./Ultimate.py --spec ../sv-benchmarks/c/properties/unreach-call.prp --file ../sv-benchmarks/c/product-lines/minepump_spec1_product11.cil.c --full-output -ea --architecture 32bit -------------------------------------------------------------------------------- Checking for ERROR reachability Using default analysis Version 03d7b7b3 Calling Ultimate with: /usr/bin/java -Dosgi.configuration.area=/storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/data/config -Xmx15G -Xms4m -ea -jar /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/plugins/org.eclipse.equinox.launcher_1.5.800.v20200727-1323.jar -data @noDefault -ultimatedata /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/data -tc /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/config/AutomizerReach.xml -i ../sv-benchmarks/c/product-lines/minepump_spec1_product11.cil.c -s /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/config/svcomp-Reach-32bit-Automizer_Default.epf --cacsl2boogietranslator.entry.function main --witnessprinter.witness.directory /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux --witnessprinter.witness.filename witness.graphml --witnessprinter.write.witness.besides.input.file false --witnessprinter.graph.data.specification CHECK( init(main()), LTL(G ! call(reach_error())) ) --witnessprinter.graph.data.producer Automizer --witnessprinter.graph.data.architecture 32bit --witnessprinter.graph.data.programhash 9f744cc9100fe4c41c9cd8fddc1d55538ad14922708f8374e740fa1a934b47f6 --- Real Ultimate output --- This is Ultimate 0.2.2-dev-03d7b7b [2022-02-20 18:05:47,014 INFO L177 SettingsManager]: Resetting all preferences to default values... [2022-02-20 18:05:47,016 INFO L181 SettingsManager]: Resetting UltimateCore preferences to default values [2022-02-20 18:05:47,058 INFO L184 SettingsManager]: Ultimate Commandline Interface provides no preferences, ignoring... [2022-02-20 18:05:47,058 INFO L181 SettingsManager]: Resetting Boogie Preprocessor preferences to default values [2022-02-20 18:05:47,061 INFO L181 SettingsManager]: Resetting Boogie Procedure Inliner preferences to default values [2022-02-20 18:05:47,061 INFO L181 SettingsManager]: Resetting Abstract Interpretation preferences to default values [2022-02-20 18:05:47,064 INFO L181 SettingsManager]: Resetting LassoRanker preferences to default values [2022-02-20 18:05:47,065 INFO L181 SettingsManager]: Resetting Reaching Definitions preferences to default values [2022-02-20 18:05:47,069 INFO L181 SettingsManager]: Resetting SyntaxChecker preferences to default values [2022-02-20 18:05:47,069 INFO L181 SettingsManager]: Resetting Sifa preferences to default values [2022-02-20 18:05:47,070 INFO L184 SettingsManager]: Büchi Program Product provides no preferences, ignoring... [2022-02-20 18:05:47,071 INFO L181 SettingsManager]: Resetting LTL2Aut preferences to default values [2022-02-20 18:05:47,072 INFO L181 SettingsManager]: Resetting PEA to Boogie preferences to default values [2022-02-20 18:05:47,073 INFO L181 SettingsManager]: Resetting BlockEncodingV2 preferences to default values [2022-02-20 18:05:47,076 INFO L181 SettingsManager]: Resetting ChcToBoogie preferences to default values [2022-02-20 18:05:47,077 INFO L181 SettingsManager]: Resetting AutomataScriptInterpreter preferences to default values [2022-02-20 18:05:47,077 INFO L181 SettingsManager]: Resetting BuchiAutomizer preferences to default values [2022-02-20 18:05:47,079 INFO L181 SettingsManager]: Resetting CACSL2BoogieTranslator preferences to default values [2022-02-20 18:05:47,083 INFO L181 SettingsManager]: Resetting CodeCheck preferences to default values [2022-02-20 18:05:47,084 INFO L181 SettingsManager]: Resetting InvariantSynthesis preferences to default values [2022-02-20 18:05:47,084 INFO L181 SettingsManager]: Resetting RCFGBuilder preferences to default values [2022-02-20 18:05:47,086 INFO L181 SettingsManager]: Resetting Referee preferences to default values [2022-02-20 18:05:47,086 INFO L181 SettingsManager]: Resetting TraceAbstraction preferences to default values [2022-02-20 18:05:47,091 INFO L184 SettingsManager]: TraceAbstractionConcurrent provides no preferences, ignoring... [2022-02-20 18:05:47,092 INFO L184 SettingsManager]: TraceAbstractionWithAFAs provides no preferences, ignoring... [2022-02-20 18:05:47,092 INFO L181 SettingsManager]: Resetting TreeAutomizer preferences to default values [2022-02-20 18:05:47,093 INFO L181 SettingsManager]: Resetting IcfgToChc preferences to default values [2022-02-20 18:05:47,094 INFO L181 SettingsManager]: Resetting IcfgTransformer preferences to default values [2022-02-20 18:05:47,094 INFO L184 SettingsManager]: ReqToTest provides no preferences, ignoring... [2022-02-20 18:05:47,095 INFO L181 SettingsManager]: Resetting Boogie Printer preferences to default values [2022-02-20 18:05:47,095 INFO L181 SettingsManager]: Resetting ChcSmtPrinter preferences to default values [2022-02-20 18:05:47,097 INFO L181 SettingsManager]: Resetting ReqPrinter preferences to default values [2022-02-20 18:05:47,097 INFO L181 SettingsManager]: Resetting Witness Printer preferences to default values [2022-02-20 18:05:47,098 INFO L184 SettingsManager]: Boogie PL CUP Parser provides no preferences, ignoring... [2022-02-20 18:05:47,098 INFO L181 SettingsManager]: Resetting CDTParser preferences to default values [2022-02-20 18:05:47,099 INFO L184 SettingsManager]: AutomataScriptParser provides no preferences, ignoring... [2022-02-20 18:05:47,099 INFO L184 SettingsManager]: ReqParser provides no preferences, ignoring... [2022-02-20 18:05:47,099 INFO L181 SettingsManager]: Resetting SmtParser preferences to default values [2022-02-20 18:05:47,101 INFO L181 SettingsManager]: Resetting Witness Parser preferences to default values [2022-02-20 18:05:47,101 INFO L188 SettingsManager]: Finished resetting all preferences to default values... [2022-02-20 18:05:47,102 INFO L101 SettingsManager]: Beginning loading settings from /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/config/svcomp-Reach-32bit-Automizer_Default.epf [2022-02-20 18:05:47,128 INFO L113 SettingsManager]: Loading preferences was successful [2022-02-20 18:05:47,128 INFO L115 SettingsManager]: Preferences different from defaults after loading the file: [2022-02-20 18:05:47,129 INFO L136 SettingsManager]: Preferences of UltimateCore differ from their defaults: [2022-02-20 18:05:47,129 INFO L138 SettingsManager]: * Log level for class=de.uni_freiburg.informatik.ultimate.lib.smtlibutils.quantifier.QuantifierPusher=ERROR; [2022-02-20 18:05:47,130 INFO L136 SettingsManager]: Preferences of Boogie Procedure Inliner differ from their defaults: [2022-02-20 18:05:47,130 INFO L138 SettingsManager]: * Ignore calls to procedures called more than once=ONLY_FOR_SEQUENTIAL_PROGRAMS [2022-02-20 18:05:47,130 INFO L136 SettingsManager]: Preferences of BlockEncodingV2 differ from their defaults: [2022-02-20 18:05:47,130 INFO L138 SettingsManager]: * Create parallel compositions if possible=false [2022-02-20 18:05:47,130 INFO L138 SettingsManager]: * Use SBE=true [2022-02-20 18:05:47,131 INFO L136 SettingsManager]: Preferences of CACSL2BoogieTranslator differ from their defaults: [2022-02-20 18:05:47,131 INFO L138 SettingsManager]: * sizeof long=4 [2022-02-20 18:05:47,132 INFO L138 SettingsManager]: * Overapproximate operations on floating types=true [2022-02-20 18:05:47,132 INFO L138 SettingsManager]: * sizeof POINTER=4 [2022-02-20 18:05:47,132 INFO L138 SettingsManager]: * Check division by zero=IGNORE [2022-02-20 18:05:47,132 INFO L138 SettingsManager]: * Pointer to allocated memory at dereference=IGNORE [2022-02-20 18:05:47,132 INFO L138 SettingsManager]: * If two pointers are subtracted or compared they have the same base address=IGNORE [2022-02-20 18:05:47,132 INFO L138 SettingsManager]: * Check array bounds for arrays that are off heap=IGNORE [2022-02-20 18:05:47,132 INFO L138 SettingsManager]: * sizeof long double=12 [2022-02-20 18:05:47,133 INFO L138 SettingsManager]: * Check if freed pointer was valid=false [2022-02-20 18:05:47,133 INFO L138 SettingsManager]: * Use constant arrays=true [2022-02-20 18:05:47,133 INFO L138 SettingsManager]: * Pointer base address is valid at dereference=IGNORE [2022-02-20 18:05:47,133 INFO L136 SettingsManager]: Preferences of RCFGBuilder differ from their defaults: [2022-02-20 18:05:47,133 INFO L138 SettingsManager]: * Size of a code block=SequenceOfStatements [2022-02-20 18:05:47,133 INFO L138 SettingsManager]: * SMT solver=External_DefaultMode [2022-02-20 18:05:47,133 INFO L138 SettingsManager]: * Command for external solver=z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in -t:2000 [2022-02-20 18:05:47,134 INFO L136 SettingsManager]: Preferences of TraceAbstraction differ from their defaults: [2022-02-20 18:05:47,134 INFO L138 SettingsManager]: * Compute Interpolants along a Counterexample=FPandBP [2022-02-20 18:05:47,134 INFO L138 SettingsManager]: * Positions where we compute the Hoare Annotation=LoopsAndPotentialCycles [2022-02-20 18:05:47,134 INFO L138 SettingsManager]: * Trace refinement strategy=CAMEL [2022-02-20 18:05:47,134 INFO L138 SettingsManager]: * Command for external solver=z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in [2022-02-20 18:05:47,134 INFO L138 SettingsManager]: * Large block encoding in concurrent analysis=OFF [2022-02-20 18:05:47,135 INFO L138 SettingsManager]: * Automaton type used in concurrency analysis=PETRI_NET [2022-02-20 18:05:47,135 INFO L138 SettingsManager]: * Compute Hoare Annotation of negated interpolant automaton, abstraction and CFG=true [2022-02-20 18:05:47,135 INFO L138 SettingsManager]: * SMT solver=External_ModelsAndUnsatCoreMode WARNING: An illegal reflective access operation has occurred WARNING: Illegal reflective access by com.sun.xml.bind.v2.runtime.reflect.opt.Injector$1 (file:/storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/plugins/com.sun.xml.bind_2.2.0.v201505121915.jar) to method java.lang.ClassLoader.defineClass(java.lang.String,byte[],int,int) WARNING: Please consider reporting this to the maintainers of com.sun.xml.bind.v2.runtime.reflect.opt.Injector$1 WARNING: Use --illegal-access=warn to enable warnings of further illegal reflective access operations WARNING: All illegal access operations will be denied in a future release Applying setting for plugin de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator: Entry function -> main Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Witness directory -> /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Witness filename -> witness.graphml Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Write witness besides input file -> false Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Graph data specification -> CHECK( init(main()), LTL(G ! call(reach_error())) ) Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Graph data producer -> Automizer Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Graph data architecture -> 32bit Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Graph data programhash -> 9f744cc9100fe4c41c9cd8fddc1d55538ad14922708f8374e740fa1a934b47f6 [2022-02-20 18:05:47,375 INFO L75 nceAwareModelManager]: Repository-Root is: /tmp [2022-02-20 18:05:47,394 INFO L261 ainManager$Toolchain]: [Toolchain 1]: Applicable parser(s) successfully (re)initialized [2022-02-20 18:05:47,396 INFO L217 ainManager$Toolchain]: [Toolchain 1]: Toolchain selected. [2022-02-20 18:05:47,397 INFO L271 PluginConnector]: Initializing CDTParser... [2022-02-20 18:05:47,398 INFO L275 PluginConnector]: CDTParser initialized [2022-02-20 18:05:47,399 INFO L432 ainManager$Toolchain]: [Toolchain 1]: Parsing single file: /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/../sv-benchmarks/c/product-lines/minepump_spec1_product11.cil.c [2022-02-20 18:05:47,483 INFO L220 CDTParser]: Created temporary CDT project at /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/data/43a2ba98c/ee09eb47a6c8472bb0a8c86e274a0114/FLAGd02bea800 [2022-02-20 18:05:47,891 INFO L306 CDTParser]: Found 1 translation units. [2022-02-20 18:05:47,892 INFO L160 CDTParser]: Scanning /storage/repos/ultimate/releaseScripts/default/sv-benchmarks/c/product-lines/minepump_spec1_product11.cil.c [2022-02-20 18:05:47,903 INFO L349 CDTParser]: About to delete temporary CDT project at /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/data/43a2ba98c/ee09eb47a6c8472bb0a8c86e274a0114/FLAGd02bea800 [2022-02-20 18:05:48,286 INFO L357 CDTParser]: Successfully deleted /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/data/43a2ba98c/ee09eb47a6c8472bb0a8c86e274a0114 [2022-02-20 18:05:48,288 INFO L299 ainManager$Toolchain]: ####################### [Toolchain 1] ####################### [2022-02-20 18:05:48,289 INFO L131 ToolchainWalker]: Walking toolchain with 6 elements. [2022-02-20 18:05:48,290 INFO L113 PluginConnector]: ------------------------CACSL2BoogieTranslator---------------------------- [2022-02-20 18:05:48,291 INFO L271 PluginConnector]: Initializing CACSL2BoogieTranslator... [2022-02-20 18:05:48,296 INFO L275 PluginConnector]: CACSL2BoogieTranslator initialized [2022-02-20 18:05:48,297 INFO L185 PluginConnector]: Executing the observer ACSLObjectContainerObserver from plugin CACSL2BoogieTranslator for "CDTParser AST 20.02 06:05:48" (1/1) ... [2022-02-20 18:05:48,298 INFO L205 PluginConnector]: Invalid model from CACSL2BoogieTranslator for observer de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator.ACSLObjectContainerObserver@48c490f and model type de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 20.02 06:05:48, skipping insertion in model container [2022-02-20 18:05:48,298 INFO L185 PluginConnector]: Executing the observer CACSL2BoogieTranslatorObserver from plugin CACSL2BoogieTranslator for "CDTParser AST 20.02 06:05:48" (1/1) ... [2022-02-20 18:05:48,303 INFO L145 MainTranslator]: Starting translation in SV-COMP mode [2022-02-20 18:05:48,353 INFO L178 MainTranslator]: Built tables and reachable declarations [2022-02-20 18:05:48,574 WARN L230 ndardFunctionHandler]: Function reach_error is already implemented but we override the implementation for the call at /storage/repos/ultimate/releaseScripts/default/sv-benchmarks/c/product-lines/minepump_spec1_product11.cil.c[6038,6051] [2022-02-20 18:05:48,647 INFO L210 PostProcessor]: Analyzing one entry point: main [2022-02-20 18:05:48,663 INFO L203 MainTranslator]: Completed pre-run [2022-02-20 18:05:48,694 WARN L230 ndardFunctionHandler]: Function reach_error is already implemented but we override the implementation for the call at /storage/repos/ultimate/releaseScripts/default/sv-benchmarks/c/product-lines/minepump_spec1_product11.cil.c[6038,6051] [2022-02-20 18:05:48,747 INFO L210 PostProcessor]: Analyzing one entry point: main [2022-02-20 18:05:48,759 INFO L208 MainTranslator]: Completed translation [2022-02-20 18:05:48,759 INFO L202 PluginConnector]: Adding new model de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 20.02 06:05:48 WrapperNode [2022-02-20 18:05:48,759 INFO L132 PluginConnector]: ------------------------ END CACSL2BoogieTranslator---------------------------- [2022-02-20 18:05:48,765 INFO L113 PluginConnector]: ------------------------Boogie Procedure Inliner---------------------------- [2022-02-20 18:05:48,766 INFO L271 PluginConnector]: Initializing Boogie Procedure Inliner... [2022-02-20 18:05:48,766 INFO L275 PluginConnector]: Boogie Procedure Inliner initialized [2022-02-20 18:05:48,772 INFO L185 PluginConnector]: Executing the observer TypeChecker from plugin Boogie Procedure Inliner for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 20.02 06:05:48" (1/1) ... [2022-02-20 18:05:48,785 INFO L185 PluginConnector]: Executing the observer Inliner from plugin Boogie Procedure Inliner for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 20.02 06:05:48" (1/1) ... [2022-02-20 18:05:48,829 INFO L137 Inliner]: procedures = 51, calls = 148, calls flagged for inlining = 20, calls inlined = 15, statements flattened = 187 [2022-02-20 18:05:48,830 INFO L132 PluginConnector]: ------------------------ END Boogie Procedure Inliner---------------------------- [2022-02-20 18:05:48,830 INFO L113 PluginConnector]: ------------------------Boogie Preprocessor---------------------------- [2022-02-20 18:05:48,830 INFO L271 PluginConnector]: Initializing Boogie Preprocessor... [2022-02-20 18:05:48,831 INFO L275 PluginConnector]: Boogie Preprocessor initialized [2022-02-20 18:05:48,839 INFO L185 PluginConnector]: Executing the observer EnsureBoogieModelObserver from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 20.02 06:05:48" (1/1) ... [2022-02-20 18:05:48,840 INFO L185 PluginConnector]: Executing the observer TypeChecker from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 20.02 06:05:48" (1/1) ... [2022-02-20 18:05:48,850 INFO L185 PluginConnector]: Executing the observer ConstExpander from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 20.02 06:05:48" (1/1) ... [2022-02-20 18:05:48,853 INFO L185 PluginConnector]: Executing the observer StructExpander from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 20.02 06:05:48" (1/1) ... [2022-02-20 18:05:48,857 INFO L185 PluginConnector]: Executing the observer UnstructureCode from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 20.02 06:05:48" (1/1) ... [2022-02-20 18:05:48,871 INFO L185 PluginConnector]: Executing the observer FunctionInliner from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 20.02 06:05:48" (1/1) ... [2022-02-20 18:05:48,873 INFO L185 PluginConnector]: Executing the observer BoogieSymbolTableConstructor