./Ultimate.py --spec ../sv-benchmarks/c/properties/unreach-call.prp --file ../sv-benchmarks/c/product-lines/minepump_spec4_product60.cil.c --full-output --architecture 32bit -------------------------------------------------------------------------------- Checking for ERROR reachability Using default analysis Version 791161d1 Calling Ultimate with: /usr/bin/java -Dosgi.configuration.area=/storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/data/config -Xmx15G -Xms4m -jar /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/plugins/org.eclipse.equinox.launcher_1.5.800.v20200727-1323.jar -data @noDefault -ultimatedata /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/data -tc /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/config/AutomizerReach.xml -i ../sv-benchmarks/c/product-lines/minepump_spec4_product60.cil.c -s /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/config/svcomp-Reach-32bit-Automizer_Default.epf --cacsl2boogietranslator.entry.function main --witnessprinter.witness.directory /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux --witnessprinter.witness.filename witness.graphml --witnessprinter.write.witness.besides.input.file false --witnessprinter.graph.data.specification CHECK( init(main()), LTL(G ! call(reach_error())) ) --witnessprinter.graph.data.producer Automizer --witnessprinter.graph.data.architecture 32bit --witnessprinter.graph.data.programhash 63a498e40ee7fb7960293994084186ed238562f61fafb5e109bd8b394667fc1f --- Real Ultimate output --- This is Ultimate 0.2.2-?-791161d [2022-07-22 17:39:19,511 INFO L177 SettingsManager]: Resetting all preferences to default values... [2022-07-22 17:39:19,513 INFO L181 SettingsManager]: Resetting UltimateCore preferences to default values [2022-07-22 17:39:19,550 INFO L184 SettingsManager]: Ultimate Commandline Interface provides no preferences, ignoring... [2022-07-22 17:39:19,550 INFO L181 SettingsManager]: Resetting Boogie Preprocessor preferences to default values [2022-07-22 17:39:19,551 INFO L181 SettingsManager]: Resetting Boogie Procedure Inliner preferences to default values [2022-07-22 17:39:19,553 INFO L181 SettingsManager]: Resetting Abstract Interpretation preferences to default values [2022-07-22 17:39:19,554 INFO L181 SettingsManager]: Resetting LassoRanker preferences to default values [2022-07-22 17:39:19,556 INFO L181 SettingsManager]: Resetting Reaching Definitions preferences to default values [2022-07-22 17:39:19,556 INFO L181 SettingsManager]: Resetting SyntaxChecker preferences to default values [2022-07-22 17:39:19,557 INFO L181 SettingsManager]: Resetting Sifa preferences to default values [2022-07-22 17:39:19,558 INFO L184 SettingsManager]: Büchi Program Product provides no preferences, ignoring... [2022-07-22 17:39:19,559 INFO L181 SettingsManager]: Resetting LTL2Aut preferences to default values [2022-07-22 17:39:19,560 INFO L181 SettingsManager]: Resetting PEA to Boogie preferences to default values [2022-07-22 17:39:19,561 INFO L181 SettingsManager]: Resetting BlockEncodingV2 preferences to default values [2022-07-22 17:39:19,562 INFO L181 SettingsManager]: Resetting ChcToBoogie preferences to default values [2022-07-22 17:39:19,563 INFO L181 SettingsManager]: Resetting AutomataScriptInterpreter preferences to default values [2022-07-22 17:39:19,564 INFO L181 SettingsManager]: Resetting BuchiAutomizer preferences to default values [2022-07-22 17:39:19,566 INFO L181 SettingsManager]: Resetting CACSL2BoogieTranslator preferences to default values [2022-07-22 17:39:19,568 INFO L181 SettingsManager]: Resetting CodeCheck preferences to default values [2022-07-22 17:39:19,569 INFO L181 SettingsManager]: Resetting HornVerifier preferences to default values [2022-07-22 17:39:19,577 INFO L181 SettingsManager]: Resetting InvariantSynthesis preferences to default values [2022-07-22 17:39:19,578 INFO L181 SettingsManager]: Resetting RCFGBuilder preferences to default values [2022-07-22 17:39:19,579 INFO L181 SettingsManager]: Resetting Referee preferences to default values [2022-07-22 17:39:19,580 INFO L181 SettingsManager]: Resetting TraceAbstraction preferences to default values [2022-07-22 17:39:19,582 INFO L184 SettingsManager]: TraceAbstractionConcurrent provides no preferences, ignoring... [2022-07-22 17:39:19,582 INFO L184 SettingsManager]: TraceAbstractionWithAFAs provides no preferences, ignoring... [2022-07-22 17:39:19,583 INFO L181 SettingsManager]: Resetting TreeAutomizer preferences to default values [2022-07-22 17:39:19,583 INFO L181 SettingsManager]: Resetting IcfgToChc preferences to default values [2022-07-22 17:39:19,584 INFO L181 SettingsManager]: Resetting IcfgTransformer preferences to default values [2022-07-22 17:39:19,585 INFO L184 SettingsManager]: ReqToTest provides no preferences, ignoring... [2022-07-22 17:39:19,588 INFO L181 SettingsManager]: Resetting Boogie Printer preferences to default values [2022-07-22 17:39:19,589 INFO L181 SettingsManager]: Resetting ChcSmtPrinter preferences to default values [2022-07-22 17:39:19,590 INFO L181 SettingsManager]: Resetting ReqPrinter preferences to default values [2022-07-22 17:39:19,591 INFO L181 SettingsManager]: Resetting Witness Printer preferences to default values [2022-07-22 17:39:19,592 INFO L184 SettingsManager]: Boogie PL CUP Parser provides no preferences, ignoring... [2022-07-22 17:39:19,593 INFO L181 SettingsManager]: Resetting CDTParser preferences to default values [2022-07-22 17:39:19,593 INFO L184 SettingsManager]: AutomataScriptParser provides no preferences, ignoring... [2022-07-22 17:39:19,593 INFO L184 SettingsManager]: ReqParser provides no preferences, ignoring... [2022-07-22 17:39:19,594 INFO L181 SettingsManager]: Resetting SmtParser preferences to default values [2022-07-22 17:39:19,595 INFO L181 SettingsManager]: Resetting Witness Parser preferences to default values [2022-07-22 17:39:19,597 INFO L188 SettingsManager]: Finished resetting all preferences to default values... [2022-07-22 17:39:19,597 INFO L101 SettingsManager]: Beginning loading settings from /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/config/svcomp-Reach-32bit-Automizer_Default.epf [2022-07-22 17:39:19,636 INFO L113 SettingsManager]: Loading preferences was successful [2022-07-22 17:39:19,640 INFO L115 SettingsManager]: Preferences different from defaults after loading the file: [2022-07-22 17:39:19,641 INFO L136 SettingsManager]: Preferences of UltimateCore differ from their defaults: [2022-07-22 17:39:19,641 INFO L138 SettingsManager]: * Log level for class=de.uni_freiburg.informatik.ultimate.lib.smtlibutils.quantifier.QuantifierPusher=ERROR; [2022-07-22 17:39:19,642 INFO L136 SettingsManager]: Preferences of Boogie Procedure Inliner differ from their defaults: [2022-07-22 17:39:19,642 INFO L138 SettingsManager]: * Ignore calls to procedures called more than once=ONLY_FOR_SEQUENTIAL_PROGRAMS [2022-07-22 17:39:19,643 INFO L136 SettingsManager]: Preferences of BlockEncodingV2 differ from their defaults: [2022-07-22 17:39:19,643 INFO L138 SettingsManager]: * Create parallel compositions if possible=false [2022-07-22 17:39:19,643 INFO L138 SettingsManager]: * Use SBE=true [2022-07-22 17:39:19,644 INFO L136 SettingsManager]: Preferences of CACSL2BoogieTranslator differ from their defaults: [2022-07-22 17:39:19,645 INFO L138 SettingsManager]: * sizeof long=4 [2022-07-22 17:39:19,645 INFO L138 SettingsManager]: * Overapproximate operations on floating types=true [2022-07-22 17:39:19,645 INFO L138 SettingsManager]: * sizeof POINTER=4 [2022-07-22 17:39:19,645 INFO L138 SettingsManager]: * Check division by zero=IGNORE [2022-07-22 17:39:19,645 INFO L138 SettingsManager]: * Pointer to allocated memory at dereference=IGNORE [2022-07-22 17:39:19,646 INFO L138 SettingsManager]: * If two pointers are subtracted or compared they have the same base address=IGNORE [2022-07-22 17:39:19,646 INFO L138 SettingsManager]: * Check array bounds for arrays that are off heap=IGNORE [2022-07-22 17:39:19,646 INFO L138 SettingsManager]: * sizeof long double=12 [2022-07-22 17:39:19,646 INFO L138 SettingsManager]: * Check if freed pointer was valid=false [2022-07-22 17:39:19,646 INFO L138 SettingsManager]: * Use constant arrays=true [2022-07-22 17:39:19,646 INFO L138 SettingsManager]: * Pointer base address is valid at dereference=IGNORE [2022-07-22 17:39:19,647 INFO L136 SettingsManager]: Preferences of RCFGBuilder differ from their defaults: [2022-07-22 17:39:19,647 INFO L138 SettingsManager]: * Size of a code block=SequenceOfStatements [2022-07-22 17:39:19,648 INFO L138 SettingsManager]: * SMT solver=External_DefaultMode [2022-07-22 17:39:19,648 INFO L138 SettingsManager]: * Command for external solver=z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in -t:2000 [2022-07-22 17:39:19,648 INFO L136 SettingsManager]: Preferences of TraceAbstraction differ from their defaults: [2022-07-22 17:39:19,648 INFO L138 SettingsManager]: * Compute Interpolants along a Counterexample=FPandBP [2022-07-22 17:39:19,649 INFO L138 SettingsManager]: * Positions where we compute the Hoare Annotation=LoopsAndPotentialCycles [2022-07-22 17:39:19,649 INFO L138 SettingsManager]: * Trace refinement strategy=CAMEL [2022-07-22 17:39:19,649 INFO L138 SettingsManager]: * Command for external solver=z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in [2022-07-22 17:39:19,649 INFO L138 SettingsManager]: * Apply one-shot large block encoding in concurrent analysis=false [2022-07-22 17:39:19,650 INFO L138 SettingsManager]: * Automaton type used in concurrency analysis=PETRI_NET [2022-07-22 17:39:19,650 INFO L138 SettingsManager]: * Compute Hoare Annotation of negated interpolant automaton, abstraction and CFG=true [2022-07-22 17:39:19,650 INFO L138 SettingsManager]: * SMT solver=External_ModelsAndUnsatCoreMode WARNING: An illegal reflective access operation has occurred WARNING: Illegal reflective access by com.sun.xml.bind.v2.runtime.reflect.opt.Injector$1 (file:/storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/plugins/com.sun.xml.bind_2.2.0.v201505121915.jar) to method java.lang.ClassLoader.defineClass(java.lang.String,byte[],int,int) WARNING: Please consider reporting this to the maintainers of com.sun.xml.bind.v2.runtime.reflect.opt.Injector$1 WARNING: Use --illegal-access=warn to enable warnings of further illegal reflective access operations WARNING: All illegal access operations will be denied in a future release Applying setting for plugin de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator: Entry function -> main Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Witness directory -> /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Witness filename -> witness.graphml Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Write witness besides input file -> false Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Graph data specification -> CHECK( init(main()), LTL(G ! call(reach_error())) ) Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Graph data producer -> Automizer Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Graph data architecture -> 32bit Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Graph data programhash -> 63a498e40ee7fb7960293994084186ed238562f61fafb5e109bd8b394667fc1f [2022-07-22 17:39:19,872 INFO L75 nceAwareModelManager]: Repository-Root is: /tmp [2022-07-22 17:39:19,899 INFO L261 ainManager$Toolchain]: [Toolchain 1]: Applicable parser(s) successfully (re)initialized [2022-07-22 17:39:19,902 INFO L217 ainManager$Toolchain]: [Toolchain 1]: Toolchain selected. [2022-07-22 17:39:19,903 INFO L271 PluginConnector]: Initializing CDTParser... [2022-07-22 17:39:19,904 INFO L275 PluginConnector]: CDTParser initialized [2022-07-22 17:39:19,905 INFO L432 ainManager$Toolchain]: [Toolchain 1]: Parsing single file: /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/../sv-benchmarks/c/product-lines/minepump_spec4_product60.cil.c [2022-07-22 17:39:19,972 INFO L220 CDTParser]: Created temporary CDT project at /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/data/5a7294f80/a1d4fbc6a4804cd089639084f7edec4b/FLAG2a1e942c6 [2022-07-22 17:39:20,492 INFO L306 CDTParser]: Found 1 translation units. [2022-07-22 17:39:20,493 INFO L160 CDTParser]: Scanning /storage/repos/ultimate/releaseScripts/default/sv-benchmarks/c/product-lines/minepump_spec4_product60.cil.c [2022-07-22 17:39:20,504 INFO L349 CDTParser]: About to delete temporary CDT project at /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/data/5a7294f80/a1d4fbc6a4804cd089639084f7edec4b/FLAG2a1e942c6 [2022-07-22 17:39:20,845 INFO L357 CDTParser]: Successfully deleted /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/data/5a7294f80/a1d4fbc6a4804cd089639084f7edec4b [2022-07-22 17:39:20,847 INFO L299 ainManager$Toolchain]: ####################### [Toolchain 1] ####################### [2022-07-22 17:39:20,849 INFO L131 ToolchainWalker]: Walking toolchain with 6 elements. [2022-07-22 17:39:20,852 INFO L113 PluginConnector]: ------------------------CACSL2BoogieTranslator---------------------------- [2022-07-22 17:39:20,852 INFO L271 PluginConnector]: Initializing CACSL2BoogieTranslator... [2022-07-22 17:39:20,855 INFO L275 PluginConnector]: CACSL2BoogieTranslator initialized [2022-07-22 17:39:20,855 INFO L185 PluginConnector]: Executing the observer ACSLObjectContainerObserver from plugin CACSL2BoogieTranslator for "CDTParser AST 22.07 05:39:20" (1/1) ... [2022-07-22 17:39:20,856 INFO L205 PluginConnector]: Invalid model from CACSL2BoogieTranslator for observer de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator.ACSLObjectContainerObserver@35b1e301 and model type de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 22.07 05:39:20, skipping insertion in model container [2022-07-22 17:39:20,857 INFO L185 PluginConnector]: Executing the observer CACSL2BoogieTranslatorObserver from plugin CACSL2BoogieTranslator for "CDTParser AST 22.07 05:39:20" (1/1) ... [2022-07-22 17:39:20,864 INFO L145 MainTranslator]: Starting translation in SV-COMP mode [2022-07-22 17:39:20,912 INFO L178 MainTranslator]: Built tables and reachable declarations [2022-07-22 17:39:21,142 WARN L230 ndardFunctionHandler]: Function reach_error is already implemented but we override the implementation for the call at /storage/repos/ultimate/releaseScripts/default/sv-benchmarks/c/product-lines/minepump_spec4_product60.cil.c[13463,13476] [2022-07-22 17:39:21,175 INFO L210 PostProcessor]: Analyzing one entry point: main [2022-07-22 17:39:21,183 INFO L203 MainTranslator]: Completed pre-run [2022-07-22 17:39:21,222 WARN L230 ndardFunctionHandler]: Function reach_error is already implemented but we override the implementation for the call at /storage/repos/ultimate/releaseScripts/default/sv-benchmarks/c/product-lines/minepump_spec4_product60.cil.c[13463,13476] [2022-07-22 17:39:21,238 INFO L210 PostProcessor]: Analyzing one entry point: main [2022-07-22 17:39:21,253 INFO L208 MainTranslator]: Completed translation [2022-07-22 17:39:21,254 INFO L202 PluginConnector]: Adding new model de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 22.07 05:39:21 WrapperNode [2022-07-22 17:39:21,254 INFO L132 PluginConnector]: ------------------------ END CACSL2BoogieTranslator---------------------------- [2022-07-22 17:39:21,255 INFO L113 PluginConnector]: ------------------------Boogie Procedure Inliner---------------------------- [2022-07-22 17:39:21,255 INFO L271 PluginConnector]: Initializing Boogie Procedure Inliner... [2022-07-22 17:39:21,255 INFO L275 PluginConnector]: Boogie Procedure Inliner initialized [2022-07-22 17:39:21,265 INFO L185 PluginConnector]: Executing the observer TypeChecker from plugin Boogie Procedure Inliner for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 22.07 05:39:21" (1/1) ... [2022-07-22 17:39:21,287 INFO L185 PluginConnector]: Executing the observer Inliner from plugin Boogie Procedure Inliner for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 22.07 05:39:21" (1/1) ... [2022-07-22 17:39:21,327 INFO L137 Inliner]: procedures = 58, calls = 159, calls flagged for inlining = 27, calls inlined = 24, statements flattened = 286 [2022-07-22 17:39:21,328 INFO L132 PluginConnector]: ------------------------ END Boogie Procedure Inliner---------------------------- [2022-07-22 17:39:21,329 INFO L113 PluginConnector]: ------------------------Boogie Preprocessor---------------------------- [2022-07-22 17:39:21,329 INFO L271 PluginConnector]: Initializing Boogie Preprocessor... [2022-07-22 17:39:21,329 INFO L275 PluginConnector]: Boogie Preprocessor initialized [2022-07-22 17:39:21,336 INFO L185 PluginConnector]: Executing the observer EnsureBoogieModelObserver from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 22.07 05:39:21" (1/1) ... [2022-07-22 17:39:21,337 INFO L185 PluginConnector]: Executing the observer TypeChecker from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 22.07 05:39:21" (1/1) ... [2022-07-22 17:39:21,349 INFO L185 PluginConnector]: Executing the observer ConstExpander from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 22.07 05:39:21" (1/1) ... [2022-07-22 17:39:21,353 INFO L185 PluginConnector]: Executing the observer StructExpander from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 22.07 05:39:21" (1/1) ... [2022-07-22 17:39:21,359 INFO L185 PluginConnector]: Executing the observer UnstructureCode from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 22.07 05:39:21" (1/1) ... [2022-07-22 17:39:21,374 INFO L185 PluginConnector]: Executing the observer FunctionInliner from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 22.07 05:39:21" (1/1) ... [2022-07-22 17:39:21,377 INFO L185 PluginConnector]: Executing the observer BoogieSymbolTableConstructor from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 22.07 05:39:21" (1/1) ... [2022-07-22 17:39:21,380 INFO L132 PluginConnector]: ------------------------ END Boogie Preprocessor---------------------------- [2022-07-22 17:39:21,381 INFO L113 PluginConnector]: ------------------------RCFGBuilder---------------------------- [2022-07-22 17:39:21,381 INFO L271 PluginConnector]: Initializing RCFGBuilder... [2022-07-22 17:39:21,381 INFO L275 PluginConnector]: RCFGBuilder initialized [2022-07-22 17:39:21,383 INFO L185 PluginConnector]: Executing the observer RCFGBuilderObserver from plugin RCFGBuilder for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 22.07 05:39:21" (1/1) ... [2022-07-22 17:39:21,390 INFO L173 SolverBuilder]: Constructing external solver with command: z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in -t:2000 [2022-07-22 17:39:21,404 INFO L189 MonitoredProcess]: No working directory specified, using /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 [2022-07-22 17:39:21,415 INFO L229 MonitoredProcess]: Starting monitored process 1 with /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in -t:2000 (exit command is (exit), workingDir is null) [2022-07-22 17:39:21,422 INFO L327 MonitoredProcess]: [MP /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in -t:2000 (1)] Waiting until timeout for monitored process [2022-07-22 17:39:21,447 INFO L130 BoogieDeclarations]: Found specification of procedure #Ultimate.allocInit [2022-07-22 17:39:21,447 INFO L130 BoogieDeclarations]: Found specification of procedure processEnvironment__wrappee__base [2022-07-22 17:39:21,449 INFO L138 BoogieDeclarations]: Found implementation of procedure processEnvironment__wrappee__base [2022-07-22 17:39:21,449 INFO L130 BoogieDeclarations]: Found specification of procedure timeShift [2022-07-22 17:39:21,449 INFO L138 BoogieDeclarations]: Found implementation of procedure timeShift [2022-07-22 17:39:21,449 INFO L130 BoogieDeclarations]: Found specification of procedure cleanup [2022-07-22 17:39:21,449 INFO L138 BoogieDeclarations]: Found implementation of procedure cleanup [2022-07-22 17:39:21,449 INFO L130 BoogieDeclarations]: Found specification of procedure processEnvironment__wrappee__highWaterSensor [2022-07-22 17:39:21,450 INFO L138 BoogieDeclarations]: Found implementation of procedure processEnvironment__wrappee__highWaterSensor [2022-07-22 17:39:21,450 INFO L130 BoogieDeclarations]: Found specification of procedure waterRise [2022-07-22 17:39:21,450 INFO L138 BoogieDeclarations]: Found implementation of procedure waterRise [2022-07-22 17:39:21,450 INFO L130 BoogieDeclarations]: Found specification of procedure deactivatePump [2022-07-22 17:39:21,450 INFO L138 BoogieDeclarations]: Found implementation of procedure deactivatePump [2022-07-22 17:39:21,450 INFO L130 BoogieDeclarations]: Found specification of procedure write~init~int [2022-07-22 17:39:21,451 INFO L130 BoogieDeclarations]: Found specification of procedure changeMethaneLevel [2022-07-22 17:39:21,451 INFO L138 BoogieDeclarations]: Found implementation of procedure changeMethaneLevel [2022-07-22 17:39:21,451 INFO L130 BoogieDeclarations]: Found specification of procedure ULTIMATE.start [2022-07-22 17:39:21,451 INFO L138 BoogieDeclarations]: Found implementation of procedure ULTIMATE.start [2022-07-22 17:39:21,522 INFO L234 CfgBuilder]: Building ICFG [2022-07-22 17:39:21,523 INFO L260 CfgBuilder]: Building CFG for each procedure with an implementation [2022-07-22 17:39:21,779 INFO L275 CfgBuilder]: Performing block encoding [2022-07-22 17:39:21,785 INFO L294 CfgBuilder]: Using the 1 location(s) as analysis (start of procedure ULTIMATE.start) [2022-07-22 17:39:21,786 INFO L299 CfgBuilder]: Removed 2 assume(true) statements. [2022-07-22 17:39:21,787 INFO L202 PluginConnector]: Adding new model de.uni_freiburg.informatik.ultimate.plugins.generator.rcfgbuilder CFG 22.07 05:39:21 BoogieIcfgContainer [2022-07-22 17:39:21,788 INFO L132 PluginConnector]: ------------------------ END RCFGBuilder---------------------------- [2022-07-22 17:39:21,789 INFO L113 PluginConnector]: ------------------------TraceAbstraction---------------------------- [2022-07-22 17:39:21,790 INFO L271 PluginConnector]: Initializing TraceAbstraction... [2022-07-22 17:39:21,793 INFO L275 PluginConnector]: TraceAbstraction initialized [2022-07-22 17:39:21,793 INFO L185 PluginConnector]: Executing the observer TraceAbstractionObserver from plugin TraceAbstraction for "CDTParser AST 22.07 05:39:20" (1/3) ... [2022-07-22 17:39:21,794 INFO L205 PluginConnector]: Invalid model from TraceAbstraction for observer de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction.TraceAbstractionObserver@1aedf36e and model type de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction AST 22.07 05:39:21, skipping insertion in model container [2022-07-22 17:39:21,794 INFO L185 PluginConnector]: Executing the observer TraceAbstractionObserver from plugin TraceAbstraction for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 22.07 05:39:21" (2/3) ... [2022-07-22 17:39:21,794 INFO L205 PluginConnector]: Invalid model from TraceAbstraction for observer de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction.TraceAbstractionObserver@1aedf36e and model type de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction AST 22.07 05:39:21, skipping insertion in model container [2022-07-22 17:39:21,794 INFO L185 PluginConnector]: Executing the observer TraceAbstractionObserver from plugin TraceAbstraction for "de.uni_freiburg.informatik.ultimate.plugins.generator.rcfgbuilder CFG 22.07 05:39:21" (3/3) ... [2022-07-22 17:39:21,795 INFO L111 eAbstractionObserver]: Analyzing ICFG minepump_spec4_product60.cil.c [2022-07-22 17:39:21,808 INFO L201 ceAbstractionStarter]: Automizer settings: Hoare:true NWA Interpolation:FPandBP Determinization: PREDICATE_ABSTRACTION [2022-07-22 17:39:21,808 INFO L160 ceAbstractionStarter]: Applying trace abstraction to program that has 1 error locations. [2022-07-22 17:39:21,882 INFO L356 AbstractCegarLoop]: ======== Iteration 0 == of CEGAR loop == AllErrorsAtOnce ======== [2022-07-22 17:39:21,888 INFO L357 AbstractCegarLoop]: Settings: SEPARATE_VIOLATION_CHECK=true, mInterprocedural=true, mMaxIterations=1000000, mWatchIteration=1000000, mArtifact=RCFG, mInterpolation=FPandBP, mInterpolantAutomaton=STRAIGHT_LINE, mDumpAutomata=false, mAutomataFormat=ATS_NUMERATE, mDumpPath=., mDeterminiation=PREDICATE_ABSTRACTION, mMinimize=MINIMIZE_SEVPA, mHoare=true, mAutomataTypeConcurrency=PETRI_NET, mHoareTripleChecks=INCREMENTAL, mHoareAnnotationPositions=LoopsAndPotentialCycles, mDumpOnlyReuseAutomata=false, mLimitTraceHistogram=0, mErrorLocTimeLimit=0, mLimitPathProgramCount=0, mCollectInterpolantStatistics=true, mHeuristicEmptinessCheck=false, mHeuristicEmptinessCheckAStarHeuristic=ZERO, mHeuristicEmptinessCheckAStarHeuristicRandomSeed=1337, mHeuristicEmptinessCheckSmtFeatureScoringMethod=DAGSIZE, mSMTFeatureExtraction=false, mSMTFeatureExtractionDumpPath=., mOverrideInterpolantAutomaton=false, mMcrInterpolantMethod=WP, mPorIndependenceSettings=de.uni_freiburg.informatik.ultimate.lib.tracecheckerutils.partialorder.independence.IndependenceSettings@75236c1f, mLbeIndependenceSettings=de.uni_freiburg.informatik.ultimate.lib.tracecheckerutils.partialorder.independence.IndependenceSettings@28e6a97b [2022-07-22 17:39:21,889 INFO L358 AbstractCegarLoop]: Starting to check reachability of 1 error locations. [2022-07-22 17:39:21,893 INFO L276 IsEmpty]: Start isEmpty. Operand has 94 states, 73 states have (on average 1.3835616438356164) internal successors, (101), 82 states have internal predecessors, (101), 12 states have call successors, (12), 7 states have call predecessors, (12), 7 states have return successors, (12), 9 states have call predecessors, (12), 12 states have call successors, (12) [2022-07-22 17:39:21,901 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 20 [2022-07-22 17:39:21,901 INFO L187 NwaCegarLoop]: Found error trace [2022-07-22 17:39:21,902 INFO L195 NwaCegarLoop]: trace histogram [1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-07-22 17:39:21,902 INFO L420 AbstractCegarLoop]: === Iteration 1 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2022-07-22 17:39:21,908 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2022-07-22 17:39:21,908 INFO L85 PathProgramCache]: Analyzing trace with hash 194395982, now seen corresponding path program 1 times [2022-07-22 17:39:21,916 INFO L118 FreeRefinementEngine]: Executing refinement strategy CAMEL [2022-07-22 17:39:21,917 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [1300187186] [2022-07-22 17:39:21,917 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-07-22 17:39:21,918 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2022-07-22 17:39:22,046 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-07-22 17:39:22,096 INFO L134 CoverageAnalysis]: Checked inductivity of 0 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2022-07-22 17:39:22,097 INFO L136 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2022-07-22 17:39:22,097 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [1300187186] [2022-07-22 17:39:22,098 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [1300187186] provided 1 perfect and 0 imperfect interpolant sequences [2022-07-22 17:39:22,098 INFO L184 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2022-07-22 17:39:22,098 INFO L197 FreeRefinementEngine]: Number of different interpolants: perfect sequences [2] imperfect sequences [] total 2 [2022-07-22 17:39:22,099 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [599548639] [2022-07-22 17:39:22,100 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2022-07-22 17:39:22,103 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 2 states [2022-07-22 17:39:22,104 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2022-07-22 17:39:22,130 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 2 interpolants. [2022-07-22 17:39:22,131 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=1, Invalid=1, Unknown=0, NotChecked=0, Total=2 [2022-07-22 17:39:22,134 INFO L87 Difference]: Start difference. First operand has 94 states, 73 states have (on average 1.3835616438356164) internal successors, (101), 82 states have internal predecessors, (101), 12 states have call successors, (12), 7 states have call predecessors, (12), 7 states have return successors, (12), 9 states have call predecessors, (12), 12 states have call successors, (12) Second operand has 2 states, 2 states have (on average 8.5) internal successors, (17), 2 states have internal predecessors, (17), 1 states have call successors, (2), 1 states have call predecessors, (2), 0 states have return successors, (0), 0 states have call predecessors, (0), 0 states have call successors, (0) [2022-07-22 17:39:22,187 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-07-22 17:39:22,188 INFO L93 Difference]: Finished difference Result 180 states and 245 transitions. [2022-07-22 17:39:22,189 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 2 states. [2022-07-22 17:39:22,190 INFO L78 Accepts]: Start accepts. Automaton has has 2 states, 2 states have (on average 8.5) internal successors, (17), 2 states have internal predecessors, (17), 1 states have call successors, (2), 1 states have call predecessors, (2), 0 states have return successors, (0), 0 states have call predecessors, (0), 0 states have call successors, (0) Word has length 19 [2022-07-22 17:39:22,190 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2022-07-22 17:39:22,205 INFO L225 Difference]: With dead ends: 180 [2022-07-22 17:39:22,205 INFO L226 Difference]: Without dead ends: 85 [2022-07-22 17:39:22,210 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 2 GetRequests, 2 SyntacticMatches, 0 SemanticMatches, 0 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 0 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=1, Invalid=1, Unknown=0, NotChecked=0, Total=2 [2022-07-22 17:39:22,215 INFO L413 NwaCegarLoop]: 119 mSDtfsCounter, 0 mSDsluCounter, 0 mSDsCounter, 0 mSdLazyCounter, 0 mSolverCounterSat, 0 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.0s Time, 0 mProtectedPredicate, 0 mProtectedAction, 0 SdHoareTripleChecker+Valid, 119 SdHoareTripleChecker+Invalid, 0 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 0 IncrementalHoareTripleChecker+Valid, 0 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.0s IncrementalHoareTripleChecker+Time [2022-07-22 17:39:22,215 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [0 Valid, 119 Invalid, 0 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [0 Valid, 0 Invalid, 0 Unknown, 0 Unchecked, 0.0s Time] [2022-07-22 17:39:22,226 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 85 states. [2022-07-22 17:39:22,245 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 85 to 85. [2022-07-22 17:39:22,247 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 85 states, 66 states have (on average 1.3181818181818181) internal successors, (87), 74 states have internal predecessors, (87), 12 states have call successors, (12), 7 states have call predecessors, (12), 6 states have return successors, (11), 8 states have call predecessors, (11), 11 states have call successors, (11) [2022-07-22 17:39:22,249 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 85 states to 85 states and 110 transitions. [2022-07-22 17:39:22,250 INFO L78 Accepts]: Start accepts. Automaton has 85 states and 110 transitions. Word has length 19 [2022-07-22 17:39:22,250 INFO L84 Accepts]: Finished accepts. word is rejected. [2022-07-22 17:39:22,251 INFO L495 AbstractCegarLoop]: Abstraction has 85 states and 110 transitions. [2022-07-22 17:39:22,251 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 2 states, 2 states have (on average 8.5) internal successors, (17), 2 states have internal predecessors, (17), 1 states have call successors, (2), 1 states have call predecessors, (2), 0 states have return successors, (0), 0 states have call predecessors, (0), 0 states have call successors, (0) [2022-07-22 17:39:22,251 INFO L276 IsEmpty]: Start isEmpty. Operand 85 states and 110 transitions. [2022-07-22 17:39:22,253 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 21 [2022-07-22 17:39:22,253 INFO L187 NwaCegarLoop]: Found error trace [2022-07-22 17:39:22,253 INFO L195 NwaCegarLoop]: trace histogram [1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-07-22 17:39:22,254 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable0 [2022-07-22 17:39:22,254 INFO L420 AbstractCegarLoop]: === Iteration 2 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2022-07-22 17:39:22,255 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2022-07-22 17:39:22,255 INFO L85 PathProgramCache]: Analyzing trace with hash -891560987, now seen corresponding path program 1 times [2022-07-22 17:39:22,255 INFO L118 FreeRefinementEngine]: Executing refinement strategy CAMEL [2022-07-22 17:39:22,255 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [752341990] [2022-07-22 17:39:22,255 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-07-22 17:39:22,256 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2022-07-22 17:39:22,280 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-07-22 17:39:22,316 INFO L134 CoverageAnalysis]: Checked inductivity of 0 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2022-07-22 17:39:22,317 INFO L136 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2022-07-22 17:39:22,317 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [752341990] [2022-07-22 17:39:22,317 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [752341990] provided 1 perfect and 0 imperfect interpolant sequences [2022-07-22 17:39:22,317 INFO L184 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2022-07-22 17:39:22,318 INFO L197 FreeRefinementEngine]: Number of different interpolants: perfect sequences [3] imperfect sequences [] total 3 [2022-07-22 17:39:22,318 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [46652378] [2022-07-22 17:39:22,318 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2022-07-22 17:39:22,319 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 3 states [2022-07-22 17:39:22,319 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2022-07-22 17:39:22,328 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 3 interpolants. [2022-07-22 17:39:22,328 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=3, Invalid=3, Unknown=0, NotChecked=0, Total=6 [2022-07-22 17:39:22,329 INFO L87 Difference]: Start difference. First operand 85 states and 110 transitions. Second operand has 3 states, 3 states have (on average 6.0) internal successors, (18), 3 states have internal predecessors, (18), 1 states have call successors, (2), 1 states have call predecessors, (2), 0 states have return successors, (0), 0 states have call predecessors, (0), 0 states have call successors, (0) [2022-07-22 17:39:22,344 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-07-22 17:39:22,347 INFO L93 Difference]: Finished difference Result 131 states and 169 transitions. [2022-07-22 17:39:22,348 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 3 states. [2022-07-22 17:39:22,349 INFO L78 Accepts]: Start accepts. Automaton has has 3 states, 3 states have (on average 6.0) internal successors, (18), 3 states have internal predecessors, (18), 1 states have call successors, (2), 1 states have call predecessors, (2), 0 states have return successors, (0), 0 states have call predecessors, (0), 0 states have call successors, (0) Word has length 20 [2022-07-22 17:39:22,349 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2022-07-22 17:39:22,352 INFO L225 Difference]: With dead ends: 131 [2022-07-22 17:39:22,352 INFO L226 Difference]: Without dead ends: 76 [2022-07-22 17:39:22,353 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 3 GetRequests, 2 SyntacticMatches, 0 SemanticMatches, 1 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 0 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=3, Invalid=3, Unknown=0, NotChecked=0, Total=6 [2022-07-22 17:39:22,354 INFO L413 NwaCegarLoop]: 97 mSDtfsCounter, 17 mSDsluCounter, 75 mSDsCounter, 0 mSdLazyCounter, 1 mSolverCounterSat, 0 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.0s Time, 0 mProtectedPredicate, 0 mProtectedAction, 21 SdHoareTripleChecker+Valid, 172 SdHoareTripleChecker+Invalid, 1 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 0 IncrementalHoareTripleChecker+Valid, 1 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.0s IncrementalHoareTripleChecker+Time [2022-07-22 17:39:22,355 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [21 Valid, 172 Invalid, 1 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [0 Valid, 1 Invalid, 0 Unknown, 0 Unchecked, 0.0s Time] [2022-07-22 17:39:22,356 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 76 states. [2022-07-22 17:39:22,363 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 76 to 76. [2022-07-22 17:39:22,371 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 76 states, 60 states have (on average 1.3333333333333333) internal successors, (80), 68 states have internal predecessors, (80), 9 states have call successors, (9), 6 states have call predecessors, (9), 6 states have return successors, (9), 6 states have call predecessors, (9), 9 states have call successors, (9) [2022-07-22 17:39:22,373 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 76 states to 76 states and 98 transitions. [2022-07-22 17:39:22,373 INFO L78 Accepts]: Start accepts. Automaton has 76 states and 98 transitions. Word has length 20 [2022-07-22 17:39:22,373 INFO L84 Accepts]: Finished accepts. word is rejected. [2022-07-22 17:39:22,373 INFO L495 AbstractCegarLoop]: Abstraction has 76 states and 98 transitions. [2022-07-22 17:39:22,374 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 3 states, 3 states have (on average 6.0) internal successors, (18), 3 states have internal predecessors, (18), 1 states have call successors, (2), 1 states have call predecessors, (2), 0 states have return successors, (0), 0 states have call predecessors, (0), 0 states have call successors, (0) [2022-07-22 17:39:22,374 INFO L276 IsEmpty]: Start isEmpty. Operand 76 states and 98 transitions. [2022-07-22 17:39:22,375 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 26 [2022-07-22 17:39:22,375 INFO L187 NwaCegarLoop]: Found error trace [2022-07-22 17:39:22,375 INFO L195 NwaCegarLoop]: trace histogram [1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-07-22 17:39:22,375 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable1 [2022-07-22 17:39:22,375 INFO L420 AbstractCegarLoop]: === Iteration 3 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2022-07-22 17:39:22,376 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2022-07-22 17:39:22,376 INFO L85 PathProgramCache]: Analyzing trace with hash 1763827496, now seen corresponding path program 1 times [2022-07-22 17:39:22,376 INFO L118 FreeRefinementEngine]: Executing refinement strategy CAMEL [2022-07-22 17:39:22,377 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [1610784366] [2022-07-22 17:39:22,377 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-07-22 17:39:22,377 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2022-07-22 17:39:22,411 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-07-22 17:39:22,474 INFO L134 CoverageAnalysis]: Checked inductivity of 0 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2022-07-22 17:39:22,474 INFO L136 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2022-07-22 17:39:22,474 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [1610784366] [2022-07-22 17:39:22,474 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [1610784366] provided 1 perfect and 0 imperfect interpolant sequences [2022-07-22 17:39:22,474 INFO L184 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2022-07-22 17:39:22,475 INFO L197 FreeRefinementEngine]: Number of different interpolants: perfect sequences [5] imperfect sequences [] total 5 [2022-07-22 17:39:22,475 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [1875329161] [2022-07-22 17:39:22,475 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2022-07-22 17:39:22,475 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 6 states [2022-07-22 17:39:22,476 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2022-07-22 17:39:22,476 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 6 interpolants. [2022-07-22 17:39:22,476 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=10, Invalid=20, Unknown=0, NotChecked=0, Total=30 [2022-07-22 17:39:22,476 INFO L87 Difference]: Start difference. First operand 76 states and 98 transitions. Second operand has 6 states, 6 states have (on average 4.0) internal successors, (24), 5 states have internal predecessors, (24), 1 states have call successors, (1), 1 states have call predecessors, (1), 0 states have return successors, (0), 0 states have call predecessors, (0), 0 states have call successors, (0) [2022-07-22 17:39:22,664 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-07-22 17:39:22,664 INFO L93 Difference]: Finished difference Result 266 states and 356 transitions. [2022-07-22 17:39:22,665 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 6 states. [2022-07-22 17:39:22,665 INFO L78 Accepts]: Start accepts. Automaton has has 6 states, 6 states have (on average 4.0) internal successors, (24), 5 states have internal predecessors, (24), 1 states have call successors, (1), 1 states have call predecessors, (1), 0 states have return successors, (0), 0 states have call predecessors, (0), 0 states have call successors, (0) Word has length 25 [2022-07-22 17:39:22,665 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2022-07-22 17:39:22,667 INFO L225 Difference]: With dead ends: 266 [2022-07-22 17:39:22,668 INFO L226 Difference]: Without dead ends: 197 [2022-07-22 17:39:22,669 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 7 GetRequests, 1 SyntacticMatches, 0 SemanticMatches, 6 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 0 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=22, Invalid=34, Unknown=0, NotChecked=0, Total=56 [2022-07-22 17:39:22,670 INFO L413 NwaCegarLoop]: 119 mSDtfsCounter, 284 mSDsluCounter, 339 mSDsCounter, 0 mSdLazyCounter, 101 mSolverCounterSat, 41 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.1s Time, 0 mProtectedPredicate, 0 mProtectedAction, 284 SdHoareTripleChecker+Valid, 458 SdHoareTripleChecker+Invalid, 142 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 41 IncrementalHoareTripleChecker+Valid, 101 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.1s IncrementalHoareTripleChecker+Time [2022-07-22 17:39:22,670 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [284 Valid, 458 Invalid, 142 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [41 Valid, 101 Invalid, 0 Unknown, 0 Unchecked, 0.1s Time] [2022-07-22 17:39:22,672 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 197 states. [2022-07-22 17:39:22,690 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 197 to 175. [2022-07-22 17:39:22,693 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 175 states, 136 states have (on average 1.3676470588235294) internal successors, (186), 154 states have internal predecessors, (186), 22 states have call successors, (22), 16 states have call predecessors, (22), 16 states have return successors, (23), 14 states have call predecessors, (23), 22 states have call successors, (23) [2022-07-22 17:39:22,697 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 175 states to 175 states and 231 transitions. [2022-07-22 17:39:22,697 INFO L78 Accepts]: Start accepts. Automaton has 175 states and 231 transitions. Word has length 25 [2022-07-22 17:39:22,698 INFO L84 Accepts]: Finished accepts. word is rejected. [2022-07-22 17:39:22,698 INFO L495 AbstractCegarLoop]: Abstraction has 175 states and 231 transitions. [2022-07-22 17:39:22,698 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 6 states, 6 states have (on average 4.0) internal successors, (24), 5 states have internal predecessors, (24), 1 states have call successors, (1), 1 states have call predecessors, (1), 0 states have return successors, (0), 0 states have call predecessors, (0), 0 states have call successors, (0) [2022-07-22 17:39:22,698 INFO L276 IsEmpty]: Start isEmpty. Operand 175 states and 231 transitions. [2022-07-22 17:39:22,700 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 29 [2022-07-22 17:39:22,700 INFO L187 NwaCegarLoop]: Found error trace [2022-07-22 17:39:22,700 INFO L195 NwaCegarLoop]: trace histogram [1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-07-22 17:39:22,700 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable2 [2022-07-22 17:39:22,700 INFO L420 AbstractCegarLoop]: === Iteration 4 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2022-07-22 17:39:22,701 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2022-07-22 17:39:22,701 INFO L85 PathProgramCache]: Analyzing trace with hash 687850495, now seen corresponding path program 1 times [2022-07-22 17:39:22,701 INFO L118 FreeRefinementEngine]: Executing refinement strategy CAMEL [2022-07-22 17:39:22,702 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [1863592123] [2022-07-22 17:39:22,702 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-07-22 17:39:22,702 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2022-07-22 17:39:22,722 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-07-22 17:39:22,763 INFO L134 CoverageAnalysis]: Checked inductivity of 0 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2022-07-22 17:39:22,763 INFO L136 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2022-07-22 17:39:22,764 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [1863592123] [2022-07-22 17:39:22,764 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [1863592123] provided 1 perfect and 0 imperfect interpolant sequences [2022-07-22 17:39:22,764 INFO L184 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2022-07-22 17:39:22,764 INFO L197 FreeRefinementEngine]: Number of different interpolants: perfect sequences [4] imperfect sequences [] total 4 [2022-07-22 17:39:22,764 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [1148956351] [2022-07-22 17:39:22,765 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2022-07-22 17:39:22,765 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 5 states [2022-07-22 17:39:22,765 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2022-07-22 17:39:22,766 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 5 interpolants. [2022-07-22 17:39:22,766 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=7, Invalid=13, Unknown=0, NotChecked=0, Total=20 [2022-07-22 17:39:22,766 INFO L87 Difference]: Start difference. First operand 175 states and 231 transitions. Second operand has 5 states, 5 states have (on average 5.4) internal successors, (27), 4 states have internal predecessors, (27), 1 states have call successors, (1), 1 states have call predecessors, (1), 0 states have return successors, (0), 0 states have call predecessors, (0), 0 states have call successors, (0) [2022-07-22 17:39:22,820 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-07-22 17:39:22,821 INFO L93 Difference]: Finished difference Result 494 states and 678 transitions. [2022-07-22 17:39:22,821 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 5 states. [2022-07-22 17:39:22,821 INFO L78 Accepts]: Start accepts. Automaton has has 5 states, 5 states have (on average 5.4) internal successors, (27), 4 states have internal predecessors, (27), 1 states have call successors, (1), 1 states have call predecessors, (1), 0 states have return successors, (0), 0 states have call predecessors, (0), 0 states have call successors, (0) Word has length 28 [2022-07-22 17:39:22,822 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2022-07-22 17:39:22,824 INFO L225 Difference]: With dead ends: 494 [2022-07-22 17:39:22,825 INFO L226 Difference]: Without dead ends: 326 [2022-07-22 17:39:22,826 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 7 GetRequests, 2 SyntacticMatches, 0 SemanticMatches, 5 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 0 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=17, Invalid=25, Unknown=0, NotChecked=0, Total=42 [2022-07-22 17:39:22,828 INFO L413 NwaCegarLoop]: 100 mSDtfsCounter, 69 mSDsluCounter, 285 mSDsCounter, 0 mSdLazyCounter, 29 mSolverCounterSat, 4 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.0s Time, 0 mProtectedPredicate, 0 mProtectedAction, 69 SdHoareTripleChecker+Valid, 385 SdHoareTripleChecker+Invalid, 33 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 4 IncrementalHoareTripleChecker+Valid, 29 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.0s IncrementalHoareTripleChecker+Time [2022-07-22 17:39:22,828 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [69 Valid, 385 Invalid, 33 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [4 Valid, 29 Invalid, 0 Unknown, 0 Unchecked, 0.0s Time] [2022-07-22 17:39:22,829 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 326 states. [2022-07-22 17:39:22,854 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 326 to 326. [2022-07-22 17:39:22,855 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 326 states, 252 states have (on average 1.3412698412698412) internal successors, (338), 284 states have internal predecessors, (338), 44 states have call successors, (44), 32 states have call predecessors, (44), 29 states have return successors, (50), 25 states have call predecessors, (50), 44 states have call successors, (50) [2022-07-22 17:39:22,857 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 326 states to 326 states and 432 transitions. [2022-07-22 17:39:22,857 INFO L78 Accepts]: Start accepts. Automaton has 326 states and 432 transitions. Word has length 28 [2022-07-22 17:39:22,857 INFO L84 Accepts]: Finished accepts. word is rejected. [2022-07-22 17:39:22,858 INFO L495 AbstractCegarLoop]: Abstraction has 326 states and 432 transitions. [2022-07-22 17:39:22,858 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 5 states, 5 states have (on average 5.4) internal successors, (27), 4 states have internal predecessors, (27), 1 states have call successors, (1), 1 states have call predecessors, (1), 0 states have return successors, (0), 0 states have call predecessors, (0), 0 states have call successors, (0) [2022-07-22 17:39:22,858 INFO L276 IsEmpty]: Start isEmpty. Operand 326 states and 432 transitions. [2022-07-22 17:39:22,860 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 31 [2022-07-22 17:39:22,863 INFO L187 NwaCegarLoop]: Found error trace [2022-07-22 17:39:22,864 INFO L195 NwaCegarLoop]: trace histogram [1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-07-22 17:39:22,864 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable3 [2022-07-22 17:39:22,864 INFO L420 AbstractCegarLoop]: === Iteration 5 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2022-07-22 17:39:22,865 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2022-07-22 17:39:22,865 INFO L85 PathProgramCache]: Analyzing trace with hash 1450440452, now seen corresponding path program 1 times [2022-07-22 17:39:22,874 INFO L118 FreeRefinementEngine]: Executing refinement strategy CAMEL [2022-07-22 17:39:22,874 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [459069204] [2022-07-22 17:39:22,874 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-07-22 17:39:22,874 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2022-07-22 17:39:22,892 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-07-22 17:39:22,927 INFO L134 CoverageAnalysis]: Checked inductivity of 0 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2022-07-22 17:39:22,928 INFO L136 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2022-07-22 17:39:22,928 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [459069204] [2022-07-22 17:39:22,928 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [459069204] provided 1 perfect and 0 imperfect interpolant sequences [2022-07-22 17:39:22,928 INFO L184 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2022-07-22 17:39:22,929 INFO L197 FreeRefinementEngine]: Number of different interpolants: perfect sequences [2] imperfect sequences [] total 2 [2022-07-22 17:39:22,929 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [1763380923] [2022-07-22 17:39:22,929 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2022-07-22 17:39:22,929 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 3 states [2022-07-22 17:39:22,930 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2022-07-22 17:39:22,930 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 3 interpolants. [2022-07-22 17:39:22,930 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=3, Invalid=3, Unknown=0, NotChecked=0, Total=6 [2022-07-22 17:39:22,930 INFO L87 Difference]: Start difference. First operand 326 states and 432 transitions. Second operand has 3 states, 3 states have (on average 9.666666666666666) internal successors, (29), 2 states have internal predecessors, (29), 1 states have call successors, (1), 1 states have call predecessors, (1), 0 states have return successors, (0), 0 states have call predecessors, (0), 0 states have call successors, (0) [2022-07-22 17:39:22,968 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-07-22 17:39:22,968 INFO L93 Difference]: Finished difference Result 754 states and 1025 transitions. [2022-07-22 17:39:22,968 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 3 states. [2022-07-22 17:39:22,969 INFO L78 Accepts]: Start accepts. Automaton has has 3 states, 3 states have (on average 9.666666666666666) internal successors, (29), 2 states have internal predecessors, (29), 1 states have call successors, (1), 1 states have call predecessors, (1), 0 states have return successors, (0), 0 states have call predecessors, (0), 0 states have call successors, (0) Word has length 30 [2022-07-22 17:39:22,969 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2022-07-22 17:39:22,972 INFO L225 Difference]: With dead ends: 754 [2022-07-22 17:39:22,972 INFO L226 Difference]: Without dead ends: 435 [2022-07-22 17:39:22,974 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 3 GetRequests, 2 SyntacticMatches, 0 SemanticMatches, 1 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 0 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=3, Invalid=3, Unknown=0, NotChecked=0, Total=6 [2022-07-22 17:39:22,975 INFO L413 NwaCegarLoop]: 98 mSDtfsCounter, 57 mSDsluCounter, 60 mSDsCounter, 0 mSdLazyCounter, 11 mSolverCounterSat, 8 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.0s Time, 0 mProtectedPredicate, 0 mProtectedAction, 57 SdHoareTripleChecker+Valid, 158 SdHoareTripleChecker+Invalid, 19 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 8 IncrementalHoareTripleChecker+Valid, 11 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.0s IncrementalHoareTripleChecker+Time [2022-07-22 17:39:22,976 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [57 Valid, 158 Invalid, 19 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [8 Valid, 11 Invalid, 0 Unknown, 0 Unchecked, 0.0s Time] [2022-07-22 17:39:22,977 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 435 states. [2022-07-22 17:39:23,009 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 435 to 424. [2022-07-22 17:39:23,018 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 424 states, 334 states have (on average 1.2934131736526946) internal successors, (432), 361 states have internal predecessors, (432), 47 states have call successors, (47), 45 states have call predecessors, (47), 42 states have return successors, (69), 41 states have call predecessors, (69), 47 states have call successors, (69) [2022-07-22 17:39:23,024 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 424 states to 424 states and 548 transitions. [2022-07-22 17:39:23,026 INFO L78 Accepts]: Start accepts. Automaton has 424 states and 548 transitions. Word has length 30 [2022-07-22 17:39:23,026 INFO L84 Accepts]: Finished accepts. word is rejected. [2022-07-22 17:39:23,026 INFO L495 AbstractCegarLoop]: Abstraction has 424 states and 548 transitions. [2022-07-22 17:39:23,026 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 3 states, 3 states have (on average 9.666666666666666) internal successors, (29), 2 states have internal predecessors, (29), 1 states have call successors, (1), 1 states have call predecessors, (1), 0 states have return successors, (0), 0 states have call predecessors, (0), 0 states have call successors, (0) [2022-07-22 17:39:23,027 INFO L276 IsEmpty]: Start isEmpty. Operand 424 states and 548 transitions. [2022-07-22 17:39:23,031 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 33 [2022-07-22 17:39:23,035 INFO L187 NwaCegarLoop]: Found error trace [2022-07-22 17:39:23,035 INFO L195 NwaCegarLoop]: trace histogram [1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-07-22 17:39:23,035 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable4 [2022-07-22 17:39:23,036 INFO L420 AbstractCegarLoop]: === Iteration 6 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2022-07-22 17:39:23,036 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2022-07-22 17:39:23,038 INFO L85 PathProgramCache]: Analyzing trace with hash 1164230885, now seen corresponding path program 1 times [2022-07-22 17:39:23,038 INFO L118 FreeRefinementEngine]: Executing refinement strategy CAMEL [2022-07-22 17:39:23,038 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [2007784226] [2022-07-22 17:39:23,039 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-07-22 17:39:23,039 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2022-07-22 17:39:23,068 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-07-22 17:39:23,123 