./Ultimate.py --spec ../sv-benchmarks/c/properties/unreach-call.prp --file ../sv-benchmarks/c/product-lines/minepump_spec4_product52.cil.c --full-output --architecture 32bit -------------------------------------------------------------------------------- Checking for ERROR reachability Using default analysis Version 35987657 Calling Ultimate with: /usr/bin/java -Dosgi.configuration.area=/storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/data/config -Xmx15G -Xms4m -jar /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/plugins/org.eclipse.equinox.launcher_1.5.800.v20200727-1323.jar -data @noDefault -ultimatedata /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/data -tc /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/config/AutomizerReach.xml -i ../sv-benchmarks/c/product-lines/minepump_spec4_product52.cil.c -s /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/config/svcomp-Reach-32bit-Automizer_Default.epf --cacsl2boogietranslator.entry.function main --witnessprinter.witness.directory /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux --witnessprinter.witness.filename witness.graphml --witnessprinter.write.witness.besides.input.file false --witnessprinter.graph.data.specification CHECK( init(main()), LTL(G ! call(reach_error())) ) --witnessprinter.graph.data.producer Automizer --witnessprinter.graph.data.architecture 32bit --witnessprinter.graph.data.programhash e4fc698cb41b54b4c4983dda7de32b2f9c78701d9e96fbbf9a36472a5bdbde25 --- Real Ultimate output --- This is Ultimate 0.2.2-?-3598765 [2022-07-21 05:01:45,603 INFO L177 SettingsManager]: Resetting all preferences to default values... [2022-07-21 05:01:45,604 INFO L181 SettingsManager]: Resetting UltimateCore preferences to default values [2022-07-21 05:01:45,626 INFO L184 SettingsManager]: Ultimate Commandline Interface provides no preferences, ignoring... [2022-07-21 05:01:45,629 INFO L181 SettingsManager]: Resetting Boogie Preprocessor preferences to default values [2022-07-21 05:01:45,630 INFO L181 SettingsManager]: Resetting Boogie Procedure Inliner preferences to default values [2022-07-21 05:01:45,634 INFO L181 SettingsManager]: Resetting Abstract Interpretation preferences to default values [2022-07-21 05:01:45,636 INFO L181 SettingsManager]: Resetting LassoRanker preferences to default values [2022-07-21 05:01:45,639 INFO L181 SettingsManager]: Resetting Reaching Definitions preferences to default values [2022-07-21 05:01:45,640 INFO L181 SettingsManager]: Resetting SyntaxChecker preferences to default values [2022-07-21 05:01:45,641 INFO L181 SettingsManager]: Resetting Sifa preferences to default values [2022-07-21 05:01:45,645 INFO L184 SettingsManager]: Büchi Program Product provides no preferences, ignoring... [2022-07-21 05:01:45,646 INFO L181 SettingsManager]: Resetting LTL2Aut preferences to default values [2022-07-21 05:01:45,648 INFO L181 SettingsManager]: Resetting PEA to Boogie preferences to default values [2022-07-21 05:01:45,649 INFO L181 SettingsManager]: Resetting BlockEncodingV2 preferences to default values [2022-07-21 05:01:45,651 INFO L181 SettingsManager]: Resetting ChcToBoogie preferences to default values [2022-07-21 05:01:45,652 INFO L181 SettingsManager]: Resetting AutomataScriptInterpreter preferences to default values [2022-07-21 05:01:45,656 INFO L181 SettingsManager]: Resetting BuchiAutomizer preferences to default values [2022-07-21 05:01:45,657 INFO L181 SettingsManager]: Resetting CACSL2BoogieTranslator preferences to default values [2022-07-21 05:01:45,658 INFO L181 SettingsManager]: Resetting CodeCheck preferences to default values [2022-07-21 05:01:45,663 INFO L181 SettingsManager]: Resetting HornVerifier preferences to default values [2022-07-21 05:01:45,675 INFO L181 SettingsManager]: Resetting InvariantSynthesis preferences to default values [2022-07-21 05:01:45,676 INFO L181 SettingsManager]: Resetting RCFGBuilder preferences to default values [2022-07-21 05:01:45,678 INFO L181 SettingsManager]: Resetting Referee preferences to default values [2022-07-21 05:01:45,678 INFO L181 SettingsManager]: Resetting TraceAbstraction preferences to default values [2022-07-21 05:01:45,681 INFO L184 SettingsManager]: TraceAbstractionConcurrent provides no preferences, ignoring... [2022-07-21 05:01:45,683 INFO L184 SettingsManager]: TraceAbstractionWithAFAs provides no preferences, ignoring... [2022-07-21 05:01:45,683 INFO L181 SettingsManager]: Resetting TreeAutomizer preferences to default values [2022-07-21 05:01:45,684 INFO L181 SettingsManager]: Resetting IcfgToChc preferences to default values [2022-07-21 05:01:45,684 INFO L181 SettingsManager]: Resetting IcfgTransformer preferences to default values [2022-07-21 05:01:45,685 INFO L184 SettingsManager]: ReqToTest provides no preferences, ignoring... [2022-07-21 05:01:45,685 INFO L181 SettingsManager]: Resetting Boogie Printer preferences to default values [2022-07-21 05:01:45,686 INFO L181 SettingsManager]: Resetting ChcSmtPrinter preferences to default values [2022-07-21 05:01:45,687 INFO L181 SettingsManager]: Resetting ReqPrinter preferences to default values [2022-07-21 05:01:45,688 INFO L181 SettingsManager]: Resetting Witness Printer preferences to default values [2022-07-21 05:01:45,688 INFO L184 SettingsManager]: Boogie PL CUP Parser provides no preferences, ignoring... [2022-07-21 05:01:45,689 INFO L181 SettingsManager]: Resetting CDTParser preferences to default values [2022-07-21 05:01:45,689 INFO L184 SettingsManager]: AutomataScriptParser provides no preferences, ignoring... [2022-07-21 05:01:45,689 INFO L184 SettingsManager]: ReqParser provides no preferences, ignoring... [2022-07-21 05:01:45,689 INFO L181 SettingsManager]: Resetting SmtParser preferences to default values [2022-07-21 05:01:45,690 INFO L181 SettingsManager]: Resetting Witness Parser preferences to default values [2022-07-21 05:01:45,691 INFO L188 SettingsManager]: Finished resetting all preferences to default values... [2022-07-21 05:01:45,694 INFO L101 SettingsManager]: Beginning loading settings from /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/config/svcomp-Reach-32bit-Automizer_Default.epf [2022-07-21 05:01:45,732 INFO L113 SettingsManager]: Loading preferences was successful [2022-07-21 05:01:45,733 INFO L115 SettingsManager]: Preferences different from defaults after loading the file: [2022-07-21 05:01:45,733 INFO L136 SettingsManager]: Preferences of UltimateCore differ from their defaults: [2022-07-21 05:01:45,733 INFO L138 SettingsManager]: * Log level for class=de.uni_freiburg.informatik.ultimate.lib.smtlibutils.quantifier.QuantifierPusher=ERROR; [2022-07-21 05:01:45,733 INFO L136 SettingsManager]: Preferences of Boogie Procedure Inliner differ from their defaults: [2022-07-21 05:01:45,734 INFO L138 SettingsManager]: * Ignore calls to procedures called more than once=ONLY_FOR_SEQUENTIAL_PROGRAMS [2022-07-21 05:01:45,735 INFO L136 SettingsManager]: Preferences of BlockEncodingV2 differ from their defaults: [2022-07-21 05:01:45,735 INFO L138 SettingsManager]: * Create parallel compositions if possible=false [2022-07-21 05:01:45,735 INFO L138 SettingsManager]: * Use SBE=true [2022-07-21 05:01:45,736 INFO L136 SettingsManager]: Preferences of CACSL2BoogieTranslator differ from their defaults: [2022-07-21 05:01:45,736 INFO L138 SettingsManager]: * sizeof long=4 [2022-07-21 05:01:45,736 INFO L138 SettingsManager]: * Overapproximate operations on floating types=true [2022-07-21 05:01:45,736 INFO L138 SettingsManager]: * sizeof POINTER=4 [2022-07-21 05:01:45,736 INFO L138 SettingsManager]: * Check division by zero=IGNORE [2022-07-21 05:01:45,736 INFO L138 SettingsManager]: * Pointer to allocated memory at dereference=IGNORE [2022-07-21 05:01:45,737 INFO L138 SettingsManager]: * If two pointers are subtracted or compared they have the same base address=IGNORE [2022-07-21 05:01:45,737 INFO L138 SettingsManager]: * Check array bounds for arrays that are off heap=IGNORE [2022-07-21 05:01:45,737 INFO L138 SettingsManager]: * sizeof long double=12 [2022-07-21 05:01:45,737 INFO L138 SettingsManager]: * Check if freed pointer was valid=false [2022-07-21 05:01:45,737 INFO L138 SettingsManager]: * Use constant arrays=true [2022-07-21 05:01:45,737 INFO L138 SettingsManager]: * Pointer base address is valid at dereference=IGNORE [2022-07-21 05:01:45,737 INFO L136 SettingsManager]: Preferences of RCFGBuilder differ from their defaults: [2022-07-21 05:01:45,738 INFO L138 SettingsManager]: * Size of a code block=SequenceOfStatements [2022-07-21 05:01:45,738 INFO L138 SettingsManager]: * SMT solver=External_DefaultMode [2022-07-21 05:01:45,738 INFO L138 SettingsManager]: * Command for external solver=z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in -t:2000 [2022-07-21 05:01:45,738 INFO L136 SettingsManager]: Preferences of TraceAbstraction differ from their defaults: [2022-07-21 05:01:45,738 INFO L138 SettingsManager]: * Compute Interpolants along a Counterexample=FPandBP [2022-07-21 05:01:45,738 INFO L138 SettingsManager]: * Positions where we compute the Hoare Annotation=LoopsAndPotentialCycles [2022-07-21 05:01:45,739 INFO L138 SettingsManager]: * Trace refinement strategy=CAMEL [2022-07-21 05:01:45,739 INFO L138 SettingsManager]: * Command for external solver=z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in [2022-07-21 05:01:45,739 INFO L138 SettingsManager]: * Apply one-shot large block encoding in concurrent analysis=false [2022-07-21 05:01:45,739 INFO L138 SettingsManager]: * Automaton type used in concurrency analysis=PETRI_NET [2022-07-21 05:01:45,739 INFO L138 SettingsManager]: * Compute Hoare Annotation of negated interpolant automaton, abstraction and CFG=true [2022-07-21 05:01:45,739 INFO L138 SettingsManager]: * SMT solver=External_ModelsAndUnsatCoreMode WARNING: An illegal reflective access operation has occurred WARNING: Illegal reflective access by com.sun.xml.bind.v2.runtime.reflect.opt.Injector$1 (file:/storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/plugins/com.sun.xml.bind_2.2.0.v201505121915.jar) to method java.lang.ClassLoader.defineClass(java.lang.String,byte[],int,int) WARNING: Please consider reporting this to the maintainers of com.sun.xml.bind.v2.runtime.reflect.opt.Injector$1 WARNING: Use --illegal-access=warn to enable warnings of further illegal reflective access operations WARNING: All illegal access operations will be denied in a future release Applying setting for plugin de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator: Entry function -> main Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Witness directory -> /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Witness filename -> witness.graphml Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Write witness besides input file -> false Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Graph data specification -> CHECK( init(main()), LTL(G ! call(reach_error())) ) Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Graph data producer -> Automizer Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Graph data architecture -> 32bit Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Graph data programhash -> e4fc698cb41b54b4c4983dda7de32b2f9c78701d9e96fbbf9a36472a5bdbde25 [2022-07-21 05:01:45,995 INFO L75 nceAwareModelManager]: Repository-Root is: /tmp [2022-07-21 05:01:46,010 INFO L261 ainManager$Toolchain]: [Toolchain 1]: Applicable parser(s) successfully (re)initialized [2022-07-21 05:01:46,012 INFO L217 ainManager$Toolchain]: [Toolchain 1]: Toolchain selected. [2022-07-21 05:01:46,013 INFO L271 PluginConnector]: Initializing CDTParser... [2022-07-21 05:01:46,014 INFO L275 PluginConnector]: CDTParser initialized [2022-07-21 05:01:46,015 INFO L432 ainManager$Toolchain]: [Toolchain 1]: Parsing single file: /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/../sv-benchmarks/c/product-lines/minepump_spec4_product52.cil.c [2022-07-21 05:01:46,059 INFO L220 CDTParser]: Created temporary CDT project at /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/data/630ce215f/b982c571e2814659854234251bca912a/FLAGd21e2163d [2022-07-21 05:01:46,448 INFO L306 CDTParser]: Found 1 translation units. [2022-07-21 05:01:46,448 INFO L160 CDTParser]: Scanning /storage/repos/ultimate/releaseScripts/default/sv-benchmarks/c/product-lines/minepump_spec4_product52.cil.c [2022-07-21 05:01:46,460 INFO L349 CDTParser]: About to delete temporary CDT project at /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/data/630ce215f/b982c571e2814659854234251bca912a/FLAGd21e2163d [2022-07-21 05:01:46,866 INFO L357 CDTParser]: Successfully deleted /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/data/630ce215f/b982c571e2814659854234251bca912a [2022-07-21 05:01:46,868 INFO L299 ainManager$Toolchain]: ####################### [Toolchain 1] ####################### [2022-07-21 05:01:46,869 INFO L131 ToolchainWalker]: Walking toolchain with 6 elements. [2022-07-21 05:01:46,871 INFO L113 PluginConnector]: ------------------------CACSL2BoogieTranslator---------------------------- [2022-07-21 05:01:46,871 INFO L271 PluginConnector]: Initializing CACSL2BoogieTranslator... [2022-07-21 05:01:46,874 INFO L275 PluginConnector]: CACSL2BoogieTranslator initialized [2022-07-21 05:01:46,874 INFO L185 PluginConnector]: Executing the observer ACSLObjectContainerObserver from plugin CACSL2BoogieTranslator for "CDTParser AST 21.07 05:01:46" (1/1) ... [2022-07-21 05:01:46,875 INFO L205 PluginConnector]: Invalid model from CACSL2BoogieTranslator for observer de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator.ACSLObjectContainerObserver@45fd31b5 and model type de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 21.07 05:01:46, skipping insertion in model container [2022-07-21 05:01:46,875 INFO L185 PluginConnector]: Executing the observer CACSL2BoogieTranslatorObserver from plugin CACSL2BoogieTranslator for "CDTParser AST 21.07 05:01:46" (1/1) ... [2022-07-21 05:01:46,885 INFO L145 MainTranslator]: Starting translation in SV-COMP mode [2022-07-21 05:01:46,908 INFO L178 MainTranslator]: Built tables and reachable declarations [2022-07-21 05:01:47,109 WARN L230 ndardFunctionHandler]: Function reach_error is already implemented but we override the implementation for the call at /storage/repos/ultimate/releaseScripts/default/sv-benchmarks/c/product-lines/minepump_spec4_product52.cil.c[18431,18444] [2022-07-21 05:01:47,112 INFO L210 PostProcessor]: Analyzing one entry point: main [2022-07-21 05:01:47,117 INFO L203 MainTranslator]: Completed pre-run [2022-07-21 05:01:47,162 WARN L230 ndardFunctionHandler]: Function reach_error is already implemented but we override the implementation for the call at /storage/repos/ultimate/releaseScripts/default/sv-benchmarks/c/product-lines/minepump_spec4_product52.cil.c[18431,18444] [2022-07-21 05:01:47,163 INFO L210 PostProcessor]: Analyzing one entry point: main [2022-07-21 05:01:47,184 INFO L208 MainTranslator]: Completed translation [2022-07-21 05:01:47,184 INFO L202 PluginConnector]: Adding new model de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 21.07 05:01:47 WrapperNode [2022-07-21 05:01:47,185 INFO L132 PluginConnector]: ------------------------ END CACSL2BoogieTranslator---------------------------- [2022-07-21 05:01:47,185 INFO L113 PluginConnector]: ------------------------Boogie Procedure Inliner---------------------------- [2022-07-21 05:01:47,186 INFO L271 PluginConnector]: Initializing Boogie Procedure Inliner... [2022-07-21 05:01:47,186 INFO L275 PluginConnector]: Boogie Procedure Inliner initialized [2022-07-21 05:01:47,191 INFO L185 PluginConnector]: Executing the observer TypeChecker from plugin Boogie Procedure Inliner for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 21.07 05:01:47" (1/1) ... [2022-07-21 05:01:47,212 INFO L185 PluginConnector]: Executing the observer Inliner from plugin Boogie Procedure Inliner for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 21.07 05:01:47" (1/1) ... [2022-07-21 05:01:47,248 INFO L137 Inliner]: procedures = 57, calls = 157, calls flagged for inlining = 25, calls inlined = 21, statements flattened = 263 [2022-07-21 05:01:47,249 INFO L132 PluginConnector]: ------------------------ END Boogie Procedure Inliner---------------------------- [2022-07-21 05:01:47,251 INFO L113 PluginConnector]: ------------------------Boogie Preprocessor---------------------------- [2022-07-21 05:01:47,252 INFO L271 PluginConnector]: Initializing Boogie Preprocessor... [2022-07-21 05:01:47,252 INFO L275 PluginConnector]: Boogie Preprocessor initialized [2022-07-21 05:01:47,257 INFO L185 PluginConnector]: Executing the observer EnsureBoogieModelObserver from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 21.07 05:01:47" (1/1) ... [2022-07-21 05:01:47,258 INFO L185 PluginConnector]: Executing the observer TypeChecker from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 21.07 05:01:47" (1/1) ... [2022-07-21 05:01:47,269 INFO L185 PluginConnector]: Executing the observer ConstExpander from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 21.07 05:01:47" (1/1) ... [2022-07-21 05:01:47,275 INFO L185 PluginConnector]: Executing the observer StructExpander from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 21.07 05:01:47" (1/1) ... [2022-07-21 05:01:47,280 INFO L185 PluginConnector]: Executing the observer UnstructureCode from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 21.07 05:01:47" (1/1) ... [2022-07-21 05:01:47,284 INFO L185 PluginConnector]: Executing the observer FunctionInliner from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 21.07 05:01:47" (1/1) ... [2022-07-21 05:01:47,286 INFO L185 PluginConnector]: Executing the observer BoogieSymbolTableConstructor from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 21.07 05:01:47" (1/1) ... [2022-07-21 05:01:47,288 INFO L132 PluginConnector]: ------------------------ END Boogie Preprocessor---------------------------- [2022-07-21 05:01:47,289 INFO L113 PluginConnector]: ------------------------RCFGBuilder---------------------------- [2022-07-21 05:01:47,289 INFO L271 PluginConnector]: Initializing RCFGBuilder... [2022-07-21 05:01:47,289 INFO L275 PluginConnector]: RCFGBuilder initialized [2022-07-21 05:01:47,290 INFO L185 PluginConnector]: Executing the observer RCFGBuilderObserver from plugin RCFGBuilder for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 21.07 05:01:47" (1/1) ... [2022-07-21 05:01:47,307 INFO L173 SolverBuilder]: Constructing external solver with command: z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in -t:2000 [2022-07-21 05:01:47,316 INFO L189 MonitoredProcess]: No working directory specified, using /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 [2022-07-21 05:01:47,325 INFO L229 MonitoredProcess]: Starting monitored process 1 with /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in -t:2000 (exit command is (exit), workingDir