scripts/cpa.sh -heap 10000M -setprop specification=/home/stahlbau/benchmarking/bench_regression_ea_safe_inproc/LDVErrorLabel.spc -explicitAnalysis -setprop analysis.summaryEdges=true -setprop cpa.callstack.skipRecursion=true -disable-java-assertions -noout -setprop analysis.entryFunction=ldv_main0_sequence_infinite_withcheck_stateful -64 -stats /home/stahlbau/benchmarking/bench_regression_ea_safe_inproc/programs/drivers--gpu--drm--i915--i915.ko/054.461cba2.08_1a.cil_safe.i -------------------------------------------------------------------------------- Running JavaVM with special heap size: 10000M CPAchecker 1.2-svn started (CPAchecker.run, INFO) Dead code detected at line 4822: switch (size) (CFACreationUtils.addEdgeToCFA, INFO) Dead code detected at line 4823: [!(size == 1U)] (CFACreationUtils.addEdgeToCFA, INFO) Dead code detected at line 4825: __asm__ volatile ("1:\tmovb %2,%b1\n2:\n.section .fixup,\"ax\"\n3:\tmov %3,%0\n\txorb %b1,%b1\n\tjmp 2b\n.previous\n .section __ex_table,\"a\"\n .balign 8 \n .quad 1b,3b\n .previous\n": "=r" (ret), "=q" (*((u8 *)dst)): "m" (*((struct __large_struct *)src)), "i" (1), "0" (ret)); (CFACreationUtils.addEdgeToCFA, INFO) Dead code detected at line 4830: [size == 2U] (CFACreationUtils.addEdgeToCFA, INFO) Dead code detected at line 4830: [!(size == 2U)] (CFACreationUtils.addEdgeToCFA, INFO) Dead code detected at line 4832: __asm__ volatile ("1:\tmovw %2,%w1\n2:\n.section .fixup,\"ax\"\n3:\tmov %3,%0\n\txorw %w1,%w1\n\tjmp 2b\n.previous\n .section __ex_table,\"a\"\n .balign 8 \n .quad 1b,3b\n .previous\n": "=r" (ret), "=r" (*((u16 *)dst)): "m" (*((struct __large_struct *)src)), "i" (2), "0" (ret)); (CFACreationUtils.addEdgeToCFA, INFO) Dead code detected at line 4837: [size == 4U] (CFACreationUtils.addEdgeToCFA, INFO) Dead code detected at line 4837: [!(size == 4U)] (CFACreationUtils.addEdgeToCFA, INFO) Dead code detected at line 4839: __asm__ volatile ("1:\tmovl %2,%k1\n2:\n.section .fixup,\"ax\"\n3:\tmov %3,%0\n\txorl %k1,%k1\n\tjmp 2b\n.previous\n .section __ex_table,\"a\"\n .balign 8 \n .quad 1b,3b\n .previous\n": "=r" (ret), "=r" (*((u32 *)dst)): "m" (*((struct __large_struct *)src)), "i" (4), "0" (ret)); (CFACreationUtils.addEdgeToCFA, INFO) Dead code detected at line 4844: [size == 8U] (CFACreationUtils.addEdgeToCFA, INFO) Dead code detected at line 4844: [!(size == 8U)] (CFACreationUtils.addEdgeToCFA, INFO) Dead code detected at line 4846: __asm__ volatile ("1:\tmovq %2,%1\n2:\n.section .fixup,\"ax\"\n3:\tmov %3,%0\n\txorq %1,%1\n\tjmp 2b\n.previous\n .section __ex_table,\"a\"\n .balign 8 \n .quad 1b,3b\n .previous\n": "=r" (ret), "=r" (*((u64 *)dst)): "m" (*((struct __large_struct *)src)), "i" (8), "0" (ret)); (CFACreationUtils.addEdgeToCFA, INFO) Dead code detected at line 4851: [size == 10U] (CFACreationUtils.addEdgeToCFA, INFO) Dead code detected at line 4851: [!