./Ultimate.py --spec ../sv-benchmarks/c/properties/unreach-call.prp --file ../sv-benchmarks/c/product-lines/minepump_spec4_product11.cil.c --full-output --architecture 32bit -------------------------------------------------------------------------------- Checking for ERROR reachability Using default analysis Version 35987657 Calling Ultimate with: /usr/bin/java -Dosgi.configuration.area=/storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/data/config -Xmx15G -Xms4m -jar /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/plugins/org.eclipse.equinox.launcher_1.5.800.v20200727-1323.jar -data @noDefault -ultimatedata /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/data -tc /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/config/AutomizerReach.xml -i ../sv-benchmarks/c/product-lines/minepump_spec4_product11.cil.c -s /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/config/svcomp-Reach-32bit-Automizer_Default.epf --cacsl2boogietranslator.entry.function main --witnessprinter.witness.directory /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux --witnessprinter.witness.filename witness.graphml --witnessprinter.write.witness.besides.input.file false --witnessprinter.graph.data.specification CHECK( init(main()), LTL(G ! call(reach_error())) ) --witnessprinter.graph.data.producer Automizer --witnessprinter.graph.data.architecture 32bit --witnessprinter.graph.data.programhash bd7f84863cb412e83f8c5773a09de3282aa45b8f86409f0c880aae27635b0b5f --- Real Ultimate output --- This is Ultimate 0.2.2-?-3598765 [2022-07-21 05:01:23,154 INFO L177 SettingsManager]: Resetting all preferences to default values... [2022-07-21 05:01:23,156 INFO L181 SettingsManager]: Resetting UltimateCore preferences to default values [2022-07-21 05:01:23,182 INFO L184 SettingsManager]: Ultimate Commandline Interface provides no preferences, ignoring... [2022-07-21 05:01:23,183 INFO L181 SettingsManager]: Resetting Boogie Preprocessor preferences to default values [2022-07-21 05:01:23,184 INFO L181 SettingsManager]: Resetting Boogie Procedure Inliner preferences to default values [2022-07-21 05:01:23,190 INFO L181 SettingsManager]: Resetting Abstract Interpretation preferences to default values [2022-07-21 05:01:23,193 INFO L181 SettingsManager]: Resetting LassoRanker preferences to default values [2022-07-21 05:01:23,196 INFO L181 SettingsManager]: Resetting Reaching Definitions preferences to default values [2022-07-21 05:01:23,200 INFO L181 SettingsManager]: Resetting SyntaxChecker preferences to default values [2022-07-21 05:01:23,201 INFO L181 SettingsManager]: Resetting Sifa preferences to default values [2022-07-21 05:01:23,206 INFO L184 SettingsManager]: Büchi Program Product provides no preferences, ignoring... [2022-07-21 05:01:23,206 INFO L181 SettingsManager]: Resetting LTL2Aut preferences to default values [2022-07-21 05:01:23,208 INFO L181 SettingsManager]: Resetting PEA to Boogie preferences to default values [2022-07-21 05:01:23,209 INFO L181 SettingsManager]: Resetting BlockEncodingV2 preferences to default values [2022-07-21 05:01:23,210 INFO L181 SettingsManager]: Resetting ChcToBoogie preferences to default values [2022-07-21 05:01:23,211 INFO L181 SettingsManager]: Resetting AutomataScriptInterpreter preferences to default values [2022-07-21 05:01:23,213 INFO L181 SettingsManager]: Resetting BuchiAutomizer preferences to default values [2022-07-21 05:01:23,216 INFO L181 SettingsManager]: Resetting CACSL2BoogieTranslator preferences to default values [2022-07-21 05:01:23,223 INFO L181 SettingsManager]: Resetting CodeCheck preferences to default values [2022-07-21 05:01:23,225 INFO L181 SettingsManager]: Resetting HornVerifier preferences to default values [2022-07-21 05:01:23,226 INFO L181 SettingsManager]: Resetting InvariantSynthesis preferences to default values [2022-07-21 05:01:23,227 INFO L181 SettingsManager]: Resetting RCFGBuilder preferences to default values [2022-07-21 05:01:23,228 INFO L181 SettingsManager]: Resetting Referee preferences to default values [2022-07-21 05:01:23,228 INFO L181 SettingsManager]: Resetting TraceAbstraction preferences to default values [2022-07-21 05:01:23,231 INFO L184 SettingsManager]: TraceAbstractionConcurrent provides no preferences, ignoring... [2022-07-21 05:01:23,234 INFO L184 SettingsManager]: TraceAbstractionWithAFAs provides no preferences, ignoring... [2022-07-21 05:01:23,235 INFO L181 SettingsManager]: Resetting TreeAutomizer preferences to default values [2022-07-21 05:01:23,236 INFO L181 SettingsManager]: Resetting IcfgToChc preferences to default values [2022-07-21 05:01:23,236 INFO L181 SettingsManager]: Resetting IcfgTransformer preferences to default values [2022-07-21 05:01:23,237 INFO L184 SettingsManager]: ReqToTest provides no preferences, ignoring... [2022-07-21 05:01:23,237 INFO L181 SettingsManager]: Resetting Boogie Printer preferences to default values [2022-07-21 05:01:23,238 INFO L181 SettingsManager]: Resetting ChcSmtPrinter preferences to default values [2022-07-21 05:01:23,239 INFO L181 SettingsManager]: Resetting ReqPrinter preferences to default values [2022-07-21 05:01:23,240 INFO L181 SettingsManager]: Resetting Witness Printer preferences to default values [2022-07-21 05:01:23,241 INFO L184 SettingsManager]: Boogie PL CUP Parser provides no preferences, ignoring... [2022-07-21 05:01:23,241 INFO L181 SettingsManager]: Resetting CDTParser preferences to default values [2022-07-21 05:01:23,242 INFO L184 SettingsManager]: AutomataScriptParser provides no preferences, ignoring... [2022-07-21 05:01:23,242 INFO L184 SettingsManager]: ReqParser provides no preferences, ignoring... [2022-07-21 05:01:23,242 INFO L181 SettingsManager]: Resetting SmtParser preferences to default values [2022-07-21 05:01:23,243 INFO L181 SettingsManager]: Resetting Witness Parser preferences to default values [2022-07-21 05:01:23,245 INFO L188 SettingsManager]: Finished resetting all preferences to default values... [2022-07-21 05:01:23,250 INFO L101 SettingsManager]: Beginning loading settings from /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/config/svcomp-Reach-32bit-Automizer_Default.epf [2022-07-21 05:01:23,285 INFO L113 SettingsManager]: Loading preferences was successful [2022-07-21 05:01:23,285 INFO L115 SettingsManager]: Preferences different from defaults after loading the file: [2022-07-21 05:01:23,286 INFO L136 SettingsManager]: Preferences of UltimateCore differ from their defaults: [2022-07-21 05:01:23,286 INFO L138 SettingsManager]: * Log level for class=de.uni_freiburg.informatik.ultimate.lib.smtlibutils.quantifier.QuantifierPusher=ERROR; [2022-07-21 05:01:23,287 INFO L136 SettingsManager]: Preferences of Boogie Procedure Inliner differ from their defaults: [2022-07-21 05:01:23,287 INFO L138 SettingsManager]: * Ignore calls to procedures called more than once=ONLY_FOR_SEQUENTIAL_PROGRAMS [2022-07-21 05:01:23,287 INFO L136 SettingsManager]: Preferences of BlockEncodingV2 differ from their defaults: [2022-07-21 05:01:23,288 INFO L138 SettingsManager]: * Create parallel compositions if possible=false [2022-07-21 05:01:23,288 INFO L138 SettingsManager]: * Use SBE=true [2022-07-21 05:01:23,289 INFO L136 SettingsManager]: Preferences of CACSL2BoogieTranslator differ from their defaults: [2022-07-21 05:01:23,289 INFO L138 SettingsManager]: * sizeof long=4 [2022-07-21 05:01:23,289 INFO L138 SettingsManager]: * Overapproximate operations on floating types=true [2022-07-21 05:01:23,289 INFO L138 SettingsManager]: * sizeof POINTER=4 [2022-07-21 05:01:23,290 INFO L138 SettingsManager]: * Check division by zero=IGNORE [2022-07-21 05:01:23,296 INFO L138 SettingsManager]: * Pointer to allocated memory at dereference=IGNORE [2022-07-21 05:01:23,297 INFO L138 SettingsManager]: * If two pointers are subtracted or compared they have the same base address=IGNORE [2022-07-21 05:01:23,297 INFO L138 SettingsManager]: * Check array bounds for arrays that are off heap=IGNORE [2022-07-21 05:01:23,297 INFO L138 SettingsManager]: * sizeof long double=12 [2022-07-21 05:01:23,297 INFO L138 SettingsManager]: * Check if freed pointer was valid=false [2022-07-21 05:01:23,298 INFO L138 SettingsManager]: * Use constant arrays=true [2022-07-21 05:01:23,298 INFO L138 SettingsManager]: * Pointer base address is valid at dereference=IGNORE [2022-07-21 05:01:23,298 INFO L136 SettingsManager]: Preferences of RCFGBuilder differ from their defaults: [2022-07-21 05:01:23,298 INFO L138 SettingsManager]: * Size of a code block=SequenceOfStatements [2022-07-21 05:01:23,298 INFO L138 SettingsManager]: * SMT solver=External_DefaultMode [2022-07-21 05:01:23,299 INFO L138 SettingsManager]: * Command for external solver=z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in -t:2000 [2022-07-21 05:01:23,299 INFO L136 SettingsManager]: Preferences of TraceAbstraction differ from their defaults: [2022-07-21 05:01:23,299 INFO L138 SettingsManager]: * Compute Interpolants along a Counterexample=FPandBP [2022-07-21 05:01:23,299 INFO L138 SettingsManager]: * Positions where we compute the Hoare Annotation=LoopsAndPotentialCycles [2022-07-21 05:01:23,299 INFO L138 SettingsManager]: * Trace refinement strategy=CAMEL [2022-07-21 05:01:23,300 INFO L138 SettingsManager]: * Command for external solver=z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in [2022-07-21 05:01:23,300 INFO L138 SettingsManager]: * Apply one-shot large block encoding in concurrent analysis=false [2022-07-21 05:01:23,300 INFO L138 SettingsManager]: * Automaton type used in concurrency analysis=PETRI_NET [2022-07-21 05:01:23,300 INFO L138 SettingsManager]: * Compute Hoare Annotation of negated interpolant automaton, abstraction and CFG=true [2022-07-21 05:01:23,301 INFO L138 SettingsManager]: * SMT solver=External_ModelsAndUnsatCoreMode WARNING: An illegal reflective access operation has occurred WARNING: Illegal reflective access by com.sun.xml.bind.v2.runtime.reflect.opt.Injector$1 (file:/storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/plugins/com.sun.xml.bind_2.2.0.v201505121915.jar) to method java.lang.ClassLoader.defineClass(java.lang.String,byte[],int,int) WARNING: Please consider reporting this to the maintainers of com.sun.xml.bind.v2.runtime.reflect.opt.Injector$1 WARNING: Use --illegal-access=warn to enable warnings of further illegal reflective access operations WARNING: All illegal access operations will be denied in a future release Applying setting for plugin de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator: Entry function -> main Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Witness directory -> /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Witness filename -> witness.graphml Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Write witness besides input file -> false Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Graph data specification -> CHECK( init(main()), LTL(G ! call(reach_error())) ) Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Graph data producer -> Automizer Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Graph data architecture -> 32bit Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Graph data programhash -> bd7f84863cb412e83f8c5773a09de3282aa45b8f86409f0c880aae27635b0b5f [2022-07-21 05:01:23,587 INFO L75 nceAwareModelManager]: Repository-Root is: /tmp [2022-07-21 05:01:23,606 INFO L261 ainManager$Toolchain]: [Toolchain 1]: Applicable parser(s) successfully (re)initialized [2022-07-21 05:01:23,608 INFO L217 ainManager$Toolchain]: [Toolchain 1]: Toolchain selected. [2022-07-21 05:01:23,609 INFO L271 PluginConnector]: Initializing CDTParser... [2022-07-21 05:01:23,609 INFO L275 PluginConnector]: CDTParser initialized [2022-07-21 05:01:23,610 INFO L432 ainManager$Toolchain]: [Toolchain 1]: Parsing single file: /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/../sv-benchmarks/c/product-lines/minepump_spec4_product11.cil.c [2022-07-21 05:01:23,665 INFO L220 CDTParser]: Created temporary CDT project at /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/data/05d7d545b/2d6e8fba34f04ead8df33130629356d8/FLAG5e62e5744 [2022-07-21 05:01:24,085 INFO L306 CDTParser]: Found 1 translation units. [2022-07-21 05:01:24,086 INFO L160 CDTParser]: Scanning /storage/repos/ultimate/releaseScripts/default/sv-benchmarks/c/product-lines/minepump_spec4_product11.cil.c [2022-07-21 05:01:24,099 INFO L349 CDTParser]: About to delete temporary CDT project at /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/data/05d7d545b/2d6e8fba34f04ead8df33130629356d8/FLAG5e62e5744 [2022-07-21 05:01:24,451 INFO L357 CDTParser]: Successfully deleted /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/data/05d7d545b/2d6e8fba34f04ead8df33130629356d8 [2022-07-21 05:01:24,453 INFO L299 ainManager$Toolchain]: ####################### [Toolchain 1] ####################### [2022-07-21 05:01:24,454 INFO L131 ToolchainWalker]: Walking toolchain with 6 elements. [2022-07-21 05:01:24,455 INFO L113 PluginConnector]: ------------------------CACSL2BoogieTranslator---------------------------- [2022-07-21 05:01:24,456 INFO L271 PluginConnector]: Initializing CACSL2BoogieTranslator... [2022-07-21 05:01:24,460 INFO L275 PluginConnector]: CACSL2BoogieTranslator initialized [2022-07-21 05:01:24,460 INFO L185 PluginConnector]: Executing the observer ACSLObjectContainerObserver from plugin CACSL2BoogieTranslator for "CDTParser AST 21.07 05:01:24" (1/1) ... [2022-07-21 05:01:24,461 INFO L205 PluginConnector]: Invalid model from CACSL2BoogieTranslator for observer de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator.ACSLObjectContainerObserver@6fb4fb8a and model type de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 21.07 05:01:24, skipping insertion in model container [2022-07-21 05:01:24,462 INFO L185 PluginConnector]: Executing the observer CACSL2BoogieTranslatorObserver from plugin CACSL2BoogieTranslator for "CDTParser AST 21.07 05:01:24" (1/1) ... [2022-07-21 05:01:24,467 INFO L145 MainTranslator]: Starting translation in SV-COMP mode [2022-07-21 05:01:24,496 INFO L178 MainTranslator]: Built tables and reachable declarations [2022-07-21 05:01:24,601 WARN L230 ndardFunctionHandler]: Function reach_error is already implemented but we override the implementation for the call at /storage/repos/ultimate/releaseScripts/default/sv-benchmarks/c/product-lines/minepump_spec4_product11.cil.c[1605,1618] [2022-07-21 05:01:24,719 INFO L210 PostProcessor]: Analyzing one entry point: main [2022-07-21 05:01:24,726 INFO L203 MainTranslator]: Completed pre-run [2022-07-21 05:01:24,737 WARN L230 ndardFunctionHandler]: Function reach_error is already implemented but we override the implementation for the call at /storage/repos/ultimate/releaseScripts/default/sv-benchmarks/c/product-lines/minepump_spec4_product11.cil.c[1605,1618] [2022-07-21 05:01:24,813 INFO L210 PostProcessor]: Analyzing one entry point: main [2022-07-21 05:01:24,837 INFO L208 MainTranslator]: Completed translation [2022-07-21 05:01:24,838 INFO L202 PluginConnector]: Adding new model de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 21.07 05:01:24 WrapperNode [2022-07-21 05:01:24,838 INFO L132 PluginConnector]: ------------------------ END CACSL2BoogieTranslator---------------------------- [2022-07-21 05:01:24,840 INFO L113 PluginConnector]: ------------------------Boogie Procedure Inliner---------------------------- [2022-07-21 05:01:24,840 INFO L271 PluginConnector]: Initializing Boogie Procedure Inliner... [2022-07-21 05:01:24,840 INFO L275 PluginConnector]: Boogie Procedure Inliner initialized [2022-07-21 05:01:24,846 INFO L185 PluginConnector]: Executing the observer TypeChecker from plugin Boogie Procedure Inliner for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 21.07 05:01:24" (1/1) ... [2022-07-21 05:01:24,873 INFO L185 PluginConnector]: Executing the observer Inliner from plugin Boogie Procedure Inliner for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 21.07 05:01:24" (1/1) ... [2022-07-21 05:01:24,904 INFO L137 Inliner]: procedures = 51, calls = 148, calls flagged for inlining = 22, calls inlined = 16, statements flattened = 193 [2022-07-21 05:01:24,904 INFO L132 PluginConnector]: ------------------------ END Boogie Procedure Inliner---------------------------- [2022-07-21 05:01:24,905 INFO L113 PluginConnector]: ------------------------Boogie Preprocessor---------------------------- [2022-07-21 05:01:24,906 INFO L271 PluginConnector]: Initializing Boogie Preprocessor... [2022-07-21 05:01:24,906 INFO L275 PluginConnector]: Boogie Preprocessor initialized [2022-07-21 05:01:24,913 INFO L185 PluginConnector]: Executing the observer EnsureBoogieModelObserver from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 21.07 05:01:24" (1/1) ... [2022-07-21 05:01:24,913 INFO L185 PluginConnector]: Executing the observer TypeChecker from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 21.07 05:01:24" (1/1) ... [2022-07-21 05:01:24,925 INFO L185 PluginConnector]: Executing the observer ConstExpander from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 21.07 05:01:24" (1/1) ... [2022-07-21 05:01:24,925 INFO L185 PluginConnector]: Executing the observer StructExpander from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 21.07 05:01:24" (1/1) ... [2022-07-21 05:01:24,932 INFO L185 PluginConnector]: Executing the observer UnstructureCode from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 21.07 05:01:24" (1/1) ... [2022-07-21 05:01:24,944 INFO L185 PluginConnector]: Executing the observer FunctionInliner from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 21.07 05:01:24" (1/1) ... [2022-07-21 05:01:24,946 INFO L185 PluginConnector]: Executing the observer BoogieSymbolTableConstructor from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 21.07 05:01:24" (1/1) ... [2022-07-21 05:01:24,951 INFO L132 PluginConnector]: ------------------------ END Boogie Preprocessor---------------------------- [2022-07-21 05:01:24,952 INFO L113 PluginConnector]: ------------------------RCFGBuilder---------------------------- [2022-07-21 05:01:24,952 INFO L271 PluginConnector]: Initializing RCFGBuilder... [2022-07-21 05:01:24,952 INFO L275 PluginConnector]: RCFGBuilder initialized [2022-07-21 05:01:24,953 INFO L185 PluginConnector]: Executing the observer RCFGBuilderObserver from plugin RCFGBuilder for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 21.07 05:01:24" (1/1) ... [2022-07-21 05:01:24,960 INFO L173 SolverBuilder]: Constructing external solver with command: z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in -t:2000 [2022-07-21 05:01:24,970 INFO L189 MonitoredProcess]: No working directory specified, using /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 [2022-07-21 05:01:24,988 INFO L229 MonitoredProcess]: Starting monitored process 1 with /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in -t:2000 (exit command is (exit), workingDir is null) [2022-07-21 05:01:25,011 INFO L327 MonitoredProcess]: [MP /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in -t:2000 (1)] Waiting until timeout for monitored process [2022-07-21 05:01:25,030 INFO L130 BoogieDeclarations]: Found specification of procedure #Ultimate.allocInit [2022-07-21 05:01:25,030 INFO L130 BoogieDeclarations]: Found specification of procedure cleanup [2022-07-21 05:01:25,030 INFO L138 BoogieDeclarations]: Found implementation of procedure cleanup [2022-07-21 05:01:25,031 INFO L130 BoogieDeclarations]: Found specification of procedure timeShift [2022-07-21 05:01:25,031 INFO L138 BoogieDeclarations]: Found implementation of procedure timeShift [2022-07-21 05:01:25,031 INFO L130 BoogieDeclarations]: Found specification of procedure waterRise [2022-07-21 05:01:25,031 INFO L138 BoogieDeclarations]: Found implementation of procedure waterRise [2022-07-21 05:01:25,031 INFO L130 BoogieDeclarations]: Found specification of procedure write~init~int [2022-07-21 05:01:25,031 INFO L130 BoogieDeclarations]: Found specification of procedure changeMethaneLevel [2022-07-21 05:01:25,031 INFO L138 BoogieDeclarations]: Found implementation of procedure changeMethaneLevel [2022-07-21 05:01:25,032 INFO L130 BoogieDeclarations]: Found specification of procedure ULTIMATE.start [2022-07-21 05:01:25,032 INFO L138 BoogieDeclarations]: Found implementation of procedure ULTIMATE.start [2022-07-21 05:01:25,141 INFO L234 CfgBuilder]: Building ICFG [2022-07-21 05:01:25,142 INFO L260 CfgBuilder]: Building CFG for each procedure with an implementation [2022-07-21 05:01:25,448 INFO L275 CfgBuilder]: Performing block encoding [2022-07-21 05:01:25,454 INFO L294 CfgBuilder]: Using the 1 location(s) as analysis (start of procedure ULTIMATE.start) [2022-07-21 05:01:25,455 INFO L299 CfgBuilder]: Removed 2 assume(true) statements. [2022-07-21 05:01:25,456 INFO L202 PluginConnector]: Adding new model de.uni_freiburg.informatik.ultimate.plugins.generator.rcfgbuilder CFG 21.07 05:01:25 BoogieIcfgContainer [2022-07-21 05:01:25,457 INFO L132 PluginConnector]: ------------------------ END RCFGBuilder---------------------------- [2022-07-21 05:01:25,458 INFO L113 PluginConnector]: ------------------------TraceAbstraction---------------------------- [2022-07-21 05:01:25,458 INFO L271 PluginConnector]: Initializing TraceAbstraction... [2022-07-21 05:01:25,461 INFO L275 PluginConnector]: TraceAbstraction initialized [2022-07-21 05:01:25,461 INFO L185 PluginConnector]: Executing the observer TraceAbstractionObserver from plugin TraceAbstraction for "CDTParser AST 21.07 05:01:24" (1/3) ... [2022-07-21 05:01:25,462 INFO L205 PluginConnector]: Invalid model from TraceAbstraction for observer de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction.TraceAbstractionObserver@5f7a6f66 and model type de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction AST 21.07 05:01:25, skipping insertion in model container [2022-07-21 05:01:25,462 INFO L185 PluginConnector]: Executing the observer TraceAbstractionObserver from plugin TraceAbstraction for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 21.07 05:01:24" (2/3) ... [2022-07-21 05:01:25,462 INFO L205 PluginConnector]: Invalid model from TraceAbstraction for observer de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction.TraceAbstractionObserver@5f7a6f66 and model type de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction AST 21.07 05:01:25, skipping insertion in model container [2022-07-21 05:01:25,463 INFO L185 PluginConnector]: Executing the observer TraceAbstractionObserver from plugin TraceAbstraction for "de.uni_freiburg.informatik.ultimate.plugins.generator.rcfgbuilder CFG 21.07 05:01:25" (3/3) ... [2022-07-21 05:01:25,464 INFO L111 eAbstractionObserver]: Analyzing ICFG minepump_spec4_product11.cil.c [2022-07-21 05:01:25,476 INFO L201 ceAbstractionStarter]: Automizer settings: Hoare:true NWA Interpolation:FPandBP Determinization: PREDICATE_ABSTRACTION [2022-07-21 05:01:25,477 INFO L160 ceAbstractionStarter]: Applying trace abstraction to program that has 1 error locations. [2022-07-21 05:01:25,540 INFO L356 AbstractCegarLoop]: ======== Iteration 0 == of CEGAR loop == AllErrorsAtOnce ======== [2022-07-21 05:01:25,548 INFO L357 AbstractCegarLoop]: Settings: SEPARATE_VIOLATION_CHECK=true, mInterprocedural=true, mMaxIterations=1000000, mWatchIteration=1000000, mArtifact=RCFG, mInterpolation=FPandBP, mInterpolantAutomaton=STRAIGHT_LINE, mDumpAutomata=false, mAutomataFormat=ATS_NUMERATE, mDumpPath=., mDeterminiation=PREDICATE_ABSTRACTION, mMinimize=MINIMIZE_SEVPA, mHoare=true, mAutomataTypeConcurrency=PETRI_NET, mHoareTripleChecks=INCREMENTAL, mHoareAnnotationPositions=LoopsAndPotentialCycles, mDumpOnlyReuseAutomata=false, mLimitTraceHistogram=0, mErrorLocTimeLimit=0, mLimitPathProgramCount=0, mCollectInterpolantStatistics=true, mHeuristicEmptinessCheck=false, mHeuristicEmptinessCheckAStarHeuristic=ZERO, mHeuristicEmptinessCheckAStarHeuristicRandomSeed=1337, mHeuristicEmptinessCheckSmtFeatureScoringMethod=DAGSIZE, mSMTFeatureExtraction=false, mSMTFeatureExtractionDumpPath=., mOverrideInterpolantAutomaton=false, mMcrInterpolantMethod=WP, mPorIndependenceSettings=de.uni_freiburg.informatik.ultimate.lib.tracecheckerutils.partialorder.independence.IndependenceSettings@43e72fbe, mLbeIndependenceSettings=de.uni_freiburg.informatik.ultimate.lib.tracecheckerutils.partialorder.independence.IndependenceSettings@2e2f42fd [2022-07-21 05:01:25,548 INFO L358 AbstractCegarLoop]: Starting to check reachability of 1 error locations. [2022-07-21 05:01:25,560 INFO L276 IsEmpty]: Start isEmpty. Operand has 62 states, 50 states have (on average 1.4) internal successors, (70), 54 states have internal predecessors, (70), 6 states have call successors, (6), 4 states have call predecessors, (6), 4 states have return successors, (6), 6 states have call predecessors, (6), 6 states have call successors, (6) [2022-07-21 05:01:25,570 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 20 [2022-07-21 05:01:25,570 INFO L187 NwaCegarLoop]: Found error trace [2022-07-21 05:01:25,571 INFO L195 NwaCegarLoop]: trace histogram [1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-07-21 05:01:25,572 INFO L420 AbstractCegarLoop]: === Iteration 1 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2022-07-21 05:01:25,578 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2022-07-21 05:01:25,579 INFO L85 PathProgramCache]: Analyzing trace with hash -192528358, now seen corresponding path program 1 times [2022-07-21 05:01:25,587 INFO L118 FreeRefinementEngine]: Executing refinement strategy CAMEL [2022-07-21 05:01:25,588 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [1506999408] [2022-07-21 05:01:25,588 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-07-21 05:01:25,589 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2022-07-21 05:01:25,758 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-07-21 05:01:25,828 INFO L134 CoverageAnalysis]: Checked inductivity of 0 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2022-07-21 05:01:25,828 INFO L136 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2022-07-21 05:01:25,829 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [1506999408] [2022-07-21 05:01:25,829 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [1506999408] provided 1 perfect and 0 imperfect interpolant sequences [2022-07-21 05:01:25,829 INFO L184 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2022-07-21 05:01:25,829 INFO L197 FreeRefinementEngine]: Number of different interpolants: perfect sequences [2] imperfect sequences [] total 2 [2022-07-21 05:01:25,831 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [622391380] [2022-07-21 05:01:25,831 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2022-07-21 05:01:25,835 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 2 states [2022-07-21 05:01:25,835 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2022-07-21 05:01:25,857 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 2 interpolants. [2022-07-21 05:01:25,858 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=1, Invalid=1, Unknown=0, NotChecked=0, Total=2 [2022-07-21 05:01:25,861 INFO L87 Difference]: Start difference. First operand has 62 states, 50 states have (on average 1.4) internal successors, (70), 54 states have internal predecessors, (70), 6 states have call successors, (6), 4 states have call predecessors, (6), 4 states have return successors, (6), 6 states have call predecessors, (6), 6 states have call successors, (6) Second operand has 2 states, 2 states have (on average 8.5) internal successors, (17), 2 states have internal predecessors, (17), 1 states have call successors, (2), 1 states have call predecessors, (2), 0 states have return successors, (0), 0 states have call predecessors, (0), 0 states have call successors, (0) [2022-07-21 05:01:25,891 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-07-21 05:01:25,891 INFO L93 Difference]: Finished difference Result 116 states and 159 transitions. [2022-07-21 05:01:25,892 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 2 states. [2022-07-21 05:01:25,893 INFO L78 Accepts]: Start accepts. Automaton has has 2 states, 2 states have (on average 8.5) internal successors, (17), 2 states have internal predecessors, (17), 1 states have call successors, (2), 1 states have call predecessors, (2), 0 states have return successors, (0), 0 states have call predecessors, (0), 0 states have call successors, (0) Word has length 19 [2022-07-21 05:01:25,894 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2022-07-21 05:01:25,902 INFO L225 Difference]: With dead ends: 116 [2022-07-21 05:01:25,902 INFO L226 Difference]: Without dead ends: 53 [2022-07-21 05:01:25,906 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 2 GetRequests, 2 SyntacticMatches, 0 SemanticMatches, 0 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 0 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=1, Invalid=1, Unknown=0, NotChecked=0, Total=2 [2022-07-21 05:01:25,911 INFO L413 NwaCegarLoop]: 76 mSDtfsCounter, 0 mSDsluCounter, 0 mSDsCounter, 0 mSdLazyCounter, 0 mSolverCounterSat, 0 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.0s Time, 0 mProtectedPredicate, 0 mProtectedAction, 0 SdHoareTripleChecker+Valid, 76 SdHoareTripleChecker+Invalid, 0 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 0 IncrementalHoareTripleChecker+Valid, 0 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.0s IncrementalHoareTripleChecker+Time [2022-07-21 05:01:25,913 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [0 Valid, 76 Invalid, 0 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [0 Valid, 0 Invalid, 0 Unknown, 0 Unchecked, 0.0s Time] [2022-07-21 05:01:25,927 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 53 states. [2022-07-21 05:01:25,953 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 53 to 53. [2022-07-21 05:01:25,954 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 53 states, 43 states have (on average 1.302325581395349) internal successors, (56), 46 states have internal predecessors, (56), 6 states have call successors, (6), 4 states have call predecessors, (6), 3 states have return successors, (5), 5 states have call predecessors, (5), 5 states have call successors, (5) [2022-07-21 05:01:25,957 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 53 states to 53 states and 67 transitions. [2022-07-21 05:01:25,958 INFO L78 Accepts]: Start accepts. Automaton has 53 states and 67 transitions. Word has length 19 [2022-07-21 05:01:25,959 INFO L84 Accepts]: Finished accepts. word is rejected. [2022-07-21 05:01:25,959 INFO L495 AbstractCegarLoop]: Abstraction has 53 states and 67 transitions. [2022-07-21 05:01:25,960 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 2 states, 2 states have (on average 8.5) internal successors, (17), 2 states have internal predecessors, (17), 1 states have call successors, (2), 1 states have call predecessors, (2), 0 states have return successors, (0), 0 states have call predecessors, (0), 0 states have call successors, (0) [2022-07-21 05:01:25,960 INFO L276 IsEmpty]: Start isEmpty. Operand 53 states and 67 transitions. [2022-07-21 05:01:25,963 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 21 [2022-07-21 05:01:25,963 INFO L187 NwaCegarLoop]: Found error trace [2022-07-21 05:01:25,963 INFO L195 NwaCegarLoop]: trace histogram [1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-07-21 05:01:25,963 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable0 [2022-07-21 05:01:25,964 INFO L420 AbstractCegarLoop]: === Iteration 2 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2022-07-21 05:01:25,965 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2022-07-21 05:01:25,965 INFO L85 PathProgramCache]: Analyzing trace with hash 1987482606, now seen corresponding path program 1 times [2022-07-21 05:01:25,965 INFO L118 FreeRefinementEngine]: Executing refinement strategy CAMEL [2022-07-21 05:01:25,965 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [2052596889] [2022-07-21 05:01:25,966 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-07-21 05:01:25,966 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2022-07-21 05:01:26,013 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-07-21 05:01:26,056 INFO L134 CoverageAnalysis]: Checked inductivity of 0 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2022-07-21 05:01:26,056 INFO L136 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2022-07-21 05:01:26,056 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [2052596889] [2022-07-21 05:01:26,056 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [2052596889] provided 1 perfect and 0 imperfect interpolant sequences [2022-07-21 05:01:26,057 INFO L184 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2022-07-21 05:01:26,057 INFO L197 FreeRefinementEngine]: Number of different interpolants: perfect sequences [3] imperfect sequences [] total 3 [2022-07-21 05:01:26,057 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [1239732395] [2022-07-21 05:01:26,057 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2022-07-21 05:01:26,058 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 3 states [2022-07-21 05:01:26,059 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2022-07-21 05:01:26,059 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 3 interpolants. [2022-07-21 05:01:26,059 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=3, Invalid=3, Unknown=0, NotChecked=0, Total=6 [2022-07-21 05:01:26,059 INFO L87 Difference]: Start difference. First operand 53 states and 67 transitions. Second operand has 3 states, 3 states have (on average 6.0) internal successors, (18), 3 states have internal predecessors, (18), 1 states have call successors, (2), 1 states have call predecessors, (2), 0 states have return successors, (0), 0 states have call predecessors, (0), 0 states have call successors, (0) [2022-07-21 05:01:26,070 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-07-21 05:01:26,075 INFO L93 Difference]: Finished difference Result 68 states and 85 transitions. [2022-07-21 05:01:26,076 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 3 states. [2022-07-21 05:01:26,076 INFO L78 Accepts]: Start accepts. Automaton has has 3 states, 3 states have (on average 6.0) internal successors, (18), 3 states have internal predecessors, (18), 1 states have call successors, (2), 1 states have call predecessors, (2), 0 states have return successors, (0), 0 states have call predecessors, (0), 0 states have call successors, (0) Word has length 20 [2022-07-21 05:01:26,076 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2022-07-21 05:01:26,077 INFO L225 Difference]: With dead ends: 68 [2022-07-21 05:01:26,078 INFO L226 Difference]: Without dead ends: 44 [2022-07-21 05:01:26,079 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 3 GetRequests, 2 SyntacticMatches, 0 SemanticMatches, 1 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 0 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=3, Invalid=3, Unknown=0, NotChecked=0, Total=6 [2022-07-21 05:01:26,081 INFO L413 NwaCegarLoop]: 54 mSDtfsCounter, 17 mSDsluCounter, 33 mSDsCounter, 0 mSdLazyCounter, 1 mSolverCounterSat, 0 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.0s Time, 0 mProtectedPredicate, 0 mProtectedAction, 20 SdHoareTripleChecker+Valid, 87 SdHoareTripleChecker+Invalid, 1 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 0 IncrementalHoareTripleChecker+Valid, 1 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.0s IncrementalHoareTripleChecker+Time [2022-07-21 05:01:26,082 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [20 Valid, 87 Invalid, 1 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [0 Valid, 1 Invalid, 0 Unknown, 0 Unchecked, 0.0s Time] [2022-07-21 05:01:26,083 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 44 states. [2022-07-21 05:01:26,087 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 44 to 44. [2022-07-21 05:01:26,088 