./Ultimate.py --spec ../sv-benchmarks/c/properties/unreach-call.prp --file ../sv-benchmarks/c/product-lines/minepump_spec4_product56.cil.c --full-output --architecture 32bit -------------------------------------------------------------------------------- Checking for ERROR reachability Using default analysis Version 35987657 Calling Ultimate with: /usr/bin/java -Dosgi.configuration.area=/storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/data/config -Xmx15G -Xms4m -jar /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/plugins/org.eclipse.equinox.launcher_1.5.800.v20200727-1323.jar -data @noDefault -ultimatedata /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/data -tc /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/config/AutomizerReach.xml -i ../sv-benchmarks/c/product-lines/minepump_spec4_product56.cil.c -s /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/config/svcomp-Reach-32bit-Automizer_Default.epf --cacsl2boogietranslator.entry.function main --witnessprinter.witness.directory /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux --witnessprinter.witness.filename witness.graphml --witnessprinter.write.witness.besides.input.file false --witnessprinter.graph.data.specification CHECK( init(main()), LTL(G ! call(reach_error())) ) --witnessprinter.graph.data.producer Automizer --witnessprinter.graph.data.architecture 32bit --witnessprinter.graph.data.programhash 03daf3415808298ae6016bdc33e04662b3dd63f1cba0029f4033bbf040a042d2 --- Real Ultimate output --- This is Ultimate 0.2.2-?-3598765 [2022-07-21 05:01:47,372 INFO L177 SettingsManager]: Resetting all preferences to default values... [2022-07-21 05:01:47,374 INFO L181 SettingsManager]: Resetting UltimateCore preferences to default values [2022-07-21 05:01:47,414 INFO L184 SettingsManager]: Ultimate Commandline Interface provides no preferences, ignoring... [2022-07-21 05:01:47,414 INFO L181 SettingsManager]: Resetting Boogie Preprocessor preferences to default values [2022-07-21 05:01:47,415 INFO L181 SettingsManager]: Resetting Boogie Procedure Inliner preferences to default values [2022-07-21 05:01:47,418 INFO L181 SettingsManager]: Resetting Abstract Interpretation preferences to default values [2022-07-21 05:01:47,420 INFO L181 SettingsManager]: Resetting LassoRanker preferences to default values [2022-07-21 05:01:47,422 INFO L181 SettingsManager]: Resetting Reaching Definitions preferences to default values [2022-07-21 05:01:47,425 INFO L181 SettingsManager]: Resetting SyntaxChecker preferences to default values [2022-07-21 05:01:47,426 INFO L181 SettingsManager]: Resetting Sifa preferences to default values [2022-07-21 05:01:47,428 INFO L184 SettingsManager]: Büchi Program Product provides no preferences, ignoring... [2022-07-21 05:01:47,428 INFO L181 SettingsManager]: Resetting LTL2Aut preferences to default values [2022-07-21 05:01:47,430 INFO L181 SettingsManager]: Resetting PEA to Boogie preferences to default values [2022-07-21 05:01:47,430 INFO L181 SettingsManager]: Resetting BlockEncodingV2 preferences to default values [2022-07-21 05:01:47,434 INFO L181 SettingsManager]: Resetting ChcToBoogie preferences to default values [2022-07-21 05:01:47,435 INFO L181 SettingsManager]: Resetting AutomataScriptInterpreter preferences to default values [2022-07-21 05:01:47,436 INFO L181 SettingsManager]: Resetting BuchiAutomizer preferences to default values [2022-07-21 05:01:47,437 INFO L181 SettingsManager]: Resetting CACSL2BoogieTranslator preferences to default values [2022-07-21 05:01:47,442 INFO L181 SettingsManager]: Resetting CodeCheck preferences to default values [2022-07-21 05:01:47,442 INFO L181 SettingsManager]: Resetting HornVerifier preferences to default values [2022-07-21 05:01:47,443 INFO L181 SettingsManager]: Resetting InvariantSynthesis preferences to default values [2022-07-21 05:01:47,445 INFO L181 SettingsManager]: Resetting RCFGBuilder preferences to default values [2022-07-21 05:01:47,445 INFO L181 SettingsManager]: Resetting Referee preferences to default values [2022-07-21 05:01:47,447 INFO L181 SettingsManager]: Resetting TraceAbstraction preferences to default values [2022-07-21 05:01:47,452 INFO L184 SettingsManager]: TraceAbstractionConcurrent provides no preferences, ignoring... [2022-07-21 05:01:47,452 INFO L184 SettingsManager]: TraceAbstractionWithAFAs provides no preferences, ignoring... [2022-07-21 05:01:47,452 INFO L181 SettingsManager]: Resetting TreeAutomizer preferences to default values [2022-07-21 05:01:47,453 INFO L181 SettingsManager]: Resetting IcfgToChc preferences to default values [2022-07-21 05:01:47,453 INFO L181 SettingsManager]: Resetting IcfgTransformer preferences to default values [2022-07-21 05:01:47,454 INFO L184 SettingsManager]: ReqToTest provides no preferences, ignoring... [2022-07-21 05:01:47,454 INFO L181 SettingsManager]: Resetting Boogie Printer preferences to default values [2022-07-21 05:01:47,456 INFO L181 SettingsManager]: Resetting ChcSmtPrinter preferences to default values [2022-07-21 05:01:47,456 INFO L181 SettingsManager]: Resetting ReqPrinter preferences to default values [2022-07-21 05:01:47,457 INFO L181 SettingsManager]: Resetting Witness Printer preferences to default values [2022-07-21 05:01:47,458 INFO L184 SettingsManager]: Boogie PL CUP Parser provides no preferences, ignoring... [2022-07-21 05:01:47,458 INFO L181 SettingsManager]: Resetting CDTParser preferences to default values [2022-07-21 05:01:47,458 INFO L184 SettingsManager]: AutomataScriptParser provides no preferences, ignoring... [2022-07-21 05:01:47,459 INFO L184 SettingsManager]: ReqParser provides no preferences, ignoring... [2022-07-21 05:01:47,459 INFO L181 SettingsManager]: Resetting SmtParser preferences to default values [2022-07-21 05:01:47,459 INFO L181 SettingsManager]: Resetting Witness Parser preferences to default values [2022-07-21 05:01:47,460 INFO L188 SettingsManager]: Finished resetting all preferences to default values... [2022-07-21 05:01:47,463 INFO L101 SettingsManager]: Beginning loading settings from /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/config/svcomp-Reach-32bit-Automizer_Default.epf [2022-07-21 05:01:47,495 INFO L113 SettingsManager]: Loading preferences was successful [2022-07-21 05:01:47,496 INFO L115 SettingsManager]: Preferences different from defaults after loading the file: [2022-07-21 05:01:47,496 INFO L136 SettingsManager]: Preferences of UltimateCore differ from their defaults: [2022-07-21 05:01:47,496 INFO L138 SettingsManager]: * Log level for class=de.uni_freiburg.informatik.ultimate.lib.smtlibutils.quantifier.QuantifierPusher=ERROR; [2022-07-21 05:01:47,497 INFO L136 SettingsManager]: Preferences of Boogie Procedure Inliner differ from their defaults: [2022-07-21 05:01:47,497 INFO L138 SettingsManager]: * Ignore calls to procedures called more than once=ONLY_FOR_SEQUENTIAL_PROGRAMS [2022-07-21 05:01:47,498 INFO L136 SettingsManager]: Preferences of BlockEncodingV2 differ from their defaults: [2022-07-21 05:01:47,498 INFO L138 SettingsManager]: * Create parallel compositions if possible=false [2022-07-21 05:01:47,498 INFO L138 SettingsManager]: * Use SBE=true [2022-07-21 05:01:47,498 INFO L136 SettingsManager]: Preferences of CACSL2BoogieTranslator differ from their defaults: [2022-07-21 05:01:47,499 INFO L138 SettingsManager]: * sizeof long=4 [2022-07-21 05:01:47,499 INFO L138 SettingsManager]: * Overapproximate operations on floating types=true [2022-07-21 05:01:47,499 INFO L138 SettingsManager]: * sizeof POINTER=4 [2022-07-21 05:01:47,499 INFO L138 SettingsManager]: * Check division by zero=IGNORE [2022-07-21 05:01:47,499 INFO L138 SettingsManager]: * Pointer to allocated memory at dereference=IGNORE [2022-07-21 05:01:47,499 INFO L138 SettingsManager]: * If two pointers are subtracted or compared they have the same base address=IGNORE [2022-07-21 05:01:47,499 INFO L138 SettingsManager]: * Check array bounds for arrays that are off heap=IGNORE [2022-07-21 05:01:47,499 INFO L138 SettingsManager]: * sizeof long double=12 [2022-07-21 05:01:47,499 INFO L138 SettingsManager]: * Check if freed pointer was valid=false [2022-07-21 05:01:47,499 INFO L138 SettingsManager]: * Use constant arrays=true [2022-07-21 05:01:47,499 INFO L138 SettingsManager]: * Pointer base address is valid at dereference=IGNORE [2022-07-21 05:01:47,500 INFO L136 SettingsManager]: Preferences of RCFGBuilder differ from their defaults: [2022-07-21 05:01:47,500 INFO L138 SettingsManager]: * Size of a code block=SequenceOfStatements [2022-07-21 05:01:47,500 INFO L138 SettingsManager]: * SMT solver=External_DefaultMode [2022-07-21 05:01:47,500 INFO L138 SettingsManager]: * Command for external solver=z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in -t:2000 [2022-07-21 05:01:47,500 INFO L136 SettingsManager]: Preferences of TraceAbstraction differ from their defaults: [2022-07-21 05:01:47,500 INFO L138 SettingsManager]: * Compute Interpolants along a Counterexample=FPandBP [2022-07-21 05:01:47,500 INFO L138 SettingsManager]: * Positions where we compute the Hoare Annotation=LoopsAndPotentialCycles [2022-07-21 05:01:47,500 INFO L138 SettingsManager]: * Trace refinement strategy=CAMEL [2022-07-21 05:01:47,500 INFO L138 SettingsManager]: * Command for external solver=z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in [2022-07-21 05:01:47,501 INFO L138 SettingsManager]: * Apply one-shot large block encoding in concurrent analysis=false [2022-07-21 05:01:47,501 INFO L138 SettingsManager]: * Automaton type used in concurrency analysis=PETRI_NET [2022-07-21 05:01:47,501 INFO L138 SettingsManager]: * Compute Hoare Annotation of negated interpolant automaton, abstraction and CFG=true [2022-07-21 05:01:47,501 INFO L138 SettingsManager]: * SMT solver=External_ModelsAndUnsatCoreMode WARNING: An illegal reflective access operation has occurred WARNING: Illegal reflective access by com.sun.xml.bind.v2.runtime.reflect.opt.Injector$1 (file:/storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/plugins/com.sun.xml.bind_2.2.0.v201505121915.jar) to method java.lang.ClassLoader.defineClass(java.lang.String,byte[],int,int) WARNING: Please consider reporting this to the maintainers of com.sun.xml.bind.v2.runtime.reflect.opt.Injector$1 WARNING: Use --illegal-access=warn to enable warnings of further illegal reflective access operations WARNING: All illegal access operations will be denied in a future release Applying setting for plugin de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator: Entry function -> main Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Witness directory -> /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Witness filename -> witness.graphml Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Write witness besides input file -> false Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Graph data specification -> CHECK( init(main()), LTL(G ! call(reach_error())) ) Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Graph data producer -> Automizer Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Graph data architecture -> 32bit Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Graph data programhash -> 03daf3415808298ae6016bdc33e04662b3dd63f1cba0029f4033bbf040a042d2 [2022-07-21 05:01:47,772 INFO L75 nceAwareModelManager]: Repository-Root is: /tmp [2022-07-21 05:01:47,792 INFO L261 ainManager$Toolchain]: [Toolchain 1]: Applicable parser(s) successfully (re)initialized [2022-07-21 05:01:47,794 INFO L217 ainManager$Toolchain]: [Toolchain 1]: Toolchain selected. [2022-07-21 05:01:47,795 INFO L271 PluginConnector]: Initializing CDTParser... [2022-07-21 05:01:47,796 INFO L275 PluginConnector]: CDTParser initialized [2022-07-21 05:01:47,796 INFO L432 ainManager$Toolchain]: [Toolchain 1]: Parsing single file: /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/../sv-benchmarks/c/product-lines/minepump_spec4_product56.cil.c [2022-07-21 05:01:47,839 INFO L220 CDTParser]: Created temporary CDT project at /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/data/4c5a55344/65d4a09bdfaa4311a504e90b3455ebf3/FLAG1f66a6115 [2022-07-21 05:01:48,205 INFO L306 CDTParser]: Found 1 translation units. [2022-07-21 05:01:48,205 INFO L160 CDTParser]: Scanning /storage/repos/ultimate/releaseScripts/default/sv-benchmarks/c/product-lines/minepump_spec4_product56.cil.c [2022-07-21 05:01:48,222 INFO L349 CDTParser]: About to delete temporary CDT project at /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/data/4c5a55344/65d4a09bdfaa4311a504e90b3455ebf3/FLAG1f66a6115 [2022-07-21 05:01:48,588 INFO L357 CDTParser]: Successfully deleted /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/data/4c5a55344/65d4a09bdfaa4311a504e90b3455ebf3 [2022-07-21 05:01:48,589 INFO L299 ainManager$Toolchain]: ####################### [Toolchain 1] ####################### [2022-07-21 05:01:48,590 INFO L131 ToolchainWalker]: Walking toolchain with 6 elements. [2022-07-21 05:01:48,593 INFO L113 PluginConnector]: ------------------------CACSL2BoogieTranslator---------------------------- [2022-07-21 05:01:48,593 INFO L271 PluginConnector]: Initializing CACSL2BoogieTranslator... [2022-07-21 05:01:48,595 INFO L275 PluginConnector]: CACSL2BoogieTranslator initialized [2022-07-21 05:01:48,596 INFO L185 PluginConnector]: Executing the observer ACSLObjectContainerObserver from plugin CACSL2BoogieTranslator for "CDTParser AST 21.07 05:01:48" (1/1) ... [2022-07-21 05:01:48,596 INFO L205 PluginConnector]: Invalid model from CACSL2BoogieTranslator for observer de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator.ACSLObjectContainerObserver@66eed753 and model type de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 21.07 05:01:48, skipping insertion in model container [2022-07-21 05:01:48,596 INFO L185 PluginConnector]: Executing the observer CACSL2BoogieTranslatorObserver from plugin CACSL2BoogieTranslator for "CDTParser AST 21.07 05:01:48" (1/1) ... [2022-07-21 05:01:48,604 INFO L145 MainTranslator]: Starting translation in SV-COMP mode [2022-07-21 05:01:48,658 INFO L178 MainTranslator]: Built tables and reachable declarations [2022-07-21 05:01:48,925 WARN L230 ndardFunctionHandler]: Function reach_error is already implemented but we override the implementation for the call at /storage/repos/ultimate/releaseScripts/default/sv-benchmarks/c/product-lines/minepump_spec4_product56.cil.c[17338,17351] [2022-07-21 05:01:48,938 INFO L210 PostProcessor]: Analyzing one entry point: main [2022-07-21 05:01:48,963 INFO L203 MainTranslator]: Completed pre-run [2022-07-21 05:01:49,070 WARN L230 ndardFunctionHandler]: Function reach_error is already implemented but we override the implementation for the call at /storage/repos/ultimate/releaseScripts/default/sv-benchmarks/c/product-lines/minepump_spec4_product56.cil.c[17338,17351] [2022-07-21 05:01:49,080 INFO L210 PostProcessor]: Analyzing one entry point: main [2022-07-21 05:01:49,109 INFO L208 MainTranslator]: Completed translation [2022-07-21 05:01:49,109 INFO L202 PluginConnector]: Adding new model de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 21.07 05:01:49 WrapperNode [2022-07-21 05:01:49,109 INFO L132 PluginConnector]: ------------------------ END CACSL2BoogieTranslator---------------------------- [2022-07-21 05:01:49,110 INFO L113 PluginConnector]: ------------------------Boogie Procedure Inliner---------------------------- [2022-07-21 05:01:49,110 INFO L271 PluginConnector]: Initializing Boogie Procedure Inliner... [2022-07-21 05:01:49,110 INFO L275 PluginConnector]: Boogie Procedure Inliner initialized [2022-07-21 05:01:49,114 INFO L185 PluginConnector]: Executing the observer TypeChecker from plugin Boogie Procedure Inliner for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 21.07 05:01:49" (1/1) ... [2022-07-21 05:01:49,142 INFO L185 PluginConnector]: Executing the observer Inliner from plugin Boogie Procedure Inliner for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 21.07 05:01:49" (1/1) ... [2022-07-21 05:01:49,187 INFO L137 Inliner]: procedures = 58, calls = 161, calls flagged for inlining = 26, calls inlined = 23, statements flattened = 289 [2022-07-21 05:01:49,188 INFO L132 PluginConnector]: ------------------------ END Boogie Procedure Inliner---------------------------- [2022-07-21 05:01:49,189 INFO L113 PluginConnector]: ------------------------Boogie Preprocessor---------------------------- [2022-07-21 05:01:49,189 INFO L271 PluginConnector]: Initializing Boogie Preprocessor... [2022-07-21 05:01:49,189 INFO L275 PluginConnector]: Boogie Preprocessor initialized [2022-07-21 05:01:49,194 INFO L185 PluginConnector]: Executing the observer EnsureBoogieModelObserver from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 21.07 05:01:49" (1/1) ... [2022-07-21 05:01:49,195 INFO L185 PluginConnector]: Executing the observer TypeChecker from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 21.07 05:01:49" (1/1) ... [2022-07-21 05:01:49,206 INFO L185 PluginConnector]: Executing the observer ConstExpander from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 21.07 05:01:49" (1/1) ... [2022-07-21 05:01:49,207 INFO L185 PluginConnector]: Executing the observer StructExpander from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 21.07 05:01:49" (1/1) ... [2022-07-21 05:01:49,211 INFO L185 PluginConnector]: Executing the observer UnstructureCode from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 21.07 05:01:49" (1/1) ... [2022-07-21 05:01:49,216 INFO L185 PluginConnector]: Executing the observer FunctionInliner from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 21.07 05:01:49" (1/1) ... [2022-07-21 05:01:49,217 INFO L185 PluginConnector]: Executing the observer BoogieSymbolTableConstructor from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 21.07 05:01:49" (1/1) ... [2022-07-21 05:01:49,218 INFO L132 PluginConnector]: ------------------------ END Boogie Preprocessor---------------------------- [2022-07-21 05:01:49,219 INFO L113 PluginConnector]: ------------------------RCFGBuilder---------------------------- [2022-07-21 05:01:49,219 INFO L271 PluginConnector]: Initializing RCFGBuilder... [2022-07-21 05:01:49,219 INFO L275 PluginConnector]: RCFGBuilder initialized [2022-07-21 05:01:49,220 INFO L185 PluginConnector]: Executing the observer RCFGBuilderObserver from plugin RCFGBuilder for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 21.07 05:01:49" (1/1) ... [2022-07-21 05:01:49,224 INFO L173 SolverBuilder]: Constructing external solver with command: z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in -t:2000 [2022-07-21 05:01:49,233 INFO L189 MonitoredProcess]: No working directory specified, using /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 [2022-07-21 05:01:49,245 INFO L229 MonitoredProcess]: Starting monitored process 1 with /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in -t:2000 (exit command is (exit), workingDir is null) [2022-07-21 05:01:49,283 INFO L327 MonitoredProcess]: [MP /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in -t:2000 (1)] Waiting until timeout for monitored process [2022-07-21 05:01:49,303 INFO L130 BoogieDeclarations]: Found specification of procedure #Ultimate.allocInit [2022-07-21 05:01:49,303 INFO L130 BoogieDeclarations]: Found specification of procedure processEnvironment__wrappee__base [2022-07-21 05:01:49,303 INFO L138 BoogieDeclarations]: Found implementation of procedure processEnvironment__wrappee__base [2022-07-21 05:01:49,303 INFO L130 BoogieDeclarations]: Found specification of procedure cleanup [2022-07-21 05:01:49,303 INFO L138 BoogieDeclarations]: Found implementation of procedure cleanup [2022-07-21 05:01:49,304 INFO L130 BoogieDeclarations]: Found specification of procedure timeShift [2022-07-21 05:01:49,304 INFO L138 BoogieDeclarations]: Found implementation of procedure timeShift [2022-07-21 05:01:49,304 INFO L130 BoogieDeclarations]: Found specification of procedure processEnvironment__wrappee__highWaterSensor [2022-07-21 05:01:49,304 INFO L138 BoogieDeclarations]: Found implementation of procedure processEnvironment__wrappee__highWaterSensor [2022-07-21 05:01:49,304 INFO L130 BoogieDeclarations]: Found specification of procedure waterRise [2022-07-21 05:01:49,305 INFO L138 BoogieDeclarations]: Found implementation of procedure waterRise [2022-07-21 05:01:49,305 INFO L130 BoogieDeclarations]: Found specification of procedure processEnvironment__wrappee__lowWaterSensor [2022-07-21 05:01:49,305 INFO L138 BoogieDeclarations]: Found implementation of procedure processEnvironment__wrappee__lowWaterSensor [2022-07-21 05:01:49,305 INFO L130 BoogieDeclarations]: Found specification of procedure deactivatePump [2022-07-21 05:01:49,305 INFO L138 BoogieDeclarations]: Found implementation of procedure deactivatePump [2022-07-21 05:01:49,305 INFO L130 BoogieDeclarations]: Found specification of procedure write~init~int [2022-07-21 05:01:49,305 INFO L130 BoogieDeclarations]: Found specification of procedure changeMethaneLevel [2022-07-21 05:01:49,306 INFO L138 BoogieDeclarations]: Found implementation of procedure changeMethaneLevel [2022-07-21 05:01:49,306 INFO L130 BoogieDeclarations]: Found specification of procedure ULTIMATE.start [2022-07-21 05:01:49,306 INFO L138 BoogieDeclarations]: Found implementation of procedure ULTIMATE.start [2022-07-21 05:01:49,373 INFO L234 CfgBuilder]: Building ICFG [2022-07-21 05:01:49,374 INFO L260 CfgBuilder]: Building CFG for each procedure with an implementation [2022-07-21 05:01:49,612 INFO L275 CfgBuilder]: Performing block encoding [2022-07-21 05:01:49,616 INFO L294 CfgBuilder]: Using the 1 location(s) as analysis (start of procedure ULTIMATE.start) [2022-07-21 05:01:49,617 INFO L299 CfgBuilder]: Removed 2 assume(true) statements. [2022-07-21 05:01:49,618 INFO L202 PluginConnector]: Adding new model de.uni_freiburg.informatik.ultimate.plugins.generator.rcfgbuilder CFG 21.07 05:01:49 BoogieIcfgContainer [2022-07-21 05:01:49,618 INFO L132 PluginConnector]: ------------------------ END RCFGBuilder---------------------------- [2022-07-21 05:01:49,619 INFO L113 PluginConnector]: ------------------------TraceAbstraction---------------------------- [2022-07-21 05:01:49,619 INFO L271 PluginConnector]: Initializing TraceAbstraction... [2022-07-21 05:01:49,621 INFO L275 PluginConnector]: TraceAbstraction initialized [2022-07-21 05:01:49,621 INFO L185 PluginConnector]: Executing the observer TraceAbstractionObserver from plugin TraceAbstraction for "CDTParser AST 21.07 05:01:48" (1/3) ... [2022-07-21 05:01:49,622 INFO L205 PluginConnector]: Invalid model from TraceAbstraction for observer de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction.TraceAbstractionObserver@467f4089 and model type de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction AST 21.07 05:01:49, skipping insertion in model container [2022-07-21 05:01:49,622 INFO L185 PluginConnector]: Executing the observer TraceAbstractionObserver from plugin TraceAbstraction for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 21.07 05:01:49" (2/3) ... [2022-07-21 05:01:49,622 INFO L205 PluginConnector]: Invalid model from TraceAbstraction for observer de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction.TraceAbstractionObserver@467f4089 and model type de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction AST 21.07 05:01:49, skipping insertion in model container [2022-07-21 05:01:49,622 INFO L185 PluginConnector]: Executing the observer TraceAbstractionObserver from plugin TraceAbstraction for "de.uni_freiburg.informatik.ultimate.plugins.generator.rcfgbuilder CFG 21.07 05:01:49" (3/3) ... [2022-07-21 05:01:49,623 INFO L111 eAbstractionObserver]: Analyzing ICFG minepump_spec4_product56.cil.c [2022-07-21 05:01:49,632 INFO L201 ceAbstractionStarter]: Automizer settings: Hoare:true NWA Interpolation:FPandBP Determinization: PREDICATE_ABSTRACTION [2022-07-21 05:01:49,632 INFO L160 ceAbstractionStarter]: Applying trace abstraction to program that has 1 error locations. [2022-07-21 05:01:49,661 INFO L356 AbstractCegarLoop]: ======== Iteration 0 == of CEGAR loop == AllErrorsAtOnce ======== [2022-07-21 05:01:49,665 INFO L357 AbstractCegarLoop]: Settings: SEPARATE_VIOLATION_CHECK=true, mInterprocedural=true, mMaxIterations=1000000, mWatchIteration=1000000, mArtifact=RCFG, mInterpolation=FPandBP, mInterpolantAutomaton=STRAIGHT_LINE, mDumpAutomata=false, mAutomataFormat=ATS_NUMERATE, mDumpPath=., mDeterminiation=PREDICATE_ABSTRACTION, mMinimize=MINIMIZE_SEVPA, mHoare=true, mAutomataTypeConcurrency=PETRI_NET, mHoareTripleChecks=INCREMENTAL, mHoareAnnotationPositions=LoopsAndPotentialCycles, mDumpOnlyReuseAutomata=false, mLimitTraceHistogram=0, mErrorLocTimeLimit=0, mLimitPathProgramCount=0, mCollectInterpolantStatistics=true, mHeuristicEmptinessCheck=false, mHeuristicEmptinessCheckAStarHeuristic=ZERO, mHeuristicEmptinessCheckAStarHeuristicRandomSeed=1337, mHeuristicEmptinessCheckSmtFeatureScoringMethod=DAGSIZE, mSMTFeatureExtraction=false, mSMTFeatureExtractionDumpPath=., mOverrideInterpolantAutomaton=false, mMcrInterpolantMethod=WP, mPorIndependenceSettings=de.uni_freiburg.informatik.ultimate.lib.tracecheckerutils.partialorder.independence.IndependenceSettings@75f79de1, mLbeIndependenceSettings=de.uni_freiburg.informatik.ultimate.lib.tracecheckerutils.partialorder.independence.IndependenceSettings@472410cc [2022-07-21 05:01:49,665 INFO L358 AbstractCegarLoop]: Starting to check reachability of 1 error locations. [2022-07-21 05:01:49,668 INFO L276 IsEmpty]: Start isEmpty. Operand has 100 states, 75 states have (on average 1.3866666666666667) internal successors, (104), 86 states have internal predecessors, (104), 15 states have call successors, (15), 8 states have call predecessors, (15), 8 states have return successors, (15), 10 states have call predecessors, (15), 15 states have call successors, (15) [2022-07-21 05:01:49,674 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 20 [2022-07-21 05:01:49,674 INFO L187 NwaCegarLoop]: Found error trace [2022-07-21 05:01:49,674 INFO L195 NwaCegarLoop]: trace histogram [1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-07-21 05:01:49,675 INFO L420 AbstractCegarLoop]: === Iteration 1 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2022-07-21 05:01:49,678 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2022-07-21 05:01:49,678 INFO L85 PathProgramCache]: Analyzing trace with hash 975776348, now seen corresponding path program 1 times [2022-07-21 05:01:49,684 INFO L118 FreeRefinementEngine]: Executing refinement strategy CAMEL [2022-07-21 05:01:49,684 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [127890279] [2022-07-21 05:01:49,685 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-07-21 05:01:49,685 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2022-07-21 05:01:49,777 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-07-21 05:01:49,844 INFO L134 CoverageAnalysis]: Checked inductivity of 0 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2022-07-21 05:01:49,845 INFO L136 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2022-07-21 05:01:49,846 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [127890279] [2022-07-21 05:01:49,846 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [127890279] provided 1 perfect and 0 imperfect interpolant sequences [2022-07-21 05:01:49,847 INFO L184 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2022-07-21 05:01:49,847 INFO L197 FreeRefinementEngine]: Number of different interpolants: perfect sequences [2] imperfect sequences [] total 2 [2022-07-21 05:01:49,848 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [1542888059] [2022-07-21 05:01:49,848 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2022-07-21 05:01:49,851 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 2 states [2022-07-21 05:01:49,852 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2022-07-21 05:01:49,871 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 2 interpolants. [2022-07-21 05:01:49,872 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=1, Invalid=1, Unknown=0, NotChecked=0, Total=2 [2022-07-21 05:01:49,874 INFO L87 Difference]: Start difference. First operand has 100 states, 75 states have (on average 1.3866666666666667) internal successors, (104), 86 states have internal predecessors, (104), 15 states have call successors, (15), 8 states have call predecessors, (15), 8 states have return successors, (15), 10 states have call predecessors, (15), 15 states have call successors, (15) Second operand has 2 states, 2 states have (on average 8.5) internal successors, (17), 2 states have internal predecessors, (17), 1 states have call successors, (2), 1 states have call predecessors, (2), 0 states have return successors, (0), 0 states have call predecessors, (0), 0 states have call successors, (0) [2022-07-21 05:01:49,915 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-07-21 05:01:49,916 INFO L93 Difference]: Finished difference Result 192 states and 263 transitions. [2022-07-21 05:01:49,916 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 2 states. [2022-07-21 05:01:49,917 INFO L78 Accepts]: Start accepts. Automaton has has 2 states, 2 states have (on average 8.5) internal successors, (17), 2 states have internal predecessors, (17), 1 states have call successors, (2), 1 states have call predecessors, (2), 0 states have return successors, (0), 0 states have call predecessors, (0), 0 states have call successors, (0) Word has length 19 [2022-07-21 05:01:49,917 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2022-07-21 05:01:49,937 INFO L225 Difference]: With dead ends: 192 [2022-07-21 05:01:49,937 INFO L226 Difference]: Without dead ends: 91 [2022-07-21 05:01:49,940 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 2 GetRequests, 2 SyntacticMatches, 0 SemanticMatches, 0 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 0 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=1, Invalid=1, Unknown=0, NotChecked=0, Total=2 [2022-07-21 05:01:49,942 INFO L413 NwaCegarLoop]: 128 mSDtfsCounter, 0 mSDsluCounter, 0 mSDsCounter, 0 mSdLazyCounter, 0 mSolverCounterSat, 0 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.0s Time, 0 mProtectedPredicate, 0 mProtectedAction, 0 SdHoareTripleChecker+Valid, 128 SdHoareTripleChecker+Invalid, 0 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 0 IncrementalHoareTripleChecker+Valid, 0 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.0s IncrementalHoareTripleChecker+Time [2022-07-21 05:01:49,943 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [0 Valid, 128 Invalid, 0 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [0 Valid, 0 Invalid, 0 Unknown, 0 Unchecked, 0.0s Time] [2022-07-21 05:01:49,953 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 91 states. [2022-07-21 05:01:49,977 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 91 to 91. [2022-07-21 05:01:49,978 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 91 states, 68 states have (on average 1.3235294117647058) internal successors, (90), 78 states have internal predecessors, (90), 15 states have call successors, (15), 8 states have call predecessors, (15), 7 states have return successors, (14), 9 states have call predecessors, (14), 14 states have call successors, (14) [2022-07-21 05:01:49,983 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 91 states to 91 states and 119 transitions. [2022-07-21 05:01:49,985 INFO L78 Accepts]: Start accepts. Automaton has 91 states and 119 transitions. Word has length 19 [2022-07-21 05:01:49,985 INFO L84 Accepts]: Finished accepts. word is rejected. [2022-07-21 05:01:49,985 INFO L495 AbstractCegarLoop]: Abstraction has 91 states and 119 transitions. [2022-07-21 05:01:49,986 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 2 states, 2 states have (on average 8.5) internal successors, (17), 2 states have internal predecessors, (17), 1 states have call successors, (2), 1 states have call predecessors, (2), 0 states have return successors, (0), 0 states have call predecessors, (0), 0 states have call successors, (0) [2022-07-21 05:01:49,986 INFO L276 IsEmpty]: Start isEmpty. Operand 91 states and 119 transitions. [2022-07-21 05:01:49,988 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 21 [2022-07-21 05:01:49,988 INFO L187 NwaCegarLoop]: Found error trace [2022-07-21 05:01:49,988 INFO L195 NwaCegarLoop]: trace histogram [1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-07-21 05:01:49,988 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable0 [2022-07-21 05:01:49,989 INFO L420 AbstractCegarLoop]: === Iteration 2 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2022-07-21 05:01:49,989 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2022-07-21 05:01:49,989 INFO L85 PathProgramCache]: Analyzing trace with hash -1543378342, now seen corresponding path program 1 times [2022-07-21 05:01:49,989 INFO L118 FreeRefinementEngine]: Executing refinement strategy CAMEL [2022-07-21 05:01:49,990 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [897495067] [2022-07-21 05:01:49,990 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-07-21 05:01:49,991 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2022-07-21 05:01:50,033 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-07-21 05:01:50,104 INFO L134 CoverageAnalysis]: Checked inductivity of 0 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2022-07-21 05:01:50,104 INFO L136 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2022-07-21 05:01:50,105 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [897495067] [2022-07-21 05:01:50,105 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [897495067] provided 1 perfect and 0 imperfect interpolant sequences [2022-07-21 05:01:50,105 INFO L184 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2022-07-21 05:01:50,105 INFO L197 FreeRefinementEngine]: Number of different interpolants: perfect sequences [3] imperfect sequences [] total 3 [2022-07-21 05:01:50,105 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [2125047558] [2022-07-21 05:01:50,106 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2022-07-21 05:01:50,107 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 3 states [2022-07-21 05:01:50,107 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2022-07-21 05:01:50,107 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 3 interpolants. [2022-07-21 05:01:50,108 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=3, Invalid=3, Unknown=0, NotChecked=0, Total=6 [2022-07-21 05:01:50,108 INFO L87 Difference]: Start difference. First operand 91 states and 119 transitions. Second operand has 3 states, 3 states have (on average 6.0) internal successors, (18), 3 states have internal predecessors, (18), 1 states have call successors, (2), 1 states have call predecessors, (2), 0 states have return successors, (0), 0 states have call predecessors, (0), 0 states have call successors, (0) [2022-07-21 05:01:50,124 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-07-21 05:01:50,124 INFO L93 Difference]: Finished difference Result 143 states and 187 transitions. [2022-07-21 05:01:50,125 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 3 states. [2022-07-21 05:01:50,125 INFO L78 Accepts]: Start accepts. Automaton has has 3 states, 3 states have (on average 6.0) internal successors, (18), 3 states have internal predecessors, (18), 1 states have call successors, (2), 1 states have call predecessors, (2), 0 states have return successors, (0), 0 states have call predecessors, (0), 0 states have call successors, (0) Word has length 20 [2022-07-21 05:01:50,126 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2022-07-21 05:01:50,126 INFO L225 Difference]: With dead ends: 143 [2022-07-21 05:01:50,127 INFO L226 Difference]: Without dead ends: 82 [2022-07-21 05:01:50,127 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 3 GetRequests, 2 SyntacticMatches, 0 SemanticMatches, 1 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 0 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=3, Invalid=3, Unknown=0, NotChecked=0, Total=6 [2022-07-21 05:01:50,128 INFO L413 NwaCegarLoop]: 106 mSDtfsCounter, 17 mSDsluCounter, 84 mSDsCounter, 0 mSdLazyCounter, 1 mSolverCounterSat, 0 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.0s Time, 0 mProtectedPredicate, 0 mProtectedAction, 21 SdHoareTripleChecker+Valid, 190 SdHoareTripleChecker+Invalid, 1 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 0 IncrementalHoareTripleChecker+Valid, 1 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.0s IncrementalHoareTripleChecker+Time [2022-07-21 05:01:50,129 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [21 Valid, 190 Invalid, 1 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [0 Valid, 1 Invalid, 0 Unknown, 0 Unchecked, 0.0s Time] [2022-07-21 05:01:50,129 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 82 states. [2022-07-21 05:01:50,134 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 82 to 82. [2022-07-21 05:01:50,135 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 82 states, 62 states have (on average 1.3387096774193548) internal successors, (83), 72 states have internal predecessors, (83), 12 states have call successors, (12), 7 states have call predecessors, (12), 7 states have return successors, (12), 7 states have call predecessors, (12), 12 states have call successors, (12) [2022-07-21 05:01:50,136 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 82 states to 82 states and 107 transitions. [2022-07-21 05:01:50,136 INFO L78 Accepts]: Start accepts. Automaton has 82 states and 107 transitions. Word has length 20 [2022-07-21 05:01:50,136 INFO L84 Accepts]: Finished accepts. word is rejected. [2022-07-21 05:01:50,136 INFO L495 AbstractCegarLoop]: Abstraction has 82 states and 107 transitions. [2022-07-21 05:01:50,137 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 3 states, 3 states have (on average 6.0) internal successors, (18), 3 states have internal predecessors, (18), 1 states have call successors, (2), 1 states have call predecessors, (2), 0 states have return successors, (0), 0 states have call predecessors, (0), 0 states have call successors, (0) [2022-07-21 05:01:50,137 INFO L276 IsEmpty]: Start isEmpty. Operand 82 states and 107 transitions. [2022-07-21 05:01:50,137 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 26 [2022-07-21 05:01:50,138 INFO L187 NwaCegarLoop]: Found error trace [2022-07-21 05:01:50,138 INFO L195 NwaCegarLoop]: trace histogram [1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-07-21 05:01:50,138 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable1 [2022-07-21 05:01:50,138 INFO L420 AbstractCegarLoop]: === Iteration 3 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2022-07-21 05:01:50,139 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2022-07-21 05:01:50,139 INFO L85 PathProgramCache]: Analyzing trace with hash 1300509367, now seen corresponding path program 1 times [2022-07-21 05:01:50,139 INFO L118 FreeRefinementEngine]: Executing refinement strategy CAMEL [2022-07-21 05:01:50,139 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [1620328514] [2022-07-21 05:01:50,139 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-07-21 05:01:50,139 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2022-07-21 05:01:50,153 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-07-21 05:01:50,180 INFO L134 CoverageAnalysis]: Checked inductivity of 0 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2022-07-21 05:01:50,180 INFO L136 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2022-07-21 05:01:50,180 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [1620328514] [2022-07-21 05:01:50,180 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [1620328514] provided 1 perfect and 0 imperfect interpolant sequences [2022-07-21 05:01:50,181 INFO L184 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2022-07-21 05:01:50,181 INFO L197 FreeRefinementEngine]: Number of different interpolants: perfect sequences [5] imperfect sequences [] total 5 [2022-07-21 05:01:50,181 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [2010596257] [2022-07-21 05:01:50,181 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2022-07-21 05:01:50,181 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 5 states [2022-07-21 05:01:50,182 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2022-07-21 05:01:50,182 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 5 interpolants. [2022-07-21 05:01:50,182 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=7, Invalid=13, Unknown=0, NotChecked=0, Total=20 [2022-07-21 05:01:50,182 INFO L87 Difference]: Start difference. First operand 82 states and 107 transitions. Second operand has 5 states, 5 states have (on average 4.8) internal successors, (24), 5 states have internal predecessors, (24), 1 states have call successors, (1), 1 states have call predecessors, (1), 0 states have return successors, (0), 0 states have call predecessors, (0), 0 states have call successors, (0) [2022-07-21 05:01:50,246 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-07-21 05:01:50,246 INFO L93 Difference]: Finished difference Result 195 states and 258 transitions. [2022-07-21 05:01:50,246 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 6 states. [2022-07-21 05:01:50,247 INFO L78 Accepts]: Start accepts. Automaton has has 5 states, 5 states have (on average 4.8) internal successors, (24), 