./Ultimate.py --spec ../sv-benchmarks/c/properties/unreach-call.prp --file ../sv-benchmarks/c/product-lines/minepump_spec3_product38.cil.c --full-output --architecture 32bit -------------------------------------------------------------------------------- Checking for ERROR reachability Using default analysis Version f4b24e32 Calling Ultimate with: /usr/bin/java -Dosgi.configuration.area=/storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/data/config -Xmx15G -Xms4m -jar /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/plugins/org.eclipse.equinox.launcher_1.5.800.v20200727-1323.jar -data @noDefault -ultimatedata /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/data -tc /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/config/AutomizerReach.xml -i ../sv-benchmarks/c/product-lines/minepump_spec3_product38.cil.c -s /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/config/svcomp-Reach-32bit-Automizer_Default.epf --cacsl2boogietranslator.entry.function main --witnessprinter.witness.directory /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux --witnessprinter.witness.filename witness.graphml --witnessprinter.write.witness.besides.input.file false --witnessprinter.graph.data.specification CHECK( init(main()), LTL(G ! call(reach_error())) ) --witnessprinter.graph.data.producer Automizer --witnessprinter.graph.data.architecture 32bit --witnessprinter.graph.data.programhash c8e3613a57f37f194f1fe75086d0eb5e0d997c2a9b69c99903e0a1a10a2db5eb --- Real Ultimate output --- This is Ultimate 0.2.2-?-f4b24e3 [2022-07-13 17:59:20,253 INFO L177 SettingsManager]: Resetting all preferences to default values... [2022-07-13 17:59:20,256 INFO L181 SettingsManager]: Resetting UltimateCore preferences to default values [2022-07-13 17:59:20,294 INFO L184 SettingsManager]: Ultimate Commandline Interface provides no preferences, ignoring... [2022-07-13 17:59:20,294 INFO L181 SettingsManager]: Resetting Boogie Preprocessor preferences to default values [2022-07-13 17:59:20,296 INFO L181 SettingsManager]: Resetting Boogie Procedure Inliner preferences to default values [2022-07-13 17:59:20,298 INFO L181 SettingsManager]: Resetting Abstract Interpretation preferences to default values [2022-07-13 17:59:20,303 INFO L181 SettingsManager]: Resetting LassoRanker preferences to default values [2022-07-13 17:59:20,305 INFO L181 SettingsManager]: Resetting Reaching Definitions preferences to default values [2022-07-13 17:59:20,309 INFO L181 SettingsManager]: Resetting SyntaxChecker preferences to default values [2022-07-13 17:59:20,310 INFO L181 SettingsManager]: Resetting Sifa preferences to default values [2022-07-13 17:59:20,312 INFO L184 SettingsManager]: Büchi Program Product provides no preferences, ignoring... [2022-07-13 17:59:20,313 INFO L181 SettingsManager]: Resetting LTL2Aut preferences to default values [2022-07-13 17:59:20,315 INFO L181 SettingsManager]: Resetting PEA to Boogie preferences to default values [2022-07-13 17:59:20,317 INFO L181 SettingsManager]: Resetting BlockEncodingV2 preferences to default values [2022-07-13 17:59:20,320 INFO L181 SettingsManager]: Resetting ChcToBoogie preferences to default values [2022-07-13 17:59:20,321 INFO L181 SettingsManager]: Resetting AutomataScriptInterpreter preferences to default values [2022-07-13 17:59:20,323 INFO L181 SettingsManager]: Resetting BuchiAutomizer preferences to default values [2022-07-13 17:59:20,325 INFO L181 SettingsManager]: Resetting CACSL2BoogieTranslator preferences to default values [2022-07-13 17:59:20,330 INFO L181 SettingsManager]: Resetting CodeCheck preferences to default values [2022-07-13 17:59:20,332 INFO L181 SettingsManager]: Resetting HornVerifier preferences to default values [2022-07-13 17:59:20,333 INFO L181 SettingsManager]: Resetting InvariantSynthesis preferences to default values [2022-07-13 17:59:20,334 INFO L181 SettingsManager]: Resetting RCFGBuilder preferences to default values [2022-07-13 17:59:20,335 INFO L181 SettingsManager]: Resetting Referee preferences to default values [2022-07-13 17:59:20,337 INFO L181 SettingsManager]: Resetting TraceAbstraction preferences to default values [2022-07-13 17:59:20,343 INFO L184 SettingsManager]: TraceAbstractionConcurrent provides no preferences, ignoring... [2022-07-13 17:59:20,343 INFO L184 SettingsManager]: TraceAbstractionWithAFAs provides no preferences, ignoring... [2022-07-13 17:59:20,344 INFO L181 SettingsManager]: Resetting TreeAutomizer preferences to default values [2022-07-13 17:59:20,345 INFO L181 SettingsManager]: Resetting IcfgToChc preferences to default values [2022-07-13 17:59:20,345 INFO L181 SettingsManager]: Resetting IcfgTransformer preferences to default values [2022-07-13 17:59:20,347 INFO L184 SettingsManager]: ReqToTest provides no preferences, ignoring... [2022-07-13 17:59:20,347 INFO L181 SettingsManager]: Resetting Boogie Printer preferences to default values [2022-07-13 17:59:20,348 INFO L181 SettingsManager]: Resetting ChcSmtPrinter preferences to default values [2022-07-13 17:59:20,349 INFO L181 SettingsManager]: Resetting ReqPrinter preferences to default values [2022-07-13 17:59:20,350 INFO L181 SettingsManager]: Resetting Witness Printer preferences to default values [2022-07-13 17:59:20,350 INFO L184 SettingsManager]: Boogie PL CUP Parser provides no preferences, ignoring... [2022-07-13 17:59:20,352 INFO L181 SettingsManager]: Resetting CDTParser preferences to default values [2022-07-13 17:59:20,352 INFO L184 SettingsManager]: AutomataScriptParser provides no preferences, ignoring... [2022-07-13 17:59:20,352 INFO L184 SettingsManager]: ReqParser provides no preferences, ignoring... [2022-07-13 17:59:20,353 INFO L181 SettingsManager]: Resetting SmtParser preferences to default values [2022-07-13 17:59:20,353 INFO L181 SettingsManager]: Resetting Witness Parser preferences to default values [2022-07-13 17:59:20,355 INFO L188 SettingsManager]: Finished resetting all preferences to default values... [2022-07-13 17:59:20,356 INFO L101 SettingsManager]: Beginning loading settings from /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/config/svcomp-Reach-32bit-Automizer_Default.epf [2022-07-13 17:59:20,387 INFO L113 SettingsManager]: Loading preferences was successful [2022-07-13 17:59:20,388 INFO L115 SettingsManager]: Preferences different from defaults after loading the file: [2022-07-13 17:59:20,388 INFO L136 SettingsManager]: Preferences of UltimateCore differ from their defaults: [2022-07-13 17:59:20,389 INFO L138 SettingsManager]: * Log level for class=de.uni_freiburg.informatik.ultimate.lib.smtlibutils.quantifier.QuantifierPusher=ERROR; [2022-07-13 17:59:20,389 INFO L136 SettingsManager]: Preferences of Boogie Procedure Inliner differ from their defaults: [2022-07-13 17:59:20,389 INFO L138 SettingsManager]: * Ignore calls to procedures called more than once=ONLY_FOR_SEQUENTIAL_PROGRAMS [2022-07-13 17:59:20,390 INFO L136 SettingsManager]: Preferences of BlockEncodingV2 differ from their defaults: [2022-07-13 17:59:20,390 INFO L138 SettingsManager]: * Create parallel compositions if possible=false [2022-07-13 17:59:20,391 INFO L138 SettingsManager]: * Use SBE=true [2022-07-13 17:59:20,391 INFO L136 SettingsManager]: Preferences of CACSL2BoogieTranslator differ from their defaults: [2022-07-13 17:59:20,392 INFO L138 SettingsManager]: * sizeof long=4 [2022-07-13 17:59:20,392 INFO L138 SettingsManager]: * Overapproximate operations on floating types=true [2022-07-13 17:59:20,392 INFO L138 SettingsManager]: * sizeof POINTER=4 [2022-07-13 17:59:20,392 INFO L138 SettingsManager]: * Check division by zero=IGNORE [2022-07-13 17:59:20,392 INFO L138 SettingsManager]: * Pointer to allocated memory at dereference=IGNORE [2022-07-13 17:59:20,393 INFO L138 SettingsManager]: * If two pointers are subtracted or compared they have the same base address=IGNORE [2022-07-13 17:59:20,393 INFO L138 SettingsManager]: * Check array bounds for arrays that are off heap=IGNORE [2022-07-13 17:59:20,393 INFO L138 SettingsManager]: * sizeof long double=12 [2022-07-13 17:59:20,393 INFO L138 SettingsManager]: * Check if freed pointer was valid=false [2022-07-13 17:59:20,394 INFO L138 SettingsManager]: * Use constant arrays=true [2022-07-13 17:59:20,395 INFO L138 SettingsManager]: * Pointer base address is valid at dereference=IGNORE [2022-07-13 17:59:20,395 INFO L136 SettingsManager]: Preferences of RCFGBuilder differ from their defaults: [2022-07-13 17:59:20,395 INFO L138 SettingsManager]: * Size of a code block=SequenceOfStatements [2022-07-13 17:59:20,395 INFO L138 SettingsManager]: * SMT solver=External_DefaultMode [2022-07-13 17:59:20,396 INFO L138 SettingsManager]: * Command for external solver=z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in -t:2000 [2022-07-13 17:59:20,396 INFO L136 SettingsManager]: Preferences of TraceAbstraction differ from their defaults: [2022-07-13 17:59:20,396 INFO L138 SettingsManager]: * Compute Interpolants along a Counterexample=FPandBP [2022-07-13 17:59:20,396 INFO L138 SettingsManager]: * Positions where we compute the Hoare Annotation=LoopsAndPotentialCycles [2022-07-13 17:59:20,396 INFO L138 SettingsManager]: * Trace refinement strategy=CAMEL [2022-07-13 17:59:20,397 INFO L138 SettingsManager]: * Command for external solver=z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in [2022-07-13 17:59:20,397 INFO L138 SettingsManager]: * Apply one-shot large block encoding in concurrent analysis=false [2022-07-13 17:59:20,397 INFO L138 SettingsManager]: * Automaton type used in concurrency analysis=PETRI_NET [2022-07-13 17:59:20,397 INFO L138 SettingsManager]: * Compute Hoare Annotation of negated interpolant automaton, abstraction and CFG=true [2022-07-13 17:59:20,398 INFO L138 SettingsManager]: * SMT solver=External_ModelsAndUnsatCoreMode WARNING: An illegal reflective access operation has occurred WARNING: Illegal reflective access by com.sun.xml.bind.v2.runtime.reflect.opt.Injector$1 (file:/storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/plugins/com.sun.xml.bind_2.2.0.v201505121915.jar) to method java.lang.ClassLoader.defineClass(java.lang.String,byte[],int,int) WARNING: Please consider reporting this to the maintainers of com.sun.xml.bind.v2.runtime.reflect.opt.Injector$1 WARNING: Use --illegal-access=warn to enable warnings of further illegal reflective access operations WARNING: All illegal access operations will be denied in a future release Applying setting for plugin de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator: Entry function -> main Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Witness directory -> /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Witness filename -> witness.graphml Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Write witness besides input file -> false Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Graph data specification -> CHECK( init(main()), LTL(G ! call(reach_error())) ) Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Graph data producer -> Automizer Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Graph data architecture -> 32bit Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Graph data programhash -> c8e3613a57f37f194f1fe75086d0eb5e0d997c2a9b69c99903e0a1a10a2db5eb [2022-07-13 17:59:20,638 INFO L75 nceAwareModelManager]: Repository-Root is: /tmp [2022-07-13 17:59:20,658 INFO L261 ainManager$Toolchain]: [Toolchain 1]: Applicable parser(s) successfully (re)initialized [2022-07-13 17:59:20,660 INFO L217 ainManager$Toolchain]: [Toolchain 1]: Toolchain selected. [2022-07-13 17:59:20,662 INFO L271 PluginConnector]: Initializing CDTParser... [2022-07-13 17:59:20,663 INFO L275 PluginConnector]: CDTParser initialized [2022-07-13 17:59:20,664 INFO L432 ainManager$Toolchain]: [Toolchain 1]: Parsing single file: /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/../sv-benchmarks/c/product-lines/minepump_spec3_product38.cil.c [2022-07-13 17:59:20,741 INFO L220 CDTParser]: Created temporary CDT project at /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/data/8353ac887/6f2ef6cbfd4147ceb8245d817b8a7796/FLAG1b54e0b25 [2022-07-13 17:59:21,177 INFO L306 CDTParser]: Found 1 translation units. [2022-07-13 17:59:21,179 INFO L160 CDTParser]: Scanning /storage/repos/ultimate/releaseScripts/default/sv-benchmarks/c/product-lines/minepump_spec3_product38.cil.c [2022-07-13 17:59:21,189 INFO L349 CDTParser]: About to delete temporary CDT project at /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/data/8353ac887/6f2ef6cbfd4147ceb8245d817b8a7796/FLAG1b54e0b25 [2022-07-13 17:59:21,543 INFO L357 CDTParser]: Successfully deleted /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/data/8353ac887/6f2ef6cbfd4147ceb8245d817b8a7796 [2022-07-13 17:59:21,545 INFO L299 ainManager$Toolchain]: ####################### [Toolchain 1] ####################### [2022-07-13 17:59:21,546 INFO L131 ToolchainWalker]: Walking toolchain with 6 elements. [2022-07-13 17:59:21,547 INFO L113 PluginConnector]: ------------------------CACSL2BoogieTranslator---------------------------- [2022-07-13 17:59:21,548 INFO L271 PluginConnector]: Initializing CACSL2BoogieTranslator... [2022-07-13 17:59:21,557 INFO L275 PluginConnector]: CACSL2BoogieTranslator initialized [2022-07-13 17:59:21,558 INFO L185 PluginConnector]: Executing the observer ACSLObjectContainerObserver from plugin CACSL2BoogieTranslator for "CDTParser AST 13.07 05:59:21" (1/1) ... [2022-07-13 17:59:21,559 INFO L205 PluginConnector]: Invalid model from CACSL2BoogieTranslator for observer de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator.ACSLObjectContainerObserver@483ce83d and model type de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 13.07 05:59:21, skipping insertion in model container [2022-07-13 17:59:21,560 INFO L185 PluginConnector]: Executing the observer CACSL2BoogieTranslatorObserver from plugin CACSL2BoogieTranslator for "CDTParser AST 13.07 05:59:21" (1/1) ... [2022-07-13 17:59:21,567 INFO L145 MainTranslator]: Starting translation in SV-COMP mode [2022-07-13 17:59:21,606 INFO L178 MainTranslator]: Built tables and reachable declarations [2022-07-13 17:59:21,817 WARN L230 ndardFunctionHandler]: Function reach_error is already implemented but we override the implementation for the call at /storage/repos/ultimate/releaseScripts/default/sv-benchmarks/c/product-lines/minepump_spec3_product38.cil.c[15422,15435] [2022-07-13 17:59:21,830 INFO L210 PostProcessor]: Analyzing one entry point: main [2022-07-13 17:59:21,847 INFO L203 MainTranslator]: Completed pre-run [2022-07-13 17:59:21,938 WARN L230 ndardFunctionHandler]: Function reach_error is already implemented but we override the implementation for the call at /storage/repos/ultimate/releaseScripts/default/sv-benchmarks/c/product-lines/minepump_spec3_product38.cil.c[15422,15435] [2022-07-13 17:59:21,950 INFO L210 PostProcessor]: Analyzing one entry point: main [2022-07-13 17:59:21,974 INFO L208 MainTranslator]: Completed translation [2022-07-13 17:59:21,975 INFO L202 PluginConnector]: Adding new model de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 13.07 05:59:21 WrapperNode [2022-07-13 17:59:21,975 INFO L132 PluginConnector]: ------------------------ END CACSL2BoogieTranslator---------------------------- [2022-07-13 17:59:21,976 INFO L113 PluginConnector]: ------------------------Boogie Procedure Inliner---------------------------- [2022-07-13 17:59:21,976 INFO L271 PluginConnector]: Initializing Boogie Procedure Inliner... [2022-07-13 17:59:21,977 INFO L275 PluginConnector]: Boogie Procedure Inliner initialized [2022-07-13 17:59:21,983 INFO L185 PluginConnector]: Executing the observer TypeChecker from plugin Boogie Procedure Inliner for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 13.07 05:59:21" (1/1) ... [2022-07-13 17:59:22,008 INFO L185 PluginConnector]: Executing the observer Inliner from plugin Boogie Procedure Inliner for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 13.07 05:59:21" (1/1) ... [2022-07-13 17:59:22,048 INFO L137 Inliner]: procedures = 54, calls = 155, calls flagged for inlining = 23, calls inlined = 20, statements flattened = 254 [2022-07-13 17:59:22,048 INFO L132 PluginConnector]: ------------------------ END Boogie Procedure Inliner---------------------------- [2022-07-13 17:59:22,050 INFO L113 PluginConnector]: ------------------------Boogie Preprocessor---------------------------- [2022-07-13 17:59:22,051 INFO L271 PluginConnector]: Initializing Boogie Preprocessor... [2022-07-13 17:59:22,051 INFO L275 PluginConnector]: Boogie Preprocessor initialized [2022-07-13 17:59:22,058 INFO L185 PluginConnector]: Executing the observer EnsureBoogieModelObserver from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 13.07 05:59:21" (1/1) ... [2022-07-13 17:59:22,058 INFO L185 PluginConnector]: Executing the observer TypeChecker from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 13.07 05:59:21" (1/1) ... [2022-07-13 17:59:22,060 INFO L185 PluginConnector]: Executing the observer ConstExpander from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 13.07 05:59:21" (1/1) ... [2022-07-13 17:59:22,060 INFO L185 PluginConnector]: Executing the observer StructExpander from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 13.07 05:59:21" (1/1) ... [2022-07-13 17:59:22,075 INFO L185 PluginConnector]: Executing the observer UnstructureCode from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 13.07 05:59:21" (1/1) ... [2022-07-13 17:59:22,079 INFO L185 PluginConnector]: Executing the observer FunctionInliner from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 13.07 05:59:21" (1/1) ... [2022-07-13 17:59:22,087 INFO L185 PluginConnector]: Executing the observer BoogieSymbolTableConstructor from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 13.07 05:59:21" (1/1) ... [2022-07-13 17:59:22,089 INFO L132 PluginConnector]: ------------------------ END Boogie Preprocessor---------------------------- [2022-07-13 17:59:22,090 INFO L113 PluginConnector]: ------------------------RCFGBuilder---------------------------- [2022-07-13 17:59:22,090 INFO L271 PluginConnector]: Initializing RCFGBuilder... [2022-07-13 17:59:22,090 INFO L275 PluginConnector]: RCFGBuilder initialized [2022-07-13 17:59:22,091 INFO L185 PluginConnector]: Executing the observer RCFGBuilderObserver from plugin RCFGBuilder for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 13.07 05:59:21" (1/1) ... [2022-07-13 17:59:22,100 INFO L173 SolverBuilder]: Constructing external solver with command: z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in -t:2000 [2022-07-13 17:59:22,111 INFO L189 MonitoredProcess]: No working directory specified, using /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 [2022-07-13 17:59:22,122 INFO L229 MonitoredProcess]: Starting monitored process 1 with /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in -t:2000 (exit command is (exit), workingDir is null) [2022-07-13 17:59:22,124 INFO L327 MonitoredProcess]: [MP /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in -t:2000 (1)] Waiting until timeout for monitored process [2022-07-13 17:59:22,152 INFO L130 BoogieDeclarations]: Found specification of procedure #Ultimate.allocInit [2022-07-13 17:59:22,152 INFO L130 BoogieDeclarations]: Found specification of procedure processEnvironment__wrappee__base [2022-07-13 17:59:22,152 INFO L138 BoogieDeclarations]: Found implementation of procedure