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 44 states, 37 states have (on average 1.3243243243243243) internal successors, (49), 40 states have internal predecessors, (49), 3 states have call successors, (3), 3 states have call predecessors, (3), 3 states have return successors, (3), 3 states have call predecessors, (3), 3 states have call successors, (3) [2022-07-21 05:01:26,089 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 44 states to 44 states and 55 transitions. [2022-07-21 05:01:26,090 INFO L78 Accepts]: Start accepts. Automaton has 44 states and 55 transitions. Word has length 20 [2022-07-21 05:01:26,090 INFO L84 Accepts]: Finished accepts. word is rejected. [2022-07-21 05:01:26,091 INFO L495 AbstractCegarLoop]: Abstraction has 44 states and 55 transitions. [2022-07-21 05:01:26,092 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 3 states, 3 states have (on average 6.0) internal successors, (18), 3 states have internal predecessors, (18), 1 states have call successors, (2), 1 states have call predecessors, (2), 0 states have return successors, (0), 0 states have call predecessors, (0), 0 states have call successors, (0) [2022-07-21 05:01:26,092 INFO L276 IsEmpty]: Start isEmpty. Operand 44 states and 55 transitions. [2022-07-21 05:01:26,093 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 25 [2022-07-21 05:01:26,094 INFO L187 NwaCegarLoop]: Found error trace [2022-07-21 05:01:26,094 INFO L195 NwaCegarLoop]: trace histogram [1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-07-21 05:01:26,095 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable1 [2022-07-21 05:01:26,095 INFO L420 AbstractCegarLoop]: === Iteration 3 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2022-07-21 05:01:26,096 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2022-07-21 05:01:26,099 INFO L85 PathProgramCache]: Analyzing trace with hash -296029766, now seen corresponding path program 1 times [2022-07-21 05:01:26,100 INFO L118 FreeRefinementEngine]: Executing refinement strategy CAMEL [2022-07-21 05:01:26,100 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [2061922536] [2022-07-21 05:01:26,101 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-07-21 05:01:26,101 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2022-07-21 05:01:26,135 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-07-21 05:01:26,174 INFO L134 CoverageAnalysis]: Checked inductivity of 0 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2022-07-21 05:01:26,174 INFO L136 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2022-07-21 05:01:26,175 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [2061922536] [2022-07-21 05:01:26,175 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [2061922536] provided 1 perfect and 0 imperfect interpolant sequences [2022-07-21 05:01:26,175 INFO L184 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2022-07-21 05:01:26,175 INFO L197 FreeRefinementEngine]: Number of different interpolants: perfect sequences [2] imperfect sequences [] total 2 [2022-07-21 05:01:26,175 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [1407628351] [2022-07-21 05:01:26,176 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2022-07-21 05:01:26,176 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 3 states [2022-07-21 05:01:26,176 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2022-07-21 05:01:26,177 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 3 interpolants. [2022-07-21 05:01:26,177 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=3, Invalid=3, Unknown=0, NotChecked=0, Total=6 [2022-07-21 05:01:26,177 INFO L87 Difference]: Start difference. First operand 44 states and 55 transitions. Second operand has 3 states, 3 states have (on average 7.666666666666667) internal successors, (23), 2 states have internal predecessors, (23), 1 states have call successors, (1), 1 states have call predecessors, (1), 0 states have return successors, (0), 0 states have call predecessors, (0), 0 states have call successors, (0) [2022-07-21 05:01:26,192 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-07-21 05:01:26,192 INFO L93 Difference]: Finished difference Result 117 states and 151 transitions. [2022-07-21 05:01:26,193 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 3 states. [2022-07-21 05:01:26,193 INFO L78 Accepts]: Start accepts. Automaton has has 3 states, 3 states have (on average 7.666666666666667) internal successors, (23), 2 states have internal predecessors, (23), 1 states have call successors, (1), 1 states have call predecessors, (1), 0 states have return successors, (0), 0 states have call predecessors, (0), 0 states have call successors, (0) Word has length 24 [2022-07-21 05:01:26,193 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2022-07-21 05:01:26,195 INFO L225 Difference]: With dead ends: 117 [2022-07-21 05:01:26,195 INFO L226 Difference]: Without dead ends: 80 [2022-07-21 05:01:26,195 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 2 GetRequests, 1 SyntacticMatches, 0 SemanticMatches, 1 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 0 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=3, Invalid=3, Unknown=0, NotChecked=0, Total=6 [2022-07-21 05:01:26,196 INFO L413 NwaCegarLoop]: 57 mSDtfsCounter, 35 mSDsluCounter, 45 mSDsCounter, 0 mSdLazyCounter, 4 mSolverCounterSat, 0 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.0s Time, 0 mProtectedPredicate, 0 mProtectedAction, 35 SdHoareTripleChecker+Valid, 102 SdHoareTripleChecker+Invalid, 4 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 0 IncrementalHoareTripleChecker+Valid, 4 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.0s IncrementalHoareTripleChecker+Time [2022-07-21 05:01:26,197 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [35 Valid, 102 Invalid, 4 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [0 Valid, 4 Invalid, 0 Unknown, 0 Unchecked, 0.0s Time] [2022-07-21 05:01:26,198 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 80 states. [2022-07-21 05:01:26,205 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 80 to 75. [2022-07-21 05:01:26,206 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 75 states, 62 states have (on average 1.3548387096774193) internal successors, (84), 67 states have internal predecessors, (84), 6 states have call successors, (6), 6 states have call predecessors, (6), 6 states have return successors, (6), 6 states have call predecessors, (6), 6 states have call successors, (6) [2022-07-21 05:01:26,207 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 75 states to 75 states and 96 transitions. [2022-07-21 05:01:26,207 INFO L78 Accepts]: Start accepts. Automaton has 75 states and 96 transitions. Word has length 24 [2022-07-21 05:01:26,207 INFO L84 Accepts]: Finished accepts. word is rejected. [2022-07-21 05:01:26,207 INFO L495 AbstractCegarLoop]: Abstraction has 75 states and 96 transitions. [2022-07-21 05:01:26,208 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 3 states, 3 states have (on average 7.666666666666667) internal successors, (23), 2 states have internal predecessors, (23), 1 states have call successors, (1), 1 states have call predecessors, (1), 0 states have return successors, (0), 0 states have call predecessors, (0), 0 states have call successors, (0) [2022-07-21 05:01:26,208 INFO L276 IsEmpty]: Start isEmpty. Operand 75 states and 96 transitions. [2022-07-21 05:01:26,209 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 26 [2022-07-21 05:01:26,209 INFO L187 NwaCegarLoop]: Found error trace [2022-07-21 05:01:26,209 INFO L195 NwaCegarLoop]: trace histogram [1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-07-21 05:01:26,209 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable2 [2022-07-21 05:01:26,209 INFO L420 AbstractCegarLoop]: === Iteration 4 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2022-07-21 05:01:26,210 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2022-07-21 05:01:26,210 INFO L85 PathProgramCache]: Analyzing trace with hash 1716566345, now seen corresponding path program 1 times [2022-07-21 05:01:26,210 INFO L118 FreeRefinementEngine]: Executing refinement strategy CAMEL [2022-07-21 05:01:26,210 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [529906814] [2022-07-21 05:01:26,211 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-07-21 05:01:26,211 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2022-07-21 05:01:26,231 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-07-21 05:01:26,277 INFO L134 CoverageAnalysis]: Checked inductivity of 0 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2022-07-21 05:01:26,277 INFO L136 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2022-07-21 05:01:26,277 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [529906814] [2022-07-21 05:01:26,278 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [529906814] provided 1 perfect and 0 imperfect interpolant sequences [2022-07-21 05:01:26,278 INFO L184 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2022-07-21 05:01:26,278 INFO L197 FreeRefinementEngine]: Number of different interpolants: perfect sequences [5] imperfect sequences [] total 5 [2022-07-21 05:01:26,278 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [1646930893] [2022-07-21 05:01:26,279 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2022-07-21 05:01:26,279 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 6 states [2022-07-21 05:01:26,279 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2022-07-21 05:01:26,280 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 6 interpolants. [2022-07-21 05:01:26,280 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=9, Invalid=21, Unknown=0, NotChecked=0, Total=30 [2022-07-21 05:01:26,280 INFO L87 Difference]: Start difference. First operand 75 states and 96 transitions. Second operand has 6 states, 6 states have (on average 4.0) internal successors, (24), 5 states have internal predecessors, (24), 1 states have call successors, (1), 1 states have call predecessors, (1), 0 states have return successors, (0), 0 states have call predecessors, (0), 0 states have call successors, (0) [2022-07-21 05:01:26,400 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-07-21 05:01:26,400 INFO L93 Difference]: Finished difference Result 243 states and 329 transitions. [2022-07-21 05:01:26,401 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 9 states. [2022-07-21 05:01:26,401 INFO L78 Accepts]: Start accepts. Automaton has has 6 states, 6 states have (on average 4.0) internal successors, (24), 5 states have internal predecessors, (24), 1 states have call successors, (1), 1 states have call predecessors, (1), 0 states have return successors, (0), 0 states have call predecessors, (0), 0 states have call successors, (0) Word has length 25 [2022-07-21 05:01:26,402 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2022-07-21 05:01:26,405 INFO L225 Difference]: With dead ends: 243 [2022-07-21 05:01:26,405 INFO L226 Difference]: Without dead ends: 175 [2022-07-21 05:01:26,406 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 11 GetRequests, 2 SyntacticMatches, 0 SemanticMatches, 9 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 7 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=40, Invalid=70, Unknown=0, NotChecked=0, Total=110 [2022-07-21 05:01:26,407 INFO L413 NwaCegarLoop]: 57 mSDtfsCounter, 112 mSDsluCounter, 227 mSDsCounter, 0 mSdLazyCounter, 50 mSolverCounterSat, 15 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.0s Time, 0 mProtectedPredicate, 0 mProtectedAction, 112 SdHoareTripleChecker+Valid, 284 SdHoareTripleChecker+Invalid, 65 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 15 IncrementalHoareTripleChecker+Valid, 50 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.1s IncrementalHoareTripleChecker+Time [2022-07-21 05:01:26,407 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [112 Valid, 284 Invalid, 65 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [15 Valid, 