./Ultimate.py --spec ../sv-benchmarks/c/properties/unreach-call.prp --file ../sv-benchmarks/c/product-lines/minepump_spec5_product29.cil.c --full-output -ea --architecture 32bit -------------------------------------------------------------------------------- Checking for ERROR reachability Using default analysis Version 03d7b7b3 Calling Ultimate with: /usr/bin/java -Dosgi.configuration.area=/storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/data/config -Xmx15G -Xms4m -ea -jar /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/plugins/org.eclipse.equinox.launcher_1.5.800.v20200727-1323.jar -data @noDefault -ultimatedata /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/data -tc /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/config/AutomizerReach.xml -i ../sv-benchmarks/c/product-lines/minepump_spec5_product29.cil.c -s /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/config/svcomp-Reach-32bit-Automizer_Default.epf --cacsl2boogietranslator.entry.function main --witnessprinter.witness.directory /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux --witnessprinter.witness.filename witness.graphml --witnessprinter.write.witness.besides.input.file false --witnessprinter.graph.data.specification CHECK( init(main()), LTL(G ! call(reach_error())) ) --witnessprinter.graph.data.producer Automizer --witnessprinter.graph.data.architecture 32bit --witnessprinter.graph.data.programhash ccaa7fbdcb9338da1f8fd3ccb37732a1f2165a762a28b1457475bd920e3cf3c3 --- Real Ultimate output --- This is Ultimate 0.2.2-dev-03d7b7b [2022-02-20 18:11:51,427 INFO L177 SettingsManager]: Resetting all preferences to default values... [2022-02-20 18:11:51,429 INFO L181 SettingsManager]: Resetting UltimateCore preferences to default values [2022-02-20 18:11:51,456 INFO L184 SettingsManager]: Ultimate Commandline Interface provides no preferences, ignoring... [2022-02-20 18:11:51,457 INFO L181 SettingsManager]: Resetting Boogie Preprocessor preferences to default values [2022-02-20 18:11:51,458 INFO L181 SettingsManager]: Resetting Boogie Procedure Inliner preferences to default values [2022-02-20 18:11:51,459 INFO L181 SettingsManager]: Resetting Abstract Interpretation preferences to default values [2022-02-20 18:11:51,461 INFO L181 SettingsManager]: Resetting LassoRanker preferences to default values [2022-02-20 18:11:51,463 INFO L181 SettingsManager]: Resetting Reaching Definitions preferences to default values [2022-02-20 18:11:51,464 INFO L181 SettingsManager]: Resetting SyntaxChecker preferences to default values [2022-02-20 18:11:51,465 INFO L181 SettingsManager]: Resetting Sifa preferences to default values [2022-02-20 18:11:51,466 INFO L184 SettingsManager]: Büchi Program Product provides no preferences, ignoring... [2022-02-20 18:11:51,466 INFO L181 SettingsManager]: Resetting LTL2Aut preferences to default values [2022-02-20 18:11:51,467 INFO L181 SettingsManager]: Resetting PEA to Boogie preferences to default values [2022-02-20 18:11:51,468 INFO L181 SettingsManager]: Resetting BlockEncodingV2 preferences to default values [2022-02-20 18:11:51,469 INFO L181 SettingsManager]: Resetting ChcToBoogie preferences to default values [2022-02-20 18:11:51,470 INFO L181 SettingsManager]: Resetting AutomataScriptInterpreter preferences to default values [2022-02-20 18:11:51,470 INFO L181 SettingsManager]: Resetting BuchiAutomizer preferences to default values [2022-02-20 18:11:51,472 INFO L181 SettingsManager]: Resetting CACSL2BoogieTranslator preferences to default values [2022-02-20 18:11:51,474 INFO L181 SettingsManager]: Resetting CodeCheck preferences to default values [2022-02-20 18:11:51,475 INFO L181 SettingsManager]: Resetting InvariantSynthesis preferences to default values [2022-02-20 18:11:51,476 INFO L181 SettingsManager]: Resetting RCFGBuilder preferences to default values [2022-02-20 18:11:51,477 INFO L181 SettingsManager]: Resetting Referee preferences to default values [2022-02-20 18:11:51,478 INFO L181 SettingsManager]: Resetting TraceAbstraction preferences to default values [2022-02-20 18:11:51,481 INFO L184 SettingsManager]: TraceAbstractionConcurrent provides no preferences, ignoring... [2022-02-20 18:11:51,481 INFO L184 SettingsManager]: TraceAbstractionWithAFAs provides no preferences, ignoring... [2022-02-20 18:11:51,482 INFO L181 SettingsManager]: Resetting TreeAutomizer preferences to default values [2022-02-20 18:11:51,483 INFO L181 SettingsManager]: Resetting IcfgToChc preferences to default values [2022-02-20 18:11:51,483 INFO L181 SettingsManager]: Resetting IcfgTransformer preferences to default values [2022-02-20 18:11:51,484 INFO L184 SettingsManager]: ReqToTest provides no preferences, ignoring... [2022-02-20 18:11:51,484 INFO L181 SettingsManager]: Resetting Boogie Printer preferences to default values [2022-02-20 18:11:51,485 INFO L181 SettingsManager]: Resetting ChcSmtPrinter preferences to default values [2022-02-20 18:11:51,486 INFO L181 SettingsManager]: Resetting ReqPrinter preferences to default values [2022-02-20 18:11:51,487 INFO L181 SettingsManager]: Resetting Witness Printer preferences to default values [2022-02-20 18:11:51,488 INFO L184 SettingsManager]: Boogie PL CUP Parser provides no preferences, ignoring... [2022-02-20 18:11:51,488 INFO L181 SettingsManager]: Resetting CDTParser preferences to default values [2022-02-20 18:11:51,489 INFO L184 SettingsManager]: AutomataScriptParser provides no preferences, ignoring... [2022-02-20 18:11:51,489 INFO L184 SettingsManager]: ReqParser provides no preferences, ignoring... [2022-02-20 18:11:51,489 INFO L181 SettingsManager]: Resetting SmtParser preferences to default values [2022-02-20 18:11:51,490 INFO L181 SettingsManager]: Resetting Witness Parser preferences to default values [2022-02-20 18:11:51,491 INFO L188 SettingsManager]: Finished resetting all preferences to default values... [2022-02-20 18:11:51,491 INFO L101 SettingsManager]: Beginning loading settings from /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/config/svcomp-Reach-32bit-Automizer_Default.epf [2022-02-20 18:11:51,513 INFO L113 SettingsManager]: Loading preferences was successful [2022-02-20 18:11:51,514 INFO L115 SettingsManager]: Preferences different from defaults after loading the file: [2022-02-20 18:11:51,514 INFO L136 SettingsManager]: Preferences of UltimateCore differ from their defaults: [2022-02-20 18:11:51,514 INFO L138 SettingsManager]: * Log level for class=de.uni_freiburg.informatik.ultimate.lib.smtlibutils.quantifier.QuantifierPusher=ERROR; [2022-02-20 18:11:51,515 INFO L136 SettingsManager]: Preferences of Boogie Procedure Inliner differ from their defaults: [2022-02-20 18:11:51,515 INFO L138 SettingsManager]: * Ignore calls to procedures called more than once=ONLY_FOR_SEQUENTIAL_PROGRAMS [2022-02-20 18:11:51,516 INFO L136 SettingsManager]: Preferences of BlockEncodingV2 differ from their defaults: [2022-02-20 18:11:51,516 INFO L138 SettingsManager]: * Create parallel compositions if possible=false [2022-02-20 18:11:51,516 INFO L138 SettingsManager]: * Use SBE=true [2022-02-20 18:11:51,517 INFO L136 SettingsManager]: Preferences of CACSL2BoogieTranslator differ from their defaults: [2022-02-20 18:11:51,517 INFO L138 SettingsManager]: * sizeof long=4 [2022-02-20 18:11:51,517 INFO L138 SettingsManager]: * Overapproximate operations on floating types=true [2022-02-20 18:11:51,517 INFO L138 SettingsManager]: * sizeof POINTER=4 [2022-02-20 18:11:51,517 INFO L138 SettingsManager]: * Check division by zero=IGNORE [2022-02-20 18:11:51,518 INFO L138 SettingsManager]: * Pointer to allocated memory at dereference=IGNORE [2022-02-20 18:11:51,518 INFO L138 SettingsManager]: * If two pointers are subtracted or compared they have the same base address=IGNORE [2022-02-20 18:11:51,518 INFO L138 SettingsManager]: * Check array bounds for arrays that are off heap=IGNORE [2022-02-20 18:11:51,518 INFO L138 SettingsManager]: * sizeof long double=12 [2022-02-20 18:11:51,518 INFO L138 SettingsManager]: * Check if freed pointer was valid=false [2022-02-20 18:11:51,519 INFO L138 SettingsManager]: * Use constant arrays=true [2022-02-20 18:11:51,519 INFO L138 SettingsManager]: * Pointer base address is valid at dereference=IGNORE [2022-02-20 18:11:51,519 INFO L136 SettingsManager]: Preferences of RCFGBuilder differ from their defaults: [2022-02-20 18:11:51,519 INFO L138 SettingsManager]: * Size of a code block=SequenceOfStatements [2022-02-20 18:11:51,520 INFO L138 SettingsManager]: * SMT solver=External_DefaultMode [2022-02-20 18:11:51,520 INFO L138 SettingsManager]: * Command for external solver=z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in -t:2000 [2022-02-20 18:11:51,520 INFO L136 SettingsManager]: Preferences of TraceAbstraction differ from their defaults: [2022-02-20 18:11:51,520 INFO L138 SettingsManager]: * Compute Interpolants along a Counterexample=FPandBP [2022-02-20 18:11:51,521 INFO L138 SettingsManager]: * Positions where we compute the Hoare Annotation=LoopsAndPotentialCycles [2022-02-20 18:11:51,521 INFO L138 SettingsManager]: * Trace refinement strategy=CAMEL [2022-02-20 18:11:51,521 INFO L138 SettingsManager]: * Command for external solver=z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in [2022-02-20 18:11:51,521 INFO L138 SettingsManager]: * Large block encoding in concurrent analysis=OFF [2022-02-20 18:11:51,521 INFO L138 SettingsManager]: * Automaton type used in concurrency analysis=PETRI_NET [2022-02-20 18:11:51,522 INFO L138 SettingsManager]: * Compute Hoare Annotation of negated interpolant automaton, abstraction and CFG=true [2022-02-20 18:11:51,522 INFO L138 SettingsManager]: * SMT solver=External_ModelsAndUnsatCoreMode WARNING: An illegal reflective access operation has occurred WARNING: Illegal reflective access by com.sun.xml.bind.v2.runtime.reflect.opt.Injector$1 (file:/storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/plugins/com.sun.xml.bind_2.2.0.v201505121915.jar) to method java.lang.ClassLoader.defineClass(java.lang.String,byte[],int,int) WARNING: Please consider reporting this to the maintainers of com.sun.xml.bind.v2.runtime.reflect.opt.Injector$1 WARNING: Use --illegal-access=warn to enable warnings of further illegal reflective access operations WARNING: All illegal access operations will be denied in a future release Applying setting for plugin de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator: Entry function -> main Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Witness directory -> /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Witness filename -> witness.graphml Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Write witness besides input file -> false Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Graph data specification -> CHECK( init(main()), LTL(G ! call(reach_error())) ) Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Graph data producer -> Automizer Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Graph data architecture -> 32bit Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Graph data programhash -> ccaa7fbdcb9338da1f8fd3ccb37732a1f2165a762a28b1457475bd920e3cf3c3 [2022-02-20 18:11:51,739 INFO L75 nceAwareModelManager]: Repository-Root is: /tmp [2022-02-20 18:11:51,766 INFO L261 ainManager$Toolchain]: [Toolchain 1]: Applicable parser(s) successfully (re)initialized [2022-02-20 18:11:51,769 INFO L217 ainManager$Toolchain]: [Toolchain 1]: Toolchain selected. [2022-02-20 18:11:51,770 INFO L271 PluginConnector]: Initializing CDTParser... [2022-02-20 18:11:51,770 INFO L275 PluginConnector]: CDTParser initialized [2022-02-20 18:11:51,771 INFO L432 ainManager$Toolchain]: [Toolchain 1]: Parsing single file: /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/../sv-benchmarks/c/product-lines/minepump_spec5_product29.cil.c [2022-02-20 18:11:51,842 INFO L220 CDTParser]: Created temporary CDT project at /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/data/7fe88f60e/3ae8dad89f804f759fd34f69f682a782/FLAG5232ae5f5 [2022-02-20 18:11:52,244 INFO L306 CDTParser]: Found 1 translation units. [2022-02-20 18:11:52,245 INFO L160 CDTParser]: Scanning /storage/repos/ultimate/releaseScripts/default/sv-benchmarks/c/product-lines/minepump_spec5_product29.cil.c [2022-02-20 18:11:52,262 INFO L349 CDTParser]: About to delete temporary CDT project at /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/data/7fe88f60e/3ae8dad89f804f759fd34f69f682a782/FLAG5232ae5f5 [2022-02-20 18:11:52,625 INFO L357 CDTParser]: Successfully deleted /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/data/7fe88f60e/3ae8dad89f804f759fd34f69f682a782 [2022-02-20 18:11:52,627 INFO L299 ainManager$Toolchain]: ####################### [Toolchain 1] ####################### [2022-02-20 18:11:52,630 INFO L131 ToolchainWalker]: Walking toolchain with 6 elements. [2022-02-20 18:11:52,633 INFO L113 PluginConnector]: ------------------------CACSL2BoogieTranslator---------------------------- [2022-02-20 18:11:52,633 INFO L271 PluginConnector]: Initializing CACSL2BoogieTranslator... [2022-02-20 18:11:52,636 INFO L275 PluginConnector]: CACSL2BoogieTranslator initialized [2022-02-20 18:11:52,637 INFO L185 PluginConnector]: Executing the observer ACSLObjectContainerObserver from plugin CACSL2BoogieTranslator for "CDTParser AST 20.02 06:11:52" (1/1) ... [2022-02-20 18:11:52,638 INFO L205 PluginConnector]: Invalid model from CACSL2BoogieTranslator for observer de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator.ACSLObjectContainerObserver@229e3791 and model type de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 20.02 06:11:52, skipping insertion in model container [2022-02-20 18:11:52,638 INFO L185 PluginConnector]: Executing the observer CACSL2BoogieTranslatorObserver from plugin CACSL2BoogieTranslator for "CDTParser AST 20.02 06:11:52" (1/1) ... [2022-02-20 18:11:52,645 INFO L145 MainTranslator]: Starting translation in SV-COMP mode [2022-02-20 18:11:52,693 INFO L178 MainTranslator]: Built tables and reachable declarations [2022-02-20 18:11:52,878 WARN L230 ndardFunctionHandler]: Function reach_error is already implemented but we override the implementation for the call at /storage/repos/ultimate/releaseScripts/default/sv-benchmarks/c/product-lines/minepump_spec5_product29.cil.c[2141,2154] [2022-02-20 18:11:53,026 INFO L210 PostProcessor]: Analyzing one entry point: main [2022-02-20 18:11:53,035 INFO L203 MainTranslator]: Completed pre-run [2022-02-20 18:11:53,062 WARN L230 ndardFunctionHandler]: Function reach_error is already implemented but we override the implementation for the call at /storage/repos/ultimate/releaseScripts/default/sv-benchmarks/c/product-lines/minepump_spec5_product29.cil.c[2141,2154] [2022-02-20 18:11:53,133 INFO L210 PostProcessor]: Analyzing one entry point: main [2022-02-20 18:11:53,162 INFO L208 MainTranslator]: Completed translation [2022-02-20 18:11:53,163 INFO L202 PluginConnector]: Adding new model de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 20.02 06:11:53 WrapperNode [2022-02-20 18:11:53,163 INFO L132 PluginConnector]: ------------------------ END CACSL2BoogieTranslator---------------------------- [2022-02-20 18:11:53,164 INFO L113 PluginConnector]: ------------------------Boogie Procedure Inliner---------------------------- [2022-02-20 18:11:53,164 INFO L271 PluginConnector]: Initializing Boogie Procedure Inliner... [2022-02-20 18:11:53,165 INFO L275 PluginConnector]: Boogie Procedure Inliner initialized [2022-02-20 18:11:53,172 INFO L185 PluginConnector]: Executing the observer TypeChecker from plugin Boogie Procedure Inliner for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 20.02 06:11:53" (1/1) ... [2022-02-20 18:11:53,196 INFO L185 PluginConnector]: Executing the observer Inliner from plugin Boogie Procedure Inliner for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 20.02 06:11:53" (1/1) ... [2022-02-20 18:11:53,239 INFO L137 Inliner]: procedures = 56, calls = 158, calls flagged for inlining = 22, calls inlined = 18, statements flattened = 248 [2022-02-20 18:11:53,239 INFO L132 PluginConnector]: ------------------------ END Boogie Procedure Inliner---------------------------- [2022-02-20 18:11:53,240 INFO L113 PluginConnector]: ------------------------Boogie Preprocessor---------------------------- [2022-02-20 18:11:53,241 INFO L271 PluginConnector]: Initializing Boogie Preprocessor... [2022-02-20 18:11:53,241 INFO L275 PluginConnector]: Boogie Preprocessor initialized [2022-02-20 18:11:53,248 INFO L185 PluginConnector]: Executing the observer EnsureBoogieModelObserver from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 20.02 06:11:53" (1/1) ... [2022-02-20 18:11:53,249 INFO L185 PluginConnector]: Executing the observer TypeChecker from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 20.02 06:11:53" (1/1) ... [2022-02-20 18:11:53,264 INFO L185 PluginConnector]: Executing the observer ConstExpander from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 20.02 06:11:53" (1/1) ... [2022-02-20 18:11:53,267 INFO L185 PluginConnector]: Executing the observer StructExpander from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 20.02 06:11:53" (1/1) ... [2022-02-20 18:11:53,273 INFO L185 PluginConnector]: Executing the observer UnstructureCode from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 20.02 06:11:53" (1/1) ... [2022-02-20 18:11:53,289 INFO L185 PluginConnector]: Executing the observer FunctionInliner from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 20.02 06:11:53" (1/1) ... [2022-02-20 18:11:53,290 INFO L185 PluginConnector]: Executing the observer BoogieSymbolTableConstructor from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 20.02 06:11:53" (1/1) ... [2022-02-20 18:11:53,292 INFO L132 PluginConnector]: ------------------------ END Boogie Preprocessor---------------------------- [2022-02-20 18:11:53,293 INFO L113 PluginConnector]: ------------------------RCFGBuilder---------------------------- [2022-02-20 18:11:53,293 INFO L271 PluginConnector]: Initializing RCFGBuilder... [2022-02-20 18:11:53,293 INFO L275 PluginConnector]: RCFGBuilder initialized [2022-02-20 18:11:53,294 INFO L185 PluginConnector]: Executing the observer RCFGBuilderObserver from plugin RCFGBuilder for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 20.02 06:11:53" (1/1) ... [2022-02-20 18:11:53,304 INFO L173 SolverBuilder]: Constructing external solver with command: z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in -t:2000 [2022-02-20 18:11:53,315 INFO L189 MonitoredProcess]: No working directory specified, using /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 [2022-02-20 18:11:53,327 INFO L229 MonitoredProcess]: Starting monitored process 1 with /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in -t:2000 (exit command is (exit), workingDir is null) [2022-02-20 18:11:53,330 INFO L327 MonitoredProcess]: [MP /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in -t:2000 (1)] Waiting until timeout for monitored process [2022-02-20 18:11:53,363 INFO L130 BoogieDeclarations]: Found specification of procedure #Ultimate.allocInit [2022-02-20 18:11:53,364 INFO L130 BoogieDeclarations]: Found specification of procedure processEnvironment__wrappee__base [2022-02-20 18:11:53,364 INFO L138 BoogieDeclarations]: Found implementation of procedure processEnvironment__wrappee__base [2022-02-20 18:11:53,364 INFO L130 BoogieDeclarations]: Found specification of procedure timeShift [2022-02-20 18:11:53,364 INFO L138 BoogieDeclarations]: Found implementation of procedure timeShift [2022-02-20 18:11:53,364 INFO L130 BoogieDeclarations]: Found specification of procedure cleanup [2022-02-20 18:11:53,364 INFO L138 BoogieDeclarations]: Found implementation of procedure cleanup [2022-02-20 18:11:53,365 INFO L130 BoogieDeclarations]: Found specification of procedure waterRise [2022-02-20 18:11:53,365 INFO L138 BoogieDeclarations]: Found implementation of procedure waterRise [2022-02-20 18:11:53,365 INFO L130 BoogieDeclarations]: Found specification of procedure processEnvironment__wrappee__methaneQuery [2022-02-20 18:11:53,365 INFO L138 BoogieDeclarations]: Found implementation of procedure processEnvironment__wrappee__methaneQuery [2022-02-20 18:11:53,366 INFO L130 BoogieDeclarations]: Found specification of procedure isPumpRunning [2022-02-20 18:11:53,366 INFO L138 BoogieDeclarations]: Found implementation of procedure isPumpRunning [2022-02-20 18:11:53,366 INFO L130 BoogieDeclarations]: Found specification of procedure isMethaneAlarm [2022-02-20 18:11:53,366 INFO L138 BoogieDeclarations]: Found implementation of procedure isMethaneAlarm [2022-02-20 18:11:53,366 INFO L130 BoogieDeclarations]: Found specification of procedure deactivatePump [2022-02-20 18:11:53,366 INFO L138 BoogieDeclarations]: Found implementation of procedure deactivatePump [2022-02-20 18:11:53,367 INFO L130 BoogieDeclarations]: Found specification of procedure