java -Xmx8000000000 -jar /storage/repos/ultimate/releaseScripts/default/UTaipan-linux/plugins/org.eclipse.equinox.launcher_1.3.100.v20150511-1540.jar -data @noDefault -ultimatedata /storage/repos/ultimate/releaseScripts/default/UTaipan-linux/data -tc ../../../trunk/examples/toolchains/AutomizerCInline.xml -s ../../../trunk/examples/settings/default/taipan/svcomp-Reach-64bit-Taipan_Default.epf -i ../../../trunk/examples/svcomp/eca-rers2012/Problem12_label56_true-unreach-call.c -------------------------------------------------------------------------------- This is Ultimate 0.1.23-d380424 [2018-10-24 21:25:49,283 INFO L170 SettingsManager]: Resetting all preferences to default values... [2018-10-24 21:25:49,285 INFO L174 SettingsManager]: Resetting UltimateCore preferences to default values [2018-10-24 21:25:49,297 INFO L177 SettingsManager]: Ultimate Commandline Interface provides no preferences, ignoring... [2018-10-24 21:25:49,298 INFO L174 SettingsManager]: Resetting Boogie Preprocessor preferences to default values [2018-10-24 21:25:49,299 INFO L174 SettingsManager]: Resetting Boogie Procedure Inliner preferences to default values [2018-10-24 21:25:49,300 INFO L174 SettingsManager]: Resetting Abstract Interpretation preferences to default values [2018-10-24 21:25:49,302 INFO L174 SettingsManager]: Resetting LassoRanker preferences to default values [2018-10-24 21:25:49,304 INFO L174 SettingsManager]: Resetting Reaching Definitions preferences to default values [2018-10-24 21:25:49,304 INFO L174 SettingsManager]: Resetting SyntaxChecker preferences to default values [2018-10-24 21:25:49,305 INFO L177 SettingsManager]: Büchi Program Product provides no preferences, ignoring... [2018-10-24 21:25:49,306 INFO L174 SettingsManager]: Resetting LTL2Aut preferences to default values [2018-10-24 21:25:49,307 INFO L174 SettingsManager]: Resetting PEA to Boogie preferences to default values [2018-10-24 21:25:49,308 INFO L174 SettingsManager]: Resetting BlockEncodingV2 preferences to default values [2018-10-24 21:25:49,309 INFO L174 SettingsManager]: Resetting ChcToBoogie preferences to default values [2018-10-24 21:25:49,310 INFO L174 SettingsManager]: Resetting AutomataScriptInterpreter preferences to default values [2018-10-24 21:25:49,311 INFO L174 SettingsManager]: Resetting BuchiAutomizer preferences to default values [2018-10-24 21:25:49,314 INFO L174 SettingsManager]: Resetting CACSL2BoogieTranslator preferences to default values [2018-10-24 21:25:49,321 INFO L174 SettingsManager]: Resetting CodeCheck preferences to default values [2018-10-24 21:25:49,326 INFO L174 SettingsManager]: Resetting InvariantSynthesis preferences to default values [2018-10-24 21:25:49,327 INFO L174 SettingsManager]: Resetting RCFGBuilder preferences to default values [2018-10-24 21:25:49,330 INFO L174 SettingsManager]: Resetting TraceAbstraction preferences to default values [2018-10-24 21:25:49,333 INFO L177 SettingsManager]: TraceAbstractionConcurrent provides no preferences, ignoring... [2018-10-24 21:25:49,335 INFO L177 SettingsManager]: TraceAbstractionWithAFAs provides no preferences, ignoring... [2018-10-24 21:25:49,335 INFO L174 SettingsManager]: Resetting TreeAutomizer preferences to default values [2018-10-24 21:25:49,336 INFO L174 SettingsManager]: Resetting IcfgTransformer preferences to default values [2018-10-24 21:25:49,337 INFO L174 SettingsManager]: Resetting Boogie Printer preferences to default values [2018-10-24 21:25:49,340 INFO L174 SettingsManager]: Resetting ReqPrinter preferences to default values [2018-10-24 21:25:49,341 INFO L174 SettingsManager]: Resetting Witness Printer preferences to default values [2018-10-24 21:25:49,344 INFO L177 SettingsManager]: Boogie PL CUP Parser provides no preferences, ignoring... [2018-10-24 21:25:49,344 INFO L174 SettingsManager]: Resetting CDTParser preferences to default values [2018-10-24 21:25:49,346 INFO L177 SettingsManager]: AutomataScriptParser provides no preferences, ignoring... [2018-10-24 21:25:49,346 INFO L177 SettingsManager]: ReqParser provides no preferences, ignoring... [2018-10-24 21:25:49,346 INFO L174 SettingsManager]: Resetting SmtParser preferences to default values [2018-10-24 21:25:49,347 INFO L174 SettingsManager]: Resetting Witness Parser preferences to default values [2018-10-24 21:25:49,349 INFO L181 SettingsManager]: Finished resetting all preferences to default values... [2018-10-24 21:25:49,349 INFO L98 SettingsManager]: Beginning loading settings from /storage/repos/ultimate/releaseScripts/default/UTaipan-linux/../../../trunk/examples/settings/default/taipan/svcomp-Reach-64bit-Taipan_Default.epf [2018-10-24 21:25:49,377 INFO L110 SettingsManager]: Loading preferences was successful [2018-10-24 21:25:49,378 INFO L112 SettingsManager]: Preferences different from defaults after loading the file: [2018-10-24 21:25:49,379 INFO L131 SettingsManager]: Preferences of Boogie Procedure Inliner differ from their defaults: [2018-10-24 21:25:49,380 INFO L133 SettingsManager]: * User list type=DISABLED [2018-10-24 21:25:49,380 INFO L133 SettingsManager]: * calls to implemented procedures=false [2018-10-24 21:25:49,380 INFO L131 SettingsManager]: Preferences of Abstract Interpretation differ from their defaults: [2018-10-24 21:25:49,380 INFO L133 SettingsManager]: * Abstract domain for RCFG-of-the-future=PoormanAbstractDomain [2018-10-24 21:25:49,380 INFO L133 SettingsManager]: * Abstract domain=CompoundDomain [2018-10-24 21:25:49,381 INFO L133 SettingsManager]: * Log string format=TERM [2018-10-24 21:25:49,381 INFO L133 SettingsManager]: * Check feasibility of abstract posts with an SMT solver=true [2018-10-24 21:25:49,381 INFO L133 SettingsManager]: * Use the RCFG-of-the-future interface=true [2018-10-24 21:25:49,381 INFO L133 SettingsManager]: * Interval Domain=false [2018-10-24 21:25:49,382 INFO L131 SettingsManager]: Preferences of CACSL2BoogieTranslator differ from their defaults: [2018-10-24 21:25:49,382 INFO L133 SettingsManager]: * Overapproximate operations on floating types=true [2018-10-24 21:25:49,383 INFO L133 SettingsManager]: * Check division by zero=IGNORE [2018-10-24 21:25:49,383 INFO L133 SettingsManager]: * Pointer to allocated memory at dereference=IGNORE [2018-10-24 21:25:49,383 INFO L133 SettingsManager]: * If two pointers are subtracted or compared they have the same base address=IGNORE [2018-10-24 21:25:49,383 INFO L133 SettingsManager]: * Check array bounds for arrays that are off heap=IGNORE [2018-10-24 21:25:49,383 INFO L133 SettingsManager]: * Check if freed pointer was valid=false [2018-10-24 21:25:49,384 INFO L133 SettingsManager]: * Pointer base address is valid at dereference=IGNORE [2018-10-24 21:25:49,384 INFO L131 SettingsManager]: Preferences of RCFGBuilder differ from their defaults: [2018-10-24 21:25:49,384 INFO L133 SettingsManager]: * Size of a code block=SequenceOfStatements [2018-10-24 21:25:49,384 INFO L133 SettingsManager]: * To the following directory=./dump/ [2018-10-24 21:25:49,384 INFO L133 SettingsManager]: * SMT solver=External_DefaultMode [2018-10-24 21:25:49,385 INFO L133 