./Ultimate.py --spec ../sv-benchmarks/c/properties/unreach-call.prp --file ../sv-benchmarks/c/product-lines/minepump_spec2_product30.cil.c --full-output -ea --architecture 32bit -------------------------------------------------------------------------------- Checking for ERROR reachability Using default analysis Version 03d7b7b3 Calling Ultimate with: /usr/bin/java -Dosgi.configuration.area=/storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/data/config -Xmx15G -Xms4m -ea -jar /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/plugins/org.eclipse.equinox.launcher_1.5.800.v20200727-1323.jar -data @noDefault -ultimatedata /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/data -tc /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/config/AutomizerReach.xml -i ../sv-benchmarks/c/product-lines/minepump_spec2_product30.cil.c -s /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/config/svcomp-Reach-32bit-Automizer_Default.epf --cacsl2boogietranslator.entry.function main --witnessprinter.witness.directory /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux --witnessprinter.witness.filename witness.graphml --witnessprinter.write.witness.besides.input.file false --witnessprinter.graph.data.specification CHECK( init(main()), LTL(G ! call(reach_error())) ) --witnessprinter.graph.data.producer Automizer --witnessprinter.graph.data.architecture 32bit --witnessprinter.graph.data.programhash b2bdcdf2450fe12dc31eba38670a2ad19cdc8c29d88388843515301032876b8f --- Real Ultimate output --- This is Ultimate 0.2.2-dev-03d7b7b [2022-02-20 18:07:28,096 INFO L177 SettingsManager]: Resetting all preferences to default values... [2022-02-20 18:07:28,099 INFO L181 SettingsManager]: Resetting UltimateCore preferences to default values [2022-02-20 18:07:28,139 INFO L184 SettingsManager]: Ultimate Commandline Interface provides no preferences, ignoring... [2022-02-20 18:07:28,140 INFO L181 SettingsManager]: Resetting Boogie Preprocessor preferences to default values [2022-02-20 18:07:28,143 INFO L181 SettingsManager]: Resetting Boogie Procedure Inliner preferences to default values [2022-02-20 18:07:28,145 INFO L181 SettingsManager]: Resetting Abstract Interpretation preferences to default values [2022-02-20 18:07:28,147 INFO L181 SettingsManager]: Resetting LassoRanker preferences to default values [2022-02-20 18:07:28,149 INFO L181 SettingsManager]: Resetting Reaching Definitions preferences to default values [2022-02-20 18:07:28,153 INFO L181 SettingsManager]: Resetting SyntaxChecker preferences to default values [2022-02-20 18:07:28,153 INFO L181 SettingsManager]: Resetting Sifa preferences to default values [2022-02-20 18:07:28,154 INFO L184 SettingsManager]: Büchi Program Product provides no preferences, ignoring... [2022-02-20 18:07:28,155 INFO L181 SettingsManager]: Resetting LTL2Aut preferences to default values [2022-02-20 18:07:28,157 INFO L181 SettingsManager]: Resetting PEA to Boogie preferences to default values [2022-02-20 18:07:28,158 INFO L181 SettingsManager]: Resetting BlockEncodingV2 preferences to default values [2022-02-20 18:07:28,161 INFO L181 SettingsManager]: Resetting ChcToBoogie preferences to default values [2022-02-20 18:07:28,162 INFO L181 SettingsManager]: Resetting AutomataScriptInterpreter preferences to default values [2022-02-20 18:07:28,162 INFO L181 SettingsManager]: Resetting BuchiAutomizer preferences to default values [2022-02-20 18:07:28,164 INFO L181 SettingsManager]: Resetting CACSL2BoogieTranslator preferences to default values [2022-02-20 18:07:28,169 INFO L181 SettingsManager]: Resetting CodeCheck preferences to default values [2022-02-20 18:07:28,171 INFO L181 SettingsManager]: Resetting InvariantSynthesis preferences to default values [2022-02-20 18:07:28,172 INFO L181 SettingsManager]: Resetting RCFGBuilder preferences to default values [2022-02-20 18:07:28,173 INFO L181 SettingsManager]: Resetting Referee preferences to default values [2022-02-20 18:07:28,174 INFO L181 SettingsManager]: Resetting TraceAbstraction preferences to default values [2022-02-20 18:07:28,179 INFO L184 SettingsManager]: TraceAbstractionConcurrent provides no preferences, ignoring... [2022-02-20 18:07:28,180 INFO L184 SettingsManager]: TraceAbstractionWithAFAs provides no preferences, ignoring... [2022-02-20 18:07:28,180 INFO L181 SettingsManager]: Resetting TreeAutomizer preferences to default values [2022-02-20 18:07:28,181 INFO L181 SettingsManager]: Resetting IcfgToChc preferences to default values [2022-02-20 18:07:28,182 INFO L181 SettingsManager]: Resetting IcfgTransformer preferences to default values [2022-02-20 18:07:28,182 INFO L184 SettingsManager]: ReqToTest provides no preferences, ignoring... [2022-02-20 18:07:28,183 INFO L181 SettingsManager]: Resetting Boogie Printer preferences to default values [2022-02-20 18:07:28,183 INFO L181 SettingsManager]: Resetting ChcSmtPrinter preferences to default values [2022-02-20 18:07:28,185 INFO L181 SettingsManager]: Resetting ReqPrinter preferences to default values [2022-02-20 18:07:28,186 INFO L181 SettingsManager]: Resetting Witness Printer preferences to default values [2022-02-20 18:07:28,187 INFO L184 SettingsManager]: Boogie PL CUP Parser provides no preferences, ignoring... [2022-02-20 18:07:28,187 INFO L181 SettingsManager]: Resetting CDTParser preferences to default values [2022-02-20 18:07:28,188 INFO L184 SettingsManager]: AutomataScriptParser provides no preferences, ignoring... [2022-02-20 18:07:28,189 INFO L184 SettingsManager]: ReqParser provides no preferences, ignoring... [2022-02-20 18:07:28,189 INFO L181 SettingsManager]: Resetting SmtParser preferences to default values [2022-02-20 18:07:28,190 INFO L181 SettingsManager]: Resetting Witness Parser preferences to default values [2022-02-20 18:07:28,190 INFO L188 SettingsManager]: Finished resetting all preferences to default values... [2022-02-20 18:07:28,191 INFO L101 SettingsManager]: Beginning loading settings from /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/config/svcomp-Reach-32bit-Automizer_Default.epf [2022-02-20 18:07:28,217 INFO L113 SettingsManager]: Loading preferences was successful [2022-02-20 18:07:28,217 INFO L115 SettingsManager]: Preferences different from defaults after loading the file: [2022-02-20 18:07:28,218 INFO L136 SettingsManager]: Preferences of UltimateCore differ from their defaults: [2022-02-20 18:07:28,218 INFO L138 SettingsManager]: * Log level for class=de.uni_freiburg.informatik.ultimate.lib.smtlibutils.quantifier.QuantifierPusher=ERROR; [2022-02-20 18:07:28,219 INFO L136 SettingsManager]: Preferences of Boogie Procedure Inliner differ from their defaults: [2022-02-20 18:07:28,219 INFO L138 SettingsManager]: * Ignore calls to procedures called more than once=ONLY_FOR_SEQUENTIAL_PROGRAMS [2022-02-20 18:07:28,220 INFO L136 SettingsManager]: Preferences of BlockEncodingV2 differ from their defaults: [2022-02-20 18:07:28,220 INFO L138 SettingsManager]: * Create parallel compositions if possible=false [2022-02-20 18:07:28,220 INFO L138 SettingsManager]: * Use SBE=true [2022-02-20 18:07:28,220 INFO L136 SettingsManager]: Preferences of CACSL2BoogieTranslator differ from their defaults: [2022-02-20 18:07:28,221 INFO L138 SettingsManager]: * sizeof long=4 [2022-02-20 18:07:28,221 INFO L138 SettingsManager]: * Overapproximate operations on floating types=true [2022-02-20 18:07:28,222 INFO L138 SettingsManager]: * sizeof POINTER=4 [2022-02-20 18:07:28,222 INFO L138 SettingsManager]: * Check division by zero=IGNORE [2022-02-20 18:07:28,222 INFO L138 SettingsManager]: * Pointer to allocated memory at dereference=IGNORE [2022-02-20 18:07:28,222 INFO L138 SettingsManager]: * If two pointers are subtracted or compared they have the same base address=IGNORE [2022-02-20 18:07:28,222 INFO L138 SettingsManager]: * Check array bounds for arrays that are off heap=IGNORE [2022-02-20 18:07:28,222 INFO L138 SettingsManager]: * sizeof long double=12 [2022-02-20 18:07:28,222 INFO L138 SettingsManager]: * Check if freed pointer was valid=false [2022-02-20 18:07:28,222 INFO L138 SettingsManager]: * Use constant arrays=true [2022-02-20 18:07:28,223 INFO L138 SettingsManager]: * Pointer base address is valid at dereference=IGNORE [2022-02-20 18:07:28,223 INFO L136 SettingsManager]: Preferences of RCFGBuilder differ from their defaults: [2022-02-20 18:07:28,223 INFO L138 SettingsManager]: * Size of a code block=SequenceOfStatements [2022-02-20 18:07:28,223 INFO L138 SettingsManager]: * SMT solver=External_DefaultMode [2022-02-20 18:07:28,223 INFO L138 SettingsManager]: * Command for external solver=z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in -t:2000 [2022-02-20 18:07:28,223 INFO L136 SettingsManager]: Preferences of TraceAbstraction differ from their defaults: [2022-02-20 18:07:28,224 INFO L138 SettingsManager]: * Compute Interpolants along a Counterexample=FPandBP [2022-02-20 18:07:28,224 INFO L138 SettingsManager]: * Positions where we compute the Hoare Annotation=LoopsAndPotentialCycles [2022-02-20 18:07:28,224 INFO L138 SettingsManager]: * Trace refinement strategy=CAMEL [2022-02-20 18:07:28,224 INFO L138 SettingsManager]: * Command for external solver=z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in [2022-02-20 18:07:28,224 INFO L138 SettingsManager]: * Large block encoding in concurrent analysis=OFF [2022-02-20 18:07:28,225 INFO L138 SettingsManager]: * Automaton type used in concurrency analysis=PETRI_NET [2022-02-20 18:07:28,225 INFO L138 SettingsManager]: * Compute Hoare Annotation of negated interpolant automaton, abstraction and CFG=true [2022-02-20 18:07:28,225 INFO L138 SettingsManager]: * SMT solver=External_ModelsAndUnsatCoreMode WARNING: An illegal reflective access operation has occurred WARNING: Illegal reflective access by com.sun.xml.bind.v2.runtime.reflect.opt.Injector$1 (file:/storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/plugins/com.sun.xml.bind_2.2.0.v201505121915.jar) to method java.lang.ClassLoader.defineClass(java.lang.String,byte[],int,int) WARNING: Please consider reporting this to the maintainers of com.sun.xml.bind.v2.runtime.reflect.opt.Injector$1 WARNING: Use --illegal-access=warn to enable warnings of further illegal reflective access operations WARNING: All illegal access operations will be denied in a future release Applying setting for plugin de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator: Entry function -> main Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Witness directory -> /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Witness filename -> witness.graphml Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Write witness besides input file -> false Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Graph data specification -> CHECK( init(main()), LTL(G ! call(reach_error())) ) Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Graph data producer -> Automizer Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Graph data architecture -> 32bit Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Graph data programhash -> b2bdcdf2450fe12dc31eba38670a2ad19cdc8c29d88388843515301032876b8f [2022-02-20 18:07:28,441 INFO L75 nceAwareModelManager]: Repository-Root is: /tmp [2022-02-20 18:07:28,460 INFO L261 ainManager$Toolchain]: [Toolchain 1]: Applicable parser(s) successfully (re)initialized [2022-02-20 18:07:28,463 INFO L217 ainManager$Toolchain]: [Toolchain 1]: Toolchain selected. [2022-02-20 18:07:28,463 INFO L271 PluginConnector]: Initializing CDTParser... [2022-02-20 18:07:28,464 INFO L275 PluginConnector]: CDTParser initialized [2022-02-20 18:07:28,465 INFO L432 ainManager$Toolchain]: [Toolchain 1]: Parsing single file: /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/../sv-benchmarks/c/product-lines/minepump_spec2_product30.cil.c [2022-02-20 18:07:28,532 INFO L220 CDTParser]: Created temporary CDT project at /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/data/d0a70be4d/e31442df148d4e2ab2da6e538794a777/FLAGd81f9fc66 [2022-02-20 18:07:28,926 INFO L306 CDTParser]: Found 1 translation units. [2022-02-20 18:07:28,926 INFO L160 CDTParser]: Scanning /storage/repos/ultimate/releaseScripts/default/sv-benchmarks/c/product-lines/minepump_spec2_product30.cil.c [2022-02-20 18:07:28,939 INFO L349 CDTParser]: About to delete temporary CDT project at /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/data/d0a70be4d/e31442df148d4e2ab2da6e538794a777/FLAGd81f9fc66 [2022-02-20 18:07:28,950 INFO L357 CDTParser]: Successfully deleted /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/data/d0a70be4d/e31442df148d4e2ab2da6e538794a777 [2022-02-20 18:07:28,952 INFO L299 ainManager$Toolchain]: ####################### [Toolchain 1] ####################### [2022-02-20 18:07:28,956 INFO L131 ToolchainWalker]: Walking toolchain with 6 elements. [2022-02-20 18:07:28,957 INFO L113 PluginConnector]: ------------------------CACSL2BoogieTranslator---------------------------- [2022-02-20 18:07:28,957 INFO L271 PluginConnector]: Initializing CACSL2BoogieTranslator... [2022-02-20 18:07:28,960 INFO L275 PluginConnector]: CACSL2BoogieTranslator initialized [2022-02-20 18:07:28,961 INFO L185 PluginConnector]: Executing the observer ACSLObjectContainerObserver from plugin CACSL2BoogieTranslator for "CDTParser AST 20.02 06:07:28" (1/1) ... [2022-02-20 18:07:28,962 INFO L205 PluginConnector]: Invalid model from CACSL2BoogieTranslator for observer de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator.ACSLObjectContainerObserver@7d002544 and model type de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 20.02 06:07:28, skipping insertion in model container [2022-02-20 18:07:28,962 INFO L185 PluginConnector]: Executing the observer CACSL2BoogieTranslatorObserver from plugin CACSL2BoogieTranslator for "CDTParser AST 20.02 06:07:28" (1/1) ... [2022-02-20 18:07:28,968 INFO L145 MainTranslator]: Starting translation in SV-COMP mode [2022-02-20 18:07:29,000 INFO L178 MainTranslator]: Built tables and reachable declarations [2022-02-20 18:07:29,246 WARN L230 ndardFunctionHandler]: Function reach_error is already implemented but we override the implementation for the call at /storage/repos/ultimate/releaseScripts/default/sv-benchmarks/c/product-lines/minepump_spec2_product30.cil.c[17982,17995] [2022-02-20 18:07:29,250 INFO L210 PostProcessor]: Analyzing one entry point: main [2022-02-20 18:07:29,266 INFO L203 MainTranslator]: Completed pre-run [2022-02-20 18:07:29,326 WARN L230 ndardFunctionHandler]: Function reach_error is already implemented but we override the implementation for the call at /storage/repos/ultimate/releaseScripts/default/sv-benchmarks/c/product-lines/minepump_spec2_product30.cil.c[17982,17995] [2022-02-20 18:07:29,328 INFO L210 PostProcessor]: Analyzing one entry point: main [2022-02-20 18:07:29,342 INFO L208 MainTranslator]: Completed translation [2022-02-20 18:07:29,343 INFO L202 PluginConnector]: Adding new model de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 20.02 06:07:29 WrapperNode [2022-02-20 18:07:29,343 INFO L132 PluginConnector]: ------------------------ END CACSL2BoogieTranslator---------------------------- [2022-02-20 18:07:29,344 INFO L113 PluginConnector]: ------------------------Boogie Procedure Inliner---------------------------- [2022-02-20 18:07:29,344 INFO L271 PluginConnector]: Initializing Boogie Procedure Inliner... [2022-02-20 18:07:29,344 INFO L275 PluginConnector]: Boogie Procedure Inliner initialized [2022-02-20 18:07:29,349 INFO L185 PluginConnector]: Executing the observer TypeChecker from plugin Boogie Procedure Inliner for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 20.02 06:07:29" (1/1) ... [2022-02-20 18:07:29,361 INFO L185 PluginConnector]: Executing the observer Inliner from plugin Boogie Procedure Inliner for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 20.02 06:07:29" (1/1) ... [2022-02-20 18:07:29,389 INFO L137 Inliner]: procedures = 56, calls = 157, calls flagged for inlining = 21, calls inlined = 17, statements flattened = 233 [2022-02-20 18:07:29,389 INFO L132 PluginConnector]: ------------------------ END Boogie Procedure Inliner---------------------------- [2022-02-20 18:07:29,390 INFO L113 PluginConnector]: ------------------------Boogie Preprocessor---------------------------- [2022-02-20 18:07:29,390 INFO L271 PluginConnector]: Initializing Boogie Preprocessor... [2022-02-20 18:07:29,390 INFO L275 PluginConnector]: Boogie Preprocessor initialized [2022-02-20 18:07:29,397 INFO L185 PluginConnector]: Executing the observer EnsureBoogieModelObserver from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 20.02 06:07:29" (1/1) ... [2022-02-20 18:07:29,397 INFO L185 PluginConnector]: Executing the observer TypeChecker from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 20.02 06:07:29" (1/1) ... [2022-02-20 18:07:29,399 INFO L185 PluginConnector]: Executing the observer ConstExpander from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 20.02 06:07:29" (1/1) ... [2022-02-20 18:07:29,399 INFO L185 PluginConnector]: Executing the observer StructExpander from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 20.02 06:07:29" (1/1) ... [2022-02-20 18:07:29,404 INFO L185 PluginConnector]: Executing the observer UnstructureCode from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 20.02 06:07:29" (1/1) ... [2022-02-20 18:07:29,408 INFO L185 PluginConnector]: Executing the observer FunctionInliner from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 20.02 06:07:29" (1/1) ... [2022-02-20 18:07:29,409 INFO L185 PluginConnector]: Executing the observer BoogieSymbolTableConstructor from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 20.02 06:07:29" (1/1) ... [2022-02-20 18:07:29,411 INFO L132 PluginConnector]: ------------------------ END Boogie Preprocessor---------------------------- [2022-02-20 18:07:29,424 INFO L113 PluginConnector]: ------------------------RCFGBuilder---------------------------- [2022-02-20 18:07:29,424 INFO L271 PluginConnector]: Initializing RCFGBuilder... [2022-02-20 18:07:29,424 INFO L275 PluginConnector]: RCFGBuilder initialized [2022-02-20 18:07:29,425 INFO L185 PluginConnector]: Executing the observer RCFGBuilderObserver from plugin RCFGBuilder for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 20.02 06:07:29" (1/1) ... [2022-02-20 18:07:29,431 INFO L173 SolverBuilder]: Constructing external solver with command: z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in -t:2000 [2022-02-20 18:07:29,440 INFO L189 MonitoredProcess]: No working directory specified, using /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 [2022-02-20 18:07:29,455 INFO L229 MonitoredProcess]: Starting monitored process 1 with /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in -t:2000 (exit command is (exit), workingDir is null) [2022-02-20 18:07:29,467 INFO L327 MonitoredProcess]: [MP /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in -t:2000 (1)] Waiting until timeout for monitored process [2022-02-20 18:07:29,486 INFO L130 BoogieDeclarations]: Found specification of procedure #Ultimate.allocInit [2022-02-20 18:07:29,486 INFO L130 BoogieDeclarations]: Found specification of procedure processEnvironment__wrappee__base [2022-02-20 18:07:29,487 INFO L138 BoogieDeclarations]: Found implementation of procedure processEnvironment__wrappee__base [2022-02-20 18:07:29,487 INFO L130 BoogieDeclarations]: Found specification of procedure isMethaneLevelCritical [2022-02-20 18:07:29,487 INFO L138 BoogieDeclarations]: Found implementation of procedure isMethaneLevelCritical [2022-02-20 18:07:29,487 INFO L130 BoogieDeclarations]: Found specification of procedure timeShift [2022-02-20 18:07:29,487 INFO L138 BoogieDeclarations]: Found implementation of procedure timeShift [2022-02-20 18:07:29,487 INFO L130 BoogieDeclarations]: Found specification of procedure cleanup [2022-02-20 18:07:29,488 INFO L138 BoogieDeclarations]: Found implementation of procedure cleanup [2022-02-20 18:07:29,488 INFO L130 BoogieDeclarations]: Found specification of procedure waterRise [2022-02-20 18:07:29,488 INFO L138 BoogieDeclarations]: Found implementation of procedure waterRise [2022-02-20 18:07:29,488 INFO L130 BoogieDeclarations]: Found specification of procedure processEnvironment__wrappee__methaneQuery [2022-02-20 18:07:29,488 INFO L138 BoogieDeclarations]: Found implementation of procedure processEnvironment__wrappee__methaneQuery [2022-02-20 18:07:29,488 INFO L130 BoogieDeclarations]: Found specification of procedure isMethaneAlarm [2022-02-20 18:07:29,489 INFO L138 BoogieDeclarations]: Found implementation of procedure isMethaneAlarm [2022-02-20 18:07:29,489 INFO L130 BoogieDeclarations]: Found specification of procedure deactivatePump [2022-02-20 18:07:29,489 INFO L138 BoogieDeclarations]: Found implementation of procedure deactivatePump [2022-02-20 18:07:29,489 INFO L130 BoogieDeclarations]: Found specification of procedure write~init~int [2022-02-20 18:07:29,489 INFO L130 BoogieDeclarations]: Found specification of procedure changeMethaneLevel [2022-02-20 18:07:29,490 INFO L138 BoogieDeclarations]: Found implementation of procedure changeMethaneLevel [2022-02-20 18:07:29,490 INFO L130 BoogieDeclarations]: Found specification of procedure ULTIMATE.start [2022-02-20 18:07:29,490 INFO L138 BoogieDeclarations]: Found implementation of procedure ULTIMATE.start [2022-02-20 18:07:29,549 INFO L234 CfgBuilder]: Building ICFG [2022-02-20 18:07:29,551 INFO L260 CfgBuilder]: Building CFG for each procedure with an implementation [2022-02-20 18:07:29,901 INFO L275 CfgBuilder]: Performing block encoding [2022-02-20 18:07:29,908 INFO L294 CfgBuilder]: Using the 1 location(s) as analysis (start of procedure ULTIMATE.start) [2022-02-20 18:07:29,908 INFO L299 CfgBuilder]: Removed 2 assume(true) statements. [2022-02-20 18:07:29,909 INFO L202 PluginConnector]: Adding new model de.uni_freiburg.informatik.ultimate.plugins.generator.rcfgbuilder CFG 20.02 06:07:29 BoogieIcfgContainer [2022-02-20 18:07:29,910 INFO L132 PluginConnector]: ------------------------ END RCFGBuilder---------------------------- [2022-02-20 18:07:29,911 INFO L113 PluginConnector]: ------------------------TraceAbstraction---------------------------- [2022-02-20 18:07:29,911 INFO L271 PluginConnector]: Initializing TraceAbstraction... [2022-02-20 18:07:29,914 INFO L275 PluginConnector]: TraceAbstraction initialized [2022-02-20 18:07:29,914 INFO L185 PluginConnector]: Executing the observer TraceAbstractionObserver from plugin TraceAbstraction for "CDTParser AST 20.02 06:07:28" (1/3) ... [2022-02-20 18:07:29,915 INFO L205 PluginConnector]: Invalid model from TraceAbstraction for observer de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction.TraceAbstractionObserver@5afd5baa and model type de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction AST 20.02 06:07:29, skipping insertion in model container [2022-02-20 18:07:29,915 INFO L185 PluginConnector]: Executing the observer TraceAbstractionObserver from plugin TraceAbstraction for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 20.02 06:07:29" (2/3) ... [2022-02-20 18:07:29,916 INFO L205 PluginConnector]: Invalid model from TraceAbstraction for observer de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction.TraceAbstractionObserver@5afd5baa and model type de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction AST 20.02 06:07:29, skipping insertion in model container [2022-02-20 18:07:29,916 INFO L185 PluginConnector]: Executing the observer TraceAbstractionObserver from plugin TraceAbstraction for "de.uni_freiburg.informatik.ultimate.plugins.generator.rcfgbuilder CFG 20.02 06:07:29" (3/3) ... [2022-02-20 18:07:29,917 INFO L111 