write~init~int [2022-02-20 18:11:53,367 INFO L130 BoogieDeclarations]: Found specification of procedure changeMethaneLevel [2022-02-20 18:11:53,367 INFO L138 BoogieDeclarations]: Found implementation of procedure changeMethaneLevel [2022-02-20 18:11:53,367 INFO L130 BoogieDeclarations]: Found specification of procedure ULTIMATE.start [2022-02-20 18:11:53,367 INFO L138 BoogieDeclarations]: Found implementation of procedure ULTIMATE.start [2022-02-20 18:11:53,446 INFO L234 CfgBuilder]: Building ICFG [2022-02-20 18:11:53,447 INFO L260 CfgBuilder]: Building CFG for each procedure with an implementation [2022-02-20 18:11:53,828 INFO L275 CfgBuilder]: Performing block encoding [2022-02-20 18:11:53,836 INFO L294 CfgBuilder]: Using the 1 location(s) as analysis (start of procedure ULTIMATE.start) [2022-02-20 18:11:53,836 INFO L299 CfgBuilder]: Removed 2 assume(true) statements. [2022-02-20 18:11:53,838 INFO L202 PluginConnector]: Adding new model de.uni_freiburg.informatik.ultimate.plugins.generator.rcfgbuilder CFG 20.02 06:11:53 BoogieIcfgContainer [2022-02-20 18:11:53,838 INFO L132 PluginConnector]: ------------------------ END RCFGBuilder---------------------------- [2022-02-20 18:11:53,840 INFO L113 PluginConnector]: ------------------------TraceAbstraction---------------------------- [2022-02-20 18:11:53,840 INFO L271 PluginConnector]: Initializing TraceAbstraction... [2022-02-20 18:11:53,842 INFO L275 PluginConnector]: TraceAbstraction initialized [2022-02-20 18:11:53,843 INFO L185 PluginConnector]: Executing the observer TraceAbstractionObserver from plugin TraceAbstraction for "CDTParser AST 20.02 06:11:52" (1/3) ... [2022-02-20 18:11:53,844 INFO L205 PluginConnector]: Invalid model from TraceAbstraction for observer de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction.TraceAbstractionObserver@771dafc2 and model type de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction AST 20.02 06:11:53, skipping insertion in model container [2022-02-20 18:11:53,844 INFO L185 PluginConnector]: Executing the observer TraceAbstractionObserver from plugin TraceAbstraction for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 20.02 06:11:53" (2/3) ... [2022-02-20 18:11:53,844 INFO L205 PluginConnector]: Invalid model from TraceAbstraction for observer de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction.TraceAbstractionObserver@771dafc2 and model type de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction AST 20.02 06:11:53, skipping insertion in model container [2022-02-20 18:11:53,844 INFO L185 PluginConnector]: Executing the observer TraceAbstractionObserver from plugin TraceAbstraction for "de.uni_freiburg.informatik.ultimate.plugins.generator.rcfgbuilder CFG 20.02 06:11:53" (3/3) ... [2022-02-20 18:11:53,846 INFO L111 eAbstractionObserver]: Analyzing ICFG minepump_spec5_product29.cil.c [2022-02-20 18:11:53,851 INFO L205 ceAbstractionStarter]: Automizer settings: Hoare:true NWA Interpolation:FPandBP Determinization: PREDICATE_ABSTRACTION [2022-02-20 18:11:53,851 INFO L164 ceAbstractionStarter]: Applying trace abstraction to program that has 1 error locations. [2022-02-20 18:11:53,893 INFO L338 AbstractCegarLoop]: ======== Iteration 0 == of CEGAR loop == AllErrorsAtOnce ======== [2022-02-20 18:11:53,898 INFO L339 AbstractCegarLoop]: Settings: SEPARATE_VIOLATION_CHECK=true, mInterprocedural=true, mMaxIterations=1000000, mWatchIteration=1000000, mArtifact=RCFG, mInterpolation=FPandBP, mInterpolantAutomaton=STRAIGHT_LINE, mDumpAutomata=false, mAutomataFormat=ATS_NUMERATE, mDumpPath=., mDeterminiation=PREDICATE_ABSTRACTION, mMinimize=MINIMIZE_SEVPA, mHoare=true, mAutomataTypeConcurrency=PETRI_NET, mHoareTripleChecks=INCREMENTAL, mHoareAnnotationPositions=LoopsAndPotentialCycles, mDumpOnlyReuseAutomata=false, mLimitTraceHistogram=0, mErrorLocTimeLimit=0, mLimitPathProgramCount=0, mCollectInterpolantStatistics=true, mHeuristicEmptinessCheck=false, mHeuristicEmptinessCheckAStarHeuristic=ZERO, mHeuristicEmptinessCheckAStarHeuristicRandomSeed=1337, mHeuristicEmptinessCheckSmtFeatureScoringMethod=DAGSIZE, mSMTFeatureExtraction=false, mSMTFeatureExtractionDumpPath=., mOverrideInterpolantAutomaton=false, mMcrInterpolantMethod=WP, mLoopAccelerationTechnique=FAST_UPR [2022-02-20 18:11:53,898 INFO L340 AbstractCegarLoop]: Starting to check reachability of 1 error locations. [2022-02-20 18:11:53,922 INFO L276 IsEmpty]: Start isEmpty. Operand has 96 states, 70 states have (on average 1.3571428571428572) internal successors, (95), 78 states have internal predecessors, (95), 15 states have call successors, (15), 9 states have call predecessors, (15), 9 states have return successors, (15), 11 states have call predecessors, (15), 15 states have call successors, (15) [2022-02-20 18:11:53,996 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 33 [2022-02-20 18:11:53,996 INFO L506 BasicCegarLoop]: Found error trace [2022-02-20 18:11:53,997 INFO L514 BasicCegarLoop]: trace histogram [2, 2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-02-20 18:11:53,998 INFO L402 AbstractCegarLoop]: === Iteration 1 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2022-02-20 18:11:54,005 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2022-02-20 18:11:54,005 INFO L85 PathProgramCache]: Analyzing trace with hash 162796435, now seen corresponding path program 1 times [2022-02-20 18:11:54,014 INFO L126 FreeRefinementEngine]: Executing refinement strategy CAMEL [2022-02-20 18:11:54,014 INFO L338 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [395089062] [2022-02-20 18:11:54,015 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-02-20 18:11:54,015 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2022-02-20 18:11:54,152 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-02-20 18:11:54,253 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 13 [2022-02-20 18:11:54,260 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-02-20 18:11:54,277 INFO L290 TraceCheckUtils]: 0: Hoare triple {99#true} havoc ~retValue_acc~7;~retValue_acc~7 := ~pumpRunning~0;#res := ~retValue_acc~7; {99#true} is VALID [2022-02-20 18:11:54,278 INFO L290 TraceCheckUtils]: 1: Hoare triple {99#true} assume true; {99#true} is VALID [2022-02-20 18:11:54,279 INFO L284 TraceCheckUtils]: 2: Hoare quadruple {99#true} {100#false} #229#return; {100#false} is VALID [2022-02-20 18:11:54,280 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 24 [2022-02-20 18:11:54,287 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-02-20 18:11:54,296 INFO L290 TraceCheckUtils]: 0: Hoare triple {99#true} havoc ~retValue_acc~7;~retValue_acc~7 := ~pumpRunning~0;#res := ~retValue_acc~7; {99#true} is VALID [2022-02-20 18:11:54,297 INFO L290 TraceCheckUtils]: 1: Hoare triple {99#true} assume true; {99#true} is VALID [2022-02-20 18:11:54,297 INFO L284 TraceCheckUtils]: 2: Hoare quadruple {99#true} {100#false} #239#return; {100#false} is VALID [2022-02-20 18:11:54,303 INFO L290 TraceCheckUtils]: 0: Hoare triple {99#true} assume { :begin_inline_ULTIMATE.init } true;#NULL.base, #NULL.offset := 0, 0;assume 0 == #valid[0];assume 0 < #StackHeapBarrier;call #Ultimate.allocInit(2, 1);call write~init~int(48, 1, 0, 1);call write~init~int(0, 1, 1, 1);call #Ultimate.allocInit(31, 2);call #Ultimate.allocInit(12, 3);call #Ultimate.allocInit(13, 4);call #Ultimate.allocInit(7, 5);call write~init~int(44, 5, 0, 1);call write~init~int(77, 5, 1, 1);call write~init~int(101, 5, 2, 1);call write~init~int(116, 5, 3, 1);call write~init~int(104, 5, 4, 1);call write~init~int(58, 5, 5, 1);call write~init~int(0, 5, 6, 1);call #Ultimate.allocInit(5, 6);call write~init~int(67, 6, 0, 1);call write~init~int(82, 6, 1, 1);call write~init~int(73, 6, 2, 1);call write~init~int(84, 6, 3, 1);call write~init~int(0, 6, 4, 1);call #Ultimate.allocInit(3, 7);call write~init~int(79, 7, 0, 1);call write~init~int(75, 7, 1, 1);call write~init~int(0, 7, 2, 1);call #Ultimate.allocInit(2, 8);call write~init~int(41, 8, 0, 1);call write~init~int(0, 8, 1, 1);call #Ultimate.allocInit(13, 9);call #Ultimate.allocInit(3, 10);call write~init~int(79, 10, 0, 1);call write~init~int(110, 10, 1, 1);call write~init~int(0, 10, 2, 1);call #Ultimate.allocInit(4, 11);call write~init~int(79, 11, 0, 1);call write~init~int(102, 11, 1, 1);call write~init~int(102, 11, 2, 1);call write~init~int(0, 11, 3, 1);call #Ultimate.allocInit(7, 12);call write~init~int(44, 12, 0, 1);call write~init~int(80, 12, 1, 1);call write~init~int(117, 12, 2, 1);call write~init~int(109, 12, 3, 1);call write~init~int(112, 12, 4, 1);call write~init~int(58, 12, 5, 1);call write~init~int(0, 12, 6, 1);call #Ultimate.allocInit(3, 13);call write~init~int(79, 13, 0, 1);call write~init~int(110, 13, 1, 1);call write~init~int(0, 13, 2, 1);call #Ultimate.allocInit(4, 14);call write~init~int(79, 14, 0, 1);call write~init~int(102, 14, 1, 1);call write~init~int(102, 14, 2, 1);call write~init~int(0, 14, 3, 1);call #Ultimate.allocInit(3, 15);call write~init~int(41, 15, 0, 1);call write~init~int(32, 15, 1, 1);call write~init~int(0, 15, 2, 1);call #Ultimate.allocInit(2, 16);call write~init~int(10, 16, 0, 1);call write~init~int(0, 16, 1, 1);call #Ultimate.allocInit(30, 17);call #Ultimate.allocInit(9, 18);call #Ultimate.allocInit(21, 19);call #Ultimate.allocInit(30, 20);call #Ultimate.allocInit(9, 21);call #Ultimate.allocInit(21, 22);call #Ultimate.allocInit(30, 23);call #Ultimate.allocInit(9, 24);call #Ultimate.allocInit(25, 25);call #Ultimate.allocInit(30, 26);call #Ultimate.allocInit(9, 27);call #Ultimate.allocInit(25, 28);~waterLevel~0 := 1;~methaneLevelCritical~0 := 0;~cleanupTimeShifts~0 := 4;~pumpRunning~0 := 0;~systemActive~0 := 1;~head~0.base, ~head~0.offset := 0, 0;~switchedOnBeforeTS~0 := 0; {99#true} is VALID [2022-02-20 18:11:54,303 INFO L290 TraceCheckUtils]: 1: Hoare triple {99#true} assume { :end_inline_ULTIMATE.init } true;assume { :begin_inline_main } true;havoc main_#res#1;havoc main_#t~ret10#1, main_~retValue_acc~5#1, main_~tmp~0#1;havoc main_~retValue_acc~5#1;havoc main_~tmp~0#1;assume { :begin_inline_select_helpers } true; {99#true} is VALID [2022-02-20 18:11:54,303 INFO L290 TraceCheckUtils]: 2: Hoare triple {99#true} assume { :end_inline_select_helpers } true;assume { :begin_inline_select_features } true; {99#true} is VALID [2022-02-20 18:11:54,304 INFO L290 TraceCheckUtils]: 3: Hoare triple {99#true} assume { :end_inline_select_features } true;assume { :begin_inline_valid_product } true;havoc valid_product_#res#1;havoc valid_product_~retValue_acc~1#1;havoc valid_product_~retValue_acc~1#1;valid_product_~retValue_acc~1#1 := 1;valid_product_#res#1 := valid_product_~retValue_acc~1#1; {99#true} is VALID [2022-02-20 18:11:54,304 INFO L290 TraceCheckUtils]: 4: Hoare triple {99#true} main_#t~ret10#1 := valid_product_#res#1;assume { :end_inline_valid_product } true;assume -2147483648 <= main_#t~ret10#1 && main_#t~ret10#1 <= 2147483647;main_~tmp~0#1 := main_#t~ret10#1;havoc main_#t~ret10#1; {99#true} is VALID [2022-02-20 18:11:54,304 INFO L290 TraceCheckUtils]: 5: Hoare triple {99#true} assume 0 != main_~tmp~0#1;assume { :begin_inline_setup } true; {99#true} is VALID [2022-02-20 18:11:54,304 INFO L290 TraceCheckUtils]: 6: Hoare triple {99#true} assume { :end_inline_setup } true;assume { :begin_inline_runTest } true;assume { :begin_inline___utac_acc__Specification5_spec__1 } true;~switchedOnBeforeTS~0 := 0; {99#true} is VALID [2022-02-20 18:11:54,305 INFO L290 TraceCheckUtils]: 7: Hoare triple {99#true} assume { :end_inline___utac_acc__Specification5_spec__1 } true;assume { :begin_inline_test } true;havoc test_#t~nondet24#1, test_#t~nondet25#1, test_#t~nondet26#1, test_#t~nondet27#1, test_~splverifierCounter~0#1, test_~tmp~5#1, test_~tmp___0~1#1, test_~tmp___1~0#1, test_~tmp___2~0#1;havoc test_~splverifierCounter~0#1;havoc test_~tmp~5#1;havoc test_~tmp___0~1#1;havoc test_~tmp___1~0#1;havoc test_~tmp___2~0#1;test_~splverifierCounter~0#1 := 0; {99#true} is VALID [2022-02-20 18:11:54,307 INFO L290 TraceCheckUtils]: 8: Hoare triple {99#true} assume false; {100#false} is VALID [2022-02-20 18:11:54,307 INFO L272 TraceCheckUtils]: 9: Hoare triple {100#false} call cleanup(); {100#false} is VALID [2022-02-20 18:11:54,308 INFO L290 TraceCheckUtils]: 10: Hoare triple {100#false} havoc ~i~0;havoc ~__cil_tmp2~0; {100#false} is VALID [2022-02-20 18:11:54,308 INFO L272 TraceCheckUtils]: 11: Hoare triple {100#false} call timeShift(); {100#false} is VALID [2022-02-20 18:11:54,308 INFO L290 TraceCheckUtils]: 12: Hoare triple {100#false} assume { :begin_inline___utac_acc__Specification5_spec__2 } true;havoc __utac_acc__Specification5_spec__2_#t~ret51#1; {100#false} is VALID [2022-02-20 18:11:54,308 INFO L272 TraceCheckUtils]: 13: Hoare triple {100#false} call __utac_acc__Specification5_spec__2_#t~ret51#1 := isPumpRunning(); {99#true} is VALID [2022-02-20 18:11:54,308 INFO L290 TraceCheckUtils]: 14: Hoare triple {99#true} havoc ~retValue_acc~7;~retValue_acc~7 := ~pumpRunning~0;#res := ~retValue_acc~7; {99#true} is VALID [2022-02-20 18:11:54,309 INFO L290 TraceCheckUtils]: 15: Hoare triple {99#true} assume true; {99#true} is VALID [2022-02-20 18:11:54,310 INFO L284 TraceCheckUtils]: 16: Hoare quadruple {99#true} {100#false} #229#return; {100#false} is VALID [2022-02-20 18:11:54,310 INFO L290 TraceCheckUtils]: 17: Hoare triple {100#false} assume -2147483648 <= __utac_acc__Specification5_spec__2_#t~ret51#1 && __utac_acc__Specification5_spec__2_#t~ret51#1 <= 2147483647;~switchedOnBeforeTS~0 := __utac_acc__Specification5_spec__2_#t~ret51#1;havoc __utac_acc__Specification5_spec__2_#t~ret51#1; {100#false} is VALID [2022-02-20 18:11:54,310 INFO L290 TraceCheckUtils]: 18: Hoare triple {100#false} assume { :end_inline___utac_acc__Specification5_spec__2 } true; {100#false} is VALID [2022-02-20 18:11:54,310 INFO L290 TraceCheckUtils]: 19: Hoare triple {100#false} assume !(0 != ~pumpRunning~0); {100#false} is VALID [2022-02-20 18:11:54,311 INFO L290 TraceCheckUtils]: 20: Hoare triple {100#false} assume !(0 != ~systemActive~0); {100#false} is VALID [2022-02-20 18:11:54,311 INFO L290 TraceCheckUtils]: 21: Hoare triple {100#false} assume { :begin_inline___utac_acc__Specification5_spec__3 } true;havoc __utac_acc__Specification5_spec__3_#t~ret52#1, __utac_acc__Specification5_spec__3_#t~ret53#1, __utac_acc__Specification5_spec__3_~tmp~9#1, __utac_acc__Specification5_spec__3_~tmp___0~2#1;havoc __utac_acc__Specification5_spec__3_~tmp~9#1;havoc __utac_acc__Specification5_spec__3_~tmp___0~2#1;assume { :begin_inline_getWaterLevel } true;havoc getWaterLevel_#res#1;havoc getWaterLevel_~retValue_acc~3#1;havoc getWaterLevel_~retValue_acc~3#1;getWaterLevel_~retValue_acc~3#1 := ~waterLevel~0;getWaterLevel_#res#1 := getWaterLevel_~retValue_acc~3#1; {100#false} is VALID [2022-02-20 18:11:54,311 INFO L290 TraceCheckUtils]: 22: Hoare triple {100#false} __utac_acc__Specification5_spec__3_#t~ret52#1 := getWaterLevel_#res#1;assume { :end_inline_getWaterLevel } true;assume -2147483648 <= __utac_acc__Specification5_spec__3_#t~ret52#1 && __utac_acc__Specification5_spec__3_#t~ret52#1 <= 2147483647;__utac_acc__Specification5_spec__3_~tmp~9#1 := __utac_acc__Specification5_spec__3_#t~ret52#1;havoc __utac_acc__Specification5_spec__3_#t~ret52#1; {100#false} is VALID [2022-02-20 18:11:54,311 INFO L290 TraceCheckUtils]: 23: Hoare triple {100#false} assume 2 != __utac_acc__Specification5_spec__3_~tmp~9#1; {100#false} is VALID [2022-02-20 18:11:54,311 INFO L272 TraceCheckUtils]: 24: Hoare triple {100#false} call __utac_acc__Specification5_spec__3_#t~ret53#1 := isPumpRunning(); {99#true} is VALID [2022-02-20 18:11:54,312 INFO L290 TraceCheckUtils]: 25: Hoare triple {99#true} havoc ~retValue_acc~7;~retValue_acc~7 := ~pumpRunning~0;#res := ~retValue_acc~7; {99#true} is VALID [2022-02-20 18:11:54,312 INFO L290 TraceCheckUtils]: 26: Hoare triple {99#true} assume true; {99#true} is VALID [2022-02-20 18:11:54,312 INFO L284 TraceCheckUtils]: 27: Hoare quadruple {99#true} {100#false} #239#return; {100#false} is VALID [2022-02-20 18:11:54,313 INFO L290 TraceCheckUtils]: 28: Hoare triple {100#false} assume -2147483648 <= __utac_acc__Specification5_spec__3_#t~ret53#1 && __utac_acc__Specification5_spec__3_#t~ret53#1 <= 2147483647;__utac_acc__Specification5_spec__3_~tmp___0~2#1 := __utac_acc__Specification5_spec__3_#t~ret53#1;havoc __utac_acc__Specification5_spec__3_#t~ret53#1; {100#false} is VALID [2022-02-20 18:11:54,313 INFO L290 TraceCheckUtils]: 29: Hoare triple {100#false} assume 0 != __utac_acc__Specification5_spec__3_~tmp___0~2#1; {100#false} is VALID [2022-02-20 18:11:54,314 INFO L290 TraceCheckUtils]: 30: Hoare triple {100#false} assume 0 == ~switchedOnBeforeTS~0;assume { :begin_inline___automaton_fail } true; {100#false} is VALID [2022-02-20 18:11:54,314 INFO L290 TraceCheckUtils]: 31: Hoare triple {100#false} assume !false; {100#false} is VALID [2022-02-20 18:11:54,315 INFO L134 CoverageAnalysis]: Checked inductivity of 3 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 3 trivial. 0 not checked. [2022-02-20 18:11:54,316 INFO L144 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2022-02-20 18:11:54,316 INFO L338 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [395089062] [2022-02-20 18:11:54,316 INFO L165 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [395089062] provided 1 perfect and 0 imperfect interpolant sequences [2022-02-20 18:11:54,317 INFO L191 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2022-02-20 18:11:54,317 INFO L204 FreeRefinementEngine]: Number of different interpolants: perfect sequences [2] imperfect sequences [] total 2 [2022-02-20 18:11:54,320 INFO L118 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [1568637764] [2022-02-20 18:11:54,320 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2022-02-20 18:11:54,326 INFO L78 Accepts]: Start accepts. Automaton has has 2 states, 2 states have (on average 12.0) internal successors, (24), 2 states have internal predecessors, (24), 1 states have call successors, (4), 2 states have call predecessors, (4), 1 states have return successors, (2), 1 states have call predecessors, (2), 1 states have call successors, (2) Word has length 32 [2022-02-20 18:11:54,330 INFO L84 Accepts]: Finished accepts. word is accepted. [2022-02-20 18:11:54,333 INFO L86 InductivityCheck]: Starting indutivity check of a Floyd-Hoare automaton with has 2 states, 2 states have (on average 12.0) internal successors, (24), 2 states have internal predecessors, (24), 1 states have call successors, (4), 2 states have call predecessors, (4), 1 states have return successors, (2), 1 states have call predecessors, (2), 1 states have call successors, (2) [2022-02-20 18:11:54,382 INFO L122 InductivityCheck]: Floyd-Hoare automaton has 30 edges. 30 inductive. 0 not inductive. 0 times theorem prover too weak to decide inductivity. [2022-02-20 18:11:54,382 INFO L546 AbstractCegarLoop]: INTERPOLANT automaton has 2 states [2022-02-20 18:11:54,382 INFO L108 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2022-02-20 18:11:54,414 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 2 interpolants. [2022-02-20 18:11:54,415 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=1, Invalid=1, Unknown=0, NotChecked=0, Total=2 [2022-02-20 18:11:54,420 INFO L87 Difference]: Start difference. First operand has 96 states, 70 states have (on average 1.3571428571428572) internal successors, (95), 78 states have internal predecessors, (95), 15 states have call successors, (15), 9 states have call predecessors, (15), 9 states have return successors, (15), 11 states have call predecessors, (15), 15 states have call successors, (15) Second operand has 2 states, 2 states have (on average 12.0) internal successors, (24), 2 states have internal predecessors, (24), 1 states have call successors, (4), 2 states have call predecessors, (4), 1 states have return successors, (2), 1 states have call predecessors, (2), 1 states have call successors, (2) [2022-02-20 18:11:54,567 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-02-20 18:11:54,567 INFO L93 Difference]: Finished difference Result 183 states and 244 transitions. [2022-02-20 18:11:54,567 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 2 states. [2022-02-20 18:11:54,568 INFO L78 Accepts]: Start accepts. Automaton has has 2 states, 2 states have (on average 12.0) internal successors, (24), 2 states have internal predecessors, (24), 1 states have call successors, (4), 2 states have call predecessors, (4), 1 states have return successors, (2), 1 states have call predecessors, (2), 1 states have call successors, (2) Word has length 32 [2022-02-20 18:11:54,568 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2022-02-20 18:11:54,569 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 2 states, 2 states have (on average 12.0) internal successors, (24), 2 states have internal predecessors, (24), 1 states have call successors, (4), 2 states have call predecessors, (4), 1 states have return successors, (2), 1 states have call predecessors, (2), 1 states have call successors, (2) [2022-02-20 18:11:54,583 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 2 states to 2 states and 244 transitions. [2022-02-20 18:11:54,584 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 2 states, 2 states have (on average 12.0) internal successors, (24), 2 states have internal predecessors, (24), 1 states have call successors, (4), 2 states have call predecessors, (4), 1 states have return successors, (2), 1 states have call predecessors, (2), 1 states have call successors, (2) [2022-02-20 18:11:54,593 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 2 states to 2 states and 244 transitions. [2022-02-20 18:11:54,593 INFO L86 InductivityCheck]: Starting indutivity check of a Floyd-Hoare automaton with 2 states and 244 transitions. [2022-02-20 18:11:54,810 INFO L122 InductivityCheck]: Floyd-Hoare automaton has 244 edges. 