee__Keys_~tmp~8#1); {2939#false} is VALID [2022-02-20 18:00:00,373 INFO L290 TraceCheckUtils]: 88: Hoare triple {2939#false} ~handle := #in~handle;~value := #in~value; {2939#false} is VALID [2022-02-20 18:00:00,373 INFO L290 TraceCheckUtils]: 89: Hoare triple {2939#false} assume 1 == ~handle;~__ste_email_from0~0 := ~value; {2939#false} is VALID [2022-02-20 18:00:00,373 INFO L290 TraceCheckUtils]: 90: Hoare triple {2939#false} assume true; {2939#false} is VALID [2022-02-20 18:00:00,373 INFO L284 TraceCheckUtils]: 91: Hoare quadruple {2939#false} {2939#false} #1064#return; {2939#false} is VALID [2022-02-20 18:00:00,373 INFO L290 TraceCheckUtils]: 92: Hoare triple {2939#false} assume { :begin_inline_mail } true;mail_#in~client#1, mail_#in~msg#1 := outgoing__wrappee__Keys_~client#1, outgoing__wrappee__Keys_~msg#1;havoc mail_#t~ret59#1, mail_#t~ret60#1, mail_~client#1, mail_~msg#1, mail_~__utac__ad__arg1~0#1, mail_~__utac__ad__arg2~0#1, mail_~tmp~7#1;mail_~client#1 := mail_#in~client#1;mail_~msg#1 := mail_#in~msg#1;havoc mail_~__utac__ad__arg1~0#1;havoc mail_~__utac__ad__arg2~0#1;havoc mail_~tmp~7#1;mail_~__utac__ad__arg1~0#1 := mail_~client#1;mail_~__utac__ad__arg2~0#1 := mail_~msg#1;assume { :begin_inline___utac_acc__SignForward_spec__1 } true;__utac_acc__SignForward_spec__1_#in~client#1, __utac_acc__SignForward_spec__1_#in~msg#1 := mail_~__utac__ad__arg1~0#1, mail_~__utac__ad__arg2~0#1;havoc __utac_acc__SignForward_spec__1_#t~ret107#1, __utac_acc__SignForward_spec__1_#t~ret108#1, __utac_acc__SignForward_spec__1_#t~ret109#1, __utac_acc__SignForward_spec__1_~client#1, __utac_acc__SignForward_spec__1_~msg#1, __utac_acc__SignForward_spec__1_~tmp~25#1, __utac_acc__SignForward_spec__1_~tmp___0~9#1;__utac_acc__SignForward_spec__1_~client#1 := __utac_acc__SignForward_spec__1_#in~client#1;__utac_acc__SignForward_spec__1_~msg#1 := __utac_acc__SignForward_spec__1_#in~msg#1;havoc __utac_acc__SignForward_spec__1_~tmp~25#1;havoc __utac_acc__SignForward_spec__1_~tmp___0~9#1;call __utac_acc__SignForward_spec__1_#t~ret107#1 := puts(39, 0);assume -2147483648 <= __utac_acc__SignForward_spec__1_#t~ret107#1 && __utac_acc__SignForward_spec__1_#t~ret107#1 <= 2147483647;havoc __utac_acc__SignForward_spec__1_#t~ret107#1; {2939#false} is VALID [2022-02-20 18:00:00,373 INFO L272 TraceCheckUtils]: 93: Hoare triple {2939#false} call __utac_acc__SignForward_spec__1_#t~ret108#1 := isSigned(__utac_acc__SignForward_spec__1_~msg#1); {2939#false} is VALID [2022-02-20 18:00:00,374 INFO L290 TraceCheckUtils]: 94: Hoare triple {2939#false} ~handle := #in~handle;havoc ~retValue_acc~41; {2939#false} is VALID [2022-02-20 18:00:00,374 INFO L290 TraceCheckUtils]: 95: Hoare triple {2939#false} assume 1 == ~handle;~retValue_acc~41 := ~__ste_email_isSigned0~0;#res := ~retValue_acc~41; {2939#false} is VALID [2022-02-20 18:00:00,374 INFO L290 TraceCheckUtils]: 96: Hoare triple {2939#false} assume true; {2939#false} is VALID [2022-02-20 18:00:00,374 INFO L284 TraceCheckUtils]: 97: Hoare quadruple {2939#false} {2939#false} #1066#return; {2939#false} is VALID [2022-02-20 18:00:00,374 INFO L290 TraceCheckUtils]: 98: Hoare triple {2939#false} assume -2147483648 <= __utac_acc__SignForward_spec__1_#t~ret108#1 && __utac_acc__SignForward_spec__1_#t~ret108#1 <= 2147483647;__utac_acc__SignForward_spec__1_~tmp___0~9#1 := __utac_acc__SignForward_spec__1_#t~ret108#1;havoc __utac_acc__SignForward_spec__1_#t~ret108#1; {2939#false} is VALID [2022-02-20 18:00:00,374 INFO L290 TraceCheckUtils]: 99: Hoare triple {2939#false} assume 0 != __utac_acc__SignForward_spec__1_~tmp___0~9#1; {2939#false} is VALID [2022-02-20 18:00:00,374 INFO L272 TraceCheckUtils]: 100: Hoare triple {2939#false} call __utac_acc__SignForward_spec__1_#t~ret109#1 := getClientPrivateKey(__utac_acc__SignForward_spec__1_~client#1); {2939#false} is VALID [2022-02-20 18:00:00,374 INFO L290 TraceCheckUtils]: 101: Hoare triple {2939#false} ~handle := #in~handle;havoc ~retValue_acc~20; {2939#false} is VALID [2022-02-20 18:00:00,374 INFO L290 TraceCheckUtils]: 102: Hoare triple {2939#false} assume 1 == ~handle;~retValue_acc~20 := ~__ste_client_privateKey0~0;#res := ~retValue_acc~20; {2939#false} is VALID [2022-02-20 18:00:00,375 INFO L290 TraceCheckUtils]: 103: Hoare triple {2939#false} assume true; {2939#false} is VALID [2022-02-20 18:00:00,375 INFO L284 TraceCheckUtils]: 104: Hoare quadruple {2939#false} {2939#false} #1068#return; {2939#false} is VALID [2022-02-20 18:00:00,375 INFO L290 TraceCheckUtils]: 105: Hoare triple {2939#false} assume -2147483648 <= __utac_acc__SignForward_spec__1_#t~ret109#1 && __utac_acc__SignForward_spec__1_#t~ret109#1 <= 2147483647;__utac_acc__SignForward_spec__1_~tmp~25#1 := __utac_acc__SignForward_spec__1_#t~ret109#1;havoc __utac_acc__SignForward_spec__1_#t~ret109#1; {2939#false} is VALID [2022-02-20 18:00:00,375 INFO L290 TraceCheckUtils]: 106: Hoare triple {2939#false} assume 0 == __utac_acc__SignForward_spec__1_~tmp~25#1;assume { :begin_inline___automaton_fail } true; {2939#false} is VALID [2022-02-20 18:00:00,375 INFO L290 TraceCheckUtils]: 107: Hoare triple {2939#false} assume !false; {2939#false} is VALID [2022-02-20 18:00:00,375 INFO L134 CoverageAnalysis]: Checked inductivity of 32 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 32 trivial. 0 not checked. [2022-02-20 18:00:00,375 INFO L324 TraceCheckSpWp]: Omiting computation of backward sequence because forward sequence was already perfect [2022-02-20 18:00:00,376 INFO L165 FreeRefinementEngine]: IpTcStrategyModuleZ3 [657611898] provided 1 perfect and 0 imperfect interpolant sequences [2022-02-20 18:00:00,376 INFO L191 FreeRefinementEngine]: Found 1 perfect and 1 imperfect interpolant sequences. [2022-02-20 18:00:00,376 INFO L204 FreeRefinementEngine]: Number of different interpolants: perfect sequences [3] imperfect sequences [9] total 10 [2022-02-20 18:00:00,376 INFO L118 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [1325709503] [2022-02-20 18:00:00,376 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2022-02-20 18:00:00,382 INFO L78 Accepts]: Start accepts. Automaton has has 3 states, 3 states have (on average 20.0) internal successors, (60), 3 states have internal predecessors, (60), 2 states have call successors, (16), 2 states have call predecessors, (16), 2 states have return successors, (14), 2 states have call predecessors, (14), 2 states have call successors, (14) Word has length 108 [2022-02-20 18:00:00,383 INFO L84 Accepts]: Finished accepts. word is accepted. [2022-02-20 18:00:00,383 INFO L86 InductivityCheck]: Starting indutivity check of a Floyd-Hoare automaton with has 3 states, 3 states have (on average 20.0) internal successors, (60), 3 states have internal predecessors, (60), 2 states have call successors, (16), 2 states have call predecessors, (16), 2 states have return successors, (14), 2 states have call predecessors, (14), 2 states have call successors, (14) [2022-02-20 18:00:00,435 INFO L122 InductivityCheck]: Floyd-Hoare automaton has 90 edges. 90 inductive. 0 not inductive. 0 times theorem prover too weak to decide inductivity. [2022-02-20 18:00:00,435 INFO L546 AbstractCegarLoop]: INTERPOLANT automaton has 3 states [2022-02-20 18:00:00,435 INFO L108 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2022-02-20 18:00:00,436 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 3 interpolants. [2022-02-20 18:00:00,436 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=17, Invalid=73, Unknown=0, NotChecked=0, Total=90 [2022-02-20 18:00:00,436 INFO L87 Difference]: Start difference. First operand 381 states and 563 transitions. Second operand has 3 states, 3 states have (on average 20.0) internal successors, (60), 3 states have internal predecessors, (60), 2 states have call successors, (16), 2 states have call predecessors, (16), 2 states have return successors, (14), 2 states have call predecessors, (14), 2 states have call successors, (14) [2022-02-20 18:00:00,815 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-02-20 18:00:00,816 INFO L93 Difference]: Finished difference Result 607 states and 877 transitions. [2022-02-20 18:00:00,816 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 3 states. [2022-02-20 18:00:00,817 INFO L78 Accepts]: Start accepts. Automaton has has 3 states, 3 states have (on average 20.0) internal successors, (60), 3 states have internal predecessors, (60), 2 states have call successors, (16), 2 states have call predecessors, (16), 2 states have return successors, (14), 2 states have call predecessors, (14), 2 states have call successors, (14) Word has length 108 [2022-02-20 18:00:00,818 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2022-02-20 18:00:00,818 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 3 states, 3 states have (on average 20.0) internal successors, (60), 3 states have internal predecessors, (60), 2 states have call successors, (16), 2 states have call predecessors, (16), 2 states have return successors, (14), 2 states have call predecessors, (14), 2 states have call successors, (14) [2022-02-20 18:00:00,828 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 3 states to 3 states and 877 transitions. [2022-02-20 18:00:00,828 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 3 states, 3 states have (on average 20.0) internal successors, (60), 3 states have internal predecessors, (60), 2 states have call successors, (16), 2 states have call predecessors, (16), 2 states have return successors, (14), 2 states have call predecessors, (14), 2 states have call successors, (14) [2022-02-20 18:00:00,847 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 3 states to 3 states and 877 transitions. [2022-02-20 18:00:00,847 INFO L86 InductivityCheck]: Starting indutivity check of a Floyd-Hoare automaton with 3 states and 877 transitions. [2022-02-20 18:00:01,386 INFO L122 InductivityCheck]: Floyd-Hoare automaton has 877 edges. 877 inductive. 0 not inductive. 0 times theorem prover too weak to decide inductivity. [2022-02-20 18:00:01,398 INFO L225 Difference]: With dead ends: 607 [2022-02-20 18:00:01,398 INFO L226 Difference]: Without dead ends: 384 [2022-02-20 18:00:01,400 INFO L932 BasicCegarLoop]: 0 DeclaredPredicates, 139 GetRequests, 131 SyntacticMatches, 0 SemanticMatches, 8 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 0 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=17, Invalid=73, Unknown=0, NotChecked=0, Total=90 [2022-02-20 18:00:01,402 INFO L933 BasicCegarLoop]: 561 mSDtfsCounter, 1 mSDsluCounter, 559 mSDsCounter, 0 mSdLazyCounter, 5 mSolverCounterSat, 0 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.0s Time, 0 mProtectedPredicate, 0 mProtectedAction, 1 SdHoareTripleChecker+Valid, 1120 SdHoareTripleChecker+Invalid, 5 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 0 IncrementalHoareTripleChecker+Valid, 5 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.0s IncrementalHoareTripleChecker+Time [2022-02-20 18:00:01,402 INFO L934 BasicCegarLoop]: SdHoareTripleChecker [1 Valid, 1120 Invalid, 5 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [0 Valid, 5 Invalid, 0 Unknown, 0 Unchecked, 0.0s Time] [2022-02-20 18:00:01,403 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 384 states. [2022-02-20 18:00:01,414 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 384 to 383. [2022-02-20 18:00:01,414 INFO L214 AbstractMinimizeNwa]: Start testing correctness of minimizeSevpa [2022-02-20 18:00:01,415 INFO L82 GeneralOperation]: Start isEquivalent. First operand 384 states. Second operand has 383 states, 295 states have (on average 1.4915254237288136) internal successors, (440), 298 states have internal predecessors, (440), 63 states have call successors, (63), 24 states have call predecessors, (63), 24 states have return successors, (62), 62 states have call predecessors, (62), 62 states have call successors, (62) [2022-02-20 18:00:01,416 INFO L74 IsIncluded]: Start isIncluded. First operand 384 states. Second operand has 383 states, 295 states have (on average 1.4915254237288136) internal successors, (440), 298 states have internal predecessors, (440), 63 states have call successors, (63), 24 states have call predecessors, (63), 24 states have return successors, (62), 62 states have call predecessors, (62), 62 states have call successors, (62) [2022-02-20 18:00:01,417 INFO L87 Difference]: Start difference. First operand 384 states. Second operand has 383 states, 295 states have (on average 1.4915254237288136) internal successors, (440), 298 states have internal predecessors, (440), 63 states have call successors, (63), 24 states have call predecessors, (63), 24 states have return successors, (62), 62 states have call predecessors, (62), 62 states have call successors, (62) [2022-02-20 18:00:01,428 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-02-20 18:00:01,428 INFO L93 Difference]: Finished difference Result 384 states and 566 transitions. [2022-02-20 18:00:01,428 INFO L276 IsEmpty]: Start isEmpty. Operand 384 states and 566 transitions. [2022-02-20 18:00:01,429 INFO L282 IsEmpty]: Finished isEmpty. No accepting run. [2022-02-20 18:00:01,430 INFO L83 IsIncluded]: Finished isIncluded. Language is included [2022-02-20 18:00:01,431 INFO L74 IsIncluded]: Start isIncluded. First operand has 383 states, 295 states have (on average 1.4915254237288136) internal successors, (440), 298 states have internal predecessors, (440), 63 states have call successors, (63), 24 states have call predecessors, (63), 24 states have return successors, (62), 62 states have call predecessors, (62), 62 states have call successors, (62) Second operand 384 states. [2022-02-20 18:00:01,431 INFO L87 Difference]: Start difference. First operand has 383 states, 295 states have (on average 1.4915254237288136) internal successors, (440), 298 states have internal predecessors, (440), 63 states have call successors, (63), 24 states have call predecessors, (63), 24 states have return successors, (62), 62 states have call predecessors, (62), 62 states have call successors, (62) Second operand 384 states. [2022-02-20 18:00:01,441 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-02-20 18:00:01,442 INFO L93 Difference]: Finished difference Result 384 states and 566 transitions. [2022-02-20 18:00:01,442 INFO L276 IsEmpty]: Start isEmpty. Operand 384 states and 566 transitions. [2022-02-20 18:00:01,443 INFO L282 IsEmpty]: Finished isEmpty. No accepting run. [2022-02-20 18:00:01,443 INFO L83 IsIncluded]: Finished isIncluded. Language is included [2022-02-20 18:00:01,443 INFO L88 GeneralOperation]: Finished isEquivalent. [2022-02-20 18:00:01,443 INFO L221 AbstractMinimizeNwa]: Finished testing correctness of minimizeSevpa [2022-02-20 18:00:01,444 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 383 states, 295 states have (on average 1.4915254237288136) internal successors, (440), 298 states have internal predecessors, (440), 63 states have call successors, (63), 24 states have call predecessors, (63), 24 states have return successors, (62), 62 states have call predecessors, (62), 62 states have call successors, (62) [2022-02-20 18:00:01,456 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 383 states to 383 states and 565 transitions. [2022-02-20 18:00:01,456 INFO L78 Accepts]: Start accepts. Automaton has 383 states and 565 transitions. Word has length 108 [2022-02-20 18:00:01,456 INFO L84 Accepts]: Finished accepts. word is rejected. [2022-02-20 18:00:01,456 INFO L470 AbstractCegarLoop]: Abstraction has 383 states and 565 transitions. [2022-02-20 18:00:01,457 INFO L471 AbstractCegarLoop]: INTERPOLANT automaton has has 3 states, 3 states have (on average 20.0) internal successors, (60), 3 states have internal predecessors, (60), 2 states have call successors, (16), 2 states have call predecessors, (16), 2 states have return successors, (14), 2 states have call predecessors, (14), 2 states have call successors, (14) [2022-02-20 18:00:01,457 INFO L276 IsEmpty]: Start isEmpty. Operand 383 states and 565 transitions. [2022-02-20 18:00:01,458 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 118 [2022-02-20 18:00:01,458 INFO L506 BasicCegarLoop]: Found error trace [2022-02-20 18:00:01,458 INFO L514 BasicCegarLoop]: trace histogram [3, 3, 3, 3, 3, 3, 2, 2, 2, 2, 2, 2, 2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-02-20 18:00:01,479 INFO L540 MonitoredProcess]: [MP /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 -smt2 -in SMTLIB2_COMPLIANT=true (3)] Forceful destruction successful, exit code 0 [2022-02-20 18:00:01,679 WARN L452 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: 3 /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 -smt2 -in SMTLIB2_COMPLIANT=true,SelfDestructingSolverStorable1 [2022-02-20 18:00:01,679 INFO L402 AbstractCegarLoop]: === Iteration 3 === Targeting outgoingErr0ASSERT_VIOLATIONERROR_FUNCTION === [outgoingErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2022-02-20 18:00:01,679 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2022-02-20 18:00:01,680 INFO L85 PathProgramCache]: Analyzing trace with hash -2011102110, now seen corresponding path program 1 times [2022-02-20 18:00:01,680 INFO L126 FreeRefinementEngine]: Executing refinement strategy CAMEL [2022-02-20 18:00:01,680 INFO L338 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [2060140944] [2022-02-20 18:00:01,680 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-02-20 18:00:01,680 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2022-02-20 18:00:01,704 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-02-20 18:00:01,726 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 6 [2022-02-20 18:00:01,728 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-02-20 18:00:01,730 INFO L290 TraceCheckUtils]: 0: Hoare triple {5542#(and (= |old(~__ste_client_idCounter0~0)| ~__ste_client_idCounter0~0) (= |old(~__ste_client_idCounter1~0)| ~__ste_client_idCounter1~0) (= |old(~__ste_client_idCounter2~0)| ~__ste_client_idCounter2~0))} ~handle := #in~handle;~value := #in~value; {5482#true} is VALID [2022-02-20 18:00:01,730 INFO L290 TraceCheckUtils]: 1: Hoare triple {5482#true} assume 1 == ~handle;~__ste_client_idCounter0~0 := ~value; {5482#true} is VALID [2022-02-20 18:00:01,730 INFO L290 TraceCheckUtils]: 2: Hoare triple {5482#true} assume true; {5482#true} is VALID [2022-02-20 18:00:01,730 INFO L284 TraceCheckUtils]: 3: Hoare quadruple {5482#true} {5482#true} #1134#return; {5482#true} is VALID [2022-02-20 18:00:01,735 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 12 [2022-02-20 18:00:01,736 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-02-20 18:00:01,738 INFO L290 TraceCheckUtils]: 0: Hoare triple {5543#(and (= ~__ste_client_privateKey0~0 |old(~__ste_client_privateKey0~0)|) (= ~__ste_client_privateKey2~0 |old(~__ste_client_privateKey2~0)|) (= ~__ste_client_privateKey1~0 |old(~__ste_client_privateKey1~0)|))} ~handle := #in~handle;~value := #in~value; {5482#true} is VALID [2022-02-20 18:00:01,739 INFO L290 TraceCheckUtils]: 1: Hoare triple {5482#true} assume 1 == ~handle;~__ste_client_privateKey0~0 := ~value; {5482#true} is VALID [2022-02-20 18:00:01,739 INFO L290 TraceCheckUtils]: 2: Hoare triple {5482#true} assume true; {5482#true} is VALID [2022-02-20 18:00:01,739 INFO L284 TraceCheckUtils]: 3: Hoare quadruple {5482#true} {5482#true} #1136#return; {5482#true} is VALID [2022-02-20 18:00:01,739 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 18 [2022-02-20 18:00:01,740 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-02-20 18:00:01,752 INFO L290 TraceCheckUtils]: 0: Hoare triple {5542#(and (= |old(~__ste_client_idCounter0~0)| ~__ste_client_idCounter0~0) (= |old(~__ste_client_idCounter1~0)| ~__ste_client_idCounter1~0) (= |old(~__ste_client_idCounter2~0)| ~__ste_client_idCounter2~0))} ~handle := #in~handle;~value := #in~value; {5544#(= setClientId_~handle |setClientId_#in~handle|)} is VALID [2022-02-20 18:00:01,752 INFO L290 TraceCheckUtils]: 1: Hoare triple {5544#(= setClientId_~handle |setClientId_#in~handle|)} assume 1 == ~handle;~__ste_client_idCounter0~0 := ~value; {5545#(= |setClientId_#in~handle| 1)} is VALID [2022-02-20 18:00:01,753 INFO L290 TraceCheckUtils]: 2: Hoare triple {5545#(= |setClientId_#in~handle| 1)} assume true; {5545#(= |setClientId_#in~handle| 1)} is VALID [2022-02-20 18:00:01,753 INFO L284 TraceCheckUtils]: 3: Hoare quadruple {5545#(= |setClientId_#in~handle| 1)} {5492#(= |ULTIMATE.start_setup_rjh__wrappee__Base_~rjh___0#1| 2)} #1138#return; {5483#false} is VALID [2022-02-20 18:00:01,753 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 24 [2022-02-20 18:00:01,755 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-02-20 18:00:01,757 INFO L290 TraceCheckUtils]: 0: Hoare triple {5543#(and (= ~__ste_client_privateKey0~0 |old(~__ste_client_privateKey0~0)|) (= ~__ste_client_privateKey2~0 |old(~__ste_client_privateKey2~0)|) (= ~__ste_client_privateKey1~0 |old(~__ste_client_privateKey1~0)|))} ~handle := #in~handle;~value := #in~value; {5482#true} is VALID [2022-02-20 18:00:01,757 INFO L290 TraceCheckUtils]: 1: Hoare triple {5482#true} assume 1 == ~handle;~__ste_client_privateKey0~0 := ~value; {5482#true} is VALID [2022-02-20 18:00:01,757 INFO L290 TraceCheckUtils]: 2: Hoare triple {5482#true} assume true; {5482#true} is VALID [2022-02-20 18:00:01,757 INFO L284 TraceCheckUtils]: 3: Hoare quadruple {5482#true} {5483#false} #1140#return; {5483#false} is VALID [2022-02-20 18:00:01,757 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 30 [2022-02-20 18:00:01,759 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-02-20 18:00:01,760 INFO L290 TraceCheckUtils]: 0: Hoare triple {5542#(and (= |old(~__ste_client_idCounter0~0)| ~__ste_client_idCounter0~0) (= |old(~__ste_client_idCounter1~0)| ~__ste_client_idCounter1~0) (= |old(~__ste_client_idCounter2~0)| ~__ste_client_idCounter2~0))} ~handle := #in~handle;~value := #in~value; {5482#true} is VALID [2022-02-20 18:00:01,761 INFO L290 TraceCheckUtils]: 1: Hoare triple {5482#true} assume 1 == ~handle;~__ste_client_idCounter0~0 := ~value; {5482#true} is VALID [2022-02-20 18:00:01,761 INFO L290 TraceCheckUtils]: 2: Hoare triple {5482#true} assume true; {5482#true} is VALID [2022-02-20 18:00:01,761 INFO L284 TraceCheckUtils]: 3: Hoare quadruple {5482#true} {5483#false} #1142#return; {5483#false} is VALID [2022-02-20 18:00:01,761 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 36 [2022-02-20 18:00:01,762 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-02-20 18:00:01,764 INFO L290 TraceCheckUtils]: 0: Hoare triple {5543#(and (= ~__ste_client_privateKey0~0 |old(~__ste_client_privateKey0~0)|) (= ~__ste_client_privateKey2~0 |old(~__ste_client_privateKey2~0)|) (= ~__ste_client_privateKey1~0 |old(~__ste_client_privateKey1~0)|))} ~handle := #in~handle;~value := #in~value; {5482#true} is VALID [2022-02-20 18:00:01,764 INFO L290 TraceCheckUtils]: 1: Hoare triple {5482#true} assume 1 == ~handle;~__ste_client_privateKey0~0 := ~value; {5482#true} is VALID [2022-02-20 18:00:01,765 INFO L290 TraceCheckUtils]: 2: Hoare triple {5482#true} assume true; {5482#true} is VALID [2022-02-20 18:00:01,765 INFO L284 TraceCheckUtils]: 3: Hoare quadruple {5482#true} {5483#false} #1144#return; {5483#false} is VALID [2022-02-20 18:00:01,771 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 57 [2022-02-20 18:00:01,771 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-02-20 18:00:01,773 INFO L290 TraceCheckUtils]: 0: Hoare triple {5546#(and (= |old(~__ste_email_from0~0)| ~__ste_email_from0~0) (= |old(~__ste_email_from1~0)| ~__ste_email_from1~0))} ~handle := #in~handle;~value := #in~value; {5482#true} is VALID [2022-02-20 18:00:01,773 INFO L290 TraceCheckUtils]: 1: Hoare triple {5482#true} assume 1 == ~handle;~__ste_email_from0~0 := ~value; {5482#true} is VALID [2022-02-20 18:00:01,774 INFO L290 TraceCheckUtils]: 2: Hoare triple {5482#true} assume true; {5482#true} is VALID [2022-02-20 18:00:01,774 INFO L284 TraceCheckUtils]: 3: Hoare quadruple {5482#true} {5483#false} #1120#return; {5483#false} is VALID [2022-02-20 18:00:01,780 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 62 [2022-02-20 18:00:01,781 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-02-20 18:00:01,783 INFO L290 TraceCheckUtils]: 0: Hoare triple {5547#(and (= ~__ste_email_to0~0 |old(~__ste_email_to0~0)|) (= ~__ste_email_to1~0 |old(~__ste_email_to1~0)|))} ~handle := #in~handle;~value := #in~value; {5482#true} is VALID [2022-02-20 18:00:01,783 INFO L290 TraceCheckUtils]: 1: Hoare triple {5482#true} assume 1 == ~handle;~__ste_email_to0~0 := ~value; {5482#true} is VALID [2022-02-20 18:00:01,783 INFO L290 TraceCheckUtils]: 2: Hoare triple {5482#true} assume true; {5482#true} is VALID [2022-02-20 18:00:01,783 INFO L284 TraceCheckUtils]: 3: Hoare quadruple {5482#true} {5483#false} #1122#return; {5483#false} is VALID [2022-02-20 18:00:01,783 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 71 [2022-02-20 18:00:01,784 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-02-20 18:00:01,785 INFO L290 TraceCheckUtils]: 0: Hoare triple {5482#true} ~handle := #in~handle;havoc ~retValue_acc~20; {5482#true} is VALID [2022-02-20 18:00:01,785 INFO L290 TraceCheckUtils]: 1: Hoare triple {5482#true} assume 1 == ~handle;~retValue_acc~20 := ~__ste_client_privateKey0~0;#res := ~retValue_acc~20; {5482#true} is VALID [2022-02-20 18:00:01,786 INFO L290 TraceCheckUtils]: 2: Hoare triple {5482#true} assume true; {5482#true} is VALID [2022-02-20 18:00:01,786 INFO L284 TraceCheckUtils]: 3: Hoare quadruple {5482#true} {5483#false} #1054#return; {5483#false} is VALID [2022-02-20 18:00:01,786 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 79 [2022-02-20 18:00:01,786 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-02-20 18:00:01,788 INFO L290 TraceCheckUtils]: 0: Hoare triple {5482#true} ~handle := #in~handle;havoc ~retValue_acc~36; {5482#true} is VALID [2022-02-20 18:00:01,788 INFO L290 TraceCheckUtils]: 1: Hoare triple {5482#true} assume 1 == ~handle;~retValue_acc~36 := ~__ste_email_to0~0;#res := ~retValue_acc~36; {5482#true} is VALID [2022-02-20 18:00:01,788 INFO L290 TraceCheckUtils]: 2: Hoare triple {5482#true} assume true; {5482#true} is VALID [2022-02-20 18:00:01,788 INFO L284 TraceCheckUtils]: 3: Hoare quadruple {5482#true} {5483#false} #1056#return; {5483#false} is VALID [2022-02-20 18:00:01,789 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 85 [2022-02-20 18:00:01,789 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-02-20 18:00:01,791 INFO L290 TraceCheckUtils]: 0: Hoare triple {5482#true} ~handle := #in~handle;~userid := #in~userid;havoc ~retValue_acc~25; {5482#true} is VALID [2022-02-20 18:00:01,791 INFO L290 TraceCheckUtils]: 1: Hoare triple {5482#true} assume 1 == ~handle; {5482#true} is VALID [2022-02-20 18:00:01,791 INFO L290 TraceCheckUtils]: 2: Hoare triple {5482#true} assume ~userid == ~__ste_Client_Keyring0_User0~0;~retValue_acc~25 := ~__ste_Client_Keyring0_PublicKey0~0;#res := ~retValue_acc~25; {5482#true} is VALID [2022-02-20 18:00:01,791 INFO L290 TraceCheckUtils]: 3: Hoare triple {5482#true} assume true; {5482#true} is VALID [2022-02-20 18:00:01,791 INFO L284 TraceCheckUtils]: 4: Hoare quadruple {5482#true} {5483#false} #1058#return; {5483#false} is VALID [2022-02-20 18:00:01,791 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 96 [2022-02-20 18:00:01,792 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-02-20 18:00:01,794 INFO L290 TraceCheckUtils]: 0: Hoare triple {5546#(and (= |old(~__ste_email_from0~0)| ~__ste_email_from0~0) (= |old(~__ste_email_from1~0)| ~__ste_email_from1~0))} ~handle := #in~handle;~value := #in~value; {5482#true} is VALID [2022-02-20 18:00:01,794 INFO L290 TraceCheckUtils]: 1: Hoare triple {5482#true} assume 1 == ~handle;~__ste_email_from0~0 := ~value; {5482#true} is VALID [2022-02-20 18:00:01,794 INFO L290 TraceCheckUtils]: 2: Hoare triple {5482#true} assume true; {5482#true} is VALID [2022-02-20 18:00:01,794 INFO L284 TraceCheckUtils]: 3: Hoare quadruple {5482#true} {5483#false} #1064#return; {5483#false} is VALID [2022-02-20 18:00:01,794 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 102 [2022-02-20 18:00:01,795 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-02-20 18:00:01,796 INFO L290 TraceCheckUtils]: 0: Hoare triple {5482#true} ~handle := #in~handle;havoc ~retValue_acc~41; {5482#true} is VALID [2022-02-20 18:00:01,796 INFO L290 TraceCheckUtils]: 1: Hoare triple {5482#true} assume 1 == ~handle;~retValue_acc~41 := ~__ste_email_isSigned0~0;#res := ~retValue_acc~41; {5482#true} is VALID [2022-02-20 18:00:01,797 INFO L290 TraceCheckUtils]: 2: Hoare triple {5482#true} assume true; {5482#true} is VALID [2022-02-20 18:00:01,797 INFO L284 TraceCheckUtils]: 3: Hoare quadruple {5482#true} {5483#false} #1066#return; {5483#false} is VALID [2022-02-20 18:00:01,797 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 109 [2022-02-20 18:00:01,797 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-02-20 18:00:01,800 INFO L290 TraceCheckUtils]: 0: Hoare triple {5482#true} ~handle := #in~handle;havoc ~retValue_acc~20; {5482#true} is VALID [2022-02-20 18:00:01,800 INFO L290 TraceCheckUtils]: 1: Hoare triple {5482#true} assume 1 == ~handle;~retValue_acc~20 := ~__ste_client_privateKey0~0;#res := ~retValue_acc~20; {5482#true} is VALID [2022-02-20 18:00:01,801 INFO L290 TraceCheckUtils]: 2: Hoare triple {5482#true} assume true; {5482#true} is VALID [2022-02-20 18:00:01,801 INFO L284 TraceCheckUtils]: 3: Hoare quadruple {5482#true} {5483#false} #1068#return; {5483#false} is VALID [2022-02-20 18:00:01,801 INFO L290 TraceCheckUtils]: 0: Hoare triple {5482#true} assume { :begin_inline_ULTIMATE.init } true;#NULL.base, #NULL.offset := 0, 0;assume 0 == #valid[0];assume 0 < #StackHeapBarrier;call #Ultimate.allocInit(2, 1);call write~init~int(48, 1, 0, 1);call write~init~int(0, 1, 1, 1);call #Ultimate.allocInit(28, 2);call #Ultimate.allocInit(12, 3);call #Ultimate.allocInit(30, 4);call #Ultimate.allocInit(9, 5);call #Ultimate.allocInit(21, 6);call #Ultimate.allocInit(30, 7);call #Ultimate.allocInit(9, 8);call #Ultimate.allocInit(21, 9);call #Ultimate.allocInit(30, 10);call #Ultimate.allocInit(9, 11);call #Ultimate.allocInit(25, 12);call #Ultimate.allocInit(30, 13);call #Ultimate.allocInit(9, 14);call #Ultimate.allocInit(25, 15);call #Ultimate.allocInit(44, 16);call #Ultimate.allocInit(44, 17);call #Ultimate.allocInit(9, 18);call #Ultimate.allocInit(9, 19);call #Ultimate.allocInit(11, 20);call #Ultimate.allocInit(19, 21);call #Ultimate.allocInit(4, 22);call write~init~int(37, 22, 0, 1);call write~init~int(100, 22, 1, 1);call write~init~int(10, 22, 2, 1);call write~init~int(0, 22, 3, 1);call #Ultimate.allocInit(4, 23);call write~init~int(37, 23, 0, 1);call write~init~int(100, 23, 1, 1);call write~init~int(10, 23, 2, 1);call write~init~int(0, 23, 3, 1);call #Ultimate.allocInit(10, 24);call #Ultimate.allocInit(16, 25);call #Ultimate.allocInit(20, 26);call #Ultimate.allocInit(22, 27);call #Ultimate.allocInit(21, 28);call #Ultimate.allocInit(10, 29);call #Ultimate.allocInit(12, 30);call #Ultimate.allocInit(10, 31);call #Ultimate.allocInit(18, 32);call #Ultimate.allocInit(16, 33);call #Ultimate.allocInit(21, 34);call #Ultimate.allocInit(13, 35);call #Ultimate.allocInit(16, 36);call #Ultimate.allocInit(25, 37);call #Ultimate.allocInit(4, 38);call write~init~int(37, 38, 0, 1);call write~init~int(115, 38, 1, 1);call write~init~int(10, 38, 2, 1);call write~init~int(0, 38, 3, 1);call #Ultimate.allocInit(13, 39);~head~0.base, ~head~0.offset := 0, 0;~__SELECTED_FEATURE_Base~0 := 0;~__SELECTED_FEATURE_Keys~0 := 0;~__SELECTED_FEATURE_Encrypt~0 := 0;~__SELECTED_FEATURE_AutoResponder~0 := 0;~__SELECTED_FEATURE_AddressBook~0 := 0;~__SELECTED_FEATURE_Sign~0 := 0;~__SELECTED_FEATURE_Forward~0 := 0;~__SELECTED_FEATURE_Verify~0 := 0;~__SELECTED_FEATURE_Decrypt~0 := 0;~__GUIDSL_ROOT_PRODUCTION~0 := 0;~__GUIDSL_NON_TERMINAL_main~0 := 0;~bob~0 := 0;~rjh~0 := 0;~chuck~0 := 0;~queue_empty~0 := 1;~queued_message~0 := 0;~queued_client~0 := 0;~__ste_Client_counter~0 := 0;~__ste_client_name0~0.base, ~__ste_client_name0~0.offset := 0, 0;~__ste_client_name1~0.base, ~__ste_client_name1~0.offset := 0, 0;~__ste_client_name2~0.base, ~__ste_client_name2~0.offset := 0, 0;~__ste_client_outbuffer0~0 := 0;~__ste_client_outbuffer1~0 := 0;~__ste_client_outbuffer2~0 := 0;~__ste_client_outbuffer3~0 := 0;~__ste_ClientAddressBook_size0~0 := 0;~__ste_ClientAddressBook_size1~0 := 0;~__ste_ClientAddressBook_size2~0 := 0;~__ste_Client_AddressBook0_Alias0~0 := 0;~__ste_Client_AddressBook0_Alias1~0 := 0;~__ste_Client_AddressBook0_Alias2~0 := 0;~__ste_Client_AddressBook1_Alias0~0 := 0;~__ste_Client_AddressBook1_Alias1~0 := 0;~__ste_Client_AddressBook1_Alias2~0 := 0;~__ste_Client_AddressBook2_Alias0~0 := 0;~__ste_Client_AddressBook2_Alias1~0 := 0;~__ste_Client_AddressBook2_Alias2~0 := 0;~__ste_Client_AddressBook0_Address0~0 := 0;~__ste_Client_AddressBook0_Address1~0 := 0;~__ste_Client_AddressBook0_Address2~0 := 0;~__ste_Client_AddressBook1_Address0~0 := 0;~__ste_Client_AddressBook1_Address1~0 := 0;~__ste_Client_AddressBook1_Address2~0 := 0;~__ste_Client_AddressBook2_Address0~0 := 0;~__ste_Client_AddressBook2_Address1~0 := 0;~__ste_Client_AddressBook2_Address2~0 := 0;~__ste_client_autoResponse0~0 := 0;~__ste_client_autoResponse1~0 := 0;~__ste_client_autoResponse2~0 := 0;~__ste_client_privateKey0~0 := 0;~__ste_client_privateKey1~0 := 0;~__ste_client_privateKey2~0 := 0;~__ste_ClientKeyring_size0~0 := 0;~__ste_ClientKeyring_size1~0 := 0;~__ste_ClientKeyring_size2~0 := 0;~__ste_Client_Keyring0_User0~0 := 0;~__ste_Client_Keyring0_User1~0 := 0;~__ste_Client_Keyring0_User2~0 := 0;~__ste_Client_Keyring1_User0~0 := 0;~__ste_Client_Keyring1_User1~0 := 0;~__ste_Client_Keyring1_User2~0 := 0;~__ste_Client_Keyring2_User0~0 := 0;~__ste_Client_Keyring2_User1~0 := 0;~__ste_Client_Keyring2_User2~0 := 0;~__ste_Client_Keyring0_PublicKey0~0 := 0;~__ste_Client_Keyring0_PublicKey1~0 := 0;~__ste_Client_Keyring0_PublicKey2~0 := 0;~__ste_Client_Keyring1_PublicKey0~0 := 0;~__ste_Client_Keyring1_PublicKey1~0 := 0;~__ste_Client_Keyring1_PublicKey2~0 := 0;~__ste_Client_Keyring2_PublicKey0~0 := 0;~__ste_Client_Keyring2_PublicKey1~0 := 0;~__ste_Client_Keyring2_PublicKey2~0 := 0;~__ste_client_forwardReceiver0~0 := 0;~__ste_client_forwardReceiver1~0 := 0;~__ste_client_forwardReceiver2~0 := 0;~__ste_client_forwardReceiver3~0 := 0;~__ste_client_idCounter0~0 := 0;~__ste_client_idCounter1~0 := 0;~__ste_client_idCounter2~0 := 0;~__ste_Email_counter~0 := 0;~__ste_email_id0~0 := 0;~__ste_email_id1~0 := 0;~__ste_email_from0~0 := 0;~__ste_email_from1~0 := 0;~__ste_email_to0~0 := 0;~__ste_email_to1~0 := 0;~__ste_email_subject0~0.base, ~__ste_email_subject0~0.offset := 0, 0;~__ste_email_subject1~0.base, ~__ste_email_subject1~0.offset := 0, 0;~__ste_email_body0~0.base, ~__ste_email_body0~0.offset := 0, 0;~__ste_email_body1~0.base, ~__ste_email_body1~0.offset := 0, 0;~__ste_email_isEncrypted0~0 := 0;~__ste_email_isEncrypted1~0 := 0;~__ste_email_encryptionKey0~0 := 0;~__ste_email_encryptionKey1~0 := 0;~__ste_email_isSigned0~0 := 0;~__ste_email_isSigned1~0 := 0;~__ste_email_signKey0~0 := 0;~__ste_email_signKey1~0 := 0;~__ste_email_isSignatureVerified0~0 := 0;~__ste_email_isSignatureVerified1~0 := 0; {5482#true} is VALID [2022-02-20 18:00:01,801 INFO L290 TraceCheckUtils]: 1: Hoare triple {5482#true} assume { :end_inline_ULTIMATE.init } true;assume { :begin_inline_main } true;havoc main_#res#1;havoc main_#t~ret35#1, main_~retValue_acc~3#1, main_~tmp~4#1;havoc main_~retValue_acc~3#1;havoc main_~tmp~4#1;assume { :begin_inline_select_helpers } true; {5482#true} is VALID [2022-02-20 18:00:01,801 INFO L290 TraceCheckUtils]: 2: Hoare triple {5482#true} assume { :end_inline_select_helpers } true;assume { :begin_inline_select_features } true; {5482#true} is VALID [2022-02-20 18:00:01,801 INFO L290 TraceCheckUtils]: 3: Hoare triple {5482#true} assume { :end_inline_select_features } true;assume { :begin_inline_valid_product } true;havoc valid_product_#res#1;havoc valid_product_~retValue_acc~5#1;havoc valid_product_~retValue_acc~5#1;valid_product_~retValue_acc~5#1 := 1;valid_product_#res#1 := valid_product_~retValue_acc~5#1; {5482#true} is VALID [2022-02-20 18:00:01,801 INFO L290 TraceCheckUtils]: 4: Hoare triple {5482#true} main_#t~ret35#1 := valid_product_#res#1;assume { :end_inline_valid_product } true;assume -2147483648 <= main_#t~ret35#1 && main_#t~ret35#1 <= 2147483647;main_~tmp~4#1 := main_#t~ret35#1;havoc main_#t~ret35#1; {5482#true} is VALID [2022-02-20 18:00:01,801 INFO L290 TraceCheckUtils]: 5: Hoare triple {5482#true} assume 0 != main_~tmp~4#1;assume { :begin_inline_setup } true;havoc setup_#t~nondet32#1, setup_#t~nondet33#1, setup_#t~nondet34#1, setup_~__cil_tmp1~0#1.base, setup_~__cil_tmp1~0#1.offset, setup_~__cil_tmp2~0#1.base, setup_~__cil_tmp2~0#1.offset, setup_~__cil_tmp3~0#1.base, setup_~__cil_tmp3~0#1.offset;havoc setup_~__cil_tmp1~0#1.base, setup_~__cil_tmp1~0#1.offset;havoc setup_~__cil_tmp2~0#1.base, setup_~__cil_tmp2~0#1.offset;havoc setup_~__cil_tmp3~0#1.base, setup_~__cil_tmp3~0#1.offset;~bob~0 := 1;assume { :begin_inline_setup_bob } true;setup_bob_#in~bob___0#1 := ~bob~0;havoc setup_bob_~bob___0#1;setup_bob_~bob___0#1 := setup_bob_#in~bob___0#1;assume { :begin_inline_setup_bob__wrappee__Base } true;setup_bob__wrappee__Base_#in~bob___0#1 := setup_bob_~bob___0#1;havoc setup_bob__wrappee__Base_~bob___0#1;setup_bob__wrappee__Base_~bob___0#1 := setup_bob__wrappee__Base_#in~bob___0#1; {5482#true} is VALID [2022-02-20 18:00:01,802 INFO L272 TraceCheckUtils]: 6: Hoare triple {5482#true} call setClientId(setup_bob__wrappee__Base_~bob___0#1, setup_bob__wrappee__Base_~bob___0#1); {5542#(and (= |old(~__ste_client_idCounter0~0)| ~__ste_client_idCounter0~0) (= |old(~__ste_client_idCounter1~0)| ~__ste_client_idCounter1~0) (= |old(~__ste_client_idCounter2~0)| ~__ste_client_idCounter2~0))} is VALID [2022-02-20 18:00:01,802 INFO L290 TraceCheckUtils]: 7: Hoare triple {5542#(and (= |old(~__ste_client_idCounter0~0)| ~__ste_client_idCounter0~0) (= |old(~__ste_client_idCounter1~0)| ~__ste_client_idCounter1~0) (= |old(~__ste_client_idCounter2~0)| ~__ste_client_idCounter2~0))} ~handle := #in~handle;~value := #in~value; {5482#true} is VALID [2022-02-20 18:00:01,802 INFO L290 TraceCheckUtils]: 8: Hoare triple {5482#true} assume 1 == ~handle;~__ste_client_idCounter0~0 := ~value; {5482#true} is VALID [2022-02-20 18:00:01,802 INFO L290 TraceCheckUtils]: 9: Hoare triple {5482#true} assume true; {5482#true} is VALID [2022-02-20 18:00:01,803 INFO L284 TraceCheckUtils]: 10: Hoare quadruple {5482#true} {5482#true} #1134#return; {5482#true} is VALID [2022-02-20 18:00:01,803 INFO L290 TraceCheckUtils]: 11: Hoare triple {5482#true} assume { :end_inline_setup_bob__wrappee__Base } true; {5482#true} is VALID [2022-02-20 18:00:01,803 INFO L272 TraceCheckUtils]: 12: Hoare triple {5482#true} call setClientPrivateKey(setup_bob_~bob___0#1, 123); {5543#(and (= ~__ste_client_privateKey0~0 |old(~__ste_client_privateKey0~0)|) (= ~__ste_client_privateKey2~0 |old(~__ste_client_privateKey2~0)|) (= ~__ste_client_privateKey1~0 |old(~__ste_client_privateKey1~0)|))} is VALID [2022-02-20 18:00:01,803 INFO L290 TraceCheckUtils]: 13: Hoare triple {5543#(and (= ~__ste_client_privateKey0~0 |old(~__ste_client_privateKey0~0)|) (= ~__ste_client_privateKey2~0 |old(~__ste_client_privateKey2~0)|) (= ~__ste_client_privateKey1~0 |old(~__ste_client_privateKey1~0)|))} ~handle := #in~handle;~value := #in~value; {5482#true} is VALID [2022-02-20 18:00:01,803 INFO L290 TraceCheckUtils]: 14: Hoare triple {5482#true} assume 1 == ~handle;~__ste_client_privateKey0~0 := ~value; {5482#true} is VALID [2022-02-20 18:00:01,804 INFO L290 TraceCheckUtils]: 15: Hoare triple {5482#true} assume true; {5482#true} is VALID [2022-02-20 18:00:01,804 INFO L284 TraceCheckUtils]: 16: Hoare quadruple {5482#true} {5482#true} #1136#return; {5482#true} is VALID [2022-02-20 18:00:01,804 INFO L290 TraceCheckUtils]: 17: Hoare triple {5482#true} assume { :end_inline_setup_bob } true;setup_~__cil_tmp1~0#1.base, setup_~__cil_tmp1~0#1.offset := 18, 0;havoc setup_#t~nondet32#1;~rjh~0 := 2;assume { :begin_inline_setup_rjh } true;setup_rjh_#in~rjh___0#1 := ~rjh~0;havoc setup_rjh_~rjh___0#1;setup_rjh_~rjh___0#1 := setup_rjh_#in~rjh___0#1;assume { :begin_inline_setup_rjh__wrappee__Base } true;setup_rjh__wrappee__Base_#in~rjh___0#1 := setup_rjh_~rjh___0#1;havoc setup_rjh__wrappee__Base_~rjh___0#1;setup_rjh__wrappee__Base_~rjh___0#1 := setup_rjh__wrappee__Base_#in~rjh___0#1; {5492#(= |ULTIMATE.start_setup_rjh__wrappee__Base_~rjh___0#1| 2)} is VALID [2022-02-20 18:00:01,806 INFO L272 TraceCheckUtils]: 18: Hoare triple {5492#(= |ULTIMATE.start_setup_rjh__wrappee__Base_~rjh___0#1| 2)} call setClientId(setup_rjh__wrappee__Base_~rjh___0#1, setup_rjh__wrappee__Base_~rjh___0#1); {5542#(and (= |old(~__ste_client_idCounter0~0)| ~__ste_client_idCounter0~0) (= |old(~__ste_client_idCounter1~0)| ~__ste_client_idCounter1~0) (= |old(~__ste_client_idCounter2~0)| ~__ste_client_idCounter2~0))} is VALID [2022-02-20 18:00:01,806 INFO L290 TraceCheckUtils]: 19: Hoare triple {5542#(and (= |old(~__ste_client_idCounter0~0)| ~__ste_client_idCounter0~0) (= |old(~__ste_client_idCounter1~0)| ~__ste_client_idCounter1~0) (= |old(~__ste_client_idCounter2~0)| ~__ste_client_idCounter2~0))} ~handle := #in~handle;~value := #in~value; {5544#(= setClientId_~handle |setClientId_#in~handle|)} is VALID [2022-02-20 18:00:01,807 INFO L290 TraceCheckUtils]: 20: Hoare triple {5544#(= setClientId_~handle |setClientId_#in~handle|)} assume 1 == ~handle;~__ste_client_idCounter0~0 := ~value; {5545#(= |setClientId_#in~handle| 1)} is VALID [2022-02-20 18:00:01,807 INFO L290 TraceCheckUtils]: 21: Hoare triple {5545#(= |setClientId_#in~handle| 1)} assume true; {5545#(= |setClientId_#in~handle| 1)} is VALID [2022-02-20 18:00:01,808 INFO L284 TraceCheckUtils]: 22: Hoare quadruple {5545#(= |setClientId_#in~handle| 1)} {5492#(= |ULTIMATE.start_setup_rjh__wrappee__Base_~rjh___0#1| 2)} #1138#return; {5483#false} is VALID [2022-02-20 18:00:01,808 INFO L290 TraceCheckUtils]: 23: Hoare triple {5483#false} assume { :end_inline_setup_rjh__wrappee__Base } true; {5483#false} is VALID [2022-02-20 18:00:01,808 INFO L272 TraceCheckUtils]: 24: Hoare triple {5483#false} call setClientPrivateKey(setup_rjh_~rjh___0#1, 456); {5543#(and (= ~__ste_client_privateKey0~0 |old(~__ste_client_privateKey0~0)|) (= ~__ste_client_privateKey2~0 |old(~__ste_client_privateKey2~0)|) (= ~__ste_client_privateKey1~0 |old(~__ste_client_privateKey1~0)|))} is VALID [2022-02-20 18:00:01,808 INFO L290 TraceCheckUtils]: 25: Hoare triple {5543#(and (= ~__ste_client_privateKey0~0 |old(~__ste_client_privateKey0~0)|) (= ~__ste_client_privateKey2~0 |old(~__ste_client_privateKey2~0)|) (= ~__ste_client_privateKey1~0 |old(~__ste_client_privateKey1~0)|))} ~handle := #in~handle;~value := #in~value; {5482#true} is VALID [2022-02-20 18:00:01,808 INFO L290 TraceCheckUtils]: 26: Hoare triple {5482#true} assume 1 == ~handle;~__ste_client_privateKey0~0 := ~value; {5482#true} is VALID [2022-02-20 18:00:01,808 INFO L290 TraceCheckUtils]: 27: Hoare triple {5482#true} assume true; {5482#true} is VALID [2022-02-20 18:00:01,808 INFO L284 TraceCheckUtils]: 28: Hoare quadruple {5482#true} {5483#false} #1140#return; {5483#false} is VALID [2022-02-20 18:00:01,808 INFO L290 TraceCheckUtils]: 29: Hoare triple {5483#false} assume { :end_inline_setup_rjh } true;setup_~__cil_tmp2~0#1.base, setup_~__cil_tmp2~0#1.offset := 19, 0;havoc setup_#t~nondet33#1;~chuck~0 := 3;assume { :begin_inline_setup_chuck } true;setup_chuck_#in~chuck___0#1 := ~chuck~0;havoc setup_chuck_~chuck___0#1;setup_chuck_~chuck___0#1 := setup_chuck_#in~chuck___0#1;assume { :begin_inline_setup_chuck__wrappee__Base } true;setup_chuck__wrappee__Base_#in~chuck___0#1 := setup_chuck_~chuck___0#1;havoc setup_chuck__wrappee__Base_~chuck___0#1;setup_chuck__wrappee__Base_~chuck___0#1 := setup_chuck__wrappee__Base_#in~chuck___0#1; {5483#false} is VALID [2022-02-20 18:00:01,808 INFO L272 TraceCheckUtils]: 30: Hoare triple {5483#false} call setClientId(setup_chuck__wrappee__Base_~chuck___0#1, setup_chuck__wrappee__Base_~chuck___0#1); {5542#(and (= |old(~__ste_client_idCounter0~0)| ~__ste_client_idCounter0~0) (= |old(~__ste_client_idCounter1~0)| ~__ste_client_idCounter1~0) (= |old(~__ste_client_idCounter2~0)| ~__ste_client_idCounter2~0))} is VALID [2022-02-20 18:00:01,809 INFO L290 TraceCheckUtils]: 31: Hoare triple {5542#(and (= |old(~__ste_client_idCounter0~0)| ~__ste_client_idCounter0~0) (= |old(~__ste_client_idCounter1~0)| ~__ste_client_idCounter1~0) (= |old(~__ste_client_idCounter2~0)| ~__ste_client_idCounter2~0))} ~handle := #in~handle;~value := #in~value; {5482#true} is VALID [2022-02-20 18:00:01,809 INFO L290 TraceCheckUtils]: 32: Hoare triple {5482#true} assume 1 == ~handle;~__ste_client_idCounter0~0 := ~value; {5482#true} is VALID [2022-02-20 18:00:01,809 INFO L290 TraceCheckUtils]: 33: Hoare triple {5482#true} assume true; {5482#true} is VALID [2022-02-20 18:00:01,809 INFO L284 TraceCheckUtils]: 34: Hoare quadruple {5482#true} {5483#false} #1142#return; {5483#false} is VALID [2022-02-20 18:00:01,809 INFO L290 TraceCheckUtils]: 35: Hoare triple {5483#false} assume { :end_inline_setup_chuck__wrappee__Base } true; {5483#false} is VALID [2022-02-20 18:00:01,809 INFO L272 TraceCheckUtils]: 36: Hoare triple {5483#false} call setClientPrivateKey(setup_chuck_~chuck___0#1, 789); {5543#(and (= ~__ste_client_privateKey0~0 |old(~__ste_client_privateKey0~0)|) (= ~__ste_client_privateKey2~0 |old(~__ste_client_privateKey2~0)|) (= ~__ste_client_privateKey1~0 |old(~__ste_client_privateKey1~0)|))} is VALID [2022-02-20 18:00:01,809 INFO L290 TraceCheckUtils]: 37: Hoare triple {5543#(and (= ~__ste_client_privateKey0~0 |old(~__ste_client_privateKey0~0)|) (= ~__ste_client_privateKey2~0 |old(~__ste_client_privateKey2~0)|) (= ~__ste_client_privateKey1~0 |old(~__ste_client_privateKey1~0)|))} ~handle := #in~handle;~value := #in~value; {5482#true} is VALID [2022-02-20 18:00:01,809 INFO L290 TraceCheckUtils]: 38: Hoare triple {5482#true} assume 1 == ~handle;~__ste_client_privateKey0~0 := ~value; {5482#true} is VALID [2022-02-20 18:00:01,809 INFO L290 TraceCheckUtils]: 39: Hoare triple {5482#true} assume true; {5482#true} is VALID [2022-02-20 18:00:01,810 INFO L284 TraceCheckUtils]: 40: Hoare quadruple {5482#true} {5483#false} #1144#return; {5483#false} is VALID [2022-02-20 18:00:01,810 INFO L290 TraceCheckUtils]: 41: Hoare triple {5483#false} assume { :end_inline_setup_chuck } true;setup_~__cil_tmp3~0#1.base, setup_~__cil_tmp3~0#1.offset := 20, 0;havoc setup_#t~nondet34#1; {5483#false} is VALID [2022-02-20 18:00:01,810 INFO L290 TraceCheckUtils]: 42: Hoare triple {5483#false} assume { :end_inline_setup } true;assume { :begin_inline_test } true;havoc test_#t~nondet47#1, test_#t~nondet48#1, test_#t~nondet49#1, test_#t~nondet50#1, test_#t~nondet51#1, test_#t~nondet52#1, test_#t~nondet53#1, test_#t~nondet54#1, test_#t~nondet55#1, test_#t~nondet56#1, test_#t~nondet57#1, test_~op1~0#1, test_~op2~0#1, test_~op3~0#1, test_~op4~0#1, test_~op5~0#1, test_~op6~0#1, test_~op7~0#1, test_~op8~0#1, test_~op9~0#1, test_~op10~0#1, test_~op11~0#1, test_~splverifierCounter~0#1, test_~tmp~6#1, test_~tmp___0~2#1, test_~tmp___1~1#1, test_~tmp___2~0#1, test_~tmp___3~0#1, test_~tmp___4~0#1, test_~tmp___5~0#1, test_~tmp___6~0#1, test_~tmp___7~0#1, test_~tmp___8~0#1, test_~tmp___9~0#1;havoc test_~op1~0#1;havoc test_~op2~0#1;havoc test_~op3~0#1;havoc test_~op4~0#1;havoc test_~op5~0#1;havoc test_~op6~0#1;havoc test_~op7~0#1;havoc test_~op8~0#1;havoc test_~op9~0#1;havoc test_~op10~0#1;havoc test_~op11~0#1;havoc test_~splverifierCounter~0#1;havoc test_~tmp~6#1;havoc test_~tmp___0~2#1;havoc test_~tmp___1~1#1;havoc test_~tmp___2~0#1;havoc test_~tmp___3~0#1;havoc test_~tmp___4~0#1;havoc test_~tmp___5~0#1;havoc test_~tmp___6~0#1;havoc test_~tmp___7~0#1;havoc test_~tmp___8~0#1;havoc test_~tmp___9~0#1;test_~op1~0#1 := 0;test_~op2~0#1 := 0;test_~op3~0#1 := 0;test_~op4~0#1 := 0;test_~op5~0#1 := 0;test_~op6~0#1 := 0;test_~op7~0#1 := 0;test_~op8~0#1 := 0;test_~op9~0#1 := 0;test_~op10~0#1 := 0;test_~op11~0#1 := 0;test_~splverifierCounter~0#1 := 0; {5483#false} is VALID [2022-02-20 18:00:01,810 INFO L290 TraceCheckUtils]: 43: Hoare triple {5483#false} assume !false; {5483#false} is VALID [2022-02-20 18:00:01,810 INFO L290 TraceCheckUtils]: 44: Hoare triple {5483#false} assume test_~splverifierCounter~0#1 < 4; {5483#false} is VALID [2022-02-20 18:00:01,810 INFO L290 TraceCheckUtils]: 45: Hoare triple {5483#false} test_~splverifierCounter~0#1 := 1 + test_~splverifierCounter~0#1; {5483#false} is VALID [2022-02-20 18:00:01,810 INFO L290 TraceCheckUtils]: 46: Hoare triple {5483#false} assume !(0 == test_~op1~0#1); {5483#false} is VALID [2022-02-20 18:00:01,810 INFO L290 TraceCheckUtils]: 47: Hoare triple {5483#false} assume 0 == test_~op2~0#1;assume -2147483648 <= test_#t~nondet48#1 && test_#t~nondet48#1 <= 2147483647;test_~tmp___8~0#1 := test_#t~nondet48#1;havoc test_#t~nondet48#1; {5483#false} is VALID [2022-02-20 18:00:01,811 INFO L290 TraceCheckUtils]: 48: Hoare triple {5483#false} assume 0 != test_~tmp___8~0#1;assume { :begin_inline_rjhSetAutoRespond } true;assume { :begin_inline_setClientAutoResponse } true;setClientAutoResponse_#in~handle#1, setClientAutoResponse_#in~value#1 := ~rjh~0, 1;havoc setClientAutoResponse_~handle#1, setClientAutoResponse_~value#1;setClientAutoResponse_~handle#1 := setClientAutoResponse_#in~handle#1;setClientAutoResponse_~value#1 := setClientAutoResponse_#in~value#1; {5483#false} is VALID [2022-02-20 18:00:01,811 INFO L290 TraceCheckUtils]: 49: Hoare triple {5483#false} assume 1 == setClientAutoResponse_~handle#1;~__ste_client_autoResponse0~0 := setClientAutoResponse_~value#1; {5483#false} is VALID [2022-02-20 18:00:01,811 INFO L290 TraceCheckUtils]: 50: Hoare triple {5483#false} assume { :end_inline_setClientAutoResponse } true; {5483#false} is VALID [2022-02-20 18:00:01,811 INFO L290 TraceCheckUtils]: 51: Hoare triple {5483#false} assume { :end_inline_rjhSetAutoRespond } true;test_~op2~0#1 := 1; {5483#false} is VALID [2022-02-20 18:00:01,811 INFO L290 TraceCheckUtils]: 52: Hoare triple {5483#false} assume !false; {5483#false} is VALID [2022-02-20 18:00:01,811 INFO L290 TraceCheckUtils]: 53: Hoare triple {5483#false} assume !(test_~splverifierCounter~0#1 < 4); {5483#false} is VALID [2022-02-20 18:00:01,811 INFO L290 TraceCheckUtils]: 54: Hoare triple {5483#false} assume { :begin_inline_bobToRjh } true;havoc bobToRjh_#t~ret27#1, bobToRjh_#t~ret28#1, bobToRjh_#t~ret29#1, bobToRjh_#t~ret30#1, bobToRjh_~tmp~3#1, bobToRjh_~tmp___0~0#1, bobToRjh_~tmp___1~0#1;havoc bobToRjh_~tmp~3#1;havoc bobToRjh_~tmp___0~0#1;havoc bobToRjh_~tmp___1~0#1;call bobToRjh_#t~ret27#1 := puts(16, 0);assume -2147483648 <= bobToRjh_#t~ret27#1 && bobToRjh_#t~ret27#1 <= 2147483647;havoc bobToRjh_#t~ret27#1; {5483#false} is VALID [2022-02-20 18:00:01,811 INFO L272 TraceCheckUtils]: 55: Hoare triple {5483#false} call sendEmail(~bob~0, ~rjh~0); {5483#false} is VALID [2022-02-20 18:00:01,811 INFO L290 TraceCheckUtils]: 56: Hoare triple {5483#false} ~sender#1 := #in~sender#1;~receiver#1 := #in~receiver#1;havoc ~email~0#1;havoc ~tmp~14#1;assume { :begin_inline_createEmail } true;createEmail_#in~from#1, createEmail_#in~to#1 := 0, ~receiver#1;havoc createEmail_#res#1;havoc createEmail_~from#1, createEmail_~to#1, createEmail_~retValue_acc~31#1, createEmail_~msg~0#1;createEmail_~from#1 := createEmail_#in~from#1;createEmail_~to#1 := createEmail_#in~to#1;havoc createEmail_~retValue_acc~31#1;havoc createEmail_~msg~0#1;createEmail_~msg~0#1 := 1; {5483#false} is VALID [2022-02-20 18:00:01,812 INFO L272 TraceCheckUtils]: 57: Hoare triple {5483#false} call setEmailFrom(createEmail_~msg~0#1, createEmail_~from#1); {5546#(and (= |old(~__ste_email_from0~0)| ~__ste_email_from0~0) (= |old(~__ste_email_from1~0)| ~__ste_email_from1~0))} is VALID [2022-02-20 18:00:01,812 INFO L290 TraceCheckUtils]: 58: Hoare triple {5546#(and (= |old(~__ste_email_from0~0)| ~__ste_email_from0~0) (= |old(~__ste_email_from1~0)| ~__ste_email_from1~0))} ~handle := #in~handle;~value := #in~value; {5482#true} is VALID [2022-02-20 18:00:01,812 INFO L290 TraceCheckUtils]: 59: Hoare triple {5482#true} assume 1 == ~handle;~__ste_email_from0~0 := ~value; {5482#true} is VALID [2022-02-20 18:00:01,812 INFO L290 TraceCheckUtils]: 60: Hoare triple {5482#true} assume true; {5482#true} is VALID [2022-02-20 18:00:01,812 INFO L284 TraceCheckUtils]: 61: Hoare quadruple {5482#true} {5483#false} #1120#return; {5483#false} is VALID [2022-02-20 18:00:01,812 INFO L272 TraceCheckUtils]: 62: Hoare triple {5483#false} call setEmailTo(createEmail_~msg~0#1, createEmail_~to#1); {5547#(and (= ~__ste_email_to0~0 |old(~__ste_email_to0~0)|) (= ~__ste_email_to1~0 |old(~__ste_email_to1~0)|))} is VALID [2022-02-20 18:00:01,812 INFO L290 TraceCheckUtils]: 63: Hoare triple {5547#(and (= ~__ste_email_to0~0 |old(~__ste_email_to0~0)|) (= ~__ste_email_to1~0 |old(~__ste_email_to1~0)|))} ~handle := #in~handle;~value := #in~value; {5482#true} is VALID [2022-02-20 18:00:01,812 INFO L290 TraceCheckUtils]: 64: Hoare triple {5482#true} assume 1 == ~handle;~__ste_email_to0~0 := ~value; {5482#true} is VALID [2022-02-20 18:00:01,812 INFO L290 TraceCheckUtils]: 65: Hoare triple {5482#true} assume true; {5482#true} is VALID [2022-02-20 18:00:01,813 INFO L284 TraceCheckUtils]: 66: Hoare quadruple {5482#true} {5483#false} #1122#return; {5483#false} is VALID [2022-02-20 18:00:01,813 INFO L290 TraceCheckUtils]: 67: Hoare triple {5483#false} createEmail_~retValue_acc~31#1 := createEmail_~msg~0#1;createEmail_#res#1 := createEmail_~retValue_acc~31#1; {5483#false} is VALID [2022-02-20 18:00:01,813 INFO L290 TraceCheckUtils]: 68: Hoare triple {5483#false} #t~ret72#1 := createEmail_#res#1;assume { :end_inline_createEmail } true;assume -2147483648 <= #t~ret72#1 && #t~ret72#1 <= 2147483647;~tmp~14#1 := #t~ret72#1;havoc #t~ret72#1;~email~0#1 := ~tmp~14#1; {5483#false} is VALID [2022-02-20 18:00:01,813 INFO L272 TraceCheckUtils]: 69: Hoare triple {5483#false} call outgoing(~sender#1, ~email~0#1); {5483#false} is VALID [2022-02-20 18:00:01,813 INFO L290 TraceCheckUtils]: 70: Hoare triple {5483#false} ~client#1 := #in~client#1;~msg#1 := #in~msg#1;assume { :begin_inline_sign } true;sign_#in~client#1, sign_#in~msg#1 := ~client#1, ~msg#1;havoc sign_#t~ret76#1, sign_~client#1, sign_~msg#1, sign_~privkey~1#1, sign_~tmp~16#1;sign_~client#1 := sign_#in~client#1;sign_~msg#1 := sign_#in~msg#1;havoc sign_~privkey~1#1;havoc sign_~tmp~16#1; {5483#false} is VALID [2022-02-20 18:00:01,813 INFO L272 TraceCheckUtils]: 71: Hoare triple {5483#false} call sign_#t~ret76#1 := getClientPrivateKey(sign_~client#1); {5482#true} is VALID [2022-02-20 18:00:01,813 INFO L290 TraceCheckUtils]: 72: Hoare triple {5482#true} ~handle := #in~handle;havoc ~retValue_acc~20; {5482#true} is VALID [2022-02-20 18:00:01,813 INFO L290 TraceCheckUtils]: 73: Hoare triple {5482#true} assume 1 == ~handle;~retValue_acc~20 := ~__ste_client_privateKey0~0;#res := ~retValue_acc~20; {5482#true} is VALID [2022-02-20 18:00:01,813 INFO L290 TraceCheckUtils]: 74: Hoare triple {5482#true} assume true; {5482#true} is VALID [2022-02-20 18:00:01,813 INFO L284 TraceCheckUtils]: 75: Hoare quadruple {5482#true} {5483#false} #1054#return; {5483#false} is VALID [2022-02-20 18:00:01,814 INFO L290 TraceCheckUtils]: 76: Hoare triple {5483#false} assume -2147483648 <= sign_#t~ret76#1 && sign_#t~ret76#1 <= 2147483647;sign_~tmp~16#1 := sign_#t~ret76#1;havoc sign_#t~ret76#1;sign_~privkey~1#1 := sign_~tmp~16#1; {5483#false} is VALID [2022-02-20 18:00:01,814 INFO L290 TraceCheckUtils]: 77: Hoare triple {5483#false} assume 0 == sign_~privkey~1#1; {5483#false} is VALID [2022-02-20 18:00:01,814 INFO L290 TraceCheckUtils]: 78: Hoare triple {5483#false} assume { :end_inline_sign } true;assume { :begin_inline_outgoing__wrappee__AutoResponder } true;outgoing__wrappee__AutoResponder_#in~client#1, outgoing__wrappee__AutoResponder_#in~msg#1 := ~client#1, ~msg#1;havoc outgoing__wrappee__AutoResponder_#t~ret62#1, outgoing__wrappee__AutoResponder_#t~ret63#1, outgoing__wrappee__AutoResponder_~client#1, outgoing__wrappee__AutoResponder_~msg#1, outgoing__wrappee__AutoResponder_~receiver~0#1, outgoing__wrappee__AutoResponder_~tmp~9#1, outgoing__wrappee__AutoResponder_~pubkey~0#1, outgoing__wrappee__AutoResponder_~tmp___0~3#1;outgoing__wrappee__AutoResponder_~client#1 := outgoing__wrappee__AutoResponder_#in~client#1;outgoing__wrappee__AutoResponder_~msg#1 := outgoing__wrappee__AutoResponder_#in~msg#1;havoc outgoing__wrappee__AutoResponder_~receiver~0#1;havoc outgoing__wrappee__AutoResponder_~tmp~9#1;havoc outgoing__wrappee__AutoResponder_~pubkey~0#1;havoc outgoing__wrappee__AutoResponder_~tmp___0~3#1; {5483#false} is VALID [2022-02-20 18:00:01,814 INFO L272 TraceCheckUtils]: 79: Hoare triple {5483#false} call outgoing__wrappee__AutoResponder_#t~ret62#1 := getEmailTo(outgoing__wrappee__AutoResponder_~msg#1); {5482#true} is VALID [2022-02-20 18:00:01,814 INFO L290 TraceCheckUtils]: 80: Hoare triple {5482#true} ~handle := #in~handle;havoc ~retValue_acc~36; {5482#true} is VALID [2022-02-20 18:00:01,814 INFO L290 TraceCheckUtils]: 81: Hoare triple {5482#true} assume 1 == ~handle;~retValue_acc~36 := ~__ste_email_to0~0;#res := ~retValue_acc~36; {5482#true} is VALID [2022-02-20 18:00:01,814 INFO L290 TraceCheckUtils]: 82: Hoare triple {5482#true} assume true; {5482#true} is VALID [2022-02-20 18:00:01,814 INFO L284 TraceCheckUtils]: 83: Hoare quadruple {5482#true} {5483#false} #1056#return; {5483#false} is VALID [2022-02-20 18:00:01,814 INFO L290 TraceCheckUtils]: 84: Hoare triple {5483#false} assume -2147483648 <= outgoing__wrappee__AutoResponder_#t~ret62#1 && outgoing__wrappee__AutoResponder_#t~ret62#1 <= 2147483647;outgoing__wrappee__AutoResponder_~tmp~9#1 := outgoing__wrappee__AutoResponder_#t~ret62#1;havoc outgoing__wrappee__AutoResponder_#t~ret62#1;outgoing__wrappee__AutoResponder_~receiver~0#1 := outgoing__wrappee__AutoResponder_~tmp~9#1; {5483#false} is VALID [2022-02-20 18:00:01,815 INFO L272 TraceCheckUtils]: 85: Hoare triple {5483#false} call outgoing__wrappee__AutoResponder_#t~ret63#1 := findPublicKey(outgoing__wrappee__AutoResponder_~client#1, outgoing__wrappee__AutoResponder_~receiver~0#1); {5482#true} is VALID [2022-02-20 18:00:01,815 INFO L290 TraceCheckUtils]: 86: Hoare triple {5482#true} ~handle := #in~handle;~userid := #in~userid;havoc ~retValue_acc~25; {5482#true} is VALID [2022-02-20 18:00:01,815 INFO L290 TraceCheckUtils]: 87: Hoare triple {5482#true} assume 1 == ~handle; {5482#true} is VALID [2022-02-20 18:00:01,815 INFO L290 TraceCheckUtils]: 88: Hoare triple {5482#true} assume ~userid == ~__ste_Client_Keyring0_User0~0;~retValue_acc~25 := ~__ste_Client_Keyring0_PublicKey0~0;#res := ~retValue_acc~25; {5482#true} is VALID [2022-02-20 18:00:01,815 INFO L290 TraceCheckUtils]: 89: Hoare triple {5482#true} assume true; {5482#true} is VALID [2022-02-20 18:00:01,815 INFO L284 TraceCheckUtils]: 90: Hoare quadruple {5482#true} {5483#false} #1058#return; {5483#false} is VALID [2022-02-20 18:00:01,815 INFO L290 TraceCheckUtils]: 91: Hoare triple {5483#false} assume -2147483648 <= outgoing__wrappee__AutoResponder_#t~ret63#1 && outgoing__wrappee__AutoResponder_#t~ret63#1 <= 2147483647;outgoing__wrappee__AutoResponder_~tmp___0~3#1 := outgoing__wrappee__AutoResponder_#t~ret63#1;havoc outgoing__wrappee__AutoResponder_#t~ret63#1;outgoing__wrappee__AutoResponder_~pubkey~0#1 := outgoing__wrappee__AutoResponder_~tmp___0~3#1; {5483#false} is VALID [2022-02-20 18:00:01,815 INFO L290 TraceCheckUtils]: 92: Hoare triple {5483#false} assume !(0 != outgoing__wrappee__AutoResponder_~pubkey~0#1); {5483#false} is VALID [2022-02-20 18:00:01,815 INFO L290 TraceCheckUtils]: 93: Hoare triple {5483#false} assume { :begin_inline_outgoing__wrappee__Keys } true;outgoing__wrappee__Keys_#in~client#1, outgoing__wrappee__Keys_#in~msg#1 := outgoing__wrappee__AutoResponder_~client#1, outgoing__wrappee__AutoResponder_~msg#1;havoc outgoing__wrappee__Keys_#t~ret61#1, outgoing__wrappee__Keys_~client#1, outgoing__wrappee__Keys_~msg#1, outgoing__wrappee__Keys_~tmp~8#1;outgoing__wrappee__Keys_~client#1 := outgoing__wrappee__Keys_#in~client#1;outgoing__wrappee__Keys_~msg#1 := outgoing__wrappee__Keys_#in~msg#1;havoc outgoing__wrappee__Keys_~tmp~8#1;assume { :begin_inline_getClientId } true;getClientId_#in~handle#1 := outgoing__wrappee__Keys_~client#1;havoc getClientId_#res#1;havoc getClientId_~handle#1, getClientId_~retValue_acc~27#1;getClientId_~handle#1 := getClientId_#in~handle#1;havoc getClientId_~retValue_acc~27#1; {5483#false} is VALID [2022-02-20 18:00:01,816 INFO L290 TraceCheckUtils]: 94: Hoare triple {5483#false} assume 1 == getClientId_~handle#1;getClientId_~retValue_acc~27#1 := ~__ste_client_idCounter0~0;getClientId_#res#1 := getClientId_~retValue_acc~27#1; {5483#false} is VALID [2022-02-20 18:00:01,816 INFO L290 TraceCheckUtils]: 95: Hoare triple {5483#false} outgoing__wrappee__Keys_#t~ret61#1 := getClientId_#res#1;assume { :end_inline_getClientId } true;assume -2147483648 <= outgoing__wrappee__Keys_#t~ret61#1 && outgoing__wrappee__Keys_#t~ret61#1 <= 2147483647;outgoing__wrappee__Keys_~tmp~8#1 := outgoing__wrappee__Keys_#t~ret61#1;havoc outgoing__wrappee__Keys_#t~ret61#1; {5483#false} is VALID [2022-02-20 18:00:01,816 INFO L272 TraceCheckUtils]: 96: Hoare triple {5483#false} call setEmailFrom(outgoing__wrappee__Keys_~msg#1, outgoing__wrappee__Keys_~tmp~8#1); {5546#(and (= |old(~__ste_email_from0~0)| ~__ste_email_from0~0) (= |old(~__ste_email_from1~0)| ~__ste_email_from1~0))} is VALID [2022-02-20 18:00:01,816 INFO L290 TraceCheckUtils]: 97: Hoare triple {5546#(and (= |old(~__ste_email_from0~0)| ~__ste_email_from0~0) (= |old(~__ste_email_from1~0)| ~__ste_email_from1~0))} ~handle := #in~handle;~value := #in~value; {5482#true} is VALID [2022-02-20 18:00:01,816 INFO L290 TraceCheckUtils]: 98: Hoare triple {5482#true} assume 1 == ~handle;~__ste_email_from0~0 := ~value; {5482#true} is VALID [2022-02-20 18:00:01,816 INFO L290 TraceCheckUtils]: 99: Hoare triple {5482#true} assume true; {5482#true} is VALID [2022-02-20 18:00:01,816 INFO L284 TraceCheckUtils]: 100: Hoare quadruple {5482#true} {5483#false} #1064#return; {5483#false} is VALID [2022-02-20 18:00:01,816 INFO L290 TraceCheckUtils]: 101: Hoare triple {5483#false} assume { :begin_inline_mail } true;mail_#in~client#1, mail_#in~msg#1 := outgoing__wrappee__Keys_~client#1, outgoing__wrappee__Keys_~msg#1;havoc mail_#t~ret59#1, mail_#t~ret60#1, mail_~client#1, mail_~msg#1, mail_~__utac__ad__arg1~0#1, mail_~__utac__ad__arg2~0#1, mail_~tmp~7#1;mail_~client#1 := mail_#in~client#1;mail_~msg#1 := mail_#in~msg#1;havoc mail_~__utac__ad__arg1~0#1;havoc mail_~__utac__ad__arg2~0#1;havoc mail_~tmp~7#1;mail_~__utac__ad__arg1~0#1 := mail_~client#1;mail_~__utac__ad__arg2~0#1 := mail_~msg#1;assume { :begin_inline___utac_acc__SignForward_spec__1 } true;__utac_acc__SignForward_spec__1_#in~client#1, __utac_acc__SignForward_spec__1_#in~msg#1 := mail_~__utac__ad__arg1~0#1, mail_~__utac__ad__arg2~0#1;havoc __utac_acc__SignForward_spec__1_#t~ret107#1, __utac_acc__SignForward_spec__1_#t~ret108#1, __utac_acc__SignForward_spec__1_#t~ret109#1, __utac_acc__SignForward_spec__1_~client#1, __utac_acc__SignForward_spec__1_~msg#1, __utac_acc__SignForward_spec__1_~tmp~25#1, __utac_acc__SignForward_spec__1_~tmp___0~9#1;__utac_acc__SignForward_spec__1_~client#1 := __utac_acc__SignForward_spec__1_#in~client#1;__utac_acc__SignForward_spec__1_~msg#1 := __utac_acc__SignForward_spec__1_#in~msg#1;havoc __utac_acc__SignForward_spec__1_~tmp~25#1;havoc __utac_acc__SignForward_spec__1_~tmp___0~9#1;call __utac_acc__SignForward_spec__1_#t~ret107#1 := puts(39, 0);assume -2147483648 <= __utac_acc__SignForward_spec__1_#t~ret107#1 && __utac_acc__SignForward_spec__1_#t~ret107#1 <= 2147483647;havoc __utac_acc__SignForward_spec__1_#t~ret107#1; {5483#false} is VALID [2022-02-20 18:00:01,816 INFO L272 TraceCheckUtils]: 102: Hoare triple {5483#false} call __utac_acc__SignForward_spec__1_#t~ret108#1 := isSigned(__utac_acc__SignForward_spec__1_~msg#1); {5482#true} is VALID [2022-02-20 18:00:01,817 INFO L290 TraceCheckUtils]: 103: Hoare triple {5482#true} ~handle := #in~handle;havoc ~retValue_acc~41; {5482#true} is VALID [2022-02-20 18:00:01,817 INFO L290 TraceCheckUtils]: 104: Hoare triple {5482#true} assume 1 == ~handle;~retValue_acc~41 := ~__ste_email_isSigned0~0;#res := ~retValue_acc~41; {5482#true} is VALID [2022-02-20 18:00:01,817 INFO L290 TraceCheckUtils]: 105: Hoare triple {5482#true} assume true; {5482#true} is VALID [2022-02-20 18:00:01,817 INFO L284 TraceCheckUtils]: 106: Hoare quadruple {5482#true} {5483#false} #1066#return; {5483#false} is VALID [2022-02-20 18:00:01,817 INFO L290 TraceCheckUtils]: 107: Hoare triple {5483#false} assume -2147483648 <= __utac_acc__SignForward_spec__1_#t~ret108#1 && __utac_acc__SignForward_spec__1_#t~ret108#1 <= 2147483647;__utac_acc__SignForward_spec__1_~tmp___0~9#1 := __utac_acc__SignForward_spec__1_#t~ret108#1;havoc __utac_acc__SignForward_spec__1_#t~ret108#1; {5483#false} is VALID [2022-02-20 18:00:01,817 INFO L290 TraceCheckUtils]: 108: Hoare triple {5483#false} assume 0 != __utac_acc__SignForward_spec__1_~tmp___0~9#1; {5483#false} is VALID [2022-02-20 18:00:01,817 INFO L272 TraceCheckUtils]: 109: Hoare triple {5483#false} call __utac_acc__SignForward_spec__1_#t~ret109#1 := getClientPrivateKey(__utac_acc__SignForward_spec__1_~client#1); {5482#true} is VALID [2022-02-20 18:00:01,817 INFO L290 TraceCheckUtils]: 110: Hoare triple {5482#true} ~handle := #in~handle;havoc ~retValue_acc~20; {5482#true} is VALID [2022-02-20 18:00:01,818 INFO L290 TraceCheckUtils]: 111: Hoare triple {5482#true} assume 1 == ~handle;~retValue_acc~20 := ~__ste_client_privateKey0~0;#res := ~retValue_acc~20; {5482#true} is VALID [2022-02-20 18:00:01,818 INFO L290 TraceCheckUtils]: 112: Hoare triple {5482#true} assume true; {5482#true} is VALID [2022-02-20 18:00:01,818 INFO L284 TraceCheckUtils]: 113: Hoare quadruple {5482#true} {5483#false} #1068#return; {5483#false} is VALID [2022-02-20 18:00:01,818 INFO L290 TraceCheckUtils]: 114: Hoare triple {5483#false} assume -2147483648 <= __utac_acc__SignForward_spec__1_#t~ret109#1 && __utac_acc__SignForward_spec__1_#t~ret109#1 <= 2147483647;__utac_acc__SignForward_spec__1_~tmp~25#1 := __utac_acc__SignForward_spec__1_#t~ret109#1;havoc __utac_acc__SignForward_spec__1_#t~ret109#1; {5483#false} is VALID [2022-02-20 18:00:01,818 INFO L290 TraceCheckUtils]: 115: Hoare triple {5483#false} assume 0 == __utac_acc__SignForward_spec__1_~tmp~25#1;assume { :begin_inline___automaton_fail } true; {5483#false} is VALID [2022-02-20 18:00:01,818 INFO L290 TraceCheckUtils]: 116: Hoare triple {5483#false} assume !false; {5483#false} is VALID [2022-02-20 18:00:01,818 INFO L134 CoverageAnalysis]: Checked inductivity of 34 backedges. 3 proven. 3 refuted. 0 times theorem prover too weak. 28 trivial. 0 not checked. [2022-02-20 18:00:01,819 INFO L144 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2022-02-20 18:00:01,819 INFO L338 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [2060140944] [2022-02-20 18:00:01,819 INFO L165 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [2060140944] provided 0 perfect and 1 imperfect interpolant sequences [2022-02-20 18:00:01,819 INFO L338 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleZ3 [1767264139] [2022-02-20 18:00:01,819 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-02-20 18:00:01,819 INFO L173 SolverBuilder]: Constructing external solver with command: z3 -smt2 -in SMTLIB2_COMPLIANT=true [2022-02-20 18:00:01,819 INFO L189 MonitoredProcess]: No working directory specified, using /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 [2022-02-20 18:00:01,844 INFO L229 MonitoredProcess]: Starting monitored process 4 with /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 -smt2 -in SMTLIB2_COMPLIANT=true (exit command is (exit), workingDir is null) [2022-02-20 18:00:01,845 INFO L327 MonitoredProcess]: [MP /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 -smt2 -in SMTLIB2_COMPLIANT=true (4)] Waiting until timeout for monitored process [2022-02-20 18:00:02,079 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-02-20 18:00:02,083 INFO L263 TraceCheckSpWp]: Trace formula consists of 1093 conjuncts, 3 conjunts are in the unsatisfiable core [2022-02-20 18:00:02,126 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-02-20 18:00:02,130 INFO L286 TraceCheckSpWp]: Computing forward predicates... [2022-02-20 18:00:02,374 INFO L290 TraceCheckUtils]: 0: Hoare triple {5482#true} assume { :begin_inline_ULTIMATE.init } true;#NULL.base, #NULL.offset := 0, 0;assume 0 == #valid[0];assume 0 < #StackHeapBarrier;call #Ultimate.allocInit(2, 1);call write~init~int(48, 1, 0, 1);call write~init~int(0, 1, 1, 1);call #Ultimate.allocInit(28, 2);call #Ultimate.allocInit(12, 3);call #Ultimate.allocInit(30, 4);call #Ultimate.allocInit(9, 5);call #Ultimate.allocInit(21, 6);call #Ultimate.allocInit(30, 7);call #Ultimate.allocInit(9, 8);call #Ultimate.allocInit(21, 9);call #Ultimate.allocInit(30, 10);call #Ultimate.allocInit(9, 11);call #Ultimate.allocInit(25, 12);call #Ultimate.allocInit(30, 13);call #Ultimate.allocInit(9, 14);call #Ultimate.allocInit(25, 15);call #Ultimate.allocInit(44, 16);call #Ultimate.allocInit(44, 17);call #Ultimate.allocInit(9, 18);call #Ultimate.allocInit(9, 19);call #Ultimate.allocInit(11, 20);call #Ultimate.allocInit(19, 21);call #Ultimate.allocInit(4, 22);call write~init~int(37, 22, 0, 1);call write~init~int(100, 22, 1, 1);call write~init~int(10, 22, 2, 1);call write~init~int(0, 22, 3, 1);call #Ultimate.allocInit(4, 23);call write~init~int(37, 23, 0, 1);call write~init~int(100, 23, 1, 1);call write~init~int(10, 23, 2, 1);call write~init~int(0, 23, 3, 1);call #Ultimate.allocInit(10, 24);call #Ultimate.allocInit(16, 25);call #Ultimate.allocInit(20, 26);call #Ultimate.allocInit(22, 27);call #Ultimate.allocInit(21, 28);call #Ultimate.allocInit(10, 29);call #Ultimate.allocInit(12, 30);call #Ultimate.allocInit(10, 31);call #Ultimate.allocInit(18, 32);call #Ultimate.allocInit(16, 33);call #Ultimate.allocInit(21, 34);call #Ultimate.allocInit(13, 35);call #Ultimate.allocInit(16, 36);call #Ultimate.allocInit(25, 37);call #Ultimate.allocInit(4, 38);call write~init~int(37, 38, 0, 1);call write~init~int(115, 38, 1, 1);call write~init~int(10, 38, 2, 1);call write~init~int(0, 38, 3, 1);call #Ultimate.allocInit(13, 39);~head~0.base, ~head~0.offset := 0, 0;~__SELECTED_FEATURE_Base~0 := 0;~__SELECTED_FEATURE_Keys~0 := 0;~__SELECTED_FEATURE_Encrypt~0 := 0;~__SELECTED_FEATURE_AutoResponder~0 := 0;~__SELECTED_FEATURE_AddressBook~0 := 0;~__SELECTED_FEATURE_Sign~0 := 0;~__SELECTED_FEATURE_Forward~0 := 0;~__SELECTED_FEATURE_Verify~0 := 0;~__SELECTED_FEATURE_Decrypt~0 := 0;~__GUIDSL_ROOT_PRODUCTION~0 := 0;~__GUIDSL_NON_TERMINAL_main~0 := 0;~bob~0 := 0;~rjh~0 := 0;~chuck~0 := 0;~queue_empty~0 := 1;~queued_message~0 := 0;~queued_client~0 := 0;~__ste_Client_counter~0 := 0;~__ste_client_name0~0.base, ~__ste_client_name0~0.offset := 0, 0;~__ste_client_name1~0.base, ~__ste_client_name1~0.offset := 0, 0;~__ste_client_name2~0.base, ~__ste_client_name2~0.offset := 0, 0;~__ste_client_outbuffer0~0 := 0;~__ste_client_outbuffer1~0 := 0;~__ste_client_outbuffer2~0 := 0;~__ste_client_outbuffer3~0 := 0;~__ste_ClientAddressBook_size0~0 := 0;~__ste_ClientAddressBook_size1~0 := 0;~__ste_ClientAddressBook_size2~0 := 0;~__ste_Client_AddressBook0_Alias0~0 := 0;~__ste_Client_AddressBook0_Alias1~0 := 0;~__ste_Client_AddressBook0_Alias2~0 := 0;~__ste_Client_AddressBook1_Alias0~0 := 0;~__ste_Client_AddressBook1_Alias1~0 := 0;~__ste_Client_AddressBook1_Alias2~0 := 0;~__ste_Client_AddressBook2_Alias0~0 := 0;~__ste_Client_AddressBook2_Alias1~0 := 0;~__ste_Client_AddressBook2_Alias2~0 := 0;~__ste_Client_AddressBook0_Address0~0 := 0;~__ste_Client_AddressBook0_Address1~0 := 0;~__ste_Client_AddressBook0_Address2~0 := 0;~__ste_Client_AddressBook1_Address0~0 := 0;~__ste_Client_AddressBook1_Address1~0 := 0;~__ste_Client_AddressBook1_Address2~0 := 0;~__ste_Client_AddressBook2_Address0~0 := 0;~__ste_Client_AddressBook2_Address1~0 := 0;~__ste_Client_AddressBook2_Address2~0 := 0;~__ste_client_autoResponse0~0 := 0;~__ste_client_autoResponse1~0 := 0;~__ste_client_autoResponse2~0 := 0;~__ste_client_privateKey0~0 := 0;~__ste_client_privateKey1~0 := 0;~__ste_client_privateKey2~0 := 0;~__ste_ClientKeyring_size0~0 := 0;~__ste_ClientKeyring_size1~0 := 0;~__ste_ClientKeyring_size2~0 := 0;~__ste_Client_Keyring0_User0~0 := 0;~__ste_Client_Keyring0_User1~0 := 0;~__ste_Client_Keyring0_User2~0 := 0;~__ste_Client_Keyring1_User0~0 := 0;~__ste_Client_Keyring1_User1~0 := 0;~__ste_Client_Keyring1_User2~0 := 0;~__ste_Client_Keyring2_User0~0 := 0;~__ste_Client_Keyring2_User1~0 := 0;~__ste_Client_Keyring2_User2~0 := 0;~__ste_Client_Keyring0_PublicKey0~0 := 0;~__ste_Client_Keyring0_PublicKey1~0 := 0;~__ste_Client_Keyring0_PublicKey2~0 := 0;~__ste_Client_Keyring1_PublicKey0~0 := 0;~__ste_Client_Keyring1_PublicKey1~0 := 0;~__ste_Client_Keyring1_PublicKey2~0 := 0;~__ste_Client_Keyring2_PublicKey0~0 := 0;~__ste_Client_Keyring2_PublicKey1~0 := 0;~__ste_Client_Keyring2_PublicKey2~0 := 0;~__ste_client_forwardReceiver0~0 := 0;~__ste_client_forwardReceiver1~0 := 0;~__ste_client_forwardReceiver2~0 := 0;~__ste_client_forwardReceiver3~0 := 0;~__ste_client_idCounter0~0 := 0;~__ste_client_idCounter1~0 := 0;~__ste_client_idCounter2~0 := 0;~__ste_Email_counter~0 := 0;~__ste_email_id0~0 := 0;~__ste_email_id1~0 := 0;~__ste_email_from0~0 := 0;~__ste_email_from1~0 := 0;~__ste_email_to0~0 := 0;~__ste_email_to1~0 := 0;~__ste_email_subject0~0.base, ~__ste_email_subject0~0.offset := 0, 0;~__ste_email_subject1~0.base, ~__ste_email_subject1~0.offset := 0, 0;~__ste_email_body0~0.base, ~__ste_email_body0~0.offset := 0, 0;~__ste_email_body1~0.base, ~__ste_email_body1~0.offset := 0, 0;~__ste_email_isEncrypted0~0 := 0;~__ste_email_isEncrypted1~0 := 0;~__ste_email_encryptionKey0~0 := 0;~__ste_email_encryptionKey1~0 := 0;~__ste_email_isSigned0~0 := 0;~__ste_email_isSigned1~0 := 0;~__ste_email_signKey0~0 := 0;~__ste_email_signKey1~0 := 0;~__ste_email_isSignatureVerified0~0 := 0;~__ste_email_isSignatureVerified1~0 := 0; {5482#true} is VALID [2022-02-20 18:00:02,374 INFO L290 TraceCheckUtils]: 1: Hoare triple {5482#true} assume { :end_inline_ULTIMATE.init } true;assume { :begin_inline_main } true;havoc main_#res#1;havoc main_#t~ret35#1, main_~retValue_acc~3#1, main_~tmp~4#1;havoc main_~retValue_acc~3#1;havoc main_~tmp~4#1;assume { :begin_inline_select_helpers } true; {5482#true} is VALID [2022-02-20 18:00:02,374 INFO L290 TraceCheckUtils]: 2: Hoare triple {5482#true} assume { :end_inline_select_helpers } true;assume { :begin_inline_select_features } true; {5482#true} is VALID [2022-02-20 18:00:02,374 INFO L290 TraceCheckUtils]: 3: Hoare triple {5482#true} assume { :end_inline_select_features } true;assume { :begin_inline_valid_product } true;havoc valid_product_#res#1;havoc valid_product_~retValue_acc~5#1;havoc valid_product_~retValue_acc~5#1;valid_product_~retValue_acc~5#1 := 1;valid_product_#res#1 := valid_product_~retValue_acc~5#1; {5482#true} is VALID [2022-02-20 18:00:02,374 INFO L290 TraceCheckUtils]: 4: Hoare triple {5482#true} main_#t~ret35#1 := valid_product_#res#1;assume { :end_inline_valid_product } true;assume -2147483648 <= main_#t~ret35#1 && main_#t~ret35#1 <= 2147483647;main_~tmp~4#1 := main_#t~ret35#1;havoc main_#t~ret35#1; {5482#true} is VALID [2022-02-20 18:00:02,374 INFO L290 TraceCheckUtils]: 5: Hoare triple {5482#true} assume 0 != main_~tmp~4#1;assume { :begin_inline_setup } true;havoc setup_#t~nondet32#1, setup_#t~nondet33#1, setup_#t~nondet34#1, setup_~__cil_tmp1~0#1.base, setup_~__cil_tmp1~0#1.offset, setup_~__cil_tmp2~0#1.base, setup_~__cil_tmp2~0#1.offset, setup_~__cil_tmp3~0#1.base, setup_~__cil_tmp3~0#1.offset;havoc setup_~__cil_tmp1~0#1.base, setup_~__cil_tmp1~0#1.offset;havoc setup_~__cil_tmp2~0#1.base, setup_~__cil_tmp2~0#1.offset;havoc setup_~__cil_tmp3~0#1.base, setup_~__cil_tmp3~0#1.offset;~bob~0 := 1;assume { :begin_inline_setup_bob } true;setup_bob_#in~bob___0#1 := ~bob~0;havoc setup_bob_~bob___0#1;setup_bob_~bob___0#1 := setup_bob_#in~bob___0#1;assume { :begin_inline_setup_bob__wrappee__Base } true;setup_bob__wrappee__Base_#in~bob___0#1 := setup_bob_~bob___0#1;havoc setup_bob__wrappee__Base_~bob___0#1;setup_bob__wrappee__Base_~bob___0#1 := setup_bob__wrappee__Base_#in~bob___0#1; {5482#true} is VALID [2022-02-20 18:00:02,374 INFO L272 TraceCheckUtils]: 6: Hoare triple {5482#true} call setClientId(setup_bob__wrappee__Base_~bob___0#1, setup_bob__wrappee__Base_~bob___0#1); {5482#true} is VALID [2022-02-20 18:00:02,374 INFO L290 TraceCheckUtils]: 7: Hoare triple {5482#true} ~handle := #in~handle;~value := #in~value; {5482#true} is VALID [2022-02-20 18:00:02,375 INFO L290 TraceCheckUtils]: 8: Hoare triple {5482#true} assume 1 == ~handle;~__ste_client_idCounter0~0 := ~value; {5482#true} is VALID [2022-02-20 18:00:02,375 INFO L290 TraceCheckUtils]: 9: Hoare triple {5482#true} assume true; {5482#true} is VALID [2022-02-20 18:00:02,375 INFO L284 TraceCheckUtils]: 10: Hoare quadruple {5482#true} {5482#true} #1134#return; {5482#true} is VALID [2022-02-20 18:00:02,375 INFO L290 TraceCheckUtils]: 11: Hoare triple {5482#true} assume { :end_inline_setup_bob__wrappee__Base } true; {5482#true} is VALID [2022-02-20 18:00:02,375 INFO L272 TraceCheckUtils]: 12: Hoare triple {5482#true} call setClientPrivateKey(setup_bob_~bob___0#1, 123); {5482#true} is VALID [2022-02-20 18:00:02,375 INFO L290 TraceCheckUtils]: 13: Hoare triple {5482#true} ~handle := #in~handle;~value := #in~value; {5482#true} is VALID [2022-02-20 18:00:02,375 INFO L290 TraceCheckUtils]: 14: Hoare triple {5482#true} assume 1 == ~handle;~__ste_client_privateKey0~0 := ~value; {5482#true} is VALID [2022-02-20 18:00:02,375 INFO L290 TraceCheckUtils]: 15: Hoare triple {5482#true} assume true; {5482#true} is VALID [2022-02-20 18:00:02,375 INFO L284 TraceCheckUtils]: 16: Hoare quadruple {5482#true} {5482#true} #1136#return; {5482#true} is VALID [2022-02-20 18:00:02,375 INFO L290 TraceCheckUtils]: 17: Hoare triple {5482#true} assume { :end_inline_setup_bob } true;setup_~__cil_tmp1~0#1.base, setup_~__cil_tmp1~0#1.offset := 18, 0;havoc setup_#t~nondet32#1;~rjh~0 := 2;assume { :begin_inline_setup_rjh } true;setup_rjh_#in~rjh___0#1 := ~rjh~0;havoc setup_rjh_~rjh___0#1;setup_rjh_~rjh___0#1 := setup_rjh_#in~rjh___0#1;assume { :begin_inline_setup_rjh__wrappee__Base } true;setup_rjh__wrappee__Base_#in~rjh___0#1 := setup_rjh_~rjh___0#1;havoc setup_rjh__wrappee__Base_~rjh___0#1;setup_rjh__wrappee__Base_~rjh___0#1 := setup_rjh__wrappee__Base_#in~rjh___0#1; {5482#true} is VALID [2022-02-20 18:00:02,375 INFO L272 TraceCheckUtils]: 18: Hoare triple {5482#true} call setClientId(setup_rjh__wrappee__Base_~rjh___0#1, setup_rjh__wrappee__Base_~rjh___0#1); {5482#true} is VALID [2022-02-20 18:00:02,375 INFO L290 TraceCheckUtils]: 19: Hoare triple {5482#true} ~handle := #in~handle;~value := #in~value; {5482#true} is VALID [2022-02-20 18:00:02,375 INFO L290 TraceCheckUtils]: 20: Hoare triple {5482#true} assume 1 == ~handle;~__ste_client_idCounter0~0 := ~value; {5482#true} is VALID [2022-02-20 18:00:02,375 INFO L290 TraceCheckUtils]: 21: Hoare triple {5482#true} assume true; {5482#true} is VALID [2022-02-20 18:00:02,375 INFO L284 TraceCheckUtils]: 22: Hoare quadruple {5482#true} {5482#true} #1138#return; {5482#true} is VALID [2022-02-20 18:00:02,375 INFO L290 TraceCheckUtils]: 23: Hoare triple {5482#true} assume { :end_inline_setup_rjh__wrappee__Base } true; {5482#true} is VALID [2022-02-20 18:00:02,375 INFO L272 TraceCheckUtils]: 24: Hoare triple {5482#true} call setClientPrivateKey(setup_rjh_~rjh___0#1, 456); {5482#true} is VALID [2022-02-20 18:00:02,375 INFO L290 TraceCheckUtils]: 25: Hoare triple {5482#true} ~handle := #in~handle;~value := #in~value; {5482#true} is VALID [2022-02-20 18:00:02,375 INFO L290 TraceCheckUtils]: 26: Hoare triple {5482#true} assume 1 == ~handle;~__ste_client_privateKey0~0 := ~value; {5482#true} is VALID [2022-02-20 18:00:02,375 INFO L290 TraceCheckUtils]: 27: Hoare triple {5482#true} assume true; {5482#true} is VALID [2022-02-20 18:00:02,376 INFO L284 TraceCheckUtils]: 28: Hoare quadruple {5482#true} {5482#true} #1140#return; {5482#true} is VALID [2022-02-20 18:00:02,376 INFO L290 TraceCheckUtils]: 29: Hoare triple {5482#true} assume { :end_inline_setup_rjh } true;setup_~__cil_tmp2~0#1.base, setup_~__cil_tmp2~0#1.offset := 19, 0;havoc setup_#t~nondet33#1;~chuck~0 := 3;assume { :begin_inline_setup_chuck } true;setup_chuck_#in~chuck___0#1 := ~chuck~0;havoc setup_chuck_~chuck___0#1;setup_chuck_~chuck___0#1 := setup_chuck_#in~chuck___0#1;assume { :begin_inline_setup_chuck__wrappee__Base } true;setup_chuck__wrappee__Base_#in~chuck___0#1 := setup_chuck_~chuck___0#1;havoc setup_chuck__wrappee__Base_~chuck___0#1;setup_chuck__wrappee__Base_~chuck___0#1 := setup_chuck__wrappee__Base_#in~chuck___0#1; {5482#true} is VALID [2022-02-20 18:00:02,376 INFO L272 TraceCheckUtils]: 30: Hoare triple {5482#true} call setClientId(setup_chuck__wrappee__Base_~chuck___0#1, setup_chuck__wrappee__Base_~chuck___0#1); {5482#true} is VALID [2022-02-20 18:00:02,376 INFO L290 TraceCheckUtils]: 31: Hoare triple {5482#true} ~handle := #in~handle;~value := #in~value; {5482#true} is VALID [2022-02-20 18:00:02,376 INFO L290 TraceCheckUtils]: 32: Hoare triple {5482#true} assume 1 == ~handle;~__ste_client_idCounter0~0 := ~value; {5482#true} is VALID [2022-02-20 18:00:02,376 INFO L290 TraceCheckUtils]: 33: Hoare triple {5482#true} assume true; {5482#true} is VALID [2022-02-20 18:00:02,376 INFO L284 TraceCheckUtils]: 34: Hoare quadruple {5482#true} {5482#true} #1142#return; {5482#true} is VALID [2022-02-20 18:00:02,376 INFO L290 TraceCheckUtils]: 35: Hoare triple {5482#true} assume { :end_inline_setup_chuck__wrappee__Base } true; {5482#true} is VALID [2022-02-20 18:00:02,376 INFO L272 TraceCheckUtils]: 36: Hoare triple {5482#true} call setClientPrivateKey(setup_chuck_~chuck___0#1, 789); {5482#true} is VALID [2022-02-20 18:00:02,376 INFO L290 TraceCheckUtils]: 37: Hoare triple {5482#true} ~handle := #in~handle;~value := #in~value; {5482#true} is VALID [2022-02-20 18:00:02,376 INFO L290 TraceCheckUtils]: 38: Hoare triple {5482#true} assume 1 == ~handle;~__ste_client_privateKey0~0 := ~value; {5482#true} is VALID [2022-02-20 18:00:02,376 INFO L290 TraceCheckUtils]: 39: Hoare triple {5482#true} assume true; {5482#true} is VALID [2022-02-20 18:00:02,376 INFO L284 TraceCheckUtils]: 40: Hoare quadruple {5482#true} {5482#true} #1144#return; {5482#true} is VALID [2022-02-20 18:00:02,376 INFO L290 TraceCheckUtils]: 41: Hoare triple {5482#true} assume { :end_inline_setup_chuck } true;setup_~__cil_tmp3~0#1.base, setup_~__cil_tmp3~0#1.offset := 20, 0;havoc setup_#t~nondet34#1; {5482#true} is VALID [2022-02-20 18:00:02,377 INFO L290 TraceCheckUtils]: 42: Hoare triple {5482#true} assume { :end_inline_setup } true;assume { :begin_inline_test } true;havoc test_#t~nondet47#1, test_#t~nondet48#1, test_#t~nondet49#1, test_#t~nondet50#1, test_#t~nondet51#1, test_#t~nondet52#1, test_#t~nondet53#1, test_#t~nondet54#1, test_#t~nondet55#1, test_#t~nondet56#1, test_#t~nondet57#1, test_~op1~0#1, test_~op2~0#1, test_~op3~0#1, test_~op4~0#1, test_~op5~0#1, test_~op6~0#1, test_~op7~0#1, test_~op8~0#1, test_~op9~0#1, test_~op10~0#1, test_~op11~0#1, test_~splverifierCounter~0#1, test_~tmp~6#1, test_~tmp___0~2#1, test_~tmp___1~1#1, test_~tmp___2~0#1, test_~tmp___3~0#1, test_~tmp___4~0#1, test_~tmp___5~0#1, test_~tmp___6~0#1, test_~tmp___7~0#1, test_~tmp___8~0#1, test_~tmp___9~0#1;havoc test_~op1~0#1;havoc test_~op2~0#1;havoc test_~op3~0#1;havoc test_~op4~0#1;havoc test_~op5~0#1;havoc test_~op6~0#1;havoc test_~op7~0#1;havoc test_~op8~0#1;havoc test_~op9~0#1;havoc test_~op10~0#1;havoc test_~op11~0#1;havoc test_~splverifierCounter~0#1;havoc test_~tmp~6#1;havoc test_~tmp___0~2#1;havoc test_~tmp___1~1#1;havoc test_~tmp___2~0#1;havoc test_~tmp___3~0#1;havoc test_~tmp___4~0#1;havoc test_~tmp___5~0#1;havoc test_~tmp___6~0#1;havoc test_~tmp___7~0#1;havoc test_~tmp___8~0#1;havoc test_~tmp___9~0#1;test_~op1~0#1 := 0;test_~op2~0#1 := 0;test_~op3~0#1 := 0;test_~op4~0#1 := 0;test_~op5~0#1 := 0;test_~op6~0#1 := 0;test_~op7~0#1 := 0;test_~op8~0#1 := 0;test_~op9~0#1 := 0;test_~op10~0#1 := 0;test_~op11~0#1 := 0;test_~splverifierCounter~0#1 := 0; {5677#(= |ULTIMATE.start_test_~op1~0#1| 0)} is VALID [2022-02-20 18:00:02,377 INFO L290 TraceCheckUtils]: 43: Hoare triple {5677#(= |ULTIMATE.start_test_~op1~0#1| 0)} assume !false; {5677#(= |ULTIMATE.start_test_~op1~0#1| 0)} is VALID [2022-02-20 18:00:02,378 INFO L290 TraceCheckUtils]: 44: Hoare triple {5677#(= |ULTIMATE.start_test_~op1~0#1| 0)} assume test_~splverifierCounter~0#1 < 4; {5677#(= |ULTIMATE.start_test_~op1~0#1| 0)} is VALID [2022-02-20 18:00:02,378 INFO L290 TraceCheckUtils]: 45: Hoare triple {5677#(= |ULTIMATE.start_test_~op1~0#1| 0)} test_~splverifierCounter~0#1 := 1 + test_~splverifierCounter~0#1; {5677#(= |ULTIMATE.start_test_~op1~0#1| 0)} is VALID [2022-02-20 18:00:02,378 INFO L290 TraceCheckUtils]: 46: Hoare triple {5677#(= |ULTIMATE.start_test_~op1~0#1| 0)} assume !(0 == test_~op1~0#1); {5483#false} is VALID [2022-02-20 18:00:02,378 INFO L290 TraceCheckUtils]: 47: Hoare triple {5483#false} assume 0 == test_~op2~0#1;assume -2147483648 <= test_#t~nondet48#1 && test_#t~nondet48#1 <= 2147483647;test_~tmp___8~0#1 := test_#t~nondet48#1;havoc test_#t~nondet48#1; {5483#false} is VALID [2022-02-20 18:00:02,378 INFO L290 TraceCheckUtils]: 48: Hoare triple {5483#false} assume 0 != test_~tmp___8~0#1;assume { :begin_inline_rjhSetAutoRespond } true;assume { :begin_inline_setClientAutoResponse } true;setClientAutoResponse_#in~handle#1, setClientAutoResponse_#in~value#1 := ~rjh~0, 1;havoc setClientAutoResponse_~handle#1, setClientAutoResponse_~value#1;setClientAutoResponse_~handle#1 := setClientAutoResponse_#in~handle#1;setClientAutoResponse_~value#1 := setClientAutoResponse_#in~value#1; {5483#false} is VALID [2022-02-20 18:00:02,378 INFO L290 TraceCheckUtils]: 49: Hoare triple {5483#false} assume 1 == setClientAutoResponse_~handle#1;~__ste_client_autoResponse0~0 := setClientAutoResponse_~value#1; {5483#false} is VALID [2022-02-20 18:00:02,378 INFO L290 TraceCheckUtils]: 50: Hoare triple {5483#false} assume { :end_inline_setClientAutoResponse } true; {5483#false} is VALID [2022-02-20 18:00:02,379 INFO L290 TraceCheckUtils]: 51: Hoare triple {5483#false} assume { :end_inline_rjhSetAutoRespond } true;test_~op2~0#1 := 1; {5483#false} is VALID [2022-02-20 18:00:02,379 INFO L290 TraceCheckUtils]: 52: Hoare triple {5483#false} assume !false; {5483#false} is VALID [2022-02-20 18:00:02,379 INFO L290 TraceCheckUtils]: 53: Hoare triple {5483#false} assume !