./Ultimate.py --spec ../sv-benchmarks/c/properties/unreach-call.prp --file ../sv-benchmarks/c/product-lines/minepump_spec5_product12.cil.c --full-output -ea --architecture 32bit -------------------------------------------------------------------------------- Checking for ERROR reachability Using default analysis Version 03d7b7b3 Calling Ultimate with: /usr/bin/java -Dosgi.configuration.area=/storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/data/config -Xmx15G -Xms4m -ea -jar /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/plugins/org.eclipse.equinox.launcher_1.5.800.v20200727-1323.jar -data @noDefault -ultimatedata /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/data -tc /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/config/AutomizerReach.xml -i ../sv-benchmarks/c/product-lines/minepump_spec5_product12.cil.c -s /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/config/svcomp-Reach-32bit-Automizer_Default.epf --cacsl2boogietranslator.entry.function main --witnessprinter.witness.directory /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux --witnessprinter.witness.filename witness.graphml --witnessprinter.write.witness.besides.input.file false --witnessprinter.graph.data.specification CHECK( init(main()), LTL(G ! call(reach_error())) ) --witnessprinter.graph.data.producer Automizer --witnessprinter.graph.data.architecture 32bit --witnessprinter.graph.data.programhash a08a330faab409752e65fe7d3101f81f24601e18bc944ca2e918542b1c9d8232 --- Real Ultimate output --- This is Ultimate 0.2.2-dev-03d7b7b [2022-02-20 18:11:37,453 INFO L177 SettingsManager]: Resetting all preferences to default values... [2022-02-20 18:11:37,457 INFO L181 SettingsManager]: Resetting UltimateCore preferences to default values [2022-02-20 18:11:37,504 INFO L184 SettingsManager]: Ultimate Commandline Interface provides no preferences, ignoring... [2022-02-20 18:11:37,505 INFO L181 SettingsManager]: Resetting Boogie Preprocessor preferences to default values [2022-02-20 18:11:37,509 INFO L181 SettingsManager]: Resetting Boogie Procedure Inliner preferences to default values [2022-02-20 18:11:37,511 INFO L181 SettingsManager]: Resetting Abstract Interpretation preferences to default values [2022-02-20 18:11:37,516 INFO L181 SettingsManager]: Resetting LassoRanker preferences to default values [2022-02-20 18:11:37,518 INFO L181 SettingsManager]: Resetting Reaching Definitions preferences to default values [2022-02-20 18:11:37,519 INFO L181 SettingsManager]: Resetting SyntaxChecker preferences to default values [2022-02-20 18:11:37,520 INFO L181 SettingsManager]: Resetting Sifa preferences to default values [2022-02-20 18:11:37,523 INFO L184 SettingsManager]: Büchi Program Product provides no preferences, ignoring... [2022-02-20 18:11:37,523 INFO L181 SettingsManager]: Resetting LTL2Aut preferences to default values [2022-02-20 18:11:37,530 INFO L181 SettingsManager]: Resetting PEA to Boogie preferences to default values [2022-02-20 18:11:37,532 INFO L181 SettingsManager]: Resetting BlockEncodingV2 preferences to default values [2022-02-20 18:11:37,534 INFO L181 SettingsManager]: Resetting ChcToBoogie preferences to default values [2022-02-20 18:11:37,538 INFO L181 SettingsManager]: Resetting AutomataScriptInterpreter preferences to default values [2022-02-20 18:11:37,540 INFO L181 SettingsManager]: Resetting BuchiAutomizer preferences to default values [2022-02-20 18:11:37,542 INFO L181 SettingsManager]: Resetting CACSL2BoogieTranslator preferences to default values [2022-02-20 18:11:37,544 INFO L181 SettingsManager]: Resetting CodeCheck preferences to default values [2022-02-20 18:11:37,548 INFO L181 SettingsManager]: Resetting InvariantSynthesis preferences to default values [2022-02-20 18:11:37,550 INFO L181 SettingsManager]: Resetting RCFGBuilder preferences to default values [2022-02-20 18:11:37,552 INFO L181 SettingsManager]: Resetting Referee preferences to default values [2022-02-20 18:11:37,553 INFO L181 SettingsManager]: Resetting TraceAbstraction preferences to default values [2022-02-20 18:11:37,559 INFO L184 SettingsManager]: TraceAbstractionConcurrent provides no preferences, ignoring... [2022-02-20 18:11:37,559 INFO L184 SettingsManager]: TraceAbstractionWithAFAs provides no preferences, ignoring... [2022-02-20 18:11:37,559 INFO L181 SettingsManager]: Resetting TreeAutomizer preferences to default values [2022-02-20 18:11:37,561 INFO L181 SettingsManager]: Resetting IcfgToChc preferences to default values [2022-02-20 18:11:37,562 INFO L181 SettingsManager]: Resetting IcfgTransformer preferences to default values [2022-02-20 18:11:37,562 INFO L184 SettingsManager]: ReqToTest provides no preferences, ignoring... [2022-02-20 18:11:37,563 INFO L181 SettingsManager]: Resetting Boogie Printer preferences to default values [2022-02-20 18:11:37,564 INFO L181 SettingsManager]: Resetting ChcSmtPrinter preferences to default values [2022-02-20 18:11:37,565 INFO L181 SettingsManager]: Resetting ReqPrinter preferences to default values [2022-02-20 18:11:37,566 INFO L181 SettingsManager]: Resetting Witness Printer preferences to default values [2022-02-20 18:11:37,568 INFO L184 SettingsManager]: Boogie PL CUP Parser provides no preferences, ignoring... [2022-02-20 18:11:37,568 INFO L181 SettingsManager]: Resetting CDTParser preferences to default values [2022-02-20 18:11:37,569 INFO L184 SettingsManager]: AutomataScriptParser provides no preferences, ignoring... [2022-02-20 18:11:37,569 INFO L184 SettingsManager]: ReqParser provides no preferences, ignoring... [2022-02-20 18:11:37,570 INFO L181 SettingsManager]: Resetting SmtParser preferences to default values [2022-02-20 18:11:37,570 INFO L181 SettingsManager]: Resetting Witness Parser preferences to default values [2022-02-20 18:11:37,571 INFO L188 SettingsManager]: Finished resetting all preferences to default values... [2022-02-20 18:11:37,572 INFO L101 SettingsManager]: Beginning loading settings from /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/config/svcomp-Reach-32bit-Automizer_Default.epf [2022-02-20 18:11:37,606 INFO L113 SettingsManager]: Loading preferences was successful [2022-02-20 18:11:37,607 INFO L115 SettingsManager]: Preferences different from defaults after loading the file: [2022-02-20 18:11:37,607 INFO L136 SettingsManager]: Preferences of UltimateCore differ from their defaults: [2022-02-20 18:11:37,608 INFO L138 SettingsManager]: * Log level for class=de.uni_freiburg.informatik.ultimate.lib.smtlibutils.quantifier.QuantifierPusher=ERROR; [2022-02-20 18:11:37,609 INFO L136 SettingsManager]: Preferences of Boogie Procedure Inliner differ from their defaults: [2022-02-20 18:11:37,609 INFO L138 SettingsManager]: * Ignore calls to procedures called more than once=ONLY_FOR_SEQUENTIAL_PROGRAMS [2022-02-20 18:11:37,609 INFO L136 SettingsManager]: Preferences of BlockEncodingV2 differ from their defaults: [2022-02-20 18:11:37,609 INFO L138 SettingsManager]: * Create parallel compositions if possible=false [2022-02-20 18:11:37,610 INFO L138 SettingsManager]: * Use SBE=true [2022-02-20 18:11:37,610 INFO L136 SettingsManager]: Preferences of CACSL2BoogieTranslator differ from their defaults: [2022-02-20 18:11:37,611 INFO L138 SettingsManager]: * sizeof long=4 [2022-02-20 18:11:37,611 INFO L138 SettingsManager]: * Overapproximate operations on floating types=true [2022-02-20 18:11:37,611 INFO L138 SettingsManager]: * sizeof POINTER=4 [2022-02-20 18:11:37,611 INFO L138 SettingsManager]: * Check division by zero=IGNORE [2022-02-20 18:11:37,612 INFO L138 SettingsManager]: * Pointer to allocated memory at dereference=IGNORE [2022-02-20 18:11:37,612 INFO L138 SettingsManager]: * If two pointers are subtracted or compared they have the same base address=IGNORE [2022-02-20 18:11:37,612 INFO L138 SettingsManager]: * Check array bounds for arrays that are off heap=IGNORE [2022-02-20 18:11:37,612 INFO L138 SettingsManager]: * sizeof long double=12 [2022-02-20 18:11:37,612 INFO L138 SettingsManager]: * Check if freed pointer was valid=false [2022-02-20 18:11:37,612 INFO L138 SettingsManager]: * Use constant arrays=true [2022-02-20 18:11:37,613 INFO L138 SettingsManager]: * Pointer base address is valid at dereference=IGNORE [2022-02-20 18:11:37,613 INFO L136 SettingsManager]: Preferences of RCFGBuilder differ from their defaults: [2022-02-20 18:11:37,613 INFO L138 SettingsManager]: * Size of a code block=SequenceOfStatements [2022-02-20 18:11:37,613 INFO L138 SettingsManager]: * SMT solver=External_DefaultMode [2022-02-20 18:11:37,613 INFO L138 SettingsManager]: * Command for external solver=z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in -t:2000 [2022-02-20 18:11:37,614 INFO L136 SettingsManager]: Preferences of TraceAbstraction differ from their defaults: [2022-02-20 18:11:37,614 INFO L138 SettingsManager]: * Compute Interpolants along a Counterexample=FPandBP [2022-02-20 18:11:37,614 INFO L138 SettingsManager]: * Positions where we compute the Hoare Annotation=LoopsAndPotentialCycles [2022-02-20 18:11:37,614 INFO L138 SettingsManager]: * Trace refinement strategy=CAMEL [2022-02-20 18:11:37,614 INFO L138 SettingsManager]: * Command for external solver=z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in [2022-02-20 18:11:37,615 INFO L138 SettingsManager]: * Large block encoding in concurrent analysis=OFF [2022-02-20 18:11:37,615 INFO L138 SettingsManager]: * Automaton type used in concurrency analysis=PETRI_NET [2022-02-20 18:11:37,615 INFO L138 SettingsManager]: * Compute Hoare Annotation of negated interpolant automaton, abstraction and CFG=true [2022-02-20 18:11:37,615 INFO L138 SettingsManager]: * SMT solver=External_ModelsAndUnsatCoreMode WARNING: An illegal reflective access operation has occurred WARNING: Illegal reflective access by com.sun.xml.bind.v2.runtime.reflect.opt.Injector$1 (file:/storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/plugins/com.sun.xml.bind_2.2.0.v201505121915.jar) to method java.lang.ClassLoader.defineClass(java.lang.String,byte[],int,int) WARNING: Please consider reporting this to the maintainers of com.sun.xml.bind.v2.runtime.reflect.opt.Injector$1 WARNING: Use --illegal-access=warn to enable warnings of further illegal reflective access operations WARNING: All illegal access operations will be denied in a future release Applying setting for plugin de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator: Entry function -> main Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Witness directory -> /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Witness filename -> witness.graphml Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Write witness besides input file -> false Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Graph data specification -> CHECK( init(main()), LTL(G ! call(reach_error())) ) Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Graph data producer -> Automizer Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Graph data architecture -> 32bit Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Graph data programhash -> a08a330faab409752e65fe7d3101f81f24601e18bc944ca2e918542b1c9d8232 [2022-02-20 18:11:37,900 INFO L75 nceAwareModelManager]: Repository-Root is: /tmp [2022-02-20 18:11:37,924 INFO L261 ainManager$Toolchain]: [Toolchain 1]: Applicable parser(s) successfully (re)initialized [2022-02-20 18:11:37,927 INFO L217 ainManager$Toolchain]: [Toolchain 1]: Toolchain selected. [2022-02-20 18:11:37,928 INFO L271 PluginConnector]: Initializing CDTParser... [2022-02-20 18:11:37,929 INFO L275 PluginConnector]: CDTParser initialized [2022-02-20 18:11:37,930 INFO L432 ainManager$Toolchain]: [Toolchain 1]: Parsing single file: /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/../sv-benchmarks/c/product-lines/minepump_spec5_product12.cil.c [2022-02-20 18:11:37,993 INFO L220 CDTParser]: Created temporary CDT project at /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/data/40b43851e/c28e9720fb0547ed8f785c3b4bf09235/FLAG4d5c06b64 [2022-02-20 18:11:38,508 INFO L306 CDTParser]: Found 1 translation units. [2022-02-20 18:11:38,516 INFO L160 CDTParser]: Scanning /storage/repos/ultimate/releaseScripts/default/sv-benchmarks/c/product-lines/minepump_spec5_product12.cil.c [2022-02-20 18:11:38,527 INFO L349 CDTParser]: About to delete temporary CDT project at /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/data/40b43851e/c28e9720fb0547ed8f785c3b4bf09235/FLAG4d5c06b64 [2022-02-20 18:11:38,984 INFO L357 CDTParser]: Successfully deleted /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/data/40b43851e/c28e9720fb0547ed8f785c3b4bf09235 [2022-02-20 18:11:38,986 INFO L299 ainManager$Toolchain]: ####################### [Toolchain 1] ####################### [2022-02-20 18:11:38,987 INFO L131 ToolchainWalker]: Walking toolchain with 6 elements. [2022-02-20 18:11:38,989 INFO L113 PluginConnector]: ------------------------CACSL2BoogieTranslator---------------------------- [2022-02-20 18:11:38,989 INFO L271 PluginConnector]: Initializing CACSL2BoogieTranslator... [2022-02-20 18:11:38,992 INFO L275 PluginConnector]: CACSL2BoogieTranslator initialized [2022-02-20 18:11:38,993 INFO L185 PluginConnector]: Executing the observer ACSLObjectContainerObserver from plugin CACSL2BoogieTranslator for "CDTParser AST 20.02 06:11:38" (1/1) ... [2022-02-20 18:11:38,994 INFO L205 PluginConnector]: Invalid model from CACSL2BoogieTranslator for observer de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator.ACSLObjectContainerObserver@327abd90 and model type de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 20.02 06:11:38, skipping insertion in model container [2022-02-20 18:11:38,995 INFO L185 PluginConnector]: Executing the observer CACSL2BoogieTranslatorObserver from plugin CACSL2BoogieTranslator for "CDTParser AST 20.02 06:11:38" (1/1) ... [2022-02-20 18:11:39,010 INFO L145 MainTranslator]: Starting translation in SV-COMP mode [2022-02-20 18:11:39,048 INFO L178 MainTranslator]: Built tables and reachable declarations [2022-02-20 18:11:39,250 WARN L230 ndardFunctionHandler]: Function reach_error is already implemented but we override the implementation for the call at /storage/repos/ultimate/releaseScripts/default/sv-benchmarks/c/product-lines/minepump_spec5_product12.cil.c[6299,6312] [2022-02-20 18:11:39,324 INFO L210 PostProcessor]: Analyzing one entry point: main [2022-02-20 18:11:39,332 INFO L203 MainTranslator]: Completed pre-run [2022-02-20 18:11:39,384 WARN L230 ndardFunctionHandler]: Function reach_error is already implemented but we override the implementation for the call at /storage/repos/ultimate/releaseScripts/default/sv-benchmarks/c/product-lines/minepump_spec5_product12.cil.c[6299,6312] [2022-02-20 18:11:39,439 INFO L210 PostProcessor]: Analyzing one entry point: main [2022-02-20 18:11:39,458 INFO L208 MainTranslator]: Completed translation [2022-02-20 18:11:39,459 INFO L202 PluginConnector]: Adding new model de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 20.02 06:11:39 WrapperNode [2022-02-20 18:11:39,459 INFO L132 PluginConnector]: ------------------------ END CACSL2BoogieTranslator---------------------------- [2022-02-20 18:11:39,460 INFO L113 PluginConnector]: ------------------------Boogie Procedure Inliner---------------------------- [2022-02-20 18:11:39,460 INFO L271 PluginConnector]: Initializing Boogie Procedure Inliner... [2022-02-20 18:11:39,460 INFO L275 PluginConnector]: Boogie Procedure Inliner initialized [2022-02-20 18:11:39,466 INFO L185 PluginConnector]: Executing the observer TypeChecker from plugin Boogie Procedure Inliner for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 20.02 06:11:39" (1/1) ... [2022-02-20 18:11:39,489 INFO L185 PluginConnector]: Executing the observer Inliner from plugin Boogie Procedure Inliner for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 20.02 06:11:39" (1/1) ... [2022-02-20 18:11:39,520 INFO L137 Inliner]: procedures = 54, calls = 152, calls flagged for inlining = 24, calls inlined = 18, statements flattened = 201 [2022-02-20 18:11:39,520 INFO L132 PluginConnector]: ------------------------ END Boogie Procedure Inliner---------------------------- [2022-02-20 18:11:39,521 INFO L113 PluginConnector]: ------------------------Boogie Preprocessor---------------------------- [2022-02-20 18:11:39,521 INFO L271 PluginConnector]: Initializing Boogie Preprocessor... [2022-02-20 18:11:39,521 INFO L275 PluginConnector]: Boogie Preprocessor initialized [2022-02-20 18:11:39,529 INFO L185 PluginConnector]: Executing the observer EnsureBoogieModelObserver from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 20.02 06:11:39" (1/1) ... [2022-02-20 18:11:39,530 INFO L185 PluginConnector]: Executing the observer TypeChecker from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 20.02 06:11:39" (1/1) ... [2022-02-20 18:11:39,532 INFO L185 PluginConnector]: Executing the observer ConstExpander from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 20.02 06:11:39" (1/1) ... [2022-02-20 18:11:39,532 INFO L185 PluginConnector]: Executing the observer StructExpander from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 20.02 06:11:39" (1/1) ... [2022-02-20 18:11:39,539 INFO L185 PluginConnector]: Executing the observer UnstructureCode from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 20.02 06:11:39" (1/1) ... [2022-02-20 18:11:39,545 INFO L185 PluginConnector]: Executing the observer FunctionInliner from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 20.02 06:11:39" (1/1) ... [2022-02-20 18:11:39,546 INFO L185 PluginConnector]: Executing the observer BoogieSymbolTableConstructor from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 20.02 06:11:39" (1/1) ... [2022-02-20 18:11:39,549 INFO L132 PluginConnector]: ------------------------ END Boogie Preprocessor---------------------------- [2022-02-20 18:11:39,550 INFO L113 PluginConnector]: ------------------------RCFGBuilder---------------------------- [2022-02-20 18:11:39,550 INFO L271 PluginConnector]: Initializing RCFGBuilder... [2022-02-20 18:11:39,550 INFO L275 PluginConnector]: RCFGBuilder initialized [2022-02-20 18:11:39,555 INFO L185 PluginConnector]: Executing the observer RCFGBuilderObserver from plugin RCFGBuilder for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 20.02 06:11:39" (1/1) ... [2022-02-20 18:11:39,569 INFO L173 SolverBuilder]: Constructing external solver with command: z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in -t:2000 [2022-02-20 18:11:39,579 INFO L189 MonitoredProcess]: No working directory specified, using /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 [2022-02-20 18:11:39,592 INFO L229 MonitoredProcess]: Starting monitored process 1 with /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in -t:2000 (exit command is (exit), workingDir is null) [2022-02-20 18:11:39,600 INFO L327 MonitoredProcess]: [MP /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in -t:2000 (1)] Waiting until timeout for monitored process [2022-02-20 18:11:39,630 INFO L130 BoogieDeclarations]: Found specification of procedure #Ultimate.allocInit [2022-02-20 18:11:39,630 INFO L130 BoogieDeclarations]: Found specification of procedure cleanup [2022-02-20 18:11:39,631 INFO L138 