./Ultimate.py --spec ../sv-benchmarks/c/properties/unreach-call.prp --file ../sv-benchmarks/c/product-lines/minepump_spec5_product04.cil.c --full-output -ea --architecture 32bit -------------------------------------------------------------------------------- Checking for ERROR reachability Using default analysis Version 03d7b7b3 Calling Ultimate with: /usr/bin/java -Dosgi.configuration.area=/storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/data/config -Xmx15G -Xms4m -ea -jar /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/plugins/org.eclipse.equinox.launcher_1.5.800.v20200727-1323.jar -data @noDefault -ultimatedata /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/data -tc /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/config/AutomizerReach.xml -i ../sv-benchmarks/c/product-lines/minepump_spec5_product04.cil.c -s /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/config/svcomp-Reach-32bit-Automizer_Default.epf --cacsl2boogietranslator.entry.function main --witnessprinter.witness.directory /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux --witnessprinter.witness.filename witness.graphml --witnessprinter.write.witness.besides.input.file false --witnessprinter.graph.data.specification CHECK( init(main()), LTL(G ! call(reach_error())) ) --witnessprinter.graph.data.producer Automizer --witnessprinter.graph.data.architecture 32bit --witnessprinter.graph.data.programhash b31717b9bd1ac5cd1350f18acb90cf1947e367b4bc98f1fbfc3c2d7d8e7480dc --- Real Ultimate output --- This is Ultimate 0.2.2-dev-03d7b7b [2022-02-20 18:11:28,160 INFO L177 SettingsManager]: Resetting all preferences to default values... [2022-02-20 18:11:28,162 INFO L181 SettingsManager]: Resetting UltimateCore preferences to default values [2022-02-20 18:11:28,200 INFO L184 SettingsManager]: Ultimate Commandline Interface provides no preferences, ignoring... [2022-02-20 18:11:28,201 INFO L181 SettingsManager]: Resetting Boogie Preprocessor preferences to default values [2022-02-20 18:11:28,202 INFO L181 SettingsManager]: Resetting Boogie Procedure Inliner preferences to default values [2022-02-20 18:11:28,203 INFO L181 SettingsManager]: Resetting Abstract Interpretation preferences to default values [2022-02-20 18:11:28,204 INFO L181 SettingsManager]: Resetting LassoRanker preferences to default values [2022-02-20 18:11:28,205 INFO L181 SettingsManager]: Resetting Reaching Definitions preferences to default values [2022-02-20 18:11:28,210 INFO L181 SettingsManager]: Resetting SyntaxChecker preferences to default values [2022-02-20 18:11:28,211 INFO L181 SettingsManager]: Resetting Sifa preferences to default values [2022-02-20 18:11:28,212 INFO L184 SettingsManager]: Büchi Program Product provides no preferences, ignoring... [2022-02-20 18:11:28,213 INFO L181 SettingsManager]: Resetting LTL2Aut preferences to default values [2022-02-20 18:11:28,215 INFO L181 SettingsManager]: Resetting PEA to Boogie preferences to default values [2022-02-20 18:11:28,216 INFO L181 SettingsManager]: Resetting BlockEncodingV2 preferences to default values [2022-02-20 18:11:28,217 INFO L181 SettingsManager]: Resetting ChcToBoogie preferences to default values [2022-02-20 18:11:28,220 INFO L181 SettingsManager]: Resetting AutomataScriptInterpreter preferences to default values [2022-02-20 18:11:28,221 INFO L181 SettingsManager]: Resetting BuchiAutomizer preferences to default values [2022-02-20 18:11:28,222 INFO L181 SettingsManager]: Resetting CACSL2BoogieTranslator preferences to default values [2022-02-20 18:11:28,223 INFO L181 SettingsManager]: Resetting CodeCheck preferences to default values [2022-02-20 18:11:28,227 INFO L181 SettingsManager]: Resetting InvariantSynthesis preferences to default values [2022-02-20 18:11:28,228 INFO L181 SettingsManager]: Resetting RCFGBuilder preferences to default values [2022-02-20 18:11:28,228 INFO L181 SettingsManager]: Resetting Referee preferences to default values [2022-02-20 18:11:28,230 INFO L181 SettingsManager]: Resetting TraceAbstraction preferences to default values [2022-02-20 18:11:28,233 INFO L184 SettingsManager]: TraceAbstractionConcurrent provides no preferences, ignoring... [2022-02-20 18:11:28,234 INFO L184 SettingsManager]: TraceAbstractionWithAFAs provides no preferences, ignoring... [2022-02-20 18:11:28,234 INFO L181 SettingsManager]: Resetting TreeAutomizer preferences to default values [2022-02-20 18:11:28,236 INFO L181 SettingsManager]: Resetting IcfgToChc preferences to default values [2022-02-20 18:11:28,236 INFO L181 SettingsManager]: Resetting IcfgTransformer preferences to default values [2022-02-20 18:11:28,237 INFO L184 SettingsManager]: ReqToTest provides no preferences, ignoring... [2022-02-20 18:11:28,237 INFO L181 SettingsManager]: Resetting Boogie Printer preferences to default values [2022-02-20 18:11:28,238 INFO L181 SettingsManager]: Resetting ChcSmtPrinter preferences to default values [2022-02-20 18:11:28,239 INFO L181 SettingsManager]: Resetting ReqPrinter preferences to default values [2022-02-20 18:11:28,240 INFO L181 SettingsManager]: Resetting Witness Printer preferences to default values [2022-02-20 18:11:28,240 INFO L184 SettingsManager]: Boogie PL CUP Parser provides no preferences, ignoring... [2022-02-20 18:11:28,241 INFO L181 SettingsManager]: Resetting CDTParser preferences to default values [2022-02-20 18:11:28,241 INFO L184 SettingsManager]: AutomataScriptParser provides no preferences, ignoring... [2022-02-20 18:11:28,241 INFO L184 SettingsManager]: ReqParser provides no preferences, ignoring... [2022-02-20 18:11:28,241 INFO L181 SettingsManager]: Resetting SmtParser preferences to default values [2022-02-20 18:11:28,242 INFO L181 SettingsManager]: Resetting Witness Parser preferences to default values [2022-02-20 18:11:28,242 INFO L188 SettingsManager]: Finished resetting all preferences to default values... [2022-02-20 18:11:28,243 INFO L101 SettingsManager]: Beginning loading settings from /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/config/svcomp-Reach-32bit-Automizer_Default.epf [2022-02-20 18:11:28,267 INFO L113 SettingsManager]: Loading preferences was successful [2022-02-20 18:11:28,268 INFO L115 SettingsManager]: Preferences different from defaults after loading the file: [2022-02-20 18:11:28,268 INFO L136 SettingsManager]: Preferences of UltimateCore differ from their defaults: [2022-02-20 18:11:28,268 INFO L138 SettingsManager]: * Log level for class=de.uni_freiburg.informatik.ultimate.lib.smtlibutils.quantifier.QuantifierPusher=ERROR; [2022-02-20 18:11:28,269 INFO L136 SettingsManager]: Preferences of Boogie Procedure Inliner differ from their defaults: [2022-02-20 18:11:28,269 INFO L138 SettingsManager]: * Ignore calls to procedures called more than once=ONLY_FOR_SEQUENTIAL_PROGRAMS [2022-02-20 18:11:28,270 INFO L136 SettingsManager]: Preferences of BlockEncodingV2 differ from their defaults: [2022-02-20 18:11:28,270 INFO L138 SettingsManager]: * Create parallel compositions if possible=false [2022-02-20 18:11:28,270 INFO L138 SettingsManager]: * Use SBE=true [2022-02-20 18:11:28,270 INFO L136 SettingsManager]: Preferences of CACSL2BoogieTranslator differ from their defaults: [2022-02-20 18:11:28,271 INFO L138 SettingsManager]: * sizeof long=4 [2022-02-20 18:11:28,271 INFO L138 SettingsManager]: * Overapproximate operations on floating types=true [2022-02-20 18:11:28,271 INFO L138 SettingsManager]: * sizeof POINTER=4 [2022-02-20 18:11:28,271 INFO L138 SettingsManager]: * Check division by zero=IGNORE [2022-02-20 18:11:28,272 INFO L138 SettingsManager]: * Pointer to allocated memory at dereference=IGNORE [2022-02-20 18:11:28,272 INFO L138 SettingsManager]: * If two pointers are subtracted or compared they have the same base address=IGNORE [2022-02-20 18:11:28,272 INFO L138 SettingsManager]: * Check array bounds for arrays that are off heap=IGNORE [2022-02-20 18:11:28,272 INFO L138 SettingsManager]: * sizeof long double=12 [2022-02-20 18:11:28,272 INFO L138 SettingsManager]: * Check if freed pointer was valid=false [2022-02-20 18:11:28,272 INFO L138 SettingsManager]: * Use constant arrays=true [2022-02-20 18:11:28,272 INFO L138 SettingsManager]: * Pointer base address is valid at dereference=IGNORE [2022-02-20 18:11:28,273 INFO L136 SettingsManager]: Preferences of RCFGBuilder differ from their defaults: [2022-02-20 18:11:28,273 INFO L138 SettingsManager]: * Size of a code block=SequenceOfStatements [2022-02-20 18:11:28,273 INFO L138 SettingsManager]: * SMT solver=External_DefaultMode [2022-02-20 18:11:28,273 INFO L138 SettingsManager]: * Command for external solver=z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in -t:2000 [2022-02-20 18:11:28,273 INFO L136 SettingsManager]: Preferences of TraceAbstraction differ from their defaults: [2022-02-20 18:11:28,273 INFO L138 SettingsManager]: * Compute Interpolants along a Counterexample=FPandBP [2022-02-20 18:11:28,273 INFO L138 SettingsManager]: * Positions where we compute the Hoare Annotation=LoopsAndPotentialCycles [2022-02-20 18:11:28,274 INFO L138 SettingsManager]: * Trace refinement strategy=CAMEL [2022-02-20 18:11:28,274 INFO L138 SettingsManager]: * Command for external solver=z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in [2022-02-20 18:11:28,274 INFO L138 SettingsManager]: * Large block encoding in concurrent analysis=OFF [2022-02-20 18:11:28,274 INFO L138 SettingsManager]: * Automaton type used in concurrency analysis=PETRI_NET [2022-02-20 18:11:28,274 INFO L138 SettingsManager]: * Compute Hoare Annotation of negated interpolant automaton, abstraction and CFG=true [2022-02-20 18:11:28,274 INFO L138 SettingsManager]: * SMT solver=External_ModelsAndUnsatCoreMode WARNING: An illegal reflective access operation has occurred WARNING: Illegal reflective access by com.sun.xml.bind.v2.runtime.reflect.opt.Injector$1 (file:/storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/plugins/com.sun.xml.bind_2.2.0.v201505121915.jar) to method java.lang.ClassLoader.defineClass(java.lang.String,byte[],int,int) WARNING: Please consider reporting this to the maintainers of com.sun.xml.bind.v2.runtime.reflect.opt.Injector$1 WARNING: Use --illegal-access=warn to enable warnings of further illegal reflective access operations WARNING: All illegal access operations will be denied in a future release Applying setting for plugin de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator: Entry function -> main Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Witness directory -> /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Witness filename -> witness.graphml Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Write witness besides input file -> false Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Graph data specification -> CHECK( init(main()), LTL(G ! call(reach_error())) ) Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Graph data producer -> Automizer Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Graph data architecture -> 32bit Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Graph data programhash -> b31717b9bd1ac5cd1350f18acb90cf1947e367b4bc98f1fbfc3c2d7d8e7480dc [2022-02-20 18:11:28,511 INFO L75 nceAwareModelManager]: Repository-Root is: /tmp [2022-02-20 18:11:28,538 INFO L261 ainManager$Toolchain]: [Toolchain 1]: Applicable parser(s) successfully (re)initialized [2022-02-20 18:11:28,540 INFO L217 ainManager$Toolchain]: [Toolchain 1]: Toolchain selected. [2022-02-20 18:11:28,541 INFO L271 PluginConnector]: Initializing CDTParser... [2022-02-20 18:11:28,542 INFO L275 PluginConnector]: CDTParser initialized [2022-02-20 18:11:28,543 INFO L432 ainManager$Toolchain]: [Toolchain 1]: Parsing single file: /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/../sv-benchmarks/c/product-lines/minepump_spec5_product04.cil.c [2022-02-20 18:11:28,603 INFO L220 CDTParser]: Created temporary CDT project at /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/data/f1adfe1d8/568b68089b4344e6a64cb9c8b9f26dcb/FLAGa10fcc05a [2022-02-20 18:11:28,981 INFO L306 CDTParser]: Found 1 translation units. [2022-02-20 18:11:28,982 INFO L160 CDTParser]: Scanning /storage/repos/ultimate/releaseScripts/default/sv-benchmarks/c/product-lines/minepump_spec5_product04.cil.c [2022-02-20 18:11:28,993 INFO L349 CDTParser]: About to delete temporary CDT project at /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/data/f1adfe1d8/568b68089b4344e6a64cb9c8b9f26dcb/FLAGa10fcc05a [2022-02-20 18:11:29,374 INFO L357 CDTParser]: Successfully deleted /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/data/f1adfe1d8/568b68089b4344e6a64cb9c8b9f26dcb [2022-02-20 18:11:29,376 INFO L299 ainManager$Toolchain]: ####################### [Toolchain 1] ####################### [2022-02-20 18:11:29,377 INFO L131 ToolchainWalker]: Walking toolchain with 6 elements. [2022-02-20 18:11:29,380 INFO L113 PluginConnector]: ------------------------CACSL2BoogieTranslator---------------------------- [2022-02-20 18:11:29,381 INFO L271 PluginConnector]: Initializing CACSL2BoogieTranslator... [2022-02-20 18:11:29,383 INFO L275 PluginConnector]: CACSL2BoogieTranslator initialized [2022-02-20 18:11:29,384 INFO L185 PluginConnector]: Executing the observer ACSLObjectContainerObserver from plugin CACSL2BoogieTranslator for "CDTParser AST 20.02 06:11:29" (1/1) ... [2022-02-20 18:11:29,385 INFO L205 PluginConnector]: Invalid model from CACSL2BoogieTranslator for observer de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator.ACSLObjectContainerObserver@4b9683bb and model type de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 20.02 06:11:29, skipping insertion in model container [2022-02-20 18:11:29,385 INFO L185 PluginConnector]: Executing the observer CACSL2BoogieTranslatorObserver from plugin CACSL2BoogieTranslator for "CDTParser AST 20.02 06:11:29" (1/1) ... [2022-02-20 18:11:29,391 INFO L145 MainTranslator]: Starting translation in SV-COMP mode [2022-02-20 18:11:29,419 INFO L178 MainTranslator]: Built tables and reachable declarations [2022-02-20 18:11:29,645 WARN L230 ndardFunctionHandler]: Function reach_error is already implemented but we override the implementation for the call at /storage/repos/ultimate/releaseScripts/default/sv-benchmarks/c/product-lines/minepump_spec5_product04.cil.c[16991,17004] [2022-02-20 18:11:29,649 INFO L210 PostProcessor]: Analyzing one entry point: main [2022-02-20 18:11:29,656 INFO L203 MainTranslator]: Completed pre-run [2022-02-20 18:11:29,733 WARN L230 ndardFunctionHandler]: Function reach_error is already implemented but we override the implementation for the call at /storage/repos/ultimate/releaseScripts/default/sv-benchmarks/c/product-lines/minepump_spec5_product04.cil.c[16991,17004] [2022-02-20 18:11:29,734 INFO L210 PostProcessor]: Analyzing one entry point: main [2022-02-20 18:11:29,747 INFO L208 MainTranslator]: Completed translation [2022-02-20 18:11:29,747 INFO L202 PluginConnector]: Adding new model de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 20.02 06:11:29 WrapperNode [2022-02-20 18:11:29,747 INFO L132 PluginConnector]: ------------------------ END CACSL2BoogieTranslator---------------------------- [2022-02-20 18:11:29,748 INFO L113 PluginConnector]: ------------------------Boogie Procedure Inliner---------------------------- [2022-02-20 18:11:29,748 INFO L271 PluginConnector]: Initializing Boogie Procedure Inliner... [2022-02-20 18:11:29,748 INFO L275 PluginConnector]: Boogie Procedure Inliner initialized [2022-02-20 18:11:29,756 INFO L185 PluginConnector]: Executing the observer TypeChecker from plugin Boogie Procedure Inliner for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 20.02 06:11:29" (1/1) ... [2022-02-20 18:11:29,773 INFO L185 PluginConnector]: Executing the observer Inliner from plugin Boogie Procedure Inliner for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 20.02 06:11:29" (1/1) ... [2022-02-20 18:11:29,798 INFO L137 Inliner]: procedures = 53, calls = 150, calls flagged for inlining = 22, calls inlined = 18, statements flattened = 201 [2022-02-20 18:11:29,798 INFO L132 PluginConnector]: ------------------------ END Boogie Procedure Inliner---------------------------- [2022-02-20 18:11:29,799 INFO L113 PluginConnector]: ------------------------Boogie Preprocessor---------------------------- [2022-02-20 18:11:29,799 INFO L271 PluginConnector]: Initializing Boogie Preprocessor... [2022-02-20 18:11:29,800 INFO L275 PluginConnector]: Boogie Preprocessor initialized [2022-02-20 18:11:29,805 INFO L185 PluginConnector]: Executing the observer EnsureBoogieModelObserver from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 20.02 06:11:29" (1/1) ... [2022-02-20 18:11:29,806 INFO L185 PluginConnector]: Executing the observer TypeChecker from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 20.02 06:11:29" (1/1) ... [2022-02-20 18:11:29,808 INFO L185 PluginConnector]: Executing the observer ConstExpander from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 20.02 06:11:29" (1/1) ... [2022-02-20 18:11:29,817 INFO L185 PluginConnector]: Executing the observer StructExpander from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 20.02 06:11:29" (1/1) ... [2022-02-20 18:11:29,821 INFO L185 PluginConnector]: Executing the observer UnstructureCode from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 20.02 06:11:29" (1/1) ... [2022-02-20 18:11:29,824 INFO L185 PluginConnector]: Executing the observer FunctionInliner from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 20.02 06:11:29" (1/1) ... [2022-02-20 18:11:29,837 INFO L185 PluginConnector]: Executing the observer BoogieSymbolTableConstructor from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 20.02 06:11:29" (1/1) ... [2022-02-20 18:11:29,839 INFO L132 PluginConnector]: ------------------------ END Boogie Preprocessor---------------------------- [2022-02-20 18:11:29,840 INFO L113 PluginConnector]: ------------------------RCFGBuilder---------------------------- [2022-02-20 18:11:29,840 INFO L271 PluginConnector]: Initializing RCFGBuilder... [2022-02-20 18:11:29,840 INFO L275 PluginConnector]: RCFGBuilder initialized [2022-02-20 18:11:29,841 INFO L185 PluginConnector]: Executing the observer RCFGBuilderObserver from plugin RCFGBuilder for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 20.02 06:11:29" (1/1) ... [2022-02-20 18:11:29,846 INFO L173 SolverBuilder]: Constructing external solver with command: z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in -t:2000 [2022-02-20 18:11:29,858 INFO L189 MonitoredProcess]: No working directory specified, using /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 [2022-02-20 18:11:29,870 INFO L229 MonitoredProcess]: Starting monitored process 1 with /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in -t:2000 (exit command is (exit), workingDir is null) [2022-02-20 18:11:29,887 INFO L327 MonitoredProcess]: [MP /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in -t:2000 (1)] Waiting until timeout for monitored process [2022-02-20 18:11:29,906 INFO L130 BoogieDeclarations]: Found