SettingsManager]: * Command for external solver=z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in -t:2000 [2018-10-24 21:25:49,386 INFO L131 SettingsManager]: Preferences of TraceAbstraction differ from their defaults: [2018-10-24 21:25:49,387 INFO L133 SettingsManager]: * Compute Interpolants along a Counterexample=FPandBP [2018-10-24 21:25:49,387 INFO L133 SettingsManager]: * Positions where we compute the Hoare Annotation=LoopsAndPotentialCycles [2018-10-24 21:25:49,387 INFO L133 SettingsManager]: * Trace refinement strategy=TAIPAN [2018-10-24 21:25:49,387 INFO L133 SettingsManager]: * SMT solver=External_ModelsAndUnsatCoreMode [2018-10-24 21:25:49,387 INFO L133 SettingsManager]: * Command for external solver=z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in [2018-10-24 21:25:49,387 INFO L133 SettingsManager]: * Compute Hoare Annotation of negated interpolant automaton, abstraction and CFG=true [2018-10-24 21:25:49,388 INFO L133 SettingsManager]: * To the following directory=dump/ [2018-10-24 21:25:49,388 INFO L133 SettingsManager]: * Abstract interpretation Mode=USE_PREDICATES [2018-10-24 21:25:49,436 INFO L81 nceAwareModelManager]: Repository-Root is: /tmp [2018-10-24 21:25:49,452 INFO L258 ainManager$Toolchain]: [Toolchain 1]: Applicable parser(s) successfully (re)initialized [2018-10-24 21:25:49,456 INFO L214 ainManager$Toolchain]: [Toolchain 1]: Toolchain selected. [2018-10-24 21:25:49,457 INFO L271 PluginConnector]: Initializing CDTParser... [2018-10-24 21:25:49,458 INFO L276 PluginConnector]: CDTParser initialized [2018-10-24 21:25:49,459 INFO L418 ainManager$Toolchain]: [Toolchain 1]: Parsing single file: /storage/repos/ultimate/releaseScripts/default/UTaipan-linux/../../../trunk/examples/svcomp/eca-rers2012/Problem12_label56_true-unreach-call.c [2018-10-24 21:25:49,524 INFO L218 CDTParser]: Created temporary CDT project at /storage/repos/ultimate/releaseScripts/default/UTaipan-linux/data/76724889c/1a90d16ca26d41d39306e667dedfe69d/FLAG3dbc258c8 [2018-10-24 21:25:50,246 INFO L298 CDTParser]: Found 1 translation units. [2018-10-24 21:25:50,247 INFO L158 CDTParser]: Scanning /storage/repos/ultimate/trunk/examples/svcomp/eca-rers2012/Problem12_label56_true-unreach-call.c [2018-10-24 21:25:50,275 INFO L346 CDTParser]: About to delete temporary CDT project at /storage/repos/ultimate/releaseScripts/default/UTaipan-linux/data/76724889c/1a90d16ca26d41d39306e667dedfe69d/FLAG3dbc258c8 [2018-10-24 21:25:50,292 INFO L354 CDTParser]: Successfully deleted /storage/repos/ultimate/releaseScripts/default/UTaipan-linux/data/76724889c/1a90d16ca26d41d39306e667dedfe69d [2018-10-24 21:25:50,307 INFO L296 ainManager$Toolchain]: ####################### [Toolchain 1] ####################### [2018-10-24 21:25:50,309 INFO L131 ToolchainWalker]: Walking toolchain with 5 elements. [2018-10-24 21:25:50,310 INFO L113 PluginConnector]: ------------------------CACSL2BoogieTranslator---------------------------- [2018-10-24 21:25:50,311 INFO L271 PluginConnector]: Initializing CACSL2BoogieTranslator... [2018-10-24 21:25:50,315 INFO L276 PluginConnector]: CACSL2BoogieTranslator initialized [2018-10-24 21:25:50,316 INFO L185 PluginConnector]: Executing the observer ACSLObjectContainerObserver from plugin CACSL2BoogieTranslator for "CDTParser AST 24.10 09:25:50" (1/1) ... [2018-10-24 21:25:50,319 INFO L205 PluginConnector]: Invalid model from CACSL2BoogieTranslator for observer de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator.ACSLObjectContainerObserver@32327da6 and model type de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 24.10 09:25:50, skipping insertion in model container [2018-10-24 21:25:50,319 INFO L185 PluginConnector]: Executing the observer CACSL2BoogieTranslatorObserver from plugin CACSL2BoogieTranslator for "CDTParser AST 24.10 09:25:50" (1/1) ... [2018-10-24 21:25:50,331 INFO L145 MainTranslator]: Starting translation in SV-COMP mode [2018-10-24 21:25:50,497 INFO L174 MainTranslator]: Built tables and reachable declarations [2018-10-24 21:25:51,807 INFO L202 PostProcessor]: Analyzing one entry point: main [2018-10-24 21:25:51,812 INFO L189 MainTranslator]: Completed pre-run [2018-10-24 21:25:52,421 INFO L202 PostProcessor]: Analyzing one entry point: main [2018-10-24 21:25:52,455 INFO L193 MainTranslator]: Completed translation [2018-10-24 21:25:52,455 INFO L202 PluginConnector]: Adding new model de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 24.10 09:25:52 WrapperNode [2018-10-24 21:25:52,455 INFO L132 PluginConnector]: ------------------------ END CACSL2BoogieTranslator---------------------------- [2018-10-24 21:25:52,456 INFO L113 PluginConnector]: ------------------------Boogie Procedure Inliner---------------------------- [2018-10-24 21:25:52,457 INFO L271 PluginConnector]: Initializing Boogie Procedure Inliner... [2018-10-24 21:25:52,457 INFO L276 PluginConnector]: Boogie Procedure Inliner initialized [2018-10-24 21:25:52,467 INFO L185 PluginConnector]: Executing the observer TypeChecker from plugin Boogie Procedure Inliner for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 24.10 09:25:52" (1/1) ... [2018-10-24 21:25:52,534 INFO L185 PluginConnector]: Executing the observer Inliner from plugin Boogie Procedure Inliner for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 24.10 09:25:52" (1/1) ... [2018-10-24 21:25:53,011 INFO L132 PluginConnector]: ------------------------ END Boogie Procedure Inliner---------------------------- [2018-10-24 21:25:53,012 INFO L113 PluginConnector]: ------------------------Boogie Preprocessor---------------------------- [2018-10-24 21:25:53,012 INFO L271 PluginConnector]: Initializing Boogie Preprocessor... [2018-10-24 21:25:53,012 INFO L276 PluginConnector]: Boogie Preprocessor initialized [2018-10-24 21:25:53,025 INFO L185 PluginConnector]: Executing the observer EnsureBoogieModelObserver from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 24.10 09:25:52" (1/1) ... [2018-10-24 21:25:53,025 INFO L185 PluginConnector]: Executing the observer TypeChecker from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 24.10 09:25:52" (1/1) ... [2018-10-24 21:25:53,053 INFO L185 PluginConnector]: Executing the observer ConstExpander from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 24.10 09:25:52" (1/1) ... [2018-10-24 21:25:53,053 INFO L185 PluginConnector]: Executing the observer StructExpander from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 24.10 09:25:52" (1/1) ... [2018-10-24 21:25:53,164 INFO L185 PluginConnector]: Executing the observer UnstructureCode from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 24.10 09:25:52" (1/1) ... [2018-10-24 21:25:53,209 INFO L185 PluginConnector]: Executing the observer FunctionInliner from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 24.10 09:25:52" (1/1) ... [2018-10-24 21:25:53,242 INFO L185 PluginConnector]: Executing the observer BoogieSymbolTableConstructor from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 24.10 09:25:52" (1/1) ... [2018-10-24 21:25:53,274 INFO L132 PluginConnector]: ------------------------ END