25.65/8.34 YES 25.65/8.35 proof of /export/starexec/sandbox/benchmark/theBenchmark.c 25.65/8.35 # AProVE Commit ID: 48fb2092695e11cc9f56e44b17a92a5f88ffb256 marcel 20180622 unpublished dirty 25.65/8.35 25.65/8.35 25.65/8.35 Termination of the given C Problem could be proven: 25.65/8.35 25.65/8.35 (0) C Problem 25.65/8.35 (1) CToLLVMProof [EQUIVALENT, 175 ms] 25.65/8.35 (2) LLVM problem 25.65/8.35 (3) LLVMToTerminationGraphProof [EQUIVALENT, 4460 ms] 25.65/8.35 (4) LLVM Symbolic Execution Graph 25.65/8.35 (5) SymbolicExecutionGraphToSCCProof [SOUND, 0 ms] 25.65/8.35 (6) LLVM Symbolic Execution SCC 25.65/8.35 (7) SCC2IRS [SOUND, 83 ms] 25.65/8.35 (8) IntTRS 25.65/8.35 (9) IntTRSCompressionProof [EQUIVALENT, 0 ms] 25.65/8.35 (10) IntTRS 25.65/8.35 (11) RankingReductionPairProof [EQUIVALENT, 24 ms] 25.65/8.35 (12) YES 25.65/8.35 25.65/8.35 25.65/8.35 ---------------------------------------- 25.65/8.35 25.65/8.35 (0) 25.65/8.35 Obligation: 25.65/8.35 c file /export/starexec/sandbox/benchmark/theBenchmark.c 25.65/8.35 ---------------------------------------- 25.65/8.35 25.65/8.35 (1) CToLLVMProof (EQUIVALENT) 25.65/8.35 Compiled c-file /export/starexec/sandbox/benchmark/theBenchmark.c to LLVM. 25.65/8.35 ---------------------------------------- 25.65/8.35 25.65/8.35 (2) 25.65/8.35 Obligation: 25.65/8.35 LLVM Problem 25.65/8.35 25.65/8.35 Aliases: 25.65/8.35 25.65/8.35 Data layout: 25.65/8.35 25.65/8.35 "e-p:64:64:64-i1:8:8-i8:8:8-i16:16:16-i32:32:32-i64:64:64-f32:32:32-f64:64:64-v64:64:64-v128:128:128-a0:0:64-s0:64:64-f80:128:128-n8:16:32:64-S128" 25.65/8.35 25.65/8.35 Machine: 25.65/8.35 25.65/8.35 "x86_64-pc-linux-gnu" 25.65/8.35 25.65/8.35 Type definitions: 25.65/8.35 25.65/8.35 Global variables: 25.65/8.35 25.65/8.35 Function declarations and definitions: 25.65/8.35 25.65/8.35 *BasicFunctionTypename: "__VERIFIER_nondet_int" returnParam: i32 parameters: () variableLength: false visibilityType: DEFAULT callingConvention: ccc 25.65/8.35 *BasicFunctionTypename: "strlen_rec" linkageType: EXTERNALLY_VISIBLE returnParam: i32 parameters: (p *i8) variableLength: false visibilityType: DEFAULT callingConvention: ccc 25.65/8.35 0: 25.65/8.35 %1 = alloca i32, align 4 25.65/8.35 %2 = alloca *i8, align 8 25.65/8.35 store %p, %2 25.65/8.35 %3 = load %2 25.65/8.35 %4 = load %3 25.65/8.35 %5 = sext i8 %4 to i32 25.65/8.35 %6 = icmp eq %5 0 25.65/8.35 br %6, %7, %8 25.65/8.35 7: 25.65/8.35 store 0, %1 25.65/8.35 br %13 25.65/8.35 8: 25.65/8.35 %9 = load %2 25.65/8.35 %10 = getelementptr %9, 1 25.65/8.35 %11 = call i32 @strlen_rec(*i8 %10) 25.65/8.35 %12 = add 1 %11 25.65/8.35 store %12, %1 25.65/8.35 br %13 25.65/8.35 13: 25.65/8.35 %14 = load %1 25.65/8.35 ret %14 25.65/8.35 