./Ultimate.py --spec ../sv-benchmarks/c/properties/unreach-call.prp --file ../sv-benchmarks/c/product-lines/minepump_spec4_product03.cil.c --full-output --architecture 32bit -------------------------------------------------------------------------------- Checking for ERROR reachability Using default analysis Version eb692b52 Calling Ultimate with: /usr/bin/java -Dosgi.configuration.area=/storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/data/config -Xmx15G -Xms4m -jar /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/plugins/org.eclipse.equinox.launcher_1.5.800.v20200727-1323.jar -data @noDefault -ultimatedata /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/data -tc /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/config/AutomizerReach.xml -i ../sv-benchmarks/c/product-lines/minepump_spec4_product03.cil.c -s /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/config/svcomp-Reach-32bit-Automizer_Default.epf --cacsl2boogietranslator.entry.function main --witnessprinter.witness.directory /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux --witnessprinter.witness.filename witness.graphml --witnessprinter.write.witness.besides.input.file false --witnessprinter.graph.data.specification CHECK( init(main()), LTL(G ! call(reach_error())) ) --witnessprinter.graph.data.producer Automizer --witnessprinter.graph.data.architecture 32bit --witnessprinter.graph.data.programhash 355b5902b5f931f50c54d9516b33231d0a6419b36d45cf753c504688535a3e74 --- Real Ultimate output --- This is Ultimate 0.2.2-?-eb692b5 [2022-07-19 17:24:54,651 INFO L177 SettingsManager]: Resetting all preferences to default values... [2022-07-19 17:24:54,654 INFO L181 SettingsManager]: Resetting UltimateCore preferences to default values [2022-07-19 17:24:54,694 INFO L184 SettingsManager]: Ultimate Commandline Interface provides no preferences, ignoring... [2022-07-19 17:24:54,695 INFO L181 SettingsManager]: Resetting Boogie Preprocessor preferences to default values [2022-07-19 17:24:54,696 INFO L181 SettingsManager]: Resetting Boogie Procedure Inliner preferences to default values [2022-07-19 17:24:54,698 INFO L181 SettingsManager]: Resetting Abstract Interpretation preferences to default values [2022-07-19 17:24:54,703 INFO L181 SettingsManager]: Resetting LassoRanker preferences to default values [2022-07-19 17:24:54,705 INFO L181 SettingsManager]: Resetting Reaching Definitions preferences to default values [2022-07-19 17:24:54,712 INFO L181 SettingsManager]: Resetting SyntaxChecker preferences to default values [2022-07-19 17:24:54,713 INFO L181 SettingsManager]: Resetting Sifa preferences to default values [2022-07-19 17:24:54,715 INFO L184 SettingsManager]: Büchi Program Product provides no preferences, ignoring... [2022-07-19 17:24:54,715 INFO L181 SettingsManager]: Resetting LTL2Aut preferences to default values [2022-07-19 17:24:54,718 INFO L181 SettingsManager]: Resetting PEA to Boogie preferences to default values [2022-07-19 17:24:54,720 INFO L181 SettingsManager]: Resetting BlockEncodingV2 preferences to default values [2022-07-19 17:24:54,723 INFO L181 SettingsManager]: Resetting ChcToBoogie preferences to default values [2022-07-19 17:24:54,724 INFO L181 SettingsManager]: Resetting AutomataScriptInterpreter preferences to default values [2022-07-19 17:24:54,725 INFO L181 SettingsManager]: Resetting BuchiAutomizer preferences to default values [2022-07-19 17:24:54,727 INFO L181 SettingsManager]: Resetting CACSL2BoogieTranslator preferences to default values [2022-07-19 17:24:54,730 INFO L181 SettingsManager]: Resetting CodeCheck preferences to default values [2022-07-19 17:24:54,733 INFO L181 SettingsManager]: Resetting HornVerifier preferences to default values [2022-07-19 17:24:54,735 INFO L181 SettingsManager]: Resetting InvariantSynthesis preferences to default values [2022-07-19 17:24:54,736 INFO L181 SettingsManager]: Resetting RCFGBuilder preferences to default values [2022-07-19 17:24:54,737 INFO L181 SettingsManager]: Resetting Referee preferences to default values [2022-07-19 17:24:54,738 INFO L181 SettingsManager]: Resetting TraceAbstraction preferences to default values [2022-07-19 17:24:54,742 INFO L184 SettingsManager]: TraceAbstractionConcurrent provides no preferences, ignoring... [2022-07-19 17:24:54,743 INFO L184 SettingsManager]: TraceAbstractionWithAFAs provides no preferences, ignoring... [2022-07-19 17:24:54,744 INFO L181 SettingsManager]: Resetting TreeAutomizer preferences to default values [2022-07-19 17:24:54,745 INFO L181 SettingsManager]: Resetting IcfgToChc preferences to default values [2022-07-19 17:24:54,746 INFO L181 SettingsManager]: Resetting IcfgTransformer preferences to default values [2022-07-19 17:24:54,747 INFO L184 SettingsManager]: ReqToTest provides no preferences, ignoring... [2022-07-19 17:24:54,747 INFO L181 SettingsManager]: Resetting Boogie Printer preferences to default values [2022-07-19 17:24:54,748 INFO L181 SettingsManager]: Resetting ChcSmtPrinter preferences to default values [2022-07-19 17:24:54,749 INFO L181 SettingsManager]: Resetting ReqPrinter preferences to default values [2022-07-19 17:24:54,749 INFO L181 SettingsManager]: Resetting Witness Printer preferences to default values [2022-07-19 17:24:54,750 INFO L184 SettingsManager]: Boogie PL CUP Parser provides no preferences, ignoring... [2022-07-19 17:24:54,750 INFO L181 SettingsManager]: Resetting CDTParser preferences to default values [2022-07-19 17:24:54,751 INFO L184 SettingsManager]: AutomataScriptParser provides no preferences, ignoring... [2022-07-19 17:24:54,751 INFO L184 SettingsManager]: ReqParser provides no preferences, ignoring... [2022-07-19 17:24:54,751 INFO L181 SettingsManager]: Resetting SmtParser preferences to default values [2022-07-19 17:24:54,752 INFO L181 SettingsManager]: Resetting Witness Parser preferences to default values [2022-07-19 17:24:54,754 INFO L188 SettingsManager]: Finished resetting all preferences to default values... [2022-07-19 17:24:54,755 INFO L101 SettingsManager]: Beginning loading settings from /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/config/svcomp-Reach-32bit-Automizer_Default.epf [2022-07-19 17:24:54,791 INFO L113 SettingsManager]: Loading preferences was successful [2022-07-19 17:24:54,791 INFO L115 SettingsManager]: Preferences different from defaults after loading the file: [2022-07-19 17:24:54,792 INFO L136 SettingsManager]: Preferences of UltimateCore differ from their defaults: [2022-07-19 17:24:54,792 INFO L138 SettingsManager]: * Log level for class=de.uni_freiburg.informatik.ultimate.lib.smtlibutils.quantifier.QuantifierPusher=ERROR; [2022-07-19 17:24:54,792 INFO L136 SettingsManager]: Preferences of Boogie Procedure Inliner differ from their defaults: [2022-07-19 17:24:54,793 INFO L138 SettingsManager]: * Ignore calls to procedures called more than once=ONLY_FOR_SEQUENTIAL_PROGRAMS [2022-07-19 17:24:54,793 INFO L136 SettingsManager]: Preferences of BlockEncodingV2 differ from their defaults: [2022-07-19 17:24:54,793 INFO L138 SettingsManager]: * Create parallel compositions if possible=false [2022-07-19 17:24:54,794 INFO L138 SettingsManager]: * Use SBE=true [2022-07-19 17:24:54,794 INFO L136 SettingsManager]: Preferences of CACSL2BoogieTranslator differ from their defaults: [2022-07-19 17:24:54,795 INFO L138 SettingsManager]: * sizeof long=4 [2022-07-19 17:24:54,795 INFO L138 SettingsManager]: * Overapproximate operations on floating types=true [2022-07-19 17:24:54,795 INFO L138 SettingsManager]: * sizeof POINTER=4 [2022-07-19 17:24:54,795 INFO L138 SettingsManager]: * Check division by zero=IGNORE [2022-07-19 17:24:54,795 INFO L138 SettingsManager]: * Pointer to allocated memory at dereference=IGNORE [2022-07-19 17:24:54,795 INFO L138 SettingsManager]: * If two pointers are subtracted or compared they have the same base address=IGNORE [2022-07-19 17:24:54,796 INFO L138 SettingsManager]: * Check array bounds for arrays that are off heap=IGNORE [2022-07-19 17:24:54,796 INFO L138 SettingsManager]: * sizeof long double=12 [2022-07-19 17:24:54,796 INFO L138 SettingsManager]: * Check if freed pointer was valid=false [2022-07-19 17:24:54,796 INFO L138 SettingsManager]: * Use constant arrays=true [2022-07-19 17:24:54,796 INFO L138 SettingsManager]: * Pointer base address is valid at dereference=IGNORE [2022-07-19 17:24:54,797 INFO L136 SettingsManager]: Preferences of RCFGBuilder differ from their defaults: [2022-07-19 17:24:54,797 INFO L138 SettingsManager]: * Size of a code block=SequenceOfStatements [2022-07-19 17:24:54,797 INFO L138 SettingsManager]: * SMT solver=External_DefaultMode [2022-07-19 17:24:54,797 INFO L138 SettingsManager]: * Command for external solver=z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in -t:2000 [2022-07-19 17:24:54,797 INFO L136 SettingsManager]: Preferences of TraceAbstraction differ from their defaults: [2022-07-19 17:24:54,797 INFO L138 SettingsManager]: * Compute Interpolants along a Counterexample=FPandBP [2022-07-19 17:24:54,798 INFO L138 SettingsManager]: * Positions where we compute the Hoare Annotation=LoopsAndPotentialCycles [2022-07-19 17:24:54,798 INFO L138 SettingsManager]: * Trace refinement strategy=CAMEL [2022-07-19 17:24:54,798 INFO L138 SettingsManager]: * Command for external solver=z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in [2022-07-19 17:24:54,798 INFO L138 SettingsManager]: * Apply one-shot large block encoding in concurrent analysis=false [2022-07-19 17:24:54,798 INFO L138 SettingsManager]: * Automaton type used in concurrency analysis=PETRI_NET [2022-07-19 17:24:54,799 INFO L138 SettingsManager]: * Compute Hoare Annotation of negated interpolant automaton, abstraction and CFG=true [2022-07-19 17:24:54,799 INFO L138 SettingsManager]: * SMT solver=External_ModelsAndUnsatCoreMode WARNING: An illegal reflective access operation has occurred WARNING: Illegal reflective access by com.sun.xml.bind.v2.runtime.reflect.opt.Injector$1 (file:/storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/plugins/com.sun.xml.bind_2.2.0.v201505121915.jar) to method java.lang.ClassLoader.defineClass(java.lang.String,byte[],int,int) WARNING: Please consider reporting this to the maintainers of com.sun.xml.bind.v2.runtime.reflect.opt.Injector$1 WARNING: Use --illegal-access=warn to enable warnings of further illegal reflective access operations WARNING: All illegal access operations will be denied in a future release Applying setting for plugin de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator: Entry function -> main Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Witness directory -> /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Witness filename -> witness.graphml Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Write witness besides input file -> false Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Graph data specification -> CHECK( init(main()), LTL(G ! call(reach_error())) ) Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Graph data producer -> Automizer Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Graph data architecture -> 32bit Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Graph data programhash -> 355b5902b5f931f50c54d9516b33231d0a6419b36d45cf753c504688535a3e74 [2022-07-19 17:24:55,040 INFO L75 nceAwareModelManager]: Repository-Root is: /tmp [2022-07-19 17:24:55,065 INFO L261 ainManager$Toolchain]: [Toolchain 1]: Applicable parser(s) successfully (re)initialized [2022-07-19 17:24:55,067 INFO L217 ainManager$Toolchain]: [Toolchain 1]: Toolchain selected. [2022-07-19 17:24:55,069 INFO L271 PluginConnector]: Initializing CDTParser... [2022-07-19 17:24:55,069 INFO L275 PluginConnector]: CDTParser initialized [2022-07-19 17:24:55,071 INFO L432 ainManager$Toolchain]: [Toolchain 1]: Parsing single file: /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/../sv-benchmarks/c/product-lines/minepump_spec4_product03.cil.c [2022-07-19 17:24:55,136 INFO L220 CDTParser]: Created temporary CDT project at /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/data/f4e2b7fcd/1e0bac0eeb0c4a54920fde961d228d9b/FLAGe880091c1 [2022-07-19 17:24:55,642 INFO L306 CDTParser]: Found 1 translation units. [2022-07-19 17:24:55,643 INFO L160 CDTParser]: Scanning /storage/repos/ultimate/releaseScripts/default/sv-benchmarks/c/product-lines/minepump_spec4_product03.cil.c [2022-07-19 17:24:55,660 INFO L349 CDTParser]: About to delete temporary CDT project at /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/data/f4e2b7fcd/1e0bac0eeb0c4a54920fde961d228d9b/FLAGe880091c1 [2022-07-19 17:24:56,132 INFO L357 CDTParser]: Successfully deleted /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/data/f4e2b7fcd/1e0bac0eeb0c4a54920fde961d228d9b [2022-07-19 17:24:56,134 INFO L299 ainManager$Toolchain]: ####################### [Toolchain 1] ####################### [2022-07-19 17:24:56,136 INFO L131 ToolchainWalker]: Walking toolchain with 6 elements. [2022-07-19 17:24:56,137 INFO L113 PluginConnector]: ------------------------CACSL2BoogieTranslator---------------------------- [2022-07-19 17:24:56,137 INFO L271 PluginConnector]: Initializing CACSL2BoogieTranslator... [2022-07-19 17:24:56,140 INFO L275 PluginConnector]: CACSL2BoogieTranslator initialized [2022-07-19 17:24:56,140 INFO L185 PluginConnector]: Executing the observer ACSLObjectContainerObserver from plugin CACSL2BoogieTranslator for "CDTParser AST 19.07 05:24:56" (1/1) ... [2022-07-19 17:24:56,141 INFO L205 PluginConnector]: Invalid model from CACSL2BoogieTranslator for observer de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator.ACSLObjectContainerObserver@3bb88e8f and model type de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 19.07 05:24:56, skipping insertion in model container [2022-07-19 17:24:56,141 INFO L185 PluginConnector]: Executing the observer CACSL2BoogieTranslatorObserver from plugin CACSL2BoogieTranslator for "CDTParser AST 19.07 05:24:56" (1/1) ... [2022-07-19 17:24:56,150 INFO L145 MainTranslator]: Starting translation in SV-COMP mode [2022-07-19 17:24:56,183 INFO L178 MainTranslator]: Built tables and reachable declarations [2022-07-19 17:24:56,314 WARN L230 ndardFunctionHandler]: Function reach_error is already implemented but we override the implementation for the call at /storage/repos/ultimate/releaseScripts/default/sv-benchmarks/c/product-lines/minepump_spec4_product03.cil.c[1605,1618] [2022-07-19 17:24:56,401 INFO L210 PostProcessor]: Analyzing one entry point: main [2022-07-19 17:24:56,409 INFO L203 MainTranslator]: Completed pre-run [2022-07-19 17:24:56,421 WARN L230 ndardFunctionHandler]: Function reach_error is already implemented but we override the implementation for the call at /storage/repos/ultimate/releaseScripts/default/sv-benchmarks/c/product-lines/minepump_spec4_product03.cil.c[1605,1618] [2022-07-19 17:24:56,464 INFO L210 PostProcessor]: Analyzing one entry point: main [2022-07-19 17:24:56,478 INFO L208 MainTranslator]: Completed translation [2022-07-19 17:24:56,479 INFO L202 PluginConnector]: Adding new model de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 19.07 05:24:56 WrapperNode [2022-07-19 17:24:56,479 INFO L132 PluginConnector]: ------------------------ END CACSL2BoogieTranslator---------------------------- [2022-07-19 17:24:56,480 INFO L113 PluginConnector]: ------------------------Boogie Procedure Inliner---------------------------- [2022-07-19 17:24:56,480 INFO L271 PluginConnector]: Initializing Boogie Procedure Inliner... [2022-07-19 17:24:56,481 INFO L275 PluginConnector]: Boogie Procedure Inliner initialized [2022-07-19 17:24:56,487 INFO L185 PluginConnector]: Executing the observer TypeChecker from plugin Boogie Procedure Inliner for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 19.07 05:24:56" (1/1) ... [2022-07-19 17:24:56,499 INFO L185 PluginConnector]: Executing the observer Inliner from plugin Boogie Procedure Inliner for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 19.07 05:24:56" (1/1) ... [2022-07-19 17:24:56,520 INFO L137 Inliner]: procedures = 50, calls = 146, calls flagged for inlining = 20, calls inlined = 16, statements flattened = 193 [2022-07-19 17:24:56,521 INFO L132 PluginConnector]: ------------------------ END Boogie Procedure Inliner---------------------------- [2022-07-19 17:24:56,522 INFO L113 PluginConnector]: ------------------------Boogie Preprocessor---------------------------- [2022-07-19 17:24:56,522 INFO L271 PluginConnector]: Initializing Boogie Preprocessor... [2022-07-19 17:24:56,522 INFO L275 PluginConnector]: Boogie Preprocessor initialized [2022-07-19 17:24:56,529 INFO L185 PluginConnector]: Executing the observer EnsureBoogieModelObserver from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 19.07 05:24:56" (1/1) ... [2022-07-19 17:24:56,529 INFO L185 PluginConnector]: Executing the observer TypeChecker from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 19.07 05:24:56" (1/1) ... [2022-07-19 17:24:56,531 INFO L185 PluginConnector]: Executing the observer ConstExpander from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 19.07 05:24:56" (1/1) ... [2022-07-19 17:24:56,532 INFO L185 PluginConnector]: Executing the observer StructExpander from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 19.07 05:24:56" (1/1) ... [2022-07-19 17:24:56,535 INFO L185 PluginConnector]: Executing the observer UnstructureCode from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 19.07 05:24:56" (1/1) ... [2022-07-19 17:24:56,539 INFO L185 PluginConnector]: Executing the observer FunctionInliner from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 19.07 05:24:56" (1/1) ... [2022-07-19 17:24:56,540 INFO L185 PluginConnector]: Executing the observer BoogieSymbolTableConstructor from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 19.07 05:24:56" (1/1) ... [2022-07-19 17:24:56,542 INFO L132 PluginConnector]: ------------------------ END Boogie Preprocessor---------------------------- [2022-07-19 17:24:56,543 INFO L113 PluginConnector]: ------------------------RCFGBuilder---------------------------- [2022-07-19 17:24:56,543 INFO L271 PluginConnector]: Initializing RCFGBuilder... [2022-07-19 17:24:56,544 INFO L275 PluginConnector]: RCFGBuilder initialized [2022-07-19 17:24:56,544 INFO L185 PluginConnector]: Executing the observer RCFGBuilderObserver from plugin RCFGBuilder for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 19.07 05:24:56" (1/1) ... [2022-07-19 17:24:56,551 INFO L173 SolverBuilder]: Constructing external solver with command: z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in -t:2000 [2022-07-19 17:24:56,561 INFO L189 MonitoredProcess]: No working directory specified, using /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 [2022-07-19 17:24:56,573 INFO L229 MonitoredProcess]: Starting monitored process 1 with /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in -t:2000 (exit command is (exit), workingDir is null) [2022-07-19 17:24:56,605 INFO L327 MonitoredProcess]: [MP /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in -t:2000 (1)] Waiting until timeout for monitored process [2022-07-19 17:24:56,620 INFO L130 BoogieDeclarations]: Found specification of procedure #Ultimate.allocInit [2022-07-19 17:24:56,620 INFO L130 BoogieDeclarations]: Found specification of procedure cleanup [2022-07-19 17:24:56,620 INFO L138 BoogieDeclarations]: Found implementation of procedure cleanup [2022-07-19 17:24:56,620 INFO L130 BoogieDeclarations]: Found specification of procedure timeShift [2022-07-19 17:24:56,621 INFO L138 BoogieDeclarations]: Found implementation of procedure timeShift [2022-07-19 17:24:56,621 INFO L130 BoogieDeclarations]: Found specification of procedure waterRise [2022-07-19 17:24:56,621 INFO L138 BoogieDeclarations]: Found implementation of procedure waterRise [2022-07-19 17:24:56,622 INFO L130 BoogieDeclarations]: Found specification of procedure write~init~int [2022-07-19 17:24:56,623 INFO L130 BoogieDeclarations]: Found specification of procedure changeMethaneLevel [2022-07-19 17:24:56,623 INFO L138 BoogieDeclarations]: Found implementation of procedure changeMethaneLevel [2022-07-19 17:24:56,623 INFO L130 BoogieDeclarations]: Found specification of procedure ULTIMATE.start [2022-07-19 17:24:56,623 INFO L138 BoogieDeclarations]: Found implementation of procedure ULTIMATE.start [2022-07-19 17:24:56,697 INFO L234 CfgBuilder]: Building ICFG [2022-07-19 17:24:56,699 INFO L260 CfgBuilder]: Building CFG for each procedure with an implementation [2022-07-19 17:24:56,954 INFO L275 CfgBuilder]: Performing block encoding [2022-07-19 17:24:56,960 INFO L294 CfgBuilder]: Using the 1 location(s) as analysis (start of procedure ULTIMATE.start) [2022-07-19 17:24:56,961 INFO L299 CfgBuilder]: Removed 2 assume(true) statements. [2022-07-19 17:24:56,963 INFO L202 PluginConnector]: Adding new model de.uni_freiburg.informatik.ultimate.plugins.generator.rcfgbuilder CFG 19.07 05:24:56 BoogieIcfgContainer [2022-07-19 17:24:56,963 INFO L132 PluginConnector]: ------------------------ END RCFGBuilder---------------------------- [2022-07-19 17:24:56,964 INFO L113 PluginConnector]: ------------------------TraceAbstraction---------------------------- [2022-07-19 17:24:56,965 INFO L271 PluginConnector]: Initializing TraceAbstraction... [2022-07-19 17:24:56,967 INFO L275 PluginConnector]: TraceAbstraction initialized [2022-07-19 17:24:56,968 INFO L185 PluginConnector]: Executing the observer TraceAbstractionObserver from plugin TraceAbstraction for "CDTParser AST 19.07 05:24:56" (1/3) ... [2022-07-19 17:24:56,968 INFO L205 PluginConnector]: Invalid model from TraceAbstraction for observer de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction.TraceAbstractionObserver@45c378fd and model type de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction AST 19.07 05:24:56, skipping insertion in model container [2022-07-19 17:24:56,968 INFO L185 PluginConnector]: Executing the observer TraceAbstractionObserver from plugin TraceAbstraction for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 19.07 05:24:56" (2/3) ... [2022-07-19 17:24:56,969 INFO L205 PluginConnector]: Invalid model from TraceAbstraction for observer de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction.TraceAbstractionObserver@45c378fd and model type de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction AST 19.07 05:24:56, skipping insertion in model container [2022-07-19 17:24:56,969 INFO L185 PluginConnector]: Executing the observer TraceAbstractionObserver from plugin TraceAbstraction for "de.uni_freiburg.informatik.ultimate.plugins.generator.rcfgbuilder CFG 19.07 05:24:56" (3/3) ... [2022-07-19 17:24:56,970 INFO L111 eAbstractionObserver]: Analyzing ICFG minepump_spec4_product03.cil.c [2022-07-19 17:24:56,982 INFO L201 ceAbstractionStarter]: Automizer settings: Hoare:true NWA Interpolation:FPandBP Determinization: PREDICATE_ABSTRACTION [2022-07-19 17:24:56,982 INFO L160 ceAbstractionStarter]: Applying trace abstraction to program that has 1 error locations. [2022-07-19 17:24:57,040 INFO L356 AbstractCegarLoop]: ======== Iteration 0 == of CEGAR loop == AllErrorsAtOnce ======== [2022-07-19 17:24:57,047 INFO L357 AbstractCegarLoop]: Settings: SEPARATE_VIOLATION_CHECK=true, mInterprocedural=true, mMaxIterations=1000000, mWatchIteration=1000000, mArtifact=RCFG, mInterpolation=FPandBP, mInterpolantAutomaton=STRAIGHT_LINE, mDumpAutomata=false, mAutomataFormat=ATS_NUMERATE, mDumpPath=., mDeterminiation=PREDICATE_ABSTRACTION, mMinimize=MINIMIZE_SEVPA, mHoare=true, mAutomataTypeConcurrency=PETRI_NET, mHoareTripleChecks=INCREMENTAL, mHoareAnnotationPositions=LoopsAndPotentialCycles, mDumpOnlyReuseAutomata=false, mLimitTraceHistogram=0, mErrorLocTimeLimit=0, mLimitPathProgramCount=0, mCollectInterpolantStatistics=true, mHeuristicEmptinessCheck=false, mHeuristicEmptinessCheckAStarHeuristic=ZERO, mHeuristicEmptinessCheckAStarHeuristicRandomSeed=1337, mHeuristicEmptinessCheckSmtFeatureScoringMethod=DAGSIZE, mSMTFeatureExtraction=false, mSMTFeatureExtractionDumpPath=., mOverrideInterpolantAutomaton=false, mMcrInterpolantMethod=WP, mPorIndependenceSettings=de.uni_freiburg.informatik.ultimate.lib.tracecheckerutils.partialorder.independence.IndependenceSettings@349178cd, mLbeIndependenceSettings=de.uni_freiburg.informatik.ultimate.lib.tracecheckerutils.partialorder.independence.IndependenceSettings@6d03e8e2 [2022-07-19 17:24:57,047 INFO L358 AbstractCegarLoop]: Starting to check reachability of 1 error locations. [2022-07-19 17:24:57,056 INFO L276 IsEmpty]: Start isEmpty. Operand has 62 states, 50 states have (on average 1.4) internal successors, (70), 54 states have internal predecessors, (70), 6 states have call successors, (6), 4 states have call predecessors, (6), 4 states have return successors, (6), 6 states have call predecessors, (6), 6 states have call successors, (6) [2022-07-19 17:24:57,069 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 20 [2022-07-19 17:24:57,073 INFO L187 NwaCegarLoop]: Found error trace [2022-07-19 17:24:57,074 INFO L195 NwaCegarLoop]: trace histogram [1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-07-19 17:24:57,075 INFO L420 AbstractCegarLoop]: === Iteration 1 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2022-07-19 17:24:57,080 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2022-07-19 17:24:57,080 INFO L85 PathProgramCache]: Analyzing trace with hash -192528358, now seen corresponding path program 1 times [2022-07-19 17:24:57,097 INFO L118 FreeRefinementEngine]: Executing refinement strategy CAMEL [2022-07-19 17:24:57,098 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [1863766077] [2022-07-19 17:24:57,098 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-07-19 17:24:57,099 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2022-07-19 17:24:57,247 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-07-19 17:24:57,324 INFO L134 CoverageAnalysis]: Checked inductivity of 0 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2022-07-19 17:24:57,326 INFO L136 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2022-07-19 17:24:57,326 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [1863766077] [2022-07-19 17:24:57,327 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [1863766077] provided 1 perfect and 0 imperfect interpolant sequences [2022-07-19 17:24:57,327 INFO L184 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2022-07-19 17:24:57,328 INFO L197 FreeRefinementEngine]: Number of different interpolants: perfect sequences [2] imperfect sequences [] total 2 [2022-07-19 17:24:57,329 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [1089125156] [2022-07-19 17:24:57,329 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2022-07-19 17:24:57,333 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 2 states [2022-07-19 17:24:57,335 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2022-07-19 17:24:57,361 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 2 interpolants. [2022-07-19 17:24:57,363 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=1, Invalid=1, Unknown=0, NotChecked=0, Total=2 [2022-07-19 17:24:57,366 INFO L87 Difference]: Start difference. First operand has 62 states, 50 states have (on average 1.4) internal successors, (70), 54 states have internal predecessors, (70), 6 states have call successors, (6), 4 states have call predecessors, (6), 4 states have return successors, (6), 6 states have call predecessors, (6), 6 states have call successors, (6) Second operand has 2 states, 2 states have (on average 8.5) internal successors, (17), 2 states have internal predecessors, (17), 1 states have call successors, (2), 1 states have call predecessors, (2), 0 states have return successors, (0), 0 states have call predecessors, (0), 0 states have call successors, (0) [2022-07-19 17:24:57,399 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-07-19 17:24:57,400 INFO L93 Difference]: Finished difference Result 116 states and 159 transitions. [2022-07-19 17:24:57,401 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 2 states. [2022-07-19 17:24:57,402 INFO L78 Accepts]: Start accepts. Automaton has has 2 states, 2 states have (on average 8.5) internal successors, (17), 2 states have internal predecessors, (17), 1 states have call successors, (2), 1 states have call predecessors, (2), 0 states have return successors, (0), 0 states have call predecessors, (0), 0 states have call successors, (0) Word has length 19 [2022-07-19 17:24:57,403 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2022-07-19 17:24:57,410 INFO L225 Difference]: With dead ends: 116 [2022-07-19 17:24:57,410 INFO L226 Difference]: Without dead ends: 53 [2022-07-19 17:24:57,418 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 2 GetRequests, 2 SyntacticMatches, 0 SemanticMatches, 0 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 0 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=1, Invalid=1, Unknown=0, NotChecked=0, Total=2 [2022-07-19 17:24:57,422 INFO L413 NwaCegarLoop]: 76 mSDtfsCounter, 0 mSDsluCounter, 0 mSDsCounter, 0 mSdLazyCounter, 0 mSolverCounterSat, 0 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.0s Time, 0 mProtectedPredicate, 0 mProtectedAction, 0 SdHoareTripleChecker+Valid, 76 SdHoareTripleChecker+Invalid, 0 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 0 IncrementalHoareTripleChecker+Valid, 0 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.0s IncrementalHoareTripleChecker+Time [2022-07-19 17:24:57,423 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [0 Valid, 76 Invalid, 0 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [0 Valid, 0 Invalid, 0 Unknown, 0 Unchecked, 0.0s Time] [2022-07-19 17:24:57,437 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 53 states. [2022-07-19 17:24:57,460 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 53 to 53. [2022-07-19 17:24:57,461 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 53 states, 43 states have (on average 1.302325581395349) internal successors, (56), 46 states have internal predecessors, (56), 6 states have call successors, (6), 4 states have call predecessors, (6), 3 states have return successors, (5), 5 states have call predecessors, (5), 5 states have call successors, (5) [2022-07-19 17:24:57,464 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 53 states to 53 states and 67 transitions. [2022-07-19 17:24:57,466 INFO L78 Accepts]: Start accepts. Automaton has 53 states and 67 transitions. Word has length 19 [2022-07-19 17:24:57,466 INFO L84 Accepts]: Finished accepts. word is rejected. [2022-07-19 17:24:57,466 INFO L495 AbstractCegarLoop]: Abstraction has 53 states and 67 transitions. [2022-07-19 17:24:57,467 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 2 states, 2 states have (on average 8.5) internal successors, (17), 2 states have internal predecessors, (17), 1 states have call successors, (2), 1 states have call predecessors, (2), 0 states have return successors, (0), 0 states have call predecessors, (0), 0 states have call successors, (0) [2022-07-19 17:24:57,467 INFO L276 IsEmpty]: Start isEmpty. Operand 53 states and 67 transitions. [2022-07-19 17:24:57,469 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 21 [2022-07-19 17:24:57,469 INFO L187 NwaCegarLoop]: Found error trace [2022-07-19 17:24:57,470 INFO L195 NwaCegarLoop]: trace histogram [1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-07-19 17:24:57,470 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable0 [2022-07-19 17:24:57,471 INFO L420 AbstractCegarLoop]: === Iteration 2 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2022-07-19 17:24:57,471 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2022-07-19 17:24:57,471 INFO L85 PathProgramCache]: Analyzing trace with hash 1987482606, now seen corresponding path program 1 times [2022-07-19 17:24:57,472 INFO L118 FreeRefinementEngine]: Executing refinement strategy CAMEL [2022-07-19 17:24:57,472 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [59996337] [2022-07-19 17:24:57,472 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-07-19 17:24:57,473 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2022-07-19 17:24:57,511 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-07-19 17:24:57,568 INFO L134 CoverageAnalysis]: Checked inductivity of 0 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2022-07-19 17:24:57,569 INFO L136 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2022-07-19 17:24:57,570 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [59996337] [2022-07-19 17:24:57,571 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [59996337] provided 1 perfect and 0 imperfect interpolant sequences [2022-07-19 17:24:57,571 INFO L184 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2022-07-19 17:24:57,571 INFO L197 FreeRefinementEngine]: Number of different interpolants: perfect sequences [3] imperfect sequences [] total 3 [2022-07-19 17:24:57,572 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [1681424645] [2022-07-19 17:24:57,572 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2022-07-19 17:24:57,573 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 3 states [2022-07-19 17:24:57,573 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2022-07-19 17:24:57,574 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 3 interpolants. [2022-07-19 17:24:57,575 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=3, Invalid=3, Unknown=0, NotChecked=0, Total=6 [2022-07-19 17:24:57,575 INFO L87 Difference]: Start difference. First operand 53 states and 67 transitions. Second operand has 3 states, 3 states have (on average 6.0) internal successors, (18), 3 states have internal predecessors, (18), 1 states have call successors, (2), 1 states have call predecessors, (2), 0 states have return successors, (0), 0 states have call predecessors, (0), 0 states have call successors, (0) [2022-07-19 17:24:57,593 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-07-19 17:24:57,593 INFO L93 Difference]: Finished difference Result 68 states and 85 transitions. [2022-07-19 17:24:57,594 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 3 states. [2022-07-19 17:24:57,594 INFO L78 Accepts]: Start accepts. Automaton has has 3 states, 3 states have (on average 6.0) internal successors, (18), 3 states have internal predecessors, (18), 1 states have call successors, (2), 1 states have call predecessors, (2), 0 states have return successors, (0), 0 states have call predecessors, (0), 0 states have call successors, (0) Word has length 20 [2022-07-19 17:24:57,595 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2022-07-19 17:24:57,596 INFO L225 Difference]: With dead ends: 68 [2022-07-19 17:24:57,596 INFO L226 Difference]: Without dead ends: 44 [2022-07-19 17:24:57,600 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 3 GetRequests, 2 SyntacticMatches, 0 SemanticMatches, 1 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 0 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=3, Invalid=3, Unknown=0, NotChecked=0, Total=6 [2022-07-19 17:24:57,602 INFO L413 NwaCegarLoop]: 54 mSDtfsCounter, 17 mSDsluCounter, 33 mSDsCounter, 0 mSdLazyCounter, 1 mSolverCounterSat, 0 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.0s Time, 0 mProtectedPredicate, 0 mProtectedAction, 20 SdHoareTripleChecker+Valid, 87 SdHoareTripleChecker+Invalid, 1 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 0 IncrementalHoareTripleChecker+Valid, 1 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.0s IncrementalHoareTripleChecker+Time [2022-07-19 17:24:57,603 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [20 Valid, 87 Invalid, 1 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [0 Valid, 1 Invalid, 0 Unknown, 0 Unchecked, 0.0s Time] [2022-07-19 17:24:57,606 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 44 states. [2022-07-19 17:24:57,613 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 44 to 44. [2022-07-19 17:24:57,614 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 