eAbstractionObserver]: Analyzing ICFG minepump_spec2_product30.cil.c [2022-02-20 18:07:29,921 INFO L205 ceAbstractionStarter]: Automizer settings: Hoare:true NWA Interpolation:FPandBP Determinization: PREDICATE_ABSTRACTION [2022-02-20 18:07:29,921 INFO L164 ceAbstractionStarter]: Applying trace abstraction to program that has 1 error locations. [2022-02-20 18:07:29,959 INFO L338 AbstractCegarLoop]: ======== Iteration 0 == of CEGAR loop == AllErrorsAtOnce ======== [2022-02-20 18:07:29,964 INFO L339 AbstractCegarLoop]: Settings: SEPARATE_VIOLATION_CHECK=true, mInterprocedural=true, mMaxIterations=1000000, mWatchIteration=1000000, mArtifact=RCFG, mInterpolation=FPandBP, mInterpolantAutomaton=STRAIGHT_LINE, mDumpAutomata=false, mAutomataFormat=ATS_NUMERATE, mDumpPath=., mDeterminiation=PREDICATE_ABSTRACTION, mMinimize=MINIMIZE_SEVPA, mHoare=true, mAutomataTypeConcurrency=PETRI_NET, mHoareTripleChecks=INCREMENTAL, mHoareAnnotationPositions=LoopsAndPotentialCycles, mDumpOnlyReuseAutomata=false, mLimitTraceHistogram=0, mErrorLocTimeLimit=0, mLimitPathProgramCount=0, mCollectInterpolantStatistics=true, mHeuristicEmptinessCheck=false, mHeuristicEmptinessCheckAStarHeuristic=ZERO, mHeuristicEmptinessCheckAStarHeuristicRandomSeed=1337, mHeuristicEmptinessCheckSmtFeatureScoringMethod=DAGSIZE, mSMTFeatureExtraction=false, mSMTFeatureExtractionDumpPath=., mOverrideInterpolantAutomaton=false, mMcrInterpolantMethod=WP, mLoopAccelerationTechnique=FAST_UPR [2022-02-20 18:07:29,965 INFO L340 AbstractCegarLoop]: Starting to check reachability of 1 error locations. [2022-02-20 18:07:29,983 INFO L276 IsEmpty]: Start isEmpty. Operand has 94 states, 68 states have (on average 1.3676470588235294) internal successors, (93), 76 states have internal predecessors, (93), 15 states have call successors, (15), 9 states have call predecessors, (15), 9 states have return successors, (15), 11 states have call predecessors, (15), 15 states have call successors, (15) [2022-02-20 18:07:29,990 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 26 [2022-02-20 18:07:29,991 INFO L506 BasicCegarLoop]: Found error trace [2022-02-20 18:07:29,991 INFO L514 BasicCegarLoop]: trace histogram [1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-02-20 18:07:29,992 INFO L402 AbstractCegarLoop]: === Iteration 1 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2022-02-20 18:07:29,996 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2022-02-20 18:07:29,996 INFO L85 PathProgramCache]: Analyzing trace with hash 975753900, now seen corresponding path program 1 times [2022-02-20 18:07:30,003 INFO L126 FreeRefinementEngine]: Executing refinement strategy CAMEL [2022-02-20 18:07:30,004 INFO L338 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [2069846244] [2022-02-20 18:07:30,004 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-02-20 18:07:30,005 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2022-02-20 18:07:30,157 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-02-20 18:07:30,236 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 15 [2022-02-20 18:07:30,243 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-02-20 18:07:30,260 INFO L290 TraceCheckUtils]: 0: Hoare triple {97#true} havoc ~retValue_acc~6;~retValue_acc~6 := ~methaneLevelCritical~0;#res := ~retValue_acc~6; {97#true} is VALID [2022-02-20 18:07:30,261 INFO L290 TraceCheckUtils]: 1: Hoare triple {97#true} assume true; {97#true} is VALID [2022-02-20 18:07:30,261 INFO L284 TraceCheckUtils]: 2: Hoare quadruple {97#true} {98#false} #234#return; {98#false} is VALID [2022-02-20 18:07:30,267 INFO L290 TraceCheckUtils]: 0: Hoare triple {97#true} assume { :begin_inline_ULTIMATE.init } true;#NULL.base, #NULL.offset := 0, 0;assume 0 == #valid[0];assume 0 < #StackHeapBarrier;call #Ultimate.allocInit(2, 1);call write~init~int(48, 1, 0, 1);call write~init~int(0, 1, 1, 1);call #Ultimate.allocInit(31, 2);call #Ultimate.allocInit(12, 3);call #Ultimate.allocInit(30, 4);call #Ultimate.allocInit(9, 5);call #Ultimate.allocInit(21, 6);call #Ultimate.allocInit(30, 7);call #Ultimate.allocInit(9, 8);call #Ultimate.allocInit(21, 9);call #Ultimate.allocInit(30, 10);call #Ultimate.allocInit(9, 11);call #Ultimate.allocInit(25, 12);call #Ultimate.allocInit(30, 13);call #Ultimate.allocInit(9, 14);call #Ultimate.allocInit(25, 15);call #Ultimate.allocInit(13, 16);call #Ultimate.allocInit(7, 17);call write~init~int(44, 17, 0, 1);call write~init~int(77, 17, 1, 1);call write~init~int(101, 17, 2, 1);call write~init~int(116, 17, 3, 1);call write~init~int(104, 17, 4, 1);call write~init~int(58, 17, 5, 1);call write~init~int(0, 17, 6, 1);call #Ultimate.allocInit(5, 18);call write~init~int(67, 18, 0, 1);call write~init~int(82, 18, 1, 1);call write~init~int(73, 18, 2, 1);call write~init~int(84, 18, 3, 1);call write~init~int(0, 18, 4, 1);call #Ultimate.allocInit(3, 19);call write~init~int(79, 19, 0, 1);call write~init~int(75, 19, 1, 1);call write~init~int(0, 19, 2, 1);call #Ultimate.allocInit(2, 20);call write~init~int(41, 20, 0, 1);call write~init~int(0, 20, 1, 1);call #Ultimate.allocInit(13, 21);call #Ultimate.allocInit(3, 22);call write~init~int(79, 22, 0, 1);call write~init~int(110, 22, 1, 1);call write~init~int(0, 22, 2, 1);call #Ultimate.allocInit(4, 23);call write~init~int(79, 23, 0, 1);call write~init~int(102, 23, 1, 1);call write~init~int(102, 23, 2, 1);call write~init~int(0, 23, 3, 1);call #Ultimate.allocInit(7, 24);call write~init~int(44, 24, 0, 1);call write~init~int(80, 24, 1, 1);call write~init~int(117, 24, 2, 1);call write~init~int(109, 24, 3, 1);call write~init~int(112, 24, 4, 1);call write~init~int(58, 24, 5, 1);call write~init~int(0, 24, 6, 1);call #Ultimate.allocInit(3, 25);call write~init~int(79, 25, 0, 1);call write~init~int(110, 25, 1, 1);call write~init~int(0, 25, 2, 1);call #Ultimate.allocInit(4, 26);call write~init~int(79, 26, 0, 1);call write~init~int(102, 26, 1, 1);call write~init~int(102, 26, 2, 1);call write~init~int(0, 26, 3, 1);call #Ultimate.allocInit(3, 27);call write~init~int(41, 27, 0, 1);call write~init~int(32, 27, 1, 1);call write~init~int(0, 27, 2, 1);call #Ultimate.allocInit(2, 28);call write~init~int(10, 28, 0, 1);call write~init~int(0, 28, 1, 1);~head~0.base, ~head~0.offset := 0, 0;~cleanupTimeShifts~0 := 4;~waterLevel~0 := 1;~methaneLevelCritical~0 := 0;~pumpRunning~0 := 0;~systemActive~0 := 1;~methAndRunningLastTime~0 := 0; {97#true} is VALID [2022-02-20 18:07:30,267 INFO L290 TraceCheckUtils]: 1: Hoare triple {97#true} assume { :end_inline_ULTIMATE.init } true;assume { :begin_inline_main } true;havoc main_#res#1;havoc main_#t~ret28#1, main_~retValue_acc~5#1, main_~tmp~3#1;havoc main_~retValue_acc~5#1;havoc main_~tmp~3#1;assume { :begin_inline_select_helpers } true; {97#true} is VALID [2022-02-20 18:07:30,268 INFO L290 TraceCheckUtils]: 2: Hoare triple {97#true} assume { :end_inline_select_helpers } true;assume { :begin_inline_select_features } true; {97#true} is VALID [2022-02-20 18:07:30,268 INFO L290 TraceCheckUtils]: 3: Hoare triple {97#true} assume { :end_inline_select_features } true;assume { :begin_inline_valid_product } true;havoc valid_product_#res#1;havoc valid_product_~retValue_acc~4#1;havoc valid_product_~retValue_acc~4#1;valid_product_~retValue_acc~4#1 := 1;valid_product_#res#1 := valid_product_~retValue_acc~4#1; {97#true} is VALID [2022-02-20 18:07:30,269 INFO L290 TraceCheckUtils]: 4: Hoare triple {97#true} main_#t~ret28#1 := valid_product_#res#1;assume { :end_inline_valid_product } true;assume -2147483648 <= main_#t~ret28#1 && main_#t~ret28#1 <= 2147483647;main_~tmp~3#1 := main_#t~ret28#1;havoc main_#t~ret28#1; {97#true} is VALID [2022-02-20 18:07:30,269 INFO L290 TraceCheckUtils]: 5: Hoare triple {97#true} assume 0 != main_~tmp~3#1;assume { :begin_inline_setup } true; {97#true} is VALID [2022-02-20 18:07:30,269 INFO L290 TraceCheckUtils]: 6: Hoare triple {97#true} assume { :end_inline_setup } true;assume { :begin_inline_runTest } true;assume { :begin_inline___utac_acc__Specification2_spec__1 } true;~methAndRunningLastTime~0 := 0; {97#true} is VALID [2022-02-20 18:07:30,269 INFO L290 TraceCheckUtils]: 7: Hoare triple {97#true} assume { :end_inline___utac_acc__Specification2_spec__1 } true;assume { :begin_inline_test } true;havoc test_#t~nondet34#1, test_#t~nondet35#1, test_#t~nondet36#1, test_#t~nondet37#1, test_~splverifierCounter~0#1, test_~tmp~4#1, test_~tmp___0~0#1, test_~tmp___1~0#1, test_~tmp___2~0#1;havoc test_~splverifierCounter~0#1;havoc test_~tmp~4#1;havoc test_~tmp___0~0#1;havoc test_~tmp___1~0#1;havoc test_~tmp___2~0#1;test_~splverifierCounter~0#1 := 0; {97#true} is VALID [2022-02-20 18:07:30,271 INFO L290 TraceCheckUtils]: 8: Hoare triple {97#true} assume false; {98#false} is VALID [2022-02-20 18:07:30,271 INFO L272 TraceCheckUtils]: 9: Hoare triple {98#false} call cleanup(); {98#false} is VALID [2022-02-20 18:07:30,271 INFO L290 TraceCheckUtils]: 10: Hoare triple {98#false} havoc ~i~0;havoc ~__cil_tmp2~0; {98#false} is VALID [2022-02-20 18:07:30,271 INFO L272 TraceCheckUtils]: 11: Hoare triple {98#false} call timeShift(); {98#false} is VALID [2022-02-20 18:07:30,272 INFO L290 TraceCheckUtils]: 12: Hoare triple {98#false} assume !(0 != ~pumpRunning~0); {98#false} is VALID [2022-02-20 18:07:30,272 INFO L290 TraceCheckUtils]: 13: Hoare triple {98#false} assume !(0 != ~systemActive~0); {98#false} is VALID [2022-02-20 18:07:30,273 INFO L290 TraceCheckUtils]: 14: Hoare triple {98#false} assume { :begin_inline___utac_acc__Specification2_spec__2 } true;havoc __utac_acc__Specification2_spec__2_#t~ret51#1, __utac_acc__Specification2_spec__2_#t~ret52#1, __utac_acc__Specification2_spec__2_~tmp~9#1, __utac_acc__Specification2_spec__2_~tmp___0~2#1;havoc __utac_acc__Specification2_spec__2_~tmp~9#1;havoc __utac_acc__Specification2_spec__2_~tmp___0~2#1; {98#false} is VALID [2022-02-20 18:07:30,273 INFO L272 TraceCheckUtils]: 15: Hoare triple {98#false} call __utac_acc__Specification2_spec__2_#t~ret51#1 := isMethaneLevelCritical(); {97#true} is VALID [2022-02-20 18:07:30,273 INFO L290 TraceCheckUtils]: 16: Hoare triple {97#true} havoc ~retValue_acc~6;~retValue_acc~6 := ~methaneLevelCritical~0;#res := ~retValue_acc~6; {97#true} is VALID [2022-02-20 18:07:30,273 INFO L290 TraceCheckUtils]: 17: Hoare triple {97#true} assume true; {97#true} is VALID [2022-02-20 18:07:30,274 INFO L284 TraceCheckUtils]: 18: Hoare quadruple {97#true} {98#false} #234#return; {98#false} is VALID [2022-02-20 18:07:30,275 INFO L290 TraceCheckUtils]: 19: Hoare triple {98#false} assume -2147483648 <= __utac_acc__Specification2_spec__2_#t~ret51#1 && __utac_acc__Specification2_spec__2_#t~ret51#1 <= 2147483647;__utac_acc__Specification2_spec__2_~tmp~9#1 := __utac_acc__Specification2_spec__2_#t~ret51#1;havoc __utac_acc__Specification2_spec__2_#t~ret51#1; {98#false} is VALID [2022-02-20 18:07:30,275 INFO L290 TraceCheckUtils]: 20: Hoare triple {98#false} assume 0 != __utac_acc__Specification2_spec__2_~tmp~9#1;assume { :begin_inline_isPumpRunning } true;havoc isPumpRunning_#res#1;havoc isPumpRunning_~retValue_acc~10#1;havoc isPumpRunning_~retValue_acc~10#1;isPumpRunning_~retValue_acc~10#1 := ~pumpRunning~0;isPumpRunning_#res#1 := isPumpRunning_~retValue_acc~10#1; {98#false} is VALID [2022-02-20 18:07:30,275 INFO L290 TraceCheckUtils]: 21: Hoare triple {98#false} __utac_acc__Specification2_spec__2_#t~ret52#1 := isPumpRunning_#res#1;assume { :end_inline_isPumpRunning } true;assume -2147483648 <= __utac_acc__Specification2_spec__2_#t~ret52#1 && __utac_acc__Specification2_spec__2_#t~ret52#1 <= 2147483647;__utac_acc__Specification2_spec__2_~tmp___0~2#1 := __utac_acc__Specification2_spec__2_#t~ret52#1;havoc __utac_acc__Specification2_spec__2_#t~ret52#1; {98#false} is VALID [2022-02-20 18:07:30,276 INFO L290 TraceCheckUtils]: 22: Hoare triple {98#false} assume 0 != __utac_acc__Specification2_spec__2_~tmp___0~2#1; {98#false} is VALID [2022-02-20 18:07:30,276 INFO L290 TraceCheckUtils]: 23: Hoare triple {98#false} assume 0 != ~methAndRunningLastTime~0;assume { :begin_inline___automaton_fail } true; {98#false} is VALID [2022-02-20 18:07:30,276 INFO L290 TraceCheckUtils]: 24: Hoare triple {98#false} assume !false; {98#false} is VALID [2022-02-20 18:07:30,277 INFO L134 CoverageAnalysis]: Checked inductivity of 0 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2022-02-20 18:07:30,277 INFO L144 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2022-02-20 18:07:30,277 INFO L338 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [2069846244] [2022-02-20 18:07:30,278 INFO L165 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [2069846244] provided 1 perfect and 0 imperfect interpolant sequences [2022-02-20 18:07:30,278 INFO L191 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2022-02-20 18:07:30,279 INFO L204 FreeRefinementEngine]: Number of different interpolants: perfect sequences [2] imperfect sequences [] total 2 [2022-02-20 18:07:30,281 INFO L118 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [2017806460] [2022-02-20 18:07:30,282 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2022-02-20 18:07:30,287 INFO L78 Accepts]: Start accepts. Automaton has has 2 states, 2 states have (on average 10.5) internal successors, (21), 2 states have internal predecessors, (21), 1 states have call successors, (3), 2 states have call predecessors, (3), 1 states have return successors, (1), 1 states have call predecessors, (1), 1 states have call successors, (1) Word has length 25 [2022-02-20 18:07:30,288 INFO L84 Accepts]: Finished accepts. word is accepted. [2022-02-20 18:07:30,292 INFO L86 InductivityCheck]: Starting indutivity check of a Floyd-Hoare automaton with has 2 states, 2 states have (on average 10.5) internal successors, (21), 2 states have internal predecessors, (21), 1 states have call successors, (3), 2 states have call predecessors, (3), 1 states have return successors, (1), 1 states have call predecessors, (1), 1 states have call successors, (1) [2022-02-20 18:07:30,335 INFO L122 InductivityCheck]: Floyd-Hoare automaton has 25 edges. 25 inductive. 0 not inductive. 0 times theorem prover too weak to decide inductivity. [2022-02-20 18:07:30,335 INFO L546 AbstractCegarLoop]: INTERPOLANT automaton has 2 states [2022-02-20 18:07:30,336 INFO L108 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2022-02-20 18:07:30,357 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 2 interpolants. [2022-02-20 18:07:30,358 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=1, Invalid=1, Unknown=0, NotChecked=0, Total=2 [2022-02-20 18:07:30,362 INFO L87 Difference]: Start difference. First operand has 94 states, 68 states have (on average 1.3676470588235294) internal successors, (93), 76 states have internal predecessors, (93), 15 states have call successors, (15), 9 states have call predecessors, (15), 9 states have return successors, (15), 11 states have call predecessors, (15), 15 states have call successors, (15) Second operand has 2 states, 2 states have (on average 10.5) internal successors, (21), 2 states have internal predecessors, (21), 1 states have call successors, (3), 2 states have call predecessors, (3), 1 states have return successors, (1), 1 states have call predecessors, (1), 1 states have call successors, (1) [2022-02-20 18:07:30,505 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-02-20 18:07:30,506 INFO L93 Difference]: Finished difference Result 179 states and 240 transitions. [2022-02-20 18:07:30,506 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 2 states. [2022-02-20 18:07:30,506 INFO L78 Accepts]: Start accepts. Automaton has has 2 states, 2 states have (on average 10.5) internal successors, (21), 2 states have internal predecessors, (21), 1 states have call successors, (3), 2 states have call predecessors, (3), 1 states have return successors, (1), 1 states have call predecessors, (1), 1 states have call successors, (1) Word has length 25 [2022-02-20 18:07:30,507 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2022-02-20 18:07:30,508 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 2 states, 2 states have (on average 10.5) internal successors, (21), 2 states have internal predecessors, (21), 1 states have call successors, (3), 2 states have call predecessors, (3), 1 states have return successors, (1), 1 states have call predecessors, (1), 1 states have call successors, (1) [2022-02-20 18:07:30,520 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 2 states to 2 states and 240 transitions. [2022-02-20 18:07:30,521 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 2 states, 2 states have (on average 10.5) internal successors, (21), 2 states have internal predecessors, (21), 1 states have call successors, (3), 2 states have call predecessors, (3), 1 states have return successors, (1), 1 states have call predecessors, (1), 1 states have call successors, (1) [2022-02-20 18:07:30,529 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 2 states to 2 states and 240 transitions. [2022-02-20 18:07:30,529 INFO L86 InductivityCheck]: Starting indutivity check of a Floyd-Hoare automaton with 2 states and 240 transitions. [2022-02-20 18:07:30,736 INFO L122 InductivityCheck]: Floyd-Hoare automaton has 240 edges. 240 inductive. 0 not inductive. 0 times theorem prover too weak to decide inductivity. [2022-02-20 18:07:30,752 INFO L225 Difference]: With dead ends: 179 [2022-02-20 18:07:30,752 INFO L226 Difference]: Without dead ends: 85 [2022-02-20 18:07:30,756 INFO L932 BasicCegarLoop]: 0 DeclaredPredicates, 4 GetRequests, 4 SyntacticMatches, 0 SemanticMatches, 0 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 0 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=1, Invalid=1, Unknown=0, NotChecked=0, Total=2 [2022-02-20 18:07:30,760 INFO L933 BasicCegarLoop]: 117 mSDtfsCounter, 0 mSDsluCounter, 0 mSDsCounter, 0 mSdLazyCounter, 0 mSolverCounterSat, 0 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.0s Time, 0 mProtectedPredicate, 0 mProtectedAction, 0 SdHoareTripleChecker+Valid, 117 SdHoareTripleChecker+Invalid, 0 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 0 IncrementalHoareTripleChecker+Valid, 0 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.0s IncrementalHoareTripleChecker+Time [2022-02-20 18:07:30,764 INFO L934 BasicCegarLoop]: SdHoareTripleChecker [0 Valid, 117 Invalid, 0 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [0 Valid, 0 Invalid, 0 Unknown, 0 Unchecked, 0.0s Time] [2022-02-20 18:07:30,779 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 85 states. [2022-02-20 18:07:30,800 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 85 to 85. [2022-02-20 18:07:30,801 INFO L214 AbstractMinimizeNwa]: Start testing correctness of minimizeSevpa [2022-02-20 18:07:30,804 INFO L82 GeneralOperation]: Start isEquivalent. First operand 85 states. Second operand has 85 states, 61 states have (on average 1.2950819672131149) internal successors, (79), 68 states have internal predecessors, (79), 15 states have call successors, (15), 9 states have call predecessors, (15), 8 states have return successors, (14), 10 states have call predecessors, (14), 14 states have call successors, (14) [2022-02-20 18:07:30,815 INFO L74 IsIncluded]: Start isIncluded. First operand 85 states. Second operand has 85 states, 61 states have (on average 1.2950819672131149) internal successors, (79), 68 states have internal predecessors, (79), 15 states have call successors, (15), 9 states have call predecessors, (15), 8 states have return successors, (14), 10 states have call predecessors, (14), 14 states have call successors, (14) [2022-02-20 18:07:30,817 INFO L87 Difference]: Start difference. First operand 85 states. Second operand has 85 states, 61 states have (on average 1.2950819672131149) internal successors, (79), 68 states have internal predecessors, (79), 15 states have call successors, (15), 9 states have call predecessors, (15), 8 states have return successors, (14), 10 states have call predecessors, (14), 14 states have call successors, (14) [2022-02-20 18:07:30,837 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-02-20 18:07:30,837 INFO L93 Difference]: Finished difference Result 85 states and 108 transitions. [2022-02-20 18:07:30,841 INFO L276 IsEmpty]: Start isEmpty. Operand 85 states and 108 transitions. [2022-02-20 18:07:30,842 INFO L282 IsEmpty]: Finished isEmpty. No accepting run. [2022-02-20 18:07:30,843 INFO L83 IsIncluded]: Finished isIncluded. Language is included [2022-02-20 18:07:30,844 INFO L74 IsIncluded]: Start isIncluded. First operand has 85 states, 61 states have (on average 1.2950819672131149) internal successors, (79), 68 states have internal predecessors, (79), 15 states have call successors, (15), 9 states have call predecessors, (15), 8 states have return successors, (14), 10 states have call predecessors, (14), 14 states have call successors, (14) Second operand 85 states. [2022-02-20 18:07:30,845 INFO L87 Difference]: Start difference. First operand has 85 states, 61 states have (on average 1.2950819672131149) internal successors, (79), 68 states have internal predecessors, (79), 15 states have call successors, (15), 9 states have call predecessors, (15), 8 states have return successors, (14), 10 states have call predecessors, (14), 14 states have call successors, (14) Second operand 85 states. [2022-02-20 18:07:30,849 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-02-20 18:07:30,849 INFO L93 Difference]: Finished difference Result 85 states and 108 transitions. [2022-02-20 18:07:30,850 INFO L276 IsEmpty]: Start isEmpty. Operand 85 states and 108 transitions. [2022-02-20 18:07:30,851 INFO L282 IsEmpty]: Finished isEmpty. No accepting run. [2022-02-20 18:07:30,851 INFO L83 IsIncluded]: Finished isIncluded. Language is included [2022-02-20 18:07:30,851 INFO L88 GeneralOperation]: Finished isEquivalent. [2022-02-20 18:07:30,851 INFO L221 AbstractMinimizeNwa]: Finished testing correctness of minimizeSevpa [2022-02-20 18:07:30,851 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 85 states, 61 states have (on average 1.2950819672131149) internal successors, (79), 68 states have internal predecessors, (79), 15 states have call successors, (15), 9 states have call predecessors, (15), 8 states have return successors, (14), 10 states have call predecessors, (14), 14 states have call successors, (14) [2022-02-20 18:07:30,856 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 85 states to 85 states and 108 transitions. [2022-02-20 18:07:30,857 INFO L78 Accepts]: Start accepts. Automaton has 85 states and 108 transitions. Word has length 25 [2022-02-20 18:07:30,857 INFO L84 Accepts]: Finished accepts. word is rejected. [2022-02-20 18:07:30,857 INFO L470 AbstractCegarLoop]: Abstraction has 85 states and 108 transitions. [2022-02-20 18:07:30,858 INFO L471 AbstractCegarLoop]: INTERPOLANT automaton has has 2 states, 2 states have (on average 10.5) internal successors, (21), 2 states have internal predecessors, (21), 1 states have call successors, (3), 2 states have call predecessors, (3), 1 states have return successors, (1), 1 states have call predecessors, (1), 1 states have call successors, (1) [2022-02-20 18:07:30,858 INFO L276 IsEmpty]: Start isEmpty. Operand 85 states and 108 transitions. [2022-02-20 18:07:30,859 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 27 [2022-02-20 18:07:30,860 INFO L506 BasicCegarLoop]: Found error trace [2022-02-20 18:07:30,860 INFO L514 BasicCegarLoop]: trace histogram [1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-02-20 18:07:30,860 WARN L452 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable0 [2022-02-20 18:07:30,860 INFO L402 AbstractCegarLoop]: === Iteration 2 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2022-02-20 