./Ultimate.py --spec ../sv-benchmarks/c/properties/unreach-call.prp --file ../sv-benchmarks/c/product-lines/minepump_spec4_product60.cil.c --full-output --architecture 32bit -------------------------------------------------------------------------------- Checking for ERROR reachability Using default analysis Version f4b24e32 Calling Ultimate with: /usr/bin/java -Dosgi.configuration.area=/storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/data/config -Xmx15G -Xms4m -jar /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/plugins/org.eclipse.equinox.launcher_1.5.800.v20200727-1323.jar -data @noDefault -ultimatedata /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/data -tc /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/config/AutomizerReach.xml -i ../sv-benchmarks/c/product-lines/minepump_spec4_product60.cil.c -s /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/config/svcomp-Reach-32bit-Automizer_Default.epf --cacsl2boogietranslator.entry.function main --witnessprinter.witness.directory /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux --witnessprinter.witness.filename witness.graphml --witnessprinter.write.witness.besides.input.file false --witnessprinter.graph.data.specification CHECK( init(main()), LTL(G ! call(reach_error())) ) --witnessprinter.graph.data.producer Automizer --witnessprinter.graph.data.architecture 32bit --witnessprinter.graph.data.programhash 63a498e40ee7fb7960293994084186ed238562f61fafb5e109bd8b394667fc1f --- Real Ultimate output --- This is Ultimate 0.2.2-?-f4b24e3 [2022-07-13 18:00:16,065 INFO L177 SettingsManager]: Resetting all preferences to default values... [2022-07-13 18:00:16,067 INFO L181 SettingsManager]: Resetting UltimateCore preferences to default values [2022-07-13 18:00:16,096 INFO L184 SettingsManager]: Ultimate Commandline Interface provides no preferences, ignoring... [2022-07-13 18:00:16,096 INFO L181 SettingsManager]: Resetting Boogie Preprocessor preferences to default values [2022-07-13 18:00:16,098 INFO L181 SettingsManager]: Resetting Boogie Procedure Inliner preferences to default values [2022-07-13 18:00:16,100 INFO L181 SettingsManager]: Resetting Abstract Interpretation preferences to default values [2022-07-13 18:00:16,106 INFO L181 SettingsManager]: Resetting LassoRanker preferences to default values [2022-07-13 18:00:16,108 INFO L181 SettingsManager]: Resetting Reaching Definitions preferences to default values [2022-07-13 18:00:16,113 INFO L181 SettingsManager]: Resetting SyntaxChecker preferences to default values [2022-07-13 18:00:16,114 INFO L181 SettingsManager]: Resetting Sifa preferences to default values [2022-07-13 18:00:16,115 INFO L184 SettingsManager]: Büchi Program Product provides no preferences, ignoring... [2022-07-13 18:00:16,116 INFO L181 SettingsManager]: Resetting LTL2Aut preferences to default values [2022-07-13 18:00:16,117 INFO L181 SettingsManager]: Resetting PEA to Boogie preferences to default values [2022-07-13 18:00:16,119 INFO L181 SettingsManager]: Resetting BlockEncodingV2 preferences to default values [2022-07-13 18:00:16,121 INFO L181 SettingsManager]: Resetting ChcToBoogie preferences to default values [2022-07-13 18:00:16,122 INFO L181 SettingsManager]: Resetting AutomataScriptInterpreter preferences to default values [2022-07-13 18:00:16,122 INFO L181 SettingsManager]: Resetting BuchiAutomizer preferences to default values [2022-07-13 18:00:16,124 INFO L181 SettingsManager]: Resetting CACSL2BoogieTranslator preferences to default values [2022-07-13 18:00:16,128 INFO L181 SettingsManager]: Resetting CodeCheck preferences to default values [2022-07-13 18:00:16,132 INFO L181 SettingsManager]: Resetting HornVerifier preferences to default values [2022-07-13 18:00:16,133 INFO L181 SettingsManager]: Resetting InvariantSynthesis preferences to default values [2022-07-13 18:00:16,134 INFO L181 SettingsManager]: Resetting RCFGBuilder preferences to default values [2022-07-13 18:00:16,134 INFO L181 SettingsManager]: Resetting Referee preferences to default values [2022-07-13 18:00:16,135 INFO L181 SettingsManager]: Resetting TraceAbstraction preferences to default values [2022-07-13 18:00:16,138 INFO L184 SettingsManager]: TraceAbstractionConcurrent provides no preferences, ignoring... [2022-07-13 18:00:16,139 INFO L184 SettingsManager]: TraceAbstractionWithAFAs provides no preferences, ignoring... [2022-07-13 18:00:16,140 INFO L181 SettingsManager]: Resetting TreeAutomizer preferences to default values [2022-07-13 18:00:16,141 INFO L181 SettingsManager]: Resetting IcfgToChc preferences to default values [2022-07-13 18:00:16,142 INFO L181 SettingsManager]: Resetting IcfgTransformer preferences to default values [2022-07-13 18:00:16,143 INFO L184 SettingsManager]: ReqToTest provides no preferences, ignoring... [2022-07-13 18:00:16,143 INFO L181 SettingsManager]: Resetting Boogie Printer preferences to default values [2022-07-13 18:00:16,145 INFO L181 SettingsManager]: Resetting ChcSmtPrinter preferences to default values [2022-07-13 18:00:16,145 INFO L181 SettingsManager]: Resetting ReqPrinter preferences to default values [2022-07-13 18:00:16,146 INFO L181 SettingsManager]: Resetting Witness Printer preferences to default values [2022-07-13 18:00:16,146 INFO L184 SettingsManager]: Boogie PL CUP Parser provides no preferences, ignoring... [2022-07-13 18:00:16,147 INFO L181 SettingsManager]: Resetting CDTParser preferences to default values [2022-07-13 18:00:16,147 INFO L184 SettingsManager]: AutomataScriptParser provides no preferences, ignoring... [2022-07-13 18:00:16,147 INFO L184 SettingsManager]: ReqParser provides no preferences, ignoring... [2022-07-13 18:00:16,148 INFO L181 SettingsManager]: Resetting SmtParser preferences to default values [2022-07-13 18:00:16,148 INFO L181 SettingsManager]: Resetting Witness Parser preferences to default values [2022-07-13 18:00:16,150 INFO L188 SettingsManager]: Finished resetting all preferences to default values... [2022-07-13 18:00:16,151 INFO L101 SettingsManager]: Beginning loading settings from /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/config/svcomp-Reach-32bit-Automizer_Default.epf [2022-07-13 18:00:16,184 INFO L113 SettingsManager]: Loading preferences was successful [2022-07-13 18:00:16,184 INFO L115 SettingsManager]: Preferences different from defaults after loading the file: [2022-07-13 18:00:16,185 INFO L136 SettingsManager]: Preferences of UltimateCore differ from their defaults: [2022-07-13 18:00:16,185 INFO L138 SettingsManager]: * Log level for class=de.uni_freiburg.informatik.ultimate.lib.smtlibutils.quantifier.QuantifierPusher=ERROR; [2022-07-13 18:00:16,186 INFO L136 SettingsManager]: Preferences of Boogie Procedure Inliner differ from their defaults: [2022-07-13 18:00:16,186 INFO L138 SettingsManager]: * Ignore calls to procedures called more than once=ONLY_FOR_SEQUENTIAL_PROGRAMS [2022-07-13 18:00:16,186 INFO L136 SettingsManager]: Preferences of BlockEncodingV2 differ from their defaults: [2022-07-13 18:00:16,186 INFO L138 SettingsManager]: * Create parallel compositions if possible=false [2022-07-13 18:00:16,187 INFO L138 SettingsManager]: * Use SBE=true [2022-07-13 18:00:16,188 INFO L136 SettingsManager]: Preferences of CACSL2BoogieTranslator differ from their defaults: [2022-07-13 18:00:16,188 INFO L138 SettingsManager]: * sizeof long=4 [2022-07-13 18:00:16,188 INFO L138 SettingsManager]: * Overapproximate operations on floating types=true [2022-07-13 18:00:16,188 INFO L138 SettingsManager]: * sizeof POINTER=4 [2022-07-13 18:00:16,188 INFO L138 SettingsManager]: * Check division by zero=IGNORE [2022-07-13 18:00:16,189 INFO L138 SettingsManager]: * Pointer to allocated memory at dereference=IGNORE [2022-07-13 18:00:16,189 INFO L138 SettingsManager]: * If two pointers are subtracted or compared they have the same base address=IGNORE [2022-07-13 18:00:16,189 INFO L138 SettingsManager]: * Check array bounds for arrays that are off heap=IGNORE [2022-07-13 18:00:16,189 INFO L138 SettingsManager]: * sizeof long double=12 [2022-07-13 18:00:16,189 INFO L138 SettingsManager]: * Check if freed pointer was valid=false [2022-07-13 18:00:16,191 INFO L138 SettingsManager]: * Use constant arrays=true [2022-07-13 18:00:16,191 INFO L138 SettingsManager]: * Pointer base address is valid at dereference=IGNORE [2022-07-13 18:00:16,191 INFO L136 SettingsManager]: Preferences of RCFGBuilder differ from their defaults: [2022-07-13 18:00:16,191 INFO L138 SettingsManager]: * Size of a code block=SequenceOfStatements [2022-07-13 18:00:16,192 INFO L138 SettingsManager]: * SMT solver=External_DefaultMode [2022-07-13 18:00:16,192 INFO L138 SettingsManager]: * Command for external solver=z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in -t:2000 [2022-07-13 18:00:16,192 INFO L136 SettingsManager]: Preferences of TraceAbstraction differ from their defaults: [2022-07-13 18:00:16,192 INFO L138 SettingsManager]: * Compute Interpolants along a Counterexample=FPandBP [2022-07-13 18:00:16,192 INFO L138 SettingsManager]: * Positions where we compute the Hoare Annotation=LoopsAndPotentialCycles [2022-07-13 18:00:16,193 INFO L138 SettingsManager]: * Trace refinement strategy=CAMEL [2022-07-13 18:00:16,193 INFO L138 SettingsManager]: * Command for external solver=z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in [2022-07-13 18:00:16,193 INFO L138 SettingsManager]: * Apply one-shot large block encoding in concurrent analysis=false [2022-07-13 18:00:16,193 INFO L138 SettingsManager]: * Automaton type used in concurrency analysis=PETRI_NET [2022-07-13 18:00:16,193 INFO L138 SettingsManager]: * Compute Hoare Annotation of negated interpolant automaton, abstraction and CFG=true [2022-07-13 18:00:16,194 INFO L138 SettingsManager]: * SMT solver=External_ModelsAndUnsatCoreMode WARNING: An illegal reflective access operation has occurred WARNING: Illegal reflective access by com.sun.xml.bind.v2.runtime.reflect.opt.Injector$1 (file:/storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/plugins/com.sun.xml.bind_2.2.0.v201505121915.jar) to method java.lang.ClassLoader.defineClass(java.lang.String,byte[],int,int) WARNING: Please consider reporting this to the maintainers of com.sun.xml.bind.v2.runtime.reflect.opt.Injector$1 WARNING: Use --illegal-access=warn to enable warnings of further illegal reflective access operations WARNING: All illegal access operations will be denied in a future release Applying setting for plugin de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator: Entry function -> main Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Witness directory -> /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Witness filename -> witness.graphml Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Write witness besides input file -> false Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Graph data specification -> CHECK( init(main()), LTL(G ! call(reach_error())) ) Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Graph data producer -> Automizer Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Graph data architecture -> 32bit Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Graph data programhash -> 63a498e40ee7fb7960293994084186ed238562f61fafb5e109bd8b394667fc1f [2022-07-13 18:00:16,419 INFO L75 nceAwareModelManager]: Repository-Root is: /tmp [2022-07-13 18:00:16,443 INFO L261 ainManager$Toolchain]: [Toolchain 1]: Applicable parser(s) successfully (re)initialized [2022-07-13 18:00:16,446 INFO L217 ainManager$Toolchain]: [Toolchain 1]: Toolchain selected. [2022-07-13 18:00:16,462 INFO L271 PluginConnector]: Initializing CDTParser... [2022-07-13 18:00:16,464 INFO L275 PluginConnector]: CDTParser initialized [2022-07-13 18:00:16,465 INFO L432 ainManager$Toolchain]: [Toolchain 1]: Parsing single file: /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/../sv-benchmarks/c/product-lines/minepump_spec4_product60.cil.c [2022-07-13 18:00:16,520 INFO L220 CDTParser]: Created temporary CDT project at /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/data/742441131/707bea683e124d13a3b6eac369be3209/FLAG54bc7606f [2022-07-13 18:00:16,935 INFO L306 CDTParser]: Found 1 translation units. [2022-07-13 18:00:16,936 INFO L160 CDTParser]: Scanning /storage/repos/ultimate/releaseScripts/default/sv-benchmarks/c/product-lines/minepump_spec4_product60.cil.c [2022-07-13 18:00:16,945 INFO L349 CDTParser]: About to delete temporary CDT project at /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/data/742441131/707bea683e124d13a3b6eac369be3209/FLAG54bc7606f [2022-07-13 18:00:16,966 INFO L357 CDTParser]: Successfully deleted /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/data/742441131/707bea683e124d13a3b6eac369be3209 [2022-07-13 18:00:16,968 INFO L299 ainManager$Toolchain]: ####################### [Toolchain 1] ####################### [2022-07-13 18:00:16,969 INFO L131 ToolchainWalker]: Walking toolchain with 6 elements. [2022-07-13 18:00:16,970 INFO L113 PluginConnector]: ------------------------CACSL2BoogieTranslator---------------------------- [2022-07-13 18:00:16,970 INFO L271 PluginConnector]: Initializing CACSL2BoogieTranslator... [2022-07-13 18:00:16,972 INFO L275 PluginConnector]: CACSL2BoogieTranslator initialized [2022-07-13 18:00:16,973 INFO L185 PluginConnector]: Executing the observer ACSLObjectContainerObserver from plugin CACSL2BoogieTranslator for "CDTParser AST 13.07 06:00:16" (1/1) ... [2022-07-13 18:00:16,974 INFO L205 PluginConnector]: Invalid model from CACSL2BoogieTranslator for observer de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator.ACSLObjectContainerObserver@5d6f16eb and model type de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 13.07 06:00:16, skipping insertion in model container [2022-07-13 18:00:16,974 INFO L185 PluginConnector]: Executing the observer CACSL2BoogieTranslatorObserver from plugin CACSL2BoogieTranslator for "CDTParser AST 13.07 06:00:16" (1/1) ... [2022-07-13 18:00:16,979 INFO L145 MainTranslator]: Starting translation in SV-COMP mode [2022-07-13 18:00:17,031 INFO L178 MainTranslator]: Built tables and reachable declarations [2022-07-13 18:00:17,308 WARN L230 ndardFunctionHandler]: Function reach_error is already implemented but we override the implementation for the call at /storage/repos/ultimate/releaseScripts/default/sv-benchmarks/c/product-lines/minepump_spec4_product60.cil.c[13463,13476] [2022-07-13 18:00:17,335 INFO L210 PostProcessor]: Analyzing one entry point: main [2022-07-13 18:00:17,347 INFO L203 MainTranslator]: Completed pre-run [2022-07-13 18:00:17,421 WARN L230 ndardFunctionHandler]: Function reach_error is already implemented but we override the implementation for the call at /storage/repos/ultimate/releaseScripts/default/sv-benchmarks/c/product-lines/minepump_spec4_product60.cil.c[13463,13476] [2022-07-13 18:00:17,449 INFO L210 PostProcessor]: Analyzing one entry point: main [2022-07-13 18:00:17,465 INFO L208 MainTranslator]: Completed translation [2022-07-13 18:00:17,466 INFO L202 PluginConnector]: Adding new model