(test_~splverifierCounter~0#1 < 4); {5483#false} is VALID [2022-02-20 18:00:02,379 INFO L290 TraceCheckUtils]: 54: Hoare triple {5483#false} assume { :begin_inline_bobToRjh } true;havoc bobToRjh_#t~ret27#1, bobToRjh_#t~ret28#1, bobToRjh_#t~ret29#1, bobToRjh_#t~ret30#1, bobToRjh_~tmp~3#1, bobToRjh_~tmp___0~0#1, bobToRjh_~tmp___1~0#1;havoc bobToRjh_~tmp~3#1;havoc bobToRjh_~tmp___0~0#1;havoc bobToRjh_~tmp___1~0#1;call bobToRjh_#t~ret27#1 := puts(16, 0);assume -2147483648 <= bobToRjh_#t~ret27#1 && bobToRjh_#t~ret27#1 <= 2147483647;havoc bobToRjh_#t~ret27#1; {5483#false} is VALID [2022-02-20 18:00:02,379 INFO L272 TraceCheckUtils]: 55: Hoare triple {5483#false} call sendEmail(~bob~0, ~rjh~0); {5483#false} is VALID [2022-02-20 18:00:02,379 INFO L290 TraceCheckUtils]: 56: Hoare triple {5483#false} ~sender#1 := #in~sender#1;~receiver#1 := #in~receiver#1;havoc ~email~0#1;havoc ~tmp~14#1;assume { :begin_inline_createEmail } true;createEmail_#in~from#1, createEmail_#in~to#1 := 0, ~receiver#1;havoc createEmail_#res#1;havoc createEmail_~from#1, createEmail_~to#1, createEmail_~retValue_acc~31#1, createEmail_~msg~0#1;createEmail_~from#1 := createEmail_#in~from#1;createEmail_~to#1 := createEmail_#in~to#1;havoc createEmail_~retValue_acc~31#1;havoc createEmail_~msg~0#1;createEmail_~msg~0#1 := 1; {5483#false} is VALID [2022-02-20 18:00:02,379 INFO L272 TraceCheckUtils]: 57: Hoare triple {5483#false} call setEmailFrom(createEmail_~msg~0#1, createEmail_~from#1); {5483#false} is VALID [2022-02-20 18:00:02,379 INFO L290 TraceCheckUtils]: 58: Hoare triple {5483#false} ~handle := #in~handle;~value := #in~value; {5483#false} is VALID [2022-02-20 18:00:02,379 INFO L290 TraceCheckUtils]: 59: Hoare triple {5483#false} assume 1 == ~handle;~__ste_email_from0~0 := ~value; {5483#false} is VALID [2022-02-20 18:00:02,379 INFO L290 TraceCheckUtils]: 60: Hoare triple {5483#false} assume true; {5483#false} is VALID [2022-02-20 18:00:02,379 INFO L284 TraceCheckUtils]: 61: Hoare quadruple {5483#false} {5483#false} #1120#return; {5483#false} is VALID [2022-02-20 18:00:02,379 INFO L272 TraceCheckUtils]: 62: Hoare triple {5483#false} call setEmailTo(createEmail_~msg~0#1, createEmail_~to#1); {5483#false} is VALID [2022-02-20 18:00:02,379 INFO L290 TraceCheckUtils]: 63: Hoare triple {5483#false} ~handle := #in~handle;~value := #in~value; {5483#false} is VALID [2022-02-20 18:00:02,379 INFO L290 TraceCheckUtils]: 64: Hoare triple {5483#false} assume 1 == ~handle;~__ste_email_to0~0 := ~value; {5483#false} is VALID [2022-02-20 18:00:02,379 INFO L290 TraceCheckUtils]: 65: Hoare triple {5483#false} assume true; {5483#false} is VALID [2022-02-20 18:00:02,380 INFO L284 TraceCheckUtils]: 66: Hoare quadruple {5483#false} {5483#false} #1122#return; {5483#false} is VALID [2022-02-20 18:00:02,380 INFO L290 TraceCheckUtils]: 67: Hoare triple {5483#false} createEmail_~retValue_acc~31#1 := createEmail_~msg~0#1;createEmail_#res#1 := createEmail_~retValue_acc~31#1; {5483#false} is VALID [2022-02-20 18:00:02,380 INFO L290 TraceCheckUtils]: 68: Hoare triple {5483#false} #t~ret72#1 := createEmail_#res#1;assume { :end_inline_createEmail } true;assume -2147483648 <= #t~ret72#1 && #t~ret72#1 <= 2147483647;~tmp~14#1 := #t~ret72#1;havoc #t~ret72#1;~email~0#1 := ~tmp~14#1; {5483#false} is VALID [2022-02-20 18:00:02,380 INFO L272 TraceCheckUtils]: 69: Hoare triple {5483#false} call outgoing(~sender#1, ~email~0#1); {5483#false} is VALID [2022-02-20 18:00:02,380 INFO L290 TraceCheckUtils]: 70: Hoare triple {5483#false} ~client#1 := #in~client#1;~msg#1 := #in~msg#1;assume { :begin_inline_sign } true;sign_#in~client#1, sign_#in~msg#1 := ~client#1, ~msg#1;havoc sign_#t~ret76#1, sign_~client#1, sign_~msg#1, sign_~privkey~1#1, sign_~tmp~16#1;sign_~client#1 := sign_#in~client#1;sign_~msg#1 := sign_#in~msg#1;havoc sign_~privkey~1#1;havoc sign_~tmp~16#1; {5483#false} is VALID [2022-02-20 18:00:02,380 INFO L272 TraceCheckUtils]: 71: Hoare triple {5483#false} call sign_#t~ret76#1 := getClientPrivateKey(sign_~client#1); {5483#false} is VALID [2022-02-20 18:00:02,380 INFO L290 TraceCheckUtils]: 72: Hoare triple {5483#false} ~handle := #in~handle;havoc ~retValue_acc~20; {5483#false} is VALID [2022-02-20 18:00:02,380 INFO L290 TraceCheckUtils]: 73: Hoare triple {5483#false} assume 1 == ~handle;~retValue_acc~20 := ~__ste_client_privateKey0~0;#res := ~retValue_acc~20; {5483#false} is VALID [2022-02-20 18:00:02,380 INFO L290 TraceCheckUtils]: 74: Hoare triple {5483#false} assume true; {5483#false} is VALID [2022-02-20 18:00:02,380 INFO L284 TraceCheckUtils]: 75: Hoare quadruple {5483#false} {5483#false} #1054#return; {5483#false} is VALID [2022-02-20 18:00:02,380 INFO L290 TraceCheckUtils]: 76: Hoare triple {5483#false} assume -2147483648 <= sign_#t~ret76#1 && sign_#t~ret76#1 <= 2147483647;sign_~tmp~16#1 := sign_#t~ret76#1;havoc sign_#t~ret76#1;sign_~privkey~1#1 := sign_~tmp~16#1; {5483#false} is VALID [2022-02-20 18:00:02,380 INFO L290 TraceCheckUtils]: 77: Hoare triple {5483#false} assume 0 == sign_~privkey~1#1; {5483#false} is VALID [2022-02-20 18:00:02,380 INFO L290 TraceCheckUtils]: 78: Hoare triple {5483#false} assume { :end_inline_sign } true;assume { :begin_inline_outgoing__wrappee__AutoResponder } true;outgoing__wrappee__AutoResponder_#in~client#1, outgoing__wrappee__AutoResponder_#in~msg#1 := ~client#1, ~msg#1;havoc outgoing__wrappee__AutoResponder_#t~ret62#1, outgoing__wrappee__AutoResponder_#t~ret63#1, outgoing__wrappee__AutoResponder_~client#1, outgoing__wrappee__AutoResponder_~msg#1, outgoing__wrappee__AutoResponder_~receiver~0#1, outgoing__wrappee__AutoResponder_~tmp~9#1, outgoing__wrappee__AutoResponder_~pubkey~0#1, outgoing__wrappee__AutoResponder_~tmp___0~3#1;outgoing__wrappee__AutoResponder_~client#1 := outgoing__wrappee__AutoResponder_#in~client#1;outgoing__wrappee__AutoResponder_~msg#1 := outgoing__wrappee__AutoResponder_#in~msg#1;havoc outgoing__wrappee__AutoResponder_~receiver~0#1;havoc outgoing__wrappee__AutoResponder_~tmp~9#1;havoc outgoing__wrappee__AutoResponder_~pubkey~0#1;havoc outgoing__wrappee__AutoResponder_~tmp___0~3#1; {5483#false} is VALID [2022-02-20 18:00:02,380 INFO L272 TraceCheckUtils]: 79: Hoare triple {5483#false} call outgoing__wrappee__AutoResponder_#t~ret62#1 := getEmailTo(outgoing__wrappee__AutoResponder_~msg#1); {5483#false} is VALID [2022-02-20 18:00:02,380 INFO L290 TraceCheckUtils]: 80: Hoare triple {5483#false} ~handle := #in~handle;havoc ~retValue_acc~36; {5483#false} is VALID [2022-02-20 18:00:02,380 INFO L290 TraceCheckUtils]: 81: Hoare triple {5483#false} assume 1 == ~handle;~retValue_acc~36 := ~__ste_email_to0~0;#res := ~retValue_acc~36; {5483#false} is VALID [2022-02-20 18:00:02,381 INFO L290 TraceCheckUtils]: 82: Hoare triple {5483#false} assume true; {5483#false} is VALID [2022-02-20 18:00:02,381 INFO L284 TraceCheckUtils]: 83: Hoare quadruple {5483#false} {5483#false} #1056#return; {5483#false} is VALID [2022-02-20 18:00:02,381 INFO L290 TraceCheckUtils]: 84: Hoare triple {5483#false} assume -2147483648 <= outgoing__wrappee__AutoResponder_#t~ret62#1 && outgoing__wrappee__AutoResponder_#t~ret62#1 <= 2147483647;outgoing__wrappee__AutoResponder_~tmp~9#1 := outgoing__wrappee__AutoResponder_#t~ret62#1;havoc outgoing__wrappee__AutoResponder_#t~ret62#1;outgoing__wrappee__AutoResponder_~receiver~0#1 := outgoing__wrappee__AutoResponder_~tmp~9#1; {5483#false} is VALID [2022-02-20 18:00:02,381 INFO L272 TraceCheckUtils]: 85: Hoare triple {5483#false} call outgoing__wrappee__AutoResponder_#t~ret63#1 := findPublicKey(outgoing__wrappee__AutoResponder_~client#1, outgoing__wrappee__AutoResponder_~receiver~0#1); {5483#false} is VALID [2022-02-20 18:00:02,381 INFO L290 TraceCheckUtils]: 86: Hoare triple {5483#false} ~handle := #in~handle;~userid := #in~userid;havoc ~retValue_acc~25; {5483#false} is VALID [2022-02-20 18:00:02,381 INFO L290 TraceCheckUtils]: 87: Hoare triple {5483#false} assume 1 == ~handle; {5483#false} is VALID [2022-02-20 18:00:02,381 INFO L290 TraceCheckUtils]: 88: Hoare triple {5483#false} assume ~userid == ~__ste_Client_Keyring0_User0~0;~retValue_acc~25 := ~__ste_Client_Keyring0_PublicKey0~0;#res := ~retValue_acc~25; {5483#false} is VALID [2022-02-20 18:00:02,381 INFO L290 TraceCheckUtils]: 89: Hoare triple {5483#false} assume true; {5483#false} is VALID [2022-02-20 18:00:02,381 INFO L284 TraceCheckUtils]: 90: Hoare quadruple {5483#false} {5483#false} #1058#return; {5483#false} is VALID [2022-02-20 18:00:02,381 INFO L290 TraceCheckUtils]: 91: Hoare triple {5483#false} assume -2147483648 <= outgoing__wrappee__AutoResponder_#t~ret63#1 && outgoing__wrappee__AutoResponder_#t~ret63#1 <= 2147483647;outgoing__wrappee__AutoResponder_~tmp___0~3#1 := outgoing__wrappee__AutoResponder_#t~ret63#1;havoc outgoing__wrappee__AutoResponder_#t~ret63#1;outgoing__wrappee__AutoResponder_~pubkey~0#1 := outgoing__wrappee__AutoResponder_~tmp___0~3#1; {5483#false} is VALID [2022-02-20 18:00:02,381 INFO L290 TraceCheckUtils]: 92: Hoare triple {5483#false} assume !(0 != outgoing__wrappee__AutoResponder_~pubkey~0#1); {5483#false} is VALID [2022-02-20 18:00:02,381 INFO L290 TraceCheckUtils]: 93: Hoare triple {5483#false} assume { :begin_inline_outgoing__wrappee__Keys } true;outgoing__wrappee__Keys_#in~client#1, outgoing__wrappee__Keys_#in~msg#1 := outgoing__wrappee__AutoResponder_~client#1, outgoing__wrappee__AutoResponder_~msg#1;havoc outgoing__wrappee__Keys_#t~ret61#1, outgoing__wrappee__Keys_~client#1, outgoing__wrappee__Keys_~msg#1, outgoing__wrappee__Keys_~tmp~8#1;outgoing__wrappee__Keys_~client#1 := outgoing__wrappee__Keys_#in~client#1;outgoing__wrappee__Keys_~msg#1 := outgoing__wrappee__Keys_#in~msg#1;havoc outgoing__wrappee__Keys_~tmp~8#1;assume { :begin_inline_getClientId } true;getClientId_#in~handle#1 := outgoing__wrappee__Keys_~client#1;havoc getClientId_#res#1;havoc getClientId_~handle#1, getClientId_~retValue_acc~27#1;getClientId_~handle#1 := getClientId_#in~handle#1;havoc getClientId_~retValue_acc~27#1; {5483#false} is VALID [2022-02-20 18:00:02,381 INFO L290 TraceCheckUtils]: 94: Hoare triple {5483#false} assume 1 == getClientId_~handle#1;getClientId_~retValue_acc~27#1 := ~__ste_client_idCounter0~0;getClientId_#res#1 := getClientId_~retValue_acc~27#1; {5483#false} is VALID [2022-02-20 18:00:02,381 INFO L290 TraceCheckUtils]: 95: Hoare triple {5483#false} outgoing__wrappee__Keys_#t~ret61#1 := getClientId_#res#1;assume { :end_inline_getClientId } true;assume -2147483648 <= outgoing__wrappee__Keys_#t~ret61#1 && outgoing__wrappee__Keys_#t~ret61#1 <= 2147483647;outgoing__wrappee__Keys_~tmp~8#1 := outgoing__wrappee__Keys_#t~ret61#1;havoc outgoing__wrappee__Keys_#t~ret61#1; {5483#false} is VALID [2022-02-20 18:00:02,381 INFO L272 TraceCheckUtils]: 96: Hoare triple {5483#false} call setEmailFrom(outgoing__wrappee__Keys_~msg#1, outgoing__wrappee__Keys_~tmp~8#1); {5483#false} is VALID [2022-02-20 18:00:02,382 INFO L290 TraceCheckUtils]: 97: Hoare triple {5483#false} ~handle := #in~handle;~value := #in~value; {5483#false} is VALID [2022-02-20 18:00:02,382 INFO L290 TraceCheckUtils]: 98: Hoare triple {5483#false} assume 1 == ~handle;~__ste_email_from0~0 := ~value; {5483#false} is VALID [2022-02-20 18:00:02,382 INFO L290 TraceCheckUtils]: 99: Hoare triple {5483#false} assume true; {5483#false} is VALID [2022-02-20 18:00:02,382 INFO L284 TraceCheckUtils]: 100: Hoare quadruple {5483#false} {5483#false} #1064#return; {5483#false} is VALID [2022-02-20 18:00:02,382 INFO L290 TraceCheckUtils]: 101: Hoare triple {5483#false} assume { :begin_inline_mail } true;mail_#in~client#1, mail_#in~msg#1 := outgoing__wrappee__Keys_~client#1, outgoing__wrappee__Keys_~msg#1;havoc mail_#t~ret59#1, mail_#t~ret60#1, mail_~client#1, mail_~msg#1, mail_~__utac__ad__arg1~0#1, mail_~__utac__ad__arg2~0#1, mail_~tmp~7#1;mail_~client#1 := mail_#in~client#1;mail_~msg#1 := mail_#in~msg#1;havoc mail_~__utac__ad__arg1~0#1;havoc mail_~__utac__ad__arg2~0#1;havoc mail_~tmp~7#1;mail_~__utac__ad__arg1~0#1 := mail_~client#1;mail_~__utac__ad__arg2~0#1 := mail_~msg#1;assume { :begin_inline___utac_acc__SignForward_spec__1 } true;__utac_acc__SignForward_spec__1_#in~client#1, __utac_acc__SignForward_spec__1_#in~msg#1 := mail_~__utac__ad__arg1~0#1, mail_~__utac__ad__arg2~0#1;havoc __utac_acc__SignForward_spec__1_#t~ret107#1, __utac_acc__SignForward_spec__1_#t~ret108#1, __utac_acc__SignForward_spec__1_#t~ret109#1, __utac_acc__SignForward_spec__1_~client#1, __utac_acc__SignForward_spec__1_~msg#1, __utac_acc__SignForward_spec__1_~tmp~25#1, __utac_acc__SignForward_spec__1_~tmp___0~9#1;__utac_acc__SignForward_spec__1_~client#1 := __utac_acc__SignForward_spec__1_#in~client#1;__utac_acc__SignForward_spec__1_~msg#1 := __utac_acc__SignForward_spec__1_#in~msg#1;havoc __utac_acc__SignForward_spec__1_~tmp~25#1;havoc __utac_acc__SignForward_spec__1_~tmp___0~9#1;call __utac_acc__SignForward_spec__1_#t~ret107#1 := puts(39, 0);assume -2147483648 <= __utac_acc__SignForward_spec__1_#t~ret107#1 && __utac_acc__SignForward_spec__1_#t~ret107#1 <= 2147483647;havoc __utac_acc__SignForward_spec__1_#t~ret107#1; {5483#false} is VALID [2022-02-20 18:00:02,382 INFO L272 TraceCheckUtils]: 102: Hoare triple {5483#false} call __utac_acc__SignForward_spec__1_#t~ret108#1 := isSigned(__utac_acc__SignForward_spec__1_~msg#1); {5483#false} is VALID [2022-02-20 18:00:02,382 INFO L290 TraceCheckUtils]: 103: Hoare triple {5483#false} ~handle := #in~handle;havoc ~retValue_acc~41; {5483#false} is VALID [2022-02-20 18:00:02,382 INFO L290 TraceCheckUtils]: 104: Hoare triple {5483#false} assume 1 == ~handle;~retValue_acc~41 := ~__ste_email_isSigned0~0;#res := ~retValue_acc~41; {5483#false} is VALID [2022-02-20 18:00:02,382 INFO L290 TraceCheckUtils]: 105: Hoare triple {5483#false} assume true; {5483#false} is VALID [2022-02-20 18:00:02,383 INFO L284 TraceCheckUtils]: 106: Hoare quadruple {5483#false} {5483#false} #1066#return; {5483#false} is VALID [2022-02-20 18:00:02,383 INFO L290 TraceCheckUtils]: 107: Hoare triple {5483#false} assume -2147483648 <= __utac_acc__SignForward_spec__1_#t~ret108#1 && __utac_acc__SignForward_spec__1_#t~ret108#1 <= 2147483647;__utac_acc__SignForward_spec__1_~tmp___0~9#1 := __utac_acc__SignForward_spec__1_#t~ret108#1;havoc __utac_acc__SignForward_spec__1_#t~ret108#1; {5483#false} is VALID [2022-02-20 18:00:02,383 INFO L290 TraceCheckUtils]: 108: Hoare triple {5483#false} assume 0 != __utac_acc__SignForward_spec__1_~tmp___0~9#1; {5483#false} is VALID [2022-02-20 18:00:02,383 INFO L272 TraceCheckUtils]: 109: Hoare triple {5483#false} call __utac_acc__SignForward_spec__1_#t~ret109#1 := getClientPrivateKey(__utac_acc__SignForward_spec__1_~client#1); {5483#false} is VALID [2022-02-20 18:00:02,383 INFO L290 TraceCheckUtils]: 110: Hoare triple {5483#false} ~handle := #in~handle;havoc ~retValue_acc~20; {5483#false} is VALID [2022-02-20 18:00:02,383 INFO L290 TraceCheckUtils]: 111: Hoare triple {5483#false} assume 1 == ~handle;~retValue_acc~20 := ~__ste_client_privateKey0~0;#res := ~retValue_acc~20; {5483#false} is VALID [2022-02-20 18:00:02,383 INFO L290 TraceCheckUtils]: 112: Hoare triple {5483#false} assume true; {5483#false} is VALID [2022-02-20 18:00:02,383 INFO L284 TraceCheckUtils]: 113: Hoare quadruple {5483#false} {5483#false} #1068#return; {5483#false} is VALID [2022-02-20 18:00:02,383 INFO L290 TraceCheckUtils]: 114: Hoare triple {5483#false} assume -2147483648 <= __utac_acc__SignForward_spec__1_#t~ret109#1 && __utac_acc__SignForward_spec__1_#t~ret109#1 <= 2147483647;__utac_acc__SignForward_spec__1_~tmp~25#1 := __utac_acc__SignForward_spec__1_#t~ret109#1;havoc __utac_acc__SignForward_spec__1_#t~ret109#1; {5483#false} is VALID [2022-02-20 18:00:02,384 INFO L290 TraceCheckUtils]: 115: Hoare triple {5483#false} assume 0 == __utac_acc__SignForward_spec__1_~tmp~25#1;assume { :begin_inline___automaton_fail } true; {5483#false} is VALID [2022-02-20 18:00:02,384 INFO L290 TraceCheckUtils]: 116: Hoare triple {5483#false} assume !false; {5483#false} is VALID [2022-02-20 18:00:02,384 INFO L134 CoverageAnalysis]: Checked inductivity of 34 backedges. 2 proven. 0 refuted. 0 times theorem prover too weak. 32 trivial. 0 not checked. [2022-02-20 18:00:02,384 INFO L324 TraceCheckSpWp]: Omiting computation of backward sequence because forward sequence was already perfect [2022-02-20 18:00:02,384 INFO L165 FreeRefinementEngine]: IpTcStrategyModuleZ3 [1767264139] provided 1 perfect and 0 imperfect interpolant sequences [2022-02-20 18:00:02,384 INFO L191 FreeRefinementEngine]: Found 1 perfect and 1 imperfect interpolant sequences. [2022-02-20 18:00:02,385 INFO L204 FreeRefinementEngine]: Number of different interpolants: perfect sequences [3] imperfect sequences [9] total 10 [2022-02-20 18:00:02,385 INFO L118 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [148223410] [2022-02-20 18:00:02,385 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2022-02-20 18:00:02,386 INFO L78 Accepts]: Start accepts. Automaton has has 3 states, 3 states have (on average 23.0) internal successors, (69), 3 states have internal predecessors, (69), 2 states have call successors, (16), 2 states have call predecessors, (16), 2 states have return successors, (14), 2 states have call predecessors, (14), 2 states have call successors, (14) Word has length 117 [2022-02-20 18:00:02,386 INFO L84 Accepts]: Finished accepts. word is accepted. [2022-02-20 18:00:02,386 INFO L86 InductivityCheck]: Starting indutivity check of a Floyd-Hoare automaton with has 3 states, 3 states have (on average 23.0) internal successors, (69), 3 states have internal predecessors, (69), 2 states have call successors, (16), 2 states have call predecessors, (16), 2 states have return successors, (14), 2 states have call predecessors, (14), 2 states have call successors, (14) [2022-02-20 18:00:02,453 INFO L122 InductivityCheck]: Floyd-Hoare automaton has 99 edges. 99 inductive. 0 not inductive. 0 times theorem prover too weak to decide inductivity. [2022-02-20 18:00:02,453 INFO L546 AbstractCegarLoop]: INTERPOLANT automaton has 3 states [2022-02-20 18:00:02,453 INFO L108 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2022-02-20 18:00:02,454 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 3 interpolants. [2022-02-20 18:00:02,454 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=17, Invalid=73, Unknown=0, NotChecked=0, Total=90 [2022-02-20 18:00:02,454 INFO L87 Difference]: Start difference. First operand 383 states and 565 transitions. Second operand has 3 states, 3 states have (on average 23.0) internal successors, (69), 3 states have internal predecessors, (69), 2 states have call successors, (16), 2 states have call predecessors, (16), 2 states have return successors, (14), 2 states have call predecessors, (14), 2 states have call successors, (14) [2022-02-20 18:00:02,937 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-02-20 18:00:02,938 INFO L93 Difference]: Finished difference Result 801 states and 1197 transitions. [2022-02-20 18:00:02,938 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 3 states. [2022-02-20 18:00:02,938 INFO L78 Accepts]: Start accepts. Automaton has has 3 states, 3 states have (on average 23.0) internal successors, (69), 3 states have internal predecessors, (69), 2 states have call successors, (16), 2 states have call predecessors, (16), 2 states have return successors, (14), 2 states have call predecessors, (14), 2 states have call successors, (14) Word has length 117 [2022-02-20 18:00:02,938 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2022-02-20 18:00:02,938 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 3 states, 3 states have (on average 23.0) internal successors, (69), 3 states have internal predecessors, (69), 2 states have call successors, (16), 2 states have call predecessors, (16), 2 states have return successors, (14), 2 states have call predecessors, (14), 2 states have call successors, (14) [2022-02-20 18:00:02,965 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 3 states to 3 states and 1195 transitions. [2022-02-20 18:00:02,965 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 3 states, 3 states have (on average 23.0) internal successors, (69), 3 states have internal predecessors, (69), 2 states have call successors, (16), 2 states have call predecessors, (16), 2 states have return successors, (14), 2 states have call predecessors, (14), 2 states have call successors, (14) [2022-02-20 18:00:02,977 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 3 states to 3 states and 1195 transitions. [2022-02-20 18:00:02,977 INFO L86 InductivityCheck]: Starting indutivity check of a Floyd-Hoare automaton with 3 states and 1195 transitions. [2022-02-20 18:00:03,775 INFO L122 InductivityCheck]: Floyd-Hoare automaton has 1195 edges. 1195 inductive. 0 not inductive. 0 times theorem prover too weak to decide inductivity. [2022-02-20 18:00:03,790 INFO L225 Difference]: With dead ends: 801 [2022-02-20 18:00:03,791 INFO L226 Difference]: Without dead ends: 445 [2022-02-20 18:00:03,792 INFO L932 BasicCegarLoop]: 0 DeclaredPredicates, 148 GetRequests, 140 SyntacticMatches, 0 SemanticMatches, 8 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 0 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=17, Invalid=73, Unknown=0, NotChecked=0, Total=90 [2022-02-20 18:00:03,793 INFO L933 BasicCegarLoop]: 579 mSDtfsCounter, 115 mSDsluCounter, 515 mSDsCounter, 0 mSdLazyCounter, 3 mSolverCounterSat, 1 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.0s Time, 0 mProtectedPredicate, 0 mProtectedAction, 130 SdHoareTripleChecker+Valid, 1094 SdHoareTripleChecker+Invalid, 4 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 1 IncrementalHoareTripleChecker+Valid, 3 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.0s IncrementalHoareTripleChecker+Time [2022-02-20 18:00:03,793 INFO L934 BasicCegarLoop]: SdHoareTripleChecker [130 Valid, 1094 Invalid, 4 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [1 Valid, 3 Invalid, 0 Unknown, 0 Unchecked, 0.0s Time] [2022-02-20 18:00:03,794 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 445 states. [2022-02-20 18:00:03,804 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 445 to 437. [2022-02-20 18:00:03,804 INFO L214 AbstractMinimizeNwa]: Start testing correctness of minimizeSevpa [2022-02-20 18:00:03,805 INFO L82 GeneralOperation]: Start isEquivalent. First operand 445 states. Second operand has 437 states, 338 states have (on average 1.5088757396449703) internal successors, (510), 341 states have internal predecessors, (510), 74 states have call successors, (74), 24 states have call predecessors, (74), 24 states have return successors, (73), 73 states have call predecessors, (73), 73 states have call successors, (73) [2022-02-20 18:00:03,806 INFO L74 IsIncluded]: Start isIncluded. First operand 445 states. Second operand has 437 states, 338 states have (on average 1.5088757396449703) internal successors, (510), 341 states have internal predecessors, (510), 74 states have call successors, (74), 24 states have call predecessors, (74), 24 states have return successors, (73), 73 states have call predecessors, (73), 73 states have call successors, (73) [2022-02-20 18:00:03,807 INFO L87 Difference]: Start difference. First operand 445 states. Second operand has 437 states, 338 states have (on average 1.5088757396449703) internal successors, (510), 341 states have internal predecessors, (510), 74 states have call successors, (74), 24 states have call predecessors, (74), 24 states have return successors, (73), 73 states have call predecessors, (73), 73 states have call successors, (73) [2022-02-20 18:00:03,819 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-02-20 18:00:03,819 INFO L93 Difference]: Finished difference Result 445 states and 666 transitions. [2022-02-20 18:00:03,819 INFO L276 IsEmpty]: Start isEmpty. Operand 445 states and 666 transitions. [2022-02-20 18:00:03,821 INFO L282 IsEmpty]: Finished isEmpty. No accepting run. [2022-02-20 18:00:03,821 INFO L83 IsIncluded]: Finished isIncluded. Language is included [2022-02-20 18:00:03,822 INFO L74 IsIncluded]: Start isIncluded. First operand has 437 states, 338 states have (on average 1.5088757396449703) internal successors, (510), 341 states have internal predecessors, (510), 74 states have call successors, (74), 24 states have call predecessors, (74), 24 states have return successors, (73), 73 states have call predecessors, (73), 73 states have call successors, (73) Second operand 445 states. [2022-02-20 18:00:03,823 INFO L87 Difference]: Start difference. First operand has 437 states, 338 states have (on average 1.5088757396449703) internal successors, (510), 341 states have internal predecessors, (510), 74 states have call successors, (74), 24 states have call predecessors, (74), 24 states have return successors, (73), 73 states have call predecessors, (73), 73 states have call successors, (73) Second operand 445 states. [2022-02-20 18:00:03,835 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-02-20 18:00:03,835 INFO L93 Difference]: Finished difference Result 445 states and 666 transitions. [2022-02-20 18:00:03,835 INFO L276 IsEmpty]: Start isEmpty. Operand 445 states and 666 transitions. [2022-02-20 18:00:03,837 INFO L282 IsEmpty]: Finished isEmpty. No accepting run. [2022-02-20 18:00:03,837 INFO L83 IsIncluded]: Finished isIncluded. Language is included [2022-02-20 18:00:03,837 INFO L88 GeneralOperation]: Finished isEquivalent. [2022-02-20 18:00:03,837 INFO L221 AbstractMinimizeNwa]: Finished testing correctness of minimizeSevpa [2022-02-20 18:00:03,838 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 437 states, 338 states have (on average 1.5088757396449703) internal successors, (510), 341 states have internal predecessors, (510), 74 states have call successors, (74), 24 states have call predecessors, (74), 24 states have return successors, (73), 73 states have call predecessors, (73), 73 states have call successors, (73) [2022-02-20 18:00:03,851 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 437 states to 437 states and 657 transitions. [2022-02-20 18:00:03,852 INFO L78 Accepts]: Start accepts. Automaton has 437 states and 657 transitions. Word has length 117 [2022-02-20 18:00:03,852 INFO L84 Accepts]: Finished accepts. word is rejected. [2022-02-20 18:00:03,852 INFO L470 AbstractCegarLoop]: Abstraction has 437 states and 657 transitions. [2022-02-20 18:00:03,852 INFO L471 AbstractCegarLoop]: INTERPOLANT automaton has has 3 states, 3 states have (on average 23.0) internal successors, (69), 3 states have internal predecessors, (69), 2 states have call successors, (16), 2 states have call predecessors, (16), 2 states have return successors, (14), 2 states have call predecessors, (14), 2 states have call successors, (14) [2022-02-20 18:00:03,852 INFO L276 IsEmpty]: Start isEmpty. Operand 437 states and 657 transitions. [2022-02-20 18:00:03,854 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 119 [2022-02-20 18:00:03,854 INFO L506 BasicCegarLoop]: Found error trace [2022-02-20 18:00:03,854 INFO L514 BasicCegarLoop]: trace histogram [3, 3, 3, 3, 3, 3, 2, 2, 2, 2, 2, 2, 2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-02-20 18:00:03,889 INFO L552 MonitoredProcess]: [MP /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 -smt2 -in SMTLIB2_COMPLIANT=true (4)] Ended with exit code 0 [2022-02-20 18:00:04,090 WARN L452 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable2,4 /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 -smt2 -in SMTLIB2_COMPLIANT=true [2022-02-20 18:00:04,091 INFO L402 AbstractCegarLoop]: === Iteration 4 === Targeting outgoingErr0ASSERT_VIOLATIONERROR_FUNCTION === [outgoingErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2022-02-20 18:00:04,091 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2022-02-20 18:00:04,091 INFO L85 PathProgramCache]: Analyzing trace with hash 245871513, now seen corresponding path program 1 times [2022-02-20 18:00:04,091 INFO L126 FreeRefinementEngine]: Executing refinement strategy CAMEL [2022-02-20 18:00:04,091 INFO L338 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [1119638945] [2022-02-20 18:00:04,092 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-02-20 18:00:04,092 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2022-02-20 18:00:04,116 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-02-20 18:00:04,138 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 6 [2022-02-20 18:00:04,140 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-02-20 18:00:04,142 INFO L290 TraceCheckUtils]: 0: Hoare triple {8599#(and (= |old(~__ste_client_idCounter0~0)| ~__ste_client_idCounter0~0) (= |old(~__ste_client_idCounter1~0)| ~__ste_client_idCounter1~0) (= |old(~__ste_client_idCounter2~0)| ~__ste_client_idCounter2~0))} ~handle := #in~handle;~value := #in~value; {8539#true} is VALID [2022-02-20 18:00:04,142 INFO L290 TraceCheckUtils]: 1: Hoare triple {8539#true} assume 1 == ~handle;~__ste_client_idCounter0~0 := ~value; {8539#true} is VALID [2022-02-20 18:00:04,142 INFO L290 TraceCheckUtils]: 2: Hoare triple {8539#true} assume true; {8539#true} is VALID [2022-02-20 18:00:04,142 INFO L284 TraceCheckUtils]: 3: Hoare quadruple {8539#true} {8539#true} #1134#return; {8539#true} is VALID [2022-02-20 18:00:04,148 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 12 [2022-02-20 18:00:04,149 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-02-20 18:00:04,151 INFO L290 TraceCheckUtils]: 0: Hoare triple {8600#(and (= ~__ste_client_privateKey0~0 |old(~__ste_client_privateKey0~0)|) (= ~__ste_client_privateKey2~0 |old(~__ste_client_privateKey2~0)|) (= ~__ste_client_privateKey1~0 |old(~__ste_client_privateKey1~0)|))} ~handle := #in~handle;~value := #in~value; {8539#true} is VALID [2022-02-20 18:00:04,151 INFO L290 TraceCheckUtils]: 1: Hoare triple {8539#true} assume 1 == ~handle;~__ste_client_privateKey0~0 := ~value; {8539#true} is VALID [2022-02-20 18:00:04,151 INFO L290 TraceCheckUtils]: 2: Hoare triple {8539#true} assume true; {8539#true} is VALID [2022-02-20 18:00:04,152 INFO L284 TraceCheckUtils]: 3: Hoare quadruple {8539#true} {8539#true} #1136#return; {8539#true} is VALID [2022-02-20 18:00:04,152 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 18 [2022-02-20 18:00:04,153 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-02-20 18:00:04,166 INFO L290 TraceCheckUtils]: 0: Hoare triple {8599#(and (= |old(~__ste_client_idCounter0~0)| ~__ste_client_idCounter0~0) (= |old(~__ste_client_idCounter1~0)| ~__ste_client_idCounter1~0) (= |old(~__ste_client_idCounter2~0)| ~__ste_client_idCounter2~0))} ~handle := #in~handle;~value := #in~value; {8601#(= setClientId_~handle |setClientId_#in~handle|)} is VALID [2022-02-20 18:00:04,166 INFO L290 TraceCheckUtils]: 1: Hoare triple {8601#(= setClientId_~handle |setClientId_#in~handle|)} assume 1 == ~handle;~__ste_client_idCounter0~0 := ~value; {8602#(= |setClientId_#in~handle| 1)} is VALID [2022-02-20 18:00:04,167 INFO L290 TraceCheckUtils]: 2: Hoare triple {8602#(= |setClientId_#in~handle| 1)} assume true; {8602#(= |setClientId_#in~handle| 1)} is VALID [2022-02-20 18:00:04,167 INFO L284 TraceCheckUtils]: 3: Hoare quadruple {8602#(= |setClientId_#in~handle| 1)} {8549#(= |ULTIMATE.start_setup_rjh__wrappee__Base_~rjh___0#1| 2)} #1138#return; {8540#false} is VALID [2022-02-20 18:00:04,167 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 24 [2022-02-20 18:00:04,169 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-02-20 18:00:04,172 INFO L290 TraceCheckUtils]: 0: Hoare triple {8600#(and (= ~__ste_client_privateKey0~0 |old(~__ste_client_privateKey0~0)|) (= ~__ste_client_privateKey2~0 |old(~__ste_client_privateKey2~0)|) (= ~__ste_client_privateKey1~0 |old(~__ste_client_privateKey1~0)|))} ~handle := #in~handle;~value := #in~value; {8539#true} is VALID [2022-02-20 18:00:04,173 INFO L290 TraceCheckUtils]: 1: Hoare triple {8539#true} assume 1 == ~handle;~__ste_client_privateKey0~0 := ~value; {8539#true} is VALID [2022-02-20 18:00:04,173 INFO L290 TraceCheckUtils]: 2: Hoare triple {8539#true} assume true; {8539#true} is VALID [2022-02-20 18:00:04,173 INFO L284 TraceCheckUtils]: 3: Hoare quadruple {8539#true} {8540#false} #1140#return; {8540#false} is VALID [2022-02-20 18:00:04,173 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 30 [2022-02-20 18:00:04,175 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-02-20 18:00:04,177 INFO L290 TraceCheckUtils]: 0: Hoare triple {8599#(and (= |old(~__ste_client_idCounter0~0)| ~__ste_client_idCounter0~0) (= |old(~__ste_client_idCounter1~0)| ~__ste_client_idCounter1~0) (= |old(~__ste_client_idCounter2~0)| ~__ste_client_idCounter2~0))} ~handle := #in~handle;~value := #in~value; {8539#true} is VALID [2022-02-20 18:00:04,177 INFO L290 TraceCheckUtils]: 1: Hoare triple {8539#true} assume 1 == ~handle;~__ste_client_idCounter0~0 := ~value; {8539#true} is VALID [2022-02-20 18:00:04,177 INFO L290 TraceCheckUtils]: 2: Hoare triple {8539#true} assume true; {8539#true} is VALID [2022-02-20 18:00:04,177 INFO L284 TraceCheckUtils]: 3: Hoare quadruple {8539#true} {8540#false} #1142#return; {8540#false} is VALID [2022-02-20 18:00:04,177 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 36 [2022-02-20 18:00:04,179 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-02-20 18:00:04,181 INFO L290 TraceCheckUtils]: 0: Hoare triple {8600#(and (= ~__ste_client_privateKey0~0 |old(~__ste_client_privateKey0~0)|) (= ~__ste_client_privateKey2~0 |old(~__ste_client_privateKey2~0)|) (= ~__ste_client_privateKey1~0 |old(~__ste_client_privateKey1~0)|))} ~handle := #in~handle;~value := #in~value; {8539#true} is VALID [2022-02-20 18:00:04,181 INFO L290 TraceCheckUtils]: 1: Hoare triple {8539#true} assume 1 == ~handle;~__ste_client_privateKey0~0 := ~value; {8539#true} is VALID [2022-02-20 18:00:04,181 INFO L290 TraceCheckUtils]: 2: Hoare triple {8539#true} assume true; {8539#true} is VALID [2022-02-20 18:00:04,181 INFO L284 TraceCheckUtils]: 3: Hoare quadruple {8539#true} {8540#false} #1144#return; {8540#false} is VALID [2022-02-20 18:00:04,187 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 58 [2022-02-20 18:00:04,188 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-02-20 18:00:04,190 INFO L290 TraceCheckUtils]: 0: Hoare triple {8603#(and (= |old(~__ste_email_from0~0)| ~__ste_email_from0~0) (= |old(~__ste_email_from1~0)| ~__ste_email_from1~0))} ~handle := #in~handle;~value := #in~value; {8539#true} is VALID [2022-02-20 18:00:04,191 INFO L290 TraceCheckUtils]: 1: Hoare triple {8539#true} assume 1 == ~handle;~__ste_email_from0~0 := ~value; {8539#true} is VALID [2022-02-20 18:00:04,191 INFO L290 TraceCheckUtils]: 2: Hoare triple {8539#true} assume true; {8539#true} is VALID [2022-02-20 18:00:04,191 INFO L284 TraceCheckUtils]: 3: Hoare quadruple {8539#true} {8540#false} #1120#return; {8540#false} is VALID [2022-02-20 18:00:04,198 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 63 [2022-02-20 18:00:04,199 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-02-20 18:00:04,201 INFO L290 TraceCheckUtils]: 0: Hoare triple {8604#(and (= ~__ste_email_to0~0 |old(~__ste_email_to0~0)|) (= ~__ste_email_to1~0 |old(~__ste_email_to1~0)|))} ~handle := #in~handle;~value := #in~value; {8539#true} is VALID [2022-02-20 18:00:04,201 INFO L290 TraceCheckUtils]: 1: Hoare triple {8539#true} assume 1 == ~handle;~__ste_email_to0~0 := ~value; {8539#true} is VALID [2022-02-20 18:00:04,201 INFO L290 TraceCheckUtils]: 2: Hoare triple {8539#true} assume true; {8539#true} is VALID [2022-02-20 18:00:04,202 INFO L284 TraceCheckUtils]: 3: Hoare quadruple {8539#true} {8540#false} #1122#return; {8540#false} is VALID [2022-02-20 18:00:04,202 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 72 [2022-02-20 18:00:04,203 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-02-20 18:00:04,204 INFO L290 TraceCheckUtils]: 0: Hoare triple {8539#true} ~handle := #in~handle;havoc ~retValue_acc~20; {8539#true} is VALID [2022-02-20 18:00:04,204 INFO L290 TraceCheckUtils]: 1: Hoare triple {8539#true} assume 1 == ~handle;~retValue_acc~20 := ~__ste_client_privateKey0~0;#res := ~retValue_acc~20; {8539#true} is VALID [2022-02-20 18:00:04,204 INFO L290 TraceCheckUtils]: 2: Hoare triple {8539#true} assume true; {8539#true} is VALID [2022-02-20 18:00:04,205 INFO L284 TraceCheckUtils]: 3: Hoare quadruple {8539#true} {8540#false} #1054#return; {8540#false} is VALID [2022-02-20 18:00:04,205 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 80 [2022-02-20 18:00:04,205 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-02-20 18:00:04,207 INFO L290 TraceCheckUtils]: 0: Hoare triple {8539#true} ~handle := #in~handle;havoc ~retValue_acc~36; {8539#true} is VALID [2022-02-20 18:00:04,207 INFO L290 TraceCheckUtils]: 1: Hoare triple {8539#true} assume 1 == ~handle;~retValue_acc~36 := ~__ste_email_to0~0;#res := ~retValue_acc~36; {8539#true} is VALID [2022-02-20 18:00:04,207 INFO L290 TraceCheckUtils]: 2: Hoare triple {8539#true} assume true; {8539#true} is VALID [2022-02-20 18:00:04,207 INFO L284 TraceCheckUtils]: 3: Hoare quadruple {8539#true} {8540#false} #1056#return; {8540#false} is VALID [2022-02-20 18:00:04,208 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 86 [2022-02-20 18:00:04,208 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-02-20 18:00:04,210 INFO L290 TraceCheckUtils]: 0: Hoare triple {8539#true} ~handle := #in~handle;~userid := #in~userid;havoc ~retValue_acc~25; {8539#true} is VALID [2022-02-20 18:00:04,210 INFO L290 TraceCheckUtils]: 1: Hoare triple {8539#true} assume 1 == ~handle; {8539#true} is VALID [2022-02-20 18:00:04,210 INFO L290 TraceCheckUtils]: 2: Hoare triple {8539#true} assume ~userid == ~__ste_Client_Keyring0_User0~0;~retValue_acc~25 := ~__ste_Client_Keyring0_PublicKey0~0;#res := ~retValue_acc~25; {8539#true} is VALID [2022-02-20 18:00:04,219 INFO L290 TraceCheckUtils]: 3: Hoare triple {8539#true} assume true; {8539#true} is VALID [2022-02-20 18:00:04,219 INFO L284 TraceCheckUtils]: 4: Hoare quadruple {8539#true} {8540#false} #1058#return; {8540#false} is VALID [2022-02-20 18:00:04,220 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 97 [2022-02-20 18:00:04,221 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-02-20 18:00:04,222 INFO L290 TraceCheckUtils]: 0: Hoare triple {8603#(and (= |old(~__ste_email_from0~0)| ~__ste_email_from0~0) (= |old(~__ste_email_from1~0)| ~__ste_email_from1~0))} ~handle := #in~handle;~value := #in~value; {8539#true} is VALID [2022-02-20 18:00:04,223 INFO L290 TraceCheckUtils]: 1: Hoare triple {8539#true} assume 1 == ~handle;~__ste_email_from0~0 := ~value; {8539#true} is VALID [2022-02-20 18:00:04,223 INFO L290 TraceCheckUtils]: 2: Hoare triple {8539#true} assume true; {8539#true} is VALID [2022-02-20 18:00:04,223 INFO L284 TraceCheckUtils]: 3: Hoare quadruple {8539#true} {8540#false} #1064#return; {8540#false} is VALID [2022-02-20 18:00:04,223 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 103 [2022-02-20 18:00:04,224 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-02-20 18:00:04,225 INFO L290 TraceCheckUtils]: 0: Hoare triple {8539#true} ~handle := #in~handle;havoc ~retValue_acc~41; {8539#true} is VALID [2022-02-20 18:00:04,226 INFO L290 TraceCheckUtils]: 1: Hoare triple {8539#true} assume 1 == ~handle;~retValue_acc~41 := ~__ste_email_isSigned0~0;#res := ~retValue_acc~41; {8539#true} is VALID [2022-02-20 18:00:04,226 INFO L290 TraceCheckUtils]: 2: Hoare triple {8539#true} assume true; {8539#true} is VALID [2022-02-20 18:00:04,226 INFO L284 TraceCheckUtils]: 3: Hoare quadruple {8539#true} {8540#false} #1066#return; {8540#false} is VALID [2022-02-20 18:00:04,226 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 110 [2022-02-20 18:00:04,227 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-02-20 18:00:04,230 INFO L290 TraceCheckUtils]: 0: Hoare triple {8539#true} ~handle := #in~handle;havoc ~retValue_acc~20; {8539#true} is VALID [2022-02-20 18:00:04,230 INFO L290 TraceCheckUtils]: 1: Hoare triple {8539#true} assume 1 == ~handle;~retValue_acc~20 := ~__ste_client_privateKey0~0;#res := ~retValue_acc~20; {8539#true} is VALID [2022-02-20 18:00:04,230 INFO L290 TraceCheckUtils]: 2: Hoare triple {8539#true} assume true; {8539#true} is VALID [2022-02-20 18:00:04,230 INFO L284 TraceCheckUtils]: 3: Hoare quadruple {8539#true} {8540#false} #1068#return; {8540#false} is VALID [2022-02-20 18:00:04,230 INFO L290 TraceCheckUtils]: 0: Hoare triple {8539#true} assume { :begin_inline_ULTIMATE.init } true;#NULL.base, #NULL.offset := 0, 0;assume 0 == #valid[0];assume 0 < #StackHeapBarrier;call #Ultimate.allocInit(2, 1);call write~init~int(48, 1, 0, 1);call write~init~int(0, 1, 1, 1);call #Ultimate.allocInit(28, 2);call #Ultimate.allocInit(12, 3);call #Ultimate.allocInit(30, 4);call #Ultimate.allocInit(9, 5);call #Ultimate.allocInit(21, 6);call #Ultimate.allocInit(30, 7);call #Ultimate.allocInit(9, 8);call #Ultimate.allocInit(21, 9);call #Ultimate.allocInit(30, 10);call #Ultimate.allocInit(9, 11);call #Ultimate.allocInit(25, 12);call #Ultimate.allocInit(30, 13);call #Ultimate.allocInit(9, 14);call #Ultimate.allocInit(25, 15);call #Ultimate.allocInit(44, 16);call #Ultimate.allocInit(44, 17);call #Ultimate.allocInit(9, 18);call #Ultimate.allocInit(9, 19);call #Ultimate.allocInit(11, 20);call #Ultimate.allocInit(19, 21);call #Ultimate.allocInit(4, 22);call write~init~int(37, 22, 0, 1);call write~init~int(100, 22, 1, 1);call write~init~int(10, 22, 2, 1);call write~init~int(0, 22, 3, 1);call #Ultimate.allocInit(4, 23);call write~init~int(37, 23, 0, 1);call write~init~int(100, 23, 1, 1);call write~init~int(10, 23, 2, 1);call write~init~int(0, 23, 3, 1);call #Ultimate.allocInit(10, 24);call #Ultimate.allocInit(16, 25);call #Ultimate.allocInit(20, 26);call #Ultimate.allocInit(22, 27);call #Ultimate.allocInit(21, 28);call #Ultimate.allocInit(10, 29);call #Ultimate.allocInit(12, 30);call #Ultimate.allocInit(10, 31);call #Ultimate.allocInit(18, 32);call #Ultimate.allocInit(16, 33);call #Ultimate.allocInit(21, 34);call #Ultimate.allocInit(13, 35);call #Ultimate.allocInit(16, 36);call #Ultimate.allocInit(25, 37);call #Ultimate.allocInit(4, 38);call write~init~int(37, 38, 0, 1);call write~init~int(115, 38, 1, 1);call write~init~int(10, 38, 2, 1);call write~init~int(0, 38, 3, 1);call #Ultimate.allocInit(13, 39);~head~0.base, ~head~0.offset := 0, 0;~__SELECTED_FEATURE_Base~0 := 0;~__SELECTED_FEATURE_Keys~0 := 0;~__SELECTED_FEATURE_Encrypt~0 := 0;~__SELECTED_FEATURE_AutoResponder~0 := 0;~__SELECTED_FEATURE_AddressBook~0 := 0;~__SELECTED_FEATURE_Sign~0 := 0;~__SELECTED_FEATURE_Forward~0 := 0;~__SELECTED_FEATURE_Verify~0 := 0;~__SELECTED_FEATURE_Decrypt~0 := 0;~__GUIDSL_ROOT_PRODUCTION~0 := 0;~__GUIDSL_NON_TERMINAL_main~0 := 0;~bob~0 := 0;~rjh~0 := 0;~chuck~0 := 0;~queue_empty~0 := 1;~queued_message~0 := 0;~queued_client~0 := 0;~__ste_Client_counter~0 := 0;~__ste_client_name0~0.base, ~__ste_client_name0~0.offset := 0, 0;~__ste_client_name1~0.base, ~__ste_client_name1~0.offset := 0, 0;~__ste_client_name2~0.base, ~__ste_client_name2~0.offset := 0, 0;~__ste_client_outbuffer0~0 := 0;~__ste_client_outbuffer1~0 := 0;~__ste_client_outbuffer2~0 := 0;~__ste_client_outbuffer3~0 := 0;~__ste_ClientAddressBook_size0~0 := 0;~__ste_ClientAddressBook_size1~0 := 0;~__ste_ClientAddressBook_size2~0 := 0;~__ste_Client_AddressBook0_Alias0~0 := 0;~__ste_Client_AddressBook0_Alias1~0 := 0;~__ste_Client_AddressBook0_Alias2~0 := 0;~__ste_Client_AddressBook1_Alias0~0 := 0;~__ste_Client_AddressBook1_Alias1~0 := 0;~__ste_Client_AddressBook1_Alias2~0 := 0;~__ste_Client_AddressBook2_Alias0~0 := 0;~__ste_Client_AddressBook2_Alias1~0 := 0;~__ste_Client_AddressBook2_Alias2~0 := 0;~__ste_Client_AddressBook0_Address0~0 := 0;~__ste_Client_AddressBook0_Address1~0 := 0;~__ste_Client_AddressBook0_Address2~0 := 0;~__ste_Client_AddressBook1_Address0~0 := 0;~__ste_Client_AddressBook1_Address1~0 := 0;~__ste_Client_AddressBook1_Address2~0 := 0;~__ste_Client_AddressBook2_Address0~0 := 0;~__ste_Client_AddressBook2_Address1~0 := 0;~__ste_Client_AddressBook2_Address2~0 := 0;~__ste_client_autoResponse0~0 := 0;~__ste_client_autoResponse1~0 := 0;~__ste_client_autoResponse2~0 := 0;~__ste_client_privateKey0~0 := 0;~__ste_client_privateKey1~0 := 0;~__ste_client_privateKey2~0 := 0;~__ste_ClientKeyring_size0~0 := 0;~__ste_ClientKeyring_size1~0 := 0;~__ste_ClientKeyring_size2~0 := 0;~__ste_Client_Keyring0_User0~0 := 0;~__ste_Client_Keyring0_User1~0 := 0;~__ste_Client_Keyring0_User2~0 := 0;~__ste_Client_Keyring1_User0~0 := 0;~__ste_Client_Keyring1_User1~0 := 0;~__ste_Client_Keyring1_User2~0 := 0;~__ste_Client_Keyring2_User0~0 := 0;~__ste_Client_Keyring2_User1~0 := 0;~__ste_Client_Keyring2_User2~0 := 0;~__ste_Client_Keyring0_PublicKey0~0 := 0;~__ste_Client_Keyring0_PublicKey1~0 := 0;~__ste_Client_Keyring0_PublicKey2~0 := 0;~__ste_Client_Keyring1_PublicKey0~0 := 0;~__ste_Client_Keyring1_PublicKey1~0 := 0;~__ste_Client_Keyring1_PublicKey2~0 := 0;~__ste_Client_Keyring2_PublicKey0~0 := 0;~__ste_Client_Keyring2_PublicKey1~0 := 0;~__ste_Client_Keyring2_PublicKey2~0 := 0;~__ste_client_forwardReceiver0~0 := 0;~__ste_client_forwardReceiver1~0 := 0;~__ste_client_forwardReceiver2~0 := 0;~__ste_client_forwardReceiver3~0 := 0;~__ste_client_idCounter0~0 := 0;~__ste_client_idCounter1~0 := 0;~__ste_client_idCounter2~0 := 0;~__ste_Email_counter~0 := 0;~__ste_email_id0~0 := 0;~__ste_email_id1~0 := 0;~__ste_email_from0~0 := 0;~__ste_email_from1~0 := 0;~__ste_email_to0~0 := 0;~__ste_email_to1~0 := 0;~__ste_email_subject0~0.base, ~__ste_email_subject0~0.offset := 0, 0;~__ste_email_subject1~0.base, ~__ste_email_subject1~0.offset := 0, 0;~__ste_email_body0~0.base, ~__ste_email_body0~0.offset := 0, 0;~__ste_email_body1~0.base, ~__ste_email_body1~0.offset := 0, 0;~__ste_email_isEncrypted0~0 := 0;~__ste_email_isEncrypted1~0 := 0;~__ste_email_encryptionKey0~0 := 0;~__ste_email_encryptionKey1~0 := 0;~__ste_email_isSigned0~0 := 0;~__ste_email_isSigned1~0 := 0;~__ste_email_signKey0~0 := 0;~__ste_email_signKey1~0 := 0;~__ste_email_isSignatureVerified0~0 := 0;~__ste_email_isSignatureVerified1~0 := 0; {8539#true} is VALID [2022-02-20 18:00:04,230 INFO L290 TraceCheckUtils]: 1: Hoare triple {8539#true} assume { :end_inline_ULTIMATE.init } true;assume { :begin_inline_main } true;havoc main_#res#1;havoc main_#t~ret35#1, main_~retValue_acc~3#1, main_~tmp~4#1;havoc main_~retValue_acc~3#1;havoc main_~tmp~4#1;assume { :begin_inline_select_helpers } true; {8539#true} is VALID [2022-02-20 18:00:04,231 INFO L290 TraceCheckUtils]: 2: Hoare triple {8539#true} assume { :end_inline_select_helpers } true;assume { :begin_inline_select_features } true; {8539#true} is VALID [2022-02-20 18:00:04,231 INFO L290 TraceCheckUtils]: 3: Hoare triple {8539#true} assume { :end_inline_select_features } true;assume { :begin_inline_valid_product } true;havoc valid_product_#res#1;havoc valid_product_~retValue_acc~5#1;havoc valid_product_~retValue_acc~5#1;valid_product_~retValue_acc~5#1 := 1;valid_product_#res#1 := valid_product_~retValue_acc~5#1; {8539#true} is VALID [2022-02-20 18:00:04,231 INFO L290 TraceCheckUtils]: 4: Hoare triple {8539#true} main_#t~ret35#1 := valid_product_#res#1;assume { :end_inline_valid_product } true;assume -2147483648 <= main_#t~ret35#1 && main_#t~ret35#1 <= 2147483647;main_~tmp~4#1 := main_#t~ret35#1;havoc main_#t~ret35#1; {8539#true} is VALID [2022-02-20 18:00:04,231 INFO L290 TraceCheckUtils]: 5: Hoare triple {8539#true} assume 0 != main_~tmp~4#1;assume { :begin_inline_setup } true;havoc setup_#t~nondet32#1, setup_#t~nondet33#1, setup_#t~nondet34#1, setup_~__cil_tmp1~0#1.base, setup_~__cil_tmp1~0#1.offset, setup_~__cil_tmp2~0#1.base, setup_~__cil_tmp2~0#1.offset, setup_~__cil_tmp3~0#1.base, setup_~__cil_tmp3~0#1.offset;havoc setup_~__cil_tmp1~0#1.base, setup_~__cil_tmp1~0#1.offset;havoc setup_~__cil_tmp2~0#1.base, setup_~__cil_tmp2~0#1.offset;havoc setup_~__cil_tmp3~0#1.base, setup_~__cil_tmp3~0#1.offset;~bob~0 := 1;assume { :begin_inline_setup_bob } true;setup_bob_#in~bob___0#1 := ~bob~0;havoc setup_bob_~bob___0#1;setup_bob_~bob___0#1 := setup_bob_#in~bob___0#1;assume { :begin_inline_setup_bob__wrappee__Base } true;setup_bob__wrappee__Base_#in~bob___0#1 := setup_bob_~bob___0#1;havoc setup_bob__wrappee__Base_~bob___0#1;setup_bob__wrappee__Base_~bob___0#1 := setup_bob__wrappee__Base_#in~bob___0#1; {8539#true} is VALID [2022-02-20 18:00:04,232 INFO L272 TraceCheckUtils]: 6: Hoare triple {8539#true} call setClientId(setup_bob__wrappee__Base_~bob___0#1, setup_bob__wrappee__Base_~bob___0#1); {8599#(and (= |old(~__ste_client_idCounter0~0)| ~__ste_client_idCounter0~0) (= |old(~__ste_client_idCounter1~0)| ~__ste_client_idCounter1~0) (= |old(~__ste_client_idCounter2~0)| ~__ste_client_idCounter2~0))} is VALID [2022-02-20 18:00:04,232 INFO L290 TraceCheckUtils]: 7: Hoare triple {8599#(and (= |old(~__ste_client_idCounter0~0)| ~__ste_client_idCounter0~0) (= |old(~__ste_client_idCounter1~0)| ~__ste_client_idCounter1~0) (= |old(~__ste_client_idCounter2~0)| ~__ste_client_idCounter2~0))} ~handle := #in~handle;~value := #in~value; {8539#true} is VALID [2022-02-20 18:00:04,232 INFO L290 TraceCheckUtils]: 8: Hoare triple {8539#true} assume 1 == ~handle;~__ste_client_idCounter0~0 := ~value; {8539#true} is VALID [2022-02-20 18:00:04,232 INFO L290 TraceCheckUtils]: 9: Hoare triple {8539#true} assume true; {8539#true} is VALID [2022-02-20 18:00:04,232 INFO L284 TraceCheckUtils]: 10: Hoare quadruple {8539#true} {8539#true} #1134#return; {8539#true} is VALID [2022-02-20 18:00:04,232 INFO L290 TraceCheckUtils]: 11: Hoare triple {8539#true} assume { :end_inline_setup_bob__wrappee__Base } true; {8539#true} is VALID [2022-02-20 18:00:04,233 INFO L272 TraceCheckUtils]: 12: Hoare triple {8539#true} call setClientPrivateKey(setup_bob_~bob___0#1, 123); {8600#(and (= ~__ste_client_privateKey0~0 |old(~__ste_client_privateKey0~0)|) (= ~__ste_client_privateKey2~0 |old(~__ste_client_privateKey2~0)|) (= ~__ste_client_privateKey1~0 |old(~__ste_client_privateKey1~0)|))} is VALID [2022-02-20 18:00:04,233 INFO L290 TraceCheckUtils]: 13: Hoare triple {8600#(and (= ~__ste_client_privateKey0~0 |old(~__ste_client_privateKey0~0)|) (= ~__ste_client_privateKey2~0 |old(~__ste_client_privateKey2~0)|) (= ~__ste_client_privateKey1~0 |old(~__ste_client_privateKey1~0)|))} ~handle := #in~handle;~value := #in~value; {8539#true} is VALID [2022-02-20 18:00:04,234 INFO L290 TraceCheckUtils]: 14: Hoare triple {8539#true} assume 1 == ~handle;~__ste_client_privateKey0~0 := ~value; {8539#true} is VALID [2022-02-20 18:00:04,234 INFO L290 TraceCheckUtils]: 15: Hoare triple {8539#true} assume true; {8539#true} is VALID [2022-02-20 18:00:04,234 INFO L284 TraceCheckUtils]: 16: Hoare quadruple {8539#true} {8539#true} #1136#return; {8539#true} is VALID [2022-02-20 18:00:04,234 INFO L290 TraceCheckUtils]: 17: Hoare triple {8539#true} assume { :end_inline_setup_bob } true;setup_~__cil_tmp1~0#1.base, setup_~__cil_tmp1~0#1.offset := 18, 0;havoc setup_#t~nondet32#1;~rjh~0 := 2;assume { :begin_inline_setup_rjh } true;setup_rjh_#in~rjh___0#1 := ~rjh~0;havoc setup_rjh_~rjh___0#1;setup_rjh_~rjh___0#1 := setup_rjh_#in~rjh___0#1;assume { :begin_inline_setup_rjh__wrappee__Base } true;setup_rjh__wrappee__Base_#in~rjh___0#1 := setup_rjh_~rjh___0#1;havoc setup_rjh__wrappee__Base_~rjh___0#1;setup_rjh__wrappee__Base_~rjh___0#1 := setup_rjh__wrappee__Base_#in~rjh___0#1; {8549#(= |ULTIMATE.start_setup_rjh__wrappee__Base_~rjh___0#1| 2)} is VALID [2022-02-20 18:00:04,235 INFO L272 TraceCheckUtils]: 18: Hoare triple {8549#(= |ULTIMATE.start_setup_rjh__wrappee__Base_~rjh___0#1| 2)} call setClientId(setup_rjh__wrappee__Base_~rjh___0#1, setup_rjh__wrappee__Base_~rjh___0#1); {8599#(and (= |old(~__ste_client_idCounter0~0)| ~__ste_client_idCounter0~0) (= |old(~__ste_client_idCounter1~0)| ~__ste_client_idCounter1~0) (= |old(~__ste_client_idCounter2~0)| ~__ste_client_idCounter2~0))} is VALID [2022-02-20 18:00:04,235 INFO L290 TraceCheckUtils]: 19: Hoare triple {8599#(and (= |old(~__ste_client_idCounter0~0)| ~__ste_client_idCounter0~0) (= |old(~__ste_client_idCounter1~0)| ~__ste_client_idCounter1~0) (= |old(~__ste_client_idCounter2~0)| ~__ste_client_idCounter2~0))} ~handle := #in~handle;~value := #in~value; {8601#(= setClientId_~handle |setClientId_#in~handle|)} is VALID [2022-02-20 18:00:04,236 INFO L290 TraceCheckUtils]: 20: Hoare triple {8601#(= setClientId_~handle |setClientId_#in~handle|)} assume 1 == ~handle;~__ste_client_idCounter0~0 := ~value; {8602#(= |setClientId_#in~handle| 1)} is VALID [2022-02-20 18:00:04,236 INFO L290 TraceCheckUtils]: 21: Hoare triple {8602#(= |setClientId_#in~handle| 1)} assume true; {8602#(= |setClientId_#in~handle| 1)} is VALID [2022-02-20 18:00:04,236 INFO L284 TraceCheckUtils]: 22: Hoare quadruple {8602#(= |setClientId_#in~handle| 1)} {8549#(= |ULTIMATE.start_setup_rjh__wrappee__Base_~rjh___0#1| 2)} #1138#return; {8540#false} is VALID [2022-02-20 18:00:04,236 INFO L290 TraceCheckUtils]: 23: Hoare triple {8540#false} assume { :end_inline_setup_rjh__wrappee__Base } true; {8540#false} is VALID [2022-02-20 18:00:04,237 INFO L272 TraceCheckUtils]: 24: Hoare triple {8540#false} call setClientPrivateKey(setup_rjh_~rjh___0#1, 456); {8600#(and (= ~__ste_client_privateKey0~0 |old(~__ste_client_privateKey0~0)|) (= ~__ste_client_privateKey2~0 |old(~__ste_client_privateKey2~0)|) (= ~__ste_client_privateKey1~0 |old(~__ste_client_privateKey1~0)|))} is VALID [2022-02-20 18:00:04,237 INFO L290 TraceCheckUtils]: 25: Hoare triple {8600#(and (= ~__ste_client_privateKey0~0 |old(~__ste_client_privateKey0~0)|) (= ~__ste_client_privateKey2~0 |old(~__ste_client_privateKey2~0)|) (= ~__ste_client_privateKey1~0 |old(~__ste_client_privateKey1~0)|))} ~handle := #in~handle;~value := #in~value; {8539#true} is VALID [2022-02-20 18:00:04,237 INFO L290 TraceCheckUtils]: 26: Hoare triple {8539#true} assume 1 == ~handle;~__ste_client_privateKey0~0 := ~value; {8539#true} is VALID [2022-02-20 18:00:04,237 INFO L290 TraceCheckUtils]: 27: Hoare triple {8539#true} assume true; {8539#true} is VALID [2022-02-20 18:00:04,237 INFO L284 TraceCheckUtils]: 28: Hoare quadruple {8539#true} {8540#false} #1140#return; {8540#false} is VALID [2022-02-20 18:00:04,237 INFO L290 TraceCheckUtils]: 29: Hoare triple {8540#false} assume { :end_inline_setup_rjh } true;setup_~__cil_tmp2~0#1.base, setup_~__cil_tmp2~0#1.offset := 19, 0;havoc setup_#t~nondet33#1;~chuck~0 := 3;assume { :begin_inline_setup_chuck } true;setup_chuck_#in~chuck___0#1 := ~chuck~0;havoc setup_chuck_~chuck___0#1;setup_chuck_~chuck___0#1 := setup_chuck_#in~chuck___0#1;assume { :begin_inline_setup_chuck__wrappee__Base } true;setup_chuck__wrappee__Base_#in~chuck___0#1 := setup_chuck_~chuck___0#1;havoc setup_chuck__wrappee__Base_~chuck___0#1;setup_chuck__wrappee__Base_~chuck___0#1 := setup_chuck__wrappee__Base_#in~chuck___0#1; {8540#false} is VALID [2022-02-20 18:00:04,237 INFO L272 TraceCheckUtils]: 30: Hoare triple {8540#false} call setClientId(setup_chuck__wrappee__Base_~chuck___0#1, setup_chuck__wrappee__Base_~chuck___0#1); {8599#(and (= |old(~__ste_client_idCounter0~0)| ~__ste_client_idCounter0~0) (= |old(~__ste_client_idCounter1~0)| ~__ste_client_idCounter1~0) (= |old(~__ste_client_idCounter2~0)| ~__ste_client_idCounter2~0))} is VALID [2022-02-20 18:00:04,237 INFO L290 TraceCheckUtils]: 31: Hoare triple {8599#(and (= |old(~__ste_client_idCounter0~0)| ~__ste_client_idCounter0~0) (= |old(~__ste_client_idCounter1~0)| ~__ste_client_idCounter1~0) (= |old(~__ste_client_idCounter2~0)| ~__ste_client_idCounter2~0))} ~handle := #in~handle;~value := #in~value; {8539#true} is VALID [2022-02-20 18:00:04,237 INFO L290 TraceCheckUtils]: 32: Hoare triple {8539#true} assume 1 == ~handle;~__ste_client_idCounter0~0 := ~value; {8539#true} is VALID [2022-02-20 18:00:04,238 INFO L290 TraceCheckUtils]: 33: Hoare triple {8539#true} assume true; {8539#true} is VALID [2022-02-20 18:00:04,238 INFO L284 TraceCheckUtils]: 34: Hoare quadruple {8539#true} {8540#false} #1142#return; {8540#false} is VALID [2022-02-20 18:00:04,238 INFO L290 TraceCheckUtils]: 35: Hoare triple {8540#false} assume { :end_inline_setup_chuck__wrappee__Base } true; {8540#false} is VALID [2022-02-20 18:00:04,238 INFO L272 TraceCheckUtils]: 36: Hoare triple {8540#false} call setClientPrivateKey(setup_chuck_~chuck___0#1, 789); {8600#(and (= ~__ste_client_privateKey0~0 |old(~__ste_client_privateKey0~0)|) (= ~__ste_client_privateKey2~0 |old(~__ste_client_privateKey2~0)|) (= ~__ste_client_privateKey1~0 |old(~__ste_client_privateKey1~0)|))} is VALID [2022-02-20 18:00:04,238 INFO L290 TraceCheckUtils]: 37: Hoare triple {8600#(and (= ~__ste_client_privateKey0~0 |old(~__ste_client_privateKey0~0)|) (= ~__ste_client_privateKey2~0 |old(~__ste_client_privateKey2~0)|) (= ~__ste_client_privateKey1~0 |old(~__ste_client_privateKey1~0)|))} ~handle := #in~handle;~value := #in~value; {8539#true} is VALID [2022-02-20 18:00:04,238 INFO L290 TraceCheckUtils]: 38: Hoare triple {8539#true} assume 1 == ~handle;~__ste_client_privateKey0~0 := ~value; {8539#true} is VALID [2022-02-20 18:00:04,238 INFO L290 TraceCheckUtils]: 39: Hoare triple {8539#true} assume true; {8539#true} is VALID [2022-02-20 18:00:04,238 INFO L284 TraceCheckUtils]: 40: Hoare quadruple {8539#true} {8540#false} #1144#return; {8540#false} is VALID [2022-02-20 18:00:04,238 INFO L290 TraceCheckUtils]: 41: Hoare triple {8540#false} assume { :end_inline_setup_chuck } true;setup_~__cil_tmp3~0#1.base, setup_~__cil_tmp3~0#1.offset := 20, 0;havoc setup_#t~nondet34#1; {8540#false} is VALID [2022-02-20 18:00:04,239 INFO L290 TraceCheckUtils]: 42: Hoare triple {8540#false} assume { :end_inline_setup } true;assume { :begin_inline_test } true;havoc test_#t~nondet47#1, test_#t~nondet48#1, test_#t~nondet49#1, test_#t~nondet50#1, test_#t~nondet51#1, test_#t~nondet52#1, test_#t~nondet53#1, test_#t~nondet54#1, test_#t~nondet55#1, test_#t~nondet56#1, test_#t~nondet57#1, test_~op1~0#1, test_~op2~0#1, test_~op3~0#1, test_~op4~0#1, test_~op5~0#1, test_~op6~0#1, test_~op7~0#1, test_~op8~0#1, test_~op9~0#1, test_~op10~0#1, test_~op11~0#1, test_~splverifierCounter~0#1, test_~tmp~6#1, test_~tmp___0~2#1, test_~tmp___1~1#1, test_~tmp___2~0#1, test_~tmp___3~0#1, test_~tmp___4~0#1, test_~tmp___5~0#1, test_~tmp___6~0#1, test_~tmp___7~0#1, test_~tmp___8~0#1, test_~tmp___9~0#1;havoc test_~op1~0#1;havoc test_~op2~0#1;havoc test_~op3~0#1;havoc test_~op4~0#1;havoc test_~op5~0#1;havoc test_~op6~0#1;havoc test_~op7~0#1;havoc test_~op8~0#1;havoc test_~op9~0#1;havoc test_~op10~0#1;havoc test_~op11~0#1;havoc test_~splverifierCounter~0#1;havoc test_~tmp~6#1;havoc test_~tmp___0~2#1;havoc test_~tmp___1~1#1;havoc test_~tmp___2~0#1;havoc test_~tmp___3~0#1;havoc test_~tmp___4~0#1;havoc test_~tmp___5~0#1;havoc test_~tmp___6~0#1;havoc test_~tmp___7~0#1;havoc test_~tmp___8~0#1;havoc test_~tmp___9~0#1;test_~op1~0#1 := 0;test_~op2~0#1 := 0;test_~op3~0#1 := 0;test_~op4~0#1 := 0;test_~op5~0#1 := 0;test_~op6~0#1 := 0;test_~op7~0#1 := 0;test_~op8~0#1 := 0;test_~op9~0#1 := 0;test_~op10~0#1 := 0;test_~op11~0#1 := 0;test_~splverifierCounter~0#1 := 0; {8540#false} is VALID [2022-02-20 18:00:04,239 INFO L290 TraceCheckUtils]: 43: Hoare triple {8540#false} assume !false; {8540#false} is VALID [2022-02-20 18:00:04,239 INFO L290 TraceCheckUtils]: 44: Hoare triple {8540#false} assume test_~splverifierCounter~0#1 < 4; {8540#false} is VALID [2022-02-20 18:00:04,239 INFO L290 TraceCheckUtils]: 45: Hoare triple {8540#false} test_~splverifierCounter~0#1 := 1 + test_~splverifierCounter~0#1; {8540#false} is VALID [2022-02-20 18:00:04,239 INFO L290 TraceCheckUtils]: 46: Hoare triple {8540#false} assume 0 == test_~op1~0#1;assume -2147483648 <= test_#t~nondet47#1 && test_#t~nondet47#1 <= 2147483647;test_~tmp___9~0#1 := test_#t~nondet47#1;havoc test_#t~nondet47#1; {8540#false} is VALID [2022-02-20 18:00:04,239 INFO L290 TraceCheckUtils]: 47: Hoare triple {8540#false} assume !(0 != test_~tmp___9~0#1); {8540#false} is VALID [2022-02-20 18:00:04,239 INFO L290 TraceCheckUtils]: 48: Hoare triple {8540#false} assume 0 == test_~op2~0#1;assume -2147483648 <= test_#t~nondet48#1 && test_#t~nondet48#1 <= 2147483647;test_~tmp___8~0#1 := test_#t~nondet48#1;havoc test_#t~nondet48#1; {8540#false} is VALID [2022-02-20 18:00:04,239 INFO L290 TraceCheckUtils]: 49: Hoare triple {8540#false} assume 0 != test_~tmp___8~0#1;assume { :begin_inline_rjhSetAutoRespond } true;assume { :begin_inline_setClientAutoResponse } true;setClientAutoResponse_#in~handle#1, setClientAutoResponse_#in~value#1 := ~rjh~0, 1;havoc setClientAutoResponse_~handle#1, setClientAutoResponse_~value#1;setClientAutoResponse_~handle#1 := setClientAutoResponse_#in~handle#1;setClientAutoResponse_~value#1 := setClientAutoResponse_#in~value#1; {8540#false} is VALID [2022-02-20 18:00:04,239 INFO L290 TraceCheckUtils]: 50: Hoare triple {8540#false} assume 1 == setClientAutoResponse_~handle#1;~__ste_client_autoResponse0~0 := setClientAutoResponse_~value#1; {8540#false} is VALID [2022-02-20 18:00:04,240 INFO L290 TraceCheckUtils]: 51: Hoare triple {8540#false} assume { :end_inline_setClientAutoResponse } true; {8540#false} is VALID [2022-02-20 18:00:04,240 INFO L290 TraceCheckUtils]: 52: Hoare triple {8540#false} assume { :end_inline_rjhSetAutoRespond } true;test_~op2~0#1 := 1; {8540#false} is VALID [2022-02-20 18:00:04,240 INFO L290 TraceCheckUtils]: 53: Hoare triple {8540#false} assume !false; {8540#false} is VALID [2022-02-20 18:00:04,240 INFO L290 TraceCheckUtils]: 54: Hoare triple {8540#false} assume !(test_~splverifierCounter~0#1 < 4); {8540#false} is VALID [2022-02-20 18:00:04,240 INFO L290 TraceCheckUtils]: 55: Hoare triple {8540#false} assume { :begin_inline_bobToRjh } true;havoc bobToRjh_#t~ret27#1, bobToRjh_#t~ret28#1, bobToRjh_#t~ret29#1, bobToRjh_#t~ret30#1, bobToRjh_~tmp~3#1, bobToRjh_~tmp___0~0#1, bobToRjh_~tmp___1~0#1;havoc bobToRjh_~tmp~3#1;havoc bobToRjh_~tmp___0~0#1;havoc bobToRjh_~tmp___1~0#1;call bobToRjh_#t~ret27#1 := puts(16, 0);assume -2147483648 <= bobToRjh_#t~ret27#1 && bobToRjh_#t~ret27#1 <= 2147483647;havoc bobToRjh_#t~ret27#1; {8540#false} is VALID [2022-02-20 18:00:04,240 INFO L272 TraceCheckUtils]: 56: Hoare triple {8540#false} call sendEmail(~bob~0, ~rjh~0); {8540#false} is VALID [2022-02-20 18:00:04,240 INFO L290 TraceCheckUtils]: 57: Hoare triple {8540#false} ~sender#1 := #in~sender#1;~receiver#1 := #in~receiver#1;havoc ~email~0#1;havoc ~tmp~14#1;assume { :begin_inline_createEmail } true;createEmail_#in~from#1, createEmail_#in~to#1 := 0, ~receiver#1;havoc createEmail_#res#1;havoc createEmail_~from#1, createEmail_~to#1, createEmail_~retValue_acc~31#1, createEmail_~msg~0#1;createEmail_~from#1 := createEmail_#in~from#1;createEmail_~to#1 := createEmail_#in~to#1;havoc createEmail_~retValue_acc~31#1;havoc createEmail_~msg~0#1;createEmail_~msg~0#1 := 1; {8540#false} is VALID [2022-02-20 18:00:04,240 INFO L272 TraceCheckUtils]: 58: Hoare triple {8540#false} call setEmailFrom(createEmail_~msg~0#1, createEmail_~from#1); {8603#(and (= |old(~__ste_email_from0~0)| ~__ste_email_from0~0) (= |old(~__ste_email_from1~0)| ~__ste_email_from1~0))} is VALID [2022-02-20 18:00:04,240 INFO L290 TraceCheckUtils]: 59: Hoare triple {8603#(and (= |old(~__ste_email_from0~0)| ~__ste_email_from0~0) (= |old(~__ste_email_from1~0)| ~__ste_email_from1~0))} ~handle := #in~handle;~value := #in~value; {8539#true} is VALID [2022-02-20 18:00:04,241 INFO L290 TraceCheckUtils]: 60: Hoare triple {8539#true} assume 1 == ~handle;~__ste_email_from0~0 := ~value; {8539#true} is VALID [2022-02-20 18:00:04,241 INFO L290 TraceCheckUtils]: 61: Hoare triple {8539#true} assume true; {8539#true} is VALID [2022-02-20 18:00:04,241 INFO L284 TraceCheckUtils]: 62: Hoare quadruple {8539#true} {8540#false} #1120#return; {8540#false} is VALID [2022-02-20 18:00:04,241 INFO L272 TraceCheckUtils]: 63: Hoare triple {8540#false} call setEmailTo(createEmail_~msg~0#1, createEmail_~to#1); {8604#(and (= ~__ste_email_to0~0 |old(~__ste_email_to0~0)|) (= ~__ste_email_to1~0 |old(~__ste_email_to1~0)|))} is VALID [2022-02-20 18:00:04,241 INFO L290 TraceCheckUtils]: 64: Hoare triple {8604#(and (= ~__ste_email_to0~0 |old(~__ste_email_to0~0)|) (= ~__ste_email_to1~0 |old(~__ste_email_to1~0)|))} ~handle := #in~handle;~value := #in~value; {8539#true} is VALID [2022-02-20 18:00:04,241 INFO L290 TraceCheckUtils]: 65: Hoare triple {8539#true} assume 1 == ~handle;~__ste_email_to0~0 := ~value; {8539#true} is VALID [2022-02-20 18:00:04,241 INFO L290 TraceCheckUtils]: 66: Hoare triple {8539#true} assume true; {8539#true} is VALID [2022-02-20 18:00:04,241 INFO L284 TraceCheckUtils]: 67: Hoare quadruple {8539#true} {8540#false} #1122#return; {8540#false} is VALID [2022-02-20 18:00:04,241 INFO L290 TraceCheckUtils]: 68: Hoare triple {8540#false} createEmail_~retValue_acc~31#1 := createEmail_~msg~0#1;createEmail_#res#1 := createEmail_~retValue_acc~31#1; {8540#false} is VALID [2022-02-20 18:00:04,242 INFO L290 TraceCheckUtils]: 69: Hoare triple {8540#false} #t~ret72#1 := createEmail_#res#1;assume { :end_inline_createEmail } true;assume -2147483648 <= #t~ret72#1 && #t~ret72#1 <= 2147483647;~tmp~14#1 := #t~ret72#1;havoc #t~ret72#1;~email~0#1 := ~tmp~14#1; {8540#false} is VALID [2022-02-20 18:00:04,242 INFO L272 TraceCheckUtils]: 70: Hoare triple {8540#false} call outgoing(~sender#1, ~email~0#1); {8540#false} is VALID [2022-02-20 18:00:04,242 INFO L290 TraceCheckUtils]: 71: Hoare triple {8540#false} ~client#1 := #in~client#1;~msg#1 := #in~msg#1;assume { :begin_inline_sign } true;sign_#in~client#1, sign_#in~msg#1 := ~client#1, ~msg#1;havoc sign_#t~ret76#1, sign_~client#1, sign_~msg#1, sign_~privkey~1#1, sign_~tmp~16#1;sign_~client#1 := sign_#in~client#1;sign_~msg#1 := sign_#in~msg#1;havoc sign_~privkey~1#1;havoc sign_~tmp~16#1; {8540#false} is VALID [2022-02-20 18:00:04,242 INFO L272 TraceCheckUtils]: 72: Hoare triple {8540#false} call sign_#t~ret76#1 := getClientPrivateKey(sign_~client#1); {8539#true} is VALID [2022-02-20 18:00:04,242 INFO L290 TraceCheckUtils]: 73: Hoare triple {8539#true} ~handle := #in~handle;havoc ~retValue_acc~20; {8539#true} is VALID [2022-02-20 18:00:04,242 INFO L290 TraceCheckUtils]: 74: Hoare triple {8539#true} assume 1 == ~handle;~retValue_acc~20 := ~__ste_client_privateKey0~0;#res := ~retValue_acc~20; {8539#true} is VALID [2022-02-20 18:00:04,242 INFO L290 TraceCheckUtils]: 75: Hoare triple {8539#true} assume true; {8539#true} is VALID [2022-02-20 18:00:04,242 INFO L284 TraceCheckUtils]: 76: Hoare quadruple {8539#true} {8540#false} #1054#return; {8540#false} is VALID [2022-02-20 18:00:04,242 INFO L290 TraceCheckUtils]: 77: Hoare triple {8540#false} assume -2147483648 <= sign_#t~ret76#1 && sign_#t~ret76#1 <= 2147483647;sign_~tmp~16#1 := sign_#t~ret76#1;havoc sign_#t~ret76#1;sign_~privkey~1#1 := sign_~tmp~16#1; {8540#false} is VALID [2022-02-20 18:00:04,242 INFO L290 TraceCheckUtils]: 78: Hoare triple {8540#false} assume 0 == sign_~privkey~1#1; {8540#false} is VALID [2022-02-20 18:00:04,243 INFO L290 TraceCheckUtils]: 79: Hoare triple {8540#false} assume { :end_inline_sign } true;assume { :begin_inline_outgoing__wrappee__AutoResponder } true;outgoing__wrappee__AutoResponder_#in~client#1, outgoing__wrappee__AutoResponder_#in~msg#1 := ~client#1, ~msg#1;havoc outgoing__wrappee__AutoResponder_#t~ret62#1, outgoing__wrappee__AutoResponder_#t~ret63#1, outgoing__wrappee__AutoResponder_~client#1, outgoing__wrappee__AutoResponder_~msg#1, outgoing__wrappee__AutoResponder_~receiver~0#1, outgoing__wrappee__AutoResponder_~tmp~9#1, outgoing__wrappee__AutoResponder_~pubkey~0#1, outgoing__wrappee__AutoResponder_~tmp___0~3#1;outgoing__wrappee__AutoResponder_~client#1 := outgoing__wrappee__AutoResponder_#in~client#1;outgoing__wrappee__AutoResponder_~msg#1 := outgoing__wrappee__AutoResponder_#in~msg#1;havoc outgoing__wrappee__AutoResponder_~receiver~0#1;havoc outgoing__wrappee__AutoResponder_~tmp~9#1;havoc outgoing__wrappee__AutoResponder_~pubkey~0#1;havoc outgoing__wrappee__AutoResponder_~tmp___0~3#1; {8540#false} is VALID [2022-02-20 18:00:04,243 INFO L272 TraceCheckUtils]: 80: Hoare triple {8540#false} call outgoing__wrappee__AutoResponder_#t~ret62#1 := getEmailTo(outgoing__wrappee__AutoResponder_~msg#1); {8539#true} is VALID [2022-02-20 18:00:04,243 INFO L290 TraceCheckUtils]: 81: Hoare triple {8539#true} ~handle := #in~handle;havoc ~retValue_acc~36; {8539#true} is VALID [2022-02-20 18:00:04,243 INFO L290 TraceCheckUtils]: 82: Hoare triple {8539#true} assume 1 == ~handle;~retValue_acc~36 := ~__ste_email_to0~0;#res := ~retValue_acc~36; {8539#true} is VALID [2022-02-20 18:00:04,243 INFO L290 TraceCheckUtils]: 83: Hoare triple {8539#true} assume true; {8539#true} is VALID [2022-02-20 18:00:04,243 INFO L284 TraceCheckUtils]: 84: Hoare quadruple {8539#true} {8540#false} #1056#return; {8540#false} is VALID [2022-02-20 18:00:04,243 INFO L290 TraceCheckUtils]: 85: Hoare triple {8540#false} assume -2147483648 <= outgoing__wrappee__AutoResponder_#t~ret62#1 && outgoing__wrappee__AutoResponder_#t~ret62#1 <= 2147483647;outgoing__wrappee__AutoResponder_~tmp~9#1 := outgoing__wrappee__AutoResponder_#t~ret62#1;havoc outgoing__wrappee__AutoResponder_#t~ret62#1;outgoing__wrappee__AutoResponder_~receiver~0#1 := outgoing__wrappee__AutoResponder_~tmp~9#1; {8540#false} is VALID [2022-02-20 18:00:04,243 INFO L272 TraceCheckUtils]: 86: Hoare triple {8540#false} call outgoing__wrappee__AutoResponder_#t~ret63#1 := findPublicKey(outgoing__wrappee__AutoResponder_~client#1, outgoing__wrappee__AutoResponder_~receiver~0#1); {8539#true} is VALID [2022-02-20 18:00:04,243 INFO L290 TraceCheckUtils]: 87: Hoare triple {8539#true} ~handle := #in~handle;~userid := #in~userid;havoc ~retValue_acc~25; {8539#true} is VALID [2022-02-20 18:00:04,244 INFO L290 TraceCheckUtils]: 88: Hoare triple {8539#true} assume 1 == ~handle; {8539#true} is VALID [2022-02-20 18:00:04,244 INFO L290 TraceCheckUtils]: 89: Hoare triple {8539#true} assume ~userid == ~__ste_Client_Keyring0_User0~0;~retValue_acc~25 := ~__ste_Client_Keyring0_PublicKey0~0;#res := ~retValue_acc~25; {8539#true} is VALID [2022-02-20 18:00:04,244 INFO L290 TraceCheckUtils]: 90: Hoare triple {8539#true} assume true; {8539#true} is VALID [2022-02-20 18:00:04,244 INFO L284 TraceCheckUtils]: 91: Hoare quadruple {8539#true} {8540#false} #1058#return; {8540#false} is VALID [2022-02-20 18:00:04,244 INFO L290 TraceCheckUtils]: 92: Hoare triple {8540#false} assume -2147483648 <= outgoing__wrappee__AutoResponder_#t~ret63#1 && outgoing__wrappee__AutoResponder_#t~ret63#1 <= 2147483647;outgoing__wrappee__AutoResponder_~tmp___0~3#1 := outgoing__wrappee__AutoResponder_#t~ret63#1;havoc outgoing__wrappee__AutoResponder_#t~ret63#1;outgoing__wrappee__AutoResponder_~pubkey~0#1 := outgoing__wrappee__AutoResponder_~tmp___0~3#1; {8540#false} is VALID [2022-02-20 18:00:04,244 INFO L290 TraceCheckUtils]: 93: Hoare triple {8540#false} assume !(0 != outgoing__wrappee__AutoResponder_~pubkey~0#1); {8540#false} is VALID [2022-02-20 18:00:04,244 INFO L290 TraceCheckUtils]: 94: Hoare triple {8540#false} assume { :begin_inline_outgoing__wrappee__Keys } true;outgoing__wrappee__Keys_#in~client#1, outgoing__wrappee__Keys_#in~msg#1 := outgoing__wrappee__AutoResponder_~client#1, outgoing__wrappee__AutoResponder_~msg#1;havoc outgoing__wrappee__Keys_#t~ret61#1, outgoing__wrappee__Keys_~client#1, outgoing__wrappee__Keys_~msg#1, outgoing__wrappee__Keys_~tmp~8#1;outgoing__wrappee__Keys_~client#1 := outgoing__wrappee__Keys_#in~client#1;outgoing__wrappee__Keys_~msg#1 := outgoing__wrappee__Keys_#in~msg#1;havoc outgoing__wrappee__Keys_~tmp~8#1;assume { :begin_inline_getClientId } true;getClientId_#in~handle#1 := outgoing__wrappee__Keys_~client#1;havoc getClientId_#res#1;havoc getClientId_~handle#1, getClientId_~retValue_acc~27#1;getClientId_~handle#1 := getClientId_#in~handle#1;havoc getClientId_~retValue_acc~27#1; {8540#false} is VALID [2022-02-20 18:00:04,244 INFO L290 TraceCheckUtils]: 95: Hoare triple {8540#false} assume 1 == getClientId_~handle#1;getClientId_~retValue_acc~27#1 := ~__ste_client_idCounter0~0;getClientId_#res#1 := getClientId_~retValue_acc~27#1; {8540#false} is VALID [2022-02-20 18:00:04,244 INFO L290 TraceCheckUtils]: 96: Hoare triple {8540#false} outgoing__wrappee__Keys_#t~ret61#1 := getClientId_#res#1;assume { :end_inline_getClientId } true;assume -2147483648 <= outgoing__wrappee__Keys_#t~ret61#1 && outgoing__wrappee__Keys_#t~ret61#1 <= 2147483647;outgoing__wrappee__Keys_~tmp~8#1 := outgoing__wrappee__Keys_#t~ret61#1;havoc outgoing__wrappee__Keys_#t~ret61#1; {8540#false} is VALID [2022-02-20 18:00:04,245 INFO L272 TraceCheckUtils]: 97: Hoare triple {8540#false} call setEmailFrom(outgoing__wrappee__Keys_~msg#1, outgoing__wrappee__Keys_~tmp~8#1); {8603#(and (= |old(~__ste_email_from0~0)| ~__ste_email_from0~0) (= |old(~__ste_email_from1~0)| ~__ste_email_from1~0))} is VALID [2022-02-20 18:00:04,245 INFO L290 TraceCheckUtils]: 98: Hoare triple {8603#(and (= |old(~__ste_email_from0~0)| ~__ste_email_from0~0) (= |old(~__ste_email_from1~0)| ~__ste_email_from1~0))} ~handle := #in~handle;~value := #in~value; {8539#true} is VALID [2022-02-20 18:00:04,245 INFO L290 TraceCheckUtils]: 99: Hoare triple {8539#true} assume 1 == ~handle;~__ste_email_from0~0 := ~value; {8539#true} is VALID [2022-02-20 18:00:04,245 INFO L290 TraceCheckUtils]: 100: Hoare triple {8539#true} assume true; {8539#true} is VALID [2022-02-20 18:00:04,245 INFO L284 TraceCheckUtils]: 101: Hoare quadruple {8539#true} {8540#false} #1064#return; {8540#false} is VALID [2022-02-20 18:00:04,245 INFO L290 TraceCheckUtils]: 102: Hoare triple {8540#false} assume { :begin_inline_mail } true;mail_#in~client#1, mail_#in~msg#1 := outgoing__wrappee__Keys_~client#1, outgoing__wrappee__Keys_~msg#1;havoc mail_#t~ret59#1, mail_#t~ret60#1, mail_~client#1, mail_~msg#1, mail_~__utac__ad__arg1~0#1, mail_~__utac__ad__arg2~0#1, mail_~tmp~7#1;mail_~client#1 := mail_#in~client#1;mail_~msg#1 := mail_#in~msg#1;havoc mail_~__utac__ad__arg1~0#1;havoc mail_~__utac__ad__arg2~0#1;havoc mail_~tmp~7#1;mail_~__utac__ad__arg1~0#1 := mail_~client#1;mail_~__utac__ad__arg2~0#1 := mail_~msg#1;assume { :begin_inline___utac_acc__SignForward_spec__1 } true;__utac_acc__SignForward_spec__1_#in~client#1, __utac_acc__SignForward_spec__1_#in~msg#1 := mail_~__utac__ad__arg1~0#1, mail_~__utac__ad__arg2~0#1;havoc __utac_acc__SignForward_spec__1_#t~ret107#1, __utac_acc__SignForward_spec__1_#t~ret108#1, __utac_acc__SignForward_spec__1_#t~ret109#1, __utac_acc__SignForward_spec__1_~client#1, __utac_acc__SignForward_spec__1_~msg#1, __utac_acc__SignForward_spec__1_~tmp~25#1, __utac_acc__SignForward_spec__1_~tmp___0~9#1;__utac_acc__SignForward_spec__1_~client#1 := __utac_acc__SignForward_spec__1_#in~client#1;__utac_acc__SignForward_spec__1_~msg#1 := __utac_acc__SignForward_spec__1_#in~msg#1;havoc __utac_acc__SignForward_spec__1_~tmp~25#1;havoc __utac_acc__SignForward_spec__1_~tmp___0~9#1;call __utac_acc__SignForward_spec__1_#t~ret107#1 := puts(39, 0);assume -2147483648 <= __utac_acc__SignForward_spec__1_#t~ret107#1 && __utac_acc__SignForward_spec__1_#t~ret107#1 <= 2147483647;havoc __utac_acc__SignForward_spec__1_#t~ret107#1; {8540#false} is VALID [2022-02-20 18:00:04,245 INFO L272 TraceCheckUtils]: 103: Hoare triple {8540#false} call __utac_acc__SignForward_spec__1_#t~ret108#1 := isSigned(__utac_acc__SignForward_spec__1_~msg#1); {8539#true} is VALID [2022-02-20 18:00:04,245 INFO L290 TraceCheckUtils]: 104: Hoare triple {8539#true} ~handle := #in~handle;havoc ~retValue_acc~41; {8539#true} is VALID [2022-02-20 18:00:04,245 INFO L290 TraceCheckUtils]: 105: Hoare triple {8539#true} assume 1 == ~handle;~retValue_acc~41 := ~__ste_email_isSigned0~0;#res := ~retValue_acc~41; {8539#true} is VALID [2022-02-20 18:00:04,246 INFO L290 TraceCheckUtils]: 106: Hoare triple {8539#true} assume true; {8539#true} is VALID [2022-02-20 18:00:04,246 INFO L284 TraceCheckUtils]: 107: Hoare quadruple {8539#true} {8540#false} #1066#return; {8540#false} is VALID [2022-02-20 18:00:04,246 INFO L290 TraceCheckUtils]: 108: Hoare triple {8540#false} assume -2147483648 <= __utac_acc__SignForward_spec__1_#t~ret108#1 && __utac_acc__SignForward_spec__1_#t~ret108#1 <= 2147483647;__utac_acc__SignForward_spec__1_~tmp___0~9#1 := __utac_acc__SignForward_spec__1_#t~ret108#1;havoc __utac_acc__SignForward_spec__1_#t~ret108#1; {8540#false} is VALID [2022-02-20 18:00:04,246 INFO L290 TraceCheckUtils]: 109: Hoare triple {8540#false} assume 0 != __utac_acc__SignForward_spec__1_~tmp___0~9#1; {8540#false} is VALID [2022-02-20 18:00:04,246 INFO L272 TraceCheckUtils]: 110: Hoare triple {8540#false} call __utac_acc__SignForward_spec__1_#t~ret109#1 := getClientPrivateKey(__utac_acc__SignForward_spec__1_~client#1); {8539#true} is VALID [2022-02-20 18:00:04,246 INFO L290 TraceCheckUtils]: 111: Hoare triple {8539#true} ~handle := #in~handle;havoc ~retValue_acc~20; {8539#true} is VALID [2022-02-20 18:00:04,246 INFO L290 TraceCheckUtils]: 112: Hoare triple {8539#true} assume 1 == ~handle;~retValue_acc~20 := ~__ste_client_privateKey0~0;#res := ~retValue_acc~20; {8539#true} is VALID [2022-02-20 18:00:04,246 INFO L290 TraceCheckUtils]: 113: Hoare triple {8539#true} assume true; {8539#true} is VALID [2022-02-20 18:00:04,246 INFO L284 TraceCheckUtils]: 114: Hoare quadruple {8539#true} {8540#false} #1068#return; {8540#false} is VALID [2022-02-20 18:00:04,246 INFO L290 TraceCheckUtils]: 115: Hoare triple {8540#false} assume -2147483648 <= __utac_acc__SignForward_spec__1_#t~ret109#1 && __utac_acc__SignForward_spec__1_#t~ret109#1 <= 2147483647;__utac_acc__SignForward_spec__1_~tmp~25#1 := __utac_acc__SignForward_spec__1_#t~ret109#1;havoc __utac_acc__SignForward_spec__1_#t~ret109#1; {8540#false} is VALID [2022-02-20 18:00:04,247 INFO L290 TraceCheckUtils]: 116: Hoare triple {8540#false} assume 0 == __utac_acc__SignForward_spec__1_~tmp~25#1;assume { :begin_inline___automaton_fail } true; {8540#false} is VALID [2022-02-20 18:00:04,247 INFO L290 TraceCheckUtils]: 117: Hoare triple {8540#false} assume !false; {8540#false} is VALID [2022-02-20 18:00:04,247 INFO L134 CoverageAnalysis]: Checked inductivity of 34 backedges. 3 proven. 3 refuted. 0 times theorem prover too weak. 28 trivial. 0 not checked. [2022-02-20 18:00:04,247 INFO L144 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2022-02-20 18:00:04,247 INFO L338 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [1119638945] [2022-02-20 18:00:04,248 INFO L165 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [1119638945] provided 0 perfect and 1 imperfect interpolant sequences [2022-02-20 18:00:04,248 INFO L338 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleZ3 [362626083] [2022-02-20 18:00:04,248 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-02-20 18:00:04,248 INFO L173 SolverBuilder]: Constructing external solver with command: z3 -smt2 -in SMTLIB2_COMPLIANT=true [2022-02-20 18:00:04,248 INFO L189 MonitoredProcess]: No working directory specified, using /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 [2022-02-20 18:00:04,264 INFO L229 MonitoredProcess]: Starting monitored process 5 with /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 -smt2 -in SMTLIB2_COMPLIANT=true (exit command is (exit), workingDir is null) [2022-02-20 18:00:04,337 INFO L327 MonitoredProcess]: [MP /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 -smt2 -in SMTLIB2_COMPLIANT=true (5)] Waiting until timeout for monitored process [2022-02-20 18:00:04,524 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-02-20 18:00:04,528 INFO L263 TraceCheckSpWp]: Trace formula consists of 1100 conjuncts, 8 conjunts are in the unsatisfiable core [2022-02-20 18:00:04,576 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-02-20 18:00:04,578 INFO L286 TraceCheckSpWp]: Computing forward predicates... [2022-02-20 18:00:04,891 INFO L290 TraceCheckUtils]: 0: Hoare triple {8539#true} assume { :begin_inline_ULTIMATE.init } true;#NULL.base, #NULL.offset := 0, 0;assume 0 == #valid[0];assume 0 < #StackHeapBarrier;call #Ultimate.allocInit(2, 1);call write~init~int(48, 1, 0, 1);call write~init~int(0, 1, 1, 1);call #Ultimate.allocInit(28, 2);call #Ultimate.allocInit(12, 3);call #Ultimate.allocInit(30, 4);call #Ultimate.allocInit(9, 5);call #Ultimate.allocInit(21, 6);call #Ultimate.allocInit(30, 7);call #Ultimate.allocInit(9, 8);call #Ultimate.allocInit(21, 9);call #Ultimate.allocInit(30, 10);call #Ultimate.allocInit(9, 11);call #Ultimate.allocInit(25, 12);call #Ultimate.allocInit(30, 13);call #Ultimate.allocInit(9, 14);call #Ultimate.allocInit(25, 15);call #Ultimate.allocInit(44, 16);call #Ultimate.allocInit(44, 17);call #Ultimate.allocInit(9, 18);call #Ultimate.allocInit(9, 19);call #Ultimate.allocInit(11, 20);call #Ultimate.allocInit(19, 21);call #Ultimate.allocInit(4, 22);call write~init~int(37, 22, 0, 1);call write~init~int(100, 22, 1, 1);call write~init~int(10, 22, 2, 1);call write~init~int(0, 22, 3, 1);call #Ultimate.allocInit(4, 23);call write~init~int(37, 23, 0, 1);call write~init~int(100, 23, 1, 1);call write~init~int(10, 23, 2, 1);call write~init~int(0, 23, 3, 1);call #Ultimate.allocInit(10, 24);call #Ultimate.allocInit(16, 25);call #Ultimate.allocInit(20, 26);call #Ultimate.allocInit(22, 27);call #Ultimate.allocInit(21, 28);call #Ultimate.allocInit(10, 29);call #Ultimate.allocInit(12, 30);call #Ultimate.allocInit(10, 31);call #Ultimate.allocInit(18, 32);call #Ultimate.allocInit(16, 33);call #Ultimate.allocInit(21, 34);call #Ultimate.allocInit(13, 35);call #Ultimate.allocInit(16, 36);call #Ultimate.allocInit(25, 37);call #Ultimate.allocInit(4, 38);call write~init~int(37, 38, 0, 1);call write~init~int(115, 38, 1, 1);call write~init~int(10, 38, 2, 1);call write~init~int(0, 38, 3, 1);call #Ultimate.allocInit(13, 39);~head~0.base, ~head~0.offset := 0, 0;~__SELECTED_FEATURE_Base~0 := 0;~__SELECTED_FEATURE_Keys~0 := 0;~__SELECTED_FEATURE_Encrypt~0 := 0;~__SELECTED_FEATURE_AutoResponder~0 := 0;~__SELECTED_FEATURE_AddressBook~0 := 0;~__SELECTED_FEATURE_Sign~0 := 0;~__SELECTED_FEATURE_Forward~0 := 0;~__SELECTED_FEATURE_Verify~0 := 0;~__SELECTED_FEATURE_Decrypt~0 := 0;~__GUIDSL_ROOT_PRODUCTION~0 := 0;~__GUIDSL_NON_TERMINAL_main~0 := 0;~bob~0 := 0;~rjh~0 := 0;~chuck~0 := 0;~queue_empty~0 := 1;~queued_message~0 := 0;~queued_client~0 := 0;~__ste_Client_counter~0 := 0;~__ste_client_name0~0.base, ~__ste_client_name0~0.offset := 0, 0;~__ste_client_name1~0.base, ~__ste_client_name1~0.offset := 0, 0;~__ste_client_name2~0.base, ~__ste_client_name2~0.offset := 0, 0;~__ste_client_outbuffer0~0 := 0;~__ste_client_outbuffer1~0 := 0;~__ste_client_outbuffer2~0 := 0;~__ste_client_outbuffer3~0 := 0;~__ste_ClientAddressBook_size0~0 := 0;~__ste_ClientAddressBook_size1~0 := 0;~__ste_ClientAddressBook_size2~0 := 0;~__ste_Client_AddressBook0_Alias0~0 := 0;~__ste_Client_AddressBook0_Alias1~0 := 0;~__ste_Client_AddressBook0_Alias2~0 := 0;~__ste_Client_AddressBook1_Alias0~0 := 0;~__ste_Client_AddressBook1_Alias1~0 := 0;~__ste_Client_AddressBook1_Alias2~0 := 0;~__ste_Client_AddressBook2_Alias0~0 := 0;~__ste_Client_AddressBook2_Alias1~0 := 0;~__ste_Client_AddressBook2_Alias2~0 := 0;~__ste_Client_AddressBook0_Address0~0 := 0;~__ste_Client_AddressBook0_Address1~0 := 0;~__ste_Client_AddressBook0_Address2~0 := 0;~__ste_Client_AddressBook1_Address0~0 := 0;~__ste_Client_AddressBook1_Address1~0 := 0;~__ste_Client_AddressBook1_Address2~0 := 0;~__ste_Client_AddressBook2_Address0~0 := 0;~__ste_Client_AddressBook2_Address1~0 := 0;~__ste_Client_AddressBook2_Address2~0 := 0;~__ste_client_autoResponse0~0 := 0;~__ste_client_autoResponse1~0 := 0;~__ste_client_autoResponse2~0 := 0;~__ste_client_privateKey0~0 := 0;~__ste_client_privateKey1~0 := 0;~__ste_client_privateKey2~0 := 0;~__ste_ClientKeyring_size0~0 := 0;~__ste_ClientKeyring_size1~0 := 0;~__ste_ClientKeyring_size2~0 := 0;~__ste_Client_Keyring0_User0~0 := 0;~__ste_Client_Keyring0_User1~0 := 0;~__ste_Client_Keyring0_User2~0 := 0;~__ste_Client_Keyring1_User0~0 := 0;~__ste_Client_Keyring1_User1~0 := 0;~__ste_Client_Keyring1_User2~0 := 0;~__ste_Client_Keyring2_User0~0 := 0;~__ste_Client_Keyring2_User1~0 := 0;~__ste_Client_Keyring2_User2~0 := 0;~__ste_Client_Keyring0_PublicKey0~0 := 0;~__ste_Client_Keyring0_PublicKey1~0 := 0;~__ste_Client_Keyring0_PublicKey2~0 := 0;~__ste_Client_Keyring1_PublicKey0~0 := 0;~__ste_Client_Keyring1_PublicKey1~0 := 0;~__ste_Client_Keyring1_PublicKey2~0 := 0;~__ste_Client_Keyring2_PublicKey0~0 := 0;~__ste_Client_Keyring2_PublicKey1~0 := 0;~__ste_Client_Keyring2_PublicKey2~0 := 0;~__ste_client_forwardReceiver0~0 := 0;~__ste_client_forwardReceiver1~0 := 0;~__ste_client_forwardReceiver2~0 := 0;~__ste_client_forwardReceiver3~0 := 0;~__ste_client_idCounter0~0 := 0;~__ste_client_idCounter1~0 := 0;~__ste_client_idCounter2~0 := 0;~__ste_Email_counter~0 := 0;~__ste_email_id0~0 := 0;~__ste_email_id1~0 := 0;~__ste_email_from0~0 := 0;~__ste_email_from1~0 := 0;~__ste_email_to0~0 := 0;~__ste_email_to1~0 := 0;~__ste_email_subject0~0.base, ~__ste_email_subject0~0.offset := 0, 0;~__ste_email_subject1~0.base, ~__ste_email_subject1~0.offset := 0, 0;~__ste_email_body0~0.base, ~__ste_email_body0~0.offset := 0, 0;~__ste_email_body1~0.base, ~__ste_email_body1~0.offset := 0, 0;~__ste_email_isEncrypted0~0 := 0;~__ste_email_isEncrypted1~0 := 0;~__ste_email_encryptionKey0~0 := 0;~__ste_email_encryptionKey1~0 := 0;~__ste_email_isSigned0~0 := 0;~__ste_email_isSigned1~0 := 0;~__ste_email_signKey0~0 := 0;~__ste_email_signKey1~0 := 0;~__ste_email_isSignatureVerified0~0 := 0;~__ste_email_isSignatureVerified1~0 := 0; {8539#true} is VALID [2022-02-20 18:00:04,892 INFO L290 TraceCheckUtils]: 1: Hoare triple {8539#true} assume { :end_inline_ULTIMATE.init } true;assume { :begin_inline_main } true;havoc main_#res#1;havoc main_#t~ret35#1, main_~retValue_acc~3#1, main_~tmp~4#1;havoc main_~retValue_acc~3#1;havoc main_~tmp~4#1;assume { :begin_inline_select_helpers } true; {8539#true} is VALID [2022-02-20 18:00:04,892 INFO L290 TraceCheckUtils]: 2: Hoare triple {8539#true} assume { :end_inline_select_helpers } true;assume { :begin_inline_select_features } true; {8539#true} is VALID [2022-02-20 18:00:04,892 INFO L290 TraceCheckUtils]: 3: Hoare triple {8539#true} assume { :end_inline_select_features } true;assume { :begin_inline_valid_product } true;havoc valid_product_#res#1;havoc valid_product_~retValue_acc~5#1;havoc valid_product_~retValue_acc~5#1;valid_product_~retValue_acc~5#1 := 1;valid_product_#res#1 := valid_product_~retValue_acc~5#1; {8539#true} is VALID [2022-02-20 18:00:04,892 INFO L290 TraceCheckUtils]: 4: Hoare triple {8539#true} main_#t~ret35#1 := valid_product_#res#1;assume { :end_inline_valid_product } true;assume -2147483648 <= main_#t~ret35#1 && main_#t~ret35#1 <= 2147483647;main_~tmp~4#1 := main_#t~ret35#1;havoc main_#t~ret35#1; {8539#true} is VALID [2022-02-20 18:00:04,892 INFO L290 TraceCheckUtils]: 5: Hoare triple {8539#true} assume 0 != main_~tmp~4#1;assume { :begin_inline_setup } true;havoc setup_#t~nondet32#1, setup_#t~nondet33#1, setup_#t~nondet34#1, setup_~__cil_tmp1~0#1.base, setup_~__cil_tmp1~0#1.offset, setup_~__cil_tmp2~0#1.base, setup_~__cil_tmp2~0#1.offset, setup_~__cil_tmp3~0#1.base, setup_~__cil_tmp3~0#1.offset;havoc setup_~__cil_tmp1~0#1.base, setup_~__cil_tmp1~0#1.offset;havoc setup_~__cil_tmp2~0#1.base, setup_~__cil_tmp2~0#1.offset;havoc setup_~__cil_tmp3~0#1.base, setup_~__cil_tmp3~0#1.offset;~bob~0 := 1;assume { :begin_inline_setup_bob } true;setup_bob_#in~bob___0#1 := ~bob~0;havoc setup_bob_~bob___0#1;setup_bob_~bob___0#1 := setup_bob_#in~bob___0#1;assume { :begin_inline_setup_bob__wrappee__Base } true;setup_bob__wrappee__Base_#in~bob___0#1 := setup_bob_~bob___0#1;havoc setup_bob__wrappee__Base_~bob___0#1;setup_bob__wrappee__Base_~bob___0#1 := setup_bob__wrappee__Base_#in~bob___0#1; {8539#true} is VALID [2022-02-20 18:00:04,892 INFO L272 TraceCheckUtils]: 6: Hoare triple {8539#true} call setClientId(setup_bob__wrappee__Base_~bob___0#1, setup_bob__wrappee__Base_~bob___0#1); {8539#true} is VALID [2022-02-20 18:00:04,892 INFO L290 TraceCheckUtils]: 7: Hoare triple {8539#true} ~handle := #in~handle;~value := #in~value; {8539#true} is VALID [2022-02-20 18:00:04,893 INFO L290 TraceCheckUtils]: 8: Hoare triple {8539#true} assume 1 == ~handle;~__ste_client_idCounter0~0 := ~value; {8539#true} is VALID [2022-02-20 18:00:04,893 INFO L290 TraceCheckUtils]: 9: Hoare triple {8539#true} assume true; {8539#true} is VALID [2022-02-20 18:00:04,893 INFO L284 TraceCheckUtils]: 10: Hoare quadruple {8539#true} {8539#true} #1134#return; {8539#true} is VALID [2022-02-20 18:00:04,893 INFO L290 TraceCheckUtils]: 11: Hoare triple {8539#true} assume { :end_inline_setup_bob__wrappee__Base } true; {8539#true} is VALID [2022-02-20 18:00:04,893 INFO L272 TraceCheckUtils]: 12: Hoare triple {8539#true} call setClientPrivateKey(setup_bob_~bob___0#1, 123); {8539#true} is VALID [2022-02-20 18:00:04,893 INFO L290 TraceCheckUtils]: 13: Hoare triple {8539#true} ~handle := #in~handle;~value := #in~value; {8539#true} is VALID [2022-02-20 18:00:04,893 INFO L290 TraceCheckUtils]: 14: Hoare triple {8539#true} assume 1 == ~handle;~__ste_client_privateKey0~0 := ~value; {8539#true} is VALID [2022-02-20 18:00:04,893 INFO L290 TraceCheckUtils]: 15: Hoare triple {8539#true} assume true; {8539#true} is VALID [2022-02-20 18:00:04,893 INFO L284 TraceCheckUtils]: 16: Hoare quadruple {8539#true} {8539#true} #1136#return; {8539#true} is VALID [2022-02-20 18:00:04,894 INFO L290 TraceCheckUtils]: 17: Hoare triple {8539#true} assume { :end_inline_setup_bob } true;setup_~__cil_tmp1~0#1.base, setup_~__cil_tmp1~0#1.offset := 18, 0;havoc setup_#t~nondet32#1;~rjh~0 := 2;assume { :begin_inline_setup_rjh } true;setup_rjh_#in~rjh___0#1 := ~rjh~0;havoc setup_rjh_~rjh___0#1;setup_rjh_~rjh___0#1 := setup_rjh_#in~rjh___0#1;assume { :begin_inline_setup_rjh__wrappee__Base } true;setup_rjh__wrappee__Base_#in~rjh___0#1 := setup_rjh_~rjh___0#1;havoc setup_rjh__wrappee__Base_~rjh___0#1;setup_rjh__wrappee__Base_~rjh___0#1 := setup_rjh__wrappee__Base_#in~rjh___0#1; {8659#(<= 2 |ULTIMATE.start_setup_rjh__wrappee__Base_~rjh___0#1|)} is VALID [2022-02-20 18:00:04,894 INFO L272 TraceCheckUtils]: 18: Hoare triple {8659#(<= 2 |ULTIMATE.start_setup_rjh__wrappee__Base_~rjh___0#1|)} call setClientId(setup_rjh__wrappee__Base_~rjh___0#1, setup_rjh__wrappee__Base_~rjh___0#1); {8539#true} is VALID [2022-02-20 18:00:04,894 INFO L290 TraceCheckUtils]: 19: Hoare triple {8539#true} ~handle := #in~handle;~value := #in~value; {8666#(<= |setClientId_#in~handle| setClientId_~handle)} is VALID [2022-02-20 18:00:04,895 INFO L290 TraceCheckUtils]: 20: Hoare triple {8666#(<= |setClientId_#in~handle| setClientId_~handle)} assume 1 == ~handle;~__ste_client_idCounter0~0 := ~value; {8670#(<= |setClientId_#in~handle| 1)} is VALID [2022-02-20 18:00:04,895 INFO L290 TraceCheckUtils]: 21: Hoare triple {8670#(<= |setClientId_#in~handle| 1)} assume true; {8670#(<= |setClientId_#in~handle| 1)} is VALID [2022-02-20 18:00:04,896 INFO L284 TraceCheckUtils]: 22: Hoare quadruple {8670#(<= |setClientId_#in~handle| 1)} {8659#(<= 2 |ULTIMATE.start_setup_rjh__wrappee__Base_~rjh___0#1|)} #1138#return; {8540#false} is VALID [2022-02-20 18:00:04,896 INFO L290 TraceCheckUtils]: 23: Hoare triple {8540#false} assume { :end_inline_setup_rjh__wrappee__Base } true; {8540#false} is VALID [2022-02-20 18:00:04,896 INFO L272 TraceCheckUtils]: 24: Hoare triple {8540#false} call setClientPrivateKey(setup_rjh_~rjh___0#1, 456); {8540#false} is VALID [2022-02-20 18:00:04,896 INFO L290 TraceCheckUtils]: 25: Hoare triple {8540#false} ~handle := #in~handle;~value := #in~value; {8540#false} is VALID [2022-02-20 18:00:04,896 INFO L290 TraceCheckUtils]: 26: Hoare triple {8540#false} assume 1 == ~handle;~__ste_client_privateKey0~0 := ~value; {8540#false} is VALID [2022-02-20 18:00:04,896 INFO L290 TraceCheckUtils]: 27: Hoare triple {8540#false} assume true; {8540#false} is VALID [2022-02-20 18:00:04,896 INFO L284 TraceCheckUtils]: 28: Hoare quadruple {8540#false} {8540#false} #1140#return; {8540#false} is VALID [2022-02-20 18:00:04,897 INFO L290 TraceCheckUtils]: 29: Hoare triple {8540#false} assume { :end_inline_setup_rjh } true;setup_~__cil_tmp2~0#1.base, setup_~__cil_tmp2~0#1.offset := 19, 0;havoc setup_#t~nondet33#1;~chuck~0 := 3;assume { :begin_inline_setup_chuck } true;setup_chuck_#in~chuck___0#1 := ~chuck~0;havoc setup_chuck_~chuck___0#1;setup_chuck_~chuck___0#1 := setup_chuck_#in~chuck___0#1;assume { :begin_inline_setup_chuck__wrappee__Base } true;setup_chuck__wrappee__Base_#in~chuck___0#1 := setup_chuck_~chuck___0#1;havoc setup_chuck__wrappee__Base_~chuck___0#1;setup_chuck__wrappee__Base_~chuck___0#1 := setup_chuck__wrappee__Base_#in~chuck___0#1; {8540#false} is VALID [2022-02-20 18:00:04,897 INFO L272 TraceCheckUtils]: 30: Hoare triple {8540#false} call setClientId(setup_chuck__wrappee__Base_~chuck___0#1, setup_chuck__wrappee__Base_~chuck___0#1); {8540#false} is VALID [2022-02-20 18:00:04,897 INFO L290 TraceCheckUtils]: 31: Hoare triple {8540#false} ~handle := #in~handle;~value := #in~value; {8540#false} is VALID [2022-02-20 18:00:04,897 INFO L290 TraceCheckUtils]: 32: Hoare triple {8540#false} assume 1 == ~handle;~__ste_client_idCounter0~0 := ~value; {8540#false} is VALID [2022-02-20 18:00:04,897 INFO L290 TraceCheckUtils]: 33: Hoare triple {8540#false} assume true; {8540#false} is VALID [2022-02-20 18:00:04,897 INFO L284 TraceCheckUtils]: 34: Hoare quadruple {8540#false} {8540#false} #1142#return; {8540#false} is VALID [2022-02-20 18:00:04,897 INFO L290 TraceCheckUtils]: 35: Hoare triple {8540#false} assume { :end_inline_setup_chuck__wrappee__Base } true; {8540#false} is VALID [2022-02-20 18:00:04,897 INFO L272 TraceCheckUtils]: 36: Hoare triple {8540#false} call setClientPrivateKey(setup_chuck_~chuck___0#1, 789); {8540#false} is VALID [2022-02-20 18:00:04,897 INFO L290 TraceCheckUtils]: 37: Hoare triple {8540#false} ~handle := #in~handle;~value := #in~value; {8540#false} is VALID [2022-02-20 18:00:04,898 INFO L290 TraceCheckUtils]: 38: Hoare triple {8540#false} assume 1 == ~handle;~__ste_client_privateKey0~0 := ~value; {8540#false} is VALID [2022-02-20 18:00:04,898 INFO L290 TraceCheckUtils]: 39: Hoare triple {8540#false} assume true; {8540#false} is VALID [2022-02-20 18:00:04,898 INFO L284 TraceCheckUtils]: 40: Hoare quadruple {8540#false} {8540#false} #1144#return; {8540#false} is VALID [2022-02-20 18:00:04,898 INFO L290 TraceCheckUtils]: 41: Hoare triple {8540#false} assume { :end_inline_setup_chuck } true;setup_~__cil_tmp3~0#1.base, setup_~__cil_tmp3~0#1.offset := 20, 0;havoc setup_#t~nondet34#1; {8540#false} is VALID [2022-02-20 18:00:04,898 INFO L290 TraceCheckUtils]: 42: Hoare triple {8540#false} assume { :end_inline_setup } true;assume { :begin_inline_test } true;havoc test_#t~nondet47#1, test_#t~nondet48#1, test_#t~nondet49#1, test_#t~nondet50#1, test_#t~nondet51#1, test_#t~nondet52#1, test_#t~nondet53#1, test_#t~nondet54#1, test_#t~nondet55#1, test_#t~nondet56#1, test_#t~nondet57#1, test_~op1~0#1, test_~op2~0#1, test_~op3~0#1, test_~op4~0#1, test_~op5~0#1, test_~op6~0#1, test_~op7~0#1, test_~op8~0#1, test_~op9~0#1, test_~op10~0#1, test_~op11~0#1, test_~splverifierCounter~0#1, test_~tmp~6#1, test_~tmp___0~2#1, test_~tmp___1~1#1, test_~tmp___2~0#1, test_~tmp___3~0#1, test_~tmp___4~0#1, test_~tmp___5~0#1, test_~tmp___6~0#1, test_~tmp___7~0#1, test_~tmp___8~0#1, test_~tmp___9~0#1;havoc test_~op1~0#1;havoc test_~op2~0#1;havoc test_~op3~0#1;havoc test_~op4~0#1;havoc test_~op5~0#1;havoc test_~op6~0#1;havoc test_~op7~0#1;havoc test_~op8~0#1;havoc test_~op9~0#1;havoc test_~op10~0#1;havoc test_~op11~0#1;havoc test_~splverifierCounter~0#1;havoc test_~tmp~6#1;havoc test_~tmp___0~2#1;havoc test_~tmp___1~1#1;havoc test_~tmp___2~0#1;havoc test_~tmp___3~0#1;havoc test_~tmp___4~0#1;havoc test_~tmp___5~0#1;havoc test_~tmp___6~0#1;havoc test_~tmp___7~0#1;havoc test_~tmp___8~0#1;havoc test_~tmp___9~0#1;test_~op1~0#1 := 0;test_~op2~0#1 := 0;test_~op3~0#1 := 0;test_~op4~0#1 := 0;test_~op5~0#1 := 0;test_~op6~0#1 := 0;test_~op7~0#1 := 0;test_~op8~0#1 := 0;test_~op9~0#1 := 0;test_~op10~0#1 := 0;test_~op11~0#1 := 0;test_~splverifierCounter~0#1 := 0; {8540#false} is VALID [2022-02-20 18:00:04,898 INFO L290 TraceCheckUtils]: 43: Hoare triple {8540#false} assume !false; {8540#false} is VALID [2022-02-20 18:00:04,898 INFO L290 TraceCheckUtils]: 44: Hoare triple {8540#false} assume test_~splverifierCounter~0#1 < 4; {8540#false} is VALID [2022-02-20 18:00:04,898 INFO L290 TraceCheckUtils]: 45: Hoare triple {8540#false} test_~splverifierCounter~0#1 := 1 + test_~splverifierCounter~0#1; {8540#false} is VALID [2022-02-20 18:00:04,898 INFO L290 TraceCheckUtils]: 46: Hoare triple {8540#false} assume 0 == test_~op1~0#1;assume -2147483648 <= test_#t~nondet47#1 && test_#t~nondet47#1 <= 2147483647;test_~tmp___9~0#1 := test_#t~nondet47#1;havoc test_#t~nondet47#1; {8540#false} is VALID [2022-02-20 18:00:04,899 INFO L290 TraceCheckUtils]: 47: Hoare triple {8540#false} assume !