./Ultimate.py --spec ../sv-benchmarks/c/properties/unreach-call.prp --file ../sv-benchmarks/c/product-lines/minepump_spec4_product49.cil.c --full-output --architecture 32bit -------------------------------------------------------------------------------- Checking for ERROR reachability Using default analysis Version 35987657 Calling Ultimate with: /usr/bin/java -Dosgi.configuration.area=/storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/data/config -Xmx15G -Xms4m -jar /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/plugins/org.eclipse.equinox.launcher_1.5.800.v20200727-1323.jar -data @noDefault -ultimatedata /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/data -tc /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/config/AutomizerReach.xml -i ../sv-benchmarks/c/product-lines/minepump_spec4_product49.cil.c -s /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/config/svcomp-Reach-32bit-Automizer_Default.epf --cacsl2boogietranslator.entry.function main --witnessprinter.witness.directory /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux --witnessprinter.witness.filename witness.graphml --witnessprinter.write.witness.besides.input.file false --witnessprinter.graph.data.specification CHECK( init(main()), LTL(G ! call(reach_error())) ) --witnessprinter.graph.data.producer Automizer --witnessprinter.graph.data.architecture 32bit --witnessprinter.graph.data.programhash dcab8ddabad39d2c77c9d9341cfb89acc265e09aeb5bde0419f381c4b7bb75b6 --- Real Ultimate output --- This is Ultimate 0.2.2-?-3598765 [2022-07-21 05:01:43,289 INFO L177 SettingsManager]: Resetting all preferences to default values... [2022-07-21 05:01:43,295 INFO L181 SettingsManager]: Resetting UltimateCore preferences to default values [2022-07-21 05:01:43,329 INFO L184 SettingsManager]: Ultimate Commandline Interface provides no preferences, ignoring... [2022-07-21 05:01:43,331 INFO L181 SettingsManager]: Resetting Boogie Preprocessor preferences to default values [2022-07-21 05:01:43,332 INFO L181 SettingsManager]: Resetting Boogie Procedure Inliner preferences to default values [2022-07-21 05:01:43,338 INFO L181 SettingsManager]: Resetting Abstract Interpretation preferences to default values [2022-07-21 05:01:43,340 INFO L181 SettingsManager]: Resetting LassoRanker preferences to default values [2022-07-21 05:01:43,343 INFO L181 SettingsManager]: Resetting Reaching Definitions preferences to default values [2022-07-21 05:01:43,347 INFO L181 SettingsManager]: Resetting SyntaxChecker preferences to default values [2022-07-21 05:01:43,349 INFO L181 SettingsManager]: Resetting Sifa preferences to default values [2022-07-21 05:01:43,352 INFO L184 SettingsManager]: Büchi Program Product provides no preferences, ignoring... [2022-07-21 05:01:43,355 INFO L181 SettingsManager]: Resetting LTL2Aut preferences to default values [2022-07-21 05:01:43,357 INFO L181 SettingsManager]: Resetting PEA to Boogie preferences to default values [2022-07-21 05:01:43,357 INFO L181 SettingsManager]: Resetting BlockEncodingV2 preferences to default values [2022-07-21 05:01:43,359 INFO L181 SettingsManager]: Resetting ChcToBoogie preferences to default values [2022-07-21 05:01:43,361 INFO L181 SettingsManager]: Resetting AutomataScriptInterpreter preferences to default values [2022-07-21 05:01:43,362 INFO L181 SettingsManager]: Resetting BuchiAutomizer preferences to default values [2022-07-21 05:01:43,366 INFO L181 SettingsManager]: Resetting CACSL2BoogieTranslator preferences to default values [2022-07-21 05:01:43,367 INFO L181 SettingsManager]: Resetting CodeCheck preferences to default values [2022-07-21 05:01:43,371 INFO L181 SettingsManager]: Resetting HornVerifier preferences to default values [2022-07-21 05:01:43,372 INFO L181 SettingsManager]: Resetting InvariantSynthesis preferences to default values [2022-07-21 05:01:43,373 INFO L181 SettingsManager]: Resetting RCFGBuilder preferences to default values [2022-07-21 05:01:43,376 INFO L181 SettingsManager]: Resetting Referee preferences to default values [2022-07-21 05:01:43,377 INFO L181 SettingsManager]: Resetting TraceAbstraction preferences to default values [2022-07-21 05:01:43,383 INFO L184 SettingsManager]: TraceAbstractionConcurrent provides no preferences, ignoring... [2022-07-21 05:01:43,386 INFO L184 SettingsManager]: TraceAbstractionWithAFAs provides no preferences, ignoring... [2022-07-21 05:01:43,387 INFO L181 SettingsManager]: Resetting TreeAutomizer preferences to default values [2022-07-21 05:01:43,388 INFO L181 SettingsManager]: Resetting IcfgToChc preferences to default values [2022-07-21 05:01:43,388 INFO L181 SettingsManager]: Resetting IcfgTransformer preferences to default values [2022-07-21 05:01:43,389 INFO L184 SettingsManager]: ReqToTest provides no preferences, ignoring... [2022-07-21 05:01:43,389 INFO L181 SettingsManager]: Resetting Boogie Printer preferences to default values [2022-07-21 05:01:43,391 INFO L181 SettingsManager]: Resetting ChcSmtPrinter preferences to default values [2022-07-21 05:01:43,392 INFO L181 SettingsManager]: Resetting ReqPrinter preferences to default values [2022-07-21 05:01:43,393 INFO L181 SettingsManager]: Resetting Witness Printer preferences to default values [2022-07-21 05:01:43,394 INFO L184 SettingsManager]: Boogie PL CUP Parser provides no preferences, ignoring... [2022-07-21 05:01:43,395 INFO L181 SettingsManager]: Resetting CDTParser preferences to default values [2022-07-21 05:01:43,395 INFO L184 SettingsManager]: AutomataScriptParser provides no preferences, ignoring... [2022-07-21 05:01:43,395 INFO L184 SettingsManager]: ReqParser provides no preferences, ignoring... [2022-07-21 05:01:43,396 INFO L181 SettingsManager]: Resetting SmtParser preferences to default values [2022-07-21 05:01:43,396 INFO L181 SettingsManager]: Resetting Witness Parser preferences to default values [2022-07-21 05:01:43,398 INFO L188 SettingsManager]: Finished resetting all preferences to default values... [2022-07-21 05:01:43,403 INFO L101 SettingsManager]: Beginning loading settings from /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/config/svcomp-Reach-32bit-Automizer_Default.epf [2022-07-21 05:01:43,436 INFO L113 SettingsManager]: Loading preferences was successful [2022-07-21 05:01:43,436 INFO L115 SettingsManager]: Preferences different from defaults after loading the file: [2022-07-21 05:01:43,436 INFO L136 SettingsManager]: Preferences of UltimateCore differ from their defaults: [2022-07-21 05:01:43,437 INFO L138 SettingsManager]: * Log level for class=de.uni_freiburg.informatik.ultimate.lib.smtlibutils.quantifier.QuantifierPusher=ERROR; [2022-07-21 05:01:43,437 INFO L136 SettingsManager]: Preferences of Boogie Procedure Inliner differ from their defaults: [2022-07-21 05:01:43,438 INFO L138 SettingsManager]: * Ignore calls to procedures called more than once=ONLY_FOR_SEQUENTIAL_PROGRAMS [2022-07-21 05:01:43,438 INFO L136 SettingsManager]: Preferences of BlockEncodingV2 differ from their defaults: [2022-07-21 05:01:43,438 INFO L138 SettingsManager]: * Create parallel compositions if possible=false [2022-07-21 05:01:43,439 INFO L138 SettingsManager]: * Use SBE=true [2022-07-21 05:01:43,440 INFO L136 SettingsManager]: Preferences of CACSL2BoogieTranslator differ from their defaults: [2022-07-21 05:01:43,440 INFO L138 SettingsManager]: * sizeof long=4 [2022-07-21 05:01:43,440 INFO L138 SettingsManager]: * Overapproximate operations on floating types=true [2022-07-21 05:01:43,440 INFO L138 SettingsManager]: * sizeof POINTER=4 [2022-07-21 05:01:43,440 INFO L138 SettingsManager]: * Check division by zero=IGNORE [2022-07-21 05:01:43,440 INFO L138 SettingsManager]: * Pointer to allocated memory at dereference=IGNORE [2022-07-21 05:01:43,446 INFO L138 SettingsManager]: * If two pointers are subtracted or compared they have the same base address=IGNORE [2022-07-21 05:01:43,447 INFO L138 SettingsManager]: * Check array bounds for arrays that are off heap=IGNORE [2022-07-21 05:01:43,447 INFO L138 SettingsManager]: * sizeof long double=12 [2022-07-21 05:01:43,447 INFO L138 SettingsManager]: * Check if freed pointer was valid=false [2022-07-21 05:01:43,447 INFO L138 SettingsManager]: * Use constant arrays=true [2022-07-21 05:01:43,447 INFO L138 SettingsManager]: * Pointer base address is valid at dereference=IGNORE [2022-07-21 05:01:43,448 INFO L136 SettingsManager]: Preferences of RCFGBuilder differ from their defaults: [2022-07-21 05:01:43,448 INFO L138 SettingsManager]: * Size of a code block=SequenceOfStatements [2022-07-21 05:01:43,448 INFO L138 SettingsManager]: * SMT solver=External_DefaultMode [2022-07-21 05:01:43,448 INFO L138 SettingsManager]: * Command for external solver=z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in -t:2000 [2022-07-21 05:01:43,448 INFO L136 SettingsManager]: Preferences of TraceAbstraction differ from their defaults: [2022-07-21 05:01:43,449 INFO L138 SettingsManager]: * Compute Interpolants along a Counterexample=FPandBP [2022-07-21 05:01:43,449 INFO L138 SettingsManager]: * Positions where we compute the Hoare Annotation=LoopsAndPotentialCycles [2022-07-21 05:01:43,449 INFO L138 SettingsManager]: * Trace refinement strategy=CAMEL [2022-07-21 05:01:43,449 INFO L138 SettingsManager]: * Command for external solver=z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in [2022-07-21 05:01:43,449 INFO L138 SettingsManager]: * Apply one-shot large block encoding in concurrent analysis=false [2022-07-21 05:01:43,450 INFO L138 SettingsManager]: * Automaton type used in concurrency analysis=PETRI_NET [2022-07-21 05:01:43,450 INFO L138 SettingsManager]: * Compute Hoare Annotation of negated interpolant automaton, abstraction and CFG=true [2022-07-21 05:01:43,450 INFO L138 SettingsManager]: * SMT solver=External_ModelsAndUnsatCoreMode WARNING: An illegal reflective access operation has occurred WARNING: Illegal reflective access by com.sun.xml.bind.v2.runtime.reflect.opt.Injector$1 (file:/storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/plugins/com.sun.xml.bind_2.2.0.v201505121915.jar) to method java.lang.ClassLoader.defineClass(java.lang.String,byte[],int,int) WARNING: Please consider reporting this to the maintainers of com.sun.xml.bind.v2.runtime.reflect.opt.Injector$1 WARNING: Use --illegal-access=warn to enable warnings of further illegal reflective access operations WARNING: All illegal access operations will be denied in a future release Applying setting for plugin de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator: Entry function -> main Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Witness directory -> /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Witness filename -> witness.graphml Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Write witness besides input file -> false Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Graph data specification -> CHECK( init(main()), LTL(G ! call(reach_error())) ) Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Graph data producer -> Automizer Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Graph data architecture -> 32bit Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Graph data programhash -> dcab8ddabad39d2c77c9d9341cfb89acc265e09aeb5bde0419f381c4b7bb75b6 [2022-07-21 05:01:43,766 INFO L75 nceAwareModelManager]: Repository-Root is: /tmp [2022-07-21 05:01:43,784 INFO L261 ainManager$Toolchain]: [Toolchain 1]: Applicable parser(s) successfully (re)initialized [2022-07-21 05:01:43,786 INFO L217 ainManager$Toolchain]: [Toolchain 1]: Toolchain selected. [2022-07-21 05:01:43,787 INFO L271 PluginConnector]: Initializing CDTParser... [2022-07-21 05:01:43,791 INFO L275 PluginConnector]: CDTParser initialized [2022-07-21 05:01:43,793 INFO L432 ainManager$Toolchain]: [Toolchain 1]: Parsing single file: /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/../sv-benchmarks/c/product-lines/minepump_spec4_product49.cil.c [2022-07-21 05:01:43,863 INFO L220 CDTParser]: Created temporary CDT project at /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/data/71b23d353/b3fabb91c3154bde8d401a16b1b50c82/FLAGd663779bf [2022-07-21 05:01:44,412 INFO L306 CDTParser]: Found 1 translation units. [2022-07-21 05:01:44,413 INFO L160 CDTParser]: Scanning /storage/repos/ultimate/releaseScripts/default/sv-benchmarks/c/product-lines/minepump_spec4_product49.cil.c [2022-07-21 05:01:44,427 INFO L349 CDTParser]: About to delete temporary CDT project at /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/data/71b23d353/b3fabb91c3154bde8d401a16b1b50c82/FLAGd663779bf [2022-07-21 05:01:44,735 INFO L357 CDTParser]: Successfully deleted /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/data/71b23d353/b3fabb91c3154bde8d401a16b1b50c82 [2022-07-21 05:01:44,737 INFO L299 ainManager$Toolchain]: ####################### [Toolchain 1] ####################### [2022-07-21 05:01:44,738 INFO L131 ToolchainWalker]: Walking toolchain with 6 elements. [2022-07-21 05:01:44,739 INFO L113 PluginConnector]: ------------------------CACSL2BoogieTranslator---------------------------- [2022-07-21 05:01:44,740 INFO L271 PluginConnector]: Initializing CACSL2BoogieTranslator... [2022-07-21 05:01:44,743 INFO L275 PluginConnector]: CACSL2BoogieTranslator initialized [2022-07-21 05:01:44,744 INFO L185 PluginConnector]: Executing the observer ACSLObjectContainerObserver from plugin CACSL2BoogieTranslator for "CDTParser AST 21.07 05:01:44" (1/1) ... [2022-07-21 05:01:44,745 INFO L205 PluginConnector]: Invalid model from CACSL2BoogieTranslator for observer de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator.ACSLObjectContainerObserver@26b788f2 and model type de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 21.07 05:01:44, skipping insertion in model container [2022-07-21 05:01:44,745 INFO L185 PluginConnector]: Executing the observer CACSL2BoogieTranslatorObserver from plugin CACSL2BoogieTranslator for "CDTParser AST 21.07 05:01:44" (1/1) ... [2022-07-21 05:01:44,758 INFO L145 MainTranslator]: Starting translation in SV-COMP mode [2022-07-21 05:01:44,810 INFO L178 MainTranslator]: Built tables and reachable declarations [2022-07-21 05:01:44,928 WARN L230 ndardFunctionHandler]: Function reach_error is already implemented but we override the implementation for the call at /storage/repos/ultimate/releaseScripts/default/sv-benchmarks/c/product-lines/minepump_spec4_product49.cil.c[1605,1618] [2022-07-21 05:01:45,096 INFO L210 PostProcessor]: Analyzing one entry point: main [2022-07-21 05:01:45,115 INFO L203 MainTranslator]: Completed pre-run [2022-07-21 05:01:45,133 WARN L230 ndardFunctionHandler]: Function reach_error is already implemented but we override the implementation for the call at /storage/repos/ultimate/releaseScripts/default/sv-benchmarks/c/product-lines/minepump_spec4_product49.cil.c[1605,1618] [2022-07-21 05:01:45,196 INFO L210 PostProcessor]: Analyzing one entry point: main [2022-07-21 05:01:45,214 INFO L208 MainTranslator]: Completed translation [2022-07-21 05:01:45,214 INFO L202 PluginConnector]: Adding new model de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 21.07 05:01:45 WrapperNode [2022-07-21 05:01:45,215 INFO L132 PluginConnector]: ------------------------ END CACSL2BoogieTranslator---------------------------- [2022-07-21 05:01:45,216 INFO L113 PluginConnector]: ------------------------Boogie Procedure Inliner---------------------------- [2022-07-21 05:01:45,216 INFO L271 PluginConnector]: Initializing Boogie Procedure Inliner... [2022-07-21 05:01:45,216 INFO L275 PluginConnector]: Boogie Procedure Inliner initialized [2022-07-21 05:01:45,222 INFO L185 PluginConnector]: Executing the observer TypeChecker from plugin Boogie Procedure Inliner for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 21.07 05:01:45" (1/1) ... [2022-07-21 05:01:45,249 INFO L185 PluginConnector]: Executing the observer Inliner from plugin Boogie Procedure Inliner for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 21.07 05:01:45" (1/1) ... [2022-07-21 05:01:45,281 INFO L137 Inliner]: procedures = 55, calls = 154, calls flagged for inlining = 24, calls inlined = 20, statements flattened = 257 [2022-07-21 05:01:45,282 INFO L132 PluginConnector]: ------------------------ END Boogie Procedure Inliner---------------------------- [2022-07-21 05:01:45,282 INFO L113 PluginConnector]: ------------------------Boogie Preprocessor---------------------------- [2022-07-21 05:01:45,283 INFO L271 PluginConnector]: Initializing Boogie Preprocessor... [2022-07-21 05:01:45,283 INFO L275 PluginConnector]: Boogie Preprocessor initialized [2022-07-21 05:01:45,290 INFO L185 PluginConnector]: Executing the observer EnsureBoogieModelObserver from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 21.07 05:01:45" (1/1) ... [2022-07-21 05:01:45,290 INFO L185 PluginConnector]: Executing the observer TypeChecker from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 21.07 05:01:45" (1/1) ... [2022-07-21 05:01:45,293 INFO L185 PluginConnector]: Executing the observer ConstExpander from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 21.07 05:01:45" (1/1) ... [2022-07-21 05:01:45,293 INFO L185 PluginConnector]: Executing the observer StructExpander from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 21.07 05:01:45" (1/1) ... [2022-07-21 05:01:45,298 INFO L185 PluginConnector]: Executing the observer UnstructureCode from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 21.07 05:01:45" (1/1) ... [2022-07-21 05:01:45,302 INFO L185 PluginConnector]: Executing the observer FunctionInliner from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 21.07 05:01:45" (1/1) ... [2022-07-21 05:01:45,319 INFO L185 PluginConnector]: Executing the observer BoogieSymbolTableConstructor from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 21.07 05:01:45" (1/1) ... [2022-07-21 05:01:45,330 INFO L132 PluginConnector]: ------------------------ END Boogie Preprocessor---------------------------- [2022-07-21 05:01:45,331 INFO L113 PluginConnector]: ------------------------RCFGBuilder---------------------------- [2022-07-21 05:01:45,332 INFO L271 PluginConnector]: Initializing RCFGBuilder... [2022-07-21 05:01:45,332 INFO L275 PluginConnector]: RCFGBuilder initialized [2022-07-21 05:01:45,333 INFO L185 PluginConnector]: Executing the observer RCFGBuilderObserver from plugin RCFGBuilder for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 21.07 05:01:45" (1/1) ... [2022-07-21 05:01:45,345 INFO L173 SolverBuilder]: Constructing external solver with command: z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in -t:2000 [2022-07-21 05:01:45,357 INFO L189 MonitoredProcess]: No working directory specified, using /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 [2022-07-21 05:01:45,366 INFO L229 MonitoredProcess]: Starting monitored process 1 with /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in -t:2000 (exit command is (exit), workingDir is null) [2022-07-21 05:01:45,375 INFO L327 MonitoredProcess]: [MP /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in -t:2000 (1)] Waiting until timeout for monitored process [2022-07-21 05:01:45,403 INFO L130 BoogieDeclarations]: Found specification of procedure #Ultimate.allocInit [2022-07-21 05:01:45,403 INFO L130 BoogieDeclarations]: Found specification of procedure processEnvironment__wrappee__base [2022-07-21 05:01:45,403 INFO L138 BoogieDeclarations]: Found implementation of procedure processEnvironment__wrappee__base [2022-07-21 05:01:45,404 INFO L130 BoogieDeclarations]: Found specification of procedure timeShift [2022-07-21 05:01:45,404 INFO L138 BoogieDeclarations]: Found implementation of procedure timeShift [2022-07-21 05:01:45,404 INFO L130 BoogieDeclarations]: Found specification of procedure cleanup [2022-07-21 05:01:45,404 INFO L138 BoogieDeclarations]: Found implementation of procedure cleanup [2022-07-21 05:01:45,404 INFO L130 BoogieDeclarations]: Found specification of procedure processEnvironment__wrappee__highWaterSensor [2022-07-21 05:01:45,404 INFO L138 BoogieDeclarations]: Found implementation of procedure processEnvironment__wrappee__highWaterSensor [2022-07-21 05:01:45,404 INFO L130 BoogieDeclarations]: Found specification of procedure waterRise [2022-07-21 05:01:45,405 INFO L138 BoogieDeclarations]: Found implementation of procedure waterRise [2022-07-21 05:01:45,405 INFO L130 BoogieDeclarations]: Found specification of procedure write~init~int [2022-07-21 05:01:45,405 INFO L130 BoogieDeclarations]: Found specification of procedure changeMethaneLevel [2022-07-21 05:01:45,405 INFO L138 BoogieDeclarations]: Found implementation of procedure changeMethaneLevel [2022-07-21 05:01:45,405 INFO L130 BoogieDeclarations]: Found specification of procedure ULTIMATE.start [2022-07-21 05:01:45,405 INFO L138 BoogieDeclarations]: Found implementation of procedure ULTIMATE.start [2022-07-21 05:01:45,470 INFO L234 CfgBuilder]: Building ICFG [2022-07-21 05:01:45,472 INFO L260 CfgBuilder]: Building CFG for each procedure with an implementation [2022-07-21 05:01:45,820 INFO L275 CfgBuilder]: Performing block encoding [2022-07-21 05:01:45,826 INFO L294 CfgBuilder]: Using the 1 location(s) as analysis (start of procedure ULTIMATE.start) [2022-07-21 05:01:45,827 INFO L299 CfgBuilder]: Removed 2 assume(true) statements. [2022-07-21 05:01:45,829 INFO L202 PluginConnector]: Adding new model de.uni_freiburg.informatik.ultimate.plugins.generator.rcfgbuilder CFG 21.07 05:01:45 BoogieIcfgContainer [2022-07-21 05:01:45,829 INFO L132 PluginConnector]: ------------------------ END RCFGBuilder---------------------------- [2022-07-21 05:01:45,830 INFO L113 PluginConnector]: ------------------------TraceAbstraction---------------------------- [2022-07-21 05:01:45,831 INFO L271 PluginConnector]: Initializing TraceAbstraction... [2022-07-21 05:01:45,833 INFO L275 PluginConnector]: TraceAbstraction initialized [2022-07-21 05:01:45,837 INFO L185 PluginConnector]: Executing the observer TraceAbstractionObserver from plugin TraceAbstraction for "CDTParser AST 21.07 05:01:44" (1/3) ... [2022-07-21 05:01:45,838 INFO L205 PluginConnector]: Invalid model from TraceAbstraction for observer de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction.TraceAbstractionObserver@9ca4cf3 and model type de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction AST 21.07 05:01:45, skipping insertion in model container [2022-07-21 05:01:45,838 INFO L185 PluginConnector]: Executing the observer TraceAbstractionObserver from plugin TraceAbstraction for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 21.07 05:01:45" (2/3) ... [2022-07-21 05:01:45,838 INFO L205 PluginConnector]: Invalid model from TraceAbstraction for observer de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction.TraceAbstractionObserver@9ca4cf3 and model type de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction AST 21.07 05:01:45, skipping insertion in model container [2022-07-21 05:01:45,839 INFO L185 PluginConnector]: Executing the observer TraceAbstractionObserver from plugin TraceAbstraction for "de.uni_freiburg.informatik.ultimate.plugins.generator.rcfgbuilder CFG 21.07 05:01:45" (3/3) ... [2022-07-21 05:01:45,840 INFO L111 eAbstractionObserver]: Analyzing ICFG minepump_spec4_product49.cil.c [2022-07-21 05:01:45,854 INFO L201 ceAbstractionStarter]: Automizer settings: Hoare:true NWA Interpolation:FPandBP Determinization: PREDICATE_ABSTRACTION [2022-07-21 05:01:45,854 INFO L160 ceAbstractionStarter]: Applying trace abstraction to program that has 1 error locations. [2022-07-21 05:01:45,914 INFO L356 AbstractCegarLoop]: ======== Iteration 0 == of CEGAR loop == AllErrorsAtOnce ======== [2022-07-21 05:01:45,921 INFO L357 AbstractCegarLoop]: Settings: SEPARATE_VIOLATION_CHECK=true, mInterprocedural=true, mMaxIterations=1000000, mWatchIteration=1000000, mArtifact=RCFG, mInterpolation=FPandBP, mInterpolantAutomaton=STRAIGHT_LINE, mDumpAutomata=false, mAutomataFormat=ATS_NUMERATE, mDumpPath=., mDeterminiation=PREDICATE_ABSTRACTION, mMinimize=MINIMIZE_SEVPA, mHoare=true, mAutomataTypeConcurrency=PETRI_NET, mHoareTripleChecks=INCREMENTAL, mHoareAnnotationPositions=LoopsAndPotentialCycles, mDumpOnlyReuseAutomata=false, mLimitTraceHistogram=0, mErrorLocTimeLimit=0, mLimitPathProgramCount=0, mCollectInterpolantStatistics=true, mHeuristicEmptinessCheck=false, mHeuristicEmptinessCheckAStarHeuristic=ZERO, mHeuristicEmptinessCheckAStarHeuristicRandomSeed=1337, mHeuristicEmptinessCheckSmtFeatureScoringMethod=DAGSIZE, mSMTFeatureExtraction=false, mSMTFeatureExtractionDumpPath=., mOverrideInterpolantAutomaton=false, mMcrInterpolantMethod=WP, mPorIndependenceSettings=de.uni_freiburg.informatik.ultimate.lib.tracecheckerutils.partialorder.independence.IndependenceSettings@2fba2d36, mLbeIndependenceSettings=de.uni_freiburg.informatik.ultimate.lib.tracecheckerutils.partialorder.independence.IndependenceSettings@797c45fe [2022-07-21 05:01:45,922 INFO L358 AbstractCegarLoop]: Starting to check reachability of 1 error locations. [2022-07-21 05:01:45,933 INFO L276 IsEmpty]: Start isEmpty. Operand has 82 states, 64 states have (on average 1.40625) internal successors, (90), 72 states have internal predecessors, (90), 10 states have call successors, (10), 6 states have call predecessors, (10), 6 states have return successors, (10), 8 states have call predecessors, (10), 10 states have call successors, (10) [2022-07-21 05:01:45,943 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 20 [2022-07-21 05:01:45,943 INFO L187 NwaCegarLoop]: Found error trace [2022-07-21 05:01:45,944 INFO L195 NwaCegarLoop]: trace histogram [1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-07-21 05:01:45,945 INFO L420 AbstractCegarLoop]: === Iteration 1 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2022-07-21 05:01:45,951 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2022-07-21 05:01:45,951 INFO L85 PathProgramCache]: Analyzing trace with hash -1722090408, now seen corresponding path program 1 times [2022-07-21 05:01:45,959 INFO L118 FreeRefinementEngine]: Executing refinement strategy CAMEL [2022-07-21 05:01:45,960 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [1787275814] [2022-07-21 05:01:45,960 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-07-21 05:01:45,961 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2022-07-21 05:01:46,129 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-07-21 05:01:46,189 INFO L134 CoverageAnalysis]: Checked inductivity of 0 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2022-07-21 05:01:46,190 INFO L136 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2022-07-21 05:01:46,190 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [1787275814] [2022-07-21 05:01:46,191 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [1787275814] provided 1 perfect and 0 imperfect interpolant sequences [2022-07-21 05:01:46,191 INFO L184 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2022-07-21 05:01:46,192 INFO L197 FreeRefinementEngine]: Number of different interpolants: perfect sequences [2] imperfect sequences [] total 2 [2022-07-21 05:01:46,194 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [207365447] [2022-07-21 05:01:46,194 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2022-07-21 05:01:46,200 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 2 states [2022-07-21 05:01:46,201 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2022-07-21 05:01:46,231 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 2 interpolants. [2022-07-21 05:01:46,232 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=1, Invalid=1, Unknown=0, NotChecked=0, Total=2 [2022-07-21 05:01:46,236 INFO L87 Difference]: Start difference. First operand has 82 states, 64 states have (on average 1.40625) internal successors, (90), 72 states have internal predecessors, (90), 10 states have call successors, (10), 6 states have call predecessors, (10), 6 states have return successors, (10), 8 states have call predecessors, (10), 10 states have call successors, (10) Second operand has 2 states, 2 states have (on average 8.5) internal successors, (17), 2 states have internal predecessors, (17), 1 states have call successors, (2), 1 states have call predecessors, (2), 0 states have return successors, (0), 0 states have call predecessors, (0), 0 states have call successors, (0) [2022-07-21 05:01:46,284 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-07-21 05:01:46,284 INFO L93 Difference]: Finished difference Result 156 states and 215 transitions. [2022-07-21 05:01:46,286 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 2 states. [2022-07-21 05:01:46,287 INFO L78 Accepts]: Start accepts. Automaton has has 2 states, 2 states have (on average 8.5) internal successors, (17), 2 states have internal predecessors, (17), 1 states have call successors, (2), 1 states have call predecessors, (2), 0 states have return successors, (0), 0 states have call predecessors, (0), 0 states have call successors, (0) Word has length 19 [2022-07-21 05:01:46,287 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2022-07-21 05:01:46,298 INFO L225 Difference]: With dead ends: 156 [2022-07-21 05:01:46,298 INFO L226 Difference]: Without dead ends: 73 [2022-07-21 05:01:46,303 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 2 GetRequests, 2 SyntacticMatches, 0 SemanticMatches, 0 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 0 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=1, Invalid=1, Unknown=0, NotChecked=0, Total=2 [2022-07-21 05:01:46,306 INFO L413 NwaCegarLoop]: 104 mSDtfsCounter, 0 mSDsluCounter, 0 mSDsCounter, 0 mSdLazyCounter, 0 mSolverCounterSat, 0 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.0s Time, 0 mProtectedPredicate, 0 mProtectedAction, 0 SdHoareTripleChecker+Valid, 104 SdHoareTripleChecker+Invalid, 0 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 0 IncrementalHoareTripleChecker+Valid, 0 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.0s IncrementalHoareTripleChecker+Time [2022-07-21 05:01:46,308 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [0 Valid, 104 Invalid, 0 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [0 Valid, 0 Invalid, 0 Unknown, 0 Unchecked, 0.0s Time] [2022-07-21 05:01:46,323 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 73 states. [2022-07-21 05:01:46,357 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 73 to 73. [2022-07-21 05:01:46,359 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 73 states, 57 states have (on average 1.3333333333333333) internal successors, (76), 64 states have internal predecessors, (76), 10 states have call successors, (10), 6 states have call predecessors, (10), 5 states have return successors, (9), 7 states have call predecessors, (9), 9 states have call successors, (9) [2022-07-21 05:01:46,364 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 73 states to 73 states and 95 transitions. [2022-07-21 05:01:46,365 INFO L78 Accepts]: Start accepts. Automaton has 73 states and 95 transitions. Word has length 19 [2022-07-21 05:01:46,366 INFO L84 Accepts]: Finished accepts. word is rejected. [2022-07-21 05:01:46,366 INFO L495 AbstractCegarLoop]: Abstraction has 73 states and 95 transitions. [2022-07-21 05:01:46,367 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 2 states, 2 states have (on average 8.5) internal successors, (17), 2 states have internal predecessors, (17), 1 states have call successors, (2), 1 states have call predecessors, (2), 0 states have return successors, (0), 0 states have call predecessors, (0), 0 states have call successors, (0) [2022-07-21 05:01:46,367 INFO L276 IsEmpty]: Start isEmpty. Operand 73 states and 95 transitions. [2022-07-21 05:01:46,370 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 21 [2022-07-21 05:01:46,370 INFO L187 NwaCegarLoop]: Found error trace [2022-07-21 05:01:46,370 INFO L195 NwaCegarLoop]: trace histogram [1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-07-21 05:01:46,371 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable0 [2022-07-21 05:01:46,371 INFO L420 AbstractCegarLoop]: === Iteration 2 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2022-07-21 05:01:46,371 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2022-07-21 05:01:46,372 INFO L85 PathProgramCache]: Analyzing trace with hash 1895744144, now seen corresponding path program 1 times [2022-07-21 05:01:46,372 INFO L118 FreeRefinementEngine]: Executing refinement strategy CAMEL [2022-07-21 05:01:46,372 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [2113555538] [2022-07-21 05:01:46,373 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-07-21 05:01:46,373 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2022-07-21 05:01:46,426 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-07-21 05:01:46,485 INFO L134 CoverageAnalysis]: Checked inductivity of 0 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2022-07-21 05:01:46,485 INFO L136 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2022-07-21 05:01:46,486 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [2113555538] [2022-07-21 05:01:46,486 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [2113555538] provided 1 perfect and 0 imperfect interpolant sequences [2022-07-21 05:01:46,486 INFO L184 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2022-07-21 05:01:46,486 INFO L197 FreeRefinementEngine]: Number of different interpolants: perfect sequences [3] imperfect sequences [] total 3 [2022-07-21 05:01:46,486 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [2033107087] [2022-07-21 05:01:46,487 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2022-07-21 05:01:46,488 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 3 states [2022-07-21 05:01:46,488 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2022-07-21 05:01:46,489 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 3 interpolants. [2022-07-21 05:01:46,489 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=3, Invalid=3, Unknown=0, NotChecked=0, Total=6 [2022-07-21 05:01:46,489 INFO L87 Difference]: Start difference. First operand 73 states and 95 transitions. Second operand has 3 states, 3 states have (on average 6.0) internal successors, (18), 3 states have internal predecessors, (18), 1 states have call successors, (2), 1 states have call predecessors, (2), 0 states have return successors, (0), 0 states have call predecessors, (0), 0 states have call successors, (0) [2022-07-21 05:01:46,501 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-07-21 05:01:46,501 INFO L93 Difference]: Finished difference Result 112 states and 146 transitions. [2022-07-21 05:01:46,502 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 3 states. [2022-07-21 05:01:46,502 INFO L78 Accepts]: Start accepts. Automaton has has 3 states, 3 states have (on average 6.0) internal successors, (18), 3 states have internal predecessors, (18), 1 states have call successors, (2), 1 states have call predecessors, (2), 0 states have return successors, (0), 0 states have call predecessors, (0), 0 states have call successors, (0) Word has length 20 [2022-07-21 05:01:46,502 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2022-07-21 05:01:46,503 INFO L225 Difference]: With dead ends: 112 [2022-07-21 05:01:46,503 INFO L226 Difference]: Without dead ends: 64 [2022-07-21 05:01:46,504 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 3 GetRequests, 2 SyntacticMatches, 0 SemanticMatches, 1 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 0 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=3, Invalid=3, Unknown=0, NotChecked=0, Total=6 [2022-07-21 05:01:46,505 INFO L413 NwaCegarLoop]: 82 mSDtfsCounter, 12 mSDsluCounter, 66 mSDsCounter, 0 mSdLazyCounter, 1 mSolverCounterSat, 0 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.0s Time, 0 mProtectedPredicate, 0 mProtectedAction, 15 SdHoareTripleChecker+Valid, 148 SdHoareTripleChecker+Invalid, 1 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 0 IncrementalHoareTripleChecker+Valid, 1 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.0s IncrementalHoareTripleChecker+Time [2022-07-21 05:01:46,506 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [15 Valid, 148 Invalid, 1 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [0 Valid, 1 Invalid, 0 Unknown, 0 Unchecked, 0.0s Time] [2022-07-21 05:01:46,507 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 64 states. [2022-07-21 05:01:46,512 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 64 to 64. [2022-07-21 05:01:46,513 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 64 states, 51 states have (on average 1.3529411764705883) internal successors, (69), 58 states have internal predecessors, (69), 7 states have call successors, (7), 5 states have call predecessors, (7), 5 states have return successors, (7), 5 states have call predecessors, (7), 7 states have call successors, (7) [2022-07-21 05:01:46,513 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 64 states to 64 states and 83 transitions. [2022-07-21 05:01:46,514 INFO L78 Accepts]: Start accepts. Automaton has 64 states and 83 transitions. Word has length 20 [2022-07-21 05:01:46,514 INFO L84 Accepts]: Finished accepts. word is rejected. [2022-07-21 05:01:46,514 INFO L495 AbstractCegarLoop]: Abstraction has 64 states and 83 transitions. [2022-07-21 05:01:46,514 