de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 13.07 06:00:17 WrapperNode [2022-07-13 18:00:17,466 INFO L132 PluginConnector]: ------------------------ END CACSL2BoogieTranslator---------------------------- [2022-07-13 18:00:17,468 INFO L113 PluginConnector]: ------------------------Boogie Procedure Inliner---------------------------- [2022-07-13 18:00:17,468 INFO L271 PluginConnector]: Initializing Boogie Procedure Inliner... [2022-07-13 18:00:17,468 INFO L275 PluginConnector]: Boogie Procedure Inliner initialized [2022-07-13 18:00:17,474 INFO L185 PluginConnector]: Executing the observer TypeChecker from plugin Boogie Procedure Inliner for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 13.07 06:00:17" (1/1) ... [2022-07-13 18:00:17,496 INFO L185 PluginConnector]: Executing the observer Inliner from plugin Boogie Procedure Inliner for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 13.07 06:00:17" (1/1) ... [2022-07-13 18:00:17,535 INFO L137 Inliner]: procedures = 58, calls = 159, calls flagged for inlining = 27, calls inlined = 24, statements flattened = 286 [2022-07-13 18:00:17,536 INFO L132 PluginConnector]: ------------------------ END Boogie Procedure Inliner---------------------------- [2022-07-13 18:00:17,537 INFO L113 PluginConnector]: ------------------------Boogie Preprocessor---------------------------- [2022-07-13 18:00:17,537 INFO L271 PluginConnector]: Initializing Boogie Preprocessor... [2022-07-13 18:00:17,537 INFO L275 PluginConnector]: Boogie Preprocessor initialized [2022-07-13 18:00:17,544 INFO L185 PluginConnector]: Executing the observer EnsureBoogieModelObserver from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 13.07 06:00:17" (1/1) ... [2022-07-13 18:00:17,544 INFO L185 PluginConnector]: Executing the observer TypeChecker from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 13.07 06:00:17" (1/1) ... [2022-07-13 18:00:17,546 INFO L185 PluginConnector]: Executing the observer ConstExpander from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 13.07 06:00:17" (1/1) ... [2022-07-13 18:00:17,546 INFO L185 PluginConnector]: Executing the observer StructExpander from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 13.07 06:00:17" (1/1) ... [2022-07-13 18:00:17,550 INFO L185 PluginConnector]: Executing the observer UnstructureCode from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 13.07 06:00:17" (1/1) ... [2022-07-13 18:00:17,554 INFO L185 PluginConnector]: Executing the observer FunctionInliner from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 13.07 06:00:17" (1/1) ... [2022-07-13 18:00:17,556 INFO L185 PluginConnector]: Executing the observer BoogieSymbolTableConstructor from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 13.07 06:00:17" (1/1) ... [2022-07-13 18:00:17,558 INFO L132 PluginConnector]: ------------------------ END Boogie Preprocessor---------------------------- [2022-07-13 18:00:17,559 INFO L113 PluginConnector]: ------------------------RCFGBuilder---------------------------- [2022-07-13 18:00:17,559 INFO L271 PluginConnector]: Initializing RCFGBuilder... [2022-07-13 18:00:17,559 INFO L275 PluginConnector]: RCFGBuilder initialized [2022-07-13 18:00:17,560 INFO L185 PluginConnector]: Executing the observer RCFGBuilderObserver from plugin RCFGBuilder for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 13.07 06:00:17" (1/1) ... [2022-07-13 18:00:17,577 INFO L173 SolverBuilder]: Constructing external solver with command: z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in -t:2000 [2022-07-13 18:00:17,587 INFO L189 MonitoredProcess]: No working directory specified, using /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 [2022-07-13 18:00:17,607 INFO L229 MonitoredProcess]: Starting monitored process 1 with /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in -t:2000 (exit command is (exit), workingDir is null) [2022-07-13 18:00:17,611 INFO L327 MonitoredProcess]: [MP /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in -t:2000 (1)] Waiting until timeout for monitored process [2022-07-13 18:00:17,641 INFO L130 BoogieDeclarations]: Found specification of procedure #Ultimate.allocInit [2022-07-13 18:00:17,641 INFO L130 BoogieDeclarations]: Found specification of procedure processEnvironment__wrappee__base [2022-07-13 18:00:17,641 INFO L138 BoogieDeclarations]: Found implementation of procedure processEnvironment__wrappee__base [2022-07-13 18:00:17,641 INFO L130 BoogieDeclarations]: Found specification of procedure timeShift [2022-07-13 18:00:17,642 INFO L138 BoogieDeclarations]: Found implementation of procedure timeShift [2022-07-13 18:00:17,642 INFO L130 BoogieDeclarations]: Found specification of procedure cleanup [2022-07-13 18:00:17,642 INFO L138 BoogieDeclarations]: Found implementation of procedure cleanup [2022-07-13 18:00:17,642 INFO L130 BoogieDeclarations]: Found specification of procedure processEnvironment__wrappee__highWaterSensor [2022-07-13 18:00:17,642 INFO L138 BoogieDeclarations]: Found implementation of procedure processEnvironment__wrappee__highWaterSensor [2022-07-13 18:00:17,642 INFO L130 BoogieDeclarations]: Found specification of procedure waterRise [2022-07-13 18:00:17,643 INFO L138 BoogieDeclarations]: Found implementation of procedure waterRise [2022-07-13 18:00:17,643 INFO L130 BoogieDeclarations]: Found specification of procedure deactivatePump [2022-07-13 18:00:17,643 INFO L138 BoogieDeclarations]: Found implementation of procedure deactivatePump [2022-07-13 18:00:17,643 INFO L130 BoogieDeclarations]: Found specification of procedure write~init~int [2022-07-13 18:00:17,643 INFO L130 BoogieDeclarations]: Found specification of procedure changeMethaneLevel [2022-07-13 18:00:17,644 INFO L138 BoogieDeclarations]: Found implementation of procedure changeMethaneLevel [2022-07-13 18:00:17,644 INFO L130 BoogieDeclarations]: Found specification of procedure ULTIMATE.start [2022-07-13 18:00:17,644 INFO L138 BoogieDeclarations]: Found implementation of procedure ULTIMATE.start [2022-07-13 18:00:17,705 INFO L234 CfgBuilder]: Building ICFG [2022-07-13 18:00:17,706 INFO L260 CfgBuilder]: Building CFG for each procedure with an implementation [2022-07-13 18:00:18,001 INFO L275 CfgBuilder]: Performing block encoding [2022-07-13 18:00:18,008 INFO L294 CfgBuilder]: Using the 1 location(s) as analysis (start of procedure ULTIMATE.start) [2022-07-13 18:00:18,008 INFO L299 CfgBuilder]: Removed 2 assume(true) statements. [2022-07-13 18:00:18,010 INFO L202 PluginConnector]: Adding new model de.uni_freiburg.informatik.ultimate.plugins.generator.rcfgbuilder CFG 13.07 06:00:18 BoogieIcfgContainer [2022-07-13 18:00:18,010 INFO L132 PluginConnector]: ------------------------ END RCFGBuilder---------------------------- [2022-07-13 18:00:18,012 INFO L113 PluginConnector]: ------------------------TraceAbstraction---------------------------- [2022-07-13 18:00:18,012 INFO L271 PluginConnector]: Initializing TraceAbstraction... [2022-07-13 18:00:18,017 INFO L275 PluginConnector]: TraceAbstraction initialized [2022-07-13 18:00:18,017 INFO L185 PluginConnector]: Executing the observer TraceAbstractionObserver from plugin TraceAbstraction for "CDTParser AST 13.07 06:00:16" (1/3) ... [2022-07-13 18:00:18,018 INFO L205 PluginConnector]: Invalid model from TraceAbstraction for observer de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction.TraceAbstractionObserver@51d4c607 and model type de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction AST 13.07 06:00:18, skipping insertion in model container [2022-07-13 18:00:18,018 INFO L185 PluginConnector]: Executing the observer TraceAbstractionObserver from plugin TraceAbstraction for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 13.07 06:00:17" (2/3) ... [2022-07-13 18:00:18,018 INFO L205 PluginConnector]: Invalid model from TraceAbstraction for observer de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction.TraceAbstractionObserver@51d4c607 and model type de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction AST 13.07 06:00:18, skipping insertion in model container [2022-07-13 18:00:18,019 INFO L185 PluginConnector]: Executing the observer TraceAbstractionObserver from plugin TraceAbstraction for "de.uni_freiburg.informatik.ultimate.plugins.generator.rcfgbuilder CFG 13.07 06:00:18" (3/3) ... [2022-07-13 18:00:18,020 INFO L111 eAbstractionObserver]: Analyzing ICFG minepump_spec4_product60.cil.c [2022-07-13 18:00:18,033 INFO L201 ceAbstractionStarter]: Automizer settings: Hoare:true NWA Interpolation:FPandBP Determinization: PREDICATE_ABSTRACTION [2022-07-13 18:00:18,033 INFO L160 ceAbstractionStarter]: Applying trace abstraction to program that has 1 error locations. [2022-07-13 18:00:18,082 INFO L356 AbstractCegarLoop]: ======== Iteration 0 == of CEGAR loop == AllErrorsAtOnce ======== [2022-07-13 18:00:18,089 INFO L357 AbstractCegarLoop]: Settings: SEPARATE_VIOLATION_CHECK=true, mInterprocedural=true, mMaxIterations=1000000, mWatchIteration=1000000, mArtifact=RCFG, mInterpolation=FPandBP, mInterpolantAutomaton=STRAIGHT_LINE, mDumpAutomata=false, mAutomataFormat=ATS_NUMERATE, mDumpPath=., mDeterminiation=PREDICATE_ABSTRACTION, mMinimize=MINIMIZE_SEVPA, mHoare=true, mAutomataTypeConcurrency=PETRI_NET, mHoareTripleChecks=INCREMENTAL, mHoareAnnotationPositions=LoopsAndPotentialCycles, mDumpOnlyReuseAutomata=false, mLimitTraceHistogram=0, mErrorLocTimeLimit=0, mLimitPathProgramCount=0, mCollectInterpolantStatistics=true, mHeuristicEmptinessCheck=false, mHeuristicEmptinessCheckAStarHeuristic=ZERO, mHeuristicEmptinessCheckAStarHeuristicRandomSeed=1337, mHeuristicEmptinessCheckSmtFeatureScoringMethod=DAGSIZE, mSMTFeatureExtraction=false, mSMTFeatureExtractionDumpPath=., mOverrideInterpolantAutomaton=false, mMcrInterpolantMethod=WP, mPorIndependenceSettings=de.uni_freiburg.informatik.ultimate.lib.tracecheckerutils.partialorder.independence.IndependenceSettings@6364774f, mLbeIndependenceSettings=de.uni_freiburg.informatik.ultimate.lib.tracecheckerutils.partialorder.independence.IndependenceSettings@7f68c700 [2022-07-13 18:00:18,089 INFO L358 AbstractCegarLoop]: Starting to check reachability of 1 error locations. [2022-07-13 18:00:18,095 INFO L276 IsEmpty]: Start isEmpty. Operand has 94 states, 73 states have (on average 1.3835616438356164) internal successors, (101), 82 states have internal predecessors, (101), 12 states have call successors, (12), 7 states have call predecessors, (12), 7 states have return successors, (12), 9 states have call predecessors, (12), 12 states have call successors, (12) [2022-07-13 18:00:18,103 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 20 [2022-07-13 18:00:18,103 INFO L187 NwaCegarLoop]: Found error trace [2022-07-13 18:00:18,103 INFO L195 NwaCegarLoop]: trace histogram [1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-07-13 18:00:18,104 INFO L420 AbstractCegarLoop]: === Iteration 1 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2022-07-13 18:00:18,108 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2022-07-13 18:00:18,108 INFO L85 PathProgramCache]: Analyzing trace with hash 194395982, now seen corresponding path program 1 times [2022-07-13 18:00:18,116 INFO L118 FreeRefinementEngine]: Executing refinement strategy CAMEL [2022-07-13 18:00:18,116 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [1836369734] [2022-07-13 18:00:18,117 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-07-13 18:00:18,117 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2022-07-13 18:00:18,240 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-07-13 18:00:18,293 INFO L134 CoverageAnalysis]: Checked inductivity of 0 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2022-07-13 18:00:18,293 INFO L136 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2022-07-13 18:00:18,294 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [1836369734] [2022-07-13 18:00:18,294 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [1836369734] provided 1 perfect and 0 imperfect interpolant sequences [2022-07-13 18:00:18,294 INFO L184 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2022-07-13 18:00:18,295 INFO L197 FreeRefinementEngine]: Number of different interpolants: perfect sequences [2] imperfect sequences [] total 2 [2022-07-13 18:00:18,296 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [1550815404] [2022-07-13 18:00:18,296 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2022-07-13 18:00:18,300 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 2 states [2022-07-13 18:00:18,300 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2022-07-13 18:00:18,326 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 2 interpolants. [2022-07-13 18:00:18,327 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=1, Invalid=1, Unknown=0, NotChecked=0, Total=2 [2022-07-13 18:00:18,329 INFO L87 Difference]: Start difference. First operand has 94 states, 73 states have (on average 1.3835616438356164) internal successors, (101), 82 states have internal predecessors, (101), 12 states have call successors, (12), 7 states have call predecessors, (12), 7 states have return successors, (12), 9 states have call predecessors, (12), 12 states have call successors, (12) Second operand has 2 states, 2 states have (on average 8.5) internal successors, (17), 2 states have internal predecessors, (17), 1 states have call successors, (2), 1 states have call predecessors, (2), 0 states have return successors, (0), 0 states have call predecessors, (0), 0 states have call successors, (0) [2022-07-13 18:00:18,357 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-07-13 18:00:18,357 INFO L93 Difference]: Finished difference Result 180 states and 245 transitions. [2022-07-13 18:00:18,358 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 2 states. [2022-07-13 18:00:18,359 INFO L78 Accepts]: Start accepts. Automaton has has 2 states, 2 states have (on average 8.5) internal successors, (17), 2 states have internal predecessors, (17), 1 states have call successors, (2), 1 states have call predecessors, (2), 0 states have return successors, (0), 0 states have call predecessors, (0), 0 states have call successors, (0) Word has length 19 [2022-07-13 18:00:18,359 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2022-07-13 18:00:18,366 INFO L225 Difference]: With dead ends: 180 [2022-07-13 18:00:18,366 INFO L226 Difference]: Without dead ends: 85 [2022-07-13 18:00:18,369 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 2 GetRequests, 2 SyntacticMatches, 0 SemanticMatches, 0 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 0 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=1, Invalid=1, Unknown=0, NotChecked=0, Total=2 [2022-07-13 18:00:18,372 INFO L413 NwaCegarLoop]: 119 mSDtfsCounter, 0 mSDsluCounter, 0 mSDsCounter, 0 mSdLazyCounter, 0 mSolverCounterSat, 0 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.0s Time, 0 mProtectedPredicate, 0 mProtectedAction, 0 SdHoareTripleChecker+Valid, 119 SdHoareTripleChecker+Invalid, 0 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 