./Ultimate.py --spec ../../sv-benchmarks/c/properties/unreach-call.prp --file ../../sv-benchmarks/c/product-lines/email_spec4_product28.cil.c --full-output --architecture 32bit -------------------------------------------------------------------------------- Checking for ERROR reachability Using default analysis Version 2329fc70 Calling Ultimate with: /usr/lib/jvm/java-11-openjdk-amd64/bin/java -Dosgi.configuration.area=/tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_1f82ca65-6edb-49dc-97e2-5ef2786422ba/bin/utaipan-gh47qXpMRh/data/config -Xmx15G -Xms4m -jar /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_1f82ca65-6edb-49dc-97e2-5ef2786422ba/bin/utaipan-gh47qXpMRh/plugins/org.eclipse.equinox.launcher_1.5.800.v20200727-1323.jar -data @noDefault -ultimatedata /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_1f82ca65-6edb-49dc-97e2-5ef2786422ba/bin/utaipan-gh47qXpMRh/data -tc /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_1f82ca65-6edb-49dc-97e2-5ef2786422ba/bin/utaipan-gh47qXpMRh/config/TaipanReach.xml -i ../../sv-benchmarks/c/product-lines/email_spec4_product28.cil.c -s /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_1f82ca65-6edb-49dc-97e2-5ef2786422ba/bin/utaipan-gh47qXpMRh/config/svcomp-Reach-32bit-Taipan_Default.epf --cacsl2boogietranslator.entry.function main --witnessprinter.witness.directory /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_1f82ca65-6edb-49dc-97e2-5ef2786422ba/bin/utaipan-gh47qXpMRh --witnessprinter.witness.filename witness.graphml --witnessprinter.write.witness.besides.input.file false --witnessprinter.graph.data.specification CHECK( init(main()), LTL(G ! call(reach_error())) ) --witnessprinter.graph.data.producer Taipan --witnessprinter.graph.data.architecture 32bit --witnessprinter.graph.data.programhash 619b5b07f7bee6d460265c38ff6f46d0f3c88b87f6fc28a24021d9529c74e42f --- Real Ultimate output --- [0.001s][warning][os,container] Duplicate cpuset controllers detected. Picking /sys/fs/cgroup/cpuset, skipping /sys/fs/cgroup/cpuset. This is Ultimate 0.2.2-dev-2329fc7 [2022-12-14 08:51:56,196 INFO L177 SettingsManager]: Resetting all preferences to default values... [2022-12-14 08:51:56,198 INFO L181 SettingsManager]: Resetting UltimateCore preferences to default values [2022-12-14 08:51:56,210 INFO L184 SettingsManager]: Ultimate Commandline Interface provides no preferences, ignoring... [2022-12-14 08:51:56,211 INFO L181 SettingsManager]: Resetting Boogie Preprocessor preferences to default values [2022-12-14 08:51:56,211 INFO L181 SettingsManager]: Resetting Boogie Procedure Inliner preferences to default values [2022-12-14 08:51:56,212 INFO L181 SettingsManager]: Resetting Abstract Interpretation preferences to default values [2022-12-14 08:51:56,213 INFO L181 SettingsManager]: Resetting LassoRanker preferences to default values [2022-12-14 08:51:56,214 INFO L181 SettingsManager]: Resetting Reaching Definitions preferences to default values [2022-12-14 08:51:56,215 INFO L181 SettingsManager]: Resetting SyntaxChecker preferences to default values [2022-12-14 08:51:56,216 INFO L181 SettingsManager]: Resetting Sifa preferences to default values [2022-12-14 08:51:56,217 INFO L184 SettingsManager]: Büchi Program Product provides no preferences, ignoring... [2022-12-14 08:51:56,217 INFO L181 SettingsManager]: Resetting LTL2Aut preferences to default values [2022-12-14 08:51:56,217 INFO L181 SettingsManager]: Resetting PEA to Boogie preferences to default values [2022-12-14 08:51:56,218 INFO L181 SettingsManager]: Resetting BlockEncodingV2 preferences to default values [2022-12-14 08:51:56,219 INFO L181 SettingsManager]: Resetting ChcToBoogie preferences to default values [2022-12-14 08:51:56,220 INFO L181 SettingsManager]: Resetting AutomataScriptInterpreter preferences to default values [2022-12-14 08:51:56,220 INFO L181 SettingsManager]: Resetting BuchiAutomizer preferences to default values [2022-12-14 08:51:56,221 INFO L181 SettingsManager]: Resetting CACSL2BoogieTranslator preferences to default values [2022-12-14 08:51:56,223 INFO L181 SettingsManager]: Resetting CodeCheck preferences to default values [2022-12-14 08:51:56,224 INFO L181 SettingsManager]: Resetting InvariantSynthesis preferences to default values [2022-12-14 08:51:56,225 INFO L181 SettingsManager]: Resetting RCFGBuilder preferences to default values [2022-12-14 08:51:56,225 INFO L181 SettingsManager]: Resetting Referee preferences to default values [2022-12-14 08:51:56,226 INFO L181 SettingsManager]: Resetting TraceAbstraction preferences to default values [2022-12-14 08:51:56,228 INFO L184 SettingsManager]: TraceAbstractionConcurrent provides no preferences, ignoring... [2022-12-14 08:51:56,229 INFO L184 SettingsManager]: TraceAbstractionWithAFAs provides no preferences, ignoring... [2022-12-14 08:51:56,229 INFO L181 SettingsManager]: Resetting TreeAutomizer preferences to default values [2022-12-14 08:51:56,229 INFO L181 SettingsManager]: Resetting IcfgToChc preferences to default values [2022-12-14 08:51:56,230 INFO L181 SettingsManager]: Resetting IcfgTransformer preferences to default values [2022-12-14 08:51:56,230 INFO L184 SettingsManager]: ReqToTest provides no preferences, ignoring... [2022-12-14 08:51:56,231 INFO L181 SettingsManager]: Resetting Boogie Printer preferences to default values [2022-12-14 08:51:56,231 INFO L181 SettingsManager]: Resetting ChcSmtPrinter preferences to default values [2022-12-14 08:51:56,232 INFO L181 SettingsManager]: Resetting ReqPrinter preferences to default values [2022-12-14 08:51:56,232 INFO L181 SettingsManager]: Resetting Witness Printer preferences to default values [2022-12-14 08:51:56,233 INFO L184 SettingsManager]: Boogie PL CUP Parser provides no preferences, ignoring... [2022-12-14 08:51:56,233 INFO L181 SettingsManager]: Resetting CDTParser preferences to default values [2022-12-14 08:51:56,233 INFO L184 SettingsManager]: AutomataScriptParser provides no preferences, ignoring... [2022-12-14 08:51:56,234 INFO L184 SettingsManager]: ReqParser provides no preferences, ignoring... [2022-12-14 08:51:56,234 INFO L181 SettingsManager]: Resetting SmtParser preferences to default values [2022-12-14 08:51:56,234 INFO L181 SettingsManager]: Resetting Witness Parser preferences to default values [2022-12-14 08:51:56,235 INFO L188 SettingsManager]: Finished resetting all preferences to default values... [2022-12-14 08:51:56,236 INFO L101 SettingsManager]: Beginning loading settings from /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_1f82ca65-6edb-49dc-97e2-5ef2786422ba/bin/utaipan-gh47qXpMRh/config/svcomp-Reach-32bit-Taipan_Default.epf [2022-12-14 08:51:56,249 INFO L113 SettingsManager]: Loading preferences was successful [2022-12-14 08:51:56,250 INFO L115 SettingsManager]: Preferences different from defaults after loading the file: [2022-12-14 08:51:56,250 INFO L136 SettingsManager]: Preferences of UltimateCore differ from their defaults: [2022-12-14 08:51:56,250 INFO L138 SettingsManager]: * Log level for class=de.uni_freiburg.informatik.ultimate.lib.smtlibutils.quantifier.QuantifierPusher=ERROR; [2022-12-14 08:51:56,250 INFO L136 SettingsManager]: Preferences of Boogie Procedure Inliner differ from their defaults: [2022-12-14 08:51:56,251 INFO L138 SettingsManager]: * Ignore calls to procedures called more than once=ONLY_FOR_SEQUENTIAL_PROGRAMS [2022-12-14 08:51:56,251 INFO L138 SettingsManager]: * User list type=DISABLED [2022-12-14 08:51:56,251 INFO L136 SettingsManager]: Preferences of Abstract Interpretation differ from their defaults: [2022-12-14 08:51:56,251 INFO L138 SettingsManager]: * Explicit value domain=true [2022-12-14 08:51:56,251 INFO L138 SettingsManager]: * Abstract domain for RCFG-of-the-future=PoormanAbstractDomain [2022-12-14 08:51:56,251 INFO L138 SettingsManager]: * Octagon Domain=false [2022-12-14 08:51:56,251 INFO L138 SettingsManager]: * Abstract domain=CompoundDomain [2022-12-14 08:51:56,251 INFO L138 SettingsManager]: * Check feasibility of abstract posts with an SMT solver=true [2022-12-14 08:51:56,252 INFO L138 SettingsManager]: * Use the RCFG-of-the-future interface=true [2022-12-14 08:51:56,252 INFO L138 SettingsManager]: * Interval Domain=false [2022-12-14 08:51:56,252 INFO L136 SettingsManager]: Preferences of Sifa differ from their defaults: [2022-12-14 08:51:56,252 INFO L138 SettingsManager]: * Call Summarizer=TopInputCallSummarizer [2022-12-14 08:51:56,252 INFO L138 SettingsManager]: * Simplification Technique=POLY_PAC [2022-12-14 08:51:56,253 INFO L136 SettingsManager]: Preferences of CACSL2BoogieTranslator differ from their defaults: [2022-12-14 08:51:56,253 INFO L138 SettingsManager]: * sizeof long=4 [2022-12-14 08:51:56,253 INFO L138 SettingsManager]: * Overapproximate operations on floating types=true [2022-12-14 08:51:56,253 INFO L138 SettingsManager]: * sizeof POINTER=4 [2022-12-14 08:51:56,253 INFO L138 SettingsManager]: * Check division by zero=IGNORE [2022-12-14 08:51:56,253 INFO L138 SettingsManager]: * Pointer to allocated memory at dereference=IGNORE [2022-12-14 08:51:56,253 INFO L138 SettingsManager]: * If two pointers are subtracted or compared they have the same base address=IGNORE [2022-12-14 08:51:56,253 INFO L138 SettingsManager]: * Check array bounds for arrays that are off heap=IGNORE [2022-12-14 08:51:56,253 INFO L138 SettingsManager]: * sizeof long double=12 [2022-12-14 08:51:56,254 INFO L138 SettingsManager]: * Check if freed pointer was valid=false [2022-12-14 08:51:56,254 INFO L138 SettingsManager]: * Use constant arrays=true [2022-12-14 08:51:56,254 INFO L138 SettingsManager]: * Pointer base address is valid at dereference=IGNORE [2022-12-14 08:51:56,254 INFO L136 SettingsManager]: Preferences of RCFGBuilder differ from their defaults: [2022-12-14 08:51:56,254 INFO L138 SettingsManager]: * SMT solver=External_DefaultMode [2022-12-14 08:51:56,254 INFO L138 SettingsManager]: * Command for external solver=z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in -t:2000 [2022-12-14 08:51:56,254 INFO L136 SettingsManager]: Preferences of TraceAbstraction differ from their defaults: [2022-12-14 08:51:56,254 INFO L138 SettingsManager]: * Abstract interpretation Mode=USE_PREDICATES [2022-12-14 08:51:56,255 INFO L138 SettingsManager]: * Compute Interpolants along a Counterexample=FPandBP [2022-12-14 08:51:56,255 INFO L138 SettingsManager]: * Positions where we compute the Hoare Annotation=LoopsAndPotentialCycles [2022-12-14 08:51:56,255 INFO L138 SettingsManager]: * Trace refinement strategy=SIFA_TAIPAN [2022-12-14 08:51:56,255 INFO L138 SettingsManager]: * Command for external solver=z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in [2022-12-14 08:51:56,255 INFO L138 SettingsManager]: * Compute Hoare Annotation of negated interpolant automaton, abstraction and CFG=true [2022-12-14 08:51:56,255 INFO L138 SettingsManager]: * Trace refinement exception blacklist=NONE [2022-12-14 08:51:56,255 INFO L138 SettingsManager]: * SMT solver=External_ModelsAndUnsatCoreMode WARNING: An illegal reflective access operation has occurred WARNING: Illegal reflective access by com.sun.xml.bind.v2.runtime.reflect.opt.Injector$1 (file:/tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_1f82ca65-6edb-49dc-97e2-5ef2786422ba/bin/utaipan-gh47qXpMRh/plugins/com.sun.xml.bind_2.2.0.v201505121915.jar) to method java.lang.ClassLoader.defineClass(java.lang.String,byte[],int,int) WARNING: Please consider reporting this to the maintainers of com.sun.xml.bind.v2.runtime.reflect.opt.Injector$1 WARNING: Use --illegal-access=warn to enable warnings of further illegal reflective access operations WARNING: All illegal access operations will be denied in a future release Applying setting for plugin de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator: Entry function -> main Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Witness directory -> /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_1f82ca65-6edb-49dc-97e2-5ef2786422ba/bin/utaipan-gh47qXpMRh Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Witness filename -> witness.graphml Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Write witness besides input file -> false Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Graph data specification -> CHECK( init(main()), LTL(G ! call(reach_error())) ) Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Graph data producer -> Taipan Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Graph data architecture -> 32bit Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Graph data programhash -> 619b5b07f7bee6d460265c38ff6f46d0f3c88b87f6fc28a24021d9529c74e42f [2022-12-14 08:51:56,411 INFO L75 nceAwareModelManager]: Repository-Root is: /tmp [2022-12-14 08:51:56,428 INFO L261 ainManager$Toolchain]: [Toolchain 1]: Applicable parser(s) successfully (re)initialized [2022-12-14 08:51:56,430 INFO L217 ainManager$Toolchain]: [Toolchain 1]: Toolchain selected. [2022-12-14 08:51:56,431 INFO L271 PluginConnector]: Initializing CDTParser... [2022-12-14 08:51:56,431 INFO L275 PluginConnector]: CDTParser initialized [2022-12-14 08:51:56,432 INFO L432 ainManager$Toolchain]: [Toolchain 1]: Parsing single file: /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_1f82ca65-6edb-49dc-97e2-5ef2786422ba/bin/utaipan-gh47qXpMRh/../../sv-benchmarks/c/product-lines/email_spec4_product28.cil.c [2022-12-14 08:51:58,990 INFO L500 CDTParser]: Created temporary CDT project at NULL [2022-12-14 08:51:59,251 INFO L351 CDTParser]: Found 1 translation units. [2022-12-14 08:51:59,251 INFO L172 CDTParser]: Scanning /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_1f82ca65-6edb-49dc-97e2-5ef2786422ba/sv-benchmarks/c/product-lines/email_spec4_product28.cil.c [2022-12-14 08:51:59,275 INFO L394 CDTParser]: About to delete temporary CDT project at /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_1f82ca65-6edb-49dc-97e2-5ef2786422ba/bin/utaipan-gh47qXpMRh/data/3b1dfd80c/72244685885a4603b031d37c7fb0c550/FLAG599f69456 [2022-12-14 08:51:59,570 INFO L402 CDTParser]: Successfully deleted /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_1f82ca65-6edb-49dc-97e2-5ef2786422ba/bin/utaipan-gh47qXpMRh/data/3b1dfd80c/72244685885a4603b031d37c7fb0c550 [2022-12-14 08:51:59,573 INFO L299 ainManager$Toolchain]: ####################### [Toolchain 1] ####################### [2022-12-14 08:51:59,574 INFO L131 ToolchainWalker]: Walking toolchain with 6 elements. [2022-12-14 08:51:59,575 INFO L113 PluginConnector]: ------------------------CACSL2BoogieTranslator---------------------------- [2022-12-14 08:51:59,575 INFO L271 PluginConnector]: Initializing CACSL2BoogieTranslator... [2022-12-14 08:51:59,577 INFO L275 PluginConnector]: CACSL2BoogieTranslator initialized [2022-12-14 08:51:59,578 INFO L185 PluginConnector]: Executing the observer ACSLObjectContainerObserver from plugin CACSL2BoogieTranslator for "CDTParser AST 14.12 08:51:59" (1/1) ... [2022-12-14 08:51:59,579 INFO L205 PluginConnector]: Invalid model from CACSL2BoogieTranslator for observer de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator.ACSLObjectContainerObserver@6c8d5c0 and model type de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 14.12 08:51:59, skipping insertion in model container [2022-12-14 08:51:59,579 INFO L185 PluginConnector]: Executing the observer CACSL2BoogieTranslatorObserver from plugin CACSL2BoogieTranslator for "CDTParser AST 14.12 08:51:59" (1/1) ... [2022-12-14 08:51:59,584 INFO L145 MainTranslator]: Starting translation in SV-COMP mode [2022-12-14 08:51:59,628 INFO L178 MainTranslator]: Built tables and reachable declarations [2022-12-14 08:51:59,782 WARN L623 FunctionHandler]: Unknown extern function puts [2022-12-14 08:51:59,788 WARN L623 FunctionHandler]: Unknown extern function puts [2022-12-14 08:51:59,801 WARN L237 ndardFunctionHandler]: Function reach_error is already implemented but we override the implementation for the call at /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_1f82ca65-6edb-49dc-97e2-5ef2786422ba/sv-benchmarks/c/product-lines/email_spec4_product28.cil.c[8467,8480] [2022-12-14 08:51:59,918 WARN L623 FunctionHandler]: Unknown extern function puts [2022-12-14 08:51:59,919 WARN L623 FunctionHandler]: Unknown extern function puts [2022-12-14 08:51:59,920 WARN L623 FunctionHandler]: Unknown extern function puts [2022-12-14 08:51:59,923 WARN L623 FunctionHandler]: Unknown extern function puts [2022-12-14 08:51:59,949 INFO L210 PostProcessor]: Analyzing one entry point: main [2022-12-14 08:51:59,961 INFO L203 MainTranslator]: Completed pre-run [2022-12-14 08:51:59,974 WARN L623 FunctionHandler]: Unknown extern function puts [2022-12-14 08:51:59,976 WARN L623 FunctionHandler]: Unknown extern function puts [2022-12-14 08:51:59,983 WARN L237 ndardFunctionHandler]: Function reach_error is already implemented but we override the implementation for the call at /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_1f82ca65-6edb-49dc-97e2-5ef2786422ba/sv-benchmarks/c/product-lines/email_spec4_product28.cil.c[8467,8480] [2022-12-14 08:52:00,028 WARN L623 FunctionHandler]: Unknown extern function puts [2022-12-14 08:52:00,030 WARN L623 FunctionHandler]: Unknown extern function puts [2022-12-14 08:52:00,032 WARN L623 FunctionHandler]: Unknown extern function puts [2022-12-14 08:52:00,035 WARN L623 FunctionHandler]: Unknown extern function puts [2022-12-14 08:52:00,048 INFO L210 PostProcessor]: Analyzing one entry point: main [2022-12-14 08:52:00,071 INFO L208 MainTranslator]: Completed translation [2022-12-14 08:52:00,072 INFO L202 PluginConnector]: Adding new model de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 14.12 08:52:00 WrapperNode [2022-12-14 08:52:00,072 INFO L132 PluginConnector]: ------------------------ END CACSL2BoogieTranslator---------------------------- [2022-12-14 08:52:00,073 INFO L113 PluginConnector]: ------------------------Boogie Procedure Inliner---------------------------- [2022-12-14 08:52:00,073 INFO L271 PluginConnector]: Initializing Boogie Procedure Inliner... [2022-12-14 08:52:00,073 INFO L275 PluginConnector]: Boogie Procedure Inliner initialized [2022-12-14 08:52:00,079 INFO L185 PluginConnector]: Executing the observer TypeChecker from plugin Boogie Procedure Inliner for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 14.12 08:52:00" (1/1) ... [2022-12-14 08:52:00,100 INFO L185 PluginConnector]: Executing the observer Inliner from plugin Boogie Procedure Inliner for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 14.12 08:52:00" (1/1) ... [2022-12-14 08:52:00,146 INFO L138 Inliner]: procedures = 128, calls = 208, calls flagged for inlining = 55, calls inlined = 45, statements flattened = 854 [2022-12-14 08:52:00,146 INFO L132 PluginConnector]: ------------------------ END Boogie Procedure Inliner---------------------------- [2022-12-14 08:52:00,147 INFO L113 PluginConnector]: ------------------------Boogie Preprocessor---------------------------- [2022-12-14 08:52:00,147 INFO L271 PluginConnector]: Initializing Boogie Preprocessor... [2022-12-14 08:52:00,147 INFO L275 PluginConnector]: Boogie Preprocessor initialized [2022-12-14 08:52:00,154 INFO L185 PluginConnector]: Executing the observer EnsureBoogieModelObserver from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 14.12 08:52:00" (1/1) ... [2022-12-14 08:52:00,154 INFO L185 PluginConnector]: Executing the observer TypeChecker from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 14.12 08:52:00" (1/1) ... [2022-12-14 08:52:00,157 INFO L185 PluginConnector]: Executing the observer ConstExpander from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 14.12 08:52:00" (1/1) ... [2022-12-14 08:52:00,157 INFO L185 PluginConnector]: Executing the observer StructExpander from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 14.12 08:52:00" (1/1) ... [2022-12-14 08:52:00,166 INFO L185 PluginConnector]: Executing the observer UnstructureCode from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 14.12 08:52:00" (1/1) ... [2022-12-14 08:52:00,171 INFO L185 PluginConnector]: Executing the observer FunctionInliner from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 14.12 08:52:00" (1/1) ... [2022-12-14 08:52:00,174 INFO L185 PluginConnector]: Executing the observer LTLStepAnnotator from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 14.12 08:52:00" (1/1) ... [2022-12-14 08:52:00,176 INFO L185 PluginConnector]: Executing the observer BoogieSymbolTableConstructor from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 14.12 08:52:00" (1/1) ... [2022-12-14 08:52:00,180 INFO L132 PluginConnector]: ------------------------ END Boogie Preprocessor---------------------------- [2022-12-14 08:52:00,180 INFO L113 PluginConnector]: ------------------------RCFGBuilder---------------------------- [2022-12-14 08:52:00,180 INFO L271 PluginConnector]: Initializing RCFGBuilder... [2022-12-14 08:52:00,180 INFO L275 PluginConnector]: RCFGBuilder initialized [2022-12-14 08:52:00,181 INFO L185 PluginConnector]: Executing the observer RCFGBuilderObserver from plugin RCFGBuilder for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 14.12 08:52:00" (1/1) ... [2022-12-14 08:52:00,186 INFO L173 SolverBuilder]: Constructing external solver with command: z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in -t:2000 [2022-12-14 08:52:00,195 INFO L189 MonitoredProcess]: No working directory specified, using /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_1f82ca65-6edb-49dc-97e2-5ef2786422ba/bin/utaipan-gh47qXpMRh/z3 [2022-12-14 08:52:00,205 INFO L229 MonitoredProcess]: Starting monitored process 1 with /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_1f82ca65-6edb-49dc-97e2-5ef2786422ba/bin/utaipan-gh47qXpMRh/z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in -t:2000 (exit command is (exit), workingDir is null) [2022-12-14 08:52:00,207 INFO L327 MonitoredProcess]: [MP /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_1f82ca65-6edb-49dc-97e2-5ef2786422ba/bin/utaipan-gh47qXpMRh/z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in -t:2000 (1)] Waiting until timeout for monitored process [2022-12-14 08:52:00,241 INFO L130 BoogieDeclarations]: Found specification of procedure getClientPrivateKey [2022-12-14 08:52:00,241 INFO L138 BoogieDeclarations]: Found implementation of procedure getClientPrivateKey [2022-12-14 08:52:00,241 INFO L130 BoogieDeclarations]: Found specification of procedure setEmailEncryptionKey [2022-12-14 08:52:00,241 INFO L138 BoogieDeclarations]: Found implementation of procedure setEmailEncryptionKey [2022-12-14 08:52:00,242 INFO L130 BoogieDeclarations]: Found specification of procedure getEmailEncryptionKey [2022-12-14 08:52:00,242 INFO L138 BoogieDeclarations]: Found implementation of procedure getEmailEncryptionKey [2022-12-14 08:52:00,242 INFO L130 BoogieDeclarations]: Found specification of procedure getEmailTo [2022-12-14 08:52:00,242 INFO L138 BoogieDeclarations]: Found implementation of procedure getEmailTo [2022-12-14 08:52:00,242 INFO L130 BoogieDeclarations]: Found specification of procedure setEmailFrom [2022-12-14 08:52:00,242 INFO L138 BoogieDeclarations]: Found implementation of procedure setEmailFrom [2022-12-14 08:52:00,242 INFO L130 BoogieDeclarations]: Found specification of procedure isReadable [2022-12-14 08:52:00,243 INFO L138 BoogieDeclarations]: Found implementation of procedure isReadable [2022-12-14 08:52:00,243 INFO L130 BoogieDeclarations]: Found specification of procedure createClientKeyringEntry [2022-12-14 08:52:00,243 INFO L138 BoogieDeclarations]: Found implementation of procedure createClientKeyringEntry [2022-12-14 08:52:00,243 INFO L130 BoogieDeclarations]: Found specification of procedure setEmailIsEncrypted [2022-12-14 08:52:00,243 INFO L138 BoogieDeclarations]: Found implementation of procedure setEmailIsEncrypted [2022-12-14 08:52:00,243 INFO L130 BoogieDeclarations]: Found specification of procedure getEmailSignKey [2022-12-14 08:52:00,243 INFO L138 BoogieDeclarations]: Found implementation of procedure getEmailSignKey [2022-12-14 08:52:00,244 INFO L130 BoogieDeclarations]: Found specification of procedure chuckKeyAdd [2022-12-14 08:52:00,244 INFO L138 BoogieDeclarations]: Found implementation of procedure chuckKeyAdd [2022-12-14 08:52:00,244 INFO L130 BoogieDeclarations]: Found specification of procedure puts [2022-12-14 08:52:00,244 INFO L130 BoogieDeclarations]: Found specification of procedure getEmailFrom [2022-12-14 08:52:00,244 INFO L138 BoogieDeclarations]: Found implementation of procedure getEmailFrom [2022-12-14 08:52:00,244 INFO L130 BoogieDeclarations]: Found specification of procedure setClientId [2022-12-14 08:52:00,244 INFO L138 BoogieDeclarations]: Found implementation of procedure setClientId [2022-12-14 08:52:00,245 INFO L130 BoogieDeclarations]: Found specification of procedure #Ultimate.allocInit [2022-12-14 08:52:00,245 INFO L130 BoogieDeclarations]: Found specification of procedure isSigned [2022-12-14 08:52:00,245 INFO L138 BoogieDeclarations]: Found implementation of procedure isSigned [2022-12-14 08:52:00,245 INFO L130 BoogieDeclarations]: Found specification of procedure isKeyPairValid [2022-12-14 08:52:00,245 INFO L138 BoogieDeclarations]: Found implementation of procedure isKeyPairValid [2022-12-14 08:52:00,245 INFO L130 BoogieDeclarations]: Found specification of procedure setClientKeyringUser [2022-12-14 08:52:00,245 INFO L138 BoogieDeclarations]: Found implementation of procedure setClientKeyringUser [2022-12-14 08:52:00,245 INFO L130 BoogieDeclarations]: Found specification of procedure setClientKeyringPublicKey [2022-12-14 08:52:00,246 INFO L138 BoogieDeclarations]: Found implementation of procedure setClientKeyringPublicKey [2022-12-14 08:52:00,246 INFO L130 BoogieDeclarations]: Found specification of procedure outgoing [2022-12-14 08:52:00,246 INFO L138 BoogieDeclarations]: Found implementation of procedure outgoing [2022-12-14 08:52:00,246 INFO L130 BoogieDeclarations]: Found specification of procedure findPublicKey [2022-12-14 08:52:00,246 INFO L138 BoogieDeclarations]: Found implementation of procedure findPublicKey [2022-12-14 08:52:00,246 INFO L130 BoogieDeclarations]: Found specification of procedure sendEmail [2022-12-14 08:52:00,246 INFO L138 BoogieDeclarations]: Found implementation of procedure sendEmail [2022-12-14 08:52:00,247 INFO L130 BoogieDeclarations]: Found specification of procedure isEncrypted [2022-12-14 08:52:00,247 INFO L138 BoogieDeclarations]: Found implementation of procedure isEncrypted [2022-12-14 08:52:00,247 INFO L130 BoogieDeclarations]: Found specification of procedure setClientPrivateKey [2022-12-14 08:52:00,247 INFO L138 BoogieDeclarations]: Found implementation of procedure setClientPrivateKey [2022-12-14 08:52:00,247 INFO L130 BoogieDeclarations]: Found specification of procedure write~init~int [2022-12-14 08:52:00,247 INFO L130 BoogieDeclarations]: Found specification of procedure generateKeyPair [2022-12-14 08:52:00,247 INFO L138 BoogieDeclarations]: Found implementation of procedure generateKeyPair [2022-12-14 08:52:00,248 INFO L130 BoogieDeclarations]: Found specification of procedure ULTIMATE.start [2022-12-14 08:52:00,248 INFO L138 BoogieDeclarations]: Found implementation of procedure ULTIMATE.start [2022-12-14 08:52:00,396 INFO L235 CfgBuilder]: Building ICFG [2022-12-14 08:52:00,398 INFO L261 CfgBuilder]: Building CFG for each procedure with an implementation [2022-12-14 08:52:00,909 INFO L276 CfgBuilder]: Performing block encoding [2022-12-14 08:52:01,149 INFO L295 CfgBuilder]: Using the 1 location(s) as analysis (start of procedure ULTIMATE.start) [2022-12-14 08:52:01,149 INFO L300 CfgBuilder]: Removed 1 assume(true) statements. [2022-12-14 08:52:01,152 INFO L202 PluginConnector]: Adding new model de.uni_freiburg.informatik.ultimate.plugins.generator.rcfgbuilder CFG 14.12 08:52:01 BoogieIcfgContainer [2022-12-14 08:52:01,152 INFO L132 PluginConnector]: ------------------------ END RCFGBuilder---------------------------- [2022-12-14 08:52:01,155 INFO L113 PluginConnector]: ------------------------TraceAbstraction---------------------------- [2022-12-14 08:52:01,155 INFO L271 PluginConnector]: Initializing TraceAbstraction... [2022-12-14 08:52:01,158 INFO L275 PluginConnector]: TraceAbstraction initialized [2022-12-14 08:52:01,158 INFO L185 PluginConnector]: Executing the observer TraceAbstractionObserver from plugin TraceAbstraction for "CDTParser AST 14.12 08:51:59" (1/3) ... [2022-12-14 08:52:01,159 INFO L205 PluginConnector]: Invalid model from TraceAbstraction for observer de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction.TraceAbstractionObserver@7ec3bc51 and model type de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction AST 14.12 08:52:01, skipping insertion in model container [2022-12-14 08:52:01,159 INFO L185 PluginConnector]: Executing the observer TraceAbstractionObserver from plugin TraceAbstraction for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 14.12 08:52:00" (2/3) ... [2022-12-14 08:52:01,159 INFO L205 PluginConnector]: Invalid model from TraceAbstraction for observer de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction.TraceAbstractionObserver@7ec3bc51 and model type de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction AST 14.12 08:52:01, skipping insertion in model container [2022-12-14 08:52:01,159 INFO L185 PluginConnector]: Executing the observer TraceAbstractionObserver from plugin TraceAbstraction for "de.uni_freiburg.informatik.ultimate.plugins.generator.rcfgbuilder CFG 14.12 08:52:01" (3/3) ... [2022-12-14 08:52:01,161 INFO L112 eAbstractionObserver]: Analyzing ICFG email_spec4_product28.cil.c [2022-12-14 08:52:01,180 INFO L203 ceAbstractionStarter]: Automizer settings: Hoare:true NWA Interpolation:FPandBP Determinization: PREDICATE_ABSTRACTION [2022-12-14 08:52:01,180 INFO L162 ceAbstractionStarter]: Applying trace abstraction to program that has 1 error locations. [2022-12-14 08:52:01,232 INFO L356 AbstractCegarLoop]: ======== Iteration 0 == of CEGAR loop == AllErrorsAtOnce ======== [2022-12-14 08:52:01,239 INFO L357 AbstractCegarLoop]: Settings: SEPARATE_VIOLATION_CHECK=true, mInterprocedural=true, mMaxIterations=1000000, mWatchIteration=1000000, mArtifact=RCFG, mInterpolation=FPandBP, mInterpolantAutomaton=STRAIGHT_LINE, mDumpAutomata=false, mAutomataFormat=ATS_NUMERATE, mDumpPath=., mDeterminiation=PREDICATE_ABSTRACTION, mMinimize=MINIMIZE_SEVPA, mHoare=true, mAutomataTypeConcurrency=FINITE_AUTOMATA, mHoareTripleChecks=INCREMENTAL, mHoareAnnotationPositions=LoopsAndPotentialCycles, mDumpOnlyReuseAutomata=false, mLimitTraceHistogram=0, mErrorLocTimeLimit=0, mLimitPathProgramCount=0, mCollectInterpolantStatistics=true, mHeuristicEmptinessCheck=false, mHeuristicEmptinessCheckAStarHeuristic=ZERO, mHeuristicEmptinessCheckAStarHeuristicRandomSeed=1337, mHeuristicEmptinessCheckSmtFeatureScoringMethod=DAGSIZE, mSMTFeatureExtraction=false, mSMTFeatureExtractionDumpPath=., mOverrideInterpolantAutomaton=false, mMcrInterpolantMethod=WP, mPorIndependenceSettings=[Lde.uni_freiburg.informatik.ultimate.lib.tracecheckerutils.partialorder.independence.IndependenceSettings;@3ac9ac3, mLbeIndependenceSettings=[IndependenceType=SEMANTIC, AbstractionType=NONE, UseConditional=false, UseSemiCommutativity=true, Solver=Z3, SolverTimeout=1000ms] [2022-12-14 08:52:01,239 INFO L358 AbstractCegarLoop]: Starting to check reachability of 1 error locations. [2022-12-14 08:52:01,245 INFO L276 IsEmpty]: Start isEmpty. Operand has 180 states, 106 states have (on average 1.3396226415094339) internal successors, (142), 110 states have internal predecessors, (142), 50 states have call successors, (50), 22 states have call predecessors, (50), 22 states have return successors, (50), 50 states have call predecessors, (50), 50 states have call successors, (50) [2022-12-14 08:52:01,256 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 66 [2022-12-14 08:52:01,256 INFO L187 NwaCegarLoop]: Found error trace [2022-12-14 08:52:01,257 INFO L195 NwaCegarLoop]: trace histogram [3, 3, 2, 2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-12-14 08:52:01,257 INFO L420 AbstractCegarLoop]: === Iteration 1 === Targeting outgoingErr0ASSERT_VIOLATIONERROR_FUNCTION === [outgoingErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2022-12-14 08:52:01,262 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2022-12-14 08:52:01,262 INFO L85 PathProgramCache]: Analyzing trace with hash 528091057, now seen corresponding path program 1 times [2022-12-14 08:52:01,272 INFO L118 FreeRefinementEngine]: Executing refinement strategy SIFA_TAIPAN [2022-12-14 08:52:01,272 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [1106925398] [2022-12-14 08:52:01,272 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-12-14 08:52:01,273 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2022-12-14 08:52:01,420 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-12-14 08:52:01,510 INFO L134 CoverageAnalysis]: Checked inductivity of 16 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 16 trivial. 0 not checked. [2022-12-14 08:52:01,511 INFO L136 FreeRefinementEngine]: Strategy SIFA_TAIPAN found an infeasible trace [2022-12-14 08:52:01,511 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [1106925398] [2022-12-14 08:52:01,511 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [1106925398] provided 1 perfect and 0 imperfect interpolant sequences [2022-12-14 08:52:01,511 INFO L184 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2022-12-14 08:52:01,511 INFO L197 FreeRefinementEngine]: Number of different interpolants: perfect sequences [2] imperfect sequences [] total 2 [2022-12-14 08:52:01,513 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [478400033] [2022-12-14 08:52:01,513 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2022-12-14 08:52:01,516 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 2 states [2022-12-14 08:52:01,516 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy SIFA_TAIPAN [2022-12-14 08:52:01,537 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 2 interpolants. [2022-12-14 08:52:01,538 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=1, Invalid=1, Unknown=0, NotChecked=0, Total=2 [2022-12-14 08:52:01,540 INFO L87 Difference]: Start difference. First operand has 180 states, 106 states have (on average 1.3396226415094339) internal successors, (142), 110 states have internal predecessors, (142), 50 states have call successors, (50), 22 states have call predecessors, (50), 22 states have return successors, (50), 50 states have call predecessors, (50), 50 states have call successors, (50) Second operand has 2 states, 2 states have (on average 15.5) internal successors, (31), 2 states have internal predecessors, (31), 2 states have call successors, (15), 2 states have call predecessors, (15), 1 states have return successors, (13), 2 states have call predecessors, (13), 2 states have call successors, (13) [2022-12-14 08:52:01,640 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-12-14 08:52:01,641 INFO L93 Difference]: Finished difference Result 277 states and 362 transitions. [2022-12-14 08:52:01,641 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 2 states. [2022-12-14 08:52:01,642 INFO L78 Accepts]: Start accepts. Automaton has has 2 states, 2 states have (on average 15.5) internal successors, (31), 2 states have internal predecessors, (31), 2 states have call successors, (15), 2 states have call predecessors, (15), 1 states have return successors, (13), 2 states have call predecessors, (13), 2 states have call successors, (13) Word has length 65 [2022-12-14 08:52:01,643 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2022-12-14 08:52:01,650 INFO L225 Difference]: With dead ends: 277 [2022-12-14 08:52:01,650 INFO L226 Difference]: Without dead ends: 177 [2022-12-14 08:52:01,653 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 2 GetRequests, 2 SyntacticMatches, 0 SemanticMatches, 0 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 0 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=1, Invalid=1, Unknown=0, NotChecked=0, Total=2 [2022-12-14 08:52:01,655 INFO L413 NwaCegarLoop]: 209 mSDtfsCounter, 0 mSDsluCounter, 0 mSDsCounter, 0 mSdLazyCounter, 31 mSolverCounterSat, 0 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.1s Time, 0 mProtectedPredicate, 0 mProtectedAction, 0 SdHoareTripleChecker+Valid, 209 SdHoareTripleChecker+Invalid, 31 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 0 IncrementalHoareTripleChecker+Valid, 31 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.1s IncrementalHoareTripleChecker+Time [2022-12-14 08:52:01,656 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [0 Valid, 209 Invalid, 31 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [0 Valid, 31 Invalid, 0 Unknown, 0 Unchecked, 0.1s Time] [2022-12-14 08:52:01,668 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 177 states. [2022-12-14 08:52:01,689 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 177 to 177. [2022-12-14 08:52:01,690 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 177 states, 104 states have (on average 1.3076923076923077) internal successors, (136), 107 states have internal predecessors, (136), 50 states have call successors, (50), 22 states have call predecessors, (50), 22 states have return successors, (49), 49 states have call predecessors, (49), 49 states have call successors, (49) [2022-12-14 08:52:01,692 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 177 states to 177 states and 235 transitions. [2022-12-14 08:52:01,693 INFO L78 Accepts]: Start accepts. Automaton has 177 states and 235 transitions. Word has length 65 [2022-12-14 08:52:01,694 INFO L84 Accepts]: Finished accepts. word is rejected. [2022-12-14 08:52:01,694 INFO L495 AbstractCegarLoop]: Abstraction has 177 states and 235 transitions. [2022-12-14 08:52:01,695 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 2 states, 2 states have (on average 15.5) internal successors, (31), 2 states have internal predecessors, (31), 2 states have call successors, (15), 2 states have call predecessors, (15), 1 states have return successors, (13), 2 states have call predecessors, (13), 2 states have call successors, (13) [2022-12-14 08:52:01,695 INFO L276 IsEmpty]: Start isEmpty. Operand 177 states and 235 transitions. [2022-12-14 08:52:01,696 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 67 [2022-12-14 08:52:01,697 INFO L187 NwaCegarLoop]: Found error trace [2022-12-14 08:52:01,697 INFO L195 NwaCegarLoop]: trace histogram [3, 3, 2, 2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-12-14 08:52:01,697 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable0 [2022-12-14 08:52:01,697 INFO L420 AbstractCegarLoop]: === Iteration 2 === Targeting outgoingErr0ASSERT_VIOLATIONERROR_FUNCTION === [outgoingErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2022-12-14 08:52:01,697 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2022-12-14 08:52:01,698 INFO L85 PathProgramCache]: Analyzing trace with hash 64287502, now seen corresponding path program 1 times [2022-12-14 08:52:01,698 INFO L118 FreeRefinementEngine]: Executing refinement strategy SIFA_TAIPAN [2022-12-14 08:52:01,698 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [336841390] [2022-12-14 08:52:01,698 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-12-14 08:52:01,698 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2022-12-14 08:52:01,737 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-12-14 08:52:01,841 INFO L134 CoverageAnalysis]: Checked inductivity of 16 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 16 trivial. 0 not checked. [2022-12-14 08:52:01,841 INFO L136 FreeRefinementEngine]: Strategy SIFA_TAIPAN found an infeasible trace [2022-12-14 08:52:01,841 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [336841390] [2022-12-14 08:52:01,842 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [336841390] provided 1 perfect and 0 imperfect interpolant sequences [2022-12-14 08:52:01,842 INFO L184 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2022-12-14 08:52:01,842 INFO L197 FreeRefinementEngine]: Number of different interpolants: perfect sequences [3] imperfect sequences [] total 3 [2022-12-14 08:52:01,842 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [337263242] [2022-12-14 08:52:01,842 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2022-12-14 08:52:01,843 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 3 states [2022-12-14 08:52:01,844 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy SIFA_TAIPAN [2022-12-14 08:52:01,844 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 3 interpolants. [2022-12-14 08:52:01,845 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=3, Invalid=3, Unknown=0, NotChecked=0, Total=6 [2022-12-14 08:52:01,845 INFO L87 Difference]: Start difference. First operand 177 states and 235 transitions. Second operand has 3 states, 3 states have (on average 10.666666666666666) internal successors, (32), 3 states have internal predecessors, (32), 2 states have call successors, (15), 2 states have call predecessors, (15), 1 states have return successors, (13), 2 states have call predecessors, (13), 2 states have call successors, (13) [2022-12-14 08:52:01,943 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-12-14 08:52:01,943 INFO L93 Difference]: Finished difference Result 273 states and 350 transitions. [2022-12-14 08:52:01,943 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 3 states. [2022-12-14 08:52:01,943 INFO L78 Accepts]: Start accepts. Automaton has has 3 states, 3 states have (on average 10.666666666666666) internal successors, (32), 3 states have internal predecessors, (32), 2 states have call successors, (15), 2 states have call predecessors, (15), 1 states have return successors, (13), 2 states have call predecessors, (13), 2 states have call successors, (13) Word has length 66 [2022-12-14 08:52:01,944 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2022-12-14 08:52:01,945 INFO L225 Difference]: With dead ends: 273 [2022-12-14 08:52:01,945 INFO L226 Difference]: Without dead ends: 179 [2022-12-14 08:52:01,946 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 3 GetRequests, 2 SyntacticMatches, 0 SemanticMatches, 1 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 0 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=3, Invalid=3, Unknown=0, NotChecked=0, Total=6 [2022-12-14 08:52:01,947 INFO L413 NwaCegarLoop]: 206 mSDtfsCounter, 0 mSDsluCounter, 205 mSDsCounter, 0 mSdLazyCounter, 58 mSolverCounterSat, 0 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.1s Time, 0 mProtectedPredicate, 0 mProtectedAction, 0 SdHoareTripleChecker+Valid, 411 SdHoareTripleChecker+Invalid, 58 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 0 IncrementalHoareTripleChecker+Valid, 58 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.1s IncrementalHoareTripleChecker+Time [2022-12-14 08:52:01,947 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [0 Valid, 411 Invalid, 58 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [0 Valid, 58 Invalid, 0 Unknown, 0 Unchecked, 0.1s Time] [2022-12-14 08:52:01,948 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 179 states. [2022-12-14 08:52:01,958 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 179 to 179. [2022-12-14 08:52:01,958 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 179 states, 106 states have (on average 1.3018867924528301) internal successors, (138), 109 states have internal predecessors, (138), 50 states have call successors, (50), 22 states have call predecessors, (50), 22 states have return successors, (49), 49 states have call predecessors, (49), 49 states have call successors, (49) [2022-12-14 08:52:01,959 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 179 states to 179 states and 237 transitions. [2022-12-14 08:52:01,960 INFO L78 Accepts]: Start accepts. Automaton has 179 states and 237 transitions. Word has length 66 [2022-12-14 08:52:01,960 INFO L84 Accepts]: Finished accepts. word is rejected. [2022-12-14 08:52:01,960 INFO L495 AbstractCegarLoop]: Abstraction has 179 states and 237 transitions. [2022-12-14 08:52:01,960 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 3 states, 3 states have (on average 10.666666666666666) internal successors, (32), 3 states have internal predecessors, (32), 2 states have call successors, (15), 2 states have call predecessors, (15), 1 states have return successors, (13), 2 states have call predecessors, (13), 2 states have call successors, (13) [2022-12-14 08:52:01,960 INFO L276 IsEmpty]: Start isEmpty. Operand 179 states and 237 transitions. [2022-12-14 08:52:01,961 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 72 [2022-12-14 08:52:01,962 INFO L187 NwaCegarLoop]: Found error trace [2022-12-14 08:52:01,962 INFO L195 NwaCegarLoop]: trace histogram [3, 3, 2, 2, 2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-12-14 08:52:01,962 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable1 [2022-12-14 08:52:01,962 INFO L420 AbstractCegarLoop]: === Iteration 3 === Targeting outgoingErr0ASSERT_VIOLATIONERROR_FUNCTION === [outgoingErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2022-12-14 08:52:01,962 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2022-12-14 08:52:01,962 INFO L85 PathProgramCache]: Analyzing trace with hash -1058017485, now seen corresponding path program 1 times [2022-12-14 08:52:01,962 INFO L118 FreeRefinementEngine]: Executing refinement strategy SIFA_TAIPAN [2022-12-14 08:52:01,963 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [1510326231] [2022-12-14 08:52:01,963 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-12-14 08:52:01,963 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2022-12-14 08:52:01,991 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-12-14 08:52:02,055 INFO L134 CoverageAnalysis]: Checked inductivity of 18 backedges. 