BoogieDeclarations]: Found implementation of procedure cleanup [2022-02-20 18:11:39,631 INFO L130 BoogieDeclarations]: Found specification of procedure timeShift [2022-02-20 18:11:39,631 INFO L138 BoogieDeclarations]: Found implementation of procedure timeShift [2022-02-20 18:11:39,631 INFO L130 BoogieDeclarations]: Found specification of procedure waterRise [2022-02-20 18:11:39,631 INFO L138 BoogieDeclarations]: Found implementation of procedure waterRise [2022-02-20 18:11:39,631 INFO L130 BoogieDeclarations]: Found specification of procedure isPumpRunning [2022-02-20 18:11:39,633 INFO L138 BoogieDeclarations]: Found implementation of procedure isPumpRunning [2022-02-20 18:11:39,634 INFO L130 BoogieDeclarations]: Found specification of procedure write~init~int [2022-02-20 18:11:39,634 INFO L130 BoogieDeclarations]: Found specification of procedure changeMethaneLevel [2022-02-20 18:11:39,634 INFO L138 BoogieDeclarations]: Found implementation of procedure changeMethaneLevel [2022-02-20 18:11:39,635 INFO L130 BoogieDeclarations]: Found specification of procedure ULTIMATE.start [2022-02-20 18:11:39,635 INFO L138 BoogieDeclarations]: Found implementation of procedure ULTIMATE.start [2022-02-20 18:11:39,739 INFO L234 CfgBuilder]: Building ICFG [2022-02-20 18:11:39,740 INFO L260 CfgBuilder]: Building CFG for each procedure with an implementation [2022-02-20 18:11:40,101 INFO L275 CfgBuilder]: Performing block encoding [2022-02-20 18:11:40,108 INFO L294 CfgBuilder]: Using the 1 location(s) as analysis (start of procedure ULTIMATE.start) [2022-02-20 18:11:40,108 INFO L299 CfgBuilder]: Removed 2 assume(true) statements. [2022-02-20 18:11:40,110 INFO L202 PluginConnector]: Adding new model de.uni_freiburg.informatik.ultimate.plugins.generator.rcfgbuilder CFG 20.02 06:11:40 BoogieIcfgContainer [2022-02-20 18:11:40,110 INFO L132 PluginConnector]: ------------------------ END RCFGBuilder---------------------------- [2022-02-20 18:11:40,112 INFO L113 PluginConnector]: ------------------------TraceAbstraction---------------------------- [2022-02-20 18:11:40,119 INFO L271 PluginConnector]: Initializing TraceAbstraction... [2022-02-20 18:11:40,122 INFO L275 PluginConnector]: TraceAbstraction initialized [2022-02-20 18:11:40,122 INFO L185 PluginConnector]: Executing the observer TraceAbstractionObserver from plugin TraceAbstraction for "CDTParser AST 20.02 06:11:38" (1/3) ... [2022-02-20 18:11:40,123 INFO L205 PluginConnector]: Invalid model from TraceAbstraction for observer de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction.TraceAbstractionObserver@223159f4 and model type de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction AST 20.02 06:11:40, skipping insertion in model container [2022-02-20 18:11:40,123 INFO L185 PluginConnector]: Executing the observer TraceAbstractionObserver from plugin TraceAbstraction for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 20.02 06:11:39" (2/3) ... [2022-02-20 18:11:40,123 INFO L205 PluginConnector]: Invalid model from TraceAbstraction for observer de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction.TraceAbstractionObserver@223159f4 and model type de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction AST 20.02 06:11:40, skipping insertion in model container [2022-02-20 18:11:40,124 INFO L185 PluginConnector]: Executing the observer TraceAbstractionObserver from plugin TraceAbstraction for "de.uni_freiburg.informatik.ultimate.plugins.generator.rcfgbuilder CFG 20.02 06:11:40" (3/3) ... [2022-02-20 18:11:40,125 INFO L111 eAbstractionObserver]: Analyzing ICFG minepump_spec5_product12.cil.c [2022-02-20 18:11:40,130 INFO L205 ceAbstractionStarter]: Automizer settings: Hoare:true NWA Interpolation:FPandBP Determinization: PREDICATE_ABSTRACTION [2022-02-20 18:11:40,131 INFO L164 ceAbstractionStarter]: Applying trace abstraction to program that has 1 error locations. [2022-02-20 18:11:40,202 INFO L338 AbstractCegarLoop]: ======== Iteration 0 == of CEGAR loop == AllErrorsAtOnce ======== [2022-02-20 18:11:40,209 INFO L339 AbstractCegarLoop]: Settings: SEPARATE_VIOLATION_CHECK=true, mInterprocedural=true, mMaxIterations=1000000, mWatchIteration=1000000, mArtifact=RCFG, mInterpolation=FPandBP, mInterpolantAutomaton=STRAIGHT_LINE, mDumpAutomata=false, mAutomataFormat=ATS_NUMERATE, mDumpPath=., mDeterminiation=PREDICATE_ABSTRACTION, mMinimize=MINIMIZE_SEVPA, mHoare=true, mAutomataTypeConcurrency=PETRI_NET, mHoareTripleChecks=INCREMENTAL, mHoareAnnotationPositions=LoopsAndPotentialCycles, mDumpOnlyReuseAutomata=false, mLimitTraceHistogram=0, mErrorLocTimeLimit=0, mLimitPathProgramCount=0, mCollectInterpolantStatistics=true, mHeuristicEmptinessCheck=false, mHeuristicEmptinessCheckAStarHeuristic=ZERO, mHeuristicEmptinessCheckAStarHeuristicRandomSeed=1337, mHeuristicEmptinessCheckSmtFeatureScoringMethod=DAGSIZE, mSMTFeatureExtraction=false, mSMTFeatureExtractionDumpPath=., mOverrideInterpolantAutomaton=false, mMcrInterpolantMethod=WP, mLoopAccelerationTechnique=FAST_UPR [2022-02-20 18:11:40,210 INFO L340 AbstractCegarLoop]: Starting to check reachability of 1 error locations. [2022-02-20 18:11:40,249 INFO L276 IsEmpty]: Start isEmpty. Operand has 73 states, 58 states have (on average 1.3620689655172413) internal successors, (79), 62 states have internal predecessors, (79), 8 states have call successors, (8), 5 states have call predecessors, (8), 5 states have return successors, (8), 8 states have call predecessors, (8), 8 states have call successors, (8) [2022-02-20 18:11:40,258 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 33 [2022-02-20 18:11:40,258 INFO L506 BasicCegarLoop]: Found error trace [2022-02-20 18:11:40,259 INFO L514 BasicCegarLoop]: trace histogram [2, 2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-02-20 18:11:40,260 INFO L402 AbstractCegarLoop]: === Iteration 1 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2022-02-20 18:11:40,269 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2022-02-20 18:11:40,270 INFO L85 PathProgramCache]: Analyzing trace with hash -1691668141, now seen corresponding path program 1 times [2022-02-20 18:11:40,282 INFO L126 FreeRefinementEngine]: Executing refinement strategy CAMEL [2022-02-20 18:11:40,283 INFO L338 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [1038229620] [2022-02-20 18:11:40,283 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-02-20 18:11:40,284 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2022-02-20 18:11:40,474 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-02-20 18:11:40,574 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 13 [2022-02-20 18:11:40,580 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-02-20 18:11:40,600 INFO L290 TraceCheckUtils]: 0: Hoare triple {76#true} havoc ~retValue_acc~1;~retValue_acc~1 := ~pumpRunning~0;#res := ~retValue_acc~1; {76#true} is VALID [2022-02-20 18:11:40,601 INFO L290 TraceCheckUtils]: 1: Hoare triple {76#true} assume true; {76#true} is VALID [2022-02-20 18:11:40,601 INFO L284 TraceCheckUtils]: 2: Hoare quadruple {76#true} {77#false} #194#return; {77#false} is VALID [2022-02-20 18:11:40,602 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 24 [2022-02-20 18:11:40,605 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-02-20 18:11:40,619 INFO L290 TraceCheckUtils]: 0: Hoare triple {76#true} havoc ~retValue_acc~1;~retValue_acc~1 := ~pumpRunning~0;#res := ~retValue_acc~1; {76#true} is VALID [2022-02-20 18:11:40,620 INFO L290 TraceCheckUtils]: 1: Hoare triple {76#true} assume true; {76#true} is VALID [2022-02-20 18:11:40,620 INFO L284 TraceCheckUtils]: 2: Hoare quadruple {76#true} {77#false} #196#return; {77#false} is VALID [2022-02-20 18:11:40,621 INFO L290 TraceCheckUtils]: 0: Hoare triple {76#true} assume { :begin_inline_ULTIMATE.init } true;#NULL.base, #NULL.offset := 0, 0;assume 0 == #valid[0];assume 0 < #StackHeapBarrier;call #Ultimate.allocInit(2, 1);call write~init~int(48, 1, 0, 1);call write~init~int(0, 1, 1, 1);call #Ultimate.allocInit(31, 2);call #Ultimate.allocInit(12, 3);call #Ultimate.allocInit(13, 4);call #Ultimate.allocInit(3, 5);call write~init~int(79, 5, 0, 1);call write~init~int(110, 5, 1, 1);call write~init~int(0, 5, 2, 1);call #Ultimate.allocInit(4, 6);call write~init~int(79, 6, 0, 1);call write~init~int(102, 6, 1, 1);call write~init~int(102, 6, 2, 1);call write~init~int(0, 6, 3, 1);call #Ultimate.allocInit(7, 7);call write~init~int(44, 7, 0, 1);call write~init~int(80, 7, 1, 1);call write~init~int(117, 7, 2, 1);call write~init~int(109, 7, 3, 1);call write~init~int(112, 7, 4, 1);call write~init~int(58, 7, 5, 1);call write~init~int(0, 7, 6, 1);call #Ultimate.allocInit(3, 8);call write~init~int(79, 8, 0, 1);call write~init~int(110, 8, 1, 1);call write~init~int(0, 8, 2, 1);call #Ultimate.allocInit(4, 9);call write~init~int(79, 9, 0, 1);call write~init~int(102, 9, 1, 1);call write~init~int(102, 9, 2, 1);call write~init~int(0, 9, 3, 1);call #Ultimate.allocInit(3, 10);call write~init~int(41, 10, 0, 1);call write~init~int(32, 10, 1, 1);call write~init~int(0, 10, 2, 1);call #Ultimate.allocInit(2, 11);call write~init~int(10, 11, 0, 1);call write~init~int(0, 11, 1, 1);call #Ultimate.allocInit(13, 12);call #Ultimate.allocInit(7, 13);call write~init~int(44, 13, 0, 1);call write~init~int(77, 13, 1, 1);call write~init~int(101, 13, 2, 1);call write~init~int(116, 13, 3, 1);call write~init~int(104, 13, 4, 1);call write~init~int(58, 13, 5, 1);call write~init~int(0, 13, 6, 1);call #Ultimate.allocInit(5, 14);call write~init~int(67, 14, 0, 1);call write~init~int(82, 14, 1, 1);call write~init~int(73, 14, 2, 1);call write~init~int(84, 14, 3, 1);call write~init~int(0, 14, 4, 1);call #Ultimate.allocInit(3, 15);call write~init~int(79, 15, 0, 1);call write~init~int(75, 15, 1, 1);call write~init~int(0, 15, 2, 1);call #Ultimate.allocInit(2, 16);call write~init~int(41, 16, 0, 1);call write~init~int(0, 16, 1, 1);call #Ultimate.allocInit(30, 17);call #Ultimate.allocInit(9, 18);call #Ultimate.allocInit(21, 19);call #Ultimate.allocInit(30, 20);call #Ultimate.allocInit(9, 21);call #Ultimate.allocInit(21, 22);call #Ultimate.allocInit(30, 23);call #Ultimate.allocInit(9, 24);call #Ultimate.allocInit(25, 25);call #Ultimate.allocInit(30, 26);call #Ultimate.allocInit(9, 27);call #Ultimate.allocInit(25, 28);~switchedOnBeforeTS~0 := 0;~pumpRunning~0 := 0;~systemActive~0 := 1;~waterLevel~0 := 1;~methaneLevelCritical~0 := 0;~cleanupTimeShifts~0 := 4;~head~0.base, ~head~0.offset := 0, 0; {76#true} is VALID [2022-02-20 18:11:40,621 INFO L290 TraceCheckUtils]: 1: Hoare triple {76#true} assume { :end_inline_ULTIMATE.init } true;assume { :begin_inline_main } true;havoc main_#res#1;havoc main_#t~ret26#1, main_~retValue_acc~4#1, main_~tmp~3#1;havoc main_~retValue_acc~4#1;havoc main_~tmp~3#1;assume { :begin_inline_select_helpers } true; {76#true} is VALID [2022-02-20 18:11:40,621 INFO L290 TraceCheckUtils]: 2: Hoare triple {76#true} assume { :end_inline_select_helpers } true;assume { :begin_inline_select_features } true; {76#true} is VALID [2022-02-20 18:11:40,621 INFO L290 TraceCheckUtils]: 3: Hoare triple {76#true} assume { :end_inline_select_features } true;assume { :begin_inline_valid_product } true;havoc valid_product_#res#1;havoc valid_product_~retValue_acc~9#1;havoc valid_product_~retValue_acc~9#1;valid_product_~retValue_acc~9#1 := 1;valid_product_#res#1 := valid_product_~retValue_acc~9#1; {76#true} is VALID [2022-02-20 18:11:40,622 INFO L290 TraceCheckUtils]: 4: Hoare triple {76#true} main_#t~ret26#1 := valid_product_#res#1;assume { :end_inline_valid_product } true;assume -2147483648 <= main_#t~ret26#1 && main_#t~ret26#1 <= 2147483647;main_~tmp~3#1 := main_#t~ret26#1;havoc main_#t~ret26#1; {76#true} is VALID [2022-02-20 18:11:40,622 INFO L290 TraceCheckUtils]: 5: Hoare triple {76#true} assume 0 != main_~tmp~3#1;assume { :begin_inline_setup } true; {76#true} is VALID [2022-02-20 18:11:40,622 INFO L290 TraceCheckUtils]: 6: Hoare triple {76#true} assume { :end_inline_setup } true;assume { :begin_inline_runTest } true;assume { :begin_inline___utac_acc__Specification5_spec__1 } true;~switchedOnBeforeTS~0 := 0; {76#true} is VALID [2022-02-20 18:11:40,622 INFO L290 TraceCheckUtils]: 7: Hoare triple {76#true} assume { :end_inline___utac_acc__Specification5_spec__1 } true;assume { :begin_inline_test } true;havoc test_#t~nondet22#1, test_#t~nondet23#1, test_#t~nondet24#1, test_#t~nondet25#1, test_~splverifierCounter~0#1, test_~tmp~2#1, test_~tmp___0~1#1, test_~tmp___1~0#1, test_~tmp___2~0#1;havoc test_~splverifierCounter~0#1;havoc test_~tmp~2#1;havoc test_~tmp___0~1#1;havoc test_~tmp___1~0#1;havoc test_~tmp___2~0#1;test_~splverifierCounter~0#1 := 0; {76#true} is VALID [2022-02-20 18:11:40,628 INFO L290 TraceCheckUtils]: 8: Hoare triple {76#true} assume false; {77#false} is VALID [2022-02-20 18:11:40,628 INFO L272 TraceCheckUtils]: 9: Hoare triple {77#false} call cleanup(); {77#false} is VALID [2022-02-20 18:11:40,629 INFO L290 TraceCheckUtils]: 10: Hoare triple {77#false} havoc ~i~0;havoc ~__cil_tmp2~0; {77#false} is VALID [2022-02-20 18:11:40,629 INFO L272 TraceCheckUtils]: 11: Hoare triple {77#false} call timeShift(); {77#false} is VALID [2022-02-20 18:11:40,629 INFO L290 TraceCheckUtils]: 12: Hoare triple {77#false} assume { :begin_inline___utac_acc__Specification5_spec__2 } true;havoc __utac_acc__Specification5_spec__2_#t~ret4#1; {77#false} is VALID [2022-02-20 18:11:40,631 INFO L272 TraceCheckUtils]: 13: Hoare triple {77#false} call __utac_acc__Specification5_spec__2_#t~ret4#1 := isPumpRunning(); {76#true} is VALID [2022-02-20 18:11:40,631 INFO L290 TraceCheckUtils]: 14: Hoare triple {76#true} havoc ~retValue_acc~1;~retValue_acc~1 := ~pumpRunning~0;#res := ~retValue_acc~1; {76#true} is VALID [2022-02-20 18:11:40,631 INFO L290 TraceCheckUtils]: 15: Hoare triple {76#true} assume true; {76#true} is VALID [2022-02-20 18:11:40,632 INFO L284 TraceCheckUtils]: 16: Hoare quadruple {76#true} {77#false} #194#return; {77#false} is VALID [2022-02-20 18:11:40,632 INFO L290 TraceCheckUtils]: 17: Hoare triple {77#false} assume -2147483648 <= __utac_acc__Specification5_spec__2_#t~ret4#1 && __utac_acc__Specification5_spec__2_#t~ret4#1 <= 2147483647;~switchedOnBeforeTS~0 := __utac_acc__Specification5_spec__2_#t~ret4#1;havoc __utac_acc__Specification5_spec__2_#t~ret4#1; {77#false} is VALID [2022-02-20 18:11:40,632 INFO L290 TraceCheckUtils]: 18: Hoare triple {77#false} assume { :end_inline___utac_acc__Specification5_spec__2 } true; {77#false} is VALID [2022-02-20 18:11:40,632 INFO L290 TraceCheckUtils]: 19: Hoare triple {77#false} assume !(0 != ~pumpRunning~0); {77#false} is VALID [2022-02-20 18:11:40,633 INFO L290 TraceCheckUtils]: 20: Hoare triple {77#false} assume !(0 != ~systemActive~0); {77#false} is VALID [2022-02-20 18:11:40,633 INFO L290 TraceCheckUtils]: 21: Hoare triple {77#false} assume { :begin_inline___utac_acc__Specification5_spec__3 } true;havoc __utac_acc__Specification5_spec__3_#t~ret5#1, __utac_acc__Specification5_spec__3_#t~ret6#1, __utac_acc__Specification5_spec__3_~tmp~0#1, __utac_acc__Specification5_spec__3_~tmp___0~0#1;havoc __utac_acc__Specification5_spec__3_~tmp~0#1;havoc __utac_acc__Specification5_spec__3_~tmp___0~0#1;assume { :begin_inline_getWaterLevel } true;havoc getWaterLevel_#res#1;havoc getWaterLevel_~retValue_acc~3#1;havoc getWaterLevel_~retValue_acc~3#1;getWaterLevel_~retValue_acc~3#1 := ~waterLevel~0;getWaterLevel_#res#1 := getWaterLevel_~retValue_acc~3#1; {77#false} is VALID [2022-02-20 18:11:40,633 INFO L290 TraceCheckUtils]: 22: Hoare triple {77#false} __utac_acc__Specification5_spec__3_#t~ret5#1 := getWaterLevel_#res#1;assume { :end_inline_getWaterLevel } true;assume -2147483648 <= __utac_acc__Specification5_spec__3_#t~ret5#1 && __utac_acc__Specification5_spec__3_#t~ret5#1 <= 2147483647;__utac_acc__Specification5_spec__3_~tmp~0#1 := __utac_acc__Specification5_spec__3_#t~ret5#1;havoc __utac_acc__Specification5_spec__3_#t~ret5#1; {77#false} is VALID [2022-02-20 18:11:40,634 INFO L290 TraceCheckUtils]: 23: Hoare triple {77#false} assume 2 != __utac_acc__Specification5_spec__3_~tmp~0#1; {77#false} is VALID [2022-02-20 18:11:40,634 INFO L272 TraceCheckUtils]: 24: Hoare triple {77#false} call __utac_acc__Specification5_spec__3_#t~ret6#1 := isPumpRunning(); {76#true} is VALID [2022-02-20 18:11:40,634 INFO L290 TraceCheckUtils]: 25: Hoare triple {76#true} havoc ~retValue_acc~1;~retValue_acc~1 := ~pumpRunning~0;#res := ~retValue_acc~1; {76#true} is VALID [2022-02-20 18:11:40,635 INFO L290 TraceCheckUtils]: 26: Hoare triple {76#true} assume true; {76#true} is VALID [2022-02-20 18:11:40,635 INFO L284 TraceCheckUtils]: 27: Hoare quadruple {76#true} {77#false} #196#return; {77#false} is VALID [2022-02-20 18:11:40,635 INFO L290 TraceCheckUtils]: 28: Hoare triple {77#false} assume -2147483648 <= __utac_acc__Specification5_spec__3_#t~ret6#1 && __utac_acc__Specification5_spec__3_#t~ret6#1 <= 2147483647;__utac_acc__Specification5_spec__3_~tmp___0~0#1 := __utac_acc__Specification5_spec__3_#t~ret6#1;havoc __utac_acc__Specification5_spec__3_#t~ret6#1; {77#false} is VALID [2022-02-20 18:11:40,636 INFO L290 TraceCheckUtils]: 29: Hoare triple {77#false} assume 0 != __utac_acc__Specification5_spec__3_~tmp___0~0#1; {77#false} is VALID [2022-02-20 18:11:40,636 INFO L290 TraceCheckUtils]: 30: Hoare triple {77#false} assume 0 == ~switchedOnBeforeTS~0;assume { :begin_inline___automaton_fail } true; {77#false} is VALID [2022-02-20 18:11:40,636 INFO L290 TraceCheckUtils]: 31: Hoare triple {77#false} assume !false; {77#false} is VALID [2022-02-20 18:11:40,637 INFO L134 CoverageAnalysis]: Checked inductivity of 3 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 3 trivial. 0 not checked. [2022-02-20 18:11:40,638 INFO L144 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2022-02-20 18:11:40,638 INFO L338 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [1038229620] [2022-02-20 18:11:40,639 INFO L165 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [1038229620] provided 1 perfect and 0 imperfect interpolant sequences [2022-02-20 18:11:40,639 INFO L191 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2022-02-20 18:11:40,640 INFO L204 FreeRefinementEngine]: Number of different interpolants: perfect sequences [2] imperfect sequences [] total 2 [2022-02-20 18:11:40,642 INFO L118 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [1847691258] [2022-02-20 18:11:40,643 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2022-02-20 18:11:40,649 INFO L78 Accepts]: Start accepts. Automaton has has 2 states, 2 states have (on average 12.0) internal successors, (24), 2 states have internal predecessors, (24), 1 states have call successors, (4), 2 states have call predecessors, (4), 1 states have return successors, (2), 1 states have call predecessors, (2), 1 states have call successors, (2) Word has length 32 [2022-02-20 18:11:40,651 INFO L84 Accepts]: Finished accepts. word is accepted. [2022-02-20 18:11:40,655 INFO L86 InductivityCheck]: Starting indutivity check of a Floyd-Hoare automaton with has 2 states, 2 states have (on average 12.0) internal successors, (24), 2 states have internal predecessors, (24), 1 states have call successors, (4), 2 states have call predecessors, (4), 1 states have return successors, (2), 1 states have call predecessors, (2), 1 states have call successors, (2) [2022-02-20 18:11:40,716 INFO L122 InductivityCheck]: Floyd-Hoare automaton has 30 edges. 