from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 20.02 06:05:48" (1/1) ... [2022-02-20 18:05:48,878 INFO L132 PluginConnector]: ------------------------ END Boogie Preprocessor---------------------------- [2022-02-20 18:05:48,879 INFO L113 PluginConnector]: ------------------------RCFGBuilder---------------------------- [2022-02-20 18:05:48,879 INFO L271 PluginConnector]: Initializing RCFGBuilder... [2022-02-20 18:05:48,879 INFO L275 PluginConnector]: RCFGBuilder initialized [2022-02-20 18:05:48,881 INFO L185 PluginConnector]: Executing the observer RCFGBuilderObserver from plugin RCFGBuilder for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 20.02 06:05:48" (1/1) ... [2022-02-20 18:05:48,885 INFO L173 SolverBuilder]: Constructing external solver with command: z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in -t:2000 [2022-02-20 18:05:48,893 INFO L189 MonitoredProcess]: No working directory specified, using /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 [2022-02-20 18:05:48,919 INFO L229 MonitoredProcess]: Starting monitored process 1 with /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in -t:2000 (exit command is (exit), workingDir is null) [2022-02-20 18:05:48,920 INFO L327 MonitoredProcess]: [MP /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in -t:2000 (1)] Waiting until timeout for monitored process [2022-02-20 18:05:48,945 INFO L130 BoogieDeclarations]: Found specification of procedure #Ultimate.allocInit [2022-02-20 18:05:48,945 INFO L130 BoogieDeclarations]: Found specification of procedure isMethaneLevelCritical [2022-02-20 18:05:48,945 INFO L138 BoogieDeclarations]: Found implementation of procedure isMethaneLevelCritical [2022-02-20 18:05:48,946 INFO L130 BoogieDeclarations]: Found specification of procedure timeShift [2022-02-20 18:05:48,946 INFO L138 BoogieDeclarations]: Found implementation of procedure timeShift [2022-02-20 18:05:48,946 INFO L130 BoogieDeclarations]: Found specification of procedure cleanup [2022-02-20 18:05:48,946 INFO L138 BoogieDeclarations]: Found implementation of procedure cleanup [2022-02-20 18:05:48,946 INFO L130 BoogieDeclarations]: Found specification of procedure waterRise [2022-02-20 18:05:48,946 INFO L138 BoogieDeclarations]: Found implementation of procedure waterRise [2022-02-20 18:05:48,946 INFO L130 BoogieDeclarations]: Found specification of procedure write~init~int [2022-02-20 18:05:48,946 INFO L130 BoogieDeclarations]: Found specification of procedure changeMethaneLevel [2022-02-20 18:05:48,946 INFO L138 BoogieDeclarations]: Found implementation of procedure changeMethaneLevel [2022-02-20 18:05:48,946 INFO L130 BoogieDeclarations]: Found specification of procedure ULTIMATE.start [2022-02-20 18:05:48,946 INFO L138 BoogieDeclarations]: Found implementation of procedure ULTIMATE.start [2022-02-20 18:05:49,007 INFO L234 CfgBuilder]: Building ICFG [2022-02-20 18:05:49,009 INFO L260 CfgBuilder]: Building CFG for each procedure with an implementation [2022-02-20 18:05:49,305 INFO L275 CfgBuilder]: Performing block encoding [2022-02-20 18:05:49,311 INFO L294 CfgBuilder]: Using the 1 location(s) as analysis (start of procedure ULTIMATE.start) [2022-02-20 18:05:49,311 INFO L299 CfgBuilder]: Removed 2 assume(true) statements. [2022-02-20 18:05:49,312 INFO L202 PluginConnector]: Adding new model de.uni_freiburg.informatik.ultimate.plugins.generator.rcfgbuilder CFG 20.02 06:05:49 BoogieIcfgContainer [2022-02-20 18:05:49,312 INFO L132 PluginConnector]: ------------------------ END RCFGBuilder---------------------------- [2022-02-20 18:05:49,314 INFO L113 PluginConnector]: ------------------------TraceAbstraction---------------------------- [2022-02-20 18:05:49,314 INFO L271 PluginConnector]: Initializing TraceAbstraction... [2022-02-20 18:05:49,316 INFO L275 PluginConnector]: TraceAbstraction initialized [2022-02-20 18:05:49,316 INFO L185 PluginConnector]: Executing the observer TraceAbstractionObserver from plugin TraceAbstraction for "CDTParser AST 20.02 06:05:48" (1/3) ... [2022-02-20 18:05:49,317 INFO L205 PluginConnector]: Invalid model from TraceAbstraction for observer de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction.TraceAbstractionObserver@1ae72eb7 and model type de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction AST 20.02 06:05:49, skipping insertion in model container [2022-02-20 18:05:49,317 INFO L185 PluginConnector]: Executing the observer TraceAbstractionObserver from plugin TraceAbstraction for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 20.02 06:05:48" (2/3) ... [2022-02-20 18:05:49,317 INFO L205 PluginConnector]: Invalid model from TraceAbstraction for observer de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction.TraceAbstractionObserver@1ae72eb7 and model type de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction AST 20.02 06:05:49, skipping insertion in model container [2022-02-20 18:05:49,317 INFO L185 PluginConnector]: Executing the observer TraceAbstractionObserver from plugin TraceAbstraction for "de.uni_freiburg.informatik.ultimate.plugins.generator.rcfgbuilder CFG 20.02 06:05:49" (3/3) ... [2022-02-20 18:05:49,318 INFO L111 eAbstractionObserver]: Analyzing ICFG minepump_spec1_product11.cil.c [2022-02-20 18:05:49,322 INFO L205 ceAbstractionStarter]: Automizer settings: Hoare:true NWA Interpolation:FPandBP Determinization: PREDICATE_ABSTRACTION [2022-02-20 18:05:49,322 INFO L164 ceAbstractionStarter]: Applying trace abstraction to program that has 1 error locations. [2022-02-20 18:05:49,357 INFO L338 AbstractCegarLoop]: ======== Iteration 0 == of CEGAR loop == AllErrorsAtOnce ======== [2022-02-20 18:05:49,362 INFO L339 AbstractCegarLoop]: Settings: SEPARATE_VIOLATION_CHECK=true, mInterprocedural=true, mMaxIterations=1000000, mWatchIteration=1000000, mArtifact=RCFG, mInterpolation=FPandBP, mInterpolantAutomaton=STRAIGHT_LINE, mDumpAutomata=false, mAutomataFormat=ATS_NUMERATE, mDumpPath=., mDeterminiation=PREDICATE_ABSTRACTION, mMinimize=MINIMIZE_SEVPA, mHoare=true, mAutomataTypeConcurrency=PETRI_NET, mHoareTripleChecks=INCREMENTAL, mHoareAnnotationPositions=LoopsAndPotentialCycles, mDumpOnlyReuseAutomata=false, mLimitTraceHistogram=0, mErrorLocTimeLimit=0, mLimitPathProgramCount=0, mCollectInterpolantStatistics=true, mHeuristicEmptinessCheck=false, mHeuristicEmptinessCheckAStarHeuristic=ZERO, mHeuristicEmptinessCheckAStarHeuristicRandomSeed=1337, mHeuristicEmptinessCheckSmtFeatureScoringMethod=DAGSIZE, mSMTFeatureExtraction=false, mSMTFeatureExtractionDumpPath=., mOverrideInterpolantAutomaton=false, mMcrInterpolantMethod=WP, mLoopAccelerationTechnique=FAST_UPR [2022-02-20 18:05:49,363 INFO L340 AbstractCegarLoop]: Starting to check reachability of 1 error locations. [2022-02-20 18:05:49,378 INFO L276 IsEmpty]: Start isEmpty. Operand has 66 states, 52 states have (on average 1.3846153846153846) internal successors, (72), 56 states have internal predecessors, (72), 7 states have call successors, (7), 5 states have call predecessors, (7), 5 states have return successors, (7), 7 states have call predecessors, (7), 7 states have call successors, (7) [2022-02-20 18:05:49,383 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 24 [2022-02-20 18:05:49,383 INFO L506 BasicCegarLoop]: Found error trace [2022-02-20 18:05:49,384 INFO L514 BasicCegarLoop]: trace histogram [1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-02-20 18:05:49,384 INFO L402 AbstractCegarLoop]: === Iteration 1 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2022-02-20 18:05:49,389 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2022-02-20 18:05:49,390 INFO L85 PathProgramCache]: Analyzing trace with hash 1989818001, now seen corresponding path program 1 times [2022-02-20 18:05:49,398 INFO L126 FreeRefinementEngine]: Executing refinement strategy CAMEL [2022-02-20 18:05:49,398 INFO L338 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [756659748] [2022-02-20 18:05:49,399 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-02-20 18:05:49,400 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2022-02-20 18:05:49,509 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-02-20 18:05:49,580 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 14 [2022-02-20 18:05:49,585 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-02-20 18:05:49,600 INFO L290 TraceCheckUtils]: 0: Hoare triple {69#true} havoc ~retValue_acc~5;~retValue_acc~5 := ~methaneLevelCritical~0;#res := ~retValue_acc~5; {69#true} is VALID [2022-02-20 18:05:49,601 INFO L290 TraceCheckUtils]: 1: Hoare triple {69#true} assume true; {69#true} is VALID [2022-02-20 18:05:49,601 INFO L284 TraceCheckUtils]: 2: Hoare quadruple {69#true} {70#false} #175#return; {70#false} is VALID [2022-02-20 18:05:49,603 INFO L290 TraceCheckUtils]: 0: Hoare triple {69#true} assume { :begin_inline_ULTIMATE.init } true;#NULL.base, #NULL.offset := 0, 0;assume 0 == #valid[0];assume 0 < #StackHeapBarrier;call #Ultimate.allocInit(2, 1);call write~init~int(48, 1, 0, 1);call write~init~int(0, 1, 1, 1);call #Ultimate.allocInit(31, 2);call #Ultimate.allocInit(12, 3);call #Ultimate.allocInit(13, 4);call #Ultimate.allocInit(3, 5);call write~init~int(79, 5, 0, 1);call write~init~int(110, 5, 1, 1);call write~init~int(0, 5, 2, 1);call #Ultimate.allocInit(4, 6);call write~init~int(79, 6, 0, 1);call write~init~int(102, 6, 1, 1);call write~init~int(102, 6, 2, 1);call write~init~int(0, 6, 3, 1);call #Ultimate.allocInit(7, 7);call write~init~int(44, 7, 0, 1);call write~init~int(80, 7, 1, 1);call write~init~int(117, 7, 2, 1);call write~init~int(109, 7, 3, 1);call write~init~int(112, 7, 4, 1);call write~init~int(58, 7, 5, 1);call write~init~int(0, 7, 6, 1);call #Ultimate.allocInit(3, 8);call write~init~int(79, 8, 0, 1);call write~init~int(110, 8, 1, 1);call write~init~int(0, 8, 2, 1);call #Ultimate.allocInit(4, 9);call write~init~int(79, 9, 0, 1);call write~init~int(102, 9, 1, 1);call write~init~int(102, 9, 2, 1);call write~init~int(0, 9, 3, 1);call #Ultimate.allocInit(3, 10);call write~init~int(41, 10, 0, 1);call write~init~int(32, 10, 1, 1);call write~init~int(0, 10, 2, 1);call #Ultimate.allocInit(2, 11);call write~init~int(10, 11, 0, 1);call write~init~int(0, 11, 1, 1);call #Ultimate.allocInit(13, 12);call #Ultimate.allocInit(7, 13);call write~init~int(44, 13, 0, 1);call write~init~int(77, 13, 1, 1);call write~init~int(101, 13, 2, 1);call write~init~int(116, 13, 3, 1);call write~init~int(104, 13, 4, 1);call write~init~int(58, 13, 5, 1);call write~init~int(0, 13, 6, 1);call #Ultimate.allocInit(5, 14);call write~init~int(67, 14, 0, 1);call write~init~int(82, 14, 1, 1);call write~init~int(73, 14, 2, 1);call write~init~int(84, 14, 3, 1);call write~init~int(0, 14, 4, 1);call #Ultimate.allocInit(3, 15);call write~init~int(79, 15, 0, 1);call write~init~int(75, 15, 1, 1);call write~init~int(0, 15, 2, 1);call #Ultimate.allocInit(2, 16);call write~init~int(41, 16, 0, 1);call write~init~int(0, 16, 1, 1);call #Ultimate.allocInit(30, 17);call #Ultimate.allocInit(9, 18);call #Ultimate.allocInit(21, 19);call #Ultimate.allocInit(30, 20);call #Ultimate.allocInit(9, 21);call #Ultimate.allocInit(21, 22);call #Ultimate.allocInit(30, 23);call #Ultimate.allocInit(9, 24);call #Ultimate.allocInit(25, 25);call #Ultimate.allocInit(30, 26);call #Ultimate.allocInit(9, 27);call #Ultimate.allocInit(25, 28);~cleanupTimeShifts~0 := 4;~pumpRunning~0 := 0;~systemActive~0 := 1;~waterLevel~0 := 1;~methaneLevelCritical~0 := 0;~head~0.base, ~head~0.offset := 0, 0; {69#true} is VALID [2022-02-20 18:05:49,603 INFO L290 TraceCheckUtils]: 1: Hoare triple {69#true} assume { :end_inline_ULTIMATE.init } true;assume { :begin_inline_main } true;havoc main_#res#1;havoc main_#t~ret4#1, main_~retValue_acc~0#1, main_~tmp~0#1;havoc main_~retValue_acc~0#1;havoc main_~tmp~0#1;assume { :begin_inline_select_helpers } true; {69#true} is VALID [2022-02-20 18:05:49,603 INFO L290 TraceCheckUtils]: 2: Hoare triple {69#true} assume { :end_inline_select_helpers } true;assume { :begin_inline_select_features } true; {69#true} is VALID [2022-02-20 18:05:49,603 INFO L290 TraceCheckUtils]: 3: Hoare triple {69#true} assume { :end_inline_select_features } true;assume { :begin_inline_valid_product } true;havoc valid_product_#res#1;havoc valid_product_~retValue_acc~2#1;havoc valid_product_~retValue_acc~2#1;valid_product_~retValue_acc~2#1 := 1;valid_product_#res#1 := valid_product_~retValue_acc~2#1; {69#true} is VALID [2022-02-20 18:05:49,604 INFO L290 TraceCheckUtils]: 4: Hoare triple {69#true} main_#t~ret4#1 := valid_product_#res#1;assume { :end_inline_valid_product } true;assume -2147483648 <= main_#t~ret4#1 && main_#t~ret4#1 <= 2147483647;main_~tmp~0#1 := main_#t~ret4#1;havoc main_#t~ret4#1; {69#true} is VALID [2022-02-20 18:05:49,604 INFO L290 TraceCheckUtils]: 5: Hoare triple {69#true} assume 0 != main_~tmp~0#1;assume { :begin_inline_setup } true; {69#true} is VALID [2022-02-20 18:05:49,604 INFO L290 TraceCheckUtils]: 6: Hoare triple {69#true} assume { :end_inline_setup } true;assume { :begin_inline_runTest } true;assume { :begin_inline_test } true;havoc test_#t~nondet16#1, test_#t~nondet17#1, test_#t~nondet18#1, test_#t~nondet19#1, test_~splverifierCounter~0#1, test_~tmp~2#1, test_~tmp___0~0#1, test_~tmp___1~0#1, test_~tmp___2~0#1;havoc test_~splverifierCounter~0#1;havoc test_~tmp~2#1;havoc test_~tmp___0~0#1;havoc test_~tmp___1~0#1;havoc test_~tmp___2~0#1;test_~splverifierCounter~0#1 := 0; {69#true} is VALID [2022-02-20 18:05:49,605 INFO L290 TraceCheckUtils]: 7: Hoare triple {69#true} assume false; {70#false} is VALID [2022-02-20 18:05:49,605 INFO L272 TraceCheckUtils]: 8: Hoare triple {70#false} call cleanup(); {70#false} is VALID [2022-02-20 18:05:49,605 INFO L290 TraceCheckUtils]: 9: Hoare triple {70#false} havoc ~i~0;havoc ~__cil_tmp2~0; {70#false} is VALID [2022-02-20 18:05:49,606 INFO L272 TraceCheckUtils]: 10: Hoare triple {70#false} call timeShift(); {70#false} is VALID [2022-02-20 18:05:49,606 INFO L290 TraceCheckUtils]: 11: Hoare triple {70#false} assume !(0 != ~pumpRunning~0); {70#false} is VALID [2022-02-20 18:05:49,606 INFO L290 TraceCheckUtils]: 12: Hoare triple {70#false} assume !(0 != ~systemActive~0); {70#false} is VALID [2022-02-20 18:05:49,606 INFO L290 TraceCheckUtils]: 13: Hoare triple {70#false} assume { :begin_inline___utac_acc__Specification1_spec__1 } true;havoc __utac_acc__Specification1_spec__1_#t~ret25#1, __utac_acc__Specification1_spec__1_#t~ret26#1, __utac_acc__Specification1_spec__1_~tmp~3#1, __utac_acc__Specification1_spec__1_~tmp___0~1#1;havoc __utac_acc__Specification1_spec__1_~tmp~3#1;havoc __utac_acc__Specification1_spec__1_~tmp___0~1#1; {70#false} is VALID [2022-02-20 18:05:49,606 INFO L272 TraceCheckUtils]: 14: Hoare triple {70#false} call __utac_acc__Specification1_spec__1_#t~ret25#1 := isMethaneLevelCritical(); {69#true} is VALID [2022-02-20 18:05:49,607 INFO L290 TraceCheckUtils]: 15: Hoare triple {69#true} havoc ~retValue_acc~5;~retValue_acc~5 := ~methaneLevelCritical~0;#res := ~retValue_acc~5; {69#true} is VALID [2022-02-20 18:05:49,607 INFO L290 TraceCheckUtils]: 16: Hoare triple {69#true} assume true; {69#true} is VALID [2022-02-20 18:05:49,608 INFO L284 TraceCheckUtils]: 17: Hoare quadruple {69#true} {70#false} #175#return; {70#false} is VALID [2022-02-20 18:05:49,609 INFO L290 TraceCheckUtils]: 18: Hoare triple {70#false} assume -2147483648 <= __utac_acc__Specification1_spec__1_#t~ret25#1 && __utac_acc__Specification1_spec__1_#t~ret25#1 <= 2147483647;__utac_acc__Specification1_spec__1_~tmp~3#1 := __utac_acc__Specification1_spec__1_#t~ret25#1;havoc __utac_acc__Specification1_spec__1_#t~ret25#1; {70#false} is VALID [2022-02-20 18:05:49,609 INFO L290 TraceCheckUtils]: 19: Hoare triple {70#false} assume 0 != __utac_acc__Specification1_spec__1_~tmp~3#1;assume { :begin_inline_isPumpRunning } true;havoc isPumpRunning_#res#1;havoc isPumpRunning_~retValue_acc~4#1;havoc isPumpRunning_~retValue_acc~4#1;isPumpRunning_~retValue_acc~4#1 := ~pumpRunning~0;isPumpRunning_#res#1 := isPumpRunning_~retValue_acc~4#1; {70#false} is VALID [2022-02-20 18:05:49,609 INFO L290 TraceCheckUtils]: 20: Hoare triple {70#false} __utac_acc__Specification1_spec__1_#t~ret26#1 := isPumpRunning_#res#1;assume { :end_inline_isPumpRunning } true;assume -2147483648 <= __utac_acc__Specification1_spec__1_#t~ret26#1 && __utac_acc__Specification1_spec__1_#t~ret26#1 <= 2147483647;__utac_acc__Specification1_spec__1_~tmp___0~1#1 := __utac_acc__Specification1_spec__1_#t~ret26#1;havoc __utac_acc__Specification1_spec__1_#t~ret26#1; {70#false} is VALID [2022-02-20 18:05:49,609 INFO L290 TraceCheckUtils]: 21: Hoare triple {70#false} assume 0 != __utac_acc__Specification1_spec__1_~tmp___0~1#1;assume { :begin_inline___automaton_fail } true; {70#false} is VALID [2022-02-20 18:05:49,609 INFO L290 TraceCheckUtils]: 22: Hoare triple {70#false} assume !false; {70#false} is VALID [2022-02-20 18:05:49,610 INFO L134 CoverageAnalysis]: Checked inductivity of 0 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2022-02-20 18:05:49,610 INFO L144 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2022-02-20 18:05:49,610 INFO L338 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [756659748] [2022-02-20 18:05:49,611 INFO L165 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [756659748] provided 1 perfect and 0 imperfect interpolant sequences [2022-02-20 18:05:49,611 INFO L191 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2022-02-20 18:05:49,611 INFO L204 FreeRefinementEngine]: Number of different interpolants: perfect sequences [2] imperfect sequences [] total 2 [2022-02-20 18:05:49,612 INFO L118 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [488774709] [2022-02-20 18:05:49,613 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2022-02-20 18:05:49,617 INFO L78 Accepts]: Start accepts. Automaton has has 2 states, 2 states have (on average 9.5) internal successors, (19), 2 states have internal predecessors, (19), 1 states have call successors, (3), 2 states have call predecessors, (3), 1 states have return successors, (1), 1 states have call predecessors, (1), 1 states have call successors, (1) Word has length 23 [2022-02-20 18:05:49,619 INFO L84 Accepts]: Finished accepts. word is accepted. [2022-02-20 18:05:49,622 INFO L86 InductivityCheck]: Starting indutivity check of a Floyd-Hoare automaton with has 2 states, 2 states have (on average 9.5) internal successors, (19), 2 states have internal predecessors, (19), 1 states have call successors, (3), 2 states have call predecessors, (3), 1 states have return successors, (1), 1 states have call predecessors, (1), 1 states have call successors, (1) [2022-02-20 18:05:49,658 INFO L122 InductivityCheck]: Floyd-Hoare automaton has 23 edges. 