./Ultimate.py --spec ../sv-benchmarks/c/properties/unreach-call.prp --file ../sv-benchmarks/c/product-lines/minepump_spec5_product03.cil.c --full-output -ea --architecture 32bit -------------------------------------------------------------------------------- Checking for ERROR reachability Using default analysis Version 03d7b7b3 Calling Ultimate with: /usr/bin/java -Dosgi.configuration.area=/storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/data/config -Xmx15G -Xms4m -ea -jar /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/plugins/org.eclipse.equinox.launcher_1.5.800.v20200727-1323.jar -data @noDefault -ultimatedata /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/data -tc /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/config/AutomizerReach.xml -i ../sv-benchmarks/c/product-lines/minepump_spec5_product03.cil.c -s /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/config/svcomp-Reach-32bit-Automizer_Default.epf --cacsl2boogietranslator.entry.function main --witnessprinter.witness.directory /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux --witnessprinter.witness.filename witness.graphml --witnessprinter.write.witness.besides.input.file false --witnessprinter.graph.data.specification CHECK( init(main()), LTL(G ! call(reach_error())) ) --witnessprinter.graph.data.producer Automizer --witnessprinter.graph.data.architecture 32bit --witnessprinter.graph.data.programhash db8fa4142710656a2cf6992c61a703485566be309c58b9bda433457e238bbe1a --- Real Ultimate output --- This is Ultimate 0.2.2-dev-03d7b7b [2022-02-20 18:11:27,591 INFO L177 SettingsManager]: Resetting all preferences to default values... [2022-02-20 18:11:27,593 INFO L181 SettingsManager]: Resetting UltimateCore preferences to default values [2022-02-20 18:11:27,612 INFO L184 SettingsManager]: Ultimate Commandline Interface provides no preferences, ignoring... [2022-02-20 18:11:27,613 INFO L181 SettingsManager]: Resetting Boogie Preprocessor preferences to default values [2022-02-20 18:11:27,614 INFO L181 SettingsManager]: Resetting Boogie Procedure Inliner preferences to default values [2022-02-20 18:11:27,615 INFO L181 SettingsManager]: Resetting Abstract Interpretation preferences to default values [2022-02-20 18:11:27,616 INFO L181 SettingsManager]: Resetting LassoRanker preferences to default values [2022-02-20 18:11:27,617 INFO L181 SettingsManager]: Resetting Reaching Definitions preferences to default values [2022-02-20 18:11:27,618 INFO L181 SettingsManager]: Resetting SyntaxChecker preferences to default values [2022-02-20 18:11:27,619 INFO L181 SettingsManager]: Resetting Sifa preferences to default values [2022-02-20 18:11:27,620 INFO L184 SettingsManager]: Büchi Program Product provides no preferences, ignoring... [2022-02-20 18:11:27,620 INFO L181 SettingsManager]: Resetting LTL2Aut preferences to default values [2022-02-20 18:11:27,621 INFO L181 SettingsManager]: Resetting PEA to Boogie preferences to default values [2022-02-20 18:11:27,622 INFO L181 SettingsManager]: Resetting BlockEncodingV2 preferences to default values [2022-02-20 18:11:27,622 INFO L181 SettingsManager]: Resetting ChcToBoogie preferences to default values [2022-02-20 18:11:27,623 INFO L181 SettingsManager]: Resetting AutomataScriptInterpreter preferences to default values [2022-02-20 18:11:27,624 INFO L181 SettingsManager]: Resetting BuchiAutomizer preferences to default values [2022-02-20 18:11:27,625 INFO L181 SettingsManager]: Resetting CACSL2BoogieTranslator preferences to default values [2022-02-20 18:11:27,626 INFO L181 SettingsManager]: Resetting CodeCheck preferences to default values [2022-02-20 18:11:27,627 INFO L181 SettingsManager]: Resetting InvariantSynthesis preferences to default values [2022-02-20 18:11:27,628 INFO L181 SettingsManager]: Resetting RCFGBuilder preferences to default values [2022-02-20 18:11:27,630 INFO L181 SettingsManager]: Resetting Referee preferences to default values [2022-02-20 18:11:27,630 INFO L181 SettingsManager]: Resetting TraceAbstraction preferences to default values [2022-02-20 18:11:27,633 INFO L184 SettingsManager]: TraceAbstractionConcurrent provides no preferences, ignoring... [2022-02-20 18:11:27,633 INFO L184 SettingsManager]: TraceAbstractionWithAFAs provides no preferences, ignoring... [2022-02-20 18:11:27,633 INFO L181 SettingsManager]: Resetting TreeAutomizer preferences to default values [2022-02-20 18:11:27,634 INFO L181 SettingsManager]: Resetting IcfgToChc preferences to default values [2022-02-20 18:11:27,635 INFO L181 SettingsManager]: Resetting IcfgTransformer preferences to default values [2022-02-20 18:11:27,635 INFO L184 SettingsManager]: ReqToTest provides no preferences, ignoring... [2022-02-20 18:11:27,636 INFO L181 SettingsManager]: Resetting Boogie Printer preferences to default values [2022-02-20 18:11:27,636 INFO L181 SettingsManager]: Resetting ChcSmtPrinter preferences to default values [2022-02-20 18:11:27,637 INFO L181 SettingsManager]: Resetting ReqPrinter preferences to default values [2022-02-20 18:11:27,638 INFO L181 SettingsManager]: Resetting Witness Printer preferences to default values [2022-02-20 18:11:27,639 INFO L184 SettingsManager]: Boogie PL CUP Parser provides no preferences, ignoring... [2022-02-20 18:11:27,639 INFO L181 SettingsManager]: Resetting CDTParser preferences to default values [2022-02-20 18:11:27,639 INFO L184 SettingsManager]: AutomataScriptParser provides no preferences, ignoring... [2022-02-20 18:11:27,640 INFO L184 SettingsManager]: ReqParser provides no preferences, ignoring... [2022-02-20 18:11:27,640 INFO L181 SettingsManager]: Resetting SmtParser preferences to default values [2022-02-20 18:11:27,641 INFO L181 SettingsManager]: Resetting Witness Parser preferences to default values [2022-02-20 18:11:27,641 INFO L188 SettingsManager]: Finished resetting all preferences to default values... [2022-02-20 18:11:27,642 INFO L101 SettingsManager]: Beginning loading settings from /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/config/svcomp-Reach-32bit-Automizer_Default.epf [2022-02-20 18:11:27,657 INFO L113 SettingsManager]: Loading preferences was successful [2022-02-20 18:11:27,658 INFO L115 SettingsManager]: Preferences different from defaults after loading the file: [2022-02-20 18:11:27,658 INFO L136 SettingsManager]: Preferences of UltimateCore differ from their defaults: [2022-02-20 18:11:27,658 INFO L138 SettingsManager]: * Log level for class=de.uni_freiburg.informatik.ultimate.lib.smtlibutils.quantifier.QuantifierPusher=ERROR; [2022-02-20 18:11:27,659 INFO L136 SettingsManager]: Preferences of Boogie Procedure Inliner differ from their defaults: [2022-02-20 18:11:27,659 INFO L138 SettingsManager]: * Ignore calls to procedures called more than once=ONLY_FOR_SEQUENTIAL_PROGRAMS [2022-02-20 18:11:27,660 INFO L136 SettingsManager]: Preferences of BlockEncodingV2 differ from their defaults: [2022-02-20 18:11:27,660 INFO L138 SettingsManager]: * Create parallel compositions if possible=false [2022-02-20 18:11:27,660 INFO L138 SettingsManager]: * Use SBE=true [2022-02-20 18:11:27,660 INFO L136 SettingsManager]: Preferences of CACSL2BoogieTranslator differ from their defaults: [2022-02-20 18:11:27,660 INFO L138 SettingsManager]: * sizeof long=4 [2022-02-20 18:11:27,661 INFO L138 SettingsManager]: * Overapproximate operations on floating types=true [2022-02-20 18:11:27,661 INFO L138 SettingsManager]: * sizeof POINTER=4 [2022-02-20 18:11:27,661 INFO L138 SettingsManager]: * Check division by zero=IGNORE [2022-02-20 18:11:27,661 INFO L138 SettingsManager]: * Pointer to allocated memory at dereference=IGNORE [2022-02-20 18:11:27,661 INFO L138 SettingsManager]: * If two pointers are subtracted or compared they have the same base address=IGNORE [2022-02-20 18:11:27,661 INFO L138 SettingsManager]: * Check array bounds for arrays that are off heap=IGNORE [2022-02-20 18:11:27,662 INFO L138 SettingsManager]: * sizeof long double=12 [2022-02-20 18:11:27,662 INFO L138 SettingsManager]: * Check if freed pointer was valid=false [2022-02-20 18:11:27,662 INFO L138 SettingsManager]: * Use constant arrays=true [2022-02-20 18:11:27,662 INFO L138 SettingsManager]: * Pointer base address is valid at dereference=IGNORE [2022-02-20 18:11:27,662 INFO L136 SettingsManager]: Preferences of RCFGBuilder differ from their defaults: [2022-02-20 18:11:27,663 INFO L138 SettingsManager]: * Size of a code block=SequenceOfStatements [2022-02-20 18:11:27,663 INFO L138 SettingsManager]: * SMT solver=External_DefaultMode [2022-02-20 18:11:27,663 INFO L138 SettingsManager]: * Command for external solver=z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in -t:2000 [2022-02-20 18:11:27,663 INFO L136 SettingsManager]: Preferences of TraceAbstraction differ from their defaults: [2022-02-20 18:11:27,663 INFO L138 SettingsManager]: * Compute Interpolants along a Counterexample=FPandBP [2022-02-20 18:11:27,664 INFO L138 SettingsManager]: * Positions where we compute the Hoare Annotation=LoopsAndPotentialCycles [2022-02-20 18:11:27,664 INFO L138 SettingsManager]: * Trace refinement strategy=CAMEL [2022-02-20 18:11:27,664 INFO L138 SettingsManager]: * Command for external solver=z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in [2022-02-20 18:11:27,664 INFO L138 SettingsManager]: * Large block encoding in concurrent analysis=OFF [2022-02-20 18:11:27,664 INFO L138 SettingsManager]: * Automaton type used in concurrency analysis=PETRI_NET [2022-02-20 18:11:27,664 INFO L138 SettingsManager]: * Compute Hoare Annotation of negated interpolant automaton, abstraction and CFG=true [2022-02-20 18:11:27,665 INFO L138 SettingsManager]: * SMT solver=External_ModelsAndUnsatCoreMode WARNING: An illegal reflective access operation has occurred WARNING: Illegal reflective access by com.sun.xml.bind.v2.runtime.reflect.opt.Injector$1 (file:/storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/plugins/com.sun.xml.bind_2.2.0.v201505121915.jar) to method java.lang.ClassLoader.defineClass(java.lang.String,byte[],int,int) WARNING: Please consider reporting this to the maintainers of com.sun.xml.bind.v2.runtime.reflect.opt.Injector$1 WARNING: Use --illegal-access=warn to enable warnings of further illegal reflective access operations WARNING: All illegal access operations will be denied in a future release Applying setting for plugin de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator: Entry function -> main Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Witness directory -> /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Witness filename -> witness.graphml Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Write witness besides input file -> false Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Graph data specification -> CHECK( init(main()), LTL(G ! call(reach_error())) ) Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Graph data producer -> Automizer Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Graph data architecture -> 32bit Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Graph data programhash -> db8fa4142710656a2cf6992c61a703485566be309c58b9bda433457e238bbe1a [2022-02-20 18:11:27,813 INFO L75 nceAwareModelManager]: Repository-Root is: /tmp [2022-02-20 18:11:27,827 INFO L261 ainManager$Toolchain]: [Toolchain 1]: Applicable parser(s) successfully (re)initialized [2022-02-20 18:11:27,829 INFO L217 ainManager$Toolchain]: [Toolchain 1]: Toolchain selected. [2022-02-20 18:11:27,829 INFO L271 PluginConnector]: Initializing CDTParser... [2022-02-20 18:11:27,830 INFO L275 PluginConnector]: CDTParser initialized [2022-02-20 18:11:27,831 INFO L432 ainManager$Toolchain]: [Toolchain 1]: Parsing single file: /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/../sv-benchmarks/c/product-lines/minepump_spec5_product03.cil.c [2022-02-20 18:11:27,873 INFO L220 CDTParser]: Created temporary CDT project at /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/data/7cd0b70eb/cb54898680a0406383ed0cbdbe9746c1/FLAG2a4442e2f [2022-02-20 18:11:28,265 INFO L306 CDTParser]: Found 1 translation units. [2022-02-20 18:11:28,267 INFO L160 CDTParser]: Scanning /storage/repos/ultimate/releaseScripts/default/sv-benchmarks/c/product-lines/minepump_spec5_product03.cil.c [2022-02-20 18:11:28,279 INFO L349 CDTParser]: About to delete temporary CDT project at /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/data/7cd0b70eb/cb54898680a0406383ed0cbdbe9746c1/FLAG2a4442e2f [2022-02-20 18:11:28,613 INFO L357 CDTParser]: Successfully deleted /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/data/7cd0b70eb/cb54898680a0406383ed0cbdbe9746c1 [2022-02-20 18:11:28,616 INFO L299 ainManager$Toolchain]: ####################### [Toolchain 1] ####################### [2022-02-20 18:11:28,619 INFO L131 ToolchainWalker]: Walking toolchain with 6 elements. [2022-02-20 18:11:28,621 INFO L113 PluginConnector]: ------------------------CACSL2BoogieTranslator---------------------------- [2022-02-20 18:11:28,621 INFO L271 PluginConnector]: Initializing CACSL2BoogieTranslator... [2022-02-20 18:11:28,624 INFO L275 PluginConnector]: CACSL2BoogieTranslator initialized [2022-02-20 18:11:28,625 INFO L185 PluginConnector]: Executing the observer ACSLObjectContainerObserver from plugin CACSL2BoogieTranslator for "CDTParser AST 20.02 06:11:28" (1/1) ... [2022-02-20 18:11:28,627 INFO L205 PluginConnector]: Invalid model from CACSL2BoogieTranslator for observer de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator.ACSLObjectContainerObserver@75077bf and model type de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 20.02 06:11:28, skipping insertion in model container [2022-02-20 18:11:28,628 INFO L185 PluginConnector]: Executing the observer CACSL2BoogieTranslatorObserver from plugin CACSL2BoogieTranslator for "CDTParser AST 20.02 06:11:28" (1/1) ... [2022-02-20 18:11:28,633 INFO L145 MainTranslator]: Starting translation in SV-COMP mode [2022-02-20 18:11:28,672 INFO L178 MainTranslator]: Built tables and reachable declarations [2022-02-20 18:11:28,853 WARN L230 ndardFunctionHandler]: Function reach_error is already implemented but we override the implementation for the call at /storage/repos/ultimate/releaseScripts/default/sv-benchmarks/c/product-lines/minepump_spec5_product03.cil.c[1605,1618] [2022-02-20 18:11:28,958 INFO L210 PostProcessor]: Analyzing one entry point: main [2022-02-20 18:11:28,969 INFO L203 MainTranslator]: Completed pre-run [2022-02-20 18:11:28,985 WARN L230 ndardFunctionHandler]: Function reach_error is already implemented but we override the implementation for the call at /storage/repos/ultimate/releaseScripts/default/sv-benchmarks/c/product-lines/minepump_spec5_product03.cil.c[1605,1618] [2022-02-20 18:11:29,050 INFO L210 PostProcessor]: Analyzing one entry point: main [2022-02-20 18:11:29,072 INFO L208 MainTranslator]: Completed translation [2022-02-20 18:11:29,082 INFO L202 PluginConnector]: Adding new model de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 20.02 06:11:29 WrapperNode [2022-02-20 18:11:29,083 INFO L132 PluginConnector]: ------------------------ END CACSL2BoogieTranslator---------------------------- [2022-02-20 18:11:29,084 INFO L113 PluginConnector]: ------------------------Boogie Procedure Inliner---------------------------- [2022-02-20 18:11:29,084 INFO L271 PluginConnector]: Initializing Boogie Procedure Inliner... [2022-02-20 18:11:29,084 INFO L275 PluginConnector]: Boogie Procedure Inliner initialized [2022-02-20 18:11:29,089 INFO L185 PluginConnector]: Executing the observer TypeChecker from plugin Boogie Procedure Inliner for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 20.02 06:11:29" (1/1) ... [2022-02-20 18:11:29,107 INFO L185 PluginConnector]: Executing the observer Inliner from plugin Boogie Procedure Inliner for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 20.02 06:11:29" (1/1) ... [2022-02-20 18:11:29,137 INFO L137 Inliner]: procedures = 52, calls = 149, calls flagged for inlining = 21, calls inlined = 17, statements flattened = 198 [2022-02-20 18:11:29,138 INFO L132 PluginConnector]: ------------------------ END Boogie Procedure Inliner---------------------------- [2022-02-20 18:11:29,139 INFO L113 PluginConnector]: ------------------------Boogie Preprocessor---------------------------- [2022-02-20 18:11:29,139 INFO L271 PluginConnector]: Initializing Boogie Preprocessor... [2022-02-20 18:11:29,139 INFO L275 PluginConnector]: Boogie Preprocessor initialized [2022-02-20 18:11:29,145 INFO L185 PluginConnector]: Executing the observer EnsureBoogieModelObserver from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 20.02 06:11:29" (1/1) ... [2022-02-20 18:11:29,145 INFO L185 PluginConnector]: Executing the observer TypeChecker from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 20.02 06:11:29" (1/1) ... [2022-02-20 18:11:29,154 INFO L185 PluginConnector]: Executing the observer ConstExpander from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 20.02 06:11:29" (1/1) ... [2022-02-20 18:11:29,154 INFO L185 PluginConnector]: Executing the observer StructExpander from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 20.02 06:11:29" (1/1) ... [2022-02-20 18:11:29,165 INFO L185 PluginConnector]: Executing the observer UnstructureCode from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 20.02 06:11:29" (1/1) ... [2022-02-20 18:11:29,172 INFO L185 PluginConnector]: Executing the observer FunctionInliner from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 20.02 06:11:29" (1/1) ... [2022-02-20 18:11:29,174 INFO L185 PluginConnector]: Executing the observer BoogieSymbolTableConstructor from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 20.02 06:11:29" (1/1) ... [2022-02-20 18:11:29,178 INFO L132 PluginConnector]: ------------------------ END Boogie Preprocessor---------------------------- [2022-02-20 18:11:29,180 INFO L113 PluginConnector]: ------------------------RCFGBuilder---------------------------- [2022-02-20 18:11:29,180 INFO L271 PluginConnector]: Initializing RCFGBuilder... [2022-02-20 18:11:29,180 INFO L275 PluginConnector]: RCFGBuilder initialized [2022-02-20 18:11:29,181 INFO L185 PluginConnector]: Executing the observer RCFGBuilderObserver from plugin RCFGBuilder for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 20.02 06:11:29" (1/1) ... [2022-02-20 18:11:29,186 INFO L173 SolverBuilder]: Constructing external solver with command: z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in -t:2000 [2022-02-20 18:11:29,194 INFO L189 MonitoredProcess]: No working directory specified, using /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 [2022-02-20 18:11:29,205 INFO L229 MonitoredProcess]: Starting monitored process 1 with /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in -t:2000 (exit command is (exit), workingDir is null) [2022-02-20 18:11:29,224 INFO L327 MonitoredProcess]: [MP /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in -t:2000 (1)] Waiting until timeout for monitored process [2022-02-20 18:11:29,234 INFO L130 BoogieDeclarations]: Found specification of procedure #Ultimate.allocInit [2022-02-20 18:11:29,235 INFO L130 BoogieDeclarations]: Found specification of procedure timeShift [2022-02-20 18:11:29,235 INFO L138 BoogieDeclarations]: Found implementation of procedure timeShift [2022-02-20 18:11:29,235 INFO L130 BoogieDeclarations]: Found specification of procedure cleanup [2022-02-20 18:11:29,236 INFO L138 BoogieDeclarations]: Found implementation of procedure cleanup [2022-02-20 18:11:29,236 INFO L130 BoogieDeclarations]: Found specification of procedure waterRise [2022-02-20 18:11:29,236 INFO L138 BoogieDeclarations]: Found implementation of procedure waterRise [2022-02-20 18:11:29,236 INFO L130 BoogieDeclarations]: Found specification of procedure isPumpRunning [2022-02-20 18:11:29,236 INFO L138 BoogieDeclarations]: Found implementation of procedure isPumpRunning [2022-02-20 18:11:29,236 INFO L130 BoogieDeclarations]: Found specification of procedure write~init~int [2022-02-20 18:11:29,236 INFO L130 BoogieDeclarations]: Found specification of procedure changeMethaneLevel [2022-02-20 18:11:29,236 INFO L138 BoogieDeclarations]: Found implementation of procedure changeMethaneLevel [2022-02-20 18:11:29,237 INFO L130 BoogieDeclarations]: Found specification of procedure ULTIMATE.start [2022-02-20 18:11:29,237 INFO L138 BoogieDeclarations]: Found implementation of procedure ULTIMATE.start [2022-02-20 18:11:29,300 INFO L234 CfgBuilder]: Building ICFG [2022-02-20 18:11:29,302 INFO L260 CfgBuilder]: Building CFG for each procedure with an implementation [2022-02-20 18:11:29,504 INFO L275 CfgBuilder]: Performing block encoding [2022-02-20 18:11:29,510 INFO L294 CfgBuilder]: Using the 1 location(s) as analysis (start of procedure ULTIMATE.start) [2022-02-20 18:11:29,510 INFO L299 CfgBuilder]: Removed 2 assume(true) statements. [2022-02-20 18:11:29,512 INFO L202 PluginConnector]: Adding new model de.uni_freiburg.informatik.ultimate.plugins.generator.rcfgbuilder CFG 20.02 06:11:29 BoogieIcfgContainer [2022-02-20 18:11:29,512 INFO L132 PluginConnector]: ------------------------ END RCFGBuilder---------------------------- [2022-02-20 18:11:29,513 INFO L113 PluginConnector]: ------------------------TraceAbstraction---------------------------- [2022-02-20 18:11:29,514 INFO L271 PluginConnector]: Initializing TraceAbstraction... [2022-02-20 18:11:29,516 INFO L275 PluginConnector]: TraceAbstraction initialized [2022-02-20 18:11:29,516 INFO L185 PluginConnector]: Executing the observer TraceAbstractionObserver from plugin TraceAbstraction for "CDTParser AST 20.02 06:11:28" (1/3) ... [2022-02-20 18:11:29,517 INFO L205 PluginConnector]: Invalid model from TraceAbstraction for observer de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction.TraceAbstractionObserver@65adc2a9 and model type de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction AST 20.02 06:11:29, skipping insertion in model container [2022-02-20 18:11:29,517 INFO L185 PluginConnector]: Executing the observer TraceAbstractionObserver from plugin TraceAbstraction for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 20.02 06:11:29" (2/3) ... [2022-02-20 18:11:29,517 INFO L205 PluginConnector]: Invalid model from TraceAbstraction for observer de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction.TraceAbstractionObserver@65adc2a9 and model type de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction AST 20.02 06:11:29, skipping insertion in model container [2022-02-20 18:11:29,518 INFO L185 PluginConnector]: Executing the observer TraceAbstractionObserver from plugin TraceAbstraction for "de.uni_freiburg.informatik.ultimate.plugins.generator.rcfgbuilder CFG 20.02 06:11:29" (3/3) ... [2022-02-20 18:11:29,518 INFO L111 eAbstractionObserver]: Analyzing ICFG minepump_spec5_product03.cil.c [2022-02-20 18:11:29,522 INFO L205 ceAbstractionStarter]: Automizer settings: Hoare:true NWA Interpolation:FPandBP Determinization: PREDICATE_ABSTRACTION [2022-02-20 18:11:29,522 INFO L164 ceAbstractionStarter]: Applying trace abstraction to program that has 1 error locations. [2022-02-20 18:11:29,553 INFO L338 AbstractCegarLoop]: ======== Iteration 0 == of CEGAR loop == AllErrorsAtOnce ======== [2022-02-20 18:11:29,558 INFO L339 AbstractCegarLoop]: Settings: SEPARATE_VIOLATION_CHECK=true, mInterprocedural=true, mMaxIterations=1000000, mWatchIteration=1000000, mArtifact=RCFG, mInterpolation=FPandBP, mInterpolantAutomaton=STRAIGHT_LINE, mDumpAutomata=false, mAutomataFormat=ATS_NUMERATE, mDumpPath=., mDeterminiation=PREDICATE_ABSTRACTION, mMinimize=MINIMIZE_SEVPA, mHoare=true, mAutomataTypeConcurrency=PETRI_NET, mHoareTripleChecks=INCREMENTAL, mHoareAnnotationPositions=LoopsAndPotentialCycles, mDumpOnlyReuseAutomata=false, mLimitTraceHistogram=0, mErrorLocTimeLimit=0, mLimitPathProgramCount=0, mCollectInterpolantStatistics=true, mHeuristicEmptinessCheck=false, mHeuristicEmptinessCheckAStarHeuristic=ZERO, mHeuristicEmptinessCheckAStarHeuristicRandomSeed=1337, mHeuristicEmptinessCheckSmtFeatureScoringMethod=DAGSIZE, mSMTFeatureExtraction=false, mSMTFeatureExtractionDumpPath=., mOverrideInterpolantAutomaton=false, mMcrInterpolantMethod=WP, mLoopAccelerationTechnique=FAST_UPR [2022-02-20 18:11:29,558 INFO L340 AbstractCegarLoop]: Starting to check reachability of 1 error locations. [2022-02-20 18:11:29,572 INFO L276 IsEmpty]: Start isEmpty. Operand has 72 states, 57 states have (on average 1.368421052631579) internal successors, (78), 61 states have internal predecessors, (78), 8 states have call successors, (8), 5 states have call predecessors, (8), 5 states have return successors, (8), 8 states have call predecessors, (8), 8 states have call successors, (8) [2022-02-20 18:11:29,576 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 33 [2022-02-20 18:11:29,577 INFO L506 BasicCegarLoop]: Found error trace [2022-02-20 18:11:29,578 INFO L514 BasicCegarLoop]: trace histogram [2, 2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-02-20 18:11:29,578 INFO L402 AbstractCegarLoop]: === Iteration 1 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2022-02-20 18:11:29,581 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2022-02-20 18:11:29,582 INFO L85 PathProgramCache]: Analyzing trace with hash -515124903, now seen corresponding path program 1 times [2022-02-20 18:11:29,588 INFO L126 FreeRefinementEngine]: Executing refinement strategy CAMEL [2022-02-20 18:11:29,588 INFO L338 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [1768076816] [2022-02-20 18:11:29,589 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-02-20 18:11:29,589 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2022-02-20 18:11:29,683 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-02-20 18:11:29,750 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 13 [2022-02-20 18:11:29,753 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-02-20 18:11:29,761 INFO L290 TraceCheckUtils]: 0: Hoare triple {75#true} havoc ~retValue_acc~7;~retValue_acc~7 := ~pumpRunning~0;#res := ~retValue_acc~7; {75#true} is VALID [2022-02-20 18:11:29,762 INFO L290 TraceCheckUtils]: 1: Hoare triple {75#true} assume true; {75#true} is VALID [2022-02-20 18:11:29,762 INFO L284 TraceCheckUtils]: 2: Hoare quadruple {75#true} {76#false} #188#return; {76#false} is VALID [2022-02-20 18:11:29,763 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 24 [2022-02-20 18:11:29,766 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-02-20 18:11:29,785 INFO L290 TraceCheckUtils]: 0: Hoare triple {75#true} havoc ~retValue_acc~7;~retValue_acc~7 := ~pumpRunning~0;#res := ~retValue_acc~7; {75#true} is VALID [2022-02-20 18:11:29,786 INFO L290 TraceCheckUtils]: 1: Hoare triple {75#true} assume true; {75#true} is VALID [2022-02-20 18:11:29,786 INFO L284 TraceCheckUtils]: 2: Hoare quadruple {75#true} {76#false} #190#return; {76#false} is VALID [2022-02-20 18:11:29,787 INFO L290 TraceCheckUtils]: 0: Hoare triple {75#true} assume { :begin_inline_ULTIMATE.init } true;#NULL.base, #NULL.offset := 0, 0;assume 0 == #valid[0];assume 0 < #StackHeapBarrier;call #Ultimate.allocInit(2, 1);call write~init~int(48, 1, 0, 1);call write~init~int(0, 1, 1, 1);call #Ultimate.allocInit(31, 2);call #Ultimate.allocInit(12, 3);call #Ultimate.allocInit(30, 4);call #Ultimate.allocInit(9, 5);call #Ultimate.allocInit(21, 6);call #Ultimate.allocInit(30, 7);call #Ultimate.allocInit(9, 8);call #Ultimate.allocInit(21, 9);call #Ultimate.allocInit(30, 10);call #Ultimate.allocInit(9, 11);call #Ultimate.allocInit(25, 12);call #Ultimate.allocInit(30, 13);call #Ultimate.allocInit(9, 14);call #Ultimate.allocInit(25, 15);call #Ultimate.allocInit(13, 16);call #Ultimate.allocInit(3, 17);call write~init~int(79, 17, 0, 1);call write~init~int(110, 17, 1, 1);call write~init~int(0, 17, 2, 1);call #Ultimate.allocInit(4, 18);call write~init~int(79, 18, 0, 1);call write~init~int(102, 18, 1, 1);call write~init~int(102, 18, 2, 1);call write~init~int(0, 18, 3, 1);call #Ultimate.allocInit(7, 19);call write~init~int(44, 19, 0, 1);call write~init~int(80, 19, 1, 1);call write~init~int(117, 19, 2, 1);call write~init~int(109, 19, 3, 1);call write~init~int(112, 19, 4, 1);call write~init~int(58, 19, 5, 1);call write~init~int(0, 19, 6, 1);call #Ultimate.allocInit(3, 20);call write~init~int(79, 20, 0, 1);call write~init~int(110, 20, 1, 1);call write~init~int(0, 20, 2, 1);call #Ultimate.allocInit(4, 21);call write~init~int(79, 21, 0, 1);call write~init~int(102, 21, 1, 1);call write~init~int(102, 21, 2, 1);call write~init~int(0, 21, 3, 1);call #Ultimate.allocInit(3, 22);call write~init~int(41, 22, 0, 1);call write~init~int(32, 22, 1, 1);call write~init~int(0, 22, 2, 1);call #Ultimate.allocInit(2, 23);call write~init~int(10, 23, 0, 1);call write~init~int(0, 23, 1, 1);call #Ultimate.allocInit(13, 24);call #Ultimate.allocInit(7, 25);call write~init~int(44, 25, 0, 1);call write~init~int(77, 25, 1, 1);call write~init~int(101, 25, 2, 1);call write~init~int(116, 25, 3, 1);call write~init~int(104, 25, 4, 1);call write~init~int(58, 25, 5, 1);call write~init~int(0, 25, 6, 1);call #Ultimate.allocInit(5, 26);call write~init~int(67, 26, 0, 1);call write~init~int(82, 26, 1, 1);call write~init~int(73, 26, 2, 1);call write~init~int(84, 26, 3, 1);call write~init~int(0, 26, 4, 1);call #Ultimate.allocInit(3, 27);call write~init~int(79, 27, 0, 1);call write~init~int(75, 27, 1, 1);call write~init~int(0, 27, 2, 1);call #Ultimate.allocInit(2, 28);call write~init~int(41, 28, 0, 1);call write~init~int(0, 28, 1, 1);~head~0.base, ~head~0.offset := 0, 0;~cleanupTimeShifts~0 := 4;~pumpRunning~0 := 0;~systemActive~0 := 1;~switchedOnBeforeTS~0 := 0;~waterLevel~0 := 1;~methaneLevelCritical~0 := 0; {75#true} is VALID [2022-02-20 18:11:29,787 INFO L290 TraceCheckUtils]: 1: Hoare triple {75#true} assume { :end_inline_ULTIMATE.init } true;assume { :begin_inline_main } true;havoc main_#res#1;havoc main_#t~ret27#1, main_~retValue_acc~3#1, main_~tmp~3#1;havoc main_~retValue_acc~3#1;havoc main_~tmp~3#1;assume { :begin_inline_select_helpers } true; {75#true} is VALID [2022-02-20 18:11:29,788 INFO L290 TraceCheckUtils]: 2: Hoare triple {75#true} assume { :end_inline_select_helpers } true;assume { :begin_inline_select_features } true; {75#true} is VALID [2022-02-20 18:11:29,788 INFO L290 TraceCheckUtils]: 3: Hoare triple {75#true} assume { :end_inline_select_features } true;assume { :begin_inline_valid_product } true;havoc valid_product_#res#1;havoc valid_product_~retValue_acc~5#1;havoc valid_product_~retValue_acc~5#1;valid_product_~retValue_acc~5#1 := 1;valid_product_#res#1 := valid_product_~retValue_acc~5#1; {75#true} is VALID [2022-02-20 18:11:29,788 INFO L290 TraceCheckUtils]: 4: Hoare triple {75#true} main_#t~ret27#1 := valid_product_#res#1;assume { :end_inline_valid_product } true;assume -2147483648 <= main_#t~ret27#1 && main_#t~ret27#1 <= 2147483647;main_~tmp~3#1 := main_#t~ret27#1;havoc main_#t~ret27#1; {75#true} is VALID [2022-02-20 18:11:29,788 INFO L290 TraceCheckUtils]: 5: Hoare triple {75#true} assume 0 != main_~tmp~3#1;assume { :begin_inline_setup } true; {75#true} is VALID [2022-02-20 18:11:29,789 INFO L290 TraceCheckUtils]: 6: Hoare triple {75#true} assume { :end_inline_setup } true;assume { :begin_inline_runTest } true;assume { :begin_inline___utac_acc__Specification5_spec__1 } true;~switchedOnBeforeTS~0 := 0; {75#true} is VALID [2022-02-20 18:11:29,789 INFO L290 TraceCheckUtils]: 7: Hoare triple {75#true} assume { :end_inline___utac_acc__Specification5_spec__1 } true;assume { :begin_inline_test } true;havoc test_#t~nondet38#1, test_#t~nondet39#1, test_#t~nondet40#1, test_#t~nondet41#1, test_~splverifierCounter~0#1, test_~tmp~4#1, test_~tmp___0~0#1, test_~tmp___1~0#1, test_~tmp___2~0#1;havoc test_~splverifierCounter~0#1;havoc test_~tmp~4#1;havoc test_~tmp___0~0#1;havoc test_~tmp___1~0#1;havoc test_~tmp___2~0#1;test_~splverifierCounter~0#1 := 0; {75#true} is VALID [2022-02-20 18:11:29,790 INFO L290 TraceCheckUtils]: 8: Hoare triple {75#true} assume false; {76#false} is VALID [2022-02-20 18:11:29,790 INFO L272 TraceCheckUtils]: 9: Hoare triple {76#false} call cleanup(); {76#false} is VALID [2022-02-20 18:11:29,790 INFO L290 TraceCheckUtils]: 10: Hoare triple {76#false} havoc ~i~0;havoc ~__cil_tmp2~0; {76#false} is VALID [2022-02-20 18:11:29,790 INFO L272 TraceCheckUtils]: 11: Hoare triple {76#false} call timeShift(); {76#false} is VALID [2022-02-20 18:11:29,791 INFO L290 TraceCheckUtils]: 12: Hoare triple {76#false} assume { :begin_inline___utac_acc__Specification5_spec__2 } true;havoc __utac_acc__Specification5_spec__2_#t~ret42#1; {76#false} is VALID [2022-02-20 18:11:29,791 INFO L272 TraceCheckUtils]: 13: Hoare triple {76#false} call __utac_acc__Specification5_spec__2_#t~ret42#1 := isPumpRunning(); {75#true} is VALID [2022-02-20 18:11:29,791 INFO L290 TraceCheckUtils]: 14: Hoare triple {75#true} havoc ~retValue_acc~7;~retValue_acc~7 := ~pumpRunning~0;#res := ~retValue_acc~7; {75#true} is VALID [2022-02-20 18:11:29,791 INFO L290 TraceCheckUtils]: 15: Hoare triple {75#true} assume true; {75#true} is VALID [2022-02-20 18:11:29,792 INFO L284 TraceCheckUtils]: 16: Hoare quadruple {75#true} {76#false} #188#return; {76#false} is VALID [2022-02-20 18:11:29,792 INFO L290 TraceCheckUtils]: 17: Hoare triple {76#false} assume -2147483648 <= __utac_acc__Specification5_spec__2_#t~ret42#1 && __utac_acc__Specification5_spec__2_#t~ret42#1 <= 2147483647;~switchedOnBeforeTS~0 := __utac_acc__Specification5_spec__2_#t~ret42#1;havoc __utac_acc__Specification5_spec__2_#t~ret42#1; {76#false} is VALID [2022-02-20 18:11:29,802 INFO L290 TraceCheckUtils]: 18: Hoare triple {76#false} assume { :end_inline___utac_acc__Specification5_spec__2 } true; {76#false} is VALID [2022-02-20 18:11:29,802 INFO L290 TraceCheckUtils]: 19: Hoare triple {76#false} assume !(0 != ~pumpRunning~0); {76#false} is VALID [2022-02-20 18:11:29,803 INFO L290 TraceCheckUtils]: 20: Hoare triple {76#false} assume !(0 != ~systemActive~0); {76#false} is VALID [2022-02-20 18:11:29,803 INFO L290 TraceCheckUtils]: 21: Hoare triple {76#false} assume { :begin_inline___utac_acc__Specification5_spec__3 } true;havoc __utac_acc__Specification5_spec__3_#t~ret43#1, __utac_acc__Specification5_spec__3_#t~ret44#1, __utac_acc__Specification5_spec__3_~tmp~5#1, __utac_acc__Specification5_spec__3_~tmp___0~1#1;havoc __utac_acc__Specification5_spec__3_~tmp~5#1;havoc __utac_acc__Specification5_spec__3_~tmp___0~1#1;assume { :begin_inline_getWaterLevel } true;havoc getWaterLevel_#res#1;havoc getWaterLevel_~retValue_acc~9#1;havoc getWaterLevel_~retValue_acc~9#1;getWaterLevel_~retValue_acc~9#1 := ~waterLevel~0;getWaterLevel_#res#1 := getWaterLevel_~retValue_acc~9#1; {76#false} is VALID [2022-02-20 18:11:29,803 INFO L290 TraceCheckUtils]: 22: Hoare triple {76#false} __utac_acc__Specification5_spec__3_#t~ret43#1 := getWaterLevel_#res#1;assume { :end_inline_getWaterLevel } true;assume -2147483648 <= __utac_acc__Specification5_spec__3_#t~ret43#1 && __utac_acc__Specification5_spec__3_#t~ret43#1 <= 2147483647;__utac_acc__Specification5_spec__3_~tmp~5#1 := __utac_acc__Specification5_spec__3_#t~ret43#1;havoc __utac_acc__Specification5_spec__3_#t~ret43#1; {76#false} is VALID [2022-02-20 18:11:29,803 INFO L290 TraceCheckUtils]: 23: Hoare triple {76#false} assume 2 != __utac_acc__Specification5_spec__3_~tmp~5#1; {76#false} is VALID [2022-02-20 18:11:29,804 INFO L272 TraceCheckUtils]: 24: Hoare triple {76#false} call __utac_acc__Specification5_spec__3_#t~ret44#1 := isPumpRunning(); {75#true} is VALID [2022-02-20 18:11:29,804 INFO L290 TraceCheckUtils]: 25: Hoare triple {75#true} havoc ~retValue_acc~7;~retValue_acc~7 := ~pumpRunning~0;#res := ~retValue_acc~7; {75#true} is VALID [2022-02-20 18:11:29,804 INFO L290 TraceCheckUtils]: 26: Hoare triple {75#true} assume true; {75#true} is VALID [2022-02-20 18:11:29,804 INFO L284 TraceCheckUtils]: 27: Hoare quadruple {75#true} {76#false} #190#return; {76#false} is VALID [2022-02-20 18:11:29,805 INFO L290 TraceCheckUtils]: 28: Hoare triple {76#false} assume -2147483648 <= __utac_acc__Specification5_spec__3_#t~ret44#1 && __utac_acc__Specification5_spec__3_#t~ret44#1 <= 2147483647;__utac_acc__Specification5_spec__3_~tmp___0~1#1 := __utac_acc__Specification5_spec__3_#t~ret44#1;havoc __utac_acc__Specification5_spec__3_#t~ret44#1; {76#false} is VALID [2022-02-20 18:11:29,814 INFO L290 TraceCheckUtils]: 29: Hoare triple {76#false} assume 0 != __utac_acc__Specification5_spec__3_~tmp___0~1#1; {76#false} is VALID [2022-02-20 18:11:29,815 INFO L290 TraceCheckUtils]: 30: Hoare triple {76#false} assume 0 == ~switchedOnBeforeTS~0;assume { :begin_inline___automaton_fail } true; {76#false} is VALID [2022-02-20 18:11:29,815 INFO L290 TraceCheckUtils]: 31: Hoare triple {76#false} assume !false; {76#false} is VALID [2022-02-20 18:11:29,816 INFO L134 CoverageAnalysis]: Checked inductivity of 3 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 3 trivial. 0 not checked. [2022-02-20 18:11:29,816 INFO L144 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2022-02-20 18:11:29,816 INFO L338 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [1768076816] [2022-02-20 18:11:29,817 INFO L165 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [1768076816] provided 1 perfect and 0 imperfect interpolant sequences [2022-02-20 18:11:29,817 INFO L191 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2022-02-20 18:11:29,817 INFO L204 FreeRefinementEngine]: Number of different interpolants: perfect sequences [2] imperfect sequences [] total 2 [2022-02-20 18:11:29,819 INFO L118 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [1709399843] [2022-02-20 18:11:29,819 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2022-02-20 18:11:29,823 INFO L78 Accepts]: Start accepts. Automaton has has 2 states, 2 states have (on average 12.0) internal successors, (24), 2 states have internal predecessors, (24), 1 states have call successors, (4), 2 states have call predecessors, (4), 1 states have return successors, (2), 1 states have call predecessors, (2), 1 states have call successors, (2) Word has length 32 [2022-02-20 18:11:29,825 INFO L84 Accepts]: Finished accepts. word is accepted. [2022-02-20 18:11:29,828 INFO L86 InductivityCheck]: Starting indutivity check of a Floyd-Hoare automaton with has 2 states, 2 states have (on average 12.0) internal successors, (24), 2 states have internal predecessors, (24), 1 states have call successors, (4), 2 states have call predecessors, (4), 1 states have return successors, (2), 1 states have call predecessors, (2), 1 states have call successors, (2) [2022-02-20 18:11:29,871 INFO L122 InductivityCheck]: Floyd-Hoare automaton has 30 edges. 