244 inductive. 0 not inductive. 0 times theorem prover too weak to decide inductivity. [2022-02-20 18:11:54,828 INFO L225 Difference]: With dead ends: 183 [2022-02-20 18:11:54,831 INFO L226 Difference]: Without dead ends: 87 [2022-02-20 18:11:54,835 INFO L932 BasicCegarLoop]: 0 DeclaredPredicates, 6 GetRequests, 6 SyntacticMatches, 0 SemanticMatches, 0 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 0 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=1, Invalid=1, Unknown=0, NotChecked=0, Total=2 [2022-02-20 18:11:54,838 INFO L933 BasicCegarLoop]: 119 mSDtfsCounter, 0 mSDsluCounter, 0 mSDsCounter, 0 mSdLazyCounter, 0 mSolverCounterSat, 0 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.0s Time, 0 mProtectedPredicate, 0 mProtectedAction, 0 SdHoareTripleChecker+Valid, 119 SdHoareTripleChecker+Invalid, 0 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 0 IncrementalHoareTripleChecker+Valid, 0 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.0s IncrementalHoareTripleChecker+Time [2022-02-20 18:11:54,840 INFO L934 BasicCegarLoop]: SdHoareTripleChecker [0 Valid, 119 Invalid, 0 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [0 Valid, 0 Invalid, 0 Unknown, 0 Unchecked, 0.0s Time] [2022-02-20 18:11:54,881 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 87 states. [2022-02-20 18:11:54,898 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 87 to 87. [2022-02-20 18:11:54,899 INFO L214 AbstractMinimizeNwa]: Start testing correctness of minimizeSevpa [2022-02-20 18:11:54,900 INFO L82 GeneralOperation]: Start isEquivalent. First operand 87 states. Second operand has 87 states, 63 states have (on average 1.2857142857142858) internal successors, (81), 70 states have internal predecessors, (81), 15 states have call successors, (15), 9 states have call predecessors, (15), 8 states have return successors, (14), 10 states have call predecessors, (14), 14 states have call successors, (14) [2022-02-20 18:11:54,901 INFO L74 IsIncluded]: Start isIncluded. First operand 87 states. Second operand has 87 states, 63 states have (on average 1.2857142857142858) internal successors, (81), 70 states have internal predecessors, (81), 15 states have call successors, (15), 9 states have call predecessors, (15), 8 states have return successors, (14), 10 states have call predecessors, (14), 14 states have call successors, (14) [2022-02-20 18:11:54,902 INFO L87 Difference]: Start difference. First operand 87 states. Second operand has 87 states, 63 states have (on average 1.2857142857142858) internal successors, (81), 70 states have internal predecessors, (81), 15 states have call successors, (15), 9 states have call predecessors, (15), 8 states have return successors, (14), 10 states have call predecessors, (14), 14 states have call successors, (14) [2022-02-20 18:11:54,909 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-02-20 18:11:54,909 INFO L93 Difference]: Finished difference Result 87 states and 110 transitions. [2022-02-20 18:11:54,909 INFO L276 IsEmpty]: Start isEmpty. Operand 87 states and 110 transitions. [2022-02-20 18:11:54,911 INFO L282 IsEmpty]: Finished isEmpty. No accepting run. [2022-02-20 18:11:54,911 INFO L83 IsIncluded]: Finished isIncluded. Language is included [2022-02-20 18:11:54,912 INFO L74 IsIncluded]: Start isIncluded. First operand has 87 states, 63 states have (on average 1.2857142857142858) internal successors, (81), 70 states have internal predecessors, (81), 15 states have call successors, (15), 9 states have call predecessors, (15), 8 states have return successors, (14), 10 states have call predecessors, (14), 14 states have call successors, (14) Second operand 87 states. [2022-02-20 18:11:54,925 INFO L87 Difference]: Start difference. First operand has 87 states, 63 states have (on average 1.2857142857142858) internal successors, (81), 70 states have internal predecessors, (81), 15 states have call successors, (15), 9 states have call predecessors, (15), 8 states have return successors, (14), 10 states have call predecessors, (14), 14 states have call successors, (14) Second operand 87 states. [2022-02-20 18:11:54,931 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-02-20 18:11:54,935 INFO L93 Difference]: Finished difference Result 87 states and 110 transitions. [2022-02-20 18:11:54,935 INFO L276 IsEmpty]: Start isEmpty. Operand 87 states and 110 transitions. [2022-02-20 18:11:54,937 INFO L282 IsEmpty]: Finished isEmpty. No accepting run. [2022-02-20 18:11:54,938 INFO L83 IsIncluded]: Finished isIncluded. Language is included [2022-02-20 18:11:54,938 INFO L88 GeneralOperation]: Finished isEquivalent. [2022-02-20 18:11:54,939 INFO L221 AbstractMinimizeNwa]: Finished testing correctness of minimizeSevpa [2022-02-20 18:11:54,939 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 87 states, 63 states have (on average 1.2857142857142858) internal successors, (81), 70 states have internal predecessors, (81), 15 states have call successors, (15), 9 states have call predecessors, (15), 8 states have return successors, (14), 10 states have call predecessors, (14), 14 states have call successors, (14) [2022-02-20 18:11:54,945 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 87 states to 87 states and 110 transitions. [2022-02-20 18:11:54,954 INFO L78 Accepts]: Start accepts. Automaton has 87 states and 110 transitions. Word has length 32 [2022-02-20 18:11:54,955 INFO L84 Accepts]: Finished accepts. word is rejected. [2022-02-20 18:11:54,955 INFO L470 AbstractCegarLoop]: Abstraction has 87 states and 110 transitions. [2022-02-20 18:11:54,955 INFO L471 AbstractCegarLoop]: INTERPOLANT automaton has has 2 states, 2 states have (on average 12.0) internal successors, (24), 2 states have internal predecessors, (24), 1 states have call successors, (4), 2 states have call predecessors, (4), 1 states have return successors, (2), 1 states have call predecessors, (2), 1 states have call successors, (2) [2022-02-20 18:11:54,956 INFO L276 IsEmpty]: Start isEmpty. Operand 87 states and 110 transitions. [2022-02-20 18:11:54,958 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 34 [2022-02-20 18:11:54,961 INFO L506 BasicCegarLoop]: Found error trace [2022-02-20 18:11:54,961 INFO L514 BasicCegarLoop]: trace histogram [2, 2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-02-20 18:11:54,962 WARN L452 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable0 [2022-02-20 18:11:54,962 INFO L402 AbstractCegarLoop]: === Iteration 2 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2022-02-20 18:11:54,963 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2022-02-20 18:11:54,964 INFO L85 PathProgramCache]: Analyzing trace with hash -1237788034, now seen corresponding path program 1 times [2022-02-20 18:11:54,964 INFO L126 FreeRefinementEngine]: Executing refinement strategy CAMEL [2022-02-20 18:11:54,964 INFO L338 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [282206329] [2022-02-20 18:11:54,965 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-02-20 18:11:54,965 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2022-02-20 18:11:55,015 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-02-20 18:11:55,070 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 14 [2022-02-20 18:11:55,073 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-02-20 18:11:55,077 INFO L290 TraceCheckUtils]: 0: Hoare triple {674#true} havoc ~retValue_acc~7;~retValue_acc~7 := ~pumpRunning~0;#res := ~retValue_acc~7; {674#true} is VALID [2022-02-20 18:11:55,078 INFO L290 TraceCheckUtils]: 1: Hoare triple {674#true} assume true; {674#true} is VALID [2022-02-20 18:11:55,078 INFO L284 TraceCheckUtils]: 2: Hoare quadruple {674#true} {675#false} #229#return; {675#false} is VALID [2022-02-20 18:11:55,078 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 25 [2022-02-20 18:11:55,081 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-02-20 18:11:55,093 INFO L290 TraceCheckUtils]: 0: Hoare triple {674#true} havoc ~retValue_acc~7;~retValue_acc~7 := ~pumpRunning~0;#res := ~retValue_acc~7; {674#true} is VALID [2022-02-20 18:11:55,093 INFO L290 TraceCheckUtils]: 1: Hoare triple {674#true} assume true; {674#true} is VALID [2022-02-20 18:11:55,093 INFO L284 TraceCheckUtils]: 2: Hoare quadruple {674#true} {675#false} #239#return; {675#false} is VALID [2022-02-20 18:11:55,094 INFO L290 TraceCheckUtils]: 0: Hoare triple {674#true} assume { :begin_inline_ULTIMATE.init } true;#NULL.base, #NULL.offset := 0, 0;assume 0 == #valid[0];assume 0 < #StackHeapBarrier;call #Ultimate.allocInit(2, 1);call write~init~int(48, 1, 0, 1);call write~init~int(0, 1, 1, 1);call #Ultimate.allocInit(31, 2);call #Ultimate.allocInit(12, 3);call #Ultimate.allocInit(13, 4);call #Ultimate.allocInit(7, 5);call write~init~int(44, 5, 0, 1);call write~init~int(77, 5, 1, 1);call write~init~int(101, 5, 2, 1);call write~init~int(116, 5, 3, 1);call write~init~int(104, 5, 4, 1);call write~init~int(58, 5, 5, 1);call write~init~int(0, 5, 6, 1);call #Ultimate.allocInit(5, 6);call write~init~int(67, 6, 0, 1);call write~init~int(82, 6, 1, 1);call write~init~int(73, 6, 2, 1);call write~init~int(84, 6, 3, 1);call write~init~int(0, 6, 4, 1);call #Ultimate.allocInit(3, 7);call write~init~int(79, 7, 0, 1);call write~init~int(75, 7, 1, 1);call write~init~int(0, 7, 2, 1);call #Ultimate.allocInit(2, 8);call write~init~int(41, 8, 0, 1);call write~init~int(0, 8, 1, 1);call #Ultimate.allocInit(13, 9);call #Ultimate.allocInit(3, 10);call write~init~int(79, 10, 0, 1);call write~init~int(110, 10, 1, 1);call write~init~int(0, 10, 2, 1);call #Ultimate.allocInit(4, 11);call write~init~int(79, 11, 0, 1);call write~init~int(102, 11, 1, 1);call write~init~int(102, 11, 2, 1);call write~init~int(0, 11, 3, 1);call #Ultimate.allocInit(7, 12);call write~init~int(44, 12, 0, 1);call write~init~int(80, 12, 1, 1);call write~init~int(117, 12, 2, 1);call write~init~int(109, 12, 3, 1);call write~init~int(112, 12, 4, 1);call write~init~int(58, 12, 5, 1);call write~init~int(0, 12, 6, 1);call #Ultimate.allocInit(3, 13);call write~init~int(79, 13, 0, 1);call write~init~int(110, 13, 1, 1);call write~init~int(0, 13, 2, 1);call #Ultimate.allocInit(4, 14);call write~init~int(79, 14, 0, 1);call write~init~int(102, 14, 1, 1);call write~init~int(102, 14, 2, 1);call write~init~int(0, 14, 3, 1);call #Ultimate.allocInit(3, 15);call write~init~int(41, 15, 0, 1);call write~init~int(32, 15, 1, 1);call write~init~int(0, 15, 2, 1);call #Ultimate.allocInit(2, 16);call write~init~int(10, 16, 0, 1);call write~init~int(0, 16, 1, 1);call #Ultimate.allocInit(30, 17);call #Ultimate.allocInit(9, 18);call #Ultimate.allocInit(21, 19);call #Ultimate.allocInit(30, 20);call #Ultimate.allocInit(9, 21);call #Ultimate.allocInit(21, 22);call #Ultimate.allocInit(30, 23);call #Ultimate.allocInit(9, 24);call #Ultimate.allocInit(25, 25);call #Ultimate.allocInit(30, 26);call #Ultimate.allocInit(9, 27);call #Ultimate.allocInit(25, 28);~waterLevel~0 := 1;~methaneLevelCritical~0 := 0;~cleanupTimeShifts~0 := 4;~pumpRunning~0 := 0;~systemActive~0 := 1;~head~0.base, ~head~0.offset := 0, 0;~switchedOnBeforeTS~0 := 0; {674#true} is VALID [2022-02-20 18:11:55,094 INFO L290 TraceCheckUtils]: 1: Hoare triple {674#true} assume { :end_inline_ULTIMATE.init } true;assume { :begin_inline_main } true;havoc main_#res#1;havoc main_#t~ret10#1, main_~retValue_acc~5#1, main_~tmp~0#1;havoc main_~retValue_acc~5#1;havoc main_~tmp~0#1;assume { :begin_inline_select_helpers } true; {674#true} is VALID [2022-02-20 18:11:55,094 INFO L290 TraceCheckUtils]: 2: Hoare triple {674#true} assume { :end_inline_select_helpers } true;assume { :begin_inline_select_features } true; {674#true} is VALID [2022-02-20 18:11:55,095 INFO L290 TraceCheckUtils]: 3: Hoare triple {674#true} assume { :end_inline_select_features } true;assume { :begin_inline_valid_product } true;havoc valid_product_#res#1;havoc valid_product_~retValue_acc~1#1;havoc valid_product_~retValue_acc~1#1;valid_product_~retValue_acc~1#1 := 1;valid_product_#res#1 := valid_product_~retValue_acc~1#1; {674#true} is VALID [2022-02-20 18:11:55,098 INFO L290 TraceCheckUtils]: 4: Hoare triple {674#true} main_#t~ret10#1 := valid_product_#res#1;assume { :end_inline_valid_product } true;assume -2147483648 <= main_#t~ret10#1 && main_#t~ret10#1 <= 2147483647;main_~tmp~0#1 := main_#t~ret10#1;havoc main_#t~ret10#1; {674#true} is VALID [2022-02-20 18:11:55,098 INFO L290 TraceCheckUtils]: 5: Hoare triple {674#true} assume 0 != main_~tmp~0#1;assume { :begin_inline_setup } true; {674#true} is VALID [2022-02-20 18:11:55,099 INFO L290 TraceCheckUtils]: 6: Hoare triple {674#true} assume { :end_inline_setup } true;assume { :begin_inline_runTest } true;assume { :begin_inline___utac_acc__Specification5_spec__1 } true;~switchedOnBeforeTS~0 := 0; {674#true} is VALID [2022-02-20 18:11:55,100 INFO L290 TraceCheckUtils]: 7: Hoare triple {674#true} assume { :end_inline___utac_acc__Specification5_spec__1 } true;assume { :begin_inline_test } true;havoc test_#t~nondet24#1, test_#t~nondet25#1, test_#t~nondet26#1, test_#t~nondet27#1, test_~splverifierCounter~0#1, test_~tmp~5#1, test_~tmp___0~1#1, test_~tmp___1~0#1, test_~tmp___2~0#1;havoc test_~splverifierCounter~0#1;havoc test_~tmp~5#1;havoc test_~tmp___0~1#1;havoc test_~tmp___1~0#1;havoc test_~tmp___2~0#1;test_~splverifierCounter~0#1 := 0; {676#(= |ULTIMATE.start_test_~splverifierCounter~0#1| 0)} is VALID [2022-02-20 18:11:55,102 INFO L290 TraceCheckUtils]: 8: Hoare triple {676#(= |ULTIMATE.start_test_~splverifierCounter~0#1| 0)} assume !false; {676#(= |ULTIMATE.start_test_~splverifierCounter~0#1| 0)} is VALID [2022-02-20 18:11:55,103 INFO L290 TraceCheckUtils]: 9: Hoare triple {676#(= |ULTIMATE.start_test_~splverifierCounter~0#1| 0)} assume !(test_~splverifierCounter~0#1 < 4); {675#false} is VALID [2022-02-20 18:11:55,103 INFO L272 TraceCheckUtils]: 10: Hoare triple {675#false} call cleanup(); {675#false} is VALID [2022-02-20 18:11:55,103 INFO L290 TraceCheckUtils]: 11: Hoare triple {675#false} havoc ~i~0;havoc ~__cil_tmp2~0; {675#false} is VALID [2022-02-20 18:11:55,103 INFO L272 TraceCheckUtils]: 12: Hoare triple {675#false} call timeShift(); {675#false} is VALID [2022-02-20 18:11:55,104 INFO L290 TraceCheckUtils]: 13: Hoare triple {675#false} assume { :begin_inline___utac_acc__Specification5_spec__2 } true;havoc __utac_acc__Specification5_spec__2_#t~ret51#1; {675#false} is VALID [2022-02-20 18:11:55,104 INFO L272 TraceCheckUtils]: 14: Hoare triple {675#false} call __utac_acc__Specification5_spec__2_#t~ret51#1 := isPumpRunning(); {674#true} is VALID [2022-02-20 18:11:55,104 INFO L290 TraceCheckUtils]: 15: Hoare triple {674#true} havoc ~retValue_acc~7;~retValue_acc~7 := ~pumpRunning~0;#res := ~retValue_acc~7; {674#true} is VALID [2022-02-20 18:11:55,104 INFO L290 TraceCheckUtils]: 16: Hoare triple {674#true} assume true; {674#true} is VALID [2022-02-20 18:11:55,105 INFO L284 TraceCheckUtils]: 17: Hoare quadruple {674#true} {675#false} #229#return; {675#false} is VALID [2022-02-20 18:11:55,105 INFO L290 TraceCheckUtils]: 18: Hoare triple {675#false} assume -2147483648 <= __utac_acc__Specification5_spec__2_#t~ret51#1 && __utac_acc__Specification5_spec__2_#t~ret51#1 <= 2147483647;~switchedOnBeforeTS~0 := __utac_acc__Specification5_spec__2_#t~ret51#1;havoc __utac_acc__Specification5_spec__2_#t~ret51#1; {675#false} is VALID [2022-02-20 18:11:55,106 INFO L290 TraceCheckUtils]: 19: Hoare triple {675#false} assume { :end_inline___utac_acc__Specification5_spec__2 } true; {675#false} is VALID [2022-02-20 18:11:55,106 INFO L290 TraceCheckUtils]: 20: Hoare triple {675#false} assume !(0 != ~pumpRunning~0); {675#false} is VALID [2022-02-20 18:11:55,106 INFO L290 TraceCheckUtils]: 21: Hoare triple {675#false} assume !(0 != ~systemActive~0); {675#false} is VALID [2022-02-20 18:11:55,106 INFO L290 TraceCheckUtils]: 22: Hoare triple {675#false} assume { :begin_inline___utac_acc__Specification5_spec__3 } true;havoc __utac_acc__Specification5_spec__3_#t~ret52#1, __utac_acc__Specification5_spec__3_#t~ret53#1, __utac_acc__Specification5_spec__3_~tmp~9#1, __utac_acc__Specification5_spec__3_~tmp___0~2#1;havoc __utac_acc__Specification5_spec__3_~tmp~9#1;havoc __utac_acc__Specification5_spec__3_~tmp___0~2#1;assume { :begin_inline_getWaterLevel } true;havoc getWaterLevel_#res#1;havoc getWaterLevel_~retValue_acc~3#1;havoc getWaterLevel_~retValue_acc~3#1;getWaterLevel_~retValue_acc~3#1 := ~waterLevel~0;getWaterLevel_#res#1 := getWaterLevel_~retValue_acc~3#1; {675#false} is VALID [2022-02-20 18:11:55,107 INFO L290 TraceCheckUtils]: 23: Hoare triple {675#false} __utac_acc__Specification5_spec__3_#t~ret52#1 := getWaterLevel_#res#1;assume { :end_inline_getWaterLevel } true;assume -2147483648 <= __utac_acc__Specification5_spec__3_#t~ret52#1 && __utac_acc__Specification5_spec__3_#t~ret52#1 <= 2147483647;__utac_acc__Specification5_spec__3_~tmp~9#1 := __utac_acc__Specification5_spec__3_#t~ret52#1;havoc __utac_acc__Specification5_spec__3_#t~ret52#1; {675#false} is VALID [2022-02-20 18:11:55,107 INFO L290 TraceCheckUtils]: 24: Hoare triple {675#false} assume 2 != __utac_acc__Specification5_spec__3_~tmp~9#1; {675#false} is VALID [2022-02-20 18:11:55,107 INFO L272 TraceCheckUtils]: 25: Hoare triple {675#false} call __utac_acc__Specification5_spec__3_#t~ret53#1 := isPumpRunning(); {674#true} is VALID [2022-02-20 18:11:55,107 INFO L290 TraceCheckUtils]: 26: Hoare triple {674#true} havoc ~retValue_acc~7;~retValue_acc~7 := ~pumpRunning~0;#res := ~retValue_acc~7; {674#true} is VALID [2022-02-20 18:11:55,108 INFO L290 TraceCheckUtils]: 27: Hoare triple {674#true} assume true; {674#true} is VALID [2022-02-20 18:11:55,108 INFO L284 TraceCheckUtils]: 28: Hoare quadruple {674#true} {675#false} #239#return; {675#false} is VALID [2022-02-20 18:11:55,109 INFO L290 TraceCheckUtils]: 29: Hoare triple {675#false} assume -2147483648 <= __utac_acc__Specification5_spec__3_#t~ret53#1 && __utac_acc__Specification5_spec__3_#t~ret53#1 <= 2147483647;__utac_acc__Specification5_spec__3_~tmp___0~2#1 := __utac_acc__Specification5_spec__3_#t~ret53#1;havoc __utac_acc__Specification5_spec__3_#t~ret53#1; {675#false} is VALID [2022-02-20 18:11:55,109 INFO L290 TraceCheckUtils]: 30: Hoare triple {675#false} assume 0 != __utac_acc__Specification5_spec__3_~tmp___0~2#1; {675#false} is VALID [2022-02-20 18:11:55,109 INFO L290 TraceCheckUtils]: 31: Hoare triple {675#false} assume 0 == ~switchedOnBeforeTS~0;assume { :begin_inline___automaton_fail } true; {675#false} is VALID [2022-02-20 18:11:55,109 INFO L290 TraceCheckUtils]: 32: Hoare triple {675#false} assume !false; {675#false} is VALID [2022-02-20 18:11:55,110 INFO L134 CoverageAnalysis]: Checked inductivity of 3 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 3 trivial. 0 not checked. [2022-02-20 18:11:55,110 INFO L144 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2022-02-20 18:11:55,111 INFO L338 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [282206329] [2022-02-20 18:11:55,111 INFO L165 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [282206329] provided 1 perfect and 0 imperfect interpolant sequences [2022-02-20 18:11:55,111 INFO L191 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2022-02-20 18:11:55,111 INFO L204 FreeRefinementEngine]: Number of different interpolants: perfect sequences [3] imperfect sequences [] total 3 [2022-02-20 18:11:55,112 INFO L118 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [457479386] [2022-02-20 18:11:55,112 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2022-02-20 18:11:55,113 INFO L78 Accepts]: Start accepts. Automaton has has 3 states, 3 states have (on average 8.333333333333334) internal successors, (25), 3 states have internal predecessors, (25), 1 states have call successors, (4), 2 states have call predecessors, (4), 1 states have return successors, (2), 1 states have call predecessors, (2), 1 states have call successors, (2) Word has length 33 [2022-02-20 18:11:55,113 INFO L84 Accepts]: Finished accepts. word is accepted. [2022-02-20 18:11:55,114 INFO L86 InductivityCheck]: Starting indutivity check of a Floyd-Hoare automaton with has 3 states, 3 states have (on average 8.333333333333334) internal successors, (25), 3 states have internal predecessors, (25), 1 states have call successors, (4), 2 states have call predecessors, (4), 1 states have return successors, (2), 1 states have call predecessors, (2), 1 states have call successors, (2) [2022-02-20 18:11:55,141 INFO L122 InductivityCheck]: Floyd-Hoare automaton has 31 edges. 