0 IncrementalHoareTripleChecker+Valid, 0 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.0s IncrementalHoareTripleChecker+Time [2022-07-13 18:00:18,373 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [0 Valid, 119 Invalid, 0 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [0 Valid, 0 Invalid, 0 Unknown, 0 Unchecked, 0.0s Time] [2022-07-13 18:00:18,389 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 85 states. [2022-07-13 18:00:18,406 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 85 to 85. [2022-07-13 18:00:18,408 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 85 states, 66 states have (on average 1.3181818181818181) internal successors, (87), 74 states have internal predecessors, (87), 12 states have call successors, (12), 7 states have call predecessors, (12), 6 states have return successors, (11), 8 states have call predecessors, (11), 11 states have call successors, (11) [2022-07-13 18:00:18,410 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 85 states to 85 states and 110 transitions. [2022-07-13 18:00:18,411 INFO L78 Accepts]: Start accepts. Automaton has 85 states and 110 transitions. Word has length 19 [2022-07-13 18:00:18,411 INFO L84 Accepts]: Finished accepts. word is rejected. [2022-07-13 18:00:18,411 INFO L495 AbstractCegarLoop]: Abstraction has 85 states and 110 transitions. [2022-07-13 18:00:18,412 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 2 states, 2 states have (on average 8.5) internal successors, (17), 2 states have internal predecessors, (17), 1 states have call successors, (2), 1 states have call predecessors, (2), 0 states have return successors, (0), 0 states have call predecessors, (0), 0 states have call successors, (0) [2022-07-13 18:00:18,412 INFO L276 IsEmpty]: Start isEmpty. Operand 85 states and 110 transitions. [2022-07-13 18:00:18,413 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 21 [2022-07-13 18:00:18,413 INFO L187 NwaCegarLoop]: Found error trace [2022-07-13 18:00:18,413 INFO L195 NwaCegarLoop]: trace histogram [1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-07-13 18:00:18,414 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable0 [2022-07-13 18:00:18,414 INFO L420 AbstractCegarLoop]: === Iteration 2 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2022-07-13 18:00:18,415 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2022-07-13 18:00:18,415 INFO L85 PathProgramCache]: Analyzing trace with hash -891560987, now seen corresponding path program 1 times [2022-07-13 18:00:18,415 INFO L118 FreeRefinementEngine]: Executing refinement strategy CAMEL [2022-07-13 18:00:18,415 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [1669493701] [2022-07-13 18:00:18,415 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-07-13 18:00:18,416 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2022-07-13 18:00:18,441 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-07-13 18:00:18,492 INFO L134 CoverageAnalysis]: Checked inductivity of 0 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2022-07-13 18:00:18,493 INFO L136 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2022-07-13 18:00:18,493 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [1669493701] [2022-07-13 18:00:18,493 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [1669493701] provided 1 perfect and 0 imperfect interpolant sequences [2022-07-13 18:00:18,493 INFO L184 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2022-07-13 18:00:18,494 INFO L197 FreeRefinementEngine]: Number of different interpolants: perfect sequences [3] imperfect sequences [] total 3 [2022-07-13 18:00:18,494 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [513861909] [2022-07-13 18:00:18,494 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2022-07-13 18:00:18,495 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 3 states [2022-07-13 18:00:18,495 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2022-07-13 18:00:18,496 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 3 interpolants. [2022-07-13 18:00:18,496 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=3, Invalid=3, Unknown=0, NotChecked=0, Total=6 [2022-07-13 18:00:18,496 INFO L87 Difference]: Start difference. First operand 85 states and 110 transitions. Second operand has 3 states, 3 states have (on average 6.0) internal successors, (18), 3 states have internal predecessors, (18), 1 states have call successors, (2), 1 states have call predecessors, (2), 0 states have return successors, (0), 0 states have call predecessors, (0), 0 states have call successors, (0) [2022-07-13 18:00:18,510 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-07-13 18:00:18,510 INFO L93 Difference]: Finished difference Result 131 states and 169 transitions. [2022-07-13 18:00:18,511 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 3 states. [2022-07-13 18:00:18,511 INFO L78 Accepts]: Start accepts. Automaton has has 3 states, 3 states have (on average 6.0) internal successors, (18), 3 states have internal predecessors, (18), 1 states have call successors, (2), 1 states have call predecessors, (2), 0 states have return successors, (0), 0 states have call predecessors, (0), 0 states have call successors, (0) Word has length 20 [2022-07-13 18:00:18,511 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2022-07-13 18:00:18,512 INFO L225 Difference]: With dead ends: 131 [2022-07-13 18:00:18,512 INFO L226 Difference]: Without dead ends: 76 [2022-07-13 18:00:18,513 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 3 GetRequests, 2 SyntacticMatches, 0 SemanticMatches, 1 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 0 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=3, Invalid=3, Unknown=0, NotChecked=0, Total=6 [2022-07-13 18:00:18,514 INFO L413 NwaCegarLoop]: 97 mSDtfsCounter, 17 mSDsluCounter, 75 mSDsCounter, 0 mSdLazyCounter, 1 mSolverCounterSat, 0 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.0s Time, 0 mProtectedPredicate, 0 mProtectedAction, 21 SdHoareTripleChecker+Valid, 172 SdHoareTripleChecker+Invalid, 1 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 0 IncrementalHoareTripleChecker+Valid, 1 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.0s IncrementalHoareTripleChecker+Time [2022-07-13 18:00:18,515 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [21 Valid, 172 Invalid, 1 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [0 Valid, 1 Invalid, 0 Unknown, 0 Unchecked, 0.0s Time] [2022-07-13 18:00:18,515 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 76 states. [2022-07-13 18:00:18,528 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 76 to 76. [2022-07-13 18:00:18,529 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 76 states, 60 states have (on average 1.3333333333333333) internal successors, (80), 68 states have internal predecessors, (80), 9 states have call successors, (9), 6 states have call predecessors, (9), 6 states have return successors, (9), 6 states have call predecessors, (9), 9 states have call successors, (9) [2022-07-13 18:00:18,530 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 76 states to 76 states and 98 transitions. [2022-07-13 18:00:18,530 INFO L78 Accepts]: Start accepts. Automaton has 76 states and 98 transitions. Word has length 20 [2022-07-13 18:00:18,530 INFO L84 Accepts]: Finished accepts. word is rejected. [2022-07-13 18:00:18,530 INFO L495 AbstractCegarLoop]: Abstraction has 76 states and 98 transitions. [2022-07-13 18:00:18,531 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 3 states, 3 states have (on average 6.0) internal successors, (18), 3 states have internal predecessors, (18), 1 states have call successors, (2), 1 states have call predecessors, (2), 0 states have return successors, (0), 0 states have call predecessors, (0), 0 states have call successors, (0) [2022-07-13 18:00:18,531 INFO L276 IsEmpty]: Start isEmpty. Operand 76 states and 98 transitions. [2022-07-13 18:00:18,532 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 26 [2022-07-13 18:00:18,532 INFO L187 NwaCegarLoop]: Found error trace [2022-07-13 18:00:18,532 INFO L195 NwaCegarLoop]: trace histogram [1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-07-13 18:00:18,532 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable1 [2022-07-13 18:00:18,532 INFO L420 AbstractCegarLoop]: === Iteration 3 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2022-07-13 18:00:18,533 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2022-07-13 18:00:18,533 INFO L85 PathProgramCache]: Analyzing trace with hash 1763827496, now seen corresponding path program 1 times [2022-07-13 18:00:18,533 INFO L118 FreeRefinementEngine]: Executing refinement strategy CAMEL [2022-07-13 18:00:18,533 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [1009742188] [2022-07-13 18:00:18,533 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-07-13 18:00:18,534 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2022-07-13 18:00:18,585 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-07-13 18:00:18,651 INFO L134 CoverageAnalysis]: Checked inductivity of 0 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2022-07-13 18:00:18,651 INFO L136 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2022-07-13 18:00:18,651 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [1009742188] [2022-07-13 18:00:18,652 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [1009742188] provided 1 perfect and 0 imperfect interpolant sequences [2022-07-13 18:00:18,652 INFO L184 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2022-07-13 18:00:18,652 INFO L197 FreeRefinementEngine]: Number of different interpolants: perfect sequences [5] imperfect sequences [] total 5 [2022-07-13 18:00:18,652 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [1748814210] [2022-07-13 18:00:18,652 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2022-07-13 18:00:18,653 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 6 states [2022-07-13 18:00:18,653 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2022-07-13 18:00:18,653 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 6 interpolants. [2022-07-13 18:00:18,653 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=10, Invalid=20, Unknown=0, NotChecked=0, Total=30 [2022-07-13 18:00:18,654 INFO L87 Difference]: Start difference. First operand 76 states and 98 transitions. Second operand has 6 states, 6 states have (on average 4.0) internal successors, (24), 5 states have internal predecessors, (24), 1 states have call successors, (1), 1 states have call predecessors, (1), 0 states have return successors, (0), 0 states have call predecessors, (0), 0 states have call successors, (0) [2022-07-13 18:00:18,867 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-07-13 18:00:18,867 INFO L93 Difference]: Finished difference Result 266 states and 356 transitions. [2022-07-13 18:00:18,868 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 6 states. [2022-07-13 18:00:18,868 INFO L78 Accepts]: Start accepts. Automaton has has 6 states, 6 states have (on average 4.0) internal successors, (24), 5 states have internal predecessors, (24), 1 states have call successors, (1), 1 states have call predecessors, (1), 0 states have return successors, (0), 0 states have call predecessors, (0), 0 states have call successors, (0) Word has length 25 [2022-07-13 18:00:18,869 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2022-07-13 18:00:18,874 INFO L225 Difference]: With dead ends: 266 [2022-07-13 18:00:18,874 INFO L226 Difference]: Without dead ends: 197 [2022-07-13 18:00:18,878 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 7 GetRequests, 1 SyntacticMatches, 0 SemanticMatches, 6 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 0 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=22, Invalid=34, Unknown=0, NotChecked=0, Total=56 [2022-07-13 18:00:18,884 INFO L413 NwaCegarLoop]: 119 mSDtfsCounter, 284 mSDsluCounter, 339 mSDsCounter, 0 mSdLazyCounter, 101 mSolverCounterSat, 41 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.1s Time, 0 mProtectedPredicate, 0 mProtectedAction, 284 SdHoareTripleChecker+Valid, 458 SdHoareTripleChecker+Invalid, 142 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 41 IncrementalHoareTripleChecker+Valid, 101 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.1s IncrementalHoareTripleChecker+Time [2022-07-13 18:00:18,885 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [284 Valid, 458 Invalid, 142 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [41 Valid, 101 Invalid, 0 Unknown, 0 Unchecked, 0.1s Time] [2022-07-13 18:00:18,886 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 197 states. [2022-07-13 18:00:18,906 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 197 to 175. [2022-07-13 18:00:18,906 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 175 states, 136 states have (on average 1.3676470588235294) internal successors, (186), 154 states have internal predecessors, (186), 22 states have call successors, (22), 16 states have call predecessors, (22), 16 states have return successors, (23), 14 states have call predecessors, (23), 22 states have call successors, (23) [2022-07-13 18:00:18,908 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 175 states to 175 states and 231 transitions. [2022-07-13 18:00:18,908 INFO L78 Accepts]: Start accepts. Automaton has 175 states and 231 transitions. Word has length 25 [2022-07-13 18:00:18,908 INFO L84 Accepts]: Finished accepts. word is rejected. [2022-07-13 18:00:18,909 INFO L495 AbstractCegarLoop]: Abstraction has 175 states and 231 transitions. [2022-07-13 18:00:18,909 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 6 states, 6 states have (on average 4.0) internal successors, (24), 5 states have internal predecessors, (24), 1 states have call successors, (1), 1 states have call predecessors, (1), 0 states have return successors, (0), 0 states have call predecessors, (0), 0 states have call successors, (0) [2022-07-13 18:00:18,909 INFO L276 IsEmpty]: Start isEmpty. Operand 175 states and 231 transitions. [2022-07-13 18:00:18,910 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 29 [2022-07-13 18:00:18,910 INFO L187 NwaCegarLoop]: Found error trace [2022-07-13 18:00:18,910 INFO L195 NwaCegarLoop]: trace histogram [1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-07-13 18:00:18,910 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable2 [2022-07-13 18:00:18,911 INFO L420 AbstractCegarLoop]: === Iteration 4 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2022-07-13 18:00:18,911 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2022-07-13 18:00:18,911 INFO L85 PathProgramCache]: Analyzing trace with hash 687850495, now seen corresponding path program 1 times [2022-07-13 18:00:18,911 INFO L118 FreeRefinementEngine]: Executing refinement strategy CAMEL [2022-07-13 18:00:18,911 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [1883386441] [2022-07-13 18:00:18,911 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-07-13 