Boogie Preprocessor---------------------------- [2018-10-24 21:25:53,275 INFO L113 PluginConnector]: ------------------------RCFGBuilder---------------------------- [2018-10-24 21:25:53,275 INFO L271 PluginConnector]: Initializing RCFGBuilder... [2018-10-24 21:25:53,276 INFO L276 PluginConnector]: RCFGBuilder initialized [2018-10-24 21:25:53,277 INFO L185 PluginConnector]: Executing the observer RCFGBuilderObserver from plugin RCFGBuilder for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 24.10 09:25:52" (1/1) ... No working directory specified, using /storage/repos/ultimate/releaseScripts/default/UTaipan-linux/z3 Starting monitored process 1 with z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in -t:2000 (exit command is (exit), workingDir is null) Waiting until toolchain timeout for monitored process 1 with z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in -t:2000 [2018-10-24 21:25:53,351 INFO L130 BoogieDeclarations]: Found specification of procedure ULTIMATE.init [2018-10-24 21:25:53,351 INFO L138 BoogieDeclarations]: Found implementation of procedure ULTIMATE.init [2018-10-24 21:25:53,352 INFO L130 BoogieDeclarations]: Found specification of procedure calculate_output4 [2018-10-24 21:25:53,352 INFO L138 BoogieDeclarations]: Found implementation of procedure calculate_output4 [2018-10-24 21:25:53,352 INFO L130 BoogieDeclarations]: Found specification of procedure calculate_output3 [2018-10-24 21:25:53,352 INFO L138 BoogieDeclarations]: Found implementation of procedure calculate_output3 [2018-10-24 21:25:53,352 INFO L130 BoogieDeclarations]: Found specification of procedure calculate_output2 [2018-10-24 21:25:53,353 INFO L138 BoogieDeclarations]: Found implementation of procedure calculate_output2 [2018-10-24 21:25:53,353 INFO L130 BoogieDeclarations]: Found specification of procedure calculate_output [2018-10-24 21:25:53,353 INFO L138 BoogieDeclarations]: Found implementation of procedure calculate_output [2018-10-24 21:25:53,353 INFO L130 BoogieDeclarations]: Found specification of procedure ULTIMATE.start [2018-10-24 21:25:53,353 INFO L138 BoogieDeclarations]: Found implementation of procedure ULTIMATE.start [2018-10-24 21:25:53,354 INFO L130 BoogieDeclarations]: Found specification of procedure main [2018-10-24 21:25:53,355 INFO L138 BoogieDeclarations]: Found implementation of procedure main [2018-10-24 21:26:03,840 INFO L341 CfgBuilder]: Using the 1 location(s) as analysis (start of procedure ULTIMATE.start) [2018-10-24 21:26:03,841 INFO L202 PluginConnector]: Adding new model de.uni_freiburg.informatik.ultimate.plugins.generator.rcfgbuilder CFG 24.10 09:26:03 BoogieIcfgContainer [2018-10-24 21:26:03,841 INFO L132 PluginConnector]: ------------------------ END RCFGBuilder---------------------------- [2018-10-24 21:26:03,842 INFO L113 PluginConnector]: ------------------------TraceAbstraction---------------------------- [2018-10-24 21:26:03,842 INFO L271 PluginConnector]: Initializing TraceAbstraction... [2018-10-24 21:26:03,851 INFO L276 PluginConnector]: TraceAbstraction initialized [2018-10-24 21:26:03,851 INFO L185 PluginConnector]: Executing the observer TraceAbstractionObserver from plugin TraceAbstraction for "CDTParser AST 24.10 09:25:50" (1/3) ... [2018-10-24 21:26:03,852 INFO L205 PluginConnector]: Invalid model from TraceAbstraction for observer de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction.TraceAbstractionObserver@6a46a3b3 and model type de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction AST 24.10 09:26:03, skipping insertion in model container [2018-10-24 21:26:03,852 INFO L185 PluginConnector]: Executing the observer TraceAbstractionObserver from plugin TraceAbstraction for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 24.10 09:25:52" (2/3) ... [2018-10-24 21:26:03,853 INFO L205 PluginConnector]: Invalid model from TraceAbstraction for observer de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction.TraceAbstractionObserver@6a46a3b3 and model type de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction AST 24.10 09:26:03, skipping insertion in model container [2018-10-24 21:26:03,853 INFO L185 PluginConnector]: Executing the observer TraceAbstractionObserver from plugin TraceAbstraction for "de.uni_freiburg.informatik.ultimate.plugins.generator.rcfgbuilder CFG 24.10 09:26:03" (3/3) ... [2018-10-24 21:26:03,855 INFO L112 eAbstractionObserver]: Analyzing ICFG Problem12_label56_true-unreach-call.c [2018-10-24 21:26:03,979 INFO L136 ceAbstractionStarter]: Automizer settings: Hoare:true NWA Interpolation:FPandBP Determinization: PREDICATE_ABSTRACTION [2018-10-24 21:26:03,997 INFO L148 ceAbstractionStarter]: Appying trace abstraction to program that has 1 error locations. [2018-10-24 21:26:04,015 INFO L257 AbstractCegarLoop]: Starting to check reachability of 1 error locations. [2018-10-24 21:26:04,077 INFO L382 AbstractCegarLoop]: Interprodecural is true [2018-10-24 21:26:04,077 INFO L383 AbstractCegarLoop]: Hoare is true [2018-10-24 21:26:04,078 INFO L384 AbstractCegarLoop]: Compute interpolants for FPandBP [2018-10-24 21:26:04,078 INFO L385 AbstractCegarLoop]: Backedges is STRAIGHT_LINE [2018-10-24 21:26:04,078 INFO L386 AbstractCegarLoop]: Determinization is PREDICATE_ABSTRACTION [2018-10-24 21:26:04,078 INFO L387 AbstractCegarLoop]: Difference is false [2018-10-24 21:26:04,078 INFO L388 AbstractCegarLoop]: Minimize is MINIMIZE_SEVPA [2018-10-24 21:26:04,078 INFO L393 AbstractCegarLoop]: ======== Iteration 0==of CEGAR loop == AllErrorsAtOnce======== [2018-10-24 21:26:04,137 INFO L276 IsEmpty]: Start isEmpty. Operand 840 states. [2018-10-24 21:26:04,149 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 64 [2018-10-24 21:26:04,149 INFO L367 BasicCegarLoop]: Found error trace [2018-10-24 21:26:04,151 INFO L375 BasicCegarLoop]: trace histogram [1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2018-10-24 21:26:04,154 INFO L424 AbstractCegarLoop]: === Iteration 1 === [calculate_outputErr0ASSERT_VIOLATIONERROR_FUNCTION]=== [2018-10-24 21:26:04,162 INFO L141 PredicateUnifier]: Initialized classic predicate unifier [2018-10-24 21:26:04,162 INFO L82 PathProgramCache]: Analyzing trace with hash 1384793435, now seen corresponding path program 1 times [2018-10-24 21:26:04,165 INFO L69 tionRefinementEngine]: Using refinement strategy TaipanRefinementStrategy [2018-10-24 21:26:04,222 INFO L119 rtionOrderModulation]: Craig_TreeInterpolation forces the order to NOT_INCREMENTALLY [2018-10-24 21:26:04,222 INFO L103 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2018-10-24 21:26:04,222 INFO L119 rtionOrderModulation]: Craig_TreeInterpolation forces the order to NOT_INCREMENTALLY [2018-10-24 21:26:04,222 INFO L288 anRefinementStrategy]: Using traceCheck mode SMTINTERPOL with AssertCodeBlockOrder NOT_INCREMENTALLY (IT: Craig_TreeInterpolation) [2018-10-24 21:26:04,357 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2018-10-24 21:26:04,728 WARN L179 SmtUtils]: Spent 132.00 ms on a formula simplification. DAG size of input: 11 DAG size of output: 4 [2018-10-24 21:26:04,833 INFO L134 CoverageAnalysis]: Checked inductivity of 0 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2018-10-24 21:26:04,836 INFO L312 seRefinementStrategy]: Constructing automaton from 1 perfect and 0 imperfect interpolant sequences. [2018-10-24 21:26:04,836 INFO L327 seRefinementStrategy]: Number of different interpolants: perfect sequences [3] imperfect sequences [] total 3 [2018-10-24 21:26:04,837 INFO L258 anRefinementStrategy]: Using the first perfect interpolant sequence [2018-10-24 21:26:04,843 INFO L460 AbstractCegarLoop]: Interpolant automaton has 3 states [2018-10-24 21:26:04,860 INFO L142 InterpolantAutomaton]: Constructing interpolant automaton starting with 3 interpolants. [2018-10-24 21:26:04,860 INFO L144 InterpolantAutomaton]: CoverageRelationStatistics Valid=3, Invalid=3, Unknown=0, NotChecked=0, Total=6 [2018-10-24 21:26:04,863 INFO L87 Difference]: Start difference. First operand 840 states. Second operand 3 states. [2018-10-24 21:26:15,254 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2018-10-24 21:26:15,254 INFO L93 Difference]: Finished difference Result 2446 states and 4700 transitions. [2018-10-24 21:26:15,255 INFO L142 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 3 states. [2018-10-24 21:26:15,257 INFO L78 Accepts]: Start accepts. Automaton has 3 states. Word has length 63 [2018-10-24 21:26:15,258 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2018-10-24 21:26:15,305 INFO L225 Difference]: With dead ends: 2446 [2018-10-24 21:26:15,306 INFO L226 Difference]: Without dead ends: 1604 [2018-10-24 21:26:15,322 INFO L605 BasicCegarLoop]: 0 DeclaredPredicates, 5 GetRequests, 2 SyntacticMatches, 2 SemanticMatches, 1 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 0 ImplicationChecksByTransitivity, 0.2s TimeCoverageRelationStatistics Valid=3, Invalid=3, Unknown=0, NotChecked=0, Total=6 [2018-10-24 21:26:15,349 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 1604 states. [2018-10-24 21:26:15,497 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 1604 to 1604. [2018-10-24 21:26:15,498 INFO L82 GeneralOperation]: Start removeUnreachable. Operand 1604 states. [2018-10-24 21:26:15,510 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 1604 states to 1604 states and 2909 transitions. [2018-10-24 21:26:15,512 INFO L78 Accepts]: Start accepts. Automaton has 1604 states and 2909 transitions. Word has length 63 [2018-10-24 21:26:15,514 INFO L84 Accepts]: Finished accepts. word is rejected. [2018-10-24 21:26:15,514 INFO L481 AbstractCegarLoop]: Abstraction has 1604 states and 2909 transitions. [2018-10-24 21:26:15,514 INFO L482 AbstractCegarLoop]: Interpolant automaton has 3 states. [2018-10-24 21:26:15,515 INFO L276 IsEmpty]: Start isEmpty. Operand 1604 states and 2909 transitions. [2018-10-24 21:26:15,527 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 138 [2018-10-24 21:26:15,527 INFO L367 BasicCegarLoop]: Found error trace [2018-10-24 21:26:15,528 INFO L375 BasicCegarLoop]: trace histogram [2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2018-10-24 21:26:15,528 INFO L424 AbstractCegarLoop]: === Iteration 2 === [calculate_outputErr0ASSERT_VIOLATIONERROR_FUNCTION]=== [2018-10-24 21:26:15,528 INFO L141 PredicateUnifier]: Initialized classic predicate unifier [2018-10-24 21:26:15,529 INFO L82 PathProgramCache]: Analyzing trace with hash 1410076404, now seen corresponding path program 1 times [2018-10-24 21:26:15,529 INFO L69 tionRefinementEngine]: Using refinement strategy TaipanRefinementStrategy [2018-10-24 21:26:15,530 INFO L119 rtionOrderModulation]: Craig_TreeInterpolation forces the order to NOT_INCREMENTALLY [2018-10-24 21:26:15,530 INFO L103 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2018-10-24 21:26:15,531 INFO L119 rtionOrderModulation]: Craig_TreeInterpolation forces the order to NOT_INCREMENTALLY [2018-10-24 21:26:15,531 INFO L288 anRefinementStrategy]: Using traceCheck mode SMTINTERPOL with AssertCodeBlockOrder NOT_INCREMENTALLY (IT: Craig_TreeInterpolation) [2018-10-24 21:26:15,617 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2018-10-24 21:26:15,910 INFO L134 CoverageAnalysis]: Checked inductivity of 56 backedges. 56 proven. 0 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2018-10-24 21:26:15,911 INFO L312 seRefinementStrategy]: Constructing automaton from 1 perfect and 0 imperfect interpolant sequences. [2018-10-24 21:26:15,911 INFO L327 seRefinementStrategy]: Number of different interpolants: perfect sequences [5] imperfect sequences [] total 5 [2018-10-24 21:26:15,911 INFO L258 anRefinementStrategy]: Using the first perfect interpolant sequence [2018-10-24 21:26:15,914 INFO L460 AbstractCegarLoop]: Interpolant automaton has 5 states [2018-10-24 21:26:15,914 INFO L142 InterpolantAutomaton]: Constructing interpolant automaton starting with 5 interpolants. [2018-10-24 21:26:15,914 INFO L144 InterpolantAutomaton]: CoverageRelationStatistics Valid=7, Invalid=13, Unknown=0, NotChecked=0, Total=20 [2018-10-24 21:26:15,915 INFO L87 Difference]: Start difference. First operand 1604 states and 2909 transitions. Second operand 5 states. [2018-10-24 21:26:25,590 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2018-10-24 21:26:25,590 INFO L93 Difference]: Finished difference Result 4818 states and 8826 transitions. [2018-10-24 21:26:25,593 INFO L142 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 7 states. [2018-10-24 21:26:25,593 INFO L78 Accepts]: Start accepts. Automaton has 5 states. Word has length 137 [2018-10-24 21:26:25,594 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2018-10-24 21:26:25,619 INFO L225 Difference]: With dead ends: 4818 [2018-10-24 21:26:25,620 INFO L226 Difference]: Without dead ends: 3220 [2018-10-24 21:26:25,626 INFO L605 BasicCegarLoop]: 0 DeclaredPredicates, 9 GetRequests, 2 SyntacticMatches, 1 SemanticMatches, 6 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 3 ImplicationChecksByTransitivity, 0.1s TimeCoverageRelationStatistics Valid=19, Invalid=37, Unknown=0, NotChecked=0, Total=56 [2018-10-24 21:26:25,631 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 3220 states. [2018-10-24 21:26:25,735 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 3220 to 3186. [2018-10-24 21:26:25,735 INFO L82 GeneralOperation]: Start removeUnreachable. Operand 3186 states. [2018-10-24 21:26:25,749 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 3186 states to 3186 states and 5594 transitions. [2018-10-24 21:26:25,749 INFO L78 Accepts]: Start accepts. Automaton has 3186 states and 5594 transitions. Word has length 137 [2018-10-24 21:26:25,750 INFO L84 Accepts]: Finished accepts. word is rejected. [2018-10-24 21:26:25,750 INFO L481 AbstractCegarLoop]: Abstraction has 3186 states and 5594 transitions. [2018-10-24 21:26:25,750 INFO L482 AbstractCegarLoop]: Interpolant automaton has 5 states. [2018-10-24 21:26:25,750 INFO L276 IsEmpty]: Start isEmpty. Operand 3186 states and 5594 transitions. [2018-10-24 21:26:25,754 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 143 [2018-10-24 21:26:25,754 INFO L367 BasicCegarLoop]: Found error trace [2018-10-24 21:26:25,755 