5 states have internal predecessors, (24), 1 states have call successors, (1), 1 states have call predecessors, (1), 0 states have return successors, (0), 0 states have call predecessors, (0), 0 states have call successors, (0) Word has length 25 [2022-07-21 05:01:50,247 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2022-07-21 05:01:50,248 INFO L225 Difference]: With dead ends: 195 [2022-07-21 05:01:50,248 INFO L226 Difference]: Without dead ends: 120 [2022-07-21 05:01:50,249 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 11 GetRequests, 5 SyntacticMatches, 0 SemanticMatches, 6 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 2 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=22, Invalid=34, Unknown=0, NotChecked=0, Total=56 [2022-07-21 05:01:50,249 INFO L413 NwaCegarLoop]: 115 mSDtfsCounter, 170 mSDsluCounter, 226 mSDsCounter, 0 mSdLazyCounter, 12 mSolverCounterSat, 21 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.0s Time, 0 mProtectedPredicate, 0 mProtectedAction, 170 SdHoareTripleChecker+Valid, 341 SdHoareTripleChecker+Invalid, 33 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 21 IncrementalHoareTripleChecker+Valid, 12 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.0s IncrementalHoareTripleChecker+Time [2022-07-21 05:01:50,250 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [170 Valid, 341 Invalid, 33 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [21 Valid, 12 Invalid, 0 Unknown, 0 Unchecked, 0.0s Time] [2022-07-21 05:01:50,250 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 120 states. [2022-07-21 05:01:50,259 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 120 to 117. [2022-07-21 05:01:50,259 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 117 states, 89 states have (on average 1.3595505617977528) internal successors, (121), 102 states have internal predecessors, (121), 16 states have call successors, (16), 11 states have call predecessors, (16), 11 states have return successors, (17), 10 states have call predecessors, (17), 16 states have call successors, (17) [2022-07-21 05:01:50,260 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 117 states to 117 states and 154 transitions. [2022-07-21 05:01:50,260 INFO L78 Accepts]: Start accepts. Automaton has 117 states and 154 transitions. Word has length 25 [2022-07-21 05:01:50,260 INFO L84 Accepts]: Finished accepts. word is rejected. [2022-07-21 05:01:50,261 INFO L495 AbstractCegarLoop]: Abstraction has 117 states and 154 transitions. [2022-07-21 05:01:50,261 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 5 states, 5 states have (on average 4.8) internal successors, (24), 5 states have internal predecessors, (24), 1 states have call successors, (1), 1 states have call predecessors, (1), 0 states have return successors, (0), 0 states have call predecessors, (0), 0 states have call successors, (0) [2022-07-21 05:01:50,261 INFO L276 IsEmpty]: Start isEmpty. Operand 117 states and 154 transitions. [2022-07-21 05:01:50,262 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 29 [2022-07-21 05:01:50,262 INFO L187 NwaCegarLoop]: Found error trace [2022-07-21 05:01:50,262 INFO L195 NwaCegarLoop]: trace histogram [1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-07-21 05:01:50,262 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable2 [2022-07-21 05:01:50,263 INFO L420 AbstractCegarLoop]: === Iteration 4 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2022-07-21 05:01:50,263 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2022-07-21 05:01:50,264 INFO L85 PathProgramCache]: Analyzing trace with hash 1710585576, now seen corresponding path program 1 times [2022-07-21 05:01:50,264 INFO L118 FreeRefinementEngine]: Executing refinement strategy CAMEL [2022-07-21 05:01:50,264 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [185378817] [2022-07-21 05:01:50,264 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-07-21 05:01:50,264 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2022-07-21 05:01:50,293 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-07-21 05:01:50,322 INFO L134 CoverageAnalysis]: Checked inductivity of 0 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2022-07-21 05:01:50,322 INFO L136 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2022-07-21 05:01:50,323 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [185378817] [2022-07-21 05:01:50,323 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [185378817] provided 1 perfect and 0 imperfect interpolant sequences [2022-07-21 05:01:50,323 INFO L184 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2022-07-21 05:01:50,323 INFO L197 FreeRefinementEngine]: Number of different interpolants: perfect sequences [4] imperfect sequences [] total 4 [2022-07-21 05:01:50,323 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [328983243] [2022-07-21 05:01:50,324 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2022-07-21 05:01:50,324 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 5 states [2022-07-21 05:01:50,324 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2022-07-21 05:01:50,324 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 5 interpolants. [2022-07-21 05:01:50,325 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=7, Invalid=13, Unknown=0, NotChecked=0, Total=20 [2022-07-21 05:01:50,325 INFO L87 Difference]: Start difference. First operand 117 states and 154 transitions. Second operand has 5 states, 5 states have (on average 5.4) internal successors, (27), 4 states have internal predecessors, (27), 1 states have call successors, (1), 1 states have call predecessors, (1), 0 states have return successors, (0), 0 states have call predecessors, (0), 0 states have call successors, (0) [2022-07-21 05:01:50,376 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-07-21 05:01:50,377 INFO L93 Difference]: Finished difference Result 325 states and 449 transitions. [2022-07-21 05:01:50,377 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 5 states. [2022-07-21 05:01:50,377 INFO L78 Accepts]: Start accepts. Automaton has has 5 states, 5 states have (on average 5.4) internal successors, (27), 4 states have internal predecessors, (27), 1 states have call successors, (1), 1 states have call predecessors, (1), 0 states have return successors, (0), 0 states have call predecessors, (0), 0 states have call successors, (0) Word has length 28 [2022-07-21 05:01:50,378 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2022-07-21 05:01:50,379 INFO L225 Difference]: With dead ends: 325 [2022-07-21 05:01:50,379 INFO L226 Difference]: Without dead ends: 215 [2022-07-21 05:01:50,380 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 7 GetRequests, 2 SyntacticMatches, 0 SemanticMatches, 5 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 0 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=17, Invalid=25, Unknown=0, NotChecked=0, Total=42 [2022-07-21 05:01:50,381 INFO L413 NwaCegarLoop]: 112 mSDtfsCounter, 78 mSDsluCounter, 318 mSDsCounter, 0 mSdLazyCounter, 29 mSolverCounterSat, 4 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.0s Time, 0 mProtectedPredicate, 0 mProtectedAction, 78 SdHoareTripleChecker+Valid, 430 SdHoareTripleChecker+Invalid, 33 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 4 IncrementalHoareTripleChecker+Valid, 29 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.0s IncrementalHoareTripleChecker+Time [2022-07-21 05:01:50,382 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [78 Valid, 430 Invalid, 33 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [4 Valid, 29 Invalid, 0 Unknown, 0 Unchecked, 0.0s Time] [2022-07-21 05:01:50,382 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 215 states. [2022-07-21 05:01:50,398 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 215 to 215. [2022-07-21 05:01:50,399 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 215 states, 162 states have (on average 1.3395061728395061) internal successors, (217), 185 states have internal predecessors, (217), 32 states have call successors, (32), 22 states have call predecessors, (32), 20 states have return successors, (37), 18 states have call predecessors, (37), 32 states have call successors, (37) [2022-07-21 05:01:50,400 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 215 states to 215 states and 286 transitions. [2022-07-21 05:01:50,401 INFO L78 Accepts]: Start accepts. Automaton has 215 states and 286 transitions. Word has length 28 [2022-07-21 05:01:50,401 INFO L84 Accepts]: Finished accepts. word is rejected. [2022-07-21 05:01:50,401 INFO L495 AbstractCegarLoop]: Abstraction has 215 states and 286 transitions. [2022-07-21 05:01:50,401 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 5 states, 5 states have (on average 5.4) internal successors, (27), 4 states have internal predecessors, (27), 1 states have call successors, (1), 1 states have call predecessors, (1), 0 states have return successors, (0), 0 states have call predecessors, (0), 0 states have call successors, (0) [2022-07-21 05:01:50,401 INFO L276 IsEmpty]: Start isEmpty. Operand 215 states and 286 transitions. [2022-07-21 05:01:50,403 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 31 [2022-07-21 05:01:50,403 INFO L187 NwaCegarLoop]: Found error trace [2022-07-21 05:01:50,403 INFO L195 NwaCegarLoop]: trace histogram [1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-07-21 05:01:50,404 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable3 [2022-07-21 05:01:50,404 INFO L420 AbstractCegarLoop]: === Iteration 5 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2022-07-21 05:01:50,404 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2022-07-21 05:01:50,404 INFO L85 PathProgramCache]: Analyzing trace with hash 298834221, now seen corresponding path program 1 times [2022-07-21 05:01:50,405 INFO L118 FreeRefinementEngine]: Executing refinement strategy CAMEL [2022-07-21 05:01:50,405 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [2133402236] [2022-07-21 05:01:50,405 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-07-21 05:01:50,405 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2022-07-21 05:01:50,416 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-07-21 05:01:50,434 INFO L134 CoverageAnalysis]: Checked inductivity of 0 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2022-07-21 05:01:50,434 INFO L136 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2022-07-21 05:01:50,434 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [2133402236] [2022-07-21 05:01:50,434 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [2133402236] provided 1 perfect and 0 imperfect interpolant sequences [2022-07-21 05:01:50,435 INFO L184 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2022-07-21 05:01:50,435 INFO L197 FreeRefinementEngine]: Number of different interpolants: perfect sequences [2] imperfect sequences [] total 2 [2022-07-21 05:01:50,435 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [451877822] [2022-07-21 05:01:50,435 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2022-07-21 05:01:50,436 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 3 states [2022-07-21 05:01:50,436 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2022-07-21 05:01:50,436 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 3 interpolants. [2022-07-21 05:01:50,436 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=3, Invalid=3, Unknown=0, NotChecked=0, Total=6 [2022-07-21 05:01:50,437 INFO L87 Difference]: Start difference. First operand 215 states and 286 transitions. Second operand has 3 states, 3 states have (on average 9.666666666666666) internal successors, (29), 2 states have internal predecessors, (29), 1 states have call successors, (1), 1 states have call predecessors, (1), 0 states have return successors, (0), 0 states have call predecessors, (0), 0 states have call successors, (0) [2022-07-21 05:01:50,487 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-07-21 05:01:50,493 INFO L93 Difference]: Finished difference Result 473 states and 648 transitions. [2022-07-21 05:01:50,494 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 3 states. [2022-07-21 05:01:50,494 INFO L78 Accepts]: Start accepts. Automaton has has 3 states, 3 states have (on average 9.666666666666666) internal successors, (29), 2 states have internal predecessors, (29), 1 states have call successors, (1), 1 states have call predecessors, (1), 0 states have return successors, (0), 0 states have call predecessors, (0), 0 states have call successors, (0) Word has length 30 [2022-07-21 05:01:50,494 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2022-07-21 05:01:50,496 INFO L225 Difference]: With dead ends: 473 [2022-07-21 05:01:50,496 INFO L226 Difference]: Without dead ends: 265 [2022-07-21 05:01:50,498 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 3 GetRequests, 2 SyntacticMatches, 0 SemanticMatches, 1 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 0 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=3, Invalid=3, Unknown=0, NotChecked=0, Total=6 [2022-07-21 05:01:50,512 INFO L413 NwaCegarLoop]: 112 mSDtfsCounter, 59 mSDsluCounter, 69 mSDsCounter, 0 mSdLazyCounter, 13 mSolverCounterSat, 10 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.0s Time, 0 mProtectedPredicate, 0 mProtectedAction, 59 SdHoareTripleChecker+Valid, 181 SdHoareTripleChecker+Invalid, 23 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 10 IncrementalHoareTripleChecker+Valid, 13 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.0s IncrementalHoareTripleChecker+Time [2022-07-21 05:01:50,512 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [59 Valid, 181 Invalid, 23 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [10 Valid, 13 Invalid, 0 Unknown, 0 Unchecked, 0.0s Time] [2022-07-21 05:01:50,513 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 265 states. [2022-07-21 05:01:50,529 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 265 to 261. [2022-07-21 05:01:50,544 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 261 states, 201 states have (on average 1.2835820895522387) internal successors, (258), 216 states have internal predecessors, (258), 31 states have call successors, (31), 29 states have call predecessors, (31), 28 states have return successors, (47), 28 states have call predecessors, (47), 31 states have call successors, (47) [2022-07-21 05:01:50,545 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 261 states to 261 states and 336 transitions. [2022-07-21 05:01:50,545 INFO L78 Accepts]: Start accepts. Automaton has 261 states and 336 transitions. Word has length 30 [2022-07-21 05:01:50,546 INFO L84 Accepts]: Finished accepts. word is rejected. [2022-07-21 05:01:50,546 INFO L495 AbstractCegarLoop]: Abstraction has 261 states and 336 transitions. [2022-07-21 05:01:50,546 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 3 states, 3 states have (on average 9.666666666666666) internal successors, (29), 2 states have internal predecessors, (29), 1 states have call successors, (1), 1 states have call predecessors, (1), 0 states have return successors, (0), 0 states have call predecessors, (0), 0 states have call successors, (0) [2022-07-21 05:01:50,546 INFO L276 IsEmpty]: Start isEmpty. Operand 261 states and 336 transitions. [2022-07-21 05:01:50,547 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 33 [2022-07-21 05:01:50,547 INFO L187 NwaCegarLoop]: Found error trace [2022-07-21 05:01:50,547 INFO L195 NwaCegarLoop]: trace histogram [1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-07-21 05:01:50,548 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable4 [2022-07-21 05:01:50,548 INFO L420 AbstractCegarLoop]: === Iteration 6 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2022-07-21 05:01:50,548 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2022-07-21 05:01:50,548 INFO L85 PathProgramCache]: Analyzing trace with hash -1545723250, now seen corresponding path program 1 times [2022-07-21 05:01:50,548 INFO L118 FreeRefinementEngine]: Executing refinement strategy CAMEL [2022-07-21 05:01:50,549 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [17485241] [2022-07-21 05:01:50,549 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-07-21 05:01:50,549 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2022-07-21 05:01:50,560 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-07-21 05:01:50,621 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 11 [2022-07-21 05:01:50,623 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-07-21 05:01:50,632 INFO L134 CoverageAnalysis]: Checked inductivity of 0 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2022-07-21 05:01:50,632 INFO L136 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2022-07-21 05:01:50,632 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [17485241] [2022-07-21 05:01:50,632 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [17485241] provided 1 perfect and 0 imperfect interpolant sequences [2022-07-21 05:01:50,632 INFO L184 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2022-07-21 05:01:50,632 INFO L197 FreeRefinementEngine]: Number of different interpolants: perfect sequences [6] imperfect sequences [] total 6 [2022-07-21 05:01:50,633 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [1448869783] [2022-07-21 05:01:50,633 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2022-07-21 05:01:50,633 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 6 states [2022-07-21 05:01:50,633 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2022-07-21 05:01:50,633 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 6 interpolants. [2022-07-21 05:01:50,633 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=9, Invalid=21, Unknown=0, NotChecked=0, Total=30 [2022-07-21 05:01:50,634 INFO L87 Difference]: Start difference. First operand 261 states and 336 transitions. Second operand has 6 states, 6 states have (on average 4.833333333333333) internal successors, (29), 5 states have internal predecessors, (29), 1 states have call successors, (2), 2 states have call predecessors, (2), 1 states have return successors, (1), 1 states have call predecessors, (1), 1 states have call successors, (1) [2022-07-21 05:01:50,950 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-07-21 05:01:50,951 INFO L93 Difference]: Finished difference Result 313 states and 403 transitions. [2022-07-21 05:01:50,951 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 11 states. [2022-07-21 05:01:50,951 INFO L78 Accepts]: Start accepts. Automaton has has 6 states, 6 states have (on average 4.833333333333333) internal successors, (29), 5 states have internal predecessors, (29), 1 states have call successors, (2), 2 states have call predecessors, (2), 1 states have return successors, (1), 1 states have call predecessors, (1), 1 states have call successors, (1) Word has length 32 [2022-07-21 05:01:50,952 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2022-07-21 05:01:50,959 INFO L225 Difference]: With dead ends: 313 [2022-07-21 05:01:50,959 INFO L226 Difference]: Without dead ends: 311 [2022-07-21 05:01:50,961 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 14 GetRequests, 4 SyntacticMatches, 0 SemanticMatches, 10 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 12 ImplicationChecksByTransitivity, 0.1s TimeCoverageRelationStatistics Valid=45, Invalid=87, Unknown=0, NotChecked=0, Total=132 [2022-07-21 05:01:50,968 INFO L413 NwaCegarLoop]: 111 mSDtfsCounter, 141 mSDsluCounter, 242 mSDsCounter, 0 mSdLazyCounter, 220 mSolverCounterSat, 42 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.2s Time, 0 mProtectedPredicate, 0 mProtectedAction, 148 SdHoareTripleChecker+Valid, 353 SdHoareTripleChecker+Invalid, 262 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 42 IncrementalHoareTripleChecker+Valid, 220 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.2s IncrementalHoareTripleChecker+Time [2022-07-21 05:01:50,970 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [148 Valid, 353 Invalid, 262 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [42 Valid, 220 Invalid, 0 Unknown, 0 Unchecked, 0.2s Time] [2022-07-21 05:01:50,977 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 311 states. [2022-07-21 05:01:51,005 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 311 to 294. [2022-07-21 05:01:51,007 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 294 states, 226 states have (on average 1.2654867256637168) internal successors, (286), 247 states have internal predecessors, (286), 34 states have call successors, (34), 29 states have call predecessors, (34), 33 states have return successors, (57), 30 states have call predecessors, (57), 34 states