18:00:18,912 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2022-07-13 18:00:18,930 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-07-13 18:00:18,968 INFO L134 CoverageAnalysis]: Checked inductivity of 0 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2022-07-13 18:00:18,969 INFO L136 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2022-07-13 18:00:18,969 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [1883386441] [2022-07-13 18:00:18,969 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [1883386441] provided 1 perfect and 0 imperfect interpolant sequences [2022-07-13 18:00:18,969 INFO L184 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2022-07-13 18:00:18,969 INFO L197 FreeRefinementEngine]: Number of different interpolants: perfect sequences [4] imperfect sequences [] total 4 [2022-07-13 18:00:18,969 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [674166331] [2022-07-13 18:00:18,969 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2022-07-13 18:00:18,970 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 5 states [2022-07-13 18:00:18,970 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2022-07-13 18:00:18,970 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 5 interpolants. [2022-07-13 18:00:18,970 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=7, Invalid=13, Unknown=0, NotChecked=0, Total=20 [2022-07-13 18:00:18,971 INFO L87 Difference]: Start difference. First operand 175 states and 231 transitions. Second operand has 5 states, 5 states have (on average 5.4) internal successors, (27), 4 states have internal predecessors, (27), 1 states have call successors, (1), 1 states have call predecessors, (1), 0 states have return successors, (0), 0 states have call predecessors, (0), 0 states have call successors, (0) [2022-07-13 18:00:19,029 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-07-13 18:00:19,029 INFO L93 Difference]: Finished difference Result 494 states and 678 transitions. [2022-07-13 18:00:19,030 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 5 states. [2022-07-13 18:00:19,030 INFO L78 Accepts]: Start accepts. Automaton has has 5 states, 5 states have (on average 5.4) internal successors, (27), 4 states have internal predecessors, (27), 1 states have call successors, (1), 1 states have call predecessors, (1), 0 states have return successors, (0), 0 states have call predecessors, (0), 0 states have call successors, (0) Word has length 28 [2022-07-13 18:00:19,030 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2022-07-13 18:00:19,038 INFO L225 Difference]: With dead ends: 494 [2022-07-13 18:00:19,038 INFO L226 Difference]: Without dead ends: 326 [2022-07-13 18:00:19,039 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 7 GetRequests, 2 SyntacticMatches, 0 SemanticMatches, 5 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 0 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=17, Invalid=25, Unknown=0, NotChecked=0, Total=42 [2022-07-13 18:00:19,048 INFO L413 NwaCegarLoop]: 100 mSDtfsCounter, 69 mSDsluCounter, 285 mSDsCounter, 0 mSdLazyCounter, 29 mSolverCounterSat, 4 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.0s Time, 0 mProtectedPredicate, 0 mProtectedAction, 69 SdHoareTripleChecker+Valid, 385 SdHoareTripleChecker+Invalid, 33 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 4 IncrementalHoareTripleChecker+Valid, 29 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.0s IncrementalHoareTripleChecker+Time [2022-07-13 18:00:19,048 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [69 Valid, 385 Invalid, 33 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [4 Valid, 29 Invalid, 0 Unknown, 0 Unchecked, 0.0s Time] [2022-07-13 18:00:19,049 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 326 states. [2022-07-13 18:00:19,090 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 326 to 326. [2022-07-13 18:00:19,091 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 326 states, 252 states have (on average 1.3412698412698412) internal successors, (338), 284 states have internal predecessors, (338), 44 states have call successors, (44), 32 states have call predecessors, (44), 29 states have return successors, (50), 25 states have call predecessors, (50), 44 states have call successors, (50) [2022-07-13 18:00:19,093 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 326 states to 326 states and 432 transitions. [2022-07-13 18:00:19,094 INFO L78 Accepts]: Start accepts. Automaton has 326 states and 432 transitions. Word has length 28 [2022-07-13 18:00:19,094 INFO L84 Accepts]: Finished accepts. word is rejected. [2022-07-13 18:00:19,094 INFO L495 AbstractCegarLoop]: Abstraction has 326 states and 432 transitions. [2022-07-13 18:00:19,094 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 5 states, 5 states have (on average 5.4) internal successors, (27), 4 states have internal predecessors, (27), 1 states have call successors, (1), 1 states have call predecessors, (1), 0 states have return successors, (0), 0 states have call predecessors, (0), 0 states have call successors, (0) [2022-07-13 18:00:19,094 INFO L276 IsEmpty]: Start isEmpty. Operand 326 states and 432 transitions. [2022-07-13 18:00:19,096 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 31 [2022-07-13 18:00:19,096 INFO L187 NwaCegarLoop]: Found error trace [2022-07-13 18:00:19,097 INFO L195 NwaCegarLoop]: trace histogram [1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-07-13 18:00:19,097 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable3 [2022-07-13 18:00:19,097 INFO L420 AbstractCegarLoop]: === Iteration 5 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2022-07-13 18:00:19,097 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2022-07-13 18:00:19,097 INFO L85 PathProgramCache]: Analyzing trace with hash 1450440452, now seen corresponding path program 1 times [2022-07-13 18:00:19,098 INFO L118 FreeRefinementEngine]: Executing refinement strategy CAMEL [2022-07-13 18:00:19,098 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [1047890317] [2022-07-13 18:00:19,098 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-07-13 18:00:19,098 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2022-07-13 18:00:19,113 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-07-13 18:00:19,160 INFO L134 CoverageAnalysis]: Checked inductivity of 0 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2022-07-13 18:00:19,160 INFO L136 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2022-07-13 18:00:19,161 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [1047890317] [2022-07-13 18:00:19,161 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [1047890317] provided 1 perfect and 0 imperfect interpolant sequences [2022-07-13 18:00:19,161 INFO L184 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2022-07-13 18:00:19,161 INFO L197 FreeRefinementEngine]: Number of different interpolants: perfect sequences [2] imperfect sequences [] total 2 [2022-07-13 18:00:19,161 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [1458536680] [2022-07-13 18:00:19,161 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2022-07-13 18:00:19,161 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 3 states [2022-07-13 18:00:19,161 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2022-07-13 18:00:19,162 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 3 interpolants. [2022-07-13 18:00:19,162 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=3, Invalid=3, Unknown=0, NotChecked=0, Total=6 [2022-07-13 18:00:19,162 INFO L87 Difference]: Start difference. First operand 326 states and 432 transitions. Second operand has 3 states, 3 states have (on average 9.666666666666666) internal successors, (29), 2 states have internal predecessors, (29), 1 states have call successors, (1), 1 states have call predecessors, (1), 0 states have return successors, (0), 0 states have call predecessors, (0), 0 states have call successors, (0) [2022-07-13 18:00:19,199 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-07-13 18:00:19,200 INFO L93 Difference]: Finished difference Result 754 states and 1025 transitions. [2022-07-13 18:00:19,200 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 3 states. [2022-07-13 18:00:19,200 INFO L78 Accepts]: Start accepts. Automaton has has 3 states, 3 states have (on average 9.666666666666666) internal successors, (29), 2 states have internal predecessors, (29), 1 states have call successors, (1), 1 states have call predecessors, (1), 0 states have return successors, (0), 0 states have call predecessors, (0), 0 states have call successors, (0) Word has length 30 [2022-07-13 18:00:19,201 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2022-07-13 18:00:19,203 INFO L225 Difference]: With dead ends: 754 [2022-07-13 18:00:19,203 INFO L226 Difference]: Without dead ends: 435 [2022-07-13 18:00:19,205 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 3 GetRequests, 2 SyntacticMatches, 0 SemanticMatches, 1 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 0 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=3, Invalid=3, Unknown=0, NotChecked=0, Total=6 [2022-07-13 18:00:19,206 INFO L413 NwaCegarLoop]: 97 mSDtfsCounter, 57 mSDsluCounter, 60 mSDsCounter, 0 mSdLazyCounter, 11 mSolverCounterSat, 8 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.0s Time, 0 mProtectedPredicate, 0 mProtectedAction, 57 SdHoareTripleChecker+Valid, 157 SdHoareTripleChecker+Invalid, 19 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 8 IncrementalHoareTripleChecker+Valid, 11 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.0s IncrementalHoareTripleChecker+Time [2022-07-13 18:00:19,206 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [57 Valid, 157 Invalid, 19 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [8 Valid, 11 Invalid, 0 Unknown, 0 Unchecked, 0.0s Time] [2022-07-13 18:00:19,207 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 435 states. [2022-07-13 18:00:19,230 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 435 to 424. [2022-07-13 18:00:19,231 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 424 states, 334 states have (on average 1.2934131736526946) internal successors, (432), 361 states have internal predecessors, (432), 47 states have call successors, (47), 45 states have call predecessors, (47), 42 states have return successors, (69), 41 states have call predecessors, (69), 47 states have call successors, (69) [2022-07-13 18:00:19,234 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 424 states to 424 states and 548 transitions. [2022-07-13 18:00:19,234 INFO L78 Accepts]: Start accepts. Automaton has 424 states and 548 transitions. Word has length 30 [2022-07-13 18:00:19,234 INFO L84 Accepts]: Finished accepts. word is rejected. [2022-07-13 18:00:19,234 INFO L495 AbstractCegarLoop]: Abstraction has 424 states and 548 transitions. [2022-07-13 18:00:19,234 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 3 states, 3 states have (on average 9.666666666666666) internal successors, (29), 2 states have internal predecessors, (29), 1 states have call successors, (1), 1 states have call predecessors, (1), 0 states have return successors, (0), 0 states have call predecessors, (0), 0 states have call successors, (0) [2022-07-13 18:00:19,235 INFO L276 IsEmpty]: Start isEmpty. Operand 424 states and 548 transitions. [2022-07-13 18:00:19,235 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 33 [2022-07-13 18:00:19,236 INFO L187 NwaCegarLoop]: Found error trace [2022-07-13 18:00:19,236 INFO L195 NwaCegarLoop]: trace histogram [1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-07-13 18:00:19,236 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable4 [2022-07-13 18:00:19,237 INFO L420 AbstractCegarLoop]: === Iteration 6 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2022-07-13 18:00:19,237 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2022-07-13 18:00:19,237 INFO L85 PathProgramCache]: Analyzing trace with hash 1164230885, now seen corresponding path program 1 times [2022-07-13 18:00:19,237 INFO L118 FreeRefinementEngine]: Executing refinement strategy CAMEL [2022-07-13 18:00:19,237 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [66928333] [2022-07-13 18:00:19,238 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-07-13 18:00:19,238 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2022-07-13 18:00:19,252 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-07-13 18:00:19,307 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 11 [2022-07-13 18:00:19,309 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-07-13 18:00:19,311 INFO L134 CoverageAnalysis]: Checked inductivity of 0 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2022-07-13 18:00:19,312 INFO L136 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2022-07-13 18:00:19,312 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [66928333] [2022-07-13 18:00:19,312 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [66928333] provided 1 perfect and 0 imperfect interpolant sequences [2022-07-13 18:00:19,312 INFO L184 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2022-07-13 18:00:19,312 INFO L197 FreeRefinementEngine]: Number of different interpolants: perfect sequences [6] imperfect sequences [] total 6 [2022-07-13 18:00:19,312 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [1519269990] [2022-07-13 18:00:19,313 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2022-07-13 18:00:19,313 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 6 states [2022-07-13 18:00:19,313 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2022-07-13 18:00:19,313 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 6 interpolants. [2022-07-13 18:00:19,314 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=9, Invalid=21, Unknown=0, NotChecked=0, Total=30 [2022-07-13 18:00:19,314 INFO L87 Difference]: Start difference. First operand 424 states and 548 transitions. Second operand has 6 states, 6 states have (on average 4.833333333333333) internal successors, (29), 5 states have internal predecessors, (29), 1 states have call successors, (2), 2 states have call predecessors, (2), 1 states have return successors, (1), 1 states have call predecessors, (1), 1 states have call successors, (1) [2022-07-13 18:00:19,521 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-07-13 18:00:19,521 INFO L93 Difference]: Finished difference Result 523 states and 679 transitions. [2022-07-13 18:00:19,521 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 11 states. [2022-07-13 18:00:19,521 INFO L78 Accepts]: Start accepts. Automaton has has 6 states, 6 states have (on average 4.833333333333333) internal successors, (29), 5 states have internal predecessors, (29), 1 states have call successors, (2), 2 states have call predecessors, (2), 1 states have return successors, (1), 1 states have call predecessors, (1), 1 states have call successors, (1) Word has length 32 [2022-07-13 18:00:19,522 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2022-07-13 