31 inductive. 0 not inductive. 0 times theorem prover too weak to decide inductivity. [2022-02-20 18:11:55,141 INFO L546 AbstractCegarLoop]: INTERPOLANT automaton has 3 states [2022-02-20 18:11:55,142 INFO L108 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2022-02-20 18:11:55,143 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 3 interpolants. [2022-02-20 18:11:55,143 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=3, Invalid=3, Unknown=0, NotChecked=0, Total=6 [2022-02-20 18:11:55,143 INFO L87 Difference]: Start difference. First operand 87 states and 110 transitions. Second operand has 3 states, 3 states have (on average 8.333333333333334) internal successors, (25), 3 states have internal predecessors, (25), 1 states have call successors, (4), 2 states have call predecessors, (4), 1 states have return successors, (2), 1 states have call predecessors, (2), 1 states have call successors, (2) [2022-02-20 18:11:55,277 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-02-20 18:11:55,278 INFO L93 Difference]: Finished difference Result 139 states and 175 transitions. [2022-02-20 18:11:55,278 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 3 states. [2022-02-20 18:11:55,278 INFO L78 Accepts]: Start accepts. Automaton has has 3 states, 3 states have (on average 8.333333333333334) internal successors, (25), 3 states have internal predecessors, (25), 1 states have call successors, (4), 2 states have call predecessors, (4), 1 states have return successors, (2), 1 states have call predecessors, (2), 1 states have call successors, (2) Word has length 33 [2022-02-20 18:11:55,278 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2022-02-20 18:11:55,279 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 3 states, 3 states have (on average 8.333333333333334) internal successors, (25), 3 states have internal predecessors, (25), 1 states have call successors, (4), 2 states have call predecessors, (4), 1 states have return successors, (2), 1 states have call predecessors, (2), 1 states have call successors, (2) [2022-02-20 18:11:55,284 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 3 states to 3 states and 175 transitions. [2022-02-20 18:11:55,285 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 3 states, 3 states have (on average 8.333333333333334) internal successors, (25), 3 states have internal predecessors, (25), 1 states have call successors, (4), 2 states have call predecessors, (4), 1 states have return successors, (2), 1 states have call predecessors, (2), 1 states have call successors, (2) [2022-02-20 18:11:55,294 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 3 states to 3 states and 175 transitions. [2022-02-20 18:11:55,294 INFO L86 InductivityCheck]: Starting indutivity check of a Floyd-Hoare automaton with 3 states and 175 transitions. [2022-02-20 18:11:55,437 INFO L122 InductivityCheck]: Floyd-Hoare automaton has 175 edges. 175 inductive. 0 not inductive. 0 times theorem prover too weak to decide inductivity. [2022-02-20 18:11:55,440 INFO L225 Difference]: With dead ends: 139 [2022-02-20 18:11:55,440 INFO L226 Difference]: Without dead ends: 78 [2022-02-20 18:11:55,446 INFO L932 BasicCegarLoop]: 0 DeclaredPredicates, 7 GetRequests, 6 SyntacticMatches, 0 SemanticMatches, 1 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 0 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=3, Invalid=3, Unknown=0, NotChecked=0, Total=6 [2022-02-20 18:11:55,450 INFO L933 BasicCegarLoop]: 97 mSDtfsCounter, 12 mSDsluCounter, 81 mSDsCounter, 0 mSdLazyCounter, 1 mSolverCounterSat, 0 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.0s Time, 0 mProtectedPredicate, 0 mProtectedAction, 15 SdHoareTripleChecker+Valid, 178 SdHoareTripleChecker+Invalid, 1 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 0 IncrementalHoareTripleChecker+Valid, 1 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.0s IncrementalHoareTripleChecker+Time [2022-02-20 18:11:55,450 INFO L934 BasicCegarLoop]: SdHoareTripleChecker [15 Valid, 178 Invalid, 1 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [0 Valid, 1 Invalid, 0 Unknown, 0 Unchecked, 0.0s Time] [2022-02-20 18:11:55,455 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 78 states. [2022-02-20 18:11:55,465 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 78 to 78. [2022-02-20 18:11:55,465 INFO L214 AbstractMinimizeNwa]: Start testing correctness of minimizeSevpa [2022-02-20 18:11:55,465 INFO L82 GeneralOperation]: Start isEquivalent. First operand 78 states. Second operand has 78 states, 57 states have (on average 1.2982456140350878) internal successors, (74), 64 states have internal predecessors, (74), 12 states have call successors, (12), 8 states have call predecessors, (12), 8 states have return successors, (12), 8 states have call predecessors, (12), 12 states have call successors, (12) [2022-02-20 18:11:55,466 INFO L74 IsIncluded]: Start isIncluded. First operand 78 states. Second operand has 78 states, 57 states have (on average 1.2982456140350878) internal successors, (74), 64 states have internal predecessors, (74), 12 states have call successors, (12), 8 states have call predecessors, (12), 8 states have return successors, (12), 8 states have call predecessors, (12), 12 states have call successors, (12) [2022-02-20 18:11:55,466 INFO L87 Difference]: Start difference. First operand 78 states. Second operand has 78 states, 57 states have (on average 1.2982456140350878) internal successors, (74), 64 states have internal predecessors, (74), 12 states have call successors, (12), 8 states have call predecessors, (12), 8 states have return successors, (12), 8 states have call predecessors, (12), 12 states have call successors, (12) [2022-02-20 18:11:55,469 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-02-20 18:11:55,470 INFO L93 Difference]: Finished difference Result 78 states and 98 transitions. [2022-02-20 18:11:55,470 INFO L276 IsEmpty]: Start isEmpty. Operand 78 states and 98 transitions. [2022-02-20 18:11:55,470 INFO L282 IsEmpty]: Finished isEmpty. No accepting run. [2022-02-20 18:11:55,470 INFO L83 IsIncluded]: Finished isIncluded. Language is included [2022-02-20 18:11:55,474 INFO L74 IsIncluded]: Start isIncluded. First operand has 78 states, 57 states have (on average 1.2982456140350878) internal successors, (74), 64 states have internal predecessors, (74), 12 states have call successors, (12), 8 states have call predecessors, (12), 8 states have return successors, (12), 8 states have call predecessors, (12), 12 states have call successors, (12) Second operand 78 states. [2022-02-20 18:11:55,475 INFO L87 Difference]: Start difference. First operand has 78 states, 57 states have (on average 1.2982456140350878) internal successors, (74), 64 states have internal predecessors, (74), 12 states have call successors, (12), 8 states have call predecessors, (12), 8 states have return successors, (12), 8 states have call predecessors, (12), 12 states have call successors, (12) Second operand 78 states. [2022-02-20 18:11:55,481 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-02-20 18:11:55,482 INFO L93 Difference]: Finished difference Result 78 states and 98 transitions. [2022-02-20 18:11:55,482 INFO L276 IsEmpty]: Start isEmpty. Operand 78 states and 98 transitions. [2022-02-20 18:11:55,483 INFO L282 IsEmpty]: Finished isEmpty. No accepting run. [2022-02-20 18:11:55,483 INFO L83 IsIncluded]: Finished isIncluded. Language is included [2022-02-20 18:11:55,484 INFO L88 GeneralOperation]: Finished isEquivalent. [2022-02-20 18:11:55,484 INFO L221 AbstractMinimizeNwa]: Finished testing correctness of minimizeSevpa [2022-02-20 18:11:55,484 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 78 states, 57 states have (on average 1.2982456140350878) internal successors, (74), 64 states have internal predecessors, (74), 12 states have call successors, (12), 8 states have call predecessors, (12), 8 states have return successors, (12), 8 states have call predecessors, (12), 12 states have call successors, (12) [2022-02-20 18:11:55,487 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 78 states to 78 states and 98 transitions. [2022-02-20 18:11:55,488 INFO L78 Accepts]: Start accepts. Automaton has 78 states and 98 transitions. Word has length 33 [2022-02-20 18:11:55,488 INFO L84 Accepts]: Finished accepts. word is rejected. [2022-02-20 18:11:55,489 INFO L470 AbstractCegarLoop]: Abstraction has 78 states and 98 transitions. [2022-02-20 18:11:55,489 INFO L471 AbstractCegarLoop]: INTERPOLANT automaton has has 3 states, 3 states have (on average 8.333333333333334) internal successors, (25), 3 states have internal predecessors, (25), 1 states have call successors, (4), 2 states have call predecessors, (4), 1 states have return successors, (2), 1 states have call predecessors, (2), 1 states have call successors, (2) [2022-02-20 18:11:55,490 INFO L276 IsEmpty]: Start isEmpty. Operand 78 states and 98 transitions. [2022-02-20 18:11:55,490 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 38 [2022-02-20 18:11:55,491 INFO L506 BasicCegarLoop]: Found error trace [2022-02-20 18:11:55,491 INFO L514 BasicCegarLoop]: trace histogram [2, 2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-02-20 18:11:55,491 WARN L452 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable1 [2022-02-20 18:11:55,491 INFO L402 AbstractCegarLoop]: === Iteration 3 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2022-02-20 18:11:55,492 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2022-02-20 18:11:55,492 INFO L85 PathProgramCache]: Analyzing trace with hash -896282956, now seen corresponding path program 1 times [2022-02-20 18:11:55,492 INFO L126 FreeRefinementEngine]: Executing refinement strategy CAMEL [2022-02-20 18:11:55,492 INFO L338 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [963245716] [2022-02-20 18:11:55,493 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-02-20 18:11:55,493 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2022-02-20 18:11:55,530 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-02-20 18:11:55,599 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 18 [2022-02-20 18:11:55,602 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-02-20 18:11:55,622 INFO L290 TraceCheckUtils]: 0: Hoare triple {1154#true} havoc ~retValue_acc~7;~retValue_acc~7 := ~pumpRunning~0;#res := ~retValue_acc~7; {1154#true} is VALID [2022-02-20 18:11:55,623 INFO L290 TraceCheckUtils]: 1: Hoare triple {1154#true} assume true; {1154#true} is VALID [2022-02-20 18:11:55,623 INFO L284 TraceCheckUtils]: 2: Hoare quadruple {1154#true} {1159#(not (= 0 ~systemActive~0))} #229#return; {1159#(not (= 0 ~systemActive~0))} is VALID [2022-02-20 18:11:55,624 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 29 [2022-02-20 18:11:55,625 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-02-20 18:11:55,627 INFO L290 TraceCheckUtils]: 0: Hoare triple {1154#true} havoc ~retValue_acc~7;~retValue_acc~7 := ~pumpRunning~0;#res := ~retValue_acc~7; {1154#true} is VALID [2022-02-20 18:11:55,627 INFO L290 TraceCheckUtils]: 1: Hoare triple {1154#true} assume true; {1154#true} is VALID [2022-02-20 18:11:55,628 INFO L284 TraceCheckUtils]: 2: Hoare quadruple {1154#true} {1155#false} #239#return; {1155#false} is VALID [2022-02-20 18:11:55,630 INFO L290 TraceCheckUtils]: 0: Hoare triple {1154#true} assume { :begin_inline_ULTIMATE.init } true;#NULL.base, #NULL.offset := 0, 0;assume 0 == #valid[0];assume 0 < #StackHeapBarrier;call #Ultimate.allocInit(2, 1);call write~init~int(48, 1, 0, 1);call write~init~int(0, 1, 1, 1);call #Ultimate.allocInit(31, 2);call #Ultimate.allocInit(12, 3);call #Ultimate.allocInit(13, 4);call #Ultimate.allocInit(7, 5);call write~init~int(44, 5, 0, 1);call write~init~int(77, 5, 1, 1);call write~init~int(101, 5, 2, 1);call write~init~int(116, 5, 3, 1);call write~init~int(104, 5, 4, 1);call write~init~int(58, 5, 5, 1);call write~init~int(0, 5, 6, 1);call #Ultimate.allocInit(5, 6);call write~init~int(67, 6, 0, 1);call write~init~int(82, 6, 1, 1);call write~init~int(73, 6, 2, 1);call write~init~int(84, 6, 3, 1);call write~init~int(0, 6, 4, 1);call #Ultimate.allocInit(3, 7);call write~init~int(79, 7, 0, 1);call write~init~int(75, 7, 1, 1);call write~init~int(0, 7, 2, 1);call #Ultimate.allocInit(2, 8);call write~init~int(41, 8, 0, 1);call write~init~int(0, 8, 1, 1);call #Ultimate.allocInit(13, 9);call #Ultimate.allocInit(3, 10);call write~init~int(79, 10, 0, 1);call write~init~int(110, 10, 1, 1);call write~init~int(0, 10, 2, 1);call #Ultimate.allocInit(4, 11);call write~init~int(79, 11, 0, 1);call write~init~int(102, 11, 1, 1);call write~init~int(102, 11, 2, 1);call write~init~int(0, 11, 3, 1);call #Ultimate.allocInit(7, 12);call write~init~int(44, 12, 0, 1);call write~init~int(80, 12, 1, 1);call write~init~int(117, 12, 2, 1);call write~init~int(109, 12, 3, 1);call write~init~int(112, 12, 4, 1);call write~init~int(58, 12, 5, 1);call write~init~int(0, 12, 6, 1);call #Ultimate.allocInit(3, 13);call write~init~int(79, 13, 0, 1);call write~init~int(110, 13, 1, 1);call write~init~int(0, 13, 2, 1);call #Ultimate.allocInit(4, 14);call write~init~int(79, 14, 0, 1);call write~init~int(102, 14, 1, 1);call write~init~int(102, 14, 2, 1);call write~init~int(0, 14, 3, 1);call #Ultimate.allocInit(3, 15);call write~init~int(41, 15, 0, 1);call write~init~int(32, 15, 1, 1);call write~init~int(0, 15, 2, 1);call #Ultimate.allocInit(2, 16);call write~init~int(10, 16, 0, 1);call write~init~int(0, 16, 1, 1);call #Ultimate.allocInit(30, 17);call #Ultimate.allocInit(9, 18);call #Ultimate.allocInit(21, 19);call #Ultimate.allocInit(30, 20);call #Ultimate.allocInit(9, 21);call #Ultimate.allocInit(21, 22);call #Ultimate.allocInit(30, 23);call #Ultimate.allocInit(9, 24);call #Ultimate.allocInit(25, 25);call #Ultimate.allocInit(30, 26);call #Ultimate.allocInit(9, 27);call #Ultimate.allocInit(25, 28);~waterLevel~0 := 1;~methaneLevelCritical~0 := 0;~cleanupTimeShifts~0 := 4;~pumpRunning~0 := 0;~systemActive~0 := 1;~head~0.base, ~head~0.offset := 0, 0;~switchedOnBeforeTS~0 := 0; {1156#(= 1 ~systemActive~0)} is VALID [2022-02-20 18:11:55,631 INFO L290 TraceCheckUtils]: 1: Hoare triple {1156#(= 1 ~systemActive~0)} assume { :end_inline_ULTIMATE.init } true;assume { :begin_inline_main } true;havoc main_#res#1;havoc main_#t~ret10#1, main_~retValue_acc~5#1, main_~tmp~0#1;havoc main_~retValue_acc~5#1;havoc main_~tmp~0#1;assume { :begin_inline_select_helpers } true; {1156#(= 1 ~systemActive~0)} is VALID [2022-02-20 18:11:55,631 INFO L290 TraceCheckUtils]: 2: Hoare triple {1156#(= 1 ~systemActive~0)} assume { :end_inline_select_helpers } true;assume { :begin_inline_select_features } true; {1156#(= 1 ~systemActive~0)} is VALID [2022-02-20 18:11:55,632 INFO L290 TraceCheckUtils]: 3: Hoare triple {1156#(= 1 ~systemActive~0)} assume { :end_inline_select_features } true;assume { :begin_inline_valid_product } true;havoc valid_product_#res#1;havoc valid_product_~retValue_acc~1#1;havoc valid_product_~retValue_acc~1#1;valid_product_~retValue_acc~1#1 := 1;valid_product_#res#1 := valid_product_~retValue_acc~1#1; {1157#(= |ULTIMATE.start_valid_product_#res#1| ~systemActive~0)} is VALID [2022-02-20 18:11:55,633 INFO L290 TraceCheckUtils]: 4: Hoare triple {1157#(= |ULTIMATE.start_valid_product_#res#1| ~systemActive~0)} main_#t~ret10#1 := valid_product_#res#1;assume { :end_inline_valid_product } true;assume -2147483648 <= main_#t~ret10#1 && main_#t~ret10#1 <= 2147483647;main_~tmp~0#1 := main_#t~ret10#1;havoc main_#t~ret10#1; {1158#(= |ULTIMATE.start_main_~tmp~0#1| ~systemActive~0)} is VALID [2022-02-20 18:11:55,633 INFO L290 TraceCheckUtils]: 5: Hoare triple {1158#(= |ULTIMATE.start_main_~tmp~0#1| ~systemActive~0)} assume 0 != main_~tmp~0#1;assume { :begin_inline_setup } true; {1159#(not (= 0 ~systemActive~0))} is VALID [2022-02-20 18:11:55,634 INFO L290 TraceCheckUtils]: 6: Hoare triple {1159#(not (= 0 ~systemActive~0))} assume { :end_inline_setup } true;assume { :begin_inline_runTest } true;assume { :begin_inline___utac_acc__Specification5_spec__1 } true;~switchedOnBeforeTS~0 := 0; {1159#(not (= 0 ~systemActive~0))} is VALID [2022-02-20 18:11:55,634 INFO L290 TraceCheckUtils]: 7: Hoare triple {1159#(not (= 0 ~systemActive~0))} assume { :end_inline___utac_acc__Specification5_spec__1 } true;assume { :begin_inline_test } true;havoc test_#t~nondet24#1, test_#t~nondet25#1, test_#t~nondet26#1, test_#t~nondet27#1, test_~splverifierCounter~0#1, test_~tmp~5#1, test_~tmp___0~1#1, test_~tmp___1~0#1, test_~tmp___2~0#1;havoc test_~splverifierCounter~0#1;havoc test_~tmp~5#1;havoc test_~tmp___0~1#1;havoc test_~tmp___1~0#1;havoc test_~tmp___2~0#1;test_~splverifierCounter~0#1 := 0; {1159#(not (= 0 ~systemActive~0))} is VALID [2022-02-20 18:11:55,635 INFO L290 TraceCheckUtils]: 8: Hoare triple {1159#(not (= 0 ~systemActive~0))} assume !false; {1159#(not (= 0 ~systemActive~0))} is VALID [2022-02-20 18:11:55,635 INFO L290 TraceCheckUtils]: 9: Hoare triple {1159#(not (= 0 ~systemActive~0))} assume test_~splverifierCounter~0#1 < 4; {1159#(not (= 0 ~systemActive~0))} is VALID [2022-02-20 18:11:55,636 INFO L290 TraceCheckUtils]: 10: Hoare triple {1159#(not (= 0 ~systemActive~0))} assume -2147483648 <= test_#t~nondet24#1 && test_#t~nondet24#1 <= 2147483647;test_~tmp~5#1 := test_#t~nondet24#1;havoc test_#t~nondet24#1; {1159#(not (= 0 ~systemActive~0))} is VALID [2022-02-20 18:11:55,636 INFO L290 TraceCheckUtils]: 11: Hoare triple {1159#(not (= 0 ~systemActive~0))} assume !(0 != test_~tmp~5#1); {1159#(not (= 0 ~systemActive~0))} is VALID [2022-02-20 18:11:55,637 INFO L290 TraceCheckUtils]: 12: Hoare triple {1159#(not (= 0 ~systemActive~0))} assume -2147483648 <= test_#t~nondet25#1 && test_#t~nondet25#1 <= 2147483647;test_~tmp___0~1#1 := test_#t~nondet25#1;havoc test_#t~nondet25#1; {1159#(not (= 0 ~systemActive~0))} is VALID [2022-02-20 18:11:55,637 INFO L290 TraceCheckUtils]: 13: Hoare triple {1159#(not (= 0 ~systemActive~0))} assume !(0 != test_~tmp___0~1#1); {1159#(not (= 0 ~systemActive~0))} is VALID [2022-02-20 18:11:55,638 INFO L290 TraceCheckUtils]: 14: Hoare triple {1159#(not (= 0 ~systemActive~0))} assume -2147483648 <= test_#t~nondet26#1 && test_#t~nondet26#1 <= 2147483647;test_~tmp___2~0#1 := test_#t~nondet26#1;havoc test_#t~nondet26#1; {1159#(not (= 0 ~systemActive~0))} is VALID [2022-02-20 18:11:55,638 INFO L290 TraceCheckUtils]: 15: Hoare triple {1159#(not (= 0 ~systemActive~0))} assume 0 != test_~tmp___2~0#1; {1159#(not (= 0 ~systemActive~0))} is VALID [2022-02-20 18:11:55,639 INFO L272 TraceCheckUtils]: 16: Hoare triple {1159#(not (= 0 ~systemActive~0))} call timeShift(); {1159#(not (= 0 ~systemActive~0))} is VALID [2022-02-20 18:11:55,643 INFO L290 TraceCheckUtils]: 17: Hoare triple {1159#(not (= 0 ~systemActive~0))} assume { :begin_inline___utac_acc__Specification5_spec__2 } true;havoc __utac_acc__Specification5_spec__2_#t~ret51#1; {1159#(not (= 0 ~systemActive~0))} is VALID [2022-02-20 18:11:55,643 INFO L272 TraceCheckUtils]: 18: Hoare triple {1159#(not (= 0 ~systemActive~0))} call __utac_acc__Specification5_spec__2_#t~ret51#1 := isPumpRunning(); {1154#true} is VALID [2022-02-20 18:11:55,643 INFO L290 TraceCheckUtils]: 19: Hoare triple {1154#true} havoc ~retValue_acc~7;~retValue_acc~7 := ~pumpRunning~0;#res := ~retValue_acc~7; {1154#true} is VALID [2022-02-20 18:11:55,644 INFO L290 TraceCheckUtils]: 20: Hoare triple {1154#true} assume true; {1154#true} is VALID [2022-02-20 18:11:55,646 INFO L284 TraceCheckUtils]: 21: Hoare quadruple {1154#true} {1159#(not (= 0 ~systemActive~0))} #229#return; {1159#(not (= 0 ~systemActive~0))} is VALID [2022-02-20 18:11:55,647 INFO L290 TraceCheckUtils]: 22: Hoare triple {1159#(not (= 0 ~systemActive~0))} assume -2147483648 <= __utac_acc__Specification5_spec__2_#t~ret51#1 && __utac_acc__Specification5_spec__2_#t~ret51#1 <= 2147483647;~switchedOnBeforeTS~0 := __utac_acc__Specification5_spec__2_#t~ret51#1;havoc __utac_acc__Specification5_spec__2_#t~ret51#1; {1159#(not (= 0 ~systemActive~0))} is VALID [2022-02-20 18:11:55,647 INFO L290 TraceCheckUtils]: 23: Hoare triple {1159#(not (= 0 ~systemActive~0))} assume { :end_inline___utac_acc__Specification5_spec__2 } true; {1159#(not (= 0 ~systemActive~0))} is VALID [2022-02-20 18:11:55,648 INFO L290 TraceCheckUtils]: 24: Hoare triple {1159#(not (= 0 ~systemActive~0))} assume !