processEnvironment__wrappee__base [2022-07-13 17:59:22,152 INFO L130 BoogieDeclarations]: Found specification of procedure isMethaneLevelCritical [2022-07-13 17:59:22,153 INFO L138 BoogieDeclarations]: Found implementation of procedure isMethaneLevelCritical [2022-07-13 17:59:22,153 INFO L130 BoogieDeclarations]: Found specification of procedure cleanup [2022-07-13 17:59:22,153 INFO L138 BoogieDeclarations]: Found implementation of procedure cleanup [2022-07-13 17:59:22,153 INFO L130 BoogieDeclarations]: Found specification of procedure timeShift [2022-07-13 17:59:22,153 INFO L138 BoogieDeclarations]: Found implementation of procedure timeShift [2022-07-13 17:59:22,153 INFO L130 BoogieDeclarations]: Found specification of procedure processEnvironment__wrappee__highWaterSensor [2022-07-13 17:59:22,154 INFO L138 BoogieDeclarations]: Found implementation of procedure processEnvironment__wrappee__highWaterSensor [2022-07-13 17:59:22,154 INFO L130 BoogieDeclarations]: Found specification of procedure waterRise [2022-07-13 17:59:22,154 INFO L138 BoogieDeclarations]: Found implementation of procedure waterRise [2022-07-13 17:59:22,154 INFO L130 BoogieDeclarations]: Found specification of procedure write~init~int [2022-07-13 17:59:22,154 INFO L130 BoogieDeclarations]: Found specification of procedure changeMethaneLevel [2022-07-13 17:59:22,154 INFO L138 BoogieDeclarations]: Found implementation of procedure changeMethaneLevel [2022-07-13 17:59:22,154 INFO L130 BoogieDeclarations]: Found specification of procedure ULTIMATE.start [2022-07-13 17:59:22,155 INFO L138 BoogieDeclarations]: Found implementation of procedure ULTIMATE.start [2022-07-13 17:59:22,214 INFO L234 CfgBuilder]: Building ICFG [2022-07-13 17:59:22,215 INFO L260 CfgBuilder]: Building CFG for each procedure with an implementation [2022-07-13 17:59:22,512 INFO L275 CfgBuilder]: Performing block encoding [2022-07-13 17:59:22,518 INFO L294 CfgBuilder]: Using the 1 location(s) as analysis (start of procedure ULTIMATE.start) [2022-07-13 17:59:22,519 INFO L299 CfgBuilder]: Removed 2 assume(true) statements. [2022-07-13 17:59:22,525 INFO L202 PluginConnector]: Adding new model de.uni_freiburg.informatik.ultimate.plugins.generator.rcfgbuilder CFG 13.07 05:59:22 BoogieIcfgContainer [2022-07-13 17:59:22,525 INFO L132 PluginConnector]: ------------------------ END RCFGBuilder---------------------------- [2022-07-13 17:59:22,527 INFO L113 PluginConnector]: ------------------------TraceAbstraction---------------------------- [2022-07-13 17:59:22,527 INFO L271 PluginConnector]: Initializing TraceAbstraction... [2022-07-13 17:59:22,531 INFO L275 PluginConnector]: TraceAbstraction initialized [2022-07-13 17:59:22,531 INFO L185 PluginConnector]: Executing the observer TraceAbstractionObserver from plugin TraceAbstraction for "CDTParser AST 13.07 05:59:21" (1/3) ... [2022-07-13 17:59:22,532 INFO L205 PluginConnector]: Invalid model from TraceAbstraction for observer de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction.TraceAbstractionObserver@9d49e28 and model type de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction AST 13.07 05:59:22, skipping insertion in model container [2022-07-13 17:59:22,532 INFO L185 PluginConnector]: Executing the observer TraceAbstractionObserver from plugin TraceAbstraction for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 13.07 05:59:21" (2/3) ... [2022-07-13 17:59:22,533 INFO L205 PluginConnector]: Invalid model from TraceAbstraction for observer de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction.TraceAbstractionObserver@9d49e28 and model type de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction AST 13.07 05:59:22, skipping insertion in model container [2022-07-13 17:59:22,533 INFO L185 PluginConnector]: Executing the observer TraceAbstractionObserver from plugin TraceAbstraction for "de.uni_freiburg.informatik.ultimate.plugins.generator.rcfgbuilder CFG 13.07 05:59:22" (3/3) ... [2022-07-13 17:59:22,535 INFO L111 eAbstractionObserver]: Analyzing ICFG minepump_spec3_product38.cil.c [2022-07-13 17:59:22,556 INFO L201 ceAbstractionStarter]: Automizer settings: Hoare:true NWA Interpolation:FPandBP Determinization: PREDICATE_ABSTRACTION [2022-07-13 17:59:22,557 INFO L160 ceAbstractionStarter]: Applying trace abstraction to program that has 1 error locations. [2022-07-13 17:59:22,609 INFO L356 AbstractCegarLoop]: ======== Iteration 0 == of CEGAR loop == AllErrorsAtOnce ======== [2022-07-13 17:59:22,615 INFO L357 AbstractCegarLoop]: Settings: SEPARATE_VIOLATION_CHECK=true, mInterprocedural=true, mMaxIterations=1000000, mWatchIteration=1000000, mArtifact=RCFG, mInterpolation=FPandBP, mInterpolantAutomaton=STRAIGHT_LINE, mDumpAutomata=false, mAutomataFormat=ATS_NUMERATE, mDumpPath=., mDeterminiation=PREDICATE_ABSTRACTION, mMinimize=MINIMIZE_SEVPA, mHoare=true, mAutomataTypeConcurrency=PETRI_NET, mHoareTripleChecks=INCREMENTAL, mHoareAnnotationPositions=LoopsAndPotentialCycles, mDumpOnlyReuseAutomata=false, mLimitTraceHistogram=0, mErrorLocTimeLimit=0, mLimitPathProgramCount=0, mCollectInterpolantStatistics=true, mHeuristicEmptinessCheck=false, mHeuristicEmptinessCheckAStarHeuristic=ZERO, mHeuristicEmptinessCheckAStarHeuristicRandomSeed=1337, mHeuristicEmptinessCheckSmtFeatureScoringMethod=DAGSIZE, mSMTFeatureExtraction=false, mSMTFeatureExtractionDumpPath=., mOverrideInterpolantAutomaton=false, mMcrInterpolantMethod=WP, mPorIndependenceSettings=de.uni_freiburg.informatik.ultimate.lib.tracecheckerutils.partialorder.independence.IndependenceSettings@445f34b3, mLbeIndependenceSettings=de.uni_freiburg.informatik.ultimate.lib.tracecheckerutils.partialorder.independence.IndependenceSettings@636293b9 [2022-07-13 17:59:22,616 INFO L358 AbstractCegarLoop]: Starting to check reachability of 1 error locations. [2022-07-13 17:59:22,619 INFO L276 IsEmpty]: Start isEmpty. Operand has 88 states, 67 states have (on average 1.3880597014925373) internal successors, (93), 75 states have internal predecessors, (93), 12 states have call successors, (12), 7 states have call predecessors, (12), 7 states have return successors, (12), 10 states have call predecessors, (12), 12 states have call successors, (12) [2022-07-13 17:59:22,628 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 26 [2022-07-13 17:59:22,628 INFO L187 NwaCegarLoop]: Found error trace [2022-07-13 17:59:22,629 INFO L195 NwaCegarLoop]: trace histogram [1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-07-13 17:59:22,629 INFO L420 AbstractCegarLoop]: === Iteration 1 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2022-07-13 17:59:22,633 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2022-07-13 17:59:22,634 INFO L85 PathProgramCache]: Analyzing trace with hash -1928340701, now seen corresponding path program 1 times [2022-07-13 17:59:22,642 INFO L118 FreeRefinementEngine]: Executing refinement strategy CAMEL [2022-07-13 17:59:22,642 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [426601307] [2022-07-13 17:59:22,642 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-07-13 17:59:22,643 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2022-07-13 17:59:22,801 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-07-13 17:59:22,870 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 14 [2022-07-13 17:59:22,875 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-07-13 17:59:22,882 INFO L134 CoverageAnalysis]: Checked inductivity of 0 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2022-07-13 17:59:22,884 INFO L136 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2022-07-13 17:59:22,884 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [426601307] [2022-07-13 17:59:22,885 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [426601307] provided 1 perfect and 0 imperfect interpolant sequences [2022-07-13 17:59:22,886 INFO L184 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2022-07-13 17:59:22,886 INFO L197 FreeRefinementEngine]: Number of different interpolants: perfect sequences [2] imperfect sequences [] total 2 [2022-07-13 17:59:22,888 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [2055879888] [2022-07-13 17:59:22,889 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2022-07-13 17:59:22,895 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 2 states [2022-07-13 17:59:22,896 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2022-07-13 17:59:22,923 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 2 interpolants. [2022-07-13 17:59:22,924 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=1, Invalid=1, Unknown=0, NotChecked=0, Total=2 [2022-07-13 17:59:22,927 INFO L87 Difference]: Start difference. First operand has 88 states, 67 states have (on average 1.3880597014925373) internal successors, (93), 75 states have internal predecessors, (93), 12 states have call successors, (12), 7 states have call predecessors, (12), 7 states have return successors, (12), 10 states have call predecessors, (12), 12 states have call successors, (12) Second operand has 2 states, 2 states have (on average 10.5) internal successors, (21), 2 states have internal predecessors, (21), 1 states have call successors, (3), 2 states have call predecessors, (3), 1 states have return successors, (1), 1 states have call predecessors, (1), 1 states have call successors, (1) [2022-07-13 17:59:22,982 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-07-13 17:59:22,982 INFO L93 Difference]: Finished difference Result 168 states and 229 transitions. [2022-07-13 17:59:22,983 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 2 states. [2022-07-13 17:59:22,984 INFO L78 Accepts]: Start accepts. Automaton has has 2 states, 2 states have (on average 10.5) internal successors, (21), 2 states have internal predecessors, (21), 1 states have call successors, (3), 2 states have call predecessors, (3), 1 states have return successors, (1), 1 states have call predecessors, (1), 1 states have call successors, (1) Word has length 25 [2022-07-13 17:59:22,984 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2022-07-13 17:59:22,997 INFO L225 Difference]: With dead ends: 168 [2022-07-13 17:59:22,997 INFO L226 Difference]: Without dead ends: 79 [2022-07-13 17:59:23,004 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 4 GetRequests, 4 SyntacticMatches, 0 SemanticMatches, 0 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 0 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=1, Invalid=1, Unknown=0, NotChecked=0, Total=2 [2022-07-13 17:59:23,008 INFO L413 NwaCegarLoop]: 111 mSDtfsCounter, 0 mSDsluCounter, 0 mSDsCounter, 0 mSdLazyCounter, 0 mSolverCounterSat, 0 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.0s Time, 0 mProtectedPredicate, 0 mProtectedAction, 0 SdHoareTripleChecker+Valid, 111 SdHoareTripleChecker+Invalid, 0 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 0 IncrementalHoareTripleChecker+Valid, 0 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.0s IncrementalHoareTripleChecker+Time [2022-07-13 17:59:23,009 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [0 Valid, 111 Invalid, 0 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [0 Valid, 0 Invalid, 0 Unknown, 0 Unchecked, 0.0s Time] [2022-07-13 17:59:23,024 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 79 states. [2022-07-13 17:59:23,056 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 79 to 79. [2022-07-13 17:59:23,057 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 79 states, 60 states have (on average 1.3166666666666667) internal successors, (79), 67 states have internal predecessors, (79), 12 states have call successors, (12), 7 states have call predecessors, (12), 6 states have return successors, (11), 9 states have call predecessors, (11), 11 states have call successors, (11) [2022-07-13 17:59:23,062 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 79 states to 79 states and 102 transitions. [2022-07-13 17:59:23,064 INFO L78 Accepts]: Start accepts. Automaton has 79 states and 102 transitions. Word has length 25 [2022-07-13 17:59:23,065 INFO L84 Accepts]: Finished accepts. word is rejected. [2022-07-13 17:59:23,065 INFO L495 AbstractCegarLoop]: Abstraction has 79 states and 102 transitions. [2022-07-13 17:59:23,066 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 2 states, 2 states have (on average 10.5) internal successors, (21), 2 states have internal predecessors, (21), 1 states have call successors, (3), 2 states have call predecessors, (3), 1 states have return successors, (1), 1 states have call predecessors, (1), 1 states have call successors, (1) [2022-07-13 17:59:23,066 INFO L276 IsEmpty]: Start isEmpty. Operand 79 states and 102 transitions. [2022-07-13 17:59:23,069 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 27 [2022-07-13 17:59:23,069 INFO L187 NwaCegarLoop]: Found error trace [2022-07-13 17:59:23,070 INFO L195 NwaCegarLoop]: trace histogram [1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-07-13 17:59:23,070 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable0 [2022-07-13 17:59:23,070 INFO L420 AbstractCegarLoop]: === Iteration 2 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2022-07-13 17:59:23,072 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2022-07-13 17:59:23,072 INFO L85 PathProgramCache]: Analyzing trace with hash -2041135719, now seen corresponding path program 1 times [2022-07-13 17:59:23,072 INFO L118 FreeRefinementEngine]: Executing refinement strategy CAMEL [2022-07-13 17:59:23,073 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [632943121] [2022-07-13 17:59:23,073 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-07-13 17:59:23,074 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2022-07-13 17:59:23,112 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-07-13 17:59:23,153 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 15 [2022-07-13 17:59:23,154 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-07-13 17:59:23,156 INFO L134 CoverageAnalysis]: Checked inductivity of 0 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2022-07-13 17:59:23,157 INFO L136 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2022-07-13 17:59:23,157 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [632943121] [2022-07-13 17:59:23,157 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [632943121] provided 1 perfect and 0 imperfect interpolant sequences [2022-07-13 17:59:23,157 INFO L184 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2022-07-13 17:59:23,157 INFO L197 FreeRefinementEngine]: Number of different interpolants: perfect sequences [3] imperfect sequences [] total 3 [2022-07-13 17:59:23,157 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [1563309410] [2022-07-13 17:59:23,157 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2022-07-13 17:59:23,158 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 3 states [2022-07-13 17:59:23,159 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2022-07-13 17:59:23,159 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 3 interpolants. [2022-07-13 17:59:23,159 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=3, Invalid=3, Unknown=0, NotChecked=0, Total=6 [2022-07-13 17:59:23,160 INFO L87 Difference]: Start difference. First operand 79 states and 102 transitions. Second operand has 3 states, 3 states have (on average 7.333333333333333) internal successors, (22), 3 states have internal predecessors, (22), 1 states have call successors, (3), 2 states have call predecessors, (3), 1 states have return successors, (1), 1 states have call predecessors, (1), 1 states have call successors, (1) [2022-07-13 17:59:23,189 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-07-13 17:59:23,190 INFO L93 Difference]: Finished difference Result 123 states and 159 transitions. [2022-07-13 17:59:23,193 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 3 states. [2022-07-13 17:59:23,193 INFO L78 Accepts]: Start accepts. Automaton has has 3 states, 3 states have (on average 7.333333333333333) internal successors, (22), 3 states have internal predecessors, (22), 1 states have call successors, (3), 2 states have call predecessors, (3), 1 states have return successors, (1), 1 states have call predecessors, (1), 1 states have call successors, (1) Word has length 26 [2022-07-13 17:59:23,194 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2022-07-13 17:59:23,195 INFO L225 Difference]: With dead ends: 123 [2022-07-13 17:59:23,196 INFO L226 Difference]: Without dead ends: 70 [2022-07-13 17:59:23,198 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 5 GetRequests, 4 SyntacticMatches, 0 SemanticMatches, 1 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 0 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=3, Invalid=3, Unknown=0, NotChecked=0, Total=6 [2022-07-13 17:59:23,199 INFO L413 NwaCegarLoop]: 89 mSDtfsCounter, 13 mSDsluCounter, 72 mSDsCounter, 0 mSdLazyCounter, 1 mSolverCounterSat, 0 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.0s Time, 0 mProtectedPredicate, 0 mProtectedAction, 16 SdHoareTripleChecker+Valid, 161 SdHoareTripleChecker+Invalid, 1 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 0 IncrementalHoareTripleChecker+Valid, 1 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.0s IncrementalHoareTripleChecker+Time [2022-07-13 17:59:23,199 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [16 Valid, 161 Invalid, 1 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [0 Valid, 1 Invalid, 0 Unknown, 0 Unchecked, 0.0s Time] [2022-07-13 17:59:23,200 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 70 states. [2022-07-13 17:59:23,205 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 70 to 70. [2022-07-13 17:59:23,206 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 70 states, 54 states have (on average 1.3333333333333333) internal successors, (72), 61 states have internal predecessors, (72), 9 states have call successors, (9), 6 states have call predecessors, (9), 6 states have return successors, (9), 7 states have call predecessors, (9), 9 states have call successors, (9) [2022-07-13 17:59:23,206 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 70 states to 70 states and 90 transitions. [2022-07-13 17:59:23,206 INFO L78 Accepts]: Start accepts. Automaton has 70 states and 90 transitions. Word has length 26 [2022-07-13 17:59:23,207 INFO L84 Accepts]: Finished accepts. word is rejected. [2022-07-13 17:59:23,207 INFO L495 AbstractCegarLoop]: Abstraction has 70 states and 90 transitions. [2022-07-13 17:59:23,208 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 3 states, 3 states have (on average 7.333333333333333) internal successors, (22), 3 states have internal predecessors, (22), 1 states have call successors, (3), 2 states have call predecessors, (3), 1 states have return successors, (1), 1 states have call predecessors, (1), 1 states have call successors, (1) [2022-07-13 17:59:23,209 INFO L276 IsEmpty]: Start isEmpty. Operand 70 states and 90 transitions. [2022-07-13 17:59:23,214 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 32 [2022-07-13 17:59:23,214 INFO L187 NwaCegarLoop]: Found error trace [2022-07-13 17:59:23,214 INFO L195 NwaCegarLoop]: trace histogram [1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-07-13 17:59:23,214 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable1 [2022-07-13 17:59:23,214 INFO L420 AbstractCegarLoop]: === Iteration 3 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2022-07-13 