8.51/3.33 YES 8.84/3.35 proof of /export/starexec/sandbox/benchmark/theBenchmark.c 8.84/3.35 # AProVE Commit ID: 48fb2092695e11cc9f56e44b17a92a5f88ffb256 marcel 20180622 unpublished dirty 8.84/3.35 8.84/3.35 8.84/3.35 Termination of the given C Problem could be proven: 8.84/3.35 8.84/3.35 (0) C Problem 8.84/3.35 (1) CToLLVMProof [EQUIVALENT, 174 ms] 8.84/3.35 (2) LLVM problem 8.84/3.35 (3) LLVMToTerminationGraphProof [EQUIVALENT, 803 ms] 8.84/3.35 (4) LLVM Symbolic Execution Graph 8.84/3.35 (5) SymbolicExecutionGraphToSCCProof [SOUND, 0 ms] 8.84/3.35 (6) LLVM Symbolic Execution SCC 8.84/3.35 (7) SCC2IRS [SOUND, 57 ms] 8.84/3.35 (8) IntTRS 8.84/3.35 (9) IntTRSCompressionProof [EQUIVALENT, 0 ms] 8.84/3.35 (10) IntTRS 8.84/3.35 (11) RankingReductionPairProof [EQUIVALENT, 19 ms] 8.84/3.35 (12) YES 8.84/3.35 8.84/3.35 8.84/3.35 ---------------------------------------- 8.84/3.35 8.84/3.35 (0) 8.84/3.35 Obligation: 8.84/3.35 c file /export/starexec/sandbox/benchmark/theBenchmark.c 8.84/3.35 ---------------------------------------- 8.84/3.35 8.84/3.35 (1) CToLLVMProof (EQUIVALENT) 8.84/3.35 Compiled c-file /export/starexec/sandbox/benchmark/theBenchmark.c to LLVM. 8.84/3.35 ---------------------------------------- 8.84/3.35 8.84/3.35 (2) 8.84/3.35 Obligation: 8.84/3.35 LLVM Problem 8.84/3.35 8.84/3.35 Aliases: 8.84/3.35 8.84/3.35 Data layout: 8.84/3.35 8.84/3.35 "e-p:64:64:64-i1:8:8-i8:8:8-i16:16:16-i32:32:32-i64:64:64-f32:32:32-f64:64:64-v64:64:64-v128:128:128-a0:0:64-s0:64:64-f80:128:128-n8:16:32:64-S128" 8.84/3.35 8.84/3.35 Machine: 8.84/3.35 8.84/3.35 "x86_64-pc-linux-gnu" 8.84/3.35 8.84/3.35 Type definitions: 8.84/3.35 8.84/3.35 Global variables: 8.84/3.35 8.84/3.35 Function declarations and definitions: 8.84/3.35 8.84/3.35 *BasicFunctionTypename: "__VERIFIER_nondet_int" returnParam: i32 parameters: () variableLength: true visibilityType: DEFAULT callingConvention: ccc 8.84/3.35 *BasicFunctionTypename: "main" linkageType: EXTERNALLY_VISIBLE returnParam: i32 parameters: () variableLength: false visibilityType: DEFAULT callingConvention: ccc 8.84/3.35 0: 8.84/3.35 %1 = alloca i32, align 4 8.84/3.35 %x = alloca i32, align 4 8.84/3.35 %y = alloca i32, align 4 8.84/3.35 store 0, %1 8.84/3.35 %2 = call i32 (...)* @__VERIFIER_nondet_int() 8.84/3.35 store %2, %x 8.84/3.35 %3 = call i32 (...)* @__VERIFIER_nondet_int() 8.84/3.35 store %3, %y 8.84/3.35 br %4 8.84/3.35 4: 8.84/3.35 %5 = load %x 8.84/3.35 %6 = load %y 8.84/3.35 %7 = icmp sgt %5 %6 8.84/3.35 br %7, %8, %20 8.84/3.35 8: 8.84/3.35 %9 = load %x 8.84/3.35 %10 = load %y 8.84/3.35 %11 = sub %9 %10 8.84/3.35 store %11, %x 8.84/3.35 %12 = call i32 (...)