(0 != ~pumpRunning~0); {1159#(not (= 0 ~systemActive~0))} is VALID [2022-02-20 18:11:55,648 INFO L290 TraceCheckUtils]: 25: Hoare triple {1159#(not (= 0 ~systemActive~0))} assume !(0 != ~systemActive~0); {1155#false} is VALID [2022-02-20 18:11:55,648 INFO L290 TraceCheckUtils]: 26: Hoare triple {1155#false} assume { :begin_inline___utac_acc__Specification5_spec__3 } true;havoc __utac_acc__Specification5_spec__3_#t~ret52#1, __utac_acc__Specification5_spec__3_#t~ret53#1, __utac_acc__Specification5_spec__3_~tmp~9#1, __utac_acc__Specification5_spec__3_~tmp___0~2#1;havoc __utac_acc__Specification5_spec__3_~tmp~9#1;havoc __utac_acc__Specification5_spec__3_~tmp___0~2#1;assume { :begin_inline_getWaterLevel } true;havoc getWaterLevel_#res#1;havoc getWaterLevel_~retValue_acc~3#1;havoc getWaterLevel_~retValue_acc~3#1;getWaterLevel_~retValue_acc~3#1 := ~waterLevel~0;getWaterLevel_#res#1 := getWaterLevel_~retValue_acc~3#1; {1155#false} is VALID [2022-02-20 18:11:55,648 INFO L290 TraceCheckUtils]: 27: Hoare triple {1155#false} __utac_acc__Specification5_spec__3_#t~ret52#1 := getWaterLevel_#res#1;assume { :end_inline_getWaterLevel } true;assume -2147483648 <= __utac_acc__Specification5_spec__3_#t~ret52#1 && __utac_acc__Specification5_spec__3_#t~ret52#1 <= 2147483647;__utac_acc__Specification5_spec__3_~tmp~9#1 := __utac_acc__Specification5_spec__3_#t~ret52#1;havoc __utac_acc__Specification5_spec__3_#t~ret52#1; {1155#false} is VALID [2022-02-20 18:11:55,649 INFO L290 TraceCheckUtils]: 28: Hoare triple {1155#false} assume 2 != __utac_acc__Specification5_spec__3_~tmp~9#1; {1155#false} is VALID [2022-02-20 18:11:55,649 INFO L272 TraceCheckUtils]: 29: Hoare triple {1155#false} call __utac_acc__Specification5_spec__3_#t~ret53#1 := isPumpRunning(); {1154#true} is VALID [2022-02-20 18:11:55,649 INFO L290 TraceCheckUtils]: 30: Hoare triple {1154#true} havoc ~retValue_acc~7;~retValue_acc~7 := ~pumpRunning~0;#res := ~retValue_acc~7; {1154#true} is VALID [2022-02-20 18:11:55,649 INFO L290 TraceCheckUtils]: 31: Hoare triple {1154#true} assume true; {1154#true} is VALID [2022-02-20 18:11:55,650 INFO L284 TraceCheckUtils]: 32: Hoare quadruple {1154#true} {1155#false} #239#return; {1155#false} is VALID [2022-02-20 18:11:55,650 INFO L290 TraceCheckUtils]: 33: Hoare triple {1155#false} assume -2147483648 <= __utac_acc__Specification5_spec__3_#t~ret53#1 && __utac_acc__Specification5_spec__3_#t~ret53#1 <= 2147483647;__utac_acc__Specification5_spec__3_~tmp___0~2#1 := __utac_acc__Specification5_spec__3_#t~ret53#1;havoc __utac_acc__Specification5_spec__3_#t~ret53#1; {1155#false} is VALID [2022-02-20 18:11:55,650 INFO L290 TraceCheckUtils]: 34: Hoare triple {1155#false} assume 0 != __utac_acc__Specification5_spec__3_~tmp___0~2#1; {1155#false} is VALID [2022-02-20 18:11:55,650 INFO L290 TraceCheckUtils]: 35: Hoare triple {1155#false} assume 0 == ~switchedOnBeforeTS~0;assume { :begin_inline___automaton_fail } true; {1155#false} is VALID [2022-02-20 18:11:55,651 INFO L290 TraceCheckUtils]: 36: Hoare triple {1155#false} assume !false; {1155#false} is VALID [2022-02-20 18:11:55,651 INFO L134 CoverageAnalysis]: Checked inductivity of 3 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 3 trivial. 0 not checked. [2022-02-20 18:11:55,651 INFO L144 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2022-02-20 18:11:55,652 INFO L338 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [963245716] [2022-02-20 18:11:55,652 INFO L165 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [963245716] provided 1 perfect and 0 imperfect interpolant sequences [2022-02-20 18:11:55,652 INFO L191 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2022-02-20 18:11:55,652 INFO L204 FreeRefinementEngine]: Number of different interpolants: perfect sequences [6] imperfect sequences [] total 6 [2022-02-20 18:11:55,652 INFO L118 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [716928012] [2022-02-20 18:11:55,653 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2022-02-20 18:11:55,653 INFO L78 Accepts]: Start accepts. Automaton has has 6 states, 6 states have (on average 5.0) internal successors, (30), 6 states have internal predecessors, (30), 2 states have call successors, (3), 2 states have call predecessors, (3), 1 states have return successors, (2), 2 states have call predecessors, (2), 2 states have call successors, (2) Word has length 37 [2022-02-20 18:11:55,654 INFO L84 Accepts]: Finished accepts. word is accepted. [2022-02-20 18:11:55,654 INFO L86 InductivityCheck]: Starting indutivity check of a Floyd-Hoare automaton with has 6 states, 6 states have (on average 5.0) internal successors, (30), 6 states have internal predecessors, (30), 2 states have call successors, (3), 2 states have call predecessors, (3), 1 states have return successors, (2), 2 states have call predecessors, (2), 2 states have call successors, (2) [2022-02-20 18:11:55,684 INFO L122 InductivityCheck]: Floyd-Hoare automaton has 35 edges. 35 inductive. 0 not inductive. 0 times theorem prover too weak to decide inductivity. [2022-02-20 18:11:55,684 INFO L546 AbstractCegarLoop]: INTERPOLANT automaton has 6 states [2022-02-20 18:11:55,684 INFO L108 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2022-02-20 18:11:55,685 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 6 interpolants. [2022-02-20 18:11:55,685 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=10, Invalid=20, Unknown=0, NotChecked=0, Total=30 [2022-02-20 18:11:55,686 INFO L87 Difference]: Start difference. First operand 78 states and 98 transitions. Second operand has 6 states, 6 states have (on average 5.0) internal successors, (30), 6 states have internal predecessors, (30), 2 states have call successors, (3), 2 states have call predecessors, (3), 1 states have return successors, (2), 2 states have call predecessors, (2), 2 states have call successors, (2) [2022-02-20 18:11:56,071 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-02-20 18:11:56,072 INFO L93 Difference]: Finished difference Result 148 states and 189 transitions. [2022-02-20 18:11:56,072 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 5 states. [2022-02-20 18:11:56,072 INFO L78 Accepts]: Start accepts. Automaton has has 6 states, 6 states have (on average 5.0) internal successors, (30), 6 states have internal predecessors, (30), 2 states have call successors, (3), 2 states have call predecessors, (3), 1 states have return successors, (2), 2 states have call predecessors, (2), 2 states have call successors, (2) Word has length 37 [2022-02-20 18:11:56,073 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2022-02-20 18:11:56,073 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 6 states, 6 states have (on average 5.0) internal successors, (30), 6 states have internal predecessors, (30), 2 states have call successors, (3), 2 states have call predecessors, (3), 1 states have return successors, (2), 2 states have call predecessors, (2), 2 states have call successors, (2) [2022-02-20 18:11:56,078 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 5 states to 5 states and 189 transitions. [2022-02-20 18:11:56,078 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 6 states, 6 states have (on average 5.0) internal successors, (30), 6 states have internal predecessors, (30), 2 states have call successors, (3), 2 states have call predecessors, (3), 1 states have return successors, (2), 2 states have call predecessors, (2), 2 states have call successors, (2) [2022-02-20 18:11:56,083 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 5 states to 5 states and 189 transitions. [2022-02-20 18:11:56,084 INFO L86 InductivityCheck]: Starting indutivity check of a Floyd-Hoare automaton with 5 states and 189 transitions. [2022-02-20 18:11:56,244 INFO L122 InductivityCheck]: Floyd-Hoare automaton has 189 edges. 189 inductive. 0 not inductive. 0 times theorem prover too weak to decide inductivity. [2022-02-20 18:11:56,247 INFO L225 Difference]: With dead ends: 148 [2022-02-20 18:11:56,248 INFO L226 Difference]: Without dead ends: 78 [2022-02-20 18:11:56,248 INFO L932 BasicCegarLoop]: 0 DeclaredPredicates, 11 GetRequests, 5 SyntacticMatches, 0 SemanticMatches, 6 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 0 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=22, Invalid=34, Unknown=0, NotChecked=0, Total=56 [2022-02-20 18:11:56,249 INFO L933 BasicCegarLoop]: 91 mSDtfsCounter, 181 mSDsluCounter, 106 mSDsCounter, 0 mSdLazyCounter, 53 mSolverCounterSat, 32 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.1s Time, 0 mProtectedPredicate, 0 mProtectedAction, 181 SdHoareTripleChecker+Valid, 197 SdHoareTripleChecker+Invalid, 85 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 32 IncrementalHoareTripleChecker+Valid, 53 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.1s IncrementalHoareTripleChecker+Time [2022-02-20 18:11:56,250 INFO L934 BasicCegarLoop]: SdHoareTripleChecker [181 Valid, 197 Invalid, 85 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [32 Valid, 53 Invalid, 0 Unknown, 0 Unchecked, 0.1s Time] [2022-02-20 18:11:56,251 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 78 states. [2022-02-20 18:11:56,263 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 78 to 78. [2022-02-20 18:11:56,264 INFO L214 AbstractMinimizeNwa]: Start testing correctness of minimizeSevpa [2022-02-20 18:11:56,264 INFO L82 GeneralOperation]: Start isEquivalent. First operand 78 states. Second operand has 78 states, 57 states have (on average 1.280701754385965) internal successors, (73), 64 states have internal predecessors, (73), 12 states have call successors, (12), 8 states have call predecessors, (12), 8 states have return successors, (12), 8 states have call predecessors, (12), 12 states have call successors, (12) [2022-02-20 18:11:56,265 INFO L74 IsIncluded]: Start isIncluded. First operand 78 states. Second operand has 78 states, 57 states have (on average 1.280701754385965) internal successors, (73), 64 states have internal predecessors, (73), 12 states have call successors, (12), 8 states have call predecessors, (12), 8 states have return successors, (12), 8 states have call predecessors, (12), 12 states have call successors, (12) [2022-02-20 18:11:56,265 INFO L87 Difference]: Start difference. First operand 78 states. Second operand has 78 states, 57 states have (on average 1.280701754385965) internal successors, (73), 64 states have internal predecessors, (73), 12 states have call successors, (12), 8 states have call predecessors, (12), 8 states have return successors, (12), 8 states have call predecessors, (12), 12 states have call successors, (12) [2022-02-20 18:11:56,268 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-02-20 18:11:56,268 INFO L93 Difference]: Finished difference Result 78 states and 97 transitions. [2022-02-20 18:11:56,268 INFO L276 IsEmpty]: Start isEmpty. Operand 78 states and 97 transitions. [2022-02-20 18:11:56,269 INFO L282 IsEmpty]: Finished isEmpty. No accepting run. [2022-02-20 18:11:56,269 INFO L83 IsIncluded]: Finished isIncluded. Language is included [2022-02-20 18:11:56,269 INFO L74 IsIncluded]: Start isIncluded. First operand has 78 states, 57 states have (on average 1.280701754385965) internal successors, (73), 64 states have internal predecessors, (73), 12 states have call successors, (12), 8 states have call predecessors, (12), 8 states have return successors, (12), 8 states have call predecessors, (12), 12 states have call successors, (12) Second operand 78 states. [2022-02-20 18:11:56,270 INFO L87 Difference]: Start difference. First operand has 78 states, 57 states have (on average 1.280701754385965) internal successors, (73), 64 states have internal predecessors, (73), 12 states have call successors, (12), 8 states have call predecessors, (12), 8 states have return successors, (12), 8 states have call predecessors, (12), 12 states have call successors, (12) Second operand 78 states. [2022-02-20 18:11:56,273 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-02-20 18:11:56,273 INFO L93 Difference]: Finished difference Result 78 states and 97 transitions. [2022-02-20 18:11:56,273 INFO L276 IsEmpty]: Start isEmpty. Operand 78 states and 97 transitions. [2022-02-20 18:11:56,273 INFO L282 IsEmpty]: Finished isEmpty. No accepting run. [2022-02-20 18:11:56,274 INFO L83 IsIncluded]: Finished isIncluded. Language is included [2022-02-20 18:11:56,274 INFO L88 GeneralOperation]: Finished isEquivalent. [2022-02-20 18:11:56,274 INFO L221 AbstractMinimizeNwa]: Finished testing correctness of minimizeSevpa [2022-02-20 18:11:56,274 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 78 states, 57 states have (on average 1.280701754385965) internal successors, (73), 64 states have internal predecessors, (73), 12 states have call successors, (12), 8 states have call predecessors, (12), 8 states have return successors, (12), 8 states have call predecessors, (12), 12 states have call successors, (12) [2022-02-20 18:11:56,277 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 78 states to 78 states and 97 transitions. [2022-02-20 18:11:56,277 INFO L78 Accepts]: Start accepts. Automaton has 78 states and 97 transitions. Word has length 37 [2022-02-20 18:11:56,278 INFO L84 Accepts]: Finished accepts. word is rejected. [2022-02-20 18:11:56,278 INFO L470 AbstractCegarLoop]: Abstraction has 78 states and 97 transitions. [2022-02-20 18:11:56,278 INFO L471 AbstractCegarLoop]: INTERPOLANT automaton has has 6 states, 6 states have (on average 5.0) internal successors, (30), 6 states have internal predecessors, (30), 2 states have call successors, (3), 2 states have call predecessors, (3), 1 states have return successors, (2), 2 states have call predecessors, (2), 2 states have call successors, (2) [2022-02-20 18:11:56,278 INFO L276 IsEmpty]: Start isEmpty. Operand 78 states and 97 transitions. [2022-02-20 18:11:56,279 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 48 [2022-02-20 18:11:56,279 INFO L506 BasicCegarLoop]: Found error trace [2022-02-20 18:11:56,279 INFO L514 BasicCegarLoop]: trace histogram [2, 2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-02-20 18:11:56,280 WARN L452 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable2 [2022-02-20 18:11:56,280 INFO L402 AbstractCegarLoop]: === Iteration 4 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2022-02-20 18:11:56,280 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2022-02-20 18:11:56,280 INFO L85 PathProgramCache]: Analyzing trace with hash 866173904, now seen corresponding path program 1 times [2022-02-20 18:11:56,281 INFO L126 FreeRefinementEngine]: Executing refinement strategy CAMEL [2022-02-20 18:11:56,281 INFO L338 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [1030460111] [2022-02-20 18:11:56,281 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-02-20 18:11:56,281 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2022-02-20 18:11:56,304 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-02-20 18:11:56,348 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 18 [2022-02-20 18:11:56,350 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-02-20 18:11:56,356 INFO L290 TraceCheckUtils]: 0: Hoare triple {1651#true} havoc ~retValue_acc~7;~retValue_acc~7 := ~pumpRunning~0;#res := ~retValue_acc~7; {1651#true} is VALID [2022-02-20 18:11:56,357 INFO L290 TraceCheckUtils]: 1: Hoare triple {1651#true} assume true; {1651#true} is VALID [2022-02-20 18:11:56,358 INFO L284 TraceCheckUtils]: 2: Hoare quadruple {1651#true} {1653#(= ~pumpRunning~0 0)} #229#return; {1653#(= ~pumpRunning~0 0)} is VALID [2022-02-20 18:11:56,362 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 27 [2022-02-20 18:11:56,367 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-02-20 18:11:56,379 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 2 [2022-02-20 18:11:56,381 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-02-20 18:11:56,385 INFO L290 TraceCheckUtils]: 0: Hoare triple {1651#true} assume true; {1651#true} is VALID [2022-02-20 18:11:56,386 INFO L284 TraceCheckUtils]: 1: Hoare quadruple {1651#true} {1653#(= ~pumpRunning~0 0)} #257#return; {1653#(= ~pumpRunning~0 0)} is VALID [2022-02-20 18:11:56,386 INFO L290 TraceCheckUtils]: 0: Hoare triple {1669#(= ~pumpRunning~0 |old(~pumpRunning~0)|)} havoc ~tmp~1#1; {1651#true} is VALID [2022-02-20 18:11:56,387 INFO L290 TraceCheckUtils]: 1: Hoare triple {1651#true} assume !(0 != ~pumpRunning~0); {1653#(= ~pumpRunning~0 0)} is VALID [2022-02-20 18:11:56,387 INFO L272 TraceCheckUtils]: 2: Hoare triple {1653#(= ~pumpRunning~0 0)} call processEnvironment__wrappee__base(); {1651#true} is VALID [2022-02-20 18:11:56,387 INFO L290 TraceCheckUtils]: 3: Hoare triple {1651#true} assume true; {1651#true} is VALID [2022-02-20 18:11:56,388 INFO L284 TraceCheckUtils]: 4: Hoare quadruple {1651#true} {1653#(= ~pumpRunning~0 0)} #257#return; {1653#(= ~pumpRunning~0 0)} is VALID [2022-02-20 18:11:56,388 INFO L290 TraceCheckUtils]: 5: Hoare triple {1653#(= ~pumpRunning~0 0)} assume true; {1653#(= ~pumpRunning~0 0)} is VALID [2022-02-20 18:11:56,389 INFO L284 TraceCheckUtils]: 6: Hoare quadruple {1653#(= ~pumpRunning~0 0)} {1653#(= ~pumpRunning~0 0)} #237#return; {1653#(= ~pumpRunning~0 0)} is VALID [2022-02-20 18:11:56,389 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 39 [2022-02-20 18:11:56,398 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-02-20 18:11:56,408 INFO L290 TraceCheckUtils]: 0: Hoare triple {1651#true} havoc ~retValue_acc~7;~retValue_acc~7 := ~pumpRunning~0;#res := ~retValue_acc~7; {1672#(= ~pumpRunning~0 |isPumpRunning_#res|)} is VALID [2022-02-20 18:11:56,409 INFO L290 TraceCheckUtils]: 1: Hoare triple {1672#(= ~pumpRunning~0 |isPumpRunning_#res|)} assume true; {1672#(= ~pumpRunning~0 |isPumpRunning_#res|)} is VALID [2022-02-20 18:11:56,410 INFO L284 TraceCheckUtils]: 2: Hoare quadruple {1672#(= ~pumpRunning~0 |isPumpRunning_#res|)} {1653#(= ~pumpRunning~0 0)} #239#return; {1667#(= 0 |timeShift___utac_acc__Specification5_spec__3_#t~ret53#1|)} is VALID [2022-02-20 18:11:56,410 INFO L290 TraceCheckUtils]: 0: Hoare triple {1651#true} assume { :begin_inline_ULTIMATE.init } true;#NULL.base, #NULL.offset := 0, 0;assume 0 == #valid[0];assume 0 < #StackHeapBarrier;call #Ultimate.allocInit(2, 1);call write~init~int(48, 1, 0, 1);call write~init~int(0, 1, 1, 1);call #Ultimate.allocInit(31, 2);call #Ultimate.allocInit(12, 3);call #Ultimate.allocInit(13, 4);call #Ultimate.allocInit(7, 5);call write~init~int(44, 5, 0, 1);call write~init~int(77, 5, 1, 1);call write~init~int(101, 5, 2, 1);call write~init~int(116, 5, 3, 1);call write~init~int(104, 5, 4, 1);call write~init~int(58, 5, 5, 1);call write~init~int(0, 5, 6, 1);call #Ultimate.allocInit(5, 6);call write~init~int(67, 6, 0, 1);call write~init~int(82, 6, 1, 1);call write~init~int(73, 6, 2, 1);call write~init~int(84, 6, 3, 1);call write~init~int(0, 6, 4, 1);call #Ultimate.allocInit(3, 7);call write~init~int(79, 7, 0, 1);call write~init~int(75, 7, 1, 1);call write~init~int(0, 7, 2, 1);call #Ultimate.allocInit(2, 8);call write~init~int(41, 8, 0, 1);call write~init~int(0, 8, 1, 1);call #Ultimate.allocInit(13, 9);call #Ultimate.allocInit(3, 10);call write~init~int(79, 10, 0, 1);call write~init~int(110, 10, 1, 1);call write~init~int(0, 10, 2, 1);call #Ultimate.allocInit(4, 11);call write~init~int(79, 11, 0, 1);call write~init~int(102, 11, 1, 1);call write~init~int(102, 11, 2, 1);call write~init~int(0, 11, 3, 1);call #Ultimate.allocInit(7, 12);call write~init~int(44, 12, 0, 1);call write~init~int(80, 12, 1, 1);call write~init~int(117, 12, 2, 1);call write~init~int(109, 12, 3, 1);call write~init~int(112, 12, 4, 1);call write~init~int(58, 12, 5, 1);call write~init~int(0, 12, 6, 1);call #Ultimate.allocInit(3, 13);call write~init~int(79, 13, 0, 1);call write~init~int(110, 13, 1, 1);call write~init~int(0, 13, 2, 1);call #Ultimate.allocInit(4, 14);call write~init~int(79, 14, 0, 1);call write~init~int(102, 14, 1, 1);call write~init~int(102, 14, 2, 1);call write~init~int(0, 14, 3, 1);call #Ultimate.allocInit(3, 15);call write~init~int(41, 15, 0, 1);call write~init~int(32, 15, 1, 1);call write~init~int(0, 15, 2, 1);call #Ultimate.allocInit(2, 16);call write~init~int(10, 16, 0, 1);call write~init~int(0, 16, 1, 1);call #Ultimate.allocInit(30, 17);call #Ultimate.allocInit(9, 18);call #Ultimate.allocInit(21, 19);call #Ultimate.allocInit(30, 20);call #Ultimate.allocInit(9, 21);call #Ultimate.allocInit(21, 22);call #Ultimate.allocInit(30, 23);call #Ultimate.allocInit(9, 24);call #Ultimate.allocInit(25, 25);call #Ultimate.allocInit(30, 26);call #Ultimate.allocInit(9, 27);call #Ultimate.allocInit(25, 28);~waterLevel~0 := 1;~methaneLevelCritical~0 := 0;~cleanupTimeShifts~0 := 4;~pumpRunning~0 := 0;~systemActive~0 := 1;~head~0.base, ~head~0.offset := 0, 0;~switchedOnBeforeTS~0 := 0; {1653#(= ~pumpRunning~0 0)} is VALID [2022-02-20 18:11:56,411 INFO L290 TraceCheckUtils]: 1: Hoare triple {1653#(= ~pumpRunning~0 0)} assume { :end_inline_ULTIMATE.init } true;assume { :begin_inline_main } true;havoc main_#res#1;havoc main_#t~ret10#1, main_~retValue_acc~5#1, main_~tmp~0#1;havoc main_~retValue_acc~5#1;havoc main_~tmp~0#1;assume { :begin_inline_select_helpers } true; {1653#(= ~pumpRunning~0 0)} is VALID [2022-02-20 18:11:56,411 INFO L290 TraceCheckUtils]: 2: Hoare triple {1653#(= ~pumpRunning~0 0)} assume { :end_inline_select_helpers } true;assume { :begin_inline_select_features } true; {1653#(= ~pumpRunning~0 0)} is VALID [2022-02-20 18:11:56,412 INFO L290 TraceCheckUtils]: 3: Hoare triple {1653#(= ~pumpRunning~0 0)} assume { :end_inline_select_features } true;assume { :begin_inline_valid_product } true;havoc valid_product_#res#1;havoc valid_product_~retValue_acc~1#1;havoc valid_product_~retValue_acc~1#1;valid_product_~retValue_acc~1#1 := 1;valid_product_#res#1 := valid_product_~retValue_acc~1#1; {1653#(= ~pumpRunning~0 0)} is VALID [2022-02-20 18:11:56,412 INFO L290 TraceCheckUtils]: 4: Hoare triple {1653#(= ~pumpRunning~0 0)} main_#t~ret10#1 := valid_product_#res#1;assume { :end_inline_valid_product } true;assume -2147483648 <= main_#t~ret10#1 && main_#t~ret10#1 <= 2147483647;main_~tmp~0#1 := main_#t~ret10#1;havoc main_#t~ret10#1; {1653#(= ~pumpRunning~0 0)} is VALID [2022-02-20 18:11:56,413 INFO L290 TraceCheckUtils]: 5: Hoare triple {1653#(= ~pumpRunning~0 0)} assume 0 != main_~tmp~0#1;assume { :begin_inline_setup } true; {1653#(= ~pumpRunning~0 0)} is VALID [2022-02-20 18:11:56,413 INFO L290 TraceCheckUtils]: 6: Hoare triple {1653#(= ~pumpRunning~0 0)} assume { :end_inline_setup } true;assume { :begin_inline_runTest } true;assume { :begin_inline___utac_acc__Specification5_spec__1 } true;~switchedOnBeforeTS~0 := 0; {1653#(= ~pumpRunning~0 0)} is VALID [2022-02-20 18:11:56,413 INFO L290 TraceCheckUtils]: 7: Hoare triple {1653#(= ~pumpRunning~0 0)} assume { :end_inline___utac_acc__Specification5_spec__1 } true;assume { :begin_inline_test } true;havoc test_#t~nondet24#1, test_#t~nondet25#1, test_#t~nondet26#1, test_#t~nondet27#1, test_~splverifierCounter~0#1, test_~tmp~5#1, test_~tmp___0~1#1, test_~tmp___1~0#1, test_~tmp___2~0#1;havoc test_~splverifierCounter~0#1;havoc test_~tmp~5#1;havoc test_~tmp___0~1#1;havoc test_~tmp___1~0#1;havoc test_~tmp___2~0#1;test_~splverifierCounter~0#1 := 0; {1653#(= ~pumpRunning~0 0)} is VALID [2022-02-20 18:11:56,414 INFO L290 TraceCheckUtils]: 8: Hoare triple {1653#(= ~pumpRunning~0 0)} assume !false; {1653#(= ~pumpRunning~0 0)} is VALID [2022-02-20 18:11:56,414 INFO L290 TraceCheckUtils]: 9: Hoare triple {1653#(= ~pumpRunning~0 0)} assume test_~splverifierCounter~0#1 < 4; {1653#(= ~pumpRunning~0 0)} is VALID [2022-02-20 18:11:56,415 INFO L290 TraceCheckUtils]: 10: Hoare triple {1653#(= ~pumpRunning~0 0)} assume -2147483648 <= test_#t~nondet24#1 && test_#t~nondet24#1 <= 2147483647;test_~tmp~5#1 := test_#t~nondet24#1;havoc test_#t~nondet24#1; {1653#(= ~pumpRunning~0 0)} is VALID [2022-02-20 18:11:56,415 INFO L290 TraceCheckUtils]: 11: Hoare triple {1653#(= ~pumpRunning~0 0)} assume !