23 inductive. 0 not inductive. 0 times theorem prover too weak to decide inductivity. [2022-02-20 18:05:49,658 INFO L546 AbstractCegarLoop]: INTERPOLANT automaton has 2 states [2022-02-20 18:05:49,658 INFO L108 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2022-02-20 18:05:49,683 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 2 interpolants. [2022-02-20 18:05:49,685 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=1, Invalid=1, Unknown=0, NotChecked=0, Total=2 [2022-02-20 18:05:49,687 INFO L87 Difference]: Start difference. First operand has 66 states, 52 states have (on average 1.3846153846153846) internal successors, (72), 56 states have internal predecessors, (72), 7 states have call successors, (7), 5 states have call predecessors, (7), 5 states have return successors, (7), 7 states have call predecessors, (7), 7 states have call successors, (7) Second operand has 2 states, 2 states have (on average 9.5) internal successors, (19), 2 states have internal predecessors, (19), 1 states have call successors, (3), 2 states have call predecessors, (3), 1 states have return successors, (1), 1 states have call predecessors, (1), 1 states have call successors, (1) [2022-02-20 18:05:49,793 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-02-20 18:05:49,794 INFO L93 Difference]: Finished difference Result 124 states and 167 transitions. [2022-02-20 18:05:49,794 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 2 states. [2022-02-20 18:05:49,794 INFO L78 Accepts]: Start accepts. Automaton has has 2 states, 2 states have (on average 9.5) internal successors, (19), 2 states have internal predecessors, (19), 1 states have call successors, (3), 2 states have call predecessors, (3), 1 states have return successors, (1), 1 states have call predecessors, (1), 1 states have call successors, (1) Word has length 23 [2022-02-20 18:05:49,795 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2022-02-20 18:05:49,796 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 2 states, 2 states have (on average 9.5) internal successors, (19), 2 states have internal predecessors, (19), 1 states have call successors, (3), 2 states have call predecessors, (3), 1 states have return successors, (1), 1 states have call predecessors, (1), 1 states have call successors, (1) [2022-02-20 18:05:49,810 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 2 states to 2 states and 167 transitions. [2022-02-20 18:05:49,810 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 2 states, 2 states have (on average 9.5) internal successors, (19), 2 states have internal predecessors, (19), 1 states have call successors, (3), 2 states have call predecessors, (3), 1 states have return successors, (1), 1 states have call predecessors, (1), 1 states have call successors, (1) [2022-02-20 18:05:49,816 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 2 states to 2 states and 167 transitions. [2022-02-20 18:05:49,816 INFO L86 InductivityCheck]: Starting indutivity check of a Floyd-Hoare automaton with 2 states and 167 transitions. [2022-02-20 18:05:49,958 INFO L122 InductivityCheck]: Floyd-Hoare automaton has 167 edges. 167 inductive. 0 not inductive. 0 times theorem prover too weak to decide inductivity. [2022-02-20 18:05:49,973 INFO L225 Difference]: With dead ends: 124 [2022-02-20 18:05:49,974 INFO L226 Difference]: Without dead ends: 57 [2022-02-20 18:05:49,978 INFO L932 BasicCegarLoop]: 0 DeclaredPredicates, 4 GetRequests, 4 SyntacticMatches, 0 SemanticMatches, 0 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 0 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=1, Invalid=1, Unknown=0, NotChecked=0, Total=2 [2022-02-20 18:05:49,982 INFO L933 BasicCegarLoop]: 80 mSDtfsCounter, 0 mSDsluCounter, 0 mSDsCounter, 0 mSdLazyCounter, 0 mSolverCounterSat, 0 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.0s Time, 0 mProtectedPredicate, 0 mProtectedAction, 0 SdHoareTripleChecker+Valid, 80 SdHoareTripleChecker+Invalid, 0 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 0 IncrementalHoareTripleChecker+Valid, 0 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.0s IncrementalHoareTripleChecker+Time [2022-02-20 18:05:49,984 INFO L934 BasicCegarLoop]: SdHoareTripleChecker [0 Valid, 80 Invalid, 0 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [0 Valid, 0 Invalid, 0 Unknown, 0 Unchecked, 0.0s Time] [2022-02-20 18:05:49,998 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 57 states. [2022-02-20 18:05:50,020 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 57 to 57. [2022-02-20 18:05:50,021 INFO L214 AbstractMinimizeNwa]: Start testing correctness of minimizeSevpa [2022-02-20 18:05:50,022 INFO L82 GeneralOperation]: Start isEquivalent. First operand 57 states. Second operand has 57 states, 45 states have (on average 1.288888888888889) internal successors, (58), 48 states have internal predecessors, (58), 7 states have call successors, (7), 5 states have call predecessors, (7), 4 states have return successors, (6), 6 states have call predecessors, (6), 6 states have call successors, (6) [2022-02-20 18:05:50,022 INFO L74 IsIncluded]: Start isIncluded. First operand 57 states. Second operand has 57 states, 45 states have (on average 1.288888888888889) internal successors, (58), 48 states have internal predecessors, (58), 7 states have call successors, (7), 5 states have call predecessors, (7), 4 states have return successors, (6), 6 states have call predecessors, (6), 6 states have call successors, (6) [2022-02-20 18:05:50,023 INFO L87 Difference]: Start difference. First operand 57 states. Second operand has 57 states, 45 states have (on average 1.288888888888889) internal successors, (58), 48 states have internal predecessors, (58), 7 states have call successors, (7), 5 states have call predecessors, (7), 4 states have return successors, (6), 6 states have call predecessors, (6), 6 states have call successors, (6) [2022-02-20 18:05:50,029 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-02-20 18:05:50,029 INFO L93 Difference]: Finished difference Result 57 states and 71 transitions. [2022-02-20 18:05:50,030 INFO L276 IsEmpty]: Start isEmpty. Operand 57 states and 71 transitions. [2022-02-20 18:05:50,030 INFO L282 IsEmpty]: Finished isEmpty. No accepting run. [2022-02-20 18:05:50,030 INFO L83 IsIncluded]: Finished isIncluded. Language is included [2022-02-20 18:05:50,031 INFO L74 IsIncluded]: Start isIncluded. First operand has 57 states, 45 states have (on average 1.288888888888889) internal successors, (58), 48 states have internal predecessors, (58), 7 states have call successors, (7), 5 states have call predecessors, (7), 4 states have return successors, (6), 6 states have call predecessors, (6), 6 states have call successors, (6) Second operand 57 states. [2022-02-20 18:05:50,031 INFO L87 Difference]: Start difference. First operand has 57 states, 45 states have (on average 1.288888888888889) internal successors, (58), 48 states have internal predecessors, (58), 7 states have call successors, (7), 5 states have call predecessors, (7), 4 states have return successors, (6), 6 states have call predecessors, (6), 6 states have call successors, (6) Second operand 57 states. [2022-02-20 18:05:50,035 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-02-20 18:05:50,035 INFO L93 Difference]: Finished difference Result 57 states and 71 transitions. [2022-02-20 18:05:50,035 INFO L276 IsEmpty]: Start isEmpty. Operand 57 states and 71 transitions. [2022-02-20 18:05:50,036 INFO L282 IsEmpty]: Finished isEmpty. No accepting run. [2022-02-20 18:05:50,036 INFO L83 IsIncluded]: Finished isIncluded. Language is included [2022-02-20 18:05:50,036 INFO L88 GeneralOperation]: Finished isEquivalent. [2022-02-20 18:05:50,036 INFO L221 AbstractMinimizeNwa]: Finished testing correctness of minimizeSevpa [2022-02-20 18:05:50,038 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 57 states, 45 states have (on average 1.288888888888889) internal successors, (58), 48 states have internal predecessors, (58), 7 states have call successors, (7), 5 states have call predecessors, (7), 4 states have return successors, (6), 6 states have call predecessors, (6), 6 states have call successors, (6) [2022-02-20 18:05:50,041 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 57 states to 57 states and 71 transitions. [2022-02-20 18:05:50,045 INFO L78 Accepts]: Start accepts. Automaton has 57 states and 71 transitions. Word has length 23 [2022-02-20 18:05:50,045 INFO L84 Accepts]: Finished accepts. word is rejected. [2022-02-20 18:05:50,045 INFO L470 AbstractCegarLoop]: Abstraction has 57 states and 71 transitions. [2022-02-20 18:05:50,046 INFO L471 AbstractCegarLoop]: INTERPOLANT automaton has has 2 states, 2 states have (on average 9.5) internal successors, (19), 2 states have internal predecessors, (19), 1 states have call successors, (3), 2 states have call predecessors, (3), 1 states have return successors, (1), 1 states have call predecessors, (1), 1 states have call successors, (1) [2022-02-20 18:05:50,046 INFO L276 IsEmpty]: Start isEmpty. Operand 57 states and 71 transitions. [2022-02-20 18:05:50,047 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 25 [2022-02-20 18:05:50,047 INFO L506 BasicCegarLoop]: Found error trace [2022-02-20 18:05:50,047 INFO L514 BasicCegarLoop]: trace histogram [1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-02-20 18:05:50,048 WARN L452 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable0 [2022-02-20 18:05:50,048 INFO L402 AbstractCegarLoop]: === Iteration 2 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2022-02-20 18:05:50,048 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2022-02-20 18:05:50,049 INFO L85 PathProgramCache]: Analyzing trace with hash 366452259, now seen corresponding path program 1 times [2022-02-20 18:05:50,049 INFO L126 FreeRefinementEngine]: Executing refinement strategy CAMEL [2022-02-20 18:05:50,049 INFO L338 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [199365867] [2022-02-20 18:05:50,049 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-02-20 18:05:50,049 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2022-02-20 18:05:50,083 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-02-20 18:05:50,138 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 15 [2022-02-20 18:05:50,141 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-02-20 18:05:50,151 INFO L290 TraceCheckUtils]: 0: Hoare triple {448#true} havoc ~retValue_acc~5;~retValue_acc~5 := ~methaneLevelCritical~0;#res := ~retValue_acc~5; {448#true} is VALID [2022-02-20 18:05:50,151 INFO L290 TraceCheckUtils]: 1: Hoare triple {448#true} assume true; {448#true} is VALID [2022-02-20 18:05:50,151 INFO L284 TraceCheckUtils]: 2: Hoare quadruple {448#true} {449#false} #175#return; {449#false} is VALID [2022-02-20 18:05:50,152 INFO L290 TraceCheckUtils]: 0: Hoare triple {448#true} assume { :begin_inline_ULTIMATE.init } true;#NULL.base, #NULL.offset := 0, 0;assume 0 == #valid[0];assume 0 < #StackHeapBarrier;call #Ultimate.allocInit(2, 1);call write~init~int(48, 1, 0, 1);call write~init~int(0, 1, 1, 1);call #Ultimate.allocInit(31, 2);call #Ultimate.allocInit(12, 3);call #Ultimate.allocInit(13, 4);call #Ultimate.allocInit(3, 5);call write~init~int(79, 5, 0, 1);call write~init~int(110, 5, 1, 1);call write~init~int(0, 5, 2, 1);call #Ultimate.allocInit(4, 6);call write~init~int(79, 6, 0, 1);call write~init~int(102, 6, 1, 1);call write~init~int(102, 6, 2, 1);call write~init~int(0, 6, 3, 1);call #Ultimate.allocInit(7, 7);call write~init~int(44, 7, 0, 1);call write~init~int(80, 7, 1, 1);call write~init~int(117, 7, 2, 1);call write~init~int(109, 7, 3, 1);call write~init~int(112, 7, 4, 1);call write~init~int(58, 7, 5, 1);call write~init~int(0, 7, 6, 1);call #Ultimate.allocInit(3, 8);call write~init~int(79, 8, 0, 1);call write~init~int(110, 8, 1, 1);call write~init~int(0, 8, 2, 1);call #Ultimate.allocInit(4, 9);call write~init~int(79, 9, 0, 1);call write~init~int(102, 9, 1, 1);call write~init~int(102, 9, 2, 1);call write~init~int(0, 9, 3, 1);call #Ultimate.allocInit(3, 10);call write~init~int(41, 10, 0, 1);call write~init~int(32, 10, 1, 1);call write~init~int(0, 10, 2, 1);call #Ultimate.allocInit(2, 11);call write~init~int(10, 11, 0, 1);call write~init~int(0, 11, 1, 1);call #Ultimate.allocInit(13, 12);call #Ultimate.allocInit(7, 13);call write~init~int(44, 13, 0, 1);call write~init~int(77, 13, 1, 1);call write~init~int(101, 13, 2, 1);call write~init~int(116, 13, 3, 1);call write~init~int(104, 13, 4, 1);call write~init~int(58, 13, 5, 1);call write~init~int(0, 13, 6, 1);call #Ultimate.allocInit(5, 14);call write~init~int(67, 14, 0, 1);call write~init~int(82, 14, 1, 1);call write~init~int(73, 14, 2, 1);call write~init~int(84, 14, 3, 1);call write~init~int(0, 14, 4, 1);call #Ultimate.allocInit(3, 15);call write~init~int(79, 15, 0, 1);call write~init~int(75, 15, 1, 1);call write~init~int(0, 15, 2, 1);call #Ultimate.allocInit(2, 16);call write~init~int(41, 16, 0, 1);call write~init~int(0, 16, 1, 1);call #Ultimate.allocInit(30, 17);call #Ultimate.allocInit(9, 18);call #Ultimate.allocInit(21, 19);call #Ultimate.allocInit(30, 20);call #Ultimate.allocInit(9, 21);call #Ultimate.allocInit(21, 22);call #Ultimate.allocInit(30, 23);call #Ultimate.allocInit(9, 24);call #Ultimate.allocInit(25, 25);call #Ultimate.allocInit(30, 26);call #Ultimate.allocInit(9, 27);call #Ultimate.allocInit(25, 28);~cleanupTimeShifts~0 := 4;~pumpRunning~0 := 0;~systemActive~0 := 1;~waterLevel~0 := 1;~methaneLevelCritical~0 := 0;~head~0.base, ~head~0.offset := 0, 0; {448#true} is VALID [2022-02-20 18:05:50,152 INFO L290 TraceCheckUtils]: 1: Hoare triple {448#true} assume { :end_inline_ULTIMATE.init } true;assume { :begin_inline_main } true;havoc main_#res#1;havoc main_#t~ret4#1, main_~retValue_acc~0#1, main_~tmp~0#1;havoc main_~retValue_acc~0#1;havoc main_~tmp~0#1;assume { :begin_inline_select_helpers } true; {448#true} is VALID [2022-02-20 18:05:50,152 INFO L290 TraceCheckUtils]: 2: Hoare triple {448#true} assume { :end_inline_select_helpers } true;assume { :begin_inline_select_features } true; {448#true} is VALID [2022-02-20 18:05:50,153 INFO L290 TraceCheckUtils]: 3: Hoare triple {448#true} assume { :end_inline_select_features } true;assume { :begin_inline_valid_product } true;havoc valid_product_#res#1;havoc valid_product_~retValue_acc~2#1;havoc valid_product_~retValue_acc~2#1;valid_product_~retValue_acc~2#1 := 1;valid_product_#res#1 := valid_product_~retValue_acc~2#1; {448#true} is VALID [2022-02-20 18:05:50,153 INFO L290 TraceCheckUtils]: 4: Hoare triple {448#true} main_#t~ret4#1 := valid_product_#res#1;assume { :end_inline_valid_product } true;assume -2147483648 <= main_#t~ret4#1 && main_#t~ret4#1 <= 2147483647;main_~tmp~0#1 := main_#t~ret4#1;havoc main_#t~ret4#1; {448#true} is VALID [2022-02-20 18:05:50,153 INFO L290 TraceCheckUtils]: 5: Hoare triple {448#true} assume 0 != main_~tmp~0#1;assume { :begin_inline_setup } true; {448#true} is VALID [2022-02-20 18:05:50,154 INFO L290 TraceCheckUtils]: 6: Hoare triple {448#true} assume { :end_inline_setup } true;assume { :begin_inline_runTest } true;assume { :begin_inline_test } true;havoc test_#t~nondet16#1, test_#t~nondet17#1, test_#t~nondet18#1, test_#t~nondet19#1, test_~splverifierCounter~0#1, test_~tmp~2#1, test_~tmp___0~0#1, test_~tmp___1~0#1, test_~tmp___2~0#1;havoc test_~splverifierCounter~0#1;havoc test_~tmp~2#1;havoc test_~tmp___0~0#1;havoc test_~tmp___1~0#1;havoc test_~tmp___2~0#1;test_~splverifierCounter~0#1 := 0; {450#(= |ULTIMATE.start_test_~splverifierCounter~0#1| 0)} is VALID [2022-02-20 18:05:50,154 INFO L290 TraceCheckUtils]: 7: Hoare triple {450#(= |ULTIMATE.start_test_~splverifierCounter~0#1| 0)} assume !false; {450#(= |ULTIMATE.start_test_~splverifierCounter~0#1| 0)} is VALID [2022-02-20 18:05:50,155 INFO L290 TraceCheckUtils]: 8: Hoare triple {450#(= |ULTIMATE.start_test_~splverifierCounter~0#1| 0)} assume !(test_~splverifierCounter~0#1 < 4); {449#false} is VALID [2022-02-20 18:05:50,155 INFO L272 TraceCheckUtils]: 9: Hoare triple {449#false} call cleanup(); {449#false} is VALID [2022-02-20 18:05:50,155 INFO L290 TraceCheckUtils]: 10: Hoare triple {449#false} havoc ~i~0;havoc ~__cil_tmp2~0; {449#false} is VALID [2022-02-20 18:05:50,155 INFO L272 TraceCheckUtils]: 11: Hoare triple {449#false} call timeShift(); {449#false} is VALID [2022-02-20 18:05:50,156 INFO L290 TraceCheckUtils]: 12: Hoare triple {449#false} assume !(0 != ~pumpRunning~0); {449#false} is VALID [2022-02-20 18:05:50,156 INFO L290 TraceCheckUtils]: 13: Hoare triple {449#false} assume !