have call successors, (57) [2022-07-21 05:01:51,008 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 294 states to 294 states and 377 transitions. [2022-07-21 05:01:51,009 INFO L78 Accepts]: Start accepts. Automaton has 294 states and 377 transitions. Word has length 32 [2022-07-21 05:01:51,009 INFO L84 Accepts]: Finished accepts. word is rejected. [2022-07-21 05:01:51,009 INFO L495 AbstractCegarLoop]: Abstraction has 294 states and 377 transitions. [2022-07-21 05:01:51,009 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 6 states, 6 states have (on average 4.833333333333333) internal successors, (29), 5 states have internal predecessors, (29), 1 states have call successors, (2), 2 states have call predecessors, (2), 1 states have return successors, (1), 1 states have call predecessors, (1), 1 states have call successors, (1) [2022-07-21 05:01:51,009 INFO L276 IsEmpty]: Start isEmpty. Operand 294 states and 377 transitions. [2022-07-21 05:01:51,011 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 49 [2022-07-21 05:01:51,011 INFO L187 NwaCegarLoop]: Found error trace [2022-07-21 05:01:51,011 INFO L195 NwaCegarLoop]: trace histogram [1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-07-21 05:01:51,012 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable5 [2022-07-21 05:01:51,012 INFO L420 AbstractCegarLoop]: === Iteration 7 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2022-07-21 05:01:51,012 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2022-07-21 05:01:51,012 INFO L85 PathProgramCache]: Analyzing trace with hash -766960693, now seen corresponding path program 1 times [2022-07-21 05:01:51,012 INFO L118 FreeRefinementEngine]: Executing refinement strategy CAMEL [2022-07-21 05:01:51,012 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [741807347] [2022-07-21 05:01:51,012 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-07-21 05:01:51,013 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2022-07-21 05:01:51,052 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-07-21 05:01:51,065 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 11 [2022-07-21 05:01:51,066 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-07-21 05:01:51,070 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 24 [2022-07-21 05:01:51,073 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-07-21 05:01:51,076 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 2 [2022-07-21 05:01:51,078 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-07-21 05:01:51,096 INFO L134 CoverageAnalysis]: Checked inductivity of 0 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2022-07-21 05:01:51,096 INFO L136 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2022-07-21 05:01:51,096 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [741807347] [2022-07-21 05:01:51,097 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [741807347] provided 1 perfect and 0 imperfect interpolant sequences [2022-07-21 05:01:51,097 INFO L184 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2022-07-21 05:01:51,097 INFO L197 FreeRefinementEngine]: Number of different interpolants: perfect sequences [7] imperfect sequences [] total 7 [2022-07-21 05:01:51,097 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [1476133979] [2022-07-21 05:01:51,097 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2022-07-21 05:01:51,097 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 7 states [2022-07-21 05:01:51,097 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2022-07-21 05:01:51,098 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 7 interpolants. [2022-07-21 05:01:51,098 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=11, Invalid=31, Unknown=0, NotChecked=0, Total=42 [2022-07-21 05:01:51,098 INFO L87 Difference]: Start difference. First operand 294 states and 377 transitions. Second operand has 7 states, 7 states have (on average 5.857142857142857) internal successors, (41), 5 states have internal predecessors, (41), 1 states have call successors, (4), 3 states have call predecessors, (4), 2 states have return successors, (3), 2 states have call predecessors, (3), 1 states have call successors, (3) [2022-07-21 05:01:51,342 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-07-21 05:01:51,343 INFO L93 Difference]: Finished difference Result 641 states and 835 transitions. [2022-07-21 05:01:51,343 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 9 states. [2022-07-21 05:01:51,343 INFO L78 Accepts]: Start accepts. Automaton has has 7 states, 7 states have (on average 5.857142857142857) internal successors, (41), 5 states have internal predecessors, (41), 1 states have call successors, (4), 3 states have call predecessors, (4), 2 states have return successors, (3), 2 states have call predecessors, (3), 1 states have call successors, (3) Word has length 48 [2022-07-21 05:01:51,344 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2022-07-21 05:01:51,350 INFO L225 Difference]: With dead ends: 641 [2022-07-21 05:01:51,350 INFO L226 Difference]: Without dead ends: 354 [2022-07-21 05:01:51,354 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 19 GetRequests, 9 SyntacticMatches, 0 SemanticMatches, 10 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 3 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=46, Invalid=86, Unknown=0, NotChecked=0, Total=132 [2022-07-21 05:01:51,357 INFO L413 NwaCegarLoop]: 97 mSDtfsCounter, 145 mSDsluCounter, 253 mSDsCounter, 0 mSdLazyCounter, 279 mSolverCounterSat, 52 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.1s Time, 0 mProtectedPredicate, 0 mProtectedAction, 145 SdHoareTripleChecker+Valid, 350 SdHoareTripleChecker+Invalid, 331 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 52 IncrementalHoareTripleChecker+Valid, 279 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.2s IncrementalHoareTripleChecker+Time [2022-07-21 05:01:51,358 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [145 Valid, 350 Invalid, 331 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [52 Valid, 279 Invalid, 0 Unknown, 0 Unchecked, 0.2s Time] [2022-07-21 05:01:51,359 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 354 states. [2022-07-21 05:01:51,395 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 354 to 324. [2022-07-21 05:01:51,399 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 324 states, 251 states have (on average 1.250996015936255) internal successors, (314), 272 states have internal predecessors, (314), 34 states have call successors, (34), 29 states have call predecessors, (34), 38 states have return successors, (64), 34 states have call predecessors, (64), 34 states have call successors, (64) [2022-07-21 05:01:51,401 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 324 states to 324 states and 412 transitions. [2022-07-21 05:01:51,404 INFO L78 Accepts]: Start accepts. Automaton has 324 states and 412 transitions. Word has length 48 [2022-07-21 05:01:51,404 INFO L84 Accepts]: Finished accepts. word is rejected. [2022-07-21 05:01:51,406 INFO L495 AbstractCegarLoop]: Abstraction has 324 states and 412 transitions. [2022-07-21 05:01:51,406 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 7 states, 7 states have (on average 5.857142857142857) internal successors, (41), 5 states have internal predecessors, (41), 1 states have call successors, (4), 3 states have call predecessors, (4), 2 states have return successors, (3), 2 states have call predecessors, (3), 1 states have call successors, (3) [2022-07-21 05:01:51,406 INFO L276 IsEmpty]: Start isEmpty. Operand 324 states and 412 transitions. [2022-07-21 05:01:51,407 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 52 [2022-07-21 05:01:51,409 INFO L187 NwaCegarLoop]: Found error trace [2022-07-21 05:01:51,409 INFO L195 NwaCegarLoop]: trace histogram [1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-07-21 05:01:51,410 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable6 [2022-07-21 05:01:51,411 INFO L420 AbstractCegarLoop]: === Iteration 8 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2022-07-21 05:01:51,412 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2022-07-21 05:01:51,413 INFO L85 PathProgramCache]: Analyzing trace with hash 1932063404, now seen corresponding path program 1 times [2022-07-21 05:01:51,413 INFO L118 FreeRefinementEngine]: Executing refinement strategy CAMEL [2022-07-21 05:01:51,413 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [1735462032] [2022-07-21 05:01:51,414 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-07-21 05:01:51,414 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2022-07-21 05:01:51,424 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-07-21 05:01:51,452 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 11 [2022-07-21 05:01:51,455 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-07-21 05:01:51,463 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 27 [2022-07-21 05:01:51,477 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-07-21 05:01:51,480 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 2 [2022-07-21 05:01:51,485 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-07-21 05:01:51,492 INFO L134 CoverageAnalysis]: Checked inductivity of 0 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2022-07-21 05:01:51,492 INFO L136 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2022-07-21 05:01:51,493 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [1735462032] [2022-07-21 05:01:51,493 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [1735462032] provided 1 perfect and 0 imperfect interpolant sequences [2022-07-21 05:01:51,493 INFO L184 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2022-07-21 05:01:51,493 INFO L197 FreeRefinementEngine]: Number of different interpolants: perfect sequences [5] imperfect sequences [] total 5 [2022-07-21 05:01:51,497 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [228093334] [2022-07-21 05:01:51,497 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2022-07-21 05:01:51,498 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 5 states [2022-07-21 05:01:51,498 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2022-07-21 05:01:51,498 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 5 interpolants. [2022-07-21 05:01:51,498 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=7, Invalid=13, Unknown=0, NotChecked=0, Total=20 [2022-07-21 05:01:51,499 INFO L87 Difference]: Start difference. First operand 324 states and 412 transitions. Second operand has 5 states, 5 states have (on average 8.8) internal successors, (44), 3 states have internal predecessors, (44), 3 states have call successors, (4), 3 states have call predecessors, (4), 1 states have return successors, (3), 2 states have call predecessors, (3), 2 states have call successors, (3) [2022-07-21 05:01:51,669 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-07-21 05:01:51,669 INFO L93 Difference]: Finished difference Result 669 states and 847 transitions. [2022-07-21 05:01:51,670 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 8 states. [2022-07-21 05:01:51,670 INFO L78 Accepts]: Start accepts. Automaton has has 5 states, 5 states have (on average 8.8) internal successors, (44), 3 states have internal predecessors, (44), 3 states have call successors, (4), 3 states have call predecessors, (4), 1 states have return successors, (3), 2 states have call predecessors, (3), 2 states have call successors, (3) Word has length 51 [2022-07-21 05:01:51,670 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2022-07-21 05:01:51,673 INFO L225 Difference]: With dead ends: 669 [2022-07-21 05:01:51,673 INFO L226 Difference]: Without dead ends: 352 [2022-07-21 05:01:51,674 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 14 GetRequests, 8 SyntacticMatches, 0 SemanticMatches, 6 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 2 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=22, Invalid=34, Unknown=0, NotChecked=0, Total=56 [2022-07-21 05:01:51,676 INFO L413 NwaCegarLoop]: 126 mSDtfsCounter, 167 mSDsluCounter, 163 mSDsCounter, 0 mSdLazyCounter, 158 mSolverCounterSat, 45 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.1s Time, 0 mProtectedPredicate, 0 mProtectedAction, 170 SdHoareTripleChecker+Valid, 289 SdHoareTripleChecker+Invalid, 203 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 45 IncrementalHoareTripleChecker+Valid, 158 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.1s IncrementalHoareTripleChecker+Time [2022-07-21 05:01:51,677 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [170 Valid, 289 Invalid, 203 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [45 Valid, 158 Invalid, 0 Unknown, 0 Unchecked, 0.1s Time] [2022-07-21 05:01:51,678 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 352 states. [2022-07-21 05:01:51,699 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 352 to 324. [2022-07-21 05:01:51,700 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 324 states, 251 states have (on average 1.2430278884462151) internal successors, (312), 272 states have internal predecessors, (312), 34 states have call successors, (34), 29 states have call predecessors, (34), 38 states have return successors, (60), 34 states have call predecessors, (60), 34 states have call successors, (60) [2022-07-21 05:01:51,701 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 324 states to 324 states and 406 transitions. [2022-07-21 05:01:51,701 INFO L78 Accepts]: Start accepts. Automaton has 324 states and 406 transitions. Word has length 51 [2022-07-21 05:01:51,703 INFO L84 Accepts]: Finished accepts. word is rejected. [2022-07-21 05:01:51,704 INFO L495 AbstractCegarLoop]: Abstraction has 324 states and 406 transitions. [2022-07-21 05:01:51,704 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 5 states, 5 states have (on average 8.8) internal successors, (44), 3 states have internal predecessors, (44), 3 states have call successors, (4), 3 states have call predecessors, (4), 1 states have return successors, (3), 2 states have call predecessors, (3), 2 states have call successors, (3) [2022-07-21 05:01:51,704 INFO L276 IsEmpty]: Start isEmpty. Operand 324 states and 406 transitions. [2022-07-21 05:01:51,708 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 49 [2022-07-21 05:01:51,708 INFO L187 NwaCegarLoop]: Found error trace [2022-07-21 05:01:51,708 INFO L195 NwaCegarLoop]: trace histogram [1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-07-21 05:01:51,709 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable7 [2022-07-21 05:01:51,709 INFO L420 AbstractCegarLoop]: === Iteration 9 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2022-07-21 05:01:51,709 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2022-07-21 05:01:51,709 INFO L85 PathProgramCache]: Analyzing trace with hash -1788029047, now seen corresponding path program 1 times [2022-07-21 05:01:51,709 INFO L118 FreeRefinementEngine]: Executing refinement strategy CAMEL [2022-07-21 05:01:51,710 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [1671556081] [2022-07-21 05:01:51,710 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-07-21 05:01:51,710 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2022-07-21 05:01:51,720 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-07-21 05:01:51,738 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 11 [2022-07-21 05:01:51,739 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-07-21 05:01:51,743 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 24 [2022-07-21 05:01:51,747 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-07-21 05:01:51,758 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 2 [2022-07-21 05:01:51,760 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-07-21 05:01:51,778 INFO L134 CoverageAnalysis]: Checked inductivity of 0 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2022-07-21 05:01:51,778 INFO L136 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2022-07-21 05:01:51,778 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [1671556081] [2022-07-21 05:01:51,779 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [1671556081] provided 1 perfect and 0 imperfect interpolant sequences [2022-07-21 05:01:51,779 INFO L184 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2022-07-21 05:01:51,779 INFO L197 FreeRefinementEngine]: Number of different interpolants: perfect sequences [8] imperfect sequences [] total 8 [2022-07-21 05:01:51,779 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [304334911] [2022-07-21 05:01:51,779 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2022-07-21 05:01:51,779 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 8 states [2022-07-21 05:01:51,780 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2022-07-21 05:01:51,780 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 8 interpolants. [2022-07-21 05:01:51,780 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=13, Invalid=43, Unknown=0, NotChecked=0, Total=56 [2022-07-21 05:01:51,780 INFO L87 Difference]: Start difference. First operand 324 states and 406 transitions. Second operand has 8 states, 8 states have (on average 5.125) internal successors, (41), 6 states have internal predecessors, (41), 1 states have call successors, (4), 3 states have call predecessors, (4), 2 states have return successors, (3), 2 states have call predecessors, (3), 1 states have call successors, (3) [2022-07-21 05:01:51,983 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-07-21 05:01:51,984 INFO L93 Difference]: Finished difference Result 637 states and 817 transitions. [2022-07-21 05:01:51,984 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 10 states. [2022-07-21 05:01:51,985 INFO L78 Accepts]: Start accepts. Automaton has has 8 states, 8 states have (on average 5.125) internal successors, (41), 6 states have internal predecessors, (41), 1 states have call successors, (4), 3 states have call predecessors, (4), 2 states have return successors, (3), 2 states have call predecessors, (3), 1 states have call successors, (3) Word has length 48 [2022-07-21 05:01:51,985 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2022-07-21 05:01:51,986 INFO L225 Difference]: With dead ends: 637 [2022-07-21 05:01:51,987 INFO L226 Difference]: Without dead ends: 320 [2022-07-21 05:01:51,988 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 22 GetRequests, 11 SyntacticMatches, 0 SemanticMatches, 11 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 6 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=42, Invalid=114, Unknown=0, NotChecked=0, Total=156 [2022-07-21 05:01:51,990 INFO L413 NwaCegarLoop]: 93 mSDtfsCounter, 203 mSDsluCounter, 256 mSDsCounter, 0 mSdLazyCounter, 342 mSolverCounterSat, 71 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.1s Time, 0 mProtectedPredicate, 0 mProtectedAction, 203 SdHoareTripleChecker+Valid, 349 SdHoareTripleChecker+Invalid, 413 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 71 IncrementalHoareTripleChecker+Valid, 342 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.2s IncrementalHoareTripleChecker+Time [2022-07-21 05:01:51,990 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [203 Valid, 349 Invalid, 413 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [71 Valid, 342 Invalid, 0 Unknown, 0 Unchecked, 0.2s Time] [2022-07-21 05:01:51,991 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 320 states. [2022-07-21 05:01:52,008 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 320 to 266. [2022-07-21 05:01:52,009 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 266 states, 206 states have (on average 1.2378640776699028) internal successors, (255), 223 states have internal predecessors, (255), 29 states have call successors, (29), 25 states have call predecessors, (29), 30 states have return successors, (46), 27 states have call predecessors, (46), 29 states have call successors, (46) [2022-07-21 05:01:52,011 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 266 states to 266 states and 330 transitions. [2022-07-21 05:01:52,012 INFO L78 Accepts]: Start accepts. Automaton has 266 states and 330 transitions. Word has length 48 [2022-07-21 05:01:52,012 INFO L84 Accepts]: Finished accepts. word is rejected. [2022-07-21 05:01:52,012 INFO L495 AbstractCegarLoop]: Abstraction has 266 states and 330 transitions. [2022-07-21 05:01:52,013 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 8 states, 8 states have (on average 5.125) internal successors, (41), 6 states have internal predecessors, (41), 1 states have call successors, (4), 3 states have call predecessors, (4), 2 states have return successors, (3), 2 states have call predecessors, (3), 1 states have