is null) [2022-07-21 05:01:47,330 INFO L327 MonitoredProcess]: [MP /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in -t:2000 (1)] Waiting until timeout for monitored process [2022-07-21 05:01:47,362 INFO L130 BoogieDeclarations]: Found specification of procedure #Ultimate.allocInit [2022-07-21 05:01:47,363 INFO L130 BoogieDeclarations]: Found specification of procedure processEnvironment__wrappee__base [2022-07-21 05:01:47,363 INFO L138 BoogieDeclarations]: Found implementation of procedure processEnvironment__wrappee__base [2022-07-21 05:01:47,363 INFO L130 BoogieDeclarations]: Found specification of procedure cleanup [2022-07-21 05:01:47,363 INFO L138 BoogieDeclarations]: Found implementation of procedure cleanup [2022-07-21 05:01:47,363 INFO L130 BoogieDeclarations]: Found specification of procedure timeShift [2022-07-21 05:01:47,363 INFO L138 BoogieDeclarations]: Found implementation of procedure timeShift [2022-07-21 05:01:47,363 INFO L130 BoogieDeclarations]: Found specification of procedure processEnvironment__wrappee__highWaterSensor [2022-07-21 05:01:47,364 INFO L138 BoogieDeclarations]: Found implementation of procedure processEnvironment__wrappee__highWaterSensor [2022-07-21 05:01:47,364 INFO L130 BoogieDeclarations]: Found specification of procedure waterRise [2022-07-21 05:01:47,364 INFO L138 BoogieDeclarations]: Found implementation of procedure waterRise [2022-07-21 05:01:47,364 INFO L130 BoogieDeclarations]: Found specification of procedure deactivatePump [2022-07-21 05:01:47,364 INFO L138 BoogieDeclarations]: Found implementation of procedure deactivatePump [2022-07-21 05:01:47,365 INFO L130 BoogieDeclarations]: Found specification of procedure write~init~int [2022-07-21 05:01:47,365 INFO L130 BoogieDeclarations]: Found specification of procedure changeMethaneLevel [2022-07-21 05:01:47,365 INFO L138 BoogieDeclarations]: Found implementation of procedure changeMethaneLevel [2022-07-21 05:01:47,365 INFO L130 BoogieDeclarations]: Found specification of procedure ULTIMATE.start [2022-07-21 05:01:47,365 INFO L138 BoogieDeclarations]: Found implementation of procedure ULTIMATE.start [2022-07-21 05:01:47,447 INFO L234 CfgBuilder]: Building ICFG [2022-07-21 05:01:47,448 INFO L260 CfgBuilder]: Building CFG for each procedure with an implementation [2022-07-21 05:01:47,712 INFO L275 CfgBuilder]: Performing block encoding [2022-07-21 05:01:47,719 INFO L294 CfgBuilder]: Using the 1 location(s) as analysis (start of procedure ULTIMATE.start) [2022-07-21 05:01:47,720 INFO L299 CfgBuilder]: Removed 2 assume(true) statements. [2022-07-21 05:01:47,722 INFO L202 PluginConnector]: Adding new model de.uni_freiburg.informatik.ultimate.plugins.generator.rcfgbuilder CFG 21.07 05:01:47 BoogieIcfgContainer [2022-07-21 05:01:47,722 INFO L132 PluginConnector]: ------------------------ END RCFGBuilder---------------------------- [2022-07-21 05:01:47,723 INFO L113 PluginConnector]: ------------------------TraceAbstraction---------------------------- [2022-07-21 05:01:47,724 INFO L271 PluginConnector]: Initializing TraceAbstraction... [2022-07-21 05:01:47,726 INFO L275 PluginConnector]: TraceAbstraction initialized [2022-07-21 05:01:47,726 INFO L185 PluginConnector]: Executing the observer TraceAbstractionObserver from plugin TraceAbstraction for "CDTParser AST 21.07 05:01:46" (1/3) ... [2022-07-21 05:01:47,726 INFO L205 PluginConnector]: Invalid model from TraceAbstraction for observer de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction.TraceAbstractionObserver@7f6cb165 and model type de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction AST 21.07 05:01:47, skipping insertion in model container [2022-07-21 05:01:47,727 INFO L185 PluginConnector]: Executing the observer TraceAbstractionObserver from plugin TraceAbstraction for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 21.07 05:01:47" (2/3) ... [2022-07-21 05:01:47,727 INFO L205 PluginConnector]: Invalid model from TraceAbstraction for observer de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction.TraceAbstractionObserver@7f6cb165 and model type de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction AST 21.07 05:01:47, skipping insertion in model container [2022-07-21 05:01:47,727 INFO L185 PluginConnector]: Executing the observer TraceAbstractionObserver from plugin TraceAbstraction for "de.uni_freiburg.informatik.ultimate.plugins.generator.rcfgbuilder CFG 21.07 05:01:47" (3/3) ... [2022-07-21 05:01:47,728 INFO L111 eAbstractionObserver]: Analyzing ICFG minepump_spec4_product52.cil.c [2022-07-21 05:01:47,738 INFO L201 ceAbstractionStarter]: Automizer settings: Hoare:true NWA Interpolation:FPandBP Determinization: PREDICATE_ABSTRACTION [2022-07-21 05:01:47,738 INFO L160 ceAbstractionStarter]: Applying trace abstraction to program that has 1 error locations. [2022-07-21 05:01:47,786 INFO L356 AbstractCegarLoop]: ======== Iteration 0 == of CEGAR loop == AllErrorsAtOnce ======== [2022-07-21 05:01:47,793 INFO L357 AbstractCegarLoop]: Settings: SEPARATE_VIOLATION_CHECK=true, mInterprocedural=true, mMaxIterations=1000000, mWatchIteration=1000000, mArtifact=RCFG, mInterpolation=FPandBP, mInterpolantAutomaton=STRAIGHT_LINE, mDumpAutomata=false, mAutomataFormat=ATS_NUMERATE, mDumpPath=., mDeterminiation=PREDICATE_ABSTRACTION, mMinimize=MINIMIZE_SEVPA, mHoare=true, mAutomataTypeConcurrency=PETRI_NET, mHoareTripleChecks=INCREMENTAL, mHoareAnnotationPositions=LoopsAndPotentialCycles, mDumpOnlyReuseAutomata=false, mLimitTraceHistogram=0, mErrorLocTimeLimit=0, mLimitPathProgramCount=0, mCollectInterpolantStatistics=true, mHeuristicEmptinessCheck=false, mHeuristicEmptinessCheckAStarHeuristic=ZERO, mHeuristicEmptinessCheckAStarHeuristicRandomSeed=1337, mHeuristicEmptinessCheckSmtFeatureScoringMethod=DAGSIZE, mSMTFeatureExtraction=false, mSMTFeatureExtractionDumpPath=., mOverrideInterpolantAutomaton=false, mMcrInterpolantMethod=WP, mPorIndependenceSettings=de.uni_freiburg.informatik.ultimate.lib.tracecheckerutils.partialorder.independence.IndependenceSettings@3ca19bad, mLbeIndependenceSettings=de.uni_freiburg.informatik.ultimate.lib.tracecheckerutils.partialorder.independence.IndependenceSettings@7737317b [2022-07-21 05:01:47,793 INFO L358 AbstractCegarLoop]: Starting to check reachability of 1 error locations. [2022-07-21 05:01:47,796 INFO L276 IsEmpty]: Start isEmpty. Operand has 90 states, 69 states have (on average 1.391304347826087) internal successors, (96), 78 states have internal predecessors, (96), 12 states have call successors, (12), 7 states have call predecessors, (12), 7 states have return successors, (12), 9 states have call predecessors, (12), 12 states have call successors, (12) [2022-07-21 05:01:47,802 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 20 [2022-07-21 05:01:47,802 INFO L187 NwaCegarLoop]: Found error trace [2022-07-21 05:01:47,803 INFO L195 NwaCegarLoop]: trace histogram [1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-07-21 05:01:47,803 INFO L420 AbstractCegarLoop]: === Iteration 1 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2022-07-21 05:01:47,806 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2022-07-21 05:01:47,807 INFO L85 PathProgramCache]: Analyzing trace with hash 355859289, now seen corresponding path program 1 times [2022-07-21 05:01:47,814 INFO L118 FreeRefinementEngine]: Executing refinement strategy CAMEL [2022-07-21 05:01:47,814 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [1578471852] [2022-07-21 05:01:47,814 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-07-21 05:01:47,815 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2022-07-21 05:01:47,925 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-07-21 05:01:47,991 INFO L134 CoverageAnalysis]: Checked inductivity of 0 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2022-07-21 05:01:47,991 INFO L136 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2022-07-21 05:01:47,991 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [1578471852] [2022-07-21 05:01:47,992 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [1578471852] provided 1 perfect and 0 imperfect interpolant sequences [2022-07-21 05:01:47,992 INFO L184 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2022-07-21 05:01:47,992 INFO L197 FreeRefinementEngine]: Number of different interpolants: perfect sequences [2] imperfect sequences [] total 2 [2022-07-21 05:01:47,993 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [2014910974] [2022-07-21 05:01:47,994 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2022-07-21 05:01:47,996 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 2 states [2022-07-21 05:01:47,996 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2022-07-21 05:01:48,019 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 2 interpolants. [2022-07-21 05:01:48,020 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=1, Invalid=1, Unknown=0, NotChecked=0, Total=2 [2022-07-21 05:01:48,022 INFO L87 Difference]: Start difference. First operand has 90 states, 69 states have (on average 1.391304347826087) internal successors, (96), 78 states have internal predecessors, (96), 12 states have call successors, (12), 7 states have call predecessors, (12), 7 states have return successors, (12), 9 states have call predecessors, (12), 12 states have call successors, (12) Second operand has 2 states, 2 states have (on average 8.5) internal successors, (17), 2 states have internal predecessors, (17), 1 states have call successors, (2), 1 states have call predecessors, (2), 0 states have return successors, (0), 0 states have call predecessors, (0), 0 states have call successors, (0) [2022-07-21 05:01:48,060 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-07-21 05:01:48,060 INFO L93 Difference]: Finished difference Result 172 states and 235 transitions. [2022-07-21 05:01:48,061 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 2 states. [2022-07-21 05:01:48,062 INFO L78 Accepts]: Start accepts. Automaton has has 2 states, 2 states have (on average 8.5) internal successors, (17), 2 states have internal predecessors, (17), 1 states have call successors, (2), 1 states have call predecessors, (2), 0 states have return successors, (0), 0 states have call predecessors, (0), 0 states have call successors, (0) Word has length 19 [2022-07-21 05:01:48,062 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2022-07-21 05:01:48,069 INFO L225 Difference]: With dead ends: 172 [2022-07-21 05:01:48,069 INFO L226 Difference]: Without dead ends: 81 [2022-07-21 05:01:48,072 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 2 GetRequests, 2 SyntacticMatches, 0 SemanticMatches, 0 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 0 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=1, Invalid=1, Unknown=0, NotChecked=0, Total=2 [2022-07-21 05:01:48,075 INFO L413 NwaCegarLoop]: 114 mSDtfsCounter, 0 mSDsluCounter, 0 mSDsCounter, 0 mSdLazyCounter, 0 mSolverCounterSat, 0 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.0s Time, 0 mProtectedPredicate, 0 mProtectedAction, 0 SdHoareTripleChecker+Valid, 114 SdHoareTripleChecker+Invalid, 0 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 0 IncrementalHoareTripleChecker+Valid, 0 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.0s IncrementalHoareTripleChecker+Time [2022-07-21 05:01:48,076 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [0 Valid, 114 Invalid, 0 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [0 Valid, 0 Invalid, 0 Unknown, 0 Unchecked, 0.0s Time] [2022-07-21 05:01:48,087 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 81 states. [2022-07-21 05:01:48,119 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 81 to 81. [2022-07-21 05:01:48,121 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 81 states, 62 states have (on average 1.3225806451612903) internal successors, (82), 70 states have internal predecessors, (82), 12 states have call successors, (12), 7 states have call predecessors, (12), 6 states have return successors, (11), 8 states have call predecessors, (11), 11 states have call successors, (11) [2022-07-21 05:01:48,127 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 81 states to 81 states and 105 transitions. [2022-07-21 05:01:48,128 INFO L78 Accepts]: Start accepts. Automaton has 81 states and 105 transitions. Word has length 19 [2022-07-21 05:01:48,128 INFO L84 Accepts]: Finished accepts. word is rejected. [2022-07-21 05:01:48,128 INFO L495 AbstractCegarLoop]: Abstraction has 81 states and 105 transitions. [2022-07-21 05:01:48,129 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 2 states, 2 states have (on average 8.5) internal successors, (17), 2 states have internal predecessors, (17), 1 states have call successors, (2), 1 states have call predecessors, (2), 0 states have return successors, (0), 0 states have call predecessors, (0), 0 states have call successors, (0) [2022-07-21 05:01:48,129 INFO L276 IsEmpty]: Start isEmpty. Operand 81 states and 105 transitions. [2022-07-21 05:01:48,132 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 21 [2022-07-21 05:01:48,132 INFO L187 NwaCegarLoop]: Found error trace [2022-07-21 05:01:48,132 INFO L195 NwaCegarLoop]: trace histogram [1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-07-21 05:01:48,133 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable0 [2022-07-21 05:01:48,133 INFO L420 AbstractCegarLoop]: === Iteration 2 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2022-07-21 05:01:48,134 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2022-07-21 05:01:48,134 INFO L85 PathProgramCache]: Analyzing trace with hash -730097680, now seen corresponding path program 1 times [2022-07-21 05:01:48,134 INFO L118 FreeRefinementEngine]: Executing refinement strategy CAMEL [2022-07-21 05:01:48,134 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [89943756] [2022-07-21 05:01:48,134 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-07-21 05:01:48,135 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2022-07-21 05:01:48,162 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-07-21 05:01:48,216 INFO L134 CoverageAnalysis]: Checked inductivity of 0 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2022-07-21 05:01:48,216 INFO L136 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2022-07-21 05:01:48,217 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [89943756] [2022-07-21 05:01:48,217 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [89943756] provided 1 perfect and 0 imperfect interpolant sequences [2022-07-21 05:01:48,217 INFO L184 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2022-07-21 05:01:48,217 INFO L197 FreeRefinementEngine]: Number of different interpolants: perfect sequences [3] imperfect sequences [] total 3 [2022-07-21 05:01:48,218 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [1721562100] [2022-07-21 05:01:48,218 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2022-07-21 05:01:48,221 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 3 states [2022-07-21 05:01:48,222 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2022-07-21 05:01:48,223 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 3 interpolants. [2022-07-21 05:01:48,223 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=3, Invalid=3, Unknown=0, NotChecked=0, Total=6 [2022-07-21 05:01:48,223 INFO L87 Difference]: Start difference. First operand 81 states and 105 transitions. Second operand has 3 states, 3 states have (on average 6.0) internal successors, (18), 3 states have internal predecessors, (18), 1 states have call successors, (2), 1 states have call predecessors, (2), 0 states have return successors, (0), 0 states have call predecessors, (0), 0 states have call successors, (0) [2022-07-21 05:01:48,240 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-07-21 05:01:48,243 INFO L93 Difference]: Finished difference Result 123 states and 159 transitions. [2022-07-21 05:01:48,244 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 3 states. [2022-07-21 05:01:48,245 INFO L78 Accepts]: Start accepts. Automaton has has 3 states, 3 states have (on average 6.0) internal successors, (18), 3 states have internal predecessors, (18), 1 states have call successors, (2), 1 states have call predecessors, (2), 0 states have return successors, (0), 0 states have call predecessors, (0), 0 states have call successors, (0) Word has length 20 [2022-07-21 05:01:48,245 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2022-07-21 05:01:48,246 INFO L225 Difference]: With dead ends: 123 [2022-07-21 05:01:48,247 INFO L226 Difference]: Without dead ends: 72 [2022-07-21 05:01:48,249 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 3 GetRequests, 2 SyntacticMatches, 0 SemanticMatches, 1 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 0 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=3, Invalid=3, Unknown=0, NotChecked=0, Total=6 [2022-07-21 05:01:48,250 INFO L413 NwaCegarLoop]: 92 mSDtfsCounter, 17 mSDsluCounter, 70 mSDsCounter, 0 mSdLazyCounter, 1 mSolverCounterSat, 0 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.0s Time, 0 mProtectedPredicate, 0 mProtectedAction, 21 SdHoareTripleChecker+Valid, 162 SdHoareTripleChecker+Invalid, 1 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 0 IncrementalHoareTripleChecker+Valid, 1 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.0s IncrementalHoareTripleChecker+Time [2022-07-21 05:01:48,251 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [21 Valid, 162 Invalid, 1 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [0 Valid, 1 Invalid, 0 Unknown, 0 Unchecked, 0.0s Time] [2022-07-21 05:01:48,253 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 72 states. [2022-07-21 05:01:48,259 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 72 to 72. [2022-07-21 05:01:48,261 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 72 states, 56 states have (on average 1.3392857142857142) internal successors, (75), 64 states have internal predecessors, (75), 9 states have call successors, (9), 6 states have call predecessors, (9), 6 states have return successors, (9), 6 states have call predecessors, (9), 9 states have call successors, (9) [2022-07-21 05:01:48,263 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 72 states to 72 states and 93 transitions. [2022-07-21 05:01:48,264 INFO L78 Accepts]: Start accepts. Automaton has 72 states and 93 transitions. Word has length 20 [2022-07-21 05:01:48,264 INFO L84 Accepts]: Finished accepts. word is rejected. [2022-07-21 05:01:48,264 INFO L495 AbstractCegarLoop]: Abstraction has 72 states and 93 transitions. [2022-07-21 05:01:48,267 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 3 states, 3 states have (on average 6.0) internal successors, (18), 3 states have internal predecessors, (18), 1 states have call successors, (2), 1 states have call predecessors, (2), 0 states have return successors, (0), 