17:59:23,215 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2022-07-13 17:59:23,215 INFO L85 PathProgramCache]: Analyzing trace with hash 1999159483, now seen corresponding path program 1 times [2022-07-13 17:59:23,216 INFO L118 FreeRefinementEngine]: Executing refinement strategy CAMEL [2022-07-13 17:59:23,216 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [973530243] [2022-07-13 17:59:23,216 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-07-13 17:59:23,216 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2022-07-13 17:59:23,254 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-07-13 17:59:23,339 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 20 [2022-07-13 17:59:23,341 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-07-13 17:59:23,342 INFO L134 CoverageAnalysis]: Checked inductivity of 0 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2022-07-13 17:59:23,343 INFO L136 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2022-07-13 17:59:23,343 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [973530243] [2022-07-13 17:59:23,343 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [973530243] provided 1 perfect and 0 imperfect interpolant sequences [2022-07-13 17:59:23,343 INFO L184 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2022-07-13 17:59:23,343 INFO L197 FreeRefinementEngine]: Number of different interpolants: perfect sequences [6] imperfect sequences [] total 6 [2022-07-13 17:59:23,344 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [560429737] [2022-07-13 17:59:23,344 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2022-07-13 17:59:23,344 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 6 states [2022-07-13 17:59:23,344 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2022-07-13 17:59:23,345 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 6 interpolants. [2022-07-13 17:59:23,345 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=10, Invalid=20, Unknown=0, NotChecked=0, Total=30 [2022-07-13 17:59:23,345 INFO L87 Difference]: Start difference. First operand 70 states and 90 transitions. Second operand has 6 states, 6 states have (on average 4.666666666666667) internal successors, (28), 6 states have internal predecessors, (28), 2 states have call successors, (2), 2 states have call predecessors, (2), 1 states have return successors, (1), 1 states have call predecessors, (1), 1 states have call successors, (1) [2022-07-13 17:59:23,477 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-07-13 17:59:23,477 INFO L93 Difference]: Finished difference Result 133 states and 174 transitions. [2022-07-13 17:59:23,478 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 5 states. [2022-07-13 17:59:23,478 INFO L78 Accepts]: Start accepts. Automaton has has 6 states, 6 states have (on average 4.666666666666667) internal successors, (28), 6 states have internal predecessors, (28), 2 states have call successors, (2), 2 states have call predecessors, (2), 1 states have return successors, (1), 1 states have call predecessors, (1), 1 states have call successors, (1) Word has length 31 [2022-07-13 17:59:23,478 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2022-07-13 17:59:23,481 INFO L225 Difference]: With dead ends: 133 [2022-07-13 17:59:23,481 INFO L226 Difference]: Without dead ends: 70 [2022-07-13 17:59:23,483 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 9 GetRequests, 3 SyntacticMatches, 0 SemanticMatches, 6 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 0 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=22, Invalid=34, Unknown=0, NotChecked=0, Total=56 [2022-07-13 17:59:23,488 INFO L413 NwaCegarLoop]: 83 mSDtfsCounter, 115 mSDsluCounter, 102 mSDsCounter, 0 mSdLazyCounter, 41 mSolverCounterSat, 13 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.1s Time, 0 mProtectedPredicate, 0 mProtectedAction, 115 SdHoareTripleChecker+Valid, 185 SdHoareTripleChecker+Invalid, 54 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 13 IncrementalHoareTripleChecker+Valid, 41 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.1s IncrementalHoareTripleChecker+Time [2022-07-13 17:59:23,489 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [115 Valid, 185 Invalid, 54 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [13 Valid, 41 Invalid, 0 Unknown, 0 Unchecked, 0.1s Time] [2022-07-13 17:59:23,490 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 70 states. [2022-07-13 17:59:23,503 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 70 to 70. [2022-07-13 17:59:23,505 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 70 states, 54 states have (on average 1.3148148148148149) internal successors, (71), 61 states have internal predecessors, (71), 9 states have call successors, (9), 6 states have call predecessors, (9), 6 states have return successors, (9), 7 states have call predecessors, (9), 9 states have call successors, (9) [2022-07-13 17:59:23,506 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 70 states to 70 states and 89 transitions. [2022-07-13 17:59:23,507 INFO L78 Accepts]: Start accepts. Automaton has 70 states and 89 transitions. Word has length 31 [2022-07-13 17:59:23,507 INFO L84 Accepts]: Finished accepts. word is rejected. [2022-07-13 17:59:23,507 INFO L495 AbstractCegarLoop]: Abstraction has 70 states and 89 transitions. [2022-07-13 17:59:23,507 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 6 states, 6 states have (on average 4.666666666666667) internal successors, (28), 6 states have internal predecessors, (28), 2 states have call successors, (2), 2 states have call predecessors, (2), 1 states have return successors, (1), 1 states have call predecessors, (1), 1 states have call successors, (1) [2022-07-13 17:59:23,508 INFO L276 IsEmpty]: Start isEmpty. Operand 70 states and 89 transitions. [2022-07-13 17:59:23,510 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 42 [2022-07-13 17:59:23,510 INFO L187 NwaCegarLoop]: Found error trace [2022-07-13 17:59:23,511 INFO L195 NwaCegarLoop]: trace histogram [1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-07-13 17:59:23,511 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable2 [2022-07-13 17:59:23,511 INFO L420 AbstractCegarLoop]: === Iteration 4 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2022-07-13 17:59:23,512 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2022-07-13 17:59:23,512 INFO L85 PathProgramCache]: Analyzing trace with hash 1128329484, now seen corresponding path program 1 times [2022-07-13 17:59:23,512 INFO L118 FreeRefinementEngine]: Executing refinement strategy CAMEL [2022-07-13 17:59:23,513 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [86655280] [2022-07-13 17:59:23,513 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-07-13 17:59:23,513 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2022-07-13 17:59:23,546 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-07-13 17:59:23,574 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 20 [2022-07-13 17:59:23,577 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-07-13 17:59:23,589 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 2 [2022-07-13 17:59:23,591 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-07-13 17:59:23,596 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 30 [2022-07-13 17:59:23,598 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-07-13 17:59:23,603 INFO L134 CoverageAnalysis]: Checked inductivity of 0 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2022-07-13 17:59:23,603 INFO L136 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2022-07-13 17:59:23,603 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [86655280] [2022-07-13 17:59:23,604 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [86655280] provided 1 perfect and 0 imperfect interpolant sequences [2022-07-13 17:59:23,604 INFO L184 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2022-07-13 17:59:23,604 INFO L197 FreeRefinementEngine]: Number of different interpolants: perfect sequences [5] imperfect sequences [] total 5 [2022-07-13 17:59:23,604 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [1397127904] [2022-07-13 17:59:23,605 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2022-07-13 17:59:23,606 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 5 states [2022-07-13 17:59:23,606 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2022-07-13 17:59:23,607 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 5 interpolants. [2022-07-13 17:59:23,607 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=7, Invalid=13, Unknown=0, NotChecked=0, Total=20 [2022-07-13 17:59:23,607 INFO L87 Difference]: Start difference. First operand 70 states and 89 transitions. Second operand has 5 states, 5 states have (on average 6.8) internal successors, (34), 5 states have internal predecessors, (34), 3 states have call successors, (4), 3 states have call predecessors, (4), 2 states have return successors, (3), 2 states have call predecessors, (3), 3 states have call successors, (3) [2022-07-13 17:59:23,768 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-07-13 17:59:23,769 INFO L93 Difference]: Finished difference Result 211 states and 269 transitions. [2022-07-13 17:59:23,769 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 7 states. [2022-07-13 17:59:23,770 INFO L78 Accepts]: Start accepts. Automaton has has 5 states, 5 states have (on average 6.8) internal successors, (34), 5 states have internal predecessors, (34), 3 states have call successors, (4), 3 states have call predecessors, (4), 2 states have return successors, (3), 2 states have call predecessors, (3), 3 states have call successors, (3) Word has length 41 [2022-07-13 17:59:23,770 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2022-07-13 17:59:23,774 INFO L225 Difference]: With dead ends: 211 [2022-07-13 17:59:23,774 INFO L226 Difference]: Without dead ends: 148 [2022-07-13 17:59:23,775 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 15 GetRequests, 9 SyntacticMatches, 0 SemanticMatches, 6 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 3 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=19, Invalid=37, Unknown=0, NotChecked=0, Total=56 [2022-07-13 17:59:23,777 INFO L413 NwaCegarLoop]: 133 mSDtfsCounter, 167 mSDsluCounter, 173 mSDsCounter, 0 mSdLazyCounter, 98 mSolverCounterSat, 45 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.1s Time, 0 mProtectedPredicate, 0 mProtectedAction, 169 SdHoareTripleChecker+Valid, 306 SdHoareTripleChecker+Invalid, 143 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 45 IncrementalHoareTripleChecker+Valid, 98 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.1s IncrementalHoareTripleChecker+Time [2022-07-13 17:59:23,777 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [169 Valid, 306 Invalid, 143 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [45 Valid, 98 Invalid, 0 Unknown, 0 Unchecked, 0.1s Time] [2022-07-13 17:59:23,778 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 148 states. [2022-07-13 17:59:23,791 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 148 to 142. [2022-07-13 17:59:23,792 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 142 states, 110 states have (on average 1.2727272727272727) internal successors, (140), 117 states have internal predecessors, (140), 15 states have call successors, (15), 13 states have call predecessors, (15), 16 states have return successors, (20), 16 states have call predecessors, (20), 15 states have call successors, (20) [2022-07-13 17:59:23,793 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 142 states to 142 states and 175 transitions. [2022-07-13 17:59:23,793 INFO L78 Accepts]: Start accepts. Automaton has 142 states and 175 transitions. Word has length 41 [2022-07-13 17:59:23,793 INFO L84 Accepts]: Finished accepts. word is rejected. [2022-07-13 17:59:23,794 INFO L495 AbstractCegarLoop]: Abstraction has 142 states and 175 transitions. [2022-07-13 17:59:23,794 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 5 states, 5 states have (on average 6.8) internal successors, (34), 5 states have internal predecessors, (34), 3 states have call successors, (4), 3 states have call predecessors, (4), 2 states have return successors, (3), 2 states have call predecessors, (3), 3 states have call successors, (3) [2022-07-13 17:59:23,794 INFO L276 IsEmpty]: Start isEmpty. Operand 142 states and 175 transitions. [2022-07-13 17:59:23,795 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 46 [2022-07-13 17:59:23,795 INFO L187 NwaCegarLoop]: Found error trace [2022-07-13 17:59:23,795 INFO L195 NwaCegarLoop]: trace histogram [1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-07-13 17:59:23,795 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable3 [2022-07-13 17:59:23,796 INFO L420 AbstractCegarLoop]: === Iteration 5 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2022-07-13 17:59:23,796 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2022-07-13 17:59:23,796 INFO L85 PathProgramCache]: Analyzing trace with hash 1086887613, now seen corresponding path program 1 times [2022-07-13 17:59:23,797 INFO L118 FreeRefinementEngine]: Executing refinement strategy CAMEL [2022-07-13 17:59:23,797 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [557277111] [2022-07-13 17:59:23,797 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-07-13 17:59:23,797 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2022-07-13 17:59:23,814 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-07-13 17:59:23,841 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 20 [2022-07-13 17:59:23,848 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-07-13 17:59:23,882 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 34 [2022-07-13 17:59:23,884 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-07-13 17:59:23,886 INFO L134 CoverageAnalysis]: Checked inductivity of 0 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2022-07-13 17:59:23,888 INFO L136 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2022-07-13 17:59:23,889 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [557277111] [2022-07-13 17:59:23,889 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [557277111] provided 1 perfect and 0 imperfect interpolant sequences [2022-07-13 17:59:23,889 INFO L184 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2022-07-13 17:59:23,890 INFO L197 FreeRefinementEngine]: Number of different interpolants: perfect sequences [6] imperfect sequences [] total 6 [2022-07-13 17:59:23,891 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [1103185172] [2022-07-13 17:59:23,891 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2022-07-13 17:59:23,892 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 6 states [2022-07-13 17:59:23,892 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2022-07-13 17:59:23,895 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 6 interpolants. [2022-07-13 17:59:23,895 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=9, Invalid=21, Unknown=0, NotChecked=0, Total=30 [2022-07-13 17:59:23,895 INFO L87 Difference]: Start difference. First operand 142 states and 175 transitions. Second operand has 6 states, 6 states have (on average 6.666666666666667) internal successors, (40), 5 states have internal predecessors, (40), 2 states have call successors, (3), 2 states have call predecessors, (3), 2 states have return successors, (2), 1 states have call predecessors, (2), 2 states have call successors, (2) [2022-07-13 17:59:24,027 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-07-13 17:59:24,028 INFO L93 Difference]: Finished difference Result 285 states and 355 transitions. [2022-07-13 17:59:24,028 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 7 states. [2022-07-13 17:59:24,029 INFO L78 Accepts]: Start accepts. Automaton has has 6 states, 6 states have (on average 6.666666666666667) internal successors, (40), 5 states have internal predecessors, (40), 2 states have call successors, (3), 2 states have call predecessors, (3), 2 states have return successors, (2), 1 states have call predecessors, (2), 2 states have call successors, (2) Word has length 45 [2022-07-13 17:59:24,029 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2022-07-13 17:59:24,030 INFO L225 Difference]: With dead ends: 285 [2022-07-13 17:59:24,030 INFO L226 Difference]: Without dead ends: 150 [2022-07-13 17:59:24,031 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 14 GetRequests, 6 SyntacticMatches, 0 SemanticMatches, 8 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 3 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=32, Invalid=58, Unknown=0, NotChecked=0, Total=90 [2022-07-13 17:59:24,032 INFO L413 NwaCegarLoop]: 93 mSDtfsCounter, 59 mSDsluCounter, 276 mSDsCounter, 0 mSdLazyCounter, 112 mSolverCounterSat, 18 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.1s Time, 0 mProtectedPredicate, 0 mProtectedAction, 62 SdHoareTripleChecker+Valid, 369 SdHoareTripleChecker+Invalid, 130 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 18 IncrementalHoareTripleChecker+Valid, 112 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.1s IncrementalHoareTripleChecker+Time [2022-07-13 17:59:24,032 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [62 Valid, 369 Invalid, 130 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [18 Valid, 112 Invalid, 0 Unknown, 0 Unchecked, 0.1s Time] [2022-07-13 17:59:24,033 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 150 states. [2022-07-13 17:59:24,043 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 150 to 145. [2022-07-13 17:59:24,044 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 145 states, 113 states have (on average 1.2654867256637168) internal successors, (143), 120 states have internal predecessors, (143), 15 states have call successors, (15), 13 states have call predecessors, (15), 16 states have return successors, (20), 16 states have call predecessors, (20), 15 states have call successors, (20) [2022-07-13 17:59:24,045 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 145 states to 145 states and 178 transitions. [2022-07-13 17:59:24,045 INFO L78 Accepts]: Start accepts. Automaton has 145 states and 178 transitions. Word has length 45 [2022-07-13 17:59:24,045 INFO L84 Accepts]: Finished accepts. word is rejected. [2022-07-13 17:59:24,045 INFO L495 AbstractCegarLoop]: Abstraction has 145 states and 178 transitions. [2022-07-13 17:59:24,046 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 6 states, 6 states have (on average 6.666666666666667) internal successors, (40), 5 states have internal predecessors, (40), 2 states have call successors, (3), 2 states have call predecessors, (3), 2 states have return successors, (2), 1 states have call predecessors, (2), 2 states have call successors, (2) [2022-07-13 17:59:24,046 INFO L276 IsEmpty]: Start isEmpty. Operand 145 states and 178 transitions. [2022-07-13 17:59:24,046 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 46 [2022-07-13 17:59:24,047 INFO L187 NwaCegarLoop]: Found error trace [2022-07-13 17:59:24,047 INFO L195 NwaCegarLoop]: trace histogram [1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-07-13 17:59:24,047 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable4 [2022-07-13 17:59:24,047 INFO L420 AbstractCegarLoop]: === Iteration 6 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2022-07-13 