30 inductive. 0 not inductive. 0 times theorem prover too weak to decide inductivity. [2022-02-20 18:11:40,717 INFO L546 AbstractCegarLoop]: INTERPOLANT automaton has 2 states [2022-02-20 18:11:40,717 INFO L108 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2022-02-20 18:11:40,744 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 2 interpolants. [2022-02-20 18:11:40,745 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=1, Invalid=1, Unknown=0, NotChecked=0, Total=2 [2022-02-20 18:11:40,749 INFO L87 Difference]: Start difference. First operand has 73 states, 58 states have (on average 1.3620689655172413) internal successors, (79), 62 states have internal predecessors, (79), 8 states have call successors, (8), 5 states have call predecessors, (8), 5 states have return successors, (8), 8 states have call predecessors, (8), 8 states have call successors, (8) Second operand has 2 states, 2 states have (on average 12.0) internal successors, (24), 2 states have internal predecessors, (24), 1 states have call successors, (4), 2 states have call predecessors, (4), 1 states have return successors, (2), 1 states have call predecessors, (2), 1 states have call successors, (2) [2022-02-20 18:11:40,845 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-02-20 18:11:40,846 INFO L93 Difference]: Finished difference Result 137 states and 184 transitions. [2022-02-20 18:11:40,846 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 2 states. [2022-02-20 18:11:40,847 INFO L78 Accepts]: Start accepts. Automaton has has 2 states, 2 states have (on average 12.0) internal successors, (24), 2 states have internal predecessors, (24), 1 states have call successors, (4), 2 states have call predecessors, (4), 1 states have return successors, (2), 1 states have call predecessors, (2), 1 states have call successors, (2) Word has length 32 [2022-02-20 18:11:40,847 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2022-02-20 18:11:40,848 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 2 states, 2 states have (on average 12.0) internal successors, (24), 2 states have internal predecessors, (24), 1 states have call successors, (4), 2 states have call predecessors, (4), 1 states have return successors, (2), 1 states have call predecessors, (2), 1 states have call successors, (2) [2022-02-20 18:11:40,860 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 2 states to 2 states and 184 transitions. [2022-02-20 18:11:40,861 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 2 states, 2 states have (on average 12.0) internal successors, (24), 2 states have internal predecessors, (24), 1 states have call successors, (4), 2 states have call predecessors, (4), 1 states have return successors, (2), 1 states have call predecessors, (2), 1 states have call successors, (2) [2022-02-20 18:11:40,868 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 2 states to 2 states and 184 transitions. [2022-02-20 18:11:40,869 INFO L86 InductivityCheck]: Starting indutivity check of a Floyd-Hoare automaton with 2 states and 184 transitions. [2022-02-20 18:11:41,036 INFO L122 InductivityCheck]: Floyd-Hoare automaton has 184 edges. 184 inductive. 0 not inductive. 0 times theorem prover too weak to decide inductivity. [2022-02-20 18:11:41,052 INFO L225 Difference]: With dead ends: 137 [2022-02-20 18:11:41,053 INFO L226 Difference]: Without dead ends: 64 [2022-02-20 18:11:41,057 INFO L932 BasicCegarLoop]: 0 DeclaredPredicates, 6 GetRequests, 6 SyntacticMatches, 0 SemanticMatches, 0 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 0 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=1, Invalid=1, Unknown=0, NotChecked=0, Total=2 [2022-02-20 18:11:41,062 INFO L933 BasicCegarLoop]: 89 mSDtfsCounter, 0 mSDsluCounter, 0 mSDsCounter, 0 mSdLazyCounter, 0 mSolverCounterSat, 0 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.0s Time, 0 mProtectedPredicate, 0 mProtectedAction, 0 SdHoareTripleChecker+Valid, 89 SdHoareTripleChecker+Invalid, 0 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 0 IncrementalHoareTripleChecker+Valid, 0 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.0s IncrementalHoareTripleChecker+Time [2022-02-20 18:11:41,064 INFO L934 BasicCegarLoop]: SdHoareTripleChecker [0 Valid, 89 Invalid, 0 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [0 Valid, 0 Invalid, 0 Unknown, 0 Unchecked, 0.0s Time] [2022-02-20 18:11:41,080 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 64 states. [2022-02-20 18:11:41,102 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 64 to 64. [2022-02-20 18:11:41,102 INFO L214 AbstractMinimizeNwa]: Start testing correctness of minimizeSevpa [2022-02-20 18:11:41,104 INFO L82 GeneralOperation]: Start isEquivalent. First operand 64 states. Second operand has 64 states, 51 states have (on average 1.2745098039215685) internal successors, (65), 54 states have internal predecessors, (65), 8 states have call successors, (8), 5 states have call predecessors, (8), 4 states have return successors, (7), 7 states have call predecessors, (7), 7 states have call successors, (7) [2022-02-20 18:11:41,112 INFO L74 IsIncluded]: Start isIncluded. First operand 64 states. Second operand has 64 states, 51 states have (on average 1.2745098039215685) internal successors, (65), 54 states have internal predecessors, (65), 8 states have call successors, (8), 5 states have call predecessors, (8), 4 states have return successors, (7), 7 states have call predecessors, (7), 7 states have call successors, (7) [2022-02-20 18:11:41,114 INFO L87 Difference]: Start difference. First operand 64 states. Second operand has 64 states, 51 states have (on average 1.2745098039215685) internal successors, (65), 54 states have internal predecessors, (65), 8 states have call successors, (8), 5 states have call predecessors, (8), 4 states have return successors, (7), 7 states have call predecessors, (7), 7 states have call successors, (7) [2022-02-20 18:11:41,127 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-02-20 18:11:41,128 INFO L93 Difference]: Finished difference Result 64 states and 80 transitions. [2022-02-20 18:11:41,128 INFO L276 IsEmpty]: Start isEmpty. Operand 64 states and 80 transitions. [2022-02-20 18:11:41,129 INFO L282 IsEmpty]: Finished isEmpty. No accepting run. [2022-02-20 18:11:41,129 INFO L83 IsIncluded]: Finished isIncluded. Language is included [2022-02-20 18:11:41,131 INFO L74 IsIncluded]: Start isIncluded. First operand has 64 states, 51 states have (on average 1.2745098039215685) internal successors, (65), 54 states have internal predecessors, (65), 8 states have call successors, (8), 5 states have call predecessors, (8), 4 states have return successors, (7), 7 states have call predecessors, (7), 7 states have call successors, (7) Second operand 64 states. [2022-02-20 18:11:41,132 INFO L87 Difference]: Start difference. First operand has 64 states, 51 states have (on average 1.2745098039215685) internal successors, (65), 54 states have internal predecessors, (65), 8 states have call successors, (8), 5 states have call predecessors, (8), 4 states have return successors, (7), 7 states have call predecessors, (7), 7 states have call successors, (7) Second operand 64 states. [2022-02-20 18:11:41,143 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-02-20 18:11:41,145 INFO L93 Difference]: Finished difference Result 64 states and 80 transitions. [2022-02-20 18:11:41,145 INFO L276 IsEmpty]: Start isEmpty. Operand 64 states and 80 transitions. [2022-02-20 18:11:41,147 INFO L282 IsEmpty]: Finished isEmpty. No accepting run. [2022-02-20 18:11:41,147 INFO L83 IsIncluded]: Finished isIncluded. Language is included [2022-02-20 18:11:41,148 INFO L88 GeneralOperation]: Finished isEquivalent. [2022-02-20 18:11:41,148 INFO L221 AbstractMinimizeNwa]: Finished testing correctness of minimizeSevpa [2022-02-20 18:11:41,149 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 64 states, 51 states have (on average 1.2745098039215685) internal successors, (65), 54 states have internal predecessors, (65), 8 states have call successors, (8), 5 states have call predecessors, (8), 4 states have return successors, (7), 7 states have call predecessors, (7), 7 states have call successors, (7) [2022-02-20 18:11:41,158 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 64 states to 64 states and 80 transitions. [2022-02-20 18:11:41,159 INFO L78 Accepts]: Start accepts. Automaton has 64 states and 80 transitions. Word has length 32 [2022-02-20 18:11:41,160 INFO L84 Accepts]: Finished accepts. word is rejected. [2022-02-20 18:11:41,160 INFO L470 AbstractCegarLoop]: Abstraction has 64 states and 80 transitions. [2022-02-20 18:11:41,161 INFO L471 AbstractCegarLoop]: INTERPOLANT automaton has has 2 states, 2 states have (on average 12.0) internal successors, (24), 2 states have internal predecessors, (24), 1 states have call successors, (4), 2 states have call predecessors, (4), 1 states have return successors, (2), 1 states have call predecessors, (2), 1 states have call successors, (2) [2022-02-20 18:11:41,161 INFO L276 IsEmpty]: Start isEmpty. Operand 64 states and 80 transitions. [2022-02-20 18:11:41,165 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 34 [2022-02-20 18:11:41,166 INFO L506 BasicCegarLoop]: Found error trace [2022-02-20 18:11:41,167 INFO L514 BasicCegarLoop]: trace histogram [2, 2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-02-20 18:11:41,167 WARN L452 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable0 [2022-02-20 18:11:41,168 INFO L402 AbstractCegarLoop]: === Iteration 2 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2022-02-20 18:11:41,169 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2022-02-20 18:11:41,169 INFO L85 PathProgramCache]: Analyzing trace with hash 1926580266, now seen corresponding path program 1 times [2022-02-20 18:11:41,169 INFO L126 FreeRefinementEngine]: Executing refinement strategy CAMEL [2022-02-20 18:11:41,169 INFO L338 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [492255490] [2022-02-20 18:11:41,170 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-02-20 18:11:41,170 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2022-02-20 18:11:41,223 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-02-20 18:11:41,288 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 14 [2022-02-20 18:11:41,297 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-02-20 18:11:41,304 INFO L290 TraceCheckUtils]: 0: Hoare triple {503#true} havoc ~retValue_acc~1;~retValue_acc~1 := ~pumpRunning~0;#res := ~retValue_acc~1; {503#true} is VALID [2022-02-20 18:11:41,305 INFO L290 TraceCheckUtils]: 1: Hoare triple {503#true} assume true; {503#true} is VALID [2022-02-20 18:11:41,305 INFO L284 TraceCheckUtils]: 2: Hoare quadruple {503#true} {504#false} #194#return; {504#false} is VALID [2022-02-20 18:11:41,306 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 25 [2022-02-20 18:11:41,312 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-02-20 18:11:41,324 INFO L290 TraceCheckUtils]: 0: Hoare triple {503#true} havoc ~retValue_acc~1;~retValue_acc~1 := ~pumpRunning~0;#res := ~retValue_acc~1; {503#true} is VALID [2022-02-20 18:11:41,324 INFO L290 TraceCheckUtils]: 1: Hoare triple {503#true} assume true; {503#true} is VALID [2022-02-20 18:11:41,324 INFO L284 TraceCheckUtils]: 2: Hoare quadruple {503#true} {504#false} #196#return; {504#false} is VALID [2022-02-20 18:11:41,325 INFO L290 TraceCheckUtils]: 0: Hoare triple {503#true} assume { :begin_inline_ULTIMATE.init } true;#NULL.base, #NULL.offset := 0, 0;assume 0 == #valid[0];assume 0 < #StackHeapBarrier;call #Ultimate.allocInit(2, 1);call write~init~int(48, 1, 0, 1);call write~init~int(0, 1, 1, 1);call #Ultimate.allocInit(31, 2);call #Ultimate.allocInit(12, 3);call #Ultimate.allocInit(13, 4);call #Ultimate.allocInit(3, 5);call write~init~int(79, 5, 0, 1);call write~init~int(110, 5, 1, 1);call write~init~int(0, 5, 2, 1);call #Ultimate.allocInit(4, 6);call write~init~int(79, 6, 0, 1);call write~init~int(102, 6, 1, 1);call write~init~int(102, 6, 2, 1);call write~init~int(0, 6, 3, 1);call #Ultimate.allocInit(7, 7);call write~init~int(44, 7, 0, 1);call write~init~int(80, 7, 1, 1);call write~init~int(117, 7, 2, 1);call write~init~int(109, 7, 3, 1);call write~init~int(112, 7, 4, 1);call write~init~int(58, 7, 5, 1);call write~init~int(0, 7, 6, 1);call #Ultimate.allocInit(3, 8);call write~init~int(79, 8, 0, 1);call write~init~int(110, 8, 1, 1);call write~init~int(0, 8, 2, 1);call #Ultimate.allocInit(4, 9);call write~init~int(79, 9, 0, 1);call write~init~int(102, 9, 1, 1);call write~init~int(102, 9, 2, 1);call write~init~int(0, 9, 3, 1);call #Ultimate.allocInit(3, 10);call write~init~int(41, 10, 0, 1);call write~init~int(32, 10, 1, 1);call write~init~int(0, 10, 2, 1);call #Ultimate.allocInit(2, 11);call write~init~int(10, 11, 0, 1);call write~init~int(0, 11, 1, 1);call #Ultimate.allocInit(13, 12);call #Ultimate.allocInit(7, 13);call write~init~int(44, 13, 0, 1);call write~init~int(77, 13, 1, 1);call write~init~int(101, 13, 2, 1);call write~init~int(116, 13, 3, 1);call write~init~int(104, 13, 4, 1);call write~init~int(58, 13, 5, 1);call write~init~int(0, 13, 6, 1);call #Ultimate.allocInit(5, 14);call write~init~int(67, 14, 0, 1);call write~init~int(82, 14, 1, 1);call write~init~int(73, 14, 2, 1);call write~init~int(84, 14, 3, 1);call write~init~int(0, 14, 4, 1);call #Ultimate.allocInit(3, 15);call write~init~int(79, 15, 0, 1);call write~init~int(75, 15, 1, 1);call write~init~int(0, 15, 2, 1);call #Ultimate.allocInit(2, 16);call write~init~int(41, 16, 0, 1);call write~init~int(0, 16, 1, 1);call #Ultimate.allocInit(30, 17);call #Ultimate.allocInit(9, 18);call #Ultimate.allocInit(21, 19);call #Ultimate.allocInit(30, 20);call #Ultimate.allocInit(9, 21);call #Ultimate.allocInit(21, 22);call #Ultimate.allocInit(30, 23);call #Ultimate.allocInit(9, 24);call #Ultimate.allocInit(25, 25);call #Ultimate.allocInit(30, 26);call #Ultimate.allocInit(9, 27);call #Ultimate.allocInit(25, 28);~switchedOnBeforeTS~0 := 0;~pumpRunning~0 := 0;~systemActive~0 := 1;~waterLevel~0 := 1;~methaneLevelCritical~0 := 0;~cleanupTimeShifts~0 := 4;~head~0.base, ~head~0.offset := 0, 0; {503#true} is VALID [2022-02-20 18:11:41,325 INFO L290 TraceCheckUtils]: 1: Hoare triple {503#true} assume { :end_inline_ULTIMATE.init } true;assume { :begin_inline_main } true;havoc main_#res#1;havoc main_#t~ret26#1, main_~retValue_acc~4#1, main_~tmp~3#1;havoc main_~retValue_acc~4#1;havoc main_~tmp~3#1;assume { :begin_inline_select_helpers } true; {503#true} is VALID [2022-02-20 18:11:41,325 INFO L290 TraceCheckUtils]: 2: Hoare triple {503#true} assume { :end_inline_select_helpers } true;assume { :begin_inline_select_features } true; {503#true} is VALID [2022-02-20 18:11:41,325 INFO L290 TraceCheckUtils]: 3: Hoare triple {503#true} assume { :end_inline_select_features } true;assume { :begin_inline_valid_product } true;havoc valid_product_#res#1;havoc valid_product_~retValue_acc~9#1;havoc valid_product_~retValue_acc~9#1;valid_product_~retValue_acc~9#1 := 1;valid_product_#res#1 := valid_product_~retValue_acc~9#1; {503#true} is VALID [2022-02-20 18:11:41,326 INFO L290 TraceCheckUtils]: 4: Hoare triple {503#true} main_#t~ret26#1 := valid_product_#res#1;assume { :end_inline_valid_product } true;assume -2147483648 <= main_#t~ret26#1 && main_#t~ret26#1 <= 2147483647;main_~tmp~3#1 := main_#t~ret26#1;havoc main_#t~ret26#1; {503#true} is VALID [2022-02-20 18:11:41,330 INFO L290 TraceCheckUtils]: 5: Hoare triple {503#true} assume 0 != main_~tmp~3#1;assume { :begin_inline_setup } true; {503#true} is VALID [2022-02-20 18:11:41,331 INFO L290 TraceCheckUtils]: 6: Hoare triple {503#true} assume { :end_inline_setup } true;assume { :begin_inline_runTest } true;assume { :begin_inline___utac_acc__Specification5_spec__1 } true;~switchedOnBeforeTS~0 := 0; {503#true} is VALID [2022-02-20 18:11:41,332 INFO L290 TraceCheckUtils]: 7: Hoare triple {503#true} assume { :end_inline___utac_acc__Specification5_spec__1 } true;assume { :begin_inline_test } true;havoc test_#t~nondet22#1, test_#t~nondet23#1, test_#t~nondet24#1, test_#t~nondet25#1, test_~splverifierCounter~0#1, test_~tmp~2#1, test_~tmp___0~1#1, test_~tmp___1~0#1, test_~tmp___2~0#1;havoc test_~splverifierCounter~0#1;havoc test_~tmp~2#1;havoc test_~tmp___0~1#1;havoc test_~tmp___1~0#1;havoc test_~tmp___2~0#1;test_~splverifierCounter~0#1 := 0; {505#(= |ULTIMATE.start_test_~splverifierCounter~0#1| 0)} is VALID [2022-02-20 18:11:41,332 INFO L290 TraceCheckUtils]: 8: Hoare triple {505#(= |ULTIMATE.start_test_~splverifierCounter~0#1| 0)} assume !false; {505#(= |ULTIMATE.start_test_~splverifierCounter~0#1| 0)} is VALID [2022-02-20 18:11:41,333 INFO L290 TraceCheckUtils]: 9: Hoare triple {505#(= |ULTIMATE.start_test_~splverifierCounter~0#1| 0)} assume !(test_~splverifierCounter~0#1 < 4); {504#false} is VALID [2022-02-20 18:11:41,333 INFO L272 TraceCheckUtils]: 10: Hoare triple {504#false} call cleanup(); {504#false} is VALID [2022-02-20 18:11:41,333 INFO L290 TraceCheckUtils]: 11: Hoare triple {504#false} havoc ~i~0;havoc ~__cil_tmp2~0; {504#false} is VALID [2022-02-20 18:11:41,334 INFO L272 TraceCheckUtils]: 12: Hoare triple {504#false} call timeShift(); {504#false} is VALID [2022-02-20 18:11:41,334 INFO L290 TraceCheckUtils]: 13: Hoare triple {504#false} assume { :begin_inline___utac_acc__Specification5_spec__2 } true;havoc __utac_acc__Specification5_spec__2_#t~ret4#1; {504#false} is VALID [2022-02-20 18:11:41,334 INFO L272 TraceCheckUtils]: 14: Hoare triple {504#false} call __utac_acc__Specification5_spec__2_#t~ret4#1 := isPumpRunning(); {503#true} is VALID [2022-02-20 18:11:41,334 INFO L290 TraceCheckUtils]: 15: Hoare triple {503#true} havoc ~retValue_acc~1;~retValue_acc~1 := ~pumpRunning~0;#res := ~retValue_acc~1; {503#true} is VALID [2022-02-20 18:11:41,335 INFO L290 TraceCheckUtils]: 16: Hoare triple {503#true} assume true; {503#true} is VALID [2022-02-20 18:11:41,335 INFO L284 TraceCheckUtils]: 17: Hoare quadruple {503#true} {504#false} #194#return; {504#false} is VALID [2022-02-20 18:11:41,335 INFO L290 TraceCheckUtils]: 18: Hoare triple {504#false} assume -2147483648 <= __utac_acc__Specification5_spec__2_#t~ret4#1 && __utac_acc__Specification5_spec__2_#t~ret4#1 <= 2147483647;~switchedOnBeforeTS~0 := __utac_acc__Specification5_spec__2_#t~ret4#1;havoc __utac_acc__Specification5_spec__2_#t~ret4#1; {504#false} is VALID [2022-02-20 18:11:41,337 INFO L290 TraceCheckUtils]: 19: Hoare triple {504#false} assume { :end_inline___utac_acc__Specification5_spec__2 } true; {504#false} is VALID [2022-02-20 18:11:41,337 INFO L290 TraceCheckUtils]: 20: Hoare triple {504#false} assume !(0 != ~pumpRunning~0); {504#false} is VALID [2022-02-20 18:11:41,338 INFO L290 TraceCheckUtils]: 21: Hoare triple {504#false} assume !