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 11 [2022-07-22 17:39:23,126 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-07-22 17:39:23,128 INFO L134 CoverageAnalysis]: Checked inductivity of 0 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2022-07-22 17:39:23,128 INFO L136 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2022-07-22 17:39:23,128 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [2007784226] [2022-07-22 17:39:23,128 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [2007784226] provided 1 perfect and 0 imperfect interpolant sequences [2022-07-22 17:39:23,129 INFO L184 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2022-07-22 17:39:23,129 INFO L197 FreeRefinementEngine]: Number of different interpolants: perfect sequences [6] imperfect sequences [] total 6 [2022-07-22 17:39:23,129 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [1409472208] [2022-07-22 17:39:23,129 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2022-07-22 17:39:23,130 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 6 states [2022-07-22 17:39:23,130 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2022-07-22 17:39:23,130 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 6 interpolants. [2022-07-22 17:39:23,130 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=9, Invalid=21, Unknown=0, NotChecked=0, Total=30 [2022-07-22 17:39:23,131 INFO L87 Difference]: Start difference. First operand 424 states and 548 transitions. Second operand has 6 states, 6 states have (on average 4.833333333333333) internal successors, (29), 5 states have internal predecessors, (29), 1 states have call successors, (2), 2 states have call predecessors, (2), 1 states have return successors, (1), 1 states have call predecessors, (1), 1 states have call successors, (1) [2022-07-22 17:39:23,356 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-07-22 17:39:23,357 INFO L93 Difference]: Finished difference Result 523 states and 679 transitions. [2022-07-22 17:39:23,357 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 11 states. [2022-07-22 17:39:23,357 INFO L78 Accepts]: Start accepts. Automaton has has 6 states, 6 states have (on average 4.833333333333333) internal successors, (29), 5 states have internal predecessors, (29), 1 states have call successors, (2), 2 states have call predecessors, (2), 1 states have return successors, (1), 1 states have call predecessors, (1), 1 states have call successors, (1) Word has length 32 [2022-07-22 17:39:23,358 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2022-07-22 17:39:23,363 INFO L225 Difference]: With dead ends: 523 [2022-07-22 17:39:23,363 INFO L226 Difference]: Without dead ends: 521 [2022-07-22 17:39:23,364 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 14 GetRequests, 4 SyntacticMatches, 0 SemanticMatches, 10 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 12 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=45, Invalid=87, Unknown=0, NotChecked=0, Total=132 [2022-07-22 17:39:23,369 INFO L413 NwaCegarLoop]: 109 mSDtfsCounter, 138 mSDsluCounter, 274 mSDsCounter, 0 mSdLazyCounter, 176 mSolverCounterSat, 34 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.1s Time, 0 mProtectedPredicate, 0 mProtectedAction, 142 SdHoareTripleChecker+Valid, 383 SdHoareTripleChecker+Invalid, 210 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 34 IncrementalHoareTripleChecker+Valid, 176 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.1s IncrementalHoareTripleChecker+Time [2022-07-22 17:39:23,372 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [142 Valid, 383 Invalid, 210 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [34 Valid, 176 Invalid, 0 Unknown, 0 Unchecked, 0.1s Time] [2022-07-22 17:39:23,374 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 521 states. [2022-07-22 17:39:23,409 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 521 to 492. [2022-07-22 17:39:23,410 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 492 states, 387 states have (on average 1.276485788113695) internal successors, (494), 425 states have internal predecessors, (494), 53 states have call successors, (53), 45 states have call predecessors, (53), 51 states have return successors, (88), 45 states have call predecessors, (88), 53 states have call successors, (88) [2022-07-22 17:39:23,414 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 492 states to 492 states and 635 transitions. [2022-07-22 17:39:23,414 INFO L78 Accepts]: Start accepts. Automaton has 492 states and 635 transitions. Word has length 32 [2022-07-22 17:39:23,415 INFO L84 Accepts]: Finished accepts. word is rejected. [2022-07-22 17:39:23,416 INFO L495 AbstractCegarLoop]: Abstraction has 492 states and 635 transitions. [2022-07-22 17:39:23,416 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 6 states, 6 states have (on average 4.833333333333333) internal successors, (29), 5 states have internal predecessors, (29), 1 states have call successors, (2), 2 states have call predecessors, (2), 1 states have return successors, (1), 1 states have call predecessors, (1), 1 states have call successors, (1) [2022-07-22 17:39:23,416 INFO L276 IsEmpty]: Start isEmpty. Operand 492 states and 635 transitions. [2022-07-22 17:39:23,419 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 48 [2022-07-22 17:39:23,420 INFO L187 NwaCegarLoop]: Found error trace [2022-07-22 17:39:23,420 INFO L195 NwaCegarLoop]: trace histogram [1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-07-22 17:39:23,420 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable5 [2022-07-22 17:39:23,422 INFO L420 AbstractCegarLoop]: === Iteration 7 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2022-07-22 17:39:23,423 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2022-07-22 17:39:23,423 INFO L85 PathProgramCache]: Analyzing trace with hash 108395810, now seen corresponding path program 1 times [2022-07-22 17:39:23,423 INFO L118 FreeRefinementEngine]: Executing refinement strategy CAMEL [2022-07-22 17:39:23,424 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [1936421433] [2022-07-22 17:39:23,424 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-07-22 17:39:23,424 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2022-07-22 17:39:23,454 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-07-22 17:39:23,490 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 11 [2022-07-22 17:39:23,492 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-07-22 17:39:23,497 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 24 [2022-07-22 17:39:23,508 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-07-22 17:39:23,541 INFO L134 CoverageAnalysis]: Checked inductivity of 0 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2022-07-22 17:39:23,542 INFO L136 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2022-07-22 17:39:23,542 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [1936421433] [2022-07-22 17:39:23,542 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [1936421433] provided 1 perfect and 0 imperfect interpolant sequences [2022-07-22 17:39:23,542 INFO L184 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2022-07-22 17:39:23,542 INFO L197 FreeRefinementEngine]: Number of different interpolants: perfect sequences [7] imperfect sequences [] total 7 [2022-07-22 17:39:23,542 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [1906297768] [2022-07-22 17:39:23,542 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2022-07-22 17:39:23,543 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 7 states [2022-07-22 17:39:23,543 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2022-07-22 17:39:23,544 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 7 interpolants. [2022-07-22 17:39:23,544 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=11, Invalid=31, Unknown=0, NotChecked=0, Total=42 [2022-07-22 17:39:23,544 INFO L87 Difference]: Start difference. First operand 492 states and 635 transitions. Second operand has 7 states, 7 states have (on average 6.0) internal successors, (42), 5 states have internal predecessors, (42), 1 states have call successors, (3), 3 states have call predecessors, (3), 2 states have return successors, (2), 2 states have call predecessors, (2), 1 states have call successors, (2) [2022-07-22 17:39:23,778 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-07-22 17:39:23,779 INFO L93 Difference]: Finished difference Result 1091 states and 1460 transitions. [2022-07-22 17:39:23,779 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 9 states. [2022-07-22 17:39:23,779 INFO L78 Accepts]: Start accepts. Automaton has has 7 states, 7 states have (on average 6.0) internal successors, (42), 5 states have internal predecessors, (42), 1 states have call successors, (3), 3 states have call predecessors, (3), 2 states have return successors, (2), 2 states have call predecessors, (2), 1 states have call successors, (2) Word has length 47 [2022-07-22 17:39:23,779 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2022-07-22 17:39:23,782 INFO L225 Difference]: With dead ends: 1091 [2022-07-22 17:39:23,782 INFO L226 Difference]: Without dead ends: 606 [2022-07-22 17:39:23,791 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 16 GetRequests, 6 SyntacticMatches, 0 SemanticMatches, 10 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 3 ImplicationChecksByTransitivity, 0.1s TimeCoverageRelationStatistics Valid=46, Invalid=86, Unknown=0, NotChecked=0, Total=132 [2022-07-22 17:39:23,795 INFO L413 NwaCegarLoop]: 94 mSDtfsCounter, 141 mSDsluCounter, 271 mSDsCounter, 0 mSdLazyCounter, 230 mSolverCounterSat, 45 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.1s Time, 0 mProtectedPredicate, 0 mProtectedAction, 141 SdHoareTripleChecker+Valid, 365 SdHoareTripleChecker+Invalid, 275 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 45 IncrementalHoareTripleChecker+Valid, 230 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.2s IncrementalHoareTripleChecker+Time [2022-07-22 17:39:23,795 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [141 Valid, 365 Invalid, 275 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [45 Valid, 230 Invalid, 0 Unknown, 0 Unchecked, 0.2s Time] [2022-07-22 17:39:23,797 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 606 states. [2022-07-22 17:39:23,829 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 606 to 544. [2022-07-22 17:39:23,831 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 544 states, 433 states have (on average 1.2609699769053118) internal successors, (546), 471 states have internal predecessors, (546), 53 states have call successors, (53), 45 states have call predecessors, (53), 57 states have return successors, (96), 49 states have call predecessors, (96), 53 states have call successors, (96) [2022-07-22 17:39:23,835 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 544 states to 544 states and 695 transitions. [2022-07-22 17:39:23,836 INFO L78 Accepts]: Start accepts. Automaton has 544 states and 695 transitions. Word has length 47 [2022-07-22 17:39:23,836 INFO L84 Accepts]: Finished accepts. word is rejected. [2022-07-22 17:39:23,837 INFO L495 AbstractCegarLoop]: Abstraction has 544 states and 695 transitions. [2022-07-22 17:39:23,837 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 7 states, 7 states have (on average 6.0) internal successors, (42), 5 states have internal predecessors, (42), 1 states have call successors, (3), 3 states have call predecessors, (3), 2 states have return successors, (2), 2 states have call predecessors, (2), 1 states have call successors, (2) [2022-07-22 17:39:23,837 INFO L276 IsEmpty]: Start isEmpty. Operand 544 states and 695 transitions. [2022-07-22 17:39:23,839 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 48 [2022-07-22 17:39:23,839 INFO L187 NwaCegarLoop]: Found error trace [2022-07-22 17:39:23,839 INFO L195 NwaCegarLoop]: trace histogram [1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-07-22 17:39:23,840 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable6 [2022-07-22 17:39:23,840 INFO L420 AbstractCegarLoop]: === Iteration 8 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2022-07-22 17:39:23,841 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2022-07-22 17:39:23,841 INFO L85 PathProgramCache]: Analyzing trace with hash -1885748896, now seen corresponding path program 1 times [2022-07-22 17:39:23,841 INFO L118 FreeRefinementEngine]: Executing refinement strategy CAMEL [2022-07-22 17:39:23,841 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [356366441] [2022-07-22 17:39:23,841 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-07-22 17:39:23,842 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2022-07-22 17:39:23,877 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-07-22 17:39:23,921 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 11 [2022-07-22 17:39:23,924 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-07-22 17:39:23,930 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 24 [2022-07-22 17:39:23,935 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-07-22 17:39:23,971 INFO L134 CoverageAnalysis]: Checked inductivity of 0 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2022-07-22 17:39:23,972 INFO L136 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2022-07-22 17:39:23,972 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [356366441] [2022-07-22 17:39:23,974 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [356366441] provided 1 perfect and 0 imperfect interpolant sequences [2022-07-22 17:39:23,975 INFO L184 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2022-07-22 17:39:23,975 INFO L197 FreeRefinementEngine]: Number of different interpolants: perfect sequences [8] imperfect sequences [] total 8 [2022-07-22 17:39:23,975 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [840939970] [2022-07-22 17:39:23,975 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2022-07-22 17:39:23,976 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 8 states [2022-07-22 17:39:23,976 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2022-07-22 17:39:23,977 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 8 interpolants. [2022-07-22 17:39:23,978 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=13, Invalid=43, Unknown=0, NotChecked=0, Total=56 [2022-07-22 17:39:23,979 INFO L87 Difference]: Start difference. First operand 544 states and 695 transitions. Second operand has 8 states, 8 states have (on average 5.25) internal successors, (42), 6 states have internal predecessors, (42), 1 states have call successors, (3), 3 states have call predecessors, (3), 2 states have return successors, (2), 2 states have call predecessors, (2), 1 states have call successors, (2) [2022-07-22 17:39:24,235 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-07-22 17:39:24,235 INFO L93 Difference]: Finished difference Result 1067 states and 1402 transitions. [2022-07-22 17:39:24,236 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 10 states. [2022-07-22 17:39:24,236 INFO L78 Accepts]: Start accepts. Automaton has has 8 states, 8 states have (on average 5.25) internal successors, (42), 6 states have internal predecessors, (42), 1 states have call successors, (3), 3 states have call predecessors, (3), 2 states have return successors, (2), 2 states have call predecessors, (2), 1 states have call successors, (2) Word has length 47 [2022-07-22 17:39:24,236 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2022-07-22 17:39:24,239 INFO L225 Difference]: With dead ends: 1067 [2022-07-22 17:39:24,239 INFO L226 Difference]: Without dead ends: 530 [2022-07-22 17:39:24,240 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 19 GetRequests, 8 SyntacticMatches, 0 SemanticMatches, 11 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 6 ImplicationChecksByTransitivity, 0.1s TimeCoverageRelationStatistics Valid=42, Invalid=114, Unknown=0, NotChecked=0, Total=156 [2022-07-22 17:39:24,241 INFO L413 NwaCegarLoop]: 80 mSDtfsCounter, 209 mSDsluCounter, 235 mSDsCounter, 0 mSdLazyCounter, 285 mSolverCounterSat, 66 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.2s Time, 0 mProtectedPredicate, 0 mProtectedAction, 209 SdHoareTripleChecker+Valid, 315 SdHoareTripleChecker+Invalid, 351 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 66 IncrementalHoareTripleChecker+Valid, 285 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.2s IncrementalHoareTripleChecker+Time [2022-07-22 17:39:24,241 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [209 Valid, 315 Invalid, 351 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [66 Valid, 285 Invalid, 0 Unknown, 0 Unchecked, 0.2s Time] [2022-07-22 17:39:24,242 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 530 states. [2022-07-22 17:39:24,264 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 530 to 428. [2022-07-22 17:39:24,265 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 428 states, 339 states have (on average 1.2595870206489677) internal successors, (427), 368 states have internal predecessors, (427), 44 states have call successors, (44), 38 states have call predecessors, (44), 44 states have return successors, (70), 38 states have call predecessors, (70), 44 states have call successors, (70) [2022-07-22 17:39:24,267 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 428 states to 428 states and 541 transitions. [2022-07-22 17:39:24,268 INFO L78 Accepts]: Start accepts. Automaton has 428 states and 541 transitions. Word has length 47 [2022-07-22 17:39:24,268 INFO L84 Accepts]: Finished accepts. word is rejected. [2022-07-22 17:39:24,268 INFO L495 AbstractCegarLoop]: Abstraction has 428 states and 541 transitions. [2022-07-22 17:39:24,268 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 8 states, 8 states have (on average 5.25) internal successors, (42), 6 states have internal predecessors, (42), 1 states have call successors, (3), 3 states have call predecessors, (3), 2 states have return successors, (2), 2 states have call predecessors, (2), 1 states have call successors, (2) [2022-07-22 17:39:24,268 INFO L276 IsEmpty]: Start isEmpty. Operand 428 states and 541 transitions. [2022-07-22 17:39:24,270 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 48 [2022-07-22 17:39:24,270 INFO L187 NwaCegarLoop]: Found error trace [2022-07-22 17:39:24,270 INFO L195 NwaCegarLoop]: trace histogram [1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-07-22 17:39:24,270 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable7 [2022-07-22 17:39:24,271 INFO L420 AbstractCegarLoop]: === Iteration 9 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2022-07-22 17:39:24,271 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2022-07-22 17:39:24,271 INFO L85 PathProgramCache]: Analyzing trace with hash 1591569950, now seen corresponding path program 1 times [2022-07-22 17:39:24,271 INFO L118 FreeRefinementEngine]: Executing refinement strategy CAMEL [2022-07-22 17:39:24,271 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [914571907] [2022-07-22 17:39:24,271 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-07-22 17:39:24,272 