INFO L375 BasicCegarLoop]: trace histogram [2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2018-10-24 21:26:25,755 INFO L424 AbstractCegarLoop]: === Iteration 3 === [calculate_outputErr0ASSERT_VIOLATIONERROR_FUNCTION]=== [2018-10-24 21:26:25,755 INFO L141 PredicateUnifier]: Initialized classic predicate unifier [2018-10-24 21:26:25,756 INFO L82 PathProgramCache]: Analyzing trace with hash -284658707, now seen corresponding path program 1 times [2018-10-24 21:26:25,756 INFO L69 tionRefinementEngine]: Using refinement strategy TaipanRefinementStrategy [2018-10-24 21:26:25,757 INFO L119 rtionOrderModulation]: Craig_TreeInterpolation forces the order to NOT_INCREMENTALLY [2018-10-24 21:26:25,757 INFO L103 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2018-10-24 21:26:25,757 INFO L119 rtionOrderModulation]: Craig_TreeInterpolation forces the order to NOT_INCREMENTALLY [2018-10-24 21:26:25,757 INFO L288 anRefinementStrategy]: Using traceCheck mode SMTINTERPOL with AssertCodeBlockOrder NOT_INCREMENTALLY (IT: Craig_TreeInterpolation) [2018-10-24 21:26:25,784 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2018-10-24 21:26:25,994 INFO L134 CoverageAnalysis]: Checked inductivity of 56 backedges. 56 proven. 0 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2018-10-24 21:26:25,995 INFO L312 seRefinementStrategy]: Constructing automaton from 1 perfect and 0 imperfect interpolant sequences. [2018-10-24 21:26:25,995 INFO L327 seRefinementStrategy]: Number of different interpolants: perfect sequences [6] imperfect sequences [] total 6 [2018-10-24 21:26:25,995 INFO L258 anRefinementStrategy]: Using the first perfect interpolant sequence [2018-10-24 21:26:25,997 INFO L460 AbstractCegarLoop]: Interpolant automaton has 6 states [2018-10-24 21:26:25,997 INFO L142 InterpolantAutomaton]: Constructing interpolant automaton starting with 6 interpolants. [2018-10-24 21:26:25,997 INFO L144 InterpolantAutomaton]: CoverageRelationStatistics Valid=12, Invalid=18, Unknown=0, NotChecked=0, Total=30 [2018-10-24 21:26:25,998 INFO L87 Difference]: Start difference. First operand 3186 states and 5594 transitions. Second operand 6 states. [2018-10-24 21:26:40,706 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2018-10-24 21:26:40,706 INFO L93 Difference]: Finished difference Result 11148 states and 19850 transitions. [2018-10-24 21:26:40,708 INFO L142 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 7 states. [2018-10-24 21:26:40,708 INFO L78 Accepts]: Start accepts. Automaton has 6 states. Word has length 142 [2018-10-24 21:26:40,708 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2018-10-24 21:26:40,764 INFO L225 Difference]: With dead ends: 11148 [2018-10-24 21:26:40,765 INFO L226 Difference]: Without dead ends: 7968 [2018-10-24 21:26:40,781 INFO L605 BasicCegarLoop]: 0 DeclaredPredicates, 10 GetRequests, 2 SyntacticMatches, 1 SemanticMatches, 7 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 4 ImplicationChecksByTransitivity, 0.1s TimeCoverageRelationStatistics Valid=27, Invalid=45, Unknown=0, NotChecked=0, Total=72 [2018-10-24 21:26:40,788 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 7968 states. [2018-10-24 21:26:41,035 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 7968 to 7924. [2018-10-24 21:26:41,035 INFO L82 GeneralOperation]: Start removeUnreachable. Operand 7924 states. [2018-10-24 21:26:41,080 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 7924 states to 7924 states and 13424 transitions. [2018-10-24 21:26:41,081 INFO L78 Accepts]: Start accepts. Automaton has 7924 states and 13424 transitions. Word has length 142 [2018-10-24 21:26:41,081 INFO L84 Accepts]: Finished accepts. word is rejected. [2018-10-24 21:26:41,082 INFO L481 AbstractCegarLoop]: Abstraction has 7924 states and 13424 transitions. [2018-10-24 21:26:41,082 INFO L482 AbstractCegarLoop]: Interpolant automaton has 6 states. [2018-10-24 21:26:41,082 INFO L276 IsEmpty]: Start isEmpty. Operand 7924 states and 13424 transitions. [2018-10-24 21:26:41,086 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 151 [2018-10-24 21:26:41,086 INFO L367 BasicCegarLoop]: Found error trace [2018-10-24 21:26:41,089 INFO L375 BasicCegarLoop]: trace histogram [2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2018-10-24 21:26:41,090 INFO L424 AbstractCegarLoop]: === Iteration 4 === [calculate_outputErr0ASSERT_VIOLATIONERROR_FUNCTION]=== [2018-10-24 21:26:41,090 INFO L141 PredicateUnifier]: Initialized classic predicate unifier [2018-10-24 21:26:41,090 INFO L82 PathProgramCache]: Analyzing trace with hash -1120664195, now seen corresponding path program 1 times [2018-10-24 21:26:41,090 INFO L69 tionRefinementEngine]: Using refinement strategy TaipanRefinementStrategy [2018-10-24 21:26:41,091 INFO L119 rtionOrderModulation]: Craig_TreeInterpolation forces the order to NOT_INCREMENTALLY [2018-10-24 21:26:41,092 INFO L103 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2018-10-24 21:26:41,092 INFO L119 rtionOrderModulation]: Craig_TreeInterpolation forces the order to NOT_INCREMENTALLY [2018-10-24 21:26:41,092 INFO L288 anRefinementStrategy]: Using traceCheck mode SMTINTERPOL with AssertCodeBlockOrder NOT_INCREMENTALLY (IT: Craig_TreeInterpolation) [2018-10-24 21:26:41,147 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2018-10-24 21:26:41,409 WARN L179 SmtUtils]: Spent 165.00 ms on a formula simplification. DAG size of input: 11 DAG size of output: 4 [2018-10-24 21:26:41,783 INFO L134 CoverageAnalysis]: Checked inductivity of 56 backedges. 56 proven. 0 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2018-10-24 21:26:41,784 INFO L312 seRefinementStrategy]: Constructing automaton from 1 perfect and 0 imperfect interpolant sequences. [2018-10-24 21:26:41,784 INFO L327 seRefinementStrategy]: Number of different interpolants: perfect sequences [6] imperfect sequences [] total 6 [2018-10-24 21:26:41,784 INFO L258 anRefinementStrategy]: Using the first perfect interpolant sequence [2018-10-24 21:26:41,785 INFO L460 AbstractCegarLoop]: Interpolant automaton has 6 states [2018-10-24 21:26:41,785 INFO L142 InterpolantAutomaton]: Constructing interpolant automaton starting with 6 interpolants. [2018-10-24 21:26:41,786 INFO L144 InterpolantAutomaton]: CoverageRelationStatistics Valid=12, Invalid=18, Unknown=0, NotChecked=0, Total=30 [2018-10-24 21:26:41,786 INFO L87 Difference]: Start difference. First operand 7924 states and 13424 transitions. Second operand 6 states. [2018-10-24 21:26:51,799 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2018-10-24 21:26:51,799 INFO L93 Difference]: Finished difference Result 22224 states and 38004 transitions. [2018-10-24 21:26:51,799 INFO L142 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 7 states. [2018-10-24 21:26:51,800 INFO L78 Accepts]: Start accepts. Automaton has 6 states. Word has length 150 [2018-10-24 21:26:51,800 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2018-10-24 21:26:51,872 INFO L225 Difference]: With dead ends: 22224 [2018-10-24 21:26:51,873 INFO L226 Difference]: Without dead ends: 14306 [2018-10-24 