(0 != ~systemActive~0); {504#false} is VALID [2022-02-20 18:11:41,338 INFO L290 TraceCheckUtils]: 22: Hoare triple {504#false} assume { :begin_inline___utac_acc__Specification5_spec__3 } true;havoc __utac_acc__Specification5_spec__3_#t~ret5#1, __utac_acc__Specification5_spec__3_#t~ret6#1, __utac_acc__Specification5_spec__3_~tmp~0#1, __utac_acc__Specification5_spec__3_~tmp___0~0#1;havoc __utac_acc__Specification5_spec__3_~tmp~0#1;havoc __utac_acc__Specification5_spec__3_~tmp___0~0#1;assume { :begin_inline_getWaterLevel } true;havoc getWaterLevel_#res#1;havoc getWaterLevel_~retValue_acc~3#1;havoc getWaterLevel_~retValue_acc~3#1;getWaterLevel_~retValue_acc~3#1 := ~waterLevel~0;getWaterLevel_#res#1 := getWaterLevel_~retValue_acc~3#1; {504#false} is VALID [2022-02-20 18:11:41,338 INFO L290 TraceCheckUtils]: 23: Hoare triple {504#false} __utac_acc__Specification5_spec__3_#t~ret5#1 := getWaterLevel_#res#1;assume { :end_inline_getWaterLevel } true;assume -2147483648 <= __utac_acc__Specification5_spec__3_#t~ret5#1 && __utac_acc__Specification5_spec__3_#t~ret5#1 <= 2147483647;__utac_acc__Specification5_spec__3_~tmp~0#1 := __utac_acc__Specification5_spec__3_#t~ret5#1;havoc __utac_acc__Specification5_spec__3_#t~ret5#1; {504#false} is VALID [2022-02-20 18:11:41,338 INFO L290 TraceCheckUtils]: 24: Hoare triple {504#false} assume 2 != __utac_acc__Specification5_spec__3_~tmp~0#1; {504#false} is VALID [2022-02-20 18:11:41,339 INFO L272 TraceCheckUtils]: 25: Hoare triple {504#false} call __utac_acc__Specification5_spec__3_#t~ret6#1 := isPumpRunning(); {503#true} is VALID [2022-02-20 18:11:41,339 INFO L290 TraceCheckUtils]: 26: Hoare triple {503#true} havoc ~retValue_acc~1;~retValue_acc~1 := ~pumpRunning~0;#res := ~retValue_acc~1; {503#true} is VALID [2022-02-20 18:11:41,339 INFO L290 TraceCheckUtils]: 27: Hoare triple {503#true} assume true; {503#true} is VALID [2022-02-20 18:11:41,339 INFO L284 TraceCheckUtils]: 28: Hoare quadruple {503#true} {504#false} #196#return; {504#false} is VALID [2022-02-20 18:11:41,340 INFO L290 TraceCheckUtils]: 29: Hoare triple {504#false} assume -2147483648 <= __utac_acc__Specification5_spec__3_#t~ret6#1 && __utac_acc__Specification5_spec__3_#t~ret6#1 <= 2147483647;__utac_acc__Specification5_spec__3_~tmp___0~0#1 := __utac_acc__Specification5_spec__3_#t~ret6#1;havoc __utac_acc__Specification5_spec__3_#t~ret6#1; {504#false} is VALID [2022-02-20 18:11:41,340 INFO L290 TraceCheckUtils]: 30: Hoare triple {504#false} assume 0 != __utac_acc__Specification5_spec__3_~tmp___0~0#1; {504#false} is VALID [2022-02-20 18:11:41,340 INFO L290 TraceCheckUtils]: 31: Hoare triple {504#false} assume 0 == ~switchedOnBeforeTS~0;assume { :begin_inline___automaton_fail } true; {504#false} is VALID [2022-02-20 18:11:41,340 INFO L290 TraceCheckUtils]: 32: Hoare triple {504#false} assume !false; {504#false} is VALID [2022-02-20 18:11:41,341 INFO L134 CoverageAnalysis]: Checked inductivity of 3 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 3 trivial. 0 not checked. [2022-02-20 18:11:41,341 INFO L144 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2022-02-20 18:11:41,341 INFO L338 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [492255490] [2022-02-20 18:11:41,341 INFO L165 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [492255490] provided 1 perfect and 0 imperfect interpolant sequences [2022-02-20 18:11:41,342 INFO L191 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2022-02-20 18:11:41,342 INFO L204 FreeRefinementEngine]: Number of different interpolants: perfect sequences [3] imperfect sequences [] total 3 [2022-02-20 18:11:41,342 INFO L118 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [2050454854] [2022-02-20 18:11:41,342 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2022-02-20 18:11:41,344 INFO L78 Accepts]: Start accepts. Automaton has has 3 states, 3 states have (on average 8.333333333333334) internal successors, (25), 3 states have internal predecessors, (25), 1 states have call successors, (4), 2 states have call predecessors, (4), 1 states have return successors, (2), 1 states have call predecessors, (2), 1 states have call successors, (2) Word has length 33 [2022-02-20 18:11:41,344 INFO L84 Accepts]: Finished accepts. word is accepted. [2022-02-20 18:11:41,344 INFO L86 InductivityCheck]: Starting indutivity check of a Floyd-Hoare automaton with has 3 states, 3 states have (on average 8.333333333333334) internal successors, (25), 3 states have internal predecessors, (25), 1 states have call successors, (4), 2 states have call predecessors, (4), 1 states have return successors, (2), 1 states have call predecessors, (2), 1 states have call successors, (2) [2022-02-20 18:11:41,371 INFO L122 InductivityCheck]: Floyd-Hoare automaton has 31 edges. 31 inductive. 0 not inductive. 0 times theorem prover too weak to decide inductivity. [2022-02-20 18:11:41,372 INFO L546 AbstractCegarLoop]: INTERPOLANT automaton has 3 states [2022-02-20 18:11:41,372 INFO L108 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2022-02-20 18:11:41,373 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 3 interpolants. [2022-02-20 18:11:41,373 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=3, Invalid=3, Unknown=0, NotChecked=0, Total=6 [2022-02-20 18:11:41,373 INFO L87 Difference]: Start difference. First operand 64 states and 80 transitions. Second operand has 3 states, 3 states have (on average 8.333333333333334) internal successors, (25), 3 states have internal predecessors, (25), 1 states have call successors, (4), 2 states have call predecessors, (4), 1 states have return successors, (2), 1 states have call predecessors, (2), 1 states have call successors, (2) [2022-02-20 18:11:41,444 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-02-20 18:11:41,445 INFO L93 Difference]: Finished difference Result 88 states and 109 transitions. [2022-02-20 18:11:41,445 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 3 states. [2022-02-20 18:11:41,446 INFO L78 Accepts]: Start accepts. Automaton has has 3 states, 3 states have (on average 8.333333333333334) internal successors, (25), 3 states have internal predecessors, (25), 1 states have call successors, (4), 2 states have call predecessors, (4), 1 states have return successors, (2), 1 states have call predecessors, (2), 1 states have call successors, (2) Word has length 33 [2022-02-20 18:11:41,446 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2022-02-20 18:11:41,446 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 3 states, 3 states have (on average 8.333333333333334) internal successors, (25), 3 states have internal predecessors, (25), 1 states have call successors, (4), 2 states have call predecessors, (4), 1 states have return successors, (2), 1 states have call predecessors, (2), 1 states have call successors, (2) [2022-02-20 18:11:41,449 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 3 states to 3 states and 109 transitions. [2022-02-20 18:11:41,450 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 3 states, 3 states have (on average 8.333333333333334) internal successors, (25), 3 states have internal predecessors, (25), 1 states have call successors, (4), 2 states have call predecessors, (4), 1 states have return successors, (2), 1 states have call predecessors, (2), 1 states have call successors, (2) [2022-02-20 18:11:41,452 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 3 states to 3 states and 109 transitions. [2022-02-20 18:11:41,453 INFO L86 InductivityCheck]: Starting indutivity check of a Floyd-Hoare automaton with 3 states and 109 transitions. [2022-02-20 18:11:41,540 INFO L122 InductivityCheck]: Floyd-Hoare automaton has 109 edges. 109 inductive. 0 not inductive. 0 times theorem prover too weak to decide inductivity. [2022-02-20 18:11:41,544 INFO L225 Difference]: With dead ends: 88 [2022-02-20 18:11:41,544 INFO L226 Difference]: Without dead ends: 55 [2022-02-20 18:11:41,548 INFO L932 BasicCegarLoop]: 0 DeclaredPredicates, 7 GetRequests, 6 SyntacticMatches, 0 SemanticMatches, 1 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 0 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=3, Invalid=3, Unknown=0, NotChecked=0, Total=6 [2022-02-20 18:11:41,550 INFO L933 BasicCegarLoop]: 67 mSDtfsCounter, 18 mSDsluCounter, 45 mSDsCounter, 0 mSdLazyCounter, 1 mSolverCounterSat, 0 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.0s Time, 0 mProtectedPredicate, 0 mProtectedAction, 21 SdHoareTripleChecker+Valid, 112 SdHoareTripleChecker+Invalid, 1 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 0 IncrementalHoareTripleChecker+Valid, 1 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.0s IncrementalHoareTripleChecker+Time [2022-02-20 18:11:41,551 INFO L934 BasicCegarLoop]: SdHoareTripleChecker [21 Valid, 112 Invalid, 1 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [0 Valid, 1 Invalid, 0 Unknown, 0 Unchecked, 0.0s Time] [2022-02-20 18:11:41,553 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 55 states. [2022-02-20 18:11:41,563 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 55 to 55. [2022-02-20 18:11:41,563 INFO L214 AbstractMinimizeNwa]: Start testing correctness of minimizeSevpa [2022-02-20 18:11:41,564 INFO L82 GeneralOperation]: Start isEquivalent. First operand 55 states. Second operand has 55 states, 45 states have (on average 1.288888888888889) internal successors, (58), 48 states have internal predecessors, (58), 5 states have call successors, (5), 4 states have call predecessors, (5), 4 states have return successors, (5), 5 states have call predecessors, (5), 5 states have call successors, (5) [2022-02-20 18:11:41,565 INFO L74 IsIncluded]: Start isIncluded. First operand 55 states. Second operand has 55 states, 45 states have (on average 1.288888888888889) internal successors, (58), 48 states have internal predecessors, (58), 5 states have call successors, (5), 4 states have call predecessors, (5), 4 states have return successors, (5), 5 states have call predecessors, (5), 5 states have call successors, (5) [2022-02-20 18:11:41,565 INFO L87 Difference]: Start difference. First operand 55 states. Second operand has 55 states, 45 states have (on average 1.288888888888889) internal successors, (58), 48 states have internal predecessors, (58), 5 states have call successors, (5), 4 states have call predecessors, (5), 4 states have return successors, (5), 5 states have call predecessors, (5), 5 states have call successors, (5) [2022-02-20 18:11:41,570 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-02-20 18:11:41,573 INFO L93 Difference]: Finished difference Result 55 states and 68 transitions. [2022-02-20 18:11:41,573 INFO L276 IsEmpty]: Start isEmpty. Operand 55 states and 68 transitions. [2022-02-20 18:11:41,574 INFO L282 IsEmpty]: Finished isEmpty. No accepting run. [2022-02-20 18:11:41,575 INFO L83 IsIncluded]: Finished isIncluded. Language is included [2022-02-20 18:11:41,575 INFO L74 IsIncluded]: Start isIncluded. First operand has 55 states, 45 states have (on average 1.288888888888889) internal successors, (58), 48 states have internal predecessors, (58), 5 states have call successors, (5), 4 states have call predecessors, (5), 4 states have return successors, (5), 5 states have call predecessors, (5), 5 states have call successors, (5) Second operand 55 states. [2022-02-20 18:11:41,575 INFO L87 Difference]: Start difference. First operand has 55 states, 45 states have (on average 1.288888888888889) internal successors, (58), 48 states have internal predecessors, (58), 5 states have call successors, (5), 4 states have call predecessors, (5), 4 states have return successors, (5), 5 states have call predecessors, (5), 5 states have call successors, (5) Second operand 55 states. [2022-02-20 18:11:41,578 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-02-20 18:11:41,578 INFO L93 Difference]: Finished difference Result 55 states and 68 transitions. [2022-02-20 18:11:41,578 INFO L276 IsEmpty]: Start isEmpty. Operand 55 states and 68 transitions. [2022-02-20 18:11:41,580 INFO L282 IsEmpty]: Finished isEmpty. No accepting run. [2022-02-20 18:11:41,580 INFO L83 IsIncluded]: Finished isIncluded. Language is included [2022-02-20 18:11:41,581 INFO L88 GeneralOperation]: Finished isEquivalent. [2022-02-20 18:11:41,581 INFO L221 AbstractMinimizeNwa]: Finished testing correctness of minimizeSevpa [2022-02-20 18:11:41,581 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 55 states, 45 states have (on average 1.288888888888889) internal successors, (58), 48 states have internal predecessors, (58), 5 states have call successors, (5), 4 states have call predecessors, (5), 4 states have return successors, (5), 5 states have call predecessors, (5), 5 states have call successors, (5) [2022-02-20 18:11:41,584 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 55 states to 55 states and 68 transitions. [2022-02-20 18:11:41,584 INFO L78 Accepts]: Start accepts. Automaton has 55 states and 68 transitions. Word has length 33 [2022-02-20 18:11:41,585 INFO L84 Accepts]: Finished accepts. word is rejected. [2022-02-20 18:11:41,586 INFO L470 AbstractCegarLoop]: Abstraction has 55 states and 68 transitions. [2022-02-20 18:11:41,586 INFO L471 AbstractCegarLoop]: INTERPOLANT automaton has has 3 states, 3 states have (on average 8.333333333333334) internal successors, (25), 3 states have internal predecessors, (25), 1 states have call successors, (4), 2 states have call predecessors, (4), 1 states have return successors, (2), 1 states have call predecessors, (2), 1 states have call successors, (2) [2022-02-20 18:11:41,587 INFO L276 IsEmpty]: Start isEmpty. Operand 55 states and 68 transitions. [2022-02-20 18:11:41,590 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 39 [2022-02-20 18:11:41,590 INFO L506 BasicCegarLoop]: Found error trace [2022-02-20 18:11:41,590 INFO L514 BasicCegarLoop]: trace histogram [2, 2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-02-20 18:11:41,591 WARN L452 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable1 [2022-02-20 18:11:41,591 INFO L402 AbstractCegarLoop]: === Iteration 3 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2022-02-20 18:11:41,591 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2022-02-20 18:11:41,592 INFO L85 PathProgramCache]: Analyzing trace with hash 172632065, now seen corresponding path program 1 times [2022-02-20 18:11:41,592 INFO L126 FreeRefinementEngine]: Executing refinement strategy CAMEL [2022-02-20 18:11:41,592 INFO L338 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [787333304] [2022-02-20 18:11:41,592 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-02-20 18:11:41,593 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2022-02-20 18:11:41,647 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-02-20 18:11:41,717 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 19 [2022-02-20 18:11:41,720 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-02-20 18:11:41,724 INFO L290 TraceCheckUtils]: 0: Hoare triple {827#true} havoc ~retValue_acc~1;~retValue_acc~1 := ~pumpRunning~0;#res := ~retValue_acc~1; {827#true} is VALID [2022-02-20 18:11:41,725 INFO L290 TraceCheckUtils]: 1: Hoare triple {827#true} assume true; {827#true} is VALID [2022-02-20 18:11:41,726 INFO L284 TraceCheckUtils]: 2: Hoare quadruple {827#true} {832#(not (= 0 ~systemActive~0))} #194#return; {832#(not (= 0 ~systemActive~0))} is VALID [2022-02-20 18:11:41,726 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 30 [2022-02-20 18:11:41,728 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-02-20 18:11:41,730 INFO L290 TraceCheckUtils]: 0: Hoare triple {827#true} havoc ~retValue_acc~1;~retValue_acc~1 := ~pumpRunning~0;#res := ~retValue_acc~1; {827#true} is VALID [2022-02-20 18:11:41,731 INFO L290 TraceCheckUtils]: 1: Hoare triple {827#true} assume true; {827#true} is VALID [2022-02-20 18:11:41,731 INFO L284 TraceCheckUtils]: 2: Hoare quadruple {827#true} {828#false} #196#return; {828#false} is VALID [2022-02-20 18:11:41,743 INFO L290 TraceCheckUtils]: 0: Hoare triple {827#true} assume { :begin_inline_ULTIMATE.init } true;#NULL.base, #NULL.offset := 0, 0;assume 0 == #valid[0];assume 0 < #StackHeapBarrier;call #Ultimate.allocInit(2, 1);call write~init~int(48, 1, 0, 1);call write~init~int(0, 1, 1, 1);call #Ultimate.allocInit(31, 2);call #Ultimate.allocInit(12, 3);call #Ultimate.allocInit(13, 4);call #Ultimate.allocInit(3, 5);call write~init~int(79, 5, 0, 1);call write~init~int(110, 5, 1, 1);call write~init~int(0, 5, 2, 1);call #Ultimate.allocInit(4, 6);call write~init~int(79, 6, 0, 1);call write~init~int(102, 6, 1, 1);call write~init~int(102, 6, 2, 1);call write~init~int(0, 6, 3, 1);call #Ultimate.allocInit(7, 7);call write~init~int(44, 7, 0, 1);call write~init~int(80, 7, 1, 1);call write~init~int(117, 7, 2, 1);call write~init~int(109, 7, 3, 1);call write~init~int(112, 7, 4, 1);call write~init~int(58, 7, 5, 1);call write~init~int(0, 7, 6, 1);call #Ultimate.allocInit(3, 8);call write~init~int(79, 8, 0, 1);call write~init~int(110, 8, 1, 1);call write~init~int(0, 8, 2, 1);call #Ultimate.allocInit(4, 9);call write~init~int(79, 9, 0, 1);call write~init~int(102, 9, 1, 1);call write~init~int(102, 9, 2, 1);call write~init~int(0, 9, 3, 1);call #Ultimate.allocInit(3, 10);call write~init~int(41, 10, 0, 1);call write~init~int(32, 10, 1, 1);call write~init~int(0, 10, 2, 1);call #Ultimate.allocInit(2, 11);call write~init~int(10, 11, 0, 1);call write~init~int(0, 11, 1, 1);call #Ultimate.allocInit(13, 12);call #Ultimate.allocInit(7, 13);call write~init~int(44, 13, 0, 1);call write~init~int(77, 13, 1, 1);call write~init~int(101, 13, 2, 1);call write~init~int(116, 13, 3, 1);call write~init~int(104, 13, 4, 1);call write~init~int(58, 13, 5, 1);call write~init~int(0, 13, 6, 1);call #Ultimate.allocInit(5, 14);call write~init~int(67, 14, 0, 1);call write~init~int(82, 14, 1, 1);call write~init~int(73, 14, 2, 1);call write~init~int(84, 14, 3, 1);call write~init~int(0, 14, 4, 1);call #Ultimate.allocInit(3, 15);call write~init~int(79, 15, 0, 1);call write~init~int(75, 15, 1, 1);call write~init~int(0, 15, 2, 1);call #Ultimate.allocInit(2, 16);call write~init~int(41, 16, 0, 1);call write~init~int(0, 16, 1, 1);call #Ultimate.allocInit(30, 17);call #Ultimate.allocInit(9, 18);call #Ultimate.allocInit(21, 19);call #Ultimate.allocInit(30, 20);call #Ultimate.allocInit(9, 21);call #Ultimate.allocInit(21, 22);call #Ultimate.allocInit(30, 23);call #Ultimate.allocInit(9, 24);call #Ultimate.allocInit(25, 25);call #Ultimate.allocInit(30, 26);call #Ultimate.allocInit(9, 27);call #Ultimate.allocInit(25, 28);~switchedOnBeforeTS~0 := 0;~pumpRunning~0 := 0;~systemActive~0 := 1;~waterLevel~0 := 1;~methaneLevelCritical~0 := 0;~cleanupTimeShifts~0 := 4;~head~0.base, ~head~0.offset := 0, 0; {829#(= 1 ~systemActive~0)} is VALID [2022-02-20 18:11:41,744 INFO L290 TraceCheckUtils]: 1: Hoare triple {829#(= 1 ~systemActive~0)} assume { :end_inline_ULTIMATE.init } true;assume { :begin_inline_main } true;havoc main_#res#1;havoc main_#t~ret26#1, main_~retValue_acc~4#1, main_~tmp~3#1;havoc main_~retValue_acc~4#1;havoc main_~tmp~3#1;assume { :begin_inline_select_helpers } true; {829#(= 1 ~systemActive~0)} is VALID [2022-02-20 18:11:41,745 INFO L290 TraceCheckUtils]: 2: Hoare triple {829#(= 1 ~systemActive~0)} assume { :end_inline_select_helpers } true;assume { :begin_inline_select_features } true; {829#(= 1 ~systemActive~0)} is VALID [2022-02-20 18:11:41,746 INFO L290 TraceCheckUtils]: 3: Hoare triple {829#(= 1 ~systemActive~0)} assume { :end_inline_select_features } true;assume { :begin_inline_valid_product } true;havoc valid_product_#res#1;havoc valid_product_~retValue_acc~9#1;havoc valid_product_~retValue_acc~9#1;valid_product_~retValue_acc~9#1 := 1;valid_product_#res#1 := valid_product_~retValue_acc~9#1; {830#(= |ULTIMATE.start_valid_product_#res#1| ~systemActive~0)} is VALID [2022-02-20 18:11:41,746 INFO L290 TraceCheckUtils]: 4: Hoare triple {830#(= |ULTIMATE.start_valid_product_#res#1| ~systemActive~0)} main_#t~ret26#1 := valid_product_#res#1;assume { :end_inline_valid_product } true;assume -2147483648 <= main_#t~ret26#1 && main_#t~ret26#1 <= 2147483647;main_~tmp~3#1 := main_#t~ret26#1;havoc main_#t~ret26#1; {831#(= |ULTIMATE.start_main_~tmp~3#1| ~systemActive~0)} is VALID [2022-02-20 18:11:41,747 INFO L290 TraceCheckUtils]: 5: Hoare triple {831#(= |ULTIMATE.start_main_~tmp~3#1| ~systemActive~0)} assume 0 != main_~tmp~3#1;assume { :begin_inline_setup } true; {832#(not (= 0 ~systemActive~0))} is VALID [2022-02-20 18:11:41,747 INFO L290 TraceCheckUtils]: 6: Hoare triple {832#(not (= 0 ~systemActive~0))} assume { :end_inline_setup } true;assume { :begin_inline_runTest } true;assume { :begin_inline___utac_acc__Specification5_spec__1 } true;~switchedOnBeforeTS~0 := 0; {832#(not (= 0 ~systemActive~0))} is VALID [2022-02-20 18:11:41,748 INFO L290 TraceCheckUtils]: 7: Hoare triple {832#(not (= 0 ~systemActive~0))} assume { :end_inline___utac_acc__Specification5_spec__1 } true;assume { :begin_inline_test } true;havoc test_#t~nondet22#1, test_#t~nondet23#1, test_#t~nondet24#1, test_#t~nondet25#1, test_~splverifierCounter~0#1, test_~tmp~2#1, test_~tmp___0~1#1, test_~tmp___1~0#1, test_~tmp___2~0#1;havoc test_~splverifierCounter~0#1;havoc test_~tmp~2#1;havoc test_~tmp___0~1#1;havoc test_~tmp___1~0#1;havoc test_~tmp___2~0#1;test_~splverifierCounter~0#1 := 0; {832#(not (= 0 ~systemActive~0))} is VALID [2022-02-20 18:11:41,748 INFO L290 TraceCheckUtils]: 8: Hoare triple {832#(not (= 0 ~systemActive~0))} assume !false; {832#(not (= 0 ~systemActive~0))} is VALID [2022-02-20 18:11:41,749 INFO L290 TraceCheckUtils]: 9: Hoare triple {832#(not (= 0 ~systemActive~0))} assume test_~splverifierCounter~0#1 < 4; {832#(not (= 0 ~systemActive~0))} is VALID [2022-02-20 18:11:41,749 INFO L290 TraceCheckUtils]: 10: Hoare triple {832#(not (= 0 ~systemActive~0))} assume -2147483648 <= test_#t~nondet22#1 && test_#t~nondet22#1 <= 2147483647;test_~tmp~2#1 := test_#t~nondet22#1;havoc test_#t~nondet22#1; {832#(not (= 0 ~systemActive~0))} is VALID [2022-02-20 18:11:41,750 INFO L290 TraceCheckUtils]: 11: Hoare triple {832#(not (= 0 ~systemActive~0))} assume !