(size == 10U)] (CFACreationUtils.addEdgeToCFA, INFO) Dead code detected at line 4853: __asm__ volatile ("1:\tmovq %2,%1\n2:\n.section .fixup,\"ax\"\n3:\tmov %3,%0\n\txorq %1,%1\n\tjmp 2b\n.previous\n .section __ex_table,\"a\"\n .balign 8 \n .quad 1b,3b\n .previous\n": "=r" (ret), "=r" (*((u64 *)dst)): "m" (*((struct __large_struct *)src)), "i" (10), "0" (ret)); (CFACreationUtils.addEdgeToCFA, INFO) Dead code detected at line 4859: [!(tmp___0 != 0L)] (CFACreationUtils.addEdgeToCFA, INFO) Dead code detected at line 4861: return (ret); (CFACreationUtils.addEdgeToCFA, INFO) Dead code detected at line 4866: __asm__ volatile ("1:\tmovw %2,%w1\n2:\n.section .fixup,\"ax\"\n3:\tmov %3,%0\n\txorw %w1,%w1\n\tjmp 2b\n.previous\n .section __ex_table,\"a\"\n .balign 8 \n .quad 1b,3b\n .previous\n": "=r" (ret), "=r" (*((u16 *)dst + 8U)): "m" (*((struct __large_struct *)src + 8U)), "i" (2), "0" (ret)); (CFACreationUtils.addEdgeToCFA, INFO) Dead code detected at line 4871: [size == 16U] (CFACreationUtils.addEdgeToCFA, INFO) Dead code detected at line 4871: [!(size == 16U)] (CFACreationUtils.addEdgeToCFA, INFO) Dead code detected at line 4873: __asm__ volatile ("1:\tmovq %2,%1\n2:\n.section .fixup,\"ax\"\n3:\tmov %3,%0\n\txorq %1,%1\n\tjmp 2b\n.previous\n .section __ex_table,\"a\"\n .balign 8 \n .quad 1b,3b\n .previous\n": "=r" (ret), "=r" (*((u64 *)dst)): "m" (*((struct __large_struct *)src)), "i" (16), "0" (ret)); (CFACreationUtils.addEdgeToCFA, INFO) Dead code detected at line 4879: [!(tmp___1 != 0L)] (CFACreationUtils.addEdgeToCFA, INFO) Dead code detected at line 4881: return (ret); (CFACreationUtils.addEdgeToCFA, INFO) Dead code detected at line 4886: __asm__ volatile ("1:\tmovq %2,%1\n2:\n.section .fixup,\"ax\"\n3:\tmov %3,%0\n\txorq %1,%1\n\tjmp 2b\n.previous\n .section __ex_table,\"a\"\n .balign 8 \n .quad 1b,3b\n .previous\n": "=r" (ret), "=r" (*((u64 *)dst + 8U)): "m" (*((struct __large_struct *)src + 8U)), "i" (8), "0" (ret)); (CFACreationUtils.addEdgeToCFA, INFO) Dead code detected at line 4891: switch (size) { case 1U: #line 35 __asm__ volatile ("1:\tmovb %2,%b1\n2:\n.section .fixup,\"ax\"\n3:\tmov %3,%0\n\txorb %b1,%b1\n\tjmp 2b\n.previous\n .section __ex_table,\"a\"\n .balign 8 \n .quad 1b,3b\n .previous\n": "=r" (ret), "=q" (*((u8 *)dst)): "m" (*((struct __large_struct *)src)), "i" (1), "0" (ret)); #line 37 return (ret); case 2U: #line 38 __asm__ volatile ("1:\tmovw %2,%w1\n2:\n.section .fixup,\"ax\"\n3:\tmov %3,%0\n\txorw %w1,%w1\n\tjmp 2b\n.previous\n .section __ex_table,\"a\"\n .balign 8 \n .quad 1b,3b\n .previous\n": "=r" (ret), "=r" (*((u16 *)dst)): "m" (*((struct __large_struct *)src)), "i" (2), "0" (ret)); #line 40 return (ret); case 4U: #line 41 __asm__ volatile ("1:\tmovl %2,%k1\n2:\n.section .fixup,\"ax\"\n3:\tmov %3,%0\n\txorl %k1,%k1\n\tjmp 2b\n.previous\n .section __ex_table,\"a\"\n .balign 8 \n .quad 1b,3b\n .previous\n": "=r" (ret), "=r" (*((u32 *)dst)): "m" (*((struct __large_struct *)src)), "i" (4), "0" (ret)); #line 43 return (ret); case 