0 states have call predecessors, (0), 0 states have call successors, (0) [2022-07-21 05:01:48,267 INFO L276 IsEmpty]: Start isEmpty. Operand 72 states and 93 transitions. [2022-07-21 05:01:48,268 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 26 [2022-07-21 05:01:48,268 INFO L187 NwaCegarLoop]: Found error trace [2022-07-21 05:01:48,268 INFO L195 NwaCegarLoop]: trace histogram [1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-07-21 05:01:48,268 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable1 [2022-07-21 05:01:48,269 INFO L420 AbstractCegarLoop]: === Iteration 3 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2022-07-21 05:01:48,272 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2022-07-21 05:01:48,275 INFO L85 PathProgramCache]: Analyzing trace with hash -1878665188, now seen corresponding path program 1 times [2022-07-21 05:01:48,275 INFO L118 FreeRefinementEngine]: Executing refinement strategy CAMEL [2022-07-21 05:01:48,275 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [790614943] [2022-07-21 05:01:48,275 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-07-21 05:01:48,275 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2022-07-21 05:01:48,314 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-07-21 05:01:48,382 INFO L134 CoverageAnalysis]: Checked inductivity of 0 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2022-07-21 05:01:48,383 INFO L136 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2022-07-21 05:01:48,383 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [790614943] [2022-07-21 05:01:48,383 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [790614943] provided 1 perfect and 0 imperfect interpolant sequences [2022-07-21 05:01:48,384 INFO L184 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2022-07-21 05:01:48,384 INFO L197 FreeRefinementEngine]: Number of different interpolants: perfect sequences [5] imperfect sequences [] total 5 [2022-07-21 05:01:48,384 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [1876181503] [2022-07-21 05:01:48,384 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2022-07-21 05:01:48,385 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 6 states [2022-07-21 05:01:48,385 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2022-07-21 05:01:48,385 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 6 interpolants. [2022-07-21 05:01:48,386 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=10, Invalid=20, Unknown=0, NotChecked=0, Total=30 [2022-07-21 05:01:48,386 INFO L87 Difference]: Start difference. First operand 72 states and 93 transitions. Second operand has 6 states, 6 states have (on average 4.0) internal successors, (24), 5 states have internal predecessors, (24), 1 states have call successors, (1), 1 states have call predecessors, (1), 0 states have return successors, (0), 0 states have call predecessors, (0), 0 states have call successors, (0) [2022-07-21 05:01:48,562 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-07-21 05:01:48,562 INFO L93 Difference]: Finished difference Result 254 states and 341 transitions. [2022-07-21 05:01:48,562 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 6 states. [2022-07-21 05:01:48,562 INFO L78 Accepts]: Start accepts. Automaton has has 6 states, 6 states have (on average 4.0) internal successors, (24), 5 states have internal predecessors, (24), 1 states have call successors, (1), 1 states have call predecessors, (1), 0 states have return successors, (0), 0 states have call predecessors, (0), 0 states have call successors, (0) Word has length 25 [2022-07-21 05:01:48,563 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2022-07-21 05:01:48,566 INFO L225 Difference]: With dead ends: 254 [2022-07-21 05:01:48,566 INFO L226 Difference]: Without dead ends: 189 [2022-07-21 05:01:48,568 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 7 GetRequests, 1 SyntacticMatches, 0 SemanticMatches, 6 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 0 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=22, Invalid=34, Unknown=0, NotChecked=0, Total=56 [2022-07-21 05:01:48,572 INFO L413 NwaCegarLoop]: 114 mSDtfsCounter, 212 mSDsluCounter, 368 mSDsCounter, 0 mSdLazyCounter, 103 mSolverCounterSat, 18 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.1s Time, 0 mProtectedPredicate, 0 mProtectedAction, 212 SdHoareTripleChecker+Valid, 482 SdHoareTripleChecker+Invalid, 121 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 18 IncrementalHoareTripleChecker+Valid, 103 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.1s IncrementalHoareTripleChecker+Time [2022-07-21 05:01:48,573 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [212 Valid, 482 Invalid, 121 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [18 Valid, 103 Invalid, 0 Unknown, 0 Unchecked, 0.1s Time] [2022-07-21 05:01:48,574 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 189 states. [2022-07-21 05:01:48,601 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 189 to 167. [2022-07-21 05:01:48,601 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 167 states, 128 states have (on average 1.375) internal successors, (176), 146 states have internal predecessors, (176), 22 states have call successors, (22), 16 states have call predecessors, (22), 16 states have return successors, (23), 14 states have call predecessors, (23), 22 states have call successors, (23) [2022-07-21 05:01:48,602 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 167 states to 167 states and 221 transitions. [2022-07-21 05:01:48,602 INFO L78 Accepts]: Start accepts. Automaton has 167 states and 221 transitions. Word has length 25 [2022-07-21 05:01:48,603 INFO L84 Accepts]: Finished accepts. word is rejected. [2022-07-21 05:01:48,603 INFO L495 AbstractCegarLoop]: Abstraction has 167 states and 221 transitions. [2022-07-21 05:01:48,603 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 6 states, 6 states have (on average 4.0) internal successors, (24), 5 states have internal predecessors, (24), 1 states have call successors, (1), 1 states have call predecessors, (1), 0 states have return successors, (0), 0 states have call predecessors, (0), 0 states have call successors, (0) [2022-07-21 05:01:48,603 INFO L276 IsEmpty]: Start isEmpty. Operand 167 states and 221 transitions. [2022-07-21 05:01:48,604 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 29 [2022-07-21 05:01:48,604 INFO L187 NwaCegarLoop]: Found error trace [2022-07-21 05:01:48,604 INFO L195 NwaCegarLoop]: trace histogram [1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-07-21 05:01:48,604 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable2 [2022-07-21 05:01:48,604 INFO L420 AbstractCegarLoop]: === Iteration 4 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2022-07-21 05:01:48,605 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2022-07-21 05:01:48,605 INFO L85 PathProgramCache]: Analyzing trace with hash 1340325107, now seen corresponding path program 1 times [2022-07-21 05:01:48,605 INFO L118 FreeRefinementEngine]: Executing refinement strategy CAMEL [2022-07-21 05:01:48,605 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [1067160325] [2022-07-21 05:01:48,606 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-07-21 05:01:48,606 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2022-07-21 05:01:48,620 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-07-21 05:01:48,665 INFO L134 CoverageAnalysis]: Checked inductivity of 0 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2022-07-21 05:01:48,667 INFO L136 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2022-07-21 05:01:48,667 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [1067160325] [2022-07-21 05:01:48,667 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [1067160325] provided 1 perfect and 0 imperfect interpolant sequences [2022-07-21 05:01:48,667 INFO L184 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2022-07-21 05:01:48,668 INFO L197 FreeRefinementEngine]: Number of different interpolants: perfect sequences [4] imperfect sequences [] total 4 [2022-07-21 05:01:48,669 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [111193616] [2022-07-21 05:01:48,669 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2022-07-21 05:01:48,670 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 5 states [2022-07-21 05:01:48,670 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2022-07-21 05:01:48,671 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 5 interpolants. [2022-07-21 05:01:48,671 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=7, Invalid=13, Unknown=0, NotChecked=0, Total=20 [2022-07-21 05:01:48,671 INFO L87 Difference]: Start difference. First operand 167 states and 221 transitions. Second operand has 5 states, 5 states have (on average 5.4) internal successors, (27), 4 states have internal predecessors, (27), 1 states have call successors, (1), 1 states have call predecessors, (1), 0 states have return successors, (0), 0 states have call predecessors, (0), 0 states have call successors, (0) [2022-07-21 05:01:48,725 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-07-21 05:01:48,725 INFO L93 Difference]: Finished difference Result 470 states and 648 transitions. [2022-07-21 05:01:48,726 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 5 states. [2022-07-21 05:01:48,726 INFO L78 Accepts]: Start accepts. Automaton has has 5 states, 5 states have (on average 5.4) internal successors, (27), 4 states have internal predecessors, (27), 1 states have call successors, (1), 1 states have call predecessors, (1), 0 states have return successors, (0), 0 states have call predecessors, (0), 0 states have call successors, (0) Word has length 28 [2022-07-21 05:01:48,726 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2022-07-21 05:01:48,731 INFO L225 Difference]: With dead ends: 470 [2022-07-21 05:01:48,731 INFO L226 Difference]: Without dead ends: 310 [2022-07-21 05:01:48,732 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 7 GetRequests, 2 SyntacticMatches, 0 SemanticMatches, 5 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 0 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=17, Invalid=25, Unknown=0, NotChecked=0, Total=42 [2022-07-21 05:01:48,734 INFO L413 NwaCegarLoop]: 95 mSDtfsCounter, 64 mSDsluCounter, 270 mSDsCounter, 0 mSdLazyCounter, 29 mSolverCounterSat, 4 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.0s Time, 0 mProtectedPredicate, 0 mProtectedAction, 64 SdHoareTripleChecker+Valid, 365 SdHoareTripleChecker+Invalid, 33 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 4 IncrementalHoareTripleChecker+Valid, 29 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.0s IncrementalHoareTripleChecker+Time [2022-07-21 05:01:48,735 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [64 Valid, 365 Invalid, 33 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [4 Valid, 29 Invalid, 0 Unknown, 0 Unchecked, 0.0s Time] [2022-07-21 05:01:48,736 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 310 states. [2022-07-21 05:01:48,776 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 310 to 310. [2022-07-21 05:01:48,777 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 310 states, 236 states have (on average 1.347457627118644) internal successors, (318), 268 states have internal predecessors, (318), 44 states have call successors, (44), 32 states have call predecessors, (44), 29 states have return successors, (50), 25 states have call predecessors, (50), 44 states have call successors, (50) [2022-07-21 05:01:48,779 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 310 states to 310 states and 412 transitions. [2022-07-21 05:01:48,779 INFO L78 Accepts]: Start accepts. Automaton has 310 states and 412 transitions. Word has length 28 [2022-07-21 05:01:48,780 INFO L84 Accepts]: Finished accepts. word is rejected. [2022-07-21 05:01:48,780 INFO L495 AbstractCegarLoop]: Abstraction has 310 states and 412 transitions. [2022-07-21 05:01:48,780 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 5 states, 5 states have (on average 5.4) internal successors, (27), 4 states have internal predecessors, (27), 1 states have call successors, (1), 1 states have call predecessors, (1), 0 states have return successors, (0), 0 states have call predecessors, (0), 0 states have call successors, (0) [2022-07-21 05:01:48,780 INFO L276 IsEmpty]: Start isEmpty. Operand 310 states and 412 transitions. [2022-07-21 05:01:48,786 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 31 [2022-07-21 05:01:48,786 INFO L187 NwaCegarLoop]: Found error trace [2022-07-21 05:01:48,786 INFO L195 NwaCegarLoop]: trace histogram [1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-07-21 05:01:48,786 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable3 [2022-07-21 05:01:48,786 INFO L420 AbstractCegarLoop]: === Iteration 5 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2022-07-21 05:01:48,787 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2022-07-21 05:01:48,787 INFO L85 PathProgramCache]: Analyzing trace with hash 1413318200, now seen corresponding path program 1 times [2022-07-21 05:01:48,787 INFO L118 FreeRefinementEngine]: Executing refinement strategy CAMEL [2022-07-21 05:01:48,787 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [944839638] [2022-07-21 05:01:48,787 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-07-21 05:01:48,787 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2022-07-21 05:01:48,807 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-07-21 05:01:48,827 INFO L134 CoverageAnalysis]: Checked inductivity of 0 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2022-07-21 05:01:48,827 INFO L136 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2022-07-21 05:01:48,828 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [944839638] [2022-07-21 05:01:48,828 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [944839638] provided 1 perfect and 0 imperfect interpolant sequences [2022-07-21 05:01:48,828 INFO L184 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2022-07-21 05:01:48,828 INFO L197 FreeRefinementEngine]: Number of different interpolants: perfect sequences [2] imperfect sequences [] total 2 [2022-07-21 05:01:48,828 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [852535522] [2022-07-21 05:01:48,828 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2022-07-21 05:01:48,828 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 3 states [2022-07-21 05:01:48,828 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2022-07-21 05:01:48,829 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 3 interpolants. [2022-07-21 05:01:48,829 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=3, Invalid=3, Unknown=0, NotChecked=0, Total=6 [2022-07-21 05:01:48,829 INFO L87 Difference]: Start difference. First operand 310 states and 412 transitions. Second operand has 3 states, 3 states have (on average 9.666666666666666) internal successors, (29), 2 states have internal predecessors, (29), 1 states have call successors, (1), 1 states have call predecessors, (1), 0 states have return successors, (0), 0 states have call predecessors, (0), 0 states have call successors, (0) [2022-07-21 05:01:48,877 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-07-21 05:01:48,878 INFO L93 Difference]: Finished difference Result 718 states and 981 transitions. [2022-07-21 05:01:48,878 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 3 states. [2022-07-21 05:01:48,878 INFO L78 Accepts]: Start accepts. Automaton has has 3 states, 3 states have (on average 9.666666666666666) internal successors, (29), 2 states have internal predecessors, (29), 1 states have call successors, (1), 1 states have call predecessors, (1), 0 states have return successors, (0), 0 states have call predecessors, (0), 0 states have call successors, (0) Word has length 30 [2022-07-21 05:01:48,884 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2022-07-21 05:01:48,887 INFO L225 Difference]: With dead ends: 718 [2022-07-21 05:01:48,887 INFO L226 Difference]: Without dead ends: 415 [2022-07-21 05:01:48,888 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 3 GetRequests, 2 SyntacticMatches, 0 SemanticMatches, 1 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 0 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=3, Invalid=3, Unknown=0, NotChecked=0, Total=6 [2022-07-21 05:01:48,888 INFO L413 NwaCegarLoop]: 96 mSDtfsCounter, 52 mSDsluCounter, 59 mSDsCounter, 0 mSdLazyCounter, 11 mSolverCounterSat, 8 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.0s Time, 0 mProtectedPredicate, 0 mProtectedAction, 52 SdHoareTripleChecker+Valid, 155 SdHoareTripleChecker+Invalid, 19 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 8 IncrementalHoareTripleChecker+Valid, 11 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.0s IncrementalHoareTripleChecker+Time [2022-07-21 05:01:48,889 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [52 Valid, 155 Invalid, 19 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [8 Valid, 11 Invalid, 0 Unknown, 0 Unchecked, 0.0s Time] [2022-07-21 05:01:48,890 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 415 states. [2022-07-21 05:01:48,909 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 415 to 404. [2022-07-21 05:01:48,910 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 404 states, 314 states have (on average 1.2993630573248407) internal successors, (408), 337 states have internal predecessors, (408), 47 states have call successors, (47), 45 states have call predecessors, (47), 42 states have return successors, (69), 41 states have call predecessors, (69), 47 states have call successors, (69) [2022-07-21 05:01:48,912 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 404 states to 404 states and 524 transitions. [2022-07-21 05:01:48,912 INFO L78 Accepts]: Start accepts. Automaton has 404 states and 524 transitions. Word has length 30 [2022-07-21 05:01:48,912 INFO L84 Accepts]: Finished accepts. word is rejected. [2022-07-21 05:01:48,912 INFO L495 AbstractCegarLoop]: Abstraction has 404 states and 524 transitions. [2022-07-21 05:01:48,912 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 3 states, 3 states have (on average 9.666666666666666) internal successors, (29), 2 states have internal predecessors, (29), 1 states have call successors, (1), 1 states have call predecessors, (1), 0 states have return successors, (0), 0 states have call predecessors, (0), 0 states have call successors, (0) [2022-07-21 05:01:48,913 INFO L276 IsEmpty]: Start isEmpty. Operand 404 states and 524 transitions. [2022-07-21 05:01:48,913 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 33 [2022-07-21 05:01:48,913 INFO L187 NwaCegarLoop]: Found error trace [2022-07-21 05:01:48,913 INFO L195 NwaCegarLoop]: trace histogram [1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-07-21 