2 proven. 0 refuted. 0 times theorem prover too weak. 16 trivial. 0 not checked. [2022-12-14 08:52:02,055 INFO L136 FreeRefinementEngine]: Strategy SIFA_TAIPAN found an infeasible trace [2022-12-14 08:52:02,055 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [1510326231] [2022-12-14 08:52:02,055 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [1510326231] provided 1 perfect and 0 imperfect interpolant sequences [2022-12-14 08:52:02,055 INFO L184 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2022-12-14 08:52:02,055 INFO L197 FreeRefinementEngine]: Number of different interpolants: perfect sequences [3] imperfect sequences [] total 3 [2022-12-14 08:52:02,055 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [2033333410] [2022-12-14 08:52:02,056 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2022-12-14 08:52:02,056 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 3 states [2022-12-14 08:52:02,056 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy SIFA_TAIPAN [2022-12-14 08:52:02,057 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 3 interpolants. [2022-12-14 08:52:02,057 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=3, Invalid=3, Unknown=0, NotChecked=0, Total=6 [2022-12-14 08:52:02,057 INFO L87 Difference]: Start difference. First operand 179 states and 237 transitions. Second operand has 3 states, 3 states have (on average 12.333333333333334) internal successors, (37), 3 states have internal predecessors, (37), 2 states have call successors, (15), 2 states have call predecessors, (15), 1 states have return successors, (13), 2 states have call predecessors, (13), 2 states have call successors, (13) [2022-12-14 08:52:02,142 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-12-14 08:52:02,142 INFO L93 Difference]: Finished difference Result 388 states and 533 transitions. [2022-12-14 08:52:02,142 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 3 states. [2022-12-14 08:52:02,142 INFO L78 Accepts]: Start accepts. Automaton has has 3 states, 3 states have (on average 12.333333333333334) internal successors, (37), 3 states have internal predecessors, (37), 2 states have call successors, (15), 2 states have call predecessors, (15), 1 states have return successors, (13), 2 states have call predecessors, (13), 2 states have call successors, (13) Word has length 71 [2022-12-14 08:52:02,143 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2022-12-14 08:52:02,144 INFO L225 Difference]: With dead ends: 388 [2022-12-14 08:52:02,144 INFO L226 Difference]: Without dead ends: 227 [2022-12-14 08:52:02,145 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 3 GetRequests, 2 SyntacticMatches, 0 SemanticMatches, 1 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 0 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=3, Invalid=3, Unknown=0, NotChecked=0, Total=6 [2022-12-14 08:52:02,146 INFO L413 NwaCegarLoop]: 226 mSDtfsCounter, 57 mSDsluCounter, 201 mSDsCounter, 0 mSdLazyCounter, 61 mSolverCounterSat, 1 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.1s Time, 0 mProtectedPredicate, 0 mProtectedAction, 72 SdHoareTripleChecker+Valid, 427 SdHoareTripleChecker+Invalid, 62 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 1 IncrementalHoareTripleChecker+Valid, 61 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.1s IncrementalHoareTripleChecker+Time [2022-12-14 08:52:02,147 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [72 Valid, 427 Invalid, 62 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [1 Valid, 61 Invalid, 0 Unknown, 0 Unchecked, 0.1s Time] [2022-12-14 08:52:02,147 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 227 states. [2022-12-14 08:52:02,163 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 227 to 222. [2022-12-14 08:52:02,163 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 222 states, 138 states have (on average 1.3840579710144927) internal successors, (191), 141 states have internal predecessors, (191), 61 states have call successors, (61), 22 states have call predecessors, (61), 22 states have return successors, (60), 60 states have call predecessors, (60), 60 states have call successors, (60) [2022-12-14 08:52:02,165 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 222 states to 222 states and 312 transitions. [2022-12-14 08:52:02,165 INFO L78 Accepts]: Start accepts. Automaton has 222 states and 312 transitions. Word has length 71 [2022-12-14 08:52:02,165 INFO L84 Accepts]: Finished accepts. word is rejected. [2022-12-14 08:52:02,165 INFO L495 AbstractCegarLoop]: Abstraction has 222 states and 312 transitions. [2022-12-14 08:52:02,165 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 3 states, 3 states have (on average 12.333333333333334) internal successors, (37), 3 states have internal predecessors, (37), 2 states have call successors, (15), 2 states have call predecessors, (15), 1 states have return successors, (13), 2 states have call predecessors, (13), 2 states have call successors, (13) [2022-12-14 08:52:02,165 INFO L276 IsEmpty]: Start isEmpty. Operand 222 states and 312 transitions. [2022-12-14 08:52:02,167 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 73 [2022-12-14 08:52:02,167 INFO L187 NwaCegarLoop]: Found error trace [2022-12-14 08:52:02,168 INFO L195 NwaCegarLoop]: trace histogram [3, 3, 2, 2, 2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-12-14 08:52:02,168 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable2 [2022-12-14 08:52:02,168 INFO L420 AbstractCegarLoop]: === Iteration 4 === Targeting outgoingErr0ASSERT_VIOLATIONERROR_FUNCTION === [outgoingErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2022-12-14 08:52:02,168 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2022-12-14 08:52:02,168 INFO L85 PathProgramCache]: Analyzing trace with hash -1400331086, now seen corresponding path program 1 times [2022-12-14 08:52:02,169 INFO L118 FreeRefinementEngine]: Executing refinement strategy SIFA_TAIPAN [2022-12-14 08:52:02,169 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [2111449401] [2022-12-14 08:52:02,169 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-12-14 08:52:02,169 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2022-12-14 08:52:02,204 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-12-14 08:52:02,317 INFO L134 CoverageAnalysis]: Checked inductivity of 18 backedges. 0 proven. 2 refuted. 0 times theorem prover too weak. 16 trivial. 0 not checked. [2022-12-14 08:52:02,317 INFO L136 FreeRefinementEngine]: Strategy SIFA_TAIPAN found an infeasible trace [2022-12-14 08:52:02,318 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [2111449401] [2022-12-14 08:52:02,318 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [2111449401] provided 0 perfect and 1 imperfect interpolant sequences [2022-12-14 08:52:02,318 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleZ3 [1853600483] [2022-12-14 08:52:02,318 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-12-14 08:52:02,318 INFO L173 SolverBuilder]: Constructing external solver with command: z3 -smt2 -in SMTLIB2_COMPLIANT=true [2022-12-14 08:52:02,318 INFO L189 MonitoredProcess]: No working directory specified, using /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_1f82ca65-6edb-49dc-97e2-5ef2786422ba/bin/utaipan-gh47qXpMRh/z3 [2022-12-14 08:52:02,319 INFO L229 MonitoredProcess]: Starting monitored process 2 with /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_1f82ca65-6edb-49dc-97e2-5ef2786422ba/bin/utaipan-gh47qXpMRh/z3 -smt2 -in SMTLIB2_COMPLIANT=true (exit command is (exit), workingDir is null) [2022-12-14 08:52:02,320 INFO L327 MonitoredProcess]: [MP /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_1f82ca65-6edb-49dc-97e2-5ef2786422ba/bin/utaipan-gh47qXpMRh/z3 -smt2 -in SMTLIB2_COMPLIANT=true (2)] Waiting until timeout for monitored process [2022-12-14 08:52:02,527 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-12-14 08:52:02,531 INFO L263 TraceCheckSpWp]: Trace formula consists of 964 conjuncts, 3 conjunts are in the unsatisfiable core [2022-12-14 08:52:02,536 INFO L286 TraceCheckSpWp]: Computing forward predicates... [2022-12-14 08:52:02,583 INFO L134 CoverageAnalysis]: Checked inductivity of 18 backedges. 0 proven. 2 refuted. 0 times theorem prover too weak. 16 trivial. 0 not checked. [2022-12-14 08:52:02,583 INFO L328 TraceCheckSpWp]: Computing backward predicates... [2022-12-14 08:52:02,637 INFO L134 CoverageAnalysis]: Checked inductivity of 18 backedges. 0 proven. 2 refuted. 0 times theorem prover too weak. 16 trivial. 0 not checked. [2022-12-14 08:52:02,638 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleZ3 [1853600483] provided 0 perfect and 2 imperfect interpolant sequences [2022-12-14 08:52:02,638 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSifa [1400246066] [2022-12-14 08:52:02,659 INFO L159 IcfgInterpreter]: Started Sifa with 59 locations of interest [2022-12-14 08:52:02,660 INFO L166 IcfgInterpreter]: Building call graph [2022-12-14 08:52:02,663 INFO L171 IcfgInterpreter]: Initial procedures are [ULTIMATE.start] [2022-12-14 08:52:02,669 INFO L176 IcfgInterpreter]: Starting interpretation [2022-12-14 08:52:02,669 INFO L197 IcfgInterpreter]: Interpreting procedure ULTIMATE.start with input of size 1 for LOIs [2022-12-14 08:52:25,370 INFO L197 IcfgInterpreter]: Interpreting procedure setClientId with input of size 439 for LOIs [2022-12-14 08:52:25,655 INFO L197 IcfgInterpreter]: Interpreting procedure setClientPrivateKey with input of size 441 for LOIs [2022-12-14 08:52:25,960 INFO L180 IcfgInterpreter]: Interpretation finished [2022-12-14 08:53:04,930 WARN L233 SmtUtils]: Spent 8.28s on a formula simplification. DAG size of input: 577 DAG size of output: 381 (called from [L 361] de.uni_freiburg.informatik.ultimate.lib.modelcheckerutils.smt.predicates.PredicateUnifier.getOrConstructPredicate) [2022-12-14 08:53:12,191 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleSifa [1400246066] provided 1 perfect and 0 imperfect interpolant sequences [2022-12-14 08:53:12,191 INFO L184 FreeRefinementEngine]: Found 1 perfect and 3 imperfect interpolant sequences. [2022-12-14 08:53:12,191 INFO L197 FreeRefinementEngine]: Number of different interpolants: perfect sequences [20] imperfect sequences [4, 4, 4] total 26 [2022-12-14 08:53:12,192 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [1729832328] [2022-12-14 08:53:12,192 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2022-12-14 08:53:12,193 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 21 states [2022-12-14 08:53:12,193 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy SIFA_TAIPAN [2022-12-14 08:53:12,193 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 21 interpolants. [2022-12-14 08:53:12,194 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=83, Invalid=567, Unknown=0, NotChecked=0, Total=650 [2022-12-14 08:53:12,194 INFO L87 Difference]: Start difference. First operand 222 states and 312 transitions. Second operand has 21 states, 16 states have (on average 2.3125) internal successors, (37), 15 states have internal predecessors, (37), 7 states have call successors, (15), 3 states have call predecessors, (15), 3 states have return successors, (13), 7 states have call predecessors, (13), 7 states have call successors, (13) [2022-12-14 08:53:17,301 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-12-14 08:53:17,302 INFO L93 Difference]: Finished difference Result 523 states and 785 transitions. [2022-12-14 08:53:17,302 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 21 states. [2022-12-14 08:53:17,302 INFO L78 Accepts]: Start accepts. Automaton has has 21 states, 16 states have (on average 2.3125) internal successors, (37), 15 states have internal predecessors, (37), 7 states have call successors, (15), 3 states have call predecessors, (15), 3 states have return successors, (13), 7 states have call predecessors, (13), 7 states have call successors, (13) Word has length 72 [2022-12-14 08:53:17,303 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2022-12-14 08:53:17,304 INFO L225 Difference]: With dead ends: 523 [2022-12-14 08:53:17,304 INFO L226 Difference]: Without dead ends: 319 [2022-12-14 08:53:17,306 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 218 GetRequests, 194 SyntacticMatches, 0 SemanticMatches, 24 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 145 ImplicationChecksByTransitivity, 46.2s TimeCoverageRelationStatistics Valid=83, Invalid=567, Unknown=0, NotChecked=0, Total=650 [2022-12-14 08:53:17,306 INFO L413 NwaCegarLoop]: 250 mSDtfsCounter, 161 mSDsluCounter, 2936 mSDsCounter, 0 mSdLazyCounter, 1843 mSolverCounterSat, 9 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 4.6s Time, 0 mProtectedPredicate, 0 mProtectedAction, 161 SdHoareTripleChecker+Valid, 3186 SdHoareTripleChecker+Invalid, 1852 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.1s SdHoareTripleChecker+Time, 9 IncrementalHoareTripleChecker+Valid, 1843 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 4.9s IncrementalHoareTripleChecker+Time [2022-12-14 08:53:17,307 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [161 Valid, 3186 Invalid, 1852 Unknown, 0 Unchecked, 0.1s Time], IncrementalHoareTripleChecker [9 Valid, 1843 Invalid, 0 Unknown, 0 Unchecked, 4.9s Time] [2022-12-14 08:53:17,307 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 319 states. [2022-12-14 08:53:17,380 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 319 to 245. [2022-12-14 08:53:17,380 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 245 states, 160 states have (on average 1.4) internal successors, (224), 163 states have internal predecessors, (224), 61 states have call successors, (61), 23 states have call predecessors, (61), 23 states have return successors, (60), 60 states have call predecessors, (60), 60 states have call successors, (60) [2022-12-14 08:53:17,381 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 245 states to 245 states and 345 transitions. [2022-12-14 08:53:17,382 INFO L78 Accepts]: Start accepts. Automaton has 245 states and 345 transitions. Word has length 72 [2022-12-14 08:53:17,382 INFO L84 Accepts]: Finished accepts. word is rejected. [2022-12-14 08:53:17,382 INFO L495 AbstractCegarLoop]: Abstraction has 245 states and 345 transitions. [2022-12-14 08:53:17,382 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 21 states, 16 states have (on average 2.3125) internal successors, (37), 15 states have internal predecessors, (37), 7 states have call successors, (15), 3 states have call predecessors, (15), 3 states have return successors, (13), 7 states have call predecessors, (13), 7 states have call successors, (13) [2022-12-14 08:53:17,382 INFO L276 IsEmpty]: Start isEmpty. Operand 245 states and 345 transitions. [2022-12-14 08:53:17,384 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 78 [2022-12-14 08:53:17,384 INFO L187 NwaCegarLoop]: Found error trace [2022-12-14 08:53:17,384 INFO L195 NwaCegarLoop]: trace histogram [4, 3, 2, 2, 2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-12-14 08:53:17,392 INFO L540 MonitoredProcess]: [MP /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_1f82ca65-6edb-49dc-97e2-5ef2786422ba/bin/utaipan-gh47qXpMRh/z3 -smt2 -in SMTLIB2_COMPLIANT=true (2)] Forceful destruction successful, exit code 0 [2022-12-14 08:53:17,585 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable3,2 /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_1f82ca65-6edb-49dc-97e2-5ef2786422ba/bin/utaipan-gh47qXpMRh/z3 -smt2 -in SMTLIB2_COMPLIANT=true [2022-12-14 08:53:17,585 INFO L420 AbstractCegarLoop]: === Iteration 5 === Targeting outgoingErr0ASSERT_VIOLATIONERROR_FUNCTION === [outgoingErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2022-12-14 08:53:17,586 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2022-12-14 08:53:17,586 INFO L85 PathProgramCache]: Analyzing trace with hash 1384784358, now seen corresponding path program 1 times [2022-12-14 08:53:17,586 INFO L118 FreeRefinementEngine]: Executing refinement strategy SIFA_TAIPAN [2022-12-14 08:53:17,586 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [1989295980] [2022-12-14 08:53:17,586 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-12-14 08:53:17,586 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2022-12-14 08:53:17,609 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-12-14 08:53:17,649 INFO L134 CoverageAnalysis]: Checked inductivity of 24 backedges. 2 proven. 0 refuted. 0 times theorem prover too weak. 22 trivial. 0 not checked. [2022-12-14 08:53:17,650 INFO L136 FreeRefinementEngine]: Strategy SIFA_TAIPAN found an infeasible trace [2022-12-14 08:53:17,650 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [1989295980] [2022-12-14 08:53:17,650 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [1989295980] provided 1 perfect and 0 imperfect interpolant sequences [2022-12-14 08:53:17,650 INFO L184 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2022-12-14 08:53:17,650 INFO L197 FreeRefinementEngine]: Number of different interpolants: perfect sequences [3] imperfect sequences [] total 3 [2022-12-14 08:53:17,650 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [283198899] [2022-12-14 08:53:17,650 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2022-12-14 08:53:17,651 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 3 states [2022-12-14 08:53:17,651 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy SIFA_TAIPAN [2022-12-14 08:53:17,652 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 3 interpolants. [2022-12-14 08:53:17,652 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=3, Invalid=3, Unknown=0, NotChecked=0, Total=6 [2022-12-14 08:53:17,652 INFO L87 Difference]: Start difference. First operand 245 states and 345 transitions. Second operand has 3 states, 3 states have (on average 13.333333333333334) internal successors, (40), 3 states have internal predecessors, (40), 2 states have call successors, (16), 2 states have call predecessors, (16), 1 states have return successors, (14), 2 states have call predecessors, (14), 2 states have call successors, (14) [2022-12-14 08:53:17,878 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-12-14 08:53:17,878 INFO L93 Difference]: Finished difference Result 583 states and 854 transitions. [2022-12-14 08:53:17,879 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 3 states. [2022-12-14 08:53:17,879 INFO L78 Accepts]: Start accepts. Automaton has has 3 states, 3 states have (on average 13.333333333333334) internal successors, (40), 3 states have internal predecessors, (40), 2 states have call successors, (16), 2 states have call predecessors, (16), 1 states have return successors, (14), 2 states have call predecessors, (14), 2 states have call successors, (14) Word has length 77 [2022-12-14 08:53:17,879 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2022-12-14 08:53:17,882 INFO L225 Difference]: With dead ends: 583 [2022-12-14 08:53:17,882 INFO L226 Difference]: Without dead ends: 362 [2022-12-14 08:53:17,884 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 3 GetRequests, 2 SyntacticMatches, 0 SemanticMatches, 1 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 0 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=3, Invalid=3, Unknown=0, NotChecked=0, Total=6 [2022-12-14 08:53:17,884 INFO L413 NwaCegarLoop]: 227 mSDtfsCounter, 55 mSDsluCounter, 205 mSDsCounter, 0 mSdLazyCounter, 62 mSolverCounterSat, 1 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.1s Time, 0 mProtectedPredicate, 0 mProtectedAction, 70 SdHoareTripleChecker+Valid, 432 SdHoareTripleChecker+Invalid, 63 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 1 IncrementalHoareTripleChecker+Valid, 62 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.1s IncrementalHoareTripleChecker+Time [2022-12-14 08:53:17,884 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [70 Valid, 432 Invalid, 63 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [1 Valid, 62 Invalid, 0 Unknown, 0 Unchecked, 0.1s Time] [2022-12-14 08:53:17,885 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 362 states. [2022-12-14 08:53:18,000 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 362 to 357. [2022-12-14 08:53:18,000 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 357 states, 247 states have (on average 1.45748987854251) internal successors, (360), 250 states have internal predecessors, (360), 86 states have call successors, (86), 23 states have call predecessors, (86), 23 states have return successors, (85), 85 states have call predecessors, (85), 85 states have call successors, (85) [2022-12-14 08:53:18,002 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 357 states to 357 states and 531 transitions. [2022-12-14 08:53:18,002 INFO L78 Accepts]: Start accepts. Automaton has 357 states and 531 transitions. Word has length 77 [2022-12-14 08:53:18,002 INFO L84 Accepts]: Finished accepts. word is rejected. [2022-12-14 08:53:18,002 INFO L495 AbstractCegarLoop]: Abstraction has 357 states and 531 transitions. [2022-12-14 08:53:18,002 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 3 states, 3 states have (on average 13.333333333333334) internal successors, (40), 3 states have internal predecessors, (40), 2 states have call successors, (16), 2 states have call predecessors, (16), 1 states have return successors, (14), 2 states have call predecessors, (14), 2 states have call successors, (14) [2022-12-14 08:53:18,002 INFO L276 IsEmpty]: Start isEmpty. Operand 357 states and 531 transitions. [2022-12-14 08:53:18,004 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 79 [2022-12-14 08:53:18,004 INFO L187 NwaCegarLoop]: Found error trace [2022-12-14 08:53:18,004 INFO L195 NwaCegarLoop]: trace histogram [4, 3, 2, 2, 2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-12-14 08:53:18,004 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable4 [2022-12-14 08:53:18,004 INFO L420 AbstractCegarLoop]: === Iteration 6 === Targeting outgoingErr0ASSERT_VIOLATIONERROR_FUNCTION === [outgoingErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2022-12-14 08:53:18,005 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2022-12-14 08:53:18,005 INFO L85 PathProgramCache]: Analyzing trace with hash 871434472, now seen corresponding path program 1 times [2022-12-14 08:53:18,005 INFO L118 FreeRefinementEngine]: Executing refinement strategy SIFA_TAIPAN [2022-12-14 08:53:18,005 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [296789596] [2022-12-14 08:53:18,005 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-12-14 08:53:18,005 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2022-12-14 08:53:18,023 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-12-14 08:53:18,102 INFO L134 CoverageAnalysis]: Checked inductivity of 24 backedges. 0 proven. 2 refuted. 0 times theorem prover too weak. 22 trivial. 0 not checked. [2022-12-14 08:53:18,102 INFO L136 FreeRefinementEngine]: Strategy SIFA_TAIPAN found an infeasible trace [2022-12-14 08:53:18,102 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [296789596] [2022-12-14 08:53:18,102 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [296789596] provided 0 perfect and 1 imperfect interpolant sequences [2022-12-14 08:53:18,103 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleZ3 [1844417615] [2022-12-14 08:53:18,103 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-12-14 08:53:18,103 INFO L173 SolverBuilder]: Constructing external solver with command: z3 -smt2 -in SMTLIB2_COMPLIANT=true [2022-12-14 08:53:18,103 INFO L189 MonitoredProcess]: No working directory specified, using /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_1f82ca65-6edb-49dc-97e2-5ef2786422ba/bin/utaipan-gh47qXpMRh/z3 [2022-12-14 08:53:18,104 INFO L229 MonitoredProcess]: Starting monitored process 3 with /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_1f82ca65-6edb-49dc-97e2-5ef2786422ba/bin/utaipan-gh47qXpMRh/z3 -smt2 -in SMTLIB2_COMPLIANT=true (exit command is (exit), workingDir is null) [2022-12-14 08:53:18,105 INFO L327 MonitoredProcess]: [MP /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_1f82ca65-6edb-49dc-97e2-5ef2786422ba/bin/utaipan-gh47qXpMRh/z3 -smt2 -in SMTLIB2_COMPLIANT=true (3)] Waiting until timeout for monitored process [2022-12-14 08:53:18,297 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-12-14 08:53:18,301 INFO L263 TraceCheckSpWp]: Trace formula consists of 994 conjuncts, 3 conjunts are in the unsatisfiable core [2022-12-14 08:53:18,305 INFO L286 TraceCheckSpWp]: Computing forward predicates... [2022-12-14 08:53:18,324 INFO L134 CoverageAnalysis]: Checked inductivity of 24 backedges. 0 proven. 2 refuted. 0 times theorem prover too weak. 22 trivial. 0 not checked. [2022-12-14 08:53:18,324 INFO L328 TraceCheckSpWp]: Computing backward predicates... [2022-12-14 08:53:18,368 INFO L134 CoverageAnalysis]: Checked inductivity of 24 backedges. 0 proven. 2 refuted. 0 times theorem prover too weak. 22 trivial. 0 not checked. [2022-12-14 08:53:18,368 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleZ3 [1844417615] provided 0 perfect and 2 imperfect interpolant sequences [2022-12-14 08:53:18,368 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSifa [1066105260] [2022-12-14 08:53:18,371 INFO L159 IcfgInterpreter]: Started Sifa with 63 locations of interest [2022-12-14 08:53:18,371 INFO L166 IcfgInterpreter]: Building call graph [2022-12-14 08:53:18,372 INFO L171 IcfgInterpreter]: Initial procedures are [ULTIMATE.start] [2022-12-14 08:53:18,372 INFO L176 IcfgInterpreter]: Starting interpretation [2022-12-14 08:53:18,372 INFO L197 IcfgInterpreter]: Interpreting procedure ULTIMATE.start with input of size 1 for LOIs [2022-12-14 08:54:01,522 INFO L197 IcfgInterpreter]: Interpreting procedure setClientId with input of size 439 for LOIs [2022-12-14 08:54:01,812 INFO L197 IcfgInterpreter]: Interpreting procedure setClientPrivateKey with input of size 450 for LOIs [2022-12-14 08:54:02,101 INFO L180 IcfgInterpreter]: Interpretation finished [2022-12-14 08:54:43,770 WARN L233 SmtUtils]: Spent 10.36s on a formula simplification. DAG size of input: 583 DAG size of output: 458 (called from [L 361] de.uni_freiburg.informatik.ultimate.lib.modelcheckerutils.smt.predicates.PredicateUnifier.getOrConstructPredicate) [2022-12-14 08:54:59,570 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleSifa [1066105260] provided 1 perfect and 0 imperfect interpolant sequences [2022-12-14 08:54:59,570 INFO L184 FreeRefinementEngine]: Found 1 perfect and 3 imperfect interpolant sequences. [2022-12-14 08:54:59,570 INFO L197 FreeRefinementEngine]: Number of different interpolants: perfect sequences [24] imperfect sequences [4, 4, 4] total 30 [2022-12-14 08:54:59,570 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [1168605182] [2022-12-14 08:54:59,570 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2022-12-14 08:54:59,571 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 25 states [2022-12-14 08:54:59,571 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy SIFA_TAIPAN [2022-12-14 08:54:59,571 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 25 interpolants. [2022-12-14 08:54:59,571 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=109, Invalid=761, Unknown=0, NotChecked=0, Total=870 [2022-12-14 08:54:59,572 INFO L87 Difference]: Start difference. First operand 357 states and 531 transitions. Second operand has 25 states, 19 states have (on average 2.1052631578947367) internal successors, (40), 18 states have internal predecessors, (40), 8 states have call successors, (16), 3 states have call predecessors, (16), 3 states have return successors, (14), 8 states have call predecessors, (14), 8 states have call successors, (14) [2022-12-14 08:55:11,308 WARN L233 SmtUtils]: Spent 10.62s on a formula simplification. DAG size of input: 560 DAG size of output: 457 (called from [L 361] de.uni_freiburg.informatik.ultimate.lib.modelcheckerutils.smt.predicates.PredicateUnifier.getOrConstructPredicate) [2022-12-14 08:55:26,945 WARN L233 SmtUtils]: Spent 6.16s on a formula simplification. DAG size of input: 582 DAG size of output: 448 (called from [L 361] de.uni_freiburg.informatik.ultimate.lib.modelcheckerutils.smt.predicates.PredicateUnifier.getOrConstructPredicate) [2022-12-14 08:55:33,406 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-12-14 08:55:33,406 INFO L93 Difference]: Finished difference Result 798 states and 1243 transitions. [2022-12-14 08:55:33,407 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 31 states. [2022-12-14 08:55:33,407 INFO L78 Accepts]: Start accepts. Automaton has has 25 states, 19 states have (on average 2.1052631578947367) internal successors, (40), 18 states have internal predecessors, (40), 8 states have call successors, (16), 3 states have call predecessors, (16), 3 states have return successors, (14), 8 states have call predecessors, (14), 8 states have call successors, (14) Word has length 78 [2022-12-14 08:55:33,407 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2022-12-14 08:55:33,409 INFO L225 Difference]: With dead ends: 798 [2022-12-14 08:55:33,409 INFO L226 Difference]: Without dead ends: 504 [2022-12-14 08:55:33,410 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 244 GetRequests, 208 SyntacticMatches, 0 SemanticMatches, 36 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 274 ImplicationChecksByTransitivity, 83.8s TimeCoverageRelationStatistics Valid=181, Invalid=1225, Unknown=0, NotChecked=0, Total=1406 [2022-12-14 08:55:33,410 INFO L413 NwaCegarLoop]: 217 mSDtfsCounter, 182 mSDsluCounter, 3094 mSDsCounter, 0 mSdLazyCounter, 2288 mSolverCounterSat, 20 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 6.6s Time, 0 mProtectedPredicate, 0 mProtectedAction, 184 SdHoareTripleChecker+Valid, 3311 SdHoareTripleChecker+Invalid, 2308 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.1s SdHoareTripleChecker+Time, 20 IncrementalHoareTripleChecker+Valid, 2288 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 7.1s IncrementalHoareTripleChecker+Time [2022-12-14 08:55:33,410 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [184 Valid, 3311 Invalid, 2308 Unknown, 0 Unchecked, 0.1s Time], IncrementalHoareTripleChecker [20 Valid, 2288 Invalid, 0 Unknown, 0 Unchecked, 7.1s Time] [2022-12-14 08:55:33,411 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 504 states. [2022-12-14 08:55:33,588 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 504 to 418. [2022-12-14 08:55:33,588 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 418 states, 304 states have (on average 1.5032894736842106) internal successors, (457), 309 states have internal predecessors, (457), 89 states have call successors, (89), 24 states have call predecessors, (89), 24 states have return successors, (88), 86 states have call predecessors, (88), 88 states have call successors, (88) [2022-12-14 08:55:33,590 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 418 states to 418 states and 634 transitions. [2022-12-14 08:55:33,590 INFO L78 Accepts]: Start accepts. Automaton has 418 states and 634 transitions. Word has length 78 [2022-12-14 08:55:33,590 INFO L84 Accepts]: Finished accepts. word is rejected. [2022-12-14 08:55:33,590 INFO L495 AbstractCegarLoop]: Abstraction has 418 states and 634 transitions. [2022-12-14 08:55:33,590 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 25 states, 19 states have (on average 2.1052631578947367) internal successors, (40), 18 states have internal predecessors, (40), 8 states have call successors, (16), 3 states have call predecessors, (16), 3 states have return successors, (14), 8 states have call predecessors, (14), 8 states have call successors, (14) [2022-12-14 08:55:33,590 INFO L276 IsEmpty]: Start isEmpty. Operand 418 states and 634 transitions. [2022-12-14 08:55:33,591 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 82 [2022-12-14 08:55:33,592 INFO L187 NwaCegarLoop]: Found error trace [2022-12-14 08:55:33,592 INFO L195 NwaCegarLoop]: trace histogram [3, 3, 2, 2, 2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-12-14 08:55:33,597 INFO L552 MonitoredProcess]: [MP /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_1f82ca65-6edb-49dc-97e2-5ef2786422ba/bin/utaipan-gh47qXpMRh/z3 -smt2 -in SMTLIB2_COMPLIANT=true (3)] Ended with exit code 0 [2022-12-14 08:55:33,792 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: 3 /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_1f82ca65-6edb-49dc-97e2-5ef2786422ba/bin/utaipan-gh47qXpMRh/z3 -smt2 -in SMTLIB2_COMPLIANT=true,SelfDestructingSolverStorable5 [2022-12-14 08:55:33,793 INFO L420 AbstractCegarLoop]: === Iteration 7 === Targeting outgoingErr0ASSERT_VIOLATIONERROR_FUNCTION === [outgoingErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2022-12-14 08:55:33,794 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2022-12-14 08:55:33,795 INFO L85 PathProgramCache]: Analyzing trace with hash 77150056, now seen corresponding path program 1 times [2022-12-14 08:55:33,795 INFO L118 FreeRefinementEngine]: Executing refinement strategy SIFA_TAIPAN [2022-12-14 08:55:33,795 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [809381670] [2022-12-14 08:55:33,795 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-12-14 08:55:33,796 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2022-12-14 08:55:33,848 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-12-14 08:55:33,937 INFO L134 CoverageAnalysis]: Checked inductivity of 18 backedges. 0 proven. 2 refuted. 0 times theorem prover too weak. 16 trivial. 0 not checked. [2022-12-14 08:55:33,937 INFO L136 FreeRefinementEngine]: Strategy SIFA_TAIPAN found an infeasible trace [2022-12-14 08:55:33,937 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [809381670] [2022-12-14 08:55:33,938 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [809381670] provided 0 perfect and 1 imperfect interpolant sequences [2022-12-14 08:55:33,938 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleZ3 [838862330] [2022-12-14 08:55:33,938 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-12-14 08:55:33,938 INFO L173 SolverBuilder]: Constructing external solver with command: z3 -smt2 -in SMTLIB2_COMPLIANT=true [2022-12-14 08:55:33,938 INFO L189 MonitoredProcess]: No working directory specified, using /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_1f82ca65-6edb-49dc-97e2-5ef2786422ba/bin/utaipan-gh47qXpMRh/z3 [2022-12-14 08:55:33,939 INFO L229 MonitoredProcess]: Starting monitored process 4 with /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_1f82ca65-6edb-49dc-97e2-5ef2786422ba/bin/utaipan-gh47qXpMRh/z3 -smt2 -in SMTLIB2_COMPLIANT=true (exit command is (exit), workingDir is null) [2022-12-14 08:55:33,939 INFO L327 MonitoredProcess]: [MP /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_1f82ca65-6edb-49dc-97e2-5ef2786422ba/bin/utaipan-gh47qXpMRh/z3 -smt2 -in SMTLIB2_COMPLIANT=true (4)] Waiting until timeout for monitored process [2022-12-14 08:55:34,116 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-12-14 08:55:34,119 INFO L263 TraceCheckSpWp]: Trace formula consists of 1100 conjuncts, 3 conjunts are in the unsatisfiable core [2022-12-14 08:55:34,123 INFO L286 TraceCheckSpWp]: Computing forward predicates... [2022-12-14 08:55:34,141 INFO L134 CoverageAnalysis]: Checked inductivity of 18 backedges. 0 proven. 2 refuted. 0 times theorem prover too weak. 16 trivial. 0 not checked. [2022-12-14 08:55:34,141 INFO L328 TraceCheckSpWp]: Computing backward predicates... [2022-12-14 08:55:34,180 INFO L134 CoverageAnalysis]: Checked inductivity of 18 backedges. 0 proven. 2 refuted. 0 times theorem prover too weak. 16 trivial. 0 not checked. [2022-12-14 08:55:34,180 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleZ3 [838862330] provided 0 perfect and 2 imperfect interpolant sequences [2022-12-14 08:55:34,180 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSifa [1540934860] [2022-12-14 08:55:34,184 INFO L159 IcfgInterpreter]: Started Sifa with 68 locations of interest [2022-12-14 08:55:34,184 INFO L166 IcfgInterpreter]: Building call graph [2022-12-14 08:55:34,185 INFO L171 IcfgInterpreter]: Initial procedures are [ULTIMATE.start] [2022-12-14 08:55:34,185 INFO L176 IcfgInterpreter]: Starting interpretation [2022-12-14 08:55:34,185 INFO L197 IcfgInterpreter]: Interpreting procedure ULTIMATE.start with input of size 1 for LOIs [2022-12-14 08:56:23,727 INFO L197 IcfgInterpreter]: Interpreting procedure setClientId with input of size 439 for LOIs [2022-12-14 08:56:24,011 INFO L197 IcfgInterpreter]: Interpreting procedure setClientKeyringPublicKey with input of size 234 for LOIs [2022-12-14 08:56:24,071 INFO L197 IcfgInterpreter]: Interpreting procedure setClientKeyringUser with input of size 243 for LOIs [2022-12-14 08:56:24,135 INFO L197 IcfgInterpreter]: Interpreting procedure createClientKeyringEntry with input of size 449 for LOIs [2022-12-14 08:56:24,463 INFO L197 IcfgInterpreter]: Interpreting procedure setClientPrivateKey with input of size 441 for LOIs [2022-12-14 08:56:24,749 INFO L180 IcfgInterpreter]: Interpretation finished [2022-12-14 08:57:02,350 WARN L233 SmtUtils]: Spent 8.27s on a formula simplification. DAG size of input: 623 DAG size of output: 458 (called from [L 361] de.uni_freiburg.informatik.ultimate.lib.modelcheckerutils.smt.predicates.PredicateUnifier.getOrConstructPredicate) [2022-12-14 08:57:15,122 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleSifa [1540934860] provided 1 perfect and 0 imperfect interpolant sequences [2022-12-14 08:57:15,122 INFO L184 FreeRefinementEngine]: Found 1 perfect and 3 imperfect interpolant sequences. [2022-12-14 08:57:15,123 INFO L197 FreeRefinementEngine]: Number of different interpolants: perfect sequences [28] imperfect sequences [4, 4, 4] total 34 [2022-12-14 08:57:15,123 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [695267403] [2022-12-14 08:57:15,123 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2022-12-14 08:57:15,123 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 29 states [2022-12-14 08:57:15,124 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy SIFA_TAIPAN [2022-12-14 08:57:15,124 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 29 interpolants. [2022-12-14 08:57:15,124 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=101, Invalid=1021, Unknown=0, NotChecked=0, Total=1122 [2022-12-14 08:57:15,124 INFO L87 Difference]: Start difference. First operand 418 states and 634 transitions. Second operand has 29 states, 19 states have (on average 2.1052631578947367) internal successors, (40), 17 states have internal predecessors, (40), 10 states have call successors, (18), 6 states have call predecessors, (18), 6 states have return successors, (16), 10 states have call predecessors, (16), 10 states have call successors, (16) [2022-12-14 08:57:29,888 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-12-14 08:57:29,888 INFO L93 Difference]: Finished difference Result 919 states and 1449 transitions. [2022-12-14 08:57:29,889 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 31 states. [2022-12-14 08:57:29,889 INFO L78 Accepts]: Start accepts. Automaton has has 29 states, 19 states have (on average 2.1052631578947367) internal successors, (40), 17 states have internal predecessors, (40), 10 states have call successors, (18), 6 states have call predecessors, (18), 6 states have return successors, (16), 10 states have call predecessors, (16), 10 states have call successors, (16) Word has length 81 [2022-12-14 08:57:29,889 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2022-12-14 08:57:29,891 INFO L225 Difference]: With dead ends: 919 [2022-12-14 08:57:29,891 INFO L226 Difference]: Without dead ends: 625 [2022-12-14 08:57:29,892 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 247 GetRequests, 212 SyntacticMatches, 1 SemanticMatches, 34 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 262 ImplicationChecksByTransitivity, 54.9s TimeCoverageRelationStatistics Valid=118, Invalid=1142, Unknown=0, NotChecked=0, Total=1260 [2022-12-14 08:57:29,893 INFO L413 NwaCegarLoop]: 211 mSDtfsCounter, 197 mSDsluCounter, 3361 mSDsCounter, 0 mSdLazyCounter, 3145 mSolverCounterSat, 10 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 9.0s Time, 0 mProtectedPredicate, 0 mProtectedAction, 197 SdHoareTripleChecker+Valid, 3572 SdHoareTripleChecker+Invalid, 3155 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.1s SdHoareTripleChecker+Time, 10 IncrementalHoareTripleChecker+Valid, 3145 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 9.6s IncrementalHoareTripleChecker+Time [2022-12-14 08:57:29,893 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [197 Valid, 3572 Invalid, 3155 Unknown, 0 Unchecked, 0.1s Time], IncrementalHoareTripleChecker [10 Valid, 3145 Invalid, 0 Unknown, 0 Unchecked, 9.6s Time] [2022-12-14 08:57:29,894 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 625 states. [2022-12-14 08:57:30,198 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 625 to 549. [2022-12-14 08:57:30,199 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 549 states, 427 states have (on average 1.5550351288056206) internal successors, (664), 434 states have internal predecessors, (664), 94 states have call successors, (94), 27 states have call predecessors, (94), 27 states have return successors, (93), 89 states have call predecessors, (93), 93 states have call successors, (93) [2022-12-14 08:57:30,200 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 549 states to 549 states and 851 transitions. [2022-12-14 08:57:30,201 INFO L78 Accepts]: Start accepts. Automaton has 549 states and 851 transitions. Word has length 81 [2022-12-14 08:57:30,201 INFO L84 Accepts]: Finished accepts. word is rejected. [2022-12-14 08:57:30,201 INFO L495 AbstractCegarLoop]: Abstraction has 549 states and 851 transitions. [2022-12-14 08:57:30,201 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 29 states, 19 states have (on average 2.1052631578947367) internal successors, (40), 17 states have internal predecessors, (40), 10 states have call successors, (18), 6 states have call predecessors, (18), 6 states have return successors, (16), 10 states have call predecessors, (16), 10 states have call successors, (16) [2022-12-14 08:57:30,201 INFO L276 IsEmpty]: Start isEmpty. Operand 549 states and 851 transitions. [2022-12-14 08:57:30,202 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 81 [2022-12-14 08:57:30,202 INFO L187 NwaCegarLoop]: Found error trace [2022-12-14 08:57:30,203 INFO L195 NwaCegarLoop]: trace histogram [3, 3, 2, 2, 2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-12-14 08:57:30,208 INFO L540 MonitoredProcess]: [MP /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_1f82ca65-6edb-49dc-97e2-5ef2786422ba/bin/utaipan-gh47qXpMRh/z3 -smt2 -in SMTLIB2_COMPLIANT=true (4)] Forceful destruction successful, exit code 0 [2022-12-14 08:57:30,403 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: 4 /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_1f82ca65-6edb-49dc-97e2-5ef2786422ba/bin/utaipan-gh47qXpMRh/z3 -smt2 -in SMTLIB2_COMPLIANT=true,SelfDestructingSolverStorable6 [2022-12-14 08:57:30,404 INFO L420 AbstractCegarLoop]: === Iteration 8 === Targeting outgoingErr0ASSERT_VIOLATIONERROR_FUNCTION === [outgoingErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2022-12-14 08:57:30,405 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2022-12-14 08:57:30,405 INFO L85 PathProgramCache]: Analyzing trace with hash 70315637, now seen corresponding path program 1 times [2022-12-14 08:57:30,406 INFO L118 FreeRefinementEngine]: Executing refinement strategy SIFA_TAIPAN [2022-12-14 08:57:30,406 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [1248133896] [2022-12-14 08:57:30,406 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-12-14 08:57:30,407 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2022-12-14 08:57:30,430 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-12-14 08:57:30,489 INFO L134 CoverageAnalysis]: Checked inductivity of 18 backedges. 0 proven. 2 refuted. 0 times theorem prover too weak. 16 trivial. 