call successors, (3) [2022-07-21 05:01:52,013 INFO L276 IsEmpty]: Start isEmpty. Operand 266 states and 330 transitions. [2022-07-21 05:01:52,013 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 49 [2022-07-21 05:01:52,013 INFO L187 NwaCegarLoop]: Found error trace [2022-07-21 05:01:52,014 INFO L195 NwaCegarLoop]: trace histogram [1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-07-21 05:01:52,014 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable8 [2022-07-21 05:01:52,014 INFO L420 AbstractCegarLoop]: === Iteration 10 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2022-07-21 05:01:52,014 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2022-07-21 05:01:52,014 INFO L85 PathProgramCache]: Analyzing trace with hash 512793543, now seen corresponding path program 1 times [2022-07-21 05:01:52,015 INFO L118 FreeRefinementEngine]: Executing refinement strategy CAMEL [2022-07-21 05:01:52,015 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [41584330] [2022-07-21 05:01:52,015 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-07-21 05:01:52,015 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2022-07-21 05:01:52,042 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-07-21 05:01:52,083 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 11 [2022-07-21 05:01:52,085 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-07-21 05:01:52,091 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 24 [2022-07-21 05:01:52,096 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-07-21 05:01:52,103 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 2 [2022-07-21 05:01:52,111 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-07-21 05:01:52,117 INFO L134 CoverageAnalysis]: Checked inductivity of 0 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2022-07-21 05:01:52,117 INFO L136 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2022-07-21 05:01:52,117 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [41584330] [2022-07-21 05:01:52,117 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [41584330] provided 1 perfect and 0 imperfect interpolant sequences [2022-07-21 05:01:52,118 INFO L184 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2022-07-21 05:01:52,118 INFO L197 FreeRefinementEngine]: Number of different interpolants: perfect sequences [7] imperfect sequences [] total 7 [2022-07-21 05:01:52,118 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [1384655650] [2022-07-21 05:01:52,118 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2022-07-21 05:01:52,118 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 7 states [2022-07-21 05:01:52,119 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2022-07-21 05:01:52,119 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 7 interpolants. [2022-07-21 05:01:52,119 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=11, Invalid=31, Unknown=0, NotChecked=0, Total=42 [2022-07-21 05:01:52,119 INFO L87 Difference]: Start difference. First operand 266 states and 330 transitions. Second operand has 7 states, 7 states have (on average 5.857142857142857) internal successors, (41), 5 states have internal predecessors, (41), 1 states have call successors, (4), 3 states have call predecessors, (4), 2 states have return successors, (3), 2 states have call predecessors, (3), 1 states have call successors, (3) [2022-07-21 05:01:52,422 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-07-21 05:01:52,422 INFO L93 Difference]: Finished difference Result 591 states and 775 transitions. [2022-07-21 05:01:52,423 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 17 states. [2022-07-21 05:01:52,423 INFO L78 Accepts]: Start accepts. Automaton has has 7 states, 7 states have (on average 5.857142857142857) internal successors, (41), 5 states have internal predecessors, (41), 1 states have call successors, (4), 3 states have call predecessors, (4), 2 states have return successors, (3), 2 states have call predecessors, (3), 1 states have call successors, (3) Word has length 48 [2022-07-21 05:01:52,423 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2022-07-21 05:01:52,425 INFO L225 Difference]: With dead ends: 591 [2022-07-21 05:01:52,425 INFO L226 Difference]: Without dead ends: 405 [2022-07-21 05:01:52,426 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 27 GetRequests, 8 SyntacticMatches, 2 SemanticMatches, 17 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 54 ImplicationChecksByTransitivity, 0.1s TimeCoverageRelationStatistics Valid=106, Invalid=236, Unknown=0, NotChecked=0, Total=342 [2022-07-21 05:01:52,426 INFO L413 NwaCegarLoop]: 144 mSDtfsCounter, 205 mSDsluCounter, 338 mSDsCounter, 0 mSdLazyCounter, 395 mSolverCounterSat, 76 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.2s Time, 0 mProtectedPredicate, 0 mProtectedAction, 207 SdHoareTripleChecker+Valid, 482 SdHoareTripleChecker+Invalid, 471 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 76 IncrementalHoareTripleChecker+Valid, 395 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.2s IncrementalHoareTripleChecker+Time [2022-07-21 05:01:52,426 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [207 Valid, 482 Invalid, 471 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [76 Valid, 395 Invalid, 0 Unknown, 0 Unchecked, 0.2s Time] [2022-07-21 05:01:52,427 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 405 states. [2022-07-21 05:01:52,440 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 405 to 394. [2022-07-21 05:01:52,440 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 394 states, 306 states have (on average 1.2189542483660132) internal successors, (373), 328 states have internal predecessors, (373), 43 states have call successors, (43), 38 states have call predecessors, (43), 44 states have return successors, (81), 44 states have call predecessors, (81), 43 states have call successors, (81) [2022-07-21 05:01:52,442 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 394 states to 394 states and 497 transitions. [2022-07-21 05:01:52,442 INFO L78 Accepts]: Start accepts. Automaton has 394 states and 497 transitions. Word has length 48 [2022-07-21 05:01:52,442 INFO L84 Accepts]: Finished accepts. word is rejected. [2022-07-21 05:01:52,442 INFO L495 AbstractCegarLoop]: Abstraction has 394 states and 497 transitions. [2022-07-21 05:01:52,442 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 7 states, 7 states have (on average 5.857142857142857) internal successors, (41), 5 states have internal predecessors, (41), 1 states have call successors, (4), 3 states have call predecessors, (4), 2 states have return successors, (3), 2 states have call predecessors, (3), 1 states have call successors, (3) [2022-07-21 05:01:52,443 INFO L276 IsEmpty]: Start isEmpty. Operand 394 states and 497 transitions. [2022-07-21 05:01:52,444 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 92 [2022-07-21 05:01:52,444 INFO L187 NwaCegarLoop]: Found error trace [2022-07-21 05:01:52,444 INFO L195 NwaCegarLoop]: trace histogram [2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-07-21 05:01:52,444 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable9 [2022-07-21 05:01:52,445 INFO L420 AbstractCegarLoop]: === Iteration 11 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2022-07-21 05:01:52,445 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2022-07-21 05:01:52,445 INFO L85 PathProgramCache]: Analyzing trace with hash -1953453445, now seen corresponding path program 1 times [2022-07-21 05:01:52,445 INFO L118 FreeRefinementEngine]: Executing refinement strategy CAMEL [2022-07-21 05:01:52,445 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [1774895659] [2022-07-21 05:01:52,445 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-07-21 05:01:52,446 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2022-07-21 05:01:52,459 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-07-21 05:01:52,487 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 11 [2022-07-21 05:01:52,488 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-07-21 05:01:52,494 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 20 [2022-07-21 05:01:52,496 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-07-21 05:01:52,506 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 3 [2022-07-21 05:01:52,508 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-07-21 05:01:52,520 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 2 [2022-07-21 05:01:52,522 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-07-21 05:01:52,527 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 66 [2022-07-21 05:01:52,528 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-07-21 05:01:52,530 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 7 [2022-07-21 05:01:52,531 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-07-21 05:01:52,532 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 2 [2022-07-21 05:01:52,532 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-07-21 05:01:52,533 INFO L134 CoverageAnalysis]: Checked inductivity of 25 backedges. 12 proven. 9 refuted. 0 times theorem prover too weak. 4 trivial. 0 not checked. [2022-07-21 05:01:52,533 INFO L136 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2022-07-21 05:01:52,533 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [1774895659] [2022-07-21 05:01:52,533 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [1774895659] provided 0 perfect and 1 imperfect interpolant sequences [2022-07-21 05:01:52,534 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleZ3 [1437319473] [2022-07-21 05:01:52,534 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-07-21 05:01:52,534 INFO L173 SolverBuilder]: Constructing external solver with command: z3 -smt2 -in SMTLIB2_COMPLIANT=true [2022-07-21 05:01:52,534 INFO L189 MonitoredProcess]: No working directory specified, using /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 [2022-07-21 05:01:52,535 INFO L229 MonitoredProcess]: Starting monitored process 2 with /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 -smt2 -in SMTLIB2_COMPLIANT=true (exit command is (exit), workingDir is null) [2022-07-21 05:01:52,581 INFO L327 MonitoredProcess]: [MP /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 -smt2 -in SMTLIB2_COMPLIANT=true (2)] Waiting until timeout for monitored process [2022-07-21 05:01:52,647 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-07-21 05:01:52,650 INFO L263 TraceCheckSpWp]: Trace formula consists of 460 conjuncts, 8 conjunts are in the unsatisfiable core [2022-07-21 05:01:52,655 INFO L286 TraceCheckSpWp]: Computing forward predicates... [2022-07-21 05:01:52,739 INFO L134 CoverageAnalysis]: Checked inductivity of 25 backedges. 17 proven. 8 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2022-07-21 05:01:52,739 INFO L328 TraceCheckSpWp]: Computing backward predicates... [2022-07-21 05:01:52,836 INFO L134 CoverageAnalysis]: Checked inductivity of 25 backedges. 13 proven. 8 refuted. 0 times theorem prover too weak. 4 trivial. 0 not checked. [2022-07-21 05:01:52,836 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleZ3 [1437319473] provided 0 perfect and 2 imperfect interpolant sequences [2022-07-21 05:01:52,836 INFO L184 FreeRefinementEngine]: Found 0 perfect and 3 imperfect interpolant sequences. [2022-07-21 05:01:52,836 INFO L197 FreeRefinementEngine]: Number of different interpolants: perfect sequences [] imperfect sequences [9, 6, 6] total 9 [2022-07-21 05:01:52,837 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [492348469] [2022-07-21 05:01:52,837 INFO L85 oduleStraightlineAll]: Using 3 imperfect interpolants to construct interpolant automaton [2022-07-21 05:01:52,837 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 9 states [2022-07-21 05:01:52,837 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2022-07-21 05:01:52,838 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 9 interpolants. [2022-07-21 05:01:52,838 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=18, Invalid=54, Unknown=0, NotChecked=0, Total=72 [2022-07-21 05:01:52,838 INFO L87 Difference]: Start difference. First operand 394 states and 497 transitions. Second operand has 9 states, 9 states have (on average 10.0) internal successors, (90), 6 states have internal predecessors, (90), 3 states have call successors, (17), 6 states have call predecessors, (17), 3 states have return successors, (10), 3 states have call predecessors, (10), 2 states have call successors, (10) [2022-07-21 05:01:53,465 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-07-21 05:01:53,465 INFO L93 Difference]: Finished difference Result 938 states and 1245 transitions. [2022-07-21 05:01:53,466 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 27 states. [2022-07-21 05:01:53,466 INFO L78 Accepts]: Start accepts. Automaton has has 9 states, 9 states have (on average 10.0) internal successors, (90), 6 states have internal predecessors, (90), 3 states have call successors, (17), 6 states have call predecessors, (17), 3 states have return successors, (10), 3 states have call predecessors, (10), 2 states have call successors, (10) Word has length 91 [2022-07-21 05:01:53,467 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2022-07-21 05:01:53,469 INFO L225 Difference]: With dead ends: 938 [2022-07-21 05:01:53,470 INFO L226 Difference]: Without dead ends: 624 [2022-07-21 05:01:53,471 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 230 GetRequests, 198 SyntacticMatches, 5 SemanticMatches, 27 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 201 ImplicationChecksByTransitivity, 0.2s TimeCoverageRelationStatistics Valid=227, Invalid=585, Unknown=0, NotChecked=0, Total=812 [2022-07-21 05:01:53,472 INFO L413 NwaCegarLoop]: 146 mSDtfsCounter, 368 mSDsluCounter, 418 mSDsCounter, 0 mSdLazyCounter, 595 mSolverCounterSat, 152 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.3s Time, 0 mProtectedPredicate, 0 mProtectedAction, 374 SdHoareTripleChecker+Valid, 564 SdHoareTripleChecker+Invalid, 747 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 152 IncrementalHoareTripleChecker+Valid, 595 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.4s IncrementalHoareTripleChecker+Time [2022-07-21 05:01:53,472 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [374 Valid, 564 Invalid, 747 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [152 Valid, 595 Invalid, 0 Unknown, 0 Unchecked, 0.4s Time] [2022-07-21 05:01:53,473 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 624 states. [2022-07-21 05:01:53,497 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 624 to 540. [2022-07-21 05:01:53,498 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 540 states, 415 states have (on average 1.2265060240963856) internal successors, (509), 447 states have internal predecessors, (509), 62 states have call successors, (62), 54 states have call predecessors, (62), 62 states have return successors, (124), 59 states have call predecessors, (124), 62 states have call successors, (124) [2022-07-21 05:01:53,501 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 540 states to 540 states and 695 transitions. [2022-07-21 05:01:53,501 INFO L78 Accepts]: Start accepts. Automaton has 540 states and 695 transitions. Word has length 91 [2022-07-21 05:01:53,502 INFO L84 Accepts]: Finished accepts. word is rejected. [2022-07-21 05:01:53,502 INFO L495 AbstractCegarLoop]: Abstraction has 540 states and 695 transitions. [2022-07-21 05:01:53,502 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 9 states, 9 states have (on average 10.0) internal successors, (90), 6 states have internal predecessors, (90), 3 states have call successors, (17), 6 states have call predecessors, (17), 3 states have return successors, (10), 3 states have call predecessors, (10), 2 states have call successors, (10) [2022-07-21 05:01:53,503 INFO L276 IsEmpty]: Start isEmpty. Operand 540 states and 695 transitions. [2022-07-21 05:01:53,505 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 135 [2022-07-21 05:01:53,506 INFO L187 NwaCegarLoop]: Found error trace [2022-07-21 05:01:53,506 INFO L195 NwaCegarLoop]: trace histogram [3, 3, 3, 3, 3, 3, 3, 3, 3, 3, 3, 3, 3, 3, 3, 3, 3, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-07-21 05:01:53,541 INFO L540 MonitoredProcess]: [MP /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 -smt2 -in SMTLIB2_COMPLIANT=true (2)] Forceful destruction successful, exit code 0 [2022-07-21 05:01:53,725 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: 2 /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 -smt2 -in SMTLIB2_COMPLIANT=true,SelfDestructingSolverStorable10 [2022-07-21 05:01:53,726 INFO L420 AbstractCegarLoop]: === Iteration 12 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2022-07-21 05:01:53,727 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2022-07-21 05:01:53,727 INFO L85 PathProgramCache]: Analyzing trace with hash -91360441, now seen corresponding path program 2 times [2022-07-21 05:01:53,727 INFO L118 FreeRefinementEngine]: Executing refinement strategy CAMEL [2022-07-21 05:01:53,727 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [1723298670] [2022-07-21 05:01:53,727 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-07-21 05:01:53,727 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2022-07-21 05:01:53,745 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-07-21 05:01:53,783 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 11 [2022-07-21 05:01:53,784 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-07-21 05:01:53,789 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 20 [2022-07-21 05:01:53,792 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-07-21 05:01:53,814 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 3 [2022-07-21 05:01:53,816 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-07-21 05:01:53,820 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 2 [2022-07-21 05:01:53,822 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-07-21 05:01:53,826 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 57 [2022-07-21 05:01:53,830 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-07-21 05:01:53,887 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 8 [2022-07-21 05:01:53,890 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-07-21 05:01:53,915 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 7 [2022-07-21 05:01:53,916 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-07-21 05:01:53,917 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 2 [2022-07-21 05:01:53,918 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-07-21 05:01:53,919 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 109 [2022-07-21 05:01:53,921 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-07-21 05:01:53,923 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 7 [2022-07-21 05:01:53,924 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-07-21 05:01:53,925 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 2 [2022-07-21 05:01:53,925 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-07-21 05:01:53,926 INFO L134 CoverageAnalysis]: Checked inductivity of 93 backedges. 52 proven. 23 refuted. 0 times theorem prover too weak. 18 trivial. 0 not checked. [2022-07-21 05:01:53,927 INFO L136 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2022-07-21 05:01:53,927 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [1723298670] [2022-07-21 05:01:53,927 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [1723298670] provided 0 perfect and 1 imperfect interpolant sequences [2022-07-21 05:01:53,927 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleZ3 [288616164] [2022-07-21 05:01:53,927 INFO L93 rtionOrderModulation]: Changing assertion order to OUTSIDE_LOOP_FIRST1 [2022-07-21 05:01:53,927 INFO L173 SolverBuilder]: Constructing external solver with command: z3 -smt2 -in SMTLIB2_COMPLIANT=true [2022-07-21 05:01:53,928 INFO L189 MonitoredProcess]: No working directory specified, using /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 [2022-07-21 05:01:53,929 INFO L229 MonitoredProcess]: Starting monitored process 3 with /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 -smt2 -in SMTLIB2_COMPLIANT=true (exit command is (exit), workingDir is null) [2022-07-21 05:01:53,930 INFO L327 MonitoredProcess]: [MP /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 -smt2 -in SMTLIB2_COMPLIANT=true (3)] Waiting until timeout for monitored process [2022-07-21 05:01:54,052 INFO L228 tOrderPrioritization]: Assert order OUTSIDE_LOOP_FIRST1 issued 2 check-sat command(s) [2022-07-21 05:01:54,053 INFO L229 tOrderPrioritization]: Conjunction of SSA is unsat [2022-07-21 05:01:54,055 INFO L263 TraceCheckSpWp]: Trace formula consists of 571 conjuncts, 10 conjunts are in the unsatisfiable core [2022-07-21 05:01:54,058 INFO L286 TraceCheckSpWp]: Computing forward predicates... [2022-07-21 05:01:54,208 INFO L134 CoverageAnalysis]: Checked inductivity of 93 backedges. 