21:26:51,917 INFO L605 BasicCegarLoop]: 0 DeclaredPredicates, 10 GetRequests, 2 SyntacticMatches, 1 SemanticMatches, 7 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 4 ImplicationChecksByTransitivity, 0.5s TimeCoverageRelationStatistics Valid=27, Invalid=45, Unknown=0, NotChecked=0, Total=72 [2018-10-24 21:26:51,931 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 14306 states. [2018-10-24 21:26:52,222 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 14306 to 14219. [2018-10-24 21:26:52,222 INFO L82 GeneralOperation]: Start removeUnreachable. Operand 14219 states. [2018-10-24 21:26:52,259 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 14219 states to 14219 states and 21550 transitions. [2018-10-24 21:26:52,260 INFO L78 Accepts]: Start accepts. Automaton has 14219 states and 21550 transitions. Word has length 150 [2018-10-24 21:26:52,260 INFO L84 Accepts]: Finished accepts. word is rejected. [2018-10-24 21:26:52,261 INFO L481 AbstractCegarLoop]: Abstraction has 14219 states and 21550 transitions. [2018-10-24 21:26:52,261 INFO L482 AbstractCegarLoop]: Interpolant automaton has 6 states. [2018-10-24 21:26:52,261 INFO L276 IsEmpty]: Start isEmpty. Operand 14219 states and 21550 transitions. [2018-10-24 21:26:52,267 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 168 [2018-10-24 21:26:52,267 INFO L367 BasicCegarLoop]: Found error trace [2018-10-24 21:26:52,267 INFO L375 BasicCegarLoop]: trace histogram [2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2018-10-24 21:26:52,268 INFO L424 AbstractCegarLoop]: === Iteration 5 === [calculate_outputErr0ASSERT_VIOLATIONERROR_FUNCTION]=== [2018-10-24 21:26:52,268 INFO L141 PredicateUnifier]: Initialized classic predicate unifier [2018-10-24 21:26:52,268 INFO L82 PathProgramCache]: Analyzing trace with hash 1804914960, now seen corresponding path program 1 times [2018-10-24 21:26:52,268 INFO L69 tionRefinementEngine]: Using refinement strategy TaipanRefinementStrategy [2018-10-24 21:26:52,269 INFO L119 rtionOrderModulation]: Craig_TreeInterpolation forces the order to NOT_INCREMENTALLY [2018-10-24 21:26:52,269 INFO L103 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2018-10-24 21:26:52,269 INFO L119 rtionOrderModulation]: Craig_TreeInterpolation forces the order to NOT_INCREMENTALLY [2018-10-24 21:26:52,270 INFO L288 anRefinementStrategy]: Using traceCheck mode SMTINTERPOL with AssertCodeBlockOrder NOT_INCREMENTALLY (IT: Craig_TreeInterpolation) [2018-10-24 21:26:52,293 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2018-10-24 21:26:52,725 INFO L134 CoverageAnalysis]: Checked inductivity of 56 backedges. 56 proven. 0 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2018-10-24 21:26:52,725 INFO L312 seRefinementStrategy]: Constructing automaton from 1 perfect and 0 imperfect interpolant sequences. [2018-10-24 21:26:52,725 INFO L327 seRefinementStrategy]: Number of different interpolants: perfect sequences [6] imperfect sequences [] total 6 [2018-10-24 21:26:52,725 INFO L258 anRefinementStrategy]: Using the first perfect interpolant sequence [2018-10-24 21:26:52,726 INFO L460 AbstractCegarLoop]: Interpolant automaton has 6 states [2018-10-24 21:26:52,726 INFO L142 InterpolantAutomaton]: Constructing interpolant automaton starting with 6 interpolants. [2018-10-24 21:26:52,727 INFO L144 InterpolantAutomaton]: CoverageRelationStatistics Valid=11, Invalid=19, Unknown=0, NotChecked=0, Total=30 [2018-10-24 21:26:52,727 INFO L87 Difference]: Start difference. First operand 14219 states and 21550 transitions. Second operand 6 states. [2018-10-24 21:27:12,858 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2018-10-24 21:27:12,859 INFO L93 Difference]: Finished difference Result 56461 states and 95988 transitions. [2018-10-24 21:27:12,860 INFO L142 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 10 states. [2018-10-24 21:27:12,860 INFO L78 Accepts]: Start accepts. Automaton has 6 states. Word has length 167 [2018-10-24 21:27:12,860 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2018-10-24 21:27:13,130 INFO L225 Difference]: With dead ends: 56461 [2018-10-24 21:27:13,130 INFO L226 Difference]: Without dead ends: 42248 [2018-10-24 21:27:13,272 INFO L605 BasicCegarLoop]: 0 DeclaredPredicates, 11 GetRequests, 3 SyntacticMatches, 0 SemanticMatches, 8 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 7 ImplicationChecksByTransitivity, 0.3s TimeCoverageRelationStatistics Valid=32, Invalid=58, Unknown=0, NotChecked=0, Total=90 [2018-10-24 21:27:13,319 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 42248 states. [2018-10-24 21:27:14,481 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 42248 to 42003. [2018-10-24 21:27:14,481 INFO L82 GeneralOperation]: Start removeUnreachable. Operand 42003 states. [2018-10-24 21:27:15,113 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 42003 states to 42003 states and 62980 transitions. [2018-10-24 21:27:15,114 INFO L78 Accepts]: Start accepts. Automaton has 42003 states and 62980 transitions. Word has length 167 [2018-10-24 21:27:15,115 INFO L84 Accepts]: Finished accepts. word is rejected. [2018-10-24 21:27:15,115 INFO L481 AbstractCegarLoop]: Abstraction has 42003 states and 62980 transitions. [2018-10-24 21:27:15,115 INFO L482 AbstractCegarLoop]: Interpolant automaton has 6 states. [2018-10-24 21:27:15,115 INFO L276 IsEmpty]: Start isEmpty. Operand 42003 states and 62980 transitions. [2018-10-24 21:27:15,125 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 189 [2018-10-24 21:27:15,125 INFO L367 BasicCegarLoop]: Found error trace [2018-10-24 21:27:15,126 INFO L375 BasicCegarLoop]: trace histogram [2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2018-10-24 21:27:15,126 INFO L424 AbstractCegarLoop]: === Iteration 6 === [calculate_outputErr0ASSERT_VIOLATIONERROR_FUNCTION]=== [2018-10-24 21:27:15,127 INFO L141 PredicateUnifier]: Initialized classic predicate unifier [2018-10-24 21:27:15,128 INFO L82 PathProgramCache]: Analyzing trace with hash -1097653015, now seen corresponding path program 1 times [2018-10-24 21:27:15,128 INFO L69 tionRefinementEngine]: Using refinement strategy TaipanRefinementStrategy [2018-10-24 21:27:15,129 INFO L119 rtionOrderModulation]: Craig_TreeInterpolation forces the order to NOT_INCREMENTALLY [2018-10-24 21:27:15,129 INFO L103 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2018-10-24 21:27:15,129 INFO L119 rtionOrderModulation]: Craig_TreeInterpolation forces the order to NOT_INCREMENTALLY [2018-10-24 21:27:15,129 INFO L288 anRefinementStrategy]: Using traceCheck mode SMTINTERPOL with AssertCodeBlockOrder NOT_INCREMENTALLY (IT: Craig_TreeInterpolation) [2018-10-24 21:27:15,168 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2018-10-24 21:27:15,420 WARN L179 SmtUtils]: Spent 138.00 ms on a formula simplification. DAG size of input: 11 DAG size of output: 4 [2018-10-24 21:27:15,839 INFO L134 CoverageAnalysis]: Checked inductivity of 56 backedges. 56 proven. 