18:00:19,525 INFO L225 Difference]: With dead ends: 523 [2022-07-13 18:00:19,525 INFO L226 Difference]: Without dead ends: 521 [2022-07-13 18:00:19,526 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 14 GetRequests, 4 SyntacticMatches, 0 SemanticMatches, 10 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 12 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=45, Invalid=87, Unknown=0, NotChecked=0, Total=132 [2022-07-13 18:00:19,528 INFO L413 NwaCegarLoop]: 109 mSDtfsCounter, 138 mSDsluCounter, 274 mSDsCounter, 0 mSdLazyCounter, 176 mSolverCounterSat, 34 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.1s Time, 0 mProtectedPredicate, 0 mProtectedAction, 142 SdHoareTripleChecker+Valid, 383 SdHoareTripleChecker+Invalid, 210 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 34 IncrementalHoareTripleChecker+Valid, 176 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.1s IncrementalHoareTripleChecker+Time [2022-07-13 18:00:19,529 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [142 Valid, 383 Invalid, 210 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [34 Valid, 176 Invalid, 0 Unknown, 0 Unchecked, 0.1s Time] [2022-07-13 18:00:19,530 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 521 states. [2022-07-13 18:00:19,574 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 521 to 492. [2022-07-13 18:00:19,575 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 492 states, 387 states have (on average 1.276485788113695) internal successors, (494), 425 states have internal predecessors, (494), 53 states have call successors, (53), 45 states have call predecessors, (53), 51 states have return successors, (88), 45 states have call predecessors, (88), 53 states have call successors, (88) [2022-07-13 18:00:19,579 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 492 states to 492 states and 635 transitions. [2022-07-13 18:00:19,579 INFO L78 Accepts]: Start accepts. Automaton has 492 states and 635 transitions. Word has length 32 [2022-07-13 18:00:19,580 INFO L84 Accepts]: Finished accepts. word is rejected. [2022-07-13 18:00:19,580 INFO L495 AbstractCegarLoop]: Abstraction has 492 states and 635 transitions. [2022-07-13 18:00:19,580 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 6 states, 6 states have (on average 4.833333333333333) internal successors, (29), 5 states have internal predecessors, (29), 1 states have call successors, (2), 2 states have call predecessors, (2), 1 states have return successors, (1), 1 states have call predecessors, (1), 1 states have call successors, (1) [2022-07-13 18:00:19,581 INFO L276 IsEmpty]: Start isEmpty. Operand 492 states and 635 transitions. [2022-07-13 18:00:19,583 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 48 [2022-07-13 18:00:19,583 INFO L187 NwaCegarLoop]: Found error trace [2022-07-13 18:00:19,584 INFO L195 NwaCegarLoop]: trace histogram [1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-07-13 18:00:19,584 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable5 [2022-07-13 18:00:19,584 INFO L420 AbstractCegarLoop]: === Iteration 7 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2022-07-13 18:00:19,584 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2022-07-13 18:00:19,584 INFO L85 PathProgramCache]: Analyzing trace with hash 108395810, now seen corresponding path program 1 times [2022-07-13 18:00:19,584 INFO L118 FreeRefinementEngine]: Executing refinement strategy CAMEL [2022-07-13 18:00:19,585 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [1125709678] [2022-07-13 18:00:19,585 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-07-13 18:00:19,585 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2022-07-13 18:00:19,625 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-07-13 18:00:19,665 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 11 [2022-07-13 18:00:19,666 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-07-13 18:00:19,672 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 24 [2022-07-13 18:00:19,676 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-07-13 18:00:19,696 INFO L134 CoverageAnalysis]: Checked inductivity of 0 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2022-07-13 18:00:19,696 INFO L136 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2022-07-13 18:00:19,696 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [1125709678] [2022-07-13 18:00:19,697 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [1125709678] provided 1 perfect and 0 imperfect interpolant sequences [2022-07-13 18:00:19,697 INFO L184 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2022-07-13 18:00:19,697 INFO L197 FreeRefinementEngine]: Number of different interpolants: perfect sequences [7] imperfect sequences [] total 7 [2022-07-13 18:00:19,697 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [1206111634] [2022-07-13 18:00:19,697 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2022-07-13 18:00:19,698 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 7 states [2022-07-13 18:00:19,698 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2022-07-13 18:00:19,698 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 7 interpolants. [2022-07-13 18:00:19,698 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=11, Invalid=31, Unknown=0, NotChecked=0, Total=42 [2022-07-13 18:00:19,699 INFO L87 Difference]: Start difference. First operand 492 states and 635 transitions. Second operand has 7 states, 7 states have (on average 6.0) internal successors, (42), 5 states have internal predecessors, (42), 1 states have call successors, (3), 3 states have call predecessors, (3), 2 states have return successors, (2), 2 states have call predecessors, (2), 1 states have call successors, (2) [2022-07-13 18:00:19,915 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-07-13 18:00:19,916 INFO L93 Difference]: Finished difference Result 1091 states and 1460 transitions. [2022-07-13 18:00:19,916 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 9 states. [2022-07-13 18:00:19,916 INFO L78 Accepts]: Start accepts. Automaton has has 7 states, 7 states have (on average 6.0) internal successors, (42), 5 states have internal predecessors, (42), 1 states have call successors, (3), 3 states have call predecessors, (3), 2 states have return successors, (2), 2 states have call predecessors, (2), 1 states have call successors, (2) Word has length 47 [2022-07-13 18:00:19,916 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2022-07-13 18:00:19,921 INFO L225 Difference]: With dead ends: 1091 [2022-07-13 18:00:19,921 INFO L226 Difference]: Without dead ends: 606 [2022-07-13 18:00:19,923 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 16 GetRequests, 6 SyntacticMatches, 0 SemanticMatches, 10 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 3 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=46, Invalid=86, Unknown=0, NotChecked=0, Total=132 [2022-07-13 18:00:19,924 INFO L413 NwaCegarLoop]: 94 mSDtfsCounter, 141 mSDsluCounter, 271 mSDsCounter, 0 mSdLazyCounter, 230 mSolverCounterSat, 45 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.1s Time, 0 mProtectedPredicate, 0 mProtectedAction, 141 SdHoareTripleChecker+Valid, 365 SdHoareTripleChecker+Invalid, 275 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 45 IncrementalHoareTripleChecker+Valid, 230 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.1s IncrementalHoareTripleChecker+Time [2022-07-13 18:00:19,924 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [141 Valid, 365 Invalid, 275 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [45 Valid, 230 Invalid, 0 Unknown, 0 Unchecked, 0.1s Time] [2022-07-13 18:00:19,926 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 606 states. [2022-07-13 18:00:19,971 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 606 to 544. [2022-07-13 18:00:19,973 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 544 states, 433 states have (on average 1.2609699769053118) internal successors, (546), 471 states have internal predecessors, (546), 53 states have call successors, (53), 45 states have call predecessors, (53), 57 states have return successors, (96), 49 states have call predecessors, (96), 53 states have call successors, (96) [2022-07-13 18:00:19,977 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 544 states to 544 states and 695 transitions. [2022-07-13 18:00:19,978 INFO L78 Accepts]: Start accepts. Automaton has 544 states and 695 transitions. Word has length 47 [2022-07-13 18:00:19,979 INFO L84 Accepts]: Finished accepts. word is rejected. [2022-07-13 18:00:19,979 INFO L495 AbstractCegarLoop]: Abstraction has 544 states and 695 transitions. [2022-07-13 18:00:19,979 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 7 states, 7 states have (on average 6.0) internal successors, (42), 5 states have internal predecessors, (42), 1 states have call successors, (3), 3 states have call predecessors, (3), 2 states have return successors, (2), 2 states have call predecessors, (2), 1 states have call successors, (2) [2022-07-13 18:00:19,979 INFO L276 IsEmpty]: Start isEmpty. Operand 544 states and 695 transitions. [2022-07-13 18:00:19,981 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 48 [2022-07-13 18:00:19,981 INFO L187 NwaCegarLoop]: Found error trace [2022-07-13 18:00:19,982 INFO L195 NwaCegarLoop]: trace histogram [1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-07-13 18:00:19,982 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable6 [2022-07-13 18:00:19,982 INFO L420 AbstractCegarLoop]: === Iteration 8 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2022-07-13 18:00:19,982 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2022-07-13 18:00:19,982 INFO L85 PathProgramCache]: Analyzing trace with hash -1885748896, now seen corresponding path program 1 times [2022-07-13 18:00:19,983 INFO L118 FreeRefinementEngine]: Executing refinement strategy CAMEL [2022-07-13 18:00:19,983 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [1112536440] [2022-07-13 18:00:19,983 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-07-13 18:00:19,983 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2022-07-13 18:00:20,019 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-07-13 18:00:20,060 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 11 [2022-07-13 18:00:20,062 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-07-13 18:00:20,069 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 24 [2022-07-13 18:00:20,074 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-07-13 18:00:20,114 INFO L134 CoverageAnalysis]: Checked inductivity of 0 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2022-07-13 18:00:20,114 INFO L136 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2022-07-13 18:00:20,115 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [1112536440] [2022-07-13 18:00:20,116 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [1112536440] provided 1 perfect and 0 imperfect interpolant sequences [2022-07-13 18:00:20,117 INFO L184 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2022-07-13 18:00:20,117 INFO L197 FreeRefinementEngine]: Number of different interpolants: perfect sequences [8] imperfect sequences [] total 8 [2022-07-13 18:00:20,118 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [2115401837] [2022-07-13 18:00:20,118 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2022-07-13 18:00:20,119 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 8 states [2022-07-13 18:00:20,119 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2022-07-13 18:00:20,119 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 8 interpolants. [2022-07-13 18:00:20,119 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=13, Invalid=43, Unknown=0, NotChecked=0, Total=56 [2022-07-13 18:00:20,121 INFO L87 Difference]: Start difference. First operand 544 states and 695 transitions. Second operand has 8 states, 8 states have (on average 5.25) internal successors, (42), 6 states have internal predecessors, (42), 1 states have call successors, (3), 3 states have call predecessors, (3), 2 states have return successors, (2), 2 states have call predecessors, (2), 1 states have call successors, (2) [2022-07-13 18:00:20,522 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-07-13 18:00:20,522 INFO L93 Difference]: Finished difference Result 1067 states and 1402 transitions. [2022-07-13 18:00:20,523 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 10 states. [2022-07-13 18:00:20,523 INFO L78 Accepts]: Start accepts. Automaton has has 8 states, 8 states have (on average 5.25) internal successors, (42), 6 states have internal predecessors, (42), 1 states have call successors, (3), 3 states have call predecessors, (3), 2 states have return successors, (2), 2 states have call predecessors, (2), 1 states have call successors, (2) Word has length 47 [2022-07-13 18:00:20,523 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2022-07-13 18:00:20,526 INFO L225 Difference]: With dead ends: 1067 [2022-07-13 18:00:20,526 INFO L226 Difference]: Without dead ends: 530 [2022-07-13 18:00:20,528 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 19 GetRequests, 8 SyntacticMatches, 0 SemanticMatches, 11 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 6 ImplicationChecksByTransitivity, 0.1s TimeCoverageRelationStatistics Valid=42, Invalid=114, Unknown=0, NotChecked=0, Total=156 [2022-07-13 18:00:20,528 INFO L413 NwaCegarLoop]: 80 mSDtfsCounter, 209 mSDsluCounter, 235 mSDsCounter, 0 mSdLazyCounter, 285 mSolverCounterSat, 66 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.3s Time, 0 mProtectedPredicate, 0 mProtectedAction, 209 SdHoareTripleChecker+Valid, 315 SdHoareTripleChecker+Invalid, 351 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 66 IncrementalHoareTripleChecker+Valid, 285 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.3s IncrementalHoareTripleChecker+Time [2022-07-13 18:00:20,529 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [209 Valid, 315 Invalid, 351 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [66 Valid, 285 Invalid, 0 Unknown, 0 Unchecked, 0.3s Time] [2022-07-13 18:00:20,529 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 530 states. [2022-07-13 18:00:20,548 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 530 to 428. [2022-07-13 18:00:20,564 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 428 states, 339 states have (on average 1.2595870206489677) internal successors, (427), 368 states have internal predecessors, (427), 44 states have call successors, (44), 38 states have call predecessors, (44), 44 states have return successors, (70), 38 states have call predecessors, (70), 44 states have call successors, (70) [2022-07-13 18:00:20,566 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 428 states to 428 states and 541 transitions. [2022-07-13 18:00:20,566 INFO L78 Accepts]: Start accepts. Automaton has 428 states and 541 transitions. Word has length 47 [2022-07-13 18:00:20,567 INFO L84 Accepts]: Finished accepts. word