(0 != test_~tmp___9~0#1); {8540#false} is VALID [2022-02-20 18:00:04,899 INFO L290 TraceCheckUtils]: 48: Hoare triple {8540#false} assume 0 == test_~op2~0#1;assume -2147483648 <= test_#t~nondet48#1 && test_#t~nondet48#1 <= 2147483647;test_~tmp___8~0#1 := test_#t~nondet48#1;havoc test_#t~nondet48#1; {8540#false} is VALID [2022-02-20 18:00:04,899 INFO L290 TraceCheckUtils]: 49: Hoare triple {8540#false} assume 0 != test_~tmp___8~0#1;assume { :begin_inline_rjhSetAutoRespond } true;assume { :begin_inline_setClientAutoResponse } true;setClientAutoResponse_#in~handle#1, setClientAutoResponse_#in~value#1 := ~rjh~0, 1;havoc setClientAutoResponse_~handle#1, setClientAutoResponse_~value#1;setClientAutoResponse_~handle#1 := setClientAutoResponse_#in~handle#1;setClientAutoResponse_~value#1 := setClientAutoResponse_#in~value#1; {8540#false} is VALID [2022-02-20 18:00:04,899 INFO L290 TraceCheckUtils]: 50: Hoare triple {8540#false} assume 1 == setClientAutoResponse_~handle#1;~__ste_client_autoResponse0~0 := setClientAutoResponse_~value#1; {8540#false} is VALID [2022-02-20 18:00:04,899 INFO L290 TraceCheckUtils]: 51: Hoare triple {8540#false} assume { :end_inline_setClientAutoResponse } true; {8540#false} is VALID [2022-02-20 18:00:04,899 INFO L290 TraceCheckUtils]: 52: Hoare triple {8540#false} assume { :end_inline_rjhSetAutoRespond } true;test_~op2~0#1 := 1; {8540#false} is VALID [2022-02-20 18:00:04,899 INFO L290 TraceCheckUtils]: 53: Hoare triple {8540#false} assume !false; {8540#false} is VALID [2022-02-20 18:00:04,899 INFO L290 TraceCheckUtils]: 54: Hoare triple {8540#false} assume !(test_~splverifierCounter~0#1 < 4); {8540#false} is VALID [2022-02-20 18:00:04,899 INFO L290 TraceCheckUtils]: 55: Hoare triple {8540#false} assume { :begin_inline_bobToRjh } true;havoc bobToRjh_#t~ret27#1, bobToRjh_#t~ret28#1, bobToRjh_#t~ret29#1, bobToRjh_#t~ret30#1, bobToRjh_~tmp~3#1, bobToRjh_~tmp___0~0#1, bobToRjh_~tmp___1~0#1;havoc bobToRjh_~tmp~3#1;havoc bobToRjh_~tmp___0~0#1;havoc bobToRjh_~tmp___1~0#1;call bobToRjh_#t~ret27#1 := puts(16, 0);assume -2147483648 <= bobToRjh_#t~ret27#1 && bobToRjh_#t~ret27#1 <= 2147483647;havoc bobToRjh_#t~ret27#1; {8540#false} is VALID [2022-02-20 18:00:04,899 INFO L272 TraceCheckUtils]: 56: Hoare triple {8540#false} call sendEmail(~bob~0, ~rjh~0); {8540#false} is VALID [2022-02-20 18:00:04,900 INFO L290 TraceCheckUtils]: 57: Hoare triple {8540#false} ~sender#1 := #in~sender#1;~receiver#1 := #in~receiver#1;havoc ~email~0#1;havoc ~tmp~14#1;assume { :begin_inline_createEmail } true;createEmail_#in~from#1, createEmail_#in~to#1 := 0, ~receiver#1;havoc createEmail_#res#1;havoc createEmail_~from#1, createEmail_~to#1, createEmail_~retValue_acc~31#1, createEmail_~msg~0#1;createEmail_~from#1 := createEmail_#in~from#1;createEmail_~to#1 := createEmail_#in~to#1;havoc createEmail_~retValue_acc~31#1;havoc createEmail_~msg~0#1;createEmail_~msg~0#1 := 1; {8540#false} is VALID [2022-02-20 18:00:04,900 INFO L272 TraceCheckUtils]: 58: Hoare triple {8540#false} call setEmailFrom(createEmail_~msg~0#1, createEmail_~from#1); {8540#false} is VALID [2022-02-20 18:00:04,900 INFO L290 TraceCheckUtils]: 59: Hoare triple {8540#false} ~handle := #in~handle;~value := #in~value; {8540#false} is VALID [2022-02-20 18:00:04,900 INFO L290 TraceCheckUtils]: 60: Hoare triple {8540#false} assume 1 == ~handle;~__ste_email_from0~0 := ~value; {8540#false} is VALID [2022-02-20 18:00:04,900 INFO L290 TraceCheckUtils]: 61: Hoare triple {8540#false} assume true; {8540#false} is VALID [2022-02-20 18:00:04,900 INFO L284 TraceCheckUtils]: 62: Hoare quadruple {8540#false} {8540#false} #1120#return; {8540#false} is VALID [2022-02-20 18:00:04,900 INFO L272 TraceCheckUtils]: 63: Hoare triple {8540#false} call setEmailTo(createEmail_~msg~0#1, createEmail_~to#1); {8540#false} is VALID [2022-02-20 18:00:04,900 INFO L290 TraceCheckUtils]: 64: Hoare triple {8540#false} ~handle := #in~handle;~value := #in~value; {8540#false} is VALID [2022-02-20 18:00:04,900 INFO L290 TraceCheckUtils]: 65: Hoare triple {8540#false} assume 1 == ~handle;~__ste_email_to0~0 := ~value; {8540#false} is VALID [2022-02-20 18:00:04,901 INFO L290 TraceCheckUtils]: 66: Hoare triple {8540#false} assume true; {8540#false} is VALID [2022-02-20 18:00:04,901 INFO L284 TraceCheckUtils]: 67: Hoare quadruple {8540#false} {8540#false} #1122#return; {8540#false} is VALID [2022-02-20 18:00:04,901 INFO L290 TraceCheckUtils]: 68: Hoare triple {8540#false} createEmail_~retValue_acc~31#1 := createEmail_~msg~0#1;createEmail_#res#1 := createEmail_~retValue_acc~31#1; {8540#false} is VALID [2022-02-20 18:00:04,901 INFO L290 TraceCheckUtils]: 69: Hoare triple {8540#false} #t~ret72#1 := createEmail_#res#1;assume { :end_inline_createEmail } true;assume -2147483648 <= #t~ret72#1 && #t~ret72#1 <= 2147483647;~tmp~14#1 := #t~ret72#1;havoc #t~ret72#1;~email~0#1 := ~tmp~14#1; {8540#false} is VALID [2022-02-20 18:00:04,901 INFO L272 TraceCheckUtils]: 70: Hoare triple {8540#false} call outgoing(~sender#1, ~email~0#1); {8540#false} is VALID [2022-02-20 18:00:04,901 INFO L290 TraceCheckUtils]: 71: Hoare triple {8540#false} ~client#1 := #in~client#1;~msg#1 := #in~msg#1;assume { :begin_inline_sign } true;sign_#in~client#1, sign_#in~msg#1 := ~client#1, ~msg#1;havoc sign_#t~ret76#1, sign_~client#1, sign_~msg#1, sign_~privkey~1#1, sign_~tmp~16#1;sign_~client#1 := sign_#in~client#1;sign_~msg#1 := sign_#in~msg#1;havoc sign_~privkey~1#1;havoc sign_~tmp~16#1; {8540#false} is VALID [2022-02-20 18:00:04,901 INFO L272 TraceCheckUtils]: 72: Hoare triple {8540#false} call sign_#t~ret76#1 := getClientPrivateKey(sign_~client#1); {8540#false} is VALID [2022-02-20 18:00:04,901 INFO L290 TraceCheckUtils]: 73: Hoare triple {8540#false} ~handle := #in~handle;havoc ~retValue_acc~20; {8540#false} is VALID [2022-02-20 18:00:04,901 INFO L290 TraceCheckUtils]: 74: Hoare triple {8540#false} assume 1 == ~handle;~retValue_acc~20 := ~__ste_client_privateKey0~0;#res := ~retValue_acc~20; {8540#false} is VALID [2022-02-20 18:00:04,901 INFO L290 TraceCheckUtils]: 75: Hoare triple {8540#false} assume true; {8540#false} is VALID [2022-02-20 18:00:04,902 INFO L284 TraceCheckUtils]: 76: Hoare quadruple {8540#false} {8540#false} #1054#return; {8540#false} is VALID [2022-02-20 18:00:04,902 INFO L290 TraceCheckUtils]: 77: Hoare triple {8540#false} assume -2147483648 <= sign_#t~ret76#1 && sign_#t~ret76#1 <= 2147483647;sign_~tmp~16#1 := sign_#t~ret76#1;havoc sign_#t~ret76#1;sign_~privkey~1#1 := sign_~tmp~16#1; {8540#false} is VALID [2022-02-20 18:00:04,902 INFO L290 TraceCheckUtils]: 78: Hoare triple {8540#false} assume 0 == sign_~privkey~1#1; {8540#false} is VALID [2022-02-20 18:00:04,902 INFO L290 TraceCheckUtils]: 79: Hoare triple {8540#false} assume { :end_inline_sign } true;assume { :begin_inline_outgoing__wrappee__AutoResponder } true;outgoing__wrappee__AutoResponder_#in~client#1, outgoing__wrappee__AutoResponder_#in~msg#1 := ~client#1, ~msg#1;havoc outgoing__wrappee__AutoResponder_#t~ret62#1, outgoing__wrappee__AutoResponder_#t~ret63#1, outgoing__wrappee__AutoResponder_~client#1, outgoing__wrappee__AutoResponder_~msg#1, outgoing__wrappee__AutoResponder_~receiver~0#1, outgoing__wrappee__AutoResponder_~tmp~9#1, outgoing__wrappee__AutoResponder_~pubkey~0#1, outgoing__wrappee__AutoResponder_~tmp___0~3#1;outgoing__wrappee__AutoResponder_~client#1 := outgoing__wrappee__AutoResponder_#in~client#1;outgoing__wrappee__AutoResponder_~msg#1 := outgoing__wrappee__AutoResponder_#in~msg#1;havoc outgoing__wrappee__AutoResponder_~receiver~0#1;havoc outgoing__wrappee__AutoResponder_~tmp~9#1;havoc outgoing__wrappee__AutoResponder_~pubkey~0#1;havoc outgoing__wrappee__AutoResponder_~tmp___0~3#1; {8540#false} is VALID [2022-02-20 18:00:04,902 INFO L272 TraceCheckUtils]: 80: Hoare triple {8540#false} call outgoing__wrappee__AutoResponder_#t~ret62#1 := getEmailTo(outgoing__wrappee__AutoResponder_~msg#1); {8540#false} is VALID [2022-02-20 18:00:04,902 INFO L290 TraceCheckUtils]: 81: Hoare triple {8540#false} ~handle := #in~handle;havoc ~retValue_acc~36; {8540#false} is VALID [2022-02-20 18:00:04,902 INFO L290 TraceCheckUtils]: 82: Hoare triple {8540#false} assume 1 == ~handle;~retValue_acc~36 := ~__ste_email_to0~0;#res := ~retValue_acc~36; {8540#false} is VALID [2022-02-20 18:00:04,902 INFO L290 TraceCheckUtils]: 83: Hoare triple {8540#false} assume true; {8540#false} is VALID [2022-02-20 18:00:04,903 INFO L284 TraceCheckUtils]: 84: Hoare quadruple {8540#false} {8540#false} #1056#return; {8540#false} is VALID [2022-02-20 18:00:04,903 INFO L290 TraceCheckUtils]: 85: Hoare triple {8540#false} assume -2147483648 <= outgoing__wrappee__AutoResponder_#t~ret62#1 && outgoing__wrappee__AutoResponder_#t~ret62#1 <= 2147483647;outgoing__wrappee__AutoResponder_~tmp~9#1 := outgoing__wrappee__AutoResponder_#t~ret62#1;havoc outgoing__wrappee__AutoResponder_#t~ret62#1;outgoing__wrappee__AutoResponder_~receiver~0#1 := outgoing__wrappee__AutoResponder_~tmp~9#1; {8540#false} is VALID [2022-02-20 18:00:04,903 INFO L272 TraceCheckUtils]: 86: Hoare triple {8540#false} call outgoing__wrappee__AutoResponder_#t~ret63#1 := findPublicKey(outgoing__wrappee__AutoResponder_~client#1, outgoing__wrappee__AutoResponder_~receiver~0#1); {8540#false} is VALID [2022-02-20 18:00:04,903 INFO L290 TraceCheckUtils]: 87: Hoare triple {8540#false} ~handle := #in~handle;~userid := #in~userid;havoc ~retValue_acc~25; {8540#false} is VALID [2022-02-20 18:00:04,903 INFO L290 TraceCheckUtils]: 88: Hoare triple {8540#false} assume 1 == ~handle; {8540#false} is VALID [2022-02-20 18:00:04,903 INFO L290 TraceCheckUtils]: 89: Hoare triple {8540#false} assume ~userid == ~__ste_Client_Keyring0_User0~0;~retValue_acc~25 := ~__ste_Client_Keyring0_PublicKey0~0;#res := ~retValue_acc~25; {8540#false} is VALID [2022-02-20 18:00:04,903 INFO L290 TraceCheckUtils]: 90: Hoare triple {8540#false} assume true; {8540#false} is VALID [2022-02-20 18:00:04,903 INFO L284 TraceCheckUtils]: 91: Hoare quadruple {8540#false} {8540#false} #1058#return; {8540#false} is VALID [2022-02-20 18:00:04,903 INFO L290 TraceCheckUtils]: 92: Hoare triple {8540#false} assume -2147483648 <= outgoing__wrappee__AutoResponder_#t~ret63#1 && outgoing__wrappee__AutoResponder_#t~ret63#1 <= 2147483647;outgoing__wrappee__AutoResponder_~tmp___0~3#1 := outgoing__wrappee__AutoResponder_#t~ret63#1;havoc outgoing__wrappee__AutoResponder_#t~ret63#1;outgoing__wrappee__AutoResponder_~pubkey~0#1 := outgoing__wrappee__AutoResponder_~tmp___0~3#1; {8540#false} is VALID [2022-02-20 18:00:04,903 INFO L290 TraceCheckUtils]: 93: Hoare triple {8540#false} assume !(0 != outgoing__wrappee__AutoResponder_~pubkey~0#1); {8540#false} is VALID [2022-02-20 18:00:04,904 INFO L290 TraceCheckUtils]: 94: Hoare triple {8540#false} assume { :begin_inline_outgoing__wrappee__Keys } true;outgoing__wrappee__Keys_#in~client#1, outgoing__wrappee__Keys_#in~msg#1 := outgoing__wrappee__AutoResponder_~client#1, outgoing__wrappee__AutoResponder_~msg#1;havoc outgoing__wrappee__Keys_#t~ret61#1, outgoing__wrappee__Keys_~client#1, outgoing__wrappee__Keys_~msg#1, outgoing__wrappee__Keys_~tmp~8#1;outgoing__wrappee__Keys_~client#1 := outgoing__wrappee__Keys_#in~client#1;outgoing__wrappee__Keys_~msg#1 := outgoing__wrappee__Keys_#in~msg#1;havoc outgoing__wrappee__Keys_~tmp~8#1;assume { :begin_inline_getClientId } true;getClientId_#in~handle#1 := outgoing__wrappee__Keys_~client#1;havoc getClientId_#res#1;havoc getClientId_~handle#1, getClientId_~retValue_acc~27#1;getClientId_~handle#1 := getClientId_#in~handle#1;havoc getClientId_~retValue_acc~27#1; {8540#false} is VALID [2022-02-20 18:00:04,904 INFO L290 TraceCheckUtils]: 95: Hoare triple {8540#false} assume 1 == getClientId_~handle#1;getClientId_~retValue_acc~27#1 := ~__ste_client_idCounter0~0;getClientId_#res#1 := getClientId_~retValue_acc~27#1; {8540#false} is VALID [2022-02-20 18:00:04,904 INFO L290 TraceCheckUtils]: 96: Hoare triple {8540#false} outgoing__wrappee__Keys_#t~ret61#1 := getClientId_#res#1;assume { :end_inline_getClientId } true;assume -2147483648 <= outgoing__wrappee__Keys_#t~ret61#1 && outgoing__wrappee__Keys_#t~ret61#1 <= 2147483647;outgoing__wrappee__Keys_~tmp~8#1 := outgoing__wrappee__Keys_#t~ret61#1;havoc outgoing__wrappee__Keys_#t~ret61#1; {8540#false} is VALID [2022-02-20 18:00:04,904 INFO L272 TraceCheckUtils]: 97: Hoare triple {8540#false} call setEmailFrom(outgoing__wrappee__Keys_~msg#1, outgoing__wrappee__Keys_~tmp~8#1); {8540#false} is VALID [2022-02-20 18:00:04,904 INFO L290 TraceCheckUtils]: 98: Hoare triple {8540#false} ~handle := #in~handle;~value := #in~value; {8540#false} is VALID [2022-02-20 18:00:04,904 INFO L290 TraceCheckUtils]: 99: Hoare triple {8540#false} assume 1 == ~handle;~__ste_email_from0~0 := ~value; {8540#false} is VALID [2022-02-20 18:00:04,904 INFO L290 TraceCheckUtils]: 100: Hoare triple {8540#false} assume true; {8540#false} is VALID [2022-02-20 18:00:04,904 INFO L284 TraceCheckUtils]: 101: Hoare quadruple {8540#false} {8540#false} #1064#return; {8540#false} is VALID [2022-02-20 18:00:04,904 INFO L290 TraceCheckUtils]: 102: Hoare triple {8540#false} assume { :begin_inline_mail } true;mail_#in~client#1, mail_#in~msg#1 := outgoing__wrappee__Keys_~client#1, outgoing__wrappee__Keys_~msg#1;havoc mail_#t~ret59#1, mail_#t~ret60#1, mail_~client#1, mail_~msg#1, mail_~__utac__ad__arg1~0#1, mail_~__utac__ad__arg2~0#1, mail_~tmp~7#1;mail_~client#1 := mail_#in~client#1;mail_~msg#1 := mail_#in~msg#1;havoc mail_~__utac__ad__arg1~0#1;havoc mail_~__utac__ad__arg2~0#1;havoc mail_~tmp~7#1;mail_~__utac__ad__arg1~0#1 := mail_~client#1;mail_~__utac__ad__arg2~0#1 := mail_~msg#1;assume { :begin_inline___utac_acc__SignForward_spec__1 } true;__utac_acc__SignForward_spec__1_#in~client#1, __utac_acc__SignForward_spec__1_#in~msg#1 := mail_~__utac__ad__arg1~0#1, mail_~__utac__ad__arg2~0#1;havoc __utac_acc__SignForward_spec__1_#t~ret107#1, __utac_acc__SignForward_spec__1_#t~ret108#1, __utac_acc__SignForward_spec__1_#t~ret109#1, __utac_acc__SignForward_spec__1_~client#1, __utac_acc__SignForward_spec__1_~msg#1, __utac_acc__SignForward_spec__1_~tmp~25#1, __utac_acc__SignForward_spec__1_~tmp___0~9#1;__utac_acc__SignForward_spec__1_~client#1 := __utac_acc__SignForward_spec__1_#in~client#1;__utac_acc__SignForward_spec__1_~msg#1 := __utac_acc__SignForward_spec__1_#in~msg#1;havoc __utac_acc__SignForward_spec__1_~tmp~25#1;havoc __utac_acc__SignForward_spec__1_~tmp___0~9#1;call __utac_acc__SignForward_spec__1_#t~ret107#1 := puts(39, 0);assume -2147483648 <= __utac_acc__SignForward_spec__1_#t~ret107#1 && __utac_acc__SignForward_spec__1_#t~ret107#1 <= 2147483647;havoc __utac_acc__SignForward_spec__1_#t~ret107#1; {8540#false} is VALID [2022-02-20 18:00:04,905 INFO L272 TraceCheckUtils]: 103: Hoare triple {8540#false} call __utac_acc__SignForward_spec__1_#t~ret108#1 := isSigned(__utac_acc__SignForward_spec__1_~msg#1); {8540#false} is VALID [2022-02-20 18:00:04,905 INFO L290 TraceCheckUtils]: 104: Hoare triple {8540#false} ~handle := #in~handle;havoc ~retValue_acc~41; {8540#false} is VALID [2022-02-20 18:00:04,905 INFO L290 TraceCheckUtils]: 105: Hoare triple {8540#false} assume 1 == ~handle;~retValue_acc~41 := ~__ste_email_isSigned0~0;#res := ~retValue_acc~41; {8540#false} is VALID [2022-02-20 18:00:04,905 INFO L290 TraceCheckUtils]: 106: Hoare triple {8540#false} assume true; {8540#false} is VALID [2022-02-20 18:00:04,905 INFO L284 TraceCheckUtils]: 107: Hoare quadruple {8540#false} {8540#false} #1066#return; {8540#false} is VALID [2022-02-20 18:00:04,905 INFO L290 TraceCheckUtils]: 108: Hoare triple {8540#false} assume -2147483648 <= __utac_acc__SignForward_spec__1_#t~ret108#1 && __utac_acc__SignForward_spec__1_#t~ret108#1 <= 2147483647;__utac_acc__SignForward_spec__1_~tmp___0~9#1 := __utac_acc__SignForward_spec__1_#t~ret108#1;havoc __utac_acc__SignForward_spec__1_#t~ret108#1; {8540#false} is VALID [2022-02-20 18:00:04,905 INFO L290 TraceCheckUtils]: 109: Hoare triple {8540#false} assume 0 != __utac_acc__SignForward_spec__1_~tmp___0~9#1; {8540#false} is VALID [2022-02-20 18:00:04,905 INFO L272 TraceCheckUtils]: 110: Hoare triple {8540#false} call __utac_acc__SignForward_spec__1_#t~ret109#1 := getClientPrivateKey(__utac_acc__SignForward_spec__1_~client#1); {8540#false} is VALID [2022-02-20 18:00:04,905 INFO L290 TraceCheckUtils]: 111: Hoare triple {8540#false} ~handle := #in~handle;havoc ~retValue_acc~20; {8540#false} is VALID [2022-02-20 18:00:04,906 INFO L290 TraceCheckUtils]: 112: Hoare triple {8540#false} assume 1 == ~handle;~retValue_acc~20 := ~__ste_client_privateKey0~0;#res := ~retValue_acc~20; {8540#false} is VALID [2022-02-20 18:00:04,906 INFO L290 TraceCheckUtils]: 113: Hoare triple {8540#false} assume true; {8540#false} is VALID [2022-02-20 18:00:04,906 INFO L284 TraceCheckUtils]: 114: Hoare quadruple {8540#false} {8540#false} #1068#return; {8540#false} is VALID [2022-02-20 18:00:04,906 INFO L290 TraceCheckUtils]: 115: Hoare triple {8540#false} assume -2147483648 <= __utac_acc__SignForward_spec__1_#t~ret109#1 && __utac_acc__SignForward_spec__1_#t~ret109#1 <= 2147483647;__utac_acc__SignForward_spec__1_~tmp~25#1 := __utac_acc__SignForward_spec__1_#t~ret109#1;havoc __utac_acc__SignForward_spec__1_#t~ret109#1; {8540#false} is VALID [2022-02-20 18:00:04,906 INFO L290 TraceCheckUtils]: 116: Hoare triple {8540#false} assume 0 == __utac_acc__SignForward_spec__1_~tmp~25#1;assume { :begin_inline___automaton_fail } true; {8540#false} is VALID [2022-02-20 18:00:04,906 INFO L290 TraceCheckUtils]: 117: Hoare triple {8540#false} assume !false; {8540#false} is VALID [2022-02-20 18:00:04,906 INFO L134 CoverageAnalysis]: Checked inductivity of 34 backedges. 19 proven. 0 refuted. 0 times theorem prover too weak. 15 trivial. 0 not checked. [2022-02-20 18:00:04,906 INFO L324 TraceCheckSpWp]: Omiting computation of backward sequence because forward sequence was already perfect [2022-02-20 18:00:04,907 INFO L165 FreeRefinementEngine]: IpTcStrategyModuleZ3 [362626083] provided 1 perfect and 0 imperfect interpolant sequences [2022-02-20 18:00:04,907 INFO L191 FreeRefinementEngine]: Found 1 perfect and 1 imperfect interpolant sequences. [2022-02-20 18:00:04,907 INFO L204 FreeRefinementEngine]: Number of different interpolants: perfect sequences [5] imperfect sequences [9] total 12 [2022-02-20 18:00:04,907 INFO L118 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [77577865] [2022-02-20 18:00:04,907 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2022-02-20 18:00:04,908 INFO L78 Accepts]: Start accepts. Automaton has has 5 states, 4 states have (on average 19.5) internal successors, (78), 5 states have internal predecessors, (78), 3 states have call successors, (16), 2 states have call predecessors, (16), 3 states have return successors, (14), 2 states have call predecessors, (14), 3 states have call successors, (14) Word has length 118 [2022-02-20 18:00:04,908 INFO L84 Accepts]: Finished accepts. word is accepted. [2022-02-20 18:00:04,908 INFO L86 InductivityCheck]: Starting indutivity check of a Floyd-Hoare automaton with has 5 states, 4 states have (on average 19.5) internal successors, (78), 5 states have internal predecessors, (78), 3 states have call successors, (16), 2 states have call predecessors, (16), 3 states have return successors, (14), 2 states have call predecessors, (14), 3 states have call successors, (14) [2022-02-20 18:00:04,986 INFO L122 InductivityCheck]: Floyd-Hoare automaton has 108 edges. 108 inductive. 0 not inductive. 0 times theorem prover too weak to decide inductivity. [2022-02-20 18:00:04,986 INFO L546 AbstractCegarLoop]: INTERPOLANT automaton has 5 states [2022-02-20 18:00:04,986 INFO L108 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2022-02-20 18:00:04,986 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 5 interpolants. [2022-02-20 18:00:04,987 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=24, Invalid=108, Unknown=0, NotChecked=0, Total=132 [2022-02-20 18:00:04,987 INFO L87 Difference]: Start difference. First operand 437 states and 657 transitions. Second operand has 5 states, 4 states have (on average 19.5) internal successors, (78), 5 states have internal predecessors, (78), 3 states have call successors, (16), 2 states have call predecessors, (16), 3 states have return successors, (14), 2 states have call predecessors, (14), 3 states have call successors, (14) [2022-02-20 18:00:05,941 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-02-20 18:00:05,942 INFO L93 Difference]: Finished difference Result 865 states and 1304 transitions. [2022-02-20 18:00:05,942 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 5 states. [2022-02-20 18:00:05,942 INFO L78 Accepts]: Start accepts. Automaton has has 5 states, 4 states have (on average 19.5) internal successors, (78), 5 states have internal predecessors, (78), 3 states have call successors, (16), 2 states have call predecessors, (16), 3 states have return successors, (14), 2 states have call predecessors, (14), 3 states have call successors, (14) Word has length 118 [2022-02-20 18:00:05,942 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2022-02-20 18:00:05,943 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 5 states, 4 states have (on average 19.5) internal successors, (78), 5 states have internal predecessors, (78), 3 states have call successors, (16), 2 states have call predecessors, (16), 3 states have return successors, (14), 2 states have call predecessors, (14), 3 states have call successors, (14) [2022-02-20 18:00:05,951 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 5 states to 5 states and 1116 transitions. [2022-02-20 18:00:05,952 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 5 states, 4 states have (on average 19.5) internal successors, (78), 5 states have internal predecessors, (78), 3 states have call successors, (16), 2 states have call predecessors, (16), 3 states have return successors, (14), 2 states have call predecessors, (14), 3 states have call successors, (14) [2022-02-20 18:00:05,960 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 5 states to 5 states and 1116 transitions. [2022-02-20 18:00:05,960 INFO L86 InductivityCheck]: Starting indutivity check of a Floyd-Hoare automaton with 5 states and 1116 transitions. [2022-02-20 18:00:06,652 INFO L122 InductivityCheck]: Floyd-Hoare automaton has 1116 edges. 1116 inductive. 0 not inductive. 0 times theorem prover too weak to decide inductivity. [2022-02-20 18:00:06,669 INFO L225 Difference]: With dead ends: 865 [2022-02-20 18:00:06,669 INFO L226 Difference]: Without dead ends: 439 [2022-02-20 18:00:06,671 INFO L932 BasicCegarLoop]: 0 DeclaredPredicates, 150 GetRequests, 139 SyntacticMatches, 0 SemanticMatches, 11 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 3 ImplicationChecksByTransitivity, 0.1s TimeCoverageRelationStatistics Valid=28, Invalid=128, Unknown=0, NotChecked=0, Total=156 [2022-02-20 18:00:06,674 INFO L933 BasicCegarLoop]: 554 mSDtfsCounter, 133 mSDsluCounter, 1510 mSDsCounter, 0 mSdLazyCounter, 34 mSolverCounterSat, 0 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.0s Time, 0 mProtectedPredicate, 0 mProtectedAction, 153 SdHoareTripleChecker+Valid, 2064 SdHoareTripleChecker+Invalid, 34 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 0 IncrementalHoareTripleChecker+Valid, 34 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.0s IncrementalHoareTripleChecker+Time [2022-02-20 18:00:06,675 INFO L934 BasicCegarLoop]: SdHoareTripleChecker [153 Valid, 2064 Invalid, 34 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [0 Valid, 34 Invalid, 0 Unknown, 0 Unchecked, 0.0s Time] [2022-02-20 18:00:06,677 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 439 states. [2022-02-20 18:00:06,737 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 439 to 439. [2022-02-20 18:00:06,737 INFO L214 AbstractMinimizeNwa]: Start testing correctness of minimizeSevpa [2022-02-20 18:00:06,739 INFO L82 GeneralOperation]: Start isEquivalent. First operand 439 states. Second operand has 439 states, 339 states have (on average 1.5073746312684366) internal successors, (511), 343 states have internal predecessors, (511), 74 states have call successors, (74), 24 states have call predecessors, (74), 25 states have return successors, (75), 73 states have call predecessors, (75), 73 states have call successors, (75) [2022-02-20 18:00:06,742 INFO L74 IsIncluded]: Start isIncluded. First operand 439 states. Second operand has 439 states, 339 states have (on average 1.5073746312684366) internal successors, (511), 343 states have internal predecessors, (511), 74 states have call successors, (74), 24 states have call predecessors, (74), 25 states have return successors, (75), 73 states have call predecessors, (75), 73 states have call successors, (75) [2022-02-20 18:00:06,743 INFO L87 Difference]: Start difference. First operand 439 states. Second operand has 439 states, 339 states have (on average 1.5073746312684366) internal successors, (511), 343 states have internal predecessors, (511), 74 states have call successors, (74), 24 states have call predecessors, (74), 25 states have return successors, (75), 73 states have call predecessors, (75), 73 states have call successors, (75) [2022-02-20 18:00:06,764 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-02-20 18:00:06,764 INFO L93 Difference]: Finished difference Result 439 states and 660 transitions. [2022-02-20 18:00:06,764 INFO L276 IsEmpty]: Start isEmpty. Operand 439 states and 660 transitions. [2022-02-20 18:00:06,766 INFO L282 IsEmpty]: Finished isEmpty. No accepting run. [2022-02-20 18:00:06,766 INFO L83 IsIncluded]: Finished isIncluded. Language is included [2022-02-20 18:00:06,768 INFO L74 IsIncluded]: Start isIncluded. First operand has 439 states, 339 states have (on average 1.5073746312684366) internal successors, (511), 343 states have internal predecessors, (511), 74 states have call successors, (74), 24 states have call predecessors, (74), 25 states have return successors, (75), 73 states have call predecessors, (75), 73 states have call successors, (75) Second operand 439 states. [2022-02-20 18:00:06,769 INFO L87 Difference]: Start difference. First operand has 439 states, 339 states have (on average 1.5073746312684366) internal successors, (511), 343 states have internal predecessors, (511), 74 states have call successors, (74), 24 states have call predecessors, (74), 25 states have return successors, (75), 73 states have call predecessors, (75), 73 states have call successors, (75) Second operand 439 states. [2022-02-20 18:00:06,808 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-02-20 18:00:06,808 INFO L93 Difference]: Finished difference Result 439 states and 660 transitions. [2022-02-20 18:00:06,808 INFO L276 IsEmpty]: Start isEmpty. Operand 439 states and 660 transitions. [2022-02-20 18:00:06,810 INFO L282 IsEmpty]: Finished isEmpty. No accepting run. [2022-02-20 18:00:06,810 INFO L83 IsIncluded]: Finished isIncluded. Language is included [2022-02-20 18:00:06,810 INFO L88 GeneralOperation]: Finished isEquivalent. [2022-02-20 18:00:06,810 INFO L221 AbstractMinimizeNwa]: Finished testing correctness of minimizeSevpa [2022-02-20 18:00:06,811 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 439 states, 339 states have (on average 1.5073746312684366) internal successors, (511), 343 states have internal predecessors, (511), 74 states have call successors, (74), 24 states have call predecessors, (74), 25 states have return successors, (75), 73 states have call predecessors, (75), 73 states have call successors, (75) [2022-02-20 18:00:06,830 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 439 states to 439 states and 660 transitions. [2022-02-20 18:00:06,831 INFO L78 Accepts]: Start accepts. Automaton has 439 states and 660 transitions. Word has length 118 [2022-02-20 18:00:06,831 INFO L84 Accepts]: Finished accepts. word is rejected. [2022-02-20 18:00:06,831 INFO L470 AbstractCegarLoop]: Abstraction has 439 states and 660 transitions. [2022-02-20 18:00:06,831 INFO L471 AbstractCegarLoop]: INTERPOLANT automaton has has 5 states, 4 states have (on average 19.5) internal successors, (78), 5 states have internal predecessors, (78), 3 states have call successors, (16), 2 states have call predecessors, (16), 3 states have return successors, (14), 2 states have call predecessors, (14), 3 states have call successors, (14) [2022-02-20 18:00:06,831 INFO L276 IsEmpty]: Start isEmpty. Operand 439 states and 660 transitions. [2022-02-20 18:00:06,833 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 120 [2022-02-20 18:00:06,833 INFO L506 BasicCegarLoop]: Found error trace [2022-02-20 18:00:06,833 INFO L514 BasicCegarLoop]: trace histogram [3, 3, 3, 3, 3, 2, 2, 2, 2, 2, 2, 2, 2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-02-20 18:00:06,871 INFO L540 MonitoredProcess]: [MP /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 -smt2 -in SMTLIB2_COMPLIANT=true (5)] Forceful destruction successful, exit code 0 [2022-02-20 18:00:07,058 WARN L452 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable3,5 /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 -smt2 -in SMTLIB2_COMPLIANT=true [2022-02-20 18:00:07,058 INFO L402 AbstractCegarLoop]: === Iteration 5 === Targeting outgoingErr0ASSERT_VIOLATIONERROR_FUNCTION === [outgoingErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2022-02-20 18:00:07,059 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2022-02-20 18:00:07,059 INFO L85 PathProgramCache]: Analyzing trace with hash -1183278252, now seen corresponding path program 1 times [2022-02-20 18:00:07,059 INFO L126 FreeRefinementEngine]: Executing refinement strategy CAMEL [2022-02-20 18:00:07,059 INFO L338 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [1326278447] [2022-02-20 18:00:07,059 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-02-20 18:00:07,059 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2022-02-20 18:00:07,092 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-02-20 18:00:07,136 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 6 [2022-02-20 18:00:07,137 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-02-20 18:00:07,140 INFO L290 TraceCheckUtils]: 0: Hoare triple {11754#(and (= |old(~__ste_client_idCounter0~0)| ~__ste_client_idCounter0~0) (= |old(~__ste_client_idCounter1~0)| ~__ste_client_idCounter1~0) (= |old(~__ste_client_idCounter2~0)| ~__ste_client_idCounter2~0))} ~handle := #in~handle;~value := #in~value; {11692#true} is VALID [2022-02-20 18:00:07,140 INFO L290 TraceCheckUtils]: 1: Hoare triple {11692#true} assume 1 == ~handle;~__ste_client_idCounter0~0 := ~value; {11692#true} is VALID [2022-02-20 18:00:07,140 INFO L290 TraceCheckUtils]: 2: Hoare triple {11692#true} assume true; {11692#true} is VALID [2022-02-20 18:00:07,140 INFO L284 TraceCheckUtils]: 3: Hoare quadruple {11692#true} {11692#true} #1134#return; {11692#true} is VALID [2022-02-20 18:00:07,146 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 12 [2022-02-20 18:00:07,149 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-02-20 18:00:07,153 INFO L290 TraceCheckUtils]: 0: Hoare triple {11755#(and (= ~__ste_client_privateKey0~0 |old(~__ste_client_privateKey0~0)|) (= ~__ste_client_privateKey2~0 |old(~__ste_client_privateKey2~0)|) (= ~__ste_client_privateKey1~0 |old(~__ste_client_privateKey1~0)|))} ~handle := #in~handle;~value := #in~value; {11692#true} is VALID [2022-02-20 18:00:07,153 INFO L290 TraceCheckUtils]: 1: Hoare triple {11692#true} assume 1 == ~handle;~__ste_client_privateKey0~0 := ~value; {11692#true} is VALID [2022-02-20 18:00:07,153 INFO L290 TraceCheckUtils]: 2: Hoare triple {11692#true} assume true; {11692#true} is VALID [2022-02-20 18:00:07,153 INFO L284 TraceCheckUtils]: 3: Hoare quadruple {11692#true} {11692#true} #1136#return; {11692#true} is VALID [2022-02-20 18:00:07,154 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 18 [2022-02-20 18:00:07,156 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-02-20 18:00:07,169 INFO L290 TraceCheckUtils]: 0: Hoare triple {11754#(and (= |old(~__ste_client_idCounter0~0)| ~__ste_client_idCounter0~0) (= |old(~__ste_client_idCounter1~0)| ~__ste_client_idCounter1~0) (= |old(~__ste_client_idCounter2~0)| ~__ste_client_idCounter2~0))} ~handle := #in~handle;~value := #in~value; {11756#(= setClientId_~handle |setClientId_#in~handle|)} is VALID [2022-02-20 18:00:07,169 INFO L290 TraceCheckUtils]: 1: Hoare triple {11756#(= setClientId_~handle |setClientId_#in~handle|)} assume !(1 == ~handle); {11756#(= setClientId_~handle |setClientId_#in~handle|)} is VALID [2022-02-20 18:00:07,170 INFO L290 TraceCheckUtils]: 2: Hoare triple {11756#(= setClientId_~handle |setClientId_#in~handle|)} assume 2 == ~handle;~__ste_client_idCounter1~0 := ~value; {11757#(= 2 |setClientId_#in~handle|)} is VALID [2022-02-20 18:00:07,170 INFO L290 TraceCheckUtils]: 3: Hoare triple {11757#(= 2 |setClientId_#in~handle|)} assume true; {11757#(= 2 |setClientId_#in~handle|)} is VALID [2022-02-20 18:00:07,170 INFO L284 TraceCheckUtils]: 4: Hoare quadruple {11757#(= 2 |setClientId_#in~handle|)} {11702#(= |ULTIMATE.start_setup_rjh_~rjh___0#1| |ULTIMATE.start_setup_rjh__wrappee__Base_~rjh___0#1|)} #1138#return; {11708#(not (= |ULTIMATE.start_setup_rjh_~rjh___0#1| 1))} is VALID [2022-02-20 18:00:07,171 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 25 [2022-02-20 18:00:07,173 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-02-20 18:00:07,190 INFO L290 TraceCheckUtils]: 0: Hoare triple {11755#(and (= ~__ste_client_privateKey0~0 |old(~__ste_client_privateKey0~0)|) (= ~__ste_client_privateKey2~0 |old(~__ste_client_privateKey2~0)|) (= ~__ste_client_privateKey1~0 |old(~__ste_client_privateKey1~0)|))} ~handle := #in~handle;~value := #in~value; {11758#(= setClientPrivateKey_~handle |setClientPrivateKey_#in~handle|)} is VALID [2022-02-20 18:00:07,190 INFO L290 TraceCheckUtils]: 1: Hoare triple {11758#(= setClientPrivateKey_~handle |setClientPrivateKey_#in~handle|)} assume 1 == ~handle;~__ste_client_privateKey0~0 := ~value; {11759#(= |setClientPrivateKey_#in~handle| 1)} is VALID [2022-02-20 18:00:07,191 INFO L290 TraceCheckUtils]: 2: Hoare triple {11759#(= |setClientPrivateKey_#in~handle| 1)} assume true; {11759#(= |setClientPrivateKey_#in~handle| 1)} is VALID [2022-02-20 18:00:07,191 INFO L284 TraceCheckUtils]: 3: Hoare quadruple {11759#(= |setClientPrivateKey_#in~handle| 1)} {11708#(not (= |ULTIMATE.start_setup_rjh_~rjh___0#1| 1))} #1140#return; {11693#false} is VALID [2022-02-20 18:00:07,192 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 31 [2022-02-20 18:00:07,193 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-02-20 18:00:07,195 INFO L290 TraceCheckUtils]: 0: Hoare triple {11754#(and (= |old(~__ste_client_idCounter0~0)| ~__ste_client_idCounter0~0) (= |old(~__ste_client_idCounter1~0)| ~__ste_client_idCounter1~0) (= |old(~__ste_client_idCounter2~0)| ~__ste_client_idCounter2~0))} ~handle := #in~handle;~value := #in~value; {11692#true} is VALID [2022-02-20 18:00:07,195 INFO L290 TraceCheckUtils]: 1: Hoare triple {11692#true} assume 1 == ~handle;~__ste_client_idCounter0~0 := ~value; {11692#true} is VALID [2022-02-20 18:00:07,196 INFO L290 TraceCheckUtils]: 2: Hoare triple {11692#true} assume true; {11692#true} is VALID [2022-02-20 18:00:07,196 INFO L284 TraceCheckUtils]: 3: Hoare quadruple {11692#true} {11693#false} #1142#return; {11693#false} is VALID [2022-02-20 18:00:07,196 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 37 [2022-02-20 18:00:07,197 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-02-20 18:00:07,199 INFO L290 TraceCheckUtils]: 0: Hoare triple {11755#(and (= ~__ste_client_privateKey0~0 |old(~__ste_client_privateKey0~0)|) (= ~__ste_client_privateKey2~0 |old(~__ste_client_privateKey2~0)|) (= ~__ste_client_privateKey1~0 |old(~__ste_client_privateKey1~0)|))} ~handle := #in~handle;~value := #in~value; {11692#true} is VALID [2022-02-20 18:00:07,199 INFO L290 TraceCheckUtils]: 1: Hoare triple {11692#true} assume 1 == ~handle;~__ste_client_privateKey0~0 := ~value; {11692#true} is VALID [2022-02-20 18:00:07,199 INFO L290 TraceCheckUtils]: 2: Hoare triple {11692#true} assume true; {11692#true} is VALID [2022-02-20 18:00:07,199 INFO L284 TraceCheckUtils]: 3: Hoare quadruple {11692#true} {11693#false} #1144#return; {11693#false} is VALID [2022-02-20 18:00:07,209 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 59 [2022-02-20 18:00:07,210 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-02-20 18:00:07,214 INFO L290 TraceCheckUtils]: 0: Hoare triple {11760#(and (= |old(~__ste_email_from0~0)| ~__ste_email_from0~0) (= |old(~__ste_email_from1~0)| ~__ste_email_from1~0))} ~handle := #in~handle;~value := #in~value; {11692#true} is VALID [2022-02-20 18:00:07,214 INFO L290 TraceCheckUtils]: 1: Hoare triple {11692#true} assume 1 == ~handle;~__ste_email_from0~0 := ~value; {11692#true} is VALID [2022-02-20 18:00:07,214 INFO L290 TraceCheckUtils]: 2: Hoare triple {11692#true} assume true; {11692#true} is VALID [2022-02-20 18:00:07,214 INFO L284 TraceCheckUtils]: 3: Hoare quadruple {11692#true} {11693#false} #1120#return; {11693#false} is VALID [2022-02-20 18:00:07,224 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 64 [2022-02-20 18:00:07,226 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-02-20 18:00:07,233 INFO L290 TraceCheckUtils]: 0: Hoare triple {11761#(and (= ~__ste_email_to0~0 |old(~__ste_email_to0~0)|) (= ~__ste_email_to1~0 |old(~__ste_email_to1~0)|))} ~handle := #in~handle;~value := #in~value; {11692#true} is VALID [2022-02-20 18:00:07,233 INFO L290 TraceCheckUtils]: 1: Hoare triple {11692#true} assume 1 == ~handle;~__ste_email_to0~0 := ~value; {11692#true} is VALID [2022-02-20 18:00:07,233 INFO L290 TraceCheckUtils]: 2: Hoare triple {11692#true} assume true; {11692#true} is VALID [2022-02-20 18:00:07,234 INFO L284 TraceCheckUtils]: 3: Hoare quadruple {11692#true} {11693#false} #1122#return; {11693#false} is VALID [2022-02-20 18:00:07,234 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 73 [2022-02-20 18:00:07,235 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-02-20 18:00:07,237 INFO L290 TraceCheckUtils]: 0: Hoare triple {11692#true} ~handle := #in~handle;havoc ~retValue_acc~20; {11692#true} is VALID [2022-02-20 18:00:07,237 INFO L290 TraceCheckUtils]: 1: Hoare triple {11692#true} assume 1 == ~handle;~retValue_acc~20 := ~__ste_client_privateKey0~0;#res := ~retValue_acc~20; {11692#true} is VALID [2022-02-20 18:00:07,237 INFO L290 TraceCheckUtils]: 2: Hoare triple {11692#true} assume true; {11692#true} is VALID [2022-02-20 18:00:07,237 INFO L284 TraceCheckUtils]: 3: Hoare quadruple {11692#true} {11693#false} #1054#return; {11693#false} is VALID [2022-02-20 18:00:07,237 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 81 [2022-02-20 18:00:07,238 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-02-20 18:00:07,240 INFO L290 TraceCheckUtils]: 0: Hoare triple {11692#true} ~handle := #in~handle;havoc ~retValue_acc~36; {11692#true} is VALID [2022-02-20 18:00:07,240 INFO L290 TraceCheckUtils]: 1: Hoare triple {11692#true} assume 1 == ~handle;~retValue_acc~36 := ~__ste_email_to0~0;#res := ~retValue_acc~36; {11692#true} is VALID [2022-02-20 18:00:07,240 INFO L290 TraceCheckUtils]: 2: Hoare triple {11692#true} assume true; {11692#true} is VALID [2022-02-20 18:00:07,240 INFO L284 TraceCheckUtils]: 3: Hoare quadruple {11692#true} {11693#false} #1056#return; {11693#false} is VALID [2022-02-20 18:00:07,241 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 87 [2022-02-20 18:00:07,241 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-02-20 18:00:07,243 INFO L290 TraceCheckUtils]: 0: Hoare triple {11692#true} ~handle := #in~handle;~userid := #in~userid;havoc ~retValue_acc~25; {11692#true} is VALID [2022-02-20 18:00:07,243 INFO L290 TraceCheckUtils]: 1: Hoare triple {11692#true} assume 1 == ~handle; {11692#true} is VALID [2022-02-20 18:00:07,243 INFO L290 TraceCheckUtils]: 2: Hoare triple {11692#true} assume ~userid == ~__ste_Client_Keyring0_User0~0;~retValue_acc~25 := ~__ste_Client_Keyring0_PublicKey0~0;#res := ~retValue_acc~25; {11692#true} is VALID [2022-02-20 18:00:07,243 INFO L290 TraceCheckUtils]: 3: Hoare triple {11692#true} assume true; {11692#true} is VALID [2022-02-20 18:00:07,244 INFO L284 TraceCheckUtils]: 4: Hoare quadruple {11692#true} {11693#false} #1058#return; {11693#false} is VALID [2022-02-20 18:00:07,244 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 98 [2022-02-20 18:00:07,245 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-02-20 18:00:07,253 INFO L290 TraceCheckUtils]: 0: Hoare triple {11760#(and (= |old(~__ste_email_from0~0)| ~__ste_email_from0~0) (= |old(~__ste_email_from1~0)| ~__ste_email_from1~0))} ~handle := #in~handle;~value := #in~value; {11692#true} is VALID [2022-02-20 18:00:07,254 INFO L290 TraceCheckUtils]: 1: Hoare triple {11692#true} assume 1 == ~handle;~__ste_email_from0~0 := ~value; {11692#true} is VALID [2022-02-20 18:00:07,254 INFO L290 TraceCheckUtils]: 2: Hoare triple {11692#true} assume true; {11692#true} is VALID [2022-02-20 18:00:07,254 INFO L284 TraceCheckUtils]: 3: Hoare quadruple {11692#true} {11693#false} #1064#return; {11693#false} is VALID [2022-02-20 18:00:07,254 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 104 [2022-02-20 18:00:07,255 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-02-20 18:00:07,265 INFO L290 TraceCheckUtils]: 0: Hoare triple {11692#true} ~handle := #in~handle;havoc ~retValue_acc~41; {11692#true} is VALID [2022-02-20 18:00:07,266 INFO L290 TraceCheckUtils]: 1: Hoare triple {11692#true} assume 1 == ~handle;~retValue_acc~41 := ~__ste_email_isSigned0~0;#res := ~retValue_acc~41; {11692#true} is VALID [2022-02-20 18:00:07,266 INFO L290 TraceCheckUtils]: 2: Hoare triple {11692#true} assume true; {11692#true} is VALID [2022-02-20 18:00:07,266 INFO L284 TraceCheckUtils]: 3: Hoare quadruple {11692#true} {11693#false} #1066#return; {11693#false} is VALID [2022-02-20 18:00:07,266 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 111 [2022-02-20 18:00:07,267 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-02-20 18:00:07,271 INFO L290 TraceCheckUtils]: 0: Hoare triple {11692#true} ~handle := #in~handle;havoc ~retValue_acc~20; {11692#true} is VALID [2022-02-20 18:00:07,271 INFO L290 TraceCheckUtils]: 1: Hoare triple {11692#true} assume 1 == ~handle;~retValue_acc~20 := ~__ste_client_privateKey0~0;#res := ~retValue_acc~20; {11692#true} is VALID [2022-02-20 18:00:07,271 INFO L290 TraceCheckUtils]: 2: Hoare triple {11692#true} assume true; {11692#true} is VALID [2022-02-20 18:00:07,272 INFO L284 TraceCheckUtils]: 3: Hoare quadruple {11692#true} {11693#false} #1068#return; {11693#false} is VALID [2022-02-20 18:00:07,272 INFO L290 TraceCheckUtils]: 0: Hoare triple {11692#true} assume { :begin_inline_ULTIMATE.init } true;#NULL.base, #NULL.offset := 0, 0;assume 0 == #valid[0];assume 0 < #StackHeapBarrier;call #Ultimate.allocInit(2, 1);call write~init~int(48, 1, 0, 1);call write~init~int(0, 1, 1, 1);call #Ultimate.allocInit(28, 2);call #Ultimate.allocInit(12, 3);call #Ultimate.allocInit(30, 4);call #Ultimate.allocInit(9, 5);call #Ultimate.allocInit(21, 6);call #Ultimate.allocInit(30, 7);call #Ultimate.allocInit(9, 8);call #Ultimate.allocInit(21, 9);call #Ultimate.allocInit(30, 10);call #Ultimate.allocInit(9, 11);call #Ultimate.allocInit(25, 12);call #Ultimate.allocInit(30, 13);call #Ultimate.allocInit(9, 14);call #Ultimate.allocInit(25, 15);call #Ultimate.allocInit(44, 16);call #Ultimate.allocInit(44, 17);call #Ultimate.allocInit(9, 18);call #Ultimate.allocInit(9, 19);call #Ultimate.allocInit(11, 20);call #Ultimate.allocInit(19, 21);call #Ultimate.allocInit(4, 22);call write~init~int(37, 22, 0, 1);call write~init~int(100, 22, 1, 1);call write~init~int(10, 22, 2, 1);call write~init~int(0, 22, 3, 1);call #Ultimate.allocInit(4, 23);call write~init~int(37, 23, 0, 1);call write~init~int(100, 23, 1, 1);call write~init~int(10, 23, 2, 1);call write~init~int(0, 23, 3, 1);call #Ultimate.allocInit(10, 24);call #Ultimate.allocInit(16, 25);call #Ultimate.allocInit(20, 26);call #Ultimate.allocInit(22, 27);call #Ultimate.allocInit(21, 28);call #Ultimate.allocInit(10, 29);call #Ultimate.allocInit(12, 30);call #Ultimate.allocInit(10, 31);call #Ultimate.allocInit(18, 32);call #Ultimate.allocInit(16, 33);call #Ultimate.allocInit(21, 34);call #Ultimate.allocInit(13, 35);call #Ultimate.allocInit(16, 36);call #Ultimate.allocInit(25, 37);call #Ultimate.allocInit(4, 38);call write~init~int(37, 38, 0, 1);call write~init~int(115, 38, 1, 1);call write~init~int(10, 38, 2, 1);call write~init~int(0, 38, 3, 1);call #Ultimate.allocInit(13, 39);~head~0.base, ~head~0.offset := 0, 0;~__SELECTED_FEATURE_Base~0 := 0;~__SELECTED_FEATURE_Keys~0 := 0;~__SELECTED_FEATURE_Encrypt~0 := 0;~__SELECTED_FEATURE_AutoResponder~0 := 0;~__SELECTED_FEATURE_AddressBook~0 := 0;~__SELECTED_FEATURE_Sign~0 := 0;~__SELECTED_FEATURE_Forward~0 := 0;~__SELECTED_FEATURE_Verify~0 := 0;~__SELECTED_FEATURE_Decrypt~0 := 0;~__GUIDSL_ROOT_PRODUCTION~0 := 0;~__GUIDSL_NON_TERMINAL_main~0 := 0;~bob~0 := 0;~rjh~0 := 0;~chuck~0 := 0;~queue_empty~0 := 1;~queued_message~0 := 0;~queued_client~0 := 0;~__ste_Client_counter~0 := 0;~__ste_client_name0~0.base, ~__ste_client_name0~0.offset := 0, 0;~__ste_client_name1~0.base, ~__ste_client_name1~0.offset := 0, 0;~__ste_client_name2~0.base, ~__ste_client_name2~0.offset := 0, 0;~__ste_client_outbuffer0~0 := 0;~__ste_client_outbuffer1~0 := 0;~__ste_client_outbuffer2~0 := 0;~__ste_client_outbuffer3~0 := 0;~__ste_ClientAddressBook_size0~0 := 0;~__ste_ClientAddressBook_size1~0 := 0;~__ste_ClientAddressBook_size2~0 := 0;~__ste_Client_AddressBook0_Alias0~0 := 0;~__ste_Client_AddressBook0_Alias1~0 := 0;~__ste_Client_AddressBook0_Alias2~0 := 0;~__ste_Client_AddressBook1_Alias0~0 := 0;~__ste_Client_AddressBook1_Alias1~0 := 0;~__ste_Client_AddressBook1_Alias2~0 := 0;~__ste_Client_AddressBook2_Alias0~0 := 0;~__ste_Client_AddressBook2_Alias1~0 := 0;~__ste_Client_AddressBook2_Alias2~0 := 0;~__ste_Client_AddressBook0_Address0~0 := 0;~__ste_Client_AddressBook0_Address1~0 := 0;~__ste_Client_AddressBook0_Address2~0 := 0;~__ste_Client_AddressBook1_Address0~0 := 0;~__ste_Client_AddressBook1_Address1~0 := 0;~__ste_Client_AddressBook1_Address2~0 := 0;~__ste_Client_AddressBook2_Address0~0 := 0;~__ste_Client_AddressBook2_Address1~0 := 0;~__ste_Client_AddressBook2_Address2~0 := 0;~__ste_client_autoResponse0~0 := 0;~__ste_client_autoResponse1~0 := 0;~__ste_client_autoResponse2~0 := 0;~__ste_client_privateKey0~0 := 0;~__ste_client_privateKey1~0 := 0;~__ste_client_privateKey2~0 := 0;~__ste_ClientKeyring_size0~0 := 0;~__ste_ClientKeyring_size1~0 := 0;~__ste_ClientKeyring_size2~0 := 0;~__ste_Client_Keyring0_User0~0 := 0;~__ste_Client_Keyring0_User1~0 := 0;~__ste_Client_Keyring0_User2~0 := 0;~__ste_Client_Keyring1_User0~0 := 0;~__ste_Client_Keyring1_User1~0 := 0;~__ste_Client_Keyring1_User2~0 := 0;~__ste_Client_Keyring2_User0~0 := 0;~__ste_Client_Keyring2_User1~0 := 0;~__ste_Client_Keyring2_User2~0 := 0;~__ste_Client_Keyring0_PublicKey0~0 := 0;~__ste_Client_Keyring0_PublicKey1~0 := 0;~__ste_Client_Keyring0_PublicKey2~0 := 0;~__ste_Client_Keyring1_PublicKey0~0 := 0;~__ste_Client_Keyring1_PublicKey1~0 := 0;~__ste_Client_Keyring1_PublicKey2~0 := 0;~__ste_Client_Keyring2_PublicKey0~0 := 0;~__ste_Client_Keyring2_PublicKey1~0 := 0;~__ste_Client_Keyring2_PublicKey2~0 := 0;~__ste_client_forwardReceiver0~0 := 0;~__ste_client_forwardReceiver1~0 := 0;~__ste_client_forwardReceiver2~0 := 0;~__ste_client_forwardReceiver3~0 := 0;~__ste_client_idCounter0~0 := 0;~__ste_client_idCounter1~0 := 0;~__ste_client_idCounter2~0 := 0;~__ste_Email_counter~0 := 0;~__ste_email_id0~0 := 0;~__ste_email_id1~0 := 0;~__ste_email_from0~0 := 0;~__ste_email_from1~0 := 0;~__ste_email_to0~0 := 0;~__ste_email_to1~0 := 0;~__ste_email_subject0~0.base, ~__ste_email_subject0~0.offset := 0, 0;~__ste_email_subject1~0.base, ~__ste_email_subject1~0.offset := 0, 0;~__ste_email_body0~0.base, ~__ste_email_body0~0.offset := 0, 0;~__ste_email_body1~0.base, ~__ste_email_body1~0.offset := 0, 0;~__ste_email_isEncrypted0~0 := 0;~__ste_email_isEncrypted1~0 := 0;~__ste_email_encryptionKey0~0 := 0;~__ste_email_encryptionKey1~0 := 0;~__ste_email_isSigned0~0 := 0;~__ste_email_isSigned1~0 := 0;~__ste_email_signKey0~0 := 0;~__ste_email_signKey1~0 := 0;~__ste_email_isSignatureVerified0~0 := 0;~__ste_email_isSignatureVerified1~0 := 0; {11692#true} is VALID [2022-02-20 18:00:07,272 INFO L290 TraceCheckUtils]: 1: Hoare triple {11692#true} assume { :end_inline_ULTIMATE.init } true;assume { :begin_inline_main } true;havoc main_#res#1;havoc main_#t~ret35#1, main_~retValue_acc~3#1, main_~tmp~4#1;havoc main_~retValue_acc~3#1;havoc main_~tmp~4#1;assume { :begin_inline_select_helpers } true; {11692#true} is VALID [2022-02-20 18:00:07,272 INFO L290 TraceCheckUtils]: 2: Hoare triple {11692#true} assume { :end_inline_select_helpers } true;assume { :begin_inline_select_features } true; {11692#true} is VALID [2022-02-20 18:00:07,272 INFO L290 TraceCheckUtils]: 3: Hoare triple {11692#true} assume { :end_inline_select_features } true;assume { :begin_inline_valid_product } true;havoc valid_product_#res#1;havoc valid_product_~retValue_acc~5#1;havoc valid_product_~retValue_acc~5#1;valid_product_~retValue_acc~5#1 := 1;valid_product_#res#1 := valid_product_~retValue_acc~5#1; {11692#true} is VALID [2022-02-20 18:00:07,272 INFO L290 TraceCheckUtils]: 4: Hoare triple {11692#true} main_#t~ret35#1 := valid_product_#res#1;assume { :end_inline_valid_product } true;assume -2147483648 <= main_#t~ret35#1 && main_#t~ret35#1 <= 2147483647;main_~tmp~4#1 := main_#t~ret35#1;havoc main_#t~ret35#1; {11692#true} is VALID [2022-02-20 18:00:07,272 INFO L290 TraceCheckUtils]: 5: Hoare triple {11692#true} assume 0 != main_~tmp~4#1;assume { :begin_inline_setup } true;havoc setup_#t~nondet32#1, setup_#t~nondet33#1, setup_#t~nondet34#1, setup_~__cil_tmp1~0#1.base, setup_~__cil_tmp1~0#1.offset, setup_~__cil_tmp2~0#1.base, setup_~__cil_tmp2~0#1.offset, setup_~__cil_tmp3~0#1.base, setup_~__cil_tmp3~0#1.offset;havoc setup_~__cil_tmp1~0#1.base, setup_~__cil_tmp1~0#1.offset;havoc setup_~__cil_tmp2~0#1.base, setup_~__cil_tmp2~0#1.offset;havoc setup_~__cil_tmp3~0#1.base, setup_~__cil_tmp3~0#1.offset;~bob~0 := 1;assume { :begin_inline_setup_bob } true;setup_bob_#in~bob___0#1 := ~bob~0;havoc setup_bob_~bob___0#1;setup_bob_~bob___0#1 := setup_bob_#in~bob___0#1;assume { :begin_inline_setup_bob__wrappee__Base } true;setup_bob__wrappee__Base_#in~bob___0#1 := setup_bob_~bob___0#1;havoc setup_bob__wrappee__Base_~bob___0#1;setup_bob__wrappee__Base_~bob___0#1 := setup_bob__wrappee__Base_#in~bob___0#1; {11692#true} is VALID [2022-02-20 18:00:07,273 INFO L272 TraceCheckUtils]: 6: Hoare triple {11692#true} call setClientId(setup_bob__wrappee__Base_~bob___0#1, setup_bob__wrappee__Base_~bob___0#1); {11754#(and (= |old(~__ste_client_idCounter0~0)| ~__ste_client_idCounter0~0) (= |old(~__ste_client_idCounter1~0)| ~__ste_client_idCounter1~0) (= |old(~__ste_client_idCounter2~0)| ~__ste_client_idCounter2~0))} is VALID [2022-02-20 18:00:07,273 INFO L290 TraceCheckUtils]: 7: Hoare triple {11754#(and (= |old(~__ste_client_idCounter0~0)| ~__ste_client_idCounter0~0) (= |old(~__ste_client_idCounter1~0)| ~__ste_client_idCounter1~0) (= |old(~__ste_client_idCounter2~0)| ~__ste_client_idCounter2~0))} ~handle := #in~handle;~value := #in~value; {11692#true} is VALID [2022-02-20 18:00:07,273 INFO L290 TraceCheckUtils]: 8: Hoare triple {11692#true} assume 1 == ~handle;~__ste_client_idCounter0~0 := ~value; {11692#true} is VALID [2022-02-20 18:00:07,273 INFO L290 TraceCheckUtils]: 9: Hoare triple {11692#true} assume true; {11692#true} is VALID [2022-02-20 18:00:07,274 INFO L284 TraceCheckUtils]: 10: Hoare quadruple {11692#true} {11692#true} #1134#return; {11692#true} is VALID [2022-02-20 18:00:07,274 INFO L290 TraceCheckUtils]: 11: Hoare triple {11692#true} assume { :end_inline_setup_bob__wrappee__Base } true; {11692#true} is VALID [2022-02-20 18:00:07,274 INFO L272 TraceCheckUtils]: 12: Hoare triple {11692#true} call setClientPrivateKey(setup_bob_~bob___0#1, 123); {11755#(and (= ~__ste_client_privateKey0~0 |old(~__ste_client_privateKey0~0)|) (= ~__ste_client_privateKey2~0 |old(~__ste_client_privateKey2~0)|) (= ~__ste_client_privateKey1~0 |old(~__ste_client_privateKey1~0)|))} is VALID [2022-02-20 18:00:07,275 INFO L290 TraceCheckUtils]: 13: Hoare triple {11755#(and (= ~__ste_client_privateKey0~0 |old(~__ste_client_privateKey0~0)|) (= ~__ste_client_privateKey2~0 |old(~__ste_client_privateKey2~0)|) (= ~__ste_client_privateKey1~0 |old(~__ste_client_privateKey1~0)|))} ~handle := #in~handle;~value := #in~value; {11692#true} is VALID [2022-02-20 18:00:07,275 INFO L290 TraceCheckUtils]: 14: Hoare triple {11692#true} assume 1 == ~handle;~__ste_client_privateKey0~0 := ~value; {11692#true} is VALID [2022-02-20 18:00:07,275 INFO L290 TraceCheckUtils]: 15: Hoare triple {11692#true} assume true; {11692#true} is VALID [2022-02-20 18:00:07,275 INFO L284 TraceCheckUtils]: 16: Hoare quadruple {11692#true} {11692#true} #1136#return; {11692#true} is VALID [2022-02-20 18:00:07,275 INFO L290 TraceCheckUtils]: 17: Hoare triple {11692#true} assume { :end_inline_setup_bob } true;setup_~__cil_tmp1~0#1.base, setup_~__cil_tmp1~0#1.offset := 18, 0;havoc setup_#t~nondet32#1;~rjh~0 := 2;assume { :begin_inline_setup_rjh } true;setup_rjh_#in~rjh___0#1 := ~rjh~0;havoc setup_rjh_~rjh___0#1;setup_rjh_~rjh___0#1 := setup_rjh_#in~rjh___0#1;assume { :begin_inline_setup_rjh__wrappee__Base } true;setup_rjh__wrappee__Base_#in~rjh___0#1 := setup_rjh_~rjh___0#1;havoc setup_rjh__wrappee__Base_~rjh___0#1;setup_rjh__wrappee__Base_~rjh___0#1 := setup_rjh__wrappee__Base_#in~rjh___0#1; {11702#(= |ULTIMATE.start_setup_rjh_~rjh___0#1| |ULTIMATE.start_setup_rjh__wrappee__Base_~rjh___0#1|)} is VALID [2022-02-20 18:00:07,276 INFO L272 TraceCheckUtils]: 18: Hoare triple {11702#(= |ULTIMATE.start_setup_rjh_~rjh___0#1| |ULTIMATE.start_setup_rjh__wrappee__Base_~rjh___0#1|)} call setClientId(setup_rjh__wrappee__Base_~rjh___0#1, setup_rjh__wrappee__Base_~rjh___0#1); {11754#(and (= |old(~__ste_client_idCounter0~0)| ~__ste_client_idCounter0~0) (= |old(~__ste_client_idCounter1~0)| ~__ste_client_idCounter1~0) (= |old(~__ste_client_idCounter2~0)| ~__ste_client_idCounter2~0))} is VALID [2022-02-20 18:00:07,276 INFO L290 TraceCheckUtils]: 19: Hoare triple {11754#(and (= |old(~__ste_client_idCounter0~0)| ~__ste_client_idCounter0~0) (= |old(~__ste_client_idCounter1~0)| ~__ste_client_idCounter1~0) (= |old(~__ste_client_idCounter2~0)| ~__ste_client_idCounter2~0))} ~handle := #in~handle;~value := #in~value; {11756#(= setClientId_~handle |setClientId_#in~handle|)} is VALID [2022-02-20 18:00:07,277 INFO L290 TraceCheckUtils]: 20: Hoare triple {11756#(= setClientId_~handle |setClientId_#in~handle|)} assume !(1 == ~handle); {11756#(= setClientId_~handle |setClientId_#in~handle|)} is VALID [2022-02-20 18:00:07,277 INFO L290 TraceCheckUtils]: 21: Hoare triple {11756#(= setClientId_~handle |setClientId_#in~handle|)} assume 2 == ~handle;~__ste_client_idCounter1~0 := ~value; {11757#(= 2 |setClientId_#in~handle|)} is VALID [2022-02-20 18:00:07,278 INFO L290 TraceCheckUtils]: 22: Hoare triple {11757#(= 2 |setClientId_#in~handle|)} assume true; {11757#(= 2 |setClientId_#in~handle|)} is VALID [2022-02-20 18:00:07,278 INFO L284 TraceCheckUtils]: 23: Hoare quadruple {11757#(= 2 |setClientId_#in~handle|)} {11702#(= |ULTIMATE.start_setup_rjh_~rjh___0#1| |ULTIMATE.start_setup_rjh__wrappee__Base_~rjh___0#1|)} #1138#return; {11708#(not (= |ULTIMATE.start_setup_rjh_~rjh___0#1| 1))} is VALID [2022-02-20 18:00:07,278 INFO L290 TraceCheckUtils]: 24: Hoare triple {11708#(not (= |ULTIMATE.start_setup_rjh_~rjh___0#1| 1))} assume { :end_inline_setup_rjh__wrappee__Base } true; {11708#(not (= |ULTIMATE.start_setup_rjh_~rjh___0#1| 1))} is VALID [2022-02-20 18:00:07,279 INFO L272 TraceCheckUtils]: 25: Hoare triple {11708#(not (= |ULTIMATE.start_setup_rjh_~rjh___0#1| 1))} call setClientPrivateKey(setup_rjh_~rjh___0#1, 456); {11755#(and (= ~__ste_client_privateKey0~0 |old(~__ste_client_privateKey0~0)|) (= ~__ste_client_privateKey2~0 |old(~__ste_client_privateKey2~0)|) (= ~__ste_client_privateKey1~0 |old(~__ste_client_privateKey1~0)|))} is VALID [2022-02-20 18:00:07,280 INFO L290 TraceCheckUtils]: 26: Hoare triple {11755#(and (= ~__ste_client_privateKey0~0 |old(~__ste_client_privateKey0~0)|) (= ~__ste_client_privateKey2~0 |old(~__ste_client_privateKey2~0)|) (= ~__ste_client_privateKey1~0 |old(~__ste_client_privateKey1~0)|))} ~handle := #in~handle;~value := #in~value; {11758#(= setClientPrivateKey_~handle |setClientPrivateKey_#in~handle|)} is VALID [2022-02-20 18:00:07,280 INFO L290 TraceCheckUtils]: 27: Hoare triple {11758#(= setClientPrivateKey_~handle |setClientPrivateKey_#in~handle|)} assume 1 == ~handle;~__ste_client_privateKey0~0 := ~value; {11759#(= |setClientPrivateKey_#in~handle| 1)} is VALID [2022-02-20 18:00:07,280 INFO L290 TraceCheckUtils]: 28: Hoare triple {11759#(= |setClientPrivateKey_#in~handle| 1)} assume true; {11759#(= |setClientPrivateKey_#in~handle| 1)} is VALID [2022-02-20 18:00:07,281 INFO L284 TraceCheckUtils]: 29: Hoare quadruple {11759#(= |setClientPrivateKey_#in~handle| 1)} {11708#(not (= |ULTIMATE.start_setup_rjh_~rjh___0#1| 1))} #1140#return; {11693#false} is VALID [2022-02-20 18:00:07,281 INFO L290 TraceCheckUtils]: 30: Hoare triple {11693#false} assume { :end_inline_setup_rjh } true;setup_~__cil_tmp2~0#1.base, setup_~__cil_tmp2~0#1.offset := 19, 0;havoc setup_#t~nondet33#1;~chuck~0 := 3;assume { :begin_inline_setup_chuck } true;setup_chuck_#in~chuck___0#1 := ~chuck~0;havoc setup_chuck_~chuck___0#1;setup_chuck_~chuck___0#1 := setup_chuck_#in~chuck___0#1;assume { :begin_inline_setup_chuck__wrappee__Base } true;setup_chuck__wrappee__Base_#in~chuck___0#1 := setup_chuck_~chuck___0#1;havoc setup_chuck__wrappee__Base_~chuck___0#1;setup_chuck__wrappee__Base_~chuck___0#1 := setup_chuck__wrappee__Base_#in~chuck___0#1; {11693#false} is VALID [2022-02-20 18:00:07,281 INFO L272 TraceCheckUtils]: 31: Hoare triple {11693#false} call setClientId(setup_chuck__wrappee__Base_~chuck___0#1, setup_chuck__wrappee__Base_~chuck___0#1); {11754#(and (= |old(~__ste_client_idCounter0~0)| ~__ste_client_idCounter0~0) (= |old(~__ste_client_idCounter1~0)| ~__ste_client_idCounter1~0) (= |old(~__ste_client_idCounter2~0)| ~__ste_client_idCounter2~0))} is VALID [2022-02-20 18:00:07,281 INFO L290 TraceCheckUtils]: 32: Hoare triple {11754#(and (= |old(~__ste_client_idCounter0~0)| ~__ste_client_idCounter0~0) (= |old(~__ste_client_idCounter1~0)| ~__ste_client_idCounter1~0) (= |old(~__ste_client_idCounter2~0)| ~__ste_client_idCounter2~0))} ~handle := #in~handle;~value := #in~value; {11692#true} is VALID [2022-02-20 18:00:07,281 INFO L290 TraceCheckUtils]: 33: Hoare triple {11692#true} assume 1 == ~handle;~__ste_client_idCounter0~0 := ~value; {11692#true} is VALID [2022-02-20 18:00:07,282 INFO L290 TraceCheckUtils]: 34: Hoare triple {11692#true} assume true; {11692#true} is VALID [2022-02-20 18:00:07,282 INFO L284 TraceCheckUtils]: 35: Hoare quadruple {11692#true} {11693#false} #1142#return; {11693#false} is VALID [2022-02-20 18:00:07,282 INFO L290 TraceCheckUtils]: 36: Hoare triple {11693#false} assume { :end_inline_setup_chuck__wrappee__Base } true; {11693#false} is VALID [2022-02-20 18:00:07,282 INFO L272 TraceCheckUtils]: 37: Hoare triple {11693#false} call setClientPrivateKey(setup_chuck_~chuck___0#1, 789); {11755#(and (= ~__ste_client_privateKey0~0 |old(~__ste_client_privateKey0~0)|) (= ~__ste_client_privateKey2~0 |old(~__ste_client_privateKey2~0)|) (= ~__ste_client_privateKey1~0 |old(~__ste_client_privateKey1~0)|))} is VALID [2022-02-20 18:00:07,282 INFO L290 TraceCheckUtils]: 38: Hoare triple {11755#(and (= ~__ste_client_privateKey0~0 |old(~__ste_client_privateKey0~0)|) (= ~__ste_client_privateKey2~0 |old(~__ste_client_privateKey2~0)|) (= ~__ste_client_privateKey1~0 |old(~__ste_client_privateKey1~0)|))} ~handle := #in~handle;~value := #in~value; {11692#true} is VALID [2022-02-20 18:00:07,282 INFO L290 TraceCheckUtils]: 39: Hoare triple {11692#true} assume 1 == ~handle;~__ste_client_privateKey0~0 := ~value; {11692#true} is VALID [2022-02-20 18:00:07,282 INFO L290 TraceCheckUtils]: 40: Hoare triple {11692#true} assume true; {11692#true} is VALID [2022-02-20 18:00:07,282 INFO L284 TraceCheckUtils]: 41: Hoare quadruple {11692#true} {11693#false} #1144#return; {11693#false} is VALID [2022-02-20 18:00:07,283 INFO L290 TraceCheckUtils]: 42: Hoare triple {11693#false} assume { :end_inline_setup_chuck } true;setup_~__cil_tmp3~0#1.base, setup_~__cil_tmp3~0#1.offset := 20, 0;havoc setup_#t~nondet34#1; {11693#false} is VALID [2022-02-20 18:00:07,283 INFO L290 TraceCheckUtils]: 43: Hoare triple {11693#false} assume { :end_inline_setup } true;assume { :begin_inline_test } true;havoc test_#t~nondet47#1, test_#t~nondet48#1, test_#t~nondet49#1, test_#t~nondet50#1, test_#t~nondet51#1, test_#t~nondet52#1, test_#t~nondet53#1, test_#t~nondet54#1, test_#t~nondet55#1, test_#t~nondet56#1, test_#t~nondet57#1, test_~op1~0#1, test_~op2~0#1, test_~op3~0#1, test_~op4~0#1, test_~op5~0#1, test_~op6~0#1, test_~op7~0#1, test_~op8~0#1, test_~op9~0#1, test_~op10~0#1, test_~op11~0#1, test_~splverifierCounter~0#1, test_~tmp~6#1, test_~tmp___0~2#1, test_~tmp___1~1#1, test_~tmp___2~0#1, test_~tmp___3~0#1, test_~tmp___4~0#1, test_~tmp___5~0#1, test_~tmp___6~0#1, test_~tmp___7~0#1, test_~tmp___8~0#1, test_~tmp___9~0#1;havoc test_~op1~0#1;havoc test_~op2~0#1;havoc test_~op3~0#1;havoc test_~op4~0#1;havoc test_~op5~0#1;havoc test_~op6~0#1;havoc test_~op7~0#1;havoc test_~op8~0#1;havoc test_~op9~0#1;havoc test_~op10~0#1;havoc test_~op11~0#1;havoc test_~splverifierCounter~0#1;havoc test_~tmp~6#1;havoc test_~tmp___0~2#1;havoc test_~tmp___1~1#1;havoc test_~tmp___2~0#1;havoc test_~tmp___3~0#1;havoc test_~tmp___4~0#1;havoc test_~tmp___5~0#1;havoc test_~tmp___6~0#1;havoc test_~tmp___7~0#1;havoc test_~tmp___8~0#1;havoc test_~tmp___9~0#1;test_~op1~0#1 := 0;test_~op2~0#1 := 0;test_~op3~0#1 := 0;test_~op4~0#1 := 0;test_~op5~0#1 := 0;test_~op6~0#1 := 0;test_~op7~0#1 := 0;test_~op8~0#1 := 0;test_~op9~0#1 := 0;test_~op10~0#1 := 0;test_~op11~0#1 := 0;test_~splverifierCounter~0#1 := 0; {11693#false} is VALID [2022-02-20 18:00:07,283 INFO L290 TraceCheckUtils]: 44: Hoare triple {11693#false} assume !false; {11693#false} is VALID [2022-02-20 18:00:07,283 INFO L290 TraceCheckUtils]: 45: Hoare triple {11693#false} assume test_~splverifierCounter~0#1 < 4; {11693#false} is VALID [2022-02-20 18:00:07,283 INFO L290 TraceCheckUtils]: 46: Hoare triple {11693#false} test_~splverifierCounter~0#1 := 1 + test_~splverifierCounter~0#1; {11693#false} is VALID [2022-02-20 18:00:07,283 INFO L290 TraceCheckUtils]: 47: Hoare triple {11693#false} assume 0 == test_~op1~0#1;assume -2147483648 <= test_#t~nondet47#1 && test_#t~nondet47#1 <= 2147483647;test_~tmp___9~0#1 := test_#t~nondet47#1;havoc test_#t~nondet47#1; {11693#false} is VALID [2022-02-20 18:00:07,283 INFO L290 TraceCheckUtils]: 48: Hoare triple {11693#false} assume !(0 != test_~tmp___9~0#1); {11693#false} is VALID [2022-02-20 18:00:07,284 INFO L290 TraceCheckUtils]: 49: Hoare triple {11693#false} assume 0 == test_~op2~0#1;assume -2147483648 <= test_#t~nondet48#1 && test_#t~nondet48#1 <= 2147483647;test_~tmp___8~0#1 := test_#t~nondet48#1;havoc test_#t~nondet48#1; {11693#false} is VALID [2022-02-20 18:00:07,284 INFO L290 TraceCheckUtils]: 50: Hoare triple {11693#false} assume 0 != test_~tmp___8~0#1;assume { :begin_inline_rjhSetAutoRespond } true;assume { :begin_inline_setClientAutoResponse } true;setClientAutoResponse_#in~handle#1, setClientAutoResponse_#in~value#1 := ~rjh~0, 1;havoc setClientAutoResponse_~handle#1, setClientAutoResponse_~value#1;setClientAutoResponse_~handle#1 := setClientAutoResponse_#in~handle#1;setClientAutoResponse_~value#1 := setClientAutoResponse_#in~value#1; {11693#false} is VALID [2022-02-20 18:00:07,284 INFO L290 TraceCheckUtils]: 51: Hoare triple {11693#false} assume 1 == setClientAutoResponse_~handle#1;~__ste_client_autoResponse0~0 := setClientAutoResponse_~value#1; {11693#false} is VALID [2022-02-20 18:00:07,284 INFO L290 TraceCheckUtils]: 52: Hoare triple {11693#false} assume { :end_inline_setClientAutoResponse } true; {11693#false} is VALID [2022-02-20 18:00:07,284 INFO L290 TraceCheckUtils]: 53: Hoare triple {11693#false} assume { :end_inline_rjhSetAutoRespond } true;test_~op2~0#1 := 1; {11693#false} is VALID [2022-02-20 18:00:07,284 INFO L290 TraceCheckUtils]: 54: Hoare triple {11693#false} assume !false; {11693#false} is VALID [2022-02-20 18:00:07,284 INFO L290 TraceCheckUtils]: 55: Hoare triple {11693#false} assume !(test_~splverifierCounter~0#1 < 4); {11693#false} is VALID [2022-02-20 18:00:07,284 INFO L290 TraceCheckUtils]: 56: Hoare triple {11693#false} assume { :begin_inline_bobToRjh } true;havoc bobToRjh_#t~ret27#1, bobToRjh_#t~ret28#1, bobToRjh_#t~ret29#1, bobToRjh_#t~ret30#1, bobToRjh_~tmp~3#1, bobToRjh_~tmp___0~0#1, bobToRjh_~tmp___1~0#1;havoc bobToRjh_~tmp~3#1;havoc bobToRjh_~tmp___0~0#1;havoc bobToRjh_~tmp___1~0#1;call bobToRjh_#t~ret27#1 := puts(16, 0);assume -2147483648 <= bobToRjh_#t~ret27#1 && bobToRjh_#t~ret27#1 <= 2147483647;havoc bobToRjh_#t~ret27#1; {11693#false} is VALID [2022-02-20 18:00:07,285 INFO L272 TraceCheckUtils]: 57: Hoare triple {11693#false} call sendEmail(~bob~0, ~rjh~0); {11693#false} is VALID [2022-02-20 18:00:07,285 INFO L290 TraceCheckUtils]: 58: Hoare triple {11693#false} ~sender#1 := #in~sender#1;~receiver#1 := #in~receiver#1;havoc ~email~0#1;havoc ~tmp~14#1;assume { :begin_inline_createEmail } true;createEmail_#in~from#1, createEmail_#in~to#1 := 0, ~receiver#1;havoc createEmail_#res#1;havoc createEmail_~from#1, createEmail_~to#1, createEmail_~retValue_acc~31#1, createEmail_~msg~0#1;createEmail_~from#1 := createEmail_#in~from#1;createEmail_~to#1 := createEmail_#in~to#1;havoc createEmail_~retValue_acc~31#1;havoc createEmail_~msg~0#1;createEmail_~msg~0#1 := 1; {11693#false} is VALID [2022-02-20 18:00:07,285 INFO L272 TraceCheckUtils]: 59: Hoare triple {11693#false} call setEmailFrom(createEmail_~msg~0#1, createEmail_~from#1); {11760#(and (= |old(~__ste_email_from0~0)| ~__ste_email_from0~0) (= |old(~__ste_email_from1~0)| ~__ste_email_from1~0))} is VALID [2022-02-20 18:00:07,285 INFO L290 TraceCheckUtils]: 60: Hoare triple {11760#(and (= |old(~__ste_email_from0~0)| ~__ste_email_from0~0) (= |old(~__ste_email_from1~0)| ~__ste_email_from1~0))} ~handle := #in~handle;~value := #in~value; {11692#true} is VALID [2022-02-20 18:00:07,285 INFO L290 TraceCheckUtils]: 61: Hoare triple {11692#true} assume 1 == ~handle;~__ste_email_from0~0 := ~value; {11692#true} is VALID [2022-02-20 18:00:07,285 INFO L290 TraceCheckUtils]: 62: Hoare triple {11692#true} assume true; {11692#true} is VALID [2022-02-20 18:00:07,285 INFO L284 TraceCheckUtils]: 63: Hoare quadruple {11692#true} {11693#false} #1120#return; {11693#false} is VALID [2022-02-20 18:00:07,286 INFO L272 TraceCheckUtils]: 64: Hoare triple {11693#false} call setEmailTo(createEmail_~msg~0#1, createEmail_~to#1); {11761#(and (= ~__ste_email_to0~0 |old(~__ste_email_to0~0)|) (= ~__ste_email_to1~0 |old(~__ste_email_to1~0)|))} is VALID [2022-02-20 18:00:07,286 INFO L290 TraceCheckUtils]: 65: Hoare triple {11761#(and (= ~__ste_email_to0~0 |old(~__ste_email_to0~0)|) (= ~__ste_email_to1~0 |old(~__ste_email_to1~0)|))} ~handle := #in~handle;~value := #in~value; {11692#true} is VALID [2022-02-20 18:00:07,286 INFO L290 TraceCheckUtils]: 66: Hoare triple {11692#true} assume 1 == ~handle;~__ste_email_to0~0 := ~value; {11692#true} is VALID [2022-02-20 18:00:07,286 INFO L290 TraceCheckUtils]: 67: Hoare triple {11692#true} assume true; {11692#true} is VALID [2022-02-20 18:00:07,286 INFO L284 TraceCheckUtils]: 68: Hoare quadruple {11692#true} {11693#false} #1122#return; {11693#false} is VALID [2022-02-20 18:00:07,286 INFO L290 TraceCheckUtils]: 69: Hoare triple {11693#false} createEmail_~retValue_acc~31#1 := createEmail_~msg~0#1;createEmail_#res#1 := createEmail_~retValue_acc~31#1; {11693#false} is VALID [2022-02-20 18:00:07,286 INFO L290 TraceCheckUtils]: 70: Hoare triple {11693#false} #t~ret72#1 := createEmail_#res#1;assume { :end_inline_createEmail } true;assume -2147483648 <= #t~ret72#1 && #t~ret72#1 <= 2147483647;~tmp~14#1 := #t~ret72#1;havoc #t~ret72#1;~email~0#1 := ~tmp~14#1; {11693#false} is VALID [2022-02-20 18:00:07,286 INFO L272 TraceCheckUtils]: 71: Hoare triple {11693#false} call outgoing(~sender#1, ~email~0#1); {11693#false} is VALID [2022-02-20 18:00:07,287 INFO L290 TraceCheckUtils]: 72: Hoare triple {11693#false} ~client#1 := #in~client#1;~msg#1 := #in~msg#1;assume { :begin_inline_sign } true;sign_#in~client#1, sign_#in~msg#1 := ~client#1, ~msg#1;havoc sign_#t~ret76#1, sign_~client#1, sign_~msg#1, sign_~privkey~1#1, sign_~tmp~16#1;sign_~client#1 := sign_#in~client#1;sign_~msg#1 := sign_#in~msg#1;havoc sign_~privkey~1#1;havoc sign_~tmp~16#1; {11693#false} is VALID [2022-02-20 18:00:07,287 INFO L272 TraceCheckUtils]: 73: Hoare triple {11693#false} call sign_#t~ret76#1 := getClientPrivateKey(sign_~client#1); {11692#true} is VALID [2022-02-20 18:00:07,287 INFO L290 TraceCheckUtils]: 74: Hoare triple {11692#true} ~handle := #in~handle;havoc ~retValue_acc~20; {11692#true} is VALID [2022-02-20 18:00:07,287 INFO L290 TraceCheckUtils]: 75: Hoare triple {11692#true} assume 1 == ~handle;~retValue_acc~20 := ~__ste_client_privateKey0~0;#res := ~retValue_acc~20; {11692#true} is VALID [2022-02-20 18:00:07,287 INFO L290 TraceCheckUtils]: 76: Hoare triple {11692#true} assume true; {11692#true} is VALID [2022-02-20 18:00:07,287 INFO L284 TraceCheckUtils]: 77: Hoare quadruple {11692#true} {11693#false} #1054#return; {11693#false} is VALID [2022-02-20 18:00:07,287 INFO L290 TraceCheckUtils]: 78: Hoare triple {11693#false} assume -2147483648 <= sign_#t~ret76#1 && sign_#t~ret76#1 <= 2147483647;sign_~tmp~16#1 := sign_#t~ret76#1;havoc sign_#t~ret76#1;sign_~privkey~1#1 := sign_~tmp~16#1; {11693#false} is VALID [2022-02-20 18:00:07,288 INFO L290 TraceCheckUtils]: 79: Hoare triple {11693#false} assume 0 == sign_~privkey~1#1; {11693#false} is VALID [2022-02-20 18:00:07,288 INFO L290 TraceCheckUtils]: 80: Hoare triple {11693#false} assume { :end_inline_sign } true;assume { :begin_inline_outgoing__wrappee__AutoResponder } true;outgoing__wrappee__AutoResponder_#in~client#1, outgoing__wrappee__AutoResponder_#in~msg#1 := ~client#1, ~msg#1;havoc outgoing__wrappee__AutoResponder_#t~ret62#1, outgoing__wrappee__AutoResponder_#t~ret63#1, outgoing__wrappee__AutoResponder_~client#1, outgoing__wrappee__AutoResponder_~msg#1, outgoing__wrappee__AutoResponder_~receiver~0#1, outgoing__wrappee__AutoResponder_~tmp~9#1, outgoing__wrappee__AutoResponder_~pubkey~0#1, outgoing__wrappee__AutoResponder_~tmp___0~3#1;outgoing__wrappee__AutoResponder_~client#1 := outgoing__wrappee__AutoResponder_#in~client#1;outgoing__wrappee__AutoResponder_~msg#1 := outgoing__wrappee__AutoResponder_#in~msg#1;havoc outgoing__wrappee__AutoResponder_~receiver~0#1;havoc outgoing__wrappee__AutoResponder_~tmp~9#1;havoc outgoing__wrappee__AutoResponder_~pubkey~0#1;havoc outgoing__wrappee__AutoResponder_~tmp___0~3#1; {11693#false} is VALID [2022-02-20 18:00:07,288 INFO L272 TraceCheckUtils]: 81: Hoare triple {11693#false} call outgoing__wrappee__AutoResponder_#t~ret62#1 := getEmailTo(outgoing__wrappee__AutoResponder_~msg#1); {11692#true} is VALID [2022-02-20 18:00:07,288 INFO L290 TraceCheckUtils]: 82: Hoare triple {11692#true} ~handle := #in~handle;havoc ~retValue_acc~36; {11692#true} is VALID [2022-02-20 18:00:07,288 INFO L290 TraceCheckUtils]: 83: Hoare triple {11692#true} assume 1 == ~handle;~retValue_acc~36 := ~__ste_email_to0~0;#res := ~retValue_acc~36; {11692#true} is VALID [2022-02-20 18:00:07,288 INFO L290 TraceCheckUtils]: 84: Hoare triple {11692#true} assume true; {11692#true} is VALID [2022-02-20 18:00:07,288 INFO L284 TraceCheckUtils]: 85: Hoare quadruple {11692#true} {11693#false} #1056#return; {11693#false} is VALID [2022-02-20 18:00:07,288 INFO L290 TraceCheckUtils]: 86: Hoare triple {11693#false} assume -2147483648 <= outgoing__wrappee__AutoResponder_#t~ret62#1 && outgoing__wrappee__AutoResponder_#t~ret62#1 <= 2147483647;outgoing__wrappee__AutoResponder_~tmp~9#1 := outgoing__wrappee__AutoResponder_#t~ret62#1;havoc outgoing__wrappee__AutoResponder_#t~ret62#1;outgoing__wrappee__AutoResponder_~receiver~0#1 := outgoing__wrappee__AutoResponder_~tmp~9#1; {11693#false} is VALID [2022-02-20 18:00:07,289 INFO L272 TraceCheckUtils]: 87: Hoare triple {11693#false} call outgoing__wrappee__AutoResponder_#t~ret63#1 := findPublicKey(outgoing__wrappee__AutoResponder_~client#1, outgoing__wrappee__AutoResponder_~receiver~0#1); {11692#true} is VALID [2022-02-20 18:00:07,289 INFO L290 TraceCheckUtils]: 88: Hoare triple {11692#true} ~handle := #in~handle;~userid := #in~userid;havoc ~retValue_acc~25; {11692#true} is VALID [2022-02-20 18:00:07,289 INFO L290 TraceCheckUtils]: 89: Hoare triple {11692#true} assume 1 == ~handle; {11692#true} is VALID [2022-02-20 18:00:07,289 INFO L290 TraceCheckUtils]: 90: Hoare triple {11692#true} assume ~userid == ~__ste_Client_Keyring0_User0~0;~retValue_acc~25 := ~__ste_Client_Keyring0_PublicKey0~0;#res := ~retValue_acc~25; {11692#true} is VALID [2022-02-20 18:00:07,289 INFO L290 TraceCheckUtils]: 91: Hoare triple {11692#true} assume true; {11692#true} is VALID [2022-02-20 18:00:07,289 INFO L284 TraceCheckUtils]: 92: Hoare quadruple {11692#true} {11693#false} #1058#return; {11693#false} is VALID [2022-02-20 18:00:07,289 INFO L290 TraceCheckUtils]: 93: Hoare triple {11693#false} assume -2147483648 <= outgoing__wrappee__AutoResponder_#t~ret63#1 && outgoing__wrappee__AutoResponder_#t~ret63#1 <= 2147483647;outgoing__wrappee__AutoResponder_~tmp___0~3#1 := outgoing__wrappee__AutoResponder_#t~ret63#1;havoc outgoing__wrappee__AutoResponder_#t~ret63#1;outgoing__wrappee__AutoResponder_~pubkey~0#1 := outgoing__wrappee__AutoResponder_~tmp___0~3#1; {11693#false} is VALID [2022-02-20 18:00:07,289 INFO L290 TraceCheckUtils]: 94: Hoare triple {11693#false} assume !(0 != outgoing__wrappee__AutoResponder_~pubkey~0#1); {11693#false} is VALID [2022-02-20 18:00:07,290 INFO L290 TraceCheckUtils]: 95: Hoare triple {11693#false} assume { :begin_inline_outgoing__wrappee__Keys } true;outgoing__wrappee__Keys_#in~client#1, outgoing__wrappee__Keys_#in~msg#1 := outgoing__wrappee__AutoResponder_~client#1, outgoing__wrappee__AutoResponder_~msg#1;havoc outgoing__wrappee__Keys_#t~ret61#1, outgoing__wrappee__Keys_~client#1, outgoing__wrappee__Keys_~msg#1, outgoing__wrappee__Keys_~tmp~8#1;outgoing__wrappee__Keys_~client#1 := outgoing__wrappee__Keys_#in~client#1;outgoing__wrappee__Keys_~msg#1 := outgoing__wrappee__Keys_#in~msg#1;havoc outgoing__wrappee__Keys_~tmp~8#1;assume { :begin_inline_getClientId } true;getClientId_#in~handle#1 := outgoing__wrappee__Keys_~client#1;havoc getClientId_#res#1;havoc getClientId_~handle#1, getClientId_~retValue_acc~27#1;getClientId_~handle#1 := getClientId_#in~handle#1;havoc getClientId_~retValue_acc~27#1; {11693#false} is VALID [2022-02-20 18:00:07,290 INFO L290 TraceCheckUtils]: 96: Hoare triple {11693#false} assume 1 == getClientId_~handle#1;getClientId_~retValue_acc~27#1 := ~__ste_client_idCounter0~0;getClientId_#res#1 := getClientId_~retValue_acc~27#1; {11693#false} is VALID [2022-02-20 18:00:07,290 INFO L290 TraceCheckUtils]: 97: Hoare triple {11693#false} outgoing__wrappee__Keys_#t~ret61#1 := getClientId_#res#1;assume { :end_inline_getClientId } true;assume -2147483648 <= outgoing__wrappee__Keys_#t~ret61#1 && outgoing__wrappee__Keys_#t~ret61#1 <= 2147483647;outgoing__wrappee__Keys_~tmp~8#1 := outgoing__wrappee__Keys_#t~ret61#1;havoc outgoing__wrappee__Keys_#t~ret61#1; {11693#false} is VALID [2022-02-20 18:00:07,290 INFO L272 TraceCheckUtils]: 98: Hoare triple {11693#false} call setEmailFrom(outgoing__wrappee__Keys_~msg#1, outgoing__wrappee__Keys_~tmp~8#1); {11760#(and (= |old(~__ste_email_from0~0)| ~__ste_email_from0~0) (= |old(~__ste_email_from1~0)| ~__ste_email_from1~0))} is VALID [2022-02-20 18:00:07,290 INFO L290 TraceCheckUtils]: 99: Hoare triple {11760#(and (= |old(~__ste_email_from0~0)| ~__ste_email_from0~0) (= |old(~__ste_email_from1~0)| ~__ste_email_from1~0))} ~handle := #in~handle;~value := #in~value; {11692#true} is VALID [2022-02-20 18:00:07,290 INFO L290 TraceCheckUtils]: 100: Hoare triple {11692#true} assume 1 == ~handle;~__ste_email_from0~0 := ~value; {11692#true} is VALID [2022-02-20 18:00:07,290 INFO L290 TraceCheckUtils]: 101: Hoare triple {11692#true} assume true; {11692#true} is VALID [2022-02-20 18:00:07,291 INFO L284 TraceCheckUtils]: 102: Hoare quadruple {11692#true} {11693#false} #1064#return; {11693#false} is VALID [2022-02-20 18:00:07,291 INFO L290 TraceCheckUtils]: 103: Hoare triple {11693#false} assume { :begin_inline_mail } true;mail_#in~client#1, mail_#in~msg#1 := outgoing__wrappee__Keys_~client#1, outgoing__wrappee__Keys_~msg#1;havoc mail_#t~ret59#1, mail_#t~ret60#1, mail_~client#1, mail_~msg#1, mail_~__utac__ad__arg1~0#1, mail_~__utac__ad__arg2~0#1, mail_~tmp~7#1;mail_~client#1 := mail_#in~client#1;mail_~msg#1 := mail_#in~msg#1;havoc mail_~__utac__ad__arg1~0#1;havoc mail_~__utac__ad__arg2~0#1;havoc mail_~tmp~7#1;mail_~__utac__ad__arg1~0#1 := mail_~client#1;mail_~__utac__ad__arg2~0#1 := mail_~msg#1;assume { :begin_inline___utac_acc__SignForward_spec__1 } true;__utac_acc__SignForward_spec__1_#in~client#1, __utac_acc__SignForward_spec__1_#in~msg#1 := mail_~__utac__ad__arg1~0#1, mail_~__utac__ad__arg2~0#1;havoc __utac_acc__SignForward_spec__1_#t~ret107#1, __utac_acc__SignForward_spec__1_#t~ret108#1, __utac_acc__SignForward_spec__1_#t~ret109#1, __utac_acc__SignForward_spec__1_~client#1, __utac_acc__SignForward_spec__1_~msg#1, __utac_acc__SignForward_spec__1_~tmp~25#1, __utac_acc__SignForward_spec__1_~tmp___0~9#1;__utac_acc__SignForward_spec__1_~client#1 := __utac_acc__SignForward_spec__1_#in~client#1;__utac_acc__SignForward_spec__1_~msg#1 := __utac_acc__SignForward_spec__1_#in~msg#1;havoc __utac_acc__SignForward_spec__1_~tmp~25#1;havoc __utac_acc__SignForward_spec__1_~tmp___0~9#1;call __utac_acc__SignForward_spec__1_#t~ret107#1 := puts(39, 0);assume -2147483648 <= __utac_acc__SignForward_spec__1_#t~ret107#1 && __utac_acc__SignForward_spec__1_#t~ret107#1 <= 2147483647;havoc __utac_acc__SignForward_spec__1_#t~ret107#1; {11693#false} is VALID [2022-02-20 18:00:07,291 INFO L272 TraceCheckUtils]: 104: Hoare triple {11693#false} call __utac_acc__SignForward_spec__1_#t~ret108#1 := isSigned(__utac_acc__SignForward_spec__1_~msg#1); {11692#true} is VALID [2022-02-20 18:00:07,291 INFO L290 TraceCheckUtils]: 105: Hoare triple {11692#true} ~handle := #in~handle;havoc ~retValue_acc~41; {11692#true} is VALID [2022-02-20 18:00:07,291 INFO L290 TraceCheckUtils]: 106: Hoare triple {11692#true} assume 1 == ~handle;~retValue_acc~41 := ~__ste_email_isSigned0~0;#res := ~retValue_acc~41; {11692#true} is VALID [2022-02-20 18:00:07,291 INFO L290 TraceCheckUtils]: 107: Hoare triple {11692#true} assume true; {11692#true} is VALID [2022-02-20 18:00:07,291 INFO L284 TraceCheckUtils]: 108: Hoare quadruple {11692#true} {11693#false} #1066#return; {11693#false} is VALID [2022-02-20 18:00:07,291 INFO L290 TraceCheckUtils]: 109: Hoare triple {11693#false} assume -2147483648 <= __utac_acc__SignForward_spec__1_#t~ret108#1 && __utac_acc__SignForward_spec__1_#t~ret108#1 <= 2147483647;__utac_acc__SignForward_spec__1_~tmp___0~9#1 := __utac_acc__SignForward_spec__1_#t~ret108#1;havoc __utac_acc__SignForward_spec__1_#t~ret108#1; {11693#false} is VALID [2022-02-20 18:00:07,292 INFO L290 TraceCheckUtils]: 110: Hoare triple {11693#false} assume 0 != __utac_acc__SignForward_spec__1_~tmp___0~9#1; {11693#false} is VALID [2022-02-20 18:00:07,292 INFO L272 TraceCheckUtils]: 111: Hoare triple {11693#false} call __utac_acc__SignForward_spec__1_#t~ret109#1 := getClientPrivateKey(__utac_acc__SignForward_spec__1_~client#1); {11692#true} is VALID [2022-02-20 18:00:07,292 INFO L290 TraceCheckUtils]: 112: Hoare triple {11692#true} ~handle := #in~handle;havoc ~retValue_acc~20; {11692#true} is VALID [2022-02-20 18:00:07,292 INFO L290 TraceCheckUtils]: 113: Hoare triple {11692#true} assume 1 == ~handle;~retValue_acc~20 := ~__ste_client_privateKey0~0;#res := ~retValue_acc~20; {11692#true} is VALID [2022-02-20 18:00:07,292 INFO L290 TraceCheckUtils]: 114: Hoare triple {11692#true} assume true; {11692#true} is VALID [2022-02-20 18:00:07,292 INFO L284 TraceCheckUtils]: 115: Hoare quadruple {11692#true} {11693#false} #1068#return; {11693#false} is VALID [2022-02-20 18:00:07,292 INFO L290 TraceCheckUtils]: 116: Hoare triple {11693#false} assume -2147483648 <= __utac_acc__SignForward_spec__1_#t~ret109#1 && __utac_acc__SignForward_spec__1_#t~ret109#1 <= 2147483647;__utac_acc__SignForward_spec__1_~tmp~25#1 := __utac_acc__SignForward_spec__1_#t~ret109#1;havoc __utac_acc__SignForward_spec__1_#t~ret109#1; {11693#false} is VALID [2022-02-20 18:00:07,293 INFO L290 TraceCheckUtils]: 117: Hoare triple {11693#false} assume 0 == __utac_acc__SignForward_spec__1_~tmp~25#1;assume { :begin_inline___automaton_fail } true; {11693#false} is VALID [2022-02-20 18:00:07,293 INFO L290 TraceCheckUtils]: 118: Hoare triple {11693#false} assume !false; {11693#false} is VALID [2022-02-20 18:00:07,293 INFO L134 CoverageAnalysis]: Checked inductivity of 34 backedges. 