30 inductive. 0 not inductive. 0 times theorem prover too weak to decide inductivity. [2022-02-20 18:11:29,871 INFO L546 AbstractCegarLoop]: INTERPOLANT automaton has 2 states [2022-02-20 18:11:29,872 INFO L108 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2022-02-20 18:11:29,885 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 2 interpolants. [2022-02-20 18:11:29,886 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=1, Invalid=1, Unknown=0, NotChecked=0, Total=2 [2022-02-20 18:11:29,888 INFO L87 Difference]: Start difference. First operand has 72 states, 57 states have (on average 1.368421052631579) internal successors, (78), 61 states have internal predecessors, (78), 8 states have call successors, (8), 5 states have call predecessors, (8), 5 states have return successors, (8), 8 states have call predecessors, (8), 8 states have call successors, (8) Second operand has 2 states, 2 states have (on average 12.0) internal successors, (24), 2 states have internal predecessors, (24), 1 states have call successors, (4), 2 states have call predecessors, (4), 1 states have return successors, (2), 1 states have call predecessors, (2), 1 states have call successors, (2) [2022-02-20 18:11:29,985 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-02-20 18:11:29,986 INFO L93 Difference]: Finished difference Result 135 states and 182 transitions. [2022-02-20 18:11:29,986 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 2 states. [2022-02-20 18:11:29,986 INFO L78 Accepts]: Start accepts. Automaton has has 2 states, 2 states have (on average 12.0) internal successors, (24), 2 states have internal predecessors, (24), 1 states have call successors, (4), 2 states have call predecessors, (4), 1 states have return successors, (2), 1 states have call predecessors, (2), 1 states have call successors, (2) Word has length 32 [2022-02-20 18:11:29,987 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2022-02-20 18:11:29,988 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 2 states, 2 states have (on average 12.0) internal successors, (24), 2 states have internal predecessors, (24), 1 states have call successors, (4), 2 states have call predecessors, (4), 1 states have return successors, (2), 1 states have call predecessors, (2), 1 states have call successors, (2) [2022-02-20 18:11:30,003 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 2 states to 2 states and 182 transitions. [2022-02-20 18:11:30,009 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 2 states, 2 states have (on average 12.0) internal successors, (24), 2 states have internal predecessors, (24), 1 states have call successors, (4), 2 states have call predecessors, (4), 1 states have return successors, (2), 1 states have call predecessors, (2), 1 states have call successors, (2) [2022-02-20 18:11:30,026 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 2 states to 2 states and 182 transitions. [2022-02-20 18:11:30,033 INFO L86 InductivityCheck]: Starting indutivity check of a Floyd-Hoare automaton with 2 states and 182 transitions. [2022-02-20 18:11:30,242 INFO L122 InductivityCheck]: Floyd-Hoare automaton has 182 edges. 182 inductive. 0 not inductive. 0 times theorem prover too weak to decide inductivity. [2022-02-20 18:11:30,251 INFO L225 Difference]: With dead ends: 135 [2022-02-20 18:11:30,251 INFO L226 Difference]: Without dead ends: 63 [2022-02-20 18:11:30,253 INFO L932 BasicCegarLoop]: 0 DeclaredPredicates, 6 GetRequests, 6 SyntacticMatches, 0 SemanticMatches, 0 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 0 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=1, Invalid=1, Unknown=0, NotChecked=0, Total=2 [2022-02-20 18:11:30,261 INFO L933 BasicCegarLoop]: 88 mSDtfsCounter, 0 mSDsluCounter, 0 mSDsCounter, 0 mSdLazyCounter, 0 mSolverCounterSat, 0 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.0s Time, 0 mProtectedPredicate, 0 mProtectedAction, 0 SdHoareTripleChecker+Valid, 88 SdHoareTripleChecker+Invalid, 0 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 0 IncrementalHoareTripleChecker+Valid, 0 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.0s IncrementalHoareTripleChecker+Time [2022-02-20 18:11:30,262 INFO L934 BasicCegarLoop]: SdHoareTripleChecker [0 Valid, 88 Invalid, 0 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [0 Valid, 0 Invalid, 0 Unknown, 0 Unchecked, 0.0s Time] [2022-02-20 18:11:30,278 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 63 states. [2022-02-20 18:11:30,296 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 63 to 63. [2022-02-20 18:11:30,297 INFO L214 AbstractMinimizeNwa]: Start testing correctness of minimizeSevpa [2022-02-20 18:11:30,298 INFO L82 GeneralOperation]: Start isEquivalent. First operand 63 states. Second operand has 63 states, 50 states have (on average 1.28) internal successors, (64), 53 states have internal predecessors, (64), 8 states have call successors, (8), 5 states have call predecessors, (8), 4 states have return successors, (7), 7 states have call predecessors, (7), 7 states have call successors, (7) [2022-02-20 18:11:30,305 INFO L74 IsIncluded]: Start isIncluded. First operand 63 states. Second operand has 63 states, 50 states have (on average 1.28) internal successors, (64), 53 states have internal predecessors, (64), 8 states have call successors, (8), 5 states have call predecessors, (8), 4 states have return successors, (7), 7 states have call predecessors, (7), 7 states have call successors, (7) [2022-02-20 18:11:30,308 INFO L87 Difference]: Start difference. First operand 63 states. Second operand has 63 states, 50 states have (on average 1.28) internal successors, (64), 53 states have internal predecessors, (64), 8 states have call successors, (8), 5 states have call predecessors, (8), 4 states have return successors, (7), 7 states have call predecessors, (7), 7 states have call successors, (7) [2022-02-20 18:11:30,317 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-02-20 18:11:30,320 INFO L93 Difference]: Finished difference Result 63 states and 79 transitions. [2022-02-20 18:11:30,321 INFO L276 IsEmpty]: Start isEmpty. Operand 63 states and 79 transitions. [2022-02-20 18:11:30,322 INFO L282 IsEmpty]: Finished isEmpty. No accepting run. [2022-02-20 18:11:30,322 INFO L83 IsIncluded]: Finished isIncluded. Language is included [2022-02-20 18:11:30,323 INFO L74 IsIncluded]: Start isIncluded. First operand has 63 states, 50 states have (on average 1.28) internal successors, (64), 53 states have internal predecessors, (64), 8 states have call successors, (8), 5 states have call predecessors, (8), 4 states have return successors, (7), 7 states have call predecessors, (7), 7 states have call successors, (7) Second operand 63 states. [2022-02-20 18:11:30,324 INFO L87 Difference]: Start difference. First operand has 63 states, 50 states have (on average 1.28) internal successors, (64), 53 states have internal predecessors, (64), 8 states have call successors, (8), 5 states have call predecessors, (8), 4 states have return successors, (7), 7 states have call predecessors, (7), 7 states have call successors, (7) Second operand 63 states. [2022-02-20 18:11:30,333 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-02-20 18:11:30,335 INFO L93 Difference]: Finished difference Result 63 states and 79 transitions. [2022-02-20 18:11:30,336 INFO L276 IsEmpty]: Start isEmpty. Operand 63 states and 79 transitions. [2022-02-20 18:11:30,336 INFO L282 IsEmpty]: Finished isEmpty. No accepting run. [2022-02-20 18:11:30,337 INFO L83 IsIncluded]: Finished isIncluded. Language is included [2022-02-20 18:11:30,337 INFO L88 GeneralOperation]: Finished isEquivalent. [2022-02-20 18:11:30,337 INFO L221 AbstractMinimizeNwa]: Finished testing correctness of minimizeSevpa [2022-02-20 18:11:30,337 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 63 states, 50 states have (on average 1.28) internal successors, (64), 53 states have internal predecessors, (64), 8 states have call successors, (8), 5 states have call predecessors, (8), 4 states have return successors, (7), 7 states have call predecessors, (7), 7 states have call successors, (7) [2022-02-20 18:11:30,341 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 63 states to 63 states and 79 transitions. [2022-02-20 18:11:30,342 INFO L78 Accepts]: Start accepts. Automaton has 63 states and 79 transitions. Word has length 32 [2022-02-20 18:11:30,342 INFO L84 Accepts]: Finished accepts. word is rejected. [2022-02-20 18:11:30,342 INFO L470 AbstractCegarLoop]: Abstraction has 63 states and 79 transitions. [2022-02-20 18:11:30,343 INFO L471 AbstractCegarLoop]: INTERPOLANT automaton has has 2 states, 2 states have (on average 12.0) internal successors, (24), 2 states have internal predecessors, (24), 1 states have call successors, (4), 2 states have call predecessors, (4), 1 states have return successors, (2), 1 states have call predecessors, (2), 1 states have call successors, (2) [2022-02-20 18:11:30,343 INFO L276 IsEmpty]: Start isEmpty. Operand 63 states and 79 transitions. [2022-02-20 18:11:30,344 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 34 [2022-02-20 18:11:30,344 INFO L506 BasicCegarLoop]: Found error trace [2022-02-20 18:11:30,344 INFO L514 BasicCegarLoop]: trace histogram [2, 2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-02-20 18:11:30,344 WARN L452 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable0 [2022-02-20 18:11:30,345 INFO L402 AbstractCegarLoop]: === Iteration 2 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2022-02-20 18:11:30,345 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2022-02-20 18:11:30,345 INFO L85 PathProgramCache]: Analyzing trace with hash -1191843792, now seen corresponding path program 1 times [2022-02-20 18:11:30,346 INFO L126 FreeRefinementEngine]: Executing refinement strategy CAMEL [2022-02-20 18:11:30,346 INFO L338 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [869423719] [2022-02-20 18:11:30,346 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-02-20 18:11:30,346 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2022-02-20 18:11:30,371 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-02-20 18:11:30,401 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 14 [2022-02-20 18:11:30,404 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-02-20 18:11:30,410 INFO L290 TraceCheckUtils]: 0: Hoare triple {494#true} havoc ~retValue_acc~7;~retValue_acc~7 := ~pumpRunning~0;#res := ~retValue_acc~7; {494#true} is VALID [2022-02-20 18:11:30,411 INFO L290 TraceCheckUtils]: 1: Hoare triple {494#true} assume true; {494#true} is VALID [2022-02-20 18:11:30,411 INFO L284 TraceCheckUtils]: 2: Hoare quadruple {494#true} {495#false} #188#return; {495#false} is VALID [2022-02-20 18:11:30,411 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 25 [2022-02-20 18:11:30,413 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-02-20 18:11:30,433 INFO L290 TraceCheckUtils]: 0: Hoare triple {494#true} havoc ~retValue_acc~7;~retValue_acc~7 := ~pumpRunning~0;#res := ~retValue_acc~7; {494#true} is VALID [2022-02-20 18:11:30,433 INFO L290 TraceCheckUtils]: 1: Hoare triple {494#true} assume true; {494#true} is VALID [2022-02-20 18:11:30,433 INFO L284 TraceCheckUtils]: 2: Hoare quadruple {494#true} {495#false} #190#return; {495#false} is VALID [2022-02-20 18:11:30,434 INFO L290 TraceCheckUtils]: 0: Hoare triple {494#true} assume { :begin_inline_ULTIMATE.init } true;#NULL.base, #NULL.offset := 0, 0;assume 0 == #valid[0];assume 0 < #StackHeapBarrier;call #Ultimate.allocInit(2, 1);call write~init~int(48, 1, 0, 1);call write~init~int(0, 1, 1, 1);call #Ultimate.allocInit(31, 2);call #Ultimate.allocInit(12, 3);call #Ultimate.allocInit(30, 4);call #Ultimate.allocInit(9, 5);call #Ultimate.allocInit(21, 6);call #Ultimate.allocInit(30, 7);call #Ultimate.allocInit(9, 8);call #Ultimate.allocInit(21, 9);call #Ultimate.allocInit(30, 10);call #Ultimate.allocInit(9, 11);call #Ultimate.allocInit(25, 12);call #Ultimate.allocInit(30, 13);call #Ultimate.allocInit(9, 14);call #Ultimate.allocInit(25, 15);call #Ultimate.allocInit(13, 16);call #Ultimate.allocInit(3, 17);call write~init~int(79, 17, 0, 1);call write~init~int(110, 17, 1, 1);call write~init~int(0, 17, 2, 1);call #Ultimate.allocInit(4, 18);call write~init~int(79, 18, 0, 1);call write~init~int(102, 18, 1, 1);call write~init~int(102, 18, 2, 1);call write~init~int(0, 18, 3, 1);call #Ultimate.allocInit(7, 19);call write~init~int(44, 19, 0, 1);call write~init~int(80, 19, 1, 1);call write~init~int(117, 19, 2, 1);call write~init~int(109, 19, 3, 1);call write~init~int(112, 19, 4, 1);call write~init~int(58, 19, 5, 1);call write~init~int(0, 19, 6, 1);call #Ultimate.allocInit(3, 20);call write~init~int(79, 20, 0, 1);call write~init~int(110, 20, 1, 1);call write~init~int(0, 20, 2, 1);call #Ultimate.allocInit(4, 21);call write~init~int(79, 21, 0, 1);call write~init~int(102, 21, 1, 1);call write~init~int(102, 21, 2, 1);call write~init~int(0, 21, 3, 1);call #Ultimate.allocInit(3, 22);call write~init~int(41, 22, 0, 1);call write~init~int(32, 22, 1, 1);call write~init~int(0, 22, 2, 1);call #Ultimate.allocInit(2, 23);call write~init~int(10, 23, 0, 1);call write~init~int(0, 23, 1, 1);call #Ultimate.allocInit(13, 24);call #Ultimate.allocInit(7, 25);call write~init~int(44, 25, 0, 1);call write~init~int(77, 25, 1, 1);call write~init~int(101, 25, 2, 1);call write~init~int(116, 25, 3, 1);call write~init~int(104, 25, 4, 1);call write~init~int(58, 25, 5, 1);call write~init~int(0, 25, 6, 1);call #Ultimate.allocInit(5, 26);call write~init~int(67, 26, 0, 1);call write~init~int(82, 26, 1, 1);call write~init~int(73, 26, 2, 1);call write~init~int(84, 26, 3, 1);call write~init~int(0, 26, 4, 1);call #Ultimate.allocInit(3, 27);call write~init~int(79, 27, 0, 1);call write~init~int(75, 27, 1, 1);call write~init~int(0, 27, 2, 1);call #Ultimate.allocInit(2, 28);call write~init~int(41, 28, 0, 1);call write~init~int(0, 28, 1, 1);~head~0.base, ~head~0.offset := 0, 0;~cleanupTimeShifts~0 := 4;~pumpRunning~0 := 0;~systemActive~0 := 1;~switchedOnBeforeTS~0 := 0;~waterLevel~0 := 1;~methaneLevelCritical~0 := 0; {494#true} is VALID [2022-02-20 18:11:30,434 INFO L290 TraceCheckUtils]: 1: Hoare triple {494#true} assume { :end_inline_ULTIMATE.init } true;assume { :begin_inline_main } true;havoc main_#res#1;havoc main_#t~ret27#1, main_~retValue_acc~3#1, main_~tmp~3#1;havoc main_~retValue_acc~3#1;havoc main_~tmp~3#1;assume { :begin_inline_select_helpers } true; {494#true} is VALID [2022-02-20 18:11:30,434 INFO L290 TraceCheckUtils]: 2: Hoare triple {494#true} assume { :end_inline_select_helpers } true;assume { :begin_inline_select_features } true; {494#true} is VALID [2022-02-20 18:11:30,434 INFO L290 TraceCheckUtils]: 3: Hoare triple {494#true} assume { :end_inline_select_features } true;assume { :begin_inline_valid_product } true;havoc valid_product_#res#1;havoc valid_product_~retValue_acc~5#1;havoc valid_product_~retValue_acc~5#1;valid_product_~retValue_acc~5#1 := 1;valid_product_#res#1 := valid_product_~retValue_acc~5#1; {494#true} is VALID [2022-02-20 18:11:30,434 INFO L290 TraceCheckUtils]: 4: Hoare triple {494#true} main_#t~ret27#1 := valid_product_#res#1;assume { :end_inline_valid_product } true;assume -2147483648 <= main_#t~ret27#1 && main_#t~ret27#1 <= 2147483647;main_~tmp~3#1 := main_#t~ret27#1;havoc main_#t~ret27#1; {494#true} is VALID [2022-02-20 18:11:30,435 INFO L290 TraceCheckUtils]: 5: Hoare triple {494#true} assume 0 != main_~tmp~3#1;assume { :begin_inline_setup } true; {494#true} is VALID [2022-02-20 18:11:30,435 INFO L290 TraceCheckUtils]: 6: Hoare triple {494#true} assume { :end_inline_setup } true;assume { :begin_inline_runTest } true;assume { :begin_inline___utac_acc__Specification5_spec__1 } true;~switchedOnBeforeTS~0 := 0; {494#true} is VALID [2022-02-20 18:11:30,435 INFO L290 TraceCheckUtils]: 7: Hoare triple {494#true} assume { :end_inline___utac_acc__Specification5_spec__1 } true;assume { :begin_inline_test } true;havoc test_#t~nondet38#1, test_#t~nondet39#1, test_#t~nondet40#1, test_#t~nondet41#1, test_~splverifierCounter~0#1, test_~tmp~4#1, test_~tmp___0~0#1, test_~tmp___1~0#1, test_~tmp___2~0#1;havoc test_~splverifierCounter~0#1;havoc test_~tmp~4#1;havoc test_~tmp___0~0#1;havoc test_~tmp___1~0#1;havoc test_~tmp___2~0#1;test_~splverifierCounter~0#1 := 0; {496#(= |ULTIMATE.start_test_~splverifierCounter~0#1| 0)} is VALID [2022-02-20 18:11:30,436 INFO L290 TraceCheckUtils]: 8: Hoare triple {496#(= |ULTIMATE.start_test_~splverifierCounter~0#1| 0)} assume !false; {496#(= |ULTIMATE.start_test_~splverifierCounter~0#1| 0)} is VALID [2022-02-20 18:11:30,436 INFO L290 TraceCheckUtils]: 9: Hoare triple {496#(= |ULTIMATE.start_test_~splverifierCounter~0#1| 0)} assume !(test_~splverifierCounter~0#1 < 4); {495#false} is VALID [2022-02-20 18:11:30,437 INFO L272 TraceCheckUtils]: 10: Hoare triple {495#false} call cleanup(); {495#false} is VALID [2022-02-20 18:11:30,437 INFO L290 TraceCheckUtils]: 11: Hoare triple {495#false} havoc ~i~0;havoc ~__cil_tmp2~0; {495#false} is VALID [2022-02-20 18:11:30,437 INFO L272 TraceCheckUtils]: 12: Hoare triple {495#false} call timeShift(); {495#false} is VALID [2022-02-20 18:11:30,437 INFO L290 TraceCheckUtils]: 13: Hoare triple {495#false} assume { :begin_inline___utac_acc__Specification5_spec__2 } true;havoc __utac_acc__Specification5_spec__2_#t~ret42#1; {495#false} is VALID [2022-02-20 18:11:30,437 INFO L272 TraceCheckUtils]: 14: Hoare triple {495#false} call __utac_acc__Specification5_spec__2_#t~ret42#1 := isPumpRunning(); {494#true} is VALID [2022-02-20 18:11:30,438 INFO L290 TraceCheckUtils]: 15: Hoare triple {494#true} havoc ~retValue_acc~7;~retValue_acc~7 := ~pumpRunning~0;#res := ~retValue_acc~7; {494#true} is VALID [2022-02-20 18:11:30,438 INFO L290 TraceCheckUtils]: 16: Hoare triple {494#true} assume true; {494#true} is VALID [2022-02-20 18:11:30,438 INFO L284 TraceCheckUtils]: 17: Hoare quadruple {494#true} {495#false} #188#return; {495#false} is VALID [2022-02-20 18:11:30,438 INFO L290 TraceCheckUtils]: 18: Hoare triple {495#false} assume -2147483648 <= __utac_acc__Specification5_spec__2_#t~ret42#1 && __utac_acc__Specification5_spec__2_#t~ret42#1 <= 2147483647;~switchedOnBeforeTS~0 := __utac_acc__Specification5_spec__2_#t~ret42#1;havoc __utac_acc__Specification5_spec__2_#t~ret42#1; {495#false} is VALID [2022-02-20 18:11:30,438 INFO L290 TraceCheckUtils]: 19: Hoare triple {495#false} assume { :end_inline___utac_acc__Specification5_spec__2 } true; {495#false} is VALID [2022-02-20 18:11:30,439 INFO L290 TraceCheckUtils]: 20: Hoare triple {495#false} assume !