78 proven. 0 refuted. 0 times theorem prover too weak. 15 trivial. 0 not checked. [2022-07-21 05:01:54,208 INFO L324 TraceCheckSpWp]: Omiting computation of backward sequence because forward sequence was already perfect [2022-07-21 05:01:54,208 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleZ3 [288616164] provided 1 perfect and 0 imperfect interpolant sequences [2022-07-21 05:01:54,208 INFO L184 FreeRefinementEngine]: Found 1 perfect and 1 imperfect interpolant sequences. [2022-07-21 05:01:54,209 INFO L197 FreeRefinementEngine]: Number of different interpolants: perfect sequences [6] imperfect sequences [12] total 15 [2022-07-21 05:01:54,209 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [1326609759] [2022-07-21 05:01:54,209 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2022-07-21 05:01:54,209 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 6 states [2022-07-21 05:01:54,209 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2022-07-21 05:01:54,210 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 6 interpolants. [2022-07-21 05:01:54,210 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=44, Invalid=166, Unknown=0, NotChecked=0, Total=210 [2022-07-21 05:01:54,210 INFO L87 Difference]: Start difference. First operand 540 states and 695 transitions. Second operand has 6 states, 6 states have (on average 16.833333333333332) internal successors, (101), 6 states have internal predecessors, (101), 3 states have call successors, (11), 4 states have call predecessors, (11), 3 states have return successors, (11), 3 states have call predecessors, (11), 3 states have call successors, (11) [2022-07-21 05:01:54,439 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-07-21 05:01:54,439 INFO L93 Difference]: Finished difference Result 1431 states and 1922 transitions. [2022-07-21 05:01:54,440 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 10 states. [2022-07-21 05:01:54,440 INFO L78 Accepts]: Start accepts. Automaton has has 6 states, 6 states have (on average 16.833333333333332) internal successors, (101), 6 states have internal predecessors, (101), 3 states have call successors, (11), 4 states have call predecessors, (11), 3 states have return successors, (11), 3 states have call predecessors, (11), 3 states have call successors, (11) Word has length 134 [2022-07-21 05:01:54,440 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2022-07-21 05:01:54,444 INFO L225 Difference]: With dead ends: 1431 [2022-07-21 05:01:54,444 INFO L226 Difference]: Without dead ends: 970 [2022-07-21 05:01:54,445 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 175 GetRequests, 154 SyntacticMatches, 3 SemanticMatches, 18 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 77 ImplicationChecksByTransitivity, 0.2s TimeCoverageRelationStatistics Valid=84, Invalid=296, Unknown=0, NotChecked=0, Total=380 [2022-07-21 05:01:54,446 INFO L413 NwaCegarLoop]: 190 mSDtfsCounter, 236 mSDsluCounter, 440 mSDsCounter, 0 mSdLazyCounter, 157 mSolverCounterSat, 47 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.1s Time, 0 mProtectedPredicate, 0 mProtectedAction, 236 SdHoareTripleChecker+Valid, 630 SdHoareTripleChecker+Invalid, 204 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 47 IncrementalHoareTripleChecker+Valid, 157 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.1s IncrementalHoareTripleChecker+Time [2022-07-21 05:01:54,446 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [236 Valid, 630 Invalid, 204 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [47 Valid, 157 Invalid, 0 Unknown, 0 Unchecked, 0.1s Time] [2022-07-21 05:01:54,447 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 970 states. [2022-07-21 05:01:54,485 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 970 to 947. [2022-07-21 05:01:54,486 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 947 states, 729 states have (on average 1.2263374485596708) internal successors, (894), 776 states have internal predecessors, (894), 106 states have call successors, (106), 95 states have call predecessors, (106), 111 states have return successors, (202), 108 states have call predecessors, (202), 106 states have call successors, (202) [2022-07-21 05:01:54,489 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 947 states to 947 states and 1202 transitions. [2022-07-21 05:01:54,489 INFO L78 Accepts]: Start accepts. Automaton has 947 states and 1202 transitions. Word has length 134 [2022-07-21 05:01:54,489 INFO L84 Accepts]: Finished accepts. word is rejected. [2022-07-21 05:01:54,490 INFO L495 AbstractCegarLoop]: Abstraction has 947 states and 1202 transitions. [2022-07-21 05:01:54,490 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 6 states, 6 states have (on average 16.833333333333332) internal successors, (101), 6 states have internal predecessors, (101), 3 states have call successors, (11), 4 states have call predecessors, (11), 3 states have return successors, (11), 3 states have call predecessors, (11), 3 states have call successors, (11) [2022-07-21 05:01:54,490 INFO L276 IsEmpty]: Start isEmpty. Operand 947 states and 1202 transitions. [2022-07-21 05:01:54,492 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 135 [2022-07-21 05:01:54,492 INFO L187 NwaCegarLoop]: Found error trace [2022-07-21 05:01:54,493 INFO L195 NwaCegarLoop]: trace histogram [3, 3, 3, 3, 3, 3, 3, 3, 3, 3, 3, 3, 3, 3, 3, 3, 3, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-07-21 05:01:54,534 INFO L540 MonitoredProcess]: [MP /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 -smt2 -in SMTLIB2_COMPLIANT=true (3)] Forceful destruction successful, exit code 0 [2022-07-21 05:01:54,719 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: 3 /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 -smt2 -in SMTLIB2_COMPLIANT=true,SelfDestructingSolverStorable11 [2022-07-21 05:01:54,719 INFO L420 AbstractCegarLoop]: === Iteration 13 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2022-07-21 05:01:54,720 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2022-07-21 05:01:54,720 INFO L85 PathProgramCache]: Analyzing trace with hash -145753339, now seen corresponding path program 1 times [2022-07-21 05:01:54,720 INFO L118 FreeRefinementEngine]: Executing refinement strategy CAMEL [2022-07-21 05:01:54,720 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [1492636492] [2022-07-21 05:01:54,720 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-07-21 05:01:54,721 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2022-07-21 05:01:54,736 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-07-21 05:01:54,755 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 11 [2022-07-21 05:01:54,756 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-07-21 05:01:54,760 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 20 [2022-07-21 05:01:54,761 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-07-21 05:01:54,765 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 3 [2022-07-21 05:01:54,766 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-07-21 05:01:54,767 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 2 [2022-07-21 05:01:54,768 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-07-21 05:01:54,769 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 57 [2022-07-21 05:01:54,772 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-07-21 05:01:54,775 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 8 [2022-07-21 05:01:54,777 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-07-21 05:01:54,796 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 7 [2022-07-21 05:01:54,797 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-07-21 05:01:54,798 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 2 [2022-07-21 05:01:54,799 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-07-21 05:01:54,799 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 109 [2022-07-21 05:01:54,801 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-07-21 05:01:54,802 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 7 [2022-07-21 05:01:54,802 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-07-21 05:01:54,803 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 2 [2022-07-21 05:01:54,803 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-07-21 05:01:54,804 INFO L134 CoverageAnalysis]: Checked inductivity of 93 backedges. 45 proven. 6 refuted. 0 times theorem prover too weak. 42 trivial. 0 not checked. [2022-07-21 05:01:54,804 INFO L136 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2022-07-21 05:01:54,805 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [1492636492] [2022-07-21 05:01:54,805 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [1492636492] provided 0 perfect and 1 imperfect interpolant sequences [2022-07-21 05:01:54,805 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleZ3 [320457091] [2022-07-21 05:01:54,805 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-07-21 05:01:54,805 INFO L173 SolverBuilder]: Constructing external solver with command: z3 -smt2 -in SMTLIB2_COMPLIANT=true [2022-07-21 05:01:54,805 INFO L189 MonitoredProcess]: No working directory specified, using /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 [2022-07-21 05:01:54,806 INFO L229 MonitoredProcess]: Starting monitored process 4 with /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 -smt2 -in SMTLIB2_COMPLIANT=true (exit command is (exit), workingDir is null) [2022-07-21 05:01:54,807 INFO L327 MonitoredProcess]: [MP /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 -smt2 -in SMTLIB2_COMPLIANT=true (4)] Waiting until timeout for monitored process [2022-07-21 05:01:54,894 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-07-21 05:01:54,897 INFO L263 TraceCheckSpWp]: Trace formula consists of 572 conjuncts, 5 conjunts are in the unsatisfiable core [2022-07-21 05:01:54,899 INFO L286 TraceCheckSpWp]: Computing forward predicates... [2022-07-21 05:01:54,908 INFO L134 CoverageAnalysis]: Checked inductivity of 93 backedges. 64 proven. 0 refuted. 0 times theorem prover too weak. 29 trivial. 0 not checked. [2022-07-21 05:01:54,909 INFO L324 TraceCheckSpWp]: Omiting computation of backward sequence because forward sequence was already perfect [2022-07-21 05:01:54,909 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleZ3 [320457091] provided 1 perfect and 0 imperfect interpolant sequences [2022-07-21 05:01:54,909 INFO L184 FreeRefinementEngine]: Found 1 perfect and 1 imperfect interpolant sequences. [2022-07-21 05:01:54,909 INFO L197 FreeRefinementEngine]: Number of different interpolants: perfect sequences [5] imperfect sequences [8] total 8 [2022-07-21 05:01:54,909 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [443123169] [2022-07-21 05:01:54,909 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2022-07-21 05:01:54,910 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 5 states [2022-07-21 05:01:54,910 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2022-07-21 05:01:54,910 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 5 interpolants. [2022-07-21 05:01:54,910 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=15, Invalid=41, Unknown=0, NotChecked=0, Total=56 [2022-07-21 05:01:54,911 INFO L87 Difference]: Start difference. First operand 947 states and 1202 transitions. Second operand has 5 states, 5 states have (on average 18.6) internal successors, (93), 5 states have internal predecessors, (93), 2 states have call successors, (9), 2 states have call predecessors, (9), 2 states have return successors, (9), 2 states have call predecessors, (9), 2 states have call successors, (9) [2022-07-21 05:01:54,943 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-07-21 05:01:54,943 INFO L93 Difference]: Finished difference Result 1310 states and 1649 transitions. [2022-07-21 05:01:54,944 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 5 states. [2022-07-21 05:01:54,944 INFO L78 Accepts]: Start accepts. Automaton has has 5 states, 5 states have (on average 18.6) internal successors, (93), 5 states have internal predecessors, (93), 2 states have call successors, (9), 2 states have call predecessors, (9), 2 states have return successors, (9), 2 states have call predecessors, (9), 2 states have call successors, (9) Word has length 134 [2022-07-21 05:01:54,944 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2022-07-21 05:01:54,945 INFO L225 Difference]: With dead ends: 1310 [2022-07-21 05:01:54,945 INFO L226 Difference]: Without dead ends: 0 [2022-07-21 05:01:54,947 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 165 GetRequests, 157 SyntacticMatches, 0 SemanticMatches, 8 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 9 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=25, Invalid=65, Unknown=0, NotChecked=0, Total=90 [2022-07-21 05:01:54,947 INFO L413 NwaCegarLoop]: 105 mSDtfsCounter, 9 mSDsluCounter, 298 mSDsCounter, 0 mSdLazyCounter, 14 mSolverCounterSat, 3 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.0s Time, 0 mProtectedPredicate, 0 mProtectedAction, 9 SdHoareTripleChecker+Valid, 403 SdHoareTripleChecker+Invalid, 17 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 3 IncrementalHoareTripleChecker+Valid, 14 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.0s IncrementalHoareTripleChecker+Time [2022-07-21 05:01:54,948 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [9 Valid, 403 Invalid, 17 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [3 Valid, 14 Invalid, 0 Unknown, 0 Unchecked, 0.0s Time] [2022-07-21 05:01:54,948 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 0 states. [2022-07-21 05:01:54,948 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 0 to 0. [2022-07-21 05:01:54,948 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 0 states, 0 states have (on average 0.0) internal successors, (0), 0 states have internal predecessors, (0), 0 states have call successors, (0), 0 states have call predecessors, (0), 0 states have return successors, (0), 0 states have call predecessors, (0), 0 states have call successors, (0) [2022-07-21 05:01:54,948 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 0 states to 0 states and 0 transitions. [2022-07-21 05:01:54,948 INFO L78 Accepts]: Start accepts. Automaton has 0 states and 0 transitions. Word has length 134 [2022-07-21 05:01:54,949 INFO L84 Accepts]: Finished accepts. word is rejected. [2022-07-21 05:01:54,949 INFO L495 AbstractCegarLoop]: Abstraction has 0 states and 0 transitions. [2022-07-21 05:01:54,949 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 5 states, 5 states have (on average 18.6) internal successors, (93), 5 states have internal predecessors, (93), 2 states have call successors, (9), 2 states have call predecessors, (9), 2 states have return successors, (9), 2 states have call predecessors, (9), 2 states have call successors, (9) [2022-07-21 05:01:54,949 INFO L276 IsEmpty]: Start isEmpty. Operand 0 states and 0 transitions. [2022-07-21 05:01:54,949 INFO L282 IsEmpty]: Finished isEmpty. No accepting run. [2022-07-21 05:01:54,951 INFO L805 garLoopResultBuilder]: Registering result SAFE for location timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION (0 of 1 remaining) [2022-07-21 05:01:54,971 INFO L540 MonitoredProcess]: [MP /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 -smt2 -in SMTLIB2_COMPLIANT=true (4)] Forceful destruction successful, exit code 0 [2022-07-21 05:01:55,168 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable12,4 /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 -smt2 -in SMTLIB2_COMPLIANT=true [2022-07-21 05:01:55,170 INFO L343 DoubleDeckerVisitor]: Before removal of dead ends 0 states and 0 transitions. [2022-07-21 05:01:57,116 INFO L895 garLoopResultBuilder]: At program point deactivatePumpENTRY(lines 183 190) the Hoare annotation is: (or (= ~pumpRunning~0 |old(~pumpRunning~0)|) (not (<= 1 ~waterLevel~0)) (= 0 ~systemActive~0)) [2022-07-21 05:01:57,116 INFO L899 garLoopResultBuilder]: For program point deactivatePumpEXIT(lines 183 190) no Hoare annotation was computed. [2022-07-21 05:01:57,116 INFO L899 garLoopResultBuilder]: For program point deactivatePumpFINAL(lines 183 190) no Hoare annotation was computed. [2022-07-21 05:01:57,116 INFO L899 garLoopResultBuilder]: For program point processEnvironment__wrappee__baseEXIT(lines 90 96) no Hoare annotation was computed. [2022-07-21 05:01:57,116 INFO L902 garLoopResultBuilder]: At program point processEnvironment__wrappee__baseFINAL(lines 90 96) the Hoare annotation is: true [2022-07-21 05:01:57,117 INFO L899 garLoopResultBuilder]: For program point L913-1(lines 909 920) no Hoare annotation was computed. [2022-07-21 05:01:57,117 INFO L902 garLoopResultBuilder]: At program point changeMethaneLevelENTRY(lines 909 920) the Hoare annotation is: true [2022-07-21 05:01:57,117 INFO L899 garLoopResultBuilder]: For program point changeMethaneLevelEXIT(lines 909 920) no Hoare annotation was computed. [2022-07-21 05:01:57,117 INFO L902 garLoopResultBuilder]: At program point L801(lines 776 805) the Hoare annotation is: true [2022-07-21 05:01:57,117 INFO L899 garLoopResultBuilder]: For program point cleanupEXIT(lines 776 805) no Hoare annotation was computed. [2022-07-21 05:01:57,117 INFO L899 garLoopResultBuilder]: For program point L797(line 797) no Hoare annotation was computed. [2022-07-21 05:01:57,117 INFO L902 garLoopResultBuilder]: At program point cleanupENTRY(lines 776 805) the Hoare annotation is: true [2022-07-21 05:01:57,117 INFO L899 garLoopResultBuilder]: For program point L790(lines 790 794) no Hoare annotation was computed. [2022-07-21 05:01:57,117 INFO L902 garLoopResultBuilder]: At program point L790-1(lines 790 794) the Hoare annotation is: true [2022-07-21 05:01:57,117 INFO L899 garLoopResultBuilder]: For program point L787(line 787) no Hoare annotation was computed. [2022-07-21 05:01:57,117 INFO L902 garLoopResultBuilder]: At program point L786-2(lines 786 800) the Hoare annotation is: true [2022-07-21 05:01:57,117 INFO L902 garLoopResultBuilder]: At program point L782(line 782) the Hoare annotation is: true [2022-07-21 05:01:57,117 INFO L899 garLoopResultBuilder]: For program point L782-1(line 782) no Hoare annotation was computed. [2022-07-21 05:01:57,117 INFO L899 garLoopResultBuilder]: For program point L878(line 878) no Hoare annotation was computed. [2022-07-21 05:01:57,117 INFO L899 garLoopResultBuilder]: For program point L77-1(lines 77 83) no Hoare annotation was computed. [2022-07-21 05:01:57,117 INFO L899 garLoopResultBuilder]: For program point timeShiftFINAL(lines 66 89) no Hoare annotation was computed. [2022-07-21 05:01:57,117 INFO L895 garLoopResultBuilder]: At program point L164(line 164) the Hoare annotation is: (and (or (not (= |old(~pumpRunning~0)| 0)) (not (<= 1 |old(~waterLevel~0)|))) (or (and (= ~pumpRunning~0 |old(~pumpRunning~0)|) (<= 1 ~waterLevel~0)) (= 0 ~systemActive~0) (not (<= 2 |old(~waterLevel~0)|)))) [2022-07-21 05:01:57,117 INFO L895 garLoopResultBuilder]: At program point L160(line 160) the Hoare annotation is: (and (or (not (= |old(~pumpRunning~0)| 0)) (not (<= 1 |old(~waterLevel~0)|))) (or (and (= ~pumpRunning~0 |old(~pumpRunning~0)|) (<= 1 ~waterLevel~0)) (= 0 ~systemActive~0) (not (<= 2 |old(~waterLevel~0)|)))) [2022-07-21 05:01:57,118 INFO L895 garLoopResultBuilder]: At program point L879(lines 874 881) the Hoare annotation is: (and (or (not (= |old(~pumpRunning~0)| 0)) (not (<= 1 |old(~waterLevel~0)|))) (or (= 0 ~systemActive~0) (not (<= 2 |old(~waterLevel~0)|)))) [2022-07-21 05:01:57,118 INFO L895 garLoopResultBuilder]: At program point L169(line 169) the Hoare annotation is: (let ((.cse0 (not (= |old(~pumpRunning~0)| 0))) (.cse2 (not (<= 1 |old(~waterLevel~0)|))) (.cse1 (= ~pumpRunning~0 0)) (.cse3 (= 0 ~systemActive~0))) (and (or .cse0 (and .cse1 (= |old(~waterLevel~0)| ~waterLevel~0)) .cse2) (or .cse0 .cse2 (not .cse3)) (or (and (= ~pumpRunning~0 |old(~pumpRunning~0)|) .cse1) .cse3 (not (<= 2 |old(~waterLevel~0)|))))) [2022-07-21 05:01:57,118 INFO L895 garLoopResultBuilder]: At program point L169-1(lines 150 174) the Hoare annotation is: (let ((.cse2 (= 0 ~systemActive~0)) (.cse0 (not (= |old(~pumpRunning~0)| 0))) (.cse4 (= ~pumpRunning~0 0)) (.cse1 (not (<= 1 |old(~waterLevel~0)|))) (.cse3 (<= 2 ~waterLevel~0))) (and (or .cse0 .cse1 (not .cse2)) (or .cse3 .cse2 (and .cse4 (<= 1 ~waterLevel~0)) (not (<= 2 |old(~waterLevel~0)|))) (let ((.cse5 (= |old(~waterLevel~0)| ~waterLevel~0))) (or .cse0 (and .cse4 .cse5) .cse1 (and .cse3 .cse5))))) [2022-07-21 05:01:57,118 INFO L895 garLoopResultBuilder]: At program point L198(lines 191 201) the Hoare annotation is: (and (or (not (= |old(~pumpRunning~0)| 0)) (not (<= 1 |old(~waterLevel~0)|))) (or (and (= ~pumpRunning~0 |old(~pumpRunning~0)|) (<= 1 ~waterLevel~0)) (= 0 ~systemActive~0) (not (<= 2 |old(~waterLevel~0)|)))) [2022-07-21 05:01:57,118 INFO L899 garLoopResultBuilder]: For program point L70-1(lines 69 88) no Hoare annotation was computed. [2022-07-21 05:01:57,118 INFO L895 garLoopResultBuilder]: At program point L958(lines 953 961) the Hoare annotation is: (let ((.cse2 (= ~pumpRunning~0 0)) (.cse3 (<= 1 |timeShift_getWaterLevel_#res#1|)) (.cse5 (= 0 ~systemActive~0)) (.cse4 (= |old(~waterLevel~0)| ~waterLevel~0)) (.cse7 (<= 2 |timeShift_getWaterLevel_#res#1|)) (.cse6 (not (<= 2 |old(~waterLevel~0)|))) (.cse0 (not (= |old(~pumpRunning~0)| 0))) (.cse1 (not (= |old(~waterLevel~0)| 1)))) (and (or .cse0 .cse1 (and .cse2 (= ~waterLevel~0 1))) (or .cse0 (and .cse2 .cse3 .cse4) (not .cse5) .cse6) (or (and (<= 2 ~waterLevel~0) .cse7) (and .cse2 (<= 1 ~waterLevel~0) .cse3) .cse5 .cse6) (or .cse0 .cse5 (and .cse4 .cse7) .cse6) (or .cse0 .cse1 (= |timeShift_getWaterLevel_#res#1| 1)))) [2022-07-21 05:01:57,118 INFO L895 garLoopResultBuilder]: At program point L207(lines 202 210) the Hoare annotation is: (and (or (not (= |old(~pumpRunning~0)| 0)) (not (<= 1 |old(~waterLevel~0)|))) (or (= 0 ~systemActive~0) (not (<= 2 |old(~waterLevel~0)|)))) [2022-07-21 05:01:57,118 INFO L895 garLoopResultBuilder]: At program point L926(lines 921 929) the Hoare annotation is: (and (or (not (= |old(~pumpRunning~0)| 0)) (not (<= 1 |old(~waterLevel~0)|))) (or (and (= ~pumpRunning~0 |old(~pumpRunning~0)|) (<= 1 ~waterLevel~0)) (= 0 ~systemActive~0) (not (<= 2 |old(~waterLevel~0)|)))) [2022-07-21 05:01:57,118 INFO L899 garLoopResultBuilder]: For program point L158(lines 158 166) no Hoare annotation was computed. [2022-07-21 05:01:57,118 INFO L899 garLoopResultBuilder]: For program point L154(lines 154 171) no Hoare annotation was computed. [2022-07-21 05:01:57,118 INFO L899 garLoopResultBuilder]: For program point L889(lines 889 893) no Hoare annotation was computed. [2022-07-21 05:01:57,118 INFO L899 garLoopResultBuilder]: For program point L761(lines 761 767) no Hoare annotation was computed. [2022-07-21 05:01:57,118 INFO L895 garLoopResultBuilder]: At program point L889-2(lines 885 896) the Hoare annotation is: (and (or (not (= |old(~pumpRunning~0)| 0)) (not (<= 1 |old(~waterLevel~0)|))) (or (and (= ~pumpRunning~0 |old(~pumpRunning~0)|) (<= 1 ~waterLevel~0)) (= 0 ~systemActive~0) (not (<= 2 |old(~waterLevel~0)|)))) [2022-07-21 05:01:57,118 INFO L899 garLoopResultBuilder]: For program point L757(lines 757 770) no Hoare annotation was computed. [2022-07-21 05:01:57,119 INFO L895 garLoopResultBuilder]: At program point L757-1(lines 749 773) the Hoare annotation is: (let ((.cse6 (= ~pumpRunning~0 0)) (.cse9 (<= 2 ~waterLevel~0)) (.cse12 (= |old(~waterLevel~0)| ~waterLevel~0)) (.cse10 (<= 2 |timeShift_getWaterLevel_#res#1|)) (.cse11 (<= 2 |timeShift___utac_acc__Specification4_spec__1_~tmp~9#1|))) (let ((.cse1 (and .cse9 .cse12 .cse10 .cse11)) (.cse4 (and .cse6 .cse12)) (.cse5 (not (<= 1 |old(~waterLevel~0)|))) (.cse2 (= 0 ~systemActive~0)) (.cse0 (not (= |old(~pumpRunning~0)| 0))) (.cse7 (<= 1 |timeShift___utac_acc__Specification4_spec__1_~tmp~9#1|)) (.cse8 (<= 1 |timeShift_getWaterLevel_#res#1|)) (.cse3 (not (<= 2 |old(~waterLevel~0)|)))) (and (or .cse0 .cse1 .cse2 .cse3) (or .cse0 (not (= |old(~waterLevel~0)| 1)) (and (= |timeShift___utac_acc__Specification4_spec__1_~tmp~9#1| 1) (= |timeShift_getWaterLevel_#res#1| 1))) (or .cse0 .cse4 .cse5 .cse1) (or .cse0 .cse4 .cse5 (not .cse2)) (or (and .cse6 .cse7 (<= 1 ~waterLevel~0) .cse8) (and .cse9 .cse10 .cse11) .cse2 .cse3) (or .cse0 (and .cse7 .cse8) .cse3)))) [2022-07-21 05:01:57,119 INFO L895 garLoopResultBuilder]: At program point timeShiftENTRY(lines 66 89) the Hoare annotation is: (let ((.cse0 (not (= |old(~pumpRunning~0)| 0))) (.cse1 (= ~pumpRunning~0 0)) (.cse2 (= |old(~waterLevel~0)| ~waterLevel~0)) (.cse3 (not (<= 2 |old(~waterLevel~0)|)))) (and (or .cse0 (not (= |old(~waterLevel~0)| 1)) (and .cse1 (= ~waterLevel~0 1))) (or .cse0 (and .cse1 .cse2) .cse3) (or (and (= ~pumpRunning~0 |old(~pumpRunning~0)|) .cse2) (= 0 ~systemActive~0) .cse3))) [2022-07-21 05:01:57,119 INFO L899 garLoopResultBuilder]: For program point timeShiftEXIT(lines 66 89) no Hoare annotation was computed. [2022-07-21 05:01:57,119 INFO L899 garLoopResultBuilder]: For program point timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION(line 878) no Hoare annotation was computed. [2022-07-21 05:01:57,119 INFO L895 garLoopResultBuilder]: At program point L700(line 700) the Hoare annotation is: (let ((.cse2 (<= 2 ~waterLevel~0)) (.cse0 (= ~pumpRunning~0 0)) (.cse1 (= |ULTIMATE.start_valid_product_#res#1| 1)) (.cse3 (= |ULTIMATE.start_test_~splverifierCounter~0#1| 0)) (.cse4 (= |ULTIMATE.start_main_~tmp~10#1| 1))) (or (and .cse0 .cse1 .cse2 .cse3 .cse4) (and .cse1 .cse2 .cse3 .cse4 (not (= 0 ~systemActive~0))) (and .cse0 .cse1 .cse3 (= ~waterLevel~0 1) .cse4))) [2022-07-21 05:01:57,119 INFO L895 garLoopResultBuilder]: At program point L738(lines 687 739) the Hoare annotation is: false [2022-07-21 05:01:57,119 INFO L899 garLoopResultBuilder]: For program point L-1(line -1) no Hoare annotation was computed. [2022-07-21 05:01:57,119 INFO L899 garLoopResultBuilder]: For program point ULTIMATE.startENTRY(line -1) no Hoare annotation was computed. [2022-07-21 05:01:57,119 INFO L899 garLoopResultBuilder]: For program point ULTIMATE.startFINAL(line -1) no Hoare annotation was computed. [2022-07-21 05:01:57,119 INFO L899 garLoopResultBuilder]: For program point L726(lines 726 732) no Hoare annotation was computed. [2022-07-21 05:01:57,119 INFO L895 garLoopResultBuilder]: At program point L726-2(lines 718 733) the Hoare annotation is: (let ((.cse2 (<= 2 ~waterLevel~0)) (.cse0 (= ~pumpRunning~0 0)) (.cse1 (= |ULTIMATE.start_valid_product_#res#1| 1)) (.cse3 (= |ULTIMATE.start_test_~splverifierCounter~0#1| 0)) (.cse4 (= |ULTIMATE.start_main_~tmp~10#1| 1))) (or (and .cse0 .cse1 .cse2 .cse3 .cse4) (and .cse1 .cse2 .cse3 .cse4 (not (= 0 ~systemActive~0))) (and .cse0 .cse1 .cse3 (= ~waterLevel~0 1) .cse4))) [2022-07-21 05:01:57,119 INFO L899 garLoopResultBuilder]: For program point L689(lines 688 737) no Hoare annotation was computed. [2022-07-21 05:01:57,119 INFO L895 garLoopResultBuilder]: At program point L305(lines 300 307) the Hoare annotation is: (let ((.cse0 (= |ULTIMATE.start_valid_product_#res#1| 1)) (.cse1 (= |ULTIMATE.start_test_~splverifierCounter~0#1| 0)) (.cse2 (= |ULTIMATE.start_main_~tmp~10#1| 1)) (.cse3 (not (= 0 ~systemActive~0)))) (or (and .cse0 (<= 2 ~waterLevel~0) .cse1 .cse2 .cse3) (and (= ~pumpRunning~0 0) .cse0 .cse1 (<= 1 ~waterLevel~0) .cse2 .cse3))) [2022-07-21 05:01:57,119 INFO L899 garLoopResultBuilder]: For program point L718(lines 718 733) no Hoare annotation was computed. [2022-07-21 05:01:57,120 INFO L895 garLoopResultBuilder]: At program point L297(lines 285 299) the Hoare annotation is: (let ((.cse0 (= ~pumpRunning~0 0)) (.cse1 (= |ULTIMATE.start_valid_product_#res#1| 1)) (.cse2 (= |ULTIMATE.start_test_~splverifierCounter~0#1| 0)) (.cse3 (= 0 ~systemActive~0)) (.cse4 (= |ULTIMATE.start_main_~tmp~10#1| 1))) (or (and .cse0 .cse1 .cse2 .cse3 (= ~waterLevel~0 1) .cse4) (and .cse0 .cse1 (<= 2 ~waterLevel~0) .cse2 .cse3 .cse4))) [2022-07-21 05:01:57,120 INFO L895 garLoopResultBuilder]: At program point L710(line 710) the Hoare annotation is: (let ((.cse2 (<= 2 ~waterLevel~0)) (.cse0 (= ~pumpRunning~0 0)) (.cse1 (= |ULTIMATE.start_valid_product_#res#1| 1)) (.cse3 (= |ULTIMATE.start_test_~splverifierCounter~0#1| 0)) (.cse4 (= |ULTIMATE.start_main_~tmp~10#1| 1))) (or (and .cse0 .cse1 .cse2 .cse3 .cse4) (and .cse1 .cse2 .cse3 .cse4 (not (= 0 ~systemActive~0))) (and .cse0 .cse1 .cse3 (= ~waterLevel~0 1) .cse4))) [2022-07-21 05:01:57,120 INFO L895 garLoopResultBuilder]: At program point L834(lines 830 836) the Hoare annotation is: (and (= ~pumpRunning~0 0) (= |ULTIMATE.start_valid_product_#res#1| 1) (= ~waterLevel~0 1) (= |ULTIMATE.start_main_~tmp~10#1| 1) (not (= 0 ~systemActive~0))) [2022-07-21 05:01:57,120 INFO L899 garLoopResultBuilder]: For program point L289(lines 289 295) no Hoare annotation was computed. [2022-07-21 05:01:57,120 INFO L899 garLoopResultBuilder]: For program point ULTIMATE.startEXIT(line -1) no Hoare annotation was computed. [2022-07-21 05:01:57,120 INFO L899 garLoopResultBuilder]: For program point L289-1(lines 289 295) no Hoare annotation was computed. [2022-07-21 05:01:57,120 INFO L895 garLoopResultBuilder]: At program point L735(lines 688 737) the Hoare annotation is: (let ((.cse2 (<= 2 ~waterLevel~0)) (.cse0 (= ~pumpRunning~0 0)) (.cse1 (= |ULTIMATE.start_valid_product_#res#1| 1)) (.cse3 (= |ULTIMATE.start_test_~splverifierCounter~0#1| 0)) (.cse4 (= |ULTIMATE.start_main_~tmp~10#1| 1))) (or (and .cse0 .cse1 .cse2 .cse3 .cse4) (and .cse1 .cse2 .cse3 .cse4 (not (= 0 ~systemActive~0))) (and .cse0 .cse1 .cse3 (= ~waterLevel~0 1) .cse4))) [2022-07-21 05:01:57,120 INFO L899 garLoopResultBuilder]: For program point L698(lines 698 704) no Hoare annotation was computed. [2022-07-21 05:01:57,120 INFO L899 garLoopResultBuilder]: For program point L698-1(lines 698 704) no Hoare annotation was computed. [2022-07-21 05:01:57,120 INFO L895 garLoopResultBuilder]: At program point L1016(lines 1011 1019) the Hoare annotation is: (and (= ~pumpRunning~0 0) (= |ULTIMATE.start_valid_product_#res#1| 1) (= ~waterLevel~0 1) (not (= 0 ~systemActive~0))) [2022-07-21 05:01:57,120 INFO L899 garLoopResultBuilder]: For program point L690(lines 690 694) no Hoare annotation was computed. [2022-07-21 05:01:57,120 INFO L895 garLoopResultBuilder]: At program point L1008(lines 1004 1010) the Hoare annotation is: (and (= ~pumpRunning~0 0) (= ~waterLevel~0 1) (not (= 0 ~systemActive~0))) [2022-07-21 05:01:57,120 INFO L899 garLoopResultBuilder]: For program point L860(lines 860 867) no Hoare annotation was computed. [2022-07-21 05:01:57,120 INFO L899 garLoopResultBuilder]: For program point L860-2(lines 860 867) no Hoare annotation was computed. [2022-07-21 05:01:57,120 INFO L902 garLoopResultBuilder]: At program point L844(lines 837 846) the Hoare annotation is: true [2022-07-21 05:01:57,120 INFO L895 garLoopResultBuilder]: At program point L1001(lines 997 1003) the Hoare annotation is: (and (= ~pumpRunning~0 0) (= ~waterLevel~0 1) (not (= 0 ~systemActive~0))) [2022-07-21 05:01:57,120 INFO L902 garLoopResultBuilder]: At program point L741(lines 678 745) the Hoare annotation is: true [2022-07-21 05:01:57,121 INFO L902 garLoopResultBuilder]: At program point L869(lines 850 872) the Hoare annotation is: true [2022-07-21 05:01:57,121 INFO L899 garLoopResultBuilder]: For program point L708(lines 708 714) no Hoare annotation was computed. [2022-07-21 05:01:57,121 INFO L899 garLoopResultBuilder]: For program point L708-1(lines 708 714) no Hoare annotation was computed. [2022-07-21 05:01:57,121 INFO L895 garLoopResultBuilder]: At program point L291(line 291) the Hoare annotation is: (and (= |ULTIMATE.start_valid_product_#res#1| 1) (<= 2 ~waterLevel~0) (= |ULTIMATE.start_test_~splverifierCounter~0#1| 0) (= |ULTIMATE.start_main_~tmp~10#1| 1) (not (= 0 ~systemActive~0))) [2022-07-21 05:01:57,121 INFO L895 garLoopResultBuilder]: At program point processEnvironment__wrappee__highWaterSensorENTRY(lines 98 122) the Hoare annotation is: (or (not (= |old(~pumpRunning~0)| 0)) (= ~pumpRunning~0 0) (not (<= 1 ~waterLevel~0)) (= 0 ~systemActive~0)) [2022-07-21 05:01:57,121 INFO L899 garLoopResultBuilder]: For program point L256(lines 256 260) no Hoare annotation was computed. [2022-07-21 05:01:57,121 INFO L899 garLoopResultBuilder]: For program point L256-2(lines 256 260) no Hoare annotation was computed. [2022-07-21 05:01:57,121 INFO L895 garLoopResultBuilder]: At program point L180(lines 175 182) the Hoare annotation is: (or (not (= ~waterLevel~0 1)) (not (= |old(~pumpRunning~0)| 0)) (= 0 ~systemActive~0)) [2022-07-21 05:01:57,121 INFO L895 garLoopResultBuilder]: At program point L112(line 112) the Hoare annotation is: (let ((.cse0 (not (= |old(~pumpRunning~0)| 0))) (.cse1 (= 0 ~systemActive~0))) (and (or (not (= ~waterLevel~0 1)) .cse0 (and (not (= |processEnvironment__wrappee__highWaterSensor_isHighWaterSensorDry_#res#1| 0)) (not (= |processEnvironment__wrappee__highWaterSensor_isHighWaterLevel_~tmp~3#1| 0))) .cse1) (or .cse0 (not (<= 1 ~waterLevel~0)) (and (= ~pumpRunning~0 0) (= |processEnvironment__wrappee__highWaterSensor_~tmp~0#1| 0)) .cse1))) [2022-07-21 05:01:57,121 INFO L895 garLoopResultBuilder]: At program point L971(lines 962 975) the Hoare annotation is: (let ((.cse0 (= ~pumpRunning~0 0))) (or (not (= |old(~pumpRunning~0)| 0)) (not (<= 1 ~waterLevel~0)) (and .cse0 (not (= |processEnvironment__wrappee__highWaterSensor_isHighWaterSensorDry_#res#1| 0))) (and .cse0 (<= 2 ~waterLevel~0)) (= 0 ~systemActive~0))) [2022-07-21 05:01:57,121 INFO L899 garLoopResultBuilder]: For program point L106(lines 106 114) no Hoare annotation was computed. [2022-07-21 05:01:57,121 INFO L899 garLoopResultBuilder]: For program point L102(lines 102 119) no Hoare annotation was computed. [2022-07-21 05:01:57,121 INFO L899 garLoopResultBuilder]: For program point processEnvironment__wrappee__highWaterSensorEXIT(lines 98 122) no Hoare annotation was computed. [2022-07-21 05:01:57,121 INFO L895 garLoopResultBuilder]: At program point L117(line 117) the Hoare annotation is: (or (not (= |old(~pumpRunning~0)| 0)) (not (<= 1 ~waterLevel~0)) (= 0 ~systemActive~0)) [2022-07-21 05:01:57,121 INFO L899 garLoopResultBuilder]: For program point L117-1(lines 98 122) no Hoare annotation was computed. [2022-07-21 05:01:57,121 INFO L899 garLoopResultBuilder]: For program point L966(lines 966 972) no Hoare annotation was computed. [2022-07-21 05:01:57,121 INFO L895 garLoopResultBuilder]: At program point L262(lines 247 265) the Hoare annotation is: (let ((.cse0 (not (= |old(~pumpRunning~0)| 0))) (.cse1 (= ~pumpRunning~0 0)) (.cse2 (= 0 ~systemActive~0))) (and (or .cse0 .cse1 (not (<= 2 ~waterLevel~0)) .cse2) (or (not (= ~waterLevel~0 1)) .cse0 (and .cse1 (not (= |processEnvironment__wrappee__highWaterSensor_isHighWaterSensorDry_#res#1| 0)) (= |processEnvironment__wrappee__highWaterSensor_isHighWaterLevel_#res#1| 0) (= |processEnvironment__wrappee__highWaterSensor_isHighWaterLevel_~tmp___0~0#1| 0) (not (= |processEnvironment__wrappee__highWaterSensor_isHighWaterLevel_~tmp~3#1| 0))) .cse2))) [2022-07-21 05:01:57,122 INFO L899 garLoopResultBuilder]: For program point waterRiseEXIT(lines 897 908) no Hoare annotation was computed. [2022-07-21 05:01:57,122 INFO L899 garLoopResultBuilder]: For program point L901-1(lines 897 908) no Hoare annotation was computed. [2022-07-21 05:01:57,122 INFO L895 garLoopResultBuilder]: At program point waterRiseENTRY(lines 897 908) the Hoare annotation is: (let ((.cse0 (= |old(~waterLevel~0)| ~waterLevel~0))) (and (or (not (= ~pumpRunning~0 0)) (not (<= 1 |old(~waterLevel~0)|)) .cse0) (or .cse0 (= 0 ~systemActive~0) (not (<= 2 |old(~waterLevel~0)|))))) [2022-07-21 05:01:57,122 INFO L899 garLoopResultBuilder]: For program point L128(lines 128 145) no Hoare annotation was computed. [2022-07-21 05:01:57,122 INFO L895 garLoopResultBuilder]: At program point processEnvironment__wrappee__lowWaterSensorENTRY(lines 124 148) the Hoare annotation is: (or (= ~pumpRunning~0 |old(~pumpRunning~0)|) (not (<= 1 ~waterLevel~0)) (= 0 ~systemActive~0)) [2022-07-21 05:01:57,122 INFO L895 garLoopResultBuilder]: At program point L281(lines 266 284) the Hoare annotation is: (let ((.cse0 (not (<= 1 ~waterLevel~0))) (.cse1 (= 0 ~systemActive~0))) (and (or .cse0 (and (= ~pumpRunning~0 |old(~pumpRunning~0)|) (<= 1 |processEnvironment__wrappee__lowWaterSensor_isLowWaterLevel_#res#1|) (<= 1 |processEnvironment__wrappee__lowWaterSensor_isLowWaterLevel_~tmp___0~1#1|) (= |processEnvironment__wrappee__lowWaterSensor_isLowWaterLevel_~tmp~4#1| 0) (= |processEnvironment__wrappee__lowWaterSensor_isLowWaterSensorDry_#res#1| 0)) .cse1) (or (not (= |old(~pumpRunning~0)| 0)) .cse0 .cse1))) [2022-07-21 05:01:57,122 INFO L895 garLoopResultBuilder]: At program point L981(lines 976 984) the Hoare annotation is: (let ((.cse0 (not (<= 1 ~waterLevel~0))) (.cse1 (= 0 ~systemActive~0))) (and (or .cse0 (and (= ~pumpRunning~0 |old(~pumpRunning~0)|) (= |processEnvironment__wrappee__lowWaterSensor_isLowWaterSensorDry_#res#1| 0)) .cse1) (or (not (= |old(~pumpRunning~0)| 0)) .cse0 .cse1))) [2022-07-21 05:01:57,122 INFO L899 garLoopResultBuilder]: For program point L275(lines 275 279) no Hoare annotation was computed. [2022-07-21 05:01:57,122 INFO L899 garLoopResultBuilder]: For program point L275-2(lines 275 279) no Hoare annotation was computed. [2022-07-21 05:01:57,122 INFO L895 garLoopResultBuilder]: At program point L143(line 143) the Hoare annotation is: (or (not (<= 1 ~waterLevel~0)) (and (= ~pumpRunning~0 |old(~pumpRunning~0)|) (= ~pumpRunning~0 0)) (= 0 ~systemActive~0)) [2022-07-21 05:01:57,122 INFO L899 garLoopResultBuilder]: For program point L143-1(lines 124 148) no Hoare annotation was computed. [2022-07-21 05:01:57,122 INFO L899 garLoopResultBuilder]: For program point processEnvironment__wrappee__lowWaterSensorEXIT(lines 124 148) no Hoare annotation was computed. [2022-07-21 05:01:57,122 INFO L895 garLoopResultBuilder]: At program point L138(line 138) the Hoare annotation is: (or (not (<= 1 ~waterLevel~0)) (= 0 ~systemActive~0)) [2022-07-21 05:01:57,122 INFO L895 garLoopResultBuilder]: At program point L134(line 134) the Hoare annotation is: (let ((.cse0 (not (<= 1 ~waterLevel~0))) (.cse1 (= 0 ~systemActive~0))) (and (or .cse0 (and (= ~pumpRunning~0 |old(~pumpRunning~0)|) (<= 1 |processEnvironment__wrappee__lowWaterSensor_isLowWaterLevel_#res#1|) (<= 1 |processEnvironment__wrappee__lowWaterSensor_isLowWaterLevel_~tmp___0~1#1|) (= |processEnvironment__wrappee__lowWaterSensor_isLowWaterLevel_~tmp~4#1| 0) (= |processEnvironment__wrappee__lowWaterSensor_isLowWaterSensorDry_#res#1| 0) (<= 1 |processEnvironment__wrappee__lowWaterSensor_~tmp~1#1|)) .cse1) (or (not (= |old(~pumpRunning~0)| 0)) .cse0 .cse1))) [2022-07-21 05:01:57,122 INFO L899 garLoopResultBuilder]: For program point L132(lines 132 140) no Hoare annotation was computed. [2022-07-21 05:01:57,128 INFO L356 BasicCegarLoop]: Path program histogram: [2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-07-21 05:01:57,130 INFO L176 ceAbstractionStarter]: Computing trace abstraction results [2022-07-21 05:01:57,156 INFO L202 PluginConnector]: Adding new model de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction CFG 21.07 05:01:57 BoogieIcfgContainer [2022-07-21 05:01:57,156 INFO L132 PluginConnector]: ------------------------ END TraceAbstraction---------------------------- [2022-07-21 05:01:57,157 INFO L113 PluginConnector]: ------------------------Witness Printer---------------------------- [2022-07-21 05:01:57,157 INFO L271 PluginConnector]: Initializing Witness Printer... [2022-07-21 05:01:57,157 INFO L275 PluginConnector]: Witness Printer initialized [2022-07-21 05:01:57,157 INFO L185 PluginConnector]: Executing the observer RCFGCatcher from plugin Witness Printer for "de.uni_freiburg.informatik.ultimate.plugins.generator.rcfgbuilder CFG 21.07 05:01:49" (3/4) ... [2022-07-21 05:01:57,159 INFO L137 WitnessPrinter]: Generating witness for correct program [2022-07-21 05:01:57,164 INFO L354 RCFGBacktranslator]: Ignoring RootEdge to procedure deactivatePump [2022-07-21 05:01:57,164 INFO L354 RCFGBacktranslator]: Ignoring RootEdge to procedure processEnvironment__wrappee__base [2022-07-21 05:01:57,164 INFO L354 RCFGBacktranslator]: Ignoring RootEdge to procedure changeMethaneLevel [2022-07-21 05:01:57,164 INFO L354 RCFGBacktranslator]: Ignoring RootEdge to procedure cleanup [2022-07-21 05:01:57,164 INFO L354 RCFGBacktranslator]: Ignoring RootEdge to procedure timeShift [2022-07-21 05:01:57,164 INFO L354 RCFGBacktranslator]: Ignoring RootEdge to procedure processEnvironment__wrappee__highWaterSensor [2022-07-21 05:01:57,164 INFO L354 RCFGBacktranslator]: Ignoring RootEdge to procedure waterRise [2022-07-21 05:01:57,165 INFO L354 RCFGBacktranslator]: Ignoring RootEdge to procedure processEnvironment__wrappee__lowWaterSensor [2022-07-21 05:01:57,169 INFO L910 BoogieBacktranslator]: Reduced CFG by removing 55 nodes and edges [2022-07-21 05:01:57,170 INFO L910 BoogieBacktranslator]: Reduced CFG by removing 22 nodes and edges [2022-07-21 05:01:57,170 INFO L910 BoogieBacktranslator]: Reduced CFG by removing 11 nodes and edges [2022-07-21 05:01:57,171 INFO L910 BoogieBacktranslator]: Reduced CFG by removing 5 nodes and edges [2022-07-21 05:01:57,171 INFO L910 BoogieBacktranslator]: Reduced CFG by removing 2 nodes and edges [2022-07-21 05:01:57,171 INFO L910 BoogieBacktranslator]: Reduced CFG by removing 1 nodes and edges [2022-07-21 05:01:57,172 INFO L910 BoogieBacktranslator]: Reduced CFG by removing 1 nodes and edges [2022-07-21 05:01:57,188 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: ((pumpRunning == 0 && \result == 1) && waterLevel == 1) && !