(0 != test_~tmp~2#1); {832#(not (= 0 ~systemActive~0))} is VALID [2022-02-20 18:11:41,750 INFO L290 TraceCheckUtils]: 12: Hoare triple {832#(not (= 0 ~systemActive~0))} assume -2147483648 <= test_#t~nondet23#1 && test_#t~nondet23#1 <= 2147483647;test_~tmp___0~1#1 := test_#t~nondet23#1;havoc test_#t~nondet23#1; {832#(not (= 0 ~systemActive~0))} is VALID [2022-02-20 18:11:41,751 INFO L290 TraceCheckUtils]: 13: Hoare triple {832#(not (= 0 ~systemActive~0))} assume !(0 != test_~tmp___0~1#1); {832#(not (= 0 ~systemActive~0))} is VALID [2022-02-20 18:11:41,751 INFO L290 TraceCheckUtils]: 14: Hoare triple {832#(not (= 0 ~systemActive~0))} assume -2147483648 <= test_#t~nondet24#1 && test_#t~nondet24#1 <= 2147483647;test_~tmp___2~0#1 := test_#t~nondet24#1;havoc test_#t~nondet24#1; {832#(not (= 0 ~systemActive~0))} is VALID [2022-02-20 18:11:41,756 INFO L290 TraceCheckUtils]: 15: Hoare triple {832#(not (= 0 ~systemActive~0))} assume !(0 != test_~tmp___2~0#1);assume -2147483648 <= test_#t~nondet25#1 && test_#t~nondet25#1 <= 2147483647;test_~tmp___1~0#1 := test_#t~nondet25#1;havoc test_#t~nondet25#1; {832#(not (= 0 ~systemActive~0))} is VALID [2022-02-20 18:11:41,758 INFO L290 TraceCheckUtils]: 16: Hoare triple {832#(not (= 0 ~systemActive~0))} assume !(0 != test_~tmp___1~0#1); {832#(not (= 0 ~systemActive~0))} is VALID [2022-02-20 18:11:41,758 INFO L272 TraceCheckUtils]: 17: Hoare triple {832#(not (= 0 ~systemActive~0))} call timeShift(); {832#(not (= 0 ~systemActive~0))} is VALID [2022-02-20 18:11:41,759 INFO L290 TraceCheckUtils]: 18: Hoare triple {832#(not (= 0 ~systemActive~0))} assume { :begin_inline___utac_acc__Specification5_spec__2 } true;havoc __utac_acc__Specification5_spec__2_#t~ret4#1; {832#(not (= 0 ~systemActive~0))} is VALID [2022-02-20 18:11:41,761 INFO L272 TraceCheckUtils]: 19: Hoare triple {832#(not (= 0 ~systemActive~0))} call __utac_acc__Specification5_spec__2_#t~ret4#1 := isPumpRunning(); {827#true} is VALID [2022-02-20 18:11:41,761 INFO L290 TraceCheckUtils]: 20: Hoare triple {827#true} havoc ~retValue_acc~1;~retValue_acc~1 := ~pumpRunning~0;#res := ~retValue_acc~1; {827#true} is VALID [2022-02-20 18:11:41,761 INFO L290 TraceCheckUtils]: 21: Hoare triple {827#true} assume true; {827#true} is VALID [2022-02-20 18:11:41,762 INFO L284 TraceCheckUtils]: 22: Hoare quadruple {827#true} {832#(not (= 0 ~systemActive~0))} #194#return; {832#(not (= 0 ~systemActive~0))} is VALID [2022-02-20 18:11:41,763 INFO L290 TraceCheckUtils]: 23: Hoare triple {832#(not (= 0 ~systemActive~0))} assume -2147483648 <= __utac_acc__Specification5_spec__2_#t~ret4#1 && __utac_acc__Specification5_spec__2_#t~ret4#1 <= 2147483647;~switchedOnBeforeTS~0 := __utac_acc__Specification5_spec__2_#t~ret4#1;havoc __utac_acc__Specification5_spec__2_#t~ret4#1; {832#(not (= 0 ~systemActive~0))} is VALID [2022-02-20 18:11:41,764 INFO L290 TraceCheckUtils]: 24: Hoare triple {832#(not (= 0 ~systemActive~0))} assume { :end_inline___utac_acc__Specification5_spec__2 } true; {832#(not (= 0 ~systemActive~0))} is VALID [2022-02-20 18:11:41,765 INFO L290 TraceCheckUtils]: 25: Hoare triple {832#(not (= 0 ~systemActive~0))} assume !(0 != ~pumpRunning~0); {832#(not (= 0 ~systemActive~0))} is VALID [2022-02-20 18:11:41,766 INFO L290 TraceCheckUtils]: 26: Hoare triple {832#(not (= 0 ~systemActive~0))} assume !(0 != ~systemActive~0); {828#false} is VALID [2022-02-20 18:11:41,766 INFO L290 TraceCheckUtils]: 27: Hoare triple {828#false} assume { :begin_inline___utac_acc__Specification5_spec__3 } true;havoc __utac_acc__Specification5_spec__3_#t~ret5#1, __utac_acc__Specification5_spec__3_#t~ret6#1, __utac_acc__Specification5_spec__3_~tmp~0#1, __utac_acc__Specification5_spec__3_~tmp___0~0#1;havoc __utac_acc__Specification5_spec__3_~tmp~0#1;havoc __utac_acc__Specification5_spec__3_~tmp___0~0#1;assume { :begin_inline_getWaterLevel } true;havoc getWaterLevel_#res#1;havoc getWaterLevel_~retValue_acc~3#1;havoc getWaterLevel_~retValue_acc~3#1;getWaterLevel_~retValue_acc~3#1 := ~waterLevel~0;getWaterLevel_#res#1 := getWaterLevel_~retValue_acc~3#1; {828#false} is VALID [2022-02-20 18:11:41,768 INFO L290 TraceCheckUtils]: 28: Hoare triple {828#false} __utac_acc__Specification5_spec__3_#t~ret5#1 := getWaterLevel_#res#1;assume { :end_inline_getWaterLevel } true;assume -2147483648 <= __utac_acc__Specification5_spec__3_#t~ret5#1 && __utac_acc__Specification5_spec__3_#t~ret5#1 <= 2147483647;__utac_acc__Specification5_spec__3_~tmp~0#1 := __utac_acc__Specification5_spec__3_#t~ret5#1;havoc __utac_acc__Specification5_spec__3_#t~ret5#1; {828#false} is VALID [2022-02-20 18:11:41,768 INFO L290 TraceCheckUtils]: 29: Hoare triple {828#false} assume 2 != __utac_acc__Specification5_spec__3_~tmp~0#1; {828#false} is VALID [2022-02-20 18:11:41,776 INFO L272 TraceCheckUtils]: 30: Hoare triple {828#false} call __utac_acc__Specification5_spec__3_#t~ret6#1 := isPumpRunning(); {827#true} is VALID [2022-02-20 18:11:41,777 INFO L290 TraceCheckUtils]: 31: Hoare triple {827#true} havoc ~retValue_acc~1;~retValue_acc~1 := ~pumpRunning~0;#res := ~retValue_acc~1; {827#true} is VALID [2022-02-20 18:11:41,777 INFO L290 TraceCheckUtils]: 32: Hoare triple {827#true} assume true; {827#true} is VALID [2022-02-20 18:11:41,777 INFO L284 TraceCheckUtils]: 33: Hoare quadruple {827#true} {828#false} #196#return; {828#false} is VALID [2022-02-20 18:11:41,777 INFO L290 TraceCheckUtils]: 34: Hoare triple {828#false} assume -2147483648 <= __utac_acc__Specification5_spec__3_#t~ret6#1 && __utac_acc__Specification5_spec__3_#t~ret6#1 <= 2147483647;__utac_acc__Specification5_spec__3_~tmp___0~0#1 := __utac_acc__Specification5_spec__3_#t~ret6#1;havoc __utac_acc__Specification5_spec__3_#t~ret6#1; {828#false} is VALID [2022-02-20 18:11:41,777 INFO L290 TraceCheckUtils]: 35: Hoare triple {828#false} assume 0 != __utac_acc__Specification5_spec__3_~tmp___0~0#1; {828#false} is VALID [2022-02-20 18:11:41,778 INFO L290 TraceCheckUtils]: 36: Hoare triple {828#false} assume 0 == ~switchedOnBeforeTS~0;assume { :begin_inline___automaton_fail } true; {828#false} is VALID [2022-02-20 18:11:41,778 INFO L290 TraceCheckUtils]: 37: Hoare triple {828#false} assume !false; {828#false} is VALID [2022-02-20 18:11:41,778 INFO L134 CoverageAnalysis]: Checked inductivity of 3 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 3 trivial. 0 not checked. [2022-02-20 18:11:41,778 INFO L144 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2022-02-20 18:11:41,781 INFO L338 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [787333304] [2022-02-20 18:11:41,781 INFO L165 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [787333304] provided 1 perfect and 0 imperfect interpolant sequences [2022-02-20 18:11:41,781 INFO L191 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2022-02-20 18:11:41,782 INFO L204 FreeRefinementEngine]: Number of different interpolants: perfect sequences [6] imperfect sequences [] total 6 [2022-02-20 18:11:41,782 INFO L118 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [1894333011] [2022-02-20 18:11:41,782 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2022-02-20 18:11:41,783 INFO L78 Accepts]: Start accepts. Automaton has has 6 states, 6 states have (on average 5.166666666666667) internal successors, (31), 6 states have internal predecessors, (31), 2 states have call successors, (3), 2 states have call predecessors, (3), 1 states have return successors, (2), 2 states have call predecessors, (2), 2 states have call successors, (2) Word has length 38 [2022-02-20 18:11:41,783 INFO L84 Accepts]: Finished accepts. word is accepted. [2022-02-20 18:11:41,783 INFO L86 InductivityCheck]: Starting indutivity check of a Floyd-Hoare automaton with has 6 states, 6 states have (on average 5.166666666666667) internal successors, (31), 6 states have internal predecessors, (31), 2 states have call successors, (3), 2 states have call predecessors, (3), 1 states have return successors, (2), 2 states have call predecessors, (2), 2 states have call successors, (2) [2022-02-20 18:11:41,823 INFO L122 InductivityCheck]: Floyd-Hoare automaton has 36 edges. 36 inductive. 0 not inductive. 0 times theorem prover too weak to decide inductivity. [2022-02-20 18:11:41,824 INFO L546 AbstractCegarLoop]: INTERPOLANT automaton has 6 states [2022-02-20 18:11:41,824 INFO L108 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2022-02-20 18:11:41,824 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 6 interpolants. [2022-02-20 18:11:41,825 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=10, Invalid=20, Unknown=0, NotChecked=0, Total=30 [2022-02-20 18:11:41,825 INFO L87 Difference]: Start difference. First operand 55 states and 68 transitions. Second operand has 6 states, 6 states have (on average 5.166666666666667) internal successors, (31), 6 states have internal predecessors, (31), 2 states have call successors, (3), 2 states have call predecessors, (3), 1 states have return successors, (2), 2 states have call predecessors, (2), 2 states have call successors, (2) [2022-02-20 18:11:42,286 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-02-20 18:11:42,286 INFO L93 Difference]: Finished difference Result 207 states and 271 transitions. [2022-02-20 18:11:42,287 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 6 states. [2022-02-20 18:11:42,287 INFO L78 Accepts]: Start accepts. Automaton has has 6 states, 6 states have (on average 5.166666666666667) internal successors, (31), 6 states have internal predecessors, (31), 2 states have call successors, (3), 2 states have call predecessors, (3), 1 states have return successors, (2), 2 states have call predecessors, (2), 2 states have call successors, (2) Word has length 38 [2022-02-20 18:11:42,287 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2022-02-20 18:11:42,288 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 6 states, 6 states have (on average 5.166666666666667) internal successors, (31), 6 states have internal predecessors, (31), 2 states have call successors, (3), 2 states have call predecessors, (3), 1 states have return successors, (2), 2 states have call predecessors, (2), 2 states have call successors, (2) [2022-02-20 18:11:42,294 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 6 states to 6 states and 271 transitions. [2022-02-20 18:11:42,294 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 6 states, 6 states have (on average 5.166666666666667) internal successors, (31), 6 states have internal predecessors, (31), 2 states have call successors, (3), 2 states have call predecessors, (3), 1 states have return successors, (2), 2 states have call predecessors, (2), 2 states have call successors, (2) [2022-02-20 18:11:42,299 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 6 states to 6 states and 271 transitions. [2022-02-20 18:11:42,300 INFO L86 InductivityCheck]: Starting indutivity check of a Floyd-Hoare automaton with 6 states and 271 transitions. [2022-02-20 18:11:42,508 INFO L122 InductivityCheck]: Floyd-Hoare automaton has 271 edges. 271 inductive. 0 not inductive. 0 times theorem prover too weak to decide inductivity. [2022-02-20 18:11:42,513 INFO L225 Difference]: With dead ends: 207 [2022-02-20 18:11:42,513 INFO L226 Difference]: Without dead ends: 160 [2022-02-20 18:11:42,514 INFO L932 BasicCegarLoop]: 0 DeclaredPredicates, 11 GetRequests, 5 SyntacticMatches, 0 SemanticMatches, 6 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 0 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=22, Invalid=34, Unknown=0, NotChecked=0, Total=56 [2022-02-20 18:11:42,515 INFO L933 BasicCegarLoop]: 82 mSDtfsCounter, 191 mSDsluCounter, 276 mSDsCounter, 0 mSdLazyCounter, 68 mSolverCounterSat, 28 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.1s Time, 0 mProtectedPredicate, 0 mProtectedAction, 191 SdHoareTripleChecker+Valid, 358 SdHoareTripleChecker+Invalid, 96 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 28 IncrementalHoareTripleChecker+Valid, 68 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.1s IncrementalHoareTripleChecker+Time [2022-02-20 18:11:42,516 INFO L934 BasicCegarLoop]: SdHoareTripleChecker [191 Valid, 358 Invalid, 96 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [28 Valid, 68 Invalid, 0 Unknown, 0 Unchecked, 0.1s Time] [2022-02-20 18:11:42,517 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 160 states. [2022-02-20 18:11:42,529 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 160 to 134. [2022-02-20 18:11:42,530 INFO L214 AbstractMinimizeNwa]: Start testing correctness of minimizeSevpa [2022-02-20 18:11:42,530 INFO L82 GeneralOperation]: Start isEquivalent. First operand 160 states. Second operand has 134 states, 106 states have (on average 1.330188679245283) internal successors, (141), 113 states have internal predecessors, (141), 15 states have call successors, (15), 12 states have call predecessors, (15), 12 states have return successors, (16), 15 states have call predecessors, (16), 15 states have call successors, (16) [2022-02-20 18:11:42,531 INFO L74 IsIncluded]: Start isIncluded. First operand 160 states. Second operand has 134 states, 106 states have (on average 1.330188679245283) internal successors, (141), 113 states have internal predecessors, (141), 15 states have call successors, (15), 12 states have call predecessors, (15), 12 states have return successors, (16), 15 states have call predecessors, (16), 15 states have call successors, (16) [2022-02-20 18:11:42,532 INFO L87 Difference]: Start difference. First operand 160 states. Second operand has 134 states, 106 states have (on average 1.330188679245283) internal successors, (141), 113 states have internal predecessors, (141), 15 states have call successors, (15), 12 states have call predecessors, (15), 12 states have return successors, (16), 15 states have call predecessors, (16), 15 states have call successors, (16) [2022-02-20 18:11:42,538 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-02-20 18:11:42,538 INFO L93 Difference]: Finished difference Result 160 states and 206 transitions. [2022-02-20 18:11:42,539 INFO L276 IsEmpty]: Start isEmpty. Operand 160 states and 206 transitions. [2022-02-20 18:11:42,539 INFO L282 IsEmpty]: Finished isEmpty. No accepting run. [2022-02-20 18:11:42,539 INFO L83 IsIncluded]: Finished isIncluded. Language is included [2022-02-20 18:11:42,540 INFO L74 IsIncluded]: Start isIncluded. First operand has 134 states, 106 states have (on average 1.330188679245283) internal successors, (141), 113 states have internal predecessors, (141), 15 states have call successors, (15), 12 states have call predecessors, (15), 12 states have return successors, (16), 15 states have call predecessors, (16), 15 states have call successors, (16) Second operand 160 states. [2022-02-20 18:11:42,541 INFO L87 Difference]: Start difference. First operand has 134 states, 106 states have (on average 1.330188679245283) internal successors, (141), 113 states have internal predecessors, (141), 15 states have call successors, (15), 12 states have call predecessors, (15), 12 states have return successors, (16), 15 states have call predecessors, (16), 15 states have call successors, (16) Second operand 160 states. [2022-02-20 18:11:42,547 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-02-20 18:11:42,548 INFO L93 Difference]: Finished difference Result 160 states and 206 transitions. [2022-02-20 18:11:42,548 INFO L276 IsEmpty]: Start isEmpty. Operand 160 states and 206 transitions. [2022-02-20 18:11:42,548 INFO L282 IsEmpty]: Finished isEmpty. No accepting run. [2022-02-20 18:11:42,548 INFO L83 IsIncluded]: Finished isIncluded. Language is included [2022-02-20 18:11:42,549 INFO L88 GeneralOperation]: Finished isEquivalent. [2022-02-20 18:11:42,549 INFO L221 AbstractMinimizeNwa]: Finished testing correctness of minimizeSevpa [2022-02-20 18:11:42,550 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 134 states, 106 states have (on average 1.330188679245283) internal successors, (141), 113 states have internal predecessors, (141), 15 states have call successors, (15), 12 states have call predecessors, (15), 12 states have return successors, (16), 15 states have call predecessors, (16), 15 states have call successors, (16) [2022-02-20 18:11:42,554 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 134 states to 134 states and 172 transitions. [2022-02-20 18:11:42,555 INFO L78 Accepts]: Start accepts. Automaton has 134 states and 172 transitions. Word has length 38 [2022-02-20 18:11:42,555 INFO L84 Accepts]: Finished accepts. word is rejected. [2022-02-20 18:11:42,555 INFO L470 