(0 != ~pumpRunning~0); {495#false} is VALID [2022-02-20 18:11:30,439 INFO L290 TraceCheckUtils]: 21: Hoare triple {495#false} assume !(0 != ~systemActive~0); {495#false} is VALID [2022-02-20 18:11:30,439 INFO L290 TraceCheckUtils]: 22: Hoare triple {495#false} assume { :begin_inline___utac_acc__Specification5_spec__3 } true;havoc __utac_acc__Specification5_spec__3_#t~ret43#1, __utac_acc__Specification5_spec__3_#t~ret44#1, __utac_acc__Specification5_spec__3_~tmp~5#1, __utac_acc__Specification5_spec__3_~tmp___0~1#1;havoc __utac_acc__Specification5_spec__3_~tmp~5#1;havoc __utac_acc__Specification5_spec__3_~tmp___0~1#1;assume { :begin_inline_getWaterLevel } true;havoc getWaterLevel_#res#1;havoc getWaterLevel_~retValue_acc~9#1;havoc getWaterLevel_~retValue_acc~9#1;getWaterLevel_~retValue_acc~9#1 := ~waterLevel~0;getWaterLevel_#res#1 := getWaterLevel_~retValue_acc~9#1; {495#false} is VALID [2022-02-20 18:11:30,439 INFO L290 TraceCheckUtils]: 23: Hoare triple {495#false} __utac_acc__Specification5_spec__3_#t~ret43#1 := getWaterLevel_#res#1;assume { :end_inline_getWaterLevel } true;assume -2147483648 <= __utac_acc__Specification5_spec__3_#t~ret43#1 && __utac_acc__Specification5_spec__3_#t~ret43#1 <= 2147483647;__utac_acc__Specification5_spec__3_~tmp~5#1 := __utac_acc__Specification5_spec__3_#t~ret43#1;havoc __utac_acc__Specification5_spec__3_#t~ret43#1; {495#false} is VALID [2022-02-20 18:11:30,439 INFO L290 TraceCheckUtils]: 24: Hoare triple {495#false} assume 2 != __utac_acc__Specification5_spec__3_~tmp~5#1; {495#false} is VALID [2022-02-20 18:11:30,439 INFO L272 TraceCheckUtils]: 25: Hoare triple {495#false} call __utac_acc__Specification5_spec__3_#t~ret44#1 := isPumpRunning(); {494#true} is VALID [2022-02-20 18:11:30,440 INFO L290 TraceCheckUtils]: 26: Hoare triple {494#true} havoc ~retValue_acc~7;~retValue_acc~7 := ~pumpRunning~0;#res := ~retValue_acc~7; {494#true} is VALID [2022-02-20 18:11:30,440 INFO L290 TraceCheckUtils]: 27: Hoare triple {494#true} assume true; {494#true} is VALID [2022-02-20 18:11:30,440 INFO L284 TraceCheckUtils]: 28: Hoare quadruple {494#true} {495#false} #190#return; {495#false} is VALID [2022-02-20 18:11:30,440 INFO L290 TraceCheckUtils]: 29: Hoare triple {495#false} assume -2147483648 <= __utac_acc__Specification5_spec__3_#t~ret44#1 && __utac_acc__Specification5_spec__3_#t~ret44#1 <= 2147483647;__utac_acc__Specification5_spec__3_~tmp___0~1#1 := __utac_acc__Specification5_spec__3_#t~ret44#1;havoc __utac_acc__Specification5_spec__3_#t~ret44#1; {495#false} is VALID [2022-02-20 18:11:30,440 INFO L290 TraceCheckUtils]: 30: Hoare triple {495#false} assume 0 != __utac_acc__Specification5_spec__3_~tmp___0~1#1; {495#false} is VALID [2022-02-20 18:11:30,441 INFO L290 TraceCheckUtils]: 31: Hoare triple {495#false} assume 0 == ~switchedOnBeforeTS~0;assume { :begin_inline___automaton_fail } true; {495#false} is VALID [2022-02-20 18:11:30,441 INFO L290 TraceCheckUtils]: 32: Hoare triple {495#false} assume !false; {495#false} is VALID [2022-02-20 18:11:30,441 INFO L134 CoverageAnalysis]: Checked inductivity of 3 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 3 trivial. 0 not checked. [2022-02-20 18:11:30,441 INFO L144 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2022-02-20 18:11:30,442 INFO L338 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [869423719] [2022-02-20 18:11:30,442 INFO L165 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [869423719] provided 1 perfect and 0 imperfect interpolant sequences [2022-02-20 18:11:30,442 INFO L191 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2022-02-20 18:11:30,442 INFO L204 FreeRefinementEngine]: Number of different interpolants: perfect sequences [3] imperfect sequences [] total 3 [2022-02-20 18:11:30,442 INFO L118 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [1499596666] [2022-02-20 18:11:30,442 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2022-02-20 18:11:30,443 INFO L78 Accepts]: Start accepts. Automaton has has 3 states, 3 states have (on average 8.333333333333334) internal successors, (25), 3 states have internal predecessors, (25), 1 states have call successors, (4), 2 states have call predecessors, (4), 1 states have return successors, (2), 1 states have call predecessors, (2), 1 states have call successors, (2) Word has length 33 [2022-02-20 18:11:30,444 INFO L84 Accepts]: Finished accepts. word is accepted. [2022-02-20 18:11:30,444 INFO L86 InductivityCheck]: Starting indutivity check of a Floyd-Hoare automaton with has 3 states, 3 states have (on average 8.333333333333334) internal successors, (25), 3 states have internal predecessors, (25), 1 states have call successors, (4), 2 states have call predecessors, (4), 1 states have return successors, (2), 1 states have call predecessors, (2), 1 states have call successors, (2) [2022-02-20 18:11:30,471 INFO L122 InductivityCheck]: Floyd-Hoare automaton has 31 edges. 31 inductive. 0 not inductive. 0 times theorem prover too weak to decide inductivity. [2022-02-20 18:11:30,471 INFO L546 AbstractCegarLoop]: INTERPOLANT automaton has 3 states [2022-02-20 18:11:30,472 INFO L108 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2022-02-20 18:11:30,473 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 3 interpolants. [2022-02-20 18:11:30,473 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=3, Invalid=3, Unknown=0, NotChecked=0, Total=6 [2022-02-20 18:11:30,473 INFO L87 Difference]: Start difference. First operand 63 states and 79 transitions. Second operand has 3 states, 3 states have (on average 8.333333333333334) internal successors, (25), 3 states have internal predecessors, (25), 1 states have call successors, (4), 2 states have call predecessors, (4), 1 states have return successors, (2), 1 states have call predecessors, (2), 1 states have call successors, (2) [2022-02-20 18:11:30,552 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-02-20 18:11:30,552 INFO L93 Difference]: Finished difference Result 87 states and 108 transitions. [2022-02-20 18:11:30,552 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 3 states. [2022-02-20 18:11:30,553 INFO L78 Accepts]: Start accepts. Automaton has has 3 states, 3 states have (on average 8.333333333333334) internal successors, (25), 3 states have internal predecessors, (25), 1 states have call successors, (4), 2 states have call predecessors, (4), 1 states have return successors, (2), 1 states have call predecessors, (2), 1 states have call successors, (2) Word has length 33 [2022-02-20 18:11:30,553 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2022-02-20 18:11:30,553 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 3 states, 3 states have (on average 8.333333333333334) internal successors, (25), 3 states have internal predecessors, (25), 1 states have call successors, (4), 2 states have call predecessors, (4), 1 states have return successors, (2), 1 states have call predecessors, (2), 1 states have call successors, (2) [2022-02-20 18:11:30,555 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 3 states to 3 states and 108 transitions. [2022-02-20 18:11:30,556 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 3 states, 3 states have (on average 8.333333333333334) internal successors, (25), 3 states have internal predecessors, (25), 1 states have call successors, (4), 2 states have call predecessors, (4), 1 states have return successors, (2), 1 states have call predecessors, (2), 1 states have call successors, (2) [2022-02-20 18:11:30,560 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 3 states to 3 states and 108 transitions. [2022-02-20 18:11:30,560 INFO L86 InductivityCheck]: Starting indutivity check of a Floyd-Hoare automaton with 3 states and 108 transitions. [2022-02-20 18:11:30,640 INFO L122 InductivityCheck]: Floyd-Hoare automaton has 108 edges. 108 inductive. 0 not inductive. 0 times theorem prover too weak to decide inductivity. [2022-02-20 18:11:30,643 INFO L225 Difference]: With dead ends: 87 [2022-02-20 18:11:30,643 INFO L226 Difference]: Without dead ends: 54 [2022-02-20 18:11:30,646 INFO L932 BasicCegarLoop]: 0 DeclaredPredicates, 7 GetRequests, 6 SyntacticMatches, 0 SemanticMatches, 1 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 0 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=3, Invalid=3, Unknown=0, NotChecked=0, Total=6 [2022-02-20 18:11:30,649 INFO L933 BasicCegarLoop]: 66 mSDtfsCounter, 17 mSDsluCounter, 45 mSDsCounter, 0 mSdLazyCounter, 1 mSolverCounterSat, 0 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.0s Time, 0 mProtectedPredicate, 0 mProtectedAction, 20 SdHoareTripleChecker+Valid, 111 SdHoareTripleChecker+Invalid, 1 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 0 IncrementalHoareTripleChecker+Valid, 1 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.0s IncrementalHoareTripleChecker+Time [2022-02-20 18:11:30,649 INFO L934 BasicCegarLoop]: SdHoareTripleChecker [20 Valid, 111 Invalid, 1 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [0 Valid, 1 Invalid, 0 Unknown, 0 Unchecked, 0.0s Time] [2022-02-20 18:11:30,650 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 54 states. [2022-02-20 18:11:30,653 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 54 to 54. [2022-02-20 18:11:30,653 INFO L214 AbstractMinimizeNwa]: Start testing correctness of minimizeSevpa [2022-02-20 18:11:30,654 INFO L82 GeneralOperation]: Start isEquivalent. First operand 54 states. Second operand has 54 states, 44 states have (on average 1.2954545454545454) internal successors, (57), 47 states have internal predecessors, (57), 5 states have call successors, (5), 4 states have call predecessors, (5), 4 states have return successors, (5), 5 states have call predecessors, (5), 5 states have call successors, (5) [2022-02-20 18:11:30,654 INFO L74 IsIncluded]: Start isIncluded. First operand 54 states. Second operand has 54 states, 44 states have (on average 1.2954545454545454) internal successors, (57), 47 states have internal predecessors, (57), 5 states have call successors, (5), 4 states have call predecessors, (5), 4 states have return successors, (5), 5 states have call predecessors, (5), 5 states have call successors, (5) [2022-02-20 18:11:30,654 INFO L87 Difference]: Start difference. First operand 54 states. Second operand has 54 states, 44 states have (on average 1.2954545454545454) internal successors, (57), 47 states have internal predecessors, (57), 5 states have call successors, (5), 4 states have call predecessors, (5), 4 states have return successors, (5), 5 states have call predecessors, (5), 5 states have call successors, (5) [2022-02-20 18:11:30,656 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-02-20 18:11:30,656 INFO L93 Difference]: Finished difference Result 54 states and 67 transitions. [2022-02-20 18:11:30,657 INFO L276 IsEmpty]: Start isEmpty. Operand 54 states and 67 transitions. [2022-02-20 18:11:30,657 INFO L282 IsEmpty]: Finished isEmpty. No accepting run. [2022-02-20 18:11:30,657 INFO L83 IsIncluded]: Finished isIncluded. Language is included [2022-02-20 18:11:30,657 INFO L74 IsIncluded]: Start isIncluded. First operand has 54 states, 44 states have (on average 1.2954545454545454) internal successors, (57), 47 states have internal predecessors, (57), 5 states have call successors, (5), 4 states have call predecessors, (5), 4 states have return successors, (5), 5 states have call predecessors, (5), 5 states have call successors, (5) Second operand 54 states. [2022-02-20 18:11:30,658 INFO L87 Difference]: Start difference. First operand has 54 states, 44 states have (on average 1.2954545454545454) internal successors, (57), 47 states have internal predecessors, (57), 5 states have call successors, (5), 4 states have call predecessors, (5), 4 states have return successors, (5), 5 states have call predecessors, (5), 5 states have call successors, (5) Second operand 54 states. [2022-02-20 18:11:30,659 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-02-20 18:11:30,659 INFO L93 Difference]: Finished difference Result 54 states and 67 transitions. [2022-02-20 18:11:30,660 INFO L276 IsEmpty]: Start isEmpty. Operand 54 states and 67 transitions. [2022-02-20 18:11:30,660 INFO L282 IsEmpty]: Finished isEmpty. No accepting run. [2022-02-20 18:11:30,660 INFO L83 IsIncluded]: Finished isIncluded. Language is included [2022-02-20 18:11:30,660 INFO L88 GeneralOperation]: Finished isEquivalent. [2022-02-20 18:11:30,660 INFO L221 AbstractMinimizeNwa]: Finished testing correctness of minimizeSevpa [2022-02-20 18:11:30,661 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 54 states, 44 states have (on average 1.2954545454545454) internal successors, (57), 47 states have internal predecessors, (57), 5 states have call successors, (5), 4 states have call predecessors, (5), 4 states have return successors, (5), 5 states have call predecessors, (5), 5 states have call successors, (5) [2022-02-20 18:11:30,662 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 54 states to 54 states and 67 transitions. [2022-02-20 18:11:30,662 INFO L78 Accepts]: Start accepts. Automaton has 54 states and 67 transitions. Word has length 33 [2022-02-20 18:11:30,662 INFO L84 Accepts]: Finished accepts. word is rejected. [2022-02-20 18:11:30,663 INFO L470 AbstractCegarLoop]: Abstraction has 54 states and 67 transitions. [2022-02-20 18:11:30,663 INFO L471 AbstractCegarLoop]: INTERPOLANT automaton has has 3 states, 3 states have (on average 8.333333333333334) internal successors, (25), 3 states have internal predecessors, (25), 1 states have call successors, (4), 2 states have call predecessors, (4), 1 states have return successors, (2), 1 states have call predecessors, (2), 1 states have call successors, (2) [2022-02-20 18:11:30,663 INFO L276 IsEmpty]: Start isEmpty. Operand 54 states and 67 transitions. [2022-02-20 18:11:30,664 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 38 [2022-02-20 18:11:30,664 INFO L506 BasicCegarLoop]: Found error trace [2022-02-20 18:11:30,664 INFO L514 BasicCegarLoop]: trace histogram [2, 2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-02-20 18:11:30,664 WARN L452 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable1 [2022-02-20 18:11:30,664 INFO L402 AbstractCegarLoop]: === Iteration 3 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2022-02-20 18:11:30,665 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2022-02-20 18:11:30,665 INFO L85 PathProgramCache]: Analyzing trace with hash -948437565, now seen corresponding path program 1 times [2022-02-20 18:11:30,665 INFO L126 FreeRefinementEngine]: Executing refinement strategy CAMEL [2022-02-20 18:11:30,665 INFO L338 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [819781654] [2022-02-20 18:11:30,665 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-02-20 18:11:30,666 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2022-02-20 18:11:30,690 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-02-20 18:11:30,735 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 18 [2022-02-20 18:11:30,749 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-02-20 18:11:30,752 INFO L290 TraceCheckUtils]: 0: Hoare triple {812#true} havoc ~retValue_acc~7;~retValue_acc~7 := ~pumpRunning~0;#res := ~retValue_acc~7; {812#true} is VALID [2022-02-20 18:11:30,752 INFO L290 TraceCheckUtils]: 1: Hoare triple {812#true} assume true; {812#true} is VALID [2022-02-20 18:11:30,753 INFO L284 TraceCheckUtils]: 2: Hoare quadruple {812#true} {817#(not (= 0 ~systemActive~0))} #188#return; {817#(not (= 0 ~systemActive~0))} is VALID [2022-02-20 18:11:30,754 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 29 [2022-02-20 18:11:30,755 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-02-20 18:11:30,758 INFO L290 TraceCheckUtils]: 0: Hoare triple {812#true} havoc ~retValue_acc~7;~retValue_acc~7 := ~pumpRunning~0;#res := ~retValue_acc~7; {812#true} is VALID [2022-02-20 18:11:30,759 INFO L290 TraceCheckUtils]: 1: Hoare triple {812#true} assume true; {812#true} is VALID [2022-02-20 18:11:30,759 INFO L284 TraceCheckUtils]: 2: Hoare quadruple {812#true} {813#false} #190#return; {813#false} is VALID [2022-02-20 18:11:30,761 INFO L290 TraceCheckUtils]: 0: Hoare triple {812#true} assume { :begin_inline_ULTIMATE.init } true;#NULL.base, #NULL.offset := 0, 0;assume 0 == #valid[0];assume 0 < #StackHeapBarrier;call #Ultimate.allocInit(2, 1);call write~init~int(48, 1, 0, 1);call write~init~int(0, 1, 1, 1);call #Ultimate.allocInit(31, 2);call #Ultimate.allocInit(12, 3);call #Ultimate.allocInit(30, 4);call #Ultimate.allocInit(9, 5);call #Ultimate.allocInit(21, 6);call #Ultimate.allocInit(30, 7);call #Ultimate.allocInit(9, 8);call #Ultimate.allocInit(21, 9);call #Ultimate.allocInit(30, 10);call #Ultimate.allocInit(9, 11);call #Ultimate.allocInit(25, 12);call #Ultimate.allocInit(30, 13);call #Ultimate.allocInit(9, 14);call #Ultimate.allocInit(25, 15);call #Ultimate.allocInit(13, 16);call #Ultimate.allocInit(3, 17);call write~init~int(79, 17, 0, 1);call write~init~int(110, 17, 1, 1);call write~init~int(0, 17, 2, 1);call #Ultimate.allocInit(4, 18);call write~init~int(79, 18, 0, 1);call write~init~int(102, 18, 1, 1);call write~init~int(102, 18, 2, 1);call write~init~int(0, 18, 3, 1);call #Ultimate.allocInit(7, 19);call write~init~int(44, 19, 0, 1);call write~init~int(80, 19, 1, 1);call write~init~int(117, 19, 2, 1);call write~init~int(109, 19, 3, 1);call write~init~int(112, 19, 4, 1);call write~init~int(58, 19, 5, 1);call write~init~int(0, 19, 6, 1);call #Ultimate.allocInit(3, 20);call write~init~int(79, 20, 0, 1);call write~init~int(110, 20, 1, 1);call write~init~int(0, 20, 2, 1);call #Ultimate.allocInit(4, 21);call write~init~int(79, 21, 0, 1);call write~init~int(102, 21, 1, 1);call write~init~int(102, 21, 2, 1);call write~init~int(0, 21, 3, 1);call #Ultimate.allocInit(3, 22);call write~init~int(41, 22, 0, 1);call write~init~int(32, 22, 1, 1);call write~init~int(0, 22, 2, 1);call #Ultimate.allocInit(2, 23);call write~init~int(10, 23, 0, 1);call write~init~int(0, 23, 1, 1);call #Ultimate.allocInit(13, 24);call #Ultimate.allocInit(7, 25);call write~init~int(44, 25, 0, 1);call write~init~int(77, 25, 1, 1);call write~init~int(101, 25, 2, 1);call write~init~int(116, 25, 3, 1);call write~init~int(104, 25, 4, 1);call write~init~int(58, 25, 5, 1);call write~init~int(0, 25, 6, 1);call #Ultimate.allocInit(5, 26);call write~init~int(67, 26, 0, 1);call write~init~int(82, 26, 1, 1);call write~init~int(73, 26, 2, 1);call write~init~int(84, 26, 3, 1);call write~init~int(0, 26, 4, 1);call #Ultimate.allocInit(3, 27);call write~init~int(79, 27, 0, 1);call write~init~int(75, 27, 1, 1);call write~init~int(0, 27, 2, 1);call #Ultimate.allocInit(2, 28);call write~init~int(41, 28, 0, 1);call write~init~int(0, 28, 1, 1);~head~0.base, ~head~0.offset := 0, 0;~cleanupTimeShifts~0 := 4;~pumpRunning~0 := 0;~systemActive~0 := 1;~switchedOnBeforeTS~0 := 0;~waterLevel~0 := 1;~methaneLevelCritical~0 := 0; {814#(= 1 ~systemActive~0)} is VALID [2022-02-20 18:11:30,762 INFO L290 TraceCheckUtils]: 1: Hoare triple {814#(= 1 ~systemActive~0)} assume { :end_inline_ULTIMATE.init } true;assume { :begin_inline_main } true;havoc main_#res#1;havoc main_#t~ret27#1, main_~retValue_acc~3#1, main_~tmp~3#1;havoc main_~retValue_acc~3#1;havoc main_~tmp~3#1;assume { :begin_inline_select_helpers } true; {814#(= 1 ~systemActive~0)} is VALID [2022-02-20 18:11:30,762 INFO L290 TraceCheckUtils]: 2: Hoare triple {814#(= 1 ~systemActive~0)} assume { :end_inline_select_helpers } true;assume { :begin_inline_select_features } true; {814#(= 1 ~systemActive~0)} is VALID [2022-02-20 18:11:30,763 INFO L290 TraceCheckUtils]: 3: Hoare triple {814#(= 1 ~systemActive~0)} assume { :end_inline_select_features } true;assume { :begin_inline_valid_product } true;havoc valid_product_#res#1;havoc valid_product_~retValue_acc~5#1;havoc valid_product_~retValue_acc~5#1;valid_product_~retValue_acc~5#1 := 1;valid_product_#res#1 := valid_product_~retValue_acc~5#1; {815#(= |ULTIMATE.start_valid_product_#res#1| ~systemActive~0)} is VALID [2022-02-20 18:11:30,763 INFO L290 TraceCheckUtils]: 4: Hoare triple {815#(= |ULTIMATE.start_valid_product_#res#1| ~systemActive~0)} main_#t~ret27#1 := valid_product_#res#1;assume { :end_inline_valid_product } true;assume -2147483648 <= main_#t~ret27#1 && main_#t~ret27#1 <= 2147483647;main_~tmp~3#1 := main_#t~ret27#1;havoc main_#t~ret27#1; {816#(= |ULTIMATE.start_main_~tmp~3#1| ~systemActive~0)} is VALID [2022-02-20 18:11:30,764 INFO L290 TraceCheckUtils]: 5: Hoare triple {816#(= |ULTIMATE.start_main_~tmp~3#1| ~systemActive~0)} assume 0 != main_~tmp~3#1;assume { :begin_inline_setup } true; {817#(not (= 0 ~systemActive~0))} is VALID [2022-02-20 18:11:30,768 INFO L290 TraceCheckUtils]: 6: Hoare triple {817#(not (= 0 ~systemActive~0))} assume { :end_inline_setup } true;assume { :begin_inline_runTest } true;assume { :begin_inline___utac_acc__Specification5_spec__1 } true;~switchedOnBeforeTS~0 := 0; {817#(not (= 0 ~systemActive~0))} is VALID [2022-02-20 18:11:30,769 INFO L290 TraceCheckUtils]: 7: Hoare triple {817#(not (= 0 ~systemActive~0))} assume { :end_inline___utac_acc__Specification5_spec__1 } true;assume { :begin_inline_test } true;havoc test_#t~nondet38#1, test_#t~nondet39#1, test_#t~nondet40#1, test_#t~nondet41#1, test_~splverifierCounter~0#1, test_~tmp~4#1, test_~tmp___0~0#1, test_~tmp___1~0#1, test_~tmp___2~0#1;havoc test_~splverifierCounter~0#1;havoc test_~tmp~4#1;havoc test_~tmp___0~0#1;havoc test_~tmp___1~0#1;havoc test_~tmp___2~0#1;test_~splverifierCounter~0#1 := 0; {817#(not (= 0 ~systemActive~0))} is VALID [2022-02-20 18:11:30,769 INFO L290 TraceCheckUtils]: 8: Hoare triple {817#(not (= 0 ~systemActive~0))} assume !false; {817#(not (= 0 ~systemActive~0))} is VALID [2022-02-20 18:11:30,770 INFO L290 TraceCheckUtils]: 9: Hoare triple {817#(not (= 0 ~systemActive~0))} assume test_~splverifierCounter~0#1 < 4; {817#(not (= 0 ~systemActive~0))} is VALID [2022-02-20 18:11:30,770 INFO L290 TraceCheckUtils]: 10: Hoare triple {817#(not (= 0 ~systemActive~0))} assume -2147483648 <= test_#t~nondet38#1 && test_#t~nondet38#1 <= 2147483647;test_~tmp~4#1 := test_#t~nondet38#1;havoc test_#t~nondet38#1; {817#(not (= 0 ~systemActive~0))} is VALID [2022-02-20 18:11:30,771 INFO L290 TraceCheckUtils]: 11: Hoare triple {817#(not (= 0 ~systemActive~0))} assume !(0 != test_~tmp~4#1); {817#(not (= 0 ~systemActive~0))} is VALID [2022-02-20 18:11:30,771 INFO L290 TraceCheckUtils]: 12: Hoare triple {817#(not (= 0 ~systemActive~0))} assume -2147483648 <= test_#t~nondet39#1 && test_#t~nondet39#1 <= 2147483647;test_~tmp___0~0#1 := test_#t~nondet39#1;havoc test_#t~nondet39#1; {817#(not (= 0 ~systemActive~0))} is VALID [2022-02-20 18:11:30,772 INFO L290 TraceCheckUtils]: 13: Hoare triple {817#(not (= 0 ~systemActive~0))} assume !(0 != test_~tmp___0~0#1); {817#(not (= 0 ~systemActive~0))} is VALID [2022-02-20 18:11:30,772 INFO L290 TraceCheckUtils]: 14: Hoare triple {817#(not (= 0 ~systemActive~0))} assume -2147483648 <= test_#t~nondet40#1 && test_#t~nondet40#1 <= 2147483647;test_~tmp___2~0#1 := test_#t~nondet40#1;havoc test_#t~nondet40#1; {817#(not (= 0 ~systemActive~0))} is VALID [2022-02-20 18:11:30,773 INFO L290 TraceCheckUtils]: 15: Hoare triple {817#(not (= 0 ~systemActive~0))} assume 0 != test_~tmp___2~0#1; {817#(not (= 0 ~systemActive~0))} is VALID [2022-02-20 18:11:30,773 INFO L272 TraceCheckUtils]: 16: Hoare triple {817#(not (= 0 ~systemActive~0))} call timeShift(); {817#(not (= 0 ~systemActive~0))} is VALID [2022-02-20 18:11:30,774 INFO L290 TraceCheckUtils]: 17: Hoare triple {817#(not (= 0 ~systemActive~0))} assume { :begin_inline___utac_acc__Specification5_spec__2 } true;havoc __utac_acc__Specification5_spec__2_#t~ret42#1; {817#(not (= 0 ~systemActive~0))} is VALID [2022-02-20 18:11:30,774 INFO L272 TraceCheckUtils]: 18: Hoare triple {817#(not (= 0 ~systemActive~0))} call __utac_acc__Specification5_spec__2_#t~ret42#1 := isPumpRunning(); {812#true} is VALID [2022-02-20 18:11:30,774 INFO L290 TraceCheckUtils]: 19: Hoare triple {812#true} havoc ~retValue_acc~7;~retValue_acc~7 := ~pumpRunning~0;#res := ~retValue_acc~7; {812#true} is VALID [2022-02-20 18:11:30,774 INFO L290 TraceCheckUtils]: 20: Hoare triple {812#true} assume true; {812#true} is VALID [2022-02-20 18:11:30,775 INFO L284 TraceCheckUtils]: 21: Hoare quadruple {812#true} {817#(not (= 0 ~systemActive~0))} #188#return; {817#(not (= 0 ~systemActive~0))} is VALID [2022-02-20 18:11:30,775 INFO L290 TraceCheckUtils]: 22: Hoare triple {817#(not (= 0 ~systemActive~0))} assume -2147483648 <= __utac_acc__Specification5_spec__2_#t~ret42#1 && __utac_acc__Specification5_spec__2_#t~ret42#1 <= 2147483647;~switchedOnBeforeTS~0 := __utac_acc__Specification5_spec__2_#t~ret42#1;havoc __utac_acc__Specification5_spec__2_#t~ret42#1; {817#(not (= 0 ~systemActive~0))} is VALID [2022-02-20 18:11:30,784 INFO L290 TraceCheckUtils]: 23: Hoare triple {817#(not (= 0 ~systemActive~0))} assume { :end_inline___utac_acc__Specification5_spec__2 } true; {817#(not (= 0 ~systemActive~0))} is VALID [2022-02-20 18:11:30,785 INFO L290 TraceCheckUtils]: 24: Hoare triple {817#(not (= 0 ~systemActive~0))} assume !(0 != ~pumpRunning~0); {817#(not (= 0 ~systemActive~0))} is VALID [2022-02-20 18:11:30,785 INFO L290 TraceCheckUtils]: 25: Hoare triple {817#(not (= 0 ~systemActive~0))} assume !(0 != ~systemActive~0); {813#false} is VALID [2022-02-20 18:11:30,786 INFO L290 TraceCheckUtils]: 26: Hoare triple {813#false} assume { :begin_inline___utac_acc__Specification5_spec__3 } true;havoc __utac_acc__Specification5_spec__3_#t~ret43#1, __utac_acc__Specification5_spec__3_#t~ret44#1, __utac_acc__Specification5_spec__3_~tmp~5#1, __utac_acc__Specification5_spec__3_~tmp___0~1#1;havoc __utac_acc__Specification5_spec__3_~tmp~5#1;havoc __utac_acc__Specification5_spec__3_~tmp___0~1#1;assume { :begin_inline_getWaterLevel } true;havoc getWaterLevel_#res#1;havoc getWaterLevel_~retValue_acc~9#1;havoc getWaterLevel_~retValue_acc~9#1;getWaterLevel_~retValue_acc~9#1 := ~waterLevel~0;getWaterLevel_#res#1 := getWaterLevel_~retValue_acc~9#1; {813#false} is VALID [2022-02-20 18:11:30,786 INFO L290 TraceCheckUtils]: 27: Hoare triple {813#false} __utac_acc__Specification5_spec__3_#t~ret43#1 := getWaterLevel_#res#1;assume { :end_inline_getWaterLevel } true;assume -2147483648 <= __utac_acc__Specification5_spec__3_#t~ret43#1 && __utac_acc__Specification5_spec__3_#t~ret43#1 <= 2147483647;__utac_acc__Specification5_spec__3_~tmp~5#1 := __utac_acc__Specification5_spec__3_#t~ret43#1;havoc __utac_acc__Specification5_spec__3_#t~ret43#1; {813#false} is VALID [2022-02-20 18:11:30,786 INFO L290 TraceCheckUtils]: 28: Hoare triple {813#false} assume 2 != __utac_acc__Specification5_spec__3_~tmp~5#1; {813#false} is VALID [2022-02-20 18:11:30,786 INFO L272 TraceCheckUtils]: 29: Hoare triple {813#false} call __utac_acc__Specification5_spec__3_#t~ret44#1 := isPumpRunning(); {812#true} is VALID [2022-02-20 18:11:30,786 INFO L290 TraceCheckUtils]: 30: Hoare triple {812#true} havoc ~retValue_acc~7;~retValue_acc~7 := ~pumpRunning~0;#res := ~retValue_acc~7; {812#true} is VALID [2022-02-20 18:11:30,786 INFO L290 TraceCheckUtils]: 31: Hoare triple {812#true} assume true; {812#true} is VALID [2022-02-20 18:11:30,786 INFO L284 TraceCheckUtils]: 32: Hoare quadruple {812#true} {813#false} #190#return; {813#false} is VALID [2022-02-20 18:11:30,787 INFO L290 TraceCheckUtils]: 33: Hoare triple {813#false} assume -2147483648 <= __utac_acc__Specification5_spec__3_#t~ret44#1 && __utac_acc__Specification5_spec__3_#t~ret44#1 <= 2147483647;__utac_acc__Specification5_spec__3_~tmp___0~1#1 := __utac_acc__Specification5_spec__3_#t~ret44#1;havoc __utac_acc__Specification5_spec__3_#t~ret44#1; {813#false} is VALID [2022-02-20 18:11:30,787 INFO L290 TraceCheckUtils]: 34: Hoare triple {813#false} assume 0 != __utac_acc__Specification5_spec__3_~tmp___0~1#1; {813#false} is VALID [2022-02-20 18:11:30,787 INFO L290 TraceCheckUtils]: 35: Hoare triple {813#false} assume 0 == ~switchedOnBeforeTS~0;assume { :begin_inline___automaton_fail } true; {813#false} is VALID [2022-02-20 18:11:30,787 INFO L290 TraceCheckUtils]: 36: Hoare triple {813#false} assume !false; {813#false} is VALID [2022-02-20 18:11:30,788 INFO L134 CoverageAnalysis]: Checked inductivity of 3 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 3 trivial. 0 not checked. [2022-02-20 18:11:30,788 INFO L144 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2022-02-20 18:11:30,788 INFO L338 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [819781654] [2022-02-20 18:11:30,788 INFO L165 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [819781654] provided 1 perfect and 0 imperfect interpolant sequences [2022-02-20 18:11:30,788 INFO L191 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2022-02-20 18:11:30,788 INFO L204 FreeRefinementEngine]: Number of different interpolants: perfect sequences [6] imperfect sequences [] total 6 [2022-02-20 18:11:30,788 INFO L118 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [781548963] [2022-02-20 18:11:30,788 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2022-02-20 18:11:30,789 INFO L78 Accepts]: Start accepts. Automaton has has 6 states, 6 states have (on average 5.0) internal successors, (30), 6 states have internal predecessors, (30), 2 states have call successors, (3), 2 states have call predecessors, (3), 1 states have return successors, (2), 2 states have call predecessors, (2), 2 states have call successors, (2) Word has length 37 [2022-02-20 18:11:30,789 INFO L84 Accepts]: Finished accepts. word is accepted. [2022-02-20 18:11:30,789 INFO L86 InductivityCheck]: Starting indutivity check of a Floyd-Hoare automaton with has 6 states, 6 states have (on average 5.0) internal successors, (30), 6 states have internal predecessors, (30), 2 states have call successors, (3), 2 states have call predecessors, (3), 1 states have return successors, (2), 2 states have call predecessors, (2), 2 states have call successors, (2) [2022-02-20 18:11:30,825 INFO L122 InductivityCheck]: Floyd-Hoare automaton has 35 edges. 35 inductive. 0 not inductive. 0 times theorem prover too weak to decide inductivity. [2022-02-20 18:11:30,825 INFO L546 AbstractCegarLoop]: INTERPOLANT automaton has 6 states [2022-02-20 18:11:30,826 INFO L108 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2022-02-20 18:11:30,826 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 6 interpolants. [2022-02-20 18:11:30,826 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=10, Invalid=20, Unknown=0, NotChecked=0, Total=30 [2022-02-20 18:11:30,827 INFO L87 Difference]: Start difference. First operand 54 states and 67 transitions. Second operand has 6 states, 6 states have (on average 5.0) internal successors, (30), 6 states have internal predecessors, (30), 2 states have call successors, (3), 2 states have call predecessors, (3), 1 states have return successors, (2), 2 states have call predecessors, (2), 2 states have call successors, (2) [2022-02-20 18:11:31,280 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-02-20 18:11:31,281 INFO L93 Difference]: Finished difference Result 189 states and 244 transitions. [2022-02-20 18:11:31,281 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 6 states. [2022-02-20 18:11:31,281 INFO L78 Accepts]: Start accepts. Automaton has has 6 states, 6 states have (on average 5.0) internal successors, (30), 6 states have internal predecessors, (30), 2 states have call successors, (3), 2 states have call predecessors, (3), 1 states have return successors, (2), 2 states have call predecessors, (2), 2 states have call successors, (2) Word has length 37 [2022-02-20 18:11:31,281 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2022-02-20 18:11:31,282 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 6 states, 6 states have (on average 5.0) internal successors, (30), 6 states have internal predecessors, (30), 2 states have call successors, (3), 2 states have call predecessors, (3), 1 states have return successors, (2), 2 states have call predecessors, (2), 2 states have call successors, (2) [2022-02-20 18:11:31,287 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 6 states to 6 states and 244 transitions. [2022-02-20 18:11:31,287 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 6 states, 6 states have (on average 5.0) internal successors, (30), 6 states have internal predecessors, (30), 2 states have call successors, (3), 2 states have call predecessors, (3), 1 states have return successors, (2), 2 states have call predecessors, (2), 2 states have call successors, (2) [2022-02-20 18:11:31,292 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 6 states to 6 states and 244 transitions. [2022-02-20 18:11:31,292 INFO L86 InductivityCheck]: Starting indutivity check of a Floyd-Hoare automaton with 6 states and 244 transitions. [2022-02-20 18:11:31,478 INFO L122 InductivityCheck]: Floyd-Hoare automaton has 244 edges. 244 inductive. 0 not inductive. 0 times theorem prover too weak to decide inductivity. [2022-02-20 18:11:31,482 INFO L225 Difference]: With dead ends: 189 [2022-02-20 18:11:31,483 INFO L226 Difference]: Without dead ends: 143 [2022-02-20 18:11:31,483 INFO L932 BasicCegarLoop]: 0 DeclaredPredicates, 11 GetRequests, 5 SyntacticMatches, 0 SemanticMatches, 6 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 0 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=22, Invalid=34, Unknown=0, NotChecked=0, Total=56 [2022-02-20 18:11:31,484 INFO L933 BasicCegarLoop]: 78 mSDtfsCounter, 171 mSDsluCounter, 250 mSDsCounter, 0 mSdLazyCounter, 56 mSolverCounterSat, 19 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.1s Time, 0 mProtectedPredicate, 0 mProtectedAction, 171 SdHoareTripleChecker+Valid, 328 SdHoareTripleChecker+Invalid, 75 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 19 IncrementalHoareTripleChecker+Valid, 56 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.1s IncrementalHoareTripleChecker+Time [2022-02-20 18:11:31,484 INFO L934 BasicCegarLoop]: SdHoareTripleChecker [171 Valid, 328 Invalid, 75 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [19 Valid, 56 Invalid, 0 Unknown, 0 Unchecked, 0.1s Time] [2022-02-20 18:11:31,485 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 143 states. [2022-02-20 18:11:31,496 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 143 to 133. [2022-02-20 18:11:31,497 INFO L214 AbstractMinimizeNwa]: Start testing correctness of minimizeSevpa [2022-02-20 18:11:31,497 INFO L82 GeneralOperation]: Start isEquivalent. First operand 143 states. Second operand has 133 states, 105 states have (on average 1.3333333333333333) internal successors, (140), 112 states have internal predecessors, (140), 15 states have call successors, (15), 12 states have call predecessors, (15), 12 states have return successors, (16), 15 states have call predecessors, (16), 15 states have call successors, (16) [2022-02-20 18:11:31,498 INFO L74 IsIncluded]: Start isIncluded. First operand 143 states. Second operand has 133 states, 105 states have (on average 1.3333333333333333) internal successors, (140), 112 states have internal predecessors, (140), 15 states have call successors, (15), 12 states have call predecessors, (15), 12 states have return successors, (16), 15 states have call predecessors, (16), 15 states have call successors, (16) [2022-02-20 18:11:31,498 INFO L87 Difference]: Start difference. First operand 143 states. Second operand has 133 states, 105 states have (on average 1.3333333333333333) internal successors, (140), 112 states have internal predecessors, (140), 15 states have call successors, (15), 12 states have call predecessors, (15), 12 states have return successors, (16), 15 states have call predecessors, (16), 15 states have call successors, (16) [2022-02-20 18:11:31,504 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-02-20 18:11:31,504 INFO L93 Difference]: Finished difference Result 143 states and 181 transitions. [2022-02-20 18:11:31,504 INFO L276 IsEmpty]: Start isEmpty. Operand 143 states and 181 transitions. [2022-02-20 18:11:31,505 INFO L282 IsEmpty]: Finished isEmpty. No accepting run. [2022-02-20 18:11:31,505 INFO L83 IsIncluded]: Finished isIncluded. Language is included [2022-02-20 18:11:31,506 INFO L74 IsIncluded]: Start isIncluded. First operand has 133 states, 105 states have (on average 1.3333333333333333) internal successors, (140), 112 states have internal predecessors, (140), 15 states have call successors, (15), 12 states have call predecessors, (15), 12 states have return successors, (16), 15 states have call predecessors, (16), 15 states have call successors, (16) Second operand 143 states. [2022-02-20 18:11:31,507 INFO L87 Difference]: Start difference. First operand has 133 states, 105 states have (on average 1.3333333333333333) internal successors, (140), 112 states have internal predecessors, (140), 15 states have call successors, (15), 12 states have call predecessors, (15), 12 states have return successors, (16), 15 states have call predecessors, (16), 15 states have call successors, (16) Second operand 143 states. [2022-02-20 18:11:31,512 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-02-20 18:11:31,512 INFO L93 Difference]: Finished difference Result 143 states and 181 transitions. [2022-02-20 18:11:31,512 INFO L276 IsEmpty]: Start isEmpty. Operand 143 states and 181 transitions. [2022-02-20 18:11:31,513 INFO L282 IsEmpty]: Finished isEmpty. No accepting run. [2022-02-20 18:11:31,513 INFO L83 IsIncluded]: Finished isIncluded. Language is included [2022-02-20 18:11:31,513 INFO L88 GeneralOperation]: Finished isEquivalent. [2022-02-20 18:11:31,513 INFO L221 AbstractMinimizeNwa]: Finished testing correctness of minimizeSevpa [2022-02-20 18:11:31,514 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 133 states, 105 states have (on average 1.3333333333333333) internal successors, (140), 112 states have internal predecessors, (140), 15 states have call successors, (15), 12 states have call predecessors, (15), 12 states have return successors, (16), 15 states have call predecessors, (16), 15 states have call successors, (16) [2022-02-20 18:11:31,518 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 