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 3 states, 3 states have (on average 6.0) internal successors, (18), 3 states have internal predecessors, (18), 1 states have call successors, (2), 1 states have call predecessors, (2), 0 states have return successors, (0), 0 states have call predecessors, (0), 0 states have call successors, (0) [2022-07-21 05:01:46,515 INFO L276 IsEmpty]: Start isEmpty. Operand 64 states and 83 transitions. [2022-07-21 05:01:46,515 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 25 [2022-07-21 05:01:46,515 INFO L187 NwaCegarLoop]: Found error trace [2022-07-21 05:01:46,516 INFO L195 NwaCegarLoop]: trace histogram [1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-07-21 05:01:46,516 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable1 [2022-07-21 05:01:46,516 INFO L420 AbstractCegarLoop]: === Iteration 3 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2022-07-21 05:01:46,516 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2022-07-21 05:01:46,517 INFO L85 PathProgramCache]: Analyzing trace with hash 540813392, now seen corresponding path program 1 times [2022-07-21 05:01:46,517 INFO L118 FreeRefinementEngine]: Executing refinement strategy CAMEL [2022-07-21 05:01:46,517 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [1426117971] [2022-07-21 05:01:46,517 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-07-21 05:01:46,517 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2022-07-21 05:01:46,536 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-07-21 05:01:46,573 INFO L134 CoverageAnalysis]: Checked inductivity of 0 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2022-07-21 05:01:46,574 INFO L136 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2022-07-21 05:01:46,574 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [1426117971] [2022-07-21 05:01:46,574 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [1426117971] provided 1 perfect and 0 imperfect interpolant sequences [2022-07-21 05:01:46,574 INFO L184 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2022-07-21 05:01:46,574 INFO L197 FreeRefinementEngine]: Number of different interpolants: perfect sequences [2] imperfect sequences [] total 2 [2022-07-21 05:01:46,574 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [1046314711] [2022-07-21 05:01:46,575 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2022-07-21 05:01:46,575 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 3 states [2022-07-21 05:01:46,575 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2022-07-21 05:01:46,576 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 3 interpolants. [2022-07-21 05:01:46,576 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=3, Invalid=3, Unknown=0, NotChecked=0, Total=6 [2022-07-21 05:01:46,576 INFO L87 Difference]: Start difference. First operand 64 states and 83 transitions. Second operand has 3 states, 3 states have (on average 7.666666666666667) internal successors, (23), 2 states have internal predecessors, (23), 1 states have call successors, (1), 1 states have call predecessors, (1), 0 states have return successors, (0), 0 states have call predecessors, (0), 0 states have call successors, (0) [2022-07-21 05:01:46,590 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-07-21 05:01:46,591 INFO L93 Difference]: Finished difference Result 121 states and 160 transitions. [2022-07-21 05:01:46,591 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 3 states. [2022-07-21 05:01:46,591 INFO L78 Accepts]: Start accepts. Automaton has has 3 states, 3 states have (on average 7.666666666666667) internal successors, (23), 2 states have internal predecessors, (23), 1 states have call successors, (1), 1 states have call predecessors, (1), 0 states have return successors, (0), 0 states have call predecessors, (0), 0 states have call successors, (0) Word has length 24 [2022-07-21 05:01:46,592 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2022-07-21 05:01:46,593 INFO L225 Difference]: With dead ends: 121 [2022-07-21 05:01:46,593 INFO L226 Difference]: Without dead ends: 64 [2022-07-21 05:01:46,593 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 2 GetRequests, 1 SyntacticMatches, 0 SemanticMatches, 1 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 0 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=3, Invalid=3, Unknown=0, NotChecked=0, Total=6 [2022-07-21 05:01:46,595 INFO L413 NwaCegarLoop]: 81 mSDtfsCounter, 65 mSDsluCounter, 0 mSDsCounter, 0 mSdLazyCounter, 1 mSolverCounterSat, 0 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.0s Time, 0 mProtectedPredicate, 0 mProtectedAction, 65 SdHoareTripleChecker+Valid, 81 SdHoareTripleChecker+Invalid, 1 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 0 IncrementalHoareTripleChecker+Valid, 1 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.0s IncrementalHoareTripleChecker+Time [2022-07-21 05:01:46,595 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [65 Valid, 81 Invalid, 1 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [0 Valid, 1 Invalid, 0 Unknown, 0 Unchecked, 0.0s Time] [2022-07-21 05:01:46,596 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 64 states. [2022-07-21 05:01:46,601 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 64 to 64. [2022-07-21 05:01:46,601 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 64 states, 51 states have (on average 1.3333333333333333) internal successors, (68), 58 states have internal predecessors, (68), 7 states have call successors, (7), 5 states have call predecessors, (7), 5 states have return successors, (7), 5 states have call predecessors, (7), 7 states have call successors, (7) [2022-07-21 05:01:46,602 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 64 states to 64 states and 82 transitions. [2022-07-21 05:01:46,602 INFO L78 Accepts]: Start accepts. Automaton has 64 states and 82 transitions. Word has length 24 [2022-07-21 05:01:46,602 INFO L84 Accepts]: Finished accepts. word is rejected. [2022-07-21 05:01:46,603 INFO L495 AbstractCegarLoop]: Abstraction has 64 states and 82 transitions. [2022-07-21 05:01:46,603 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 3 states, 3 states have (on average 7.666666666666667) internal successors, (23), 2 states have internal predecessors, (23), 1 states have call successors, (1), 1 states have call predecessors, (1), 0 states have return successors, (0), 0 states have call predecessors, (0), 0 states have call successors, (0) [2022-07-21 05:01:46,603 INFO L276 IsEmpty]: Start isEmpty. Operand 64 states and 82 transitions. [2022-07-21 05:01:46,604 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 35 [2022-07-21 05:01:46,604 INFO L187 NwaCegarLoop]: Found error trace [2022-07-21 05:01:46,604 INFO L195 NwaCegarLoop]: trace histogram [1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-07-21 05:01:46,605 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable2 [2022-07-21 05:01:46,605 INFO L420 AbstractCegarLoop]: === Iteration 4 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2022-07-21 05:01:46,605 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2022-07-21 05:01:46,605 INFO L85 PathProgramCache]: Analyzing trace with hash 412315462, now seen corresponding path program 1 times [2022-07-21 05:01:46,606 INFO L118 FreeRefinementEngine]: Executing refinement strategy CAMEL [2022-07-21 05:01:46,606 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [1979479916] [2022-07-21 05:01:46,606 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-07-21 05:01:46,606 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2022-07-21 05:01:46,622 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-07-21 05:01:46,659 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 19 [2022-07-21 05:01:46,662 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-07-21 05:01:46,674 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 2 [2022-07-21 05:01:46,676 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-07-21 05:01:46,679 INFO L134 CoverageAnalysis]: Checked inductivity of 0 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2022-07-21 05:01:46,680 INFO L136 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2022-07-21 05:01:46,680 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [1979479916] [2022-07-21 05:01:46,680 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [1979479916] provided 1 perfect and 0 imperfect interpolant sequences [2022-07-21 05:01:46,681 INFO L184 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2022-07-21 05:01:46,681 INFO L197 FreeRefinementEngine]: Number of different interpolants: perfect sequences [5] imperfect sequences [] total 5 [2022-07-21 05:01:46,681 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [1906230490] [2022-07-21 05:01:46,682 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2022-07-21 05:01:46,683 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 5 states [2022-07-21 05:01:46,684 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2022-07-21 05:01:46,684 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 5 interpolants. [2022-07-21 05:01:46,685 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=7, Invalid=13, Unknown=0, NotChecked=0, Total=20 [2022-07-21 05:01:46,685 INFO L87 Difference]: Start difference. First operand 64 states and 82 transitions. Second operand has 5 states, 5 states have (on average 5.8) internal successors, (29), 5 states have internal predecessors, (29), 2 states have call successors, (3), 3 states have call predecessors, (3), 2 states have return successors, (2), 2 states have call predecessors, (2), 2 states have call successors, (2) [2022-07-21 05:01:46,877 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-07-21 05:01:46,877 INFO L93 Difference]: Finished difference Result 183 states and 235 transitions. [2022-07-21 05:01:46,877 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 7 states. [2022-07-21 05:01:46,878 INFO L78 Accepts]: Start accepts. Automaton has has 5 states, 5 states have (on average 5.8) internal successors, (29), 5 states have internal predecessors, (29), 2 states have call successors, (3), 3 states have call predecessors, (3), 2 states have return successors, (2), 2 states have call predecessors, (2), 2 states have call successors, (2) Word has length 34 [2022-07-21 05:01:46,878 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2022-07-21 05:01:46,880 INFO L225 Difference]: With dead ends: 183 [2022-07-21 05:01:46,880 INFO L226 Difference]: Without dead ends: 126 [2022-07-21 05:01:46,881 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 13 GetRequests, 7 SyntacticMatches, 0 SemanticMatches, 6 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 3 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=19, Invalid=37, Unknown=0, NotChecked=0, Total=56 [2022-07-21 05:01:46,882 INFO L413 NwaCegarLoop]: 111 mSDtfsCounter, 149 mSDsluCounter, 154 mSDsCounter, 0 mSdLazyCounter, 74 mSolverCounterSat, 31 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.1s Time, 0 mProtectedPredicate, 0 mProtectedAction, 151 SdHoareTripleChecker+Valid, 265 SdHoareTripleChecker+Invalid, 105 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 31 IncrementalHoareTripleChecker+Valid, 74 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.1s IncrementalHoareTripleChecker+Time [2022-07-21 05:01:46,883 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [151 Valid, 265 Invalid, 105 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [31 Valid, 74 Invalid, 0 Unknown, 0 Unchecked, 0.1s Time] [2022-07-21 05:01:46,884 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 126 states. [2022-07-21 05:01:46,895 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 126 to 120. [2022-07-21 05:01:46,896 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 120 states, 96 states have (on average 1.28125) internal successors, (123), 103 states have internal predecessors, (123), 10 states have call successors, (10), 10 states have call predecessors, (10), 13 states have return successors, (15), 11 states have call predecessors, (15), 10 states have call successors, (15) [2022-07-21 05:01:46,896 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 120 states to 120 states and 148 transitions. [2022-07-21 05:01:46,897 INFO L78 Accepts]: Start accepts. Automaton has 120 states and 148 transitions. Word has length 34 [2022-07-21 05:01:46,897 INFO L84 Accepts]: Finished accepts. word is rejected. [2022-07-21 05:01:46,897 INFO L495 AbstractCegarLoop]: Abstraction has 120 states and 148 transitions. [2022-07-21 05:01:46,897 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 5 states, 5 states have (on average 5.8) internal successors, (29), 5 states have internal predecessors, (29), 2 states have call successors, (3), 3 states have call predecessors, (3), 2 states have return successors, (2), 2 states have call predecessors, (2), 2 states have call successors, (2) [2022-07-21 05:01:46,898 INFO L276 IsEmpty]: Start isEmpty. Operand 120 states and 148 transitions. [2022-07-21 05:01:46,898 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 39 [2022-07-21 05:01:46,899 INFO L187 NwaCegarLoop]: Found error trace [2022-07-21 05:01:46,899 INFO L195 NwaCegarLoop]: trace histogram [1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-07-21 05:01:46,899 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable3 [2022-07-21 05:01:46,899 INFO L420 AbstractCegarLoop]: === Iteration 5 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2022-07-21 05:01:46,900 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2022-07-21 05:01:46,900 INFO L85 PathProgramCache]: Analyzing trace with hash 1451427371, now seen corresponding path program 1 times [2022-07-21 05:01:46,900 INFO L118 FreeRefinementEngine]: Executing refinement strategy CAMEL [2022-07-21 05:01:46,900 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [1879968922] [2022-07-21 05:01:46,901 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-07-21 05:01:46,901 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2022-07-21 05:01:46,918 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-07-21 05:01:46,936 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 19 [2022-07-21 05:01:46,947 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-07-21 05:01:46,968 INFO L134 CoverageAnalysis]: Checked inductivity of 0 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2022-07-21 05:01:46,968 INFO L136 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2022-07-21 05:01:46,968 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [1879968922] [2022-07-21 05:01:46,969 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [1879968922] provided 1 perfect and 0 imperfect interpolant sequences [2022-07-21 05:01:46,969 INFO L184 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2022-07-21 05:01:46,969 INFO L197 FreeRefinementEngine]: Number of different interpolants: perfect sequences [6] imperfect sequences [] total 6 [2022-07-21 05:01:46,969 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [618864037] [2022-07-21 05:01:46,969 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2022-07-21 05:01:46,970 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 6 states [2022-07-21 05:01:46,970 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2022-07-21 05:01:46,971 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 6 interpolants. [2022-07-21 05:01:46,971 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=9, Invalid=21, Unknown=0, NotChecked=0, Total=30 [2022-07-21 05:01:46,971 INFO L87 Difference]: Start difference. First operand 120 states and 148 transitions. Second operand has 6 states, 6 states have (on average 5.833333333333333) internal successors, (35), 5 states have internal predecessors, (35), 1 states have call successors, (2), 2 states have call predecessors, (2), 1 states have return successors, (1), 1 states have call predecessors, (1), 1 states have call successors, (1) [2022-07-21 05:01:47,091 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-07-21 05:01:47,091 INFO L93 Difference]: Finished difference Result 241 states and 301 transitions. [2022-07-21 05:01:47,092 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 7 states. [2022-07-21 05:01:47,092 INFO L78 Accepts]: Start accepts. Automaton has has 6 states, 6 states have (on average 5.833333333333333) internal successors, (35), 5 states have internal predecessors, (35), 1 states have call successors, (2), 2 states have call predecessors, (2), 1 states have return successors, (1), 1 states have call predecessors, (1), 1 states have call successors, (1) Word has length 38 [2022-07-21 05:01:47,093 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2022-07-21 05:01:47,095 INFO L225 Difference]: With dead ends: 241 [2022-07-21 05:01:47,095 INFO L226 Difference]: Without dead ends: 128 [2022-07-21 05:01:47,098 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 12 GetRequests, 4 SyntacticMatches, 0 SemanticMatches, 8 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 3 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=32, Invalid=58, Unknown=0, NotChecked=0, Total=90 [2022-07-21 05:01:47,103 INFO L413 NwaCegarLoop]: 82 mSDtfsCounter, 59 mSDsluCounter, 251 mSDsCounter, 0 mSdLazyCounter, 90 mSolverCounterSat, 17 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.1s Time, 0 mProtectedPredicate, 0 mProtectedAction, 60 SdHoareTripleChecker+Valid, 333 SdHoareTripleChecker+Invalid, 107 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 17 IncrementalHoareTripleChecker+Valid, 90 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.1s IncrementalHoareTripleChecker+Time [2022-07-21 05:01:47,107 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [60 Valid, 333 Invalid, 107 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [17 Valid, 90 Invalid, 0 Unknown, 0 Unchecked, 0.1s Time] [2022-07-21 05:01:47,110 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 128 states. [2022-07-21 05:01:47,124 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 128 to 123. [2022-07-21 05:01:47,125 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 123 states, 99 states have (on average 1.2727272727272727) internal successors, (126), 106 states have internal predecessors, (126), 10 states have call successors, (10), 10 states have call predecessors, (10), 13 states have return successors, (15), 11 states have call predecessors, (15), 10 states have call successors, (15) [2022-07-21 05:01:47,126 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 123 states to 123 states and 151 transitions. [2022-07-21 05:01:47,126 INFO L78 Accepts]: Start accepts. Automaton has 123 