specification of procedure #Ultimate.allocInit [2022-02-20 18:11:29,907 INFO L130 BoogieDeclarations]: Found specification of procedure cleanup [2022-02-20 18:11:29,907 INFO L138 BoogieDeclarations]: Found implementation of procedure cleanup [2022-02-20 18:11:29,907 INFO L130 BoogieDeclarations]: Found specification of procedure timeShift [2022-02-20 18:11:29,907 INFO L138 BoogieDeclarations]: Found implementation of procedure timeShift [2022-02-20 18:11:29,907 INFO L130 BoogieDeclarations]: Found specification of procedure waterRise [2022-02-20 18:11:29,907 INFO L138 BoogieDeclarations]: Found implementation of procedure waterRise [2022-02-20 18:11:29,908 INFO L130 BoogieDeclarations]: Found specification of procedure isPumpRunning [2022-02-20 18:11:29,908 INFO L138 BoogieDeclarations]: Found implementation of procedure isPumpRunning [2022-02-20 18:11:29,908 INFO L130 BoogieDeclarations]: Found specification of procedure write~init~int [2022-02-20 18:11:29,908 INFO L130 BoogieDeclarations]: Found specification of procedure changeMethaneLevel [2022-02-20 18:11:29,909 INFO L138 BoogieDeclarations]: Found implementation of procedure changeMethaneLevel [2022-02-20 18:11:29,909 INFO L130 BoogieDeclarations]: Found specification of procedure ULTIMATE.start [2022-02-20 18:11:29,909 INFO L138 BoogieDeclarations]: Found implementation of procedure ULTIMATE.start [2022-02-20 18:11:29,982 INFO L234 CfgBuilder]: Building ICFG [2022-02-20 18:11:29,983 INFO L260 CfgBuilder]: Building CFG for each procedure with an implementation [2022-02-20 18:11:30,219 INFO L275 CfgBuilder]: Performing block encoding [2022-02-20 18:11:30,225 INFO L294 CfgBuilder]: Using the 1 location(s) as analysis (start of procedure ULTIMATE.start) [2022-02-20 18:11:30,225 INFO L299 CfgBuilder]: Removed 2 assume(true) statements. [2022-02-20 18:11:30,226 INFO L202 PluginConnector]: Adding new model de.uni_freiburg.informatik.ultimate.plugins.generator.rcfgbuilder CFG 20.02 06:11:30 BoogieIcfgContainer [2022-02-20 18:11:30,227 INFO L132 PluginConnector]: ------------------------ END RCFGBuilder---------------------------- [2022-02-20 18:11:30,228 INFO L113 PluginConnector]: ------------------------TraceAbstraction---------------------------- [2022-02-20 18:11:30,228 INFO L271 PluginConnector]: Initializing TraceAbstraction... [2022-02-20 18:11:30,230 INFO L275 PluginConnector]: TraceAbstraction initialized [2022-02-20 18:11:30,231 INFO L185 PluginConnector]: Executing the observer TraceAbstractionObserver from plugin TraceAbstraction for "CDTParser AST 20.02 06:11:29" (1/3) ... [2022-02-20 18:11:30,231 INFO L205 PluginConnector]: Invalid model from TraceAbstraction for observer de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction.TraceAbstractionObserver@18c40d22 and model type de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction AST 20.02 06:11:30, skipping insertion in model container [2022-02-20 18:11:30,231 INFO L185 PluginConnector]: Executing the observer TraceAbstractionObserver from plugin TraceAbstraction for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 20.02 06:11:29" (2/3) ... [2022-02-20 18:11:30,232 INFO L205 PluginConnector]: Invalid model from TraceAbstraction for observer de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction.TraceAbstractionObserver@18c40d22 and model type de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction AST 20.02 06:11:30, skipping insertion in model container [2022-02-20 18:11:30,232 INFO L185 PluginConnector]: Executing the observer TraceAbstractionObserver from plugin TraceAbstraction for "de.uni_freiburg.informatik.ultimate.plugins.generator.rcfgbuilder CFG 20.02 06:11:30" (3/3) ... [2022-02-20 18:11:30,233 INFO L111 eAbstractionObserver]: Analyzing ICFG minepump_spec5_product04.cil.c [2022-02-20 18:11:30,237 INFO L205 ceAbstractionStarter]: Automizer settings: Hoare:true NWA Interpolation:FPandBP Determinization: PREDICATE_ABSTRACTION [2022-02-20 18:11:30,237 INFO L164 ceAbstractionStarter]: Applying trace abstraction to program that has 1 error locations. [2022-02-20 18:11:30,279 INFO L338 AbstractCegarLoop]: ======== Iteration 0 == of CEGAR loop == AllErrorsAtOnce ======== [2022-02-20 18:11:30,286 INFO L339 AbstractCegarLoop]: Settings: SEPARATE_VIOLATION_CHECK=true, mInterprocedural=true, mMaxIterations=1000000, mWatchIteration=1000000, mArtifact=RCFG, mInterpolation=FPandBP, mInterpolantAutomaton=STRAIGHT_LINE, mDumpAutomata=false, mAutomataFormat=ATS_NUMERATE, mDumpPath=., mDeterminiation=PREDICATE_ABSTRACTION, mMinimize=MINIMIZE_SEVPA, mHoare=true, mAutomataTypeConcurrency=PETRI_NET, mHoareTripleChecks=INCREMENTAL, mHoareAnnotationPositions=LoopsAndPotentialCycles, mDumpOnlyReuseAutomata=false, mLimitTraceHistogram=0, mErrorLocTimeLimit=0, mLimitPathProgramCount=0, mCollectInterpolantStatistics=true, mHeuristicEmptinessCheck=false, mHeuristicEmptinessCheckAStarHeuristic=ZERO, mHeuristicEmptinessCheckAStarHeuristicRandomSeed=1337, mHeuristicEmptinessCheckSmtFeatureScoringMethod=DAGSIZE, mSMTFeatureExtraction=false, mSMTFeatureExtractionDumpPath=., mOverrideInterpolantAutomaton=false, mMcrInterpolantMethod=WP, mLoopAccelerationTechnique=FAST_UPR [2022-02-20 18:11:30,286 INFO L340 AbstractCegarLoop]: Starting to check reachability of 1 error locations. [2022-02-20 18:11:30,317 INFO L276 IsEmpty]: Start isEmpty. Operand has 73 states, 58 states have (on average 1.3620689655172413) internal successors, (79), 62 states have internal predecessors, (79), 8 states have call successors, (8), 5 states have call predecessors, (8), 5 states have return successors, (8), 8 states have call predecessors, (8), 8 states have call successors, (8) [2022-02-20 18:11:30,323 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 33 [2022-02-20 18:11:30,324 INFO L506 BasicCegarLoop]: Found error trace [2022-02-20 18:11:30,325 INFO L514 BasicCegarLoop]: trace histogram [2, 2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-02-20 18:11:30,325 INFO L402 AbstractCegarLoop]: === Iteration 1 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2022-02-20 18:11:30,329 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2022-02-20 18:11:30,330 INFO L85 PathProgramCache]: Analyzing trace with hash -1691668141, now seen corresponding path program 1 times [2022-02-20 18:11:30,337 INFO L126 FreeRefinementEngine]: Executing refinement strategy CAMEL [2022-02-20 18:11:30,338 INFO L338 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [1423802808] [2022-02-20 18:11:30,338 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-02-20 18:11:30,338 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2022-02-20 18:11:30,516 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-02-20 18:11:30,583 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 13 [2022-02-20 18:11:30,589 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-02-20 18:11:30,604 INFO L290 TraceCheckUtils]: 0: Hoare triple {76#true} havoc ~retValue_acc~1;~retValue_acc~1 := ~pumpRunning~0;#res := ~retValue_acc~1; {76#true} is VALID [2022-02-20 18:11:30,605 INFO L290 TraceCheckUtils]: 1: Hoare triple {76#true} assume true; {76#true} is VALID [2022-02-20 18:11:30,606 INFO L284 TraceCheckUtils]: 2: Hoare quadruple {76#true} {77#false} #194#return; {77#false} is VALID [2022-02-20 18:11:30,607 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 24 [2022-02-20 18:11:30,615 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-02-20 18:11:30,628 INFO L290 TraceCheckUtils]: 0: Hoare triple {76#true} havoc ~retValue_acc~1;~retValue_acc~1 := ~pumpRunning~0;#res := ~retValue_acc~1; {76#true} is VALID [2022-02-20 18:11:30,629 INFO L290 TraceCheckUtils]: 1: Hoare triple {76#true} assume true; {76#true} is VALID [2022-02-20 18:11:30,631 INFO L284 TraceCheckUtils]: 2: Hoare quadruple {76#true} {77#false} #196#return; {77#false} is VALID [2022-02-20 18:11:30,632 INFO L290 TraceCheckUtils]: 0: Hoare triple {76#true} assume { :begin_inline_ULTIMATE.init } true;#NULL.base, #NULL.offset := 0, 0;assume 0 == #valid[0];assume 0 < #StackHeapBarrier;call #Ultimate.allocInit(2, 1);call write~init~int(48, 1, 0, 1);call write~init~int(0, 1, 1, 1);call #Ultimate.allocInit(31, 2);call #Ultimate.allocInit(12, 3);call #Ultimate.allocInit(13, 4);call #Ultimate.allocInit(3, 5);call write~init~int(79, 5, 0, 1);call write~init~int(110, 5, 1, 1);call write~init~int(0, 5, 2, 1);call #Ultimate.allocInit(4, 6);call write~init~int(79, 6, 0, 1);call write~init~int(102, 6, 1, 1);call write~init~int(102, 6, 2, 1);call write~init~int(0, 6, 3, 1);call #Ultimate.allocInit(7, 7);call write~init~int(44, 7, 0, 1);call write~init~int(80, 7, 1, 1);call write~init~int(117, 7, 2, 1);call write~init~int(109, 7, 3, 1);call write~init~int(112, 7, 4, 1);call write~init~int(58, 7, 5, 1);call write~init~int(0, 7, 6, 1);call #Ultimate.allocInit(3, 8);call write~init~int(79, 8, 0, 1);call write~init~int(110, 8, 1, 1);call write~init~int(0, 8, 2, 1);call #Ultimate.allocInit(4, 9);call write~init~int(79, 9, 0, 1);call write~init~int(102, 9, 1, 1);call write~init~int(102, 9, 2, 1);call write~init~int(0, 9, 3, 1);call #Ultimate.allocInit(3, 10);call write~init~int(41, 10, 0, 1);call write~init~int(32, 10, 1, 1);call write~init~int(0, 10, 2, 1);call #Ultimate.allocInit(2, 11);call write~init~int(10, 11, 0, 1);call write~init~int(0, 11, 1, 1);call #Ultimate.allocInit(30, 12);call #Ultimate.allocInit(9, 13);call #Ultimate.allocInit(21, 14);call #Ultimate.allocInit(30, 15);call #Ultimate.allocInit(9, 16);call #Ultimate.allocInit(21, 17);call #Ultimate.allocInit(30, 18);call #Ultimate.allocInit(9, 19);call #Ultimate.allocInit(25, 20);call #Ultimate.allocInit(30, 21);call #Ultimate.allocInit(9, 22);call #Ultimate.allocInit(25, 23);call #Ultimate.allocInit(13, 24);call #Ultimate.allocInit(7, 25);call write~init~int(44, 25, 0, 1);call write~init~int(77, 25, 1, 1);call write~init~int(101, 25, 2, 1);call write~init~int(116, 25, 3, 1);call write~init~int(104, 25, 4, 1);call write~init~int(58, 25, 5, 1);call write~init~int(0, 25, 6, 1);call #Ultimate.allocInit(5, 26);call write~init~int(67, 26, 0, 1);call write~init~int(82, 26, 1, 1);call write~init~int(73, 26, 2, 1);call write~init~int(84, 26, 3, 1);call write~init~int(0, 26, 4, 1);call #Ultimate.allocInit(3, 27);call write~init~int(79, 27, 0, 1);call write~init~int(75, 27, 1, 1);call write~init~int(0, 27, 2, 1);call #Ultimate.allocInit(2, 28);call write~init~int(41, 28, 0, 1);call write~init~int(0, 28, 1, 1);~switchedOnBeforeTS~0 := 0;~pumpRunning~0 := 0;~systemActive~0 := 1;~head~0.base, ~head~0.offset := 0, 0;~waterLevel~0 := 1;~methaneLevelCritical~0 := 0;~cleanupTimeShifts~0 := 4; {76#true} is VALID [2022-02-20 18:11:30,632 INFO L290 TraceCheckUtils]: 1: Hoare triple {76#true} assume { :end_inline_ULTIMATE.init } true;assume { :begin_inline_main } true;havoc main_#res#1;havoc main_#t~ret48#1, main_~retValue_acc~7#1, main_~tmp~5#1;havoc main_~retValue_acc~7#1;havoc main_~tmp~5#1;assume { :begin_inline_select_helpers } true; {76#true} is VALID [2022-02-20 18:11:30,632 INFO L290 TraceCheckUtils]: 2: Hoare triple {76#true} assume { :end_inline_select_helpers } true;assume { :begin_inline_select_features } true; {76#true} is VALID [2022-02-20 18:11:30,633 INFO L290 TraceCheckUtils]: 3: Hoare triple {76#true} assume { :end_inline_select_features } true;assume { :begin_inline_valid_product } true;havoc valid_product_#res#1;havoc valid_product_~retValue_acc~9#1;havoc valid_product_~retValue_acc~9#1;valid_product_~retValue_acc~9#1 := 1;valid_product_#res#1 := valid_product_~retValue_acc~9#1; {76#true} is VALID [2022-02-20 18:11:30,633 INFO L290 TraceCheckUtils]: 4: Hoare triple {76#true} main_#t~ret48#1 := valid_product_#res#1;assume { :end_inline_valid_product } true;assume -2147483648 <= main_#t~ret48#1 && main_#t~ret48#1 <= 2147483647;main_~tmp~5#1 := main_#t~ret48#1;havoc main_#t~ret48#1; {76#true} is VALID [2022-02-20 18:11:30,633 INFO L290 TraceCheckUtils]: 5: Hoare triple {76#true} assume 0 != main_~tmp~5#1;assume { :begin_inline_setup } true; {76#true} is VALID [2022-02-20 18:11:30,633 INFO L290 TraceCheckUtils]: 6: Hoare triple {76#true} assume { :end_inline_setup } true;assume { :begin_inline_runTest } true;assume { :begin_inline___utac_acc__Specification5_spec__1 } true;~switchedOnBeforeTS~0 := 0; {76#true} is VALID [2022-02-20 18:11:30,638 INFO L290 TraceCheckUtils]: 7: Hoare triple {76#true} assume { :end_inline___utac_acc__Specification5_spec__1 } true;assume { :begin_inline_test } true;havoc test_#t~nondet7#1, test_#t~nondet8#1, test_#t~nondet9#1, test_#t~nondet10#1, test_~splverifierCounter~0#1, test_~tmp~1#1, test_~tmp___0~1#1, test_~tmp___1~0#1, test_~tmp___2~0#1;havoc test_~splverifierCounter~0#1;havoc test_~tmp~1#1;havoc test_~tmp___0~1#1;havoc test_~tmp___1~0#1;havoc test_~tmp___2~0#1;test_~splverifierCounter~0#1 := 0; {76#true} is VALID [2022-02-20 18:11:30,639 INFO L290 TraceCheckUtils]: 8: Hoare triple {76#true} assume false; {77#false} is VALID [2022-02-20 18:11:30,639 INFO L272 TraceCheckUtils]: 9: Hoare triple {77#false} call cleanup(); {77#false} is VALID [2022-02-20 18:11:30,639 INFO L290 TraceCheckUtils]: 10: Hoare triple {77#false} havoc ~i~0;havoc ~__cil_tmp2~0; {77#false} is VALID [2022-02-20 18:11:30,640 INFO L272 TraceCheckUtils]: 11: Hoare triple {77#false} call timeShift(); {77#false} is VALID [2022-02-20 18:11:30,640 INFO L290 TraceCheckUtils]: 12: Hoare triple {77#false} assume { :begin_inline___utac_acc__Specification5_spec__2 } true;havoc __utac_acc__Specification5_spec__2_#t~ret4#1; {77#false} is VALID [2022-02-20 18:11:30,640 INFO L272 TraceCheckUtils]: 13: Hoare triple {77#false} call __utac_acc__Specification5_spec__2_#t~ret4#1 := isPumpRunning(); {76#true} is VALID [2022-02-20 18:11:30,640 INFO L290 TraceCheckUtils]: 14: Hoare triple {76#true} havoc ~retValue_acc~1;~retValue_acc~1 := ~pumpRunning~0;#res := ~retValue_acc~1; {76#true} is VALID [2022-02-20 18:11:30,641 INFO L290 TraceCheckUtils]: 15: Hoare triple {76#true} assume true; {76#true} is VALID [2022-02-20 18:11:30,641 INFO L284 TraceCheckUtils]: 16: Hoare quadruple {76#true} {77#false} #194#return; {77#false} is VALID [2022-02-20 18:11:30,641 INFO L290 TraceCheckUtils]: 17: Hoare triple {77#false} assume -2147483648 <= __utac_acc__Specification5_spec__2_#t~ret4#1 && __utac_acc__Specification5_spec__2_#t~ret4#1 <= 2147483647;~switchedOnBeforeTS~0 := __utac_acc__Specification5_spec__2_#t~ret4#1;havoc __utac_acc__Specification5_spec__2_#t~ret4#1; {77#false} is VALID [2022-02-20 18:11:30,641 INFO L290 TraceCheckUtils]: 18: Hoare triple {77#false} assume { :end_inline___utac_acc__Specification5_spec__2 } true; {77#false} is VALID [2022-02-20 18:11:30,641 INFO L290 TraceCheckUtils]: 19: Hoare triple {77#false} assume !(0 != ~pumpRunning~0); {77#false} is VALID [2022-02-20 18:11:30,642 INFO L290 TraceCheckUtils]: 20: Hoare triple {77#false} assume !(0 != ~systemActive~0); {77#false} is VALID [2022-02-20 18:11:30,642 INFO L290 TraceCheckUtils]: 21: Hoare triple {77#false} assume { :begin_inline___utac_acc__Specification5_spec__3 } true;havoc __utac_acc__Specification5_spec__3_#t~ret5#1, __utac_acc__Specification5_spec__3_#t~ret6#1, __utac_acc__Specification5_spec__3_~tmp~0#1, __utac_acc__Specification5_spec__3_~tmp___0~0#1;havoc __utac_acc__Specification5_spec__3_~tmp~0#1;havoc __utac_acc__Specification5_spec__3_~tmp___0~0#1;assume { :begin_inline_getWaterLevel } true;havoc getWaterLevel_#res#1;havoc getWaterLevel_~retValue_acc~6#1;havoc getWaterLevel_~retValue_acc~6#1;getWaterLevel_~retValue_acc~6#1 := ~waterLevel~0;getWaterLevel_#res#1 := getWaterLevel_~retValue_acc~6#1; {77#false} is VALID [2022-02-20 18:11:30,642 INFO L290 TraceCheckUtils]: 22: Hoare triple {77#false} __utac_acc__Specification5_spec__3_#t~ret5#1 := getWaterLevel_#res#1;assume { :end_inline_getWaterLevel } true;assume -2147483648 <= __utac_acc__Specification5_spec__3_#t~ret5#1 && __utac_acc__Specification5_spec__3_#t~ret5#1 <= 2147483647;__utac_acc__Specification5_spec__3_~tmp~0#1 := __utac_acc__Specification5_spec__3_#t~ret5#1;havoc __utac_acc__Specification5_spec__3_#t~ret5#1; {77#false} is VALID [2022-02-20 18:11:30,642 INFO L290 TraceCheckUtils]: 23: Hoare triple {77#false} assume 2 != __utac_acc__Specification5_spec__3_~tmp~0#1; {77#false} is VALID [2022-02-20 18:11:30,643 INFO L272 TraceCheckUtils]: 24: Hoare triple {77#false} call __utac_acc__Specification5_spec__3_#t~ret6#1 := isPumpRunning(); {76#true} is VALID [2022-02-20 18:11:30,643 INFO L290 TraceCheckUtils]: 25: Hoare triple {76#true} havoc ~retValue_acc~1;~retValue_acc~1 := ~pumpRunning~0;#res := ~retValue_acc~1; {76#true} is VALID [2022-02-20 18:11:30,643 INFO L290 TraceCheckUtils]: 26: Hoare triple {76#true} assume true; {76#true} is VALID [2022-02-20 18:11:30,645 INFO L284 TraceCheckUtils]: 27: Hoare quadruple {76#true} {77#false} #196#return; {77#false} is VALID [2022-02-20 18:11:30,645 INFO L290 TraceCheckUtils]: 28: Hoare triple {77#false} assume -2147483648 <= __utac_acc__Specification5_spec__3_#t~ret6#1 && __utac_acc__Specification5_spec__3_#t~ret6#1 <= 2147483647;__utac_acc__Specification5_spec__3_~tmp___0~0#1 := __utac_acc__Specification5_spec__3_#t~ret6#1;havoc __utac_acc__Specification5_spec__3_#t~ret6#1; {77#false} is VALID [2022-02-20 18:11:30,645 INFO L290 TraceCheckUtils]: 29: Hoare triple {77#false} assume 0 != __utac_acc__Specification5_spec__3_~tmp___0~0#1; {77#false} is VALID [2022-02-20 18:11:30,645 INFO L290 TraceCheckUtils]: 30: Hoare triple {77#false} assume 0 == ~switchedOnBeforeTS~0;assume { :begin_inline___automaton_fail } true; {77#false} is VALID [2022-02-20 18:11:30,646 INFO L290 TraceCheckUtils]: 31: Hoare triple {77#false} assume !false; {77#false} is VALID [2022-02-20 18:11:30,646 INFO L134 CoverageAnalysis]: Checked inductivity of 3 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 3 trivial. 0 not checked. [2022-02-20 18:11:30,647 INFO L144 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2022-02-20 18:11:30,647 INFO L338 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [1423802808] [2022-02-20 18:11:30,648 INFO L165 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [1423802808] provided 1 perfect and 0 imperfect interpolant sequences [2022-02-20 18:11:30,648 INFO L191 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2022-02-20 18:11:30,648 INFO L204 FreeRefinementEngine]: Number of different interpolants: perfect sequences [2] imperfect sequences [] total 2 [2022-02-20 18:11:30,650 INFO L118 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [1650653148] [2022-02-20 18:11:30,652 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2022-02-20 18:11:30,656 INFO L78 Accepts]: Start accepts. Automaton has has 2 states, 2 states have (on average 12.0) internal successors, (24), 2 states have internal predecessors, (24), 1 states have call successors, (4), 2 states have call predecessors, (4), 1 states have return successors, (2), 1 states have call predecessors, (2), 1 states have call successors, (2) Word has length 32 [2022-02-20 18:11:30,657 INFO L84 Accepts]: Finished accepts. word is accepted. [2022-02-20 18:11:30,660 INFO L86 InductivityCheck]: Starting indutivity check of a Floyd-Hoare automaton with has 2 states, 2 states have (on average 12.0) internal successors, (24), 2 states have internal predecessors, (24), 1 states have call successors, (4), 2 states have call predecessors, (4), 1 states have return successors, (2), 1 states have call predecessors, (2), 1 states have call successors, (2) [2022-02-20 18:11:30,706 INFO L122 InductivityCheck]: Floyd-Hoare automaton has 30 edges. 