133 states to 133 states and 171 transitions. [2022-02-20 18:11:31,518 INFO L78 Accepts]: Start accepts. Automaton has 133 states and 171 transitions. Word has length 37 [2022-02-20 18:11:31,519 INFO L84 Accepts]: Finished accepts. word is rejected. [2022-02-20 18:11:31,519 INFO L470 AbstractCegarLoop]: Abstraction has 133 states and 171 transitions. [2022-02-20 18:11:31,519 INFO L471 AbstractCegarLoop]: INTERPOLANT automaton has has 6 states, 6 states have (on average 5.0) internal successors, (30), 6 states have internal predecessors, (30), 2 states have call successors, (3), 2 states have call predecessors, (3), 1 states have return successors, (2), 2 states have call predecessors, (2), 2 states have call successors, (2) [2022-02-20 18:11:31,519 INFO L276 IsEmpty]: Start isEmpty. Operand 133 states and 171 transitions. [2022-02-20 18:11:31,520 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 39 [2022-02-20 18:11:31,520 INFO L506 BasicCegarLoop]: Found error trace [2022-02-20 18:11:31,520 INFO L514 BasicCegarLoop]: trace histogram [2, 2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-02-20 18:11:31,520 WARN L452 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable2 [2022-02-20 18:11:31,521 INFO L402 AbstractCegarLoop]: === Iteration 4 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2022-02-20 18:11:31,521 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2022-02-20 18:11:31,521 INFO L85 PathProgramCache]: Analyzing trace with hash -739007729, now seen corresponding path program 1 times [2022-02-20 18:11:31,521 INFO L126 FreeRefinementEngine]: Executing refinement strategy CAMEL [2022-02-20 18:11:31,521 INFO L338 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [1281780061] [2022-02-20 18:11:31,522 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-02-20 18:11:31,522 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2022-02-20 18:11:31,549 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-02-20 18:11:31,592 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 18 [2022-02-20 18:11:31,595 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-02-20 18:11:31,598 INFO L290 TraceCheckUtils]: 0: Hoare triple {1559#true} havoc ~retValue_acc~7;~retValue_acc~7 := ~pumpRunning~0;#res := ~retValue_acc~7; {1559#true} is VALID [2022-02-20 18:11:31,598 INFO L290 TraceCheckUtils]: 1: Hoare triple {1559#true} assume true; {1559#true} is VALID [2022-02-20 18:11:31,599 INFO L284 TraceCheckUtils]: 2: Hoare quadruple {1559#true} {1561#(= ~pumpRunning~0 0)} #188#return; {1561#(= ~pumpRunning~0 0)} is VALID [2022-02-20 18:11:31,599 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 30 [2022-02-20 18:11:31,606 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-02-20 18:11:31,615 INFO L290 TraceCheckUtils]: 0: Hoare triple {1559#true} havoc ~retValue_acc~7;~retValue_acc~7 := ~pumpRunning~0;#res := ~retValue_acc~7; {1570#(= ~pumpRunning~0 |isPumpRunning_#res|)} is VALID [2022-02-20 18:11:31,616 INFO L290 TraceCheckUtils]: 1: Hoare triple {1570#(= ~pumpRunning~0 |isPumpRunning_#res|)} assume true; {1570#(= ~pumpRunning~0 |isPumpRunning_#res|)} is VALID [2022-02-20 18:11:31,616 INFO L284 TraceCheckUtils]: 2: Hoare quadruple {1570#(= ~pumpRunning~0 |isPumpRunning_#res|)} {1561#(= ~pumpRunning~0 0)} #190#return; {1568#(= 0 |timeShift___utac_acc__Specification5_spec__3_#t~ret44#1|)} is VALID [2022-02-20 18:11:31,617 INFO L290 TraceCheckUtils]: 0: Hoare triple {1559#true} assume { :begin_inline_ULTIMATE.init } true;#NULL.base, #NULL.offset := 0, 0;assume 0 == #valid[0];assume 0 < #StackHeapBarrier;call #Ultimate.allocInit(2, 1);call write~init~int(48, 1, 0, 1);call write~init~int(0, 1, 1, 1);call #Ultimate.allocInit(31, 2);call #Ultimate.allocInit(12, 3);call #Ultimate.allocInit(30, 4);call #Ultimate.allocInit(9, 5);call #Ultimate.allocInit(21, 6);call #Ultimate.allocInit(30, 7);call #Ultimate.allocInit(9, 8);call #Ultimate.allocInit(21, 9);call #Ultimate.allocInit(30, 10);call #Ultimate.allocInit(9, 11);call #Ultimate.allocInit(25, 12);call #Ultimate.allocInit(30, 13);call #Ultimate.allocInit(9, 14);call #Ultimate.allocInit(25, 15);call #Ultimate.allocInit(13, 16);call #Ultimate.allocInit(3, 17);call write~init~int(79, 17, 0, 1);call write~init~int(110, 17, 1, 1);call write~init~int(0, 17, 2, 1);call #Ultimate.allocInit(4, 18);call write~init~int(79, 18, 0, 1);call write~init~int(102, 18, 1, 1);call write~init~int(102, 18, 2, 1);call write~init~int(0, 18, 3, 1);call #Ultimate.allocInit(7, 19);call write~init~int(44, 19, 0, 1);call write~init~int(80, 19, 1, 1);call write~init~int(117, 19, 2, 1);call write~init~int(109, 19, 3, 1);call write~init~int(112, 19, 4, 1);call write~init~int(58, 19, 5, 1);call write~init~int(0, 19, 6, 1);call #Ultimate.allocInit(3, 20);call write~init~int(79, 20, 0, 1);call write~init~int(110, 20, 1, 1);call write~init~int(0, 20, 2, 1);call #Ultimate.allocInit(4, 21);call write~init~int(79, 21, 0, 1);call write~init~int(102, 21, 1, 1);call write~init~int(102, 21, 2, 1);call write~init~int(0, 21, 3, 1);call #Ultimate.allocInit(3, 22);call write~init~int(41, 22, 0, 1);call write~init~int(32, 22, 1, 1);call write~init~int(0, 22, 2, 1);call #Ultimate.allocInit(2, 23);call write~init~int(10, 23, 0, 1);call write~init~int(0, 23, 1, 1);call #Ultimate.allocInit(13, 24);call #Ultimate.allocInit(7, 25);call write~init~int(44, 25, 0, 1);call write~init~int(77, 25, 1, 1);call write~init~int(101, 25, 2, 1);call write~init~int(116, 25, 3, 1);call write~init~int(104, 25, 4, 1);call write~init~int(58, 25, 5, 1);call write~init~int(0, 25, 6, 1);call #Ultimate.allocInit(5, 26);call write~init~int(67, 26, 0, 1);call write~init~int(82, 26, 1, 1);call write~init~int(73, 26, 2, 1);call write~init~int(84, 26, 3, 1);call write~init~int(0, 26, 4, 1);call #Ultimate.allocInit(3, 27);call write~init~int(79, 27, 0, 1);call write~init~int(75, 27, 1, 1);call write~init~int(0, 27, 2, 1);call #Ultimate.allocInit(2, 28);call write~init~int(41, 28, 0, 1);call write~init~int(0, 28, 1, 1);~head~0.base, ~head~0.offset := 0, 0;~cleanupTimeShifts~0 := 4;~pumpRunning~0 := 0;~systemActive~0 := 1;~switchedOnBeforeTS~0 := 0;~waterLevel~0 := 1;~methaneLevelCritical~0 := 0; {1561#(= ~pumpRunning~0 0)} is VALID [2022-02-20 18:11:31,617 INFO L290 TraceCheckUtils]: 1: Hoare triple {1561#(= ~pumpRunning~0 0)} assume { :end_inline_ULTIMATE.init } true;assume { :begin_inline_main } true;havoc main_#res#1;havoc main_#t~ret27#1, main_~retValue_acc~3#1, main_~tmp~3#1;havoc main_~retValue_acc~3#1;havoc main_~tmp~3#1;assume { :begin_inline_select_helpers } true; {1561#(= ~pumpRunning~0 0)} is VALID [2022-02-20 18:11:31,618 INFO L290 TraceCheckUtils]: 2: Hoare triple {1561#(= ~pumpRunning~0 0)} assume { :end_inline_select_helpers } true;assume { :begin_inline_select_features } true; {1561#(= ~pumpRunning~0 0)} is VALID [2022-02-20 18:11:31,618 INFO L290 TraceCheckUtils]: 3: Hoare triple {1561#(= ~pumpRunning~0 0)} assume { :end_inline_select_features } true;assume { :begin_inline_valid_product } true;havoc valid_product_#res#1;havoc valid_product_~retValue_acc~5#1;havoc valid_product_~retValue_acc~5#1;valid_product_~retValue_acc~5#1 := 1;valid_product_#res#1 := valid_product_~retValue_acc~5#1; {1561#(= ~pumpRunning~0 0)} is VALID [2022-02-20 18:11:31,618 INFO L290 TraceCheckUtils]: 4: Hoare triple {1561#(= ~pumpRunning~0 0)} main_#t~ret27#1 := valid_product_#res#1;assume { :end_inline_valid_product } true;assume -2147483648 <= main_#t~ret27#1 && main_#t~ret27#1 <= 2147483647;main_~tmp~3#1 := main_#t~ret27#1;havoc main_#t~ret27#1; {1561#(= ~pumpRunning~0 0)} is VALID [2022-02-20 18:11:31,619 INFO L290 TraceCheckUtils]: 5: Hoare triple {1561#(= ~pumpRunning~0 0)} assume 0 != main_~tmp~3#1;assume { :begin_inline_setup } true; {1561#(= ~pumpRunning~0 0)} is VALID [2022-02-20 18:11:31,619 INFO L290 TraceCheckUtils]: 6: Hoare triple {1561#(= ~pumpRunning~0 0)} assume { :end_inline_setup } true;assume { :begin_inline_runTest } true;assume { :begin_inline___utac_acc__Specification5_spec__1 } true;~switchedOnBeforeTS~0 := 0; {1561#(= ~pumpRunning~0 0)} is VALID [2022-02-20 18:11:31,620 INFO L290 TraceCheckUtils]: 7: Hoare triple {1561#(= ~pumpRunning~0 0)} assume { :end_inline___utac_acc__Specification5_spec__1 } true;assume { :begin_inline_test } true;havoc test_#t~nondet38#1, test_#t~nondet39#1, test_#t~nondet40#1, test_#t~nondet41#1, test_~splverifierCounter~0#1, test_~tmp~4#1, test_~tmp___0~0#1, test_~tmp___1~0#1, test_~tmp___2~0#1;havoc test_~splverifierCounter~0#1;havoc test_~tmp~4#1;havoc test_~tmp___0~0#1;havoc test_~tmp___1~0#1;havoc test_~tmp___2~0#1;test_~splverifierCounter~0#1 := 0; {1561#(= ~pumpRunning~0 0)} is VALID [2022-02-20 18:11:31,620 INFO L290 TraceCheckUtils]: 8: Hoare triple {1561#(= ~pumpRunning~0 0)} assume !false; {1561#(= ~pumpRunning~0 0)} is VALID [2022-02-20 18:11:31,620 INFO L290 TraceCheckUtils]: 9: Hoare triple {1561#(= ~pumpRunning~0 0)} assume test_~splverifierCounter~0#1 < 4; {1561#(= ~pumpRunning~0 0)} is VALID [2022-02-20 18:11:31,621 INFO L290 TraceCheckUtils]: 10: Hoare triple {1561#(= ~pumpRunning~0 0)} assume -2147483648 <= test_#t~nondet38#1 && test_#t~nondet38#1 <= 2147483647;test_~tmp~4#1 := test_#t~nondet38#1;havoc test_#t~nondet38#1; {1561#(= ~pumpRunning~0 0)} is VALID [2022-02-20 18:11:31,621 INFO L290 TraceCheckUtils]: 11: Hoare triple {1561#(= ~pumpRunning~0 0)} assume !(0 != test_~tmp~4#1); {1561#(= ~pumpRunning~0 0)} is VALID [2022-02-20 18:11:31,622 INFO L290 TraceCheckUtils]: 12: Hoare triple {1561#(= ~pumpRunning~0 0)} assume -2147483648 <= test_#t~nondet39#1 && test_#t~nondet39#1 <= 2147483647;test_~tmp___0~0#1 := test_#t~nondet39#1;havoc test_#t~nondet39#1; {1561#(= ~pumpRunning~0 0)} is VALID [2022-02-20 18:11:31,622 INFO L290 TraceCheckUtils]: 13: Hoare triple {1561#(= ~pumpRunning~0 0)} assume !(0 != test_~tmp___0~0#1); {1561#(= ~pumpRunning~0 0)} is VALID [2022-02-20 18:11:31,622 INFO L290 TraceCheckUtils]: 14: Hoare triple {1561#(= ~pumpRunning~0 0)} assume -2147483648 <= test_#t~nondet40#1 && test_#t~nondet40#1 <= 2147483647;test_~tmp___2~0#1 := test_#t~nondet40#1;havoc test_#t~nondet40#1; {1561#(= ~pumpRunning~0 0)} is VALID [2022-02-20 18:11:31,623 INFO L290 TraceCheckUtils]: 15: Hoare triple {1561#(= ~pumpRunning~0 0)} assume 0 != test_~tmp___2~0#1; {1561#(= ~pumpRunning~0 0)} is VALID [2022-02-20 18:11:31,623 INFO L272 TraceCheckUtils]: 16: Hoare triple {1561#(= ~pumpRunning~0 0)} call timeShift(); {1561#(= ~pumpRunning~0 0)} is VALID [2022-02-20 18:11:31,624 INFO L290 TraceCheckUtils]: 17: Hoare triple {1561#(= ~pumpRunning~0 0)} assume { :begin_inline___utac_acc__Specification5_spec__2 } true;havoc __utac_acc__Specification5_spec__2_#t~ret42#1; {1561#(= ~pumpRunning~0 0)} is VALID [2022-02-20 18:11:31,624 INFO L272 TraceCheckUtils]: 18: Hoare triple {1561#(= ~pumpRunning~0 0)} call __utac_acc__Specification5_spec__2_#t~ret42#1 := isPumpRunning(); {1559#true} is VALID [2022-02-20 18:11:31,624 INFO L290 TraceCheckUtils]: 19: Hoare triple {1559#true} havoc ~retValue_acc~7;~retValue_acc~7 := ~pumpRunning~0;#res := ~retValue_acc~7; {1559#true} is VALID [2022-02-20 18:11:31,624 INFO L290 TraceCheckUtils]: 20: Hoare triple {1559#true} assume true; {1559#true} is VALID [2022-02-20 18:11:31,625 INFO L284 TraceCheckUtils]: 21: Hoare quadruple {1559#true} {1561#(= ~pumpRunning~0 0)} #188#return; {1561#(= ~pumpRunning~0 0)} is VALID [2022-02-20 18:11:31,625 INFO L290 TraceCheckUtils]: 22: Hoare triple {1561#(= ~pumpRunning~0 0)} assume -2147483648 <= __utac_acc__Specification5_spec__2_#t~ret42#1 && __utac_acc__Specification5_spec__2_#t~ret42#1 <= 2147483647;~switchedOnBeforeTS~0 := __utac_acc__Specification5_spec__2_#t~ret42#1;havoc __utac_acc__Specification5_spec__2_#t~ret42#1; {1561#(= ~pumpRunning~0 0)} is VALID [2022-02-20 18:11:31,625 INFO L290 TraceCheckUtils]: 23: Hoare triple {1561#(= ~pumpRunning~0 0)} assume { :end_inline___utac_acc__Specification5_spec__2 } true; {1561#(= ~pumpRunning~0 0)} is VALID [2022-02-20 18:11:31,626 INFO L290 TraceCheckUtils]: 24: Hoare triple {1561#(= ~pumpRunning~0 0)} assume !(0 != ~pumpRunning~0); {1561#(= ~pumpRunning~0 0)} is VALID [2022-02-20 18:11:31,626 INFO L290 TraceCheckUtils]: 25: Hoare triple {1561#(= ~pumpRunning~0 0)} assume 0 != ~systemActive~0;assume { :begin_inline_processEnvironment } true; {1561#(= ~pumpRunning~0 0)} is VALID [2022-02-20 18:11:31,626 INFO L290 TraceCheckUtils]: 26: Hoare triple {1561#(= ~pumpRunning~0 0)} assume { :end_inline_processEnvironment } true; {1561#(= ~pumpRunning~0 0)} is VALID [2022-02-20 18:11:31,627 INFO L290 TraceCheckUtils]: 27: Hoare triple {1561#(= ~pumpRunning~0 0)} assume { :begin_inline___utac_acc__Specification5_spec__3 } true;havoc __utac_acc__Specification5_spec__3_#t~ret43#1, __utac_acc__Specification5_spec__3_#t~ret44#1, __utac_acc__Specification5_spec__3_~tmp~5#1, __utac_acc__Specification5_spec__3_~tmp___0~1#1;havoc __utac_acc__Specification5_spec__3_~tmp~5#1;havoc __utac_acc__Specification5_spec__3_~tmp___0~1#1;assume { :begin_inline_getWaterLevel } true;havoc getWaterLevel_#res#1;havoc getWaterLevel_~retValue_acc~9#1;havoc getWaterLevel_~retValue_acc~9#1;getWaterLevel_~retValue_acc~9#1 := ~waterLevel~0;getWaterLevel_#res#1 := getWaterLevel_~retValue_acc~9#1; {1561#(= ~pumpRunning~0 0)} is VALID [2022-02-20 18:11:31,627 INFO L290 TraceCheckUtils]: 28: Hoare triple {1561#(= ~pumpRunning~0 0)} __utac_acc__Specification5_spec__3_#t~ret43#1 := getWaterLevel_#res#1;assume { :end_inline_getWaterLevel } true;assume -2147483648 <= __utac_acc__Specification5_spec__3_#t~ret43#1 && __utac_acc__Specification5_spec__3_#t~ret43#1 <= 2147483647;__utac_acc__Specification5_spec__3_~tmp~5#1 := __utac_acc__Specification5_spec__3_#t~ret43#1;havoc __utac_acc__Specification5_spec__3_#t~ret43#1; {1561#(= ~pumpRunning~0 0)} is VALID [2022-02-20 18:11:31,628 INFO L290 TraceCheckUtils]: 29: Hoare triple {1561#(= ~pumpRunning~0 0)} assume 2 != __utac_acc__Specification5_spec__3_~tmp~5#1; {1561#(= ~pumpRunning~0 0)} is VALID [2022-02-20 18:11:31,628 INFO L272 TraceCheckUtils]: 30: Hoare triple {1561#(= ~pumpRunning~0 0)} call __utac_acc__Specification5_spec__3_#t~ret44#1 := isPumpRunning(); {1559#true} is VALID [2022-02-20 18:11:31,628 INFO L290 TraceCheckUtils]: 31: Hoare triple {1559#true} havoc ~retValue_acc~7;~retValue_acc~7 := ~pumpRunning~0;#res := ~retValue_acc~7; {1570#(= ~pumpRunning~0 |isPumpRunning_#res|)} is VALID [2022-02-20 18:11:31,629 INFO L290 TraceCheckUtils]: 32: Hoare triple {1570#(= ~pumpRunning~0 |isPumpRunning_#res|)} assume true; {1570#(= ~pumpRunning~0 |isPumpRunning_#res|)} is VALID [2022-02-20 18:11:31,629 INFO L284 TraceCheckUtils]: 33: Hoare quadruple {1570#(= ~pumpRunning~0 |isPumpRunning_#res|)} {1561#(= ~pumpRunning~0 0)} #190#return; {1568#(= 0 |timeShift___utac_acc__Specification5_spec__3_#t~ret44#1|)} is VALID [2022-02-20 18:11:31,630 INFO L290 TraceCheckUtils]: 34: Hoare triple {1568#(= 0 |timeShift___utac_acc__Specification5_spec__3_#t~ret44#1|)} assume -2147483648 <= __utac_acc__Specification5_spec__3_#t~ret44#1 && __utac_acc__Specification5_spec__3_#t~ret44#1 <= 2147483647;__utac_acc__Specification5_spec__3_~tmp___0~1#1 := __utac_acc__Specification5_spec__3_#t~ret44#1;havoc __utac_acc__Specification5_spec__3_#t~ret44#1; {1569#(= |timeShift___utac_acc__Specification5_spec__3_~tmp___0~1#1| 0)} is VALID [2022-02-20 18:11:31,630 INFO L290 TraceCheckUtils]: 35: Hoare triple {1569#(= |timeShift___utac_acc__Specification5_spec__3_~tmp___0~1#1| 0)} assume 0 != __utac_acc__Specification5_spec__3_~tmp___0~1#1; {1560#false} is VALID [2022-02-20 18:11:31,630 INFO L290 TraceCheckUtils]: 36: Hoare triple {1560#false} assume 0 == ~switchedOnBeforeTS~0;assume { :begin_inline___automaton_fail } true; {1560#false} is VALID [2022-02-20 18:11:31,630 INFO L290 TraceCheckUtils]: 37: Hoare triple {1560#false} assume !false; {1560#false} is VALID [2022-02-20 18:11:31,631 INFO L134 CoverageAnalysis]: Checked inductivity of 3 backedges. 2 proven. 0 refuted. 0 times theorem prover too weak. 1 trivial. 0 not checked. [2022-02-20 18:11:31,631 INFO L144 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2022-02-20 18:11:31,631 INFO L338 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [1281780061] [2022-02-20 18:11:31,631 INFO L165 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [1281780061] provided 1 perfect and 0 imperfect interpolant sequences [2022-02-20 18:11:31,631 INFO L191 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2022-02-20 18:11:31,631 INFO L204 FreeRefinementEngine]: Number of different interpolants: perfect sequences [6] imperfect sequences [] total 6 [2022-02-20 18:11:31,632 INFO L118 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [1496876819] [2022-02-20 18:11:31,632 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2022-02-20 18:11:31,632 INFO L78 Accepts]: Start accepts. Automaton has has 6 states, 6 states have (on average 5.5) internal successors, (33), 5 states have internal predecessors, (33), 1 states have call successors, (3), 2 states have call predecessors, (3), 2 states have return successors, (2), 2 states have call predecessors, (2), 1 states have call successors, (2) Word has length 38 [2022-02-20 18:11:31,632 INFO L84 Accepts]: Finished accepts. word is accepted. [2022-02-20 18:11:31,633 INFO L86 InductivityCheck]: Starting indutivity check of a Floyd-Hoare automaton with has 6 states, 6 states have (on average 5.5) internal successors, (33), 5 states have internal predecessors, (33), 1 states have call successors, (3), 2 states have call predecessors, (3), 2 states have return successors, (2), 2 states have call predecessors, (2), 1 states have call successors, (2) [2022-02-20 18:11:31,659 INFO L122 InductivityCheck]: Floyd-Hoare automaton has 38 edges. 38 inductive. 0 not inductive. 