17:59:24,048 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2022-07-13 17:59:24,048 INFO L85 PathProgramCache]: Analyzing trace with hash 269239163, now seen corresponding path program 1 times [2022-07-13 17:59:24,048 INFO L118 FreeRefinementEngine]: Executing refinement strategy CAMEL [2022-07-13 17:59:24,048 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [398615233] [2022-07-13 17:59:24,048 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-07-13 17:59:24,049 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2022-07-13 17:59:24,063 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-07-13 17:59:24,086 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 20 [2022-07-13 17:59:24,090 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-07-13 17:59:24,105 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 34 [2022-07-13 17:59:24,106 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-07-13 17:59:24,107 INFO L134 CoverageAnalysis]: Checked inductivity of 0 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2022-07-13 17:59:24,108 INFO L136 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2022-07-13 17:59:24,108 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [398615233] [2022-07-13 17:59:24,108 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [398615233] provided 1 perfect and 0 imperfect interpolant sequences [2022-07-13 17:59:24,108 INFO L184 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2022-07-13 17:59:24,108 INFO L197 FreeRefinementEngine]: Number of different interpolants: perfect sequences [7] imperfect sequences [] total 7 [2022-07-13 17:59:24,109 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [1551667759] [2022-07-13 17:59:24,109 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2022-07-13 17:59:24,109 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 7 states [2022-07-13 17:59:24,109 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2022-07-13 17:59:24,110 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 7 interpolants. [2022-07-13 17:59:24,110 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=11, Invalid=31, Unknown=0, NotChecked=0, Total=42 [2022-07-13 17:59:24,110 INFO L87 Difference]: Start difference. First operand 145 states and 178 transitions. Second operand has 7 states, 7 states have (on average 5.714285714285714) internal successors, (40), 6 states have internal predecessors, (40), 2 states have call successors, (3), 2 states have call predecessors, (3), 2 states have return successors, (2), 1 states have call predecessors, (2), 2 states have call successors, (2) [2022-07-13 17:59:24,254 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-07-13 17:59:24,254 INFO L93 Difference]: Finished difference Result 293 states and 366 transitions. [2022-07-13 17:59:24,255 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 7 states. [2022-07-13 17:59:24,255 INFO L78 Accepts]: Start accepts. Automaton has has 7 states, 7 states have (on average 5.714285714285714) internal successors, (40), 6 states have internal predecessors, (40), 2 states have call successors, (3), 2 states have call predecessors, (3), 2 states have return successors, (2), 1 states have call predecessors, (2), 2 states have call successors, (2) Word has length 45 [2022-07-13 17:59:24,256 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2022-07-13 17:59:24,260 INFO L225 Difference]: With dead ends: 293 [2022-07-13 17:59:24,260 INFO L226 Difference]: Without dead ends: 155 [2022-07-13 17:59:24,261 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 16 GetRequests, 8 SyntacticMatches, 0 SemanticMatches, 8 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 2 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=25, Invalid=65, Unknown=0, NotChecked=0, Total=90 [2022-07-13 17:59:24,263 INFO L413 NwaCegarLoop]: 92 mSDtfsCounter, 95 mSDsluCounter, 315 mSDsCounter, 0 mSdLazyCounter, 146 mSolverCounterSat, 20 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.1s Time, 0 mProtectedPredicate, 0 mProtectedAction, 99 SdHoareTripleChecker+Valid, 407 SdHoareTripleChecker+Invalid, 166 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 20 IncrementalHoareTripleChecker+Valid, 146 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.1s IncrementalHoareTripleChecker+Time [2022-07-13 17:59:24,265 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [99 Valid, 407 Invalid, 166 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [20 Valid, 146 Invalid, 0 Unknown, 0 Unchecked, 0.1s Time] [2022-07-13 17:59:24,266 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 155 states. [2022-07-13 17:59:24,288 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 155 to 147. [2022-07-13 17:59:24,292 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 147 states, 115 states have (on average 1.2608695652173914) internal successors, (145), 122 states have internal predecessors, (145), 15 states have call successors, (15), 13 states have call predecessors, (15), 16 states have return successors, (20), 16 states have call predecessors, (20), 15 states have call successors, (20) [2022-07-13 17:59:24,294 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 147 states to 147 states and 180 transitions. [2022-07-13 17:59:24,294 INFO L78 Accepts]: Start accepts. Automaton has 147 states and 180 transitions. Word has length 45 [2022-07-13 17:59:24,295 INFO L84 Accepts]: Finished accepts. word is rejected. [2022-07-13 17:59:24,295 INFO L495 AbstractCegarLoop]: Abstraction has 147 states and 180 transitions. [2022-07-13 17:59:24,295 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 7 states, 7 states have (on average 5.714285714285714) internal successors, (40), 6 states have internal predecessors, (40), 2 states have call successors, (3), 2 states have call predecessors, (3), 2 states have return successors, (2), 1 states have call predecessors, (2), 2 states have call successors, (2) [2022-07-13 17:59:24,295 INFO L276 IsEmpty]: Start isEmpty. Operand 147 states and 180 transitions. [2022-07-13 17:59:24,298 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 46 [2022-07-13 17:59:24,299 INFO L187 NwaCegarLoop]: Found error trace [2022-07-13 17:59:24,299 INFO L195 NwaCegarLoop]: trace histogram [1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-07-13 17:59:24,299 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable5 [2022-07-13 17:59:24,299 INFO L420 AbstractCegarLoop]: === Iteration 7 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2022-07-13 17:59:24,300 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2022-07-13 17:59:24,300 INFO L85 PathProgramCache]: Analyzing trace with hash 488093881, now seen corresponding path program 1 times [2022-07-13 17:59:24,300 INFO L118 FreeRefinementEngine]: Executing refinement strategy CAMEL [2022-07-13 17:59:24,300 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [2035911755] [2022-07-13 17:59:24,301 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-07-13 17:59:24,301 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2022-07-13 17:59:24,318 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-07-13 17:59:24,346 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 20 [2022-07-13 17:59:24,349 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-07-13 17:59:24,358 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 34 [2022-07-13 17:59:24,359 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-07-13 17:59:24,360 INFO L134 CoverageAnalysis]: Checked inductivity of 0 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2022-07-13 17:59:24,361 INFO L136 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2022-07-13 17:59:24,361 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [2035911755] [2022-07-13 17:59:24,361 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [2035911755] provided 1 perfect and 0 imperfect interpolant sequences [2022-07-13 17:59:24,361 INFO L184 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2022-07-13 17:59:24,361 INFO L197 FreeRefinementEngine]: Number of different interpolants: perfect sequences [5] imperfect sequences [] total 5 [2022-07-13 17:59:24,361 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [919330496] [2022-07-13 17:59:24,361 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2022-07-13 17:59:24,362 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 5 states [2022-07-13 17:59:24,362 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2022-07-13 17:59:24,362 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 5 interpolants. [2022-07-13 17:59:24,362 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=7, Invalid=13, Unknown=0, NotChecked=0, Total=20 [2022-07-13 17:59:24,362 INFO L87 Difference]: Start difference. First operand 147 states and 180 transitions. Second operand has 5 states, 5 states have (on average 8.0) internal successors, (40), 4 states have internal predecessors, (40), 2 states have call successors, (3), 3 states have call predecessors, (3), 2 states have return successors, (2), 1 states have call predecessors, (2), 2 states have call successors, (2) [2022-07-13 17:59:24,564 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-07-13 17:59:24,564 INFO L93 Difference]: Finished difference Result 414 states and 528 transitions. [2022-07-13 17:59:24,565 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 7 states. [2022-07-13 17:59:24,565 INFO L78 Accepts]: Start accepts. Automaton has has 5 states, 5 states have (on average 8.0) internal successors, (40), 4 states have internal predecessors, (40), 2 states have call successors, (3), 3 states have call predecessors, (3), 2 states have return successors, (2), 1 states have call predecessors, (2), 2 states have call successors, (2) Word has length 45 [2022-07-13 17:59:24,565 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2022-07-13 17:59:24,568 INFO L225 Difference]: With dead ends: 414 [2022-07-13 17:59:24,568 INFO L226 Difference]: Without dead ends: 274 [2022-07-13 17:59:24,568 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 13 GetRequests, 7 SyntacticMatches, 1 SemanticMatches, 5 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 1 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=15, Invalid=27, Unknown=0, NotChecked=0, Total=42 [2022-07-13 17:59:24,571 INFO L413 NwaCegarLoop]: 142 mSDtfsCounter, 201 mSDsluCounter, 163 mSDsCounter, 0 mSdLazyCounter, 144 mSolverCounterSat, 53 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.1s Time, 0 mProtectedPredicate, 0 mProtectedAction, 208 SdHoareTripleChecker+Valid, 305 SdHoareTripleChecker+Invalid, 197 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 53 IncrementalHoareTripleChecker+Valid, 144 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.2s IncrementalHoareTripleChecker+Time [2022-07-13 17:59:24,571 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [208 Valid, 305 Invalid, 197 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [53 Valid, 144 Invalid, 0 Unknown, 0 Unchecked, 0.2s Time] [2022-07-13 17:59:24,572 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 274 states. [2022-07-13 17:59:24,592 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 274 to 266. [2022-07-13 17:59:24,593 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 266 states, 206 states have (on average 1.2524271844660195) internal successors, (258), 217 states have internal predecessors, (258), 30 states have call successors, (30), 28 states have call predecessors, (30), 29 states have return successors, (45), 30 states have call predecessors, (45), 30 states have call successors, (45) [2022-07-13 17:59:24,595 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 266 states to 266 states and 333 transitions. [2022-07-13 17:59:24,595 INFO L78 Accepts]: Start accepts. Automaton has 266 states and 333 transitions. Word has length 45 [2022-07-13 17:59:24,598 INFO L84 Accepts]: Finished accepts. word is rejected. [2022-07-13 17:59:24,598 INFO L495 AbstractCegarLoop]: Abstraction has 266 states and 333 transitions. [2022-07-13 17:59:24,599 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 5 states, 5 states have (on average 8.0) internal successors, (40), 4 states have internal predecessors, (40), 2 states have call successors, (3), 3 states have call predecessors, (3), 2 states have return successors, (2), 1 states have call predecessors, (2), 2 states have call successors, (2) [2022-07-13 17:59:24,599 INFO L276 IsEmpty]: Start isEmpty. Operand 266 states and 333 transitions. [2022-07-13 17:59:24,602 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 48 [2022-07-13 17:59:24,602 INFO L187 NwaCegarLoop]: Found error trace [2022-07-13 17:59:24,602 INFO L195 NwaCegarLoop]: trace histogram [1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-07-13 17:59:24,602 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable6 [2022-07-13 17:59:24,602 INFO L420 AbstractCegarLoop]: === Iteration 8 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2022-07-13 17:59:24,603 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2022-07-13 17:59:24,603 INFO L85 PathProgramCache]: Analyzing trace with hash -2000597692, now seen corresponding path program 1 times [2022-07-13 17:59:24,603 INFO L118 FreeRefinementEngine]: Executing refinement strategy CAMEL [2022-07-13 17:59:24,603 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [1933396566] [2022-07-13 17:59:24,604 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-07-13 17:59:24,605 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2022-07-13 17:59:24,625 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-07-13 17:59:24,672 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 20 [2022-07-13 17:59:24,680 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-07-13 17:59:24,683 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 8 [2022-07-13 17:59:24,684 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-07-13 17:59:24,685 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 36 [2022-07-13 17:59:24,689 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-07-13 17:59:24,690 INFO L134 CoverageAnalysis]: Checked inductivity of 0 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2022-07-13 17:59:24,691 INFO L136 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2022-07-13 17:59:24,691 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [1933396566] [2022-07-13 17:59:24,691 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [1933396566] provided 1 perfect and 0 imperfect interpolant sequences [2022-07-13 17:59:24,691 INFO L184 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2022-07-13 17:59:24,691 INFO L197 FreeRefinementEngine]: Number of different interpolants: perfect sequences [6] imperfect sequences [] total 6 [2022-07-13 17:59:24,692 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [1108426297] [2022-07-13 17:59:24,692 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2022-07-13 17:59:24,692 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 6 states [2022-07-13 17:59:24,693 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2022-07-13 17:59:24,693 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 6 interpolants. [2022-07-13 17:59:24,693 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=9, Invalid=21, Unknown=0, NotChecked=0, Total=30 [2022-07-13 17:59:24,694 INFO L87 Difference]: Start difference. First operand 266 states and 333 transitions. Second operand has 6 states, 6 states have (on average 6.666666666666667) internal successors, (40), 5 states have internal predecessors, (40), 2 states have call successors, (4), 3 states have call predecessors, (4), 1 states have return successors, (3), 2 states have call predecessors, (3), 2 states have call successors, (3) [2022-07-13 17:59:24,843 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-07-13 17:59:24,843 INFO L93 Difference]: Finished difference Result 528 states and 661 transitions. [2022-07-13 17:59:24,843 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 7 states. [2022-07-13 17:59:24,844 INFO L78 Accepts]: Start accepts. Automaton has has 6 states, 6 states have (on average 6.666666666666667) internal successors, (40), 5 states have internal predecessors, (40), 2 states have call successors, (4), 3 states have call predecessors, (4), 1 states have return successors, (3), 2 states have call predecessors, (3), 2 states have call successors, (3) Word has length 47 [2022-07-13 17:59:24,844 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2022-07-13 17:59:24,846 INFO L225 Difference]: With dead ends: 528 [2022-07-13 17:59:24,846 INFO L226 Difference]: Without dead ends: 269 [2022-07-13 17:59:24,847 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 15 GetRequests, 8 SyntacticMatches, 0 SemanticMatches, 7 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 0 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=27, Invalid=45, Unknown=0, NotChecked=0, Total=72 [2022-07-13 17:59:24,848 INFO L413 NwaCegarLoop]: 85 mSDtfsCounter, 108 mSDsluCounter, 247 mSDsCounter, 0 mSdLazyCounter, 139 mSolverCounterSat, 25 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.1s Time, 0 mProtectedPredicate, 0 mProtectedAction, 113 SdHoareTripleChecker+Valid, 332 SdHoareTripleChecker+Invalid, 164 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 25 IncrementalHoareTripleChecker+Valid, 139 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.1s IncrementalHoareTripleChecker+Time [2022-07-13 17:59:24,848 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [113 Valid, 332 Invalid, 164 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [25 Valid, 139 Invalid, 0 Unknown, 0 Unchecked, 0.1s Time] [2022-07-13 17:59:24,851 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 269 states. [2022-07-13 17:59:24,865 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 269 to 264. [2022-07-13 17:59:24,865 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 264 states, 204 states have (on average 1.2450980392156863) internal successors, (254), 215 states have internal predecessors, (254), 30 states have call successors, (30), 28 states have call predecessors, (30), 29 states have return successors, (45), 30 states have call predecessors, (45), 30 states have call successors, (45) [2022-07-13 17:59:24,867 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 264 states to 264 states and 329 transitions. [2022-07-13 17:59:24,867 INFO L78 Accepts]: Start accepts. Automaton has 264 states and 329 transitions. Word has length 47 [2022-07-13 17:59:24,868 INFO L84 Accepts]: Finished accepts. word is rejected. [2022-07-13 17:59:24,868 INFO L495 AbstractCegarLoop]: Abstraction has 264 states and 329 transitions. [2022-07-13 17:59:24,868 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 6 states, 6 states have (on average 6.666666666666667) internal successors, (40), 5 states have internal predecessors, (40), 2 states have call successors, (4), 3 states have call predecessors, (4), 1 states have return successors, (3), 2 states have call predecessors, (3), 2 states have call successors, (3) [2022-07-13 17:59:24,868 INFO L276 IsEmpty]: Start isEmpty. Operand 264 states and 329 transitions. [2022-07-13 17:59:24,869 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 50 [2022-07-13 17:59:24,869 INFO L187 NwaCegarLoop]: Found error trace [2022-07-13 17:59:24,869 INFO L195 NwaCegarLoop]: trace histogram [1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-07-13 