05:01:48,914 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable4 [2022-07-21 05:01:48,914 INFO L420 AbstractCegarLoop]: === Iteration 6 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2022-07-21 05:01:48,914 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2022-07-21 05:01:48,914 INFO L85 PathProgramCache]: Analyzing trace with hash 515112153, now seen corresponding path program 1 times [2022-07-21 05:01:48,914 INFO L118 FreeRefinementEngine]: Executing refinement strategy CAMEL [2022-07-21 05:01:48,914 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [1502903095] [2022-07-21 05:01:48,915 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-07-21 05:01:48,915 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2022-07-21 05:01:48,927 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-07-21 05:01:48,970 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 11 [2022-07-21 05:01:48,972 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-07-21 05:01:48,973 INFO L134 CoverageAnalysis]: Checked inductivity of 0 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2022-07-21 05:01:48,974 INFO L136 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2022-07-21 05:01:48,974 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [1502903095] [2022-07-21 05:01:48,974 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [1502903095] provided 1 perfect and 0 imperfect interpolant sequences [2022-07-21 05:01:48,974 INFO L184 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2022-07-21 05:01:48,974 INFO L197 FreeRefinementEngine]: Number of different interpolants: perfect sequences [6] imperfect sequences [] total 6 [2022-07-21 05:01:48,974 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [1263690087] [2022-07-21 05:01:48,974 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2022-07-21 05:01:48,975 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 6 states [2022-07-21 05:01:48,975 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2022-07-21 05:01:48,975 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 6 interpolants. [2022-07-21 05:01:48,975 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=9, Invalid=21, Unknown=0, NotChecked=0, Total=30 [2022-07-21 05:01:48,976 INFO L87 Difference]: Start difference. First operand 404 states and 524 transitions. Second operand has 6 states, 6 states have (on average 4.833333333333333) internal successors, (29), 5 states have internal predecessors, (29), 1 states have call successors, (2), 2 states have call predecessors, (2), 1 states have return successors, (1), 1 states have call predecessors, (1), 1 states have call successors, (1) [2022-07-21 05:01:49,152 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-07-21 05:01:49,152 INFO L93 Difference]: Finished difference Result 503 states and 655 transitions. [2022-07-21 05:01:49,153 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 11 states. [2022-07-21 05:01:49,153 INFO L78 Accepts]: Start accepts. Automaton has has 6 states, 6 states have (on average 4.833333333333333) internal successors, (29), 5 states have internal predecessors, (29), 1 states have call successors, (2), 2 states have call predecessors, (2), 1 states have return successors, (1), 1 states have call predecessors, (1), 1 states have call successors, (1) Word has length 32 [2022-07-21 05:01:49,153 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2022-07-21 05:01:49,156 INFO L225 Difference]: With dead ends: 503 [2022-07-21 05:01:49,156 INFO L226 Difference]: Without dead ends: 501 [2022-07-21 05:01:49,156 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 14 GetRequests, 4 SyntacticMatches, 0 SemanticMatches, 10 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 12 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=45, Invalid=87, Unknown=0, NotChecked=0, Total=132 [2022-07-21 05:01:49,158 INFO L413 NwaCegarLoop]: 107 mSDtfsCounter, 125 mSDsluCounter, 276 mSDsCounter, 0 mSdLazyCounter, 173 mSolverCounterSat, 33 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.1s Time, 0 mProtectedPredicate, 0 mProtectedAction, 129 SdHoareTripleChecker+Valid, 383 SdHoareTripleChecker+Invalid, 206 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 33 IncrementalHoareTripleChecker+Valid, 173 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.1s IncrementalHoareTripleChecker+Time [2022-07-21 05:01:49,160 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [129 Valid, 383 Invalid, 206 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [33 Valid, 173 Invalid, 0 Unknown, 0 Unchecked, 0.1s Time] [2022-07-21 05:01:49,161 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 501 states. [2022-07-21 05:01:49,195 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 501 to 472. [2022-07-21 05:01:49,196 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 472 states, 367 states have (on average 1.2806539509536785) internal successors, (470), 401 states have internal predecessors, (470), 53 states have call successors, (53), 45 states have call predecessors, (53), 51 states have return successors, (88), 45 states have call predecessors, (88), 53 states have call successors, (88) [2022-07-21 05:01:49,200 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 472 states to 472 states and 611 transitions. [2022-07-21 05:01:49,200 INFO L78 Accepts]: Start accepts. Automaton has 472 states and 611 transitions. Word has length 32 [2022-07-21 05:01:49,201 INFO L84 Accepts]: Finished accepts. word is rejected. [2022-07-21 05:01:49,201 INFO L495 AbstractCegarLoop]: Abstraction has 472 states and 611 transitions. [2022-07-21 05:01:49,201 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 6 states, 6 states have (on average 4.833333333333333) internal successors, (29), 5 states have internal predecessors, (29), 1 states have call successors, (2), 2 states have call predecessors, (2), 1 states have return successors, (1), 1 states have call predecessors, (1), 1 states have call successors, (1) [2022-07-21 05:01:49,202 INFO L276 IsEmpty]: Start isEmpty. Operand 472 states and 611 transitions. [2022-07-21 05:01:49,203 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 44 [2022-07-21 05:01:49,203 INFO L187 NwaCegarLoop]: Found error trace [2022-07-21 05:01:49,203 INFO L195 NwaCegarLoop]: trace histogram [1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-07-21 05:01:49,204 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable5 [2022-07-21 05:01:49,204 INFO L420 AbstractCegarLoop]: === Iteration 7 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2022-07-21 05:01:49,204 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2022-07-21 05:01:49,204 INFO L85 PathProgramCache]: Analyzing trace with hash 585600178, now seen corresponding path program 1 times [2022-07-21 05:01:49,204 INFO L118 FreeRefinementEngine]: Executing refinement strategy CAMEL [2022-07-21 05:01:49,205 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [1909500077] [2022-07-21 05:01:49,205 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-07-21 05:01:49,205 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2022-07-21 05:01:49,224 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-07-21 05:01:49,251 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 11 [2022-07-21 05:01:49,253 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-07-21 05:01:49,257 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 24 [2022-07-21 05:01:49,262 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-07-21 05:01:49,289 INFO L134 CoverageAnalysis]: Checked inductivity of 0 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2022-07-21 05:01:49,290 INFO L136 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2022-07-21 05:01:49,290 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [1909500077] [2022-07-21 05:01:49,290 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [1909500077] provided 1 perfect and 0 imperfect interpolant sequences [2022-07-21 05:01:49,290 INFO L184 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2022-07-21 05:01:49,290 INFO L197 FreeRefinementEngine]: Number of different interpolants: perfect sequences [7] imperfect sequences [] total 7 [2022-07-21 05:01:49,290 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [1167719312] [2022-07-21 05:01:49,291 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2022-07-21 05:01:49,291 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 7 states [2022-07-21 05:01:49,291 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2022-07-21 05:01:49,292 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 7 interpolants. [2022-07-21 05:01:49,292 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=11, Invalid=31, Unknown=0, NotChecked=0, Total=42 [2022-07-21 05:01:49,292 INFO L87 Difference]: Start difference. First operand 472 states and 611 transitions. Second operand has 7 states, 7 states have (on average 5.428571428571429) internal successors, (38), 5 states have internal predecessors, (38), 1 states have call successors, (3), 3 states have call predecessors, (3), 2 states have return successors, (2), 2 states have call predecessors, (2), 1 states have call successors, (2) [2022-07-21 05:01:49,500 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-07-21 05:01:49,500 INFO L93 Difference]: Finished difference Result 1043 states and 1374 transitions. [2022-07-21 05:01:49,500 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 9 states. [2022-07-21 05:01:49,501 INFO L78 Accepts]: Start accepts. Automaton has has 7 states, 7 states have (on average 5.428571428571429) internal successors, (38), 5 states have internal predecessors, (38), 1 states have call successors, (3), 3 states have call predecessors, (3), 2 states have return successors, (2), 2 states have call predecessors, (2), 1 states have call successors, (2) Word has length 43 [2022-07-21 05:01:49,501 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2022-07-21 05:01:49,503 INFO L225 Difference]: With dead ends: 1043 [2022-07-21 05:01:49,503 INFO L226 Difference]: Without dead ends: 578 [2022-07-21 05:01:49,504 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 16 GetRequests, 6 SyntacticMatches, 0 SemanticMatches, 10 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 3 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=46, Invalid=86, Unknown=0, NotChecked=0, Total=132 [2022-07-21 05:01:49,506 INFO L413 NwaCegarLoop]: 91 mSDtfsCounter, 127 mSDsluCounter, 274 mSDsCounter, 0 mSdLazyCounter, 221 mSolverCounterSat, 41 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.1s Time, 0 mProtectedPredicate, 0 mProtectedAction, 127 SdHoareTripleChecker+Valid, 365 SdHoareTripleChecker+Invalid, 262 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 41 IncrementalHoareTripleChecker+Valid, 221 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.1s IncrementalHoareTripleChecker+Time [2022-07-21 05:01:49,506 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [127 Valid, 365 Invalid, 262 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [41 Valid, 221 Invalid, 0 Unknown, 0 Unchecked, 0.1s Time] [2022-07-21 05:01:49,507 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 578 states. [2022-07-21 05:01:49,530 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 578 to 524. [2022-07-21 05:01:49,532 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 524 states, 413 states have (on average 1.2639225181598064) internal successors, (522), 447 states have internal predecessors, (522), 53 states have call successors, (53), 45 states have call predecessors, (53), 57 states have return successors, (96), 49 states have call predecessors, (96), 53 states have call successors, (96) [2022-07-21 05:01:49,534 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 524 states to 524 states and 671 transitions. [2022-07-21 05:01:49,535 INFO L78 Accepts]: Start accepts. Automaton has 524 states and 671 transitions. Word has length 43 [2022-07-21 05:01:49,535 INFO L84 Accepts]: Finished accepts. word is rejected. [2022-07-21 05:01:49,535 INFO L495 AbstractCegarLoop]: Abstraction has 524 states and 671 transitions. [2022-07-21 05:01:49,536 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 7 states, 7 states have (on average 5.428571428571429) internal successors, (38), 5 states have internal predecessors, (38), 1 states have call successors, (3), 3 states have call predecessors, (3), 2 states have return successors, (2), 2 states have call predecessors, (2), 1 states have call successors, (2) [2022-07-21 05:01:49,536 INFO L276 IsEmpty]: Start isEmpty. Operand 524 states and 671 transitions. [2022-07-21 05:01:49,536 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 44 [2022-07-21 05:01:49,537 INFO L187 NwaCegarLoop]: Found error trace [2022-07-21 05:01:49,537 INFO L195 NwaCegarLoop]: trace histogram [1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-07-21 05:01:49,537 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable6 [2022-07-21 05:01:49,537 INFO L420 AbstractCegarLoop]: === Iteration 8 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2022-07-21 05:01:49,537 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2022-07-21 05:01:49,537 INFO L85 PathProgramCache]: Analyzing trace with hash -425517072, now seen corresponding path program 1 times [2022-07-21 05:01:49,538 INFO L118 FreeRefinementEngine]: Executing refinement strategy CAMEL [2022-07-21 05:01:49,538 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [367055716] [2022-07-21 05:01:49,538 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-07-21 05:01:49,538 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2022-07-21 05:01:49,559 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-07-21 05:01:49,577 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 11 [2022-07-21 05:01:49,578 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-07-21 05:01:49,583 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 24 [2022-07-21 05:01:49,585 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-07-21 05:01:49,603 INFO L134 CoverageAnalysis]: Checked inductivity of 0 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2022-07-21 05:01:49,603 INFO L136 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2022-07-21 05:01:49,604 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [367055716] [2022-07-21 05:01:49,604 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [367055716] provided 1 perfect and 0 imperfect interpolant sequences [2022-07-21 05:01:49,604 INFO L184 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2022-07-21 05:01:49,604 INFO L197 FreeRefinementEngine]: Number of different interpolants: perfect sequences [8] imperfect sequences [] total 8 [2022-07-21 05:01:49,604 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [1228984037] [2022-07-21 05:01:49,604 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2022-07-21 05:01:49,605 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 8 states [2022-07-21 05:01:49,605 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2022-07-21 05:01:49,605 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 8 interpolants. [2022-07-21 05:01:49,605 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=13, Invalid=43, Unknown=0, NotChecked=0, Total=56 [2022-07-21 05:01:49,606 INFO L87 Difference]: Start difference. First operand 524 states and 671 transitions. Second operand has 8 states, 8 states have (on average 4.75) internal successors, (38), 6 states have internal predecessors, (38), 1 states have call successors, (3), 3 states have call predecessors, (3), 2 states have return successors, (2), 2 states have call predecessors, (2), 1 states have call successors, (2) [2022-07-21 05:01:49,818 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-07-21 05:01:49,818 INFO L93 Difference]: Finished difference Result 1037 states and 1366 transitions. [2022-07-21 05:01:49,819 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 10 states. [2022-07-21 05:01:49,819 INFO L78 Accepts]: Start accepts. Automaton has has 8 states, 8 states have (on average 4.75) internal successors, (38), 6 states have internal predecessors, (38), 1 states have call successors, (3), 3 states have call predecessors, (3), 2 states have return successors, (2), 2 states have call predecessors, (2), 1 states have call successors, (2) Word has length 43 [2022-07-21 05:01:49,819 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2022-07-21 05:01:49,821 INFO L225 Difference]: With dead ends: 1037 [2022-07-21 05:01:49,821 INFO L226 Difference]: Without dead ends: 520 [2022-07-21 05:01:49,823 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 19 GetRequests, 8 SyntacticMatches, 0 SemanticMatches, 11 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 6 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=42, Invalid=114, Unknown=0, NotChecked=0, Total=156 [2022-07-21 05:01:49,823 INFO L413 NwaCegarLoop]: 85 mSDtfsCounter, 189 mSDsluCounter, 275 mSDsCounter, 0 mSdLazyCounter, 270 mSolverCounterSat, 62 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.1s Time, 0 mProtectedPredicate, 0 mProtectedAction, 189 SdHoareTripleChecker+Valid, 360 SdHoareTripleChecker+Invalid, 332 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 62 IncrementalHoareTripleChecker+Valid, 270 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.2s IncrementalHoareTripleChecker+Time [2022-07-21 05:01:49,824 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [189 Valid, 360 Invalid, 332 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [62 Valid, 270 Invalid, 0 Unknown, 0 Unchecked, 0.2s Time] [2022-07-21 05:01:49,824 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 520 states. [2022-07-21 05:01:49,843 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 520 to 418. [2022-07-21 05:01:49,844 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 418 states, 329 states have (on average 1.2613981762917934) internal successors, (415), 356 states have internal predecessors, (415), 44 states have call successors, (44), 38 states have call predecessors, (44), 44 states have return successors, (70), 38 states have call predecessors, (70), 44 states have call successors, (70) [2022-07-21 05:01:49,846 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 418 states to 418 states and 529 transitions. [2022-07-21 05:01:49,846 INFO L78 Accepts]: Start accepts. Automaton has 418 states and 529 transitions. Word has length 43 [2022-07-21 05:01:49,846 INFO L84 Accepts]: Finished accepts. word is rejected. [2022-07-21 05:01:49,846 INFO L495 AbstractCegarLoop]: Abstraction has 418 states and 529 transitions. [2022-07-21 05:01:49,847 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 8 states, 8 states have (on average 4.75) internal successors, (38), 6 states have internal predecessors, (38), 1 states have call successors, (3), 3 states have call predecessors, (3), 2 states have return successors, (2), 2 states have call predecessors, (2), 