* @__VERIFIER_nondet_int() 8.84/3.35 store %12, %y 8.84/3.35 %13 = load %y 8.84/3.35 %14 = icmp slt %13 1 8.84/3.35 br %14, %18, %15 8.84/3.35 15: 8.84/3.35 %16 = load %y 8.84/3.35 %17 = icmp sgt %16 2 8.84/3.35 br %17, %18, %19 8.84/3.35 18: 8.84/3.35 br %20 8.84/3.35 19: 8.84/3.35 br %4 8.84/3.35 20: 8.84/3.35 ret 0 8.84/3.35 8.84/3.35 8.84/3.35 Analyze Termination of all function calls matching the pattern: 8.84/3.35 main() 8.84/3.35 ---------------------------------------- 8.84/3.35 8.84/3.35 (3) LLVMToTerminationGraphProof (EQUIVALENT) 8.84/3.35 Constructed symbolic execution graph for LLVM program and proved memory safety. 8.84/3.35 ---------------------------------------- 8.84/3.35 8.84/3.35 (4) 8.84/3.35 Obligation: 8.84/3.35 SE Graph 8.84/3.35 ---------------------------------------- 8.84/3.35 8.84/3.35 (5) SymbolicExecutionGraphToSCCProof (SOUND) 8.84/3.35 Splitted symbolic execution graph to 1 SCC. 8.84/3.35 ---------------------------------------- 8.84/3.35 8.84/3.35 (6) 8.84/3.35 Obligation: 8.84/3.35 SCC 8.84/3.35 ---------------------------------------- 8.84/3.35 8.84/3.35 (7) SCC2IRS (SOUND) 8.84/3.35 Transformed LLVM symbolic execution graph SCC into a rewrite problem. Log: 8.84/3.35 Generated rules. Obtained 21 rulesP rules: 8.84/3.35 f_160(v102, v103, v104, v105, v106, v110, v108, 1, v107, v111, 0, v113, v114, v115, 3, 2, 4) -> f_161(v102, v103, v104, v105, v106, v110, v111, 1, v107, v108, 0, v113, v114, v115, 3, 2, 4) :|: 0 = 0 8.84/3.35 f_161(v102, v103, v104, v105, v106, v110, v111, 1, v107, v108, 0, v113, v114, v115, 3, 2, 4) -> f_162(v102, v103, v104, v105, v106, v110, v111, 1, v107, v108, 0, v113, v114, v115, 3, 2, 4) :|: v111 < v110 && 2 <= v110 8.84/3.35 f_162(v102, v103, v104, v105, v106, v110, v111, 1, v107, v108, 0, v113, v114, v115, 3, 2, 4) -> f_164(v102, v103, v104, v105, v106, v110, v111, 1, v107, v108, 0, v113, v114, v115, 3, 2, 4) :|: 0 = 0 8.84/3.35 f_164(v102, v103, v104, v105, v106, v110, v111, 1, v107, v108, 0, v113, v114, v115, 3, 2, 4) -> f_166(v102, v103, v104, v105, v106, v110, v111, 1, v107, v108, 0, v113, v114, v115, 3, 2, 4) :|: TRUE 8.84/3.35 f_166(v102, v103, v104, v105, v106, v110, v111, 1, v107, v108, 0, v113, v114, v115, 3, 2, 4) -> f_168(v102, v103, v104, v105, v106, v110, v111, 1, v108, 0, v113, v114, v115, 3, 2, 4) :|: 0 = 0 8.84/3.35 f_168(v102, v103, v104, v105, v106, v110, v111, 1, v108, 0, v113, v114, v115, 3, 2, 4) -> f_169(v102, v103, v104, v105, v106, v110, v111, 1, 0, v113, v114, v115, 3, 2, 4) :|: 0 = 0 8.84/3.35 f_169(v102, v103, v104, v105, v106, v110, v111, 1, 0, v113, v114, v115, 3, 2, 4) -> f_170(v102, v103, v104, v105, v106, v110, v111, 1, v128, 0, v113, v114, v115, 3, 2, 4) :|: v128 + v111 = v110 && 1 <= v128 8.84/3.35 f_170(v102, v103, v104, v105, v106, v110, v111, 