6 proven. 6 refuted. 0 times theorem prover too weak. 22 trivial. 0 not checked. [2022-02-20 18:00:07,293 INFO L144 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2022-02-20 18:00:07,293 INFO L338 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [1326278447] [2022-02-20 18:00:07,294 INFO L165 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [1326278447] provided 0 perfect and 1 imperfect interpolant sequences [2022-02-20 18:00:07,294 INFO L338 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleZ3 [1867605390] [2022-02-20 18:00:07,294 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-02-20 18:00:07,294 INFO L173 SolverBuilder]: Constructing external solver with command: z3 -smt2 -in SMTLIB2_COMPLIANT=true [2022-02-20 18:00:07,294 INFO L189 MonitoredProcess]: No working directory specified, using /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 [2022-02-20 18:00:07,321 INFO L229 MonitoredProcess]: Starting monitored process 6 with /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 -smt2 -in SMTLIB2_COMPLIANT=true (exit command is (exit), workingDir is null) [2022-02-20 18:00:07,390 INFO L327 MonitoredProcess]: [MP /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 -smt2 -in SMTLIB2_COMPLIANT=true (6)] Waiting until timeout for monitored process [2022-02-20 18:00:07,631 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-02-20 18:00:07,635 INFO L263 TraceCheckSpWp]: Trace formula consists of 1101 conjuncts, 6 conjunts are in the unsatisfiable core [2022-02-20 18:00:07,672 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-02-20 18:00:07,675 INFO L286 TraceCheckSpWp]: Computing forward predicates... [2022-02-20 18:00:07,955 INFO L290 TraceCheckUtils]: 0: Hoare triple {11692#true} assume { :begin_inline_ULTIMATE.init } true;#NULL.base, #NULL.offset := 0, 0;assume 0 == #valid[0];assume 0 < #StackHeapBarrier;call #Ultimate.allocInit(2, 1);call write~init~int(48, 1, 0, 1);call write~init~int(0, 1, 1, 1);call #Ultimate.allocInit(28, 2);call #Ultimate.allocInit(12, 3);call #Ultimate.allocInit(30, 4);call #Ultimate.allocInit(9, 5);call #Ultimate.allocInit(21, 6);call #Ultimate.allocInit(30, 7);call #Ultimate.allocInit(9, 8);call #Ultimate.allocInit(21, 9);call #Ultimate.allocInit(30, 10);call #Ultimate.allocInit(9, 11);call #Ultimate.allocInit(25, 12);call #Ultimate.allocInit(30, 13);call #Ultimate.allocInit(9, 14);call #Ultimate.allocInit(25, 15);call #Ultimate.allocInit(44, 16);call #Ultimate.allocInit(44, 17);call #Ultimate.allocInit(9, 18);call #Ultimate.allocInit(9, 19);call #Ultimate.allocInit(11, 20);call #Ultimate.allocInit(19, 21);call #Ultimate.allocInit(4, 22);call write~init~int(37, 22, 0, 1);call write~init~int(100, 22, 1, 1);call write~init~int(10, 22, 2, 1);call write~init~int(0, 22, 3, 1);call #Ultimate.allocInit(4, 23);call write~init~int(37, 23, 0, 1);call write~init~int(100, 23, 1, 1);call write~init~int(10, 23, 2, 1);call write~init~int(0, 23, 3, 1);call #Ultimate.allocInit(10, 24);call #Ultimate.allocInit(16, 25);call #Ultimate.allocInit(20, 26);call #Ultimate.allocInit(22, 27);call #Ultimate.allocInit(21, 28);call #Ultimate.allocInit(10, 29);call #Ultimate.allocInit(12, 30);call #Ultimate.allocInit(10, 31);call #Ultimate.allocInit(18, 32);call #Ultimate.allocInit(16, 33);call #Ultimate.allocInit(21, 34);call #Ultimate.allocInit(13, 35);call #Ultimate.allocInit(16, 36);call #Ultimate.allocInit(25, 37);call #Ultimate.allocInit(4, 38);call write~init~int(37, 38, 0, 1);call write~init~int(115, 38, 1, 1);call write~init~int(10, 38, 2, 1);call write~init~int(0, 38, 3, 1);call #Ultimate.allocInit(13, 39);~head~0.base, ~head~0.offset := 0, 0;~__SELECTED_FEATURE_Base~0 := 0;~__SELECTED_FEATURE_Keys~0 := 0;~__SELECTED_FEATURE_Encrypt~0 := 0;~__SELECTED_FEATURE_AutoResponder~0 := 0;~__SELECTED_FEATURE_AddressBook~0 := 0;~__SELECTED_FEATURE_Sign~0 := 0;~__SELECTED_FEATURE_Forward~0 := 0;~__SELECTED_FEATURE_Verify~0 := 0;~__SELECTED_FEATURE_Decrypt~0 := 0;~__GUIDSL_ROOT_PRODUCTION~0 := 0;~__GUIDSL_NON_TERMINAL_main~0 := 0;~bob~0 := 0;~rjh~0 := 0;~chuck~0 := 0;~queue_empty~0 := 1;~queued_message~0 := 0;~queued_client~0 := 0;~__ste_Client_counter~0 := 0;~__ste_client_name0~0.base, ~__ste_client_name0~0.offset := 0, 0;~__ste_client_name1~0.base, ~__ste_client_name1~0.offset := 0, 0;~__ste_client_name2~0.base, ~__ste_client_name2~0.offset := 0, 0;~__ste_client_outbuffer0~0 := 0;~__ste_client_outbuffer1~0 := 0;~__ste_client_outbuffer2~0 := 0;~__ste_client_outbuffer3~0 := 0;~__ste_ClientAddressBook_size0~0 := 0;~__ste_ClientAddressBook_size1~0 := 0;~__ste_ClientAddressBook_size2~0 := 0;~__ste_Client_AddressBook0_Alias0~0 := 0;~__ste_Client_AddressBook0_Alias1~0 := 0;~__ste_Client_AddressBook0_Alias2~0 := 0;~__ste_Client_AddressBook1_Alias0~0 := 0;~__ste_Client_AddressBook1_Alias1~0 := 0;~__ste_Client_AddressBook1_Alias2~0 := 0;~__ste_Client_AddressBook2_Alias0~0 := 0;~__ste_Client_AddressBook2_Alias1~0 := 0;~__ste_Client_AddressBook2_Alias2~0 := 0;~__ste_Client_AddressBook0_Address0~0 := 0;~__ste_Client_AddressBook0_Address1~0 := 0;~__ste_Client_AddressBook0_Address2~0 := 0;~__ste_Client_AddressBook1_Address0~0 := 0;~__ste_Client_AddressBook1_Address1~0 := 0;~__ste_Client_AddressBook1_Address2~0 := 0;~__ste_Client_AddressBook2_Address0~0 := 0;~__ste_Client_AddressBook2_Address1~0 := 0;~__ste_Client_AddressBook2_Address2~0 := 0;~__ste_client_autoResponse0~0 := 0;~__ste_client_autoResponse1~0 := 0;~__ste_client_autoResponse2~0 := 0;~__ste_client_privateKey0~0 := 0;~__ste_client_privateKey1~0 := 0;~__ste_client_privateKey2~0 := 0;~__ste_ClientKeyring_size0~0 := 0;~__ste_ClientKeyring_size1~0 := 0;~__ste_ClientKeyring_size2~0 := 0;~__ste_Client_Keyring0_User0~0 := 0;~__ste_Client_Keyring0_User1~0 := 0;~__ste_Client_Keyring0_User2~0 := 0;~__ste_Client_Keyring1_User0~0 := 0;~__ste_Client_Keyring1_User1~0 := 0;~__ste_Client_Keyring1_User2~0 := 0;~__ste_Client_Keyring2_User0~0 := 0;~__ste_Client_Keyring2_User1~0 := 0;~__ste_Client_Keyring2_User2~0 := 0;~__ste_Client_Keyring0_PublicKey0~0 := 0;~__ste_Client_Keyring0_PublicKey1~0 := 0;~__ste_Client_Keyring0_PublicKey2~0 := 0;~__ste_Client_Keyring1_PublicKey0~0 := 0;~__ste_Client_Keyring1_PublicKey1~0 := 0;~__ste_Client_Keyring1_PublicKey2~0 := 0;~__ste_Client_Keyring2_PublicKey0~0 := 0;~__ste_Client_Keyring2_PublicKey1~0 := 0;~__ste_Client_Keyring2_PublicKey2~0 := 0;~__ste_client_forwardReceiver0~0 := 0;~__ste_client_forwardReceiver1~0 := 0;~__ste_client_forwardReceiver2~0 := 0;~__ste_client_forwardReceiver3~0 := 0;~__ste_client_idCounter0~0 := 0;~__ste_client_idCounter1~0 := 0;~__ste_client_idCounter2~0 := 0;~__ste_Email_counter~0 := 0;~__ste_email_id0~0 := 0;~__ste_email_id1~0 := 0;~__ste_email_from0~0 := 0;~__ste_email_from1~0 := 0;~__ste_email_to0~0 := 0;~__ste_email_to1~0 := 0;~__ste_email_subject0~0.base, ~__ste_email_subject0~0.offset := 0, 0;~__ste_email_subject1~0.base, ~__ste_email_subject1~0.offset := 0, 0;~__ste_email_body0~0.base, ~__ste_email_body0~0.offset := 0, 0;~__ste_email_body1~0.base, ~__ste_email_body1~0.offset := 0, 0;~__ste_email_isEncrypted0~0 := 0;~__ste_email_isEncrypted1~0 := 0;~__ste_email_encryptionKey0~0 := 0;~__ste_email_encryptionKey1~0 := 0;~__ste_email_isSigned0~0 := 0;~__ste_email_isSigned1~0 := 0;~__ste_email_signKey0~0 := 0;~__ste_email_signKey1~0 := 0;~__ste_email_isSignatureVerified0~0 := 0;~__ste_email_isSignatureVerified1~0 := 0; {11692#true} is VALID [2022-02-20 18:00:07,956 INFO L290 TraceCheckUtils]: 1: Hoare triple {11692#true} assume { :end_inline_ULTIMATE.init } true;assume { :begin_inline_main } true;havoc main_#res#1;havoc main_#t~ret35#1, main_~retValue_acc~3#1, main_~tmp~4#1;havoc main_~retValue_acc~3#1;havoc main_~tmp~4#1;assume { :begin_inline_select_helpers } true; {11692#true} is VALID [2022-02-20 18:00:07,956 INFO L290 TraceCheckUtils]: 2: Hoare triple {11692#true} assume { :end_inline_select_helpers } true;assume { :begin_inline_select_features } true; {11692#true} is VALID [2022-02-20 18:00:07,956 INFO L290 TraceCheckUtils]: 3: Hoare triple {11692#true} assume { :end_inline_select_features } true;assume { :begin_inline_valid_product } true;havoc valid_product_#res#1;havoc valid_product_~retValue_acc~5#1;havoc valid_product_~retValue_acc~5#1;valid_product_~retValue_acc~5#1 := 1;valid_product_#res#1 := valid_product_~retValue_acc~5#1; {11692#true} is VALID [2022-02-20 18:00:07,956 INFO L290 TraceCheckUtils]: 4: Hoare triple {11692#true} main_#t~ret35#1 := valid_product_#res#1;assume { :end_inline_valid_product } true;assume -2147483648 <= main_#t~ret35#1 && main_#t~ret35#1 <= 2147483647;main_~tmp~4#1 := main_#t~ret35#1;havoc main_#t~ret35#1; {11692#true} is VALID [2022-02-20 18:00:07,956 INFO L290 TraceCheckUtils]: 5: Hoare triple {11692#true} assume 0 != main_~tmp~4#1;assume { :begin_inline_setup } true;havoc setup_#t~nondet32#1, setup_#t~nondet33#1, setup_#t~nondet34#1, setup_~__cil_tmp1~0#1.base, setup_~__cil_tmp1~0#1.offset, setup_~__cil_tmp2~0#1.base, setup_~__cil_tmp2~0#1.offset, setup_~__cil_tmp3~0#1.base, setup_~__cil_tmp3~0#1.offset;havoc setup_~__cil_tmp1~0#1.base, setup_~__cil_tmp1~0#1.offset;havoc setup_~__cil_tmp2~0#1.base, setup_~__cil_tmp2~0#1.offset;havoc setup_~__cil_tmp3~0#1.base, setup_~__cil_tmp3~0#1.offset;~bob~0 := 1;assume { :begin_inline_setup_bob } true;setup_bob_#in~bob___0#1 := ~bob~0;havoc setup_bob_~bob___0#1;setup_bob_~bob___0#1 := setup_bob_#in~bob___0#1;assume { :begin_inline_setup_bob__wrappee__Base } true;setup_bob__wrappee__Base_#in~bob___0#1 := setup_bob_~bob___0#1;havoc setup_bob__wrappee__Base_~bob___0#1;setup_bob__wrappee__Base_~bob___0#1 := setup_bob__wrappee__Base_#in~bob___0#1; {11692#true} is VALID [2022-02-20 18:00:07,957 INFO L272 TraceCheckUtils]: 6: Hoare triple {11692#true} call setClientId(setup_bob__wrappee__Base_~bob___0#1, setup_bob__wrappee__Base_~bob___0#1); {11692#true} is VALID [2022-02-20 18:00:07,957 INFO L290 TraceCheckUtils]: 7: Hoare triple {11692#true} ~handle := #in~handle;~value := #in~value; {11692#true} is VALID [2022-02-20 18:00:07,957 INFO L290 TraceCheckUtils]: 8: Hoare triple {11692#true} assume 1 == ~handle;~__ste_client_idCounter0~0 := ~value; {11692#true} is VALID [2022-02-20 18:00:07,957 INFO L290 TraceCheckUtils]: 9: Hoare triple {11692#true} assume true; {11692#true} is VALID [2022-02-20 18:00:07,957 INFO L284 TraceCheckUtils]: 10: Hoare quadruple {11692#true} {11692#true} #1134#return; {11692#true} is VALID [2022-02-20 18:00:07,957 INFO L290 TraceCheckUtils]: 11: Hoare triple {11692#true} assume { :end_inline_setup_bob__wrappee__Base } true; {11692#true} is VALID [2022-02-20 18:00:07,957 INFO L272 TraceCheckUtils]: 12: Hoare triple {11692#true} call setClientPrivateKey(setup_bob_~bob___0#1, 123); {11692#true} is VALID [2022-02-20 18:00:07,958 INFO L290 TraceCheckUtils]: 13: Hoare triple {11692#true} ~handle := #in~handle;~value := #in~value; {11692#true} is VALID [2022-02-20 18:00:07,958 INFO L290 TraceCheckUtils]: 14: Hoare triple {11692#true} assume 1 == ~handle;~__ste_client_privateKey0~0 := ~value; {11692#true} is VALID [2022-02-20 18:00:07,958 INFO L290 TraceCheckUtils]: 15: Hoare triple {11692#true} assume true; {11692#true} is VALID [2022-02-20 18:00:07,958 INFO L284 TraceCheckUtils]: 16: Hoare quadruple {11692#true} {11692#true} #1136#return; {11692#true} is VALID [2022-02-20 18:00:07,958 INFO L290 TraceCheckUtils]: 17: Hoare triple {11692#true} assume { :end_inline_setup_bob } true;setup_~__cil_tmp1~0#1.base, setup_~__cil_tmp1~0#1.offset := 18, 0;havoc setup_#t~nondet32#1;~rjh~0 := 2;assume { :begin_inline_setup_rjh } true;setup_rjh_#in~rjh___0#1 := ~rjh~0;havoc setup_rjh_~rjh___0#1;setup_rjh_~rjh___0#1 := setup_rjh_#in~rjh___0#1;assume { :begin_inline_setup_rjh__wrappee__Base } true;setup_rjh__wrappee__Base_#in~rjh___0#1 := setup_rjh_~rjh___0#1;havoc setup_rjh__wrappee__Base_~rjh___0#1;setup_rjh__wrappee__Base_~rjh___0#1 := setup_rjh__wrappee__Base_#in~rjh___0#1; {11816#(<= 2 |ULTIMATE.start_setup_rjh_~rjh___0#1|)} is VALID [2022-02-20 18:00:07,959 INFO L272 TraceCheckUtils]: 18: Hoare triple {11816#(<= 2 |ULTIMATE.start_setup_rjh_~rjh___0#1|)} call setClientId(setup_rjh__wrappee__Base_~rjh___0#1, setup_rjh__wrappee__Base_~rjh___0#1); {11692#true} is VALID [2022-02-20 18:00:07,959 INFO L290 TraceCheckUtils]: 19: Hoare triple {11692#true} ~handle := #in~handle;~value := #in~value; {11692#true} is VALID [2022-02-20 18:00:07,959 INFO L290 TraceCheckUtils]: 20: Hoare triple {11692#true} assume !(1 == ~handle); {11692#true} is VALID [2022-02-20 18:00:07,959 INFO L290 TraceCheckUtils]: 21: Hoare triple {11692#true} assume 2 == ~handle;~__ste_client_idCounter1~0 := ~value; {11692#true} is VALID [2022-02-20 18:00:07,959 INFO L290 TraceCheckUtils]: 22: Hoare triple {11692#true} assume true; {11692#true} is VALID [2022-02-20 18:00:07,960 INFO L284 TraceCheckUtils]: 23: Hoare quadruple {11692#true} {11816#(<= 2 |ULTIMATE.start_setup_rjh_~rjh___0#1|)} #1138#return; {11816#(<= 2 |ULTIMATE.start_setup_rjh_~rjh___0#1|)} is VALID [2022-02-20 18:00:07,960 INFO L290 TraceCheckUtils]: 24: Hoare triple {11816#(<= 2 |ULTIMATE.start_setup_rjh_~rjh___0#1|)} assume { :end_inline_setup_rjh__wrappee__Base } true; {11816#(<= 2 |ULTIMATE.start_setup_rjh_~rjh___0#1|)} is VALID [2022-02-20 18:00:07,961 INFO L272 TraceCheckUtils]: 25: Hoare triple {11816#(<= 2 |ULTIMATE.start_setup_rjh_~rjh___0#1|)} call setClientPrivateKey(setup_rjh_~rjh___0#1, 456); {11692#true} is VALID [2022-02-20 18:00:07,961 INFO L290 TraceCheckUtils]: 26: Hoare triple {11692#true} ~handle := #in~handle;~value := #in~value; {11844#(<= |setClientPrivateKey_#in~handle| setClientPrivateKey_~handle)} is VALID [2022-02-20 18:00:07,962 INFO L290 TraceCheckUtils]: 27: Hoare triple {11844#(<= |setClientPrivateKey_#in~handle| setClientPrivateKey_~handle)} assume 1 == ~handle;~__ste_client_privateKey0~0 := ~value; {11848#(<= |setClientPrivateKey_#in~handle| 1)} is VALID [2022-02-20 18:00:07,962 INFO L290 TraceCheckUtils]: 28: Hoare triple {11848#(<= |setClientPrivateKey_#in~handle| 1)} assume true; {11848#(<= |setClientPrivateKey_#in~handle| 1)} is VALID [2022-02-20 18:00:07,963 INFO L284 TraceCheckUtils]: 29: Hoare quadruple {11848#(<= |setClientPrivateKey_#in~handle| 1)} {11816#(<= 2 |ULTIMATE.start_setup_rjh_~rjh___0#1|)} #1140#return; {11693#false} is VALID [2022-02-20 18:00:07,963 INFO L290 TraceCheckUtils]: 30: Hoare triple {11693#false} assume { :end_inline_setup_rjh } true;setup_~__cil_tmp2~0#1.base, setup_~__cil_tmp2~0#1.offset := 19, 0;havoc setup_#t~nondet33#1;~chuck~0 := 3;assume { :begin_inline_setup_chuck } true;setup_chuck_#in~chuck___0#1 := ~chuck~0;havoc setup_chuck_~chuck___0#1;setup_chuck_~chuck___0#1 := setup_chuck_#in~chuck___0#1;assume { :begin_inline_setup_chuck__wrappee__Base } true;setup_chuck__wrappee__Base_#in~chuck___0#1 := setup_chuck_~chuck___0#1;havoc setup_chuck__wrappee__Base_~chuck___0#1;setup_chuck__wrappee__Base_~chuck___0#1 := setup_chuck__wrappee__Base_#in~chuck___0#1; {11693#false} is VALID [2022-02-20 18:00:07,963 INFO L272 TraceCheckUtils]: 31: Hoare triple {11693#false} call setClientId(setup_chuck__wrappee__Base_~chuck___0#1, setup_chuck__wrappee__Base_~chuck___0#1); {11693#false} is VALID [2022-02-20 18:00:07,963 INFO L290 TraceCheckUtils]: 32: Hoare triple {11693#false} ~handle := #in~handle;~value := #in~value; {11693#false} is VALID [2022-02-20 18:00:07,963 INFO L290 TraceCheckUtils]: 33: Hoare triple {11693#false} assume 1 == ~handle;~__ste_client_idCounter0~0 := ~value; {11693#false} is VALID [2022-02-20 18:00:07,963 INFO L290 TraceCheckUtils]: 34: Hoare triple {11693#false} assume true; {11693#false} is VALID [2022-02-20 18:00:07,963 INFO L284 TraceCheckUtils]: 35: Hoare quadruple {11693#false} {11693#false} #1142#return; {11693#false} is VALID [2022-02-20 18:00:07,964 INFO L290 TraceCheckUtils]: 36: Hoare triple {11693#false} assume { :end_inline_setup_chuck__wrappee__Base } true; {11693#false} is VALID [2022-02-20 18:00:07,964 INFO L272 TraceCheckUtils]: 37: Hoare triple {11693#false} call setClientPrivateKey(setup_chuck_~chuck___0#1, 789); {11693#false} is VALID [2022-02-20 18:00:07,964 INFO L290 TraceCheckUtils]: 38: Hoare triple {11693#false} ~handle := #in~handle;~value := #in~value; {11693#false} is VALID [2022-02-20 18:00:07,964 INFO L290 TraceCheckUtils]: 39: Hoare triple {11693#false} assume 1 == ~handle;~__ste_client_privateKey0~0 := ~value; {11693#false} is VALID [2022-02-20 18:00:07,964 INFO L290 TraceCheckUtils]: 40: Hoare triple {11693#false} assume true; {11693#false} is VALID [2022-02-20 18:00:07,964 INFO L284 TraceCheckUtils]: 41: Hoare quadruple {11693#false} {11693#false} #1144#return; {11693#false} is VALID [2022-02-20 18:00:07,964 INFO L290 TraceCheckUtils]: 42: Hoare triple {11693#false} assume { :end_inline_setup_chuck } true;setup_~__cil_tmp3~0#1.base, setup_~__cil_tmp3~0#1.offset := 20, 0;havoc setup_#t~nondet34#1; {11693#false} is VALID [2022-02-20 18:00:07,965 INFO L290 TraceCheckUtils]: 43: Hoare triple {11693#false} assume { :end_inline_setup } true;assume { :begin_inline_test } true;havoc test_#t~nondet47#1, test_#t~nondet48#1, test_#t~nondet49#1, test_#t~nondet50#1, test_#t~nondet51#1, test_#t~nondet52#1, test_#t~nondet53#1, test_#t~nondet54#1, test_#t~nondet55#1, test_#t~nondet56#1, test_#t~nondet57#1, test_~op1~0#1, test_~op2~0#1, test_~op3~0#1, test_~op4~0#1, test_~op5~0#1, test_~op6~0#1, test_~op7~0#1, test_~op8~0#1, test_~op9~0#1, test_~op10~0#1, test_~op11~0#1, test_~splverifierCounter~0#1, test_~tmp~6#1, test_~tmp___0~2#1, test_~tmp___1~1#1, test_~tmp___2~0#1, test_~tmp___3~0#1, test_~tmp___4~0#1, test_~tmp___5~0#1, test_~tmp___6~0#1, test_~tmp___7~0#1, test_~tmp___8~0#1, test_~tmp___9~0#1;havoc test_~op1~0#1;havoc test_~op2~0#1;havoc test_~op3~0#1;havoc test_~op4~0#1;havoc test_~op5~0#1;havoc test_~op6~0#1;havoc test_~op7~0#1;havoc test_~op8~0#1;havoc test_~op9~0#1;havoc test_~op10~0#1;havoc test_~op11~0#1;havoc test_~splverifierCounter~0#1;havoc test_~tmp~6#1;havoc test_~tmp___0~2#1;havoc test_~tmp___1~1#1;havoc test_~tmp___2~0#1;havoc test_~tmp___3~0#1;havoc test_~tmp___4~0#1;havoc test_~tmp___5~0#1;havoc test_~tmp___6~0#1;havoc test_~tmp___7~0#1;havoc test_~tmp___8~0#1;havoc test_~tmp___9~0#1;test_~op1~0#1 := 0;test_~op2~0#1 := 0;test_~op3~0#1 := 0;test_~op4~0#1 := 0;test_~op5~0#1 := 0;test_~op6~0#1 := 0;test_~op7~0#1 := 0;test_~op8~0#1 := 0;test_~op9~0#1 := 0;test_~op10~0#1 := 0;test_~op11~0#1 := 0;test_~splverifierCounter~0#1 := 0; {11693#false} is VALID [2022-02-20 18:00:07,965 INFO L290 TraceCheckUtils]: 44: Hoare triple {11693#false} assume !false; {11693#false} is VALID [2022-02-20 18:00:07,965 INFO L290 TraceCheckUtils]: 45: Hoare triple {11693#false} assume test_~splverifierCounter~0#1 < 4; {11693#false} is VALID [2022-02-20 18:00:07,965 INFO L290 TraceCheckUtils]: 46: Hoare triple {11693#false} test_~splverifierCounter~0#1 := 1 + test_~splverifierCounter~0#1; {11693#false} is VALID [2022-02-20 18:00:07,965 INFO L290 TraceCheckUtils]: 47: Hoare triple {11693#false} assume 0 == test_~op1~0#1;assume -2147483648 <= test_#t~nondet47#1 && test_#t~nondet47#1 <= 2147483647;test_~tmp___9~0#1 := test_#t~nondet47#1;havoc test_#t~nondet47#1; {11693#false} is VALID [2022-02-20 18:00:07,965 INFO L290 TraceCheckUtils]: 48: Hoare triple {11693#false} assume !(0 != test_~tmp___9~0#1); {11693#false} is VALID [2022-02-20 18:00:07,965 INFO L290 TraceCheckUtils]: 49: Hoare triple {11693#false} assume 0 == test_~op2~0#1;assume -2147483648 <= test_#t~nondet48#1 && test_#t~nondet48#1 <= 2147483647;test_~tmp___8~0#1 := test_#t~nondet48#1;havoc test_#t~nondet48#1; {11693#false} is VALID [2022-02-20 18:00:07,966 INFO L290 TraceCheckUtils]: 50: Hoare triple {11693#false} assume 0 != test_~tmp___8~0#1;assume { :begin_inline_rjhSetAutoRespond } true;assume { :begin_inline_setClientAutoResponse } true;setClientAutoResponse_#in~handle#1, setClientAutoResponse_#in~value#1 := ~rjh~0, 1;havoc setClientAutoResponse_~handle#1, setClientAutoResponse_~value#1;setClientAutoResponse_~handle#1 := setClientAutoResponse_#in~handle#1;setClientAutoResponse_~value#1 := setClientAutoResponse_#in~value#1; {11693#false} is VALID [2022-02-20 18:00:07,966 INFO L290 TraceCheckUtils]: 51: Hoare triple {11693#false} assume 1 == setClientAutoResponse_~handle#1;~__ste_client_autoResponse0~0 := setClientAutoResponse_~value#1; {11693#false} is VALID [2022-02-20 18:00:07,966 INFO L290 TraceCheckUtils]: 52: Hoare triple {11693#false} assume { :end_inline_setClientAutoResponse } true; {11693#false} is VALID [2022-02-20 18:00:07,966 INFO L290 TraceCheckUtils]: 53: Hoare triple {11693#false} assume { :end_inline_rjhSetAutoRespond } true;test_~op2~0#1 := 1; {11693#false} is VALID [2022-02-20 18:00:07,966 INFO L290 TraceCheckUtils]: 54: Hoare triple {11693#false} assume !false; {11693#false} is VALID [2022-02-20 18:00:07,966 INFO L290 TraceCheckUtils]: 55: Hoare triple {11693#false} assume !(test_~splverifierCounter~0#1 < 4); {11693#false} is VALID [2022-02-20 18:00:07,966 INFO L290 TraceCheckUtils]: 56: Hoare triple {11693#false} assume { :begin_inline_bobToRjh } true;havoc bobToRjh_#t~ret27#1, bobToRjh_#t~ret28#1, bobToRjh_#t~ret29#1, bobToRjh_#t~ret30#1, bobToRjh_~tmp~3#1, bobToRjh_~tmp___0~0#1, bobToRjh_~tmp___1~0#1;havoc bobToRjh_~tmp~3#1;havoc bobToRjh_~tmp___0~0#1;havoc bobToRjh_~tmp___1~0#1;call bobToRjh_#t~ret27#1 := puts(16, 0);assume -2147483648 <= bobToRjh_#t~ret27#1 && bobToRjh_#t~ret27#1 <= 2147483647;havoc bobToRjh_#t~ret27#1; {11693#false} is VALID [2022-02-20 18:00:07,966 INFO L272 TraceCheckUtils]: 57: Hoare triple {11693#false} call sendEmail(~bob~0, ~rjh~0); {11693#false} is VALID [2022-02-20 18:00:07,967 INFO L290 TraceCheckUtils]: 58: Hoare triple {11693#false} ~sender#1 := #in~sender#1;~receiver#1 := #in~receiver#1;havoc ~email~0#1;havoc ~tmp~14#1;assume { :begin_inline_createEmail } true;createEmail_#in~from#1, createEmail_#in~to#1 := 0, ~receiver#1;havoc createEmail_#res#1;havoc createEmail_~from#1, createEmail_~to#1, createEmail_~retValue_acc~31#1, createEmail_~msg~0#1;createEmail_~from#1 := createEmail_#in~from#1;createEmail_~to#1 := createEmail_#in~to#1;havoc createEmail_~retValue_acc~31#1;havoc createEmail_~msg~0#1;createEmail_~msg~0#1 := 1; {11693#false} is VALID [2022-02-20 18:00:07,967 INFO L272 TraceCheckUtils]: 59: Hoare triple {11693#false} call setEmailFrom(createEmail_~msg~0#1, createEmail_~from#1); {11693#false} is VALID [2022-02-20 18:00:07,967 INFO L290 TraceCheckUtils]: 60: Hoare triple {11693#false} ~handle := #in~handle;~value := #in~value; {11693#false} is VALID [2022-02-20 18:00:07,967 INFO L290 TraceCheckUtils]: 61: Hoare triple {11693#false} assume 1 == ~handle;~__ste_email_from0~0 := ~value; {11693#false} is VALID [2022-02-20 18:00:07,967 INFO L290 TraceCheckUtils]: 62: Hoare triple {11693#false} assume true; {11693#false} is VALID [2022-02-20 18:00:07,967 INFO L284 TraceCheckUtils]: 63: Hoare quadruple {11693#false} {11693#false} #1120#return; {11693#false} is VALID [2022-02-20 18:00:07,967 INFO L272 TraceCheckUtils]: 64: Hoare triple {11693#false} call setEmailTo(createEmail_~msg~0#1, createEmail_~to#1); {11693#false} is VALID [2022-02-20 18:00:07,967 INFO L290 TraceCheckUtils]: 65: Hoare triple {11693#false} ~handle := #in~handle;~value := #in~value; {11693#false} is VALID [2022-02-20 18:00:07,968 INFO L290 TraceCheckUtils]: 66: Hoare triple {11693#false} assume 1 == ~handle;~__ste_email_to0~0 := ~value; {11693#false} is VALID [2022-02-20 18:00:07,968 INFO L290 TraceCheckUtils]: 67: Hoare triple {11693#false} assume true; {11693#false} is VALID [2022-02-20 18:00:07,968 INFO L284 TraceCheckUtils]: 68: Hoare quadruple {11693#false} {11693#false} #1122#return; {11693#false} is VALID [2022-02-20 18:00:07,968 INFO L290 TraceCheckUtils]: 69: Hoare triple {11693#false} createEmail_~retValue_acc~31#1 := createEmail_~msg~0#1;createEmail_#res#1 := createEmail_~retValue_acc~31#1; {11693#false} is VALID [2022-02-20 18:00:07,968 INFO L290 TraceCheckUtils]: 70: Hoare triple {11693#false} #t~ret72#1 := createEmail_#res#1;assume { :end_inline_createEmail } true;assume -2147483648 <= #t~ret72#1 && #t~ret72#1 <= 2147483647;~tmp~14#1 := #t~ret72#1;havoc #t~ret72#1;~email~0#1 := ~tmp~14#1; {11693#false} is VALID [2022-02-20 18:00:07,968 INFO L272 TraceCheckUtils]: 71: Hoare triple {11693#false} call outgoing(~sender#1, ~email~0#1); {11693#false} is VALID [2022-02-20 18:00:07,968 INFO L290 TraceCheckUtils]: 72: Hoare triple {11693#false} ~client#1 := #in~client#1;~msg#1 := #in~msg#1;assume { :begin_inline_sign } true;sign_#in~client#1, sign_#in~msg#1 := ~client#1, ~msg#1;havoc sign_#t~ret76#1, sign_~client#1, sign_~msg#1, sign_~privkey~1#1, sign_~tmp~16#1;sign_~client#1 := sign_#in~client#1;sign_~msg#1 := sign_#in~msg#1;havoc sign_~privkey~1#1;havoc sign_~tmp~16#1; {11693#false} is VALID [2022-02-20 18:00:07,969 INFO L272 TraceCheckUtils]: 73: Hoare triple {11693#false} call sign_#t~ret76#1 := getClientPrivateKey(sign_~client#1); {11693#false} is VALID [2022-02-20 18:00:07,969 INFO L290 TraceCheckUtils]: 74: Hoare triple {11693#false} ~handle := #in~handle;havoc ~retValue_acc~20; {11693#false} is VALID [2022-02-20 18:00:07,969 INFO L290 TraceCheckUtils]: 75: Hoare triple {11693#false} assume 1 == ~handle;~retValue_acc~20 := ~__ste_client_privateKey0~0;#res := ~retValue_acc~20; {11693#false} is VALID [2022-02-20 18:00:07,969 INFO L290 TraceCheckUtils]: 76: Hoare triple {11693#false} assume true; {11693#false} is VALID [2022-02-20 18:00:07,969 INFO L284 TraceCheckUtils]: 77: Hoare quadruple {11693#false} {11693#false} #1054#return; {11693#false} is VALID [2022-02-20 18:00:07,969 INFO L290 TraceCheckUtils]: 78: Hoare triple {11693#false} assume -2147483648 <= sign_#t~ret76#1 && sign_#t~ret76#1 <= 2147483647;sign_~tmp~16#1 := sign_#t~ret76#1;havoc sign_#t~ret76#1;sign_~privkey~1#1 := sign_~tmp~16#1; {11693#false} is VALID [2022-02-20 18:00:07,969 INFO L290 TraceCheckUtils]: 79: Hoare triple {11693#false} assume 0 == sign_~privkey~1#1; {11693#false} is VALID [2022-02-20 18:00:07,969 INFO L290 TraceCheckUtils]: 80: Hoare triple {11693#false} assume { :end_inline_sign } true;assume { :begin_inline_outgoing__wrappee__AutoResponder } true;outgoing__wrappee__AutoResponder_#in~client#1, outgoing__wrappee__AutoResponder_#in~msg#1 := ~client#1, ~msg#1;havoc outgoing__wrappee__AutoResponder_#t~ret62#1, outgoing__wrappee__AutoResponder_#t~ret63#1, outgoing__wrappee__AutoResponder_~client#1, outgoing__wrappee__AutoResponder_~msg#1, outgoing__wrappee__AutoResponder_~receiver~0#1, outgoing__wrappee__AutoResponder_~tmp~9#1, outgoing__wrappee__AutoResponder_~pubkey~0#1, outgoing__wrappee__AutoResponder_~tmp___0~3#1;outgoing__wrappee__AutoResponder_~client#1 := outgoing__wrappee__AutoResponder_#in~client#1;outgoing__wrappee__AutoResponder_~msg#1 := outgoing__wrappee__AutoResponder_#in~msg#1;havoc outgoing__wrappee__AutoResponder_~receiver~0#1;havoc outgoing__wrappee__AutoResponder_~tmp~9#1;havoc outgoing__wrappee__AutoResponder_~pubkey~0#1;havoc outgoing__wrappee__AutoResponder_~tmp___0~3#1; {11693#false} is VALID [2022-02-20 18:00:07,970 INFO L272 TraceCheckUtils]: 81: Hoare triple {11693#false} call outgoing__wrappee__AutoResponder_#t~ret62#1 := getEmailTo(outgoing__wrappee__AutoResponder_~msg#1); {11693#false} is VALID [2022-02-20 18:00:07,970 INFO L290 TraceCheckUtils]: 82: Hoare triple {11693#false} ~handle := #in~handle;havoc ~retValue_acc~36; {11693#false} is VALID [2022-02-20 18:00:07,970 INFO L290 TraceCheckUtils]: 83: Hoare triple {11693#false} assume 1 == ~handle;~retValue_acc~36 := ~__ste_email_to0~0;#res := ~retValue_acc~36; {11693#false} is VALID [2022-02-20 18:00:07,970 INFO L290 TraceCheckUtils]: 84: Hoare triple {11693#false} assume true; {11693#false} is VALID [2022-02-20 18:00:07,970 INFO L284 TraceCheckUtils]: 85: Hoare quadruple {11693#false} {11693#false} #1056#return; {11693#false} is VALID [2022-02-20 18:00:07,970 INFO L290 TraceCheckUtils]: 86: Hoare triple {11693#false} assume -2147483648 <= outgoing__wrappee__AutoResponder_#t~ret62#1 && outgoing__wrappee__AutoResponder_#t~ret62#1 <= 2147483647;outgoing__wrappee__AutoResponder_~tmp~9#1 := outgoing__wrappee__AutoResponder_#t~ret62#1;havoc outgoing__wrappee__AutoResponder_#t~ret62#1;outgoing__wrappee__AutoResponder_~receiver~0#1 := outgoing__wrappee__AutoResponder_~tmp~9#1; {11693#false} is VALID [2022-02-20 18:00:07,970 INFO L272 TraceCheckUtils]: 87: Hoare triple {11693#false} call outgoing__wrappee__AutoResponder_#t~ret63#1 := findPublicKey(outgoing__wrappee__AutoResponder_~client#1, outgoing__wrappee__AutoResponder_~receiver~0#1); {11693#false} is VALID [2022-02-20 18:00:07,970 INFO L290 TraceCheckUtils]: 88: Hoare triple {11693#false} ~handle := #in~handle;~userid := #in~userid;havoc ~retValue_acc~25; {11693#false} is VALID [2022-02-20 18:00:07,971 INFO L290 TraceCheckUtils]: 89: Hoare triple {11693#false} assume 1 == ~handle; {11693#false} is VALID [2022-02-20 18:00:07,971 INFO L290 TraceCheckUtils]: 90: Hoare triple {11693#false} assume ~userid == ~__ste_Client_Keyring0_User0~0;~retValue_acc~25 := ~__ste_Client_Keyring0_PublicKey0~0;#res := ~retValue_acc~25; {11693#false} is VALID [2022-02-20 18:00:07,971 INFO L290 TraceCheckUtils]: 91: Hoare triple {11693#false} assume true; {11693#false} is VALID [2022-02-20 18:00:07,971 INFO L284 TraceCheckUtils]: 92: Hoare quadruple {11693#false} {11693#false} #1058#return; {11693#false} is VALID [2022-02-20 18:00:07,971 INFO L290 TraceCheckUtils]: 93: Hoare triple {11693#false} assume -2147483648 <= outgoing__wrappee__AutoResponder_#t~ret63#1 && outgoing__wrappee__AutoResponder_#t~ret63#1 <= 2147483647;outgoing__wrappee__AutoResponder_~tmp___0~3#1 := outgoing__wrappee__AutoResponder_#t~ret63#1;havoc outgoing__wrappee__AutoResponder_#t~ret63#1;outgoing__wrappee__AutoResponder_~pubkey~0#1 := outgoing__wrappee__AutoResponder_~tmp___0~3#1; {11693#false} is VALID [2022-02-20 18:00:07,971 INFO L290 TraceCheckUtils]: 94: Hoare triple {11693#false} assume !(0 != outgoing__wrappee__AutoResponder_~pubkey~0#1); {11693#false} is VALID [2022-02-20 18:00:07,971 INFO L290 TraceCheckUtils]: 95: Hoare triple {11693#false} assume { :begin_inline_outgoing__wrappee__Keys } true;outgoing__wrappee__Keys_#in~client#1, outgoing__wrappee__Keys_#in~msg#1 := outgoing__wrappee__AutoResponder_~client#1, outgoing__wrappee__AutoResponder_~msg#1;havoc outgoing__wrappee__Keys_#t~ret61#1, outgoing__wrappee__Keys_~client#1, outgoing__wrappee__Keys_~msg#1, outgoing__wrappee__Keys_~tmp~8#1;outgoing__wrappee__Keys_~client#1 := outgoing__wrappee__Keys_#in~client#1;outgoing__wrappee__Keys_~msg#1 := outgoing__wrappee__Keys_#in~msg#1;havoc outgoing__wrappee__Keys_~tmp~8#1;assume { :begin_inline_getClientId } true;getClientId_#in~handle#1 := outgoing__wrappee__Keys_~client#1;havoc getClientId_#res#1;havoc getClientId_~handle#1, getClientId_~retValue_acc~27#1;getClientId_~handle#1 := getClientId_#in~handle#1;havoc getClientId_~retValue_acc~27#1; {11693#false} is VALID [2022-02-20 18:00:07,972 INFO L290 TraceCheckUtils]: 96: Hoare triple {11693#false} assume 1 == getClientId_~handle#1;getClientId_~retValue_acc~27#1 := ~__ste_client_idCounter0~0;getClientId_#res#1 := getClientId_~retValue_acc~27#1; {11693#false} is VALID [2022-02-20 18:00:07,972 INFO L290 TraceCheckUtils]: 97: Hoare triple {11693#false} outgoing__wrappee__Keys_#t~ret61#1 := getClientId_#res#1;assume { :end_inline_getClientId } true;assume -2147483648 <= outgoing__wrappee__Keys_#t~ret61#1 && outgoing__wrappee__Keys_#t~ret61#1 <= 2147483647;outgoing__wrappee__Keys_~tmp~8#1 := outgoing__wrappee__Keys_#t~ret61#1;havoc outgoing__wrappee__Keys_#t~ret61#1; {11693#false} is VALID [2022-02-20 18:00:07,972 INFO L272 TraceCheckUtils]: 98: Hoare triple {11693#false} call setEmailFrom(outgoing__wrappee__Keys_~msg#1, outgoing__wrappee__Keys_~tmp~8#1); {11693#false} is VALID [2022-02-20 18:00:07,972 INFO L290 TraceCheckUtils]: 99: Hoare triple {11693#false} ~handle := #in~handle;~value := #in~value; {11693#false} is VALID [2022-02-20 18:00:07,972 INFO L290 TraceCheckUtils]: 100: Hoare triple {11693#false} assume 1 == ~handle;~__ste_email_from0~0 := ~value; {11693#false} is VALID [2022-02-20 18:00:07,972 INFO L290 TraceCheckUtils]: 101: Hoare triple {11693#false} assume true; {11693#false} is VALID [2022-02-20 18:00:07,972 INFO L284 TraceCheckUtils]: 102: Hoare quadruple {11693#false} {11693#false} #1064#return; {11693#false} is VALID [2022-02-20 18:00:07,972 INFO L290 TraceCheckUtils]: 103: Hoare triple {11693#false} assume { :begin_inline_mail } true;mail_#in~client#1, mail_#in~msg#1 := outgoing__wrappee__Keys_~client#1, outgoing__wrappee__Keys_~msg#1;havoc mail_#t~ret59#1, mail_#t~ret60#1, mail_~client#1, mail_~msg#1, mail_~__utac__ad__arg1~0#1, mail_~__utac__ad__arg2~0#1, mail_~tmp~7#1;mail_~client#1 := mail_#in~client#1;mail_~msg#1 := mail_#in~msg#1;havoc mail_~__utac__ad__arg1~0#1;havoc mail_~__utac__ad__arg2~0#1;havoc mail_~tmp~7#1;mail_~__utac__ad__arg1~0#1 := mail_~client#1;mail_~__utac__ad__arg2~0#1 := mail_~msg#1;assume { :begin_inline___utac_acc__SignForward_spec__1 } true;__utac_acc__SignForward_spec__1_#in~client#1, __utac_acc__SignForward_spec__1_#in~msg#1 := mail_~__utac__ad__arg1~0#1, mail_~__utac__ad__arg2~0#1;havoc __utac_acc__SignForward_spec__1_#t~ret107#1, __utac_acc__SignForward_spec__1_#t~ret108#1, __utac_acc__SignForward_spec__1_#t~ret109#1, __utac_acc__SignForward_spec__1_~client#1, __utac_acc__SignForward_spec__1_~msg#1, __utac_acc__SignForward_spec__1_~tmp~25#1, __utac_acc__SignForward_spec__1_~tmp___0~9#1;__utac_acc__SignForward_spec__1_~client#1 := __utac_acc__SignForward_spec__1_#in~client#1;__utac_acc__SignForward_spec__1_~msg#1 := __utac_acc__SignForward_spec__1_#in~msg#1;havoc __utac_acc__SignForward_spec__1_~tmp~25#1;havoc __utac_acc__SignForward_spec__1_~tmp___0~9#1;call __utac_acc__SignForward_spec__1_#t~ret107#1 := puts(39, 0);assume -2147483648 <= __utac_acc__SignForward_spec__1_#t~ret107#1 && __utac_acc__SignForward_spec__1_#t~ret107#1 <= 2147483647;havoc __utac_acc__SignForward_spec__1_#t~ret107#1; {11693#false} is VALID [2022-02-20 18:00:07,973 INFO L272 TraceCheckUtils]: 104: Hoare triple {11693#false} call __utac_acc__SignForward_spec__1_#t~ret108#1 := isSigned(__utac_acc__SignForward_spec__1_~msg#1); {11693#false} is VALID [2022-02-20 18:00:07,973 INFO L290 TraceCheckUtils]: 105: Hoare triple {11693#false} ~handle := #in~handle;havoc ~retValue_acc~41; {11693#false} is VALID [2022-02-20 18:00:07,973 INFO L290 TraceCheckUtils]: 106: Hoare triple {11693#false} assume 1 == ~handle;~retValue_acc~41 := ~__ste_email_isSigned0~0;#res := ~retValue_acc~41; {11693#false} is VALID [2022-02-20 18:00:07,973 INFO L290 TraceCheckUtils]: 107: Hoare triple {11693#false} assume true; {11693#false} is VALID [2022-02-20 18:00:07,973 INFO L284 TraceCheckUtils]: 108: Hoare quadruple {11693#false} {11693#false} #1066#return; {11693#false} is VALID [2022-02-20 18:00:07,973 INFO L290 TraceCheckUtils]: 109: Hoare triple {11693#false} assume -2147483648 <= __utac_acc__SignForward_spec__1_#t~ret108#1 && __utac_acc__SignForward_spec__1_#t~ret108#1 <= 2147483647;__utac_acc__SignForward_spec__1_~tmp___0~9#1 := __utac_acc__SignForward_spec__1_#t~ret108#1;havoc __utac_acc__SignForward_spec__1_#t~ret108#1; {11693#false} is VALID [2022-02-20 18:00:07,974 INFO L290 TraceCheckUtils]: 110: Hoare triple {11693#false} assume 0 != __utac_acc__SignForward_spec__1_~tmp___0~9#1; {11693#false} is VALID [2022-02-20 18:00:07,974 INFO L272 TraceCheckUtils]: 111: Hoare triple {11693#false} call __utac_acc__SignForward_spec__1_#t~ret109#1 := getClientPrivateKey(__utac_acc__SignForward_spec__1_~client#1); {11693#false} is VALID [2022-02-20 18:00:07,974 INFO L290 TraceCheckUtils]: 112: Hoare triple {11693#false} ~handle := #in~handle;havoc ~retValue_acc~20; {11693#false} is VALID [2022-02-20 18:00:07,974 INFO L290 TraceCheckUtils]: 113: Hoare triple {11693#false} assume 1 == ~handle;~retValue_acc~20 := ~__ste_client_privateKey0~0;#res := ~retValue_acc~20; {11693#false} is VALID [2022-02-20 18:00:07,974 INFO L290 TraceCheckUtils]: 114: Hoare triple {11693#false} assume true; {11693#false} is VALID [2022-02-20 18:00:07,974 INFO L284 TraceCheckUtils]: 115: Hoare quadruple {11693#false} {11693#false} #1068#return; {11693#false} is VALID [2022-02-20 18:00:07,974 INFO L290 TraceCheckUtils]: 116: Hoare triple {11693#false} assume -2147483648 <= __utac_acc__SignForward_spec__1_#t~ret109#1 && __utac_acc__SignForward_spec__1_#t~ret109#1 <= 2147483647;__utac_acc__SignForward_spec__1_~tmp~25#1 := __utac_acc__SignForward_spec__1_#t~ret109#1;havoc __utac_acc__SignForward_spec__1_#t~ret109#1; {11693#false} is VALID [2022-02-20 18:00:07,974 INFO L290 TraceCheckUtils]: 117: Hoare triple {11693#false} assume 0 == __utac_acc__SignForward_spec__1_~tmp~25#1;assume { :begin_inline___automaton_fail } true; {11693#false} is VALID [2022-02-20 18:00:07,975 INFO L290 TraceCheckUtils]: 118: Hoare triple {11693#false} assume !false; {11693#false} is VALID [2022-02-20 18:00:07,975 INFO L134 CoverageAnalysis]: Checked inductivity of 34 backedges. 19 proven. 0 refuted. 0 times theorem prover too weak. 15 trivial. 0 not checked. [2022-02-20 18:00:07,975 INFO L324 TraceCheckSpWp]: Omiting computation of backward sequence because forward sequence was already perfect [2022-02-20 18:00:07,975 INFO L165 FreeRefinementEngine]: IpTcStrategyModuleZ3 [1867605390] provided 1 perfect and 0 imperfect interpolant sequences [2022-02-20 18:00:07,975 INFO L191 FreeRefinementEngine]: Found 1 perfect and 1 imperfect interpolant sequences. [2022-02-20 18:00:07,976 INFO L204 FreeRefinementEngine]: Number of different interpolants: perfect sequences [5] imperfect sequences [12] total 15 [2022-02-20 18:00:07,976 INFO L118 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [917597740] [2022-02-20 18:00:07,976 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2022-02-20 18:00:07,977 INFO L78 Accepts]: Start accepts. Automaton has has 5 states, 5 states have (on average 16.0) internal successors, (80), 5 states have internal predecessors, (80), 3 states have call successors, (16), 2 states have call predecessors, (16), 3 states have return successors, (14), 3 states have call predecessors, (14), 3 states have call successors, (14) Word has length 119 [2022-02-20 18:00:07,978 INFO L84 Accepts]: Finished accepts. word is accepted. [2022-02-20 18:00:07,978 INFO L86 InductivityCheck]: Starting indutivity check of a Floyd-Hoare automaton with has 5 states, 5 states have (on average 16.0) internal successors, (80), 5 states have internal predecessors, (80), 3 states have call successors, (16), 2 states have call predecessors, (16), 3 states have return successors, (14), 3 states have call predecessors, (14), 3 states have call successors, (14) [2022-02-20 18:00:08,048 INFO L122 InductivityCheck]: Floyd-Hoare automaton has 110 edges. 110 inductive. 0 not inductive. 0 times theorem prover too weak to decide inductivity. [2022-02-20 18:00:08,049 INFO L546 AbstractCegarLoop]: INTERPOLANT automaton has 5 states [2022-02-20 18:00:08,049 INFO L108 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2022-02-20 18:00:08,050 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 5 interpolants. [2022-02-20 18:00:08,050 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=30, Invalid=180, Unknown=0, NotChecked=0, Total=210 [2022-02-20 18:00:08,050 INFO L87 Difference]: Start difference. First operand 439 states and 660 transitions. Second operand has 5 states, 5 states have (on average 16.0) internal successors, (80), 5 states have internal predecessors, (80), 3 states have call successors, (16), 2 states have call predecessors, (16), 3 states have return successors, (14), 3 states have call predecessors, (14), 3 states have call successors, (14) [2022-02-20 18:00:09,078 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-02-20 18:00:09,079 INFO L93 Difference]: Finished difference Result 867 states and 1309 transitions. [2022-02-20 18:00:09,079 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 5 states. [2022-02-20 18:00:09,079 INFO L78 Accepts]: Start accepts. Automaton has has 5 states, 5 states have (on average 16.0) internal successors, (80), 5 states have internal predecessors, (80), 3 states have call successors, (16), 2 states have call predecessors, (16), 3 states have return successors, (14), 3 states have call predecessors, (14), 3 states have call successors, (14) Word has length 119 [2022-02-20 18:00:09,079 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2022-02-20 18:00:09,080 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 5 states, 5 states have (on average 16.0) internal successors, (80), 5 states have internal predecessors, (80), 3 states have call successors, (16), 2 states have call predecessors, (16), 3 states have return successors, (14), 3 states have call predecessors, (14), 3 states have call successors, (14) [2022-02-20 18:00:09,090 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 5 states to 5 states and 1115 transitions. [2022-02-20 18:00:09,091 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 5 states, 5 states have (on average 16.0) internal successors, (80), 5 states have internal predecessors, (80), 3 states have call successors, (16), 2 states have call predecessors, (16), 3 states have return successors, (14), 3 states have call predecessors, (14), 3 states have call successors, (14) [2022-02-20 18:00:09,101 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 5 states to 5 states and 1115 transitions. [2022-02-20 18:00:09,101 INFO L86 InductivityCheck]: Starting indutivity check of a Floyd-Hoare automaton with 5 states and 1115 transitions. [2022-02-20 18:00:09,839 INFO L122 InductivityCheck]: Floyd-Hoare automaton has 1115 edges. 1115 inductive. 0 not inductive. 0 times theorem prover too weak to decide inductivity. [2022-02-20 18:00:09,856 INFO L225 Difference]: With dead ends: 867 [2022-02-20 18:00:09,857 INFO L226 Difference]: Without dead ends: 441 [2022-02-20 18:00:09,858 INFO L932 BasicCegarLoop]: 0 DeclaredPredicates, 153 GetRequests, 139 SyntacticMatches, 0 SemanticMatches, 14 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 4 ImplicationChecksByTransitivity, 0.1s TimeCoverageRelationStatistics Valid=34, Invalid=206, Unknown=0, NotChecked=0, Total=240 [2022-02-20 18:00:09,859 INFO L933 BasicCegarLoop]: 552 mSDtfsCounter, 132 mSDsluCounter, 1501 mSDsCounter, 0 mSdLazyCounter, 45 mSolverCounterSat, 0 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.0s Time, 0 mProtectedPredicate, 0 mProtectedAction, 152 SdHoareTripleChecker+Valid, 2053 SdHoareTripleChecker+Invalid, 45 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 0 IncrementalHoareTripleChecker+Valid, 45 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.0s IncrementalHoareTripleChecker+Time [2022-02-20 18:00:09,860 INFO L934 BasicCegarLoop]: SdHoareTripleChecker [152 Valid, 2053 Invalid, 45 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [0 Valid, 45 Invalid, 0 Unknown, 0 Unchecked, 0.0s Time] [2022-02-20 18:00:09,861 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 441 states. [2022-02-20 18:00:09,977 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 441 to 441. [2022-02-20 18:00:09,977 INFO L214 AbstractMinimizeNwa]: Start testing correctness of minimizeSevpa [2022-02-20 18:00:09,979 INFO L82 GeneralOperation]: Start isEquivalent. First operand 441 states. Second operand has 441 states, 340 states have (on average 1.5058823529411764) internal successors, (512), 345 states have internal predecessors, (512), 74 states have call successors, (74), 24 states have call predecessors, (74), 26 states have return successors, (80), 73 states have call predecessors, (80), 73 states have call successors, (80) [2022-02-20 18:00:09,980 INFO L74 IsIncluded]: Start isIncluded. First operand 441 states. Second operand has 441 states, 340 states have (on average 1.5058823529411764) internal successors, (512), 345 states have internal predecessors, (512), 74 states have call successors, (74), 24 states have call predecessors, (74), 26 states have return successors, (80), 73 states have call predecessors, (80), 73 states have call successors, (80) [2022-02-20 18:00:09,981 INFO L87 Difference]: Start difference. First operand 441 states. Second operand has 441 states, 340 states have (on average 1.5058823529411764) internal successors, (512), 345 states have internal predecessors, (512), 74 states have call successors, (74), 24 states have call predecessors, (74), 26 states have return successors, (80), 73 states have call predecessors, (80), 73 states have call successors, (80) [2022-02-20 18:00:09,997 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-02-20 18:00:09,997 INFO L93 Difference]: Finished difference Result 441 states and 666 transitions. [2022-02-20 18:00:09,997 INFO L276 IsEmpty]: Start isEmpty. Operand 441 states and 666 transitions. [2022-02-20 18:00:09,999 INFO L282 IsEmpty]: Finished isEmpty. No accepting run. [2022-02-20 18:00:09,999 INFO L83 IsIncluded]: Finished isIncluded. Language is included [2022-02-20 18:00:10,001 INFO L74 IsIncluded]: Start isIncluded. First operand has 441 states, 340 states have (on average 1.5058823529411764) internal successors, (512), 345 states have internal predecessors, (512), 74 states have call successors, (74), 24 states have call predecessors, (74), 26 states have return successors, (80), 73 states have call predecessors, (80), 73 states have call successors, (80) Second operand 441 states. [2022-02-20 18:00:10,002 INFO L87 Difference]: Start difference. First operand has 441 states, 340 states have (on average 1.5058823529411764) internal successors, (512), 345 states have internal predecessors, (512), 74 states have call successors, (74), 24 states have call predecessors, (74), 26 states have return successors, (80), 73 states have call predecessors, (80), 73 states have call successors, (80) Second operand 441 states. [2022-02-20 18:00:10,018 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-02-20 18:00:10,018 INFO L93 Difference]: Finished difference Result 441 states and 666 transitions. [2022-02-20 18:00:10,018 INFO L276 IsEmpty]: Start isEmpty. Operand 441 states and 666 transitions. [2022-02-20 18:00:10,020 INFO L282 IsEmpty]: Finished isEmpty. No accepting run. [2022-02-20 18:00:10,020 INFO L83 IsIncluded]: Finished isIncluded. Language is included [2022-02-20 18:00:10,020 INFO L88 GeneralOperation]: Finished isEquivalent. [2022-02-20 18:00:10,020 INFO L221 AbstractMinimizeNwa]: Finished testing correctness of minimizeSevpa [2022-02-20 18:00:10,022 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 441 states, 340 states have (on average 1.5058823529411764) internal successors, (512), 345 states have internal predecessors, (512), 74 states have call successors, (74), 24 states have call predecessors, (74), 26 states have return successors, (80), 73 states have call predecessors, (80), 73 states have call successors, (80) [2022-02-20 18:00:10,040 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 441 states to 441 states and 666 transitions. [2022-02-20 18:00:10,040 INFO L78 Accepts]: Start accepts. Automaton has 441 states and 666 transitions. Word has length 119 [2022-02-20 18:00:10,040 INFO L84 Accepts]: Finished accepts. word is rejected. [2022-02-20 18:00:10,041 INFO L470 AbstractCegarLoop]: Abstraction has 441 states and 666 transitions. [2022-02-20 18:00:10,041 INFO L471 AbstractCegarLoop]: INTERPOLANT automaton has has 5 states, 5 states have (on average 16.0) internal successors, (80), 5 states have internal predecessors, (80), 3 states have call successors, (16), 2 states have call predecessors, (16), 3 states have return successors, (14), 3 states have call predecessors, (14), 3 states have call successors, (14) [2022-02-20 18:00:10,041 INFO L276 IsEmpty]: Start isEmpty. Operand 441 states and 666 transitions. [2022-02-20 18:00:10,043 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 121 [2022-02-20 18:00:10,043 INFO L506 BasicCegarLoop]: Found error trace [2022-02-20 18:00:10,043 INFO L514 BasicCegarLoop]: trace histogram [3, 3, 3, 3, 2, 2, 2, 2, 2, 2, 2, 2, 2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-02-20 18:00:10,091 INFO L552 MonitoredProcess]: [MP /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 -smt2 -in SMTLIB2_COMPLIANT=true (6)] Ended with exit code 0 [2022-02-20 18:00:10,262 WARN L452 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable4,6 /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 -smt2 -in SMTLIB2_COMPLIANT=true [2022-02-20 18:00:10,263 INFO L402 AbstractCegarLoop]: === Iteration 6 === Targeting outgoingErr0ASSERT_VIOLATIONERROR_FUNCTION === [outgoingErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2022-02-20 18:00:10,263 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2022-02-20 18:00:10,263 INFO L85 PathProgramCache]: Analyzing trace with hash -164798134, now seen corresponding path program 1 times [2022-02-20 18:00:10,263 INFO L126 FreeRefinementEngine]: Executing refinement strategy CAMEL [2022-02-20 18:00:10,263 INFO L338 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [524129602] [2022-02-20 18:00:10,263 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-02-20 18:00:10,264 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2022-02-20 18:00:10,292 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-02-20 18:00:10,317 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 6 [2022-02-20 18:00:10,319 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-02-20 18:00:10,321 INFO L290 TraceCheckUtils]: 0: Hoare triple {14920#(and (= |old(~__ste_client_idCounter0~0)| ~__ste_client_idCounter0~0) (= |old(~__ste_client_idCounter1~0)| ~__ste_client_idCounter1~0) (= |old(~__ste_client_idCounter2~0)| ~__ste_client_idCounter2~0))} ~handle := #in~handle;~value := #in~value; {14858#true} is VALID [2022-02-20 18:00:10,321 INFO L290 TraceCheckUtils]: 1: Hoare triple {14858#true} assume 1 == ~handle;~__ste_client_idCounter0~0 := ~value; {14858#true} is VALID [2022-02-20 18:00:10,321 INFO L290 TraceCheckUtils]: 2: Hoare triple {14858#true} assume true; {14858#true} is VALID [2022-02-20 18:00:10,321 INFO L284 TraceCheckUtils]: 3: Hoare quadruple {14858#true} {14858#true} #1134#return; {14858#true} is VALID [2022-02-20 18:00:10,327 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 12 [2022-02-20 18:00:10,328 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-02-20 18:00:10,331 INFO L290 TraceCheckUtils]: 0: Hoare triple {14921#(and (= ~__ste_client_privateKey0~0 |old(~__ste_client_privateKey0~0)|) (= ~__ste_client_privateKey2~0 |old(~__ste_client_privateKey2~0)|) (= ~__ste_client_privateKey1~0 |old(~__ste_client_privateKey1~0)|))} ~handle := #in~handle;~value := #in~value; {14858#true} is VALID [2022-02-20 18:00:10,331 INFO L290 TraceCheckUtils]: 1: Hoare triple {14858#true} assume 1 == ~handle;~__ste_client_privateKey0~0 := ~value; {14858#true} is VALID [2022-02-20 18:00:10,331 INFO L290 TraceCheckUtils]: 2: Hoare triple {14858#true} assume true; {14858#true} is VALID [2022-02-20 18:00:10,331 INFO L284 TraceCheckUtils]: 3: Hoare quadruple {14858#true} {14858#true} #1136#return; {14858#true} is VALID [2022-02-20 18:00:10,331 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 18 [2022-02-20 18:00:10,333 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-02-20 18:00:10,335 INFO L290 TraceCheckUtils]: 0: Hoare triple {14920#(and (= |old(~__ste_client_idCounter0~0)| ~__ste_client_idCounter0~0) (= |old(~__ste_client_idCounter1~0)| ~__ste_client_idCounter1~0) (= |old(~__ste_client_idCounter2~0)| ~__ste_client_idCounter2~0))} ~handle := #in~handle;~value := #in~value; {14858#true} is VALID [2022-02-20 18:00:10,335 INFO L290 TraceCheckUtils]: 1: Hoare triple {14858#true} assume !(1 == ~handle); {14858#true} is VALID [2022-02-20 18:00:10,335 INFO L290 TraceCheckUtils]: 2: Hoare triple {14858#true} assume 2 == ~handle;~__ste_client_idCounter1~0 := ~value; {14858#true} is VALID [2022-02-20 18:00:10,335 INFO L290 TraceCheckUtils]: 3: Hoare triple {14858#true} assume true; {14858#true} is VALID [2022-02-20 18:00:10,335 INFO L284 TraceCheckUtils]: 4: Hoare quadruple {14858#true} {14858#true} #1138#return; {14858#true} is VALID [2022-02-20 18:00:10,335 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 25 [2022-02-20 18:00:10,338 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-02-20 18:00:10,341 INFO L290 TraceCheckUtils]: 0: Hoare triple {14921#(and (= ~__ste_client_privateKey0~0 |old(~__ste_client_privateKey0~0)|) (= ~__ste_client_privateKey2~0 |old(~__ste_client_privateKey2~0)|) (= ~__ste_client_privateKey1~0 |old(~__ste_client_privateKey1~0)|))} ~handle := #in~handle;~value := #in~value; {14858#true} is VALID [2022-02-20 18:00:10,341 INFO L290 TraceCheckUtils]: 1: Hoare triple {14858#true} assume !(1 == ~handle); {14858#true} is VALID [2022-02-20 18:00:10,341 INFO L290 TraceCheckUtils]: 2: Hoare triple {14858#true} assume 2 == ~handle;~__ste_client_privateKey1~0 := ~value; {14858#true} is VALID [2022-02-20 18:00:10,341 INFO L290 TraceCheckUtils]: 3: Hoare triple {14858#true} assume true; {14858#true} is VALID [2022-02-20 18:00:10,342 INFO L284 TraceCheckUtils]: 4: Hoare quadruple {14858#true} {14858#true} #1140#return; {14858#true} is VALID [2022-02-20 18:00:10,342 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 32 [2022-02-20 18:00:10,344 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-02-20 18:00:10,357 INFO L290 TraceCheckUtils]: 0: Hoare triple {14920#(and (= |old(~__ste_client_idCounter0~0)| ~__ste_client_idCounter0~0) (= |old(~__ste_client_idCounter1~0)| ~__ste_client_idCounter1~0) (= |old(~__ste_client_idCounter2~0)| ~__ste_client_idCounter2~0))} ~handle := #in~handle;~value := #in~value; {14922#(= setClientId_~handle |setClientId_#in~handle|)} is VALID [2022-02-20 18:00:10,358 INFO L290 TraceCheckUtils]: 1: Hoare triple {14922#(= setClientId_~handle |setClientId_#in~handle|)} assume 1 == ~handle;~__ste_client_idCounter0~0 := ~value; {14923#(= |setClientId_#in~handle| 1)} is VALID [2022-02-20 18:00:10,358 INFO L290 TraceCheckUtils]: 2: Hoare triple {14923#(= |setClientId_#in~handle| 1)} assume true; {14923#(= |setClientId_#in~handle| 1)} is VALID [2022-02-20 18:00:10,359 INFO L284 TraceCheckUtils]: 3: Hoare quadruple {14923#(= |setClientId_#in~handle| 1)} {14878#(= 3 |ULTIMATE.start_setup_chuck__wrappee__Base_~chuck___0#1|)} #1142#return; {14859#false} is VALID [2022-02-20 18:00:10,359 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 38 [2022-02-20 18:00:10,361 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-02-20 18:00:10,363 INFO L290 TraceCheckUtils]: 0: Hoare triple {14921#(and (= ~__ste_client_privateKey0~0 |old(~__ste_client_privateKey0~0)|) (= ~__ste_client_privateKey2~0 |old(~__ste_client_privateKey2~0)|) (= ~__ste_client_privateKey1~0 |old(~__ste_client_privateKey1~0)|))} ~handle := #in~handle;~value := #in~value; {14858#true} is VALID [2022-02-20 18:00:10,363 INFO L290 TraceCheckUtils]: 1: Hoare triple {14858#true} assume 1 == ~handle;~__ste_client_privateKey0~0 := ~value; {14858#true} is VALID [2022-02-20 18:00:10,363 INFO L290 TraceCheckUtils]: 2: Hoare triple {14858#true} assume true; {14858#true} is VALID [2022-02-20 18:00:10,364 INFO L284 TraceCheckUtils]: 3: Hoare quadruple {14858#true} {14859#false} #1144#return; {14859#false} is VALID [2022-02-20 18:00:10,370 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 60 [2022-02-20 18:00:10,371 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-02-20 18:00:10,373 INFO L290 TraceCheckUtils]: 0: Hoare triple {14924#(and (= |old(~__ste_email_from0~0)| ~__ste_email_from0~0) (= |old(~__ste_email_from1~0)| ~__ste_email_from1~0))} ~handle := #in~handle;~value := #in~value; {14858#true} is VALID [2022-02-20 18:00:10,374 INFO L290 TraceCheckUtils]: 1: Hoare triple {14858#true} assume 1 == ~handle;~__ste_email_from0~0 := ~value; {14858#true} is VALID [2022-02-20 18:00:10,374 INFO L290 TraceCheckUtils]: 2: Hoare triple {14858#true} assume true; {14858#true} is VALID [2022-02-20 18:00:10,374 INFO L284 TraceCheckUtils]: 3: Hoare quadruple {14858#true} {14859#false} #1120#return; {14859#false} is VALID [2022-02-20 18:00:10,381 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 65 [2022-02-20 18:00:10,382 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-02-20 18:00:10,384 INFO L290 TraceCheckUtils]: 0: Hoare triple {14925#(and (= ~__ste_email_to0~0 |old(~__ste_email_to0~0)|) (= ~__ste_email_to1~0 |old(~__ste_email_to1~0)|))} ~handle := #in~handle;~value := #in~value; {14858#true} is VALID [2022-02-20 18:00:10,384 INFO L290 TraceCheckUtils]: 1: Hoare triple {14858#true} assume 1 == ~handle;~__ste_email_to0~0 := ~value; {14858#true} is VALID [2022-02-20 18:00:10,385 INFO L290 TraceCheckUtils]: 2: Hoare triple {14858#true} assume true; {14858#true} is VALID [2022-02-20 18:00:10,385 INFO L284 TraceCheckUtils]: 3: Hoare quadruple {14858#true} {14859#false} #1122#return; {14859#false} is VALID [2022-02-20 18:00:10,385 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 74 [2022-02-20 18:00:10,386 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-02-20 18:00:10,388 INFO L290 TraceCheckUtils]: 0: Hoare triple {14858#true} ~handle := #in~handle;havoc ~retValue_acc~20; {14858#true} is VALID [2022-02-20 18:00:10,388 INFO L290 TraceCheckUtils]: 1: Hoare triple {14858#true} assume 1 == ~handle;~retValue_acc~20 := ~__ste_client_privateKey0~0;#res := ~retValue_acc~20; {14858#true} is VALID [2022-02-20 18:00:10,388 INFO L290 TraceCheckUtils]: 2: Hoare triple {14858#true} assume true; {14858#true} is VALID [2022-02-20 18:00:10,389 INFO L284 TraceCheckUtils]: 3: Hoare quadruple {14858#true} {14859#false} #1054#return; {14859#false} is VALID [2022-02-20 18:00:10,389 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 82 [2022-02-20 18:00:10,390 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-02-20 18:00:10,392 INFO L290 TraceCheckUtils]: 0: Hoare triple {14858#true} ~handle := #in~handle;havoc ~retValue_acc~36; {14858#true} is VALID [2022-02-20 18:00:10,392 INFO L290 TraceCheckUtils]: 1: Hoare triple {14858#true} assume 1 == ~handle;~retValue_acc~36 := ~__ste_email_to0~0;#res := ~retValue_acc~36; {14858#true} is VALID [2022-02-20 18:00:10,392 INFO L290 TraceCheckUtils]: 2: Hoare triple {14858#true} assume true; {14858#true} is VALID [2022-02-20 18:00:10,392 INFO L284 TraceCheckUtils]: 3: Hoare quadruple {14858#true} {14859#false} #1056#return; {14859#false} is VALID [2022-02-20 18:00:10,392 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 88 [2022-02-20 18:00:10,393 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-02-20 18:00:10,395 INFO L290 TraceCheckUtils]: 0: Hoare triple {14858#true} ~handle := #in~handle;~userid := #in~userid;havoc ~retValue_acc~25; {14858#true} is VALID [2022-02-20 18:00:10,395 INFO L290 TraceCheckUtils]: 1: Hoare triple {14858#true} assume 1 == ~handle; {14858#true} is VALID [2022-02-20 18:00:10,395 INFO L290 TraceCheckUtils]: 2: Hoare triple {14858#true} assume ~userid == ~__ste_Client_Keyring0_User0~0;~retValue_acc~25 := ~__ste_Client_Keyring0_PublicKey0~0;#res := ~retValue_acc~25; {14858#true} is VALID [2022-02-20 18:00:10,395 INFO L290 TraceCheckUtils]: 3: Hoare triple {14858#true} assume true; {14858#true} is VALID [2022-02-20 18:00:10,395 INFO L284 TraceCheckUtils]: 4: Hoare quadruple {14858#true} {14859#false} #1058#return; {14859#false} is VALID [2022-02-20 18:00:10,396 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 99 [2022-02-20 18:00:10,397 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-02-20 18:00:10,399 INFO L290 TraceCheckUtils]: 0: Hoare triple {14924#(and (= |old(~__ste_email_from0~0)| ~__ste_email_from0~0) (= |old(~__ste_email_from1~0)| ~__ste_email_from1~0))} ~handle := #in~handle;~value := #in~value; {14858#true} is VALID [2022-02-20 18:00:10,399 INFO L290 TraceCheckUtils]: 1: Hoare triple {14858#true} assume 1 == ~handle;~__ste_email_from0~0 := ~value; {14858#true} is VALID [2022-02-20 18:00:10,399 INFO L290 TraceCheckUtils]: 2: Hoare triple {14858#true} assume true; {14858#true} is VALID [2022-02-20 18:00:10,399 INFO L284 TraceCheckUtils]: 3: Hoare quadruple {14858#true} {14859#false} #1064#return; {14859#false} is VALID [2022-02-20 18:00:10,399 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 105 [2022-02-20 18:00:10,400 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-02-20 18:00:10,402 INFO L290 TraceCheckUtils]: 0: Hoare triple {14858#true} ~handle := #in~handle;havoc ~retValue_acc~41; {14858#true} is VALID [2022-02-20 18:00:10,402 INFO L290 TraceCheckUtils]: 1: Hoare triple {14858#true} assume 1 == ~handle;~retValue_acc~41 := ~__ste_email_isSigned0~0;#res := ~retValue_acc~41; {14858#true} is VALID [2022-02-20 18:00:10,402 INFO L290 TraceCheckUtils]: 2: Hoare triple {14858#true} assume true; {14858#true} is VALID [2022-02-20 18:00:10,403 INFO L284 TraceCheckUtils]: 3: Hoare quadruple {14858#true} {14859#false} #1066#return; {14859#false} is VALID [2022-02-20 18:00:10,403 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 112 [2022-02-20 18:00:10,404 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-02-20 18:00:10,406 INFO L290 TraceCheckUtils]: 0: Hoare triple {14858#true} ~handle := #in~handle;havoc ~retValue_acc~20; {14858#true} is VALID [2022-02-20 18:00:10,406 INFO L290 TraceCheckUtils]: 1: Hoare triple {14858#true} assume 1 == ~handle;~retValue_acc~20 := ~__ste_client_privateKey0~0;#res := ~retValue_acc~20; {14858#true} is VALID [2022-02-20 18:00:10,406 INFO L290 TraceCheckUtils]: 2: Hoare triple {14858#true} assume true; {14858#true} is VALID [2022-02-20 18:00:10,406 INFO L284 TraceCheckUtils]: 3: Hoare quadruple {14858#true} {14859#false} #1068#return; {14859#false} is VALID [2022-02-20 18:00:10,406 INFO L290 TraceCheckUtils]: 0: Hoare triple {14858#true} assume { :begin_inline_ULTIMATE.init } true;#NULL.base, #NULL.offset := 0, 0;assume 0 == #valid[0];assume 0 < #StackHeapBarrier;call #Ultimate.allocInit(2, 1);call write~init~int(48, 1, 0, 1);call write~init~int(0, 1, 1, 1);call #Ultimate.allocInit(28, 2);call #Ultimate.allocInit(12, 3);call #Ultimate.allocInit(30, 4);call #Ultimate.allocInit(9, 5);call #Ultimate.allocInit(21, 6);call #Ultimate.allocInit(30, 7);call #Ultimate.allocInit(9, 8);call #Ultimate.allocInit(21, 9);call #Ultimate.allocInit(30, 10);call #Ultimate.allocInit(9, 11);call #Ultimate.allocInit(25, 12);call #Ultimate.allocInit(30, 13);call #Ultimate.allocInit(9, 14);call #Ultimate.allocInit(25, 15);call #Ultimate.allocInit(44, 16);call #Ultimate.allocInit(44, 17);call #Ultimate.allocInit(9, 18);call #Ultimate.allocInit(9, 19);call #Ultimate.allocInit(11, 20);call #Ultimate.allocInit(19, 21);call #Ultimate.allocInit(4, 22);call write~init~int(37, 22, 0, 1);call write~init~int(100, 22, 1, 1);call write~init~int(10, 22, 2, 1);call write~init~int(0, 22, 3, 1);call #Ultimate.allocInit(4, 23);call write~init~int(37, 23, 0, 1);call write~init~int(100, 23, 1, 1);call write~init~int(10, 23, 2, 1);call write~init~int(0, 23, 3, 1);call #Ultimate.allocInit(10, 24);call #Ultimate.allocInit(16, 25);call #Ultimate.allocInit(20, 26);call #Ultimate.allocInit(22, 27);call #Ultimate.allocInit(21, 28);call #Ultimate.allocInit(10, 29);call #Ultimate.allocInit(12, 30);call #Ultimate.allocInit(10, 31);call #Ultimate.allocInit(18, 32);call #Ultimate.allocInit(16, 33);call #Ultimate.allocInit(21, 34);call #Ultimate.allocInit(13, 35);call #Ultimate.allocInit(16, 36);call #Ultimate.allocInit(25, 37);call #Ultimate.allocInit(4, 38);call write~init~int(37, 38, 0, 1);call write~init~int(115, 38, 1, 1);call write~init~int(10, 38, 2, 1);call write~init~int(0, 38, 3, 1);call #Ultimate.allocInit(13, 39);~head~0.base, ~head~0.offset := 0, 0;~__SELECTED_FEATURE_Base~0 := 0;~__SELECTED_FEATURE_Keys~0 := 0;~__SELECTED_FEATURE_Encrypt~0 := 0;~__SELECTED_FEATURE_AutoResponder~0 := 0;~__SELECTED_FEATURE_AddressBook~0 := 0;~__SELECTED_FEATURE_Sign~0 := 0;~__SELECTED_FEATURE_Forward~0 := 0;~__SELECTED_FEATURE_Verify~0 := 0;~__SELECTED_FEATURE_Decrypt~0 := 0;~__GUIDSL_ROOT_PRODUCTION~0 := 0;~__GUIDSL_NON_TERMINAL_main~0 := 0;~bob~0 := 0;~rjh~0 := 0;~chuck~0 := 0;~queue_empty~0 := 1;~queued_message~0 := 0;~queued_client~0 := 0;~__ste_Client_counter~0 := 0;~__ste_client_name0~0.base, ~__ste_client_name0~0.offset := 0, 0;~__ste_client_name1~0.base, ~__ste_client_name1~0.offset := 0, 0;~__ste_client_name2~0.base, ~__ste_client_name2~0.offset := 0, 0;~__ste_client_outbuffer0~0 := 0;~__ste_client_outbuffer1~0 := 0;~__ste_client_outbuffer2~0 := 0;~__ste_client_outbuffer3~0 := 0;~__ste_ClientAddressBook_size0~0 := 0;~__ste_ClientAddressBook_size1~0 := 0;~__ste_ClientAddressBook_size2~0 := 0;~__ste_Client_AddressBook0_Alias0~0 := 0;~__ste_Client_AddressBook0_Alias1~0 := 0;~__ste_Client_AddressBook0_Alias2~0 := 0;~__ste_Client_AddressBook1_Alias0~0 := 0;~__ste_Client_AddressBook1_Alias1~0 := 0;~__ste_Client_AddressBook1_Alias2~0 := 0;~__ste_Client_AddressBook2_Alias0~0 := 0;~__ste_Client_AddressBook2_Alias1~0 := 0;~__ste_Client_AddressBook2_Alias2~0 := 0;~__ste_Client_AddressBook0_Address0~0 := 0;~__ste_Client_AddressBook0_Address1~0 := 0;~__ste_Client_AddressBook0_Address2~0 := 0;~__ste_Client_AddressBook1_Address0~0 := 0;~__ste_Client_AddressBook1_Address1~0 := 0;~__ste_Client_AddressBook1_Address2~0 := 0;~__ste_Client_AddressBook2_Address0~0 := 0;~__ste_Client_AddressBook2_Address1~0 := 0;~__ste_Client_AddressBook2_Address2~0 := 0;~__ste_client_autoResponse0~0 := 0;~__ste_client_autoResponse1~0 := 0;~__ste_client_autoResponse2~0 := 0;~__ste_client_privateKey0~0 := 0;~__ste_client_privateKey1~0 := 0;~__ste_client_privateKey2~0 := 0;~__ste_ClientKeyring_size0~0 := 0;~__ste_ClientKeyring_size1~0 := 0;~__ste_ClientKeyring_size2~0 := 0;~__ste_Client_Keyring0_User0~0 := 0;~__ste_Client_Keyring0_User1~0 := 0;~__ste_Client_Keyring0_User2~0 := 0;~__ste_Client_Keyring1_User0~0 := 0;~__ste_Client_Keyring1_User1~0 := 0;~__ste_Client_Keyring1_User2~0 := 0;~__ste_Client_Keyring2_User0~0 := 0;~__ste_Client_Keyring2_User1~0 := 0;~__ste_Client_Keyring2_User2~0 := 0;~__ste_Client_Keyring0_PublicKey0~0 := 0;~__ste_Client_Keyring0_PublicKey1~0 := 0;~__ste_Client_Keyring0_PublicKey2~0 := 0;~__ste_Client_Keyring1_PublicKey0~0 := 0;~__ste_Client_Keyring1_PublicKey1~0 := 0;~__ste_Client_Keyring1_PublicKey2~0 := 0;~__ste_Client_Keyring2_PublicKey0~0 := 0;~__ste_Client_Keyring2_PublicKey1~0 := 0;~__ste_Client_Keyring2_PublicKey2~0 := 0;~__ste_client_forwardReceiver0~0 := 0;~__ste_client_forwardReceiver1~0 := 0;~__ste_client_forwardReceiver2~0 := 0;~__ste_client_forwardReceiver3~0 := 0;~__ste_client_idCounter0~0 := 0;~__ste_client_idCounter1~0 := 0;~__ste_client_idCounter2~0 := 0;~__ste_Email_counter~0 := 0;~__ste_email_id0~0 := 0;~__ste_email_id1~0 := 0;~__ste_email_from0~0 := 0;~__ste_email_from1~0 := 0;~__ste_email_to0~0 := 0;~__ste_email_to1~0 := 0;~__ste_email_subject0~0.base, ~__ste_email_subject0~0.offset := 0, 0;~__ste_email_subject1~0.base, ~__ste_email_subject1~0.offset := 0, 0;~__ste_email_body0~0.base, ~__ste_email_body0~0.offset := 0, 0;~__ste_email_body1~0.base, ~__ste_email_body1~0.offset := 0, 0;~__ste_email_isEncrypted0~0 := 0;~__ste_email_isEncrypted1~0 := 0;~__ste_email_encryptionKey0~0 := 0;~__ste_email_encryptionKey1~0 := 0;~__ste_email_isSigned0~0 := 0;~__ste_email_isSigned1~0 := 0;~__ste_email_signKey0~0 := 0;~__ste_email_signKey1~0 := 0;~__ste_email_isSignatureVerified0~0 := 0;~__ste_email_isSignatureVerified1~0 := 0; {14858#true} is VALID [2022-02-20 18:00:10,407 INFO L290 TraceCheckUtils]: 1: Hoare triple {14858#true} assume { :end_inline_ULTIMATE.init } true;assume { :begin_inline_main } true;havoc main_#res#1;havoc main_#t~ret35#1, main_~retValue_acc~3#1, main_~tmp~4#1;havoc main_~retValue_acc~3#1;havoc main_~tmp~4#1;assume { :begin_inline_select_helpers } true; {14858#true} is VALID [2022-02-20 18:00:10,407 INFO L290 TraceCheckUtils]: 2: Hoare triple {14858#true} assume { :end_inline_select_helpers } true;assume { :begin_inline_select_features } true; {14858#true} is VALID [2022-02-20 18:00:10,407 INFO L290 TraceCheckUtils]: 3: Hoare triple {14858#true} assume { :end_inline_select_features } true;assume { :begin_inline_valid_product } true;havoc valid_product_#res#1;havoc valid_product_~retValue_acc~5#1;havoc valid_product_~retValue_acc~5#1;valid_product_~retValue_acc~5#1 := 1;valid_product_#res#1 := valid_product_~retValue_acc~5#1; {14858#true} is VALID [2022-02-20 18:00:10,407 INFO L290 TraceCheckUtils]: 4: Hoare triple {14858#true} main_#t~ret35#1 := valid_product_#res#1;assume { :end_inline_valid_product } true;assume -2147483648 <= main_#t~ret35#1 && main_#t~ret35#1 <= 2147483647;main_~tmp~4#1 := main_#t~ret35#1;havoc main_#t~ret35#1; {14858#true} is VALID [2022-02-20 18:00:10,407 INFO L290 TraceCheckUtils]: 5: Hoare triple {14858#true} assume 0 != main_~tmp~4#1;assume { :begin_inline_setup } true;havoc setup_#t~nondet32#1, setup_#t~nondet33#1, setup_#t~nondet34#1, setup_~__cil_tmp1~0#1.base, setup_~__cil_tmp1~0#1.offset, setup_~__cil_tmp2~0#1.base, setup_~__cil_tmp2~0#1.offset, setup_~__cil_tmp3~0#1.base, setup_~__cil_tmp3~0#1.offset;havoc setup_~__cil_tmp1~0#1.base, setup_~__cil_tmp1~0#1.offset;havoc setup_~__cil_tmp2~0#1.base, setup_~__cil_tmp2~0#1.offset;havoc setup_~__cil_tmp3~0#1.base, setup_~__cil_tmp3~0#1.offset;~bob~0 := 1;assume { :begin_inline_setup_bob } true;setup_bob_#in~bob___0#1 := ~bob~0;havoc setup_bob_~bob___0#1;setup_bob_~bob___0#1 := setup_bob_#in~bob___0#1;assume { :begin_inline_setup_bob__wrappee__Base } true;setup_bob__wrappee__Base_#in~bob___0#1 := setup_bob_~bob___0#1;havoc setup_bob__wrappee__Base_~bob___0#1;setup_bob__wrappee__Base_~bob___0#1 := setup_bob__wrappee__Base_#in~bob___0#1; {14858#true} is VALID [2022-02-20 18:00:10,408 INFO L272 TraceCheckUtils]: 6: Hoare triple {14858#true} call setClientId(setup_bob__wrappee__Base_~bob___0#1, setup_bob__wrappee__Base_~bob___0#1); {14920#(and (= |old(~__ste_client_idCounter0~0)| ~__ste_client_idCounter0~0) (= |old(~__ste_client_idCounter1~0)| ~__ste_client_idCounter1~0) (= |old(~__ste_client_idCounter2~0)| ~__ste_client_idCounter2~0))} is VALID [2022-02-20 18:00:10,408 INFO L290 TraceCheckUtils]: 7: Hoare triple {14920#(and (= |old(~__ste_client_idCounter0~0)| ~__ste_client_idCounter0~0) (= |old(~__ste_client_idCounter1~0)| ~__ste_client_idCounter1~0) (= |old(~__ste_client_idCounter2~0)| ~__ste_client_idCounter2~0))} ~handle := #in~handle;~value := #in~value; {14858#true} is VALID [2022-02-20 18:00:10,408 INFO L290 TraceCheckUtils]: 8: Hoare triple {14858#true} assume 1 == ~handle;~__ste_client_idCounter0~0 := ~value; {14858#true} is VALID [2022-02-20 18:00:10,408 INFO L290 TraceCheckUtils]: 9: Hoare triple {14858#true} assume true; {14858#true} is VALID [2022-02-20 18:00:10,408 INFO L284 TraceCheckUtils]: 10: Hoare quadruple {14858#true} {14858#true} #1134#return; {14858#true} is VALID [2022-02-20 18:00:10,409 INFO L290 TraceCheckUtils]: 11: Hoare triple {14858#true} assume { :end_inline_setup_bob__wrappee__Base } true; {14858#true} is VALID [2022-02-20 18:00:10,409 INFO L272 TraceCheckUtils]: 12: Hoare triple {14858#true} call setClientPrivateKey(setup_bob_~bob___0#1, 123); {14921#(and (= ~__ste_client_privateKey0~0 |old(~__ste_client_privateKey0~0)|) (= ~__ste_client_privateKey2~0 |old(~__ste_client_privateKey2~0)|) (= ~__ste_client_privateKey1~0 |old(~__ste_client_privateKey1~0)|))} is VALID [2022-02-20 18:00:10,409 INFO L290 TraceCheckUtils]: 13: Hoare triple {14921#(and (= ~__ste_client_privateKey0~0 |old(~__ste_client_privateKey0~0)|) (= ~__ste_client_privateKey2~0 |old(~__ste_client_privateKey2~0)|) (= ~__ste_client_privateKey1~0 |old(~__ste_client_privateKey1~0)|))} ~handle := #in~handle;~value := #in~value; {14858#true} is VALID [2022-02-20 18:00:10,409 INFO L290 TraceCheckUtils]: 14: Hoare triple {14858#true} assume 1 == ~handle;~__ste_client_privateKey0~0 := ~value; {14858#true} is VALID [2022-02-20 18:00:10,410 INFO L290 TraceCheckUtils]: 15: Hoare triple {14858#true} assume true; {14858#true} is VALID [2022-02-20 18:00:10,410 INFO L284 TraceCheckUtils]: 16: Hoare quadruple {14858#true} {14858#true} #1136#return; {14858#true} is VALID [2022-02-20 18:00:10,410 INFO L290 TraceCheckUtils]: 17: Hoare triple {14858#true} assume { :end_inline_setup_bob } true;setup_~__cil_tmp1~0#1.base, setup_~__cil_tmp1~0#1.offset := 18, 0;havoc setup_#t~nondet32#1;~rjh~0 := 2;assume { :begin_inline_setup_rjh } true;setup_rjh_#in~rjh___0#1 := ~rjh~0;havoc setup_rjh_~rjh___0#1;setup_rjh_~rjh___0#1 := setup_rjh_#in~rjh___0#1;assume { :begin_inline_setup_rjh__wrappee__Base } true;setup_rjh__wrappee__Base_#in~rjh___0#1 := setup_rjh_~rjh___0#1;havoc setup_rjh__wrappee__Base_~rjh___0#1;setup_rjh__wrappee__Base_~rjh___0#1 := setup_rjh__wrappee__Base_#in~rjh___0#1; {14858#true} is VALID [2022-02-20 18:00:10,410 INFO L272 TraceCheckUtils]: 18: Hoare triple {14858#true} call setClientId(setup_rjh__wrappee__Base_~rjh___0#1, setup_rjh__wrappee__Base_~rjh___0#1); {14920#(and (= |old(~__ste_client_idCounter0~0)| ~__ste_client_idCounter0~0) (= |old(~__ste_client_idCounter1~0)| ~__ste_client_idCounter1~0) (= |old(~__ste_client_idCounter2~0)| ~__ste_client_idCounter2~0))} is VALID [2022-02-20 18:00:10,411 INFO L290 TraceCheckUtils]: 19: Hoare triple {14920#(and (= |old(~__ste_client_idCounter0~0)| ~__ste_client_idCounter0~0) (= |old(~__ste_client_idCounter1~0)| ~__ste_client_idCounter1~0) (= |old(~__ste_client_idCounter2~0)| ~__ste_client_idCounter2~0))} ~handle := #in~handle;~value := #in~value; {14858#true} is VALID [2022-02-20 18:00:10,411 INFO L290 TraceCheckUtils]: 20: Hoare triple {14858#true} assume !(1 == ~handle); {14858#true} is VALID [2022-02-20 18:00:10,411 INFO L290 TraceCheckUtils]: 21: Hoare triple {14858#true} assume 2 == ~handle;~__ste_client_idCounter1~0 := ~value; {14858#true} is VALID [2022-02-20 18:00:10,411 INFO L290 TraceCheckUtils]: 22: Hoare triple {14858#true} assume true; {14858#true} is VALID [2022-02-20 18:00:10,411 INFO L284 TraceCheckUtils]: 23: Hoare quadruple {14858#true} {14858#true} #1138#return; {14858#true} is VALID [2022-02-20 18:00:10,411 INFO L290 TraceCheckUtils]: 24: Hoare triple {14858#true} assume { :end_inline_setup_rjh__wrappee__Base } true; {14858#true} is VALID [2022-02-20 18:00:10,412 INFO L272 TraceCheckUtils]: 25: Hoare triple {14858#true} call setClientPrivateKey(setup_rjh_~rjh___0#1, 456); {14921#(and (= ~__ste_client_privateKey0~0 |old(~__ste_client_privateKey0~0)|) (= ~__ste_client_privateKey2~0 |old(~__ste_client_privateKey2~0)|) (= ~__ste_client_privateKey1~0 |old(~__ste_client_privateKey1~0)|))} is VALID [2022-02-20 18:00:10,412 INFO L290 TraceCheckUtils]: 26: Hoare triple {14921#(and (= ~__ste_client_privateKey0~0 |old(~__ste_client_privateKey0~0)|) (= ~__ste_client_privateKey2~0 |old(~__ste_client_privateKey2~0)|) (= ~__ste_client_privateKey1~0 |old(~__ste_client_privateKey1~0)|))} ~handle := #in~handle;~value := #in~value; {14858#true} is VALID [2022-02-20 18:00:10,412 INFO L290 TraceCheckUtils]: 27: Hoare triple {14858#true} assume !(1 == ~handle); {14858#true} is VALID [2022-02-20 18:00:10,412 INFO L290 TraceCheckUtils]: 28: Hoare triple {14858#true} assume 2 == ~handle;~__ste_client_privateKey1~0 := ~value; {14858#true} is VALID [2022-02-20 18:00:10,412 INFO L290 TraceCheckUtils]: 29: Hoare triple {14858#true} assume true; {14858#true} is VALID [2022-02-20 18:00:10,413 INFO L284 TraceCheckUtils]: 30: Hoare quadruple {14858#true} {14858#true} #1140#return; {14858#true} is VALID [2022-02-20 18:00:10,413 INFO L290 TraceCheckUtils]: 31: Hoare triple {14858#true} assume { :end_inline_setup_rjh } true;setup_~__cil_tmp2~0#1.base, setup_~__cil_tmp2~0#1.offset := 19, 0;havoc setup_#t~nondet33#1;~chuck~0 := 3;assume { :begin_inline_setup_chuck } true;setup_chuck_#in~chuck___0#1 := ~chuck~0;havoc setup_chuck_~chuck___0#1;setup_chuck_~chuck___0#1 := setup_chuck_#in~chuck___0#1;assume { :begin_inline_setup_chuck__wrappee__Base } true;setup_chuck__wrappee__Base_#in~chuck___0#1 := setup_chuck_~chuck___0#1;havoc setup_chuck__wrappee__Base_~chuck___0#1;setup_chuck__wrappee__Base_~chuck___0#1 := setup_chuck__wrappee__Base_#in~chuck___0#1; {14878#(= 3 |ULTIMATE.start_setup_chuck__wrappee__Base_~chuck___0#1|)} is VALID [2022-02-20 18:00:10,414 INFO L272 TraceCheckUtils]: 32: Hoare triple {14878#(= 3 |ULTIMATE.start_setup_chuck__wrappee__Base_~chuck___0#1|)} call setClientId(setup_chuck__wrappee__Base_~chuck___0#1, setup_chuck__wrappee__Base_~chuck___0#1); {14920#(and (= |old(~__ste_client_idCounter0~0)| ~__ste_client_idCounter0~0) (= |old(~__ste_client_idCounter1~0)| ~__ste_client_idCounter1~0) (= |old(~__ste_client_idCounter2~0)| ~__ste_client_idCounter2~0))} is VALID [2022-02-20 18:00:10,414 INFO L290 TraceCheckUtils]: 33: Hoare triple {14920#(and (= |old(~__ste_client_idCounter0~0)| ~__ste_client_idCounter0~0) (= |old(~__ste_client_idCounter1~0)| ~__ste_client_idCounter1~0) (= |old(~__ste_client_idCounter2~0)| ~__ste_client_idCounter2~0))} ~handle := #in~handle;~value := #in~value; {14922#(= setClientId_~handle |setClientId_#in~handle|)} is VALID [2022-02-20 18:00:10,414 INFO L290 TraceCheckUtils]: 34: Hoare triple {14922#(= setClientId_~handle |setClientId_#in~handle|)} assume 1 == ~handle;~__ste_client_idCounter0~0 := ~value; {14923#(= |setClientId_#in~handle| 1)} is VALID [2022-02-20 18:00:10,415 INFO L290 TraceCheckUtils]: 35: Hoare triple {14923#(= |setClientId_#in~handle| 1)} assume true; {14923#(= |setClientId_#in~handle| 1)} is VALID [2022-02-20 18:00:10,415 INFO L284 TraceCheckUtils]: 36: Hoare quadruple {14923#(= |setClientId_#in~handle| 1)} {14878#(= 3 |ULTIMATE.start_setup_chuck__wrappee__Base_~chuck___0#1|)} #1142#return; {14859#false} is VALID [2022-02-20 18:00:10,415 INFO L290 TraceCheckUtils]: 37: Hoare triple {14859#false} assume { :end_inline_setup_chuck__wrappee__Base } true; {14859#false} is VALID [2022-02-20 18:00:10,416 INFO L272 TraceCheckUtils]: 38: Hoare triple {14859#false} call setClientPrivateKey(setup_chuck_~chuck___0#1, 789); {14921#(and (= ~__ste_client_privateKey0~0 |old(~__ste_client_privateKey0~0)|) (= ~__ste_client_privateKey2~0 |old(~__ste_client_privateKey2~0)|) (= ~__ste_client_privateKey1~0 |old(~__ste_client_privateKey1~0)|))} is VALID [2022-02-20 18:00:10,416 INFO L290 TraceCheckUtils]: 39: Hoare triple {14921#(and (= ~__ste_client_privateKey0~0 |old(~__ste_client_privateKey0~0)|) (= ~__ste_client_privateKey2~0 |old(~__ste_client_privateKey2~0)|) (= ~__ste_client_privateKey1~0 |old(~__ste_client_privateKey1~0)|))} ~handle := #in~handle;~value := #in~value; {14858#true} is VALID [2022-02-20 18:00:10,416 INFO L290 TraceCheckUtils]: 40: Hoare triple {14858#true} assume 1 == ~handle;~__ste_client_privateKey0~0 := ~value; {14858#true} is VALID [2022-02-20 18:00:10,416 INFO L290 TraceCheckUtils]: 41: Hoare triple {14858#true} assume true; {14858#true} is VALID [2022-02-20 18:00:10,416 INFO L284 TraceCheckUtils]: 42: Hoare quadruple {14858#true} {14859#false} #1144#return; {14859#false} is VALID [2022-02-20 18:00:10,416 INFO L290 TraceCheckUtils]: 43: Hoare triple {14859#false} assume { :end_inline_setup_chuck } true;setup_~__cil_tmp3~0#1.base, setup_~__cil_tmp3~0#1.offset := 20, 0;havoc setup_#t~nondet34#1; {14859#false} is VALID [2022-02-20 18:00:10,416 INFO L290 TraceCheckUtils]: 44: Hoare triple {14859#false} assume { :end_inline_setup } true;assume { :begin_inline_test } true;havoc test_#t~nondet47#1, test_#t~nondet48#1, test_#t~nondet49#1, test_#t~nondet50#1, test_#t~nondet51#1, test_#t~nondet52#1, test_#t~nondet53#1, test_#t~nondet54#1, test_#t~nondet55#1, test_#t~nondet56#1, test_#t~nondet57#1, test_~op1~0#1, test_~op2~0#1, test_~op3~0#1, test_~op4~0#1, test_~op5~0#1, test_~op6~0#1, test_~op7~0#1, test_~op8~0#1, test_~op9~0#1, test_~op10~0#1, test_~op11~0#1, test_~splverifierCounter~0#1, test_~tmp~6#1, test_~tmp___0~2#1, test_~tmp___1~1#1, test_~tmp___2~0#1, test_~tmp___3~0#1, test_~tmp___4~0#1, test_~tmp___5~0#1, test_~tmp___6~0#1, test_~tmp___7~0#1, test_~tmp___8~0#1, test_~tmp___9~0#1;havoc test_~op1~0#1;havoc test_~op2~0#1;havoc test_~op3~0#1;havoc test_~op4~0#1;havoc test_~op5~0#1;havoc test_~op6~0#1;havoc test_~op7~0#1;havoc test_~op8~0#1;havoc test_~op9~0#1;havoc test_~op10~0#1;havoc test_~op11~0#1;havoc test_~splverifierCounter~0#1;havoc test_~tmp~6#1;havoc test_~tmp___0~2#1;havoc test_~tmp___1~1#1;havoc test_~tmp___2~0#1;havoc test_~tmp___3~0#1;havoc test_~tmp___4~0#1;havoc test_~tmp___5~0#1;havoc test_~tmp___6~0#1;havoc test_~tmp___7~0#1;havoc test_~tmp___8~0#1;havoc test_~tmp___9~0#1;test_~op1~0#1 := 0;test_~op2~0#1 := 0;test_~op3~0#1 := 0;test_~op4~0#1 := 0;test_~op5~0#1 := 0;test_~op6~0#1 := 0;test_~op7~0#1 := 0;test_~op8~0#1 := 0;test_~op9~0#1 := 0;test_~op10~0#1 := 0;test_~op11~0#1 := 0;test_~splverifierCounter~0#1 := 0; {14859#false} is VALID [2022-02-20 18:00:10,416 INFO L290 TraceCheckUtils]: 45: Hoare triple {14859#false} assume !false; {14859#false} is VALID [2022-02-20 18:00:10,417 INFO L290 TraceCheckUtils]: 46: Hoare triple {14859#false} assume test_~splverifierCounter~0#1 < 4; {14859#false} is VALID [2022-02-20 18:00:10,417 INFO L290 TraceCheckUtils]: 47: Hoare triple {14859#false} test_~splverifierCounter~0#1 := 1 + test_~splverifierCounter~0#1; {14859#false} is VALID [2022-02-20 18:00:10,417 INFO L290 TraceCheckUtils]: 48: Hoare triple {14859#false} assume 0 == test_~op1~0#1;assume -2147483648 <= test_#t~nondet47#1 && test_#t~nondet47#1 <= 2147483647;test_~tmp___9~0#1 := test_#t~nondet47#1;havoc test_#t~nondet47#1; {14859#false} is VALID [2022-02-20 18:00:10,417 INFO L290 TraceCheckUtils]: 49: Hoare triple {14859#false} assume !(0 != test_~tmp___9~0#1); {14859#false} is VALID [2022-02-20 18:00:10,417 INFO L290 TraceCheckUtils]: 50: Hoare triple {14859#false} assume 0 == test_~op2~0#1;assume -2147483648 <= test_#t~nondet48#1 && test_#t~nondet48#1 <= 2147483647;test_~tmp___8~0#1 := test_#t~nondet48#1;havoc test_#t~nondet48#1; {14859#false} is VALID [2022-02-20 18:00:10,417 INFO L290 TraceCheckUtils]: 51: Hoare triple {14859#false} assume 0 != test_~tmp___8~0#1;assume { :begin_inline_rjhSetAutoRespond } true;assume { :begin_inline_setClientAutoResponse } true;setClientAutoResponse_#in~handle#1, setClientAutoResponse_#in~value#1 := ~rjh~0, 1;havoc setClientAutoResponse_~handle#1, setClientAutoResponse_~value#1;setClientAutoResponse_~handle#1 := setClientAutoResponse_#in~handle#1;setClientAutoResponse_~value#1 := setClientAutoResponse_#in~value#1; {14859#false} is VALID [2022-02-20 18:00:10,417 INFO L290 TraceCheckUtils]: 52: Hoare triple {14859#false} assume 1 == setClientAutoResponse_~handle#1;~__ste_client_autoResponse0~0 := setClientAutoResponse_~value#1; {14859#false} is VALID [2022-02-20 18:00:10,418 INFO L290 TraceCheckUtils]: 53: Hoare triple {14859#false} assume { :end_inline_setClientAutoResponse } true; {14859#false} is VALID [2022-02-20 18:00:10,418 INFO L290 TraceCheckUtils]: 54: Hoare triple {14859#false} assume { :end_inline_rjhSetAutoRespond } true;test_~op2~0#1 := 1; {14859#false} is VALID [2022-02-20 18:00:10,418 INFO L290 TraceCheckUtils]: 55: Hoare triple {14859#false} assume !false; {14859#false} is VALID [2022-02-20 18:00:10,418 INFO L290 TraceCheckUtils]: 56: Hoare triple {14859#false} assume !