0 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2018-10-24 21:27:15,839 INFO L312 seRefinementStrategy]: Constructing automaton from 1 perfect and 0 imperfect interpolant sequences. [2018-10-24 21:27:15,840 INFO L327 seRefinementStrategy]: Number of different interpolants: perfect sequences [6] imperfect sequences [] total 6 [2018-10-24 21:27:15,840 INFO L258 anRefinementStrategy]: Using the first perfect interpolant sequence [2018-10-24 21:27:15,840 INFO L460 AbstractCegarLoop]: Interpolant automaton has 6 states [2018-10-24 21:27:15,841 INFO L142 InterpolantAutomaton]: Constructing interpolant automaton starting with 6 interpolants. [2018-10-24 21:27:15,842 INFO L144 InterpolantAutomaton]: CoverageRelationStatistics Valid=12, Invalid=18, Unknown=0, NotChecked=0, Total=30 [2018-10-24 21:27:15,843 INFO L87 Difference]: Start difference. First operand 42003 states and 62980 transitions. Second operand 6 states. [2018-10-24 21:27:27,210 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2018-10-24 21:27:27,211 INFO L93 Difference]: Finished difference Result 104615 states and 165884 transitions. [2018-10-24 21:27:27,214 INFO L142 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 7 states. [2018-10-24 21:27:27,214 INFO L78 Accepts]: Start accepts. Automaton has 6 states. Word has length 188 [2018-10-24 21:27:27,215 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2018-10-24 21:27:27,509 INFO L225 Difference]: With dead ends: 104615 [2018-10-24 21:27:27,510 INFO L226 Difference]: Without dead ends: 62618 [2018-10-24 21:27:27,678 INFO L605 BasicCegarLoop]: 0 DeclaredPredicates, 10 GetRequests, 2 SyntacticMatches, 1 SemanticMatches, 7 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 4 ImplicationChecksByTransitivity, 0.6s TimeCoverageRelationStatistics Valid=27, Invalid=45, Unknown=0, NotChecked=0, Total=72 [2018-10-24 21:27:27,735 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 62618 states. [2018-10-24 21:27:28,973 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 62618 to 62368. [2018-10-24 21:27:28,974 INFO L82 GeneralOperation]: Start removeUnreachable. Operand 62368 states. [2018-10-24 21:27:29,182 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 62368 states to 62368 states and 87762 transitions. [2018-10-24 21:27:29,183 INFO L78 Accepts]: Start accepts. Automaton has 62368 states and 87762 transitions. Word has length 188 [2018-10-24 21:27:29,184 INFO L84 Accepts]: Finished accepts. word is rejected. [2018-10-24 21:27:29,184 INFO L481 AbstractCegarLoop]: Abstraction has 62368 states and 87762 transitions. [2018-10-24 21:27:29,184 INFO L482 AbstractCegarLoop]: Interpolant automaton has 6 states. [2018-10-24 21:27:29,184 INFO L276 IsEmpty]: Start isEmpty. Operand 62368 states and 87762 transitions. [2018-10-24 21:27:29,200 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 223 [2018-10-24 21:27:29,200 INFO L367 BasicCegarLoop]: Found error trace [2018-10-24 21:27:29,201 INFO L375 BasicCegarLoop]: trace histogram [3, 3, 3, 3, 3, 3, 3, 3, 3, 3, 3, 3, 3, 3, 3, 3, 3, 3, 3, 3, 3, 3, 3, 3, 3, 3, 3, 3, 3, 3, 3, 3, 3, 3, 3, 3, 3, 3, 3, 3, 3, 3, 3, 3, 3, 3, 3, 3, 3, 3, 3, 3, 3, 3, 3, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2018-10-24 21:27:29,201 INFO L424 AbstractCegarLoop]: === Iteration 7 === [calculate_outputErr0ASSERT_VIOLATIONERROR_FUNCTION]=== [2018-10-24 21:27:29,201 INFO L141 PredicateUnifier]: Initialized classic predicate unifier [2018-10-24 21:27:29,202 INFO L82 PathProgramCache]: Analyzing trace with hash 960313160, now seen corresponding path program 1 times [2018-10-24 21:27:29,202 INFO L69 tionRefinementEngine]: Using refinement strategy TaipanRefinementStrategy [2018-10-24 21:27:29,203 INFO L119 rtionOrderModulation]: Craig_TreeInterpolation forces the order to NOT_INCREMENTALLY [2018-10-24 21:27:29,203 INFO L103 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2018-10-24 21:27:29,203 INFO L119 rtionOrderModulation]: Craig_TreeInterpolation forces the order to NOT_INCREMENTALLY [2018-10-24 21:27:29,203 INFO L288 anRefinementStrategy]: Using traceCheck mode SMTINTERPOL with AssertCodeBlockOrder NOT_INCREMENTALLY (IT: Craig_TreeInterpolation) [2018-10-24 21:27:29,228 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2018-10-24 21:27:29,574 INFO L134 CoverageAnalysis]: Checked inductivity of 191 backedges. 112 proven. 74 refuted. 0 times theorem prover too weak. 5 trivial. 0 not checked. [2018-10-24 21:27:29,575 INFO L300 seRefinementStrategy]: The current sequences of interpolants are not accepted, trying to find more. [2018-10-24 21:27:29,575 INFO L194 anRefinementStrategy]: Switched to InterpolantGenerator mode ABSTRACT_INTERPRETATION [2018-10-24 21:27:29,576 INFO L200 CegarAbsIntRunner]: Running AI on error trace of length 223 with the following transitions: [2018-10-24 21:27:29,580 INFO L202 CegarAbsIntRunner]: [0], [1], [1868], [1875], [1883], [1891], [1899], [1907], [1915], [1923], [1931], [1939], [1947], [1955], [1963], [1971], [1979], [1987], [1995], [2003], [2011], [2019], [2027], [2035], [2043], [2051], [2059], [2067], [2075], [2083], [2091], [2099], [2107], [2115], [2123], [2131], [2139], [2147], [2155], [2163], [2171], [2179], [2187], [2195], [2203], [2211], [2219], [2227], [2235], [2243], [2251], [2259], [2267], [2271], [2273], [2276], [2284], [2292], [2300], [2308], [2316], [2324], [2332], [2340], [2348], [2356], [2361], [2365], [2369], [2373], [2377], [2381], [2385], [2389], [2393], [2396], [2397], [2400], [3240], [3244], [3248], [3254], [3258], [3260], [3271], [3272], [3273], [3275], [3276] [2018-10-24 21:27:29,697 INFO L148 AbstractInterpreter]: Using domain PoormanAbstractDomain with backing domain CompoundDomain [CongruenceDomain, OctagonDomain] [2018-10-24 21:27:29,698 INFO L101 FixpointEngine]: Starting fixpoint engine with domain PoormanAbstractDomain (maxUnwinding=3, maxParallelStates=2) [2018-10-24 21:27:32,702 WARN L79 EvaluatorLogger]: Possible loss of precision. Operator ARITHMOD has no precise implementation. [2018-10-24 21:27:32,939 INFO L266 AbstractInterpreter]: Error location(s) were unreachable [2018-10-24 21:27:32,941 INFO L272 AbstractInterpreter]: Visited 85 different actions 85 times. Never merged. Never widened. Never found a fixpoint. Largest state had 26 variables. [2018-10-24 21:27:32,974 INFO L141 PredicateUnifier]: Initialized classic predicate unifier [2018-10-24 21:27:32,975 INFO L398 sIntCurrentIteration]: Generating AbsInt predicates [2018-10-24 21:27:35,322 INFO L232 lantSequenceWeakener]: Weakened 214 states. On average, predicates are now at 75.91% of their original sizes. [2018-10-24 21:27:35,322 INFO L411 sIntCurrentIteration]: Unifying AI predicates [2018-10-24 21:27:35,972 INFO L413 sIntCurrentIteration]: We have 221 unified AI predicates [2018-10-24 21:27:35,973 INFO L422 sIntCurrentIteration]: Finished generation of AbsInt predicates [2018-10-24 21:27:35,974 INFO L312 seRefinementStrategy]: Constructing automaton from 1 perfect and 1 imperfect interpolant sequences. [2018-10-24 21:27:35,974 INFO L327 seRefinementStrategy]: Number of different interpolants: perfect sequences [8] imperfect sequences [5] total 11 [2018-10-24 21:27:35,974 INFO L258 anRefinementStrategy]: Using the first