44 states, 37 states have (on average 1.3243243243243243) internal successors, (49), 40 states have internal predecessors, (49), 3 states have call successors, (3), 3 states have call predecessors, (3), 3 states have return successors, (3), 3 states have call predecessors, (3), 3 states have call successors, (3) [2022-07-19 17:24:57,616 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 44 states to 44 states and 55 transitions. [2022-07-19 17:24:57,617 INFO L78 Accepts]: Start accepts. Automaton has 44 states and 55 transitions. Word has length 20 [2022-07-19 17:24:57,617 INFO L84 Accepts]: Finished accepts. word is rejected. [2022-07-19 17:24:57,618 INFO L495 AbstractCegarLoop]: Abstraction has 44 states and 55 transitions. [2022-07-19 17:24:57,619 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 3 states, 3 states have (on average 6.0) internal successors, (18), 3 states have internal predecessors, (18), 1 states have call successors, (2), 1 states have call predecessors, (2), 0 states have return successors, (0), 0 states have call predecessors, (0), 0 states have call successors, (0) [2022-07-19 17:24:57,619 INFO L276 IsEmpty]: Start isEmpty. Operand 44 states and 55 transitions. [2022-07-19 17:24:57,620 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 25 [2022-07-19 17:24:57,620 INFO L187 NwaCegarLoop]: Found error trace [2022-07-19 17:24:57,621 INFO L195 NwaCegarLoop]: trace histogram [1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-07-19 17:24:57,621 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable1 [2022-07-19 17:24:57,624 INFO L420 AbstractCegarLoop]: === Iteration 3 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2022-07-19 17:24:57,624 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2022-07-19 17:24:57,625 INFO L85 PathProgramCache]: Analyzing trace with hash -296029766, now seen corresponding path program 1 times [2022-07-19 17:24:57,625 INFO L118 FreeRefinementEngine]: Executing refinement strategy CAMEL [2022-07-19 17:24:57,625 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [119555376] [2022-07-19 17:24:57,625 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-07-19 17:24:57,626 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2022-07-19 17:24:57,644 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-07-19 17:24:57,679 INFO L134 CoverageAnalysis]: Checked inductivity of 0 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2022-07-19 17:24:57,679 INFO L136 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2022-07-19 17:24:57,680 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [119555376] [2022-07-19 17:24:57,680 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [119555376] provided 1 perfect and 0 imperfect interpolant sequences [2022-07-19 17:24:57,680 INFO L184 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2022-07-19 17:24:57,680 INFO L197 FreeRefinementEngine]: Number of different interpolants: perfect sequences [2] imperfect sequences [] total 2 [2022-07-19 17:24:57,680 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [152688523] [2022-07-19 17:24:57,680 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2022-07-19 17:24:57,681 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 3 states [2022-07-19 17:24:57,681 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2022-07-19 17:24:57,681 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 3 interpolants. [2022-07-19 17:24:57,682 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=3, Invalid=3, Unknown=0, NotChecked=0, Total=6 [2022-07-19 17:24:57,682 INFO L87 Difference]: Start difference. First operand 44 states and 55 transitions. Second operand has 3 states, 3 states have (on average 7.666666666666667) internal successors, (23), 2 states have internal predecessors, (23), 1 states have call successors, (1), 1 states have call predecessors, (1), 0 states have return successors, (0), 0 states have call predecessors, (0), 0 states have call successors, (0) [2022-07-19 17:24:57,703 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-07-19 17:24:57,703 INFO L93 Difference]: Finished difference Result 117 states and 151 transitions. [2022-07-19 17:24:57,704 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 3 states. [2022-07-19 17:24:57,704 INFO L78 Accepts]: Start accepts. Automaton has has 3 states, 3 states have (on average 7.666666666666667) internal successors, (23), 2 states have internal predecessors, (23), 1 states have call successors, (1), 1 states have call predecessors, (1), 0 states have return successors, (0), 0 states have call predecessors, (0), 0 states have call successors, (0) Word has length 24 [2022-07-19 17:24:57,704 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2022-07-19 17:24:57,705 INFO L225 Difference]: With dead ends: 117 [2022-07-19 17:24:57,705 INFO L226 Difference]: Without dead ends: 80 [2022-07-19 17:24:57,706 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 2 GetRequests, 1 SyntacticMatches, 0 SemanticMatches, 1 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 0 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=3, Invalid=3, Unknown=0, NotChecked=0, Total=6 [2022-07-19 17:24:57,707 INFO L413 NwaCegarLoop]: 57 mSDtfsCounter, 35 mSDsluCounter, 45 mSDsCounter, 0 mSdLazyCounter, 4 mSolverCounterSat, 0 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.0s Time, 0 mProtectedPredicate, 0 mProtectedAction, 35 SdHoareTripleChecker+Valid, 102 SdHoareTripleChecker+Invalid, 4 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 0 IncrementalHoareTripleChecker+Valid, 4 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.0s IncrementalHoareTripleChecker+Time [2022-07-19 17:24:57,708 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [35 Valid, 102 Invalid, 4 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [0 Valid, 4 Invalid, 0 Unknown, 0 Unchecked, 0.0s Time] [2022-07-19 17:24:57,708 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 80 states. [2022-07-19 17:24:57,716 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 80 to 75. [2022-07-19 17:24:57,717 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 75 states, 62 states have (on average 1.3548387096774193) internal successors, (84), 67 states have internal predecessors, (84), 6 states have call successors, (6), 6 states have call predecessors, (6), 6 states have return successors, (6), 6 states have call predecessors, (6), 6 states have call successors, (6) [2022-07-19 17:24:57,718 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 75 states to 75 states and 96 transitions. [2022-07-19 17:24:57,718 INFO L78 Accepts]: Start accepts. Automaton has 75 states and 96 transitions. Word has length 24 [2022-07-19 17:24:57,718 INFO L84 Accepts]: Finished accepts. word is rejected. [2022-07-19 17:24:57,719 INFO L495 AbstractCegarLoop]: Abstraction has 75 states and 96 transitions. [2022-07-19 17:24:57,719 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 3 states, 3 states have (on average 7.666666666666667) internal successors, (23), 2 states have internal predecessors, (23), 1 states have call successors, (1), 1 states have call predecessors, (1), 0 states have return successors, (0), 0 states have call predecessors, (0), 0 states have call successors, (0) [2022-07-19 17:24:57,719 INFO L276 IsEmpty]: Start isEmpty. Operand 75 states and 96 transitions. [2022-07-19 17:24:57,720 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 26 [2022-07-19 17:24:57,720 INFO L187 NwaCegarLoop]: Found error trace [2022-07-19 17:24:57,720 INFO L195 NwaCegarLoop]: trace histogram [1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-07-19 17:24:57,720 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable2 [2022-07-19 17:24:57,721 INFO L420 AbstractCegarLoop]: === Iteration 4 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2022-07-19 17:24:57,721 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2022-07-19 17:24:57,722 INFO L85 PathProgramCache]: Analyzing trace with hash 1716566345, now seen corresponding path program 1 times [2022-07-19 17:24:57,722 INFO L118 FreeRefinementEngine]: Executing refinement strategy CAMEL [2022-07-19 17:24:57,722 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [212545895] [2022-07-19 17:24:57,722 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-07-19 17:24:57,723 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2022-07-19 17:24:57,748 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-07-19 17:24:57,796 INFO L134 CoverageAnalysis]: Checked inductivity of 0 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2022-07-19 17:24:57,796 INFO L136 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2022-07-19 17:24:57,796 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [212545895] [2022-07-19 17:24:57,797 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [212545895] provided 1 perfect and 0 imperfect interpolant sequences [2022-07-19 17:24:57,797 INFO L184 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2022-07-19 17:24:57,797 INFO L197 FreeRefinementEngine]: Number of different interpolants: perfect sequences [5] imperfect sequences [] total 5 [2022-07-19 17:24:57,797 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [1988401879] [2022-07-19 17:24:57,797 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2022-07-19 17:24:57,798 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 6 states [2022-07-19 17:24:57,798 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2022-07-19 17:24:57,798 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 6 interpolants. [2022-07-19 17:24:57,799 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=9, Invalid=21, Unknown=0, NotChecked=0, Total=30 [2022-07-19 17:24:57,799 INFO L87 Difference]: Start difference. First operand 75 states and 96 transitions. Second operand has 6 states, 6 states have (on average 4.0) internal successors, (24), 5 states have internal predecessors, (24), 1 states have call successors, (1), 1 states have call predecessors, (1), 0 states have return successors, (0), 0 states have call predecessors, (0), 0 states have call successors, (0) [2022-07-19 17:24:57,910 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-07-19 17:24:57,910 INFO L93 Difference]: Finished difference Result 243 states and 329 transitions. [2022-07-19 17:24:57,911 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 9 states. [2022-07-19 17:24:57,911 INFO L78 Accepts]: Start accepts. Automaton has has 6 states, 6 states have (on average 4.0) internal successors, (24), 5 states have internal predecessors, (24), 1 states have call successors, (1), 1 states have call predecessors, (1), 0 states have return successors, (0), 0 states have call predecessors, (0), 0 states have call successors, (0) Word has length 25 [2022-07-19 17:24:57,911 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2022-07-19 17:24:57,914 INFO L225 Difference]: With dead ends: 243 [2022-07-19 17:24:57,915 INFO L226 Difference]: Without dead ends: 175 [2022-07-19 17:24:57,916 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 11 GetRequests, 2 SyntacticMatches, 0 SemanticMatches, 9 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 7 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=40, Invalid=70, Unknown=0, NotChecked=0, Total=110 [2022-07-19 17:24:57,917 INFO L413 NwaCegarLoop]: 57 mSDtfsCounter, 112 mSDsluCounter, 227 mSDsCounter, 0 mSdLazyCounter, 50 mSolverCounterSat, 15 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.0s Time, 0 mProtectedPredicate, 0 mProtectedAction, 112 SdHoareTripleChecker+Valid, 284 SdHoareTripleChecker+Invalid, 65 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 15 IncrementalHoareTripleChecker+Valid, 50 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.1s IncrementalHoareTripleChecker+Time [2022-07-19 17:24:57,917 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [112 Valid, 284 Invalid, 65 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [15 Valid, 50 Invalid, 