17:59:24,869 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable7 [2022-07-13 17:59:24,869 INFO L420 AbstractCegarLoop]: === Iteration 9 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2022-07-13 17:59:24,870 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2022-07-13 17:59:24,870 INFO L85 PathProgramCache]: Analyzing trace with hash 568530835, now seen corresponding path program 1 times [2022-07-13 17:59:24,870 INFO L118 FreeRefinementEngine]: Executing refinement strategy CAMEL [2022-07-13 17:59:24,870 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [508535375] [2022-07-13 17:59:24,870 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-07-13 17:59:24,871 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2022-07-13 17:59:24,887 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-07-13 17:59:24,931 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 11 [2022-07-13 17:59:24,933 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-07-13 17:59:24,941 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 24 [2022-07-13 17:59:24,943 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-07-13 17:59:24,960 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 38 [2022-07-13 17:59:24,961 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-07-13 17:59:24,964 INFO L134 CoverageAnalysis]: Checked inductivity of 0 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2022-07-13 17:59:24,965 INFO L136 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2022-07-13 17:59:24,965 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [508535375] [2022-07-13 17:59:24,965 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [508535375] provided 1 perfect and 0 imperfect interpolant sequences [2022-07-13 17:59:24,965 INFO L184 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2022-07-13 17:59:24,965 INFO L197 FreeRefinementEngine]: Number of different interpolants: perfect sequences [10] imperfect sequences [] total 10 [2022-07-13 17:59:24,966 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [1316854163] [2022-07-13 17:59:24,966 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2022-07-13 17:59:24,966 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 10 states [2022-07-13 17:59:24,967 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2022-07-13 17:59:24,967 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 10 interpolants. [2022-07-13 17:59:24,967 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=18, Invalid=72, Unknown=0, NotChecked=0, Total=90 [2022-07-13 17:59:24,968 INFO L87 Difference]: Start difference. First operand 264 states and 329 transitions. Second operand has 10 states, 10 states have (on average 4.2) internal successors, (42), 8 states have internal predecessors, (42), 2 states have call successors, (4), 3 states have call predecessors, (4), 2 states have return successors, (3), 2 states have call predecessors, (3), 2 states have call successors, (3) [2022-07-13 17:59:25,393 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-07-13 17:59:25,393 INFO L93 Difference]: Finished difference Result 534 states and 669 transitions. [2022-07-13 17:59:25,394 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 20 states. [2022-07-13 17:59:25,394 INFO L78 Accepts]: Start accepts. Automaton has has 10 states, 10 states have (on average 4.2) internal successors, (42), 8 states have internal predecessors, (42), 2 states have call successors, (4), 3 states have call predecessors, (4), 2 states have return successors, (3), 2 states have call predecessors, (3), 2 states have call successors, (3) Word has length 49 [2022-07-13 17:59:25,394 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2022-07-13 17:59:25,396 INFO L225 Difference]: With dead ends: 534 [2022-07-13 17:59:25,396 INFO L226 Difference]: Without dead ends: 324 [2022-07-13 17:59:25,397 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 34 GetRequests, 12 SyntacticMatches, 0 SemanticMatches, 22 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 71 ImplicationChecksByTransitivity, 0.1s TimeCoverageRelationStatistics Valid=128, Invalid=424, Unknown=0, NotChecked=0, Total=552 [2022-07-13 17:59:25,398 INFO L413 NwaCegarLoop]: 149 mSDtfsCounter, 289 mSDsluCounter, 526 mSDsCounter, 0 mSdLazyCounter, 448 mSolverCounterSat, 105 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.2s Time, 0 mProtectedPredicate, 0 mProtectedAction, 290 SdHoareTripleChecker+Valid, 675 SdHoareTripleChecker+Invalid, 553 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 105 IncrementalHoareTripleChecker+Valid, 448 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.3s IncrementalHoareTripleChecker+Time [2022-07-13 17:59:25,398 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [290 Valid, 675 Invalid, 553 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [105 Valid, 448 Invalid, 0 Unknown, 0 Unchecked, 0.3s Time] [2022-07-13 17:59:25,399 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 324 states. [2022-07-13 17:59:25,413 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 324 to 299. [2022-07-13 17:59:25,414 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 299 states, 232 states have (on average 1.2241379310344827) internal successors, (284), 246 states have internal predecessors, (284), 34 states have call successors, (34), 28 states have call predecessors, (34), 32 states have return successors, (46), 34 states have call predecessors, (46), 34 states have call successors, (46) [2022-07-13 17:59:25,416 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 299 states to 299 states and 364 transitions. [2022-07-13 17:59:25,416 INFO L78 Accepts]: Start accepts. Automaton has 299 states and 364 transitions. Word has length 49 [2022-07-13 17:59:25,416 INFO L84 Accepts]: Finished accepts. word is rejected. [2022-07-13 17:59:25,417 INFO L495 AbstractCegarLoop]: Abstraction has 299 states and 364 transitions. [2022-07-13 17:59:25,417 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 10 states, 10 states have (on average 4.2) internal successors, (42), 8 states have internal predecessors, (42), 2 states have call successors, (4), 3 states have call predecessors, (4), 2 states have return successors, (3), 2 states have call predecessors, (3), 2 states have call successors, (3) [2022-07-13 17:59:25,417 INFO L276 IsEmpty]: Start isEmpty. Operand 299 states and 364 transitions. [2022-07-13 17:59:25,418 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 52 [2022-07-13 17:59:25,418 INFO L187 NwaCegarLoop]: Found error trace [2022-07-13 17:59:25,418 INFO L195 NwaCegarLoop]: trace histogram [1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-07-13 17:59:25,418 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable8 [2022-07-13 17:59:25,418 INFO L420 AbstractCegarLoop]: === Iteration 10 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2022-07-13 17:59:25,419 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2022-07-13 17:59:25,419 INFO L85 PathProgramCache]: Analyzing trace with hash -2144109732, now seen corresponding path program 1 times [2022-07-13 17:59:25,419 INFO L118 FreeRefinementEngine]: Executing refinement strategy CAMEL [2022-07-13 17:59:25,419 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [626918323] [2022-07-13 17:59:25,419 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-07-13 17:59:25,420 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2022-07-13 17:59:25,429 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-07-13 17:59:25,440 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 11 [2022-07-13 17:59:25,442 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-07-13 17:59:25,445 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 24 [2022-07-13 17:59:25,447 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-07-13 17:59:25,459 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 8 [2022-07-13 17:59:25,460 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-07-13 17:59:25,461 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 40 [2022-07-13 17:59:25,462 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-07-13 17:59:25,463 INFO L134 CoverageAnalysis]: Checked inductivity of 0 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2022-07-13 17:59:25,463 INFO L136 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2022-07-13 17:59:25,463 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [626918323] [2022-07-13 17:59:25,464 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [626918323] provided 1 perfect and 0 imperfect interpolant sequences [2022-07-13 17:59:25,464 INFO L184 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2022-07-13 17:59:25,464 INFO L197 FreeRefinementEngine]: Number of different interpolants: perfect sequences [6] imperfect sequences [] total 6 [2022-07-13 17:59:25,464 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [1090808987] [2022-07-13 17:59:25,464 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2022-07-13 17:59:25,465 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 6 states [2022-07-13 17:59:25,465 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2022-07-13 17:59:25,465 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 6 interpolants. [2022-07-13 17:59:25,465 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=9, Invalid=21, Unknown=0, NotChecked=0, Total=30 [2022-07-13 17:59:25,466 INFO L87 Difference]: Start difference. First operand 299 states and 364 transitions. Second operand has 6 states, 6 states have (on average 7.0) internal successors, (42), 4 states have internal predecessors, (42), 2 states have call successors, (5), 3 states have call predecessors, (5), 2 states have return successors, (4), 2 states have call predecessors, (4), 2 states have call successors, (4) [2022-07-13 17:59:25,616 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-07-13 17:59:25,616 INFO L93 Difference]: Finished difference Result 543 states and 669 transitions. [2022-07-13 17:59:25,616 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 8 states. [2022-07-13 17:59:25,616 INFO L78 Accepts]: Start accepts. Automaton has has 6 states, 6 states have (on average 7.0) internal successors, (42), 4 states have internal predecessors, (42), 2 states have call successors, (5), 3 states have call predecessors, (5), 2 states have return successors, (4), 2 states have call predecessors, (4), 2 states have call successors, (4) Word has length 51 [2022-07-13 17:59:25,618 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2022-07-13 17:59:25,620 INFO L225 Difference]: With dead ends: 543 [2022-07-13 17:59:25,620 INFO L226 Difference]: Without dead ends: 300 [2022-07-13 17:59:25,621 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 18 GetRequests, 10 SyntacticMatches, 0 SemanticMatches, 8 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 3 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=33, Invalid=57, Unknown=0, NotChecked=0, Total=90 [2022-07-13 17:59:25,621 INFO L413 NwaCegarLoop]: 88 mSDtfsCounter, 132 mSDsluCounter, 204 mSDsCounter, 0 mSdLazyCounter, 158 mSolverCounterSat, 40 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.1s Time, 0 mProtectedPredicate, 0 mProtectedAction, 135 SdHoareTripleChecker+Valid, 292 SdHoareTripleChecker+Invalid, 198 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 40 IncrementalHoareTripleChecker+Valid, 158 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.1s IncrementalHoareTripleChecker+Time [2022-07-13 17:59:25,622 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [135 Valid, 292 Invalid, 198 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [40 Valid, 158 Invalid, 0 Unknown, 0 Unchecked, 0.1s Time] [2022-07-13 17:59:25,623 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 300 states. [2022-07-13 17:59:25,638 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 300 to 296. [2022-07-13 17:59:25,639 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 296 states, 229 states have (on average 1.222707423580786) internal successors, (280), 243 states have internal predecessors, (280), 34 states have call successors, (34), 28 states have call predecessors, (34), 32 states have return successors, (46), 34 states have call predecessors, (46), 34 states have call successors, (46) [2022-07-13 17:59:25,641 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 296 states to 296 states and 360 transitions. [2022-07-13 17:59:25,641 INFO L78 Accepts]: Start accepts. Automaton has 296 states and 360 transitions. Word has length 51 [2022-07-13 17:59:25,641 INFO L84 Accepts]: Finished accepts. word is rejected. [2022-07-13 17:59:25,641 INFO L495 AbstractCegarLoop]: Abstraction has 296 states and 360 transitions. [2022-07-13 17:59:25,641 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 6 states, 6 states have (on average 7.0) internal successors, (42), 4 states have internal predecessors, (42), 2 states have call successors, (5), 3 states have call predecessors, (5), 2 states have return successors, (4), 2 states have call predecessors, (4), 2 states have call successors, (4) [2022-07-13 17:59:25,641 INFO L276 IsEmpty]: Start isEmpty. Operand 296 states and 360 transitions. [2022-07-13 17:59:25,642 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 52 [2022-07-13 17:59:25,642 INFO L187 NwaCegarLoop]: Found error trace [2022-07-13 17:59:25,642 INFO L195 NwaCegarLoop]: trace histogram [1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-07-13 17:59:25,652 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable9 [2022-07-13 17:59:25,653 INFO L420 AbstractCegarLoop]: === Iteration 11 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2022-07-13 17:59:25,653 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2022-07-13 17:59:25,653 INFO L85 PathProgramCache]: Analyzing trace with hash -1925255014, now seen corresponding path program 1 times [2022-07-13 17:59:25,653 INFO L118 FreeRefinementEngine]: Executing refinement strategy CAMEL [2022-07-13 17:59:25,653 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [690435363] [2022-07-13 17:59:25,653 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-07-13 17:59:25,654 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2022-07-13 17:59:25,665 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-07-13 17:59:25,686 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 11 [2022-07-13 17:59:25,687 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-07-13 17:59:25,691 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 24 [2022-07-13 17:59:25,694 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-07-13 17:59:25,712 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 8 [2022-07-13 17:59:25,713 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-07-13 17:59:25,714 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 40 [2022-07-13 17:59:25,715 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-07-13 17:59:25,716 INFO L134 CoverageAnalysis]: Checked inductivity of 0 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2022-07-13 17:59:25,716 INFO L136 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2022-07-13 17:59:25,716 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [690435363] [2022-07-13 17:59:25,716 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [690435363] provided 1 perfect and 0 imperfect interpolant sequences [2022-07-13 17:59:25,716 INFO L184 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2022-07-13 17:59:25,717 INFO L197 FreeRefinementEngine]: Number of different interpolants: perfect sequences [7] imperfect sequences [] total 7 [2022-07-13 17:59:25,717 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [823045125] [2022-07-13 17:59:25,717 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2022-07-13 17:59:25,717 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 7 states [2022-07-13 17:59:25,718 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2022-07-13 17:59:25,718 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 7 interpolants. [2022-07-13 17:59:25,718 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=11, Invalid=31, Unknown=0, NotChecked=0, Total=42 [2022-07-13 17:59:25,718 INFO L87 Difference]: Start difference. First operand 296 states and 360 transitions. Second operand has 7 states, 7 states have (on average 6.0) internal successors, (42), 5 states have internal predecessors, (42), 2 states have call successors, (5), 3 states have call predecessors, (5), 2 states have return successors, (4), 2 states have call predecessors, (4), 2 states have call successors, (4) [2022-07-13 17:59:25,907 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-07-13 17:59:25,907 INFO L93 Difference]: Finished difference Result 514 states and 631 transitions. [2022-07-13 17:59:25,907 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 9 states. [2022-07-13 17:59:25,908 INFO L78 Accepts]: Start accepts. Automaton has has 7 states, 7 states have (on average 6.0) internal successors, (42), 5 states have internal predecessors, (42), 2 states have call successors, (5), 3 states have call predecessors, (5), 2 states have return successors, (4), 2 states have call predecessors, (4), 2 states have call successors, (4) Word has length 51 [2022-07-13 17:59:25,908 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2022-07-13 17:59:25,909 INFO L225 Difference]: With dead ends: 514 [2022-07-13 17:59:25,909 INFO L226 Difference]: Without dead ends: 274 [2022-07-13 17:59:25,910 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 20 GetRequests, 10 SyntacticMatches, 0 SemanticMatches, 10 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 4 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=46, Invalid=86, Unknown=0, NotChecked=0, Total=132 [2022-07-13 17:59:25,911 INFO L413 NwaCegarLoop]: 87 mSDtfsCounter, 122 mSDsluCounter, 275 mSDsCounter, 0 mSdLazyCounter, 208 mSolverCounterSat, 40 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.1s Time, 0 mProtectedPredicate, 0 mProtectedAction, 125 SdHoareTripleChecker+Valid, 362 SdHoareTripleChecker+Invalid, 248 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 40 IncrementalHoareTripleChecker+Valid, 208 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.1s IncrementalHoareTripleChecker+Time [2022-07-13 17:59:25,911 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [125 Valid, 362 Invalid, 248 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [40 Valid, 208 Invalid, 0 Unknown, 0 Unchecked, 0.1s Time] [2022-07-13 17:59:25,912 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 274 states. [2022-07-13 17:59:25,921 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 274 to 270. [2022-07-13 17:59:25,922 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 270 states, 210 states have (on average 1.2190476190476192) internal successors, (256), 223 states have internal predecessors, (256), 31 states have call successors, (31), 25 states have call predecessors, (31), 28 states have return successors, (39), 30 states have call predecessors, (39), 31 states have call successors, (39) [2022-07-13 17:59:25,923 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 270 states to 270 states and 326 transitions. [2022-07-13 17:59:25,923 INFO L78 Accepts]: Start accepts. Automaton has 270 states and 326 transitions. Word has length 51 [2022-07-13 17:59:25,923 INFO L84 Accepts]: Finished accepts. word is rejected. [2022-07-13 17:59:25,924 INFO L495 AbstractCegarLoop]: Abstraction has 270 states and 326 transitions. [2022-07-13 17:59:25,924 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 7 states, 7 states have (on average 6.0) internal successors, (42), 5 states have internal predecessors, (42), 2 states have call successors, (5), 3 states have call predecessors, (5), 2 states have return successors, (4), 2 states have call predecessors, (4), 2 states have call successors, (4) [2022-07-13 17:59:25,924 INFO L276 IsEmpty]: Start isEmpty. Operand 270 states and 326 transitions. [2022-07-13 17:59:25,925 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 84 [2022-07-13 17:59:25,925 INFO L187 NwaCegarLoop]: Found error trace [2022-07-13 17:59:25,925 INFO L195 NwaCegarLoop]: trace histogram [3, 3, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-07-13 17:59:25,925 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable10 [2022-07-13 17:59:25,925 INFO L420 AbstractCegarLoop]: === Iteration 12 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2022-07-13 17:59:25,926 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2022-07-13 17:59:25,926 INFO L85 PathProgramCache]: Analyzing trace with hash 896506289, now seen corresponding path program 1 times [2022-07-13 17:59:25,926 INFO L118 FreeRefinementEngine]: Executing refinement strategy CAMEL [2022-07-13 17:59:25,926 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [749965905] [2022-07-13 17:59:25,926 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-07-13 17:59:25,927 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2022-07-13 17:59:25,937 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-07-13 17:59:25,956 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 11 [2022-07-13 17:59:25,957 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-07-13 17:59:25,963 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 20 [2022-07-13 17:59:25,966 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-07-13 17:59:25,989 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 3 [2022-07-13 17:59:25,992 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-07-13 17:59:25,999 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 17 [2022-07-13 17:59:26,005 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-07-13 17:59:26,014 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 62 [2022-07-13 17:59:26,015 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-07-13 17:59:26,016 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 72 [2022-07-13 17:59:26,017 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-07-13 17:59:26,018 INFO L134 CoverageAnalysis]: Checked inductivity of 27 backedges. 