18:07:30,861 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2022-02-20 18:07:30,861 INFO L85 PathProgramCache]: Analyzing trace with hash -638241596, now seen corresponding path program 1 times [2022-02-20 18:07:30,861 INFO L126 FreeRefinementEngine]: Executing refinement strategy CAMEL [2022-02-20 18:07:30,862 INFO L338 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [680689556] [2022-02-20 18:07:30,862 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-02-20 18:07:30,862 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2022-02-20 18:07:30,890 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-02-20 18:07:30,934 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 16 [2022-02-20 18:07:30,937 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-02-20 18:07:30,944 INFO L290 TraceCheckUtils]: 0: Hoare triple {656#true} havoc ~retValue_acc~6;~retValue_acc~6 := ~methaneLevelCritical~0;#res := ~retValue_acc~6; {656#true} is VALID [2022-02-20 18:07:30,945 INFO L290 TraceCheckUtils]: 1: Hoare triple {656#true} assume true; {656#true} is VALID [2022-02-20 18:07:30,945 INFO L284 TraceCheckUtils]: 2: Hoare quadruple {656#true} {657#false} #234#return; {657#false} is VALID [2022-02-20 18:07:30,945 INFO L290 TraceCheckUtils]: 0: Hoare triple {656#true} assume { :begin_inline_ULTIMATE.init } true;#NULL.base, #NULL.offset := 0, 0;assume 0 == #valid[0];assume 0 < #StackHeapBarrier;call #Ultimate.allocInit(2, 1);call write~init~int(48, 1, 0, 1);call write~init~int(0, 1, 1, 1);call #Ultimate.allocInit(31, 2);call #Ultimate.allocInit(12, 3);call #Ultimate.allocInit(30, 4);call #Ultimate.allocInit(9, 5);call #Ultimate.allocInit(21, 6);call #Ultimate.allocInit(30, 7);call #Ultimate.allocInit(9, 8);call #Ultimate.allocInit(21, 9);call #Ultimate.allocInit(30, 10);call #Ultimate.allocInit(9, 11);call #Ultimate.allocInit(25, 12);call #Ultimate.allocInit(30, 13);call #Ultimate.allocInit(9, 14);call #Ultimate.allocInit(25, 15);call #Ultimate.allocInit(13, 16);call #Ultimate.allocInit(7, 17);call write~init~int(44, 17, 0, 1);call write~init~int(77, 17, 1, 1);call write~init~int(101, 17, 2, 1);call write~init~int(116, 17, 3, 1);call write~init~int(104, 17, 4, 1);call write~init~int(58, 17, 5, 1);call write~init~int(0, 17, 6, 1);call #Ultimate.allocInit(5, 18);call write~init~int(67, 18, 0, 1);call write~init~int(82, 18, 1, 1);call write~init~int(73, 18, 2, 1);call write~init~int(84, 18, 3, 1);call write~init~int(0, 18, 4, 1);call #Ultimate.allocInit(3, 19);call write~init~int(79, 19, 0, 1);call write~init~int(75, 19, 1, 1);call write~init~int(0, 19, 2, 1);call #Ultimate.allocInit(2, 20);call write~init~int(41, 20, 0, 1);call write~init~int(0, 20, 1, 1);call #Ultimate.allocInit(13, 21);call #Ultimate.allocInit(3, 22);call write~init~int(79, 22, 0, 1);call write~init~int(110, 22, 1, 1);call write~init~int(0, 22, 2, 1);call #Ultimate.allocInit(4, 23);call write~init~int(79, 23, 0, 1);call write~init~int(102, 23, 1, 1);call write~init~int(102, 23, 2, 1);call write~init~int(0, 23, 3, 1);call #Ultimate.allocInit(7, 24);call write~init~int(44, 24, 0, 1);call write~init~int(80, 24, 1, 1);call write~init~int(117, 24, 2, 1);call write~init~int(109, 24, 3, 1);call write~init~int(112, 24, 4, 1);call write~init~int(58, 24, 5, 1);call write~init~int(0, 24, 6, 1);call #Ultimate.allocInit(3, 25);call write~init~int(79, 25, 0, 1);call write~init~int(110, 25, 1, 1);call write~init~int(0, 25, 2, 1);call #Ultimate.allocInit(4, 26);call write~init~int(79, 26, 0, 1);call write~init~int(102, 26, 1, 1);call write~init~int(102, 26, 2, 1);call write~init~int(0, 26, 3, 1);call #Ultimate.allocInit(3, 27);call write~init~int(41, 27, 0, 1);call write~init~int(32, 27, 1, 1);call write~init~int(0, 27, 2, 1);call #Ultimate.allocInit(2, 28);call write~init~int(10, 28, 0, 1);call write~init~int(0, 28, 1, 1);~head~0.base, ~head~0.offset := 0, 0;~cleanupTimeShifts~0 := 4;~waterLevel~0 := 1;~methaneLevelCritical~0 := 0;~pumpRunning~0 := 0;~systemActive~0 := 1;~methAndRunningLastTime~0 := 0; {656#true} is VALID [2022-02-20 18:07:30,946 INFO L290 TraceCheckUtils]: 1: Hoare triple {656#true} assume { :end_inline_ULTIMATE.init } true;assume { :begin_inline_main } true;havoc main_#res#1;havoc main_#t~ret28#1, main_~retValue_acc~5#1, main_~tmp~3#1;havoc main_~retValue_acc~5#1;havoc main_~tmp~3#1;assume { :begin_inline_select_helpers } true; {656#true} is VALID [2022-02-20 18:07:30,946 INFO L290 TraceCheckUtils]: 2: Hoare triple {656#true} assume { :end_inline_select_helpers } true;assume { :begin_inline_select_features } true; {656#true} is VALID [2022-02-20 18:07:30,946 INFO L290 TraceCheckUtils]: 3: Hoare triple {656#true} assume { :end_inline_select_features } true;assume { :begin_inline_valid_product } true;havoc valid_product_#res#1;havoc valid_product_~retValue_acc~4#1;havoc valid_product_~retValue_acc~4#1;valid_product_~retValue_acc~4#1 := 1;valid_product_#res#1 := valid_product_~retValue_acc~4#1; {656#true} is VALID [2022-02-20 18:07:30,946 INFO L290 TraceCheckUtils]: 4: Hoare triple {656#true} main_#t~ret28#1 := valid_product_#res#1;assume { :end_inline_valid_product } true;assume -2147483648 <= main_#t~ret28#1 && main_#t~ret28#1 <= 2147483647;main_~tmp~3#1 := main_#t~ret28#1;havoc main_#t~ret28#1; {656#true} is VALID [2022-02-20 18:07:30,946 INFO L290 TraceCheckUtils]: 5: Hoare triple {656#true} assume 0 != main_~tmp~3#1;assume { :begin_inline_setup } true; {656#true} is VALID [2022-02-20 18:07:30,947 INFO L290 TraceCheckUtils]: 6: Hoare triple {656#true} assume { :end_inline_setup } true;assume { :begin_inline_runTest } true;assume { :begin_inline___utac_acc__Specification2_spec__1 } true;~methAndRunningLastTime~0 := 0; {656#true} is VALID [2022-02-20 18:07:30,947 INFO L290 TraceCheckUtils]: 7: Hoare triple {656#true} assume { :end_inline___utac_acc__Specification2_spec__1 } true;assume { :begin_inline_test } true;havoc test_#t~nondet34#1, test_#t~nondet35#1, test_#t~nondet36#1, test_#t~nondet37#1, test_~splverifierCounter~0#1, test_~tmp~4#1, test_~tmp___0~0#1, test_~tmp___1~0#1, test_~tmp___2~0#1;havoc test_~splverifierCounter~0#1;havoc test_~tmp~4#1;havoc test_~tmp___0~0#1;havoc test_~tmp___1~0#1;havoc test_~tmp___2~0#1;test_~splverifierCounter~0#1 := 0; {658#(= |ULTIMATE.start_test_~splverifierCounter~0#1| 0)} is VALID [2022-02-20 18:07:30,948 INFO L290 TraceCheckUtils]: 8: Hoare triple {658#(= |ULTIMATE.start_test_~splverifierCounter~0#1| 0)} assume !false; {658#(= |ULTIMATE.start_test_~splverifierCounter~0#1| 0)} is VALID [2022-02-20 18:07:30,948 INFO L290 TraceCheckUtils]: 9: Hoare triple {658#(= |ULTIMATE.start_test_~splverifierCounter~0#1| 0)} assume !(test_~splverifierCounter~0#1 < 4); {657#false} is VALID [2022-02-20 18:07:30,949 INFO L272 TraceCheckUtils]: 10: Hoare triple {657#false} call cleanup(); {657#false} is VALID [2022-02-20 18:07:30,949 INFO L290 TraceCheckUtils]: 11: Hoare triple {657#false} havoc ~i~0;havoc ~__cil_tmp2~0; {657#false} is VALID [2022-02-20 18:07:30,949 INFO L272 TraceCheckUtils]: 12: Hoare triple {657#false} call timeShift(); {657#false} is VALID [2022-02-20 18:07:30,949 INFO L290 TraceCheckUtils]: 13: Hoare triple {657#false} assume !(0 != ~pumpRunning~0); {657#false} is VALID [2022-02-20 18:07:30,950 INFO L290 TraceCheckUtils]: 14: Hoare triple {657#false} assume !(0 != ~systemActive~0); {657#false} is VALID [2022-02-20 18:07:30,950 INFO L290 TraceCheckUtils]: 15: Hoare triple {657#false} assume { :begin_inline___utac_acc__Specification2_spec__2 } true;havoc __utac_acc__Specification2_spec__2_#t~ret51#1, __utac_acc__Specification2_spec__2_#t~ret52#1, __utac_acc__Specification2_spec__2_~tmp~9#1, __utac_acc__Specification2_spec__2_~tmp___0~2#1;havoc __utac_acc__Specification2_spec__2_~tmp~9#1;havoc __utac_acc__Specification2_spec__2_~tmp___0~2#1; {657#false} is VALID [2022-02-20 18:07:30,950 INFO L272 TraceCheckUtils]: 16: Hoare triple {657#false} call __utac_acc__Specification2_spec__2_#t~ret51#1 := isMethaneLevelCritical(); {656#true} is VALID [2022-02-20 18:07:30,951 INFO L290 TraceCheckUtils]: 17: Hoare triple {656#true} havoc ~retValue_acc~6;~retValue_acc~6 := ~methaneLevelCritical~0;#res := ~retValue_acc~6; {656#true} is VALID [2022-02-20 18:07:30,955 INFO L290 TraceCheckUtils]: 18: Hoare triple {656#true} assume true; {656#true} is VALID [2022-02-20 18:07:30,955 INFO L284 TraceCheckUtils]: 19: Hoare quadruple {656#true} {657#false} #234#return; {657#false} is VALID [2022-02-20 18:07:30,955 INFO L290 TraceCheckUtils]: 20: Hoare triple {657#false} assume -2147483648 <= __utac_acc__Specification2_spec__2_#t~ret51#1 && __utac_acc__Specification2_spec__2_#t~ret51#1 <= 2147483647;__utac_acc__Specification2_spec__2_~tmp~9#1 := __utac_acc__Specification2_spec__2_#t~ret51#1;havoc __utac_acc__Specification2_spec__2_#t~ret51#1; {657#false} is VALID [2022-02-20 18:07:30,956 INFO L290 TraceCheckUtils]: 21: Hoare triple {657#false} assume 0 != __utac_acc__Specification2_spec__2_~tmp~9#1;assume { :begin_inline_isPumpRunning } true;havoc isPumpRunning_#res#1;havoc isPumpRunning_~retValue_acc~10#1;havoc isPumpRunning_~retValue_acc~10#1;isPumpRunning_~retValue_acc~10#1 := ~pumpRunning~0;isPumpRunning_#res#1 := isPumpRunning_~retValue_acc~10#1; {657#false} is VALID [2022-02-20 18:07:30,956 INFO L290 TraceCheckUtils]: 22: Hoare triple {657#false} __utac_acc__Specification2_spec__2_#t~ret52#1 := isPumpRunning_#res#1;assume { :end_inline_isPumpRunning } true;assume -2147483648 <= __utac_acc__Specification2_spec__2_#t~ret52#1 && __utac_acc__Specification2_spec__2_#t~ret52#1 <= 2147483647;__utac_acc__Specification2_spec__2_~tmp___0~2#1 := __utac_acc__Specification2_spec__2_#t~ret52#1;havoc __utac_acc__Specification2_spec__2_#t~ret52#1; {657#false} is VALID [2022-02-20 18:07:30,957 INFO L290 TraceCheckUtils]: 23: Hoare triple {657#false} assume 0 != __utac_acc__Specification2_spec__2_~tmp___0~2#1; {657#false} is VALID [2022-02-20 18:07:30,957 INFO L290 TraceCheckUtils]: 24: Hoare triple {657#false} assume 0 != ~methAndRunningLastTime~0;assume { :begin_inline___automaton_fail } true; {657#false} is VALID [2022-02-20 18:07:30,957 INFO L290 TraceCheckUtils]: 25: Hoare triple {657#false} assume !false; {657#false} is VALID [2022-02-20 18:07:30,957 INFO L134 CoverageAnalysis]: Checked inductivity of 0 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2022-02-20 18:07:30,958 INFO L144 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2022-02-20 18:07:30,958 INFO L338 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [680689556] [2022-02-20 18:07:30,958 INFO L165 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [680689556] provided 1 perfect and 0 imperfect interpolant sequences [2022-02-20 18:07:30,958 INFO L191 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2022-02-20 18:07:30,959 INFO L204 FreeRefinementEngine]: Number of different interpolants: perfect sequences [3] imperfect sequences [] total 3 [2022-02-20 18:07:30,959 INFO L118 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [374269936] [2022-02-20 18:07:30,959 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2022-02-20 18:07:30,960 INFO L78 Accepts]: Start accepts. Automaton has has 3 states, 3 states have (on average 7.333333333333333) internal successors, (22), 3 states have internal predecessors, (22), 1 states have call successors, (3), 2 states have call predecessors, (3), 1 states have return successors, (1), 1 states have call predecessors, (1), 1 states have call successors, (1) Word has length 26 [2022-02-20 18:07:30,961 INFO L84 Accepts]: Finished accepts. word is accepted. [2022-02-20 18:07:30,961 INFO L86 InductivityCheck]: Starting indutivity check of a Floyd-Hoare automaton with has 3 states, 3 states have (on average 7.333333333333333) internal successors, (22), 3 states have internal predecessors, (22), 1 states have call successors, (3), 2 states have call predecessors, (3), 1 states have return successors, (1), 1 states have call predecessors, (1), 1 states have call successors, (1) [2022-02-20 18:07:30,983 INFO L122 InductivityCheck]: Floyd-Hoare automaton has 26 edges. 26 inductive. 0 not inductive. 0 times theorem prover too weak to decide inductivity. [2022-02-20 18:07:30,984 INFO L546 AbstractCegarLoop]: INTERPOLANT automaton has 3 states [2022-02-20 18:07:30,984 INFO L108 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2022-02-20 18:07:30,985 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 3 interpolants. [2022-02-20 18:07:30,985 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=3, Invalid=3, Unknown=0, NotChecked=0, Total=6 [2022-02-20 18:07:30,986 INFO L87 Difference]: Start difference. First operand 85 states and 108 transitions. Second operand has 3 states, 3 states have (on average 7.333333333333333) internal successors, (22), 3 states have internal predecessors, (22), 1 states have call successors, (3), 2 states have call predecessors, (3), 1 states have return successors, (1), 1 states have call predecessors, (1), 1 states have call successors, (1) [2022-02-20 18:07:31,095 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-02-20 18:07:31,096 INFO L93 Difference]: Finished difference Result 134 states and 170 transitions. [2022-02-20 18:07:31,096 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 3 states. [2022-02-20 18:07:31,096 INFO L78 Accepts]: Start accepts. Automaton has has 3 states, 3 states have (on average 7.333333333333333) internal successors, (22), 3 states have internal predecessors, (22), 1 states have call successors, (3), 2 states have call predecessors, (3), 1 states have return successors, (1), 1 states have call predecessors, (1), 1 states have call successors, (1) Word has length 26 [2022-02-20 18:07:31,097 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2022-02-20 18:07:31,097 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 3 states, 3 states have (on average 7.333333333333333) internal successors, (22), 3 states have internal predecessors, (22), 1 states have call successors, (3), 2 states have call predecessors, (3), 1 states have return successors, (1), 1 states have call predecessors, (1), 1 states have call successors, (1) [2022-02-20 18:07:31,100 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 3 states to 3 states and 170 transitions. [2022-02-20 18:07:31,101 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 3 states, 3 states have (on average 7.333333333333333) internal successors, (22), 3 states have internal predecessors, (22), 1 states have call successors, (3), 2 states have call predecessors, (3), 1 states have return successors, (1), 1 states have call predecessors, (1), 1 states have call successors, (1) [2022-02-20 18:07:31,104 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 3 states to 3 states and 170 transitions. [2022-02-20 18:07:31,104 INFO L86 InductivityCheck]: Starting indutivity check of a Floyd-Hoare automaton with 3 states and 170 transitions. [2022-02-20 18:07:31,245 INFO L122 InductivityCheck]: Floyd-Hoare automaton has 170 edges. 170 inductive. 0 not inductive. 0 times theorem prover too weak to decide inductivity. [2022-02-20 18:07:31,248 INFO L225 Difference]: With dead ends: 134 [2022-02-20 18:07:31,248 INFO L226 Difference]: Without dead ends: 76 [2022-02-20 18:07:31,249 INFO L932 BasicCegarLoop]: 0 DeclaredPredicates, 5 GetRequests, 4 SyntacticMatches, 0 SemanticMatches, 1 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 0 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=3, Invalid=3, Unknown=0, NotChecked=0, Total=6 [2022-02-20 18:07:31,250 INFO L933 BasicCegarLoop]: 95 mSDtfsCounter, 13 mSDsluCounter, 78 mSDsCounter, 0 mSdLazyCounter, 1 mSolverCounterSat, 0 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.0s Time, 0 mProtectedPredicate, 0 mProtectedAction, 16 SdHoareTripleChecker+Valid, 173 SdHoareTripleChecker+Invalid, 1 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 0 IncrementalHoareTripleChecker+Valid, 1 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.0s IncrementalHoareTripleChecker+Time [2022-02-20 18:07:31,250 INFO L934 BasicCegarLoop]: SdHoareTripleChecker [16 Valid, 173 Invalid, 1 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [0 Valid, 1 Invalid, 0 Unknown, 0 Unchecked, 0.0s Time] [2022-02-20 18:07:31,251 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 76 states. [2022-02-20 18:07:31,256 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 76 to 76. [2022-02-20 18:07:31,256 INFO L214 AbstractMinimizeNwa]: Start testing correctness of minimizeSevpa [2022-02-20 18:07:31,257 INFO L82 GeneralOperation]: Start isEquivalent. First operand 76 states. Second operand has 76 states, 55 states have (on average 1.309090909090909) internal successors, (72), 62 states have internal predecessors, (72), 12 states have call successors, (12), 8 states have call predecessors, (12), 8 states have return successors, (12), 8 states have call predecessors, (12), 12 states have call successors, (12) [2022-02-20 18:07:31,257 INFO L74 IsIncluded]: Start isIncluded. First operand 76 states. Second operand has 76 states, 55 states have (on average 1.309090909090909) internal successors, (72), 62 states have internal predecessors, (72), 12 states have call successors, (12), 8 states have call predecessors, (12), 8 states have return successors, (12), 8 states have call predecessors, (12), 12 states have call successors, (12) [2022-02-20 18:07:31,257 INFO L87 Difference]: Start difference. First operand 76 states. Second operand has 76 states, 55 states have (on average 1.309090909090909) internal successors, (72), 62 states have internal predecessors, (72), 12 states have call successors, (12), 8 states have call predecessors, (12), 8 states have return successors, (12), 8 states have call predecessors, (12), 12 states have call successors, (12) [2022-02-20 18:07:31,260 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-02-20 18:07:31,261 INFO L93 Difference]: Finished difference Result 76 states and 96 transitions. [2022-02-20 18:07:31,261 INFO L276 IsEmpty]: Start isEmpty. Operand 76 states and 96 transitions. [2022-02-20 18:07:31,262 INFO L282 IsEmpty]: Finished isEmpty. No accepting run. [2022-02-20 18:07:31,262 INFO L83 IsIncluded]: Finished isIncluded. Language is included [2022-02-20 18:07:31,262 INFO L74 IsIncluded]: Start isIncluded. First operand has 76 states, 55 states have (on average 1.309090909090909) internal successors, (72), 62 states have internal predecessors, (72), 12 states have call successors, (12), 8 states have call predecessors, (12), 8 states have return successors, (12), 8 states have call predecessors, (12), 12 states have call successors, (12) Second operand 76 states. [2022-02-20 18:07:31,262 INFO L87 Difference]: Start difference. First operand has 76 states, 55 states have (on average 1.309090909090909) internal successors, (72), 62 states have internal predecessors, (72), 12 states have call successors, (12), 8 states have call predecessors, (12), 8 states have return successors, (12), 8 states have call predecessors, (12), 12 states have call successors, (12) Second operand 76 states. [2022-02-20 18:07:31,265 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-02-20 18:07:31,265 INFO L93 Difference]: Finished difference Result 76 states and 96 transitions. [2022-02-20 18:07:31,266 INFO L276 IsEmpty]: Start isEmpty. Operand 76 states and 96 transitions. [2022-02-20 18:07:31,266 INFO L282 IsEmpty]: Finished isEmpty. No accepting run. [2022-02-20 18:07:31,266 INFO L83 IsIncluded]: Finished isIncluded. Language is included [2022-02-20 18:07:31,267 INFO L88 GeneralOperation]: Finished isEquivalent. [2022-02-20 18:07:31,267 INFO L221 AbstractMinimizeNwa]: Finished testing correctness of minimizeSevpa [2022-02-20 18:07:31,267 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 76 states, 55 states have (on average 1.309090909090909) internal successors, (72), 62 states have internal predecessors, (72), 12 states have call successors, (12), 8 states have call predecessors, (12), 8 states have return successors, (12), 8 states have call predecessors, (12), 12 states have call successors, (12) [2022-02-20 18:07:31,270 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 76 states to 76 states and 96 transitions. [2022-02-20 18:07:31,270 INFO L78 Accepts]: Start accepts. Automaton has 76 states and 96 transitions. Word has length 26 [2022-02-20 18:07:31,270 INFO L84 Accepts]: Finished accepts. word is rejected. [2022-02-20 18:07:31,270 INFO L470 AbstractCegarLoop]: Abstraction has 76 states and 96 transitions. [2022-02-20 18:07:31,270 INFO L471 AbstractCegarLoop]: INTERPOLANT automaton has has 3 states, 3 states have (on average 7.333333333333333) internal successors, (22), 3 states have internal predecessors, (22), 1 states have call successors, (3), 2 states have call predecessors, (3), 1 states have return successors, (1), 1 states have call predecessors, (1), 1 states have call successors, (1) [2022-02-20 18:07:31,270 INFO L276 IsEmpty]: Start isEmpty. Operand 76 states and 96 transitions. [2022-02-20 18:07:31,271 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 32 [2022-02-20 18:07:31,271 INFO L506 BasicCegarLoop]: Found error trace [2022-02-20 18:07:31,271 INFO L514 BasicCegarLoop]: trace histogram [1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-02-20 18:07:31,272 WARN L452 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable1 [2022-02-20 18:07:31,272 INFO L402 AbstractCegarLoop]: === Iteration 3 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2022-02-20 18:07:31,272 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2022-02-20 18:07:31,272 INFO L85 PathProgramCache]: Analyzing trace with hash 1981192212, now seen corresponding path program 1 times [2022-02-20 18:07:31,272 INFO L126 FreeRefinementEngine]: Executing refinement strategy CAMEL [2022-02-20 18:07:31,273 INFO L338 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [1846031325] [2022-02-20 18:07:31,273 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-02-20 18:07:31,273 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2022-02-20 18:07:31,327 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-02-20 18:07:31,385 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 21 [2022-02-20 18:07:31,386 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-02-20 18:07:31,389 INFO L290 TraceCheckUtils]: 0: Hoare triple {1118#true} havoc ~retValue_acc~6;~retValue_acc~6 := ~methaneLevelCritical~0;#res := ~retValue_acc~6; {1118#true} is VALID [2022-02-20 18:07:31,389 INFO L290 TraceCheckUtils]: 1: Hoare triple {1118#true} assume true; {1118#true} is VALID [2022-02-20 18:07:31,389 INFO L284 TraceCheckUtils]: 2: Hoare quadruple {1118#true} {1119#false} #234#return; {1119#false} is VALID [2022-02-20 18:07:31,391 INFO L290 TraceCheckUtils]: 0: Hoare triple {1118#true} assume { :begin_inline_ULTIMATE.init } true;#NULL.base, #NULL.offset := 0, 0;assume 0 == #valid[0];assume 0 < #StackHeapBarrier;call #Ultimate.allocInit(2, 1);call write~init~int(48, 1, 0, 1);call write~init~int(0, 1, 1, 1);call #Ultimate.allocInit(31, 2);call #Ultimate.allocInit(12, 3);call #Ultimate.allocInit(30, 4);call #Ultimate.allocInit(9, 5);call #Ultimate.allocInit(21, 6);call #Ultimate.allocInit(30, 7);call #Ultimate.allocInit(9, 8);call #Ultimate.allocInit(21, 9);call #Ultimate.allocInit(30, 10);call #Ultimate.allocInit(9, 11);call #Ultimate.allocInit(25, 12);call #Ultimate.allocInit(30, 13);call #Ultimate.allocInit(9, 14);call #Ultimate.allocInit(25, 15);call #Ultimate.allocInit(13, 16);call #Ultimate.allocInit(7, 17);call write~init~int(44, 17, 0, 1);call write~init~int(77, 17, 1, 1);call write~init~int(101, 17, 2, 1);call write~init~int(116, 17, 3, 1);call write~init~int(104, 