(0 != test_~tmp~5#1); {1653#(= ~pumpRunning~0 0)} is VALID [2022-02-20 18:11:56,416 INFO L290 TraceCheckUtils]: 12: Hoare triple {1653#(= ~pumpRunning~0 0)} assume -2147483648 <= test_#t~nondet25#1 && test_#t~nondet25#1 <= 2147483647;test_~tmp___0~1#1 := test_#t~nondet25#1;havoc test_#t~nondet25#1; {1653#(= ~pumpRunning~0 0)} is VALID [2022-02-20 18:11:56,416 INFO L290 TraceCheckUtils]: 13: Hoare triple {1653#(= ~pumpRunning~0 0)} assume !(0 != test_~tmp___0~1#1); {1653#(= ~pumpRunning~0 0)} is VALID [2022-02-20 18:11:56,417 INFO L290 TraceCheckUtils]: 14: Hoare triple {1653#(= ~pumpRunning~0 0)} assume -2147483648 <= test_#t~nondet26#1 && test_#t~nondet26#1 <= 2147483647;test_~tmp___2~0#1 := test_#t~nondet26#1;havoc test_#t~nondet26#1; {1653#(= ~pumpRunning~0 0)} is VALID [2022-02-20 18:11:56,417 INFO L290 TraceCheckUtils]: 15: Hoare triple {1653#(= ~pumpRunning~0 0)} assume 0 != test_~tmp___2~0#1; {1653#(= ~pumpRunning~0 0)} is VALID [2022-02-20 18:11:56,418 INFO L272 TraceCheckUtils]: 16: Hoare triple {1653#(= ~pumpRunning~0 0)} call timeShift(); {1653#(= ~pumpRunning~0 0)} is VALID [2022-02-20 18:11:56,418 INFO L290 TraceCheckUtils]: 17: Hoare triple {1653#(= ~pumpRunning~0 0)} assume { :begin_inline___utac_acc__Specification5_spec__2 } true;havoc __utac_acc__Specification5_spec__2_#t~ret51#1; {1653#(= ~pumpRunning~0 0)} is VALID [2022-02-20 18:11:56,418 INFO L272 TraceCheckUtils]: 18: Hoare triple {1653#(= ~pumpRunning~0 0)} call __utac_acc__Specification5_spec__2_#t~ret51#1 := isPumpRunning(); {1651#true} is VALID [2022-02-20 18:11:56,418 INFO L290 TraceCheckUtils]: 19: Hoare triple {1651#true} havoc ~retValue_acc~7;~retValue_acc~7 := ~pumpRunning~0;#res := ~retValue_acc~7; {1651#true} is VALID [2022-02-20 18:11:56,419 INFO L290 TraceCheckUtils]: 20: Hoare triple {1651#true} assume true; {1651#true} is VALID [2022-02-20 18:11:56,419 INFO L284 TraceCheckUtils]: 21: Hoare quadruple {1651#true} {1653#(= ~pumpRunning~0 0)} #229#return; {1653#(= ~pumpRunning~0 0)} is VALID [2022-02-20 18:11:56,420 INFO L290 TraceCheckUtils]: 22: Hoare triple {1653#(= ~pumpRunning~0 0)} assume -2147483648 <= __utac_acc__Specification5_spec__2_#t~ret51#1 && __utac_acc__Specification5_spec__2_#t~ret51#1 <= 2147483647;~switchedOnBeforeTS~0 := __utac_acc__Specification5_spec__2_#t~ret51#1;havoc __utac_acc__Specification5_spec__2_#t~ret51#1; {1653#(= ~pumpRunning~0 0)} is VALID [2022-02-20 18:11:56,420 INFO L290 TraceCheckUtils]: 23: Hoare triple {1653#(= ~pumpRunning~0 0)} assume { :end_inline___utac_acc__Specification5_spec__2 } true; {1653#(= ~pumpRunning~0 0)} is VALID [2022-02-20 18:11:56,421 INFO L290 TraceCheckUtils]: 24: Hoare triple {1653#(= ~pumpRunning~0 0)} assume !(0 != ~pumpRunning~0); {1653#(= ~pumpRunning~0 0)} is VALID [2022-02-20 18:11:56,421 INFO L290 TraceCheckUtils]: 25: Hoare triple {1653#(= ~pumpRunning~0 0)} assume 0 != ~systemActive~0;assume { :begin_inline_processEnvironment } true;havoc processEnvironment_#t~ret12#1, processEnvironment_~tmp~2#1;havoc processEnvironment_~tmp~2#1; {1653#(= ~pumpRunning~0 0)} is VALID [2022-02-20 18:11:56,422 INFO L290 TraceCheckUtils]: 26: Hoare triple {1653#(= ~pumpRunning~0 0)} assume !(0 != ~pumpRunning~0); {1653#(= ~pumpRunning~0 0)} is VALID [2022-02-20 18:11:56,422 INFO L272 TraceCheckUtils]: 27: Hoare triple {1653#(= ~pumpRunning~0 0)} call processEnvironment__wrappee__methaneQuery(); {1669#(= ~pumpRunning~0 |old(~pumpRunning~0)|)} is VALID [2022-02-20 18:11:56,422 INFO L290 TraceCheckUtils]: 28: Hoare triple {1669#(= ~pumpRunning~0 |old(~pumpRunning~0)|)} havoc ~tmp~1#1; {1651#true} is VALID [2022-02-20 18:11:56,423 INFO L290 TraceCheckUtils]: 29: Hoare triple {1651#true} assume !(0 != ~pumpRunning~0); {1653#(= ~pumpRunning~0 0)} is VALID [2022-02-20 18:11:56,423 INFO L272 TraceCheckUtils]: 30: Hoare triple {1653#(= ~pumpRunning~0 0)} call processEnvironment__wrappee__base(); {1651#true} is VALID [2022-02-20 18:11:56,423 INFO L290 TraceCheckUtils]: 31: Hoare triple {1651#true} assume true; {1651#true} is VALID [2022-02-20 18:11:56,424 INFO L284 TraceCheckUtils]: 32: Hoare quadruple {1651#true} {1653#(= ~pumpRunning~0 0)} #257#return; {1653#(= ~pumpRunning~0 0)} is VALID [2022-02-20 18:11:56,424 INFO L290 TraceCheckUtils]: 33: Hoare triple {1653#(= ~pumpRunning~0 0)} assume true; {1653#(= ~pumpRunning~0 0)} is VALID [2022-02-20 18:11:56,425 INFO L284 TraceCheckUtils]: 34: Hoare quadruple {1653#(= ~pumpRunning~0 0)} {1653#(= ~pumpRunning~0 0)} #237#return; {1653#(= ~pumpRunning~0 0)} is VALID [2022-02-20 18:11:56,425 INFO L290 TraceCheckUtils]: 35: Hoare triple {1653#(= ~pumpRunning~0 0)} assume { :end_inline_processEnvironment } true; {1653#(= ~pumpRunning~0 0)} is VALID [2022-02-20 18:11:56,426 INFO L290 TraceCheckUtils]: 36: Hoare triple {1653#(= ~pumpRunning~0 0)} assume { :begin_inline___utac_acc__Specification5_spec__3 } true;havoc __utac_acc__Specification5_spec__3_#t~ret52#1, __utac_acc__Specification5_spec__3_#t~ret53#1, __utac_acc__Specification5_spec__3_~tmp~9#1, __utac_acc__Specification5_spec__3_~tmp___0~2#1;havoc __utac_acc__Specification5_spec__3_~tmp~9#1;havoc __utac_acc__Specification5_spec__3_~tmp___0~2#1;assume { :begin_inline_getWaterLevel } true;havoc getWaterLevel_#res#1;havoc getWaterLevel_~retValue_acc~3#1;havoc getWaterLevel_~retValue_acc~3#1;getWaterLevel_~retValue_acc~3#1 := ~waterLevel~0;getWaterLevel_#res#1 := getWaterLevel_~retValue_acc~3#1; {1653#(= ~pumpRunning~0 0)} is VALID [2022-02-20 18:11:56,426 INFO L290 TraceCheckUtils]: 37: Hoare triple {1653#(= ~pumpRunning~0 0)} __utac_acc__Specification5_spec__3_#t~ret52#1 := getWaterLevel_#res#1;assume { :end_inline_getWaterLevel } true;assume -2147483648 <= __utac_acc__Specification5_spec__3_#t~ret52#1 && __utac_acc__Specification5_spec__3_#t~ret52#1 <= 2147483647;__utac_acc__Specification5_spec__3_~tmp~9#1 := __utac_acc__Specification5_spec__3_#t~ret52#1;havoc __utac_acc__Specification5_spec__3_#t~ret52#1; {1653#(= ~pumpRunning~0 0)} is VALID [2022-02-20 18:11:56,427 INFO L290 TraceCheckUtils]: 38: Hoare triple {1653#(= ~pumpRunning~0 0)} assume 2 != __utac_acc__Specification5_spec__3_~tmp~9#1; {1653#(= ~pumpRunning~0 0)} is VALID [2022-02-20 18:11:56,427 INFO L272 TraceCheckUtils]: 39: Hoare triple {1653#(= ~pumpRunning~0 0)} call __utac_acc__Specification5_spec__3_#t~ret53#1 := isPumpRunning(); {1651#true} is VALID [2022-02-20 18:11:56,428 INFO L290 TraceCheckUtils]: 40: Hoare triple {1651#true} havoc ~retValue_acc~7;~retValue_acc~7 := ~pumpRunning~0;#res := ~retValue_acc~7; {1672#(= ~pumpRunning~0 |isPumpRunning_#res|)} is VALID [2022-02-20 18:11:56,428 INFO L290 TraceCheckUtils]: 41: Hoare triple {1672#(= ~pumpRunning~0 |isPumpRunning_#res|)} assume true; {1672#(= ~pumpRunning~0 |isPumpRunning_#res|)} is VALID [2022-02-20 18:11:56,429 INFO L284 TraceCheckUtils]: 42: Hoare quadruple {1672#(= ~pumpRunning~0 |isPumpRunning_#res|)} {1653#(= ~pumpRunning~0 0)} #239#return; {1667#(= 0 |timeShift___utac_acc__Specification5_spec__3_#t~ret53#1|)} is VALID [2022-02-20 18:11:56,430 INFO L290 TraceCheckUtils]: 43: Hoare triple {1667#(= 0 |timeShift___utac_acc__Specification5_spec__3_#t~ret53#1|)} assume -2147483648 <= __utac_acc__Specification5_spec__3_#t~ret53#1 && __utac_acc__Specification5_spec__3_#t~ret53#1 <= 2147483647;__utac_acc__Specification5_spec__3_~tmp___0~2#1 := __utac_acc__Specification5_spec__3_#t~ret53#1;havoc __utac_acc__Specification5_spec__3_#t~ret53#1; {1668#(= |timeShift___utac_acc__Specification5_spec__3_~tmp___0~2#1| 0)} is VALID [2022-02-20 18:11:56,431 INFO L290 TraceCheckUtils]: 44: Hoare triple {1668#(= |timeShift___utac_acc__Specification5_spec__3_~tmp___0~2#1| 0)} assume 0 != __utac_acc__Specification5_spec__3_~tmp___0~2#1; {1652#false} is VALID [2022-02-20 18:11:56,431 INFO L290 TraceCheckUtils]: 45: Hoare triple {1652#false} assume 0 == ~switchedOnBeforeTS~0;assume { :begin_inline___automaton_fail } true; {1652#false} is VALID [2022-02-20 18:11:56,431 INFO L290 TraceCheckUtils]: 46: Hoare triple {1652#false} assume !false; {1652#false} is VALID [2022-02-20 18:11:56,432 INFO L134 CoverageAnalysis]: Checked inductivity of 3 backedges. 2 proven. 0 refuted. 0 times theorem prover too weak. 1 trivial. 0 not checked. [2022-02-20 18:11:56,433 INFO L144 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2022-02-20 18:11:56,433 INFO L338 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [1030460111] [2022-02-20 18:11:56,433 INFO L165 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [1030460111] provided 1 perfect and 0 imperfect interpolant sequences [2022-02-20 18:11:56,433 INFO L191 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2022-02-20 18:11:56,434 INFO L204 FreeRefinementEngine]: Number of different interpolants: perfect sequences [7] imperfect sequences [] total 7 [2022-02-20 18:11:56,434 INFO L118 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [241291439] [2022-02-20 18:11:56,434 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2022-02-20 18:11:56,435 INFO L78 Accepts]: Start accepts. Automaton has has 7 states, 7 states have (on average 5.428571428571429) internal successors, (38), 5 states have internal predecessors, (38), 1 states have call successors, (5), 3 states have call predecessors, (5), 3 states have return successors, (4), 2 states have call predecessors, (4), 1 states have call successors, (4) Word has length 47 [2022-02-20 18:11:56,436 INFO L84 Accepts]: Finished accepts. word is accepted. [2022-02-20 18:11:56,436 INFO L86 InductivityCheck]: Starting indutivity check of a Floyd-Hoare automaton with has 7 states, 7 states have (on average 5.428571428571429) internal successors, (38), 5 states have internal predecessors, (38), 1 states have call successors, (5), 3 states have call predecessors, (5), 3 states have return successors, (4), 2 states have call predecessors, (4), 1 states have call successors, (4) [2022-02-20 18:11:56,473 INFO L122 InductivityCheck]: Floyd-Hoare automaton has 47 edges. 47 inductive. 0 not inductive. 0 times theorem prover too weak to decide inductivity. [2022-02-20 18:11:56,473 INFO L546 AbstractCegarLoop]: INTERPOLANT automaton has 7 states [2022-02-20 18:11:56,474 INFO L108 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2022-02-20 18:11:56,475 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 7 interpolants. [2022-02-20 18:11:56,475 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=11, Invalid=31, Unknown=0, NotChecked=0, Total=42 [2022-02-20 18:11:56,475 INFO L87 Difference]: Start difference. First operand 78 states and 97 transitions. Second operand has 7 states, 7 states have (on average 5.428571428571429) internal successors, (38), 5 states have internal predecessors, (38), 1 states have call successors, (5), 3 states have call predecessors, (5), 3 states have return successors, (4), 2 states have call predecessors, (4), 1 states have call successors, (4) [2022-02-20 18:11:56,791 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-02-20 18:11:56,792 INFO L93 Difference]: Finished difference Result 127 states and 160 transitions. [2022-02-20 18:11:56,792 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 7 states. [2022-02-20 18:11:56,792 INFO L78 Accepts]: Start accepts. Automaton has has 7 states, 7 states have (on average 5.428571428571429) internal successors, (38), 5 states have internal predecessors, (38), 1 states have call successors, (5), 3 states have call predecessors, (5), 3 states have return successors, (4), 2 states have call predecessors, (4), 1 states have call successors, (4) Word has length 47 [2022-02-20 18:11:56,792 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2022-02-20 18:11:56,793 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 7 states, 7 states have (on average 5.428571428571429) internal successors, (38), 5 states have internal predecessors, (38), 1 states have call successors, (5), 3 states have call predecessors, (5), 3 states have return successors, (4), 2 states have call predecessors, (4), 1 states have call successors, (4) [2022-02-20 18:11:56,795 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 7 states to 7 states and 160 transitions. [2022-02-20 18:11:56,796 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 7 states, 7 states have (on average 5.428571428571429) internal successors, (38), 5 states have internal predecessors, (38), 1 states have call successors, (5), 3 states have call predecessors, (5), 3 states have return successors, (4), 2 states have call predecessors, (4), 1 states have call successors, (4) [2022-02-20 18:11:56,798 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 7 states to 7 states and 160 transitions. [2022-02-20 18:11:56,798 INFO L86 InductivityCheck]: Starting indutivity check of a Floyd-Hoare automaton with 7 states and 160 transitions. [2022-02-20 18:11:56,926 INFO L122 InductivityCheck]: Floyd-Hoare automaton has 160 edges. 160 inductive. 0 not inductive. 0 times theorem prover too weak to decide inductivity. [2022-02-20 18:11:56,927 INFO L225 Difference]: With dead ends: 127 [2022-02-20 18:11:56,927 INFO L226 Difference]: Without dead ends: 0 [2022-02-20 18:11:56,928 INFO L932 BasicCegarLoop]: 0 DeclaredPredicates, 20 GetRequests, 11 SyntacticMatches, 0 SemanticMatches, 9 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 3 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=33, Invalid=77, Unknown=0, NotChecked=0, Total=110 [2022-02-20 18:11:56,937 INFO L933 BasicCegarLoop]: 51 mSDtfsCounter, 50 mSDsluCounter, 137 mSDsCounter, 0 mSdLazyCounter, 90 mSolverCounterSat, 21 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.1s Time, 0 mProtectedPredicate, 0 mProtectedAction, 52 SdHoareTripleChecker+Valid, 188 SdHoareTripleChecker+Invalid, 111 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 21 IncrementalHoareTripleChecker+Valid, 90 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.1s IncrementalHoareTripleChecker+Time [2022-02-20 18:11:56,939 INFO L934 BasicCegarLoop]: SdHoareTripleChecker [52 Valid, 188 Invalid, 111 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [21 Valid, 90 Invalid, 0 Unknown, 0 Unchecked, 0.1s Time] [2022-02-20 18:11:56,941 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 0 states. [2022-02-20 18:11:56,941 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 0 to 0. [2022-02-20 18:11:56,941 INFO L214 AbstractMinimizeNwa]: Start testing correctness of minimizeSevpa [2022-02-20 18:11:56,942 INFO L82 GeneralOperation]: Start isEquivalent. First operand 0 states. Second operand has 0 states, 0 states have (on average 0.0) internal successors, (0), 0 states have internal predecessors, (0), 0 states have call successors, (0), 0 states have call predecessors, (0), 0 states have return successors, (0), 0 states have call predecessors, (0), 0 states have call successors, (0) [2022-02-20 18:11:56,944 INFO L74 IsIncluded]: Start isIncluded. First operand 0 states. Second operand has 0 states, 0 states have (on average 0.0) internal successors, (0), 0 states have internal predecessors, (0), 0 states have call successors, (0), 0 states have call predecessors, (0), 0 states have return successors, (0), 0 states have call predecessors, (0), 0 states have call successors, (0) [2022-02-20 18:11:56,944 INFO L87 Difference]: Start difference. First operand 0 states. Second operand has 0 states, 0 states have (on average 0.0) internal successors, (0), 0 states have internal predecessors, (0), 0 states have call successors, (0), 0 states have call predecessors, (0), 0 states have return successors, (0), 0 states have call predecessors, (0), 0 states have call successors, (0) [2022-02-20 18:11:56,944 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-02-20 18:11:56,945 INFO L93 Difference]: Finished difference Result 0 states and 0 transitions. [2022-02-20 18:11:56,945 INFO L276 IsEmpty]: Start isEmpty. Operand 0 states and 0 transitions. [2022-02-20 18:11:56,945 INFO L282 IsEmpty]: Finished isEmpty. No accepting run. [2022-02-20 18:11:56,945 INFO L83 IsIncluded]: Finished isIncluded. Language is included [2022-02-20 18:11:56,945 INFO L74 IsIncluded]: Start isIncluded. First operand has 0 states, 0 states have (on average 0.0) internal successors, (0), 0 states have internal predecessors, (0), 0 states have call successors, (0), 0 states have call predecessors, (0), 0 states have return successors, (0), 0 states have call predecessors, (0), 0 states have call successors, (0) Second operand 0 states. [2022-02-20 18:11:56,945 INFO L87 Difference]: Start difference. First operand has 0 states, 0 states have (on average 0.0) internal successors, (0), 0 states have internal predecessors, (0), 0 states have call successors, (0), 0 states have call predecessors, (0), 0 states have return successors, (0), 0 states have call predecessors, (0), 0 states have call successors, (0) Second operand 0 states. [2022-02-20 18:11:56,946 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-02-20 18:11:56,946 INFO L93 Difference]: Finished difference Result 0 states and 0 transitions. [2022-02-20 18:11:56,946 INFO L276 IsEmpty]: Start isEmpty. Operand 0 states and 0 transitions. [2022-02-20 18:11:56,946 INFO L282 IsEmpty]: Finished isEmpty. No accepting run. [2022-02-20 18:11:56,946 INFO L83 IsIncluded]: Finished isIncluded. Language is included [2022-02-20 18:11:56,946 INFO L88 GeneralOperation]: Finished isEquivalent. [2022-02-20 18:11:56,946 INFO L221 AbstractMinimizeNwa]: Finished testing correctness of minimizeSevpa [2022-02-20 18:11:56,947 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 0 states, 0 states have (on average 0.0) internal successors, (0), 0 states have internal predecessors, (0), 0 states have call successors, (0), 0 states have call predecessors, (0), 0 states have return successors, (0), 0 states have call predecessors, (0), 0 states have call successors, (0) [2022-02-20 18:11:56,947 