0 not checked. [2022-12-14 08:57:30,489 INFO L136 FreeRefinementEngine]: Strategy SIFA_TAIPAN found an infeasible trace [2022-12-14 08:57:30,489 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [1248133896] [2022-12-14 08:57:30,490 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [1248133896] provided 0 perfect and 1 imperfect interpolant sequences [2022-12-14 08:57:30,490 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleZ3 [1676367344] [2022-12-14 08:57:30,490 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-12-14 08:57:30,490 INFO L173 SolverBuilder]: Constructing external solver with command: z3 -smt2 -in SMTLIB2_COMPLIANT=true [2022-12-14 08:57:30,490 INFO L189 MonitoredProcess]: No working directory specified, using /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_1f82ca65-6edb-49dc-97e2-5ef2786422ba/bin/utaipan-gh47qXpMRh/z3 [2022-12-14 08:57:30,491 INFO L229 MonitoredProcess]: Starting monitored process 5 with /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_1f82ca65-6edb-49dc-97e2-5ef2786422ba/bin/utaipan-gh47qXpMRh/z3 -smt2 -in SMTLIB2_COMPLIANT=true (exit command is (exit), workingDir is null) [2022-12-14 08:57:30,492 INFO L327 MonitoredProcess]: [MP /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_1f82ca65-6edb-49dc-97e2-5ef2786422ba/bin/utaipan-gh47qXpMRh/z3 -smt2 -in SMTLIB2_COMPLIANT=true (5)] Waiting until timeout for monitored process [2022-12-14 08:57:30,667 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-12-14 08:57:30,671 INFO L263 TraceCheckSpWp]: Trace formula consists of 996 conjuncts, 3 conjunts are in the unsatisfiable core [2022-12-14 08:57:30,674 INFO L286 TraceCheckSpWp]: Computing forward predicates... [2022-12-14 08:57:30,694 INFO L134 CoverageAnalysis]: Checked inductivity of 18 backedges. 0 proven. 2 refuted. 0 times theorem prover too weak. 16 trivial. 0 not checked. [2022-12-14 08:57:30,694 INFO L328 TraceCheckSpWp]: Computing backward predicates... [2022-12-14 08:57:30,737 INFO L134 CoverageAnalysis]: Checked inductivity of 18 backedges. 0 proven. 2 refuted. 0 times theorem prover too weak. 16 trivial. 0 not checked. [2022-12-14 08:57:30,737 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleZ3 [1676367344] provided 0 perfect and 2 imperfect interpolant sequences [2022-12-14 08:57:30,737 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSifa [2111083254] [2022-12-14 08:57:30,741 INFO L159 IcfgInterpreter]: Started Sifa with 67 locations of interest [2022-12-14 08:57:30,741 INFO L166 IcfgInterpreter]: Building call graph [2022-12-14 08:57:30,741 INFO L171 IcfgInterpreter]: Initial procedures are [ULTIMATE.start] [2022-12-14 08:57:30,741 INFO L176 IcfgInterpreter]: Starting interpretation [2022-12-14 08:57:30,741 INFO L197 IcfgInterpreter]: Interpreting procedure ULTIMATE.start with input of size 1 for LOIs [2022-12-14 08:58:11,994 INFO L197 IcfgInterpreter]: Interpreting procedure setClientId with input of size 444 for LOIs [2022-12-14 08:58:12,276 INFO L197 IcfgInterpreter]: Interpreting procedure setClientPrivateKey with input of size 441 for LOIs [2022-12-14 08:58:12,558 INFO L197 IcfgInterpreter]: Interpreting procedure sendEmail with input of size 474 for LOIs [2022-12-14 08:58:22,433 INFO L197 IcfgInterpreter]: Interpreting procedure outgoing with input of size 469 for LOIs [2022-12-14 08:58:44,159 INFO L197 IcfgInterpreter]: Interpreting procedure getClientPrivateKey with input of size 443 for LOIs [2022-12-14 08:58:44,419 INFO L197 IcfgInterpreter]: Interpreting procedure findPublicKey with input of size 245 for LOIs [2022-12-14 08:58:44,483 INFO L197 IcfgInterpreter]: Interpreting procedure getEmailTo with input of size 250 for LOIs [2022-12-14 08:58:44,523 INFO L197 IcfgInterpreter]: Interpreting procedure setEmailFrom with input of size 454 for LOIs [2022-12-14 08:58:45,151 INFO L197 IcfgInterpreter]: Interpreting procedure isSigned with input of size 247 for LOIs [2022-12-14 08:58:45,189 INFO L180 IcfgInterpreter]: Interpretation finished [2022-12-14 09:01:09,873 WARN L233 SmtUtils]: Spent 5.06s on a formula simplification. DAG size of input: 599 DAG size of output: 435 (called from [L 361] de.uni_freiburg.informatik.ultimate.lib.modelcheckerutils.smt.predicates.PredicateUnifier.getOrConstructPredicate) [2022-12-14 09:01:22,574 WARN L233 SmtUtils]: Spent 8.96s on a formula simplification. DAG size of input: 606 DAG size of output: 493 (called from [L 361] de.uni_freiburg.informatik.ultimate.lib.modelcheckerutils.smt.predicates.PredicateUnifier.getOrConstructPredicate) [2022-12-14 09:01:27,966 INFO L133 SifaRunner]: Sifa could not show that error location is unreachable, found '11556#(and (= |old(~__ste_email_encryptionKey0~0)| 0) (<= 1 |outgoing_outgoing__wrappee__Keys_~msg#1|) (<= 2 |outgoing_outgoing__wrappee__Encrypt_~tmp~2#1|) (<= 0 ~__ste_email_encryptionKey1~0) (= ~__SELECTED_FEATURE_Sign~0 0) (= ~__ste_client_outbuffer3~0 0) (<= 1 |outgoing___utac_acc__SignForward_spec__1_~client#1|) (<= |outgoing___utac_acc__SignForward_spec__1_~msg#1| 1) (<= 1 |outgoing_mail_#in~client#1|) (<= |outgoing_mail_#in~msg#1| 1) (<= 0 (+ 2147483648 |outgoing_getClientId_#res#1|)) (= ~__ste_Client_counter~0 0) (<= ~__ste_email_encryptionKey1~0 0) (<= ~__ste_email_isSignatureVerified1~0 0) (<= 0 ~__ste_Client_AddressBook1_Address1~0) (= ~__ste_Client_AddressBook2_Alias0~0 0) (= 0 ~__ste_email_subject0~0.base) (<= |outgoing_outgoing__wrappee__Keys_~tmp~1#1| 2147483647) (<= 1 |outgoing_sign_~client#1|) (<= 1 |outgoing_mail_~msg#1|) (<= ~__ste_Client_Keyring0_User0~0 0) (<= |outgoing_mail_~__utac__ad__arg2~0#1| 1) (<= |outgoing_sign_~privkey~1#1| 2147483647) (<= |outgoing_#in~msg#1| 1) (<= 0 ~__ste_Client_Keyring0_PublicKey2~0) (<= 0 ~__ste_ClientAddressBook_size0~0) (<= 2 ~rjh~0) (<= |outgoing___utac_acc__SignForward_spec__1_~client#1| 1) (<= 0 ~__SELECTED_FEATURE_Encrypt~0) (<= 0 ~__ste_client_autoResponse1~0) (<= 0 ~__ste_client_outbuffer0~0) (<= ~__ste_Client_Keyring2_PublicKey2~0 0) (<= 0 |old(~__ste_email_encryptionKey1~0)|) (<= |outgoing_sign_~msg#1| 1) (<= ~chuck~0 3) (<= 0 ~__ste_client_outbuffer1~0) (<= 0 ~__ste_ClientAddressBook_size1~0) (<= ~__ste_client_idCounter2~0 3) (<= ~queued_message~0 0) (<= |old(~__ste_email_from0~0)| 0) (<= ~__ste_email_isSignatureVerified0~0 0) (<= ~__ste_client_name0~0.base 0) (<= 0 ~__ste_Client_AddressBook0_Alias1~0) (<= |outgoing_outgoing__wrappee__Encrypt_~pubkey~0#1| 0) (= ~__ste_Client_AddressBook1_Address2~0 0) (<= ~__ste_email_from0~0 2147483647) (<= 1 |outgoing_outgoing__wrappee__Encrypt_~msg#1|) (<= 0 ~__ste_Client_Keyring0_User0~0) (<= 1 |outgoing___utac_acc__SignForward_spec__1_#in~client#1|) (<= |outgoing_sign_~client#1| 1) (<= 0 ~__SELECTED_FEATURE_AutoResponder~0) (= ~__ste_email_body0~0.offset 0) (<= ~__SELECTED_FEATURE_Keys~0 0) (<= 1 |outgoing_~client#1|) (<= 1 |outgoing_outgoing__wrappee__Encrypt_#in~msg#1|) (<= 0 ~__ste_email_isSigned1~0) (<= ~__SELECTED_FEATURE_Decrypt~0 0) (<= 0 (+ ~__ste_email_from0~0 2147483648)) (= ~__ste_Client_Keyring0_User2~0 0) (<= |old(~__ste_email_isSigned0~0)| 0) (<= ~__ste_Client_Keyring1_PublicKey0~0 0) (<= |old(~__ste_email_isEncrypted0~0)| 0) (= ~__ste_Client_Keyring0_User1~0 0) (= ~__ste_Client_AddressBook1_Alias1~0 0) (= ~__ste_client_name1~0.offset 0) (<= ~__GUIDSL_NON_TERMINAL_main~0 0) (<= |outgoing_getClientId_#res#1| 2147483647) (<= |outgoing___utac_acc__SignForward_spec__1_#in~client#1| 1) (<= ~__ste_Client_AddressBook2_Address0~0 0) (<= ~__SELECTED_FEATURE_AutoResponder~0 0) (<= ~__ste_email_id0~0 0) (<= 0 ~__ste_client_name2~0.offset) (<= 1 |outgoing_outgoing__wrappee__Encrypt_~client#1|) (= ~head~0.offset 0) (<= ~__GUIDSL_ROOT_PRODUCTION~0 0) (<= ~__ste_Client_AddressBook2_Alias1~0 0) (<= 1 |outgoing_outgoing__wrappee__Keys_~client#1|) (<= 0 ~__GUIDSL_ROOT_PRODUCTION~0) (<= ~__ste_Email_counter~0 0) (<= ~__ste_Client_Keyring2_User2~0 0) (<= ~__ste_email_body1~0.offset 0) (<= ~__ste_client_privateKey2~0 789) (<= 0 ~__SELECTED_FEATURE_Decrypt~0) (<= |outgoing_sign_#in~client#1| 1) (<= 0 ~__ste_email_to1~0) (<= ~queue_empty~0 1) (<= |outgoing_sign_~tmp~6#1| 2147483647) (<= 0 ~__ste_Client_AddressBook2_Alias1~0) (<= |outgoing_outgoing__wrappee__Encrypt_~tmp~2#1| 2) (<= 0 ~__ste_Client_Keyring2_User2~0) (<= 1 |outgoing_getClientId_~handle#1|) (<= 0 ~__ste_Client_Keyring1_User2~0) (<= 0 |old(~__ste_email_isEncrypted0~0)|) (<= 0 (+ ~__ste_email_signKey0~0 2147483648)) (<= 0 ~__ste_email_isEncrypted1~0) (<= ~__ste_email_signKey0~0 2147483647) (<= 0 |old(~__ste_email_from0~0)|) (<= |#NULL.offset| 0) (<= 0 ~__ste_Client_Keyring1_User0~0) (<= 1 |outgoing___utac_acc__SignForward_spec__1_~msg#1|) (<= 0 ~__SELECTED_FEATURE_AddressBook~0) (= ~__ste_Client_Keyring0_PublicKey1~0 0) (= ~__SELECTED_FEATURE_Forward~0 0) (<= |outgoing___utac_acc__SignForward_spec__1_#in~msg#1| 1) (<= 0 ~__ste_email_isEncrypted0~0) (<= 0 |old(~__ste_email_signKey0~0)|) (<= 1 |outgoing_mail_#in~msg#1|) (<= ~__ste_Client_Keyring0_PublicKey2~0 0) (<= ~__ste_client_idCounter0~0 2147483647) (= ~__ste_Client_Keyring2_PublicKey1~0 0) (<= 0 ~__ste_email_id1~0) (<= ~__ste_Client_AddressBook0_Address1~0 0) (= ~__ste_email_body0~0.base 0) (<= ~__ste_email_isSigned0~0 1) (<= ~__ste_email_isEncrypted0~0 0) (= ~__ste_Client_AddressBook0_Alias0~0 0) (<= |outgoing_getClientId_~retValue_acc~35#1| 2147483647) (<= 1 |outgoing_outgoing__wrappee__Keys_#in~msg#1|) (<= 0 (+ |outgoing_sign_~tmp~6#1| 2147483648)) (<= 0 ~__ste_Client_AddressBook2_Address1~0) (<= 0 ~__ste_client_name0~0.offset) (<= 0 (+ |outgoing_outgoing__wrappee__Keys_~tmp~1#1| 2147483648)) (<= ~__ste_Client_Keyring0_PublicKey0~0 0) (<= ~__ste_client_name1~0.base 0) (<= ~__ste_client_autoResponse0~0 0) (<= ~__ste_email_to1~0 0) (<= ~__SELECTED_FEATURE_AddressBook~0 0) (<= ~__ste_Client_Keyring1_PublicKey2~0 0) (<= 0 ~__ste_Client_Keyring0_PublicKey0~0) (<= |outgoing_mail_~__utac__ad__arg1~0#1| 1) (<= 1 |outgoing_mail_~__utac__ad__arg1~0#1|) (<= ~__ste_client_forwardReceiver3~0 0) (<= 3 ~__ste_client_idCounter2~0) (= ~__ste_Client_AddressBook2_Address2~0 0) (<= ~__ste_ClientAddressBook_size0~0 0) (<= 0 ~__ste_Client_Keyring1_PublicKey2~0) (<= ~__ste_Client_AddressBook0_Address0~0 0) (<= 0 |outgoing___utac_acc__SignForward_spec__1_~tmp___0~9#1|) (<= 0 ~__ste_client_name0~0.base) (<= 0 ~__ste_email_signKey1~0) (<= 0 ~__ste_email_body1~0.offset) (<= 1 ~queue_empty~0) (<= ~__ste_email_signKey1~0 0) (<= 0 ~__ste_client_forwardReceiver3~0) (<= ~__ste_client_name2~0.offset 0) (<= ~__ste_email_isSigned1~0 0) (<= |outgoing_outgoing__wrappee__Encrypt_~receiver~0#1| 2) (<= ~__SELECTED_FEATURE_Encrypt~0 0) (<= 0 ~__ste_Email_counter~0) (<= ~__ste_email_subject0~0.offset 0) (<= |old(~__ste_email_signKey0~0)| 0) (<= 0 ~__ste_client_autoResponse0~0) (<= 0 ~__ste_Client_AddressBook0_Alias2~0) (<= 0 ~queued_message~0) (<= 0 |old(~__ste_email_isSignatureVerified0~0)|) (<= 0 ~__ste_email_isSignatureVerified1~0) (<= |outgoing_outgoing__wrappee__Keys_~client#1| 1) (<= 789 ~__ste_client_privateKey2~0) (<= ~__SELECTED_FEATURE_Verify~0 0) (<= 1 |outgoing_sign_#in~client#1|) (<= |outgoing_getClientId_#in~handle#1| 1) (<= |outgoing_outgoing__wrappee__Encrypt_~tmp___0~0#1| 0) (<= 1 |outgoing_sign_~msg#1|) (<= ~__ste_ClientKeyring_size1~0 0) (<= ~__ste_Client_Keyring1_User2~0 0) (<= 1 |outgoing___utac_acc__SignForward_spec__1_#in~msg#1|) (<= 0 ~head~0.base) (<= 1 |outgoing_~msg#1|) (= ~__SELECTED_FEATURE_Base~0 0) (<= ~__ste_Client_AddressBook1_Alias2~0 0) (<= 0 ~__ste_Client_AddressBook0_Address2~0) (= ~__ste_client_forwardReceiver0~0 0) (<= 0 (+ |outgoing_getClientId_~retValue_acc~35#1| 2147483648)) (<= 0 |old(~__ste_email_isSigned0~0)|) (<= |outgoing_mail_~client#1| 1) (= ~__ste_Client_Keyring2_User0~0 0) (<= 0 ~__ste_email_subject0~0.offset) (<= 0 ~__ste_Client_AddressBook1_Alias0~0) (= ~__ste_Client_Keyring1_PublicKey1~0 0) (<= 0 ~queued_client~0) (<= 0 ~__SELECTED_FEATURE_Keys~0) (<= ~__ste_Client_AddressBook1_Alias0~0 0) (<= 0 ~__ste_Client_Keyring1_PublicKey0~0) (<= 1 |outgoing_outgoing__wrappee__Encrypt_#in~client#1|) (= ~__ste_Client_Keyring2_PublicKey0~0 0) (<= 0 ~__ste_email_isSignatureVerified0~0) (= ~__ste_Client_AddressBook1_Address0~0 0) (<= 0 ~__ste_ClientKeyring_size1~0) (<= 0 ~__ste_client_forwardReceiver2~0) (= ~__ste_client_name2~0.base 0) (<= 0 ~__ste_Client_AddressBook0_Address1~0) (<= |outgoing_mail_~msg#1| 1) (not (= |outgoing___utac_acc__SignForward_spec__1_~tmp___0~9#1| 0)) (<= ~__ste_email_encryptionKey0~0 0) (<= |old(~__ste_email_encryptionKey1~0)| 0) (= ~__ste_email_subject1~0.base 0) (<= ~__ste_ClientKeyring_size0~0 0) (<= ~__ste_email_id1~0 0) (<= 0 ~__ste_Client_AddressBook0_Address0~0) (<= ~__ste_Client_Keyring1_User0~0 0) (<= 2 |outgoing_outgoing__wrappee__Encrypt_~receiver~0#1|) (<= |outgoing_mail_#in~client#1| 1) (<= ~__ste_Client_AddressBook0_Alias2~0 0) (<= |outgoing_outgoing__wrappee__Keys_#in~client#1| 1) (<= ~__ste_Client_AddressBook0_Address2~0 0) (<= ~__ste_client_autoResponse1~0 0) (<= ~__ste_client_outbuffer0~0 0) (<= ~head~0.base 0) (<= ~__ste_client_forwardReceiver1~0 0) (<= |outgoing_outgoing__wrappee__Encrypt_#in~msg#1| 1) (= ~__ste_Client_Keyring1_User1~0 0) (<= |outgoing___utac_acc__SignForward_spec__1_~tmp___0~9#1| 1) (<= |outgoing_sign_#in~msg#1| 1) (<= |old(~__ste_email_isSigned1~0)| 0) (= ~__ste_Client_AddressBook2_Alias2~0 0) (<= |outgoing_#in~client#1| 1) (<= 0 (+ |outgoing_sign_~privkey~1#1| 2147483648)) (<= ~__ste_Client_Keyring2_User1~0 0) (<= 0 ~__ste_email_isSigned0~0) (<= 0 ~__SELECTED_FEATURE_Verify~0) (<= 0 |outgoing_outgoing__wrappee__Encrypt_~pubkey~0#1|) (= |outgoing___utac_acc__SignForward_spec__1_~tmp~19#1| 0) (<= 0 ~__ste_Client_AddressBook1_Alias2~0) (<= 0 ~__ste_client_autoResponse2~0) (= ~__ste_email_subject1~0.offset 0) (<= 0 ~__ste_Client_AddressBook2_Address0~0) (<= 0 ~__ste_Client_Keyring2_User1~0) (<= |outgoing_~msg#1| 1) (<= 0 |outgoing_outgoing__wrappee__Encrypt_~tmp___0~0#1|) (<= |outgoing_outgoing__wrappee__Keys_~msg#1| 1) (<= |outgoing_outgoing__wrappee__Encrypt_~msg#1| 1) (<= ~__ste_client_name0~0.offset 0) (<= 0 ~__ste_ClientKeyring_size0~0) (<= ~__ste_email_isEncrypted1~0 0) (= |old(~__ste_email_isEncrypted1~0)| 0) (<= 1 |outgoing_getClientId_#in~handle#1|) (<= |old(~__ste_email_isSignatureVerified0~0)| 0) (<= 0 |#NULL.offset|) (<= |old(~__ste_email_isSignatureVerified1~0)| 0) (<= ~rjh~0 2) (<= |outgoing_getClientId_~handle#1| 1) (<= 1 |outgoing_sign_#in~msg#1|) (<= ~__ste_Client_AddressBook1_Address1~0 0) (<= 1 |outgoing_#in~client#1|) (<= |outgoing_~client#1| 1) (<= 1 |outgoing_#in~msg#1|) (<= ~__ste_Client_AddressBook0_Alias1~0 0) (<= 0 ~__ste_client_forwardReceiver1~0) (<= 1 |outgoing_mail_~__utac__ad__arg2~0#1|) (<= 0 ~__ste_Client_Keyring2_PublicKey2~0) (= ~__ste_client_privateKey0~0 |outgoing___utac_acc__SignForward_spec__1_~tmp~19#1|) (<= 0 |old(~__ste_email_isSignatureVerified1~0)|) (<= ~__ste_Client_AddressBook2_Address1~0 0) (= ~__ste_client_outbuffer2~0 0) (<= 1 |outgoing_outgoing__wrappee__Keys_#in~client#1|) (<= ~bob~0 1) (<= |outgoing_outgoing__wrappee__Encrypt_#in~client#1| 1) (<= 0 |old(~__ste_email_isSigned1~0)|) (<= 0 ~__GUIDSL_NON_TERMINAL_main~0) (<= |old(~__ste_email_signKey1~0)| 0) (<= 0 (+ ~__ste_client_idCounter0~0 2147483648)) (<= ~__ste_client_forwardReceiver2~0 0) (<= 2 ~__ste_email_to0~0) (<= 0 |#StackHeapBarrier|) (<= ~__ste_email_to0~0 2) (<= 1 |outgoing_mail_~client#1|) (= ~__ste_ClientAddressBook_size2~0 0) (<= 3 ~chuck~0) (<= ~__ste_client_autoResponse2~0 0) (= ~__ste_email_body1~0.base 0) (<= 1 ~bob~0) (<= ~__ste_client_outbuffer1~0 0) (= ~__ste_ClientKeyring_size2~0 0) (<= ~__ste_ClientAddressBook_size1~0 0) (<= 0 ~__ste_client_name1~0.base) (<= 0 |old(~__ste_email_signKey1~0)|) (<= |outgoing_outgoing__wrappee__Encrypt_~client#1| 1) (<= 0 ~__ste_email_id0~0) (<= 0 ~__ste_email_encryptionKey0~0) (= |#NULL.base| 0) (<= |outgoing_outgoing__wrappee__Keys_#in~msg#1| 1) (<= ~queued_client~0 0))' at error location [2022-12-14 09:01:27,966 WARN L310 FreeRefinementEngine]: Interpolation failed due to KNOWN_IGNORE: ALGORITHM_FAILED [2022-12-14 09:01:27,966 INFO L184 FreeRefinementEngine]: Found 0 perfect and 3 imperfect interpolant sequences. [2022-12-14 09:01:27,966 INFO L197 FreeRefinementEngine]: Number of different interpolants: perfect sequences [] imperfect sequences [4, 4, 4] total 7 [2022-12-14 09:01:27,966 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [433858427] [2022-12-14 09:01:27,966 INFO L85 oduleStraightlineAll]: Using 3 imperfect interpolants to construct interpolant automaton [2022-12-14 09:01:27,967 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 7 states [2022-12-14 09:01:27,967 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy SIFA_TAIPAN [2022-12-14 09:01:27,967 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 7 interpolants. [2022-12-14 09:01:27,968 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=221, Invalid=4069, Unknown=0, NotChecked=0, Total=4290 [2022-12-14 09:01:27,968 INFO L87 Difference]: Start difference. First operand 549 states and 851 transitions. Second operand has 7 states, 7 states have (on average 10.142857142857142) internal successors, (71), 7 states have internal predecessors, (71), 2 states have call successors, (22), 2 states have call predecessors, (22), 2 states have return successors, (20), 2 states have call predecessors, (20), 2 states have call successors, (20) [2022-12-14 09:01:29,105 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-12-14 09:01:29,105 INFO L93 Difference]: Finished difference Result 1339 states and 2096 transitions. [2022-12-14 09:01:29,106 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 6 states. [2022-12-14 09:01:29,106 INFO L78 Accepts]: Start accepts. Automaton has has 7 states, 7 states have (on average 10.142857142857142) internal successors, (71), 7 states have internal predecessors, (71), 2 states have call successors, (22), 2 states have call predecessors, (22), 2 states have return successors, (20), 2 states have call predecessors, (20), 2 states have call successors, (20) Word has length 80 [2022-12-14 09:01:29,106 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2022-12-14 09:01:29,109 INFO L225 Difference]: With dead ends: 1339 [2022-12-14 09:01:29,110 INFO L226 Difference]: Without dead ends: 1245 [2022-12-14 09:01:29,111 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 242 GetRequests, 177 SyntacticMatches, 1 SemanticMatches, 64 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 1148 ImplicationChecksByTransitivity, 162.7s TimeCoverageRelationStatistics Valid=221, Invalid=4069, Unknown=0, NotChecked=0, Total=4290 [2022-12-14 09:01:29,111 INFO L413 NwaCegarLoop]: 262 mSDtfsCounter, 170 mSDsluCounter, 597 mSDsCounter, 0 mSdLazyCounter, 192 mSolverCounterSat, 16 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.1s Time, 0 mProtectedPredicate, 0 mProtectedAction, 215 SdHoareTripleChecker+Valid, 859 SdHoareTripleChecker+Invalid, 208 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 16 IncrementalHoareTripleChecker+Valid, 192 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.2s IncrementalHoareTripleChecker+Time [2022-12-14 09:01:29,112 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [215 Valid, 859 Invalid, 208 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [16 Valid, 192 Invalid, 0 Unknown, 0 Unchecked, 0.2s Time] [2022-12-14 09:01:29,113 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 1245 states. [2022-12-14 09:01:29,943 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 1245 to 1217. [2022-12-14 09:01:29,944 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 1217 states, 982 states have (on average 1.5427698574338085) internal successors, (1515), 995 states have internal predecessors, (1515), 207 states have call successors, (207), 27 states have call predecessors, (207), 27 states have return successors, (206), 196 states have call predecessors, (206), 206 states have call successors, (206) [2022-12-14 09:01:29,947 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 1217 states to 1217 states and 1928 transitions. [2022-12-14 09:01:29,947 INFO L78 Accepts]: Start accepts. Automaton has 1217 states and 1928 transitions. Word has length 80 [2022-12-14 09:01:29,947 INFO L84 Accepts]: Finished accepts. word is rejected. [2022-12-14 09:01:29,947 INFO L495 AbstractCegarLoop]: Abstraction has 1217 states and 1928 transitions. [2022-12-14 09:01:29,947 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 7 states, 7 states have (on average 10.142857142857142) internal successors, (71), 7 states have internal predecessors, (71), 2 states have call successors, (22), 2 states have call predecessors, (22), 2 states have return successors, (20), 2 states have call predecessors, (20), 2 states have call successors, (20) [2022-12-14 09:01:29,947 INFO L276 IsEmpty]: Start isEmpty. Operand 1217 states and 1928 transitions. [2022-12-14 09:01:29,950 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 89 [2022-12-14 09:01:29,950 INFO L187 NwaCegarLoop]: Found error trace [2022-12-14 09:01:29,950 INFO L195 NwaCegarLoop]: trace histogram [3, 3, 2, 2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-12-14 09:01:29,955 INFO L552 MonitoredProcess]: [MP /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_1f82ca65-6edb-49dc-97e2-5ef2786422ba/bin/utaipan-gh47qXpMRh/z3 -smt2 -in SMTLIB2_COMPLIANT=true (5)] Ended with exit code 0 [2022-12-14 09:01:30,150 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable7,5 /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_1f82ca65-6edb-49dc-97e2-5ef2786422ba/bin/utaipan-gh47qXpMRh/z3 -smt2 -in SMTLIB2_COMPLIANT=true [2022-12-14 09:01:30,152 INFO L420 AbstractCegarLoop]: === Iteration 9 === Targeting outgoingErr0ASSERT_VIOLATIONERROR_FUNCTION === [outgoingErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2022-12-14 09:01:30,152 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2022-12-14 09:01:30,153 INFO L85 PathProgramCache]: Analyzing trace with hash -453214508, now seen corresponding path program 1 times [2022-12-14 09:01:30,153 INFO L118 FreeRefinementEngine]: Executing refinement strategy SIFA_TAIPAN [2022-12-14 09:01:30,154 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [2042965393] [2022-12-14 09:01:30,154 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-12-14 09:01:30,154 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2022-12-14 09:01:30,214 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-12-14 09:01:31,112 INFO L134 CoverageAnalysis]: Checked inductivity of 16 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 16 trivial. 0 not checked. [2022-12-14 09:01:31,113 INFO L136 FreeRefinementEngine]: Strategy SIFA_TAIPAN found an infeasible trace [2022-12-14 09:01:31,113 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [2042965393] [2022-12-14 09:01:31,113 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [2042965393] provided 1 perfect and 0 imperfect interpolant sequences [2022-12-14 09:01:31,113 INFO L184 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2022-12-14 09:01:31,113 INFO L197 FreeRefinementEngine]: Number of different interpolants: perfect sequences [20] imperfect sequences [] total 20 [2022-12-14 09:01:31,113 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [2145393477] [2022-12-14 09:01:31,113 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2022-12-14 09:01:31,113 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 20 states [2022-12-14 09:01:31,113 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy SIFA_TAIPAN [2022-12-14 09:01:31,114 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 20 interpolants. [2022-12-14 09:01:31,114 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=46, Invalid=334, Unknown=0, NotChecked=0, Total=380 [2022-12-14 09:01:31,114 INFO L87 Difference]: Start difference. First operand 1217 states and 1928 transitions. Second operand has 20 states, 14 states have (on average 3.857142857142857) internal successors, (54), 15 states have internal predecessors, (54), 8 states have call successors, (15), 3 states have call predecessors, (15), 3 states have return successors, (13), 7 states have call predecessors, (13), 7 states have call successors, (13) [2022-12-14 09:01:33,189 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-12-14 09:01:33,189 INFO L93 Difference]: Finished difference Result 1344 states and 2118 transitions. [2022-12-14 09:01:33,189 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 22 states. [2022-12-14 09:01:33,189 INFO L78 Accepts]: Start accepts. Automaton has has 20 states, 14 states have (on average 3.857142857142857) internal successors, (54), 15 states have internal predecessors, (54), 8 states have call successors, (15), 3 states have call predecessors, (15), 3 states have return successors, (13), 7 states have call predecessors, (13), 7 states have call successors, (13) Word has length 88 [2022-12-14 09:01:33,190 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2022-12-14 09:01:33,195 INFO L225 Difference]: With dead ends: 1344 [2022-12-14 09:01:33,195 INFO L226 Difference]: Without dead ends: 1274 [2022-12-14 09:01:33,196 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 35 GetRequests, 3 SyntacticMatches, 0 SemanticMatches, 32 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 197 ImplicationChecksByTransitivity, 0.3s TimeCoverageRelationStatistics Valid=159, Invalid=963, Unknown=0, NotChecked=0, Total=1122 [2022-12-14 09:01:33,196 INFO L413 NwaCegarLoop]: 255 mSDtfsCounter, 371 mSDsluCounter, 2912 mSDsCounter, 0 mSdLazyCounter, 1958 mSolverCounterSat, 161 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.7s Time, 0 mProtectedPredicate, 0 mProtectedAction, 386 SdHoareTripleChecker+Valid, 3167 SdHoareTripleChecker+Invalid, 2119 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 161 IncrementalHoareTripleChecker+Valid, 1958 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.8s IncrementalHoareTripleChecker+Time [2022-12-14 09:01:33,196 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [386 Valid, 3167 Invalid, 2119 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [161 Valid, 1958 Invalid, 0 Unknown, 0 Unchecked, 0.8s Time] [2022-12-14 09:01:33,198 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 1274 states. [2022-12-14 09:01:34,080 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 1274 to 1240. [2022-12-14 09:01:34,082 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 1240 states, 995 states have (on average 1.535678391959799) internal successors, (1528), 1008 states have internal predecessors, (1528), 215 states have call successors, (215), 30 states have call predecessors, (215), 29 states have return successors, (214), 204 states have call predecessors, (214), 214 states have call successors, (214) [2022-12-14 09:01:34,085 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 1240 states to 1240 states and 1957 transitions. [2022-12-14 09:01:34,085 INFO L78 Accepts]: Start accepts. Automaton has 1240 states and 1957 transitions. Word has length 88 [2022-12-14 09:01:34,085 INFO L84 Accepts]: Finished accepts. word is rejected. [2022-12-14 09:01:34,085 INFO L495 AbstractCegarLoop]: Abstraction has 1240 states and 1957 transitions. [2022-12-14 09:01:34,085 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 20 states, 14 states have (on average 3.857142857142857) internal successors, (54), 15 states have internal predecessors, (54), 8 states have call successors, (15), 3 states have call predecessors, (15), 3 states have return successors, (13), 7 states have call predecessors, (13), 7 states have call successors, (13) [2022-12-14 09:01:34,085 INFO L276 IsEmpty]: Start isEmpty. Operand 1240 states and 1957 transitions. [2022-12-14 09:01:34,088 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 140 [2022-12-14 09:01:34,088 INFO L187 NwaCegarLoop]: Found error trace [2022-12-14 09:01:34,088 INFO L195 NwaCegarLoop]: trace histogram [4, 3, 3, 3, 3, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-12-14 09:01:34,088 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable8 [2022-12-14 09:01:34,089 INFO L420 AbstractCegarLoop]: === Iteration 10 === Targeting outgoingErr0ASSERT_VIOLATIONERROR_FUNCTION === [outgoingErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2022-12-14 09:01:34,089 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2022-12-14 09:01:34,089 INFO L85 PathProgramCache]: Analyzing trace with hash 1037934150, now seen corresponding path program 1 times [2022-12-14 09:01:34,089 INFO L118 FreeRefinementEngine]: Executing refinement strategy SIFA_TAIPAN [2022-12-14 09:01:34,089 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [69070731] [2022-12-14 09:01:34,089 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-12-14 09:01:34,089 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2022-12-14 09:01:34,116 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-12-14 09:01:34,825 INFO L134 CoverageAnalysis]: Checked inductivity of 54 backedges. 14 proven. 0 refuted. 0 times theorem prover too weak. 40 trivial. 0 not checked. [2022-12-14 09:01:34,826 INFO L136 FreeRefinementEngine]: Strategy SIFA_TAIPAN found an infeasible trace [2022-12-14 09:01:34,826 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [69070731] [2022-12-14 09:01:34,826 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [69070731] provided 1 perfect and 0 imperfect interpolant sequences [2022-12-14 09:01:34,826 INFO L184 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2022-12-14 09:01:34,826 INFO L197 FreeRefinementEngine]: Number of different interpolants: perfect sequences [21] imperfect sequences [] total 21 [2022-12-14 09:01:34,826 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [2053374781] [2022-12-14 09:01:34,827 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2022-12-14 09:01:34,827 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 21 states [2022-12-14 09:01:34,827 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy SIFA_TAIPAN [2022-12-14 09:01:34,828 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 21 interpolants. [2022-12-14 09:01:34,828 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=53, Invalid=367, Unknown=0, NotChecked=0, Total=420 [2022-12-14 09:01:34,829 INFO L87 Difference]: Start difference. First operand 1240 states and 1957 transitions. Second operand has 21 states, 16 states have (on average 4.8125) internal successors, (77), 18 states have internal predecessors, (77), 11 states have call successors, (25), 3 states have call predecessors, (25), 5 states have return successors, (24), 11 states have call predecessors, (24), 11 states have call successors, (24) [2022-12-14 09:01:37,164 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-12-14 09:01:37,164 INFO L93 Difference]: Finished difference Result 1388 states and 2127 transitions. [2022-12-14 09:01:37,164 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 28 states. [2022-12-14 09:01:37,164 INFO L78 Accepts]: Start accepts. Automaton has has 21 states, 16 states have (on average 4.8125) internal successors, (77), 18 states have internal predecessors, (77), 11 states have call successors, (25), 3 states have call predecessors, (25), 5 states have return successors, (24), 11 states have call predecessors, (24), 11 states have call successors, (24) Word has length 139 [2022-12-14 09:01:37,165 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2022-12-14 09:01:37,168 INFO L225 Difference]: With dead ends: 1388 [2022-12-14 09:01:37,168 INFO L226 Difference]: Without dead ends: 1346 [2022-12-14 09:01:37,169 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 46 GetRequests, 4 SyntacticMatches, 0 SemanticMatches, 42 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 332 ImplicationChecksByTransitivity, 0.4s TimeCoverageRelationStatistics Valid=291, Invalid=1601, Unknown=0, NotChecked=0, Total=1892 [2022-12-14 09:01:37,169 INFO L413 NwaCegarLoop]: 197 mSDtfsCounter, 381 mSDsluCounter, 1650 mSDsCounter, 0 mSdLazyCounter, 2602 mSolverCounterSat, 234 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.9s Time, 0 mProtectedPredicate, 0 mProtectedAction, 401 SdHoareTripleChecker+Valid, 1847 SdHoareTripleChecker+Invalid, 2836 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 234 IncrementalHoareTripleChecker+Valid, 2602 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 1.0s IncrementalHoareTripleChecker+Time [2022-12-14 09:01:37,169 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [401 Valid, 1847 Invalid, 2836 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [234 Valid, 2602 Invalid, 0 Unknown, 0 Unchecked, 1.0s Time] [2022-12-14 09:01:37,170 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 1346 states. [2022-12-14 09:01:38,060 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 1346 to 1328. [2022-12-14 09:01:38,062 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 1328 states, 1046 states have (on average 1.5162523900573615) internal successors, (1586), 1060 states have internal predecessors, (1586), 238 states have call successors, (238), 43 states have call predecessors, (238), 43 states have return successors, (238), 226 states have call predecessors, (238), 236 states have call successors, (238) [2022-12-14 09:01:38,065 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 1328 states to 1328 states and 2062 transitions. [2022-12-14 09:01:38,065 INFO L78 Accepts]: Start accepts. Automaton has 1328 states and 2062 transitions. Word has length 139 [2022-12-14 09:01:38,065 INFO L84 Accepts]: Finished accepts. word is rejected. [2022-12-14 09:01:38,065 INFO L495 AbstractCegarLoop]: Abstraction has 1328 states and 2062 transitions. [2022-12-14 09:01:38,065 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 21 states, 16 states have (on average 4.8125) internal successors, (77), 18 states have internal predecessors, (77), 11 states have call successors, (25), 3 states have call predecessors, (25), 5 states have return successors, (24), 11 states have call predecessors, (24), 11 states have call successors, (24) [2022-12-14 09:01:38,065 INFO L276 IsEmpty]: Start isEmpty. Operand 1328 states and 2062 transitions. [2022-12-14 09:01:38,069 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 151 [2022-12-14 09:01:38,069 INFO L187 NwaCegarLoop]: Found error trace [2022-12-14 09:01:38,070 INFO L195 NwaCegarLoop]: trace histogram [4, 3, 3, 3, 3, 3, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-12-14 09:01:38,070 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable9 [2022-12-14 09:01:38,070 INFO L420 AbstractCegarLoop]: === Iteration 11 === Targeting outgoingErr0ASSERT_VIOLATIONERROR_FUNCTION === [outgoingErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2022-12-14 09:01:38,070 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2022-12-14 09:01:38,070 INFO L85 PathProgramCache]: Analyzing trace with hash -880836882, now seen corresponding path program 1 times [2022-12-14 09:01:38,070 INFO L118 FreeRefinementEngine]: Executing refinement strategy SIFA_TAIPAN [2022-12-14 09:01:38,070 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [1998430510] [2022-12-14 09:01:38,071 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-12-14 09:01:38,071 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2022-12-14 09:01:38,100 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-12-14 09:01:38,211 INFO L134 CoverageAnalysis]: Checked inductivity of 58 backedges. 14 proven. 0 refuted. 0 times theorem prover too weak. 44 trivial. 0 not checked. [2022-12-14 09:01:38,211 INFO L136 FreeRefinementEngine]: Strategy SIFA_TAIPAN found an infeasible trace [2022-12-14 09:01:38,211 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [1998430510] [2022-12-14 09:01:38,211 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [1998430510] provided 1 perfect and 0 imperfect interpolant sequences [2022-12-14 09:01:38,211 INFO L184 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2022-12-14 09:01:38,212 INFO L197 FreeRefinementEngine]: Number of different interpolants: perfect sequences [4] imperfect sequences [] total 4 [2022-12-14 09:01:38,212 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [155406864] [2022-12-14 09:01:38,212 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2022-12-14 09:01:38,212 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 4 states [2022-12-14 09:01:38,212 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy SIFA_TAIPAN [2022-12-14 09:01:38,213 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 4 interpolants. [2022-12-14 09:01:38,213 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=5, Invalid=7, Unknown=0, NotChecked=0, Total=12 [2022-12-14 09:01:38,213 INFO L87 Difference]: Start difference. First operand 1328 states and 2062 transitions. Second operand has 4 states, 4 states have (on average 20.25) internal successors, (81), 4 states have internal predecessors, (81), 3 states have call successors, (28), 2 states have call predecessors, (28), 1 states have return successors, (27), 3 states have call predecessors, (27), 3 states have call successors, (27) [2022-12-14 09:01:39,175 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-12-14 09:01:39,175 INFO L93 Difference]: Finished difference Result 1354 states and 2075 transitions. [2022-12-14 09:01:39,176 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 4 states. [2022-12-14 09:01:39,176 INFO L78 Accepts]: Start accepts. Automaton has has 4 states, 4 states have (on average 20.25) internal successors, (81), 4 states have internal predecessors, (81), 3 states have call successors, (28), 2 states have call predecessors, (28), 1 states have return successors, (27), 3 states have call predecessors, (27), 3 states have call successors, (27) Word has length 150 [2022-12-14 09:01:39,176 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2022-12-14 09:01:39,176 INFO L225 Difference]: With dead ends: 1354 [2022-12-14 09:01:39,176 INFO L226 Difference]: Without dead ends: 0 [2022-12-14 09:01:39,177 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 5 GetRequests, 2 SyntacticMatches, 0 SemanticMatches, 3 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 0 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=9, Invalid=11, Unknown=0, NotChecked=0, Total=20 [2022-12-14 09:01:39,178 INFO L413 NwaCegarLoop]: 203 mSDtfsCounter, 191 mSDsluCounter, 202 mSDsCounter, 0 mSdLazyCounter, 56 mSolverCounterSat, 0 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.0s Time, 0 mProtectedPredicate, 0 mProtectedAction, 191 SdHoareTripleChecker+Valid, 405 SdHoareTripleChecker+Invalid, 56 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 0 IncrementalHoareTripleChecker+Valid, 56 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.1s IncrementalHoareTripleChecker+Time [2022-12-14 09:01:39,178 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [191 Valid, 405 Invalid, 56 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [0 Valid, 56 Invalid, 0 Unknown, 0 Unchecked, 0.1s Time] [2022-12-14 09:01:39,178 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 0 states. [2022-12-14 09:01:39,178 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 0 to 0. [2022-12-14 09:01:39,178 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 0 states, 0 states have (on average 0.0) internal successors, (0), 0 states have internal predecessors, (0), 0 states have call successors, (0), 0 states have call predecessors, (0), 0 states have return successors, (0), 0 states have call predecessors, (0), 0 states have call successors, (0) [2022-12-14 09:01:39,178 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 0 states to 0 states and 0 transitions. [2022-12-14 09:01:39,179 INFO L78 Accepts]: Start accepts. Automaton has 0 states and 0 transitions. Word has length 150 [2022-12-14 09:01:39,179 INFO L84 Accepts]: Finished accepts. word is rejected. [2022-12-14 09:01:39,179 INFO L495 AbstractCegarLoop]: Abstraction has 0 states and 0 transitions. [2022-12-14 09:01:39,179 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 4 states, 4 states have (on average 20.25) internal successors, (81), 4 states have internal predecessors, (81), 3 states have call successors, (28), 2 states have call predecessors, (28), 1 states have return successors, (27), 3 states have call predecessors, (27), 3 states have call successors, (27) [2022-12-14 09:01:39,179 INFO L276 IsEmpty]: Start isEmpty. Operand 0 states and 0 transitions. [2022-12-14 09:01:39,179 INFO L282 IsEmpty]: Finished isEmpty. No accepting run. [2022-12-14 09:01:39,181 INFO L805 garLoopResultBuilder]: Registering result SAFE for location outgoingErr0ASSERT_VIOLATIONERROR_FUNCTION (0 of 1 remaining) [2022-12-14 09:01:39,181 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable10 [2022-12-14 09:01:39,182 INFO L343 DoubleDeckerVisitor]: Before removal of dead ends 0 states and 0 transitions. [2022-12-14 09:01:54,252 WARN L233 SmtUtils]: Spent 11.57s on a formula simplification. DAG size of input: 502 DAG size of output: 496 (called from [L 182] de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction.HoareAnnotationComposer.or) [2022-12-14 09:02:00,054 WARN L233 SmtUtils]: Spent 5.80s on a formula simplification. DAG size of input: 490 DAG size of output: 398 (called from [L 182] de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction.HoareAnnotationComposer.or) [2022-12-14 09:02:08,413 WARN L233 SmtUtils]: Spent 8.32s on a formula simplification. DAG size of input: 505 DAG size of output: 499 (called from [L 182] de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction.HoareAnnotationComposer.or) [2022-12-14 09:02:17,462 WARN L233 SmtUtils]: Spent 9.04s on a formula simplification. DAG size of input: 505 DAG size of output: 499 (called from [L 182] de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction.HoareAnnotationComposer.or) [2022-12-14 09:02:24,890 WARN L233 SmtUtils]: Spent 5.80s on a formula simplification. DAG size of input: 490 DAG size of output: 398 (called from [L 182] de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction.HoareAnnotationComposer.or) [2022-12-14 09:02:36,500 WARN L233 SmtUtils]: Spent 11.45s on a formula simplification. DAG size of input: 502 DAG size of output: 496 (called from [L 182] de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction.HoareAnnotationComposer.or) [2022-12-14 09:02:44,835 WARN L233 SmtUtils]: Spent 8.33s on a formula simplification. DAG size of input: 505 DAG size of output: 499 (called from [L 182] de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction.HoareAnnotationComposer.or) [2022-12-14 09:02:51,379 WARN L233 SmtUtils]: Spent 6.51s on a formula simplification. DAG size of input: 490 DAG size of output: 398 (called from [L 182] de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction.HoareAnnotationComposer.or) [2022-12-14 09:03:02,252 WARN L233 SmtUtils]: Spent 8.30s on a formula simplification. DAG size of input: 505 DAG size of output: 499 (called from [L 182] de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction.HoareAnnotationComposer.or) [2022-12-14 09:03:12,398 WARN L233 SmtUtils]: Spent 8.32s on a formula simplification. DAG size of input: 505 DAG size of output: 499 (called from [L 182] de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction.HoareAnnotationComposer.or) [2022-12-14 09:03:18,253 WARN L233 SmtUtils]: Spent 5.81s on a formula simplification. DAG size of input: 490 DAG size of output: 398 (called from [L 182] de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction.HoareAnnotationComposer.or) [2022-12-14 09:03:29,074 WARN L233 SmtUtils]: Spent 10.82s on a formula simplification. DAG size of input: 502 DAG size of output: 496 (called from [L 182] de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction.HoareAnnotationComposer.or) [2022-12-14 09:03:35,277 WARN L233 SmtUtils]: Spent 6.17s on a formula simplification. DAG size of input: 490 DAG size of output: 398 (called from [L 182] de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction.HoareAnnotationComposer.or) [2022-12-14 09:03:41,851 WARN L233 SmtUtils]: Spent 6.11s on a formula simplification. DAG size of input: 490 DAG size of output: 398 (called from [L 182] de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction.HoareAnnotationComposer.or) [2022-12-14 09:03:53,903 WARN L233 SmtUtils]: Spent 6.70s on a formula simplification. DAG size of input: 699 DAG size of output: 13 (called from [L 149] de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction.HoareAnnotationComposer.combineInter) [2022-12-14 09:04:34,626 INFO L895 garLoopResultBuilder]: At program point L258-1(line 258) the Hoare annotation is: (or (not (= ~bob~0 1)) (not (= |outgoing_#in~msg#1| 1)) (let ((.cse0 (not (= ~__ste_client_privateKey0~0 0)))) (and (= |outgoing_outgoing__wrappee__Keys_~msg#1| 1) (or (= ~__ste_email_isSigned0~0 0) .cse0) (= |outgoing___utac_acc__SignForward_spec__1_~msg#1| 1) (= |outgoing_outgoing__wrappee__Keys_~client#1| 1) (= |outgoing_outgoing__wrappee__Encrypt_~msg#1| 1) (= |outgoing_outgoing__wrappee__Encrypt_~client#1| 1) (= |outgoing___utac_acc__SignForward_spec__1_~client#1| 1) (or .cse0 (= |outgoing___utac_acc__SignForward_spec__1_~tmp___0~9#1| 0)))) (not (= |outgoing_#in~client#1| 1)) (not (= |old(~__ste_email_isEncrypted0~0)| 0)) (not (= |old(~__ste_email_isSigned0~0)| 0)) (not (= ~queue_empty~0 1))) [2022-12-14 09:04:34,626 INFO L895 garLoopResultBuilder]: At program point L382(line 382) the Hoare annotation is: (or (not (= ~bob~0 1)) (not (= |outgoing_#in~msg#1| 1)) (not (= |outgoing_#in~client#1| 1)) (not (= |old(~__ste_email_isEncrypted0~0)| 0)) (not (= |old(~__ste_email_isSigned0~0)| 0)) (not (= ~queue_empty~0 1)) (and (= ~__ste_email_isSigned0~0 0) (= |outgoing_sign_~client#1| 1) (= |outgoing_~msg#1| 