17, 4, 1);call write~init~int(58, 17, 5, 1);call write~init~int(0, 17, 6, 1);call #Ultimate.allocInit(5, 18);call write~init~int(67, 18, 0, 1);call write~init~int(82, 18, 1, 1);call write~init~int(73, 18, 2, 1);call write~init~int(84, 18, 3, 1);call write~init~int(0, 18, 4, 1);call #Ultimate.allocInit(3, 19);call write~init~int(79, 19, 0, 1);call write~init~int(75, 19, 1, 1);call write~init~int(0, 19, 2, 1);call #Ultimate.allocInit(2, 20);call write~init~int(41, 20, 0, 1);call write~init~int(0, 20, 1, 1);call #Ultimate.allocInit(13, 21);call #Ultimate.allocInit(3, 22);call write~init~int(79, 22, 0, 1);call write~init~int(110, 22, 1, 1);call write~init~int(0, 22, 2, 1);call #Ultimate.allocInit(4, 23);call write~init~int(79, 23, 0, 1);call write~init~int(102, 23, 1, 1);call write~init~int(102, 23, 2, 1);call write~init~int(0, 23, 3, 1);call #Ultimate.allocInit(7, 24);call write~init~int(44, 24, 0, 1);call write~init~int(80, 24, 1, 1);call write~init~int(117, 24, 2, 1);call write~init~int(109, 24, 3, 1);call write~init~int(112, 24, 4, 1);call write~init~int(58, 24, 5, 1);call write~init~int(0, 24, 6, 1);call #Ultimate.allocInit(3, 25);call write~init~int(79, 25, 0, 1);call write~init~int(110, 25, 1, 1);call write~init~int(0, 25, 2, 1);call #Ultimate.allocInit(4, 26);call write~init~int(79, 26, 0, 1);call write~init~int(102, 26, 1, 1);call write~init~int(102, 26, 2, 1);call write~init~int(0, 26, 3, 1);call #Ultimate.allocInit(3, 27);call write~init~int(41, 27, 0, 1);call write~init~int(32, 27, 1, 1);call write~init~int(0, 27, 2, 1);call #Ultimate.allocInit(2, 28);call write~init~int(10, 28, 0, 1);call write~init~int(0, 28, 1, 1);~head~0.base, ~head~0.offset := 0, 0;~cleanupTimeShifts~0 := 4;~waterLevel~0 := 1;~methaneLevelCritical~0 := 0;~pumpRunning~0 := 0;~systemActive~0 := 1;~methAndRunningLastTime~0 := 0; {1120#(= 1 ~systemActive~0)} is VALID [2022-02-20 18:07:31,392 INFO L290 TraceCheckUtils]: 1: Hoare triple {1120#(= 1 ~systemActive~0)} assume { :end_inline_ULTIMATE.init } true;assume { :begin_inline_main } true;havoc main_#res#1;havoc main_#t~ret28#1, main_~retValue_acc~5#1, main_~tmp~3#1;havoc main_~retValue_acc~5#1;havoc main_~tmp~3#1;assume { :begin_inline_select_helpers } true; {1120#(= 1 ~systemActive~0)} is VALID [2022-02-20 18:07:31,392 INFO L290 TraceCheckUtils]: 2: Hoare triple {1120#(= 1 ~systemActive~0)} assume { :end_inline_select_helpers } true;assume { :begin_inline_select_features } true; {1120#(= 1 ~systemActive~0)} is VALID [2022-02-20 18:07:31,393 INFO L290 TraceCheckUtils]: 3: Hoare triple {1120#(= 1 ~systemActive~0)} assume { :end_inline_select_features } true;assume { :begin_inline_valid_product } true;havoc valid_product_#res#1;havoc valid_product_~retValue_acc~4#1;havoc valid_product_~retValue_acc~4#1;valid_product_~retValue_acc~4#1 := 1;valid_product_#res#1 := valid_product_~retValue_acc~4#1; {1121#(= |ULTIMATE.start_valid_product_#res#1| ~systemActive~0)} is VALID [2022-02-20 18:07:31,393 INFO L290 TraceCheckUtils]: 4: Hoare triple {1121#(= |ULTIMATE.start_valid_product_#res#1| ~systemActive~0)} main_#t~ret28#1 := valid_product_#res#1;assume { :end_inline_valid_product } true;assume -2147483648 <= main_#t~ret28#1 && main_#t~ret28#1 <= 2147483647;main_~tmp~3#1 := main_#t~ret28#1;havoc main_#t~ret28#1; {1122#(= |ULTIMATE.start_main_~tmp~3#1| ~systemActive~0)} is VALID [2022-02-20 18:07:31,394 INFO L290 TraceCheckUtils]: 5: Hoare triple {1122#(= |ULTIMATE.start_main_~tmp~3#1| ~systemActive~0)} assume 0 != main_~tmp~3#1;assume { :begin_inline_setup } true; {1123#(not (= 0 ~systemActive~0))} is VALID [2022-02-20 18:07:31,394 INFO L290 TraceCheckUtils]: 6: Hoare triple {1123#(not (= 0 ~systemActive~0))} assume { :end_inline_setup } true;assume { :begin_inline_runTest } true;assume { :begin_inline___utac_acc__Specification2_spec__1 } true;~methAndRunningLastTime~0 := 0; {1123#(not (= 0 ~systemActive~0))} is VALID [2022-02-20 18:07:31,394 INFO L290 TraceCheckUtils]: 7: Hoare triple {1123#(not (= 0 ~systemActive~0))} assume { :end_inline___utac_acc__Specification2_spec__1 } true;assume { :begin_inline_test } true;havoc test_#t~nondet34#1, test_#t~nondet35#1, test_#t~nondet36#1, test_#t~nondet37#1, test_~splverifierCounter~0#1, test_~tmp~4#1, test_~tmp___0~0#1, test_~tmp___1~0#1, test_~tmp___2~0#1;havoc test_~splverifierCounter~0#1;havoc test_~tmp~4#1;havoc test_~tmp___0~0#1;havoc test_~tmp___1~0#1;havoc test_~tmp___2~0#1;test_~splverifierCounter~0#1 := 0; {1123#(not (= 0 ~systemActive~0))} is VALID [2022-02-20 18:07:31,395 INFO L290 TraceCheckUtils]: 8: Hoare triple {1123#(not (= 0 ~systemActive~0))} assume !false; {1123#(not (= 0 ~systemActive~0))} is VALID [2022-02-20 18:07:31,395 INFO L290 TraceCheckUtils]: 9: Hoare triple {1123#(not (= 0 ~systemActive~0))} assume test_~splverifierCounter~0#1 < 4; {1123#(not (= 0 ~systemActive~0))} is VALID [2022-02-20 18:07:31,396 INFO L290 TraceCheckUtils]: 10: Hoare triple {1123#(not (= 0 ~systemActive~0))} assume -2147483648 <= test_#t~nondet34#1 && test_#t~nondet34#1 <= 2147483647;test_~tmp~4#1 := test_#t~nondet34#1;havoc test_#t~nondet34#1; {1123#(not (= 0 ~systemActive~0))} is VALID [2022-02-20 18:07:31,396 INFO L290 TraceCheckUtils]: 11: Hoare triple {1123#(not (= 0 ~systemActive~0))} assume !(0 != test_~tmp~4#1); {1123#(not (= 0 ~systemActive~0))} is VALID [2022-02-20 18:07:31,397 INFO L290 TraceCheckUtils]: 12: Hoare triple {1123#(not (= 0 ~systemActive~0))} assume -2147483648 <= test_#t~nondet35#1 && test_#t~nondet35#1 <= 2147483647;test_~tmp___0~0#1 := test_#t~nondet35#1;havoc test_#t~nondet35#1; {1123#(not (= 0 ~systemActive~0))} is VALID [2022-02-20 18:07:31,397 INFO L290 TraceCheckUtils]: 13: Hoare triple {1123#(not (= 0 ~systemActive~0))} assume !(0 != test_~tmp___0~0#1); {1123#(not (= 0 ~systemActive~0))} is VALID [2022-02-20 18:07:31,398 INFO L290 TraceCheckUtils]: 14: Hoare triple {1123#(not (= 0 ~systemActive~0))} assume -2147483648 <= test_#t~nondet36#1 && test_#t~nondet36#1 <= 2147483647;test_~tmp___2~0#1 := test_#t~nondet36#1;havoc test_#t~nondet36#1; {1123#(not (= 0 ~systemActive~0))} is VALID [2022-02-20 18:07:31,398 INFO L290 TraceCheckUtils]: 15: Hoare triple {1123#(not (= 0 ~systemActive~0))} assume !(0 != test_~tmp___2~0#1);assume -2147483648 <= test_#t~nondet37#1 && test_#t~nondet37#1 <= 2147483647;test_~tmp___1~0#1 := test_#t~nondet37#1;havoc test_#t~nondet37#1; {1123#(not (= 0 ~systemActive~0))} is VALID [2022-02-20 18:07:31,399 INFO L290 TraceCheckUtils]: 16: Hoare triple {1123#(not (= 0 ~systemActive~0))} assume 0 != test_~tmp___1~0#1; {1123#(not (= 0 ~systemActive~0))} is VALID [2022-02-20 18:07:31,399 INFO L272 TraceCheckUtils]: 17: Hoare triple {1123#(not (= 0 ~systemActive~0))} call timeShift(); {1123#(not (= 0 ~systemActive~0))} is VALID [2022-02-20 18:07:31,400 INFO L290 TraceCheckUtils]: 18: Hoare triple {1123#(not (= 0 ~systemActive~0))} assume !(0 != ~pumpRunning~0); {1123#(not (= 0 ~systemActive~0))} is VALID [2022-02-20 18:07:31,400 INFO L290 TraceCheckUtils]: 19: Hoare triple {1123#(not (= 0 ~systemActive~0))} assume !(0 != ~systemActive~0); {1119#false} is VALID [2022-02-20 18:07:31,400 INFO L290 TraceCheckUtils]: 20: Hoare triple {1119#false} assume { :begin_inline___utac_acc__Specification2_spec__2 } true;havoc __utac_acc__Specification2_spec__2_#t~ret51#1, __utac_acc__Specification2_spec__2_#t~ret52#1, __utac_acc__Specification2_spec__2_~tmp~9#1, __utac_acc__Specification2_spec__2_~tmp___0~2#1;havoc __utac_acc__Specification2_spec__2_~tmp~9#1;havoc __utac_acc__Specification2_spec__2_~tmp___0~2#1; {1119#false} is VALID [2022-02-20 18:07:31,400 INFO L272 TraceCheckUtils]: 21: Hoare triple {1119#false} call __utac_acc__Specification2_spec__2_#t~ret51#1 := isMethaneLevelCritical(); {1118#true} is VALID [2022-02-20 18:07:31,400 INFO L290 TraceCheckUtils]: 22: Hoare triple {1118#true} havoc ~retValue_acc~6;~retValue_acc~6 := ~methaneLevelCritical~0;#res := ~retValue_acc~6; {1118#true} is VALID [2022-02-20 18:07:31,401 INFO L290 TraceCheckUtils]: 23: Hoare triple {1118#true} assume true; {1118#true} is VALID [2022-02-20 18:07:31,401 INFO L284 TraceCheckUtils]: 24: Hoare quadruple {1118#true} {1119#false} #234#return; {1119#false} is VALID [2022-02-20 18:07:31,401 INFO L290 TraceCheckUtils]: 25: Hoare triple {1119#false} assume -2147483648 <= __utac_acc__Specification2_spec__2_#t~ret51#1 && __utac_acc__Specification2_spec__2_#t~ret51#1 <= 2147483647;__utac_acc__Specification2_spec__2_~tmp~9#1 := __utac_acc__Specification2_spec__2_#t~ret51#1;havoc __utac_acc__Specification2_spec__2_#t~ret51#1; {1119#false} is VALID [2022-02-20 18:07:31,401 INFO L290 TraceCheckUtils]: 26: Hoare triple {1119#false} assume 0 != __utac_acc__Specification2_spec__2_~tmp~9#1;assume { :begin_inline_isPumpRunning } true;havoc isPumpRunning_#res#1;havoc isPumpRunning_~retValue_acc~10#1;havoc isPumpRunning_~retValue_acc~10#1;isPumpRunning_~retValue_acc~10#1 := ~pumpRunning~0;isPumpRunning_#res#1 := isPumpRunning_~retValue_acc~10#1; {1119#false} is VALID [2022-02-20 18:07:31,401 INFO L290 TraceCheckUtils]: 27: Hoare triple {1119#false} __utac_acc__Specification2_spec__2_#t~ret52#1 := isPumpRunning_#res#1;assume { :end_inline_isPumpRunning } true;assume -2147483648 <= __utac_acc__Specification2_spec__2_#t~ret52#1 && __utac_acc__Specification2_spec__2_#t~ret52#1 <= 2147483647;__utac_acc__Specification2_spec__2_~tmp___0~2#1 := __utac_acc__Specification2_spec__2_#t~ret52#1;havoc __utac_acc__Specification2_spec__2_#t~ret52#1; {1119#false} is VALID [2022-02-20 18:07:31,401 INFO L290 TraceCheckUtils]: 28: Hoare triple {1119#false} assume 0 != __utac_acc__Specification2_spec__2_~tmp___0~2#1; {1119#false} is VALID [2022-02-20 18:07:31,402 INFO L290 TraceCheckUtils]: 29: Hoare triple {1119#false} assume 0 != ~methAndRunningLastTime~0;assume { :begin_inline___automaton_fail } true; {1119#false} is VALID [2022-02-20 18:07:31,402 INFO L290 TraceCheckUtils]: 30: Hoare triple {1119#false} assume !false; {1119#false} is VALID [2022-02-20 18:07:31,402 INFO L134 CoverageAnalysis]: Checked inductivity of 0 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2022-02-20 18:07:31,402 INFO L144 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2022-02-20 18:07:31,402 INFO L338 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [1846031325] [2022-02-20 18:07:31,403 INFO L165 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [1846031325] provided 1 perfect and 0 imperfect interpolant sequences [2022-02-20 18:07:31,403 INFO L191 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2022-02-20 18:07:31,403 INFO L204 FreeRefinementEngine]: Number of different interpolants: perfect sequences [6] imperfect sequences [] total 6 [2022-02-20 18:07:31,403 INFO L118 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [281290409] [2022-02-20 18:07:31,403 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2022-02-20 18:07:31,404 INFO L78 Accepts]: Start accepts. Automaton has has 6 states, 6 states have (on average 4.666666666666667) internal successors, (28), 6 states have internal predecessors, (28), 2 states have call successors, (2), 2 states have call predecessors, (2), 1 states have return successors, (1), 1 states have call predecessors, (1), 1 states have call successors, (1) Word has length 31 [2022-02-20 18:07:31,404 INFO L84 Accepts]: Finished accepts. word is accepted. [2022-02-20 18:07:31,404 INFO L86 InductivityCheck]: Starting indutivity check of a Floyd-Hoare automaton with has 6 states, 6 states have (on average 4.666666666666667) internal successors, (28), 6 states have internal predecessors, (28), 2 states have call successors, (2), 2 states have call predecessors, (2), 1 states have return successors, (1), 1 states have call predecessors, (1), 1 states have call successors, (1) [2022-02-20 18:07:31,427 INFO L122 InductivityCheck]: Floyd-Hoare automaton has 31 edges. 31 inductive. 0 not inductive. 0 times theorem prover too weak to decide inductivity. [2022-02-20 18:07:31,427 INFO L546 AbstractCegarLoop]: INTERPOLANT automaton has 6 states [2022-02-20 18:07:31,427 INFO L108 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2022-02-20 18:07:31,428 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 6 interpolants. [2022-02-20 18:07:31,428 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=10, Invalid=20, Unknown=0, NotChecked=0, Total=30 [2022-02-20 18:07:31,428 INFO L87 Difference]: Start difference. First operand 76 states and 96 transitions. Second operand has 6 states, 6 states have (on average 4.666666666666667) internal successors, (28), 6 states have internal predecessors, (28), 2 states have call successors, (2), 2 states have call predecessors, (2), 1 states have return successors, (1), 1 states have call predecessors, (1), 1 states have call successors, (1) [2022-02-20 18:07:31,705 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-02-20 18:07:31,705 INFO L93 Difference]: Finished difference Result 144 states and 185 transitions. [2022-02-20 18:07:31,705 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 5 states. [2022-02-20 18:07:31,706 INFO L78 Accepts]: Start accepts. Automaton has has 6 states, 6 states have (on average 4.666666666666667) internal successors, (28), 6 states have internal predecessors, (28), 2 states have call successors, (2), 2 states have call predecessors, (2), 1 states have return successors, (1), 1 states have call predecessors, (1), 1 states have call successors, (1) Word has length 31 [2022-02-20 18:07:31,706 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2022-02-20 18:07:31,706 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 6 states, 6 states have (on average 4.666666666666667) internal successors, (28), 6 states have internal predecessors, (28), 2 states have call successors, (2), 2 states have call predecessors, (2), 1 states have return successors, (1), 1 states have call predecessors, (1), 1 states have call successors, (1) [2022-02-20 18:07:31,710 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 5 states to 5 states and 185 transitions. [2022-02-20 18:07:31,710 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 6 states, 6 states have (on average 4.666666666666667) internal successors, (28), 6 states have internal predecessors, (28), 2 states have call successors, (2), 2 states have call predecessors, (2), 1 states have return successors, (1), 1 states have call predecessors, (1), 1 states have call successors, (1) [2022-02-20 18:07:31,713 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 5 states to 5 states and 185 transitions. [2022-02-20 18:07:31,713 INFO L86 InductivityCheck]: Starting indutivity check of a Floyd-Hoare automaton with 5 states and 185 transitions. [2022-02-20 18:07:31,872 INFO L122 InductivityCheck]: Floyd-Hoare automaton has 185 edges. 185 inductive. 0 not inductive. 0 times theorem prover too weak to decide inductivity. [2022-02-20 18:07:31,874 INFO L225 Difference]: With dead ends: 144 [2022-02-20 18:07:31,874 INFO L226 Difference]: Without dead ends: 76 [2022-02-20 18:07:31,875 INFO L932 BasicCegarLoop]: 0 DeclaredPredicates, 9 GetRequests, 3 SyntacticMatches, 0 SemanticMatches, 6 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 0 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=22, Invalid=34, Unknown=0, NotChecked=0, Total=56 [2022-02-20 18:07:31,876 INFO L933 BasicCegarLoop]: 89 mSDtfsCounter, 123 mSDsluCounter, 100 mSDsCounter, 0 mSdLazyCounter, 53 mSolverCounterSat, 13 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.1s Time, 0 mProtectedPredicate, 0 mProtectedAction, 123 SdHoareTripleChecker+Valid, 189 SdHoareTripleChecker+Invalid, 66 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 13 IncrementalHoareTripleChecker+Valid, 53 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.1s IncrementalHoareTripleChecker+Time [2022-02-20 18:07:31,877 INFO L934 BasicCegarLoop]: SdHoareTripleChecker [123 Valid, 189 Invalid, 66 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [13 Valid, 53 Invalid, 0 Unknown, 0 Unchecked, 0.1s Time] [2022-02-20 18:07:31,878 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 76 states. [2022-02-20 18:07:31,885 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 76 to 76. [2022-02-20 18:07:31,885 INFO L214 AbstractMinimizeNwa]: Start testing correctness of minimizeSevpa [2022-02-20 18:07:31,886 INFO L82 GeneralOperation]: Start isEquivalent. First operand 76 states. Second operand has 76 states, 55 states have (on average 1.290909090909091) internal successors, (71), 62 states have internal predecessors, (71), 12 states have call successors, (12), 8 states have call predecessors, (12), 8 states have return successors, (12), 8 states have call predecessors, (12), 12 states have call successors, (12) [2022-02-20 18:07:31,887 INFO L74 IsIncluded]: Start isIncluded. First operand 76 states. Second operand has 76 states, 55 states have (on average 1.290909090909091) internal successors, (71), 62 states have internal predecessors, (71), 12 states have call successors, (12), 8 states have call predecessors, (12), 8 states have return successors, (12), 8 states have call predecessors, (12), 12 states have call successors, (12) [2022-02-20 18:07:31,887 INFO L87 Difference]: Start difference. First operand 76 states. Second operand has 76 states, 55 states have (on average 1.290909090909091) internal successors, (71), 62 states have internal predecessors, (71), 12 states have call successors, (12), 8 states have call predecessors, (12), 8 states have return successors, (12), 8 states have call predecessors, (12), 12 states have call successors, (12) [2022-02-20 18:07:31,891 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-02-20 18:07:31,891 INFO L93 Difference]: Finished difference Result 76 states and 95 transitions. [2022-02-20 18:07:31,891 INFO L276 IsEmpty]: Start isEmpty. Operand 76 states and 95 transitions. [2022-02-20 18:07:31,891 INFO L282 IsEmpty]: Finished isEmpty. No accepting run. [2022-02-20 18:07:31,892 INFO L83 IsIncluded]: Finished isIncluded. Language is included [2022-02-20 18:07:31,892 INFO L74 IsIncluded]: Start isIncluded. First operand has 76 states, 55 states have (on average 1.290909090909091) internal successors, (71), 62 states have internal predecessors, (71), 12 states have call successors, (12), 8 states have call predecessors, (12), 8 states have return successors, (12), 8 states have call predecessors, (12), 12 states have call successors, (12) Second operand 76 states. [2022-02-20 18:07:31,894 INFO L87 Difference]: Start difference. First operand has 76 states, 55 states have (on average 1.290909090909091) internal successors, (71), 62 states have internal predecessors, (71), 12 states have call successors, (12), 8 states have call predecessors, (12), 8 states have return successors, (12), 8 states have call predecessors, (12), 12 states have call successors, (12) Second operand 76 states. [2022-02-20 18:07:31,897 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-02-20 18:07:31,897 INFO L93 Difference]: Finished difference Result 76 states and 95 transitions. [2022-02-20 18:07:31,897 INFO L276 IsEmpty]: Start isEmpty. Operand 76 states and 95 transitions. [2022-02-20 18:07:31,897 INFO L282 IsEmpty]: Finished isEmpty. No accepting run. [2022-02-20 18:07:31,897 INFO L83 IsIncluded]: Finished isIncluded. Language is included [2022-02-20 18:07:31,898 INFO L88 GeneralOperation]: Finished isEquivalent. [2022-02-20 18:07:31,898 INFO L221 AbstractMinimizeNwa]: Finished testing correctness of minimizeSevpa [2022-02-20 18:07:31,898 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 76 states, 55 states have (on average 1.290909090909091) internal successors, (71), 62 states have internal predecessors, (71), 12 states have call successors, (12), 8 states have call predecessors, (12), 8 states have return successors, (12), 8 states have call predecessors, (12), 12 states have call successors, (12) [2022-02-20 18:07:31,901 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 76 states to 76 states and 95 transitions. [2022-02-20 18:07:31,901 INFO L78 Accepts]: Start accepts. Automaton has 76 states and 95 transitions. Word has length 31 [2022-02-20 18:07:31,901 INFO L84 Accepts]: Finished accepts. word is rejected. [2022-02-20 18:07:31,901 INFO L470 AbstractCegarLoop]: Abstraction has 76 states and 95 transitions. [2022-02-20 18:07:31,902 INFO L471 AbstractCegarLoop]: INTERPOLANT automaton has has 6 states, 6 states have (on average 4.666666666666667) internal successors, (28), 6 states have internal predecessors, (28), 2 states have call successors, (2), 2 states have call predecessors, (2), 1 states have return successors, (1), 1 states have call predecessors, (1), 1 states have call successors, (1) [2022-02-20 18:07:31,902 INFO L276 IsEmpty]: Start isEmpty. Operand 76 states and 95 transitions. [2022-02-20 18:07:31,903 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 42 [2022-02-20 18:07:31,903 INFO L506 BasicCegarLoop]: Found error trace [2022-02-20 18:07:31,903 INFO L514 BasicCegarLoop]: trace histogram [1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-02-20 18:07:31,903 WARN L452 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable2 [2022-02-20 18:07:31,903 INFO L402 AbstractCegarLoop]: === Iteration 4 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2022-02-20 18:07:31,904 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2022-02-20 18:07:31,904 INFO L85 PathProgramCache]: Analyzing trace with hash 1055507879, now seen corresponding path program 1 times [2022-02-20 18:07:31,904 INFO L126 FreeRefinementEngine]: Executing refinement strategy CAMEL [2022-02-20 18:07:31,904 INFO L338 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [1673976686] [2022-02-20 18:07:31,905 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-02-20 18:07:31,905 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2022-02-20 18:07:31,940 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-02-20 18:07:31,992 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 21 [2022-02-20 18:07:31,994 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-02-20 18:07:31,999 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 2 [2022-02-20 18:07:32,001 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-02-20 18:07:32,007 INFO L290 TraceCheckUtils]: 0: Hoare triple {1599#true} assume true; {1599#true} is VALID [2022-02-20 18:07:32,008 INFO L284 TraceCheckUtils]: 1: Hoare quadruple {1599#true} {1599#true} #252#return; {1599#true} is VALID [2022-02-20 18:07:32,008 INFO L290 TraceCheckUtils]: 0: Hoare triple {1614#(= ~pumpRunning~0 |old(~pumpRunning~0)|)} havoc ~tmp~5#1; {1599#true} is VALID [2022-02-20 18:07:32,008 INFO L290 TraceCheckUtils]: 1: Hoare triple {1599#true} assume !