(0 == systemActive) [2022-07-21 05:01:57,189 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (((pumpRunning == 0 && \result == 1) && waterLevel == 1) && tmp == 1) && !(0 == systemActive) [2022-07-21 05:01:57,189 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (((((pumpRunning == 0 && \result == 1) && 2 <= waterLevel) && splverifierCounter == 0) && tmp == 1) || ((((\result == 1 && 2 <= waterLevel) && splverifierCounter == 0) && tmp == 1) && !(0 == systemActive))) || ((((pumpRunning == 0 && \result == 1) && splverifierCounter == 0) && waterLevel == 1) && tmp == 1) [2022-07-21 05:01:57,189 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (!(\old(pumpRunning) == 0) || !(1 <= \old(waterLevel))) && (((pumpRunning == \old(pumpRunning) && 1 <= waterLevel) || 0 == systemActive) || !(2 <= \old(waterLevel))) [2022-07-21 05:01:57,190 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (((!(\old(pumpRunning) == 0) || !(1 <= \old(waterLevel))) || !(0 == systemActive)) && (((2 <= waterLevel || 0 == systemActive) || (pumpRunning == 0 && 1 <= waterLevel)) || !(2 <= \old(waterLevel)))) && (((!(\old(pumpRunning) == 0) || (pumpRunning == 0 && \old(waterLevel) == waterLevel)) || !(1 <= \old(waterLevel))) || (2 <= waterLevel && \old(waterLevel) == waterLevel)) [2022-07-21 05:01:57,190 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: ((((\result == 1 && 2 <= waterLevel) && splverifierCounter == 0) && tmp == 1) && !(0 == systemActive)) || (((((pumpRunning == 0 && \result == 1) && splverifierCounter == 0) && 1 <= waterLevel) && tmp == 1) && !(0 == systemActive)) [2022-07-21 05:01:57,190 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (((((!(\old(pumpRunning) == 0) || !(\old(waterLevel) == 1)) || (pumpRunning == 0 && waterLevel == 1)) && (((!(\old(pumpRunning) == 0) || ((pumpRunning == 0 && 1 <= \result) && \old(waterLevel) == waterLevel)) || !(0 == systemActive)) || !(2 <= \old(waterLevel)))) && ((((2 <= waterLevel && 2 <= \result) || ((pumpRunning == 0 && 1 <= waterLevel) && 1 <= \result)) || 0 == systemActive) || !(2 <= \old(waterLevel)))) && (((!(\old(pumpRunning) == 0) || 0 == systemActive) || (\old(waterLevel) == waterLevel && 2 <= \result)) || !(2 <= \old(waterLevel)))) && ((!(\old(pumpRunning) == 0) || !(\old(waterLevel) == 1)) || \result == 1) [2022-07-21 05:01:57,190 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (!(\old(pumpRunning) == 0) || !(1 <= \old(waterLevel))) && (((pumpRunning == \old(pumpRunning) && 1 <= waterLevel) || 0 == systemActive) || !(2 <= \old(waterLevel))) [2022-07-21 05:01:57,191 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (((((pumpRunning == 0 && \result == 1) && splverifierCounter == 0) && 0 == systemActive) && waterLevel == 1) && tmp == 1) || (((((pumpRunning == 0 && \result == 1) && 2 <= waterLevel) && splverifierCounter == 0) && 0 == systemActive) && tmp == 1) [2022-07-21 05:01:57,191 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (((((((!(\old(pumpRunning) == 0) || (((2 <= waterLevel && \old(waterLevel) == waterLevel) && 2 <= \result) && 2 <= tmp)) || 0 == systemActive) || !(2 <= \old(waterLevel))) && ((!(\old(pumpRunning) == 0) || !(\old(waterLevel) == 1)) || (tmp == 1 && \result == 1))) && (((!(\old(pumpRunning) == 0) || (pumpRunning == 0 && \old(waterLevel) == waterLevel)) || !(1 <= \old(waterLevel))) || (((2 <= waterLevel && \old(waterLevel) == waterLevel) && 2 <= \result) && 2 <= tmp))) && (((!(\old(pumpRunning) == 0) || (pumpRunning == 0 && \old(waterLevel) == waterLevel)) || !(1 <= \old(waterLevel))) || !(0 == systemActive))) && ((((((pumpRunning == 0 && 1 <= tmp) && 1 <= waterLevel) && 1 <= \result) || ((2 <= waterLevel && 2 <= \result) && 2 <= tmp)) || 0 == systemActive) || !(2 <= \old(waterLevel)))) && ((!(\old(pumpRunning) == 0) || (1 <= tmp && 1 <= \result)) || !(2 <= \old(waterLevel))) [2022-07-21 05:01:57,191 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (!(\old(pumpRunning) == 0) || !(1 <= \old(waterLevel))) && (((pumpRunning == \old(pumpRunning) && 1 <= waterLevel) || 0 == systemActive) || !(2 <= \old(waterLevel))) [2022-07-21 05:01:57,191 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: ((!(1 <= waterLevel) || (pumpRunning == \old(pumpRunning) && \result == 0)) || 0 == systemActive) && ((!(\old(pumpRunning) == 0) || !(1 <= waterLevel)) || 0 == systemActive) [2022-07-21 05:01:57,191 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (!(\old(pumpRunning) == 0) || !(1 <= \old(waterLevel))) && (0 == systemActive || !(2 <= \old(waterLevel))) [2022-07-21 05:01:57,191 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (((!(\old(pumpRunning) == 0) || !(1 <= waterLevel)) || (pumpRunning == 0 && !(\result == 0))) || (pumpRunning == 0 && 2 <= waterLevel)) || 0 == systemActive [2022-07-21 05:01:57,192 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: ((!(1 <= waterLevel) || ((((pumpRunning == \old(pumpRunning) && 1 <= \result) && 1 <= tmp___0) && tmp == 0) && \result == 0)) || 0 == systemActive) && ((!(\old(pumpRunning) == 0) || !(1 <= waterLevel)) || 0 == systemActive) [2022-07-21 05:01:57,192 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (!(\old(pumpRunning) == 0) || !(1 <= \old(waterLevel))) && (0 == systemActive || !(2 <= \old(waterLevel))) [2022-07-21 05:01:57,192 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (((!(\old(pumpRunning) == 0) || pumpRunning == 0) || !(2 <= waterLevel)) || 0 == systemActive) && (((!(waterLevel == 1) || !(\old(pumpRunning) == 0)) || ((((pumpRunning == 0 && !(\result == 0)) && \result == 0) && tmp___0 == 0) && !(tmp == 0))) || 0 == systemActive) [2022-07-21 05:01:57,192 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (!(waterLevel == 1) || !(\old(pumpRunning) == 0)) || 0 == systemActive [2022-07-21 05:01:57,222 INFO L141 WitnessManager]: Wrote witness to /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/witness.graphml [2022-07-21 05:01:57,223 INFO L132 PluginConnector]: ------------------------ END Witness Printer---------------------------- [2022-07-21 05:01:57,223 INFO L158 Benchmark]: Toolchain (without parser) took 8632.65ms. Allocated memory was 52.4MB in the beginning and 148.9MB in the end (delta: 96.5MB). Free memory was 28.5MB in the beginning and 84.6MB in the end (delta: -56.1MB). Peak memory consumption was 40.7MB. Max. memory is 16.1GB. [2022-07-21 05:01:57,223 INFO L158 Benchmark]: CDTParser took 0.16ms. Allocated memory is still 52.4MB. Free memory is still 33.7MB. There was no memory consumed. Max. memory is 16.1GB. [2022-07-21 05:01:57,224 INFO L158 Benchmark]: CACSL2BoogieTranslator took 516.90ms. Allocated memory was 52.4MB in the beginning and 73.4MB in the end (delta: 21.0MB). Free memory was 28.3MB in the beginning and 49.0MB in the end (delta: -20.7MB). Peak memory consumption was 7.7MB. Max. memory is 16.1GB. [2022-07-21 05:01:57,224 INFO L158 Benchmark]: Boogie Procedure Inliner took 77.87ms. Allocated memory is still 73.4MB. Free memory was 49.0MB in the beginning and 46.2MB in the end (delta: 2.8MB). Peak memory consumption was 4.2MB. Max. memory is 16.1GB. [2022-07-21 05:01:57,224 INFO L158 Benchmark]: Boogie Preprocessor took 29.71ms. Allocated memory is still 73.4MB. Free memory was 46.2MB in the beginning and 44.6MB in the end (delta: 1.6MB). There was no memory consumed. Max. memory is 16.1GB. [2022-07-21 05:01:57,224 INFO L158 Benchmark]: RCFGBuilder took 399.23ms. Allocated memory is still 73.4MB. Free memory was 44.6MB in the beginning and 44.4MB in the end (delta: 153.1kB). Peak memory consumption was 12.3MB. Max. memory is 16.1GB. [2022-07-21 05:01:57,225 INFO L158 Benchmark]: TraceAbstraction took 7537.09ms. Allocated memory was 73.4MB in the beginning and 148.9MB in the end (delta: 75.5MB). Free memory was 43.5MB in the beginning and 90.9MB in the end (delta: -47.4MB). Peak memory consumption was 78.8MB. Max. memory is 16.1GB. [2022-07-21 05:01:57,225 INFO L158 Benchmark]: Witness Printer took 66.04ms. Allocated memory is still 148.9MB. Free memory was 90.9MB in the beginning and 84.6MB in the end (delta: 6.3MB). Peak memory consumption was 6.3MB. Max. memory is 16.1GB. [2022-07-21 05:01:57,228 INFO L339 ainManager$Toolchain]: ####################### End [Toolchain 1] ####################### --- Results --- * Results from de.uni_freiburg.informatik.ultimate.core: - StatisticsResult: Toolchain Benchmarks Benchmark results are: * CDTParser took 0.16ms. Allocated memory is still 52.4MB. Free memory is still 33.7MB. There was no memory consumed. Max. memory is 16.1GB. * CACSL2BoogieTranslator took 516.90ms. Allocated memory was 52.4MB in the beginning and 73.4MB in the end (delta: 21.0MB). Free memory was 28.3MB in the beginning and 49.0MB in the end (delta: -20.7MB). Peak memory consumption was 7.7MB. Max. memory is 16.1GB. * Boogie Procedure Inliner took 77.87ms. Allocated memory is still 73.4MB. Free memory was 49.0MB in the beginning and 46.2MB in the end (delta: 2.8MB). Peak memory consumption was 4.2MB. Max. memory is 16.1GB. * Boogie Preprocessor took 29.71ms. Allocated memory is still 73.4MB. Free memory was 46.2MB in the beginning and 44.6MB in the end (delta: 1.6MB). There was no memory consumed. Max. memory is 16.1GB. * RCFGBuilder took 399.23ms. Allocated memory is still 73.4MB. Free memory was 44.6MB in the beginning and 44.4MB in the end (delta: 153.1kB). Peak memory consumption was 12.3MB. Max. memory is 16.1GB. * TraceAbstraction took 7537.09ms. Allocated memory was 73.4MB in the beginning and 148.9MB in the end (delta: 75.5MB). Free memory was 43.5MB in the beginning and 90.9MB in the end (delta: -47.4MB). Peak memory consumption was 78.8MB. Max. memory is 16.1GB. * Witness Printer took 66.04ms. Allocated memory is still 148.9MB. Free memory was 90.9MB in the beginning and 84.6MB in the end (delta: 6.3MB). Peak memory consumption was 6.3MB. Max. memory is 16.1GB. * Results from de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction: - StatisticsResult: ErrorAutomatonStatistics NumberErrorTraces: 0, NumberStatementsAllTraces: 0, NumberRelevantStatements: 0, 0.0s ErrorAutomatonConstructionTimeTotal, 0.0s FaulLocalizationTime, NumberStatementsFirstTrace: -1, TraceLengthAvg: 0, 0.0s ErrorAutomatonConstructionTimeAvg, 0.0s ErrorAutomatonDifferenceTimeAvg, 0.0s ErrorAutomatonDifferenceTimeTotal, NumberOfNoEnhancement: 0, NumberOfFiniteEnhancement: 0, NumberOfInfiniteEnhancement: 0 - PositiveResult [Line: 878]: call to reach_error is unreachable For all program executions holds that call to reach_error is unreachable at this location - StatisticsResult: Ultimate Automizer benchmark data CFG has 9 procedures, 100 locations, 1 error locations. Started 1 CEGAR loops. OverallTime: 7.5s, OverallIterations: 13, TraceHistogramMax: 3, PathProgramHistogramMax: 2, EmptinessCheckTime: 0.0s, AutomataDifference: 2.5s, DeadEndRemovalTime: 0.0s, HoareAnnotationTime: 1.9s, InitialAbstractionConstructionTime: 0.0s, HoareTripleCheckerStatistics: 0 mSolverCounterUnknown, 1820 SdHoareTripleChecker+Valid, 1.5s IncrementalHoareTripleChecker+Time, 0 mSdLazyCounter, 1798 mSDsluCounter, 4690 SdHoareTripleChecker+Invalid, 1.2s Time, 0 mProtectedAction, 0 SdHoareTripleChecker+Unchecked, 0 IncrementalHoareTripleChecker+Unchecked, 3105 mSDsCounter, 523 IncrementalHoareTripleChecker+Valid, 0 mProtectedPredicate, 2215 IncrementalHoareTripleChecker+Invalid, 2738 SdHoareTripleChecker+Unknown, 0 mSolverCounterNotChecked, 523 mSolverCounterUnsat, 1585 mSDtfsCounter, 2215 mSolverCounterSat, 0.0s SdHoareTripleChecker+Time, 0 IncrementalHoareTripleChecker+Unknown, PredicateUnifierStatistics: 0 DeclaredPredicates, 692 GetRequests, 562 SyntacticMatches, 10 SemanticMatches, 120 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 366 ImplicationChecksByTransitivity, 0.7s Time, 0.0s BasicInterpolantAutomatonTime, BiggestAbstraction: size=947occurred in iteration=12, InterpolantAutomatonStates: 116, traceCheckStatistics: No data available, InterpolantConsolidationStatistics: No data available, PathInvariantsStatistics: No data available, 0/0 InterpolantCoveringCapability, TotalInterpolationStatistics: No data available, 0.0s DumpTime, AutomataMinimizationStatistics: 0.3s AutomataMinimizationTime, 13 MinimizatonAttempts, 254 StatesRemovedByMinimization, 9 NontrivialMinimizations, HoareAnnotationStatistics: 0.0s HoareAnnotationTime, 48 LocationsWithAnnotation, 1824 PreInvPairs, 1961 NumberOfFragments, 1228 HoareAnnotationTreeSize, 1824 FomulaSimplifications, 2237 FormulaSimplificationTreeSizeReduction, 0.3s HoareSimplificationTime, 48 FomulaSimplificationsInter, 8974 FormulaSimplificationTreeSizeReductionInter, 1.6s HoareSimplificationTimeInter, RefinementEngineStatistics: TRACE_CHECK: 0.1s SsaConstructionTime, 0.4s SatisfiabilityAnalysisTime, 1.2s InterpolantComputationTime, 1067 NumberOfCodeBlocks, 1067 NumberOfCodeBlocksAsserted, 17 NumberOfCheckSat, 1141 ConstructedInterpolants, 0 QuantifiedInterpolants, 1996 SizeOfPredicates, 11 NumberOfNonLiveVariables, 1603 ConjunctsInSsa, 23 ConjunctsInUnsatCore, 17 InterpolantComputations, 12 PerfectInterpolantSequences, 393/447 InterpolantCoveringCapability, INVARIANT_SYNTHESIS: No data available, INTERPOLANT_CONSOLIDATION: No data available, ABSTRACT_INTERPRETATION: No data available, PDR: No data available, ACCELERATED_INTERPOLATION: No data available, SIFA: No data available, ReuseStatistics: No data available - AllSpecificationsHoldResult: All specifications hold 1 specifications checked. All of them hold - InvariantResult [Line: 976]: Loop Invariant Derived loop invariant: ((!(1 <= waterLevel) || (pumpRunning == \old(pumpRunning) && \result == 0)) || 0 == systemActive) && ((!(\old(pumpRunning) == 0) || !(1 <= waterLevel)) || 0 == systemActive) - InvariantResult [Line: 837]: Loop Invariant Derived loop invariant: 1 - InvariantResult [Line: 962]: Loop Invariant Derived loop invariant: (((!(\old(pumpRunning) == 0) || !(1 <= waterLevel)) || (pumpRunning == 0 && !(\result == 0))) || (pumpRunning == 0 && 2 <= waterLevel)) || 0 == systemActive - InvariantResult [Line: 953]: Loop Invariant Derived loop invariant: (((((!(\old(pumpRunning) == 0) || !(\old(waterLevel) == 1)) || (pumpRunning == 0 && waterLevel == 1)) && (((!(\old(pumpRunning) == 0) || ((pumpRunning == 0 && 1 <= \result) && \old(waterLevel) == waterLevel)) || !(0 == systemActive)) || !(2 <= \old(waterLevel)))) && ((((2 <= waterLevel && 2 <= \result) || ((pumpRunning == 0 && 1 <= waterLevel) && 1 <= \result)) || 0 == systemActive) || !(2 <= \old(waterLevel)))) && (((!(\old(pumpRunning) == 0) || 0 == systemActive) || (\old(waterLevel) == waterLevel && 2 <= \result)) || !(2 <= \old(waterLevel)))) && ((!(\old(pumpRunning) == 0) || !(\old(waterLevel) == 1)) || \result == 1) - InvariantResult [Line: 1011]: Loop Invariant Derived loop invariant: ((pumpRunning == 0 && \result == 1) && waterLevel == 1) && !(0 == systemActive) - InvariantResult [Line: 830]: Loop Invariant Derived loop invariant: (((pumpRunning == 0 && \result == 1) && waterLevel == 1) && tmp == 1) && !(0 == systemActive) - InvariantResult [Line: 921]: Loop Invariant Derived loop invariant: (!(\old(pumpRunning) == 0) || !(1 <= \old(waterLevel))) && (((pumpRunning == \old(pumpRunning) && 1 <= waterLevel) || 0 == systemActive) || !(2 <= \old(waterLevel))) - InvariantResult [Line: 850]: Loop Invariant Derived loop invariant: 1 - InvariantResult [Line: 191]: Loop Invariant Derived loop invariant: (!(\old(pumpRunning) == 0) || !(1 <= \old(waterLevel))) && (((pumpRunning == \old(pumpRunning) && 1 <= waterLevel) || 0 == systemActive) || !(2 <= \old(waterLevel))) - InvariantResult [Line: 266]: Loop Invariant Derived loop invariant: ((!(1 <= waterLevel) || ((((pumpRunning == \old(pumpRunning) && 1 <= \result) && 1 <= tmp___0) && tmp == 0) && \result == 0)) || 0 == systemActive) && ((!(\old(pumpRunning) == 0) || !(1 <= waterLevel)) || 0 == systemActive) - InvariantResult [Line: 749]: Loop Invariant Derived loop invariant: (((((((!(\old(pumpRunning) == 0) || (((2 <= waterLevel && \old(waterLevel) == waterLevel) && 2 <= \result) && 2 <= tmp)) || 0 == systemActive) || !(2 <= \old(waterLevel))) && ((!(\old(pumpRunning) == 0) || !(\old(waterLevel) == 1)) || (tmp == 1 && \result == 1))) && (((!(\old(pumpRunning) == 0) || (pumpRunning == 0 && \old(waterLevel) == waterLevel)) || !(1 <= \old(waterLevel))) || (((2 <= waterLevel && \old(waterLevel) == waterLevel) && 2 <= \result) && 2 <= tmp))) && (((!(\old(pumpRunning) == 0) || (pumpRunning == 0 && \old(waterLevel) == waterLevel)) || !(1 <= \old(waterLevel))) || !(0 == systemActive))) && ((((((pumpRunning == 0 && 1 <= tmp) && 1 <= waterLevel) && 1 <= \result) || ((2 <= waterLevel && 2 <= \result) && 2 <= tmp)) || 0 == systemActive) || !(2 <= \old(waterLevel)))) && ((!(\old(pumpRunning) == 0) || (1 <= tmp && 1 <= \result)) || !(2 <= \old(waterLevel))) - InvariantResult [Line: 678]: Loop Invariant Derived loop invariant: 1 - InvariantResult [Line: 247]: Loop Invariant Derived loop invariant: (((!(\old(pumpRunning) == 0) || pumpRunning == 0) || !(2 <= waterLevel)) || 0 == systemActive) && (((!(waterLevel == 1) || !(\old(pumpRunning) == 0)) || ((((pumpRunning == 0 && !(\result == 0)) && \result == 0) && tmp___0 == 0) && !(tmp == 0))) || 0 == systemActive) - InvariantResult [Line: 687]: Loop Invariant Derived loop invariant: 0 - InvariantResult [Line: 776]: Loop Invariant Derived loop invariant: 1 - InvariantResult [Line: 688]: Loop Invariant Derived loop invariant: (((((pumpRunning == 0 && \result == 1) && 2 <= waterLevel) && splverifierCounter == 0) && tmp == 1) || ((((\result == 1 && 2 <= waterLevel) && splverifierCounter == 0) && tmp == 1) && !(0 == systemActive))) || ((((pumpRunning == 0 && \result == 1) && splverifierCounter == 0) && waterLevel == 1) && tmp == 1) - InvariantResult [Line: 175]: Loop Invariant Derived loop invariant: (!(waterLevel == 1) || !(\old(pumpRunning) == 0)) || 0 == systemActive - InvariantResult [Line: 1004]: Loop Invariant Derived loop invariant: (pumpRunning == 0 && waterLevel == 1) && !(0 == systemActive) - InvariantResult [Line: 874]: Loop Invariant Derived loop invariant: (!(\old(pumpRunning) == 0) || !(1 <= \old(waterLevel))) && (0 == systemActive || !(2 <= \old(waterLevel))) - InvariantResult [Line: 300]: Loop Invariant Derived loop invariant: ((((\result == 1 && 2 <= waterLevel) && splverifierCounter == 0) && tmp == 1) && !(0 == systemActive)) || (((((pumpRunning == 0 && \result == 1) && splverifierCounter == 0) && 1 <= waterLevel) && tmp == 1) && !(0 == systemActive)) - InvariantResult [Line: 885]: Loop Invariant Derived loop invariant: (!(\old(pumpRunning) == 0) || !(1 <= \old(waterLevel))) && (((pumpRunning == \old(pumpRunning) && 1 <= waterLevel) || 0 == systemActive) || !(2 <= \old(waterLevel))) - InvariantResult [Line: 997]: Loop Invariant Derived loop invariant: (pumpRunning == 0 && waterLevel == 1) && !(0 == systemActive) - InvariantResult [Line: 285]: Loop Invariant Derived loop invariant: (((((pumpRunning == 0 && \result == 1) && splverifierCounter == 0) && 0 == systemActive) && waterLevel == 1) && tmp == 1) || (((((pumpRunning == 0 && \result == 1) && 2 <= waterLevel) && splverifierCounter == 0) && 0 == systemActive) && tmp == 1) - InvariantResult [Line: 150]: Loop Invariant Derived loop invariant: (((!(\old(pumpRunning) == 0) || !(1 <= \old(waterLevel))) || !(0 == systemActive)) && (((2 <= waterLevel || 0 == systemActive) || (pumpRunning == 0 && 1 <= waterLevel)) || !(2 <= \old(waterLevel)))) && (((!(\old(pumpRunning) == 0) || (pumpRunning == 0 && \old(waterLevel) == waterLevel)) || !(1 <= \old(waterLevel))) || (2 <= waterLevel && \old(waterLevel) == waterLevel)) - InvariantResult [Line: 786]: Loop Invariant Derived loop invariant: 1 - InvariantResult [Line: 202]: Loop Invariant Derived loop invariant: (!(\old(pumpRunning) == 0) || !(1 <= \old(waterLevel))) && (0 == systemActive || !(2 <= \old(waterLevel))) RESULT: Ultimate proved your program to be correct! [2022-07-21 05:01:57,294 INFO L540 MonitoredProcess]: [MP /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in -t:2000 (1)] Forceful destruction successful, exit code 0 Received shutdown request... --- End real Ultimate output --- Execution finished normally Writing output log to file Ultimate.log Result: TRUE