30 inductive. 0 not inductive. 0 times theorem prover too weak to decide inductivity. [2022-02-20 18:11:30,707 INFO L546 AbstractCegarLoop]: INTERPOLANT automaton has 2 states [2022-02-20 18:11:30,707 INFO L108 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2022-02-20 18:11:30,725 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 2 interpolants. [2022-02-20 18:11:30,727 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=1, Invalid=1, Unknown=0, NotChecked=0, Total=2 [2022-02-20 18:11:30,730 INFO L87 Difference]: Start difference. First operand has 73 states, 58 states have (on average 1.3620689655172413) internal successors, (79), 62 states have internal predecessors, (79), 8 states have call successors, (8), 5 states have call predecessors, (8), 5 states have return successors, (8), 8 states have call predecessors, (8), 8 states have call successors, (8) Second operand has 2 states, 2 states have (on average 12.0) internal successors, (24), 2 states have internal predecessors, (24), 1 states have call successors, (4), 2 states have call predecessors, (4), 1 states have return successors, (2), 1 states have call predecessors, (2), 1 states have call successors, (2) [2022-02-20 18:11:30,837 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-02-20 18:11:30,838 INFO L93 Difference]: Finished difference Result 137 states and 184 transitions. [2022-02-20 18:11:30,839 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 2 states. [2022-02-20 18:11:30,839 INFO L78 Accepts]: Start accepts. Automaton has has 2 states, 2 states have (on average 12.0) internal successors, (24), 2 states have internal predecessors, (24), 1 states have call successors, (4), 2 states have call predecessors, (4), 1 states have return successors, (2), 1 states have call predecessors, (2), 1 states have call successors, (2) Word has length 32 [2022-02-20 18:11:30,839 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2022-02-20 18:11:30,841 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 2 states, 2 states have (on average 12.0) internal successors, (24), 2 states have internal predecessors, (24), 1 states have call successors, (4), 2 states have call predecessors, (4), 1 states have return successors, (2), 1 states have call predecessors, (2), 1 states have call successors, (2) [2022-02-20 18:11:30,855 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 2 states to 2 states and 184 transitions. [2022-02-20 18:11:30,855 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 2 states, 2 states have (on average 12.0) internal successors, (24), 2 states have internal predecessors, (24), 1 states have call successors, (4), 2 states have call predecessors, (4), 1 states have return successors, (2), 1 states have call predecessors, (2), 1 states have call successors, (2) [2022-02-20 18:11:30,863 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 2 states to 2 states and 184 transitions. [2022-02-20 18:11:30,864 INFO L86 InductivityCheck]: Starting indutivity check of a Floyd-Hoare automaton with 2 states and 184 transitions. [2022-02-20 18:11:31,011 INFO L122 InductivityCheck]: Floyd-Hoare automaton has 184 edges. 184 inductive. 0 not inductive. 0 times theorem prover too weak to decide inductivity. [2022-02-20 18:11:31,021 INFO L225 Difference]: With dead ends: 137 [2022-02-20 18:11:31,021 INFO L226 Difference]: Without dead ends: 64 [2022-02-20 18:11:31,024 INFO L932 BasicCegarLoop]: 0 DeclaredPredicates, 6 GetRequests, 6 SyntacticMatches, 0 SemanticMatches, 0 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 0 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=1, Invalid=1, Unknown=0, NotChecked=0, Total=2 [2022-02-20 18:11:31,026 INFO L933 BasicCegarLoop]: 89 mSDtfsCounter, 0 mSDsluCounter, 0 mSDsCounter, 0 mSdLazyCounter, 0 mSolverCounterSat, 0 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.0s Time, 0 mProtectedPredicate, 0 mProtectedAction, 0 SdHoareTripleChecker+Valid, 89 SdHoareTripleChecker+Invalid, 0 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 0 IncrementalHoareTripleChecker+Valid, 0 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.0s IncrementalHoareTripleChecker+Time [2022-02-20 18:11:31,027 INFO L934 BasicCegarLoop]: SdHoareTripleChecker [0 Valid, 89 Invalid, 0 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [0 Valid, 0 Invalid, 0 Unknown, 0 Unchecked, 0.0s Time] [2022-02-20 18:11:31,040 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 64 states. [2022-02-20 18:11:31,053 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 64 to 64. [2022-02-20 18:11:31,053 INFO L214 AbstractMinimizeNwa]: Start testing correctness of minimizeSevpa [2022-02-20 18:11:31,054 INFO L82 GeneralOperation]: Start isEquivalent. First operand 64 states. Second operand has 64 states, 51 states have (on average 1.2745098039215685) internal successors, (65), 54 states have internal predecessors, (65), 8 states have call successors, (8), 5 states have call predecessors, (8), 4 states have return successors, (7), 7 states have call predecessors, (7), 7 states have call successors, (7) [2022-02-20 18:11:31,055 INFO L74 IsIncluded]: Start isIncluded. First operand 64 states. Second operand has 64 states, 51 states have (on average 1.2745098039215685) internal successors, (65), 54 states have internal predecessors, (65), 8 states have call successors, (8), 5 states have call predecessors, (8), 4 states have return successors, (7), 7 states have call predecessors, (7), 7 states have call successors, (7) [2022-02-20 18:11:31,055 INFO L87 Difference]: Start difference. First operand 64 states. Second operand has 64 states, 51 states have (on average 1.2745098039215685) internal successors, (65), 54 states have internal predecessors, (65), 8 states have call successors, (8), 5 states have call predecessors, (8), 4 states have return successors, (7), 7 states have call predecessors, (7), 7 states have call successors, (7) [2022-02-20 18:11:31,061 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-02-20 18:11:31,061 INFO L93 Difference]: Finished difference Result 64 states and 80 transitions. [2022-02-20 18:11:31,061 INFO L276 IsEmpty]: Start isEmpty. Operand 64 states and 80 transitions. [2022-02-20 18:11:31,062 INFO L282 IsEmpty]: Finished isEmpty. No accepting run. [2022-02-20 18:11:31,062 INFO L83 IsIncluded]: Finished isIncluded. Language is included [2022-02-20 18:11:31,063 INFO L74 IsIncluded]: Start isIncluded. First operand has 64 states, 51 states have (on average 1.2745098039215685) internal successors, (65), 54 states have internal predecessors, (65), 8 states have call successors, (8), 5 states have call predecessors, (8), 4 states have return successors, (7), 7 states have call predecessors, (7), 7 states have call successors, (7) Second operand 64 states. [2022-02-20 18:11:31,063 INFO L87 Difference]: Start difference. First operand has 64 states, 51 states have (on average 1.2745098039215685) internal successors, (65), 54 states have internal predecessors, (65), 8 states have call successors, (8), 5 states have call predecessors, (8), 4 states have return successors, (7), 7 states have call predecessors, (7), 7 states have call successors, (7) Second operand 64 states. [2022-02-20 18:11:31,067 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-02-20 18:11:31,067 INFO L93 Difference]: Finished difference Result 64 states and 80 transitions. [2022-02-20 18:11:31,067 INFO L276 IsEmpty]: Start isEmpty. Operand 64 states and 80 transitions. [2022-02-20 18:11:31,068 INFO L282 IsEmpty]: Finished isEmpty. No accepting run. [2022-02-20 18:11:31,068 INFO L83 IsIncluded]: Finished isIncluded. Language is included [2022-02-20 18:11:31,068 INFO L88 GeneralOperation]: Finished isEquivalent. [2022-02-20 18:11:31,069 INFO L221 AbstractMinimizeNwa]: Finished testing correctness of minimizeSevpa [2022-02-20 18:11:31,069 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 64 states, 51 states have (on average 1.2745098039215685) internal successors, (65), 54 states have internal predecessors, (65), 8 states have call successors, (8), 5 states have call predecessors, (8), 4 states have return successors, (7), 7 states have call predecessors, (7), 7 states have call successors, (7) [2022-02-20 18:11:31,072 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 64 states to 64 states and 80 transitions. [2022-02-20 18:11:31,073 INFO L78 Accepts]: Start accepts. Automaton has 64 states and 80 transitions. Word has length 32 [2022-02-20 18:11:31,073 INFO L84 Accepts]: Finished accepts. word is rejected. [2022-02-20 18:11:31,073 INFO L470 AbstractCegarLoop]: Abstraction has 64 states and 80 transitions. [2022-02-20 18:11:31,074 INFO L471 AbstractCegarLoop]: INTERPOLANT automaton has has 2 states, 2 states have (on average 12.0) internal successors, (24), 2 states have internal predecessors, (24), 1 states have call successors, (4), 2 states have call predecessors, (4), 1 states have return successors, (2), 1 states have call predecessors, (2), 1 states have call successors, (2) [2022-02-20 18:11:31,074 INFO L276 IsEmpty]: Start isEmpty. Operand 64 states and 80 transitions. [2022-02-20 18:11:31,075 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 34 [2022-02-20 18:11:31,075 INFO L506 BasicCegarLoop]: Found error trace [2022-02-20 18:11:31,075 INFO L514 BasicCegarLoop]: trace histogram [2, 2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-02-20 18:11:31,076 WARN L452 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable0 [2022-02-20 18:11:31,076 INFO L402 AbstractCegarLoop]: === Iteration 2 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2022-02-20 18:11:31,076 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2022-02-20 18:11:31,077 INFO L85 PathProgramCache]: Analyzing trace with hash 1926580266, now seen corresponding path program 1 times [2022-02-20 18:11:31,077 INFO L126 FreeRefinementEngine]: Executing refinement strategy CAMEL [2022-02-20 18:11:31,077 INFO L338 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [729357993] [2022-02-20 18:11:31,077 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-02-20 18:11:31,077 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2022-02-20 18:11:31,100 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-02-20 18:11:31,126 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 14 [2022-02-20 18:11:31,128 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-02-20 18:11:31,130 INFO L290 TraceCheckUtils]: 0: Hoare triple {503#true} havoc ~retValue_acc~1;~retValue_acc~1 := ~pumpRunning~0;#res := ~retValue_acc~1; {503#true} is VALID [2022-02-20 18:11:31,130 INFO L290 TraceCheckUtils]: 1: Hoare triple {503#true} assume true; {503#true} is VALID [2022-02-20 18:11:31,131 INFO L284 TraceCheckUtils]: 2: Hoare quadruple {503#true} {504#false} #194#return; {504#false} is VALID [2022-02-20 18:11:31,131 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 25 [2022-02-20 18:11:31,132 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-02-20 18:11:31,134 INFO L290 TraceCheckUtils]: 0: Hoare triple {503#true} havoc ~retValue_acc~1;~retValue_acc~1 := ~pumpRunning~0;#res := ~retValue_acc~1; {503#true} is VALID [2022-02-20 18:11:31,135 INFO L290 TraceCheckUtils]: 1: Hoare triple {503#true} assume true; {503#true} is VALID [2022-02-20 18:11:31,135 INFO L284 TraceCheckUtils]: 2: Hoare quadruple {503#true} {504#false} #196#return; {504#false} is VALID [2022-02-20 18:11:31,135 INFO L290 TraceCheckUtils]: 0: Hoare triple {503#true} assume { :begin_inline_ULTIMATE.init } true;#NULL.base, #NULL.offset := 0, 0;assume 0 == #valid[0];assume 0 < #StackHeapBarrier;call #Ultimate.allocInit(2, 1);call write~init~int(48, 1, 0, 1);call write~init~int(0, 1, 1, 1);call #Ultimate.allocInit(31, 2);call #Ultimate.allocInit(12, 3);call #Ultimate.allocInit(13, 4);call #Ultimate.allocInit(3, 5);call write~init~int(79, 5, 0, 1);call write~init~int(110, 5, 1, 1);call write~init~int(0, 5, 2, 1);call #Ultimate.allocInit(4, 6);call write~init~int(79, 6, 0, 1);call write~init~int(102, 6, 1, 1);call write~init~int(102, 6, 2, 1);call write~init~int(0, 6, 3, 1);call #Ultimate.allocInit(7, 7);call write~init~int(44, 7, 0, 1);call write~init~int(80, 7, 1, 1);call write~init~int(117, 7, 2, 1);call write~init~int(109, 7, 3, 1);call write~init~int(112, 7, 4, 1);call write~init~int(58, 7, 5, 1);call write~init~int(0, 7, 6, 1);call #Ultimate.allocInit(3, 8);call write~init~int(79, 8, 0, 1);call write~init~int(110, 8, 1, 1);call write~init~int(0, 8, 2, 1);call #Ultimate.allocInit(4, 9);call write~init~int(79, 9, 0, 1);call write~init~int(102, 9, 1, 1);call write~init~int(102, 9, 2, 1);call write~init~int(0, 9, 3, 1);call #Ultimate.allocInit(3, 10);call write~init~int(41, 10, 0, 1);call write~init~int(32, 10, 1, 1);call write~init~int(0, 10, 2, 1);call #Ultimate.allocInit(2, 11);call write~init~int(10, 11, 0, 1);call write~init~int(0, 11, 1, 1);call #Ultimate.allocInit(30, 12);call #Ultimate.allocInit(9, 13);call #Ultimate.allocInit(21, 14);call #Ultimate.allocInit(30, 15);call #Ultimate.allocInit(9, 16);call #Ultimate.allocInit(21, 17);call #Ultimate.allocInit(30, 18);call #Ultimate.allocInit(9, 19);call #Ultimate.allocInit(25, 20);call #Ultimate.allocInit(30, 21);call #Ultimate.allocInit(9, 22);call #Ultimate.allocInit(25, 23);call #Ultimate.allocInit(13, 24);call #Ultimate.allocInit(7, 25);call write~init~int(44, 25, 0, 1);call write~init~int(77, 25, 1, 1);call write~init~int(101, 25, 2, 1);call write~init~int(116, 25, 3, 1);call write~init~int(104, 25, 4, 1);call write~init~int(58, 25, 5, 1);call write~init~int(0, 25, 6, 1);call #Ultimate.allocInit(5, 26);call write~init~int(67, 26, 0, 1);call write~init~int(82, 26, 1, 1);call write~init~int(73, 26, 2, 1);call write~init~int(84, 26, 3, 1);call write~init~int(0, 26, 4, 1);call #Ultimate.allocInit(3, 27);call write~init~int(79, 27, 0, 1);call write~init~int(75, 27, 1, 1);call write~init~int(0, 27, 2, 1);call #Ultimate.allocInit(2, 28);call write~init~int(41, 28, 0, 1);call write~init~int(0, 28, 1, 1);~switchedOnBeforeTS~0 := 0;~pumpRunning~0 := 0;~systemActive~0 := 1;~head~0.base, ~head~0.offset := 0, 0;~waterLevel~0 := 1;~methaneLevelCritical~0 := 0;~cleanupTimeShifts~0 := 4; {503#true} is VALID [2022-02-20 18:11:31,135 INFO L290 TraceCheckUtils]: 1: Hoare triple {503#true} assume { :end_inline_ULTIMATE.init } true;assume { :begin_inline_main } true;havoc main_#res#1;havoc main_#t~ret48#1, main_~retValue_acc~7#1, main_~tmp~5#1;havoc main_~retValue_acc~7#1;havoc main_~tmp~5#1;assume { :begin_inline_select_helpers } true; {503#true} is VALID [2022-02-20 18:11:31,136 INFO L290 TraceCheckUtils]: 2: Hoare triple {503#true} assume { :end_inline_select_helpers } true;assume { :begin_inline_select_features } true; {503#true} is VALID [2022-02-20 18:11:31,136 INFO L290 TraceCheckUtils]: 3: Hoare triple {503#true} assume { :end_inline_select_features } true;assume { :begin_inline_valid_product } true;havoc valid_product_#res#1;havoc valid_product_~retValue_acc~9#1;havoc valid_product_~retValue_acc~9#1;valid_product_~retValue_acc~9#1 := 1;valid_product_#res#1 := valid_product_~retValue_acc~9#1; {503#true} is VALID [2022-02-20 18:11:31,136 INFO L290 TraceCheckUtils]: 4: Hoare triple {503#true} main_#t~ret48#1 := valid_product_#res#1;assume { :end_inline_valid_product } true;assume -2147483648 <= main_#t~ret48#1 && main_#t~ret48#1 <= 2147483647;main_~tmp~5#1 := main_#t~ret48#1;havoc main_#t~ret48#1; {503#true} is VALID [2022-02-20 18:11:31,136 INFO L290 TraceCheckUtils]: 5: Hoare triple {503#true} assume 0 != main_~tmp~5#1;assume { :begin_inline_setup } true; {503#true} is VALID [2022-02-20 18:11:31,136 INFO L290 TraceCheckUtils]: 6: Hoare triple {503#true} assume { :end_inline_setup } true;assume { :begin_inline_runTest } true;assume { :begin_inline___utac_acc__Specification5_spec__1 } true;~switchedOnBeforeTS~0 := 0; {503#true} is VALID [2022-02-20 18:11:31,137 INFO L290 TraceCheckUtils]: 7: Hoare triple {503#true} assume { :end_inline___utac_acc__Specification5_spec__1 } true;assume { :begin_inline_test } true;havoc test_#t~nondet7#1, test_#t~nondet8#1, test_#t~nondet9#1, test_#t~nondet10#1, test_~splverifierCounter~0#1, test_~tmp~1#1, test_~tmp___0~1#1, test_~tmp___1~0#1, test_~tmp___2~0#1;havoc test_~splverifierCounter~0#1;havoc test_~tmp~1#1;havoc test_~tmp___0~1#1;havoc test_~tmp___1~0#1;havoc test_~tmp___2~0#1;test_~splverifierCounter~0#1 := 0; {505#(= |ULTIMATE.start_test_~splverifierCounter~0#1| 0)} is VALID [2022-02-20 18:11:31,137 INFO L290 TraceCheckUtils]: 8: Hoare triple {505#(= |ULTIMATE.start_test_~splverifierCounter~0#1| 0)} assume !false; {505#(= |ULTIMATE.start_test_~splverifierCounter~0#1| 0)} is VALID [2022-02-20 18:11:31,138 INFO L290 TraceCheckUtils]: 9: Hoare triple {505#(= |ULTIMATE.start_test_~splverifierCounter~0#1| 0)} assume !(test_~splverifierCounter~0#1 < 4); {504#false} is VALID [2022-02-20 18:11:31,138 INFO L272 TraceCheckUtils]: 10: Hoare triple {504#false} call cleanup(); {504#false} is VALID [2022-02-20 18:11:31,138 INFO L290 TraceCheckUtils]: 11: Hoare triple {504#false} havoc ~i~0;havoc ~__cil_tmp2~0; {504#false} is VALID [2022-02-20 18:11:31,138 INFO L272 TraceCheckUtils]: 12: Hoare triple {504#false} call timeShift(); {504#false} is VALID [2022-02-20 18:11:31,139 INFO L290 TraceCheckUtils]: 13: Hoare triple {504#false} assume { :begin_inline___utac_acc__Specification5_spec__2 } true;havoc __utac_acc__Specification5_spec__2_#t~ret4#1; {504#false} is VALID [2022-02-20 18:11:31,139 INFO L272 TraceCheckUtils]: 14: Hoare triple {504#false} call __utac_acc__Specification5_spec__2_#t~ret4#1 := isPumpRunning(); {503#true} is VALID [2022-02-20 18:11:31,139 INFO L290 TraceCheckUtils]: 15: Hoare triple {503#true} havoc ~retValue_acc~1;~retValue_acc~1 := ~pumpRunning~0;#res := ~retValue_acc~1; {503#true} is VALID [2022-02-20 18:11:31,139 INFO L290 TraceCheckUtils]: 16: Hoare triple {503#true} assume true; {503#true} is VALID [2022-02-20 18:11:31,139 INFO L284 TraceCheckUtils]: 17: Hoare quadruple {503#true} {504#false} #194#return; {504#false} is VALID [2022-02-20 18:11:31,140 INFO L290 TraceCheckUtils]: 18: Hoare triple {504#false} assume -2147483648 <= __utac_acc__Specification5_spec__2_#t~ret4#1 && __utac_acc__Specification5_spec__2_#t~ret4#1 <= 2147483647;~switchedOnBeforeTS~0 := __utac_acc__Specification5_spec__2_#t~ret4#1;havoc __utac_acc__Specification5_spec__2_#t~ret4#1; {504#false} is VALID [2022-02-20 18:11:31,140 INFO L290 TraceCheckUtils]: 19: Hoare triple {504#false} assume { :end_inline___utac_acc__Specification5_spec__2 } true; {504#false} is VALID [2022-02-20 18:11:31,140 INFO L290 TraceCheckUtils]: 20: Hoare triple {504#false} assume !