0 times theorem prover too weak to decide inductivity. [2022-02-20 18:11:31,659 INFO L546 AbstractCegarLoop]: INTERPOLANT automaton has 6 states [2022-02-20 18:11:31,659 INFO L108 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2022-02-20 18:11:31,660 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 6 interpolants. [2022-02-20 18:11:31,660 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=9, Invalid=21, Unknown=0, NotChecked=0, Total=30 [2022-02-20 18:11:31,660 INFO L87 Difference]: Start difference. First operand 133 states and 171 transitions. Second operand has 6 states, 6 states have (on average 5.5) internal successors, (33), 5 states have internal predecessors, (33), 1 states have call successors, (3), 2 states have call predecessors, (3), 2 states have return successors, (2), 2 states have call predecessors, (2), 1 states have call successors, (2) [2022-02-20 18:11:31,847 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-02-20 18:11:31,847 INFO L93 Difference]: Finished difference Result 255 states and 331 transitions. [2022-02-20 18:11:31,847 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 6 states. [2022-02-20 18:11:31,847 INFO L78 Accepts]: Start accepts. Automaton has has 6 states, 6 states have (on average 5.5) internal successors, (33), 5 states have internal predecessors, (33), 1 states have call successors, (3), 2 states have call predecessors, (3), 2 states have return successors, (2), 2 states have call predecessors, (2), 1 states have call successors, (2) Word has length 38 [2022-02-20 18:11:31,848 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2022-02-20 18:11:31,848 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 6 states, 6 states have (on average 5.5) internal successors, (33), 5 states have internal predecessors, (33), 1 states have call successors, (3), 2 states have call predecessors, (3), 2 states have return successors, (2), 2 states have call predecessors, (2), 1 states have call successors, (2) [2022-02-20 18:11:31,851 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 6 states to 6 states and 123 transitions. [2022-02-20 18:11:31,851 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 6 states, 6 states have (on average 5.5) internal successors, (33), 5 states have internal predecessors, (33), 1 states have call successors, (3), 2 states have call predecessors, (3), 2 states have return successors, (2), 2 states have call predecessors, (2), 1 states have call successors, (2) [2022-02-20 18:11:31,853 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 6 states to 6 states and 123 transitions. [2022-02-20 18:11:31,853 INFO L86 InductivityCheck]: Starting indutivity check of a Floyd-Hoare automaton with 6 states and 123 transitions. [2022-02-20 18:11:31,944 INFO L122 InductivityCheck]: Floyd-Hoare automaton has 123 edges. 123 inductive. 0 not inductive. 0 times theorem prover too weak to decide inductivity. [2022-02-20 18:11:31,944 INFO L225 Difference]: With dead ends: 255 [2022-02-20 18:11:31,945 INFO L226 Difference]: Without dead ends: 0 [2022-02-20 18:11:31,946 INFO L932 BasicCegarLoop]: 0 DeclaredPredicates, 11 GetRequests, 4 SyntacticMatches, 0 SemanticMatches, 7 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 3 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=21, Invalid=51, Unknown=0, NotChecked=0, Total=72 [2022-02-20 18:11:31,947 INFO L933 BasicCegarLoop]: 55 mSDtfsCounter, 31 mSDsluCounter, 147 mSDsCounter, 0 mSdLazyCounter, 31 mSolverCounterSat, 3 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.0s Time, 0 mProtectedPredicate, 0 mProtectedAction, 32 SdHoareTripleChecker+Valid, 202 SdHoareTripleChecker+Invalid, 34 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 3 IncrementalHoareTripleChecker+Valid, 31 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.0s IncrementalHoareTripleChecker+Time [2022-02-20 18:11:31,950 INFO L934 BasicCegarLoop]: SdHoareTripleChecker [32 Valid, 202 Invalid, 34 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [3 Valid, 31 Invalid, 0 Unknown, 0 Unchecked, 0.0s Time] [2022-02-20 18:11:31,951 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 0 states. [2022-02-20 18:11:31,951 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 0 to 0. [2022-02-20 18:11:31,951 INFO L214 AbstractMinimizeNwa]: Start testing correctness of minimizeSevpa [2022-02-20 18:11:31,951 INFO L82 GeneralOperation]: Start isEquivalent. First operand 0 states. Second operand has 0 states, 0 states have (on average 0.0) internal successors, (0), 0 states have internal predecessors, (0), 0 states have call successors, (0), 0 states have call predecessors, (0), 0 states have return successors, (0), 0 states have call predecessors, (0), 0 states have call successors, (0) [2022-02-20 18:11:31,952 INFO L74 IsIncluded]: Start isIncluded. First operand 0 states. Second operand has 0 states, 0 states have (on average 0.0) internal successors, (0), 0 states have internal predecessors, (0), 0 states have call successors, (0), 0 states have call predecessors, (0), 0 states have return successors, (0), 0 states have call predecessors, (0), 0 states have call successors, (0) [2022-02-20 18:11:31,952 INFO L87 Difference]: Start difference. First operand 0 states. Second operand has 0 states, 0 states have (on average 0.0) internal successors, (0), 0 states have internal predecessors, (0), 0 states have call successors, (0), 0 states have call predecessors, (0), 0 states have return successors, (0), 0 states have call predecessors, (0), 0 states have call successors, (0) [2022-02-20 18:11:31,952 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-02-20 18:11:31,952 INFO L93 Difference]: Finished difference Result 0 states and 0 transitions. [2022-02-20 18:11:31,952 INFO L276 IsEmpty]: Start isEmpty. Operand 0 states and 0 transitions. [2022-02-20 18:11:31,952 INFO L282 IsEmpty]: Finished isEmpty. No accepting run. [2022-02-20 18:11:31,952 INFO L83 IsIncluded]: Finished isIncluded. Language is included [2022-02-20 18:11:31,952 INFO L74 IsIncluded]: Start isIncluded. First operand has 0 states, 0 states have (on average 0.0) internal successors, (0), 0 states have internal predecessors, (0), 0 states have call successors, (0), 0 states have call predecessors, (0), 0 states have return successors, (0), 0 states have call predecessors, (0), 0 states have call successors, (0) Second operand 0 states. [2022-02-20 18:11:31,952 INFO L87 Difference]: Start difference. First operand has 0 states, 0 states have (on average 0.0) internal successors, (0), 0 states have internal predecessors, (0), 0 states have call successors, (0), 0 states have call predecessors, (0), 0 states have return successors, (0), 0 states have call predecessors, (0), 0 states have call successors, (0) Second operand 0 states. [2022-02-20 18:11:31,952 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-02-20 18:11:31,953 INFO L93 Difference]: Finished difference Result 0 states and 0 transitions. [2022-02-20 18:11:31,953 INFO L276 IsEmpty]: Start isEmpty. Operand 0 states and 0 transitions. [2022-02-20 18:11:31,953 INFO L282 IsEmpty]: Finished isEmpty. No accepting run. [2022-02-20 18:11:31,953 INFO L83 IsIncluded]: Finished isIncluded. Language is included [2022-02-20 18:11:31,953 INFO L88 GeneralOperation]: Finished isEquivalent. [2022-02-20 18:11:31,953 INFO L221 AbstractMinimizeNwa]: Finished testing correctness of minimizeSevpa [2022-02-20 18:11:31,953 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 0 states, 0 states have (on average 0.0) internal successors, (0), 0 states have internal predecessors, (0), 0 states have call successors, (0), 0 states have call predecessors, (0), 0 states have return successors, (0), 0 states have call predecessors, (0), 0 states have call successors, (0) [2022-02-20 18:11:31,953 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 0 states to 0 states and 0 transitions. [2022-02-20 18:11:31,953 INFO L78 Accepts]: Start accepts. Automaton has 0 states and 0 transitions. Word has length 38 [2022-02-20 18:11:31,953 INFO L84 Accepts]: Finished accepts. word is rejected. [2022-02-20 18:11:31,954 INFO L470 AbstractCegarLoop]: Abstraction has 0 states and 0 transitions. [2022-02-20 18:11:31,954 INFO L471 AbstractCegarLoop]: INTERPOLANT automaton has has 6 states, 6 states have (on average 5.5) internal successors, (33), 5 states have internal predecessors, (33), 1 states have call successors, (3), 2 states have call predecessors, (3), 2 states have return successors, (2), 2 states have call predecessors, (2), 1 states have call successors, (2) [2022-02-20 18:11:31,954 INFO L276 IsEmpty]: Start isEmpty. Operand 0 states and 0 transitions. [2022-02-20 18:11:31,954 INFO L282 IsEmpty]: Finished isEmpty. No accepting run. [2022-02-20 18:11:31,956 INFO L764 garLoopResultBuilder]: Registering result SAFE for location timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION (0 of 1 remaining) [2022-02-20 18:11:31,957 WARN L452 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable3 [2022-02-20 18:11:31,959 INFO L343 DoubleDeckerVisitor]: Before removal of dead ends 0 states and 0 transitions. [2022-02-20 18:11:32,169 INFO L858 garLoopResultBuilder]: For program point L847-1(lines 843 854) no Hoare annotation was computed. [2022-02-20 18:11:32,170 INFO L861 garLoopResultBuilder]: At program point changeMethaneLevelENTRY(lines 843 854) the Hoare annotation is: true [2022-02-20 18:11:32,170 INFO L858 garLoopResultBuilder]: For program point changeMethaneLevelEXIT(lines 843 854) no Hoare annotation was computed. [2022-02-20 18:11:32,170 INFO L854 garLoopResultBuilder]: At program point L609(lines 605 611) the Hoare annotation is: (or (not (= ~pumpRunning~0 0)) (not (= 0 ~systemActive~0))) [2022-02-20 18:11:32,170 INFO L858 garLoopResultBuilder]: For program point L799(lines 799 809) no Hoare annotation was computed. [2022-02-20 18:11:32,170 INFO L858 garLoopResultBuilder]: For program point L795(lines 795 812) no Hoare annotation was computed. [2022-02-20 18:11:32,170 INFO L861 garLoopResultBuilder]: At program point L795-1(lines 787 815) the Hoare annotation is: true [2022-02-20 18:11:32,170 INFO L858 garLoopResultBuilder]: For program point L585(lines 585 591) no Hoare annotation was computed. [2022-02-20 18:11:32,170 INFO L858 garLoopResultBuilder]: For program point L585-2(lines 581 603) no Hoare annotation was computed. [2022-02-20 18:11:32,170 INFO L858 garLoopResultBuilder]: For program point timeShiftFINAL(lines 578 604) no Hoare annotation was computed. [2022-02-20 18:11:32,170 INFO L858 garLoopResultBuilder]: For program point L800(lines 800 806) no Hoare annotation was computed. [2022-02-20 18:11:32,170 INFO L861 garLoopResultBuilder]: At program point L784(lines 777 786) the Hoare annotation is: true [2022-02-20 18:11:32,171 INFO L861 garLoopResultBuilder]: At program point L797(line 797) the Hoare annotation is: true [2022-02-20 18:11:32,171 INFO L861 garLoopResultBuilder]: At program point L892(lines 887 895) the Hoare annotation is: true [2022-02-20 18:11:32,171 INFO L858 garLoopResultBuilder]: For program point L797-1(line 797) no Hoare annotation was computed. [2022-02-20 18:11:32,171 INFO L858 garLoopResultBuilder]: For program point L54(line 54) no Hoare annotation was computed. [2022-02-20 18:11:32,171 INFO L858 garLoopResultBuilder]: For program point L823(lines 823 827) no Hoare annotation was computed. [2022-02-20 18:11:32,172 INFO L854 garLoopResultBuilder]: At program point L55(lines 50 57) the Hoare annotation is: (not (= ~pumpRunning~0 0)) [2022-02-20 18:11:32,173 INFO L854 garLoopResultBuilder]: At program point L823-2(lines 819 830) the Hoare annotation is: (not (= ~pumpRunning~0 0)) [2022-02-20 18:11:32,173 INFO L861 garLoopResultBuilder]: At program point timeShiftENTRY(lines 578 604) the Hoare annotation is: true [2022-02-20 18:11:32,173 INFO L858 garLoopResultBuilder]: For program point L592-1(lines 592 598) no Hoare annotation was computed. [2022-02-20 18:11:32,173 INFO L861 garLoopResultBuilder]: At program point L782(line 782) the Hoare annotation is: true [2022-02-20 18:11:32,173 INFO L858 garLoopResultBuilder]: For program point L782-1(line 782) no Hoare annotation was computed. [2022-02-20 18:11:32,173 INFO L858 garLoopResultBuilder]: For program point timeShiftEXIT(lines 578 604) no Hoare annotation was computed. [2022-02-20 18:11:32,173 INFO L858 garLoopResultBuilder]: For program point timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION(line 54) no Hoare annotation was computed. [2022-02-20 18:11:32,173 INFO L858 garLoopResultBuilder]: For program point L448(line 448) no Hoare annotation was computed. [2022-02-20 18:11:32,173 INFO L858 garLoopResultBuilder]: For program point cleanupEXIT(lines 427 456) no Hoare annotation was computed. [2022-02-20 18:11:32,173 INFO L861 garLoopResultBuilder]: At program point cleanupENTRY(lines 427 456) the Hoare annotation is: true [2022-02-20 18:11:32,173 INFO L858 garLoopResultBuilder]: For program point L441(lines 441 445) no Hoare annotation was computed. [2022-02-20 18:11:32,173 INFO L861 garLoopResultBuilder]: At program point L441-1(lines 441 445) the Hoare annotation is: true [2022-02-20 18:11:32,174 INFO L858 garLoopResultBuilder]: For program point L438(line 438) no Hoare annotation was computed. [2022-02-20 18:11:32,174 INFO L861 garLoopResultBuilder]: At program point L437-2(lines 437 451) the Hoare annotation is: true [2022-02-20 18:11:32,174 INFO L861 garLoopResultBuilder]: At program point L433(line 433) the Hoare annotation is: true [2022-02-20 18:11:32,174 INFO L858 garLoopResultBuilder]: For program point L433-1(line 433) no Hoare annotation was computed. [2022-02-20 18:11:32,174 INFO L861 garLoopResultBuilder]: At program point L452(lines 427 456) the Hoare annotation is: true [2022-02-20 18:11:32,174 INFO L854 garLoopResultBuilder]: At program point L696(lines 684 698) the Hoare annotation is: (and (= ~pumpRunning~0 0) (= |ULTIMATE.start_test_~splverifierCounter~0#1| 0)) [2022-02-20 18:11:32,174 INFO L854 garLoopResultBuilder]: At program point L758(lines 709 759) the Hoare annotation is: false [2022-02-20 18:11:32,174 INFO L858 garLoopResultBuilder]: For program point L688(lines 688 694) no Hoare annotation was computed. [2022-02-20 18:11:32,174 INFO L858 garLoopResultBuilder]: For program point L688-2(lines 688 694) no Hoare annotation was computed. [2022-02-20 18:11:32,174 INFO L858 garLoopResultBuilder]: For program point L746(lines 746 752) no Hoare annotation was computed. [2022-02-20 18:11:32,174 INFO L854 garLoopResultBuilder]: At program point L746-2(lines 740 753) the Hoare annotation is: (and (= ~pumpRunning~0 0) (= |ULTIMATE.start_test_~splverifierCounter~0#1| 0)) [2022-02-20 18:11:32,174 INFO L858 garLoopResultBuilder]: For program point L-1(line -1) no Hoare annotation was computed. [2022-02-20 18:11:32,174 INFO L858 garLoopResultBuilder]: For program point ULTIMATE.startENTRY(line -1) no Hoare annotation was computed. [2022-02-20 18:11:32,175 INFO L858 garLoopResultBuilder]: For program point ULTIMATE.startFINAL(line -1) no Hoare annotation was computed. [2022-02-20 18:11:32,175 INFO L858 garLoopResultBuilder]: For program point L730(lines 730 736) no Hoare annotation was computed. [2022-02-20 18:11:32,175 INFO L858 garLoopResultBuilder]: For program point L730-1(lines 730 736) no Hoare annotation was computed. [2022-02-20 18:11:32,175 INFO L854 garLoopResultBuilder]: At program point L755(lines 710 757) the Hoare annotation is: (and (= ~pumpRunning~0 0) (= |ULTIMATE.start_test_~splverifierCounter~0#1| 0)) [2022-02-20 18:11:32,175 INFO L854 garLoopResultBuilder]: At program point L722(line 722) the Hoare annotation is: (and (= ~pumpRunning~0 0) (= |ULTIMATE.start_test_~splverifierCounter~0#1| 0)) [2022-02-20 18:11:32,175 INFO L854 garLoopResultBuilder]: At program point L561(lines 556 564) the Hoare annotation is: (and (= ~pumpRunning~0 0) (= 1 ~systemActive~0) (= |ULTIMATE.start_valid_product_#res#1| ~systemActive~0)) [2022-02-20 18:11:32,175 INFO L854 garLoopResultBuilder]: At program point L553(lines 549 555) the Hoare annotation is: (and (= ~pumpRunning~0 0) (= 1 ~systemActive~0)) [2022-02-20 18:11:32,175 INFO L858 garLoopResultBuilder]: For program point ULTIMATE.startEXIT(line -1) no Hoare annotation was computed. [2022-02-20 18:11:32,175 INFO L854 garLoopResultBuilder]: At program point L488(lines 484 490) the Hoare annotation is: (and (= ~pumpRunning~0 0) (= |ULTIMATE.start_main_~tmp~3#1| ~systemActive~0) (= 1 ~systemActive~0) (= |ULTIMATE.start_valid_product_#res#1| ~systemActive~0)) [2022-02-20 18:11:32,175 INFO L858 garLoopResultBuilder]: For program point L711(lines 710 757) no Hoare annotation was computed. [2022-02-20 18:11:32,175 INFO L858 garLoopResultBuilder]: For program point L517(lines 517 524) no Hoare annotation was computed. [2022-02-20 18:11:32,175 INFO L858 garLoopResultBuilder]: For program point L740(lines 740 753) no Hoare annotation was computed. [2022-02-20 18:11:32,175 INFO L858 garLoopResultBuilder]: For program point L517-2(lines 517 524) no Hoare annotation was computed. [2022-02-20 18:11:32,176 INFO L854 garLoopResultBuilder]: At program point L546(lines 542 548) the Hoare annotation is: (and (= ~pumpRunning~0 0) (= 1 ~systemActive~0)) [2022-02-20 18:11:32,176 INFO L854 garLoopResultBuilder]: At program point L732(line 732) the Hoare annotation is: (and (= ~pumpRunning~0 0) (= |ULTIMATE.start_test_~splverifierCounter~0#1| 0)) [2022-02-20 18:11:32,176 INFO L861 garLoopResultBuilder]: At program point L761(lines 700 765) the Hoare annotation is: true [2022-02-20 18:11:32,176 INFO L861 garLoopResultBuilder]: At program point L501(lines 493 503) the Hoare annotation is: true [2022-02-20 18:11:32,176 INFO L854 garLoopResultBuilder]: At program point L625(lines 620 627) the Hoare annotation is: false [2022-02-20 18:11:32,176 INFO L858 garLoopResultBuilder]: For program point L720(lines 720 726) no Hoare annotation was computed. [2022-02-20 18:11:32,176 INFO L858 garLoopResultBuilder]: For program point L720-1(lines 720 726) no Hoare annotation was computed. [2022-02-20 18:11:32,176 INFO L861 garLoopResultBuilder]: At program point L526(lines 507 529) the Hoare annotation is: true [2022-02-20 18:11:32,176 INFO L858 garLoopResultBuilder]: For program point L712(lines 712 716) no Hoare annotation was computed. [2022-02-20 18:11:32,176 INFO L854 garLoopResultBuilder]: At program point L774(lines 769 776) the Hoare annotation is: (and (= ~pumpRunning~0 0) (= |ULTIMATE.start_main_~tmp~3#1| ~systemActive~0) (= 1 ~systemActive~0) (= |ULTIMATE.start_valid_product_#res#1| ~systemActive~0)) [2022-02-20 18:11:32,176 INFO L858 garLoopResultBuilder]: For program point waterRiseEXIT(lines 831 842) no Hoare annotation was computed. [2022-02-20 18:11:32,176 INFO L861 garLoopResultBuilder]: At program point waterRiseENTRY(lines 831 842) the Hoare annotation is: true [2022-02-20 18:11:32,177 INFO L858 garLoopResultBuilder]: For program point L835-1(lines 831 842) no Hoare annotation was computed. [2022-02-20 18:11:32,177 INFO L858 garLoopResultBuilder]: For program point isPumpRunningEXIT(lines 639 647) no Hoare annotation was computed. [2022-02-20 18:11:32,177 INFO L861 garLoopResultBuilder]: At program point isPumpRunningENTRY(lines 639 647) the Hoare annotation is: true [2022-02-20 18:11:32,177 INFO L858 garLoopResultBuilder]: For program point isPumpRunningFINAL(lines 639 647) no Hoare annotation was computed. [2022-02-20 18:11:32,180 INFO L732 BasicCegarLoop]: Path program histogram: [1, 1, 1, 1] [2022-02-20 18:11:32,181 INFO L180 ceAbstractionStarter]: Computing trace abstraction results [2022-02-20 18:11:32,184 WARN L170 areAnnotationChecker]: L847-1 has no Hoare annotation [2022-02-20 18:11:32,184 WARN L170 areAnnotationChecker]: L847-1 has no Hoare annotation [2022-02-20 18:11:32,185 WARN L170 areAnnotationChecker]: ULTIMATE.startENTRY has no Hoare annotation [2022-02-20 18:11:32,185 WARN L170 areAnnotationChecker]: L835-1 has no Hoare annotation [2022-02-20 18:11:32,185 WARN L170 areAnnotationChecker]: L835-1 has no Hoare annotation [2022-02-20 18:11:32,185 WARN L170 areAnnotationChecker]: isPumpRunningFINAL has no Hoare annotation [2022-02-20 18:11:32,185 WARN L170 areAnnotationChecker]: L847-1 has no Hoare annotation [2022-02-20 18:11:32,185 WARN L170 areAnnotationChecker]: L782-1 has no Hoare annotation [2022-02-20 18:11:32,185 WARN L170 areAnnotationChecker]: L433-1 has no Hoare annotation [2022-02-20 18:11:32,185 WARN L170 areAnnotationChecker]: L-1 has no Hoare annotation [2022-02-20 18:11:32,185 WARN L170 areAnnotationChecker]: L835-1 has no Hoare annotation [2022-02-20 18:11:32,185 WARN L170 areAnnotationChecker]: isPumpRunningFINAL has no Hoare annotation [2022-02-20 18:11:32,185 WARN L170 areAnnotationChecker]: changeMethaneLevelEXIT has no Hoare annotation [2022-02-20 18:11:32,185 WARN L170 areAnnotationChecker]: L782-1 has no Hoare annotation [2022-02-20 18:11:32,185 WARN L170 areAnnotationChecker]: L433-1 has no Hoare annotation [2022-02-20 18:11:32,186 WARN L170 areAnnotationChecker]: waterRiseEXIT has no Hoare annotation [2022-02-20 18:11:32,186 WARN L170 areAnnotationChecker]: isPumpRunningEXIT has no Hoare annotation [2022-02-20 18:11:32,186 WARN L170 areAnnotationChecker]: isPumpRunningEXIT has no Hoare annotation [2022-02-20 18:11:32,186 WARN L170 areAnnotationChecker]: L730-1 has no Hoare annotation [2022-02-20 18:11:32,186 WARN L170 areAnnotationChecker]: L585 has no Hoare annotation [2022-02-20 18:11:32,186 WARN L170 areAnnotationChecker]: L438 has no Hoare annotation [2022-02-20 18:11:32,186 WARN L170 areAnnotationChecker]: L720-1 has no Hoare annotation [2022-02-20 18:11:32,187 WARN L170 areAnnotationChecker]: L797-1 has no Hoare annotation [2022-02-20 18:11:32,187 WARN L170 areAnnotationChecker]: L740 has no Hoare annotation [2022-02-20 18:11:32,187 WARN L170 areAnnotationChecker]: L740 has no Hoare annotation [2022-02-20 18:11:32,187 WARN L170 areAnnotationChecker]: L585 has no Hoare annotation [2022-02-20 18:11:32,187 WARN L170 areAnnotationChecker]: L585 has no Hoare annotation [2022-02-20 18:11:32,187 WARN L170 areAnnotationChecker]: cleanupEXIT has no Hoare annotation [2022-02-20 18:11:32,187 WARN L170 areAnnotationChecker]: L438 has no Hoare annotation [2022-02-20 18:11:32,187 WARN L170 areAnnotationChecker]: L517 has no Hoare annotation [2022-02-20 18:11:32,187 WARN L170 areAnnotationChecker]: L730 has no Hoare annotation [2022-02-20 18:11:32,187 WARN L170 areAnnotationChecker]: L730 has no Hoare annotation [2022-02-20 18:11:32,187 WARN L170 areAnnotationChecker]: L799 has no Hoare annotation [2022-02-20 18:11:32,187 WARN L170 areAnnotationChecker]: L799 has no Hoare annotation [2022-02-20 18:11:32,187 WARN L170 areAnnotationChecker]: L746 has no Hoare annotation [2022-02-20 18:11:32,187 WARN L170 areAnnotationChecker]: L746 has no Hoare annotation [2022-02-20 18:11:32,187 WARN L170 areAnnotationChecker]: L823 has no Hoare annotation [2022-02-20 18:11:32,187 WARN L170 areAnnotationChecker]: L823 has no Hoare annotation [2022-02-20 18:11:32,187 WARN L170 areAnnotationChecker]: L585-2 has no Hoare annotation [2022-02-20 18:11:32,187 WARN L170 areAnnotationChecker]: L585-2 has no Hoare annotation [2022-02-20 18:11:32,187 WARN L170 areAnnotationChecker]: cleanupEXIT has no Hoare annotation [2022-02-20 18:11:32,187 WARN L170 areAnnotationChecker]: L441 has no Hoare annotation [2022-02-20 18:11:32,188 WARN L170 areAnnotationChecker]: L441 has no Hoare annotation [2022-02-20 18:11:32,188 WARN L170 areAnnotationChecker]: L517 has no Hoare annotation [2022-02-20 18:11:32,188 WARN L170 areAnnotationChecker]: L517 has no Hoare annotation [2022-02-20 18:11:32,188 WARN L170 areAnnotationChecker]: L730-1 has no Hoare annotation [2022-02-20 18:11:32,188 WARN L170 areAnnotationChecker]: L800 has no Hoare annotation [2022-02-20 18:11:32,188 WARN L170 areAnnotationChecker]: L800 has no Hoare annotation [2022-02-20 18:11:32,188 WARN L170 areAnnotationChecker]: timeShiftFINAL has no Hoare annotation [2022-02-20 18:11:32,188 WARN L170 areAnnotationChecker]: L711 has no Hoare annotation [2022-02-20 18:11:32,188 WARN L170 areAnnotationChecker]: L688 has no Hoare annotation [2022-02-20 18:11:32,188 WARN L170 areAnnotationChecker]: L688 has no Hoare annotation [2022-02-20 18:11:32,189 WARN L170 areAnnotationChecker]: L585-2 has no Hoare annotation [2022-02-20 18:11:32,189 WARN L170 areAnnotationChecker]: L592-1 has no Hoare annotation [2022-02-20 18:11:32,189 WARN L170 areAnnotationChecker]: L592-1 has no Hoare annotation [2022-02-20 18:11:32,189 WARN L170 areAnnotationChecker]: L448 has no Hoare annotation [2022-02-20 18:11:32,189 WARN L170 areAnnotationChecker]: L517-2 has no Hoare annotation [2022-02-20 18:11:32,189 WARN L170 areAnnotationChecker]: L54 has no Hoare annotation [2022-02-20 18:11:32,189 WARN L170 areAnnotationChecker]: L54 has no Hoare annotation [2022-02-20 18:11:32,189 WARN L170 areAnnotationChecker]: timeShiftFINAL has no Hoare annotation [2022-02-20 18:11:32,189 WARN L170 areAnnotationChecker]: L711 has no Hoare annotation [2022-02-20 18:11:32,189 WARN L170 areAnnotationChecker]: L711 has no Hoare annotation [2022-02-20 18:11:32,189 WARN L170 areAnnotationChecker]: L688-2 has no Hoare annotation [2022-02-20 18:11:32,189 WARN L170 areAnnotationChecker]: L688-2 has no Hoare annotation [2022-02-20 18:11:32,190 WARN L170 areAnnotationChecker]: L795 has no Hoare annotation [2022-02-20 18:11:32,190 WARN L170 areAnnotationChecker]: L517-2 has no Hoare annotation [2022-02-20 18:11:32,190 WARN L170 areAnnotationChecker]: L448 has no Hoare annotation [2022-02-20 18:11:32,190 WARN L170 areAnnotationChecker]: ULTIMATE.startFINAL has no Hoare annotation [2022-02-20 18:11:32,190 WARN L170 areAnnotationChecker]: timeShiftEXIT has no Hoare annotation [2022-02-20 18:11:32,190 WARN L170 areAnnotationChecker]: timeShiftEXIT has no Hoare annotation [2022-02-20 18:11:32,190 WARN L170 areAnnotationChecker]: timeShiftEXIT has no Hoare annotation [2022-02-20 18:11:32,190 WARN L170 areAnnotationChecker]: L712 has no Hoare annotation [2022-02-20 18:11:32,191 WARN L170 areAnnotationChecker]: L795 has no Hoare annotation [2022-02-20 18:11:32,191 WARN L170 areAnnotationChecker]: L795 has no Hoare annotation [2022-02-20 18:11:32,191 WARN L170 areAnnotationChecker]: ULTIMATE.startFINAL has no Hoare annotation [2022-02-20 18:11:32,191 WARN L170 areAnnotationChecker]: L720 has no Hoare annotation [2022-02-20 18:11:32,191 WARN L170 areAnnotationChecker]: L720 has no Hoare annotation [2022-02-20 18:11:32,191 WARN L170 areAnnotationChecker]: L797-1 has no Hoare annotation [2022-02-20 18:11:32,191 WARN L170 areAnnotationChecker]: L720-1 has no Hoare annotation [2022-02-20 18:11:32,191 INFO L163 areAnnotationChecker]: CFG has 21 edges. 21 inductive. 0 not inductive. 0 times theorem prover too weak to decide inductivity. 0 times interpolants missing. [2022-02-20 18:11:32,202 INFO L202 PluginConnector]: Adding new model de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction CFG 20.02 06:11:32 BoogieIcfgContainer [2022-02-20 18:11:32,202 INFO L132 PluginConnector]: ------------------------ END TraceAbstraction---------------------------- [2022-02-20 18:11:32,202 INFO L113 PluginConnector]: ------------------------Witness Printer---------------------------- [2022-02-20 18:11:32,202 INFO L271 PluginConnector]: Initializing Witness Printer... [2022-02-20 18:11:32,203 INFO L275 PluginConnector]: Witness Printer initialized [2022-02-20 18:11:32,203 INFO L185 PluginConnector]: Executing the observer RCFGCatcher from plugin Witness Printer for "de.uni_freiburg.informatik.ultimate.plugins.generator.rcfgbuilder CFG 20.02 06:11:29" (3/4) ... [2022-02-20 18:11:32,206 INFO L137 WitnessPrinter]: Generating witness for correct program [2022-02-20 18:11:32,210 INFO L354 RCFGBacktranslator]: Ignoring RootEdge to procedure changeMethaneLevel [2022-02-20 18:11:32,210 INFO L354 RCFGBacktranslator]: Ignoring RootEdge to procedure timeShift [2022-02-20 18:11:32,210 INFO L354 RCFGBacktranslator]: Ignoring RootEdge to procedure cleanup [2022-02-20 18:11:32,210 INFO L354 RCFGBacktranslator]: Ignoring RootEdge to procedure waterRise [2022-02-20 18:11:32,210 INFO L354 RCFGBacktranslator]: Ignoring RootEdge to procedure isPumpRunning [2022-02-20 18:11:32,215 INFO L910 BoogieBacktranslator]: Reduced CFG by removing 46 nodes and edges [2022-02-20 18:11:32,216 INFO L910 BoogieBacktranslator]: Reduced CFG by removing 22 nodes and edges [2022-02-20 18:11:32,216 INFO L910 BoogieBacktranslator]: Reduced CFG by removing 11 nodes and edges [2022-02-20 18:11:32,216 INFO L910 BoogieBacktranslator]: Reduced CFG by removing 5 nodes and edges [2022-02-20 18:11:32,216 INFO L910 BoogieBacktranslator]: Reduced CFG by removing 2 nodes and edges [2022-02-20 18:11:32,217 INFO L910 BoogieBacktranslator]: Reduced CFG by removing 1 nodes and edges [2022-02-20 18:11:32,217 INFO L910 BoogieBacktranslator]: Reduced CFG by removing 1 nodes and edges [2022-02-20 18:11:32,236 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (pumpRunning == 0 && 1 == systemActive) && \result == systemActive [2022-02-20 18:11:32,237 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: ((pumpRunning == 0 && tmp == systemActive) && 1 == systemActive) && \result == systemActive [2022-02-20 18:11:32,237 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: ((pumpRunning == 0 && tmp == systemActive) && 1 == systemActive) && \result == systemActive [2022-02-20 18:11:32,252 INFO L141 WitnessManager]: Wrote witness to /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/witness.graphml [2022-02-20 18:11:32,252 INFO L132 PluginConnector]: ------------------------ END Witness Printer---------------------------- [2022-02-20 18:11:32,253 INFO L158 Benchmark]: Toolchain (without parser) took 3634.79ms. Allocated memory was 151.0MB in the beginning and 182.5MB in the end (delta: 31.5MB). Free memory was 89.6MB in the beginning and 57.6MB in the end (delta: 32.0MB). Peak memory consumption was 64.4MB. Max. memory is 16.1GB. [2022-02-20 18:11:32,254 INFO L158 Benchmark]: CDTParser took 0.22ms. Allocated memory is still 151.0MB. Free memory is still 106.8MB. There was no memory consumed. Max. memory is 16.1GB. [2022-02-20 18:11:32,254 INFO L158 Benchmark]: CACSL2BoogieTranslator took 462.14ms. Allocated memory is still 151.0MB. Free memory was 89.4MB in the beginning and 113.3MB in the end (delta: -23.9MB). Peak memory consumption was 11.8MB. Max. memory is 16.1GB. [2022-02-20 18:11:32,254 INFO L158 Benchmark]: Boogie Procedure Inliner took 54.31ms. Allocated memory is still 151.0MB. Free memory was 113.3MB in the beginning and 111.2MB in the end (delta: 2.1MB). Peak memory consumption was 2.1MB. Max. memory is 16.1GB. [2022-02-20 18:11:32,254 INFO L158 Benchmark]: Boogie Preprocessor took 40.25ms. Allocated memory is still 151.0MB. Free memory was 111.2MB in the beginning and 109.6MB in the end (delta: 1.6MB). There was no memory consumed. Max. memory is 16.1GB. [2022-02-20 18:11:32,254 INFO L158 Benchmark]: RCFGBuilder took 332.76ms. Allocated memory is still 151.0MB. Free memory was 109.6MB in the beginning and 92.3MB in the end (delta: 17.3MB). Peak memory consumption was 18.9MB. Max. memory is 16.1GB. [2022-02-20 18:11:32,255 INFO L158 Benchmark]: TraceAbstraction took 2688.42ms. Allocated memory was 151.0MB in the beginning and 182.5MB in the end (delta: 31.5MB). Free memory was 91.8MB in the beginning and 61.8MB in the end (delta: 30.0MB). Peak memory consumption was 61.5MB. Max. memory is 16.1GB. [2022-02-20 18:11:32,255 INFO L158 Benchmark]: Witness Printer took 49.94ms. Allocated memory is still 182.5MB. Free memory was 61.8MB in the beginning and 57.6MB in the end (delta: 4.2MB). Peak memory consumption was 4.2MB. Max. memory is 16.1GB. [2022-02-20 18:11:32,256 INFO L339 ainManager$Toolchain]: ####################### End [Toolchain 1] ####################### --- Results --- * Results from de.uni_freiburg.informatik.ultimate.core: - AssertionsEnabledResult: Assertions are enabled Assertions are enabled - StatisticsResult: Toolchain Benchmarks Benchmark results are: * CDTParser took 0.22ms. Allocated memory is still 151.0MB. Free memory is still 106.8MB. There was no memory consumed. Max. memory is 16.1GB. * CACSL2BoogieTranslator took 462.14ms. Allocated memory is still 151.0MB. Free memory was 89.4MB in the beginning and 113.3MB in the end (delta: -23.9MB). Peak memory consumption was 11.8MB. Max. memory is 16.1GB. * Boogie Procedure Inliner took 54.31ms. Allocated memory is still 151.0MB. Free memory was 113.3MB in the beginning and 111.2MB in the end (delta: 2.1MB). Peak memory consumption was 2.1MB. Max. memory is 16.1GB. * Boogie Preprocessor took 40.25ms. Allocated memory is still 151.0MB. Free memory was 111.2MB in the beginning and 109.6MB in the end (delta: 1.6MB). There was no memory consumed. Max. memory is 16.1GB. * RCFGBuilder took 332.76ms. Allocated memory is still 151.0MB. Free memory was 109.6MB in the beginning and 92.3MB in the end (delta: 17.3MB). Peak memory consumption was 18.9MB. Max. memory is 16.1GB. * TraceAbstraction took 2688.42ms. Allocated memory was 151.0MB in the beginning and 182.5MB in the end (delta: 31.5MB). Free memory was 91.8MB in the beginning and 61.8MB in the end (delta: 30.0MB). Peak memory consumption was 61.5MB. Max. memory is 16.1GB. * Witness Printer took 49.94ms. Allocated memory is still 182.5MB. Free memory was 61.8MB in the beginning and 57.6MB in the end (delta: 4.2MB). Peak memory consumption was 4.2MB. Max. memory is 16.1GB. * Results from de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction: - StatisticsResult: ErrorAutomatonStatistics NumberErrorTraces: 0, NumberStatementsAllTraces: 0, NumberRelevantStatements: 0, 0.0s ErrorAutomatonConstructionTimeTotal, 0.0s FaulLocalizationTime, NumberStatementsFirstTrace: -1, TraceLengthAvg: 0, 0.0s ErrorAutomatonConstructionTimeAvg, 0.0s ErrorAutomatonDifferenceTimeAvg, 0.0s ErrorAutomatonDifferenceTimeTotal, NumberOfNoEnhancement: 0, NumberOfFiniteEnhancement: 0, NumberOfInfiniteEnhancement: 0 - PositiveResult [Line: 54]: call to reach_error is unreachable For all program executions holds that call to reach_error is unreachable at this location - StatisticsResult: Ultimate Automizer benchmark data CFG has 6 procedures, 72 locations, 1 error locations. Started 1 CEGAR loops. OverallTime: 2.6s, OverallIterations: 4, TraceHistogramMax: 2, PathProgramHistogramMax: 1, EmptinessCheckTime: 0.0s, AutomataDifference: 1.5s, DeadEndRemovalTime: 0.0s, HoareAnnotationTime: 0.2s, InitialAbstractionConstructionTime: 0.0s, PartialOrderReductionTime: 0.0s, HoareTripleCheckerStatistics: 0 mSolverCounterUnknown, 223 SdHoareTripleChecker+Valid, 0.1s IncrementalHoareTripleChecker+Time, 0 mSdLazyCounter, 219 mSDsluCounter, 729 SdHoareTripleChecker+Invalid, 0.1s Time, 0 mProtectedAction, 0 SdHoareTripleChecker+Unchecked, 0 IncrementalHoareTripleChecker+Unchecked, 442 mSDsCounter, 22 IncrementalHoareTripleChecker+Valid, 0 mProtectedPredicate, 88 IncrementalHoareTripleChecker+Invalid, 110 SdHoareTripleChecker+Unknown, 0 mSolverCounterNotChecked, 22 mSolverCounterUnsat, 287 mSDtfsCounter, 88 mSolverCounterSat, 0.0s SdHoareTripleChecker+Time, 0 IncrementalHoareTripleChecker+Unknown, PredicateUnifierStatistics: 0 DeclaredPredicates, 35 GetRequests, 21 SyntacticMatches, 0 SemanticMatches, 14 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 3 ImplicationChecksByTransitivity, 0.0s Time, 0.0s BasicInterpolantAutomatonTime, BiggestAbstraction: size=133occurred in iteration=3, InterpolantAutomatonStates: 17, traceCheckStatistics: No data available, InterpolantConsolidationStatistics: No data available, PathInvariantsStatistics: No data available, 0/0 InterpolantCoveringCapability, TotalInterpolationStatistics: No data available, 0.0s DumpTime, AutomataMinimizationStatistics: 0.1s AutomataMinimizationTime, 4 MinimizatonAttempts, 10 StatesRemovedByMinimization, 1 NontrivialMinimizations, HoareAnnotationStatistics: 0.0s HoareAnnotationTime, 32 LocationsWithAnnotation, 167 PreInvPairs, 203 NumberOfFragments, 121 HoareAnnotationTreeSize, 167 FomulaSimplifications, 45 FormulaSimplificationTreeSizeReduction, 0.1s HoareSimplificationTime, 32 FomulaSimplificationsInter, 494 FormulaSimplificationTreeSizeReductionInter, 0.1s HoareSimplificationTimeInter, RefinementEngineStatistics: TRACE_CHECK: 0.0s SsaConstructionTime, 0.1s SatisfiabilityAnalysisTime, 0.4s InterpolantComputationTime, 140 NumberOfCodeBlocks, 140 NumberOfCodeBlocksAsserted, 4 NumberOfCheckSat, 136 ConstructedInterpolants, 0 QuantifiedInterpolants, 263 SizeOfPredicates, 0 NumberOfNonLiveVariables, 0 ConjunctsInSsa, 0 ConjunctsInUnsatCore, 4 InterpolantComputations, 4 PerfectInterpolantSequences, 12/12 InterpolantCoveringCapability, INVARIANT_SYNTHESIS: No data available, INTERPOLANT_CONSOLIDATION: No data available, ABSTRACT_INTERPRETATION: No data available, PDR: No data available, ACCELERATED_INTERPOLATION: No data available, SIFA: No data available, ReuseStatistics: No data available - AllSpecificationsHoldResult: All specifications hold 1 specifications checked. All of them hold - InvariantResult [Line: 556]: Loop Invariant Derived loop invariant: (pumpRunning == 0 && 1 == systemActive) && \result == systemActive - InvariantResult [Line: 437]: Loop Invariant Derived loop invariant: 1 - InvariantResult [Line: 542]: Loop Invariant Derived loop invariant: pumpRunning == 0 && 1 == systemActive - InvariantResult [Line: 769]: Loop Invariant Derived loop invariant: ((pumpRunning == 0 && tmp == systemActive) && 1 == systemActive) && \result == systemActive - InvariantResult [Line: 427]: Loop Invariant Derived loop invariant: 1 - InvariantResult [Line: 819]: Loop Invariant Derived loop invariant: !(pumpRunning == 0) - InvariantResult [Line: 777]: Loop Invariant Derived loop invariant: 1 - InvariantResult [Line: 620]: Loop Invariant Derived loop invariant: 0 - InvariantResult [Line: 787]: Loop Invariant Derived loop invariant: 1 - InvariantResult [Line: 710]: Loop Invariant Derived loop invariant: pumpRunning == 0 && splverifierCounter == 0 - InvariantResult [Line: 549]: Loop Invariant Derived loop invariant: pumpRunning == 0 && 1 == systemActive - InvariantResult [Line: 700]: Loop Invariant Derived loop invariant: 1 - InvariantResult [Line: 507]: Loop Invariant Derived loop invariant: 1 - InvariantResult [Line: 709]: Loop Invariant Derived loop invariant: 0 - InvariantResult [Line: 50]: Loop Invariant Derived loop invariant: !(pumpRunning == 0) - InvariantResult [Line: 684]: Loop Invariant Derived loop invariant: pumpRunning == 0 && splverifierCounter == 0 - InvariantResult [Line: 887]: Loop Invariant Derived loop invariant: 1 - InvariantResult [Line: 493]: Loop Invariant Derived loop invariant: 1 - InvariantResult [Line: 605]: Loop Invariant Derived loop invariant: !(pumpRunning == 0) || !(0 == systemActive) - InvariantResult [Line: 484]: Loop Invariant Derived loop invariant: ((pumpRunning == 0 && tmp == systemActive) && 1 == systemActive) && \result == systemActive RESULT: Ultimate proved your program to be correct! [2022-02-20 18:11:32,293 INFO L552 MonitoredProcess]: [MP /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in -t:2000 (1)] Ended with exit code 0 Received shutdown request... --- End real Ultimate output --- Execution finished normally Writing output log to file Ultimate.log Result: TRUE