1, v128, 0, v113, v114, v115, 3, 2, 4) -> f_171(v102, v103, v104, v105, v106, v110, v111, 1, v128, 0, v113, v114, v115, 3, 2, 4) :|: TRUE 8.84/3.35 f_171(v102, v103, v104, v105, v106, v110, v111, 1, v128, 0, v113, v114, v115, 3, 2, 4) -> f_172(v102, v103, v104, v105, v106, v110, v111, 1, v128, v130, 0, v113, v114, v115, 3, 2, 4) :|: TRUE 8.84/3.35 f_172(v102, v103, v104, v105, v106, v110, v111, 1, v128, v130, 0, v113, v114, v115, 3, 2, 4) -> f_173(v102, v103, v104, v105, v106, v110, v111, 1, v128, v130, 0, v113, v114, v115, 3, 2, 4) :|: TRUE 8.84/3.35 f_173(v102, v103, v104, v105, v106, v110, v111, 1, v128, v130, 0, v113, v114, v115, 3, 2, 4) -> f_174(v102, v103, v104, v105, v106, v110, v111, 1, v128, v130, 0, v113, v114, v115, 3, 2, 4) :|: 0 = 0 8.84/3.35 f_174(v102, v103, v104, v105, v106, v110, v111, 1, v128, v130, 0, v113, v114, v115, 3, 2, 4) -> f_176(v102, v103, v104, v105, v106, v110, v111, 1, v128, v130, 0, v113, v114, v115, 3, 2, 4) :|: 1 <= v130 8.84/3.35 f_176(v102, v103, v104, v105, v106, v110, v111, 1, v128, v130, 0, v113, v114, v115, 3, 2, 4) -> f_178(v102, v103, v104, v105, v106, v110, v111, 1, v128, v130, 0, v113, v114, v115, 3, 2, 4) :|: 0 = 0 8.84/3.35 f_178(v102, v103, v104, v105, v106, v110, v111, 1, v128, v130, 0, v113, v114, v115, 3, 2, 4) -> f_180(v102, v103, v104, v105, v106, v110, v111, 1, v128, v130, 0, v113, v114, v115, 3, 2, 4) :|: TRUE 8.84/3.35 f_180(v102, v103, v104, v105, v106, v110, v111, 1, v128, v130, 0, v113, v114, v115, 3, 2, 4) -> f_182(v102, v103, v104, v105, v106, v110, v111, 1, v128, v130, 0, v113, v114, v115, 3, 2, 4) :|: 0 = 0 8.84/3.35 f_182(v102, v103, v104, v105, v106, v110, v111, 1, v128, v130, 0, v113, v114, v115, 3, 2, 4) -> f_184(v102, v103, v104, v105, v106, v110, v111, 1, v128, v130, 0, v113, v114, v115, 3, 2, 4) :|: v130 <= 2 8.84/3.35 f_184(v102, v103, v104, v105, v106, v110, v111, 1, v128, v130, 0, v113, v114, v115, 3, 2, 4) -> f_186(v102, v103, v104, v105, v106, v110, v111, 1, v128, v130, 0, v113, v114, v115, 3, 2, 4) :|: 0 = 0 8.84/3.35 f_186(v102, v103, v104, v105, v106, v110, v111, 1, v128, v130, 0, v113, v114, v115, 3, 2, 4) -> f_188(v102, v103, v104, v105, v106, v110, v111, 1, v128, v130, 0, v113, v114, v115, 3, 2, 4) :|: TRUE 8.84/3.35 f_188(v102, v103, v104, v105, v106, v110, v111, 1, v128, v130, 0, v113, v114, v115, 3, 2, 4) -> f_190(v102, v103, v104, v105, v106, v110, v111, 1, v128, v130, 0, v113, v114, v115, 3, 2, 4) :|: TRUE 8.84/3.35 f_190(v102, v103, v104, v105, v106, v110, v111, 1, v128, v130, 0, v113, v114, v115, 3, 2, 4) -> f_159(v102, v103, v104, v105, v106, v110, v111, 1, v128, v130, 0, v113, v114, v115, 3, 2, 4) :|: TRUE 8.84/3.35 f_159(v102, v103, v104, v105, v106, v107, v108, 1, v110, v111, 