(test_~splverifierCounter~0#1 < 4); {14859#false} is VALID [2022-02-20 18:00:10,418 INFO L290 TraceCheckUtils]: 57: Hoare triple {14859#false} assume { :begin_inline_bobToRjh } true;havoc bobToRjh_#t~ret27#1, bobToRjh_#t~ret28#1, bobToRjh_#t~ret29#1, bobToRjh_#t~ret30#1, bobToRjh_~tmp~3#1, bobToRjh_~tmp___0~0#1, bobToRjh_~tmp___1~0#1;havoc bobToRjh_~tmp~3#1;havoc bobToRjh_~tmp___0~0#1;havoc bobToRjh_~tmp___1~0#1;call bobToRjh_#t~ret27#1 := puts(16, 0);assume -2147483648 <= bobToRjh_#t~ret27#1 && bobToRjh_#t~ret27#1 <= 2147483647;havoc bobToRjh_#t~ret27#1; {14859#false} is VALID [2022-02-20 18:00:10,418 INFO L272 TraceCheckUtils]: 58: Hoare triple {14859#false} call sendEmail(~bob~0, ~rjh~0); {14859#false} is VALID [2022-02-20 18:00:10,418 INFO L290 TraceCheckUtils]: 59: Hoare triple {14859#false} ~sender#1 := #in~sender#1;~receiver#1 := #in~receiver#1;havoc ~email~0#1;havoc ~tmp~14#1;assume { :begin_inline_createEmail } true;createEmail_#in~from#1, createEmail_#in~to#1 := 0, ~receiver#1;havoc createEmail_#res#1;havoc createEmail_~from#1, createEmail_~to#1, createEmail_~retValue_acc~31#1, createEmail_~msg~0#1;createEmail_~from#1 := createEmail_#in~from#1;createEmail_~to#1 := createEmail_#in~to#1;havoc createEmail_~retValue_acc~31#1;havoc createEmail_~msg~0#1;createEmail_~msg~0#1 := 1; {14859#false} is VALID [2022-02-20 18:00:10,418 INFO L272 TraceCheckUtils]: 60: Hoare triple {14859#false} call setEmailFrom(createEmail_~msg~0#1, createEmail_~from#1); {14924#(and (= |old(~__ste_email_from0~0)| ~__ste_email_from0~0) (= |old(~__ste_email_from1~0)| ~__ste_email_from1~0))} is VALID [2022-02-20 18:00:10,419 INFO L290 TraceCheckUtils]: 61: Hoare triple {14924#(and (= |old(~__ste_email_from0~0)| ~__ste_email_from0~0) (= |old(~__ste_email_from1~0)| ~__ste_email_from1~0))} ~handle := #in~handle;~value := #in~value; {14858#true} is VALID [2022-02-20 18:00:10,419 INFO L290 TraceCheckUtils]: 62: Hoare triple {14858#true} assume 1 == ~handle;~__ste_email_from0~0 := ~value; {14858#true} is VALID [2022-02-20 18:00:10,419 INFO L290 TraceCheckUtils]: 63: Hoare triple {14858#true} assume true; {14858#true} is VALID [2022-02-20 18:00:10,419 INFO L284 TraceCheckUtils]: 64: Hoare quadruple {14858#true} {14859#false} #1120#return; {14859#false} is VALID [2022-02-20 18:00:10,419 INFO L272 TraceCheckUtils]: 65: Hoare triple {14859#false} call setEmailTo(createEmail_~msg~0#1, createEmail_~to#1); {14925#(and (= ~__ste_email_to0~0 |old(~__ste_email_to0~0)|) (= ~__ste_email_to1~0 |old(~__ste_email_to1~0)|))} is VALID [2022-02-20 18:00:10,419 INFO L290 TraceCheckUtils]: 66: Hoare triple {14925#(and (= ~__ste_email_to0~0 |old(~__ste_email_to0~0)|) (= ~__ste_email_to1~0 |old(~__ste_email_to1~0)|))} ~handle := #in~handle;~value := #in~value; {14858#true} is VALID [2022-02-20 18:00:10,419 INFO L290 TraceCheckUtils]: 67: Hoare triple {14858#true} assume 1 == ~handle;~__ste_email_to0~0 := ~value; {14858#true} is VALID [2022-02-20 18:00:10,419 INFO L290 TraceCheckUtils]: 68: Hoare triple {14858#true} assume true; {14858#true} is VALID [2022-02-20 18:00:10,420 INFO L284 TraceCheckUtils]: 69: Hoare quadruple {14858#true} {14859#false} #1122#return; {14859#false} is VALID [2022-02-20 18:00:10,420 INFO L290 TraceCheckUtils]: 70: Hoare triple {14859#false} createEmail_~retValue_acc~31#1 := createEmail_~msg~0#1;createEmail_#res#1 := createEmail_~retValue_acc~31#1; {14859#false} is VALID [2022-02-20 18:00:10,420 INFO L290 TraceCheckUtils]: 71: Hoare triple {14859#false} #t~ret72#1 := createEmail_#res#1;assume { :end_inline_createEmail } true;assume -2147483648 <= #t~ret72#1 && #t~ret72#1 <= 2147483647;~tmp~14#1 := #t~ret72#1;havoc #t~ret72#1;~email~0#1 := ~tmp~14#1; {14859#false} is VALID [2022-02-20 18:00:10,420 INFO L272 TraceCheckUtils]: 72: Hoare triple {14859#false} call outgoing(~sender#1, ~email~0#1); {14859#false} is VALID [2022-02-20 18:00:10,420 INFO L290 TraceCheckUtils]: 73: Hoare triple {14859#false} ~client#1 := #in~client#1;~msg#1 := #in~msg#1;assume { :begin_inline_sign } true;sign_#in~client#1, sign_#in~msg#1 := ~client#1, ~msg#1;havoc sign_#t~ret76#1, sign_~client#1, sign_~msg#1, sign_~privkey~1#1, sign_~tmp~16#1;sign_~client#1 := sign_#in~client#1;sign_~msg#1 := sign_#in~msg#1;havoc sign_~privkey~1#1;havoc sign_~tmp~16#1; {14859#false} is VALID [2022-02-20 18:00:10,420 INFO L272 TraceCheckUtils]: 74: Hoare triple {14859#false} call sign_#t~ret76#1 := getClientPrivateKey(sign_~client#1); {14858#true} is VALID [2022-02-20 18:00:10,420 INFO L290 TraceCheckUtils]: 75: Hoare triple {14858#true} ~handle := #in~handle;havoc ~retValue_acc~20; {14858#true} is VALID [2022-02-20 18:00:10,420 INFO L290 TraceCheckUtils]: 76: Hoare triple {14858#true} assume 1 == ~handle;~retValue_acc~20 := ~__ste_client_privateKey0~0;#res := ~retValue_acc~20; {14858#true} is VALID [2022-02-20 18:00:10,421 INFO L290 TraceCheckUtils]: 77: Hoare triple {14858#true} assume true; {14858#true} is VALID [2022-02-20 18:00:10,421 INFO L284 TraceCheckUtils]: 78: Hoare quadruple {14858#true} {14859#false} #1054#return; {14859#false} is VALID [2022-02-20 18:00:10,421 INFO L290 TraceCheckUtils]: 79: Hoare triple {14859#false} assume -2147483648 <= sign_#t~ret76#1 && sign_#t~ret76#1 <= 2147483647;sign_~tmp~16#1 := sign_#t~ret76#1;havoc sign_#t~ret76#1;sign_~privkey~1#1 := sign_~tmp~16#1; {14859#false} is VALID [2022-02-20 18:00:10,421 INFO L290 TraceCheckUtils]: 80: Hoare triple {14859#false} assume 0 == sign_~privkey~1#1; {14859#false} is VALID [2022-02-20 18:00:10,421 INFO L290 TraceCheckUtils]: 81: Hoare triple {14859#false} assume { :end_inline_sign } true;assume { :begin_inline_outgoing__wrappee__AutoResponder } true;outgoing__wrappee__AutoResponder_#in~client#1, outgoing__wrappee__AutoResponder_#in~msg#1 := ~client#1, ~msg#1;havoc outgoing__wrappee__AutoResponder_#t~ret62#1, outgoing__wrappee__AutoResponder_#t~ret63#1, outgoing__wrappee__AutoResponder_~client#1, outgoing__wrappee__AutoResponder_~msg#1, outgoing__wrappee__AutoResponder_~receiver~0#1, outgoing__wrappee__AutoResponder_~tmp~9#1, outgoing__wrappee__AutoResponder_~pubkey~0#1, outgoing__wrappee__AutoResponder_~tmp___0~3#1;outgoing__wrappee__AutoResponder_~client#1 := outgoing__wrappee__AutoResponder_#in~client#1;outgoing__wrappee__AutoResponder_~msg#1 := outgoing__wrappee__AutoResponder_#in~msg#1;havoc outgoing__wrappee__AutoResponder_~receiver~0#1;havoc outgoing__wrappee__AutoResponder_~tmp~9#1;havoc outgoing__wrappee__AutoResponder_~pubkey~0#1;havoc outgoing__wrappee__AutoResponder_~tmp___0~3#1; {14859#false} is VALID [2022-02-20 18:00:10,421 INFO L272 TraceCheckUtils]: 82: Hoare triple {14859#false} call outgoing__wrappee__AutoResponder_#t~ret62#1 := getEmailTo(outgoing__wrappee__AutoResponder_~msg#1); {14858#true} is VALID [2022-02-20 18:00:10,421 INFO L290 TraceCheckUtils]: 83: Hoare triple {14858#true} ~handle := #in~handle;havoc ~retValue_acc~36; {14858#true} is VALID [2022-02-20 18:00:10,422 INFO L290 TraceCheckUtils]: 84: Hoare triple {14858#true} assume 1 == ~handle;~retValue_acc~36 := ~__ste_email_to0~0;#res := ~retValue_acc~36; {14858#true} is VALID [2022-02-20 18:00:10,422 INFO L290 TraceCheckUtils]: 85: Hoare triple {14858#true} assume true; {14858#true} is VALID [2022-02-20 18:00:10,422 INFO L284 TraceCheckUtils]: 86: Hoare quadruple {14858#true} {14859#false} #1056#return; {14859#false} is VALID [2022-02-20 18:00:10,422 INFO L290 TraceCheckUtils]: 87: Hoare triple {14859#false} assume -2147483648 <= outgoing__wrappee__AutoResponder_#t~ret62#1 && outgoing__wrappee__AutoResponder_#t~ret62#1 <= 2147483647;outgoing__wrappee__AutoResponder_~tmp~9#1 := outgoing__wrappee__AutoResponder_#t~ret62#1;havoc outgoing__wrappee__AutoResponder_#t~ret62#1;outgoing__wrappee__AutoResponder_~receiver~0#1 := outgoing__wrappee__AutoResponder_~tmp~9#1; {14859#false} is VALID [2022-02-20 18:00:10,422 INFO L272 TraceCheckUtils]: 88: Hoare triple {14859#false} call outgoing__wrappee__AutoResponder_#t~ret63#1 := findPublicKey(outgoing__wrappee__AutoResponder_~client#1, outgoing__wrappee__AutoResponder_~receiver~0#1); {14858#true} is VALID [2022-02-20 18:00:10,422 INFO L290 TraceCheckUtils]: 89: Hoare triple {14858#true} ~handle := #in~handle;~userid := #in~userid;havoc ~retValue_acc~25; {14858#true} is VALID [2022-02-20 18:00:10,422 INFO L290 TraceCheckUtils]: 90: Hoare triple {14858#true} assume 1 == ~handle; {14858#true} is VALID [2022-02-20 18:00:10,422 INFO L290 TraceCheckUtils]: 91: Hoare triple {14858#true} assume ~userid == ~__ste_Client_Keyring0_User0~0;~retValue_acc~25 := ~__ste_Client_Keyring0_PublicKey0~0;#res := ~retValue_acc~25; {14858#true} is VALID [2022-02-20 18:00:10,423 INFO L290 TraceCheckUtils]: 92: Hoare triple {14858#true} assume true; {14858#true} is VALID [2022-02-20 18:00:10,423 INFO L284 TraceCheckUtils]: 93: Hoare quadruple {14858#true} {14859#false} #1058#return; {14859#false} is VALID [2022-02-20 18:00:10,423 INFO L290 TraceCheckUtils]: 94: Hoare triple {14859#false} assume -2147483648 <= outgoing__wrappee__AutoResponder_#t~ret63#1 && outgoing__wrappee__AutoResponder_#t~ret63#1 <= 2147483647;outgoing__wrappee__AutoResponder_~tmp___0~3#1 := outgoing__wrappee__AutoResponder_#t~ret63#1;havoc outgoing__wrappee__AutoResponder_#t~ret63#1;outgoing__wrappee__AutoResponder_~pubkey~0#1 := outgoing__wrappee__AutoResponder_~tmp___0~3#1; {14859#false} is VALID [2022-02-20 18:00:10,423 INFO L290 TraceCheckUtils]: 95: Hoare triple {14859#false} assume !(0 != outgoing__wrappee__AutoResponder_~pubkey~0#1); {14859#false} is VALID [2022-02-20 18:00:10,423 INFO L290 TraceCheckUtils]: 96: Hoare triple {14859#false} assume { :begin_inline_outgoing__wrappee__Keys } true;outgoing__wrappee__Keys_#in~client#1, outgoing__wrappee__Keys_#in~msg#1 := outgoing__wrappee__AutoResponder_~client#1, outgoing__wrappee__AutoResponder_~msg#1;havoc outgoing__wrappee__Keys_#t~ret61#1, outgoing__wrappee__Keys_~client#1, outgoing__wrappee__Keys_~msg#1, outgoing__wrappee__Keys_~tmp~8#1;outgoing__wrappee__Keys_~client#1 := outgoing__wrappee__Keys_#in~client#1;outgoing__wrappee__Keys_~msg#1 := outgoing__wrappee__Keys_#in~msg#1;havoc outgoing__wrappee__Keys_~tmp~8#1;assume { :begin_inline_getClientId } true;getClientId_#in~handle#1 := outgoing__wrappee__Keys_~client#1;havoc getClientId_#res#1;havoc getClientId_~handle#1, getClientId_~retValue_acc~27#1;getClientId_~handle#1 := getClientId_#in~handle#1;havoc getClientId_~retValue_acc~27#1; {14859#false} is VALID [2022-02-20 18:00:10,423 INFO L290 TraceCheckUtils]: 97: Hoare triple {14859#false} assume 1 == getClientId_~handle#1;getClientId_~retValue_acc~27#1 := ~__ste_client_idCounter0~0;getClientId_#res#1 := getClientId_~retValue_acc~27#1; {14859#false} is VALID [2022-02-20 18:00:10,423 INFO L290 TraceCheckUtils]: 98: Hoare triple {14859#false} outgoing__wrappee__Keys_#t~ret61#1 := getClientId_#res#1;assume { :end_inline_getClientId } true;assume -2147483648 <= outgoing__wrappee__Keys_#t~ret61#1 && outgoing__wrappee__Keys_#t~ret61#1 <= 2147483647;outgoing__wrappee__Keys_~tmp~8#1 := outgoing__wrappee__Keys_#t~ret61#1;havoc outgoing__wrappee__Keys_#t~ret61#1; {14859#false} is VALID [2022-02-20 18:00:10,423 INFO L272 TraceCheckUtils]: 99: Hoare triple {14859#false} call setEmailFrom(outgoing__wrappee__Keys_~msg#1, outgoing__wrappee__Keys_~tmp~8#1); {14924#(and (= |old(~__ste_email_from0~0)| ~__ste_email_from0~0) (= |old(~__ste_email_from1~0)| ~__ste_email_from1~0))} is VALID [2022-02-20 18:00:10,424 INFO L290 TraceCheckUtils]: 100: Hoare triple {14924#(and (= |old(~__ste_email_from0~0)| ~__ste_email_from0~0) (= |old(~__ste_email_from1~0)| ~__ste_email_from1~0))} ~handle := #in~handle;~value := #in~value; {14858#true} is VALID [2022-02-20 18:00:10,424 INFO L290 TraceCheckUtils]: 101: Hoare triple {14858#true} assume 1 == ~handle;~__ste_email_from0~0 := ~value; {14858#true} is VALID [2022-02-20 18:00:10,424 INFO L290 TraceCheckUtils]: 102: Hoare triple {14858#true} assume true; {14858#true} is VALID [2022-02-20 18:00:10,424 INFO L284 TraceCheckUtils]: 103: Hoare quadruple {14858#true} {14859#false} #1064#return; {14859#false} is VALID [2022-02-20 18:00:10,424 INFO L290 TraceCheckUtils]: 104: Hoare triple {14859#false} assume { :begin_inline_mail } true;mail_#in~client#1, mail_#in~msg#1 := outgoing__wrappee__Keys_~client#1, outgoing__wrappee__Keys_~msg#1;havoc mail_#t~ret59#1, mail_#t~ret60#1, mail_~client#1, mail_~msg#1, mail_~__utac__ad__arg1~0#1, mail_~__utac__ad__arg2~0#1, mail_~tmp~7#1;mail_~client#1 := mail_#in~client#1;mail_~msg#1 := mail_#in~msg#1;havoc mail_~__utac__ad__arg1~0#1;havoc mail_~__utac__ad__arg2~0#1;havoc mail_~tmp~7#1;mail_~__utac__ad__arg1~0#1 := mail_~client#1;mail_~__utac__ad__arg2~0#1 := mail_~msg#1;assume { :begin_inline___utac_acc__SignForward_spec__1 } true;__utac_acc__SignForward_spec__1_#in~client#1, __utac_acc__SignForward_spec__1_#in~msg#1 := mail_~__utac__ad__arg1~0#1, mail_~__utac__ad__arg2~0#1;havoc __utac_acc__SignForward_spec__1_#t~ret107#1, __utac_acc__SignForward_spec__1_#t~ret108#1, __utac_acc__SignForward_spec__1_#t~ret109#1, __utac_acc__SignForward_spec__1_~client#1, __utac_acc__SignForward_spec__1_~msg#1, __utac_acc__SignForward_spec__1_~tmp~25#1, __utac_acc__SignForward_spec__1_~tmp___0~9#1;__utac_acc__SignForward_spec__1_~client#1 := __utac_acc__SignForward_spec__1_#in~client#1;__utac_acc__SignForward_spec__1_~msg#1 := __utac_acc__SignForward_spec__1_#in~msg#1;havoc __utac_acc__SignForward_spec__1_~tmp~25#1;havoc __utac_acc__SignForward_spec__1_~tmp___0~9#1;call __utac_acc__SignForward_spec__1_#t~ret107#1 := puts(39, 0);assume -2147483648 <= __utac_acc__SignForward_spec__1_#t~ret107#1 && __utac_acc__SignForward_spec__1_#t~ret107#1 <= 2147483647;havoc __utac_acc__SignForward_spec__1_#t~ret107#1; {14859#false} is VALID [2022-02-20 18:00:10,424 INFO L272 TraceCheckUtils]: 105: Hoare triple {14859#false} call __utac_acc__SignForward_spec__1_#t~ret108#1 := isSigned(__utac_acc__SignForward_spec__1_~msg#1); {14858#true} is VALID [2022-02-20 18:00:10,424 INFO L290 TraceCheckUtils]: 106: Hoare triple {14858#true} ~handle := #in~handle;havoc ~retValue_acc~41; {14858#true} is VALID [2022-02-20 18:00:10,424 INFO L290 TraceCheckUtils]: 107: Hoare triple {14858#true} assume 1 == ~handle;~retValue_acc~41 := ~__ste_email_isSigned0~0;#res := ~retValue_acc~41; {14858#true} is VALID [2022-02-20 18:00:10,425 INFO L290 TraceCheckUtils]: 108: Hoare triple {14858#true} assume true; {14858#true} is VALID [2022-02-20 18:00:10,425 INFO L284 TraceCheckUtils]: 109: Hoare quadruple {14858#true} {14859#false} #1066#return; {14859#false} is VALID [2022-02-20 18:00:10,425 INFO L290 TraceCheckUtils]: 110: Hoare triple {14859#false} assume -2147483648 <= __utac_acc__SignForward_spec__1_#t~ret108#1 && __utac_acc__SignForward_spec__1_#t~ret108#1 <= 2147483647;__utac_acc__SignForward_spec__1_~tmp___0~9#1 := __utac_acc__SignForward_spec__1_#t~ret108#1;havoc __utac_acc__SignForward_spec__1_#t~ret108#1; {14859#false} is VALID [2022-02-20 18:00:10,425 INFO L290 TraceCheckUtils]: 111: Hoare triple {14859#false} assume 0 != __utac_acc__SignForward_spec__1_~tmp___0~9#1; {14859#false} is VALID [2022-02-20 18:00:10,425 INFO L272 TraceCheckUtils]: 112: Hoare triple {14859#false} call __utac_acc__SignForward_spec__1_#t~ret109#1 := getClientPrivateKey(__utac_acc__SignForward_spec__1_~client#1); {14858#true} is VALID [2022-02-20 18:00:10,425 INFO L290 TraceCheckUtils]: 113: Hoare triple {14858#true} ~handle := #in~handle;havoc ~retValue_acc~20; {14858#true} is VALID [2022-02-20 18:00:10,425 INFO L290 TraceCheckUtils]: 114: Hoare triple {14858#true} assume 1 == ~handle;~retValue_acc~20 := ~__ste_client_privateKey0~0;#res := ~retValue_acc~20; {14858#true} is VALID [2022-02-20 18:00:10,425 INFO L290 TraceCheckUtils]: 115: Hoare triple {14858#true} assume true; {14858#true} is VALID [2022-02-20 18:00:10,426 INFO L284 TraceCheckUtils]: 116: Hoare quadruple {14858#true} {14859#false} #1068#return; {14859#false} is VALID [2022-02-20 18:00:10,426 INFO L290 TraceCheckUtils]: 117: Hoare triple {14859#false} assume -2147483648 <= __utac_acc__SignForward_spec__1_#t~ret109#1 && __utac_acc__SignForward_spec__1_#t~ret109#1 <= 2147483647;__utac_acc__SignForward_spec__1_~tmp~25#1 := __utac_acc__SignForward_spec__1_#t~ret109#1;havoc __utac_acc__SignForward_spec__1_#t~ret109#1; {14859#false} is VALID [2022-02-20 18:00:10,426 INFO L290 TraceCheckUtils]: 118: Hoare triple {14859#false} assume 0 == __utac_acc__SignForward_spec__1_~tmp~25#1;assume { :begin_inline___automaton_fail } true; {14859#false} is VALID [2022-02-20 18:00:10,426 INFO L290 TraceCheckUtils]: 119: Hoare triple {14859#false} assume !false; {14859#false} is VALID [2022-02-20 18:00:10,426 INFO L134 CoverageAnalysis]: Checked inductivity of 34 backedges. 6 proven. 0 refuted. 0 times theorem prover too weak. 28 trivial. 0 not checked. [2022-02-20 18:00:10,427 INFO L144 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2022-02-20 18:00:10,427 INFO L338 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [524129602] [2022-02-20 18:00:10,427 INFO L165 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [524129602] provided 1 perfect and 0 imperfect interpolant sequences [2022-02-20 18:00:10,427 INFO L191 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2022-02-20 18:00:10,427 INFO L204 FreeRefinementEngine]: Number of different interpolants: perfect sequences [9] imperfect sequences [] total 9 [2022-02-20 18:00:10,427 INFO L118 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [2000962465] [2022-02-20 18:00:10,427 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2022-02-20 18:00:10,428 INFO L78 Accepts]: Start accepts. Automaton has has 9 states, 8 states have (on average 9.5) internal successors, (76), 5 states have internal predecessors, (76), 3 states have call successors, (16), 6 states have call predecessors, (16), 2 states have return successors, (14), 2 states have call predecessors, (14), 3 states have call successors, (14) Word has length 120 [2022-02-20 18:00:10,428 INFO L84 Accepts]: Finished accepts. word is accepted. [2022-02-20 18:00:10,429 INFO L86 InductivityCheck]: Starting indutivity check of a Floyd-Hoare automaton with has 9 states, 8 states have (on average 9.5) internal successors, (76), 5 states have internal predecessors, (76), 3 states have call successors, (16), 6 states have call predecessors, (16), 2 states have return successors, (14), 2 states have call predecessors, (14), 3 states have call successors, (14) [2022-02-20 18:00:10,498 INFO L122 InductivityCheck]: Floyd-Hoare automaton has 106 edges. 106 inductive. 0 not inductive. 0 times theorem prover too weak to decide inductivity. [2022-02-20 18:00:10,499 INFO L546 AbstractCegarLoop]: INTERPOLANT automaton has 9 states [2022-02-20 18:00:10,499 INFO L108 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2022-02-20 18:00:10,499 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 9 interpolants. [2022-02-20 18:00:10,500 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=15, Invalid=57, Unknown=0, NotChecked=0, Total=72 [2022-02-20 18:00:10,500 INFO L87 Difference]: Start difference. First operand 441 states and 666 transitions. Second operand has 9 states, 8 states have (on average 9.5) internal successors, (76), 5 states have internal predecessors, (76), 3 states have call successors, (16), 6 states have call predecessors, (16), 2 states have return successors, (14), 2 states have call predecessors, (14), 3 states have call successors, (14) [2022-02-20 18:00:18,021 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-02-20 18:00:18,021 INFO L93 Difference]: Finished difference Result 1073 states and 1630 transitions. [2022-02-20 18:00:18,022 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 11 states. [2022-02-20 18:00:18,022 INFO L78 Accepts]: Start accepts. Automaton has has 9 states, 8 states have (on average 9.5) internal successors, (76), 5 states have internal predecessors, (76), 3 states have call successors, (16), 6 states have call predecessors, (16), 2 states have return successors, (14), 2 states have call predecessors, (14), 3 states have call successors, (14) Word has length 120 [2022-02-20 18:00:18,022 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2022-02-20 18:00:18,023 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 9 states, 8 states have (on average 9.5) internal successors, (76), 5 states have internal predecessors, (76), 3 states have call successors, (16), 6 states have call predecessors, (16), 2 states have return successors, (14), 2 states have call predecessors, (14), 3 states have call successors, (14) [2022-02-20 18:00:18,037 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 11 states to 11 states and 1428 transitions. [2022-02-20 18:00:18,037 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 9 states, 8 states have (on average 9.5) internal successors, (76), 5 states have internal predecessors, (76), 3 states have call successors, (16), 6 states have call predecessors, (16), 2 states have return successors, (14), 2 states have call predecessors, (14), 3 states have call successors, (14) [2022-02-20 18:00:18,053 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 11 states to 11 states and 1428 transitions. [2022-02-20 18:00:18,053 INFO L86 InductivityCheck]: Starting indutivity check of a Floyd-Hoare automaton with 11 states and 1428 transitions. [2022-02-20 18:00:19,350 INFO L122 InductivityCheck]: Floyd-Hoare automaton has 1428 edges. 1428 inductive. 0 not inductive. 0 times theorem prover too weak to decide inductivity. [2022-02-20 18:00:19,379 INFO L225 Difference]: With dead ends: 1073 [2022-02-20 18:00:19,380 INFO L226 Difference]: Without dead ends: 655 [2022-02-20 18:00:19,381 INFO L932 BasicCegarLoop]: 0 DeclaredPredicates, 46 GetRequests, 31 SyntacticMatches, 0 SemanticMatches, 15 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 31 ImplicationChecksByTransitivity, 0.1s TimeCoverageRelationStatistics Valid=73, Invalid=199, Unknown=0, NotChecked=0, Total=272 [2022-02-20 18:00:19,383 INFO L933 BasicCegarLoop]: 709 mSDtfsCounter, 1390 mSDsluCounter, 863 mSDsCounter, 0 mSdLazyCounter, 2583 mSolverCounterSat, 593 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 3.4s Time, 0 mProtectedPredicate, 0 mProtectedAction, 1407 SdHoareTripleChecker+Valid, 1572 SdHoareTripleChecker+Invalid, 3176 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 593 IncrementalHoareTripleChecker+Valid, 2583 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 3.4s IncrementalHoareTripleChecker+Time [2022-02-20 18:00:19,383 INFO L934 BasicCegarLoop]: SdHoareTripleChecker [1407 Valid, 1572 Invalid, 3176 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [593 Valid, 2583 Invalid, 0 Unknown, 0 Unchecked, 3.4s Time] [2022-02-20 18:00:19,384 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 655 states. [2022-02-20 18:00:19,504 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 655 to 441. [2022-02-20 18:00:19,505 INFO L214 AbstractMinimizeNwa]: Start testing correctness of minimizeSevpa [2022-02-20 18:00:19,506 INFO L82 GeneralOperation]: Start isEquivalent. First operand 655 states. Second operand has 441 states, 340 states have (on average 1.5058823529411764) internal successors, (512), 345 states have internal predecessors, (512), 74 states have call successors, (74), 24 states have call predecessors, (74), 26 states have return successors, (79), 73 states have call predecessors, (79), 73 states have call successors, (79) [2022-02-20 18:00:19,507 INFO L74 IsIncluded]: Start isIncluded. First operand 655 states. Second operand has 441 states, 340 states have (on average 1.5058823529411764) internal successors, (512), 345 states have internal predecessors, (512), 74 states have call successors, (74), 24 states have call predecessors, (74), 26 states have return successors, (79), 73 states have call predecessors, (79), 73 states have call successors, (79) [2022-02-20 18:00:19,508 INFO L87 Difference]: Start difference. First operand 655 states. Second operand has 441 states, 340 states have (on average 1.5058823529411764) internal successors, (512), 345 states have internal predecessors, (512), 74 states have call successors, (74), 24 states have call predecessors, (74), 26 states have return successors, (79), 73 states have call predecessors, (79), 73 states have call successors, (79) [2022-02-20 18:00:19,531 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-02-20 18:00:19,531 INFO L93 Difference]: Finished difference Result 655 states and 995 transitions. [2022-02-20 18:00:19,531 INFO L276 IsEmpty]: Start isEmpty. Operand 655 states and 995 transitions. [2022-02-20 18:00:19,536 INFO L282 IsEmpty]: Finished isEmpty. No accepting run. [2022-02-20 18:00:19,537 INFO L83 IsIncluded]: Finished isIncluded. Language is included [2022-02-20 18:00:19,538 INFO L74 IsIncluded]: Start isIncluded. First operand has 441 states, 340 states have (on average 1.5058823529411764) internal successors, (512), 345 states have internal predecessors, (512), 74 states have call successors, (74), 24 states have call predecessors, (74), 26 states have return successors, (79), 73 states have call predecessors, (79), 73 states have call successors, (79) Second operand 655 states. [2022-02-20 18:00:19,539 INFO L87 Difference]: Start difference. First operand has 441 states, 340 states have (on average 1.5058823529411764) internal successors, (512), 345 states have internal predecessors, (512), 74 states have call successors, (74), 24 states have call predecessors, (74), 26 states have return successors, (79), 73 states have call predecessors, (79), 73 states have call successors, (79) Second operand 655 states. [2022-02-20 18:00:19,565 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-02-20 18:00:19,565 INFO L93 Difference]: Finished difference Result 655 states and 995 transitions. [2022-02-20 18:00:19,566 INFO L276 IsEmpty]: Start isEmpty. Operand 655 states and 995 transitions. [2022-02-20 18:00:19,569 INFO L282 IsEmpty]: Finished isEmpty. No accepting run. [2022-02-20 18:00:19,569 INFO L83 IsIncluded]: Finished isIncluded. Language is included [2022-02-20 18:00:19,569 INFO L88 GeneralOperation]: Finished isEquivalent. [2022-02-20 18:00:19,569 INFO L221 AbstractMinimizeNwa]: Finished testing correctness of minimizeSevpa [2022-02-20 18:00:19,570 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 441 states, 340 states have (on average 1.5058823529411764) internal successors, (512), 345 states have internal predecessors, (512), 74 states have call successors, (74), 24 states have call predecessors, (74), 26 states have return successors, (79), 73 states have call predecessors, (79), 73 states have call successors, (79) [2022-02-20 18:00:19,584 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 441 states to 441 states and 665 transitions. [2022-02-20 18:00:19,585 INFO L78 Accepts]: Start accepts. Automaton has 441 states and 665 transitions. Word has length 120 [2022-02-20 18:00:19,585 INFO L84 Accepts]: Finished accepts. word is rejected. [2022-02-20 18:00:19,585 INFO L470 AbstractCegarLoop]: Abstraction has 441 states and 665 transitions. [2022-02-20 18:00:19,585 INFO L471 AbstractCegarLoop]: INTERPOLANT automaton has has 9 states, 8 states have (on average 9.5) internal successors, (76), 5 states have internal predecessors, (76), 3 states have call successors, (16), 6 states have call predecessors, (16), 2 states have return successors, (14), 2 states have call predecessors, (14), 3 states have call successors, (14) [2022-02-20 18:00:19,585 INFO L276 IsEmpty]: Start isEmpty. Operand 441 states and 665 transitions. [2022-02-20 18:00:19,587 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 122 [2022-02-20 18:00:19,587 INFO L506 BasicCegarLoop]: Found error trace [2022-02-20 18:00:19,587 INFO L514 BasicCegarLoop]: trace histogram [3, 3, 3, 3, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-02-20 18:00:19,587 WARN L452 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable5 [2022-02-20 18:00:19,587 INFO L402 AbstractCegarLoop]: === Iteration 7 === Targeting outgoingErr0ASSERT_VIOLATIONERROR_FUNCTION === [outgoingErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2022-02-20 18:00:19,588 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2022-02-20 18:00:19,588 INFO L85 PathProgramCache]: Analyzing trace with hash 586639335, now seen corresponding path program 2 times [2022-02-20 18:00:19,588 INFO L126 FreeRefinementEngine]: Executing refinement strategy CAMEL [2022-02-20 18:00:19,588 INFO L338 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [1295899514] [2022-02-20 18:00:19,588 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-02-20 18:00:19,588 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2022-02-20 18:00:19,618 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-02-20 18:00:19,640 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 6 [2022-02-20 18:00:19,642 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-02-20 18:00:19,643 INFO L290 TraceCheckUtils]: 0: Hoare triple {18487#(and (= |old(~__ste_client_idCounter0~0)| ~__ste_client_idCounter0~0) (= |old(~__ste_client_idCounter1~0)| ~__ste_client_idCounter1~0) (= |old(~__ste_client_idCounter2~0)| ~__ste_client_idCounter2~0))} ~handle := #in~handle;~value := #in~value; {18424#true} is VALID [2022-02-20 18:00:19,644 INFO L290 TraceCheckUtils]: 1: Hoare triple {18424#true} assume 1 == ~handle;~__ste_client_idCounter0~0 := ~value; {18424#true} is VALID [2022-02-20 18:00:19,644 INFO L290 TraceCheckUtils]: 2: Hoare triple {18424#true} assume true; {18424#true} is VALID [2022-02-20 18:00:19,644 INFO L284 TraceCheckUtils]: 3: Hoare quadruple {18424#true} {18424#true} #1134#return; {18424#true} is VALID [2022-02-20 18:00:19,649 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 12 [2022-02-20 18:00:19,654 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-02-20 18:00:19,657 INFO L290 TraceCheckUtils]: 0: Hoare triple {18488#(and (= ~__ste_client_privateKey0~0 |old(~__ste_client_privateKey0~0)|) (= ~__ste_client_privateKey2~0 |old(~__ste_client_privateKey2~0)|) (= ~__ste_client_privateKey1~0 |old(~__ste_client_privateKey1~0)|))} ~handle := #in~handle;~value := #in~value; {18424#true} is VALID [2022-02-20 18:00:19,657 INFO L290 TraceCheckUtils]: 1: Hoare triple {18424#true} assume 1 == ~handle;~__ste_client_privateKey0~0 := ~value; {18424#true} is VALID [2022-02-20 18:00:19,657 INFO L290 TraceCheckUtils]: 2: Hoare triple {18424#true} assume true; {18424#true} is VALID [2022-02-20 18:00:19,658 INFO L284 TraceCheckUtils]: 3: Hoare quadruple {18424#true} {18424#true} #1136#return; {18424#true} is VALID [2022-02-20 18:00:19,658 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 18 [2022-02-20 18:00:19,659 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-02-20 18:00:19,660 INFO L290 TraceCheckUtils]: 0: Hoare triple {18487#(and (= |old(~__ste_client_idCounter0~0)| ~__ste_client_idCounter0~0) (= |old(~__ste_client_idCounter1~0)| ~__ste_client_idCounter1~0) (= |old(~__ste_client_idCounter2~0)| ~__ste_client_idCounter2~0))} ~handle := #in~handle;~value := #in~value; {18424#true} is VALID [2022-02-20 18:00:19,661 INFO L290 TraceCheckUtils]: 1: Hoare triple {18424#true} assume !(1 == ~handle); {18424#true} is VALID [2022-02-20 18:00:19,661 INFO L290 TraceCheckUtils]: 2: Hoare triple {18424#true} assume 2 == ~handle;~__ste_client_idCounter1~0 := ~value; {18424#true} is VALID [2022-02-20 18:00:19,661 INFO L290 TraceCheckUtils]: 3: Hoare triple {18424#true} assume true; {18424#true} is VALID [2022-02-20 18:00:19,661 INFO L284 TraceCheckUtils]: 4: Hoare quadruple {18424#true} {18424#true} #1138#return; {18424#true} is VALID [2022-02-20 18:00:19,661 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 25 [2022-02-20 18:00:19,663 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-02-20 18:00:19,665 INFO L290 TraceCheckUtils]: 0: Hoare triple {18488#(and (= ~__ste_client_privateKey0~0 |old(~__ste_client_privateKey0~0)|) (= ~__ste_client_privateKey2~0 |old(~__ste_client_privateKey2~0)|) (= ~__ste_client_privateKey1~0 |old(~__ste_client_privateKey1~0)|))} ~handle := #in~handle;~value := #in~value; {18424#true} is VALID [2022-02-20 18:00:19,665 INFO L290 TraceCheckUtils]: 1: Hoare triple {18424#true} assume !(1 == ~handle); {18424#true} is VALID [2022-02-20 18:00:19,665 INFO L290 TraceCheckUtils]: 2: Hoare triple {18424#true} assume 2 == ~handle;~__ste_client_privateKey1~0 := ~value; {18424#true} is VALID [2022-02-20 18:00:19,665 INFO L290 TraceCheckUtils]: 3: Hoare triple {18424#true} assume true; {18424#true} is VALID [2022-02-20 18:00:19,665 INFO L284 TraceCheckUtils]: 4: Hoare quadruple {18424#true} {18424#true} #1140#return; {18424#true} is VALID [2022-02-20 18:00:19,665 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 32 [2022-02-20 18:00:19,667 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-02-20 18:00:19,681 INFO L290 TraceCheckUtils]: 0: Hoare triple {18487#(and (= |old(~__ste_client_idCounter0~0)| ~__ste_client_idCounter0~0) (= |old(~__ste_client_idCounter1~0)| ~__ste_client_idCounter1~0) (= |old(~__ste_client_idCounter2~0)| ~__ste_client_idCounter2~0))} ~handle := #in~handle;~value := #in~value; {18489#(= setClientId_~handle |setClientId_#in~handle|)} is VALID [2022-02-20 18:00:19,681 INFO L290 TraceCheckUtils]: 1: Hoare triple {18489#(= setClientId_~handle |setClientId_#in~handle|)} assume !(1 == ~handle); {18489#(= setClientId_~handle |setClientId_#in~handle|)} is VALID [2022-02-20 18:00:19,681 INFO L290 TraceCheckUtils]: 2: Hoare triple {18489#(= setClientId_~handle |setClientId_#in~handle|)} assume 2 == ~handle;~__ste_client_idCounter1~0 := ~value; {18490#(= 2 |setClientId_#in~handle|)} is VALID [2022-02-20 18:00:19,682 INFO L290 TraceCheckUtils]: 3: Hoare triple {18490#(= 2 |setClientId_#in~handle|)} assume true; {18490#(= 2 |setClientId_#in~handle|)} is VALID [2022-02-20 18:00:19,682 INFO L284 TraceCheckUtils]: 4: Hoare quadruple {18490#(= 2 |setClientId_#in~handle|)} {18444#(= 3 |ULTIMATE.start_setup_chuck__wrappee__Base_~chuck___0#1|)} #1142#return; {18425#false} is VALID [2022-02-20 18:00:19,682 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 39 [2022-02-20 18:00:19,684 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-02-20 18:00:19,687 INFO L290 TraceCheckUtils]: 0: Hoare triple {18488#(and (= ~__ste_client_privateKey0~0 |old(~__ste_client_privateKey0~0)|) (= ~__ste_client_privateKey2~0 |old(~__ste_client_privateKey2~0)|) (= ~__ste_client_privateKey1~0 |old(~__ste_client_privateKey1~0)|))} ~handle := #in~handle;~value := #in~value; {18424#true} is VALID [2022-02-20 18:00:19,687 INFO L290 TraceCheckUtils]: 1: Hoare triple {18424#true} assume 1 == ~handle;~__ste_client_privateKey0~0 := ~value; {18424#true} is VALID [2022-02-20 18:00:19,687 INFO L290 TraceCheckUtils]: 2: Hoare triple {18424#true} assume true; {18424#true} is VALID [2022-02-20 18:00:19,687 INFO L284 TraceCheckUtils]: 3: Hoare quadruple {18424#true} {18425#false} #1144#return; {18425#false} is VALID [2022-02-20 18:00:19,693 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 61 [2022-02-20 18:00:19,694 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-02-20 18:00:19,698 INFO L290 TraceCheckUtils]: 0: Hoare triple {18491#(and (= |old(~__ste_email_from0~0)| ~__ste_email_from0~0) (= |old(~__ste_email_from1~0)| ~__ste_email_from1~0))} ~handle := #in~handle;~value := #in~value; {18424#true} is VALID [2022-02-20 18:00:19,698 INFO L290 TraceCheckUtils]: 1: Hoare triple {18424#true} assume 1 == ~handle;~__ste_email_from0~0 := ~value; {18424#true} is VALID [2022-02-20 18:00:19,698 INFO L290 TraceCheckUtils]: 2: Hoare triple {18424#true} assume true; {18424#true} is VALID [2022-02-20 18:00:19,699 INFO L284 TraceCheckUtils]: 3: Hoare quadruple {18424#true} {18425#false} #1120#return; {18425#false} is VALID [2022-02-20 18:00:19,705 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 66 [2022-02-20 18:00:19,706 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-02-20 18:00:19,707 INFO L290 TraceCheckUtils]: 0: Hoare triple {18492#(and (= ~__ste_email_to0~0 |old(~__ste_email_to0~0)|) (= ~__ste_email_to1~0 |old(~__ste_email_to1~0)|))} ~handle := #in~handle;~value := #in~value; {18424#true} is VALID [2022-02-20 18:00:19,708 INFO L290 TraceCheckUtils]: 1: Hoare triple {18424#true} assume 1 == ~handle;~__ste_email_to0~0 := ~value; {18424#true} is VALID [2022-02-20 18:00:19,708 INFO L290 TraceCheckUtils]: 2: Hoare triple {18424#true} assume true; {18424#true} is VALID [2022-02-20 18:00:19,708 INFO L284 TraceCheckUtils]: 3: Hoare quadruple {18424#true} {18425#false} #1122#return; {18425#false} is VALID [2022-02-20 18:00:19,708 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 75 [2022-02-20 18:00:19,709 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-02-20 18:00:19,711 INFO L290 TraceCheckUtils]: 0: Hoare triple {18424#true} ~handle := #in~handle;havoc ~retValue_acc~20; {18424#true} is VALID [2022-02-20 18:00:19,711 INFO L290 TraceCheckUtils]: 1: Hoare triple {18424#true} assume 1 == ~handle;~retValue_acc~20 := ~__ste_client_privateKey0~0;#res := ~retValue_acc~20; {18424#true} is VALID [2022-02-20 18:00:19,711 INFO L290 TraceCheckUtils]: 2: Hoare triple {18424#true} assume true; {18424#true} is VALID [2022-02-20 18:00:19,711 INFO L284 TraceCheckUtils]: 3: Hoare quadruple {18424#true} {18425#false} #1054#return; {18425#false} is VALID [2022-02-20 18:00:19,712 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 83 [2022-02-20 18:00:19,712 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-02-20 18:00:19,717 INFO L290 TraceCheckUtils]: 0: Hoare triple {18424#true} ~handle := #in~handle;havoc ~retValue_acc~36; {18424#true} is VALID [2022-02-20 18:00:19,717 INFO L290 TraceCheckUtils]: 1: Hoare triple {18424#true} assume 1 == ~handle;~retValue_acc~36 := ~__ste_email_to0~0;#res := ~retValue_acc~36; {18424#true} is VALID [2022-02-20 18:00:19,717 INFO L290 TraceCheckUtils]: 2: Hoare triple {18424#true} assume true; {18424#true} is VALID [2022-02-20 18:00:19,717 INFO L284 TraceCheckUtils]: 3: Hoare quadruple {18424#true} {18425#false} #1056#return; {18425#false} is VALID [2022-02-20 18:00:19,718 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 89 [2022-02-20 18:00:19,718 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-02-20 18:00:19,720 INFO L290 TraceCheckUtils]: 0: Hoare triple {18424#true} ~handle := #in~handle;~userid := #in~userid;havoc ~retValue_acc~25; {18424#true} is VALID [2022-02-20 18:00:19,720 INFO L290 TraceCheckUtils]: 1: Hoare triple {18424#true} assume 1 == ~handle; {18424#true} is VALID [2022-02-20 18:00:19,720 INFO L290 TraceCheckUtils]: 2: Hoare triple {18424#true} assume ~userid == ~__ste_Client_Keyring0_User0~0;~retValue_acc~25 := ~__ste_Client_Keyring0_PublicKey0~0;#res := ~retValue_acc~25; {18424#true} is VALID [2022-02-20 18:00:19,720 INFO L290 TraceCheckUtils]: 3: Hoare triple {18424#true} assume true; {18424#true} is VALID [2022-02-20 18:00:19,720 INFO L284 TraceCheckUtils]: 4: Hoare quadruple {18424#true} {18425#false} #1058#return; {18425#false} is VALID [2022-02-20 18:00:19,721 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 100 [2022-02-20 18:00:19,721 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-02-20 18:00:19,723 INFO L290 TraceCheckUtils]: 0: Hoare triple {18491#(and (= |old(~__ste_email_from0~0)| ~__ste_email_from0~0) (= |old(~__ste_email_from1~0)| ~__ste_email_from1~0))} ~handle := #in~handle;~value := #in~value; {18424#true} is VALID [2022-02-20 18:00:19,723 INFO L290 TraceCheckUtils]: 1: Hoare triple {18424#true} assume 1 == ~handle;~__ste_email_from0~0 := ~value; {18424#true} is VALID [2022-02-20 18:00:19,723 INFO L290 TraceCheckUtils]: 2: Hoare triple {18424#true} assume true; {18424#true} is VALID [2022-02-20 18:00:19,723 INFO L284 TraceCheckUtils]: 3: Hoare quadruple {18424#true} {18425#false} #1064#return; {18425#false} is VALID [2022-02-20 18:00:19,723 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 106 [2022-02-20 18:00:19,724 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-02-20 18:00:19,725 INFO L290 TraceCheckUtils]: 0: Hoare triple {18424#true} ~handle := #in~handle;havoc ~retValue_acc~41; {18424#true} is VALID [2022-02-20 18:00:19,725 INFO L290 TraceCheckUtils]: 1: Hoare triple {18424#true} assume 1 == ~handle;~retValue_acc~41 := ~__ste_email_isSigned0~0;#res := ~retValue_acc~41; {18424#true} is VALID [2022-02-20 18:00:19,726 INFO L290 TraceCheckUtils]: 2: Hoare triple {18424#true} assume true; {18424#true} is VALID [2022-02-20 18:00:19,726 INFO L284 TraceCheckUtils]: 3: Hoare quadruple {18424#true} {18425#false} #1066#return; {18425#false} is VALID [2022-02-20 18:00:19,726 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 113 [2022-02-20 18:00:19,726 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-02-20 18:00:19,728 INFO L290 TraceCheckUtils]: 0: Hoare triple {18424#true} ~handle := #in~handle;havoc ~retValue_acc~20; {18424#true} is VALID [2022-02-20 18:00:19,728 INFO L290 TraceCheckUtils]: 1: Hoare triple {18424#true} assume 1 == ~handle;~retValue_acc~20 := ~__ste_client_privateKey0~0;#res := ~retValue_acc~20; {18424#true} is VALID [2022-02-20 18:00:19,728 INFO L290 TraceCheckUtils]: 2: Hoare triple {18424#true} assume true; {18424#true} is VALID [2022-02-20 18:00:19,728 INFO L284 TraceCheckUtils]: 3: Hoare quadruple {18424#true} {18425#false} #1068#return; {18425#false} is VALID [2022-02-20 18:00:19,728 INFO L290 TraceCheckUtils]: 0: Hoare triple {18424#true} assume { :begin_inline_ULTIMATE.init } true;#NULL.base, #NULL.offset := 0, 0;assume 0 == #valid[0];assume 0 < #StackHeapBarrier;call #Ultimate.allocInit(2, 1);call write~init~int(48, 1, 0, 1);call write~init~int(0, 1, 1, 1);call #Ultimate.allocInit(28, 2);call #Ultimate.allocInit(12, 3);call #Ultimate.allocInit(30, 4);call #Ultimate.allocInit(9, 5);call #Ultimate.allocInit(21, 6);call #Ultimate.allocInit(30, 7);call #Ultimate.allocInit(9, 8);call #Ultimate.allocInit(21, 9);call #Ultimate.allocInit(30, 10);call #Ultimate.allocInit(9, 11);call #Ultimate.allocInit(25, 12);call #Ultimate.allocInit(30, 13);call #Ultimate.allocInit(9, 14);call #Ultimate.allocInit(25, 15);call #Ultimate.allocInit(44, 16);call #Ultimate.allocInit(44, 17);call #Ultimate.allocInit(9, 18);call #Ultimate.allocInit(9, 19);call #Ultimate.allocInit(11, 20);call #Ultimate.allocInit(19, 21);call #Ultimate.allocInit(4, 22);call write~init~int(37, 22, 0, 1);call write~init~int(100, 22, 1, 1);call write~init~int(10, 22, 2, 1);call write~init~int(0, 22, 3, 1);call #Ultimate.allocInit(4, 23);call write~init~int(37, 23, 0, 1);call write~init~int(100, 23, 1, 1);call write~init~int(10, 23, 2, 1);call write~init~int(0, 23, 3, 1);call #Ultimate.allocInit(10, 24);call #Ultimate.allocInit(16, 25);call #Ultimate.allocInit(20, 26);call #Ultimate.allocInit(22, 27);call #Ultimate.allocInit(21, 28);call #Ultimate.allocInit(10, 29);call #Ultimate.allocInit(12, 30);call #Ultimate.allocInit(10, 31);call #Ultimate.allocInit(18, 32);call #Ultimate.allocInit(16, 33);call #Ultimate.allocInit(21, 34);call #Ultimate.allocInit(13, 35);call #Ultimate.allocInit(16, 36);call #Ultimate.allocInit(25, 37);call #Ultimate.allocInit(4, 38);call write~init~int(37, 38, 0, 1);call write~init~int(115, 38, 1, 1);call write~init~int(10, 38, 2, 1);call write~init~int(0, 38, 3, 1);call #Ultimate.allocInit(13, 39);~head~0.base, ~head~0.offset := 0, 0;~__SELECTED_FEATURE_Base~0 := 0;~__SELECTED_FEATURE_Keys~0 := 0;~__SELECTED_FEATURE_Encrypt~0 := 0;~__SELECTED_FEATURE_AutoResponder~0 := 0;~__SELECTED_FEATURE_AddressBook~0 := 0;~__SELECTED_FEATURE_Sign~0 := 0;~__SELECTED_FEATURE_Forward~0 := 0;~__SELECTED_FEATURE_Verify~0 := 0;~__SELECTED_FEATURE_Decrypt~0 := 0;~__GUIDSL_ROOT_PRODUCTION~0 := 0;~__GUIDSL_NON_TERMINAL_main~0 := 0;~bob~0 := 0;~rjh~0 := 0;~chuck~0 := 0;~queue_empty~0 := 1;~queued_message~0 := 0;~queued_client~0 := 0;~__ste_Client_counter~0 := 0;~__ste_client_name0~0.base, ~__ste_client_name0~0.offset := 0, 0;~__ste_client_name1~0.base, ~__ste_client_name1~0.offset := 0, 0;~__ste_client_name2~0.base, ~__ste_client_name2~0.offset := 0, 0;~__ste_client_outbuffer0~0 := 0;~__ste_client_outbuffer1~0 := 0;~__ste_client_outbuffer2~0 := 0;~__ste_client_outbuffer3~0 := 0;~__ste_ClientAddressBook_size0~0 := 0;~__ste_ClientAddressBook_size1~0 := 0;~__ste_ClientAddressBook_size2~0 := 0;~__ste_Client_AddressBook0_Alias0~0 := 0;~__ste_Client_AddressBook0_Alias1~0 := 0;~__ste_Client_AddressBook0_Alias2~0 := 0;~__ste_Client_AddressBook1_Alias0~0 := 0;~__ste_Client_AddressBook1_Alias1~0 := 0;~__ste_Client_AddressBook1_Alias2~0 := 0;~__ste_Client_AddressBook2_Alias0~0 := 0;~__ste_Client_AddressBook2_Alias1~0 := 0;~__ste_Client_AddressBook2_Alias2~0 := 0;~__ste_Client_AddressBook0_Address0~0 := 0;~__ste_Client_AddressBook0_Address1~0 := 0;~__ste_Client_AddressBook0_Address2~0 := 0;~__ste_Client_AddressBook1_Address0~0 := 0;~__ste_Client_AddressBook1_Address1~0 := 0;~__ste_Client_AddressBook1_Address2~0 := 0;~__ste_Client_AddressBook2_Address0~0 := 0;~__ste_Client_AddressBook2_Address1~0 := 0;~__ste_Client_AddressBook2_Address2~0 := 0;~__ste_client_autoResponse0~0 := 0;~__ste_client_autoResponse1~0 := 0;~__ste_client_autoResponse2~0 := 0;~__ste_client_privateKey0~0 := 0;~__ste_client_privateKey1~0 := 0;~__ste_client_privateKey2~0 := 0;~__ste_ClientKeyring_size0~0 := 0;~__ste_ClientKeyring_size1~0 := 0;~__ste_ClientKeyring_size2~0 := 0;~__ste_Client_Keyring0_User0~0 := 0;~__ste_Client_Keyring0_User1~0 := 0;~__ste_Client_Keyring0_User2~0 := 0;~__ste_Client_Keyring1_User0~0 := 0;~__ste_Client_Keyring1_User1~0 := 0;~__ste_Client_Keyring1_User2~0 := 0;~__ste_Client_Keyring2_User0~0 := 0;~__ste_Client_Keyring2_User1~0 := 0;~__ste_Client_Keyring2_User2~0 := 0;~__ste_Client_Keyring0_PublicKey0~0 := 0;~__ste_Client_Keyring0_PublicKey1~0 := 0;~__ste_Client_Keyring0_PublicKey2~0 := 0;~__ste_Client_Keyring1_PublicKey0~0 := 0;~__ste_Client_Keyring1_PublicKey1~0 := 0;~__ste_Client_Keyring1_PublicKey2~0 := 0;~__ste_Client_Keyring2_PublicKey0~0 := 0;~__ste_Client_Keyring2_PublicKey1~0 := 0;~__ste_Client_Keyring2_PublicKey2~0 := 0;~__ste_client_forwardReceiver0~0 := 0;~__ste_client_forwardReceiver1~0 := 0;~__ste_client_forwardReceiver2~0 := 0;~__ste_client_forwardReceiver3~0 := 0;~__ste_client_idCounter0~0 := 0;~__ste_client_idCounter1~0 := 0;~__ste_client_idCounter2~0 := 0;~__ste_Email_counter~0 := 0;~__ste_email_id0~0 := 0;~__ste_email_id1~0 := 0;~__ste_email_from0~0 := 0;~__ste_email_from1~0 := 0;~__ste_email_to0~0 := 0;~__ste_email_to1~0 := 0;~__ste_email_subject0~0.base, ~__ste_email_subject0~0.offset := 0, 0;~__ste_email_subject1~0.base, ~__ste_email_subject1~0.offset := 0, 0;~__ste_email_body0~0.base, ~__ste_email_body0~0.offset := 0, 0;~__ste_email_body1~0.base, ~__ste_email_body1~0.offset := 0, 0;~__ste_email_isEncrypted0~0 := 0;~__ste_email_isEncrypted1~0 := 0;~__ste_email_encryptionKey0~0 := 0;~__ste_email_encryptionKey1~0 := 0;~__ste_email_isSigned0~0 := 0;~__ste_email_isSigned1~0 := 0;~__ste_email_signKey0~0 := 0;~__ste_email_signKey1~0 := 0;~__ste_email_isSignatureVerified0~0 := 0;~__ste_email_isSignatureVerified1~0 := 0; {18424#true} is VALID [2022-02-20 18:00:19,728 INFO L290 TraceCheckUtils]: 1: Hoare triple {18424#true} assume { :end_inline_ULTIMATE.init } true;assume { :begin_inline_main } true;havoc main_#res#1;havoc main_#t~ret35#1, main_~retValue_acc~3#1, main_~tmp~4#1;havoc main_~retValue_acc~3#1;havoc main_~tmp~4#1;assume { :begin_inline_select_helpers } true; {18424#true} is VALID [2022-02-20 18:00:19,728 INFO L290 TraceCheckUtils]: 2: Hoare triple {18424#true} assume { :end_inline_select_helpers } true;assume { :begin_inline_select_features } true; {18424#true} is VALID [2022-02-20 18:00:19,729 INFO L290 TraceCheckUtils]: 3: Hoare triple {18424#true} assume { :end_inline_select_features } true;assume { :begin_inline_valid_product } true;havoc valid_product_#res#1;havoc valid_product_~retValue_acc~5#1;havoc valid_product_~retValue_acc~5#1;valid_product_~retValue_acc~5#1 := 1;valid_product_#res#1 := valid_product_~retValue_acc~5#1; {18424#true} is VALID [2022-02-20 18:00:19,729 INFO L290 TraceCheckUtils]: 4: Hoare triple {18424#true} main_#t~ret35#1 := valid_product_#res#1;assume { :end_inline_valid_product } true;assume -2147483648 <= main_#t~ret35#1 && main_#t~ret35#1 <= 2147483647;main_~tmp~4#1 := main_#t~ret35#1;havoc main_#t~ret35#1; {18424#true} is VALID [2022-02-20 18:00:19,729 INFO L290 TraceCheckUtils]: 5: Hoare triple {18424#true} assume 0 != main_~tmp~4#1;assume { :begin_inline_setup } true;havoc setup_#t~nondet32#1, setup_#t~nondet33#1, setup_#t~nondet34#1, setup_~__cil_tmp1~0#1.base, setup_~__cil_tmp1~0#1.offset, setup_~__cil_tmp2~0#1.base, setup_~__cil_tmp2~0#1.offset, setup_~__cil_tmp3~0#1.base, setup_~__cil_tmp3~0#1.offset;havoc setup_~__cil_tmp1~0#1.base, setup_~__cil_tmp1~0#1.offset;havoc setup_~__cil_tmp2~0#1.base, setup_~__cil_tmp2~0#1.offset;havoc setup_~__cil_tmp3~0#1.base, setup_~__cil_tmp3~0#1.offset;~bob~0 := 1;assume { :begin_inline_setup_bob } true;setup_bob_#in~bob___0#1 := ~bob~0;havoc setup_bob_~bob___0#1;setup_bob_~bob___0#1 := setup_bob_#in~bob___0#1;assume { :begin_inline_setup_bob__wrappee__Base } true;setup_bob__wrappee__Base_#in~bob___0#1 := setup_bob_~bob___0#1;havoc setup_bob__wrappee__Base_~bob___0#1;setup_bob__wrappee__Base_~bob___0#1 := setup_bob__wrappee__Base_#in~bob___0#1; {18424#true} is VALID [2022-02-20 18:00:19,729 INFO L272 TraceCheckUtils]: 6: Hoare triple {18424#true} call setClientId(setup_bob__wrappee__Base_~bob___0#1, setup_bob__wrappee__Base_~bob___0#1); {18487#(and (= |old(~__ste_client_idCounter0~0)| ~__ste_client_idCounter0~0) (= |old(~__ste_client_idCounter1~0)| ~__ste_client_idCounter1~0) (= |old(~__ste_client_idCounter2~0)| ~__ste_client_idCounter2~0))} is VALID [2022-02-20 18:00:19,730 INFO L290 TraceCheckUtils]: 7: Hoare triple {18487#(and (= |old(~__ste_client_idCounter0~0)| ~__ste_client_idCounter0~0) (= |old(~__ste_client_idCounter1~0)| ~__ste_client_idCounter1~0) (= |old(~__ste_client_idCounter2~0)| ~__ste_client_idCounter2~0))} ~handle := #in~handle;~value := #in~value; {18424#true} is VALID [2022-02-20 18:00:19,730 INFO L290 TraceCheckUtils]: 8: Hoare triple {18424#true} assume 1 == ~handle;~__ste_client_idCounter0~0 := ~value; {18424#true} is VALID [2022-02-20 18:00:19,730 INFO L290 TraceCheckUtils]: 9: Hoare triple {18424#true} assume true; {18424#true} is VALID [2022-02-20 18:00:19,730 INFO L284 TraceCheckUtils]: 10: Hoare quadruple {18424#true} {18424#true} #1134#return; {18424#true} is VALID [2022-02-20 18:00:19,730 INFO L290 TraceCheckUtils]: 11: Hoare triple {18424#true} assume { :end_inline_setup_bob__wrappee__Base } true; {18424#true} is VALID [2022-02-20 18:00:19,730 INFO L272 TraceCheckUtils]: 12: Hoare triple {18424#true} call setClientPrivateKey(setup_bob_~bob___0#1, 123); {18488#(and (= ~__ste_client_privateKey0~0 |old(~__ste_client_privateKey0~0)|) (= ~__ste_client_privateKey2~0 |old(~__ste_client_privateKey2~0)|) (= ~__ste_client_privateKey1~0 |old(~__ste_client_privateKey1~0)|))} is VALID [2022-02-20 18:00:19,731 INFO L290 TraceCheckUtils]: 13: Hoare triple {18488#(and (= ~__ste_client_privateKey0~0 |old(~__ste_client_privateKey0~0)|) (= ~__ste_client_privateKey2~0 |old(~__ste_client_privateKey2~0)|) (= ~__ste_client_privateKey1~0 |old(~__ste_client_privateKey1~0)|))} ~handle := #in~handle;~value := #in~value; {18424#true} is VALID [2022-02-20 18:00:19,731 INFO L290 TraceCheckUtils]: 14: Hoare triple {18424#true} assume 1 == ~handle;~__ste_client_privateKey0~0 := ~value; {18424#true} is VALID [2022-02-20 18:00:19,731 INFO L290 TraceCheckUtils]: 15: Hoare triple {18424#true} assume true; {18424#true} is VALID [2022-02-20 18:00:19,731 INFO L284 TraceCheckUtils]: 16: Hoare quadruple {18424#true} {18424#true} #1136#return; {18424#true} is VALID [2022-02-20 18:00:19,731 INFO L290 TraceCheckUtils]: 17: Hoare triple {18424#true} assume { :end_inline_setup_bob } true;setup_~__cil_tmp1~0#1.base, setup_~__cil_tmp1~0#1.offset := 18, 0;havoc setup_#t~nondet32#1;~rjh~0 := 2;assume { :begin_inline_setup_rjh } true;setup_rjh_#in~rjh___0#1 := ~rjh~0;havoc setup_rjh_~rjh___0#1;setup_rjh_~rjh___0#1 := setup_rjh_#in~rjh___0#1;assume { :begin_inline_setup_rjh__wrappee__Base } true;setup_rjh__wrappee__Base_#in~rjh___0#1 := setup_rjh_~rjh___0#1;havoc setup_rjh__wrappee__Base_~rjh___0#1;setup_rjh__wrappee__Base_~rjh___0#1 := setup_rjh__wrappee__Base_#in~rjh___0#1; {18424#true} is VALID [2022-02-20 18:00:19,732 INFO L272 TraceCheckUtils]: 18: Hoare triple {18424#true} call setClientId(setup_rjh__wrappee__Base_~rjh___0#1, setup_rjh__wrappee__Base_~rjh___0#1); {18487#(and (= |old(~__ste_client_idCounter0~0)| ~__ste_client_idCounter0~0) (= |old(~__ste_client_idCounter1~0)| ~__ste_client_idCounter1~0) (= |old(~__ste_client_idCounter2~0)| ~__ste_client_idCounter2~0))} is VALID [2022-02-20 18:00:19,732 INFO L290 TraceCheckUtils]: 19: Hoare triple {18487#(and (= |old(~__ste_client_idCounter0~0)| ~__ste_client_idCounter0~0) (= |old(~__ste_client_idCounter1~0)| ~__ste_client_idCounter1~0) (= |old(~__ste_client_idCounter2~0)| ~__ste_client_idCounter2~0))} ~handle := #in~handle;~value := #in~value; {18424#true} is VALID [2022-02-20 18:00:19,732 INFO L290 TraceCheckUtils]: 20: Hoare triple {18424#true} assume !(1 == ~handle); {18424#true} is VALID [2022-02-20 18:00:19,732 INFO L290 TraceCheckUtils]: 21: Hoare triple {18424#true} assume 2 == ~handle;~__ste_client_idCounter1~0 := ~value; {18424#true} is VALID [2022-02-20 18:00:19,732 INFO L290 TraceCheckUtils]: 22: Hoare triple {18424#true} assume true; {18424#true} is VALID [2022-02-20 18:00:19,732 INFO L284 TraceCheckUtils]: 23: Hoare quadruple {18424#true} {18424#true} #1138#return; {18424#true} is VALID [2022-02-20 18:00:19,732 INFO L290 TraceCheckUtils]: 24: Hoare triple {18424#true} assume { :end_inline_setup_rjh__wrappee__Base } true; {18424#true} is VALID [2022-02-20 18:00:19,733 INFO L272 TraceCheckUtils]: 25: Hoare triple {18424#true} call setClientPrivateKey(setup_rjh_~rjh___0#1, 456); {18488#(and (= ~__ste_client_privateKey0~0 |old(~__ste_client_privateKey0~0)|) (= ~__ste_client_privateKey2~0 |old(~__ste_client_privateKey2~0)|) (= ~__ste_client_privateKey1~0 |old(~__ste_client_privateKey1~0)|))} is VALID [2022-02-20 18:00:19,733 INFO L290 TraceCheckUtils]: 26: Hoare triple {18488#(and (= ~__ste_client_privateKey0~0 |old(~__ste_client_privateKey0~0)|) (= ~__ste_client_privateKey2~0 |old(~__ste_client_privateKey2~0)|) (= ~__ste_client_privateKey1~0 |old(~__ste_client_privateKey1~0)|))} ~handle := #in~handle;~value := #in~value; {18424#true} is VALID [2022-02-20 18:00:19,733 INFO L290 TraceCheckUtils]: 27: Hoare triple {18424#true} assume !(1 == ~handle); {18424#true} is VALID [2022-02-20 18:00:19,733 INFO L290 TraceCheckUtils]: 28: Hoare triple {18424#true} assume 2 == ~handle;~__ste_client_privateKey1~0 := ~value; {18424#true} is VALID [2022-02-20 18:00:19,733 INFO L290 TraceCheckUtils]: 29: Hoare triple {18424#true} assume true; {18424#true} is VALID [2022-02-20 18:00:19,734 INFO L284 TraceCheckUtils]: 30: Hoare quadruple {18424#true} {18424#true} #1140#return; {18424#true} is VALID [2022-02-20 18:00:19,734 INFO L290 TraceCheckUtils]: 31: Hoare triple {18424#true} assume { :end_inline_setup_rjh } true;setup_~__cil_tmp2~0#1.base, setup_~__cil_tmp2~0#1.offset := 19, 0;havoc setup_#t~nondet33#1;~chuck~0 := 3;assume { :begin_inline_setup_chuck } true;setup_chuck_#in~chuck___0#1 := ~chuck~0;havoc setup_chuck_~chuck___0#1;setup_chuck_~chuck___0#1 := setup_chuck_#in~chuck___0#1;assume { :begin_inline_setup_chuck__wrappee__Base } true;setup_chuck__wrappee__Base_#in~chuck___0#1 := setup_chuck_~chuck___0#1;havoc setup_chuck__wrappee__Base_~chuck___0#1;setup_chuck__wrappee__Base_~chuck___0#1 := setup_chuck__wrappee__Base_#in~chuck___0#1; {18444#(= 3 |ULTIMATE.start_setup_chuck__wrappee__Base_~chuck___0#1|)} is VALID [2022-02-20 18:00:19,735 INFO L272 TraceCheckUtils]: 32: Hoare triple {18444#(= 3 |ULTIMATE.start_setup_chuck__wrappee__Base_~chuck___0#1|)} call setClientId(setup_chuck__wrappee__Base_~chuck___0#1, setup_chuck__wrappee__Base_~chuck___0#1); {18487#(and (= |old(~__ste_client_idCounter0~0)| ~__ste_client_idCounter0~0) (= |old(~__ste_client_idCounter1~0)| ~__ste_client_idCounter1~0) (= |old(~__ste_client_idCounter2~0)| ~__ste_client_idCounter2~0))} is VALID [2022-02-20 18:00:19,735 INFO L290 TraceCheckUtils]: 33: Hoare triple {18487#(and (= |old(~__ste_client_idCounter0~0)| ~__ste_client_idCounter0~0) (= |old(~__ste_client_idCounter1~0)| ~__ste_client_idCounter1~0) (= |old(~__ste_client_idCounter2~0)| ~__ste_client_idCounter2~0))} ~handle := #in~handle;~value := #in~value; {18489#(= setClientId_~handle |setClientId_#in~handle|)} is VALID [2022-02-20 18:00:19,736 INFO L290 TraceCheckUtils]: 34: Hoare triple {18489#(= setClientId_~handle |setClientId_#in~handle|)} assume !(1 == ~handle); {18489#(= setClientId_~handle |setClientId_#in~handle|)} is VALID [2022-02-20 18:00:19,736 INFO L290 TraceCheckUtils]: 35: Hoare triple {18489#(= setClientId_~handle |setClientId_#in~handle|)} assume 2 == ~handle;~__ste_client_idCounter1~0 := ~value; {18490#(= 2 |setClientId_#in~handle|)} is VALID [2022-02-20 18:00:19,736 INFO L290 TraceCheckUtils]: 36: Hoare triple {18490#(= 2 |setClientId_#in~handle|)} assume true; {18490#(= 2 |setClientId_#in~handle|)} is VALID [2022-02-20 18:00:19,737 INFO L284 TraceCheckUtils]: 37: Hoare quadruple {18490#(= 2 |setClientId_#in~handle|)} {18444#(= 3 |ULTIMATE.start_setup_chuck__wrappee__Base_~chuck___0#1|)} #1142#return; {18425#false} is VALID [2022-02-20 18:00:19,737 INFO L290 TraceCheckUtils]: 38: Hoare triple {18425#false} assume { :end_inline_setup_chuck__wrappee__Base } true; {18425#false} is VALID [2022-02-20 18:00:19,737 INFO L272 TraceCheckUtils]: 39: Hoare triple {18425#false} call setClientPrivateKey(setup_chuck_~chuck___0#1, 789); {18488#(and (= ~__ste_client_privateKey0~0 |old(~__ste_client_privateKey0~0)|) (= ~__ste_client_privateKey2~0 |old(~__ste_client_privateKey2~0)|) (= ~__ste_client_privateKey1~0 |old(~__ste_client_privateKey1~0)|))} is VALID [2022-02-20 18:00:19,737 INFO L290 TraceCheckUtils]: 40: Hoare triple {18488#(and (= ~__ste_client_privateKey0~0 |old(~__ste_client_privateKey0~0)|) (= ~__ste_client_privateKey2~0 |old(~__ste_client_privateKey2~0)|) (= ~__ste_client_privateKey1~0 |old(~__ste_client_privateKey1~0)|))} ~handle := #in~handle;~value := #in~value; {18424#true} is VALID [2022-02-20 18:00:19,737 INFO L290 TraceCheckUtils]: 41: Hoare triple {18424#true} assume 1 == ~handle;~__ste_client_privateKey0~0 := ~value; {18424#true} is VALID [2022-02-20 18:00:19,737 INFO L290 TraceCheckUtils]: 42: Hoare triple {18424#true} assume true; {18424#true} is VALID [2022-02-20 18:00:19,737 INFO L284 TraceCheckUtils]: 43: Hoare quadruple {18424#true} {18425#false} #1144#return; {18425#false} is VALID [2022-02-20 18:00:19,737 INFO L290 TraceCheckUtils]: 44: Hoare triple {18425#false} assume { :end_inline_setup_chuck } true;setup_~__cil_tmp3~0#1.base, setup_~__cil_tmp3~0#1.offset := 20, 0;havoc setup_#t~nondet34#1; {18425#false} is VALID [2022-02-20 18:00:19,738 INFO L290 TraceCheckUtils]: 45: Hoare triple {18425#false} assume { :end_inline_setup } true;assume { :begin_inline_test } true;havoc test_#t~nondet47#1, test_#t~nondet48#1, test_#t~nondet49#1, test_#t~nondet50#1, test_#t~nondet51#1, test_#t~nondet52#1, test_#t~nondet53#1, test_#t~nondet54#1, test_#t~nondet55#1, test_#t~nondet56#1, test_#t~nondet57#1, test_~op1~0#1, test_~op2~0#1, test_~op3~0#1, test_~op4~0#1, test_~op5~0#1, test_~op6~0#1, test_~op7~0#1, test_~op8~0#1, test_~op9~0#1, test_~op10~0#1, test_~op11~0#1, test_~splverifierCounter~0#1, test_~tmp~6#1, test_~tmp___0~2#1, test_~tmp___1~1#1, test_~tmp___2~0#1, test_~tmp___3~0#1, test_~tmp___4~0#1, test_~tmp___5~0#1, test_~tmp___6~0#1, test_~tmp___7~0#1, test_~tmp___8~0#1, test_~tmp___9~0#1;havoc test_~op1~0#1;havoc test_~op2~0#1;havoc test_~op3~0#1;havoc test_~op4~0#1;havoc test_~op5~0#1;havoc test_~op6~0#1;havoc test_~op7~0#1;havoc test_~op8~0#1;havoc test_~op9~0#1;havoc test_~op10~0#1;havoc test_~op11~0#1;havoc test_~splverifierCounter~0#1;havoc test_~tmp~6#1;havoc test_~tmp___0~2#1;havoc test_~tmp___1~1#1;havoc test_~tmp___2~0#1;havoc test_~tmp___3~0#1;havoc test_~tmp___4~0#1;havoc test_~tmp___5~0#1;havoc test_~tmp___6~0#1;havoc test_~tmp___7~0#1;havoc test_~tmp___8~0#1;havoc test_~tmp___9~0#1;test_~op1~0#1 := 0;test_~op2~0#1 := 0;test_~op3~0#1 := 0;test_~op4~0#1 := 0;test_~op5~0#1 := 0;test_~op6~0#1 := 0;test_~op7~0#1 := 0;test_~op8~0#1 := 0;test_~op9~0#1 := 0;test_~op10~0#1 := 0;test_~op11~0#1 := 0;test_~splverifierCounter~0#1 := 0; {18425#false} is VALID [2022-02-20 18:00:19,738 INFO L290 TraceCheckUtils]: 46: Hoare triple {18425#false} assume !false; {18425#false} is VALID [2022-02-20 18:00:19,738 INFO L290 TraceCheckUtils]: 47: Hoare triple {18425#false} assume test_~splverifierCounter~0#1 < 4; {18425#false} is VALID [2022-02-20 18:00:19,738 INFO L290 TraceCheckUtils]: 48: Hoare triple {18425#false} test_~splverifierCounter~0#1 := 1 + test_~splverifierCounter~0#1; {18425#false} is VALID [2022-02-20 18:00:19,738 INFO L290 TraceCheckUtils]: 49: Hoare triple {18425#false} assume 0 == test_~op1~0#1;assume -2147483648 <= test_#t~nondet47#1 && test_#t~nondet47#1 <= 2147483647;test_~tmp___9~0#1 := test_#t~nondet47#1;havoc test_#t~nondet47#1; {18425#false} is VALID [2022-02-20 18:00:19,738 INFO L290 TraceCheckUtils]: 50: Hoare triple {18425#false} assume !(0 != test_~tmp___9~0#1); {18425#false} is VALID [2022-02-20 18:00:19,738 INFO L290 TraceCheckUtils]: 51: Hoare triple {18425#false} assume 0 == test_~op2~0#1;assume -2147483648 <= test_#t~nondet48#1 && test_#t~nondet48#1 <= 2147483647;test_~tmp___8~0#1 := test_#t~nondet48#1;havoc test_#t~nondet48#1; {18425#false} is VALID [2022-02-20 18:00:19,738 INFO L290 TraceCheckUtils]: 52: Hoare triple {18425#false} assume 0 != test_~tmp___8~0#1;assume { :begin_inline_rjhSetAutoRespond } true;assume { :begin_inline_setClientAutoResponse } true;setClientAutoResponse_#in~handle#1, setClientAutoResponse_#in~value#1 := ~rjh~0, 1;havoc setClientAutoResponse_~handle#1, setClientAutoResponse_~value#1;setClientAutoResponse_~handle#1 := setClientAutoResponse_#in~handle#1;setClientAutoResponse_~value#1 := setClientAutoResponse_#in~value#1; {18425#false} is VALID [2022-02-20 18:00:19,739 INFO L290 TraceCheckUtils]: 53: Hoare triple {18425#false} assume 1 == setClientAutoResponse_~handle#1;~__ste_client_autoResponse0~0 := setClientAutoResponse_~value#1; {18425#false} is VALID [2022-02-20 18:00:19,739 INFO L290 TraceCheckUtils]: 54: Hoare triple {18425#false} assume { :end_inline_setClientAutoResponse } true; {18425#false} is VALID [2022-02-20 18:00:19,739 INFO L290 TraceCheckUtils]: 55: Hoare triple {18425#false} assume { :end_inline_rjhSetAutoRespond } true;test_~op2~0#1 := 1; {18425#false} is VALID [2022-02-20 18:00:19,739 INFO L290 TraceCheckUtils]: 56: Hoare triple {18425#false} assume !false; {18425#false} is VALID [2022-02-20 18:00:19,739 INFO L290 TraceCheckUtils]: 57: Hoare triple {18425#false} assume !(test_~splverifierCounter~0#1 < 4); {18425#false} is VALID [2022-02-20 18:00:19,739 INFO L290 TraceCheckUtils]: 58: Hoare triple {18425#false} assume { :begin_inline_bobToRjh } true;havoc bobToRjh_#t~ret27#1, bobToRjh_#t~ret28#1, bobToRjh_#t~ret29#1, bobToRjh_#t~ret30#1, bobToRjh_~tmp~3#1, bobToRjh_~tmp___0~0#1, bobToRjh_~tmp___1~0#1;havoc bobToRjh_~tmp~3#1;havoc bobToRjh_~tmp___0~0#1;havoc bobToRjh_~tmp___1~0#1;call bobToRjh_#t~ret27#1 := puts(16, 0);assume -2147483648 <= bobToRjh_#t~ret27#1 && bobToRjh_#t~ret27#1 <= 2147483647;havoc bobToRjh_#t~ret27#1; {18425#false} is VALID [2022-02-20 18:00:19,739 INFO L272 TraceCheckUtils]: 59: Hoare triple {18425#false} call sendEmail(~bob~0, ~rjh~0); {18425#false} is VALID [2022-02-20 18:00:19,739 INFO L290 TraceCheckUtils]: 60: Hoare triple {18425#false} ~sender#1 := #in~sender#1;~receiver#1 := #in~receiver#1;havoc ~email~0#1;havoc ~tmp~14#1;assume { :begin_inline_createEmail } true;createEmail_#in~from#1, createEmail_#in~to#1 := 0, ~receiver#1;havoc createEmail_#res#1;havoc createEmail_~from#1, createEmail_~to#1, createEmail_~retValue_acc~31#1, createEmail_~msg~0#1;createEmail_~from#1 := createEmail_#in~from#1;createEmail_~to#1 := createEmail_#in~to#1;havoc createEmail_~retValue_acc~31#1;havoc createEmail_~msg~0#1;createEmail_~msg~0#1 := 1; {18425#false} is VALID [2022-02-20 18:00:19,740 INFO L272 TraceCheckUtils]: 61: Hoare triple {18425#false} call setEmailFrom(createEmail_~msg~0#1, createEmail_~from#1); {18491#(and (= |old(~__ste_email_from0~0)| ~__ste_email_from0~0) (= |old(~__ste_email_from1~0)| ~__ste_email_from1~0))} is VALID [2022-02-20 18:00:19,740 INFO L290 TraceCheckUtils]: 62: Hoare triple {18491#(and (= |old(~__ste_email_from0~0)| ~__ste_email_from0~0) (= |old(~__ste_email_from1~0)| ~__ste_email_from1~0))} ~handle := #in~handle;~value := #in~value; {18424#true} is VALID [2022-02-20 18:00:19,740 INFO L290 TraceCheckUtils]: 63: Hoare triple {18424#true} assume 1 == ~handle;~__ste_email_from0~0 := ~value; {18424#true} is VALID [2022-02-20 18:00:19,740 INFO L290 TraceCheckUtils]: 64: Hoare triple {18424#true} assume true; {18424#true} is VALID [2022-02-20 18:00:19,740 INFO L284 TraceCheckUtils]: 65: Hoare quadruple {18424#true} {18425#false} #1120#return; {18425#false} is VALID [2022-02-20 18:00:19,740 INFO L272 TraceCheckUtils]: 66: Hoare triple {18425#false} call setEmailTo(createEmail_~msg~0#1, createEmail_~to#1); {18492#(and (= ~__ste_email_to0~0 |old(~__ste_email_to0~0)|) (= ~__ste_email_to1~0 |old(~__ste_email_to1~0)|))} is VALID [2022-02-20 18:00:19,740 INFO L290 TraceCheckUtils]: 67: Hoare triple {18492#(and (= ~__ste_email_to0~0 |old(~__ste_email_to0~0)|) (= ~__ste_email_to1~0 |old(~__ste_email_to1~0)|))} ~handle := #in~handle;~value := #in~value; {18424#true} is VALID [2022-02-20 18:00:19,740 INFO L290 TraceCheckUtils]: 68: Hoare triple {18424#true} assume 1 == ~handle;~__ste_email_to0~0 := ~value; {18424#true} is VALID [2022-02-20 18:00:19,741 INFO L290 TraceCheckUtils]: 69: Hoare triple {18424#true} assume true; {18424#true} is VALID [2022-02-20 18:00:19,741 INFO L284 TraceCheckUtils]: 70: Hoare quadruple {18424#true} {18425#false} #1122#return; {18425#false} is VALID [2022-02-20 18:00:19,741 INFO L290 TraceCheckUtils]: 71: Hoare triple {18425#false} createEmail_~retValue_acc~31#1 := createEmail_~msg~0#1;createEmail_#res#1 := createEmail_~retValue_acc~31#1; {18425#false} is VALID [2022-02-20 18:00:19,741 INFO L290 TraceCheckUtils]: 72: Hoare triple {18425#false} #t~ret72#1 := createEmail_#res#1;assume { :end_inline_createEmail } true;assume -2147483648 <= #t~ret72#1 && #t~ret72#1 <= 2147483647;~tmp~14#1 := #t~ret72#1;havoc #t~ret72#1;~email~0#1 := ~tmp~14#1; {18425#false} is VALID [2022-02-20 18:00:19,741 INFO L272 TraceCheckUtils]: 73: Hoare triple {18425#false} call outgoing(~sender#1, ~email~0#1); {18425#false} is VALID [2022-02-20 18:00:19,741 INFO L290 TraceCheckUtils]: 74: Hoare triple {18425#false} ~client#1 := #in~client#1;~msg#1 := #in~msg#1;assume { :begin_inline_sign } true;sign_#in~client#1, sign_#in~msg#1 := ~client#1, ~msg#1;havoc sign_#t~ret76#1, sign_~client#1, sign_~msg#1, sign_~privkey~1#1, sign_~tmp~16#1;sign_~client#1 := sign_#in~client#1;sign_~msg#1 := sign_#in~msg#1;havoc sign_~privkey~1#1;havoc sign_~tmp~16#1; {18425#false} is VALID [2022-02-20 18:00:19,741 INFO L272 TraceCheckUtils]: 75: Hoare triple {18425#false} call sign_#t~ret76#1 := getClientPrivateKey(sign_~client#1); {18424#true} is VALID [2022-02-20 18:00:19,741 INFO L290 TraceCheckUtils]: 76: Hoare triple {18424#true} ~handle := #in~handle;havoc ~retValue_acc~20; {18424#true} is VALID [2022-02-20 18:00:19,741 INFO L290 TraceCheckUtils]: 77: Hoare triple {18424#true} assume 1 == ~handle;~retValue_acc~20 := ~__ste_client_privateKey0~0;#res := ~retValue_acc~20; {18424#true} is VALID [2022-02-20 18:00:19,741 INFO L290 TraceCheckUtils]: 78: Hoare triple {18424#true} assume true; {18424#true} is VALID [2022-02-20 18:00:19,742 INFO L284 TraceCheckUtils]: 79: Hoare quadruple {18424#true} {18425#false} #1054#return; {18425#false} is VALID [2022-02-20 18:00:19,742 INFO L290 TraceCheckUtils]: 80: Hoare triple {18425#false} assume -2147483648 <= sign_#t~ret76#1 && sign_#t~ret76#1 <= 2147483647;sign_~tmp~16#1 := sign_#t~ret76#1;havoc sign_#t~ret76#1;sign_~privkey~1#1 := sign_~tmp~16#1; {18425#false} is VALID [2022-02-20 18:00:19,742 INFO L290 TraceCheckUtils]: 81: Hoare triple {18425#false} assume 0 == sign_~privkey~1#1; {18425#false} is VALID [2022-02-20 18:00:19,742 INFO L290 TraceCheckUtils]: 82: Hoare triple {18425#false} assume { :end_inline_sign } true;assume { :begin_inline_outgoing__wrappee__AutoResponder } true;outgoing__wrappee__AutoResponder_#in~client#1, outgoing__wrappee__AutoResponder_#in~msg#1 := ~client#1, ~msg#1;havoc outgoing__wrappee__AutoResponder_#t~ret62#1, outgoing__wrappee__AutoResponder_#t~ret63#1, outgoing__wrappee__AutoResponder_~client#1, outgoing__wrappee__AutoResponder_~msg#1, outgoing__wrappee__AutoResponder_~receiver~0#1, outgoing__wrappee__AutoResponder_~tmp~9#1, outgoing__wrappee__AutoResponder_~pubkey~0#1, outgoing__wrappee__AutoResponder_~tmp___0~3#1;outgoing__wrappee__AutoResponder_~client#1 := outgoing__wrappee__AutoResponder_#in~client#1;outgoing__wrappee__AutoResponder_~msg#1 := outgoing__wrappee__AutoResponder_#in~msg#1;havoc outgoing__wrappee__AutoResponder_~receiver~0#1;havoc outgoing__wrappee__AutoResponder_~tmp~9#1;havoc outgoing__wrappee__AutoResponder_~pubkey~0#1;havoc outgoing__wrappee__AutoResponder_~tmp___0~3#1; {18425#false} is VALID [2022-02-20 18:00:19,742 INFO L272 TraceCheckUtils]: 83: Hoare triple {18425#false} call outgoing__wrappee__AutoResponder_#t~ret62#1 := getEmailTo(outgoing__wrappee__AutoResponder_~msg#1); {18424#true} is VALID [2022-02-20 18:00:19,742 INFO L290 TraceCheckUtils]: 84: Hoare triple {18424#true} ~handle := #in~handle;havoc ~retValue_acc~36; {18424#true} is VALID [2022-02-20 18:00:19,742 INFO L290 TraceCheckUtils]: 85: Hoare triple {18424#true} assume 1 == ~handle;~retValue_acc~36 := ~__ste_email_to0~0;#res := ~retValue_acc~36; {18424#true} is VALID [2022-02-20 18:00:19,742 INFO L290 TraceCheckUtils]: 86: Hoare triple {18424#true} assume true; {18424#true} is VALID [2022-02-20 18:00:19,742 INFO L284 TraceCheckUtils]: 87: Hoare quadruple {18424#true} {18425#false} #1056#return; {18425#false} is VALID [2022-02-20 18:00:19,742 INFO L290 TraceCheckUtils]: 88: Hoare triple {18425#false} assume -2147483648 <= outgoing__wrappee__AutoResponder_#t~ret62#1 && outgoing__wrappee__AutoResponder_#t~ret62#1 <= 2147483647;outgoing__wrappee__AutoResponder_~tmp~9#1 := outgoing__wrappee__AutoResponder_#t~ret62#1;havoc outgoing__wrappee__AutoResponder_#t~ret62#1;outgoing__wrappee__AutoResponder_~receiver~0#1 := outgoing__wrappee__AutoResponder_~tmp~9#1; {18425#false} is VALID [2022-02-20 18:00:19,743 INFO L272 TraceCheckUtils]: 89: Hoare triple {18425#false} call outgoing__wrappee__AutoResponder_#t~ret63#1 := findPublicKey(outgoing__wrappee__AutoResponder_~client#1, outgoing__wrappee__AutoResponder_~receiver~0#1); {18424#true} is VALID [2022-02-20 18:00:19,743 INFO L290 TraceCheckUtils]: 90: Hoare triple {18424#true} ~handle := #in~handle;~userid := #in~userid;havoc ~retValue_acc~25; {18424#true} is VALID [2022-02-20 18:00:19,743 INFO L290 TraceCheckUtils]: 91: Hoare triple {18424#true} assume 1 == ~handle; {18424#true} is VALID [2022-02-20 18:00:19,743 INFO L290 TraceCheckUtils]: 92: Hoare triple {18424#true} assume ~userid == ~__ste_Client_Keyring0_User0~0;~retValue_acc~25 := ~__ste_Client_Keyring0_PublicKey0~0;#res := ~retValue_acc~25; {18424#true} is VALID [2022-02-20 18:00:19,743 INFO L290 TraceCheckUtils]: 93: Hoare triple {18424#true} assume true; {18424#true} is VALID [2022-02-20 18:00:19,743 INFO L284 TraceCheckUtils]: 94: Hoare quadruple {18424#true} {18425#false} #1058#return; {18425#false} is VALID [2022-02-20 18:00:19,743 INFO L290 TraceCheckUtils]: 95: Hoare triple {18425#false} assume -2147483648 <= outgoing__wrappee__AutoResponder_#t~ret63#1 && outgoing__wrappee__AutoResponder_#t~ret63#1 <= 2147483647;outgoing__wrappee__AutoResponder_~tmp___0~3#1 := outgoing__wrappee__AutoResponder_#t~ret63#1;havoc outgoing__wrappee__AutoResponder_#t~ret63#1;outgoing__wrappee__AutoResponder_~pubkey~0#1 := outgoing__wrappee__AutoResponder_~tmp___0~3#1; {18425#false} is VALID [2022-02-20 18:00:19,743 INFO L290 TraceCheckUtils]: 96: Hoare triple {18425#false} assume !(0 != outgoing__wrappee__AutoResponder_~pubkey~0#1); {18425#false} is VALID [2022-02-20 18:00:19,743 INFO L290 TraceCheckUtils]: 97: Hoare triple {18425#false} assume { :begin_inline_outgoing__wrappee__Keys } true;outgoing__wrappee__Keys_#in~client#1, outgoing__wrappee__Keys_#in~msg#1 := outgoing__wrappee__AutoResponder_~client#1, outgoing__wrappee__AutoResponder_~msg#1;havoc outgoing__wrappee__Keys_#t~ret61#1, outgoing__wrappee__Keys_~client#1, outgoing__wrappee__Keys_~msg#1, outgoing__wrappee__Keys_~tmp~8#1;outgoing__wrappee__Keys_~client#1 := outgoing__wrappee__Keys_#in~client#1;outgoing__wrappee__Keys_~msg#1 := outgoing__wrappee__Keys_#in~msg#1;havoc outgoing__wrappee__Keys_~tmp~8#1;assume { :begin_inline_getClientId } true;getClientId_#in~handle#1 := outgoing__wrappee__Keys_~client#1;havoc getClientId_#res#1;havoc getClientId_~handle#1, getClientId_~retValue_acc~27#1;getClientId_~handle#1 := getClientId_#in~handle#1;havoc getClientId_~retValue_acc~27#1; {18425#false} is VALID [2022-02-20 18:00:19,744 INFO L290 TraceCheckUtils]: 98: Hoare triple {18425#false} assume 1 == getClientId_~handle#1;getClientId_~retValue_acc~27#1 := ~__ste_client_idCounter0~0;getClientId_#res#1 := getClientId_~retValue_acc~27#1; {18425#false} is VALID [2022-02-20 18:00:19,744 INFO L290 TraceCheckUtils]: 99: Hoare triple {18425#false} outgoing__wrappee__Keys_#t~ret61#1 := getClientId_#res#1;assume { :end_inline_getClientId } true;assume -2147483648 <= outgoing__wrappee__Keys_#t~ret61#1 && outgoing__wrappee__Keys_#t~ret61#1 <= 2147483647;outgoing__wrappee__Keys_~tmp~8#1 := outgoing__wrappee__Keys_#t~ret61#1;havoc outgoing__wrappee__Keys_#t~ret61#1; {18425#false} is VALID [2022-02-20 18:00:19,744 INFO L272 TraceCheckUtils]: 100: Hoare triple {18425#false} call setEmailFrom(outgoing__wrappee__Keys_~msg#1, outgoing__wrappee__Keys_~tmp~8#1); {18491#(and (= |old(~__ste_email_from0~0)| ~__ste_email_from0~0) (= |old(~__ste_email_from1~0)| ~__ste_email_from1~0))} is VALID [2022-02-20 18:00:19,744 INFO L290 TraceCheckUtils]: 101: Hoare triple {18491#(and (= |old(~__ste_email_from0~0)| ~__ste_email_from0~0) (= |old(~__ste_email_from1~0)| ~__ste_email_from1~0))} ~handle := #in~handle;~value := #in~value; {18424#true} is VALID [2022-02-20 18:00:19,744 INFO L290 TraceCheckUtils]: 102: Hoare triple {18424#true} assume 1 == ~handle;~__ste_email_from0~0 := ~value; {18424#true} is VALID [2022-02-20 18:00:19,744 INFO L290 TraceCheckUtils]: 103: Hoare triple {18424#true} assume true; {18424#true} is VALID [2022-02-20 18:00:19,744 INFO L284 TraceCheckUtils]: 104: Hoare quadruple {18424#true} {18425#false} #1064#return; {18425#false} is VALID [2022-02-20 18:00:19,744 INFO L290 TraceCheckUtils]: 105: Hoare triple {18425#false} assume { :begin_inline_mail } true;mail_#in~client#1, mail_#in~msg#1 := outgoing__wrappee__Keys_~client#1, outgoing__wrappee__Keys_~msg#1;havoc mail_#t~ret59#1, mail_#t~ret60#1, mail_~client#1, mail_~msg#1, mail_~__utac__ad__arg1~0#1, mail_~__utac__ad__arg2~0#1, mail_~tmp~7#1;mail_~client#1 := mail_#in~client#1;mail_~msg#1 := mail_#in~msg#1;havoc mail_~__utac__ad__arg1~0#1;havoc mail_~__utac__ad__arg2~0#1;havoc mail_~tmp~7#1;mail_~__utac__ad__arg1~0#1 := mail_~client#1;mail_~__utac__ad__arg2~0#1 := mail_~msg#1;assume { :begin_inline___utac_acc__SignForward_spec__1 } true;__utac_acc__SignForward_spec__1_#in~client#1, __utac_acc__SignForward_spec__1_#in~msg#1 := mail_~__utac__ad__arg1~0#1, mail_~__utac__ad__arg2~0#1;havoc __utac_acc__SignForward_spec__1_#t~ret107#1, __utac_acc__SignForward_spec__1_#t~ret108#1, __utac_acc__SignForward_spec__1_#t~ret109#1, __utac_acc__SignForward_spec__1_~client#1, __utac_acc__SignForward_spec__1_~msg#1, __utac_acc__SignForward_spec__1_~tmp~25#1, __utac_acc__SignForward_spec__1_~tmp___0~9#1;__utac_acc__SignForward_spec__1_~client#1 := __utac_acc__SignForward_spec__1_#in~client#1;__utac_acc__SignForward_spec__1_~msg#1 := __utac_acc__SignForward_spec__1_#in~msg#1;havoc __utac_acc__SignForward_spec__1_~tmp~25#1;havoc __utac_acc__SignForward_spec__1_~tmp___0~9#1;call __utac_acc__SignForward_spec__1_#t~ret107#1 := puts(39, 0);assume -2147483648 <= __utac_acc__SignForward_spec__1_#t~ret107#1 && __utac_acc__SignForward_spec__1_#t~ret107#1 <= 2147483647;havoc __utac_acc__SignForward_spec__1_#t~ret107#1; {18425#false} is VALID [2022-02-20 18:00:19,744 INFO L272 TraceCheckUtils]: 106: Hoare triple {18425#false} call __utac_acc__SignForward_spec__1_#t~ret108#1 := isSigned(__utac_acc__SignForward_spec__1_~msg#1); {18424#true} is VALID [2022-02-20 18:00:19,745 INFO L290 TraceCheckUtils]: 107: Hoare triple {18424#true} ~handle := #in~handle;havoc ~retValue_acc~41; {18424#true} is VALID [2022-02-20 18:00:19,745 INFO L290 TraceCheckUtils]: 108: Hoare triple {18424#true} assume 1 == ~handle;~retValue_acc~41 := ~__ste_email_isSigned0~0;#res := ~retValue_acc~41; {18424#true} is VALID [2022-02-20 18:00:19,745 INFO L290 TraceCheckUtils]: 109: Hoare triple {18424#true} assume true; {18424#true} is VALID [2022-02-20 18:00:19,745 INFO L284 TraceCheckUtils]: 110: Hoare quadruple {18424#true} {18425#false} #1066#return; {18425#false} is VALID [2022-02-20 18:00:19,745 INFO L290 TraceCheckUtils]: 111: Hoare triple {18425#false} assume -2147483648 <= __utac_acc__SignForward_spec__1_#t~ret108#1 && __utac_acc__SignForward_spec__1_#t~ret108#1 <= 2147483647;__utac_acc__SignForward_spec__1_~tmp___0~9#1 := __utac_acc__SignForward_spec__1_#t~ret108#1;havoc __utac_acc__SignForward_spec__1_#t~ret108#1; {18425#false} is VALID [2022-02-20 18:00:19,745 INFO L290 TraceCheckUtils]: 112: Hoare triple {18425#false} assume 0 != __utac_acc__SignForward_spec__1_~tmp___0~9#1; {18425#false} is VALID [2022-02-20 18:00:19,745 INFO L272 TraceCheckUtils]: 113: Hoare triple {18425#false} call __utac_acc__SignForward_spec__1_#t~ret109#1 := getClientPrivateKey(__utac_acc__SignForward_spec__1_~client#1); {18424#true} is VALID [2022-02-20 18:00:19,745 INFO L290 TraceCheckUtils]: 114: Hoare triple {18424#true} ~handle := #in~handle;havoc ~retValue_acc~20; {18424#true} is VALID [2022-02-20 18:00:19,746 INFO L290 TraceCheckUtils]: 115: Hoare triple {18424#true} assume 1 == ~handle;~retValue_acc~20 := ~__ste_client_privateKey0~0;#res := ~retValue_acc~20; {18424#true} is VALID [2022-02-20 18:00:19,746 INFO L290 TraceCheckUtils]: 116: Hoare triple {18424#true} assume true; {18424#true} is VALID [2022-02-20 18:00:19,746 INFO L284 TraceCheckUtils]: 117: Hoare quadruple {18424#true} {18425#false} #1068#return; {18425#false} is VALID [2022-02-20 18:00:19,746 INFO L290 TraceCheckUtils]: 118: Hoare triple {18425#false} assume -2147483648 <= __utac_acc__SignForward_spec__1_#t~ret109#1 && __utac_acc__SignForward_spec__1_#t~ret109#1 <= 2147483647;__utac_acc__SignForward_spec__1_~tmp~25#1 := __utac_acc__SignForward_spec__1_#t~ret109#1;havoc __utac_acc__SignForward_spec__1_#t~ret109#1; {18425#false} is VALID [2022-02-20 18:00:19,746 INFO L290 TraceCheckUtils]: 119: Hoare triple {18425#false} assume 0 == __utac_acc__SignForward_spec__1_~tmp~25#1;assume { :begin_inline___automaton_fail } true; {18425#false} is VALID [2022-02-20 18:00:19,746 INFO L290 TraceCheckUtils]: 120: Hoare triple {18425#false} assume !false; {18425#false} is VALID [2022-02-20 18:00:19,747 INFO L134 CoverageAnalysis]: Checked inductivity of 35 backedges. 7 proven. 0 refuted. 0 times theorem prover too weak. 28 trivial. 0 not checked. [2022-02-20 18:00:19,747 INFO L144 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2022-02-20 18:00:19,747 INFO L338 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [1295899514] [2022-02-20 18:00:19,747 INFO L165 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [1295899514] provided 1 perfect and 0 imperfect interpolant sequences [2022-02-20 18:00:19,747 INFO L191 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2022-02-20 18:00:19,747 INFO L204 FreeRefinementEngine]: Number of different interpolants: perfect sequences [9] imperfect sequences [] total 9 [2022-02-20 18:00:19,748 INFO L118 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [1859364948] [2022-02-20 18:00:19,748 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2022-02-20 18:00:19,749 INFO L78 Accepts]: Start accepts. Automaton has has 9 states, 8 states have (on average 9.625) internal successors, (77), 5 states have internal predecessors, (77), 3 states have call successors, (16), 6 states have call predecessors, (16), 2 states have return successors, (14), 2 states have call predecessors, (14), 3 states have call successors, (14) Word has length 121 [2022-02-20 18:00:19,749 INFO L84 Accepts]: Finished accepts. word is accepted. [2022-02-20 18:00:19,749 INFO L86 InductivityCheck]: Starting indutivity check of a Floyd-Hoare automaton with has 9 states, 8 states have (on average 9.625) internal successors, (77), 5 states have internal predecessors, (77), 3 states have call successors, (16), 6 states have call predecessors, (16), 2 states have return successors, (14), 2 states have call predecessors, (14), 3 states have call successors, (14) [2022-02-20 18:00:19,827 INFO L122 InductivityCheck]: Floyd-Hoare automaton has 107 edges. 107 inductive. 0 not inductive. 0 times theorem prover too weak to decide inductivity. [2022-02-20 18:00:19,827 INFO L546 AbstractCegarLoop]: INTERPOLANT automaton has 9 states [2022-02-20 18:00:19,827 INFO L108 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2022-02-20 18:00:19,827 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 9 interpolants. [2022-02-20 18:00:19,828 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=15, Invalid=57, Unknown=0, NotChecked=0, Total=72 [2022-02-20 18:00:19,828 INFO L87 Difference]: Start difference. First operand 441 states and 665 transitions. Second operand has 9 states, 8 states have (on average 9.625) internal successors, (77), 5 states have internal predecessors, (77), 3 states have call successors, (16), 6 states have call predecessors, (16), 2 states have return successors, (14), 2 states have call predecessors, (14), 3 states have call successors, (14) [2022-02-20 18:00:29,328 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-02-20 18:00:29,329 INFO L93 Difference]: Finished difference Result 1075 states and 1633 transitions. [2022-02-20 18:00:29,329 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 11 states. [2022-02-20 18:00:29,329 INFO L78 Accepts]: Start accepts. Automaton has has 9 states, 8 states have (on average 9.625) internal successors, (77), 5 states have internal predecessors, (77), 3 states have call successors, (16), 6 states have call predecessors, (16), 2 states have return successors, (14), 2 states have call predecessors, (14), 3 states have call successors, (14) Word has length 121 [2022-02-20 18:00:29,330 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2022-02-20 18:00:29,330 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 9 states, 8 states have (on average 9.625) internal successors, (77), 5 states have internal predecessors, (77), 3 states have call successors, (16), 6 states have call predecessors, (16), 2 states have return successors, (14), 2 states have call predecessors, (14), 3 states have call successors, (14) [2022-02-20 18:00:29,343 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 11 states to 11 states and 1429 transitions. [2022-02-20 18:00:29,343 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 9 states, 8 states have (on average 9.625) internal successors, (77), 5 states have internal predecessors, (77), 3 states have call successors, (16), 6 states have call predecessors, (16), 2 states have return successors, (14), 2 states have call predecessors, (14), 3 states have call successors, (14) [2022-02-20 18:00:29,356 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 11 states to 11 states and 1429 transitions. [2022-02-20 18:00:29,357 INFO L86 InductivityCheck]: Starting indutivity check of a Floyd-Hoare automaton with 11 states and 1429 transitions. [2022-02-20 18:00:30,589 INFO L122 InductivityCheck]: Floyd-Hoare automaton has 1429 edges. 1429 inductive. 0 not inductive. 