25.65/8.35 *BasicFunctionTypename: "main" linkageType: EXTERNALLY_VISIBLE returnParam: i32 parameters: () variableLength: false visibilityType: DEFAULT callingConvention: ccc 25.65/8.35 0: 25.65/8.35 %1 = alloca i32, align 4 25.65/8.35 %length1 = alloca i32, align 4 25.65/8.35 %nondetString1 = alloca *i8, align 8 25.65/8.35 store 0, %1 25.65/8.35 %2 = call i32 @__VERIFIER_nondet_int() 25.65/8.35 store %2, %length1 25.65/8.35 %3 = load %length1 25.65/8.35 %4 = icmp slt %3 1 25.65/8.35 br %4, %5, %6 25.65/8.35 5: 25.65/8.35 store 1, %length1 25.65/8.35 br %6 25.65/8.35 6: 25.65/8.35 %7 = load %length1 25.65/8.35 %8 = sext i32 %7 to i64 25.65/8.35 %9 = mul %8 1 25.65/8.35 %10 = alloca i8, numElementsLit: %9 25.65/8.35 store %10, %nondetString1 25.65/8.35 %11 = load %length1 25.65/8.35 %12 = sub %11 1 25.65/8.35 %13 = sext i32 %12 to i64 25.65/8.35 %14 = load %nondetString1 25.65/8.35 %15 = getelementptr %14, %13 25.65/8.35 store 0, %15 25.65/8.35 %16 = load %nondetString1 25.65/8.35 %17 = call i32 @strlen_rec(*i8 %16) 25.65/8.35 %18 = load %1 25.65/8.35 ret %18 25.65/8.35 25.65/8.35 25.65/8.35 Analyze Termination of all function calls matching the pattern: 25.65/8.35 main() 25.65/8.35 ---------------------------------------- 25.65/8.35 25.65/8.35 (3) LLVMToTerminationGraphProof (EQUIVALENT) 25.65/8.35 Constructed symbolic execution graph for LLVM program and proved memory safety. 25.65/8.35 ---------------------------------------- 25.65/8.35 25.65/8.35 (4) 25.65/8.35 Obligation: 25.65/8.35 SE Graph 25.65/8.35 ---------------------------------------- 25.65/8.35 25.65/8.35 (5) SymbolicExecutionGraphToSCCProof (SOUND) 25.65/8.35 Splitted symbolic execution graph to 1 SCC. 25.65/8.35 ---------------------------------------- 25.65/8.35 25.65/8.35 (6) 25.65/8.35 Obligation: 25.65/8.35 SCC 25.65/8.35 ---------------------------------------- 25.65/8.35 25.65/8.35 (7) SCC2IRS (SOUND) 25.65/8.35 Transformed LLVM symbolic execution graph SCC into a rewrite problem. Log: 25.65/8.35 Generated rules. Obtained 14 rulesP rules: 25.65/8.35 f_235(v110, v121, v111, v112, v113, v114, v115, v116, v117, v118, v122, 0, v120, 3, 7, 1, 4, 8) -> f_236(v110, v121, v123, v111, v112, v113, v114, v115, v116, v117, v118, v122, v124, 0, v120, 3, 7, 1, 4, 8) :|: 1 <= v123 && v124 = 7 + v123 && 8 <= v124 25.65/8.35 f_236(v110, v121, v123, v111, v112, v113, v114, v115, v116, v117, v118, v122, v124, 0, v120, 3, 7, 1, 4, 8) -> f_237(v110, v121, v123, v111, v112, v113, v114, v115, v116, v117, v118, v122, v124, 0, v120, 3, 7, 1, 4, 8) :|: TRUE 25.65/8.35 f_237(v110, v121, v123, v111, v112, v113, v114, v115, v116, v117, v118, v122, v124, 0, v120, 3, 7, 1, 4, 