1 states have call successors, (2) [2022-07-21 05:01:49,847 INFO L276 IsEmpty]: Start isEmpty. Operand 418 states and 529 transitions. [2022-07-21 05:01:49,848 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 44 [2022-07-21 05:01:49,848 INFO L187 NwaCegarLoop]: Found error trace [2022-07-21 05:01:49,848 INFO L195 NwaCegarLoop]: trace histogram [1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-07-21 05:01:49,848 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable7 [2022-07-21 05:01:49,848 INFO L420 AbstractCegarLoop]: === Iteration 9 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2022-07-21 05:01:49,849 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2022-07-21 05:01:49,849 INFO L85 PathProgramCache]: Analyzing trace with hash -1446585426, now seen corresponding path program 1 times [2022-07-21 05:01:49,849 INFO L118 FreeRefinementEngine]: Executing refinement strategy CAMEL [2022-07-21 05:01:49,849 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [1261589591] [2022-07-21 05:01:49,849 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-07-21 05:01:49,849 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2022-07-21 05:01:49,859 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-07-21 05:01:49,882 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 11 [2022-07-21 05:01:49,883 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-07-21 05:01:49,888 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 24 [2022-07-21 05:01:49,890 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-07-21 05:01:49,900 INFO L134 CoverageAnalysis]: Checked inductivity of 0 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2022-07-21 05:01:49,900 INFO L136 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2022-07-21 05:01:49,900 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [1261589591] [2022-07-21 05:01:49,901 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [1261589591] provided 1 perfect and 0 imperfect interpolant sequences [2022-07-21 05:01:49,901 INFO L184 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2022-07-21 05:01:49,901 INFO L197 FreeRefinementEngine]: Number of different interpolants: perfect sequences [7] imperfect sequences [] total 7 [2022-07-21 05:01:49,901 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [693704299] [2022-07-21 05:01:49,901 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2022-07-21 05:01:49,901 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 7 states [2022-07-21 05:01:49,901 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2022-07-21 05:01:49,902 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 7 interpolants. [2022-07-21 05:01:49,902 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=11, Invalid=31, Unknown=0, NotChecked=0, Total=42 [2022-07-21 05:01:49,902 INFO L87 Difference]: Start difference. First operand 418 states and 529 transitions. Second operand has 7 states, 7 states have (on average 5.428571428571429) internal successors, (38), 5 states have internal predecessors, (38), 1 states have call successors, (3), 3 states have call predecessors, (3), 2 states have return successors, (2), 2 states have call predecessors, (2), 1 states have call successors, (2) [2022-07-21 05:01:50,199 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-07-21 05:01:50,199 INFO L93 Difference]: Finished difference Result 958 states and 1287 transitions. [2022-07-21 05:01:50,199 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 17 states. [2022-07-21 05:01:50,200 INFO L78 Accepts]: Start accepts. Automaton has has 7 states, 7 states have (on average 5.428571428571429) internal successors, (38), 5 states have internal predecessors, (38), 1 states have call successors, (3), 3 states have call predecessors, (3), 2 states have return successors, (2), 2 states have call predecessors, (2), 1 states have call successors, (2) Word has length 43 [2022-07-21 05:01:50,201 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2022-07-21 05:01:50,203 INFO L225 Difference]: With dead ends: 958 [2022-07-21 05:01:50,203 INFO L226 Difference]: Without dead ends: 655 [2022-07-21 05:01:50,204 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 24 GetRequests, 6 SyntacticMatches, 1 SemanticMatches, 17 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 58 ImplicationChecksByTransitivity, 0.1s TimeCoverageRelationStatistics Valid=106, Invalid=236, Unknown=0, NotChecked=0, Total=342 [2022-07-21 05:01:50,206 INFO L413 NwaCegarLoop]: 133 mSDtfsCounter, 197 mSDsluCounter, 356 mSDsCounter, 0 mSdLazyCounter, 305 mSolverCounterSat, 59 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.1s Time, 0 mProtectedPredicate, 0 mProtectedAction, 199 SdHoareTripleChecker+Valid, 489 SdHoareTripleChecker+Invalid, 364 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 59 IncrementalHoareTripleChecker+Valid, 305 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.2s IncrementalHoareTripleChecker+Time [2022-07-21 05:01:50,206 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [199 Valid, 489 Invalid, 364 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [59 Valid, 305 Invalid, 0 Unknown, 0 Unchecked, 0.2s Time] [2022-07-21 05:01:50,207 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 655 states. [2022-07-21 05:01:50,231 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 655 to 630. [2022-07-21 05:01:50,232 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 630 states, 496 states have (on average 1.2358870967741935) internal successors, (613), 531 states have internal predecessors, (613), 66 states have call successors, (66), 58 states have call predecessors, (66), 67 states have return successors, (131), 66 states have call predecessors, (131), 66 states have call successors, (131) [2022-07-21 05:01:50,234 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 630 states to 630 states and 810 transitions. [2022-07-21 05:01:50,235 INFO L78 Accepts]: Start accepts. Automaton has 630 states and 810 transitions. Word has length 43 [2022-07-21 05:01:50,236 INFO L84 Accepts]: Finished accepts. word is rejected. [2022-07-21 05:01:50,236 INFO L495 AbstractCegarLoop]: Abstraction has 630 states and 810 transitions. [2022-07-21 05:01:50,236 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 7 states, 7 states have (on average 5.428571428571429) internal successors, (38), 5 states have internal predecessors, (38), 1 states have call successors, (3), 3 states have call predecessors, (3), 2 states have return successors, (2), 2 states have call predecessors, (2), 1 states have call successors, (2) [2022-07-21 05:01:50,236 INFO L276 IsEmpty]: Start isEmpty. Operand 630 states and 810 transitions. [2022-07-21 05:01:50,238 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 79 [2022-07-21 05:01:50,238 INFO L187 NwaCegarLoop]: Found error trace [2022-07-21 05:01:50,238 INFO L195 NwaCegarLoop]: trace histogram [2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-07-21 05:01:50,239 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable8 [2022-07-21 05:01:50,239 INFO L420 AbstractCegarLoop]: === Iteration 10 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2022-07-21 05:01:50,239 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2022-07-21 05:01:50,239 INFO L85 PathProgramCache]: Analyzing trace with hash 781656095, now seen corresponding path program 1 times [2022-07-21 05:01:50,239 INFO L118 FreeRefinementEngine]: Executing refinement strategy CAMEL [2022-07-21 05:01:50,239 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [110185941] [2022-07-21 05:01:50,240 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-07-21 05:01:50,240 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2022-07-21 05:01:50,269 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-07-21 05:01:50,301 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 11 [2022-07-21 05:01:50,302 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-07-21 05:01:50,308 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 20 [2022-07-21 05:01:50,311 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-07-21 05:01:50,322 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 3 [2022-07-21 05:01:50,324 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-07-21 05:01:50,331 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 63 [2022-07-21 05:01:50,333 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-07-21 05:01:50,334 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 2 [2022-07-21 05:01:50,334 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-07-21 05:01:50,335 INFO L134 CoverageAnalysis]: Checked inductivity of 21 backedges. 12 proven. 7 refuted. 0 times theorem prover too weak. 2 trivial. 0 not checked. [2022-07-21 05:01:50,335 INFO L136 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2022-07-21 05:01:50,335 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [110185941] [2022-07-21 05:01:50,335 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [110185941] provided 0 perfect and 1 imperfect interpolant sequences [2022-07-21 05:01:50,335 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleZ3 [1907339903] [2022-07-21 05:01:50,335 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-07-21 05:01:50,335 INFO L173 SolverBuilder]: Constructing external solver with command: z3 -smt2 -in SMTLIB2_COMPLIANT=true [2022-07-21 05:01:50,336 INFO L189 MonitoredProcess]: No working directory specified, using /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 [2022-07-21 05:01:50,337 INFO L229 MonitoredProcess]: Starting monitored process 2 with /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 -smt2 -in SMTLIB2_COMPLIANT=true (exit command is (exit), workingDir is null) [2022-07-21 05:01:50,339 INFO L327 MonitoredProcess]: [MP /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 -smt2 -in SMTLIB2_COMPLIANT=true (2)] Waiting until timeout for monitored process [2022-07-21 05:01:50,418 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-07-21 05:01:50,421 INFO L263 TraceCheckSpWp]: Trace formula consists of 433 conjuncts, 8 conjunts are in the unsatisfiable core [2022-07-21 05:01:50,426 INFO L286 TraceCheckSpWp]: Computing forward predicates... [2022-07-21 05:01:50,562 INFO L134 CoverageAnalysis]: Checked inductivity of 21 backedges. 15 proven. 6 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2022-07-21 05:01:50,562 INFO L328 TraceCheckSpWp]: Computing backward predicates... [2022-07-21 05:01:50,653 INFO L134 CoverageAnalysis]: Checked inductivity of 21 backedges. 13 proven. 6 refuted. 0 times theorem prover too weak. 2 trivial. 0 not checked. [2022-07-21 05:01:50,653 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleZ3 [1907339903] provided 0 perfect and 2 imperfect interpolant sequences [2022-07-21 05:01:50,653 INFO L184 FreeRefinementEngine]: Found 0 perfect and 3 imperfect interpolant sequences. [2022-07-21 05:01:50,653 INFO L197 FreeRefinementEngine]: Number of different interpolants: perfect sequences [] imperfect sequences [9, 6, 6] total 9 [2022-07-21 05:01:50,653 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [524005150] [2022-07-21 05:01:50,653 INFO L85 oduleStraightlineAll]: Using 3 imperfect interpolants to construct interpolant automaton [2022-07-21 05:01:50,653 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 9 states [2022-07-21 05:01:50,654 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2022-07-21 05:01:50,654 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 9 interpolants. [2022-07-21 05:01:50,654 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=18, Invalid=54, Unknown=0, NotChecked=0, Total=72 [2022-07-21 05:01:50,654 INFO L87 Difference]: Start difference. First operand 630 states and 810 transitions. Second operand has 9 states, 9 states have (on average 8.11111111111111) internal successors, (73), 6 states have internal predecessors, (73), 3 states have call successors, (12), 6 states have call predecessors, (12), 3 states have return successors, (7), 3 states have call predecessors, (7), 2 states have call successors, (7) [2022-07-21 05:01:51,090 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-07-21 05:01:51,090 INFO L93 Difference]: Finished difference Result 1505 states and 2040 transitions. [2022-07-21 05:01:51,090 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 27 states. [2022-07-21 05:01:51,091 INFO L78 Accepts]: Start accepts. Automaton has has 9 states, 9 states have (on average 8.11111111111111) internal successors, (73), 6 states have internal predecessors, (73), 3 states have call successors, (12), 6 states have call predecessors, (12), 3 states have return successors, (7), 3 states have call predecessors, (7), 2 states have call successors, (7) Word has length 78 [2022-07-21 05:01:51,091 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2022-07-21 05:01:51,095 INFO L225 Difference]: With dead ends: 1505 [2022-07-21 05:01:51,096 INFO L226 Difference]: Without dead ends: 990 [2022-07-21 05:01:51,097 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 198 GetRequests, 167 SyntacticMatches, 4 SemanticMatches, 27 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 200 ImplicationChecksByTransitivity, 0.1s TimeCoverageRelationStatistics Valid=227, Invalid=585, Unknown=0, NotChecked=0, Total=812 [2022-07-21 05:01:51,098 INFO L413 NwaCegarLoop]: 136 mSDtfsCounter, 380 mSDsluCounter, 440 mSDsCounter, 0 mSdLazyCounter, 446 mSolverCounterSat, 136 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.2s Time, 0 mProtectedPredicate, 0 mProtectedAction, 386 SdHoareTripleChecker+Valid, 576 SdHoareTripleChecker+Invalid, 582 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 136 IncrementalHoareTripleChecker+Valid, 446 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.3s IncrementalHoareTripleChecker+Time [2022-07-21 05:01:51,098 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [386 Valid, 576 Invalid, 582 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [136 Valid, 446 Invalid, 0 Unknown, 0 Unchecked, 0.3s Time] [2022-07-21 05:01:51,099 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 990 states. [2022-07-21 05:01:51,133 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 990 to 859. [2022-07-21 05:01:51,134 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 859 states, 669 states have (on average 1.242152466367713) internal successors, (831), 720 states have internal predecessors, (831), 95 states have call successors, (95), 83 states have call predecessors, (95), 94 states have return successors, (198), 87 states have call predecessors, (198), 95 states have call successors, (198) [2022-07-21 05:01:51,138 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 859 states to 859 states and 1124 transitions. [2022-07-21 05:01:51,139 INFO L78 Accepts]: Start accepts. Automaton has 859 states and 1124 transitions. Word has length 78 [2022-07-21 05:01:51,140 INFO L84 Accepts]: Finished accepts. word is rejected. [2022-07-21 05:01:51,140 INFO L495 AbstractCegarLoop]: Abstraction has 859 states and 1124 transitions. [2022-07-21 05:01:51,140 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 9 states, 9 states have (on average 8.11111111111111) internal successors, (73), 6 states have internal predecessors, (73), 3 states have call successors, (12), 6 states have call predecessors, (12), 3 states have return successors, (7), 3 states have call predecessors, (7), 2 states have call successors, (7) [2022-07-21 05:01:51,140 INFO L276 IsEmpty]: Start isEmpty. Operand 859 states and 1124 transitions. [2022-07-21 05:01:51,144 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 114 [2022-07-21 05:01:51,144 INFO L187 NwaCegarLoop]: Found error trace [2022-07-21 05:01:51,144 INFO L195 NwaCegarLoop]: trace histogram [3, 3, 3, 3, 3, 3, 3, 3, 3, 3, 3, 3, 3, 3, 3, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-07-21 05:01:51,169 INFO L540 MonitoredProcess]: [MP /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 -smt2 -in SMTLIB2_COMPLIANT=true (2)] Forceful destruction successful, exit code 0 [2022-07-21 05:01:51,359 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: 2 /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 -smt2 -in SMTLIB2_COMPLIANT=true,SelfDestructingSolverStorable9 [2022-07-21 05:01:51,359 INFO L420 AbstractCegarLoop]: === Iteration 11 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2022-07-21 05:01:51,360 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2022-07-21 05:01:51,360 INFO L85 PathProgramCache]: Analyzing trace with hash 313015822, now seen corresponding path program 2 times [2022-07-21 05:01:51,360 INFO L118 FreeRefinementEngine]: Executing refinement strategy CAMEL [2022-07-21 05:01:51,360 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [433844042] [2022-07-21 05:01:51,360 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-07-21 05:01:51,360 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2022-07-21 05:01:51,375 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-07-21 05:01:51,410 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 11 [2022-07-21 05:01:51,411 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-07-21 05:01:51,416 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 20 [2022-07-21 05:01:51,418 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-07-21 05:01:51,425 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 3 [2022-07-21 05:01:51,427 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-07-21 05:01:51,431 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 52 [2022-07-21 05:01:51,438 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-07-21 05:01:51,524 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 10 [2022-07-21 05:01:51,526 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-07-21 05:01:51,527 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 2 [2022-07-21 05:01:51,528 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-07-21 05:01:51,529 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 98 [2022-07-21 05:01:51,530 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-07-21 05:01:51,531 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 2 [2022-07-21 05:01:51,531 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-07-21 05:01:51,532 INFO L134 CoverageAnalysis]: Checked inductivity of 77 backedges. 54 proven. 11 refuted. 0 times theorem prover too weak. 12 trivial. 