18 proven. 4 refuted. 0 times theorem prover too weak. 5 trivial. 0 not checked. [2022-07-13 17:59:26,018 INFO L136 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2022-07-13 17:59:26,018 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [749965905] [2022-07-13 17:59:26,018 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [749965905] provided 0 perfect and 1 imperfect interpolant sequences [2022-07-13 17:59:26,019 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleZ3 [1470304199] [2022-07-13 17:59:26,019 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-07-13 17:59:26,019 INFO L173 SolverBuilder]: Constructing external solver with command: z3 -smt2 -in SMTLIB2_COMPLIANT=true [2022-07-13 17:59:26,019 INFO L189 MonitoredProcess]: No working directory specified, using /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 [2022-07-13 17:59:26,023 INFO L229 MonitoredProcess]: Starting monitored process 2 with /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 -smt2 -in SMTLIB2_COMPLIANT=true (exit command is (exit), workingDir is null) [2022-07-13 17:59:26,030 INFO L327 MonitoredProcess]: [MP /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 -smt2 -in SMTLIB2_COMPLIANT=true (2)] Waiting until timeout for monitored process [2022-07-13 17:59:26,119 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-07-13 17:59:26,122 INFO L263 TraceCheckSpWp]: Trace formula consists of 445 conjuncts, 13 conjunts are in the unsatisfiable core [2022-07-13 17:59:26,131 INFO L286 TraceCheckSpWp]: Computing forward predicates... [2022-07-13 17:59:26,357 INFO L134 CoverageAnalysis]: Checked inductivity of 27 backedges. 6 proven. 12 refuted. 0 times theorem prover too weak. 9 trivial. 0 not checked. [2022-07-13 17:59:26,357 INFO L328 TraceCheckSpWp]: Computing backward predicates... [2022-07-13 17:59:26,563 INFO L134 CoverageAnalysis]: Checked inductivity of 27 backedges. 8 proven. 4 refuted. 0 times theorem prover too weak. 15 trivial. 0 not checked. [2022-07-13 17:59:26,563 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleZ3 [1470304199] provided 0 perfect and 2 imperfect interpolant sequences [2022-07-13 17:59:26,563 INFO L184 FreeRefinementEngine]: Found 0 perfect and 3 imperfect interpolant sequences. [2022-07-13 17:59:26,564 INFO L197 FreeRefinementEngine]: Number of different interpolants: perfect sequences [] imperfect sequences [10, 8, 9] total 19 [2022-07-13 17:59:26,564 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [1473109971] [2022-07-13 17:59:26,564 INFO L85 oduleStraightlineAll]: Using 3 imperfect interpolants to construct interpolant automaton [2022-07-13 17:59:26,564 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 19 states [2022-07-13 17:59:26,565 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2022-07-13 17:59:26,565 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 19 interpolants. [2022-07-13 17:59:26,565 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=60, Invalid=282, Unknown=0, NotChecked=0, Total=342 [2022-07-13 17:59:26,566 INFO L87 Difference]: Start difference. First operand 270 states and 326 transitions. Second operand has 19 states, 19 states have (on average 6.7368421052631575) internal successors, (128), 14 states have internal predecessors, (128), 7 states have call successors, (20), 10 states have call predecessors, (20), 8 states have return successors, (18), 8 states have call predecessors, (18), 7 states have call successors, (18) [2022-07-13 17:59:28,049 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-07-13 17:59:28,049 INFO L93 Difference]: Finished difference Result 814 states and 1054 transitions. [2022-07-13 17:59:28,050 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 52 states. [2022-07-13 17:59:28,050 INFO L78 Accepts]: Start accepts. Automaton has has 19 states, 19 states have (on average 6.7368421052631575) internal successors, (128), 14 states have internal predecessors, (128), 7 states have call successors, (20), 10 states have call predecessors, (20), 8 states have return successors, (18), 8 states have call predecessors, (18), 7 states have call successors, (18) Word has length 83 [2022-07-13 17:59:28,050 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2022-07-13 17:59:28,051 INFO L225 Difference]: With dead ends: 814 [2022-07-13 17:59:28,051 INFO L226 Difference]: Without dead ends: 0 [2022-07-13 17:59:28,055 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 241 GetRequests, 173 SyntacticMatches, 1 SemanticMatches, 67 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 1195 ImplicationChecksByTransitivity, 0.8s TimeCoverageRelationStatistics Valid=927, Invalid=3765, Unknown=0, NotChecked=0, Total=4692 [2022-07-13 17:59:28,056 INFO L413 NwaCegarLoop]: 124 mSDtfsCounter, 1040 mSDsluCounter, 642 mSDsCounter, 0 mSdLazyCounter, 1053 mSolverCounterSat, 506 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.6s Time, 0 mProtectedPredicate, 0 mProtectedAction, 1040 SdHoareTripleChecker+Valid, 766 SdHoareTripleChecker+Invalid, 1559 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 506 IncrementalHoareTripleChecker+Valid, 1053 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.8s IncrementalHoareTripleChecker+Time [2022-07-13 17:59:28,056 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [1040 Valid, 766 Invalid, 1559 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [506 Valid, 1053 Invalid, 0 Unknown, 0 Unchecked, 0.8s Time] [2022-07-13 17:59:28,056 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 0 states. [2022-07-13 17:59:28,057 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 0 to 0. [2022-07-13 17:59:28,057 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 0 states, 0 states have (on average 0.0) internal successors, (0), 0 states have internal predecessors, (0), 0 states have call successors, (0), 0 states have call predecessors, (0), 0 states have return successors, (0), 0 states have call predecessors, (0), 0 states have call successors, (0) [2022-07-13 17:59:28,057 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 0 states to 0 states and 0 transitions. [2022-07-13 17:59:28,057 INFO L78 Accepts]: Start accepts. Automaton has 0 states and 0 transitions. Word has length 83 [2022-07-13 17:59:28,058 INFO L84 Accepts]: Finished accepts. word is rejected. [2022-07-13 17:59:28,058 INFO L495 AbstractCegarLoop]: Abstraction has 0 states and 0 transitions. [2022-07-13 17:59:28,058 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 19 states, 19 states have (on average 6.7368421052631575) internal successors, (128), 14 states have internal predecessors, (128), 7 states have call successors, (20), 10 states have call predecessors, (20), 8 states have return successors, (18), 8 states have call predecessors, (18), 7 states have call successors, (18) [2022-07-13 17:59:28,058 INFO L276 IsEmpty]: Start isEmpty. Operand 0 states and 0 transitions. [2022-07-13 17:59:28,058 INFO L282 IsEmpty]: Finished isEmpty. No accepting run. [2022-07-13 17:59:28,061 INFO L805 garLoopResultBuilder]: Registering result SAFE for location timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION (0 of 1 remaining) [2022-07-13 17:59:28,083 INFO L552 MonitoredProcess]: [MP /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 -smt2 -in SMTLIB2_COMPLIANT=true (2)] Ended with exit code 0 [2022-07-13 17:59:28,275 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: 2 /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 -smt2 -in SMTLIB2_COMPLIANT=true,SelfDestructingSolverStorable11 [2022-07-13 17:59:28,277 INFO L343 DoubleDeckerVisitor]: Before removal of dead ends 0 states and 0 transitions. [2022-07-13 17:59:31,933 INFO L899 garLoopResultBuilder]: For program point processEnvironment__wrappee__baseEXIT(lines 196 202) no Hoare annotation was computed. [2022-07-13 17:59:31,934 INFO L902 garLoopResultBuilder]: At program point processEnvironment__wrappee__baseFINAL(lines 196 202) the Hoare annotation is: true [2022-07-13 17:59:31,934 INFO L895 garLoopResultBuilder]: At program point changeMethaneLevelENTRY(lines 853 864) the Hoare annotation is: (let ((.cse1 (= ~methaneLevelCritical~0 0)) (.cse6 (= |old(~methaneLevelCritical~0)| 0))) (let ((.cse0 (not .cse6)) (.cse3 (not (<= 1 ~pumpRunning~0))) (.cse5 (not (= ~pumpRunning~0 0))) (.cse2 (not (= 1 ~systemActive~0))) (.cse7 (not .cse1)) (.cse4 (not (<= ~waterLevel~0 2)))) (and (or .cse0 .cse1 .cse2 .cse3 .cse4) (or .cse0 .cse5 .cse1 .cse2 .cse4) (or .cse2 .cse6 .cse7 .cse3 .cse4) (or .cse5 .cse2 .cse6 .cse7 .cse4)))) [2022-07-13 17:59:31,934 INFO L899 garLoopResultBuilder]: For program point L857-1(lines 853 864) no Hoare annotation was computed. [2022-07-13 17:59:31,934 INFO L899 garLoopResultBuilder]: For program point changeMethaneLevelEXIT(lines 853 864) no Hoare annotation was computed. [2022-07-13 17:59:31,934 INFO L902 garLoopResultBuilder]: At program point isMethaneLevelCriticalENTRY(lines 865 873) the Hoare annotation is: true [2022-07-13 17:59:31,934 INFO L899 garLoopResultBuilder]: For program point isMethaneLevelCriticalFINAL(lines 865 873) no Hoare annotation was computed. [2022-07-13 17:59:31,935 INFO L899 garLoopResultBuilder]: For program point isMethaneLevelCriticalEXIT(lines 865 873) no Hoare annotation was computed. [2022-07-13 17:59:31,935 INFO L902 garLoopResultBuilder]: At program point L737(line 737) the Hoare annotation is: true [2022-07-13 17:59:31,935 INFO L899 garLoopResultBuilder]: For program point L737-1(line 737) no Hoare annotation was computed. [2022-07-13 17:59:31,935 INFO L899 garLoopResultBuilder]: For program point cleanupEXIT(lines 731 760) no Hoare annotation was computed. [2022-07-13 17:59:31,935 INFO L902 garLoopResultBuilder]: At program point cleanupENTRY(lines 731 760) the Hoare annotation is: true [2022-07-13 17:59:31,935 INFO L902 garLoopResultBuilder]: At program point L756(lines 731 760) the Hoare annotation is: true [2022-07-13 17:59:31,935 INFO L899 garLoopResultBuilder]: For program point L752(line 752) no Hoare annotation was computed. [2022-07-13 17:59:31,935 INFO L899 garLoopResultBuilder]: For program point L745(lines 745 749) no Hoare annotation was computed. [2022-07-13 17:59:31,935 INFO L902 garLoopResultBuilder]: At program point L745-1(lines 745 749) the Hoare annotation is: true [2022-07-13 17:59:31,935 INFO L899 garLoopResultBuilder]: For program point L742(line 742) no Hoare annotation was computed. [2022-07-13 17:59:31,935 INFO L902 garLoopResultBuilder]: At program point L741-2(lines 741 755) the Hoare annotation is: true [2022-07-13 17:59:31,936 INFO L895 garLoopResultBuilder]: At program point L287(lines 282 290) the Hoare annotation is: (let ((.cse0 (not (= |old(~pumpRunning~0)| 0))) (.cse1 (not (= 1 ~systemActive~0))) (.cse2 (not (<= |old(~waterLevel~0)| 2)))) (and (or .cse0 (= ~methaneLevelCritical~0 0) .cse1 .cse2) (or .cse0 .cse1 .cse2 (and (<= 1 ~pumpRunning~0) (not (= |timeShift_isPumpRunning_#res#1| 0)) (<= 2 ~waterLevel~0) (= |old(~waterLevel~0)| ~waterLevel~0) (= ~methaneLevelCritical~0 |timeShift___utac_acc__Specification3_spec__1_~tmp~8#1|))) (or .cse1 (not (<= 1 |old(~pumpRunning~0)|)) .cse2))) [2022-07-13 17:59:31,936 INFO L899 garLoopResultBuilder]: For program point L725(line 725) no Hoare annotation was computed. [2022-07-13 17:59:31,936 INFO L899 garLoopResultBuilder]: For program point L176-1(lines 175 194) no Hoare annotation was computed. [2022-07-13 17:59:31,936 INFO L899 garLoopResultBuilder]: For program point L238(lines 238 246) no Hoare annotation was computed. [2022-07-13 17:59:31,936 INFO L899 garLoopResultBuilder]: For program point L940(lines 940 946) no Hoare annotation was computed. [2022-07-13 17:59:31,936 INFO L899 garLoopResultBuilder]: For program point L234(lines 234 251) no Hoare annotation was computed. [2022-07-13 17:59:31,936 INFO L899 garLoopResultBuilder]: For program point L936(lines 936 949) no Hoare annotation was computed. [2022-07-13 17:59:31,936 INFO L895 garLoopResultBuilder]: At program point L936-1(lines 921 953) the Hoare annotation is: (let ((.cse12 (= 1 ~systemActive~0)) (.cse4 (= |old(~waterLevel~0)| ~waterLevel~0)) (.cse5 (= ~methaneLevelCritical~0 |timeShift___utac_acc__Specification3_spec__1_~tmp~8#1|))) (let ((.cse2 (= ~pumpRunning~0 0)) (.cse3 (<= ~waterLevel~0 1)) (.cse0 (not (= |old(~pumpRunning~0)| 0))) (.cse7 (and (<= 1 ~pumpRunning~0) (<= 2 ~waterLevel~0) .cse12 .cse4 .cse5)) (.cse1 (not .cse12)) (.cse10 (and (<= |timeShift___utac_acc__Specification3_spec__1_~tmp___0~2#1| 1) (<= |timeShift_getWaterLevel_#res#1| 1))) (.cse9 (not (<= 1 |old(~pumpRunning~0)|))) (.cse11 (not (= ~methaneLevelCritical~0 0))) (.cse6 (not (<= |old(~waterLevel~0)| 2)))) (and (or .cse0 .cse1 (and .cse2 .cse3 .cse4 .cse5) .cse6 .cse7) (let ((.cse8 (<= ~waterLevel~0 |old(~waterLevel~0)|))) (or (and .cse2 .cse3 .cse8 .cse5) .cse1 .cse9 (and (= ~pumpRunning~0 |old(~pumpRunning~0)|) .cse3 .cse8 .cse5) .cse6)) (or .cse0 .cse1 .cse10 .cse11 .cse6 .cse7) (or .cse1 .cse10 .cse9 .cse11 .cse6)))) [2022-07-13 17:59:31,936 INFO L899 garLoopResultBuilder]: For program point timeShiftFINAL(lines 172 195) no Hoare annotation was computed. [2022-07-13 17:59:31,937 INFO L899 garLoopResultBuilder]: For program point L833(lines 833 837) no Hoare annotation was computed. [2022-07-13 17:59:31,937 INFO L895 garLoopResultBuilder]: At program point L928(line 928) the Hoare annotation is: (let ((.cse3 (= ~pumpRunning~0 0)) (.cse1 (<= ~waterLevel~0 1)) (.cse0 (not (= 1 ~systemActive~0))) (.cse4 (not (<= |old(~waterLevel~0)| 2)))) (and (let ((.cse2 (<= ~waterLevel~0 |old(~waterLevel~0)|))) (or .cse0 (and (= ~pumpRunning~0 |old(~pumpRunning~0)|) .cse1 .cse2) (not (<= 1 |old(~pumpRunning~0)|)) (and .cse3 .cse1 .cse2) .cse4)) (let ((.cse5 (= |old(~waterLevel~0)| ~waterLevel~0))) (or (and .cse3 .cse1 .cse5) (not (= |old(~pumpRunning~0)| 0)) .cse0 (and (<= 1 ~pumpRunning~0) (<= 2 ~waterLevel~0) .cse5) .cse4)))) [2022-07-13 17:59:31,937 INFO L895 garLoopResultBuilder]: At program point L833-2(lines 829 840) the Hoare annotation is: (let ((.cse0 (not (= 1 ~systemActive~0))) (.cse1 (not (<= |old(~waterLevel~0)| 2)))) (and (or .cse0 (and (= ~pumpRunning~0 |old(~pumpRunning~0)|) (<= ~waterLevel~0 1) (<= ~waterLevel~0 |old(~waterLevel~0)|)) (not (<= 1 |old(~pumpRunning~0)|)) .cse1) (or (not (= |old(~pumpRunning~0)| 0)) .cse0 .cse1))) [2022-07-13 17:59:31,937 INFO L899 garLoopResultBuilder]: For program point L928-1(line 928) no Hoare annotation was computed. [2022-07-13 17:59:31,937 INFO L895 garLoopResultBuilder]: At program point L726(lines 721 728) the Hoare annotation is: (let ((.cse0 (not (= 1 ~systemActive~0))) (.cse1 (not (<= |old(~waterLevel~0)| 2)))) (and (or .cse0 (not (<= 1 |old(~pumpRunning~0)|)) .cse1) (or (not (= |old(~pumpRunning~0)| 0)) .cse0 .cse1))) [2022-07-13 17:59:31,937 INFO L895 garLoopResultBuilder]: At program point L276(line 276) the Hoare annotation is: (let ((.cse0 (not (= 1 ~systemActive~0))) (.cse1 (not (<= |old(~waterLevel~0)| 2)))) (and (or .cse0 (and (= ~pumpRunning~0 |old(~pumpRunning~0)|) (<= ~waterLevel~0 1) (<= ~waterLevel~0 |old(~waterLevel~0)|)) (not (<= 1 |old(~pumpRunning~0)|)) .cse1) (or (not (= |old(~pumpRunning~0)| 0)) .cse0 .cse1))) [2022-07-13 17:59:31,937 INFO L899 garLoopResultBuilder]: For program point L276-1(line 276) no Hoare annotation was computed. [2022-07-13 17:59:31,937 INFO L895 garLoopResultBuilder]: At program point L268(lines 263 270) the Hoare annotation is: (let ((.cse0 (not (= 1 ~systemActive~0))) (.cse1 (not (<= |old(~waterLevel~0)| 2)))) (and (or .cse0 (not (<= 1 |old(~pumpRunning~0)|)) (and (= ~pumpRunning~0 0) (<= ~waterLevel~0 1) (<= ~waterLevel~0 |old(~waterLevel~0)|)) .cse1) (or (not (= |old(~pumpRunning~0)| 0)) .cse0 .cse1))) [2022-07-13 17:59:31,937 INFO L895 garLoopResultBuilder]: At program point L244(line 244) the Hoare annotation is: (let ((.cse0 (not (= 1 ~systemActive~0))) (.cse1 (not (<= |old(~waterLevel~0)| 2)))) (and (or .cse0 (and (= ~pumpRunning~0 |old(~pumpRunning~0)|) (<= ~waterLevel~0 1) (<= ~waterLevel~0 |old(~waterLevel~0)|)) (not (<= 1 |old(~pumpRunning~0)|)) .cse1) (or (not (= |old(~pumpRunning~0)| 0)) .cse0 .cse1))) [2022-07-13 17:59:31,938 INFO L899 garLoopResultBuilder]: For program point L930(lines 930 950) no Hoare annotation was computed. [2022-07-13 17:59:31,938 INFO L895 garLoopResultBuilder]: At program point L249(line 249) the Hoare annotation is: (let ((.cse0 (not (= 1 ~systemActive~0))) (.cse1 (not (<= |old(~waterLevel~0)| 2)))) (and (or (not (= |old(~pumpRunning~0)| 0)) (and (= ~pumpRunning~0 0) (= |old(~waterLevel~0)| ~waterLevel~0)) .cse0 .cse1) (or .cse0 (not (<= 1 |old(~pumpRunning~0)|)) .cse1))) [2022-07-13 17:59:31,938 INFO L895 garLoopResultBuilder]: At program point L249-1(lines 230 254) the Hoare annotation is: (let ((.cse3 (= ~pumpRunning~0 0)) (.cse1 (<= ~waterLevel~0 1)) (.cse0 (not (= 1 ~systemActive~0))) (.cse4 (not (<= |old(~waterLevel~0)| 2)))) (and (let ((.cse2 (<= ~waterLevel~0 |old(~waterLevel~0)|))) (or .cse0 (and (= ~pumpRunning~0 |old(~pumpRunning~0)|) .cse1 .cse2) (not (<= 1 |old(~pumpRunning~0)|)) (and .cse3 .cse1 .cse2) .cse4)) (let ((.cse5 (= |old(~waterLevel~0)| ~waterLevel~0))) (or (and .cse3 .cse1 .cse5) (not (= |old(~pumpRunning~0)| 0)) .cse0 (and (<= 1 ~pumpRunning~0) (<= 2 ~waterLevel~0) .cse5) .cse4)))) [2022-07-13 17:59:31,938 INFO L895 garLoopResultBuilder]: At program point L278(lines 271 281) the Hoare annotation is: (let ((.cse0 (not (= 1 ~systemActive~0))) (.cse1 (not (<= |old(~waterLevel~0)| 2)))) (and (or .cse0 (and (= ~pumpRunning~0 |old(~pumpRunning~0)|) (<= ~waterLevel~0 1) (<= ~waterLevel~0 |old(~waterLevel~0)|)) (not (<= 1 |old(~pumpRunning~0)|)) .cse1) (or (not (= |old(~pumpRunning~0)| 0)) .cse0 .cse1))) [2022-07-13 17:59:31,938 INFO L899 garLoopResultBuilder]: For program point L183-1(lines 183 189) no Hoare annotation was computed. [2022-07-13 17:59:31,938 INFO L895 garLoopResultBuilder]: At program point timeShiftENTRY(lines 172 195) the Hoare annotation is: (let ((.cse1 (= |old(~waterLevel~0)| ~waterLevel~0)) (.cse0 (not (= 1 ~systemActive~0))) (.cse2 (not (<= |old(~waterLevel~0)| 2)))) (and (or .cse0 (not (<= 1 |old(~pumpRunning~0)|)) (and (= ~pumpRunning~0 |old(~pumpRunning~0)|) .cse1) .cse2) (or (not (= |old(~pumpRunning~0)| 0)) (and (= ~pumpRunning~0 0) .cse1) .cse0 .cse2))) [2022-07-13 17:59:31,938 INFO L899 garLoopResultBuilder]: For program point timeShiftEXIT(lines 172 195) no Hoare annotation was computed. [2022-07-13 17:59:31,938 INFO L899 garLoopResultBuilder]: For program point timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION(line 725) no Hoare annotation was computed. [2022-07-13 17:59:31,938 INFO L895 garLoopResultBuilder]: At program point L902(lines 897 905) the Hoare annotation is: (let ((.cse0 (not (= |old(~pumpRunning~0)| 0))) (.cse2 (= ~methaneLevelCritical~0 0)) (.cse1 (not (= 1 ~systemActive~0))) (.cse9 (not (<= 1 |old(~pumpRunning~0)|))) (.cse8 (not (<= |old(~waterLevel~0)| 2))) (.cse5 (= ~pumpRunning~0 0)) (.cse6 (<= ~waterLevel~0 1)) (.cse4 (= ~methaneLevelCritical~0 |timeShift___utac_acc__Specification3_spec__1_~tmp~8#1|)) (.cse7 (<= |timeShift_getWaterLevel_#res#1| 1))) (and (or .cse0 (not (= |old(~waterLevel~0)| 1)) .cse1 (= |timeShift_getWaterLevel_#res#1| 1)) (or (not (<= |old(~waterLevel~0)| 1)) .cse0 .cse2 .cse1) (let ((.cse3 (= |old(~waterLevel~0)| ~waterLevel~0))) (or .cse0 .cse1 (and (<= 1 ~pumpRunning~0) .cse2 (<= 2 ~waterLevel~0) .cse3 .cse4) (and .cse5 .cse6 .cse3 .cse4 .cse7) .cse8)) (or .cse2 .cse1 .cse9 .cse8) (let ((.cse10 (<= ~waterLevel~0 |old(~waterLevel~0)|))) (or (and (= ~pumpRunning~0 |old(~pumpRunning~0)|) .cse6 .cse10 .cse4 .cse7) .cse1 .cse9 .cse8 (and .cse5 .cse6 .cse10 .cse4 .cse7))))) [2022-07-13 17:59:31,939 INFO L902 garLoopResultBuilder]: At program point L799(lines 792 801) the Hoare annotation is: true [2022-07-13 17:59:31,939 INFO L895 garLoopResultBuilder]: At program point L151(lines 102 152) the Hoare annotation is: false [2022-07-13 17:59:31,939 INFO L899 garLoopResultBuilder]: For program point L812(lines 812 819) no Hoare annotation was computed. [2022-07-13 17:59:31,939 INFO L899 garLoopResultBuilder]: For program point L812-2(lines 812 819) no Hoare annotation was computed. [2022-07-13 17:59:31,939 INFO L899 garLoopResultBuilder]: For program point L-1(line -1) no Hoare annotation was computed. [2022-07-13 17:59:31,939 INFO L899 garLoopResultBuilder]: For program point ULTIMATE.startENTRY(line -1) no Hoare annotation was computed. [2022-07-13 17:59:31,939 INFO L899 garLoopResultBuilder]: For program point ULTIMATE.startFINAL(line -1) no Hoare annotation was computed. [2022-07-13 17:59:31,939 INFO L899 garLoopResultBuilder]: For program point L123(lines 123 129) no Hoare annotation was computed. [2022-07-13 17:59:31,939 INFO L899 garLoopResultBuilder]: For program point L123-1(lines 123 129) no Hoare annotation was computed. [2022-07-13 17:59:31,939 INFO L902 garLoopResultBuilder]: At program point L821(lines 802 824) the Hoare annotation is: true [2022-07-13 17:59:31,939 INFO L895 garLoopResultBuilder]: At program point L148(lines 103 150) the Hoare annotation is: (let ((.cse0 (= 1 ~systemActive~0)) (.cse1 (= |ULTIMATE.start_valid_product_#res#1| ~systemActive~0)) (.cse2 (= |ULTIMATE.start_test_~splverifierCounter~0#1| 0)) (.cse3 (= |ULTIMATE.start_main_~tmp~7#1| ~systemActive~0))) (or (and (<= 1 ~pumpRunning~0) .cse0 .cse1 .cse2 (<= ~waterLevel~0 2) .cse3) (and (= ~pumpRunning~0 0) (<= ~waterLevel~0 1) .cse0 .cse1 .cse2 .cse3))) [2022-07-13 17:59:31,940 INFO L895 garLoopResultBuilder]: At program point L115(line 115) the Hoare annotation is: (let ((.cse0 (= 1 ~systemActive~0)) (.cse1 (= |ULTIMATE.start_valid_product_#res#1| ~systemActive~0)) (.cse2 (= |ULTIMATE.start_test_~splverifierCounter~0#1| 0)) (.cse3 (= |ULTIMATE.start_main_~tmp~7#1| ~systemActive~0))) (or (and (<= 1 ~pumpRunning~0) .cse0 .cse1 .cse2 (<= ~waterLevel~0 2) .cse3) (and (= ~pumpRunning~0 0) (<= ~waterLevel~0 1) .cse0 .cse1 .cse2 .cse3))) [2022-07-13 17:59:31,940 INFO L899 garLoopResultBuilder]: For program point ULTIMATE.startEXIT(line -1) no Hoare annotation was computed. [2022-07-13 17:59:31,940 INFO L895 garLoopResultBuilder]: At program point L351(lines 346 353) the Hoare annotation is: (let ((.cse0 (= 1 ~systemActive~0)) (.cse1 (= |ULTIMATE.start_valid_product_#res#1| ~systemActive~0)) (.cse2 (= |ULTIMATE.start_test_~splverifierCounter~0#1| 0)) (.cse3 (<= ~waterLevel~0 2)) (.cse4 (= |ULTIMATE.start_main_~tmp~7#1| ~systemActive~0))) (or (and (= ~pumpRunning~0 0) .cse0 .cse1 .cse2 .cse3 .cse4) (and (<= 1 ~pumpRunning~0) .cse0 .cse1 .cse2 .cse3 .cse4))) [2022-07-13 17:59:31,940 INFO L895 garLoopResultBuilder]: At program point L789(lines 785 791) the Hoare annotation is: (and (= ~pumpRunning~0 0) (= ~methaneLevelCritical~0 0) (= 1 ~systemActive~0) (= |ULTIMATE.start_valid_product_#res#1| ~systemActive~0) (= ~waterLevel~0 1) (= |ULTIMATE.start_main_~tmp~7#1| ~systemActive~0)) [2022-07-13 17:59:31,940 INFO L895 garLoopResultBuilder]: At program point L83(lines 78 86) the Hoare annotation is: (and (= ~pumpRunning~0 0) (= ~methaneLevelCritical~0 0) (= 1 ~systemActive~0) (= |ULTIMATE.start_valid_product_#res#1| ~systemActive~0) (= ~waterLevel~0 1)) [2022-07-13 17:59:31,940 INFO L899 garLoopResultBuilder]: For program point L141(lines 141 145) no Hoare annotation was computed. [2022-07-13 17:59:31,940 INFO L895 garLoopResultBuilder]: At program point L75(lines 71 77) the Hoare annotation is: (and (= ~pumpRunning~0 0) (= ~methaneLevelCritical~0 0) (= 1 ~systemActive~0) (= ~waterLevel~0 1)) [2022-07-13 17:59:31,940 INFO L895 garLoopResultBuilder]: At program point L141-2(lines 133 146) the Hoare annotation is: (let ((.cse0 (= 1 ~systemActive~0)) (.cse1 (= |ULTIMATE.start_valid_product_#res#1| ~systemActive~0)) (.cse2 (= |ULTIMATE.start_test_~splverifierCounter~0#1| 0)) (.cse3 (<= ~waterLevel~0 2)) (.cse4 (= |ULTIMATE.start_main_~tmp~7#1| ~systemActive~0))) (or (and (= ~pumpRunning~0 0) .cse0 .cse1 .cse2 .cse3 .cse4) (and (<= 1 ~pumpRunning~0) .cse0 .cse1 .cse2 .cse3 .cse4))) [2022-07-13 17:59:31,940 INFO L899 garLoopResultBuilder]: For program point L104(lines 103 150) no Hoare annotation was computed. [2022-07-13 17:59:31,940 INFO L899 garLoopResultBuilder]: For program point L133(lines 133 146) no Hoare annotation was computed. [2022-07-13 17:59:31,940 INFO L895 garLoopResultBuilder]: At program point L125(line 125) the Hoare annotation is: (let ((.cse0 (= 1 ~systemActive~0)) (.cse1 (= |ULTIMATE.start_valid_product_#res#1| ~systemActive~0)) (.cse2 (= |ULTIMATE.start_test_~splverifierCounter~0#1| 0)) (.cse3 (<= ~waterLevel~0 2)) (.cse4 (= |ULTIMATE.start_main_~tmp~7#1| ~systemActive~0))) (or (and (= ~pumpRunning~0 0) .cse0 .cse1 .cse2 .cse3 .cse4) (and (<= 1 ~pumpRunning~0) .cse0 .cse1 .cse2 .cse3 .cse4))) [2022-07-13 17:59:31,941 INFO L902 garLoopResultBuilder]: At program point L154(lines 93 158) the Hoare annotation is: true [2022-07-13 17:59:31,941 INFO L899 garLoopResultBuilder]: For program point L113(lines 113 119) no Hoare annotation was computed. [2022-07-13 17:59:31,941 INFO L899 garLoopResultBuilder]: For program point L113-1(lines 113 119) no Hoare annotation was computed. [2022-07-13 17:59:31,941 INFO L899 garLoopResultBuilder]: For program point L105(lines 105 109) no Hoare annotation was computed. [2022-07-13 17:59:31,941 INFO L895 garLoopResultBuilder]: At program point L68(lines 64 70) the Hoare annotation is: (and (= ~pumpRunning~0 0) (= ~methaneLevelCritical~0 0) (= 1 ~systemActive~0) (= ~waterLevel~0 1)) [2022-07-13 17:59:31,941 INFO L895 garLoopResultBuilder]: At program point processEnvironment__wrappee__highWaterSensorENTRY(lines 204 228) the Hoare annotation is: (let ((.cse0 (not (= 1 ~systemActive~0)))) (and (or (not (= |old(~pumpRunning~0)| 0)) (= ~pumpRunning~0 0) .cse0 (not (<= ~waterLevel~0 2))) (or (= ~pumpRunning~0 |old(~pumpRunning~0)|) .cse0 (not (<= 1 |old(~pumpRunning~0)|)) (not (<= ~waterLevel~0 1))))) [2022-07-13 17:59:31,941 INFO L895 garLoopResultBuilder]: At program point L223(line 223) the Hoare annotation is: (let ((.cse0 (not (= 1 ~systemActive~0)))) (and (or (= ~pumpRunning~0 |old(~pumpRunning~0)|) .cse0 (not (<= 1 |old(~pumpRunning~0)|)) (not (<= ~waterLevel~0 1))) (or (not (= |old(~pumpRunning~0)| 0)) .cse0 (not (<= ~waterLevel~0 2))))) [2022-07-13 17:59:31,941 INFO L899 garLoopResultBuilder]: For program point L223-1(lines 204 228) no Hoare annotation was computed. [2022-07-13 17:59:31,941 INFO L895 garLoopResultBuilder]: At program point L915(lines 906 919) the Hoare annotation is: (let ((.cse0 (not (= 1 ~systemActive~0))) (.cse2 (<= ~waterLevel~0 1))) (and (let ((.cse1 (= ~pumpRunning~0 0))) (or (not (= |old(~pumpRunning~0)| 0)) .cse0 (and .cse1 (<= 2 ~waterLevel~0) (= |processEnvironment__wrappee__highWaterSensor_isHighWaterSensorDry_#res#1| 0)) (not (<= ~waterLevel~0 2)) (and (<= 1 |processEnvironment__wrappee__highWaterSensor_isHighWaterSensorDry_#res#1|) .cse1 .cse2))) (or .cse0 (not (<= 1 |old(~pumpRunning~0)|)) (not .cse2)))) [2022-07-13 17:59:31,941 INFO L899 garLoopResultBuilder]: For program point processEnvironment__wrappee__highWaterSensorEXIT(lines 204 228) no Hoare annotation was computed. [2022-07-13 17:59:31,941 INFO L895 garLoopResultBuilder]: At program point L218(line 218) the Hoare annotation is: (let ((.cse0 (not (= 1 ~systemActive~0))) (.cse1 (<= ~waterLevel~0 1))) (and (or (not (= |old(~pumpRunning~0)| 0)) .cse0 (not (<= ~waterLevel~0 2)) (and (= ~pumpRunning~0 0) .cse1 (= |processEnvironment__wrappee__highWaterSensor_~tmp~1#1| 0))) (or .cse0 (not (<= 1 |old(~pumpRunning~0)|)) (not .cse1)))) [2022-07-13 17:59:31,942 INFO L895 garLoopResultBuilder]: At program point L342(lines 327 345) the Hoare annotation is: (let ((.cse0 (not (= 1 ~systemActive~0))) (.cse1 (<= ~waterLevel~0 1))) (and (or .cse0 (not (<= 1 |old(~pumpRunning~0)|)) (not .cse1)) (let ((.cse2 (= ~pumpRunning~0 0))) (or (not (= |old(~pumpRunning~0)| 0)) .cse0 (and .cse2 (= |processEnvironment__wrappee__highWaterSensor_isHighWaterLevel_~tmp___0~1#1| 0) .cse1 (= |processEnvironment__wrappee__highWaterSensor_isHighWaterLevel_#res#1| 0)) (not (<= ~waterLevel~0 2)) (and (= |processEnvironment__wrappee__highWaterSensor_isHighWaterLevel_~tmp~3#1| 0) .cse2 (<= 2 ~waterLevel~0) (<= 1 |processEnvironment__wrappee__highWaterSensor_isHighWaterLevel_#res#1|) (<= 1 |processEnvironment__wrappee__highWaterSensor_isHighWaterLevel_~tmp___0~1#1|) (= |processEnvironment__wrappee__highWaterSensor_isHighWaterSensorDry_#res#1| 0)))))) [2022-07-13 17:59:31,942 INFO L899 garLoopResultBuilder]: For program point L212(lines 212 220) no Hoare annotation was computed. [2022-07-13 17:59:31,942 INFO L899 garLoopResultBuilder]: For program point L208(lines 208 225) no Hoare annotation was computed. [2022-07-13 17:59:31,942 INFO L899 garLoopResultBuilder]: For program point L336(lines 336 340) no Hoare annotation was computed. [2022-07-13 17:59:31,942 INFO L899 garLoopResultBuilder]: For program point L910(lines 910 916) no Hoare annotation was computed. [2022-07-13 17:59:31,942 INFO L899 garLoopResultBuilder]: For program point L336-2(lines 336 340) no Hoare annotation was computed. [2022-07-13 17:59:31,942 INFO L895 garLoopResultBuilder]: At program point L260(lines 255 262) the Hoare annotation is: (let ((.cse0 (not (= 1 ~systemActive~0)))) (and (or .cse0 (not (<= 1 |old(~pumpRunning~0)|)) (not (<= ~waterLevel~0 1))) (or (not (= |old(~pumpRunning~0)| 0)) .cse0 (not (<= ~waterLevel~0 2)) (and (<= 1 ~pumpRunning~0) (= |processEnvironment__wrappee__highWaterSensor_isHighWaterLevel_~tmp~3#1| 0) (<= 2 ~waterLevel~0) (<= 1 |processEnvironment__wrappee__highWaterSensor_isHighWaterLevel_#res#1|) (<= 1 |processEnvironment__wrappee__highWaterSensor_isHighWaterLevel_~tmp___0~1#1|) (<= 1 |processEnvironment__wrappee__highWaterSensor_~tmp~1#1|) (= |processEnvironment__wrappee__highWaterSensor_isHighWaterSensorDry_#res#1| 0))))) [2022-07-13 17:59:31,942 INFO L899 garLoopResultBuilder]: For program point waterRiseEXIT(lines 841 852) no Hoare annotation was computed. [2022-07-13 17:59:31,942 INFO L899 garLoopResultBuilder]: For program point L845-1(lines 841 852) no Hoare annotation was computed. [2022-07-13 17:59:31,942 INFO L895 garLoopResultBuilder]: At program point waterRiseENTRY(lines 841 852) the Hoare annotation is: (let ((.cse0 (not (= 1 ~systemActive~0))) (.cse1 (= |old(~waterLevel~0)| ~waterLevel~0))) (and (or .cse0 (not (<= 1 ~pumpRunning~0)) .cse1 (not (<= |old(~waterLevel~0)| 2))) (or (not (<= |old(~waterLevel~0)| 1)) (not (= ~pumpRunning~0 0)) .cse0 .cse1))) [2022-07-13 17:59:31,945 INFO L356 BasicCegarLoop]: Path program histogram: [1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-07-13 17:59:31,947 INFO L176 ceAbstractionStarter]: Computing trace abstraction results [2022-07-13 17:59:31,972 INFO L202 PluginConnector]: Adding new model de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction CFG 13.07 05:59:31 BoogieIcfgContainer [2022-07-13 17:59:31,972 INFO L132 PluginConnector]: ------------------------ END TraceAbstraction---------------------------- [2022-07-13 17:59:31,973 INFO L113 PluginConnector]: ------------------------Witness Printer---------------------------- [2022-07-13 17:59:31,973 INFO L271 PluginConnector]: Initializing Witness Printer... [2022-07-13 17:59:31,973 INFO L275 PluginConnector]: Witness Printer initialized [2022-07-13 17:59:31,973 INFO L185 PluginConnector]: Executing the observer RCFGCatcher from plugin Witness Printer for "de.uni_freiburg.informatik.ultimate.plugins.generator.rcfgbuilder CFG 13.07 05:59:22" (3/4) ... [2022-07-13 17:59:31,976 INFO L137 WitnessPrinter]: Generating witness for correct program [2022-07-13 17:59:31,981 INFO L354 RCFGBacktranslator]: Ignoring RootEdge to procedure processEnvironment__wrappee__base [2022-07-13 17:59:31,981 INFO L354 RCFGBacktranslator]: Ignoring RootEdge to procedure changeMethaneLevel [2022-07-13 17:59:31,981 INFO L354 RCFGBacktranslator]: Ignoring RootEdge to procedure isMethaneLevelCritical [2022-07-13 17:59:31,981 INFO L354 RCFGBacktranslator]: Ignoring RootEdge to procedure cleanup [2022-07-13 17:59:31,982 INFO L354 RCFGBacktranslator]: Ignoring RootEdge to procedure timeShift [2022-07-13 17:59:31,982 INFO L354 RCFGBacktranslator]: Ignoring RootEdge to procedure processEnvironment__wrappee__highWaterSensor [2022-07-13 17:59:31,982 INFO L354 RCFGBacktranslator]: Ignoring RootEdge to procedure waterRise [2022-07-13 17:59:31,988 INFO L910 BoogieBacktranslator]: Reduced CFG by removing 51 nodes and edges [2022-07-13 17:59:31,988 INFO L910 BoogieBacktranslator]: Reduced CFG by removing 22 nodes and edges [2022-07-13 17:59:31,989 INFO L910 BoogieBacktranslator]: Reduced CFG by removing 11 nodes and edges [2022-07-13 17:59:31,989 INFO L910 BoogieBacktranslator]: Reduced CFG by removing 5 nodes and edges [2022-07-13 17:59:31,989 INFO L910 BoogieBacktranslator]: Reduced CFG by removing 2 nodes and edges [2022-07-13 17:59:31,990 INFO L910 BoogieBacktranslator]: Reduced CFG by removing 1 nodes and edges [2022-07-13 17:59:31,990 INFO L910 BoogieBacktranslator]: Reduced CFG by removing 1 nodes and edges [2022-07-13 17:59:32,011 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (((pumpRunning == 0 && methaneLevelCritical == 0) && 1 == systemActive) && \result == systemActive) && waterLevel == 1 [2022-07-13 17:59:32,011 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: ((((pumpRunning == 0 && methaneLevelCritical == 0) && 1 == systemActive) && \result == systemActive) && waterLevel == 1) && tmp == systemActive [2022-07-13 17:59:32,011 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (((((1 <= pumpRunning && 1 == systemActive) && \result == systemActive) && splverifierCounter == 0) && waterLevel <= 2) && tmp == systemActive) || (((((pumpRunning == 0 && waterLevel <= 1) && 1 == systemActive) && \result == systemActive) && splverifierCounter == 0) && tmp == systemActive) [2022-07-13 17:59:32,012 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (((!(1 == systemActive) || ((pumpRunning == \old(pumpRunning) && waterLevel <= 1) && waterLevel <= \old(waterLevel))) || !(1 <= \old(pumpRunning))) || !(\old(waterLevel) <= 2)) && ((!(\old(pumpRunning) == 0) || !(1 == systemActive)) || !(\old(waterLevel) <= 2)) [2022-07-13 17:59:32,012 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: ((((!(1 == systemActive) || ((pumpRunning == \old(pumpRunning) && waterLevel <= 1) && waterLevel <= \old(waterLevel))) || !(1 <= \old(pumpRunning))) || ((pumpRunning == 0 && waterLevel <= 1) && waterLevel <= \old(waterLevel))) || !(\old(waterLevel) <= 2)) && ((((((pumpRunning == 0 && waterLevel <= 1) && \old(waterLevel) == waterLevel) || !(\old(pumpRunning) == 0)) || !(1 == systemActive)) || ((1 <= pumpRunning && 2 <= waterLevel) && \old(waterLevel) == waterLevel)) || !(\old(waterLevel) <= 2)) [2022-07-13 17:59:32,013 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (((((pumpRunning == 0 && 1 == systemActive) && \result == systemActive) && splverifierCounter == 0) && waterLevel <= 2) && tmp == systemActive) || (((((1 <= pumpRunning && 1 == systemActive) && \result == systemActive) && splverifierCounter == 0) && waterLevel <= 2) && tmp == systemActive) [2022-07-13 17:59:32,013 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: ((((((!(\old(pumpRunning) == 0) || !(1 == systemActive)) || (((pumpRunning == 0 && waterLevel <= 1) && \old(waterLevel) == waterLevel) && methaneLevelCritical == tmp)) || !(\old(waterLevel) <= 2)) || ((((1 <= pumpRunning && 2 <= waterLevel) && 1 == systemActive) && \old(waterLevel) == waterLevel) && methaneLevelCritical == tmp)) && (((((((pumpRunning == 0 && waterLevel <= 1) && waterLevel <= \old(waterLevel)) && methaneLevelCritical == tmp) || !(1 == systemActive)) || !(1 <= \old(pumpRunning))) || (((pumpRunning == \old(pumpRunning) && waterLevel <= 1) && waterLevel <= \old(waterLevel)) && methaneLevelCritical == tmp)) || !(\old(waterLevel) <= 2))) && (((((!(\old(pumpRunning) == 0) || !(1 == systemActive)) || (tmp___0 <= 1 && \result <= 1)) || !(methaneLevelCritical == 0)) || !(\old(waterLevel) <= 2)) || ((((1 <= pumpRunning && 2 <= waterLevel) && 1 == systemActive) && \old(waterLevel) == waterLevel) && methaneLevelCritical == tmp))) && ((((!(1 == systemActive) || (tmp___0 <= 1 && \result <= 1)) || !