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2022-07-22 17:39:24,300 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-07-22 17:39:24,328 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 11 [2022-07-22 17:39:24,329 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-07-22 17:39:24,335 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 24 [2022-07-22 17:39:24,337 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-07-22 17:39:24,345 INFO L134 CoverageAnalysis]: Checked inductivity of 0 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2022-07-22 17:39:24,345 INFO L136 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2022-07-22 17:39:24,345 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [914571907] [2022-07-22 17:39:24,345 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [914571907] provided 1 perfect and 0 imperfect interpolant sequences [2022-07-22 17:39:24,345 INFO L184 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2022-07-22 17:39:24,346 INFO L197 FreeRefinementEngine]: Number of different interpolants: perfect sequences [7] imperfect sequences [] total 7 [2022-07-22 17:39:24,346 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [1795468311] [2022-07-22 17:39:24,346 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2022-07-22 17:39:24,346 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 7 states [2022-07-22 17:39:24,346 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2022-07-22 17:39:24,347 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 7 interpolants. [2022-07-22 17:39:24,347 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=11, Invalid=31, Unknown=0, NotChecked=0, Total=42 [2022-07-22 17:39:24,347 INFO L87 Difference]: Start difference. First operand 428 states and 541 transitions. Second operand has 7 states, 7 states have (on average 6.0) internal successors, (42), 5 states have internal predecessors, (42), 1 states have call successors, (3), 3 states have call predecessors, (3), 2 states have return successors, (2), 2 states have call predecessors, (2), 1 states have call successors, (2) [2022-07-22 17:39:24,684 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-07-22 17:39:24,684 INFO L93 Difference]: Finished difference Result 978 states and 1311 transitions. [2022-07-22 17:39:24,684 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 17 states. [2022-07-22 17:39:24,684 INFO L78 Accepts]: Start accepts. Automaton has has 7 states, 7 states have (on average 6.0) internal successors, (42), 5 states have internal predecessors, (42), 1 states have call successors, (3), 3 states have call predecessors, (3), 2 states have return successors, (2), 2 states have call predecessors, (2), 1 states have call successors, (2) Word has length 47 [2022-07-22 17:39:24,686 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2022-07-22 17:39:24,689 INFO L225 Difference]: With dead ends: 978 [2022-07-22 17:39:24,689 INFO L226 Difference]: Without dead ends: 665 [2022-07-22 17:39:24,691 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 24 GetRequests, 6 SyntacticMatches, 1 SemanticMatches, 17 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 60 ImplicationChecksByTransitivity, 0.1s TimeCoverageRelationStatistics Valid=106, Invalid=236, Unknown=0, NotChecked=0, Total=342 [2022-07-22 17:39:24,693 INFO L413 NwaCegarLoop]: 133 mSDtfsCounter, 221 mSDsluCounter, 351 mSDsCounter, 0 mSdLazyCounter, 306 mSolverCounterSat, 60 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.2s Time, 0 mProtectedPredicate, 0 mProtectedAction, 223 SdHoareTripleChecker+Valid, 484 SdHoareTripleChecker+Invalid, 366 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 60 IncrementalHoareTripleChecker+Valid, 306 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.2s IncrementalHoareTripleChecker+Time [2022-07-22 17:39:24,693 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [223 Valid, 484 Invalid, 366 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [60 Valid, 306 Invalid, 0 Unknown, 0 Unchecked, 0.2s Time] [2022-07-22 17:39:24,694 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 665 states. [2022-07-22 17:39:24,726 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 665 to 640. [2022-07-22 17:39:24,727 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 640 states, 506 states have (on average 1.2351778656126482) internal successors, (625), 543 states have internal predecessors, (625), 66 states have call successors, (66), 58 states have call predecessors, (66), 67 states have return successors, (131), 66 states have call predecessors, (131), 66 states have call successors, (131) [2022-07-22 17:39:24,730 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 640 states to 640 states and 822 transitions. [2022-07-22 17:39:24,731 INFO L78 Accepts]: Start accepts. Automaton has 640 states and 822 transitions. Word has length 47 [2022-07-22 17:39:24,731 INFO L84 Accepts]: Finished accepts. word is rejected. [2022-07-22 17:39:24,731 INFO L495 AbstractCegarLoop]: Abstraction has 640 states and 822 transitions. [2022-07-22 17:39:24,731 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 7 states, 7 states have (on average 6.0) internal successors, (42), 5 states have internal predecessors, (42), 1 states have call successors, (3), 3 states have call predecessors, (3), 2 states have return successors, (2), 2 states have call predecessors, (2), 1 states have call successors, (2) [2022-07-22 17:39:24,731 INFO L276 IsEmpty]: Start isEmpty. Operand 640 states and 822 transitions. [2022-07-22 17:39:24,734 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 83 [2022-07-22 17:39:24,734 INFO L187 NwaCegarLoop]: Found error trace [2022-07-22 17:39:24,734 INFO L195 NwaCegarLoop]: trace histogram [2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-07-22 17:39:24,734 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable8 [2022-07-22 17:39:24,734 INFO L420 AbstractCegarLoop]: === Iteration 10 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2022-07-22 17:39:24,735 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2022-07-22 17:39:24,735 INFO L85 PathProgramCache]: Analyzing trace with hash -351052253, now seen corresponding path program 1 times [2022-07-22 17:39:24,735 INFO L118 FreeRefinementEngine]: Executing refinement strategy CAMEL [2022-07-22 17:39:24,735 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [1179621000] [2022-07-22 17:39:24,735 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-07-22 17:39:24,735 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2022-07-22 17:39:24,770 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-07-22 17:39:24,816 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 11 [2022-07-22 17:39:24,817 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-07-22 17:39:24,824 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 20 [2022-07-22 17:39:24,828 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-07-22 17:39:24,858 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 3 [2022-07-22 17:39:24,860 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-07-22 17:39:24,871 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 67 [2022-07-22 17:39:24,872 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-07-22 17:39:24,874 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 2 [2022-07-22 17:39:24,874 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-07-22 17:39:24,875 INFO L134 CoverageAnalysis]: Checked inductivity of 21 backedges. 12 proven. 7 refuted. 0 times theorem prover too weak. 2 trivial. 0 not checked. [2022-07-22 17:39:24,875 INFO L136 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2022-07-22 17:39:24,875 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [1179621000] [2022-07-22 17:39:24,876 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [1179621000] provided 0 perfect and 1 imperfect interpolant sequences [2022-07-22 17:39:24,876 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleZ3 [1180709554] [2022-07-22 17:39:24,876 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-07-22 17:39:24,876 INFO L173 SolverBuilder]: Constructing external solver with command: z3 -smt2 -in SMTLIB2_COMPLIANT=true [2022-07-22 17:39:24,876 INFO L189 MonitoredProcess]: No working directory specified, using /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 [2022-07-22 17:39:24,879 INFO L229 MonitoredProcess]: Starting monitored process 2 with /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 -smt2 -in SMTLIB2_COMPLIANT=true (exit command is (exit), workingDir is null) [2022-07-22 17:39:24,908 INFO L327 MonitoredProcess]: [MP /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 -smt2 -in SMTLIB2_COMPLIANT=true (2)] Waiting until timeout for monitored process [2022-07-22 17:39:24,982 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-07-22 17:39:24,986 INFO L263 TraceCheckSpWp]: Trace formula consists of 450 conjuncts, 8 conjunts are in the unsatisfiable core [2022-07-22 17:39:24,993 INFO L286 TraceCheckSpWp]: Computing forward predicates... [2022-07-22 17:39:25,154 INFO L134 CoverageAnalysis]: Checked inductivity of 21 backedges. 15 proven. 6 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2022-07-22 17:39:25,154 INFO L328 TraceCheckSpWp]: Computing backward predicates... [2022-07-22 17:39:25,275 INFO L134 CoverageAnalysis]: Checked inductivity of 21 backedges. 13 proven. 6 refuted. 0 times theorem prover too weak. 2 trivial. 0 not checked. [2022-07-22 17:39:25,275 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleZ3 [1180709554] provided 0 perfect and 2 imperfect interpolant sequences [2022-07-22 17:39:25,276 INFO L184 FreeRefinementEngine]: Found 0 perfect and 3 imperfect interpolant sequences. [2022-07-22 17:39:25,276 INFO L197 FreeRefinementEngine]: Number of different interpolants: perfect sequences [] imperfect sequences [9, 6, 6] total 9 [2022-07-22 17:39:25,276 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [1967239524] [2022-07-22 17:39:25,276 INFO L85 oduleStraightlineAll]: Using 3 imperfect interpolants to construct interpolant automaton [2022-07-22 17:39:25,277 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 9 states [2022-07-22 17:39:25,277 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2022-07-22 17:39:25,277 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 9 interpolants. [2022-07-22 17:39:25,277 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=18, Invalid=54, Unknown=0, NotChecked=0, Total=72 [2022-07-22 17:39:25,278 INFO L87 Difference]: Start difference. First operand 640 states and 822 transitions. Second operand has 9 states, 9 states have (on average 8.555555555555555) internal successors, (77), 6 states have internal predecessors, (77), 3 states have call successors, (12), 6 states have call predecessors, (12), 3 states have return successors, (7), 3 states have call predecessors, (7), 2 states have call successors, (7) [2022-07-22 17:39:25,806 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-07-22 17:39:25,806 INFO L93 Difference]: Finished difference Result 1525 states and 2064 transitions. [2022-07-22 17:39:25,808 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 27 states. [2022-07-22 17:39:25,808 INFO L78 Accepts]: Start accepts. Automaton has has 9 states, 9 states have (on average 8.555555555555555) internal successors, (77), 6 states have internal predecessors, (77), 3 states have call successors, (12), 6 states have call predecessors, (12), 3 states have return successors, (7), 3 states have call predecessors, (7), 2 states have call successors, (7) Word has length 82 [2022-07-22 17:39:25,809 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2022-07-22 17:39:25,814 INFO L225 Difference]: With dead ends: 1525 [2022-07-22 17:39:25,814 INFO L226 Difference]: Without dead ends: 1000 [2022-07-22 17:39:25,816 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 206 GetRequests, 175 SyntacticMatches, 4 SemanticMatches, 27 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 200 ImplicationChecksByTransitivity, 0.2s TimeCoverageRelationStatistics Valid=227, Invalid=585, Unknown=0, NotChecked=0, Total=812 [2022-07-22 17:39:25,817 INFO L413 NwaCegarLoop]: 139 mSDtfsCounter, 346 mSDsluCounter, 443 mSDsCounter, 0 mSdLazyCounter, 467 mSolverCounterSat, 114 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.3s Time, 0 mProtectedPredicate, 0 mProtectedAction, 352 SdHoareTripleChecker+Valid, 582 SdHoareTripleChecker+Invalid, 581 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 114 IncrementalHoareTripleChecker+Valid, 467 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.3s IncrementalHoareTripleChecker+Time [2022-07-22 17:39:25,817 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [352 Valid, 582 Invalid, 581 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [114 Valid, 467 Invalid, 0 Unknown, 0 Unchecked, 0.3s Time] [2022-07-22 17:39:25,818 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 1000 states. [2022-07-22 17:39:25,860 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 1000 to 869. [2022-07-22 17:39:25,862 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 869 states, 679 states have (on average 1.2415316642120766) internal successors, (843), 732 states have internal predecessors, (843), 95 states have call successors, (95), 83 states have call predecessors, (95), 94 states have return successors, (198), 87 states have call predecessors, (198), 95 states have call successors, (198) [2022-07-22 17:39:25,866 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 869 states to 869 states and 1136 transitions. [2022-07-22 17:39:25,867 INFO L78 Accepts]: Start accepts. Automaton has 869 states and 1136 transitions. Word has length 82 [2022-07-22 17:39:25,867 INFO L84 Accepts]: Finished accepts. word is rejected. [2022-07-22 17:39:25,867 INFO L495 AbstractCegarLoop]: Abstraction has 869 states and 1136 transitions. [2022-07-22 17:39:25,867 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 9 states, 9 states have (on average 8.555555555555555) internal successors, (77), 6 states have internal predecessors, (77), 3 states have call successors, (12), 6 states have call predecessors, (12), 3 states have return successors, (7), 3 states have call predecessors, (7), 2 states have call successors, (7) [2022-07-22 17:39:25,867 INFO L276 IsEmpty]: Start isEmpty. Operand 869 states and 1136 transitions. [2022-07-22 17:39:25,870 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 118 [2022-07-22 17:39:25,870 INFO L187 NwaCegarLoop]: Found error trace [2022-07-22 17:39:25,871 INFO L195 NwaCegarLoop]: trace histogram [3, 3, 3, 3, 3, 3, 3, 3, 3, 3, 3, 3, 3, 3, 3, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-07-22 17:39:25,899 INFO L540 MonitoredProcess]: [MP /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 -smt2 -in SMTLIB2_COMPLIANT=true (2)] Forceful destruction successful, exit code 0 [2022-07-22 17:39:26,095 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: 2 /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 -smt2 -in SMTLIB2_COMPLIANT=true,SelfDestructingSolverStorable9 [2022-07-22 17:39:26,096 INFO L420 AbstractCegarLoop]: === Iteration 11 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2022-07-22 17:39:26,096 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2022-07-22 17:39:26,096 INFO L85 PathProgramCache]: Analyzing trace with hash 349407230, now seen corresponding path program 2 times [2022-07-22 17:39:26,096 INFO L118 FreeRefinementEngine]: Executing refinement strategy CAMEL [2022-07-22 17:39:26,096 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [1328715928] [2022-07-22 17:39:26,097 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-07-22 17:39:26,097 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2022-07-22 17:39:26,117 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-07-22 17:39:26,144 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 11 [2022-07-22 17:39:26,146 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-07-22 17:39:26,152 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 20 [2022-07-22 17:39:26,155 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-07-22 17:39:26,171 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 3 [2022-07-22 17:39:26,174 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-07-22 17:39:26,186 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 56 [2022-07-22 17:39:26,191 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-07-22 17:39:26,244 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 10 [2022-07-22 17:39:26,246 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-07-22 17:39:26,247 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 2 [2022-07-22 17:39:26,248 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-07-22 17:39:26,248 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 102 [2022-07-22 17:39:26,249 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-07-22 17:39:26,250 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 2 [2022-07-22 17:39:26,250 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-07-22 17:39:26,251 INFO L134 CoverageAnalysis]: Checked inductivity of 77 backedges. 54 proven. 11 refuted. 0 times theorem prover too weak. 12 trivial. 0 not checked. [2022-07-22 17:39:26,251 INFO L136 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2022-07-22 17:39:26,251 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [1328715928] [2022-07-22 17:39:26,251 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [1328715928] provided 0 perfect and 1 imperfect interpolant sequences [2022-07-22 17:39:26,252 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleZ3 [915359469] [2022-07-22 17:39:26,252 INFO L93 rtionOrderModulation]: Changing assertion order to OUTSIDE_LOOP_FIRST1 [2022-07-22 17:39:26,252 INFO L173 SolverBuilder]: Constructing external solver with command: z3 -smt2 -in SMTLIB2_COMPLIANT=true [2022-07-22 17:39:26,252 INFO L189 MonitoredProcess]: No working directory specified, using /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 [2022-07-22 17:39:26,253 INFO L229 MonitoredProcess]: Starting monitored process 3 with /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 -smt2 -in SMTLIB2_COMPLIANT=true (exit command is (exit), workingDir is null) [2022-07-22 17:39:26,255 INFO L327 MonitoredProcess]: [MP /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 -smt2 -in SMTLIB2_COMPLIANT=true (3)] Waiting until timeout for monitored process [2022-07-22 17:39:26,360 INFO L228 tOrderPrioritization]: Assert order OUTSIDE_LOOP_FIRST1 issued 2 check-sat command(s) [2022-07-22 17:39:26,360 INFO L229 tOrderPrioritization]: Conjunction of SSA is unsat [2022-07-22 17:39:26,362 INFO L263 TraceCheckSpWp]: Trace formula consists of 540 conjuncts, 10 conjunts are in the unsatisfiable core [2022-07-22 17:39:26,366 INFO L286 TraceCheckSpWp]: Computing forward predicates... [2022-07-22 17:39:26,490 INFO L134 CoverageAnalysis]: Checked inductivity of 77 backedges. 64 proven. 0 refuted. 0 times theorem prover too weak. 13 trivial. 