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 0 states to 0 states and 0 transitions. [2022-02-20 18:11:56,947 INFO L78 Accepts]: Start accepts. Automaton has 0 states and 0 transitions. Word has length 47 [2022-02-20 18:11:56,947 INFO L84 Accepts]: Finished accepts. word is rejected. [2022-02-20 18:11:56,947 INFO L470 AbstractCegarLoop]: Abstraction has 0 states and 0 transitions. [2022-02-20 18:11:56,948 INFO L471 AbstractCegarLoop]: INTERPOLANT automaton has has 7 states, 7 states have (on average 5.428571428571429) internal successors, (38), 5 states have internal predecessors, (38), 1 states have call successors, (5), 3 states have call predecessors, (5), 3 states have return successors, (4), 2 states have call predecessors, (4), 1 states have call successors, (4) [2022-02-20 18:11:56,948 INFO L276 IsEmpty]: Start isEmpty. Operand 0 states and 0 transitions. [2022-02-20 18:11:56,948 INFO L282 IsEmpty]: Finished isEmpty. No accepting run. [2022-02-20 18:11:56,952 INFO L764 garLoopResultBuilder]: Registering result SAFE for location timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION (0 of 1 remaining) [2022-02-20 18:11:56,952 WARN L452 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable3 [2022-02-20 18:11:56,954 INFO L343 DoubleDeckerVisitor]: Before removal of dead ends 0 states and 0 transitions. [2022-02-20 18:11:57,252 INFO L861 garLoopResultBuilder]: At program point deactivatePumpENTRY(lines 413 420) the Hoare annotation is: true [2022-02-20 18:11:57,252 INFO L858 garLoopResultBuilder]: For program point deactivatePumpEXIT(lines 413 420) no Hoare annotation was computed. [2022-02-20 18:11:57,252 INFO L858 garLoopResultBuilder]: For program point deactivatePumpFINAL(lines 413 420) no Hoare annotation was computed. [2022-02-20 18:11:57,252 INFO L858 garLoopResultBuilder]: For program point processEnvironment__wrappee__baseEXIT(lines 329 335) no Hoare annotation was computed. [2022-02-20 18:11:57,253 INFO L861 garLoopResultBuilder]: At program point processEnvironment__wrappee__baseFINAL(lines 329 335) the Hoare annotation is: true [2022-02-20 18:11:57,253 INFO L861 garLoopResultBuilder]: At program point changeMethaneLevelENTRY(lines 130 141) the Hoare annotation is: true [2022-02-20 18:11:57,253 INFO L858 garLoopResultBuilder]: For program point changeMethaneLevelEXIT(lines 130 141) no Hoare annotation was computed. [2022-02-20 18:11:57,253 INFO L858 garLoopResultBuilder]: For program point L134-1(lines 130 141) no Hoare annotation was computed. [2022-02-20 18:11:57,253 INFO L858 garLoopResultBuilder]: For program point L960(lines 960 966) no Hoare annotation was computed. [2022-02-20 18:11:57,253 INFO L854 garLoopResultBuilder]: At program point L382(line 382) the Hoare annotation is: (or (not (= |old(~pumpRunning~0)| 0)) (= ~pumpRunning~0 0) (not (= 1 ~systemActive~0))) [2022-02-20 18:11:57,254 INFO L854 garLoopResultBuilder]: At program point L382-1(lines 363 387) the Hoare annotation is: (or (not (= |old(~pumpRunning~0)| 0)) (= ~pumpRunning~0 0) (not (= 1 ~systemActive~0))) [2022-02-20 18:11:57,254 INFO L854 garLoopResultBuilder]: At program point L93(lines 88 95) the Hoare annotation is: (or (not (= |old(~pumpRunning~0)| 0)) (not (= 1 ~systemActive~0))) [2022-02-20 18:11:57,254 INFO L858 garLoopResultBuilder]: For program point L316-1(lines 316 322) no Hoare annotation was computed. [2022-02-20 18:11:57,254 INFO L854 garLoopResultBuilder]: At program point L944(lines 937 946) the Hoare annotation is: (or (not (= |old(~pumpRunning~0)| 0)) (= ~pumpRunning~0 0) (not (= 1 ~systemActive~0))) [2022-02-20 18:11:57,254 INFO L858 garLoopResultBuilder]: For program point L110(lines 110 114) no Hoare annotation was computed. [2022-02-20 18:11:57,254 INFO L854 garLoopResultBuilder]: At program point L110-2(lines 106 117) the Hoare annotation is: (or (not (= |old(~pumpRunning~0)| 0)) (not (= 1 ~systemActive~0))) [2022-02-20 18:11:57,255 INFO L858 garLoopResultBuilder]: For program point timeShiftFINAL(lines 302 328) no Hoare annotation was computed. [2022-02-20 18:11:57,255 INFO L854 garLoopResultBuilder]: At program point L957(line 957) the Hoare annotation is: (or (not (= |old(~pumpRunning~0)| 0)) (= ~pumpRunning~0 0) (not (= 1 ~systemActive~0))) [2022-02-20 18:11:57,255 INFO L858 garLoopResultBuilder]: For program point L957-1(line 957) no Hoare annotation was computed. [2022-02-20 18:11:57,255 INFO L858 garLoopResultBuilder]: For program point L309(lines 309 315) no Hoare annotation was computed. [2022-02-20 18:11:57,255 INFO L858 garLoopResultBuilder]: For program point L309-2(lines 305 327) no Hoare annotation was computed. [2022-02-20 18:11:57,255 INFO L858 garLoopResultBuilder]: For program point L371(lines 371 379) no Hoare annotation was computed. [2022-02-20 18:11:57,255 INFO L858 garLoopResultBuilder]: For program point L367(lines 367 384) no Hoare annotation was computed. [2022-02-20 18:11:57,256 INFO L854 garLoopResultBuilder]: At program point L942(line 942) the Hoare annotation is: (or (not (= |old(~pumpRunning~0)| 0)) (= ~pumpRunning~0 0) (not (= 1 ~systemActive~0))) [2022-02-20 18:11:57,256 INFO L858 garLoopResultBuilder]: For program point L942-1(line 942) no Hoare annotation was computed. [2022-02-20 18:11:57,256 INFO L858 garLoopResultBuilder]: For program point L959(lines 959 969) no Hoare annotation was computed. [2022-02-20 18:11:57,256 INFO L858 garLoopResultBuilder]: For program point L92(line 92) no Hoare annotation was computed. [2022-02-20 18:11:57,256 INFO L858 garLoopResultBuilder]: For program point L955(lines 955 972) no Hoare annotation was computed. [2022-02-20 18:11:57,256 INFO L854 garLoopResultBuilder]: At program point L955-1(lines 947 975) the Hoare annotation is: (or (not (= |old(~pumpRunning~0)| 0)) (= ~pumpRunning~0 0) (not (= 1 ~systemActive~0))) [2022-02-20 18:11:57,256 INFO L854 garLoopResultBuilder]: At program point L377(line 377) the Hoare annotation is: (or (not (= |old(~pumpRunning~0)| 0)) (not (= 1 ~systemActive~0))) [2022-02-20 18:11:57,256 INFO L854 garLoopResultBuilder]: At program point L373(line 373) the Hoare annotation is: (or (not (= |old(~pumpRunning~0)| 0)) (not (= 1 ~systemActive~0))) [2022-02-20 18:11:57,257 INFO L854 garLoopResultBuilder]: At program point L179(lines 174 182) the Hoare annotation is: (or (not (= |old(~pumpRunning~0)| 0)) (= ~pumpRunning~0 0) (not (= 1 ~systemActive~0))) [2022-02-20 18:11:57,257 INFO L854 garLoopResultBuilder]: At program point L369(line 369) the Hoare annotation is: (or (not (= |old(~pumpRunning~0)| 0)) (not (= 1 ~systemActive~0))) [2022-02-20 18:11:57,257 INFO L858 garLoopResultBuilder]: For program point L369-1(line 369) no Hoare annotation was computed. [2022-02-20 18:11:57,257 INFO L854 garLoopResultBuilder]: At program point timeShiftENTRY(lines 302 328) the Hoare annotation is: (or (not (= |old(~pumpRunning~0)| 0)) (= ~pumpRunning~0 0) (not (= 1 ~systemActive~0))) [2022-02-20 18:11:57,257 INFO L858 garLoopResultBuilder]: For program point timeShiftEXIT(lines 302 328) no Hoare annotation was computed. [2022-02-20 18:11:57,257 INFO L858 garLoopResultBuilder]: For program point timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION(line 92) no Hoare annotation was computed. [2022-02-20 18:11:57,258 INFO L858 garLoopResultBuilder]: For program point cleanupEXIT(lines 195 224) no Hoare annotation was computed. [2022-02-20 18:11:57,258 INFO L861 garLoopResultBuilder]: At program point cleanupENTRY(lines 195 224) the Hoare annotation is: true [2022-02-20 18:11:57,258 INFO L861 garLoopResultBuilder]: At program point L220(lines 195 224) the Hoare annotation is: true [2022-02-20 18:11:57,258 INFO L858 garLoopResultBuilder]: For program point L216(line 216) no Hoare annotation was computed. [2022-02-20 18:11:57,258 INFO L858 garLoopResultBuilder]: For program point L209(lines 209 213) no Hoare annotation was computed. [2022-02-20 18:11:57,258 INFO L861 garLoopResultBuilder]: At program point L209-1(lines 209 213) the Hoare annotation is: true [2022-02-20 18:11:57,258 INFO L858 garLoopResultBuilder]: For program point L206(line 206) no Hoare annotation was computed. [2022-02-20 18:11:57,258 INFO L861 garLoopResultBuilder]: At program point L205-2(lines 205 219) the Hoare annotation is: true [2022-02-20 18:11:57,259 INFO L861 garLoopResultBuilder]: At program point L201(line 201) the Hoare annotation is: true [2022-02-20 18:11:57,259 INFO L858 garLoopResultBuilder]: For program point L201-1(line 201) no Hoare annotation was computed. [2022-02-20 18:11:57,259 INFO L858 garLoopResultBuilder]: For program point L543(lines 543 547) no Hoare annotation was computed. [2022-02-20 18:11:57,259 INFO L854 garLoopResultBuilder]: At program point L254(lines 250 256) the Hoare annotation is: (and (= |ULTIMATE.start_main_~tmp~0#1| ~systemActive~0) (= ~pumpRunning~0 0) (= 1 ~systemActive~0) (= |ULTIMATE.start_valid_product_#res#1| ~systemActive~0)) [2022-02-20 18:11:57,259 INFO L854 garLoopResultBuilder]: At program point L543-2(lines 537 548) the Hoare annotation is: (and (= |ULTIMATE.start_main_~tmp~0#1| ~systemActive~0) (= ~pumpRunning~0 0) (= 1 ~systemActive~0) (= |ULTIMATE.start_valid_product_#res#1| ~systemActive~0) (= |ULTIMATE.start_test_~splverifierCounter~0#1| 0)) [2022-02-20 18:11:57,259 INFO L858 garLoopResultBuilder]: For program point L527(lines 527 533) no Hoare annotation was computed. [2022-02-20 18:11:57,259 INFO L858 garLoopResultBuilder]: For program point L527-1(lines 527 533) no Hoare annotation was computed. [2022-02-20 18:11:57,260 INFO L861 garLoopResultBuilder]: At program point L556(lines 497 560) the Hoare annotation is: true [2022-02-20 18:11:57,260 INFO L861 garLoopResultBuilder]: At program point L267(lines 259 269) the Hoare annotation is: true [2022-02-20 18:11:57,260 INFO L854 garLoopResultBuilder]: At program point L519(line 519) the Hoare annotation is: (and (= |ULTIMATE.start_main_~tmp~0#1| ~systemActive~0) (= ~pumpRunning~0 0) (= 1 ~systemActive~0) (= |ULTIMATE.start_valid_product_#res#1| ~systemActive~0) (= |ULTIMATE.start_test_~splverifierCounter~0#1| 0)) [2022-02-20 18:11:57,260 INFO L858 garLoopResultBuilder]: For program point L-1(line -1) no Hoare annotation was computed. [2022-02-20 18:11:57,260 INFO L858 garLoopResultBuilder]: For program point ULTIMATE.startENTRY(line -1) no Hoare annotation was computed. [2022-02-20 18:11:57,260 INFO L858 garLoopResultBuilder]: For program point ULTIMATE.startFINAL(line -1) no Hoare annotation was computed. [2022-02-20 18:11:57,260 INFO L858 garLoopResultBuilder]: For program point L280(lines 280 287) no Hoare annotation was computed. [2022-02-20 18:11:57,261 INFO L858 garLoopResultBuilder]: For program point L280-2(lines 280 287) no Hoare annotation was computed. [2022-02-20 18:11:57,261 INFO L854 garLoopResultBuilder]: At program point L553(lines 506 554) the Hoare annotation is: false [2022-02-20 18:11:57,261 INFO L861 garLoopResultBuilder]: At program point L289(lines 270 292) the Hoare annotation is: true [2022-02-20 18:11:57,261 INFO L858 garLoopResultBuilder]: For program point ULTIMATE.startEXIT(line -1) no Hoare annotation was computed. [2022-02-20 18:11:57,261 INFO L858 garLoopResultBuilder]: For program point L508(lines 507 552) no Hoare annotation was computed. [2022-02-20 18:11:57,261 INFO L858 garLoopResultBuilder]: For program point L537(lines 537 548) no Hoare annotation was computed. [2022-02-20 18:11:57,261 INFO L854 garLoopResultBuilder]: At program point L83(lines 78 86) the Hoare annotation is: (and (= ~pumpRunning~0 0) (= 1 ~systemActive~0) (= |ULTIMATE.start_valid_product_#res#1| ~systemActive~0)) [2022-02-20 18:11:57,261 INFO L854 garLoopResultBuilder]: At program point L529(line 529) the Hoare annotation is: (and (= |ULTIMATE.start_main_~tmp~0#1| ~systemActive~0) (= ~pumpRunning~0 0) (= 1 ~systemActive~0) (= |ULTIMATE.start_valid_product_#res#1| ~systemActive~0) (= |ULTIMATE.start_test_~splverifierCounter~0#1| 0)) [2022-02-20 18:11:57,262 INFO L854 garLoopResultBuilder]: At program point L75(lines 71 77) the Hoare annotation is: (and (= ~pumpRunning~0 0) (= 1 ~systemActive~0)) [2022-02-20 18:11:57,262 INFO L854 garLoopResultBuilder]: At program point L934(lines 929 936) the Hoare annotation is: (and (= |ULTIMATE.start_main_~tmp~0#1| ~systemActive~0) (= ~pumpRunning~0 0) (= 1 ~systemActive~0) (= |ULTIMATE.start_valid_product_#res#1| ~systemActive~0)) [2022-02-20 18:11:57,262 INFO L854 garLoopResultBuilder]: At program point L550(lines 507 552) the Hoare annotation is: (and (= |ULTIMATE.start_main_~tmp~0#1| ~systemActive~0) (= ~pumpRunning~0 0) (= 1 ~systemActive~0) (= |ULTIMATE.start_valid_product_#res#1| ~systemActive~0) (= |ULTIMATE.start_test_~splverifierCounter~0#1| 0)) [2022-02-20 18:11:57,262 INFO L858 garLoopResultBuilder]: For program point L517(lines 517 523) no Hoare annotation was computed. [2022-02-20 18:11:57,262 INFO L858 garLoopResultBuilder]: For program point L517-1(lines 517 523) no Hoare annotation was computed. [2022-02-20 18:11:57,262 INFO L858 garLoopResultBuilder]: For program point L509(lines 509 513) no Hoare annotation was computed. [2022-02-20 18:11:57,263 INFO L854 garLoopResultBuilder]: At program point L68(lines 64 70) the Hoare annotation is: (and (= ~pumpRunning~0 0) (= 1 ~systemActive~0)) [2022-02-20 18:11:57,263 INFO L858 garLoopResultBuilder]: For program point waterRiseEXIT(lines 118 129) no Hoare annotation was computed. [2022-02-20 18:11:57,263 INFO L858 garLoopResultBuilder]: For program point L122-1(lines 118 129) no Hoare annotation was computed. [2022-02-20 18:11:57,263 INFO L861 garLoopResultBuilder]: At program point waterRiseENTRY(lines 118 129) the Hoare annotation is: true [2022-02-20 18:11:57,263 INFO L854 garLoopResultBuilder]: At program point L351(line 351) the Hoare annotation is: (or (not (= |old(~pumpRunning~0)| 0)) (not (= 1 ~systemActive~0))) [2022-02-20 18:11:57,263 INFO L854 garLoopResultBuilder]: At program point L188(lines 183 191) the Hoare annotation is: (or (not (= |old(~pumpRunning~0)| 0)) (not (= 1 ~systemActive~0))) [2022-02-20 18:11:57,263 INFO L854 garLoopResultBuilder]: At program point L347(line 347) the Hoare annotation is: (or (not (= |old(~pumpRunning~0)| 0)) (not (= 1 ~systemActive~0))) [2022-02-20 18:11:57,264 INFO L858 garLoopResultBuilder]: For program point L345(lines 345 353) no Hoare annotation was computed. [2022-02-20 18:11:57,264 INFO L858 garLoopResultBuilder]: For program point L341(lines 341 358) no Hoare annotation was computed. [2022-02-20 18:11:57,264 INFO L854 garLoopResultBuilder]: At program point L492(lines 477 495) the Hoare annotation is: (or (not (= |old(~pumpRunning~0)| 0)) (not (= 1 ~systemActive~0))) [2022-02-20 18:11:57,264 INFO L858 garLoopResultBuilder]: For program point L486(lines 486 490) no Hoare annotation was computed. [2022-02-20 18:11:57,264 INFO L858 garLoopResultBuilder]: For program point L486-2(lines 486 490) no Hoare annotation was computed. [2022-02-20 18:11:57,264 INFO L854 garLoopResultBuilder]: At program point L356(line 356) the Hoare annotation is: (or (not (= |old(~pumpRunning~0)| 0)) (= ~pumpRunning~0 0) (not (= 1 ~systemActive~0))) [2022-02-20 18:11:57,264 INFO L858 garLoopResultBuilder]: For program point L356-1(lines 337 361) no Hoare annotation was computed. [2022-02-20 18:11:57,265 INFO L854 garLoopResultBuilder]: At program point processEnvironment__wrappee__methaneQueryENTRY(lines 337 361) the Hoare annotation is: (or (not (= |old(~pumpRunning~0)| 0)) (= ~pumpRunning~0 0) (not (= 1 ~systemActive~0))) [2022-02-20 18:11:57,265 INFO L858 garLoopResultBuilder]: For program point processEnvironment__wrappee__methaneQueryEXIT(lines 337 361) no Hoare annotation was computed. [2022-02-20 18:11:57,265 INFO L858 garLoopResultBuilder]: For program point isPumpRunningEXIT(lines 432 440) no Hoare annotation was computed. [2022-02-20 18:11:57,265 INFO L861 garLoopResultBuilder]: At program point isPumpRunningENTRY(lines 432 440) the Hoare annotation is: true [2022-02-20 18:11:57,265 INFO L858 garLoopResultBuilder]: For program point isPumpRunningFINAL(lines 432 440) no Hoare annotation was computed. [2022-02-20 18:11:57,265 INFO L861 garLoopResultBuilder]: At program point isMethaneAlarmENTRY(lines 421 431) the Hoare annotation is: true [2022-02-20 18:11:57,265 INFO L858 garLoopResultBuilder]: For program point isMethaneAlarmEXIT(lines 421 431) no Hoare annotation was computed. [2022-02-20 18:11:57,265 INFO L858 garLoopResultBuilder]: For program point isMethaneAlarmFINAL(lines 421 431) no Hoare annotation was computed. [2022-02-20 18:11:57,266 INFO L861 garLoopResultBuilder]: At program point L147(lines 142 150) the Hoare annotation is: true [2022-02-20 18:11:57,268 INFO L732 BasicCegarLoop]: Path program histogram: [1, 1, 1, 1] [2022-02-20 18:11:57,269 INFO L180 ceAbstractionStarter]: Computing trace abstraction results [2022-02-20 18:11:57,272 WARN L170 areAnnotationChecker]: deactivatePumpFINAL has no Hoare annotation [2022-02-20 18:11:57,272 WARN L170 areAnnotationChecker]: processEnvironment__wrappee__baseEXIT has no Hoare annotation [2022-02-20 18:11:57,272 WARN L170 areAnnotationChecker]: L134-1 has no Hoare annotation [2022-02-20 18:11:57,272 WARN L170 areAnnotationChecker]: L134-1 has no Hoare annotation [2022-02-20 18:11:57,273 WARN L170 areAnnotationChecker]: ULTIMATE.startENTRY has no Hoare annotation [2022-02-20 18:11:57,273 WARN L170 areAnnotationChecker]: L122-1 has no Hoare annotation [2022-02-20 18:11:57,273 WARN L170 areAnnotationChecker]: L122-1 has no Hoare annotation [2022-02-20 18:11:57,274 WARN L170 areAnnotationChecker]: L341 has no Hoare annotation [2022-02-20 18:11:57,274 WARN L170 areAnnotationChecker]: isPumpRunningFINAL has no Hoare annotation [2022-02-20 18:11:57,274 WARN L170 areAnnotationChecker]: deactivatePumpFINAL has no Hoare annotation [2022-02-20 18:11:57,274 WARN L170 areAnnotationChecker]: processEnvironment__wrappee__baseEXIT has no Hoare annotation [2022-02-20 18:11:57,274 WARN L170 areAnnotationChecker]: processEnvironment__wrappee__baseEXIT has no Hoare annotation [2022-02-20 18:11:57,274 WARN L170 areAnnotationChecker]: L134-1 has no Hoare annotation [2022-02-20 18:11:57,274 WARN L170 areAnnotationChecker]: L942-1 has no Hoare annotation [2022-02-20 18:11:57,274 WARN L170 areAnnotationChecker]: L201-1 has no Hoare annotation [2022-02-20 18:11:57,275 WARN L170 areAnnotationChecker]: L-1 has no Hoare annotation [2022-02-20 18:11:57,275 WARN L170 areAnnotationChecker]: L122-1 has no Hoare annotation [2022-02-20 18:11:57,275 WARN L170 areAnnotationChecker]: L341 has no Hoare annotation [2022-02-20 18:11:57,275 WARN L170 areAnnotationChecker]: L341 has no Hoare annotation [2022-02-20 18:11:57,275 WARN L170 areAnnotationChecker]: isPumpRunningFINAL has no Hoare annotation [2022-02-20 18:11:57,275 WARN L170 areAnnotationChecker]: isMethaneAlarmFINAL has no Hoare annotation [2022-02-20 18:11:57,276 WARN L170 areAnnotationChecker]: deactivatePumpEXIT has no Hoare annotation [2022-02-20 18:11:57,276 WARN L170 areAnnotationChecker]: deactivatePumpEXIT has no Hoare annotation [2022-02-20 18:11:57,276 WARN L170 areAnnotationChecker]: L356-1 has no Hoare annotation [2022-02-20 18:11:57,276 WARN L170 areAnnotationChecker]: changeMethaneLevelEXIT has no Hoare annotation [2022-02-20 18:11:57,276 WARN L170 areAnnotationChecker]: L942-1 has no Hoare annotation [2022-02-20 18:11:57,276 WARN L170 areAnnotationChecker]: L201-1 has no Hoare annotation [2022-02-20 18:11:57,277 WARN L170 areAnnotationChecker]: waterRiseEXIT has no Hoare annotation [2022-02-20 18:11:57,277 WARN L170 areAnnotationChecker]: L486 has no Hoare annotation [2022-02-20 18:11:57,277 WARN L170 areAnnotationChecker]: L356-1 has no Hoare annotation [2022-02-20 18:11:57,277 WARN L170 areAnnotationChecker]: isPumpRunningEXIT has no Hoare annotation [2022-02-20 18:11:57,277 WARN L170 areAnnotationChecker]: isPumpRunningEXIT has no Hoare annotation [2022-02-20 18:11:57,277 WARN L170 areAnnotationChecker]: isMethaneAlarmFINAL has no Hoare annotation [2022-02-20 18:11:57,277 WARN L170 areAnnotationChecker]: L316-1 has no Hoare annotation [2022-02-20 18:11:57,277 WARN L170 areAnnotationChecker]: processEnvironment__wrappee__methaneQueryEXIT has no Hoare annotation [2022-02-20 18:11:57,277 WARN L170 areAnnotationChecker]: processEnvironment__wrappee__methaneQueryEXIT has no Hoare annotation [2022-02-20 18:11:57,278 WARN L170 areAnnotationChecker]: L527-1 has no Hoare annotation [2022-02-20 18:11:57,278 WARN L170 areAnnotationChecker]: L309 has no Hoare annotation [2022-02-20 18:11:57,278 WARN L170 areAnnotationChecker]: L206 has no Hoare annotation [2022-02-20 18:11:57,278 WARN L170 areAnnotationChecker]: L517-1 has no Hoare annotation [2022-02-20 18:11:57,278 WARN L170 areAnnotationChecker]: L486 has no Hoare annotation [2022-02-20 18:11:57,278 WARN L170 areAnnotationChecker]: L486 has no Hoare annotation [2022-02-20 18:11:57,279 WARN L170 