0 Unknown, 0 Unchecked, 0.1s Time] [2022-07-19 17:24:57,918 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 175 states. [2022-07-19 17:24:57,933 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 175 to 133. [2022-07-19 17:24:57,934 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 133 states, 110 states have (on average 1.3454545454545455) internal successors, (148), 119 states have internal predecessors, (148), 10 states have call successors, (10), 10 states have call predecessors, (10), 12 states have return successors, (14), 12 states have call predecessors, (14), 10 states have call successors, (14) [2022-07-19 17:24:57,935 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 133 states to 133 states and 172 transitions. [2022-07-19 17:24:57,935 INFO L78 Accepts]: Start accepts. Automaton has 133 states and 172 transitions. Word has length 25 [2022-07-19 17:24:57,935 INFO L84 Accepts]: Finished accepts. word is rejected. [2022-07-19 17:24:57,935 INFO L495 AbstractCegarLoop]: Abstraction has 133 states and 172 transitions. [2022-07-19 17:24:57,936 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 6 states, 6 states have (on average 4.0) internal successors, (24), 5 states have internal predecessors, (24), 1 states have call successors, (1), 1 states have call predecessors, (1), 0 states have return successors, (0), 0 states have call predecessors, (0), 0 states have call successors, (0) [2022-07-19 17:24:57,936 INFO L276 IsEmpty]: Start isEmpty. Operand 133 states and 172 transitions. [2022-07-19 17:24:57,937 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 28 [2022-07-19 17:24:57,937 INFO L187 NwaCegarLoop]: Found error trace [2022-07-19 17:24:57,937 INFO L195 NwaCegarLoop]: trace histogram [1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-07-19 17:24:57,937 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable3 [2022-07-19 17:24:57,938 INFO L420 AbstractCegarLoop]: === Iteration 5 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2022-07-19 17:24:57,938 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2022-07-19 17:24:57,938 INFO L85 PathProgramCache]: Analyzing trace with hash 1833945412, now seen corresponding path program 1 times [2022-07-19 17:24:57,939 INFO L118 FreeRefinementEngine]: Executing refinement strategy CAMEL [2022-07-19 17:24:57,939 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [2064139293] [2022-07-19 17:24:57,939 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-07-19 17:24:57,939 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2022-07-19 17:24:57,953 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-07-19 17:24:57,971 INFO L134 CoverageAnalysis]: Checked inductivity of 0 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2022-07-19 17:24:57,971 INFO L136 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2022-07-19 17:24:57,972 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [2064139293] [2022-07-19 17:24:57,972 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [2064139293] provided 1 perfect and 0 imperfect interpolant sequences [2022-07-19 17:24:57,972 INFO L184 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2022-07-19 17:24:57,972 INFO L197 FreeRefinementEngine]: Number of different interpolants: perfect sequences [2] imperfect sequences [] total 2 [2022-07-19 17:24:57,972 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [686046820] [2022-07-19 17:24:57,973 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2022-07-19 17:24:57,973 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 3 states [2022-07-19 17:24:57,973 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2022-07-19 17:24:57,974 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 3 interpolants. [2022-07-19 17:24:57,974 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=3, Invalid=3, Unknown=0, NotChecked=0, Total=6 [2022-07-19 17:24:57,974 INFO L87 Difference]: Start difference. First operand 133 states and 172 transitions. Second operand has 3 states, 3 states have (on average 8.666666666666666) internal successors, (26), 2 states have internal predecessors, (26), 1 states have call successors, (1), 1 states have call predecessors, (1), 0 states have return successors, (0), 0 states have call predecessors, (0), 0 states have call successors, (0) [2022-07-19 17:24:57,989 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-07-19 17:24:57,991 INFO L93 Difference]: Finished difference Result 249 states and 327 transitions. [2022-07-19 17:24:57,991 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 3 states. [2022-07-19 17:24:57,992 INFO L78 Accepts]: Start accepts. Automaton has has 3 states, 3 states have (on average 8.666666666666666) internal successors, (26), 2 states have internal predecessors, (26), 1 states have call successors, (1), 1 states have call predecessors, (1), 0 states have return successors, (0), 0 states have call predecessors, (0), 0 states have call successors, (0) Word has length 27 [2022-07-19 17:24:57,992 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2022-07-19 17:24:57,993 INFO L225 Difference]: With dead ends: 249 [2022-07-19 17:24:57,993 INFO L226 Difference]: Without dead ends: 123 [2022-07-19 17:24:57,994 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 2 GetRequests, 1 SyntacticMatches, 0 SemanticMatches, 1 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 0 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=3, Invalid=3, Unknown=0, NotChecked=0, Total=6 [2022-07-19 17:24:57,995 INFO L413 NwaCegarLoop]: 46 mSDtfsCounter, 33 mSDsluCounter, 0 mSDsCounter, 0 mSdLazyCounter, 3 mSolverCounterSat, 1 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.0s Time, 0 mProtectedPredicate, 0 mProtectedAction, 33 SdHoareTripleChecker+Valid, 46 SdHoareTripleChecker+Invalid, 4 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 1 IncrementalHoareTripleChecker+Valid, 3 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.0s IncrementalHoareTripleChecker+Time [2022-07-19 17:24:57,996 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [33 Valid, 46 Invalid, 4 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [1 Valid, 3 Invalid, 0 Unknown, 0 Unchecked, 0.0s Time] [2022-07-19 17:24:57,996 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 123 states. [2022-07-19 17:24:58,006 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 123 to 123. [2022-07-19 17:24:58,007 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 123 states, 100 states have (on average 1.28) internal successors, (128), 109 states have internal predecessors, (128), 10 states have call successors, (10), 10 states have call predecessors, (10), 12 states have return successors, (12), 12 states have call predecessors, (12), 10 states have call successors, (12) [2022-07-19 17:24:58,008 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 123 states to 123 states and 150 transitions. [2022-07-19 17:24:58,008 INFO L78 Accepts]: Start accepts. Automaton has 123 states and 150 transitions. Word has length 27 [2022-07-19 17:24:58,009 INFO L84 Accepts]: Finished accepts. word is rejected. [2022-07-19 17:24:58,009 INFO L495 AbstractCegarLoop]: Abstraction has 123 states and 150 transitions. [2022-07-19 17:24:58,009 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 3 states, 3 states have (on average 8.666666666666666) internal successors, (26), 2 states have internal predecessors, (26), 1 states have call successors, (1), 1 states have call predecessors, (1), 0 states have return successors, (0), 0 states have call predecessors, (0), 0 states have call successors, (0) [2022-07-19 17:24:58,009 INFO L276 IsEmpty]: Start isEmpty. Operand 123 states and 150 transitions. [2022-07-19 17:24:58,010 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 30 [2022-07-19 17:24:58,010 INFO L187 NwaCegarLoop]: Found error trace [2022-07-19 17:24:58,011 INFO L195 NwaCegarLoop]: trace histogram [1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-07-19 17:24:58,011 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable4 [2022-07-19 17:24:58,011 INFO L420 AbstractCegarLoop]: === Iteration 6 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2022-07-19 17:24:58,011 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2022-07-19 17:24:58,012 INFO L85 PathProgramCache]: Analyzing trace with hash 957939555, now seen corresponding path program 1 times [2022-07-19 17:24:58,012 INFO L118 FreeRefinementEngine]: Executing refinement strategy CAMEL [2022-07-19 17:24:58,012 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [232757935] [2022-07-19 17:24:58,012 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-07-19 17:24:58,012 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2022-07-19 17:24:58,025 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-07-19 17:24:58,083 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 11 [2022-07-19 17:24:58,086 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-07-19 17:24:58,099 INFO L134 CoverageAnalysis]: Checked inductivity of 0 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2022-07-19 17:24:58,100 INFO L136 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2022-07-19 17:24:58,100 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [232757935] [2022-07-19 17:24:58,100 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [232757935] provided 1 perfect and 0 imperfect interpolant sequences [2022-07-19 17:24:58,100 INFO L184 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2022-07-19 17:24:58,101 INFO L197 FreeRefinementEngine]: Number of different interpolants: perfect sequences [7] imperfect sequences [] total 7 [2022-07-19 17:24:58,101 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [213897416] [2022-07-19 17:24:58,101 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2022-07-19 17:24:58,101 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 8 states [2022-07-19 17:24:58,102 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2022-07-19 17:24:58,102 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 8 interpolants. [2022-07-19 17:24:58,102 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=14, Invalid=42, Unknown=0, NotChecked=0, Total=56 [2022-07-19 17:24:58,103 INFO L87 Difference]: Start difference. First operand 123 states and 150 transitions. Second operand has 8 states, 8 states have (on average 3.25) internal successors, (26), 6 states have internal predecessors, (26), 2 states have call successors, (2), 2 states have call predecessors, (2), 1 states have return successors, (1), 1 states have call predecessors, (1), 1 states have call successors, (1) [2022-07-19 17:24:58,281 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-07-19 17:24:58,281 INFO L93 Difference]: Finished difference Result 355 states and 445 transitions. [2022-07-19 17:24:58,282 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 14 states. [2022-07-19 17:24:58,283 INFO L78 Accepts]: Start accepts. Automaton has has 8 states, 8 states have (on average 3.25) internal successors, (26), 6 states have internal predecessors, (26), 2 states have call successors, (2), 2 states have call predecessors, (2), 1 states have return successors, (1), 1 states have call predecessors, (1), 1 states have call successors, (1) Word has length 29 [2022-07-19 17:24:58,284 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2022-07-19 17:24:58,288 INFO L225 Difference]: With dead ends: 355 [2022-07-19 17:24:58,289 INFO L226 Difference]: Without dead ends: 239 [2022-07-19 17:24:58,290 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 16 GetRequests, 2 SyntacticMatches, 0 SemanticMatches, 14 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 27 ImplicationChecksByTransitivity, 0.1s TimeCoverageRelationStatistics Valid=69, Invalid=171, Unknown=0, NotChecked=0, Total=240 [2022-07-19 17:24:58,292 INFO L413 NwaCegarLoop]: 46 mSDtfsCounter, 142 mSDsluCounter, 198 mSDsCounter, 0 mSdLazyCounter, 103 mSolverCounterSat, 21 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.1s