states and 151 transitions. Word has length 38 [2022-07-21 05:01:47,126 INFO L84 Accepts]: Finished accepts. word is rejected. [2022-07-21 05:01:47,127 INFO L495 AbstractCegarLoop]: Abstraction has 123 states and 151 transitions. [2022-07-21 05:01:47,127 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 6 states, 6 states have (on average 5.833333333333333) internal successors, (35), 5 states have internal predecessors, (35), 1 states have call successors, (2), 2 states have call predecessors, (2), 1 states have return successors, (1), 1 states have call predecessors, (1), 1 states have call successors, (1) [2022-07-21 05:01:47,127 INFO L276 IsEmpty]: Start isEmpty. Operand 123 states and 151 transitions. [2022-07-21 05:01:47,128 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 39 [2022-07-21 05:01:47,128 INFO L187 NwaCegarLoop]: Found error trace [2022-07-21 05:01:47,128 INFO L195 NwaCegarLoop]: trace histogram [1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-07-21 05:01:47,129 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable4 [2022-07-21 05:01:47,129 INFO L420 AbstractCegarLoop]: === Iteration 6 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2022-07-21 05:01:47,129 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2022-07-21 05:01:47,129 INFO L85 PathProgramCache]: Analyzing trace with hash 440310121, now seen corresponding path program 1 times [2022-07-21 05:01:47,130 INFO L118 FreeRefinementEngine]: Executing refinement strategy CAMEL [2022-07-21 05:01:47,130 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [1338447348] [2022-07-21 05:01:47,130 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-07-21 05:01:47,130 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2022-07-21 05:01:47,148 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-07-21 05:01:47,171 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 19 [2022-07-21 05:01:47,177 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-07-21 05:01:47,201 INFO L134 CoverageAnalysis]: Checked inductivity of 0 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2022-07-21 05:01:47,201 INFO L136 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2022-07-21 05:01:47,202 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [1338447348] [2022-07-21 05:01:47,202 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [1338447348] provided 1 perfect and 0 imperfect interpolant sequences [2022-07-21 05:01:47,202 INFO L184 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2022-07-21 05:01:47,202 INFO L197 FreeRefinementEngine]: Number of different interpolants: perfect sequences [6] imperfect sequences [] total 6 [2022-07-21 05:01:47,202 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [923557107] [2022-07-21 05:01:47,203 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2022-07-21 05:01:47,203 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 6 states [2022-07-21 05:01:47,203 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2022-07-21 05:01:47,204 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 6 interpolants. [2022-07-21 05:01:47,204 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=9, Invalid=21, Unknown=0, NotChecked=0, Total=30 [2022-07-21 05:01:47,204 INFO L87 Difference]: Start difference. First operand 123 states and 151 transitions. Second operand has 6 states, 6 states have (on average 5.833333333333333) internal successors, (35), 5 states have internal predecessors, (35), 2 states have call successors, (2), 2 states have call predecessors, (2), 1 states have return successors, (1), 1 states have call predecessors, (1), 1 states have call successors, (1) [2022-07-21 05:01:47,319 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-07-21 05:01:47,320 INFO L93 Difference]: Finished difference Result 252 states and 316 transitions. [2022-07-21 05:01:47,320 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 7 states. [2022-07-21 05:01:47,321 INFO L78 Accepts]: Start accepts. Automaton has has 6 states, 6 states have (on average 5.833333333333333) internal successors, (35), 5 states have internal predecessors, (35), 2 states have call successors, (2), 2 states have call predecessors, (2), 1 states have return successors, (1), 1 states have call predecessors, (1), 1 states have call successors, (1) Word has length 38 [2022-07-21 05:01:47,321 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2022-07-21 05:01:47,322 INFO L225 Difference]: With dead ends: 252 [2022-07-21 05:01:47,322 INFO L226 Difference]: Without dead ends: 136 [2022-07-21 05:01:47,323 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 13 GetRequests, 5 SyntacticMatches, 0 SemanticMatches, 8 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 2 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=34, Invalid=56, Unknown=0, NotChecked=0, Total=90 [2022-07-21 05:01:47,324 INFO L413 NwaCegarLoop]: 83 mSDtfsCounter, 130 mSDsluCounter, 176 mSDsCounter, 0 mSdLazyCounter, 80 mSolverCounterSat, 29 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.1s Time, 0 mProtectedPredicate, 0 mProtectedAction, 132 SdHoareTripleChecker+Valid, 259 SdHoareTripleChecker+Invalid, 109 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 29 IncrementalHoareTripleChecker+Valid, 80 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.1s IncrementalHoareTripleChecker+Time [2022-07-21 05:01:47,324 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [132 Valid, 259 Invalid, 109 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [29 Valid, 80 Invalid, 0 Unknown, 0 Unchecked, 0.1s Time] [2022-07-21 05:01:47,325 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 136 states. [2022-07-21 05:01:47,334 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 136 to 125. [2022-07-21 05:01:47,335 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 125 states, 101 states have (on average 1.2673267326732673) internal successors, (128), 108 states have internal predecessors, (128), 10 states have call successors, (10), 10 states have call predecessors, (10), 13 states have return successors, (15), 11 states have call predecessors, (15), 10 states have call successors, (15) [2022-07-21 05:01:47,336 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 125 states to 125 states and 153 transitions. [2022-07-21 05:01:47,336 INFO L78 Accepts]: Start accepts. Automaton has 125 states and 153 transitions. Word has length 38 [2022-07-21 05:01:47,336 INFO L84 Accepts]: Finished accepts. word is rejected. [2022-07-21 05:01:47,337 INFO L495 AbstractCegarLoop]: Abstraction has 125 states and 153 transitions. [2022-07-21 05:01:47,337 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 6 states, 6 states have (on average 5.833333333333333) internal successors, (35), 5 states have internal predecessors, (35), 2 states have call successors, (2), 2 states have call predecessors, (2), 1 states have return successors, (1), 1 states have call predecessors, (1), 1 states have call successors, (1) [2022-07-21 05:01:47,337 INFO L276 IsEmpty]: Start isEmpty. Operand 125 states and 153 transitions. [2022-07-21 05:01:47,338 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 39 [2022-07-21 05:01:47,338 INFO L187 NwaCegarLoop]: Found error trace [2022-07-21 05:01:47,338 INFO L195 NwaCegarLoop]: trace histogram [1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-07-21 05:01:47,338 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable5 [2022-07-21 05:01:47,339 INFO L420 AbstractCegarLoop]: === Iteration 7 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2022-07-21 05:01:47,339 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2022-07-21 05:01:47,339 INFO L85 PathProgramCache]: Analyzing trace with hash -580758233, now seen corresponding path program 1 times [2022-07-21 05:01:47,339 INFO L118 FreeRefinementEngine]: Executing refinement strategy CAMEL [2022-07-21 05:01:47,340 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [2117908934] [2022-07-21 05:01:47,340 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-07-21 05:01:47,340 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2022-07-21 05:01:47,353 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-07-21 05:01:47,377 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 19 [2022-07-21 05:01:47,380 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-07-21 05:01:47,390 INFO L134 CoverageAnalysis]: Checked inductivity of 0 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2022-07-21 05:01:47,391 INFO L136 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2022-07-21 05:01:47,391 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [2117908934] [2022-07-21 05:01:47,391 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [2117908934] provided 1 perfect and 0 imperfect interpolant sequences [2022-07-21 05:01:47,391 INFO L184 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2022-07-21 05:01:47,392 INFO L197 FreeRefinementEngine]: Number of different interpolants: perfect sequences [5] imperfect sequences [] total 5 [2022-07-21 05:01:47,392 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [36506934] [2022-07-21 05:01:47,392 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2022-07-21 05:01:47,392 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 5 states [2022-07-21 05:01:47,392 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2022-07-21 05:01:47,393 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 5 interpolants. [2022-07-21 05:01:47,393 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=7, Invalid=13, Unknown=0, NotChecked=0, Total=20 [2022-07-21 05:01:47,393 INFO L87 Difference]: Start difference. First operand 125 states and 153 transitions. Second operand has 5 states, 5 states have (on average 7.0) internal successors, (35), 4 states have internal predecessors, (35), 1 states have call successors, (2), 2 states have call predecessors, (2), 1 states have return successors, (1), 1 states have call predecessors, (1), 1 states have call successors, (1) [2022-07-21 05:01:47,539 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-07-21 05:01:47,539 INFO L93 Difference]: Finished difference Result 355 states and 457 transitions. [2022-07-21 05:01:47,540 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 7 states. [2022-07-21 05:01:47,540 INFO L78 Accepts]: Start accepts. Automaton has has 5 states, 5 states have (on average 7.0) internal successors, (35), 4 states have internal predecessors, (35), 1 states have call successors, (2), 2 states have call predecessors, (2), 1 states have return successors, (1), 1 states have call predecessors, (1), 1 states have call successors, (1) Word has length 38 [2022-07-21 05:01:47,540 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2022-07-21 05:01:47,542 INFO L225 Difference]: With dead ends: 355 [2022-07-21 05:01:47,542 INFO L226 Difference]: Without dead ends: 237 [2022-07-21 05:01:47,543 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 11 GetRequests, 5 SyntacticMatches, 1 SemanticMatches, 5 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 1 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=15, Invalid=27, Unknown=0, NotChecked=0, Total=42 [2022-07-21 05:01:47,544 INFO L413 NwaCegarLoop]: 124 mSDtfsCounter, 177 mSDsluCounter, 151 mSDsCounter, 0 mSdLazyCounter, 122 mSolverCounterSat, 44 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.1s Time, 0 mProtectedPredicate, 0 mProtectedAction, 181 SdHoareTripleChecker+Valid, 275 SdHoareTripleChecker+Invalid, 166 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 44 IncrementalHoareTripleChecker+Valid, 122 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.1s IncrementalHoareTripleChecker+Time [2022-07-21 05:01:47,544 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [181 Valid, 275 Invalid, 166 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [44 Valid, 122 Invalid, 0 Unknown, 0 Unchecked, 0.1s Time] [2022-07-21 05:01:47,545 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 237 states. [2022-07-21 05:01:47,561 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 237 to 229. [2022-07-21 05:01:47,572 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 229 states, 181 states have (on average 1.2596685082872927) internal successors, (228), 192 states have internal predecessors, (228), 23 states have call successors, (23), 23 states have call predecessors, (23), 24 states have return successors, (38), 23 states have call predecessors, (38), 23 states have call successors, (38) [2022-07-21 05:01:47,573 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 229 states to 229 states and 289 transitions. [2022-07-21 05:01:47,574 INFO L78 Accepts]: Start accepts. Automaton has 229 states and 289 transitions. Word has length 38 [2022-07-21 05:01:47,574 INFO L84 Accepts]: Finished accepts. word is rejected. [2022-07-21 05:01:47,574 INFO L495 AbstractCegarLoop]: Abstraction has 229 states and 289 transitions. [2022-07-21 05:01:47,574 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 5 states, 5 states have (on average 7.0) internal successors, (35), 4 states have internal predecessors, (35), 1 states have call successors, (2), 2 states have call predecessors, (2), 1 states have return successors, (1), 1 states have call predecessors, (1), 1 states have call successors, (1) [2022-07-21 05:01:47,575 INFO L276 IsEmpty]: Start isEmpty. Operand 229 states and 289 transitions. [2022-07-21 05:01:47,575 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 41 [2022-07-21 05:01:47,576 INFO L187 NwaCegarLoop]: Found error trace [2022-07-21 05:01:47,576 INFO L195 NwaCegarLoop]: trace histogram [1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-07-21 05:01:47,576 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable6 [2022-07-21 05:01:47,576 INFO L420 AbstractCegarLoop]: === Iteration 8 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2022-07-21 05:01:47,577 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2022-07-21 05:01:47,577 INFO L85 PathProgramCache]: Analyzing trace with hash -360899650, now seen corresponding path program 1 times [2022-07-21 05:01:47,577 INFO L118 FreeRefinementEngine]: Executing refinement strategy CAMEL [2022-07-21 05:01:47,577 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [843653643] [2022-07-21 05:01:47,577 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-07-21 05:01:47,577 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2022-07-21 05:01:47,590 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-07-21 05:01:47,637 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 19 [2022-07-21 05:01:47,640 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-07-21 05:01:47,643 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 8 [2022-07-21 05:01:47,644 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-07-21 05:01:47,645 INFO L134 CoverageAnalysis]: Checked inductivity of 0 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2022-07-21 05:01:47,645 INFO L136 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2022-07-21 05:01:47,645 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [843653643] [2022-07-21 05:01:47,646 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [843653643] provided 1 perfect and 0 imperfect interpolant sequences [2022-07-21 05:01:47,646 INFO L184 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2022-07-21 05:01:47,646 INFO L197 FreeRefinementEngine]: Number of different interpolants: perfect sequences [6] imperfect sequences [] total 6 [2022-07-21 05:01:47,646 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [1006476877] [2022-07-21 05:01:47,646 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2022-07-21 05:01:47,647 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 6 states [2022-07-21 05:01:47,647 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2022-07-21 05:01:47,647 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 6 interpolants. [2022-07-21 05:01:47,648 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=9, Invalid=21, Unknown=0, NotChecked=0, Total=30 [2022-07-21 05:01:47,648 INFO L87 Difference]: Start difference. First operand 229 states and 289 transitions. Second operand has 6 states, 6 states have (on average 5.833333333333333) internal successors, (35), 5 states have internal predecessors, (35), 2 states have call successors, (3), 3 states have call predecessors, (3), 1 states have return successors, (2), 2 states have call predecessors, (2), 2 states have call successors, (2) [2022-07-21 05:01:47,772 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-07-21 05:01:47,773 INFO L93 Difference]: Finished difference Result 451 states and 570 transitions. [2022-07-21 05:01:47,773 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 7 states. [2022-07-21 05:01:47,773 INFO L78 Accepts]: Start accepts. Automaton has has 6 states, 6 states have (on average 5.833333333333333) internal successors, (35), 5 states have internal predecessors, (35), 2 states have call successors, (3), 3 states have call predecessors, (3), 1 states have return successors, (2), 2 states have call predecessors, (2), 2 states have call successors, (2) Word has length 40 [2022-07-21 05:01:47,774 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2022-07-21 05:01:47,775 INFO L225 Difference]: With dead ends: 451 [2022-07-21 05:01:47,776 INFO L226 Difference]: Without dead ends: 229 [2022-07-21 05:01:47,776 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 13 GetRequests, 6 SyntacticMatches, 0 SemanticMatches, 7 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 0 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=27, Invalid=45, Unknown=0, NotChecked=0, Total=72 [2022-07-21 05:01:47,777 INFO L413 NwaCegarLoop]: 76 mSDtfsCounter, 98 mSDsluCounter, 233 mSDsCounter, 0 mSdLazyCounter, 116 mSolverCounterSat, 20 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.1s Time, 0 mProtectedPredicate, 0 mProtectedAction, 101 SdHoareTripleChecker+Valid, 309 SdHoareTripleChecker+Invalid, 136 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 20 IncrementalHoareTripleChecker+Valid, 116 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.1s IncrementalHoareTripleChecker+Time [2022-07-21 05:01:47,777 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [101 Valid, 309 Invalid, 136 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [20 Valid, 116 Invalid, 0 Unknown, 0 Unchecked, 0.1s Time] [2022-07-21 05:01:47,778 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 229 states. [2022-07-21 05:01:47,797 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 229 to 227. [2022-07-21 05:01:47,798 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 227 states, 179 states have (on