50 Invalid, 0 Unknown, 0 Unchecked, 0.1s Time] [2022-07-21 05:01:26,408 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 175 states. [2022-07-21 05:01:26,424 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 175 to 133. [2022-07-21 05:01:26,424 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 133 states, 110 states have (on average 1.3454545454545455) internal successors, (148), 119 states have internal predecessors, (148), 10 states have call successors, (10), 10 states have call predecessors, (10), 12 states have return successors, (14), 12 states have call predecessors, (14), 10 states have call successors, (14) [2022-07-21 05:01:26,426 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 133 states to 133 states and 172 transitions. [2022-07-21 05:01:26,426 INFO L78 Accepts]: Start accepts. Automaton has 133 states and 172 transitions. Word has length 25 [2022-07-21 05:01:26,426 INFO L84 Accepts]: Finished accepts. word is rejected. [2022-07-21 05:01:26,426 INFO L495 AbstractCegarLoop]: Abstraction has 133 states and 172 transitions. [2022-07-21 05:01:26,426 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 6 states, 6 states have (on average 4.0) internal successors, (24), 5 states have internal predecessors, (24), 1 states have call successors, (1), 1 states have call predecessors, (1), 0 states have return successors, (0), 0 states have call predecessors, (0), 0 states have call successors, (0) [2022-07-21 05:01:26,427 INFO L276 IsEmpty]: Start isEmpty. Operand 133 states and 172 transitions. [2022-07-21 05:01:26,436 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 28 [2022-07-21 05:01:26,436 INFO L187 NwaCegarLoop]: Found error trace [2022-07-21 05:01:26,437 INFO L195 NwaCegarLoop]: trace histogram [1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-07-21 05:01:26,437 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable3 [2022-07-21 05:01:26,437 INFO L420 AbstractCegarLoop]: === Iteration 5 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2022-07-21 05:01:26,437 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2022-07-21 05:01:26,438 INFO L85 PathProgramCache]: Analyzing trace with hash 1833945412, now seen corresponding path program 1 times [2022-07-21 05:01:26,438 INFO L118 FreeRefinementEngine]: Executing refinement strategy CAMEL [2022-07-21 05:01:26,438 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [1474320830] [2022-07-21 05:01:26,438 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-07-21 05:01:26,439 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2022-07-21 05:01:26,467 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-07-21 05:01:26,510 INFO L134 CoverageAnalysis]: Checked inductivity of 0 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2022-07-21 05:01:26,511 INFO L136 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2022-07-21 05:01:26,511 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [1474320830] [2022-07-21 05:01:26,511 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [1474320830] provided 1 perfect and 0 imperfect interpolant sequences [2022-07-21 05:01:26,511 INFO L184 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2022-07-21 05:01:26,511 INFO L197 FreeRefinementEngine]: Number of different interpolants: perfect sequences [2] imperfect sequences [] total 2 [2022-07-21 05:01:26,511 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [391201507] [2022-07-21 05:01:26,511 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2022-07-21 05:01:26,512 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 3 states [2022-07-21 05:01:26,512 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2022-07-21 05:01:26,512 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 3 interpolants. [2022-07-21 05:01:26,513 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=3, Invalid=3, Unknown=0, NotChecked=0, Total=6 [2022-07-21 05:01:26,513 INFO L87 Difference]: Start difference. First operand 133 states and 172 transitions. Second operand has 3 states, 3 states have (on average 8.666666666666666) internal successors, (26), 2 states have internal predecessors, (26), 1 states have call successors, (1), 1 states have call predecessors, (1), 0 states have return successors, (0), 0 states have call predecessors, (0), 0 states have call successors, (0) [2022-07-21 05:01:26,541 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-07-21 05:01:26,541 INFO L93 Difference]: Finished difference Result 249 states and 327 transitions. [2022-07-21 05:01:26,545 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 3 states. [2022-07-21 05:01:26,546 INFO L78 Accepts]: Start accepts. Automaton has has 3 states, 3 states have (on average 8.666666666666666) internal successors, (26), 2 states have internal predecessors, (26), 1 states have call successors, (1), 1 states have call predecessors, (1), 0 states have return successors, (0), 0 states have call predecessors, (0), 0 states have call successors, (0) Word has length 27 [2022-07-21 05:01:26,546 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2022-07-21 05:01:26,547 INFO L225 Difference]: With dead ends: 249 [2022-07-21 05:01:26,547 INFO L226 Difference]: Without dead ends: 123 [2022-07-21 05:01:26,548 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 2 GetRequests, 1 SyntacticMatches, 0 SemanticMatches, 1 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 0 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=3, Invalid=3, Unknown=0, NotChecked=0, Total=6 [2022-07-21 05:01:26,549 INFO L413 NwaCegarLoop]: 46 mSDtfsCounter, 33 mSDsluCounter, 0 mSDsCounter, 0 mSdLazyCounter, 3 mSolverCounterSat, 1 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.0s Time, 0 mProtectedPredicate, 0 mProtectedAction, 33 SdHoareTripleChecker+Valid, 46 SdHoareTripleChecker+Invalid, 4 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 1 IncrementalHoareTripleChecker+Valid, 3 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.0s IncrementalHoareTripleChecker+Time [2022-07-21 05:01:26,549 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [33 Valid, 46 Invalid, 4 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [1 Valid, 3 Invalid, 0 Unknown, 0 Unchecked, 0.0s Time] [2022-07-21 05:01:26,554 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 123 states. [2022-07-21 05:01:26,563 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 123 to 123. [2022-07-21 05:01:26,564 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 123 states, 100 states have (on average 1.28) internal successors, (128), 109 states have internal predecessors, (128), 10 states have call successors, (10), 10 states have call predecessors, (10), 12 states have return successors, (12), 12 states have call predecessors, (12), 10 states have call successors, (12) [2022-07-21 05:01:26,565 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 123 states to 123 states and 150 transitions. [2022-07-21 05:01:26,565 INFO L78 Accepts]: Start accepts. Automaton has 123 states and 150 transitions. Word has length 27 [2022-07-21 05:01:26,565 INFO L84 Accepts]: Finished accepts. word is rejected. [2022-07-21 05:01:26,566 INFO L495 AbstractCegarLoop]: Abstraction has 123 states and 150 transitions. [2022-07-21 05:01:26,566 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 3 states, 3 states have (on average 8.666666666666666) internal successors, (26), 2 states have internal predecessors, (26), 1 states have call successors, (1), 1 states have call predecessors, (1), 0 states have return successors, (0), 0 states have call predecessors, (0), 0 states have call successors, (0) [2022-07-21 05:01:26,566 INFO L276 IsEmpty]: Start isEmpty. Operand 123 states and 150 transitions. [2022-07-21 05:01:26,566 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 30 [2022-07-21 05:01:26,567 INFO L187 NwaCegarLoop]: Found error trace [2022-07-21 05:01:26,567 INFO L195 NwaCegarLoop]: trace histogram [1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-07-21 05:01:26,567 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable4 [2022-07-21 05:01:26,567 INFO L420 AbstractCegarLoop]: === Iteration 6 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2022-07-21 05:01:26,567 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2022-07-21 05:01:26,568 INFO L85 PathProgramCache]: Analyzing trace with hash 957939555, now seen corresponding path program 1 times [2022-07-21 05:01:26,568 INFO L118 FreeRefinementEngine]: Executing refinement strategy CAMEL [2022-07-21 05:01:26,568 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [2046599265] [2022-07-21 05:01:26,568 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-07-21 05:01:26,568 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2022-07-21 05:01:26,581 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-07-21 05:01:26,636 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 11 [2022-07-21 05:01:26,640 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-07-21 05:01:26,663 INFO L134 CoverageAnalysis]: Checked inductivity of 0 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2022-07-21 05:01:26,664 INFO L136 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2022-07-21 05:01:26,664 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [2046599265] [2022-07-21 05:01:26,664 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [2046599265] provided 1 perfect and 0 imperfect interpolant sequences [2022-07-21 05:01:26,664 INFO L184 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2022-07-21 05:01:26,665 INFO L197 FreeRefinementEngine]: Number of different interpolants: perfect sequences [7] imperfect sequences [] total 7 [2022-07-21 05:01:26,665 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [1586506487] [2022-07-21 05:01:26,665 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2022-07-21 05:01:26,667 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 8 states [2022-07-21 05:01:26,667 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2022-07-21 05:01:26,668 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 8 interpolants. [2022-07-21 05:01:26,668 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=14, Invalid=42, Unknown=0, NotChecked=0, Total=56 [2022-07-21 05:01:26,668 INFO L87 Difference]: Start difference. First operand 123 states and 150 transitions. Second operand has 8 states, 8 states have (on average 3.25) internal successors, (26), 6 states have internal predecessors, (26), 2 states have call successors, (2), 2 states have call predecessors, (2), 1 states have return successors, (1), 1 states have call predecessors, (1), 1 states have call successors, (1) [2022-07-21 05:01:26,845 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-07-21 05:01:26,845 INFO L93 Difference]: Finished difference Result 355 states and 445 transitions. [2022-07-21 05:01:26,845 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 14 states. [2022-07-21 05:01:26,848 INFO L78 Accepts]: Start accepts. Automaton has has 8 states, 8 states have (on average 3.25) internal successors, (26), 6 states have internal predecessors, (26), 2 states have call successors, (2), 2 states have call predecessors, (2), 1 states have return successors, (1), 1 states have call predecessors, (1), 1 states have call successors, (1) Word has length 29 [2022-07-21 05:01:26,848 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2022-07-21 05:01:26,851 INFO L225 Difference]: With dead ends: 355 [2022-07-21 05:01:26,851 INFO L226 Difference]: Without dead ends: 239 [2022-07-21 05:01:26,852 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 16 GetRequests, 2 SyntacticMatches, 0 SemanticMatches, 14 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 27 ImplicationChecksByTransitivity, 0.1s TimeCoverageRelationStatistics Valid=69, Invalid=171, Unknown=0, NotChecked=0, Total=240 [2022-07-21 05:01:26,862 INFO L413 NwaCegarLoop]: 46 mSDtfsCounter, 142 mSDsluCounter, 198 mSDsCounter, 0 mSdLazyCounter, 103 mSolverCounterSat, 21 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.1s