0, v113, v114, v115, 3, 2, 4) -> f_160(v102, v103, v104, v105, v106, v110, v108, 1, v107, v111, 0, v113, v114, v115, 3, 2, 4) :|: 0 = 0 8.84/3.35 Combined rules. Obtained 1 rulesP rules: 8.84/3.35 f_160(v102:0, v103:0, v104:0, v105:0, v106:0, v128:0 + v111:0, v108:0, 1, v107:0, v111:0, 0, v113:0, v114:0, v115:0, 3, 2, 4) -> f_160(v102:0, v103:0, v104:0, v105:0, v106:0, v128:0, v111:0, 1, v128:0 + v111:0, v130:0, 0, v113:0, v114:0, v115:0, 3, 2, 4) :|: v128:0 + v111:0 > 1 && v128:0 + v111:0 > v111:0 && v128:0 > 0 && v130:0 < 3 && v130:0 > 0 8.84/3.35 Filtered unneeded arguments: 8.84/3.35 f_160(x1, x2, x3, x4, x5, x6, x7, x8, x9, x10, x11, x12, x13, x14, x15, x16, x17) -> f_160(x6, x10) 8.84/3.35 Removed division, modulo operations, cleaned up constraints. Obtained 1 rules.P rules: 8.84/3.35 f_160(sum~v128:0~v111:0, v111:0) -> f_160(v128:0, v130:0) :|: v128:0 + v111:0 > v111:0 && v128:0 + v111:0 > 1 && v128:0 > 0 && v130:0 > 0 && v130:0 < 3 && sum~v128:0~v111:0 = v128:0 + v111:0 8.84/3.35 8.84/3.35 ---------------------------------------- 8.84/3.35 8.84/3.35 (8) 8.84/3.35 Obligation: 8.84/3.35 Rules: 8.84/3.35 f_160(sum~v128:0~v111:0, v111:0) -> f_160(v128:0, v130:0) :|: v128:0 + v111:0 > v111:0 && v128:0 + v111:0 > 1 && v128:0 > 0 && v130:0 > 0 && v130:0 < 3 && sum~v128:0~v111:0 = v128:0 + v111:0 8.84/3.35 8.84/3.35 ---------------------------------------- 8.84/3.35 8.84/3.35 (9) IntTRSCompressionProof (EQUIVALENT) 8.84/3.35 Compressed rules. 8.84/3.35 ---------------------------------------- 8.84/3.35 8.84/3.35 (10) 8.84/3.35 Obligation: 8.84/3.35 Rules: 8.84/3.35 f_160(sum~v128:0:0~v111:0:0, v111:0:0) -> f_160(v128:0:0, v130:0:0) :|: v130:0:0 > 0 && v130:0:0 < 3 && v128:0:0 > 0 && v128:0:0 + v111:0:0 > 1 && v128:0:0 + v111:0:0 > v111:0:0 && sum~v128:0:0~v111:0:0 = v128:0:0 + v111:0:0 8.84/3.35 8.84/3.35 ---------------------------------------- 8.84/3.35 8.84/3.35 (11) RankingReductionPairProof (EQUIVALENT) 8.84/3.35 Interpretation: 8.84/3.35 [ f_160 ] = f_160_1 + -1*f_160_2 8.84/3.35 8.84/3.35 The following rules are decreasing: 8.84/3.35 f_160(sum~v128:0:0~v111:0:0, v111:0:0) -> f_160(v128:0:0, v130:0:0) :|: v130:0:0 > 0 && v130:0:0 < 3 && v128:0:0 > 0 && v128:0:0 + v111:0:0 > 1 && v128:0:0 + v111:0:0 > v111:0:0 && sum~v128:0:0~v111:0:0 = v128:0:0 + v111:0:0 8.84/3.35 8.84/3.35 The following rules are bounded: 8.84/3.35 f_160(sum~v128:0:0~v111:0:0, v111:0:0) -> f_160(v128:0:0, v130:0:0) :|: v130:0:0 > 0 && v130:0:0 < 3 && v128:0:0 > 0 && v128:0:0 + v111:0:0 > 1 && v128:0:0 + v111:0:0 > v111:0:0 && sum~v128:0:0~v111:0:0 = v128:0:0 + v111:0:0 8.84/3.35 8.84/3.35 8.84/3.35 ---------------------------------------- 8.84/3.35 8.84/3.35 (12) 8.84/3.35 YES 8.98/3.39 EOF