average 1.2513966480446927) internal successors, (224), 190 states have internal predecessors, (224), 23 states have call successors, (23), 23 states have call predecessors, (23), 24 states have return successors, (38), 23 states have call predecessors, (38), 23 states have call successors, (38) [2022-07-21 05:01:47,799 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 227 states to 227 states and 285 transitions. [2022-07-21 05:01:47,801 INFO L78 Accepts]: Start accepts. Automaton has 227 states and 285 transitions. Word has length 40 [2022-07-21 05:01:47,801 INFO L84 Accepts]: Finished accepts. word is rejected. [2022-07-21 05:01:47,801 INFO L495 AbstractCegarLoop]: Abstraction has 227 states and 285 transitions. [2022-07-21 05:01:47,802 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 6 states, 6 states have (on average 5.833333333333333) internal successors, (35), 5 states have internal predecessors, (35), 2 states have call successors, (3), 3 states have call predecessors, (3), 1 states have return successors, (2), 2 states have call predecessors, (2), 2 states have call successors, (2) [2022-07-21 05:01:47,802 INFO L276 IsEmpty]: Start isEmpty. Operand 227 states and 285 transitions. [2022-07-21 05:01:47,803 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 43 [2022-07-21 05:01:47,803 INFO L187 NwaCegarLoop]: Found error trace [2022-07-21 05:01:47,803 INFO L195 NwaCegarLoop]: trace histogram [1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-07-21 05:01:47,803 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable7 [2022-07-21 05:01:47,804 INFO L420 AbstractCegarLoop]: === Iteration 9 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2022-07-21 05:01:47,804 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2022-07-21 05:01:47,804 INFO L85 PathProgramCache]: Analyzing trace with hash 2038696205, now seen corresponding path program 1 times [2022-07-21 05:01:47,804 INFO L118 FreeRefinementEngine]: Executing refinement strategy CAMEL [2022-07-21 05:01:47,804 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [1165476944] [2022-07-21 05:01:47,805 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-07-21 05:01:47,805 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2022-07-21 05:01:47,818 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-07-21 05:01:47,859 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 11 [2022-07-21 05:01:47,860 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-07-21 05:01:47,866 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 23 [2022-07-21 05:01:47,868 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-07-21 05:01:47,875 INFO L134 CoverageAnalysis]: Checked inductivity of 0 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2022-07-21 05:01:47,875 INFO L136 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2022-07-21 05:01:47,876 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [1165476944] [2022-07-21 05:01:47,876 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [1165476944] provided 1 perfect and 0 imperfect interpolant sequences [2022-07-21 05:01:47,876 INFO L184 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2022-07-21 05:01:47,876 INFO L197 FreeRefinementEngine]: Number of different interpolants: perfect sequences [7] imperfect sequences [] total 7 [2022-07-21 05:01:47,876 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [1891742766] [2022-07-21 05:01:47,876 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2022-07-21 05:01:47,877 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 7 states [2022-07-21 05:01:47,877 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2022-07-21 05:01:47,877 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 7 interpolants. [2022-07-21 05:01:47,878 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=11, Invalid=31, Unknown=0, NotChecked=0, Total=42 [2022-07-21 05:01:47,878 INFO L87 Difference]: Start difference. First operand 227 states and 285 transitions. Second operand has 7 states, 7 states have (on average 5.285714285714286) internal successors, (37), 5 states have internal predecessors, (37), 1 states have call successors, (3), 3 states have call predecessors, (3), 2 states have return successors, (2), 2 states have call predecessors, (2), 1 states have call successors, (2) [2022-07-21 05:01:48,123 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-07-21 05:01:48,123 INFO L93 Difference]: Finished difference Result 456 states and 585 transitions. [2022-07-21 05:01:48,124 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 12 states. [2022-07-21 05:01:48,124 INFO L78 Accepts]: Start accepts. Automaton has has 7 states, 7 states have (on average 5.285714285714286) internal successors, (37), 5 states have internal predecessors, (37), 1 states have call successors, (3), 3 states have call predecessors, (3), 2 states have return successors, (2), 2 states have call predecessors, (2), 1 states have call successors, (2) Word has length 42 [2022-07-21 05:01:48,124 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2022-07-21 05:01:48,126 INFO L225 Difference]: With dead ends: 456 [2022-07-21 05:01:48,126 INFO L226 Difference]: Without dead ends: 276 [2022-07-21 05:01:48,127 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 19 GetRequests, 6 SyntacticMatches, 1 SemanticMatches, 12 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 9 ImplicationChecksByTransitivity, 0.1s TimeCoverageRelationStatistics Valid=63, Invalid=119, Unknown=0, NotChecked=0, Total=182 [2022-07-21 05:01:48,128 INFO L413 NwaCegarLoop]: 126 mSDtfsCounter, 159 mSDsluCounter, 344 mSDsCounter, 0 mSdLazyCounter, 255 mSolverCounterSat, 39 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.1s Time, 0 mProtectedPredicate, 0 mProtectedAction, 160 SdHoareTripleChecker+Valid, 470 SdHoareTripleChecker+Invalid, 294 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 39 IncrementalHoareTripleChecker+Valid, 255 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.2s IncrementalHoareTripleChecker+Time [2022-07-21 05:01:48,128 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [160 Valid, 470 Invalid, 294 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [39 Valid, 255 Invalid, 0 Unknown, 0 Unchecked, 0.2s Time] [2022-07-21 05:01:48,129 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 276 states. [2022-07-21 05:01:48,142 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 276 to 253. [2022-07-21 05:01:48,143 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 253 states, 201 states have (on average 1.2338308457711442) internal successors, (248), 215 states have internal predecessors, (248), 24 states have call successors, (24), 23 states have call predecessors, (24), 27 states have return successors, (41), 24 states have call predecessors, (41), 24 states have call successors, (41) [2022-07-21 05:01:48,144 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 253 states to 253 states and 313 transitions. [2022-07-21 05:01:48,145 INFO L78 Accepts]: Start accepts. Automaton has 253 states and 313 transitions. Word has length 42 [2022-07-21 05:01:48,145 INFO L84 Accepts]: Finished accepts. word is rejected. [2022-07-21 05:01:48,145 INFO L495 AbstractCegarLoop]: Abstraction has 253 states and 313 transitions. [2022-07-21 05:01:48,145 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 7 states, 7 states have (on average 5.285714285714286) internal successors, (37), 5 states have internal predecessors, (37), 1 states have call successors, (3), 3 states have call predecessors, (3), 2 states have return successors, (2), 2 states have call predecessors, (2), 1 states have call successors, (2) [2022-07-21 05:01:48,145 INFO L276 IsEmpty]: Start isEmpty. Operand 253 states and 313 transitions. [2022-07-21 05:01:48,147 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 70 [2022-07-21 05:01:48,147 INFO L187 NwaCegarLoop]: Found error trace [2022-07-21 05:01:48,147 INFO L195 NwaCegarLoop]: trace histogram [2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-07-21 05:01:48,147 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable8 [2022-07-21 05:01:48,148 INFO L420 AbstractCegarLoop]: === Iteration 10 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2022-07-21 05:01:48,148 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2022-07-21 05:01:48,148 INFO L85 PathProgramCache]: Analyzing trace with hash 871440435, now seen corresponding path program 1 times [2022-07-21 05:01:48,148 INFO L118 FreeRefinementEngine]: Executing refinement strategy CAMEL [2022-07-21 05:01:48,149 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [83850937] [2022-07-21 05:01:48,149 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-07-21 05:01:48,149 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2022-07-21 05:01:48,181 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-07-21 05:01:48,230 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 11 [2022-07-21 05:01:48,232 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-07-21 05:01:48,241 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 19 [2022-07-21 05:01:48,244 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-07-21 05:01:48,262 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 3 [2022-07-21 05:01:48,264 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-07-21 05:01:48,267 INFO L134 CoverageAnalysis]: Checked inductivity of 16 backedges. 4 proven. 1 refuted. 0 times theorem prover too weak. 11 trivial. 0 not checked. [2022-07-21 05:01:48,283 INFO L136 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2022-07-21 05:01:48,283 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [83850937] [2022-07-21 05:01:48,284 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [83850937] provided 0 perfect and 1 imperfect interpolant sequences [2022-07-21 05:01:48,284 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleZ3 [1333633767] [2022-07-21 05:01:48,284 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-07-21 05:01:48,284 INFO L173 SolverBuilder]: Constructing external solver with command: z3 -smt2 -in SMTLIB2_COMPLIANT=true [2022-07-21 05:01:48,284 INFO L189 MonitoredProcess]: No working directory specified, using /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 [2022-07-21 05:01:48,309 INFO L229 MonitoredProcess]: Starting monitored process 2 with /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 -smt2 -in SMTLIB2_COMPLIANT=true (exit command is (exit), workingDir is null) [2022-07-21 05:01:48,335 INFO L327 MonitoredProcess]: [MP /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 -smt2 -in SMTLIB2_COMPLIANT=true (2)] Waiting until timeout for monitored process [2022-07-21 05:01:48,408 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-07-21 05:01:48,413 INFO L263 TraceCheckSpWp]: Trace formula consists of 407 conjuncts, 8 conjunts are in the unsatisfiable core [2022-07-21 05:01:48,419 INFO L286 TraceCheckSpWp]: Computing forward predicates... [2022-07-21 05:01:48,595 INFO L134 CoverageAnalysis]: Checked inductivity of 16 backedges. 12 proven. 4 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2022-07-21 05:01:48,595 INFO L328 TraceCheckSpWp]: Computing backward predicates... [2022-07-21 05:01:48,694 INFO L134 CoverageAnalysis]: Checked inductivity of 16 backedges. 12 proven. 4 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2022-07-21 05:01:48,694 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleZ3 [1333633767] provided 0 perfect and 2 imperfect interpolant sequences [2022-07-21 05:01:48,695 INFO L184 FreeRefinementEngine]: Found 0 perfect and 3 imperfect interpolant sequences. [2022-07-21 05:01:48,695 INFO L197 FreeRefinementEngine]: Number of different interpolants: perfect sequences [] imperfect sequences [8, 6, 6] total 12 [2022-07-21 05:01:48,695 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [1851080782] [2022-07-21 05:01:48,695 INFO L85 oduleStraightlineAll]: Using 3 imperfect interpolants to construct interpolant automaton [2022-07-21 05:01:48,696 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 12 states [2022-07-21 05:01:48,696 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2022-07-21 05:01:48,696 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 12 interpolants. [2022-07-21 05:01:48,696 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=24, Invalid=108, Unknown=0, NotChecked=0, Total=132 [2022-07-21 05:01:48,697 INFO L87 Difference]: Start difference. First operand 253 states and 313 transitions. Second operand has 12 states, 12 states have (on average 7.833333333333333) internal successors, (94), 9 states have internal predecessors, (94), 2 states have call successors, (7), 5 states have call predecessors, (7), 2 states have return successors, (5), 2 states have call predecessors, (5), 1 states have call successors, (5) [2022-07-21 05:01:49,442 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-07-21 05:01:49,443 INFO L93 Difference]: Finished difference Result 628 states and 814 transitions. [2022-07-21 05:01:49,447 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 36 states. [2022-07-21 05:01:49,447 INFO L78 Accepts]: Start accepts. Automaton has has 12 states, 12 states have (on average 7.833333333333333) internal successors, (94), 9 states have internal predecessors, (94), 2 states have call successors, (7), 5 states have call predecessors, (7), 2 states have return successors, (5), 2 states have call predecessors, (5), 1 states have call successors, (5) Word has length 69 [2022-07-21 05:01:49,448 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2022-07-21 05:01:49,450 INFO L225 Difference]: With dead ends: 628 [2022-07-21 05:01:49,450 INFO L226 Difference]: Without dead ends: 424 [2022-07-21 05:01:49,452 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 185 GetRequests, 142 SyntacticMatches, 4 SemanticMatches, 39 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 402 ImplicationChecksByTransitivity, 0.3s TimeCoverageRelationStatistics Valid=312, Invalid=1328, Unknown=0, NotChecked=0, Total=1640 [2022-07-21 05:01:49,452 INFO L413 NwaCegarLoop]: 140 mSDtfsCounter, 307 mSDsluCounter, 803 mSDsCounter, 0 mSdLazyCounter, 791 mSolverCounterSat, 85 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.3s Time, 0 mProtectedPredicate, 0 mProtectedAction, 311 SdHoareTripleChecker+Valid, 943 SdHoareTripleChecker+Invalid, 876 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 85 IncrementalHoareTripleChecker+Valid, 791 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.4s IncrementalHoareTripleChecker+Time [2022-07-21 05:01:49,455 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [311 Valid, 943 Invalid, 876 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [85 Valid, 791 Invalid, 0 Unknown, 0 Unchecked, 0.4s Time] [2022-07-21 05:01:49,455 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 424 states. [2022-07-21 05:01:49,474 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 424 to 355. [2022-07-21 05:01:49,475 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 355 states, 282 states have (on average 1.2234042553191489) internal successors, (345), 301 states have internal predecessors, (345), 34 states have call successors, (34), 33 states have call predecessors, (34), 38 states have return successors, (61), 32 states have call predecessors, (61), 34 states have call successors, (61) [2022-07-21 05:01:49,477 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 355 states to 355 states and 440 transitions. [2022-07-21 05:01:49,477 INFO L78 Accepts]: Start accepts. Automaton has 355 states and 440 transitions. Word has length 69 [2022-07-21 05:01:49,477 INFO L84 Accepts]: Finished accepts. word is rejected. [2022-07-21 05:01:49,477 INFO L495 AbstractCegarLoop]: Abstraction has 355 states and 440 transitions. [2022-07-21 05:01:49,478 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 12 states, 12 states have (on average 7.833333333333333) internal successors, (94), 9 states have internal predecessors, (94), 2 states have call successors, (7), 5 states have call predecessors, (7), 2 states have return successors, (5), 2 states have call predecessors, (5), 1 states have call successors, (5) [2022-07-21 05:01:49,478 INFO L276 IsEmpty]: Start isEmpty. Operand 355 states and 440 transitions. [2022-07-21 05:01:49,479 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 104 [2022-07-21 05:01:49,479 INFO L187 NwaCegarLoop]: Found error trace [2022-07-21 05:01:49,480 INFO L195 NwaCegarLoop]: trace histogram [3, 3, 3, 3, 3, 3, 3, 3, 3, 3, 3, 3, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-07-21 05:01:49,507 INFO L540 MonitoredProcess]: [MP /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 -smt2 -in SMTLIB2_COMPLIANT=true (2)] Forceful destruction successful, exit code 0 [2022-07-21 05:01:49,691 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: 2 /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 -smt2 -in SMTLIB2_COMPLIANT=true,SelfDestructingSolverStorable9 [2022-07-21 05:01:49,692 INFO L420 AbstractCegarLoop]: === Iteration 11 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2022-07-21 05:01:49,692 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2022-07-21 05:01:49,692 INFO L85 PathProgramCache]: Analyzing trace with hash 1761843705, now seen corresponding path program 1 times [2022-07-21 05:01:49,692 INFO L118 FreeRefinementEngine]: Executing refinement strategy CAMEL [2022-07-21 05:01:49,692 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [876959504] [2022-07-21 05:01:49,692 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-07-21 05:01:49,693 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2022-07-21 05:01:49,710 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-07-21 05:01:49,747 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 11 [2022-07-21 05:01:49,749 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-07-21 05:01:49,758 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 19 [2022-07-21 05:01:49,761 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-07-21 05:01:49,773 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 3 [2022-07-21 05:01:49,775 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-07-21 05:01:49,777 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 50 [2022-07-21 05:01:49,779 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-07-21 05:01:49,783 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 10 [2022-07-21 05:01:49,784 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-07-21 05:01:49,785 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 2 [2022-07-21 05:01:49,786 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-07-21 05:01:49,787 INFO L134 CoverageAnalysis]: Checked inductivity of 62 backedges. 