(0 != ~pumpRunning~0); {504#false} is VALID [2022-02-20 18:11:31,140 INFO L290 TraceCheckUtils]: 21: Hoare triple {504#false} assume !(0 != ~systemActive~0); {504#false} is VALID [2022-02-20 18:11:31,140 INFO L290 TraceCheckUtils]: 22: Hoare triple {504#false} assume { :begin_inline___utac_acc__Specification5_spec__3 } true;havoc __utac_acc__Specification5_spec__3_#t~ret5#1, __utac_acc__Specification5_spec__3_#t~ret6#1, __utac_acc__Specification5_spec__3_~tmp~0#1, __utac_acc__Specification5_spec__3_~tmp___0~0#1;havoc __utac_acc__Specification5_spec__3_~tmp~0#1;havoc __utac_acc__Specification5_spec__3_~tmp___0~0#1;assume { :begin_inline_getWaterLevel } true;havoc getWaterLevel_#res#1;havoc getWaterLevel_~retValue_acc~6#1;havoc getWaterLevel_~retValue_acc~6#1;getWaterLevel_~retValue_acc~6#1 := ~waterLevel~0;getWaterLevel_#res#1 := getWaterLevel_~retValue_acc~6#1; {504#false} is VALID [2022-02-20 18:11:31,140 INFO L290 TraceCheckUtils]: 23: Hoare triple {504#false} __utac_acc__Specification5_spec__3_#t~ret5#1 := getWaterLevel_#res#1;assume { :end_inline_getWaterLevel } true;assume -2147483648 <= __utac_acc__Specification5_spec__3_#t~ret5#1 && __utac_acc__Specification5_spec__3_#t~ret5#1 <= 2147483647;__utac_acc__Specification5_spec__3_~tmp~0#1 := __utac_acc__Specification5_spec__3_#t~ret5#1;havoc __utac_acc__Specification5_spec__3_#t~ret5#1; {504#false} is VALID [2022-02-20 18:11:31,141 INFO L290 TraceCheckUtils]: 24: Hoare triple {504#false} assume 2 != __utac_acc__Specification5_spec__3_~tmp~0#1; {504#false} is VALID [2022-02-20 18:11:31,141 INFO L272 TraceCheckUtils]: 25: Hoare triple {504#false} call __utac_acc__Specification5_spec__3_#t~ret6#1 := isPumpRunning(); {503#true} is VALID [2022-02-20 18:11:31,141 INFO L290 TraceCheckUtils]: 26: Hoare triple {503#true} havoc ~retValue_acc~1;~retValue_acc~1 := ~pumpRunning~0;#res := ~retValue_acc~1; {503#true} is VALID [2022-02-20 18:11:31,141 INFO L290 TraceCheckUtils]: 27: Hoare triple {503#true} assume true; {503#true} is VALID [2022-02-20 18:11:31,141 INFO L284 TraceCheckUtils]: 28: Hoare quadruple {503#true} {504#false} #196#return; {504#false} is VALID [2022-02-20 18:11:31,142 INFO L290 TraceCheckUtils]: 29: Hoare triple {504#false} assume -2147483648 <= __utac_acc__Specification5_spec__3_#t~ret6#1 && __utac_acc__Specification5_spec__3_#t~ret6#1 <= 2147483647;__utac_acc__Specification5_spec__3_~tmp___0~0#1 := __utac_acc__Specification5_spec__3_#t~ret6#1;havoc __utac_acc__Specification5_spec__3_#t~ret6#1; {504#false} is VALID [2022-02-20 18:11:31,142 INFO L290 TraceCheckUtils]: 30: Hoare triple {504#false} assume 0 != __utac_acc__Specification5_spec__3_~tmp___0~0#1; {504#false} is VALID [2022-02-20 18:11:31,142 INFO L290 TraceCheckUtils]: 31: Hoare triple {504#false} assume 0 == ~switchedOnBeforeTS~0;assume { :begin_inline___automaton_fail } true; {504#false} is VALID [2022-02-20 18:11:31,142 INFO L290 TraceCheckUtils]: 32: Hoare triple {504#false} assume !false; {504#false} is VALID [2022-02-20 18:11:31,143 INFO L134 CoverageAnalysis]: Checked inductivity of 3 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 3 trivial. 0 not checked. [2022-02-20 18:11:31,143 INFO L144 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2022-02-20 18:11:31,143 INFO L338 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [729357993] [2022-02-20 18:11:31,143 INFO L165 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [729357993] provided 1 perfect and 0 imperfect interpolant sequences [2022-02-20 18:11:31,143 INFO L191 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2022-02-20 18:11:31,143 INFO L204 FreeRefinementEngine]: Number of different interpolants: perfect sequences [3] imperfect sequences [] total 3 [2022-02-20 18:11:31,144 INFO L118 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [36700295] [2022-02-20 18:11:31,144 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2022-02-20 18:11:31,145 INFO L78 Accepts]: Start accepts. Automaton has has 3 states, 3 states have (on average 8.333333333333334) internal successors, (25), 3 states have internal predecessors, (25), 1 states have call successors, (4), 2 states have call predecessors, (4), 1 states have return successors, (2), 1 states have call predecessors, (2), 1 states have call successors, (2) Word has length 33 [2022-02-20 18:11:31,145 INFO L84 Accepts]: Finished accepts. word is accepted. [2022-02-20 18:11:31,146 INFO L86 InductivityCheck]: Starting indutivity check of a Floyd-Hoare automaton with has 3 states, 3 states have (on average 8.333333333333334) internal successors, (25), 3 states have internal predecessors, (25), 1 states have call successors, (4), 2 states have call predecessors, (4), 1 states have return successors, (2), 1 states have call predecessors, (2), 1 states have call successors, (2) [2022-02-20 18:11:31,166 INFO L122 InductivityCheck]: Floyd-Hoare automaton has 31 edges. 31 inductive. 0 not inductive. 0 times theorem prover too weak to decide inductivity. [2022-02-20 18:11:31,166 INFO L546 AbstractCegarLoop]: INTERPOLANT automaton has 3 states [2022-02-20 18:11:31,166 INFO L108 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2022-02-20 18:11:31,167 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 3 interpolants. [2022-02-20 18:11:31,167 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=3, Invalid=3, Unknown=0, NotChecked=0, Total=6 [2022-02-20 18:11:31,167 INFO L87 Difference]: Start difference. First operand 64 states and 80 transitions. Second operand has 3 states, 3 states have (on average 8.333333333333334) internal successors, (25), 3 states have internal predecessors, (25), 1 states have call successors, (4), 2 states have call predecessors, (4), 1 states have return successors, (2), 1 states have call predecessors, (2), 1 states have call successors, (2) [2022-02-20 18:11:31,259 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-02-20 18:11:31,259 INFO L93 Difference]: Finished difference Result 88 states and 109 transitions. [2022-02-20 18:11:31,259 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 3 states. [2022-02-20 18:11:31,260 INFO L78 Accepts]: Start accepts. Automaton has has 3 states, 3 states have (on average 8.333333333333334) internal successors, (25), 3 states have internal predecessors, (25), 1 states have call successors, (4), 2 states have call predecessors, (4), 1 states have return successors, (2), 1 states have call predecessors, (2), 1 states have call successors, (2) Word has length 33 [2022-02-20 18:11:31,260 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2022-02-20 18:11:31,260 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 3 states, 3 states have (on average 8.333333333333334) internal successors, (25), 3 states have internal predecessors, (25), 1 states have call successors, (4), 2 states have call predecessors, (4), 1 states have return successors, (2), 1 states have call predecessors, (2), 1 states have call successors, (2) [2022-02-20 18:11:31,265 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 3 states to 3 states and 109 transitions. [2022-02-20 18:11:31,266 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 3 states, 3 states have (on average 8.333333333333334) internal successors, (25), 3 states have internal predecessors, (25), 1 states have call successors, (4), 2 states have call predecessors, (4), 1 states have return successors, (2), 1 states have call predecessors, (2), 1 states have call successors, (2) [2022-02-20 18:11:31,270 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 3 states to 3 states and 109 transitions. [2022-02-20 18:11:31,271 INFO L86 InductivityCheck]: Starting indutivity check of a Floyd-Hoare automaton with 3 states and 109 transitions. [2022-02-20 18:11:31,346 INFO L122 InductivityCheck]: Floyd-Hoare automaton has 109 edges. 109 inductive. 0 not inductive. 0 times theorem prover too weak to decide inductivity. [2022-02-20 18:11:31,348 INFO L225 Difference]: With dead ends: 88 [2022-02-20 18:11:31,349 INFO L226 Difference]: Without dead ends: 55 [2022-02-20 18:11:31,349 INFO L932 BasicCegarLoop]: 0 DeclaredPredicates, 7 GetRequests, 6 SyntacticMatches, 0 SemanticMatches, 1 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 0 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=3, Invalid=3, Unknown=0, NotChecked=0, Total=6 [2022-02-20 18:11:31,350 INFO L933 BasicCegarLoop]: 67 mSDtfsCounter, 18 mSDsluCounter, 45 mSDsCounter, 0 mSdLazyCounter, 1 mSolverCounterSat, 0 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.0s Time, 0 mProtectedPredicate, 0 mProtectedAction, 21 SdHoareTripleChecker+Valid, 112 SdHoareTripleChecker+Invalid, 1 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 0 IncrementalHoareTripleChecker+Valid, 1 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.0s IncrementalHoareTripleChecker+Time [2022-02-20 18:11:31,351 INFO L934 BasicCegarLoop]: SdHoareTripleChecker [21 Valid, 112 Invalid, 1 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [0 Valid, 1 Invalid, 0 Unknown, 0 Unchecked, 0.0s Time] [2022-02-20 18:11:31,351 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 55 states. [2022-02-20 18:11:31,355 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 55 to 55. [2022-02-20 18:11:31,355 INFO L214 AbstractMinimizeNwa]: Start testing correctness of minimizeSevpa [2022-02-20 18:11:31,355 INFO L82 GeneralOperation]: Start isEquivalent. First operand 55 states. Second operand has 55 states, 45 states have (on average 1.288888888888889) internal successors, (58), 48 states have internal predecessors, (58), 5 states have call successors, (5), 4 states have call predecessors, (5), 4 states have return successors, (5), 5 states have call predecessors, (5), 5 states have call successors, (5) [2022-02-20 18:11:31,356 INFO L74 IsIncluded]: Start isIncluded. First operand 55 states. Second operand has 55 states, 45 states have (on average 1.288888888888889) internal successors, (58), 48 states have internal predecessors, (58), 5 states have call successors, (5), 4 states have call predecessors, (5), 4 states have return successors, (5), 5 states have call predecessors, (5), 5 states have call successors, (5) [2022-02-20 18:11:31,356 INFO L87 Difference]: Start difference. First operand 55 states. Second operand has 55 states, 45 states have (on average 1.288888888888889) internal successors, (58), 48 states have internal predecessors, (58), 5 states have call successors, (5), 4 states have call predecessors, (5), 4 states have return successors, (5), 5 states have call predecessors, (5), 5 states have call successors, (5) [2022-02-20 18:11:31,358 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-02-20 18:11:31,358 INFO L93 Difference]: Finished difference Result 55 states and 68 transitions. [2022-02-20 18:11:31,359 INFO L276 IsEmpty]: Start isEmpty. Operand 55 states and 68 transitions. [2022-02-20 18:11:31,359 INFO L282 IsEmpty]: Finished isEmpty. No accepting run. [2022-02-20 18:11:31,359 INFO L83 IsIncluded]: Finished isIncluded. Language is included [2022-02-20 18:11:31,360 INFO L74 IsIncluded]: Start isIncluded. First operand has 55 states, 45 states have (on average 1.288888888888889) internal successors, (58), 48 states have internal predecessors, (58), 5 states have call successors, (5), 4 states have call predecessors, (5), 4 states have return successors, (5), 5 states have call predecessors, (5), 5 states have call successors, (5) Second operand 55 states. [2022-02-20 18:11:31,360 INFO L87 Difference]: Start difference. First operand has 55 states, 45 states have (on average 1.288888888888889) internal successors, (58), 48 states have internal predecessors, (58), 5 states have call successors, (5), 4 states have call predecessors, (5), 4 states have return successors, (5), 5 states have call predecessors, (5), 5 states have call successors, (5) Second operand 55 states. [2022-02-20 18:11:31,362 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-02-20 18:11:31,362 INFO L93 Difference]: Finished difference Result 55 states and 68 transitions. [2022-02-20 18:11:31,362 INFO L276 IsEmpty]: Start isEmpty. Operand 55 states and 68 transitions. [2022-02-20 18:11:31,363 INFO L282 IsEmpty]: Finished isEmpty. No accepting run. [2022-02-20 18:11:31,363 INFO L83 IsIncluded]: Finished isIncluded. Language is included [2022-02-20 18:11:31,363 INFO L88 GeneralOperation]: Finished isEquivalent. [2022-02-20 18:11:31,363 INFO L221 AbstractMinimizeNwa]: Finished testing correctness of minimizeSevpa [2022-02-20 18:11:31,363 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 55 states, 45 states have (on average 1.288888888888889) internal successors, (58), 48 states have internal predecessors, (58), 5 states have call successors, (5), 4 states have call predecessors, (5), 4 states have return successors, (5), 5 states have call predecessors, (5), 5 states have call successors, (5) [2022-02-20 18:11:31,365 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 55 states to 55 states and 68 transitions. [2022-02-20 18:11:31,365 INFO L78 Accepts]: Start accepts. Automaton has 55 states and 68 transitions. Word has length 33 [2022-02-20 18:11:31,365 INFO L84 Accepts]: Finished accepts. word is rejected. [2022-02-20 18:11:31,366 INFO L470 AbstractCegarLoop]: Abstraction has 55 states and 68 transitions. [2022-02-20 18:11:31,366 INFO L471 AbstractCegarLoop]: INTERPOLANT automaton has has 3 states, 3 states have (on average 8.333333333333334) internal successors, (25), 3 states have internal predecessors, (25), 1 states have call successors, (4), 2 states have call predecessors, (4), 1 states have return successors, (2), 1 states have call predecessors, (2), 1 states have call successors, (2) [2022-02-20 18:11:31,366 INFO L276 IsEmpty]: Start isEmpty. Operand 55 states and 68 transitions. [2022-02-20 18:11:31,367 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 39 [2022-02-20 18:11:31,367 INFO L506 BasicCegarLoop]: Found error trace [2022-02-20 18:11:31,367 INFO L514 BasicCegarLoop]: trace histogram [2, 2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-02-20 18:11:31,367 WARN L452 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable1 [2022-02-20 18:11:31,368 INFO L402 AbstractCegarLoop]: === Iteration 3 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2022-02-20 18:11:31,368 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2022-02-20 18:11:31,368 INFO L85 PathProgramCache]: Analyzing trace with hash 172632065, now seen corresponding path program 1 times [2022-02-20 18:11:31,368 INFO L126 FreeRefinementEngine]: Executing refinement strategy CAMEL [2022-02-20 18:11:31,369 INFO L338 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [947946862] [2022-02-20 18:11:31,369 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-02-20 18:11:31,369 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2022-02-20 18:11:31,392 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-02-20 18:11:31,464 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 19 [2022-02-20 18:11:31,465 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-02-20 18:11:31,468 INFO L290 TraceCheckUtils]: 0: Hoare triple {827#true} havoc ~retValue_acc~1;~retValue_acc~1 := ~pumpRunning~0;#res := ~retValue_acc~1; {827#true} is VALID [2022-02-20 18:11:31,468 INFO L290 TraceCheckUtils]: 1: Hoare triple {827#true} assume true; {827#true} is VALID [2022-02-20 18:11:31,469 INFO L284 TraceCheckUtils]: 2: Hoare quadruple {827#true} {829#(= 1 ~systemActive~0)} #194#return; {829#(= 1 ~systemActive~0)} is VALID [2022-02-20 18:11:31,469 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 30 [2022-02-20 18:11:31,471 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-02-20 18:11:31,475 INFO L290 TraceCheckUtils]: 0: Hoare triple {827#true} havoc ~retValue_acc~1;~retValue_acc~1 := ~pumpRunning~0;#res := ~retValue_acc~1; {827#true} is VALID [2022-02-20 18:11:31,475 INFO L290 TraceCheckUtils]: 1: Hoare triple {827#true} assume true; {827#true} is VALID [2022-02-20 18:11:31,475 INFO L284 TraceCheckUtils]: 2: Hoare quadruple {827#true} {828#false} #196#return; {828#false} is VALID [2022-02-20 18:11:31,482 INFO L290 TraceCheckUtils]: 0: Hoare triple {827#true} assume { :begin_inline_ULTIMATE.init } true;#NULL.base, #NULL.offset := 0, 0;assume 0 == #valid[0];assume 0 < #StackHeapBarrier;call #Ultimate.allocInit(2, 1);call write~init~int(48, 1, 0, 1);call write~init~int(0, 1, 1, 1);call #Ultimate.allocInit(31, 2);call #Ultimate.allocInit(12, 3);call #Ultimate.allocInit(13, 4);call #Ultimate.allocInit(3, 5);call write~init~int(79, 5, 0, 1);call write~init~int(110, 5, 1, 1);call write~init~int(0, 5, 2, 1);call #Ultimate.allocInit(4, 6);call write~init~int(79, 6, 0, 1);call write~init~int(102, 6, 1, 1);call write~init~int(102, 6, 2, 1);call write~init~int(0, 6, 3, 1);call #Ultimate.allocInit(7, 7);call write~init~int(44, 7, 0, 1);call write~init~int(80, 7, 1, 1);call write~init~int(117, 7, 2, 1);call write~init~int(109, 7, 3, 1);call write~init~int(112, 7, 4, 1);call write~init~int(58, 7, 5, 1);call write~init~int(0, 7, 6, 1);call #Ultimate.allocInit(3, 8);call write~init~int(79, 8, 0, 1);call write~init~int(110, 8, 1, 1);call write~init~int(0, 8, 2, 1);call #Ultimate.allocInit(4, 9);call write~init~int(79, 9, 0, 1);call write~init~int(102, 9, 1, 1);call write~init~int(102, 9, 2, 1);call write~init~int(0, 9, 3, 1);call #Ultimate.allocInit(3, 10);call write~init~int(41, 10, 0, 1);call write~init~int(32, 10, 1, 1);call write~init~int(0, 10, 2, 1);call #Ultimate.allocInit(2, 11);call write~init~int(10, 11, 0, 1);call write~init~int(0, 11, 1, 1);call #Ultimate.allocInit(30, 12);call #Ultimate.allocInit(9, 13);call #Ultimate.allocInit(21, 14);call #Ultimate.allocInit(30, 15);call #Ultimate.allocInit(9, 16);call #Ultimate.allocInit(21, 17);call #Ultimate.allocInit(30, 18);call #Ultimate.allocInit(9, 19);call #Ultimate.allocInit(25, 20);call #Ultimate.allocInit(30, 21);call #Ultimate.allocInit(9, 22);call #Ultimate.allocInit(25, 23);call #Ultimate.allocInit(13, 24);call #Ultimate.allocInit(7, 25);call write~init~int(44, 25, 0, 1);call write~init~int(77, 25, 1, 1);call write~init~int(101, 25, 2, 1);call write~init~int(116, 25, 3, 1);call write~init~int(104, 25, 4, 1);call write~init~int(58, 25, 5, 1);call write~init~int(0, 25, 6, 1);call #Ultimate.allocInit(5, 26);call write~init~int(67, 26, 0, 1);call write~init~int(82, 26, 1, 1);call write~init~int(73, 26, 2, 1);call write~init~int(84, 26, 3, 1);call write~init~int(0, 26, 4, 1);call #Ultimate.allocInit(3, 27);call write~init~int(79, 27, 0, 1);call write~init~int(75, 27, 1, 1);call write~init~int(0, 27, 2, 1);call #Ultimate.allocInit(2, 28);call write~init~int(41, 28, 0, 1);call write~init~int(0, 28, 1, 1);~switchedOnBeforeTS~0 := 0;~pumpRunning~0 := 0;~systemActive~0 := 1;~head~0.base, ~head~0.offset := 0, 0;~waterLevel~0 := 1;~methaneLevelCritical~0 := 0;~cleanupTimeShifts~0 := 4; {829#(= 