perfect interpolant sequence [2018-10-24 21:27:35,975 INFO L460 AbstractCegarLoop]: Interpolant automaton has 8 states [2018-10-24 21:27:35,975 INFO L142 InterpolantAutomaton]: Constructing interpolant automaton starting with 8 interpolants. [2018-10-24 21:27:35,975 INFO L144 InterpolantAutomaton]: CoverageRelationStatistics Valid=20, Invalid=36, Unknown=0, NotChecked=0, Total=56 [2018-10-24 21:27:35,976 INFO L87 Difference]: Start difference. First operand 62368 states and 87762 transitions. Second operand 8 states. Received shutdown request... [2018-10-24 21:29:30,361 INFO L142 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 8 states. [2018-10-24 21:29:30,361 WARN L550 AbstractCegarLoop]: Verification canceled [2018-10-24 21:29:30,366 WARN L205 ceAbstractionStarter]: Timeout [2018-10-24 21:29:30,367 INFO L202 PluginConnector]: Adding new model de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction CFG 24.10 09:29:30 BoogieIcfgContainer [2018-10-24 21:29:30,367 INFO L132 PluginConnector]: ------------------------ END TraceAbstraction---------------------------- [2018-10-24 21:29:30,368 INFO L168 Benchmark]: Toolchain (without parser) took 220059.63 ms. Allocated memory was 1.5 GB in the beginning and 4.2 GB in the end (delta: 2.6 GB). Free memory was 1.4 GB in the beginning and 3.2 GB in the end (delta: -1.8 GB). Peak memory consumption was 833.1 MB. Max. memory is 7.1 GB. [2018-10-24 21:29:30,369 INFO L168 Benchmark]: CDTParser took 0.20 ms. Allocated memory is still 1.5 GB. Free memory is still 1.5 GB. There was no memory consumed. Max. memory is 7.1 GB. [2018-10-24 21:29:30,370 INFO L168 Benchmark]: CACSL2BoogieTranslator took 2145.61 ms. Allocated memory is still 1.5 GB. Free memory was 1.4 GB in the beginning and 1.2 GB in the end (delta: 200.8 MB). Peak memory consumption was 200.8 MB. Max. memory is 7.1 GB. [2018-10-24 21:29:30,370 INFO L168 Benchmark]: Boogie Procedure Inliner took 555.35 ms. Allocated memory was 1.5 GB in the beginning and 2.4 GB in the end (delta: 833.6 MB). Free memory was 1.2 GB in the beginning and 2.3 GB in the end (delta: -1.1 GB). Peak memory consumption was 58.3 MB. Max. memory is 7.1 GB. [2018-10-24 21:29:30,371 INFO L168 Benchmark]: Boogie Preprocessor took 262.68 ms. Allocated memory is still 2.4 GB. Free memory was 2.3 GB in the beginning and 2.3 GB in the end (delta: 37.0 MB). Peak memory consumption was 37.0 MB. Max. memory is 7.1 GB. [2018-10-24 21:29:30,372 INFO L168 Benchmark]: RCFGBuilder took 10565.96 ms. Allocated memory is still 2.4 GB. Free memory was 2.3 GB in the beginning and 1.6 GB in the end (delta: 649.4 MB). Peak memory consumption was 649.4 MB. Max. memory is 7.1 GB. [2018-10-24 21:29:30,373 INFO L168 Benchmark]: TraceAbstraction took 206524.76 ms. Allocated memory was 2.4 GB in the beginning and 4.2 GB in the end (delta: 1.8 GB). Free memory was 1.6 GB in the beginning and 3.2 GB in the end (delta: -1.6 GB). Peak memory consumption was 186.3 MB. Max. memory is 7.1 GB. [2018-10-24 21:29:30,378 INFO L336 ainManager$Toolchain]: ####################### End [Toolchain 1] ####################### --- Results --- * Results from de.uni_freiburg.informatik.ultimate.core: - StatisticsResult: Toolchain Benchmarks Benchmark results are: * CDTParser took 0.20 ms. Allocated memory is still 1.5 GB. Free memory is still 1.5 GB. There was no memory consumed. Max. memory is 7.1 GB. * CACSL2BoogieTranslator took 2145.61 ms. Allocated memory is still 1.5 GB. Free memory was 1.4 GB in the beginning and 1.2 GB in the end (delta: 200.8 MB). Peak memory consumption was 200.8 MB. Max. memory is 7.1 GB. * Boogie Procedure Inliner took 555.35 ms. Allocated memory was 1.5 GB in the beginning and 2.4 GB in the end (delta: 833.6 MB). Free memory was 1.2 GB in the beginning and 2.3 GB in the end (delta: -1.1 GB). Peak memory consumption was 58.3 MB. Max. memory is 7.1 GB. * Boogie Preprocessor took 262.68 ms. Allocated memory is still 2.4 GB. Free memory was 2.3 GB in the beginning and 2.3 GB in the end (delta: 37.0 MB). Peak memory consumption was 37.0 MB. Max. memory is 7.1 GB. * RCFGBuilder took 10565.96 ms. Allocated memory is still 2.4 GB. Free memory was 2.3 GB in the beginning and 1.6 GB in the end (delta: 649.4 MB). Peak memory consumption was 649.4 MB. Max. memory is 7.1 GB. * TraceAbstraction took 206524.76 ms. Allocated memory was 2.4 GB in the beginning and 4.2 GB in the end (delta: 1.8 GB). Free memory was 1.6 GB in the beginning and 3.2 GB in the end (delta: -1.6 GB). Peak memory consumption was 186.3 MB. Max. memory is 7.1 GB. * Results from de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction: - TimeoutResultAtElement [Line: 180]: Timeout (TraceAbstraction) Unable to prove that call of __VERIFIER_error() unreachable (line 180). Cancelled while BasicCegarLoop was constructing difference of abstraction (62368states) and FLOYD_HOARE automaton (currently 8 states, 8 states before enhancement),while ReachableStatesComputation was computing reachable states (35482 states constructedinput type IntersectNwa). - StatisticsResult: Ultimate Automizer benchmark data CFG has 7 procedures, 840 locations, 1 error locations. TIMEOUT Result, 206.3s OverallTime, 7 OverallIterations, 3 TraceHistogramMax, 191.8s AutomataDifference, 0.0s DeadEndRemovalTime, 0.0s HoareAnnotationTime, HoareTripleCheckerStatistics: 1329 SDtfs, 19916 SDslu, 1167 SDs, 0 SdLazy, 36363 SolverSat, 8416 SolverUnsat, 2 SolverUnknown, 0 SolverNotchecked, 149.2s Time, PredicateUnifierStatistics: 2 DeclaredPredicates, 278 GetRequests, 228 SyntacticMatches, 6 SemanticMatches, 44 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 27 ImplicationChecksByTransitivity, 2.7s Time, 0.0s BasicInterpolantAutomatonTime, BiggestAbstraction: size=62368occurred in iteration=6, traceCheckStatistics: No data available, InterpolantConsolidationStatistics: No data available, PathInvariantsStatistics: No data available, 0/0 InterpolantCoveringCapability, TotalInterpolationStatistics: No data available, 3.3s AbstIntTime, 1 AbstIntIterations, 1 AbstIntStrong, 0.9956143404107204 AbsIntWeakeningRatio, 0.12217194570135746 AbsIntAvgWeakeningVarsNumRemoved, 1047.4570135746606 AbsIntAvgWeakenedConjuncts, 0.0s DumpTime, AutomataMinimizationStatistics: 4.2s AutomataMinimizationTime, 6 MinimizatonAttempts, 660 StatesRemovedByMinimization, 5 NontrivialMinimizations, HoareAnnotationStatistics: No data available, RefinementEngineStatistics: TraceCheckStatistics: 0.0s SsaConstructionTime, 0.2s SatisfiabilityAnalysisTime, 2.7s InterpolantComputationTime, 1069 NumberOfCodeBlocks, 1069 NumberOfCodeBlocksAsserted, 7 NumberOfCheckSat, 1062 ConstructedInterpolants, 0 QuantifiedInterpolants, 697454 SizeOfPredicates, 0 NumberOfNonLiveVariables, 0 ConjunctsInSsa, 0 ConjunctsInUnsatCore, 7 InterpolantComputations, 6 PerfectInterpolantSequences, 397/471 InterpolantCoveringCapability, InvariantSynthesisStatistics: No data available, InterpolantConsolidationStatistics: No data available, ReuseStatistics: No data available RESULT: Ultimate could not prove your program: Timeout Completed graceful shutdown