0 not checked. [2022-07-22 17:39:26,491 INFO L324 TraceCheckSpWp]: Omiting computation of backward sequence because forward sequence was already perfect [2022-07-22 17:39:26,491 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleZ3 [915359469] provided 1 perfect and 0 imperfect interpolant sequences [2022-07-22 17:39:26,491 INFO L184 FreeRefinementEngine]: Found 1 perfect and 1 imperfect interpolant sequences. [2022-07-22 17:39:26,491 INFO L197 FreeRefinementEngine]: Number of different interpolants: perfect sequences [6] imperfect sequences [10] total 14 [2022-07-22 17:39:26,492 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [283663262] [2022-07-22 17:39:26,492 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2022-07-22 17:39:26,492 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 6 states [2022-07-22 17:39:26,492 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2022-07-22 17:39:26,493 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 6 interpolants. [2022-07-22 17:39:26,493 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=32, Invalid=150, Unknown=0, NotChecked=0, Total=182 [2022-07-22 17:39:26,493 INFO L87 Difference]: Start difference. First operand 869 states and 1136 transitions. Second operand has 6 states, 6 states have (on average 15.166666666666666) internal successors, (91), 6 states have internal predecessors, (91), 3 states have call successors, (8), 4 states have call predecessors, (8), 3 states have return successors, (8), 3 states have call predecessors, (8), 3 states have call successors, (8) [2022-07-22 17:39:26,776 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-07-22 17:39:26,776 INFO L93 Difference]: Finished difference Result 2382 states and 3234 transitions. [2022-07-22 17:39:26,777 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 10 states. [2022-07-22 17:39:26,777 INFO L78 Accepts]: Start accepts. Automaton has has 6 states, 6 states have (on average 15.166666666666666) internal successors, (91), 6 states have internal predecessors, (91), 3 states have call successors, (8), 4 states have call predecessors, (8), 3 states have return successors, (8), 3 states have call predecessors, (8), 3 states have call successors, (8) Word has length 117 [2022-07-22 17:39:26,777 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2022-07-22 17:39:26,785 INFO L225 Difference]: With dead ends: 2382 [2022-07-22 17:39:26,786 INFO L226 Difference]: Without dead ends: 1626 [2022-07-22 17:39:26,790 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 149 GetRequests, 130 SyntacticMatches, 2 SemanticMatches, 17 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 45 ImplicationChecksByTransitivity, 0.2s TimeCoverageRelationStatistics Valid=63, Invalid=279, Unknown=0, NotChecked=0, Total=342 [2022-07-22 17:39:26,791 INFO L413 NwaCegarLoop]: 161 mSDtfsCounter, 262 mSDsluCounter, 390 mSDsCounter, 0 mSdLazyCounter, 132 mSolverCounterSat, 40 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.1s Time, 0 mProtectedPredicate, 0 mProtectedAction, 262 SdHoareTripleChecker+Valid, 551 SdHoareTripleChecker+Invalid, 172 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 40 IncrementalHoareTripleChecker+Valid, 132 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.1s IncrementalHoareTripleChecker+Time [2022-07-22 17:39:26,791 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [262 Valid, 551 Invalid, 172 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [40 Valid, 132 Invalid, 0 Unknown, 0 Unchecked, 0.1s Time] [2022-07-22 17:39:26,793 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 1626 states. [2022-07-22 17:39:26,902 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 1626 to 1505. [2022-07-22 17:39:26,904 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 1505 states, 1178 states have (on average 1.2410865874363328) internal successors, (1462), 1258 states have internal predecessors, (1462), 166 states have call successors, (166), 148 states have call predecessors, (166), 160 states have return successors, (304), 150 states have call predecessors, (304), 166 states have call successors, (304) [2022-07-22 17:39:26,912 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 1505 states to 1505 states and 1932 transitions. [2022-07-22 17:39:26,912 INFO L78 Accepts]: Start accepts. Automaton has 1505 states and 1932 transitions. Word has length 117 [2022-07-22 17:39:26,913 INFO L84 Accepts]: Finished accepts. word is rejected. [2022-07-22 17:39:26,913 INFO L495 AbstractCegarLoop]: Abstraction has 1505 states and 1932 transitions. [2022-07-22 17:39:26,913 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 6 states, 6 states have (on average 15.166666666666666) internal successors, (91), 6 states have internal predecessors, (91), 3 states have call successors, (8), 4 states have call predecessors, (8), 3 states have return successors, (8), 3 states have call predecessors, (8), 3 states have call successors, (8) [2022-07-22 17:39:26,913 INFO L276 IsEmpty]: Start isEmpty. Operand 1505 states and 1932 transitions. [2022-07-22 17:39:26,921 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 118 [2022-07-22 17:39:26,921 INFO L187 NwaCegarLoop]: Found error trace [2022-07-22 17:39:26,922 INFO L195 NwaCegarLoop]: trace histogram [3, 3, 3, 3, 3, 3, 3, 3, 3, 3, 3, 3, 3, 3, 3, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-07-22 17:39:26,949 INFO L552 MonitoredProcess]: [MP /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 -smt2 -in SMTLIB2_COMPLIANT=true (3)] Ended with exit code 0 [2022-07-22 17:39:27,135 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: 3 /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 -smt2 -in SMTLIB2_COMPLIANT=true,SelfDestructingSolverStorable10 [2022-07-22 17:39:27,136 INFO L420 AbstractCegarLoop]: === Iteration 12 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2022-07-22 17:39:27,136 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2022-07-22 17:39:27,136 INFO L85 PathProgramCache]: Analyzing trace with hash 1225426236, now seen corresponding path program 1 times [2022-07-22 17:39:27,136 INFO L118 FreeRefinementEngine]: Executing refinement strategy CAMEL [2022-07-22 17:39:27,136 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [781995926] [2022-07-22 17:39:27,136 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-07-22 17:39:27,136 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2022-07-22 17:39:27,151 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-07-22 17:39:27,167 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 11 [2022-07-22 17:39:27,168 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-07-22 17:39:27,173 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 20 [2022-07-22 17:39:27,175 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-07-22 17:39:27,181 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 3 [2022-07-22 17:39:27,183 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-07-22 17:39:27,186 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 56 [2022-07-22 17:39:27,191 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-07-22 17:39:27,210 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 10 [2022-07-22 17:39:27,211 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-07-22 17:39:27,213 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 2 [2022-07-22 17:39:27,214 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-07-22 17:39:27,215 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 102 [2022-07-22 17:39:27,215 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-07-22 17:39:27,216 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 2 [2022-07-22 17:39:27,216 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-07-22 17:39:27,218 INFO L134 CoverageAnalysis]: Checked inductivity of 77 backedges. 44 proven. 0 refuted. 0 times theorem prover too weak. 33 trivial. 0 not checked. [2022-07-22 17:39:27,218 INFO L136 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2022-07-22 17:39:27,218 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [781995926] [2022-07-22 17:39:27,218 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [781995926] provided 1 perfect and 0 imperfect interpolant sequences [2022-07-22 17:39:27,218 INFO L184 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2022-07-22 17:39:27,218 INFO L197 FreeRefinementEngine]: Number of different interpolants: perfect sequences [8] imperfect sequences [] total 8 [2022-07-22 17:39:27,218 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [921544237] [2022-07-22 17:39:27,219 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2022-07-22 17:39:27,219 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 8 states [2022-07-22 17:39:27,219 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2022-07-22 17:39:27,219 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 8 interpolants. [2022-07-22 17:39:27,220 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=15, Invalid=41, Unknown=0, NotChecked=0, Total=56 [2022-07-22 17:39:27,220 INFO L87 Difference]: Start difference. First operand 1505 states and 1932 transitions. Second operand has 8 states, 8 states have (on average 10.25) internal successors, (82), 5 states have internal predecessors, (82), 2 states have call successors, (6), 5 states have call predecessors, (6), 2 states have return successors, (6), 2 states have call predecessors, (6), 2 states have call successors, (6) [2022-07-22 17:39:27,412 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-07-22 17:39:27,412 INFO L93 Difference]: Finished difference Result 2115 states and 2678 transitions. [2022-07-22 17:39:27,413 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 9 states. [2022-07-22 17:39:27,413 INFO L78 Accepts]: Start accepts. Automaton has has 8 states, 8 states have (on average 10.25) internal successors, (82), 5 states have internal predecessors, (82), 2 states have call successors, (6), 5 states have call predecessors, (6), 2 states have return successors, (6), 2 states have call predecessors, (6), 2 states have call successors, (6) Word has length 117 [2022-07-22 17:39:27,413 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2022-07-22 17:39:27,414 INFO L225 Difference]: With dead ends: 2115 [2022-07-22 17:39:27,414 INFO L226 Difference]: Without dead ends: 0 [2022-07-22 17:39:27,419 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 27 GetRequests, 17 SyntacticMatches, 0 SemanticMatches, 10 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 14 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=39, Invalid=93, Unknown=0, NotChecked=0, Total=132 [2022-07-22 17:39:27,420 INFO L413 NwaCegarLoop]: 87 mSDtfsCounter, 155 mSDsluCounter, 224 mSDsCounter, 0 mSdLazyCounter, 210 mSolverCounterSat, 41 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.1s Time, 0 mProtectedPredicate, 0 mProtectedAction, 157 SdHoareTripleChecker+Valid, 311 SdHoareTripleChecker+Invalid, 251 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 41 IncrementalHoareTripleChecker+Valid, 210 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.1s IncrementalHoareTripleChecker+Time [2022-07-22 17:39:27,421 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [157 Valid, 311 Invalid, 251 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [41 Valid, 210 Invalid, 0 Unknown, 0 Unchecked, 0.1s Time] [2022-07-22 17:39:27,421 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 0 states. [2022-07-22 17:39:27,421 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 0 to 0. [2022-07-22 17:39:27,421 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 0 states, 0 states have (on average 0.0) internal successors, (0), 0 states have internal predecessors, (0), 0 states have call successors, (0), 0 states have call predecessors, (0), 0 states have return successors, (0), 0 states have call predecessors, (0), 0 states have call successors, (0) [2022-07-22 17:39:27,422 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 0 states to 0 states and 0 transitions. [2022-07-22 17:39:27,422 INFO L78 Accepts]: Start accepts. Automaton has 0 states and 0 transitions. Word has length 117 [2022-07-22 17:39:27,422 INFO L84 Accepts]: Finished accepts. word is rejected. [2022-07-22 17:39:27,422 INFO L495 AbstractCegarLoop]: Abstraction has 0 states and 0 transitions. [2022-07-22 17:39:27,422 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 8 states, 8 states have (on average 10.25) internal successors, (82), 5 states have internal predecessors, (82), 2 states have call successors, (6), 5 states have call predecessors, (6), 2 states have return successors, (6), 2 states have call predecessors, (6), 2 states have call successors, (6) [2022-07-22 17:39:27,423 INFO L276 IsEmpty]: Start isEmpty. Operand 0 states and 0 transitions. [2022-07-22 17:39:27,423 INFO L282 IsEmpty]: Finished isEmpty. No accepting run. [2022-07-22 17:39:27,425 INFO L805 garLoopResultBuilder]: Registering result SAFE for location timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION (0 of 1 remaining) [2022-07-22 17:39:27,425 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable11 [2022-07-22 17:39:27,427 INFO L343 DoubleDeckerVisitor]: Before removal of dead ends 0 states and 0 transitions. [2022-07-22 17:39:31,185 INFO L895 garLoopResultBuilder]: At program point deactivatePumpENTRY(lines 714 721) the Hoare annotation is: (or (= ~pumpRunning~0 |old(~pumpRunning~0)|) (not (<= 1 ~waterLevel~0)) (= 0 ~systemActive~0)) [2022-07-22 17:39:31,185 INFO L899 garLoopResultBuilder]: For program point deactivatePumpEXIT(lines 714 721) no Hoare annotation was computed. [2022-07-22 17:39:31,185 INFO L899 garLoopResultBuilder]: For program point deactivatePumpFINAL(lines 714 721) no Hoare annotation was computed. [2022-07-22 17:39:31,185 INFO L899 garLoopResultBuilder]: For program point processEnvironment__wrappee__baseEXIT(lines 629 635) no Hoare annotation was computed. [2022-07-22 17:39:31,185 INFO L902 garLoopResultBuilder]: At program point processEnvironment__wrappee__baseFINAL(lines 629 635) the Hoare annotation is: true [2022-07-22 17:39:31,186 INFO L902 garLoopResultBuilder]: At program point changeMethaneLevelENTRY(lines 935 946) the Hoare annotation is: true [2022-07-22 17:39:31,186 INFO L899 garLoopResultBuilder]: For program point L939-1(lines 935 946) no Hoare annotation was computed. [2022-07-22 17:39:31,186 INFO L899 garLoopResultBuilder]: For program point changeMethaneLevelEXIT(lines 935 946) no Hoare annotation was computed. [2022-07-22 17:39:31,186 INFO L899 garLoopResultBuilder]: For program point L609-1(lines 608 627) no Hoare annotation was computed. [2022-07-22 17:39:31,186 INFO L899 garLoopResultBuilder]: For program point L671(lines 671 679) no Hoare annotation was computed. [2022-07-22 17:39:31,186 INFO L899 garLoopResultBuilder]: For program point L667(lines 667 684) no Hoare annotation was computed. [2022-07-22 17:39:31,186 INFO L899 garLoopResultBuilder]: For program point L915(lines 915 919) no Hoare annotation was computed. [2022-07-22 17:39:31,187 INFO L895 garLoopResultBuilder]: At program point L915-2(lines 911 922) the Hoare annotation is: (and (or (not (= |old(~pumpRunning~0)| 0)) (not (<= 1 |old(~waterLevel~0)|))) (or (and (= ~pumpRunning~0 |old(~pumpRunning~0)|) (<= 1 ~waterLevel~0)) (= 0 ~systemActive~0) (not (<= 2 |old(~waterLevel~0)|)))) [2022-07-22 17:39:31,187 INFO L895 garLoopResultBuilder]: At program point L589(lines 584 591) the Hoare annotation is: (and (or (not (= |old(~pumpRunning~0)| 0)) (not (<= 1 |old(~waterLevel~0)|))) (or (= 0 ~systemActive~0) (not (<= 2 |old(~waterLevel~0)|)))) [2022-07-22 17:39:31,187 INFO L895 garLoopResultBuilder]: At program point L812(lines 797 815) the Hoare annotation is: (and (or (not (= |old(~pumpRunning~0)| 0)) (not (<= 1 |old(~waterLevel~0)|))) (or (and (= ~pumpRunning~0 |old(~pumpRunning~0)|) (= |timeShift_isLowWaterSensorDry_#res#1| 0) (<= 1 |timeShift_isLowWaterLevel_#res#1|) (= |timeShift_isLowWaterLevel_~tmp~9#1| 0) (<= 1 ~waterLevel~0) (<= 1 |timeShift_isLowWaterLevel_~tmp___0~2#1|)) (= 0 ~systemActive~0) (not (<= 2 |old(~waterLevel~0)|)))) [2022-07-22 17:39:31,187 INFO L899 garLoopResultBuilder]: For program point timeShiftFINAL(lines 605 628) no Hoare annotation was computed. [2022-07-22 17:39:31,187 INFO L895 garLoopResultBuilder]: At program point L738(lines 733 741) the Hoare annotation is: (and (or (not (= |old(~pumpRunning~0)| 0)) (not (<= 1 |old(~waterLevel~0)|))) (or (= 0 ~systemActive~0) (not (<= 2 |old(~waterLevel~0)|)))) [2022-07-22 17:39:31,187 INFO L895 garLoopResultBuilder]: At program point L1007(lines 1002 1010) the Hoare annotation is: (and (or (not (= |old(~pumpRunning~0)| 0)) (not (<= 1 |old(~waterLevel~0)|))) (or (and (= ~pumpRunning~0 |old(~pumpRunning~0)|) (= |timeShift_isLowWaterSensorDry_#res#1| 0) (<= 1 ~waterLevel~0)) (= 0 ~systemActive~0) (not (<= 2 |old(~waterLevel~0)|)))) [2022-07-22 17:39:31,187 INFO L895 garLoopResultBuilder]: At program point L677(line 677) the Hoare annotation is: (and (or (not (= |old(~pumpRunning~0)| 0)) (not (<= 1 |old(~waterLevel~0)|))) (or (= 0 ~systemActive~0) (not (<= 2 |old(~waterLevel~0)|)))) [2022-07-22 17:39:31,188 INFO L895 garLoopResultBuilder]: At program point L673(line 673) the Hoare annotation is: (and (or (= 0 ~systemActive~0) (and (= ~pumpRunning~0 |old(~pumpRunning~0)|) (= |timeShift_isLowWaterSensorDry_#res#1| 0) (<= 1 |timeShift_isLowWaterLevel_#res#1|) (<= 1 |timeShift_processEnvironment_~tmp~6#1|) (= |timeShift_isLowWaterLevel_~tmp~9#1| 0) (<= 1 ~waterLevel~0) (<= 1 |timeShift_isLowWaterLevel_~tmp___0~2#1|)) (not (<= 2 |old(~waterLevel~0)|))) (or (not (= |old(~pumpRunning~0)| 0)) (not (<= 1 |old(~waterLevel~0)|)))) [2022-07-22 17:39:31,188 INFO L899 garLoopResultBuilder]: For program point L570(lines 570 576) no Hoare annotation was computed. [2022-07-22 17:39:31,188 INFO L899 garLoopResultBuilder]: For program point L566(lines 566 579) no Hoare annotation was computed. [2022-07-22 17:39:31,188 INFO L895 garLoopResultBuilder]: At program point L566-1(lines 558 582) the Hoare annotation is: (let ((.cse7 (<= 2 ~waterLevel~0)) (.cse2 (= |old(~waterLevel~0)| ~waterLevel~0)) (.cse8 (<= 2 |timeShift_getWaterLevel_#res#1|)) (.cse9 (<= 2 |timeShift___utac_acc__Specification4_spec__1_~tmp~4#1|)) (.cse10 (= 0 ~systemActive~0))) (let ((.cse1 (= ~pumpRunning~0 0)) (.cse4 (<= 1 |timeShift_getWaterLevel_#res#1|)) (.cse5 (<= 1 |timeShift___utac_acc__Specification4_spec__1_~tmp~4#1|)) (.cse0 (not (= |old(~pumpRunning~0)| 0))) (.cse3 (and .cse7 .cse2 .cse8 .cse9 (not .cse10))) (.cse6 (not (<= 2 |old(~waterLevel~0)|)))) (and (or .cse0 (and .cse1 .cse2) .cse3 (not (<= 1 |old(~waterLevel~0)|))) (or .cse0 (not (= |old(~waterLevel~0)| 1)) (and (= |timeShift___utac_acc__Specification4_spec__1_~tmp~4#1| 1) (= |timeShift_getWaterLevel_#res#1| 1))) (or .cse0 (and .cse4 .cse5) .cse6) (or (and .cse1 (<= 1 |timeShift_isLowWaterLevel_#res#1|) (<= 1 |timeShift_processEnvironment_~tmp~6#1|) (<= 1 ~waterLevel~0) .cse4 .cse5 (<= 1 |timeShift_isLowWaterLevel_~tmp___0~2#1|)) (and .cse7 .cse8 .cse9) .cse10 .cse6) (or .cse0 .cse3 .cse10 .cse6)))) [2022-07-22 17:39:31,188 INFO L895 garLoopResultBuilder]: At program point L682(line 682) the Hoare annotation is: (let ((.cse3 (= 0 ~systemActive~0))) (let ((.cse0 (= ~pumpRunning~0 0)) (.cse2 (not (= |old(~pumpRunning~0)| 0))) (.cse1 (not .cse3)) (.cse4 (not (<= 2 |old(~waterLevel~0)|)))) (and (or (and .cse0 (= ~waterLevel~0 1) .cse1) .cse2 (not (= |old(~waterLevel~0)| 1))) (or (and (= ~pumpRunning~0 |old(~pumpRunning~0)|) .cse0) .cse3 .cse4) (or .cse2 (and (= |old(~waterLevel~0)| ~waterLevel~0) .cse1) .cse4)))) [2022-07-22 17:39:31,189 INFO L895 garLoopResultBuilder]: At program point L682-1(lines 663 687) the Hoare annotation is: (let ((.cse0 (= ~pumpRunning~0 0)) (.cse3 (<= 2 ~waterLevel~0)) (.cse4 (= 0 ~systemActive~0))) (and (let ((.cse1 (= |old(~waterLevel~0)| ~waterLevel~0)) (.cse2 (not .cse4))) (or (not (= |old(~pumpRunning~0)| 0)) (not (<= 1 |old(~waterLevel~0)|)) (and .cse0 .cse1 .cse2) (and .cse3 .cse1 .cse2))) (or (and .cse0 (<= 1 |timeShift_isLowWaterLevel_#res#1|) (<= 1 |timeShift_processEnvironment_~tmp~6#1|) (<= 1 ~waterLevel~0) (<= 1 |timeShift_isLowWaterLevel_~tmp___0~2#1|)) .cse3 .cse4 (not (<= 2 |old(~waterLevel~0)|))))) [2022-07-22 17:39:31,189 INFO L899 garLoopResultBuilder]: For program point L616-1(lines 616 622) no Hoare annotation was computed. [2022-07-22 17:39:31,189 INFO L899 garLoopResultBuilder]: For program point L806(lines 806 810) no Hoare annotation was computed. [2022-07-22 17:39:31,189 INFO L899 garLoopResultBuilder]: For program point L806-2(lines 806 810) no Hoare annotation was computed. [2022-07-22 17:39:31,189 INFO L895 garLoopResultBuilder]: At program point L984(lines 979 987) the Hoare annotation is: (let ((.cse7 (<= 2 ~waterLevel~0)) (.cse6 (= |old(~waterLevel~0)| ~waterLevel~0)) (.cse8 (<= 2 |timeShift_getWaterLevel_#res#1|)) (.cse2 (= 0 ~systemActive~0))) (let ((.cse1 (and .cse7 .cse6 .cse8 (not .cse2))) (.cse5 (= ~pumpRunning~0 0)) (.cse4 (<= 1 |timeShift_getWaterLevel_#res#1|)) (.cse3 (not (<= 2 |old(~waterLevel~0)|))) (.cse0 (not (= |old(~pumpRunning~0)| 0)))) (and (or .cse0 .cse1 .cse2 .cse3) (or .cse0 .cse4 .cse3) (or .cse0 (and .cse5 .cse6) .cse1 (not (<= 1 |old(~waterLevel~0)|))) (or (and .cse7 .cse8) (and .cse5 (<= 1 |timeShift_isLowWaterLevel_#res#1|) (<= 1 |timeShift_processEnvironment_~tmp~6#1|) (<= 1 ~waterLevel~0) .cse4 (<= 1 |timeShift_isLowWaterLevel_~tmp___0~2#1|)) .cse2 .cse3) (or .cse0 (not (= |old(~waterLevel~0)| 1)) (= |timeShift_getWaterLevel_#res#1| 1))))) [2022-07-22 17:39:31,189 INFO L895 garLoopResultBuilder]: At program point timeShiftENTRY(lines 605 628) the Hoare annotation is: (let ((.cse0 (= |old(~waterLevel~0)| ~waterLevel~0))) (and (or (not (= |old(~pumpRunning~0)| 0)) (and (= ~pumpRunning~0 0) .cse0) (not (<= 1 |old(~waterLevel~0)|))) (or (and (= ~pumpRunning~0 |old(~pumpRunning~0)|) .cse0) (= 0 ~systemActive~0) (not (<= 2 |old(~waterLevel~0)|))))) [2022-07-22 17:39:31,190 INFO L899 garLoopResultBuilder]: For program point L588(line 588) no Hoare annotation was computed. [2022-07-22 17:39:31,190 INFO L899 garLoopResultBuilder]: For program point timeShiftEXIT(lines 605 628) no Hoare annotation was computed. [2022-07-22 17:39:31,190 INFO L899 garLoopResultBuilder]: For program point timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION(line 588) no Hoare annotation was computed. [2022-07-22 17:39:31,190 INFO L902 garLoopResultBuilder]: At program point L96(line 96) the Hoare annotation is: true [2022-07-22 17:39:31,190 INFO L899 garLoopResultBuilder]: For program point cleanupEXIT(lines 90 119) no Hoare annotation was computed. [2022-07-22 17:39:31,190 INFO L899 garLoopResultBuilder]: For program point L96-1(line 96) no Hoare annotation was computed. [2022-07-22 17:39:31,190 INFO L902 garLoopResultBuilder]: At program point cleanupENTRY(lines 90 119) the Hoare annotation is: true [2022-07-22 17:39:31,191 INFO L902 garLoopResultBuilder]: At program point L115(lines 90 119) the Hoare annotation is: true [2022-07-22 17:39:31,191 INFO L899 garLoopResultBuilder]: For program point L111(line 111) no Hoare annotation was computed. [2022-07-22 17:39:31,191 INFO L899 garLoopResultBuilder]: For program point L104(lines 104 108) no Hoare annotation was computed. [2022-07-22 17:39:31,191 INFO L902 garLoopResultBuilder]: At program point L104-1(lines 104 108) the Hoare annotation is: true [2022-07-22 17:39:31,191 INFO L899 garLoopResultBuilder]: For program point L101(line 101) no Hoare annotation was computed. [2022-07-22 17:39:31,191 INFO L902 garLoopResultBuilder]: At program point L100-2(lines 100 114) the Hoare annotation is: true [2022-07-22 17:39:31,191 INFO L895 garLoopResultBuilder]: At program point L828(lines 816 830) the Hoare annotation is: (and (= ~pumpRunning~0 0) (= |ULTIMATE.start_valid_product_#res#1| 1) (= |ULTIMATE.start_main_~tmp~0#1| 1) (= |ULTIMATE.start_test_~splverifierCounter~0#1| 0) (<= 1 ~waterLevel~0)) [2022-07-22 17:39:31,192 INFO L902 garLoopResultBuilder]: At program point L184(lines 165 187) the Hoare annotation is: true [2022-07-22 17:39:31,192 INFO L895 garLoopResultBuilder]: At program point L151(lines 147 153) the Hoare annotation is: (and (= ~pumpRunning~0 0) (= |ULTIMATE.start_main_~tmp~0#1| 1) (= 1 ~systemActive~0) (= |ULTIMATE.start_valid_product_#res#1| ~systemActive~0) (= ~waterLevel~0 1)) [2022-07-22 17:39:31,192 INFO L899 garLoopResultBuilder]: For program point L820(lines 820 826) no Hoare annotation was computed. [2022-07-22 17:39:31,192 INFO L899 garLoopResultBuilder]: For program point L820-1(lines 820 826) no Hoare annotation was computed. [2022-07-22 17:39:31,192 INFO L902 garLoopResultBuilder]: At program point L903(lines 840 907) the Hoare annotation is: true [2022-07-22 17:39:31,192 INFO L899 garLoopResultBuilder]: For program point L870(lines 870 876) no Hoare annotation was computed. [2022-07-22 17:39:31,192 INFO L899 garLoopResultBuilder]: For program point L870-1(lines 870 876) no Hoare annotation was computed. [2022-07-22 17:39:31,192 INFO L899 garLoopResultBuilder]: For program point L-1(line -1) no Hoare annotation was computed. [2022-07-22 17:39:31,193 INFO L895 garLoopResultBuilder]: At program point L862(line 862) the Hoare annotation is: (let ((.cse0 (= |ULTIMATE.start_valid_product_#res#1| 1)) (.cse1 (= |ULTIMATE.start_main_~tmp~0#1| 1)) (.cse2 (= |ULTIMATE.start_test_~splverifierCounter~0#1| 0))) (or (and (= ~pumpRunning~0 0) .cse0 .cse1 .cse2 (<= 1 ~waterLevel~0)) (and .cse0 .cse1 (<= 2 ~waterLevel~0) .cse2 (not (= 0 ~systemActive~0))))) [2022-07-22 17:39:31,193 INFO L899 garLoopResultBuilder]: For program point ULTIMATE.startENTRY(line -1) no Hoare annotation was computed. [2022-07-22 17:39:31,193 INFO L899 garLoopResultBuilder]: For program point ULTIMATE.startFINAL(line -1) no Hoare annotation was computed. [2022-07-22 17:39:31,193 INFO L895 garLoopResultBuilder]: At program point L900(lines 849 901) the Hoare annotation is: false [2022-07-22 17:39:31,193 INFO L899 garLoopResultBuilder]: For program point ULTIMATE.startEXIT(line -1) no Hoare annotation was computed. [2022-07-22 17:39:31,193 INFO L899 garLoopResultBuilder]: For program point L888(lines 888 894) no Hoare annotation was computed. [2022-07-22 17:39:31,193 INFO L895 garLoopResultBuilder]: At program point L822(line 822) the Hoare annotation is: (and (= |ULTIMATE.start_valid_product_#res#1| 1) (= |ULTIMATE.start_main_~tmp~0#1| 1) (<= 2 ~waterLevel~0) (= |ULTIMATE.start_test_~splverifierCounter~0#1| 0) (not (= 0 ~systemActive~0))) [2022-07-22 17:39:31,194 INFO L895 garLoopResultBuilder]: At program point L888-2(lines 880 895) the Hoare annotation is: (let ((.cse0 (= |ULTIMATE.start_valid_product_#res#1| 1)) (.cse1 (= |ULTIMATE.start_main_~tmp~0#1| 1)) (.cse2 (= |ULTIMATE.start_test_~splverifierCounter~0#1| 0))) (or (and (= ~pumpRunning~0 0) .cse0 .cse1 .cse2 (<= 1 ~waterLevel~0)) (and .cse0 .cse1 (<= 2 ~waterLevel~0) .cse2 (not (= 0 ~systemActive~0))))) [2022-07-22 17:39:31,194 INFO L895 garLoopResultBuilder]: At program point L83(lines 78 86) the Hoare annotation is: (and (= ~pumpRunning~0 0) (= 1 ~systemActive~0) (= |ULTIMATE.start_valid_product_#res#1| ~systemActive~0) (= ~waterLevel~0 1)) [2022-07-22 17:39:31,194 INFO L899 garLoopResultBuilder]: For program point L851(lines 850 899) no Hoare annotation was computed. [2022-07-22 17:39:31,194 INFO L899 garLoopResultBuilder]: For program point L880(lines 880 895) no Hoare annotation was computed. [2022-07-22 17:39:31,194 INFO L895 garLoopResultBuilder]: At program point L75(lines 71 77) the Hoare annotation is: (and (= ~pumpRunning~0 0) (= 1 ~systemActive~0) (= ~waterLevel~0 1)) [2022-07-22 17:39:31,194 INFO L895 garLoopResultBuilder]: At program point L872(line 872) the Hoare annotation is: (let ((.cse0 (= |ULTIMATE.start_valid_product_#res#1| 1)) (.cse1 (= |ULTIMATE.start_main_~tmp~0#1| 1)) (.cse2 (= |ULTIMATE.start_test_~splverifierCounter~0#1| 0))) (or (and (= ~pumpRunning~0 0) .cse0 .cse1 .cse2 (<= 1 ~waterLevel~0)) (and .cse0 .cse1 (<= 2 ~waterLevel~0) .cse2 (not (= 0 ~systemActive~0))))) [2022-07-22 17:39:31,195 INFO L902 garLoopResultBuilder]: At program point L162(lines 155 164) the Hoare annotation is: true [2022-07-22 17:39:31,195 INFO L895 garLoopResultBuilder]: At program point L897(lines 850 899) the Hoare annotation is: (let ((.cse0 (= |ULTIMATE.start_valid_product_#res#1| 1)) (.cse1 (= |ULTIMATE.start_main_~tmp~0#1| 1)) (.cse2 (= |ULTIMATE.start_test_~splverifierCounter~0#1| 0))) (or (and (= ~pumpRunning~0 0) .cse0 .cse1 .cse2 (<= 1 ~waterLevel~0)) (and .cse0 .cse1 (<= 2 ~waterLevel~0) .cse2 (not (= 0 ~systemActive~0))))) [2022-07-22 17:39:31,195 INFO L899 garLoopResultBuilder]: For program point L860(lines 860 866) no Hoare annotation was computed. [2022-07-22 17:39:31,195 INFO L899 garLoopResultBuilder]: For program point L860-1(lines 860 866) no Hoare annotation was computed. [2022-07-22 17:39:31,195 INFO L899 garLoopResultBuilder]: For program point L852(lines 852 856) no Hoare annotation was computed. [2022-07-22 17:39:31,196 INFO L899 garLoopResultBuilder]: For program point L175(lines 175 182) no Hoare annotation was computed. [2022-07-22 17:39:31,196 INFO L899 garLoopResultBuilder]: For program point L175-2(lines 175 182) no Hoare annotation was computed. [2022-07-22 17:39:31,196 INFO L895 garLoopResultBuilder]: At program point L68(lines 64 70) the Hoare annotation is: (and (= ~pumpRunning~0 0) (= 1 ~systemActive~0) (= ~waterLevel~0 1)) [2022-07-22 17:39:31,196 INFO L895 garLoopResultBuilder]: At program point L836(lines 831 838) the Hoare annotation is: (let ((.cse0 (= |ULTIMATE.start_valid_product_#res#1| 1)) (.cse1 (= |ULTIMATE.start_main_~tmp~0#1| 1)) (.cse2 (= 1 ~systemActive~0)) (.cse3 (= |ULTIMATE.start_test_~splverifierCounter~0#1| 0))) (or (and .cse0 .cse1 (<= 2 ~waterLevel~0) .cse2 .cse3) (and (= ~pumpRunning~0 0) .cse0 .cse1 .cse2 .cse3 (= ~waterLevel~0 1)))) [2022-07-22 17:39:31,196 INFO L895 garLoopResultBuilder]: At program point processEnvironment__wrappee__highWaterSensorENTRY(lines 637 661) the Hoare annotation is: (or (not (= |old(~pumpRunning~0)| 0)) (= ~pumpRunning~0 0) (not (<= 1 ~waterLevel~0)) (= 0 ~systemActive~0)) [2022-07-22 17:39:31,196 INFO L899 garLoopResultBuilder]: For program point L704(lines 704 710) no Hoare annotation was computed. [2022-07-22 17:39:31,197 INFO L895 garLoopResultBuilder]: At program point L704-2(lines 697 713) the Hoare annotation is: (or (not (= |old(~pumpRunning~0)| 0)) (not (<= 1 ~waterLevel~0)) (<= 2 ~waterLevel~0) (= 0 ~systemActive~0)) [2022-07-22 17:39:31,197 INFO L895 garLoopResultBuilder]: At program point L793(lines 778 796) the Hoare annotation is: (let ((.cse0 (not (= |old(~pumpRunning~0)| 0))) (.cse1 (= ~pumpRunning~0 0)) (.cse2 (= 0 ~systemActive~0))) (and (or .cse0 .cse1 (not (<= 2 ~waterLevel~0)) .cse2) (or (not (= ~waterLevel~0 1)) .cse0 (and (not (= |processEnvironment__wrappee__highWaterSensor_isHighWaterLevel_~tmp~8#1| 0)) .cse1 (= |processEnvironment__wrappee__highWaterSensor_isHighWaterLevel_~tmp___0~1#1| 0) (not (= |processEnvironment__wrappee__highWaterSensor_isHighWaterSensorDry_#res#1| 0)) (= |processEnvironment__wrappee__highWaterSensor_isHighWaterLevel_#res#1| 0)) .cse2))) [2022-07-22 17:39:31,197 INFO L895 garLoopResultBuilder]: At program point L729(lines 722 732) the Hoare annotation is: (let ((.cse0 (not (= |old(~pumpRunning~0)| 0))) (.cse1 (= 0 ~systemActive~0))) (and (or .cse0 (= ~pumpRunning~0 0) (not (<= 2 ~waterLevel~0)) .cse1) (or (not (= ~waterLevel~0 1)) .cse0 .cse1))) [2022-07-22 17:39:31,197 INFO L895 garLoopResultBuilder]: At program point L952(lines 947 955) the Hoare annotation is: (let ((.cse0 (not (= |old(~pumpRunning~0)| 0))) (.cse1 (= 0 ~systemActive~0))) (and (or .cse0 (= ~pumpRunning~0 0) (not (<= 2 ~waterLevel~0)) .cse1) (or (not (= ~waterLevel~0 1)) .cse0 .cse1))) [2022-07-22 17:39:31,197 INFO L899 garLoopResultBuilder]: For program point L787(lines 787 791) no Hoare annotation was computed. [2022-07-22 17:39:31,197 INFO L899 garLoopResultBuilder]: For program point L787-2(lines 787 791) no Hoare annotation was computed. [2022-07-22 17:39:31,197 INFO L895 garLoopResultBuilder]: At program point L651(line 651) the Hoare annotation is: (let ((.cse0 (not (= |old(~pumpRunning~0)| 0))) (.cse2 (= ~pumpRunning~0 0)) (.cse3 (= |processEnvironment__wrappee__highWaterSensor_~tmp~5#1| 0)) (.cse1 (= 0 ~systemActive~0))) (and (or (not (= ~waterLevel~0 1)) .cse0 .cse1 (and (not (= |processEnvironment__wrappee__highWaterSensor_isHighWaterLevel_~tmp~8#1| 0)) .cse2 .cse3 (not (= |processEnvironment__wrappee__highWaterSensor_isHighWaterSensorDry_#res#1| 0)))) (or .cse0 (and .cse2 .cse3) (not (<= 2 ~waterLevel~0)) .cse1))) [2022-07-22 17:39:31,198 INFO L899 garLoopResultBuilder]: For program point L645(lines 645 653) no Hoare annotation was computed. [2022-07-22 17:39:31,198 INFO L899 garLoopResultBuilder]: For program point L641(lines 641 658) no Hoare annotation was computed. [2022-07-22 17:39:31,198 INFO L899 garLoopResultBuilder]: For program point L992(lines 992 998) no Hoare annotation was computed. [2022-07-22 17:39:31,198 INFO L899 garLoopResultBuilder]: For program point processEnvironment__wrappee__highWaterSensorEXIT(lines 637 661) no Hoare annotation was computed. [2022-07-22 17:39:31,198 INFO L895 garLoopResultBuilder]: At program point L693(lines 688 695) the Hoare annotation is: (or (not (= ~waterLevel~0 1)) (not (= |old(~pumpRunning~0)| 0)) (= 0 ~systemActive~0)) [2022-07-22 17:39:31,198 INFO L895 garLoopResultBuilder]: At program point L656(line 656) the Hoare annotation is: (or (not (= |old(~pumpRunning~0)| 0)) (not (<= 1 ~waterLevel~0)) (= 0 ~systemActive~0)) [2022-07-22 17:39:31,198 INFO L899 garLoopResultBuilder]: For program point L656-1(lines 637 661) no Hoare annotation was computed. [2022-07-22 17:39:31,198 INFO L895 garLoopResultBuilder]: At program point L997(lines 988 1001) the Hoare annotation is: (let ((.cse0 (= ~pumpRunning~0 0))) (or (not (= |old(~pumpRunning~0)| 0)) (not (<= 1 ~waterLevel~0)) (and .cse0 (not (= |processEnvironment__wrappee__highWaterSensor_isHighWaterSensorDry_#res#1| 0))) (and .cse0 (<= 2 ~waterLevel~0)) (= 0 ~systemActive~0))) [2022-07-22 17:39:31,199 INFO L899 garLoopResultBuilder]: For program point waterRiseEXIT(lines 923 934) no Hoare annotation was computed. [2022-07-22 17:39:31,199 INFO L899 garLoopResultBuilder]: For program point L927-1(lines 923 934) no Hoare annotation was computed. [2022-07-22 17:39:31,199 INFO L895 garLoopResultBuilder]: At program point waterRiseENTRY(lines 923 934) the Hoare annotation is: (let ((.cse0 (= |old(~waterLevel~0)| ~waterLevel~0))) (and (or (not (= ~pumpRunning~0 0)) (not (<= 1 |old(~waterLevel~0)|)) .cse0) (or .cse0 (= 0 ~systemActive~0) (not (<= 2 |old(~waterLevel~0)|))))) [2022-07-22 17:39:31,202 INFO L356 BasicCegarLoop]: Path program histogram: [2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-07-22 17:39:31,204 INFO L176 ceAbstractionStarter]: Computing trace abstraction results [2022-07-22 17:39:31,228 INFO L202 PluginConnector]: Adding new model de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction CFG 22.07 05:39:31 BoogieIcfgContainer [2022-07-22 17:39:31,228 INFO L132 PluginConnector]: ------------------------ END TraceAbstraction---------------------------- [2022-07-22 17:39:31,229 INFO L113 PluginConnector]: ------------------------Witness Printer---------------------------- [2022-07-22 17:39:31,229 INFO L271 PluginConnector]: Initializing Witness Printer... [2022-07-22 17:39:31,229 INFO L275 PluginConnector]: Witness Printer initialized [2022-07-22 17:39:31,230 INFO L185 PluginConnector]: Executing the observer RCFGCatcher from plugin Witness Printer for "de.uni_freiburg.informatik.ultimate.plugins.generator.rcfgbuilder CFG 22.07 05:39:21" (3/4) ... [2022-07-22 17:39:31,232 INFO L137 WitnessPrinter]: Generating witness for correct program [2022-07-22 17:39:31,238 INFO L354 RCFGBacktranslator]: Ignoring RootEdge to procedure deactivatePump [2022-07-22 17:39:31,238 INFO L354 RCFGBacktranslator]: Ignoring RootEdge to procedure processEnvironment__wrappee__base [2022-07-22 17:39:31,238 INFO L354 RCFGBacktranslator]: Ignoring RootEdge to procedure changeMethaneLevel [2022-07-22 17:39:31,238 INFO L354 RCFGBacktranslator]: Ignoring RootEdge to procedure timeShift [2022-07-22 17:39:31,238 INFO L354 RCFGBacktranslator]: Ignoring RootEdge to procedure cleanup [2022-07-22 17:39:31,239 INFO L354 RCFGBacktranslator]: Ignoring RootEdge to procedure processEnvironment__wrappee__highWaterSensor [2022-07-22 17:39:31,239 INFO L354 RCFGBacktranslator]: Ignoring RootEdge to procedure waterRise [2022-07-22 17:39:31,246 INFO L910 BoogieBacktranslator]: Reduced CFG by removing 55 nodes and edges [2022-07-22 17:39:31,253 INFO L910 BoogieBacktranslator]: Reduced CFG by removing 22 nodes and edges [2022-07-22 17:39:31,253 INFO L910 BoogieBacktranslator]: Reduced CFG by removing 11 nodes and edges [2022-07-22 17:39:31,254 INFO L910 BoogieBacktranslator]: Reduced CFG by removing 5 nodes and edges [2022-07-22 17:39:31,254 INFO L910 BoogieBacktranslator]: Reduced CFG by removing 2 nodes and edges [2022-07-22 17:39:31,254 INFO L910 BoogieBacktranslator]: Reduced CFG by removing 1 nodes and edges [2022-07-22 17:39:31,255 INFO L910 BoogieBacktranslator]: Reduced CFG by removing 1 nodes and edges [2022-07-22 17:39:31,274 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: ((pumpRunning == 0 && 1 == systemActive) && \result == systemActive) && waterLevel == 1 [2022-07-22 17:39:31,274 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (((pumpRunning == 0 && tmp == 1) && 1 == systemActive) && \result == systemActive) && waterLevel == 1 [2022-07-22 17:39:31,275 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: ((((pumpRunning == 0 && \result == 1) && tmp == 1) && splverifierCounter == 0) && 1 <= waterLevel) || ((((\result == 1 && tmp == 1) && 2 <= waterLevel) && splverifierCounter == 0) && !(0 == systemActive)) [2022-07-22 17:39:31,277 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (!(\old(pumpRunning) == 0) || !(1 <= \old(waterLevel))) && (((pumpRunning == \old(pumpRunning) && 1 <= waterLevel) || 0 == systemActive) || !(2 <= \old(waterLevel))) [2022-07-22 17:39:31,278 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (((!(\old(pumpRunning) == 0) || !(1 <= \old(waterLevel))) || ((pumpRunning == 0 && \old(waterLevel) == waterLevel) && !(0 == systemActive))) || ((2 <= waterLevel && \old(waterLevel) == waterLevel) && !(0 == systemActive))) && (((((((pumpRunning == 0 && 1 <= \result) && 1 <= tmp) && 1 <= waterLevel) && 1 <= tmp___0) || 2 <= waterLevel) || 0 == systemActive) || !