(0 != ~systemActive~0); {449#false} is VALID [2022-02-20 18:05:50,156 INFO L290 TraceCheckUtils]: 14: Hoare triple {449#false} assume { :begin_inline___utac_acc__Specification1_spec__1 } true;havoc __utac_acc__Specification1_spec__1_#t~ret25#1, __utac_acc__Specification1_spec__1_#t~ret26#1, __utac_acc__Specification1_spec__1_~tmp~3#1, __utac_acc__Specification1_spec__1_~tmp___0~1#1;havoc __utac_acc__Specification1_spec__1_~tmp~3#1;havoc __utac_acc__Specification1_spec__1_~tmp___0~1#1; {449#false} is VALID [2022-02-20 18:05:50,156 INFO L272 TraceCheckUtils]: 15: Hoare triple {449#false} call __utac_acc__Specification1_spec__1_#t~ret25#1 := isMethaneLevelCritical(); {448#true} is VALID [2022-02-20 18:05:50,156 INFO L290 TraceCheckUtils]: 16: Hoare triple {448#true} havoc ~retValue_acc~5;~retValue_acc~5 := ~methaneLevelCritical~0;#res := ~retValue_acc~5; {448#true} is VALID [2022-02-20 18:05:50,157 INFO L290 TraceCheckUtils]: 17: Hoare triple {448#true} assume true; {448#true} is VALID [2022-02-20 18:05:50,157 INFO L284 TraceCheckUtils]: 18: Hoare quadruple {448#true} {449#false} #175#return; {449#false} is VALID [2022-02-20 18:05:50,160 INFO L290 TraceCheckUtils]: 19: Hoare triple {449#false} assume -2147483648 <= __utac_acc__Specification1_spec__1_#t~ret25#1 && __utac_acc__Specification1_spec__1_#t~ret25#1 <= 2147483647;__utac_acc__Specification1_spec__1_~tmp~3#1 := __utac_acc__Specification1_spec__1_#t~ret25#1;havoc __utac_acc__Specification1_spec__1_#t~ret25#1; {449#false} is VALID [2022-02-20 18:05:50,161 INFO L290 TraceCheckUtils]: 20: Hoare triple {449#false} assume 0 != __utac_acc__Specification1_spec__1_~tmp~3#1;assume { :begin_inline_isPumpRunning } true;havoc isPumpRunning_#res#1;havoc isPumpRunning_~retValue_acc~4#1;havoc isPumpRunning_~retValue_acc~4#1;isPumpRunning_~retValue_acc~4#1 := ~pumpRunning~0;isPumpRunning_#res#1 := isPumpRunning_~retValue_acc~4#1; {449#false} is VALID [2022-02-20 18:05:50,161 INFO L290 TraceCheckUtils]: 21: Hoare triple {449#false} __utac_acc__Specification1_spec__1_#t~ret26#1 := isPumpRunning_#res#1;assume { :end_inline_isPumpRunning } true;assume -2147483648 <= __utac_acc__Specification1_spec__1_#t~ret26#1 && __utac_acc__Specification1_spec__1_#t~ret26#1 <= 2147483647;__utac_acc__Specification1_spec__1_~tmp___0~1#1 := __utac_acc__Specification1_spec__1_#t~ret26#1;havoc __utac_acc__Specification1_spec__1_#t~ret26#1; {449#false} is VALID [2022-02-20 18:05:50,161 INFO L290 TraceCheckUtils]: 22: Hoare triple {449#false} assume 0 != __utac_acc__Specification1_spec__1_~tmp___0~1#1;assume { :begin_inline___automaton_fail } true; {449#false} is VALID [2022-02-20 18:05:50,161 INFO L290 TraceCheckUtils]: 23: Hoare triple {449#false} assume !false; {449#false} is VALID [2022-02-20 18:05:50,163 INFO L134 CoverageAnalysis]: Checked inductivity of 0 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2022-02-20 18:05:50,164 INFO L144 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2022-02-20 18:05:50,164 INFO L338 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [199365867] [2022-02-20 18:05:50,164 INFO L165 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [199365867] provided 1 perfect and 0 imperfect interpolant sequences [2022-02-20 18:05:50,165 INFO L191 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2022-02-20 18:05:50,165 INFO L204 FreeRefinementEngine]: Number of different interpolants: perfect sequences [3] imperfect sequences [] total 3 [2022-02-20 18:05:50,165 INFO L118 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [10642075] [2022-02-20 18:05:50,165 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2022-02-20 18:05:50,166 INFO L78 Accepts]: Start accepts. Automaton has has 3 states, 3 states have (on average 6.666666666666667) internal successors, (20), 3 states have internal predecessors, (20), 1 states have call successors, (3), 2 states have call predecessors, (3), 1 states have return successors, (1), 1 states have call predecessors, (1), 1 states have call successors, (1) Word has length 24 [2022-02-20 18:05:50,167 INFO L84 Accepts]: Finished accepts. word is accepted. [2022-02-20 18:05:50,167 INFO L86 InductivityCheck]: Starting indutivity check of a Floyd-Hoare automaton with has 3 states, 3 states have (on average 6.666666666666667) internal successors, (20), 3 states have internal predecessors, (20), 1 states have call successors, (3), 2 states have call predecessors, (3), 1 states have return successors, (1), 1 states have call predecessors, (1), 1 states have call successors, (1) [2022-02-20 18:05:50,184 INFO L122 InductivityCheck]: Floyd-Hoare automaton has 24 edges. 24 inductive. 0 not inductive. 0 times theorem prover too weak to decide inductivity. [2022-02-20 18:05:50,184 INFO L546 AbstractCegarLoop]: INTERPOLANT automaton has 3 states [2022-02-20 18:05:50,185 INFO L108 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2022-02-20 18:05:50,185 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 3 interpolants. [2022-02-20 18:05:50,186 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=3, Invalid=3, Unknown=0, NotChecked=0, Total=6 [2022-02-20 18:05:50,186 INFO L87 Difference]: Start difference. First operand 57 states and 71 transitions. Second operand has 3 states, 3 states have (on average 6.666666666666667) internal successors, (20), 3 states have internal predecessors, (20), 1 states have call successors, (3), 2 states have call predecessors, (3), 1 states have return successors, (1), 1 states have call predecessors, (1), 1 states have call successors, (1) [2022-02-20 18:05:50,251 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-02-20 18:05:50,252 INFO L93 Difference]: Finished difference Result 76 states and 93 transitions. [2022-02-20 18:05:50,252 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 3 states. [2022-02-20 18:05:50,252 INFO L78 Accepts]: Start accepts. Automaton has has 3 states, 3 states have (on average 6.666666666666667) internal successors, (20), 3 states have internal predecessors, (20), 1 states have call successors, (3), 2 states have call predecessors, (3), 1 states have return successors, (1), 1 states have call predecessors, (1), 1 states have call successors, (1) Word has length 24 [2022-02-20 18:05:50,252 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2022-02-20 18:05:50,252 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 3 states, 3 states have (on average 6.666666666666667) internal successors, (20), 3 states have internal predecessors, (20), 1 states have call successors, (3), 2 states have call predecessors, (3), 1 states have return successors, (1), 1 states have call predecessors, (1), 1 states have call successors, (1) [2022-02-20 18:05:50,255 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 3 states to 3 states and 93 transitions. [2022-02-20 18:05:50,255 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 3 states, 3 states have (on average 6.666666666666667) internal successors, (20), 3 states have internal predecessors, (20), 1 states have call successors, (3), 2 states have call predecessors, (3), 1 states have return successors, (1), 1 states have call predecessors, (1), 1 states have call successors, (1) [2022-02-20 18:05:50,257 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 3 states to 3 states and 93 transitions. [2022-02-20 18:05:50,257 INFO L86 InductivityCheck]: Starting indutivity check of a Floyd-Hoare automaton with 3 states and 93 transitions. [2022-02-20 18:05:50,332 INFO L122 InductivityCheck]: Floyd-Hoare automaton has 93 edges. 93 inductive. 0 not inductive. 0 times theorem prover too weak to decide inductivity. [2022-02-20 18:05:50,336 INFO L225 Difference]: With dead ends: 76 [2022-02-20 18:05:50,336 INFO L226 Difference]: Without dead ends: 48 [2022-02-20 18:05:50,340 INFO L932 BasicCegarLoop]: 0 DeclaredPredicates, 5 GetRequests, 4 SyntacticMatches, 0 SemanticMatches, 1 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 0 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=3, Invalid=3, Unknown=0, NotChecked=0, Total=6 [2022-02-20 18:05:50,342 INFO L933 BasicCegarLoop]: 58 mSDtfsCounter, 17 mSDsluCounter, 37 mSDsCounter, 0 mSdLazyCounter, 1 mSolverCounterSat, 0 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.0s Time, 0 mProtectedPredicate, 0 mProtectedAction, 20 SdHoareTripleChecker+Valid, 95 SdHoareTripleChecker+Invalid, 1 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 0 IncrementalHoareTripleChecker+Valid, 1 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.0s IncrementalHoareTripleChecker+Time [2022-02-20 18:05:50,342 INFO L934 BasicCegarLoop]: SdHoareTripleChecker [20 Valid, 95 Invalid, 1 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [0 Valid, 1 Invalid, 0 Unknown, 0 Unchecked, 0.0s Time] [2022-02-20 18:05:50,343 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 48 states. [2022-02-20 18:05:50,346 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 48 to 48. [2022-02-20 18:05:50,346 INFO L214 AbstractMinimizeNwa]: Start testing correctness of minimizeSevpa [2022-02-20 18:05:50,346 INFO L82 GeneralOperation]: Start isEquivalent. First operand 48 states. Second operand has 48 states, 39 states have (on average 1.3076923076923077) internal successors, (51), 42 states have internal predecessors, (51), 4 states have call successors, (4), 4 states have call predecessors, (4), 4 states have return successors, (4), 4 states have call predecessors, (4), 4 states have call successors, (4) [2022-02-20 18:05:50,347 INFO L74 IsIncluded]: Start isIncluded. First operand 48 states. Second operand has 48 states, 39 states have (on average 1.3076923076923077) internal successors, (51), 42 states have internal predecessors, (51), 4 states have call successors, (4), 4 states have call predecessors, (4), 4 states have return successors, (4), 4 states have call predecessors, (4), 4 states have call successors, (4) [2022-02-20 18:05:50,347 INFO L87 Difference]: Start difference. First operand 48 states. Second operand has 48 states, 39 states have (on average 1.3076923076923077) internal successors, (51), 42 states have internal predecessors, (51), 4 states have call successors, (4), 4 states have call predecessors, (4), 4 states have return successors, (4), 4 states have call predecessors, (4), 4 states have call successors, (4) [2022-02-20 18:05:50,348 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-02-20 18:05:50,349 INFO L93 Difference]: Finished difference Result 48 states and 59 transitions. [2022-02-20 18:05:50,349 INFO L276 IsEmpty]: Start isEmpty. Operand 48 states and 59 transitions. [2022-02-20 18:05:50,349 INFO L282 IsEmpty]: Finished isEmpty. No accepting run. [2022-02-20 18:05:50,349 INFO L83 IsIncluded]: Finished isIncluded. Language is included [2022-02-20 18:05:50,350 INFO L74 IsIncluded]: Start isIncluded. First operand has 48 states, 39 states have (on average 1.3076923076923077) internal successors, (51), 42 states have internal predecessors, (51), 4 states have call successors, (4), 4 states have call predecessors, (4), 4 states have return successors, (4), 4 states have call predecessors, (4), 4 states have call successors, (4) Second operand 48 states. [2022-02-20 18:05:50,350 INFO L87 Difference]: Start difference. First operand has 48 states, 39 states have (on average 1.3076923076923077) internal successors, (51), 42 states have internal predecessors, (51), 4 states have call successors, (4), 4 states have call predecessors, (4), 4 states have return successors, (4), 4 states have call predecessors, (4), 4 states have call successors, (4) Second operand 48 states. [2022-02-20 18:05:50,352 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-02-20 18:05:50,352 INFO L93 Difference]: Finished difference Result 48 states and 59 transitions. [2022-02-20 18:05:50,352 INFO L276 IsEmpty]: Start isEmpty. Operand 48 states and 59 transitions. [2022-02-20 18:05:50,352 INFO L282 IsEmpty]: Finished isEmpty. No accepting run. [2022-02-20 18:05:50,353 INFO L83 IsIncluded]: Finished isIncluded. Language is included [2022-02-20 18:05:50,353 INFO L88 GeneralOperation]: Finished isEquivalent. [2022-02-20 18:05:50,353 INFO L221 AbstractMinimizeNwa]: Finished testing correctness of minimizeSevpa [2022-02-20 18:05:50,353 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 48 states, 39 states have (on average 1.3076923076923077) internal successors, (51), 42 states have internal predecessors, (51), 4 states have call successors, (4), 4 states have call predecessors, (4), 4 states have return successors, (4), 4 states have call predecessors, (4), 4 states have call successors, (4) [2022-02-20 18:05:50,355 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 48 states to 48 states and 59 transitions. [2022-02-20 18:05:50,355 INFO L78 Accepts]: Start accepts. Automaton has 48 states and 59 transitions. Word has length 24 [2022-02-20 18:05:50,355 INFO L84 Accepts]: Finished accepts. word is rejected. [2022-02-20 18:05:50,355 INFO L470 AbstractCegarLoop]: Abstraction has 48 states and 59 transitions. [2022-02-20 18:05:50,355 INFO L471 AbstractCegarLoop]: INTERPOLANT automaton has has 3 states, 3 states have (on average 6.666666666666667) internal successors, (20), 3 states have internal predecessors, (20), 1 states have call successors, (3), 2 states have call predecessors, (3), 1 states have return successors, (1), 1 states have call predecessors, (1), 1 states have call successors, (1) [2022-02-20 18:05:50,356 INFO L276 IsEmpty]: Start isEmpty. Operand 48 states and 59 transitions. [2022-02-20 18:05:50,356 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 29 [2022-02-20 18:05:50,356 INFO L506 BasicCegarLoop]: Found error trace [2022-02-20 18:05:50,356 INFO L514 BasicCegarLoop]: trace histogram [1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-02-20 18:05:50,357 WARN L452 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable1 [2022-02-20 18:05:50,357 INFO L402 AbstractCegarLoop]: === Iteration 3 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2022-02-20 18:05:50,357 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2022-02-20 18:05:50,357 INFO L85 PathProgramCache]: Analyzing trace with hash 1516817852, now seen corresponding path program 1 times [2022-02-20 18:05:50,358 INFO L126 FreeRefinementEngine]: Executing refinement strategy CAMEL [2022-02-20 18:05:50,358 INFO L338 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [558945] [2022-02-20 18:05:50,358 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-02-20 18:05:50,358 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2022-02-20 18:05:50,388 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-02-20 18:05:50,459 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 19 [2022-02-20 18:05:50,463 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-02-20 18:05:50,467 INFO L290 TraceCheckUtils]: 0: Hoare triple {726#true} havoc ~retValue_acc~5;~retValue_acc~5 := ~methaneLevelCritical~0;#res := ~retValue_acc~5; {726#true} is VALID [2022-02-20 18:05:50,467 INFO L290 TraceCheckUtils]: 1: Hoare triple {726#true} assume true; {726#true} is VALID [2022-02-20 18:05:50,467 INFO L284 TraceCheckUtils]: 2: Hoare quadruple {726#true} {727#false} #175#return; {727#false} is VALID [2022-02-20 18:05:50,469 INFO L290 TraceCheckUtils]: 0: Hoare triple {726#true} assume { :begin_inline_ULTIMATE.init } true;#NULL.base, #NULL.offset := 0, 0;assume 0 == #valid[0];assume 0 < #StackHeapBarrier;call #Ultimate.allocInit(2, 1);call write~init~int(48, 1, 0, 1);call write~init~int(0, 1, 1, 1);call #Ultimate.allocInit(31, 2);call #Ultimate.allocInit(12, 3);call #Ultimate.allocInit(13, 4);call #Ultimate.allocInit(3, 5);call write~init~int(79, 5, 0, 1);call write~init~int(110, 5, 1, 1);call write~init~int(0, 5, 2, 1);call #Ultimate.allocInit(4, 6);call write~init~int(79, 6, 0, 1);call write~init~int(102, 6, 1, 1);call write~init~int(102, 6, 2, 1);call write~init~int(0, 6, 3, 1);call #Ultimate.allocInit(7, 7);call write~init~int(44, 7, 0, 1);call write~init~int(80, 7, 1, 1);call write~init~int(117, 7, 2, 1);call write~init~int(109, 7, 3, 1);call write~init~int(112, 7, 4, 1);call write~init~int(58, 7, 5, 1);call write~init~int(0, 7, 6, 1);call #Ultimate.allocInit(3, 8);call write~init~int(79, 8, 0, 1);call write~init~int(110, 8, 1, 1);call write~init~int(0, 8, 2, 1);call #Ultimate.allocInit(4, 9);call write~init~int(79, 9, 0, 1);call write~init~int(102, 9, 1, 1);call write~init~int(102, 9, 2, 1);call write~init~int(0, 9, 3, 1);call #Ultimate.allocInit(3, 10);call write~init~int(41, 10, 0, 1);call write~init~int(32, 10, 1, 1);call write~init~int(0, 10, 2, 1);call #Ultimate.allocInit(2, 11);call write~init~int(10, 11, 0, 1);call write~init~int(0, 11, 1, 1);call #Ultimate.allocInit(13, 12);call #Ultimate.allocInit(7, 13);call write~init~int(44, 13, 0, 1);call write~init~int(77, 13, 1, 1);call write~init~int(101, 13, 2, 1);call write~init~int(116, 13, 3, 1);call write~init~int(104, 13, 4, 1);call write~init~int(58, 13, 5, 1);call write~init~int(0, 13, 6, 1);call #Ultimate.allocInit(5, 14);call write~init~int(67, 14, 0, 1);call write~init~int(82, 14, 1, 1);call write~init~int(73, 14, 2, 1);call write~init~int(84, 14, 3, 1);call write~init~int(0, 14, 4, 1);call #Ultimate.allocInit(3, 15);call write~init~int(79, 15, 0, 1);call write~init~int(75, 15, 1, 1);call write~init~int(0, 15, 2, 1);call #Ultimate.allocInit(2, 16);call write~init~int(41, 16, 0, 1);call write~init~int(0, 16, 1, 1);call #Ultimate.allocInit(30, 17);call #Ultimate.allocInit(9, 18);call #Ultimate.allocInit(21, 19);call #Ultimate.allocInit(30, 20);call #Ultimate.allocInit(9, 