1 ~systemActive~0)} is VALID [2022-02-20 18:11:31,484 INFO L290 TraceCheckUtils]: 1: Hoare triple {829#(= 1 ~systemActive~0)} assume { :end_inline_ULTIMATE.init } true;assume { :begin_inline_main } true;havoc main_#res#1;havoc main_#t~ret48#1, main_~retValue_acc~7#1, main_~tmp~5#1;havoc main_~retValue_acc~7#1;havoc main_~tmp~5#1;assume { :begin_inline_select_helpers } true; {829#(= 1 ~systemActive~0)} is VALID [2022-02-20 18:11:31,484 INFO L290 TraceCheckUtils]: 2: Hoare triple {829#(= 1 ~systemActive~0)} assume { :end_inline_select_helpers } true;assume { :begin_inline_select_features } true; {829#(= 1 ~systemActive~0)} is VALID [2022-02-20 18:11:31,485 INFO L290 TraceCheckUtils]: 3: Hoare triple {829#(= 1 ~systemActive~0)} assume { :end_inline_select_features } true;assume { :begin_inline_valid_product } true;havoc valid_product_#res#1;havoc valid_product_~retValue_acc~9#1;havoc valid_product_~retValue_acc~9#1;valid_product_~retValue_acc~9#1 := 1;valid_product_#res#1 := valid_product_~retValue_acc~9#1; {829#(= 1 ~systemActive~0)} is VALID [2022-02-20 18:11:31,486 INFO L290 TraceCheckUtils]: 4: Hoare triple {829#(= 1 ~systemActive~0)} main_#t~ret48#1 := valid_product_#res#1;assume { :end_inline_valid_product } true;assume -2147483648 <= main_#t~ret48#1 && main_#t~ret48#1 <= 2147483647;main_~tmp~5#1 := main_#t~ret48#1;havoc main_#t~ret48#1; {829#(= 1 ~systemActive~0)} is VALID [2022-02-20 18:11:31,486 INFO L290 TraceCheckUtils]: 5: Hoare triple {829#(= 1 ~systemActive~0)} assume 0 != main_~tmp~5#1;assume { :begin_inline_setup } true; {829#(= 1 ~systemActive~0)} is VALID [2022-02-20 18:11:31,487 INFO L290 TraceCheckUtils]: 6: Hoare triple {829#(= 1 ~systemActive~0)} assume { :end_inline_setup } true;assume { :begin_inline_runTest } true;assume { :begin_inline___utac_acc__Specification5_spec__1 } true;~switchedOnBeforeTS~0 := 0; {829#(= 1 ~systemActive~0)} is VALID [2022-02-20 18:11:31,487 INFO L290 TraceCheckUtils]: 7: Hoare triple {829#(= 1 ~systemActive~0)} assume { :end_inline___utac_acc__Specification5_spec__1 } true;assume { :begin_inline_test } true;havoc test_#t~nondet7#1, test_#t~nondet8#1, test_#t~nondet9#1, test_#t~nondet10#1, test_~splverifierCounter~0#1, test_~tmp~1#1, test_~tmp___0~1#1, test_~tmp___1~0#1, test_~tmp___2~0#1;havoc test_~splverifierCounter~0#1;havoc test_~tmp~1#1;havoc test_~tmp___0~1#1;havoc test_~tmp___1~0#1;havoc test_~tmp___2~0#1;test_~splverifierCounter~0#1 := 0; {829#(= 1 ~systemActive~0)} is VALID [2022-02-20 18:11:31,488 INFO L290 TraceCheckUtils]: 8: Hoare triple {829#(= 1 ~systemActive~0)} assume !false; {829#(= 1 ~systemActive~0)} is VALID [2022-02-20 18:11:31,489 INFO L290 TraceCheckUtils]: 9: Hoare triple {829#(= 1 ~systemActive~0)} assume test_~splverifierCounter~0#1 < 4; {829#(= 1 ~systemActive~0)} is VALID [2022-02-20 18:11:31,489 INFO L290 TraceCheckUtils]: 10: Hoare triple {829#(= 1 ~systemActive~0)} assume -2147483648 <= test_#t~nondet7#1 && test_#t~nondet7#1 <= 2147483647;test_~tmp~1#1 := test_#t~nondet7#1;havoc test_#t~nondet7#1; {829#(= 1 ~systemActive~0)} is VALID [2022-02-20 18:11:31,490 INFO L290 TraceCheckUtils]: 11: Hoare triple {829#(= 1 ~systemActive~0)} assume !(0 != test_~tmp~1#1); {829#(= 1 ~systemActive~0)} is VALID [2022-02-20 18:11:31,491 INFO L290 TraceCheckUtils]: 12: Hoare triple {829#(= 1 ~systemActive~0)} assume -2147483648 <= test_#t~nondet8#1 && test_#t~nondet8#1 <= 2147483647;test_~tmp___0~1#1 := test_#t~nondet8#1;havoc test_#t~nondet8#1; {829#(= 1 ~systemActive~0)} is VALID [2022-02-20 18:11:31,491 INFO L290 TraceCheckUtils]: 13: Hoare triple {829#(= 1 ~systemActive~0)} assume !(0 != test_~tmp___0~1#1); {829#(= 1 ~systemActive~0)} is VALID [2022-02-20 18:11:31,491 INFO L290 TraceCheckUtils]: 14: Hoare triple {829#(= 1 ~systemActive~0)} assume -2147483648 <= test_#t~nondet9#1 && test_#t~nondet9#1 <= 2147483647;test_~tmp___2~0#1 := test_#t~nondet9#1;havoc test_#t~nondet9#1; {829#(= 1 ~systemActive~0)} is VALID [2022-02-20 18:11:31,492 INFO L290 TraceCheckUtils]: 15: Hoare triple {829#(= 1 ~systemActive~0)} assume !(0 != test_~tmp___2~0#1);assume -2147483648 <= test_#t~nondet10#1 && test_#t~nondet10#1 <= 2147483647;test_~tmp___1~0#1 := test_#t~nondet10#1;havoc test_#t~nondet10#1; {829#(= 1 ~systemActive~0)} is VALID [2022-02-20 18:11:31,492 INFO L290 TraceCheckUtils]: 16: Hoare triple {829#(= 1 ~systemActive~0)} assume !(0 != test_~tmp___1~0#1); {829#(= 1 ~systemActive~0)} is VALID [2022-02-20 18:11:31,493 INFO L272 TraceCheckUtils]: 17: Hoare triple {829#(= 1 ~systemActive~0)} call timeShift(); {829#(= 1 ~systemActive~0)} is VALID [2022-02-20 18:11:31,494 INFO L290 TraceCheckUtils]: 18: Hoare triple {829#(= 1 ~systemActive~0)} assume { :begin_inline___utac_acc__Specification5_spec__2 } true;havoc __utac_acc__Specification5_spec__2_#t~ret4#1; {829#(= 1 ~systemActive~0)} is VALID [2022-02-20 18:11:31,494 INFO L272 TraceCheckUtils]: 19: Hoare triple {829#(= 1 ~systemActive~0)} call __utac_acc__Specification5_spec__2_#t~ret4#1 := isPumpRunning(); {827#true} is VALID [2022-02-20 18:11:31,494 INFO L290 TraceCheckUtils]: 20: Hoare triple {827#true} havoc ~retValue_acc~1;~retValue_acc~1 := ~pumpRunning~0;#res := ~retValue_acc~1; {827#true} is VALID [2022-02-20 18:11:31,494 INFO L290 TraceCheckUtils]: 21: Hoare triple {827#true} assume true; {827#true} is VALID [2022-02-20 18:11:31,495 INFO L284 TraceCheckUtils]: 22: Hoare quadruple {827#true} {829#(= 1 ~systemActive~0)} #194#return; {829#(= 1 ~systemActive~0)} is VALID [2022-02-20 18:11:31,496 INFO L290 TraceCheckUtils]: 23: Hoare triple {829#(= 1 ~systemActive~0)} assume -2147483648 <= __utac_acc__Specification5_spec__2_#t~ret4#1 && __utac_acc__Specification5_spec__2_#t~ret4#1 <= 2147483647;~switchedOnBeforeTS~0 := __utac_acc__Specification5_spec__2_#t~ret4#1;havoc __utac_acc__Specification5_spec__2_#t~ret4#1; {829#(= 1 ~systemActive~0)} is VALID [2022-02-20 18:11:31,496 INFO L290 TraceCheckUtils]: 24: Hoare triple {829#(= 1 ~systemActive~0)} assume { :end_inline___utac_acc__Specification5_spec__2 } true; {829#(= 1 ~systemActive~0)} is VALID [2022-02-20 18:11:31,496 INFO L290 TraceCheckUtils]: 25: Hoare triple {829#(= 1 ~systemActive~0)} assume !(0 != ~pumpRunning~0); {829#(= 1 ~systemActive~0)} is VALID [2022-02-20 18:11:31,497 INFO L290 TraceCheckUtils]: 26: Hoare triple {829#(= 1 ~systemActive~0)} assume !(0 != ~systemActive~0); {828#false} is VALID [2022-02-20 18:11:31,497 INFO L290 TraceCheckUtils]: 27: Hoare triple {828#false} assume { :begin_inline___utac_acc__Specification5_spec__3 } true;havoc __utac_acc__Specification5_spec__3_#t~ret5#1, __utac_acc__Specification5_spec__3_#t~ret6#1, __utac_acc__Specification5_spec__3_~tmp~0#1, __utac_acc__Specification5_spec__3_~tmp___0~0#1;havoc __utac_acc__Specification5_spec__3_~tmp~0#1;havoc __utac_acc__Specification5_spec__3_~tmp___0~0#1;assume { :begin_inline_getWaterLevel } true;havoc getWaterLevel_#res#1;havoc getWaterLevel_~retValue_acc~6#1;havoc getWaterLevel_~retValue_acc~6#1;getWaterLevel_~retValue_acc~6#1 := ~waterLevel~0;getWaterLevel_#res#1 := getWaterLevel_~retValue_acc~6#1; {828#false} is VALID [2022-02-20 18:11:31,497 INFO L290 TraceCheckUtils]: 28: Hoare triple {828#false} __utac_acc__Specification5_spec__3_#t~ret5#1 := getWaterLevel_#res#1;assume { :end_inline_getWaterLevel } true;assume -2147483648 <= __utac_acc__Specification5_spec__3_#t~ret5#1 && __utac_acc__Specification5_spec__3_#t~ret5#1 <= 2147483647;__utac_acc__Specification5_spec__3_~tmp~0#1 := __utac_acc__Specification5_spec__3_#t~ret5#1;havoc __utac_acc__Specification5_spec__3_#t~ret5#1; {828#false} is VALID [2022-02-20 18:11:31,498 INFO L290 TraceCheckUtils]: 29: Hoare triple {828#false} assume 2 != __utac_acc__Specification5_spec__3_~tmp~0#1; {828#false} is VALID [2022-02-20 18:11:31,498 INFO L272 TraceCheckUtils]: 30: Hoare triple {828#false} call __utac_acc__Specification5_spec__3_#t~ret6#1 := isPumpRunning(); {827#true} is VALID [2022-02-20 18:11:31,498 INFO L290 TraceCheckUtils]: 31: Hoare triple {827#true} havoc ~retValue_acc~1;~retValue_acc~1 := ~pumpRunning~0;#res := ~retValue_acc~1; {827#true} is VALID [2022-02-20 18:11:31,498 INFO L290 TraceCheckUtils]: 32: Hoare triple {827#true} assume true; {827#true} is VALID [2022-02-20 18:11:31,498 INFO L284 TraceCheckUtils]: 33: Hoare quadruple {827#true} {828#false} #196#return; {828#false} is VALID [2022-02-20 18:11:31,499 INFO L290 TraceCheckUtils]: 34: Hoare triple {828#false} assume -2147483648 <= __utac_acc__Specification5_spec__3_#t~ret6#1 && __utac_acc__Specification5_spec__3_#t~ret6#1 <= 2147483647;__utac_acc__Specification5_spec__3_~tmp___0~0#1 := __utac_acc__Specification5_spec__3_#t~ret6#1;havoc __utac_acc__Specification5_spec__3_#t~ret6#1; {828#false} is VALID [2022-02-20 18:11:31,499 INFO L290 TraceCheckUtils]: 35: Hoare triple {828#false} assume 0 != __utac_acc__Specification5_spec__3_~tmp___0~0#1; {828#false} is VALID [2022-02-20 18:11:31,499 INFO L290 TraceCheckUtils]: 36: Hoare triple {828#false} assume 0 == ~switchedOnBeforeTS~0;assume { :begin_inline___automaton_fail } true; {828#false} is VALID [2022-02-20 18:11:31,499 INFO L290 TraceCheckUtils]: 37: Hoare triple {828#false} assume !false; {828#false} is VALID [2022-02-20 18:11:31,500 INFO L134 CoverageAnalysis]: Checked inductivity of 3 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 3 trivial. 0 not checked. [2022-02-20 18:11:31,500 INFO L144 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2022-02-20 18:11:31,500 INFO L338 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [947946862] [2022-02-20 18:11:31,500 INFO L165 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [947946862] provided 1 perfect and 0 imperfect interpolant sequences [2022-02-20 18:11:31,501 INFO L191 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2022-02-20 18:11:31,501 INFO L204 FreeRefinementEngine]: Number of different interpolants: perfect sequences [3] imperfect sequences [] total 3 [2022-02-20 18:11:31,501 INFO L118 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [457290245] [2022-02-20 18:11:31,501 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2022-02-20 18:11:31,502 INFO L78 Accepts]: Start accepts. Automaton has has 3 states, 3 states have (on average 10.333333333333334) internal successors, (31), 3 states have internal predecessors, (31), 2 states have call successors, (3), 2 states have call predecessors, (3), 1 states have return successors, (2), 2 states have call predecessors, (2), 2 states have call successors, (2) Word has length 38 [2022-02-20 18:11:31,502 INFO L84 Accepts]: Finished accepts. word is accepted. [2022-02-20 18:11:31,502 INFO L86 InductivityCheck]: Starting indutivity check of a Floyd-Hoare automaton with has 3 states, 3 states have (on average 10.333333333333334) internal successors, (31), 3 states have internal predecessors, (31), 2 states have call successors, (3), 2 states have call predecessors, (3), 1 states have return successors, (2), 2 states have call predecessors, (2), 2 states have call successors, (2) [2022-02-20 18:11:31,527 INFO L122 InductivityCheck]: Floyd-Hoare automaton has 36 edges. 36 inductive. 0 not inductive. 0 times theorem prover too weak to decide inductivity. [2022-02-20 18:11:31,527 INFO L546 AbstractCegarLoop]: INTERPOLANT automaton has 3 states [2022-02-20 18:11:31,527 INFO L108 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2022-02-20 18:11:31,528 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 3 interpolants. [2022-02-20 18:11:31,528 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=3, Invalid=3, Unknown=0, NotChecked=0, Total=6 [2022-02-20 18:11:31,528 INFO L87 Difference]: Start difference. First operand 55 states and 68 transitions. Second operand has 3 states, 3 states have (on average 10.333333333333334) internal successors, (31), 3 states have internal predecessors, (31), 2 states have call successors, (3), 2 states have call predecessors, (3), 1 states have return successors, (2), 2 states have call predecessors, (2), 2 states have call successors, (2) [2022-02-20 18:11:31,602 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-02-20 18:11:31,602 INFO L93 Difference]: Finished difference Result 147 states and 187 transitions. [2022-02-20 18:11:31,602 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 3 states. [2022-02-20 18:11:31,602 INFO L78 Accepts]: Start accepts. Automaton has has 3 states, 3 states have (on average 10.333333333333334) internal successors, (31), 3 states have internal predecessors, (31), 2 states have call successors, (3), 2 states have call predecessors, (3), 1 states have return successors, (2), 2 states have call predecessors, (2), 2 states have call successors, (2) Word has length 38 [2022-02-20 18:11:31,603 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2022-02-20 18:11:31,603 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 3 states, 3 states have (on average 10.333333333333334) internal successors, (31), 3 states have internal predecessors, (31), 2 states have call successors, (3), 2 states have call predecessors, (3), 1 states have return successors, (2), 2 states have call predecessors, (2), 2 states have call successors, (2) [2022-02-20 18:11:31,605 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 3 states to 3 states and 187 transitions. [2022-02-20 18:11:31,605 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 3 states, 3 states have (on average 10.333333333333334) internal successors, (31), 3 states have internal predecessors, (31), 2 states have call successors, (3), 2 states have call predecessors, (3), 1 states have return successors, (2), 2 states have call predecessors, (2), 2 states have call successors, (2) [2022-02-20 18:11:31,607 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 3 states to 3 states and 187 transitions. [2022-02-20 18:11:31,607 INFO L86 InductivityCheck]: Starting indutivity check of a Floyd-Hoare automaton with 3 states and 187 transitions. [2022-02-20 18:11:31,721 INFO L122 InductivityCheck]: Floyd-Hoare automaton has 187 edges. 187 inductive. 0 not inductive. 0 times theorem prover too weak to decide inductivity. [2022-02-20 18:11:31,723 INFO L225 Difference]: With dead ends: 147 [2022-02-20 18:11:31,724 INFO L226 Difference]: Without dead ends: 100 [2022-02-20 18:11:31,724 INFO L932 BasicCegarLoop]: 0 DeclaredPredicates, 6 GetRequests, 5 SyntacticMatches, 0 SemanticMatches, 1 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 0 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=3, Invalid=3, Unknown=0, NotChecked=0, Total=6 [2022-02-20 18:11:31,725 INFO L933 BasicCegarLoop]: 72 mSDtfsCounter, 41 mSDsluCounter, 55 mSDsCounter, 0 mSdLazyCounter, 4 mSolverCounterSat, 2 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.0s Time, 0 mProtectedPredicate, 0 mProtectedAction, 41 SdHoareTripleChecker+Valid, 127 SdHoareTripleChecker+Invalid, 6 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 2 IncrementalHoareTripleChecker+Valid, 4 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.0s IncrementalHoareTripleChecker+Time [2022-02-20 18:11:31,726 INFO L934 BasicCegarLoop]: SdHoareTripleChecker [41 Valid, 127 Invalid, 6 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [2 Valid, 4 Invalid, 0 Unknown, 0 Unchecked, 0.0s Time] [2022-02-20 18:11:31,727 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 100 states. [2022-02-20 18:11:31,733 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 100 to 95. [2022-02-20 18:11:31,733 INFO L214 AbstractMinimizeNwa]: Start testing correctness of minimizeSevpa [2022-02-20 18:11:31,734 INFO L82 GeneralOperation]: Start isEquivalent. First operand 100 states. Second operand has 95 states, 76 states have (on average 1.3157894736842106) internal successors, (100), 81 states have internal predecessors, (100), 10 states have call successors, (10), 8 states have call predecessors, (10), 8 states have return successors, (10), 10 states have call predecessors, (10), 10 states have call successors, (10) [2022-02-20 18:11:31,734 INFO L74 IsIncluded]: Start isIncluded. First operand 100 states. Second operand has 95 states, 76 states have (on average 1.3157894736842106) internal successors, (100), 81 states have internal predecessors, (100), 10 states have call successors, (10), 8 states have call predecessors, (10), 8 states have return successors, (10), 10 states have call predecessors, (10), 10 states have call successors, (10) [2022-02-20 18:11:31,735 INFO L87 Difference]: Start difference. First operand 100 states. Second operand has 95 states, 76 states have (on average 1.3157894736842106) internal successors, (100), 81 states have internal predecessors, (100), 10 states have call successors, (10), 8 states have call predecessors, (10), 8 states have return successors, (10), 10 states have call predecessors, (10), 10 states have call successors, (10) [2022-02-20 18:11:31,737 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-02-20 18:11:31,738 INFO L93 Difference]: Finished difference Result 100 states and 125 transitions. [2022-02-20 18:11:31,738 INFO L276 IsEmpty]: Start isEmpty. Operand 100 states and 125 transitions. [2022-02-20 18:11:31,738 INFO L282 IsEmpty]: Finished isEmpty. No accepting run. [2022-02-20 18:11:31,738 INFO L83 IsIncluded]: Finished isIncluded. Language is included [2022-02-20 18:11:31,739 INFO L74 IsIncluded]: Start isIncluded. First operand has 95 states, 76 states have (on average 1.3157894736842106) internal successors, (100), 81 states have internal predecessors, (100), 10 states have call successors, (10), 8 states have call predecessors, (10), 8 states have return successors, (10), 10 states have call predecessors, (10), 10 states have call successors, (10) Second operand 100 states. [2022-02-20 18:11:31,739 INFO L87 Difference]: Start difference. First operand has 95 states, 76 states have (on average 1.3157894736842106) internal successors, (100), 81 states have internal predecessors, (100), 10 states have call successors, (10), 8 states have call predecessors, (10), 8 states have return successors, (10), 10 states have call predecessors, (10), 10 states have call successors, (10) Second operand 100 states. [2022-02-20 18:11:31,742 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-02-20 18:11:31,742 INFO L93 Difference]: Finished difference Result 100 states and 125 transitions. [2022-02-20 18:11:31,742 INFO L276 IsEmpty]: Start isEmpty. Operand 100 states and 125 transitions. [2022-02-20 18:11:31,743 INFO L282 IsEmpty]: Finished isEmpty. No accepting run. [2022-02-20 18:11:31,743 INFO L83 IsIncluded]: Finished isIncluded. Language is included [2022-02-20 18:11:31,743 INFO L88 GeneralOperation]: Finished isEquivalent. [2022-02-20 18:11:31,743 INFO L221 AbstractMinimizeNwa]: Finished testing correctness of minimizeSevpa [2022-02-20 18:11:31,744 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 95 states, 76 states have (on average 1.3157894736842106) internal successors, (100), 81 states have internal predecessors, (100), 10 states have call successors, (10), 8 states have call predecessors, (10), 