(0 != ~pumpRunning~0); {1599#true} is VALID [2022-02-20 18:07:32,008 INFO L272 TraceCheckUtils]: 2: Hoare triple {1599#true} call processEnvironment__wrappee__base(); {1599#true} is VALID [2022-02-20 18:07:32,009 INFO L290 TraceCheckUtils]: 3: Hoare triple {1599#true} assume true; {1599#true} is VALID [2022-02-20 18:07:32,009 INFO L284 TraceCheckUtils]: 4: Hoare quadruple {1599#true} {1599#true} #252#return; {1599#true} is VALID [2022-02-20 18:07:32,009 INFO L290 TraceCheckUtils]: 5: Hoare triple {1599#true} assume true; {1599#true} is VALID [2022-02-20 18:07:32,010 INFO L284 TraceCheckUtils]: 6: Hoare quadruple {1599#true} {1601#(= ~methaneLevelCritical~0 0)} #232#return; {1601#(= ~methaneLevelCritical~0 0)} is VALID [2022-02-20 18:07:32,010 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 31 [2022-02-20 18:07:32,012 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-02-20 18:07:32,026 INFO L290 TraceCheckUtils]: 0: Hoare triple {1599#true} havoc ~retValue_acc~6;~retValue_acc~6 := ~methaneLevelCritical~0;#res := ~retValue_acc~6; {1617#(= |isMethaneLevelCritical_#res| ~methaneLevelCritical~0)} is VALID [2022-02-20 18:07:32,027 INFO L290 TraceCheckUtils]: 1: Hoare triple {1617#(= |isMethaneLevelCritical_#res| ~methaneLevelCritical~0)} assume true; {1617#(= |isMethaneLevelCritical_#res| ~methaneLevelCritical~0)} is VALID [2022-02-20 18:07:32,029 INFO L284 TraceCheckUtils]: 2: Hoare quadruple {1617#(= |isMethaneLevelCritical_#res| ~methaneLevelCritical~0)} {1601#(= ~methaneLevelCritical~0 0)} #234#return; {1612#(= |timeShift___utac_acc__Specification2_spec__2_#t~ret51#1| 0)} is VALID [2022-02-20 18:07:32,030 INFO L290 TraceCheckUtils]: 0: Hoare triple {1599#true} assume { :begin_inline_ULTIMATE.init } true;#NULL.base, #NULL.offset := 0, 0;assume 0 == #valid[0];assume 0 < #StackHeapBarrier;call #Ultimate.allocInit(2, 1);call write~init~int(48, 1, 0, 1);call write~init~int(0, 1, 1, 1);call #Ultimate.allocInit(31, 2);call #Ultimate.allocInit(12, 3);call #Ultimate.allocInit(30, 4);call #Ultimate.allocInit(9, 5);call #Ultimate.allocInit(21, 6);call #Ultimate.allocInit(30, 7);call #Ultimate.allocInit(9, 8);call #Ultimate.allocInit(21, 9);call #Ultimate.allocInit(30, 10);call #Ultimate.allocInit(9, 11);call #Ultimate.allocInit(25, 12);call #Ultimate.allocInit(30, 13);call #Ultimate.allocInit(9, 14);call #Ultimate.allocInit(25, 15);call #Ultimate.allocInit(13, 16);call #Ultimate.allocInit(7, 17);call write~init~int(44, 17, 0, 1);call write~init~int(77, 17, 1, 1);call write~init~int(101, 17, 2, 1);call write~init~int(116, 17, 3, 1);call write~init~int(104, 17, 4, 1);call write~init~int(58, 17, 5, 1);call write~init~int(0, 17, 6, 1);call #Ultimate.allocInit(5, 18);call write~init~int(67, 18, 0, 1);call write~init~int(82, 18, 1, 1);call write~init~int(73, 18, 2, 1);call write~init~int(84, 18, 3, 1);call write~init~int(0, 18, 4, 1);call #Ultimate.allocInit(3, 19);call write~init~int(79, 19, 0, 1);call write~init~int(75, 19, 1, 1);call write~init~int(0, 19, 2, 1);call #Ultimate.allocInit(2, 20);call write~init~int(41, 20, 0, 1);call write~init~int(0, 20, 1, 1);call #Ultimate.allocInit(13, 21);call #Ultimate.allocInit(3, 22);call write~init~int(79, 22, 0, 1);call write~init~int(110, 22, 1, 1);call write~init~int(0, 22, 2, 1);call #Ultimate.allocInit(4, 23);call write~init~int(79, 23, 0, 1);call write~init~int(102, 23, 1, 1);call write~init~int(102, 23, 2, 1);call write~init~int(0, 23, 3, 1);call #Ultimate.allocInit(7, 24);call write~init~int(44, 24, 0, 1);call write~init~int(80, 24, 1, 1);call write~init~int(117, 24, 2, 1);call write~init~int(109, 24, 3, 1);call write~init~int(112, 24, 4, 1);call write~init~int(58, 24, 5, 1);call write~init~int(0, 24, 6, 1);call #Ultimate.allocInit(3, 25);call write~init~int(79, 25, 0, 1);call write~init~int(110, 25, 1, 1);call write~init~int(0, 25, 2, 1);call #Ultimate.allocInit(4, 26);call write~init~int(79, 26, 0, 1);call write~init~int(102, 26, 1, 1);call write~init~int(102, 26, 2, 1);call write~init~int(0, 26, 3, 1);call #Ultimate.allocInit(3, 27);call write~init~int(41, 27, 0, 1);call write~init~int(32, 27, 1, 1);call write~init~int(0, 27, 2, 1);call #Ultimate.allocInit(2, 28);call write~init~int(10, 28, 0, 1);call write~init~int(0, 28, 1, 1);~head~0.base, ~head~0.offset := 0, 0;~cleanupTimeShifts~0 := 4;~waterLevel~0 := 1;~methaneLevelCritical~0 := 0;~pumpRunning~0 := 0;~systemActive~0 := 1;~methAndRunningLastTime~0 := 0; {1601#(= ~methaneLevelCritical~0 0)} is VALID [2022-02-20 18:07:32,031 INFO L290 TraceCheckUtils]: 1: Hoare triple {1601#(= ~methaneLevelCritical~0 0)} assume { :end_inline_ULTIMATE.init } true;assume { :begin_inline_main } true;havoc main_#res#1;havoc main_#t~ret28#1, main_~retValue_acc~5#1, main_~tmp~3#1;havoc main_~retValue_acc~5#1;havoc main_~tmp~3#1;assume { :begin_inline_select_helpers } true; {1601#(= ~methaneLevelCritical~0 0)} is VALID [2022-02-20 18:07:32,031 INFO L290 TraceCheckUtils]: 2: Hoare triple {1601#(= ~methaneLevelCritical~0 0)} assume { :end_inline_select_helpers } true;assume { :begin_inline_select_features } true; {1601#(= ~methaneLevelCritical~0 0)} is VALID [2022-02-20 18:07:32,031 INFO L290 TraceCheckUtils]: 3: Hoare triple {1601#(= ~methaneLevelCritical~0 0)} assume { :end_inline_select_features } true;assume { :begin_inline_valid_product } true;havoc valid_product_#res#1;havoc valid_product_~retValue_acc~4#1;havoc valid_product_~retValue_acc~4#1;valid_product_~retValue_acc~4#1 := 1;valid_product_#res#1 := valid_product_~retValue_acc~4#1; {1601#(= ~methaneLevelCritical~0 0)} is VALID [2022-02-20 18:07:32,032 INFO L290 TraceCheckUtils]: 4: Hoare triple {1601#(= ~methaneLevelCritical~0 0)} main_#t~ret28#1 := valid_product_#res#1;assume { :end_inline_valid_product } true;assume -2147483648 <= main_#t~ret28#1 && main_#t~ret28#1 <= 2147483647;main_~tmp~3#1 := main_#t~ret28#1;havoc main_#t~ret28#1; {1601#(= ~methaneLevelCritical~0 0)} is VALID [2022-02-20 18:07:32,032 INFO L290 TraceCheckUtils]: 5: Hoare triple {1601#(= ~methaneLevelCritical~0 0)} assume 0 != main_~tmp~3#1;assume { :begin_inline_setup } true; {1601#(= ~methaneLevelCritical~0 0)} is VALID [2022-02-20 18:07:32,033 INFO L290 TraceCheckUtils]: 6: Hoare triple {1601#(= ~methaneLevelCritical~0 0)} assume { :end_inline_setup } true;assume { :begin_inline_runTest } true;assume { :begin_inline___utac_acc__Specification2_spec__1 } true;~methAndRunningLastTime~0 := 0; {1601#(= ~methaneLevelCritical~0 0)} is VALID [2022-02-20 18:07:32,033 INFO L290 TraceCheckUtils]: 7: Hoare triple {1601#(= ~methaneLevelCritical~0 0)} assume { :end_inline___utac_acc__Specification2_spec__1 } true;assume { :begin_inline_test } true;havoc test_#t~nondet34#1, test_#t~nondet35#1, test_#t~nondet36#1, test_#t~nondet37#1, test_~splverifierCounter~0#1, test_~tmp~4#1, test_~tmp___0~0#1, test_~tmp___1~0#1, test_~tmp___2~0#1;havoc test_~splverifierCounter~0#1;havoc test_~tmp~4#1;havoc test_~tmp___0~0#1;havoc test_~tmp___1~0#1;havoc test_~tmp___2~0#1;test_~splverifierCounter~0#1 := 0; {1601#(= ~methaneLevelCritical~0 0)} is VALID [2022-02-20 18:07:32,034 INFO L290 TraceCheckUtils]: 8: Hoare triple {1601#(= ~methaneLevelCritical~0 0)} assume !false; {1601#(= ~methaneLevelCritical~0 0)} is VALID [2022-02-20 18:07:32,034 INFO L290 TraceCheckUtils]: 9: Hoare triple {1601#(= ~methaneLevelCritical~0 0)} assume test_~splverifierCounter~0#1 < 4; {1601#(= ~methaneLevelCritical~0 0)} is VALID [2022-02-20 18:07:32,035 INFO L290 TraceCheckUtils]: 10: Hoare triple {1601#(= ~methaneLevelCritical~0 0)} assume -2147483648 <= test_#t~nondet34#1 && test_#t~nondet34#1 <= 2147483647;test_~tmp~4#1 := test_#t~nondet34#1;havoc test_#t~nondet34#1; {1601#(= ~methaneLevelCritical~0 0)} is VALID [2022-02-20 18:07:32,035 INFO L290 TraceCheckUtils]: 11: Hoare triple {1601#(= ~methaneLevelCritical~0 0)} assume !(0 != test_~tmp~4#1); {1601#(= ~methaneLevelCritical~0 0)} is VALID [2022-02-20 18:07:32,036 INFO L290 TraceCheckUtils]: 12: Hoare triple {1601#(= ~methaneLevelCritical~0 0)} assume -2147483648 <= test_#t~nondet35#1 && test_#t~nondet35#1 <= 2147483647;test_~tmp___0~0#1 := test_#t~nondet35#1;havoc test_#t~nondet35#1; {1601#(= ~methaneLevelCritical~0 0)} is VALID [2022-02-20 18:07:32,036 INFO L290 TraceCheckUtils]: 13: Hoare triple {1601#(= ~methaneLevelCritical~0 0)} assume !(0 != test_~tmp___0~0#1); {1601#(= ~methaneLevelCritical~0 0)} is VALID [2022-02-20 18:07:32,036 INFO L290 TraceCheckUtils]: 14: Hoare triple {1601#(= ~methaneLevelCritical~0 0)} assume -2147483648 <= test_#t~nondet36#1 && test_#t~nondet36#1 <= 2147483647;test_~tmp___2~0#1 := test_#t~nondet36#1;havoc test_#t~nondet36#1; {1601#(= ~methaneLevelCritical~0 0)} is VALID [2022-02-20 18:07:32,037 INFO L290 TraceCheckUtils]: 15: Hoare triple {1601#(= ~methaneLevelCritical~0 0)} assume !(0 != test_~tmp___2~0#1);assume -2147483648 <= test_#t~nondet37#1 && test_#t~nondet37#1 <= 2147483647;test_~tmp___1~0#1 := test_#t~nondet37#1;havoc test_#t~nondet37#1; {1601#(= ~methaneLevelCritical~0 0)} is VALID [2022-02-20 18:07:32,037 INFO L290 TraceCheckUtils]: 16: Hoare triple {1601#(= ~methaneLevelCritical~0 0)} assume 0 != test_~tmp___1~0#1; {1601#(= ~methaneLevelCritical~0 0)} is VALID [2022-02-20 18:07:32,038 INFO L272 TraceCheckUtils]: 17: Hoare triple {1601#(= ~methaneLevelCritical~0 0)} call timeShift(); {1601#(= ~methaneLevelCritical~0 0)} is VALID [2022-02-20 18:07:32,038 INFO L290 TraceCheckUtils]: 18: Hoare triple {1601#(= ~methaneLevelCritical~0 0)} assume !(0 != ~pumpRunning~0); {1601#(= ~methaneLevelCritical~0 0)} is VALID [2022-02-20 18:07:32,038 INFO L290 TraceCheckUtils]: 19: Hoare triple {1601#(= ~methaneLevelCritical~0 0)} assume 0 != ~systemActive~0;assume { :begin_inline_processEnvironment } true;havoc processEnvironment_#t~ret39#1, processEnvironment_~tmp~6#1;havoc processEnvironment_~tmp~6#1; {1601#(= ~methaneLevelCritical~0 0)} is VALID [2022-02-20 18:07:32,039 INFO L290 TraceCheckUtils]: 20: Hoare triple {1601#(= ~methaneLevelCritical~0 0)} assume !(0 != ~pumpRunning~0); {1601#(= ~methaneLevelCritical~0 0)} is VALID [2022-02-20 18:07:32,039 INFO L272 TraceCheckUtils]: 21: Hoare triple {1601#(= ~methaneLevelCritical~0 0)} call processEnvironment__wrappee__methaneQuery(); {1614#(= ~pumpRunning~0 |old(~pumpRunning~0)|)} is VALID [2022-02-20 18:07:32,040 INFO L290 TraceCheckUtils]: 22: Hoare triple {1614#(= ~pumpRunning~0 |old(~pumpRunning~0)|)} havoc ~tmp~5#1; {1599#true} is VALID [2022-02-20 18:07:32,040 INFO L290 TraceCheckUtils]: 23: Hoare triple {1599#true} assume !(0 != ~pumpRunning~0); {1599#true} is VALID [2022-02-20 18:07:32,040 INFO L272 TraceCheckUtils]: 24: Hoare triple {1599#true} call processEnvironment__wrappee__base(); {1599#true} is VALID [2022-02-20 18:07:32,040 INFO L290 TraceCheckUtils]: 25: Hoare triple {1599#true} assume true; {1599#true} is VALID [2022-02-20 18:07:32,040 INFO L284 TraceCheckUtils]: 26: Hoare quadruple {1599#true} {1599#true} #252#return; {1599#true} is VALID [2022-02-20 18:07:32,041 INFO L290 TraceCheckUtils]: 27: Hoare triple {1599#true} assume true; {1599#true} is VALID [2022-02-20 18:07:32,041 INFO L284 TraceCheckUtils]: 28: Hoare quadruple {1599#true} {1601#(= ~methaneLevelCritical~0 0)} #232#return; {1601#(= ~methaneLevelCritical~0 0)} is VALID [2022-02-20 18:07:32,041 INFO L290 TraceCheckUtils]: 29: Hoare triple {1601#(= ~methaneLevelCritical~0 0)} assume { :end_inline_processEnvironment } true; {1601#(= ~methaneLevelCritical~0 0)} is VALID [2022-02-20 18:07:32,042 INFO L290 TraceCheckUtils]: 30: Hoare triple {1601#(= ~methaneLevelCritical~0 0)} assume { :begin_inline___utac_acc__Specification2_spec__2 } true;havoc __utac_acc__Specification2_spec__2_#t~ret51#1, __utac_acc__Specification2_spec__2_#t~ret52#1, __utac_acc__Specification2_spec__2_~tmp~9#1, __utac_acc__Specification2_spec__2_~tmp___0~2#1;havoc __utac_acc__Specification2_spec__2_~tmp~9#1;havoc __utac_acc__Specification2_spec__2_~tmp___0~2#1; {1601#(= ~methaneLevelCritical~0 0)} is VALID [2022-02-20 18:07:32,042 INFO L272 TraceCheckUtils]: 31: Hoare triple {1601#(= ~methaneLevelCritical~0 0)} call __utac_acc__Specification2_spec__2_#t~ret51#1 := isMethaneLevelCritical(); {1599#true} is VALID [2022-02-20 18:07:32,042 INFO L290 TraceCheckUtils]: 32: Hoare triple {1599#true} havoc ~retValue_acc~6;~retValue_acc~6 := ~methaneLevelCritical~0;#res := ~retValue_acc~6; {1617#(= |isMethaneLevelCritical_#res| ~methaneLevelCritical~0)} is VALID [2022-02-20 18:07:32,043 INFO L290 TraceCheckUtils]: 33: Hoare triple {1617#(= |isMethaneLevelCritical_#res| ~methaneLevelCritical~0)} assume true; {1617#(= |isMethaneLevelCritical_#res| ~methaneLevelCritical~0)} is VALID [2022-02-20 18:07:32,043 INFO L284 TraceCheckUtils]: 34: Hoare quadruple {1617#(= |isMethaneLevelCritical_#res| ~methaneLevelCritical~0)} {1601#(= ~methaneLevelCritical~0 0)} #234#return; {1612#(= |timeShift___utac_acc__Specification2_spec__2_#t~ret51#1| 0)} is VALID [2022-02-20 18:07:32,044 INFO L290 TraceCheckUtils]: 35: Hoare triple {1612#(= |timeShift___utac_acc__Specification2_spec__2_#t~ret51#1| 0)} assume -2147483648 <= __utac_acc__Specification2_spec__2_#t~ret51#1 && __utac_acc__Specification2_spec__2_#t~ret51#1 <= 2147483647;__utac_acc__Specification2_spec__2_~tmp~9#1 := __utac_acc__Specification2_spec__2_#t~ret51#1;havoc __utac_acc__Specification2_spec__2_#t~ret51#1; {1613#(= |timeShift___utac_acc__Specification2_spec__2_~tmp~9#1| 0)} is VALID [2022-02-20 18:07:32,044 INFO L290 TraceCheckUtils]: 36: Hoare triple {1613#(= |timeShift___utac_acc__Specification2_spec__2_~tmp~9#1| 0)} assume 0 != __utac_acc__Specification2_spec__2_~tmp~9#1;assume { :begin_inline_isPumpRunning } true;havoc isPumpRunning_#res#1;havoc isPumpRunning_~retValue_acc~10#1;havoc isPumpRunning_~retValue_acc~10#1;isPumpRunning_~retValue_acc~10#1 := ~pumpRunning~0;isPumpRunning_#res#1 := isPumpRunning_~retValue_acc~10#1; {1600#false} is VALID [2022-02-20 18:07:32,044 INFO L290 TraceCheckUtils]: 37: Hoare triple {1600#false} __utac_acc__Specification2_spec__2_#t~ret52#1 := isPumpRunning_#res#1;assume { :end_inline_isPumpRunning } true;assume -2147483648 <= __utac_acc__Specification2_spec__2_#t~ret52#1 && __utac_acc__Specification2_spec__2_#t~ret52#1 <= 2147483647;__utac_acc__Specification2_spec__2_~tmp___0~2#1 := __utac_acc__Specification2_spec__2_#t~ret52#1;havoc __utac_acc__Specification2_spec__2_#t~ret52#1; {1600#false} is VALID [2022-02-20 18:07:32,045 INFO L290 TraceCheckUtils]: 38: Hoare triple {1600#false} assume 0 != __utac_acc__Specification2_spec__2_~tmp___0~2#1; {1600#false} is VALID [2022-02-20 18:07:32,045 INFO L290 TraceCheckUtils]: 39: Hoare triple {1600#false} assume 0 != ~methAndRunningLastTime~0;assume { :begin_inline___automaton_fail } true; {1600#false} is VALID [2022-02-20 18:07:32,045 INFO L290 TraceCheckUtils]: 40: Hoare triple {1600#false} assume !false; {1600#false} is VALID [2022-02-20 18:07:32,045 INFO L134 CoverageAnalysis]: Checked inductivity of 0 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2022-02-20 18:07:32,046 INFO L144 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2022-02-20 18:07:32,046 INFO L338 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [1673976686] [2022-02-20 18:07:32,046 INFO L165 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [1673976686] provided 1 perfect and 0 imperfect interpolant sequences [2022-02-20 18:07:32,046 INFO L191 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2022-02-20 18:07:32,046 INFO L204 FreeRefinementEngine]: Number of different interpolants: perfect sequences [7] imperfect sequences [] total 7 [2022-02-20 18:07:32,046 INFO L118 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [1316132150] [2022-02-20 18:07:32,047 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2022-02-20 18:07:32,047 INFO L78 Accepts]: Start accepts. Automaton has has 7 states, 7 states have (on average 4.857142857142857) internal successors, (34), 5 states have internal predecessors, (34), 2 states have call successors, (4), 3 states have call predecessors, (4), 2 states have return successors, (3), 3 states have call predecessors, (3), 2 states have call successors, (3) Word has length 41 [2022-02-20 18:07:32,047 INFO L84 Accepts]: Finished accepts. word is accepted. [2022-02-20 18:07:32,048 INFO L86 InductivityCheck]: Starting indutivity check of a Floyd-Hoare automaton with has 7 states, 7 states have (on average 4.857142857142857) internal successors, (34), 5 states have internal predecessors, (34), 2 states have call successors, (4), 3 states have call predecessors, (4), 2 states have return successors, (3), 3 states have call predecessors, (3), 2 states have call successors, (3) [2022-02-20 18:07:32,077 INFO L122 InductivityCheck]: Floyd-Hoare automaton has 41 edges. 41 inductive. 0 not inductive. 0 times theorem prover too weak to decide inductivity. [2022-02-20 18:07:32,077 INFO L546 AbstractCegarLoop]: INTERPOLANT automaton has 7 states [2022-02-20 18:07:32,077 INFO L108 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2022-02-20 18:07:32,078 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 7 interpolants. [2022-02-20 18:07:32,078 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=11, Invalid=31, Unknown=0, NotChecked=0, Total=42 [2022-02-20 18:07:32,078 INFO L87 Difference]: Start difference. First operand 76 states and 95 transitions. Second operand has 7 states, 7 states have (on average 4.857142857142857) internal successors, (34), 5 states have internal predecessors, (34), 2 states have call successors, (4), 3 states have call predecessors, (4), 2 states have return successors, (3), 3 states have call predecessors, (3), 2 states have call successors, (3) [2022-02-20 18:07:32,824 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-02-20 18:07:32,824 INFO L93 Difference]: Finished difference Result 238 states and 304 transitions. [2022-02-20 18:07:32,824 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 13 states. [2022-02-20 18:07:32,824 INFO L78 Accepts]: Start accepts. Automaton has has 7 states, 7 states have (on average 4.857142857142857) internal successors, (34), 5 states have internal predecessors, (34), 2 states have call successors, (4), 3 states have call predecessors, (4), 2 states have return successors, (3), 3 states have call predecessors, (3), 2 states have call successors, (3) Word has length 41 [2022-02-20 18:07:32,826 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2022-02-20 18:07:32,826 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 7 states, 7 states have (on average 4.857142857142857) internal successors, (34), 5 states have internal predecessors, (34), 2 states have call successors, (4), 3 states have call predecessors, (4), 2 states have return successors, (3), 3 states have call predecessors, (3), 2 states have call successors, (3) [2022-02-20 18:07:32,831 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 13 states to 13 states and 304 transitions. [2022-02-20 18:07:32,832 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 7 states, 7 states have (on average 4.857142857142857) internal successors, (34), 5 states have internal predecessors, (34), 2 states have call successors, (4), 3 states have call predecessors, (4), 2 states have return successors, (3), 3 states have call predecessors, (3), 2 states have call successors, (3) [2022-02-20 18:07:32,837 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 13 states to 13 states and 304 transitions. [2022-02-20 18:07:32,837 INFO L86 InductivityCheck]: Starting indutivity check of a Floyd-Hoare automaton with 13 states and 304 transitions. [2022-02-20 18:07:33,063 INFO L122 InductivityCheck]: Floyd-Hoare automaton has 304 edges. 304 inductive. 0 not inductive. 0 times theorem prover too weak to decide inductivity. [2022-02-20 18:07:33,068 INFO L225 Difference]: With dead ends: 238 [2022-02-20 18:07:33,068 INFO L226 Difference]: Without dead ends: 170 [2022-02-20 18:07:33,069 INFO L932 BasicCegarLoop]: 0 DeclaredPredicates, 19 GetRequests, 6 SyntacticMatches, 0 SemanticMatches, 13 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 25 ImplicationChecksByTransitivity, 0.1s TimeCoverageRelationStatistics Valid=53, Invalid=157, Unknown=0, NotChecked=0, Total=210 [2022-02-20 18:07:33,070 INFO L933 BasicCegarLoop]: 83 mSDtfsCounter, 144 mSDsluCounter, 271 mSDsCounter, 0 mSdLazyCounter, 223 mSolverCounterSat, 58 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.3s Time, 0 mProtectedPredicate, 0 mProtectedAction, 153 SdHoareTripleChecker+Valid, 354 SdHoareTripleChecker+Invalid, 281 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 58 IncrementalHoareTripleChecker+Valid, 223 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.3s IncrementalHoareTripleChecker+Time [2022-02-20 18:07:33,070 INFO L934 BasicCegarLoop]: SdHoareTripleChecker [153 Valid, 354 Invalid, 281 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [58 Valid, 223 Invalid, 0 Unknown, 0 Unchecked, 0.3s Time] [2022-02-20 18:07:33,071 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 170 states. [2022-02-20 18:07:33,084 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 170 to 139. [2022-02-20 18:07:33,086 INFO L214 AbstractMinimizeNwa]: Start testing correctness of minimizeSevpa [2022-02-20 18:07:33,086 INFO L82 GeneralOperation]: Start isEquivalent. First operand 170 states. Second operand has 139 states, 98 states have (on average 1.2857142857142858) internal successors, (126), 111 states have internal predecessors, (126), 24 states have call successors, (24), 16 states have call predecessors, (24), 16 states have return successors, (25), 16 states have call predecessors, (25), 24 states have call successors, (25) [2022-02-20 18:07:33,088 INFO L74 IsIncluded]: Start isIncluded. First operand 170 states. Second operand has 139 states, 98 states have (on average 1.2857142857142858) internal successors, (126), 111 states have internal predecessors, (126), 24 states have call successors, (24), 16 states have call predecessors, (24), 16 states have return successors, (25), 16 states have call predecessors, (25), 24 states have call successors, (25) [2022-02-20 18:07:33,089 INFO L87 Difference]: Start difference. First operand 170 states. Second operand has 139 states, 98 states have (on average 1.2857142857142858) internal successors, (126), 111 states have internal predecessors, (126), 24 states have call successors, (24), 16 states have call predecessors, (24), 16 states have return successors, (25), 16 states have call predecessors, (25), 24 states have call successors, (25) [2022-02-20 18:07:33,095 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-02-20 18:07:33,095 INFO L93 Difference]: Finished difference Result 170 states and 212 transitions. [2022-02-20 18:07:33,095 INFO L276 IsEmpty]: Start isEmpty. Operand 170 states and 212 transitions. [2022-02-20 18:07:33,096 INFO L282 IsEmpty]: Finished isEmpty. No accepting run. [2022-02-20 18:07:33,096 INFO L83 IsIncluded]: Finished isIncluded. Language is included [2022-02-20 18:07:33,097 INFO L74 IsIncluded]: Start isIncluded. First operand has 139 states, 98 states have (on average 1.2857142857142858) internal successors, (126), 111 states have internal predecessors, (126), 24 states have call successors, (24), 16 states have call predecessors, (24), 16 states have return successors, (25), 16 states have call predecessors, (25), 24 states have call successors, (25) Second operand 170 states. [2022-02-20 18:07:33,098 INFO L87 Difference]: Start difference. First operand has 139 states, 98 states have (on average 1.2857142857142858) internal successors, (126), 111 states have internal predecessors, (126), 24 states have call successors, (24), 16 states have call predecessors, (24), 16 states have return successors, (25), 16 states have call predecessors, (25), 24 states have call successors, (25) Second operand 170 states. [2022-02-20 18:07:33,103 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-02-20 18:07:33,104 INFO L93 Difference]: Finished difference Result 170 states and 212 transitions. [2022-02-20 18:07:33,104 INFO L276 IsEmpty]: Start isEmpty. Operand 170 states and 212 transitions. [2022-02-20 18:07:33,104 INFO L282 IsEmpty]: Finished isEmpty. No accepting run. [2022-02-20 18:07:33,105 INFO L83 IsIncluded]: Finished isIncluded. Language is included [2022-02-20 18:07:33,105 INFO L88 GeneralOperation]: Finished isEquivalent. [2022-02-20 18:07:33,105 INFO L221 AbstractMinimizeNwa]: Finished testing correctness of minimizeSevpa [2022-02-20 18:07:33,105 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 139 states, 98 states have (on average 1.2857142857142858) internal successors, (126), 111 states have internal predecessors, (126), 24 states have call successors, (24), 16 states have call predecessors, (24), 16 states have return successors, (25), 16 states have call predecessors, (25), 24 states have call successors, (25) [2022-02-20 18:07:33,110 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 139 states to 139 states and 175 transitions. [2022-02-20 18:07:33,110 INFO L78 Accepts]: Start accepts. Automaton has 139 states and 175 transitions. Word has length 41 [2022-02-20 18:07:33,110 INFO L84 Accepts]: Finished accepts. word is rejected. [2022-02-20 18:07:33,110 INFO L470 AbstractCegarLoop]: Abstraction has 139 states and 175 transitions. [2022-02-20 18:07:33,111 INFO L471 AbstractCegarLoop]: INTERPOLANT automaton has has 7 states, 7 states have (on average 4.857142857142857) internal successors, (34), 5 states have internal predecessors, (34), 2 states have call successors, (4), 3 states have call predecessors, (4), 2 states have return successors, (3), 3 states have call predecessors, (3), 2 states have call successors, (3) [2022-02-20 18:07:33,111 INFO L276 IsEmpty]: Start isEmpty. Operand 139 states and 175 transitions. [2022-02-20 18:07:33,112 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 46 [2022-02-20 18:07:33,112 INFO L506 BasicCegarLoop]: Found error trace [2022-02-20 18:07:33,112 INFO L514 BasicCegarLoop]: trace histogram [1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-02-20 18:07:33,112 WARN L452 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable3 [2022-02-20 18:07:33,112 INFO L402 AbstractCegarLoop]: === Iteration 5 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2022-02-20 18:07:33,113 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2022-02-20 18:07:33,113 INFO L85 PathProgramCache]: Analyzing trace with hash -1634457109, now seen corresponding path program 1 times [2022-02-20 18:07:33,113 INFO L126 FreeRefinementEngine]: Executing refinement strategy CAMEL [2022-02-20 18:07:33,113 INFO L338 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [7496910] [2022-02-20 18:07:33,113 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-02-20 18:07:33,114 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2022-02-20 18:07:33,137 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-02-20 18:07:33,189 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 14 [2022-02-20 18:07:33,191 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-02-20 18:07:33,194 INFO L290 TraceCheckUtils]: 0: Hoare triple {2529#(= |old(~methaneLevelCritical~0)| ~methaneLevelCritical~0)} assume !