areAnnotationChecker]: L957-1 has no Hoare annotation [2022-02-20 18:11:57,279 WARN L170 areAnnotationChecker]: isMethaneAlarmEXIT has no Hoare annotation [2022-02-20 18:11:57,279 WARN L170 areAnnotationChecker]: L316-1 has no Hoare annotation [2022-02-20 18:11:57,279 WARN L170 areAnnotationChecker]: L537 has no Hoare annotation [2022-02-20 18:11:57,279 WARN L170 areAnnotationChecker]: L537 has no Hoare annotation [2022-02-20 18:11:57,279 WARN L170 areAnnotationChecker]: L309 has no Hoare annotation [2022-02-20 18:11:57,279 WARN L170 areAnnotationChecker]: L309 has no Hoare annotation [2022-02-20 18:11:57,279 WARN L170 areAnnotationChecker]: cleanupEXIT has no Hoare annotation [2022-02-20 18:11:57,279 WARN L170 areAnnotationChecker]: L206 has no Hoare annotation [2022-02-20 18:11:57,280 WARN L170 areAnnotationChecker]: L280 has no Hoare annotation [2022-02-20 18:11:57,280 WARN L170 areAnnotationChecker]: L527 has no Hoare annotation [2022-02-20 18:11:57,280 WARN L170 areAnnotationChecker]: L527 has no Hoare annotation [2022-02-20 18:11:57,280 WARN L170 areAnnotationChecker]: L486-2 has no Hoare annotation [2022-02-20 18:11:57,280 WARN L170 areAnnotationChecker]: L959 has no Hoare annotation [2022-02-20 18:11:57,280 WARN L170 areAnnotationChecker]: L959 has no Hoare annotation [2022-02-20 18:11:57,280 WARN L170 areAnnotationChecker]: L369-1 has no Hoare annotation [2022-02-20 18:11:57,280 WARN L170 areAnnotationChecker]: L955 has no Hoare annotation [2022-02-20 18:11:57,281 WARN L170 areAnnotationChecker]: L543 has no Hoare annotation [2022-02-20 18:11:57,281 WARN L170 areAnnotationChecker]: L543 has no Hoare annotation [2022-02-20 18:11:57,281 WARN L170 areAnnotationChecker]: L110 has no Hoare annotation [2022-02-20 18:11:57,281 WARN L170 areAnnotationChecker]: L110 has no Hoare annotation [2022-02-20 18:11:57,281 WARN L170 areAnnotationChecker]: L309-2 has no Hoare annotation [2022-02-20 18:11:57,282 WARN L170 areAnnotationChecker]: L309-2 has no Hoare annotation [2022-02-20 18:11:57,282 WARN L170 areAnnotationChecker]: cleanupEXIT has no Hoare annotation [2022-02-20 18:11:57,282 WARN L170 areAnnotationChecker]: L209 has no Hoare annotation [2022-02-20 18:11:57,282 WARN L170 areAnnotationChecker]: L209 has no Hoare annotation [2022-02-20 18:11:57,282 WARN L170 areAnnotationChecker]: L280 has no Hoare annotation [2022-02-20 18:11:57,282 WARN L170 areAnnotationChecker]: L280 has no Hoare annotation [2022-02-20 18:11:57,282 WARN L170 areAnnotationChecker]: L527-1 has no Hoare annotation [2022-02-20 18:11:57,282 WARN L170 areAnnotationChecker]: L345 has no Hoare annotation [2022-02-20 18:11:57,282 WARN L170 areAnnotationChecker]: L960 has no Hoare annotation [2022-02-20 18:11:57,283 WARN L170 areAnnotationChecker]: L960 has no Hoare annotation [2022-02-20 18:11:57,283 WARN L170 areAnnotationChecker]: timeShiftFINAL has no Hoare annotation [2022-02-20 18:11:57,283 WARN L170 areAnnotationChecker]: L371 has no Hoare annotation [2022-02-20 18:11:57,283 WARN L170 areAnnotationChecker]: L371 has no Hoare annotation [2022-02-20 18:11:57,283 WARN L170 areAnnotationChecker]: L955 has no Hoare annotation [2022-02-20 18:11:57,283 WARN L170 areAnnotationChecker]: L955 has no Hoare annotation [2022-02-20 18:11:57,284 WARN L170 areAnnotationChecker]: L508 has no Hoare annotation [2022-02-20 18:11:57,284 WARN L170 areAnnotationChecker]: L309-2 has no Hoare annotation [2022-02-20 18:11:57,284 WARN L170 areAnnotationChecker]: L367 has no Hoare annotation [2022-02-20 18:11:57,284 WARN L170 areAnnotationChecker]: L367 has no Hoare annotation [2022-02-20 18:11:57,284 WARN L170 areAnnotationChecker]: L216 has no Hoare annotation [2022-02-20 18:11:57,285 WARN L170 areAnnotationChecker]: L280-2 has no Hoare annotation [2022-02-20 18:11:57,285 WARN L170 areAnnotationChecker]: L345 has no Hoare annotation [2022-02-20 18:11:57,285 WARN L170 areAnnotationChecker]: L345 has no Hoare annotation [2022-02-20 18:11:57,285 WARN L170 areAnnotationChecker]: L92 has no Hoare annotation [2022-02-20 18:11:57,285 WARN L170 areAnnotationChecker]: L92 has no Hoare annotation [2022-02-20 18:11:57,286 WARN L170 areAnnotationChecker]: timeShiftFINAL has no Hoare annotation [2022-02-20 18:11:57,286 WARN L170 areAnnotationChecker]: L957-1 has no Hoare annotation [2022-02-20 18:11:57,286 WARN L170 areAnnotationChecker]: L508 has no Hoare annotation [2022-02-20 18:11:57,286 WARN L170 areAnnotationChecker]: L508 has no Hoare annotation [2022-02-20 18:11:57,286 WARN L170 areAnnotationChecker]: L369-1 has no Hoare annotation [2022-02-20 18:11:57,287 WARN L170 areAnnotationChecker]: L280-2 has no Hoare annotation [2022-02-20 18:11:57,287 WARN L170 areAnnotationChecker]: L216 has no Hoare annotation [2022-02-20 18:11:57,287 WARN L170 areAnnotationChecker]: ULTIMATE.startFINAL has no Hoare annotation [2022-02-20 18:11:57,288 WARN L170 areAnnotationChecker]: L356-1 has no Hoare annotation [2022-02-20 18:11:57,288 WARN L170 areAnnotationChecker]: L356-1 has no Hoare annotation [2022-02-20 18:11:57,288 WARN L170 areAnnotationChecker]: timeShiftEXIT has no Hoare annotation [2022-02-20 18:11:57,288 WARN L170 areAnnotationChecker]: timeShiftEXIT has no Hoare annotation [2022-02-20 18:11:57,288 WARN L170 areAnnotationChecker]: timeShiftEXIT has no Hoare annotation [2022-02-20 18:11:57,288 WARN L170 areAnnotationChecker]: L509 has no Hoare annotation [2022-02-20 18:11:57,289 WARN L170 areAnnotationChecker]: ULTIMATE.startFINAL has no Hoare annotation [2022-02-20 18:11:57,289 WARN L170 areAnnotationChecker]: L517 has no Hoare annotation [2022-02-20 18:11:57,289 WARN L170 areAnnotationChecker]: L517 has no Hoare annotation [2022-02-20 18:11:57,289 WARN L170 areAnnotationChecker]: L517-1 has no Hoare annotation [2022-02-20 18:11:57,289 INFO L163 areAnnotationChecker]: CFG has 28 edges. 28 inductive. 0 not inductive. 0 times theorem prover too weak to decide inductivity. 0 times interpolants missing. [2022-02-20 18:11:57,302 INFO L202 PluginConnector]: Adding new model de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction CFG 20.02 06:11:57 BoogieIcfgContainer [2022-02-20 18:11:57,303 INFO L132 PluginConnector]: ------------------------ END TraceAbstraction---------------------------- [2022-02-20 18:11:57,303 INFO L113 PluginConnector]: ------------------------Witness Printer---------------------------- [2022-02-20 18:11:57,303 INFO L271 PluginConnector]: Initializing Witness Printer... [2022-02-20 18:11:57,304 INFO L275 PluginConnector]: Witness Printer initialized [2022-02-20 18:11:57,304 INFO L185 PluginConnector]: Executing the observer RCFGCatcher from plugin Witness Printer for "de.uni_freiburg.informatik.ultimate.plugins.generator.rcfgbuilder CFG 20.02 06:11:53" (3/4) ... [2022-02-20 18:11:57,306 INFO L137 WitnessPrinter]: Generating witness for correct program [2022-02-20 18:11:57,311 INFO L354 RCFGBacktranslator]: Ignoring RootEdge to procedure deactivatePump [2022-02-20 18:11:57,311 INFO L354 RCFGBacktranslator]: Ignoring RootEdge to procedure processEnvironment__wrappee__base [2022-02-20 18:11:57,311 INFO L354 RCFGBacktranslator]: Ignoring RootEdge to procedure changeMethaneLevel [2022-02-20 18:11:57,311 INFO L354 RCFGBacktranslator]: Ignoring RootEdge to procedure timeShift [2022-02-20 18:11:57,312 INFO L354 RCFGBacktranslator]: Ignoring RootEdge to procedure cleanup [2022-02-20 18:11:57,312 INFO L354 RCFGBacktranslator]: Ignoring RootEdge to procedure waterRise [2022-02-20 18:11:57,312 INFO L354 RCFGBacktranslator]: Ignoring RootEdge to procedure processEnvironment__wrappee__methaneQuery [2022-02-20 18:11:57,312 INFO L354 RCFGBacktranslator]: Ignoring RootEdge to procedure isPumpRunning [2022-02-20 18:11:57,312 INFO L354 RCFGBacktranslator]: Ignoring RootEdge to procedure isMethaneAlarm [2022-02-20 18:11:57,318 INFO L910 BoogieBacktranslator]: Reduced CFG by removing 51 nodes and edges [2022-02-20 18:11:57,319 INFO L910 BoogieBacktranslator]: Reduced CFG by removing 22 nodes and edges [2022-02-20 18:11:57,319 INFO L910 BoogieBacktranslator]: Reduced CFG by removing 11 nodes and edges [2022-02-20 18:11:57,319 INFO L910 BoogieBacktranslator]: Reduced CFG by removing 5 nodes and edges [2022-02-20 18:11:57,320 INFO L910 BoogieBacktranslator]: Reduced CFG by removing 2 nodes and edges [2022-02-20 18:11:57,320 INFO L910 BoogieBacktranslator]: Reduced CFG by removing 1 nodes and edges [2022-02-20 18:11:57,320 INFO L910 BoogieBacktranslator]: Reduced CFG by removing 1 nodes and edges [2022-02-20 18:11:57,340 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (pumpRunning == 0 && 1 == systemActive) && \result == systemActive [2022-02-20 18:11:57,340 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: ((tmp == systemActive && pumpRunning == 0) && 1 == systemActive) && \result == systemActive [2022-02-20 18:11:57,340 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: ((tmp == systemActive && pumpRunning == 0) && 1 == systemActive) && \result == systemActive [2022-02-20 18:11:57,341 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (((tmp == systemActive && pumpRunning == 0) && 1 == systemActive) && \result == systemActive) && splverifierCounter == 0 [2022-02-20 18:11:57,341 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (!(\old(pumpRunning) == 0) || pumpRunning == 0) || !(1 == systemActive) [2022-02-20 18:11:57,342 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: !(\old(pumpRunning) == 0) || !(1 == systemActive) [2022-02-20 18:11:57,342 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (!(\old(pumpRunning) == 0) || pumpRunning == 0) || !(1 == systemActive) [2022-02-20 18:11:57,343 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (!(\old(pumpRunning) == 0) || pumpRunning == 0) || !(1 == systemActive) [2022-02-20 18:11:57,343 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: !(\old(pumpRunning) == 0) || !(1 == systemActive) [2022-02-20 18:11:57,343 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (!(\old(pumpRunning) == 0) || pumpRunning == 0) || !(1 == systemActive) [2022-02-20 18:11:57,344 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: !(\old(pumpRunning) == 0) || !(1 == systemActive) [2022-02-20 18:11:57,344 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: !(\old(pumpRunning) == 0) || !(1 == systemActive) [2022-02-20 18:11:57,362 INFO L141 WitnessManager]: Wrote witness to /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/witness.graphml [2022-02-20 18:11:57,363 INFO L132 PluginConnector]: ------------------------ END Witness Printer---------------------------- [2022-02-20 18:11:57,364 INFO L158 Benchmark]: Toolchain (without parser) took 4733.82ms. Allocated memory was 90.2MB in the beginning and 132.1MB in the end (delta: 41.9MB). Free memory was 50.4MB in the beginning and 68.4MB in the end (delta: -18.1MB). Peak memory consumption was 23.3MB. Max. memory is 16.1GB. [2022-02-20 18:11:57,364 INFO L158 Benchmark]: CDTParser took 0.21ms. Allocated memory is still 90.2MB. Free memory was 68.3MB in the beginning and 68.2MB in the end (delta: 90.9kB). There was no memory consumed. Max. memory is 16.1GB. [2022-02-20 18:11:57,364 INFO L158 Benchmark]: CACSL2BoogieTranslator took 530.99ms. Allocated memory was 90.2MB in the beginning and 109.1MB in the end (delta: 18.9MB). Free memory was 50.1MB in the beginning and 73.1MB in the end (delta: -23.0MB). Peak memory consumption was 8.4MB. Max. memory is 16.1GB. [2022-02-20 18:11:57,365 INFO L158 Benchmark]: Boogie Procedure Inliner took 75.28ms. Allocated memory is still 109.1MB. Free memory was 73.1MB in the beginning and 70.5MB in the end (delta: 2.6MB). Peak memory consumption was 2.1MB. Max. memory is 16.1GB. [2022-02-20 18:11:57,365 INFO L158 Benchmark]: Boogie Preprocessor took 52.04ms. Allocated memory is still 109.1MB. Free memory was 70.1MB in the beginning and 68.5MB in the end (delta: 1.6MB). Peak memory consumption was 2.1MB. Max. memory is 16.1GB. [2022-02-20 18:11:57,365 INFO L158 Benchmark]: RCFGBuilder took 544.95ms. Allocated memory is still 109.1MB. Free memory was 68.5MB in the beginning and 48.4MB in the end (delta: 20.1MB). Peak memory consumption was 21.0MB. Max. memory is 16.1GB. [2022-02-20 18:11:57,365 INFO L158 Benchmark]: TraceAbstraction took 3463.31ms. Allocated memory was 109.1MB in the beginning and 132.1MB in the end (delta: 23.1MB). Free memory was 48.0MB in the beginning and 73.7MB in the end (delta: -25.7MB). There was no memory consumed. Max. memory is 16.1GB. [2022-02-20 18:11:57,366 INFO L158 Benchmark]: Witness Printer took 59.28ms. Allocated memory is still 132.1MB. Free memory was 73.7MB in the beginning and 68.4MB in the end (delta: 5.2MB). Peak memory consumption was 6.3MB. Max. memory is 16.1GB. [2022-02-20 18:11:57,367 INFO L339 ainManager$Toolchain]: ####################### End [Toolchain 1] ####################### --- Results --- * Results from de.uni_freiburg.informatik.ultimate.core: - AssertionsEnabledResult: Assertions are enabled Assertions are enabled - StatisticsResult: Toolchain Benchmarks Benchmark results are: * CDTParser took 0.21ms. Allocated memory is still 90.2MB. Free memory was 68.3MB in the beginning and 68.2MB in the end (delta: 90.9kB). There was no memory consumed. Max. memory is 16.1GB. * CACSL2BoogieTranslator took 530.99ms. Allocated memory was 90.2MB in the beginning and 109.1MB in the end (delta: 18.9MB). Free memory was 50.1MB in the beginning and 73.1MB in the end (delta: -23.0MB). Peak memory consumption was 8.4MB. Max. memory is 16.1GB. * Boogie Procedure Inliner took 75.28ms. Allocated memory is still 109.1MB. Free memory was 73.1MB in the beginning and 70.5MB in the end (delta: 2.6MB). Peak memory consumption was 2.1MB. Max. memory is 16.1GB. * Boogie Preprocessor took 52.04ms. Allocated memory is still 109.1MB. Free memory was 70.1MB in the beginning and 68.5MB in the end (delta: 1.6MB). Peak memory consumption was 2.1MB. Max. memory is 16.1GB. * RCFGBuilder took 544.95ms. Allocated memory is still 109.1MB. Free memory was 68.5MB in the beginning and 48.4MB in the end (delta: 20.1MB). Peak memory consumption was 21.0MB. Max. memory is 16.1GB. * TraceAbstraction took 3463.31ms. Allocated memory was 109.1MB in the beginning and 132.1MB in the end (delta: 23.1MB). Free memory was 48.0MB in the beginning and 73.7MB in the end (delta: -25.7MB). There was no memory consumed. Max. memory is 16.1GB. * Witness Printer took 59.28ms. Allocated memory is still 132.1MB. Free memory was 73.7MB in the beginning and 68.4MB in the end (delta: 5.2MB). Peak memory consumption was 6.3MB. Max. memory is 16.1GB. * Results from de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction: - StatisticsResult: ErrorAutomatonStatistics NumberErrorTraces: 0, NumberStatementsAllTraces: 0, NumberRelevantStatements: 0, 0.0s ErrorAutomatonConstructionTimeTotal, 0.0s FaulLocalizationTime, NumberStatementsFirstTrace: -1, TraceLengthAvg: 0, 0.0s ErrorAutomatonConstructionTimeAvg, 0.0s ErrorAutomatonDifferenceTimeAvg, 0.0s ErrorAutomatonDifferenceTimeTotal, NumberOfNoEnhancement: 0, NumberOfFiniteEnhancement: 0, NumberOfInfiniteEnhancement: 0 - PositiveResult [Line: 92]: call to reach_error is unreachable For all program executions holds that call to reach_error is unreachable at this location - StatisticsResult: Ultimate Automizer benchmark data CFG has 10 procedures, 96 locations, 1 error locations. Started 1 CEGAR loops. OverallTime: 3.4s, OverallIterations: 4, TraceHistogramMax: 2, PathProgramHistogramMax: 1, EmptinessCheckTime: 0.1s, AutomataDifference: 1.8s, DeadEndRemovalTime: 0.0s, HoareAnnotationTime: 0.3s, InitialAbstractionConstructionTime: 0.0s, PartialOrderReductionTime: 0.0s, HoareTripleCheckerStatistics: 0 mSolverCounterUnknown, 248 SdHoareTripleChecker+Valid, 0.2s IncrementalHoareTripleChecker+Time, 0 mSdLazyCounter, 243 mSDsluCounter, 682 SdHoareTripleChecker+Invalid, 0.2s Time, 0 mProtectedAction, 0 SdHoareTripleChecker+Unchecked, 0 IncrementalHoareTripleChecker+Unchecked, 324 mSDsCounter, 53 IncrementalHoareTripleChecker+Valid, 0 mProtectedPredicate, 144 IncrementalHoareTripleChecker+Invalid, 197 SdHoareTripleChecker+Unknown, 0 mSolverCounterNotChecked, 53 mSolverCounterUnsat, 358 mSDtfsCounter, 144 mSolverCounterSat, 0.0s SdHoareTripleChecker+Time, 0 IncrementalHoareTripleChecker+Unknown, PredicateUnifierStatistics: 0 DeclaredPredicates, 44 GetRequests, 28 SyntacticMatches, 0 SemanticMatches, 16 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 3 ImplicationChecksByTransitivity, 0.1s Time, 0.0s BasicInterpolantAutomatonTime, BiggestAbstraction: size=96occurred in iteration=0, InterpolantAutomatonStates: 17, traceCheckStatistics: No data available, InterpolantConsolidationStatistics: No data available, PathInvariantsStatistics: No data available, 0/0 InterpolantCoveringCapability, TotalInterpolationStatistics: No data available, 0.0s DumpTime, AutomataMinimizationStatistics: 0.1s AutomataMinimizationTime, 4 MinimizatonAttempts, 0 StatesRemovedByMinimization, 0 NontrivialMinimizations, HoareAnnotationStatistics: 0.0s HoareAnnotationTime, 44 LocationsWithAnnotation, 224 PreInvPairs, 238 NumberOfFragments, 331 HoareAnnotationTreeSize, 224 FomulaSimplifications, 0 FormulaSimplificationTreeSizeReduction, 0.1s HoareSimplificationTime, 44 FomulaSimplificationsInter, 143 FormulaSimplificationTreeSizeReductionInter, 0.2s HoareSimplificationTimeInter, RefinementEngineStatistics: TRACE_CHECK: 0.0s SsaConstructionTime, 0.1s SatisfiabilityAnalysisTime, 0.5s InterpolantComputationTime, 149 NumberOfCodeBlocks, 149 NumberOfCodeBlocksAsserted, 4 NumberOfCheckSat, 145 ConstructedInterpolants, 0 QuantifiedInterpolants, 284 SizeOfPredicates, 0 NumberOfNonLiveVariables, 0 ConjunctsInSsa, 0 ConjunctsInUnsatCore, 4 InterpolantComputations, 4 PerfectInterpolantSequences, 12/12 InterpolantCoveringCapability, INVARIANT_SYNTHESIS: No data available, INTERPOLANT_CONSOLIDATION: No data available, ABSTRACT_INTERPRETATION: No data available, PDR: No data available, ACCELERATED_INTERPOLATION: No data available, SIFA: No data available, ReuseStatistics: No data available - AllSpecificationsHoldResult: All specifications hold 1 specifications checked. All of them hold - InvariantResult [Line: 270]: Loop Invariant Derived loop invariant: 1 - InvariantResult [Line: 363]: Loop Invariant Derived loop invariant: (!(\old(pumpRunning) == 0) || pumpRunning == 0) || !(1 == systemActive) - InvariantResult [Line: 205]: Loop Invariant Derived loop invariant: 1 - InvariantResult [Line: 142]: Loop Invariant Derived loop invariant: 1 - InvariantResult [Line: 250]: Loop Invariant Derived loop invariant: ((tmp == systemActive && pumpRunning == 0) && 1 == systemActive) && \result == systemActive - InvariantResult [Line: 497]: Loop Invariant Derived loop invariant: 1 - InvariantResult [Line: 183]: Loop Invariant Derived loop invariant: !(\old(pumpRunning) == 0) || !(1 == systemActive) - InvariantResult [Line: 174]: Loop Invariant Derived loop invariant: (!(\old(pumpRunning) == 0) || pumpRunning == 0) || !(1 == systemActive) - InvariantResult [Line: 78]: Loop Invariant Derived loop invariant: (pumpRunning == 0 && 1 == systemActive) && \result == systemActive - InvariantResult [Line: 64]: Loop Invariant Derived loop invariant: pumpRunning == 0 && 1 == systemActive - InvariantResult [Line: 259]: Loop Invariant Derived loop invariant: 1 - InvariantResult [Line: 477]: Loop Invariant Derived loop invariant: !(\old(pumpRunning) == 0) || !(1 == systemActive) - InvariantResult [Line: 506]: Loop Invariant Derived loop invariant: 0 - InvariantResult [Line: 71]: Loop Invariant Derived loop invariant: pumpRunning == 0 && 1 == systemActive - InvariantResult [Line: 929]: Loop Invariant Derived loop invariant: ((tmp == systemActive && pumpRunning == 0) && 1 == systemActive) && \result == systemActive - InvariantResult [Line: 106]: Loop Invariant Derived loop invariant: !(\old(pumpRunning) == 0) || !(1 == systemActive) - InvariantResult [Line: 947]: Loop Invariant Derived loop invariant: (!(\old(pumpRunning) == 0) || pumpRunning == 0) || !(1 == systemActive) - InvariantResult [Line: 195]: Loop Invariant Derived loop invariant: 1 - InvariantResult [Line: 937]: Loop Invariant Derived loop invariant: (!(\old(pumpRunning) == 0) || pumpRunning == 0) || !(1 == systemActive) - InvariantResult [Line: 507]: Loop Invariant Derived loop invariant: (((tmp == systemActive && pumpRunning == 0) && 1 == systemActive) && \result == systemActive) && splverifierCounter == 0 - InvariantResult [Line: 88]: Loop Invariant Derived loop invariant: !(\old(pumpRunning) == 0) || !(1 == systemActive) RESULT: Ultimate proved your program to be correct! [2022-02-20 18:11:57,412 INFO L552 MonitoredProcess]: [MP /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in -t:2000 (1)] Ended with exit code 0 Received shutdown request... --- End real Ultimate output --- Execution finished normally Writing output log to file Ultimate.log Result: TRUE