is rejected. [2022-07-13 18:00:20,567 INFO L495 AbstractCegarLoop]: Abstraction has 428 states and 541 transitions. [2022-07-13 18:00:20,567 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 8 states, 8 states have (on average 5.25) internal successors, (42), 6 states have internal predecessors, (42), 1 states have call successors, (3), 3 states have call predecessors, (3), 2 states have return successors, (2), 2 states have call predecessors, (2), 1 states have call successors, (2) [2022-07-13 18:00:20,567 INFO L276 IsEmpty]: Start isEmpty. Operand 428 states and 541 transitions. [2022-07-13 18:00:20,568 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 48 [2022-07-13 18:00:20,568 INFO L187 NwaCegarLoop]: Found error trace [2022-07-13 18:00:20,568 INFO L195 NwaCegarLoop]: trace histogram [1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-07-13 18:00:20,569 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable7 [2022-07-13 18:00:20,569 INFO L420 AbstractCegarLoop]: === Iteration 9 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2022-07-13 18:00:20,569 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2022-07-13 18:00:20,569 INFO L85 PathProgramCache]: Analyzing trace with hash 1591569950, now seen corresponding path program 1 times [2022-07-13 18:00:20,570 INFO L118 FreeRefinementEngine]: Executing refinement strategy CAMEL [2022-07-13 18:00:20,570 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [2076330732] [2022-07-13 18:00:20,570 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-07-13 18:00:20,570 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2022-07-13 18:00:20,588 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-07-13 18:00:20,667 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 11 [2022-07-13 18:00:20,668 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-07-13 18:00:20,676 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 24 [2022-07-13 18:00:20,681 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-07-13 18:00:20,709 INFO L134 CoverageAnalysis]: Checked inductivity of 0 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2022-07-13 18:00:20,709 INFO L136 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2022-07-13 18:00:20,709 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [2076330732] [2022-07-13 18:00:20,710 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [2076330732] provided 1 perfect and 0 imperfect interpolant sequences [2022-07-13 18:00:20,710 INFO L184 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2022-07-13 18:00:20,710 INFO L197 FreeRefinementEngine]: Number of different interpolants: perfect sequences [7] imperfect sequences [] total 7 [2022-07-13 18:00:20,710 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [1121534830] [2022-07-13 18:00:20,710 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2022-07-13 18:00:20,711 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 7 states [2022-07-13 18:00:20,712 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2022-07-13 18:00:20,712 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 7 interpolants. [2022-07-13 18:00:20,712 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=11, Invalid=31, Unknown=0, NotChecked=0, Total=42 [2022-07-13 18:00:20,712 INFO L87 Difference]: Start difference. First operand 428 states and 541 transitions. Second operand has 7 states, 7 states have (on average 6.0) internal successors, (42), 5 states have internal predecessors, (42), 1 states have call successors, (3), 3 states have call predecessors, (3), 2 states have return successors, (2), 2 states have call predecessors, (2), 1 states have call successors, (2) [2022-07-13 18:00:21,379 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-07-13 18:00:21,379 INFO L93 Difference]: Finished difference Result 978 states and 1311 transitions. [2022-07-13 18:00:21,380 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 17 states. [2022-07-13 18:00:21,380 INFO L78 Accepts]: Start accepts. Automaton has has 7 states, 7 states have (on average 6.0) internal successors, (42), 5 states have internal predecessors, (42), 1 states have call successors, (3), 3 states have call predecessors, (3), 2 states have return successors, (2), 2 states have call predecessors, (2), 1 states have call successors, (2) Word has length 47 [2022-07-13 18:00:21,381 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2022-07-13 18:00:21,385 INFO L225 Difference]: With dead ends: 978 [2022-07-13 18:00:21,385 INFO L226 Difference]: Without dead ends: 665 [2022-07-13 18:00:21,387 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 24 GetRequests, 6 SyntacticMatches, 1 SemanticMatches, 17 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 60 ImplicationChecksByTransitivity, 0.1s TimeCoverageRelationStatistics Valid=106, Invalid=236, Unknown=0, NotChecked=0, Total=342 [2022-07-13 18:00:21,389 INFO L413 NwaCegarLoop]: 133 mSDtfsCounter, 221 mSDsluCounter, 351 mSDsCounter, 0 mSdLazyCounter, 306 mSolverCounterSat, 60 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.4s Time, 0 mProtectedPredicate, 0 mProtectedAction, 223 SdHoareTripleChecker+Valid, 484 SdHoareTripleChecker+Invalid, 366 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 60 IncrementalHoareTripleChecker+Valid, 306 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.5s IncrementalHoareTripleChecker+Time [2022-07-13 18:00:21,389 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [223 Valid, 484 Invalid, 366 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [60 Valid, 306 Invalid, 0 Unknown, 0 Unchecked, 0.5s Time] [2022-07-13 18:00:21,390 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 665 states. [2022-07-13 18:00:21,422 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 665 to 640. [2022-07-13 18:00:21,424 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 640 states, 506 states have (on average 1.2351778656126482) internal successors, (625), 543 states have internal predecessors, (625), 66 states have call successors, (66), 58 states have call predecessors, (66), 67 states have return successors, (131), 66 states have call predecessors, (131), 66 states have call successors, (131) [2022-07-13 18:00:21,427 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 640 states to 640 states and 822 transitions. [2022-07-13 18:00:21,428 INFO L78 Accepts]: Start accepts. Automaton has 640 states and 822 transitions. Word has length 47 [2022-07-13 18:00:21,428 INFO L84 Accepts]: Finished accepts. word is rejected. [2022-07-13 18:00:21,428 INFO L495 AbstractCegarLoop]: Abstraction has 640 states and 822 transitions. [2022-07-13 18:00:21,429 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 7 states, 7 states have (on average 6.0) internal successors, (42), 5 states have internal predecessors, (42), 1 states have call successors, (3), 3 states have call predecessors, (3), 2 states have return successors, (2), 2 states have call predecessors, (2), 1 states have call successors, (2) [2022-07-13 18:00:21,429 INFO L276 IsEmpty]: Start isEmpty. Operand 640 states and 822 transitions. [2022-07-13 18:00:21,431 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 83 [2022-07-13 18:00:21,431 INFO L187 NwaCegarLoop]: Found error trace [2022-07-13 18:00:21,431 INFO L195 NwaCegarLoop]: trace histogram [2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-07-13 18:00:21,432 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable8 [2022-07-13 18:00:21,432 INFO L420 AbstractCegarLoop]: === Iteration 10 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2022-07-13 18:00:21,432 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2022-07-13 18:00:21,432 INFO L85 PathProgramCache]: Analyzing trace with hash -351052253, now seen corresponding path program 1 times [2022-07-13 18:00:21,433 INFO L118 FreeRefinementEngine]: Executing refinement strategy CAMEL [2022-07-13 18:00:21,433 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [773393198] [2022-07-13 18:00:21,433 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-07-13 18:00:21,433 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2022-07-13 18:00:21,492 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-07-13 18:00:21,569 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 11 [2022-07-13 18:00:21,571 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-07-13 18:00:21,590 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 20 [2022-07-13 18:00:21,594 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-07-13 18:00:21,624 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 3 [2022-07-13 18:00:21,628 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-07-13 18:00:21,641 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 67 [2022-07-13 18:00:21,643 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-07-13 18:00:21,644 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 2 [2022-07-13 18:00:21,645 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-07-13 18:00:21,648 INFO L134 CoverageAnalysis]: Checked inductivity of 21 backedges. 12 proven. 7 refuted. 0 times theorem prover too weak. 2 trivial. 0 not checked. [2022-07-13 18:00:21,648 INFO L136 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2022-07-13 18:00:21,649 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [773393198] [2022-07-13 18:00:21,649 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [773393198] provided 0 perfect and 1 imperfect interpolant sequences [2022-07-13 18:00:21,649 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleZ3 [1209328697] [2022-07-13 18:00:21,649 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-07-13 18:00:21,649 INFO L173 SolverBuilder]: Constructing external solver with command: z3 -smt2 -in SMTLIB2_COMPLIANT=true [2022-07-13 18:00:21,650 INFO L189 MonitoredProcess]: No working directory specified, using /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 [2022-07-13 18:00:21,651 INFO L229 MonitoredProcess]: Starting monitored process 2 with /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 -smt2 -in SMTLIB2_COMPLIANT=true (exit command is (exit), workingDir is null) [2022-07-13 18:00:21,655 INFO L327 MonitoredProcess]: [MP /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 -smt2 -in SMTLIB2_COMPLIANT=true (2)] Waiting until timeout for monitored process [2022-07-13 18:00:21,822 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-07-13 18:00:21,838 INFO L263 TraceCheckSpWp]: Trace formula consists of 450 conjuncts, 8 conjunts are in the unsatisfiable core [2022-07-13 18:00:21,844 INFO L286 TraceCheckSpWp]: Computing forward predicates... [2022-07-13 18:00:22,007 INFO L134 CoverageAnalysis]: Checked inductivity of 21 backedges. 15 proven. 6 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2022-07-13 18:00:22,007 INFO L328 TraceCheckSpWp]: Computing backward predicates... [2022-07-13 18:00:22,248 INFO L134 CoverageAnalysis]: Checked inductivity of 21 backedges. 13 proven. 6 refuted. 0 times theorem prover too weak. 2 trivial. 0 not checked. [2022-07-13 18:00:22,248 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleZ3 [1209328697] provided 0 perfect and 2 imperfect interpolant sequences [2022-07-13 18:00:22,249 INFO L184 FreeRefinementEngine]: Found 0 perfect and 3 imperfect interpolant sequences. [2022-07-13 18:00:22,249 INFO L197 FreeRefinementEngine]: Number of different interpolants: perfect sequences [] imperfect sequences [9, 6, 6] total 9 [2022-07-13 18:00:22,249 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [918105015] [2022-07-13 18:00:22,249 INFO L85 oduleStraightlineAll]: Using 3 imperfect interpolants to construct interpolant automaton [2022-07-13 18:00:22,249 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 9 states [2022-07-13 18:00:22,250 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2022-07-13 18:00:22,250 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 9 interpolants. [2022-07-13 18:00:22,250 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=18, Invalid=54, Unknown=0, NotChecked=0, Total=72 [2022-07-13 18:00:22,250 INFO L87 Difference]: Start difference. First operand 640 states and 822 transitions. Second operand has 9 states, 9 states have (on average 8.555555555555555) internal successors, (77), 6 states have internal predecessors, (77), 3 states have call successors, (12), 6 states have call predecessors, (12), 3 states have return successors, (7), 3 states have call predecessors, (7), 2 states have call successors, (7) [2022-07-13 18:00:22,887 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-07-13 18:00:22,888 INFO L93 Difference]: Finished difference Result 1525 states and 2064 transitions. [2022-07-13 18:00:22,888 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 27 states. [2022-07-13 18:00:22,889 INFO L78 Accepts]: Start accepts. Automaton has has 9 states, 9 states have (on average 8.555555555555555) internal successors, (77), 6 states have internal predecessors, (77), 3 states have call successors, (12), 6 states have call predecessors, (12), 3 states have return successors, (7), 3 states have call predecessors, (7), 2 states have call successors, (7) Word has length 82 [2022-07-13 18:00:22,889 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2022-07-13 18:00:22,894 INFO L225 Difference]: With dead ends: 1525 [2022-07-13 18:00:22,894 INFO L226 Difference]: Without dead ends: 1000 [2022-07-13 18:00:22,897 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 206 GetRequests, 175 SyntacticMatches, 4 SemanticMatches, 27 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 200 ImplicationChecksByTransitivity, 0.2s TimeCoverageRelationStatistics Valid=227, Invalid=585, Unknown=0, NotChecked=0, Total=812 [2022-07-13 18:00:22,897 INFO L413 NwaCegarLoop]: 139 mSDtfsCounter, 346 mSDsluCounter, 443 mSDsCounter, 0 mSdLazyCounter, 467 mSolverCounterSat, 114 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.3s Time, 0 mProtectedPredicate, 0 mProtectedAction, 352 SdHoareTripleChecker+Valid, 582 SdHoareTripleChecker+Invalid, 581 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 114 IncrementalHoareTripleChecker+Valid, 467 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.4s IncrementalHoareTripleChecker+Time [2022-07-13 18:00:22,898 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [352 Valid, 582 Invalid, 581 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [114 Valid, 467 Invalid, 0 Unknown, 0 Unchecked, 0.4s Time] [2022-07-13 18:00:22,899 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 1000 states. [2022-07-13 18:00:22,940 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 1000 to 869. [2022-07-13 18:00:22,941 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 869 states, 679 states have (on average 1.2415316642120766) internal successors, (843), 732 states have internal predecessors, (843), 95 states have call successors, (95), 83 states have call predecessors, (95), 94 states have return successors, (198), 87 states have call predecessors, (198), 95 states have call successors, (198) [2022-07-13 18:00:22,945 