8U: #line 44 __asm__ volatile ("1:\tmovq %2,%1\n2:\n.section .fixup,\"ax\"\n3:\tmov %3,%0\n\txorq %1,%1\n\tjmp 2b\n.previous\n .section __ex_table,\"a\"\n .balign 8 \n .quad 1b,3b\n .previous\n": "=r" (ret), "=r" (*((u64 *)dst)): "m" (*((struct __large_struct *)src)), "i" (8), "0" (ret)); #line 46 return (ret); case 10U: #line 48 __asm__ volatile ("1:\tmovq %2,%1\n2:\n.section .fixup,\"ax\"\n3:\tmov %3,%0\n\txorq %1,%1\n\tjmp 2b\n.previous\n .section __ex_table,\"a\"\n .balign 8 \n .quad 1b,3b\n .previous\n": "=r" (ret), "=r" (*((u64 *)dst)): "m" (*((struct __large_struct *)src)), "i" (10), "0" (ret)); #line 50 tmp___0 = __builtin_expect(ret != 0, 0L); #line 50 if (tmp___0 != 0L) { #line 51 return (ret); } else { } #line 52 __asm__ volatile ("1:\tmovw %2,%w1\n2:\n.section .fixup,\"ax\"\n3:\tmov %3,%0\n\txorw %w1,%w1\n\tjmp 2b\n.previous\n .section __ex_table,\"a\"\n .balign 8 \n .quad 1b,3b\n .previous\n": "=r" (ret), "=r" (*((u16 *)dst + 8U)): "m" (*((struct __large_struct *)src + 8U)), "i" (2), "0" (ret)); #line 55 return (ret); case 16U: #line 57 __asm__ volatile ("1:\tmovq %2,%1\n2:\n.section .fixup,\"ax\"\n3:\tmov %3,%0\n\txorq %1,%1\n\tjmp 2b\n.previous\n .section __ex_table,\"a\"\n .balign 8 \n .quad 1b,3b\n .previous\n": "=r" (ret), "=r" (*((u64 *)dst)): "m" (*((struct __large_struct *)src)), "i" (16), "0" (ret)); #line 59 tmp___1 = __builtin_expect(ret != 0, 0L); #line 59 if (tmp___1 != 0L) { #line 60 return (ret); } else { } #line 61 __asm__ volatile ("1:\tmovq %2,%1\n2:\n.section .fixup,\"ax\"\n3:\tmov %3,%0\n\txorq %1,%1\n\tjmp 2b\n.previous\n .section __ex_table,\"a\"\n .balign 8 \n .quad 1b,3b\n .previous\n": "=r" (ret), "=r" (*((u64 *)dst + 8U)): "m" (*((struct __large_struct *)src + 8U)), "i" (8), "0" (ret)); #line 64 return (ret); default: #line 66 tmp___2 = copy_user_generic(dst, src, size); #line 66 return ((int )tmp___2); } (CFACreationUtils.addEdgeToCFA, INFO) Dead code detected at line 5476: Goto: ldv_23754 (CFACreationUtils.addEdgeToCFA, INFO) Dead code detected at line 5548: Label ldv_23754 is not reachable. (CFAFunctionBuilder.leave, INFO) Inline assembler ignored, analysis is probably unsound! (CFABuilder.leave, WARNING) Function pointer *fn with type drm_ioctl_compat_t * is called in line 17353, but no possible target functions were found. (CFunctionPointerResolver.replaceFunctionPointerCall, WARNING) Analyzing with the following global conditions: timeout (walltime): 900 s (GlobalConditionsCPA., INFO) Starting analysis ... (CPAchecker.runAlgorithm, INFO) Stopping analysis ... (CPAchecker.runAlgorithm, INFO) ExplicitCPA statistics ---------------------- Max. number of variables: 1 Max. number of globals variables: 0 Avg. number of variables: 8.0E-4 Avg. number of global variables: 0.0 AutomatonAnalysis (SVCOMP) statistics ------------------------------------- Number of states: 1 Total time for successor computation: 0.015s OmniscientCompositePrecisionAdjustment