(1 <= \old(pumpRunning))) || !(methaneLevelCritical == 0)) || !(\old(waterLevel) <= 2)) [2022-07-13 17:59:32,013 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (((!(1 == systemActive) || ((pumpRunning == \old(pumpRunning) && waterLevel <= 1) && waterLevel <= \old(waterLevel))) || !(1 <= \old(pumpRunning))) || !(\old(waterLevel) <= 2)) && ((!(\old(pumpRunning) == 0) || !(1 == systemActive)) || !(\old(waterLevel) <= 2)) [2022-07-13 17:59:32,013 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: ((((((!(\old(pumpRunning) == 0) || !(\old(waterLevel) == 1)) || !(1 == systemActive)) || \result == 1) && (((!(\old(waterLevel) <= 1) || !(\old(pumpRunning) == 0)) || methaneLevelCritical == 0) || !(1 == systemActive))) && ((((!(\old(pumpRunning) == 0) || !(1 == systemActive)) || ((((1 <= pumpRunning && methaneLevelCritical == 0) && 2 <= waterLevel) && \old(waterLevel) == waterLevel) && methaneLevelCritical == tmp)) || ((((pumpRunning == 0 && waterLevel <= 1) && \old(waterLevel) == waterLevel) && methaneLevelCritical == tmp) && \result <= 1)) || !(\old(waterLevel) <= 2))) && (((methaneLevelCritical == 0 || !(1 == systemActive)) || !(1 <= \old(pumpRunning))) || !(\old(waterLevel) <= 2))) && ((((((((pumpRunning == \old(pumpRunning) && waterLevel <= 1) && waterLevel <= \old(waterLevel)) && methaneLevelCritical == tmp) && \result <= 1) || !(1 == systemActive)) || !(1 <= \old(pumpRunning))) || !(\old(waterLevel) <= 2)) || ((((pumpRunning == 0 && waterLevel <= 1) && waterLevel <= \old(waterLevel)) && methaneLevelCritical == tmp) && \result <= 1)) [2022-07-13 17:59:32,014 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (((!(1 == systemActive) || !(1 <= \old(pumpRunning))) || ((pumpRunning == 0 && waterLevel <= 1) && waterLevel <= \old(waterLevel))) || !(\old(waterLevel) <= 2)) && ((!(\old(pumpRunning) == 0) || !(1 == systemActive)) || !(\old(waterLevel) <= 2)) [2022-07-13 17:59:32,014 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: ((((!(\old(pumpRunning) == 0) || !(1 == systemActive)) || ((pumpRunning == 0 && 2 <= waterLevel) && \result == 0)) || !(waterLevel <= 2)) || ((1 <= \result && pumpRunning == 0) && waterLevel <= 1)) && ((!(1 == systemActive) || !(1 <= \old(pumpRunning))) || !(waterLevel <= 1)) [2022-07-13 17:59:32,014 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: ((((!(\old(pumpRunning) == 0) || methaneLevelCritical == 0) || !(1 == systemActive)) || !(\old(waterLevel) <= 2)) && (((!(\old(pumpRunning) == 0) || !(1 == systemActive)) || !(\old(waterLevel) <= 2)) || ((((1 <= pumpRunning && !(\result == 0)) && 2 <= waterLevel) && \old(waterLevel) == waterLevel) && methaneLevelCritical == tmp))) && ((!(1 == systemActive) || !(1 <= \old(pumpRunning))) || !(\old(waterLevel) <= 2)) [2022-07-13 17:59:32,014 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: ((!(1 == systemActive) || !(1 <= \old(pumpRunning))) || !(waterLevel <= 1)) && ((((!(\old(pumpRunning) == 0) || !(1 == systemActive)) || (((pumpRunning == 0 && tmp___0 == 0) && waterLevel <= 1) && \result == 0)) || !(waterLevel <= 2)) || (((((tmp == 0 && pumpRunning == 0) && 2 <= waterLevel) && 1 <= \result) && 1 <= tmp___0) && \result == 0)) [2022-07-13 17:59:32,014 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: ((!(1 == systemActive) || !(1 <= \old(pumpRunning))) || !(waterLevel <= 1)) && (((!(\old(pumpRunning) == 0) || !(1 == systemActive)) || !(waterLevel <= 2)) || ((((((1 <= pumpRunning && tmp == 0) && 2 <= waterLevel) && 1 <= \result) && 1 <= tmp___0) && 1 <= tmp) && \result == 0)) [2022-07-13 17:59:32,015 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: ((!(1 == systemActive) || !(1 <= \old(pumpRunning))) || !(\old(waterLevel) <= 2)) && ((!(\old(pumpRunning) == 0) || !(1 == systemActive)) || !(\old(waterLevel) <= 2)) [2022-07-13 17:59:32,032 INFO L141 WitnessManager]: Wrote witness to /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/witness.graphml [2022-07-13 17:59:32,032 INFO L132 PluginConnector]: ------------------------ END Witness Printer---------------------------- [2022-07-13 17:59:32,033 INFO L158 Benchmark]: Toolchain (without parser) took 10486.66ms. Allocated memory was 111.1MB in the beginning and 161.5MB in the end (delta: 50.3MB). Free memory was 82.4MB in the beginning and 97.0MB in the end (delta: -14.6MB). Peak memory consumption was 34.1MB. Max. memory is 16.1GB. [2022-07-13 17:59:32,033 INFO L158 Benchmark]: CDTParser took 0.37ms. Allocated memory is still 111.1MB. Free memory was 67.4MB in the beginning and 67.3MB in the end (delta: 49.3kB). There was no memory consumed. Max. memory is 16.1GB. [2022-07-13 17:59:32,033 INFO L158 Benchmark]: CACSL2BoogieTranslator took 427.90ms. Allocated memory is still 111.1MB. Free memory was 82.2MB in the beginning and 77.4MB in the end (delta: 4.9MB). Peak memory consumption was 8.4MB. Max. memory is 16.1GB. [2022-07-13 17:59:32,034 INFO L158 Benchmark]: Boogie Procedure Inliner took 73.15ms. Allocated memory is still 111.1MB. Free memory was 77.1MB in the beginning and 74.8MB in the end (delta: 2.4MB). Peak memory consumption was 2.1MB. Max. memory is 16.1GB. [2022-07-13 17:59:32,034 INFO L158 Benchmark]: Boogie Preprocessor took 38.96ms. Allocated memory is still 111.1MB. Free memory was 74.8MB in the beginning and 73.1MB in the end (delta: 1.7MB). Peak memory consumption was 2.1MB. Max. memory is 16.1GB. [2022-07-13 17:59:32,034 INFO L158 Benchmark]: RCFGBuilder took 435.65ms. Allocated memory is still 111.1MB. Free memory was 73.1MB in the beginning and 56.9MB in the end (delta: 16.1MB). Peak memory consumption was 16.8MB. Max. memory is 16.1GB. [2022-07-13 17:59:32,035 INFO L158 Benchmark]: TraceAbstraction took 9445.35ms. Allocated memory was 111.1MB in the beginning and 161.5MB in the end (delta: 50.3MB). Free memory was 56.3MB in the beginning and 103.3MB in the end (delta: -47.0MB). Peak memory consumption was 67.4MB. Max. memory is 16.1GB. [2022-07-13 17:59:32,035 INFO L158 Benchmark]: Witness Printer took 60.02ms. Allocated memory is still 161.5MB. Free memory was 102.2MB in the beginning and 97.0MB in the end (delta: 5.2MB). Peak memory consumption was 4.2MB. Max. memory is 16.1GB. [2022-07-13 17:59:32,036 INFO L339 ainManager$Toolchain]: ####################### End [Toolchain 1] ####################### --- Results --- * Results from de.uni_freiburg.informatik.ultimate.core: - StatisticsResult: Toolchain Benchmarks Benchmark results are: * CDTParser took 0.37ms. Allocated memory is still 111.1MB. Free memory was 67.4MB in the beginning and 67.3MB in the end (delta: 49.3kB). There was no memory consumed. Max. memory is 16.1GB. * CACSL2BoogieTranslator took 427.90ms. Allocated memory is still 111.1MB. Free memory was 82.2MB in the beginning and 77.4MB in the end (delta: 4.9MB). Peak memory consumption was 8.4MB. Max. memory is 16.1GB. * Boogie Procedure Inliner took 73.15ms. Allocated memory is still 111.1MB. Free memory was 77.1MB in the beginning and 74.8MB in the end (delta: 2.4MB). Peak memory consumption was 2.1MB. Max. memory is 16.1GB. * Boogie Preprocessor took 38.96ms. Allocated memory is still 111.1MB. Free memory was 74.8MB in the beginning and 73.1MB in the end (delta: 1.7MB). Peak memory consumption was 2.1MB. Max. memory is 16.1GB. * RCFGBuilder took 435.65ms. Allocated memory is still 111.1MB. Free memory was 73.1MB in the beginning and 56.9MB in the end (delta: 16.1MB). Peak memory consumption was 16.8MB. Max. memory is 16.1GB. * TraceAbstraction took 9445.35ms. Allocated memory was 111.1MB in the beginning and 161.5MB in the end (delta: 50.3MB). Free memory was 56.3MB in the beginning and 103.3MB in the end (delta: -47.0MB). Peak memory consumption was 67.4MB. Max. memory is 16.1GB. * Witness Printer took 60.02ms. Allocated memory is still 161.5MB. Free memory was 102.2MB in the beginning and 97.0MB in the end (delta: 5.2MB). Peak memory consumption was 4.2MB. Max. memory is 16.1GB. * Results from de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction: - StatisticsResult: ErrorAutomatonStatistics NumberErrorTraces: 0, NumberStatementsAllTraces: 0, NumberRelevantStatements: 0, 0.0s ErrorAutomatonConstructionTimeTotal, 0.0s FaulLocalizationTime, NumberStatementsFirstTrace: -1, TraceLengthAvg: 0, 0.0s ErrorAutomatonConstructionTimeAvg, 0.0s ErrorAutomatonDifferenceTimeAvg, 0.0s ErrorAutomatonDifferenceTimeTotal, NumberOfNoEnhancement: 0, NumberOfFiniteEnhancement: 0, NumberOfInfiniteEnhancement: 0 - PositiveResult [Line: 725]: call to reach_error is unreachable For all program executions holds that call to reach_error is unreachable at this location - StatisticsResult: Ultimate Automizer benchmark data CFG has 8 procedures, 88 locations, 1 error locations. Started 1 CEGAR loops. OverallTime: 9.4s, OverallIterations: 12, TraceHistogramMax: 3, PathProgramHistogramMax: 1, EmptinessCheckTime: 0.0s, AutomataDifference: 3.4s, DeadEndRemovalTime: 0.0s, HoareAnnotationTime: 3.7s, InitialAbstractionConstructionTime: 0.0s, HoareTripleCheckerStatistics: 0 mSolverCounterUnknown, 2372 SdHoareTripleChecker+Valid, 1.9s IncrementalHoareTripleChecker+Time, 0 mSdLazyCounter, 2341 mSDsluCounter, 4271 SdHoareTripleChecker+Invalid, 1.6s Time, 0 mProtectedAction, 0 SdHoareTripleChecker+Unchecked, 0 IncrementalHoareTripleChecker+Unchecked, 2995 mSDsCounter, 865 IncrementalHoareTripleChecker+Valid, 0 mProtectedPredicate, 2548 IncrementalHoareTripleChecker+Invalid, 3413 SdHoareTripleChecker+Unknown, 0 mSolverCounterNotChecked, 865 mSolverCounterUnsat, 1276 mSDtfsCounter, 2548 mSolverCounterSat, 0.1s SdHoareTripleChecker+Time, 0 IncrementalHoareTripleChecker+Unknown, PredicateUnifierStatistics: 0 DeclaredPredicates, 404 GetRequests, 254 SyntacticMatches, 2 SemanticMatches, 148 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 1282 ImplicationChecksByTransitivity, 1.2s Time, 0.0s BasicInterpolantAutomatonTime, BiggestAbstraction: size=299occurred in iteration=9, InterpolantAutomatonStates: 134, traceCheckStatistics: No data available, InterpolantConsolidationStatistics: No data available, PathInvariantsStatistics: No data available, 0/0 InterpolantCoveringCapability, TotalInterpolationStatistics: No data available, 0.0s DumpTime, AutomataMinimizationStatistics: 0.2s AutomataMinimizationTime, 12 MinimizatonAttempts, 65 StatesRemovedByMinimization, 8 NontrivialMinimizations, HoareAnnotationStatistics: 0.0s HoareAnnotationTime, 41 LocationsWithAnnotation, 1136 PreInvPairs, 1387 NumberOfFragments, 1402 HoareAnnotationTreeSize, 1136 FomulaSimplifications, 120 FormulaSimplificationTreeSizeReduction, 0.3s HoareSimplificationTime, 41 FomulaSimplificationsInter, 12449 FormulaSimplificationTreeSizeReductionInter, 3.4s HoareSimplificationTimeInter, RefinementEngineStatistics: TRACE_CHECK: 0.1s SsaConstructionTime, 0.3s SatisfiabilityAnalysisTime, 1.2s InterpolantComputationTime, 622 NumberOfCodeBlocks, 622 NumberOfCodeBlocksAsserted, 13 NumberOfCheckSat, 691 ConstructedInterpolants, 0 QuantifiedInterpolants, 1363 SizeOfPredicates, 4 NumberOfNonLiveVariables, 445 ConjunctsInSsa, 13 ConjunctsInUnsatCore, 14 InterpolantComputations, 11 PerfectInterpolantSequences, 61/81 InterpolantCoveringCapability, INVARIANT_SYNTHESIS: No data available, INTERPOLANT_CONSOLIDATION: No data available, ABSTRACT_INTERPRETATION: No data available, PDR: No data available, ACCELERATED_INTERPOLATION: No data available, SIFA: No data available, ReuseStatistics: No data available - AllSpecificationsHoldResult: All specifications hold 1 specifications checked. All of them hold - InvariantResult [Line: 346]: Loop Invariant Derived loop invariant: (((((pumpRunning == 0 && 1 == systemActive) && \result == systemActive) && splverifierCounter == 0) && waterLevel <= 2) && tmp == systemActive) || (((((1 <= pumpRunning && 1 == systemActive) && \result == systemActive) && splverifierCounter == 0) && waterLevel <= 2) && tmp == systemActive) - InvariantResult [Line: 785]: Loop Invariant Derived loop invariant: ((((pumpRunning == 0 && methaneLevelCritical == 0) && 1 == systemActive) && \result == systemActive) && waterLevel == 1) && tmp == systemActive - InvariantResult [Line: 255]: Loop Invariant Derived loop invariant: ((!(1 == systemActive) || !(1 <= \old(pumpRunning))) || !(waterLevel <= 1)) && (((!(\old(pumpRunning) == 0) || !(1 == systemActive)) || !(waterLevel <= 2)) || ((((((1 <= pumpRunning && tmp == 0) && 2 <= waterLevel) && 1 <= \result) && 1 <= tmp___0) && 1 <= tmp) && \result == 0)) - InvariantResult [Line: 263]: Loop Invariant Derived loop invariant: (((!(1 == systemActive) || !(1 <= \old(pumpRunning))) || ((pumpRunning == 0 && waterLevel <= 1) && waterLevel <= \old(waterLevel))) || !(\old(waterLevel) <= 2)) && ((!(\old(pumpRunning) == 0) || !(1 == systemActive)) || !(\old(waterLevel) <= 2)) - InvariantResult [Line: 721]: Loop Invariant Derived loop invariant: ((!(1 == systemActive) || !(1 <= \old(pumpRunning))) || !(\old(waterLevel) <= 2)) && ((!(\old(pumpRunning) == 0) || !(1 == systemActive)) || !(\old(waterLevel) <= 2)) - InvariantResult [Line: 78]: Loop Invariant Derived loop invariant: (((pumpRunning == 0 && methaneLevelCritical == 0) && 1 == systemActive) && \result == systemActive) && waterLevel == 1 - InvariantResult [Line: 64]: Loop Invariant Derived loop invariant: ((pumpRunning == 0 && methaneLevelCritical == 0) && 1 == systemActive) && waterLevel == 1 - InvariantResult [Line: 93]: Loop Invariant Derived loop invariant: 1 - InvariantResult [Line: 792]: Loop Invariant Derived loop invariant: 1 - InvariantResult [Line: 802]: Loop Invariant Derived loop invariant: 1 - InvariantResult [Line: 829]: Loop Invariant Derived loop invariant: (((!(1 == systemActive) || ((pumpRunning == \old(pumpRunning) && waterLevel <= 1) && waterLevel <= \old(waterLevel))) || !(1 <= \old(pumpRunning))) || !(\old(waterLevel) <= 2)) && ((!(\old(pumpRunning) == 0) || !(1 == systemActive)) || !(\old(waterLevel) <= 2)) - InvariantResult [Line: 921]: Loop Invariant Derived loop invariant: ((((((!(\old(pumpRunning) == 0) || !(1 == systemActive)) || (((pumpRunning == 0 && waterLevel <= 1) && \old(waterLevel) == waterLevel) && methaneLevelCritical == tmp)) || !(\old(waterLevel) <= 2)) || ((((1 <= pumpRunning && 2 <= waterLevel) && 1 == systemActive) && \old(waterLevel) == waterLevel) && methaneLevelCritical == tmp)) && (((((((pumpRunning == 0 && waterLevel <= 1) && waterLevel <= \old(waterLevel)) && methaneLevelCritical == tmp) || !(1 == systemActive)) || !(1 <= \old(pumpRunning))) || (((pumpRunning == \old(pumpRunning) && waterLevel <= 1) && waterLevel <= \old(waterLevel)) && methaneLevelCritical == tmp)) || !(\old(waterLevel) <= 2))) && (((((!(\old(pumpRunning) == 0) || !(1 == systemActive)) || (tmp___0 <= 1 && \result <= 1)) || !(methaneLevelCritical == 0)) || !(\old(waterLevel) <= 2)) || ((((1 <= pumpRunning && 2 <= waterLevel) && 1 == systemActive) && \old(waterLevel) == waterLevel) && methaneLevelCritical == tmp))) && ((((!(1 == systemActive) || (tmp___0 <= 1 && \result <= 1)) || !(1 <= \old(pumpRunning))) || !(methaneLevelCritical == 0)) || !(\old(waterLevel) <= 2)) - InvariantResult [Line: 71]: Loop Invariant Derived loop invariant: ((pumpRunning == 0 && methaneLevelCritical == 0) && 1 == systemActive) && waterLevel == 1 - InvariantResult [Line: 897]: Loop Invariant Derived loop invariant: ((((((!(\old(pumpRunning) == 0) || !(\old(waterLevel) == 1)) || !(1 == systemActive)) || \result == 1) && (((!(\old(waterLevel) <= 1) || !(\old(pumpRunning) == 0)) || methaneLevelCritical == 0) || !(1 == systemActive))) && ((((!(\old(pumpRunning) == 0) || !(1 == systemActive)) || ((((1 <= pumpRunning && methaneLevelCritical == 0) && 2 <= waterLevel) && \old(waterLevel) == waterLevel) && methaneLevelCritical == tmp)) || ((((pumpRunning == 0 && waterLevel <= 1) && \old(waterLevel) == waterLevel) && methaneLevelCritical == tmp) && \result <= 1)) || !(\old(waterLevel) <= 2))) && (((methaneLevelCritical == 0 || !(1 == systemActive)) || !(1 <= \old(pumpRunning))) || !(\old(waterLevel) <= 2))) && ((((((((pumpRunning == \old(pumpRunning) && waterLevel <= 1) && waterLevel <= \old(waterLevel)) && methaneLevelCritical == tmp) && \result <= 1) || !(1 == systemActive)) || !(1 <= \old(pumpRunning))) || !(\old(waterLevel) <= 2)) || ((((pumpRunning == 0 && waterLevel <= 1) && waterLevel <= \old(waterLevel)) && methaneLevelCritical == tmp) && \result <= 1)) - InvariantResult [Line: 282]: Loop Invariant Derived loop invariant: ((((!(\old(pumpRunning) == 0) || methaneLevelCritical == 0) || !(1 == systemActive)) || !(\old(waterLevel) <= 2)) && (((!(\old(pumpRunning) == 0) || !(1 == systemActive)) || !(\old(waterLevel) <= 2)) || ((((1 <= pumpRunning && !(\result == 0)) && 2 <= waterLevel) && \old(waterLevel) == waterLevel) && methaneLevelCritical == tmp))) && ((!(1 == systemActive) || !(1 <= \old(pumpRunning))) || !(\old(waterLevel) <= 2)) - InvariantResult [Line: 327]: Loop Invariant Derived loop invariant: ((!(1 == systemActive) || !(1 <= \old(pumpRunning))) || !(waterLevel <= 1)) && ((((!(\old(pumpRunning) == 0) || !(1 == systemActive)) || (((pumpRunning == 0 && tmp___0 == 0) && waterLevel <= 1) && \result == 0)) || !(waterLevel <= 2)) || (((((tmp == 0 && pumpRunning == 0) && 2 <= waterLevel) && 1 <= \result) && 1 <= tmp___0) && \result == 0)) - InvariantResult [Line: 103]: Loop Invariant Derived loop invariant: (((((1 <= pumpRunning && 1 == systemActive) && \result == systemActive) && splverifierCounter == 0) && waterLevel <= 2) && tmp == systemActive) || (((((pumpRunning == 0 && waterLevel <= 1) && 1 == systemActive) && \result == systemActive) && splverifierCounter == 0) && tmp == systemActive) - InvariantResult [Line: 271]: Loop Invariant Derived loop invariant: (((!(1 == systemActive) || ((pumpRunning == \old(pumpRunning) && waterLevel <= 1) && waterLevel <= \old(waterLevel))) || !(1 <= \old(pumpRunning))) || !(\old(waterLevel) <= 2)) && ((!(\old(pumpRunning) == 0) || !(1 == systemActive)) || !(\old(waterLevel) <= 2)) - InvariantResult [Line: 230]: Loop Invariant Derived loop invariant: ((((!(1 == systemActive) || ((pumpRunning == \old(pumpRunning) && waterLevel <= 1) && waterLevel <= \old(waterLevel))) || !(1 <= \old(pumpRunning))) || ((pumpRunning == 0 && waterLevel <= 1) && waterLevel <= \old(waterLevel))) || !(\old(waterLevel) <= 2)) && ((((((pumpRunning == 0 && waterLevel <= 1) && \old(waterLevel) == waterLevel) || !(\old(pumpRunning) == 0)) || !(1 == systemActive)) || ((1 <= pumpRunning && 2 <= waterLevel) && \old(waterLevel) == waterLevel)) || !(\old(waterLevel) <= 2)) - InvariantResult [Line: 906]: Loop Invariant Derived loop invariant: ((((!(\old(pumpRunning) == 0) || !(1 == systemActive)) || ((pumpRunning == 0 && 2 <= waterLevel) && \result == 0)) || !(waterLevel <= 2)) || ((1 <= \result && pumpRunning == 0) && waterLevel <= 1)) && ((!(1 == systemActive) || !(1 <= \old(pumpRunning))) || !(waterLevel <= 1)) - InvariantResult [Line: 102]: Loop Invariant Derived loop invariant: 0 - InvariantResult [Line: 741]: Loop Invariant Derived loop invariant: 1 - InvariantResult [Line: 731]: Loop Invariant Derived loop invariant: 1 RESULT: Ultimate proved your program to be correct! [2022-07-13 17:59:32,089 INFO L540 MonitoredProcess]: [MP /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in -t:2000 (1)] Forceful destruction successful, exit code 0 Received shutdown request... --- End real Ultimate output --- Execution finished normally Writing output log to file Ultimate.log Result: TRUE