0 not checked. [2022-07-21 05:01:51,532 INFO L136 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2022-07-21 05:01:51,533 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [433844042] [2022-07-21 05:01:51,533 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [433844042] provided 0 perfect and 1 imperfect interpolant sequences [2022-07-21 05:01:51,533 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleZ3 [839129874] [2022-07-21 05:01:51,533 INFO L93 rtionOrderModulation]: Changing assertion order to OUTSIDE_LOOP_FIRST1 [2022-07-21 05:01:51,533 INFO L173 SolverBuilder]: Constructing external solver with command: z3 -smt2 -in SMTLIB2_COMPLIANT=true [2022-07-21 05:01:51,533 INFO L189 MonitoredProcess]: No working directory specified, using /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 [2022-07-21 05:01:51,541 INFO L229 MonitoredProcess]: Starting monitored process 3 with /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 -smt2 -in SMTLIB2_COMPLIANT=true (exit command is (exit), workingDir is null) [2022-07-21 05:01:51,542 INFO L327 MonitoredProcess]: [MP /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 -smt2 -in SMTLIB2_COMPLIANT=true (3)] Waiting until timeout for monitored process [2022-07-21 05:01:51,637 INFO L228 tOrderPrioritization]: Assert order OUTSIDE_LOOP_FIRST1 issued 2 check-sat command(s) [2022-07-21 05:01:51,637 INFO L229 tOrderPrioritization]: Conjunction of SSA is unsat [2022-07-21 05:01:51,639 INFO L263 TraceCheckSpWp]: Trace formula consists of 523 conjuncts, 10 conjunts are in the unsatisfiable core [2022-07-21 05:01:51,642 INFO L286 TraceCheckSpWp]: Computing forward predicates... [2022-07-21 05:01:51,734 INFO L134 CoverageAnalysis]: Checked inductivity of 77 backedges. 64 proven. 0 refuted. 0 times theorem prover too weak. 13 trivial. 0 not checked. [2022-07-21 05:01:51,734 INFO L324 TraceCheckSpWp]: Omiting computation of backward sequence because forward sequence was already perfect [2022-07-21 05:01:51,734 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleZ3 [839129874] provided 1 perfect and 0 imperfect interpolant sequences [2022-07-21 05:01:51,734 INFO L184 FreeRefinementEngine]: Found 1 perfect and 1 imperfect interpolant sequences. [2022-07-21 05:01:51,734 INFO L197 FreeRefinementEngine]: Number of different interpolants: perfect sequences [6] imperfect sequences [10] total 14 [2022-07-21 05:01:51,734 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [150708066] [2022-07-21 05:01:51,734 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2022-07-21 05:01:51,735 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 6 states [2022-07-21 05:01:51,735 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2022-07-21 05:01:51,735 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 6 interpolants. [2022-07-21 05:01:51,735 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=32, Invalid=150, Unknown=0, NotChecked=0, Total=182 [2022-07-21 05:01:51,735 INFO L87 Difference]: Start difference. First operand 859 states and 1124 transitions. Second operand has 6 states, 6 states have (on average 14.5) internal successors, (87), 6 states have internal predecessors, (87), 3 states have call successors, (8), 4 states have call predecessors, (8), 3 states have return successors, (8), 3 states have call predecessors, (8), 3 states have call successors, (8) [2022-07-21 05:01:51,969 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-07-21 05:01:51,969 INFO L93 Difference]: Finished difference Result 2362 states and 3210 transitions. [2022-07-21 05:01:51,969 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 10 states. [2022-07-21 05:01:51,969 INFO L78 Accepts]: Start accepts. Automaton has has 6 states, 6 states have (on average 14.5) internal successors, (87), 6 states have internal predecessors, (87), 3 states have call successors, (8), 4 states have call predecessors, (8), 3 states have return successors, (8), 3 states have call predecessors, (8), 3 states have call successors, (8) Word has length 113 [2022-07-21 05:01:51,970 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2022-07-21 05:01:51,976 INFO L225 Difference]: With dead ends: 2362 [2022-07-21 05:01:51,976 INFO L226 Difference]: Without dead ends: 1616 [2022-07-21 05:01:51,979 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 145 GetRequests, 126 SyntacticMatches, 2 SemanticMatches, 17 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 41 ImplicationChecksByTransitivity, 0.2s TimeCoverageRelationStatistics Valid=63, Invalid=279, Unknown=0, NotChecked=0, Total=342 [2022-07-21 05:01:51,979 INFO L413 NwaCegarLoop]: 156 mSDtfsCounter, 224 mSDsluCounter, 459 mSDsCounter, 0 mSdLazyCounter, 149 mSolverCounterSat, 29 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.1s Time, 0 mProtectedPredicate, 0 mProtectedAction, 224 SdHoareTripleChecker+Valid, 615 SdHoareTripleChecker+Invalid, 178 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 29 IncrementalHoareTripleChecker+Valid, 149 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.1s IncrementalHoareTripleChecker+Time [2022-07-21 05:01:51,979 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [224 Valid, 615 Invalid, 178 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [29 Valid, 149 Invalid, 0 Unknown, 0 Unchecked, 0.1s Time] [2022-07-21 05:01:51,981 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 1616 states. [2022-07-21 05:01:52,042 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 1616 to 1495. [2022-07-21 05:01:52,044 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 1495 states, 1168 states have (on average 1.2414383561643836) internal successors, (1450), 1246 states have internal predecessors, (1450), 166 states have call successors, (166), 148 states have call predecessors, (166), 160 states have return successors, (304), 150 states have call predecessors, (304), 166 states have call successors, (304) [2022-07-21 05:01:52,051 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 1495 states to 1495 states and 1920 transitions. [2022-07-21 05:01:52,052 INFO L78 Accepts]: Start accepts. Automaton has 1495 states and 1920 transitions. Word has length 113 [2022-07-21 05:01:52,052 INFO L84 Accepts]: Finished accepts. word is rejected. [2022-07-21 05:01:52,052 INFO L495 AbstractCegarLoop]: Abstraction has 1495 states and 1920 transitions. [2022-07-21 05:01:52,052 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 6 states, 6 states have (on average 14.5) internal successors, (87), 6 states have internal predecessors, (87), 3 states have call successors, (8), 4 states have call predecessors, (8), 3 states have return successors, (8), 3 states have call predecessors, (8), 3 states have call successors, (8) [2022-07-21 05:01:52,052 INFO L276 IsEmpty]: Start isEmpty. Operand 1495 states and 1920 transitions. [2022-07-21 05:01:52,055 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 114 [2022-07-21 05:01:52,055 INFO L187 NwaCegarLoop]: Found error trace [2022-07-21 05:01:52,055 INFO L195 NwaCegarLoop]: trace histogram [3, 3, 3, 3, 3, 3, 3, 3, 3, 3, 3, 3, 3, 3, 3, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-07-21 05:01:52,076 INFO L540 MonitoredProcess]: [MP /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 -smt2 -in SMTLIB2_COMPLIANT=true (3)] Forceful destruction successful, exit code 0 [2022-07-21 05:01:52,277 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: 3 /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 -smt2 -in SMTLIB2_COMPLIANT=true,SelfDestructingSolverStorable10 [2022-07-21 05:01:52,278 INFO L420 AbstractCegarLoop]: === Iteration 12 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2022-07-21 05:01:52,278 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2022-07-21 05:01:52,278 INFO L85 PathProgramCache]: Analyzing trace with hash 1189034828, now seen corresponding path program 1 times [2022-07-21 05:01:52,278 INFO L118 FreeRefinementEngine]: Executing refinement strategy CAMEL [2022-07-21 05:01:52,278 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [2031548926] [2022-07-21 05:01:52,278 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-07-21 05:01:52,278 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2022-07-21 05:01:52,291 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-07-21 05:01:52,316 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 11 [2022-07-21 05:01:52,317 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-07-21 05:01:52,331 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 20 [2022-07-21 05:01:52,332 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-07-21 05:01:52,336 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 3 [2022-07-21 05:01:52,337 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-07-21 05:01:52,340 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 52 [2022-07-21 05:01:52,343 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-07-21 05:01:52,358 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 10 [2022-07-21 05:01:52,359 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-07-21 05:01:52,359 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 2 [2022-07-21 05:01:52,360 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-07-21 05:01:52,361 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 98 [2022-07-21 05:01:52,362 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-07-21 05:01:52,363 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 2 [2022-07-21 05:01:52,363 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-07-21 05:01:52,364 INFO L134 CoverageAnalysis]: Checked inductivity of 77 backedges. 44 proven. 0 refuted. 0 times theorem prover too weak. 33 trivial. 0 not checked. [2022-07-21 05:01:52,364 INFO L136 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2022-07-21 05:01:52,364 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [2031548926] [2022-07-21 05:01:52,364 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [2031548926] provided 1 perfect and 0 imperfect interpolant sequences [2022-07-21 05:01:52,364 INFO L184 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2022-07-21 05:01:52,364 INFO L197 FreeRefinementEngine]: Number of different interpolants: perfect sequences [8] imperfect sequences [] total 8 [2022-07-21 05:01:52,364 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [724245718] [2022-07-21 05:01:52,365 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2022-07-21 05:01:52,365 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 8 states [2022-07-21 05:01:52,365 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2022-07-21 05:01:52,365 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 8 interpolants. [2022-07-21 05:01:52,366 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=15, Invalid=41, Unknown=0, NotChecked=0, Total=56 [2022-07-21 05:01:52,366 INFO L87 Difference]: Start difference. First operand 1495 states and 1920 transitions. Second operand has 8 states, 8 states have (on average 9.75) internal successors, (78), 5 states have internal predecessors, (78), 2 states have call successors, (6), 5 states have call predecessors, (6), 2 states have return successors, (6), 2 states have call predecessors, (6), 2 states have call successors, (6) [2022-07-21 05:01:52,514 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-07-21 05:01:52,514 INFO L93 Difference]: Finished difference Result 2095 states and 2654 transitions. [2022-07-21 05:01:52,515 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 9 states. [2022-07-21 05:01:52,515 INFO L78 Accepts]: Start accepts. Automaton has has 8 states, 8 states have (on average 9.75) internal successors, (78), 5 states have internal predecessors, (78), 2 states have call successors, (6), 5 states have call predecessors, (6), 2 states have return successors, (6), 2 states have call predecessors, (6), 2 states have call successors, (6) Word has length 113 [2022-07-21 05:01:52,515 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2022-07-21 05:01:52,516 INFO L225 Difference]: With dead ends: 2095 [2022-07-21 05:01:52,516 INFO L226 Difference]: Without dead ends: 0 [2022-07-21 05:01:52,519 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 27 GetRequests, 17 SyntacticMatches, 0 SemanticMatches, 10 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 14 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=39, Invalid=93, Unknown=0, NotChecked=0, Total=132 [2022-07-21 05:01:52,520 INFO L413 NwaCegarLoop]: 82 mSDtfsCounter, 82 mSDsluCounter, 271 mSDsCounter, 0 mSdLazyCounter, 223 mSolverCounterSat, 20 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.1s Time, 0 mProtectedPredicate, 0 mProtectedAction, 84 SdHoareTripleChecker+Valid, 353 SdHoareTripleChecker+Invalid, 243 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 20 IncrementalHoareTripleChecker+Valid, 223 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.1s IncrementalHoareTripleChecker+Time [2022-07-21 05:01:52,520 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [84 Valid, 353 Invalid, 243 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [20 Valid, 223 Invalid, 0 Unknown, 0 Unchecked, 0.1s Time] [2022-07-21 05:01:52,521 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 0 states. [2022-07-21 05:01:52,521 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 0 to 0. [2022-07-21 05:01:52,521 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 0 states, 0 states have (on average 0.0) internal successors, (0), 0 states have internal predecessors, (0), 0 states have call successors, (0), 0 states have call predecessors, (0), 0 states have return successors, (0), 0 states have call predecessors, (0), 0 states have call successors, (0) [2022-07-21 05:01:52,521 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 0 states to 0 states and 0 transitions. [2022-07-21 05:01:52,521 INFO L78 Accepts]: Start accepts. Automaton has 0 states and 0 transitions. Word has length 113 [2022-07-21 05:01:52,521 INFO L84 Accepts]: Finished accepts. word is rejected. [2022-07-21 05:01:52,522 INFO L495 AbstractCegarLoop]: Abstraction has 0 states and 0 transitions. [2022-07-21 05:01:52,522 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 8 states, 8 states have (on average 9.75) internal successors, (78), 5 states have internal predecessors, (78), 2 states have call successors, (6), 5 states have call predecessors, (6), 2 states have return successors, (6), 2 states have call predecessors, (6), 2 states have call successors, (6) [2022-07-21 05:01:52,522 INFO L276 IsEmpty]: Start isEmpty. Operand 0 states and 0 transitions. [2022-07-21 05:01:52,522 INFO L282 IsEmpty]: Finished isEmpty. No accepting run. [2022-07-21 05:01:52,524 INFO L805 garLoopResultBuilder]: Registering result SAFE for location timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION (0 of 1 remaining) [2022-07-21 05:01:52,524 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable11 [2022-07-21 05:01:52,525 INFO L343 DoubleDeckerVisitor]: Before removal of dead ends 0 states and 0 transitions. [2022-07-21 05:01:55,285 INFO L895 garLoopResultBuilder]: At program point deactivatePumpENTRY(lines 263 270) the Hoare annotation is: (or (= ~pumpRunning~0 |old(~pumpRunning~0)|) (not (<= 1 ~waterLevel~0)) (= 0 ~systemActive~0)) [2022-07-21 05:01:55,286 INFO L899 garLoopResultBuilder]: For program point deactivatePumpEXIT(lines 263 270) no Hoare annotation was computed. [2022-07-21 05:01:55,286 INFO L899 garLoopResultBuilder]: For program point deactivatePumpFINAL(lines 263 270) no Hoare annotation was computed. [2022-07-21 05:01:55,286 INFO L899 garLoopResultBuilder]: For program point processEnvironment__wrappee__baseEXIT(lines 196 202) no Hoare annotation was computed. [2022-07-21 05:01:55,286 INFO L902 garLoopResultBuilder]: At program point processEnvironment__wrappee__baseFINAL(lines 196 202) the Hoare annotation is: true [2022-07-21 05:01:55,286 INFO L902 garLoopResultBuilder]: At program point changeMethaneLevelENTRY(lines 84 95) the Hoare annotation is: true [2022-07-21 05:01:55,286 INFO L899 garLoopResultBuilder]: For program point L88-1(lines 84 95) no Hoare annotation was computed. [2022-07-21 05:01:55,286 INFO L899 garLoopResultBuilder]: For program point changeMethaneLevelEXIT(lines 84 95) no Hoare annotation was computed. [2022-07-21 05:01:55,286 INFO L902 garLoopResultBuilder]: At program point L832(line 832) the Hoare annotation is: true [2022-07-21 05:01:55,286 INFO L899 garLoopResultBuilder]: For program point cleanupEXIT(lines 826 855) no Hoare annotation was computed. [2022-07-21 05:01:55,286 INFO L899 garLoopResultBuilder]: For program point L832-1(line 832) no Hoare annotation was computed. [2022-07-21 05:01:55,286 INFO L902 garLoopResultBuilder]: At program point cleanupENTRY(lines 826 855) the Hoare annotation is: true [2022-07-21 05:01:55,286 INFO L902 garLoopResultBuilder]: At program point L851(lines 826 855) the Hoare annotation is: true [2022-07-21 05:01:55,287 INFO L899 garLoopResultBuilder]: For program point L847(line 847) no Hoare annotation was computed. [2022-07-21 05:01:55,287 INFO L899 garLoopResultBuilder]: For program point L840(lines 840 844) no Hoare annotation was computed. [2022-07-21 05:01:55,287 INFO L902 garLoopResultBuilder]: At program point L840-1(lines 840 844) the Hoare annotation is: true [2022-07-21 05:01:55,287 INFO L899 garLoopResultBuilder]: For program point L837(line 837) no Hoare annotation was computed. [2022-07-21 05:01:55,287 INFO L902 garLoopResultBuilder]: At program point L836-2(lines 836 850) the Hoare annotation is: true [2022-07-21 05:01:55,287 INFO L899 garLoopResultBuilder]: For program point L64(lines 64 68) no Hoare annotation was computed. [2022-07-21 05:01:55,287 INFO L895 garLoopResultBuilder]: At program point L287(lines 282 290) the Hoare annotation is: (and (or (not (= |old(~pumpRunning~0)| 0)) (not (<= 1 |old(~waterLevel~0)|))) (or (= 0 ~systemActive~0) (not (<= 2 |old(~waterLevel~0)|)))) [2022-07-21 05:01:55,287 INFO L895 garLoopResultBuilder]: At program point L64-2(lines 60 71) the Hoare annotation is: (and (or (not (= |old(~pumpRunning~0)| 0)) (not (<= 1 |old(~waterLevel~0)|))) (or (and (= ~pumpRunning~0 |old(~pumpRunning~0)|) (<= 1 ~waterLevel~0)) (= 0 ~systemActive~0) (not (<= 2 |old(~waterLevel~0)|)))) [2022-07-21 05:01:55,287 INFO L899 garLoopResultBuilder]: For program point L176-1(lines 175 194) no Hoare annotation was computed. [2022-07-21 05:01:55,287 INFO L899 garLoopResultBuilder]: For program point L238(lines 238 246) no Hoare annotation was computed. [2022-07-21 05:01:55,287 INFO L899 garLoopResultBuilder]: For program point L234(lines 234 251) no Hoare annotation was computed. [2022-07-21 05:01:55,287 INFO L899 garLoopResultBuilder]: For program point timeShiftFINAL(lines 172 195) no Hoare annotation was computed. [2022-07-21 05:01:55,287 INFO L895 garLoopResultBuilder]: At program point L156(lines 151 159) the Hoare annotation is: (and (or (not (= |old(~pumpRunning~0)| 0)) (not (<= 1 |old(~waterLevel~0)|))) (or (and (= ~pumpRunning~0 |old(~pumpRunning~0)|) (= |timeShift_isLowWaterSensorDry_#res#1| 0) (<= 1 ~waterLevel~0)) (= 0 ~systemActive~0) (not (<= 2 |old(~waterLevel~0)|)))) [2022-07-21 05:01:55,287 INFO L899 garLoopResultBuilder]: For program point L355(lines 355 359) no Hoare annotation was computed. [2022-07-21 05:01:55,288 INFO L899 garLoopResultBuilder]: For program point L355-2(lines 355 359) no Hoare annotation was computed. [2022-07-21 05:01:55,288 INFO L895 