0 times theorem prover too weak to decide inductivity. [2022-02-20 18:00:30,613 INFO L225 Difference]: With dead ends: 1075 [2022-02-20 18:00:30,613 INFO L226 Difference]: Without dead ends: 657 [2022-02-20 18:00:30,615 INFO L932 BasicCegarLoop]: 0 DeclaredPredicates, 46 GetRequests, 31 SyntacticMatches, 0 SemanticMatches, 15 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 30 ImplicationChecksByTransitivity, 0.1s TimeCoverageRelationStatistics Valid=73, Invalid=199, Unknown=0, NotChecked=0, Total=272 [2022-02-20 18:00:30,616 INFO L933 BasicCegarLoop]: 712 mSDtfsCounter, 1384 mSDsluCounter, 863 mSDsCounter, 0 mSdLazyCounter, 2613 mSolverCounterSat, 583 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 4.1s Time, 0 mProtectedPredicate, 0 mProtectedAction, 1401 SdHoareTripleChecker+Valid, 1575 SdHoareTripleChecker+Invalid, 3196 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 583 IncrementalHoareTripleChecker+Valid, 2613 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 4.2s IncrementalHoareTripleChecker+Time [2022-02-20 18:00:30,616 INFO L934 BasicCegarLoop]: SdHoareTripleChecker [1401 Valid, 1575 Invalid, 3196 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [583 Valid, 2613 Invalid, 0 Unknown, 0 Unchecked, 4.2s Time] [2022-02-20 18:00:30,617 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 657 states. [2022-02-20 18:00:30,709 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 657 to 443. [2022-02-20 18:00:30,710 INFO L214 AbstractMinimizeNwa]: Start testing correctness of minimizeSevpa [2022-02-20 18:00:30,711 INFO L82 GeneralOperation]: Start isEquivalent. First operand 657 states. Second operand has 443 states, 341 states have (on average 1.5043988269794721) internal successors, (513), 347 states have internal predecessors, (513), 74 states have call successors, (74), 24 states have call predecessors, (74), 27 states have return successors, (81), 73 states have call predecessors, (81), 73 states have call successors, (81) [2022-02-20 18:00:30,712 INFO L74 IsIncluded]: Start isIncluded. First operand 657 states. Second operand has 443 states, 341 states have (on average 1.5043988269794721) internal successors, (513), 347 states have internal predecessors, (513), 74 states have call successors, (74), 24 states have call predecessors, (74), 27 states have return successors, (81), 73 states have call predecessors, (81), 73 states have call successors, (81) [2022-02-20 18:00:30,722 INFO L87 Difference]: Start difference. First operand 657 states. Second operand has 443 states, 341 states have (on average 1.5043988269794721) internal successors, (513), 347 states have internal predecessors, (513), 74 states have call successors, (74), 24 states have call predecessors, (74), 27 states have return successors, (81), 73 states have call predecessors, (81), 73 states have call successors, (81) [2022-02-20 18:00:30,742 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-02-20 18:00:30,742 INFO L93 Difference]: Finished difference Result 657 states and 998 transitions. [2022-02-20 18:00:30,743 INFO L276 IsEmpty]: Start isEmpty. Operand 657 states and 998 transitions. [2022-02-20 18:00:30,745 INFO L282 IsEmpty]: Finished isEmpty. No accepting run. [2022-02-20 18:00:30,745 INFO L83 IsIncluded]: Finished isIncluded. Language is included [2022-02-20 18:00:30,747 INFO L74 IsIncluded]: Start isIncluded. First operand has 443 states, 341 states have (on average 1.5043988269794721) internal successors, (513), 347 states have internal predecessors, (513), 74 states have call successors, (74), 24 states have call predecessors, (74), 27 states have return successors, (81), 73 states have call predecessors, (81), 73 states have call successors, (81) Second operand 657 states. [2022-02-20 18:00:30,747 INFO L87 Difference]: Start difference. First operand has 443 states, 341 states have (on average 1.5043988269794721) internal successors, (513), 347 states have internal predecessors, (513), 74 states have call successors, (74), 24 states have call predecessors, (74), 27 states have return successors, (81), 73 states have call predecessors, (81), 73 states have call successors, (81) Second operand 657 states. [2022-02-20 18:00:30,767 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-02-20 18:00:30,767 INFO L93 Difference]: Finished difference Result 657 states and 998 transitions. [2022-02-20 18:00:30,767 INFO L276 IsEmpty]: Start isEmpty. Operand 657 states and 998 transitions. [2022-02-20 18:00:30,770 INFO L282 IsEmpty]: Finished isEmpty. No accepting run. [2022-02-20 18:00:30,770 INFO L83 IsIncluded]: Finished isIncluded. Language is included [2022-02-20 18:00:30,770 INFO L88 GeneralOperation]: Finished isEquivalent. [2022-02-20 18:00:30,770 INFO L221 AbstractMinimizeNwa]: Finished testing correctness of minimizeSevpa [2022-02-20 18:00:30,771 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 443 states, 341 states have (on average 1.5043988269794721) internal successors, (513), 347 states have internal predecessors, (513), 74 states have call successors, (74), 24 states have call predecessors, (74), 27 states have return successors, (81), 73 states have call predecessors, (81), 73 states have call successors, (81) [2022-02-20 18:00:30,783 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 443 states to 443 states and 668 transitions. [2022-02-20 18:00:30,783 INFO L78 Accepts]: Start accepts. Automaton has 443 states and 668 transitions. Word has length 121 [2022-02-20 18:00:30,783 INFO L84 Accepts]: Finished accepts. word is rejected. [2022-02-20 18:00:30,783 INFO L470 AbstractCegarLoop]: Abstraction has 443 states and 668 transitions. [2022-02-20 18:00:30,783 INFO L471 AbstractCegarLoop]: INTERPOLANT automaton has has 9 states, 8 states have (on average 9.625) internal successors, (77), 5 states have internal predecessors, (77), 3 states have call successors, (16), 6 states have call predecessors, (16), 2 states have return successors, (14), 2 states have call predecessors, (14), 3 states have call successors, (14) [2022-02-20 18:00:30,784 INFO L276 IsEmpty]: Start isEmpty. Operand 443 states and 668 transitions. [2022-02-20 18:00:30,790 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 123 [2022-02-20 18:00:30,790 INFO L506 BasicCegarLoop]: Found error trace [2022-02-20 18:00:30,791 INFO L514 BasicCegarLoop]: trace histogram [3, 3, 3, 3, 2, 2, 2, 2, 2, 2, 2, 2, 2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-02-20 18:00:30,791 WARN L452 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable6 [2022-02-20 18:00:30,791 INFO L402 AbstractCegarLoop]: === Iteration 8 === Targeting outgoingErr0ASSERT_VIOLATIONERROR_FUNCTION === [outgoingErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2022-02-20 18:00:30,791 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2022-02-20 18:00:30,792 INFO L85 PathProgramCache]: Analyzing trace with hash -342588923, now seen corresponding path program 1 times [2022-02-20 18:00:30,792 INFO L126 FreeRefinementEngine]: Executing refinement strategy CAMEL [2022-02-20 18:00:30,792 INFO L338 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [1608934556] [2022-02-20 18:00:30,792 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-02-20 18:00:30,792 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2022-02-20 18:00:30,811 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-02-20 18:00:30,836 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 6 [2022-02-20 18:00:30,837 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-02-20 18:00:30,839 INFO L290 TraceCheckUtils]: 0: Hoare triple {22064#(and (= |old(~__ste_client_idCounter0~0)| ~__ste_client_idCounter0~0) (= |old(~__ste_client_idCounter1~0)| ~__ste_client_idCounter1~0) (= |old(~__ste_client_idCounter2~0)| ~__ste_client_idCounter2~0))} ~handle := #in~handle;~value := #in~value; {21999#true} is VALID [2022-02-20 18:00:30,840 INFO L290 TraceCheckUtils]: 1: Hoare triple {21999#true} assume 1 == ~handle;~__ste_client_idCounter0~0 := ~value; {21999#true} is VALID [2022-02-20 18:00:30,840 INFO L290 TraceCheckUtils]: 2: Hoare triple {21999#true} assume true; {21999#true} is VALID [2022-02-20 18:00:30,840 INFO L284 TraceCheckUtils]: 3: Hoare quadruple {21999#true} {21999#true} #1134#return; {21999#true} is VALID [2022-02-20 18:00:30,845 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 12 [2022-02-20 18:00:30,846 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-02-20 18:00:30,849 INFO L290 TraceCheckUtils]: 0: Hoare triple {22065#(and (= ~__ste_client_privateKey0~0 |old(~__ste_client_privateKey0~0)|) (= ~__ste_client_privateKey2~0 |old(~__ste_client_privateKey2~0)|) (= ~__ste_client_privateKey1~0 |old(~__ste_client_privateKey1~0)|))} ~handle := #in~handle;~value := #in~value; {21999#true} is VALID [2022-02-20 18:00:30,849 INFO L290 TraceCheckUtils]: 1: Hoare triple {21999#true} assume 1 == ~handle;~__ste_client_privateKey0~0 := ~value; {21999#true} is VALID [2022-02-20 18:00:30,849 INFO L290 TraceCheckUtils]: 2: Hoare triple {21999#true} assume true; {21999#true} is VALID [2022-02-20 18:00:30,849 INFO L284 TraceCheckUtils]: 3: Hoare quadruple {21999#true} {21999#true} #1136#return; {21999#true} is VALID [2022-02-20 18:00:30,849 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 18 [2022-02-20 18:00:30,850 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-02-20 18:00:30,852 INFO L290 TraceCheckUtils]: 0: Hoare triple {22064#(and (= |old(~__ste_client_idCounter0~0)| ~__ste_client_idCounter0~0) (= |old(~__ste_client_idCounter1~0)| ~__ste_client_idCounter1~0) (= |old(~__ste_client_idCounter2~0)| ~__ste_client_idCounter2~0))} ~handle := #in~handle;~value := #in~value; {21999#true} is VALID [2022-02-20 18:00:30,852 INFO L290 TraceCheckUtils]: 1: Hoare triple {21999#true} assume !(1 == ~handle); {21999#true} is VALID [2022-02-20 18:00:30,852 INFO L290 TraceCheckUtils]: 2: Hoare triple {21999#true} assume 2 == ~handle;~__ste_client_idCounter1~0 := ~value; {21999#true} is VALID [2022-02-20 18:00:30,852 INFO L290 TraceCheckUtils]: 3: Hoare triple {21999#true} assume true; {21999#true} is VALID [2022-02-20 18:00:30,852 INFO L284 TraceCheckUtils]: 4: Hoare quadruple {21999#true} {21999#true} #1138#return; {21999#true} is VALID [2022-02-20 18:00:30,852 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 25 [2022-02-20 18:00:30,854 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-02-20 18:00:30,855 INFO L290 TraceCheckUtils]: 0: Hoare triple {22065#(and (= ~__ste_client_privateKey0~0 |old(~__ste_client_privateKey0~0)|) (= ~__ste_client_privateKey2~0 |old(~__ste_client_privateKey2~0)|) (= ~__ste_client_privateKey1~0 |old(~__ste_client_privateKey1~0)|))} ~handle := #in~handle;~value := #in~value; {21999#true} is VALID [2022-02-20 18:00:30,855 INFO L290 TraceCheckUtils]: 1: Hoare triple {21999#true} assume !(1 == ~handle); {21999#true} is VALID [2022-02-20 18:00:30,855 INFO L290 TraceCheckUtils]: 2: Hoare triple {21999#true} assume 2 == ~handle;~__ste_client_privateKey1~0 := ~value; {21999#true} is VALID [2022-02-20 18:00:30,856 INFO L290 TraceCheckUtils]: 3: Hoare triple {21999#true} assume true; {21999#true} is VALID [2022-02-20 18:00:30,856 INFO L284 TraceCheckUtils]: 4: Hoare quadruple {21999#true} {21999#true} #1140#return; {21999#true} is VALID [2022-02-20 18:00:30,856 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 32 [2022-02-20 18:00:30,857 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-02-20 18:00:30,869 INFO L290 TraceCheckUtils]: 0: Hoare triple {22064#(and (= |old(~__ste_client_idCounter0~0)| ~__ste_client_idCounter0~0) (= |old(~__ste_client_idCounter1~0)| ~__ste_client_idCounter1~0) (= |old(~__ste_client_idCounter2~0)| ~__ste_client_idCounter2~0))} ~handle := #in~handle;~value := #in~value; {22066#(= setClientId_~handle |setClientId_#in~handle|)} is VALID [2022-02-20 18:00:30,869 INFO L290 TraceCheckUtils]: 1: Hoare triple {22066#(= setClientId_~handle |setClientId_#in~handle|)} assume !(1 == ~handle); {22066#(= setClientId_~handle |setClientId_#in~handle|)} is VALID [2022-02-20 18:00:30,870 INFO L290 TraceCheckUtils]: 2: Hoare triple {22066#(= setClientId_~handle |setClientId_#in~handle|)} assume !(2 == ~handle); {22066#(= setClientId_~handle |setClientId_#in~handle|)} is VALID [2022-02-20 18:00:30,870 INFO L290 TraceCheckUtils]: 3: Hoare triple {22066#(= setClientId_~handle |setClientId_#in~handle|)} assume 3 == ~handle;~__ste_client_idCounter2~0 := ~value; {22067#(= 3 |setClientId_#in~handle|)} is VALID [2022-02-20 18:00:30,870 INFO L290 TraceCheckUtils]: 4: Hoare triple {22067#(= 3 |setClientId_#in~handle|)} assume true; {22067#(= 3 |setClientId_#in~handle|)} is VALID [2022-02-20 18:00:30,871 INFO L284 TraceCheckUtils]: 5: Hoare quadruple {22067#(= 3 |setClientId_#in~handle|)} {22019#(= |ULTIMATE.start_setup_chuck_~chuck___0#1| |ULTIMATE.start_setup_chuck__wrappee__Base_~chuck___0#1|)} #1142#return; {22026#(not (= |ULTIMATE.start_setup_chuck_~chuck___0#1| 1))} is VALID [2022-02-20 18:00:30,871 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 40 [2022-02-20 18:00:30,872 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-02-20 18:00:30,887 INFO L290 TraceCheckUtils]: 0: Hoare triple {22065#(and (= ~__ste_client_privateKey0~0 |old(~__ste_client_privateKey0~0)|) (= ~__ste_client_privateKey2~0 |old(~__ste_client_privateKey2~0)|) (= ~__ste_client_privateKey1~0 |old(~__ste_client_privateKey1~0)|))} ~handle := #in~handle;~value := #in~value; {22068#(= setClientPrivateKey_~handle |setClientPrivateKey_#in~handle|)} is VALID [2022-02-20 18:00:30,887 INFO L290 TraceCheckUtils]: 1: Hoare triple {22068#(= setClientPrivateKey_~handle |setClientPrivateKey_#in~handle|)} assume 1 == ~handle;~__ste_client_privateKey0~0 := ~value; {22069#(= |setClientPrivateKey_#in~handle| 1)} is VALID [2022-02-20 18:00:30,887 INFO L290 TraceCheckUtils]: 2: Hoare triple {22069#(= |setClientPrivateKey_#in~handle| 1)} assume true; {22069#(= |setClientPrivateKey_#in~handle| 1)} is VALID [2022-02-20 18:00:30,888 INFO L284 TraceCheckUtils]: 3: Hoare quadruple {22069#(= |setClientPrivateKey_#in~handle| 1)} {22026#(not (= |ULTIMATE.start_setup_chuck_~chuck___0#1| 1))} #1144#return; {22000#false} is VALID [2022-02-20 18:00:30,895 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 62 [2022-02-20 18:00:30,896 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-02-20 18:00:30,897 INFO L290 TraceCheckUtils]: 0: Hoare triple {22070#(and (= |old(~__ste_email_from0~0)| ~__ste_email_from0~0) (= |old(~__ste_email_from1~0)| ~__ste_email_from1~0))} ~handle := #in~handle;~value := #in~value; {21999#true} is VALID [2022-02-20 18:00:30,897 INFO L290 TraceCheckUtils]: 1: Hoare triple {21999#true} assume 1 == ~handle;~__ste_email_from0~0 := ~value; {21999#true} is VALID [2022-02-20 18:00:30,897 INFO L290 TraceCheckUtils]: 2: Hoare triple {21999#true} assume true; {21999#true} is VALID [2022-02-20 18:00:30,897 INFO L284 TraceCheckUtils]: 3: Hoare quadruple {21999#true} {22000#false} #1120#return; {22000#false} is VALID [2022-02-20 18:00:30,909 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 67 [2022-02-20 18:00:30,910 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-02-20 18:00:30,913 INFO L290 TraceCheckUtils]: 0: Hoare triple {22071#(and (= ~__ste_email_to0~0 |old(~__ste_email_to0~0)|) (= ~__ste_email_to1~0 |old(~__ste_email_to1~0)|))} ~handle := #in~handle;~value := #in~value; {21999#true} is VALID [2022-02-20 18:00:30,913 INFO L290 TraceCheckUtils]: 1: Hoare triple {21999#true} assume 1 == ~handle;~__ste_email_to0~0 := ~value; {21999#true} is VALID [2022-02-20 18:00:30,913 INFO L290 TraceCheckUtils]: 2: Hoare triple {21999#true} assume true; {21999#true} is VALID [2022-02-20 18:00:30,914 INFO L284 TraceCheckUtils]: 3: Hoare quadruple {21999#true} {22000#false} #1122#return; {22000#false} is VALID [2022-02-20 18:00:30,914 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 76 [2022-02-20 18:00:30,915 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-02-20 18:00:30,916 INFO L290 TraceCheckUtils]: 0: Hoare triple {21999#true} ~handle := #in~handle;havoc ~retValue_acc~20; {21999#true} is VALID [2022-02-20 18:00:30,916 INFO L290 TraceCheckUtils]: 1: Hoare triple {21999#true} assume 1 == ~handle;~retValue_acc~20 := ~__ste_client_privateKey0~0;#res := ~retValue_acc~20; {21999#true} is VALID [2022-02-20 18:00:30,916 INFO L290 TraceCheckUtils]: 2: Hoare triple {21999#true} assume true; {21999#true} is VALID [2022-02-20 18:00:30,917 INFO L284 TraceCheckUtils]: 3: Hoare quadruple {21999#true} {22000#false} #1054#return; {22000#false} is VALID [2022-02-20 18:00:30,917 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 84 [2022-02-20 18:00:30,917 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-02-20 18:00:30,919 INFO L290 TraceCheckUtils]: 0: Hoare triple {21999#true} ~handle := #in~handle;havoc ~retValue_acc~36; {21999#true} is VALID [2022-02-20 18:00:30,920 INFO L290 TraceCheckUtils]: 1: Hoare triple {21999#true} assume 1 == ~handle;~retValue_acc~36 := ~__ste_email_to0~0;#res := ~retValue_acc~36; {21999#true} is VALID [2022-02-20 18:00:30,920 INFO L290 TraceCheckUtils]: 2: Hoare triple {21999#true} assume true; {21999#true} is VALID [2022-02-20 18:00:30,920 INFO L284 TraceCheckUtils]: 3: Hoare quadruple {21999#true} {22000#false} #1056#return; {22000#false} is VALID [2022-02-20 18:00:30,920 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 90 [2022-02-20 18:00:30,921 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-02-20 18:00:30,923 INFO L290 TraceCheckUtils]: 0: Hoare triple {21999#true} ~handle := #in~handle;~userid := #in~userid;havoc ~retValue_acc~25; {21999#true} is VALID [2022-02-20 18:00:30,923 INFO L290 TraceCheckUtils]: 1: Hoare triple {21999#true} assume 1 == ~handle; {21999#true} is VALID [2022-02-20 18:00:30,923 INFO L290 TraceCheckUtils]: 2: Hoare triple {21999#true} assume ~userid == ~__ste_Client_Keyring0_User0~0;~retValue_acc~25 := ~__ste_Client_Keyring0_PublicKey0~0;#res := ~retValue_acc~25; {21999#true} is VALID [2022-02-20 18:00:30,923 INFO L290 TraceCheckUtils]: 3: Hoare triple {21999#true} assume true; {21999#true} is VALID [2022-02-20 18:00:30,923 INFO L284 TraceCheckUtils]: 4: Hoare quadruple {21999#true} {22000#false} #1058#return; {22000#false} is VALID [2022-02-20 18:00:30,924 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 101 [2022-02-20 18:00:30,933 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-02-20 18:00:30,935 INFO L290 TraceCheckUtils]: 0: Hoare triple {22070#(and (= |old(~__ste_email_from0~0)| ~__ste_email_from0~0) (= |old(~__ste_email_from1~0)| ~__ste_email_from1~0))} ~handle := #in~handle;~value := #in~value; {21999#true} is VALID [2022-02-20 18:00:30,935 INFO L290 TraceCheckUtils]: 1: Hoare triple {21999#true} assume 1 == ~handle;~__ste_email_from0~0 := ~value; {21999#true} is VALID [2022-02-20 18:00:30,935 INFO L290 TraceCheckUtils]: 2: Hoare triple {21999#true} assume true; {21999#true} is VALID [2022-02-20 18:00:30,935 INFO L284 TraceCheckUtils]: 3: Hoare quadruple {21999#true} {22000#false} #1064#return; {22000#false} is VALID [2022-02-20 18:00:30,935 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 107 [2022-02-20 18:00:30,936 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-02-20 18:00:30,938 INFO L290 TraceCheckUtils]: 0: Hoare triple {21999#true} ~handle := #in~handle;havoc ~retValue_acc~41; {21999#true} is VALID [2022-02-20 18:00:30,938 INFO L290 TraceCheckUtils]: 1: Hoare triple {21999#true} assume 1 == ~handle;~retValue_acc~41 := ~__ste_email_isSigned0~0;#res := ~retValue_acc~41; {21999#true} is VALID [2022-02-20 18:00:30,938 INFO L290 TraceCheckUtils]: 2: Hoare triple {21999#true} assume true; {21999#true} is VALID [2022-02-20 18:00:30,939 INFO L284 TraceCheckUtils]: 3: Hoare quadruple {21999#true} {22000#false} #1066#return; {22000#false} is VALID [2022-02-20 18:00:30,939 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 114 [2022-02-20 18:00:30,940 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-02-20 18:00:30,942 INFO L290 TraceCheckUtils]: 0: Hoare triple {21999#true} ~handle := #in~handle;havoc ~retValue_acc~20; {21999#true} is VALID [2022-02-20 18:00:30,942 INFO L290 TraceCheckUtils]: 1: Hoare triple {21999#true} assume 1 == ~handle;~retValue_acc~20 := ~__ste_client_privateKey0~0;#res := ~retValue_acc~20; {21999#true} is VALID [2022-02-20 18:00:30,942 INFO L290 TraceCheckUtils]: 2: Hoare triple {21999#true} assume true; {21999#true} is VALID [2022-02-20 18:00:30,942 INFO L284 TraceCheckUtils]: 3: Hoare quadruple {21999#true} {22000#false} #1068#return; {22000#false} is VALID [2022-02-20 18:00:30,942 INFO L290 TraceCheckUtils]: 0: Hoare triple {21999#true} assume { :begin_inline_ULTIMATE.init } true;#NULL.base, #NULL.offset := 0, 0;assume 0 == #valid[0];assume 0 < #StackHeapBarrier;call #Ultimate.allocInit(2, 1);call write~init~int(48, 1, 0, 1);call write~init~int(0, 1, 1, 1);call #Ultimate.allocInit(28, 2);call #Ultimate.allocInit(12, 3);call #Ultimate.allocInit(30, 4);call #Ultimate.allocInit(9, 5);call #Ultimate.allocInit(21, 6);call #Ultimate.allocInit(30, 7);call #Ultimate.allocInit(9, 8);call #Ultimate.allocInit(21, 9);call #Ultimate.allocInit(30, 10);call #Ultimate.allocInit(9, 11);call #Ultimate.allocInit(25, 12);call #Ultimate.allocInit(30, 13);call #Ultimate.allocInit(9, 14);call #Ultimate.allocInit(25, 15);call #Ultimate.allocInit(44, 16);call #Ultimate.allocInit(44, 17);call #Ultimate.allocInit(9, 18);call #Ultimate.allocInit(9, 19);call #Ultimate.allocInit(11, 20);call #Ultimate.allocInit(19, 21);call #Ultimate.allocInit(4, 22);call write~init~int(37, 22, 0, 1);call write~init~int(100, 22, 1, 1);call write~init~int(10, 22, 2, 1);call write~init~int(0, 22, 3, 1);call #Ultimate.allocInit(4, 23);call write~init~int(37, 23, 0, 1);call write~init~int(100, 23, 1, 1);call write~init~int(10, 23, 2, 1);call write~init~int(0, 23, 3, 1);call #Ultimate.allocInit(10, 24);call #Ultimate.allocInit(16, 25);call #Ultimate.allocInit(20, 26);call #Ultimate.allocInit(22, 27);call #Ultimate.allocInit(21, 28);call #Ultimate.allocInit(10, 29);call #Ultimate.allocInit(12, 30);call #Ultimate.allocInit(10, 31);call #Ultimate.allocInit(18, 32);call #Ultimate.allocInit(16, 33);call #Ultimate.allocInit(21, 34);call #Ultimate.allocInit(13, 35);call #Ultimate.allocInit(16, 36);call #Ultimate.allocInit(25, 37);call #Ultimate.allocInit(4, 38);call write~init~int(37, 38, 0, 1);call write~init~int(115, 38, 1, 1);call write~init~int(10, 38, 2, 1);call write~init~int(0, 38, 3, 1);call #Ultimate.allocInit(13, 39);~head~0.base, ~head~0.offset := 0, 0;~__SELECTED_FEATURE_Base~0 := 0;~__SELECTED_FEATURE_Keys~0 := 0;~__SELECTED_FEATURE_Encrypt~0 := 0;~__SELECTED_FEATURE_AutoResponder~0 := 0;~__SELECTED_FEATURE_AddressBook~0 := 0;~__SELECTED_FEATURE_Sign~0 := 0;~__SELECTED_FEATURE_Forward~0 := 0;~__SELECTED_FEATURE_Verify~0 := 0;~__SELECTED_FEATURE_Decrypt~0 := 0;~__GUIDSL_ROOT_PRODUCTION~0 := 0;~__GUIDSL_NON_TERMINAL_main~0 := 0;~bob~0 := 0;~rjh~0 := 0;~chuck~0 := 0;~queue_empty~0 := 1;~queued_message~0 := 0;~queued_client~0 := 0;~__ste_Client_counter~0 := 0;~__ste_client_name0~0.base, ~__ste_client_name0~0.offset := 0, 0;~__ste_client_name1~0.base, ~__ste_client_name1~0.offset := 0, 0;~__ste_client_name2~0.base, ~__ste_client_name2~0.offset := 0, 0;~__ste_client_outbuffer0~0 := 0;~__ste_client_outbuffer1~0 := 0;~__ste_client_outbuffer2~0 := 0;~__ste_client_outbuffer3~0 := 0;~__ste_ClientAddressBook_size0~0 := 0;~__ste_ClientAddressBook_size1~0 := 0;~__ste_ClientAddressBook_size2~0 := 0;~__ste_Client_AddressBook0_Alias0~0 := 0;~__ste_Client_AddressBook0_Alias1~0 := 0;~__ste_Client_AddressBook0_Alias2~0 := 0;~__ste_Client_AddressBook1_Alias0~0 := 0;~__ste_Client_AddressBook1_Alias1~0 := 0;~__ste_Client_AddressBook1_Alias2~0 := 0;~__ste_Client_AddressBook2_Alias0~0 := 0;~__ste_Client_AddressBook2_Alias1~0 := 0;~__ste_Client_AddressBook2_Alias2~0 := 0;~__ste_Client_AddressBook0_Address0~0 := 0;~__ste_Client_AddressBook0_Address1~0 := 0;~__ste_Client_AddressBook0_Address2~0 := 0;~__ste_Client_AddressBook1_Address0~0 := 0;~__ste_Client_AddressBook1_Address1~0 := 0;~__ste_Client_AddressBook1_Address2~0 := 0;~__ste_Client_AddressBook2_Address0~0 := 0;~__ste_Client_AddressBook2_Address1~0 := 0;~__ste_Client_AddressBook2_Address2~0 := 0;~__ste_client_autoResponse0~0 := 0;~__ste_client_autoResponse1~0 := 0;~__ste_client_autoResponse2~0 := 0;~__ste_client_privateKey0~0 := 0;~__ste_client_privateKey1~0 := 0;~__ste_client_privateKey2~0 := 0;~__ste_ClientKeyring_size0~0 := 0;~__ste_ClientKeyring_size1~0 := 0;~__ste_ClientKeyring_size2~0 := 0;~__ste_Client_Keyring0_User0~0 := 0;~__ste_Client_Keyring0_User1~0 := 0;~__ste_Client_Keyring0_User2~0 := 0;~__ste_Client_Keyring1_User0~0 := 0;~__ste_Client_Keyring1_User1~0 := 0;~__ste_Client_Keyring1_User2~0 := 0;~__ste_Client_Keyring2_User0~0 := 0;~__ste_Client_Keyring2_User1~0 := 0;~__ste_Client_Keyring2_User2~0 := 0;~__ste_Client_Keyring0_PublicKey0~0 := 0;~__ste_Client_Keyring0_PublicKey1~0 := 0;~__ste_Client_Keyring0_PublicKey2~0 := 0;~__ste_Client_Keyring1_PublicKey0~0 := 0;~__ste_Client_Keyring1_PublicKey1~0 := 0;~__ste_Client_Keyring1_PublicKey2~0 := 0;~__ste_Client_Keyring2_PublicKey0~0 := 0;~__ste_Client_Keyring2_PublicKey1~0 := 0;~__ste_Client_Keyring2_PublicKey2~0 := 0;~__ste_client_forwardReceiver0~0 := 0;~__ste_client_forwardReceiver1~0 := 0;~__ste_client_forwardReceiver2~0 := 0;~__ste_client_forwardReceiver3~0 := 0;~__ste_client_idCounter0~0 := 0;~__ste_client_idCounter1~0 := 0;~__ste_client_idCounter2~0 := 0;~__ste_Email_counter~0 := 0;~__ste_email_id0~0 := 0;~__ste_email_id1~0 := 0;~__ste_email_from0~0 := 0;~__ste_email_from1~0 := 0;~__ste_email_to0~0 := 0;~__ste_email_to1~0 := 0;~__ste_email_subject0~0.base, ~__ste_email_subject0~0.offset := 0, 0;~__ste_email_subject1~0.base, ~__ste_email_subject1~0.offset := 0, 0;~__ste_email_body0~0.base, ~__ste_email_body0~0.offset := 0, 0;~__ste_email_body1~0.base, ~__ste_email_body1~0.offset := 0, 0;~__ste_email_isEncrypted0~0 := 0;~__ste_email_isEncrypted1~0 := 0;~__ste_email_encryptionKey0~0 := 0;~__ste_email_encryptionKey1~0 := 0;~__ste_email_isSigned0~0 := 0;~__ste_email_isSigned1~0 := 0;~__ste_email_signKey0~0 := 0;~__ste_email_signKey1~0 := 0;~__ste_email_isSignatureVerified0~0 := 0;~__ste_email_isSignatureVerified1~0 := 0; {21999#true} is VALID [2022-02-20 18:00:30,943 INFO L290 TraceCheckUtils]: 1: Hoare triple {21999#true} assume { :end_inline_ULTIMATE.init } true;assume { :begin_inline_main } true;havoc main_#res#1;havoc main_#t~ret35#1, main_~retValue_acc~3#1, main_~tmp~4#1;havoc main_~retValue_acc~3#1;havoc main_~tmp~4#1;assume { :begin_inline_select_helpers } true; {21999#true} is VALID [2022-02-20 18:00:30,943 INFO L290 TraceCheckUtils]: 2: Hoare triple {21999#true} assume { :end_inline_select_helpers } true;assume { :begin_inline_select_features } true; {21999#true} is VALID [2022-02-20 18:00:30,943 INFO L290 TraceCheckUtils]: 3: Hoare triple {21999#true} assume { :end_inline_select_features } true;assume { :begin_inline_valid_product } true;havoc valid_product_#res#1;havoc valid_product_~retValue_acc~5#1;havoc valid_product_~retValue_acc~5#1;valid_product_~retValue_acc~5#1 := 1;valid_product_#res#1 := valid_product_~retValue_acc~5#1; {21999#true} is VALID [2022-02-20 18:00:30,943 INFO L290 TraceCheckUtils]: 4: Hoare triple {21999#true} main_#t~ret35#1 := valid_product_#res#1;assume { :end_inline_valid_product } true;assume -2147483648 <= main_#t~ret35#1 && main_#t~ret35#1 <= 2147483647;main_~tmp~4#1 := main_#t~ret35#1;havoc main_#t~ret35#1; {21999#true} is VALID [2022-02-20 18:00:30,943 INFO L290 TraceCheckUtils]: 5: Hoare triple {21999#true} assume 0 != main_~tmp~4#1;assume { :begin_inline_setup } true;havoc setup_#t~nondet32#1, setup_#t~nondet33#1, setup_#t~nondet34#1, setup_~__cil_tmp1~0#1.base, setup_~__cil_tmp1~0#1.offset, setup_~__cil_tmp2~0#1.base, setup_~__cil_tmp2~0#1.offset, setup_~__cil_tmp3~0#1.base, setup_~__cil_tmp3~0#1.offset;havoc setup_~__cil_tmp1~0#1.base, setup_~__cil_tmp1~0#1.offset;havoc setup_~__cil_tmp2~0#1.base, setup_~__cil_tmp2~0#1.offset;havoc setup_~__cil_tmp3~0#1.base, setup_~__cil_tmp3~0#1.offset;~bob~0 := 1;assume { :begin_inline_setup_bob } true;setup_bob_#in~bob___0#1 := ~bob~0;havoc setup_bob_~bob___0#1;setup_bob_~bob___0#1 := setup_bob_#in~bob___0#1;assume { :begin_inline_setup_bob__wrappee__Base } true;setup_bob__wrappee__Base_#in~bob___0#1 := setup_bob_~bob___0#1;havoc setup_bob__wrappee__Base_~bob___0#1;setup_bob__wrappee__Base_~bob___0#1 := setup_bob__wrappee__Base_#in~bob___0#1; {21999#true} is VALID [2022-02-20 18:00:30,944 INFO L272 TraceCheckUtils]: 6: Hoare triple {21999#true} call setClientId(setup_bob__wrappee__Base_~bob___0#1, setup_bob__wrappee__Base_~bob___0#1); {22064#(and (= |old(~__ste_client_idCounter0~0)| ~__ste_client_idCounter0~0) (= |old(~__ste_client_idCounter1~0)| ~__ste_client_idCounter1~0) (= |old(~__ste_client_idCounter2~0)| ~__ste_client_idCounter2~0))} is VALID [2022-02-20 18:00:30,944 INFO L290 TraceCheckUtils]: 7: Hoare triple {22064#(and (= |old(~__ste_client_idCounter0~0)| ~__ste_client_idCounter0~0) (= |old(~__ste_client_idCounter1~0)| ~__ste_client_idCounter1~0) (= |old(~__ste_client_idCounter2~0)| ~__ste_client_idCounter2~0))} ~handle := #in~handle;~value := #in~value; {21999#true} is VALID [2022-02-20 18:00:30,944 INFO L290 TraceCheckUtils]: 8: Hoare triple {21999#true} assume 1 == ~handle;~__ste_client_idCounter0~0 := ~value; {21999#true} is VALID [2022-02-20 18:00:30,944 INFO L290 TraceCheckUtils]: 9: Hoare triple {21999#true} assume true; {21999#true} is VALID [2022-02-20 18:00:30,944 INFO L284 TraceCheckUtils]: 10: Hoare quadruple {21999#true} {21999#true} #1134#return; {21999#true} is VALID [2022-02-20 18:00:30,944 INFO L290 TraceCheckUtils]: 11: Hoare triple {21999#true} assume { :end_inline_setup_bob__wrappee__Base } true; {21999#true} is VALID [2022-02-20 18:00:30,945 INFO L272 TraceCheckUtils]: 12: Hoare triple {21999#true} call setClientPrivateKey(setup_bob_~bob___0#1, 123); {22065#(and (= ~__ste_client_privateKey0~0 |old(~__ste_client_privateKey0~0)|) (= ~__ste_client_privateKey2~0 |old(~__ste_client_privateKey2~0)|) (= ~__ste_client_privateKey1~0 |old(~__ste_client_privateKey1~0)|))} is VALID [2022-02-20 18:00:30,945 INFO L290 TraceCheckUtils]: 13: Hoare triple {22065#(and (= ~__ste_client_privateKey0~0 |old(~__ste_client_privateKey0~0)|) (= ~__ste_client_privateKey2~0 |old(~__ste_client_privateKey2~0)|) (= ~__ste_client_privateKey1~0 |old(~__ste_client_privateKey1~0)|))} ~handle := #in~handle;~value := #in~value; {21999#true} is VALID [2022-02-20 18:00:30,945 INFO L290 TraceCheckUtils]: 14: Hoare triple {21999#true} assume 1 == ~handle;~__ste_client_privateKey0~0 := ~value; {21999#true} is VALID [2022-02-20 18:00:30,945 INFO L290 TraceCheckUtils]: 15: Hoare triple {21999#true} assume true; {21999#true} is VALID [2022-02-20 18:00:30,945 INFO L284 TraceCheckUtils]: 16: Hoare quadruple {21999#true} {21999#true} #1136#return; {21999#true} is VALID [2022-02-20 18:00:30,945 INFO L290 TraceCheckUtils]: 17: Hoare triple {21999#true} assume { :end_inline_setup_bob } true;setup_~__cil_tmp1~0#1.base, setup_~__cil_tmp1~0#1.offset := 18, 0;havoc setup_#t~nondet32#1;~rjh~0 := 2;assume { :begin_inline_setup_rjh } true;setup_rjh_#in~rjh___0#1 := ~rjh~0;havoc setup_rjh_~rjh___0#1;setup_rjh_~rjh___0#1 := setup_rjh_#in~rjh___0#1;assume { :begin_inline_setup_rjh__wrappee__Base } true;setup_rjh__wrappee__Base_#in~rjh___0#1 := setup_rjh_~rjh___0#1;havoc setup_rjh__wrappee__Base_~rjh___0#1;setup_rjh__wrappee__Base_~rjh___0#1 := setup_rjh__wrappee__Base_#in~rjh___0#1; {21999#true} is VALID [2022-02-20 18:00:30,946 INFO L272 TraceCheckUtils]: 18: Hoare triple {21999#true} call setClientId(setup_rjh__wrappee__Base_~rjh___0#1, setup_rjh__wrappee__Base_~rjh___0#1); {22064#(and (= |old(~__ste_client_idCounter0~0)| ~__ste_client_idCounter0~0) (= |old(~__ste_client_idCounter1~0)| ~__ste_client_idCounter1~0) (= |old(~__ste_client_idCounter2~0)| ~__ste_client_idCounter2~0))} is VALID [2022-02-20 18:00:30,946 INFO L290 TraceCheckUtils]: 19: Hoare triple {22064#(and (= |old(~__ste_client_idCounter0~0)| ~__ste_client_idCounter0~0) (= |old(~__ste_client_idCounter1~0)| ~__ste_client_idCounter1~0) (= |old(~__ste_client_idCounter2~0)| ~__ste_client_idCounter2~0))} ~handle := #in~handle;~value := #in~value; {21999#true} is VALID [2022-02-20 18:00:30,946 INFO L290 TraceCheckUtils]: 20: Hoare triple {21999#true} assume !(1 == ~handle); {21999#true} is VALID [2022-02-20 18:00:30,946 INFO L290 TraceCheckUtils]: 21: Hoare triple {21999#true} assume 2 == ~handle;~__ste_client_idCounter1~0 := ~value; {21999#true} is VALID [2022-02-20 18:00:30,946 INFO L290 TraceCheckUtils]: 22: Hoare triple {21999#true} assume true; {21999#true} is VALID [2022-02-20 18:00:30,946 INFO L284 TraceCheckUtils]: 23: Hoare quadruple {21999#true} {21999#true} #1138#return; {21999#true} is VALID [2022-02-20 18:00:30,946 INFO L290 TraceCheckUtils]: 24: Hoare triple {21999#true} assume { :end_inline_setup_rjh__wrappee__Base } true; {21999#true} is VALID [2022-02-20 18:00:30,947 INFO L272 TraceCheckUtils]: 25: Hoare triple {21999#true} call setClientPrivateKey(setup_rjh_~rjh___0#1, 456); {22065#(and (= ~__ste_client_privateKey0~0 |old(~__ste_client_privateKey0~0)|) (= ~__ste_client_privateKey2~0 |old(~__ste_client_privateKey2~0)|) (= ~__ste_client_privateKey1~0 |old(~__ste_client_privateKey1~0)|))} is VALID [2022-02-20 18:00:30,947 INFO L290 TraceCheckUtils]: 26: Hoare triple {22065#(and (= ~__ste_client_privateKey0~0 |old(~__ste_client_privateKey0~0)|) (= ~__ste_client_privateKey2~0 |old(~__ste_client_privateKey2~0)|) (= ~__ste_client_privateKey1~0 |old(~__ste_client_privateKey1~0)|))} ~handle := #in~handle;~value := #in~value; {21999#true} is VALID [2022-02-20 18:00:30,947 INFO L290 TraceCheckUtils]: 27: Hoare triple {21999#true} assume !(1 == ~handle); {21999#true} is VALID [2022-02-20 18:00:30,947 INFO L290 TraceCheckUtils]: 28: Hoare triple {21999#true} assume 2 == ~handle;~__ste_client_privateKey1~0 := ~value; {21999#true} is VALID [2022-02-20 18:00:30,947 INFO L290 TraceCheckUtils]: 29: Hoare triple {21999#true} assume true; {21999#true} is VALID [2022-02-20 18:00:30,948 INFO L284 TraceCheckUtils]: 30: Hoare quadruple {21999#true} {21999#true} #1140#return; {21999#true} is VALID [2022-02-20 18:00:30,948 INFO L290 TraceCheckUtils]: 31: Hoare triple {21999#true} assume { :end_inline_setup_rjh } true;setup_~__cil_tmp2~0#1.base, setup_~__cil_tmp2~0#1.offset := 19, 0;havoc setup_#t~nondet33#1;~chuck~0 := 3;assume { :begin_inline_setup_chuck } true;setup_chuck_#in~chuck___0#1 := ~chuck~0;havoc setup_chuck_~chuck___0#1;setup_chuck_~chuck___0#1 := setup_chuck_#in~chuck___0#1;assume { :begin_inline_setup_chuck__wrappee__Base } true;setup_chuck__wrappee__Base_#in~chuck___0#1 := setup_chuck_~chuck___0#1;havoc setup_chuck__wrappee__Base_~chuck___0#1;setup_chuck__wrappee__Base_~chuck___0#1 := setup_chuck__wrappee__Base_#in~chuck___0#1; {22019#(= |ULTIMATE.start_setup_chuck_~chuck___0#1| |ULTIMATE.start_setup_chuck__wrappee__Base_~chuck___0#1|)} is VALID [2022-02-20 18:00:30,949 INFO L272 TraceCheckUtils]: 32: Hoare triple {22019#(= |ULTIMATE.start_setup_chuck_~chuck___0#1| |ULTIMATE.start_setup_chuck__wrappee__Base_~chuck___0#1|)} call setClientId(setup_chuck__wrappee__Base_~chuck___0#1, setup_chuck__wrappee__Base_~chuck___0#1); {22064#(and (= |old(~__ste_client_idCounter0~0)| ~__ste_client_idCounter0~0) (= |old(~__ste_client_idCounter1~0)| ~__ste_client_idCounter1~0) (= |old(~__ste_client_idCounter2~0)| ~__ste_client_idCounter2~0))} is VALID [2022-02-20 18:00:30,949 INFO L290 TraceCheckUtils]: 33: Hoare triple {22064#(and (= |old(~__ste_client_idCounter0~0)| ~__ste_client_idCounter0~0) (= |old(~__ste_client_idCounter1~0)| ~__ste_client_idCounter1~0) (= |old(~__ste_client_idCounter2~0)| ~__ste_client_idCounter2~0))} ~handle := #in~handle;~value := #in~value; {22066#(= setClientId_~handle |setClientId_#in~handle|)} is VALID [2022-02-20 18:00:30,949 INFO L290 TraceCheckUtils]: 34: Hoare triple {22066#(= setClientId_~handle |setClientId_#in~handle|)} assume !(1 == ~handle); {22066#(= setClientId_~handle |setClientId_#in~handle|)} is VALID [2022-02-20 18:00:30,949 INFO L290 TraceCheckUtils]: 35: Hoare triple {22066#(= setClientId_~handle |setClientId_#in~handle|)} assume !(2 == ~handle); {22066#(= setClientId_~handle |setClientId_#in~handle|)} is VALID [2022-02-20 18:00:30,950 INFO L290 TraceCheckUtils]: 36: Hoare triple {22066#(= setClientId_~handle |setClientId_#in~handle|)} assume 3 == ~handle;~__ste_client_idCounter2~0 := ~value; {22067#(= 3 |setClientId_#in~handle|)} is VALID [2022-02-20 18:00:30,950 INFO L290 TraceCheckUtils]: 37: Hoare triple {22067#(= 3 |setClientId_#in~handle|)} assume true; {22067#(= 3 |setClientId_#in~handle|)} is VALID [2022-02-20 18:00:30,950 INFO L284 TraceCheckUtils]: 38: Hoare quadruple {22067#(= 3 |setClientId_#in~handle|)} {22019#(= |ULTIMATE.start_setup_chuck_~chuck___0#1| |ULTIMATE.start_setup_chuck__wrappee__Base_~chuck___0#1|)} #1142#return; {22026#(not (= |ULTIMATE.start_setup_chuck_~chuck___0#1| 1))} is VALID [2022-02-20 18:00:30,951 INFO L290 TraceCheckUtils]: 39: Hoare triple {22026#(not (= |ULTIMATE.start_setup_chuck_~chuck___0#1| 1))} assume { :end_inline_setup_chuck__wrappee__Base } true; {22026#(not (= |ULTIMATE.start_setup_chuck_~chuck___0#1| 1))} is VALID [2022-02-20 18:00:30,951 INFO L272 TraceCheckUtils]: 40: Hoare triple {22026#(not (= |ULTIMATE.start_setup_chuck_~chuck___0#1| 1))} call setClientPrivateKey(setup_chuck_~chuck___0#1, 789); {22065#(and (= ~__ste_client_privateKey0~0 |old(~__ste_client_privateKey0~0)|) (= ~__ste_client_privateKey2~0 |old(~__ste_client_privateKey2~0)|) (= ~__ste_client_privateKey1~0 |old(~__ste_client_privateKey1~0)|))} is VALID [2022-02-20 18:00:30,952 INFO L290 TraceCheckUtils]: 41: Hoare triple {22065#(and (= ~__ste_client_privateKey0~0 |old(~__ste_client_privateKey0~0)|) (= ~__ste_client_privateKey2~0 |old(~__ste_client_privateKey2~0)|) (= ~__ste_client_privateKey1~0 |old(~__ste_client_privateKey1~0)|))} ~handle := #in~handle;~value := #in~value; {22068#(= setClientPrivateKey_~handle |setClientPrivateKey_#in~handle|)} is VALID [2022-02-20 18:00:30,952 INFO L290 TraceCheckUtils]: 42: Hoare triple {22068#(= setClientPrivateKey_~handle |setClientPrivateKey_#in~handle|)} assume 1 == ~handle;~__ste_client_privateKey0~0 := ~value; {22069#(= |setClientPrivateKey_#in~handle| 1)} is VALID [2022-02-20 18:00:30,952 INFO L290 TraceCheckUtils]: 43: Hoare triple {22069#(= |setClientPrivateKey_#in~handle| 1)} assume true; {22069#(= |setClientPrivateKey_#in~handle| 1)} is VALID [2022-02-20 18:00:30,953 INFO L284 TraceCheckUtils]: 44: Hoare quadruple {22069#(= |setClientPrivateKey_#in~handle| 1)} {22026#(not (= |ULTIMATE.start_setup_chuck_~chuck___0#1| 1))} #1144#return; {22000#false} is VALID [2022-02-20 18:00:30,953 INFO L290 TraceCheckUtils]: 45: Hoare triple {22000#false} assume { :end_inline_setup_chuck } true;setup_~__cil_tmp3~0#1.base, setup_~__cil_tmp3~0#1.offset := 20, 0;havoc setup_#t~nondet34#1; {22000#false} is VALID [2022-02-20 18:00:30,953 INFO L290 TraceCheckUtils]: 46: Hoare triple {22000#false} assume { :end_inline_setup } true;assume { :begin_inline_test } true;havoc test_#t~nondet47#1, test_#t~nondet48#1, test_#t~nondet49#1, test_#t~nondet50#1, test_#t~nondet51#1, test_#t~nondet52#1, test_#t~nondet53#1, test_#t~nondet54#1, test_#t~nondet55#1, test_#t~nondet56#1, test_#t~nondet57#1, test_~op1~0#1, test_~op2~0#1, test_~op3~0#1, test_~op4~0#1, test_~op5~0#1, test_~op6~0#1, test_~op7~0#1, test_~op8~0#1, test_~op9~0#1, test_~op10~0#1, test_~op11~0#1, test_~splverifierCounter~0#1, test_~tmp~6#1, test_~tmp___0~2#1, test_~tmp___1~1#1, test_~tmp___2~0#1, test_~tmp___3~0#1, test_~tmp___4~0#1, test_~tmp___5~0#1, test_~tmp___6~0#1, test_~tmp___7~0#1, test_~tmp___8~0#1, test_~tmp___9~0#1;havoc test_~op1~0#1;havoc test_~op2~0#1;havoc test_~op3~0#1;havoc test_~op4~0#1;havoc test_~op5~0#1;havoc test_~op6~0#1;havoc test_~op7~0#1;havoc test_~op8~0#1;havoc test_~op9~0#1;havoc test_~op10~0#1;havoc test_~op11~0#1;havoc test_~splverifierCounter~0#1;havoc test_~tmp~6#1;havoc test_~tmp___0~2#1;havoc test_~tmp___1~1#1;havoc test_~tmp___2~0#1;havoc test_~tmp___3~0#1;havoc test_~tmp___4~0#1;havoc test_~tmp___5~0#1;havoc test_~tmp___6~0#1;havoc test_~tmp___7~0#1;havoc test_~tmp___8~0#1;havoc test_~tmp___9~0#1;test_~op1~0#1 := 0;test_~op2~0#1 := 0;test_~op3~0#1 := 0;test_~op4~0#1 := 0;test_~op5~0#1 := 0;test_~op6~0#1 := 0;test_~op7~0#1 := 0;test_~op8~0#1 := 0;test_~op9~0#1 := 0;test_~op10~0#1 := 0;test_~op11~0#1 := 0;test_~splverifierCounter~0#1 := 0; {22000#false} is VALID [2022-02-20 18:00:30,953 INFO L290 TraceCheckUtils]: 47: Hoare triple {22000#false} assume !false; {22000#false} is VALID [2022-02-20 18:00:30,953 INFO L290 TraceCheckUtils]: 48: Hoare triple {22000#false} assume test_~splverifierCounter~0#1 < 4; {22000#false} is VALID [2022-02-20 18:00:30,953 INFO L290 TraceCheckUtils]: 49: Hoare triple {22000#false} test_~splverifierCounter~0#1 := 1 + test_~splverifierCounter~0#1; {22000#false} is VALID [2022-02-20 18:00:30,953 INFO L290 TraceCheckUtils]: 50: Hoare triple {22000#false} assume 0 == test_~op1~0#1;assume -2147483648 <= test_#t~nondet47#1 && test_#t~nondet47#1 <= 2147483647;test_~tmp___9~0#1 := test_#t~nondet47#1;havoc test_#t~nondet47#1; {22000#false} is VALID [2022-02-20 18:00:30,953 INFO L290 TraceCheckUtils]: 51: Hoare triple {22000#false} assume !(0 != test_~tmp___9~0#1); {22000#false} is VALID [2022-02-20 18:00:30,954 INFO L290 TraceCheckUtils]: 52: Hoare triple {22000#false} assume 0 == test_~op2~0#1;assume -2147483648 <= test_#t~nondet48#1 && test_#t~nondet48#1 <= 2147483647;test_~tmp___8~0#1 := test_#t~nondet48#1;havoc test_#t~nondet48#1; {22000#false} is VALID [2022-02-20 18:00:30,954 INFO L290 TraceCheckUtils]: 53: Hoare triple {22000#false} assume 0 != test_~tmp___8~0#1;assume { :begin_inline_rjhSetAutoRespond } true;assume { :begin_inline_setClientAutoResponse } true;setClientAutoResponse_#in~handle#1, setClientAutoResponse_#in~value#1 := ~rjh~0, 1;havoc setClientAutoResponse_~handle#1, setClientAutoResponse_~value#1;setClientAutoResponse_~handle#1 := setClientAutoResponse_#in~handle#1;setClientAutoResponse_~value#1 := setClientAutoResponse_#in~value#1; {22000#false} is VALID [2022-02-20 18:00:30,954 INFO L290 TraceCheckUtils]: 54: Hoare triple {22000#false} assume 1 == setClientAutoResponse_~handle#1;~__ste_client_autoResponse0~0 := setClientAutoResponse_~value#1; {22000#false} is VALID [2022-02-20 18:00:30,954 INFO L290 TraceCheckUtils]: 55: Hoare triple {22000#false} assume { :end_inline_setClientAutoResponse } true; {22000#false} is VALID [2022-02-20 18:00:30,954 INFO L290 TraceCheckUtils]: 56: Hoare triple {22000#false} assume { :end_inline_rjhSetAutoRespond } true;test_~op2~0#1 := 1; {22000#false} is VALID [2022-02-20 18:00:30,954 INFO L290 TraceCheckUtils]: 57: Hoare triple {22000#false} assume !false; {22000#false} is VALID [2022-02-20 18:00:30,954 INFO L290 TraceCheckUtils]: 58: Hoare triple {22000#false} assume !(test_~splverifierCounter~0#1 < 4); {22000#false} is VALID [2022-02-20 18:00:30,954 INFO L290 TraceCheckUtils]: 59: Hoare triple {22000#false} assume { :begin_inline_bobToRjh } true;havoc bobToRjh_#t~ret27#1, bobToRjh_#t~ret28#1, bobToRjh_#t~ret29#1, bobToRjh_#t~ret30#1, bobToRjh_~tmp~3#1, bobToRjh_~tmp___0~0#1, bobToRjh_~tmp___1~0#1;havoc bobToRjh_~tmp~3#1;havoc bobToRjh_~tmp___0~0#1;havoc bobToRjh_~tmp___1~0#1;call bobToRjh_#t~ret27#1 := puts(16, 0);assume -2147483648 <= bobToRjh_#t~ret27#1 && bobToRjh_#t~ret27#1 <= 2147483647;havoc bobToRjh_#t~ret27#1; {22000#false} is VALID [2022-02-20 18:00:30,954 INFO L272 TraceCheckUtils]: 60: Hoare triple {22000#false} call sendEmail(~bob~0, ~rjh~0); {22000#false} is VALID [2022-02-20 18:00:30,954 INFO L290 TraceCheckUtils]: 61: Hoare triple {22000#false} ~sender#1 := #in~sender#1;~receiver#1 := #in~receiver#1;havoc ~email~0#1;havoc ~tmp~14#1;assume { :begin_inline_createEmail } true;createEmail_#in~from#1, createEmail_#in~to#1 := 0, ~receiver#1;havoc createEmail_#res#1;havoc createEmail_~from#1, createEmail_~to#1, createEmail_~retValue_acc~31#1, createEmail_~msg~0#1;createEmail_~from#1 := createEmail_#in~from#1;createEmail_~to#1 := createEmail_#in~to#1;havoc createEmail_~retValue_acc~31#1;havoc createEmail_~msg~0#1;createEmail_~msg~0#1 := 1; {22000#false} is VALID [2022-02-20 18:00:30,955 INFO L272 TraceCheckUtils]: 62: Hoare triple {22000#false} call setEmailFrom(createEmail_~msg~0#1, createEmail_~from#1); {22070#(and (= |old(~__ste_email_from0~0)| ~__ste_email_from0~0) (= |old(~__ste_email_from1~0)| ~__ste_email_from1~0))} is VALID [2022-02-20 18:00:30,955 INFO L290 TraceCheckUtils]: 63: Hoare triple {22070#(and (= |old(~__ste_email_from0~0)| ~__ste_email_from0~0) (= |old(~__ste_email_from1~0)| ~__ste_email_from1~0))} ~handle := #in~handle;~value := #in~value; {21999#true} is VALID [2022-02-20 18:00:30,955 INFO L290 TraceCheckUtils]: 64: Hoare triple {21999#true} assume 1 == ~handle;~__ste_email_from0~0 := ~value; {21999#true} is VALID [2022-02-20 18:00:30,955 INFO L290 TraceCheckUtils]: 65: Hoare triple {21999#true} assume true; {21999#true} is VALID [2022-02-20 18:00:30,955 INFO L284 TraceCheckUtils]: 66: Hoare quadruple {21999#true} {22000#false} #1120#return; {22000#false} is VALID [2022-02-20 18:00:30,955 INFO L272 TraceCheckUtils]: 67: Hoare triple {22000#false} call setEmailTo(createEmail_~msg~0#1, createEmail_~to#1); {22071#(and (= ~__ste_email_to0~0 |old(~__ste_email_to0~0)|) (= ~__ste_email_to1~0 |old(~__ste_email_to1~0)|))} is VALID [2022-02-20 18:00:30,955 INFO L290 TraceCheckUtils]: 68: Hoare triple {22071#(and (= ~__ste_email_to0~0 |old(~__ste_email_to0~0)|) (= ~__ste_email_to1~0 |old(~__ste_email_to1~0)|))} ~handle := #in~handle;~value := #in~value; {21999#true} is VALID [2022-02-20 18:00:30,955 INFO L290 TraceCheckUtils]: 69: Hoare triple {21999#true} assume 1 == ~handle;~__ste_email_to0~0 := ~value; {21999#true} is VALID [2022-02-20 18:00:30,956 INFO L290 TraceCheckUtils]: 70: Hoare triple {21999#true} assume true; {21999#true} is VALID [2022-02-20 18:00:30,956 INFO L284 TraceCheckUtils]: 71: Hoare quadruple {21999#true} {22000#false} #1122#return; {22000#false} is VALID [2022-02-20 18:00:30,956 INFO L290 TraceCheckUtils]: 72: Hoare triple {22000#false} createEmail_~retValue_acc~31#1 := createEmail_~msg~0#1;createEmail_#res#1 := createEmail_~retValue_acc~31#1; {22000#false} is VALID [2022-02-20 18:00:30,956 INFO L290 TraceCheckUtils]: 73: Hoare triple {22000#false} #t~ret72#1 := createEmail_#res#1;assume { :end_inline_createEmail } true;assume -2147483648 <= #t~ret72#1 && #t~ret72#1 <= 2147483647;~tmp~14#1 := #t~ret72#1;havoc #t~ret72#1;~email~0#1 := ~tmp~14#1; {22000#false} is VALID [2022-02-20 18:00:30,956 INFO L272 TraceCheckUtils]: 74: Hoare triple {22000#false} call outgoing(~sender#1, ~email~0#1); {22000#false} is VALID [2022-02-20 18:00:30,956 INFO L290 TraceCheckUtils]: 75: Hoare triple {22000#false} ~client#1 := #in~client#1;~msg#1 := #in~msg#1;assume { :begin_inline_sign } true;sign_#in~client#1, sign_#in~msg#1 := ~client#1, ~msg#1;havoc sign_#t~ret76#1, sign_~client#1, sign_~msg#1, sign_~privkey~1#1, sign_~tmp~16#1;sign_~client#1 := sign_#in~client#1;sign_~msg#1 := sign_#in~msg#1;havoc sign_~privkey~1#1;havoc sign_~tmp~16#1; {22000#false} is VALID [2022-02-20 18:00:30,956 INFO L272 TraceCheckUtils]: 76: Hoare triple {22000#false} call sign_#t~ret76#1 := getClientPrivateKey(sign_~client#1); {21999#true} is VALID [2022-02-20 18:00:30,956 INFO L290 TraceCheckUtils]: 77: Hoare triple {21999#true} ~handle := #in~handle;havoc ~retValue_acc~20; {21999#true} is VALID [2022-02-20 18:00:30,956 INFO L290 TraceCheckUtils]: 78: Hoare triple {21999#true} assume 1 == ~handle;~retValue_acc~20 := ~__ste_client_privateKey0~0;#res := ~retValue_acc~20; {21999#true} is VALID [2022-02-20 18:00:30,957 INFO L290 TraceCheckUtils]: 79: Hoare triple {21999#true} assume true; {21999#true} is VALID [2022-02-20 18:00:30,957 INFO L284 TraceCheckUtils]: 80: Hoare quadruple {21999#true} {22000#false} #1054#return; {22000#false} is VALID [2022-02-20 18:00:30,957 INFO L290 TraceCheckUtils]: 81: Hoare triple {22000#false} assume -2147483648 <= sign_#t~ret76#1 && sign_#t~ret76#1 <= 2147483647;sign_~tmp~16#1 := sign_#t~ret76#1;havoc sign_#t~ret76#1;sign_~privkey~1#1 := sign_~tmp~16#1; {22000#false} is VALID [2022-02-20 18:00:30,957 INFO L290 TraceCheckUtils]: 82: Hoare triple {22000#false} assume 0 == sign_~privkey~1#1; {22000#false} is VALID [2022-02-20 18:00:30,957 INFO L290 TraceCheckUtils]: 83: Hoare triple {22000#false} assume { :end_inline_sign } true;assume { :begin_inline_outgoing__wrappee__AutoResponder } true;outgoing__wrappee__AutoResponder_#in~client#1, outgoing__wrappee__AutoResponder_#in~msg#1 := ~client#1, ~msg#1;havoc outgoing__wrappee__AutoResponder_#t~ret62#1, outgoing__wrappee__AutoResponder_#t~ret63#1, outgoing__wrappee__AutoResponder_~client#1, outgoing__wrappee__AutoResponder_~msg#1, outgoing__wrappee__AutoResponder_~receiver~0#1, outgoing__wrappee__AutoResponder_~tmp~9#1, outgoing__wrappee__AutoResponder_~pubkey~0#1, outgoing__wrappee__AutoResponder_~tmp___0~3#1;outgoing__wrappee__AutoResponder_~client#1 := outgoing__wrappee__AutoResponder_#in~client#1;outgoing__wrappee__AutoResponder_~msg#1 := outgoing__wrappee__AutoResponder_#in~msg#1;havoc outgoing__wrappee__AutoResponder_~receiver~0#1;havoc outgoing__wrappee__AutoResponder_~tmp~9#1;havoc outgoing__wrappee__AutoResponder_~pubkey~0#1;havoc outgoing__wrappee__AutoResponder_~tmp___0~3#1; {22000#false} is VALID [2022-02-20 18:00:30,957 INFO L272 TraceCheckUtils]: 84: Hoare triple {22000#false} call outgoing__wrappee__AutoResponder_#t~ret62#1 := getEmailTo(outgoing__wrappee__AutoResponder_~msg#1); {21999#true} is VALID [2022-02-20 18:00:30,957 INFO L290 TraceCheckUtils]: 85: Hoare triple {21999#true} ~handle := #in~handle;havoc ~retValue_acc~36; {21999#true} is VALID [2022-02-20 18:00:30,957 INFO L290 TraceCheckUtils]: 86: Hoare triple {21999#true} assume 1 == ~handle;~retValue_acc~36 := ~__ste_email_to0~0;#res := ~retValue_acc~36; {21999#true} is VALID [2022-02-20 18:00:30,958 INFO L290 TraceCheckUtils]: 87: Hoare triple {21999#true} assume true; {21999#true} is VALID [2022-02-20 18:00:30,958 INFO L284 TraceCheckUtils]: 88: Hoare quadruple {21999#true} {22000#false} #1056#return; {22000#false} is VALID [2022-02-20 18:00:30,958 INFO L290 TraceCheckUtils]: 89: Hoare triple {22000#false} assume -2147483648 <= outgoing__wrappee__AutoResponder_#t~ret62#1 && outgoing__wrappee__AutoResponder_#t~ret62#1 <= 2147483647;outgoing__wrappee__AutoResponder_~tmp~9#1 := outgoing__wrappee__AutoResponder_#t~ret62#1;havoc outgoing__wrappee__AutoResponder_#t~ret62#1;outgoing__wrappee__AutoResponder_~receiver~0#1 := outgoing__wrappee__AutoResponder_~tmp~9#1; {22000#false} is VALID [2022-02-20 18:00:30,958 INFO L272 TraceCheckUtils]: 90: Hoare triple {22000#false} call outgoing__wrappee__AutoResponder_#t~ret63#1 := findPublicKey(outgoing__wrappee__AutoResponder_~client#1, outgoing__wrappee__AutoResponder_~receiver~0#1); {21999#true} is VALID [2022-02-20 18:00:30,958 INFO L290 TraceCheckUtils]: 91: Hoare triple {21999#true} ~handle := #in~handle;~userid := #in~userid;havoc ~retValue_acc~25; {21999#true} is VALID [2022-02-20 18:00:30,958 INFO L290 TraceCheckUtils]: 92: Hoare triple {21999#true} assume 1 == ~handle; {21999#true} is VALID [2022-02-20 18:00:30,958 INFO L290 TraceCheckUtils]: 93: Hoare triple {21999#true} assume ~userid == ~__ste_Client_Keyring0_User0~0;~retValue_acc~25 := ~__ste_Client_Keyring0_PublicKey0~0;#res := ~retValue_acc~25; {21999#true} is VALID [2022-02-20 18:00:30,958 INFO L290 TraceCheckUtils]: 94: Hoare triple {21999#true} assume true; {21999#true} is VALID [2022-02-20 18:00:30,958 INFO L284 TraceCheckUtils]: 95: Hoare quadruple {21999#true} {22000#false} #1058#return; {22000#false} is VALID [2022-02-20 18:00:30,958 INFO L290 TraceCheckUtils]: 96: Hoare triple {22000#false} assume -2147483648 <= outgoing__wrappee__AutoResponder_#t~ret63#1 && outgoing__wrappee__AutoResponder_#t~ret63#1 <= 2147483647;outgoing__wrappee__AutoResponder_~tmp___0~3#1 := outgoing__wrappee__AutoResponder_#t~ret63#1;havoc outgoing__wrappee__AutoResponder_#t~ret63#1;outgoing__wrappee__AutoResponder_~pubkey~0#1 := outgoing__wrappee__AutoResponder_~tmp___0~3#1; {22000#false} is VALID [2022-02-20 18:00:30,959 INFO L290 TraceCheckUtils]: 97: Hoare triple {22000#false} assume !(0 != outgoing__wrappee__AutoResponder_~pubkey~0#1); {22000#false} is VALID [2022-02-20 18:00:30,959 INFO L290 TraceCheckUtils]: 98: Hoare triple {22000#false} assume { :begin_inline_outgoing__wrappee__Keys } true;outgoing__wrappee__Keys_#in~client#1, outgoing__wrappee__Keys_#in~msg#1 := outgoing__wrappee__AutoResponder_~client#1, outgoing__wrappee__AutoResponder_~msg#1;havoc outgoing__wrappee__Keys_#t~ret61#1, outgoing__wrappee__Keys_~client#1, outgoing__wrappee__Keys_~msg#1, outgoing__wrappee__Keys_~tmp~8#1;outgoing__wrappee__Keys_~client#1 := outgoing__wrappee__Keys_#in~client#1;outgoing__wrappee__Keys_~msg#1 := outgoing__wrappee__Keys_#in~msg#1;havoc outgoing__wrappee__Keys_~tmp~8#1;assume { :begin_inline_getClientId } true;getClientId_#in~handle#1 := outgoing__wrappee__Keys_~client#1;havoc getClientId_#res#1;havoc getClientId_~handle#1, getClientId_~retValue_acc~27#1;getClientId_~handle#1 := getClientId_#in~handle#1;havoc getClientId_~retValue_acc~27#1; {22000#false} is VALID [2022-02-20 18:00:30,959 INFO L290 TraceCheckUtils]: 99: Hoare triple {22000#false} assume 1 == getClientId_~handle#1;getClientId_~retValue_acc~27#1 := ~__ste_client_idCounter0~0;getClientId_#res#1 := getClientId_~retValue_acc~27#1; {22000#false} is VALID [2022-02-20 18:00:30,959 INFO L290 TraceCheckUtils]: 100: Hoare triple {22000#false} outgoing__wrappee__Keys_#t~ret61#1 := getClientId_#res#1;assume { :end_inline_getClientId } true;assume -2147483648 <= outgoing__wrappee__Keys_#t~ret61#1 && outgoing__wrappee__Keys_#t~ret61#1 <= 2147483647;outgoing__wrappee__Keys_~tmp~8#1 := outgoing__wrappee__Keys_#t~ret61#1;havoc outgoing__wrappee__Keys_#t~ret61#1; {22000#false} is VALID [2022-02-20 18:00:30,959 INFO L272 TraceCheckUtils]: 101: Hoare triple {22000#false} call setEmailFrom(outgoing__wrappee__Keys_~msg#1, outgoing__wrappee__Keys_~tmp~8#1); {22070#(and (= |old(~__ste_email_from0~0)| ~__ste_email_from0~0) (= |old(~__ste_email_from1~0)| ~__ste_email_from1~0))} is VALID [2022-02-20 18:00:30,959 INFO L290 TraceCheckUtils]: 102: Hoare triple {22070#(and (= |old(~__ste_email_from0~0)| ~__ste_email_from0~0) (= |old(~__ste_email_from1~0)| ~__ste_email_from1~0))} ~handle := #in~handle;~value := #in~value; {21999#true} is VALID [2022-02-20 18:00:30,959 INFO L290 TraceCheckUtils]: 103: Hoare triple {21999#true} assume 1 == ~handle;~__ste_email_from0~0 := ~value; {21999#true} is VALID [2022-02-20 18:00:30,959 INFO L290 TraceCheckUtils]: 104: Hoare triple {21999#true} assume true; {21999#true} is VALID [2022-02-20 18:00:30,959 INFO L284 TraceCheckUtils]: 105: Hoare quadruple {21999#true} {22000#false} #1064#return; {22000#false} is VALID [2022-02-20 18:00:30,960 INFO L290 TraceCheckUtils]: 106: Hoare triple {22000#false} assume { :begin_inline_mail } true;mail_#in~client#1, mail_#in~msg#1 := outgoing__wrappee__Keys_~client#1, outgoing__wrappee__Keys_~msg#1;havoc mail_#t~ret59#1, mail_#t~ret60#1, mail_~client#1, mail_~msg#1, mail_~__utac__ad__arg1~0#1, mail_~__utac__ad__arg2~0#1, mail_~tmp~7#1;mail_~client#1 := mail_#in~client#1;mail_~msg#1 := mail_#in~msg#1;havoc mail_~__utac__ad__arg1~0#1;havoc mail_~__utac__ad__arg2~0#1;havoc mail_~tmp~7#1;mail_~__utac__ad__arg1~0#1 := mail_~client#1;mail_~__utac__ad__arg2~0#1 := mail_~msg#1;assume { :begin_inline___utac_acc__SignForward_spec__1 } true;__utac_acc__SignForward_spec__1_#in~client#1, __utac_acc__SignForward_spec__1_#in~msg#1 := mail_~__utac__ad__arg1~0#1, mail_~__utac__ad__arg2~0#1;havoc __utac_acc__SignForward_spec__1_#t~ret107#1, __utac_acc__SignForward_spec__1_#t~ret108#1, __utac_acc__SignForward_spec__1_#t~ret109#1, __utac_acc__SignForward_spec__1_~client#1, __utac_acc__SignForward_spec__1_~msg#1, __utac_acc__SignForward_spec__1_~tmp~25#1, __utac_acc__SignForward_spec__1_~tmp___0~9#1;__utac_acc__SignForward_spec__1_~client#1 := __utac_acc__SignForward_spec__1_#in~client#1;__utac_acc__SignForward_spec__1_~msg#1 := __utac_acc__SignForward_spec__1_#in~msg#1;havoc __utac_acc__SignForward_spec__1_~tmp~25#1;havoc __utac_acc__SignForward_spec__1_~tmp___0~9#1;call __utac_acc__SignForward_spec__1_#t~ret107#1 := puts(39, 0);assume -2147483648 <= __utac_acc__SignForward_spec__1_#t~ret107#1 && __utac_acc__SignForward_spec__1_#t~ret107#1 <= 2147483647;havoc __utac_acc__SignForward_spec__1_#t~ret107#1; {22000#false} is VALID [2022-02-20 18:00:30,960 INFO L272 TraceCheckUtils]: 107: Hoare triple {22000#false} call __utac_acc__SignForward_spec__1_#t~ret108#1 := isSigned(__utac_acc__SignForward_spec__1_~msg#1); {21999#true} is VALID [2022-02-20 18:00:30,960 INFO L290 TraceCheckUtils]: 108: Hoare triple {21999#true} ~handle := #in~handle;havoc ~retValue_acc~41; {21999#true} is VALID [2022-02-20 18:00:30,960 INFO L290 TraceCheckUtils]: 109: Hoare triple {21999#true} assume 1 == ~handle;~retValue_acc~41 := ~__ste_email_isSigned0~0;#res := ~retValue_acc~41; {21999#true} is VALID [2022-02-20 18:00:30,960 INFO L290 TraceCheckUtils]: 110: Hoare triple {21999#true} assume true; {21999#true} is VALID [2022-02-20 18:00:30,960 INFO L284 TraceCheckUtils]: 111: Hoare quadruple {21999#true} {22000#false} #1066#return; {22000#false} is VALID [2022-02-20 18:00:30,960 INFO L290 TraceCheckUtils]: 112: Hoare triple {22000#false} assume -2147483648 <= __utac_acc__SignForward_spec__1_#t~ret108#1 && __utac_acc__SignForward_spec__1_#t~ret108#1 <= 2147483647;__utac_acc__SignForward_spec__1_~tmp___0~9#1 := __utac_acc__SignForward_spec__1_#t~ret108#1;havoc __utac_acc__SignForward_spec__1_#t~ret108#1; {22000#false} is VALID [2022-02-20 18:00:30,960 INFO L290 TraceCheckUtils]: 113: Hoare triple {22000#false} assume 0 != __utac_acc__SignForward_spec__1_~tmp___0~9#1; {22000#false} is VALID [2022-02-20 18:00:30,960 INFO L272 TraceCheckUtils]: 114: Hoare triple {22000#false} call __utac_acc__SignForward_spec__1_#t~ret109#1 := getClientPrivateKey(__utac_acc__SignForward_spec__1_~client#1); {21999#true} is VALID [2022-02-20 18:00:30,960 INFO L290 TraceCheckUtils]: 115: Hoare triple {21999#true} ~handle := #in~handle;havoc ~retValue_acc~20; {21999#true} is VALID [2022-02-20 18:00:30,961 INFO L290 TraceCheckUtils]: 116: Hoare triple {21999#true} assume 1 == ~handle;~retValue_acc~20 := ~__ste_client_privateKey0~0;#res := ~retValue_acc~20; {21999#true} is VALID [2022-02-20 18:00:30,961 INFO L290 TraceCheckUtils]: 117: Hoare triple {21999#true} assume true; {21999#true} is VALID [2022-02-20 18:00:30,961 INFO L284 TraceCheckUtils]: 118: Hoare quadruple {21999#true} {22000#false} #1068#return; {22000#false} is VALID [2022-02-20 18:00:30,961 INFO L290 TraceCheckUtils]: 119: Hoare triple {22000#false} assume -2147483648 <= __utac_acc__SignForward_spec__1_#t~ret109#1 && __utac_acc__SignForward_spec__1_#t~ret109#1 <= 2147483647;__utac_acc__SignForward_spec__1_~tmp~25#1 := __utac_acc__SignForward_spec__1_#t~ret109#1;havoc __utac_acc__SignForward_spec__1_#t~ret109#1; {22000#false} is VALID [2022-02-20 18:00:30,961 INFO L290 TraceCheckUtils]: 120: Hoare triple {22000#false} assume 0 == __utac_acc__SignForward_spec__1_~tmp~25#1;assume { :begin_inline___automaton_fail } true; {22000#false} is VALID [2022-02-20 18:00:30,961 INFO L290 TraceCheckUtils]: 121: Hoare triple {22000#false} assume !false; {22000#false} is VALID [2022-02-20 18:00:30,961 INFO L134 CoverageAnalysis]: Checked inductivity of 35 backedges. 13 proven. 0 refuted. 0 times theorem prover too weak. 22 trivial. 0 not checked. [2022-02-20 18:00:30,962 INFO L144 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2022-02-20 18:00:30,962 INFO L338 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [1608934556] [2022-02-20 18:00:30,962 INFO L165 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [1608934556] provided 1 perfect and 0 imperfect interpolant sequences [2022-02-20 18:00:30,962 INFO L191 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2022-02-20 18:00:30,962 INFO L204 FreeRefinementEngine]: Number of different interpolants: perfect sequences [12] imperfect sequences [] total 12 [2022-02-20 18:00:30,962 INFO L118 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [176448040] [2022-02-20 18:00:30,962 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2022-02-20 18:00:30,963 INFO L78 Accepts]: Start accepts. Automaton has has 12 states, 11 states have (on average 7.363636363636363) internal successors, (81), 8 states have internal predecessors, (81), 4 states have call successors, (16), 6 states have call predecessors, (16), 3 states have return successors, (14), 3 states have call predecessors, (14), 4 states have call successors, (14) Word has length 122 [2022-02-20 18:00:30,963 INFO L84 Accepts]: Finished accepts. word is accepted. [2022-02-20 18:00:30,963 INFO L86 InductivityCheck]: Starting indutivity check of a Floyd-Hoare automaton with has 12 states, 11 states have (on average 7.363636363636363) internal successors, (81), 8 states have internal predecessors, (81), 4 states have call successors, (16), 6 states have call predecessors, (16), 3 states have return successors, (14), 3 states have call predecessors, (14), 4 states have call successors, (14) [2022-02-20 18:00:31,039 INFO L122 InductivityCheck]: Floyd-Hoare automaton has 111 edges. 111 inductive. 0 not inductive. 0 times theorem prover too weak to decide inductivity. [2022-02-20 18:00:31,039 INFO L546 AbstractCegarLoop]: INTERPOLANT automaton has 12 states [2022-02-20 18:00:31,039 INFO L108 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2022-02-20 18:00:31,040 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 12 interpolants. [2022-02-20 18:00:31,040 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=21, Invalid=111, Unknown=0, NotChecked=0, Total=132 [2022-02-20 18:00:31,040 INFO L87 Difference]: Start difference. First operand 443 states and 668 transitions. Second operand has 12 states, 11 states have (on average 7.363636363636363) internal successors, (81), 8 states have internal predecessors, (81), 4 states have call successors, (16), 6 states have call predecessors, (16), 3 states have return successors, (14), 3 states have call predecessors, (14), 4 states have call successors, (14) [2022-02-20 18:00:41,880 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-02-20 18:00:41,880 INFO L93 Difference]: Finished difference Result 1073 states and 1628 transitions. [2022-02-20 18:00:41,880 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 14 states. [2022-02-20 18:00:41,881 INFO L78 Accepts]: Start accepts. Automaton has has 12 states, 11 states have (on average 7.363636363636363) internal successors, (81), 8 states have internal predecessors, (81), 4 states have call successors, (16), 6 states have call predecessors, (16), 3 states have return successors, (14), 3 states have call predecessors, (14), 4 states have call successors, (14) Word has length 122 [2022-02-20 18:00:41,881 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2022-02-20 18:00:41,881 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 12 states, 11 states have (on average 7.363636363636363) internal successors, (81), 8 states have internal predecessors, (81), 4 states have call successors, (16), 6 states have call predecessors, (16), 3 states have return successors, (14), 3 states have call predecessors, (14), 4 states have call successors, (14) [2022-02-20 18:00:41,897 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 14 states to 14 states and 1430 transitions. [2022-02-20 18:00:41,898 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 12 states, 11 states have (on average 7.363636363636363) internal successors, (81), 8 states have internal predecessors, (81), 4 states have call successors, (16), 6 states have call predecessors, (16), 3 states have return successors, (14), 3 states have call predecessors, (14), 4 states have call successors, (14) [2022-02-20 18:00:41,913 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 14 states to 14 states and 1430 transitions. [2022-02-20 18:00:41,914 INFO L86 InductivityCheck]: Starting indutivity check of a Floyd-Hoare automaton with 14 states and 1430 transitions. [2022-02-20 18:00:43,367 INFO L122 InductivityCheck]: Floyd-Hoare automaton has 1430 edges. 1430 inductive. 0 not inductive. 0 times theorem prover too weak to decide inductivity. [2022-02-20 18:00:43,403 INFO L225 Difference]: With dead ends: 1073 [2022-02-20 18:00:43,404 INFO L226 Difference]: Without dead ends: 657 [2022-02-20 18:00:43,418 INFO L932 BasicCegarLoop]: 0 DeclaredPredicates, 53 GetRequests, 31 SyntacticMatches, 0 SemanticMatches, 22 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 71 ImplicationChecksByTransitivity, 0.2s TimeCoverageRelationStatistics Valid=112, Invalid=440, Unknown=0, NotChecked=0, Total=552 [2022-02-20 18:00:43,432 INFO L933 BasicCegarLoop]: 704 mSDtfsCounter, 1498 mSDsluCounter, 1196 mSDsCounter, 0 mSdLazyCounter, 4710 mSolverCounterSat, 631 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 5.0s Time, 0 mProtectedPredicate, 0 mProtectedAction, 1498 SdHoareTripleChecker+Valid, 1900 SdHoareTripleChecker+Invalid, 5341 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 631 IncrementalHoareTripleChecker+Valid, 4710 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 5.0s IncrementalHoareTripleChecker+Time [2022-02-20 18:00:43,432 INFO L934 BasicCegarLoop]: SdHoareTripleChecker [1498 Valid, 1900 Invalid, 5341 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [631 Valid, 4710 Invalid, 0 Unknown, 0 Unchecked, 5.0s Time] [2022-02-20 18:00:43,434 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 657 states. [2022-02-20 18:00:43,542 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 657 to 443. [2022-02-20 18:00:43,542 INFO L214 AbstractMinimizeNwa]: Start testing correctness of minimizeSevpa [2022-02-20 18:00:43,544 INFO L82 GeneralOperation]: Start isEquivalent. First operand 657 states. Second operand has 443 states, 341 states have (on average 1.5043988269794721) internal successors, (513), 347 states have internal predecessors, (513), 74 states have call successors, (74), 24 states have call predecessors, (74), 27 states have return successors, (80), 73 states have call predecessors, (80), 73 states have call successors, (80) [2022-02-20 18:00:43,545 INFO L74 IsIncluded]: Start isIncluded. First operand 657 states. Second operand has 443 states, 341 states have (on average 1.5043988269794721) internal successors, (513), 347 states have internal predecessors, (513), 74 states have call successors, (74), 24 states have call predecessors, (74), 27 states have return successors, (80), 73 states have call predecessors, (80), 73 states have call successors, (80) [2022-02-20 18:00:43,546 INFO L87 Difference]: Start difference. First operand 657 states. Second operand has 443 states, 341 states have (on average 1.5043988269794721) internal successors, (513), 347 states have internal predecessors, (513), 74 states have call successors, (74), 24 states have call predecessors, (74), 27 states have return successors, (80), 73 states have call predecessors, (80), 73 states have call successors, (80) [2022-02-20 18:00:43,576 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-02-20 18:00:43,577 INFO L93 Difference]: Finished difference Result 657 states and 997 transitions. [2022-02-20 18:00:43,577 INFO L276 IsEmpty]: Start isEmpty. Operand 657 states and 997 transitions. [2022-02-20 18:00:43,581 INFO L282 IsEmpty]: Finished isEmpty. No accepting run. [2022-02-20 18:00:43,582 INFO L83 IsIncluded]: Finished isIncluded. Language is included [2022-02-20 18:00:43,583 INFO L74 IsIncluded]: Start isIncluded. First operand has 443 states, 341 states have (on average 1.5043988269794721) internal successors, (513), 347 states have internal predecessors, (513), 74 states have call successors, (74), 24 states have call predecessors, (74), 27 states have return successors, (80), 73 states have call predecessors, (80), 73 states have call successors, (80) Second operand 657 states. [2022-02-20 18:00:43,583 INFO L87 Difference]: Start difference. First operand has 443 states, 341 states have (on average 1.5043988269794721) internal successors, (513), 347 states have internal predecessors, (513), 74 states have call successors, (74), 24 states have call predecessors, (74), 27 states have return successors, (80), 73 states have call predecessors, (80), 73 states have call successors, (80) Second operand 657 states. [2022-02-20 18:00:43,616 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-02-20 18:00:43,616 INFO L93 Difference]: Finished difference Result 657 states and 997 transitions. [2022-02-20 18:00:43,616 INFO L276 IsEmpty]: Start isEmpty. Operand 657 states and 997 transitions. [2022-02-20 18:00:43,620 INFO L282 IsEmpty]: Finished isEmpty. No accepting run. [2022-02-20 18:00:43,620 INFO L83 IsIncluded]: Finished isIncluded. Language is included [2022-02-20 18:00:43,620 INFO L88 GeneralOperation]: Finished isEquivalent. [2022-02-20 18:00:43,621 INFO L221 AbstractMinimizeNwa]: Finished testing correctness of minimizeSevpa [2022-02-20 18:00:43,622 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 443 states, 341 states have (on average 1.5043988269794721) internal successors, (513), 347 states have internal predecessors, (513), 74 states have call successors, (74), 24 states have call predecessors, (74), 27 states have return successors, (80), 73 states have call predecessors, (80), 73 states have call successors, (80) [2022-02-20 18:00:43,637 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 443 states to 443 states and 667 transitions. [2022-02-20 18:00:43,638 INFO L78 Accepts]: Start accepts. Automaton has 443 states and 667 transitions. Word has length 122 [2022-02-20 18:00:43,638 INFO L84 Accepts]: Finished accepts. word is rejected. [2022-02-20 18:00:43,638 INFO L470 AbstractCegarLoop]: Abstraction has 443 states and 667 transitions. [2022-02-20 18:00:43,639 INFO L471 AbstractCegarLoop]: INTERPOLANT automaton has has 12 states, 11 states have (on average 7.363636363636363) internal successors, (81), 8 states have internal predecessors, (81), 4 states have call successors, (16), 6 states have call predecessors, (16), 3 states have return successors, (14), 3 states have call predecessors, (14), 4 states have call successors, (14) [2022-02-20 18:00:43,639 INFO L276 IsEmpty]: Start isEmpty. Operand 443 states and 667 transitions. [2022-02-20 18:00:43,641 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 124 [2022-02-20 18:00:43,641 INFO L506 BasicCegarLoop]: Found error trace [2022-02-20 18:00:43,642 INFO L514 BasicCegarLoop]: trace histogram [3, 3, 3, 3, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-02-20 18:00:43,642 WARN L452 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable7 [2022-02-20 18:00:43,642 INFO L402 AbstractCegarLoop]: === Iteration 9 === Targeting outgoingErr0ASSERT_VIOLATIONERROR_FUNCTION === [outgoingErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2022-02-20 18:00:43,642 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2022-02-20 18:00:43,642 INFO L85 PathProgramCache]: Analyzing trace with hash 620387617, now seen corresponding path program 2 times [2022-02-20 18:00:43,643 INFO L126 FreeRefinementEngine]: Executing refinement strategy CAMEL [2022-02-20 18:00:43,643 INFO L338 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [1732424396] [2022-02-20 18:00:43,643 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-02-20 18:00:43,643 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2022-02-20 18:00:43,670 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-02-20 18:00:43,721 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 6 [2022-02-20 18:00:43,723 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-02-20 18:00:43,725 INFO L290 TraceCheckUtils]: 0: Hoare triple {25649#(and (= |old(~__ste_client_idCounter0~0)| ~__ste_client_idCounter0~0) (= |old(~__ste_client_idCounter1~0)| ~__ste_client_idCounter1~0) (= |old(~__ste_client_idCounter2~0)| ~__ste_client_idCounter2~0))} ~handle := #in~handle;~value := #in~value; {25583#true} is VALID [2022-02-20 18:00:43,725 INFO L290 TraceCheckUtils]: 1: Hoare triple {25583#true} assume 1 == ~handle;~__ste_client_idCounter0~0 := ~value; {25583#true} is VALID [2022-02-20 18:00:43,725 INFO L290 TraceCheckUtils]: 2: Hoare triple {25583#true} assume true; {25583#true} is VALID [2022-02-20 18:00:43,725 INFO L284 TraceCheckUtils]: 3: Hoare quadruple {25583#true} {25583#true} #1134#return; {25583#true} is VALID [2022-02-20 18:00:43,731 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 12 [2022-02-20 18:00:43,733 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-02-20 18:00:43,736 INFO L290 TraceCheckUtils]: 0: Hoare triple {25650#(and (= ~__ste_client_privateKey0~0 |old(~__ste_client_privateKey0~0)|) (= ~__ste_client_privateKey2~0 |old(~__ste_client_privateKey2~0)|) (= ~__ste_client_privateKey1~0 |old(~__ste_client_privateKey1~0)|))} ~handle := #in~handle;~value := #in~value; {25583#true} is VALID [2022-02-20 18:00:43,736 INFO L290 TraceCheckUtils]: 1: Hoare triple {25583#true} assume 1 == ~handle;~__ste_client_privateKey0~0 := ~value; {25583#true} is VALID [2022-02-20 18:00:43,736 INFO L290 TraceCheckUtils]: 2: Hoare triple {25583#true} assume true; {25583#true} is VALID [2022-02-20 18:00:43,736 INFO L284 TraceCheckUtils]: 3: Hoare quadruple {25583#true} {25583#true} #1136#return; {25583#true} is VALID [2022-02-20 18:00:43,736 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 18 [2022-02-20 18:00:43,737 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-02-20 18:00:43,741 INFO L290 TraceCheckUtils]: 0: Hoare triple {25649#(and (= |old(~__ste_client_idCounter0~0)| ~__ste_client_idCounter0~0) (= |old(~__ste_client_idCounter1~0)| ~__ste_client_idCounter1~0) (= |old(~__ste_client_idCounter2~0)| ~__ste_client_idCounter2~0))} ~handle := #in~handle;~value := #in~value; {25583#true} is VALID [2022-02-20 18:00:43,741 INFO L290 TraceCheckUtils]: 1: Hoare triple {25583#true} assume !(1 == ~handle); {25583#true} is VALID [2022-02-20 18:00:43,741 INFO L290 TraceCheckUtils]: 2: Hoare triple {25583#true} assume 2 == ~handle;~__ste_client_idCounter1~0 := ~value; {25583#true} is VALID [2022-02-20 18:00:43,741 INFO L290 TraceCheckUtils]: 3: Hoare triple {25583#true} assume true; {25583#true} is VALID [2022-02-20 18:00:43,741 INFO L284 TraceCheckUtils]: 4: Hoare quadruple {25583#true} {25583#true} #1138#return; {25583#true} is VALID [2022-02-20 18:00:43,741 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 25 [2022-02-20 18:00:43,743 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-02-20 18:00:43,747 INFO L290 TraceCheckUtils]: 0: Hoare triple {25650#(and (= ~__ste_client_privateKey0~0 |old(~__ste_client_privateKey0~0)|) (= ~__ste_client_privateKey2~0 |old(~__ste_client_privateKey2~0)|) (= ~__ste_client_privateKey1~0 |old(~__ste_client_privateKey1~0)|))} ~handle := #in~handle;~value := #in~value; {25583#true} is VALID [2022-02-20 18:00:43,747 INFO L290 TraceCheckUtils]: 1: Hoare triple {25583#true} assume !(1 == ~handle); {25583#true} is VALID [2022-02-20 18:00:43,747 INFO L290 TraceCheckUtils]: 2: Hoare triple {25583#true} assume 2 == ~handle;~__ste_client_privateKey1~0 := ~value; {25583#true} is VALID [2022-02-20 18:00:43,747 INFO L290 TraceCheckUtils]: 3: Hoare triple {25583#true} assume true; {25583#true} is VALID [2022-02-20 18:00:43,747 INFO L284 TraceCheckUtils]: 4: Hoare quadruple {25583#true} {25583#true} #1140#return; {25583#true} is VALID [2022-02-20 18:00:43,747 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 32 [2022-02-20 18:00:43,750 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-02-20 18:00:43,766 INFO L290 TraceCheckUtils]: 0: Hoare triple {25649#(and (= |old(~__ste_client_idCounter0~0)| ~__ste_client_idCounter0~0) (= |old(~__ste_client_idCounter1~0)| ~__ste_client_idCounter1~0) (= |old(~__ste_client_idCounter2~0)| ~__ste_client_idCounter2~0))} ~handle := #in~handle;~value := #in~value; {25651#(= setClientId_~handle |setClientId_#in~handle|)} is VALID [2022-02-20 18:00:43,766 INFO L290 TraceCheckUtils]: 1: Hoare triple {25651#(= setClientId_~handle |setClientId_#in~handle|)} assume !(1 == ~handle); {25651#(= setClientId_~handle |setClientId_#in~handle|)} is VALID [2022-02-20 18:00:43,767 INFO L290 TraceCheckUtils]: 2: Hoare triple {25651#(= setClientId_~handle |setClientId_#in~handle|)} assume !(2 == ~handle); {25651#(= setClientId_~handle |setClientId_#in~handle|)} is VALID [2022-02-20 18:00:43,767 INFO L290 TraceCheckUtils]: 3: Hoare triple {25651#(= setClientId_~handle |setClientId_#in~handle|)} assume 3 == ~handle;~__ste_client_idCounter2~0 := ~value; {25652#(= 3 |setClientId_#in~handle|)} is VALID [2022-02-20 18:00:43,767 INFO L290 TraceCheckUtils]: 4: Hoare triple {25652#(= 3 |setClientId_#in~handle|)} assume true; {25652#(= 3 |setClientId_#in~handle|)} is VALID [2022-02-20 18:00:43,768 INFO L284 TraceCheckUtils]: 5: Hoare quadruple {25652#(= 3 |setClientId_#in~handle|)} {25603#(= |ULTIMATE.start_setup_chuck_~chuck___0#1| |ULTIMATE.start_setup_chuck__wrappee__Base_~chuck___0#1|)} #1142#return; {25610#(not (= |ULTIMATE.start_setup_chuck_~chuck___0#1| 2))} is VALID [2022-02-20 18:00:43,768 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 40 [2022-02-20 18:00:43,772 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-02-20 18:00:43,792 INFO L290 TraceCheckUtils]: 0: Hoare triple {25650#(and (= ~__ste_client_privateKey0~0 |old(~__ste_client_privateKey0~0)|) (= ~__ste_client_privateKey2~0 |old(~__ste_client_privateKey2~0)|) (= ~__ste_client_privateKey1~0 |old(~__ste_client_privateKey1~0)|))} ~handle := #in~handle;~value := #in~value; {25653#(= setClientPrivateKey_~handle |setClientPrivateKey_#in~handle|)} is VALID [2022-02-20 18:00:43,793 INFO L290 TraceCheckUtils]: 1: Hoare triple {25653#(= setClientPrivateKey_~handle |setClientPrivateKey_#in~handle|)} assume !(1 == ~handle); {25653#(= setClientPrivateKey_~handle |setClientPrivateKey_#in~handle|)} is VALID [2022-02-20 18:00:43,793 INFO L290 TraceCheckUtils]: 2: Hoare triple {25653#(= setClientPrivateKey_~handle |setClientPrivateKey_#in~handle|)} assume 2 == ~handle;~__ste_client_privateKey1~0 := ~value; {25654#(= 2 |setClientPrivateKey_#in~handle|)} is VALID [2022-02-20 18:00:43,794 INFO L290 TraceCheckUtils]: 3: Hoare triple {25654#(= 2 |setClientPrivateKey_#in~handle|)} assume true; {25654#(= 2 |setClientPrivateKey_#in~handle|)} is VALID [2022-02-20 18:00:43,794 INFO L284 TraceCheckUtils]: 4: Hoare quadruple {25654#(= 2 |setClientPrivateKey_#in~handle|)} {25610#(not (= |ULTIMATE.start_setup_chuck_~chuck___0#1| 2))} #1144#return; {25584#false} is VALID [2022-02-20 18:00:43,803 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 63 [2022-02-20 18:00:43,805 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-02-20 18:00:43,807 INFO L290 TraceCheckUtils]: 0: Hoare triple {25655#(and (= |old(~__ste_email_from0~0)| ~__ste_email_from0~0) (= |old(~__ste_email_from1~0)| ~__ste_email_from1~0))} ~handle := #in~handle;~value := #in~value; {25583#true} is VALID [2022-02-20 18:00:43,808 INFO L290 TraceCheckUtils]: 1: Hoare triple {25583#true} assume 1 == ~handle;~__ste_email_from0~0 := ~value; {25583#true} is VALID [2022-02-20 18:00:43,808 INFO L290 TraceCheckUtils]: 2: Hoare triple {25583#true} assume true; {25583#true} is VALID [2022-02-20 18:00:43,808 INFO L284 TraceCheckUtils]: 3: Hoare quadruple {25583#true} {25584#false} #1120#return; {25584#false} is VALID [2022-02-20 18:00:43,817 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 68 [2022-02-20 18:00:43,818 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-02-20 18:00:43,820 INFO L290 TraceCheckUtils]: 0: Hoare triple {25656#(and (= ~__ste_email_to0~0 |old(~__ste_email_to0~0)|) (= ~__ste_email_to1~0 |old(~__ste_email_to1~0)|))} ~handle := #in~handle;~value := #in~value; {25583#true} is VALID [2022-02-20 18:00:43,821 INFO L290 TraceCheckUtils]: 1: Hoare triple {25583#true} assume 1 == ~handle;~__ste_email_to0~0 := ~value; {25583#true} is VALID [2022-02-20 18:00:43,821 INFO L290 TraceCheckUtils]: 2: Hoare triple {25583#true} assume true; {25583#true} is VALID [2022-02-20 18:00:43,821 INFO L284 TraceCheckUtils]: 3: Hoare quadruple {25583#true} {25584#false} #1122#return; {25584#false} is VALID [2022-02-20 18:00:43,821 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 77 [2022-02-20 18:00:43,822 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-02-20 18:00:43,823 INFO L290 TraceCheckUtils]: 0: Hoare triple {25583#true} ~handle := #in~handle;havoc ~retValue_acc~20; {25583#true} is VALID [2022-02-20 18:00:43,823 INFO L290 TraceCheckUtils]: 1: Hoare triple {25583#true} assume 1 == ~handle;~retValue_acc~20 := ~__ste_client_privateKey0~0;#res := ~retValue_acc~20; {25583#true} is VALID [2022-02-20 18:00:43,824 INFO L290 TraceCheckUtils]: 2: Hoare triple {25583#true} assume true; {25583#true} is VALID [2022-02-20 18:00:43,824 INFO L284 TraceCheckUtils]: 3: Hoare quadruple {25583#true} {25584#false} #1054#return; {25584#false} is VALID [2022-02-20 18:00:43,824 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 85 [2022-02-20 18:00:43,825 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-02-20 18:00:43,826 INFO L290 TraceCheckUtils]: 0: Hoare triple {25583#true} ~handle := #in~handle;havoc ~retValue_acc~36; {25583#true} is VALID [2022-02-20 18:00:43,827 INFO L290 TraceCheckUtils]: 1: Hoare triple {25583#true} assume 1 == ~handle;~retValue_acc~36 := ~__ste_email_to0~0;#res := ~retValue_acc~36; {25583#true} is VALID [2022-02-20 18:00:43,827 INFO L290 TraceCheckUtils]: 2: Hoare triple {25583#true} assume true; {25583#true} is VALID [2022-02-20 18:00:43,827 INFO L284 TraceCheckUtils]: 3: Hoare quadruple {25583#true} {25584#false} #1056#return; {25584#false} is VALID [2022-02-20 18:00:43,827 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 91 [2022-02-20 18:00:43,828 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-02-20 18:00:43,830 INFO L290 TraceCheckUtils]: 0: Hoare triple {25583#true} ~handle := #in~handle;~userid := #in~userid;havoc ~retValue_acc~25; {25583#true} is VALID [2022-02-20 18:00:43,830 INFO L290 TraceCheckUtils]: 1: Hoare triple {25583#true} assume 1 == ~handle; {25583#true} is VALID [2022-02-20 18:00:43,830 INFO L290 TraceCheckUtils]: 2: Hoare triple {25583#true} assume ~userid == ~__ste_Client_Keyring0_User0~0;~retValue_acc~25 := ~__ste_Client_Keyring0_PublicKey0~0;#res := ~retValue_acc~25; {25583#true} is VALID [2022-02-20 18:00:43,830 INFO L290 TraceCheckUtils]: 3: Hoare triple {25583#true} assume true; {25583#true} is VALID [2022-02-20 18:00:43,830 INFO L284 TraceCheckUtils]: 4: Hoare quadruple {25583#true} {25584#false} #1058#return; {25584#false} is VALID [2022-02-20 18:00:43,830 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 102 [2022-02-20 18:00:43,831 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-02-20 18:00:43,833 INFO L290 TraceCheckUtils]: 0: Hoare triple {25655#(and (= |old(~__ste_email_from0~0)| ~__ste_email_from0~0) (= |old(~__ste_email_from1~0)| ~__ste_email_from1~0))} ~handle := #in~handle;~value := #in~value; {25583#true} is VALID [2022-02-20 18:00:43,833 INFO L290 TraceCheckUtils]: 1: Hoare triple {25583#true} assume 1 == ~handle;~__ste_email_from0~0 := ~value; {25583#true} is VALID [2022-02-20 18:00:43,833 INFO L290 TraceCheckUtils]: 2: Hoare triple {25583#true} assume true; {25583#true} is VALID [2022-02-20 18:00:43,833 INFO L284 TraceCheckUtils]: 3: Hoare quadruple {25583#true} {25584#false} #1064#return; {25584#false} is VALID [2022-02-20 18:00:43,833 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 108 [2022-02-20 18:00:43,834 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-02-20 18:00:43,836 INFO L290 TraceCheckUtils]: 0: Hoare triple {25583#true} ~handle := #in~handle;havoc ~retValue_acc~41; {25583#true} is VALID [2022-02-20 18:00:43,836 INFO L290 TraceCheckUtils]: 1: Hoare triple {25583#true} assume 1 == ~handle;~retValue_acc~41 := ~__ste_email_isSigned0~0;#res := ~retValue_acc~41; {25583#true} is VALID [2022-02-20 18:00:43,836 INFO L290 TraceCheckUtils]: 2: Hoare triple {25583#true} assume true; {25583#true} is VALID [2022-02-20 18:00:43,836 INFO L284 TraceCheckUtils]: 3: Hoare quadruple {25583#true} {25584#false} #1066#return; {25584#false} is VALID [2022-02-20 18:00:43,837 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 115 [2022-02-20 18:00:43,837 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-02-20 18:00:43,839 INFO L290 TraceCheckUtils]: 0: Hoare triple {25583#true} ~handle := #in~handle;havoc ~retValue_acc~20; {25583#true} is VALID [2022-02-20 18:00:43,839 INFO L290 TraceCheckUtils]: 1: Hoare triple {25583#true} assume 1 == ~handle;~retValue_acc~20 := ~__ste_client_privateKey0~0;#res := ~retValue_acc~20; {25583#true} is VALID [2022-02-20 18:00:43,840 INFO L290 TraceCheckUtils]: 2: Hoare triple {25583#true} assume true; {25583#true} is VALID [2022-02-20 18:00:43,840 INFO L284 TraceCheckUtils]: 3: Hoare quadruple {25583#true} {25584#false} #1068#return; {25584#false} is VALID [2022-02-20 18:00:43,840 INFO L290 TraceCheckUtils]: 0: Hoare triple {25583#true} assume { :begin_inline_ULTIMATE.init } true;#NULL.base, #NULL.offset := 0, 0;assume 0 == #valid[0];assume 0 < #StackHeapBarrier;call #Ultimate.allocInit(2, 1);call write~init~int(48, 1, 0, 1);call write~init~int(0, 1, 1, 1);call #Ultimate.allocInit(28, 2);call #Ultimate.allocInit(12, 3);call #Ultimate.allocInit(30, 4);call #Ultimate.allocInit(9, 5);call #Ultimate.allocInit(21, 6);call #Ultimate.allocInit(30, 7);call #Ultimate.allocInit(9, 8);call #Ultimate.allocInit(21, 9);call #Ultimate.allocInit(30, 10);call #Ultimate.allocInit(9, 11);call #Ultimate.allocInit(25, 12);call #Ultimate.allocInit(30, 13);call #Ultimate.allocInit(9, 14);call #Ultimate.allocInit(25, 15);call #Ultimate.allocInit(44, 16);call #Ultimate.allocInit(44, 17);call #Ultimate.allocInit(9, 18);call #Ultimate.allocInit(9, 19);call #Ultimate.allocInit(11, 20);call #Ultimate.allocInit(19, 21);call #Ultimate.allocInit(4, 22);call write~init~int(37, 22, 0, 1);call write~init~int(100, 22, 1, 1);call write~init~int(10, 22, 2, 1);call write~init~int(0, 22, 3, 1);call #Ultimate.allocInit(4, 23);call write~init~int(37, 23, 0, 1);call write~init~int(100, 23, 1, 1);call write~init~int(10, 23, 2, 1);call write~init~int(0, 23, 3, 1);call #Ultimate.allocInit(10, 24);call #Ultimate.allocInit(16, 25);call #Ultimate.allocInit(20, 26);call #Ultimate.allocInit(22, 27);call #Ultimate.allocInit(21, 28);call #Ultimate.allocInit(10, 29);call #Ultimate.allocInit(12, 30);call #Ultimate.allocInit(10, 31);call #Ultimate.allocInit(18, 32);call #Ultimate.allocInit(16, 33);call #Ultimate.allocInit(21, 34);call #Ultimate.allocInit(13, 35);call #Ultimate.allocInit(16, 36);call #Ultimate.allocInit(25, 37);call #Ultimate.allocInit(4, 38);call write~init~int(37, 38, 0, 1);call write~init~int(115, 38, 1, 1);call write~init~int(10, 38, 2, 1);call write~init~int(0, 38, 3, 1);call #Ultimate.allocInit(13, 39);~head~0.base, ~head~0.offset := 0, 0;~__SELECTED_FEATURE_Base~0 := 0;~__SELECTED_FEATURE_Keys~0 := 0;~__SELECTED_FEATURE_Encrypt~0 := 0;~__SELECTED_FEATURE_AutoResponder~0 := 0;~__SELECTED_FEATURE_AddressBook~0 := 0;~__SELECTED_FEATURE_Sign~0 := 0;~__SELECTED_FEATURE_Forward~0 := 0;~__SELECTED_FEATURE_Verify~0 := 0;~__SELECTED_FEATURE_Decrypt~0 := 0;~__GUIDSL_ROOT_PRODUCTION~0 := 0;~__GUIDSL_NON_TERMINAL_main~0 := 0;~bob~0 := 0;~rjh~0 := 0;~chuck~0 := 0;~queue_empty~0 := 1;~queued_message~0 := 0;~queued_client~0 := 0;~__ste_Client_counter~0 := 0;~__ste_client_name0~0.base, ~__ste_client_name0~0.offset := 0, 0;~__ste_client_name1~0.base, ~__ste_client_name1~0.offset := 0, 0;~__ste_client_name2~0.base, ~__ste_client_name2~0.offset := 0, 0;~__ste_client_outbuffer0~0 := 0;~__ste_client_outbuffer1~0 := 0;~__ste_client_outbuffer2~0 := 0;~__ste_client_outbuffer3~0 := 0;~__ste_ClientAddressBook_size0~0 := 0;~__ste_ClientAddressBook_size1~0 := 0;~__ste_ClientAddressBook_size2~0 := 0;~__ste_Client_AddressBook0_Alias0~0 := 0;~__ste_Client_AddressBook0_Alias1~0 := 0;~__ste_Client_AddressBook0_Alias2~0 := 0;~__ste_Client_AddressBook1_Alias0~0 := 0;~__ste_Client_AddressBook1_Alias1~0 := 0;~__ste_Client_AddressBook1_Alias2~0 := 0;~__ste_Client_AddressBook2_Alias0~0 := 0;~__ste_Client_AddressBook2_Alias1~0 := 0;~__ste_Client_AddressBook2_Alias2~0 := 0;~__ste_Client_AddressBook0_Address0~0 := 0;~__ste_Client_AddressBook0_Address1~0 := 0;~__ste_Client_AddressBook0_Address2~0 := 0;~__ste_Client_AddressBook1_Address0~0 := 0;~__ste_Client_AddressBook1_Address1~0 := 0;~__ste_Client_AddressBook1_Address2~0 := 0;~__ste_Client_AddressBook2_Address0~0 := 0;~__ste_Client_AddressBook2_Address1~0 := 0;~__ste_Client_AddressBook2_Address2~0 := 0;~__ste_client_autoResponse0~0 := 0;~__ste_client_autoResponse1~0 := 0;~__ste_client_autoResponse2~0 := 0;~__ste_client_privateKey0~0 := 0;~__ste_client_privateKey1~0 := 0;~__ste_client_privateKey2~0 := 0;~__ste_ClientKeyring_size0~0 := 0;~__ste_ClientKeyring_size1~0 := 0;~__ste_ClientKeyring_size2~0 := 0;~__ste_Client_Keyring0_User0~0 := 0;~__ste_Client_Keyring0_User1~0 := 0;~__ste_Client_Keyring0_User2~0 := 0;~__ste_Client_Keyring1_User0~0 := 0;~__ste_Client_Keyring1_User1~0 := 0;~__ste_Client_Keyring1_User2~0 := 0;~__ste_Client_Keyring2_User0~0 := 0;~__ste_Client_Keyring2_User1~0 := 0;~__ste_Client_Keyring2_User2~0 := 0;~__ste_Client_Keyring0_PublicKey0~0 := 0;~__ste_Client_Keyring0_PublicKey1~0 := 0;~__ste_Client_Keyring0_PublicKey2~0 := 0;~__ste_Client_Keyring1_PublicKey0~0 := 0;~__ste_Client_Keyring1_PublicKey1~0 := 0;~__ste_Client_Keyring1_PublicKey2~0 := 0;~__ste_Client_Keyring2_PublicKey0~0 := 0;~__ste_Client_Keyring2_PublicKey1~0 := 0;~__ste_Client_Keyring2_PublicKey2~0 := 0;~__ste_client_forwardReceiver0~0 := 0;~__ste_client_forwardReceiver1~0 := 0;~__ste_client_forwardReceiver2~0 := 0;~__ste_client_forwardReceiver3~0 := 0;~__ste_client_idCounter0~0 := 0;~__ste_client_idCounter1~0 := 0;~__ste_client_idCounter2~0 := 0;~__ste_Email_counter~0 := 0;~__ste_email_id0~0 := 0;~__ste_email_id1~0 := 0;~__ste_email_from0~0 := 0;~__ste_email_from1~0 := 0;~__ste_email_to0~0 := 0;~__ste_email_to1~0 := 0;~__ste_email_subject0~0.base, ~__ste_email_subject0~0.offset := 0, 0;~__ste_email_subject1~0.base, ~__ste_email_subject1~0.offset := 0, 0;~__ste_email_body0~0.base, ~__ste_email_body0~0.offset := 0, 0;~__ste_email_body1~0.base, ~__ste_email_body1~0.offset := 0, 0;~__ste_email_isEncrypted0~0 := 0;~__ste_email_isEncrypted1~0 := 0;~__ste_email_encryptionKey0~0 := 0;~__ste_email_encryptionKey1~0 := 0;~__ste_email_isSigned0~0 := 0;~__ste_email_isSigned1~0 := 0;~__ste_email_signKey0~0 := 0;~__ste_email_signKey1~0 := 0;~__ste_email_isSignatureVerified0~0 := 0;~__ste_email_isSignatureVerified1~0 := 0; {25583#true} is VALID [2022-02-20 18:00:43,840 INFO L290 TraceCheckUtils]: 1: Hoare triple {25583#true} assume { :end_inline_ULTIMATE.init } true;assume { :begin_inline_main } true;havoc main_#res#1;havoc main_#t~ret35#1, main_~retValue_acc~3#1, main_~tmp~4#1;havoc main_~retValue_acc~3#1;havoc main_~tmp~4#1;assume { :begin_inline_select_helpers } true; {25583#true} is VALID [2022-02-20 18:00:43,840 INFO L290 TraceCheckUtils]: 2: Hoare triple {25583#true} assume { :end_inline_select_helpers } true;assume { :begin_inline_select_features } true; {25583#true} is VALID [2022-02-20 18:00:43,840 INFO L290 TraceCheckUtils]: 3: Hoare triple {25583#true} assume { :end_inline_select_features } true;assume { :begin_inline_valid_product } true;havoc valid_product_#res#1;havoc valid_product_~retValue_acc~5#1;havoc valid_product_~retValue_acc~5#1;valid_product_~retValue_acc~5#1 := 1;valid_product_#res#1 := valid_product_~retValue_acc~5#1; {25583#true} is VALID [2022-02-20 18:00:43,840 INFO L290 TraceCheckUtils]: 4: Hoare triple {25583#true} main_#t~ret35#1 := valid_product_#res#1;assume { :end_inline_valid_product } true;assume -2147483648 <= main_#t~ret35#1 && main_#t~ret35#1 <= 2147483647;main_~tmp~4#1 := main_#t~ret35#1;havoc main_#t~ret35#1; {25583#true} is VALID [2022-02-20 18:00:43,841 INFO L290 TraceCheckUtils]: 5: Hoare triple {25583#true} assume 0 != main_~tmp~4#1;assume { :begin_inline_setup } true;havoc setup_#t~nondet32#1, setup_#t~nondet33#1, setup_#t~nondet34#1, setup_~__cil_tmp1~0#1.base, setup_~__cil_tmp1~0#1.offset, setup_~__cil_tmp2~0#1.base, setup_~__cil_tmp2~0#1.offset, setup_~__cil_tmp3~0#1.base, setup_~__cil_tmp3~0#1.offset;havoc setup_~__cil_tmp1~0#1.base, setup_~__cil_tmp1~0#1.offset;havoc setup_~__cil_tmp2~0#1.base, setup_~__cil_tmp2~0#1.offset;havoc setup_~__cil_tmp3~0#1.base, setup_~__cil_tmp3~0#1.offset;~bob~0 := 1;assume { :begin_inline_setup_bob } true;setup_bob_#in~bob___0#1 := ~bob~0;havoc setup_bob_~bob___0#1;setup_bob_~bob___0#1 := setup_bob_#in~bob___0#1;assume { :begin_inline_setup_bob__wrappee__Base } true;setup_bob__wrappee__Base_#in~bob___0#1 := setup_bob_~bob___0#1;havoc setup_bob__wrappee__Base_~bob___0#1;setup_bob__wrappee__Base_~bob___0#1 := setup_bob__wrappee__Base_#in~bob___0#1; {25583#true} is VALID [2022-02-20 18:00:43,841 INFO L272 TraceCheckUtils]: 6: Hoare triple {25583#true} call setClientId(setup_bob__wrappee__Base_~bob___0#1, setup_bob__wrappee__Base_~bob___0#1); {25649#(and (= |old(~__ste_client_idCounter0~0)| ~__ste_client_idCounter0~0) (= |old(~__ste_client_idCounter1~0)| ~__ste_client_idCounter1~0) (= |old(~__ste_client_idCounter2~0)| ~__ste_client_idCounter2~0))} is VALID [2022-02-20 18:00:43,841 INFO L290 TraceCheckUtils]: 7: Hoare triple {25649#(and (= |old(~__ste_client_idCounter0~0)| ~__ste_client_idCounter0~0) (= |old(~__ste_client_idCounter1~0)| ~__ste_client_idCounter1~0) (= |old(~__ste_client_idCounter2~0)| ~__ste_client_idCounter2~0))} ~handle := #in~handle;~value := #in~value; {25583#true} is VALID [2022-02-20 18:00:43,842 INFO L290 TraceCheckUtils]: 8: Hoare triple {25583#true} assume 1 == ~handle;~__ste_client_idCounter0~0 := ~value; {25583#true} is VALID [2022-02-20 18:00:43,842 INFO L290 TraceCheckUtils]: 9: Hoare triple {25583#true} assume true; {25583#true} is VALID [2022-02-20 18:00:43,842 INFO L284 TraceCheckUtils]: 10: Hoare quadruple {25583#true} {25583#true} #1134#return; {25583#true} is VALID [2022-02-20 18:00:43,842 INFO L290 TraceCheckUtils]: 11: Hoare triple {25583#true} assume { :end_inline_setup_bob__wrappee__Base } true; {25583#true} is VALID [2022-02-20 18:00:43,843 INFO L272 TraceCheckUtils]: 12: Hoare triple {25583#true} call setClientPrivateKey(setup_bob_~bob___0#1, 123); {25650#(and (= ~__ste_client_privateKey0~0 |old(~__ste_client_privateKey0~0)|) (= ~__ste_client_privateKey2~0 |old(~__ste_client_privateKey2~0)|) (= ~__ste_client_privateKey1~0 |old(~__ste_client_privateKey1~0)|))} is VALID [2022-02-20 18:00:43,843 INFO L290 TraceCheckUtils]: 13: Hoare triple {25650#(and (= ~__ste_client_privateKey0~0 |old(~__ste_client_privateKey0~0)|) (= ~__ste_client_privateKey2~0 |old(~__ste_client_privateKey2~0)|) (= ~__ste_client_privateKey1~0 |old(~__ste_client_privateKey1~0)|))} ~handle := #in~handle;~value := #in~value; {25583#true} is VALID [2022-02-20 18:00:43,843 INFO L290 TraceCheckUtils]: 14: Hoare triple {25583#true} assume 1 == ~handle;~__ste_client_privateKey0~0 := ~value; {25583#true} is VALID [2022-02-20 18:00:43,843 INFO L290 TraceCheckUtils]: 15: Hoare triple {25583#true} assume true; {25583#true} is VALID [2022-02-20 18:00:43,843 INFO L284 TraceCheckUtils]: 16: Hoare quadruple {25583#true} {25583#true} #1136#return; {25583#true} is VALID [2022-02-20 18:00:43,843 INFO L290 TraceCheckUtils]: 17: Hoare triple {25583#true} assume { :end_inline_setup_bob } true;setup_~__cil_tmp1~0#1.base, setup_~__cil_tmp1~0#1.offset := 18, 0;havoc setup_#t~nondet32#1;~rjh~0 := 2;assume { :begin_inline_setup_rjh } true;setup_rjh_#in~rjh___0#1 := ~rjh~0;havoc setup_rjh_~rjh___0#1;setup_rjh_~rjh___0#1 := setup_rjh_#in~rjh___0#1;assume { :begin_inline_setup_rjh__wrappee__Base } true;setup_rjh__wrappee__Base_#in~rjh___0#1 := setup_rjh_~rjh___0#1;havoc setup_rjh__wrappee__Base_~rjh___0#1;setup_rjh__wrappee__Base_~rjh___0#1 := setup_rjh__wrappee__Base_#in~rjh___0#1; {25583#true} is VALID [2022-02-20 18:00:43,844 INFO L272 TraceCheckUtils]: 18: Hoare triple {25583#true} call setClientId(setup_rjh__wrappee__Base_~rjh___0#1, setup_rjh__wrappee__Base_~rjh___0#1); {25649#(and (= |old(~__ste_client_idCounter0~0)| ~__ste_client_idCounter0~0) (= |old(~__ste_client_idCounter1~0)| ~__ste_client_idCounter1~0) (= |old(~__ste_client_idCounter2~0)| ~__ste_client_idCounter2~0))} is VALID [2022-02-20 18:00:43,844 INFO L290 TraceCheckUtils]: 19: Hoare triple {25649#(and (= |old(~__ste_client_idCounter0~0)| ~__ste_client_idCounter0~0) (= |old(~__ste_client_idCounter1~0)| ~__ste_client_idCounter1~0) (= |old(~__ste_client_idCounter2~0)| ~__ste_client_idCounter2~0))} ~handle := #in~handle;~value := #in~value; {25583#true} is VALID [2022-02-20 18:00:43,844 INFO L290 TraceCheckUtils]: 20: Hoare triple {25583#true} assume !