Time, 0 mProtectedPredicate, 0 mProtectedAction, 144 SdHoareTripleChecker+Valid, 244 SdHoareTripleChecker+Invalid, 124 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 21 IncrementalHoareTripleChecker+Valid, 103 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.1s IncrementalHoareTripleChecker+Time [2022-07-21 05:01:26,864 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [144 Valid, 244 Invalid, 124 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [21 Valid, 103 Invalid, 0 Unknown, 0 Unchecked, 0.1s Time] [2022-07-21 05:01:26,867 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 239 states. [2022-07-21 05:01:26,896 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 239 to 180. [2022-07-21 05:01:26,900 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 180 states, 145 states have (on average 1.2689655172413794) internal successors, (184), 158 states have internal predecessors, (184), 16 states have call successors, (16), 16 states have call predecessors, (16), 18 states have return successors, (18), 16 states have call predecessors, (18), 16 states have call successors, (18) [2022-07-21 05:01:26,902 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 180 states to 180 states and 218 transitions. [2022-07-21 05:01:26,906 INFO L78 Accepts]: Start accepts. Automaton has 180 states and 218 transitions. Word has length 29 [2022-07-21 05:01:26,907 INFO L84 Accepts]: Finished accepts. word is rejected. [2022-07-21 05:01:26,907 INFO L495 AbstractCegarLoop]: Abstraction has 180 states and 218 transitions. [2022-07-21 05:01:26,907 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 8 states, 8 states have (on average 3.25) internal successors, (26), 6 states have internal predecessors, (26), 2 states have call successors, (2), 2 states have call predecessors, (2), 1 states have return successors, (1), 1 states have call predecessors, (1), 1 states have call successors, (1) [2022-07-21 05:01:26,907 INFO L276 IsEmpty]: Start isEmpty. Operand 180 states and 218 transitions. [2022-07-21 05:01:26,909 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 52 [2022-07-21 05:01:26,909 INFO L187 NwaCegarLoop]: Found error trace [2022-07-21 05:01:26,910 INFO L195 NwaCegarLoop]: trace histogram [2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-07-21 05:01:26,911 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable5 [2022-07-21 05:01:26,911 INFO L420 AbstractCegarLoop]: === Iteration 7 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2022-07-21 05:01:26,912 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2022-07-21 05:01:26,913 INFO L85 PathProgramCache]: Analyzing trace with hash -426576330, now seen corresponding path program 1 times [2022-07-21 05:01:26,913 INFO L118 FreeRefinementEngine]: Executing refinement strategy CAMEL [2022-07-21 05:01:26,913 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [550947210] [2022-07-21 05:01:26,913 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-07-21 05:01:26,914 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2022-07-21 05:01:26,942 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-07-21 05:01:26,989 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 11 [2022-07-21 05:01:26,993 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-07-21 05:01:26,995 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 19 [2022-07-21 05:01:27,002 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-07-21 05:01:27,009 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 33 [2022-07-21 05:01:27,011 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-07-21 05:01:27,013 INFO L134 CoverageAnalysis]: Checked inductivity of 19 backedges. 0 proven. 1 refuted. 0 times theorem prover too weak. 18 trivial. 0 not checked. [2022-07-21 05:01:27,013 INFO L136 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2022-07-21 05:01:27,013 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [550947210] [2022-07-21 05:01:27,013 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [550947210] provided 0 perfect and 1 imperfect interpolant sequences [2022-07-21 05:01:27,013 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleZ3 [1440753116] [2022-07-21 05:01:27,014 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-07-21 05:01:27,014 INFO L173 SolverBuilder]: Constructing external solver with command: z3 -smt2 -in SMTLIB2_COMPLIANT=true [2022-07-21 05:01:27,014 INFO L189 MonitoredProcess]: No working directory specified, using /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 [2022-07-21 05:01:27,019 INFO L229 MonitoredProcess]: Starting monitored process 2 with /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 -smt2 -in SMTLIB2_COMPLIANT=true (exit command is (exit), workingDir is null) [2022-07-21 05:01:27,049 INFO L327 MonitoredProcess]: [MP /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 -smt2 -in SMTLIB2_COMPLIANT=true (2)] Waiting until timeout for monitored process [2022-07-21 05:01:27,112 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-07-21 05:01:27,115 INFO L263 TraceCheckSpWp]: Trace formula consists of 344 conjuncts, 9 conjunts are in the unsatisfiable core [2022-07-21 05:01:27,120 INFO L286 TraceCheckSpWp]: Computing forward predicates... [2022-07-21 05:01:27,294 INFO L134 CoverageAnalysis]: Checked inductivity of 19 backedges. 16 proven. 2 refuted. 0 times theorem prover too weak. 1 trivial. 0 not checked. [2022-07-21 05:01:27,294 INFO L328 TraceCheckSpWp]: Computing backward predicates... [2022-07-21 05:01:27,484 INFO L134 CoverageAnalysis]: Checked inductivity of 19 backedges. 16 proven. 3 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2022-07-21 05:01:27,485 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleZ3 [1440753116] provided 0 perfect and 2 imperfect interpolant sequences [2022-07-21 05:01:27,485 INFO L184 FreeRefinementEngine]: Found 0 perfect and 3 imperfect interpolant sequences. [2022-07-21 05:01:27,485 INFO L197 FreeRefinementEngine]: Number of different interpolants: perfect sequences [] imperfect sequences [6, 6, 7] total 14 [2022-07-21 05:01:27,485 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [646039186] [2022-07-21 05:01:27,485 INFO L85 oduleStraightlineAll]: Using 3 imperfect interpolants to construct interpolant automaton [2022-07-21 05:01:27,486 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 14 states [2022-07-21 05:01:27,486 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2022-07-21 05:01:27,487 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 14 interpolants. [2022-07-21 05:01:27,487 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=42, Invalid=140, Unknown=0, NotChecked=0, Total=182 [2022-07-21 05:01:27,487 INFO L87 Difference]: Start difference. First operand 180 states and 218 transitions. Second operand has 14 states, 14 states have (on average 6.0) internal successors, (84), 12 states have internal predecessors, (84), 4 states have call successors, (10), 6 states have call predecessors, (10), 7 states have return successors, (7), 3 states have call predecessors, (7), 3 states have call successors, (7) [2022-07-21 05:01:27,649 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-07-21 05:01:27,650 INFO L93 Difference]: Finished difference Result 237 states and 290 transitions. [2022-07-21 05:01:27,650 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 7 states. [2022-07-21 05:01:27,650 INFO L78 Accepts]: Start accepts. Automaton has has 14 states, 14 states have (on average 6.0) internal successors, (84), 12 states have internal predecessors, (84), 4 states have call successors, (10), 6 states have call predecessors, (10), 7 states have return successors, (7), 3 states have call predecessors, (7), 3 states have call successors, (7) Word has length 51 [2022-07-21 05:01:27,651 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2022-07-21 05:01:27,651 INFO L225 Difference]: With dead ends: 237 [2022-07-21 05:01:27,651 INFO L226 Difference]: Without dead ends: 0 [2022-07-21 05:01:27,652 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 116 GetRequests, 98 SyntacticMatches, 1 SemanticMatches, 17 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 29 ImplicationChecksByTransitivity, 0.1s TimeCoverageRelationStatistics Valid=91, Invalid=251, Unknown=0, NotChecked=0, Total=342 [2022-07-21 05:01:27,652 INFO L413 NwaCegarLoop]: 65 mSDtfsCounter, 129 mSDsluCounter, 307 mSDsCounter, 0 mSdLazyCounter, 131 mSolverCounterSat, 39 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.1s Time, 0 mProtectedPredicate, 0 mProtectedAction, 129 SdHoareTripleChecker+Valid, 372 SdHoareTripleChecker+Invalid, 170 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 39 IncrementalHoareTripleChecker+Valid, 131 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.1s IncrementalHoareTripleChecker+Time [2022-07-21 05:01:27,652 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [129 Valid, 372 Invalid, 170 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [39 Valid, 131 Invalid, 0 Unknown, 0 Unchecked, 0.1s Time] [2022-07-21 05:01:27,653 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 0 states. [2022-07-21 05:01:27,653 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 0 to 0. [2022-07-21 05:01:27,653 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 0 states, 0 states have (on average 0.0) internal successors, (0), 0 states have internal predecessors, (0), 0 states have call successors, (0), 0 states have call predecessors, (0), 0 states have return successors, (0), 0 states have call predecessors, (0), 0 states have call successors, (0) [2022-07-21 05:01:27,653 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 0 states to 0 states and 0 transitions. [2022-07-21 05:01:27,654 INFO L78 Accepts]: Start accepts. Automaton has 0 states and 0 transitions. Word has length 51 [2022-07-21 05:01:27,654 INFO L84 Accepts]: Finished accepts. word is rejected. [2022-07-21 05:01:27,654 INFO L495 AbstractCegarLoop]: Abstraction has 0 states and 0 transitions. [2022-07-21 05:01:27,654 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 14 states, 14 states have (on average 6.0) internal successors, (84), 12 states have internal predecessors, (84), 4 states have call successors, (10), 6 states have call predecessors, (10), 7 states have return successors, (7), 3 states have call predecessors, (7), 3 states have call successors, (7) [2022-07-21 05:01:27,654 INFO L276 IsEmpty]: Start isEmpty. Operand 0 states and 0 transitions. [2022-07-21 05:01:27,654 INFO L282 IsEmpty]: Finished isEmpty. No accepting run. [2022-07-21 05:01:27,656 INFO L805 garLoopResultBuilder]: Registering result SAFE for location timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION (0 of 1 remaining) [2022-07-21 05:01:27,678 INFO L552 MonitoredProcess]: [MP /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 -smt2 -in SMTLIB2_COMPLIANT=true (2)] Ended with exit code 0 [2022-07-21 05:01:27,871 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable6,2 /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 -smt2 -in SMTLIB2_COMPLIANT=true [2022-07-21 05:01:27,873 INFO L343 DoubleDeckerVisitor]: Before removal of dead ends 0 states and 0 transitions. [2022-07-21 05:01:28,517 INFO L899 garLoopResultBuilder]: For program point L336-1(lines 332 343) no Hoare annotation was computed. [2022-07-21 05:01:28,518 INFO L902 garLoopResultBuilder]: At program point changeMethaneLevelENTRY(lines 332 343) the Hoare annotation is: true [2022-07-21 05:01:28,518 INFO L899 garLoopResultBuilder]: For program point changeMethaneLevelEXIT(lines 332 343) no Hoare annotation was computed. [2022-07-21 05:01:28,518 INFO L899 garLoopResultBuilder]: For program point cleanupEXIT(lines 387 416) no Hoare annotation was computed. [2022-07-21 05:01:28,518 INFO L902 garLoopResultBuilder]: At program point cleanupENTRY(lines 387 416) the Hoare annotation is: true [2022-07-21 05:01:28,518 INFO L902 garLoopResultBuilder]: At program point L412(lines 387 416) the Hoare