garLoopResultBuilder]: At program point L244(line 244) the Hoare annotation is: (and (or (not (= |old(~pumpRunning~0)| 0)) (not (<= 1 |old(~waterLevel~0)|))) (or (= 0 ~systemActive~0) (not (<= 2 |old(~waterLevel~0)|)))) [2022-07-21 05:01:55,288 INFO L895 garLoopResultBuilder]: At program point L240(line 240) the Hoare annotation is: (and (or (not (= |old(~pumpRunning~0)| 0)) (not (<= 1 |old(~waterLevel~0)|))) (or (= 0 ~systemActive~0) (and (= ~pumpRunning~0 |old(~pumpRunning~0)|) (= |timeShift_isLowWaterSensorDry_#res#1| 0) (= |timeShift_isLowWaterLevel_~tmp~3#1| 0) (<= 1 |timeShift_isLowWaterLevel_~tmp___0~1#1|) (<= 1 |timeShift_isLowWaterLevel_#res#1|) (<= 1 |timeShift_processEnvironment_~tmp~1#1|) (<= 1 ~waterLevel~0)) (not (<= 2 |old(~waterLevel~0)|)))) [2022-07-21 05:01:55,288 INFO L895 garLoopResultBuilder]: At program point L133(lines 128 136) the Hoare annotation is: (let ((.cse7 (<= 2 ~waterLevel~0)) (.cse6 (= |old(~waterLevel~0)| ~waterLevel~0)) (.cse8 (<= 2 |timeShift_getWaterLevel_#res#1|)) (.cse2 (= 0 ~systemActive~0))) (let ((.cse1 (and .cse7 .cse6 .cse8 (not .cse2))) (.cse0 (not (= |old(~pumpRunning~0)| 0))) (.cse5 (= ~pumpRunning~0 0)) (.cse4 (<= 1 |timeShift_getWaterLevel_#res#1|)) (.cse3 (not (<= 2 |old(~waterLevel~0)|)))) (and (or .cse0 .cse1 .cse2 .cse3) (or .cse0 .cse4 .cse3) (or .cse0 (and .cse5 .cse6) .cse1 (not (<= 1 |old(~waterLevel~0)|))) (or .cse0 (not (= |old(~waterLevel~0)| 1)) (= |timeShift_getWaterLevel_#res#1| 1)) (or (and .cse7 .cse8) .cse2 (and .cse5 (<= 1 |timeShift_isLowWaterLevel_~tmp___0~1#1|) (<= 1 |timeShift_isLowWaterLevel_#res#1|) (<= 1 |timeShift_processEnvironment_~tmp~1#1|) (<= 1 ~waterLevel~0) .cse4) .cse3)))) [2022-07-21 05:01:55,288 INFO L899 garLoopResultBuilder]: For program point L963(line 963) no Hoare annotation was computed. [2022-07-21 05:01:55,289 INFO L895 garLoopResultBuilder]: At program point L249(line 249) the Hoare annotation is: (let ((.cse3 (= 0 ~systemActive~0))) (let ((.cse0 (= ~pumpRunning~0 0)) (.cse2 (not (= |old(~pumpRunning~0)| 0))) (.cse1 (not .cse3)) (.cse4 (not (<= 2 |old(~waterLevel~0)|)))) (and (or (and .cse0 (= ~waterLevel~0 1) .cse1) .cse2 (not (= |old(~waterLevel~0)| 1))) (or (and (= ~pumpRunning~0 |old(~pumpRunning~0)|) .cse0) .cse3 .cse4) (or .cse2 (and (= |old(~waterLevel~0)| ~waterLevel~0) .cse1) .cse4)))) [2022-07-21 05:01:55,289 INFO L895 garLoopResultBuilder]: At program point L249-1(lines 230 254) the Hoare annotation is: (let ((.cse0 (= ~pumpRunning~0 0)) (.cse1 (<= 2 ~waterLevel~0)) (.cse2 (= 0 ~systemActive~0))) (and (or (and .cse0 (<= 1 |timeShift_isLowWaterLevel_~tmp___0~1#1|) (<= 1 |timeShift_isLowWaterLevel_#res#1|) (<= 1 |timeShift_processEnvironment_~tmp~1#1|) (<= 1 ~waterLevel~0)) .cse1 .cse2 (not (<= 2 |old(~waterLevel~0)|))) (let ((.cse3 (= |old(~waterLevel~0)| ~waterLevel~0)) (.cse4 (not .cse2))) (or (not (= |old(~pumpRunning~0)| 0)) (not (<= 1 |old(~waterLevel~0)|)) (and .cse0 .cse3 .cse4) (and .cse1 .cse3 .cse4))))) [2022-07-21 05:01:55,289 INFO L899 garLoopResultBuilder]: For program point L183-1(lines 183 189) no Hoare annotation was computed. [2022-07-21 05:01:55,289 INFO L899 garLoopResultBuilder]: For program point L980(lines 980 986) no Hoare annotation was computed. [2022-07-21 05:01:55,289 INFO L899 garLoopResultBuilder]: For program point L976(lines 976 989) no Hoare annotation was computed. [2022-07-21 05:01:55,289 INFO L895 garLoopResultBuilder]: At program point timeShiftENTRY(lines 172 195) the Hoare annotation is: (let ((.cse0 (= |old(~waterLevel~0)| ~waterLevel~0))) (and (or (not (= |old(~pumpRunning~0)| 0)) (and (= ~pumpRunning~0 0) .cse0) (not (<= 1 |old(~waterLevel~0)|))) (or (and (= ~pumpRunning~0 |old(~pumpRunning~0)|) .cse0) (= 0 ~systemActive~0) (not (<= 2 |old(~waterLevel~0)|))))) [2022-07-21 05:01:55,289 INFO L895 garLoopResultBuilder]: At program point L976-1(lines 968 992) the Hoare annotation is: (let ((.cse7 (= |old(~waterLevel~0)| ~waterLevel~0)) (.cse8 (<= 2 |timeShift_getWaterLevel_#res#1|)) (.cse9 (<= 2 |timeShift___utac_acc__Specification4_spec__1_~tmp~9#1|)) (.cse2 (= 0 ~systemActive~0))) (let ((.cse0 (not (= |old(~pumpRunning~0)| 0))) (.cse1 (and .cse7 .cse8 .cse9 (not .cse2))) (.cse4 (= ~pumpRunning~0 0)) (.cse5 (<= 1 |timeShift___utac_acc__Specification4_spec__1_~tmp~9#1|)) (.cse6 (<= 1 |timeShift_getWaterLevel_#res#1|)) (.cse3 (not (<= 2 |old(~waterLevel~0)|)))) (and (or .cse0 .cse1 .cse2 .cse3) (or .cse0 (not (= |old(~waterLevel~0)| 1)) (and (= |timeShift___utac_acc__Specification4_spec__1_~tmp~9#1| 1) .cse4 (= ~waterLevel~0 1) (= |timeShift_getWaterLevel_#res#1| 1))) (or (and .cse4 .cse5 .cse6 .cse7) .cse0 .cse1 .cse3) (or (and (<= 2 ~waterLevel~0) .cse8 .cse9) (and .cse4 (<= 1 |timeShift_isLowWaterLevel_~tmp___0~1#1|) (<= 1 |timeShift_isLowWaterLevel_#res#1|) (<= 1 |timeShift_processEnvironment_~tmp~1#1|) .cse5 (<= 1 ~waterLevel~0) .cse6) .cse2 .cse3)))) [2022-07-21 05:01:55,289 INFO L899 garLoopResultBuilder]: For program point timeShiftEXIT(lines 172 195) no Hoare annotation was computed. [2022-07-21 05:01:55,289 INFO L895 garLoopResultBuilder]: At program point L361(lines 346 364) the Hoare annotation is: (and (or (and (= ~pumpRunning~0 |old(~pumpRunning~0)|) (= |timeShift_isLowWaterSensorDry_#res#1| 0) (= |timeShift_isLowWaterLevel_~tmp~3#1| 0) (<= 1 |timeShift_isLowWaterLevel_~tmp___0~1#1|) (<= 1 |timeShift_isLowWaterLevel_#res#1|) (<= 1 ~waterLevel~0)) (= 0 ~systemActive~0) (not (<= 2 |old(~waterLevel~0)|))) (or (not (= |old(~pumpRunning~0)| 0)) (not (<= 1 |old(~waterLevel~0)|)))) [2022-07-21 05:01:55,289 INFO L899 garLoopResultBuilder]: For program point timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION(line 963) no Hoare annotation was computed. [2022-07-21 05:01:55,289 INFO L895 garLoopResultBuilder]: At program point L964(lines 959 966) the Hoare annotation is: (and (or (not (= |old(~pumpRunning~0)| 0)) (not (<= 1 |old(~waterLevel~0)|))) (or (= 0 ~systemActive~0) (not (<= 2 |old(~waterLevel~0)|)))) [2022-07-21 05:01:55,289 INFO L902 garLoopResultBuilder]: At program point L894(lines 887 896) the Hoare annotation is: true [2022-07-21 05:01:55,290 INFO L902 garLoopResultBuilder]: At program point L919(lines 900 922) the Hoare annotation is: true [2022-07-21 05:01:55,290 INFO L902 garLoopResultBuilder]: At program point L453(lines 390 457) the Hoare annotation is: true [2022-07-21 05:01:55,290 INFO L899 garLoopResultBuilder]: For program point L420(lines 420 426) no Hoare annotation was computed. [2022-07-21 05:01:55,290 INFO L899 garLoopResultBuilder]: For program point L420-1(lines 420 426) no Hoare annotation was computed. [2022-07-21 05:01:55,290 INFO L899 garLoopResultBuilder]: For program point L-1(line -1) no Hoare annotation was computed. [2022-07-21 05:01:55,290 INFO L899 garLoopResultBuilder]: For program point ULTIMATE.startENTRY(line -1) no Hoare annotation was computed. [2022-07-21 05:01:55,290 INFO L899 garLoopResultBuilder]: For program point ULTIMATE.startFINAL(line -1) no Hoare annotation was computed. [2022-07-21 05:01:55,290 INFO L895 garLoopResultBuilder]: At program point L412(line 412) the Hoare annotation is: (let ((.cse0 (= |ULTIMATE.start_valid_product_#res#1| 1)) (.cse1 (= |ULTIMATE.start_main_~tmp~8#1| 1)) (.cse2 (= |ULTIMATE.start_test_~splverifierCounter~0#1| 0))) (or (and .cse0 (<= 2 ~waterLevel~0) .cse1 .cse2 (not (= 0 ~systemActive~0))) (and (= ~pumpRunning~0 0) .cse0 .cse1 .cse2 (<= 1 ~waterLevel~0)))) [2022-07-21 05:01:55,290 INFO L895 garLoopResultBuilder]: At program point L371(line 371) the Hoare annotation is: (and (= |ULTIMATE.start_valid_product_#res#1| 1) (<= 2 ~waterLevel~0) (= |ULTIMATE.start_main_~tmp~8#1| 1) (= |ULTIMATE.start_test_~splverifierCounter~0#1| 0) (not (= 0 ~systemActive~0))) [2022-07-21 05:01:55,290 INFO L895 garLoopResultBuilder]: At program point L450(lines 399 451) the Hoare annotation is: false [2022-07-21 05:01:55,290 INFO L899 garLoopResultBuilder]: For program point ULTIMATE.startEXIT(line -1) no Hoare annotation was computed. [2022-07-21 05:01:55,290 INFO L895 garLoopResultBuilder]: At program point L954(lines 949 957) the Hoare annotation is: (and (= ~pumpRunning~0 0) (= 1 ~systemActive~0) (= |ULTIMATE.start_valid_product_#res#1| ~systemActive~0) (= ~waterLevel~0 1)) [2022-07-21 05:01:55,290 INFO L899 garLoopResultBuilder]: For program point L438(lines 438 444) no Hoare annotation was computed. [2022-07-21 05:01:55,290 INFO L895 garLoopResultBuilder]: At program point L884(lines 880 886) the Hoare annotation is: (and (= ~pumpRunning~0 0) (= |ULTIMATE.start_main_~tmp~8#1| 1) (= |ULTIMATE.start_valid_product_#res#1| ~systemActive~0) (= ~waterLevel~0 1) (= |ULTIMATE.start_main_~tmp~8#1| ~systemActive~0)) [2022-07-21 05:01:55,290 INFO L895 garLoopResultBuilder]: At program point L438-2(lines 430 445) the Hoare annotation is: (let ((.cse0 (= |ULTIMATE.start_valid_product_#res#1| 1)) (.cse1 (= |ULTIMATE.start_main_~tmp~8#1| 1)) (.cse2 (= |ULTIMATE.start_test_~splverifierCounter~0#1| 0))) (or (and .cse0 (<= 2 ~waterLevel~0) .cse1 .cse2 (not (= 0 ~systemActive~0))) (and (= ~pumpRunning~0 0) .cse0 .cse1 .cse2 (<= 1 ~waterLevel~0)))) [2022-07-21 05:01:55,290 INFO L895 garLoopResultBuilder]: At program point L946(lines 942 948) the Hoare annotation is: (and (= ~pumpRunning~0 0) (= 1 ~systemActive~0) (= ~waterLevel~0 1)) [2022-07-21 05:01:55,290 INFO L899 garLoopResultBuilder]: For program point L401(lines 400 449) no Hoare annotation was computed. [2022-07-21 05:01:55,290 INFO L899 garLoopResultBuilder]: For program point L430(lines 430 445) no Hoare annotation was computed. [2022-07-21 05:01:55,290 INFO L895 garLoopResultBuilder]: At program point L422(line 422) the Hoare annotation is: (let ((.cse0 (= |ULTIMATE.start_valid_product_#res#1| 1)) (.cse1 (= |ULTIMATE.start_main_~tmp~8#1| 1)) (.cse2 (= |ULTIMATE.start_test_~splverifierCounter~0#1| 0))) (or (and .cse0 (<= 2 ~waterLevel~0) .cse1 .cse2 (not (= 0 ~systemActive~0))) (and (= ~pumpRunning~0 0) .cse0 .cse1 .cse2 (<= 1 ~waterLevel~0)))) [2022-07-21 05:01:55,290 INFO L895 garLoopResultBuilder]: At program point L385(lines 380 387) the Hoare annotation is: (let ((.cse0 (= |ULTIMATE.start_valid_product_#res#1| 1)) (.cse1 (= 1 ~systemActive~0)) (.cse2 (= |ULTIMATE.start_main_~tmp~8#1| 1)) (.cse3 (= |ULTIMATE.start_test_~splverifierCounter~0#1| 0))) (or (and .cse0 (<= 2 ~waterLevel~0) .cse1 .cse2 .cse3) (and (= ~pumpRunning~0 0) .cse0 .cse1 .cse2 .cse3 (= ~waterLevel~0 1)))) [2022-07-21 05:01:55,290 INFO L895 garLoopResultBuilder]: At program point L447(lines 400 449) the Hoare annotation is: (let ((.cse0 (= |ULTIMATE.start_valid_product_#res#1| 1)) (.cse1 (= |ULTIMATE.start_main_~tmp~8#1| 1)) (.cse2 (= |ULTIMATE.start_test_~splverifierCounter~0#1| 0))) (or (and .cse0 (<= 2 ~waterLevel~0) .cse1 .cse2 (not (= 0 ~systemActive~0))) (and (= ~pumpRunning~0 0) .cse0 .cse1 .cse2 (<= 1 ~waterLevel~0)))) [2022-07-21 05:01:55,291 INFO L899 garLoopResultBuilder]: For program point L410(lines 410 416) no Hoare annotation was computed. [2022-07-21 05:01:55,291 INFO L899 garLoopResultBuilder]: For program point L410-1(lines 410 416) no Hoare annotation was computed. [2022-07-21 05:01:55,291 INFO L895 garLoopResultBuilder]: At program point L377(lines 365 379) the Hoare annotation is: (and (= ~pumpRunning~0 0) (= |ULTIMATE.start_valid_product_#res#1| 1) (= |ULTIMATE.start_main_~tmp~8#1| 1) (= |ULTIMATE.start_test_~splverifierCounter~0#1| 0) (<= 1 ~waterLevel~0)) [2022-07-21 05:01:55,291 INFO L899 garLoopResultBuilder]: For program point L402(lines 402 406) no Hoare annotation was computed. [2022-07-21 05:01:55,291 INFO L899 garLoopResultBuilder]: For program point L369(lines 369 375) no Hoare annotation was computed. [2022-07-21 05:01:55,291 INFO L899 garLoopResultBuilder]: For program point L369-1(lines 369 375) no Hoare annotation was computed. [2022-07-21 05:01:55,291 INFO L899 garLoopResultBuilder]: For program point L910(lines 910 917) no Hoare annotation was computed. [2022-07-21 05:01:55,291 INFO L899 garLoopResultBuilder]: For program point L910-2(lines 910 917) no Hoare annotation was computed. [2022-07-21 05:01:55,291 INFO L895 garLoopResultBuilder]: At program point L939(lines 935 941) the Hoare annotation is: (and (= ~pumpRunning~0 0) (= 1 ~systemActive~0) (= ~waterLevel~0 1)) [2022-07-21 05:01:55,291 INFO L895 garLoopResultBuilder]: At program point processEnvironment__wrappee__highWaterSensorENTRY(lines 204 228) the Hoare annotation is: (or (not (= |old(~pumpRunning~0)| 0)) (= ~pumpRunning~0 0) (not (<= 1 ~waterLevel~0)) (= 0 ~systemActive~0)) [2022-07-21 05:01:55,291 INFO L895 garLoopResultBuilder]: At program point L223(line 223) the Hoare annotation is: (or (not (= |old(~pumpRunning~0)| 0)) (not (<= 1 ~waterLevel~0)) (= 0 ~systemActive~0)) [2022-07-21 05:01:55,292 INFO L899 garLoopResultBuilder]: For program point L223-1(lines 204 228) no Hoare annotation was computed. [2022-07-21 05:01:55,292 INFO L899 garLoopResultBuilder]: For program point L141(lines 141 147) no Hoare annotation was computed. [2022-07-21 05:01:55,292 INFO L899 garLoopResultBuilder]: For program point processEnvironment__wrappee__highWaterSensorEXIT(lines 204 228) no Hoare annotation was computed. [2022-07-21 05:01:55,292 INFO L895 garLoopResultBuilder]: At program point L218(line 218) the Hoare annotation is: (let ((.cse0 (not (= |old(~pumpRunning~0)| 0))) (.cse1 (= 0 ~systemActive~0))) (and (or (not (= ~waterLevel~0 1)) .cse0 (and (not (= |processEnvironment__wrappee__highWaterSensor_isHighWaterLevel_~tmp~2#1| 0)) (not (= |processEnvironment__wrappee__highWaterSensor_isHighWaterSensorDry_#res#1| 0))) .cse1) (or .cse0 (not (<= 1 ~waterLevel~0)) (and (= ~pumpRunning~0 0) (= |processEnvironment__wrappee__highWaterSensor_~tmp~0#1| 0)) .cse1))) [2022-07-21 05:01:55,292 INFO L895 garLoopResultBuilder]: At program point L342(lines 327 345) the Hoare annotation is: (let ((.cse0 (not (= |old(~pumpRunning~0)| 0))) (.cse1 (= 0 ~systemActive~0))) (and (or (not (= ~waterLevel~0 1)) .cse0 (not (= |processEnvironment__wrappee__highWaterSensor_isHighWaterSensorDry_#res#1| 0)) .cse1) (let ((.cse2 (= ~pumpRunning~0 0))) (or .cse0 (and (not (= |processEnvironment__wrappee__highWaterSensor_isHighWaterLevel_~tmp~2#1| 0)) .cse2 (= |processEnvironment__wrappee__highWaterSensor_isHighWaterLevel_#res#1| 0) (= |processEnvironment__wrappee__highWaterSensor_isHighWaterLevel_~tmp___0~0#1| 0)) (not (<= 1 ~waterLevel~0)) (and .cse2 (<= 2 ~waterLevel~0)) .cse1)))) [2022-07-21 05:01:55,293 INFO L899 garLoopResultBuilder]: For program point L212(lines 212 220) no Hoare annotation was computed. [2022-07-21 05:01:55,293 INFO L895 garLoopResultBuilder]: At program point L146(lines 137 150) the Hoare annotation is: (let ((.cse0 (= ~pumpRunning~0 0))) (or (not (= |old(~pumpRunning~0)| 0)) (not (<= 1 ~waterLevel~0)) (and .cse0 (not (= |processEnvironment__wrappee__highWaterSensor_isHighWaterSensorDry_#res#1| 0))) (and .cse0 (<= 2 ~waterLevel~0)) (= 0 ~systemActive~0))) [2022-07-21 05:01:55,293 INFO L899 garLoopResultBuilder]: For program point L208(lines 208 225) no Hoare annotation was computed. [2022-07-21 05:01:55,293 INFO L899 garLoopResultBuilder]: For program point L336(lines 336 340) no Hoare annotation was computed. [2022-07-21 05:01:55,293 INFO L899 garLoopResultBuilder]: For program point L336-2(lines 336 340) no Hoare annotation was computed. [2022-07-21 05:01:55,293 INFO L895 garLoopResultBuilder]: At program point L260(lines 255 262) the Hoare annotation is: (or (not (= ~waterLevel~0 1)) (not (= |old(~pumpRunning~0)| 0)) (= 0 ~systemActive~0)) [2022-07-21 05:01:55,293 INFO L899 garLoopResultBuilder]: For program point waterRiseEXIT(lines 72 83) no Hoare annotation was computed. [2022-07-21 05:01:55,294 INFO L899 garLoopResultBuilder]: For program point L76-1(lines 72 83) no Hoare annotation was computed. [2022-07-21 05:01:55,294 INFO L895 garLoopResultBuilder]: At program point waterRiseENTRY(lines 72 83) the Hoare annotation is: (let ((.cse0 (= |old(~waterLevel~0)| ~waterLevel~0))) (and (or (not (= ~pumpRunning~0 0)) (not (<= 1 |old(~waterLevel~0)|)) .cse0) (or .cse0 (= 0 ~systemActive~0) (not (<= 2 |old(~waterLevel~0)|))))) [2022-07-21 05:01:55,297 INFO L356 BasicCegarLoop]: Path program histogram: [2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-07-21 05:01:55,298 INFO L176 ceAbstractionStarter]: Computing trace abstraction results [2022-07-21 05:01:55,322 INFO L202 PluginConnector]: Adding new model de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction CFG 21.07 05:01:55 BoogieIcfgContainer [2022-07-21 05:01:55,322 INFO L132 PluginConnector]: ------------------------ END TraceAbstraction---------------------------- [2022-07-21 05:01:55,322 INFO L113 PluginConnector]: ------------------------Witness Printer---------------------------- [2022-07-21 05:01:55,323 INFO L271 PluginConnector]: Initializing Witness Printer... [2022-07-21 05:01:55,323 INFO L275 PluginConnector]: Witness Printer initialized [2022-07-21 05:01:55,323 INFO L185 PluginConnector]: Executing the observer RCFGCatcher from plugin Witness Printer for "de.uni_freiburg.informatik.ultimate.plugins.generator.rcfgbuilder CFG 21.07 05:01:47" (3/4) ... [2022-07-21 05:01:55,325 INFO L137 WitnessPrinter]: Generating witness for correct program [2022-07-21 05:01:55,332 INFO L354 RCFGBacktranslator]: Ignoring RootEdge to procedure deactivatePump [2022-07-21 05:01:55,332 INFO L354 RCFGBacktranslator]: Ignoring RootEdge to procedure processEnvironment__wrappee__base [2022-07-21 05:01:55,332 INFO L354 RCFGBacktranslator]: Ignoring RootEdge to procedure changeMethaneLevel [2022-07-21 05:01:55,332 INFO L354 RCFGBacktranslator]: Ignoring RootEdge to procedure cleanup [2022-07-21 05:01:55,333 INFO L354 RCFGBacktranslator]: Ignoring RootEdge to procedure timeShift [2022-07-21 05:01:55,333 INFO L354 RCFGBacktranslator]: Ignoring RootEdge to procedure processEnvironment__wrappee__highWaterSensor [2022-07-21 05:01:55,333 INFO L354 RCFGBacktranslator]: Ignoring RootEdge to procedure waterRise [2022-07-21 05:01:55,338 INFO L910 BoogieBacktranslator]: Reduced CFG by removing 52 nodes and edges [2022-07-21 05:01:55,339 INFO L910 BoogieBacktranslator]: Reduced CFG by removing 22 nodes and edges [2022-07-21 05:01:55,339 INFO L910 BoogieBacktranslator]: Reduced CFG by removing 11 nodes and edges [2022-07-21 05:01:55,339 INFO L910 BoogieBacktranslator]: Reduced CFG by removing 5 nodes and edges [2022-07-21 05:01:55,340 INFO L910 BoogieBacktranslator]: Reduced CFG by removing 2 nodes and edges [2022-07-21 05:01:55,340 INFO L910 BoogieBacktranslator]: Reduced CFG by removing 1 nodes and edges [2022-07-21 05:01:55,340 INFO L910 BoogieBacktranslator]: Reduced CFG by removing 1 nodes and edges [2022-07-21 05:01:55,356 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: ((pumpRunning == 0 && 1 == systemActive) && \result == systemActive) && waterLevel == 1 [2022-07-21 05:01:55,357 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (((pumpRunning == 0 && tmp == 1) && \result == systemActive) && waterLevel == 1) && tmp == systemActive [2022-07-21 05:01:55,357 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: ((((\result == 1 && 2 <= waterLevel) && tmp == 1) && splverifierCounter == 0) && !