(0 != ~methaneLevelCritical~0);~methaneLevelCritical~0 := 1; {2511#true} is VALID [2022-02-20 18:07:33,194 INFO L290 TraceCheckUtils]: 1: Hoare triple {2511#true} assume true; {2511#true} is VALID [2022-02-20 18:07:33,194 INFO L284 TraceCheckUtils]: 2: Hoare quadruple {2511#true} {2513#(= ~pumpRunning~0 0)} #242#return; {2513#(= ~pumpRunning~0 0)} is VALID [2022-02-20 18:07:33,202 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 25 [2022-02-20 18:07:33,204 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-02-20 18:07:33,215 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 2 [2022-02-20 18:07:33,219 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-02-20 18:07:33,221 INFO L290 TraceCheckUtils]: 0: Hoare triple {2511#true} assume true; {2511#true} is VALID [2022-02-20 18:07:33,222 INFO L284 TraceCheckUtils]: 1: Hoare quadruple {2511#true} {2513#(= ~pumpRunning~0 0)} #252#return; {2513#(= ~pumpRunning~0 0)} is VALID [2022-02-20 18:07:33,222 INFO L290 TraceCheckUtils]: 0: Hoare triple {2530#(= ~pumpRunning~0 |old(~pumpRunning~0)|)} havoc ~tmp~5#1; {2511#true} is VALID [2022-02-20 18:07:33,223 INFO L290 TraceCheckUtils]: 1: Hoare triple {2511#true} assume !(0 != ~pumpRunning~0); {2513#(= ~pumpRunning~0 0)} is VALID [2022-02-20 18:07:33,223 INFO L272 TraceCheckUtils]: 2: Hoare triple {2513#(= ~pumpRunning~0 0)} call processEnvironment__wrappee__base(); {2511#true} is VALID [2022-02-20 18:07:33,223 INFO L290 TraceCheckUtils]: 3: Hoare triple {2511#true} assume true; {2511#true} is VALID [2022-02-20 18:07:33,223 INFO L284 TraceCheckUtils]: 4: Hoare quadruple {2511#true} {2513#(= ~pumpRunning~0 0)} #252#return; {2513#(= ~pumpRunning~0 0)} is VALID [2022-02-20 18:07:33,224 INFO L290 TraceCheckUtils]: 5: Hoare triple {2513#(= ~pumpRunning~0 0)} assume true; {2513#(= ~pumpRunning~0 0)} is VALID [2022-02-20 18:07:33,224 INFO L284 TraceCheckUtils]: 6: Hoare quadruple {2513#(= ~pumpRunning~0 0)} {2513#(= ~pumpRunning~0 0)} #232#return; {2513#(= ~pumpRunning~0 0)} is VALID [2022-02-20 18:07:33,224 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 35 [2022-02-20 18:07:33,225 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-02-20 18:07:33,230 INFO L290 TraceCheckUtils]: 0: Hoare triple {2511#true} havoc ~retValue_acc~6;~retValue_acc~6 := ~methaneLevelCritical~0;#res := ~retValue_acc~6; {2511#true} is VALID [2022-02-20 18:07:33,230 INFO L290 TraceCheckUtils]: 1: Hoare triple {2511#true} assume true; {2511#true} is VALID [2022-02-20 18:07:33,231 INFO L284 TraceCheckUtils]: 2: Hoare quadruple {2511#true} {2513#(= ~pumpRunning~0 0)} #234#return; {2513#(= ~pumpRunning~0 0)} is VALID [2022-02-20 18:07:33,231 INFO L290 TraceCheckUtils]: 0: Hoare triple {2511#true} assume { :begin_inline_ULTIMATE.init } true;#NULL.base, #NULL.offset := 0, 0;assume 0 == #valid[0];assume 0 < #StackHeapBarrier;call #Ultimate.allocInit(2, 1);call write~init~int(48, 1, 0, 1);call write~init~int(0, 1, 1, 1);call #Ultimate.allocInit(31, 2);call #Ultimate.allocInit(12, 3);call #Ultimate.allocInit(30, 4);call #Ultimate.allocInit(9, 5);call #Ultimate.allocInit(21, 6);call #Ultimate.allocInit(30, 7);call #Ultimate.allocInit(9, 8);call #Ultimate.allocInit(21, 9);call #Ultimate.allocInit(30, 10);call #Ultimate.allocInit(9, 11);call #Ultimate.allocInit(25, 12);call #Ultimate.allocInit(30, 13);call #Ultimate.allocInit(9, 14);call #Ultimate.allocInit(25, 15);call #Ultimate.allocInit(13, 16);call #Ultimate.allocInit(7, 17);call write~init~int(44, 17, 0, 1);call write~init~int(77, 17, 1, 1);call write~init~int(101, 17, 2, 1);call write~init~int(116, 17, 3, 1);call write~init~int(104, 17, 4, 1);call write~init~int(58, 17, 5, 1);call write~init~int(0, 17, 6, 1);call #Ultimate.allocInit(5, 18);call write~init~int(67, 18, 0, 1);call write~init~int(82, 18, 1, 1);call write~init~int(73, 18, 2, 1);call write~init~int(84, 18, 3, 1);call write~init~int(0, 18, 4, 1);call #Ultimate.allocInit(3, 19);call write~init~int(79, 19, 0, 1);call write~init~int(75, 19, 1, 1);call write~init~int(0, 19, 2, 1);call #Ultimate.allocInit(2, 20);call write~init~int(41, 20, 0, 1);call write~init~int(0, 20, 1, 1);call #Ultimate.allocInit(13, 21);call #Ultimate.allocInit(3, 22);call write~init~int(79, 22, 0, 1);call write~init~int(110, 22, 1, 1);call write~init~int(0, 22, 2, 1);call #Ultimate.allocInit(4, 23);call write~init~int(79, 23, 0, 1);call write~init~int(102, 23, 1, 1);call write~init~int(102, 23, 2, 1);call write~init~int(0, 23, 3, 1);call #Ultimate.allocInit(7, 24);call write~init~int(44, 24, 0, 1);call write~init~int(80, 24, 1, 1);call write~init~int(117, 24, 2, 1);call write~init~int(109, 24, 3, 1);call write~init~int(112, 24, 4, 1);call write~init~int(58, 24, 5, 1);call write~init~int(0, 24, 6, 1);call #Ultimate.allocInit(3, 25);call write~init~int(79, 25, 0, 1);call write~init~int(110, 25, 1, 1);call write~init~int(0, 25, 2, 1);call #Ultimate.allocInit(4, 26);call write~init~int(79, 26, 0, 1);call write~init~int(102, 26, 1, 1);call write~init~int(102, 26, 2, 1);call write~init~int(0, 26, 3, 1);call #Ultimate.allocInit(3, 27);call write~init~int(41, 27, 0, 1);call write~init~int(32, 27, 1, 1);call write~init~int(0, 27, 2, 1);call #Ultimate.allocInit(2, 28);call write~init~int(10, 28, 0, 1);call write~init~int(0, 28, 1, 1);~head~0.base, ~head~0.offset := 0, 0;~cleanupTimeShifts~0 := 4;~waterLevel~0 := 1;~methaneLevelCritical~0 := 0;~pumpRunning~0 := 0;~systemActive~0 := 1;~methAndRunningLastTime~0 := 0; {2513#(= ~pumpRunning~0 0)} is VALID [2022-02-20 18:07:33,232 INFO L290 TraceCheckUtils]: 1: Hoare triple {2513#(= ~pumpRunning~0 0)} assume { :end_inline_ULTIMATE.init } true;assume { :begin_inline_main } true;havoc main_#res#1;havoc main_#t~ret28#1, main_~retValue_acc~5#1, main_~tmp~3#1;havoc main_~retValue_acc~5#1;havoc main_~tmp~3#1;assume { :begin_inline_select_helpers } true; {2513#(= ~pumpRunning~0 0)} is VALID [2022-02-20 18:07:33,232 INFO L290 TraceCheckUtils]: 2: Hoare triple {2513#(= ~pumpRunning~0 0)} assume { :end_inline_select_helpers } true;assume { :begin_inline_select_features } true; {2513#(= ~pumpRunning~0 0)} is VALID [2022-02-20 18:07:33,232 INFO L290 TraceCheckUtils]: 3: Hoare triple {2513#(= ~pumpRunning~0 0)} assume { :end_inline_select_features } true;assume { :begin_inline_valid_product } true;havoc valid_product_#res#1;havoc valid_product_~retValue_acc~4#1;havoc valid_product_~retValue_acc~4#1;valid_product_~retValue_acc~4#1 := 1;valid_product_#res#1 := valid_product_~retValue_acc~4#1; {2513#(= ~pumpRunning~0 0)} is VALID [2022-02-20 18:07:33,233 INFO L290 TraceCheckUtils]: 4: Hoare triple {2513#(= ~pumpRunning~0 0)} main_#t~ret28#1 := valid_product_#res#1;assume { :end_inline_valid_product } true;assume -2147483648 <= main_#t~ret28#1 && main_#t~ret28#1 <= 2147483647;main_~tmp~3#1 := main_#t~ret28#1;havoc main_#t~ret28#1; {2513#(= ~pumpRunning~0 0)} is VALID [2022-02-20 18:07:33,233 INFO L290 TraceCheckUtils]: 5: Hoare triple {2513#(= ~pumpRunning~0 0)} assume 0 != main_~tmp~3#1;assume { :begin_inline_setup } true; {2513#(= ~pumpRunning~0 0)} is VALID [2022-02-20 18:07:33,233 INFO L290 TraceCheckUtils]: 6: Hoare triple {2513#(= ~pumpRunning~0 0)} assume { :end_inline_setup } true;assume { :begin_inline_runTest } true;assume { :begin_inline___utac_acc__Specification2_spec__1 } true;~methAndRunningLastTime~0 := 0; {2513#(= ~pumpRunning~0 0)} is VALID [2022-02-20 18:07:33,234 INFO L290 TraceCheckUtils]: 7: Hoare triple {2513#(= ~pumpRunning~0 0)} assume { :end_inline___utac_acc__Specification2_spec__1 } true;assume { :begin_inline_test } true;havoc test_#t~nondet34#1, test_#t~nondet35#1, test_#t~nondet36#1, test_#t~nondet37#1, test_~splverifierCounter~0#1, test_~tmp~4#1, test_~tmp___0~0#1, test_~tmp___1~0#1, test_~tmp___2~0#1;havoc test_~splverifierCounter~0#1;havoc test_~tmp~4#1;havoc test_~tmp___0~0#1;havoc test_~tmp___1~0#1;havoc test_~tmp___2~0#1;test_~splverifierCounter~0#1 := 0; {2513#(= ~pumpRunning~0 0)} is VALID [2022-02-20 18:07:33,234 INFO L290 TraceCheckUtils]: 8: Hoare triple {2513#(= ~pumpRunning~0 0)} assume !false; {2513#(= ~pumpRunning~0 0)} is VALID [2022-02-20 18:07:33,235 INFO L290 TraceCheckUtils]: 9: Hoare triple {2513#(= ~pumpRunning~0 0)} assume test_~splverifierCounter~0#1 < 4; {2513#(= ~pumpRunning~0 0)} is VALID [2022-02-20 18:07:33,235 INFO L290 TraceCheckUtils]: 10: Hoare triple {2513#(= ~pumpRunning~0 0)} assume -2147483648 <= test_#t~nondet34#1 && test_#t~nondet34#1 <= 2147483647;test_~tmp~4#1 := test_#t~nondet34#1;havoc test_#t~nondet34#1; {2513#(= ~pumpRunning~0 0)} is VALID [2022-02-20 18:07:33,235 INFO L290 TraceCheckUtils]: 11: Hoare triple {2513#(= ~pumpRunning~0 0)} assume !(0 != test_~tmp~4#1); {2513#(= ~pumpRunning~0 0)} is VALID [2022-02-20 18:07:33,236 INFO L290 TraceCheckUtils]: 12: Hoare triple {2513#(= ~pumpRunning~0 0)} assume -2147483648 <= test_#t~nondet35#1 && test_#t~nondet35#1 <= 2147483647;test_~tmp___0~0#1 := test_#t~nondet35#1;havoc test_#t~nondet35#1; {2513#(= ~pumpRunning~0 0)} is VALID [2022-02-20 18:07:33,236 INFO L290 TraceCheckUtils]: 13: Hoare triple {2513#(= ~pumpRunning~0 0)} assume 0 != test_~tmp___0~0#1; {2513#(= ~pumpRunning~0 0)} is VALID [2022-02-20 18:07:33,237 INFO L272 TraceCheckUtils]: 14: Hoare triple {2513#(= ~pumpRunning~0 0)} call changeMethaneLevel(); {2529#(= |old(~methaneLevelCritical~0)| ~methaneLevelCritical~0)} is VALID [2022-02-20 18:07:33,237 INFO L290 TraceCheckUtils]: 15: Hoare triple {2529#(= |old(~methaneLevelCritical~0)| ~methaneLevelCritical~0)} assume !(0 != ~methaneLevelCritical~0);~methaneLevelCritical~0 := 1; {2511#true} is VALID [2022-02-20 18:07:33,237 INFO L290 TraceCheckUtils]: 16: Hoare triple {2511#true} assume true; {2511#true} is VALID [2022-02-20 18:07:33,237 INFO L284 TraceCheckUtils]: 17: Hoare quadruple {2511#true} {2513#(= ~pumpRunning~0 0)} #242#return; {2513#(= ~pumpRunning~0 0)} is VALID [2022-02-20 18:07:33,238 INFO L290 TraceCheckUtils]: 18: Hoare triple {2513#(= ~pumpRunning~0 0)} assume -2147483648 <= test_#t~nondet36#1 && test_#t~nondet36#1 <= 2147483647;test_~tmp___2~0#1 := test_#t~nondet36#1;havoc test_#t~nondet36#1; {2513#(= ~pumpRunning~0 0)} is VALID [2022-02-20 18:07:33,238 INFO L290 TraceCheckUtils]: 19: Hoare triple {2513#(= ~pumpRunning~0 0)} assume !(0 != test_~tmp___2~0#1);assume -2147483648 <= test_#t~nondet37#1 && test_#t~nondet37#1 <= 2147483647;test_~tmp___1~0#1 := test_#t~nondet37#1;havoc test_#t~nondet37#1; {2513#(= ~pumpRunning~0 0)} is VALID [2022-02-20 18:07:33,238 INFO L290 TraceCheckUtils]: 20: Hoare triple {2513#(= ~pumpRunning~0 0)} assume 0 != test_~tmp___1~0#1; {2513#(= ~pumpRunning~0 0)} is VALID [2022-02-20 18:07:33,239 INFO L272 TraceCheckUtils]: 21: Hoare triple {2513#(= ~pumpRunning~0 0)} call timeShift(); {2513#(= ~pumpRunning~0 0)} is VALID [2022-02-20 18:07:33,239 INFO L290 TraceCheckUtils]: 22: Hoare triple {2513#(= ~pumpRunning~0 0)} assume !(0 != ~pumpRunning~0); {2513#(= ~pumpRunning~0 0)} is VALID [2022-02-20 18:07:33,240 INFO L290 TraceCheckUtils]: 23: Hoare triple {2513#(= ~pumpRunning~0 0)} assume 0 != ~systemActive~0;assume { :begin_inline_processEnvironment } true;havoc processEnvironment_#t~ret39#1, processEnvironment_~tmp~6#1;havoc processEnvironment_~tmp~6#1; {2513#(= ~pumpRunning~0 0)} is VALID [2022-02-20 18:07:33,241 INFO L290 TraceCheckUtils]: 24: Hoare triple {2513#(= ~pumpRunning~0 0)} assume !(0 != ~pumpRunning~0); {2513#(= ~pumpRunning~0 0)} is VALID [2022-02-20 18:07:33,241 INFO L272 TraceCheckUtils]: 25: Hoare triple {2513#(= ~pumpRunning~0 0)} call processEnvironment__wrappee__methaneQuery(); {2530#(= ~pumpRunning~0 |old(~pumpRunning~0)|)} is VALID [2022-02-20 18:07:33,242 INFO L290 TraceCheckUtils]: 26: Hoare triple {2530#(= ~pumpRunning~0 |old(~pumpRunning~0)|)} havoc ~tmp~5#1; {2511#true} is VALID [2022-02-20 18:07:33,242 INFO L290 TraceCheckUtils]: 27: Hoare triple {2511#true} assume !(0 != ~pumpRunning~0); {2513#(= ~pumpRunning~0 0)} is VALID [2022-02-20 18:07:33,242 INFO L272 TraceCheckUtils]: 28: Hoare triple {2513#(= ~pumpRunning~0 0)} call processEnvironment__wrappee__base(); {2511#true} is VALID [2022-02-20 18:07:33,242 INFO L290 TraceCheckUtils]: 29: Hoare triple {2511#true} assume true; {2511#true} is VALID [2022-02-20 18:07:33,243 INFO L284 TraceCheckUtils]: 30: Hoare quadruple {2511#true} {2513#(= ~pumpRunning~0 0)} #252#return; {2513#(= ~pumpRunning~0 0)} is VALID [2022-02-20 18:07:33,243 INFO L290 TraceCheckUtils]: 31: Hoare triple {2513#(= ~pumpRunning~0 0)} assume true; {2513#(= ~pumpRunning~0 0)} is VALID [2022-02-20 18:07:33,243 INFO L284 TraceCheckUtils]: 32: Hoare quadruple {2513#(= ~pumpRunning~0 0)} {2513#(= ~pumpRunning~0 0)} #232#return; {2513#(= ~pumpRunning~0 0)} is VALID [2022-02-20 18:07:33,244 INFO L290 TraceCheckUtils]: 33: Hoare triple {2513#(= ~pumpRunning~0 0)} assume { :end_inline_processEnvironment } true; {2513#(= ~pumpRunning~0 0)} is VALID [2022-02-20 18:07:33,244 INFO L290 TraceCheckUtils]: 34: Hoare triple {2513#(= ~pumpRunning~0 0)} assume { :begin_inline___utac_acc__Specification2_spec__2 } true;havoc __utac_acc__Specification2_spec__2_#t~ret51#1, __utac_acc__Specification2_spec__2_#t~ret52#1, __utac_acc__Specification2_spec__2_~tmp~9#1, __utac_acc__Specification2_spec__2_~tmp___0~2#1;havoc __utac_acc__Specification2_spec__2_~tmp~9#1;havoc __utac_acc__Specification2_spec__2_~tmp___0~2#1; {2513#(= ~pumpRunning~0 0)} is VALID [2022-02-20 18:07:33,244 INFO L272 TraceCheckUtils]: 35: Hoare triple {2513#(= ~pumpRunning~0 0)} call __utac_acc__Specification2_spec__2_#t~ret51#1 := isMethaneLevelCritical(); {2511#true} is VALID [2022-02-20 18:07:33,245 INFO L290 TraceCheckUtils]: 36: Hoare triple {2511#true} havoc ~retValue_acc~6;~retValue_acc~6 := ~methaneLevelCritical~0;#res := ~retValue_acc~6; {2511#true} is VALID [2022-02-20 18:07:33,245 INFO L290 TraceCheckUtils]: 37: Hoare triple {2511#true} assume true; {2511#true} is VALID [2022-02-20 18:07:33,245 INFO L284 TraceCheckUtils]: 38: Hoare quadruple {2511#true} {2513#(= ~pumpRunning~0 0)} #234#return; {2513#(= ~pumpRunning~0 0)} is VALID [2022-02-20 18:07:33,246 INFO L290 TraceCheckUtils]: 39: Hoare triple {2513#(= ~pumpRunning~0 0)} assume -2147483648 <= __utac_acc__Specification2_spec__2_#t~ret51#1 && __utac_acc__Specification2_spec__2_#t~ret51#1 <= 2147483647;__utac_acc__Specification2_spec__2_~tmp~9#1 := __utac_acc__Specification2_spec__2_#t~ret51#1;havoc __utac_acc__Specification2_spec__2_#t~ret51#1; {2513#(= ~pumpRunning~0 0)} is VALID [2022-02-20 18:07:33,250 INFO L290 TraceCheckUtils]: 40: Hoare triple {2513#(= ~pumpRunning~0 0)} assume 0 != __utac_acc__Specification2_spec__2_~tmp~9#1;assume { :begin_inline_isPumpRunning } true;havoc isPumpRunning_#res#1;havoc isPumpRunning_~retValue_acc~10#1;havoc isPumpRunning_~retValue_acc~10#1;isPumpRunning_~retValue_acc~10#1 := ~pumpRunning~0;isPumpRunning_#res#1 := isPumpRunning_~retValue_acc~10#1; {2527#(= |timeShift_isPumpRunning_#res#1| 0)} is VALID [2022-02-20 18:07:33,250 INFO L290 TraceCheckUtils]: 41: Hoare triple {2527#(= |timeShift_isPumpRunning_#res#1| 0)} __utac_acc__Specification2_spec__2_#t~ret52#1 := isPumpRunning_#res#1;assume { :end_inline_isPumpRunning } true;assume -2147483648 <= __utac_acc__Specification2_spec__2_#t~ret52#1 && __utac_acc__Specification2_spec__2_#t~ret52#1 <= 2147483647;__utac_acc__Specification2_spec__2_~tmp___0~2#1 := __utac_acc__Specification2_spec__2_#t~ret52#1;havoc __utac_acc__Specification2_spec__2_#t~ret52#1; {2528#(= |timeShift___utac_acc__Specification2_spec__2_~tmp___0~2#1| 0)} is VALID [2022-02-20 18:07:33,251 INFO L290 TraceCheckUtils]: 42: Hoare triple {2528#(= |timeShift___utac_acc__Specification2_spec__2_~tmp___0~2#1| 0)} assume 0 != __utac_acc__Specification2_spec__2_~tmp___0~2#1; {2512#false} is VALID [2022-02-20 18:07:33,251 INFO L290 TraceCheckUtils]: 43: Hoare triple {2512#false} assume 0 != ~methAndRunningLastTime~0;assume { :begin_inline___automaton_fail } true; {2512#false} is VALID [2022-02-20 18:07:33,251 INFO L290 TraceCheckUtils]: 44: Hoare triple {2512#false} assume !false; {2512#false} is VALID [2022-02-20 18:07:33,259 INFO L134 CoverageAnalysis]: Checked inductivity of 0 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2022-02-20 18:07:33,259 INFO L144 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2022-02-20 18:07:33,260 INFO L338 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [7496910] [2022-02-20 18:07:33,260 INFO L165 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [7496910] provided 1 perfect and 0 imperfect interpolant sequences [2022-02-20 18:07:33,260 INFO L191 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2022-02-20 18:07:33,260 INFO L204 FreeRefinementEngine]: Number of different interpolants: perfect sequences [7] imperfect sequences [] total 7 [2022-02-20 18:07:33,260 INFO L118 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [39323955] [2022-02-20 18:07:33,262 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2022-02-20 18:07:33,262 INFO L78 Accepts]: Start accepts. Automaton has has 7 states, 7 states have (on average 5.142857142857143) internal successors, (36), 5 states have internal predecessors, (36), 1 states have call successors, (5), 4 states have call predecessors, (5), 2 states have return successors, (4), 1 states have call predecessors, (4), 1 states have call successors, (4) Word has length 45 [2022-02-20 18:07:33,262 INFO L84 Accepts]: Finished accepts. word is accepted. [2022-02-20 18:07:33,263 INFO L86 InductivityCheck]: Starting indutivity check of a Floyd-Hoare automaton with has 7 states, 7 states have (on average 5.142857142857143) internal successors, (36), 5 states have internal predecessors, (36), 1 states have call successors, (5), 4 states have call predecessors, (5), 2 states have return successors, (4), 1 states have call predecessors, (4), 1 states have call successors, (4) [2022-02-20 18:07:33,298 INFO L122 InductivityCheck]: Floyd-Hoare automaton has 45 edges. 45 inductive. 0 not inductive. 0 times theorem prover too weak to decide inductivity. [2022-02-20 18:07:33,298 INFO L546 AbstractCegarLoop]: INTERPOLANT automaton has 7 states [2022-02-20 18:07:33,298 INFO L108 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2022-02-20 18:07:33,298 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 7 interpolants. [2022-02-20 18:07:33,299 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=11, Invalid=31, Unknown=0, NotChecked=0, Total=42 [2022-02-20 18:07:33,299 INFO L87 Difference]: Start difference. First operand 139 states and 175 transitions. Second operand has 7 states, 7 states have (on average 5.142857142857143) internal successors, (36), 5 states have internal predecessors, (36), 1 states have call successors, (5), 4 states have call predecessors, (5), 2 states have return successors, (4), 1 states have call predecessors, (4), 1 states have call successors, (4) [2022-02-20 18:07:33,611 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-02-20 18:07:33,611 INFO L93 Difference]: Finished difference Result 226 states and 286 transitions. [2022-02-20 18:07:33,611 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 7 states. [2022-02-20 18:07:33,611 INFO L78 Accepts]: Start accepts. Automaton has has 7 states, 7 states have (on average 5.142857142857143) internal successors, (36), 5 states have internal predecessors, (36), 1 states have call successors, (5), 4 states have call predecessors, (5), 2 states have return successors, (4), 1 states have call predecessors, (4), 1 states have call successors, (4) Word has length 45 [2022-02-20 18:07:33,612 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2022-02-20 18:07:33,612 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 7 states, 7 states have (on average 5.142857142857143) internal successors, (36), 5 states have internal predecessors, (36), 1 states have call successors, (5), 4 states have call predecessors, (5), 2 states have return successors, (4), 1 states have call predecessors, (4), 1 states have call successors, (4) [2022-02-20 18:07:33,614 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 7 states to 7 states and 154 transitions. [2022-02-20 18:07:33,614 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 7 states, 7 states have (on average 5.142857142857143) internal successors, (36), 5 states have internal predecessors, (36), 1 states have call successors, (5), 4 states have call predecessors, (5), 2 states have return successors, (4), 1 states have call predecessors, (4), 1 states have call successors, (4) [2022-02-20 18:07:33,617 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 7 states to 7 states and 154 transitions. [2022-02-20 18:07:33,617 INFO L86 InductivityCheck]: Starting indutivity check of a Floyd-Hoare automaton with 7 states and 154 transitions. [2022-02-20 18:07:33,741 INFO L122 InductivityCheck]: Floyd-Hoare automaton has 154 edges. 154 inductive. 0 not inductive. 