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 869 states to 869 states and 1136 transitions. [2022-07-13 18:00:22,946 INFO L78 Accepts]: Start accepts. Automaton has 869 states and 1136 transitions. Word has length 82 [2022-07-13 18:00:22,946 INFO L84 Accepts]: Finished accepts. word is rejected. [2022-07-13 18:00:22,946 INFO L495 AbstractCegarLoop]: Abstraction has 869 states and 1136 transitions. [2022-07-13 18:00:22,946 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 9 states, 9 states have (on average 8.555555555555555) internal successors, (77), 6 states have internal predecessors, (77), 3 states have call successors, (12), 6 states have call predecessors, (12), 3 states have return successors, (7), 3 states have call predecessors, (7), 2 states have call successors, (7) [2022-07-13 18:00:22,947 INFO L276 IsEmpty]: Start isEmpty. Operand 869 states and 1136 transitions. [2022-07-13 18:00:22,949 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 118 [2022-07-13 18:00:22,949 INFO L187 NwaCegarLoop]: Found error trace [2022-07-13 18:00:22,950 INFO L195 NwaCegarLoop]: trace histogram [3, 3, 3, 3, 3, 3, 3, 3, 3, 3, 3, 3, 3, 3, 3, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-07-13 18:00:22,979 INFO L540 MonitoredProcess]: [MP /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 -smt2 -in SMTLIB2_COMPLIANT=true (2)] Forceful destruction successful, exit code 0 [2022-07-13 18:00:23,171 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: 2 /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 -smt2 -in SMTLIB2_COMPLIANT=true,SelfDestructingSolverStorable9 [2022-07-13 18:00:23,172 INFO L420 AbstractCegarLoop]: === Iteration 11 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2022-07-13 18:00:23,172 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2022-07-13 18:00:23,172 INFO L85 PathProgramCache]: Analyzing trace with hash 349407230, now seen corresponding path program 2 times [2022-07-13 18:00:23,172 INFO L118 FreeRefinementEngine]: Executing refinement strategy CAMEL [2022-07-13 18:00:23,172 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [90526620] [2022-07-13 18:00:23,172 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-07-13 18:00:23,173 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2022-07-13 18:00:23,197 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-07-13 18:00:23,255 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 11 [2022-07-13 18:00:23,256 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-07-13 18:00:23,263 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 20 [2022-07-13 18:00:23,267 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-07-13 18:00:23,292 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 3 [2022-07-13 18:00:23,294 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-07-13 18:00:23,301 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 56 [2022-07-13 18:00:23,306 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-07-13 18:00:23,376 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 10 [2022-07-13 18:00:23,377 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-07-13 18:00:23,379 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 2 [2022-07-13 18:00:23,380 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-07-13 18:00:23,381 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 102 [2022-07-13 18:00:23,381 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-07-13 18:00:23,382 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 2 [2022-07-13 18:00:23,382 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-07-13 18:00:23,383 INFO L134 CoverageAnalysis]: Checked inductivity of 77 backedges. 54 proven. 11 refuted. 0 times theorem prover too weak. 12 trivial. 0 not checked. [2022-07-13 18:00:23,383 INFO L136 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2022-07-13 18:00:23,383 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [90526620] [2022-07-13 18:00:23,383 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [90526620] provided 0 perfect and 1 imperfect interpolant sequences [2022-07-13 18:00:23,383 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleZ3 [1120600125] [2022-07-13 18:00:23,383 INFO L93 rtionOrderModulation]: Changing assertion order to OUTSIDE_LOOP_FIRST1 [2022-07-13 18:00:23,383 INFO L173 SolverBuilder]: Constructing external solver with command: z3 -smt2 -in SMTLIB2_COMPLIANT=true [2022-07-13 18:00:23,383 INFO L189 MonitoredProcess]: No working directory specified, using /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 [2022-07-13 18:00:23,387 INFO L229 MonitoredProcess]: Starting monitored process 3 with /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 -smt2 -in SMTLIB2_COMPLIANT=true (exit command is (exit), workingDir is null) [2022-07-13 18:00:23,427 INFO L327 MonitoredProcess]: [MP /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 -smt2 -in SMTLIB2_COMPLIANT=true (3)] Waiting until timeout for monitored process [2022-07-13 18:00:23,509 INFO L228 tOrderPrioritization]: Assert order OUTSIDE_LOOP_FIRST1 issued 2 check-sat command(s) [2022-07-13 18:00:23,509 INFO L229 tOrderPrioritization]: Conjunction of SSA is unsat [2022-07-13 18:00:23,511 INFO L263 TraceCheckSpWp]: Trace formula consists of 540 conjuncts, 10 conjunts are in the unsatisfiable core [2022-07-13 18:00:23,519 INFO L286 TraceCheckSpWp]: Computing forward predicates... [2022-07-13 18:00:23,861 INFO L134 CoverageAnalysis]: Checked inductivity of 77 backedges. 64 proven. 0 refuted. 0 times theorem prover too weak. 13 trivial. 0 not checked. [2022-07-13 18:00:23,861 INFO L324 TraceCheckSpWp]: Omiting computation of backward sequence because forward sequence was already perfect [2022-07-13 18:00:23,861 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleZ3 [1120600125] provided 1 perfect and 0 imperfect interpolant sequences [2022-07-13 18:00:23,861 INFO L184 FreeRefinementEngine]: Found 1 perfect and 1 imperfect interpolant sequences. [2022-07-13 18:00:23,861 INFO L197 FreeRefinementEngine]: Number of different interpolants: perfect sequences [6] imperfect sequences [10] total 14 [2022-07-13 18:00:23,861 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [1811908539] [2022-07-13 18:00:23,861 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2022-07-13 18:00:23,862 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 6 states [2022-07-13 18:00:23,862 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2022-07-13 18:00:23,862 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 6 interpolants. [2022-07-13 18:00:23,862 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=32, Invalid=150, Unknown=0, NotChecked=0, Total=182 [2022-07-13 18:00:23,863 INFO L87 Difference]: Start difference. First operand 869 states and 1136 transitions. Second operand has 6 states, 6 states have (on average 15.166666666666666) internal successors, (91), 6 states have internal predecessors, (91), 3 states have call successors, (8), 4 states have call predecessors, (8), 3 states have return successors, (8), 3 states have call predecessors, (8), 3 states have call successors, (8) [2022-07-13 18:00:24,297 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-07-13 18:00:24,297 INFO L93 Difference]: Finished difference Result 2382 states and 3234 transitions. [2022-07-13 18:00:24,297 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 10 states. [2022-07-13 18:00:24,297 INFO L78 Accepts]: Start accepts. Automaton has has 6 states, 6 states have (on average 15.166666666666666) internal successors, (91), 6 states have internal predecessors, (91), 3 states have call successors, (8), 4 states have call predecessors, (8), 3 states have return successors, (8), 3 states have call predecessors, (8), 3 states have call successors, (8) Word has length 117 [2022-07-13 18:00:24,308 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2022-07-13 18:00:24,327 INFO L225 Difference]: With dead ends: 2382 [2022-07-13 18:00:24,331 INFO L226 Difference]: Without dead ends: 1626 [2022-07-13 18:00:24,340 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 149 GetRequests, 130 SyntacticMatches, 2 SemanticMatches, 17 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 45 ImplicationChecksByTransitivity, 0.3s TimeCoverageRelationStatistics Valid=63, Invalid=279, Unknown=0, NotChecked=0, Total=342 [2022-07-13 18:00:24,341 INFO L413 NwaCegarLoop]: 161 mSDtfsCounter, 262 mSDsluCounter, 390 mSDsCounter, 0 mSdLazyCounter, 132 mSolverCounterSat, 40 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.2s Time, 0 mProtectedPredicate, 0 mProtectedAction, 262 SdHoareTripleChecker+Valid, 551 SdHoareTripleChecker+Invalid, 172 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 40 IncrementalHoareTripleChecker+Valid, 132 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.2s IncrementalHoareTripleChecker+Time [2022-07-13 18:00:24,341 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [262 Valid, 551 Invalid, 172 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [40 Valid, 132 Invalid, 0 Unknown, 0 Unchecked, 0.2s Time] [2022-07-13 18:00:24,347 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 1626 states. [2022-07-13 18:00:24,436 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 1626 to 1505. [2022-07-13 18:00:24,438 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 1505 states, 1178 states have (on average 1.2410865874363328) internal successors, (1462), 1258 states have internal predecessors, (1462), 166 states have call successors, (166), 148 states have call predecessors, (166), 160 states have return successors, (304), 150 states have call predecessors, (304), 166 states have call successors, (304) [2022-07-13 18:00:24,445 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 1505 states to 1505 states and 1932 transitions. [2022-07-13 18:00:24,446 INFO L78 Accepts]: Start accepts. Automaton has 1505 states and 1932 transitions. Word has length 117 [2022-07-13 18:00:24,446 INFO L84 Accepts]: Finished accepts. word is rejected. [2022-07-13 18:00:24,446 INFO L495 AbstractCegarLoop]: Abstraction has 1505 states and 1932 transitions. [2022-07-13 18:00:24,447 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 6 states, 6 states have (on average 15.166666666666666) internal successors, (91), 6 states have internal predecessors, (91), 3 states have call successors, (8), 4 states have call predecessors, (8), 3 states have return successors, (8), 3 states have call predecessors, (8), 3 states have call successors, (8) [2022-07-13 18:00:24,447 INFO L276 IsEmpty]: Start isEmpty. Operand 1505 states and 1932 transitions. [2022-07-13 18:00:24,454 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 118 [2022-07-13 18:00:24,455 INFO L187 NwaCegarLoop]: Found error trace [2022-07-13 18:00:24,455 INFO L195 NwaCegarLoop]: trace histogram [3, 3, 3, 3, 3, 3, 3, 3, 3, 3, 3, 3, 3, 3, 3, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-07-13 18:00:24,483 INFO L540 MonitoredProcess]: [MP /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 -smt2 -in SMTLIB2_COMPLIANT=true (3)] Forceful destruction successful, exit code 0 [2022-07-13 18:00:24,675 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: 3 /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 -smt2 -in SMTLIB2_COMPLIANT=true,SelfDestructingSolverStorable10 [2022-07-13 18:00:24,675 INFO L420 AbstractCegarLoop]: === Iteration 12 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2022-07-13 18:00:24,676 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2022-07-13 18:00:24,676 INFO L85 PathProgramCache]: Analyzing trace with hash 1225426236, now seen corresponding path program 1 times [2022-07-13 18:00:24,676 INFO L118 FreeRefinementEngine]: Executing refinement strategy CAMEL [2022-07-13 18:00:24,676 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [303546863] [2022-07-13 18:00:24,676 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-07-13 18:00:24,676 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2022-07-13 18:00:24,712 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-07-13 18:00:24,761 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 11 [2022-07-13 18:00:24,763 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-07-13 18:00:24,768 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 20 [2022-07-13 18:00:24,770 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-07-13 18:00:24,776 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 3 [2022-07-13 18:00:24,778 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-07-13 18:00:24,780 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 56 [2022-07-13 18:00:24,786 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-07-13 18:00:24,826 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 10 [2022-07-13 18:00:24,827 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-07-13 18:00:24,830 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 2 [2022-07-13 18:00:24,830 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-07-13 18:00:24,831 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 102 [2022-07-13 18:00:24,832 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-07-13 18:00:24,835 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 2 [2022-07-13 18:00:24,836 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-07-13 18:00:24,837 INFO L134 CoverageAnalysis]: Checked inductivity of 77 backedges. 44 proven. 0 refuted. 0 times theorem prover too weak. 33 trivial. 