1) (= |outgoing_~client#1| 1) (= ~__ste_email_isEncrypted0~0 0))) [2022-12-14 09:04:34,626 INFO L895 garLoopResultBuilder]: At program point L382-1(line 382) the Hoare annotation is: (or (and (= ~__ste_email_isSigned0~0 0) (= |outgoing_sign_~client#1| 1) (= |outgoing_~msg#1| 1) (= ~__ste_client_privateKey0~0 |outgoing_sign_#t~ret18#1|) (= |outgoing_~client#1| 1) (= ~__ste_email_isEncrypted0~0 0)) (not (= ~bob~0 1)) (not (= |outgoing_#in~msg#1| 1)) (not (= |outgoing_#in~client#1| 1)) (not (= |old(~__ste_email_isEncrypted0~0)| 0)) (not (= |old(~__ste_email_isSigned0~0)| 0)) (not (= ~queue_empty~0 1))) [2022-12-14 09:04:34,627 INFO L895 garLoopResultBuilder]: At program point L176(line 176) the Hoare annotation is: (or (not (= ~bob~0 1)) (not (= |outgoing_#in~msg#1| 1)) (not (= |outgoing_#in~client#1| 1)) (and (or (= ~__ste_email_isSigned0~0 0) (not (= ~__ste_client_privateKey0~0 0))) (= |outgoing_#in~msg#1| |outgoing_~msg#1|) (= |outgoing_outgoing__wrappee__Encrypt_~msg#1| 1) (= |outgoing_outgoing__wrappee__Encrypt_~client#1| 1) (= ~__ste_email_isEncrypted0~0 0)) (not (= |old(~__ste_email_isEncrypted0~0)| 0)) (not (= |old(~__ste_email_isSigned0~0)| 0)) (not (= ~queue_empty~0 1))) [2022-12-14 09:04:34,627 INFO L899 garLoopResultBuilder]: For program point L176-1(line 176) no Hoare annotation was computed. [2022-12-14 09:04:34,627 INFO L895 garLoopResultBuilder]: At program point L424(line 424) the Hoare annotation is: (or (not (= ~bob~0 1)) (not (= |outgoing_#in~msg#1| 1)) (let ((.cse0 (not (= ~__ste_client_privateKey0~0 0)))) (and (= |outgoing_outgoing__wrappee__Keys_~msg#1| 1) (or (= ~__ste_email_isSigned0~0 0) .cse0) (= |outgoing___utac_acc__SignForward_spec__1_~msg#1| 1) (= |outgoing_outgoing__wrappee__Keys_~client#1| 1) (= |outgoing_outgoing__wrappee__Encrypt_~msg#1| 1) (= |outgoing_outgoing__wrappee__Encrypt_~client#1| 1) (= |outgoing___utac_acc__SignForward_spec__1_~client#1| 1) (or .cse0 (= |outgoing___utac_acc__SignForward_spec__1_~tmp___0~9#1| 0)))) (not (= |outgoing_#in~client#1| 1)) (not (= |old(~__ste_email_isEncrypted0~0)| 0)) (not (= |old(~__ste_email_isSigned0~0)| 0)) (not (= ~queue_empty~0 1))) [2022-12-14 09:04:34,627 INFO L899 garLoopResultBuilder]: For program point L424-1(line 424) no Hoare annotation was computed. [2022-12-14 09:04:34,627 INFO L895 garLoopResultBuilder]: At program point L160(line 160) the Hoare annotation is: (or (not (= ~bob~0 1)) (not (= |outgoing_#in~msg#1| 1)) (not (= |outgoing_#in~client#1| 1)) (and (= |outgoing_outgoing__wrappee__Keys_~msg#1| 1) (or (= ~__ste_email_isSigned0~0 0) (not (= ~__ste_client_privateKey0~0 0))) (= |outgoing_outgoing__wrappee__Keys_~client#1| 1) (= |outgoing_outgoing__wrappee__Encrypt_~msg#1| 1) (= |outgoing_outgoing__wrappee__Encrypt_~client#1| 1)) (not (= |old(~__ste_email_isEncrypted0~0)| 0)) (not (= |old(~__ste_email_isSigned0~0)| 0)) (not (= ~queue_empty~0 1))) [2022-12-14 09:04:34,627 INFO L899 garLoopResultBuilder]: For program point L160-1(line 160) no Hoare annotation was computed. [2022-12-14 09:04:34,628 INFO L899 garLoopResultBuilder]: For program point L251(lines 251 266) no Hoare annotation was computed. [2022-12-14 09:04:34,628 INFO L895 garLoopResultBuilder]: At program point L408(line 408) the Hoare annotation is: (or (not (= ~bob~0 1)) (not (= |outgoing_#in~msg#1| 1)) (let ((.cse0 (not (= ~__ste_client_privateKey0~0 0)))) (and (= |outgoing_outgoing__wrappee__Keys_~msg#1| 1) (or (= ~__ste_email_isSigned0~0 0) .cse0) (= |outgoing___utac_acc__SignForward_spec__1_~msg#1| 1) (= |outgoing_outgoing__wrappee__Keys_~client#1| 1) (= |outgoing_outgoing__wrappee__Encrypt_~msg#1| 1) (= |outgoing_outgoing__wrappee__Encrypt_~client#1| 1) (= |outgoing___utac_acc__SignForward_spec__1_~client#1| 1) (or .cse0 (= |outgoing___utac_acc__SignForward_spec__1_~tmp___0~9#1| 0)))) (not (= |outgoing_#in~client#1| 1)) (not (= |old(~__ste_email_isEncrypted0~0)| 0)) (not (= |old(~__ste_email_isSigned0~0)| 0)) (not (= ~queue_empty~0 1))) [2022-12-14 09:04:34,628 INFO L899 garLoopResultBuilder]: For program point L408-1(line 408) no Hoare annotation was computed. [2022-12-14 09:04:34,628 INFO L895 garLoopResultBuilder]: At program point L2580(line 2580) the Hoare annotation is: (or (and (= |outgoing_outgoing__wrappee__Keys_~msg#1| 1) (= |outgoing___utac_acc__SignForward_spec__1_~msg#1| 1) (= |outgoing_outgoing__wrappee__Keys_~client#1| 1) (not (= ~__ste_client_privateKey0~0 0)) (= |outgoing_outgoing__wrappee__Encrypt_~msg#1| 1) (= |outgoing_outgoing__wrappee__Encrypt_~client#1| 1) (= |outgoing___utac_acc__SignForward_spec__1_~client#1| 1)) (not (= ~bob~0 1)) (not (= |outgoing_#in~msg#1| 1)) (not (= |outgoing_#in~client#1| 1)) (not (= |old(~__ste_email_isEncrypted0~0)| 0)) (not (= |old(~__ste_email_isSigned0~0)| 0)) (not (= ~queue_empty~0 1))) [2022-12-14 09:04:34,628 INFO L899 garLoopResultBuilder]: For program point L2580-1(line 2580) no Hoare annotation was computed. [2022-12-14 09:04:34,628 INFO L895 garLoopResultBuilder]: At program point L450(line 450) the Hoare annotation is: (or (not (= ~bob~0 1)) (not (= |outgoing_#in~msg#1| 1)) (not (= |outgoing_#in~client#1| 1)) (not (= |old(~__ste_email_isEncrypted0~0)| 0)) (not (= |old(~__ste_email_isSigned0~0)| 0)) (not (= ~queue_empty~0 1))) [2022-12-14 09:04:34,628 INFO L895 garLoopResultBuilder]: At program point L244(line 244) the Hoare annotation is: (or (not (= ~bob~0 1)) (not (= |outgoing_#in~msg#1| 1)) (let ((.cse0 (not (= ~__ste_client_privateKey0~0 0)))) (and (= |outgoing_outgoing__wrappee__Keys_~msg#1| 1) (or (= ~__ste_email_isSigned0~0 0) .cse0) (= |outgoing___utac_acc__SignForward_spec__1_~msg#1| 1) (= |outgoing_outgoing__wrappee__Keys_~client#1| 1) (= |outgoing_outgoing__wrappee__Encrypt_~msg#1| 1) (= |outgoing_outgoing__wrappee__Encrypt_~client#1| 1) (= |outgoing___utac_acc__SignForward_spec__1_~client#1| 1) (or .cse0 (= |outgoing___utac_acc__SignForward_spec__1_~tmp___0~9#1| 0)))) (not (= |outgoing_#in~client#1| 1)) (not (= |old(~__ste_email_isEncrypted0~0)| 0)) (not (= |old(~__ste_email_isSigned0~0)| 0)) (not (= ~queue_empty~0 1))) [2022-12-14 09:04:34,629 INFO L899 garLoopResultBuilder]: For program point L244-1(line 244) no Hoare annotation was computed. [2022-12-14 09:04:34,629 INFO L895 garLoopResultBuilder]: At program point $Ultimate##0(lines 193 203) the Hoare annotation is: (or (not (= ~bob~0 1)) (not (= |outgoing_#in~msg#1| 1)) (and (= ~__ste_email_isSigned0~0 0) (= ~__ste_email_isEncrypted0~0 0)) (not (= |outgoing_#in~client#1| 1)) (not (= |old(~__ste_email_isEncrypted0~0)| 0)) (not (= |old(~__ste_email_isSigned0~0)| 0)) (not (= ~queue_empty~0 1))) [2022-12-14 09:04:34,629 INFO L895 garLoopResultBuilder]: At program point L253(line 253) the Hoare annotation is: (or (not (= ~bob~0 1)) (not (= |outgoing_#in~msg#1| 1)) (let ((.cse0 (not (= ~__ste_client_privateKey0~0 0)))) (and (= |outgoing_outgoing__wrappee__Keys_~msg#1| 1) (or (= ~__ste_email_isSigned0~0 0) .cse0) (= |outgoing___utac_acc__SignForward_spec__1_~msg#1| 1) (= |outgoing_outgoing__wrappee__Keys_~client#1| 1) (= |outgoing_outgoing__wrappee__Encrypt_~msg#1| 1) (= |outgoing_outgoing__wrappee__Encrypt_~client#1| 1) (= |outgoing___utac_acc__SignForward_spec__1_~client#1| 1) (or .cse0 (= |outgoing___utac_acc__SignForward_spec__1_~tmp___0~9#1| 0)))) (not (= |outgoing_#in~client#1| 1)) (not (= |old(~__ste_email_isEncrypted0~0)| 0)) (not (= |old(~__ste_email_isSigned0~0)| 0)) (not (= ~queue_empty~0 1))) [2022-12-14 09:04:34,629 INFO L899 garLoopResultBuilder]: For program point L253-1(line 253) no Hoare annotation was computed. [2022-12-14 09:04:34,629 INFO L899 garLoopResultBuilder]: For program point L410(lines 410 421) no Hoare annotation was computed. [2022-12-14 09:04:34,629 INFO L899 garLoopResultBuilder]: For program point L2582(lines 2582 2588) no Hoare annotation was computed. [2022-12-14 09:04:34,629 INFO L899 garLoopResultBuilder]: For program point L179(lines 179 186) no Hoare annotation was computed. [2022-12-14 09:04:34,629 INFO L895 garLoopResultBuilder]: At program point L179-1(lines 179 186) the Hoare annotation is: (or (not (= ~bob~0 1)) (and (or (= ~__ste_email_isSigned0~0 0) (not (= ~__ste_client_privateKey0~0 0))) (= |outgoing_outgoing__wrappee__Encrypt_~msg#1| 1) (= |outgoing_outgoing__wrappee__Encrypt_~client#1| 1)) (not (= |outgoing_#in~msg#1| 1)) (not (= |outgoing_#in~client#1| 1)) (not (= |old(~__ste_email_isEncrypted0~0)| 0)) (not (= |old(~__ste_email_isSigned0~0)| 0)) (not (= ~queue_empty~0 1))) [2022-12-14 09:04:34,630 INFO L899 garLoopResultBuilder]: For program point L427(lines 427 441) no Hoare annotation was computed. [2022-12-14 09:04:34,630 INFO L895 garLoopResultBuilder]: At program point L427-1(lines 397 444) the Hoare annotation is: (or (not (= ~bob~0 1)) (not (= |outgoing_#in~msg#1| 1)) (let ((.cse0 (not (= ~__ste_client_privateKey0~0 0)))) (and (= |outgoing_outgoing__wrappee__Keys_~msg#1| 1) (or (= ~__ste_email_isSigned0~0 0) .cse0) (= |outgoing___utac_acc__SignForward_spec__1_~msg#1| 1) (= |outgoing_outgoing__wrappee__Keys_~client#1| 1) (= |outgoing_outgoing__wrappee__Encrypt_~msg#1| 1) (= |outgoing_outgoing__wrappee__Encrypt_~client#1| 1) (= |outgoing___utac_acc__SignForward_spec__1_~client#1| 1) (or .cse0 (= |outgoing___utac_acc__SignForward_spec__1_~tmp___0~9#1| 0)))) (not (= |outgoing_#in~client#1| 1)) (not (= |old(~__ste_email_isEncrypted0~0)| 0)) (not (= |old(~__ste_email_isSigned0~0)| 0)) (not (= ~queue_empty~0 1))) [2022-12-14 09:04:34,630 INFO L895 garLoopResultBuilder]: At program point L254(line 254) the Hoare annotation is: (or (not (= ~bob~0 1)) (not (= |outgoing_#in~msg#1| 1)) (let ((.cse0 (not (= ~__ste_client_privateKey0~0 0)))) (and (= |outgoing_outgoing__wrappee__Keys_~msg#1| 1) (or (= ~__ste_email_isSigned0~0 0) .cse0) (= |outgoing___utac_acc__SignForward_spec__1_~msg#1| 1) (= |outgoing_outgoing__wrappee__Keys_~client#1| 1) (= |outgoing_outgoing__wrappee__Encrypt_~msg#1| 1) (= |outgoing_outgoing__wrappee__Encrypt_~client#1| 1) (= |outgoing___utac_acc__SignForward_spec__1_~client#1| 1) (or .cse0 (= |outgoing___utac_acc__SignForward_spec__1_~tmp___0~9#1| 0)))) (not (= |outgoing_#in~client#1| 1)) (not (= |old(~__ste_email_isEncrypted0~0)| 0)) (not (= |old(~__ste_email_isSigned0~0)| 0)) (not (= ~queue_empty~0 1))) [2022-12-14 09:04:34,630 INFO L899 garLoopResultBuilder]: For program point L254-1(line 254) no Hoare annotation was computed. [2022-12-14 09:04:34,630 INFO L895 garLoopResultBuilder]: At program point L412(line 412) the Hoare annotation is: (or (not (= ~bob~0 1)) (not (= |outgoing_#in~msg#1| 1)) (let ((.cse0 (not (= ~__ste_client_privateKey0~0 0)))) (and (= |outgoing_outgoing__wrappee__Keys_~msg#1| 1) (or (= ~__ste_email_isSigned0~0 0) .cse0) (= |outgoing___utac_acc__SignForward_spec__1_~msg#1| 1) (= |outgoing_outgoing__wrappee__Keys_~client#1| 1) (= |outgoing_outgoing__wrappee__Encrypt_~msg#1| 1) (= |outgoing_outgoing__wrappee__Encrypt_~client#1| 1) (= |outgoing___utac_acc__SignForward_spec__1_~client#1| 1) (or .cse0 (= |outgoing___utac_acc__SignForward_spec__1_~tmp___0~9#1| 0)))) (not (= |outgoing_#in~client#1| 1)) (not (= |old(~__ste_email_isEncrypted0~0)| 0)) (not (= |old(~__ste_email_isSigned0~0)| 0)) (not (= ~queue_empty~0 1))) [2022-12-14 09:04:34,630 INFO L899 garLoopResultBuilder]: For program point L412-1(line 412) no Hoare annotation was computed. [2022-12-14 09:04:34,630 INFO L899 garLoopResultBuilder]: For program point L247(lines 247 269) no Hoare annotation was computed. [2022-12-14 09:04:34,630 INFO L899 garLoopResultBuilder]: For program point L247-1(lines 247 269) no Hoare annotation was computed. [2022-12-14 09:04:34,631 INFO L895 garLoopResultBuilder]: At program point L181(line 181) the Hoare annotation is: (or (not (= ~bob~0 1)) (not (= |outgoing_#in~msg#1| 1)) (not (= |outgoing_#in~client#1| 1)) (and (or (= ~__ste_email_isSigned0~0 0) (not (= ~__ste_client_privateKey0~0 0))) (= |outgoing_#in~msg#1| |outgoing_~msg#1|) (= |outgoing_outgoing__wrappee__Encrypt_~msg#1| 1) (= |outgoing_outgoing__wrappee__Encrypt_~client#1| 1) (= ~__ste_email_isEncrypted0~0 0)) (not (= |old(~__ste_email_isEncrypted0~0)| 0)) (not (= |old(~__ste_email_isSigned0~0)| 0)) (not (= ~queue_empty~0 1))) [2022-12-14 09:04:34,631 INFO L895 garLoopResultBuilder]: At program point L181-1(line 181) the Hoare annotation is: (or (not (= ~bob~0 1)) (not (= |outgoing_#in~msg#1| 1)) (not (= |outgoing_#in~client#1| 1)) (and (or (= ~__ste_email_isSigned0~0 0) (not (= ~__ste_client_privateKey0~0 0))) (= |outgoing_#in~msg#1| |outgoing_~msg#1|) (= |outgoing_outgoing__wrappee__Encrypt_~msg#1| 1) (= |outgoing_outgoing__wrappee__Encrypt_~client#1| 1) (= ~__ste_email_isEncrypted0~0 0)) (not (= |old(~__ste_email_isEncrypted0~0)| 0)) (not (= |old(~__ste_email_isSigned0~0)| 0)) (not (= ~queue_empty~0 1))) [2022-12-14 09:04:34,631 INFO L895 garLoopResultBuilder]: At program point L148(line 148) the Hoare annotation is: (or (not (= ~bob~0 1)) (not (= |outgoing_#in~msg#1| 1)) (let ((.cse0 (not (= ~__ste_client_privateKey0~0 0)))) (and (= |outgoing_outgoing__wrappee__Keys_~msg#1| 1) (or (= ~__ste_email_isSigned0~0 0) .cse0) (= |outgoing___utac_acc__SignForward_spec__1_~msg#1| 1) (= |outgoing_outgoing__wrappee__Keys_~client#1| 1) (= |outgoing_outgoing__wrappee__Encrypt_~msg#1| 1) (= |outgoing_outgoing__wrappee__Encrypt_~client#1| 1) (= |outgoing___utac_acc__SignForward_spec__1_~client#1| 1) (or .cse0 (= |outgoing___utac_acc__SignForward_spec__1_~tmp___0~9#1| 0)))) (not (= |outgoing_#in~client#1| 1)) (not (= |old(~__ste_email_isEncrypted0~0)| 0)) (not (= |old(~__ste_email_isSigned0~0)| 0)) (not (= ~queue_empty~0 1))) [2022-12-14 09:04:34,631 INFO L899 garLoopResultBuilder]: For program point L148-1(line 148) no Hoare annotation was computed. [2022-12-14 09:04:34,631 INFO L895 garLoopResultBuilder]: At program point L2576(line 2576) the Hoare annotation is: (or (not (= ~bob~0 1)) (not (= |outgoing_#in~msg#1| 1)) (not (= |outgoing_#in~client#1| 1)) (not (= |old(~__ste_email_isEncrypted0~0)| 0)) (not (= |old(~__ste_email_isSigned0~0)| 0)) (and (= |outgoing_outgoing__wrappee__Keys_~msg#1| 1) (or (= ~__ste_email_isSigned0~0 0) (not (= ~__ste_client_privateKey0~0 0))) (= |outgoing___utac_acc__SignForward_spec__1_~msg#1| 1) (= |outgoing_outgoing__wrappee__Keys_~client#1| 1) (= |outgoing_outgoing__wrappee__Encrypt_~msg#1| 1) (= |outgoing_outgoing__wrappee__Encrypt_~client#1| 1) (= |outgoing___utac_acc__SignForward_spec__1_~client#1| 1)) (not (= ~queue_empty~0 1))) [2022-12-14 09:04:34,631 INFO L899 garLoopResultBuilder]: For program point L2576-1(line 2576) no Hoare annotation was computed. [2022-12-14 09:04:34,632 INFO L895 garLoopResultBuilder]: At program point L429(line 429) the Hoare annotation is: (or (not (= ~bob~0 1)) (not (= |outgoing_#in~msg#1| 1)) (let ((.cse0 (not (= ~__ste_client_privateKey0~0 0)))) (and (= |outgoing_outgoing__wrappee__Keys_~msg#1| 1) (or (= ~__ste_email_isSigned0~0 0) .cse0) (= |outgoing___utac_acc__SignForward_spec__1_~msg#1| 1) (= |outgoing_outgoing__wrappee__Keys_~client#1| 1) (= |outgoing_outgoing__wrappee__Encrypt_~msg#1| 1) (= |outgoing_outgoing__wrappee__Encrypt_~client#1| 1) (= |outgoing___utac_acc__SignForward_spec__1_~client#1| 1) (or .cse0 (= |outgoing___utac_acc__SignForward_spec__1_~tmp___0~9#1| 0)))) (not (= |outgoing_#in~client#1| 1)) (not (= |old(~__ste_email_isEncrypted0~0)| 0)) (not (= |old(~__ste_email_isSigned0~0)| 0)) (not (= ~queue_empty~0 1))) [2022-12-14 09:04:34,632 INFO L899 garLoopResultBuilder]: For program point L429-1(line 429) no Hoare annotation was computed. [2022-12-14 09:04:34,632 INFO L899 garLoopResultBuilder]: For program point L256(lines 256 263) no Hoare annotation was computed. [2022-12-14 09:04:34,632 INFO L899 garLoopResultBuilder]: For program point outgoingErr0ASSERT_VIOLATIONERROR_FUNCTION(line 450) no Hoare annotation was computed. [2022-12-14 09:04:34,632 INFO L895 garLoopResultBuilder]: At program point L174(line 174) the Hoare annotation is: (or (not (= ~bob~0 1)) (not (= |outgoing_#in~msg#1| 1)) (not (= |outgoing_#in~client#1| 1)) (and (or (= ~__ste_email_isSigned0~0 0) (not (= ~__ste_client_privateKey0~0 0))) (= |outgoing_#in~msg#1| |outgoing_~msg#1|) (= |outgoing_outgoing__wrappee__Encrypt_~msg#1| 1) (= |outgoing_outgoing__wrappee__Encrypt_~client#1| 1) (= ~__ste_email_isEncrypted0~0 0)) (not (= |old(~__ste_email_isEncrypted0~0)| 0)) (not (= |old(~__ste_email_isSigned0~0)| 0)) (not (= ~queue_empty~0 1))) [2022-12-14 09:04:34,632 INFO L895 garLoopResultBuilder]: At program point L430(line 430) the Hoare annotation is: (or (not (= ~bob~0 1)) (not (= |outgoing_#in~msg#1| 1)) (let ((.cse0 (not (= ~__ste_client_privateKey0~0 0)))) (and (= |outgoing_outgoing__wrappee__Keys_~msg#1| 1) (or (= ~__ste_email_isSigned0~0 0) .cse0) (= |outgoing___utac_acc__SignForward_spec__1_~msg#1| 1) (= |outgoing_outgoing__wrappee__Keys_~client#1| 1) (= |outgoing_outgoing__wrappee__Encrypt_~msg#1| 1) (= |outgoing_outgoing__wrappee__Encrypt_~client#1| 1) (= |outgoing___utac_acc__SignForward_spec__1_~client#1| 1) (or .cse0 (= |outgoing___utac_acc__SignForward_spec__1_~tmp___0~9#1| 0)))) (not (= |outgoing_#in~client#1| 1)) (not (= |old(~__ste_email_isEncrypted0~0)| 0)) (not (= |old(~__ste_email_isSigned0~0)| 0)) (not (= ~queue_empty~0 1))) [2022-12-14 09:04:34,632 INFO L899 garLoopResultBuilder]: For program point L174-1(line 174) no Hoare annotation was computed. [2022-12-14 09:04:34,633 INFO L895 garLoopResultBuilder]: At program point L430-1(line 430) the Hoare annotation is: (or (not (= ~bob~0 1)) (not (= |outgoing_#in~msg#1| 1)) (let ((.cse0 (not (= ~__ste_client_privateKey0~0 0)))) (and (= |outgoing_outgoing__wrappee__Keys_~msg#1| 1) (or (= ~__ste_email_isSigned0~0 0) .cse0) (= |outgoing___utac_acc__SignForward_spec__1_~msg#1| 1) (= |outgoing_outgoing__wrappee__Keys_~client#1| 1) (= |outgoing_outgoing__wrappee__Encrypt_~msg#1| 1) (= |outgoing_outgoing__wrappee__Encrypt_~client#1| 1) (= |outgoing___utac_acc__SignForward_spec__1_~client#1| 1) (or .cse0 (= |outgoing___utac_acc__SignForward_spec__1_~tmp___0~9#1| 0)))) (not (= |outgoing_#in~client#1| 1)) (not (= |old(~__ste_email_isEncrypted0~0)| 0)) (not (= |old(~__ste_email_isSigned0~0)| 0)) (not (= ~queue_empty~0 1))) [2022-12-14 09:04:34,633 INFO L899 garLoopResultBuilder]: For program point L414(lines 414 418) no Hoare annotation was computed. [2022-12-14 09:04:34,633 INFO L895 garLoopResultBuilder]: At program point L414-1(lines 410 421) the Hoare annotation is: (or (not (= ~bob~0 1)) (not (= |outgoing_#in~msg#1| 1)) (let ((.cse0 (not (= ~__ste_client_privateKey0~0 0)))) (and (= |outgoing_outgoing__wrappee__Keys_~msg#1| 1) (or (= ~__ste_email_isSigned0~0 0) .cse0) (= |outgoing___utac_acc__SignForward_spec__1_~msg#1| 1) (= |outgoing_outgoing__wrappee__Keys_~client#1| 1) (= |outgoing_outgoing__wrappee__Encrypt_~msg#1| 1) (= |outgoing_outgoing__wrappee__Encrypt_~client#1| 1) (= |outgoing___utac_acc__SignForward_spec__1_~client#1| 1) (or .cse0 (= |outgoing___utac_acc__SignForward_spec__1_~tmp___0~9#1| 0)))) (not (= |outgoing_#in~client#1| 1)) (not (= |old(~__ste_email_isEncrypted0~0)| 0)) (not (= |old(~__ste_email_isSigned0~0)| 0)) (not (= ~queue_empty~0 1))) [2022-12-14 09:04:34,633 INFO L895 garLoopResultBuilder]: At program point L249(line 249) the Hoare annotation is: (or (not (= ~bob~0 1)) (not (= |outgoing_#in~msg#1| 1)) (let ((.cse0 (not (= ~__ste_client_privateKey0~0 0)))) (and (= |outgoing_outgoing__wrappee__Keys_~msg#1| 1) (or (= ~__ste_email_isSigned0~0 0) .cse0) (= |outgoing___utac_acc__SignForward_spec__1_~msg#1| 1) (= |outgoing_outgoing__wrappee__Keys_~client#1| 1) (= |outgoing_outgoing__wrappee__Encrypt_~msg#1| 1) (= |outgoing_outgoing__wrappee__Encrypt_~client#1| 1) (= |outgoing___utac_acc__SignForward_spec__1_~client#1| 1) (or .cse0 (= |outgoing___utac_acc__SignForward_spec__1_~tmp___0~9#1| 0)))) (not (= |outgoing_#in~client#1| 1)) (not (= |old(~__ste_email_isEncrypted0~0)| 0)) (not (= |old(~__ste_email_isSigned0~0)| 0)) (not (= ~queue_empty~0 1))) [2022-12-14 09:04:34,633 INFO L899 garLoopResultBuilder]: For program point L249-1(line 249) no Hoare annotation was computed. [2022-12-14 09:04:34,633 INFO L899 garLoopResultBuilder]: For program point outgoingEXIT(lines 193 203) no Hoare annotation was computed. [2022-12-14 09:04:34,633 INFO L899 garLoopResultBuilder]: For program point L2578(lines 2578 2591) no Hoare annotation was computed. [2022-12-14 09:04:34,634 INFO L895 garLoopResultBuilder]: At program point L2578-1(lines 2569 2594) the Hoare annotation is: (or (not (= ~bob~0 1)) (not (= |outgoing_#in~msg#1| 1)) (let ((.cse0 (not (= ~__ste_client_privateKey0~0 0)))) (and (= |outgoing_outgoing__wrappee__Keys_~msg#1| 1) (or (= ~__ste_email_isSigned0~0 0) .cse0) (= |outgoing___utac_acc__SignForward_spec__1_~msg#1| 1) (= |outgoing_outgoing__wrappee__Keys_~client#1| 1) (= |outgoing_outgoing__wrappee__Encrypt_~msg#1| 1) (= |outgoing_outgoing__wrappee__Encrypt_~client#1| 1) (= |outgoing___utac_acc__SignForward_spec__1_~client#1| 1) (or .cse0 (= |outgoing___utac_acc__SignForward_spec__1_~tmp___0~9#1| 0)))) (not (= |outgoing_#in~client#1| 1)) (not (= |old(~__ste_email_isEncrypted0~0)| 0)) (not (= |old(~__ste_email_isSigned0~0)| 0)) (not (= ~queue_empty~0 1))) [2022-12-14 09:04:34,634 INFO L899 garLoopResultBuilder]: For program point L423(line 423) no Hoare annotation was computed. [2022-12-14 09:04:34,634 INFO L895 garLoopResultBuilder]: At program point L258(line 258) the Hoare annotation is: (or (not (= ~bob~0 1)) (not (= |outgoing_#in~msg#1| 1)) (let ((.cse0 (not (= ~__ste_client_privateKey0~0 0)))) (and (= |outgoing_outgoing__wrappee__Keys_~msg#1| 1) (or (= ~__ste_email_isSigned0~0 0) .cse0) (= |outgoing___utac_acc__SignForward_spec__1_~msg#1| 1) (= |outgoing_outgoing__wrappee__Keys_~client#1| 1) (= |outgoing_outgoing__wrappee__Encrypt_~msg#1| 1) (= |outgoing_outgoing__wrappee__Encrypt_~client#1| 1) (= |outgoing___utac_acc__SignForward_spec__1_~client#1| 1) (or .cse0 (= |outgoing___utac_acc__SignForward_spec__1_~tmp___0~9#1| 0)))) (not (= |outgoing_#in~client#1| 1)) (not (= |old(~__ste_email_isEncrypted0~0)| 0)) (not (= |old(~__ste_email_isSigned0~0)| 0)) (not (= ~queue_empty~0 1))) [2022-12-14 09:04:34,634 INFO L899 garLoopResultBuilder]: For program point isSignedEXIT(lines 762 780) no Hoare annotation was computed. [2022-12-14 09:04:34,634 INFO L902 garLoopResultBuilder]: At program point $Ultimate##0(lines 762 780) the Hoare annotation is: true [2022-12-14 09:04:34,634 INFO L899 garLoopResultBuilder]: For program point isKeyPairValidEXIT(lines 341 365) no Hoare annotation was computed. [2022-12-14 09:04:34,634 INFO L902 garLoopResultBuilder]: At program point $Ultimate##0(lines 341 365) the Hoare annotation is: true [2022-12-14 09:04:34,636 INFO L895 garLoopResultBuilder]: At program point $Ultimate##0(lines 1779 1803) the Hoare annotation is: (or (not (= ~__ste_Client_AddressBook1_Address2~0 0)) (and (= |old(~__ste_ClientKeyring_size1~0)| ~__ste_ClientKeyring_size1~0) (= |old(~__ste_ClientKeyring_size2~0)| ~__ste_ClientKeyring_size2~0) (= |old(~__ste_ClientKeyring_size0~0)| ~__ste_ClientKeyring_size0~0)) (not (= ~__ste_email_from0~0 0)) (not (<= 0 ~__ste_Client_Keyring0_PublicKey1~0)) (not (= ~__ste_client_autoResponse2~0 0)) (not (= ~__ste_client_name2~0.base 0)) (not (= ~__ste_Client_AddressBook1_Alias1~0 0)) (not (= ~rjh~0 2)) (not (<= ~__ste_client_privateKey2~0 789)) (not (= ~__ste_ClientAddressBook_size1~0 0)) (not (= 0 ~__ste_Client_AddressBook0_Address0~0)) (not (= |#NULL.offset| 0)) (not (= ~__ste_Client_counter~0 0)) (not (<= 0 |old(~__ste_ClientKeyring_size0~0)|)) (not (= 0 ~__ste_Client_AddressBook0_Address1~0)) (not (= ~bob~0 1)) (not (= ~queued_message~0 0)) (not (<= 0 ~__ste_Client_Keyring0_User0~0)) (not (= ~__ste_client_name2~0.offset 0)) (not (= ~__ste_ClientAddressBook_size2~0 0)) (not (= ~__SELECTED_FEATURE_AddressBook~0 0)) (not (= ~__ste_Client_AddressBook0_Alias2~0 0)) (not (= ~__ste_email_id0~0 0)) (not (= ~__SELECTED_FEATURE_Keys~0 0)) (not (= ~__ste_Client_AddressBook2_Address0~0 0)) (not (= ~__ste_Client_Keyring0_User2~0 0)) (not (<= |old(~__ste_ClientKeyring_size2~0)| 0)) (not (= ~queued_client~0 0)) (not (<= 0 ~__ste_Client_Keyring1_User1~0)) (not (= ~__ste_Client_AddressBook2_Alias2~0 0)) (not (= ~__ste_email_isSigned0~0 0)) (not (= ~__ste_email_encryptionKey0~0 0)) (not (<= 0 |old(~__ste_ClientKeyring_size2~0)|)) (not (= ~__ste_email_signKey1~0 0)) (not (= ~__ste_client_name0~0.base 0)) (not (= ~__ste_Client_AddressBook2_Address1~0 0)) (not (= ~__GUIDSL_ROOT_PRODUCTION~0 0)) (not (<= ~__ste_Client_Keyring1_User1~0 0)) (not (= ~__SELECTED_FEATURE_Forward~0 0)) (not (<= 0 ~__ste_Client_Keyring2_PublicKey0~0)) (not (= ~__ste_email_body1~0.base 0)) (not (= ~__GUIDSL_NON_TERMINAL_main~0 0)) (not (= ~__ste_email_to0~0 0)) (not (= |createClientKeyringEntry_#in~handle#1| ~bob~0)) (not (= ~__ste_Client_Keyring1_PublicKey2~0 0)) (not (= ~__ste_client_outbuffer0~0 0)) (not (= 0 ~__ste_Client_AddressBook0_Address2~0)) (not (= ~__ste_client_forwardReceiver0~0 0)) (not (= ~__ste_email_body1~0.offset 0)) (not (= ~__ste_email_body0~0.offset 0)) (not (= ~__ste_email_isEncrypted1~0 0)) (not (= ~__ste_Client_AddressBook1_Alias0~0 0)) (not (= ~head~0.offset 0)) (not (= ~__ste_email_id1~0 0)) (not (= ~__ste_client_forwardReceiver2~0 0)) (not (<= 0 ~__ste_Client_Keyring2_User1~0)) (not (<= 789 ~__ste_client_privateKey2~0)) (not (= ~__ste_client_outbuffer1~0 0)) (not (<= ~__ste_Client_Keyring1_PublicKey1~0 0)) (not (= ~__ste_email_signKey0~0 0)) (not (<= ~__ste_Client_Keyring2_User0~0 0)) (not (= ~__SELECTED_FEATURE_Sign~0 0)) (not (= ~__ste_Client_AddressBook2_Alias1~0 0)) (not (= ~__ste_email_isSignatureVerified0~0 0)) (not (= ~__ste_Client_AddressBook0_Alias0~0 0)) (not (<= ~__ste_Client_Keyring1_PublicKey0~0 0)) (not (= ~__ste_client_outbuffer3~0 0)) (not (<= |old(~__ste_ClientKeyring_size1~0)| 0)) (not (= ~__SELECTED_FEATURE_Base~0 0)) (not (= ~__ste_email_encryptionKey1~0 0)) (not (= ~__ste_email_subject0~0.offset 0)) (not (<= 0 ~__ste_Client_Keyring2_User0~0)) (not (<= ~__ste_Client_Keyring1_User0~0 0)) (not (= ~__ste_email_to1~0 0)) (not (= ~__ste_Client_AddressBook1_Alias2~0 0)) (not (= |#NULL.base| 0)) (not (<= ~__ste_Client_Keyring2_User1~0 0)) (not (<= ~__ste_Client_Keyring2_PublicKey1~0 0)) (not (= ~__ste_email_isSignatureVerified1~0 0)) (not (= ~__ste_email_subject1~0.base 0)) (not (= ~__ste_client_autoResponse1~0 0)) (not (= ~__ste_Client_AddressBook2_Address2~0 0)) (not (= ~__ste_client_name1~0.offset 0)) (not (<= 0 ~__ste_Client_Keyring2_PublicKey1~0)) (not (= ~__ste_email_body0~0.base 0)) (not (= ~__ste_Client_AddressBook1_Address1~0 0)) (not (= ~__SELECTED_FEATURE_Decrypt~0 0)) (not (<= 0 ~__ste_Client_Keyring0_PublicKey0~0)) (not (<= ~__ste_Client_Keyring0_PublicKey1~0 0)) (not (= ~__ste_client_name0~0.offset 0)) (not (= 3 ~chuck~0)) (not (<= ~__ste_client_idCounter2~0 3)) (not (= ~__ste_Client_AddressBook1_Address0~0 0)) (not (<= 0 ~__ste_Client_Keyring0_User1~0)) (not (= ~__SELECTED_FEATURE_Verify~0 0)) (not (<= 0 |#StackHeapBarrier|)) (not (<= 0 |old(~__ste_ClientKeyring_size1~0)|)) (not (= ~__ste_Client_Keyring2_User2~0 0)) (not (= ~__SELECTED_FEATURE_AutoResponder~0 0)) (not (<= 0 ~__ste_Client_Keyring1_PublicKey0~0)) (not (<= |old(~__ste_ClientKeyring_size0~0)| 0)) (not (= ~__ste_ClientAddressBook_size0~0 0)) (not (<= ~__ste_Client_Keyring2_PublicKey0~0 0)) (not (<= 0 ~__ste_Client_Keyring1_User0~0)) (not (= ~__ste_client_forwardReceiver3~0 0)) (not (= ~__ste_client_forwardReceiver1~0 0)) (not (= ~__ste_Client_Keyring1_User2~0 0)) (not (<= ~__ste_Client_Keyring0_User0~0 0)) (not (= ~__ste_client_outbuffer2~0 0)) (not (= ~__ste_email_isEncrypted0~0 0)) (not (= ~__ste_Client_Keyring2_PublicKey2~0 0)) (not (= ~__SELECTED_FEATURE_Encrypt~0 0)) (not (<= ~__ste_Client_Keyring0_PublicKey0~0 0)) (not (= ~__ste_client_autoResponse0~0 0)) (not (= ~queue_empty~0 1)) (not (= ~__ste_client_name1~0.base 0)) (not (<= ~__ste_Client_Keyring0_User1~0 0)) (not (= ~__ste_Client_AddressBook2_Alias0~0 0)) (not (= ~__ste_email_isSigned1~0 0)) (not (= ~head~0.base 0)) (not (= ~__ste_Client_AddressBook0_Alias1~0 0)) (not (<= 0 ~__ste_Client_Keyring1_PublicKey1~0)) (not (= ~__ste_Email_counter~0 0)) (not (<= 3 ~__ste_client_idCounter2~0)) (not (= ~__ste_email_from1~0 0)) (not (= ~__ste_email_subject1~0.offset 0)) (not (= 0 ~__ste_email_subject0~0.base)) (not (= ~__ste_Client_Keyring0_PublicKey2~0 0))) [2022-12-14 09:04:34,636 INFO L899 garLoopResultBuilder]: For program point createClientKeyringEntryEXIT(lines 1779 1803) no Hoare annotation was computed. [2022-12-14 09:04:34,637 INFO L902 garLoopResultBuilder]: At program point $Ultimate##0(lines 1974 2027) the Hoare annotation is: true [2022-12-14 09:04:34,637 INFO L899 garLoopResultBuilder]: For program point findPublicKeyEXIT(lines 1974 2027) no Hoare annotation was computed. [2022-12-14 09:04:34,637 INFO L899 garLoopResultBuilder]: For program point getClientPrivateKeyEXIT(lines 1688 1711) no Hoare annotation was computed. [2022-12-14 09:04:34,637 INFO L902 garLoopResultBuilder]: At program point $Ultimate##0(lines 1688 1711) the Hoare annotation is: true [2022-12-14 09:04:34,637 INFO L895 garLoopResultBuilder]: At program point L2295-1(line 2295) the Hoare annotation is: (or (not (= |sendEmail_#in~sender#1| 1)) (and (= |sendEmail_~sender#1| 1) (= ~__ste_email_isSigned0~0 0) (= ~__ste_email_isEncrypted0~0 0) (= 1 |sendEmail_createEmail_~msg~0#1|)) (not (= ~bob~0 1)) (not (= |old(~__ste_email_isEncrypted0~0)| 0)) (not (= |old(~__ste_email_isSigned0~0)| 0)) (not (= ~queue_empty~0 1))) [2022-12-14 09:04:34,637 INFO L895 garLoopResultBuilder]: At program point L2295(line 2295) the Hoare annotation is: (or (not (= |sendEmail_#in~sender#1| 1)) (and (= |sendEmail_~sender#1| 1) (= ~__ste_email_isSigned0~0 0) (= ~__ste_email_isEncrypted0~0 0) (= 1 |sendEmail_createEmail_~msg~0#1|)) (not (= ~bob~0 1)) (not (= |old(~__ste_email_isEncrypted0~0)| 0)) (not (= |old(~__ste_email_isSigned0~0)| 0)) (not (= ~queue_empty~0 1))) [2022-12-14 09:04:34,637 INFO L899 garLoopResultBuilder]: For program point sendEmailEXIT(lines 291 303) no Hoare annotation was computed. [2022-12-14 09:04:34,637 INFO L899 garLoopResultBuilder]: For program point sendEmailFINAL(lines 291 303) no Hoare annotation was computed. [2022-12-14 09:04:34,637 INFO L895 garLoopResultBuilder]: At program point L299(line 299) the Hoare annotation is: (or (not (= |sendEmail_#in~sender#1| 1)) (not (= ~bob~0 1)) (not (= |old(~__ste_email_isEncrypted0~0)| 0)) (not (= |old(~__ste_email_isSigned0~0)| 0)) (not (= ~queue_empty~0 1)) (and (= |sendEmail_~sender#1| 1) (= |sendEmail_~email~0#1| 1) (= ~__ste_email_isSigned0~0 0) (= ~__ste_email_isEncrypted0~0 0) (= 1 |sendEmail_createEmail_~msg~0#1|))) [2022-12-14 09:04:34,638 INFO L895 garLoopResultBuilder]: At program point $Ultimate##0(lines 291 303) the Hoare annotation is: (or (not (= |sendEmail_#in~sender#1| 1)) (not (= ~bob~0 1)) (and (= ~__ste_email_isSigned0~0 0) (= ~__ste_email_isEncrypted0~0 0)) (not (= |old(~__ste_email_isEncrypted0~0)| 0)) (not (= |old(~__ste_email_isSigned0~0)| 0)) (not (= ~queue_empty~0 1))) [2022-12-14 09:04:34,638 INFO L902 garLoopResultBuilder]: At program point $Ultimate##0(lines 744 759) the Hoare annotation is: true [2022-12-14 09:04:34,638 INFO L899 garLoopResultBuilder]: For program point setEmailEncryptionKeyEXIT(lines 744 759) no Hoare annotation was computed. [2022-12-14 09:04:34,638 INFO L899 garLoopResultBuilder]: For program point isEncryptedEXIT(lines 688 706) no Hoare annotation was computed. [2022-12-14 09:04:34,638 INFO L902 garLoopResultBuilder]: At program point $Ultimate##0(lines 688 706) the Hoare annotation is: true [2022-12-14 09:04:34,638 INFO L899 garLoopResultBuilder]: For program point setEmailIsEncryptedEXIT(lines 707 722) no Hoare annotation was computed. [2022-12-14 09:04:34,638 INFO L895 garLoopResultBuilder]: At program point $Ultimate##0(lines 707 722) the Hoare annotation is: (or (= ~__ste_email_isEncrypted0~0 |old(~__ste_email_isEncrypted0~0)|) (not (= ~queue_empty~0 1))) [2022-12-14 09:04:34,638 INFO L902 garLoopResultBuilder]: At program point $Ultimate##0(lines 725 743) the Hoare annotation is: true [2022-12-14 09:04:34,638 INFO L899 garLoopResultBuilder]: For program point getEmailEncryptionKeyEXIT(lines 725 743) no Hoare annotation was computed. [2022-12-14 09:04:34,638 INFO L899 garLoopResultBuilder]: For program point getEmailSignKeyEXIT(lines 799 817) no Hoare annotation was computed. [2022-12-14 09:04:34,638 INFO L902 garLoopResultBuilder]: At program point $Ultimate##0(lines 799 817) the Hoare annotation is: true [2022-12-14 09:04:34,638 INFO L899 garLoopResultBuilder]: For program point setClientPrivateKeyEXIT(lines 1712 1731) no Hoare annotation was computed. [2022-12-14 09:04:34,639 INFO L902 garLoopResultBuilder]: At program point $Ultimate##0(lines 1712 1731) the Hoare annotation is: true [2022-12-14 09:04:34,639 INFO L899 garLoopResultBuilder]: For program point chuckKeyAddEXIT(lines 2514 2525) no Hoare annotation was computed. [2022-12-14 09:04:34,639 INFO L902 garLoopResultBuilder]: At program point $Ultimate##0(lines 2514 2525) the Hoare annotation is: true [2022-12-14 09:04:34,639 INFO L902 garLoopResultBuilder]: At program point L2520(line 2520) the Hoare annotation is: true [2022-12-14 09:04:34,639 INFO L899 garLoopResultBuilder]: For program point L2519(line 2519) no Hoare annotation was computed. [2022-12-14 09:04:34,639 INFO L902 garLoopResultBuilder]: At program point L2520-1(line 2520) the Hoare annotation is: true [2022-12-14 09:04:34,639 INFO L899 garLoopResultBuilder]: For program point chuckKeyAddFINAL(lines 2514 2525) no Hoare annotation was computed. [2022-12-14 09:04:34,639 INFO L899 garLoopResultBuilder]: For program point getEmailToEXIT(lines 573 591) no Hoare annotation was computed. [2022-12-14 09:04:34,639 INFO L902 garLoopResultBuilder]: At program point $Ultimate##0(lines 573 591) the Hoare annotation is: true [2022-12-14 09:04:34,639 INFO L899 garLoopResultBuilder]: For program point generateKeyPairFINAL(lines 366 375) no Hoare annotation was computed. [2022-12-14 09:04:34,639 INFO L902 garLoopResultBuilder]: At program point $Ultimate##0(lines 366 375) the Hoare annotation is: true [2022-12-14 09:04:34,639 INFO L899 garLoopResultBuilder]: For program point generateKeyPairEXIT(lines 366 375) no Hoare annotation was computed. [2022-12-14 09:04:34,640 INFO L902 garLoopResultBuilder]: At program point L371(line 371) the Hoare annotation is: true [2022-12-14 09:04:34,642 INFO L895 garLoopResultBuilder]: At program point $Ultimate##0(lines 1867 1910) the Hoare annotation is: (or (not (= ~__ste_Client_AddressBook1_Address2~0 0)) (not (= ~__ste_email_from0~0 0)) (not (= |setClientKeyringUser_#in~index| 0)) (not (<= ~__ste_ClientKeyring_size0~0 2147483647)) (not (= |old(~__ste_Client_Keyring1_User0~0)| 0)) (not (= ~__ste_client_autoResponse2~0 0)) (not (= ~__ste_client_name2~0.base 0)) (not (= ~__ste_Client_AddressBook1_Alias1~0 0)) (not (= ~rjh~0 2)) (not (<= ~__ste_client_privateKey2~0 789)) (not (= |setClientKeyringUser_#in~handle| ~bob~0)) (not (= ~__ste_ClientAddressBook_size1~0 0)) (not (= 0 ~__ste_Client_AddressBook0_Address0~0)) (not (= |#NULL.offset| 0)) (not (= ~__ste_Client_counter~0 0)) (not (= 0 ~__ste_Client_AddressBook0_Address1~0)) (not (= ~bob~0 1)) (not (= ~queued_message~0 0)) (not (= ~__ste_Client_Keyring1_PublicKey1~0 0)) (not (<= 0 (+ 2147483647 ~__ste_ClientKeyring_size0~0))) (not (= ~__ste_client_name2~0.offset 0)) (not (= ~__ste_ClientAddressBook_size2~0 0)) (not (= ~__SELECTED_FEATURE_AddressBook~0 0)) (not (= ~__ste_Client_AddressBook0_Alias2~0 0)) (not (= ~__ste_email_id0~0 0)) (not (= ~__SELECTED_FEATURE_Keys~0 0)) (not (= ~__ste_Client_AddressBook2_Address0~0 0)) (not (= ~__ste_Client_Keyring0_User2~0 0)) (not (= ~queued_client~0 0)) (not (= ~__ste_Client_AddressBook2_Alias2~0 0)) (not (= ~__ste_email_isSigned0~0 0)) (not (= ~__ste_email_encryptionKey0~0 0)) (not (= |setClientKeyringUser_#in~value| 2)) (not (= ~__ste_email_signKey1~0 0)) (and (= ~__ste_Client_Keyring0_User1~0 |old(~__ste_Client_Keyring0_User1~0)|) (= |old(~__ste_Client_Keyring2_User1~0)| ~__ste_Client_Keyring2_User1~0) (= ~__ste_Client_Keyring1_User1~0 |old(~__ste_Client_Keyring1_User1~0)|) (= ~__ste_Client_Keyring0_User0~0 |old(~__ste_Client_Keyring0_User0~0)|) (= ~__ste_Client_Keyring1_User0~0 |old(~__ste_Client_Keyring1_User0~0)|) (= |old(~__ste_Client_Keyring2_User0~0)| ~__ste_Client_Keyring2_User0~0)) (not (= ~__ste_client_name0~0.base 0)) (not (= ~__ste_Client_AddressBook2_Address1~0 0)) (not (= ~__GUIDSL_ROOT_PRODUCTION~0 0)) (not (= ~__SELECTED_FEATURE_Forward~0 0)) (not (= ~__ste_email_body1~0.base 0)) (not (= ~__GUIDSL_NON_TERMINAL_main~0 0)) (not (= ~__ste_email_to0~0 0)) (not (= ~__ste_Client_Keyring1_PublicKey2~0 0)) (not (= ~__ste_client_outbuffer0~0 0)) (not (= 0 ~__ste_Client_AddressBook0_Address2~0)) (not (= ~__ste_client_forwardReceiver0~0 0)) (not (= ~__ste_email_body1~0.offset 0)) (not (= ~__ste_email_body0~0.offset 0)) (not (= ~__ste_email_isEncrypted1~0 0)) (not (= ~__ste_Client_AddressBook1_Alias0~0 0)) (not (= ~head~0.offset 0)) (not (= ~__ste_email_id1~0 0)) (not (= ~__ste_client_forwardReceiver2~0 0)) (not (<= 789 ~__ste_client_privateKey2~0)) (not (= ~__ste_client_outbuffer1~0 0)) (not (= ~__ste_email_signKey0~0 0)) (not (= ~__SELECTED_FEATURE_Sign~0 0)) (not (= |old(~__ste_Client_Keyring0_User0~0)| 0)) (not (= ~__ste_Client_AddressBook2_Alias1~0 0)) (not (= ~__ste_Client_Keyring2_PublicKey0~0 0)) (not (= ~__ste_email_isSignatureVerified0~0 0)) (not (= ~__ste_Client_AddressBook0_Alias0~0 0)) (not (= ~__ste_client_outbuffer3~0 0)) (not (= |old(~__ste_Client_Keyring2_User0~0)| 0)) (not (= ~__ste_Client_Keyring2_PublicKey1~0 0)) (not (= ~__SELECTED_FEATURE_Base~0 0)) (not (= ~__ste_email_encryptionKey1~0 0)) (not (= ~__ste_email_subject0~0.offset 0)) (not (= ~__ste_email_to1~0 0)) (not (= ~__ste_Client_AddressBook1_Alias2~0 0)) (not (= ~__ste_Client_Keyring1_PublicKey0~0 0)) (not (= |#NULL.base| 0)) (not (= ~__ste_Client_Keyring0_PublicKey1~0 0)) (not (= ~__ste_Client_Keyring0_PublicKey0~0 0)) (not (= ~__ste_email_isSignatureVerified1~0 0)) (not (= ~__ste_email_subject1~0.base 0)) (not (= ~__ste_client_autoResponse1~0 0)) (not (= ~__ste_Client_AddressBook2_Address2~0 0)) (not (= ~__ste_client_name1~0.offset 0)) (not (= ~__ste_email_body0~0.base 0)) (not (= ~__ste_Client_AddressBook1_Address1~0 0)) (not (= ~__SELECTED_FEATURE_Decrypt~0 0)) (not (= ~__ste_client_name0~0.offset 0)) (not (= 3 ~chuck~0)) (not (<= ~__ste_client_idCounter2~0 3)) (not (= ~__ste_Client_AddressBook1_Address0~0 0)) (not (= ~__SELECTED_FEATURE_Verify~0 0)) (not (= |old(~__ste_Client_Keyring1_User1~0)| 0)) (not (<= 0 |#StackHeapBarrier|)) (not (= |old(~__ste_Client_Keyring2_User1~0)| 0)) (not (= ~__ste_Client_Keyring2_User2~0 0)) (not (= ~__SELECTED_FEATURE_AutoResponder~0 0)) (not (= ~__ste_ClientAddressBook_size0~0 0)) (not (= ~__ste_client_forwardReceiver3~0 0)) (not (= ~__ste_client_forwardReceiver1~0 0)) (not (= ~__ste_Client_Keyring1_User2~0 0)) (not (= ~__ste_client_outbuffer2~0 0)) (not (= ~__ste_email_isEncrypted0~0 0)) (not (= ~__ste_Client_Keyring2_PublicKey2~0 0)) (not (= ~__SELECTED_FEATURE_Encrypt~0 0)) (not (= ~__ste_client_autoResponse0~0 0)) (not (= ~queue_empty~0 1)) (not (= ~__ste_client_name1~0.base 0)) (not (= |old(~__ste_Client_Keyring0_User1~0)| 0)) (not (= ~__ste_Client_AddressBook2_Alias0~0 0)) (not (= ~__ste_email_isSigned1~0 0)) (not (= ~head~0.base 0)) (not (= ~__ste_Client_AddressBook0_Alias1~0 0)) (not (= ~__ste_Email_counter~0 0)) (not (<= 3 ~__ste_client_idCounter2~0)) (not (= ~__ste_email_from1~0 0)) (not (= ~__ste_email_subject1~0.offset 0)) (not (= 0 ~__ste_email_subject0~0.base)) (not (= ~__ste_Client_Keyring0_PublicKey2~0 0))) [2022-12-14 09:04:34,642 INFO L899 garLoopResultBuilder]: For program point setClientKeyringUserEXIT(lines 1867 1910) no Hoare annotation was computed. [2022-12-14 09:04:34,642 INFO L899 garLoopResultBuilder]: For program point setEmailFromEXIT(lines 555 570) no Hoare annotation was computed. [2022-12-14 09:04:34,642 INFO L902 garLoopResultBuilder]: At program point $Ultimate##0(lines 555 570) the Hoare annotation is: true [2022-12-14 09:04:34,642 INFO L899 garLoopResultBuilder]: For program point L927(lines 927 1082) no Hoare annotation was computed. [2022-12-14 09:04:34,643 INFO L895 garLoopResultBuilder]: At program point L2331-1(lines 2325 2335) the Hoare annotation is: (and (= ~__ste_Client_Keyring1_User2~0 0) (= ~__GUIDSL_NON_TERMINAL_main~0 0) (= ~__ste_email_isEncrypted1~0 0) (= ~__SELECTED_FEATURE_Sign~0 0) (= ~__ste_client_outbuffer3~0 0) (<= 1 |ULTIMATE.start_valid_product_#res#1|) (<= 1 |ULTIMATE.start_setup_bob_#in~bob___0#1|) (= ~__ste_Client_counter~0 0) (= ~rjh~0 0) (<= |ULTIMATE.start_main_~retValue_acc~40#1| 2147483647) (<= |ULTIMATE.start_setup_bob__wrappee__Base_#in~bob___0#1| 1) (= ~__ste_client_autoResponse1~0 0) (= ~__ste_Client_AddressBook2_Alias0~0 0) (<= 1 |ULTIMATE.start_setup_bob__wrappee__Base_#in~bob___0#1|) (= 0 ~__ste_email_subject0~0.base) (= ~__ste_Client_AddressBook2_Alias1~0 0) (= ~__ste_Client_Keyring2_PublicKey2~0 0) (<= |ULTIMATE.start_setup_bob_#in~bob___0#1| 1) (= ~__ste_client_name2~0.offset 0) (= ~__ste_email_body1~0.offset 0) (= ~__SELECTED_FEATURE_Encrypt~0 0) (= ~__ste_Client_AddressBook1_Address2~0 0) (<= 1 |ULTIMATE.start_setup_bob_~bob___0#1|) (= ~__ste_ClientAddressBook_size1~0 0) (= ~__ste_Email_counter~0 0) (= ~__ste_email_body0~0.offset 0) (= ~__ste_email_isSignatureVerified0~0 0) (= ~__ste_Client_Keyring0_User2~0 0) (= ~__ste_ClientAddressBook_size0~0 0) (= ~__ste_Client_Keyring0_User1~0 0) (= ~__ste_Client_AddressBook1_Alias1~0 0) (= ~__ste_email_to1~0 0) (= ~__ste_client_name1~0.offset 0) (= ~head~0.offset 0) (= ~__ste_Client_Keyring0_PublicKey2~0 0) (= ~__ste_Client_Keyring1_PublicKey0~0 0) (= ~__ste_email_to0~0 0) (= ~__ste_email_signKey0~0 0) (= ~__SELECTED_FEATURE_Decrypt~0 0) (= ~__SELECTED_FEATURE_Keys~0 0) (<= |#NULL.offset| 0) (<= 0 ~__ste_Client_Keyring1_User0~0) (<= 0 ~__SELECTED_FEATURE_AddressBook~0) (= ~__ste_Client_Keyring0_PublicKey1~0 0) (<= 1 |ULTIMATE.start_valid_product_~retValue_acc~1#1|) (<= 0 ~__ste_email_from1~0) (= ~__SELECTED_FEATURE_Forward~0 0) (= ~__ste_Client_Keyring0_User0~0 0) (= ~__ste_email_isSigned0~0 0) (= ~__ste_Client_Keyring2_PublicKey1~0 0) (= ~__ste_email_isSigned1~0 0) (<= 0 ~__ste_email_id1~0) (<= ~__ste_Client_AddressBook0_Address1~0 0) (= ~__ste_email_body0~0.base 0) (= ~__ste_Client_AddressBook0_Alias0~0 0) (<= 0 (+ 2147483648 |ULTIMATE.start_main_~retValue_acc~40#1|)) (<= 0 ~__ste_Client_AddressBook2_Address1~0) (<= 0 ~__ste_client_name0~0.offset) (<= ~__ste_Client_Keyring0_PublicKey0~0 0) (<= ~__ste_client_name1~0.base 0) (= ~__ste_email_id0~0 0) (<= ~__ste_client_autoResponse0~0 0) (<= ~__SELECTED_FEATURE_AddressBook~0 0) (= ~__ste_email_from0~0 0) (<= ~__ste_Client_Keyring1_PublicKey2~0 0) (<= |ULTIMATE.start_setup_bob_~bob___0#1| 1) (<= 0 ~__ste_Client_Keyring0_PublicKey0~0) (<= ~__ste_client_forwardReceiver3~0 0) (= ~__ste_Client_AddressBook2_Address2~0 0) (<= 0 ~__ste_Client_Keyring1_PublicKey2~0) (<= |ULTIMATE.start_valid_product_#res#1| 1) (<= ~__ste_Client_AddressBook0_Address0~0 0) (<= 0 ~__ste_email_signKey1~0) (<= ~__ste_email_signKey1~0 0) (<= 0 ~__ste_client_forwardReceiver3~0) (<= ~__ste_email_subject0~0.offset 0) (= ~bob~0 1) (<= 0 ~__ste_client_autoResponse0~0) (<= 1 |ULTIMATE.start_setup_bob__wrappee__Base_~bob___0#1|) (<= 0 ~__ste_Client_AddressBook0_Alias2~0) (= ~__ste_client_outbuffer0~0 0) (<= ~__SELECTED_FEATURE_Verify~0 0) (<= ~__ste_ClientKeyring_size1~0 0) (<= 0 ~head~0.base) (= ~queue_empty~0 1) (= ~__SELECTED_FEATURE_Base~0 0) (<= ~__ste_Client_AddressBook1_Alias2~0 0) (<= 0 ~__ste_Client_AddressBook0_Address2~0) (= ~__ste_client_forwardReceiver0~0 0) (= ~__ste_Client_Keyring2_User0~0 0) (<= 0 ~__ste_email_subject0~0.offset) (<= 0 ~__ste_Client_AddressBook1_Alias0~0) (= ~__ste_Client_AddressBook2_Address0~0 0) (= ~__ste_email_isSignatureVerified1~0 0) (= ~__ste_Client_Keyring1_PublicKey1~0 0) (<= 0 ~queued_client~0) (<= ~__ste_client_privateKey0~0 123) (<= ~__ste_Client_AddressBook1_Alias0~0 0) (= ~__ste_Client_Keyring2_PublicKey0~0 0) (= ~__ste_Client_AddressBook1_Address0~0 0) (<= 0 ~__ste_ClientKeyring_size1~0) (<= 0 ~__ste_client_forwardReceiver2~0) (= ~__ste_client_name2~0.base 0) (<= 0 ~__ste_Client_AddressBook0_Address1~0) (<= ~__ste_email_encryptionKey0~0 0) (<= ~__ste_client_idCounter0~0 1) (= ~__ste_email_subject1~0.base 0) (<= ~__ste_ClientKeyring_size0~0 0) (<= ~__ste_email_id1~0 0) (<= 0 ~__ste_Client_AddressBook0_Address0~0) (<= ~__ste_Client_Keyring1_User0~0 0) (<= ~__ste_Client_AddressBook0_Alias2~0 0) (<= ~__ste_Client_AddressBook0_Address2~0 0) (= ~__ste_Client_Keyring2_User2~0 0) (<= |ULTIMATE.start_setup_bob__wrappee__Base_~bob___0#1| 1) (<= ~__ste_email_from1~0 0) (<= ~head~0.base 0) (<= ~__ste_client_forwardReceiver1~0 0) (= ~__ste_Client_Keyring1_User1~0 0) (= ~__ste_Client_AddressBook2_Alias2~0 0) (<= ~__ste_Client_Keyring2_User1~0 0) (<= 0 ~__SELECTED_FEATURE_Verify~0) (<= 0 ~__ste_Client_AddressBook1_Alias2~0) (<= 0 ~__ste_client_autoResponse2~0) (= ~__ste_email_subject1~0.offset 0) (= ~__ste_email_isEncrypted0~0 0) (<= 0 ~__ste_Client_Keyring2_User1~0) (= ~queued_message~0 0) (= ~__ste_Client_AddressBook1_Address1~0 