8 states have return successors, (10), 10 states have call predecessors, (10), 10 states have call successors, (10) [2022-02-20 18:11:31,746 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 95 states to 95 states and 120 transitions. [2022-02-20 18:11:31,746 INFO L78 Accepts]: Start accepts. Automaton has 95 states and 120 transitions. Word has length 38 [2022-02-20 18:11:31,747 INFO L84 Accepts]: Finished accepts. word is rejected. [2022-02-20 18:11:31,747 INFO L470 AbstractCegarLoop]: Abstraction has 95 states and 120 transitions. [2022-02-20 18:11:31,747 INFO L471 AbstractCegarLoop]: INTERPOLANT automaton has has 3 states, 3 states have (on average 10.333333333333334) internal successors, (31), 3 states have internal predecessors, (31), 2 states have call successors, (3), 2 states have call predecessors, (3), 1 states have return successors, (2), 2 states have call predecessors, (2), 2 states have call successors, (2) [2022-02-20 18:11:31,747 INFO L276 IsEmpty]: Start isEmpty. Operand 95 states and 120 transitions. [2022-02-20 18:11:31,748 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 40 [2022-02-20 18:11:31,748 INFO L506 BasicCegarLoop]: Found error trace [2022-02-20 18:11:31,748 INFO L514 BasicCegarLoop]: trace histogram [2, 2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-02-20 18:11:31,749 WARN L452 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable2 [2022-02-20 18:11:31,749 INFO L402 AbstractCegarLoop]: === Iteration 4 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2022-02-20 18:11:31,749 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2022-02-20 18:11:31,749 INFO L85 PathProgramCache]: Analyzing trace with hash 408348587, now seen corresponding path program 1 times [2022-02-20 18:11:31,749 INFO L126 FreeRefinementEngine]: Executing refinement strategy CAMEL [2022-02-20 18:11:31,750 INFO L338 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [1698779299] [2022-02-20 18:11:31,750 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-02-20 18:11:31,750 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2022-02-20 18:11:31,772 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-02-20 18:11:31,808 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 19 [2022-02-20 18:11:31,810 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-02-20 18:11:31,818 INFO L290 TraceCheckUtils]: 0: Hoare triple {1375#true} havoc ~retValue_acc~1;~retValue_acc~1 := ~pumpRunning~0;#res := ~retValue_acc~1; {1375#true} is VALID [2022-02-20 18:11:31,818 INFO L290 TraceCheckUtils]: 1: Hoare triple {1375#true} assume true; {1375#true} is VALID [2022-02-20 18:11:31,819 INFO L284 TraceCheckUtils]: 2: Hoare quadruple {1375#true} {1377#(= ~pumpRunning~0 0)} #194#return; {1377#(= ~pumpRunning~0 0)} is VALID [2022-02-20 18:11:31,819 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 31 [2022-02-20 18:11:31,821 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-02-20 18:11:31,828 INFO L290 TraceCheckUtils]: 0: Hoare triple {1375#true} havoc ~retValue_acc~1;~retValue_acc~1 := ~pumpRunning~0;#res := ~retValue_acc~1; {1386#(= ~pumpRunning~0 |isPumpRunning_#res|)} is VALID [2022-02-20 18:11:31,828 INFO L290 TraceCheckUtils]: 1: Hoare triple {1386#(= ~pumpRunning~0 |isPumpRunning_#res|)} assume true; {1386#(= ~pumpRunning~0 |isPumpRunning_#res|)} is VALID [2022-02-20 18:11:31,836 INFO L284 TraceCheckUtils]: 2: Hoare quadruple {1386#(= ~pumpRunning~0 |isPumpRunning_#res|)} {1377#(= ~pumpRunning~0 0)} #196#return; {1384#(= |timeShift___utac_acc__Specification5_spec__3_#t~ret6#1| 0)} is VALID [2022-02-20 18:11:31,837 INFO L290 TraceCheckUtils]: 0: Hoare triple {1375#true} assume { :begin_inline_ULTIMATE.init } true;#NULL.base, #NULL.offset := 0, 0;assume 0 == #valid[0];assume 0 < #StackHeapBarrier;call #Ultimate.allocInit(2, 1);call write~init~int(48, 1, 0, 1);call write~init~int(0, 1, 1, 1);call #Ultimate.allocInit(31, 2);call #Ultimate.allocInit(12, 3);call #Ultimate.allocInit(13, 4);call #Ultimate.allocInit(3, 5);call write~init~int(79, 5, 0, 1);call write~init~int(110, 5, 1, 1);call write~init~int(0, 5, 2, 1);call #Ultimate.allocInit(4, 6);call write~init~int(79, 6, 0, 1);call write~init~int(102, 6, 1, 1);call write~init~int(102, 6, 2, 1);call write~init~int(0, 6, 3, 1);call #Ultimate.allocInit(7, 7);call write~init~int(44, 7, 0, 1);call write~init~int(80, 7, 1, 1);call write~init~int(117, 7, 2, 1);call write~init~int(109, 7, 3, 1);call write~init~int(112, 7, 4, 1);call write~init~int(58, 7, 5, 1);call write~init~int(0, 7, 6, 1);call #Ultimate.allocInit(3, 8);call write~init~int(79, 8, 0, 1);call write~init~int(110, 8, 1, 1);call write~init~int(0, 8, 2, 1);call #Ultimate.allocInit(4, 9);call write~init~int(79, 9, 0, 1);call write~init~int(102, 9, 1, 1);call write~init~int(102, 9, 2, 1);call write~init~int(0, 9, 3, 1);call #Ultimate.allocInit(3, 10);call write~init~int(41, 10, 0, 1);call write~init~int(32, 10, 1, 1);call write~init~int(0, 10, 2, 1);call #Ultimate.allocInit(2, 11);call write~init~int(10, 11, 0, 1);call write~init~int(0, 11, 1, 1);call #Ultimate.allocInit(30, 12);call #Ultimate.allocInit(9, 13);call #Ultimate.allocInit(21, 14);call #Ultimate.allocInit(30, 15);call #Ultimate.allocInit(9, 16);call #Ultimate.allocInit(21, 17);call #Ultimate.allocInit(30, 18);call #Ultimate.allocInit(9, 19);call #Ultimate.allocInit(25, 20);call #Ultimate.allocInit(30, 21);call #Ultimate.allocInit(9, 22);call #Ultimate.allocInit(25, 23);call #Ultimate.allocInit(13, 24);call #Ultimate.allocInit(7, 25);call write~init~int(44, 25, 0, 1);call write~init~int(77, 25, 1, 1);call write~init~int(101, 25, 2, 1);call write~init~int(116, 25, 3, 1);call write~init~int(104, 25, 4, 1);call write~init~int(58, 25, 5, 1);call write~init~int(0, 25, 6, 1);call #Ultimate.allocInit(5, 26);call write~init~int(67, 26, 0, 1);call write~init~int(82, 26, 1, 1);call write~init~int(73, 26, 2, 1);call write~init~int(84, 26, 3, 1);call write~init~int(0, 26, 4, 1);call #Ultimate.allocInit(3, 27);call write~init~int(79, 27, 0, 1);call write~init~int(75, 27, 1, 1);call write~init~int(0, 27, 2, 1);call #Ultimate.allocInit(2, 28);call write~init~int(41, 28, 0, 1);call write~init~int(0, 28, 1, 1);~switchedOnBeforeTS~0 := 0;~pumpRunning~0 := 0;~systemActive~0 := 1;~head~0.base, ~head~0.offset := 0, 0;~waterLevel~0 := 1;~methaneLevelCritical~0 := 0;~cleanupTimeShifts~0 := 4; {1377#(= ~pumpRunning~0 0)} is VALID [2022-02-20 18:11:31,837 INFO L290 TraceCheckUtils]: 1: Hoare triple {1377#(= ~pumpRunning~0 0)} assume { :end_inline_ULTIMATE.init } true;assume { :begin_inline_main } true;havoc main_#res#1;havoc main_#t~ret48#1, main_~retValue_acc~7#1, main_~tmp~5#1;havoc main_~retValue_acc~7#1;havoc main_~tmp~5#1;assume { :begin_inline_select_helpers } true; {1377#(= ~pumpRunning~0 0)} is VALID [2022-02-20 18:11:31,847 INFO L290 TraceCheckUtils]: 2: Hoare triple {1377#(= ~pumpRunning~0 0)} assume { :end_inline_select_helpers } true;assume { :begin_inline_select_features } true; {1377#(= ~pumpRunning~0 0)} is VALID [2022-02-20 18:11:31,848 INFO L290 TraceCheckUtils]: 3: Hoare triple {1377#(= ~pumpRunning~0 0)} assume { :end_inline_select_features } true;assume { :begin_inline_valid_product } true;havoc valid_product_#res#1;havoc valid_product_~retValue_acc~9#1;havoc valid_product_~retValue_acc~9#1;valid_product_~retValue_acc~9#1 := 1;valid_product_#res#1 := valid_product_~retValue_acc~9#1; {1377#(= ~pumpRunning~0 0)} is VALID [2022-02-20 18:11:31,848 INFO L290 TraceCheckUtils]: 4: Hoare triple {1377#(= ~pumpRunning~0 0)} main_#t~ret48#1 := valid_product_#res#1;assume { :end_inline_valid_product } true;assume -2147483648 <= main_#t~ret48#1 && main_#t~ret48#1 <= 2147483647;main_~tmp~5#1 := main_#t~ret48#1;havoc main_#t~ret48#1; {1377#(= ~pumpRunning~0 0)} is VALID [2022-02-20 18:11:31,849 INFO L290 TraceCheckUtils]: 5: Hoare triple {1377#(= ~pumpRunning~0 0)} assume 0 != main_~tmp~5#1;assume { :begin_inline_setup } true; {1377#(= ~pumpRunning~0 0)} is VALID [2022-02-20 18:11:31,849 INFO L290 TraceCheckUtils]: 6: Hoare triple {1377#(= ~pumpRunning~0 0)} assume { :end_inline_setup } true;assume { :begin_inline_runTest } true;assume { :begin_inline___utac_acc__Specification5_spec__1 } true;~switchedOnBeforeTS~0 := 0; {1377#(= ~pumpRunning~0 0)} is VALID [2022-02-20 18:11:31,849 INFO L290 TraceCheckUtils]: 7: Hoare triple {1377#(= ~pumpRunning~0 0)} assume { :end_inline___utac_acc__Specification5_spec__1 } true;assume { :begin_inline_test } true;havoc test_#t~nondet7#1, test_#t~nondet8#1, test_#t~nondet9#1, test_#t~nondet10#1, test_~splverifierCounter~0#1, test_~tmp~1#1, test_~tmp___0~1#1, test_~tmp___1~0#1, test_~tmp___2~0#1;havoc test_~splverifierCounter~0#1;havoc test_~tmp~1#1;havoc test_~tmp___0~1#1;havoc test_~tmp___1~0#1;havoc test_~tmp___2~0#1;test_~splverifierCounter~0#1 := 0; {1377#(= ~pumpRunning~0 0)} is VALID [2022-02-20 18:11:31,849 INFO L290 TraceCheckUtils]: 8: Hoare triple {1377#(= ~pumpRunning~0 0)} assume !false; {1377#(= ~pumpRunning~0 0)} is VALID [2022-02-20 18:11:31,850 INFO L290 TraceCheckUtils]: 9: Hoare triple {1377#(= ~pumpRunning~0 0)} assume test_~splverifierCounter~0#1 < 4; {1377#(= ~pumpRunning~0 0)} is VALID [2022-02-20 18:11:31,850 INFO L290 TraceCheckUtils]: 10: Hoare triple {1377#(= ~pumpRunning~0 0)} assume -2147483648 <= test_#t~nondet7#1 && test_#t~nondet7#1 <= 2147483647;test_~tmp~1#1 := test_#t~nondet7#1;havoc test_#t~nondet7#1; {1377#(= ~pumpRunning~0 0)} is VALID [2022-02-20 18:11:31,850 INFO L290 TraceCheckUtils]: 11: Hoare triple {1377#(= ~pumpRunning~0 0)} assume !(0 != test_~tmp~1#1); {1377#(= ~pumpRunning~0 0)} is VALID [2022-02-20 18:11:31,851 INFO L290 TraceCheckUtils]: 12: Hoare triple {1377#(= ~pumpRunning~0 0)} assume -2147483648 <= test_#t~nondet8#1 && test_#t~nondet8#1 <= 2147483647;test_~tmp___0~1#1 := test_#t~nondet8#1;havoc test_#t~nondet8#1; {1377#(= ~pumpRunning~0 0)} is VALID [2022-02-20 18:11:31,851 INFO L290 TraceCheckUtils]: 13: Hoare triple {1377#(= ~pumpRunning~0 0)} assume !(0 != test_~tmp___0~1#1); {1377#(= ~pumpRunning~0 0)} is VALID [2022-02-20 18:11:31,852 INFO L290 TraceCheckUtils]: 14: Hoare triple {1377#(= ~pumpRunning~0 0)} assume -2147483648 <= test_#t~nondet9#1 && test_#t~nondet9#1 <= 2147483647;test_~tmp___2~0#1 := test_#t~nondet9#1;havoc test_#t~nondet9#1; {1377#(= ~pumpRunning~0 0)} is VALID [2022-02-20 18:11:31,852 INFO L290 TraceCheckUtils]: 15: Hoare triple {1377#(= ~pumpRunning~0 0)} assume !(0 != test_~tmp___2~0#1);assume -2147483648 <= test_#t~nondet10#1 && test_#t~nondet10#1 <= 2147483647;test_~tmp___1~0#1 := test_#t~nondet10#1;havoc test_#t~nondet10#1; {1377#(= ~pumpRunning~0 0)} is VALID [2022-02-20 18:11:31,853 INFO L290 TraceCheckUtils]: 16: Hoare triple {1377#(= ~pumpRunning~0 0)} assume !(0 != test_~tmp___1~0#1); {1377#(= ~pumpRunning~0 0)} is VALID [2022-02-20 18:11:31,853 INFO L272 TraceCheckUtils]: 17: Hoare triple {1377#(= ~pumpRunning~0 0)} call timeShift(); {1377#(= ~pumpRunning~0 0)} is VALID [2022-02-20 18:11:31,854 INFO L290 TraceCheckUtils]: 18: Hoare triple {1377#(= ~pumpRunning~0 0)} assume { :begin_inline___utac_acc__Specification5_spec__2 } true;havoc __utac_acc__Specification5_spec__2_#t~ret4#1; {1377#(= ~pumpRunning~0 0)} is VALID [2022-02-20 18:11:31,854 INFO L272 TraceCheckUtils]: 19: Hoare triple {1377#(= ~pumpRunning~0 0)} call __utac_acc__Specification5_spec__2_#t~ret4#1 := isPumpRunning(); {1375#true} is VALID [2022-02-20 18:11:31,854 INFO L290 TraceCheckUtils]: 20: Hoare triple {1375#true} havoc ~retValue_acc~1;~retValue_acc~1 := ~pumpRunning~0;#res := ~retValue_acc~1; {1375#true} is VALID [2022-02-20 18:11:31,854 INFO L290 TraceCheckUtils]: 21: Hoare triple {1375#true} assume true; {1375#true} is VALID [2022-02-20 18:11:31,855 INFO L284 TraceCheckUtils]: 22: Hoare quadruple {1375#true} {1377#(= ~pumpRunning~0 0)} #194#return; {1377#(= ~pumpRunning~0 0)} is VALID [2022-02-20 18:11:31,855 INFO L290 TraceCheckUtils]: 23: Hoare triple {1377#(= ~pumpRunning~0 0)} assume -2147483648 <= __utac_acc__Specification5_spec__2_#t~ret4#1 && __utac_acc__Specification5_spec__2_#t~ret4#1 <= 2147483647;~switchedOnBeforeTS~0 := __utac_acc__Specification5_spec__2_#t~ret4#1;havoc __utac_acc__Specification5_spec__2_#t~ret4#1; {1377#(= ~pumpRunning~0 0)} is VALID [2022-02-20 18:11:31,855 INFO L290 TraceCheckUtils]: 24: Hoare triple {1377#(= ~pumpRunning~0 0)} assume { :end_inline___utac_acc__Specification5_spec__2 } true; {1377#(= ~pumpRunning~0 0)} is VALID [2022-02-20 18:11:31,856 INFO L290 TraceCheckUtils]: 25: Hoare triple {1377#(= ~pumpRunning~0 0)} assume !(0 != ~pumpRunning~0); {1377#(= ~pumpRunning~0 0)} is VALID [2022-02-20 18:11:31,856 INFO L290 TraceCheckUtils]: 26: Hoare triple {1377#(= ~pumpRunning~0 0)} assume 0 != ~systemActive~0;assume { :begin_inline_processEnvironment } true; {1377#(= ~pumpRunning~0 0)} is VALID [2022-02-20 18:11:31,856 INFO L290 TraceCheckUtils]: 27: Hoare triple {1377#(= ~pumpRunning~0 0)} assume { :end_inline_processEnvironment } true; {1377#(= ~pumpRunning~0 0)} is VALID [2022-02-20 18:11:31,857 INFO L290 TraceCheckUtils]: 28: Hoare triple {1377#(= ~pumpRunning~0 0)} assume { :begin_inline___utac_acc__Specification5_spec__3 } true;havoc __utac_acc__Specification5_spec__3_#t~ret5#1, __utac_acc__Specification5_spec__3_#t~ret6#1, __utac_acc__Specification5_spec__3_~tmp~0#1, __utac_acc__Specification5_spec__3_~tmp___0~0#1;havoc __utac_acc__Specification5_spec__3_~tmp~0#1;havoc __utac_acc__Specification5_spec__3_~tmp___0~0#1;assume { :begin_inline_getWaterLevel } true;havoc getWaterLevel_#res#1;havoc getWaterLevel_~retValue_acc~6#1;havoc getWaterLevel_~retValue_acc~6#1;getWaterLevel_~retValue_acc~6#1 := ~waterLevel~0;getWaterLevel_#res#1 := getWaterLevel_~retValue_acc~6#1; {1377#(= ~pumpRunning~0 0)} is VALID [2022-02-20 18:11:31,857 INFO L290 TraceCheckUtils]: 29: Hoare triple {1377#(= ~pumpRunning~0 0)} __utac_acc__Specification5_spec__3_#t~ret5#1 := getWaterLevel_#res#1;assume { :end_inline_getWaterLevel } true;assume -2147483648 <= __utac_acc__Specification5_spec__3_#t~ret5#1 && __utac_acc__Specification5_spec__3_#t~ret5#1 <= 2147483647;__utac_acc__Specification5_spec__3_~tmp~0#1 := __utac_acc__Specification5_spec__3_#t~ret5#1;havoc __utac_acc__Specification5_spec__3_#t~ret5#1; {1377#(= ~pumpRunning~0 0)} is VALID [2022-02-20 18:11:31,857 INFO L290 TraceCheckUtils]: 30: Hoare triple {1377#(= ~pumpRunning~0 0)} assume 2 != __utac_acc__Specification5_spec__3_~tmp~0#1; {1377#(= ~pumpRunning~0 0)} is VALID [2022-02-20 18:11:31,858 INFO L272 TraceCheckUtils]: 31: Hoare triple {1377#(= ~pumpRunning~0 0)} call __utac_acc__Specification5_spec__3_#t~ret6#1 := isPumpRunning(); {1375#true} is VALID [2022-02-20 18:11:31,858 INFO L290 TraceCheckUtils]: 32: Hoare triple {1375#true} havoc ~retValue_acc~1;~retValue_acc~1 := ~pumpRunning~0;#res := ~retValue_acc~1; {1386#(= ~pumpRunning~0 |isPumpRunning_#res|)} is VALID [2022-02-20 18:11:31,858 INFO L290 TraceCheckUtils]: 33: Hoare triple {1386#(= ~pumpRunning~0 |isPumpRunning_#res|)} assume true; {1386#(= ~pumpRunning~0 |isPumpRunning_#res|)} is VALID [2022-02-20 18:11:31,859 INFO L284 TraceCheckUtils]: 34: Hoare quadruple {1386#(= ~pumpRunning~0 |isPumpRunning_#res|)} {1377#(= ~pumpRunning~0 0)} #196#return; {1384#(= |timeShift___utac_acc__Specification5_spec__3_#t~ret6#1| 0)} is VALID [2022-02-20 18:11:31,859 INFO L290 TraceCheckUtils]: 35: Hoare triple {1384#(= |timeShift___utac_acc__Specification5_spec__3_#t~ret6#1| 0)} assume -2147483648 <= __utac_acc__Specification5_spec__3_#t~ret6#1 && __utac_acc__Specification5_spec__3_#t~ret6#1 <= 2147483647;__utac_acc__Specification5_spec__3_~tmp___0~0#1 := __utac_acc__Specification5_spec__3_#t~ret6#1;havoc __utac_acc__Specification5_spec__3_#t~ret6#1; {1385#(= |timeShift___utac_acc__Specification5_spec__3_~tmp___0~0#1| 0)} is VALID [2022-02-20 18:11:31,860 INFO L290 TraceCheckUtils]: 36: Hoare triple {1385#(= |timeShift___utac_acc__Specification5_spec__3_~tmp___0~0#1| 0)} assume 0 != __utac_acc__Specification5_spec__3_~tmp___0~0#1; {1376#false} is VALID [2022-02-20 18:11:31,860 INFO L290 TraceCheckUtils]: 37: Hoare triple {1376#false} assume 0 == ~switchedOnBeforeTS~0;assume { :begin_inline___automaton_fail } true; {1376#false} is VALID [2022-02-20 18:11:31,860 INFO L290 TraceCheckUtils]: 38: Hoare triple {1376#false} assume !false; {1376#false} is VALID [2022-02-20 18:11:31,860 INFO L134 CoverageAnalysis]: Checked inductivity of 3 backedges. 2 proven. 0 refuted. 0 times theorem prover too weak. 1 trivial. 0 not checked. [2022-02-20 18:11:31,861 INFO L144 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2022-02-20 18:11:31,861 INFO L338 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [1698779299] [2022-02-20 18:11:31,861 INFO L165 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [1698779299] provided 1 perfect and 0 imperfect interpolant sequences [2022-02-20 18:11:31,861 INFO L191 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2022-02-20 18:11:31,861 INFO L204 FreeRefinementEngine]: Number of different interpolants: perfect sequences [6] imperfect sequences [] total 6 [2022-02-20 18:11:31,861 INFO L118 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [509232013] [2022-02-20 18:11:31,862 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2022-02-20 18:11:31,862 INFO L78 Accepts]: Start accepts. Automaton has has 6 states, 6 states have (on average 5.666666666666667) internal successors, (34), 5 states have internal predecessors, (34), 1 states have call successors, (3), 2 states have call predecessors, (3), 2 states have return successors, (2), 2 states have call predecessors, (2), 1 states have call successors, (2) Word has length 39 [2022-02-20 18:11:31,862 INFO L84 Accepts]: Finished accepts. word is accepted. [2022-02-20 18:11:31,862 INFO L86 InductivityCheck]: Starting indutivity check of a Floyd-Hoare automaton with has 6 states, 6 states have (on average 5.666666666666667) internal successors, (34), 5 states have internal predecessors, (34), 1 states have call successors, (3), 2 states have call predecessors, (3), 2 states have return successors, (2), 2 states have call predecessors, (2), 1 states have call successors, (2) [2022-02-20 18:11:31,892 INFO L122 InductivityCheck]: Floyd-Hoare automaton has 39 edges. 39 inductive. 0 not inductive. 