[ 0:01] | load /home/xrockai/src/divine/nightly/test/refine/pointers/mem-layout-a.c mem-layout-a.c [ 0:01] | expect --result error --location mem-layout-a.c:21 [ 0:01] | expect --trace FAULT: --trace-count 1 [ 0:01] | cc -o testcase.bc mem-layout-a.c [ 0:01] | refine -o nofail:malloc --refinement pointers --output testcase.bc testcase.bc [ 0:01] | verify --max-memory 4GiB --max-time 600 --threads 2 --report-filename verify.out --solver stp -o nofail:malloc --lamp pointers --symbolic testcase.bc [ 0:01] compiling mem-layout-a.c [ 0:01] loading bitcode … DiOS … LART … RR … constants … done [ 0:58] booting … done [ 0:58] states per second: 2.10526 [ 1:00] state count: 4 [ 1:00] mips: 0.23 [ 1:00] symbolic: 1 [ 1:02] [ 1:02] error found: yes [ 1:02] error trace: | [ 1:02] ASSUME (not (= var_1 #x0000000000000000)) [ 1:02] ASSUME (not (= var_2 #x0000000000000000)) [ 1:02] ASSUME (and (not (= var_2 #x0000000000000000)) (bvult var_2 (bvsub #xffffffffffffffff #x0000000000000001))) [ 1:02] ASSUME (and (not (= var_1 #x0000000000000000)) (bvult var_1 (bvsub #xffffffffffffffff #x0000000000000001))) [ 1:02] ASSUME (and (and (and (not (= var_2 #x0000000000000000)) (bvult var_2 (bvsub #xffffffffffffffff #x0000000000000001))) (or (bvule (bvadd var_2 #x0000000000000001) var_1) (bvule (bvadd var_1 #x0000000000000001) var_2))) (and (not (= var_1 #x0000000000000000)) (bvult var_1 (bvsub #xffffffffffffffff #x0000000000000001)))) [ 1:02] ASSUME (not (= var_3 #x0000000000000000)) [ 1:02] ASSUME (and (not (= var_3 #x0000000000000000)) (bvult var_3 (bvsub #xffffffffffffffff #x0000000000000001))) [ 1:02] ASSUME (and (and (and (and (not (= var_2 #x0000000000000000)) (bvult var_2 (bvsub #xffffffffffffffff #x0000000000000001))) (or (bvule (bvadd var_2 #x0000000000000001) var_1) (bvule (bvadd var_1 #x0000000000000001) var_2))) (and (not (= var_1 #x0000000000000000)) (bvult var_1 (bvsub #xffffffffffffffff #x0000000000000001)))) (bvult var_1 (bvsub #xffffffffffffffff #x0000000000000001))) [ 1:02] ASSUME (and (and (and (not (= var_3 #x0000000000000000)) (bvult var_3 (bvsub #xffffffffffffffff #x0000000000000001))) (or (bvule (bvadd var_3 #x0000000000000001) var_1) (bvule (bvadd var_1 #x0000000000000001) var_3))) (and (and (and (and (not (= var_2 #x0000000000000000)) (bvult var_2 (bvsub #xffffffffffffffff #x0000000000000001))) (or (bvule (bvadd var_2 #x0000000000000001) var_1) (bvule (bvadd var_1 #x0000000000000001) var_2))) (and (not (= var_1 #x0000000000000000)) (bvult var_1 (bvsub #xffffffffffffffff #x0000000000000001)))) (bvult var_1 (bvsub #xffffffffffffffff #x0000000000000001)))) [ 1:02] ASSUME (and (and (and (and (not (= var_3 #x0000000000000000)) (bvult var_3 (bvsub #xffffffffffffffff #x0000000000000001))) (or (bvule (bvadd var_3 #x0000000000000001) var_1) (bvule (bvadd var_1 #x0000000000000001) var_3))) (and (and (and (and (not (= var_2 #x0000000000000000)) (bvult var_2 (bvsub #xffffffffffffffff #x0000000000000001))) (or (bvule (bvadd var_2 #x0000000000000001) var_1) (bvule (bvadd var_1 #x0000000000000001) var_2))) (and (not (= var_1 #x0000000000000000)) (bvult var_1 (bvsub #xffffffffffffffff #x0000000000000001)))) (bvult var_1 (bvsub #xffffffffffffffff #x0000000000000001)))) (bvult var_3 (bvsub #xffffffffffffffff #x0000000000000001))) [ 1:02] ASSUME (and (and (and (and (and (not (= var_3 #x0000000000000000)) (bvult var_3 (bvsub #xffffffffffffffff #x0000000000000001))) (or (bvule (bvadd var_3 #x0000000000000001) var_1) (bvule (bvadd var_1 #x0000000000000001) var_3))) (and (and (and (and (not (= var_2 #x0000000000000000)) (bvult var_2 (bvsub #xffffffffffffffff #x0000000000000001))) (or (bvule (bvadd var_2 #x0000000000000001) var_1) (bvule (bvadd var_1 #x0000000000000001) var_2))) (and (not (= var_1 #x0000000000000000)) (bvult var_1 (bvsub #xffffffffffffffff #x0000000000000001)))) (bvult var_1 (bvsub #xffffffffffffffff #x0000000000000001)))) (bvult var_3 (bvsub #xffffffffffffffff #x0000000000000001))) (bvult var_2 (bvsub #xffffffffffffffff #x0000000000000001))) [ 1:02] ASSUME (and (and (and (and (and (and (not (= var_3 #x0000000000000000)) (bvult var_3 (bvsub #xffffffffffffffff #x0000000000000001))) (or (bvule (bvadd var_3 #x0000000000000001) var_1) (bvule (bvadd var_1 #x0000000000000001) var_3))) (and (and (and (and (not (= var_2 #x0000000000000000)) (bvult var_2 (bvsub #xffffffffffffffff #x0000000000000001))) (or (bvule (bvadd var_2 #x0000000000000001) var_1) (bvule (bvadd var_1 #x0000000000000001) var_2))) (and (not (= var_1 #x0000000000000000)) (bvult var_1 (bvsub #xffffffffffffffff #x0000000000000001)))) (bvult var_1 (bvsub #xffffffffffffffff #x0000000000000001)))) (bvult var_3 (bvsub #xffffffffffffffff #x0000000000000001))) (bvult var_2 (bvsub #xffffffffffffffff #x0000000000000001))) (or (bvule (bvadd var_3 #x0000000000000001) var_2) (bvule (bvadd var_2 #x0000000000000001) var_3))) [ 1:02] ASSUME (and (and (and (and (and (and (and (not (= var_3 #x0000000000000000)) (bvult var_3 (bvsub #xffffffffffffffff #x0000000000000001))) (or (bvule (bvadd var_3 #x0000000000000001) var_1) (bvule (bvadd var_1 #x0000000000000001) var_3))) (and (and (and (and (not (= var_2 #x0000000000000000)) (bvult var_2 (bvsub #xffffffffffffffff #x0000000000000001))) (or (bvule (bvadd var_2 #x0000000000000001) var_1) (bvule (bvadd var_1 #x0000000000000001) var_2))) (and (not (= var_1 #x0000000000000000)) (bvult var_1 (bvsub #xffffffffffffffff #x0000000000000001)))) (bvult var_1 (bvsub #xffffffffffffffff #x0000000000000001)))) (bvult var_3 (bvsub #xffffffffffffffff #x0000000000000001))) (bvult var_2 (bvsub #xffffffffffffffff #x0000000000000001))) (or (bvule (bvadd var_3 #x0000000000000001) var_2) (bvule (bvadd var_2 #x0000000000000001) var_3))) (bvult var_2 var_1)) [ 1:02] ASSUME (and (and (and (and (and (and (and (and (not (= var_3 #x0000000000000000)) (bvult var_3 (bvsub #xffffffffffffffff #x0000000000000001))) (or (bvule (bvadd var_3 #x0000000000000001) var_1) (bvule (bvadd var_1 #x0000000000000001) var_3))) (and (and (and (and (not (= var_2 #x0000000000000000)) (bvult var_2 (bvsub #xffffffffffffffff #x0000000000000001))) (or (bvule (bvadd var_2 #x0000000000000001) var_1) (bvule (bvadd var_1 #x0000000000000001) var_2))) (and (not (= var_1 #x0000000000000000)) (bvult var_1 (bvsub #xffffffffffffffff #x0000000000000001)))) (bvult var_1 (bvsub #xffffffffffffffff #x0000000000000001)))) (bvult var_3 (bvsub #xffffffffffffffff #x0000000000000001))) (bvult var_2 (bvsub #xffffffffffffffff #x0000000000000001))) (or (bvule (bvadd var_3 #x0000000000000001) var_2) (bvule (bvadd var_2 #x0000000000000001) var_3))) (bvult var_2 var_1)) (bvugt var_3 var_1)) [ 1:02] ASSUME (and (and (and (and (and (and (and (and (and (not (= var_3 #x0000000000000000)) (bvult var_3 (bvsub #xffffffffffffffff #x0000000000000001))) (or (bvule (bvadd var_3 #x0000000000000001) var_1) (bvule (bvadd var_1 #x0000000000000001) var_3))) (and (and (and (and (not (= var_2 #x0000000000000000)) (bvult var_2 (bvsub #xffffffffffffffff #x0000000000000001))) (or (bvule (bvadd var_2 #x0000000000000001) var_1) (bvule (bvadd var_1 #x0000000000000001) var_2))) (and (not (= var_1 #x0000000000000000)) (bvult var_1 (bvsub #xffffffffffffffff #x0000000000000001)))) (bvult var_1 (bvsub #xffffffffffffffff #x0000000000000001)))) (bvult var_3 (bvsub #xffffffffffffffff #x0000000000000001))) (bvult var_2 (bvsub #xffffffffffffffff #x0000000000000001))) (or (bvule (bvadd var_3 #x0000000000000001) var_2) (bvule (bvadd var_2 #x0000000000000001) var_3))) (bvult var_2 var_1)) (bvugt var_3 var_1)) (not (bvugt var_2 var_3))) [ 1:02] FAULT: mem-layout-a.c:21: int main(): assertion 'xi > yi' failed [ 1:02] [0] FATAL: assertion failure in userspace [ 1:02] [ 1:02] active stack: [ 1:03] - symbol: void __dios::FaultBase::handler<__dios::Context>(_VM_Fault, _VM_Frame*, void (*)()) [ 1:04] location: /dios/sys/fault.hpp:118 [ 1:04] - symbol: __dios_fault [ 1:04] location: /dios/arch/divm/fault.c:12 [ 1:04] - symbol: lart.__assert_fail [ 1:04] location: /dios/libc/_PDCLIB/assert.c:24 [ 1:04] - symbol: main [ 1:04] location: mem-layout-a.c:21 [ 1:04] - symbol: __dios_start [ 1:04] location: /dios/libc/sys/start.cpp:94 [ 1:04] + divine sim --batch --skip-init --load-report verify.out [ 1:04] [ 1:15] ^ —————. —.— . . —.— . . .————— . . [ 1:15] ——— | | | | | | |\ | | | | [ 1:15] —(o)— | | | | | | | \ | |———— '————| [ 1:15] ——————— | | | \ / | | \| | | [ 1:15] ————————— —————' —'— ' —'— ' ' '————— ' [ 1:15] [ 1:15] Welcome to 'divine sim', an interactive debugger. Type 'help' to get started. [ 1:15] traced states: [ 1:15] ▶ state #1 [new] -- active threads: [0:0] -- [ 1:15] T: FAULT: mem-layout-a.c:21: int main(): assertion 'xi > yi' failed [ 1:16] # executing void __dios::FaultBase::handler<{Context}>(_VM_Fault, _VM_Frame*, void (*)()) at /dios/sys/fault.hpp:118 [ 1:16] # NOTE: $frame in __dios_fault [ 1:16] > backtrace [ 1:16] void __dios::FaultBase::handler<{Context}>(_VM_Fault, _VM_Frame*, void (*)()) at /dios/sys/fault.hpp:118 [ 1:16] __dios_fault at /dios/arch/divm/fault.c:12 [ 1:16] lart.__assert_fail at /dios/libc/_PDCLIB/assert.c:24 [ 1:16] main at mem-layout-a.c:21 [ 1:16] __dios_start at /dios/libc/sys/start.cpp:94 [ 1:16] # executing void __dios::FaultBase::handler<{Context}>(_VM_Fault, _VM_Frame*, void (*)()) at /dios/sys/fault.hpp:118 [ 1:17] # NOTE: $frame in __dios_fault