0) (<= ~__ste_client_name0~0.offset 0) (<= 1 ~__ste_client_idCounter0~0) (= ~__ste_client_outbuffer1~0 0) (= ~__ste_Client_AddressBook0_Alias1~0 0) (<= 0 ~__ste_ClientKeyring_size0~0) (<= |ULTIMATE.start_valid_product_~retValue_acc~1#1| 1) (= ~__GUIDSL_ROOT_PRODUCTION~0 0) (<= 0 |#NULL.offset|) (<= 123 ~__ste_client_privateKey0~0) (= ~chuck~0 0) (<= 0 ~__ste_client_forwardReceiver1~0) (= ~__ste_client_name0~0.base 0) (<= ~__ste_Client_AddressBook2_Address1~0 0) (= ~__ste_client_outbuffer2~0 0) (<= ~__ste_client_forwardReceiver2~0 0) (<= 0 |#StackHeapBarrier|) (= ~__ste_ClientAddressBook_size2~0 0) (= ~__SELECTED_FEATURE_AutoResponder~0 0) (<= ~__ste_client_autoResponse2~0 0) (= ~__ste_email_encryptionKey1~0 0) (= ~__ste_email_body1~0.base 0) (= ~__ste_ClientKeyring_size2~0 0) (<= 0 ~__ste_client_name1~0.base) (<= 0 ~__ste_email_encryptionKey0~0) (= |#NULL.base| 0) (= |ULTIMATE.start_main_~tmp~17#1| 1) (<= ~queued_client~0 0)) [2022-12-14 09:04:34,645 INFO L895 garLoopResultBuilder]: At program point L2331(line 2331) the Hoare annotation is: (and (= ~queued_client~0 0) (= ~__ste_Client_Keyring1_User2~0 0) (= ~__GUIDSL_NON_TERMINAL_main~0 0) (= ~__ste_email_isEncrypted1~0 0) (= ~__ste_email_subject0~0.offset 0) (= ~__SELECTED_FEATURE_Sign~0 0) (= 0 ~__ste_Client_AddressBook0_Address2~0) (= ~__ste_client_outbuffer3~0 0) (<= 1 |ULTIMATE.start_valid_product_#res#1|) (<= 1 |ULTIMATE.start_setup_bob_#in~bob___0#1|) (= ~__ste_Client_counter~0 0) (= ~rjh~0 0) (= ~__ste_Client_Keyring1_PublicKey2~0 0) (<= |ULTIMATE.start_main_~retValue_acc~40#1| 2147483647) (<= |ULTIMATE.start_setup_bob__wrappee__Base_#in~bob___0#1| 1) (= ~__ste_client_autoResponse1~0 0) (= ~__ste_Client_AddressBook2_Alias0~0 0) (<= 1 |ULTIMATE.start_setup_bob__wrappee__Base_#in~bob___0#1|) (= 0 ~__ste_email_subject0~0.base) (= ~__ste_Client_AddressBook2_Alias1~0 0) (= ~__ste_Client_Keyring2_PublicKey2~0 0) (= ~__ste_client_forwardReceiver3~0 0) (<= |ULTIMATE.start_setup_bob_#in~bob___0#1| 1) (= ~__ste_client_name2~0.offset 0) (= ~__ste_client_name1~0.base 0) (= ~__SELECTED_FEATURE_Verify~0 0) (= ~__ste_Client_Keyring1_User0~0 0) (= ~__ste_email_body1~0.offset 0) (= ~__SELECTED_FEATURE_Encrypt~0 0) (= ~__ste_Client_AddressBook1_Address2~0 0) (<= 1 |ULTIMATE.start_setup_bob_~bob___0#1|) (= ~__ste_ClientAddressBook_size1~0 0) (= ~__ste_Client_Keyring0_PublicKey0~0 0) (= ~__ste_Email_counter~0 0) (= ~__ste_ClientKeyring_size1~0 0) (= ~__ste_email_body0~0.offset 0) (= ~__ste_email_isSignatureVerified0~0 0) (= ~__ste_Client_Keyring0_User2~0 0) (= ~__ste_ClientAddressBook_size0~0 0) (= ~__ste_Client_Keyring0_User1~0 0) (= ~__ste_Client_AddressBook1_Alias1~0 0) (= ~__ste_email_to1~0 0) (= ~__ste_client_name1~0.offset 0) (= ~__ste_client_privateKey1~0 0) (= ~head~0.offset 0) (= ~__ste_client_name0~0.offset 0) (= ~__ste_Client_Keyring0_PublicKey2~0 0) (= ~__ste_Client_Keyring1_PublicKey0~0 0) (= ~__ste_email_to0~0 0) (= ~__ste_email_signKey0~0 0) (= ~__SELECTED_FEATURE_Decrypt~0 0) (= ~__ste_email_encryptionKey0~0 0) (= ~__SELECTED_FEATURE_Keys~0 0) (= ~__SELECTED_FEATURE_AddressBook~0 0) (= ~__ste_client_forwardReceiver2~0 0) (= ~__ste_Client_Keyring0_PublicKey1~0 0) (= ~__SELECTED_FEATURE_Forward~0 0) (= ~__ste_Client_Keyring0_User0~0 0) (= ~__ste_email_isSigned0~0 0) (= ~__ste_Client_Keyring2_PublicKey1~0 0) (= ~__ste_email_isSigned1~0 0) (= ~__ste_email_body0~0.base 0) (= ~__ste_Client_AddressBook0_Alias0~0 0) (<= 0 (+ 2147483648 |ULTIMATE.start_main_~retValue_acc~40#1|)) (= ~__ste_email_id0~0 0) (= ~__ste_client_privateKey0~0 0) (= ~__ste_email_from0~0 0) (= ~__ste_Client_Keyring2_User1~0 0) (<= |ULTIMATE.start_setup_bob_~bob___0#1| 1) (= ~__ste_Client_AddressBook2_Address2~0 0) (<= |ULTIMATE.start_valid_product_#res#1| 1) (= ~__ste_Client_AddressBook2_Address1~0 0) (= ~bob~0 1) (= ~__ste_client_forwardReceiver1~0 0) (<= 1 |ULTIMATE.start_setup_bob__wrappee__Base_~bob___0#1|) (= ~__ste_Client_AddressBook1_Alias2~0 0) (= ~__ste_client_outbuffer0~0 0) (= ~queue_empty~0 1) (= ~__SELECTED_FEATURE_Base~0 0) (= ~__ste_client_forwardReceiver0~0 0) (= ~__ste_Client_Keyring2_User0~0 0) (= 0 ~__ste_Client_AddressBook0_Address1~0) (= ~__ste_Client_AddressBook2_Address0~0 0) (= ~__ste_email_isSignatureVerified1~0 0) (= ~__ste_Client_Keyring1_PublicKey1~0 0) (= ~__ste_Client_Keyring2_PublicKey0~0 0) (= ~__ste_Client_AddressBook1_Address0~0 0) (= ~__ste_client_name2~0.base 0) (= ~__ste_email_from1~0 0) (<= ~__ste_client_idCounter0~0 1) (= ~__ste_email_subject1~0.base 0) (= ~__ste_Client_AddressBook1_Alias0~0 0) (= ~__ste_Client_Keyring2_User2~0 0) (<= |ULTIMATE.start_setup_bob__wrappee__Base_~bob___0#1| 1) (= ~head~0.base 0) (= ~__ste_client_privateKey2~0 0) (= ~__ste_Client_Keyring1_User1~0 0) (= |#NULL.offset| 0) (= ~__ste_Client_AddressBook2_Alias2~0 0) (= |ULTIMATE.start_valid_product_~retValue_acc~1#1| 1) (= ~__ste_email_subject1~0.offset 0) (= ~__ste_Client_AddressBook0_Alias2~0 0) (= ~__ste_ClientKeyring_size0~0 0) (= ~__ste_email_isEncrypted0~0 0) (= ~queued_message~0 0) (= ~__ste_Client_AddressBook1_Address1~0 0) (= 0 ~__ste_Client_AddressBook0_Address0~0) (<= 1 ~__ste_client_idCounter0~0) (= ~__ste_client_outbuffer1~0 0) (= ~__ste_Client_AddressBook0_Alias1~0 0) (= ~__GUIDSL_ROOT_PRODUCTION~0 0) (= ~chuck~0 0) (= ~__ste_client_name0~0.base 0) (= ~__ste_email_id1~0 0) (= ~__ste_client_outbuffer2~0 0) (<= 0 |#StackHeapBarrier|) (= ~__ste_ClientAddressBook_size2~0 0) (= ~__SELECTED_FEATURE_AutoResponder~0 0) (= ~__ste_email_encryptionKey1~0 0) (= ~__ste_client_autoResponse0~0 0) (= ~__ste_email_body1~0.base 0) (= ~__ste_ClientKeyring_size2~0 0) (= ~__ste_client_autoResponse2~0 0) (= |#NULL.base| 0) (= |ULTIMATE.start_main_~tmp~17#1| 1) (= ~__ste_email_signKey1~0 0)) [2022-12-14 09:04:34,645 INFO L895 garLoopResultBuilder]: At program point L2563-1(lines 2558 2567) the Hoare annotation is: (and (= ~__ste_email_isSigned0~0 0) (= ~bob~0 1) (= ~queue_empty~0 1) (= ~__ste_email_isEncrypted0~0 0) (= |ULTIMATE.start_main_~tmp~17#1| 1)) [2022-12-14 09:04:34,645 INFO L895 garLoopResultBuilder]: At program point L2563(line 2563) the Hoare annotation is: (and (= ~__ste_email_isSigned0~0 0) (= ~bob~0 1) (= ~queue_empty~0 1) (= ~__ste_email_isEncrypted0~0 0) (= |ULTIMATE.start_main_~tmp~17#1| 1)) [2022-12-14 09:04:34,645 INFO L895 garLoopResultBuilder]: At program point L2464(line 2464) the Hoare annotation is: (and (= ~__ste_email_isSigned0~0 0) (= ~bob~0 1) (= ~queue_empty~0 1) (= |ULTIMATE.start_test_~op1~0#1| 0) (= ~__ste_email_isEncrypted0~0 0) (= |ULTIMATE.start_main_~tmp~17#1| 1)) [2022-12-14 09:04:34,645 INFO L899 garLoopResultBuilder]: For program point L2464-1(line 2464) no Hoare annotation was computed. [2022-12-14 09:04:34,645 INFO L899 garLoopResultBuilder]: For program point L945(lines 945 949) no Hoare annotation was computed. [2022-12-14 09:04:34,645 INFO L899 garLoopResultBuilder]: For program point L2531-1(line 2531) no Hoare annotation was computed. [2022-12-14 09:04:34,646 INFO L895 garLoopResultBuilder]: At program point L2531(line 2531) the Hoare annotation is: (and (= ~__ste_email_isSigned0~0 0) (= ~bob~0 1) (= ~queue_empty~0 1) (= ~__ste_email_isEncrypted0~0 0) (= |ULTIMATE.start_main_~tmp~17#1| 1)) [2022-12-14 09:04:34,646 INFO L895 garLoopResultBuilder]: At program point L2465-1(line 2465) the Hoare annotation is: (and (= ~__ste_email_isSigned0~0 0) (= ~bob~0 1) (= ~queue_empty~0 1) (= |ULTIMATE.start_test_~op1~0#1| 0) (= ~__ste_email_isEncrypted0~0 0) (= |ULTIMATE.start_main_~tmp~17#1| 1)) [2022-12-14 09:04:34,646 INFO L895 garLoopResultBuilder]: At program point $Ultimate##90(lines 1019 1075) the Hoare annotation is: (and (= ~__ste_email_isSigned0~0 0) (= ~bob~0 1) (= ~queue_empty~0 1) (= ~__ste_email_isEncrypted0~0 0) (= |ULTIMATE.start_main_~tmp~17#1| 1)) [2022-12-14 09:04:34,646 INFO L895 garLoopResultBuilder]: At program point L2465(line 2465) the Hoare annotation is: (and (= ~__ste_email_isSigned0~0 0) (= ~bob~0 1) (= ~queue_empty~0 1) (= |ULTIMATE.start_test_~op1~0#1| 0) (= ~__ste_email_isEncrypted0~0 0) (= |ULTIMATE.start_main_~tmp~17#1| 1)) [2022-12-14 09:04:34,646 INFO L895 garLoopResultBuilder]: At program point $Ultimate##96(lines 1030 1074) the Hoare annotation is: (and (= ~__ste_email_isSigned0~0 0) (= ~bob~0 1) (= ~queue_empty~0 1) (= ~__ste_email_isEncrypted0~0 0) (= |ULTIMATE.start_main_~tmp~17#1| 1)) [2022-12-14 09:04:34,646 INFO L899 garLoopResultBuilder]: For program point L1062(lines 1062 1069) no Hoare annotation was computed. [2022-12-14 09:04:34,646 INFO L895 garLoopResultBuilder]: At program point L2532(line 2532) the Hoare annotation is: (and (= ~__ste_email_isSigned0~0 0) (= ~bob~0 1) (= ~queue_empty~0 1) (= ~__ste_email_isEncrypted0~0 0) (= |ULTIMATE.start_main_~tmp~17#1| 1)) [2022-12-14 09:04:34,646 INFO L895 garLoopResultBuilder]: At program point L1062-1(lines 919 1083) the Hoare annotation is: (and (= ~__ste_email_isSigned0~0 0) (= ~bob~0 1) (= ~queue_empty~0 1) (= ~__ste_email_isEncrypted0~0 0) (= |ULTIMATE.start_main_~tmp~17#1| 1)) [2022-12-14 09:04:34,646 INFO L895 garLoopResultBuilder]: At program point L2466(line 2466) the Hoare annotation is: (and (= ~__ste_email_isSigned0~0 0) (= ~bob~0 1) (= ~queue_empty~0 1) (= |ULTIMATE.start_test_~op1~0#1| 0) (= ~__ste_email_isEncrypted0~0 0) (= |ULTIMATE.start_main_~tmp~17#1| 1)) [2022-12-14 09:04:34,647 INFO L895 garLoopResultBuilder]: At program point L2532-1(line 2532) the Hoare annotation is: (and (= ~__ste_email_isSigned0~0 0) (= ~bob~0 1) (= ~queue_empty~0 1) (= ~__ste_email_isEncrypted0~0 0) (= |ULTIMATE.start_main_~tmp~17#1| 1)) [2022-12-14 09:04:34,647 INFO L899 garLoopResultBuilder]: For program point L2483-1(line 2483) no Hoare annotation was computed. [2022-12-14 09:04:34,647 INFO L895 garLoopResultBuilder]: At program point L2483(line 2483) the Hoare annotation is: (and (= ~__ste_email_isSigned0~0 0) (= ~bob~0 1) (= ~queue_empty~0 1) (= ~__ste_email_isEncrypted0~0 0) (= |ULTIMATE.start_main_~tmp~17#1| 1)) [2022-12-14 09:04:34,647 INFO L895 garLoopResultBuilder]: At program point $Ultimate##84(lines 1005 1076) the Hoare annotation is: (and (= ~__ste_email_isSigned0~0 0) (= ~bob~0 1) (= ~queue_empty~0 1) (= ~__ste_email_isEncrypted0~0 0) (= |ULTIMATE.start_main_~tmp~17#1| 1)) [2022-12-14 09:04:34,647 INFO L895 garLoopResultBuilder]: At program point L2533(lines 2526 2537) the Hoare annotation is: (and (= ~__ste_email_isSigned0~0 0) (= ~bob~0 1) (= ~queue_empty~0 1) (= ~__ste_email_isEncrypted0~0 0) (= |ULTIMATE.start_main_~tmp~17#1| 1)) [2022-12-14 09:04:34,647 INFO L899 garLoopResultBuilder]: For program point L931(lines 931 938) no Hoare annotation was computed. [2022-12-14 09:04:34,647 INFO L895 garLoopResultBuilder]: At program point $Ultimate##72(lines 980 1078) the Hoare annotation is: (and (= ~__ste_email_isSigned0~0 0) (= ~bob~0 1) (= ~queue_empty~0 1) (= ~__ste_email_isEncrypted0~0 0) (= |ULTIMATE.start_main_~tmp~17#1| 1)) [2022-12-14 09:04:34,647 INFO L895 garLoopResultBuilder]: At program point L2484(line 2484) the Hoare annotation is: (and (= ~__ste_email_isSigned0~0 0) (= ~bob~0 1) (= ~queue_empty~0 1) (= ~__ste_email_isEncrypted0~0 0) (= |ULTIMATE.start_main_~tmp~17#1| 1)) [2022-12-14 09:04:34,648 INFO L895 garLoopResultBuilder]: At program point L2484-1(line 2484) the Hoare annotation is: (and (= ~__ste_email_isSigned0~0 0) (= ~bob~0 1) (= ~queue_empty~0 1) (= ~__ste_email_isEncrypted0~0 0) (= |ULTIMATE.start_main_~tmp~17#1| 1)) [2022-12-14 09:04:34,649 INFO L895 garLoopResultBuilder]: At program point L2352(line 2352) the Hoare annotation is: (and (= ~queued_client~0 0) (= ~__ste_Client_Keyring1_User2~0 0) (= ~__GUIDSL_NON_TERMINAL_main~0 0) (= ~__ste_email_isEncrypted1~0 0) (= ~__ste_email_subject0~0.offset 0) (= ~__SELECTED_FEATURE_Sign~0 0) (= 0 ~__ste_Client_AddressBook0_Address2~0) (= ~__ste_client_outbuffer3~0 0) (<= 1 |ULTIMATE.start_valid_product_#res#1|) (<= |ULTIMATE.start_setup_rjh__wrappee__Base_#in~rjh___0#1| 2) (<= 1 |ULTIMATE.start_setup_bob_#in~bob___0#1|) (= 19 |ULTIMATE.start_setup_~__cil_tmp1~0#1.base|) (= ~__ste_Client_counter~0 0) (= ~__ste_Client_Keyring1_PublicKey2~0 0) (<= |ULTIMATE.start_main_~retValue_acc~40#1| 2147483647) (<= |ULTIMATE.start_setup_bob__wrappee__Base_#in~bob___0#1| 1) (= ~__ste_client_autoResponse1~0 0) (<= 2 |ULTIMATE.start_setup_rjh_~rjh___0#1|) (= ~__ste_Client_AddressBook2_Alias0~0 0) (= |ULTIMATE.start_setup_~__cil_tmp1~0#1.offset| 0) (<= 1 |ULTIMATE.start_setup_bob__wrappee__Base_#in~bob___0#1|) (= 0 ~__ste_email_subject0~0.base) (<= ~__ste_client_idCounter1~0 2) (= ~__ste_Client_AddressBook2_Alias1~0 0) (= ~__ste_Client_Keyring2_PublicKey2~0 0) (= ~__ste_client_forwardReceiver3~0 0) (<= |ULTIMATE.start_setup_bob_#in~bob___0#1| 1) (= ~__ste_client_name2~0.offset 0) (= ~__ste_client_name1~0.base 0) (= ~__SELECTED_FEATURE_Verify~0 0) (= ~__ste_Client_Keyring1_User0~0 0) (= ~__ste_email_body1~0.offset 0) (= ~__SELECTED_FEATURE_Encrypt~0 0) (= ~__ste_Client_AddressBook1_Address2~0 0) (<= 1 |ULTIMATE.start_setup_bob_~bob___0#1|) (= ~__ste_ClientAddressBook_size1~0 0) (= ~__ste_Client_Keyring0_PublicKey0~0 0) (= ~__ste_Email_counter~0 0) (= ~__ste_ClientKeyring_size1~0 0) (= ~__ste_email_body0~0.offset 0) (= ~__ste_email_isSignatureVerified0~0 0) (= ~__ste_Client_Keyring0_User2~0 0) (= ~__ste_ClientAddressBook_size0~0 0) (= ~__ste_Client_Keyring0_User1~0 0) (= ~__ste_Client_AddressBook1_Alias1~0 0) (= ~__ste_email_to1~0 0) (= ~__ste_client_name1~0.offset 0) (= ~head~0.offset 0) (= ~__ste_client_name0~0.offset 0) (= ~__ste_Client_Keyring0_PublicKey2~0 0) (= ~__ste_Client_Keyring1_PublicKey0~0 0) (= ~__ste_email_to0~0 0) (= ~__ste_email_signKey0~0 0) (= ~__SELECTED_FEATURE_Decrypt~0 0) (= ~__ste_email_encryptionKey0~0 0) (= ~__SELECTED_FEATURE_Keys~0 0) (= ~__SELECTED_FEATURE_AddressBook~0 0) (= ~__ste_client_forwardReceiver2~0 0) (= ~__ste_Client_Keyring0_PublicKey1~0 0) (= ~__SELECTED_FEATURE_Forward~0 0) (<= |ULTIMATE.start_setup_rjh_~rjh___0#1| 2) (= ~__ste_Client_Keyring0_User0~0 0) (= ~__ste_email_isSigned0~0 0) (= ~__ste_Client_Keyring2_PublicKey1~0 0) (= ~__ste_email_isSigned1~0 0) (= ~__ste_email_body0~0.base 0) (= ~__ste_Client_AddressBook0_Alias0~0 0) (<= 0 (+ 2147483648 |ULTIMATE.start_main_~retValue_acc~40#1|)) (= ~__ste_email_id0~0 0) (<= |ULTIMATE.start_setup_rjh_#in~rjh___0#1| 2) (= ~__ste_email_from0~0 0) (= ~__ste_Client_Keyring2_User1~0 0) (<= |ULTIMATE.start_setup_bob_~bob___0#1| 1) (= ~__ste_Client_AddressBook2_Address2~0 0) (<= |ULTIMATE.start_valid_product_#res#1| 1) (= ~__ste_Client_AddressBook2_Address1~0 0) (= ~bob~0 1) (= ~__ste_client_forwardReceiver1~0 0) (<= 1 |ULTIMATE.start_setup_bob__wrappee__Base_~bob___0#1|) (= ~__ste_Client_AddressBook1_Alias2~0 0) (<= 2 ~__ste_client_idCounter1~0) (= ~__ste_client_outbuffer0~0 0) (<= 2 |ULTIMATE.start_setup_rjh__wrappee__Base_~rjh___0#1|) (= ~queue_empty~0 1) (<= |ULTIMATE.start_setup_rjh__wrappee__Base_~rjh___0#1| 2) (= ~__SELECTED_FEATURE_Base~0 0) (= ~__ste_client_forwardReceiver0~0 0) (= ~__ste_Client_Keyring2_User0~0 0) (= ~rjh~0 2) (= 0 ~__ste_Client_AddressBook0_Address1~0) (= ~__ste_Client_AddressBook2_Address0~0 0) (= ~__ste_email_isSignatureVerified1~0 0) (= ~__ste_Client_Keyring1_PublicKey1~0 0) (<= ~__ste_client_privateKey0~0 123) (= ~__ste_Client_Keyring2_PublicKey0~0 0) (= ~__ste_Client_AddressBook1_Address0~0 0) (= ~__ste_client_name2~0.base 0) (= ~__ste_email_from1~0 0) (<= 2 |ULTIMATE.start_setup_rjh_#in~rjh___0#1|) (= ~__ste_email_subject1~0.base 0) (= ~__ste_Client_AddressBook1_Alias0~0 0) (= ~__ste_Client_Keyring2_User2~0 0) (<= |ULTIMATE.start_setup_bob__wrappee__Base_~bob___0#1| 1) (= ~head~0.base 0) (<= 2 |ULTIMATE.start_setup_rjh__wrappee__Base_#in~rjh___0#1|) (= ~__ste_Client_Keyring1_User1~0 0) (= |#NULL.offset| 0) (= ~__ste_Client_AddressBook2_Alias2~0 0) (= |ULTIMATE.start_valid_product_~retValue_acc~1#1| 1) (= ~__ste_email_subject1~0.offset 0) (= ~__ste_Client_AddressBook0_Alias2~0 0) (= ~__ste_ClientKeyring_size0~0 0) (= ~__ste_email_isEncrypted0~0 0) (= ~queued_message~0 0) (= ~__ste_Client_AddressBook1_Address1~0 0) (= 0 ~__ste_Client_AddressBook0_Address0~0) (= ~__ste_client_outbuffer1~0 0) (= ~__ste_Client_AddressBook0_Alias1~0 0) (= ~__GUIDSL_ROOT_PRODUCTION~0 0) (<= 123 ~__ste_client_privateKey0~0) (= ~chuck~0 0) (= ~__ste_client_name0~0.base 0) (= ~__ste_email_id1~0 0) (= ~__ste_client_outbuffer2~0 0) (<= 0 |#StackHeapBarrier|) (= ~__ste_ClientAddressBook_size2~0 0) (= ~__SELECTED_FEATURE_AutoResponder~0 0) (= ~__ste_email_encryptionKey1~0 0) (= ~__ste_client_autoResponse0~0 0) (= ~__ste_email_body1~0.base 0) (= ~__ste_ClientKeyring_size2~0 0) (= ~__ste_client_autoResponse2~0 0) (= |#NULL.base| 0) (= |ULTIMATE.start_main_~tmp~17#1| 1) (= ~__ste_email_signKey1~0 0)) [2022-12-14 09:04:34,651 INFO L895 garLoopResultBuilder]: At program point L2352-1(lines 2346 2356) the Hoare annotation is: (and (= ~__SELECTED_FEATURE_Sign~0 0) (= ~__ste_client_outbuffer3~0 0) (<= 1 |ULTIMATE.start_valid_product_#res#1|) (<= |ULTIMATE.start_setup_rjh__wrappee__Base_#in~rjh___0#1| 2) (<= 1 |ULTIMATE.start_setup_bob_#in~bob___0#1|) (= ~__ste_Client_counter~0 0) (<= |ULTIMATE.start_main_~retValue_acc~40#1| 2147483647) (<= |ULTIMATE.start_setup_bob__wrappee__Base_#in~bob___0#1| 1) (<= 2 |ULTIMATE.start_setup_rjh_~rjh___0#1|) (= ~__ste_Client_AddressBook2_Alias0~0 0) (<= 1 |ULTIMATE.start_setup_bob__wrappee__Base_#in~bob___0#1|) (= 0 ~__ste_email_subject0~0.base) (<= ~__ste_client_idCounter1~0 2) (<= |ULTIMATE.start_setup_bob_#in~bob___0#1| 1) (<= 0 ~__ste_ClientAddressBook_size0~0) (<= 2 ~rjh~0) (<= 0 ~__SELECTED_FEATURE_Encrypt~0) (<= 0 ~__ste_client_autoResponse1~0) (<= 0 ~__ste_client_outbuffer0~0) (<= ~__ste_Client_Keyring2_PublicKey2~0 0) (<= |ULTIMATE.start_setup_~__cil_tmp1~0#1.base| 19) (<= 0 ~__ste_client_outbuffer1~0) (<= 0 ~__ste_ClientAddressBook_size1~0) (<= ~queued_message~0 0) (<= ~__ste_email_isSignatureVerified0~0 0) (<= ~__ste_client_name0~0.base 0) (<= 0 ~__ste_Client_AddressBook0_Alias1~0) (= ~__ste_Client_AddressBook1_Address2~0 0) (<= 1 |ULTIMATE.start_setup_bob_~bob___0#1|) (<= ~chuck~0 0) (<= 0 ~__SELECTED_FEATURE_AutoResponder~0) (= ~__ste_email_body0~0.offset 0) (<= ~__SELECTED_FEATURE_Keys~0 0) (<= 0 ~__ste_email_isSigned1~0) (<= ~__SELECTED_FEATURE_Decrypt~0 0) (= ~__ste_Client_Keyring0_User2~0 0) (<= ~__ste_Client_Keyring1_PublicKey0~0 0) (= ~__ste_Client_Keyring0_User1~0 0) (= ~__ste_Client_AddressBook1_Alias1~0 0) (= ~__ste_client_name1~0.offset 0) (<= ~__GUIDSL_NON_TERMINAL_main~0 0) (<= ~__ste_Client_AddressBook2_Address0~0 0) (<= ~__SELECTED_FEATURE_AutoResponder~0 0) (<= ~__ste_email_id0~0 0) (<= 0 ~__ste_client_name2~0.offset) (= ~head~0.offset 0) (<= ~__GUIDSL_ROOT_PRODUCTION~0 0) (<= ~__ste_Client_AddressBook2_Alias1~0 0) (<= 0 ~__GUIDSL_ROOT_PRODUCTION~0) (= ~__ste_Client_Keyring0_PublicKey2~0 0) (<= ~__ste_Email_counter~0 0) (<= ~__ste_Client_Keyring2_User2~0 0) (<= ~__ste_email_body1~0.offset 0) (<= 0 ~__SELECTED_FEATURE_Decrypt~0) (<= 0 |ULTIMATE.start_setup_~__cil_tmp1~0#1.offset|) (<= 0 ~__ste_email_to0~0) (<= |ULTIMATE.start_setup_~__cil_tmp1~0#1.offset| 0) (<= 0 ~__ste_email_to1~0) (= ~__ste_email_signKey0~0 0) (<= 0 ~__ste_Client_AddressBook2_Alias1~0) (<= 0 ~__ste_Client_Keyring2_User2~0) (<= 0 ~__ste_Client_Keyring1_User2~0) (<= 0 ~__ste_email_from0~0) (<= 0 ~__ste_email_isEncrypted1~0) (<= |#NULL.offset| 0) (<= 0 ~__ste_Client_Keyring1_User0~0) (<= 0 ~__SELECTED_FEATURE_AddressBook~0) (= ~__ste_Client_Keyring0_PublicKey1~0 0) (<= 1 |ULTIMATE.start_valid_product_~retValue_acc~1#1|) (<= 0 ~__ste_email_from1~0) (= ~__SELECTED_FEATURE_Forward~0 0) (<= |ULTIMATE.start_setup_rjh_~rjh___0#1| 2) (= ~__ste_Client_Keyring0_User0~0 0) (= ~__ste_email_isSigned0~0 0) (= ~__ste_Client_Keyring2_PublicKey1~0 0) (<= 0 ~__ste_email_id1~0) (<= ~__ste_Client_AddressBook0_Address1~0 0) (= ~__ste_email_body0~0.base 0) (= ~__ste_Client_AddressBook0_Alias0~0 0) (<= 0 (+ 2147483648 |ULTIMATE.start_main_~retValue_acc~40#1|)) (<= 0 ~__ste_Client_AddressBook2_Address1~0) (<= 0 ~__ste_client_name0~0.offset) (<= ~__ste_Client_Keyring0_PublicKey0~0 0) (<= ~__ste_client_name1~0.base 0) (<= ~__ste_client_autoResponse0~0 0) (<= |ULTIMATE.start_setup_rjh_#in~rjh___0#1| 2) (<= ~__ste_email_to1~0 0) (<= ~__SELECTED_FEATURE_AddressBook~0 0) (<= ~__ste_Client_Keyring1_PublicKey2~0 0) (<= |ULTIMATE.start_setup_bob_~bob___0#1| 1) (<= 0 ~__ste_Client_Keyring0_PublicKey0~0) (<= ~__ste_client_forwardReceiver3~0 0) (= ~__ste_Client_AddressBook2_Address2~0 0) (<= ~__ste_ClientAddressBook_size0~0 0) (<= 0 ~__ste_Client_Keyring1_PublicKey2~0) (<= |ULTIMATE.start_valid_product_#res#1| 1) (<= ~__ste_Client_AddressBook0_Address0~0 0) (<= 0 ~__ste_client_name0~0.base) (<= 0 ~__ste_email_signKey1~0) (<= 0 ~__ste_email_body1~0.offset) (<= ~__ste_email_signKey1~0 0) (<= 0 ~__ste_client_forwardReceiver3~0) (<= ~__ste_client_name2~0.offset 0) (<= ~__ste_email_isSigned1~0 0) (<= ~__SELECTED_FEATURE_Encrypt~0 0) (<= 0 ~__ste_Email_counter~0) (<= ~__ste_email_subject0~0.offset 0) (= ~bob~0 1) (<= 0 ~__ste_client_autoResponse0~0) (<= 1 |ULTIMATE.start_setup_bob__wrappee__Base_~bob___0#1|) (<= 0 ~__ste_Client_AddressBook0_Alias2~0) (<= 0 ~queued_message~0) (<= 2 ~__ste_client_idCounter1~0) (<= ~__SELECTED_FEATURE_Verify~0 0) (<= ~__ste_ClientKeyring_size1~0 0) (<= ~__ste_Client_Keyring1_User2~0 0) (<= 2 |ULTIMATE.start_setup_rjh__wrappee__Base_~rjh___0#1|) (<= 0 ~chuck~0) (<= 0 ~head~0.base) (= ~queue_empty~0 1) (<= |ULTIMATE.start_setup_rjh__wrappee__Base_~rjh___0#1| 2) (= ~__SELECTED_FEATURE_Base~0 0) (<= ~__ste_Client_AddressBook1_Alias2~0 0) (<= 0 ~__ste_Client_AddressBook0_Address2~0) (= ~__ste_client_privateKey1~0 456) (= ~__ste_client_forwardReceiver0~0 0) (= ~__ste_Client_Keyring2_User0~0 0) (<= 0 ~__ste_email_subject0~0.offset) (<= ~__ste_email_from0~0 0) (<= 0 ~__ste_Client_AddressBook1_Alias0~0) (= ~__ste_email_isSignatureVerified1~0 0) (= ~__ste_Client_Keyring1_PublicKey1~0 0) (<= 0 ~queued_client~0) (<= 0 ~__SELECTED_FEATURE_Keys~0) (<= ~__ste_Client_AddressBook1_Alias0~0 0) (<= 0 ~__ste_Client_Keyring1_PublicKey0~0) (= ~__ste_Client_Keyring2_PublicKey0~0 0) (<= 0 ~__ste_email_isSignatureVerified0~0) (= ~__ste_Client_AddressBook1_Address0~0 0) (<= 0 ~__ste_ClientKeyring_size1~0) (<= 0 ~__ste_client_forwardReceiver2~0) (= ~__ste_client_name2~0.base 0) (<= 0 ~__ste_Client_AddressBook0_Address1~0) (<= 2 |ULTIMATE.start_setup_rjh_#in~rjh___0#1|) (<= ~__ste_email_encryptionKey0~0 0) (= ~__ste_email_subject1~0.base 0) (<= ~__ste_ClientKeyring_size0~0 0) (<= ~__ste_email_id1~0 0) (<= 0 ~__ste_Client_AddressBook0_Address0~0) (<= ~__ste_Client_Keyring1_User0~0 0) (<= ~__ste_Client_AddressBook0_Alias2~0 0) (<= ~__ste_Client_AddressBook0_Address2~0 0) (<= ~__ste_client_autoResponse1~0 0) (<= |ULTIMATE.start_setup_bob__wrappee__Base_~bob___0#1| 1) (<= ~__ste_client_outbuffer0~0 0) (<= ~__ste_email_from1~0 0) (<= ~head~0.base 0) (<= ~__ste_client_forwardReceiver1~0 0) (<= 2 |ULTIMATE.start_setup_rjh__wrappee__Base_#in~rjh___0#1|) (= ~__ste_Client_Keyring1_User1~0 0) (= ~__ste_Client_AddressBook2_Alias2~0 0) (<= ~__ste_email_to0~0 0) (<= ~__ste_Client_Keyring2_User1~0 0) (<= 0 ~__SELECTED_FEATURE_Verify~0) (<= 0 ~__ste_Client_AddressBook1_Alias2~0) (<= 0 ~__ste_client_autoResponse2~0) (= ~__ste_email_subject1~0.offset 0) (= ~__ste_email_isEncrypted0~0 0) (<= 0 ~__ste_Client_AddressBook2_Address0~0) (<= 0 ~__ste_Client_Keyring2_User1~0) (= ~__ste_Client_AddressBook1_Address1~0 0) (<= ~__ste_client_name0~0.offset 0) (<= 0 ~__ste_ClientKeyring_size0~0) (<= 19 |ULTIMATE.start_setup_~__cil_tmp1~0#1.base|) (<= ~__ste_email_isEncrypted1~0 0) (<= |ULTIMATE.start_valid_product_~retValue_acc~1#1| 1) (<= 0 |#NULL.offset|) (<= ~rjh~0 2) (<= ~__ste_Client_AddressBook0_Alias1~0 0) (<= 0 ~__ste_client_forwardReceiver1~0) (<= 0 ~__ste_Client_Keyring2_PublicKey2~0) (<= ~__ste_Client_AddressBook2_Address1~0 0) (= ~__ste_client_outbuffer2~0 0) (<= 0 ~__GUIDSL_NON_TERMINAL_main~0) (<= ~__ste_client_forwardReceiver2~0 0) (<= 0 |#StackHeapBarrier|) (= ~__ste_ClientAddressBook_size2~0 0) (<= ~__ste_client_autoResponse2~0 0) (= ~__ste_email_encryptionKey1~0 0) (= ~__ste_email_body1~0.base 0) (<= ~__ste_client_outbuffer1~0 0) (= ~__ste_ClientKeyring_size2~0 0) (<= ~__ste_ClientAddressBook_size1~0 0) (<= 0 ~__ste_client_name1~0.base) (<= 0 ~__ste_email_id0~0) (<= 0 ~__ste_email_encryptionKey0~0) (= |#NULL.base| 0) (= |ULTIMATE.start_main_~tmp~17#1| 1) (<= ~queued_client~0 0)) [2022-12-14 09:04:34,651 INFO L895 garLoopResultBuilder]: At program point L1064(line 1064) the Hoare annotation is: (and (= ~__ste_email_isSigned0~0 0) (= ~bob~0 1) (= ~queue_empty~0 1) (= ~__ste_email_isEncrypted0~0 0) (= |ULTIMATE.start_main_~tmp~17#1| 1)) [2022-12-14 09:04:34,651 INFO L899 garLoopResultBuilder]: For program point L1064-1(line 1064) no Hoare annotation was computed. [2022-12-14 09:04:34,651 INFO L899 garLoopResultBuilder]: For program point L998(lines 998 1002) no Hoare annotation was computed. [2022-12-14 09:04:34,652 INFO L895 garLoopResultBuilder]: At program point $Ultimate##78(lines 994 1077) the Hoare annotation is: (and (= ~__ste_email_isSigned0~0 0) (= ~bob~0 1) (= ~queue_empty~0 1) (= ~__ste_email_isEncrypted0~0 0) (= |ULTIMATE.start_main_~tmp~17#1| 1)) [2022-12-14 09:04:34,652 INFO L895 garLoopResultBuilder]: At program point $Ultimate##60(lines 952 1080) the Hoare annotation is: (and (= ~__ste_email_isSigned0~0 0) (= ~bob~0 1) (= ~queue_empty~0 1) (= ~__ste_email_isEncrypted0~0 0) (= |ULTIMATE.start_main_~tmp~17#1| 1)) [2022-12-14 09:04:34,652 INFO L899 garLoopResultBuilder]: For program point L1048(lines 1048 1055) no Hoare annotation was computed. [2022-12-14 09:04:34,652 INFO L895 garLoopResultBuilder]: At program point L2485(lines 2478 2489) the Hoare annotation is: (and (= ~__ste_email_isSigned0~0 0) (= ~bob~0 1) (= ~queue_empty~0 1) (= ~__ste_email_isEncrypted0~0 0) (= |ULTIMATE.start_main_~tmp~17#1| 1)) [2022-12-14 09:04:34,652 INFO L895 garLoopResultBuilder]: At program point L2386(line 2386) the Hoare annotation is: (and (= ~__ste_email_isSigned0~0 0) (= ~bob~0 1) (= ~queue_empty~0 1) (= ~__ste_email_isEncrypted0~0 0) (= |ULTIMATE.start_main_~tmp~17#1| 1)) [2022-12-14 09:04:34,655 INFO L895 garLoopResultBuilder]: At program point L2320(line 2320) the Hoare annotation is: (let ((.cse1 (select |#memory_int| 24)) (.cse0 (select |#memory_int| 23)) (.cse2 (select |#memory_int| 7)) (.cse3 (select |#memory_int| 1))) (and (= ~queued_client~0 0) (= 21 (select |#length| 13)) (= ~__ste_Client_Keyring1_User2~0 0) (= ~__GUIDSL_NON_TERMINAL_main~0 0) (= 13 (select |#length| 25)) (= (select |#length| 32) 30) (= |ULTIMATE.start_setup_bob_~bob___0#1| |ULTIMATE.start_setup_bob__wrappee__Base_#in~bob___0#1|) (= ~__ste_email_isEncrypted1~0 0) (= ~__ste_email_subject0~0.offset 0) (= (select |#valid| 30) 1) (= ~__SELECTED_FEATURE_Sign~0 0) (= 0 ~__ste_Client_AddressBook0_Address2~0) (= ~__ste_client_outbuffer3~0 0) (= (select |#length| 6) 20) (= 1 (select |#valid| 5)) (= (select |#length| 3) 12) (= (select |#valid| 15) 1) (= (select .cse0 0) 37) (= ~__ste_Client_counter~0 0) (= ~rjh~0 0) (= ~__ste_Client_Keyring1_PublicKey2~0 0) (<= |ULTIMATE.start_main_~retValue_acc~40#1| 2147483647) (= (select |#length| 37) 25) (= (select |#valid| 26) 1) (= (select |#length| 4) 10) (= 9 (select |#length| 30)) (= ~__ste_client_autoResponse1~0 0) (= ~__ste_Client_AddressBook2_Alias0~0 0) (= 0 ~__ste_email_subject0~0.base) (= ~__ste_Client_AddressBook2_Alias1~0 0) (= ~__ste_Client_Keyring2_PublicKey2~0 0) (= ~__ste_client_forwardReceiver3~0 0) (= (select |#valid| 35) 1) (= (select |#valid| 9) 1) (= ~__ste_client_name2~0.offset 0) (= ~__ste_client_name1~0.base 0) (= ~__SELECTED_FEATURE_Verify~0 0) (= ~__ste_Client_Keyring1_User0~0 0) (= 25 (select |#length| 34)) (= (select |#length| 11) 18) (= (select .cse1 0) 37) (= ~__ste_email_body1~0.offset 0) (= ~__SELECTED_FEATURE_Encrypt~0 0) (= (select |#valid| 11) 1) (= ~__ste_Client_AddressBook1_Address2~0 0) (= (select |#valid| 27) 1) (= 16 (select |#length| 12)) (= 9 (select |#length| 36)) (= ~__ste_ClientAddressBook_size1~0 0) (= ~__ste_Client_Keyring0_PublicKey0~0 0) (= (select |#length| 8) 10) (= ~__ste_Email_counter~0 0) (= (select |#valid| 33) 1) (= ~__ste_ClientKeyring_size1~0 0) (= ~__ste_email_body0~0.offset 0) (= ~__ste_email_isSignatureVerified0~0 0) (= ~__ste_Client_Keyring0_User2~0 0) (= |ULTIMATE.start_setup_bob_#in~bob___0#1| ~bob~0) (= ~__ste_ClientAddressBook_size0~0 0) (= ~__ste_Client_Keyring0_User1~0 0) (= ~__ste_Client_AddressBook1_Alias1~0 0) (= ~__ste_email_to1~0 0) (= ~__ste_client_name1~0.offset 0) (= (select .cse1 1) 100) (= ~__ste_client_privateKey1~0 0) (= ~head~0.offset 0) (= ~__ste_client_name0~0.offset 0) (= (select |#length| 7) 4) (= ~__ste_Client_Keyring0_PublicKey2~0 0) (= 2 (select |#length| 1)) (= ~__ste_client_idCounter1~0 0) (= ~__ste_Client_Keyring1_PublicKey0~0 0) (= ~__ste_email_to0~0 0) (= (select |#length| 10) 10) (= 44 (select |#length| 18)) (= (select |#valid| 3) 1) (= ~__ste_email_signKey0~0 0) (= (select |#valid| 7) 1) (= ~__SELECTED_FEATURE_Decrypt~0 0) (= ~__ste_email_encryptionKey0~0 0) (= (select .cse1 3) 0) (= ~__SELECTED_FEATURE_Keys~0 0) (= (select |#valid| 18) 1) (= (select |#length| 21) 11) (= (select |#valid| 22) 1) (= ~__SELECTED_FEATURE_AddressBook~0 0) (= ~__ste_client_forwardReceiver2~0 0) (= ~__ste_Client_Keyring0_PublicKey1~0 0) (= 30 (select |#length| 26)) (= ~__SELECTED_FEATURE_Forward~0 0) (= ~__ste_Client_Keyring0_User0~0 0) (= 25 (select |#length| 16)) (= ~__ste_email_isSigned0~0 0) (= ~__ste_Client_Keyring2_PublicKey1~0 0) (= ~__ste_email_isSigned1~0 0) (= (select |#length| 24) 4) (= 19 (select |#length| 22)) (= (select |#valid| 24) 1) (= ~__ste_email_body0~0.base 0) (= (select .cse0 1) 100) (= ~__ste_Client_AddressBook0_Alias0~0 0) (<= 0 (+ 2147483648 |ULTIMATE.start_main_~retValue_acc~40#1|)) (= ~__ste_email_id0~0 0) (= ~__ste_client_privateKey0~0 0) (= (select .cse2 0) 37) (= ~__ste_email_from0~0 0) (= ~__ste_Client_Keyring2_User1~0 0) (= (select |#valid| 12) 1) (= 9 (select |#length| 20)) (= (select |#length| 19) 9) (= (select |#valid| 32) 1) (= ~__ste_Client_AddressBook2_Address2~0 0) (= (select |#valid| 28) 1) (= ~__ste_Client_AddressBook2_Address1~0 0) (= (select .cse2 3) 0) (= ~bob~0 1) (= ~__ste_client_forwardReceiver1~0 0) (= (select |#valid| 37) 1) (= (select .cse1 2) 10) (= (select |#valid| 4) 1) (= 10 (select .cse0 2)) (= ~__ste_Client_AddressBook1_Alias2~0 0) (= ~__ste_client_outbuffer0~0 0) (= ~queue_empty~0 1) (= ~__SELECTED_FEATURE_Base~0 0) (= (select |#valid| 1) 1) (= ~__ste_client_forwardReceiver0~0 0) (= (select |#valid| 20) 1) (= 16 (select |#length| 5)) (= ~__ste_Client_Keyring2_User0~0 0) (= 0 ~__ste_Client_AddressBook0_Address1~0) (= (select |#length| 17) 44) (= ~__ste_Client_AddressBook2_Address0~0 0) (= ~__ste_email_isSignatureVerified1~0 0) (= ~__ste_Client_Keyring1_PublicKey1~0 0) (= |ULTIMATE.start_setup_bob__wrappee__Base_#in~bob___0#1| |ULTIMATE.start_setup_bob__wrappee__Base_~bob___0#1|) (= ~__ste_Client_Keyring2_PublicKey0~0 0) (= (select |#valid| 21) 1) (= ~__ste_Client_AddressBook1_Address0~0 0) (= ~__ste_client_idCounter2~0 0) (= ~__ste_client_name2~0.base 0) (= ~__ste_email_from1~0 0) (= 13 (select |#length| 14)) (= 28 (select |#length| 2)) (= (select |#valid| 14) 1) (= (select |#length| 9) 12) (= ~__ste_email_subject1~0.base 0) (= |ULTIMATE.start_valid_product_~retValue_acc~1#1| |ULTIMATE.start_valid_product_#res#1|) (= ~__ste_Client_AddressBook1_Alias0~0 0) (= (select |#valid| 0) 0) (= ~__ste_Client_Keyring2_User2~0 0) (= (select |#valid| 25) 1) (= ~head~0.base 0) (= (select .cse0 3) 0) (= (select .cse2 2) 10) (= ~__ste_client_privateKey2~0 0) (= ~__ste_Client_Keyring1_User1~0 0) (= (select |#valid| 2) 1) (= |#NULL.offset| 0) (= (select |#valid| 36) 1) (= ~__ste_Client_AddressBook2_Alias2~0 0) (= |ULTIMATE.start_valid_product_~retValue_acc~1#1| 1) (= (select |#length| 33) 9) (= (select |#length| 27) 9) (= (select .cse3 0) 48) (= ~__ste_email_subject1~0.offset 0) (= (select |#valid| 23) 1) (= ~__ste_Client_AddressBook0_Alias2~0 0) (= 30 (select |#length| 35)) (= ~__ste_ClientKeyring_size0~0 0) (= (select |#length| 15) 16) (= 4 (select |#length| 23)) (= ~__ste_email_isEncrypted0~0 0) (= ~queued_message~0 0) (= ~__ste_Client_AddressBook1_Address1~0 0) (= ~__ste_client_idCounter0~0 0) (= 0 ~__ste_Client_AddressBook0_Address0~0) (= ~__ste_client_outbuffer1~0 0) (= (select |#valid| 19) 1) (= 115 (select .cse2 1)) (= (select |#valid| 31) 1) (= (select |#valid| 34) 1) (= ~__ste_Client_AddressBook0_Alias1~0 0) (= ~__GUIDSL_ROOT_PRODUCTION~0 0) (= (select |#valid| 16) 1) (= 21 (select |#length| 31)) (= (select |#valid| 6) 1) (= ~chuck~0 0) (= (select .cse3 1) 0) (= ~__ste_client_name0~0.base 0) (= ~__ste_email_id1~0 0) (= |ULTIMATE.start_setup_bob_#in~bob___0#1| |ULTIMATE.start_setup_bob_~bob___0#1|) (= (select |#length| 28) 21) (= ~__ste_client_outbuffer2~0 0) (= (select |#valid| 29) 1) (= ~__ste_ClientAddressBook_size2~0 0) (= (select |#valid| 17) 1) (= (select |#valid| 10) 1) (= ~__SELECTED_FEATURE_AutoResponder~0 0) (= ~__ste_email_encryptionKey1~0 0) (= (select |#valid| 8) 1) (= ~__ste_client_autoResponse0~0 0) (= ~__ste_email_body1~0.base 0) (= ~__ste_ClientKeyring_size2~0 0) (= ~__ste_client_autoResponse2~0 0) (= 30 (select |#length| 29)) (= (select |#valid| 13) 1) (< 0 |#StackHeapBarrier|) (= |#NULL.base| 0) (= |ULTIMATE.start_main_~tmp~17#1| 1) (= ~__ste_email_signKey1~0 0))) [2022-12-14 09:04:34,655 INFO L895 garLoopResultBuilder]: At program point L2386-1(line 2386) the Hoare annotation is: (= ~queue_empty~0 1) [2022-12-14 09:04:34,656 INFO L895 garLoopResultBuilder]: At program point L2320-1(lines 2315 2324) the Hoare annotation is: (and (= ~queued_client~0 0) (= ~__ste_Client_Keyring1_User2~0 0) (= ~__GUIDSL_NON_TERMINAL_main~0 0) (= ~__ste_email_isEncrypted1~0 0) (= ~__ste_email_subject0~0.offset 0) (= ~__SELECTED_FEATURE_Sign~0 0) (= 0 ~__ste_Client_AddressBook0_Address2~0) (= ~__ste_client_outbuffer3~0 0) (<= 1 |ULTIMATE.start_valid_product_#res#1|) (<= 1 |ULTIMATE.start_setup_bob_#in~bob___0#1|) (= ~__ste_Client_counter~0 0) (= ~rjh~0 0) (= ~__ste_Client_Keyring1_PublicKey2~0 0) (<= |ULTIMATE.start_main_~retValue_acc~40#1| 2147483647) (<= |ULTIMATE.start_setup_bob__wrappee__Base_#in~bob___0#1| 1) (= ~__ste_client_autoResponse1~0 0) (= ~__ste_Client_AddressBook2_Alias0~0 0) (<= 1 |ULTIMATE.start_setup_bob__wrappee__Base_#in~bob___0#1|) (= 0 ~__ste_email_subject0~0.base) (= ~__ste_Client_AddressBook2_Alias1~0 0) (= ~__ste_Client_Keyring2_PublicKey2~0 0) (= ~__ste_client_forwardReceiver3~0 0) (<= |ULTIMATE.start_setup_bob_#in~bob___0#1| 1) (= ~__ste_client_name2~0.offset 0) (= ~__ste_client_name1~0.base 0) (= ~__SELECTED_FEATURE_Verify~0 0) (= ~__ste_Client_Keyring1_User0~0 0) (= ~__ste_email_body1~0.offset 0) (= ~__SELECTED_FEATURE_Encrypt~0 0) (= ~__ste_Client_AddressBook1_Address2~0 0) (<= 1 |ULTIMATE.start_setup_bob_~bob___0#1|) (= ~__ste_ClientAddressBook_size1~0 0) (= ~__ste_Client_Keyring0_PublicKey0~0 0) (= ~__ste_Email_counter~0 0) (= ~__ste_ClientKeyring_size1~0 0) (= ~__ste_email_body0~0.offset 0) (= ~__ste_email_isSignatureVerified0~0 0) (= ~__ste_Client_Keyring0_User2~0 0) (= ~__ste_ClientAddressBook_size0~0 0) (= ~__ste_Client_Keyring0_User1~0 0) (= ~__ste_Client_AddressBook1_Alias1~0 0) (= ~__ste_email_to1~0 0) (= ~__ste_client_name1~0.offset 0) (= ~__ste_client_privateKey1~0 0) (= ~head~0.offset 0) (= ~__ste_client_name0~0.offset 0) (= ~__ste_Client_Keyring0_PublicKey2~0 0) (= ~__ste_Client_Keyring1_PublicKey0~0 0) (= ~__ste_email_to0~0 0) (= ~__ste_email_signKey0~0 0) (= ~__SELECTED_FEATURE_Decrypt~0 0) (= ~__ste_email_encryptionKey0~0 0) (= ~__SELECTED_FEATURE_Keys~0 0) (= ~__SELECTED_FEATURE_AddressBook~0 0) (= ~__ste_client_forwardReceiver2~0 0) (= ~__ste_Client_Keyring0_PublicKey1~0 0) (= ~__SELECTED_FEATURE_Forward~0 0) (= ~__ste_Client_Keyring0_User0~0 0) (= ~__ste_email_isSigned0~0 0) (= ~__ste_Client_Keyring2_PublicKey1~0 0) (= ~__ste_email_isSigned1~0 0) (= ~__ste_email_body0~0.base 0) (= ~__ste_Client_AddressBook0_Alias0~0 0) (<= 0 (+ 2147483648 |ULTIMATE.start_main_~retValue_acc~40#1|)) (= ~__ste_email_id0~0 0) (= ~__ste_client_privateKey0~0 0) (= ~__ste_email_from0~0 0) (= ~__ste_Client_Keyring2_User1~0 0) (<= |ULTIMATE.start_setup_bob_~bob___0#1| 1) (= ~__ste_Client_AddressBook2_Address2~0 0) (<= |ULTIMATE.start_valid_product_#res#1| 1) (= ~__ste_Client_AddressBook2_Address1~0 0) (= ~bob~0 1) (= ~__ste_client_forwardReceiver1~0 0) (<= 1 |ULTIMATE.start_setup_bob__wrappee__Base_~bob___0#1|) (= ~__ste_Client_AddressBook1_Alias2~0 0) (= ~__ste_client_outbuffer0~0 0) (= ~queue_empty~0 1) (= ~__SELECTED_FEATURE_Base~0 0) (= ~__ste_client_forwardReceiver0~0 0) (= ~__ste_Client_Keyring2_User0~0 0) (= 0 ~__ste_Client_AddressBook0_Address1~0) (= ~__ste_Client_AddressBook2_Address0~0 0) (= ~__ste_email_isSignatureVerified1~0 0) (= ~__ste_Client_Keyring1_PublicKey1~0 0) (= ~__ste_Client_Keyring2_PublicKey0~0 0) (= ~__ste_Client_AddressBook1_Address0~0 0) (= ~__ste_client_name2~0.base 0) (= ~__ste_email_from1~0 0) (<= ~__ste_client_idCounter0~0 1) (= ~__ste_email_subject1~0.base 0) (= ~__ste_Client_AddressBook1_Alias0~0 0) (= ~__ste_Client_Keyring2_User2~0 0) (<= |ULTIMATE.start_setup_bob__wrappee__Base_~bob___0#1| 1) (= ~head~0.base 0) (= ~__ste_client_privateKey2~0 0) (= ~__ste_Client_Keyring1_User1~0 0) (= |#NULL.offset| 0) (= ~__ste_Client_AddressBook2_Alias2~0 0) (= |ULTIMATE.start_valid_product_~retValue_acc~1#1| 1) (= ~__ste_email_subject1~0.offset 0) (= ~__ste_Client_AddressBook0_Alias2~0 0) (= ~__ste_ClientKeyring_size0~0 0) (= ~__ste_email_isEncrypted0~0 0) (= ~queued_message~0 0) (= ~__ste_Client_AddressBook1_Address1~0 0) (= 0 ~__ste_Client_AddressBook0_Address0~0) (<= 1 ~__ste_client_idCounter0~0) (= ~__ste_client_outbuffer1~0 0) (= ~__ste_Client_AddressBook0_Alias1~0 0) (= ~__GUIDSL_ROOT_PRODUCTION~0 0) (= ~chuck~0 0) (= ~__ste_client_name0~0.base 0) (= ~__ste_email_id1~0 0) (= ~__ste_client_outbuffer2~0 0) (<= 0 |#StackHeapBarrier|) (= ~__ste_ClientAddressBook_size2~0 0) (= ~__SELECTED_FEATURE_AutoResponder~0 0) (= ~__ste_email_encryptionKey1~0 0) (= ~__ste_client_autoResponse0~0 0) (= ~__ste_email_body1~0.base 0) (= ~__ste_ClientKeyring_size2~0 0) (= ~__ste_client_autoResponse2~0 0) (= |#NULL.base| 0) (= |ULTIMATE.start_main_~tmp~17#1| 1) (= ~__ste_email_signKey1~0 0)) [2022-12-14 09:04:34,656 INFO L895 garLoopResultBuilder]: At program point $Ultimate##66(lines 966 1079) the Hoare annotation is: (and (= ~__ste_email_isSigned0~0 0) (= ~bob~0 1) (= ~queue_empty~0 1) (= ~__ste_email_isEncrypted0~0 0) (= |ULTIMATE.start_main_~tmp~17#1| 1)) [2022-12-14 09:04:34,657 INFO L899 garLoopResultBuilder]: For program point ULTIMATE.startEXIT(line -1) no Hoare annotation was computed. [2022-12-14 09:04:34,657 INFO L895 garLoopResultBuilder]: At program point $Ultimate##54(lines 941 1081) the Hoare annotation is: (and (= ~__ste_email_isSigned0~0 0) (= ~bob~0 1) (= ~queue_empty~0 1) (= ~__ste_email_isEncrypted0~0 0) (= |ULTIMATE.start_main_~tmp~17#1| 1)) [2022-12-14 09:04:34,657 INFO L895 garLoopResultBuilder]: At program point L2553-1(lines 2548 2557) the Hoare annotation is: (and (= ~__ste_email_isSigned0~0 0) (= ~bob~0 1) (= ~queue_empty~0 1) (= ~__ste_email_isEncrypted0~0 0) (= |ULTIMATE.start_main_~tmp~17#1| 1)) [2022-12-14 09:04:34,657 INFO L899 garLoopResultBuilder]: For program point L984(lines 984 991) no Hoare annotation was computed. [2022-12-14 09:04:34,657 INFO L895 garLoopResultBuilder]: At program point L2553(line 2553) the Hoare annotation is: (and (= ~__ste_email_isSigned0~0 0) (= ~bob~0 1) (= ~queue_empty~0 1) (= ~__ste_email_isEncrypted0~0 0) (= |ULTIMATE.start_main_~tmp~17#1| 1)) [2022-12-14 09:04:34,657 INFO L899 garLoopResultBuilder]: For program point L1034(lines 1034 1041) no Hoare annotation was computed. [2022-12-14 09:04:34,657 INFO L895 garLoopResultBuilder]: At program point L1084(lines 918 1085) the Hoare annotation is: (and (= ~__ste_email_isSigned0~0 0) (= ~bob~0 1) (= ~queue_empty~0 1) (= ~__ste_email_isEncrypted0~0 0) (= |ULTIMATE.start_main_~tmp~17#1| 1)) [2022-12-14 09:04:34,657 INFO L895 garLoopResultBuilder]: At program point L2389(lines 2389 2397) the Hoare annotation is: (and (<= 1 |ULTIMATE.start_bobToRjh_~tmp___1~4#1|) (= ~queue_empty~0 1)) [2022-12-14 09:04:34,659 INFO L895 garLoopResultBuilder]: At program point L2373-1(lines 2367 2377) the Hoare annotation is: (and (= ~queued_client~0 0) (= ~__ste_Client_Keyring1_User2~0 0) (= ~__GUIDSL_NON_TERMINAL_main~0 0) (<= 3 |ULTIMATE.start_setup_chuck__wrappee__Base_~chuck___0#1|) (= ~__ste_email_isEncrypted1~0 0) (= ~__ste_email_subject0~0.offset 0) (= ~__SELECTED_FEATURE_Sign~0 0) (= 0 ~__ste_Client_AddressBook0_Address2~0) (= |ULTIMATE.start_setup_~__cil_tmp2~0#1.offset| 0) (= ~__ste_client_outbuffer3~0 0) (<= 1 |ULTIMATE.start_valid_product_#res#1|) (<= |ULTIMATE.start_setup_rjh__wrappee__Base_#in~rjh___0#1| 2) (<= 1 |ULTIMATE.start_setup_bob_#in~bob___0#1|) (= 19 |ULTIMATE.start_setup_~__cil_tmp1~0#1.base|) (= ~__ste_Client_counter~0 0) (= ~__ste_Client_Keyring1_PublicKey2~0 0) (<= |ULTIMATE.start_main_~retValue_acc~40#1| 2147483647) (= |ULTIMATE.start_setup_~__cil_tmp2~0#1.base| 20) (<= |ULTIMATE.start_setup_bob__wrappee__Base_#in~bob___0#1| 1) (= ~__ste_client_autoResponse1~0 0) (<= 2 |ULTIMATE.start_setup_rjh_~rjh___0#1|) (= ~__ste_Client_AddressBook2_Alias0~0 0) (= |ULTIMATE.start_setup_~__cil_tmp1~0#1.offset| 0) (<= 1 |ULTIMATE.start_setup_bob__wrappee__Base_#in~bob___0#1|) (= 0 ~__ste_email_subject0~0.base) (= ~__ste_Client_AddressBook2_Alias1~0 0) (= ~__ste_Client_Keyring2_PublicKey2~0 0) (= ~__ste_client_forwardReceiver3~0 0) (<= |ULTIMATE.start_setup_bob_#in~bob___0#1| 1) (= ~__ste_client_name2~0.offset 0) (= ~__ste_client_name1~0.base 0) (<= |ULTIMATE.start_setup_chuck_#in~chuck___0#1| 3) (= ~__SELECTED_FEATURE_Verify~0 0) (= ~__ste_Client_Keyring1_User0~0 0) (<= ~__ste_client_idCounter2~0 3) (= ~__ste_email_body1~0.offset 0) (= ~__SELECTED_FEATURE_Encrypt~0 0) (= ~__ste_Client_AddressBook1_Address2~0 0) (<= 1 |ULTIMATE.start_setup_bob_~bob___0#1|) (= ~__ste_ClientAddressBook_size1~0 0) (= ~__ste_Client_Keyring0_PublicKey0~0 0) (= ~__ste_Email_counter~0 0) (= ~__ste_ClientKeyring_size1~0 0) (= ~__ste_email_body0~0.offset 0) (= ~__ste_email_isSignatureVerified0~0 0) (= ~__ste_Client_Keyring0_User2~0 0) (= ~__ste_ClientAddressBook_size0~0 0) (= ~__ste_Client_Keyring0_User1~0 0) (= ~__ste_Client_AddressBook1_Alias1~0 0) (= ~__ste_email_to1~0 0) (= ~__ste_client_name1~0.offset 0) (= ~head~0.offset 0) (= ~__ste_client_name0~0.offset 0) (= ~__ste_Client_Keyring0_PublicKey2~0 0) (= ~__ste_Client_Keyring1_PublicKey0~0 0) (= ~__ste_email_to0~0 0) (= 789 ~__ste_client_privateKey2~0) (= ~__ste_email_signKey0~0 0) (= ~__SELECTED_FEATURE_Decrypt~0 0) (= ~__SELECTED_FEATURE_Keys~0 0) (= ~__SELECTED_FEATURE_AddressBook~0 0) (= ~__ste_Client_Keyring0_PublicKey1~0 0) (= ~__SELECTED_FEATURE_Forward~0 0) (<= |ULTIMATE.start_setup_rjh_~rjh___0#1| 2) (= ~__ste_Client_Keyring0_User0~0 0) (= ~__ste_email_isSigned0~0 0) (= ~__ste_Client_Keyring2_PublicKey1~0 0) (= ~__ste_email_isSigned1~0 0) (= ~__ste_email_body0~0.base 0) (= ~__ste_Client_AddressBook0_Alias0~0 0) (<= 0 (+ 2147483648 |ULTIMATE.start_main_~retValue_acc~40#1|)) (= ~__ste_email_id0~0 0) (<= |ULTIMATE.start_setup_rjh_#in~rjh___0#1| 2) (= ~__ste_email_from0~0 0) (<= |ULTIMATE.start_setup_bob_~bob___0#1| 1) (<= 3 ~__ste_client_idCounter2~0) (= ~__ste_Client_AddressBook2_Address2~0 0) (<= |ULTIMATE.start_valid_product_#res#1| 1) (<= |ULTIMATE.start_setup_chuck__wrappee__Base_~chuck___0#1| 3) (= 3 ~chuck~0) (= ~__ste_Client_AddressBook2_Address1~0 0) (= ~bob~0 1) (<= 1 |ULTIMATE.start_setup_bob__wrappee__Base_~bob___0#1|) (<= 3 |ULTIMATE.start_setup_chuck_~chuck___0#1|) (= ~__ste_Client_AddressBook1_Alias2~0 0) (= ~__ste_client_outbuffer0~0 0) (<= 2 |ULTIMATE.start_setup_rjh__wrappee__Base_~rjh___0#1|) (= ~queue_empty~0 1) (<= |ULTIMATE.start_setup_rjh__wrappee__Base_~rjh___0#1| 2) (= ~__SELECTED_FEATURE_Base~0 0) (= ~__ste_client_forwardReceiver0~0 0) (<= 3 |ULTIMATE.start_setup_chuck_#in~chuck___0#1|) (= ~__ste_Client_Keyring2_User0~0 0) (= ~rjh~0 2) (= 0 ~__ste_Client_AddressBook0_Address1~0) (= ~__ste_Client_AddressBook2_Address0~0 0) (= ~__ste_email_isSignatureVerified1~0 0) (= ~__ste_Client_Keyring1_PublicKey1~0 0) (= ~__ste_Client_Keyring2_PublicKey0~0 0) (= ~__ste_Client_AddressBook1_Address0~0 0) (<= 0 ~__ste_client_forwardReceiver2~0) (= ~__ste_client_name2~0.base 0) (= ~__ste_email_from1~0 0) (<= 2 |ULTIMATE.start_setup_rjh_#in~rjh___0#1|) (<= ~__ste_email_encryptionKey0~0 0) (= ~__ste_email_subject1~0.base 0) (<= ~__ste_ClientKeyring_size0~0 0) (<= |ULTIMATE.start_setup_chuck__wrappee__Base_#in~chuck___0#1| 3) (= ~__ste_Client_AddressBook1_Alias0~0 0) (= ~__ste_Client_Keyring2_User2~0 0) (<= |ULTIMATE.start_setup_bob__wrappee__Base_~bob___0#1| 1) (= ~head~0.base 0) (<= |ULTIMATE.start_setup_chuck_~chuck___0#1| 3) (<= ~__ste_client_forwardReceiver1~0 0) (<= 2 |ULTIMATE.start_setup_rjh__wrappee__Base_#in~rjh___0#1|) (= ~__ste_Client_Keyring1_User1~0 0) (= |#NULL.offset| 0) (= ~__ste_Client_AddressBook2_Alias2~0 0) (<= ~__ste_Client_Keyring2_User1~0 0) (= |ULTIMATE.start_valid_product_~retValue_acc~1#1| 1) (<= 0 ~__ste_client_autoResponse2~0) (= ~__ste_email_subject1~0.offset 0) (= ~__ste_Client_AddressBook0_Alias2~0 