Time, 0 mProtectedPredicate, 0 mProtectedAction, 144 SdHoareTripleChecker+Valid, 244 SdHoareTripleChecker+Invalid, 124 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 21 IncrementalHoareTripleChecker+Valid, 103 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.1s IncrementalHoareTripleChecker+Time [2022-07-19 17:24:58,294 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [144 Valid, 244 Invalid, 124 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [21 Valid, 103 Invalid, 0 Unknown, 0 Unchecked, 0.1s Time] [2022-07-19 17:24:58,296 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 239 states. [2022-07-19 17:24:58,324 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 239 to 180. [2022-07-19 17:24:58,325 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 180 states, 145 states have (on average 1.2689655172413794) internal successors, (184), 158 states have internal predecessors, (184), 16 states have call successors, (16), 16 states have call predecessors, (16), 18 states have return successors, (18), 16 states have call predecessors, (18), 16 states have call successors, (18) [2022-07-19 17:24:58,329 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 180 states to 180 states and 218 transitions. [2022-07-19 17:24:58,329 INFO L78 Accepts]: Start accepts. Automaton has 180 states and 218 transitions. Word has length 29 [2022-07-19 17:24:58,329 INFO L84 Accepts]: Finished accepts. word is rejected. [2022-07-19 17:24:58,329 INFO L495 AbstractCegarLoop]: Abstraction has 180 states and 218 transitions. [2022-07-19 17:24:58,330 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 8 states, 8 states have (on average 3.25) internal successors, (26), 6 states have internal predecessors, (26), 2 states have call successors, (2), 2 states have call predecessors, (2), 1 states have return successors, (1), 1 states have call predecessors, (1), 1 states have call successors, (1) [2022-07-19 17:24:58,330 INFO L276 IsEmpty]: Start isEmpty. Operand 180 states and 218 transitions. [2022-07-19 17:24:58,335 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 52 [2022-07-19 17:24:58,337 INFO L187 NwaCegarLoop]: Found error trace [2022-07-19 17:24:58,337 INFO L195 NwaCegarLoop]: trace histogram [2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-07-19 17:24:58,337 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable5 [2022-07-19 17:24:58,338 INFO L420 AbstractCegarLoop]: === Iteration 7 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2022-07-19 17:24:58,338 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2022-07-19 17:24:58,338 INFO L85 PathProgramCache]: Analyzing trace with hash -426576330, now seen corresponding path program 1 times [2022-07-19 17:24:58,338 INFO L118 FreeRefinementEngine]: Executing refinement strategy CAMEL [2022-07-19 17:24:58,339 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [1813777053] [2022-07-19 17:24:58,339 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-07-19 17:24:58,339 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2022-07-19 17:24:58,373 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-07-19 17:24:58,430 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 11 [2022-07-19 17:24:58,434 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-07-19 17:24:58,437 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 19 [2022-07-19 17:24:58,442 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-07-19 17:24:58,449 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 33 [2022-07-19 17:24:58,450 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-07-19 17:24:58,455 INFO L134 CoverageAnalysis]: Checked inductivity of 19 backedges. 0 proven. 1 refuted. 0 times theorem prover too weak. 18 trivial. 0 not checked. [2022-07-19 17:24:58,455 INFO L136 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2022-07-19 17:24:58,456 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [1813777053] [2022-07-19 17:24:58,456 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [1813777053] provided 0 perfect and 1 imperfect interpolant sequences [2022-07-19 17:24:58,456 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleZ3 [1030608082] [2022-07-19 17:24:58,456 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-07-19 17:24:58,456 INFO L173 SolverBuilder]: Constructing external solver with command: z3 -smt2 -in SMTLIB2_COMPLIANT=true [2022-07-19 17:24:58,457 INFO L189 MonitoredProcess]: No working directory specified, using /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 [2022-07-19 17:24:58,465 INFO L229 MonitoredProcess]: Starting monitored process 2 with /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 -smt2 -in SMTLIB2_COMPLIANT=true (exit command is (exit), workingDir is null) [2022-07-19 17:24:58,472 INFO L327 MonitoredProcess]: [MP /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 -smt2 -in SMTLIB2_COMPLIANT=true (2)] Waiting until timeout for monitored process [2022-07-19 17:24:58,549 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-07-19 17:24:58,552 INFO L263 TraceCheckSpWp]: Trace formula consists of 344 conjuncts, 9 conjunts are in the unsatisfiable core [2022-07-19 17:24:58,560 INFO L286 TraceCheckSpWp]: Computing forward predicates... [2022-07-19 17:24:58,725 INFO L134 CoverageAnalysis]: Checked inductivity of 19 backedges. 16 proven. 2 refuted. 0 times theorem prover too weak. 1 trivial. 0 not checked. [2022-07-19 17:24:58,726 INFO L328 TraceCheckSpWp]: Computing backward predicates... [2022-07-19 17:24:58,918 INFO L134 CoverageAnalysis]: Checked inductivity of 19 backedges. 16 proven. 3 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2022-07-19 17:24:58,919 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleZ3 [1030608082] provided 0 perfect and 2 imperfect interpolant sequences [2022-07-19 17:24:58,919 INFO L184 FreeRefinementEngine]: Found 0 perfect and 3 imperfect interpolant sequences. [2022-07-19 17:24:58,919 INFO L197 FreeRefinementEngine]: Number of different interpolants: perfect sequences [] imperfect sequences [6, 6, 7] total 14 [2022-07-19 17:24:58,919 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [1300709845] [2022-07-19 17:24:58,920 INFO L85 oduleStraightlineAll]: Using 3 imperfect interpolants to construct interpolant automaton [2022-07-19 17:24:58,920 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 14 states [2022-07-19 17:24:58,920 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2022-07-19 17:24:58,923 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 14 interpolants. [2022-07-19 17:24:58,923 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=42, Invalid=140, Unknown=0, NotChecked=0, Total=182 [2022-07-19 17:24:58,923 INFO L87 Difference]: Start difference. First operand 180 states and 218 transitions. Second operand has 14 states, 14 states have (on average 6.0) internal successors, (84), 12 states have internal predecessors, (84), 4 states have call successors, (10), 6 states have call predecessors, (10), 7 states have return successors, (7), 3 states have call predecessors, (7), 3 states have call successors, (7) [2022-07-19 17:24:59,112 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-07-19 17:24:59,113 INFO L93 Difference]: Finished difference Result 237 states and 290 transitions. [2022-07-19 17:24:59,113 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 7 states. [2022-07-19 17:24:59,114 INFO L78 Accepts]: Start accepts. Automaton has has 14 states, 14 states have (on average 6.0) internal successors, (84), 12 states have internal predecessors, (84), 4 states have call successors, (10), 6 states have call predecessors, (10), 7 states have return successors, (7), 3 states have call predecessors, (7), 3 states have call successors, (7) Word has length 51 [2022-07-19 17:24:59,114 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2022-07-19 17:24:59,114 INFO L225 Difference]: With dead ends: 237 [2022-07-19 17:24:59,114 INFO L226 Difference]: Without dead ends: 0 [2022-07-19 17:24:59,115 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 116 GetRequests, 98 SyntacticMatches, 1 SemanticMatches, 17 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 29 ImplicationChecksByTransitivity, 0.1s TimeCoverageRelationStatistics Valid=91, Invalid=251, Unknown=0, NotChecked=0, Total=342 [2022-07-19 17:24:59,116 INFO L413 NwaCegarLoop]: 65 mSDtfsCounter, 129 mSDsluCounter, 307 mSDsCounter, 0 mSdLazyCounter, 131 mSolverCounterSat, 39 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.1s Time, 0 mProtectedPredicate, 0 mProtectedAction, 129 SdHoareTripleChecker+Valid, 372 SdHoareTripleChecker+Invalid, 170 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 39 IncrementalHoareTripleChecker+Valid, 131 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.1s IncrementalHoareTripleChecker+Time [2022-07-19 17:24:59,116 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [129 Valid, 372 Invalid, 170 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [39 Valid, 131 Invalid, 0 Unknown, 0 Unchecked, 0.1s Time] [2022-07-19 17:24:59,117 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 0 states. [2022-07-19 17:24:59,117 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 0 to 0. [2022-07-19 17:24:59,117 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 0 states, 0 states have (on average 0.0) internal successors, (0), 0 states have internal predecessors, (0), 0 states have call successors, (0), 0 states have call predecessors, (0), 0 states have return successors, (0), 0 states have call predecessors, (0), 0 states have call successors, (0) [2022-07-19 17:24:59,117 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 0 states to 0 states and 0 transitions. [2022-07-19 17:24:59,118 INFO L78 Accepts]: Start accepts. Automaton has 0 states and 0 transitions. Word has length 51 [2022-07-19 17:24:59,118 INFO L84 Accepts]: Finished accepts. word is rejected. [2022-07-19 17:24:59,118 INFO L495 AbstractCegarLoop]: Abstraction has 0 states and 0 transitions. [2022-07-19 17:24:59,118 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 14 states, 14 states have (on average 6.0) internal successors, (84), 12 states have internal predecessors, (84), 4 states have call successors, (10), 6 states have call predecessors, (10), 7 states have return successors, (7), 3 states have call predecessors, (7), 3 states have call successors, (7) [2022-07-19 17:24:59,119 INFO L276 IsEmpty]: Start isEmpty. Operand 0 states and 0 transitions. [2022-07-19 17:24:59,119 INFO L282 IsEmpty]: Finished isEmpty. No accepting run. [2022-07-19 17:24:59,121 INFO L805 garLoopResultBuilder]: Registering result SAFE for location timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION (0 of 1 remaining) [2022-07-19 17:24:59,147 INFO L552 MonitoredProcess]: [MP /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 -smt2 -in SMTLIB2_COMPLIANT=true (2)] Ended with exit code 0 [2022-07-19 17:24:59,343 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable6,2 /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 -smt2 -in SMTLIB2_COMPLIANT=true [2022-07-19 17:24:59,345 INFO L343 DoubleDeckerVisitor]: Before removal of dead ends 0 states and 0 transitions. [2022-07-19 17:24:59,966 INFO L902 garLoopResultBuilder]: At program point changeMethaneLevelENTRY(lines 692 703) the Hoare annotation is: true [2022-07-19 17:24:59,966 INFO L899 garLoopResultBuilder]: For program point L696-1(lines 692 703) no Hoare annotation was computed. [2022-07-19 17:24:59,967 INFO L899 garLoopResultBuilder]: For program point changeMethaneLevelEXIT(lines 692 703) no Hoare annotation was computed. [2022-07-19 17:24:59,967 INFO L899 garLoopResultBuilder]: For program point cleanupEXIT(lines 773 802) no Hoare annotation was computed. [2022-07-19 17:24:59,967 INFO L902 garLoopResultBuilder]: At program point L798(lines 773 802) the Hoare annotation is: true [2022-07-19 17:24:59,968 INFO L902 garLoopResultBuilder]: At program point cleanupENTRY(lines 773 802) the Hoare annotation is: true [2022-07-19 17:24:59,968 INFO L899 garLoopResultBuilder]: For program point L794(line 794) no Hoare annotation was computed. [2022-07-19 17:24:59,968 INFO L899 garLoopResultBuilder]: For program point L787(lines 787 791) no Hoare annotation was computed. [2022-07-19 17:24:59,968 INFO L902 garLoopResultBuilder]: At program point L787-1(lines 787 791) the Hoare annotation is: true [2022-07-19 17:24:59,968 INFO L899 garLoopResultBuilder]: For program point L784(line 784) no Hoare annotation was computed. [2022-07-19 17:24:59,968 INFO L902 garLoopResultBuilder]: At program point L783-2(lines 783 797) the Hoare annotation is: true [2022-07-19 17:24:59,968 INFO L902 garLoopResultBuilder]: At program point L779(line 779) the Hoare annotation is: true [2022-07-19 17:24:59,968 INFO L899 garLoopResultBuilder]: For program point L779-1(line 779) no Hoare annotation was computed. [2022-07-19 17:24:59,968 INFO L895 garLoopResultBuilder]: At program point L609(lines 604 612) the Hoare annotation is: (or (not (= ~pumpRunning~0 0)) (not (<= 1 |old(~waterLevel~0)|))) [2022-07-19 17:24:59,968 INFO L895 garLoopResultBuilder]: At program point L574(lines 570 576) the Hoare annotation is: (let ((.cse0 (not (= ~pumpRunning~0 0)))) (and (or .cse0 (= |old(~waterLevel~0)| ~waterLevel~0) (not (<= 2 |old(~waterLevel~0)|))) (or .cse0 (not (= |old(~waterLevel~0)| 1)) (= ~waterLevel~0 1)))) [2022-07-19 17:24:59,969 INFO L899 garLoopResultBuilder]: For program point L758(lines 758 764) no Hoare annotation was computed. [2022-07-19 17:24:59,969 INFO L899 garLoopResultBuilder]: For program point L54(line 54) no Hoare annotation was computed. [2022-07-19 17:24:59,974 INFO L899 garLoopResultBuilder]: For program point L754(lines 754 767) no Hoare annotation was computed. [2022-07-19 17:24:59,974 INFO L895 garLoopResultBuilder]: At program point L754-1(lines 746 770) the Hoare annotation is: (let ((.cse0 (not (= ~pumpRunning~0 0))) (.cse1 (not (= |timeShift___utac_acc__Specification4_spec__1_~tmp~4#1| 0))) (.cse2 (not (= |timeShift_getWaterLevel_#res#1| 0)))) (and (or .cse0 (and .cse1 .cse2 (= |old(~waterLevel~0)| ~waterLevel~0)) (not (<= 2 |old(~waterLevel~0)|))) (or .cse0 (not (= |old(~waterLevel~0)| 1)) (and .cse1 .cse2 (= ~waterLevel~0 1))))) [2022-07-19 17:24:59,974 INFO L899 garLoopResultBuilder]: For program point timeShiftFINAL(lines 546 569) no Hoare annotation was computed. [2022-07-19 17:24:59,974 INFO L899 garLoopResultBuilder]: For program point L550-1(lines 549 568) no Hoare annotation was computed. [2022-07-19 17:24:59,975 INFO L899 garLoopResultBuilder]: For program point L672(lines 672 676) no Hoare annotation was computed. [2022-07-19 17:24:59,975 INFO L895 garLoopResultBuilder]: At program point L672-2(lines 668 679) the Hoare annotation is: (or (not (= ~pumpRunning~0 0)) (not (<= 1 |old(~waterLevel~0)|))) [2022-07-19 17:24:59,975 INFO L895 garLoopResultBuilder]: At program point L55(lines 50 57) the Hoare annotation is: (or (not (= ~pumpRunning~0 0)) (not (<= 1 |old(~waterLevel~0)|))) [2022-07-19 17:24:59,975 INFO L895 garLoopResultBuilder]: At program point timeShiftENTRY(lines 546 569) the Hoare annotation is: (let ((.cse0 (not (= ~pumpRunning~0 0)))) (and (or .cse0 (= |old(~waterLevel~0)| ~waterLevel~0) (not (<= 2 |old(~waterLevel~0)|))) (or .cse0 (not (= |old(~waterLevel~0)| 1)) (= ~waterLevel~0 1)))) [2022-07-19 17:24:59,975 INFO L899 garLoopResultBuilder]: For program point L557-1(lines 557 563) no Hoare annotation was computed. [2022-07-19 17:24:59,975 INFO L899 garLoopResultBuilder]: For program point timeShiftEXIT(lines 546 569) no Hoare annotation was computed. [2022-07-19 17:24:59,975 INFO L899 garLoopResultBuilder]: For program point timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION(line 54) no Hoare annotation was computed. [2022-07-19 17:24:59,976 INFO L895 garLoopResultBuilder]: At program point L741(lines 736 744) the Hoare annotation is: (let ((.cse1 (not (= ~pumpRunning~0 0))) (.cse0 (not (= |timeShift_getWaterLevel_#res#1| 0)))) (and (or (and .cse0 (= ~waterLevel~0 1)) .cse1 (not (= |old(~waterLevel~0)| 1))) (or .cse1 (and .cse0 (= |old(~waterLevel~0)| ~waterLevel~0)) (not (<= 2 |old(~waterLevel~0)|))))) [2022-07-19 17:24:59,976 INFO L895 garLoopResultBuilder]: At program point L514-2(lines 508 521) the Hoare annotation is: (let ((.cse0 (= ~pumpRunning~0 0)) (.cse1 (= |ULTIMATE.start_test_~splverifierCounter~0#1| 0))) (or (and .cse0 .cse1 (= ~waterLevel~0 1)) (and .cse0 (<= 2 ~waterLevel~0) .cse1))) [2022-07-19 17:24:59,976 INFO L899 garLoopResultBuilder]: For program point L498(lines 498 504) no Hoare annotation was computed. [2022-07-19 17:24:59,976 INFO L899 garLoopResultBuilder]: For program point L498-1(lines 498 504) no Hoare annotation was computed. [2022-07-19 17:24:59,976 INFO L895 garLoopResultBuilder]: At program point L523(lines 478 525) the Hoare annotation is: (let ((.cse0 (= ~pumpRunning~0 0)) (.cse1 (= |ULTIMATE.start_test_~splverifierCounter~0#1| 0))) (or (and .cse0 .cse1 (= ~waterLevel~0 1)) (and .cse0 (<= 2 ~waterLevel~0) .cse1))) [2022-07-19 17:24:59,976 INFO L895 garLoopResultBuilder]: At program point L490(line 490) the Hoare annotation is: (let ((.cse0 (= ~pumpRunning~0 0)) (.cse1 (= |ULTIMATE.start_test_~splverifierCounter~0#1| 0))) (or (and .cse0 .cse1 (= ~waterLevel~0 1)) (and .cse0 (<= 2 ~waterLevel~0) .cse1))) [2022-07-19 17:24:59,976 INFO L902 garLoopResultBuilder]: At program point L841(lines 834 843) the Hoare annotation is: true [2022-07-19 17:24:59,976 INFO L899 garLoopResultBuilder]: For program point L-1(line -1) no Hoare annotation was computed. [2022-07-19 17:24:59,976 INFO L899 garLoopResultBuilder]: For program point ULTIMATE.startENTRY(line -1) no Hoare annotation was computed. [2022-07-19 17:24:59,976 INFO L899 garLoopResultBuilder]: For program point ULTIMATE.startFINAL(line -1) no Hoare annotation was computed. [2022-07-19 17:24:59,976 INFO L899 garLoopResultBuilder]: For program point L854(lines 854 861) no Hoare annotation was computed. [2022-07-19 17:24:59,977 INFO L899 garLoopResultBuilder]: For program point L854-2(lines 854 861) no Hoare annotation was computed. [2022-07-19 17:24:59,977 INFO L895 garLoopResultBuilder]: At program point L590(lines 585 592) the Hoare annotation is: false [2022-07-19 17:24:59,977 INFO L895 garLoopResultBuilder]: At program point L458(lines 453 461) the Hoare annotation is: (and (= ~pumpRunning~0 0) (= ~waterLevel~0 1) (= ~waterLevel~0 ~systemActive~0)) [2022-07-19 17:24:59,977 INFO L895 garLoopResultBuilder]: At program point L450(lines 446 452) the Hoare annotation is: (and (= ~pumpRunning~0 0) (= ~waterLevel~0 1) (= ~waterLevel~0 ~systemActive~0)) [2022-07-19 17:24:59,977 INFO L899 garLoopResultBuilder]: For program point ULTIMATE.startEXIT(line -1) no Hoare annotation was computed. [2022-07-19 17:24:59,977 INFO L899 garLoopResultBuilder]: For program point L479(lines 478 525) no Hoare annotation was computed. [2022-07-19 17:24:59,977 INFO L902 garLoopResultBuilder]: At program point L863(lines 844 866) the Hoare annotation is: true [2022-07-19 17:24:59,977 INFO L899 garLoopResultBuilder]: For program point L508(lines 508 521) no Hoare annotation was computed. [2022-07-19 17:24:59,977 INFO L895 garLoopResultBuilder]: At program point L661(lines 649 663) the Hoare annotation is: (let ((.cse0 (= ~pumpRunning~0 0)) (.cse1 (= |ULTIMATE.start_test_~splverifierCounter~0#1| 0))) (or (and .cse0 .cse1 (= ~waterLevel~0 1)) (and .cse0 (<= 2 ~waterLevel~0) .cse1))) [2022-07-19 17:24:59,978 INFO L895 garLoopResultBuilder]: At program point L500(line 500) the Hoare annotation is: (let ((.cse0 (= ~pumpRunning~0 0)) (.cse1 (= |ULTIMATE.start_test_~splverifierCounter~0#1| 0))) (or (and .cse0 .cse1 (= ~waterLevel~0 1)) (and .cse0 (<= 2 ~waterLevel~0) .cse1))) [2022-07-19 17:24:59,978 INFO L902 garLoopResultBuilder]: At program point L529(lines 468 533) the Hoare annotation is: true [2022-07-19 17:24:59,978 INFO L899 garLoopResultBuilder]: For program point L653(lines 653 659) no Hoare annotation was computed. [2022-07-19 17:24:59,978 INFO L899 garLoopResultBuilder]: For program point L653-2(lines 653 659) no Hoare annotation was computed. [2022-07-19 17:24:59,978 INFO L899 garLoopResultBuilder]: For program point L488(lines 488 494) no Hoare annotation was computed. [2022-07-19 17:24:59,978 INFO L899 garLoopResultBuilder]: For program point L488-1(lines 488 494) no Hoare annotation was computed. [2022-07-19 17:24:59,978 INFO L899 garLoopResultBuilder]: For program point L480(lines 480 484) no Hoare annotation was computed. [2022-07-19 17:24:59,978 INFO L895 garLoopResultBuilder]: At program point L831(lines 827 833) the Hoare annotation is: (and (= ~pumpRunning~0 0) (= ~waterLevel~0 1) (= ~waterLevel~0 ~systemActive~0)) [2022-07-19 17:24:59,978 INFO L895 garLoopResultBuilder]: At program point L443(lines 439 445) the Hoare annotation is: (and (= ~pumpRunning~0 0) (= ~waterLevel~0 1) (= ~waterLevel~0 ~systemActive~0)) [2022-07-19 17:24:59,978 INFO L895 garLoopResultBuilder]: At program point L526(lines 477 527) the Hoare annotation is: false [2022-07-19 17:24:59,979 INFO L899 garLoopResultBuilder]: For program point L514(lines 514 520) no Hoare annotation was computed. [2022-07-19 17:24:59,979 INFO L899 garLoopResultBuilder]: For program point waterRiseEXIT(lines 680 691) no Hoare annotation was computed. [2022-07-19 17:24:59,979 INFO L899 garLoopResultBuilder]: For program point L684-1(lines 680 691) no Hoare annotation was computed. [2022-07-19 17:24:59,979 INFO L895 garLoopResultBuilder]: At program point waterRiseENTRY(lines 680 691) the Hoare annotation is: (let ((.cse0 (not (= ~pumpRunning~0 0)))) (and (or .cse0 (= |old(~waterLevel~0)| ~waterLevel~0) (not (<= 2 |old(~waterLevel~0)|))) (or .cse0 (not (= |old(~waterLevel~0)| 1)) (= ~waterLevel~0 1)))) [2022-07-19 17:24:59,981 INFO L356 BasicCegarLoop]: Path program histogram: [1, 1, 1, 1, 1, 1, 1] [2022-07-19 17:24:59,983 INFO L176 ceAbstractionStarter]: Computing trace abstraction results [2022-07-19 17:24:59,997 INFO L202 PluginConnector]: Adding new model de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction CFG 19.07 05:24:59 BoogieIcfgContainer [2022-07-19 17:24:59,998 INFO L132 PluginConnector]: ------------------------ END TraceAbstraction---------------------------- [2022-07-19 17:24:59,998 INFO L113 PluginConnector]: ------------------------Witness Printer---------------------------- [2022-07-19 17:24:59,998 INFO L271 PluginConnector]: Initializing Witness Printer... [2022-07-19 17:24:59,999 INFO L275 PluginConnector]: Witness Printer initialized [2022-07-19 17:24:59,999 INFO L185 PluginConnector]: Executing the observer RCFGCatcher from plugin Witness Printer for "de.uni_freiburg.informatik.ultimate.plugins.generator.rcfgbuilder CFG 19.07 05:24:56" (3/4) ... [2022-07-19 17:25:00,002 INFO L137 WitnessPrinter]: Generating witness for correct program [2022-07-19 17:25:00,007 INFO L354 RCFGBacktranslator]: Ignoring RootEdge to procedure changeMethaneLevel [2022-07-19 17:25:00,007 INFO L354 RCFGBacktranslator]: Ignoring RootEdge to procedure cleanup [2022-07-19 17:25:00,008 INFO L354 RCFGBacktranslator]: Ignoring RootEdge to procedure timeShift [2022-07-19 17:25:00,008 INFO L354 RCFGBacktranslator]: Ignoring RootEdge to procedure waterRise [2022-07-19 17:25:00,013 INFO L910 BoogieBacktranslator]: Reduced CFG by removing 46 nodes and edges [2022-07-19 17:25:00,013 INFO L910 BoogieBacktranslator]: Reduced CFG by removing 22 nodes and edges [2022-07-19 17:25:00,013 INFO L910 BoogieBacktranslator]: Reduced CFG by removing 11 nodes and edges [2022-07-19 17:25:00,014 INFO L910 BoogieBacktranslator]: Reduced CFG by removing 5 nodes and edges [2022-07-19 17:25:00,014 INFO L910 BoogieBacktranslator]: Reduced CFG by removing 2 nodes and edges [2022-07-19 17:25:00,014 INFO L910 BoogieBacktranslator]: Reduced CFG by removing 1 nodes and edges [2022-07-19 17:25:00,015 INFO L910 BoogieBacktranslator]: Reduced CFG by removing 1 nodes and edges [2022-07-19 17:25:00,036 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: !