8 proven. 2 refuted. 0 times theorem prover too weak. 52 trivial. 0 not checked. [2022-07-21 05:01:49,787 INFO L136 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2022-07-21 05:01:49,787 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [876959504] [2022-07-21 05:01:49,787 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [876959504] provided 0 perfect and 1 imperfect interpolant sequences [2022-07-21 05:01:49,787 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleZ3 [1287410858] [2022-07-21 05:01:49,788 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-07-21 05:01:49,788 INFO L173 SolverBuilder]: Constructing external solver with command: z3 -smt2 -in SMTLIB2_COMPLIANT=true [2022-07-21 05:01:49,788 INFO L189 MonitoredProcess]: No working directory specified, using /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 [2022-07-21 05:01:49,789 INFO L229 MonitoredProcess]: Starting monitored process 3 with /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 -smt2 -in SMTLIB2_COMPLIANT=true (exit command is (exit), workingDir is null) [2022-07-21 05:01:49,791 INFO L327 MonitoredProcess]: [MP /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 -smt2 -in SMTLIB2_COMPLIANT=true (3)] Waiting until timeout for monitored process [2022-07-21 05:01:49,900 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-07-21 05:01:49,903 INFO L263 TraceCheckSpWp]: Trace formula consists of 491 conjuncts, 11 conjunts are in the unsatisfiable core [2022-07-21 05:01:49,908 INFO L286 TraceCheckSpWp]: Computing forward predicates... [2022-07-21 05:01:50,179 INFO L134 CoverageAnalysis]: Checked inductivity of 62 backedges. 53 proven. 9 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2022-07-21 05:01:50,179 INFO L328 TraceCheckSpWp]: Computing backward predicates... [2022-07-21 05:01:50,434 INFO L134 CoverageAnalysis]: Checked inductivity of 62 backedges. 51 proven. 9 refuted. 0 times theorem prover too weak. 2 trivial. 0 not checked. [2022-07-21 05:01:50,435 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleZ3 [1287410858] provided 0 perfect and 2 imperfect interpolant sequences [2022-07-21 05:01:50,435 INFO L184 FreeRefinementEngine]: Found 0 perfect and 3 imperfect interpolant sequences. [2022-07-21 05:01:50,435 INFO L197 FreeRefinementEngine]: Number of different interpolants: perfect sequences [] imperfect sequences [8, 9, 8] total 20 [2022-07-21 05:01:50,435 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [1186916239] [2022-07-21 05:01:50,436 INFO L85 oduleStraightlineAll]: Using 3 imperfect interpolants to construct interpolant automaton [2022-07-21 05:01:50,436 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 20 states [2022-07-21 05:01:50,436 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2022-07-21 05:01:50,437 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 20 interpolants. [2022-07-21 05:01:50,437 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=71, Invalid=309, Unknown=0, NotChecked=0, Total=380 [2022-07-21 05:01:50,438 INFO L87 Difference]: Start difference. First operand 355 states and 440 transitions. Second operand has 20 states, 20 states have (on average 7.25) internal successors, (145), 17 states have internal predecessors, (145), 6 states have call successors, (14), 8 states have call predecessors, (14), 5 states have return successors, (12), 6 states have call predecessors, (12), 5 states have call successors, (12) [2022-07-21 05:01:52,239 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-07-21 05:01:52,239 INFO L93 Difference]: Finished difference Result 916 states and 1194 transitions. [2022-07-21 05:01:52,240 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 42 states. [2022-07-21 05:01:52,240 INFO L78 Accepts]: Start accepts. Automaton has has 20 states, 20 states have (on average 7.25) internal successors, (145), 17 states have internal predecessors, (145), 6 states have call successors, (14), 8 states have call predecessors, (14), 5 states have return successors, (12), 6 states have call predecessors, (12), 5 states have call successors, (12) Word has length 103 [2022-07-21 05:01:52,240 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2022-07-21 05:01:52,244 INFO L225 Difference]: With dead ends: 916 [2022-07-21 05:01:52,244 INFO L226 Difference]: Without dead ends: 609 [2022-07-21 05:01:52,247 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 280 GetRequests, 226 SyntacticMatches, 1 SemanticMatches, 53 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 580 ImplicationChecksByTransitivity, 1.0s TimeCoverageRelationStatistics Valid=636, Invalid=2334, Unknown=0, NotChecked=0, Total=2970 [2022-07-21 05:01:52,248 INFO L413 NwaCegarLoop]: 245 mSDtfsCounter, 656 mSDsluCounter, 1455 mSDsCounter, 0 mSdLazyCounter, 1659 mSolverCounterSat, 198 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.7s Time, 0 mProtectedPredicate, 0 mProtectedAction, 663 SdHoareTripleChecker+Valid, 1700 SdHoareTripleChecker+Invalid, 1857 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 198 IncrementalHoareTripleChecker+Valid, 1659 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.9s IncrementalHoareTripleChecker+Time [2022-07-21 05:01:52,248 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [663 Valid, 1700 Invalid, 1857 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [198 Valid, 1659 Invalid, 0 Unknown, 0 Unchecked, 0.9s Time] [2022-07-21 05:01:52,249 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 609 states. [2022-07-21 05:01:52,281 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 609 to 525. [2022-07-21 05:01:52,282 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 525 states, 411 states have (on average 1.2092457420924574) internal successors, (497), 435 states have internal predecessors, (497), 56 states have call successors, (56), 54 states have call predecessors, (56), 57 states have return successors, (91), 51 states have call predecessors, (91), 56 states have call successors, (91) [2022-07-21 05:01:52,284 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 525 states to 525 states and 644 transitions. [2022-07-21 05:01:52,285 INFO L78 Accepts]: Start accepts. Automaton has 525 states and 644 transitions. Word has length 103 [2022-07-21 05:01:52,285 INFO L84 Accepts]: Finished accepts. word is rejected. [2022-07-21 05:01:52,285 INFO L495 AbstractCegarLoop]: Abstraction has 525 states and 644 transitions. [2022-07-21 05:01:52,286 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 20 states, 20 states have (on average 7.25) internal successors, (145), 17 states have internal predecessors, (145), 6 states have call successors, (14), 8 states have call predecessors, (14), 5 states have return successors, (12), 6 states have call predecessors, (12), 5 states have call successors, (12) [2022-07-21 05:01:52,286 INFO L276 IsEmpty]: Start isEmpty. Operand 525 states and 644 transitions. [2022-07-21 05:01:52,287 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 111 [2022-07-21 05:01:52,288 INFO L187 NwaCegarLoop]: Found error trace [2022-07-21 05:01:52,288 INFO L195 NwaCegarLoop]: trace histogram [3, 3, 3, 3, 3, 3, 3, 3, 3, 3, 3, 3, 3, 3, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-07-21 05:01:52,315 INFO L552 MonitoredProcess]: [MP /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 -smt2 -in SMTLIB2_COMPLIANT=true (3)] Ended with exit code 0 [2022-07-21 05:01:52,503 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: 3 /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 -smt2 -in SMTLIB2_COMPLIANT=true,SelfDestructingSolverStorable10 [2022-07-21 05:01:52,504 INFO L420 AbstractCegarLoop]: === Iteration 12 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2022-07-21 05:01:52,504 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2022-07-21 05:01:52,504 INFO L85 PathProgramCache]: Analyzing trace with hash 1113823743, now seen corresponding path program 1 times [2022-07-21 05:01:52,504 INFO L118 FreeRefinementEngine]: Executing refinement strategy CAMEL [2022-07-21 05:01:52,504 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [1078703857] [2022-07-21 05:01:52,504 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-07-21 05:01:52,504 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2022-07-21 05:01:52,525 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-07-21 05:01:52,555 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 11 [2022-07-21 05:01:52,557 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-07-21 05:01:52,562 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 19 [2022-07-21 05:01:52,564 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-07-21 05:01:52,569 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 3 [2022-07-21 05:01:52,571 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-07-21 05:01:52,573 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 50 [2022-07-21 05:01:52,576 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-07-21 05:01:52,597 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 10 [2022-07-21 05:01:52,598 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-07-21 05:01:52,599 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 2 [2022-07-21 05:01:52,599 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-07-21 05:01:52,600 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 95 [2022-07-21 05:01:52,601 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-07-21 05:01:52,602 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 2 [2022-07-21 05:01:52,602 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-07-21 05:01:52,603 INFO L134 CoverageAnalysis]: Checked inductivity of 74 backedges. 42 proven. 9 refuted. 0 times theorem prover too weak. 23 trivial. 0 not checked. [2022-07-21 05:01:52,603 INFO L136 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2022-07-21 05:01:52,603 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [1078703857] [2022-07-21 05:01:52,604 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [1078703857] provided 0 perfect and 1 imperfect interpolant sequences [2022-07-21 05:01:52,604 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleZ3 [1422178728] [2022-07-21 05:01:52,604 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-07-21 05:01:52,604 INFO L173 SolverBuilder]: Constructing external solver with command: z3 -smt2 -in SMTLIB2_COMPLIANT=true [2022-07-21 05:01:52,604 INFO L189 MonitoredProcess]: No working directory specified, using /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 [2022-07-21 05:01:52,605 INFO L229 MonitoredProcess]: Starting monitored process 4 with /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 -smt2 -in SMTLIB2_COMPLIANT=true (exit command is (exit), workingDir is null) [2022-07-21 05:01:52,631 INFO L327 MonitoredProcess]: [MP /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 -smt2 -in SMTLIB2_COMPLIANT=true (4)] Waiting until timeout for monitored process [2022-07-21 05:01:52,723 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-07-21 05:01:52,725 INFO L263 TraceCheckSpWp]: Trace formula consists of 503 conjuncts, 5 conjunts are in the unsatisfiable core [2022-07-21 05:01:52,728 INFO L286 TraceCheckSpWp]: Computing forward predicates... [2022-07-21 05:01:52,739 INFO L134 CoverageAnalysis]: Checked inductivity of 74 backedges. 50 proven. 0 refuted. 0 times theorem prover too weak. 24 trivial. 0 not checked. [2022-07-21 05:01:52,740 INFO L324 TraceCheckSpWp]: Omiting computation of backward sequence because forward sequence was already perfect [2022-07-21 05:01:52,740 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleZ3 [1422178728] provided 1 perfect and 0 imperfect interpolant sequences [2022-07-21 05:01:52,740 INFO L184 FreeRefinementEngine]: Found 1 perfect and 1 imperfect interpolant sequences. [2022-07-21 05:01:52,740 INFO L197 FreeRefinementEngine]: Number of different interpolants: perfect sequences [5] imperfect sequences [9] total 9 [2022-07-21 05:01:52,740 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [1578168699] [2022-07-21 05:01:52,740 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2022-07-21 05:01:52,741 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 5 states [2022-07-21 05:01:52,741 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2022-07-21 05:01:52,741 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 5 interpolants. [2022-07-21 05:01:52,742 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=17, Invalid=55, Unknown=0, NotChecked=0, Total=72 [2022-07-21 05:01:52,742 INFO L87 Difference]: Start difference. First operand 525 states and 644 transitions. Second operand has 5 states, 5 states have (on average 15.6) internal successors, (78), 5 states have internal predecessors, (78), 2 states have call successors, (6), 2 states have call predecessors, (6), 2 states have return successors, (6), 2 states have call predecessors, (6), 2 states have call successors, (6) [2022-07-21 05:01:52,777 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-07-21 05:01:52,778 INFO L93 Difference]: Finished difference Result 676 states and 824 transitions. [2022-07-21 05:01:52,778 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 5 states. [2022-07-21 05:01:52,778 INFO L78 Accepts]: Start accepts. Automaton has has 5 states, 5 states have (on average 15.6) internal successors, (78), 5 states have internal predecessors, (78), 2 states have call successors, (6), 2 states have call predecessors, (6), 2 states have return successors, (6), 2 states have call predecessors, (6), 2 states have call successors, (6) Word has length 110 [2022-07-21 05:01:52,779 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2022-07-21 05:01:52,779 INFO L225 Difference]: With dead ends: 676 [2022-07-21 05:01:52,779 INFO L226 Difference]: Without dead ends: 0 [2022-07-21 05:01:52,781 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 135 GetRequests, 126 SyntacticMatches, 0 SemanticMatches, 9 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 9 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=27, Invalid=83, Unknown=0, NotChecked=0, Total=110 [2022-07-21 05:01:52,782 INFO L413 NwaCegarLoop]: 82 mSDtfsCounter, 27 mSDsluCounter, 215 mSDsCounter, 0 mSdLazyCounter, 13 mSolverCounterSat, 0 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.0s Time, 0 mProtectedPredicate, 0 mProtectedAction, 27 SdHoareTripleChecker+Valid, 297 SdHoareTripleChecker+Invalid, 13 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 0 IncrementalHoareTripleChecker+Valid, 13 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.0s IncrementalHoareTripleChecker+Time [2022-07-21 05:01:52,782 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [27 Valid, 297 Invalid, 13 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [0 Valid, 13 Invalid, 0 Unknown, 0 Unchecked, 0.0s Time] [2022-07-21 05:01:52,782 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 0 states. [2022-07-21 05:01:52,783 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 0 to 0. [2022-07-21 05:01:52,783 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 0 states, 0 states have (on average 0.0) internal successors, (0), 0 states have internal predecessors, (0), 0 states have call successors, (0), 0 states have call predecessors, (0), 0 states have return successors, (0), 0 states have call predecessors, (0), 0 states have call successors, (0) [2022-07-21 05:01:52,783 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 0 states to 0 states and 0 transitions. [2022-07-21 05:01:52,783 INFO L78 Accepts]: Start accepts. Automaton has 0 states and 0 transitions. Word has length 110 [2022-07-21 05:01:52,783 INFO L84 Accepts]: Finished accepts. word is rejected. [2022-07-21 05:01:52,784 INFO L495 AbstractCegarLoop]: Abstraction has 0 states and 0 transitions. [2022-07-21 05:01:52,784 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 5 states, 5 states have (on average 15.6) internal successors, (78), 5 states have internal predecessors, (78), 2 states have call successors, (6), 2 states have call predecessors, (6), 2 states have return successors, (6), 2 states have call predecessors, (6), 2 states have call successors, (6) [2022-07-21 05:01:52,784 INFO L276 IsEmpty]: Start isEmpty. Operand 0 states and 0 transitions. [2022-07-21 05:01:52,784 INFO L282 IsEmpty]: Finished isEmpty. No accepting run. [2022-07-21 05:01:52,786 INFO L805 garLoopResultBuilder]: Registering result SAFE for location timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION (0 of 1 remaining) [2022-07-21 05:01:52,814 INFO L552 MonitoredProcess]: [MP /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 -smt2 -in SMTLIB2_COMPLIANT=true (4)] Ended with exit code 0 [2022-07-21 05:01:53,011 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable11,4 /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 -smt2 -in SMTLIB2_COMPLIANT=true [2022-07-21 05:01:53,013 INFO L343 DoubleDeckerVisitor]: Before removal of dead ends 0 states and 0 transitions. [2022-07-21 05:01:54,767 INFO L899 garLoopResultBuilder]: For program point processEnvironment__wrappee__baseEXIT(lines 303 309) no Hoare annotation was computed. [2022-07-21 05:01:54,767 INFO L902 garLoopResultBuilder]: At program point processEnvironment__wrappee__baseFINAL(lines 303 309) the Hoare annotation is: true [2022-07-21 05:01:54,767 INFO L899 garLoopResultBuilder]: For program point L97-1(lines 93 104) no Hoare annotation was computed. [2022-07-21 05:01:54,767 INFO L902 garLoopResultBuilder]: At program point changeMethaneLevelENTRY(lines 93 104) the Hoare annotation is: true [2022-07-21 05:01:54,767 INFO L899 garLoopResultBuilder]: For program point changeMethaneLevelEXIT(lines 93 104) no Hoare annotation was computed. [2022-07-21 05:01:54,767 INFO L899 garLoopResultBuilder]: For program point L283-1(lines 282 301) no Hoare annotation was computed. [2022-07-21 05:01:54,767 INFO L899 garLoopResultBuilder]: For program point L345(lines 345 353) no Hoare annotation was computed. [2022-07-21 05:01:54,767 INFO L899 garLoopResultBuilder]: For program point L341(lines 341 358) no Hoare annotation was computed. [2022-07-21 05:01:54,767 INFO L899 garLoopResultBuilder]: For program point L73(lines 73 77) no Hoare annotation was computed. [2022-07-21 05:01:54,767 INFO L899 garLoopResultBuilder]: For program point L585(lines 585 591) no Hoare annotation was computed. [2022-07-21 05:01:54,768 INFO L895 garLoopResultBuilder]: At program point L73-2(lines 69 80) the Hoare annotation is: (let ((.cse0 (not (= 1 ~systemActive~0)))) (and (or (not (= |old(~pumpRunning~0)| 0)) .cse0 (not (<= 1 |old(~waterLevel~0)|))) (or .cse0 (< |old(~waterLevel~0)| 2) (and (= ~pumpRunning~0 |old(~pumpRunning~0)|) (<= |old(~waterLevel~0)| (+ ~waterLevel~0 1)))))) [2022-07-21 05:01:54,768 INFO L899 garLoopResultBuilder]: For program point timeShiftFINAL(lines 279 302) no Hoare annotation was computed. [2022-07-21 05:01:54,768 INFO L899 garLoopResultBuilder]: For program point L581(lines 581 594) no Hoare annotation was computed. [2022-07-21 05:01:54,768 INFO L895 garLoopResultBuilder]: At program point L581-1(lines 573 597) the Hoare annotation is: (let ((.cse6 (= 1 ~systemActive~0)) (.cse5 (= |old(~waterLevel~0)| ~waterLevel~0))) (let ((.cse0 (not (= |old(~pumpRunning~0)| 0))) (.cse1 (and (<= 2 ~waterLevel~0) .cse6 (<= 2 |timeShift___utac_acc__Specification4_spec__1_~tmp~6#1|) .cse5 (<= 2 |timeShift_getWaterLevel_#res#1|))) (.cse2 (not .cse6)) (.cse4 (< |old(~waterLevel~0)| 2)) (.cse3 (= ~pumpRunning~0 0))) (and (or .cse0 .cse1 .cse2 (not (<= 1 |old(~waterLevel~0)|)) (and .cse3 .cse4 .cse5)) (or .cse0 (not (= |old(~waterLevel~0)| 1)) .cse2 (and (= |timeShift___utac_acc__Specification4_spec__1_~tmp~6#1| 1) (= |timeShift_getWaterLevel_#res#1| 1))) (or .cse1 .cse2 .cse4 (and (<= 1 |timeShift_processEnvironment_~tmp~2#1|) (= |timeShift_isLowWaterSensorDry_#res#1| 0) .cse3 (<= 1 |timeShift_isLowWaterLevel_~tmp___0~1#1|) (<= 1 |timeShift_isLowWaterLevel_#res#1|) (= |timeShift_isLowWaterLevel_~tmp~4#1| 0) (<= 1 |timeShift___utac_acc__Specification4_spec__1_~tmp~6#1|) (<= |old(~waterLevel~0)| (+ ~waterLevel~0 1)) (<= 1 |timeShift_getWaterLevel_#res#1|)))))) [2022-07-21 05:01:54,768 INFO L895 garLoopResultBuilder]: At program point L375(lines 370 377) the Hoare annotation is: (let ((.cse0 (not (= 1 ~systemActive~0)))) (and (or (not (= |old(~pumpRunning~0)| 0)) .cse0 (not (<= 1 |old(~waterLevel~0)|))) (or (and (<= 1 |timeShift_processEnvironment_~tmp~2#1|) (= |timeShift_isLowWaterSensorDry_#res#1| 0) (= ~pumpRunning~0 0) (<= 1 |timeShift_isLowWaterLevel_~tmp___0~1#1|) (<= 1 |timeShift_isLowWaterLevel_#res#1|) (= |timeShift_isLowWaterLevel_~tmp~4#1| 0) (<= |old(~waterLevel~0)| (+ ~waterLevel~0 1))) .cse0 (< |old(~waterLevel~0)| 2)))) [2022-07-21 05:01:54,768 INFO L899 garLoopResultBuilder]: For program point L462(lines 462 466) no Hoare annotation was computed. [2022-07-21 05:01:54,768 INFO L899 garLoopResultBuilder]: For program point L462-2(lines 462 466) no Hoare annotation was computed. [2022-07-21 05:01:54,768 INFO L895 garLoopResultBuilder]: At program point L165(lines 160 168) the Hoare annotation is: (let ((.cse0 (not (= 1 ~systemActive~0)))) (and (or (not (= |old(~pumpRunning~0)| 0)) .cse0 (not (<= 1 |old(~waterLevel~0)|))) (or .cse0 (< |old(~waterLevel~0)| 2) (and (= ~pumpRunning~0 |old(~pumpRunning~0)|) (= |timeShift_isLowWaterSensorDry_#res#1| 0) (<= |old(~waterLevel~0)| (+ ~waterLevel~0 1)))))) [2022-07-21 05:01:54,768 INFO L895 garLoopResultBuilder]: At program point L351(line 351) the Hoare annotation is: (let ((.cse0 (not (= 1 ~systemActive~0)))) (and (or (not (= |old(~pumpRunning~0)| 0)) .cse0 (not (<= 1 |old(~waterLevel~0)|))) (or .cse0 (< |old(~waterLevel~0)| 2)))) [2022-07-21 05:01:54,768 INFO L899 garLoopResultBuilder]: For program point L54(line 54) no Hoare annotation was computed. [2022-07-21 05:01:54,769 INFO L895 garLoopResultBuilder]: At program point L356(line 356) the Hoare annotation is: (let ((.cse1 (not (= 1 ~systemActive~0))) (.cse0 (= ~pumpRunning~0 0))) (and (or (not (= |old(~pumpRunning~0)| 0)) (and .cse0 (= |old(~waterLevel~0)| ~waterLevel~0)) .cse1 (not (<= 1 |old(~waterLevel~0)|))) (or .cse1 (< |old(~waterLevel~0)| 2) (and (= ~pumpRunning~0 |old(~pumpRunning~0)|) .cse0)))) [2022-07-21 05:01:54,769 INFO L895 garLoopResultBuilder]: At program point L356-1(lines 337 361) the Hoare annotation is: (let ((.cse1 (not (= 1 ~systemActive~0))) (.cse0 (not (= |old(~pumpRunning~0)| 0))) (.cse2 (= ~pumpRunning~0 0))) (and (or .cse0 (not (= |old(~waterLevel~0)| 1)) .cse1 (and .cse2 (= ~waterLevel~0 1))) (or .cse1 (< |old(~waterLevel~0)| 2) (= |old(~waterLevel~0)| ~waterLevel~0) (and (<= 1 |timeShift_processEnvironment_~tmp~2#1|) (= |timeShift_isLowWaterSensorDry_#res#1| 0) .cse0 .cse2 (<= 1 |timeShift_isLowWaterLevel_~tmp___0~1#1|) (<= 1 |timeShift_isLowWaterLevel_#res#1|) (= |timeShift_isLowWaterLevel_~tmp~4#1| 0) (<= |old(~waterLevel~0)| (+ ~waterLevel~0 1)))))) [2022-07-21 05:01:54,769 INFO L899 garLoopResultBuilder]: For program point L290-1(lines 290 296) no Hoare annotation was computed. [2022-07-21 05:01:54,769 INFO L895 garLoopResultBuilder]: At program point L55(lines 50 57) the Hoare annotation is: (let ((.cse0 (not (= 1 ~systemActive~0)))) (and (or (not (= |old(~pumpRunning~0)| 0)) .cse0 (not (<= 1 |old(~waterLevel~0)|))) (or .cse0 (< |old(~waterLevel~0)| 2)))) [2022-07-21 05:01:54,769 INFO L895 garLoopResultBuilder]: At program point L468(lines 453 471) the Hoare annotation is: (let ((.cse0 (not (= 1 ~systemActive~0)))) (and (or (not (= |old(~pumpRunning~0)| 0)) .cse0 (not (<= 1 |old(~waterLevel~0)|))) (or .cse0 (< |old(~waterLevel~0)| 2) (and (= ~pumpRunning~0 |old(~pumpRunning~0)|) (= |timeShift_isLowWaterSensorDry_#res#1| 0) (<= 1 |timeShift_isLowWaterLevel_~tmp___0~1#1|) (<= 1 |timeShift_isLowWaterLevel_#res#1|) (= |timeShift_isLowWaterLevel_~tmp~4#1| 0) (<= |old(~waterLevel~0)| (+ ~waterLevel~0 1)))))) [2022-07-21 05:01:54,769 INFO L895 garLoopResultBuilder]: At program point timeShiftENTRY(lines 279 302) the Hoare annotation is: (let ((.cse1 (not (= 1 ~systemActive~0))) (.cse0 (= |old(~waterLevel~0)| ~waterLevel~0))) (and (or (not (= |old(~pumpRunning~0)| 0)) (and (= ~pumpRunning~0 0) .cse0) .cse1 (not (<= 1 |old(~waterLevel~0)|))) (or .cse1 (< |old(~waterLevel~0)| 2) (and (= ~pumpRunning~0 |old(~pumpRunning~0)|) .cse0)))) [2022-07-21 05:01:54,769 INFO L895 garLoopResultBuilder]: At program point L142(lines 137 145) the Hoare annotation is: (let ((.cse5 (= 1 ~systemActive~0))) (let ((.cse2 (< |old(~waterLevel~0)| 2)) (.cse3 (and (<= 2 ~waterLevel~0) .cse5 (= |old(~waterLevel~0)| ~waterLevel~0) (<= 2 |timeShift_getWaterLevel_#res#1|))) (.cse0 (not (= |old(~pumpRunning~0)| 0))) (.cse1 (not .cse5)) (.cse4 (= ~pumpRunning~0 0))) (and (or .cse0 .cse1 .cse2 .cse3) (or .cse1 .cse2 (and (<= 1 |timeShift_processEnvironment_~tmp~2#1|) (= |timeShift_isLowWaterSensorDry_#res#1| 0) .cse4 (<= 1 |timeShift_isLowWaterLevel_~tmp___0~1#1|) (<= 1 |timeShift_isLowWaterLevel_#res#1|) (= |timeShift_isLowWaterLevel_~tmp~4#1| 0) (<= |old(~waterLevel~0)| (+ ~waterLevel~0 1)) (<= 1 |timeShift_getWaterLevel_#res#1|)) .cse3) (or .cse0 (not (= |old(~waterLevel~0)| 1)) .cse1 (and .cse4 (= ~waterLevel~0 1) (= |timeShift_getWaterLevel_#res#1| 1)))))) [2022-07-21 05:01:54,769 INFO L899 garLoopResultBuilder]: For program point timeShiftEXIT(lines 279 302) no Hoare annotation was computed. [2022-07-21 05:01:54,769 INFO L895 garLoopResultBuilder]: At program point L394(lines 389 397) the Hoare annotation is: (let ((.cse0 (not (= 1 ~systemActive~0)))) (and (or (not (= |old(~pumpRunning~0)| 0)) .cse0 (not (<= 1 |old(~waterLevel~0)|))) (or .cse0 (< |old(~waterLevel~0)| 2)))) [2022-07-21 05:01:54,770 INFO L899 garLoopResultBuilder]: For program point timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION(line 54) no Hoare annotation was computed. [2022-07-21 05:01:54,770 INFO L899 garLoopResultBuilder]: For program point L193(line 193) no Hoare annotation was computed. [2022-07-21 05:01:54,771 INFO L899 garLoopResultBuilder]: For program point cleanupEXIT(lines 172 201) no Hoare annotation was computed. [2022-07-21 05:01:54,771 INFO L902 garLoopResultBuilder]: At program point cleanupENTRY(lines 172 201) the Hoare annotation is: true [2022-07-21 05:01:54,771 INFO L899 garLoopResultBuilder]: For program point L186(lines 186 190) no Hoare annotation was computed. [2022-07-21 05:01:54,771 INFO L902 garLoopResultBuilder]: At program point L186-1(lines 186 190) the Hoare annotation is: true [2022-07-21 05:01:54,771 INFO L899 garLoopResultBuilder]: For program point L183(line 183) no Hoare annotation was computed. [2022-07-21 05:01:54,771 INFO L902 garLoopResultBuilder]: At program point L182-2(lines 182 196) the Hoare annotation is: true [2022-07-21 05:01:54,771 INFO L902 garLoopResultBuilder]: At program point L178(line 178) the Hoare annotation is: true [2022-07-21 05:01:54,772 INFO L899 garLoopResultBuilder]: For program point L178-1(line 178) no Hoare annotation was computed. [2022-07-21 05:01:54,772 INFO L902 garLoopResultBuilder]: At program point L197(lines 172 201) the Hoare annotation is: true [2022-07-21 05:01:54,772 INFO L899 garLoopResultBuilder]: For program point L258-2(lines 258 265) no Hoare annotation was computed. [2022-07-21 05:01:54,772 INFO L895 garLoopResultBuilder]: At program point L568(lines 563 571) the Hoare annotation is: (and (= ~pumpRunning~0 0) (= 1 ~systemActive~0) (= ~waterLevel~0 1)) [2022-07-21 05:01:54,772 INFO L902 garLoopResultBuilder]: At program point L242(lines 235 244) the Hoare annotation is: true [2022-07-21 05:01:54,772 INFO L895 garLoopResultBuilder]: At program point L560(lines 556 562) the Hoare annotation is: (and (= ~pumpRunning~0 0) (= 1 ~systemActive~0) (= ~waterLevel~0 1)) [2022-07-21 05:01:54,772 INFO L902 garLoopResultBuilder]: At program point L267(lines 248 270) the Hoare annotation is: true [2022-07-21 05:01:54,773 INFO L899 garLoopResultBuilder]: For program point L519(lines 519 523) no Hoare annotation was computed. [2022-07-21 05:01:54,773 INFO L895 garLoopResultBuilder]: At program point L519-2(lines 513 524) the Hoare annotation is: (let ((.cse0 (= 1 ~systemActive~0)) (.cse1 (= |ULTIMATE.start_test_~splverifierCounter~0#1| 0))) (or (and (not (< ~waterLevel~0 2)) .cse0 .cse1) (and (= ~pumpRunning~0 0) .cse0 .cse1 (<= 1 ~waterLevel~0)))) [2022-07-21 05:01:54,773 INFO L899 garLoopResultBuilder]: For program point L-1(line -1) no Hoare annotation was computed. [2022-07-21 05:01:54,773 INFO L899 garLoopResultBuilder]: For program point ULTIMATE.startENTRY(line -1) no Hoare annotation was computed. [2022-07-21 05:01:54,773 INFO L899 garLoopResultBuilder]: For program point ULTIMATE.startFINAL(line -1) no Hoare annotation was computed. [2022-07-21 05:01:54,773 INFO L899 garLoopResultBuilder]: For program point L503(lines 503 509) no Hoare annotation was computed. [2022-07-21 05:01:54,773 INFO L899 garLoopResultBuilder]: For program point L503-1(lines 503 509) no Hoare annotation was computed. [2022-07-21 05:01:54,774 INFO L902 garLoopResultBuilder]: At program point L532(lines 473 536) the Hoare annotation is: true [2022-07-21 05:01:54,774 INFO L895 garLoopResultBuilder]: At program point L495(line 495) the Hoare annotation is: (let ((.cse0 (= 1 ~systemActive~0)) (.cse1 (= |ULTIMATE.start_test_~splverifierCounter~0#1| 0))) (or (and (<= 2 ~waterLevel~0) .cse0 .cse1) (and (= ~pumpRunning~0 0) .cse0 .cse1 (<= 1 ~waterLevel~0)))) [2022-07-21 05:01:54,774 INFO L895 garLoopResultBuilder]: At program point L553(lines 549 555) the Hoare annotation is: (and (= ~pumpRunning~0 0) (= 1 ~systemActive~0) (= ~waterLevel~0 1)) [2022-07-21 05:01:54,774 INFO L895 garLoopResultBuilder]: At program point L231(lines 227 233) the Hoare annotation is: (and (= ~pumpRunning~0 0) (= 1 ~systemActive~0) (= ~waterLevel~0 1)) [2022-07-21 05:01:54,774 INFO L899 garLoopResultBuilder]: For program point ULTIMATE.startEXIT(line -1) no Hoare annotation was computed. [2022-07-21 05:01:54,774 INFO L895 garLoopResultBuilder]: At program point L529(lines 482 530) the Hoare annotation is: false [2022-07-21 05:01:54,775 INFO L899 garLoopResultBuilder]: For program point L484(lines 483 528) no Hoare annotation was computed. [2022-07-21 05:01:54,775 INFO L899 garLoopResultBuilder]: For program point L513(lines 513 524) no Hoare annotation was computed. [2022-07-21 05:01:54,775 INFO L895 garLoopResultBuilder]: At program point L505(line 505) the Hoare annotation is: (let ((.cse0 (= 1 ~systemActive~0)) (.cse1 (= |ULTIMATE.start_test_~splverifierCounter~0#1| 0))) (or (and (not (< ~waterLevel~0 2)) .cse0 .cse1) (and (= ~pumpRunning~0 0) .cse0 .cse1 (<= 1 ~waterLevel~0)))) [2022-07-21 05:01:54,775 INFO L895 garLoopResultBuilder]: At program point L526(lines 483 528) the Hoare annotation is: (let ((.cse0 (= 1 ~systemActive~0)) (.cse1 (= |ULTIMATE.start_test_~splverifierCounter~0#1| 0))) (or (and (<= 2 ~waterLevel~0) .cse0 .cse1) (and (= ~pumpRunning~0 0) .cse0 .cse1 (<= 1 ~waterLevel~0)))) [2022-07-21 05:01:54,775 INFO L899 garLoopResultBuilder]: For program point L493(lines 493 499) no Hoare annotation was computed. [2022-07-21 05:01:54,775 INFO L899 garLoopResultBuilder]: For program point L493-1(lines 493 499) no Hoare annotation was computed. [2022-07-21 05:01:54,776 INFO L899 garLoopResultBuilder]: For program point L485(lines 485 489) no Hoare annotation was computed. [2022-07-21 05:01:54,776 INFO L899 garLoopResultBuilder]: For program point L258(lines 258 265) no Hoare annotation was computed. [2022-07-21 05:01:54,776 INFO L895 garLoopResultBuilder]: At program point processEnvironment__wrappee__highWaterSensorENTRY(lines 311 335) the Hoare annotation is: (or (not (= |old(~pumpRunning~0)| 0)) (= ~pumpRunning~0 0) (not (= 1 ~systemActive~0)) (not (<= 1 ~waterLevel~0))) [2022-07-21 05:01:54,776 INFO L895 garLoopResultBuilder]: At program point L155(lines 146 159) the Hoare annotation is: (let ((.cse0 (not (= |old(~pumpRunning~0)| 0))) (.cse2 (not (= 1 ~systemActive~0))) (.cse1 (= ~pumpRunning~0 0))) (and (or .cse0 .cse1 .cse2 (< ~waterLevel~0 2)) (or (not (= ~waterLevel~0 1)) .cse0 .cse2 (and .cse1 (not (= |processEnvironment__wrappee__highWaterSensor_isHighWaterSensorDry_#res#1| 0)))))) [2022-07-21 05:01:54,776 INFO L895 garLoopResultBuilder]: At program point L325(line 325) the Hoare annotation is: (let ((.cse3 (= 1 ~systemActive~0))) (let ((.cse0 (and (= ~pumpRunning~0 |old(~pumpRunning~0)|) (= ~pumpRunning~0 0) .cse3 (= |processEnvironment__wrappee__highWaterSensor_~tmp~1#1| 0))) (.cse1 (not (= |old(~pumpRunning~0)| 0))) (.cse2 (not .cse3))) (and (or (not (= ~waterLevel~0 1)) .cse0 .cse1 .cse2) (or .cse0 .cse1 .cse2 (< ~waterLevel~0 2))))) [2022-07-21 05:01:54,777 INFO L895 garLoopResultBuilder]: At program point L449(lines 434 452) the Hoare annotation is: (let ((.cse0 (not (= |old(~pumpRunning~0)| 0))) (.cse1 (= ~pumpRunning~0 0)) (.cse2 (not (= 1 ~systemActive~0)))) (and (or .cse0 .cse1 .cse2 (< ~waterLevel~0 2)) (or (not (= ~waterLevel~0 1)) .cse0 (and .cse1 (= |processEnvironment__wrappee__highWaterSensor_isHighWaterLevel_#res#1| 0) (= |processEnvironment__wrappee__highWaterSensor_isHighWaterLevel_~tmp___0~0#1| 0) (not (= |processEnvironment__wrappee__highWaterSensor_isHighWaterLevel_~tmp~3#1| 0))) .cse2))) [2022-07-21 05:01:54,777 INFO L899 garLoopResultBuilder]: For program point L319(lines 319 327) no Hoare annotation was computed. [2022-07-21 05:01:54,777 INFO L899 garLoopResultBuilder]: For program point processEnvironment__wrappee__highWaterSensorEXIT(lines 311 335) no Hoare annotation was computed. [2022-07-21 05:01:54,777 INFO L899 garLoopResultBuilder]: For program point L315(lines 315 332) no Hoare annotation was computed. [2022-07-21 05:01:54,777 INFO L899 garLoopResultBuilder]: For program point L443(lines 443 447) no Hoare annotation was computed. [2022-07-21 05:01:54,777 INFO L899 garLoopResultBuilder]: For program point L443-2(lines 443 447) no Hoare annotation was computed. [2022-07-21 05:01:54,778 INFO L899 garLoopResultBuilder]: For program point L150(lines 150 156) no Hoare annotation was computed. [2022-07-21 05:01:54,778 INFO L895 garLoopResultBuilder]: At program point L367(lines 362 369) the Hoare annotation is: (or (not (= ~waterLevel~0 1)) (not (= |old(~pumpRunning~0)| 0)) (not (= 1 ~systemActive~0))) [2022-07-21 05:01:54,778 INFO L895 garLoopResultBuilder]: At program point L330(line 330) the Hoare annotation is: (or (not (= |old(~pumpRunning~0)| 0)) (not (= 1 ~systemActive~0)) (not (<= 1 ~waterLevel~0))) [2022-07-21 05:01:54,778 INFO L899 garLoopResultBuilder]: For program point L330-1(lines 311 335) no Hoare annotation was computed. [2022-07-21 05:01:54,780 INFO L899 garLoopResultBuilder]: For program point waterRiseEXIT(lines 81 92) no Hoare annotation was computed. [2022-07-21 05:01:54,781 INFO L899 garLoopResultBuilder]: For program point L85-1(lines 81 92) no Hoare annotation was computed. [2022-07-21 05:01:54,781 INFO L895 garLoopResultBuilder]: At program point waterRiseENTRY(lines 81 92) the Hoare annotation is: (let ((.cse0 (not (= 1 ~systemActive~0))) (.cse1 (= |old(~waterLevel~0)| ~waterLevel~0))) (and (or (not (= ~pumpRunning~0 0)) .cse0 (not (<= 1 |old(~waterLevel~0)|)) .cse1) (or .cse0 .cse1 (not (<= 2 |old(~waterLevel~0)|))))) [2022-07-21 05:01:54,784 INFO L356 BasicCegarLoop]: Path program histogram: [1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-07-21 05:01:54,786 INFO L176 ceAbstractionStarter]: Computing trace abstraction results [2022-07-21 05:01:54,825 INFO L202 PluginConnector]: Adding new model de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction CFG 21.07 05:01:54 BoogieIcfgContainer [2022-07-21 05:01:54,825 INFO L132 PluginConnector]: ------------------------ END TraceAbstraction---------------------------- [2022-07-21 05:01:54,826 INFO L113 PluginConnector]: ------------------------Witness Printer---------------------------- [2022-07-21 05:01:54,826 INFO L271 PluginConnector]: Initializing Witness Printer... [2022-07-21 05:01:54,826 INFO L275 PluginConnector]: Witness Printer initialized [2022-07-21 05:01:54,826 INFO L185 PluginConnector]: Executing the observer RCFGCatcher from plugin Witness Printer for "de.uni_freiburg.informatik.ultimate.plugins.generator.rcfgbuilder CFG 21.07 05:01:45" (3/4) ... [2022-07-21 05:01:54,832 INFO L137 WitnessPrinter]: Generating witness for correct program [2022-07-21 05:01:54,838 INFO L354 RCFGBacktranslator]: Ignoring RootEdge to procedure processEnvironment__wrappee__base [2022-07-21 05:01:54,838 INFO L354 RCFGBacktranslator]: Ignoring RootEdge to procedure changeMethaneLevel [2022-07-21 05:01:54,839 INFO L354 RCFGBacktranslator]: Ignoring RootEdge to procedure timeShift [2022-07-21 05:01:54,839 INFO L354 RCFGBacktranslator]: Ignoring RootEdge to procedure cleanup [2022-07-21 05:01:54,839 INFO L354 RCFGBacktranslator]: Ignoring RootEdge to procedure processEnvironment__wrappee__highWaterSensor [2022-07-21 05:01:54,839 INFO L354 RCFGBacktranslator]: Ignoring RootEdge to procedure waterRise [2022-07-21 05:01:54,851 INFO L910 BoogieBacktranslator]: Reduced CFG by removing 53 nodes and edges [2022-07-21 05:01:54,851 INFO L910 BoogieBacktranslator]: Reduced CFG by removing 22 nodes and edges [2022-07-21 05:01:54,852 INFO L910 BoogieBacktranslator]: Reduced CFG by removing 11 nodes and edges [2022-07-21 05:01:54,852 INFO L910 BoogieBacktranslator]: Reduced CFG by removing 5 nodes and edges [2022-07-21 05:01:54,854 INFO L910 BoogieBacktranslator]: Reduced CFG by removing 2 nodes and edges [2022-07-21 05:01:54,854 INFO L910 BoogieBacktranslator]: Reduced CFG by removing 1 nodes and edges [2022-07-21 05:01:54,855 INFO L910 BoogieBacktranslator]: Reduced CFG by removing 1 nodes and edges [2022-07-21 05:01:54,879 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: ((!