0) (= ~__ste_email_isEncrypted0~0 0) (<= 0 ~__ste_Client_Keyring2_User1~0) (= ~queued_message~0 0) (= ~__ste_Client_AddressBook1_Address1~0 0) (= 0 ~__ste_Client_AddressBook0_Address0~0) (= ~__ste_client_outbuffer1~0 0) (= ~__ste_Client_AddressBook0_Alias1~0 0) (<= 0 ~__ste_ClientKeyring_size0~0) (= ~__GUIDSL_ROOT_PRODUCTION~0 0) (<= 3 |ULTIMATE.start_setup_chuck__wrappee__Base_#in~chuck___0#1|) (<= 0 ~__ste_client_forwardReceiver1~0) (= ~__ste_client_name0~0.base 0) (= ~__ste_email_id1~0 0) (= ~__ste_client_outbuffer2~0 0) (<= ~__ste_client_forwardReceiver2~0 0) (<= 0 |#StackHeapBarrier|) (= ~__ste_ClientAddressBook_size2~0 0) (= ~__SELECTED_FEATURE_AutoResponder~0 0) (<= ~__ste_client_autoResponse2~0 0) (= ~__ste_email_encryptionKey1~0 0) (= ~__ste_client_autoResponse0~0 0) (= ~__ste_email_body1~0.base 0) (= ~__ste_ClientKeyring_size2~0 0) (<= 0 ~__ste_email_encryptionKey0~0) (= |#NULL.base| 0) (= |ULTIMATE.start_main_~tmp~17#1| 1) (= ~__ste_email_signKey1~0 0)) [2022-12-14 09:04:34,661 INFO L895 garLoopResultBuilder]: At program point L2373(line 2373) the Hoare annotation is: (and (= ~queued_client~0 0) (= ~__ste_Client_Keyring1_User2~0 0) (= ~__GUIDSL_NON_TERMINAL_main~0 0) (<= 456 ~__ste_client_privateKey1~0) (<= 3 |ULTIMATE.start_setup_chuck__wrappee__Base_~chuck___0#1|) (= ~__ste_email_isEncrypted1~0 0) (= ~__ste_email_subject0~0.offset 0) (= ~__SELECTED_FEATURE_Sign~0 0) (= 0 ~__ste_Client_AddressBook0_Address2~0) (= |ULTIMATE.start_setup_~__cil_tmp2~0#1.offset| 0) (= ~__ste_client_outbuffer3~0 0) (<= 1 |ULTIMATE.start_valid_product_#res#1|) (<= |ULTIMATE.start_setup_rjh__wrappee__Base_#in~rjh___0#1| 2) (<= 1 |ULTIMATE.start_setup_bob_#in~bob___0#1|) (= 19 |ULTIMATE.start_setup_~__cil_tmp1~0#1.base|) (= ~__ste_Client_counter~0 0) (= ~__ste_Client_Keyring1_PublicKey2~0 0) (<= |ULTIMATE.start_main_~retValue_acc~40#1| 2147483647) (= |ULTIMATE.start_setup_~__cil_tmp2~0#1.base| 20) (<= |ULTIMATE.start_setup_bob__wrappee__Base_#in~bob___0#1| 1) (= ~__ste_client_autoResponse1~0 0) (<= 2 |ULTIMATE.start_setup_rjh_~rjh___0#1|) (= ~__ste_Client_AddressBook2_Alias0~0 0) (= |ULTIMATE.start_setup_~__cil_tmp1~0#1.offset| 0) (<= 1 |ULTIMATE.start_setup_bob__wrappee__Base_#in~bob___0#1|) (= 0 ~__ste_email_subject0~0.base) (= ~__ste_Client_AddressBook2_Alias1~0 0) (= ~__ste_Client_Keyring2_PublicKey2~0 0) (= ~__ste_client_forwardReceiver3~0 0) (<= |ULTIMATE.start_setup_bob_#in~bob___0#1| 1) (= ~__ste_client_name2~0.offset 0) (= ~__ste_client_name1~0.base 0) (<= |ULTIMATE.start_setup_chuck_#in~chuck___0#1| 3) (= ~__SELECTED_FEATURE_Verify~0 0) (= ~__ste_Client_Keyring1_User0~0 0) (<= ~__ste_client_idCounter2~0 3) (= ~__ste_email_body1~0.offset 0) (= ~__SELECTED_FEATURE_Encrypt~0 0) (= ~__ste_Client_AddressBook1_Address2~0 0) (<= 1 |ULTIMATE.start_setup_bob_~bob___0#1|) (= ~__ste_ClientAddressBook_size1~0 0) (= ~__ste_Client_Keyring0_PublicKey0~0 0) (= ~__ste_Email_counter~0 0) (= ~__ste_ClientKeyring_size1~0 0) (= ~__ste_email_body0~0.offset 0) (= ~__ste_email_isSignatureVerified0~0 0) (= ~__ste_Client_Keyring0_User2~0 0) (= ~__ste_ClientAddressBook_size0~0 0) (= ~__ste_Client_Keyring0_User1~0 0) (= ~__ste_Client_AddressBook1_Alias1~0 0) (= ~__ste_email_to1~0 0) (= ~__ste_client_name1~0.offset 0) (= ~head~0.offset 0) (= ~__ste_client_name0~0.offset 0) (= ~__ste_Client_Keyring0_PublicKey2~0 0) (= ~__ste_Client_Keyring1_PublicKey0~0 0) (= ~__ste_email_to0~0 0) (= ~__ste_email_signKey0~0 0) (= ~__SELECTED_FEATURE_Decrypt~0 0) (= ~__ste_email_encryptionKey0~0 0) (= ~__SELECTED_FEATURE_Keys~0 0) (= ~__SELECTED_FEATURE_AddressBook~0 0) (= ~__ste_client_forwardReceiver2~0 0) (= ~__ste_Client_Keyring0_PublicKey1~0 0) (= ~__SELECTED_FEATURE_Forward~0 0) (<= |ULTIMATE.start_setup_rjh_~rjh___0#1| 2) (= ~__ste_Client_Keyring0_User0~0 0) (= ~__ste_email_isSigned0~0 0) (= ~__ste_Client_Keyring2_PublicKey1~0 0) (= ~__ste_email_isSigned1~0 0) (= ~__ste_email_body0~0.base 0) (= ~__ste_Client_AddressBook0_Alias0~0 0) (<= 0 (+ 2147483648 |ULTIMATE.start_main_~retValue_acc~40#1|)) (= ~__ste_email_id0~0 0) (<= |ULTIMATE.start_setup_rjh_#in~rjh___0#1| 2) (<= ~__ste_client_privateKey1~0 456) (= ~__ste_email_from0~0 0) (= ~__ste_Client_Keyring2_User1~0 0) (<= |ULTIMATE.start_setup_bob_~bob___0#1| 1) (<= 3 ~__ste_client_idCounter2~0) (= ~__ste_Client_AddressBook2_Address2~0 0) (<= |ULTIMATE.start_valid_product_#res#1| 1) (<= |ULTIMATE.start_setup_chuck__wrappee__Base_~chuck___0#1| 3) (= 3 ~chuck~0) (= ~__ste_Client_AddressBook2_Address1~0 0) (= ~bob~0 1) (= ~__ste_client_forwardReceiver1~0 0) (<= 1 |ULTIMATE.start_setup_bob__wrappee__Base_~bob___0#1|) (<= 3 |ULTIMATE.start_setup_chuck_~chuck___0#1|) (= ~__ste_Client_AddressBook1_Alias2~0 0) (= ~__ste_client_outbuffer0~0 0) (<= 2 |ULTIMATE.start_setup_rjh__wrappee__Base_~rjh___0#1|) (= ~queue_empty~0 1) (<= |ULTIMATE.start_setup_rjh__wrappee__Base_~rjh___0#1| 2) (= ~__SELECTED_FEATURE_Base~0 0) (= ~__ste_client_forwardReceiver0~0 0) (<= 3 |ULTIMATE.start_setup_chuck_#in~chuck___0#1|) (= ~__ste_Client_Keyring2_User0~0 0) (= ~rjh~0 2) (= 0 ~__ste_Client_AddressBook0_Address1~0) (= ~__ste_Client_AddressBook2_Address0~0 0) (= ~__ste_email_isSignatureVerified1~0 0) (= ~__ste_Client_Keyring1_PublicKey1~0 0) (= ~__ste_Client_Keyring2_PublicKey0~0 0) (= ~__ste_Client_AddressBook1_Address0~0 0) (= ~__ste_client_name2~0.base 0) (= ~__ste_email_from1~0 0) (<= 2 |ULTIMATE.start_setup_rjh_#in~rjh___0#1|) (= ~__ste_email_subject1~0.base 0) (<= |ULTIMATE.start_setup_chuck__wrappee__Base_#in~chuck___0#1| 3) (= ~__ste_Client_AddressBook1_Alias0~0 0) (= ~__ste_Client_Keyring2_User2~0 0) (<= |ULTIMATE.start_setup_bob__wrappee__Base_~bob___0#1| 1) (= ~head~0.base 0) (<= |ULTIMATE.start_setup_chuck_~chuck___0#1| 3) (<= 2 |ULTIMATE.start_setup_rjh__wrappee__Base_#in~rjh___0#1|) (= ~__ste_Client_Keyring1_User1~0 0) (= |#NULL.offset| 0) (= ~__ste_Client_AddressBook2_Alias2~0 0) (= |ULTIMATE.start_valid_product_~retValue_acc~1#1| 1) (= ~__ste_email_subject1~0.offset 0) (= ~__ste_Client_AddressBook0_Alias2~0 0) (= ~__ste_ClientKeyring_size0~0 0) (= ~__ste_email_isEncrypted0~0 0) (= ~queued_message~0 0) (= ~__ste_Client_AddressBook1_Address1~0 0) (= 0 ~__ste_Client_AddressBook0_Address0~0) (= ~__ste_client_outbuffer1~0 0) (= ~__ste_Client_AddressBook0_Alias1~0 0) (= ~__GUIDSL_ROOT_PRODUCTION~0 0) (<= 3 |ULTIMATE.start_setup_chuck__wrappee__Base_#in~chuck___0#1|) (= ~__ste_client_name0~0.base 0) (= ~__ste_email_id1~0 0) (= ~__ste_client_outbuffer2~0 0) (<= 0 |#StackHeapBarrier|) (= ~__ste_ClientAddressBook_size2~0 0) (= ~__SELECTED_FEATURE_AutoResponder~0 0) (= ~__ste_email_encryptionKey1~0 0) (= ~__ste_client_autoResponse0~0 0) (= ~__ste_email_body1~0.base 0) (= ~__ste_ClientKeyring_size2~0 0) (= ~__ste_client_autoResponse2~0 0) (= |#NULL.base| 0) (= |ULTIMATE.start_main_~tmp~17#1| 1) (= ~__ste_email_signKey1~0 0)) [2022-12-14 09:04:34,661 INFO L899 garLoopResultBuilder]: For program point L920(lines 919 1083) no Hoare annotation was computed. [2022-12-14 09:04:34,661 INFO L895 garLoopResultBuilder]: At program point L1036(line 1036) the Hoare annotation is: (and (= ~__ste_email_isSigned0~0 0) (= ~bob~0 1) (= ~queue_empty~0 1) (= ~__ste_email_isEncrypted0~0 0) (= |ULTIMATE.start_main_~tmp~17#1| 1)) [2022-12-14 09:04:34,661 INFO L899 garLoopResultBuilder]: For program point L1036-1(line 1036) no Hoare annotation was computed. [2022-12-14 09:04:34,661 INFO L899 garLoopResultBuilder]: For program point L970(lines 970 977) no Hoare annotation was computed. [2022-12-14 09:04:34,662 INFO L895 garLoopResultBuilder]: At program point L2341-1(lines 2336 2345) the Hoare annotation is: (and (= ~queued_client~0 0) (= ~__ste_Client_Keyring1_User2~0 0) (= ~__GUIDSL_NON_TERMINAL_main~0 0) (= ~__ste_email_isEncrypted1~0 0) (= ~__ste_email_subject0~0.offset 0) (= ~__SELECTED_FEATURE_Sign~0 0) (= 0 ~__ste_Client_AddressBook0_Address2~0) (= ~__ste_client_outbuffer3~0 0) (<= 1 |ULTIMATE.start_valid_product_#res#1|) (<= |ULTIMATE.start_setup_rjh__wrappee__Base_#in~rjh___0#1| 2) (<= 1 |ULTIMATE.start_setup_bob_#in~bob___0#1|) (= 19 |ULTIMATE.start_setup_~__cil_tmp1~0#1.base|) (= ~__ste_Client_counter~0 0) (= ~__ste_Client_Keyring1_PublicKey2~0 0) (<= |ULTIMATE.start_main_~retValue_acc~40#1| 2147483647) (<= |ULTIMATE.start_setup_bob__wrappee__Base_#in~bob___0#1| 1) (= ~__ste_client_autoResponse1~0 0) (<= 2 |ULTIMATE.start_setup_rjh_~rjh___0#1|) (= ~__ste_Client_AddressBook2_Alias0~0 0) (= |ULTIMATE.start_setup_~__cil_tmp1~0#1.offset| 0) (<= 1 |ULTIMATE.start_setup_bob__wrappee__Base_#in~bob___0#1|) (= 0 ~__ste_email_subject0~0.base) (<= ~__ste_client_idCounter1~0 2) (= ~__ste_Client_AddressBook2_Alias1~0 0) (= ~__ste_Client_Keyring2_PublicKey2~0 0) (= ~__ste_client_forwardReceiver3~0 0) (<= |ULTIMATE.start_setup_bob_#in~bob___0#1| 1) (= ~__ste_client_name2~0.offset 0) (= ~__ste_client_name1~0.base 0) (= ~__SELECTED_FEATURE_Verify~0 0) (= ~__ste_Client_Keyring1_User0~0 0) (= ~__ste_email_body1~0.offset 0) (= ~__SELECTED_FEATURE_Encrypt~0 0) (= ~__ste_Client_AddressBook1_Address2~0 0) (<= 1 |ULTIMATE.start_setup_bob_~bob___0#1|) (= ~__ste_ClientAddressBook_size1~0 0) (= ~__ste_Client_Keyring0_PublicKey0~0 0) (= ~__ste_Email_counter~0 0) (= ~__ste_ClientKeyring_size1~0 0) (= ~__ste_email_body0~0.offset 0) (= ~__ste_email_isSignatureVerified0~0 0) (= ~__ste_Client_Keyring0_User2~0 0) (= ~__ste_ClientAddressBook_size0~0 0) (= ~__ste_Client_Keyring0_User1~0 0) (= ~__ste_Client_AddressBook1_Alias1~0 0) (= ~__ste_email_to1~0 0) (= ~__ste_client_name1~0.offset 0) (= ~head~0.offset 0) (= ~__ste_client_name0~0.offset 0) (= ~__ste_Client_Keyring0_PublicKey2~0 0) (= ~__ste_Client_Keyring1_PublicKey0~0 0) (= ~__ste_email_to0~0 0) (= ~__ste_email_signKey0~0 0) (= ~__SELECTED_FEATURE_Decrypt~0 0) (= ~__ste_email_encryptionKey0~0 0) (= ~__SELECTED_FEATURE_Keys~0 0) (= ~__SELECTED_FEATURE_AddressBook~0 0) (= ~__ste_client_forwardReceiver2~0 0) (= ~__ste_Client_Keyring0_PublicKey1~0 0) (= ~__SELECTED_FEATURE_Forward~0 0) (<= |ULTIMATE.start_setup_rjh_~rjh___0#1| 2) (= ~__ste_Client_Keyring0_User0~0 0) (= ~__ste_email_isSigned0~0 0) (= ~__ste_Client_Keyring2_PublicKey1~0 0) (= ~__ste_email_isSigned1~0 0) (= ~__ste_email_body0~0.base 0) (= ~__ste_Client_AddressBook0_Alias0~0 0) (<= 0 (+ 2147483648 |ULTIMATE.start_main_~retValue_acc~40#1|)) (= ~__ste_email_id0~0 0) (<= |ULTIMATE.start_setup_rjh_#in~rjh___0#1| 2) (= ~__ste_email_from0~0 0) (= ~__ste_Client_Keyring2_User1~0 0) (<= |ULTIMATE.start_setup_bob_~bob___0#1| 1) (= ~__ste_Client_AddressBook2_Address2~0 0) (<= |ULTIMATE.start_valid_product_#res#1| 1) (= ~__ste_Client_AddressBook2_Address1~0 0) (= ~bob~0 1) (= ~__ste_client_forwardReceiver1~0 0) (<= 1 |ULTIMATE.start_setup_bob__wrappee__Base_~bob___0#1|) (= ~__ste_Client_AddressBook1_Alias2~0 0) (<= 2 ~__ste_client_idCounter1~0) (= ~__ste_client_outbuffer0~0 0) (<= 2 |ULTIMATE.start_setup_rjh__wrappee__Base_~rjh___0#1|) (= ~queue_empty~0 1) (<= |ULTIMATE.start_setup_rjh__wrappee__Base_~rjh___0#1| 2) (= ~__SELECTED_FEATURE_Base~0 0) (= ~__ste_client_forwardReceiver0~0 0) (= ~__ste_Client_Keyring2_User0~0 0) (= ~rjh~0 2) (= 0 ~__ste_Client_AddressBook0_Address1~0) (= ~__ste_Client_AddressBook2_Address0~0 0) (= ~__ste_email_isSignatureVerified1~0 0) (= ~__ste_Client_Keyring1_PublicKey1~0 0) (<= ~__ste_client_privateKey0~0 123) (= ~__ste_Client_Keyring2_PublicKey0~0 0) (= ~__ste_Client_AddressBook1_Address0~0 0) (= ~__ste_client_name2~0.base 0) (= ~__ste_email_from1~0 0) (<= 2 |ULTIMATE.start_setup_rjh_#in~rjh___0#1|) (= ~__ste_email_subject1~0.base 0) (= ~__ste_Client_AddressBook1_Alias0~0 0) (= ~__ste_Client_Keyring2_User2~0 0) (<= |ULTIMATE.start_setup_bob__wrappee__Base_~bob___0#1| 1) (= ~head~0.base 0) (<= 2 |ULTIMATE.start_setup_rjh__wrappee__Base_#in~rjh___0#1|) (= ~__ste_Client_Keyring1_User1~0 0) (= |#NULL.offset| 0) (= ~__ste_Client_AddressBook2_Alias2~0 0) (= |ULTIMATE.start_valid_product_~retValue_acc~1#1| 1) (= ~__ste_email_subject1~0.offset 0) (= ~__ste_Client_AddressBook0_Alias2~0 0) (= ~__ste_ClientKeyring_size0~0 0) (= ~__ste_email_isEncrypted0~0 0) (= ~queued_message~0 0) (= ~__ste_Client_AddressBook1_Address1~0 0) (= 0 ~__ste_Client_AddressBook0_Address0~0) (= ~__ste_client_outbuffer1~0 0) (= ~__ste_Client_AddressBook0_Alias1~0 0) (= ~__GUIDSL_ROOT_PRODUCTION~0 0) (<= 123 ~__ste_client_privateKey0~0) (= ~chuck~0 0) (= ~__ste_client_name0~0.base 0) (= ~__ste_email_id1~0 0) (= ~__ste_client_outbuffer2~0 0) (<= 0 |#StackHeapBarrier|) (= ~__ste_ClientAddressBook_size2~0 0) (= ~__SELECTED_FEATURE_AutoResponder~0 0) (= ~__ste_email_encryptionKey1~0 0) (= ~__ste_client_autoResponse0~0 0) (= ~__ste_email_body1~0.base 0) (= ~__ste_ClientKeyring_size2~0 0) (= ~__ste_client_autoResponse2~0 0) (= |#NULL.base| 0) (= |ULTIMATE.start_main_~tmp~17#1| 1) (= ~__ste_email_signKey1~0 0)) [2022-12-14 09:04:34,664 INFO L895 garLoopResultBuilder]: At program point L2341(line 2341) the Hoare annotation is: (and (= ~__ste_Client_Keyring1_User2~0 0) (= ~__GUIDSL_NON_TERMINAL_main~0 0) (= ~__ste_email_isEncrypted1~0 0) (= ~__ste_email_subject0~0.offset 0) (= ~__SELECTED_FEATURE_Sign~0 0) (= ~__ste_client_outbuffer3~0 0) (<= 1 |ULTIMATE.start_valid_product_#res#1|) (<= 1 |ULTIMATE.start_setup_bob_#in~bob___0#1|) (= 19 |ULTIMATE.start_setup_~__cil_tmp1~0#1.base|) (= ~__ste_Client_counter~0 0) (= ~__ste_Client_Keyring1_PublicKey2~0 0) (<= |ULTIMATE.start_main_~retValue_acc~40#1| 2147483647) (<= |ULTIMATE.start_setup_bob__wrappee__Base_#in~bob___0#1| 1) (= ~__ste_client_autoResponse1~0 0) (= ~__ste_Client_AddressBook2_Alias0~0 0) (= |ULTIMATE.start_setup_~__cil_tmp1~0#1.offset| 0) (<= 1 |ULTIMATE.start_setup_bob__wrappee__Base_#in~bob___0#1|) (= 0 ~__ste_email_subject0~0.base) (= ~__ste_Client_AddressBook2_Alias1~0 0) (= ~__ste_Client_Keyring2_PublicKey2~0 0) (= ~__ste_client_forwardReceiver3~0 0) (<= |ULTIMATE.start_setup_bob_#in~bob___0#1| 1) (= ~__ste_client_name2~0.offset 0) (= ~__ste_client_name1~0.base 0) (= ~__ste_Client_Keyring1_User0~0 0) (= ~__ste_email_body1~0.offset 0) (= ~__SELECTED_FEATURE_Encrypt~0 0) (= ~__ste_Client_AddressBook1_Address2~0 0) (<= 1 |ULTIMATE.start_setup_bob_~bob___0#1|) (= ~__ste_ClientAddressBook_size1~0 0) (= ~__ste_Client_Keyring0_PublicKey0~0 0) (= ~__ste_Email_counter~0 0) (= ~__ste_email_body0~0.offset 0) (= ~__ste_email_isSignatureVerified0~0 0) (= ~__ste_Client_Keyring0_User2~0 0) (= ~__ste_ClientAddressBook_size0~0 0) (= ~__ste_Client_Keyring0_User1~0 0) (= ~__ste_Client_AddressBook1_Alias1~0 0) (= ~__ste_email_to1~0 0) (= ~__ste_client_name1~0.offset 0) (= ~head~0.offset 0) (= ~__ste_client_name0~0.offset 0) (= ~__ste_Client_Keyring0_PublicKey2~0 0) (= ~__ste_Client_Keyring1_PublicKey0~0 0) (= |ULTIMATE.start_setup_rjh_#in~rjh___0#1| ~rjh~0) (= ~__ste_email_to0~0 0) (= ~__ste_email_signKey0~0 0) (= ~__SELECTED_FEATURE_Decrypt~0 0) (= ~__SELECTED_FEATURE_Keys~0 0) (= ~__SELECTED_FEATURE_AddressBook~0 0) (= ~__ste_Client_Keyring0_PublicKey1~0 0) (= |ULTIMATE.start_setup_rjh_#in~rjh___0#1| |ULTIMATE.start_setup_rjh_~rjh___0#1|) (= ~__SELECTED_FEATURE_Forward~0 0) (= ~__ste_Client_Keyring0_User0~0 0) (= ~__ste_email_isSigned0~0 0) (= ~__ste_Client_Keyring2_PublicKey1~0 0) (= ~__ste_email_isSigned1~0 0) (= ~__ste_email_body0~0.base 0) (= ~__ste_Client_AddressBook0_Alias0~0 0) (<= 0 (+ 2147483648 |ULTIMATE.start_main_~retValue_acc~40#1|)) (= |ULTIMATE.start_setup_rjh__wrappee__Base_#in~rjh___0#1| |ULTIMATE.start_setup_rjh_~rjh___0#1|) (= ~__ste_email_id0~0 0) (= ~__ste_email_from0~0 0) (<= |ULTIMATE.start_setup_bob_~bob___0#1| 1) (= ~__ste_Client_AddressBook2_Address2~0 0) (<= |ULTIMATE.start_valid_product_#res#1| 1) (= ~__ste_Client_AddressBook2_Address1~0 0) (= ~bob~0 1) (<= 1 |ULTIMATE.start_setup_bob__wrappee__Base_~bob___0#1|) (= ~__ste_client_outbuffer0~0 0) (<= ~__SELECTED_FEATURE_Verify~0 0) (<= ~__ste_ClientKeyring_size1~0 0) (<= 0 ~head~0.base) (= ~queue_empty~0 1) (= ~__SELECTED_FEATURE_Base~0 0) (<= ~__ste_Client_AddressBook1_Alias2~0 0) (<= 0 ~__ste_Client_AddressBook0_Address2~0) (= ~__ste_client_forwardReceiver0~0 0) (= ~__ste_Client_Keyring2_User0~0 0) (= ~rjh~0 2) (= 0 ~__ste_Client_AddressBook0_Address1~0) (<= 0 ~__ste_Client_AddressBook1_Alias0~0) (= ~__ste_Client_AddressBook2_Address0~0 0) (= ~__ste_email_isSignatureVerified1~0 0) (= ~__ste_Client_Keyring1_PublicKey1~0 0) (<= 0 ~queued_client~0) (<= ~__ste_client_privateKey0~0 123) (<= ~__ste_Client_AddressBook1_Alias0~0 0) (= ~__ste_Client_Keyring2_PublicKey0~0 0) (= ~__ste_Client_AddressBook1_Address0~0 0) (<= 0 ~__ste_ClientKeyring_size1~0) (<= 0 ~__ste_client_forwardReceiver2~0) (= ~__ste_client_name2~0.base 0) (= ~__ste_email_from1~0 0) (<= ~__ste_email_encryptionKey0~0 0) (<= ~__ste_client_idCounter0~0 1) (= ~__ste_email_subject1~0.base 0) (<= ~__ste_ClientKeyring_size0~0 0) (<= ~__ste_Client_AddressBook0_Address2~0 0) (= ~__ste_Client_Keyring2_User2~0 0) (<= |ULTIMATE.start_setup_bob__wrappee__Base_~bob___0#1| 1) (<= ~head~0.base 0) (<= ~__ste_client_forwardReceiver1~0 0) (= ~__ste_Client_Keyring1_User1~0 0) (= |#NULL.offset| 0) (= ~__ste_Client_AddressBook2_Alias2~0 0) (<= ~__ste_Client_Keyring2_User1~0 0) (= |ULTIMATE.start_valid_product_~retValue_acc~1#1| 1) (<= 0 ~__SELECTED_FEATURE_Verify~0) (<= 0 ~__ste_Client_AddressBook1_Alias2~0) (<= 0 ~__ste_client_autoResponse2~0) (= ~__ste_email_subject1~0.offset 0) (= ~__ste_Client_AddressBook0_Alias2~0 0) (= ~__ste_email_isEncrypted0~0 0) (<= 0 ~__ste_Client_Keyring2_User1~0) (= ~queued_message~0 0) (= ~__ste_Client_AddressBook1_Address1~0 0) (= 0 ~__ste_Client_AddressBook0_Address0~0) (<= 1 ~__ste_client_idCounter0~0) (= ~__ste_client_outbuffer1~0 0) (= ~__ste_Client_AddressBook0_Alias1~0 0) (<= 0 ~__ste_ClientKeyring_size0~0) (= ~__GUIDSL_ROOT_PRODUCTION~0 0) (= |ULTIMATE.start_setup_rjh__wrappee__Base_#in~rjh___0#1| |ULTIMATE.start_setup_rjh__wrappee__Base_~rjh___0#1|) (<= 123 ~__ste_client_privateKey0~0) (= ~chuck~0 0) (<= 0 ~__ste_client_forwardReceiver1~0) (= ~__ste_client_name0~0.base 0) (= ~__ste_email_id1~0 0) (= ~__ste_client_outbuffer2~0 0) (<= ~__ste_client_forwardReceiver2~0 0) (<= 0 |#StackHeapBarrier|) (= ~__ste_ClientAddressBook_size2~0 0) (= ~__SELECTED_FEATURE_AutoResponder~0 0) (<= ~__ste_client_autoResponse2~0 0) (= ~__ste_email_encryptionKey1~0 0) (= ~__ste_client_autoResponse0~0 0) (= ~__ste_email_body1~0.base 0) (= ~__ste_ClientKeyring_size2~0 0) (<= 0 ~__ste_email_encryptionKey0~0) (= |#NULL.base| 0) (= |ULTIMATE.start_main_~tmp~17#1| 1) (= ~__ste_email_signKey1~0 0) (<= ~queued_client~0 0)) [2022-12-14 09:04:34,664 INFO L902 garLoopResultBuilder]: At program point $Ultimate##0(line -1) the Hoare annotation is: true [2022-12-14 09:04:34,664 INFO L899 garLoopResultBuilder]: For program point L956(lines 956 963) no Hoare annotation was computed. [2022-12-14 09:04:34,664 INFO L899 garLoopResultBuilder]: For program point L1023(lines 1023 1027) no Hoare annotation was computed. [2022-12-14 09:04:34,664 INFO L895 garLoopResultBuilder]: At program point L2543-1(lines 2538 2547) the Hoare annotation is: (and (= ~__ste_email_isSigned0~0 0) (= ~bob~0 1) (= ~queue_empty~0 1) (= ~__ste_email_isEncrypted0~0 0) (= |ULTIMATE.start_main_~tmp~17#1| 1)) [2022-12-14 09:04:34,664 INFO L895 garLoopResultBuilder]: At program point L2543(line 2543) the Hoare annotation is: (and (= ~__ste_email_isSigned0~0 0) (= ~bob~0 1) (= ~queue_empty~0 1) (= ~__ste_email_isEncrypted0~0 0) (= |ULTIMATE.start_main_~tmp~17#1| 1)) [2022-12-14 09:04:34,665 INFO L895 garLoopResultBuilder]: At program point $Ultimate##102(lines 1044 1073) the Hoare annotation is: (and (= ~__ste_email_isSigned0~0 0) (= ~bob~0 1) (= ~queue_empty~0 1) (= ~__ste_email_isEncrypted0~0 0) (= |ULTIMATE.start_main_~tmp~17#1| 1)) [2022-12-14 09:04:34,665 INFO L895 garLoopResultBuilder]: At program point $Ultimate##108(lines 1058 1072) the Hoare annotation is: (and (= ~__ste_email_isSigned0~0 0) (= ~bob~0 1) (= ~queue_empty~0 1) (= ~__ste_email_isEncrypted0~0 0) (= |ULTIMATE.start_main_~tmp~17#1| 1)) [2022-12-14 09:04:34,667 INFO L895 garLoopResultBuilder]: At program point L2362(line 2362) the Hoare annotation is: (and (<= 0 ~__SELECTED_FEATURE_Forward~0) (<= ~__ste_Client_Keyring0_PublicKey1~0 0) (<= 0 ~__ste_Client_AddressBook2_Address2~0) (<= 456 ~__ste_client_privateKey1~0) (<= 0 ~__SELECTED_FEATURE_Base~0) (<= ~head~0.offset 0) (<= ~__ste_Client_AddressBook1_Alias1~0 0) (<= 0 ~__ste_Client_Keyring2_User0~0) (<= 0 ~__ste_Client_Keyring0_User1~0) (<= 0 ~__ste_email_encryptionKey1~0) (<= ~__ste_Client_AddressBook1_Address0~0 0) (= |ULTIMATE.start_setup_~__cil_tmp2~0#1.offset| 0) (<= 1 |ULTIMATE.start_valid_product_#res#1|) (<= |ULTIMATE.start_setup_rjh__wrappee__Base_#in~rjh___0#1| 2) (<= 1 |ULTIMATE.start_setup_bob_#in~bob___0#1|) (<= ~__ste_email_subject1~0.base 0) (<= ~__ste_client_name2~0.base 0) (<= ~__ste_Client_AddressBook0_Alias0~0 0) (<= ~__ste_email_body0~0.offset 0) (<= ~__ste_client_name1~0.offset 0) (<= 0 |#NULL.base|) (<= ~__ste_ClientAddressBook_size2~0 0) (<= ~__ste_client_outbuffer3~0 0) (<= ~__ste_Client_Keyring1_User1~0 0) (<= 0 ~__ste_email_body1~0.base) (<= ~__ste_Client_counter~0 0) (= |ULTIMATE.start_setup_chuck_~chuck___0#1| |ULTIMATE.start_setup_chuck__wrappee__Base_#in~chuck___0#1|) (<= ~__ste_ClientKeyring_size2~0 0) (<= ~__SELECTED_FEATURE_Sign~0 0) (<= ~__ste_Client_Keyring1_PublicKey1~0 0) (<= 0 ~__ste_Client_AddressBook2_Alias2~0) (<= ~__ste_client_forwardReceiver0~0 0) (<= 0 ~__ste_Client_Keyring2_PublicKey1~0) (<= |ULTIMATE.start_main_~retValue_acc~40#1| 2147483647) (= |ULTIMATE.start_setup_~__cil_tmp2~0#1.base| 20) (<= |ULTIMATE.start_setup_bob__wrappee__Base_#in~bob___0#1| 1) (<= ~__ste_Client_Keyring2_PublicKey0~0 0) (<= ~__ste_email_encryptionKey1~0 0) (<= 0 ~__ste_email_subject0~0.base) (<= ~__ste_email_subject1~0.offset 0) (<= ~__ste_Client_AddressBook2_Alias0~0 0) (<= ~__ste_email_isSignatureVerified1~0 0) (<= 2 |ULTIMATE.start_setup_rjh_~rjh___0#1|) (<= 0 ~__ste_Client_AddressBook1_Address1~0) (<= 1 |ULTIMATE.start_setup_bob__wrappee__Base_#in~bob___0#1|) (<= ~__ste_client_idCounter1~0 2) (<= 0 ~__ste_email_signKey0~0) (<= ~__ste_Client_Keyring0_User0~0 0) (<= |ULTIMATE.start_setup_bob_#in~bob___0#1| 1) (<= ~__ste_Client_Keyring2_PublicKey1~0 0) (<= 0 ~__ste_Client_Keyring0_PublicKey2~0) (<= 0 ~__ste_ClientAddressBook_size0~0) (<= 2 ~rjh~0) (<= 0 ~__SELECTED_FEATURE_Encrypt~0) (<= 0 ~__ste_client_autoResponse1~0) (<= 0 ~__ste_client_outbuffer0~0) (<= ~__ste_Client_Keyring2_PublicKey2~0 0) (<= 0 ~head~0.offset) (<= |ULTIMATE.start_setup_~__cil_tmp1~0#1.base| 19) (<= 0 ~__ste_client_outbuffer1~0) (<= 0 ~__ste_ClientAddressBook_size1~0) (<= ~queued_message~0 0) (<= ~__ste_email_isSignatureVerified0~0 0) (<= ~__SELECTED_FEATURE_Base~0 0) (<= ~__ste_client_name0~0.base 0) (<= 0 ~__ste_Client_AddressBook0_Alias1~0) (= ~__ste_Client_AddressBook1_Address2~0 0) (<= 1 |ULTIMATE.start_setup_bob_~bob___0#1|) (<= 0 ~__ste_Client_Keyring0_User0~0) (<= 0 ~__SELECTED_FEATURE_AutoResponder~0) (<= ~__SELECTED_FEATURE_Keys~0 0) (<= 0 ~__ste_email_isSigned1~0) (<= ~__SELECTED_FEATURE_Decrypt~0 0) (= |ULTIMATE.start_setup_chuck_#in~chuck___0#1| ~chuck~0) (= ~__ste_Client_Keyring0_User2~0 0) (<= 0 ~__ste_ClientKeyring_size2~0) (<= ~__ste_Client_Keyring1_PublicKey0~0 0) (<= 0 ~__ste_Client_Keyring1_User1~0) (<= ~__GUIDSL_NON_TERMINAL_main~0 0) (<= 0 ~__ste_ClientAddressBook_size2~0) (<= ~__ste_email_signKey0~0 0) (<= 0 ~__SELECTED_FEATURE_Sign~0) (<= ~__ste_Client_AddressBook2_Address0~0 0) (<= ~__SELECTED_FEATURE_AutoResponder~0 0) (<= ~__ste_email_id0~0 0) (<= 0 ~__ste_client_name2~0.offset) (<= ~__GUIDSL_ROOT_PRODUCTION~0 0) (<= ~__ste_Client_AddressBook2_Alias1~0 0) (<= 0 ~__GUIDSL_ROOT_PRODUCTION~0) (<= ~__ste_Email_counter~0 0) (<= ~__SELECTED_FEATURE_Forward~0 0) (<= ~__ste_email_subject0~0.base 0) (<= ~__ste_Client_Keyring2_User2~0 0) (<= ~__ste_email_body1~0.offset 0) (<= 0 ~__SELECTED_FEATURE_Decrypt~0) (<= 0 |ULTIMATE.start_setup_~__cil_tmp1~0#1.offset|) (<= ~__ste_Client_AddressBook2_Alias2~0 0) (<= 0 ~__ste_email_to0~0) (<= |ULTIMATE.start_setup_~__cil_tmp1~0#1.offset| 0) (<= 0 ~__ste_email_to1~0) (<= 0 ~__ste_Client_AddressBook2_Alias1~0) (<= 0 ~__ste_Client_Keyring2_User2~0) (<= 0 ~__ste_Client_Keyring1_User2~0) (<= 0 ~__ste_email_from0~0) (<= 0 ~__ste_email_subject1~0.offset) (<= 0 ~__ste_email_isEncrypted1~0) (= |ULTIMATE.start_setup_chuck_#in~chuck___0#1| |ULTIMATE.start_setup_chuck_~chuck___0#1|) (<= |#NULL.offset| 0) (<= 0 ~__ste_Client_Keyring1_User0~0) (<= 0 ~__ste_Client_counter~0) (<= 0 ~__SELECTED_FEATURE_AddressBook~0) (= |ULTIMATE.start_setup_chuck__wrappee__Base_~chuck___0#1| |ULTIMATE.start_setup_chuck__wrappee__Base_#in~chuck___0#1|) (<= 1 |ULTIMATE.start_valid_product_~retValue_acc~1#1|) (<= 0 ~__ste_email_from1~0) (<= |ULTIMATE.start_setup_rjh_~rjh___0#1| 2) (<= 0 ~__ste_Client_Keyring0_PublicKey1~0) (= ~__ste_email_isSigned0~0 0) (<= ~__ste_Client_Keyring0_PublicKey2~0 0) (<= 0 ~__ste_email_id1~0) (<= ~__ste_Client_AddressBook0_Address1~0 0) (= ~__ste_email_body0~0.base 0) (<= 0 ~__ste_Client_AddressBook1_Address0~0) (<= 0 (+ 2147483648 |ULTIMATE.start_main_~retValue_acc~40#1|)) (<= 0 ~__ste_Client_AddressBook2_Address1~0) (<= 0 ~__ste_client_name0~0.offset) (<= ~__ste_Client_Keyring0_PublicKey0~0 0) (<= ~__ste_client_name1~0.base 0) (<= 0 ~__ste_Client_AddressBook1_Alias1~0) (<= ~__ste_client_autoResponse0~0 0) (<= |ULTIMATE.start_setup_rjh_#in~rjh___0#1| 2) (<= ~__ste_client_privateKey1~0 456) (<= ~__ste_email_to1~0 0) (<= ~__SELECTED_FEATURE_AddressBook~0 0) (<= 0 ~__ste_Client_AddressBook0_Alias0~0) (<= 0 ~__ste_Client_Keyring2_PublicKey0~0) (<= ~__ste_Client_Keyring1_PublicKey2~0 0) (<= |ULTIMATE.start_setup_bob_~bob___0#1| 1) (<= 0 ~__ste_Client_Keyring0_PublicKey0~0) (<= ~__ste_client_forwardReceiver3~0 0) (<= ~__ste_ClientAddressBook_size0~0 0) (<= 0 ~__ste_Client_Keyring1_PublicKey2~0) (<= |ULTIMATE.start_valid_product_#res#1| 1) (<= ~__ste_Client_AddressBook0_Address0~0 0) (= 3 ~chuck~0) (<= 0 ~__ste_client_name0~0.base) (<= 0 ~__ste_email_signKey1~0) (<= 0 ~__ste_email_body1~0.offset) (<= ~__ste_email_signKey1~0 0) (<= 0 ~__ste_client_forwardReceiver3~0) (<= ~__ste_client_name2~0.offset 0) (<= ~__ste_email_isSigned1~0 0) (<= ~__SELECTED_FEATURE_Encrypt~0 0) (<= 0 ~__ste_Email_counter~0) (<= ~__ste_email_subject0~0.offset 0) (= ~bob~0 1) (<= 0 ~__ste_client_autoResponse0~0) (<= ~__ste_Client_AddressBook2_Address2~0 0) (<= 1 |ULTIMATE.start_setup_bob__wrappee__Base_~bob___0#1|) (<= 0 ~__ste_Client_AddressBook0_Alias2~0) (<= 0 ~queued_message~0) (<= 2 ~__ste_client_idCounter1~0) (<= 0 ~__ste_email_isSignatureVerified1~0) (<= ~__SELECTED_FEATURE_Verify~0 0) (<= 0 ~__ste_email_body0~0.offset) (<= ~__ste_ClientKeyring_size1~0 0) (<= ~__ste_Client_Keyring1_User2~0 0) (<= 2 |ULTIMATE.start_setup_rjh__wrappee__Base_~rjh___0#1|) (<= 0 ~head~0.base) (= ~queue_empty~0 1) (<= |ULTIMATE.start_setup_rjh__wrappee__Base_~rjh___0#1| 2) (<= ~__ste_Client_AddressBook1_Alias2~0 0) (<= 0 ~__ste_Client_AddressBook0_Address2~0) (<= 0 ~__ste_Client_Keyring1_PublicKey1~0) (<= 0 ~__ste_email_subject0~0.offset) (<= ~__ste_email_from0~0 0) (<= 0 ~__ste_Client_AddressBook1_Alias0~0) (<= 0 ~queued_client~0) (<= 0 ~__ste_client_forwardReceiver0~0) (<= 0 ~__SELECTED_FEATURE_Keys~0) (<= ~__ste_Client_AddressBook1_Alias0~0 0) (<= 0 ~__ste_Client_Keyring1_PublicKey0~0) (<= 0 ~__ste_email_isSignatureVerified0~0) (<= 0 ~__ste_email_subject1~0.base) (<= 0 ~__ste_ClientKeyring_size1~0) (<= |#NULL.base| 0) (<= 0 ~__ste_client_forwardReceiver2~0) (<= 0 ~__ste_Client_AddressBook0_Address1~0) (<= 2 |ULTIMATE.start_setup_rjh_#in~rjh___0#1|) (<= ~__ste_email_encryptionKey0~0 0) (<= ~__ste_ClientKeyring_size0~0 0) (<= ~__ste_email_id1~0 0) (<= 0 ~__ste_Client_AddressBook0_Address0~0) (<= ~__ste_Client_Keyring1_User0~0 0) (<= ~__ste_Client_AddressBook0_Alias2~0 0) (<= ~__ste_Client_AddressBook0_Address2~0 0) (<= ~__ste_client_autoResponse1~0 0) (<= |ULTIMATE.start_setup_bob__wrappee__Base_~bob___0#1| 1) (<= ~__ste_client_outbuffer0~0 0) (<= ~__ste_email_from1~0 0) (<= ~__ste_Client_Keyring0_User1~0 0) (<= ~head~0.base 0) (<= 0 ~__ste_client_name1~0.offset) (<= ~__ste_client_forwardReceiver1~0 0) (<= 2 |ULTIMATE.start_setup_rjh__wrappee__Base_#in~rjh___0#1|) (<= ~__ste_email_to0~0 0) (<= ~__ste_Client_Keyring2_User1~0 0) (<= 0 ~__SELECTED_FEATURE_Verify~0) (<= 0 ~__ste_Client_AddressBook1_Alias2~0) (<= 0 ~__ste_client_autoResponse2~0) (= ~__ste_email_isEncrypted0~0 0) (<= 0 ~__ste_Client_AddressBook2_Address0~0) (<= 0 ~__ste_Client_Keyring2_User1~0) (<= ~__ste_client_name0~0.offset 0) (<= 0 ~__ste_client_outbuffer3~0) (<= 0 ~__ste_client_name2~0.base) (<= 0 ~__ste_ClientKeyring_size0~0) (<= 19 |ULTIMATE.start_setup_~__cil_tmp1~0#1.base|) (<= ~__ste_email_isEncrypted1~0 0) (<= |ULTIMATE.start_valid_product_~retValue_acc~1#1| 1) (<= 0 |#NULL.offset|) (<= ~rjh~0 2) (<= ~__ste_Client_AddressBook1_Address1~0 0) (<= 0 ~__ste_Client_AddressBook2_Alias0~0) (<= ~__ste_Client_AddressBook0_Alias1~0 0) (<= 0 ~__ste_client_forwardReceiver1~0) (<= 0 ~__ste_Client_Keyring2_PublicKey2~0) (<= ~__ste_Client_AddressBook2_Address1~0 0) (= ~__ste_client_outbuffer2~0 0) (<= ~__ste_Client_Keyring2_User0~0 0) (<= 0 ~__GUIDSL_NON_TERMINAL_main~0) (<= ~__ste_client_forwardReceiver2~0 0) (<= 0 |#StackHeapBarrier|) (<= ~__ste_client_autoResponse2~0 0) (<= ~__ste_client_outbuffer1~0 0) (<= ~__ste_ClientAddressBook_size1~0 0) (<= 0 ~__ste_client_name1~0.base) (<= 0 ~__ste_email_id0~0) (<= 0 ~__ste_email_encryptionKey0~0) (= |ULTIMATE.start_main_~tmp~17#1| 1) (<= ~__ste_email_body1~0.base 0) (<= ~queued_client~0 0)) [2022-12-14 09:04:34,667 INFO L902 garLoopResultBuilder]: At program point L2395-1(lines 2378 2400) the Hoare annotation is: true [2022-12-14 09:04:34,667 INFO L895 garLoopResultBuilder]: At program point L2395(line 2395) the Hoare annotation is: false [2022-12-14 09:04:34,669 INFO L895 garLoopResultBuilder]: At program point L2362-1(lines 2357 2366) the Hoare annotation is: (and (= ~queued_client~0 0) (= ~__ste_Client_Keyring1_User2~0 0) (= ~__GUIDSL_NON_TERMINAL_main~0 0) (<= 456 ~__ste_client_privateKey1~0) (<= 3 |ULTIMATE.start_setup_chuck__wrappee__Base_~chuck___0#1|) (= ~__ste_email_isEncrypted1~0 0) (= ~__ste_email_subject0~0.offset 0) (= ~__SELECTED_FEATURE_Sign~0 0) (= 0 ~__ste_Client_AddressBook0_Address2~0) (= |ULTIMATE.start_setup_~__cil_tmp2~0#1.offset| 0) (= ~__ste_client_outbuffer3~0 0) (<= 1 |ULTIMATE.start_valid_product_#res#1|) (<= |ULTIMATE.start_setup_rjh__wrappee__Base_#in~rjh___0#1| 2) (<= 1 |ULTIMATE.start_setup_bob_#in~bob___0#1|) (= 19 |ULTIMATE.start_setup_~__cil_tmp1~0#1.base|) (= ~__ste_Client_counter~0 0) (= ~__ste_Client_Keyring1_PublicKey2~0 0) (<= |ULTIMATE.start_main_~retValue_acc~40#1| 2147483647) (= |ULTIMATE.start_setup_~__cil_tmp2~0#1.base| 20) (<= |ULTIMATE.start_setup_bob__wrappee__Base_#in~bob___0#1| 1) (= ~__ste_client_autoResponse1~0 0) (<= 2 |ULTIMATE.start_setup_rjh_~rjh___0#1|) (= ~__ste_Client_AddressBook2_Alias0~0 0) (= |ULTIMATE.start_setup_~__cil_tmp1~0#1.offset| 0) (<= 1 |ULTIMATE.start_setup_bob__wrappee__Base_#in~bob___0#1|) (= 0 ~__ste_email_subject0~0.base) (= ~__ste_Client_AddressBook2_Alias1~0 0) (= ~__ste_Client_Keyring2_PublicKey2~0 0) (= ~__ste_client_forwardReceiver3~0 0) (<= |ULTIMATE.start_setup_bob_#in~bob___0#1| 1) (= ~__ste_client_name2~0.offset 0) (= ~__ste_client_name1~0.base 0) (<= |ULTIMATE.start_setup_chuck_#in~chuck___0#1| 3) (= ~__SELECTED_FEATURE_Verify~0 0) (= ~__ste_Client_Keyring1_User0~0 0) (<= ~__ste_client_idCounter2~0 3) (= ~__ste_email_body1~0.offset 0) (= ~__SELECTED_FEATURE_Encrypt~0 0) (= ~__ste_Client_AddressBook1_Address2~0 0) (<= 1 |ULTIMATE.start_setup_bob_~bob___0#1|) (= ~__ste_ClientAddressBook_size1~0 0) (= ~__ste_Client_Keyring0_PublicKey0~0 0) (= ~__ste_Email_counter~0 0) (= ~__ste_ClientKeyring_size1~0 0) (= ~__ste_email_body0~0.offset 0) (= ~__ste_email_isSignatureVerified0~0 0) (= ~__ste_Client_Keyring0_User2~0 0) (= ~__ste_ClientAddressBook_size0~0 0) (= ~__ste_Client_Keyring0_User1~0 0) (= ~__ste_Client_AddressBook1_Alias1~0 0) (= ~__ste_email_to1~0 0) (= ~__ste_client_name1~0.offset 0) (= ~head~0.offset 0) (= ~__ste_client_name0~0.offset 0) (= ~__ste_Client_Keyring0_PublicKey2~0 0) (= ~__ste_Client_Keyring1_PublicKey0~0 0) (= ~__ste_email_to0~0 0) (= ~__ste_email_signKey0~0 0) (= ~__SELECTED_FEATURE_Decrypt~0 0) (= ~__ste_email_encryptionKey0~0 0) (= ~__SELECTED_FEATURE_Keys~0 0) (= ~__SELECTED_FEATURE_AddressBook~0 0) (= ~__ste_client_forwardReceiver2~0 0) (= ~__ste_Client_Keyring0_PublicKey1~0 0) (= ~__SELECTED_FEATURE_Forward~0 0) (<= |ULTIMATE.start_setup_rjh_~rjh___0#1| 2) (= ~__ste_Client_Keyring0_User0~0 0) (= ~__ste_email_isSigned0~0 0) (= ~__ste_Client_Keyring2_PublicKey1~0 0) (= ~__ste_email_isSigned1~0 0) (= ~__ste_email_body0~0.base 0) (= ~__ste_Client_AddressBook0_Alias0~0 0) (<= 0 (+ 2147483648 |ULTIMATE.start_main_~retValue_acc~40#1|)) (= ~__ste_email_id0~0 0) (<= |ULTIMATE.start_setup_rjh_#in~rjh___0#1| 2) (<= ~__ste_client_privateKey1~0 456) (= ~__ste_email_from0~0 0) (= ~__ste_Client_Keyring2_User1~0 0) (<= |ULTIMATE.start_setup_bob_~bob___0#1| 1) (<= 3 ~__ste_client_idCounter2~0) (= ~__ste_Client_AddressBook2_Address2~0 0) (<= |ULTIMATE.start_valid_product_#res#1| 1) (<= |ULTIMATE.start_setup_chuck__wrappee__Base_~chuck___0#1| 3) (= 3 ~chuck~0) (= ~__ste_Client_AddressBook2_Address1~0 0) (= ~bob~0 1) (= ~__ste_client_forwardReceiver1~0 0) (<= 1 |ULTIMATE.start_setup_bob__wrappee__Base_~bob___0#1|) (<= 3 |ULTIMATE.start_setup_chuck_~chuck___0#1|) (= ~__ste_Client_AddressBook1_Alias2~0 0) (= ~__ste_client_outbuffer0~0 0) (<= 2 |ULTIMATE.start_setup_rjh__wrappee__Base_~rjh___0#1|) (= ~queue_empty~0 1) (<= |ULTIMATE.start_setup_rjh__wrappee__Base_~rjh___0#1| 2) (= ~__SELECTED_FEATURE_Base~0 0) (= ~__ste_client_forwardReceiver0~0 0) (<= 3 |ULTIMATE.start_setup_chuck_#in~chuck___0#1|) (= ~__ste_Client_Keyring2_User0~0 0) (= ~rjh~0 2) (= 0 ~__ste_Client_AddressBook0_Address1~0) (= ~__ste_Client_AddressBook2_Address0~0 0) (= ~__ste_email_isSignatureVerified1~0 0) (= ~__ste_Client_Keyring1_PublicKey1~0 0) (= ~__ste_Client_Keyring2_PublicKey0~0 0) (= ~__ste_Client_AddressBook1_Address0~0 0) (= ~__ste_client_name2~0.base 0) (= ~__ste_email_from1~0 0) (<= 2 |ULTIMATE.start_setup_rjh_#in~rjh___0#1|) (= ~__ste_email_subject1~0.base 0) (<= |ULTIMATE.start_setup_chuck__wrappee__Base_#in~chuck___0#1| 3) (= ~__ste_Client_AddressBook1_Alias0~0 0) (= ~__ste_Client_Keyring2_User2~0 0) (<= |ULTIMATE.start_setup_bob__wrappee__Base_~bob___0#1| 1) (= ~head~0.base 0) (<= |ULTIMATE.start_setup_chuck_~chuck___0#1| 3) (<= 2 |ULTIMATE.start_setup_rjh__wrappee__Base_#in~rjh___0#1|) (= ~__ste_Client_Keyring1_User1~0 0) (= |#NULL.offset| 0) (= ~__ste_Client_AddressBook2_Alias2~0 0) (= |ULTIMATE.start_valid_product_~retValue_acc~1#1| 1) (= ~__ste_email_subject1~0.offset 0) (= ~__ste_Client_AddressBook0_Alias2~0 0) (= ~__ste_ClientKeyring_size0~0 0) (= ~__ste_email_isEncrypted0~0 0) (= ~queued_message~0 0) (= ~__ste_Client_AddressBook1_Address1~0 0) (= 0 ~__ste_Client_AddressBook0_Address0~0) (= ~__ste_client_outbuffer1~0 0) (= ~__ste_Client_AddressBook0_Alias1~0 0) (= ~__GUIDSL_ROOT_PRODUCTION~0 0) (<= 3 |ULTIMATE.start_setup_chuck__wrappee__Base_#in~chuck___0#1|) (= ~__ste_client_name0~0.base 0) (= ~__ste_email_id1~0 0) (= ~__ste_client_outbuffer2~0 0) (<= 0 |#StackHeapBarrier|) (= ~__ste_ClientAddressBook_size2~0 0) (= ~__SELECTED_FEATURE_AutoResponder~0 0) (= ~__ste_email_encryptionKey1~0 0) (= ~__ste_client_autoResponse0~0 0) (= ~__ste_email_body1~0.base 0) (= ~__ste_ClientKeyring_size2~0 0) (= ~__ste_client_autoResponse2~0 0) (= |#NULL.base| 0) (= |ULTIMATE.start_main_~tmp~17#1| 1) (= ~__ste_email_signKey1~0 0)) [2022-12-14 09:04:34,669 INFO L899 garLoopResultBuilder]: For program point L2445(lines 2445 2452) no Hoare annotation was computed. [2022-12-14 09:04:34,669 INFO L902 garLoopResultBuilder]: At program point L2445-2(lines 2445 2452) the Hoare annotation is: true [2022-12-14 09:04:34,669 INFO L899 garLoopResultBuilder]: For program point L1009(lines 1009 1016) no Hoare annotation was computed. [2022-12-14 09:04:34,669 INFO L899 garLoopResultBuilder]: For program point getEmailFromEXIT(lines 536 554) no Hoare annotation was computed. [2022-12-14 09:04:34,669 INFO L902 garLoopResultBuilder]: At program point $Ultimate##0(lines 536 554) the Hoare annotation is: true [2022-12-14 09:04:34,669 INFO L899 garLoopResultBuilder]: For program point isReadableEXIT(lines 2259 2278) no Hoare annotation was computed. [2022-12-14 09:04:34,670 INFO L902 garLoopResultBuilder]: At program point $Ultimate##0(lines 2259 2278) the Hoare annotation is: true [2022-12-14 09:04:34,670 INFO L895 garLoopResultBuilder]: At program point L2265-1(line 2265) the Hoare annotation is: (or (and (= |isReadable_~msg#1| |isReadable_#in~msg#1|) (or (= |isReadable_#t~ret57#1| ~__ste_email_isEncrypted0~0) (not (= |isReadable_#in~msg#1| 1)))) (not (= ~queue_empty~0 1))) [2022-12-14 09:04:34,670 INFO L895 garLoopResultBuilder]: At program point L2265(line 2265) the Hoare annotation is: (or (= |isReadable_~msg#1| |isReadable_#in~msg#1|) (not (= ~queue_empty~0 1))) [2022-12-14 09:04:34,670 INFO L899 garLoopResultBuilder]: For program point setClientKeyringPublicKeyEXIT(lines 2028 2071) no Hoare annotation was computed. [2022-12-14 09:04:34,672 INFO L895 garLoopResultBuilder]: At program point $Ultimate##0(lines 2028 2071) the Hoare annotation is: (or (not (= |old(~__ste_Client_Keyring0_PublicKey1~0)| 0)) (not (= ~__ste_Client_AddressBook1_Address2~0 0)) (not (= ~__ste_email_from0~0 0)) (not (<= ~__ste_ClientKeyring_size0~0 2147483647)) (not (= ~__ste_client_autoResponse2~0 0)) (not (= ~__ste_client_name2~0.base 0)) (not (= ~__ste_Client_AddressBook1_Alias1~0 0)) (not (= ~rjh~0 2)) (not (<= ~__ste_client_privateKey2~0 789)) (not (= ~__ste_ClientAddressBook_size1~0 0)) (not (= 0 ~__ste_Client_AddressBook0_Address0~0)) (not (= |#NULL.offset| 0)) (not (= |old(~__ste_Client_Keyring1_PublicKey0~0)| 0)) (not (= ~__ste_Client_counter~0 0)) (not (= 0 ~__ste_Client_AddressBook0_Address1~0)) (not (= ~bob~0 1)) (not (= |setClientKeyringPublicKey_#in~handle| ~bob~0)) (not (= |old(~__ste_Client_Keyring2_PublicKey0~0)| 0)) (not (= ~queued_message~0 0)) (not (<= 0 (+ 2147483647 ~__ste_ClientKeyring_size0~0))) (not (= ~__ste_client_name2~0.offset 0)) (not (= ~__ste_ClientAddressBook_size2~0 0)) (not (= ~__SELECTED_FEATURE_AddressBook~0 0)) (not (= ~__ste_Client_AddressBook0_Alias2~0 0)) (not (= ~__ste_email_id0~0 0)) (not (= ~__SELECTED_FEATURE_Keys~0 0)) (not (= |setClientKeyringPublicKey_#in~index| 0)) (not (= ~__ste_Client_AddressBook2_Address0~0 0)) (not (= ~__ste_Client_Keyring0_User2~0 0)) (not (= ~queued_client~0 0)) (not (= ~__ste_Client_AddressBook2_Alias2~0 0)) (not (= ~__ste_email_isSigned0~0 0)) (not (= ~__ste_email_encryptionKey0~0 0)) (not (= ~__ste_email_signKey1~0 0)) (not (= ~__ste_client_name0~0.base 0)) (not (= ~__ste_Client_AddressBook2_Address1~0 0)) (not (= ~__GUIDSL_ROOT_PRODUCTION~0 0)) (not (= ~__SELECTED_FEATURE_Forward~0 0)) (not (= ~__ste_email_body1~0.base 0)) (not (= ~__GUIDSL_NON_TERMINAL_main~0 0)) (not (= ~__ste_email_to0~0 0)) (not (= ~__ste_Client_Keyring1_PublicKey2~0 0)) (not (= ~__ste_client_outbuffer0~0 0)) (not (= 0 ~__ste_Client_AddressBook0_Address2~0)) (not (= ~__ste_client_forwardReceiver0~0 0)) (not (= ~__ste_email_body1~0.offset 0)) (not (= ~__ste_email_body0~0.offset 0)) (not (= ~__ste_email_isEncrypted1~0 0)) (not (= ~__ste_Client_AddressBook1_Alias0~0 0)) (and (= ~__ste_Client_Keyring1_PublicKey1~0 |old(~__ste_Client_Keyring1_PublicKey1~0)|) (= |old(~__ste_Client_Keyring2_PublicKey1~0)| ~__ste_Client_Keyring2_PublicKey1~0) (= |old(~__ste_Client_Keyring0_PublicKey1~0)| ~__ste_Client_Keyring0_PublicKey1~0) (= |old(~__ste_Client_Keyring2_PublicKey0~0)| ~__ste_Client_Keyring2_PublicKey0~0) (= |old(~__ste_Client_Keyring0_PublicKey0~0)| ~__ste_Client_Keyring0_PublicKey0~0) (= ~__ste_Client_Keyring1_PublicKey0~0 |old(~__ste_Client_Keyring1_PublicKey0~0)|)) (not (= ~head~0.offset 0)) (not (= ~__ste_email_id1~0 0)) (not (= 456 |setClientKeyringPublicKey_#in~value|)) (not (= ~__ste_client_forwardReceiver2~0 0)) (not (<= 789 ~__ste_client_privateKey2~0)) (not (= ~__ste_client_outbuffer1~0 0)) (not (= ~__ste_email_signKey0~0 0)) (not (= ~__SELECTED_FEATURE_Sign~0 0)) (not (= ~__ste_Client_AddressBook2_Alias1~0 0)) (not (= ~__ste_email_isSignatureVerified0~0 0)) (not (= ~__ste_Client_AddressBook0_Alias0~0 0)) (not (= ~__ste_client_outbuffer3~0 0)) (not (= ~__SELECTED_FEATURE_Base~0 0)) (not (= ~__ste_email_encryptionKey1~0 0)) (not (= ~__ste_email_subject0~0.offset 0)) (not (= ~__ste_email_to1~0 0)) (not (= ~__ste_Client_AddressBook1_Alias2~0 0)) (not (= |#NULL.base| 0)) (not (= ~__ste_email_isSignatureVerified1~0 0)) (not (= ~__ste_email_subject1~0.base 0)) (not (= ~__ste_client_autoResponse1~0 0)) (not (= ~__ste_Client_AddressBook2_Address2~0 0)) (not (= ~__ste_client_name1~0.offset 0)) (not (= |old(~__ste_Client_Keyring1_PublicKey1~0)| 0)) (not (= ~__ste_email_body0~0.base 0)) (not (= ~__ste_Client_AddressBook1_Address1~0 0)) (not (= ~__SELECTED_FEATURE_Decrypt~0 0)) (not (= 2 ~__ste_Client_Keyring0_User0~0)) (not (= ~__ste_client_name0~0.offset 0)) (not (= |old(~__ste_Client_Keyring2_PublicKey1~0)| 0)) (not (= 3 ~chuck~0)) (not (<= ~__ste_client_idCounter2~0 3)) (not (= |old(~__ste_Client_Keyring0_PublicKey0~0)| 0)) (not (= ~__ste_Client_AddressBook1_Address0~0 0)) (not (= ~__SELECTED_FEATURE_Verify~0 0)) (not (<= 0 |#StackHeapBarrier|)) (not (= ~__ste_Client_Keyring2_User2~0 0)) (not (= ~__SELECTED_FEATURE_AutoResponder~0 0)) (not (= ~__ste_ClientAddressBook_size0~0 0)) (not (= ~__ste_client_forwardReceiver3~0 0)) (not (= ~__ste_client_forwardReceiver1~0 0)) (not (= ~__ste_Client_Keyring1_User2~0 0)) (not (= ~__ste_client_outbuffer2~0 0)) (not (= ~__ste_email_isEncrypted0~0 0)) (not (= ~__ste_Client_Keyring2_PublicKey2~0 0)) (not (= ~__SELECTED_FEATURE_Encrypt~0 0)) (not (= ~__ste_client_autoResponse0~0 0)) (not (= ~queue_empty~0 1)) (not (= ~__ste_client_name1~0.base 0)) (not (= ~__ste_Client_AddressBook2_Alias0~0 0)) (not (= ~__ste_email_isSigned1~0 0)) (not (= ~head~0.base 0)) (not (= ~__ste_Client_AddressBook0_Alias1~0 0)) (not (= ~__ste_Email_counter~0 0)) (not (<= 3 ~__ste_client_idCounter2~0)) (not (= ~__ste_email_from1~0 0)) (not (= ~__ste_email_subject1~0.offset 0)) (not (= 0 ~__ste_email_subject0~0.base)) (not (= ~__ste_Client_Keyring0_PublicKey2~0 0))) [2022-12-14 09:04:34,672 INFO L899 garLoopResultBuilder]: For program point setClientIdEXIT(lines 2147 2166) no Hoare annotation was computed. [2022-12-14 09:04:34,672 INFO L902 garLoopResultBuilder]: At program point $Ultimate##0(lines 2147 2166) the Hoare annotation is: true [2022-12-14 09:04:34,675 INFO L445 BasicCegarLoop]: Path program histogram: [1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-12-14 09:04:34,677 INFO L178 ceAbstractionStarter]: Computing trace abstraction results [2022-12-14 09:04:34,734 INFO L202 PluginConnector]: Adding new model de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction CFG 14.12 09:04:34 BoogieIcfgContainer [2022-12-14 09:04:34,734 INFO L132 PluginConnector]: ------------------------ END TraceAbstraction---------------------------- [2022-12-14 09:04:34,735 INFO L113 PluginConnector]: ------------------------Witness Printer---------------------------- [2022-12-14 09:04:34,735 INFO L271 PluginConnector]: Initializing Witness Printer... [2022-12-14 09:04:34,735 INFO L275 PluginConnector]: Witness Printer initialized [2022-12-14 09:04:34,735 INFO L185 PluginConnector]: Executing the observer RCFGCatcher from plugin Witness Printer for "de.uni_freiburg.informatik.ultimate.plugins.generator.rcfgbuilder CFG 14.12 08:52:01" (3/4) ... [2022-12-14 09:04:34,738 INFO L137 WitnessPrinter]: Generating witness for correct program [2022-12-14 09:04:34,743 INFO L361 RCFGBacktranslator]: Ignoring RootEdge to procedure getEmailSignKey [2022-12-14 09:04:34,744 INFO L361 RCFGBacktranslator]: Ignoring RootEdge to procedure outgoing [2022-12-14 09:04:34,744 INFO L361 RCFGBacktranslator]: Ignoring RootEdge to procedure isSigned [2022-12-14 09:04:34,744 INFO L361 RCFGBacktranslator]: Ignoring RootEdge to procedure setClientPrivateKey [2022-12-14 09:04:34,744 INFO L361 RCFGBacktranslator]: Ignoring RootEdge to procedure chuckKeyAdd [2022-12-14 09:04:34,744 INFO L361 RCFGBacktranslator]: Ignoring RootEdge to procedure isKeyPairValid [2022-12-14 09:04:34,744 INFO L361 RCFGBacktranslator]: Ignoring RootEdge to procedure getEmailTo [2022-12-14 09:04:34,744 INFO L361 RCFGBacktranslator]: Ignoring RootEdge to procedure createClientKeyringEntry [2022-12-14 09:04:34,744 INFO L361 RCFGBacktranslator]: Ignoring RootEdge to procedure findPublicKey [2022-12-14 09:04:34,744 INFO L361 RCFGBacktranslator]: Ignoring RootEdge to procedure getClientPrivateKey [2022-12-14 09:04:34,744 INFO L361 RCFGBacktranslator]: Ignoring RootEdge to procedure generateKeyPair [2022-12-14 09:04:34,744 INFO L361 RCFGBacktranslator]: Ignoring RootEdge to procedure setClientKeyringUser [2022-12-14 09:04:34,744 INFO L361 RCFGBacktranslator]: Ignoring RootEdge to procedure sendEmail [2022-12-14 09:04:34,744 INFO L361 RCFGBacktranslator]: Ignoring RootEdge to procedure setEmailEncryptionKey [2022-12-14 09:04:34,744 INFO L361 RCFGBacktranslator]: Ignoring RootEdge to procedure isEncrypted [2022-12-14 09:04:34,745 INFO L361 RCFGBacktranslator]: Ignoring RootEdge to procedure setEmailFrom [2022-12-14 09:04:34,745 INFO L361 RCFGBacktranslator]: Ignoring RootEdge to procedure getEmailFrom [2022-12-14 09:04:34,745 INFO L361 RCFGBacktranslator]: Ignoring RootEdge to procedure isReadable [2022-12-14 09:04:34,745 INFO L361 RCFGBacktranslator]: Ignoring RootEdge to procedure setEmailIsEncrypted [2022-12-14 09:04:34,745 INFO L361 RCFGBacktranslator]: Ignoring RootEdge to procedure setClientKeyringPublicKey [2022-12-14 09:04:34,745 INFO L361 RCFGBacktranslator]: Ignoring RootEdge to procedure getEmailEncryptionKey [2022-12-14 09:04:34,745 INFO L361 RCFGBacktranslator]: Ignoring RootEdge to procedure setClientId [2022-12-14 09:04:34,760 INFO L961 BoogieBacktranslator]: Reduced CFG by removing 213 nodes and edges [2022-12-14 09:04:34,761 INFO L961 BoogieBacktranslator]: Reduced CFG by removing 68 nodes and edges [2022-12-14 09:04:34,763 INFO L961 BoogieBacktranslator]: Reduced CFG by removing 10 nodes and edges [2022-12-14 09:04:34,764 INFO L961 BoogieBacktranslator]: Reduced CFG by removing 4 nodes and edges [2022-12-14 09:04:34,766 INFO L961 BoogieBacktranslator]: Reduced CFG by removing 2 nodes and edges [2022-12-14 09:04:34,767 INFO L961 BoogieBacktranslator]: Reduced CFG by removing 1 nodes and edges [2022-12-14 09:04:34,794 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: ((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((queued_client == 0 && __ste_Client_Keyring1_User2 == 0) && __GUIDSL_NON_TERMINAL_main == 0) && __ste_email_isEncrypted1 == 0) && __ste_email_subject0 == 0) && __SELECTED_FEATURE_Sign == 0) && 0 == __ste_Client_AddressBook0_Address2) && __ste_client_outbuffer3 == 0) && 1 <= \result) && 1 <= \old(bob___0)) && __ste_Client_counter == 0) && rjh == 0) && __ste_Client_Keyring1_PublicKey2 == 0) && retValue_acc <= 2147483647) && \old(bob___0) <= 1) && __ste_client_autoResponse1 == 0) && __ste_Client_AddressBook2_Alias0 == 0) && 1 <= \old(bob___0)) && 0 == __ste_email_subject0) && __ste_Client_AddressBook2_Alias1 == 0) && __ste_Client_Keyring2_PublicKey2 == 0) && __ste_client_forwardReceiver3 == 0) && \old(bob___0) <= 1) && __ste_client_name2 == 0) && __ste_client_name1 == 0) && __SELECTED_FEATURE_Verify == 0) && __ste_Client_Keyring1_User0 == 0) && __ste_email_body1 == 0) && __SELECTED_FEATURE_Encrypt == 0) && __ste_Client_AddressBook1_Address2 == 0) && 1 <= bob___0) && __ste_ClientAddressBook_size1 == 0) && __ste_Client_Keyring0_PublicKey0 == 0) && __ste_Email_counter == 0) && __ste_ClientKeyring_size1 == 0) && __ste_email_body0 == 0) && __ste_email_isSignatureVerified0 == 0) && __ste_Client_Keyring0_User2 == 0) && __ste_ClientAddressBook_size0 == 0) && __ste_Client_Keyring0_User1 == 0) && __ste_Client_AddressBook1_Alias1 == 0) && __ste_email_to1 == 0) && __ste_client_name1 == 0) && __ste_client_privateKey1 == 0) && head == 0) && __ste_client_name0 == 0) && __ste_Client_Keyring0_PublicKey2 == 0) && __ste_Client_Keyring1_PublicKey0 == 0) && __ste_email_to0 == 0) && __ste_email_signKey0 == 0) && __SELECTED_FEATURE_Decrypt == 0) && __ste_email_encryptionKey0 == 0) && __SELECTED_FEATURE_Keys == 0) && __SELECTED_FEATURE_AddressBook == 0) && __ste_client_forwardReceiver2 == 0) && __ste_Client_Keyring0_PublicKey1 == 0) && __SELECTED_FEATURE_Forward == 0) && __ste_Client_Keyring0_User0 == 0) && __ste_email_isSigned0 == 0) && __ste_Client_Keyring2_PublicKey1 == 0) && __ste_email_isSigned1 == 0) && __ste_email_body0 == 0) && __ste_Client_AddressBook0_Alias0 == 0) && 0 <= 2147483648 + retValue_acc) && __ste_email_id0 == 0) && __ste_client_privateKey0 == 0) && __ste_email_from0 == 0) && __ste_Client_Keyring2_User1 == 0) && bob___0 <= 1) && __ste_Client_AddressBook2_Address2 == 0) && \result <= 1) && __ste_Client_AddressBook2_Address1 == 0) && bob == 1) && __ste_client_forwardReceiver1 == 0) && 1 <= bob___0) && __ste_Client_AddressBook1_Alias2 == 0) && __ste_client_outbuffer0 == 0) && queue_empty == 1) && __SELECTED_FEATURE_Base == 0) && __ste_client_forwardReceiver0 == 0) && __ste_Client_Keyring2_User0 == 0) && 0 == __ste_Client_AddressBook0_Address1) && __ste_Client_AddressBook2_Address0 == 0) && __ste_email_isSignatureVerified1 == 0) && __ste_Client_Keyring1_PublicKey1 == 0) && __ste_Client_Keyring2_PublicKey0 == 0) && __ste_Client_AddressBook1_Address0 == 0) && __ste_client_name2 == 0) && __ste_email_from1 == 0) && __ste_client_idCounter0 <= 1) && __ste_email_subject1 == 0) && __ste_Client_AddressBook1_Alias0 == 0) && __ste_Client_Keyring2_User2 == 0) && bob___0 <= 1) && head == 0) && __ste_client_privateKey2 == 0) && __ste_Client_Keyring1_User1 == 0) && #NULL == 0) && __ste_Client_AddressBook2_Alias2 == 0) && retValue_acc == 1) && __ste_email_subject1 == 0) && __ste_Client_AddressBook0_Alias2 == 0) && __ste_ClientKeyring_size0 == 0) && __ste_email_isEncrypted0 == 0) && queued_message == 0) && __ste_Client_AddressBook1_Address1 == 0) && 0 == __ste_Client_AddressBook0_Address0) && 1 <= __ste_client_idCounter0) && __ste_client_outbuffer1 == 0) && __ste_Client_AddressBook0_Alias1 == 0) && __GUIDSL_ROOT_PRODUCTION == 0) && chuck == 0) && __ste_client_name0 == 0) && __ste_email_id1 == 0) && __ste_client_outbuffer2 == 0) && 0 <= unknown-#StackHeapBarrier-unknown) && __ste_ClientAddressBook_size2 == 0) && __SELECTED_FEATURE_AutoResponder == 0) && __ste_email_encryptionKey1 == 0) && __ste_client_autoResponse0 == 0) && __ste_email_body1 == 0) && __ste_ClientKeyring_size2 == 0) && __ste_client_autoResponse2 == 0) && #NULL == 0) && tmp == 1) && __ste_email_signKey1 == 0 [2022-12-14 09:04:34,794 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: ((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((__ste_Client_Keyring1_User2 == 0 && __GUIDSL_NON_TERMINAL_main == 0) && __ste_email_isEncrypted1 == 0) && __SELECTED_FEATURE_Sign == 0) && __ste_client_outbuffer3 == 0) && 1 <= \result) && 1 <= \old(bob___0)) && __ste_Client_counter == 0) && rjh == 0) && retValue_acc <= 2147483647) && \old(bob___0) <= 1) && __ste_client_autoResponse1 == 0) && __ste_Client_AddressBook2_Alias0 == 0) && 1 <= \old(bob___0)) && 0 == __ste_email_subject0) && __ste_Client_AddressBook2_Alias1 == 0) && __ste_Client_Keyring2_PublicKey2 == 0) && \old(bob___0) <= 1) && __ste_client_name2 == 0) && __ste_email_body1 == 0) && __SELECTED_FEATURE_Encrypt == 0) && __ste_Client_AddressBook1_Address2 == 0) && 1 <= bob___0) && __ste_ClientAddressBook_size1 == 0) && __ste_Email_counter == 0) && __ste_email_body0 == 0) && __ste_email_isSignatureVerified0 == 0) && __ste_Client_Keyring0_User2 == 0) && __ste_ClientAddressBook_size0 == 0) && __ste_Client_Keyring0_User1 == 0) && __ste_Client_AddressBook1_Alias1 == 0) && __ste_email_to1 == 0) && __ste_client_name1 == 0) && head == 0) && __ste_Client_Keyring0_PublicKey2 == 0) && __ste_Client_Keyring1_PublicKey0 == 0) && __ste_email_to0 == 0) && __ste_email_signKey0 == 0) && __SELECTED_FEATURE_Decrypt == 0) && __SELECTED_FEATURE_Keys == 0) && #NULL <= 0) && 0 <= __ste_Client_Keyring1_User0) && 0 <= __SELECTED_FEATURE_AddressBook) && __ste_Client_Keyring0_PublicKey1 == 0) && 1 <= retValue_acc) && 0 <= __ste_email_from1) && __SELECTED_FEATURE_Forward == 0) && __ste_Client_Keyring0_User0 == 0) && __ste_email_isSigned0 == 0) && __ste_Client_Keyring2_PublicKey1 == 0) && __ste_email_isSigned1 == 0) && 0 <= __ste_email_id1) && __ste_Client_AddressBook0_Address1 <= 0) && __ste_email_body0 == 0) && __ste_Client_AddressBook0_Alias0 == 0) && 0 <= 2147483648 + retValue_acc) && 0 <= __ste_Client_AddressBook2_Address1) && 0 <= __ste_client_name0) && __ste_Client_Keyring0_PublicKey0 <= 0) && __ste_client_name1 <= 0) && __ste_email_id0 == 0) && __ste_client_autoResponse0 <= 0) && __SELECTED_FEATURE_AddressBook <= 0) && __ste_email_from0 == 0) && __ste_Client_Keyring1_PublicKey2 <= 0) && bob___0 <= 1) && 0 <= __ste_Client_Keyring0_PublicKey0) && __ste_client_forwardReceiver3 <= 0) && __ste_Client_AddressBook2_Address2 == 0) && 0 <= __ste_Client_Keyring1_PublicKey2) && \result <= 1) && __ste_Client_AddressBook0_Address0 <= 0) && 0 <= __ste_email_signKey1) && __ste_email_signKey1 <= 0) && 0 <= __ste_client_forwardReceiver3) && __ste_email_subject0 <= 0) && bob == 1) && 0 <= __ste_client_autoResponse0) && 1 <= bob___0) && 0 <= __ste_Client_AddressBook0_Alias2) && __ste_client_outbuffer0 == 0) && __SELECTED_FEATURE_Verify <= 0) && __ste_ClientKeyring_size1 <= 0) && 0 <= head) && queue_empty == 1) && __SELECTED_FEATURE_Base == 0) && __ste_Client_AddressBook1_Alias2 <= 0) && 0 <= __ste_Client_AddressBook0_Address2) && __ste_client_forwardReceiver0 == 0) && __ste_Client_Keyring2_User0 == 0) && 0 <= __ste_email_subject0) && 0 <= __ste_Client_AddressBook1_Alias0) && __ste_Client_AddressBook2_Address0 == 0) && __ste_email_isSignatureVerified1 == 0) && __ste_Client_Keyring1_PublicKey1 == 0) && 0 <= queued_client) && __ste_client_privateKey0 <= 123) && __ste_Client_AddressBook1_Alias0 <= 0) && __ste_Client_Keyring2_PublicKey0 == 0) && __ste_Client_AddressBook1_Address0 == 0) && 0 <= __ste_ClientKeyring_size1) && 0 <= __ste_client_forwardReceiver2) && __ste_client_name2 == 0) && 0 <= __ste_Client_AddressBook0_Address1) && __ste_email_encryptionKey0 <= 0) && __ste_client_idCounter0 <= 1) && __ste_email_subject1 == 0) && __ste_ClientKeyring_size0 <= 0) && __ste_email_id1 <= 0) && 0 <= __ste_Client_AddressBook0_Address0) && __ste_Client_Keyring1_User0 <= 0) && __ste_Client_AddressBook0_Alias2 <= 0) && __ste_Client_AddressBook0_Address2 <= 0) && __ste_Client_Keyring2_User2 == 0) && bob___0 <= 1) && __ste_email_from1 <= 0) && head <= 0) && __ste_client_forwardReceiver1 <= 0) && __ste_Client_Keyring1_User1 == 0) && __ste_Client_AddressBook2_Alias2 == 0) && __ste_Client_Keyring2_User1 <= 0) && 0 <= __SELECTED_FEATURE_Verify) && 0 <= __ste_Client_AddressBook1_Alias2) && 0 <= __ste_client_autoResponse2) && __ste_email_subject1 == 0) && __ste_email_isEncrypted0 == 0) && 0 <= __ste_Client_Keyring2_User1) && queued_message == 0) && __ste_Client_AddressBook1_Address1 == 0) && __ste_client_name0 <= 0) && 1 <= __ste_client_idCounter0) && __ste_client_outbuffer1 == 0) && __ste_Client_AddressBook0_Alias1 == 0) && 0 <= __ste_ClientKeyring_size0) && retValue_acc <= 1) && __GUIDSL_ROOT_PRODUCTION == 0) && 0 <= #NULL) && 123 <= __ste_client_privateKey0) && chuck == 0) && 0 <= __ste_client_forwardReceiver1) && __ste_client_name0 == 0) && __ste_Client_AddressBook2_Address1 <= 0) && __ste_client_outbuffer2 == 0) && __ste_client_forwardReceiver2 <= 0) && 0 <= unknown-#StackHeapBarrier-unknown) && __ste_ClientAddressBook_size2 == 0) && __SELECTED_FEATURE_AutoResponder == 0) && __ste_client_autoResponse2 <= 0) && __ste_email_encryptionKey1 == 0) && __ste_email_body1 == 0) && __ste_ClientKeyring_size2 == 0) && 0 <= __ste_client_name1) && 0 <= __ste_email_encryptionKey0) && #NULL == 0) && tmp == 1) && queued_client <= 0 [2022-12-14 09:04:34,794 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((queued_client == 0 && __ste_Client_Keyring1_User2 == 0) && __GUIDSL_NON_TERMINAL_main == 0) && __ste_email_isEncrypted1 == 0) && __ste_email_subject0 == 0) && __SELECTED_FEATURE_Sign == 0) && 0 == __ste_Client_AddressBook0_Address2) && __ste_client_outbuffer3 == 0) && 1 <= \result) && \old(rjh___0) <= 2) && 1 <= \old(bob___0)) && 19 == __cil_tmp1) && __ste_Client_counter == 0) && __ste_Client_Keyring1_PublicKey2 == 0) && retValue_acc <= 2147483647) && \old(bob___0) <= 1) && __ste_client_autoResponse1 == 0) && 2 <= rjh___0) && __ste_Client_AddressBook2_Alias0 == 0) && __cil_tmp1 == 0) && 1 <= \old(bob___0)) && 0 == __ste_email_subject0) && __ste_client_idCounter1 <= 2) && __ste_Client_AddressBook2_Alias1 == 0) && __ste_Client_Keyring2_PublicKey2 == 0) && __ste_client_forwardReceiver3 == 0) && \old(bob___0) <= 1) && __ste_client_name2 == 0) && __ste_client_name1 == 0) && __SELECTED_FEATURE_Verify == 0) && __ste_Client_Keyring1_User0 == 0) && __ste_email_body1 == 0) && __SELECTED_FEATURE_Encrypt == 0) && __ste_Client_AddressBook1_Address2 == 0) && 1 <= bob___0) && __ste_ClientAddressBook_size1 == 0) && __ste_Client_Keyring0_PublicKey0 == 0) && __ste_Email_counter == 0) && __ste_ClientKeyring_size1 == 0) && __ste_email_body0 == 0) && __ste_email_isSignatureVerified0 == 0) && __ste_Client_Keyring0_User2 == 0) && __ste_ClientAddressBook_size0 == 0) && __ste_Client_Keyring0_User1 == 0) && __ste_Client_AddressBook1_Alias1 == 0) && __ste_email_to1 == 0) && __ste_client_name1 == 0) && head == 0) && __ste_client_name0 == 0) && __ste_Client_Keyring0_PublicKey2 == 0) && __ste_Client_Keyring1_PublicKey0 == 0) && __ste_email_to0 == 0) && __ste_email_signKey0 == 0) && __SELECTED_FEATURE_Decrypt == 0) && __ste_email_encryptionKey0 == 0) && __SELECTED_FEATURE_Keys == 0) && __SELECTED_FEATURE_AddressBook == 0) && __ste_client_forwardReceiver2 == 0) && __ste_Client_Keyring0_PublicKey1 == 0) && __SELECTED_FEATURE_Forward == 0) && rjh___0 <= 2) && __ste_Client_Keyring0_User0 == 0) && __ste_email_isSigned0 == 0) && __ste_Client_Keyring2_PublicKey1 == 0) && __ste_email_isSigned1 == 0) && __ste_email_body0 == 0) && __ste_Client_AddressBook0_Alias0 == 0) && 0 <= 2147483648 + retValue_acc) && __ste_email_id0 == 0) && \old(rjh___0) <= 2) && __ste_email_from0 == 0) && __ste_Client_Keyring2_User1 == 0) && bob___0 <= 1) && __ste_Client_AddressBook2_Address2 == 0) && \result <= 1) && __ste_Client_AddressBook2_Address1 == 0) && bob == 1) && __ste_client_forwardReceiver1 == 0) && 1 <= bob___0) && __ste_Client_AddressBook1_Alias2 == 0) && 2 <= __ste_client_idCounter1) && __ste_client_outbuffer0 == 0) && 2 <= rjh___0) && queue_empty == 1) && rjh___0 <= 2) && __SELECTED_FEATURE_Base == 0) && __ste_client_forwardReceiver0 == 0) && __ste_Client_Keyring2_User0 == 0) && rjh == 2) && 0 == __ste_Client_AddressBook0_Address1) && __ste_Client_AddressBook2_Address0 == 0) && __ste_email_isSignatureVerified1 == 0) && __ste_Client_Keyring1_PublicKey1 == 0) && __ste_client_privateKey0 <= 123) && __ste_Client_Keyring2_PublicKey0 == 0) && __ste_Client_AddressBook1_Address0 == 0) && __ste_client_name2 == 0) && __ste_email_from1 == 0) && 2 <= \old(rjh___0)) && __ste_email_subject1 == 0) && __ste_Client_AddressBook1_Alias0 == 0) && __ste_Client_Keyring2_User2 == 0) && bob___0 <= 1) && head == 0) && 2 <= \old(rjh___0)) && __ste_Client_Keyring1_User1 == 0) && #NULL == 0) && __ste_Client_AddressBook2_Alias2 == 0) && retValue_acc == 1) && __ste_email_subject1 == 0) && __ste_Client_AddressBook0_Alias2 == 0) && __ste_ClientKeyring_size0 == 0) && __ste_email_isEncrypted0 == 0) && queued_message == 0) && __ste_Client_AddressBook1_Address1 == 0) && 0 == __ste_Client_AddressBook0_Address0) && __ste_client_outbuffer1 == 0) && __ste_Client_AddressBook0_Alias1 == 0) && __GUIDSL_ROOT_PRODUCTION == 0) && 123 <= __ste_client_privateKey0) && chuck == 0) && __ste_client_name0 == 0) && __ste_email_id1 == 0) && __ste_client_outbuffer2 == 0) && 0 <= unknown-#StackHeapBarrier-unknown) && __ste_ClientAddressBook_size2 == 0) && __SELECTED_FEATURE_AutoResponder == 0) && __ste_email_encryptionKey1 == 0) && __ste_client_autoResponse0 == 0) && __ste_email_body1 == 0) && __ste_ClientKeyring_size2 == 0) && __ste_client_autoResponse2 == 0) && #NULL == 0) && tmp == 1) && __ste_email_signKey1 == 0 [2022-12-14 09:04:34,795 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((queued_client == 0 && __ste_Client_Keyring1_User2 == 0) && __GUIDSL_NON_TERMINAL_main == 0) && 456 <= __ste_client_privateKey1) && 3 <= chuck___0) && __ste_email_isEncrypted1 == 0) && __ste_email_subject0 == 0) && __SELECTED_FEATURE_Sign == 0) && 0 == __ste_Client_AddressBook0_Address2) && __cil_tmp2 == 0) && __ste_client_outbuffer3 == 0) && 1 <= \result) && \old(rjh___0) <= 2) && 1 <= \old(bob___0)) && 19 == __cil_tmp1) && __ste_Client_counter == 0) && __ste_Client_Keyring1_PublicKey2 == 0) && retValue_acc <= 2147483647) && __cil_tmp2 == 20) && \old(bob___0) <= 1) && __ste_client_autoResponse1 == 0) && 2 <= rjh___0) && __ste_Client_AddressBook2_Alias0 == 0) && __cil_tmp1 == 0) && 1 <= \old(bob___0)) && 0 == __ste_email_subject0) && __ste_Client_AddressBook2_Alias1 == 0) && __ste_Client_Keyring2_PublicKey2 == 0) && __ste_client_forwardReceiver3 == 0) && \old(bob___0) <= 1) && __ste_client_name2 == 0) && __ste_client_name1 == 0) && \old(chuck___0) <= 3) && __SELECTED_FEATURE_Verify == 0) && __ste_Client_Keyring1_User0 == 0) && __ste_client_idCounter2 <= 3) && __ste_email_body1 == 0) && __SELECTED_FEATURE_Encrypt == 0) && __ste_Client_AddressBook1_Address2 == 0) && 1 <= bob___0) && __ste_ClientAddressBook_size1 == 0) && __ste_Client_Keyring0_PublicKey0 == 0) && __ste_Email_counter == 0) && __ste_ClientKeyring_size1 == 0) && __ste_email_body0 == 0) && __ste_email_isSignatureVerified0 == 0) && __ste_Client_Keyring0_User2 == 0) && __ste_ClientAddressBook_size0 == 0) && __ste_Client_Keyring0_User1 == 0) && __ste_Client_AddressBook1_Alias1 == 0) && __ste_email_to1 == 0) && __ste_client_name1 == 0) && head == 0) && __ste_client_name0 == 0) && __ste_Client_Keyring0_PublicKey2 == 0) && __ste_Client_Keyring1_PublicKey0 == 0) && __ste_email_to0 == 0) && __ste_email_signKey0 == 0) && __SELECTED_FEATURE_Decrypt == 0) && __ste_email_encryptionKey0 == 0) && __SELECTED_FEATURE_Keys == 0) && __SELECTED_FEATURE_AddressBook == 0) && __ste_client_forwardReceiver2 == 0) && __ste_Client_Keyring0_PublicKey1 == 0) && __SELECTED_FEATURE_Forward == 0) && rjh___0 <= 2) && __ste_Client_Keyring0_User0 == 0) && __ste_email_isSigned0 == 0) && __ste_Client_Keyring2_PublicKey1 == 0) && __ste_email_isSigned1 == 0) && __ste_email_body0 == 0) && __ste_Client_AddressBook0_Alias0 == 0) && 0 <= 2147483648 + retValue_acc) && __ste_email_id0 == 0) && \old(rjh___0) <= 2) && __ste_client_privateKey1 <= 456) && __ste_email_from0 == 0) && __ste_Client_Keyring2_User1 == 0) && bob___0 <= 1) && 3 <= __ste_client_idCounter2) && __ste_Client_AddressBook2_Address2 == 0) && \result <= 1) && chuck___0 <= 3) && 3 == chuck) && __ste_Client_AddressBook2_Address1 == 0) && bob == 1) && __ste_client_forwardReceiver1 == 0) && 1 <= bob___0) && 3 <= chuck___0) && __ste_Client_AddressBook1_Alias2 == 0) && __ste_client_outbuffer0 == 0) && 2 <= rjh___0) && queue_empty == 1) && rjh___0 <= 2) && __SELECTED_FEATURE_Base == 0) && __ste_client_forwardReceiver0 == 0) && 3 <= \old(chuck___0)) && __ste_Client_Keyring2_User0 == 0) && rjh == 2) && 0 == __ste_Client_AddressBook0_Address1) && __ste_Client_AddressBook2_Address0 == 0) && __ste_email_isSignatureVerified1 == 0) && __ste_Client_Keyring1_PublicKey1 == 0) && __ste_Client_Keyring2_PublicKey0 == 0) && __ste_Client_AddressBook1_Address0 == 0) && __ste_client_name2 == 0) && __ste_email_from1 == 0) && 2 <= \old(rjh___0)) && __ste_email_subject1 == 0) && \old(chuck___0) <= 3) && __ste_Client_AddressBook1_Alias0 == 0) && __ste_Client_Keyring2_User2 == 0) && bob___0 <= 1) && head == 0) && chuck___0 <= 3) && 2 <= \old(rjh___0)) && __ste_Client_Keyring1_User1 == 0) && #NULL == 0) && __ste_Client_AddressBook2_Alias2 == 0) && retValue_acc == 1) && __ste_email_subject1 == 0) && __ste_Client_AddressBook0_Alias2 == 0) && __ste_ClientKeyring_size0 == 0) && __ste_email_isEncrypted0 == 0) && queued_message == 0) && __ste_Client_AddressBook1_Address1 == 0) && 0 == __ste_Client_AddressBook0_Address0) && __ste_client_outbuffer1 == 0) && __ste_Client_AddressBook0_Alias1 == 0) && __GUIDSL_ROOT_PRODUCTION == 0) && 3 <= \old(chuck___0)) && __ste_client_name0 == 0) && __ste_email_id1 == 0) && __ste_client_outbuffer2 == 0) && 0 <= unknown-#StackHeapBarrier-unknown) && __ste_ClientAddressBook_size2 == 0) && __SELECTED_FEATURE_AutoResponder == 0) && __ste_email_encryptionKey1 == 0) && __ste_client_autoResponse0 == 0) && __ste_email_body1 == 0) && __ste_ClientKeyring_size2 == 0) && __ste_client_autoResponse2 == 0) && #NULL == 0) && tmp == 1) && __ste_email_signKey1 == 0 [2022-12-14 09:04:34,795 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((__SELECTED_FEATURE_Sign == 0 && __ste_client_outbuffer3 == 0) && 1 <= \result) && \old(rjh___0) <= 2) && 1 <= \old(bob___0)) && __ste_Client_counter == 0) && retValue_acc <= 2147483647) && \old(bob___0) <= 1) && 2 <= rjh___0) && __ste_Client_AddressBook2_Alias0 == 0) && 1 <= \old(bob___0)) && 0 == __ste_email_subject0) && __ste_client_idCounter1 <= 2) && \old(bob___0) <= 1) && 0 <= __ste_ClientAddressBook_size0) && 2 <= rjh) && 0 <= __SELECTED_FEATURE_Encrypt) && 0 <= __ste_client_autoResponse1) && 0 <= __ste_client_outbuffer0) && __ste_Client_Keyring2_PublicKey2 <= 0) && __cil_tmp1 <= 19) && 0 <= __ste_client_outbuffer1) && 0 <= __ste_ClientAddressBook_size1) && queued_message <= 0) && __ste_email_isSignatureVerified0 <= 0) && __ste_client_name0 <= 0) && 0 <= __ste_Client_AddressBook0_Alias1) && __ste_Client_AddressBook1_Address2 == 0) && 1 <= bob___0) && chuck <= 0) && 0 <= __SELECTED_FEATURE_AutoResponder) && __ste_email_body0 == 0) && __SELECTED_FEATURE_Keys <= 0) && 0 <= __ste_email_isSigned1) && __SELECTED_FEATURE_Decrypt <= 0) && __ste_Client_Keyring0_User2 == 0) && __ste_Client_Keyring1_PublicKey0 <= 0) && __ste_Client_Keyring0_User1 == 0) && __ste_Client_AddressBook1_Alias1 == 0) && __ste_client_name1 == 0) && __GUIDSL_NON_TERMINAL_main <= 0) && __ste_Client_AddressBook2_Address0 <= 0) && __SELECTED_FEATURE_AutoResponder <= 0) && __ste_email_id0 <= 0) && 0 <= __ste_client_name2) && head == 0) && __GUIDSL_ROOT_PRODUCTION <= 0) && __ste_Client_AddressBook2_Alias1 <= 0) && 0 <= __GUIDSL_ROOT_PRODUCTION) && __ste_Client_Keyring0_PublicKey2 == 0) && __ste_Email_counter <= 0) && __ste_Client_Keyring2_User2 <= 0) && __ste_email_body1 <= 0) && 0 <= __SELECTED_FEATURE_Decrypt) && 0 <= __cil_tmp1) && 0 <= __ste_email_to0) && __cil_tmp1 <= 0) && 0 <= __ste_email_to1) && __ste_email_signKey0 == 0) && 0 <= __ste_Client_AddressBook2_Alias1) && 0 <= __ste_Client_Keyring2_User2) && 0 <= __ste_Client_Keyring1_User2) && 0 <= __ste_email_from0) && 0 <= __ste_email_isEncrypted1) && #NULL <= 0) && 0 <= __ste_Client_Keyring1_User0) && 0 <= __SELECTED_FEATURE_AddressBook) && __ste_Client_Keyring0_PublicKey1 == 0) && 1 <= retValue_acc) && 0 <= __ste_email_from1) && __SELECTED_FEATURE_Forward == 0) && rjh___0 <= 2) && __ste_Client_Keyring0_User0 == 0) && __ste_email_isSigned0 == 0) && __ste_Client_Keyring2_PublicKey1 == 0) && 0 <= __ste_email_id1) && __ste_Client_AddressBook0_Address1 <= 0) && __ste_email_body0 == 0) && __ste_Client_AddressBook0_Alias0 == 0) && 0 <= 2147483648 + retValue_acc) && 0 <= __ste_Client_AddressBook2_Address1) && 0 <= __ste_client_name0) && __ste_Client_Keyring0_PublicKey0 <= 0) && __ste_client_name1 <= 0) && __ste_client_autoResponse0 <= 0) && \old(rjh___0) <= 2) && __ste_email_to1 <= 0) && __SELECTED_FEATURE_AddressBook <= 0) && __ste_Client_Keyring1_PublicKey2 <= 0) && bob___0 <= 1) && 0 <= __ste_Client_Keyring0_PublicKey0) && __ste_client_forwardReceiver3 <= 0) && __ste_Client_AddressBook2_Address2 == 0) && __ste_ClientAddressBook_size0 <= 0) && 0 <= __ste_Client_Keyring1_PublicKey2) && \result <= 1) && __ste_Client_AddressBook0_Address0 <= 0) && 0 <= __ste_client_name0) && 0 <= __ste_email_signKey1) && 0 <= __ste_email_body1) && __ste_email_signKey1 <= 0) && 0 <= __ste_client_forwardReceiver3) && __ste_client_name2 <= 0) && __ste_email_isSigned1 <= 0) && __SELECTED_FEATURE_Encrypt <= 0) && 0 <= __ste_Email_counter) && __ste_email_subject0 <= 0) && bob == 1) && 0 <= __ste_client_autoResponse0) && 1 <= bob___0) && 0 <= __ste_Client_AddressBook0_Alias2) && 0 <= queued_message) && 2 <= __ste_client_idCounter1) && __SELECTED_FEATURE_Verify <= 0) && __ste_ClientKeyring_size1 <= 0) && __ste_Client_Keyring1_User2 <= 0) && 2 <= rjh___0) && 0 <= chuck) && 0 <= head) && queue_empty == 1) && rjh___0 <= 2) && __SELECTED_FEATURE_Base == 0) && __ste_Client_AddressBook1_Alias2 <= 0) && 0 <= __ste_Client_AddressBook0_Address2) && __ste_client_privateKey1 == 456) && __ste_client_forwardReceiver0 == 0) && __ste_Client_Keyring2_User0 == 0) && 0 <= __ste_email_subject0) && __ste_email_from0 <= 0) && 0 <= __ste_Client_AddressBook1_Alias0) && __ste_email_isSignatureVerified1 == 0) && __ste_Client_Keyring1_PublicKey1 == 0) && 0 <= queued_client) && 0 <= __SELECTED_FEATURE_Keys) && __ste_Client_AddressBook1_Alias0 <= 0) && 0 <= __ste_Client_Keyring1_PublicKey0) && __ste_Client_Keyring2_PublicKey0 == 0) && 0 <= __ste_email_isSignatureVerified0) && __ste_Client_AddressBook1_Address0 == 0) && 0 <= __ste_ClientKeyring_size1) && 0 <= __ste_client_forwardReceiver2) && __ste_client_name2 == 0) && 0 <= __ste_Client_AddressBook0_Address1) && 2 <= \old(rjh___0)) && __ste_email_encryptionKey0 <= 0) && __ste_email_subject1 == 0) && __ste_ClientKeyring_size0 <= 0) && __ste_email_id1 <= 0) && 0 <= __ste_Client_AddressBook0_Address0) && __ste_Client_Keyring1_User0 <= 0) && __ste_Client_AddressBook0_Alias2 <= 0) && __ste_Client_AddressBook0_Address2 <= 0) && __ste_client_autoResponse1 <= 0) && bob___0 <= 1) && __ste_client_outbuffer0 <= 0) && __ste_email_from1 <= 0) && head <= 0) && __ste_client_forwardReceiver1 <= 0) && 2 <= \old(rjh___0)) && __ste_Client_Keyring1_User1 == 0) && __ste_Client_AddressBook2_Alias2 == 0) && __ste_email_to0 <= 0) && __ste_Client_Keyring2_User1 <= 0) && 0 <= __SELECTED_FEATURE_Verify) && 0 <= __ste_Client_AddressBook1_Alias2) && 0 <= __ste_client_autoResponse2) && __ste_email_subject1 == 0) && __ste_email_isEncrypted0 == 0) && 0 <= __ste_Client_AddressBook2_Address0) && 0 <= __ste_Client_Keyring2_User1) && __ste_Client_AddressBook1_Address1 == 0) && __ste_client_name0 <= 0) && 0 <= __ste_ClientKeyring_size0) && 19 <= __cil_tmp1) && __ste_email_isEncrypted1 <= 0) && retValue_acc <= 1) && 0 <= #NULL) && rjh <= 2) && __ste_Client_AddressBook0_Alias1 <= 0) && 0 <= __ste_client_forwardReceiver1) && 0 <= __ste_Client_Keyring2_PublicKey2) && __ste_Client_AddressBook2_Address1 <= 0) && __ste_client_outbuffer2 == 0) && 0 <= __GUIDSL_NON_TERMINAL_main) && __ste_client_forwardReceiver2 <= 0) && 0 <= unknown-#StackHeapBarrier-unknown) && __ste_ClientAddressBook_size2 == 0) && __ste_client_autoResponse2 <= 0) && __ste_email_encryptionKey1 == 0) && __ste_email_body1 == 0) && __ste_client_outbuffer1 <= 0) && __ste_ClientKeyring_size2 == 0) && __ste_ClientAddressBook_size1 <= 0) && 0 <= __ste_client_name1) && 0 <= __ste_email_id0) && 0 <= __ste_email_encryptionKey0) && #NULL == 0) && tmp == 1) && queued_client <= 0 [2022-12-14 09:04:34,795 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: ((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((queued_client == 0 && __ste_Client_Keyring1_User2 == 0) && __GUIDSL_NON_TERMINAL_main == 0) && 3 <= chuck___0) && __ste_email_isEncrypted1 == 0) && __ste_email_subject0 == 0) && __SELECTED_FEATURE_Sign == 0) && 0 == __ste_Client_AddressBook0_Address2) && __cil_tmp2 == 0) && __ste_client_outbuffer3 == 0) && 1 <= \result) && \old(rjh___0) <= 2) && 1 <= \old(bob___0)) && 19 == __cil_tmp1) && __ste_Client_counter == 0) && __ste_Client_Keyring1_PublicKey2 == 0) && retValue_acc <= 2147483647) && __cil_tmp2 == 20) && \old(bob___0) <= 1) && __ste_client_autoResponse1 == 0) && 2 <= rjh___0) && __ste_Client_AddressBook2_Alias0 == 0) && __cil_tmp1 == 0) && 1 <= \old(bob___0)) && 0 == __ste_email_subject0) && __ste_Client_AddressBook2_Alias1 == 0) && __ste_Client_Keyring2_PublicKey2 == 0) && __ste_client_forwardReceiver3 == 0) && \old(bob___0) <= 1) && __ste_client_name2 == 0) && __ste_client_name1 == 0) && \old(chuck___0) <= 3) && __SELECTED_FEATURE_Verify == 0) && __ste_Client_Keyring1_User0 == 0) && __ste_client_idCounter2 <= 3) && __ste_email_body1 == 0) && __SELECTED_FEATURE_Encrypt == 0) && __ste_Client_AddressBook1_Address2 == 0) && 1 <= bob___0) && __ste_ClientAddressBook_size1 == 0) && __ste_Client_Keyring0_PublicKey0 == 0) && __ste_Email_counter == 0) && __ste_ClientKeyring_size1 == 0) && __ste_email_body0 == 0) && __ste_email_isSignatureVerified0 == 0) && __ste_Client_Keyring0_User2 == 0) && __ste_ClientAddressBook_size0 == 0) && __ste_Client_Keyring0_User1 == 0) && __ste_Client_AddressBook1_Alias1 == 0) && __ste_email_to1 == 0) && __ste_client_name1 == 0) && head == 0) && __ste_client_name0 == 0) && __ste_Client_Keyring0_PublicKey2 == 0) && __ste_Client_Keyring1_PublicKey0 == 0) && __ste_email_to0 == 0) && 789 == __ste_client_privateKey2) && __ste_email_signKey0 == 0) && __SELECTED_FEATURE_Decrypt == 0) && __SELECTED_FEATURE_Keys == 0) && __SELECTED_FEATURE_AddressBook == 0) && __ste_Client_Keyring0_PublicKey1 == 0) && __SELECTED_FEATURE_Forward == 0) && rjh___0 <= 2) && __ste_Client_Keyring0_User0 == 0) && __ste_email_isSigned0 == 0) && __ste_Client_Keyring2_PublicKey1 == 0) && __ste_email_isSigned1 == 0) && __ste_email_body0 == 0) && __ste_Client_AddressBook0_Alias0 == 0) && 0 <= 2147483648 + retValue_acc) && __ste_email_id0 == 0) && \old(rjh___0) <= 2) && __ste_email_from0 == 0) && bob___0 <= 1) && 3 <= __ste_client_idCounter2) && __ste_Client_AddressBook2_Address2 == 0) && \result <= 1) && chuck___0 <= 3) && 3 == chuck) && __ste_Client_AddressBook2_Address1 == 0) && bob == 1) && 1 <= bob___0) && 3 <= chuck___0) && __ste_Client_AddressBook1_Alias2 == 0) && __ste_client_outbuffer0 == 0) && 2 <= rjh___0) && queue_empty == 1) && rjh___0 <= 2) && __SELECTED_FEATURE_Base == 0) && __ste_client_forwardReceiver0 == 0) && 3 <= \old(chuck___0)) && __ste_Client_Keyring2_User0 == 0) && rjh == 2) && 0 == __ste_Client_AddressBook0_Address1) && __ste_Client_AddressBook2_Address0 == 0) && __ste_email_isSignatureVerified1 == 0) && __ste_Client_Keyring1_PublicKey1 == 0) && __ste_Client_Keyring2_PublicKey0 == 0) && __ste_Client_AddressBook1_Address0 == 0) && 0 <= __ste_client_forwardReceiver2) && __ste_client_name2 == 0) && __ste_email_from1 == 0) && 2 <= \old(rjh___0)) && __ste_email_encryptionKey0 <= 0) && __ste_email_subject1 == 0) && __ste_ClientKeyring_size0 <= 0) && \old(chuck___0) <= 3) && __ste_Client_AddressBook1_Alias0 == 0) && __ste_Client_Keyring2_User2 == 0) && bob___0 <= 1) && head == 0) && chuck___0 <= 3) && __ste_client_forwardReceiver1 <= 0) && 2 <= \old(rjh___0)) && __ste_Client_Keyring1_User1 == 0) && #NULL == 0) && __ste_Client_AddressBook2_Alias2 == 0) && __ste_Client_Keyring2_User1 <= 0) && retValue_acc == 1) && 0 <= __ste_client_autoResponse2) && __ste_email_subject1 == 0) && __ste_Client_AddressBook0_Alias2 == 0) && __ste_email_isEncrypted0 == 0) && 0 <= __ste_Client_Keyring2_User1) && queued_message == 0) && __ste_Client_AddressBook1_Address1 == 0) && 0 == __ste_Client_AddressBook0_Address0) && __ste_client_outbuffer1 == 0) && __ste_Client_AddressBook0_Alias1 == 0) && 0 <= __ste_ClientKeyring_size0) && __GUIDSL_ROOT_PRODUCTION == 0) && 3 <= \old(chuck___0)) && 0 <= __ste_client_forwardReceiver1) && __ste_client_name0 == 0) && __ste_email_id1 == 0) && __ste_client_outbuffer2 == 0) && __ste_client_forwardReceiver2 <= 0) && 0 <= unknown-#StackHeapBarrier-unknown) && __ste_ClientAddressBook_size2 == 0) && __SELECTED_FEATURE_AutoResponder == 0) && __ste_client_autoResponse2 <= 0) && __ste_email_encryptionKey1 == 0) && __ste_client_autoResponse0 == 0) && __ste_email_body1 == 0) && __ste_ClientKeyring_size2 == 0) && 0 <= __ste_email_encryptionKey0) && #NULL == 0) && tmp == 1) && __ste_email_signKey1 == 0 [2022-12-14 09:04:34,796 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: ((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((!(__ste_Client_AddressBook1_Address2 == 0) || ((\old(__ste_ClientKeyring_size1) == __ste_ClientKeyring_size1 && \old(__ste_ClientKeyring_size2) == __ste_ClientKeyring_size2) && \old(__ste_ClientKeyring_size0) == __ste_ClientKeyring_size0)) || !(__ste_email_from0 == 0)) || !(0 <= __ste_Client_Keyring0_PublicKey1)) || !(__ste_client_autoResponse2 == 0)) || !(__ste_client_name2 == 0)) || !(__ste_Client_AddressBook1_Alias1 == 0)) || !(rjh == 2)) || !(__ste_client_privateKey2 <= 789)) || !(__ste_ClientAddressBook_size1 == 0)) || !(0 == __ste_Client_AddressBook0_Address0)) || !(#NULL == 0)) || !(__ste_Client_counter == 0)) || !(0 <= \old(__ste_ClientKeyring_size0))) || !(0 == __ste_Client_AddressBook0_Address1)) || !(bob == 1)) || !(queued_message == 0)) || !(0 <= __ste_Client_Keyring0_User0)) || !(__ste_client_name2 == 0)) || !(__ste_ClientAddressBook_size2 == 0)) || !(__SELECTED_FEATURE_AddressBook == 0)) || !(__ste_Client_AddressBook0_Alias2 == 0)) || !(__ste_email_id0 == 0)) || !(__SELECTED_FEATURE_Keys == 0)) || !(__ste_Client_AddressBook2_Address0 == 0)) || !(__ste_Client_Keyring0_User2 == 0)) || !(\old(__ste_ClientKeyring_size2) <= 0)) || !(queued_client == 0)) || !(0 <= __ste_Client_Keyring1_User1)) || !(__ste_Client_AddressBook2_Alias2 == 0)) || !(__ste_email_isSigned0 == 0)) || !(__ste_email_encryptionKey0 == 0)) || !(0 <= \old(__ste_ClientKeyring_size2))) || !(__ste_email_signKey1 == 0)) || !(__ste_client_name0 == 0)) || !(__ste_Client_AddressBook2_Address1 == 0)) || !(__GUIDSL_ROOT_PRODUCTION == 0)) || !(__ste_Client_Keyring1_User1 <= 0)) || !(__SELECTED_FEATURE_Forward == 0)) || !(0 <= __ste_Client_Keyring2_PublicKey0)) || !(__ste_email_body1 == 0)) || !(__GUIDSL_NON_TERMINAL_main == 0)) || !(__ste_email_to0 == 0)) || !(\old(handle) == bob)) || !(__ste_Client_Keyring1_PublicKey2 == 0)) || !(__ste_client_outbuffer0 == 0)) || !(0 == __ste_Client_AddressBook0_Address2)) || !(__ste_client_forwardReceiver0 == 0)) || !(__ste_email_body1 == 0)) || !(__ste_email_body0 == 0)) || !(__ste_email_isEncrypted1 == 0)) || !(__ste_Client_AddressBook1_Alias0 == 0)) || !(head == 0)) || !(__ste_email_id1 == 0)) || !(__ste_client_forwardReceiver2 == 0)) || !(0 <= __ste_Client_Keyring2_User1)) || !(789 <= __ste_client_privateKey2)) || !(__ste_client_outbuffer1 == 0)) || !(__ste_Client_Keyring1_PublicKey1 <= 0)) || !(__ste_email_signKey0 == 0)) || !(__ste_Client_Keyring2_User0 <= 0)) || !(__SELECTED_FEATURE_Sign == 0)) || !(__ste_Client_AddressBook2_Alias1 == 0)) || !(__ste_email_isSignatureVerified0 == 0)) || !(__ste_Client_AddressBook0_Alias0 == 0)) || !(__ste_Client_Keyring1_PublicKey0 <= 0)) || !(__ste_client_outbuffer3 == 0)) || !(\old(__ste_ClientKeyring_size1) <= 0)) || !(__SELECTED_FEATURE_Base == 0)) || !(__ste_email_encryptionKey1 == 0)) || !(__ste_email_subject0 == 0)) || !(0 <= __ste_Client_Keyring2_User0)) || !(__ste_Client_Keyring1_User0 <= 0)) || !(__ste_email_to1 == 0)) || !(__ste_Client_AddressBook1_Alias2 == 0)) || !(#NULL == 0)) || !(__ste_Client_Keyring2_User1 <= 0)) || !(__ste_Client_Keyring2_PublicKey1 <= 0)) || !(__ste_email_isSignatureVerified1 == 0)) || !(__ste_email_subject1 == 0)) || !(__ste_client_autoResponse1 == 0)) || !(__ste_Client_AddressBook2_Address2 == 0)) || !(__ste_client_name1 == 0)) || !(0 <= __ste_Client_Keyring2_PublicKey1)) || !(__ste_email_body0 == 0)) || !(__ste_Client_AddressBook1_Address1 == 0)) || !(__SELECTED_FEATURE_Decrypt == 0)) || !(0 <= __ste_Client_Keyring0_PublicKey0)) || !(__ste_Client_Keyring0_PublicKey1 <= 0)) || !(__ste_client_name0 == 0)) || !(3 == chuck)) || !(__ste_client_idCounter2 <= 3)) || !(__ste_Client_AddressBook1_Address0 == 0)) || !(0 <= __ste_Client_Keyring0_User1)) || !(__SELECTED_FEATURE_Verify == 0)) || !(0 <= unknown-#StackHeapBarrier-unknown)) || !(0 <= \old(__ste_ClientKeyring_size1))) || !(__ste_Client_Keyring2_User2 == 0)) || !(__SELECTED_FEATURE_AutoResponder == 0)) || !(0 <= __ste_Client_Keyring1_PublicKey0)) || !(\old(__ste_ClientKeyring_size0) <= 0)) || !(__ste_ClientAddressBook_size0 == 0)) || !(__ste_Client_Keyring2_PublicKey0 <= 0)) || !(0 <= __ste_Client_Keyring1_User0)) || !(__ste_client_forwardReceiver3 == 0)) || !(__ste_client_forwardReceiver1 == 0)) || !(__ste_Client_Keyring1_User2 == 0)) || !(__ste_Client_Keyring0_User0 <= 0)) || !(__ste_client_outbuffer2 == 0)) || !(__ste_email_isEncrypted0 == 0)) || !(__ste_Client_Keyring2_PublicKey2 == 0)) || !(__SELECTED_FEATURE_Encrypt == 0)) || !(__ste_Client_Keyring0_PublicKey0 <= 0)) || !(__ste_client_autoResponse0 == 0)) || !(queue_empty == 1)) || !(__ste_client_name1 == 0)) || !(__ste_Client_Keyring0_User1 <= 0)) || !(__ste_Client_AddressBook2_Alias0 == 0)) || !(__ste_email_isSigned1 == 0)) || !(head == 0)) || !(__ste_Client_AddressBook0_Alias1 == 0)) || !(0 <= __ste_Client_Keyring1_PublicKey1)) || !(__ste_Email_counter == 0)) || !(3 <= __ste_client_idCounter2)) || !(__ste_email_from1 == 0)) || !(__ste_email_subject1 == 0)) || !(0 == __ste_email_subject0)) || !(__ste_Client_Keyring0_PublicKey2 == 0) [2022-12-14 09:04:34,797 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: ((((!(\old(sender) == 1) || (((sender == 1 && __ste_email_isSigned0 == 0) && __ste_email_isEncrypted0 == 0) && 1 == msg)) || !(bob == 1)) || !(\old(__ste_email_isEncrypted0) == 0)) || !(\old(__ste_email_isSigned0) == 0)) || !(queue_empty == 1) [2022-12-14 09:04:34,800 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: ((((((((((__ste_email_isSigned0 == 0 && client == 1) && msg == 1) && __ste_client_privateKey0 == aux-getClientPrivateKey(client)-aux) && client == 1) && __ste_email_isEncrypted0 == 0) || !(bob == 1)) || !(\old(msg) == 1)) || !(\old(client) == 1)) || !(\old(__ste_email_isEncrypted0) == 0)) || !(\old(__ste_email_isSigned0) == 0)) || !(queue_empty == 1) [2022-12-14 09:04:34,800 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (((((!(bob == 1) || !(\old(msg) == 1)) || (((((((msg == 1 && (__ste_email_isSigned0 == 0 || !(__ste_client_privateKey0 == 0))) && msg == 1) && client == 1) && msg == 1) && client == 1) && client == 1) && (!(__ste_client_privateKey0 == 0) || tmp___0 == 0))) || !(\old(client) == 1)) || !(\old(__ste_email_isEncrypted0) == 0)) || !(\old(__ste_email_isSigned0) == 0)) || !(queue_empty == 1) [2022-12-14 09:04:34,800 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: ((((!(bob == 1) || !(\old(msg) == 1)) || !(\old(client) == 1)) || !(\old(__ste_email_isEncrypted0) == 0)) || !(\old(__ste_email_isSigned0) == 0)) || !(queue_empty == 1) [2022-12-14 09:04:34,801 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (((((!(bob == 1) || !(\old(msg) == 1)) || (((((((msg == 1 && (__ste_email_isSigned0 == 0 || !(__ste_client_privateKey0 == 0))) && msg == 1) && client == 1) && msg == 1) && client == 1) && client == 1) && (!(__ste_client_privateKey0 == 0) || tmp___0 == 0))) || !(\old(client) == 1)) || !(\old(__ste_email_isEncrypted0) == 0)) || !(\old(__ste_email_isSigned0) == 0)) || !(queue_empty == 1) [2022-12-14 09:04:34,801 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (msg == \old(msg) && (aux-isEncrypted(msg)-aux == __ste_email_isEncrypted0 || !(\old(msg) == 1))) || !(queue_empty == 1) [2022-12-14 09:04:34,801 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (((((!(bob == 1) || (((__ste_email_isSigned0 == 0 || !(__ste_client_privateKey0 == 0)) && msg == 1) && client == 1)) || !(\old(msg) == 1)) || !(\old(client) == 1)) || !(\old(__ste_email_isEncrypted0) == 0)) || !(\old(__ste_email_isSigned0) == 0)) || !(queue_empty == 1) [2022-12-14 09:04:34,801 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (((((!(bob == 1) || !(\old(msg) == 1)) || (((((((msg == 1 && (__ste_email_isSigned0 == 0 || !(__ste_client_privateKey0 == 0))) && msg == 1) && client == 1) && msg == 1) && client == 1) && client == 1) && (!(__ste_client_privateKey0 == 0) || tmp___0 == 0))) || !(\old(client) == 1)) || !(\old(__ste_email_isEncrypted0) == 0)) || !(\old(__ste_email_isSigned0) == 0)) || !(queue_empty == 1) [2022-12-14 09:04:34,868 INFO L141 WitnessManager]: Wrote witness to /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_1f82ca65-6edb-49dc-97e2-5ef2786422ba/bin/utaipan-gh47qXpMRh/witness.graphml [2022-12-14 09:04:34,868 INFO L132 PluginConnector]: ------------------------ END Witness Printer---------------------------- [2022-12-14 09:04:34,869 INFO L158 Benchmark]: Toolchain (without parser) took 755294.72ms. Allocated memory was 136.3MB in the beginning and 717.2MB in the end (delta: 580.9MB). Free memory was 100.9MB in the beginning and 238.5MB in the end (delta: -137.6MB). Peak memory consumption was 444.9MB. Max. memory is 16.1GB. [2022-12-14 09:04:34,869 INFO L158 Benchmark]: CDTParser took 0.12ms. Allocated memory is still 136.3MB. Free memory was 77.9MB in the beginning and 77.8MB in the end (delta: 125.9kB). There was no memory consumed. Max. memory is 16.1GB. [2022-12-14 09:04:34,869 INFO L158 Benchmark]: CACSL2BoogieTranslator took 497.61ms. Allocated memory is still 136.3MB. Free memory was 100.4MB in the beginning and 59.5MB in the end (delta: 40.9MB). Peak memory consumption was 39.8MB. Max. memory is 16.1GB. [2022-12-14 09:04:34,869 INFO L158 Benchmark]: Boogie Procedure Inliner took 73.68ms. Allocated memory was 136.3MB in the beginning and 163.6MB in the end (delta: 27.3MB). Free memory was 59.5MB in the beginning and 131.9MB in the end (delta: -72.4MB). Peak memory consumption was 16.7MB. Max. memory is 16.1GB. [2022-12-14 09:04:34,870 INFO L158 Benchmark]: Boogie Preprocessor took 32.91ms. Allocated memory is still 163.6MB. Free memory was 131.9MB in the beginning and 127.7MB in the end (delta: 4.2MB). Peak memory consumption was 4.2MB. Max. memory is 16.1GB. [2022-12-14 09:04:34,870 INFO L158 Benchmark]: RCFGBuilder took 972.02ms. Allocated memory is still 163.6MB. Free memory was 127.7MB in the beginning and 111.8MB in the end (delta: 15.9MB). Peak memory consumption was 74.6MB. Max. memory is 16.1GB. [2022-12-14 09:04:34,870 INFO L158 Benchmark]: TraceAbstraction took 753579.69ms. Allocated memory was 163.6MB in the beginning and 717.2MB in the end (delta: 553.6MB). Free memory was 110.7MB in the beginning and 256.3MB in the end (delta: -145.6MB). Peak memory consumption was 466.9MB. Max. memory is 16.1GB. [2022-12-14 09:04:34,871 INFO L158 Benchmark]: Witness Printer took 133.47ms. Allocated memory is still 717.2MB. Free memory was 256.3MB in the beginning and 238.5MB in the end (delta: 17.8MB). Peak memory consumption was 18.9MB. Max. memory is 16.1GB. [2022-12-14 09:04:34,872 INFO L339 ainManager$Toolchain]: ####################### End [Toolchain 1] ####################### --- Results --- * Results from de.uni_freiburg.informatik.ultimate.core: - StatisticsResult: Toolchain Benchmarks Benchmark results are: * CDTParser took 0.12ms. Allocated memory is still 136.3MB. Free memory was 77.9MB in the beginning and 77.8MB in the end (delta: 125.9kB). There was no memory consumed. Max. memory is 16.1GB. * CACSL2BoogieTranslator took 497.61ms. Allocated memory is still 136.3MB. Free memory was 100.4MB in the beginning and 59.5MB in the end (delta: 40.9MB). Peak memory consumption was 39.8MB. Max. memory is 16.1GB. * Boogie Procedure Inliner took 73.68ms. Allocated memory was 136.3MB in the beginning and 163.6MB in the end (delta: 27.3MB). Free memory was 59.5MB in the beginning and 131.9MB in the end (delta: -72.4MB). Peak memory consumption was 16.7MB. Max. memory is 16.1GB. * Boogie Preprocessor took 32.91ms. Allocated memory is still 163.6MB. Free memory was 131.9MB in the beginning and 127.7MB in the end (delta: 4.2MB). Peak memory consumption was 4.2MB. Max. memory is 16.1GB. * RCFGBuilder took 972.02ms. Allocated memory is still 163.6MB. Free memory was 127.7MB in the beginning and 111.8MB in the end (delta: 15.9MB). Peak memory consumption was 74.6MB. Max. memory is 16.1GB. * TraceAbstraction took 753579.69ms. Allocated memory was 163.6MB in the beginning and 717.2MB in the end (delta: 553.6MB). Free memory was 110.7MB in the beginning and 256.3MB in the end (delta: -145.6MB). Peak memory consumption was 466.9MB. Max. memory is 16.1GB. * Witness Printer took 133.47ms. Allocated memory is still 717.2MB. Free memory was 256.3MB in the beginning and 238.5MB in the end (delta: 17.8MB). Peak memory consumption was 18.9MB. Max. memory is 16.1GB. * Results from de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction: - StatisticsResult: ErrorAutomatonStatistics NumberErrorTraces: 0, NumberStatementsAllTraces: 0, NumberRelevantStatements: 0, 0.0s ErrorAutomatonConstructionTimeTotal, 0.0s FaulLocalizationTime, NumberStatementsFirstTrace: -1, TraceLengthAvg: 0, 0.0s ErrorAutomatonConstructionTimeAvg, 0.0s ErrorAutomatonDifferenceTimeAvg, 0.0s ErrorAutomatonDifferenceTimeTotal, NumberOfNoEnhancement: 0, NumberOfFiniteEnhancement: 0, NumberOfInfiniteEnhancement: 0 - PositiveResult [Line: 450]: call to reach_error is unreachable For all program executions holds that call to reach_error is unreachable at this location - StatisticsResult: Ultimate Automizer benchmark data CFG has 23 procedures, 180 locations, 1 error locations. Started 1 CEGAR loops. OverallTime: 753.5s, OverallIterations: 11, TraceHistogramMax: 4, PathProgramHistogramMax: 1, EmptinessCheckTime: 0.0s, AutomataDifference: 60.8s, DeadEndRemovalTime: 0.0s, HoareAnnotationTime: 175.4s, InitialAbstractionConstructionTime: 0.0s, HoareTripleCheckerStatistics: 0 mSolverCounterUnknown, 1877 SdHoareTripleChecker+Valid, 24.0s IncrementalHoareTripleChecker+Time, 0 mSdLazyCounter, 1765 mSDsluCounter, 17826 SdHoareTripleChecker+Invalid, 22.2s Time, 0 mProtectedAction, 0 SdHoareTripleChecker+Unchecked, 0 IncrementalHoareTripleChecker+Unchecked, 15363 mSDsCounter, 452 IncrementalHoareTripleChecker+Valid, 0 mProtectedPredicate, 12296 IncrementalHoareTripleChecker+Invalid, 12748 SdHoareTripleChecker+Unknown, 0 mSolverCounterNotChecked, 452 mSolverCounterUnsat, 2463 mSDtfsCounter, 12296 mSolverCounterSat, 0.3s SdHoareTripleChecker+Time, 0 IncrementalHoareTripleChecker+Unknown, PredicateUnifierStatistics: 0 DeclaredPredicates, 1048 GetRequests, 808 SyntacticMatches, 2 SemanticMatches, 238 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 2358 ImplicationChecksByTransitivity, 348.4s Time, 0.0s BasicInterpolantAutomatonTime, BiggestAbstraction: size=1328occurred in iteration=10, InterpolantAutomatonStates: 154, traceCheckStatistics: No data available, InterpolantConsolidationStatistics: No data available, PathInvariantsStatistics: No data available, 0/0 InterpolantCoveringCapability, TotalInterpolationStatistics: No data available, 0.0s DumpTime, AutomataMinimizationStatistics: 3.4s AutomataMinimizationTime, 11 MinimizatonAttempts, 326 StatesRemovedByMinimization, 8 NontrivialMinimizations, HoareAnnotationStatistics: 0.0s HoareAnnotationTime, 108 LocationsWithAnnotation, 1457 PreInvPairs, 2259 NumberOfFragments, 9639 HoareAnnotationTreeSize, 1457 FomulaSimplifications, 920687 FormulaSimplificationTreeSizeReduction, 126.5s HoareSimplificationTime, 108 FomulaSimplificationsInter, 721403 FormulaSimplificationTreeSizeReductionInter, 48.8s HoareSimplificationTimeInter, RefinementEngineStatistics: TRACE_CHECK: 0.2s SsaConstructionTime, 0.6s SatisfiabilityAnalysisTime, 2.7s InterpolantComputationTime, 1278 NumberOfCodeBlocks, 1278 NumberOfCodeBlocksAsserted, 15 NumberOfCheckSat, 1570 ConstructedInterpolants, 0 QuantifiedInterpolants, 2733 SizeOfPredicates, 0 NumberOfNonLiveVariables, 4054 ConjunctsInSsa, 12 ConjunctsInUnsatCore, 19 InterpolantComputations, 7 PerfectInterpolantSequences, 412/436 InterpolantCoveringCapability, INVARIANT_SYNTHESIS: No data available, INTERPOLANT_CONSOLIDATION: No data available, ABSTRACT_INTERPRETATION: No data available, PDR: No data available, ACCELERATED_INTERPOLATION: No data available, SIFA: OVERALL_TIME: 117.6s, ICFG_INTERPRETER_ENTERED_PROCEDURES: 12, DAG_INTERPRETER_EARLY_EXIT_QUERIES_NONTRIVIAL: 110, DAG_INTERPRETER_EARLY_EXITS: 4, TOOLS_POST_APPLICATIONS: 100, TOOLS_POST_TIME: 29.3s, TOOLS_POST_CALL_APPLICATIONS: 74, TOOLS_POST_CALL_TIME: 50.9s, TOOLS_POST_RETURN_APPLICATIONS: 52, TOOLS_POST_RETURN_TIME: 17.1s, TOOLS_QUANTIFIERELIM_APPLICATIONS: 225, TOOLS_QUANTIFIERELIM_TIME: 97.0s, TOOLS_QUANTIFIERELIM_MAX_TIME: 4.8s, FLUID_QUERY_TIME: 0.0s, FLUID_QUERIES: 298, FLUID_YES_ANSWERS: 0, DOMAIN_JOIN_APPLICATIONS: 81, DOMAIN_JOIN_TIME: 19.8s, DOMAIN_ALPHA_APPLICATIONS: 0, DOMAIN_ALPHA_TIME: 0.0s, DOMAIN_WIDEN_APPLICATIONS: 0, DOMAIN_WIDEN_TIME: 0.0s, DOMAIN_ISSUBSETEQ_APPLICATIONS: 3, DOMAIN_ISSUBSETEQ_TIME: 0.0s, DOMAIN_ISBOTTOM_APPLICATIONS: 110, DOMAIN_ISBOTTOM_TIME: 0.4s, LOOP_SUMMARIZER_APPLICATIONS: 3, LOOP_SUMMARIZER_CACHE_MISSES: 3, LOOP_SUMMARIZER_OVERALL_TIME: 15.0s, LOOP_SUMMARIZER_NEW_COMPUTATION_TIME: 15.0s, LOOP_SUMMARIZER_FIXPOINT_ITERATIONS: 3, CALL_SUMMARIZER_APPLICATIONS: 52, CALL_SUMMARIZER_CACHE_MISSES: 9, CALL_SUMMARIZER_OVERALL_TIME: 0.1s, CALL_SUMMARIZER_NEW_COMPUTATION_TIME: 0.1s, PROCEDURE_GRAPH_BUILDER_TIME: 0.0s, PATH_EXPR_TIME: 0.0s, REGEX_TO_DAG_TIME: 0.0s, DAG_COMPRESSION_TIME: 0.0s, DAG_COMPRESSION_PROCESSED_NODES: 3254, DAG_COMPRESSION_RETAINED_NODES: 323, ReuseStatistics: No data available - AllSpecificationsHoldResult: All specifications hold 1 specifications checked. All of them hold - InvariantResult [Line: 179]: Loop Invariant Derived loop invariant: (((((!