0 times theorem prover too weak to decide inductivity. [2022-02-20 18:07:33,742 INFO L225 Difference]: With dead ends: 226 [2022-02-20 18:07:33,742 INFO L226 Difference]: Without dead ends: 0 [2022-02-20 18:07:33,743 INFO L932 BasicCegarLoop]: 0 DeclaredPredicates, 21 GetRequests, 12 SyntacticMatches, 0 SemanticMatches, 9 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 3 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=39, Invalid=71, Unknown=0, NotChecked=0, Total=110 [2022-02-20 18:07:33,748 INFO L933 BasicCegarLoop]: 45 mSDtfsCounter, 71 mSDsluCounter, 92 mSDsCounter, 0 mSdLazyCounter, 92 mSolverCounterSat, 27 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.1s Time, 0 mProtectedPredicate, 0 mProtectedAction, 72 SdHoareTripleChecker+Valid, 137 SdHoareTripleChecker+Invalid, 119 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 27 IncrementalHoareTripleChecker+Valid, 92 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.1s IncrementalHoareTripleChecker+Time [2022-02-20 18:07:33,751 INFO L934 BasicCegarLoop]: SdHoareTripleChecker [72 Valid, 137 Invalid, 119 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [27 Valid, 92 Invalid, 0 Unknown, 0 Unchecked, 0.1s Time] [2022-02-20 18:07:33,751 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 0 states. [2022-02-20 18:07:33,752 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 0 to 0. [2022-02-20 18:07:33,752 INFO L214 AbstractMinimizeNwa]: Start testing correctness of minimizeSevpa [2022-02-20 18:07:33,752 INFO L82 GeneralOperation]: Start isEquivalent. First operand 0 states. Second operand has 0 states, 0 states have (on average 0.0) internal successors, (0), 0 states have internal predecessors, (0), 0 states have call successors, (0), 0 states have call predecessors, (0), 0 states have return successors, (0), 0 states have call predecessors, (0), 0 states have call successors, (0) [2022-02-20 18:07:33,752 INFO L74 IsIncluded]: Start isIncluded. First operand 0 states. Second operand has 0 states, 0 states have (on average 0.0) internal successors, (0), 0 states have internal predecessors, (0), 0 states have call successors, (0), 0 states have call predecessors, (0), 0 states have return successors, (0), 0 states have call predecessors, (0), 0 states have call successors, (0) [2022-02-20 18:07:33,752 INFO L87 Difference]: Start difference. First operand 0 states. Second operand has 0 states, 0 states have (on average 0.0) internal successors, (0), 0 states have internal predecessors, (0), 0 states have call successors, (0), 0 states have call predecessors, (0), 0 states have return successors, (0), 0 states have call predecessors, (0), 0 states have call successors, (0) [2022-02-20 18:07:33,753 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-02-20 18:07:33,753 INFO L93 Difference]: Finished difference Result 0 states and 0 transitions. [2022-02-20 18:07:33,753 INFO L276 IsEmpty]: Start isEmpty. Operand 0 states and 0 transitions. [2022-02-20 18:07:33,753 INFO L282 IsEmpty]: Finished isEmpty. No accepting run. [2022-02-20 18:07:33,753 INFO L83 IsIncluded]: Finished isIncluded. Language is included [2022-02-20 18:07:33,753 INFO L74 IsIncluded]: Start isIncluded. First operand has 0 states, 0 states have (on average 0.0) internal successors, (0), 0 states have internal predecessors, (0), 0 states have call successors, (0), 0 states have call predecessors, (0), 0 states have return successors, (0), 0 states have call predecessors, (0), 0 states have call successors, (0) Second operand 0 states. [2022-02-20 18:07:33,753 INFO L87 Difference]: Start difference. First operand has 0 states, 0 states have (on average 0.0) internal successors, (0), 0 states have internal predecessors, (0), 0 states have call successors, (0), 0 states have call predecessors, (0), 0 states have return successors, (0), 0 states have call predecessors, (0), 0 states have call successors, (0) Second operand 0 states. [2022-02-20 18:07:33,754 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-02-20 18:07:33,754 INFO L93 Difference]: Finished difference Result 0 states and 0 transitions. [2022-02-20 18:07:33,754 INFO L276 IsEmpty]: Start isEmpty. Operand 0 states and 0 transitions. [2022-02-20 18:07:33,754 INFO L282 IsEmpty]: Finished isEmpty. No accepting run. [2022-02-20 18:07:33,754 INFO L83 IsIncluded]: Finished isIncluded. Language is included [2022-02-20 18:07:33,754 INFO L88 GeneralOperation]: Finished isEquivalent. [2022-02-20 18:07:33,754 INFO L221 AbstractMinimizeNwa]: Finished testing correctness of minimizeSevpa [2022-02-20 18:07:33,754 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 0 states, 0 states have (on average 0.0) internal successors, (0), 0 states have internal predecessors, (0), 0 states have call successors, (0), 0 states have call predecessors, (0), 0 states have return successors, (0), 0 states have call predecessors, (0), 0 states have call successors, (0) [2022-02-20 18:07:33,755 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 0 states to 0 states and 0 transitions. [2022-02-20 18:07:33,755 INFO L78 Accepts]: Start accepts. Automaton has 0 states and 0 transitions. Word has length 45 [2022-02-20 18:07:33,755 INFO L84 Accepts]: Finished accepts. word is rejected. [2022-02-20 18:07:33,755 INFO L470 AbstractCegarLoop]: Abstraction has 0 states and 0 transitions. [2022-02-20 18:07:33,755 INFO L471 AbstractCegarLoop]: INTERPOLANT automaton has has 7 states, 7 states have (on average 5.142857142857143) internal successors, (36), 5 states have internal predecessors, (36), 1 states have call successors, (5), 4 states have call predecessors, (5), 2 states have return successors, (4), 1 states have call predecessors, (4), 1 states have call successors, (4) [2022-02-20 18:07:33,755 INFO L276 IsEmpty]: Start isEmpty. Operand 0 states and 0 transitions. [2022-02-20 18:07:33,756 INFO L282 IsEmpty]: Finished isEmpty. No accepting run. [2022-02-20 18:07:33,758 INFO L764 garLoopResultBuilder]: Registering result SAFE for location timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION (0 of 1 remaining) [2022-02-20 18:07:33,759 WARN L452 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable4 [2022-02-20 18:07:33,760 INFO L343 DoubleDeckerVisitor]: Before removal of dead ends 0 states and 0 transitions. [2022-02-20 18:07:34,258 INFO L861 garLoopResultBuilder]: At program point deactivatePumpENTRY(lines 834 841) the Hoare annotation is: true [2022-02-20 18:07:34,259 INFO L858 garLoopResultBuilder]: For program point deactivatePumpEXIT(lines 834 841) no Hoare annotation was computed. [2022-02-20 18:07:34,259 INFO L858 garLoopResultBuilder]: For program point deactivatePumpFINAL(lines 834 841) no Hoare annotation was computed. [2022-02-20 18:07:34,259 INFO L858 garLoopResultBuilder]: For program point processEnvironment__wrappee__baseEXIT(lines 750 756) no Hoare annotation was computed. [2022-02-20 18:07:34,259 INFO L861 garLoopResultBuilder]: At program point processEnvironment__wrappee__baseFINAL(lines 750 756) the Hoare annotation is: true [2022-02-20 18:07:34,259 INFO L858 garLoopResultBuilder]: For program point L592-1(lines 588 599) no Hoare annotation was computed. [2022-02-20 18:07:34,259 INFO L854 garLoopResultBuilder]: At program point changeMethaneLevelENTRY(lines 588 599) the Hoare annotation is: (or (not (= ~pumpRunning~0 0)) (not (= 1 ~systemActive~0)) (= |old(~methaneLevelCritical~0)| ~methaneLevelCritical~0)) [2022-02-20 18:07:34,259 INFO L858 garLoopResultBuilder]: For program point changeMethaneLevelEXIT(lines 588 599) no Hoare annotation was computed. [2022-02-20 18:07:34,259 INFO L861 garLoopResultBuilder]: At program point isMethaneLevelCriticalENTRY(lines 600 608) the Hoare annotation is: true [2022-02-20 18:07:34,260 INFO L858 garLoopResultBuilder]: For program point isMethaneLevelCriticalFINAL(lines 600 608) no Hoare annotation was computed. [2022-02-20 18:07:34,260 INFO L858 garLoopResultBuilder]: For program point isMethaneLevelCriticalEXIT(lines 600 608) no Hoare annotation was computed. [2022-02-20 18:07:34,260 INFO L858 garLoopResultBuilder]: For program point L737-1(lines 737 743) no Hoare annotation was computed. [2022-02-20 18:07:34,260 INFO L858 garLoopResultBuilder]: For program point L956(lines 956 966) no Hoare annotation was computed. [2022-02-20 18:07:34,260 INFO L858 garLoopResultBuilder]: For program point L568(lines 568 572) no Hoare annotation was computed. [2022-02-20 18:07:34,260 INFO L858 garLoopResultBuilder]: For program point L952(lines 952 969) no Hoare annotation was computed. [2022-02-20 18:07:34,260 INFO L854 garLoopResultBuilder]: At program point L952-1(lines 944 972) the Hoare annotation is: (let ((.cse0 (not (= |old(~pumpRunning~0)| 0))) (.cse1 (not (= 1 ~systemActive~0)))) (and (or .cse0 .cse1 (not (= ~methaneLevelCritical~0 0)) (= |timeShift___utac_acc__Specification2_spec__2_~tmp~9#1| 0)) (or .cse0 (= ~pumpRunning~0 0) .cse1))) [2022-02-20 18:07:34,260 INFO L854 garLoopResultBuilder]: At program point L568-2(lines 564 575) the Hoare annotation is: (or (not (= |old(~pumpRunning~0)| 0)) (not (= 1 ~systemActive~0))) [2022-02-20 18:07:34,260 INFO L858 garLoopResultBuilder]: For program point timeShiftFINAL(lines 726 749) no Hoare annotation was computed. [2022-02-20 18:07:34,260 INFO L858 garLoopResultBuilder]: For program point L957(lines 957 963) no Hoare annotation was computed. [2022-02-20 18:07:34,261 INFO L854 garLoopResultBuilder]: At program point L858(lines 853 861) the Hoare annotation is: (let ((.cse0 (not (= |old(~pumpRunning~0)| 0))) (.cse1 (not (= 1 ~systemActive~0)))) (and (or .cse0 .cse1 (and (= ~pumpRunning~0 0) (= |timeShift_isPumpRunning_#res#1| 0))) (or .cse0 .cse1 (not (= ~methaneLevelCritical~0 0))))) [2022-02-20 18:07:34,261 INFO L858 garLoopResultBuilder]: For program point L730-1(lines 729 748) no Hoare annotation was computed. [2022-02-20 18:07:34,261 INFO L858 garLoopResultBuilder]: For program point L792(lines 792 800) no Hoare annotation was computed. [2022-02-20 18:07:34,261 INFO L858 garLoopResultBuilder]: For program point L788(lines 788 805) no Hoare annotation was computed. [2022-02-20 18:07:34,261 INFO L854 garLoopResultBuilder]: At program point L950(line 950) the Hoare annotation is: (or (not (= |old(~pumpRunning~0)| 0)) (= ~pumpRunning~0 0) (not (= 1 ~systemActive~0))) [2022-02-20 18:07:34,261 INFO L858 garLoopResultBuilder]: For program point L950-1(line 950) no Hoare annotation was computed. [2022-02-20 18:07:34,261 INFO L858 garLoopResultBuilder]: For program point L930(line 930) no Hoare annotation was computed. [2022-02-20 18:07:34,261 INFO L854 garLoopResultBuilder]: At program point L798(line 798) the Hoare annotation is: (or (not (= |old(~pumpRunning~0)| 0)) (not (= 1 ~systemActive~0))) [2022-02-20 18:07:34,261 INFO L854 garLoopResultBuilder]: At program point L794(line 794) the Hoare annotation is: (or (not (= |old(~pumpRunning~0)| 0)) (not (= 1 ~systemActive~0))) [2022-02-20 18:07:34,261 INFO L854 garLoopResultBuilder]: At program point L790(line 790) the Hoare annotation is: (or (not (= |old(~pumpRunning~0)| 0)) (not (= 1 ~systemActive~0))) [2022-02-20 18:07:34,262 INFO L858 garLoopResultBuilder]: For program point L790-1(line 790) no Hoare annotation was computed. [2022-02-20 18:07:34,262 INFO L854 garLoopResultBuilder]: At program point timeShiftENTRY(lines 726 749) the Hoare annotation is: (or (not (= |old(~pumpRunning~0)| 0)) (= ~pumpRunning~0 0) (not (= 1 ~systemActive~0))) [2022-02-20 18:07:34,262 INFO L858 garLoopResultBuilder]: For program point timeShiftEXIT(lines 726 749) no Hoare annotation was computed. [2022-02-20 18:07:34,262 INFO L858 garLoopResultBuilder]: For program point timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION(line 930) no Hoare annotation was computed. [2022-02-20 18:07:34,262 INFO L854 garLoopResultBuilder]: At program point L803(line 803) the Hoare annotation is: (or (not (= |old(~pumpRunning~0)| 0)) (= ~pumpRunning~0 0) (not (= 1 ~systemActive~0))) [2022-02-20 18:07:34,262 INFO L854 garLoopResultBuilder]: At program point L931(lines 926 933) the Hoare annotation is: (or (not (= |old(~pumpRunning~0)| 0)) (not (= 1 ~systemActive~0))) [2022-02-20 18:07:34,262 INFO L854 garLoopResultBuilder]: At program point L803-1(lines 784 808) the Hoare annotation is: (or (not (= |old(~pumpRunning~0)| 0)) (= ~pumpRunning~0 0) (not (= 1 ~systemActive~0))) [2022-02-20 18:07:34,262 INFO L861 garLoopResultBuilder]: At program point L481(lines 456 485) the Hoare annotation is: true [2022-02-20 18:07:34,262 INFO L858 garLoopResultBuilder]: For program point cleanupEXIT(lines 456 485) no Hoare annotation was computed. [2022-02-20 18:07:34,262 INFO L858 garLoopResultBuilder]: For program point L477(line 477) no Hoare annotation was computed. [2022-02-20 18:07:34,263 INFO L861 garLoopResultBuilder]: At program point cleanupENTRY(lines 456 485) the Hoare annotation is: true [2022-02-20 18:07:34,263 INFO L858 garLoopResultBuilder]: For program point L470(lines 470 474) no Hoare annotation was computed. [2022-02-20 18:07:34,263 INFO L861 garLoopResultBuilder]: At program point L470-1(lines 470 474) the Hoare annotation is: true [2022-02-20 18:07:34,263 INFO L858 garLoopResultBuilder]: For program point L467(line 467) no Hoare annotation was computed. [2022-02-20 18:07:34,263 INFO L861 garLoopResultBuilder]: At program point L466-2(lines 466 480) the Hoare annotation is: true [2022-02-20 18:07:34,263 INFO L861 garLoopResultBuilder]: At program point L462(line 462) the Hoare annotation is: true [2022-02-20 18:07:34,263 INFO L858 garLoopResultBuilder]: For program point L462-1(line 462) no Hoare annotation was computed. [2022-02-20 18:07:34,263 INFO L858 garLoopResultBuilder]: For program point L543(lines 543 550) no Hoare annotation was computed. [2022-02-20 18:07:34,263 INFO L858 garLoopResultBuilder]: For program point L543-2(lines 543 550) no Hoare annotation was computed. [2022-02-20 18:07:34,263 INFO L858 garLoopResultBuilder]: For program point L700(lines 700 704) no Hoare annotation was computed. [2022-02-20 18:07:34,264 INFO L854 garLoopResultBuilder]: At program point L700-2(lines 692 705) the Hoare annotation is: (and (= ~pumpRunning~0 0) (= |ULTIMATE.start_main_~tmp~3#1| ~systemActive~0) (= 1 ~systemActive~0) (= |ULTIMATE.start_valid_product_#res#1| ~systemActive~0) (= |ULTIMATE.start_test_~splverifierCounter~0#1| 0)) [2022-02-20 18:07:34,264 INFO L858 garLoopResultBuilder]: For program point L663(lines 662 709) no Hoare annotation was computed. [2022-02-20 18:07:34,264 INFO L858 garLoopResultBuilder]: For program point L692(lines 692 705) no Hoare annotation was computed. [2022-02-20 18:07:34,264 INFO L854 garLoopResultBuilder]: At program point L684(line 684) the Hoare annotation is: (and (= ~pumpRunning~0 0) (= |ULTIMATE.start_main_~tmp~3#1| ~systemActive~0) (= 1 ~systemActive~0) (= |ULTIMATE.start_valid_product_#res#1| ~systemActive~0) (= |ULTIMATE.start_test_~splverifierCounter~0#1| 0)) [2022-02-20 18:07:34,264 INFO L861 garLoopResultBuilder]: At program point L713(lines 652 717) the Hoare annotation is: true [2022-02-20 18:07:34,264 INFO L861 garLoopResultBuilder]: At program point L552(lines 533 555) the Hoare annotation is: true [2022-02-20 18:07:34,264 INFO L854 garLoopResultBuilder]: At program point L449(lines 444 452) the Hoare annotation is: (and (= ~pumpRunning~0 0) (= ~methaneLevelCritical~0 0) (= 1 ~systemActive~0) (= |ULTIMATE.start_valid_product_#res#1| ~systemActive~0)) [2022-02-20 18:07:34,264 INFO L858 garLoopResultBuilder]: For program point L672(lines 672 678) no Hoare annotation was computed. [2022-02-20 18:07:34,264 INFO L858 garLoopResultBuilder]: For program point L-1(line -1) no Hoare annotation was computed. [2022-02-20 18:07:34,264 INFO L858 garLoopResultBuilder]: For program point L672-1(lines 672 678) no Hoare annotation was computed. [2022-02-20 18:07:34,264 INFO L858 garLoopResultBuilder]: For program point ULTIMATE.startENTRY(line -1) no Hoare annotation was computed. [2022-02-20 18:07:34,264 INFO L858 garLoopResultBuilder]: For program point ULTIMATE.startFINAL(line -1) no Hoare annotation was computed. [2022-02-20 18:07:34,265 INFO L854 garLoopResultBuilder]: At program point L441(lines 437 443) the Hoare annotation is: (and (= ~pumpRunning~0 0) (= ~methaneLevelCritical~0 0) (= 1 ~systemActive~0)) [2022-02-20 18:07:34,265 INFO L858 garLoopResultBuilder]: For program point L664(lines 664 668) no Hoare annotation was computed. [2022-02-20 18:07:34,265 INFO L854 garLoopResultBuilder]: At program point L941(lines 936 943) the Hoare annotation is: (and (= ~pumpRunning~0 0) (= |ULTIMATE.start_main_~tmp~3#1| ~systemActive~0) (= ~methaneLevelCritical~0 0) (= 1 ~systemActive~0) (= |ULTIMATE.start_valid_product_#res#1| ~systemActive~0)) [2022-02-20 18:07:34,265 INFO L854 garLoopResultBuilder]: At program point L710(lines 661 711) the Hoare annotation is: false [2022-02-20 18:07:34,265 INFO L858 garLoopResultBuilder]: For program point ULTIMATE.startEXIT(line -1) no Hoare annotation was computed. [2022-02-20 18:07:34,265 INFO L854 garLoopResultBuilder]: At program point L434(lines 430 436) the Hoare annotation is: (and (= ~pumpRunning~0 0) (= ~methaneLevelCritical~0 0) (= 1 ~systemActive~0)) [2022-02-20 18:07:34,265 INFO L858 garLoopResultBuilder]: For program point L682(lines 682 688) no Hoare annotation was computed. [2022-02-20 18:07:34,265 INFO L858 garLoopResultBuilder]: For program point L682-1(lines 682 688) no Hoare annotation was computed. [2022-02-20 18:07:34,265 INFO L854 garLoopResultBuilder]: At program point L517(lines 513 519) the Hoare annotation is: (and (= ~pumpRunning~0 0) (= |ULTIMATE.start_main_~tmp~3#1| ~systemActive~0) (= ~methaneLevelCritical~0 0) (= 1 ~systemActive~0) (= |ULTIMATE.start_valid_product_#res#1| ~systemActive~0)) [2022-02-20 18:07:34,265 INFO L854 garLoopResultBuilder]: At program point L707(lines 662 709) the Hoare annotation is: (and (= ~pumpRunning~0 0) (= |ULTIMATE.start_main_~tmp~3#1| ~systemActive~0) (= 1 ~systemActive~0) (= |ULTIMATE.start_valid_product_#res#1| ~systemActive~0) (= |ULTIMATE.start_test_~splverifierCounter~0#1| 0)) [2022-02-20 18:07:34,266 INFO L854 garLoopResultBuilder]: At program point L674(line 674) the Hoare annotation is: (and (= ~pumpRunning~0 0) (= |ULTIMATE.start_main_~tmp~3#1| ~systemActive~0) (= 1 ~systemActive~0) (= |ULTIMATE.start_valid_product_#res#1| ~systemActive~0) (= |ULTIMATE.start_test_~splverifierCounter~0#1| 0)) [2022-02-20 18:07:34,266 INFO L854 garLoopResultBuilder]: At program point L922(lines 917 924) the Hoare annotation is: (and (= ~pumpRunning~0 0) (= |ULTIMATE.start_main_~tmp~3#1| ~systemActive~0) (= 1 ~systemActive~0) (= |ULTIMATE.start_valid_product_#res#1| ~systemActive~0) (= |ULTIMATE.start_test_~splverifierCounter~0#1| 0)) [2022-02-20 18:07:34,266 INFO L861 garLoopResultBuilder]: At program point L530(lines 522 532) the Hoare annotation is: true [2022-02-20 18:07:34,266 INFO L858 garLoopResultBuilder]: For program point waterRiseEXIT(lines 576 587) no Hoare annotation was computed. [2022-02-20 18:07:34,266 INFO L861 garLoopResultBuilder]: At program point waterRiseENTRY(lines 576 587) the Hoare annotation is: true [2022-02-20 18:07:34,266 INFO L858 garLoopResultBuilder]: For program point L580-1(lines 576 587) no Hoare annotation was computed. [2022-02-20 18:07:34,266 INFO L854 garLoopResultBuilder]: At program point L768(line 768) the Hoare annotation is: (or (not (= |old(~pumpRunning~0)| 0)) (not (= 1 ~systemActive~0))) [2022-02-20 18:07:34,266 INFO L858 garLoopResultBuilder]: For program point L766(lines 766 774) no Hoare annotation was computed. [2022-02-20 18:07:34,266 INFO L858 garLoopResultBuilder]: For program point L762(lines 762 779) no Hoare annotation was computed. [2022-02-20 18:07:34,266 INFO L854 garLoopResultBuilder]: At program point L913(lines 898 916) the Hoare annotation is: (or (not (= |old(~pumpRunning~0)| 0)) (not (= 1 ~systemActive~0))) [2022-02-20 18:07:34,267 INFO L858 garLoopResultBuilder]: For program point L907(lines 907 911) no Hoare annotation was computed. [2022-02-20 18:07:34,267 INFO L858 garLoopResultBuilder]: For program point L907-2(lines 907 911) no Hoare annotation was computed. [2022-02-20 18:07:34,267 INFO L854 garLoopResultBuilder]: At program point L777(line 777) the Hoare annotation is: (or (not (= |old(~pumpRunning~0)| 0)) (= ~pumpRunning~0 0) (not (= 1 ~systemActive~0))) [2022-02-20 18:07:34,267 INFO L858 garLoopResultBuilder]: For program point L777-1(lines 758 782) no Hoare annotation was computed. [2022-02-20 18:07:34,267 INFO L854 garLoopResultBuilder]: At program point processEnvironment__wrappee__methaneQueryENTRY(lines 758 782) the Hoare annotation is: (or (not (= |old(~pumpRunning~0)| 0)) (= ~pumpRunning~0 0) (not (= 1 ~systemActive~0))) [2022-02-20 18:07:34,267 INFO L858 garLoopResultBuilder]: For program point processEnvironment__wrappee__methaneQueryEXIT(lines 758 782) no Hoare annotation was computed. [2022-02-20 18:07:34,267 INFO L854 garLoopResultBuilder]: At program point L646(lines 641 649) the Hoare annotation is: (or (not (= |old(~pumpRunning~0)| 0)) (not (= 1 ~systemActive~0))) [2022-02-20 18:07:34,267 INFO L854 garLoopResultBuilder]: At program point L772(line 772) the Hoare annotation is: (or (not (= |old(~pumpRunning~0)| 0)) (not (= 1 ~systemActive~0))) [2022-02-20 18:07:34,267 INFO L861 garLoopResultBuilder]: At program point isMethaneAlarmENTRY(lines 842 852) the Hoare annotation is: true [2022-02-20 18:07:34,267 INFO L861 garLoopResultBuilder]: At program point L847(line 847) the Hoare annotation is: true [2022-02-20 18:07:34,267 INFO L858 garLoopResultBuilder]: For program point L847-1(line 847) no Hoare annotation was computed. [2022-02-20 18:07:34,267 INFO L858 garLoopResultBuilder]: For program point isMethaneAlarmEXIT(lines 842 852) no Hoare annotation was computed. [2022-02-20 18:07:34,267 INFO L858 garLoopResultBuilder]: For program point isMethaneAlarmFINAL(lines 842 852) no Hoare annotation was computed. [2022-02-20 18:07:34,270 INFO L732 BasicCegarLoop]: Path program histogram: [1, 1, 1, 1, 1] [2022-02-20 18:07:34,271 INFO L180 ceAbstractionStarter]: Computing trace abstraction results [2022-02-20 18:07:34,274 WARN L170 areAnnotationChecker]: deactivatePumpFINAL has no Hoare annotation [2022-02-20 18:07:34,274 WARN L170 areAnnotationChecker]: processEnvironment__wrappee__baseEXIT has no Hoare annotation [2022-02-20 18:07:34,274 WARN L170 areAnnotationChecker]: L592-1 has no Hoare annotation [2022-02-20 18:07:34,274 WARN L170 areAnnotationChecker]: L592-1 has no Hoare annotation [2022-02-20 18:07:34,274 WARN L170 areAnnotationChecker]: isMethaneLevelCriticalFINAL has no Hoare annotation [2022-02-20 18:07:34,274 WARN L170 areAnnotationChecker]: L568 has no Hoare annotation [2022-02-20 18:07:34,274 WARN L170 areAnnotationChecker]: L730-1 has no Hoare annotation [2022-02-20 18:07:34,274 WARN L170 areAnnotationChecker]: ULTIMATE.startENTRY has no Hoare annotation [2022-02-20 18:07:34,274 WARN L170 areAnnotationChecker]: L580-1 has no Hoare annotation [2022-02-20 18:07:34,274 WARN L170 areAnnotationChecker]: L580-1 has no Hoare annotation [2022-02-20 18:07:34,275 WARN L170 areAnnotationChecker]: L762 has no Hoare annotation [2022-02-20 18:07:34,275 WARN L170 areAnnotationChecker]: deactivatePumpFINAL has no Hoare annotation [2022-02-20 18:07:34,275 WARN L170 areAnnotationChecker]: processEnvironment__wrappee__baseEXIT has no Hoare annotation [2022-02-20 18:07:34,275 WARN L170 areAnnotationChecker]: processEnvironment__wrappee__baseEXIT has no Hoare annotation [2022-02-20 18:07:34,275 WARN L170 areAnnotationChecker]: L592-1 has no Hoare annotation [2022-02-20 18:07:34,275 WARN L170 areAnnotationChecker]: isMethaneLevelCriticalFINAL has no Hoare annotation [2022-02-20 18:07:34,275 WARN L170 areAnnotationChecker]: L568 has no Hoare annotation [2022-02-20 18:07:34,275 WARN L170 areAnnotationChecker]: L568 has no Hoare annotation [2022-02-20 18:07:34,275 WARN L170 areAnnotationChecker]: L730-1 has no Hoare annotation [2022-02-20 