21);call #Ultimate.allocInit(21, 22);call #Ultimate.allocInit(30, 23);call #Ultimate.allocInit(9, 24);call #Ultimate.allocInit(25, 25);call #Ultimate.allocInit(30, 26);call #Ultimate.allocInit(9, 27);call #Ultimate.allocInit(25, 28);~cleanupTimeShifts~0 := 4;~pumpRunning~0 := 0;~systemActive~0 := 1;~waterLevel~0 := 1;~methaneLevelCritical~0 := 0;~head~0.base, ~head~0.offset := 0, 0; {728#(= 1 ~systemActive~0)} is VALID [2022-02-20 18:05:50,470 INFO L290 TraceCheckUtils]: 1: Hoare triple {728#(= 1 ~systemActive~0)} assume { :end_inline_ULTIMATE.init } true;assume { :begin_inline_main } true;havoc main_#res#1;havoc main_#t~ret4#1, main_~retValue_acc~0#1, main_~tmp~0#1;havoc main_~retValue_acc~0#1;havoc main_~tmp~0#1;assume { :begin_inline_select_helpers } true; {728#(= 1 ~systemActive~0)} is VALID [2022-02-20 18:05:50,470 INFO L290 TraceCheckUtils]: 2: Hoare triple {728#(= 1 ~systemActive~0)} assume { :end_inline_select_helpers } true;assume { :begin_inline_select_features } true; {728#(= 1 ~systemActive~0)} is VALID [2022-02-20 18:05:50,471 INFO L290 TraceCheckUtils]: 3: Hoare triple {728#(= 1 ~systemActive~0)} assume { :end_inline_select_features } true;assume { :begin_inline_valid_product } true;havoc valid_product_#res#1;havoc valid_product_~retValue_acc~2#1;havoc valid_product_~retValue_acc~2#1;valid_product_~retValue_acc~2#1 := 1;valid_product_#res#1 := valid_product_~retValue_acc~2#1; {729#(= |ULTIMATE.start_valid_product_#res#1| ~systemActive~0)} is VALID [2022-02-20 18:05:50,471 INFO L290 TraceCheckUtils]: 4: Hoare triple {729#(= |ULTIMATE.start_valid_product_#res#1| ~systemActive~0)} main_#t~ret4#1 := valid_product_#res#1;assume { :end_inline_valid_product } true;assume -2147483648 <= main_#t~ret4#1 && main_#t~ret4#1 <= 2147483647;main_~tmp~0#1 := main_#t~ret4#1;havoc main_#t~ret4#1; {730#(= |ULTIMATE.start_main_~tmp~0#1| ~systemActive~0)} is VALID [2022-02-20 18:05:50,472 INFO L290 TraceCheckUtils]: 5: Hoare triple {730#(= |ULTIMATE.start_main_~tmp~0#1| ~systemActive~0)} assume 0 != main_~tmp~0#1;assume { :begin_inline_setup } true; {731#(not (= 0 ~systemActive~0))} is VALID [2022-02-20 18:05:50,472 INFO L290 TraceCheckUtils]: 6: Hoare triple {731#(not (= 0 ~systemActive~0))} assume { :end_inline_setup } true;assume { :begin_inline_runTest } true;assume { :begin_inline_test } true;havoc test_#t~nondet16#1, test_#t~nondet17#1, test_#t~nondet18#1, test_#t~nondet19#1, test_~splverifierCounter~0#1, test_~tmp~2#1, test_~tmp___0~0#1, test_~tmp___1~0#1, test_~tmp___2~0#1;havoc test_~splverifierCounter~0#1;havoc test_~tmp~2#1;havoc test_~tmp___0~0#1;havoc test_~tmp___1~0#1;havoc test_~tmp___2~0#1;test_~splverifierCounter~0#1 := 0; {731#(not (= 0 ~systemActive~0))} is VALID [2022-02-20 18:05:50,473 INFO L290 TraceCheckUtils]: 7: Hoare triple {731#(not (= 0 ~systemActive~0))} assume !false; {731#(not (= 0 ~systemActive~0))} is VALID [2022-02-20 18:05:50,473 INFO L290 TraceCheckUtils]: 8: Hoare triple {731#(not (= 0 ~systemActive~0))} assume test_~splverifierCounter~0#1 < 4; {731#(not (= 0 ~systemActive~0))} is VALID [2022-02-20 18:05:50,474 INFO L290 TraceCheckUtils]: 9: Hoare triple {731#(not (= 0 ~systemActive~0))} assume -2147483648 <= test_#t~nondet16#1 && test_#t~nondet16#1 <= 2147483647;test_~tmp~2#1 := test_#t~nondet16#1;havoc test_#t~nondet16#1; {731#(not (= 0 ~systemActive~0))} is VALID [2022-02-20 18:05:50,474 INFO L290 TraceCheckUtils]: 10: Hoare triple {731#(not (= 0 ~systemActive~0))} assume !(0 != test_~tmp~2#1); {731#(not (= 0 ~systemActive~0))} is VALID [2022-02-20 18:05:50,474 INFO L290 TraceCheckUtils]: 11: Hoare triple {731#(not (= 0 ~systemActive~0))} assume -2147483648 <= test_#t~nondet17#1 && test_#t~nondet17#1 <= 2147483647;test_~tmp___0~0#1 := test_#t~nondet17#1;havoc test_#t~nondet17#1; {731#(not (= 0 ~systemActive~0))} is VALID [2022-02-20 18:05:50,475 INFO L290 TraceCheckUtils]: 12: Hoare triple {731#(not (= 0 ~systemActive~0))} assume !(0 != test_~tmp___0~0#1); {731#(not (= 0 ~systemActive~0))} is VALID [2022-02-20 18:05:50,475 INFO L290 TraceCheckUtils]: 13: Hoare triple {731#(not (= 0 ~systemActive~0))} assume -2147483648 <= test_#t~nondet18#1 && test_#t~nondet18#1 <= 2147483647;test_~tmp___2~0#1 := test_#t~nondet18#1;havoc test_#t~nondet18#1; {731#(not (= 0 ~systemActive~0))} is VALID [2022-02-20 18:05:50,476 INFO L290 TraceCheckUtils]: 14: Hoare triple {731#(not (= 0 ~systemActive~0))} assume 0 != test_~tmp___2~0#1; {731#(not (= 0 ~systemActive~0))} is VALID [2022-02-20 18:05:50,476 INFO L272 TraceCheckUtils]: 15: Hoare triple {731#(not (= 0 ~systemActive~0))} call timeShift(); {731#(not (= 0 ~systemActive~0))} is VALID [2022-02-20 18:05:50,477 INFO L290 TraceCheckUtils]: 16: Hoare triple {731#(not (= 0 ~systemActive~0))} assume !(0 != ~pumpRunning~0); {731#(not (= 0 ~systemActive~0))} is VALID [2022-02-20 18:05:50,477 INFO L290 TraceCheckUtils]: 17: Hoare triple {731#(not (= 0 ~systemActive~0))} assume !(0 != ~systemActive~0); {727#false} is VALID [2022-02-20 18:05:50,477 INFO L290 TraceCheckUtils]: 18: Hoare triple {727#false} assume { :begin_inline___utac_acc__Specification1_spec__1 } true;havoc __utac_acc__Specification1_spec__1_#t~ret25#1, __utac_acc__Specification1_spec__1_#t~ret26#1, __utac_acc__Specification1_spec__1_~tmp~3#1, __utac_acc__Specification1_spec__1_~tmp___0~1#1;havoc __utac_acc__Specification1_spec__1_~tmp~3#1;havoc __utac_acc__Specification1_spec__1_~tmp___0~1#1; {727#false} is VALID [2022-02-20 18:05:50,478 INFO L272 TraceCheckUtils]: 19: Hoare triple {727#false} call __utac_acc__Specification1_spec__1_#t~ret25#1 := isMethaneLevelCritical(); {726#true} is VALID [2022-02-20 18:05:50,478 INFO L290 TraceCheckUtils]: 20: Hoare triple {726#true} havoc ~retValue_acc~5;~retValue_acc~5 := ~methaneLevelCritical~0;#res := ~retValue_acc~5; {726#true} is VALID [2022-02-20 18:05:50,478 INFO L290 TraceCheckUtils]: 21: Hoare triple {726#true} assume true; {726#true} is VALID [2022-02-20 18:05:50,478 INFO L284 TraceCheckUtils]: 22: Hoare quadruple {726#true} {727#false} #175#return; {727#false} is VALID [2022-02-20 18:05:50,478 INFO L290 TraceCheckUtils]: 23: Hoare triple {727#false} assume -2147483648 <= __utac_acc__Specification1_spec__1_#t~ret25#1 && __utac_acc__Specification1_spec__1_#t~ret25#1 <= 2147483647;__utac_acc__Specification1_spec__1_~tmp~3#1 := __utac_acc__Specification1_spec__1_#t~ret25#1;havoc __utac_acc__Specification1_spec__1_#t~ret25#1; {727#false} is VALID [2022-02-20 18:05:50,479 INFO L290 TraceCheckUtils]: 24: Hoare triple {727#false} assume 0 != __utac_acc__Specification1_spec__1_~tmp~3#1;assume { :begin_inline_isPumpRunning } true;havoc isPumpRunning_#res#1;havoc isPumpRunning_~retValue_acc~4#1;havoc isPumpRunning_~retValue_acc~4#1;isPumpRunning_~retValue_acc~4#1 := ~pumpRunning~0;isPumpRunning_#res#1 := isPumpRunning_~retValue_acc~4#1; {727#false} is VALID [2022-02-20 18:05:50,479 INFO L290 TraceCheckUtils]: 25: Hoare triple {727#false} __utac_acc__Specification1_spec__1_#t~ret26#1 := isPumpRunning_#res#1;assume { :end_inline_isPumpRunning } true;assume -2147483648 <= __utac_acc__Specification1_spec__1_#t~ret26#1 && __utac_acc__Specification1_spec__1_#t~ret26#1 <= 2147483647;__utac_acc__Specification1_spec__1_~tmp___0~1#1 := __utac_acc__Specification1_spec__1_#t~ret26#1;havoc __utac_acc__Specification1_spec__1_#t~ret26#1; {727#false} is VALID [2022-02-20 18:05:50,479 INFO L290 TraceCheckUtils]: 26: Hoare triple {727#false} assume 0 != __utac_acc__Specification1_spec__1_~tmp___0~1#1;assume { :begin_inline___automaton_fail } true; {727#false} is VALID [2022-02-20 18:05:50,479 INFO L290 TraceCheckUtils]: 27: Hoare triple {727#false} assume !false; {727#false} is VALID [2022-02-20 18:05:50,480 INFO L134 CoverageAnalysis]: Checked inductivity of 0 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2022-02-20 18:05:50,480 INFO L144 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2022-02-20 18:05:50,480 INFO L338 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [558945] [2022-02-20 18:05:50,480 INFO L165 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [558945] provided 1 perfect and 0 imperfect interpolant sequences [2022-02-20 18:05:50,480 INFO L191 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2022-02-20 18:05:50,480 INFO L204 FreeRefinementEngine]: Number of different interpolants: perfect sequences [6] imperfect sequences [] total 6 [2022-02-20 18:05:50,481 INFO L118 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [868689563] [2022-02-20 18:05:50,481 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2022-02-20 18:05:50,481 INFO L78 Accepts]: Start accepts. Automaton has has 6 states, 6 states have (on average 4.166666666666667) internal successors, (25), 6 states have internal predecessors, (25), 2 states have call successors, (2), 2 states have call predecessors, (2), 1 states have return successors, (1), 1 states have call predecessors, (1), 1 states have call successors, (1) Word has length 28 [2022-02-20 18:05:50,481 INFO L84 Accepts]: Finished accepts. word is accepted. [2022-02-20 18:05:50,482 INFO L86 InductivityCheck]: Starting indutivity check of a Floyd-Hoare automaton with has 6 states, 6 states have (on average 4.166666666666667) internal successors, (25), 6 states have internal predecessors, (25), 2 states have call successors, (2), 2 states have call predecessors, (2), 1 states have return successors, (1), 1 states have call predecessors, (1), 1 states have call successors, (1) [2022-02-20 18:05:50,504 INFO L122 InductivityCheck]: Floyd-Hoare automaton has 28 edges. 28 inductive. 0 not inductive. 0 times theorem prover too weak to decide inductivity. [2022-02-20 18:05:50,504 INFO L546 AbstractCegarLoop]: INTERPOLANT automaton has 6 states [2022-02-20 18:05:50,504 INFO L108 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2022-02-20 18:05:50,505 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 6 interpolants. [2022-02-20 18:05:50,505 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=10, Invalid=20, Unknown=0, NotChecked=0, Total=30 [2022-02-20 18:05:50,505 INFO L87 Difference]: Start difference. First operand 48 states and 59 transitions. Second operand has 6 states, 6 states have (on average 4.166666666666667) internal successors, (25), 6 states have internal predecessors, (25), 2 states have call successors, (2), 2 states have call predecessors, (2), 1 states have return successors, (1), 1 states have call predecessors, (1), 1 states have call successors, (1) [2022-02-20 18:05:50,807 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-02-20 18:05:50,807 INFO L93 Difference]: Finished difference Result 168 states and 215 transitions. [2022-02-20 18:05:50,808 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 6 states. [2022-02-20 18:05:50,808 INFO L78 Accepts]: Start accepts. Automaton has has 6 states, 6 states have (on average 4.166666666666667) internal successors, (25), 6 states have internal predecessors, (25), 2 states have call successors, (2), 2 states have call predecessors, (2), 1 states have return successors, (1), 1 states have call predecessors, (1), 1 states have call successors, (1) Word has length 28 [2022-02-20 18:05:50,808 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2022-02-20 18:05:50,808 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 6 states, 6 states have (on average 4.166666666666667) internal successors, (25), 6 states have internal predecessors, (25), 2 states have call successors, (2), 2 states have call predecessors, (2), 1 states have return successors, (1), 1 states have call predecessors, (1), 1 states have call successors, (1) [2022-02-20 18:05:50,820 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 6 states to 6 states and 215 transitions. [2022-02-20 18:05:50,820 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 6 states, 6 states have (on average 4.166666666666667) internal successors, (25), 6 states have internal predecessors, (25), 2 states have call successors, (2), 2 states have call predecessors, (2), 1 states have return successors, (1), 1 states have call predecessors, (1), 1 states have call successors, (1) [2022-02-20 18:05:50,824 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 6 states to 6 states and 215 transitions. [2022-02-20 18:05:50,825 INFO L86 InductivityCheck]: Starting indutivity check of a Floyd-Hoare automaton with 6 states and 215 transitions. [2022-02-20 18:05:50,965 INFO L122 InductivityCheck]: Floyd-Hoare automaton has 215 edges. 215 inductive. 0 not inductive. 0 times theorem prover too weak to decide inductivity. [2022-02-20 18:05:50,969 INFO L225 Difference]: With dead ends: 168 [2022-02-20 18:05:50,970 INFO L226 Difference]: Without dead ends: 127 [2022-02-20 18:05:50,970 INFO L932 BasicCegarLoop]: 0 DeclaredPredicates, 9 GetRequests, 3 SyntacticMatches, 0 SemanticMatches, 6 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 0 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=22, Invalid=34, Unknown=0, NotChecked=0, Total=56 [2022-02-20 18:05:50,971 INFO L933 BasicCegarLoop]: 62 mSDtfsCounter, 128 mSDsluCounter, 262 mSDsCounter, 0 mSdLazyCounter, 50 mSolverCounterSat, 11 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.1s Time, 0 mProtectedPredicate, 0 mProtectedAction, 128 SdHoareTripleChecker+Valid, 324 SdHoareTripleChecker+Invalid, 61 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 11 IncrementalHoareTripleChecker+Valid, 50 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.1s IncrementalHoareTripleChecker+Time [2022-02-20 18:05:50,971 INFO L934 BasicCegarLoop]: SdHoareTripleChecker [128 Valid, 324 Invalid, 61 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [11 Valid, 50 Invalid, 0 Unknown, 0 Unchecked, 0.1s Time] [2022-02-20 18:05:50,972 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 127 states. [2022-02-20 18:05:50,982 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 127 to 117. [2022-02-20 18:05:50,983 INFO L214 AbstractMinimizeNwa]: Start testing correctness of minimizeSevpa [2022-02-20 18:05:50,983 INFO L82 GeneralOperation]: Start isEquivalent. First operand 127 states. Second operand has 117 states, 92 states have (on average 1.3478260869565217) internal successors, (124), 99 states have internal predecessors, (124), 12 states have call successors, (12), 12 states have call predecessors, (12), 12 states have return successors, (13), 12 states have call predecessors, (13), 12 states have call successors, (13) [2022-02-20 18:05:50,984 INFO L74 IsIncluded]: Start isIncluded. First operand 127 states. Second operand has 117 states, 92 states have (on average 1.3478260869565217) internal successors, (124), 99 states have internal predecessors, (124), 12 states have call successors, (12), 12 states have call predecessors, (12), 12 states have return successors, (13), 12 states have call predecessors, (13), 12 states have call successors, (13) [2022-02-20 18:05:50,985 INFO L87 Difference]: Start difference. First operand 127 states. Second operand has 117 states, 92 states have (on average 1.3478260869565217) internal successors, (124), 99 states have internal predecessors, (124), 12 states have call successors, (12), 12 states have call predecessors, (12), 12 states have return successors, (13), 12 states have call predecessors, (13), 12 states have call successors, (13) [2022-02-20 18:05:50,989 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-02-20 18:05:50,990 INFO L93 Difference]: Finished difference Result 127 states and 159 transitions. [2022-02-20 18:05:50,990 INFO L276 IsEmpty]: Start isEmpty. Operand 127 states and 159 transitions. [2022-02-20 18:05:50,991 INFO L282 IsEmpty]: Finished isEmpty. No accepting run. [2022-02-20 18:05:50,991 INFO L83 IsIncluded]: Finished isIncluded. Language is included [2022-02-20 18:05:50,991 INFO L74 IsIncluded]: Start isIncluded. First operand has 117 states, 92 states have (on average 1.3478260869565217) internal successors, (124), 99 states have internal predecessors, (124), 12 states have call successors, (12), 12 states have call predecessors, (12), 12 states have return successors, (13), 12 states have call predecessors, (13), 12 states have call successors, (13) Second operand 127 states. [2022-02-20 18:05:50,992 INFO L87 Difference]: Start difference. First operand has 117 states, 92 states have (on average 1.3478260869565217) internal successors, (124), 99 states have internal predecessors, (124), 12 states have call successors, (12), 12 states have call predecessors, (12), 12 states have return successors, (13), 12 states have call predecessors, (13), 12 states have call successors, (13) Second operand 127 states. [2022-02-20 18:05:50,996 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-02-20 18:05:50,996 INFO L93 Difference]: Finished difference Result 127 states and 159 transitions. [2022-02-20 18:05:50,997 INFO L276 IsEmpty]: Start isEmpty. Operand 127 states and 159 transitions. [2022-02-20 18:05:50,997 INFO L282 IsEmpty]: Finished isEmpty. No accepting run. [2022-02-20 18:05:50,997 INFO L83 IsIncluded]: Finished isIncluded. Language is included [2022-02-20 18:05:50,997 INFO L88 GeneralOperation]: Finished isEquivalent. [2022-02-20 18:05:50,998 INFO L221 AbstractMinimizeNwa]: Finished testing correctness of minimizeSevpa [2022-02-20 18:05:50,998 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 117 states, 92 states have (on average 1.3478260869565217) internal successors, (124), 99 states have internal predecessors, (124), 12 states have call successors, (12), 12 states have call predecessors, (12), 12 states have return successors, (13), 12 states have call predecessors, (13), 12 