AbstractCegarLoop]: Abstraction has 134 states and 172 transitions. [2022-02-20 18:11:42,556 INFO L471 AbstractCegarLoop]: INTERPOLANT automaton has has 6 states, 6 states have (on average 5.166666666666667) internal successors, (31), 6 states have internal predecessors, (31), 2 states have call successors, (3), 2 states have call predecessors, (3), 1 states have return successors, (2), 2 states have call predecessors, (2), 2 states have call successors, (2) [2022-02-20 18:11:42,556 INFO L276 IsEmpty]: Start isEmpty. Operand 134 states and 172 transitions. [2022-02-20 18:11:42,557 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 40 [2022-02-20 18:11:42,557 INFO L506 BasicCegarLoop]: Found error trace [2022-02-20 18:11:42,557 INFO L514 BasicCegarLoop]: trace histogram [2, 2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-02-20 18:11:42,557 WARN L452 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable2 [2022-02-20 18:11:42,557 INFO L402 AbstractCegarLoop]: === Iteration 4 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2022-02-20 18:11:42,558 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2022-02-20 18:11:42,558 INFO L85 PathProgramCache]: Analyzing trace with hash 408348587, now seen corresponding path program 1 times [2022-02-20 18:11:42,558 INFO L126 FreeRefinementEngine]: Executing refinement strategy CAMEL [2022-02-20 18:11:42,558 INFO L338 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [1405315280] [2022-02-20 18:11:42,559 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-02-20 18:11:42,559 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2022-02-20 18:11:42,590 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-02-20 18:11:42,625 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 19 [2022-02-20 18:11:42,627 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-02-20 18:11:42,630 INFO L290 TraceCheckUtils]: 0: Hoare triple {1636#true} havoc ~retValue_acc~1;~retValue_acc~1 := ~pumpRunning~0;#res := ~retValue_acc~1; {1636#true} is VALID [2022-02-20 18:11:42,630 INFO L290 TraceCheckUtils]: 1: Hoare triple {1636#true} assume true; {1636#true} is VALID [2022-02-20 18:11:42,631 INFO L284 TraceCheckUtils]: 2: Hoare quadruple {1636#true} {1638#(= ~pumpRunning~0 0)} #194#return; {1638#(= ~pumpRunning~0 0)} is VALID [2022-02-20 18:11:42,631 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 31 [2022-02-20 18:11:42,633 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-02-20 18:11:42,642 INFO L290 TraceCheckUtils]: 0: Hoare triple {1636#true} havoc ~retValue_acc~1;~retValue_acc~1 := ~pumpRunning~0;#res := ~retValue_acc~1; {1647#(= ~pumpRunning~0 |isPumpRunning_#res|)} is VALID [2022-02-20 18:11:42,643 INFO L290 TraceCheckUtils]: 1: Hoare triple {1647#(= ~pumpRunning~0 |isPumpRunning_#res|)} assume true; {1647#(= ~pumpRunning~0 |isPumpRunning_#res|)} is VALID [2022-02-20 18:11:42,643 INFO L284 TraceCheckUtils]: 2: Hoare quadruple {1647#(= ~pumpRunning~0 |isPumpRunning_#res|)} {1638#(= ~pumpRunning~0 0)} #196#return; {1645#(= |timeShift___utac_acc__Specification5_spec__3_#t~ret6#1| 0)} is VALID [2022-02-20 18:11:42,644 INFO L290 TraceCheckUtils]: 0: Hoare triple {1636#true} assume { :begin_inline_ULTIMATE.init } true;#NULL.base, #NULL.offset := 0, 0;assume 0 == #valid[0];assume 0 < #StackHeapBarrier;call #Ultimate.allocInit(2, 1);call write~init~int(48, 1, 0, 1);call write~init~int(0, 1, 1, 1);call #Ultimate.allocInit(31, 2);call #Ultimate.allocInit(12, 3);call #Ultimate.allocInit(13, 4);call #Ultimate.allocInit(3, 5);call write~init~int(79, 5, 0, 1);call write~init~int(110, 5, 1, 1);call write~init~int(0, 5, 2, 1);call #Ultimate.allocInit(4, 6);call write~init~int(79, 6, 0, 1);call write~init~int(102, 6, 1, 1);call write~init~int(102, 6, 2, 1);call write~init~int(0, 6, 3, 1);call #Ultimate.allocInit(7, 7);call write~init~int(44, 7, 0, 1);call write~init~int(80, 7, 1, 1);call write~init~int(117, 7, 2, 1);call write~init~int(109, 7, 3, 1);call write~init~int(112, 7, 4, 1);call write~init~int(58, 7, 5, 1);call write~init~int(0, 7, 6, 1);call #Ultimate.allocInit(3, 8);call write~init~int(79, 8, 0, 1);call write~init~int(110, 8, 1, 1);call write~init~int(0, 8, 2, 1);call #Ultimate.allocInit(4, 9);call write~init~int(79, 9, 0, 1);call write~init~int(102, 9, 1, 1);call write~init~int(102, 9, 2, 1);call write~init~int(0, 9, 3, 1);call #Ultimate.allocInit(3, 10);call write~init~int(41, 10, 0, 1);call write~init~int(32, 10, 1, 1);call write~init~int(0, 10, 2, 1);call #Ultimate.allocInit(2, 11);call write~init~int(10, 11, 0, 1);call write~init~int(0, 11, 1, 1);call #Ultimate.allocInit(13, 12);call #Ultimate.allocInit(7, 13);call write~init~int(44, 13, 0, 1);call write~init~int(77, 13, 1, 1);call write~init~int(101, 13, 2, 1);call write~init~int(116, 13, 3, 1);call write~init~int(104, 13, 4, 1);call write~init~int(58, 13, 5, 1);call write~init~int(0, 13, 6, 1);call #Ultimate.allocInit(5, 14);call write~init~int(67, 14, 0, 1);call write~init~int(82, 14, 1, 1);call write~init~int(73, 14, 2, 1);call write~init~int(84, 14, 3, 1);call write~init~int(0, 14, 4, 1);call #Ultimate.allocInit(3, 15);call write~init~int(79, 15, 0, 1);call write~init~int(75, 15, 1, 1);call write~init~int(0, 15, 2, 1);call #Ultimate.allocInit(2, 16);call write~init~int(41, 16, 0, 1);call write~init~int(0, 16, 1, 1);call #Ultimate.allocInit(30, 17);call #Ultimate.allocInit(9, 18);call #Ultimate.allocInit(21, 19);call #Ultimate.allocInit(30, 20);call #Ultimate.allocInit(9, 21);call #Ultimate.allocInit(21, 22);call #Ultimate.allocInit(30, 23);call #Ultimate.allocInit(9, 24);call #Ultimate.allocInit(25, 25);call #Ultimate.allocInit(30, 26);call #Ultimate.allocInit(9, 27);call #Ultimate.allocInit(25, 28);~switchedOnBeforeTS~0 := 0;~pumpRunning~0 := 0;~systemActive~0 := 1;~waterLevel~0 := 1;~methaneLevelCritical~0 := 0;~cleanupTimeShifts~0 := 4;~head~0.base, ~head~0.offset := 0, 0; {1638#(= ~pumpRunning~0 0)} is VALID [2022-02-20 18:11:42,644 INFO L290 TraceCheckUtils]: 1: Hoare triple {1638#(= ~pumpRunning~0 0)} assume { :end_inline_ULTIMATE.init } true;assume { :begin_inline_main } true;havoc main_#res#1;havoc main_#t~ret26#1, main_~retValue_acc~4#1, main_~tmp~3#1;havoc main_~retValue_acc~4#1;havoc main_~tmp~3#1;assume { :begin_inline_select_helpers } true; {1638#(= ~pumpRunning~0 0)} is VALID [2022-02-20 18:11:42,645 INFO L290 TraceCheckUtils]: 2: Hoare triple {1638#(= ~pumpRunning~0 0)} assume { :end_inline_select_helpers } true;assume { :begin_inline_select_features } true; {1638#(= ~pumpRunning~0 0)} is VALID [2022-02-20 18:11:42,645 INFO L290 TraceCheckUtils]: 3: Hoare triple {1638#(= ~pumpRunning~0 0)} assume { :end_inline_select_features } true;assume { :begin_inline_valid_product } true;havoc valid_product_#res#1;havoc valid_product_~retValue_acc~9#1;havoc valid_product_~retValue_acc~9#1;valid_product_~retValue_acc~9#1 := 1;valid_product_#res#1 := valid_product_~retValue_acc~9#1; {1638#(= ~pumpRunning~0 0)} is VALID [2022-02-20 18:11:42,646 INFO L290 TraceCheckUtils]: 4: Hoare triple {1638#(= ~pumpRunning~0 0)} main_#t~ret26#1 := valid_product_#res#1;assume { :end_inline_valid_product } true;assume -2147483648 <= main_#t~ret26#1 && main_#t~ret26#1 <= 2147483647;main_~tmp~3#1 := main_#t~ret26#1;havoc main_#t~ret26#1; {1638#(= ~pumpRunning~0 0)} is VALID [2022-02-20 18:11:42,646 INFO L290 TraceCheckUtils]: 5: Hoare triple {1638#(= ~pumpRunning~0 0)} assume 0 != main_~tmp~3#1;assume { :begin_inline_setup } true; {1638#(= ~pumpRunning~0 0)} is VALID [2022-02-20 18:11:42,646 INFO L290 TraceCheckUtils]: 6: Hoare triple {1638#(= ~pumpRunning~0 0)} assume { :end_inline_setup } true;assume { :begin_inline_runTest } true;assume { :begin_inline___utac_acc__Specification5_spec__1 } true;~switchedOnBeforeTS~0 := 0; {1638#(= ~pumpRunning~0 0)} is VALID [2022-02-20 18:11:42,647 INFO L290 TraceCheckUtils]: 7: Hoare triple {1638#(= ~pumpRunning~0 0)} assume { :end_inline___utac_acc__Specification5_spec__1 } true;assume { :begin_inline_test } true;havoc test_#t~nondet22#1, test_#t~nondet23#1, test_#t~nondet24#1, test_#t~nondet25#1, test_~splverifierCounter~0#1, test_~tmp~2#1, test_~tmp___0~1#1, test_~tmp___1~0#1, test_~tmp___2~0#1;havoc test_~splverifierCounter~0#1;havoc test_~tmp~2#1;havoc test_~tmp___0~1#1;havoc test_~tmp___1~0#1;havoc test_~tmp___2~0#1;test_~splverifierCounter~0#1 := 0; {1638#(= ~pumpRunning~0 0)} is VALID [2022-02-20 18:11:42,647 INFO L290 TraceCheckUtils]: 8: Hoare triple {1638#(= ~pumpRunning~0 0)} assume !false; {1638#(= ~pumpRunning~0 0)} is VALID [2022-02-20 18:11:42,648 INFO L290 TraceCheckUtils]: 9: Hoare triple {1638#(= ~pumpRunning~0 0)} assume test_~splverifierCounter~0#1 < 4; {1638#(= ~pumpRunning~0 0)} is VALID [2022-02-20 18:11:42,648 INFO L290 TraceCheckUtils]: 10: Hoare triple {1638#(= ~pumpRunning~0 0)} assume -2147483648 <= test_#t~nondet22#1 && test_#t~nondet22#1 <= 2147483647;test_~tmp~2#1 := test_#t~nondet22#1;havoc test_#t~nondet22#1; {1638#(= ~pumpRunning~0 0)} is VALID [2022-02-20 18:11:42,648 INFO L290 TraceCheckUtils]: 11: Hoare triple {1638#(= ~pumpRunning~0 0)} assume !(0 != test_~tmp~2#1); {1638#(= ~pumpRunning~0 0)} is VALID [2022-02-20 18:11:42,649 INFO L290 TraceCheckUtils]: 12: Hoare triple {1638#(= ~pumpRunning~0 0)} assume -2147483648 <= test_#t~nondet23#1 && test_#t~nondet23#1 <= 2147483647;test_~tmp___0~1#1 := test_#t~nondet23#1;havoc test_#t~nondet23#1; {1638#(= ~pumpRunning~0 0)} is VALID [2022-02-20 18:11:42,649 INFO L290 TraceCheckUtils]: 13: Hoare triple {1638#(= ~pumpRunning~0 0)} assume !(0 != test_~tmp___0~1#1); {1638#(= ~pumpRunning~0 0)} is VALID [2022-02-20 18:11:42,650 INFO L290 TraceCheckUtils]: 14: Hoare triple {1638#(= ~pumpRunning~0 0)} assume -2147483648 <= test_#t~nondet24#1 && test_#t~nondet24#1 <= 2147483647;test_~tmp___2~0#1 := test_#t~nondet24#1;havoc test_#t~nondet24#1; {1638#(= ~pumpRunning~0 0)} is VALID [2022-02-20 18:11:42,650 INFO L290 TraceCheckUtils]: 15: Hoare triple {1638#(= ~pumpRunning~0 0)} assume !(0 != test_~tmp___2~0#1);assume -2147483648 <= test_#t~nondet25#1 && test_#t~nondet25#1 <= 2147483647;test_~tmp___1~0#1 := test_#t~nondet25#1;havoc test_#t~nondet25#1; {1638#(= ~pumpRunning~0 0)} is VALID [2022-02-20 18:11:42,650 INFO L290 TraceCheckUtils]: 16: Hoare triple {1638#(= ~pumpRunning~0 0)} assume !(0 != test_~tmp___1~0#1); {1638#(= ~pumpRunning~0 0)} is VALID [2022-02-20 18:11:42,651 INFO L272 TraceCheckUtils]: 17: Hoare triple {1638#(= ~pumpRunning~0 0)} call timeShift(); {1638#(= ~pumpRunning~0 0)} is VALID [2022-02-20 18:11:42,651 INFO L290 TraceCheckUtils]: 18: Hoare triple {1638#(= ~pumpRunning~0 0)} assume { :begin_inline___utac_acc__Specification5_spec__2 } true;havoc __utac_acc__Specification5_spec__2_#t~ret4#1; {1638#(= ~pumpRunning~0 0)} is VALID [2022-02-20 18:11:42,651 INFO L272 TraceCheckUtils]: 19: Hoare triple {1638#(= ~pumpRunning~0 0)} call __utac_acc__Specification5_spec__2_#t~ret4#1 := isPumpRunning(); {1636#true} is VALID [2022-02-20 18:11:42,652 INFO L290 TraceCheckUtils]: 20: Hoare triple {1636#true} havoc ~retValue_acc~1;~retValue_acc~1 := ~pumpRunning~0;#res := ~retValue_acc~1; {1636#true} is VALID [2022-02-20 18:11:42,652 INFO L290 TraceCheckUtils]: 21: Hoare triple {1636#true} assume true; {1636#true} is VALID [2022-02-20 18:11:42,652 INFO L284 TraceCheckUtils]: 22: Hoare quadruple {1636#true} {1638#(= ~pumpRunning~0 0)} #194#return; {1638#(= ~pumpRunning~0 0)} is VALID [2022-02-20 18:11:42,653 INFO L290 TraceCheckUtils]: 23: Hoare triple {1638#(= ~pumpRunning~0 0)} assume -2147483648 <= __utac_acc__Specification5_spec__2_#t~ret4#1 && __utac_acc__Specification5_spec__2_#t~ret4#1 <= 2147483647;~switchedOnBeforeTS~0 := __utac_acc__Specification5_spec__2_#t~ret4#1;havoc __utac_acc__Specification5_spec__2_#t~ret4#1; {1638#(= ~pumpRunning~0 0)} is VALID [2022-02-20 18:11:42,653 INFO L290 TraceCheckUtils]: 24: Hoare triple {1638#(= ~pumpRunning~0 0)} assume { :end_inline___utac_acc__Specification5_spec__2 } true; {1638#(= ~pumpRunning~0 0)} is VALID [2022-02-20 18:11:42,654 INFO L290 TraceCheckUtils]: 25: Hoare triple {1638#(= ~pumpRunning~0 0)} assume !(0 != ~pumpRunning~0); {1638#(= ~pumpRunning~0 0)} is VALID [2022-02-20 18:11:42,654 INFO L290 TraceCheckUtils]: 26: Hoare triple {1638#(= ~pumpRunning~0 0)} assume 0 != ~systemActive~0;assume { :begin_inline_processEnvironment } true; {1638#(= ~pumpRunning~0 0)} is VALID [2022-02-20 18:11:42,655 INFO L290 TraceCheckUtils]: 27: Hoare triple {1638#(= ~pumpRunning~0 0)} assume { :end_inline_processEnvironment } true; {1638#(= ~pumpRunning~0 0)} is VALID [2022-02-20 18:11:42,655 INFO L290 TraceCheckUtils]: 28: Hoare triple {1638#(= ~pumpRunning~0 0)} assume { :begin_inline___utac_acc__Specification5_spec__3 } true;havoc __utac_acc__Specification5_spec__3_#t~ret5#1, __utac_acc__Specification5_spec__3_#t~ret6#1, __utac_acc__Specification5_spec__3_~tmp~0#1, __utac_acc__Specification5_spec__3_~tmp___0~0#1;havoc __utac_acc__Specification5_spec__3_~tmp~0#1;havoc __utac_acc__Specification5_spec__3_~tmp___0~0#1;assume { :begin_inline_getWaterLevel } true;havoc getWaterLevel_#res#1;havoc getWaterLevel_~retValue_acc~3#1;havoc getWaterLevel_~retValue_acc~3#1;getWaterLevel_~retValue_acc~3#1 := ~waterLevel~0;getWaterLevel_#res#1 := getWaterLevel_~retValue_acc~3#1; {1638#(= ~pumpRunning~0 0)} is VALID [2022-02-20 18:11:42,655 INFO L290 TraceCheckUtils]: 29: Hoare triple {1638#(= ~pumpRunning~0 0)} __utac_acc__Specification5_spec__3_#t~ret5#1 := getWaterLevel_#res#1;assume { :end_inline_getWaterLevel } true;assume -2147483648 <= __utac_acc__Specification5_spec__3_#t~ret5#1 && __utac_acc__Specification5_spec__3_#t~ret5#1 <= 2147483647;__utac_acc__Specification5_spec__3_~tmp~0#1 := __utac_acc__Specification5_spec__3_#t~ret5#1;havoc __utac_acc__Specification5_spec__3_#t~ret5#1; {1638#(= ~pumpRunning~0 0)} is VALID [2022-02-20 18:11:42,656 INFO L290 TraceCheckUtils]: 30: Hoare triple {1638#(= ~pumpRunning~0 0)} assume 2 != __utac_acc__Specification5_spec__3_~tmp~0#1; {1638#(= ~pumpRunning~0 0)} is VALID [2022-02-20 18:11:42,656 INFO L272 TraceCheckUtils]: 31: Hoare triple {1638#(= ~pumpRunning~0 0)} call __utac_acc__Specification5_spec__3_#t~ret6#1 := isPumpRunning(); {1636#true} is VALID [2022-02-20 18:11:42,656 INFO L290 TraceCheckUtils]: 32: Hoare triple {1636#true} havoc ~retValue_acc~1;~retValue_acc~1 := ~pumpRunning~0;#res := ~retValue_acc~1; {1647#(= ~pumpRunning~0 |isPumpRunning_#res|)} is VALID [2022-02-20 18:11:42,657 INFO L290 TraceCheckUtils]: 33: Hoare triple {1647#(= ~pumpRunning~0 |isPumpRunning_#res|)} assume true; {1647#(= ~pumpRunning~0 |isPumpRunning_#res|)} is VALID [2022-02-20 18:11:42,658 INFO L284 TraceCheckUtils]: 34: Hoare quadruple {1647#(= ~pumpRunning~0 |isPumpRunning_#res|)} {1638#(= ~pumpRunning~0 0)} #196#return; {1645#(= |timeShift___utac_acc__Specification5_spec__3_#t~ret6#1| 0)} is VALID [2022-02-20 18:11:42,658 INFO L290 TraceCheckUtils]: 35: Hoare triple {1645#(= |timeShift___utac_acc__Specification5_spec__3_#t~ret6#1| 0)} assume -2147483648 <= __utac_acc__Specification5_spec__3_#t~ret6#1 && __utac_acc__Specification5_spec__3_#t~ret6#1 <= 2147483647;__utac_acc__Specification5_spec__3_~tmp___0~0#1 := __utac_acc__Specification5_spec__3_#t~ret6#1;havoc __utac_acc__Specification5_spec__3_#t~ret6#1; {1646#(= |timeShift___utac_acc__Specification5_spec__3_~tmp___0~0#1| 0)} is VALID [2022-02-20 18:11:42,659 INFO L290 TraceCheckUtils]: 36: Hoare triple {1646#(= |timeShift___utac_acc__Specification5_spec__3_~tmp___0~0#1| 0)} assume 0 != __utac_acc__Specification5_spec__3_~tmp___0~0#1; {1637#false} is VALID [2022-02-20 18:11:42,659 INFO L290 TraceCheckUtils]: 37: Hoare triple {1637#false} assume 0 == ~switchedOnBeforeTS~0;assume { :begin_inline___automaton_fail } true; {1637#false} is VALID [2022-02-20 18:11:42,659 INFO L290 TraceCheckUtils]: 38: Hoare triple {1637#false} assume !false; {1637#false} is VALID [2022-02-20 18:11:42,660 INFO L134 CoverageAnalysis]: Checked inductivity of 3 backedges. 2 proven. 0 refuted. 0 times theorem prover too weak. 1 trivial. 0 not checked. [2022-02-20 18:11:42,660 INFO L144 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2022-02-20 18:11:42,660 INFO L338 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [1405315280] [2022-02-20 18:11:42,660 INFO L165 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [1405315280] provided 1 perfect and 0 imperfect interpolant sequences [2022-02-20 18:11:42,660 INFO L191 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2022-02-20 18:11:42,660 INFO L204 FreeRefinementEngine]: Number of different interpolants: perfect sequences [6] imperfect sequences [] total 6 [2022-02-20 18:11:42,661 INFO L118 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [939075965] [2022-02-20 18:11:42,661 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2022-02-20 18:11:42,661 INFO L78 Accepts]: Start accepts. Automaton has has 6 states, 6 states have (on average 5.666666666666667) internal successors, (34), 5 states have internal predecessors, (34), 1 states have call successors, (3), 2 states have call predecessors, (3), 2 states have return successors, (2), 2 states have call predecessors, (2), 1 states have call successors, (2) Word has length 39 [2022-02-20 18:11:42,662 INFO L84 Accepts]: Finished accepts. word is accepted. [2022-02-20 18:11:42,662 INFO L86 InductivityCheck]: Starting indutivity check of a Floyd-Hoare automaton with has 6 states, 6 states have (on average 5.666666666666667) internal successors, (34), 5 states have internal predecessors, (34), 1 states have call successors, (3), 2 states have call predecessors, (3), 2 states have return successors, (2), 2 states have call predecessors, (2), 1 states have call successors, (2) [2022-02-20 18:11:42,692 INFO L122 InductivityCheck]: Floyd-Hoare automaton has 39 edges. 39 inductive. 0 not inductive. 