Stats statistics ------------------------------------------------------- Total time: 0.384s Total time for composite: 0.021s Total time for abstraction: 0.336s Total time for reached set: 0.004s Total time for path: 0.001s abstractions: 2827 CPA algorithm statistics ------------------------ Number of iterations: 2405 Max size of waitlist: 13 Average size of waitlist: 7 Number of computed successors: 2827 Max successors for one state: 2 Number of times merged: 0 Number of times stopped: 422 Number of times breaked: 1 Total time for CPA algorithm: 0.669s (Max: 0.455s) Time for choose from waitlist: 0.010s Time for precision adjustment: 0.390s Time for transfer relation: 0.199s Time for stop operator: 0.020s Time for adding to reached set: 0.023s Explicit Interpolation-Based Refiner statistics ----------------------------------------------- number of explicit refinements: 1 number of successful explicit refinements: 1 number of explicit interpolations: 33 max. time for singe interpolation: 0.064s total time for interpolation: 0.064s CEGAR algorithm statistics -------------------------- Number of refinements: 1 Number of successful refinements: 1 Number of failed refinements: 0 Max. size of reached set before ref.: 1203 Max. size of reached set after ref.: 1 Avg. size of reached set before ref.: 1203.00 Avg. size of reached set after ref.: 1.00 Total time for CEGAR algorithm: 0.835s Time for refinements: 0.166s Average time for refinement: 0.166s Max time for refinement: 0.166s Counterexample-Check Algorithm statistics ----------------------------------------- Number of counterexample checks: 0 CPAchecker general statistics ----------------------------- Size of reached set: 1204 Number of locations: 658 Avg states per loc.: 1 Max states per loc.: 85 (at node N129) Number of partitions: 1204 Avg size of partitions: 1 Max size of partitions: 1 Number of target states: 0 Number of program locations: 4934 Number of functions: 220 Number of loops: 82 Time for analysis setup: 2.286s Time for loading CPAs: 0.087s Time for loading C parser: 0.215s Time for CFA construction: 1.870s Time for parsing C file: 0.934s Time for AST to CFA: 0.674s Time for CFA sanity check: 0.001s Time for post-processing: 0.211s Time for Analysis: 0.835s CPU time for analysis: 1.930s Total time for CPAchecker: 3.124s Total CPU time for CPAchecker: 6.070s Time for Garbage Collector: 0.048s (in 1 runs) Garbage Collector(s) used: PS MarkSweep, PS Scavenge Used heap memory: 125MB max ( 67MB avg, 148MB peak) Used non-heap memory: 17MB max ( 14MB avg, 18MB peak) Used in PS Old Gen pool: 2MB max ( 0MB avg, 2MB peak) Allocated heap memory: 480MB max ( 480MB avg) Allocated non-heap memory: 23MB max ( 23MB avg) Total process virtual memory: 11934MB max ( 11922MB avg) Verification result: SAFE. No error path found by chosen configuration. More details about the verification run can be found in the directory "./output".