(1 == ~handle); {25583#true} is VALID [2022-02-20 18:00:43,844 INFO L290 TraceCheckUtils]: 21: Hoare triple {25583#true} assume 2 == ~handle;~__ste_client_idCounter1~0 := ~value; {25583#true} is VALID [2022-02-20 18:00:43,844 INFO L290 TraceCheckUtils]: 22: Hoare triple {25583#true} assume true; {25583#true} is VALID [2022-02-20 18:00:43,845 INFO L284 TraceCheckUtils]: 23: Hoare quadruple {25583#true} {25583#true} #1138#return; {25583#true} is VALID [2022-02-20 18:00:43,845 INFO L290 TraceCheckUtils]: 24: Hoare triple {25583#true} assume { :end_inline_setup_rjh__wrappee__Base } true; {25583#true} is VALID [2022-02-20 18:00:43,845 INFO L272 TraceCheckUtils]: 25: Hoare triple {25583#true} call setClientPrivateKey(setup_rjh_~rjh___0#1, 456); {25650#(and (= ~__ste_client_privateKey0~0 |old(~__ste_client_privateKey0~0)|) (= ~__ste_client_privateKey2~0 |old(~__ste_client_privateKey2~0)|) (= ~__ste_client_privateKey1~0 |old(~__ste_client_privateKey1~0)|))} is VALID [2022-02-20 18:00:43,845 INFO L290 TraceCheckUtils]: 26: Hoare triple {25650#(and (= ~__ste_client_privateKey0~0 |old(~__ste_client_privateKey0~0)|) (= ~__ste_client_privateKey2~0 |old(~__ste_client_privateKey2~0)|) (= ~__ste_client_privateKey1~0 |old(~__ste_client_privateKey1~0)|))} ~handle := #in~handle;~value := #in~value; {25583#true} is VALID [2022-02-20 18:00:43,846 INFO L290 TraceCheckUtils]: 27: Hoare triple {25583#true} assume !(1 == ~handle); {25583#true} is VALID [2022-02-20 18:00:43,846 INFO L290 TraceCheckUtils]: 28: Hoare triple {25583#true} assume 2 == ~handle;~__ste_client_privateKey1~0 := ~value; {25583#true} is VALID [2022-02-20 18:00:43,846 INFO L290 TraceCheckUtils]: 29: Hoare triple {25583#true} assume true; {25583#true} is VALID [2022-02-20 18:00:43,846 INFO L284 TraceCheckUtils]: 30: Hoare quadruple {25583#true} {25583#true} #1140#return; {25583#true} is VALID [2022-02-20 18:00:43,846 INFO L290 TraceCheckUtils]: 31: Hoare triple {25583#true} assume { :end_inline_setup_rjh } true;setup_~__cil_tmp2~0#1.base, setup_~__cil_tmp2~0#1.offset := 19, 0;havoc setup_#t~nondet33#1;~chuck~0 := 3;assume { :begin_inline_setup_chuck } true;setup_chuck_#in~chuck___0#1 := ~chuck~0;havoc setup_chuck_~chuck___0#1;setup_chuck_~chuck___0#1 := setup_chuck_#in~chuck___0#1;assume { :begin_inline_setup_chuck__wrappee__Base } true;setup_chuck__wrappee__Base_#in~chuck___0#1 := setup_chuck_~chuck___0#1;havoc setup_chuck__wrappee__Base_~chuck___0#1;setup_chuck__wrappee__Base_~chuck___0#1 := setup_chuck__wrappee__Base_#in~chuck___0#1; {25603#(= |ULTIMATE.start_setup_chuck_~chuck___0#1| |ULTIMATE.start_setup_chuck__wrappee__Base_~chuck___0#1|)} is VALID [2022-02-20 18:00:43,847 INFO L272 TraceCheckUtils]: 32: Hoare triple {25603#(= |ULTIMATE.start_setup_chuck_~chuck___0#1| |ULTIMATE.start_setup_chuck__wrappee__Base_~chuck___0#1|)} call setClientId(setup_chuck__wrappee__Base_~chuck___0#1, setup_chuck__wrappee__Base_~chuck___0#1); {25649#(and (= |old(~__ste_client_idCounter0~0)| ~__ste_client_idCounter0~0) (= |old(~__ste_client_idCounter1~0)| ~__ste_client_idCounter1~0) (= |old(~__ste_client_idCounter2~0)| ~__ste_client_idCounter2~0))} is VALID [2022-02-20 18:00:43,848 INFO L290 TraceCheckUtils]: 33: Hoare triple {25649#(and (= |old(~__ste_client_idCounter0~0)| ~__ste_client_idCounter0~0) (= |old(~__ste_client_idCounter1~0)| ~__ste_client_idCounter1~0) (= |old(~__ste_client_idCounter2~0)| ~__ste_client_idCounter2~0))} ~handle := #in~handle;~value := #in~value; {25651#(= setClientId_~handle |setClientId_#in~handle|)} is VALID [2022-02-20 18:00:43,848 INFO L290 TraceCheckUtils]: 34: Hoare triple {25651#(= setClientId_~handle |setClientId_#in~handle|)} assume !(1 == ~handle); {25651#(= setClientId_~handle |setClientId_#in~handle|)} is VALID [2022-02-20 18:00:43,848 INFO L290 TraceCheckUtils]: 35: Hoare triple {25651#(= setClientId_~handle |setClientId_#in~handle|)} assume !(2 == ~handle); {25651#(= setClientId_~handle |setClientId_#in~handle|)} is VALID [2022-02-20 18:00:43,849 INFO L290 TraceCheckUtils]: 36: Hoare triple {25651#(= setClientId_~handle |setClientId_#in~handle|)} assume 3 == ~handle;~__ste_client_idCounter2~0 := ~value; {25652#(= 3 |setClientId_#in~handle|)} is VALID [2022-02-20 18:00:43,849 INFO L290 TraceCheckUtils]: 37: Hoare triple {25652#(= 3 |setClientId_#in~handle|)} assume true; {25652#(= 3 |setClientId_#in~handle|)} is VALID [2022-02-20 18:00:43,849 INFO L284 TraceCheckUtils]: 38: Hoare quadruple {25652#(= 3 |setClientId_#in~handle|)} {25603#(= |ULTIMATE.start_setup_chuck_~chuck___0#1| |ULTIMATE.start_setup_chuck__wrappee__Base_~chuck___0#1|)} #1142#return; {25610#(not (= |ULTIMATE.start_setup_chuck_~chuck___0#1| 2))} is VALID [2022-02-20 18:00:43,850 INFO L290 TraceCheckUtils]: 39: Hoare triple {25610#(not (= |ULTIMATE.start_setup_chuck_~chuck___0#1| 2))} assume { :end_inline_setup_chuck__wrappee__Base } true; {25610#(not (= |ULTIMATE.start_setup_chuck_~chuck___0#1| 2))} is VALID [2022-02-20 18:00:43,850 INFO L272 TraceCheckUtils]: 40: Hoare triple {25610#(not (= |ULTIMATE.start_setup_chuck_~chuck___0#1| 2))} call setClientPrivateKey(setup_chuck_~chuck___0#1, 789); {25650#(and (= ~__ste_client_privateKey0~0 |old(~__ste_client_privateKey0~0)|) (= ~__ste_client_privateKey2~0 |old(~__ste_client_privateKey2~0)|) (= ~__ste_client_privateKey1~0 |old(~__ste_client_privateKey1~0)|))} is VALID [2022-02-20 18:00:43,851 INFO L290 TraceCheckUtils]: 41: Hoare triple {25650#(and (= ~__ste_client_privateKey0~0 |old(~__ste_client_privateKey0~0)|) (= ~__ste_client_privateKey2~0 |old(~__ste_client_privateKey2~0)|) (= ~__ste_client_privateKey1~0 |old(~__ste_client_privateKey1~0)|))} ~handle := #in~handle;~value := #in~value; {25653#(= setClientPrivateKey_~handle |setClientPrivateKey_#in~handle|)} is VALID [2022-02-20 18:00:43,851 INFO L290 TraceCheckUtils]: 42: Hoare triple {25653#(= setClientPrivateKey_~handle |setClientPrivateKey_#in~handle|)} assume !(1 == ~handle); {25653#(= setClientPrivateKey_~handle |setClientPrivateKey_#in~handle|)} is VALID [2022-02-20 18:00:43,851 INFO L290 TraceCheckUtils]: 43: Hoare triple {25653#(= setClientPrivateKey_~handle |setClientPrivateKey_#in~handle|)} assume 2 == ~handle;~__ste_client_privateKey1~0 := ~value; {25654#(= 2 |setClientPrivateKey_#in~handle|)} is VALID [2022-02-20 18:00:43,852 INFO L290 TraceCheckUtils]: 44: Hoare triple {25654#(= 2 |setClientPrivateKey_#in~handle|)} assume true; {25654#(= 2 |setClientPrivateKey_#in~handle|)} is VALID [2022-02-20 18:00:43,852 INFO L284 TraceCheckUtils]: 45: Hoare quadruple {25654#(= 2 |setClientPrivateKey_#in~handle|)} {25610#(not (= |ULTIMATE.start_setup_chuck_~chuck___0#1| 2))} #1144#return; {25584#false} is VALID [2022-02-20 18:00:43,852 INFO L290 TraceCheckUtils]: 46: Hoare triple {25584#false} assume { :end_inline_setup_chuck } true;setup_~__cil_tmp3~0#1.base, setup_~__cil_tmp3~0#1.offset := 20, 0;havoc setup_#t~nondet34#1; {25584#false} is VALID [2022-02-20 18:00:43,853 INFO L290 TraceCheckUtils]: 47: Hoare triple {25584#false} assume { :end_inline_setup } true;assume { :begin_inline_test } true;havoc test_#t~nondet47#1, test_#t~nondet48#1, test_#t~nondet49#1, test_#t~nondet50#1, test_#t~nondet51#1, test_#t~nondet52#1, test_#t~nondet53#1, test_#t~nondet54#1, test_#t~nondet55#1, test_#t~nondet56#1, test_#t~nondet57#1, test_~op1~0#1, test_~op2~0#1, test_~op3~0#1, test_~op4~0#1, test_~op5~0#1, test_~op6~0#1, test_~op7~0#1, test_~op8~0#1, test_~op9~0#1, test_~op10~0#1, test_~op11~0#1, test_~splverifierCounter~0#1, test_~tmp~6#1, test_~tmp___0~2#1, test_~tmp___1~1#1, test_~tmp___2~0#1, test_~tmp___3~0#1, test_~tmp___4~0#1, test_~tmp___5~0#1, test_~tmp___6~0#1, test_~tmp___7~0#1, test_~tmp___8~0#1, test_~tmp___9~0#1;havoc test_~op1~0#1;havoc test_~op2~0#1;havoc test_~op3~0#1;havoc test_~op4~0#1;havoc test_~op5~0#1;havoc test_~op6~0#1;havoc test_~op7~0#1;havoc test_~op8~0#1;havoc test_~op9~0#1;havoc test_~op10~0#1;havoc test_~op11~0#1;havoc test_~splverifierCounter~0#1;havoc test_~tmp~6#1;havoc test_~tmp___0~2#1;havoc test_~tmp___1~1#1;havoc test_~tmp___2~0#1;havoc test_~tmp___3~0#1;havoc test_~tmp___4~0#1;havoc test_~tmp___5~0#1;havoc test_~tmp___6~0#1;havoc test_~tmp___7~0#1;havoc test_~tmp___8~0#1;havoc test_~tmp___9~0#1;test_~op1~0#1 := 0;test_~op2~0#1 := 0;test_~op3~0#1 := 0;test_~op4~0#1 := 0;test_~op5~0#1 := 0;test_~op6~0#1 := 0;test_~op7~0#1 := 0;test_~op8~0#1 := 0;test_~op9~0#1 := 0;test_~op10~0#1 := 0;test_~op11~0#1 := 0;test_~splverifierCounter~0#1 := 0; {25584#false} is VALID [2022-02-20 18:00:43,853 INFO L290 TraceCheckUtils]: 48: Hoare triple {25584#false} assume !false; {25584#false} is VALID [2022-02-20 18:00:43,853 INFO L290 TraceCheckUtils]: 49: Hoare triple {25584#false} assume test_~splverifierCounter~0#1 < 4; {25584#false} is VALID [2022-02-20 18:00:43,853 INFO L290 TraceCheckUtils]: 50: Hoare triple {25584#false} test_~splverifierCounter~0#1 := 1 + test_~splverifierCounter~0#1; {25584#false} is VALID [2022-02-20 18:00:43,853 INFO L290 TraceCheckUtils]: 51: Hoare triple {25584#false} assume 0 == test_~op1~0#1;assume -2147483648 <= test_#t~nondet47#1 && test_#t~nondet47#1 <= 2147483647;test_~tmp___9~0#1 := test_#t~nondet47#1;havoc test_#t~nondet47#1; {25584#false} is VALID [2022-02-20 18:00:43,853 INFO L290 TraceCheckUtils]: 52: Hoare triple {25584#false} assume !(0 != test_~tmp___9~0#1); {25584#false} is VALID [2022-02-20 18:00:43,853 INFO L290 TraceCheckUtils]: 53: Hoare triple {25584#false} assume 0 == test_~op2~0#1;assume -2147483648 <= test_#t~nondet48#1 && test_#t~nondet48#1 <= 2147483647;test_~tmp___8~0#1 := test_#t~nondet48#1;havoc test_#t~nondet48#1; {25584#false} is VALID [2022-02-20 18:00:43,854 INFO L290 TraceCheckUtils]: 54: Hoare triple {25584#false} assume 0 != test_~tmp___8~0#1;assume { :begin_inline_rjhSetAutoRespond } true;assume { :begin_inline_setClientAutoResponse } true;setClientAutoResponse_#in~handle#1, setClientAutoResponse_#in~value#1 := ~rjh~0, 1;havoc setClientAutoResponse_~handle#1, setClientAutoResponse_~value#1;setClientAutoResponse_~handle#1 := setClientAutoResponse_#in~handle#1;setClientAutoResponse_~value#1 := setClientAutoResponse_#in~value#1; {25584#false} is VALID [2022-02-20 18:00:43,854 INFO L290 TraceCheckUtils]: 55: Hoare triple {25584#false} assume 1 == setClientAutoResponse_~handle#1;~__ste_client_autoResponse0~0 := setClientAutoResponse_~value#1; {25584#false} is VALID [2022-02-20 18:00:43,854 INFO L290 TraceCheckUtils]: 56: Hoare triple {25584#false} assume { :end_inline_setClientAutoResponse } true; {25584#false} is VALID [2022-02-20 18:00:43,854 INFO L290 TraceCheckUtils]: 57: Hoare triple {25584#false} assume { :end_inline_rjhSetAutoRespond } true;test_~op2~0#1 := 1; {25584#false} is VALID [2022-02-20 18:00:43,854 INFO L290 TraceCheckUtils]: 58: Hoare triple {25584#false} assume !false; {25584#false} is VALID [2022-02-20 18:00:43,854 INFO L290 TraceCheckUtils]: 59: Hoare triple {25584#false} assume !(test_~splverifierCounter~0#1 < 4); {25584#false} is VALID [2022-02-20 18:00:43,854 INFO L290 TraceCheckUtils]: 60: Hoare triple {25584#false} assume { :begin_inline_bobToRjh } true;havoc bobToRjh_#t~ret27#1, bobToRjh_#t~ret28#1, bobToRjh_#t~ret29#1, bobToRjh_#t~ret30#1, bobToRjh_~tmp~3#1, bobToRjh_~tmp___0~0#1, bobToRjh_~tmp___1~0#1;havoc bobToRjh_~tmp~3#1;havoc bobToRjh_~tmp___0~0#1;havoc bobToRjh_~tmp___1~0#1;call bobToRjh_#t~ret27#1 := puts(16, 0);assume -2147483648 <= bobToRjh_#t~ret27#1 && bobToRjh_#t~ret27#1 <= 2147483647;havoc bobToRjh_#t~ret27#1; {25584#false} is VALID [2022-02-20 18:00:43,854 INFO L272 TraceCheckUtils]: 61: Hoare triple {25584#false} call sendEmail(~bob~0, ~rjh~0); {25584#false} is VALID [2022-02-20 18:00:43,855 INFO L290 TraceCheckUtils]: 62: Hoare triple {25584#false} ~sender#1 := #in~sender#1;~receiver#1 := #in~receiver#1;havoc ~email~0#1;havoc ~tmp~14#1;assume { :begin_inline_createEmail } true;createEmail_#in~from#1, createEmail_#in~to#1 := 0, ~receiver#1;havoc createEmail_#res#1;havoc createEmail_~from#1, createEmail_~to#1, createEmail_~retValue_acc~31#1, createEmail_~msg~0#1;createEmail_~from#1 := createEmail_#in~from#1;createEmail_~to#1 := createEmail_#in~to#1;havoc createEmail_~retValue_acc~31#1;havoc createEmail_~msg~0#1;createEmail_~msg~0#1 := 1; {25584#false} is VALID [2022-02-20 18:00:43,855 INFO L272 TraceCheckUtils]: 63: Hoare triple {25584#false} call setEmailFrom(createEmail_~msg~0#1, createEmail_~from#1); {25655#(and (= |old(~__ste_email_from0~0)| ~__ste_email_from0~0) (= |old(~__ste_email_from1~0)| ~__ste_email_from1~0))} is VALID [2022-02-20 18:00:43,855 INFO L290 TraceCheckUtils]: 64: Hoare triple {25655#(and (= |old(~__ste_email_from0~0)| ~__ste_email_from0~0) (= |old(~__ste_email_from1~0)| ~__ste_email_from1~0))} ~handle := #in~handle;~value := #in~value; {25583#true} is VALID [2022-02-20 18:00:43,855 INFO L290 TraceCheckUtils]: 65: Hoare triple {25583#true} assume 1 == ~handle;~__ste_email_from0~0 := ~value; {25583#true} is VALID [2022-02-20 18:00:43,855 INFO L290 TraceCheckUtils]: 66: Hoare triple {25583#true} assume true; {25583#true} is VALID [2022-02-20 18:00:43,855 INFO L284 TraceCheckUtils]: 67: Hoare quadruple {25583#true} {25584#false} #1120#return; {25584#false} is VALID [2022-02-20 18:00:43,855 INFO L272 TraceCheckUtils]: 68: Hoare triple {25584#false} call setEmailTo(createEmail_~msg~0#1, createEmail_~to#1); {25656#(and (= ~__ste_email_to0~0 |old(~__ste_email_to0~0)|) (= ~__ste_email_to1~0 |old(~__ste_email_to1~0)|))} is VALID [2022-02-20 18:00:43,856 INFO L290 TraceCheckUtils]: 69: Hoare triple {25656#(and (= ~__ste_email_to0~0 |old(~__ste_email_to0~0)|) (= ~__ste_email_to1~0 |old(~__ste_email_to1~0)|))} ~handle := #in~handle;~value := #in~value; {25583#true} is VALID [2022-02-20 18:00:43,856 INFO L290 TraceCheckUtils]: 70: Hoare triple {25583#true} assume 1 == ~handle;~__ste_email_to0~0 := ~value; {25583#true} is VALID [2022-02-20 18:00:43,856 INFO L290 TraceCheckUtils]: 71: Hoare triple {25583#true} assume true; {25583#true} is VALID [2022-02-20 18:00:43,856 INFO L284 TraceCheckUtils]: 72: Hoare quadruple {25583#true} {25584#false} #1122#return; {25584#false} is VALID [2022-02-20 18:00:43,856 INFO L290 TraceCheckUtils]: 73: Hoare triple {25584#false} createEmail_~retValue_acc~31#1 := createEmail_~msg~0#1;createEmail_#res#1 := createEmail_~retValue_acc~31#1; {25584#false} is VALID [2022-02-20 18:00:43,856 INFO L290 TraceCheckUtils]: 74: Hoare triple {25584#false} #t~ret72#1 := createEmail_#res#1;assume { :end_inline_createEmail } true;assume -2147483648 <= #t~ret72#1 && #t~ret72#1 <= 2147483647;~tmp~14#1 := #t~ret72#1;havoc #t~ret72#1;~email~0#1 := ~tmp~14#1; {25584#false} is VALID [2022-02-20 18:00:43,856 INFO L272 TraceCheckUtils]: 75: Hoare triple {25584#false} call outgoing(~sender#1, ~email~0#1); {25584#false} is VALID [2022-02-20 18:00:43,856 INFO L290 TraceCheckUtils]: 76: Hoare triple {25584#false} ~client#1 := #in~client#1;~msg#1 := #in~msg#1;assume { :begin_inline_sign } true;sign_#in~client#1, sign_#in~msg#1 := ~client#1, ~msg#1;havoc sign_#t~ret76#1, sign_~client#1, sign_~msg#1, sign_~privkey~1#1, sign_~tmp~16#1;sign_~client#1 := sign_#in~client#1;sign_~msg#1 := sign_#in~msg#1;havoc sign_~privkey~1#1;havoc sign_~tmp~16#1; {25584#false} is VALID [2022-02-20 18:00:43,857 INFO L272 TraceCheckUtils]: 77: Hoare triple {25584#false} call sign_#t~ret76#1 := getClientPrivateKey(sign_~client#1); {25583#true} is VALID [2022-02-20 18:00:43,857 INFO L290 TraceCheckUtils]: 78: Hoare triple {25583#true} ~handle := #in~handle;havoc ~retValue_acc~20; {25583#true} is VALID [2022-02-20 18:00:43,857 INFO L290 TraceCheckUtils]: 79: Hoare triple {25583#true} assume 1 == ~handle;~retValue_acc~20 := ~__ste_client_privateKey0~0;#res := ~retValue_acc~20; {25583#true} is VALID [2022-02-20 18:00:43,857 INFO L290 TraceCheckUtils]: 80: Hoare triple {25583#true} assume true; {25583#true} is VALID [2022-02-20 18:00:43,857 INFO L284 TraceCheckUtils]: 81: Hoare quadruple {25583#true} {25584#false} #1054#return; {25584#false} is VALID [2022-02-20 18:00:43,857 INFO L290 TraceCheckUtils]: 82: Hoare triple {25584#false} assume -2147483648 <= sign_#t~ret76#1 && sign_#t~ret76#1 <= 2147483647;sign_~tmp~16#1 := sign_#t~ret76#1;havoc sign_#t~ret76#1;sign_~privkey~1#1 := sign_~tmp~16#1; {25584#false} is VALID [2022-02-20 18:00:43,857 INFO L290 TraceCheckUtils]: 83: Hoare triple {25584#false} assume 0 == sign_~privkey~1#1; {25584#false} is VALID [2022-02-20 18:00:43,858 INFO L290 TraceCheckUtils]: 84: Hoare triple {25584#false} assume { :end_inline_sign } true;assume { :begin_inline_outgoing__wrappee__AutoResponder } true;outgoing__wrappee__AutoResponder_#in~client#1, outgoing__wrappee__AutoResponder_#in~msg#1 := ~client#1, ~msg#1;havoc outgoing__wrappee__AutoResponder_#t~ret62#1, outgoing__wrappee__AutoResponder_#t~ret63#1, outgoing__wrappee__AutoResponder_~client#1, outgoing__wrappee__AutoResponder_~msg#1, outgoing__wrappee__AutoResponder_~receiver~0#1, outgoing__wrappee__AutoResponder_~tmp~9#1, outgoing__wrappee__AutoResponder_~pubkey~0#1, outgoing__wrappee__AutoResponder_~tmp___0~3#1;outgoing__wrappee__AutoResponder_~client#1 := outgoing__wrappee__AutoResponder_#in~client#1;outgoing__wrappee__AutoResponder_~msg#1 := outgoing__wrappee__AutoResponder_#in~msg#1;havoc outgoing__wrappee__AutoResponder_~receiver~0#1;havoc outgoing__wrappee__AutoResponder_~tmp~9#1;havoc outgoing__wrappee__AutoResponder_~pubkey~0#1;havoc outgoing__wrappee__AutoResponder_~tmp___0~3#1; {25584#false} is VALID [2022-02-20 18:00:43,858 INFO L272 TraceCheckUtils]: 85: Hoare triple {25584#false} call outgoing__wrappee__AutoResponder_#t~ret62#1 := getEmailTo(outgoing__wrappee__AutoResponder_~msg#1); {25583#true} is VALID [2022-02-20 18:00:43,858 INFO L290 TraceCheckUtils]: 86: Hoare triple {25583#true} ~handle := #in~handle;havoc ~retValue_acc~36; {25583#true} is VALID [2022-02-20 18:00:43,858 INFO L290 TraceCheckUtils]: 87: Hoare triple {25583#true} assume 1 == ~handle;~retValue_acc~36 := ~__ste_email_to0~0;#res := ~retValue_acc~36; {25583#true} is VALID [2022-02-20 18:00:43,858 INFO L290 TraceCheckUtils]: 88: Hoare triple {25583#true} assume true; {25583#true} is VALID [2022-02-20 18:00:43,858 INFO L284 TraceCheckUtils]: 89: Hoare quadruple {25583#true} {25584#false} #1056#return; {25584#false} is VALID [2022-02-20 18:00:43,858 INFO L290 TraceCheckUtils]: 90: Hoare triple {25584#false} assume -2147483648 <= outgoing__wrappee__AutoResponder_#t~ret62#1 && outgoing__wrappee__AutoResponder_#t~ret62#1 <= 2147483647;outgoing__wrappee__AutoResponder_~tmp~9#1 := outgoing__wrappee__AutoResponder_#t~ret62#1;havoc outgoing__wrappee__AutoResponder_#t~ret62#1;outgoing__wrappee__AutoResponder_~receiver~0#1 := outgoing__wrappee__AutoResponder_~tmp~9#1; {25584#false} is VALID [2022-02-20 18:00:43,858 INFO L272 TraceCheckUtils]: 91: Hoare triple {25584#false} call outgoing__wrappee__AutoResponder_#t~ret63#1 := findPublicKey(outgoing__wrappee__AutoResponder_~client#1, outgoing__wrappee__AutoResponder_~receiver~0#1); {25583#true} is VALID [2022-02-20 18:00:43,859 INFO L290 TraceCheckUtils]: 92: Hoare triple {25583#true} ~handle := #in~handle;~userid := #in~userid;havoc ~retValue_acc~25; {25583#true} is VALID [2022-02-20 18:00:43,859 INFO L290 TraceCheckUtils]: 93: Hoare triple {25583#true} assume 1 == ~handle; {25583#true} is VALID [2022-02-20 18:00:43,859 INFO L290 TraceCheckUtils]: 94: Hoare triple {25583#true} assume ~userid == ~__ste_Client_Keyring0_User0~0;~retValue_acc~25 := ~__ste_Client_Keyring0_PublicKey0~0;#res := ~retValue_acc~25; {25583#true} is VALID [2022-02-20 18:00:43,859 INFO L290 TraceCheckUtils]: 95: Hoare triple {25583#true} assume true; {25583#true} is VALID [2022-02-20 18:00:43,859 INFO L284 TraceCheckUtils]: 96: Hoare quadruple {25583#true} {25584#false} #1058#return; {25584#false} is VALID [2022-02-20 18:00:43,859 INFO L290 TraceCheckUtils]: 97: Hoare triple {25584#false} assume -2147483648 <= outgoing__wrappee__AutoResponder_#t~ret63#1 && outgoing__wrappee__AutoResponder_#t~ret63#1 <= 2147483647;outgoing__wrappee__AutoResponder_~tmp___0~3#1 := outgoing__wrappee__AutoResponder_#t~ret63#1;havoc outgoing__wrappee__AutoResponder_#t~ret63#1;outgoing__wrappee__AutoResponder_~pubkey~0#1 := outgoing__wrappee__AutoResponder_~tmp___0~3#1; {25584#false} is VALID [2022-02-20 18:00:43,859 INFO L290 TraceCheckUtils]: 98: Hoare triple {25584#false} assume !(0 != outgoing__wrappee__AutoResponder_~pubkey~0#1); {25584#false} is VALID [2022-02-20 18:00:43,859 INFO L290 TraceCheckUtils]: 99: Hoare triple {25584#false} assume { :begin_inline_outgoing__wrappee__Keys } true;outgoing__wrappee__Keys_#in~client#1, outgoing__wrappee__Keys_#in~msg#1 := outgoing__wrappee__AutoResponder_~client#1, outgoing__wrappee__AutoResponder_~msg#1;havoc outgoing__wrappee__Keys_#t~ret61#1, outgoing__wrappee__Keys_~client#1, outgoing__wrappee__Keys_~msg#1, outgoing__wrappee__Keys_~tmp~8#1;outgoing__wrappee__Keys_~client#1 := outgoing__wrappee__Keys_#in~client#1;outgoing__wrappee__Keys_~msg#1 := outgoing__wrappee__Keys_#in~msg#1;havoc outgoing__wrappee__Keys_~tmp~8#1;assume { :begin_inline_getClientId } true;getClientId_#in~handle#1 := outgoing__wrappee__Keys_~client#1;havoc getClientId_#res#1;havoc getClientId_~handle#1, getClientId_~retValue_acc~27#1;getClientId_~handle#1 := getClientId_#in~handle#1;havoc getClientId_~retValue_acc~27#1; {25584#false} is VALID [2022-02-20 18:00:43,860 INFO L290 TraceCheckUtils]: 100: Hoare triple {25584#false} assume 1 == getClientId_~handle#1;getClientId_~retValue_acc~27#1 := ~__ste_client_idCounter0~0;getClientId_#res#1 := getClientId_~retValue_acc~27#1; {25584#false} is VALID [2022-02-20 18:00:43,860 INFO L290 TraceCheckUtils]: 101: Hoare triple {25584#false} outgoing__wrappee__Keys_#t~ret61#1 := getClientId_#res#1;assume { :end_inline_getClientId } true;assume -2147483648 <= outgoing__wrappee__Keys_#t~ret61#1 && outgoing__wrappee__Keys_#t~ret61#1 <= 2147483647;outgoing__wrappee__Keys_~tmp~8#1 := outgoing__wrappee__Keys_#t~ret61#1;havoc outgoing__wrappee__Keys_#t~ret61#1; {25584#false} is VALID [2022-02-20 18:00:43,860 INFO L272 TraceCheckUtils]: 102: Hoare triple {25584#false} call setEmailFrom(outgoing__wrappee__Keys_~msg#1, outgoing__wrappee__Keys_~tmp~8#1); {25655#(and (= |old(~__ste_email_from0~0)| ~__ste_email_from0~0) (= |old(~__ste_email_from1~0)| ~__ste_email_from1~0))} is VALID [2022-02-20 18:00:43,860 INFO L290 TraceCheckUtils]: 103: Hoare triple {25655#(and (= |old(~__ste_email_from0~0)| ~__ste_email_from0~0) (= |old(~__ste_email_from1~0)| ~__ste_email_from1~0))} ~handle := #in~handle;~value := #in~value; {25583#true} is VALID [2022-02-20 18:00:43,860 INFO L290 TraceCheckUtils]: 104: Hoare triple {25583#true} assume 1 == ~handle;~__ste_email_from0~0 := ~value; {25583#true} is VALID [2022-02-20 18:00:43,860 INFO L290 TraceCheckUtils]: 105: Hoare triple {25583#true} assume true; {25583#true} is VALID [2022-02-20 18:00:43,860 INFO L284 TraceCheckUtils]: 106: Hoare quadruple {25583#true} {25584#false} #1064#return; {25584#false} is VALID [2022-02-20 18:00:43,861 INFO L290 TraceCheckUtils]: 107: Hoare triple {25584#false} assume { :begin_inline_mail } true;mail_#in~client#1, mail_#in~msg#1 := outgoing__wrappee__Keys_~client#1, outgoing__wrappee__Keys_~msg#1;havoc mail_#t~ret59#1, mail_#t~ret60#1, mail_~client#1, mail_~msg#1, mail_~__utac__ad__arg1~0#1, mail_~__utac__ad__arg2~0#1, mail_~tmp~7#1;mail_~client#1 := mail_#in~client#1;mail_~msg#1 := mail_#in~msg#1;havoc mail_~__utac__ad__arg1~0#1;havoc mail_~__utac__ad__arg2~0#1;havoc mail_~tmp~7#1;mail_~__utac__ad__arg1~0#1 := mail_~client#1;mail_~__utac__ad__arg2~0#1 := mail_~msg#1;assume { :begin_inline___utac_acc__SignForward_spec__1 } true;__utac_acc__SignForward_spec__1_#in~client#1, __utac_acc__SignForward_spec__1_#in~msg#1 := mail_~__utac__ad__arg1~0#1, mail_~__utac__ad__arg2~0#1;havoc __utac_acc__SignForward_spec__1_#t~ret107#1, __utac_acc__SignForward_spec__1_#t~ret108#1, __utac_acc__SignForward_spec__1_#t~ret109#1, __utac_acc__SignForward_spec__1_~client#1, __utac_acc__SignForward_spec__1_~msg#1, __utac_acc__SignForward_spec__1_~tmp~25#1, __utac_acc__SignForward_spec__1_~tmp___0~9#1;__utac_acc__SignForward_spec__1_~client#1 := __utac_acc__SignForward_spec__1_#in~client#1;__utac_acc__SignForward_spec__1_~msg#1 := __utac_acc__SignForward_spec__1_#in~msg#1;havoc __utac_acc__SignForward_spec__1_~tmp~25#1;havoc __utac_acc__SignForward_spec__1_~tmp___0~9#1;call __utac_acc__SignForward_spec__1_#t~ret107#1 := puts(39, 0);assume -2147483648 <= __utac_acc__SignForward_spec__1_#t~ret107#1 && __utac_acc__SignForward_spec__1_#t~ret107#1 <= 2147483647;havoc __utac_acc__SignForward_spec__1_#t~ret107#1; {25584#false} is VALID [2022-02-20 18:00:43,861 INFO L272 TraceCheckUtils]: 108: Hoare triple {25584#false} call __utac_acc__SignForward_spec__1_#t~ret108#1 := isSigned(__utac_acc__SignForward_spec__1_~msg#1); {25583#true} is VALID [2022-02-20 18:00:43,861 INFO L290 TraceCheckUtils]: 109: Hoare triple {25583#true} ~handle := #in~handle;havoc ~retValue_acc~41; {25583#true} is VALID [2022-02-20 18:00:43,861 INFO L290 TraceCheckUtils]: 110: Hoare triple {25583#true} assume 1 == ~handle;~retValue_acc~41 := ~__ste_email_isSigned0~0;#res := ~retValue_acc~41; {25583#true} is VALID [2022-02-20 18:00:43,861 INFO L290 TraceCheckUtils]: 111: Hoare triple {25583#true} assume true; {25583#true} is VALID [2022-02-20 18:00:43,861 INFO L284 TraceCheckUtils]: 112: Hoare quadruple {25583#true} {25584#false} #1066#return; {25584#false} is VALID [2022-02-20 18:00:43,861 INFO L290 TraceCheckUtils]: 113: Hoare triple {25584#false} assume -2147483648 <= __utac_acc__SignForward_spec__1_#t~ret108#1 && __utac_acc__SignForward_spec__1_#t~ret108#1 <= 2147483647;__utac_acc__SignForward_spec__1_~tmp___0~9#1 := __utac_acc__SignForward_spec__1_#t~ret108#1;havoc __utac_acc__SignForward_spec__1_#t~ret108#1; {25584#false} is VALID [2022-02-20 18:00:43,861 INFO L290 TraceCheckUtils]: 114: Hoare triple {25584#false} assume 0 != __utac_acc__SignForward_spec__1_~tmp___0~9#1; {25584#false} is VALID [2022-02-20 18:00:43,862 INFO L272 TraceCheckUtils]: 115: Hoare triple {25584#false} call __utac_acc__SignForward_spec__1_#t~ret109#1 := getClientPrivateKey(__utac_acc__SignForward_spec__1_~client#1); {25583#true} is VALID [2022-02-20 18:00:43,862 INFO L290 TraceCheckUtils]: 116: Hoare triple {25583#true} ~handle := #in~handle;havoc ~retValue_acc~20; {25583#true} is VALID [2022-02-20 18:00:43,862 INFO L290 TraceCheckUtils]: 117: Hoare triple {25583#true} assume 1 == ~handle;~retValue_acc~20 := ~__ste_client_privateKey0~0;#res := ~retValue_acc~20; {25583#true} is VALID [2022-02-20 18:00:43,862 INFO L290 TraceCheckUtils]: 118: Hoare triple {25583#true} assume true; {25583#true} is VALID [2022-02-20 18:00:43,862 INFO L284 TraceCheckUtils]: 119: Hoare quadruple {25583#true} {25584#false} #1068#return; {25584#false} is VALID [2022-02-20 18:00:43,862 INFO L290 TraceCheckUtils]: 120: Hoare triple {25584#false} assume -2147483648 <= __utac_acc__SignForward_spec__1_#t~ret109#1 && __utac_acc__SignForward_spec__1_#t~ret109#1 <= 2147483647;__utac_acc__SignForward_spec__1_~tmp~25#1 := __utac_acc__SignForward_spec__1_#t~ret109#1;havoc __utac_acc__SignForward_spec__1_#t~ret109#1; {25584#false} is VALID [2022-02-20 18:00:43,862 INFO L290 TraceCheckUtils]: 121: Hoare triple {25584#false} assume 0 == __utac_acc__SignForward_spec__1_~tmp~25#1;assume { :begin_inline___automaton_fail } true; {25584#false} is VALID [2022-02-20 18:00:43,862 INFO L290 TraceCheckUtils]: 122: Hoare triple {25584#false} assume !false; {25584#false} is VALID [2022-02-20 18:00:43,863 INFO L134 CoverageAnalysis]: Checked inductivity of 36 backedges. 14 proven. 0 refuted. 0 times theorem prover too weak. 22 trivial. 0 not checked. [2022-02-20 18:00:43,863 INFO L144 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2022-02-20 18:00:43,863 INFO L338 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [1732424396] [2022-02-20 18:00:43,863 INFO L165 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [1732424396] provided 1 perfect and 0 imperfect interpolant sequences [2022-02-20 18:00:43,863 INFO L191 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2022-02-20 18:00:43,864 INFO L204 FreeRefinementEngine]: Number of different interpolants: perfect sequences [12] imperfect sequences [] total 12 [2022-02-20 18:00:43,864 INFO L118 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [1751369706] [2022-02-20 18:00:43,864 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2022-02-20 18:00:43,864 INFO L78 Accepts]: Start accepts. Automaton has has 12 states, 11 states have (on average 7.454545454545454) internal successors, (82), 8 states have internal predecessors, (82), 4 states have call successors, (16), 6 states have call predecessors, (16), 3 states have return successors, (14), 3 states have call predecessors, (14), 4 states have call successors, (14) Word has length 123 [2022-02-20 18:00:43,865 INFO L84 Accepts]: Finished accepts. word is accepted. [2022-02-20 18:00:43,865 INFO L86 InductivityCheck]: Starting indutivity check of a Floyd-Hoare automaton with has 12 states, 11 states have (on average 7.454545454545454) internal successors, (82), 8 states have internal predecessors, (82), 4 states have call successors, (16), 6 states have call predecessors, (16), 3 states have return successors, (14), 3 states have call predecessors, (14), 4 states have call successors, (14) [2022-02-20 18:00:43,953 INFO L122 InductivityCheck]: Floyd-Hoare automaton has 112 edges. 112 inductive. 0 not inductive. 0 times theorem prover too weak to decide inductivity. [2022-02-20 18:00:43,953 INFO L546 AbstractCegarLoop]: INTERPOLANT automaton has 12 states [2022-02-20 18:00:43,954 INFO L108 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2022-02-20 18:00:43,954 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 12 interpolants. [2022-02-20 18:00:43,955 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=21, Invalid=111, Unknown=0, NotChecked=0, Total=132 [2022-02-20 18:00:43,955 INFO L87 Difference]: Start difference. First operand 443 states and 667 transitions. Second operand has 12 states, 11 states have (on average 7.454545454545454) internal successors, (82), 8 states have internal predecessors, (82), 4 states have call successors, (16), 6 states have call predecessors, (16), 3 states have return successors, (14), 3 states have call predecessors, (14), 4 states have call successors, (14) [2022-02-20 18:00:57,160 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-02-20 18:00:57,160 INFO L93 Difference]: Finished difference Result 1075 states and 1634 transitions. [2022-02-20 18:00:57,161 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 14 states. [2022-02-20 18:00:57,162 INFO L78 Accepts]: Start accepts. Automaton has has 12 states, 11 states have (on average 7.454545454545454) internal successors, (82), 8 states have internal predecessors, (82), 4 states have call successors, (16), 6 states have call predecessors, (16), 3 states have return successors, (14), 3 states have call predecessors, (14), 4 states have call successors, (14) Word has length 123 [2022-02-20 18:00:57,162 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2022-02-20 18:00:57,162 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 12 states, 11 states have (on average 7.454545454545454) internal successors, (82), 8 states have internal predecessors, (82), 4 states have call successors, (16), 6 states have call predecessors, (16), 3 states have return successors, (14), 3 states have call predecessors, (14), 4 states have call successors, (14) [2022-02-20 18:00:57,174 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 14 states to 14 states and 1431 transitions. [2022-02-20 18:00:57,174 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 12 states, 11 states have (on average 7.454545454545454) internal successors, (82), 8 states have internal predecessors, (82), 4 states have call successors, (16), 6 states have call predecessors, (16), 3 states have return successors, (14), 3 states have call predecessors, (14), 4 states have call successors, (14) [2022-02-20 18:00:57,185 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 14 states to 14 states and 1431 transitions. [2022-02-20 18:00:57,185 INFO L86 InductivityCheck]: Starting indutivity check of a Floyd-Hoare automaton with 14 states and 1431 transitions. [2022-02-20 18:00:58,484 INFO L122 InductivityCheck]: Floyd-Hoare automaton has 1431 edges. 1431 inductive. 0 not inductive. 0 times theorem prover too weak to decide inductivity. [2022-02-20 18:00:58,506 INFO L225 Difference]: With dead ends: 1075 [2022-02-20 18:00:58,507 INFO L226 Difference]: Without dead ends: 659 [2022-02-20 18:00:58,508 INFO L932 BasicCegarLoop]: 0 DeclaredPredicates, 53 GetRequests, 31 SyntacticMatches, 0 SemanticMatches, 22 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 71 ImplicationChecksByTransitivity, 0.2s TimeCoverageRelationStatistics Valid=112, Invalid=440, Unknown=0, NotChecked=0, Total=552 [2022-02-20 18:00:58,510 INFO L933 BasicCegarLoop]: 699 mSDtfsCounter, 1499 mSDsluCounter, 1196 mSDsCounter, 0 mSdLazyCounter, 4705 mSolverCounterSat, 630 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 6.2s Time, 0 mProtectedPredicate, 0 mProtectedAction, 1499 SdHoareTripleChecker+Valid, 1895 SdHoareTripleChecker+Invalid, 5335 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 630 IncrementalHoareTripleChecker+Valid, 4705 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 6.2s IncrementalHoareTripleChecker+Time [2022-02-20 18:00:58,511 INFO L934 BasicCegarLoop]: SdHoareTripleChecker [1499 Valid, 1895 Invalid, 5335 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [630 Valid, 4705 Invalid, 0 Unknown, 0 Unchecked, 6.2s Time] [2022-02-20 18:00:58,511 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 659 states. [2022-02-20 18:00:58,599 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 659 to 445. [2022-02-20 18:00:58,599 INFO L214 AbstractMinimizeNwa]: Start testing correctness of minimizeSevpa [2022-02-20 18:00:58,600 INFO L82 GeneralOperation]: Start isEquivalent. First operand 659 states. Second operand has 445 states, 342 states have (on average 1.5029239766081872) internal successors, (514), 349 states have internal predecessors, (514), 74 states have call successors, (74), 24 states have call predecessors, (74), 28 states have return successors, (85), 73 states have call predecessors, (85), 73 states have call successors, (85) [2022-02-20 18:00:58,600 INFO L74 IsIncluded]: Start isIncluded. First operand 659 states. Second operand has 445 states, 342 states have (on average 1.5029239766081872) internal successors, (514), 349 states have internal predecessors, (514), 74 states have call successors, (74), 24 states have call predecessors, (74), 28 states have return successors, (85), 73 states have call predecessors, (85), 73 states have call successors, (85) [2022-02-20 18:00:58,601 INFO L87 Difference]: Start difference. First operand 659 states. Second operand has 445 states, 342 states have (on average 1.5029239766081872) internal successors, (514), 349 states have internal predecessors, (514), 74 states have call successors, (74), 24 states have call predecessors, (74), 28 states have return successors, (85), 73 states have call predecessors, (85), 73 states have call successors, (85) [2022-02-20 18:00:58,619 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-02-20 18:00:58,619 INFO L93 Difference]: Finished difference Result 659 states and 1003 transitions. [2022-02-20 18:00:58,619 INFO L276 IsEmpty]: Start isEmpty. Operand 659 states and 1003 transitions. [2022-02-20 18:00:58,621 INFO L282 IsEmpty]: Finished isEmpty. No accepting run. [2022-02-20 18:00:58,622 INFO L83 IsIncluded]: Finished isIncluded. Language is included [2022-02-20 18:00:58,622 INFO L74 IsIncluded]: Start isIncluded. First operand has 445 states, 342 states have (on average 1.5029239766081872) internal successors, (514), 349 states have internal predecessors, (514), 74 states have call successors, (74), 24 states have call predecessors, (74), 28 states have return successors, (85), 73 states have call predecessors, (85), 73 states have call successors, (85) Second operand 659 states. [2022-02-20 18:00:58,623 INFO L87 Difference]: Start difference. First operand has 445 states, 342 states have (on average 1.5029239766081872) internal successors, (514), 349 states have internal predecessors, (514), 74 states have call successors, (74), 24 states have call predecessors, (74), 28 states have return successors, (85), 73 states have call predecessors, (85), 73 states have call successors, (85) Second operand 659 states. [2022-02-20 18:00:58,641 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-02-20 18:00:58,642 INFO L93 Difference]: Finished difference Result 659 states and 1003 transitions. [2022-02-20 18:00:58,642 INFO L276 IsEmpty]: Start isEmpty. Operand 659 states and 1003 transitions. [2022-02-20 18:00:58,645 INFO L282 IsEmpty]: Finished isEmpty. No accepting run. [2022-02-20 18:00:58,645 INFO L83 IsIncluded]: Finished isIncluded. Language is included [2022-02-20 18:00:58,645 INFO L88 GeneralOperation]: Finished isEquivalent. [2022-02-20 18:00:58,645 INFO L221 AbstractMinimizeNwa]: Finished testing correctness of minimizeSevpa [2022-02-20 18:00:58,646 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 445 states, 342 states have (on average 1.5029239766081872) internal successors, (514), 349 states have internal predecessors, (514), 74 states have call successors, (74), 24 states have call predecessors, (74), 28 states have return successors, (85), 73 states have call predecessors, (85), 73 states have call successors, (85) [2022-02-20 18:00:58,658 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 445 states to 445 states and 673 transitions. [2022-02-20 18:00:58,658 INFO L78 Accepts]: Start accepts. Automaton has 445 states and 673 transitions. Word has length 123 [2022-02-20 18:00:58,658 INFO L84 Accepts]: Finished accepts. word is rejected. [2022-02-20 18:00:58,658 INFO L470 AbstractCegarLoop]: Abstraction has 445 states and 673 transitions. [2022-02-20 18:00:58,659 INFO L471 AbstractCegarLoop]: INTERPOLANT automaton has has 12 states, 11 states have (on average 7.454545454545454) internal successors, (82), 8 states have internal predecessors, (82), 4 states have call successors, (16), 6 states have call predecessors, (16), 3 states have return successors, (14), 3 states have call predecessors, (14), 4 states have call successors, (14) [2022-02-20 18:00:58,659 INFO L276 IsEmpty]: Start isEmpty. Operand 445 states and 673 transitions. [2022-02-20 18:00:58,660 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 125 [2022-02-20 18:00:58,660 INFO L506 BasicCegarLoop]: Found error trace [2022-02-20 18:00:58,660 INFO L514 BasicCegarLoop]: trace histogram [3, 3, 3, 3, 2, 2, 2, 2, 2, 2, 2, 2, 2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-02-20 18:00:58,660 WARN L452 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable8 [2022-02-20 18:00:58,661 INFO L402 AbstractCegarLoop]: === Iteration 10 === Targeting outgoingErr0ASSERT_VIOLATIONERROR_FUNCTION === [outgoingErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2022-02-20 18:00:58,661 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2022-02-20 18:00:58,661 INFO L85 PathProgramCache]: Analyzing trace with hash 1846600416, now seen corresponding path program 1 times [2022-02-20 18:00:58,662 INFO L126 FreeRefinementEngine]: Executing refinement strategy CAMEL [2022-02-20 18:00:58,662 INFO L338 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [39009898] [2022-02-20 18:00:58,662 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-02-20 18:00:58,662 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2022-02-20 18:00:58,697 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-02-20 18:00:58,731 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 6 [2022-02-20 18:00:58,732 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-02-20 18:00:58,734 INFO L290 TraceCheckUtils]: 0: Hoare triple {29244#(and (= |old(~__ste_client_idCounter0~0)| ~__ste_client_idCounter0~0) (= |old(~__ste_client_idCounter1~0)| ~__ste_client_idCounter1~0) (= |old(~__ste_client_idCounter2~0)| ~__ste_client_idCounter2~0))} ~handle := #in~handle;~value := #in~value; {29176#true} is VALID [2022-02-20 18:00:58,734 INFO L290 TraceCheckUtils]: 1: Hoare triple {29176#true} assume 1 == ~handle;~__ste_client_idCounter0~0 := ~value; {29176#true} is VALID [2022-02-20 18:00:58,734 INFO L290 TraceCheckUtils]: 2: Hoare triple {29176#true} assume true; {29176#true} is VALID [2022-02-20 18:00:58,734 INFO L284 TraceCheckUtils]: 3: Hoare quadruple {29176#true} {29176#true} #1134#return; {29176#true} is VALID [2022-02-20 18:00:58,740 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 12 [2022-02-20 18:00:58,741 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-02-20 18:00:58,743 INFO L290 TraceCheckUtils]: 0: Hoare triple {29245#(and (= ~__ste_client_privateKey0~0 |old(~__ste_client_privateKey0~0)|) (= ~__ste_client_privateKey2~0 |old(~__ste_client_privateKey2~0)|) (= ~__ste_client_privateKey1~0 |old(~__ste_client_privateKey1~0)|))} ~handle := #in~handle;~value := #in~value; {29176#true} is VALID [2022-02-20 18:00:58,743 INFO L290 TraceCheckUtils]: 1: Hoare triple {29176#true} assume 1 == ~handle;~__ste_client_privateKey0~0 := ~value; {29176#true} is VALID [2022-02-20 18:00:58,744 INFO L290 TraceCheckUtils]: 2: Hoare triple {29176#true} assume true; {29176#true} is VALID [2022-02-20 18:00:58,744 INFO L284 TraceCheckUtils]: 3: Hoare quadruple {29176#true} {29176#true} #1136#return; {29176#true} is VALID [2022-02-20 18:00:58,744 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 18 [2022-02-20 18:00:58,746 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-02-20 18:00:58,758 INFO L290 TraceCheckUtils]: 0: Hoare triple {29244#(and (= |old(~__ste_client_idCounter0~0)| ~__ste_client_idCounter0~0) (= |old(~__ste_client_idCounter1~0)| ~__ste_client_idCounter1~0) (= |old(~__ste_client_idCounter2~0)| ~__ste_client_idCounter2~0))} ~handle := #in~handle;~value := #in~value; {29246#(= setClientId_~handle |setClientId_#in~handle|)} is VALID [2022-02-20 18:00:58,758 INFO L290 TraceCheckUtils]: 1: Hoare triple {29246#(= setClientId_~handle |setClientId_#in~handle|)} assume !(1 == ~handle); {29246#(= setClientId_~handle |setClientId_#in~handle|)} is VALID [2022-02-20 18:00:58,759 INFO L290 TraceCheckUtils]: 2: Hoare triple {29246#(= setClientId_~handle |setClientId_#in~handle|)} assume 2 == ~handle;~__ste_client_idCounter1~0 := ~value; {29247#(= 2 |setClientId_#in~handle|)} is VALID [2022-02-20 18:00:58,759 INFO L290 TraceCheckUtils]: 3: Hoare triple {29247#(= 2 |setClientId_#in~handle|)} assume true; {29247#(= 2 |setClientId_#in~handle|)} is VALID [2022-02-20 18:00:58,760 INFO L284 TraceCheckUtils]: 4: Hoare quadruple {29247#(= 2 |setClientId_#in~handle|)} {29186#(= ~rjh~0 |ULTIMATE.start_setup_rjh__wrappee__Base_~rjh___0#1|)} #1138#return; {29192#(not (= ~rjh~0 1))} is VALID [2022-02-20 18:00:58,760 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 25 [2022-02-20 18:00:58,761 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-02-20 18:00:58,764 INFO L290 TraceCheckUtils]: 0: Hoare triple {29245#(and (= ~__ste_client_privateKey0~0 |old(~__ste_client_privateKey0~0)|) (= ~__ste_client_privateKey2~0 |old(~__ste_client_privateKey2~0)|) (= ~__ste_client_privateKey1~0 |old(~__ste_client_privateKey1~0)|))} ~handle := #in~handle;~value := #in~value; {29176#true} is VALID [2022-02-20 18:00:58,764 INFO L290 TraceCheckUtils]: 1: Hoare triple {29176#true} assume !(1 == ~handle); {29176#true} is VALID [2022-02-20 18:00:58,765 INFO L290 TraceCheckUtils]: 2: Hoare triple {29176#true} assume 2 == ~handle;~__ste_client_privateKey1~0 := ~value; {29176#true} is VALID [2022-02-20 18:00:58,765 INFO L290 TraceCheckUtils]: 3: Hoare triple {29176#true} assume true; {29176#true} is VALID [2022-02-20 18:00:58,765 INFO L284 TraceCheckUtils]: 4: Hoare quadruple {29176#true} {29192#(not (= ~rjh~0 1))} #1140#return; {29192#(not (= ~rjh~0 1))} is VALID [2022-02-20 18:00:58,765 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 32 [2022-02-20 18:00:58,767 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-02-20 18:00:58,769 INFO L290 TraceCheckUtils]: 0: Hoare triple {29244#(and (= |old(~__ste_client_idCounter0~0)| ~__ste_client_idCounter0~0) (= |old(~__ste_client_idCounter1~0)| ~__ste_client_idCounter1~0) (= |old(~__ste_client_idCounter2~0)| ~__ste_client_idCounter2~0))} ~handle := #in~handle;~value := #in~value; {29176#true} is VALID [2022-02-20 18:00:58,769 INFO L290 TraceCheckUtils]: 1: Hoare triple {29176#true} assume !(1 == ~handle); {29176#true} is VALID [2022-02-20 18:00:58,769 INFO L290 TraceCheckUtils]: 2: Hoare triple {29176#true} assume !(2 == ~handle); {29176#true} is VALID [2022-02-20 18:00:58,769 INFO L290 TraceCheckUtils]: 3: Hoare triple {29176#true} assume 3 == ~handle;~__ste_client_idCounter2~0 := ~value; {29176#true} is VALID [2022-02-20 18:00:58,769 INFO L290 TraceCheckUtils]: 4: Hoare triple {29176#true} assume true; {29176#true} is VALID [2022-02-20 18:00:58,770 INFO L284 TraceCheckUtils]: 5: Hoare quadruple {29176#true} {29192#(not (= ~rjh~0 1))} #1142#return; {29192#(not (= ~rjh~0 1))} is VALID [2022-02-20 18:00:58,770 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 40 [2022-02-20 18:00:58,771 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-02-20 18:00:58,773 INFO L290 TraceCheckUtils]: 0: Hoare triple {29245#(and (= ~__ste_client_privateKey0~0 |old(~__ste_client_privateKey0~0)|) (= ~__ste_client_privateKey2~0 |old(~__ste_client_privateKey2~0)|) (= ~__ste_client_privateKey1~0 |old(~__ste_client_privateKey1~0)|))} ~handle := #in~handle;~value := #in~value; {29176#true} is VALID [2022-02-20 18:00:58,773 INFO L290 TraceCheckUtils]: 1: Hoare triple {29176#true} assume !(1 == ~handle); {29176#true} is VALID [2022-02-20 18:00:58,773 INFO L290 TraceCheckUtils]: 2: Hoare triple {29176#true} assume !(2 == ~handle); {29176#true} is VALID [2022-02-20 18:00:58,773 INFO L290 TraceCheckUtils]: 3: Hoare triple {29176#true} assume 3 == ~handle;~__ste_client_privateKey2~0 := ~value; {29176#true} is VALID [2022-02-20 18:00:58,773 INFO L290 TraceCheckUtils]: 4: Hoare triple {29176#true} assume true; {29176#true} is VALID [2022-02-20 18:00:58,774 INFO L284 TraceCheckUtils]: 5: Hoare quadruple {29176#true} {29192#(not (= ~rjh~0 1))} #1144#return; {29192#(not (= ~rjh~0 1))} is VALID [2022-02-20 18:00:58,780 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 64 [2022-02-20 18:00:58,781 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-02-20 18:00:58,782 INFO L290 TraceCheckUtils]: 0: Hoare triple {29248#(and (= |old(~__ste_email_from0~0)| ~__ste_email_from0~0) (= |old(~__ste_email_from1~0)| ~__ste_email_from1~0))} ~handle := #in~handle;~value := #in~value; {29176#true} is VALID [2022-02-20 18:00:58,783 INFO L290 TraceCheckUtils]: 1: Hoare triple {29176#true} assume 1 == ~handle;~__ste_email_from0~0 := ~value; {29176#true} is VALID [2022-02-20 18:00:58,783 INFO L290 TraceCheckUtils]: 2: Hoare triple {29176#true} assume true; {29176#true} is VALID [2022-02-20 18:00:58,783 INFO L284 TraceCheckUtils]: 3: Hoare quadruple {29176#true} {29177#false} #1120#return; {29177#false} is VALID [2022-02-20 18:00:58,790 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 69 [2022-02-20 18:00:58,791 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-02-20 18:00:58,792 INFO L290 TraceCheckUtils]: 0: Hoare triple {29249#(and (= ~__ste_email_to0~0 |old(~__ste_email_to0~0)|) (= ~__ste_email_to1~0 |old(~__ste_email_to1~0)|))} ~handle := #in~handle;~value := #in~value; {29176#true} is VALID [2022-02-20 18:00:58,792 INFO L290 TraceCheckUtils]: 1: Hoare triple {29176#true} assume 1 == ~handle;~__ste_email_to0~0 := ~value; {29176#true} is VALID [2022-02-20 18:00:58,793 INFO L290 TraceCheckUtils]: 2: Hoare triple {29176#true} assume true; {29176#true} is VALID [2022-02-20 18:00:58,793 INFO L284 TraceCheckUtils]: 3: Hoare quadruple {29176#true} {29177#false} #1122#return; {29177#false} is VALID [2022-02-20 18:00:58,793 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 78 [2022-02-20 18:00:58,793 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-02-20 18:00:58,794 INFO L290 TraceCheckUtils]: 0: Hoare triple {29176#true} ~handle := #in~handle;havoc ~retValue_acc~20; {29176#true} is VALID [2022-02-20 18:00:58,795 INFO L290 TraceCheckUtils]: 1: Hoare triple {29176#true} assume 1 == ~handle;~retValue_acc~20 := ~__ste_client_privateKey0~0;#res := ~retValue_acc~20; {29176#true} is VALID [2022-02-20 18:00:58,795 INFO L290 TraceCheckUtils]: 2: Hoare triple {29176#true} assume true; {29176#true} is VALID [2022-02-20 18:00:58,795 INFO L284 TraceCheckUtils]: 3: Hoare quadruple {29176#true} {29177#false} #1054#return; {29177#false} is VALID [2022-02-20 18:00:58,795 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 86 [2022-02-20 18:00:58,795 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-02-20 18:00:58,798 INFO L290 TraceCheckUtils]: 0: Hoare triple {29176#true} ~handle := #in~handle;havoc ~retValue_acc~36; {29176#true} is VALID [2022-02-20 18:00:58,798 INFO L290 TraceCheckUtils]: 1: Hoare triple {29176#true} assume 1 == ~handle;~retValue_acc~36 := ~__ste_email_to0~0;#res := ~retValue_acc~36; {29176#true} is VALID [2022-02-20 18:00:58,798 INFO L290 TraceCheckUtils]: 2: Hoare triple {29176#true} assume true; {29176#true} is VALID [2022-02-20 18:00:58,798 INFO L284 TraceCheckUtils]: 3: Hoare quadruple {29176#true} {29177#false} #1056#return; {29177#false} is VALID [2022-02-20 18:00:58,799 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 92 [2022-02-20 18:00:58,800 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-02-20 18:00:58,801 INFO L290 TraceCheckUtils]: 0: Hoare triple {29176#true} ~handle := #in~handle;~userid := #in~userid;havoc ~retValue_acc~25; {29176#true} is VALID [2022-02-20 18:00:58,801 INFO L290 TraceCheckUtils]: 1: Hoare triple {29176#true} assume 1 == ~handle; {29176#true} is VALID [2022-02-20 18:00:58,801 INFO L290 TraceCheckUtils]: 2: Hoare triple {29176#true} assume ~userid == ~__ste_Client_Keyring0_User0~0;~retValue_acc~25 := ~__ste_Client_Keyring0_PublicKey0~0;#res := ~retValue_acc~25; {29176#true} is VALID [2022-02-20 18:00:58,801 INFO L290 TraceCheckUtils]: 3: Hoare triple {29176#true} assume true; {29176#true} is VALID [2022-02-20 18:00:58,802 INFO L284 TraceCheckUtils]: 4: Hoare quadruple {29176#true} {29177#false} #1058#return; {29177#false} is VALID [2022-02-20 18:00:58,802 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 103 [2022-02-20 18:00:58,802 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-02-20 18:00:58,804 INFO L290 TraceCheckUtils]: 0: Hoare triple {29248#(and (= |old(~__ste_email_from0~0)| ~__ste_email_from0~0) (= |old(~__ste_email_from1~0)| ~__ste_email_from1~0))} ~handle := #in~handle;~value := #in~value; {29176#true} is VALID [2022-02-20 18:00:58,804 INFO L290 TraceCheckUtils]: 1: Hoare triple {29176#true} assume 1 == ~handle;~__ste_email_from0~0 := ~value; {29176#true} is VALID [2022-02-20 18:00:58,804 INFO L290 TraceCheckUtils]: 2: Hoare triple {29176#true} assume true; {29176#true} is VALID [2022-02-20 18:00:58,804 INFO L284 TraceCheckUtils]: 3: Hoare quadruple {29176#true} {29177#false} #1064#return; {29177#false} is VALID [2022-02-20 18:00:58,804 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 109 [2022-02-20 18:00:58,805 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-02-20 18:00:58,806 INFO L290 TraceCheckUtils]: 0: Hoare triple {29176#true} ~handle := #in~handle;havoc ~retValue_acc~41; {29176#true} is VALID [2022-02-20 18:00:58,806 INFO L290 TraceCheckUtils]: 1: Hoare triple {29176#true} assume 1 == ~handle;~retValue_acc~41 := ~__ste_email_isSigned0~0;#res := ~retValue_acc~41; {29176#true} is VALID [2022-02-20 18:00:58,806 INFO L290 TraceCheckUtils]: 2: Hoare triple {29176#true} assume true; {29176#true} is VALID [2022-02-20 18:00:58,807 INFO L284 TraceCheckUtils]: 3: Hoare quadruple {29176#true} {29177#false} #1066#return; {29177#false} is VALID [2022-02-20 18:00:58,807 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 116 [2022-02-20 18:00:58,807 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-02-20 18:00:58,808 INFO L290 TraceCheckUtils]: 0: Hoare triple {29176#true} ~handle := #in~handle;havoc ~retValue_acc~20; {29176#true} is VALID [2022-02-20 18:00:58,808 INFO L290 TraceCheckUtils]: 1: Hoare triple {29176#true} assume 1 == ~handle;~retValue_acc~20 := ~__ste_client_privateKey0~0;#res := ~retValue_acc~20; {29176#true} is VALID [2022-02-20 18:00:58,809 INFO L290 TraceCheckUtils]: 2: Hoare triple {29176#true} assume true; {29176#true} is VALID [2022-02-20 18:00:58,809 INFO L284 TraceCheckUtils]: 3: Hoare quadruple {29176#true} {29177#false} #1068#return; {29177#false} is VALID [2022-02-20 18:00:58,809 INFO L290 TraceCheckUtils]: 0: Hoare triple {29176#true} assume { :begin_inline_ULTIMATE.init } true;#NULL.base, #NULL.offset := 0, 0;assume 0 == #valid[0];assume 0 < #StackHeapBarrier;call #Ultimate.allocInit(2, 1);call write~init~int(48, 1, 0, 1);call write~init~int(0, 1, 1, 1);call #Ultimate.allocInit(28, 2);call #Ultimate.allocInit(12, 3);call #Ultimate.allocInit(30, 4);call #Ultimate.allocInit(9, 5);call #Ultimate.allocInit(21, 6);call #Ultimate.allocInit(30, 7);call #Ultimate.allocInit(9, 8);call #Ultimate.allocInit(21, 9);call #Ultimate.allocInit(30, 10);call #Ultimate.allocInit(9, 11);call #Ultimate.allocInit(25, 12);call #Ultimate.allocInit(30, 13);call #Ultimate.allocInit(9, 14);call #Ultimate.allocInit(25, 15);call #Ultimate.allocInit(44, 16);call #Ultimate.allocInit(44, 17);call #Ultimate.allocInit(9, 18);call #Ultimate.allocInit(9, 19);call #Ultimate.allocInit(11, 20);call #Ultimate.allocInit(19, 21);call #Ultimate.allocInit(4, 22);call write~init~int(37, 22, 0, 1);call write~init~int(100, 22, 1, 1);call write~init~int(10, 22, 2, 1);call write~init~int(0, 22, 3, 1);call #Ultimate.allocInit(4, 23);call write~init~int(37, 23, 0, 1);call write~init~int(100, 23, 1, 1);call write~init~int(10, 23, 2, 1);call write~init~int(0, 23, 3, 1);call #Ultimate.allocInit(10, 24);call #Ultimate.allocInit(16, 25);call #Ultimate.allocInit(20, 26);call #Ultimate.allocInit(22, 27);call #Ultimate.allocInit(21, 28);call #Ultimate.allocInit(10, 29);call #Ultimate.allocInit(12, 30);call #Ultimate.allocInit(10, 31);call #Ultimate.allocInit(18, 32);call #Ultimate.allocInit(16, 33);call #Ultimate.allocInit(21, 34);call #Ultimate.allocInit(13, 35);call #Ultimate.allocInit(16, 36);call #Ultimate.allocInit(25, 37);call #Ultimate.allocInit(4, 38);call write~init~int(37, 38, 0, 1);call write~init~int(115, 38, 1, 1);call write~init~int(10, 38, 2, 1);call write~init~int(0, 38, 3, 1);call #Ultimate.allocInit(13, 39);~head~0.base, ~head~0.offset := 0, 0;~__SELECTED_FEATURE_Base~0 := 0;~__SELECTED_FEATURE_Keys~0 := 0;~__SELECTED_FEATURE_Encrypt~0 := 0;~__SELECTED_FEATURE_AutoResponder~0 := 0;~__SELECTED_FEATURE_AddressBook~0 := 0;~__SELECTED_FEATURE_Sign~0 := 0;~__SELECTED_FEATURE_Forward~0 := 0;~__SELECTED_FEATURE_Verify~0 := 0;~__SELECTED_FEATURE_Decrypt~0 := 0;~__GUIDSL_ROOT_PRODUCTION~0 := 0;~__GUIDSL_NON_TERMINAL_main~0 := 0;~bob~0 := 0;~rjh~0 := 0;~chuck~0 := 0;~queue_empty~0 := 1;~queued_message~0 := 0;~queued_client~0 := 0;~__ste_Client_counter~0 := 0;~__ste_client_name0~0.base, ~__ste_client_name0~0.offset := 0, 0;~__ste_client_name1~0.base, ~__ste_client_name1~0.offset := 0, 0;~__ste_client_name2~0.base, ~__ste_client_name2~0.offset := 0, 0;~__ste_client_outbuffer0~0 := 0;~__ste_client_outbuffer1~0 := 0;~__ste_client_outbuffer2~0 := 0;~__ste_client_outbuffer3~0 := 0;~__ste_ClientAddressBook_size0~0 := 0;~__ste_ClientAddressBook_size1~0 := 0;~__ste_ClientAddressBook_size2~0 := 0;~__ste_Client_AddressBook0_Alias0~0 := 0;~__ste_Client_AddressBook0_Alias1~0 := 0;~__ste_Client_AddressBook0_Alias2~0 := 0;~__ste_Client_AddressBook1_Alias0~0 := 0;~__ste_Client_AddressBook1_Alias1~0 := 0;~__ste_Client_AddressBook1_Alias2~0 := 0;~__ste_Client_AddressBook2_Alias0~0 := 0;~__ste_Client_AddressBook2_Alias1~0 := 0;~__ste_Client_AddressBook2_Alias2~0 := 0;~__ste_Client_AddressBook0_Address0~0 := 0;~__ste_Client_AddressBook0_Address1~0 := 0;~__ste_Client_AddressBook0_Address2~0 := 0;~__ste_Client_AddressBook1_Address0~0 := 0;~__ste_Client_AddressBook1_Address1~0 := 0;~__ste_Client_AddressBook1_Address2~0 := 0;~__ste_Client_AddressBook2_Address0~0 := 0;~__ste_Client_AddressBook2_Address1~0 := 0;~__ste_Client_AddressBook2_Address2~0 := 0;~__ste_client_autoResponse0~0 := 0;~__ste_client_autoResponse1~0 := 0;~__ste_client_autoResponse2~0 := 0;~__ste_client_privateKey0~0 := 0;~__ste_client_privateKey1~0 := 0;~__ste_client_privateKey2~0 := 0;~__ste_ClientKeyring_size0~0 := 0;~__ste_ClientKeyring_size1~0 := 0;~__ste_ClientKeyring_size2~0 := 0;~__ste_Client_Keyring0_User0~0 := 0;~__ste_Client_Keyring0_User1~0 := 0;~__ste_Client_Keyring0_User2~0 := 0;~__ste_Client_Keyring1_User0~0 := 0;~__ste_Client_Keyring1_User1~0 := 0;~__ste_Client_Keyring1_User2~0 := 0;~__ste_Client_Keyring2_User0~0 := 0;~__ste_Client_Keyring2_User1~0 := 0;~__ste_Client_Keyring2_User2~0 := 0;~__ste_Client_Keyring0_PublicKey0~0 := 0;~__ste_Client_Keyring0_PublicKey1~0 := 0;~__ste_Client_Keyring0_PublicKey2~0 := 0;~__ste_Client_Keyring1_PublicKey0~0 := 0;~__ste_Client_Keyring1_PublicKey1~0 := 0;~__ste_Client_Keyring1_PublicKey2~0 := 0;~__ste_Client_Keyring2_PublicKey0~0 := 0;~__ste_Client_Keyring2_PublicKey1~0 := 0;~__ste_Client_Keyring2_PublicKey2~0 := 0;~__ste_client_forwardReceiver0~0 := 0;~__ste_client_forwardReceiver1~0 := 0;~__ste_client_forwardReceiver2~0 := 0;~__ste_client_forwardReceiver3~0 := 0;~__ste_client_idCounter0~0 := 0;~__ste_client_idCounter1~0 := 0;~__ste_client_idCounter2~0 := 0;~__ste_Email_counter~0 := 0;~__ste_email_id0~0 := 0;~__ste_email_id1~0 := 0;~__ste_email_from0~0 := 0;~__ste_email_from1~0 := 0;~__ste_email_to0~0 := 0;~__ste_email_to1~0 := 0;~__ste_email_subject0~0.base, ~__ste_email_subject0~0.offset := 0, 0;~__ste_email_subject1~0.base, ~__ste_email_subject1~0.offset := 0, 0;~__ste_email_body0~0.base, ~__ste_email_body0~0.offset := 0, 0;~__ste_email_body1~0.base, ~__ste_email_body1~0.offset := 0, 0;~__ste_email_isEncrypted0~0 := 0;~__ste_email_isEncrypted1~0 := 0;~__ste_email_encryptionKey0~0 := 0;~__ste_email_encryptionKey1~0 := 0;~__ste_email_isSigned0~0 := 0;~__ste_email_isSigned1~0 := 0;~__ste_email_signKey0~0 := 0;~__ste_email_signKey1~0 := 0;~__ste_email_isSignatureVerified0~0 := 0;~__ste_email_isSignatureVerified1~0 := 0; {29176#true} is VALID [2022-02-20 18:00:58,809 INFO L290 TraceCheckUtils]: 1: Hoare triple {29176#true} assume { :end_inline_ULTIMATE.init } true;assume { :begin_inline_main } true;havoc main_#res#1;havoc main_#t~ret35#1, main_~retValue_acc~3#1, main_~tmp~4#1;havoc main_~retValue_acc~3#1;havoc main_~tmp~4#1;assume { :begin_inline_select_helpers } true; {29176#true} is VALID [2022-02-20 18:00:58,809 INFO L290 TraceCheckUtils]: 2: Hoare triple {29176#true} assume { :end_inline_select_helpers } true;assume { :begin_inline_select_features } true; {29176#true} is VALID [2022-02-20 18:00:58,809 INFO L290 TraceCheckUtils]: 3: Hoare triple {29176#true} assume { :end_inline_select_features } true;assume { :begin_inline_valid_product } true;havoc valid_product_#res#1;havoc valid_product_~retValue_acc~5#1;havoc valid_product_~retValue_acc~5#1;valid_product_~retValue_acc~5#1 := 1;valid_product_#res#1 := valid_product_~retValue_acc~5#1; {29176#true} is VALID [2022-02-20 18:00:58,809 INFO L290 TraceCheckUtils]: 4: Hoare triple {29176#true} main_#t~ret35#1 := valid_product_#res#1;assume { :end_inline_valid_product } true;assume -2147483648 <= main_#t~ret35#1 && main_#t~ret35#1 <= 2147483647;main_~tmp~4#1 := main_#t~ret35#1;havoc main_#t~ret35#1; {29176#true} is VALID [2022-02-20 18:00:58,809 INFO L290 TraceCheckUtils]: 5: Hoare triple {29176#true} assume 0 != main_~tmp~4#1;assume { :begin_inline_setup } true;havoc setup_#t~nondet32#1, setup_#t~nondet33#1, setup_#t~nondet34#1, setup_~__cil_tmp1~0#1.base, setup_~__cil_tmp1~0#1.offset, setup_~__cil_tmp2~0#1.base, setup_~__cil_tmp2~0#1.offset, setup_~__cil_tmp3~0#1.base, setup_~__cil_tmp3~0#1.offset;havoc setup_~__cil_tmp1~0#1.base, setup_~__cil_tmp1~0#1.offset;havoc setup_~__cil_tmp2~0#1.base, setup_~__cil_tmp2~0#1.offset;havoc setup_~__cil_tmp3~0#1.base, setup_~__cil_tmp3~0#1.offset;~bob~0 := 1;assume { :begin_inline_setup_bob } true;setup_bob_#in~bob___0#1 := ~bob~0;havoc setup_bob_~bob___0#1;setup_bob_~bob___0#1 := setup_bob_#in~bob___0#1;assume { :begin_inline_setup_bob__wrappee__Base } true;setup_bob__wrappee__Base_#in~bob___0#1 := setup_bob_~bob___0#1;havoc setup_bob__wrappee__Base_~bob___0#1;setup_bob__wrappee__Base_~bob___0#1 := setup_bob__wrappee__Base_#in~bob___0#1; {29176#true} is VALID [2022-02-20 18:00:58,810 INFO L272 TraceCheckUtils]: 6: Hoare triple {29176#true} call setClientId(setup_bob__wrappee__Base_~bob___0#1, setup_bob__wrappee__Base_~bob___0#1); {29244#(and (= |old(~__ste_client_idCounter0~0)| ~__ste_client_idCounter0~0) (= |old(~__ste_client_idCounter1~0)| ~__ste_client_idCounter1~0) (= |old(~__ste_client_idCounter2~0)| ~__ste_client_idCounter2~0))} is VALID [2022-02-20 18:00:58,810 INFO L290 TraceCheckUtils]: 7: Hoare triple {29244#(and (= |old(~__ste_client_idCounter0~0)| ~__ste_client_idCounter0~0) (= |old(~__ste_client_idCounter1~0)| ~__ste_client_idCounter1~0) (= |old(~__ste_client_idCounter2~0)| ~__ste_client_idCounter2~0))} ~handle := #in~handle;~value := #in~value; {29176#true} is VALID [2022-02-20 18:00:58,810 INFO L290 TraceCheckUtils]: 8: Hoare triple {29176#true} assume 1 == ~handle;~__ste_client_idCounter0~0 := ~value; {29176#true} is VALID [2022-02-20 18:00:58,810 INFO L290 TraceCheckUtils]: 9: Hoare triple {29176#true} assume true; {29176#true} is VALID [2022-02-20 18:00:58,810 INFO L284 TraceCheckUtils]: 10: Hoare quadruple {29176#true} {29176#true} #1134#return; {29176#true} is VALID [2022-02-20 18:00:58,810 INFO L290 TraceCheckUtils]: 11: Hoare triple {29176#true} assume { :end_inline_setup_bob__wrappee__Base } true; {29176#true} is VALID [2022-02-20 18:00:58,811 INFO L272 TraceCheckUtils]: 12: Hoare triple {29176#true} call setClientPrivateKey(setup_bob_~bob___0#1, 123); {29245#(and (= ~__ste_client_privateKey0~0 |old(~__ste_client_privateKey0~0)|) (= ~__ste_client_privateKey2~0 |old(~__ste_client_privateKey2~0)|) (= ~__ste_client_privateKey1~0 |old(~__ste_client_privateKey1~0)|))} is VALID [2022-02-20 18:00:58,811 INFO L290 TraceCheckUtils]: 13: Hoare triple {29245#(and (= ~__ste_client_privateKey0~0 |old(~__ste_client_privateKey0~0)|) (= ~__ste_client_privateKey2~0 |old(~__ste_client_privateKey2~0)|) (= ~__ste_client_privateKey1~0 |old(~__ste_client_privateKey1~0)|))} ~handle := #in~handle;~value := #in~value; {29176#true} is VALID [2022-02-20 18:00:58,811 INFO L290 TraceCheckUtils]: 14: Hoare triple {29176#true} assume 1 == ~handle;~__ste_client_privateKey0~0 := ~value; {29176#true} is VALID [2022-02-20 18:00:58,811 INFO L290 TraceCheckUtils]: 15: Hoare triple {29176#true} assume true; {29176#true} is VALID [2022-02-20 18:00:58,811 INFO L284 TraceCheckUtils]: 16: Hoare quadruple {29176#true} {29176#true} #1136#return; {29176#true} is VALID [2022-02-20 18:00:58,812 INFO L290 TraceCheckUtils]: 17: Hoare triple {29176#true} assume { :end_inline_setup_bob } true;setup_~__cil_tmp1~0#1.base, setup_~__cil_tmp1~0#1.offset := 18, 0;havoc setup_#t~nondet32#1;~rjh~0 := 2;assume { :begin_inline_setup_rjh } true;setup_rjh_#in~rjh___0#1 := ~rjh~0;havoc setup_rjh_~rjh___0#1;setup_rjh_~rjh___0#1 := setup_rjh_#in~rjh___0#1;assume { :begin_inline_setup_rjh__wrappee__Base } true;setup_rjh__wrappee__Base_#in~rjh___0#1 := setup_rjh_~rjh___0#1;havoc setup_rjh__wrappee__Base_~rjh___0#1;setup_rjh__wrappee__Base_~rjh___0#1 := setup_rjh__wrappee__Base_#in~rjh___0#1; {29186#(= ~rjh~0 |ULTIMATE.start_setup_rjh__wrappee__Base_~rjh___0#1|)} is VALID [2022-02-20 18:00:58,812 INFO L272 TraceCheckUtils]: 18: Hoare triple {29186#(= ~rjh~0 |ULTIMATE.start_setup_rjh__wrappee__Base_~rjh___0#1|)} call setClientId(setup_rjh__wrappee__Base_~rjh___0#1, setup_rjh__wrappee__Base_~rjh___0#1); {29244#(and (= |old(~__ste_client_idCounter0~0)| ~__ste_client_idCounter0~0) (= |old(~__ste_client_idCounter1~0)| ~__ste_client_idCounter1~0) (= |old(~__ste_client_idCounter2~0)| ~__ste_client_idCounter2~0))} is VALID [2022-02-20 18:00:58,813 INFO L290 TraceCheckUtils]: 19: Hoare triple {29244#(and (= |old(~__ste_client_idCounter0~0)| ~__ste_client_idCounter0~0) (= |old(~__ste_client_idCounter1~0)| ~__ste_client_idCounter1~0) (= |old(~__ste_client_idCounter2~0)| ~__ste_client_idCounter2~0))} ~handle := #in~handle;~value := #in~value; {29246#(= setClientId_~handle |setClientId_#in~handle|)} is VALID [2022-02-20 18:00:58,813 INFO L290 TraceCheckUtils]: 20: Hoare triple {29246#(= setClientId_~handle |setClientId_#in~handle|)} assume !(1 == ~handle); {29246#(= setClientId_~handle |setClientId_#in~handle|)} is VALID [2022-02-20 18:00:58,813 INFO L290 TraceCheckUtils]: 21: Hoare triple {29246#(= setClientId_~handle |setClientId_#in~handle|)} assume 2 == ~handle;~__ste_client_idCounter1~0 := ~value; {29247#(= 2 |setClientId_#in~handle|)} is VALID [2022-02-20 18:00:58,814 INFO L290 TraceCheckUtils]: 22: Hoare triple {29247#(= 2 |setClientId_#in~handle|)} assume true; {29247#(= 2 |setClientId_#in~handle|)} is VALID [2022-02-20 18:00:58,814 INFO L284 TraceCheckUtils]: 23: Hoare quadruple {29247#(= 2 |setClientId_#in~handle|)} {29186#(= ~rjh~0 |ULTIMATE.start_setup_rjh__wrappee__Base_~rjh___0#1|)} #1138#return; {29192#(not (= ~rjh~0 1))} is VALID [2022-02-20 18:00:58,814 INFO L290 TraceCheckUtils]: 24: Hoare triple {29192#(not (= ~rjh~0 1))} assume { :end_inline_setup_rjh__wrappee__Base } true; {29192#(not (= ~rjh~0 1))} is VALID [2022-02-20 18:00:58,815 INFO L272 TraceCheckUtils]: 25: Hoare triple {29192#(not (= ~rjh~0 1))} call setClientPrivateKey(setup_rjh_~rjh___0#1, 456); {29245#(and (= ~__ste_client_privateKey0~0 |old(~__ste_client_privateKey0~0)|) (= ~__ste_client_privateKey2~0 |old(~__ste_client_privateKey2~0)|) (= ~__ste_client_privateKey1~0 |old(~__ste_client_privateKey1~0)|))} is VALID [2022-02-20 18:00:58,815 INFO L290 TraceCheckUtils]: 26: Hoare triple {29245#(and (= ~__ste_client_privateKey0~0 |old(~__ste_client_privateKey0~0)|) (= ~__ste_client_privateKey2~0 |old(~__ste_client_privateKey2~0)|) (= ~__ste_client_privateKey1~0 |old(~__ste_client_privateKey1~0)|))} ~handle := #in~handle;~value := #in~value; {29176#true} is VALID [2022-02-20 18:00:58,815 INFO L290 TraceCheckUtils]: 27: Hoare triple {29176#true} assume !(1 == ~handle); {29176#true} is VALID [2022-02-20 18:00:58,815 INFO L290 TraceCheckUtils]: 28: Hoare triple {29176#true} assume 2 == ~handle;~__ste_client_privateKey1~0 := ~value; {29176#true} is VALID [2022-02-20 18:00:58,815 INFO L290 TraceCheckUtils]: 29: Hoare triple {29176#true} assume true; {29176#true} is VALID [2022-02-20 18:00:58,816 INFO L284 TraceCheckUtils]: 30: Hoare quadruple {29176#true} {29192#(not (= ~rjh~0 1))} #1140#return; {29192#(not (= ~rjh~0 1))} is VALID [2022-02-20 18:00:58,816 INFO L290 TraceCheckUtils]: 31: Hoare triple {29192#(not (= ~rjh~0 1))} assume { :end_inline_setup_rjh } true;setup_~__cil_tmp2~0#1.base, setup_~__cil_tmp2~0#1.offset := 19, 0;havoc setup_#t~nondet33#1;~chuck~0 := 3;assume { :begin_inline_setup_chuck } true;setup_chuck_#in~chuck___0#1 := ~chuck~0;havoc setup_chuck_~chuck___0#1;setup_chuck_~chuck___0#1 := setup_chuck_#in~chuck___0#1;assume { :begin_inline_setup_chuck__wrappee__Base } true;setup_chuck__wrappee__Base_#in~chuck___0#1 := setup_chuck_~chuck___0#1;havoc setup_chuck__wrappee__Base_~chuck___0#1;setup_chuck__wrappee__Base_~chuck___0#1 := setup_chuck__wrappee__Base_#in~chuck___0#1; {29192#(not (= ~rjh~0 1))} is VALID [2022-02-20 18:00:58,817 INFO L272 TraceCheckUtils]: 32: Hoare triple {29192#(not (= ~rjh~0 1))} call setClientId(setup_chuck__wrappee__Base_~chuck___0#1, setup_chuck__wrappee__Base_~chuck___0#1); {29244#(and (= |old(~__ste_client_idCounter0~0)| ~__ste_client_idCounter0~0) (= |old(~__ste_client_idCounter1~0)| ~__ste_client_idCounter1~0) (= |old(~__ste_client_idCounter2~0)| ~__ste_client_idCounter2~0))} is VALID [2022-02-20 18:00:58,817 INFO L290 TraceCheckUtils]: 33: Hoare triple {29244#(and (= |old(~__ste_client_idCounter0~0)| ~__ste_client_idCounter0~0) (= |old(~__ste_client_idCounter1~0)| ~__ste_client_idCounter1~0) (= |old(~__ste_client_idCounter2~0)| ~__ste_client_idCounter2~0))} ~handle := #in~handle;~value := #in~value; {29176#true} is VALID [2022-02-20 18:00:58,817 INFO L290 TraceCheckUtils]: 34: Hoare triple {29176#true} assume !(1 == ~handle); {29176#true} is VALID [2022-02-20 18:00:58,817 INFO L290 TraceCheckUtils]: 35: Hoare triple {29176#true} assume !(2 == ~handle); {29176#true} is VALID [2022-02-20 18:00:58,817 INFO L290 TraceCheckUtils]: 36: Hoare triple {29176#true} assume 3 == ~handle;~__ste_client_idCounter2~0 := ~value; {29176#true} is VALID [2022-02-20 18:00:58,817 INFO L290 TraceCheckUtils]: 37: Hoare triple {29176#true} assume true; {29176#true} is VALID [2022-02-20 18:00:58,818 INFO L284 TraceCheckUtils]: 38: Hoare quadruple {29176#true} {29192#(not (= ~rjh~0 1))} #1142#return; {29192#(not (= ~rjh~0 1))} is VALID [2022-02-20 18:00:58,818 INFO L290 TraceCheckUtils]: 39: Hoare triple {29192#(not (= ~rjh~0 1))} assume { :end_inline_setup_chuck__wrappee__Base } true; {29192#(not (= ~rjh~0 1))} is VALID [2022-02-20 18:00:58,818 INFO L272 TraceCheckUtils]: 40: Hoare triple {29192#(not (= ~rjh~0 1))} call setClientPrivateKey(setup_chuck_~chuck___0#1, 789); {29245#(and (= ~__ste_client_privateKey0~0 |old(~__ste_client_privateKey0~0)|) (= ~__ste_client_privateKey2~0 |old(~__ste_client_privateKey2~0)|) (= ~__ste_client_privateKey1~0 |old(~__ste_client_privateKey1~0)|))} is VALID [2022-02-20 18:00:58,818 INFO L290 TraceCheckUtils]: 41: Hoare triple {29245#(and (= ~__ste_client_privateKey0~0 |old(~__ste_client_privateKey0~0)|) (= ~__ste_client_privateKey2~0 |old(~__ste_client_privateKey2~0)|) (= ~__ste_client_privateKey1~0 |old(~__ste_client_privateKey1~0)|))} ~handle := #in~handle;~value := #in~value; {29176#true} is VALID [2022-02-20 18:00:58,819 INFO L290 TraceCheckUtils]: 42: Hoare triple {29176#true} assume !(1 == ~handle); {29176#true} is VALID [2022-02-20 18:00:58,819 INFO L290 TraceCheckUtils]: 43: Hoare triple {29176#true} assume !(2 == ~handle); {29176#true} is VALID [2022-02-20 18:00:58,819 INFO L290 TraceCheckUtils]: 44: Hoare triple {29176#true} assume 3 == ~handle;~__ste_client_privateKey2~0 := ~value; {29176#true} is VALID [2022-02-20 18:00:58,819 INFO L290 TraceCheckUtils]: 45: Hoare triple {29176#true} assume true; {29176#true} is VALID [2022-02-20 18:00:58,819 INFO L284 TraceCheckUtils]: 46: Hoare quadruple {29176#true} {29192#(not (= ~rjh~0 1))} #1144#return; {29192#(not (= ~rjh~0 1))} is VALID [2022-02-20 18:00:58,820 INFO L290 TraceCheckUtils]: 47: Hoare triple {29192#(not (= ~rjh~0 1))} assume { :end_inline_setup_chuck } true;setup_~__cil_tmp3~0#1.base, setup_~__cil_tmp3~0#1.offset := 20, 0;havoc setup_#t~nondet34#1; {29192#(not (= ~rjh~0 1))} is VALID [2022-02-20 18:00:58,820 INFO L290 TraceCheckUtils]: 48: Hoare triple {29192#(not (= ~rjh~0 1))} assume { :end_inline_setup } true;assume { :begin_inline_test } true;havoc test_#t~nondet47#1, test_#t~nondet48#1, test_#t~nondet49#1, test_#t~nondet50#1, test_#t~nondet51#1, test_#t~nondet52#1, test_#t~nondet53#1, test_#t~nondet54#1, test_#t~nondet55#1, test_#t~nondet56#1, test_#t~nondet57#1, test_~op1~0#1, test_~op2~0#1, test_~op3~0#1, test_~op4~0#1, test_~op5~0#1, test_~op6~0#1, test_~op7~0#1, test_~op8~0#1, test_~op9~0#1, test_~op10~0#1, test_~op11~0#1, test_~splverifierCounter~0#1, test_~tmp~6#1, test_~tmp___0~2#1, test_~tmp___1~1#1, test_~tmp___2~0#1, test_~tmp___3~0#1, test_~tmp___4~0#1, test_~tmp___5~0#1, test_~tmp___6~0#1, test_~tmp___7~0#1, test_~tmp___8~0#1, test_~tmp___9~0#1;havoc test_~op1~0#1;havoc test_~op2~0#1;havoc test_~op3~0#1;havoc test_~op4~0#1;havoc test_~op5~0#1;havoc test_~op6~0#1;havoc test_~op7~0#1;havoc test_~op8~0#1;havoc test_~op9~0#1;havoc test_~op10~0#1;havoc test_~op11~0#1;havoc test_~splverifierCounter~0#1;havoc test_~tmp~6#1;havoc test_~tmp___0~2#1;havoc test_~tmp___1~1#1;havoc test_~tmp___2~0#1;havoc test_~tmp___3~0#1;havoc test_~tmp___4~0#1;havoc test_~tmp___5~0#1;havoc test_~tmp___6~0#1;havoc test_~tmp___7~0#1;havoc test_~tmp___8~0#1;havoc test_~tmp___9~0#1;test_~op1~0#1 := 0;test_~op2~0#1 := 0;test_~op3~0#1 := 0;test_~op4~0#1 := 0;test_~op5~0#1 := 0;test_~op6~0#1 := 0;test_~op7~0#1 := 0;test_~op8~0#1 := 0;test_~op9~0#1 := 0;test_~op10~0#1 := 0;test_~op11~0#1 := 0;test_~splverifierCounter~0#1 := 0; {29192#(not (= ~rjh~0 1))} is VALID [2022-02-20 18:00:58,820 INFO L290 TraceCheckUtils]: 49: Hoare triple {29192#(not (= ~rjh~0 1))} assume !false; {29192#(not (= ~rjh~0 1))} is VALID [2022-02-20 18:00:58,820 INFO L290 TraceCheckUtils]: 50: Hoare triple {29192#(not (= ~rjh~0 1))} assume test_~splverifierCounter~0#1 < 4; {29192#(not (= ~rjh~0 1))} is VALID [2022-02-20 18:00:58,821 INFO L290 TraceCheckUtils]: 51: Hoare triple {29192#(not (= ~rjh~0 1))} test_~splverifierCounter~0#1 := 1 + test_~splverifierCounter~0#1; {29192#(not (= ~rjh~0 1))} is VALID [2022-02-20 18:00:58,821 INFO L290 TraceCheckUtils]: 52: Hoare triple {29192#(not (= ~rjh~0 1))} assume 0 == test_~op1~0#1;assume -2147483648 <= test_#t~nondet47#1 && test_#t~nondet47#1 <= 2147483647;test_~tmp___9~0#1 := test_#t~nondet47#1;havoc test_#t~nondet47#1; {29192#(not (= ~rjh~0 1))} is VALID [2022-02-20 18:00:58,821 INFO L290 TraceCheckUtils]: 53: Hoare triple {29192#(not (= ~rjh~0 1))} assume !(0 != test_~tmp___9~0#1); {29192#(not (= ~rjh~0 1))} is VALID [2022-02-20 18:00:58,821 INFO L290 TraceCheckUtils]: 54: Hoare triple {29192#(not (= ~rjh~0 1))} assume 0 == test_~op2~0#1;assume -2147483648 <= test_#t~nondet48#1 && test_#t~nondet48#1 <= 2147483647;test_~tmp___8~0#1 := test_#t~nondet48#1;havoc test_#t~nondet48#1; {29192#(not (= ~rjh~0 1))} is VALID [2022-02-20 18:00:58,822 INFO L290 TraceCheckUtils]: 55: Hoare triple {29192#(not (= ~rjh~0 1))} assume 0 != test_~tmp___8~0#1;assume { :begin_inline_rjhSetAutoRespond } true;assume { :begin_inline_setClientAutoResponse } true;setClientAutoResponse_#in~handle#1, setClientAutoResponse_#in~value#1 := ~rjh~0, 1;havoc setClientAutoResponse_~handle#1, setClientAutoResponse_~value#1;setClientAutoResponse_~handle#1 := setClientAutoResponse_#in~handle#1;setClientAutoResponse_~value#1 := setClientAutoResponse_#in~value#1; {29210#(not (= |ULTIMATE.start_setClientAutoResponse_~handle#1| 1))} is VALID [2022-02-20 18:00:58,822 INFO L290 TraceCheckUtils]: 56: Hoare triple {29210#(not (= |ULTIMATE.start_setClientAutoResponse_~handle#1| 1))} assume 1 == setClientAutoResponse_~handle#1;~__ste_client_autoResponse0~0 := setClientAutoResponse_~value#1; {29177#false} is VALID [2022-02-20 18:00:58,822 INFO L290 TraceCheckUtils]: 57: Hoare triple {29177#false} assume { :end_inline_setClientAutoResponse } true; {29177#false} is VALID [2022-02-20 18:00:58,822 INFO L290 TraceCheckUtils]: 58: Hoare triple {29177#false} assume { :end_inline_rjhSetAutoRespond } true;test_~op2~0#1 := 1; {29177#false} is VALID [2022-02-20 18:00:58,822 INFO L290 TraceCheckUtils]: 59: Hoare triple {29177#false} assume !false; {29177#false} is VALID [2022-02-20 18:00:58,823 INFO L290 TraceCheckUtils]: 60: Hoare triple {29177#false} assume !(test_~splverifierCounter~0#1 < 4); {29177#false} is VALID [2022-02-20 18:00:58,823 INFO L290 TraceCheckUtils]: 61: Hoare triple {29177#false} assume { :begin_inline_bobToRjh } true;havoc bobToRjh_#t~ret27#1, bobToRjh_#t~ret28#1, bobToRjh_#t~ret29#1, bobToRjh_#t~ret30#1, bobToRjh_~tmp~3#1, bobToRjh_~tmp___0~0#1, bobToRjh_~tmp___1~0#1;havoc bobToRjh_~tmp~3#1;havoc bobToRjh_~tmp___0~0#1;havoc bobToRjh_~tmp___1~0#1;call bobToRjh_#t~ret27#1 := puts(16, 0);assume -2147483648 <= bobToRjh_#t~ret27#1 && bobToRjh_#t~ret27#1 <= 2147483647;havoc bobToRjh_#t~ret27#1; {29177#false} is VALID [2022-02-20 18:00:58,823 INFO L272 TraceCheckUtils]: 62: Hoare triple {29177#false} call sendEmail(~bob~0, ~rjh~0); {29177#false} is VALID [2022-02-20 18:00:58,823 INFO L290 TraceCheckUtils]: 63: Hoare triple {29177#false} ~sender#1 := #in~sender#1;~receiver#1 := #in~receiver#1;havoc ~email~0#1;havoc ~tmp~14#1;assume { :begin_inline_createEmail } true;createEmail_#in~from#1, createEmail_#in~to#1 := 0, ~receiver#1;havoc createEmail_#res#1;havoc createEmail_~from#1, createEmail_~to#1, createEmail_~retValue_acc~31#1, createEmail_~msg~0#1;createEmail_~from#1 := createEmail_#in~from#1;createEmail_~to#1 := createEmail_#in~to#1;havoc createEmail_~retValue_acc~31#1;havoc createEmail_~msg~0#1;createEmail_~msg~0#1 := 1; {29177#false} is VALID [2022-02-20 18:00:58,823 INFO L272 TraceCheckUtils]: 64: Hoare triple {29177#false} call setEmailFrom(createEmail_~msg~0#1, createEmail_~from#1); {29248#(and (= |old(~__ste_email_from0~0)| ~__ste_email_from0~0) (= |old(~__ste_email_from1~0)| ~__ste_email_from1~0))} is VALID [2022-02-20 18:00:58,823 INFO L290 TraceCheckUtils]: 65: Hoare triple {29248#(and (= |old(~__ste_email_from0~0)| ~__ste_email_from0~0) (= |old(~__ste_email_from1~0)| ~__ste_email_from1~0))} ~handle := #in~handle;~value := #in~value; {29176#true} is VALID [2022-02-20 18:00:58,823 INFO L290 TraceCheckUtils]: 66: Hoare triple {29176#true} assume 1 == ~handle;~__ste_email_from0~0 := ~value; {29176#true} is VALID [2022-02-20 18:00:58,823 INFO L290 TraceCheckUtils]: 67: Hoare triple {29176#true} assume true; {29176#true} is VALID [2022-02-20 18:00:58,823 INFO L284 TraceCheckUtils]: 68: Hoare quadruple {29176#true} {29177#false} #1120#return; {29177#false} is VALID [2022-02-20 18:00:58,823 INFO L272 TraceCheckUtils]: 69: Hoare triple {29177#false} call setEmailTo(createEmail_~msg~0#1, createEmail_~to#1); {29249#(and (= ~__ste_email_to0~0 |old(~__ste_email_to0~0)|) (= ~__ste_email_to1~0 |old(~__ste_email_to1~0)|))} is VALID [2022-02-20 18:00:58,824 INFO L290 TraceCheckUtils]: 70: Hoare triple {29249#(and (= ~__ste_email_to0~0 |old(~__ste_email_to0~0)|) (= ~__ste_email_to1~0 |old(~__ste_email_to1~0)|))} ~handle := #in~handle;~value := #in~value; {29176#true} is VALID [2022-02-20 18:00:58,824 INFO L290 TraceCheckUtils]: 71: Hoare triple {29176#true} assume 1 == ~handle;~__ste_email_to0~0 := ~value; {29176#true} is VALID [2022-02-20 18:00:58,824 INFO L290 TraceCheckUtils]: 72: Hoare triple {29176#true} assume true; {29176#true} is VALID [2022-02-20 18:00:58,824 INFO L284 TraceCheckUtils]: 73: Hoare quadruple {29176#true} {29177#false} #1122#return; {29177#false} is VALID [2022-02-20 18:00:58,824 INFO L290 TraceCheckUtils]: 74: Hoare triple {29177#false} createEmail_~retValue_acc~31#1 := createEmail_~msg~0#1;createEmail_#res#1 := createEmail_~retValue_acc~31#1; {29177#false} is VALID [2022-02-20 18:00:58,824 INFO L290 TraceCheckUtils]: 75: Hoare triple {29177#false} #t~ret72#1 := createEmail_#res#1;assume { :end_inline_createEmail } true;assume -2147483648 <= #t~ret72#1 && #t~ret72#1 <= 2147483647;~tmp~14#1 := #t~ret72#1;havoc #t~ret72#1;~email~0#1 := ~tmp~14#1; {29177#false} is VALID [2022-02-20 18:00:58,824 INFO L272 TraceCheckUtils]: 76: Hoare triple {29177#false} call outgoing(~sender#1, ~email~0#1); {29177#false} is VALID [2022-02-20 18:00:58,824 INFO L290 TraceCheckUtils]: 77: Hoare triple {29177#false} ~client#1 := #in~client#1;~msg#1 := #in~msg#1;assume { :begin_inline_sign } true;sign_#in~client#1, sign_#in~msg#1 := ~client#1, ~msg#1;havoc sign_#t~ret76#1, sign_~client#1, sign_~msg#1, sign_~privkey~1#1, sign_~tmp~16#1;sign_~client#1 := sign_#in~client#1;sign_~msg#1 := sign_#in~msg#1;havoc sign_~privkey~1#1;havoc sign_~tmp~16#1; {29177#false} is VALID [2022-02-20 18:00:58,824 INFO L272 TraceCheckUtils]: 78: Hoare triple {29177#false} call sign_#t~ret76#1 := getClientPrivateKey(sign_~client#1); {29176#true} is VALID [2022-02-20 18:00:58,824 INFO L290 TraceCheckUtils]: 79: Hoare triple {29176#true} ~handle := #in~handle;havoc ~retValue_acc~20; {29176#true} is VALID [2022-02-20 18:00:58,825 INFO L290 TraceCheckUtils]: 80: Hoare triple {29176#true} assume 1 == ~handle;~retValue_acc~20 := ~__ste_client_privateKey0~0;#res := ~retValue_acc~20; {29176#true} is VALID [2022-02-20 18:00:58,825 INFO L290 TraceCheckUtils]: 81: Hoare triple {29176#true} assume true; {29176#true} is VALID [2022-02-20 18:00:58,825 INFO L284 TraceCheckUtils]: 82: Hoare quadruple {29176#true} {29177#false} #1054#return; {29177#false} is VALID [2022-02-20 18:00:58,825 INFO L290 TraceCheckUtils]: 83: Hoare triple {29177#false} assume -2147483648 <= sign_#t~ret76#1 && sign_#t~ret76#1 <= 2147483647;sign_~tmp~16#1 := sign_#t~ret76#1;havoc sign_#t~ret76#1;sign_~privkey~1#1 := sign_~tmp~16#1; {29177#false} is VALID [2022-02-20 18:00:58,825 INFO L290 TraceCheckUtils]: 84: Hoare triple {29177#false} assume 0 == sign_~privkey~1#1; {29177#false} is VALID [2022-02-20 18:00:58,825 INFO L290 TraceCheckUtils]: 85: Hoare triple {29177#false} assume { :end_inline_sign } true;assume { :begin_inline_outgoing__wrappee__AutoResponder } true;outgoing__wrappee__AutoResponder_#in~client#1, outgoing__wrappee__AutoResponder_#in~msg#1 := ~client#1, ~msg#1;havoc outgoing__wrappee__AutoResponder_#t~ret62#1, outgoing__wrappee__AutoResponder_#t~ret63#1, outgoing__wrappee__AutoResponder_~client#1, outgoing__wrappee__AutoResponder_~msg#1, outgoing__wrappee__AutoResponder_~receiver~0#1, outgoing__wrappee__AutoResponder_~tmp~9#1, outgoing__wrappee__AutoResponder_~pubkey~0#1, outgoing__wrappee__AutoResponder_~tmp___0~3#1;outgoing__wrappee__AutoResponder_~client#1 := outgoing__wrappee__AutoResponder_#in~client#1;outgoing__wrappee__AutoResponder_~msg#1 := outgoing__wrappee__AutoResponder_#in~msg#1;havoc outgoing__wrappee__AutoResponder_~receiver~0#1;havoc outgoing__wrappee__AutoResponder_~tmp~9#1;havoc outgoing__wrappee__AutoResponder_~pubkey~0#1;havoc outgoing__wrappee__AutoResponder_~tmp___0~3#1; {29177#false} is VALID [2022-02-20 18:00:58,825 INFO L272 TraceCheckUtils]: 86: Hoare triple {29177#false} call outgoing__wrappee__AutoResponder_#t~ret62#1 := getEmailTo(outgoing__wrappee__AutoResponder_~msg#1); {29176#true} is VALID [2022-02-20 18:00:58,825 INFO L290 TraceCheckUtils]: 87: Hoare triple {29176#true} ~handle := #in~handle;havoc ~retValue_acc~36; {29176#true} is VALID [2022-02-20 18:00:58,825 INFO L290 TraceCheckUtils]: 88: Hoare triple {29176#true} assume 1 == ~handle;~retValue_acc~36 := ~__ste_email_to0~0;#res := ~retValue_acc~36; {29176#true} is VALID [2022-02-20 18:00:58,826 INFO L290 TraceCheckUtils]: 89: Hoare triple {29176#true} assume true; {29176#true} is VALID [2022-02-20 18:00:58,826 INFO L284 TraceCheckUtils]: 90: Hoare quadruple {29176#true} {29177#false} #1056#return; {29177#false} is VALID [2022-02-20 18:00:58,826 INFO L290 TraceCheckUtils]: 91: Hoare triple {29177#false} assume -2147483648 <= outgoing__wrappee__AutoResponder_#t~ret62#1 && outgoing__wrappee__AutoResponder_#t~ret62#1 <= 2147483647;outgoing__wrappee__AutoResponder_~tmp~9#1 := outgoing__wrappee__AutoResponder_#t~ret62#1;havoc outgoing__wrappee__AutoResponder_#t~ret62#1;outgoing__wrappee__AutoResponder_~receiver~0#1 := outgoing__wrappee__AutoResponder_~tmp~9#1; {29177#false} is VALID [2022-02-20 18:00:58,826 INFO L272 TraceCheckUtils]: 92: Hoare triple {29177#false} call outgoing__wrappee__AutoResponder_#t~ret63#1 := findPublicKey(outgoing__wrappee__AutoResponder_~client#1, outgoing__wrappee__AutoResponder_~receiver~0#1); {29176#true} is VALID [2022-02-20 18:00:58,826 INFO L290 TraceCheckUtils]: 93: Hoare triple {29176#true} ~handle := #in~handle;~userid := #in~userid;havoc ~retValue_acc~25; {29176#true} is VALID [2022-02-20 18:00:58,826 INFO L290 TraceCheckUtils]: 94: Hoare triple {29176#true} assume 1 == ~handle; {29176#true} is VALID [2022-02-20 18:00:58,826 INFO L290 TraceCheckUtils]: 95: Hoare triple {29176#true} assume ~userid == ~__ste_Client_Keyring0_User0~0;~retValue_acc~25 := ~__ste_Client_Keyring0_PublicKey0~0;#res := ~retValue_acc~25; {29176#true} is VALID [2022-02-20 18:00:58,826 INFO L290 TraceCheckUtils]: 96: Hoare triple {29176#true} assume true; {29176#true} is VALID [2022-02-20 18:00:58,826 INFO L284 TraceCheckUtils]: 97: Hoare quadruple {29176#true} {29177#false} #1058#return; {29177#false} is VALID [2022-02-20 18:00:58,826 INFO L290 TraceCheckUtils]: 98: Hoare triple {29177#false} assume -2147483648 <= outgoing__wrappee__AutoResponder_#t~ret63#1 && outgoing__wrappee__AutoResponder_#t~ret63#1 <= 2147483647;outgoing__wrappee__AutoResponder_~tmp___0~3#1 := outgoing__wrappee__AutoResponder_#t~ret63#1;havoc outgoing__wrappee__AutoResponder_#t~ret63#1;outgoing__wrappee__AutoResponder_~pubkey~0#1 := outgoing__wrappee__AutoResponder_~tmp___0~3#1; {29177#false} is VALID [2022-02-20 18:00:58,827 INFO L290 TraceCheckUtils]: 99: Hoare triple {29177#false} assume !