(2 <= \old(waterLevel))) [2022-07-22 17:39:31,279 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: ((((\result == 1 && tmp == 1) && 2 <= waterLevel) && 1 == systemActive) && splverifierCounter == 0) || (((((pumpRunning == 0 && \result == 1) && tmp == 1) && 1 == systemActive) && splverifierCounter == 0) && waterLevel == 1) [2022-07-22 17:39:31,279 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: ((((((!(\old(pumpRunning) == 0) || (((2 <= waterLevel && \old(waterLevel) == waterLevel) && 2 <= \result) && !(0 == systemActive))) || 0 == systemActive) || !(2 <= \old(waterLevel))) && ((!(\old(pumpRunning) == 0) || 1 <= \result) || !(2 <= \old(waterLevel)))) && (((!(\old(pumpRunning) == 0) || (pumpRunning == 0 && \old(waterLevel) == waterLevel)) || (((2 <= waterLevel && \old(waterLevel) == waterLevel) && 2 <= \result) && !(0 == systemActive))) || !(1 <= \old(waterLevel)))) && ((((2 <= waterLevel && 2 <= \result) || (((((pumpRunning == 0 && 1 <= \result) && 1 <= tmp) && 1 <= waterLevel) && 1 <= \result) && 1 <= tmp___0)) || 0 == systemActive) || !(2 <= \old(waterLevel)))) && ((!(\old(pumpRunning) == 0) || !(\old(waterLevel) == 1)) || \result == 1) [2022-07-22 17:39:31,279 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (((pumpRunning == 0 && \result == 1) && tmp == 1) && splverifierCounter == 0) && 1 <= waterLevel [2022-07-22 17:39:31,280 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: ((((((!(\old(pumpRunning) == 0) || (pumpRunning == 0 && \old(waterLevel) == waterLevel)) || ((((2 <= waterLevel && \old(waterLevel) == waterLevel) && 2 <= \result) && 2 <= tmp) && !(0 == systemActive))) || !(1 <= \old(waterLevel))) && ((!(\old(pumpRunning) == 0) || !(\old(waterLevel) == 1)) || (tmp == 1 && \result == 1))) && ((!(\old(pumpRunning) == 0) || (1 <= \result && 1 <= tmp)) || !(2 <= \old(waterLevel)))) && (((((((((pumpRunning == 0 && 1 <= \result) && 1 <= tmp) && 1 <= waterLevel) && 1 <= \result) && 1 <= tmp) && 1 <= tmp___0) || ((2 <= waterLevel && 2 <= \result) && 2 <= tmp)) || 0 == systemActive) || !(2 <= \old(waterLevel)))) && (((!(\old(pumpRunning) == 0) || ((((2 <= waterLevel && \old(waterLevel) == waterLevel) && 2 <= \result) && 2 <= tmp) && !(0 == systemActive))) || 0 == systemActive) || !(2 <= \old(waterLevel))) [2022-07-22 17:39:31,280 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (!(\old(pumpRunning) == 0) || !(1 <= \old(waterLevel))) && ((((pumpRunning == \old(pumpRunning) && \result == 0) && 1 <= waterLevel) || 0 == systemActive) || !(2 <= \old(waterLevel))) [2022-07-22 17:39:31,280 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (((!(\old(pumpRunning) == 0) || !(1 <= waterLevel)) || (pumpRunning == 0 && !(\result == 0))) || (pumpRunning == 0 && 2 <= waterLevel)) || 0 == systemActive [2022-07-22 17:39:31,280 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (!(\old(pumpRunning) == 0) || !(1 <= \old(waterLevel))) && (0 == systemActive || !(2 <= \old(waterLevel))) [2022-07-22 17:39:31,280 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (!(\old(pumpRunning) == 0) || !(1 <= \old(waterLevel))) && (((((((pumpRunning == \old(pumpRunning) && \result == 0) && 1 <= \result) && tmp == 0) && 1 <= waterLevel) && 1 <= tmp___0) || 0 == systemActive) || !(2 <= \old(waterLevel))) [2022-07-22 17:39:31,281 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (((!(\old(pumpRunning) == 0) || pumpRunning == 0) || !(2 <= waterLevel)) || 0 == systemActive) && (((!(waterLevel == 1) || !(\old(pumpRunning) == 0)) || ((((!(tmp == 0) && pumpRunning == 0) && tmp___0 == 0) && !(\result == 0)) && \result == 0)) || 0 == systemActive) [2022-07-22 17:39:31,281 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (!(\old(pumpRunning) == 0) || !(1 <= \old(waterLevel))) && (0 == systemActive || !(2 <= \old(waterLevel))) [2022-07-22 17:39:31,281 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (((!(\old(pumpRunning) == 0) || pumpRunning == 0) || !(2 <= waterLevel)) || 0 == systemActive) && ((!(waterLevel == 1) || !(\old(pumpRunning) == 0)) || 0 == systemActive) [2022-07-22 17:39:31,284 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (((!(\old(pumpRunning) == 0) || pumpRunning == 0) || !(2 <= waterLevel)) || 0 == systemActive) && ((!(waterLevel == 1) || !(\old(pumpRunning) == 0)) || 0 == systemActive) [2022-07-22 17:39:31,285 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: ((!(\old(pumpRunning) == 0) || !(1 <= waterLevel)) || 2 <= waterLevel) || 0 == systemActive [2022-07-22 17:39:31,286 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (!(waterLevel == 1) || !(\old(pumpRunning) == 0)) || 0 == systemActive [2022-07-22 17:39:31,318 INFO L141 WitnessManager]: Wrote witness to /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/witness.graphml [2022-07-22 17:39:31,319 INFO L132 PluginConnector]: ------------------------ END Witness Printer---------------------------- [2022-07-22 17:39:31,319 INFO L158 Benchmark]: Toolchain (without parser) took 10470.50ms. Allocated memory was 96.5MB in the beginning and 172.0MB in the end (delta: 75.5MB). Free memory was 64.4MB in the beginning and 61.4MB in the end (delta: 3.0MB). Peak memory consumption was 79.2MB. Max. memory is 16.1GB. [2022-07-22 17:39:31,319 INFO L158 Benchmark]: CDTParser took 0.27ms. Allocated memory is still 96.5MB. Free memory is still 51.0MB. There was no memory consumed. Max. memory is 16.1GB. [2022-07-22 17:39:31,320 INFO L158 Benchmark]: CACSL2BoogieTranslator took 402.81ms. Allocated memory is still 96.5MB. Free memory was 64.1MB in the beginning and 64.1MB in the end (delta: 7.1kB). Peak memory consumption was 8.4MB. Max. memory is 16.1GB. [2022-07-22 17:39:31,320 INFO L158 Benchmark]: Boogie Procedure Inliner took 72.95ms. Allocated memory is still 96.5MB. Free memory was 64.1MB in the beginning and 61.6MB in the end (delta: 2.6MB). Peak memory consumption was 2.1MB. Max. memory is 16.1GB. [2022-07-22 17:39:31,320 INFO L158 Benchmark]: Boogie Preprocessor took 51.66ms. Allocated memory is still 96.5MB. Free memory was 61.6MB in the beginning and 59.8MB in the end (delta: 1.7MB). Peak memory consumption was 2.1MB. Max. memory is 16.1GB. [2022-07-22 17:39:31,321 INFO L158 Benchmark]: RCFGBuilder took 406.80ms. Allocated memory was 96.5MB in the beginning and 117.4MB in the end (delta: 21.0MB). Free memory was 59.8MB in the beginning and 90.5MB in the end (delta: -30.7MB). Peak memory consumption was 19.3MB. Max. memory is 16.1GB. [2022-07-22 17:39:31,321 INFO L158 Benchmark]: TraceAbstraction took 9438.92ms. Allocated memory was 117.4MB in the beginning and 172.0MB in the end (delta: 54.5MB). Free memory was 90.0MB in the beginning and 67.7MB in the end (delta: 22.3MB). Peak memory consumption was 106.3MB. Max. memory is 16.1GB. [2022-07-22 17:39:31,321 INFO L158 Benchmark]: Witness Printer took 89.81ms. Allocated memory is still 172.0MB. Free memory was 67.7MB in the beginning and 61.4MB in the end (delta: 6.3MB). Peak memory consumption was 8.4MB. Max. memory is 16.1GB. [2022-07-22 17:39:31,323 INFO L339 ainManager$Toolchain]: ####################### End [Toolchain 1] ####################### --- Results --- * Results from de.uni_freiburg.informatik.ultimate.core: - StatisticsResult: Toolchain Benchmarks Benchmark results are: * CDTParser took 0.27ms. Allocated memory is still 96.5MB. Free memory is still 51.0MB. There was no memory consumed. Max. memory is 16.1GB. * CACSL2BoogieTranslator took 402.81ms. Allocated memory is still 96.5MB. Free memory was 64.1MB in the beginning and 64.1MB in the end (delta: 7.1kB). Peak memory consumption was 8.4MB. Max. memory is 16.1GB. * Boogie Procedure Inliner took 72.95ms. Allocated memory is still 96.5MB. Free memory was 64.1MB in the beginning and 61.6MB in the end (delta: 2.6MB). Peak memory consumption was 2.1MB. Max. memory is 16.1GB. * Boogie Preprocessor took 51.66ms. Allocated memory is still 96.5MB. Free memory was 61.6MB in the beginning and 59.8MB in the end (delta: 1.7MB). Peak memory consumption was 2.1MB. Max. memory is 16.1GB. * RCFGBuilder took 406.80ms. Allocated memory was 96.5MB in the beginning and 117.4MB in the end (delta: 21.0MB). Free memory was 59.8MB in the beginning and 90.5MB in the end (delta: -30.7MB). Peak memory consumption was 19.3MB. Max. memory is 16.1GB. * TraceAbstraction took 9438.92ms. Allocated memory was 117.4MB in the beginning and 172.0MB in the end (delta: 54.5MB). Free memory was 90.0MB in the beginning and 67.7MB in the end (delta: 22.3MB). Peak memory consumption was 106.3MB. Max. memory is 16.1GB. * Witness Printer took 89.81ms. Allocated memory is still 172.0MB. Free memory was 67.7MB in the beginning and 61.4MB in the end (delta: 6.3MB). Peak memory consumption was 8.4MB. Max. memory is 16.1GB. * Results from de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction: - StatisticsResult: ErrorAutomatonStatistics NumberErrorTraces: 0, NumberStatementsAllTraces: 0, NumberRelevantStatements: 0, 0.0s ErrorAutomatonConstructionTimeTotal, 0.0s FaulLocalizationTime, NumberStatementsFirstTrace: -1, TraceLengthAvg: 0, 0.0s ErrorAutomatonConstructionTimeAvg, 0.0s ErrorAutomatonDifferenceTimeAvg, 0.0s ErrorAutomatonDifferenceTimeTotal, NumberOfNoEnhancement: 0, NumberOfFiniteEnhancement: 0, NumberOfInfiniteEnhancement: 0 - PositiveResult [Line: 588]: call to reach_error is unreachable For all program executions holds that call to reach_error is unreachable at this location - StatisticsResult: Ultimate Automizer benchmark data CFG has 8 procedures, 94 locations, 1 error locations. Started 1 CEGAR loops. OverallTime: 9.3s, OverallIterations: 12, TraceHistogramMax: 3, PathProgramHistogramMax: 2, EmptinessCheckTime: 0.1s, AutomataDifference: 2.6s, DeadEndRemovalTime: 0.0s, HoareAnnotationTime: 3.8s, InitialAbstractionConstructionTime: 0.0s, HoareTripleCheckerStatistics: 0 mSolverCounterUnknown, 1917 SdHoareTripleChecker+Valid, 1.4s IncrementalHoareTripleChecker+Time, 0 mSdLazyCounter, 1899 mSDsluCounter, 4283 SdHoareTripleChecker+Invalid, 1.1s Time, 0 mProtectedAction, 0 SdHoareTripleChecker+Unchecked, 0 IncrementalHoareTripleChecker+Unchecked, 2947 mSDsCounter, 453 IncrementalHoareTripleChecker+Valid, 0 mProtectedPredicate, 1948 IncrementalHoareTripleChecker+Invalid, 2401 SdHoareTripleChecker+Unknown, 0 mSolverCounterNotChecked, 453 mSolverCounterUnsat, 1336 mSDtfsCounter, 1948 mSolverCounterSat, 0.0s SdHoareTripleChecker+Time, 0 IncrementalHoareTripleChecker+Unknown, PredicateUnifierStatistics: 0 DeclaredPredicates, 477 GetRequests, 355 SyntacticMatches, 7 SemanticMatches, 115 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 340 ImplicationChecksByTransitivity, 0.7s Time, 0.0s BasicInterpolantAutomatonTime, BiggestAbstraction: size=1505occurred in iteration=11, InterpolantAutomatonStates: 112, traceCheckStatistics: No data available, InterpolantConsolidationStatistics: No data available, PathInvariantsStatistics: No data available, 0/0 InterpolantCoveringCapability, TotalInterpolationStatistics: No data available, 0.0s DumpTime, AutomataMinimizationStatistics: 0.5s AutomataMinimizationTime, 12 MinimizatonAttempts, 503 StatesRemovedByMinimization, 8 NontrivialMinimizations, HoareAnnotationStatistics: 0.0s HoareAnnotationTime, 45 LocationsWithAnnotation, 2691 PreInvPairs, 3001 NumberOfFragments, 1108 HoareAnnotationTreeSize, 2691 FomulaSimplifications, 4094 FormulaSimplificationTreeSizeReduction, 1.0s HoareSimplificationTime, 45 FomulaSimplificationsInter, 23822 FormulaSimplificationTreeSizeReductionInter, 2.7s HoareSimplificationTimeInter, RefinementEngineStatistics: TRACE_CHECK: 0.1s SsaConstructionTime, 0.4s SatisfiabilityAnalysisTime, 1.2s InterpolantComputationTime, 810 NumberOfCodeBlocks, 810 NumberOfCodeBlocksAsserted, 15 NumberOfCheckSat, 877 ConstructedInterpolants, 0 QuantifiedInterpolants, 1678 SizeOfPredicates, 8 NumberOfNonLiveVariables, 990 ConjunctsInSsa, 18 ConjunctsInUnsatCore, 15 InterpolantComputations, 11 PerfectInterpolantSequences, 264/294 InterpolantCoveringCapability, INVARIANT_SYNTHESIS: No data available, INTERPOLANT_CONSOLIDATION: No data available, ABSTRACT_INTERPRETATION: No data available, PDR: No data available, ACCELERATED_INTERPOLATION: No data available, SIFA: No data available, ReuseStatistics: No data available - AllSpecificationsHoldResult: All specifications hold 1 specifications checked. All of them hold - InvariantResult [Line: 840]: Loop Invariant Derived loop invariant: 1 - InvariantResult [Line: 584]: Loop Invariant Derived loop invariant: (!(\old(pumpRunning) == 0) || !(1 <= \old(waterLevel))) && (0 == systemActive || !(2 <= \old(waterLevel))) - InvariantResult [Line: 90]: Loop Invariant Derived loop invariant: 1 - InvariantResult [Line: 558]: Loop Invariant Derived loop invariant: ((((((!(\old(pumpRunning) == 0) || (pumpRunning == 0 && \old(waterLevel) == waterLevel)) || ((((2 <= waterLevel && \old(waterLevel) == waterLevel) && 2 <= \result) && 2 <= tmp) && !(0 == systemActive))) || !(1 <= \old(waterLevel))) && ((!(\old(pumpRunning) == 0) || !(\old(waterLevel) == 1)) || (tmp == 1 && \result == 1))) && ((!(\old(pumpRunning) == 0) || (1 <= \result && 1 <= tmp)) || !(2 <= \old(waterLevel)))) && (((((((((pumpRunning == 0 && 1 <= \result) && 1 <= tmp) && 1 <= waterLevel) && 1 <= \result) && 1 <= tmp) && 1 <= tmp___0) || ((2 <= waterLevel && 2 <= \result) && 2 <= tmp)) || 0 == systemActive) || !(2 <= \old(waterLevel)))) && (((!(\old(pumpRunning) == 0) || ((((2 <= waterLevel && \old(waterLevel) == waterLevel) && 2 <= \result) && 2 <= tmp) && !(0 == systemActive))) || 0 == systemActive) || !(2 <= \old(waterLevel))) - InvariantResult [Line: 688]: Loop Invariant Derived loop invariant: (!(waterLevel == 1) || !(\old(pumpRunning) == 0)) || 0 == systemActive - InvariantResult [Line: 663]: Loop Invariant Derived loop invariant: (((!(\old(pumpRunning) == 0) || !(1 <= \old(waterLevel))) || ((pumpRunning == 0 && \old(waterLevel) == waterLevel) && !(0 == systemActive))) || ((2 <= waterLevel && \old(waterLevel) == waterLevel) && !(0 == systemActive))) && (((((((pumpRunning == 0 && 1 <= \result) && 1 <= tmp) && 1 <= waterLevel) && 1 <= tmp___0) || 2 <= waterLevel) || 0 == systemActive) || !(2 <= \old(waterLevel))) - InvariantResult [Line: 850]: Loop Invariant Derived loop invariant: ((((pumpRunning == 0 && \result == 1) && tmp == 1) && splverifierCounter == 0) && 1 <= waterLevel) || ((((\result == 1 && tmp == 1) && 2 <= waterLevel) && splverifierCounter == 0) && !(0 == systemActive)) - InvariantResult [Line: 988]: Loop Invariant Derived loop invariant: (((!(\old(pumpRunning) == 0) || !(1 <= waterLevel)) || (pumpRunning == 0 && !(\result == 0))) || (pumpRunning == 0 && 2 <= waterLevel)) || 0 == systemActive - InvariantResult [Line: 697]: Loop Invariant Derived loop invariant: ((!(\old(pumpRunning) == 0) || !(1 <= waterLevel)) || 2 <= waterLevel) || 0 == systemActive - InvariantResult [Line: 831]: Loop Invariant Derived loop invariant: ((((\result == 1 && tmp == 1) && 2 <= waterLevel) && 1 == systemActive) && splverifierCounter == 0) || (((((pumpRunning == 0 && \result == 1) && tmp == 1) && 1 == systemActive) && splverifierCounter == 0) && waterLevel == 1) - InvariantResult [Line: 733]: Loop Invariant Derived loop invariant: (!(\old(pumpRunning) == 0) || !(1 <= \old(waterLevel))) && (0 == systemActive || !(2 <= \old(waterLevel))) - InvariantResult [Line: 147]: Loop Invariant Derived loop invariant: (((pumpRunning == 0 && tmp == 1) && 1 == systemActive) && \result == systemActive) && waterLevel == 1 - InvariantResult [Line: 1002]: Loop Invariant Derived loop invariant: (!(\old(pumpRunning) == 0) || !(1 <= \old(waterLevel))) && ((((pumpRunning == \old(pumpRunning) && \result == 0) && 1 <= waterLevel) || 0 == systemActive) || !(2 <= \old(waterLevel))) - InvariantResult [Line: 165]: Loop Invariant Derived loop invariant: 1 - InvariantResult [Line: 911]: Loop Invariant Derived loop invariant: (!(\old(pumpRunning) == 0) || !(1 <= \old(waterLevel))) && (((pumpRunning == \old(pumpRunning) && 1 <= waterLevel) || 0 == systemActive) || !(2 <= \old(waterLevel))) - InvariantResult [Line: 100]: Loop Invariant Derived loop invariant: 1 - InvariantResult [Line: 722]: Loop Invariant Derived loop invariant: (((!(\old(pumpRunning) == 0) || pumpRunning == 0) || !(2 <= waterLevel)) || 0 == systemActive) && ((!(waterLevel == 1) || !(\old(pumpRunning) == 0)) || 0 == systemActive) - InvariantResult [Line: 849]: Loop Invariant Derived loop invariant: 0 - InvariantResult [Line: 947]: Loop Invariant Derived loop invariant: (((!(\old(pumpRunning) == 0) || pumpRunning == 0) || !(2 <= waterLevel)) || 0 == systemActive) && ((!(waterLevel == 1) || !(\old(pumpRunning) == 0)) || 0 == systemActive) - InvariantResult [Line: 797]: Loop Invariant Derived loop invariant: (!(\old(pumpRunning) == 0) || !(1 <= \old(waterLevel))) && (((((((pumpRunning == \old(pumpRunning) && \result == 0) && 1 <= \result) && tmp == 0) && 1 <= waterLevel) && 1 <= tmp___0) || 0 == systemActive) || !(2 <= \old(waterLevel))) - InvariantResult [Line: 816]: Loop Invariant Derived loop invariant: (((pumpRunning == 0 && \result == 1) && tmp == 1) && splverifierCounter == 0) && 1 <= waterLevel - InvariantResult [Line: 78]: Loop Invariant Derived loop invariant: ((pumpRunning == 0 && 1 == systemActive) && \result == systemActive) && waterLevel == 1 - InvariantResult [Line: 64]: Loop Invariant Derived loop invariant: (pumpRunning == 0 && 1 == systemActive) && waterLevel == 1 - InvariantResult [Line: 71]: Loop Invariant Derived loop invariant: (pumpRunning == 0 && 1 == systemActive) && waterLevel == 1 - InvariantResult [Line: 979]: Loop Invariant Derived loop invariant: ((((((!(\old(pumpRunning) == 0) || (((2 <= waterLevel && \old(waterLevel) == waterLevel) && 2 <= \result) && !(0 == systemActive))) || 0 == systemActive) || !(2 <= \old(waterLevel))) && ((!(\old(pumpRunning) == 0) || 1 <= \result) || !(2 <= \old(waterLevel)))) && (((!(\old(pumpRunning) == 0) || (pumpRunning == 0 && \old(waterLevel) == waterLevel)) || (((2 <= waterLevel && \old(waterLevel) == waterLevel) && 2 <= \result) && !(0 == systemActive))) || !(1 <= \old(waterLevel)))) && ((((2 <= waterLevel && 2 <= \result) || (((((pumpRunning == 0 && 1 <= \result) && 1 <= tmp) && 1 <= waterLevel) && 1 <= \result) && 1 <= tmp___0)) || 0 == systemActive) || !(2 <= \old(waterLevel)))) && ((!(\old(pumpRunning) == 0) || !(\old(waterLevel) == 1)) || \result == 1) - InvariantResult [Line: 778]: Loop Invariant Derived loop invariant: (((!(\old(pumpRunning) == 0) || pumpRunning == 0) || !(2 <= waterLevel)) || 0 == systemActive) && (((!(waterLevel == 1) || !(\old(pumpRunning) == 0)) || ((((!(tmp == 0) && pumpRunning == 0) && tmp___0 == 0) && !(\result == 0)) && \result == 0)) || 0 == systemActive) - InvariantResult [Line: 155]: Loop Invariant Derived loop invariant: 1 RESULT: Ultimate proved your program to be correct! [2022-07-22 17:39:31,378 INFO L540 MonitoredProcess]: [MP /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in -t:2000 (1)] Forceful destruction successful, exit code 0 Received shutdown request... --- End real Ultimate output --- Execution finished normally Writing output log to file Ultimate.log Result: TRUE