18:07:34,275 WARN L170 areAnnotationChecker]: L730-1 has no Hoare annotation [2022-02-20 18:07:34,275 WARN L170 areAnnotationChecker]: L462-1 has no Hoare annotation [2022-02-20 18:07:34,276 WARN L170 areAnnotationChecker]: L-1 has no Hoare annotation [2022-02-20 18:07:34,276 WARN L170 areAnnotationChecker]: L580-1 has no Hoare annotation [2022-02-20 18:07:34,276 WARN L170 areAnnotationChecker]: L762 has no Hoare annotation [2022-02-20 18:07:34,276 WARN L170 areAnnotationChecker]: L762 has no Hoare annotation [2022-02-20 18:07:34,276 WARN L170 areAnnotationChecker]: L847-1 has no Hoare annotation [2022-02-20 18:07:34,276 WARN L170 areAnnotationChecker]: deactivatePumpEXIT has no Hoare annotation [2022-02-20 18:07:34,276 WARN L170 areAnnotationChecker]: deactivatePumpEXIT has no Hoare annotation [2022-02-20 18:07:34,276 WARN L170 areAnnotationChecker]: L777-1 has no Hoare annotation [2022-02-20 18:07:34,276 WARN L170 areAnnotationChecker]: changeMethaneLevelEXIT has no Hoare annotation [2022-02-20 18:07:34,277 WARN L170 areAnnotationChecker]: isMethaneLevelCriticalEXIT has no Hoare annotation [2022-02-20 18:07:34,277 WARN L170 areAnnotationChecker]: isMethaneLevelCriticalEXIT has no Hoare annotation [2022-02-20 18:07:34,277 WARN L170 areAnnotationChecker]: L730-1 has no Hoare annotation [2022-02-20 18:07:34,277 WARN L170 areAnnotationChecker]: L788 has no Hoare annotation [2022-02-20 18:07:34,277 WARN L170 areAnnotationChecker]: L788 has no Hoare annotation [2022-02-20 18:07:34,277 WARN L170 areAnnotationChecker]: L737-1 has no Hoare annotation [2022-02-20 18:07:34,277 WARN L170 areAnnotationChecker]: L462-1 has no Hoare annotation [2022-02-20 18:07:34,277 WARN L170 areAnnotationChecker]: waterRiseEXIT has no Hoare annotation [2022-02-20 18:07:34,277 WARN L170 areAnnotationChecker]: L907 has no Hoare annotation [2022-02-20 18:07:34,278 WARN L170 areAnnotationChecker]: L777-1 has no Hoare annotation [2022-02-20 18:07:34,278 WARN L170 areAnnotationChecker]: L847-1 has no Hoare annotation [2022-02-20 18:07:34,278 WARN L170 areAnnotationChecker]: L737-1 has no Hoare annotation [2022-02-20 18:07:34,278 WARN L170 areAnnotationChecker]: processEnvironment__wrappee__methaneQueryEXIT has no Hoare annotation [2022-02-20 18:07:34,278 WARN L170 areAnnotationChecker]: processEnvironment__wrappee__methaneQueryEXIT has no Hoare annotation [2022-02-20 18:07:34,278 WARN L170 areAnnotationChecker]: L682-1 has no Hoare annotation [2022-02-20 18:07:34,278 WARN L170 areAnnotationChecker]: L950-1 has no Hoare annotation [2022-02-20 18:07:34,278 WARN L170 areAnnotationChecker]: L790-1 has no Hoare annotation [2022-02-20 18:07:34,279 WARN L170 areAnnotationChecker]: L950-1 has no Hoare annotation [2022-02-20 18:07:34,279 WARN L170 areAnnotationChecker]: L467 has no Hoare annotation [2022-02-20 18:07:34,279 WARN L170 areAnnotationChecker]: L672-1 has no Hoare annotation [2022-02-20 18:07:34,279 WARN L170 areAnnotationChecker]: L907 has no Hoare annotation [2022-02-20 18:07:34,279 WARN L170 areAnnotationChecker]: L907 has no Hoare annotation [2022-02-20 18:07:34,279 WARN L170 areAnnotationChecker]: isMethaneAlarmFINAL has no Hoare annotation [2022-02-20 18:07:34,279 WARN L170 areAnnotationChecker]: L692 has no Hoare annotation [2022-02-20 18:07:34,279 WARN L170 areAnnotationChecker]: L692 has no Hoare annotation [2022-02-20 18:07:34,279 WARN L170 areAnnotationChecker]: L952 has no Hoare annotation [2022-02-20 18:07:34,280 WARN L170 areAnnotationChecker]: L952 has no Hoare annotation [2022-02-20 18:07:34,280 WARN L170 areAnnotationChecker]: L790-1 has no Hoare annotation [2022-02-20 18:07:34,280 WARN L170 areAnnotationChecker]: cleanupEXIT has no Hoare annotation [2022-02-20 18:07:34,280 WARN L170 areAnnotationChecker]: L467 has no Hoare annotation [2022-02-20 18:07:34,280 WARN L170 areAnnotationChecker]: L543 has no Hoare annotation [2022-02-20 18:07:34,280 WARN L170 areAnnotationChecker]: L682 has no Hoare annotation [2022-02-20 18:07:34,280 WARN L170 areAnnotationChecker]: L682 has no Hoare annotation [2022-02-20 18:07:34,280 WARN L170 areAnnotationChecker]: L907-2 has no Hoare annotation [2022-02-20 18:07:34,280 WARN L170 areAnnotationChecker]: isMethaneAlarmEXIT has no Hoare annotation [2022-02-20 18:07:34,280 WARN L170 areAnnotationChecker]: L700 has no Hoare annotation [2022-02-20 18:07:34,280 WARN L170 areAnnotationChecker]: L700 has no Hoare annotation [2022-02-20 18:07:34,280 WARN L170 areAnnotationChecker]: L956 has no Hoare annotation [2022-02-20 18:07:34,281 WARN L170 areAnnotationChecker]: timeShiftFINAL has no Hoare annotation [2022-02-20 18:07:34,281 WARN L170 areAnnotationChecker]: L792 has no Hoare annotation [2022-02-20 18:07:34,281 WARN L170 areAnnotationChecker]: L792 has no Hoare annotation [2022-02-20 18:07:34,281 WARN L170 areAnnotationChecker]: cleanupEXIT has no Hoare annotation [2022-02-20 18:07:34,281 WARN L170 areAnnotationChecker]: L470 has no Hoare annotation [2022-02-20 18:07:34,281 WARN L170 areAnnotationChecker]: L470 has no Hoare annotation [2022-02-20 18:07:34,281 WARN L170 areAnnotationChecker]: L543 has no Hoare annotation [2022-02-20 18:07:34,281 WARN L170 areAnnotationChecker]: L543 has no Hoare annotation [2022-02-20 18:07:34,281 WARN L170 areAnnotationChecker]: L682-1 has no Hoare annotation [2022-02-20 18:07:34,282 WARN L170 areAnnotationChecker]: L766 has no Hoare annotation [2022-02-20 18:07:34,282 WARN L170 areAnnotationChecker]: L956 has no Hoare annotation [2022-02-20 18:07:34,282 WARN L170 areAnnotationChecker]: L956 has no Hoare annotation [2022-02-20 18:07:34,282 WARN L170 areAnnotationChecker]: timeShiftFINAL has no Hoare annotation [2022-02-20 18:07:34,283 WARN L170 areAnnotationChecker]: L477 has no Hoare annotation [2022-02-20 18:07:34,284 WARN L170 areAnnotationChecker]: L543-2 has no Hoare annotation [2022-02-20 18:07:34,284 WARN L170 areAnnotationChecker]: L766 has no Hoare annotation [2022-02-20 18:07:34,284 WARN L170 areAnnotationChecker]: L766 has no Hoare annotation [2022-02-20 18:07:34,284 WARN L170 areAnnotationChecker]: L663 has no Hoare annotation [2022-02-20 18:07:34,285 WARN L170 areAnnotationChecker]: L957 has no Hoare annotation [2022-02-20 18:07:34,285 WARN L170 areAnnotationChecker]: L957 has no Hoare annotation [2022-02-20 18:07:34,285 WARN L170 areAnnotationChecker]: timeShiftEXIT has no Hoare annotation [2022-02-20 18:07:34,285 WARN L170 areAnnotationChecker]: timeShiftEXIT has no Hoare annotation [2022-02-20 18:07:34,285 WARN L170 areAnnotationChecker]: timeShiftEXIT has no Hoare annotation [2022-02-20 18:07:34,285 WARN L170 areAnnotationChecker]: L543-2 has no Hoare annotation [2022-02-20 18:07:34,285 WARN L170 areAnnotationChecker]: L477 has no Hoare annotation [2022-02-20 18:07:34,285 WARN L170 areAnnotationChecker]: ULTIMATE.startFINAL has no Hoare annotation [2022-02-20 18:07:34,285 WARN L170 areAnnotationChecker]: L777-1 has no Hoare annotation [2022-02-20 18:07:34,286 WARN L170 areAnnotationChecker]: L777-1 has no Hoare annotation [2022-02-20 18:07:34,286 WARN L170 areAnnotationChecker]: L663 has no Hoare annotation [2022-02-20 18:07:34,286 WARN L170 areAnnotationChecker]: L663 has no Hoare annotation [2022-02-20 18:07:34,286 WARN L170 areAnnotationChecker]: L930 has no Hoare annotation [2022-02-20 18:07:34,286 WARN L170 areAnnotationChecker]: L930 has no Hoare annotation [2022-02-20 18:07:34,286 WARN L170 areAnnotationChecker]: ULTIMATE.startFINAL has no Hoare annotation [2022-02-20 18:07:34,286 WARN L170 areAnnotationChecker]: L664 has no Hoare annotation [2022-02-20 18:07:34,287 WARN L170 areAnnotationChecker]: L672 has no Hoare annotation [2022-02-20 18:07:34,287 WARN L170 areAnnotationChecker]: L672 has no Hoare annotation [2022-02-20 18:07:34,287 WARN L170 areAnnotationChecker]: L672-1 has no Hoare annotation [2022-02-20 18:07:34,287 INFO L163 areAnnotationChecker]: CFG has 28 edges. 28 inductive. 0 not inductive. 0 times theorem prover too weak to decide inductivity. 0 times interpolants missing. [2022-02-20 18:07:34,301 INFO L202 PluginConnector]: Adding new model de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction CFG 20.02 06:07:34 BoogieIcfgContainer [2022-02-20 18:07:34,301 INFO L132 PluginConnector]: ------------------------ END TraceAbstraction---------------------------- [2022-02-20 18:07:34,301 INFO L113 PluginConnector]: ------------------------Witness Printer---------------------------- [2022-02-20 18:07:34,301 INFO L271 PluginConnector]: Initializing Witness Printer... [2022-02-20 18:07:34,302 INFO L275 PluginConnector]: Witness Printer initialized [2022-02-20 18:07:34,302 INFO L185 PluginConnector]: Executing the observer RCFGCatcher from plugin Witness Printer for "de.uni_freiburg.informatik.ultimate.plugins.generator.rcfgbuilder CFG 20.02 06:07:29" (3/4) ... [2022-02-20 18:07:34,304 INFO L137 WitnessPrinter]: Generating witness for correct program [2022-02-20 18:07:34,308 INFO L354 RCFGBacktranslator]: Ignoring RootEdge to procedure deactivatePump [2022-02-20 18:07:34,308 INFO L354 RCFGBacktranslator]: Ignoring RootEdge to procedure processEnvironment__wrappee__base [2022-02-20 18:07:34,308 INFO L354 RCFGBacktranslator]: Ignoring RootEdge to procedure changeMethaneLevel [2022-02-20 18:07:34,308 INFO L354 RCFGBacktranslator]: Ignoring RootEdge to procedure isMethaneLevelCritical [2022-02-20 18:07:34,308 INFO L354 RCFGBacktranslator]: Ignoring RootEdge to procedure timeShift [2022-02-20 18:07:34,308 INFO L354 RCFGBacktranslator]: Ignoring RootEdge to procedure cleanup [2022-02-20 18:07:34,309 INFO L354 RCFGBacktranslator]: Ignoring RootEdge to procedure waterRise [2022-02-20 18:07:34,309 INFO L354 RCFGBacktranslator]: Ignoring RootEdge to procedure processEnvironment__wrappee__methaneQuery [2022-02-20 18:07:34,309 INFO L354 RCFGBacktranslator]: Ignoring RootEdge to procedure isMethaneAlarm [2022-02-20 18:07:34,314 INFO L910 BoogieBacktranslator]: Reduced CFG by removing 50 nodes and edges [2022-02-20 18:07:34,314 INFO L910 BoogieBacktranslator]: Reduced CFG by removing 22 nodes and edges [2022-02-20 18:07:34,315 INFO L910 BoogieBacktranslator]: Reduced CFG by removing 11 nodes and edges [2022-02-20 18:07:34,315 INFO L910 BoogieBacktranslator]: Reduced CFG by removing 5 nodes and edges [2022-02-20 18:07:34,315 INFO L910 BoogieBacktranslator]: Reduced CFG by removing 2 nodes and edges [2022-02-20 18:07:34,316 INFO L910 BoogieBacktranslator]: Reduced CFG by removing 1 nodes and edges [2022-02-20 18:07:34,316 INFO L910 BoogieBacktranslator]: Reduced CFG by removing 1 nodes and edges [2022-02-20 18:07:34,334 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: ((pumpRunning == 0 && methaneLevelCritical == 0) && 1 == systemActive) && \result == systemActive [2022-02-20 18:07:34,335 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (((pumpRunning == 0 && tmp == systemActive) && methaneLevelCritical == 0) && 1 == systemActive) && \result == systemActive [2022-02-20 18:07:34,335 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (((pumpRunning == 0 && tmp == systemActive) && methaneLevelCritical == 0) && 1 == systemActive) && \result == systemActive [2022-02-20 18:07:34,335 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (((pumpRunning == 0 && tmp == systemActive) && 1 == systemActive) && \result == systemActive) && splverifierCounter == 0 [2022-02-20 18:07:34,336 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: !(\old(pumpRunning) == 0) || !(1 == systemActive) [2022-02-20 18:07:34,336 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (!(\old(pumpRunning) == 0) || pumpRunning == 0) || !(1 == systemActive) [2022-02-20 18:07:34,337 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (((pumpRunning == 0 && tmp == systemActive) && 1 == systemActive) && \result == systemActive) && splverifierCounter == 0 [2022-02-20 18:07:34,337 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (((!(\old(pumpRunning) == 0) || !(1 == systemActive)) || !(methaneLevelCritical == 0)) || tmp == 0) && ((!(\old(pumpRunning) == 0) || pumpRunning == 0) || !(1 == systemActive)) [2022-02-20 18:07:34,337 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: ((!(\old(pumpRunning) == 0) || !(1 == systemActive)) || (pumpRunning == 0 && \result == 0)) && ((!(\old(pumpRunning) == 0) || !(1 == systemActive)) || !(methaneLevelCritical == 0)) [2022-02-20 18:07:34,338 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: !(\old(pumpRunning) == 0) || !(1 == systemActive) [2022-02-20 18:07:34,338 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: !(\old(pumpRunning) == 0) || !(1 == systemActive) [2022-02-20 18:07:34,338 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: !(\old(pumpRunning) == 0) || !(1 == systemActive) [2022-02-20 18:07:34,356 INFO L141 WitnessManager]: Wrote witness to /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/witness.graphml [2022-02-20 18:07:34,356 INFO L132 PluginConnector]: ------------------------ END Witness Printer---------------------------- [2022-02-20 18:07:34,357 INFO L158 Benchmark]: Toolchain (without parser) took 5401.58ms. Allocated memory was 98.6MB in the beginning and 144.7MB in the end (delta: 46.1MB). Free memory was 65.2MB in the beginning and 101.5MB in the end (delta: -36.4MB). Peak memory consumption was 9.6MB. Max. memory is 16.1GB. [2022-02-20 18:07:34,358 INFO L158 Benchmark]: CDTParser took 0.19ms. Allocated memory is still 98.6MB. Free memory was 53.7MB in the beginning and 53.6MB in the end (delta: 83.9kB). There was no memory consumed. Max. memory is 16.1GB. [2022-02-20 18:07:34,358 INFO L158 Benchmark]: CACSL2BoogieTranslator took 386.17ms. Allocated memory is still 98.6MB. Free memory was 64.8MB in the beginning and 62.3MB in the end (delta: 2.5MB). Peak memory consumption was 6.3MB. Max. memory is 16.1GB. [2022-02-20 18:07:34,358 INFO L158 Benchmark]: Boogie Procedure Inliner took 45.46ms. Allocated memory is still 98.6MB. Free memory was 62.3MB in the beginning and 59.7MB in the end (delta: 2.7MB). Peak memory consumption was 2.1MB. Max. memory is 16.1GB. [2022-02-20 18:07:34,358 INFO L158 Benchmark]: Boogie Preprocessor took 21.32ms. Allocated memory is still 98.6MB. Free memory was 59.7MB in the beginning and 57.8MB in the end (delta: 1.8MB). Peak memory consumption was 2.1MB. Max. memory is 16.1GB. [2022-02-20 18:07:34,359 INFO L158 Benchmark]: RCFGBuilder took 486.15ms. Allocated memory was 98.6MB in the beginning and 119.5MB in the end (delta: 21.0MB). Free memory was 57.8MB in the beginning and 83.7MB in the end (delta: -25.9MB). Peak memory consumption was 12.7MB. Max. memory is 16.1GB. [2022-02-20 18:07:34,359 INFO L158 Benchmark]: TraceAbstraction took 4389.64ms. Allocated memory was 119.5MB in the beginning and 144.7MB in the end (delta: 25.2MB). Free memory was 83.0MB in the beginning and 106.8MB in the end (delta: -23.8MB). Peak memory consumption was 68.9MB. Max. memory is 16.1GB. [2022-02-20 18:07:34,359 INFO L158 Benchmark]: Witness Printer took 55.11ms. Allocated memory is still 144.7MB. Free memory was 106.8MB in the beginning and 101.5MB in the end (delta: 5.2MB). Peak memory consumption was 4.2MB. Max. memory is 16.1GB. [2022-02-20 18:07:34,361 INFO L339 ainManager$Toolchain]: ####################### End [Toolchain 1] ####################### --- Results --- * Results from de.uni_freiburg.informatik.ultimate.core: - AssertionsEnabledResult: Assertions are enabled Assertions are enabled - StatisticsResult: Toolchain Benchmarks Benchmark results are: * CDTParser took 0.19ms. Allocated memory is still 98.6MB. Free memory was 53.7MB in the beginning and 53.6MB in the end (delta: 83.9kB). There was no memory consumed. Max. memory is 16.1GB. * CACSL2BoogieTranslator took 386.17ms. Allocated memory is still 98.6MB. Free memory was 64.8MB in the beginning and 62.3MB in the end (delta: 2.5MB). Peak memory consumption was 6.3MB. Max. memory is 16.1GB. * Boogie Procedure Inliner took 45.46ms. Allocated memory is still 98.6MB. Free memory was 62.3MB in the beginning and 59.7MB in the end (delta: 2.7MB). Peak memory consumption was 2.1MB. Max. memory is 16.1GB. * Boogie Preprocessor took 21.32ms. Allocated memory is still 98.6MB. Free memory was 59.7MB in the beginning and 57.8MB in the end (delta: 1.8MB). Peak memory consumption was 2.1MB. Max. memory is 16.1GB. * RCFGBuilder took 486.15ms. Allocated memory was 98.6MB in the beginning and 119.5MB in the end (delta: 21.0MB). Free memory was 57.8MB in the beginning and 83.7MB in the end (delta: -25.9MB). Peak memory consumption was 12.7MB. Max. memory is 16.1GB. * TraceAbstraction took 4389.64ms. Allocated memory was 119.5MB in the beginning and 144.7MB in the end (delta: 25.2MB). Free memory was 83.0MB in the beginning and 106.8MB in the end (delta: -23.8MB). Peak memory consumption was 68.9MB. Max. memory is 16.1GB. * Witness Printer took 55.11ms. Allocated memory is still 144.7MB. Free memory was 106.8MB in the beginning and 101.5MB in the end (delta: 5.2MB). Peak memory consumption was 4.2MB. Max. memory is 16.1GB. * Results from de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction: - StatisticsResult: ErrorAutomatonStatistics NumberErrorTraces: 0, NumberStatementsAllTraces: 0, NumberRelevantStatements: 0, 0.0s ErrorAutomatonConstructionTimeTotal, 0.0s FaulLocalizationTime, NumberStatementsFirstTrace: -1, TraceLengthAvg: 0, 0.0s ErrorAutomatonConstructionTimeAvg, 0.0s ErrorAutomatonDifferenceTimeAvg, 0.0s ErrorAutomatonDifferenceTimeTotal, NumberOfNoEnhancement: 0, NumberOfFiniteEnhancement: 0, NumberOfInfiniteEnhancement: 0 - PositiveResult [Line: 930]: call to reach_error is unreachable For all program executions holds that call to reach_error is unreachable at this location - StatisticsResult: Ultimate Automizer benchmark data CFG has 10 procedures, 94 locations, 1 error locations. Started 1 CEGAR loops. OverallTime: 4.3s, OverallIterations: 5, TraceHistogramMax: 1, PathProgramHistogramMax: 1, EmptinessCheckTime: 0.0s, AutomataDifference: 2.6s, DeadEndRemovalTime: 0.0s, HoareAnnotationTime: 0.5s, InitialAbstractionConstructionTime: 0.0s, PartialOrderReductionTime: 0.0s, HoareTripleCheckerStatistics: 0 mSolverCounterUnknown, 364 SdHoareTripleChecker+Valid, 0.4s IncrementalHoareTripleChecker+Time, 0 mSdLazyCounter, 351 mSDsluCounter, 970 SdHoareTripleChecker+Invalid, 0.4s Time, 0 mProtectedAction, 0 SdHoareTripleChecker+Unchecked, 0 IncrementalHoareTripleChecker+Unchecked, 541 mSDsCounter, 98 IncrementalHoareTripleChecker+Valid, 0 mProtectedPredicate, 369 IncrementalHoareTripleChecker+Invalid, 467 SdHoareTripleChecker+Unknown, 0 mSolverCounterNotChecked, 98 mSolverCounterUnsat, 429 mSDtfsCounter, 369 mSolverCounterSat, 0.0s SdHoareTripleChecker+Time, 0 IncrementalHoareTripleChecker+Unknown, PredicateUnifierStatistics: 0 DeclaredPredicates, 58 GetRequests, 29 SyntacticMatches, 0 SemanticMatches, 29 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 28 ImplicationChecksByTransitivity, 0.1s Time, 0.0s BasicInterpolantAutomatonTime, BiggestAbstraction: size=139occurred in iteration=4, InterpolantAutomatonStates: 30, traceCheckStatistics: No data available, InterpolantConsolidationStatistics: No data available, PathInvariantsStatistics: No data available, 0/0 InterpolantCoveringCapability, TotalInterpolationStatistics: No data available, 0.0s DumpTime, AutomataMinimizationStatistics: 0.2s AutomataMinimizationTime, 5 MinimizatonAttempts, 31 StatesRemovedByMinimization, 1 NontrivialMinimizations, HoareAnnotationStatistics: 0.0s HoareAnnotationTime, 43 LocationsWithAnnotation, 295 PreInvPairs, 319 NumberOfFragments, 384 HoareAnnotationTreeSize, 295 FomulaSimplifications, 74 FormulaSimplificationTreeSizeReduction, 0.1s HoareSimplificationTime, 43 FomulaSimplificationsInter, 662 FormulaSimplificationTreeSizeReductionInter, 0.4s HoareSimplificationTimeInter, RefinementEngineStatistics: TRACE_CHECK: 0.0s SsaConstructionTime, 0.2s SatisfiabilityAnalysisTime, 0.5s InterpolantComputationTime, 168 NumberOfCodeBlocks, 168 NumberOfCodeBlocksAsserted, 5 NumberOfCheckSat, 163 ConstructedInterpolants, 0 QuantifiedInterpolants, 345 SizeOfPredicates, 0 NumberOfNonLiveVariables, 0 ConjunctsInSsa, 0 ConjunctsInUnsatCore, 5 InterpolantComputations, 5 PerfectInterpolantSequences, 0/0 InterpolantCoveringCapability, INVARIANT_SYNTHESIS: No data available, INTERPOLANT_CONSOLIDATION: No data available, ABSTRACT_INTERPRETATION: No data available, PDR: No data available, ACCELERATED_INTERPOLATION: No data available, SIFA: No data available, ReuseStatistics: No data available - AllSpecificationsHoldResult: All specifications hold 1 specifications checked. All of them hold - InvariantResult [Line: 444]: Loop Invariant Derived loop invariant: ((pumpRunning == 0 && methaneLevelCritical == 0) && 1 == systemActive) && \result == systemActive - InvariantResult [Line: 661]: Loop Invariant Derived loop invariant: 0 - InvariantResult [Line: 784]: Loop Invariant Derived loop invariant: (!(\old(pumpRunning) == 0) || pumpRunning == 0) || !(1 == systemActive) - InvariantResult [Line: 917]: Loop Invariant Derived loop invariant: (((pumpRunning == 0 && tmp == systemActive) && 1 == systemActive) && \result == systemActive) && splverifierCounter == 0 - InvariantResult [Line: 936]: Loop Invariant Derived loop invariant: (((pumpRunning == 0 && tmp == systemActive) && methaneLevelCritical == 0) && 1 == systemActive) && \result == systemActive - InvariantResult [Line: 437]: Loop Invariant Derived loop invariant: (pumpRunning == 0 && methaneLevelCritical == 0) && 1 == systemActive - InvariantResult [Line: 944]: Loop Invariant Derived loop invariant: (((!(\old(pumpRunning) == 0) || !(1 == systemActive)) || !(methaneLevelCritical == 0)) || tmp == 0) && ((!(\old(pumpRunning) == 0) || pumpRunning == 0) || !(1 == systemActive)) - InvariantResult [Line: 898]: Loop Invariant Derived loop invariant: !(\old(pumpRunning) == 0) || !(1 == systemActive) - InvariantResult [Line: 522]: Loop Invariant Derived loop invariant: 1 - InvariantResult [Line: 533]: Loop Invariant Derived loop invariant: 1 - InvariantResult [Line: 662]: Loop Invariant Derived loop invariant: (((pumpRunning == 0 && tmp == systemActive) && 1 == systemActive) && \result == systemActive) && splverifierCounter == 0 - InvariantResult [Line: 456]: Loop Invariant Derived loop invariant: 1 - InvariantResult [Line: 641]: Loop Invariant Derived loop invariant: !(\old(pumpRunning) == 0) || !(1 == systemActive) - InvariantResult [Line: 853]: Loop Invariant Derived loop invariant: ((!(\old(pumpRunning) == 0) || !(1 == systemActive)) || (pumpRunning == 0 && \result == 0)) && ((!(\old(pumpRunning) == 0) || !(1 == systemActive)) || !(methaneLevelCritical == 0)) - InvariantResult [Line: 564]: Loop Invariant Derived loop invariant: !(\old(pumpRunning) == 0) || !(1 == systemActive) - InvariantResult [Line: 926]: Loop Invariant Derived loop invariant: !(\old(pumpRunning) == 0) || !(1 == systemActive) - InvariantResult [Line: 652]: Loop Invariant Derived loop invariant: 1 - InvariantResult [Line: 466]: Loop Invariant Derived loop invariant: 1 - InvariantResult [Line: 430]: Loop Invariant Derived loop invariant: (pumpRunning == 0 && methaneLevelCritical == 0) && 1 == systemActive - InvariantResult [Line: 513]: Loop Invariant Derived loop invariant: (((pumpRunning == 0 && tmp == systemActive) && methaneLevelCritical == 0) && 1 == systemActive) && \result == systemActive RESULT: Ultimate proved your program to be correct! [2022-02-20 18:07:34,397 INFO L552 MonitoredProcess]: [MP /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in -t:2000 (1)] Ended with exit code 0 Received shutdown request... --- End real Ultimate output --- Execution finished normally Writing output log to file Ultimate.log Result: TRUE