states have call successors, (13) [2022-02-20 18:05:51,001 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 117 states to 117 states and 149 transitions. [2022-02-20 18:05:51,002 INFO L78 Accepts]: Start accepts. Automaton has 117 states and 149 transitions. Word has length 28 [2022-02-20 18:05:51,002 INFO L84 Accepts]: Finished accepts. word is rejected. [2022-02-20 18:05:51,002 INFO L470 AbstractCegarLoop]: Abstraction has 117 states and 149 transitions. [2022-02-20 18:05:51,003 INFO L471 AbstractCegarLoop]: INTERPOLANT automaton has has 6 states, 6 states have (on average 4.166666666666667) internal successors, (25), 6 states have internal predecessors, (25), 2 states have call successors, (2), 2 states have call predecessors, (2), 1 states have return successors, (1), 1 states have call predecessors, (1), 1 states have call successors, (1) [2022-02-20 18:05:51,003 INFO L276 IsEmpty]: Start isEmpty. Operand 117 states and 149 transitions. [2022-02-20 18:05:51,003 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 30 [2022-02-20 18:05:51,003 INFO L506 BasicCegarLoop]: Found error trace [2022-02-20 18:05:51,004 INFO L514 BasicCegarLoop]: trace histogram [1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-02-20 18:05:51,004 WARN L452 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable2 [2022-02-20 18:05:51,004 INFO L402 AbstractCegarLoop]: === Iteration 4 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2022-02-20 18:05:51,004 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2022-02-20 18:05:51,004 INFO L85 PathProgramCache]: Analyzing trace with hash -871834641, now seen corresponding path program 1 times [2022-02-20 18:05:51,005 INFO L126 FreeRefinementEngine]: Executing refinement strategy CAMEL [2022-02-20 18:05:51,005 INFO L338 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [1131342577] [2022-02-20 18:05:51,005 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-02-20 18:05:51,005 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2022-02-20 18:05:51,055 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-02-20 18:05:51,121 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 20 [2022-02-20 18:05:51,124 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-02-20 18:05:51,133 INFO L290 TraceCheckUtils]: 0: Hoare triple {1385#true} havoc ~retValue_acc~5;~retValue_acc~5 := ~methaneLevelCritical~0;#res := ~retValue_acc~5; {1385#true} is VALID [2022-02-20 18:05:51,133 INFO L290 TraceCheckUtils]: 1: Hoare triple {1385#true} assume true; {1385#true} is VALID [2022-02-20 18:05:51,134 INFO L284 TraceCheckUtils]: 2: Hoare quadruple {1385#true} {1387#(= ~pumpRunning~0 0)} #175#return; {1387#(= ~pumpRunning~0 0)} is VALID [2022-02-20 18:05:51,134 INFO L290 TraceCheckUtils]: 0: Hoare triple {1385#true} assume { :begin_inline_ULTIMATE.init } true;#NULL.base, #NULL.offset := 0, 0;assume 0 == #valid[0];assume 0 < #StackHeapBarrier;call #Ultimate.allocInit(2, 1);call write~init~int(48, 1, 0, 1);call write~init~int(0, 1, 1, 1);call #Ultimate.allocInit(31, 2);call #Ultimate.allocInit(12, 3);call #Ultimate.allocInit(13, 4);call #Ultimate.allocInit(3, 5);call write~init~int(79, 5, 0, 1);call write~init~int(110, 5, 1, 1);call write~init~int(0, 5, 2, 1);call #Ultimate.allocInit(4, 6);call write~init~int(79, 6, 0, 1);call write~init~int(102, 6, 1, 1);call write~init~int(102, 6, 2, 1);call write~init~int(0, 6, 3, 1);call #Ultimate.allocInit(7, 7);call write~init~int(44, 7, 0, 1);call write~init~int(80, 7, 1, 1);call write~init~int(117, 7, 2, 1);call write~init~int(109, 7, 3, 1);call write~init~int(112, 7, 4, 1);call write~init~int(58, 7, 5, 1);call write~init~int(0, 7, 6, 1);call #Ultimate.allocInit(3, 8);call write~init~int(79, 8, 0, 1);call write~init~int(110, 8, 1, 1);call write~init~int(0, 8, 2, 1);call #Ultimate.allocInit(4, 9);call write~init~int(79, 9, 0, 1);call write~init~int(102, 9, 1, 1);call write~init~int(102, 9, 2, 1);call write~init~int(0, 9, 3, 1);call #Ultimate.allocInit(3, 10);call write~init~int(41, 10, 0, 1);call write~init~int(32, 10, 1, 1);call write~init~int(0, 10, 2, 1);call #Ultimate.allocInit(2, 11);call write~init~int(10, 11, 0, 1);call write~init~int(0, 11, 1, 1);call #Ultimate.allocInit(13, 12);call #Ultimate.allocInit(7, 13);call write~init~int(44, 13, 0, 1);call write~init~int(77, 13, 1, 1);call write~init~int(101, 13, 2, 1);call write~init~int(116, 13, 3, 1);call write~init~int(104, 13, 4, 1);call write~init~int(58, 13, 5, 1);call write~init~int(0, 13, 6, 1);call #Ultimate.allocInit(5, 14);call write~init~int(67, 14, 0, 1);call write~init~int(82, 14, 1, 1);call write~init~int(73, 14, 2, 1);call write~init~int(84, 14, 3, 1);call write~init~int(0, 14, 4, 1);call #Ultimate.allocInit(3, 15);call write~init~int(79, 15, 0, 1);call write~init~int(75, 15, 1, 1);call write~init~int(0, 15, 2, 1);call #Ultimate.allocInit(2, 16);call write~init~int(41, 16, 0, 1);call write~init~int(0, 16, 1, 1);call #Ultimate.allocInit(30, 17);call #Ultimate.allocInit(9, 18);call #Ultimate.allocInit(21, 19);call #Ultimate.allocInit(30, 20);call #Ultimate.allocInit(9, 21);call #Ultimate.allocInit(21, 22);call #Ultimate.allocInit(30, 23);call #Ultimate.allocInit(9, 24);call #Ultimate.allocInit(25, 25);call #Ultimate.allocInit(30, 26);call #Ultimate.allocInit(9, 27);call #Ultimate.allocInit(25, 28);~cleanupTimeShifts~0 := 4;~pumpRunning~0 := 0;~systemActive~0 := 1;~waterLevel~0 := 1;~methaneLevelCritical~0 := 0;~head~0.base, ~head~0.offset := 0, 0; {1387#(= ~pumpRunning~0 0)} is VALID [2022-02-20 18:05:51,135 INFO L290 TraceCheckUtils]: 1: Hoare triple {1387#(= ~pumpRunning~0 0)} assume { :end_inline_ULTIMATE.init } true;assume { :begin_inline_main } true;havoc main_#res#1;havoc main_#t~ret4#1, main_~retValue_acc~0#1, main_~tmp~0#1;havoc main_~retValue_acc~0#1;havoc main_~tmp~0#1;assume { :begin_inline_select_helpers } true; {1387#(= ~pumpRunning~0 0)} is VALID [2022-02-20 18:05:51,135 INFO L290 TraceCheckUtils]: 2: Hoare triple {1387#(= ~pumpRunning~0 0)} assume { :end_inline_select_helpers } true;assume { :begin_inline_select_features } true; {1387#(= ~pumpRunning~0 0)} is VALID [2022-02-20 18:05:51,136 INFO L290 TraceCheckUtils]: 3: Hoare triple {1387#(= ~pumpRunning~0 0)} assume { :end_inline_select_features } true;assume { :begin_inline_valid_product } true;havoc valid_product_#res#1;havoc valid_product_~retValue_acc~2#1;havoc valid_product_~retValue_acc~2#1;valid_product_~retValue_acc~2#1 := 1;valid_product_#res#1 := valid_product_~retValue_acc~2#1; {1387#(= ~pumpRunning~0 0)} is VALID [2022-02-20 18:05:51,136 INFO L290 TraceCheckUtils]: 4: Hoare triple {1387#(= ~pumpRunning~0 0)} main_#t~ret4#1 := valid_product_#res#1;assume { :end_inline_valid_product } true;assume -2147483648 <= main_#t~ret4#1 && main_#t~ret4#1 <= 2147483647;main_~tmp~0#1 := main_#t~ret4#1;havoc main_#t~ret4#1; {1387#(= ~pumpRunning~0 0)} is VALID [2022-02-20 18:05:51,136 INFO L290 TraceCheckUtils]: 5: Hoare triple {1387#(= ~pumpRunning~0 0)} assume 0 != main_~tmp~0#1;assume { :begin_inline_setup } true; {1387#(= ~pumpRunning~0 0)} is VALID [2022-02-20 18:05:51,137 INFO L290 TraceCheckUtils]: 6: Hoare triple {1387#(= ~pumpRunning~0 0)} assume { :end_inline_setup } true;assume { :begin_inline_runTest } true;assume { :begin_inline_test } true;havoc test_#t~nondet16#1, test_#t~nondet17#1, test_#t~nondet18#1, test_#t~nondet19#1, test_~splverifierCounter~0#1, test_~tmp~2#1, test_~tmp___0~0#1, test_~tmp___1~0#1, test_~tmp___2~0#1;havoc test_~splverifierCounter~0#1;havoc test_~tmp~2#1;havoc test_~tmp___0~0#1;havoc test_~tmp___1~0#1;havoc test_~tmp___2~0#1;test_~splverifierCounter~0#1 := 0; {1387#(= ~pumpRunning~0 0)} is VALID [2022-02-20 18:05:51,137 INFO L290 TraceCheckUtils]: 7: Hoare triple {1387#(= ~pumpRunning~0 0)} assume !false; {1387#(= ~pumpRunning~0 0)} is VALID [2022-02-20 18:05:51,138 INFO L290 TraceCheckUtils]: 8: Hoare triple {1387#(= ~pumpRunning~0 0)} assume test_~splverifierCounter~0#1 < 4; {1387#(= ~pumpRunning~0 0)} is VALID [2022-02-20 18:05:51,138 INFO L290 TraceCheckUtils]: 9: Hoare triple {1387#(= ~pumpRunning~0 0)} assume -2147483648 <= test_#t~nondet16#1 && test_#t~nondet16#1 <= 2147483647;test_~tmp~2#1 := test_#t~nondet16#1;havoc test_#t~nondet16#1; {1387#(= ~pumpRunning~0 0)} is VALID [2022-02-20 18:05:51,138 INFO L290 TraceCheckUtils]: 10: Hoare triple {1387#(= ~pumpRunning~0 0)} assume !(0 != test_~tmp~2#1); {1387#(= ~pumpRunning~0 0)} is VALID [2022-02-20 18:05:51,139 INFO L290 TraceCheckUtils]: 11: Hoare triple {1387#(= ~pumpRunning~0 0)} assume -2147483648 <= test_#t~nondet17#1 && test_#t~nondet17#1 <= 2147483647;test_~tmp___0~0#1 := test_#t~nondet17#1;havoc test_#t~nondet17#1; {1387#(= ~pumpRunning~0 0)} is VALID [2022-02-20 18:05:51,139 INFO L290 TraceCheckUtils]: 12: Hoare triple {1387#(= ~pumpRunning~0 0)} assume !(0 != test_~tmp___0~0#1); {1387#(= ~pumpRunning~0 0)} is VALID [2022-02-20 18:05:51,139 INFO L290 TraceCheckUtils]: 13: Hoare triple {1387#(= ~pumpRunning~0 0)} assume -2147483648 <= test_#t~nondet18#1 && test_#t~nondet18#1 <= 2147483647;test_~tmp___2~0#1 := test_#t~nondet18#1;havoc test_#t~nondet18#1; {1387#(= ~pumpRunning~0 0)} is VALID [2022-02-20 18:05:51,140 INFO L290 TraceCheckUtils]: 14: Hoare triple {1387#(= ~pumpRunning~0 0)} assume 0 != test_~tmp___2~0#1; {1387#(= ~pumpRunning~0 0)} is VALID [2022-02-20 18:05:51,140 INFO L272 TraceCheckUtils]: 15: Hoare triple {1387#(= ~pumpRunning~0 0)} call timeShift(); {1387#(= ~pumpRunning~0 0)} is VALID [2022-02-20 18:05:51,141 INFO L290 TraceCheckUtils]: 16: Hoare triple {1387#(= ~pumpRunning~0 0)} assume !(0 != ~pumpRunning~0); {1387#(= ~pumpRunning~0 0)} is VALID [2022-02-20 18:05:51,141 INFO L290 TraceCheckUtils]: 17: Hoare triple {1387#(= ~pumpRunning~0 0)} assume 0 != ~systemActive~0;assume { :begin_inline_processEnvironment } true; {1387#(= ~pumpRunning~0 0)} is VALID [2022-02-20 18:05:51,142 INFO L290 TraceCheckUtils]: 18: Hoare triple {1387#(= ~pumpRunning~0 0)} assume { :end_inline_processEnvironment } true; {1387#(= ~pumpRunning~0 0)} is VALID [2022-02-20 18:05:51,142 INFO L290 TraceCheckUtils]: 19: Hoare triple {1387#(= ~pumpRunning~0 0)} assume { :begin_inline___utac_acc__Specification1_spec__1 } true;havoc __utac_acc__Specification1_spec__1_#t~ret25#1, __utac_acc__Specification1_spec__1_#t~ret26#1, __utac_acc__Specification1_spec__1_~tmp~3#1, __utac_acc__Specification1_spec__1_~tmp___0~1#1;havoc __utac_acc__Specification1_spec__1_~tmp~3#1;havoc __utac_acc__Specification1_spec__1_~tmp___0~1#1; {1387#(= ~pumpRunning~0 0)} is VALID [2022-02-20 18:05:51,142 INFO L272 TraceCheckUtils]: 20: Hoare triple {1387#(= ~pumpRunning~0 0)} call __utac_acc__Specification1_spec__1_#t~ret25#1 := isMethaneLevelCritical(); {1385#true} is VALID [2022-02-20 18:05:51,143 INFO L290 TraceCheckUtils]: 21: Hoare triple {1385#true} havoc ~retValue_acc~5;~retValue_acc~5 := ~methaneLevelCritical~0;#res := ~retValue_acc~5; {1385#true} is VALID [2022-02-20 18:05:51,143 INFO L290 TraceCheckUtils]: 22: Hoare triple {1385#true} assume true; {1385#true} is VALID [2022-02-20 18:05:51,144 INFO L284 TraceCheckUtils]: 23: Hoare quadruple {1385#true} {1387#(= ~pumpRunning~0 0)} #175#return; {1387#(= ~pumpRunning~0 0)} is VALID [2022-02-20 18:05:51,144 INFO L290 TraceCheckUtils]: 24: Hoare triple {1387#(= ~pumpRunning~0 0)} assume -2147483648 <= __utac_acc__Specification1_spec__1_#t~ret25#1 && __utac_acc__Specification1_spec__1_#t~ret25#1 <= 2147483647;__utac_acc__Specification1_spec__1_~tmp~3#1 := __utac_acc__Specification1_spec__1_#t~ret25#1;havoc __utac_acc__Specification1_spec__1_#t~ret25#1; {1387#(= ~pumpRunning~0 0)} is VALID [2022-02-20 18:05:51,144 INFO L290 TraceCheckUtils]: 25: Hoare triple {1387#(= ~pumpRunning~0 0)} assume 0 != __utac_acc__Specification1_spec__1_~tmp~3#1;assume { :begin_inline_isPumpRunning } true;havoc isPumpRunning_#res#1;havoc isPumpRunning_~retValue_acc~4#1;havoc isPumpRunning_~retValue_acc~4#1;isPumpRunning_~retValue_acc~4#1 := ~pumpRunning~0;isPumpRunning_#res#1 := isPumpRunning_~retValue_acc~4#1; {1391#(= |timeShift_isPumpRunning_#res#1| 0)} is VALID [2022-02-20 18:05:51,145 INFO L290 TraceCheckUtils]: 26: Hoare triple {1391#(= |timeShift_isPumpRunning_#res#1| 0)} __utac_acc__Specification1_spec__1_#t~ret26#1 := isPumpRunning_#res#1;assume { :end_inline_isPumpRunning } true;assume -2147483648 <= __utac_acc__Specification1_spec__1_#t~ret26#1 && __utac_acc__Specification1_spec__1_#t~ret26#1 <= 2147483647;__utac_acc__Specification1_spec__1_~tmp___0~1#1 := __utac_acc__Specification1_spec__1_#t~ret26#1;havoc __utac_acc__Specification1_spec__1_#t~ret26#1; {1392#(= |timeShift___utac_acc__Specification1_spec__1_~tmp___0~1#1| 0)} is VALID [2022-02-20 18:05:51,145 INFO L290 TraceCheckUtils]: 27: Hoare triple {1392#(= |timeShift___utac_acc__Specification1_spec__1_~tmp___0~1#1| 0)} assume 0 != __utac_acc__Specification1_spec__1_~tmp___0~1#1;assume { :begin_inline___automaton_fail } true; {1386#false} is VALID [2022-02-20 18:05:51,145 INFO L290 TraceCheckUtils]: 28: Hoare triple {1386#false} assume !false; {1386#false} is VALID [2022-02-20 18:05:51,146 INFO L134 CoverageAnalysis]: Checked inductivity of 0 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2022-02-20 18:05:51,146 INFO L144 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2022-02-20 18:05:51,146 INFO L338 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [1131342577] [2022-02-20 18:05:51,146 INFO L165 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [1131342577] provided 1 perfect and 0 imperfect interpolant sequences [2022-02-20 18:05:51,146 INFO L191 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2022-02-20 18:05:51,147 INFO L204 FreeRefinementEngine]: Number of different interpolants: perfect sequences [5] imperfect sequences [] total 5 [2022-02-20 18:05:51,151 INFO L118 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [1960503762] [2022-02-20 18:05:51,151 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2022-02-20 18:05:51,152 INFO L78 Accepts]: Start accepts. Automaton has has 5 states, 5 states have (on average 5.2) internal successors, (26), 5 states have internal predecessors, (26), 1 states have call successors, (2), 2 states have call predecessors, (2), 1 states have return successors, (1), 1 states have call predecessors, (1), 1 states have call successors, (1) Word has length 29 [2022-02-20 18:05:51,152 INFO L84 Accepts]: Finished accepts. word is accepted. [2022-02-20 18:05:51,152 INFO L86 InductivityCheck]: Starting indutivity check of a Floyd-Hoare automaton with has 5 states, 5 states have (on average 5.2) internal successors, (26), 5 states have internal predecessors, (26), 1 states have call successors, (2), 2 states have call predecessors, (2), 1 states have return successors, (1), 1 states have call predecessors, (1), 1 states have call successors, (1) [2022-02-20 18:05:51,172 INFO L122 InductivityCheck]: Floyd-Hoare automaton has 29 edges. 29 inductive. 0 not inductive. 0 times theorem prover too weak to decide inductivity. [2022-02-20 18:05:51,173 INFO L546 AbstractCegarLoop]: INTERPOLANT automaton has 5 states [2022-02-20 18:05:51,173 INFO L108 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2022-02-20 18:05:51,174 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 5 interpolants. [2022-02-20 18:05:51,174 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=7, Invalid=13, Unknown=0, NotChecked=0, Total=20 [2022-02-20 18:05:51,174 INFO L87 Difference]: Start difference. First operand 117 states and 149 transitions. Second operand has 5 states, 5 states have (on average 5.2) internal successors, (26), 5 states have internal predecessors, (26), 1 states have call successors, (2), 2 states have call predecessors, (2), 1 states have return successors, (1), 1 states have call predecessors, (1), 1 states have call successors, (1) [2022-02-20 18:05:51,295 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-02-20 18:05:51,295 INFO L93 Difference]: Finished difference Result 227 states and 294 transitions. [2022-02-20 18:05:51,295 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 5 states. [2022-02-20 18:05:51,296 INFO L78 Accepts]: Start accepts. Automaton has has 5 states, 5 states have (on average 5.2) internal successors, (26), 5 states have internal predecessors, (26), 1 states have call successors, (2), 2 states have call predecessors, (2), 1 states have return successors, (1), 1 states have call predecessors, (1), 1 states have call successors, (1) Word has length 29 [2022-02-20 18:05:51,296 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2022-02-20 18:05:51,297 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 5 states, 5 states have (on average 5.2) internal successors, (26), 5 states have internal predecessors, (26), 1 states have call successors, (2), 2 states have call predecessors, (2), 1 states have return successors, (1), 1 states have call predecessors, (1), 1 states have call successors, (1) [2022-02-20 18:05:51,299 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 5 states to 5 states and 110 transitions. [2022-02-20 18:05:51,299 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 5 states, 5 states have (on average 5.2) internal successors, (26), 5 states have internal predecessors, (26), 1 states have call successors, (2), 2 states have call predecessors, (2), 1 states have return successors, (1), 1 states have call predecessors, (1), 1 states have call successors, (1) [2022-02-20 18:05:51,302 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 5 states to 5 states and 110 transitions. [2022-02-20 18:05:51,302 INFO L86 InductivityCheck]: Starting indutivity check of a Floyd-Hoare automaton with 5 states and 110 transitions. [2022-02-20 18:05:51,372 INFO L122 InductivityCheck]: Floyd-Hoare automaton has 110 edges. 