0 times theorem prover too weak to decide inductivity. [2022-02-20 18:11:42,692 INFO L546 AbstractCegarLoop]: INTERPOLANT automaton has 6 states [2022-02-20 18:11:42,693 INFO L108 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2022-02-20 18:11:42,693 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 6 interpolants. [2022-02-20 18:11:42,693 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=9, Invalid=21, Unknown=0, NotChecked=0, Total=30 [2022-02-20 18:11:42,694 INFO L87 Difference]: Start difference. First operand 134 states and 172 transitions. Second operand has 6 states, 6 states have (on average 5.666666666666667) internal successors, (34), 5 states have internal predecessors, (34), 1 states have call successors, (3), 2 states have call predecessors, (3), 2 states have return successors, (2), 2 states have call predecessors, (2), 1 states have call successors, (2) [2022-02-20 18:11:42,895 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-02-20 18:11:42,896 INFO L93 Difference]: Finished difference Result 257 states and 333 transitions. [2022-02-20 18:11:42,896 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 6 states. [2022-02-20 18:11:42,896 INFO L78 Accepts]: Start accepts. Automaton has has 6 states, 6 states have (on average 5.666666666666667) internal successors, (34), 5 states have internal predecessors, (34), 1 states have call successors, (3), 2 states have call predecessors, (3), 2 states have return successors, (2), 2 states have call predecessors, (2), 1 states have call successors, (2) Word has length 39 [2022-02-20 18:11:42,897 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2022-02-20 18:11:42,897 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 6 states, 6 states have (on average 5.666666666666667) internal successors, (34), 5 states have internal predecessors, (34), 1 states have call successors, (3), 2 states have call predecessors, (3), 2 states have return successors, (2), 2 states have call predecessors, (2), 1 states have call successors, (2) [2022-02-20 18:11:42,899 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 6 states to 6 states and 125 transitions. [2022-02-20 18:11:42,900 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 6 states, 6 states have (on average 5.666666666666667) internal successors, (34), 5 states have internal predecessors, (34), 1 states have call successors, (3), 2 states have call predecessors, (3), 2 states have return successors, (2), 2 states have call predecessors, (2), 1 states have call successors, (2) [2022-02-20 18:11:42,902 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 6 states to 6 states and 125 transitions. [2022-02-20 18:11:42,902 INFO L86 InductivityCheck]: Starting indutivity check of a Floyd-Hoare automaton with 6 states and 125 transitions. [2022-02-20 18:11:42,993 INFO L122 InductivityCheck]: Floyd-Hoare automaton has 125 edges. 125 inductive. 0 not inductive. 0 times theorem prover too weak to decide inductivity. [2022-02-20 18:11:42,994 INFO L225 Difference]: With dead ends: 257 [2022-02-20 18:11:42,994 INFO L226 Difference]: Without dead ends: 0 [2022-02-20 18:11:42,995 INFO L932 BasicCegarLoop]: 0 DeclaredPredicates, 11 GetRequests, 4 SyntacticMatches, 0 SemanticMatches, 7 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 3 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=21, Invalid=51, Unknown=0, NotChecked=0, Total=72 [2022-02-20 18:11:42,996 INFO L933 BasicCegarLoop]: 56 mSDtfsCounter, 31 mSDsluCounter, 150 mSDsCounter, 0 mSdLazyCounter, 31 mSolverCounterSat, 3 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.0s Time, 0 mProtectedPredicate, 0 mProtectedAction, 32 SdHoareTripleChecker+Valid, 206 SdHoareTripleChecker+Invalid, 34 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 3 IncrementalHoareTripleChecker+Valid, 31 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.0s IncrementalHoareTripleChecker+Time [2022-02-20 18:11:42,997 INFO L934 BasicCegarLoop]: SdHoareTripleChecker [32 Valid, 206 Invalid, 34 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [3 Valid, 31 Invalid, 0 Unknown, 0 Unchecked, 0.0s Time] [2022-02-20 18:11:42,997 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 0 states. [2022-02-20 18:11:42,998 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 0 to 0. [2022-02-20 18:11:42,998 INFO L214 AbstractMinimizeNwa]: Start testing correctness of minimizeSevpa [2022-02-20 18:11:42,998 INFO L82 GeneralOperation]: Start isEquivalent. First operand 0 states. Second operand has 0 states, 0 states have (on average 0.0) internal successors, (0), 0 states have internal predecessors, (0), 0 states have call successors, (0), 0 states have call predecessors, (0), 0 states have return successors, (0), 0 states have call predecessors, (0), 0 states have call successors, (0) [2022-02-20 18:11:42,998 INFO L74 IsIncluded]: Start isIncluded. First operand 0 states. Second operand has 0 states, 0 states have (on average 0.0) internal successors, (0), 0 states have internal predecessors, (0), 0 states have call successors, (0), 0 states have call predecessors, (0), 0 states have return successors, (0), 0 states have call predecessors, (0), 0 states have call successors, (0) [2022-02-20 18:11:42,998 INFO L87 Difference]: Start difference. First operand 0 states. Second operand has 0 states, 0 states have (on average 0.0) internal successors, (0), 0 states have internal predecessors, (0), 0 states have call successors, (0), 0 states have call predecessors, (0), 0 states have return successors, (0), 0 states have call predecessors, (0), 0 states have call successors, (0) [2022-02-20 18:11:42,999 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-02-20 18:11:42,999 INFO L93 Difference]: Finished difference Result 0 states and 0 transitions. [2022-02-20 18:11:42,999 INFO L276 IsEmpty]: Start isEmpty. Operand 0 states and 0 transitions. [2022-02-20 18:11:42,999 INFO L282 IsEmpty]: Finished isEmpty. No accepting run. [2022-02-20 18:11:42,999 INFO L83 IsIncluded]: Finished isIncluded. Language is included [2022-02-20 18:11:42,999 INFO L74 IsIncluded]: Start isIncluded. First operand has 0 states, 0 states have (on average 0.0) internal successors, (0), 0 states have internal predecessors, (0), 0 states have call successors, (0), 0 states have call predecessors, (0), 0 states have return successors, (0), 0 states have call predecessors, (0), 0 states have call successors, (0) Second operand 0 states. [2022-02-20 18:11:43,000 INFO L87 Difference]: Start difference. First operand has 0 states, 0 states have (on average 0.0) internal successors, (0), 0 states have internal predecessors, (0), 0 states have call successors, (0), 0 states have call predecessors, (0), 0 states have return successors, (0), 0 states have call predecessors, (0), 0 states have call successors, (0) Second operand 0 states. [2022-02-20 18:11:43,000 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-02-20 18:11:43,000 INFO L93 Difference]: Finished difference Result 0 states and 0 transitions. [2022-02-20 18:11:43,000 INFO L276 IsEmpty]: Start isEmpty. Operand 0 states and 0 transitions. [2022-02-20 18:11:43,000 INFO L282 IsEmpty]: Finished isEmpty. No accepting run. [2022-02-20 18:11:43,000 INFO L83 IsIncluded]: Finished isIncluded. Language is included [2022-02-20 18:11:43,000 INFO L88 GeneralOperation]: Finished isEquivalent. [2022-02-20 18:11:43,001 INFO L221 AbstractMinimizeNwa]: Finished testing correctness of minimizeSevpa [2022-02-20 18:11:43,001 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 0 states, 0 states have (on average 0.0) internal successors, (0), 0 states have internal predecessors, (0), 0 states have call successors, (0), 0 states have call predecessors, (0), 0 states have return successors, (0), 0 states have call predecessors, (0), 0 states have call successors, (0) [2022-02-20 18:11:43,001 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 0 states to 0 states and 0 transitions. [2022-02-20 18:11:43,001 INFO L78 Accepts]: Start accepts. Automaton has 0 states and 0 transitions. Word has length 39 [2022-02-20 18:11:43,001 INFO L84 Accepts]: Finished accepts. word is rejected. [2022-02-20 18:11:43,001 INFO L470 AbstractCegarLoop]: Abstraction has 0 states and 0 transitions. [2022-02-20 18:11:43,002 INFO L471 AbstractCegarLoop]: INTERPOLANT automaton has has 6 states, 6 states have (on average 5.666666666666667) internal successors, (34), 5 states have internal predecessors, (34), 1 states have call successors, (3), 2 states have call predecessors, (3), 2 states have return successors, (2), 2 states have call predecessors, (2), 1 states have call successors, (2) [2022-02-20 18:11:43,002 INFO L276 IsEmpty]: Start isEmpty. Operand 0 states and 0 transitions. [2022-02-20 18:11:43,002 INFO L282 IsEmpty]: Finished isEmpty. No accepting run. [2022-02-20 18:11:43,004 INFO L764 garLoopResultBuilder]: Registering result SAFE for location timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION (0 of 1 remaining) [2022-02-20 18:11:43,005 WARN L452 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable3 [2022-02-20 18:11:43,006 INFO L343 DoubleDeckerVisitor]: Before removal of dead ends 0 states and 0 transitions. [2022-02-20 18:11:43,241 INFO L861 garLoopResultBuilder]: At program point changeMethaneLevelENTRY(lines 290 301) the Hoare annotation is: true [2022-02-20 18:11:43,241 INFO L858 garLoopResultBuilder]: For program point changeMethaneLevelEXIT(lines 290 301) no Hoare annotation was computed. [2022-02-20 18:11:43,241 INFO L858 garLoopResultBuilder]: For program point L294-1(lines 290 301) no Hoare annotation was computed. [2022-02-20 18:11:43,241 INFO L861 garLoopResultBuilder]: At program point L449(lines 424 453) the Hoare annotation is: true [2022-02-20 18:11:43,242 INFO L858 garLoopResultBuilder]: For program point cleanupEXIT(lines 424 453) no Hoare annotation was computed. [2022-02-20 18:11:43,242 INFO L858 garLoopResultBuilder]: For program point L445(line 445) no Hoare annotation was computed. [2022-02-20 18:11:43,242 INFO L861 garLoopResultBuilder]: At program point cleanupENTRY(lines 424 453) the Hoare annotation is: true [2022-02-20 18:11:43,242 INFO L858 garLoopResultBuilder]: For program point L438(lines 438 442) no Hoare annotation was computed. [2022-02-20 18:11:43,242 INFO L861 garLoopResultBuilder]: At program point L438-1(lines 438 442) the Hoare annotation is: true [2022-02-20 18:11:43,242 INFO L858 garLoopResultBuilder]: For program point L435(line 435) no Hoare annotation was computed. [2022-02-20 18:11:43,242 INFO L861 garLoopResultBuilder]: At program point L434-2(lines 434 448) the Hoare annotation is: true [2022-02-20 18:11:43,243 INFO L861 garLoopResultBuilder]: At program point L430(line 430) the Hoare annotation is: true [2022-02-20 18:11:43,243 INFO L858 garLoopResultBuilder]: For program point L430-1(line 430) no Hoare annotation was computed. [2022-02-20 18:11:43,243 INFO L858 garLoopResultBuilder]: For program point L85(lines 85 91) no Hoare annotation was computed. [2022-02-20 18:11:43,243 INFO L858 garLoopResultBuilder]: For program point timeShiftFINAL(lines 114 140) no Hoare annotation was computed. [2022-02-20 18:11:43,243 INFO L861 garLoopResultBuilder]: At program point L69(lines 62 71) the Hoare annotation is: true [2022-02-20 18:11:43,243 INFO L861 garLoopResultBuilder]: At program point L82(line 82) the Hoare annotation is: true [2022-02-20 18:11:43,244 INFO L858 garLoopResultBuilder]: For program point L82-1(line 82) no Hoare annotation was computed. [2022-02-20 18:11:43,244 INFO L858 garLoopResultBuilder]: For program point L128-1(lines 128 134) no Hoare annotation was computed. [2022-02-20 18:11:43,244 INFO L861 garLoopResultBuilder]: At program point L339(lines 334 342) the Hoare annotation is: true [2022-02-20 18:11:43,244 INFO L854 garLoopResultBuilder]: At program point L145(lines 141 147) the Hoare annotation is: (or (not (= ~pumpRunning~0 0)) (not (= 0 ~systemActive~0))) [2022-02-20 18:11:43,244 INFO L861 garLoopResultBuilder]: At program point L67(line 67) the Hoare annotation is: true [2022-02-20 18:11:43,244 INFO L858 garLoopResultBuilder]: For program point L67-1(line 67) no Hoare annotation was computed. [2022-02-20 18:11:43,244 INFO L858 garLoopResultBuilder]: For program point L418(line 418) no Hoare annotation was computed. [2022-02-20 18:11:43,245 INFO L858 garLoopResultBuilder]: For program point L121(lines 121 127) no Hoare annotation was computed. [2022-02-20 18:11:43,245 INFO L858 garLoopResultBuilder]: For program point L121-2(lines 117 139) no Hoare annotation was computed. [2022-02-20 18:11:43,245 INFO L858 garLoopResultBuilder]: For program point L84(lines 84 94) no Hoare annotation was computed. [2022-02-20 18:11:43,245 INFO L858 garLoopResultBuilder]: For program point L80(lines 80 97) no Hoare annotation was computed. [2022-02-20 18:11:43,245 INFO L861 garLoopResultBuilder]: At program point timeShiftENTRY(lines 114 140) the Hoare annotation is: true [2022-02-20 18:11:43,245 INFO L861 garLoopResultBuilder]: At program point L80-1(lines 72 100) the Hoare annotation is: true [2022-02-20 18:11:43,245 INFO L858 garLoopResultBuilder]: For program point L270(lines 270 274) no Hoare annotation was computed. [2022-02-20 18:11:43,246 INFO L854 garLoopResultBuilder]: At program point L270-2(lines 266 277) the Hoare annotation is: (not (= ~pumpRunning~0 0)) [2022-02-20 18:11:43,246 INFO L858 garLoopResultBuilder]: For program point timeShiftEXIT(lines 114 140) no Hoare annotation was computed. [2022-02-20 18:11:43,246 INFO L858 garLoopResultBuilder]: For program point timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION(line 418) no Hoare annotation was computed. [2022-02-20 18:11:43,246 INFO L854 garLoopResultBuilder]: At program point L419(lines 414 421) the Hoare annotation is: (not (= ~pumpRunning~0 0)) [2022-02-20 18:11:43,246 INFO L854 garLoopResultBuilder]: At program point L250(lines 238 252) the Hoare annotation is: (and (= ~pumpRunning~0 0) (= |ULTIMATE.start_test_~splverifierCounter~0#1| 0)) [2022-02-20 18:11:43,246 INFO L854 garLoopResultBuilder]: At program point L919(lines 914 922) the Hoare annotation is: (and (= ~pumpRunning~0 0) (= 1 ~systemActive~0) (= |ULTIMATE.start_valid_product_#res#1| ~systemActive~0)) [2022-02-20 18:11:43,247 INFO L858 garLoopResultBuilder]: For program point L242(lines 242 248) no Hoare annotation was computed. [2022-02-20 18:11:43,247 INFO L858 garLoopResultBuilder]: For program point L242-2(lines 242 248) no Hoare annotation was computed. [2022-02-20 18:11:43,247 INFO L854 garLoopResultBuilder]: At program point L911(lines 907 913) the Hoare annotation is: (and (= ~pumpRunning~0 0) (= 1 ~systemActive~0)) [2022-02-20 18:11:43,247 INFO L854 garLoopResultBuilder]: At program point L482(lines 478 484) the Hoare annotation is: (and (= ~pumpRunning~0 0) (= |ULTIMATE.start_main_~tmp~3#1| ~systemActive~0) (= 1 ~systemActive~0) (= |ULTIMATE.start_valid_product_#res#1| ~systemActive~0)) [2022-02-20 18:11:43,247 INFO L858 garLoopResultBuilder]: For program point L-1(line -1) no Hoare annotation was computed. [2022-02-20 18:11:43,247 INFO L858 garLoopResultBuilder]: For program point ULTIMATE.startENTRY(line -1) no Hoare annotation was computed. [2022-02-20 18:11:43,247 INFO L858 garLoopResultBuilder]: For program point ULTIMATE.startFINAL(line -1) no Hoare annotation was computed. [2022-02-20 18:11:43,248 INFO L861 garLoopResultBuilder]: At program point L408(lines 345 412) the Hoare annotation is: true [2022-02-20 18:11:43,248 INFO L858 garLoopResultBuilder]: For program point L375(lines 375 381) no Hoare annotation was computed. [2022-02-20 18:11:43,248 INFO L858 garLoopResultBuilder]: For program point L375-1(lines 375 381) no Hoare annotation was computed. [2022-02-20 18:11:43,248 INFO L854 garLoopResultBuilder]: At program point L367(line 367) the Hoare annotation is: (and (= ~pumpRunning~0 0) (= |ULTIMATE.start_test_~splverifierCounter~0#1| 0)) [2022-02-20 18:11:43,248 INFO L854 garLoopResultBuilder]: At program point L904(lines 900 906) the Hoare annotation is: (and (= ~pumpRunning~0 0) (= 1 ~systemActive~0)) [2022-02-20 18:11:43,248 INFO L858 garLoopResultBuilder]: For program point ULTIMATE.startEXIT(line -1) no Hoare annotation was computed. [2022-02-20 18:11:43,249 INFO L854 garLoopResultBuilder]: At program point L405(lines 354 406) the Hoare annotation is: false [2022-02-20 18:11:43,249 INFO L858 garLoopResultBuilder]: For program point L393(lines 393 399) no Hoare annotation was computed. [2022-02-20 18:11:43,249 INFO L854 garLoopResultBuilder]: At program point L393-2(lines 385 400) the Hoare annotation is: (and (= ~pumpRunning~0 0) (= |ULTIMATE.start_test_~splverifierCounter~0#1| 0)) [2022-02-20 18:11:43,249 INFO L858 garLoopResultBuilder]: For program point L356(lines 355 404) no Hoare annotation was computed. [2022-02-20 18:11:43,249 INFO L858 garLoopResultBuilder]: For program point L385(lines 385 400) no Hoare annotation was computed. [2022-02-20 18:11:43,249 INFO L858 garLoopResultBuilder]: For program point L509(lines 509 516) no Hoare annotation was computed. [2022-02-20 18:11:43,249 INFO L854 garLoopResultBuilder]: At program point L59(lines 54 61) the Hoare annotation is: (and (= ~pumpRunning~0 0) (= |ULTIMATE.start_main_~tmp~3#1| ~systemActive~0) (= 1 ~systemActive~0) (= |ULTIMATE.start_valid_product_#res#1| ~systemActive~0)) [2022-02-20 18:11:43,250 INFO L858 garLoopResultBuilder]: For program point L509-2(lines 509 516) no Hoare annotation was computed. [2022-02-20 18:11:43,250 INFO L854 garLoopResultBuilder]: At program point L377(line 377) the Hoare annotation is: (and (= ~pumpRunning~0 0) (= |ULTIMATE.start_test_~splverifierCounter~0#1| 0)) [2022-02-20 18:11:43,250 INFO L854 garLoopResultBuilder]: At program point L179(lines 174 181) the Hoare annotation is: false [2022-02-20 18:11:43,250 INFO L854 garLoopResultBuilder]: At program point L402(lines 355 404) the Hoare annotation is: (and (= ~pumpRunning~0 0) (= |ULTIMATE.start_test_~splverifierCounter~0#1| 0)) [2022-02-20 18:11:43,250 INFO L858 garLoopResultBuilder]: For program point L365(lines 365 371) no Hoare annotation was computed. [2022-02-20 18:11:43,250 INFO L861 garLoopResultBuilder]: At program point L493(lines 485 495) the Hoare annotation is: true [2022-02-20 18:11:43,250 INFO L858 garLoopResultBuilder]: For program point L365-1(lines 365 371) no Hoare annotation was computed. [2022-02-20 18:11:43,251 INFO L861 garLoopResultBuilder]: At program point L518(lines 499 521) the Hoare annotation is: true [2022-02-20 18:11:43,251 INFO L858 garLoopResultBuilder]: For program point L357(lines 357 361) no Hoare annotation was computed. [2022-02-20 18:11:43,251 INFO L854 garLoopResultBuilder]: At program point L258(lines 253 260) the Hoare annotation is: (and (= ~pumpRunning~0 0) (= 1 ~systemActive~0) (= |ULTIMATE.start_test_~splverifierCounter~0#1| 0)) [2022-02-20 18:11:43,251 INFO L858 garLoopResultBuilder]: For program point waterRiseEXIT(lines 278 289) no Hoare annotation was computed. [2022-02-20 18:11:43,251 INFO L858 garLoopResultBuilder]: For program point L282-1(lines 278 289) no Hoare annotation was computed. [2022-02-20 18:11:43,251 INFO L861 garLoopResultBuilder]: At program point waterRiseENTRY(lines 278 289) the Hoare annotation is: true [2022-02-20 18:11:43,251 INFO L858 garLoopResultBuilder]: For program point isPumpRunningEXIT(lines 193 201) no Hoare annotation was computed. [2022-02-20 18:11:43,252 INFO L861 garLoopResultBuilder]: At program point isPumpRunningENTRY(lines 193 201) the Hoare annotation is: true [2022-02-20 18:11:43,252 INFO L858 garLoopResultBuilder]: For program point isPumpRunningFINAL(lines 193 201) no Hoare annotation was computed. [2022-02-20 18:11:43,255 INFO L732 BasicCegarLoop]: Path program histogram: [1, 1, 1, 1] [2022-02-20 18:11:43,256 INFO L180 ceAbstractionStarter]: Computing trace abstraction results [2022-02-20 18:11:43,259 WARN L170 areAnnotationChecker]: L294-1 has no Hoare annotation [2022-02-20 18:11:43,259 WARN L170 areAnnotationChecker]: L294-1 has no Hoare annotation [2022-02-20 18:11:43,259 WARN L170 areAnnotationChecker]: ULTIMATE.startENTRY has no Hoare annotation [2022-02-20 18:11:43,259 WARN L170 areAnnotationChecker]: L282-1 has no Hoare annotation [2022-02-20 18:11:43,259 WARN L170 areAnnotationChecker]: L282-1 has no Hoare annotation [2022-02-20 18:11:43,260 WARN L170 areAnnotationChecker]: isPumpRunningFINAL has no Hoare annotation [2022-02-20 18:11:43,260 WARN L170 areAnnotationChecker]: L294-1 has no Hoare annotation [2022-02-20 18:11:43,260 WARN L170 areAnnotationChecker]: L430-1 has no Hoare