0 times theorem prover too weak to decide inductivity. [2022-02-20 18:11:31,892 INFO L546 AbstractCegarLoop]: INTERPOLANT automaton has 6 states [2022-02-20 18:11:31,893 INFO L108 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2022-02-20 18:11:31,893 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 6 interpolants. [2022-02-20 18:11:31,893 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=9, Invalid=21, Unknown=0, NotChecked=0, Total=30 [2022-02-20 18:11:31,894 INFO L87 Difference]: Start difference. First operand 95 states and 120 transitions. Second operand has 6 states, 6 states have (on average 5.666666666666667) internal successors, (34), 5 states have internal predecessors, (34), 1 states have call successors, (3), 2 states have call predecessors, (3), 2 states have return successors, (2), 2 states have call predecessors, (2), 1 states have call successors, (2) [2022-02-20 18:11:32,033 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-02-20 18:11:32,034 INFO L93 Difference]: Finished difference Result 179 states and 228 transitions. [2022-02-20 18:11:32,034 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 6 states. [2022-02-20 18:11:32,034 INFO L78 Accepts]: Start accepts. Automaton has has 6 states, 6 states have (on average 5.666666666666667) internal successors, (34), 5 states have internal predecessors, (34), 1 states have call successors, (3), 2 states have call predecessors, (3), 2 states have return successors, (2), 2 states have call predecessors, (2), 1 states have call successors, (2) Word has length 39 [2022-02-20 18:11:32,034 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2022-02-20 18:11:32,035 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 6 states, 6 states have (on average 5.666666666666667) internal successors, (34), 5 states have internal predecessors, (34), 1 states have call successors, (3), 2 states have call predecessors, (3), 2 states have return successors, (2), 2 states have call predecessors, (2), 1 states have call successors, (2) [2022-02-20 18:11:32,036 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 6 states to 6 states and 125 transitions. [2022-02-20 18:11:32,051 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 6 states, 6 states have (on average 5.666666666666667) internal successors, (34), 5 states have internal predecessors, (34), 1 states have call successors, (3), 2 states have call predecessors, (3), 2 states have return successors, (2), 2 states have call predecessors, (2), 1 states have call successors, (2) [2022-02-20 18:11:32,053 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 6 states to 6 states and 125 transitions. [2022-02-20 18:11:32,054 INFO L86 InductivityCheck]: Starting indutivity check of a Floyd-Hoare automaton with 6 states and 125 transitions. [2022-02-20 18:11:32,156 INFO L122 InductivityCheck]: Floyd-Hoare automaton has 125 edges. 125 inductive. 0 not inductive. 0 times theorem prover too weak to decide inductivity. [2022-02-20 18:11:32,156 INFO L225 Difference]: With dead ends: 179 [2022-02-20 18:11:32,156 INFO L226 Difference]: Without dead ends: 0 [2022-02-20 18:11:32,157 INFO L932 BasicCegarLoop]: 0 DeclaredPredicates, 11 GetRequests, 4 SyntacticMatches, 0 SemanticMatches, 7 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 3 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=21, Invalid=51, Unknown=0, NotChecked=0, Total=72 [2022-02-20 18:11:32,158 INFO L933 BasicCegarLoop]: 56 mSDtfsCounter, 31 mSDsluCounter, 150 mSDsCounter, 0 mSdLazyCounter, 31 mSolverCounterSat, 3 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.0s Time, 0 mProtectedPredicate, 0 mProtectedAction, 32 SdHoareTripleChecker+Valid, 206 SdHoareTripleChecker+Invalid, 34 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 3 IncrementalHoareTripleChecker+Valid, 31 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.0s IncrementalHoareTripleChecker+Time [2022-02-20 18:11:32,159 INFO L934 BasicCegarLoop]: SdHoareTripleChecker [32 Valid, 206 Invalid, 34 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [3 Valid, 31 Invalid, 0 Unknown, 0 Unchecked, 0.0s Time] [2022-02-20 18:11:32,159 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 0 states. [2022-02-20 18:11:32,159 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 0 to 0. [2022-02-20 18:11:32,159 INFO L214 AbstractMinimizeNwa]: Start testing correctness of minimizeSevpa [2022-02-20 18:11:32,160 INFO L82 GeneralOperation]: Start isEquivalent. First operand 0 states. Second operand has 0 states, 0 states have (on average 0.0) internal successors, (0), 0 states have internal predecessors, (0), 0 states have call successors, (0), 0 states have call predecessors, (0), 0 states have return successors, (0), 0 states have call predecessors, (0), 0 states have call successors, (0) [2022-02-20 18:11:32,160 INFO L74 IsIncluded]: Start isIncluded. First operand 0 states. Second operand has 0 states, 0 states have (on average 0.0) internal successors, (0), 0 states have internal predecessors, (0), 0 states have call successors, (0), 0 states have call predecessors, (0), 0 states have return successors, (0), 0 states have call predecessors, (0), 0 states have call successors, (0) [2022-02-20 18:11:32,160 INFO L87 Difference]: Start difference. First operand 0 states. Second operand has 0 states, 0 states have (on average 0.0) internal successors, (0), 0 states have internal predecessors, (0), 0 states have call successors, (0), 0 states have call predecessors, (0), 0 states have return successors, (0), 0 states have call predecessors, (0), 0 states have call successors, (0) [2022-02-20 18:11:32,160 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-02-20 18:11:32,160 INFO L93 Difference]: Finished difference Result 0 states and 0 transitions. [2022-02-20 18:11:32,160 INFO L276 IsEmpty]: Start isEmpty. Operand 0 states and 0 transitions. [2022-02-20 18:11:32,160 INFO L282 IsEmpty]: Finished isEmpty. No accepting run. [2022-02-20 18:11:32,161 INFO L83 IsIncluded]: Finished isIncluded. Language is included [2022-02-20 18:11:32,161 INFO L74 IsIncluded]: Start isIncluded. First operand has 0 states, 0 states have (on average 0.0) internal successors, (0), 0 states have internal predecessors, (0), 0 states have call successors, (0), 0 states have call predecessors, (0), 0 states have return successors, (0), 0 states have call predecessors, (0), 0 states have call successors, (0) Second operand 0 states. [2022-02-20 18:11:32,161 INFO L87 Difference]: Start difference. First operand has 0 states, 0 states have (on average 0.0) internal successors, (0), 0 states have internal predecessors, (0), 0 states have call successors, (0), 0 states have call predecessors, (0), 0 states have return successors, (0), 0 states have call predecessors, (0), 0 states have call successors, (0) Second operand 0 states. [2022-02-20 18:11:32,161 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-02-20 18:11:32,161 INFO L93 Difference]: Finished difference Result 0 states and 0 transitions. [2022-02-20 18:11:32,161 INFO L276 IsEmpty]: Start isEmpty. Operand 0 states and 0 transitions. [2022-02-20 18:11:32,161 INFO L282 IsEmpty]: Finished isEmpty. No accepting run. [2022-02-20 18:11:32,161 INFO L83 IsIncluded]: Finished isIncluded. Language is included [2022-02-20 18:11:32,162 INFO L88 GeneralOperation]: Finished isEquivalent. [2022-02-20 18:11:32,162 INFO L221 AbstractMinimizeNwa]: Finished testing correctness of minimizeSevpa [2022-02-20 18:11:32,162 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 0 states, 0 states have (on average 0.0) internal successors, (0), 0 states have internal predecessors, (0), 0 states have call successors, (0), 0 states have call predecessors, (0), 0 states have return successors, (0), 0 states have call predecessors, (0), 0 states have call successors, (0) [2022-02-20 18:11:32,162 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 0 states to 0 states and 0 transitions. [2022-02-20 18:11:32,162 INFO L78 Accepts]: Start accepts. Automaton has 0 states and 0 transitions. Word has length 39 [2022-02-20 18:11:32,162 INFO L84 Accepts]: Finished accepts. word is rejected. [2022-02-20 18:11:32,162 INFO L470 AbstractCegarLoop]: Abstraction has 0 states and 0 transitions. [2022-02-20 18:11:32,163 INFO L471 AbstractCegarLoop]: INTERPOLANT automaton has has 6 states, 6 states have (on average 5.666666666666667) internal successors, (34), 5 states have internal predecessors, (34), 1 states have call successors, (3), 2 states have call predecessors, (3), 2 states have return successors, (2), 2 states have call predecessors, (2), 1 states have call successors, (2) [2022-02-20 18:11:32,163 INFO L276 IsEmpty]: Start isEmpty. Operand 0 states and 0 transitions. [2022-02-20 18:11:32,163 INFO L282 IsEmpty]: Finished isEmpty. No accepting run. [2022-02-20 18:11:32,165 INFO L764 garLoopResultBuilder]: Registering result SAFE for location timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION (0 of 1 remaining) [2022-02-20 18:11:32,166 WARN L452 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable3 [2022-02-20 18:11:32,167 INFO L343 DoubleDeckerVisitor]: Before removal of dead ends 0 states and 0 transitions. [2022-02-20 18:11:32,317 INFO L861 garLoopResultBuilder]: At program point changeMethaneLevelENTRY(lines 708 719) the Hoare annotation is: true [2022-02-20 18:11:32,318 INFO L858 garLoopResultBuilder]: For program point L712-1(lines 708 719) no Hoare annotation was computed. [2022-02-20 18:11:32,318 INFO L858 garLoopResultBuilder]: For program point changeMethaneLevelEXIT(lines 708 719) no Hoare annotation was computed. [2022-02-20 18:11:32,318 INFO L861 garLoopResultBuilder]: At program point L769(line 769) the Hoare annotation is: true [2022-02-20 18:11:32,318 INFO L858 garLoopResultBuilder]: For program point L769-1(line 769) no Hoare annotation was computed. [2022-02-20 18:11:32,318 INFO L858 garLoopResultBuilder]: For program point cleanupEXIT(lines 763 792) no Hoare annotation was computed. [2022-02-20 18:11:32,318 INFO L861 garLoopResultBuilder]: At program point cleanupENTRY(lines 763 792) the Hoare annotation is: true [2022-02-20 18:11:32,318 INFO L861 garLoopResultBuilder]: At program point L788(lines 763 792) the Hoare annotation is: true [2022-02-20 18:11:32,318 INFO L858 garLoopResultBuilder]: For program point L784(line 784) no Hoare annotation was computed. [2022-02-20 18:11:32,318 INFO L858 garLoopResultBuilder]: For program point L777(lines 777 781) no Hoare annotation was computed. [2022-02-20 18:11:32,318 INFO L861 garLoopResultBuilder]: At program point L777-1(lines 777 781) the Hoare annotation is: true [2022-02-20 18:11:32,318 INFO L858 garLoopResultBuilder]: For program point L774(line 774) no Hoare annotation was computed. [2022-02-20 18:11:32,318 INFO L861 garLoopResultBuilder]: At program point L773-2(lines 773 787) the Hoare annotation is: true [2022-02-20 18:11:32,318 INFO L861 garLoopResultBuilder]: At program point L217(lines 213 219) the Hoare annotation is: true [2022-02-20 18:11:32,318 INFO L858 garLoopResultBuilder]: For program point L85(lines 85 91) no Hoare annotation was computed. [2022-02-20 18:11:32,318 INFO L858 garLoopResultBuilder]: For program point L688(lines 688 692) no Hoare annotation was computed. [2022-02-20 18:11:32,319 INFO L854 garLoopResultBuilder]: At program point L688-2(lines 684 695) the Hoare annotation is: (not (= ~pumpRunning~0 0)) [2022-02-20 18:11:32,319 INFO L858 garLoopResultBuilder]: For program point timeShiftFINAL(lines 186 212) no Hoare annotation was computed. [2022-02-20 18:11:32,319 INFO L861 garLoopResultBuilder]: At program point L69(lines 62 71) the Hoare annotation is: true [2022-02-20 18:11:32,319 INFO L858 garLoopResultBuilder]: For program point L866(line 866) no Hoare annotation was computed. [2022-02-20 18:11:32,319 INFO L858 garLoopResultBuilder]: For program point L193(lines 193 199) no Hoare annotation was computed. [2022-02-20 18:11:32,319 INFO L858 garLoopResultBuilder]: For program point L193-2(lines 189 211) no Hoare annotation was computed. [2022-02-20 18:11:32,319 INFO L861 garLoopResultBuilder]: At program point L82(line 82) the Hoare annotation is: true [2022-02-20 18:11:32,319 INFO L858 garLoopResultBuilder]: For program point L82-1(line 82) no Hoare annotation was computed. [2022-02-20 18:11:32,319 INFO L854 garLoopResultBuilder]: At program point L867(lines 862 869) the Hoare annotation is: (not (= ~pumpRunning~0 0)) [2022-02-20 18:11:32,319 INFO L861 garLoopResultBuilder]: At program point L67(line 67) the Hoare annotation is: true [2022-02-20 18:11:32,319 INFO L858 garLoopResultBuilder]: For program point L67-1(line 67) no Hoare annotation was computed. [2022-02-20 18:11:32,319 INFO L861 garLoopResultBuilder]: At program point L757(lines 752 760) the Hoare annotation is: true [2022-02-20 18:11:32,319 INFO L858 garLoopResultBuilder]: For program point L84(lines 84 94) no Hoare annotation was computed. [2022-02-20 18:11:32,319 INFO L858 garLoopResultBuilder]: For program point L80(lines 80 97) no Hoare annotation was computed. [2022-02-20 18:11:32,319 INFO L861 garLoopResultBuilder]: At program point timeShiftENTRY(lines 186 212) the Hoare annotation is: true [2022-02-20 18:11:32,320 INFO L861 garLoopResultBuilder]: At program point L80-1(lines 72 100) the Hoare annotation is: true [2022-02-20 18:11:32,320 INFO L858 garLoopResultBuilder]: For program point timeShiftEXIT(lines 186 212) no Hoare annotation was computed. [2022-02-20 18:11:32,320 INFO L858 garLoopResultBuilder]: For program point timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION(line 866) no Hoare annotation was computed. [2022-02-20 18:11:32,320 INFO L858 garLoopResultBuilder]: For program point L200-1(lines 200 206) no Hoare annotation was computed. [2022-02-20 18:11:32,320 INFO L861 garLoopResultBuilder]: At program point L832(lines 824 834) the Hoare annotation is: true [2022-02-20 18:11:32,320 INFO L861 garLoopResultBuilder]: At program point L857(lines 838 860) the Hoare annotation is: true [2022-02-20 18:11:32,320 INFO L854 garLoopResultBuilder]: At program point L312(lines 307 314) the Hoare annotation is: (and (= ~pumpRunning~0 0) (= 1 ~systemActive~0) (= |ULTIMATE.start_test_~splverifierCounter~0#1| 0)) [2022-02-20 18:11:32,320 INFO L854 garLoopResultBuilder]: At program point L886(lines 882 888) the Hoare annotation is: (and (= ~pumpRunning~0 0) (= 1 ~systemActive~0)) [2022-02-20 18:11:32,320 INFO L854 garLoopResultBuilder]: At program point L304(lines 292 306) the Hoare annotation is: (and (= ~pumpRunning~0 0) (= |ULTIMATE.start_test_~splverifierCounter~0#1| 0)) [2022-02-20 18:11:32,320 INFO L858 garLoopResultBuilder]: For program point L296(lines 296 302) no Hoare annotation was computed. [2022-02-20 18:11:32,321 INFO L854 garLoopResultBuilder]: At program point L168(lines 117 169) the Hoare annotation is: false [2022-02-20 18:11:32,321 INFO L858 garLoopResultBuilder]: For program point L296-2(lines 296 302) no Hoare annotation was computed. [2022-02-20 18:11:32,321 INFO L858 garLoopResultBuilder]: For program point L-1(line -1) no Hoare annotation was computed. [2022-02-20 18:11:32,321 INFO L858 garLoopResultBuilder]: For program point ULTIMATE.startENTRY(line -1) no Hoare annotation was computed. [2022-02-20 18:11:32,321 INFO L858 garLoopResultBuilder]: For program point ULTIMATE.startFINAL(line -1) no Hoare annotation was computed. [2022-02-20 18:11:32,321 INFO L858 garLoopResultBuilder]: For program point L156(lines 156 162) no Hoare annotation was computed. [2022-02-20 18:11:32,321 INFO L854 garLoopResultBuilder]: At program point L156-2(lines 148 163) the Hoare annotation is: (and (= ~pumpRunning~0 0) (= |ULTIMATE.start_test_~splverifierCounter~0#1| 0)) [2022-02-20 18:11:32,321 INFO L858 garLoopResultBuilder]: For program point L119(lines 118 167) no Hoare annotation was computed. [2022-02-20 18:11:32,321 INFO L854 garLoopResultBuilder]: At program point L821(lines 817 823) the Hoare annotation is: (and (= ~pumpRunning~0 0) (= 1 ~systemActive~0)) [2022-02-20 18:11:32,321 INFO L858 garLoopResultBuilder]: For program point L148(lines 148 163) no Hoare annotation was computed. [2022-02-20 18:11:32,321 INFO L854 garLoopResultBuilder]: At program point L140(line 140) the Hoare annotation is: (and (= ~pumpRunning~0 0) (= |ULTIMATE.start_test_~splverifierCounter~0#1| 0)) [2022-02-20 18:11:32,321 INFO L854 garLoopResultBuilder]: At program point L165(lines 118 167) the Hoare annotation is: (and (= ~pumpRunning~0 0) (= |ULTIMATE.start_test_~splverifierCounter~0#1| 0)) [2022-02-20 18:11:32,321 INFO L858 garLoopResultBuilder]: For program point ULTIMATE.startEXIT(line -1) no Hoare annotation was computed. [2022-02-20 18:11:32,321 INFO L858 garLoopResultBuilder]: For program point L128(lines 128 134) no Hoare annotation was computed. [2022-02-20 18:11:32,321 INFO L858 garLoopResultBuilder]: For program point L128-1(lines 128 134) no Hoare annotation was computed. [2022-02-20 18:11:32,321 INFO L858 garLoopResultBuilder]: For program point L120(lines 120 124) no Hoare annotation was computed. [2022-02-20 18:11:32,321 INFO L854 garLoopResultBuilder]: At program point L901(lines 896 904) the Hoare annotation is: (and (= ~pumpRunning~0 0) (= 1 ~systemActive~0)) [2022-02-20 18:11:32,321 INFO L854 garLoopResultBuilder]: At program point L893(lines 889 895) the Hoare annotation is: (and (= ~pumpRunning~0 0) (= 1 ~systemActive~0)) [2022-02-20 18:11:32,322 INFO L854 garLoopResultBuilder]: At program point L59(lines 54 61) the Hoare annotation is: (and (= ~pumpRunning~0 0) (= 1 ~systemActive~0)) [2022-02-20 18:11:32,322 INFO L858 garLoopResultBuilder]: For program point L848(lines 848 855) no Hoare annotation was computed. [2022-02-20 18:11:32,322 INFO L858 garLoopResultBuilder]: For program point L848-2(lines 848 855) no Hoare annotation was computed. [2022-02-20 18:11:32,322 INFO L861 garLoopResultBuilder]: At program point L171(lines 108 175) the Hoare annotation is: true [2022-02-20 18:11:32,322 INFO L858 garLoopResultBuilder]: For program point L138(lines 138 144) no Hoare annotation was computed. [2022-02-20 18:11:32,323 INFO L858 garLoopResultBuilder]: For program point L138-1(lines 138 144) no Hoare annotation was computed. [2022-02-20 18:11:32,323 INFO L854 garLoopResultBuilder]: At program point L233(lines 228 235) the Hoare annotation is: false [2022-02-20 18:11:32,323 INFO L854 garLoopResultBuilder]: At program point L130(line 130) the Hoare annotation is: (and (= ~pumpRunning~0 0) (= |ULTIMATE.start_test_~splverifierCounter~0#1| 0)) [2022-02-20 18:11:32,323 INFO L858 garLoopResultBuilder]: For program point waterRiseEXIT(lines 696 707) no Hoare annotation was computed. [2022-02-20 18:11:32,323 INFO L858 garLoopResultBuilder]: For program point L700-1(lines 696 707) no Hoare annotation was computed. [2022-02-20 18:11:32,323 INFO L861 garLoopResultBuilder]: At program point waterRiseENTRY(lines 696 707) the Hoare annotation is: true [2022-02-20 18:11:32,323 INFO L858 garLoopResultBuilder]: For program point isPumpRunningEXIT(lines 247 255) no Hoare annotation was computed. [2022-02-20 18:11:32,323 INFO L861 garLoopResultBuilder]: At program point isPumpRunningENTRY(lines 247 255) the Hoare annotation is: true [2022-02-20 18:11:32,323 INFO L858 garLoopResultBuilder]: For program point isPumpRunningFINAL(lines 247 255) no Hoare annotation was computed. [2022-02-20 18:11:32,326 INFO L732 BasicCegarLoop]: Path program histogram: [1, 1, 1, 1] [2022-02-20 18:11:32,327 INFO L180 ceAbstractionStarter]: Computing trace abstraction results [2022-02-20 18:11:32,329 WARN L170 areAnnotationChecker]: L712-1 has no Hoare annotation [2022-02-20 18:11:32,329 WARN L170 areAnnotationChecker]: L712-1 has no Hoare annotation [2022-02-20 18:11:32,329 WARN L170 areAnnotationChecker]: ULTIMATE.startENTRY has no Hoare annotation [2022-02-20 18:11:32,329 WARN L170 areAnnotationChecker]: L700-1 has no Hoare annotation [2022-02-20 18:11:32,329 WARN L170 areAnnotationChecker]: L700-1 has no Hoare annotation [2022-02-20 18:11:32,329 WARN L170 areAnnotationChecker]: isPumpRunningFINAL has no Hoare annotation [2022-02-20 18:11:32,329 WARN L170 areAnnotationChecker]: L712-1 has no Hoare annotation [2022-02-20 18:11:32,329 WARN L170 areAnnotationChecker]: L769-1 has no Hoare annotation [2022-02-20 18:11:32,329 WARN L170 areAnnotationChecker]: L67-1 has no Hoare annotation [2022-02-20 18:11:32,329 WARN L170 areAnnotationChecker]: L-1 has no Hoare annotation [2022-02-20 18:11:32,329 WARN L170 areAnnotationChecker]: L700-1 has no Hoare annotation [2022-02-20 18:11:32,329 WARN L170 areAnnotationChecker]: isPumpRunningFINAL has no Hoare annotation [2022-02-20 18:11:32,330 WARN L170 areAnnotationChecker]: changeMethaneLevelEXIT has no Hoare annotation [2022-02-20 18:11:32,330 WARN L170 areAnnotationChecker]: L769-1 has no Hoare annotation [2022-02-20 18:11:32,330 WARN L170 areAnnotationChecker]: L67-1 has no Hoare annotation [2022-02-20 18:11:32,330 WARN L170 areAnnotationChecker]: waterRiseEXIT has no Hoare annotation [2022-02-20 18:11:32,330 WARN L170 areAnnotationChecker]: isPumpRunningEXIT has no Hoare annotation [2022-02-20 18:11:32,330 WARN L170 areAnnotationChecker]: isPumpRunningEXIT has no Hoare annotation [2022-02-20 18:11:32,330 WARN L170 areAnnotationChecker]: L138-1 has no Hoare annotation [2022-02-20 18:11:32,330 WARN L170 areAnnotationChecker]: L774 has no Hoare annotation [2022-02-20 18:11:32,330 WARN L170 areAnnotationChecker]: L193 has no Hoare annotation [2022-02-20 18:11:32,331 WARN L170 areAnnotationChecker]: L128-1 has no Hoare annotation [2022-02-20 18:11:32,331 WARN L170 areAnnotationChecker]: L82-1 has no Hoare annotation [2022-02-20 18:11:32,331 WARN L170 areAnnotationChecker]: L148 has no Hoare annotation [2022-02-20 18:11:32,331 WARN L170 areAnnotationChecker]: L148 has no Hoare annotation [2022-02-20 18:11:32,331 WARN L170 areAnnotationChecker]: cleanupEXIT has no Hoare annotation [2022-02-20 18:11:32,331 WARN L170 areAnnotationChecker]: L774 has no Hoare annotation [2022-02-20 18:11:32,331 WARN L170 areAnnotationChecker]: L193 has no Hoare annotation [2022-02-20 18:11:32,331 WARN L170 areAnnotationChecker]: L193 has no Hoare annotation [2022-02-20 18:11:32,331 WARN L170 areAnnotationChecker]: L848 has no Hoare annotation [2022-02-20 18:11:32,331 WARN L170 areAnnotationChecker]: L138 has no Hoare annotation [2022-02-20 18:11:32,331 WARN L170 areAnnotationChecker]: L138 has no Hoare annotation [2022-02-20 18:11:32,331 WARN L170 areAnnotationChecker]: L84 has no Hoare annotation [2022-02-20 18:11:32,331 WARN L170 areAnnotationChecker]: L84 has no Hoare annotation [2022-02-20 18:11:32,331 WARN L170 areAnnotationChecker]: L156 has no Hoare annotation [2022-02-20 18:11:32,331 WARN L170 areAnnotationChecker]: L156 has no Hoare annotation [2022-02-20 18:11:32,331 WARN L170 areAnnotationChecker]: cleanupEXIT has no Hoare annotation [2022-02-20 18:11:32,332 WARN L170 areAnnotationChecker]: L777 has no Hoare annotation [2022-02-20 18:11:32,332 WARN L170 areAnnotationChecker]: L777 has no Hoare annotation [2022-02-20 18:11:32,332 WARN L170 areAnnotationChecker]: L688 has no Hoare annotation [2022-02-20 18:11:32,332 WARN L170 areAnnotationChecker]: L688 has no Hoare annotation [2022-02-20 18:11:32,332 WARN L170 areAnnotationChecker]: L193-2 has no Hoare annotation [2022-02-20 18:11:32,332 WARN L170 areAnnotationChecker]: L193-2 has no Hoare annotation [2022-02-20 18:11:32,332 WARN L170 areAnnotationChecker]: L848 has no Hoare annotation [2022-02-20 18:11:32,332 WARN L170 areAnnotationChecker]: L848 has no Hoare annotation [2022-02-20 18:11:32,332 WARN L170 areAnnotationChecker]: L138-1 has no Hoare annotation [2022-02-20 18:11:32,332 WARN L170 areAnnotationChecker]: L85 has no Hoare annotation [2022-02-20 18:11:32,332 WARN L170 areAnnotationChecker]: L85 has no Hoare annotation [2022-02-20 18:11:32,332 WARN L170 areAnnotationChecker]: timeShiftFINAL has no Hoare annotation [2022-02-20 18:11:32,332 WARN L170 areAnnotationChecker]: L296 has no Hoare annotation [2022-02-20 18:11:32,332 WARN L170 areAnnotationChecker]: L296 has no Hoare annotation [2022-02-20 18:11:32,332 WARN L170 areAnnotationChecker]: L784 has no Hoare annotation [2022-02-20 18:11:32,332 WARN L170 areAnnotationChecker]: L193-2 has no Hoare annotation [2022-02-20 18:11:32,332 WARN L170 areAnnotationChecker]: L200-1 has no Hoare annotation [2022-02-20 18:11:32,332 WARN L170 areAnnotationChecker]: L200-1 has no Hoare annotation [2022-02-20 18:11:32,332 WARN L170 areAnnotationChecker]: L848-2 has no Hoare annotation [2022-02-20 18:11:32,332 WARN L170 areAnnotationChecker]: L866 has no Hoare annotation [2022-02-20 18:11:32,332 WARN L170 areAnnotationChecker]: L866 has no Hoare annotation [2022-02-20 18:11:32,332 WARN L170 areAnnotationChecker]: timeShiftFINAL has no Hoare annotation [2022-02-20 18:11:32,333 WARN L170 areAnnotationChecker]: L119 has no Hoare annotation [2022-02-20 18:11:32,333 WARN L170 areAnnotationChecker]: L296-2 has no Hoare annotation [2022-02-20 18:11:32,333 WARN L170 areAnnotationChecker]: L296-2 has no Hoare annotation [2022-02-20 18:11:32,333 WARN L170 areAnnotationChecker]: L848-2 has no Hoare annotation [2022-02-20 18:11:32,333 WARN L170 areAnnotationChecker]: L784 has no Hoare annotation [2022-02-20 18:11:32,333 WARN L170 areAnnotationChecker]: L80 has no Hoare annotation [2022-02-20 18:11:32,333 WARN L170 areAnnotationChecker]: ULTIMATE.startFINAL has no Hoare annotation [2022-02-20 18:11:32,333 WARN L170 areAnnotationChecker]: timeShiftEXIT has no Hoare annotation [2022-02-20 18:11:32,333 WARN L170 areAnnotationChecker]: timeShiftEXIT has no Hoare annotation [2022-02-20 18:11:32,333 WARN L170 areAnnotationChecker]: timeShiftEXIT has no Hoare annotation [2022-02-20 18:11:32,333 WARN L170 areAnnotationChecker]: L119 has no Hoare annotation [2022-02-20 18:11:32,334 WARN L170 areAnnotationChecker]: L119 has no Hoare annotation [2022-02-20 18:11:32,334 WARN L170 areAnnotationChecker]: L80 has no Hoare annotation [2022-02-20 18:11:32,334 WARN L170 areAnnotationChecker]: L80 has no Hoare annotation [2022-02-20 18:11:32,334 WARN L170 areAnnotationChecker]: ULTIMATE.startFINAL has no Hoare annotation [2022-02-20 18:11:32,334 WARN L170 areAnnotationChecker]: L120 has no Hoare annotation [2022-02-20 18:11:32,334 WARN L170 areAnnotationChecker]: L82-1 has no Hoare annotation [2022-02-20 18:11:32,334 WARN L170 areAnnotationChecker]: L128 has no Hoare annotation [2022-02-20 18:11:32,334 WARN L170 areAnnotationChecker]: L128 has no Hoare annotation [2022-02-20 18:11:32,334 WARN L170 areAnnotationChecker]: L128-1 has no Hoare annotation [2022-02-20 18:11:32,334 INFO L163 areAnnotationChecker]: CFG has 22 edges. 22 inductive. 0 not inductive. 0 times theorem prover too weak to decide inductivity. 0 times interpolants missing. [2022-02-20 18:11:32,343 INFO L202 PluginConnector]: Adding new model de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction CFG 20.02 06:11:32 BoogieIcfgContainer [2022-02-20 18:11:32,343 INFO L132 PluginConnector]: ------------------------ END TraceAbstraction---------------------------- [2022-02-20 18:11:32,343 INFO L113 PluginConnector]: ------------------------Witness Printer---------------------------- [2022-02-20 18:11:32,343 INFO L271 PluginConnector]: Initializing Witness Printer... [2022-02-20 18:11:32,344 INFO L275 PluginConnector]: Witness Printer initialized [2022-02-20 18:11:32,344 INFO L185 PluginConnector]: Executing the observer RCFGCatcher from plugin Witness Printer for "de.uni_freiburg.informatik.ultimate.plugins.generator.rcfgbuilder CFG 20.02 06:11:30" (3/4) ... [2022-02-20 18:11:32,346 INFO L137 WitnessPrinter]: Generating witness for correct program [2022-02-20 18:11:32,349 INFO L354 RCFGBacktranslator]: Ignoring RootEdge to procedure changeMethaneLevel [2022-02-20 18:11:32,349 INFO L354 RCFGBacktranslator]: Ignoring RootEdge to procedure cleanup [2022-02-20 18:11:32,349 INFO L354 RCFGBacktranslator]: Ignoring RootEdge to procedure timeShift [2022-02-20 18:11:32,349 INFO L354 RCFGBacktranslator]: Ignoring RootEdge to procedure waterRise [2022-02-20 18:11:32,349 INFO L354 RCFGBacktranslator]: Ignoring RootEdge to procedure isPumpRunning [2022-02-20 18:11:32,353 INFO L910 BoogieBacktranslator]: Reduced CFG by removing 46 nodes and edges [2022-02-20 18:11:32,353 INFO L910 BoogieBacktranslator]: Reduced CFG by removing 22 nodes and edges [2022-02-20 18:11:32,354 INFO L910 BoogieBacktranslator]: Reduced CFG by removing 11 nodes and edges [2022-02-20 18:11:32,354 INFO L910 BoogieBacktranslator]: Reduced CFG by removing 5 nodes and edges [2022-02-20 18:11:32,354 INFO L910 BoogieBacktranslator]: Reduced CFG by removing 2 nodes and edges [2022-02-20 18:11:32,354 INFO L910 BoogieBacktranslator]: Reduced CFG by removing 1 nodes and edges [2022-02-20 18:11:32,354 INFO L910 BoogieBacktranslator]: Reduced CFG by removing 1 nodes and edges [2022-02-20 18:11:32,385 INFO L141 WitnessManager]: Wrote witness to /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/witness.graphml [2022-02-20 18:11:32,385 INFO L132 PluginConnector]: ------------------------ END Witness Printer---------------------------- [2022-02-20 18:11:32,386 INFO L158 Benchmark]: Toolchain (without parser) took 3008.87ms. Allocated memory was 117.4MB in the beginning and 151.0MB in the end (delta: 33.6MB). Free memory was 79.7MB in the beginning and 72.0MB in the end (delta: 7.7MB). Peak memory consumption was 41.1MB. Max. memory is 16.1GB. [2022-02-20 18:11:32,386 INFO L158 Benchmark]: CDTParser took 0.22ms. Allocated memory is still 117.4MB. Free memory is still 96.9MB. There was no memory consumed. Max. memory is 16.1GB. [2022-02-20 18:11:32,387 INFO L158 Benchmark]: CACSL2BoogieTranslator took 367.00ms. Allocated memory is still 117.4MB. Free memory was 79.5MB in the beginning and 81.0MB in the end (delta: -1.5MB). Peak memory consumption was 10.5MB. Max. memory is 16.1GB. [2022-02-20 18:11:32,387 INFO L158 Benchmark]: Boogie Procedure Inliner took 50.57ms. Allocated memory is still 117.4MB. Free memory was 81.0MB in the beginning and 78.5MB in the end (delta: 2.5MB). Peak memory consumption was 2.1MB. Max. memory is 16.1GB. [2022-02-20 18:11:32,387 INFO L158 Benchmark]: Boogie Preprocessor took 40.11ms. Allocated memory is still 117.4MB. Free memory was 78.5MB in the beginning and 77.1MB in the end (delta: 1.3MB). Peak memory consumption was 2.1MB. Max. memory is 16.1GB. [2022-02-20 18:11:32,387 INFO L158 Benchmark]: RCFGBuilder took 386.67ms. Allocated memory is still 117.4MB. Free memory was 77.1MB in the beginning and 60.0MB in the end (delta: 17.2MB). Peak memory consumption was 16.8MB. Max. memory is 16.1GB. [2022-02-20 18:11:32,388 INFO L158 Benchmark]: TraceAbstraction took 2115.17ms. Allocated memory was 117.4MB in the beginning and 151.0MB in the end (delta: 33.6MB). Free memory was 59.2MB in the beginning and 77.2MB in the end (delta: -18.0MB). Peak memory consumption was 18.5MB. Max. memory is 16.1GB. [2022-02-20 18:11:32,388 INFO L158 Benchmark]: Witness Printer took 41.85ms. Allocated memory is still 151.0MB. Free memory was 77.2MB in the beginning and 72.0MB in the end (delta: 5.2MB). Peak memory consumption was 4.2MB. Max. memory is 16.1GB. [2022-02-20 18:11:32,389 INFO L339 ainManager$Toolchain]: ####################### End [Toolchain 1] ####################### --- Results --- * Results from de.uni_freiburg.informatik.ultimate.core: - AssertionsEnabledResult: Assertions are enabled Assertions are enabled - StatisticsResult: Toolchain Benchmarks Benchmark results are: * CDTParser took 0.22ms. Allocated memory is still 117.4MB. Free memory is still 96.9MB. There was no memory consumed. Max. memory is 16.1GB. * CACSL2BoogieTranslator took 367.00ms. Allocated memory is still 117.4MB. Free memory was 79.5MB in the beginning and 81.0MB in the end (delta: -1.5MB). Peak memory consumption was 10.5MB. Max. memory is 16.1GB. * Boogie Procedure Inliner took 50.57ms. Allocated memory is still 117.4MB. Free memory was 81.0MB in the beginning and 78.5MB in the end (delta: 2.5MB). Peak memory consumption was 2.1MB. Max. memory is 16.1GB. * Boogie Preprocessor took 40.11ms. Allocated memory is still 117.4MB. Free memory was 78.5MB in the beginning and 77.1MB in the end (delta: 1.3MB). Peak memory consumption was 2.1MB. Max. memory is 16.1GB. * RCFGBuilder took 386.67ms. Allocated memory is still 117.4MB. Free memory was 77.1MB in the beginning and 60.0MB in the end (delta: 17.2MB). Peak memory consumption was 16.8MB. Max. memory is 16.1GB. * TraceAbstraction took 2115.17ms. Allocated memory was 117.4MB in the beginning and 151.0MB in the end (delta: 33.6MB). Free memory was 59.2MB in the beginning and 77.2MB in the end (delta: -18.0MB). Peak memory consumption was 18.5MB. Max. memory is 16.1GB. * Witness Printer took 41.85ms. Allocated memory is still 151.0MB. Free memory was 77.2MB in the beginning and 72.0MB in the end (delta: 5.2MB). Peak memory consumption was 4.2MB. Max. memory is 16.1GB. * Results from de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction: - StatisticsResult: ErrorAutomatonStatistics NumberErrorTraces: 0, NumberStatementsAllTraces: 0, NumberRelevantStatements: 0, 0.0s ErrorAutomatonConstructionTimeTotal, 0.0s FaulLocalizationTime, NumberStatementsFirstTrace: -1, TraceLengthAvg: 0, 0.0s ErrorAutomatonConstructionTimeAvg, 0.0s ErrorAutomatonDifferenceTimeAvg, 0.0s ErrorAutomatonDifferenceTimeTotal, NumberOfNoEnhancement: 0, NumberOfFiniteEnhancement: 0, NumberOfInfiniteEnhancement: 0 - PositiveResult [Line: 866]: call to reach_error is unreachable For all program executions holds that call to reach_error is unreachable at this location - StatisticsResult: Ultimate Automizer benchmark data CFG has 6 procedures, 73 locations, 1 error locations. Started 1 CEGAR loops. OverallTime: 2.0s, OverallIterations: 4, TraceHistogramMax: 2, PathProgramHistogramMax: 1, EmptinessCheckTime: 0.0s, AutomataDifference: 1.0s, DeadEndRemovalTime: 0.0s, HoareAnnotationTime: 0.2s, InitialAbstractionConstructionTime: 0.0s, PartialOrderReductionTime: 0.0s, HoareTripleCheckerStatistics: 0 mSolverCounterUnknown, 94 SdHoareTripleChecker+Valid, 0.0s IncrementalHoareTripleChecker+Time, 0 mSdLazyCounter, 90 mSDsluCounter, 534 SdHoareTripleChecker+Invalid, 0.0s Time, 0 mProtectedAction, 0 SdHoareTripleChecker+Unchecked, 0 IncrementalHoareTripleChecker+Unchecked, 250 mSDsCounter, 5 IncrementalHoareTripleChecker+Valid, 0 mProtectedPredicate, 36 IncrementalHoareTripleChecker+Invalid, 41 SdHoareTripleChecker+Unknown, 0 mSolverCounterNotChecked, 5 mSolverCounterUnsat, 284 mSDtfsCounter, 36 mSolverCounterSat, 0.0s SdHoareTripleChecker+Time, 0 IncrementalHoareTripleChecker+Unknown, PredicateUnifierStatistics: 0 DeclaredPredicates, 30 GetRequests, 21 SyntacticMatches, 0 SemanticMatches, 9 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 3 ImplicationChecksByTransitivity, 0.0s Time, 0.0s BasicInterpolantAutomatonTime, BiggestAbstraction: size=95occurred in iteration=3, InterpolantAutomatonStates: 14, traceCheckStatistics: No data available, InterpolantConsolidationStatistics: No data available, PathInvariantsStatistics: No data available, 0/0 InterpolantCoveringCapability, TotalInterpolationStatistics: No data available, 0.0s DumpTime, AutomataMinimizationStatistics: 0.1s AutomataMinimizationTime, 4 MinimizatonAttempts, 5 StatesRemovedByMinimization, 1 NontrivialMinimizations, HoareAnnotationStatistics: 0.0s HoareAnnotationTime, 33 LocationsWithAnnotation, 142 PreInvPairs, 166 NumberOfFragments, 108 HoareAnnotationTreeSize, 142 FomulaSimplifications, 8 FormulaSimplificationTreeSizeReduction, 0.0s HoareSimplificationTime, 33 FomulaSimplificationsInter, 224 FormulaSimplificationTreeSizeReductionInter, 0.1s HoareSimplificationTimeInter, RefinementEngineStatistics: TRACE_CHECK: 0.0s SsaConstructionTime, 0.1s SatisfiabilityAnalysisTime, 0.4s InterpolantComputationTime, 142 NumberOfCodeBlocks, 142 NumberOfCodeBlocksAsserted, 4 NumberOfCheckSat, 138 ConstructedInterpolants, 0 QuantifiedInterpolants, 252 SizeOfPredicates, 0 NumberOfNonLiveVariables, 0 ConjunctsInSsa, 0 ConjunctsInUnsatCore, 4 InterpolantComputations, 4 PerfectInterpolantSequences, 12/12 InterpolantCoveringCapability, INVARIANT_SYNTHESIS: No data available, INTERPOLANT_CONSOLIDATION: No data available, ABSTRACT_INTERPRETATION: No data available, PDR: No data available, ACCELERATED_INTERPOLATION: No data available, SIFA: No data available, ReuseStatistics: No data available - AllSpecificationsHoldResult: All specifications hold 1 specifications checked. All of them hold - InvariantResult [Line: 824]: Loop Invariant Derived loop invariant: 1 - InvariantResult [Line: 62]: Loop Invariant Derived loop invariant: 1 - InvariantResult [Line: 54]: Loop Invariant Derived loop invariant: pumpRunning == 0 && 1 == systemActive - InvariantResult [Line: 117]: Loop Invariant Derived loop invariant: 0 - InvariantResult [Line: 213]: Loop Invariant Derived loop invariant: 1 - InvariantResult [Line: 752]: Loop Invariant Derived loop invariant: 1 - InvariantResult [Line: 72]: Loop Invariant Derived loop invariant: 1 - InvariantResult [Line: 817]: Loop Invariant Derived loop invariant: pumpRunning == 0 && 1 == systemActive - InvariantResult [Line: 108]: Loop Invariant Derived loop invariant: 1 - InvariantResult [Line: 684]: Loop Invariant Derived loop invariant: !(pumpRunning == 0) - InvariantResult [Line: 118]: Loop Invariant Derived loop invariant: pumpRunning == 0 && splverifierCounter == 0 - InvariantResult [Line: 307]: Loop Invariant Derived loop invariant: (pumpRunning == 0 && 1 == systemActive) && splverifierCounter == 0 - InvariantResult [Line: 889]: Loop Invariant Derived loop invariant: pumpRunning == 0 && 1 == systemActive - InvariantResult [Line: 896]: Loop Invariant Derived loop invariant: pumpRunning == 0 && 1 == systemActive - InvariantResult [Line: 773]: Loop Invariant Derived loop invariant: 1 - InvariantResult [Line: 292]: Loop Invariant Derived loop invariant: pumpRunning == 0 && splverifierCounter == 0 - InvariantResult [Line: 862]: Loop Invariant Derived loop invariant: !(pumpRunning == 0) - InvariantResult [Line: 882]: Loop Invariant Derived loop invariant: pumpRunning == 0 && 1 == systemActive - InvariantResult [Line: 838]: Loop Invariant Derived loop invariant: 1 - InvariantResult [Line: 228]: Loop Invariant Derived loop invariant: 0 - InvariantResult [Line: 763]: Loop Invariant Derived loop invariant: 1 RESULT: Ultimate proved your program to be correct! [2022-02-20 18:11:32,421 INFO L552 MonitoredProcess]: [MP /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in -t:2000 (1)] Ended with exit code 0 Received shutdown request... --- End real Ultimate output --- Execution finished normally Writing output log to file Ultimate.log Result: TRUE