(\old(pumpRunning) == 0) || !(1 == systemActive)) || !(1 <= \old(waterLevel))) && ((!(1 == systemActive) || \old(waterLevel) < 2) || (pumpRunning == \old(pumpRunning) && \old(waterLevel) <= waterLevel + 1)) [2022-07-21 05:01:54,880 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (((!(\old(pumpRunning) == 0) || !(\old(waterLevel) == 1)) || !(1 == systemActive)) || (pumpRunning == 0 && waterLevel == 1)) && (((!(1 == systemActive) || \old(waterLevel) < 2) || \old(waterLevel) == waterLevel) || (((((((1 <= tmp && \result == 0) && !(\old(pumpRunning) == 0)) && pumpRunning == 0) && 1 <= tmp___0) && 1 <= \result) && tmp == 0) && \old(waterLevel) <= waterLevel + 1)) [2022-07-21 05:01:54,882 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: ((((!(\old(pumpRunning) == 0) || !(1 == systemActive)) || \old(waterLevel) < 2) || (((2 <= waterLevel && 1 == systemActive) && \old(waterLevel) == waterLevel) && 2 <= \result)) && (((!(1 == systemActive) || \old(waterLevel) < 2) || (((((((1 <= tmp && \result == 0) && pumpRunning == 0) && 1 <= tmp___0) && 1 <= \result) && tmp == 0) && \old(waterLevel) <= waterLevel + 1) && 1 <= \result)) || (((2 <= waterLevel && 1 == systemActive) && \old(waterLevel) == waterLevel) && 2 <= \result))) && (((!(\old(pumpRunning) == 0) || !(\old(waterLevel) == 1)) || !(1 == systemActive)) || ((pumpRunning == 0 && waterLevel == 1) && \result == 1)) [2022-07-21 05:01:54,882 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (((((!(\old(pumpRunning) == 0) || ((((2 <= waterLevel && 1 == systemActive) && 2 <= tmp) && \old(waterLevel) == waterLevel) && 2 <= \result)) || !(1 == systemActive)) || !(1 <= \old(waterLevel))) || ((pumpRunning == 0 && \old(waterLevel) < 2) && \old(waterLevel) == waterLevel)) && (((!(\old(pumpRunning) == 0) || !(\old(waterLevel) == 1)) || !(1 == systemActive)) || (tmp == 1 && \result == 1))) && (((((((2 <= waterLevel && 1 == systemActive) && 2 <= tmp) && \old(waterLevel) == waterLevel) && 2 <= \result) || !(1 == systemActive)) || \old(waterLevel) < 2) || ((((((((1 <= tmp && \result == 0) && pumpRunning == 0) && 1 <= tmp___0) && 1 <= \result) && tmp == 0) && 1 <= tmp) && \old(waterLevel) <= waterLevel + 1) && 1 <= \result)) [2022-07-21 05:01:54,882 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: ((!(\old(pumpRunning) == 0) || !(1 == systemActive)) || !(1 <= \old(waterLevel))) && ((!(1 == systemActive) || \old(waterLevel) < 2) || ((pumpRunning == \old(pumpRunning) && \result == 0) && \old(waterLevel) <= waterLevel + 1)) [2022-07-21 05:01:54,883 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (((!(\old(pumpRunning) == 0) || pumpRunning == 0) || !(1 == systemActive)) || waterLevel < 2) && (((!(waterLevel == 1) || !(\old(pumpRunning) == 0)) || !(1 == systemActive)) || (pumpRunning == 0 && !(\result == 0))) [2022-07-21 05:01:54,883 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: ((!(\old(pumpRunning) == 0) || !(1 == systemActive)) || !(1 <= \old(waterLevel))) && (!(1 == systemActive) || \old(waterLevel) < 2) [2022-07-21 05:01:54,883 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: ((!(\old(pumpRunning) == 0) || !(1 == systemActive)) || !(1 <= \old(waterLevel))) && ((!(1 == systemActive) || \old(waterLevel) < 2) || (((((pumpRunning == \old(pumpRunning) && \result == 0) && 1 <= tmp___0) && 1 <= \result) && tmp == 0) && \old(waterLevel) <= waterLevel + 1)) [2022-07-21 05:01:54,883 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (((!(\old(pumpRunning) == 0) || pumpRunning == 0) || !(1 == systemActive)) || waterLevel < 2) && (((!(waterLevel == 1) || !(\old(pumpRunning) == 0)) || (((pumpRunning == 0 && \result == 0) && tmp___0 == 0) && !(tmp == 0))) || !(1 == systemActive)) [2022-07-21 05:01:54,883 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: ((!(\old(pumpRunning) == 0) || !(1 == systemActive)) || !(1 <= \old(waterLevel))) && (!(1 == systemActive) || \old(waterLevel) < 2) [2022-07-21 05:01:54,884 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: ((!(\old(pumpRunning) == 0) || !(1 == systemActive)) || !(1 <= \old(waterLevel))) && ((((((((1 <= tmp && \result == 0) && pumpRunning == 0) && 1 <= tmp___0) && 1 <= \result) && tmp == 0) && \old(waterLevel) <= waterLevel + 1) || !(1 == systemActive)) || \old(waterLevel) < 2) [2022-07-21 05:01:54,884 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (!(waterLevel == 1) || !(\old(pumpRunning) == 0)) || !(1 == systemActive) [2022-07-21 05:01:54,915 INFO L141 WitnessManager]: Wrote witness to /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/witness.graphml [2022-07-21 05:01:54,915 INFO L132 PluginConnector]: ------------------------ END Witness Printer---------------------------- [2022-07-21 05:01:54,916 INFO L158 Benchmark]: Toolchain (without parser) took 10177.64ms. Allocated memory was 54.5MB in the beginning and 146.8MB in the end (delta: 92.3MB). Free memory was 34.6MB in the beginning and 88.1MB in the end (delta: -53.5MB). Peak memory consumption was 39.2MB. Max. memory is 16.1GB. [2022-07-21 05:01:54,916 INFO L158 Benchmark]: CDTParser took 0.33ms. Allocated memory is still 44.0MB. Free memory was 26.2MB in the beginning and 26.2MB in the end (delta: 50.2kB). There was no memory consumed. Max. memory is 16.1GB. [2022-07-21 05:01:54,917 INFO L158 Benchmark]: CACSL2BoogieTranslator took 475.55ms. Allocated memory is still 54.5MB. Free memory was 34.3MB in the beginning and 30.3MB in the end (delta: 4.0MB). Peak memory consumption was 9.2MB. Max. memory is 16.1GB. [2022-07-21 05:01:54,917 INFO L158 Benchmark]: Boogie Procedure Inliner took 65.85ms. Allocated memory is still 54.5MB. Free memory was 30.3MB in the beginning and 27.8MB in the end (delta: 2.5MB). Peak memory consumption was 2.1MB. Max. memory is 16.1GB. [2022-07-21 05:01:54,917 INFO L158 Benchmark]: Boogie Preprocessor took 48.26ms. Allocated memory is still 54.5MB. Free memory was 27.8MB in the beginning and 38.1MB in the end (delta: -10.2MB). Peak memory consumption was 5.1MB. Max. memory is 16.1GB. [2022-07-21 05:01:54,918 INFO L158 Benchmark]: RCFGBuilder took 497.75ms. Allocated memory was 54.5MB in the beginning and 67.1MB in the end (delta: 12.6MB). Free memory was 37.9MB in the beginning and 45.5MB in the end (delta: -7.6MB). Peak memory consumption was 14.1MB. Max. memory is 16.1GB. [2022-07-21 05:01:54,918 INFO L158 Benchmark]: TraceAbstraction took 8994.65ms. Allocated memory was 67.1MB in the beginning and 146.8MB in the end (delta: 79.7MB). Free memory was 44.9MB in the beginning and 94.4MB in the end (delta: -49.5MB). Peak memory consumption was 69.3MB. Max. memory is 16.1GB. [2022-07-21 05:01:54,919 INFO L158 Benchmark]: Witness Printer took 89.89ms. Allocated memory is still 146.8MB. Free memory was 94.4MB in the beginning and 88.1MB in the end (delta: 6.3MB). Peak memory consumption was 6.3MB. Max. memory is 16.1GB. [2022-07-21 05:01:54,920 INFO L339 ainManager$Toolchain]: ####################### End [Toolchain 1] ####################### --- Results --- * Results from de.uni_freiburg.informatik.ultimate.core: - StatisticsResult: Toolchain Benchmarks Benchmark results are: * CDTParser took 0.33ms. Allocated memory is still 44.0MB. Free memory was 26.2MB in the beginning and 26.2MB in the end (delta: 50.2kB). There was no memory consumed. Max. memory is 16.1GB. * CACSL2BoogieTranslator took 475.55ms. Allocated memory is still 54.5MB. Free memory was 34.3MB in the beginning and 30.3MB in the end (delta: 4.0MB). Peak memory consumption was 9.2MB. Max. memory is 16.1GB. * Boogie Procedure Inliner took 65.85ms. Allocated memory is still 54.5MB. Free memory was 30.3MB in the beginning and 27.8MB in the end (delta: 2.5MB). Peak memory consumption was 2.1MB. Max. memory is 16.1GB. * Boogie Preprocessor took 48.26ms. Allocated memory is still 54.5MB. Free memory was 27.8MB in the beginning and 38.1MB in the end (delta: -10.2MB). Peak memory consumption was 5.1MB. Max. memory is 16.1GB. * RCFGBuilder took 497.75ms. Allocated memory was 54.5MB in the beginning and 67.1MB in the end (delta: 12.6MB). Free memory was 37.9MB in the beginning and 45.5MB in the end (delta: -7.6MB). Peak memory consumption was 14.1MB. Max. memory is 16.1GB. * TraceAbstraction took 8994.65ms. Allocated memory was 67.1MB in the beginning and 146.8MB in the end (delta: 79.7MB). Free memory was 44.9MB in the beginning and 94.4MB in the end (delta: -49.5MB). Peak memory consumption was 69.3MB. Max. memory is 16.1GB. * Witness Printer took 89.89ms. Allocated memory is still 146.8MB. Free memory was 94.4MB in the beginning and 88.1MB in the end (delta: 6.3MB). Peak memory consumption was 6.3MB. Max. memory is 16.1GB. * Results from de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction: - StatisticsResult: ErrorAutomatonStatistics NumberErrorTraces: 0, NumberStatementsAllTraces: 0, NumberRelevantStatements: 0, 0.0s ErrorAutomatonConstructionTimeTotal, 0.0s FaulLocalizationTime, NumberStatementsFirstTrace: -1, TraceLengthAvg: 0, 0.0s ErrorAutomatonConstructionTimeAvg, 0.0s ErrorAutomatonDifferenceTimeAvg, 0.0s ErrorAutomatonDifferenceTimeTotal, NumberOfNoEnhancement: 0, NumberOfFiniteEnhancement: 0, NumberOfInfiniteEnhancement: 0 - PositiveResult [Line: 54]: call to reach_error is unreachable For all program executions holds that call to reach_error is unreachable at this location - StatisticsResult: Ultimate Automizer benchmark data CFG has 7 procedures, 82 locations, 1 error locations. Started 1 CEGAR loops. OverallTime: 8.9s, OverallIterations: 12, TraceHistogramMax: 3, PathProgramHistogramMax: 1, EmptinessCheckTime: 0.0s, AutomataDifference: 3.8s, DeadEndRemovalTime: 0.0s, HoareAnnotationTime: 1.8s, InitialAbstractionConstructionTime: 0.0s, HoareTripleCheckerStatistics: 0 mSolverCounterUnknown, 1866 SdHoareTripleChecker+Valid, 2.0s IncrementalHoareTripleChecker+Time, 0 mSdLazyCounter, 1839 mSDsluCounter, 5184 SdHoareTripleChecker+Invalid, 1.6s Time, 0 mProtectedAction, 0 SdHoareTripleChecker+Unchecked, 0 IncrementalHoareTripleChecker+Unchecked, 3848 mSDsCounter, 463 IncrementalHoareTripleChecker+Valid, 0 mProtectedPredicate, 3202 IncrementalHoareTripleChecker+Invalid, 3665 SdHoareTripleChecker+Unknown, 0 mSolverCounterNotChecked, 463 mSolverCounterUnsat, 1336 mSDtfsCounter, 3202 mSolverCounterSat, 0.1s SdHoareTripleChecker+Time, 0 IncrementalHoareTripleChecker+Unknown, PredicateUnifierStatistics: 0 DeclaredPredicates, 688 GetRequests, 532 SyntacticMatches, 7 SemanticMatches, 149 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 1009 ImplicationChecksByTransitivity, 1.6s Time, 0.0s BasicInterpolantAutomatonTime, BiggestAbstraction: size=525occurred in iteration=11, InterpolantAutomatonStates: 138, traceCheckStatistics: No data available, InterpolantConsolidationStatistics: No data available, PathInvariantsStatistics: No data available, 0/0 InterpolantCoveringCapability, TotalInterpolationStatistics: No data available, 0.0s DumpTime, AutomataMinimizationStatistics: 0.2s AutomataMinimizationTime, 12 MinimizatonAttempts, 208 StatesRemovedByMinimization, 8 NontrivialMinimizations, HoareAnnotationStatistics: 0.0s HoareAnnotationTime, 38 LocationsWithAnnotation, 977 PreInvPairs, 1057 NumberOfFragments, 915 HoareAnnotationTreeSize, 977 FomulaSimplifications, 614 FormulaSimplificationTreeSizeReduction, 0.2s HoareSimplificationTime, 38 FomulaSimplificationsInter, 4889 FormulaSimplificationTreeSizeReductionInter, 1.5s HoareSimplificationTimeInter, RefinementEngineStatistics: TRACE_CHECK: 0.1s SsaConstructionTime, 0.4s SatisfiabilityAnalysisTime, 1.5s InterpolantComputationTime, 857 NumberOfCodeBlocks, 857 NumberOfCodeBlocksAsserted, 15 NumberOfCheckSat, 1012 ConstructedInterpolants, 0 QuantifiedInterpolants, 1978 SizeOfPredicates, 10 NumberOfNonLiveVariables, 1401 ConjunctsInSsa, 24 ConjunctsInUnsatCore, 17 InterpolantComputations, 10 PerfectInterpolantSequences, 344/382 InterpolantCoveringCapability, INVARIANT_SYNTHESIS: No data available, INTERPOLANT_CONSOLIDATION: No data available, ABSTRACT_INTERPRETATION: No data available, PDR: No data available, ACCELERATED_INTERPOLATION: No data available, SIFA: No data available, ReuseStatistics: No data available - AllSpecificationsHoldResult: All specifications hold 1 specifications checked. All of them hold - InvariantResult [Line: 337]: Loop Invariant Derived loop invariant: (((!(\old(pumpRunning) == 0) || !(\old(waterLevel) == 1)) || !(1 == systemActive)) || (pumpRunning == 0 && waterLevel == 1)) && (((!(1 == systemActive) || \old(waterLevel) < 2) || \old(waterLevel) == waterLevel) || (((((((1 <= tmp && \result == 0) && !(\old(pumpRunning) == 0)) && pumpRunning == 0) && 1 <= tmp___0) && 1 <= \result) && tmp == 0) && \old(waterLevel) <= waterLevel + 1)) - InvariantResult [Line: 453]: Loop Invariant Derived loop invariant: ((!(\old(pumpRunning) == 0) || !(1 == systemActive)) || !(1 <= \old(waterLevel))) && ((!(1 == systemActive) || \old(waterLevel) < 2) || (((((pumpRunning == \old(pumpRunning) && \result == 0) && 1 <= tmp___0) && 1 <= \result) && tmp == 0) && \old(waterLevel) <= waterLevel + 1)) - InvariantResult [Line: 556]: Loop Invariant Derived loop invariant: (pumpRunning == 0 && 1 == systemActive) && waterLevel == 1 - InvariantResult [Line: 362]: Loop Invariant Derived loop invariant: (!(waterLevel == 1) || !(\old(pumpRunning) == 0)) || !(1 == systemActive) - InvariantResult [Line: 482]: Loop Invariant Derived loop invariant: 0 - InvariantResult [Line: 172]: Loop Invariant Derived loop invariant: 1 - InvariantResult [Line: 182]: Loop Invariant Derived loop invariant: 1 - InvariantResult [Line: 473]: Loop Invariant Derived loop invariant: 1 - InvariantResult [Line: 137]: Loop Invariant Derived loop invariant: ((((!(\old(pumpRunning) == 0) || !(1 == systemActive)) || \old(waterLevel) < 2) || (((2 <= waterLevel && 1 == systemActive) && \old(waterLevel) == waterLevel) && 2 <= \result)) && (((!(1 == systemActive) || \old(waterLevel) < 2) || (((((((1 <= tmp && \result == 0) && pumpRunning == 0) && 1 <= tmp___0) && 1 <= \result) && tmp == 0) && \old(waterLevel) <= waterLevel + 1) && 1 <= \result)) || (((2 <= waterLevel && 1 == systemActive) && \old(waterLevel) == waterLevel) && 2 <= \result))) && (((!(\old(pumpRunning) == 0) || !(\old(waterLevel) == 1)) || !(1 == systemActive)) || ((pumpRunning == 0 && waterLevel == 1) && \result == 1)) - InvariantResult [Line: 248]: Loop Invariant Derived loop invariant: 1 - InvariantResult [Line: 549]: Loop Invariant Derived loop invariant: (pumpRunning == 0 && 1 == systemActive) && waterLevel == 1 - InvariantResult [Line: 69]: Loop Invariant Derived loop invariant: ((!(\old(pumpRunning) == 0) || !(1 == systemActive)) || !(1 <= \old(waterLevel))) && ((!(1 == systemActive) || \old(waterLevel) < 2) || (pumpRunning == \old(pumpRunning) && \old(waterLevel) <= waterLevel + 1)) - InvariantResult [Line: 389]: Loop Invariant Derived loop invariant: ((!(\old(pumpRunning) == 0) || !(1 == systemActive)) || !(1 <= \old(waterLevel))) && (!(1 == systemActive) || \old(waterLevel) < 2) - InvariantResult [Line: 434]: Loop Invariant Derived loop invariant: (((!(\old(pumpRunning) == 0) || pumpRunning == 0) || !(1 == systemActive)) || waterLevel < 2) && (((!(waterLevel == 1) || !(\old(pumpRunning) == 0)) || (((pumpRunning == 0 && \result == 0) && tmp___0 == 0) && !(tmp == 0))) || !(1 == systemActive)) - InvariantResult [Line: 483]: Loop Invariant Derived loop invariant: ((2 <= waterLevel && 1 == systemActive) && splverifierCounter == 0) || (((pumpRunning == 0 && 1 == systemActive) && splverifierCounter == 0) && 1 <= waterLevel) - InvariantResult [Line: 227]: Loop Invariant Derived loop invariant: (pumpRunning == 0 && 1 == systemActive) && waterLevel == 1 - InvariantResult [Line: 160]: Loop Invariant Derived loop invariant: ((!(\old(pumpRunning) == 0) || !(1 == systemActive)) || !(1 <= \old(waterLevel))) && ((!(1 == systemActive) || \old(waterLevel) < 2) || ((pumpRunning == \old(pumpRunning) && \result == 0) && \old(waterLevel) <= waterLevel + 1)) - InvariantResult [Line: 50]: Loop Invariant Derived loop invariant: ((!(\old(pumpRunning) == 0) || !(1 == systemActive)) || !(1 <= \old(waterLevel))) && (!(1 == systemActive) || \old(waterLevel) < 2) - InvariantResult [Line: 235]: Loop Invariant Derived loop invariant: 1 - InvariantResult [Line: 573]: Loop Invariant Derived loop invariant: (((((!(\old(pumpRunning) == 0) || ((((2 <= waterLevel && 1 == systemActive) && 2 <= tmp) && \old(waterLevel) == waterLevel) && 2 <= \result)) || !(1 == systemActive)) || !(1 <= \old(waterLevel))) || ((pumpRunning == 0 && \old(waterLevel) < 2) && \old(waterLevel) == waterLevel)) && (((!(\old(pumpRunning) == 0) || !(\old(waterLevel) == 1)) || !(1 == systemActive)) || (tmp == 1 && \result == 1))) && (((((((2 <= waterLevel && 1 == systemActive) && 2 <= tmp) && \old(waterLevel) == waterLevel) && 2 <= \result) || !(1 == systemActive)) || \old(waterLevel) < 2) || ((((((((1 <= tmp && \result == 0) && pumpRunning == 0) && 1 <= tmp___0) && 1 <= \result) && tmp == 0) && 1 <= tmp) && \old(waterLevel) <= waterLevel + 1) && 1 <= \result)) - InvariantResult [Line: 563]: Loop Invariant Derived loop invariant: (pumpRunning == 0 && 1 == systemActive) && waterLevel == 1 - InvariantResult [Line: 370]: Loop Invariant Derived loop invariant: ((!(\old(pumpRunning) == 0) || !(1 == systemActive)) || !(1 <= \old(waterLevel))) && ((((((((1 <= tmp && \result == 0) && pumpRunning == 0) && 1 <= tmp___0) && 1 <= \result) && tmp == 0) && \old(waterLevel) <= waterLevel + 1) || !(1 == systemActive)) || \old(waterLevel) < 2) - InvariantResult [Line: 146]: Loop Invariant Derived loop invariant: (((!(\old(pumpRunning) == 0) || pumpRunning == 0) || !(1 == systemActive)) || waterLevel < 2) && (((!(waterLevel == 1) || !(\old(pumpRunning) == 0)) || !(1 == systemActive)) || (pumpRunning == 0 && !(\result == 0))) RESULT: Ultimate proved your program to be correct! [2022-07-21 05:01:54,973 INFO L540 MonitoredProcess]: [MP /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in -t:2000 (1)] Forceful destruction successful, exit code 0 Received shutdown request... --- End real Ultimate output --- Execution finished normally Writing output log to file Ultimate.log Result: TRUE