(pumpRunning == 0) || !(1 <= \old(waterLevel)) [2022-07-19 17:25:00,036 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: ((!(pumpRunning == 0) || \old(waterLevel) == waterLevel) || !(2 <= \old(waterLevel))) && ((!(pumpRunning == 0) || !(\old(waterLevel) == 1)) || waterLevel == 1) [2022-07-19 17:25:00,037 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (((!(\result == 0) && waterLevel == 1) || !(pumpRunning == 0)) || !(\old(waterLevel) == 1)) && ((!(pumpRunning == 0) || (!(\result == 0) && \old(waterLevel) == waterLevel)) || !(2 <= \old(waterLevel))) [2022-07-19 17:25:00,037 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: ((!(pumpRunning == 0) || ((!(tmp == 0) && !(\result == 0)) && \old(waterLevel) == waterLevel)) || !(2 <= \old(waterLevel))) && ((!(pumpRunning == 0) || !(\old(waterLevel) == 1)) || ((!(tmp == 0) && !(\result == 0)) && waterLevel == 1)) [2022-07-19 17:25:00,037 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: !(pumpRunning == 0) || !(1 <= \old(waterLevel)) [2022-07-19 17:25:00,037 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: !(pumpRunning == 0) || !(1 <= \old(waterLevel)) [2022-07-19 17:25:00,050 INFO L141 WitnessManager]: Wrote witness to /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/witness.graphml [2022-07-19 17:25:00,050 INFO L132 PluginConnector]: ------------------------ END Witness Printer---------------------------- [2022-07-19 17:25:00,051 INFO L158 Benchmark]: Toolchain (without parser) took 3915.26ms. Allocated memory was 86.0MB in the beginning and 125.8MB in the end (delta: 39.8MB). Free memory was 54.2MB in the beginning and 93.5MB in the end (delta: -39.3MB). There was no memory consumed. Max. memory is 16.1GB. [2022-07-19 17:25:00,051 INFO L158 Benchmark]: CDTParser took 0.24ms. Allocated memory is still 86.0MB. Free memory was 40.8MB in the beginning and 40.7MB in the end (delta: 76.9kB). There was no memory consumed. Max. memory is 16.1GB. [2022-07-19 17:25:00,051 INFO L158 Benchmark]: CACSL2BoogieTranslator took 342.76ms. Allocated memory was 86.0MB in the beginning and 104.9MB in the end (delta: 18.9MB). Free memory was 54.0MB in the beginning and 73.0MB in the end (delta: -19.1MB). Peak memory consumption was 8.4MB. Max. memory is 16.1GB. [2022-07-19 17:25:00,052 INFO L158 Benchmark]: Boogie Procedure Inliner took 40.87ms. Allocated memory is still 104.9MB. Free memory was 73.0MB in the beginning and 70.6MB in the end (delta: 2.4MB). Peak memory consumption was 2.1MB. Max. memory is 16.1GB. [2022-07-19 17:25:00,052 INFO L158 Benchmark]: Boogie Preprocessor took 20.81ms. Allocated memory is still 104.9MB. Free memory was 70.6MB in the beginning and 69.3MB in the end (delta: 1.3MB). Peak memory consumption was 2.1MB. Max. memory is 16.1GB. [2022-07-19 17:25:00,052 INFO L158 Benchmark]: RCFGBuilder took 419.67ms. Allocated memory is still 104.9MB. Free memory was 69.3MB in the beginning and 55.1MB in the end (delta: 14.3MB). Peak memory consumption was 12.6MB. Max. memory is 16.1GB. [2022-07-19 17:25:00,053 INFO L158 Benchmark]: TraceAbstraction took 3033.47ms. Allocated memory was 104.9MB in the beginning and 125.8MB in the end (delta: 21.0MB). Free memory was 54.7MB in the beginning and 97.7MB in the end (delta: -43.1MB). Peak memory consumption was 31.1MB. Max. memory is 16.1GB. [2022-07-19 17:25:00,053 INFO L158 Benchmark]: Witness Printer took 52.06ms. Allocated memory is still 125.8MB. Free memory was 97.7MB in the beginning and 93.5MB in the end (delta: 4.2MB). Peak memory consumption was 4.2MB. Max. memory is 16.1GB. [2022-07-19 17:25:00,054 INFO L339 ainManager$Toolchain]: ####################### End [Toolchain 1] ####################### --- Results --- * Results from de.uni_freiburg.informatik.ultimate.core: - StatisticsResult: Toolchain Benchmarks Benchmark results are: * CDTParser took 0.24ms. Allocated memory is still 86.0MB. Free memory was 40.8MB in the beginning and 40.7MB in the end (delta: 76.9kB). There was no memory consumed. Max. memory is 16.1GB. * CACSL2BoogieTranslator took 342.76ms. Allocated memory was 86.0MB in the beginning and 104.9MB in the end (delta: 18.9MB). Free memory was 54.0MB in the beginning and 73.0MB in the end (delta: -19.1MB). Peak memory consumption was 8.4MB. Max. memory is 16.1GB. * Boogie Procedure Inliner took 40.87ms. Allocated memory is still 104.9MB. Free memory was 73.0MB in the beginning and 70.6MB in the end (delta: 2.4MB). Peak memory consumption was 2.1MB. Max. memory is 16.1GB. * Boogie Preprocessor took 20.81ms. Allocated memory is still 104.9MB. Free memory was 70.6MB in the beginning and 69.3MB in the end (delta: 1.3MB). Peak memory consumption was 2.1MB. Max. memory is 16.1GB. * RCFGBuilder took 419.67ms. Allocated memory is still 104.9MB. Free memory was 69.3MB in the beginning and 55.1MB in the end (delta: 14.3MB). Peak memory consumption was 12.6MB. Max. memory is 16.1GB. * TraceAbstraction took 3033.47ms. Allocated memory was 104.9MB in the beginning and 125.8MB in the end (delta: 21.0MB). Free memory was 54.7MB in the beginning and 97.7MB in the end (delta: -43.1MB). Peak memory consumption was 31.1MB. Max. memory is 16.1GB. * Witness Printer took 52.06ms. Allocated memory is still 125.8MB. Free memory was 97.7MB in the beginning and 93.5MB in the end (delta: 4.2MB). Peak memory consumption was 4.2MB. Max. memory is 16.1GB. * Results from de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction: - StatisticsResult: ErrorAutomatonStatistics NumberErrorTraces: 0, NumberStatementsAllTraces: 0, NumberRelevantStatements: 0, 0.0s ErrorAutomatonConstructionTimeTotal, 0.0s FaulLocalizationTime, NumberStatementsFirstTrace: -1, TraceLengthAvg: 0, 0.0s ErrorAutomatonConstructionTimeAvg, 0.0s ErrorAutomatonDifferenceTimeAvg, 0.0s ErrorAutomatonDifferenceTimeTotal, NumberOfNoEnhancement: 0, NumberOfFiniteEnhancement: 0, NumberOfInfiniteEnhancement: 0 - PositiveResult [Line: 54]: call to reach_error is unreachable For all program executions holds that call to reach_error is unreachable at this location - StatisticsResult: Ultimate Automizer benchmark data CFG has 5 procedures, 62 locations, 1 error locations. Started 1 CEGAR loops. OverallTime: 3.0s, OverallIterations: 7, TraceHistogramMax: 2, PathProgramHistogramMax: 1, EmptinessCheckTime: 0.0s, AutomataDifference: 0.7s, DeadEndRemovalTime: 0.0s, HoareAnnotationTime: 0.6s, InitialAbstractionConstructionTime: 0.0s, HoareTripleCheckerStatistics: 0 mSolverCounterUnknown, 473 SdHoareTripleChecker+Valid, 0.3s IncrementalHoareTripleChecker+Time, 0 mSdLazyCounter, 468 mSDsluCounter, 1211 SdHoareTripleChecker+Invalid, 0.2s Time, 0 mProtectedAction, 0 SdHoareTripleChecker+Unchecked, 0 IncrementalHoareTripleChecker+Unchecked, 810 mSDsCounter, 76 IncrementalHoareTripleChecker+Valid, 0 mProtectedPredicate, 292 IncrementalHoareTripleChecker+Invalid, 368 SdHoareTripleChecker+Unknown, 0 mSolverCounterNotChecked, 76 mSolverCounterUnsat, 401 mSDtfsCounter, 292 mSolverCounterSat, 0.0s SdHoareTripleChecker+Time, 0 IncrementalHoareTripleChecker+Unknown, PredicateUnifierStatistics: 0 DeclaredPredicates, 152 GetRequests, 108 SyntacticMatches, 1 SemanticMatches, 43 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 63 ImplicationChecksByTransitivity, 0.3s Time, 0.0s BasicInterpolantAutomatonTime, BiggestAbstraction: size=180occurred in iteration=6, InterpolantAutomatonStates: 41, traceCheckStatistics: No data available, InterpolantConsolidationStatistics: No data available, PathInvariantsStatistics: No data available, 0/0 InterpolantCoveringCapability, TotalInterpolationStatistics: No data available, 0.0s DumpTime, AutomataMinimizationStatistics: 0.1s AutomataMinimizationTime, 7 MinimizatonAttempts, 106 StatesRemovedByMinimization, 3 NontrivialMinimizations, HoareAnnotationStatistics: 0.0s HoareAnnotationTime, 28 LocationsWithAnnotation, 226 PreInvPairs, 260 NumberOfFragments, 336 HoareAnnotationTreeSize, 226 FomulaSimplifications, 259 FormulaSimplificationTreeSizeReduction, 0.1s HoareSimplificationTime, 28 FomulaSimplificationsInter, 2006 FormulaSimplificationTreeSizeReductionInter, 0.5s HoareSimplificationTimeInter, RefinementEngineStatistics: TRACE_CHECK: 0.0s SsaConstructionTime, 0.2s SatisfiabilityAnalysisTime, 0.7s InterpolantComputationTime, 246 NumberOfCodeBlocks, 246 NumberOfCodeBlocksAsserted, 8 NumberOfCheckSat, 288 ConstructedInterpolants, 0 QuantifiedInterpolants, 769 SizeOfPredicates, 0 NumberOfNonLiveVariables, 344 ConjunctsInSsa, 9 ConjunctsInUnsatCore, 9 InterpolantComputations, 6 PerfectInterpolantSequences, 51/57 InterpolantCoveringCapability, INVARIANT_SYNTHESIS: No data available, INTERPOLANT_CONSOLIDATION: No data available, ABSTRACT_INTERPRETATION: No data available, PDR: No data available, ACCELERATED_INTERPOLATION: No data available, SIFA: No data available, ReuseStatistics: No data available - AllSpecificationsHoldResult: All specifications hold 1 specifications checked. All of them hold - InvariantResult [Line: 736]: Loop Invariant Derived loop invariant: (((!(\result == 0) && waterLevel == 1) || !(pumpRunning == 0)) || !(\old(waterLevel) == 1)) && ((!(pumpRunning == 0) || (!(\result == 0) && \old(waterLevel) == waterLevel)) || !(2 <= \old(waterLevel))) - InvariantResult [Line: 668]: Loop Invariant Derived loop invariant: !(pumpRunning == 0) || !(1 <= \old(waterLevel)) - InvariantResult [Line: 844]: Loop Invariant Derived loop invariant: 1 - InvariantResult [Line: 468]: Loop Invariant Derived loop invariant: 1 - InvariantResult [Line: 453]: Loop Invariant Derived loop invariant: (pumpRunning == 0 && waterLevel == 1) && waterLevel == systemActive - InvariantResult [Line: 827]: Loop Invariant Derived loop invariant: (pumpRunning == 0 && waterLevel == 1) && waterLevel == systemActive - InvariantResult [Line: 783]: Loop Invariant Derived loop invariant: 1 - InvariantResult [Line: 446]: Loop Invariant Derived loop invariant: (pumpRunning == 0 && waterLevel == 1) && waterLevel == systemActive - InvariantResult [Line: 649]: Loop Invariant Derived loop invariant: ((pumpRunning == 0 && splverifierCounter == 0) && waterLevel == 1) || ((pumpRunning == 0 && 2 <= waterLevel) && splverifierCounter == 0) - InvariantResult [Line: 439]: Loop Invariant Derived loop invariant: (pumpRunning == 0 && waterLevel == 1) && waterLevel == systemActive - InvariantResult [Line: 477]: Loop Invariant Derived loop invariant: 0 - InvariantResult [Line: 834]: Loop Invariant Derived loop invariant: 1 - InvariantResult [Line: 478]: Loop Invariant Derived loop invariant: ((pumpRunning == 0 && splverifierCounter == 0) && waterLevel == 1) || ((pumpRunning == 0 && 2 <= waterLevel) && splverifierCounter == 0) - InvariantResult [Line: 570]: Loop Invariant Derived loop invariant: ((!(pumpRunning == 0) || \old(waterLevel) == waterLevel) || !(2 <= \old(waterLevel))) && ((!(pumpRunning == 0) || !(\old(waterLevel) == 1)) || waterLevel == 1) - InvariantResult [Line: 585]: Loop Invariant Derived loop invariant: 0 - InvariantResult [Line: 50]: Loop Invariant Derived loop invariant: !(pumpRunning == 0) || !(1 <= \old(waterLevel)) - InvariantResult [Line: 746]: Loop Invariant Derived loop invariant: ((!(pumpRunning == 0) || ((!(tmp == 0) && !(\result == 0)) && \old(waterLevel) == waterLevel)) || !(2 <= \old(waterLevel))) && ((!(pumpRunning == 0) || !(\old(waterLevel) == 1)) || ((!(tmp == 0) && !(\result == 0)) && waterLevel == 1)) - InvariantResult [Line: 604]: Loop Invariant Derived loop invariant: !(pumpRunning == 0) || !(1 <= \old(waterLevel)) - InvariantResult [Line: 773]: Loop Invariant Derived loop invariant: 1 RESULT: Ultimate proved your program to be correct! [2022-07-19 17:25:00,098 INFO L540 MonitoredProcess]: [MP /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in -t:2000 (1)] Forceful destruction successful, exit code 0 Received shutdown request... --- End real Ultimate output --- Execution finished normally Writing output log to file Ultimate.log Result: TRUE