annotation [2022-02-20 18:11:43,260 WARN L170 areAnnotationChecker]: L67-1 has no Hoare annotation [2022-02-20 18:11:43,260 WARN L170 areAnnotationChecker]: L-1 has no Hoare annotation [2022-02-20 18:11:43,260 WARN L170 areAnnotationChecker]: L282-1 has no Hoare annotation [2022-02-20 18:11:43,260 WARN L170 areAnnotationChecker]: isPumpRunningFINAL has no Hoare annotation [2022-02-20 18:11:43,260 WARN L170 areAnnotationChecker]: changeMethaneLevelEXIT has no Hoare annotation [2022-02-20 18:11:43,260 WARN L170 areAnnotationChecker]: L430-1 has no Hoare annotation [2022-02-20 18:11:43,261 WARN L170 areAnnotationChecker]: L67-1 has no Hoare annotation [2022-02-20 18:11:43,261 WARN L170 areAnnotationChecker]: waterRiseEXIT has no Hoare annotation [2022-02-20 18:11:43,261 WARN L170 areAnnotationChecker]: isPumpRunningEXIT has no Hoare annotation [2022-02-20 18:11:43,262 WARN L170 areAnnotationChecker]: isPumpRunningEXIT has no Hoare annotation [2022-02-20 18:11:43,262 WARN L170 areAnnotationChecker]: L375-1 has no Hoare annotation [2022-02-20 18:11:43,262 WARN L170 areAnnotationChecker]: L435 has no Hoare annotation [2022-02-20 18:11:43,262 WARN L170 areAnnotationChecker]: L121 has no Hoare annotation [2022-02-20 18:11:43,262 WARN L170 areAnnotationChecker]: L365-1 has no Hoare annotation [2022-02-20 18:11:43,263 WARN L170 areAnnotationChecker]: L82-1 has no Hoare annotation [2022-02-20 18:11:43,263 WARN L170 areAnnotationChecker]: L385 has no Hoare annotation [2022-02-20 18:11:43,263 WARN L170 areAnnotationChecker]: L385 has no Hoare annotation [2022-02-20 18:11:43,263 WARN L170 areAnnotationChecker]: cleanupEXIT has no Hoare annotation [2022-02-20 18:11:43,263 WARN L170 areAnnotationChecker]: L435 has no Hoare annotation [2022-02-20 18:11:43,263 WARN L170 areAnnotationChecker]: L121 has no Hoare annotation [2022-02-20 18:11:43,263 WARN L170 areAnnotationChecker]: L121 has no Hoare annotation [2022-02-20 18:11:43,263 WARN L170 areAnnotationChecker]: L509 has no Hoare annotation [2022-02-20 18:11:43,263 WARN L170 areAnnotationChecker]: L375 has no Hoare annotation [2022-02-20 18:11:43,264 WARN L170 areAnnotationChecker]: L375 has no Hoare annotation [2022-02-20 18:11:43,264 WARN L170 areAnnotationChecker]: L84 has no Hoare annotation [2022-02-20 18:11:43,264 WARN L170 areAnnotationChecker]: L84 has no Hoare annotation [2022-02-20 18:11:43,264 WARN L170 areAnnotationChecker]: L393 has no Hoare annotation [2022-02-20 18:11:43,264 WARN L170 areAnnotationChecker]: L393 has no Hoare annotation [2022-02-20 18:11:43,264 WARN L170 areAnnotationChecker]: cleanupEXIT has no Hoare annotation [2022-02-20 18:11:43,265 WARN L170 areAnnotationChecker]: L438 has no Hoare annotation [2022-02-20 18:11:43,265 WARN L170 areAnnotationChecker]: L438 has no Hoare annotation [2022-02-20 18:11:43,265 WARN L170 areAnnotationChecker]: L270 has no Hoare annotation [2022-02-20 18:11:43,265 WARN L170 areAnnotationChecker]: L270 has no Hoare annotation [2022-02-20 18:11:43,265 WARN L170 areAnnotationChecker]: L121-2 has no Hoare annotation [2022-02-20 18:11:43,265 WARN L170 areAnnotationChecker]: L121-2 has no Hoare annotation [2022-02-20 18:11:43,265 WARN L170 areAnnotationChecker]: L509 has no Hoare annotation [2022-02-20 18:11:43,265 WARN L170 areAnnotationChecker]: L509 has no Hoare annotation [2022-02-20 18:11:43,265 WARN L170 areAnnotationChecker]: L375-1 has no Hoare annotation [2022-02-20 18:11:43,266 WARN L170 areAnnotationChecker]: L85 has no Hoare annotation [2022-02-20 18:11:43,266 WARN L170 areAnnotationChecker]: L85 has no Hoare annotation [2022-02-20 18:11:43,266 WARN L170 areAnnotationChecker]: timeShiftFINAL has no Hoare annotation [2022-02-20 18:11:43,266 WARN L170 areAnnotationChecker]: L242 has no Hoare annotation [2022-02-20 18:11:43,266 WARN L170 areAnnotationChecker]: L242 has no Hoare annotation [2022-02-20 18:11:43,266 WARN L170 areAnnotationChecker]: L445 has no Hoare annotation [2022-02-20 18:11:43,266 WARN L170 areAnnotationChecker]: L121-2 has no Hoare annotation [2022-02-20 18:11:43,266 WARN L170 areAnnotationChecker]: L128-1 has no Hoare annotation [2022-02-20 18:11:43,266 WARN L170 areAnnotationChecker]: L128-1 has no Hoare annotation [2022-02-20 18:11:43,267 WARN L170 areAnnotationChecker]: L509-2 has no Hoare annotation [2022-02-20 18:11:43,267 WARN L170 areAnnotationChecker]: L418 has no Hoare annotation [2022-02-20 18:11:43,267 WARN L170 areAnnotationChecker]: L418 has no Hoare annotation [2022-02-20 18:11:43,267 WARN L170 areAnnotationChecker]: timeShiftFINAL has no Hoare annotation [2022-02-20 18:11:43,268 WARN L170 areAnnotationChecker]: L356 has no Hoare annotation [2022-02-20 18:11:43,268 WARN L170 areAnnotationChecker]: L242-2 has no Hoare annotation [2022-02-20 18:11:43,268 WARN L170 areAnnotationChecker]: L242-2 has no Hoare annotation [2022-02-20 18:11:43,268 WARN L170 areAnnotationChecker]: L509-2 has no Hoare annotation [2022-02-20 18:11:43,268 WARN L170 areAnnotationChecker]: L445 has no Hoare annotation [2022-02-20 18:11:43,268 WARN L170 areAnnotationChecker]: L80 has no Hoare annotation [2022-02-20 18:11:43,269 WARN L170 areAnnotationChecker]: ULTIMATE.startFINAL has no Hoare annotation [2022-02-20 18:11:43,269 WARN L170 areAnnotationChecker]: timeShiftEXIT has no Hoare annotation [2022-02-20 18:11:43,269 WARN L170 areAnnotationChecker]: timeShiftEXIT has no Hoare annotation [2022-02-20 18:11:43,269 WARN L170 areAnnotationChecker]: timeShiftEXIT has no Hoare annotation [2022-02-20 18:11:43,269 WARN L170 areAnnotationChecker]: L356 has no Hoare annotation [2022-02-20 18:11:43,270 WARN L170 areAnnotationChecker]: L356 has no Hoare annotation [2022-02-20 18:11:43,270 WARN L170 areAnnotationChecker]: L80 has no Hoare annotation [2022-02-20 18:11:43,270 WARN L170 areAnnotationChecker]: L80 has no Hoare annotation [2022-02-20 18:11:43,270 WARN L170 areAnnotationChecker]: ULTIMATE.startFINAL has no Hoare annotation [2022-02-20 18:11:43,270 WARN L170 areAnnotationChecker]: L357 has no Hoare annotation [2022-02-20 18:11:43,270 WARN L170 areAnnotationChecker]: L82-1 has no Hoare annotation [2022-02-20 18:11:43,271 WARN L170 areAnnotationChecker]: L365 has no Hoare annotation [2022-02-20 18:11:43,271 WARN L170 areAnnotationChecker]: L365 has no Hoare annotation [2022-02-20 18:11:43,271 WARN L170 areAnnotationChecker]: L365-1 has no Hoare annotation [2022-02-20 18:11:43,271 INFO L163 areAnnotationChecker]: CFG has 22 edges. 22 inductive. 0 not inductive. 0 times theorem prover too weak to decide inductivity. 0 times interpolants missing. [2022-02-20 18:11:43,282 INFO L202 PluginConnector]: Adding new model de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction CFG 20.02 06:11:43 BoogieIcfgContainer [2022-02-20 18:11:43,282 INFO L132 PluginConnector]: ------------------------ END TraceAbstraction---------------------------- [2022-02-20 18:11:43,283 INFO L113 PluginConnector]: ------------------------Witness Printer---------------------------- [2022-02-20 18:11:43,283 INFO L271 PluginConnector]: Initializing Witness Printer... [2022-02-20 18:11:43,283 INFO L275 PluginConnector]: Witness Printer initialized [2022-02-20 18:11:43,284 INFO L185 PluginConnector]: Executing the observer RCFGCatcher from plugin Witness Printer for "de.uni_freiburg.informatik.ultimate.plugins.generator.rcfgbuilder CFG 20.02 06:11:40" (3/4) ... [2022-02-20 18:11:43,286 INFO L137 WitnessPrinter]: Generating witness for correct program [2022-02-20 18:11:43,291 INFO L354 RCFGBacktranslator]: Ignoring RootEdge to procedure changeMethaneLevel [2022-02-20 18:11:43,291 INFO L354 RCFGBacktranslator]: Ignoring RootEdge to procedure cleanup [2022-02-20 18:11:43,291 INFO L354 RCFGBacktranslator]: Ignoring RootEdge to procedure timeShift [2022-02-20 18:11:43,291 INFO L354 RCFGBacktranslator]: Ignoring RootEdge to procedure waterRise [2022-02-20 18:11:43,291 INFO L354 RCFGBacktranslator]: Ignoring RootEdge to procedure isPumpRunning [2022-02-20 18:11:43,296 INFO L910 BoogieBacktranslator]: Reduced CFG by removing 45 nodes and edges [2022-02-20 18:11:43,297 INFO L910 BoogieBacktranslator]: Reduced CFG by removing 22 nodes and edges [2022-02-20 18:11:43,297 INFO L910 BoogieBacktranslator]: Reduced CFG by removing 11 nodes and edges [2022-02-20 18:11:43,297 INFO L910 BoogieBacktranslator]: Reduced CFG by removing 5 nodes and edges [2022-02-20 18:11:43,298 INFO L910 BoogieBacktranslator]: Reduced CFG by removing 2 nodes and edges [2022-02-20 18:11:43,298 INFO L910 BoogieBacktranslator]: Reduced CFG by removing 1 nodes and edges [2022-02-20 18:11:43,298 INFO L910 BoogieBacktranslator]: Reduced CFG by removing 1 nodes and edges [2022-02-20 18:11:43,317 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (pumpRunning == 0 && 1 == systemActive) && \result == systemActive [2022-02-20 18:11:43,318 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: ((pumpRunning == 0 && tmp == systemActive) && 1 == systemActive) && \result == systemActive [2022-02-20 18:11:43,318 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: ((pumpRunning == 0 && tmp == systemActive) && 1 == systemActive) && \result == systemActive [2022-02-20 18:11:43,338 INFO L141 WitnessManager]: Wrote witness to /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/witness.graphml [2022-02-20 18:11:43,338 INFO L132 PluginConnector]: ------------------------ END Witness Printer---------------------------- [2022-02-20 18:11:43,339 INFO L158 Benchmark]: Toolchain (without parser) took 4351.81ms. Allocated memory was 96.5MB in the beginning and 125.8MB in the end (delta: 29.4MB). Free memory was 54.7MB in the beginning and 61.8MB in the end (delta: -7.1MB). Peak memory consumption was 21.6MB. Max. memory is 16.1GB. [2022-02-20 18:11:43,340 INFO L158 Benchmark]: CDTParser took 0.30ms. Allocated memory is still 96.5MB. Free memory is still 71.9MB. There was no memory consumed. Max. memory is 16.1GB. [2022-02-20 18:11:43,340 INFO L158 Benchmark]: CACSL2BoogieTranslator took 470.39ms. Allocated memory is still 96.5MB. Free memory was 54.5MB in the beginning and 59.3MB in the end (delta: -4.8MB). Peak memory consumption was 4.2MB. Max. memory is 16.1GB. [2022-02-20 18:11:43,340 INFO L158 Benchmark]: Boogie Procedure Inliner took 60.53ms. Allocated memory is still 96.5MB. Free memory was 59.3MB in the beginning and 56.5MB in the end (delta: 2.8MB). Peak memory consumption was 2.1MB. Max. memory is 16.1GB. [2022-02-20 18:11:43,340 INFO L158 Benchmark]: Boogie Preprocessor took 28.00ms. Allocated memory is still 96.5MB. Free memory was 56.5MB in the beginning and 55.2MB in the end (delta: 1.3MB). Peak memory consumption was 2.1MB. Max. memory is 16.1GB. [2022-02-20 18:11:43,341 INFO L158 Benchmark]: RCFGBuilder took 560.53ms. Allocated memory is still 96.5MB. Free memory was 55.0MB in the beginning and 37.9MB in the end (delta: 17.0MB). Peak memory consumption was 16.8MB. Max. memory is 16.1GB. [2022-02-20 18:11:43,341 INFO L158 Benchmark]: TraceAbstraction took 3170.50ms. Allocated memory was 96.5MB in the beginning and 125.8MB in the end (delta: 29.4MB). Free memory was 37.4MB in the beginning and 67.0MB in the end (delta: -29.6MB). Peak memory consumption was 2.6MB. Max. memory is 16.1GB. [2022-02-20 18:11:43,341 INFO L158 Benchmark]: Witness Printer took 55.15ms. Allocated memory is still 125.8MB. Free memory was 67.0MB in the beginning and 61.8MB in the end (delta: 5.2MB). Peak memory consumption was 4.2MB. Max. memory is 16.1GB. [2022-02-20 18:11:43,342 INFO L339 ainManager$Toolchain]: ####################### End [Toolchain 1] ####################### --- Results --- * Results from de.uni_freiburg.informatik.ultimate.core: - AssertionsEnabledResult: Assertions are enabled Assertions are enabled - StatisticsResult: Toolchain Benchmarks Benchmark results are: * CDTParser took 0.30ms. Allocated memory is still 96.5MB. Free memory is still 71.9MB. There was no memory consumed. Max. memory is 16.1GB. * CACSL2BoogieTranslator took 470.39ms. Allocated memory is still 96.5MB. Free memory was 54.5MB in the beginning and 59.3MB in the end (delta: -4.8MB). Peak memory consumption was 4.2MB. Max. memory is 16.1GB. * Boogie Procedure Inliner took 60.53ms. Allocated memory is still 96.5MB. Free memory was 59.3MB in the beginning and 56.5MB in the end (delta: 2.8MB). Peak memory consumption was 2.1MB. Max. memory is 16.1GB. * Boogie Preprocessor took 28.00ms. Allocated memory is still 96.5MB. Free memory was 56.5MB in the beginning and 55.2MB in the end (delta: 1.3MB). Peak memory consumption was 2.1MB. Max. memory is 16.1GB. * RCFGBuilder took 560.53ms. Allocated memory is still 96.5MB. Free memory was 55.0MB in the beginning and 37.9MB in the end (delta: 17.0MB). Peak memory consumption was 16.8MB. Max. memory is 16.1GB. * TraceAbstraction took 3170.50ms. Allocated memory was 96.5MB in the beginning and 125.8MB in the end (delta: 29.4MB). Free memory was 37.4MB in the beginning and 67.0MB in the end (delta: -29.6MB). Peak memory consumption was 2.6MB. Max. memory is 16.1GB. * Witness Printer took 55.15ms. Allocated memory is still 125.8MB. Free memory was 67.0MB in the beginning and 61.8MB in the end (delta: 5.2MB). Peak memory consumption was 4.2MB. Max. memory is 16.1GB. * Results from de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction: - StatisticsResult: ErrorAutomatonStatistics NumberErrorTraces: 0, NumberStatementsAllTraces: 0, NumberRelevantStatements: 0, 0.0s ErrorAutomatonConstructionTimeTotal, 0.0s FaulLocalizationTime, NumberStatementsFirstTrace: -1, TraceLengthAvg: 0, 0.0s ErrorAutomatonConstructionTimeAvg, 0.0s ErrorAutomatonDifferenceTimeAvg, 0.0s ErrorAutomatonDifferenceTimeTotal, NumberOfNoEnhancement: 0, NumberOfFiniteEnhancement: 0, NumberOfInfiniteEnhancement: 0 - PositiveResult [Line: 418]: call to reach_error is unreachable For all program executions holds that call to reach_error is unreachable at this location - StatisticsResult: Ultimate Automizer benchmark data CFG has 6 procedures, 73 locations, 1 error locations. Started 1 CEGAR loops. OverallTime: 3.1s, OverallIterations: 4, TraceHistogramMax: 2, PathProgramHistogramMax: 1, EmptinessCheckTime: 0.0s, AutomataDifference: 1.5s, DeadEndRemovalTime: 0.0s, HoareAnnotationTime: 0.2s, InitialAbstractionConstructionTime: 0.0s, PartialOrderReductionTime: 0.0s, HoareTripleCheckerStatistics: 0 mSolverCounterUnknown, 244 SdHoareTripleChecker+Valid, 0.1s IncrementalHoareTripleChecker+Time, 0 mSdLazyCounter, 240 mSDsluCounter, 765 SdHoareTripleChecker+Invalid, 0.1s Time, 0 mProtectedAction, 0 SdHoareTripleChecker+Unchecked, 0 IncrementalHoareTripleChecker+Unchecked, 471 mSDsCounter, 31 IncrementalHoareTripleChecker+Valid, 0 mProtectedPredicate, 100 IncrementalHoareTripleChecker+Invalid, 131 SdHoareTripleChecker+Unknown, 0 mSolverCounterNotChecked, 31 mSolverCounterUnsat, 294 mSDtfsCounter, 100 mSolverCounterSat, 0.0s SdHoareTripleChecker+Time, 0 IncrementalHoareTripleChecker+Unknown, PredicateUnifierStatistics: 0 DeclaredPredicates, 35 GetRequests, 21 SyntacticMatches, 0 SemanticMatches, 14 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 3 ImplicationChecksByTransitivity, 0.0s Time, 0.0s BasicInterpolantAutomatonTime, BiggestAbstraction: size=134occurred in iteration=3, InterpolantAutomatonStates: 17, traceCheckStatistics: No data available, InterpolantConsolidationStatistics: No data available, PathInvariantsStatistics: No data available, 0/0 InterpolantCoveringCapability, TotalInterpolationStatistics: No data available, 0.0s DumpTime, AutomataMinimizationStatistics: 0.2s AutomataMinimizationTime, 4 MinimizatonAttempts, 26 StatesRemovedByMinimization, 1 NontrivialMinimizations, HoareAnnotationStatistics: 0.0s HoareAnnotationTime, 33 LocationsWithAnnotation, 168 PreInvPairs, 205 NumberOfFragments, 131 HoareAnnotationTreeSize, 168 FomulaSimplifications, 45 FormulaSimplificationTreeSizeReduction, 0.1s HoareSimplificationTime, 33 FomulaSimplificationsInter, 545 FormulaSimplificationTreeSizeReductionInter, 0.1s HoareSimplificationTimeInter, RefinementEngineStatistics: TRACE_CHECK: 0.0s SsaConstructionTime, 0.2s SatisfiabilityAnalysisTime, 0.5s InterpolantComputationTime, 142 NumberOfCodeBlocks, 142 NumberOfCodeBlocksAsserted, 4 NumberOfCheckSat, 138 ConstructedInterpolants, 0 QuantifiedInterpolants, 270 SizeOfPredicates, 0 NumberOfNonLiveVariables, 0 ConjunctsInSsa, 0 ConjunctsInUnsatCore, 4 InterpolantComputations, 4 PerfectInterpolantSequences, 12/12 InterpolantCoveringCapability, INVARIANT_SYNTHESIS: No data available, INTERPOLANT_CONSOLIDATION: No data available, ABSTRACT_INTERPRETATION: No data available, PDR: No data available, ACCELERATED_INTERPOLATION: No data available, SIFA: No data available, ReuseStatistics: No data available - AllSpecificationsHoldResult: All specifications hold 1 specifications checked. All of them hold - InvariantResult [Line: 414]: Loop Invariant Derived loop invariant: !(pumpRunning == 0) - InvariantResult [Line: 62]: Loop Invariant Derived loop invariant: 1 - InvariantResult [Line: 141]: Loop Invariant Derived loop invariant: !(pumpRunning == 0) || !(0 == systemActive) - InvariantResult [Line: 54]: Loop Invariant Derived loop invariant: ((pumpRunning == 0 && tmp == systemActive) && 1 == systemActive) && \result == systemActive - InvariantResult [Line: 355]: Loop Invariant Derived loop invariant: pumpRunning == 0 && splverifierCounter == 0 - InvariantResult [Line: 238]: Loop Invariant Derived loop invariant: pumpRunning == 0 && splverifierCounter == 0 - InvariantResult [Line: 900]: Loop Invariant Derived loop invariant: pumpRunning == 0 && 1 == systemActive - InvariantResult [Line: 345]: Loop Invariant Derived loop invariant: 1 - InvariantResult [Line: 907]: Loop Invariant Derived loop invariant: pumpRunning == 0 && 1 == systemActive - InvariantResult [Line: 266]: Loop Invariant Derived loop invariant: !(pumpRunning == 0) - InvariantResult [Line: 499]: Loop Invariant Derived loop invariant: 1 - InvariantResult [Line: 174]: Loop Invariant Derived loop invariant: 0 - InvariantResult [Line: 72]: Loop Invariant Derived loop invariant: 1 - InvariantResult [Line: 334]: Loop Invariant Derived loop invariant: 1 - InvariantResult [Line: 478]: Loop Invariant Derived loop invariant: ((pumpRunning == 0 && tmp == systemActive) && 1 == systemActive) && \result == systemActive - InvariantResult [Line: 354]: Loop Invariant Derived loop invariant: 0 - InvariantResult [Line: 424]: Loop Invariant Derived loop invariant: 1 - InvariantResult [Line: 485]: Loop Invariant Derived loop invariant: 1 - InvariantResult [Line: 253]: Loop Invariant Derived loop invariant: (pumpRunning == 0 && 1 == systemActive) && splverifierCounter == 0 - InvariantResult [Line: 434]: Loop Invariant Derived loop invariant: 1 - InvariantResult [Line: 914]: Loop Invariant Derived loop invariant: (pumpRunning == 0 && 1 == systemActive) && \result == systemActive RESULT: Ultimate proved your program to be correct! [2022-02-20 18:11:43,386 INFO L540 MonitoredProcess]: [MP /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in -t:2000 (1)] Forceful destruction successful, exit code 0 Received shutdown request... --- End real Ultimate output --- Execution finished normally Writing output log to file Ultimate.log Result: TRUE