(bob == 1) || (((__ste_email_isSigned0 == 0 || !(__ste_client_privateKey0 == 0)) && msg == 1) && client == 1)) || !(\old(msg) == 1)) || !(\old(client) == 1)) || !(\old(__ste_email_isEncrypted0) == 0)) || !(\old(__ste_email_isSigned0) == 0)) || !(queue_empty == 1) - InvariantResult [Line: 2558]: Loop Invariant Derived loop invariant: (((__ste_email_isSigned0 == 0 && bob == 1) && queue_empty == 1) && __ste_email_isEncrypted0 == 0) && tmp == 1 - InvariantResult [Line: 941]: Loop Invariant Derived loop invariant: (((__ste_email_isSigned0 == 0 && bob == 1) && queue_empty == 1) && __ste_email_isEncrypted0 == 0) && tmp == 1 - InvariantResult [Line: 2295]: Loop Invariant Derived loop invariant: ((((!(\old(sender) == 1) || (((sender == 1 && __ste_email_isSigned0 == 0) && __ste_email_isEncrypted0 == 0) && 1 == msg)) || !(bob == 1)) || !(\old(__ste_email_isEncrypted0) == 0)) || !(\old(__ste_email_isSigned0) == 0)) || !(queue_empty == 1) - InvariantResult [Line: 2357]: Loop Invariant Derived loop invariant: (((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((queued_client == 0 && __ste_Client_Keyring1_User2 == 0) && __GUIDSL_NON_TERMINAL_main == 0) && 456 <= __ste_client_privateKey1) && 3 <= chuck___0) && __ste_email_isEncrypted1 == 0) && __ste_email_subject0 == 0) && __SELECTED_FEATURE_Sign == 0) && 0 == __ste_Client_AddressBook0_Address2) && __cil_tmp2 == 0) && __ste_client_outbuffer3 == 0) && 1 <= \result) && \old(rjh___0) <= 2) && 1 <= \old(bob___0)) && 19 == __cil_tmp1) && __ste_Client_counter == 0) && __ste_Client_Keyring1_PublicKey2 == 0) && retValue_acc <= 2147483647) && __cil_tmp2 == 20) && \old(bob___0) <= 1) && __ste_client_autoResponse1 == 0) && 2 <= rjh___0) && __ste_Client_AddressBook2_Alias0 == 0) && __cil_tmp1 == 0) && 1 <= \old(bob___0)) && 0 == __ste_email_subject0) && __ste_Client_AddressBook2_Alias1 == 0) && __ste_Client_Keyring2_PublicKey2 == 0) && __ste_client_forwardReceiver3 == 0) && \old(bob___0) <= 1) && __ste_client_name2 == 0) && __ste_client_name1 == 0) && \old(chuck___0) <= 3) && __SELECTED_FEATURE_Verify == 0) && __ste_Client_Keyring1_User0 == 0) && __ste_client_idCounter2 <= 3) && __ste_email_body1 == 0) && __SELECTED_FEATURE_Encrypt == 0) && __ste_Client_AddressBook1_Address2 == 0) && 1 <= bob___0) && __ste_ClientAddressBook_size1 == 0) && __ste_Client_Keyring0_PublicKey0 == 0) && __ste_Email_counter == 0) && __ste_ClientKeyring_size1 == 0) && __ste_email_body0 == 0) && __ste_email_isSignatureVerified0 == 0) && __ste_Client_Keyring0_User2 == 0) && __ste_ClientAddressBook_size0 == 0) && __ste_Client_Keyring0_User1 == 0) && __ste_Client_AddressBook1_Alias1 == 0) && __ste_email_to1 == 0) && __ste_client_name1 == 0) && head == 0) && __ste_client_name0 == 0) && __ste_Client_Keyring0_PublicKey2 == 0) && __ste_Client_Keyring1_PublicKey0 == 0) && __ste_email_to0 == 0) && __ste_email_signKey0 == 0) && __SELECTED_FEATURE_Decrypt == 0) && __ste_email_encryptionKey0 == 0) && __SELECTED_FEATURE_Keys == 0) && __SELECTED_FEATURE_AddressBook == 0) && __ste_client_forwardReceiver2 == 0) && __ste_Client_Keyring0_PublicKey1 == 0) && __SELECTED_FEATURE_Forward == 0) && rjh___0 <= 2) && __ste_Client_Keyring0_User0 == 0) && __ste_email_isSigned0 == 0) && __ste_Client_Keyring2_PublicKey1 == 0) && __ste_email_isSigned1 == 0) && __ste_email_body0 == 0) && __ste_Client_AddressBook0_Alias0 == 0) && 0 <= 2147483648 + retValue_acc) && __ste_email_id0 == 0) && \old(rjh___0) <= 2) && __ste_client_privateKey1 <= 456) && __ste_email_from0 == 0) && __ste_Client_Keyring2_User1 == 0) && bob___0 <= 1) && 3 <= __ste_client_idCounter2) && __ste_Client_AddressBook2_Address2 == 0) && \result <= 1) && chuck___0 <= 3) && 3 == chuck) && __ste_Client_AddressBook2_Address1 == 0) && bob == 1) && __ste_client_forwardReceiver1 == 0) && 1 <= bob___0) && 3 <= chuck___0) && __ste_Client_AddressBook1_Alias2 == 0) && __ste_client_outbuffer0 == 0) && 2 <= rjh___0) && queue_empty == 1) && rjh___0 <= 2) && __SELECTED_FEATURE_Base == 0) && __ste_client_forwardReceiver0 == 0) && 3 <= \old(chuck___0)) && __ste_Client_Keyring2_User0 == 0) && rjh == 2) && 0 == __ste_Client_AddressBook0_Address1) && __ste_Client_AddressBook2_Address0 == 0) && __ste_email_isSignatureVerified1 == 0) && __ste_Client_Keyring1_PublicKey1 == 0) && __ste_Client_Keyring2_PublicKey0 == 0) && __ste_Client_AddressBook1_Address0 == 0) && __ste_client_name2 == 0) && __ste_email_from1 == 0) && 2 <= \old(rjh___0)) && __ste_email_subject1 == 0) && \old(chuck___0) <= 3) && __ste_Client_AddressBook1_Alias0 == 0) && __ste_Client_Keyring2_User2 == 0) && bob___0 <= 1) && head == 0) && chuck___0 <= 3) && 2 <= \old(rjh___0)) && __ste_Client_Keyring1_User1 == 0) && #NULL == 0) && __ste_Client_AddressBook2_Alias2 == 0) && retValue_acc == 1) && __ste_email_subject1 == 0) && __ste_Client_AddressBook0_Alias2 == 0) && __ste_ClientKeyring_size0 == 0) && __ste_email_isEncrypted0 == 0) && queued_message == 0) && __ste_Client_AddressBook1_Address1 == 0) && 0 == __ste_Client_AddressBook0_Address0) && __ste_client_outbuffer1 == 0) && __ste_Client_AddressBook0_Alias1 == 0) && __GUIDSL_ROOT_PRODUCTION == 0) && 3 <= \old(chuck___0)) && __ste_client_name0 == 0) && __ste_email_id1 == 0) && __ste_client_outbuffer2 == 0) && 0 <= unknown-#StackHeapBarrier-unknown) && __ste_ClientAddressBook_size2 == 0) && __SELECTED_FEATURE_AutoResponder == 0) && __ste_email_encryptionKey1 == 0) && __ste_client_autoResponse0 == 0) && __ste_email_body1 == 0) && __ste_ClientKeyring_size2 == 0) && __ste_client_autoResponse2 == 0) && #NULL == 0) && tmp == 1) && __ste_email_signKey1 == 0 - InvariantResult [Line: 2386]: Loop Invariant Derived loop invariant: queue_empty == 1 - InvariantResult [Line: 2548]: Loop Invariant Derived loop invariant: (((__ste_email_isSigned0 == 0 && bob == 1) && queue_empty == 1) && __ste_email_isEncrypted0 == 0) && tmp == 1 - InvariantResult [Line: 2389]: Loop Invariant Derived loop invariant: 1 <= tmp___1 && queue_empty == 1 - InvariantResult [Line: 2367]: Loop Invariant Derived loop invariant: ((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((queued_client == 0 && __ste_Client_Keyring1_User2 == 0) && __GUIDSL_NON_TERMINAL_main == 0) && 3 <= chuck___0) && __ste_email_isEncrypted1 == 0) && __ste_email_subject0 == 0) && __SELECTED_FEATURE_Sign == 0) && 0 == __ste_Client_AddressBook0_Address2) && __cil_tmp2 == 0) && __ste_client_outbuffer3 == 0) && 1 <= \result) && \old(rjh___0) <= 2) && 1 <= \old(bob___0)) && 19 == __cil_tmp1) && __ste_Client_counter == 0) && __ste_Client_Keyring1_PublicKey2 == 0) && retValue_acc <= 2147483647) && __cil_tmp2 == 20) && \old(bob___0) <= 1) && __ste_client_autoResponse1 == 0) && 2 <= rjh___0) && __ste_Client_AddressBook2_Alias0 == 0) && __cil_tmp1 == 0) && 1 <= \old(bob___0)) && 0 == __ste_email_subject0) && __ste_Client_AddressBook2_Alias1 == 0) && __ste_Client_Keyring2_PublicKey2 == 0) && __ste_client_forwardReceiver3 == 0) && \old(bob___0) <= 1) && __ste_client_name2 == 0) && __ste_client_name1 == 0) && \old(chuck___0) <= 3) && __SELECTED_FEATURE_Verify == 0) && __ste_Client_Keyring1_User0 == 0) && __ste_client_idCounter2 <= 3) && __ste_email_body1 == 0) && __SELECTED_FEATURE_Encrypt == 0) && __ste_Client_AddressBook1_Address2 == 0) && 1 <= bob___0) && __ste_ClientAddressBook_size1 == 0) && __ste_Client_Keyring0_PublicKey0 == 0) && __ste_Email_counter == 0) && __ste_ClientKeyring_size1 == 0) && __ste_email_body0 == 0) && __ste_email_isSignatureVerified0 == 0) && __ste_Client_Keyring0_User2 == 0) && __ste_ClientAddressBook_size0 == 0) && __ste_Client_Keyring0_User1 == 0) && __ste_Client_AddressBook1_Alias1 == 0) && __ste_email_to1 == 0) && __ste_client_name1 == 0) && head == 0) && __ste_client_name0 == 0) && __ste_Client_Keyring0_PublicKey2 == 0) && __ste_Client_Keyring1_PublicKey0 == 0) && __ste_email_to0 == 0) && 789 == __ste_client_privateKey2) && __ste_email_signKey0 == 0) && __SELECTED_FEATURE_Decrypt == 0) && __SELECTED_FEATURE_Keys == 0) && __SELECTED_FEATURE_AddressBook == 0) && __ste_Client_Keyring0_PublicKey1 == 0) && __SELECTED_FEATURE_Forward == 0) && rjh___0 <= 2) && __ste_Client_Keyring0_User0 == 0) && __ste_email_isSigned0 == 0) && __ste_Client_Keyring2_PublicKey1 == 0) && __ste_email_isSigned1 == 0) && __ste_email_body0 == 0) && __ste_Client_AddressBook0_Alias0 == 0) && 0 <= 2147483648 + retValue_acc) && __ste_email_id0 == 0) && \old(rjh___0) <= 2) && __ste_email_from0 == 0) && bob___0 <= 1) && 3 <= __ste_client_idCounter2) && __ste_Client_AddressBook2_Address2 == 0) && \result <= 1) && chuck___0 <= 3) && 3 == chuck) && __ste_Client_AddressBook2_Address1 == 0) && bob == 1) && 1 <= bob___0) && 3 <= chuck___0) && __ste_Client_AddressBook1_Alias2 == 0) && __ste_client_outbuffer0 == 0) && 2 <= rjh___0) && queue_empty == 1) && rjh___0 <= 2) && __SELECTED_FEATURE_Base == 0) && __ste_client_forwardReceiver0 == 0) && 3 <= \old(chuck___0)) && __ste_Client_Keyring2_User0 == 0) && rjh == 2) && 0 == __ste_Client_AddressBook0_Address1) && __ste_Client_AddressBook2_Address0 == 0) && __ste_email_isSignatureVerified1 == 0) && __ste_Client_Keyring1_PublicKey1 == 0) && __ste_Client_Keyring2_PublicKey0 == 0) && __ste_Client_AddressBook1_Address0 == 0) && 0 <= __ste_client_forwardReceiver2) && __ste_client_name2 == 0) && __ste_email_from1 == 0) && 2 <= \old(rjh___0)) && __ste_email_encryptionKey0 <= 0) && __ste_email_subject1 == 0) && __ste_ClientKeyring_size0 <= 0) && \old(chuck___0) <= 3) && __ste_Client_AddressBook1_Alias0 == 0) && __ste_Client_Keyring2_User2 == 0) && bob___0 <= 1) && head == 0) && chuck___0 <= 3) && __ste_client_forwardReceiver1 <= 0) && 2 <= \old(rjh___0)) && __ste_Client_Keyring1_User1 == 0) && #NULL == 0) && __ste_Client_AddressBook2_Alias2 == 0) && __ste_Client_Keyring2_User1 <= 0) && retValue_acc == 1) && 0 <= __ste_client_autoResponse2) && __ste_email_subject1 == 0) && __ste_Client_AddressBook0_Alias2 == 0) && __ste_email_isEncrypted0 == 0) && 0 <= __ste_Client_Keyring2_User1) && queued_message == 0) && __ste_Client_AddressBook1_Address1 == 0) && 0 == __ste_Client_AddressBook0_Address0) && __ste_client_outbuffer1 == 0) && __ste_Client_AddressBook0_Alias1 == 0) && 0 <= __ste_ClientKeyring_size0) && __GUIDSL_ROOT_PRODUCTION == 0) && 3 <= \old(chuck___0)) && 0 <= __ste_client_forwardReceiver1) && __ste_client_name0 == 0) && __ste_email_id1 == 0) && __ste_client_outbuffer2 == 0) && __ste_client_forwardReceiver2 <= 0) && 0 <= unknown-#StackHeapBarrier-unknown) && __ste_ClientAddressBook_size2 == 0) && __SELECTED_FEATURE_AutoResponder == 0) && __ste_client_autoResponse2 <= 0) && __ste_email_encryptionKey1 == 0) && __ste_client_autoResponse0 == 0) && __ste_email_body1 == 0) && __ste_ClientKeyring_size2 == 0) && 0 <= __ste_email_encryptionKey0) && #NULL == 0) && tmp == 1) && __ste_email_signKey1 == 0 - InvariantResult [Line: 430]: Loop Invariant Derived loop invariant: (((((!(bob == 1) || !(\old(msg) == 1)) || (((((((msg == 1 && (__ste_email_isSigned0 == 0 || !(__ste_client_privateKey0 == 0))) && msg == 1) && client == 1) && msg == 1) && client == 1) && client == 1) && (!(__ste_client_privateKey0 == 0) || tmp___0 == 0))) || !(\old(client) == 1)) || !(\old(__ste_email_isEncrypted0) == 0)) || !(\old(__ste_email_isSigned0) == 0)) || !(queue_empty == 1) - InvariantResult [Line: 2538]: Loop Invariant Derived loop invariant: (((__ste_email_isSigned0 == 0 && bob == 1) && queue_empty == 1) && __ste_email_isEncrypted0 == 0) && tmp == 1 - InvariantResult [Line: 1779]: Loop Invariant Derived loop invariant: ((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((!(__ste_Client_AddressBook1_Address2 == 0) || ((\old(__ste_ClientKeyring_size1) == __ste_ClientKeyring_size1 && \old(__ste_ClientKeyring_size2) == __ste_ClientKeyring_size2) && \old(__ste_ClientKeyring_size0) == __ste_ClientKeyring_size0)) || !(__ste_email_from0 == 0)) || !(0 <= __ste_Client_Keyring0_PublicKey1)) || !(__ste_client_autoResponse2 == 0)) || !(__ste_client_name2 == 0)) || !(__ste_Client_AddressBook1_Alias1 == 0)) || !(rjh == 2)) || !(__ste_client_privateKey2 <= 789)) || !(__ste_ClientAddressBook_size1 == 0)) || !(0 == __ste_Client_AddressBook0_Address0)) || !(#NULL == 0)) || !(__ste_Client_counter == 0)) || !(0 <= \old(__ste_ClientKeyring_size0))) || !(0 == __ste_Client_AddressBook0_Address1)) || !(bob == 1)) || !(queued_message == 0)) || !(0 <= __ste_Client_Keyring0_User0)) || !(__ste_client_name2 == 0)) || !(__ste_ClientAddressBook_size2 == 0)) || !(__SELECTED_FEATURE_AddressBook == 0)) || !(__ste_Client_AddressBook0_Alias2 == 0)) || !(__ste_email_id0 == 0)) || !(__SELECTED_FEATURE_Keys == 0)) || !(__ste_Client_AddressBook2_Address0 == 0)) || !(__ste_Client_Keyring0_User2 == 0)) || !(\old(__ste_ClientKeyring_size2) <= 0)) || !(queued_client == 0)) || !(0 <= __ste_Client_Keyring1_User1)) || !(__ste_Client_AddressBook2_Alias2 == 0)) || !(__ste_email_isSigned0 == 0)) || !(__ste_email_encryptionKey0 == 0)) || !(0 <= \old(__ste_ClientKeyring_size2))) || !(__ste_email_signKey1 == 0)) || !(__ste_client_name0 == 0)) || !(__ste_Client_AddressBook2_Address1 == 0)) || !(__GUIDSL_ROOT_PRODUCTION == 0)) || !(__ste_Client_Keyring1_User1 <= 0)) || !(__SELECTED_FEATURE_Forward == 0)) || !(0 <= __ste_Client_Keyring2_PublicKey0)) || !(__ste_email_body1 == 0)) || !(__GUIDSL_NON_TERMINAL_main == 0)) || !(__ste_email_to0 == 0)) || !(\old(handle) == bob)) || !(__ste_Client_Keyring1_PublicKey2 == 0)) || !(__ste_client_outbuffer0 == 0)) || !(0 == __ste_Client_AddressBook0_Address2)) || !(__ste_client_forwardReceiver0 == 0)) || !(__ste_email_body1 == 0)) || !(__ste_email_body0 == 0)) || !(__ste_email_isEncrypted1 == 0)) || !(__ste_Client_AddressBook1_Alias0 == 0)) || !(head == 0)) || !(__ste_email_id1 == 0)) || !(__ste_client_forwardReceiver2 == 0)) || !(0 <= __ste_Client_Keyring2_User1)) || !(789 <= __ste_client_privateKey2)) || !(__ste_client_outbuffer1 == 0)) || !(__ste_Client_Keyring1_PublicKey1 <= 0)) || !(__ste_email_signKey0 == 0)) || !(__ste_Client_Keyring2_User0 <= 0)) || !(__SELECTED_FEATURE_Sign == 0)) || !(__ste_Client_AddressBook2_Alias1 == 0)) || !(__ste_email_isSignatureVerified0 == 0)) || !(__ste_Client_AddressBook0_Alias0 == 0)) || !(__ste_Client_Keyring1_PublicKey0 <= 0)) || !(__ste_client_outbuffer3 == 0)) || !(\old(__ste_ClientKeyring_size1) <= 0)) || !(__SELECTED_FEATURE_Base == 0)) || !(__ste_email_encryptionKey1 == 0)) || !(__ste_email_subject0 == 0)) || !(0 <= __ste_Client_Keyring2_User0)) || !(__ste_Client_Keyring1_User0 <= 0)) || !(__ste_email_to1 == 0)) || !(__ste_Client_AddressBook1_Alias2 == 0)) || !(#NULL == 0)) || !(__ste_Client_Keyring2_User1 <= 0)) || !(__ste_Client_Keyring2_PublicKey1 <= 0)) || !(__ste_email_isSignatureVerified1 == 0)) || !(__ste_email_subject1 == 0)) || !(__ste_client_autoResponse1 == 0)) || !(__ste_Client_AddressBook2_Address2 == 0)) || !(__ste_client_name1 == 0)) || !(0 <= __ste_Client_Keyring2_PublicKey1)) || !(__ste_email_body0 == 0)) || !(__ste_Client_AddressBook1_Address1 == 0)) || !(__SELECTED_FEATURE_Decrypt == 0)) || !(0 <= __ste_Client_Keyring0_PublicKey0)) || !(__ste_Client_Keyring0_PublicKey1 <= 0)) || !(__ste_client_name0 == 0)) || !(3 == chuck)) || !(__ste_client_idCounter2 <= 3)) || !(__ste_Client_AddressBook1_Address0 == 0)) || !(0 <= __ste_Client_Keyring0_User1)) || !(__SELECTED_FEATURE_Verify == 0)) || !(0 <= unknown-#StackHeapBarrier-unknown)) || !(0 <= \old(__ste_ClientKeyring_size1))) || !(__ste_Client_Keyring2_User2 == 0)) || !(__SELECTED_FEATURE_AutoResponder == 0)) || !(0 <= __ste_Client_Keyring1_PublicKey0)) || !(\old(__ste_ClientKeyring_size0) <= 0)) || !(__ste_ClientAddressBook_size0 == 0)) || !(__ste_Client_Keyring2_PublicKey0 <= 0)) || !(0 <= __ste_Client_Keyring1_User0)) || !(__ste_client_forwardReceiver3 == 0)) || !(__ste_client_forwardReceiver1 == 0)) || !(__ste_Client_Keyring1_User2 == 0)) || !(__ste_Client_Keyring0_User0 <= 0)) || !(__ste_client_outbuffer2 == 0)) || !(__ste_email_isEncrypted0 == 0)) || !(__ste_Client_Keyring2_PublicKey2 == 0)) || !(__SELECTED_FEATURE_Encrypt == 0)) || !(__ste_Client_Keyring0_PublicKey0 <= 0)) || !(__ste_client_autoResponse0 == 0)) || !(queue_empty == 1)) || !(__ste_client_name1 == 0)) || !(__ste_Client_Keyring0_User1 <= 0)) || !(__ste_Client_AddressBook2_Alias0 == 0)) || !(__ste_email_isSigned1 == 0)) || !(head == 0)) || !(__ste_Client_AddressBook0_Alias1 == 0)) || !(0 <= __ste_Client_Keyring1_PublicKey1)) || !(__ste_Email_counter == 0)) || !(3 <= __ste_client_idCounter2)) || !(__ste_email_from1 == 0)) || !(__ste_email_subject1 == 0)) || !(0 == __ste_email_subject0)) || !(__ste_Client_Keyring0_PublicKey2 == 0) - InvariantResult [Line: 2265]: Loop Invariant Derived loop invariant: (msg == \old(msg) && (aux-isEncrypted(msg)-aux == __ste_email_isEncrypted0 || !(\old(msg) == 1))) || !(queue_empty == 1) - InvariantResult [Line: 980]: Loop Invariant Derived loop invariant: (((__ste_email_isSigned0 == 0 && bob == 1) && queue_empty == 1) && __ste_email_isEncrypted0 == 0) && tmp == 1 - InvariantResult [Line: 952]: Loop Invariant Derived loop invariant: (((__ste_email_isSigned0 == 0 && bob == 1) && queue_empty == 1) && __ste_email_isEncrypted0 == 0) && tmp == 1 - InvariantResult [Line: 1019]: Loop Invariant Derived loop invariant: (((__ste_email_isSigned0 == 0 && bob == 1) && queue_empty == 1) && __ste_email_isEncrypted0 == 0) && tmp == 1 - InvariantResult [Line: 1044]: Loop Invariant Derived loop invariant: (((__ste_email_isSigned0 == 0 && bob == 1) && queue_empty == 1) && __ste_email_isEncrypted0 == 0) && tmp == 1 - InvariantResult [Line: 919]: Loop Invariant Derived loop invariant: (((__ste_email_isSigned0 == 0 && bob == 1) && queue_empty == 1) && __ste_email_isEncrypted0 == 0) && tmp == 1 - InvariantResult [Line: 2466]: Loop Invariant Derived loop invariant: ((((__ste_email_isSigned0 == 0 && bob == 1) && queue_empty == 1) && op1 == 0) && __ste_email_isEncrypted0 == 0) && tmp == 1 - InvariantResult [Line: 2569]: Loop Invariant Derived loop invariant: (((((!(bob == 1) || !(\old(msg) == 1)) || (((((((msg == 1 && (__ste_email_isSigned0 == 0 || !(__ste_client_privateKey0 == 0))) && msg == 1) && client == 1) && msg == 1) && client == 1) && client == 1) && (!(__ste_client_privateKey0 == 0) || tmp___0 == 0))) || !(\old(client) == 1)) || !(\old(__ste_email_isEncrypted0) == 0)) || !(\old(__ste_email_isSigned0) == 0)) || !(queue_empty == 1) - InvariantResult [Line: 918]: Loop Invariant Derived loop invariant: (((__ste_email_isSigned0 == 0 && bob == 1) && queue_empty == 1) && __ste_email_isEncrypted0 == 0) && tmp == 1 - InvariantResult [Line: 382]: Loop Invariant Derived loop invariant: ((((((((((__ste_email_isSigned0 == 0 && client == 1) && msg == 1) && __ste_client_privateKey0 == aux-getClientPrivateKey(client)-aux) && client == 1) && __ste_email_isEncrypted0 == 0) || !(bob == 1)) || !(\old(msg) == 1)) || !(\old(client) == 1)) || !(\old(__ste_email_isEncrypted0) == 0)) || !(\old(__ste_email_isSigned0) == 0)) || !(queue_empty == 1) - InvariantResult [Line: 450]: Loop Invariant Derived loop invariant: ((((!(bob == 1) || !(\old(msg) == 1)) || !(\old(client) == 1)) || !(\old(__ste_email_isEncrypted0) == 0)) || !(\old(__ste_email_isSigned0) == 0)) || !(queue_empty == 1) - InvariantResult [Line: 966]: Loop Invariant Derived loop invariant: (((__ste_email_isSigned0 == 0 && bob == 1) && queue_empty == 1) && __ste_email_isEncrypted0 == 0) && tmp == 1 - InvariantResult [Line: 2526]: Loop Invariant Derived loop invariant: (((__ste_email_isSigned0 == 0 && bob == 1) && queue_empty == 1) && __ste_email_isEncrypted0 == 0) && tmp == 1 - InvariantResult [Line: 1030]: Loop Invariant Derived loop invariant: (((__ste_email_isSigned0 == 0 && bob == 1) && queue_empty == 1) && __ste_email_isEncrypted0 == 0) && tmp == 1 - InvariantResult [Line: 1058]: Loop Invariant Derived loop invariant: (((__ste_email_isSigned0 == 0 && bob == 1) && queue_empty == 1) && __ste_email_isEncrypted0 == 0) && tmp == 1 - InvariantResult [Line: 2445]: Loop Invariant Derived loop invariant: 1 - InvariantResult [Line: 1005]: Loop Invariant Derived loop invariant: (((__ste_email_isSigned0 == 0 && bob == 1) && queue_empty == 1) && __ste_email_isEncrypted0 == 0) && tmp == 1 - InvariantResult [Line: 994]: Loop Invariant Derived loop invariant: (((__ste_email_isSigned0 == 0 && bob == 1) && queue_empty == 1) && __ste_email_isEncrypted0 == 0) && tmp == 1 - InvariantResult [Line: 2325]: Loop Invariant Derived loop invariant: ((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((__ste_Client_Keyring1_User2 == 0 && __GUIDSL_NON_TERMINAL_main == 0) && __ste_email_isEncrypted1 == 0) && __SELECTED_FEATURE_Sign == 0) && __ste_client_outbuffer3 == 0) && 1 <= \result) && 1 <= \old(bob___0)) && __ste_Client_counter == 0) && rjh == 0) && retValue_acc <= 2147483647) && \old(bob___0) <= 1) && __ste_client_autoResponse1 == 0) && __ste_Client_AddressBook2_Alias0 == 0) && 1 <= \old(bob___0)) && 0 == __ste_email_subject0) && __ste_Client_AddressBook2_Alias1 == 0) && __ste_Client_Keyring2_PublicKey2 == 0) && \old(bob___0) <= 1) && __ste_client_name2 == 0) && __ste_email_body1 == 0) && __SELECTED_FEATURE_Encrypt == 0) && __ste_Client_AddressBook1_Address2 == 0) && 1 <= bob___0) && __ste_ClientAddressBook_size1 == 0) && __ste_Email_counter == 0) && __ste_email_body0 == 0) && __ste_email_isSignatureVerified0 == 0) && __ste_Client_Keyring0_User2 == 0) && __ste_ClientAddressBook_size0 == 0) && __ste_Client_Keyring0_User1 == 0) && __ste_Client_AddressBook1_Alias1 == 0) && __ste_email_to1 == 0) && __ste_client_name1 == 0) && head == 0) && __ste_Client_Keyring0_PublicKey2 == 0) && __ste_Client_Keyring1_PublicKey0 == 0) && __ste_email_to0 == 0) && __ste_email_signKey0 == 0) && __SELECTED_FEATURE_Decrypt == 0) && __SELECTED_FEATURE_Keys == 0) && #NULL <= 0) && 0 <= __ste_Client_Keyring1_User0) && 0 <= __SELECTED_FEATURE_AddressBook) && __ste_Client_Keyring0_PublicKey1 == 0) && 1 <= retValue_acc) && 0 <= __ste_email_from1) && __SELECTED_FEATURE_Forward == 0) && __ste_Client_Keyring0_User0 == 0) && __ste_email_isSigned0 == 0) && __ste_Client_Keyring2_PublicKey1 == 0) && __ste_email_isSigned1 == 0) && 0 <= __ste_email_id1) && __ste_Client_AddressBook0_Address1 <= 0) && __ste_email_body0 == 0) && __ste_Client_AddressBook0_Alias0 == 0) && 0 <= 2147483648 + retValue_acc) && 0 <= __ste_Client_AddressBook2_Address1) && 0 <= __ste_client_name0) && __ste_Client_Keyring0_PublicKey0 <= 0) && __ste_client_name1 <= 0) && __ste_email_id0 == 0) && __ste_client_autoResponse0 <= 0) && __SELECTED_FEATURE_AddressBook <= 0) && __ste_email_from0 == 0) && __ste_Client_Keyring1_PublicKey2 <= 0) && bob___0 <= 1) && 0 <= __ste_Client_Keyring0_PublicKey0) && __ste_client_forwardReceiver3 <= 0) && __ste_Client_AddressBook2_Address2 == 0) && 0 <= __ste_Client_Keyring1_PublicKey2) && \result <= 1) && __ste_Client_AddressBook0_Address0 <= 0) && 0 <= __ste_email_signKey1) && __ste_email_signKey1 <= 0) && 0 <= __ste_client_forwardReceiver3) && __ste_email_subject0 <= 0) && bob == 1) && 0 <= __ste_client_autoResponse0) && 1 <= bob___0) && 0 <= __ste_Client_AddressBook0_Alias2) && __ste_client_outbuffer0 == 0) && __SELECTED_FEATURE_Verify <= 0) && __ste_ClientKeyring_size1 <= 0) && 0 <= head) && queue_empty == 1) && __SELECTED_FEATURE_Base == 0) && __ste_Client_AddressBook1_Alias2 <= 0) && 0 <= __ste_Client_AddressBook0_Address2) && __ste_client_forwardReceiver0 == 0) && __ste_Client_Keyring2_User0 == 0) && 0 <= __ste_email_subject0) && 0 <= __ste_Client_AddressBook1_Alias0) && __ste_Client_AddressBook2_Address0 == 0) && __ste_email_isSignatureVerified1 == 0) && __ste_Client_Keyring1_PublicKey1 == 0) && 0 <= queued_client) && __ste_client_privateKey0 <= 123) && __ste_Client_AddressBook1_Alias0 <= 0) && __ste_Client_Keyring2_PublicKey0 == 0) && __ste_Client_AddressBook1_Address0 == 0) && 0 <= __ste_ClientKeyring_size1) && 0 <= __ste_client_forwardReceiver2) && __ste_client_name2 == 0) && 0 <= __ste_Client_AddressBook0_Address1) && __ste_email_encryptionKey0 <= 0) && __ste_client_idCounter0 <= 1) && __ste_email_subject1 == 0) && __ste_ClientKeyring_size0 <= 0) && __ste_email_id1 <= 0) && 0 <= __ste_Client_AddressBook0_Address0) && __ste_Client_Keyring1_User0 <= 0) && __ste_Client_AddressBook0_Alias2 <= 0) && __ste_Client_AddressBook0_Address2 <= 0) && __ste_Client_Keyring2_User2 == 0) && bob___0 <= 1) && __ste_email_from1 <= 0) && head <= 0) && __ste_client_forwardReceiver1 <= 0) && __ste_Client_Keyring1_User1 == 0) && __ste_Client_AddressBook2_Alias2 == 0) && __ste_Client_Keyring2_User1 <= 0) && 0 <= __SELECTED_FEATURE_Verify) && 0 <= __ste_Client_AddressBook1_Alias2) && 0 <= __ste_client_autoResponse2) && __ste_email_subject1 == 0) && __ste_email_isEncrypted0 == 0) && 0 <= __ste_Client_Keyring2_User1) && queued_message == 0) && __ste_Client_AddressBook1_Address1 == 0) && __ste_client_name0 <= 0) && 1 <= __ste_client_idCounter0) && __ste_client_outbuffer1 == 0) && __ste_Client_AddressBook0_Alias1 == 0) && 0 <= __ste_ClientKeyring_size0) && retValue_acc <= 1) && __GUIDSL_ROOT_PRODUCTION == 0) && 0 <= #NULL) && 123 <= __ste_client_privateKey0) && chuck == 0) && 0 <= __ste_client_forwardReceiver1) && __ste_client_name0 == 0) && __ste_Client_AddressBook2_Address1 <= 0) && __ste_client_outbuffer2 == 0) && __ste_client_forwardReceiver2 <= 0) && 0 <= unknown-#StackHeapBarrier-unknown) && __ste_ClientAddressBook_size2 == 0) && __SELECTED_FEATURE_AutoResponder == 0) && __ste_client_autoResponse2 <= 0) && __ste_email_encryptionKey1 == 0) && __ste_email_body1 == 0) && __ste_ClientKeyring_size2 == 0) && 0 <= __ste_client_name1) && 0 <= __ste_email_encryptionKey0) && #NULL == 0) && tmp == 1) && queued_client <= 0 - InvariantResult [Line: 2346]: Loop Invariant Derived loop invariant: (((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((__SELECTED_FEATURE_Sign == 0 && __ste_client_outbuffer3 == 0) && 1 <= \result) && \old(rjh___0) <= 2) && 1 <= \old(bob___0)) && __ste_Client_counter == 0) && retValue_acc <= 2147483647) && \old(bob___0) <= 1) && 2 <= rjh___0) && __ste_Client_AddressBook2_Alias0 == 0) && 1 <= \old(bob___0)) && 0 == __ste_email_subject0) && __ste_client_idCounter1 <= 2) && \old(bob___0) <= 1) && 0 <= __ste_ClientAddressBook_size0) && 2 <= rjh) && 0 <= __SELECTED_FEATURE_Encrypt) && 0 <= __ste_client_autoResponse1) && 0 <= __ste_client_outbuffer0) && __ste_Client_Keyring2_PublicKey2 <= 0) && __cil_tmp1 <= 19) && 0 <= __ste_client_outbuffer1) && 0 <= __ste_ClientAddressBook_size1) && queued_message <= 0) && __ste_email_isSignatureVerified0 <= 0) && __ste_client_name0 <= 0) && 0 <= __ste_Client_AddressBook0_Alias1) && __ste_Client_AddressBook1_Address2 == 0) && 1 <= bob___0) && chuck <= 0) && 0 <= __SELECTED_FEATURE_AutoResponder) && __ste_email_body0 == 0) && __SELECTED_FEATURE_Keys <= 0) && 0 <= __ste_email_isSigned1) && __SELECTED_FEATURE_Decrypt <= 0) && __ste_Client_Keyring0_User2 == 0) && __ste_Client_Keyring1_PublicKey0 <= 0) && __ste_Client_Keyring0_User1 == 0) && __ste_Client_AddressBook1_Alias1 == 0) && __ste_client_name1 == 0) && __GUIDSL_NON_TERMINAL_main <= 0) && __ste_Client_AddressBook2_Address0 <= 0) && __SELECTED_FEATURE_AutoResponder <= 0) && __ste_email_id0 <= 0) && 0 <= __ste_client_name2) && head == 0) && __GUIDSL_ROOT_PRODUCTION <= 0) && __ste_Client_AddressBook2_Alias1 <= 0) && 0 <= __GUIDSL_ROOT_PRODUCTION) && __ste_Client_Keyring0_PublicKey2 == 0) && __ste_Email_counter <= 0) && __ste_Client_Keyring2_User2 <= 0) && __ste_email_body1 <= 0) && 0 <= __SELECTED_FEATURE_Decrypt) && 0 <= __cil_tmp1) && 0 <= __ste_email_to0) && __cil_tmp1 <= 0) && 0 <= __ste_email_to1) && __ste_email_signKey0 == 0) && 0 <= __ste_Client_AddressBook2_Alias1) && 0 <= __ste_Client_Keyring2_User2) && 0 <= __ste_Client_Keyring1_User2) && 0 <= __ste_email_from0) && 0 <= __ste_email_isEncrypted1) && #NULL <= 0) && 0 <= __ste_Client_Keyring1_User0) && 0 <= __SELECTED_FEATURE_AddressBook) && __ste_Client_Keyring0_PublicKey1 == 0) && 1 <= retValue_acc) && 0 <= __ste_email_from1) && __SELECTED_FEATURE_Forward == 0) && rjh___0 <= 2) && __ste_Client_Keyring0_User0 == 0) && __ste_email_isSigned0 == 0) && __ste_Client_Keyring2_PublicKey1 == 0) && 0 <= __ste_email_id1) && __ste_Client_AddressBook0_Address1 <= 0) && __ste_email_body0 == 0) && __ste_Client_AddressBook0_Alias0 == 0) && 0 <= 2147483648 + retValue_acc) && 0 <= __ste_Client_AddressBook2_Address1) && 0 <= __ste_client_name0) && __ste_Client_Keyring0_PublicKey0 <= 0) && __ste_client_name1 <= 0) && __ste_client_autoResponse0 <= 0) && \old(rjh___0) <= 2) && __ste_email_to1 <= 0) && __SELECTED_FEATURE_AddressBook <= 0) && __ste_Client_Keyring1_PublicKey2 <= 0) && bob___0 <= 1) && 0 <= __ste_Client_Keyring0_PublicKey0) && __ste_client_forwardReceiver3 <= 0) && __ste_Client_AddressBook2_Address2 == 0) && __ste_ClientAddressBook_size0 <= 0) && 0 <= __ste_Client_Keyring1_PublicKey2) && \result <= 1) && __ste_Client_AddressBook0_Address0 <= 0) && 0 <= __ste_client_name0) && 0 <= __ste_email_signKey1) && 0 <= __ste_email_body1) && __ste_email_signKey1 <= 0) && 0 <= __ste_client_forwardReceiver3) && __ste_client_name2 <= 0) && __ste_email_isSigned1 <= 0) && __SELECTED_FEATURE_Encrypt <= 0) && 0 <= __ste_Email_counter) && __ste_email_subject0 <= 0) && bob == 1) && 0 <= __ste_client_autoResponse0) && 1 <= bob___0) && 0 <= __ste_Client_AddressBook0_Alias2) && 0 <= queued_message) && 2 <= __ste_client_idCounter1) && __SELECTED_FEATURE_Verify <= 0) && __ste_ClientKeyring_size1 <= 0) && __ste_Client_Keyring1_User2 <= 0) && 2 <= rjh___0) && 0 <= chuck) && 0 <= head) && queue_empty == 1) && rjh___0 <= 2) && __SELECTED_FEATURE_Base == 0) && __ste_Client_AddressBook1_Alias2 <= 0) && 0 <= __ste_Client_AddressBook0_Address2) && __ste_client_privateKey1 == 456) && __ste_client_forwardReceiver0 == 0) && __ste_Client_Keyring2_User0 == 0) && 0 <= __ste_email_subject0) && __ste_email_from0 <= 0) && 0 <= __ste_Client_AddressBook1_Alias0) && __ste_email_isSignatureVerified1 == 0) && __ste_Client_Keyring1_PublicKey1 == 0) && 0 <= queued_client) && 0 <= __SELECTED_FEATURE_Keys) && __ste_Client_AddressBook1_Alias0 <= 0) && 0 <= __ste_Client_Keyring1_PublicKey0) && __ste_Client_Keyring2_PublicKey0 == 0) && 0 <= __ste_email_isSignatureVerified0) && __ste_Client_AddressBook1_Address0 == 0) && 0 <= __ste_ClientKeyring_size1) && 0 <= __ste_client_forwardReceiver2) && __ste_client_name2 == 0) && 0 <= __ste_Client_AddressBook0_Address1) && 2 <= \old(rjh___0)) && __ste_email_encryptionKey0 <= 0) && __ste_email_subject1 == 0) && __ste_ClientKeyring_size0 <= 0) && __ste_email_id1 <= 0) && 0 <= __ste_Client_AddressBook0_Address0) && __ste_Client_Keyring1_User0 <= 0) && __ste_Client_AddressBook0_Alias2 <= 0) && __ste_Client_AddressBook0_Address2 <= 0) && __ste_client_autoResponse1 <= 0) && bob___0 <= 1) && __ste_client_outbuffer0 <= 0) && __ste_email_from1 <= 0) && head <= 0) && __ste_client_forwardReceiver1 <= 0) && 2 <= \old(rjh___0)) && __ste_Client_Keyring1_User1 == 0) && __ste_Client_AddressBook2_Alias2 == 0) && __ste_email_to0 <= 0) && __ste_Client_Keyring2_User1 <= 0) && 0 <= __SELECTED_FEATURE_Verify) && 0 <= __ste_Client_AddressBook1_Alias2) && 0 <= __ste_client_autoResponse2) && __ste_email_subject1 == 0) && __ste_email_isEncrypted0 == 0) && 0 <= __ste_Client_AddressBook2_Address0) && 0 <= __ste_Client_Keyring2_User1) && __ste_Client_AddressBook1_Address1 == 0) && __ste_client_name0 <= 0) && 0 <= __ste_ClientKeyring_size0) && 19 <= __cil_tmp1) && __ste_email_isEncrypted1 <= 0) && retValue_acc <= 1) && 0 <= #NULL) && rjh <= 2) && __ste_Client_AddressBook0_Alias1 <= 0) && 0 <= __ste_client_forwardReceiver1) && 0 <= __ste_Client_Keyring2_PublicKey2) && __ste_Client_AddressBook2_Address1 <= 0) && __ste_client_outbuffer2 == 0) && 0 <= __GUIDSL_NON_TERMINAL_main) && __ste_client_forwardReceiver2 <= 0) && 0 <= unknown-#StackHeapBarrier-unknown) && __ste_ClientAddressBook_size2 == 0) && __ste_client_autoResponse2 <= 0) && __ste_email_encryptionKey1 == 0) && __ste_email_body1 == 0) && __ste_client_outbuffer1 <= 0) && __ste_ClientKeyring_size2 == 0) && __ste_ClientAddressBook_size1 <= 0) && 0 <= __ste_client_name1) && 0 <= __ste_email_id0) && 0 <= __ste_email_encryptionKey0) && #NULL == 0) && tmp == 1) && queued_client <= 0 - InvariantResult [Line: 2315]: Loop Invariant Derived loop invariant: ((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((queued_client == 0 && __ste_Client_Keyring1_User2 == 0) && __GUIDSL_NON_TERMINAL_main == 0) && __ste_email_isEncrypted1 == 0) && __ste_email_subject0 == 0) && __SELECTED_FEATURE_Sign == 0) && 0 == __ste_Client_AddressBook0_Address2) && __ste_client_outbuffer3 == 0) && 1 <= \result) && 1 <= \old(bob___0)) && __ste_Client_counter == 0) && rjh == 0) && __ste_Client_Keyring1_PublicKey2 == 0) && retValue_acc <= 2147483647) && \old(bob___0) <= 1) && __ste_client_autoResponse1 == 0) && __ste_Client_AddressBook2_Alias0 == 0) && 1 <= \old(bob___0)) && 0 == __ste_email_subject0) && __ste_Client_AddressBook2_Alias1 == 0) && __ste_Client_Keyring2_PublicKey2 == 0) && __ste_client_forwardReceiver3 == 0) && \old(bob___0) <= 1) && __ste_client_name2 == 0) && __ste_client_name1 == 0) && __SELECTED_FEATURE_Verify == 0) && __ste_Client_Keyring1_User0 == 0) && __ste_email_body1 == 0) && __SELECTED_FEATURE_Encrypt == 0) && __ste_Client_AddressBook1_Address2 == 0) && 1 <= bob___0) && __ste_ClientAddressBook_size1 == 0) && __ste_Client_Keyring0_PublicKey0 == 0) && __ste_Email_counter == 0) && __ste_ClientKeyring_size1 == 0) && __ste_email_body0 == 0) && __ste_email_isSignatureVerified0 == 0) && __ste_Client_Keyring0_User2 == 0) && __ste_ClientAddressBook_size0 == 0) && __ste_Client_Keyring0_User1 == 0) && __ste_Client_AddressBook1_Alias1 == 0) && __ste_email_to1 == 0) && __ste_client_name1 == 0) && __ste_client_privateKey1 == 0) && head == 0) && __ste_client_name0 == 0) && __ste_Client_Keyring0_PublicKey2 == 0) && __ste_Client_Keyring1_PublicKey0 == 0) && __ste_email_to0 == 0) && __ste_email_signKey0 == 0) && __SELECTED_FEATURE_Decrypt == 0) && __ste_email_encryptionKey0 == 0) && __SELECTED_FEATURE_Keys == 0) && __SELECTED_FEATURE_AddressBook == 0) && __ste_client_forwardReceiver2 == 0) && __ste_Client_Keyring0_PublicKey1 == 0) && __SELECTED_FEATURE_Forward == 0) && __ste_Client_Keyring0_User0 == 0) && __ste_email_isSigned0 == 0) && __ste_Client_Keyring2_PublicKey1 == 0) && __ste_email_isSigned1 == 0) && __ste_email_body0 == 0) && __ste_Client_AddressBook0_Alias0 == 0) && 0 <= 2147483648 + retValue_acc) && __ste_email_id0 == 0) && __ste_client_privateKey0 == 0) && __ste_email_from0 == 0) && __ste_Client_Keyring2_User1 == 0) && bob___0 <= 1) && __ste_Client_AddressBook2_Address2 == 0) && \result <= 1) && __ste_Client_AddressBook2_Address1 == 0) && bob == 1) && __ste_client_forwardReceiver1 == 0) && 1 <= bob___0) && __ste_Client_AddressBook1_Alias2 == 0) && __ste_client_outbuffer0 == 0) && queue_empty == 1) && __SELECTED_FEATURE_Base == 0) && __ste_client_forwardReceiver0 == 0) && __ste_Client_Keyring2_User0 == 0) && 0 == __ste_Client_AddressBook0_Address1) && __ste_Client_AddressBook2_Address0 == 0) && __ste_email_isSignatureVerified1 == 0) && __ste_Client_Keyring1_PublicKey1 == 0) && __ste_Client_Keyring2_PublicKey0 == 0) && __ste_Client_AddressBook1_Address0 == 0) && __ste_client_name2 == 0) && __ste_email_from1 == 0) && __ste_client_idCounter0 <= 1) && __ste_email_subject1 == 0) && __ste_Client_AddressBook1_Alias0 == 0) && __ste_Client_Keyring2_User2 == 0) && bob___0 <= 1) && head == 0) && __ste_client_privateKey2 == 0) && __ste_Client_Keyring1_User1 == 0) && #NULL == 0) && __ste_Client_AddressBook2_Alias2 == 0) && retValue_acc == 1) && __ste_email_subject1 == 0) && __ste_Client_AddressBook0_Alias2 == 0) && __ste_ClientKeyring_size0 == 0) && __ste_email_isEncrypted0 == 0) && queued_message == 0) && __ste_Client_AddressBook1_Address1 == 0) && 0 == __ste_Client_AddressBook0_Address0) && 1 <= __ste_client_idCounter0) && __ste_client_outbuffer1 == 0) && __ste_Client_AddressBook0_Alias1 == 0) && __GUIDSL_ROOT_PRODUCTION == 0) && chuck == 0) && __ste_client_name0 == 0) && __ste_email_id1 == 0) && __ste_client_outbuffer2 == 0) && 0 <= unknown-#StackHeapBarrier-unknown) && __ste_ClientAddressBook_size2 == 0) && __SELECTED_FEATURE_AutoResponder == 0) && __ste_email_encryptionKey1 == 0) && __ste_client_autoResponse0 == 0) && __ste_email_body1 == 0) && __ste_ClientKeyring_size2 == 0) && __ste_client_autoResponse2 == 0) && #NULL == 0) && tmp == 1) && __ste_email_signKey1 == 0 - InvariantResult [Line: 2478]: Loop Invariant Derived loop invariant: (((__ste_email_isSigned0 == 0 && bob == 1) && queue_empty == 1) && __ste_email_isEncrypted0 == 0) && tmp == 1 - InvariantResult [Line: -1]: Loop Invariant Derived loop invariant: 1 - InvariantResult [Line: 2378]: Loop Invariant Derived loop invariant: 1 - InvariantResult [Line: 397]: Loop Invariant Derived loop invariant: (((((!(bob == 1) || !(\old(msg) == 1)) || (((((((msg == 1 && (__ste_email_isSigned0 == 0 || !(__ste_client_privateKey0 == 0))) && msg == 1) && client == 1) && msg == 1) && client == 1) && client == 1) && (!(__ste_client_privateKey0 == 0) || tmp___0 == 0))) || !(\old(client) == 1)) || !(\old(__ste_email_isEncrypted0) == 0)) || !(\old(__ste_email_isSigned0) == 0)) || !(queue_empty == 1) - InvariantResult [Line: 2336]: Loop Invariant Derived loop invariant: (((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((queued_client == 0 && __ste_Client_Keyring1_User2 == 0) && __GUIDSL_NON_TERMINAL_main == 0) && __ste_email_isEncrypted1 == 0) && __ste_email_subject0 == 0) && __SELECTED_FEATURE_Sign == 0) && 0 == __ste_Client_AddressBook0_Address2) && __ste_client_outbuffer3 == 0) && 1 <= \result) && \old(rjh___0) <= 2) && 1 <= \old(bob___0)) && 19 == __cil_tmp1) && __ste_Client_counter == 0) && __ste_Client_Keyring1_PublicKey2 == 0) && retValue_acc <= 2147483647) && \old(bob___0) <= 1) && __ste_client_autoResponse1 == 0) && 2 <= rjh___0) && __ste_Client_AddressBook2_Alias0 == 0) && __cil_tmp1 == 0) && 1 <= \old(bob___0)) && 0 == __ste_email_subject0) && __ste_client_idCounter1 <= 2) && __ste_Client_AddressBook2_Alias1 == 0) && __ste_Client_Keyring2_PublicKey2 == 0) && __ste_client_forwardReceiver3 == 0) && \old(bob___0) <= 1) && __ste_client_name2 == 0) && __ste_client_name1 == 0) && __SELECTED_FEATURE_Verify == 0) && __ste_Client_Keyring1_User0 == 0) && __ste_email_body1 == 0) && __SELECTED_FEATURE_Encrypt == 0) && __ste_Client_AddressBook1_Address2 == 0) && 1 <= bob___0) && __ste_ClientAddressBook_size1 == 0) && __ste_Client_Keyring0_PublicKey0 == 0) && __ste_Email_counter == 0) && __ste_ClientKeyring_size1 == 0) && __ste_email_body0 == 0) && __ste_email_isSignatureVerified0 == 0) && __ste_Client_Keyring0_User2 == 0) && __ste_ClientAddressBook_size0 == 0) && __ste_Client_Keyring0_User1 == 0) && __ste_Client_AddressBook1_Alias1 == 0) && __ste_email_to1 == 0) && __ste_client_name1 == 0) && head == 0) && __ste_client_name0 == 0) && __ste_Client_Keyring0_PublicKey2 == 0) && __ste_Client_Keyring1_PublicKey0 == 0) && __ste_email_to0 == 0) && __ste_email_signKey0 == 0) && __SELECTED_FEATURE_Decrypt == 0) && __ste_email_encryptionKey0 == 0) && __SELECTED_FEATURE_Keys == 0) && __SELECTED_FEATURE_AddressBook == 0) && __ste_client_forwardReceiver2 == 0) && __ste_Client_Keyring0_PublicKey1 == 0) && __SELECTED_FEATURE_Forward == 0) && rjh___0 <= 2) && __ste_Client_Keyring0_User0 == 0) && __ste_email_isSigned0 == 0) && __ste_Client_Keyring2_PublicKey1 == 0) && __ste_email_isSigned1 == 0) && __ste_email_body0 == 0) && __ste_Client_AddressBook0_Alias0 == 0) && 0 <= 2147483648 + retValue_acc) && __ste_email_id0 == 0) && \old(rjh___0) <= 2) && __ste_email_from0 == 0) && __ste_Client_Keyring2_User1 == 0) && bob___0 <= 1) && __ste_Client_AddressBook2_Address2 == 0) && \result <= 1) && __ste_Client_AddressBook2_Address1 == 0) && bob == 1) && __ste_client_forwardReceiver1 == 0) && 1 <= bob___0) && __ste_Client_AddressBook1_Alias2 == 0) && 2 <= __ste_client_idCounter1) && __ste_client_outbuffer0 == 0) && 2 <= rjh___0) && queue_empty == 1) && rjh___0 <= 2) && __SELECTED_FEATURE_Base == 0) && __ste_client_forwardReceiver0 == 0) && __ste_Client_Keyring2_User0 == 0) && rjh == 2) && 0 == __ste_Client_AddressBook0_Address1) && __ste_Client_AddressBook2_Address0 == 0) && __ste_email_isSignatureVerified1 == 0) && __ste_Client_Keyring1_PublicKey1 == 0) && __ste_client_privateKey0 <= 123) && __ste_Client_Keyring2_PublicKey0 == 0) && __ste_Client_AddressBook1_Address0 == 0) && __ste_client_name2 == 0) && __ste_email_from1 == 0) && 2 <= \old(rjh___0)) && __ste_email_subject1 == 0) && __ste_Client_AddressBook1_Alias0 == 0) && __ste_Client_Keyring2_User2 == 0) && bob___0 <= 1) && head == 0) && 2 <= \old(rjh___0)) && __ste_Client_Keyring1_User1 == 0) && #NULL == 0) && __ste_Client_AddressBook2_Alias2 == 0) && retValue_acc == 1) && __ste_email_subject1 == 0) && __ste_Client_AddressBook0_Alias2 == 0) && __ste_ClientKeyring_size0 == 0) && __ste_email_isEncrypted0 == 0) && queued_message == 0) && __ste_Client_AddressBook1_Address1 == 0) && 0 == __ste_Client_AddressBook0_Address0) && __ste_client_outbuffer1 == 0) && __ste_Client_AddressBook0_Alias1 == 0) && __GUIDSL_ROOT_PRODUCTION == 0) && 123 <= __ste_client_privateKey0) && chuck == 0) && __ste_client_name0 == 0) && __ste_email_id1 == 0) && __ste_client_outbuffer2 == 0) && 0 <= unknown-#StackHeapBarrier-unknown) && __ste_ClientAddressBook_size2 == 0) && __SELECTED_FEATURE_AutoResponder == 0) && __ste_email_encryptionKey1 == 0) && __ste_client_autoResponse0 == 0) && __ste_email_body1 == 0) && __ste_ClientKeyring_size2 == 0) && __ste_client_autoResponse2 == 0) && #NULL == 0) && tmp == 1) && __ste_email_signKey1 == 0 RESULT: Ultimate proved your program to be correct! [2022-12-14 09:04:34,910 INFO L552 MonitoredProcess]: [MP /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_1f82ca65-6edb-49dc-97e2-5ef2786422ba/bin/utaipan-gh47qXpMRh/z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in -t:2000 (1)] Ended with exit code 0 Received shutdown request... --- End real Ultimate output --- Execution finished normally Writing output log to file Ultimate.log Result: TRUE