annotation is: true [2022-07-21 05:01:28,518 INFO L899 garLoopResultBuilder]: For program point L408(line 408) no Hoare annotation was computed. [2022-07-21 05:01:28,519 INFO L899 garLoopResultBuilder]: For program point L401(lines 401 405) no Hoare annotation was computed. [2022-07-21 05:01:28,519 INFO L902 garLoopResultBuilder]: At program point L401-1(lines 401 405) the Hoare annotation is: true [2022-07-21 05:01:28,519 INFO L899 garLoopResultBuilder]: For program point L398(line 398) no Hoare annotation was computed. [2022-07-21 05:01:28,519 INFO L902 garLoopResultBuilder]: At program point L397-2(lines 397 411) the Hoare annotation is: true [2022-07-21 05:01:28,519 INFO L902 garLoopResultBuilder]: At program point L393(line 393) the Hoare annotation is: true [2022-07-21 05:01:28,519 INFO L899 garLoopResultBuilder]: For program point L393-1(line 393) no Hoare annotation was computed. [2022-07-21 05:01:28,519 INFO L895 garLoopResultBuilder]: At program point L153(lines 148 156) the Hoare annotation is: (or (not (= ~pumpRunning~0 0)) (not (<= 1 |old(~waterLevel~0)|))) [2022-07-21 05:01:28,519 INFO L899 garLoopResultBuilder]: For program point L312(lines 312 316) no Hoare annotation was computed. [2022-07-21 05:01:28,520 INFO L895 garLoopResultBuilder]: At program point L312-2(lines 308 319) the Hoare annotation is: (or (not (= ~pumpRunning~0 0)) (not (<= 1 |old(~waterLevel~0)|))) [2022-07-21 05:01:28,520 INFO L899 garLoopResultBuilder]: For program point L54(line 54) no Hoare annotation was computed. [2022-07-21 05:01:28,520 INFO L899 garLoopResultBuilder]: For program point L83-1(lines 83 89) no Hoare annotation was computed. [2022-07-21 05:01:28,520 INFO L899 garLoopResultBuilder]: For program point timeShiftFINAL(lines 72 95) no Hoare annotation was computed. [2022-07-21 05:01:28,520 INFO L895 garLoopResultBuilder]: At program point L100(lines 96 102) the Hoare annotation is: (let ((.cse0 (not (= ~pumpRunning~0 0)))) (and (or .cse0 (= |old(~waterLevel~0)| ~waterLevel~0) (not (<= 2 |old(~waterLevel~0)|))) (or .cse0 (not (= |old(~waterLevel~0)| 1)) (= ~waterLevel~0 1)))) [2022-07-21 05:01:28,520 INFO L899 garLoopResultBuilder]: For program point L292(lines 292 298) no Hoare annotation was computed. [2022-07-21 05:01:28,520 INFO L899 garLoopResultBuilder]: For program point L288(lines 288 301) no Hoare annotation was computed. [2022-07-21 05:01:28,520 INFO L895 garLoopResultBuilder]: At program point L288-1(lines 280 304) the Hoare annotation is: (let ((.cse0 (not (= ~pumpRunning~0 0))) (.cse1 (not (= |timeShift___utac_acc__Specification4_spec__1_~tmp~2#1| 0))) (.cse2 (not (= |timeShift_getWaterLevel_#res#1| 0)))) (and (or .cse0 (and .cse1 .cse2 (= |old(~waterLevel~0)| ~waterLevel~0)) (not (<= 2 |old(~waterLevel~0)|))) (or .cse0 (not (= |old(~waterLevel~0)| 1)) (and .cse1 .cse2 (= ~waterLevel~0 1))))) [2022-07-21 05:01:28,521 INFO L895 garLoopResultBuilder]: At program point L381(lines 376 384) the Hoare annotation is: (let ((.cse1 (not (= ~pumpRunning~0 0))) (.cse0 (not (= |timeShift_getWaterLevel_#res#1| 0)))) (and (or (and .cse0 (= ~waterLevel~0 1)) .cse1 (not (= |old(~waterLevel~0)| 1))) (or .cse1 (and .cse0 (= |old(~waterLevel~0)| ~waterLevel~0)) (not (<= 2 |old(~waterLevel~0)|))))) [2022-07-21 05:01:28,521 INFO L895 garLoopResultBuilder]: At program point L55(lines 50 57) the Hoare annotation is: (or (not (= ~pumpRunning~0 0)) (not (<= 1 |old(~waterLevel~0)|))) [2022-07-21 05:01:28,521 INFO L895 garLoopResultBuilder]: At program point timeShiftENTRY(lines 72 95) the Hoare annotation is: (let ((.cse0 (not (= ~pumpRunning~0 0)))) (and (or .cse0 (= |old(~waterLevel~0)| ~waterLevel~0) (not (<= 2 |old(~waterLevel~0)|))) (or .cse0 (not (= |old(~waterLevel~0)| 1)) (= ~waterLevel~0 1)))) [2022-07-21 05:01:28,521 INFO L899 garLoopResultBuilder]: For program point L76-1(lines 75 94) no Hoare annotation was computed. [2022-07-21 05:01:28,521 INFO L899 garLoopResultBuilder]: For program point timeShiftEXIT(lines 72 95) no Hoare annotation was computed. [2022-07-21 05:01:28,521 INFO L899 garLoopResultBuilder]: For program point timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION(line 54) no Hoare annotation was computed. [2022-07-21 05:01:28,521 INFO L895 garLoopResultBuilder]: At program point L258-2(lines 252 265) the Hoare annotation is: (let ((.cse0 (= ~pumpRunning~0 0)) (.cse1 (= |ULTIMATE.start_test_~splverifierCounter~0#1| 0))) (or (and .cse0 .cse1 (= ~waterLevel~0 1)) (and .cse0 (<= 2 ~waterLevel~0) .cse1))) [2022-07-21 05:01:28,522 INFO L899 garLoopResultBuilder]: For program point L242(lines 242 248) no Hoare annotation was computed. [2022-07-21 05:01:28,522 INFO L899 garLoopResultBuilder]: For program point L242-1(lines 242 248) no Hoare annotation was computed. [2022-07-21 05:01:28,522 INFO L895 garLoopResultBuilder]: At program point L205(lines 193 207) the Hoare annotation is: (let ((.cse0 (= ~pumpRunning~0 0)) (.cse1 (= |ULTIMATE.start_test_~splverifierCounter~0#1| 0))) (or (and .cse0 .cse1 (= ~waterLevel~0 1)) (and .cse0 (<= 2 ~waterLevel~0) .cse1))) [2022-07-21 05:01:28,522 INFO L895 garLoopResultBuilder]: At program point L267(lines 222 269) the Hoare annotation is: (let ((.cse0 (= ~pumpRunning~0 0)) (.cse1 (= |ULTIMATE.start_test_~splverifierCounter~0#1| 0))) (or (and .cse0 .cse1 (= ~waterLevel~0 1)) (and .cse0 (<= 2 ~waterLevel~0) .cse1))) [2022-07-21 05:01:28,522 INFO L895 garLoopResultBuilder]: At program point L234(line 234) the Hoare annotation is: (let ((.cse0 (= ~pumpRunning~0 0)) (.cse1 (= |ULTIMATE.start_test_~splverifierCounter~0#1| 0))) (or (and .cse0 .cse1 (= ~waterLevel~0 1)) (and .cse0 (<= 2 ~waterLevel~0) .cse1))) [2022-07-21 05:01:28,522 INFO L899 garLoopResultBuilder]: For program point L197(lines 197 203) no Hoare annotation was computed. [2022-07-21 05:01:28,522 INFO L899 garLoopResultBuilder]: For program point L197-2(lines 197 203) no Hoare annotation was computed. [2022-07-21 05:01:28,522 INFO L895 garLoopResultBuilder]: At program point L866(lines 862 868) the Hoare annotation is: (and (= ~pumpRunning~0 0) (= ~waterLevel~0 1) (= ~waterLevel~0 ~systemActive~0)) [2022-07-21 05:01:28,522 INFO L899 garLoopResultBuilder]: For program point L-1(line -1) no Hoare annotation was computed. [2022-07-21 05:01:28,523 INFO L899 garLoopResultBuilder]: For program point ULTIMATE.startENTRY(line -1) no Hoare annotation was computed. [2022-07-21 05:01:28,523 INFO L895 garLoopResultBuilder]: At program point L445(lines 441 447) the Hoare annotation is: (and (= ~pumpRunning~0 0) (= ~waterLevel~0 1) (= ~waterLevel~0 ~systemActive~0)) [2022-07-21 05:01:28,523 INFO L899 garLoopResultBuilder]: For program point ULTIMATE.startFINAL(line -1) no Hoare annotation was computed. [2022-07-21 05:01:28,523 INFO L899 garLoopResultBuilder]: For program point ULTIMATE.startEXIT(line -1) no Hoare annotation was computed. [2022-07-21 05:01:28,523 INFO L899 garLoopResultBuilder]: For program point L223(lines 222 269) no Hoare annotation was computed. [2022-07-21 05:01:28,523 INFO L899 garLoopResultBuilder]: For program point L252(lines 252 265) no Hoare annotation was computed. [2022-07-21 05:01:28,523 INFO L899 garLoopResultBuilder]: For program point L471(lines 471 478) no Hoare annotation was computed. [2022-07-21 05:01:28,523 INFO L899 garLoopResultBuilder]: For program point L471-2(lines 471 478) no Hoare annotation was computed. [2022-07-21 05:01:28,524 INFO L895 garLoopResultBuilder]: At program point L244(line 244) the Hoare annotation is: (let ((.cse0 (= ~pumpRunning~0 0)) (.cse1 (= |ULTIMATE.start_test_~splverifierCounter~0#1| 0))) (or (and .cse0 .cse1 (= ~waterLevel~0 1)) (and .cse0 (<= 2 ~waterLevel~0) .cse1))) [2022-07-21 05:01:28,524 INFO L902 garLoopResultBuilder]: At program point L273(lines 212 277) the Hoare annotation is: true [2022-07-21 05:01:28,524 INFO L899 garLoopResultBuilder]: For program point L232(lines 232 238) no Hoare annotation was computed. [2022-07-21 05:01:28,524 INFO L899 garLoopResultBuilder]: For program point L232-1(lines 232 238) no Hoare annotation was computed. [2022-07-21 05:01:28,524 INFO L902 garLoopResultBuilder]: At program point L455(lines 448 457) the Hoare annotation is: true [2022-07-21 05:01:28,524 INFO L899 garLoopResultBuilder]: For program point L224(lines 224 228) no Hoare annotation was computed. [2022-07-21 05:01:28,524 INFO L902 garLoopResultBuilder]: At program point L480(lines 461 483) the Hoare annotation is: true [2022-07-21 05:01:28,524 INFO L895 garLoopResultBuilder]: At program point L881(lines 876 884) the Hoare annotation is: (and (= ~pumpRunning~0 0) (= ~waterLevel~0 1) (= ~waterLevel~0 ~systemActive~0)) [2022-07-21 05:01:28,524 INFO L895 garLoopResultBuilder]: At program point L270(lines 221 271) the Hoare annotation is: false [2022-07-21 05:01:28,525 INFO L895 garLoopResultBuilder]: At program point L873(lines 869 875) the Hoare annotation is: (and (= ~pumpRunning~0 0) (= ~waterLevel~0 1) (= ~waterLevel~0 ~systemActive~0)) [2022-07-21 05:01:28,525 INFO L895 garLoopResultBuilder]: At program point L134(lines 129 136) the Hoare annotation is: false [2022-07-21 05:01:28,525 INFO L899 garLoopResultBuilder]: For program point L258(lines 258 264) no Hoare annotation was computed. [2022-07-21 05:01:28,525 INFO L899 garLoopResultBuilder]: For program point waterRiseEXIT(lines 320 331) no Hoare annotation was computed. [2022-07-21 05:01:28,525 INFO L895 garLoopResultBuilder]: At program point waterRiseENTRY(lines 320 331) the Hoare annotation is: (let ((.cse0 (not (= ~pumpRunning~0 0)))) (and (or .cse0 (= |old(~waterLevel~0)| ~waterLevel~0) (not (<= 2 |old(~waterLevel~0)|))) (or .cse0 (not (= |old(~waterLevel~0)| 1)) (= ~waterLevel~0 1)))) [2022-07-21 05:01:28,525 INFO L899 garLoopResultBuilder]: For program point L324-1(lines 320 331) no Hoare annotation was computed. [2022-07-21 05:01:28,529 INFO L356 BasicCegarLoop]: Path program histogram: [1, 1, 1, 1, 1, 1, 1] [2022-07-21 05:01:28,531 INFO L176 ceAbstractionStarter]: Computing trace abstraction results [2022-07-21 05:01:28,545 INFO L202 PluginConnector]: Adding new model de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction CFG 21.07 05:01:28 BoogieIcfgContainer [2022-07-21 05:01:28,545 INFO L132 PluginConnector]: ------------------------ END TraceAbstraction---------------------------- [2022-07-21 05:01:28,546 INFO L113 PluginConnector]: ------------------------Witness Printer---------------------------- [2022-07-21 05:01:28,546 INFO L271 PluginConnector]: Initializing Witness Printer... [2022-07-21 05:01:28,546 INFO L275 PluginConnector]: Witness Printer initialized [2022-07-21 05:01:28,546 INFO L185 PluginConnector]: Executing the observer RCFGCatcher from plugin Witness Printer for "de.uni_freiburg.informatik.ultimate.plugins.generator.rcfgbuilder CFG 21.07 05:01:25" (3/4) ... [2022-07-21 05:01:28,549 INFO L137 WitnessPrinter]: Generating witness for correct program [2022-07-21 05:01:28,554 INFO L354 RCFGBacktranslator]: Ignoring RootEdge to procedure changeMethaneLevel [2022-07-21 05:01:28,554 INFO L354 RCFGBacktranslator]: Ignoring RootEdge to procedure cleanup [2022-07-21 05:01:28,554 INFO L354 RCFGBacktranslator]: Ignoring RootEdge to procedure timeShift [2022-07-21 05:01:28,555 INFO L354 RCFGBacktranslator]: Ignoring RootEdge to procedure waterRise [2022-07-21 05:01:28,562 INFO L910 BoogieBacktranslator]: Reduced CFG by removing 46 nodes and edges [2022-07-21 05:01:28,562 INFO L910 BoogieBacktranslator]: Reduced CFG by removing 22 nodes and edges [2022-07-21 05:01:28,563 INFO L910 BoogieBacktranslator]: Reduced CFG by removing 11 nodes and edges [2022-07-21 05:01:28,567 INFO L910 BoogieBacktranslator]: Reduced CFG by removing 5 nodes and edges [2022-07-21 05:01:28,567 INFO L910 BoogieBacktranslator]: Reduced CFG by removing 2 nodes and edges [2022-07-21 05:01:28,567 INFO L910 BoogieBacktranslator]: Reduced CFG by removing 1 nodes and edges [2022-07-21 05:01:28,567 INFO L910 BoogieBacktranslator]: Reduced CFG by removing 1 nodes and edges [2022-07-21 05:01:28,588 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: !