(0 != outgoing__wrappee__AutoResponder_~pubkey~0#1); {29177#false} is VALID [2022-02-20 18:00:58,827 INFO L290 TraceCheckUtils]: 100: Hoare triple {29177#false} assume { :begin_inline_outgoing__wrappee__Keys } true;outgoing__wrappee__Keys_#in~client#1, outgoing__wrappee__Keys_#in~msg#1 := outgoing__wrappee__AutoResponder_~client#1, outgoing__wrappee__AutoResponder_~msg#1;havoc outgoing__wrappee__Keys_#t~ret61#1, outgoing__wrappee__Keys_~client#1, outgoing__wrappee__Keys_~msg#1, outgoing__wrappee__Keys_~tmp~8#1;outgoing__wrappee__Keys_~client#1 := outgoing__wrappee__Keys_#in~client#1;outgoing__wrappee__Keys_~msg#1 := outgoing__wrappee__Keys_#in~msg#1;havoc outgoing__wrappee__Keys_~tmp~8#1;assume { :begin_inline_getClientId } true;getClientId_#in~handle#1 := outgoing__wrappee__Keys_~client#1;havoc getClientId_#res#1;havoc getClientId_~handle#1, getClientId_~retValue_acc~27#1;getClientId_~handle#1 := getClientId_#in~handle#1;havoc getClientId_~retValue_acc~27#1; {29177#false} is VALID [2022-02-20 18:00:58,827 INFO L290 TraceCheckUtils]: 101: Hoare triple {29177#false} assume 1 == getClientId_~handle#1;getClientId_~retValue_acc~27#1 := ~__ste_client_idCounter0~0;getClientId_#res#1 := getClientId_~retValue_acc~27#1; {29177#false} is VALID [2022-02-20 18:00:58,827 INFO L290 TraceCheckUtils]: 102: Hoare triple {29177#false} outgoing__wrappee__Keys_#t~ret61#1 := getClientId_#res#1;assume { :end_inline_getClientId } true;assume -2147483648 <= outgoing__wrappee__Keys_#t~ret61#1 && outgoing__wrappee__Keys_#t~ret61#1 <= 2147483647;outgoing__wrappee__Keys_~tmp~8#1 := outgoing__wrappee__Keys_#t~ret61#1;havoc outgoing__wrappee__Keys_#t~ret61#1; {29177#false} is VALID [2022-02-20 18:00:58,827 INFO L272 TraceCheckUtils]: 103: Hoare triple {29177#false} call setEmailFrom(outgoing__wrappee__Keys_~msg#1, outgoing__wrappee__Keys_~tmp~8#1); {29248#(and (= |old(~__ste_email_from0~0)| ~__ste_email_from0~0) (= |old(~__ste_email_from1~0)| ~__ste_email_from1~0))} is VALID [2022-02-20 18:00:58,827 INFO L290 TraceCheckUtils]: 104: Hoare triple {29248#(and (= |old(~__ste_email_from0~0)| ~__ste_email_from0~0) (= |old(~__ste_email_from1~0)| ~__ste_email_from1~0))} ~handle := #in~handle;~value := #in~value; {29176#true} is VALID [2022-02-20 18:00:58,827 INFO L290 TraceCheckUtils]: 105: Hoare triple {29176#true} assume 1 == ~handle;~__ste_email_from0~0 := ~value; {29176#true} is VALID [2022-02-20 18:00:58,827 INFO L290 TraceCheckUtils]: 106: Hoare triple {29176#true} assume true; {29176#true} is VALID [2022-02-20 18:00:58,827 INFO L284 TraceCheckUtils]: 107: Hoare quadruple {29176#true} {29177#false} #1064#return; {29177#false} is VALID [2022-02-20 18:00:58,827 INFO L290 TraceCheckUtils]: 108: Hoare triple {29177#false} assume { :begin_inline_mail } true;mail_#in~client#1, mail_#in~msg#1 := outgoing__wrappee__Keys_~client#1, outgoing__wrappee__Keys_~msg#1;havoc mail_#t~ret59#1, mail_#t~ret60#1, mail_~client#1, mail_~msg#1, mail_~__utac__ad__arg1~0#1, mail_~__utac__ad__arg2~0#1, mail_~tmp~7#1;mail_~client#1 := mail_#in~client#1;mail_~msg#1 := mail_#in~msg#1;havoc mail_~__utac__ad__arg1~0#1;havoc mail_~__utac__ad__arg2~0#1;havoc mail_~tmp~7#1;mail_~__utac__ad__arg1~0#1 := mail_~client#1;mail_~__utac__ad__arg2~0#1 := mail_~msg#1;assume { :begin_inline___utac_acc__SignForward_spec__1 } true;__utac_acc__SignForward_spec__1_#in~client#1, __utac_acc__SignForward_spec__1_#in~msg#1 := mail_~__utac__ad__arg1~0#1, mail_~__utac__ad__arg2~0#1;havoc __utac_acc__SignForward_spec__1_#t~ret107#1, __utac_acc__SignForward_spec__1_#t~ret108#1, __utac_acc__SignForward_spec__1_#t~ret109#1, __utac_acc__SignForward_spec__1_~client#1, __utac_acc__SignForward_spec__1_~msg#1, __utac_acc__SignForward_spec__1_~tmp~25#1, __utac_acc__SignForward_spec__1_~tmp___0~9#1;__utac_acc__SignForward_spec__1_~client#1 := __utac_acc__SignForward_spec__1_#in~client#1;__utac_acc__SignForward_spec__1_~msg#1 := __utac_acc__SignForward_spec__1_#in~msg#1;havoc __utac_acc__SignForward_spec__1_~tmp~25#1;havoc __utac_acc__SignForward_spec__1_~tmp___0~9#1;call __utac_acc__SignForward_spec__1_#t~ret107#1 := puts(39, 0);assume -2147483648 <= __utac_acc__SignForward_spec__1_#t~ret107#1 && __utac_acc__SignForward_spec__1_#t~ret107#1 <= 2147483647;havoc __utac_acc__SignForward_spec__1_#t~ret107#1; {29177#false} is VALID [2022-02-20 18:00:58,828 INFO L272 TraceCheckUtils]: 109: Hoare triple {29177#false} call __utac_acc__SignForward_spec__1_#t~ret108#1 := isSigned(__utac_acc__SignForward_spec__1_~msg#1); {29176#true} is VALID [2022-02-20 18:00:58,828 INFO L290 TraceCheckUtils]: 110: Hoare triple {29176#true} ~handle := #in~handle;havoc ~retValue_acc~41; {29176#true} is VALID [2022-02-20 18:00:58,828 INFO L290 TraceCheckUtils]: 111: Hoare triple {29176#true} assume 1 == ~handle;~retValue_acc~41 := ~__ste_email_isSigned0~0;#res := ~retValue_acc~41; {29176#true} is VALID [2022-02-20 18:00:58,828 INFO L290 TraceCheckUtils]: 112: Hoare triple {29176#true} assume true; {29176#true} is VALID [2022-02-20 18:00:58,828 INFO L284 TraceCheckUtils]: 113: Hoare quadruple {29176#true} {29177#false} #1066#return; {29177#false} is VALID [2022-02-20 18:00:58,828 INFO L290 TraceCheckUtils]: 114: Hoare triple {29177#false} assume -2147483648 <= __utac_acc__SignForward_spec__1_#t~ret108#1 && __utac_acc__SignForward_spec__1_#t~ret108#1 <= 2147483647;__utac_acc__SignForward_spec__1_~tmp___0~9#1 := __utac_acc__SignForward_spec__1_#t~ret108#1;havoc __utac_acc__SignForward_spec__1_#t~ret108#1; {29177#false} is VALID [2022-02-20 18:00:58,828 INFO L290 TraceCheckUtils]: 115: Hoare triple {29177#false} assume 0 != __utac_acc__SignForward_spec__1_~tmp___0~9#1; {29177#false} is VALID [2022-02-20 18:00:58,828 INFO L272 TraceCheckUtils]: 116: Hoare triple {29177#false} call __utac_acc__SignForward_spec__1_#t~ret109#1 := getClientPrivateKey(__utac_acc__SignForward_spec__1_~client#1); {29176#true} is VALID [2022-02-20 18:00:58,828 INFO L290 TraceCheckUtils]: 117: Hoare triple {29176#true} ~handle := #in~handle;havoc ~retValue_acc~20; {29176#true} is VALID [2022-02-20 18:00:58,828 INFO L290 TraceCheckUtils]: 118: Hoare triple {29176#true} assume 1 == ~handle;~retValue_acc~20 := ~__ste_client_privateKey0~0;#res := ~retValue_acc~20; {29176#true} is VALID [2022-02-20 18:00:58,829 INFO L290 TraceCheckUtils]: 119: Hoare triple {29176#true} assume true; {29176#true} is VALID [2022-02-20 18:00:58,829 INFO L284 TraceCheckUtils]: 120: Hoare quadruple {29176#true} {29177#false} #1068#return; {29177#false} is VALID [2022-02-20 18:00:58,829 INFO L290 TraceCheckUtils]: 121: Hoare triple {29177#false} assume -2147483648 <= __utac_acc__SignForward_spec__1_#t~ret109#1 && __utac_acc__SignForward_spec__1_#t~ret109#1 <= 2147483647;__utac_acc__SignForward_spec__1_~tmp~25#1 := __utac_acc__SignForward_spec__1_#t~ret109#1;havoc __utac_acc__SignForward_spec__1_#t~ret109#1; {29177#false} is VALID [2022-02-20 18:00:58,829 INFO L290 TraceCheckUtils]: 122: Hoare triple {29177#false} assume 0 == __utac_acc__SignForward_spec__1_~tmp~25#1;assume { :begin_inline___automaton_fail } true; {29177#false} is VALID [2022-02-20 18:00:58,829 INFO L290 TraceCheckUtils]: 123: Hoare triple {29177#false} assume !false; {29177#false} is VALID [2022-02-20 18:00:58,829 INFO L134 CoverageAnalysis]: Checked inductivity of 36 backedges. 5 proven. 4 refuted. 0 times theorem prover too weak. 27 trivial. 0 not checked. [2022-02-20 18:00:58,829 INFO L144 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2022-02-20 18:00:58,830 INFO L338 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [39009898] [2022-02-20 18:00:58,830 INFO L165 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [39009898] provided 0 perfect and 1 imperfect interpolant sequences [2022-02-20 18:00:58,830 INFO L338 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleZ3 [488039691] [2022-02-20 18:00:58,830 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-02-20 18:00:58,830 INFO L173 SolverBuilder]: Constructing external solver with command: z3 -smt2 -in SMTLIB2_COMPLIANT=true [2022-02-20 18:00:58,830 INFO L189 MonitoredProcess]: No working directory specified, using /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 [2022-02-20 18:00:58,831 INFO L229 MonitoredProcess]: Starting monitored process 7 with /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 -smt2 -in SMTLIB2_COMPLIANT=true (exit command is (exit), workingDir is null) [2022-02-20 18:00:58,863 INFO L327 MonitoredProcess]: [MP /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 -smt2 -in SMTLIB2_COMPLIANT=true (7)] Waiting until timeout for monitored process [2022-02-20 18:00:59,051 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-02-20 18:00:59,055 INFO L263 TraceCheckSpWp]: Trace formula consists of 1106 conjuncts, 3 conjunts are in the unsatisfiable core [2022-02-20 18:00:59,092 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-02-20 18:00:59,094 INFO L286 TraceCheckSpWp]: Computing forward predicates... [2022-02-20 18:00:59,389 INFO L290 TraceCheckUtils]: 0: Hoare triple {29176#true} assume { :begin_inline_ULTIMATE.init } true;#NULL.base, #NULL.offset := 0, 0;assume 0 == #valid[0];assume 0 < #StackHeapBarrier;call #Ultimate.allocInit(2, 1);call write~init~int(48, 1, 0, 1);call write~init~int(0, 1, 1, 1);call #Ultimate.allocInit(28, 2);call #Ultimate.allocInit(12, 3);call #Ultimate.allocInit(30, 4);call #Ultimate.allocInit(9, 5);call #Ultimate.allocInit(21, 6);call #Ultimate.allocInit(30, 7);call #Ultimate.allocInit(9, 8);call #Ultimate.allocInit(21, 9);call #Ultimate.allocInit(30, 10);call #Ultimate.allocInit(9, 11);call #Ultimate.allocInit(25, 12);call #Ultimate.allocInit(30, 13);call #Ultimate.allocInit(9, 14);call #Ultimate.allocInit(25, 15);call #Ultimate.allocInit(44, 16);call #Ultimate.allocInit(44, 17);call #Ultimate.allocInit(9, 18);call #Ultimate.allocInit(9, 19);call #Ultimate.allocInit(11, 20);call #Ultimate.allocInit(19, 21);call #Ultimate.allocInit(4, 22);call write~init~int(37, 22, 0, 1);call write~init~int(100, 22, 1, 1);call write~init~int(10, 22, 2, 1);call write~init~int(0, 22, 3, 1);call #Ultimate.allocInit(4, 23);call write~init~int(37, 23, 0, 1);call write~init~int(100, 23, 1, 1);call write~init~int(10, 23, 2, 1);call write~init~int(0, 23, 3, 1);call #Ultimate.allocInit(10, 24);call #Ultimate.allocInit(16, 25);call #Ultimate.allocInit(20, 26);call #Ultimate.allocInit(22, 27);call #Ultimate.allocInit(21, 28);call #Ultimate.allocInit(10, 29);call #Ultimate.allocInit(12, 30);call #Ultimate.allocInit(10, 31);call #Ultimate.allocInit(18, 32);call #Ultimate.allocInit(16, 33);call #Ultimate.allocInit(21, 34);call #Ultimate.allocInit(13, 35);call #Ultimate.allocInit(16, 36);call #Ultimate.allocInit(25, 37);call #Ultimate.allocInit(4, 38);call write~init~int(37, 38, 0, 1);call write~init~int(115, 38, 1, 1);call write~init~int(10, 38, 2, 1);call write~init~int(0, 38, 3, 1);call #Ultimate.allocInit(13, 39);~head~0.base, ~head~0.offset := 0, 0;~__SELECTED_FEATURE_Base~0 := 0;~__SELECTED_FEATURE_Keys~0 := 0;~__SELECTED_FEATURE_Encrypt~0 := 0;~__SELECTED_FEATURE_AutoResponder~0 := 0;~__SELECTED_FEATURE_AddressBook~0 := 0;~__SELECTED_FEATURE_Sign~0 := 0;~__SELECTED_FEATURE_Forward~0 := 0;~__SELECTED_FEATURE_Verify~0 := 0;~__SELECTED_FEATURE_Decrypt~0 := 0;~__GUIDSL_ROOT_PRODUCTION~0 := 0;~__GUIDSL_NON_TERMINAL_main~0 := 0;~bob~0 := 0;~rjh~0 := 0;~chuck~0 := 0;~queue_empty~0 := 1;~queued_message~0 := 0;~queued_client~0 := 0;~__ste_Client_counter~0 := 0;~__ste_client_name0~0.base, ~__ste_client_name0~0.offset := 0, 0;~__ste_client_name1~0.base, ~__ste_client_name1~0.offset := 0, 0;~__ste_client_name2~0.base, ~__ste_client_name2~0.offset := 0, 0;~__ste_client_outbuffer0~0 := 0;~__ste_client_outbuffer1~0 := 0;~__ste_client_outbuffer2~0 := 0;~__ste_client_outbuffer3~0 := 0;~__ste_ClientAddressBook_size0~0 := 0;~__ste_ClientAddressBook_size1~0 := 0;~__ste_ClientAddressBook_size2~0 := 0;~__ste_Client_AddressBook0_Alias0~0 := 0;~__ste_Client_AddressBook0_Alias1~0 := 0;~__ste_Client_AddressBook0_Alias2~0 := 0;~__ste_Client_AddressBook1_Alias0~0 := 0;~__ste_Client_AddressBook1_Alias1~0 := 0;~__ste_Client_AddressBook1_Alias2~0 := 0;~__ste_Client_AddressBook2_Alias0~0 := 0;~__ste_Client_AddressBook2_Alias1~0 := 0;~__ste_Client_AddressBook2_Alias2~0 := 0;~__ste_Client_AddressBook0_Address0~0 := 0;~__ste_Client_AddressBook0_Address1~0 := 0;~__ste_Client_AddressBook0_Address2~0 := 0;~__ste_Client_AddressBook1_Address0~0 := 0;~__ste_Client_AddressBook1_Address1~0 := 0;~__ste_Client_AddressBook1_Address2~0 := 0;~__ste_Client_AddressBook2_Address0~0 := 0;~__ste_Client_AddressBook2_Address1~0 := 0;~__ste_Client_AddressBook2_Address2~0 := 0;~__ste_client_autoResponse0~0 := 0;~__ste_client_autoResponse1~0 := 0;~__ste_client_autoResponse2~0 := 0;~__ste_client_privateKey0~0 := 0;~__ste_client_privateKey1~0 := 0;~__ste_client_privateKey2~0 := 0;~__ste_ClientKeyring_size0~0 := 0;~__ste_ClientKeyring_size1~0 := 0;~__ste_ClientKeyring_size2~0 := 0;~__ste_Client_Keyring0_User0~0 := 0;~__ste_Client_Keyring0_User1~0 := 0;~__ste_Client_Keyring0_User2~0 := 0;~__ste_Client_Keyring1_User0~0 := 0;~__ste_Client_Keyring1_User1~0 := 0;~__ste_Client_Keyring1_User2~0 := 0;~__ste_Client_Keyring2_User0~0 := 0;~__ste_Client_Keyring2_User1~0 := 0;~__ste_Client_Keyring2_User2~0 := 0;~__ste_Client_Keyring0_PublicKey0~0 := 0;~__ste_Client_Keyring0_PublicKey1~0 := 0;~__ste_Client_Keyring0_PublicKey2~0 := 0;~__ste_Client_Keyring1_PublicKey0~0 := 0;~__ste_Client_Keyring1_PublicKey1~0 := 0;~__ste_Client_Keyring1_PublicKey2~0 := 0;~__ste_Client_Keyring2_PublicKey0~0 := 0;~__ste_Client_Keyring2_PublicKey1~0 := 0;~__ste_Client_Keyring2_PublicKey2~0 := 0;~__ste_client_forwardReceiver0~0 := 0;~__ste_client_forwardReceiver1~0 := 0;~__ste_client_forwardReceiver2~0 := 0;~__ste_client_forwardReceiver3~0 := 0;~__ste_client_idCounter0~0 := 0;~__ste_client_idCounter1~0 := 0;~__ste_client_idCounter2~0 := 0;~__ste_Email_counter~0 := 0;~__ste_email_id0~0 := 0;~__ste_email_id1~0 := 0;~__ste_email_from0~0 := 0;~__ste_email_from1~0 := 0;~__ste_email_to0~0 := 0;~__ste_email_to1~0 := 0;~__ste_email_subject0~0.base, ~__ste_email_subject0~0.offset := 0, 0;~__ste_email_subject1~0.base, ~__ste_email_subject1~0.offset := 0, 0;~__ste_email_body0~0.base, ~__ste_email_body0~0.offset := 0, 0;~__ste_email_body1~0.base, ~__ste_email_body1~0.offset := 0, 0;~__ste_email_isEncrypted0~0 := 0;~__ste_email_isEncrypted1~0 := 0;~__ste_email_encryptionKey0~0 := 0;~__ste_email_encryptionKey1~0 := 0;~__ste_email_isSigned0~0 := 0;~__ste_email_isSigned1~0 := 0;~__ste_email_signKey0~0 := 0;~__ste_email_signKey1~0 := 0;~__ste_email_isSignatureVerified0~0 := 0;~__ste_email_isSignatureVerified1~0 := 0; {29176#true} is VALID [2022-02-20 18:00:59,389 INFO L290 TraceCheckUtils]: 1: Hoare triple {29176#true} assume { :end_inline_ULTIMATE.init } true;assume { :begin_inline_main } true;havoc main_#res#1;havoc main_#t~ret35#1, main_~retValue_acc~3#1, main_~tmp~4#1;havoc main_~retValue_acc~3#1;havoc main_~tmp~4#1;assume { :begin_inline_select_helpers } true; {29176#true} is VALID [2022-02-20 18:00:59,389 INFO L290 TraceCheckUtils]: 2: Hoare triple {29176#true} assume { :end_inline_select_helpers } true;assume { :begin_inline_select_features } true; {29176#true} is VALID [2022-02-20 18:00:59,389 INFO L290 TraceCheckUtils]: 3: Hoare triple {29176#true} assume { :end_inline_select_features } true;assume { :begin_inline_valid_product } true;havoc valid_product_#res#1;havoc valid_product_~retValue_acc~5#1;havoc valid_product_~retValue_acc~5#1;valid_product_~retValue_acc~5#1 := 1;valid_product_#res#1 := valid_product_~retValue_acc~5#1; {29176#true} is VALID [2022-02-20 18:00:59,390 INFO L290 TraceCheckUtils]: 4: Hoare triple {29176#true} main_#t~ret35#1 := valid_product_#res#1;assume { :end_inline_valid_product } true;assume -2147483648 <= main_#t~ret35#1 && main_#t~ret35#1 <= 2147483647;main_~tmp~4#1 := main_#t~ret35#1;havoc main_#t~ret35#1; {29176#true} is VALID [2022-02-20 18:00:59,390 INFO L290 TraceCheckUtils]: 5: Hoare triple {29176#true} assume 0 != main_~tmp~4#1;assume { :begin_inline_setup } true;havoc setup_#t~nondet32#1, setup_#t~nondet33#1, setup_#t~nondet34#1, setup_~__cil_tmp1~0#1.base, setup_~__cil_tmp1~0#1.offset, setup_~__cil_tmp2~0#1.base, setup_~__cil_tmp2~0#1.offset, setup_~__cil_tmp3~0#1.base, setup_~__cil_tmp3~0#1.offset;havoc setup_~__cil_tmp1~0#1.base, setup_~__cil_tmp1~0#1.offset;havoc setup_~__cil_tmp2~0#1.base, setup_~__cil_tmp2~0#1.offset;havoc setup_~__cil_tmp3~0#1.base, setup_~__cil_tmp3~0#1.offset;~bob~0 := 1;assume { :begin_inline_setup_bob } true;setup_bob_#in~bob___0#1 := ~bob~0;havoc setup_bob_~bob___0#1;setup_bob_~bob___0#1 := setup_bob_#in~bob___0#1;assume { :begin_inline_setup_bob__wrappee__Base } true;setup_bob__wrappee__Base_#in~bob___0#1 := setup_bob_~bob___0#1;havoc setup_bob__wrappee__Base_~bob___0#1;setup_bob__wrappee__Base_~bob___0#1 := setup_bob__wrappee__Base_#in~bob___0#1; {29176#true} is VALID [2022-02-20 18:00:59,390 INFO L272 TraceCheckUtils]: 6: Hoare triple {29176#true} call setClientId(setup_bob__wrappee__Base_~bob___0#1, setup_bob__wrappee__Base_~bob___0#1); {29176#true} is VALID [2022-02-20 18:00:59,390 INFO L290 TraceCheckUtils]: 7: Hoare triple {29176#true} ~handle := #in~handle;~value := #in~value; {29176#true} is VALID [2022-02-20 18:00:59,391 INFO L290 TraceCheckUtils]: 8: Hoare triple {29176#true} assume 1 == ~handle;~__ste_client_idCounter0~0 := ~value; {29176#true} is VALID [2022-02-20 18:00:59,391 INFO L290 TraceCheckUtils]: 9: Hoare triple {29176#true} assume true; {29176#true} is VALID [2022-02-20 18:00:59,391 INFO L284 TraceCheckUtils]: 10: Hoare quadruple {29176#true} {29176#true} #1134#return; {29176#true} is VALID [2022-02-20 18:00:59,391 INFO L290 TraceCheckUtils]: 11: Hoare triple {29176#true} assume { :end_inline_setup_bob__wrappee__Base } true; {29176#true} is VALID [2022-02-20 18:00:59,391 INFO L272 TraceCheckUtils]: 12: Hoare triple {29176#true} call setClientPrivateKey(setup_bob_~bob___0#1, 123); {29176#true} is VALID [2022-02-20 18:00:59,391 INFO L290 TraceCheckUtils]: 13: Hoare triple {29176#true} ~handle := #in~handle;~value := #in~value; {29176#true} is VALID [2022-02-20 18:00:59,391 INFO L290 TraceCheckUtils]: 14: Hoare triple {29176#true} assume 1 == ~handle;~__ste_client_privateKey0~0 := ~value; {29176#true} is VALID [2022-02-20 18:00:59,391 INFO L290 TraceCheckUtils]: 15: Hoare triple {29176#true} assume true; {29176#true} is VALID [2022-02-20 18:00:59,391 INFO L284 TraceCheckUtils]: 16: Hoare quadruple {29176#true} {29176#true} #1136#return; {29176#true} is VALID [2022-02-20 18:00:59,391 INFO L290 TraceCheckUtils]: 17: Hoare triple {29176#true} assume { :end_inline_setup_bob } true;setup_~__cil_tmp1~0#1.base, setup_~__cil_tmp1~0#1.offset := 18, 0;havoc setup_#t~nondet32#1;~rjh~0 := 2;assume { :begin_inline_setup_rjh } true;setup_rjh_#in~rjh___0#1 := ~rjh~0;havoc setup_rjh_~rjh___0#1;setup_rjh_~rjh___0#1 := setup_rjh_#in~rjh___0#1;assume { :begin_inline_setup_rjh__wrappee__Base } true;setup_rjh__wrappee__Base_#in~rjh___0#1 := setup_rjh_~rjh___0#1;havoc setup_rjh__wrappee__Base_~rjh___0#1;setup_rjh__wrappee__Base_~rjh___0#1 := setup_rjh__wrappee__Base_#in~rjh___0#1; {29176#true} is VALID [2022-02-20 18:00:59,392 INFO L272 TraceCheckUtils]: 18: Hoare triple {29176#true} call setClientId(setup_rjh__wrappee__Base_~rjh___0#1, setup_rjh__wrappee__Base_~rjh___0#1); {29176#true} is VALID [2022-02-20 18:00:59,392 INFO L290 TraceCheckUtils]: 19: Hoare triple {29176#true} ~handle := #in~handle;~value := #in~value; {29176#true} is VALID [2022-02-20 18:00:59,392 INFO L290 TraceCheckUtils]: 20: Hoare triple {29176#true} assume !(1 == ~handle); {29176#true} is VALID [2022-02-20 18:00:59,392 INFO L290 TraceCheckUtils]: 21: Hoare triple {29176#true} assume 2 == ~handle;~__ste_client_idCounter1~0 := ~value; {29176#true} is VALID [2022-02-20 18:00:59,392 INFO L290 TraceCheckUtils]: 22: Hoare triple {29176#true} assume true; {29176#true} is VALID [2022-02-20 18:00:59,392 INFO L284 TraceCheckUtils]: 23: Hoare quadruple {29176#true} {29176#true} #1138#return; {29176#true} is VALID [2022-02-20 18:00:59,392 INFO L290 TraceCheckUtils]: 24: Hoare triple {29176#true} assume { :end_inline_setup_rjh__wrappee__Base } true; {29176#true} is VALID [2022-02-20 18:00:59,392 INFO L272 TraceCheckUtils]: 25: Hoare triple {29176#true} call setClientPrivateKey(setup_rjh_~rjh___0#1, 456); {29176#true} is VALID [2022-02-20 18:00:59,392 INFO L290 TraceCheckUtils]: 26: Hoare triple {29176#true} ~handle := #in~handle;~value := #in~value; {29176#true} is VALID [2022-02-20 18:00:59,392 INFO L290 TraceCheckUtils]: 27: Hoare triple {29176#true} assume !(1 == ~handle); {29176#true} is VALID [2022-02-20 18:00:59,393 INFO L290 TraceCheckUtils]: 28: Hoare triple {29176#true} assume 2 == ~handle;~__ste_client_privateKey1~0 := ~value; {29176#true} is VALID [2022-02-20 18:00:59,393 INFO L290 TraceCheckUtils]: 29: Hoare triple {29176#true} assume true; {29176#true} is VALID [2022-02-20 18:00:59,393 INFO L284 TraceCheckUtils]: 30: Hoare quadruple {29176#true} {29176#true} #1140#return; {29176#true} is VALID [2022-02-20 18:00:59,393 INFO L290 TraceCheckUtils]: 31: Hoare triple {29176#true} assume { :end_inline_setup_rjh } true;setup_~__cil_tmp2~0#1.base, setup_~__cil_tmp2~0#1.offset := 19, 0;havoc setup_#t~nondet33#1;~chuck~0 := 3;assume { :begin_inline_setup_chuck } true;setup_chuck_#in~chuck___0#1 := ~chuck~0;havoc setup_chuck_~chuck___0#1;setup_chuck_~chuck___0#1 := setup_chuck_#in~chuck___0#1;assume { :begin_inline_setup_chuck__wrappee__Base } true;setup_chuck__wrappee__Base_#in~chuck___0#1 := setup_chuck_~chuck___0#1;havoc setup_chuck__wrappee__Base_~chuck___0#1;setup_chuck__wrappee__Base_~chuck___0#1 := setup_chuck__wrappee__Base_#in~chuck___0#1; {29176#true} is VALID [2022-02-20 18:00:59,393 INFO L272 TraceCheckUtils]: 32: Hoare triple {29176#true} call setClientId(setup_chuck__wrappee__Base_~chuck___0#1, setup_chuck__wrappee__Base_~chuck___0#1); {29176#true} is VALID [2022-02-20 18:00:59,393 INFO L290 TraceCheckUtils]: 33: Hoare triple {29176#true} ~handle := #in~handle;~value := #in~value; {29176#true} is VALID [2022-02-20 18:00:59,393 INFO L290 TraceCheckUtils]: 34: Hoare triple {29176#true} assume !(1 == ~handle); {29176#true} is VALID [2022-02-20 18:00:59,393 INFO L290 TraceCheckUtils]: 35: Hoare triple {29176#true} assume !(2 == ~handle); {29176#true} is VALID [2022-02-20 18:00:59,393 INFO L290 TraceCheckUtils]: 36: Hoare triple {29176#true} assume 3 == ~handle;~__ste_client_idCounter2~0 := ~value; {29176#true} is VALID [2022-02-20 18:00:59,393 INFO L290 TraceCheckUtils]: 37: Hoare triple {29176#true} assume true; {29176#true} is VALID [2022-02-20 18:00:59,394 INFO L284 TraceCheckUtils]: 38: Hoare quadruple {29176#true} {29176#true} #1142#return; {29176#true} is VALID [2022-02-20 18:00:59,394 INFO L290 TraceCheckUtils]: 39: Hoare triple {29176#true} assume { :end_inline_setup_chuck__wrappee__Base } true; {29176#true} is VALID [2022-02-20 18:00:59,394 INFO L272 TraceCheckUtils]: 40: Hoare triple {29176#true} call setClientPrivateKey(setup_chuck_~chuck___0#1, 789); {29176#true} is VALID [2022-02-20 18:00:59,394 INFO L290 TraceCheckUtils]: 41: Hoare triple {29176#true} ~handle := #in~handle;~value := #in~value; {29176#true} is VALID [2022-02-20 18:00:59,394 INFO L290 TraceCheckUtils]: 42: Hoare triple {29176#true} assume !(1 == ~handle); {29176#true} is VALID [2022-02-20 18:00:59,394 INFO L290 TraceCheckUtils]: 43: Hoare triple {29176#true} assume !(2 == ~handle); {29176#true} is VALID [2022-02-20 18:00:59,394 INFO L290 TraceCheckUtils]: 44: Hoare triple {29176#true} assume 3 == ~handle;~__ste_client_privateKey2~0 := ~value; {29176#true} is VALID [2022-02-20 18:00:59,394 INFO L290 TraceCheckUtils]: 45: Hoare triple {29176#true} assume true; {29176#true} is VALID [2022-02-20 18:00:59,394 INFO L284 TraceCheckUtils]: 46: Hoare quadruple {29176#true} {29176#true} #1144#return; {29176#true} is VALID [2022-02-20 18:00:59,394 INFO L290 TraceCheckUtils]: 47: Hoare triple {29176#true} assume { :end_inline_setup_chuck } true;setup_~__cil_tmp3~0#1.base, setup_~__cil_tmp3~0#1.offset := 20, 0;havoc setup_#t~nondet34#1; {29176#true} is VALID [2022-02-20 18:00:59,395 INFO L290 TraceCheckUtils]: 48: Hoare triple {29176#true} assume { :end_inline_setup } true;assume { :begin_inline_test } true;havoc test_#t~nondet47#1, test_#t~nondet48#1, test_#t~nondet49#1, test_#t~nondet50#1, test_#t~nondet51#1, test_#t~nondet52#1, test_#t~nondet53#1, test_#t~nondet54#1, test_#t~nondet55#1, test_#t~nondet56#1, test_#t~nondet57#1, test_~op1~0#1, test_~op2~0#1, test_~op3~0#1, test_~op4~0#1, test_~op5~0#1, test_~op6~0#1, test_~op7~0#1, test_~op8~0#1, test_~op9~0#1, test_~op10~0#1, test_~op11~0#1, test_~splverifierCounter~0#1, test_~tmp~6#1, test_~tmp___0~2#1, test_~tmp___1~1#1, test_~tmp___2~0#1, test_~tmp___3~0#1, test_~tmp___4~0#1, test_~tmp___5~0#1, test_~tmp___6~0#1, test_~tmp___7~0#1, test_~tmp___8~0#1, test_~tmp___9~0#1;havoc test_~op1~0#1;havoc test_~op2~0#1;havoc test_~op3~0#1;havoc test_~op4~0#1;havoc test_~op5~0#1;havoc test_~op6~0#1;havoc test_~op7~0#1;havoc test_~op8~0#1;havoc test_~op9~0#1;havoc test_~op10~0#1;havoc test_~op11~0#1;havoc test_~splverifierCounter~0#1;havoc test_~tmp~6#1;havoc test_~tmp___0~2#1;havoc test_~tmp___1~1#1;havoc test_~tmp___2~0#1;havoc test_~tmp___3~0#1;havoc test_~tmp___4~0#1;havoc test_~tmp___5~0#1;havoc test_~tmp___6~0#1;havoc test_~tmp___7~0#1;havoc test_~tmp___8~0#1;havoc test_~tmp___9~0#1;test_~op1~0#1 := 0;test_~op2~0#1 := 0;test_~op3~0#1 := 0;test_~op4~0#1 := 0;test_~op5~0#1 := 0;test_~op6~0#1 := 0;test_~op7~0#1 := 0;test_~op8~0#1 := 0;test_~op9~0#1 := 0;test_~op10~0#1 := 0;test_~op11~0#1 := 0;test_~splverifierCounter~0#1 := 0; {29397#(<= |ULTIMATE.start_test_~splverifierCounter~0#1| 0)} is VALID [2022-02-20 18:00:59,395 INFO L290 TraceCheckUtils]: 49: Hoare triple {29397#(<= |ULTIMATE.start_test_~splverifierCounter~0#1| 0)} assume !false; {29397#(<= |ULTIMATE.start_test_~splverifierCounter~0#1| 0)} is VALID [2022-02-20 18:00:59,395 INFO L290 TraceCheckUtils]: 50: Hoare triple {29397#(<= |ULTIMATE.start_test_~splverifierCounter~0#1| 0)} assume test_~splverifierCounter~0#1 < 4; {29397#(<= |ULTIMATE.start_test_~splverifierCounter~0#1| 0)} is VALID [2022-02-20 18:00:59,396 INFO L290 TraceCheckUtils]: 51: Hoare triple {29397#(<= |ULTIMATE.start_test_~splverifierCounter~0#1| 0)} test_~splverifierCounter~0#1 := 1 + test_~splverifierCounter~0#1; {29407#(<= |ULTIMATE.start_test_~splverifierCounter~0#1| 1)} is VALID [2022-02-20 18:00:59,396 INFO L290 TraceCheckUtils]: 52: Hoare triple {29407#(<= |ULTIMATE.start_test_~splverifierCounter~0#1| 1)} assume 0 == test_~op1~0#1;assume -2147483648 <= test_#t~nondet47#1 && test_#t~nondet47#1 <= 2147483647;test_~tmp___9~0#1 := test_#t~nondet47#1;havoc test_#t~nondet47#1; {29407#(<= |ULTIMATE.start_test_~splverifierCounter~0#1| 1)} is VALID [2022-02-20 18:00:59,397 INFO L290 TraceCheckUtils]: 53: Hoare triple {29407#(<= |ULTIMATE.start_test_~splverifierCounter~0#1| 1)} assume !(0 != test_~tmp___9~0#1); {29407#(<= |ULTIMATE.start_test_~splverifierCounter~0#1| 1)} is VALID [2022-02-20 18:00:59,397 INFO L290 TraceCheckUtils]: 54: Hoare triple {29407#(<= |ULTIMATE.start_test_~splverifierCounter~0#1| 1)} assume 0 == test_~op2~0#1;assume -2147483648 <= test_#t~nondet48#1 && test_#t~nondet48#1 <= 2147483647;test_~tmp___8~0#1 := test_#t~nondet48#1;havoc test_#t~nondet48#1; {29407#(<= |ULTIMATE.start_test_~splverifierCounter~0#1| 1)} is VALID [2022-02-20 18:00:59,397 INFO L290 TraceCheckUtils]: 55: Hoare triple {29407#(<= |ULTIMATE.start_test_~splverifierCounter~0#1| 1)} assume 0 != test_~tmp___8~0#1;assume { :begin_inline_rjhSetAutoRespond } true;assume { :begin_inline_setClientAutoResponse } true;setClientAutoResponse_#in~handle#1, setClientAutoResponse_#in~value#1 := ~rjh~0, 1;havoc setClientAutoResponse_~handle#1, setClientAutoResponse_~value#1;setClientAutoResponse_~handle#1 := setClientAutoResponse_#in~handle#1;setClientAutoResponse_~value#1 := setClientAutoResponse_#in~value#1; {29407#(<= |ULTIMATE.start_test_~splverifierCounter~0#1| 1)} is VALID [2022-02-20 18:00:59,397 INFO L290 TraceCheckUtils]: 56: Hoare triple {29407#(<= |ULTIMATE.start_test_~splverifierCounter~0#1| 1)} assume 1 == setClientAutoResponse_~handle#1;~__ste_client_autoResponse0~0 := setClientAutoResponse_~value#1; {29407#(<= |ULTIMATE.start_test_~splverifierCounter~0#1| 1)} is VALID [2022-02-20 18:00:59,398 INFO L290 TraceCheckUtils]: 57: Hoare triple {29407#(<= |ULTIMATE.start_test_~splverifierCounter~0#1| 1)} assume { :end_inline_setClientAutoResponse } true; {29407#(<= |ULTIMATE.start_test_~splverifierCounter~0#1| 1)} is VALID [2022-02-20 18:00:59,398 INFO L290 TraceCheckUtils]: 58: Hoare triple {29407#(<= |ULTIMATE.start_test_~splverifierCounter~0#1| 1)} assume { :end_inline_rjhSetAutoRespond } true;test_~op2~0#1 := 1; {29407#(<= |ULTIMATE.start_test_~splverifierCounter~0#1| 1)} is VALID [2022-02-20 18:00:59,398 INFO L290 TraceCheckUtils]: 59: Hoare triple {29407#(<= |ULTIMATE.start_test_~splverifierCounter~0#1| 1)} assume !false; {29407#(<= |ULTIMATE.start_test_~splverifierCounter~0#1| 1)} is VALID [2022-02-20 18:00:59,399 INFO L290 TraceCheckUtils]: 60: Hoare triple {29407#(<= |ULTIMATE.start_test_~splverifierCounter~0#1| 1)} assume !(test_~splverifierCounter~0#1 < 4); {29177#false} is VALID [2022-02-20 18:00:59,400 INFO L290 TraceCheckUtils]: 61: Hoare triple {29177#false} assume { :begin_inline_bobToRjh } true;havoc bobToRjh_#t~ret27#1, bobToRjh_#t~ret28#1, bobToRjh_#t~ret29#1, bobToRjh_#t~ret30#1, bobToRjh_~tmp~3#1, bobToRjh_~tmp___0~0#1, bobToRjh_~tmp___1~0#1;havoc bobToRjh_~tmp~3#1;havoc bobToRjh_~tmp___0~0#1;havoc bobToRjh_~tmp___1~0#1;call bobToRjh_#t~ret27#1 := puts(16, 0);assume -2147483648 <= bobToRjh_#t~ret27#1 && bobToRjh_#t~ret27#1 <= 2147483647;havoc bobToRjh_#t~ret27#1; {29177#false} is VALID [2022-02-20 18:00:59,400 INFO L272 TraceCheckUtils]: 62: Hoare triple {29177#false} call sendEmail(~bob~0, ~rjh~0); {29177#false} is VALID [2022-02-20 18:00:59,400 INFO L290 TraceCheckUtils]: 63: Hoare triple {29177#false} ~sender#1 := #in~sender#1;~receiver#1 := #in~receiver#1;havoc ~email~0#1;havoc ~tmp~14#1;assume { :begin_inline_createEmail } true;createEmail_#in~from#1, createEmail_#in~to#1 := 0, ~receiver#1;havoc createEmail_#res#1;havoc createEmail_~from#1, createEmail_~to#1, createEmail_~retValue_acc~31#1, createEmail_~msg~0#1;createEmail_~from#1 := createEmail_#in~from#1;createEmail_~to#1 := createEmail_#in~to#1;havoc createEmail_~retValue_acc~31#1;havoc createEmail_~msg~0#1;createEmail_~msg~0#1 := 1; {29177#false} is VALID [2022-02-20 18:00:59,400 INFO L272 TraceCheckUtils]: 64: Hoare triple {29177#false} call setEmailFrom(createEmail_~msg~0#1, createEmail_~from#1); {29177#false} is VALID [2022-02-20 18:00:59,400 INFO L290 TraceCheckUtils]: 65: Hoare triple {29177#false} ~handle := #in~handle;~value := #in~value; {29177#false} is VALID [2022-02-20 18:00:59,400 INFO L290 TraceCheckUtils]: 66: Hoare triple {29177#false} assume 1 == ~handle;~__ste_email_from0~0 := ~value; {29177#false} is VALID [2022-02-20 18:00:59,400 INFO L290 TraceCheckUtils]: 67: Hoare triple {29177#false} assume true; {29177#false} is VALID [2022-02-20 18:00:59,400 INFO L284 TraceCheckUtils]: 68: Hoare quadruple {29177#false} {29177#false} #1120#return; {29177#false} is VALID [2022-02-20 18:00:59,400 INFO L272 TraceCheckUtils]: 69: Hoare triple {29177#false} call setEmailTo(createEmail_~msg~0#1, createEmail_~to#1); {29177#false} is VALID [2022-02-20 18:00:59,401 INFO L290 TraceCheckUtils]: 70: Hoare triple {29177#false} ~handle := #in~handle;~value := #in~value; {29177#false} is VALID [2022-02-20 18:00:59,401 INFO L290 TraceCheckUtils]: 71: Hoare triple {29177#false} assume 1 == ~handle;~__ste_email_to0~0 := ~value; {29177#false} is VALID [2022-02-20 18:00:59,407 INFO L290 TraceCheckUtils]: 72: Hoare triple {29177#false} assume true; {29177#false} is VALID [2022-02-20 18:00:59,407 INFO L284 TraceCheckUtils]: 73: Hoare quadruple {29177#false} {29177#false} #1122#return; {29177#false} is VALID [2022-02-20 18:00:59,407 INFO L290 TraceCheckUtils]: 74: Hoare triple {29177#false} createEmail_~retValue_acc~31#1 := createEmail_~msg~0#1;createEmail_#res#1 := createEmail_~retValue_acc~31#1; {29177#false} is VALID [2022-02-20 18:00:59,408 INFO L290 TraceCheckUtils]: 75: Hoare triple {29177#false} #t~ret72#1 := createEmail_#res#1;assume { :end_inline_createEmail } true;assume -2147483648 <= #t~ret72#1 && #t~ret72#1 <= 2147483647;~tmp~14#1 := #t~ret72#1;havoc #t~ret72#1;~email~0#1 := ~tmp~14#1; {29177#false} is VALID [2022-02-20 18:00:59,408 INFO L272 TraceCheckUtils]: 76: Hoare triple {29177#false} call outgoing(~sender#1, ~email~0#1); {29177#false} is VALID [2022-02-20 18:00:59,408 INFO L290 TraceCheckUtils]: 77: Hoare triple {29177#false} ~client#1 := #in~client#1;~msg#1 := #in~msg#1;assume { :begin_inline_sign } true;sign_#in~client#1, sign_#in~msg#1 := ~client#1, ~msg#1;havoc sign_#t~ret76#1, sign_~client#1, sign_~msg#1, sign_~privkey~1#1, sign_~tmp~16#1;sign_~client#1 := sign_#in~client#1;sign_~msg#1 := sign_#in~msg#1;havoc sign_~privkey~1#1;havoc sign_~tmp~16#1; {29177#false} is VALID [2022-02-20 18:00:59,408 INFO L272 TraceCheckUtils]: 78: Hoare triple {29177#false} call sign_#t~ret76#1 := getClientPrivateKey(sign_~client#1); {29177#false} is VALID [2022-02-20 18:00:59,408 INFO L290 TraceCheckUtils]: 79: Hoare triple {29177#false} ~handle := #in~handle;havoc ~retValue_acc~20; {29177#false} is VALID [2022-02-20 18:00:59,408 INFO L290 TraceCheckUtils]: 80: Hoare triple {29177#false} assume 1 == ~handle;~retValue_acc~20 := ~__ste_client_privateKey0~0;#res := ~retValue_acc~20; {29177#false} is VALID [2022-02-20 18:00:59,408 INFO L290 TraceCheckUtils]: 81: Hoare triple {29177#false} assume true; {29177#false} is VALID [2022-02-20 18:00:59,408 INFO L284 TraceCheckUtils]: 82: Hoare quadruple {29177#false} {29177#false} #1054#return; {29177#false} is VALID [2022-02-20 18:00:59,408 INFO L290 TraceCheckUtils]: 83: Hoare triple {29177#false} assume -2147483648 <= sign_#t~ret76#1 && sign_#t~ret76#1 <= 2147483647;sign_~tmp~16#1 := sign_#t~ret76#1;havoc sign_#t~ret76#1;sign_~privkey~1#1 := sign_~tmp~16#1; {29177#false} is VALID [2022-02-20 18:00:59,408 INFO L290 TraceCheckUtils]: 84: Hoare triple {29177#false} assume 0 == sign_~privkey~1#1; {29177#false} is VALID [2022-02-20 18:00:59,423 INFO L290 TraceCheckUtils]: 85: Hoare triple {29177#false} assume { :end_inline_sign } true;assume { :begin_inline_outgoing__wrappee__AutoResponder } true;outgoing__wrappee__AutoResponder_#in~client#1, outgoing__wrappee__AutoResponder_#in~msg#1 := ~client#1, ~msg#1;havoc outgoing__wrappee__AutoResponder_#t~ret62#1, outgoing__wrappee__AutoResponder_#t~ret63#1, outgoing__wrappee__AutoResponder_~client#1, outgoing__wrappee__AutoResponder_~msg#1, outgoing__wrappee__AutoResponder_~receiver~0#1, outgoing__wrappee__AutoResponder_~tmp~9#1, outgoing__wrappee__AutoResponder_~pubkey~0#1, outgoing__wrappee__AutoResponder_~tmp___0~3#1;outgoing__wrappee__AutoResponder_~client#1 := outgoing__wrappee__AutoResponder_#in~client#1;outgoing__wrappee__AutoResponder_~msg#1 := outgoing__wrappee__AutoResponder_#in~msg#1;havoc outgoing__wrappee__AutoResponder_~receiver~0#1;havoc outgoing__wrappee__AutoResponder_~tmp~9#1;havoc outgoing__wrappee__AutoResponder_~pubkey~0#1;havoc outgoing__wrappee__AutoResponder_~tmp___0~3#1; {29177#false} is VALID [2022-02-20 18:00:59,423 INFO L272 TraceCheckUtils]: 86: Hoare triple {29177#false} call outgoing__wrappee__AutoResponder_#t~ret62#1 := getEmailTo(outgoing__wrappee__AutoResponder_~msg#1); {29177#false} is VALID [2022-02-20 18:00:59,424 INFO L290 TraceCheckUtils]: 87: Hoare triple {29177#false} ~handle := #in~handle;havoc ~retValue_acc~36; {29177#false} is VALID [2022-02-20 18:00:59,424 INFO L290 TraceCheckUtils]: 88: Hoare triple {29177#false} assume 1 == ~handle;~retValue_acc~36 := ~__ste_email_to0~0;#res := ~retValue_acc~36; {29177#false} is VALID [2022-02-20 18:00:59,424 INFO L290 TraceCheckUtils]: 89: Hoare triple {29177#false} assume true; {29177#false} is VALID [2022-02-20 18:00:59,424 INFO L284 TraceCheckUtils]: 90: Hoare quadruple {29177#false} {29177#false} #1056#return; {29177#false} is VALID [2022-02-20 18:00:59,424 INFO L290 TraceCheckUtils]: 91: Hoare triple {29177#false} assume -2147483648 <= outgoing__wrappee__AutoResponder_#t~ret62#1 && outgoing__wrappee__AutoResponder_#t~ret62#1 <= 2147483647;outgoing__wrappee__AutoResponder_~tmp~9#1 := outgoing__wrappee__AutoResponder_#t~ret62#1;havoc outgoing__wrappee__AutoResponder_#t~ret62#1;outgoing__wrappee__AutoResponder_~receiver~0#1 := outgoing__wrappee__AutoResponder_~tmp~9#1; {29177#false} is VALID [2022-02-20 18:00:59,424 INFO L272 TraceCheckUtils]: 92: Hoare triple {29177#false} call outgoing__wrappee__AutoResponder_#t~ret63#1 := findPublicKey(outgoing__wrappee__AutoResponder_~client#1, outgoing__wrappee__AutoResponder_~receiver~0#1); {29177#false} is VALID [2022-02-20 18:00:59,424 INFO L290 TraceCheckUtils]: 93: Hoare triple {29177#false} ~handle := #in~handle;~userid := #in~userid;havoc ~retValue_acc~25; {29177#false} is VALID [2022-02-20 18:00:59,425 INFO L290 TraceCheckUtils]: 94: Hoare triple {29177#false} assume 1 == ~handle; {29177#false} is VALID [2022-02-20 18:00:59,425 INFO L290 TraceCheckUtils]: 95: Hoare triple {29177#false} assume ~userid == ~__ste_Client_Keyring0_User0~0;~retValue_acc~25 := ~__ste_Client_Keyring0_PublicKey0~0;#res := ~retValue_acc~25; {29177#false} is VALID [2022-02-20 18:00:59,425 INFO L290 TraceCheckUtils]: 96: Hoare triple {29177#false} assume true; {29177#false} is VALID [2022-02-20 18:00:59,425 INFO L284 TraceCheckUtils]: 97: Hoare quadruple {29177#false} {29177#false} #1058#return; {29177#false} is VALID [2022-02-20 18:00:59,425 INFO L290 TraceCheckUtils]: 98: Hoare triple {29177#false} assume -2147483648 <= outgoing__wrappee__AutoResponder_#t~ret63#1 && outgoing__wrappee__AutoResponder_#t~ret63#1 <= 2147483647;outgoing__wrappee__AutoResponder_~tmp___0~3#1 := outgoing__wrappee__AutoResponder_#t~ret63#1;havoc outgoing__wrappee__AutoResponder_#t~ret63#1;outgoing__wrappee__AutoResponder_~pubkey~0#1 := outgoing__wrappee__AutoResponder_~tmp___0~3#1; {29177#false} is VALID [2022-02-20 18:00:59,425 INFO L290 TraceCheckUtils]: 99: Hoare triple {29177#false} assume !(0 != outgoing__wrappee__AutoResponder_~pubkey~0#1); {29177#false} is VALID [2022-02-20 18:00:59,425 INFO L290 TraceCheckUtils]: 100: Hoare triple {29177#false} assume { :begin_inline_outgoing__wrappee__Keys } true;outgoing__wrappee__Keys_#in~client#1, outgoing__wrappee__Keys_#in~msg#1 := outgoing__wrappee__AutoResponder_~client#1, outgoing__wrappee__AutoResponder_~msg#1;havoc outgoing__wrappee__Keys_#t~ret61#1, outgoing__wrappee__Keys_~client#1, outgoing__wrappee__Keys_~msg#1, outgoing__wrappee__Keys_~tmp~8#1;outgoing__wrappee__Keys_~client#1 := outgoing__wrappee__Keys_#in~client#1;outgoing__wrappee__Keys_~msg#1 := outgoing__wrappee__Keys_#in~msg#1;havoc outgoing__wrappee__Keys_~tmp~8#1;assume { :begin_inline_getClientId } true;getClientId_#in~handle#1 := outgoing__wrappee__Keys_~client#1;havoc getClientId_#res#1;havoc getClientId_~handle#1, getClientId_~retValue_acc~27#1;getClientId_~handle#1 := getClientId_#in~handle#1;havoc getClientId_~retValue_acc~27#1; {29177#false} is VALID [2022-02-20 18:00:59,425 INFO L290 TraceCheckUtils]: 101: Hoare triple {29177#false} assume 1 == getClientId_~handle#1;getClientId_~retValue_acc~27#1 := ~__ste_client_idCounter0~0;getClientId_#res#1 := getClientId_~retValue_acc~27#1; {29177#false} is VALID [2022-02-20 18:00:59,426 INFO L290 TraceCheckUtils]: 102: Hoare triple {29177#false} outgoing__wrappee__Keys_#t~ret61#1 := getClientId_#res#1;assume { :end_inline_getClientId } true;assume -2147483648 <= outgoing__wrappee__Keys_#t~ret61#1 && outgoing__wrappee__Keys_#t~ret61#1 <= 2147483647;outgoing__wrappee__Keys_~tmp~8#1 := outgoing__wrappee__Keys_#t~ret61#1;havoc outgoing__wrappee__Keys_#t~ret61#1; {29177#false} is VALID [2022-02-20 18:00:59,426 INFO L272 TraceCheckUtils]: 103: Hoare triple {29177#false} call setEmailFrom(outgoing__wrappee__Keys_~msg#1, outgoing__wrappee__Keys_~tmp~8#1); {29177#false} is VALID [2022-02-20 18:00:59,426 INFO L290 TraceCheckUtils]: 104: Hoare triple {29177#false} ~handle := #in~handle;~value := #in~value; {29177#false} is VALID [2022-02-20 18:00:59,426 INFO L290 TraceCheckUtils]: 105: Hoare triple {29177#false} assume 1 == ~handle;~__ste_email_from0~0 := ~value; {29177#false} is VALID [2022-02-20 18:00:59,426 INFO L290 TraceCheckUtils]: 106: Hoare triple {29177#false} assume true; {29177#false} is VALID [2022-02-20 18:00:59,426 INFO L284 TraceCheckUtils]: 107: Hoare quadruple {29177#false} {29177#false} #1064#return; {29177#false} is VALID [2022-02-20 18:00:59,426 INFO L290 TraceCheckUtils]: 108: Hoare triple {29177#false} assume { :begin_inline_mail } true;mail_#in~client#1, mail_#in~msg#1 := outgoing__wrappee__Keys_~client#1, outgoing__wrappee__Keys_~msg#1;havoc mail_#t~ret59#1, mail_#t~ret60#1, mail_~client#1, mail_~msg#1, mail_~__utac__ad__arg1~0#1, mail_~__utac__ad__arg2~0#1, mail_~tmp~7#1;mail_~client#1 := mail_#in~client#1;mail_~msg#1 := mail_#in~msg#1;havoc mail_~__utac__ad__arg1~0#1;havoc mail_~__utac__ad__arg2~0#1;havoc mail_~tmp~7#1;mail_~__utac__ad__arg1~0#1 := mail_~client#1;mail_~__utac__ad__arg2~0#1 := mail_~msg#1;assume { :begin_inline___utac_acc__SignForward_spec__1 } true;__utac_acc__SignForward_spec__1_#in~client#1, __utac_acc__SignForward_spec__1_#in~msg#1 := mail_~__utac__ad__arg1~0#1, mail_~__utac__ad__arg2~0#1;havoc __utac_acc__SignForward_spec__1_#t~ret107#1, __utac_acc__SignForward_spec__1_#t~ret108#1, __utac_acc__SignForward_spec__1_#t~ret109#1, __utac_acc__SignForward_spec__1_~client#1, __utac_acc__SignForward_spec__1_~msg#1, __utac_acc__SignForward_spec__1_~tmp~25#1, __utac_acc__SignForward_spec__1_~tmp___0~9#1;__utac_acc__SignForward_spec__1_~client#1 := __utac_acc__SignForward_spec__1_#in~client#1;__utac_acc__SignForward_spec__1_~msg#1 := __utac_acc__SignForward_spec__1_#in~msg#1;havoc __utac_acc__SignForward_spec__1_~tmp~25#1;havoc __utac_acc__SignForward_spec__1_~tmp___0~9#1;call __utac_acc__SignForward_spec__1_#t~ret107#1 := puts(39, 0);assume -2147483648 <= __utac_acc__SignForward_spec__1_#t~ret107#1 && __utac_acc__SignForward_spec__1_#t~ret107#1 <= 2147483647;havoc __utac_acc__SignForward_spec__1_#t~ret107#1; {29177#false} is VALID [2022-02-20 18:00:59,426 INFO L272 TraceCheckUtils]: 109: Hoare triple {29177#false} call __utac_acc__SignForward_spec__1_#t~ret108#1 := isSigned(__utac_acc__SignForward_spec__1_~msg#1); {29177#false} is VALID [2022-02-20 18:00:59,427 INFO L290 TraceCheckUtils]: 110: Hoare triple {29177#false} ~handle := #in~handle;havoc ~retValue_acc~41; {29177#false} is VALID [2022-02-20 18:00:59,427 INFO L290 TraceCheckUtils]: 111: Hoare triple {29177#false} assume 1 == ~handle;~retValue_acc~41 := ~__ste_email_isSigned0~0;#res := ~retValue_acc~41; {29177#false} is VALID [2022-02-20 18:00:59,427 INFO L290 TraceCheckUtils]: 112: Hoare triple {29177#false} assume true; {29177#false} is VALID [2022-02-20 18:00:59,427 INFO L284 TraceCheckUtils]: 113: Hoare quadruple {29177#false} {29177#false} #1066#return; {29177#false} is VALID [2022-02-20 18:00:59,427 INFO L290 TraceCheckUtils]: 114: Hoare triple {29177#false} assume -2147483648 <= __utac_acc__SignForward_spec__1_#t~ret108#1 && __utac_acc__SignForward_spec__1_#t~ret108#1 <= 2147483647;__utac_acc__SignForward_spec__1_~tmp___0~9#1 := __utac_acc__SignForward_spec__1_#t~ret108#1;havoc __utac_acc__SignForward_spec__1_#t~ret108#1; {29177#false} is VALID [2022-02-20 18:00:59,427 INFO L290 TraceCheckUtils]: 115: Hoare triple {29177#false} assume 0 != __utac_acc__SignForward_spec__1_~tmp___0~9#1; {29177#false} is VALID [2022-02-20 18:00:59,428 INFO L272 TraceCheckUtils]: 116: Hoare triple {29177#false} call __utac_acc__SignForward_spec__1_#t~ret109#1 := getClientPrivateKey(__utac_acc__SignForward_spec__1_~client#1); {29177#false} is VALID [2022-02-20 18:00:59,428 INFO L290 TraceCheckUtils]: 117: Hoare triple {29177#false} ~handle := #in~handle;havoc ~retValue_acc~20; {29177#false} is VALID [2022-02-20 18:00:59,428 INFO L290 TraceCheckUtils]: 118: Hoare triple {29177#false} assume 1 == ~handle;~retValue_acc~20 := ~__ste_client_privateKey0~0;#res := ~retValue_acc~20; {29177#false} is VALID [2022-02-20 18:00:59,428 INFO L290 TraceCheckUtils]: 119: Hoare triple {29177#false} assume true; {29177#false} is VALID [2022-02-20 18:00:59,428 INFO L284 TraceCheckUtils]: 120: Hoare quadruple {29177#false} {29177#false} #1068#return; {29177#false} is VALID [2022-02-20 18:00:59,428 INFO L290 TraceCheckUtils]: 121: Hoare triple {29177#false} assume -2147483648 <= __utac_acc__SignForward_spec__1_#t~ret109#1 && __utac_acc__SignForward_spec__1_#t~ret109#1 <= 2147483647;__utac_acc__SignForward_spec__1_~tmp~25#1 := __utac_acc__SignForward_spec__1_#t~ret109#1;havoc __utac_acc__SignForward_spec__1_#t~ret109#1; {29177#false} is VALID [2022-02-20 18:00:59,428 INFO L290 TraceCheckUtils]: 122: Hoare triple {29177#false} assume 0 == __utac_acc__SignForward_spec__1_~tmp~25#1;assume { :begin_inline___automaton_fail } true; {29177#false} is VALID [2022-02-20 18:00:59,428 INFO L290 TraceCheckUtils]: 123: Hoare triple {29177#false} assume !false; {29177#false} is VALID [2022-02-20 18:00:59,429 INFO L134 CoverageAnalysis]: Checked inductivity of 36 backedges. 0 proven. 2 refuted. 0 times theorem prover too weak. 34 trivial. 0 not checked. [2022-02-20 18:00:59,429 INFO L328 TraceCheckSpWp]: Computing backward predicates... [2022-02-20 18:00:59,876 INFO L290 TraceCheckUtils]: 123: Hoare triple {29177#false} assume !false; {29177#false} is VALID [2022-02-20 18:00:59,877 INFO L290 TraceCheckUtils]: 122: Hoare triple {29177#false} assume 0 == __utac_acc__SignForward_spec__1_~tmp~25#1;assume { :begin_inline___automaton_fail } true; {29177#false} is VALID [2022-02-20 18:00:59,877 INFO L290 TraceCheckUtils]: 121: Hoare triple {29177#false} assume -2147483648 <= __utac_acc__SignForward_spec__1_#t~ret109#1 && __utac_acc__SignForward_spec__1_#t~ret109#1 <= 2147483647;__utac_acc__SignForward_spec__1_~tmp~25#1 := __utac_acc__SignForward_spec__1_#t~ret109#1;havoc __utac_acc__SignForward_spec__1_#t~ret109#1; {29177#false} is VALID [2022-02-20 18:00:59,877 INFO L284 TraceCheckUtils]: 120: Hoare quadruple {29176#true} {29177#false} #1068#return; {29177#false} is VALID [2022-02-20 18:00:59,877 INFO L290 TraceCheckUtils]: 119: Hoare triple {29176#true} assume true; {29176#true} is VALID [2022-02-20 18:00:59,877 INFO L290 TraceCheckUtils]: 118: Hoare triple {29176#true} assume 1 == ~handle;~retValue_acc~20 := ~__ste_client_privateKey0~0;#res := ~retValue_acc~20; {29176#true} is VALID [2022-02-20 18:00:59,877 INFO L290 TraceCheckUtils]: 117: Hoare triple {29176#true} ~handle := #in~handle;havoc ~retValue_acc~20; {29176#true} is VALID [2022-02-20 18:00:59,877 INFO L272 TraceCheckUtils]: 116: Hoare triple {29177#false} call __utac_acc__SignForward_spec__1_#t~ret109#1 := getClientPrivateKey(__utac_acc__SignForward_spec__1_~client#1); {29176#true} is VALID [2022-02-20 18:00:59,877 INFO L290 TraceCheckUtils]: 115: Hoare triple {29177#false} assume 0 != __utac_acc__SignForward_spec__1_~tmp___0~9#1; {29177#false} is VALID [2022-02-20 18:00:59,877 INFO L290 TraceCheckUtils]: 114: Hoare triple {29177#false} assume -2147483648 <= __utac_acc__SignForward_spec__1_#t~ret108#1 && __utac_acc__SignForward_spec__1_#t~ret108#1 <= 2147483647;__utac_acc__SignForward_spec__1_~tmp___0~9#1 := __utac_acc__SignForward_spec__1_#t~ret108#1;havoc __utac_acc__SignForward_spec__1_#t~ret108#1; {29177#false} is VALID [2022-02-20 18:00:59,877 INFO L284 TraceCheckUtils]: 113: Hoare quadruple {29176#true} {29177#false} #1066#return; {29177#false} is VALID [2022-02-20 18:00:59,878 INFO L290 TraceCheckUtils]: 112: Hoare triple {29176#true} assume true; {29176#true} is VALID [2022-02-20 18:00:59,878 INFO L290 TraceCheckUtils]: 111: Hoare triple {29176#true} assume 1 == ~handle;~retValue_acc~41 := ~__ste_email_isSigned0~0;#res := ~retValue_acc~41; {29176#true} is VALID [2022-02-20 18:00:59,878 INFO L290 TraceCheckUtils]: 110: Hoare triple {29176#true} ~handle := #in~handle;havoc ~retValue_acc~41; {29176#true} is VALID [2022-02-20 18:00:59,878 INFO L272 TraceCheckUtils]: 109: Hoare triple {29177#false} call __utac_acc__SignForward_spec__1_#t~ret108#1 := isSigned(__utac_acc__SignForward_spec__1_~msg#1); {29176#true} is VALID [2022-02-20 18:00:59,878 INFO L290 TraceCheckUtils]: 108: Hoare triple {29177#false} assume { :begin_inline_mail } true;mail_#in~client#1, mail_#in~msg#1 := outgoing__wrappee__Keys_~client#1, outgoing__wrappee__Keys_~msg#1;havoc mail_#t~ret59#1, mail_#t~ret60#1, mail_~client#1, mail_~msg#1, mail_~__utac__ad__arg1~0#1, mail_~__utac__ad__arg2~0#1, mail_~tmp~7#1;mail_~client#1 := mail_#in~client#1;mail_~msg#1 := mail_#in~msg#1;havoc mail_~__utac__ad__arg1~0#1;havoc mail_~__utac__ad__arg2~0#1;havoc mail_~tmp~7#1;mail_~__utac__ad__arg1~0#1 := mail_~client#1;mail_~__utac__ad__arg2~0#1 := mail_~msg#1;assume { :begin_inline___utac_acc__SignForward_spec__1 } true;__utac_acc__SignForward_spec__1_#in~client#1, __utac_acc__SignForward_spec__1_#in~msg#1 := mail_~__utac__ad__arg1~0#1, mail_~__utac__ad__arg2~0#1;havoc __utac_acc__SignForward_spec__1_#t~ret107#1, __utac_acc__SignForward_spec__1_#t~ret108#1, __utac_acc__SignForward_spec__1_#t~ret109#1, __utac_acc__SignForward_spec__1_~client#1, __utac_acc__SignForward_spec__1_~msg#1, __utac_acc__SignForward_spec__1_~tmp~25#1, __utac_acc__SignForward_spec__1_~tmp___0~9#1;__utac_acc__SignForward_spec__1_~client#1 := __utac_acc__SignForward_spec__1_#in~client#1;__utac_acc__SignForward_spec__1_~msg#1 := __utac_acc__SignForward_spec__1_#in~msg#1;havoc __utac_acc__SignForward_spec__1_~tmp~25#1;havoc __utac_acc__SignForward_spec__1_~tmp___0~9#1;call __utac_acc__SignForward_spec__1_#t~ret107#1 := puts(39, 0);assume -2147483648 <= __utac_acc__SignForward_spec__1_#t~ret107#1 && __utac_acc__SignForward_spec__1_#t~ret107#1 <= 2147483647;havoc __utac_acc__SignForward_spec__1_#t~ret107#1; {29177#false} is VALID [2022-02-20 18:00:59,878 INFO L284 TraceCheckUtils]: 107: Hoare quadruple {29176#true} {29177#false} #1064#return; {29177#false} is VALID [2022-02-20 18:00:59,878 INFO L290 TraceCheckUtils]: 106: Hoare triple {29176#true} assume true; {29176#true} is VALID [2022-02-20 18:00:59,878 INFO L290 TraceCheckUtils]: 105: Hoare triple {29176#true} assume 1 == ~handle;~__ste_email_from0~0 := ~value; {29176#true} is VALID [2022-02-20 18:00:59,878 INFO L290 TraceCheckUtils]: 104: Hoare triple {29176#true} ~handle := #in~handle;~value := #in~value; {29176#true} is VALID [2022-02-20 18:00:59,879 INFO L272 TraceCheckUtils]: 103: Hoare triple {29177#false} call setEmailFrom(outgoing__wrappee__Keys_~msg#1, outgoing__wrappee__Keys_~tmp~8#1); {29176#true} is VALID [2022-02-20 18:00:59,879 INFO L290 TraceCheckUtils]: 102: Hoare triple {29177#false} outgoing__wrappee__Keys_#t~ret61#1 := getClientId_#res#1;assume { :end_inline_getClientId } true;assume -2147483648 <= outgoing__wrappee__Keys_#t~ret61#1 && outgoing__wrappee__Keys_#t~ret61#1 <= 2147483647;outgoing__wrappee__Keys_~tmp~8#1 := outgoing__wrappee__Keys_#t~ret61#1;havoc outgoing__wrappee__Keys_#t~ret61#1; {29177#false} is VALID [2022-02-20 18:00:59,879 INFO L290 TraceCheckUtils]: 101: Hoare triple {29177#false} assume 1 == getClientId_~handle#1;getClientId_~retValue_acc~27#1 := ~__ste_client_idCounter0~0;getClientId_#res#1 := getClientId_~retValue_acc~27#1; {29177#false} is VALID [2022-02-20 18:00:59,879 INFO L290 TraceCheckUtils]: 100: Hoare triple {29177#false} assume { :begin_inline_outgoing__wrappee__Keys } true;outgoing__wrappee__Keys_#in~client#1, outgoing__wrappee__Keys_#in~msg#1 := outgoing__wrappee__AutoResponder_~client#1, outgoing__wrappee__AutoResponder_~msg#1;havoc outgoing__wrappee__Keys_#t~ret61#1, outgoing__wrappee__Keys_~client#1, outgoing__wrappee__Keys_~msg#1, outgoing__wrappee__Keys_~tmp~8#1;outgoing__wrappee__Keys_~client#1 := outgoing__wrappee__Keys_#in~client#1;outgoing__wrappee__Keys_~msg#1 := outgoing__wrappee__Keys_#in~msg#1;havoc outgoing__wrappee__Keys_~tmp~8#1;assume { :begin_inline_getClientId } true;getClientId_#in~handle#1 := outgoing__wrappee__Keys_~client#1;havoc getClientId_#res#1;havoc getClientId_~handle#1, getClientId_~retValue_acc~27#1;getClientId_~handle#1 := getClientId_#in~handle#1;havoc getClientId_~retValue_acc~27#1; {29177#false} is VALID [2022-02-20 18:00:59,879 INFO L290 TraceCheckUtils]: 99: Hoare triple {29177#false} assume !(0 != outgoing__wrappee__AutoResponder_~pubkey~0#1); {29177#false} is VALID [2022-02-20 18:00:59,879 INFO L290 TraceCheckUtils]: 98: Hoare triple {29177#false} assume -2147483648 <= outgoing__wrappee__AutoResponder_#t~ret63#1 && outgoing__wrappee__AutoResponder_#t~ret63#1 <= 2147483647;outgoing__wrappee__AutoResponder_~tmp___0~3#1 := outgoing__wrappee__AutoResponder_#t~ret63#1;havoc outgoing__wrappee__AutoResponder_#t~ret63#1;outgoing__wrappee__AutoResponder_~pubkey~0#1 := outgoing__wrappee__AutoResponder_~tmp___0~3#1; {29177#false} is VALID [2022-02-20 18:00:59,879 INFO L284 TraceCheckUtils]: 97: Hoare quadruple {29176#true} {29177#false} #1058#return; {29177#false} is VALID [2022-02-20 18:00:59,879 INFO L290 TraceCheckUtils]: 96: Hoare triple {29176#true} assume true; {29176#true} is VALID [2022-02-20 18:00:59,879 INFO L290 TraceCheckUtils]: 95: Hoare triple {29176#true} assume ~userid == ~__ste_Client_Keyring0_User0~0;~retValue_acc~25 := ~__ste_Client_Keyring0_PublicKey0~0;#res := ~retValue_acc~25; {29176#true} is VALID [2022-02-20 18:00:59,879 INFO L290 TraceCheckUtils]: 94: Hoare triple {29176#true} assume 1 == ~handle; {29176#true} is VALID [2022-02-20 18:00:59,880 INFO L290 TraceCheckUtils]: 93: Hoare triple {29176#true} ~handle := #in~handle;~userid := #in~userid;havoc ~retValue_acc~25; {29176#true} is VALID [2022-02-20 18:00:59,880 INFO L272 TraceCheckUtils]: 92: Hoare triple {29177#false} call outgoing__wrappee__AutoResponder_#t~ret63#1 := findPublicKey(outgoing__wrappee__AutoResponder_~client#1, outgoing__wrappee__AutoResponder_~receiver~0#1); {29176#true} is VALID [2022-02-20 18:00:59,880 INFO L290 TraceCheckUtils]: 91: Hoare triple {29177#false} assume -2147483648 <= outgoing__wrappee__AutoResponder_#t~ret62#1 && outgoing__wrappee__AutoResponder_#t~ret62#1 <= 2147483647;outgoing__wrappee__AutoResponder_~tmp~9#1 := outgoing__wrappee__AutoResponder_#t~ret62#1;havoc outgoing__wrappee__AutoResponder_#t~ret62#1;outgoing__wrappee__AutoResponder_~receiver~0#1 := outgoing__wrappee__AutoResponder_~tmp~9#1; {29177#false} is VALID [2022-02-20 18:00:59,880 INFO L284 TraceCheckUtils]: 90: Hoare quadruple {29176#true} {29177#false} #1056#return; {29177#false} is VALID [2022-02-20 18:00:59,880 INFO L290 TraceCheckUtils]: 89: Hoare triple {29176#true} assume true; {29176#true} is VALID [2022-02-20 18:00:59,880 INFO L290 TraceCheckUtils]: 88: Hoare triple {29176#true} assume 1 == ~handle;~retValue_acc~36 := ~__ste_email_to0~0;#res := ~retValue_acc~36; {29176#true} is VALID [2022-02-20 18:00:59,880 INFO L290 TraceCheckUtils]: 87: Hoare triple {29176#true} ~handle := #in~handle;havoc ~retValue_acc~36; {29176#true} is VALID [2022-02-20 18:00:59,880 INFO L272 TraceCheckUtils]: 86: Hoare triple {29177#false} call outgoing__wrappee__AutoResponder_#t~ret62#1 := getEmailTo(outgoing__wrappee__AutoResponder_~msg#1); {29176#true} is VALID [2022-02-20 18:00:59,880 INFO L290 TraceCheckUtils]: 85: Hoare triple {29177#false} assume { :end_inline_sign } true;assume { :begin_inline_outgoing__wrappee__AutoResponder } true;outgoing__wrappee__AutoResponder_#in~client#1, outgoing__wrappee__AutoResponder_#in~msg#1 := ~client#1, ~msg#1;havoc outgoing__wrappee__AutoResponder_#t~ret62#1, outgoing__wrappee__AutoResponder_#t~ret63#1, outgoing__wrappee__AutoResponder_~client#1, outgoing__wrappee__AutoResponder_~msg#1, outgoing__wrappee__AutoResponder_~receiver~0#1, outgoing__wrappee__AutoResponder_~tmp~9#1, outgoing__wrappee__AutoResponder_~pubkey~0#1, outgoing__wrappee__AutoResponder_~tmp___0~3#1;outgoing__wrappee__AutoResponder_~client#1 := outgoing__wrappee__AutoResponder_#in~client#1;outgoing__wrappee__AutoResponder_~msg#1 := outgoing__wrappee__AutoResponder_#in~msg#1;havoc outgoing__wrappee__AutoResponder_~receiver~0#1;havoc outgoing__wrappee__AutoResponder_~tmp~9#1;havoc outgoing__wrappee__AutoResponder_~pubkey~0#1;havoc outgoing__wrappee__AutoResponder_~tmp___0~3#1; {29177#false} is VALID [2022-02-20 18:00:59,880 INFO L290 TraceCheckUtils]: 84: Hoare triple {29177#false} assume 0 == sign_~privkey~1#1; {29177#false} is VALID [2022-02-20 18:00:59,881 INFO L290 TraceCheckUtils]: 83: Hoare triple {29177#false} assume -2147483648 <= sign_#t~ret76#1 && sign_#t~ret76#1 <= 2147483647;sign_~tmp~16#1 := sign_#t~ret76#1;havoc sign_#t~ret76#1;sign_~privkey~1#1 := sign_~tmp~16#1; {29177#false} is VALID [2022-02-20 18:00:59,881 INFO L284 TraceCheckUtils]: 82: Hoare quadruple {29176#true} {29177#false} #1054#return; {29177#false} is VALID [2022-02-20 18:00:59,881 INFO L290 TraceCheckUtils]: 81: Hoare triple {29176#true} assume true; {29176#true} is VALID [2022-02-20 18:00:59,881 INFO L290 TraceCheckUtils]: 80: Hoare triple {29176#true} assume 1 == ~handle;~retValue_acc~20 := ~__ste_client_privateKey0~0;#res := ~retValue_acc~20; {29176#true} is VALID [2022-02-20 18:00:59,881 INFO L290 TraceCheckUtils]: 79: Hoare triple {29176#true} ~handle := #in~handle;havoc ~retValue_acc~20; {29176#true} is VALID [2022-02-20 18:00:59,881 INFO L272 TraceCheckUtils]: 78: Hoare triple {29177#false} call sign_#t~ret76#1 := getClientPrivateKey(sign_~client#1); {29176#true} is VALID [2022-02-20 18:00:59,881 INFO L290 TraceCheckUtils]: 77: Hoare triple {29177#false} ~client#1 := #in~client#1;~msg#1 := #in~msg#1;assume { :begin_inline_sign } true;sign_#in~client#1, sign_#in~msg#1 := ~client#1, ~msg#1;havoc sign_#t~ret76#1, sign_~client#1, sign_~msg#1, sign_~privkey~1#1, sign_~tmp~16#1;sign_~client#1 := sign_#in~client#1;sign_~msg#1 := sign_#in~msg#1;havoc sign_~privkey~1#1;havoc sign_~tmp~16#1; {29177#false} is VALID [2022-02-20 18:00:59,881 INFO L272 TraceCheckUtils]: 76: Hoare triple {29177#false} call outgoing(~sender#1, ~email~0#1); {29177#false} is VALID [2022-02-20 18:00:59,881 INFO L290 TraceCheckUtils]: 75: Hoare triple {29177#false} #t~ret72#1 := createEmail_#res#1;assume { :end_inline_createEmail } true;assume -2147483648 <= #t~ret72#1 && #t~ret72#1 <= 2147483647;~tmp~14#1 := #t~ret72#1;havoc #t~ret72#1;~email~0#1 := ~tmp~14#1; {29177#false} is VALID [2022-02-20 18:00:59,881 INFO L290 TraceCheckUtils]: 74: Hoare triple {29177#false} createEmail_~retValue_acc~31#1 := createEmail_~msg~0#1;createEmail_#res#1 := createEmail_~retValue_acc~31#1; {29177#false} is VALID [2022-02-20 18:00:59,882 INFO L284 TraceCheckUtils]: 73: Hoare quadruple {29176#true} {29177#false} #1122#return; {29177#false} is VALID [2022-02-20 18:00:59,882 INFO L290 TraceCheckUtils]: 72: Hoare triple {29176#true} assume true; {29176#true} is VALID [2022-02-20 18:00:59,882 INFO L290 TraceCheckUtils]: 71: Hoare triple {29176#true} assume 1 == ~handle;~__ste_email_to0~0 := ~value; {29176#true} is VALID [2022-02-20 18:00:59,882 INFO L290 TraceCheckUtils]: 70: Hoare triple {29176#true} ~handle := #in~handle;~value := #in~value; {29176#true} is VALID [2022-02-20 18:00:59,882 INFO L272 TraceCheckUtils]: 69: Hoare triple {29177#false} call setEmailTo(createEmail_~msg~0#1, createEmail_~to#1); {29176#true} is VALID [2022-02-20 18:00:59,882 INFO L284 TraceCheckUtils]: 68: Hoare quadruple {29176#true} {29177#false} #1120#return; {29177#false} is VALID [2022-02-20 18:00:59,882 INFO L290 TraceCheckUtils]: 67: Hoare triple {29176#true} assume true; {29176#true} is VALID [2022-02-20 18:00:59,882 INFO L290 TraceCheckUtils]: 66: Hoare triple {29176#true} assume 1 == ~handle;~__ste_email_from0~0 := ~value; {29176#true} is VALID [2022-02-20 18:00:59,882 INFO L290 TraceCheckUtils]: 65: Hoare triple {29176#true} ~handle := #in~handle;~value := #in~value; {29176#true} is VALID [2022-02-20 18:00:59,882 INFO L272 TraceCheckUtils]: 64: Hoare triple {29177#false} call setEmailFrom(createEmail_~msg~0#1, createEmail_~from#1); {29176#true} is VALID [2022-02-20 18:00:59,883 INFO L290 TraceCheckUtils]: 63: Hoare triple {29177#false} ~sender#1 := #in~sender#1;~receiver#1 := #in~receiver#1;havoc ~email~0#1;havoc ~tmp~14#1;assume { :begin_inline_createEmail } true;createEmail_#in~from#1, createEmail_#in~to#1 := 0, ~receiver#1;havoc createEmail_#res#1;havoc createEmail_~from#1, createEmail_~to#1, createEmail_~retValue_acc~31#1, createEmail_~msg~0#1;createEmail_~from#1 := createEmail_#in~from#1;createEmail_~to#1 := createEmail_#in~to#1;havoc createEmail_~retValue_acc~31#1;havoc createEmail_~msg~0#1;createEmail_~msg~0#1 := 1; {29177#false} is VALID [2022-02-20 18:00:59,883 INFO L272 TraceCheckUtils]: 62: Hoare triple {29177#false} call sendEmail(~bob~0, ~rjh~0); {29177#false} is VALID [2022-02-20 18:00:59,883 INFO L290 TraceCheckUtils]: 61: Hoare triple {29177#false} assume { :begin_inline_bobToRjh } true;havoc bobToRjh_#t~ret27#1, bobToRjh_#t~ret28#1, bobToRjh_#t~ret29#1, bobToRjh_#t~ret30#1, bobToRjh_~tmp~3#1, bobToRjh_~tmp___0~0#1, bobToRjh_~tmp___1~0#1;havoc bobToRjh_~tmp~3#1;havoc bobToRjh_~tmp___0~0#1;havoc bobToRjh_~tmp___1~0#1;call bobToRjh_#t~ret27#1 := puts(16, 0);assume -2147483648 <= bobToRjh_#t~ret27#1 && bobToRjh_#t~ret27#1 <= 2147483647;havoc bobToRjh_#t~ret27#1; {29177#false} is VALID [2022-02-20 18:00:59,883 INFO L290 TraceCheckUtils]: 60: Hoare triple {29813#(< |ULTIMATE.start_test_~splverifierCounter~0#1| 4)} assume !(test_~splverifierCounter~0#1 < 4); {29177#false} is VALID [2022-02-20 18:00:59,883 INFO L290 TraceCheckUtils]: 59: Hoare triple {29813#(< |ULTIMATE.start_test_~splverifierCounter~0#1| 4)} assume !false; {29813#(< |ULTIMATE.start_test_~splverifierCounter~0#1| 4)} is VALID [2022-02-20 18:00:59,884 INFO L290 TraceCheckUtils]: 58: Hoare triple {29813#(< |ULTIMATE.start_test_~splverifierCounter~0#1| 4)} assume { :end_inline_rjhSetAutoRespond } true;test_~op2~0#1 := 1; {29813#(< |ULTIMATE.start_test_~splverifierCounter~0#1| 4)} is VALID [2022-02-20 18:00:59,884 INFO L290 TraceCheckUtils]: 57: Hoare triple {29813#(< |ULTIMATE.start_test_~splverifierCounter~0#1| 4)} assume { :end_inline_setClientAutoResponse } true; {29813#(< |ULTIMATE.start_test_~splverifierCounter~0#1| 4)} is VALID [2022-02-20 18:00:59,884 INFO L290 TraceCheckUtils]: 56: Hoare triple {29813#(< |ULTIMATE.start_test_~splverifierCounter~0#1| 4)} assume 1 == setClientAutoResponse_~handle#1;~__ste_client_autoResponse0~0 := setClientAutoResponse_~value#1; {29813#(< |ULTIMATE.start_test_~splverifierCounter~0#1| 4)} is VALID [2022-02-20 18:00:59,884 INFO L290 TraceCheckUtils]: 55: Hoare triple {29813#(< |ULTIMATE.start_test_~splverifierCounter~0#1| 4)} assume 0 != test_~tmp___8~0#1;assume { :begin_inline_rjhSetAutoRespond } true;assume { :begin_inline_setClientAutoResponse } true;setClientAutoResponse_#in~handle#1, setClientAutoResponse_#in~value#1 := ~rjh~0, 1;havoc setClientAutoResponse_~handle#1, setClientAutoResponse_~value#1;setClientAutoResponse_~handle#1 := setClientAutoResponse_#in~handle#1;setClientAutoResponse_~value#1 := setClientAutoResponse_#in~value#1; {29813#(< |ULTIMATE.start_test_~splverifierCounter~0#1| 4)} is VALID [2022-02-20 18:00:59,885 INFO L290 TraceCheckUtils]: 54: Hoare triple {29813#(< |ULTIMATE.start_test_~splverifierCounter~0#1| 4)} assume 0 == test_~op2~0#1;assume -2147483648 <= test_#t~nondet48#1 && test_#t~nondet48#1 <= 2147483647;test_~tmp___8~0#1 := test_#t~nondet48#1;havoc test_#t~nondet48#1; {29813#(< |ULTIMATE.start_test_~splverifierCounter~0#1| 4)} is VALID [2022-02-20 18:00:59,885 INFO L290 TraceCheckUtils]: 53: Hoare triple {29813#(< |ULTIMATE.start_test_~splverifierCounter~0#1| 4)} assume !(0 != test_~tmp___9~0#1); {29813#(< |ULTIMATE.start_test_~splverifierCounter~0#1| 4)} is VALID [2022-02-20 18:00:59,885 INFO L290 TraceCheckUtils]: 52: Hoare triple {29813#(< |ULTIMATE.start_test_~splverifierCounter~0#1| 4)} assume 0 == test_~op1~0#1;assume -2147483648 <= test_#t~nondet47#1 && test_#t~nondet47#1 <= 2147483647;test_~tmp___9~0#1 := test_#t~nondet47#1;havoc test_#t~nondet47#1; {29813#(< |ULTIMATE.start_test_~splverifierCounter~0#1| 4)} is VALID [2022-02-20 18:00:59,886 INFO L290 TraceCheckUtils]: 51: Hoare triple {29841#(< |ULTIMATE.start_test_~splverifierCounter~0#1| 3)} test_~splverifierCounter~0#1 := 1 + test_~splverifierCounter~0#1; {29813#(< |ULTIMATE.start_test_~splverifierCounter~0#1| 4)} is VALID [2022-02-20 18:00:59,886 INFO L290 TraceCheckUtils]: 50: Hoare triple {29841#(< |ULTIMATE.start_test_~splverifierCounter~0#1| 3)} assume test_~splverifierCounter~0#1 < 4; {29841#(< |ULTIMATE.start_test_~splverifierCounter~0#1| 3)} is VALID [2022-02-20 18:00:59,886 INFO L290 TraceCheckUtils]: 49: Hoare triple {29841#(< |ULTIMATE.start_test_~splverifierCounter~0#1| 3)} assume !false; {29841#(< |ULTIMATE.start_test_~splverifierCounter~0#1| 3)} is VALID [2022-02-20 18:00:59,886 INFO L290 TraceCheckUtils]: 48: Hoare triple {29176#true} assume { :end_inline_setup } true;assume { :begin_inline_test } true;havoc test_#t~nondet47#1, test_#t~nondet48#1, test_#t~nondet49#1, test_#t~nondet50#1, test_#t~nondet51#1, test_#t~nondet52#1, test_#t~nondet53#1, test_#t~nondet54#1, test_#t~nondet55#1, test_#t~nondet56#1, test_#t~nondet57#1, test_~op1~0#1, test_~op2~0#1, test_~op3~0#1, test_~op4~0#1, test_~op5~0#1, test_~op6~0#1, test_~op7~0#1, test_~op8~0#1, test_~op9~0#1, test_~op10~0#1, test_~op11~0#1, test_~splverifierCounter~0#1, test_~tmp~6#1, test_~tmp___0~2#1, test_~tmp___1~1#1, test_~tmp___2~0#1, test_~tmp___3~0#1, test_~tmp___4~0#1, test_~tmp___5~0#1, test_~tmp___6~0#1, test_~tmp___7~0#1, test_~tmp___8~0#1, test_~tmp___9~0#1;havoc test_~op1~0#1;havoc test_~op2~0#1;havoc test_~op3~0#1;havoc test_~op4~0#1;havoc test_~op5~0#1;havoc test_~op6~0#1;havoc test_~op7~0#1;havoc test_~op8~0#1;havoc test_~op9~0#1;havoc test_~op10~0#1;havoc test_~op11~0#1;havoc test_~splverifierCounter~0#1;havoc test_~tmp~6#1;havoc test_~tmp___0~2#1;havoc test_~tmp___1~1#1;havoc test_~tmp___2~0#1;havoc test_~tmp___3~0#1;havoc test_~tmp___4~0#1;havoc test_~tmp___5~0#1;havoc test_~tmp___6~0#1;havoc test_~tmp___7~0#1;havoc test_~tmp___8~0#1;havoc test_~tmp___9~0#1;test_~op1~0#1 := 0;test_~op2~0#1 := 0;test_~op3~0#1 := 0;test_~op4~0#1 := 0;test_~op5~0#1 := 0;test_~op6~0#1 := 0;test_~op7~0#1 := 0;test_~op8~0#1 := 0;test_~op9~0#1 := 0;test_~op10~0#1 := 0;test_~op11~0#1 := 0;test_~splverifierCounter~0#1 := 0; {29841#(< |ULTIMATE.start_test_~splverifierCounter~0#1| 3)} is VALID [2022-02-20 18:00:59,887 INFO L290 TraceCheckUtils]: 47: Hoare triple {29176#true} assume { :end_inline_setup_chuck } true;setup_~__cil_tmp3~0#1.base, setup_~__cil_tmp3~0#1.offset := 20, 0;havoc setup_#t~nondet34#1; {29176#true} is VALID [2022-02-20 18:00:59,887 INFO L284 TraceCheckUtils]: 46: Hoare quadruple {29176#true} {29176#true} #1144#return; {29176#true} is VALID [2022-02-20 18:00:59,887 INFO L290 TraceCheckUtils]: 45: Hoare triple {29176#true} assume true; {29176#true} is VALID [2022-02-20 18:00:59,887 INFO L290 TraceCheckUtils]: 44: Hoare triple {29176#true} assume 3 == ~handle;~__ste_client_privateKey2~0 := ~value; {29176#true} is VALID [2022-02-20 18:00:59,887 INFO L290 TraceCheckUtils]: 43: Hoare triple {29176#true} assume !(2 == ~handle); {29176#true} is VALID [2022-02-20 18:00:59,887 INFO L290 TraceCheckUtils]: 42: Hoare triple {29176#true} assume !(1 == ~handle); {29176#true} is VALID [2022-02-20 18:00:59,887 INFO L290 TraceCheckUtils]: 41: Hoare triple {29176#true} ~handle := #in~handle;~value := #in~value; {29176#true} is VALID [2022-02-20 18:00:59,887 INFO L272 TraceCheckUtils]: 40: Hoare triple {29176#true} call setClientPrivateKey(setup_chuck_~chuck___0#1, 789); {29176#true} is VALID [2022-02-20 18:00:59,887 INFO L290 TraceCheckUtils]: 39: Hoare triple {29176#true} assume { :end_inline_setup_chuck__wrappee__Base } true; {29176#true} is VALID [2022-02-20 18:00:59,888 INFO L284 TraceCheckUtils]: 38: Hoare quadruple {29176#true} {29176#true} #1142#return; {29176#true} is VALID [2022-02-20 18:00:59,888 INFO L290 TraceCheckUtils]: 37: Hoare triple {29176#true} assume true; {29176#true} is VALID [2022-02-20 18:00:59,888 INFO L290 TraceCheckUtils]: 36: Hoare triple {29176#true} assume 3 == ~handle;~__ste_client_idCounter2~0 := ~value; {29176#true} is VALID [2022-02-20 18:00:59,888 INFO L290 TraceCheckUtils]: 35: Hoare triple {29176#true} assume !(2 == ~handle); {29176#true} is VALID [2022-02-20 18:00:59,888 INFO L290 TraceCheckUtils]: 34: Hoare triple {29176#true} assume !(1 == ~handle); {29176#true} is VALID [2022-02-20 18:00:59,888 INFO L290 TraceCheckUtils]: 33: Hoare triple {29176#true} ~handle := #in~handle;~value := #in~value; {29176#true} is VALID [2022-02-20 18:00:59,888 INFO L272 TraceCheckUtils]: 32: Hoare triple {29176#true} call setClientId(setup_chuck__wrappee__Base_~chuck___0#1, setup_chuck__wrappee__Base_~chuck___0#1); {29176#true} is VALID [2022-02-20 18:00:59,888 INFO L290 TraceCheckUtils]: 31: Hoare triple {29176#true} assume { :end_inline_setup_rjh } true;setup_~__cil_tmp2~0#1.base, setup_~__cil_tmp2~0#1.offset := 19, 0;havoc setup_#t~nondet33#1;~chuck~0 := 3;assume { :begin_inline_setup_chuck } true;setup_chuck_#in~chuck___0#1 := ~chuck~0;havoc setup_chuck_~chuck___0#1;setup_chuck_~chuck___0#1 := setup_chuck_#in~chuck___0#1;assume { :begin_inline_setup_chuck__wrappee__Base } true;setup_chuck__wrappee__Base_#in~chuck___0#1 := setup_chuck_~chuck___0#1;havoc setup_chuck__wrappee__Base_~chuck___0#1;setup_chuck__wrappee__Base_~chuck___0#1 := setup_chuck__wrappee__Base_#in~chuck___0#1; {29176#true} is VALID [2022-02-20 18:00:59,888 INFO L284 TraceCheckUtils]: 30: Hoare quadruple {29176#true} {29176#true} #1140#return; {29176#true} is VALID [2022-02-20 18:00:59,889 INFO L290 TraceCheckUtils]: 29: Hoare triple {29176#true} assume true; {29176#true} is VALID [2022-02-20 18:00:59,889 INFO L290 TraceCheckUtils]: 28: Hoare triple {29176#true} assume 2 == ~handle;~__ste_client_privateKey1~0 := ~value; {29176#true} is VALID [2022-02-20 18:00:59,889 INFO L290 TraceCheckUtils]: 27: Hoare triple {29176#true} assume !(1 == ~handle); {29176#true} is VALID [2022-02-20 18:00:59,889 INFO L290 TraceCheckUtils]: 26: Hoare triple {29176#true} ~handle := #in~handle;~value := #in~value; {29176#true} is VALID [2022-02-20 18:00:59,889 INFO L272 TraceCheckUtils]: 25: Hoare triple {29176#true} call setClientPrivateKey(setup_rjh_~rjh___0#1, 456); {29176#true} is VALID [2022-02-20 18:00:59,889 INFO L290 TraceCheckUtils]: 24: Hoare triple {29176#true} assume { :end_inline_setup_rjh__wrappee__Base } true; {29176#true} is VALID [2022-02-20 18:00:59,889 INFO L284 TraceCheckUtils]: 23: Hoare quadruple {29176#true} {29176#true} #1138#return; {29176#true} is VALID [2022-02-20 18:00:59,889 INFO L290 TraceCheckUtils]: 22: Hoare triple {29176#true} assume true; {29176#true} is VALID [2022-02-20 18:00:59,889 INFO L290 TraceCheckUtils]: 21: Hoare triple {29176#true} assume 2 == ~handle;~__ste_client_idCounter1~0 := ~value; {29176#true} is VALID [2022-02-20 18:00:59,889 INFO L290 TraceCheckUtils]: 20: Hoare triple {29176#true} assume !(1 == ~handle); {29176#true} is VALID [2022-02-20 18:00:59,890 INFO L290 TraceCheckUtils]: 19: Hoare triple {29176#true} ~handle := #in~handle;~value := #in~value; {29176#true} is VALID [2022-02-20 18:00:59,890 INFO L272 TraceCheckUtils]: 18: Hoare triple {29176#true} call setClientId(setup_rjh__wrappee__Base_~rjh___0#1, setup_rjh__wrappee__Base_~rjh___0#1); {29176#true} is VALID [2022-02-20 18:00:59,890 INFO L290 TraceCheckUtils]: 17: Hoare triple {29176#true} assume { :end_inline_setup_bob } true;setup_~__cil_tmp1~0#1.base, setup_~__cil_tmp1~0#1.offset := 18, 0;havoc setup_#t~nondet32#1;~rjh~0 := 2;assume { :begin_inline_setup_rjh } true;setup_rjh_#in~rjh___0#1 := ~rjh~0;havoc setup_rjh_~rjh___0#1;setup_rjh_~rjh___0#1 := setup_rjh_#in~rjh___0#1;assume { :begin_inline_setup_rjh__wrappee__Base } true;setup_rjh__wrappee__Base_#in~rjh___0#1 := setup_rjh_~rjh___0#1;havoc setup_rjh__wrappee__Base_~rjh___0#1;setup_rjh__wrappee__Base_~rjh___0#1 := setup_rjh__wrappee__Base_#in~rjh___0#1; {29176#true} is VALID [2022-02-20 18:00:59,890 INFO L284 TraceCheckUtils]: 16: Hoare quadruple {29176#true} {29176#true} #1136#return; {29176#true} is VALID [2022-02-20 18:00:59,890 INFO L290 TraceCheckUtils]: 15: Hoare triple {29176#true} assume true; {29176#true} is VALID [2022-02-20 18:00:59,890 INFO L290 TraceCheckUtils]: 14: Hoare triple {29176#true} assume 1 == ~handle;~__ste_client_privateKey0~0 := ~value; {29176#true} is VALID [2022-02-20 18:00:59,890 INFO L290 TraceCheckUtils]: 13: Hoare triple {29176#true} ~handle := #in~handle;~value := #in~value; {29176#true} is VALID [2022-02-20 18:00:59,890 INFO L272 TraceCheckUtils]: 12: Hoare triple {29176#true} call setClientPrivateKey(setup_bob_~bob___0#1, 123); {29176#true} is VALID [2022-02-20 18:00:59,890 INFO L290 TraceCheckUtils]: 11: Hoare triple {29176#true} assume { :end_inline_setup_bob__wrappee__Base } true; {29176#true} is VALID [2022-02-20 18:00:59,890 INFO L284 TraceCheckUtils]: 10: Hoare quadruple {29176#true} {29176#true} #1134#return; {29176#true} is VALID [2022-02-20 18:00:59,891 INFO L290 TraceCheckUtils]: 9: Hoare triple {29176#true} assume true; {29176#true} is VALID [2022-02-20 18:00:59,891 INFO L290 TraceCheckUtils]: 8: Hoare triple {29176#true} assume 1 == ~handle;~__ste_client_idCounter0~0 := ~value; {29176#true} is VALID [2022-02-20 18:00:59,891 INFO L290 TraceCheckUtils]: 7: Hoare triple {29176#true} ~handle := #in~handle;~value := #in~value; {29176#true} is VALID [2022-02-20 18:00:59,891 INFO L272 TraceCheckUtils]: 6: Hoare triple {29176#true} call setClientId(setup_bob__wrappee__Base_~bob___0#1, setup_bob__wrappee__Base_~bob___0#1); {29176#true} is VALID [2022-02-20 18:00:59,891 INFO L290 TraceCheckUtils]: 5: Hoare triple {29176#true} assume 0 != main_~tmp~4#1;assume { :begin_inline_setup } true;havoc setup_#t~nondet32#1, setup_#t~nondet33#1, setup_#t~nondet34#1, setup_~__cil_tmp1~0#1.base, setup_~__cil_tmp1~0#1.offset, setup_~__cil_tmp2~0#1.base, setup_~__cil_tmp2~0#1.offset, setup_~__cil_tmp3~0#1.base, setup_~__cil_tmp3~0#1.offset;havoc setup_~__cil_tmp1~0#1.base, setup_~__cil_tmp1~0#1.offset;havoc setup_~__cil_tmp2~0#1.base, setup_~__cil_tmp2~0#1.offset;havoc setup_~__cil_tmp3~0#1.base, setup_~__cil_tmp3~0#1.offset;~bob~0 := 1;assume { :begin_inline_setup_bob } true;setup_bob_#in~bob___0#1 := ~bob~0;havoc setup_bob_~bob___0#1;setup_bob_~bob___0#1 := setup_bob_#in~bob___0#1;assume { :begin_inline_setup_bob__wrappee__Base } true;setup_bob__wrappee__Base_#in~bob___0#1 := setup_bob_~bob___0#1;havoc setup_bob__wrappee__Base_~bob___0#1;setup_bob__wrappee__Base_~bob___0#1 := setup_bob__wrappee__Base_#in~bob___0#1; {29176#true} is VALID [2022-02-20 18:00:59,891 INFO L290 TraceCheckUtils]: 4: Hoare triple {29176#true} main_#t~ret35#1 := valid_product_#res#1;assume { :end_inline_valid_product } true;assume -2147483648 <= main_#t~ret35#1 && main_#t~ret35#1 <= 2147483647;main_~tmp~4#1 := main_#t~ret35#1;havoc main_#t~ret35#1; {29176#true} is VALID [2022-02-20 18:00:59,891 INFO L290 TraceCheckUtils]: 3: Hoare triple {29176#true} assume { :end_inline_select_features } true;assume { :begin_inline_valid_product } true;havoc valid_product_#res#1;havoc valid_product_~retValue_acc~5#1;havoc valid_product_~retValue_acc~5#1;valid_product_~retValue_acc~5#1 := 1;valid_product_#res#1 := valid_product_~retValue_acc~5#1; {29176#true} is VALID [2022-02-20 18:00:59,891 INFO L290 TraceCheckUtils]: 2: Hoare triple {29176#true} assume { :end_inline_select_helpers } true;assume { :begin_inline_select_features } true; {29176#true} is VALID [2022-02-20 18:00:59,891 INFO L290 TraceCheckUtils]: 1: Hoare triple {29176#true} assume { :end_inline_ULTIMATE.init } true;assume { :begin_inline_main } true;havoc main_#res#1;havoc main_#t~ret35#1, main_~retValue_acc~3#1, main_~tmp~4#1;havoc main_~retValue_acc~3#1;havoc main_~tmp~4#1;assume { :begin_inline_select_helpers } true; {29176#true} is VALID [2022-02-20 18:00:59,891 INFO L290 TraceCheckUtils]: 0: Hoare triple {29176#true} assume { :begin_inline_ULTIMATE.init } true;#NULL.base, #NULL.offset := 0, 0;assume 0 == #valid[0];assume 0 < #StackHeapBarrier;call #Ultimate.allocInit(2, 1);call write~init~int(48, 1, 0, 1);call write~init~int(0, 1, 1, 1);call #Ultimate.allocInit(28, 2);call #Ultimate.allocInit(12, 3);call #Ultimate.allocInit(30, 4);call #Ultimate.allocInit(9, 5);call #Ultimate.allocInit(21, 6);call #Ultimate.allocInit(30, 7);call #Ultimate.allocInit(9, 8);call #Ultimate.allocInit(21, 9);call #Ultimate.allocInit(30, 10);call #Ultimate.allocInit(9, 11);call #Ultimate.allocInit(25, 12);call #Ultimate.allocInit(30, 13);call #Ultimate.allocInit(9, 14);call #Ultimate.allocInit(25, 15);call #Ultimate.allocInit(44, 16);call #Ultimate.allocInit(44, 17);call #Ultimate.allocInit(9, 18);call #Ultimate.allocInit(9, 19);call #Ultimate.allocInit(11, 20);call #Ultimate.allocInit(19, 21);call #Ultimate.allocInit(4, 22);call write~init~int(37, 22, 0, 1);call write~init~int(100, 22, 1, 1);call write~init~int(10, 22, 2, 1);call write~init~int(0, 22, 3, 1);call #Ultimate.allocInit(4, 23);call write~init~int(37, 23, 0, 1);call write~init~int(100, 23, 1, 1);call write~init~int(10, 23, 2, 1);call write~init~int(0, 23, 3, 1);call #Ultimate.allocInit(10, 24);call #Ultimate.allocInit(16, 25);call #Ultimate.allocInit(20, 26);call #Ultimate.allocInit(22, 27);call #Ultimate.allocInit(21, 28);call #Ultimate.allocInit(10, 29);call #Ultimate.allocInit(12, 30);call #Ultimate.allocInit(10, 31);call #Ultimate.allocInit(18, 32);call #Ultimate.allocInit(16, 33);call #Ultimate.allocInit(21, 34);call #Ultimate.allocInit(13, 35);call #Ultimate.allocInit(16, 36);call #Ultimate.allocInit(25, 37);call #Ultimate.allocInit(4, 38);call write~init~int(37, 38, 0, 1);call write~init~int(115, 38, 1, 1);call write~init~int(10, 38, 2, 1);call write~init~int(0, 38, 3, 1);call #Ultimate.allocInit(13, 39);~head~0.base, ~head~0.offset := 0, 0;~__SELECTED_FEATURE_Base~0 := 0;~__SELECTED_FEATURE_Keys~0 := 0;~__SELECTED_FEATURE_Encrypt~0 := 0;~__SELECTED_FEATURE_AutoResponder~0 := 0;~__SELECTED_FEATURE_AddressBook~0 := 0;~__SELECTED_FEATURE_Sign~0 := 0;~__SELECTED_FEATURE_Forward~0 := 0;~__SELECTED_FEATURE_Verify~0 := 0;~__SELECTED_FEATURE_Decrypt~0 := 0;~__GUIDSL_ROOT_PRODUCTION~0 := 0;~__GUIDSL_NON_TERMINAL_main~0 := 0;~bob~0 := 0;~rjh~0 := 0;~chuck~0 := 0;~queue_empty~0 := 1;~queued_message~0 := 0;~queued_client~0 := 0;~__ste_Client_counter~0 := 0;~__ste_client_name0~0.base, ~__ste_client_name0~0.offset := 0, 0;~__ste_client_name1~0.base, ~__ste_client_name1~0.offset := 0, 0;~__ste_client_name2~0.base, ~__ste_client_name2~0.offset := 0, 0;~__ste_client_outbuffer0~0 := 0;~__ste_client_outbuffer1~0 := 0;~__ste_client_outbuffer2~0 := 0;~__ste_client_outbuffer3~0 := 0;~__ste_ClientAddressBook_size0~0 := 0;~__ste_ClientAddressBook_size1~0 := 0;~__ste_ClientAddressBook_size2~0 := 0;~__ste_Client_AddressBook0_Alias0~0 := 0;~__ste_Client_AddressBook0_Alias1~0 := 0;~__ste_Client_AddressBook0_Alias2~0 := 0;~__ste_Client_AddressBook1_Alias0~0 := 0;~__ste_Client_AddressBook1_Alias1~0 := 0;~__ste_Client_AddressBook1_Alias2~0 := 0;~__ste_Client_AddressBook2_Alias0~0 := 0;~__ste_Client_AddressBook2_Alias1~0 := 0;~__ste_Client_AddressBook2_Alias2~0 := 0;~__ste_Client_AddressBook0_Address0~0 := 0;~__ste_Client_AddressBook0_Address1~0 := 0;~__ste_Client_AddressBook0_Address2~0 := 0;~__ste_Client_AddressBook1_Address0~0 := 0;~__ste_Client_AddressBook1_Address1~0 := 0;~__ste_Client_AddressBook1_Address2~0 := 0;~__ste_Client_AddressBook2_Address0~0 := 0;~__ste_Client_AddressBook2_Address1~0 := 0;~__ste_Client_AddressBook2_Address2~0 := 0;~__ste_client_autoResponse0~0 := 0;~__ste_client_autoResponse1~0 := 0;~__ste_client_autoResponse2~0 := 0;~__ste_client_privateKey0~0 := 0;~__ste_client_privateKey1~0 := 0;~__ste_client_privateKey2~0 := 0;~__ste_ClientKeyring_size0~0 := 0;~__ste_ClientKeyring_size1~0 := 0;~__ste_ClientKeyring_size2~0 := 0;~__ste_Client_Keyring0_User0~0 := 0;~__ste_Client_Keyring0_User1~0 := 0;~__ste_Client_Keyring0_User2~0 := 0;~__ste_Client_Keyring1_User0~0 := 0;~__ste_Client_Keyring1_User1~0 := 0;~__ste_Client_Keyring1_User2~0 := 0;~__ste_Client_Keyring2_User0~0 := 0;~__ste_Client_Keyring2_User1~0 := 0;~__ste_Client_Keyring2_User2~0 := 0;~__ste_Client_Keyring0_PublicKey0~0 := 0;~__ste_Client_Keyring0_PublicKey1~0 := 0;~__ste_Client_Keyring0_PublicKey2~0 := 0;~__ste_Client_Keyring1_PublicKey0~0 := 0;~__ste_Client_Keyring1_PublicKey1~0 := 0;~__ste_Client_Keyring1_PublicKey2~0 := 0;~__ste_Client_Keyring2_PublicKey0~0 := 0;~__ste_Client_Keyring2_PublicKey1~0 := 0;~__ste_Client_Keyring2_PublicKey2~0 := 0;~__ste_client_forwardReceiver0~0 := 0;~__ste_client_forwardReceiver1~0 := 0;~__ste_client_forwardReceiver2~0 := 0;~__ste_client_forwardReceiver3~0 := 0;~__ste_client_idCounter0~0 := 0;~__ste_client_idCounter1~0 := 0;~__ste_client_idCounter2~0 := 0;~__ste_Email_counter~0 := 0;~__ste_email_id0~0 := 0;~__ste_email_id1~0 := 0;~__ste_email_from0~0 := 0;~__ste_email_from1~0 := 0;~__ste_email_to0~0 := 0;~__ste_email_to1~0 := 0;~__ste_email_subject0~0.base, ~__ste_email_subject0~0.offset := 0, 0;~__ste_email_subject1~0.base, ~__ste_email_subject1~0.offset := 0, 0;~__ste_email_body0~0.base, ~__ste_email_body0~0.offset := 0, 0;~__ste_email_body1~0.base, ~__ste_email_body1~0.offset := 0, 0;~__ste_email_isEncrypted0~0 := 0;~__ste_email_isEncrypted1~0 := 0;~__ste_email_encryptionKey0~0 := 0;~__ste_email_encryptionKey1~0 := 0;~__ste_email_isSigned0~0 := 0;~__ste_email_isSigned1~0 := 0;~__ste_email_signKey0~0 := 0;~__ste_email_signKey1~0 := 0;~__ste_email_isSignatureVerified0~0 := 0;~__ste_email_isSignatureVerified1~0 := 0; {29176#true} is VALID [2022-02-20 18:00:59,892 INFO L134 CoverageAnalysis]: Checked inductivity of 36 backedges. 0 proven. 2 refuted. 0 times theorem prover too weak. 34 trivial. 0 not checked. [2022-02-20 18:00:59,892 INFO L165 FreeRefinementEngine]: IpTcStrategyModuleZ3 [488039691] provided 0 perfect and 2 imperfect interpolant sequences [2022-02-20 18:00:59,892 INFO L191 FreeRefinementEngine]: Found 0 perfect and 3 imperfect interpolant sequences. [2022-02-20 18:00:59,892 INFO L204 FreeRefinementEngine]: Number of different interpolants: perfect sequences [] imperfect sequences [11, 4, 4] total 15 [2022-02-20 18:00:59,894 INFO L118 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [442796112] [2022-02-20 18:00:59,894 INFO L85 oduleStraightlineAll]: Using 3 imperfect interpolants to construct interpolant automaton [2022-02-20 18:00:59,895 INFO L78 Accepts]: Start accepts. Automaton has has 15 states, 14 states have (on average 9.714285714285714) internal successors, (136), 11 states have internal predecessors, (136), 4 states have call successors, (33), 6 states have call predecessors, (33), 3 states have return successors, (26), 3 states have call predecessors, (26), 4 states have call successors, (26) Word has length 124 [2022-02-20 18:00:59,974 INFO L84 Accepts]: Finished accepts. word is accepted. [2022-02-20 18:00:59,974 INFO L86 InductivityCheck]: Starting indutivity check of a Floyd-Hoare automaton with has 15 states, 14 states have (on average 9.714285714285714) internal successors, (136), 11 states have internal predecessors, (136), 4 states have call successors, (33), 6 states have call predecessors, (33), 3 states have return successors, (26), 3 states have call predecessors, (26), 4 states have call successors, (26) [2022-02-20 18:01:00,094 INFO L122 InductivityCheck]: Floyd-Hoare automaton has 195 edges. 195 inductive. 0 not inductive. 0 times theorem prover too weak to decide inductivity. [2022-02-20 18:01:00,094 INFO L546 AbstractCegarLoop]: INTERPOLANT automaton has 15 states [2022-02-20 18:01:00,095 INFO L108 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2022-02-20 18:01:00,095 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 15 interpolants. [2022-02-20 18:01:00,095 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=33, Invalid=177, Unknown=0, NotChecked=0, Total=210 [2022-02-20 18:01:00,095 INFO L87 Difference]: Start difference. First operand 445 states and 673 transitions. Second operand has 15 states, 14 states have (on average 9.714285714285714) internal successors, (136), 11 states have internal predecessors, (136), 4 states have call successors, (33), 6 states have call predecessors, (33), 3 states have return successors, (26), 3 states have call predecessors, (26), 4 states have call successors, (26)