(0 == systemActive)) || ((((pumpRunning == 0 && \result == 1) && tmp == 1) && splverifierCounter == 0) && 1 <= waterLevel) [2022-07-21 05:01:55,358 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (!(\old(pumpRunning) == 0) || !(1 <= \old(waterLevel))) && (((pumpRunning == \old(pumpRunning) && 1 <= waterLevel) || 0 == systemActive) || !(2 <= \old(waterLevel))) [2022-07-21 05:01:55,359 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (((((((pumpRunning == 0 && 1 <= tmp___0) && 1 <= \result) && 1 <= tmp) && 1 <= waterLevel) || 2 <= waterLevel) || 0 == systemActive) || !(2 <= \old(waterLevel))) && (((!(\old(pumpRunning) == 0) || !(1 <= \old(waterLevel))) || ((pumpRunning == 0 && \old(waterLevel) == waterLevel) && !(0 == systemActive))) || ((2 <= waterLevel && \old(waterLevel) == waterLevel) && !(0 == systemActive))) [2022-07-21 05:01:55,360 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: ((((\result == 1 && 2 <= waterLevel) && 1 == systemActive) && tmp == 1) && splverifierCounter == 0) || (((((pumpRunning == 0 && \result == 1) && 1 == systemActive) && tmp == 1) && splverifierCounter == 0) && waterLevel == 1) [2022-07-21 05:01:55,360 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: ((((((!(\old(pumpRunning) == 0) || (((2 <= waterLevel && \old(waterLevel) == waterLevel) && 2 <= \result) && !(0 == systemActive))) || 0 == systemActive) || !(2 <= \old(waterLevel))) && ((!(\old(pumpRunning) == 0) || 1 <= \result) || !(2 <= \old(waterLevel)))) && (((!(\old(pumpRunning) == 0) || (pumpRunning == 0 && \old(waterLevel) == waterLevel)) || (((2 <= waterLevel && \old(waterLevel) == waterLevel) && 2 <= \result) && !(0 == systemActive))) || !(1 <= \old(waterLevel)))) && ((!(\old(pumpRunning) == 0) || !(\old(waterLevel) == 1)) || \result == 1)) && ((((2 <= waterLevel && 2 <= \result) || 0 == systemActive) || (((((pumpRunning == 0 && 1 <= tmp___0) && 1 <= \result) && 1 <= tmp) && 1 <= waterLevel) && 1 <= \result)) || !(2 <= \old(waterLevel))) [2022-07-21 05:01:55,360 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (((pumpRunning == 0 && \result == 1) && tmp == 1) && splverifierCounter == 0) && 1 <= waterLevel [2022-07-21 05:01:55,360 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (((((!(\old(pumpRunning) == 0) || (((\old(waterLevel) == waterLevel && 2 <= \result) && 2 <= tmp) && !(0 == systemActive))) || 0 == systemActive) || !(2 <= \old(waterLevel))) && ((!(\old(pumpRunning) == 0) || !(\old(waterLevel) == 1)) || (((tmp == 1 && pumpRunning == 0) && waterLevel == 1) && \result == 1))) && ((((((pumpRunning == 0 && 1 <= tmp) && 1 <= \result) && \old(waterLevel) == waterLevel) || !(\old(pumpRunning) == 0)) || (((\old(waterLevel) == waterLevel && 2 <= \result) && 2 <= tmp) && !(0 == systemActive))) || !(2 <= \old(waterLevel)))) && (((((2 <= waterLevel && 2 <= \result) && 2 <= tmp) || ((((((pumpRunning == 0 && 1 <= tmp___0) && 1 <= \result) && 1 <= tmp) && 1 <= tmp) && 1 <= waterLevel) && 1 <= \result)) || 0 == systemActive) || !(2 <= \old(waterLevel))) [2022-07-21 05:01:55,361 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (!(\old(pumpRunning) == 0) || !(1 <= \old(waterLevel))) && ((((pumpRunning == \old(pumpRunning) && \result == 0) && 1 <= waterLevel) || 0 == systemActive) || !(2 <= \old(waterLevel))) [2022-07-21 05:01:55,361 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (((!(\old(pumpRunning) == 0) || !(1 <= waterLevel)) || (pumpRunning == 0 && !(\result == 0))) || (pumpRunning == 0 && 2 <= waterLevel)) || 0 == systemActive [2022-07-21 05:01:55,361 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (!(\old(pumpRunning) == 0) || !(1 <= \old(waterLevel))) && (0 == systemActive || !(2 <= \old(waterLevel))) [2022-07-21 05:01:55,361 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (((((((pumpRunning == \old(pumpRunning) && \result == 0) && tmp == 0) && 1 <= tmp___0) && 1 <= \result) && 1 <= waterLevel) || 0 == systemActive) || !(2 <= \old(waterLevel))) && (!(\old(pumpRunning) == 0) || !(1 <= \old(waterLevel))) [2022-07-21 05:01:55,361 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (((!(waterLevel == 1) || !(\old(pumpRunning) == 0)) || !(\result == 0)) || 0 == systemActive) && ((((!(\old(pumpRunning) == 0) || (((!(tmp == 0) && pumpRunning == 0) && \result == 0) && tmp___0 == 0)) || !(1 <= waterLevel)) || (pumpRunning == 0 && 2 <= waterLevel)) || 0 == systemActive) [2022-07-21 05:01:55,362 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (!(\old(pumpRunning) == 0) || !(1 <= \old(waterLevel))) && (0 == systemActive || !(2 <= \old(waterLevel))) [2022-07-21 05:01:55,362 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (!(waterLevel == 1) || !(\old(pumpRunning) == 0)) || 0 == systemActive [2022-07-21 05:01:55,389 INFO L141 WitnessManager]: Wrote witness to /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/witness.graphml [2022-07-21 05:01:55,389 INFO L132 PluginConnector]: ------------------------ END Witness Printer---------------------------- [2022-07-21 05:01:55,389 INFO L158 Benchmark]: Toolchain (without parser) took 8520.25ms. Allocated memory was 56.6MB in the beginning and 163.6MB in the end (delta: 107.0MB). Free memory was 34.8MB in the beginning and 90.0MB in the end (delta: -55.2MB). Peak memory consumption was 50.9MB. Max. memory is 16.1GB. [2022-07-21 05:01:55,390 INFO L158 Benchmark]: CDTParser took 0.46ms. Allocated memory is still 56.6MB. Free memory was 38.2MB in the beginning and 38.2MB in the end (delta: 44.6kB). There was no memory consumed. Max. memory is 16.1GB. [2022-07-21 05:01:55,390 INFO L158 Benchmark]: CACSL2BoogieTranslator took 313.63ms. Allocated memory was 56.6MB in the beginning and 73.4MB in the end (delta: 16.8MB). Free memory was 34.6MB in the beginning and 49.2MB in the end (delta: -14.6MB). Peak memory consumption was 12.6MB. Max. memory is 16.1GB. [2022-07-21 05:01:55,390 INFO L158 Benchmark]: Boogie Procedure Inliner took 63.42ms. Allocated memory is still 73.4MB. Free memory was 49.2MB in the beginning and 46.7MB in the end (delta: 2.5MB). Peak memory consumption was 2.1MB. Max. memory is 16.1GB. [2022-07-21 05:01:55,391 INFO L158 Benchmark]: Boogie Preprocessor took 37.69ms. Allocated memory is still 73.4MB. Free memory was 46.7MB in the beginning and 45.0MB in the end (delta: 1.6MB). Peak memory consumption was 2.1MB. Max. memory is 16.1GB. [2022-07-21 05:01:55,391 INFO L158 Benchmark]: RCFGBuilder took 433.60ms. Allocated memory is still 73.4MB. Free memory was 45.0MB in the beginning and 47.3MB in the end (delta: -2.3MB). Peak memory consumption was 12.5MB. Max. memory is 16.1GB. [2022-07-21 05:01:55,391 INFO L158 Benchmark]: TraceAbstraction took 7598.52ms. Allocated memory was 73.4MB in the beginning and 163.6MB in the end (delta: 90.2MB). Free memory was 46.8MB in the beginning and 95.3MB in the end (delta: -48.5MB). Peak memory consumption was 90.7MB. Max. memory is 16.1GB. [2022-07-21 05:01:55,392 INFO L158 Benchmark]: Witness Printer took 66.67ms. Allocated memory is still 163.6MB. Free memory was 95.3MB in the beginning and 90.0MB in the end (delta: 5.2MB). Peak memory consumption was 4.2MB. Max. memory is 16.1GB. [2022-07-21 05:01:55,394 INFO L339 ainManager$Toolchain]: ####################### End [Toolchain 1] ####################### --- Results --- * Results from de.uni_freiburg.informatik.ultimate.core: - StatisticsResult: Toolchain Benchmarks Benchmark results are: * CDTParser took 0.46ms. Allocated memory is still 56.6MB. Free memory was 38.2MB in the beginning and 38.2MB in the end (delta: 44.6kB). There was no memory consumed. Max. memory is 16.1GB. * CACSL2BoogieTranslator took 313.63ms. Allocated memory was 56.6MB in the beginning and 73.4MB in the end (delta: 16.8MB). Free memory was 34.6MB in the beginning and 49.2MB in the end (delta: -14.6MB). Peak memory consumption was 12.6MB. Max. memory is 16.1GB. * Boogie Procedure Inliner took 63.42ms. Allocated memory is still 73.4MB. Free memory was 49.2MB in the beginning and 46.7MB in the end (delta: 2.5MB). Peak memory consumption was 2.1MB. Max. memory is 16.1GB. * Boogie Preprocessor took 37.69ms. Allocated memory is still 73.4MB. Free memory was 46.7MB in the beginning and 45.0MB in the end (delta: 1.6MB). Peak memory consumption was 2.1MB. Max. memory is 16.1GB. * RCFGBuilder took 433.60ms. Allocated memory is still 73.4MB. Free memory was 45.0MB in the beginning and 47.3MB in the end (delta: -2.3MB). Peak memory consumption was 12.5MB. Max. memory is 16.1GB. * TraceAbstraction took 7598.52ms. Allocated memory was 73.4MB in the beginning and 163.6MB in the end (delta: 90.2MB). Free memory was 46.8MB in the beginning and 95.3MB in the end (delta: -48.5MB). Peak memory consumption was 90.7MB. Max. memory is 16.1GB. * Witness Printer took 66.67ms. Allocated memory is still 163.6MB. Free memory was 95.3MB in the beginning and 90.0MB in the end (delta: 5.2MB). Peak memory consumption was 4.2MB. Max. memory is 16.1GB. * Results from de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction: - StatisticsResult: ErrorAutomatonStatistics NumberErrorTraces: 0, NumberStatementsAllTraces: 0, NumberRelevantStatements: 0, 0.0s ErrorAutomatonConstructionTimeTotal, 0.0s FaulLocalizationTime, NumberStatementsFirstTrace: -1, TraceLengthAvg: 0, 0.0s ErrorAutomatonConstructionTimeAvg, 0.0s ErrorAutomatonDifferenceTimeAvg, 0.0s ErrorAutomatonDifferenceTimeTotal, NumberOfNoEnhancement: 0, NumberOfFiniteEnhancement: 0, NumberOfInfiniteEnhancement: 0 - PositiveResult [Line: 963]: call to reach_error is unreachable For all program executions holds that call to reach_error is unreachable at this location - StatisticsResult: Ultimate Automizer benchmark data CFG has 8 procedures, 90 locations, 1 error locations. Started 1 CEGAR loops. OverallTime: 7.5s, OverallIterations: 12, TraceHistogramMax: 3, PathProgramHistogramMax: 2, EmptinessCheckTime: 0.0s, AutomataDifference: 2.2s, DeadEndRemovalTime: 0.0s, HoareAnnotationTime: 2.8s, InitialAbstractionConstructionTime: 0.0s, HoareTripleCheckerStatistics: 0 mSolverCounterUnknown, 1687 SdHoareTripleChecker+Valid, 1.2s IncrementalHoareTripleChecker+Time, 0 mSdLazyCounter, 1669 mSDsluCounter, 4419 SdHoareTripleChecker+Invalid, 1.0s Time, 0 mProtectedAction, 0 SdHoareTripleChecker+Unchecked, 0 IncrementalHoareTripleChecker+Unchecked, 3118 mSDsCounter, 410 IncrementalHoareTripleChecker+Valid, 0 mProtectedPredicate, 1931 IncrementalHoareTripleChecker+Invalid, 2341 SdHoareTripleChecker+Unknown, 0 mSolverCounterNotChecked, 410 mSolverCounterUnsat, 1301 mSDtfsCounter, 1931 mSolverCounterSat, 0.0s SdHoareTripleChecker+Time, 0 IncrementalHoareTripleChecker+Unknown, PredicateUnifierStatistics: 0 DeclaredPredicates, 465 GetRequests, 343 SyntacticMatches, 7 SemanticMatches, 115 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 334 ImplicationChecksByTransitivity, 0.6s Time, 0.0s BasicInterpolantAutomatonTime, BiggestAbstraction: size=1495occurred in iteration=11, InterpolantAutomatonStates: 112, traceCheckStatistics: No data available, InterpolantConsolidationStatistics: No data available, PathInvariantsStatistics: No data available, 0/0 InterpolantCoveringCapability, TotalInterpolationStatistics: No data available, 0.0s DumpTime, AutomataMinimizationStatistics: 0.4s AutomataMinimizationTime, 12 MinimizatonAttempts, 495 StatesRemovedByMinimization, 8 NontrivialMinimizations, HoareAnnotationStatistics: 0.0s HoareAnnotationTime, 42 LocationsWithAnnotation, 2355 PreInvPairs, 2641 NumberOfFragments, 1025 HoareAnnotationTreeSize, 2355 FomulaSimplifications, 4094 FormulaSimplificationTreeSizeReduction, 0.6s HoareSimplificationTime, 42 FomulaSimplificationsInter, 23287 FormulaSimplificationTreeSizeReductionInter, 2.2s HoareSimplificationTimeInter, RefinementEngineStatistics: TRACE_CHECK: 0.1s SsaConstructionTime, 0.3s SatisfiabilityAnalysisTime, 1.1s InterpolantComputationTime, 778 NumberOfCodeBlocks, 778 NumberOfCodeBlocksAsserted, 15 NumberOfCheckSat, 841 ConstructedInterpolants, 0 QuantifiedInterpolants, 1633 SizeOfPredicates, 8 NumberOfNonLiveVariables, 956 ConjunctsInSsa, 18 ConjunctsInUnsatCore, 15 InterpolantComputations, 11 PerfectInterpolantSequences, 264/294 InterpolantCoveringCapability, INVARIANT_SYNTHESIS: No data available, INTERPOLANT_CONSOLIDATION: No data available, ABSTRACT_INTERPRETATION: No data available, PDR: No data available, ACCELERATED_INTERPOLATION: No data available, SIFA: No data available, ReuseStatistics: No data available - AllSpecificationsHoldResult: All specifications hold 1 specifications checked. All of them hold - InvariantResult [Line: 346]: Loop Invariant Derived loop invariant: (((((((pumpRunning == \old(pumpRunning) && \result == 0) && tmp == 0) && 1 <= tmp___0) && 1 <= \result) && 1 <= waterLevel) || 0 == systemActive) || !(2 <= \old(waterLevel))) && (!(\old(pumpRunning) == 0) || !(1 <= \old(waterLevel))) - InvariantResult [Line: 255]: Loop Invariant Derived loop invariant: (!(waterLevel == 1) || !(\old(pumpRunning) == 0)) || 0 == systemActive - InvariantResult [Line: 968]: Loop Invariant Derived loop invariant: (((((!(\old(pumpRunning) == 0) || (((\old(waterLevel) == waterLevel && 2 <= \result) && 2 <= tmp) && !(0 == systemActive))) || 0 == systemActive) || !(2 <= \old(waterLevel))) && ((!(\old(pumpRunning) == 0) || !(\old(waterLevel) == 1)) || (((tmp == 1 && pumpRunning == 0) && waterLevel == 1) && \result == 1))) && ((((((pumpRunning == 0 && 1 <= tmp) && 1 <= \result) && \old(waterLevel) == waterLevel) || !(\old(pumpRunning) == 0)) || (((\old(waterLevel) == waterLevel && 2 <= \result) && 2 <= tmp) && !(0 == systemActive))) || !(2 <= \old(waterLevel)))) && (((((2 <= waterLevel && 2 <= \result) && 2 <= tmp) || ((((((pumpRunning == 0 && 1 <= tmp___0) && 1 <= \result) && 1 <= tmp) && 1 <= tmp) && 1 <= waterLevel) && 1 <= \result)) || 0 == systemActive) || !(2 <= \old(waterLevel))) - InvariantResult [Line: 128]: Loop Invariant Derived loop invariant: ((((((!(\old(pumpRunning) == 0) || (((2 <= waterLevel && \old(waterLevel) == waterLevel) && 2 <= \result) && !(0 == systemActive))) || 0 == systemActive) || !(2 <= \old(waterLevel))) && ((!(\old(pumpRunning) == 0) || 1 <= \result) || !(2 <= \old(waterLevel)))) && (((!(\old(pumpRunning) == 0) || (pumpRunning == 0 && \old(waterLevel) == waterLevel)) || (((2 <= waterLevel && \old(waterLevel) == waterLevel) && 2 <= \result) && !(0 == systemActive))) || !(1 <= \old(waterLevel)))) && ((!(\old(pumpRunning) == 0) || !(\old(waterLevel) == 1)) || \result == 1)) && ((((2 <= waterLevel && 2 <= \result) || 0 == systemActive) || (((((pumpRunning == 0 && 1 <= tmp___0) && 1 <= \result) && 1 <= tmp) && 1 <= waterLevel) && 1 <= \result)) || !(2 <= \old(waterLevel))) - InvariantResult [Line: 942]: Loop Invariant Derived loop invariant: (pumpRunning == 0 && 1 == systemActive) && waterLevel == 1 - InvariantResult [Line: 959]: Loop Invariant Derived loop invariant: (!(\old(pumpRunning) == 0) || !(1 <= \old(waterLevel))) && (0 == systemActive || !(2 <= \old(waterLevel))) - InvariantResult [Line: 880]: Loop Invariant Derived loop invariant: (((pumpRunning == 0 && tmp == 1) && \result == systemActive) && waterLevel == 1) && tmp == systemActive - InvariantResult [Line: 60]: Loop Invariant Derived loop invariant: (!(\old(pumpRunning) == 0) || !(1 <= \old(waterLevel))) && (((pumpRunning == \old(pumpRunning) && 1 <= waterLevel) || 0 == systemActive) || !(2 <= \old(waterLevel))) - InvariantResult [Line: 399]: Loop Invariant Derived loop invariant: 0 - InvariantResult [Line: 836]: Loop Invariant Derived loop invariant: 1 - InvariantResult [Line: 949]: Loop Invariant Derived loop invariant: ((pumpRunning == 0 && 1 == systemActive) && \result == systemActive) && waterLevel == 1 - InvariantResult [Line: 390]: Loop Invariant Derived loop invariant: 1 - InvariantResult [Line: 400]: Loop Invariant Derived loop invariant: ((((\result == 1 && 2 <= waterLevel) && tmp == 1) && splverifierCounter == 0) && !(0 == systemActive)) || ((((pumpRunning == 0 && \result == 1) && tmp == 1) && splverifierCounter == 0) && 1 <= waterLevel) - InvariantResult [Line: 151]: Loop Invariant Derived loop invariant: (!(\old(pumpRunning) == 0) || !(1 <= \old(waterLevel))) && ((((pumpRunning == \old(pumpRunning) && \result == 0) && 1 <= waterLevel) || 0 == systemActive) || !(2 <= \old(waterLevel))) - InvariantResult [Line: 137]: Loop Invariant Derived loop invariant: (((!(\old(pumpRunning) == 0) || !(1 <= waterLevel)) || (pumpRunning == 0 && !(\result == 0))) || (pumpRunning == 0 && 2 <= waterLevel)) || 0 == systemActive - InvariantResult [Line: 282]: Loop Invariant Derived loop invariant: (!(\old(pumpRunning) == 0) || !(1 <= \old(waterLevel))) && (0 == systemActive || !(2 <= \old(waterLevel))) - InvariantResult [Line: 365]: Loop Invariant Derived loop invariant: (((pumpRunning == 0 && \result == 1) && tmp == 1) && splverifierCounter == 0) && 1 <= waterLevel - InvariantResult [Line: 327]: Loop Invariant Derived loop invariant: (((!(waterLevel == 1) || !(\old(pumpRunning) == 0)) || !(\result == 0)) || 0 == systemActive) && ((((!(\old(pumpRunning) == 0) || (((!(tmp == 0) && pumpRunning == 0) && \result == 0) && tmp___0 == 0)) || !(1 <= waterLevel)) || (pumpRunning == 0 && 2 <= waterLevel)) || 0 == systemActive) - InvariantResult [Line: 380]: Loop Invariant Derived loop invariant: ((((\result == 1 && 2 <= waterLevel) && 1 == systemActive) && tmp == 1) && splverifierCounter == 0) || (((((pumpRunning == 0 && \result == 1) && 1 == systemActive) && tmp == 1) && splverifierCounter == 0) && waterLevel == 1) - InvariantResult [Line: 230]: Loop Invariant Derived loop invariant: (((((((pumpRunning == 0 && 1 <= tmp___0) && 1 <= \result) && 1 <= tmp) && 1 <= waterLevel) || 2 <= waterLevel) || 0 == systemActive) || !(2 <= \old(waterLevel))) && (((!(\old(pumpRunning) == 0) || !(1 <= \old(waterLevel))) || ((pumpRunning == 0 && \old(waterLevel) == waterLevel) && !(0 == systemActive))) || ((2 <= waterLevel && \old(waterLevel) == waterLevel) && !(0 == systemActive))) - InvariantResult [Line: 887]: Loop Invariant Derived loop invariant: 1 - InvariantResult [Line: 826]: Loop Invariant Derived loop invariant: 1 - InvariantResult [Line: 935]: Loop Invariant Derived loop invariant: (pumpRunning == 0 && 1 == systemActive) && waterLevel == 1 - InvariantResult [Line: 900]: Loop Invariant Derived loop invariant: 1 RESULT: Ultimate proved your program to be correct! [2022-07-21 05:01:55,441 INFO L540 MonitoredProcess]: [MP /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in -t:2000 (1)] Forceful destruction successful, exit code 0 Received shutdown request... --- End real Ultimate output --- Execution finished normally Writing output log to file Ultimate.log Result: TRUE