(pumpRunning == 0) || !(1 <= \old(waterLevel)) [2022-07-21 05:01:28,589 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: ((!(pumpRunning == 0) || \old(waterLevel) == waterLevel) || !(2 <= \old(waterLevel))) && ((!(pumpRunning == 0) || !(\old(waterLevel) == 1)) || waterLevel == 1) [2022-07-21 05:01:28,589 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (((!(\result == 0) && waterLevel == 1) || !(pumpRunning == 0)) || !(\old(waterLevel) == 1)) && ((!(pumpRunning == 0) || (!(\result == 0) && \old(waterLevel) == waterLevel)) || !(2 <= \old(waterLevel))) [2022-07-21 05:01:28,590 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: ((!(pumpRunning == 0) || ((!(tmp == 0) && !(\result == 0)) && \old(waterLevel) == waterLevel)) || !(2 <= \old(waterLevel))) && ((!(pumpRunning == 0) || !(\old(waterLevel) == 1)) || ((!(tmp == 0) && !(\result == 0)) && waterLevel == 1)) [2022-07-21 05:01:28,590 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: !(pumpRunning == 0) || !(1 <= \old(waterLevel)) [2022-07-21 05:01:28,590 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: !(pumpRunning == 0) || !(1 <= \old(waterLevel)) [2022-07-21 05:01:28,604 INFO L141 WitnessManager]: Wrote witness to /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/witness.graphml [2022-07-21 05:01:28,604 INFO L132 PluginConnector]: ------------------------ END Witness Printer---------------------------- [2022-07-21 05:01:28,605 INFO L158 Benchmark]: Toolchain (without parser) took 4150.56ms. Allocated memory was 50.3MB in the beginning and 73.4MB in the end (delta: 23.1MB). Free memory was 26.7MB in the beginning and 51.0MB in the end (delta: -24.3MB). Peak memory consumption was 23.7MB. Max. memory is 16.1GB. [2022-07-21 05:01:28,605 INFO L158 Benchmark]: CDTParser took 0.10ms. Allocated memory is still 50.3MB. Free memory was 32.4MB in the beginning and 32.4MB in the end (delta: 40.0kB). There was no memory consumed. Max. memory is 16.1GB. [2022-07-21 05:01:28,605 INFO L158 Benchmark]: CACSL2BoogieTranslator took 383.35ms. Allocated memory was 50.3MB in the beginning and 60.8MB in the end (delta: 10.5MB). Free memory was 26.5MB in the beginning and 37.0MB in the end (delta: -10.5MB). Peak memory consumption was 5.2MB. Max. memory is 16.1GB. [2022-07-21 05:01:28,605 INFO L158 Benchmark]: Boogie Procedure Inliner took 65.05ms. Allocated memory is still 60.8MB. Free memory was 36.8MB in the beginning and 34.7MB in the end (delta: 2.1MB). Peak memory consumption was 2.1MB. Max. memory is 16.1GB. [2022-07-21 05:01:28,606 INFO L158 Benchmark]: Boogie Preprocessor took 45.88ms. Allocated memory is still 60.8MB. Free memory was 34.7MB in the beginning and 33.2MB in the end (delta: 1.5MB). Peak memory consumption was 2.1MB. Max. memory is 16.1GB. [2022-07-21 05:01:28,606 INFO L158 Benchmark]: RCFGBuilder took 504.75ms. Allocated memory is still 60.8MB. Free memory was 33.2MB in the beginning and 34.2MB in the end (delta: -919.4kB). Peak memory consumption was 10.1MB. Max. memory is 16.1GB. [2022-07-21 05:01:28,606 INFO L158 Benchmark]: TraceAbstraction took 3086.92ms. Allocated memory was 60.8MB in the beginning and 73.4MB in the end (delta: 12.6MB). Free memory was 33.7MB in the beginning and 28.3MB in the end (delta: 5.4MB). Peak memory consumption was 20.9MB. Max. memory is 16.1GB. [2022-07-21 05:01:28,607 INFO L158 Benchmark]: Witness Printer took 58.39ms. Allocated memory is still 73.4MB. Free memory was 28.3MB in the beginning and 51.0MB in the end (delta: -22.7MB). Peak memory consumption was 2.3MB. Max. memory is 16.1GB. [2022-07-21 05:01:28,608 INFO L339 ainManager$Toolchain]: ####################### End [Toolchain 1] ####################### --- Results --- * Results from de.uni_freiburg.informatik.ultimate.core: - StatisticsResult: Toolchain Benchmarks Benchmark results are: * CDTParser took 0.10ms. Allocated memory is still 50.3MB. Free memory was 32.4MB in the beginning and 32.4MB in the end (delta: 40.0kB). There was no memory consumed. Max. memory is 16.1GB. * CACSL2BoogieTranslator took 383.35ms. Allocated memory was 50.3MB in the beginning and 60.8MB in the end (delta: 10.5MB). Free memory was 26.5MB in the beginning and 37.0MB in the end (delta: -10.5MB). Peak memory consumption was 5.2MB. Max. memory is 16.1GB. * Boogie Procedure Inliner took 65.05ms. Allocated memory is still 60.8MB. Free memory was 36.8MB in the beginning and 34.7MB in the end (delta: 2.1MB). Peak memory consumption was 2.1MB. Max. memory is 16.1GB. * Boogie Preprocessor took 45.88ms. Allocated memory is still 60.8MB. Free memory was 34.7MB in the beginning and 33.2MB in the end (delta: 1.5MB). Peak memory consumption was 2.1MB. Max. memory is 16.1GB. * RCFGBuilder took 504.75ms. Allocated memory is still 60.8MB. Free memory was 33.2MB in the beginning and 34.2MB in the end (delta: -919.4kB). Peak memory consumption was 10.1MB. Max. memory is 16.1GB. * TraceAbstraction took 3086.92ms. Allocated memory was 60.8MB in the beginning and 73.4MB in the end (delta: 12.6MB). Free memory was 33.7MB in the beginning and 28.3MB in the end (delta: 5.4MB). Peak memory consumption was 20.9MB. Max. memory is 16.1GB. * Witness Printer took 58.39ms. Allocated memory is still 73.4MB. Free memory was 28.3MB in the beginning and 51.0MB in the end (delta: -22.7MB). Peak memory consumption was 2.3MB. Max. memory is 16.1GB. * Results from de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction: - StatisticsResult: ErrorAutomatonStatistics NumberErrorTraces: 0, NumberStatementsAllTraces: 0, NumberRelevantStatements: 0, 0.0s ErrorAutomatonConstructionTimeTotal, 0.0s FaulLocalizationTime, NumberStatementsFirstTrace: -1, TraceLengthAvg: 0, 0.0s ErrorAutomatonConstructionTimeAvg, 0.0s ErrorAutomatonDifferenceTimeAvg, 0.0s ErrorAutomatonDifferenceTimeTotal, NumberOfNoEnhancement: 0, NumberOfFiniteEnhancement: 0, NumberOfInfiniteEnhancement: 0 - PositiveResult [Line: 54]: call to reach_error is unreachable For all program executions holds that call to reach_error is unreachable at this location - StatisticsResult: Ultimate Automizer benchmark data CFG has 5 procedures, 62 locations, 1 error locations. Started 1 CEGAR loops. OverallTime: 3.0s, OverallIterations: 7, TraceHistogramMax: 2, PathProgramHistogramMax: 1, EmptinessCheckTime: 0.0s, AutomataDifference: 0.7s, DeadEndRemovalTime: 0.0s, HoareAnnotationTime: 0.6s, InitialAbstractionConstructionTime: 0.0s, HoareTripleCheckerStatistics: 0 mSolverCounterUnknown, 473 SdHoareTripleChecker+Valid, 0.3s IncrementalHoareTripleChecker+Time, 0 mSdLazyCounter, 468 mSDsluCounter, 1211 SdHoareTripleChecker+Invalid, 0.2s Time, 0 mProtectedAction, 0 SdHoareTripleChecker+Unchecked, 0 IncrementalHoareTripleChecker+Unchecked, 810 mSDsCounter, 76 IncrementalHoareTripleChecker+Valid, 0 mProtectedPredicate, 292 IncrementalHoareTripleChecker+Invalid, 368 SdHoareTripleChecker+Unknown, 0 mSolverCounterNotChecked, 76 mSolverCounterUnsat, 401 mSDtfsCounter, 292 mSolverCounterSat, 0.0s SdHoareTripleChecker+Time, 0 IncrementalHoareTripleChecker+Unknown, PredicateUnifierStatistics: 0 DeclaredPredicates, 152 GetRequests, 108 SyntacticMatches, 1 SemanticMatches, 43 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 63 ImplicationChecksByTransitivity, 0.3s Time, 0.0s BasicInterpolantAutomatonTime, BiggestAbstraction: size=180occurred in iteration=6, InterpolantAutomatonStates: 41, traceCheckStatistics: No data available, InterpolantConsolidationStatistics: No data available, PathInvariantsStatistics: No data available, 0/0 InterpolantCoveringCapability, TotalInterpolationStatistics: No data available, 0.0s DumpTime, AutomataMinimizationStatistics: 0.1s AutomataMinimizationTime, 7 MinimizatonAttempts, 106 StatesRemovedByMinimization, 3 NontrivialMinimizations, HoareAnnotationStatistics: 0.0s HoareAnnotationTime, 28 LocationsWithAnnotation, 226 PreInvPairs, 260 NumberOfFragments, 336 HoareAnnotationTreeSize, 226 FomulaSimplifications, 259 FormulaSimplificationTreeSizeReduction, 0.1s HoareSimplificationTime, 28 FomulaSimplificationsInter, 2006 FormulaSimplificationTreeSizeReductionInter, 0.6s HoareSimplificationTimeInter, RefinementEngineStatistics: TRACE_CHECK: 0.0s SsaConstructionTime, 0.2s SatisfiabilityAnalysisTime, 0.8s InterpolantComputationTime, 246 NumberOfCodeBlocks, 246 NumberOfCodeBlocksAsserted, 8 NumberOfCheckSat, 288 ConstructedInterpolants, 0 QuantifiedInterpolants, 769 SizeOfPredicates, 0 NumberOfNonLiveVariables, 344 ConjunctsInSsa, 9 ConjunctsInUnsatCore, 9 InterpolantComputations, 6 PerfectInterpolantSequences, 51/57 InterpolantCoveringCapability, INVARIANT_SYNTHESIS: No data available, INTERPOLANT_CONSOLIDATION: No data available, ABSTRACT_INTERPRETATION: No data available, PDR: No data available, ACCELERATED_INTERPOLATION: No data available, SIFA: No data available, ReuseStatistics: No data available - AllSpecificationsHoldResult: All specifications hold 1 specifications checked. All of them hold - InvariantResult [Line: 876]: Loop Invariant Derived loop invariant: (pumpRunning == 0 && waterLevel == 1) && waterLevel == systemActive - InvariantResult [Line: 448]: Loop Invariant Derived loop invariant: 1 - InvariantResult [Line: 129]: Loop Invariant Derived loop invariant: 0 - InvariantResult [Line: 96]: Loop Invariant Derived loop invariant: ((!(pumpRunning == 0) || \old(waterLevel) == waterLevel) || !(2 <= \old(waterLevel))) && ((!(pumpRunning == 0) || !(\old(waterLevel) == 1)) || waterLevel == 1) - InvariantResult [Line: 441]: Loop Invariant Derived loop invariant: (pumpRunning == 0 && waterLevel == 1) && waterLevel == systemActive - InvariantResult [Line: 193]: Loop Invariant Derived loop invariant: ((pumpRunning == 0 && splverifierCounter == 0) && waterLevel == 1) || ((pumpRunning == 0 && 2 <= waterLevel) && splverifierCounter == 0) - InvariantResult [Line: 222]: Loop Invariant Derived loop invariant: ((pumpRunning == 0 && splverifierCounter == 0) && waterLevel == 1) || ((pumpRunning == 0 && 2 <= waterLevel) && splverifierCounter == 0) - InvariantResult [Line: 869]: Loop Invariant Derived loop invariant: (pumpRunning == 0 && waterLevel == 1) && waterLevel == systemActive - InvariantResult [Line: 221]: Loop Invariant Derived loop invariant: 0 - InvariantResult [Line: 862]: Loop Invariant Derived loop invariant: (pumpRunning == 0 && waterLevel == 1) && waterLevel == systemActive - InvariantResult [Line: 148]: Loop Invariant Derived loop invariant: !(pumpRunning == 0) || !(1 <= \old(waterLevel)) - InvariantResult [Line: 212]: Loop Invariant Derived loop invariant: 1 - InvariantResult [Line: 397]: Loop Invariant Derived loop invariant: 1 - InvariantResult [Line: 50]: Loop Invariant Derived loop invariant: !(pumpRunning == 0) || !(1 <= \old(waterLevel)) - InvariantResult [Line: 308]: Loop Invariant Derived loop invariant: !(pumpRunning == 0) || !(1 <= \old(waterLevel)) - InvariantResult [Line: 461]: Loop Invariant Derived loop invariant: 1 - InvariantResult [Line: 280]: Loop Invariant Derived loop invariant: ((!(pumpRunning == 0) || ((!(tmp == 0) && !(\result == 0)) && \old(waterLevel) == waterLevel)) || !(2 <= \old(waterLevel))) && ((!(pumpRunning == 0) || !(\old(waterLevel) == 1)) || ((!(tmp == 0) && !(\result == 0)) && waterLevel == 1)) - InvariantResult [Line: 376]: Loop Invariant Derived loop invariant: (((!(\result == 0) && waterLevel == 1) || !(pumpRunning == 0)) || !(\old(waterLevel) == 1)) && ((!(pumpRunning == 0) || (!(\result == 0) && \old(waterLevel) == waterLevel)) || !(2 <= \old(waterLevel))) - InvariantResult [Line: 387]: Loop Invariant Derived loop invariant: 1 RESULT: Ultimate proved your program to be correct! [2022-07-21 05:01:28,646 INFO L540 MonitoredProcess]: [MP /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in -t:2000 (1)] Forceful destruction successful, exit code 0 Received shutdown request... --- End real Ultimate output --- Execution finished normally Writing output log to file Ultimate.log Result: TRUE