110 inductive. 0 not inductive. 0 times theorem prover too weak to decide inductivity. [2022-02-20 18:05:51,372 INFO L225 Difference]: With dead ends: 227 [2022-02-20 18:05:51,372 INFO L226 Difference]: Without dead ends: 0 [2022-02-20 18:05:51,376 INFO L932 BasicCegarLoop]: 0 DeclaredPredicates, 8 GetRequests, 3 SyntacticMatches, 0 SemanticMatches, 5 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 0 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=17, Invalid=25, Unknown=0, NotChecked=0, Total=42 [2022-02-20 18:05:51,384 INFO L933 BasicCegarLoop]: 49 mSDtfsCounter, 36 mSDsluCounter, 93 mSDsCounter, 0 mSdLazyCounter, 11 mSolverCounterSat, 2 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.0s Time, 0 mProtectedPredicate, 0 mProtectedAction, 36 SdHoareTripleChecker+Valid, 142 SdHoareTripleChecker+Invalid, 13 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 2 IncrementalHoareTripleChecker+Valid, 11 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.0s IncrementalHoareTripleChecker+Time [2022-02-20 18:05:51,386 INFO L934 BasicCegarLoop]: SdHoareTripleChecker [36 Valid, 142 Invalid, 13 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [2 Valid, 11 Invalid, 0 Unknown, 0 Unchecked, 0.0s Time] [2022-02-20 18:05:51,388 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 0 states. [2022-02-20 18:05:51,388 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 0 to 0. [2022-02-20 18:05:51,388 INFO L214 AbstractMinimizeNwa]: Start testing correctness of minimizeSevpa [2022-02-20 18:05:51,388 INFO L82 GeneralOperation]: Start isEquivalent. First operand 0 states. Second operand has 0 states, 0 states have (on average 0.0) internal successors, (0), 0 states have internal predecessors, (0), 0 states have call successors, (0), 0 states have call predecessors, (0), 0 states have return successors, (0), 0 states have call predecessors, (0), 0 states have call successors, (0) [2022-02-20 18:05:51,389 INFO L74 IsIncluded]: Start isIncluded. First operand 0 states. Second operand has 0 states, 0 states have (on average 0.0) internal successors, (0), 0 states have internal predecessors, (0), 0 states have call successors, (0), 0 states have call predecessors, (0), 0 states have return successors, (0), 0 states have call predecessors, (0), 0 states have call successors, (0) [2022-02-20 18:05:51,389 INFO L87 Difference]: Start difference. First operand 0 states. Second operand has 0 states, 0 states have (on average 0.0) internal successors, (0), 0 states have internal predecessors, (0), 0 states have call successors, (0), 0 states have call predecessors, (0), 0 states have return successors, (0), 0 states have call predecessors, (0), 0 states have call successors, (0) [2022-02-20 18:05:51,389 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-02-20 18:05:51,390 INFO L93 Difference]: Finished difference Result 0 states and 0 transitions. [2022-02-20 18:05:51,390 INFO L276 IsEmpty]: Start isEmpty. Operand 0 states and 0 transitions. [2022-02-20 18:05:51,390 INFO L282 IsEmpty]: Finished isEmpty. No accepting run. [2022-02-20 18:05:51,390 INFO L83 IsIncluded]: Finished isIncluded. Language is included [2022-02-20 18:05:51,390 INFO L74 IsIncluded]: Start isIncluded. First operand has 0 states, 0 states have (on average 0.0) internal successors, (0), 0 states have internal predecessors, (0), 0 states have call successors, (0), 0 states have call predecessors, (0), 0 states have return successors, (0), 0 states have call predecessors, (0), 0 states have call successors, (0) Second operand 0 states. [2022-02-20 18:05:51,390 INFO L87 Difference]: Start difference. First operand has 0 states, 0 states have (on average 0.0) internal successors, (0), 0 states have internal predecessors, (0), 0 states have call successors, (0), 0 states have call predecessors, (0), 0 states have return successors, (0), 0 states have call predecessors, (0), 0 states have call successors, (0) Second operand 0 states. [2022-02-20 18:05:51,391 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-02-20 18:05:51,391 INFO L93 Difference]: Finished difference Result 0 states and 0 transitions. [2022-02-20 18:05:51,391 INFO L276 IsEmpty]: Start isEmpty. Operand 0 states and 0 transitions. [2022-02-20 18:05:51,391 INFO L282 IsEmpty]: Finished isEmpty. No accepting run. [2022-02-20 18:05:51,391 INFO L83 IsIncluded]: Finished isIncluded. Language is included [2022-02-20 18:05:51,391 INFO L88 GeneralOperation]: Finished isEquivalent. [2022-02-20 18:05:51,391 INFO L221 AbstractMinimizeNwa]: Finished testing correctness of minimizeSevpa [2022-02-20 18:05:51,392 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 0 states, 0 states have (on average 0.0) internal successors, (0), 0 states have internal predecessors, (0), 0 states have call successors, (0), 0 states have call predecessors, (0), 0 states have return successors, (0), 0 states have call predecessors, (0), 0 states have call successors, (0) [2022-02-20 18:05:51,392 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 0 states to 0 states and 0 transitions. [2022-02-20 18:05:51,392 INFO L78 Accepts]: Start accepts. Automaton has 0 states and 0 transitions. Word has length 29 [2022-02-20 18:05:51,393 INFO L84 Accepts]: Finished accepts. word is rejected. [2022-02-20 18:05:51,393 INFO L470 AbstractCegarLoop]: Abstraction has 0 states and 0 transitions. [2022-02-20 18:05:51,393 INFO L471 AbstractCegarLoop]: INTERPOLANT automaton has has 5 states, 5 states have (on average 5.2) internal successors, (26), 5 states have internal predecessors, (26), 1 states have call successors, (2), 2 states have call predecessors, (2), 1 states have return successors, (1), 1 states have call predecessors, (1), 1 states have call successors, (1) [2022-02-20 18:05:51,394 INFO L276 IsEmpty]: Start isEmpty. Operand 0 states and 0 transitions. [2022-02-20 18:05:51,394 INFO L282 IsEmpty]: Finished isEmpty. No accepting run. [2022-02-20 18:05:51,396 INFO L764 garLoopResultBuilder]: Registering result SAFE for location timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION (0 of 1 remaining) [2022-02-20 18:05:51,397 WARN L452 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable3 [2022-02-20 18:05:51,399 INFO L343 DoubleDeckerVisitor]: Before removal of dead ends 0 states and 0 transitions. [2022-02-20 18:05:51,606 INFO L861 garLoopResultBuilder]: At program point changeMethaneLevelENTRY(lines 440 451) the Hoare annotation is: true [2022-02-20 18:05:51,606 INFO L858 garLoopResultBuilder]: For program point L444-1(lines 440 451) no Hoare annotation was computed. [2022-02-20 18:05:51,606 INFO L858 garLoopResultBuilder]: For program point changeMethaneLevelEXIT(lines 440 451) no Hoare annotation was computed. [2022-02-20 18:05:51,606 INFO L861 garLoopResultBuilder]: At program point isMethaneLevelCriticalENTRY(lines 452 460) the Hoare annotation is: true [2022-02-20 18:05:51,607 INFO L858 garLoopResultBuilder]: For program point isMethaneLevelCriticalFINAL(lines 452 460) no Hoare annotation was computed. [2022-02-20 18:05:51,607 INFO L858 garLoopResultBuilder]: For program point isMethaneLevelCriticalEXIT(lines 452 460) no Hoare annotation was computed. [2022-02-20 18:05:51,607 INFO L858 garLoopResultBuilder]: For program point L506(lines 506 512) no Hoare annotation was computed. [2022-02-20 18:05:51,607 INFO L854 garLoopResultBuilder]: At program point L281(lines 276 284) the Hoare annotation is: (or (not (= ~pumpRunning~0 0)) (= |timeShift_isPumpRunning_#res#1| 0)) [2022-02-20 18:05:51,607 INFO L854 garLoopResultBuilder]: At program point L409(lines 404 411) the Hoare annotation is: (not (= ~pumpRunning~0 0)) [2022-02-20 18:05:51,607 INFO L858 garLoopResultBuilder]: For program point L502(lines 502 515) no Hoare annotation was computed. [2022-02-20 18:05:51,608 INFO L861 garLoopResultBuilder]: At program point L502-1(lines 494 518) the Hoare annotation is: true [2022-02-20 18:05:51,608 INFO L861 garLoopResultBuilder]: At program point L500(line 500) the Hoare annotation is: true [2022-02-20 18:05:51,608 INFO L858 garLoopResultBuilder]: For program point L500-1(line 500) no Hoare annotation was computed. [2022-02-20 18:05:51,608 INFO L858 garLoopResultBuilder]: For program point L211-1(lines 211 217) no Hoare annotation was computed. [2022-02-20 18:05:51,608 INFO L858 garLoopResultBuilder]: For program point timeShiftFINAL(lines 200 223) no Hoare annotation was computed. [2022-02-20 18:05:51,608 INFO L858 garLoopResultBuilder]: For program point L420(lines 420 424) no Hoare annotation was computed. [2022-02-20 18:05:51,609 INFO L854 garLoopResultBuilder]: At program point L228(lines 224 230) the Hoare annotation is: (or (not (= ~pumpRunning~0 0)) (not (= 0 ~systemActive~0))) [2022-02-20 18:05:51,609 INFO L854 garLoopResultBuilder]: At program point L420-2(lines 416 427) the Hoare annotation is: (not (= ~pumpRunning~0 0)) [2022-02-20 18:05:51,609 INFO L858 garLoopResultBuilder]: For program point L408(line 408) no Hoare annotation was computed. [2022-02-20 18:05:51,609 INFO L861 garLoopResultBuilder]: At program point timeShiftENTRY(lines 200 223) the Hoare annotation is: true [2022-02-20 18:05:51,609 INFO L858 garLoopResultBuilder]: For program point L204-1(lines 203 222) no Hoare annotation was computed. [2022-02-20 18:05:51,609 INFO L858 garLoopResultBuilder]: For program point timeShiftEXIT(lines 200 223) no Hoare annotation was computed. [2022-02-20 18:05:51,610 INFO L858 garLoopResultBuilder]: For program point timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION(line 408) no Hoare annotation was computed. [2022-02-20 18:05:51,610 INFO L861 garLoopResultBuilder]: At program point L66-1(lines 66 70) the Hoare annotation is: true [2022-02-20 18:05:51,610 INFO L858 garLoopResultBuilder]: For program point cleanupEXIT(lines 52 81) no Hoare annotation was computed. [2022-02-20 18:05:51,610 INFO L858 garLoopResultBuilder]: For program point L63(line 63) no Hoare annotation was computed. [2022-02-20 18:05:51,610 INFO L861 garLoopResultBuilder]: At program point cleanupENTRY(lines 52 81) the Hoare annotation is: true [2022-02-20 18:05:51,610 INFO L861 garLoopResultBuilder]: At program point L62-2(lines 62 76) the Hoare annotation is: true [2022-02-20 18:05:51,611 INFO L861 garLoopResultBuilder]: At program point L58(line 58) the Hoare annotation is: true [2022-02-20 18:05:51,611 INFO L858 garLoopResultBuilder]: For program point L58-1(line 58) no Hoare annotation was computed. [2022-02-20 18:05:51,611 INFO L861 garLoopResultBuilder]: At program point L77(lines 52 81) the Hoare annotation is: true [2022-02-20 18:05:51,611 INFO L858 garLoopResultBuilder]: For program point L73(line 73) no Hoare annotation was computed. [2022-02-20 18:05:51,611 INFO L858 garLoopResultBuilder]: For program point L66(lines 66 70) no Hoare annotation was computed. [2022-02-20 18:05:51,611 INFO L858 garLoopResultBuilder]: For program point L349(lines 349 353) no Hoare annotation was computed. [2022-02-20 18:05:51,611 INFO L854 garLoopResultBuilder]: At program point L184(lines 179 187) the Hoare annotation is: (and (= ~pumpRunning~0 0) (= 1 ~systemActive~0) (= |ULTIMATE.start_valid_product_#res#1| ~systemActive~0)) [2022-02-20 18:05:51,612 INFO L854 garLoopResultBuilder]: At program point L176(lines 172 178) the Hoare annotation is: (and (= ~pumpRunning~0 0) (= 1 ~systemActive~0)) [2022-02-20 18:05:51,612 INFO L854 garLoopResultBuilder]: At program point L333(lines 321 335) the Hoare annotation is: (and (= ~pumpRunning~0 0) (= |ULTIMATE.start_test_~splverifierCounter~0#1| 0)) [2022-02-20 18:05:51,612 INFO L854 garLoopResultBuilder]: At program point L395(lines 346 396) the Hoare annotation is: false [2022-02-20 18:05:51,612 INFO L858 garLoopResultBuilder]: For program point L325(lines 325 331) no Hoare annotation was computed. [2022-02-20 18:05:51,612 INFO L858 garLoopResultBuilder]: For program point L325-2(lines 325 331) no Hoare annotation was computed. [2022-02-20 18:05:51,612 INFO L858 garLoopResultBuilder]: For program point L-1(line -1) no Hoare annotation was computed. [2022-02-20 18:05:51,612 INFO L858 garLoopResultBuilder]: For program point L383(lines 383 389) no Hoare annotation was computed. [2022-02-20 18:05:51,613 INFO L858 garLoopResultBuilder]: For program point ULTIMATE.startENTRY(line -1) no Hoare annotation was computed. [2022-02-20 18:05:51,613 INFO L854 garLoopResultBuilder]: At program point L383-2(lines 377 390) the Hoare annotation is: (and (= ~pumpRunning~0 0) (= |ULTIMATE.start_test_~splverifierCounter~0#1| 0)) [2022-02-20 18:05:51,613 INFO L858 garLoopResultBuilder]: For program point ULTIMATE.startFINAL(line -1) no Hoare annotation was computed. [2022-02-20 18:05:51,613 INFO L858 garLoopResultBuilder]: For program point L367(lines 367 373) no Hoare annotation was computed. [2022-02-20 18:05:51,613 INFO L858 garLoopResultBuilder]: For program point L367-1(lines 367 373) no Hoare annotation was computed. [2022-02-20 18:05:51,613 INFO L858 garLoopResultBuilder]: For program point L140(lines 140 147) no Hoare annotation was computed. [2022-02-20 18:05:51,613 INFO L858 garLoopResultBuilder]: For program point L140-2(lines 140 147) no Hoare annotation was computed. [2022-02-20 18:05:51,613 INFO L854 garLoopResultBuilder]: At program point L169(lines 165 171) the Hoare annotation is: (and (= ~pumpRunning~0 0) (= 1 ~systemActive~0)) [2022-02-20 18:05:51,614 INFO L854 garLoopResultBuilder]: At program point L392(lines 347 394) the Hoare annotation is: (and (= ~pumpRunning~0 0) (= |ULTIMATE.start_test_~splverifierCounter~0#1| 0)) [2022-02-20 18:05:51,614 INFO L854 garLoopResultBuilder]: At program point L359(line 359) the Hoare annotation is: (and (= ~pumpRunning~0 0) (= |ULTIMATE.start_test_~splverifierCounter~0#1| 0)) [2022-02-20 18:05:51,614 INFO L858 garLoopResultBuilder]: For program point ULTIMATE.startEXIT(line -1) no Hoare annotation was computed. [2022-02-20 18:05:51,614 INFO L861 garLoopResultBuilder]: At program point L124(lines 117 126) the Hoare annotation is: true [2022-02-20 18:05:51,614 INFO L861 garLoopResultBuilder]: At program point L149(lines 130 152) the Hoare annotation is: true [2022-02-20 18:05:51,614 INFO L858 garLoopResultBuilder]: For program point L348(lines 347 394) no Hoare annotation was computed. [2022-02-20 18:05:51,614 INFO L858 garLoopResultBuilder]: For program point L377(lines 377 390) no Hoare annotation was computed. [2022-02-20 18:05:51,615 INFO L854 garLoopResultBuilder]: At program point L113(lines 109 115) the Hoare annotation is: (and (= |ULTIMATE.start_main_~tmp~0#1| ~systemActive~0) (= ~pumpRunning~0 0) (= 1 ~systemActive~0) (= |ULTIMATE.start_valid_product_#res#1| ~systemActive~0)) [2022-02-20 18:05:51,615 INFO L854 garLoopResultBuilder]: At program point L369(line 369) the Hoare annotation is: (and (= ~pumpRunning~0 0) (= |ULTIMATE.start_test_~splverifierCounter~0#1| 0)) [2022-02-20 18:05:51,615 INFO L861 garLoopResultBuilder]: At program point L398(lines 337 402) the Hoare annotation is: true [2022-02-20 18:05:51,615 INFO L854 garLoopResultBuilder]: At program point L262(lines 257 264) the Hoare annotation is: false [2022-02-20 18:05:51,615 INFO L858 garLoopResultBuilder]: For program point L357(lines 357 363) no Hoare annotation was computed. [2022-02-20 18:05:51,615 INFO L858 garLoopResultBuilder]: For program point L357-1(lines 357 363) no Hoare annotation was computed. [2022-02-20 18:05:51,615 INFO L858 garLoopResultBuilder]: For program point L432-1(lines 428 439) no Hoare annotation was computed. [2022-02-20 18:05:51,615 INFO L858 garLoopResultBuilder]: For program point waterRiseEXIT(lines 428 439) no Hoare annotation was computed. [2022-02-20 18:05:51,616 INFO L861 garLoopResultBuilder]: At program point waterRiseENTRY(lines 428 439) the Hoare annotation is: true [2022-02-20 18:05:51,618 INFO L732 BasicCegarLoop]: Path program histogram: [1, 1, 1, 1] [2022-02-20 18:05:51,619 INFO L180 ceAbstractionStarter]: Computing trace abstraction results [2022-02-20 18:05:51,622 WARN L170 areAnnotationChecker]: L444-1 has no Hoare annotation [2022-02-20 18:05:51,622 WARN L170 areAnnotationChecker]: L444-1 has no Hoare annotation [2022-02-20 18:05:51,622 WARN L170 areAnnotationChecker]: isMethaneLevelCriticalFINAL has no Hoare annotation [2022-02-20 18:05:51,622 WARN L170 areAnnotationChecker]: L420 has no Hoare annotation [2022-02-20 18:05:51,623 WARN L170 areAnnotationChecker]: L204-1 has no Hoare annotation [2022-02-20 18:05:51,623 WARN L170 areAnnotationChecker]: ULTIMATE.startENTRY has no Hoare annotation [2022-02-20 18:05:51,623 WARN L170 areAnnotationChecker]: L432-1 has no Hoare annotation [2022-02-20 18:05:51,623 WARN L170 areAnnotationChecker]: L432-1 has no Hoare annotation [2022-02-20 18:05:51,623 WARN L170 areAnnotationChecker]: L444-1 has no Hoare annotation [2022-02-20 18:05:51,623 WARN L170 areAnnotationChecker]: isMethaneLevelCriticalFINAL has no Hoare annotation [2022-02-20 18:05:51,623 WARN L170 areAnnotationChecker]: L420 has no Hoare annotation [2022-02-20 18:05:51,623 WARN L170 areAnnotationChecker]: L420 has no Hoare annotation [2022-02-20 18:05:51,624 WARN L170 areAnnotationChecker]: L204-1 has no Hoare annotation [2022-02-20 18:05:51,624 WARN L170 areAnnotationChecker]: L204-1 has no Hoare annotation [2022-02-20 18:05:51,624 WARN L170 areAnnotationChecker]: L58-1 has no Hoare annotation [2022-02-20 18:05:51,624 WARN L170 areAnnotationChecker]: L-1 has no Hoare annotation [2022-02-20 18:05:51,624 WARN L170 