8) -> f_238(v110, v121, v123, v111, v112, v113, v114, v115, v116, v117, v118, v122, v124, 0, v120, 3, 7, 1, 4, 8) :|: 0 = 0 25.65/8.35 f_238(v110, v121, v123, v111, v112, v113, v114, v115, v116, v117, v118, v122, v124, 0, v120, 3, 7, 1, 4, 8) -> f_239(v110, v121, v123, v126, v111, v112, v113, v114, v115, v116, v117, v118, v122, v124, 0, v120, 3, 7, 1, 4, 8) :|: TRUE 25.65/8.35 f_239(v110, v121, v123, v126, v111, v112, v113, v114, v115, v116, v117, v118, v122, v124, 0, v120, 3, 7, 1, 4, 8) -> f_240(v110, v121, v123, v126, v111, v112, v113, v114, v115, v116, v117, v118, v122, v124, 0, v120, 3, 7, 1, 4, 8) :|: 0 = 0 25.65/8.35 f_240(v110, v121, v123, v126, v111, v112, v113, v114, v115, v116, v117, v118, v122, v124, 0, v120, 3, 7, 1, 4, 8) -> f_242(v110, v121, v123, v126, v111, v112, v113, v114, v115, v116, v117, v118, v122, v124, 0, v120, 3, 7, 1, 2, 4, 8) :|: v126 != 0 && v110 < v112 && 2 <= v112 25.65/8.35 f_242(v110, v121, v123, v126, v111, v112, v113, v114, v115, v116, v117, v118, v122, v124, 0, v120, 3, 7, 1, 2, 4, 8) -> f_244(v110, v121, v123, v126, 0, v111, v112, v113, v114, v115, v116, v117, v118, v122, v124, v120, 3, 7, 1, 2, 4, 8) :|: 0 = 0 25.65/8.35 f_244(v110, v121, v123, v126, 0, v111, v112, v113, v114, v115, v116, v117, v118, v122, v124, v120, 3, 7, 1, 2, 4, 8) -> f_246(v110, v121, v123, v126, 0, v111, v112, v113, v114, v115, v116, v117, v118, v122, v124, v120, 3, 7, 1, 2, 4, 8) :|: TRUE 25.65/8.35 f_246(v110, v121, v123, v126, 0, v111, v112, v113, v114, v115, v116, v117, v118, v122, v124, v120, 3, 7, 1, 2, 4, 8) -> f_248(v110, v121, v123, v126, 0, v111, v112, v113, v114, v115, v116, v117, v118, v122, v124, v120, 3, 7, 1, 2, 4, 8) :|: 0 = 0 25.65/8.35 f_248(v110, v121, v123, v126, 0, v111, v112, v113, v114, v115, v116, v117, v118, v122, v124, v120, 3, 7, 1, 2, 4, 8) -> f_250(v110, v121, v123, v126, 0, v128, v111, v112, v113, v114, v115, v116, v117, v118, v122, v124, v120, 3, 7, 1, 2, 4, 8) :|: v128 = 1 + v110 && 2 <= v128 25.65/8.35 f_250(v110, v121, v123, v126, 0, v128, v111, v112, v113, v114, v115, v116, v117, v118, v122, v124, v120, 3, 7, 1, 2, 4, 8) -> f_252(v128, v111, v112, v113, v114, v115, v116, v117, v118, v121, v122, v123, v124, 0, v120, v110, v126, 3, 7, 1, 2, 4, 8) :|: 0 = 0 25.65/8.35 f_252(v128, v111, v112, v113, v114, v115, v116, v117, v118, v121, v122, v123, v124, 0, v120, v110, v126, 3, 7, 1, 2, 4, 8) -> f_255(v128, v111, v112, v113, v114, v115, v116, v117, v118, v121, v122, v123, v124, 0, v120, v110, v126, 3, 7, 1, 2, 4, 8) :|: TRUE 25.65/8.35 f_255(v128, v111, v112, v113, v114, v115, v116, v117, v118, v121, v122, v123, v124, 0, v120, v110, v126, 3, 7, 1, 2, 4, 8) -> f_232(v128, v111, v112, v113, v114, v115, v116, v117, v118, 0, v120, 3, 7, 1, 4, 8) :|: TRUE 25.65/8.35 f_232(v110, v111, v112, v113, v114, v115, v116, v117, v118, 0, v120, 3, 7, 1, 4, 8) -> f_235(v110, v121, v111, v112, v113, v114, v115, v116, v117, v118, v122, 0, v120, 3, 7, 1, 4, 8) :|: 1 <= v121 && v122 = 3 + v121 && 4 <= v122 25.65/8.35 Combined rules. Obtained 2 rulesP rules: 25.65/8.35 f_235(v110:0, v121:0, v111:0, v112:0, v113:0, v114:0, v115:0, v116:0, v117:0, v118:0, v122:0, 0, v120:0, 3, 7, 1, 4, 8) -> f_235(1 + v110:0, v121:1, v111:0, v112:0, v113:0, v114:0, v115:0, v116:0, v117:0, v118:0, 3 + v121:1, 0, v120:0, 3, 7, 1, 4, 8) :|: v123:0 > 0 && v112:0 > v110:0 && v126:0 < 0 && v112:0 > 1 && v110:0 > 0 && v121:1 > 0 25.65/8.35 f_235(v110:0, v121:0, v111:0, v112:0, v113:0, v114:0, v115:0, v116:0, v117:0, v118:0, v122:0, 0, v120:0, 3, 7, 1, 4, 8) -> f_235(1 + v110:0, v121:1, v111:0, v112:0, v113:0, v114:0, v115:0, v116:0, v117:0, v118:0, 3 + v121:1, 0, v120:0, 3, 7, 1, 4, 8) :|: v123:0 > 0 && v112:0 > v110:0 && v126:0 > 0 && v112:0 > 1 && v110:0 > 0 && v121:1 > 0 25.65/8.35 Filtered unneeded arguments: 25.65/8.35 f_235(x1, x2, x3, x4, x5, x6, x7, x8, x9, x10, x11, x12, x13, x14, x15, x16, x17, x18) -> f_235(x1, x4) 25.65/8.35 Removed division, modulo operations, cleaned up constraints. Obtained 1 rules.P rules: 25.65/8.35 f_235(v110:0, v112:0) -> f_235(1 + v110:0, v112:0) :|: v112:0 > 1 && v110:0 > 0 && v112:0 > v110:0 25.65/8.35 25.65/8.35 ---------------------------------------- 25.65/8.35 25.65/8.35 (8) 25.65/8.35 Obligation: 25.65/8.35 Rules: 25.65/8.35 f_235(v110:0, v112:0) -> f_235(1 + v110:0, v112:0) :|: v112:0 > 1 && v110:0 > 0 && v112:0 > v110:0 25.65/8.35 25.65/8.35 ---------------------------------------- 25.65/8.35 25.65/8.35 (9) IntTRSCompressionProof (EQUIVALENT) 25.65/8.35 Compressed rules. 25.65/8.35 ---------------------------------------- 25.65/8.35 25.65/8.35 (10) 25.65/8.35 Obligation: 25.65/8.35 Rules: 25.65/8.35 f_235(v110:0:0, v112:0:0) -> f_235(1 + v110:0:0, v112:0:0) :|: v112:0:0 > 1 && v110:0:0 > 0 && v112:0:0 > v110:0:0 25.65/8.35 25.65/8.35 ---------------------------------------- 25.65/8.35 25.65/8.35 (11) RankingReductionPairProof (EQUIVALENT) 25.65/8.35 Interpretation: 25.65/8.35 [ f_235 ] = f_235_2 + -1*f_235_1 25.65/8.35 25.65/8.35 The following rules are decreasing: 25.65/8.35 f_235(v110:0:0, v112:0:0) -> f_235(1 + v110:0:0, v112:0:0) :|: v112:0:0 > 1 && v110:0:0 > 0 && v112:0:0 > v110:0:0 25.65/8.35 25.65/8.35 The following rules are bounded: 25.65/8.35 f_235(v110:0:0, v112:0:0) -> f_235(1 + v110:0:0, v112:0:0) :|: v112:0:0 > 1 && v110:0:0 > 0 && v112:0:0 > v110:0:0 25.65/8.35 25.65/8.35 25.65/8.35 ---------------------------------------- 25.65/8.35 25.65/8.35 (12) 25.65/8.35 YES 25.90/8.43 EOF