areAnnotationChecker]: L432-1 has no Hoare annotation [2022-02-20 18:05:51,624 WARN L170 areAnnotationChecker]: changeMethaneLevelEXIT has no Hoare annotation [2022-02-20 18:05:51,624 WARN L170 areAnnotationChecker]: isMethaneLevelCriticalEXIT has no Hoare annotation [2022-02-20 18:05:51,624 WARN L170 areAnnotationChecker]: L204-1 has no Hoare annotation [2022-02-20 18:05:51,624 WARN L170 areAnnotationChecker]: L211-1 has no Hoare annotation [2022-02-20 18:05:51,625 WARN L170 areAnnotationChecker]: L211-1 has no Hoare annotation [2022-02-20 18:05:51,625 WARN L170 areAnnotationChecker]: L58-1 has no Hoare annotation [2022-02-20 18:05:51,625 WARN L170 areAnnotationChecker]: waterRiseEXIT has no Hoare annotation [2022-02-20 18:05:51,625 WARN L170 areAnnotationChecker]: L367-1 has no Hoare annotation [2022-02-20 18:05:51,626 WARN L170 areAnnotationChecker]: L500-1 has no Hoare annotation [2022-02-20 18:05:51,626 WARN L170 areAnnotationChecker]: L500-1 has no Hoare annotation [2022-02-20 18:05:51,626 WARN L170 areAnnotationChecker]: L63 has no Hoare annotation [2022-02-20 18:05:51,626 WARN L170 areAnnotationChecker]: L357-1 has no Hoare annotation [2022-02-20 18:05:51,626 WARN L170 areAnnotationChecker]: L377 has no Hoare annotation [2022-02-20 18:05:51,627 WARN L170 areAnnotationChecker]: L377 has no Hoare annotation [2022-02-20 18:05:51,627 WARN L170 areAnnotationChecker]: L502 has no Hoare annotation [2022-02-20 18:05:51,627 WARN L170 areAnnotationChecker]: L502 has no Hoare annotation [2022-02-20 18:05:51,627 WARN L170 areAnnotationChecker]: cleanupEXIT has no Hoare annotation [2022-02-20 18:05:51,627 WARN L170 areAnnotationChecker]: L63 has no Hoare annotation [2022-02-20 18:05:51,627 WARN L170 areAnnotationChecker]: L140 has no Hoare annotation [2022-02-20 18:05:51,627 WARN L170 areAnnotationChecker]: L367 has no Hoare annotation [2022-02-20 18:05:51,627 WARN L170 areAnnotationChecker]: L367 has no Hoare annotation [2022-02-20 18:05:51,628 WARN L170 areAnnotationChecker]: L383 has no Hoare annotation [2022-02-20 18:05:51,628 WARN L170 areAnnotationChecker]: L383 has no Hoare annotation [2022-02-20 18:05:51,628 WARN L170 areAnnotationChecker]: L506 has no Hoare annotation [2022-02-20 18:05:51,628 WARN L170 areAnnotationChecker]: timeShiftFINAL has no Hoare annotation [2022-02-20 18:05:51,628 WARN L170 areAnnotationChecker]: cleanupEXIT has no Hoare annotation [2022-02-20 18:05:51,628 WARN L170 areAnnotationChecker]: L66 has no Hoare annotation [2022-02-20 18:05:51,628 WARN L170 areAnnotationChecker]: L66 has no Hoare annotation [2022-02-20 18:05:51,628 WARN L170 areAnnotationChecker]: L140 has no Hoare annotation [2022-02-20 18:05:51,628 WARN L170 areAnnotationChecker]: L140 has no Hoare annotation [2022-02-20 18:05:51,628 WARN L170 areAnnotationChecker]: L367-1 has no Hoare annotation [2022-02-20 18:05:51,629 WARN L170 areAnnotationChecker]: L348 has no Hoare annotation [2022-02-20 18:05:51,629 WARN L170 areAnnotationChecker]: L325 has no Hoare annotation [2022-02-20 18:05:51,629 WARN L170 areAnnotationChecker]: L325 has no Hoare annotation [2022-02-20 18:05:51,630 WARN L170 areAnnotationChecker]: L506 has no Hoare annotation [2022-02-20 18:05:51,630 WARN L170 areAnnotationChecker]: L506 has no Hoare annotation [2022-02-20 18:05:51,630 WARN L170 areAnnotationChecker]: timeShiftFINAL has no Hoare annotation [2022-02-20 18:05:51,630 WARN L170 areAnnotationChecker]: L73 has no Hoare annotation [2022-02-20 18:05:51,630 WARN L170 areAnnotationChecker]: L140-2 has no Hoare annotation [2022-02-20 18:05:51,631 WARN L170 areAnnotationChecker]: L348 has no Hoare annotation [2022-02-20 18:05:51,631 WARN L170 areAnnotationChecker]: L348 has no Hoare annotation [2022-02-20 18:05:51,631 WARN L170 areAnnotationChecker]: L325-2 has no Hoare annotation [2022-02-20 18:05:51,631 WARN L170 areAnnotationChecker]: L325-2 has no Hoare annotation [2022-02-20 18:05:51,631 WARN L170 areAnnotationChecker]: L408 has no Hoare annotation [2022-02-20 18:05:51,631 WARN L170 areAnnotationChecker]: L408 has no Hoare annotation [2022-02-20 18:05:51,631 WARN L170 areAnnotationChecker]: timeShiftEXIT has no Hoare annotation [2022-02-20 18:05:51,631 WARN L170 areAnnotationChecker]: timeShiftEXIT has no Hoare annotation [2022-02-20 18:05:51,631 WARN L170 areAnnotationChecker]: timeShiftEXIT has no Hoare annotation [2022-02-20 18:05:51,631 WARN L170 areAnnotationChecker]: L140-2 has no Hoare annotation [2022-02-20 18:05:51,631 WARN L170 areAnnotationChecker]: L73 has no Hoare annotation [2022-02-20 18:05:51,632 WARN L170 areAnnotationChecker]: ULTIMATE.startFINAL has no Hoare annotation [2022-02-20 18:05:51,632 WARN L170 areAnnotationChecker]: L349 has no Hoare annotation [2022-02-20 18:05:51,632 WARN L170 areAnnotationChecker]: ULTIMATE.startFINAL has no Hoare annotation [2022-02-20 18:05:51,632 WARN L170 areAnnotationChecker]: L357 has no Hoare annotation [2022-02-20 18:05:51,632 WARN L170 areAnnotationChecker]: L357 has no Hoare annotation [2022-02-20 18:05:51,632 WARN L170 areAnnotationChecker]: L357-1 has no Hoare annotation [2022-02-20 18:05:51,632 INFO L163 areAnnotationChecker]: CFG has 18 edges. 18 inductive. 0 not inductive. 0 times theorem prover too weak to decide inductivity. 0 times interpolants missing. [2022-02-20 18:05:51,642 INFO L202 PluginConnector]: Adding new model de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction CFG 20.02 06:05:51 BoogieIcfgContainer [2022-02-20 18:05:51,643 INFO L132 PluginConnector]: ------------------------ END TraceAbstraction---------------------------- [2022-02-20 18:05:51,643 INFO L113 PluginConnector]: ------------------------Witness Printer---------------------------- [2022-02-20 18:05:51,643 INFO L271 PluginConnector]: Initializing Witness Printer... [2022-02-20 18:05:51,644 INFO L275 PluginConnector]: Witness Printer initialized [2022-02-20 18:05:51,644 INFO L185 PluginConnector]: Executing the observer RCFGCatcher from plugin Witness Printer for "de.uni_freiburg.informatik.ultimate.plugins.generator.rcfgbuilder CFG 20.02 06:05:49" (3/4) ... [2022-02-20 18:05:51,646 INFO L137 WitnessPrinter]: Generating witness for correct program [2022-02-20 18:05:51,650 INFO L354 RCFGBacktranslator]: Ignoring RootEdge to procedure changeMethaneLevel [2022-02-20 18:05:51,650 INFO L354 RCFGBacktranslator]: Ignoring RootEdge to procedure isMethaneLevelCritical [2022-02-20 18:05:51,650 INFO L354 RCFGBacktranslator]: Ignoring RootEdge to procedure timeShift [2022-02-20 18:05:51,650 INFO L354 RCFGBacktranslator]: Ignoring RootEdge to procedure cleanup [2022-02-20 18:05:51,651 INFO L354 RCFGBacktranslator]: Ignoring RootEdge to procedure waterRise [2022-02-20 18:05:51,655 INFO L910 BoogieBacktranslator]: Reduced CFG by removing 46 nodes and edges [2022-02-20 18:05:51,655 INFO L910 BoogieBacktranslator]: Reduced CFG by removing 22 nodes and edges [2022-02-20 18:05:51,655 INFO L910 BoogieBacktranslator]: Reduced CFG by removing 11 nodes and edges [2022-02-20 18:05:51,656 INFO L910 BoogieBacktranslator]: Reduced CFG by removing 5 nodes and edges [2022-02-20 18:05:51,656 INFO L910 BoogieBacktranslator]: Reduced CFG by removing 2 nodes and edges [2022-02-20 18:05:51,656 INFO L910 BoogieBacktranslator]: Reduced CFG by removing 1 nodes and edges [2022-02-20 18:05:51,656 INFO L910 BoogieBacktranslator]: Reduced CFG by removing 1 nodes and edges [2022-02-20 18:05:51,673 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (pumpRunning == 0 && 1 == systemActive) && \result == systemActive [2022-02-20 18:05:51,674 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: ((tmp == systemActive && pumpRunning == 0) && 1 == systemActive) && \result == systemActive [2022-02-20 18:05:51,676 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: !(pumpRunning == 0) || \result == 0 [2022-02-20 18:05:51,689 INFO L141 WitnessManager]: Wrote witness to /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/witness.graphml [2022-02-20 18:05:51,689 INFO L132 PluginConnector]: ------------------------ END Witness Printer---------------------------- [2022-02-20 18:05:51,690 INFO L158 Benchmark]: Toolchain (without parser) took 3400.65ms. Allocated memory was 81.8MB in the beginning and 119.5MB in the end (delta: 37.7MB). Free memory was 57.8MB in the beginning and 59.8MB in the end (delta: -2.1MB). Peak memory consumption was 34.1MB. Max. memory is 16.1GB. [2022-02-20 18:05:51,690 INFO L158 Benchmark]: CDTParser took 0.19ms. Allocated memory is still 81.8MB. Free memory is still 58.0MB. There was no memory consumed. Max. memory is 16.1GB. [2022-02-20 18:05:51,691 INFO L158 Benchmark]: CACSL2BoogieTranslator took 469.39ms. Allocated memory is still 81.8MB. Free memory was 57.8MB in the beginning and 46.7MB in the end (delta: 11.1MB). Peak memory consumption was 12.6MB. Max. memory is 16.1GB. [2022-02-20 18:05:51,691 INFO L158 Benchmark]: Boogie Procedure Inliner took 65.06ms. Allocated memory is still 81.8MB. Free memory was 46.6MB in the beginning and 44.2MB in the end (delta: 2.4MB). Peak memory consumption was 2.1MB. Max. memory is 16.1GB. [2022-02-20 18:05:51,691 INFO L158 Benchmark]: Boogie Preprocessor took 47.67ms. Allocated memory is still 81.8MB. Free memory was 44.2MB in the beginning and 42.7MB in the end (delta: 1.5MB). There was no memory consumed. Max. memory is 16.1GB. [2022-02-20 18:05:51,691 INFO L158 Benchmark]: RCFGBuilder took 433.96ms. Allocated memory was 81.8MB in the beginning and 98.6MB in the end (delta: 16.8MB). Free memory was 42.7MB in the beginning and 65.5MB in the end (delta: -22.8MB). Peak memory consumption was 10.9MB. Max. memory is 16.1GB. [2022-02-20 18:05:51,692 INFO L158 Benchmark]: TraceAbstraction took 2329.06ms. Allocated memory was 98.6MB in the beginning and 119.5MB in the end (delta: 21.0MB). Free memory was 64.9MB in the beginning and 64.0MB in the end (delta: 844.5kB). Peak memory consumption was 20.4MB. Max. memory is 16.1GB. [2022-02-20 18:05:51,692 INFO L158 Benchmark]: Witness Printer took 46.01ms. Allocated memory is still 119.5MB. Free memory was 64.0MB in the beginning and 59.8MB in the end (delta: 4.2MB). Peak memory consumption was 4.2MB. Max. memory is 16.1GB. [2022-02-20 18:05:51,693 INFO L339 ainManager$Toolchain]: ####################### End [Toolchain 1] ####################### --- Results --- * Results from de.uni_freiburg.informatik.ultimate.core: - AssertionsEnabledResult: Assertions are enabled Assertions are enabled - StatisticsResult: Toolchain Benchmarks Benchmark results are: * CDTParser took 0.19ms. Allocated memory is still 81.8MB. Free memory is still 58.0MB. There was no memory consumed. Max. memory is 16.1GB. * CACSL2BoogieTranslator took 469.39ms. Allocated memory is still 81.8MB. Free memory was 57.8MB in the beginning and 46.7MB in the end (delta: 11.1MB). Peak memory consumption was 12.6MB. Max. memory is 16.1GB. * Boogie Procedure Inliner took 65.06ms. Allocated memory is still 81.8MB. Free memory was 46.6MB in the beginning and 44.2MB in the end (delta: 2.4MB). Peak memory consumption was 2.1MB. Max. memory is 16.1GB. * Boogie Preprocessor took 47.67ms. Allocated memory is still 81.8MB. Free memory was 44.2MB in the beginning and 42.7MB in the end (delta: 1.5MB). There was no memory consumed. Max. memory is 16.1GB. * RCFGBuilder took 433.96ms. Allocated memory was 81.8MB in the beginning and 98.6MB in the end (delta: 16.8MB). Free memory was 42.7MB in the beginning and 65.5MB in the end (delta: -22.8MB). Peak memory consumption was 10.9MB. Max. memory is 16.1GB. * TraceAbstraction took 2329.06ms. Allocated memory was 98.6MB in the beginning and 119.5MB in the end (delta: 21.0MB). Free memory was 64.9MB in the beginning and 64.0MB in the end (delta: 844.5kB). Peak memory consumption was 20.4MB. Max. memory is 16.1GB. * Witness Printer took 46.01ms. Allocated memory is still 119.5MB. Free memory was 64.0MB in the beginning and 59.8MB in the end (delta: 4.2MB). Peak memory consumption was 4.2MB. Max. memory is 16.1GB. * Results from de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction: - StatisticsResult: ErrorAutomatonStatistics NumberErrorTraces: 0, NumberStatementsAllTraces: 0, NumberRelevantStatements: 0, 0.0s ErrorAutomatonConstructionTimeTotal, 0.0s FaulLocalizationTime, NumberStatementsFirstTrace: -1, TraceLengthAvg: 0, 0.0s ErrorAutomatonConstructionTimeAvg, 0.0s ErrorAutomatonDifferenceTimeAvg, 0.0s ErrorAutomatonDifferenceTimeTotal, NumberOfNoEnhancement: 0, NumberOfFiniteEnhancement: 0, NumberOfInfiniteEnhancement: 0 - PositiveResult [Line: 408]: call to reach_error is unreachable For all program executions holds that call to reach_error is unreachable at this location - StatisticsResult: Ultimate Automizer benchmark data CFG has 6 procedures, 66 locations, 1 error locations. Started 1 CEGAR loops. OverallTime: 2.3s, OverallIterations: 4, TraceHistogramMax: 1, PathProgramHistogramMax: 1, EmptinessCheckTime: 0.0s, AutomataDifference: 1.2s, DeadEndRemovalTime: 0.0s, HoareAnnotationTime: 0.2s, InitialAbstractionConstructionTime: 0.0s, PartialOrderReductionTime: 0.0s, HoareTripleCheckerStatistics: 0 mSolverCounterUnknown, 184 SdHoareTripleChecker+Valid, 0.1s IncrementalHoareTripleChecker+Time, 0 mSdLazyCounter, 181 mSDsluCounter, 641 SdHoareTripleChecker+Invalid, 0.1s Time, 0 mProtectedAction, 0 SdHoareTripleChecker+Unchecked, 0 IncrementalHoareTripleChecker+Unchecked, 392 mSDsCounter, 13 IncrementalHoareTripleChecker+Valid, 0 mProtectedPredicate, 62 IncrementalHoareTripleChecker+Invalid, 75 SdHoareTripleChecker+Unknown, 0 mSolverCounterNotChecked, 13 mSolverCounterUnsat, 249 mSDtfsCounter, 62 mSolverCounterSat, 0.0s SdHoareTripleChecker+Time, 0 IncrementalHoareTripleChecker+Unknown, PredicateUnifierStatistics: 0 DeclaredPredicates, 26 GetRequests, 14 SyntacticMatches, 0 SemanticMatches, 12 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 0 ImplicationChecksByTransitivity, 0.0s Time, 0.0s BasicInterpolantAutomatonTime, BiggestAbstraction: size=117occurred in iteration=3, InterpolantAutomatonStates: 16, traceCheckStatistics: No data available, InterpolantConsolidationStatistics: No data available, PathInvariantsStatistics: No data available, 0/0 InterpolantCoveringCapability, TotalInterpolationStatistics: No data available, 0.0s DumpTime, AutomataMinimizationStatistics: 0.1s AutomataMinimizationTime, 4 MinimizatonAttempts, 10 StatesRemovedByMinimization, 1 NontrivialMinimizations, HoareAnnotationStatistics: 0.0s HoareAnnotationTime, 29 LocationsWithAnnotation, 133 PreInvPairs, 169 NumberOfFragments, 113 HoareAnnotationTreeSize, 133 FomulaSimplifications, 42 FormulaSimplificationTreeSizeReduction, 0.1s HoareSimplificationTime, 29 FomulaSimplificationsInter, 458 FormulaSimplificationTreeSizeReductionInter, 0.1s HoareSimplificationTimeInter, RefinementEngineStatistics: TRACE_CHECK: 0.0s SsaConstructionTime, 0.1s SatisfiabilityAnalysisTime, 0.3s InterpolantComputationTime, 104 NumberOfCodeBlocks, 104 NumberOfCodeBlocksAsserted, 4 NumberOfCheckSat, 100 ConstructedInterpolants, 0 QuantifiedInterpolants, 198 SizeOfPredicates, 0 NumberOfNonLiveVariables, 0 ConjunctsInSsa, 0 ConjunctsInUnsatCore, 4 InterpolantComputations, 4 PerfectInterpolantSequences, 0/0 InterpolantCoveringCapability, INVARIANT_SYNTHESIS: No data available, INTERPOLANT_CONSOLIDATION: No data available, ABSTRACT_INTERPRETATION: No data available, PDR: No data available, ACCELERATED_INTERPOLATION: No data available, SIFA: No data available, ReuseStatistics: No data available - AllSpecificationsHoldResult: All specifications hold 1 specifications checked. All of them hold - InvariantResult [Line: 52]: Loop Invariant Derived loop invariant: 1 - InvariantResult [Line: 404]: Loop Invariant Derived loop invariant: !(pumpRunning == 0) - InvariantResult [Line: 276]: Loop Invariant Derived loop invariant: !(pumpRunning == 0) || \result == 0 - InvariantResult [Line: 224]: Loop Invariant Derived loop invariant: !(pumpRunning == 0) || !(0 == systemActive) - InvariantResult [Line: 130]: Loop Invariant Derived loop invariant: 1 - InvariantResult [Line: 257]: Loop Invariant Derived loop invariant: 0 - InvariantResult [Line: 165]: Loop Invariant Derived loop invariant: pumpRunning == 0 && 1 == systemActive - InvariantResult [Line: 416]: Loop Invariant Derived loop invariant: !(pumpRunning == 0) - InvariantResult [Line: 172]: Loop Invariant Derived loop invariant: pumpRunning == 0 && 1 == systemActive - InvariantResult [Line: 109]: Loop Invariant Derived loop invariant: ((tmp == systemActive && pumpRunning == 0) && 1 == systemActive) && \result == systemActive - InvariantResult [Line: 321]: Loop Invariant Derived loop invariant: pumpRunning == 0 && splverifierCounter == 0 - InvariantResult [Line: 62]: Loop Invariant Derived loop invariant: 1 - InvariantResult [Line: 117]: Loop Invariant Derived loop invariant: 1 - InvariantResult [Line: 494]: Loop Invariant Derived loop invariant: 1 - InvariantResult [Line: 347]: Loop Invariant Derived loop invariant: pumpRunning == 0 && splverifierCounter == 0 - InvariantResult [Line: 337]: Loop Invariant Derived loop invariant: 1 - InvariantResult [Line: 346]: Loop Invariant Derived loop invariant: 0 - InvariantResult [Line: 179]: Loop Invariant Derived loop invariant: (pumpRunning == 0 && 1 == systemActive) && \result == systemActive RESULT: Ultimate proved your program to be correct! [2022-02-20 18:05:51,728 INFO L552 MonitoredProcess]: [MP /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in -t:2000 (1)] Ended with exit code 0 Received shutdown request... --- End real Ultimate output --- Execution finished normally Writing output log to file Ultimate.log Result: TRUE