0 not checked. [2022-07-13 18:00:24,837 INFO L136 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2022-07-13 18:00:24,837 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [303546863] [2022-07-13 18:00:24,837 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [303546863] provided 1 perfect and 0 imperfect interpolant sequences [2022-07-13 18:00:24,837 INFO L184 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2022-07-13 18:00:24,838 INFO L197 FreeRefinementEngine]: Number of different interpolants: perfect sequences [8] imperfect sequences [] total 8 [2022-07-13 18:00:24,838 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [1102358340] [2022-07-13 18:00:24,838 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2022-07-13 18:00:24,839 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 8 states [2022-07-13 18:00:24,839 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2022-07-13 18:00:24,839 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 8 interpolants. [2022-07-13 18:00:24,839 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=15, Invalid=41, Unknown=0, NotChecked=0, Total=56 [2022-07-13 18:00:24,861 INFO L87 Difference]: Start difference. First operand 1505 states and 1932 transitions. Second operand has 8 states, 8 states have (on average 10.25) internal successors, (82), 5 states have internal predecessors, (82), 2 states have call successors, (6), 5 states have call predecessors, (6), 2 states have return successors, (6), 2 states have call predecessors, (6), 2 states have call successors, (6) [2022-07-13 18:00:25,138 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-07-13 18:00:25,138 INFO L93 Difference]: Finished difference Result 2115 states and 2678 transitions. [2022-07-13 18:00:25,139 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 9 states. [2022-07-13 18:00:25,139 INFO L78 Accepts]: Start accepts. Automaton has has 8 states, 8 states have (on average 10.25) internal successors, (82), 5 states have internal predecessors, (82), 2 states have call successors, (6), 5 states have call predecessors, (6), 2 states have return successors, (6), 2 states have call predecessors, (6), 2 states have call successors, (6) Word has length 117 [2022-07-13 18:00:25,139 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2022-07-13 18:00:25,140 INFO L225 Difference]: With dead ends: 2115 [2022-07-13 18:00:25,140 INFO L226 Difference]: Without dead ends: 0 [2022-07-13 18:00:25,146 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 27 GetRequests, 17 SyntacticMatches, 0 SemanticMatches, 10 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 14 ImplicationChecksByTransitivity, 0.1s TimeCoverageRelationStatistics Valid=39, Invalid=93, Unknown=0, NotChecked=0, Total=132 [2022-07-13 18:00:25,147 INFO L413 NwaCegarLoop]: 87 mSDtfsCounter, 155 mSDsluCounter, 224 mSDsCounter, 0 mSdLazyCounter, 210 mSolverCounterSat, 41 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.2s Time, 0 mProtectedPredicate, 0 mProtectedAction, 157 SdHoareTripleChecker+Valid, 311 SdHoareTripleChecker+Invalid, 251 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 41 IncrementalHoareTripleChecker+Valid, 210 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.2s IncrementalHoareTripleChecker+Time [2022-07-13 18:00:25,148 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [157 Valid, 311 Invalid, 251 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [41 Valid, 210 Invalid, 0 Unknown, 0 Unchecked, 0.2s Time] [2022-07-13 18:00:25,148 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 0 states. [2022-07-13 18:00:25,148 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 0 to 0. [2022-07-13 18:00:25,148 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 0 states, 0 states have (on average 0.0) internal successors, (0), 0 states have internal predecessors, (0), 0 states have call successors, (0), 0 states have call predecessors, (0), 0 states have return successors, (0), 0 states have call predecessors, (0), 0 states have call successors, (0) [2022-07-13 18:00:25,149 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 0 states to 0 states and 0 transitions. [2022-07-13 18:00:25,149 INFO L78 Accepts]: Start accepts. Automaton has 0 states and 0 transitions. Word has length 117 [2022-07-13 18:00:25,149 INFO L84 Accepts]: Finished accepts. word is rejected. [2022-07-13 18:00:25,149 INFO L495 AbstractCegarLoop]: Abstraction has 0 states and 0 transitions. [2022-07-13 18:00:25,149 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 8 states, 8 states have (on average 10.25) internal successors, (82), 5 states have internal predecessors, (82), 2 states have call successors, (6), 5 states have call predecessors, (6), 2 states have return successors, (6), 2 states have call predecessors, (6), 2 states have call successors, (6) [2022-07-13 18:00:25,150 INFO L276 IsEmpty]: Start isEmpty. Operand 0 states and 0 transitions. [2022-07-13 18:00:25,150 INFO L282 IsEmpty]: Finished isEmpty. No accepting run. [2022-07-13 18:00:25,152 INFO L805 garLoopResultBuilder]: Registering result SAFE for location timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION (0 of 1 remaining) [2022-07-13 18:00:25,153 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable11 [2022-07-13 18:00:25,154 INFO L343 DoubleDeckerVisitor]: Before removal of dead ends 0 states and 0 transitions. [2022-07-13 18:00:28,849 INFO L895 garLoopResultBuilder]: At program point deactivatePumpENTRY(lines 714 721) the Hoare annotation is: (or (= ~pumpRunning~0 |old(~pumpRunning~0)|) (not (<= 1 ~waterLevel~0)) (= 0 ~systemActive~0)) [2022-07-13 18:00:28,850 INFO L899 garLoopResultBuilder]: For program point deactivatePumpEXIT(lines 714 721) no Hoare annotation was computed. [2022-07-13 18:00:28,850 INFO L899 garLoopResultBuilder]: For program point deactivatePumpFINAL(lines 714 721) no Hoare annotation was computed. [2022-07-13 18:00:28,850 INFO L899 garLoopResultBuilder]: For program point processEnvironment__wrappee__baseEXIT(lines 629 635) no Hoare annotation was computed. [2022-07-13 18:00:28,850 INFO L902 garLoopResultBuilder]: At program point processEnvironment__wrappee__baseFINAL(lines 629 635) the Hoare annotation is: true [2022-07-13 18:00:28,850 INFO L902 garLoopResultBuilder]: At program point changeMethaneLevelENTRY(lines 935 946) the Hoare annotation is: true [2022-07-13 18:00:28,851 INFO L899 garLoopResultBuilder]: For program point L939-1(lines 935 946) no Hoare annotation was computed. [2022-07-13 18:00:28,851 INFO L899 garLoopResultBuilder]: For program point changeMethaneLevelEXIT(lines 935 946) no Hoare annotation was computed. [2022-07-13 18:00:28,851 INFO L899 garLoopResultBuilder]: For program point L609-1(lines 608 627) no Hoare annotation was computed. [2022-07-13 18:00:28,851 INFO L899 garLoopResultBuilder]: For program point L671(lines 671 679) no Hoare annotation was computed. [2022-07-13 18:00:28,851 INFO L899 garLoopResultBuilder]: For program point L667(lines 667 684) no Hoare annotation was computed. [2022-07-13 18:00:28,851 INFO L899 garLoopResultBuilder]: For program point L915(lines 915 919) no Hoare annotation was computed. [2022-07-13 18:00:28,851 INFO L895 garLoopResultBuilder]: At program point L915-2(lines 911 922) the Hoare annotation is: (and (or (not (= |old(~pumpRunning~0)| 0)) (not (<= 1 |old(~waterLevel~0)|))) (or (and (= ~pumpRunning~0 |old(~pumpRunning~0)|) (<= 1 ~waterLevel~0)) (= 0 ~systemActive~0) (not (<= 2 |old(~waterLevel~0)|)))) [2022-07-13 18:00:28,852 INFO L895 garLoopResultBuilder]: At program point L589(lines 584 591) the Hoare annotation is: (and (or (not (= |old(~pumpRunning~0)| 0)) (not (<= 1 |old(~waterLevel~0)|))) (or (= 0 ~systemActive~0) (not (<= 2 |old(~waterLevel~0)|)))) [2022-07-13 18:00:28,852 INFO L895 garLoopResultBuilder]: At program point L812(lines 797 815) the Hoare annotation is: (and (or (not (= |old(~pumpRunning~0)| 0)) (not (<= 1 |old(~waterLevel~0)|))) (or (and (= ~pumpRunning~0 |old(~pumpRunning~0)|) (= |timeShift_isLowWaterSensorDry_#res#1| 0) (<= 1 |timeShift_isLowWaterLevel_#res#1|) (= |timeShift_isLowWaterLevel_~tmp~9#1| 0) (<= 1 ~waterLevel~0) (<= 1 |timeShift_isLowWaterLevel_~tmp___0~2#1|)) (= 0 ~systemActive~0) (not (<= 2 |old(~waterLevel~0)|)))) [2022-07-13 18:00:28,852 INFO L899 garLoopResultBuilder]: For program point timeShiftFINAL(lines 605 628) no Hoare annotation was computed. [2022-07-13 18:00:28,852 INFO L895 garLoopResultBuilder]: At program point L738(lines 733 741) the Hoare annotation is: (and (or (not (= |old(~pumpRunning~0)| 0)) (not (<= 1 |old(~waterLevel~0)|))) (or (= 0 ~systemActive~0) (not (<= 2 |old(~waterLevel~0)|)))) [2022-07-13 18:00:28,852 INFO L895 garLoopResultBuilder]: At program point L1007(lines 1002 1010) the Hoare annotation is: (and (or (not (= |old(~pumpRunning~0)| 0)) (not (<= 1 |old(~waterLevel~0)|))) (or (and (= ~pumpRunning~0 |old(~pumpRunning~0)|) (= |timeShift_isLowWaterSensorDry_#res#1| 0) (<= 1 ~waterLevel~0)) (= 0 ~systemActive~0) (not (<= 2 |old(~waterLevel~0)|)))) [2022-07-13 18:00:28,852 INFO L895 garLoopResultBuilder]: At program point L677(line 677) the Hoare annotation is: (and (or (not (= |old(~pumpRunning~0)| 0)) (not (<= 1 |old(~waterLevel~0)|))) (or (= 0 ~systemActive~0) (not (<= 2 |old(~waterLevel~0)|)))) [2022-07-13 18:00:28,853 INFO L895 garLoopResultBuilder]: At program point L673(line 673) the Hoare annotation is: (and (or (= 0 ~systemActive~0) (and (= ~pumpRunning~0 |old(~pumpRunning~0)|) (= |timeShift_isLowWaterSensorDry_#res#1| 0) (<= 1 |timeShift_isLowWaterLevel_#res#1|) (<= 1 |timeShift_processEnvironment_~tmp~6#1|) (= |timeShift_isLowWaterLevel_~tmp~9#1| 0) (<= 1 ~waterLevel~0) (<= 1 |timeShift_isLowWaterLevel_~tmp___0~2#1|)) (not (<= 2 |old(~waterLevel~0)|))) (or (not (= |old(~pumpRunning~0)| 0)) (not (<= 1 |old(~waterLevel~0)|)))) [2022-07-13 18:00:28,853 INFO L899 garLoopResultBuilder]: For program point L570(lines 570 576) no Hoare annotation was computed. [2022-07-13 18:00:28,853 INFO L899 garLoopResultBuilder]: For program point L566(lines 566 579) no Hoare annotation was computed. [2022-07-13 18:00:28,853 INFO L895 garLoopResultBuilder]: At program point L566-1(lines 558 582) the Hoare annotation is: (let ((.cse7 (<= 2 ~waterLevel~0)) (.cse2 (= |old(~waterLevel~0)| ~waterLevel~0)) (.cse8 (<= 2 |timeShift_getWaterLevel_#res#1|)) (.cse9 (<= 2 |timeShift___utac_acc__Specification4_spec__1_~tmp~4#1|)) (.cse10 (= 0 ~systemActive~0))) (let ((.cse1 (= ~pumpRunning~0 0)) (.cse4 (<= 1 |timeShift_getWaterLevel_#res#1|)) (.cse5 (<= 1 |timeShift___utac_acc__Specification4_spec__1_~tmp~4#1|)) (.cse0 (not (= |old(~pumpRunning~0)| 0))) (.cse3 (and .cse7 .cse2 .cse8 .cse9 (not .cse10))) (.cse6 (not (<= 2 |old(~waterLevel~0)|)))) (and (or .cse0 (and .cse1 .cse2) .cse3 (not (<= 1 |old(~waterLevel~0)|))) (or .cse0 (not (= |old(~waterLevel~0)| 1)) (and (= |timeShift___utac_acc__Specification4_spec__1_~tmp~4#1| 1) (= |timeShift_getWaterLevel_#res#1| 1))) (or .cse0 (and .cse4 .cse5) .cse6) (or (and .cse1 (<= 1 |timeShift_isLowWaterLevel_#res#1|) (<= 1 |timeShift_processEnvironment_~tmp~6#1|) (<= 1 ~waterLevel~0) .cse4 .cse5 (<= 1 |timeShift_isLowWaterLevel_~tmp___0~2#1|)) (and .cse7 .cse8 .cse9) .cse10 .cse6) (or .cse0 .cse3 .cse10 .cse6)))) [2022-07-13 18:00:28,853 INFO L895 garLoopResultBuilder]: At program point L682(line 682) the Hoare annotation is: (let ((.cse3 (= 0 ~systemActive~0))) (let ((.cse0 (= ~pumpRunning~0 0)) (.cse2 (not (= |old(~pumpRunning~0)| 0))) (.cse1 (not .cse3)) (.cse4 (not (<= 2 |old(~waterLevel~0)|)))) (and (or (and .cse0 (= ~waterLevel~0 1) .cse1) .cse2 (not (= |old(~waterLevel~0)| 1))) (or (and (= ~pumpRunning~0 |old(~pumpRunning~0)|) .cse0) .cse3 .cse4) (or .cse2 (and (= |old(~waterLevel~0)| ~waterLevel~0) .cse1) .cse4)))) [2022-07-13 18:00:28,854 INFO L895 garLoopResultBuilder]: At program point L682-1(lines 663 687) the Hoare annotation is: (let ((.cse0 (= ~pumpRunning~0 0)) (.cse3 (<= 2 ~waterLevel~0)) (.cse4 (= 0 ~systemActive~0))) (and (let ((.cse1 (= |old(~waterLevel~0)| ~waterLevel~0)) (.cse2 (not .cse4))) (or (not (= |old(~pumpRunning~0)| 0)) (not (<= 1 |old(~waterLevel~0)|)) (and .cse0 .cse1 .cse2) (and .cse3 .cse1 .cse2))) (or (and .cse0 (<= 1 |timeShift_isLowWaterLevel_#res#1|) (<= 1 |timeShift_processEnvironment_~tmp~6#1|) (<= 1 ~waterLevel~0) (<= 1 |timeShift_isLowWaterLevel_~tmp___0~2#1|)) .cse3 .cse4 (not (<= 2 |old(~waterLevel~0)|))))) [2022-07-13 18:00:28,854 INFO L899 garLoopResultBuilder]: For program point L616-1(lines 616 622) no Hoare annotation was computed. [2022-07-13 18:00:28,854 INFO L899 garLoopResultBuilder]: For program point L806(lines 806 810) no Hoare annotation was computed. [2022-07-13 18:00:28,854 INFO L899 garLoopResultBuilder]: For program point L806-2(lines 806 810) no Hoare annotation was computed. [2022-07-13 18:00:28,854 INFO L895 garLoopResultBuilder]: At program point L984(lines 979 987) the Hoare annotation is: (let ((.cse7 (<= 2 ~waterLevel~0)) (.cse6 (= |old(~waterLevel~0)| ~waterLevel~0)) (.cse8 (<= 2 |timeShift_getWaterLevel_#res#1|)) (.cse2 (= 0 ~systemActive~0))) (let ((.cse1 (and .cse7 .cse6 .cse8 (not .cse2))) (.cse5 (= ~pumpRunning~0 0)) (.cse4 (<= 1 |timeShift_getWaterLevel_#res#1|)) (.cse3 (not (<= 2 |old(~waterLevel~0)|))) (.cse0 (not (= |old(~pumpRunning~0)| 0)))) (and (or .cse0 .cse1 .cse2 .cse3) (or .cse0 .cse4 .cse3) (or .cse0 (and .cse5 .cse6) .cse1 (not (<= 1 |old(~waterLevel~0)|))) (or (and .cse7 .cse8) (and .cse5 (<= 1 |timeShift_isLowWaterLevel_#res#1|) (<= 1 |timeShift_processEnvironment_~tmp~6#1|) (<= 1 ~waterLevel~0) .cse4 (<= 1 |timeShift_isLowWaterLevel_~tmp___0~2#1|)) .cse2 .cse3) (or .cse0 (not (= |old(~waterLevel~0)| 1)) (= |timeShift_getWaterLevel_#res#1| 1))))) [2022-07-13 18:00:28,854 INFO L895 garLoopResultBuilder]: At program point timeShiftENTRY(lines 605 628) the Hoare annotation is: (let ((.cse0 (= |old(~waterLevel~0)| ~waterLevel~0))) (and (or (not (= |old(~pumpRunning~0)| 0)) (and (= ~pumpRunning~0 0) .cse0) (not (<= 1 |old(~waterLevel~0)|))) (or (and (= ~pumpRunning~0 |old(~pumpRunning~0)|) .cse0) (= 0 ~systemActive~0) (not (<= 2 |old(~waterLevel~0)|))))) [2022-07-13 18:00:28,854 INFO L899 garLoopResultBuilder]: For program point L588(line 588) no Hoare annotation was computed. [2022-07-13 18:00:28,855 INFO L899 garLoopResultBuilder]: For program point timeShiftEXIT(lines 605 628) no Hoare annotation was computed. [2022-07-13 18:00:28,855 INFO L899 garLoopResultBuilder]: For program point timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION(line 588) no Hoare annotation was computed. [2022-07-13 18:00:28,855 INFO L902 garLoopResultBuilder]: At program point L96(line 96) the Hoare annotation is: true [2022-07-13 18:00:28,855 INFO L899 garLoopResultBuilder]: For program point cleanupEXIT(lines 90 119) no Hoare annotation was computed. [2022-07-13 18:00:28,855 INFO L899 garLoopResultBuilder]: For program point L96-1(line 96) no Hoare annotation was computed. [2022-07-13 18:00:28,855 INFO L902 garLoopResultBuilder]: At program point cleanupENTRY(lines 90 119) the Hoare annotation is: true [2022-07-13 18:00:28,855 INFO L902 garLoopResultBuilder]: At program point L115(lines 90 119) the Hoare annotation is: true [2022-07-13 18:00:28,856 INFO L899 garLoopResultBuilder]: For program point L111(line 111) no Hoare annotation was computed. [2022-07-13 18:00:28,856 INFO L899 garLoopResultBuilder]: For program point L104(lines 104 108) no Hoare annotation was computed. [2022-07-13 18:00:28,856 INFO L902 garLoopResultBuilder]: At program point L104-1(lines 104 108) the Hoare annotation is: true [2022-07-13 18:00:28,856 INFO L899 garLoopResultBuilder]: For program point L101(line 101) no Hoare annotation was computed. [2022-07-13 18:00:28,856 INFO L902 garLoopResultBuilder]: At program point L100-2(lines 100 114) the Hoare annotation is: true [2022-07-13 18:00:28,856 INFO L895 garLoopResultBuilder]: At program point L828(lines 816 830) the Hoare annotation is: (and (= ~pumpRunning~0 0) (= |ULTIMATE.start_valid_product_#res#1| 1) (= |ULTIMATE.start_main_~tmp~0#1| 1) (= |ULTIMATE.start_test_~splverifierCounter~0#1| 0) (<= 1 ~waterLevel~0)) [2022-07-13 18:00:28,856 INFO L902 garLoopResultBuilder]: At program point L184(lines 165 187) the Hoare annotation is: true [2022-07-13 18:00:28,857 INFO L895 garLoopResultBuilder]: At program point L151(lines 147 153) the Hoare annotation is: (and (= ~pumpRunning~0 0) (= |ULTIMATE.start_main_~tmp~0#1| 1) (= 1 ~systemActive~0) (= |ULTIMATE.start_valid_product_#res#1| ~systemActive~0) (= ~waterLevel~0 1)) [2022-07-13 18:00:28,857 INFO L899 garLoopResultBuilder]: For program point L820(lines 820 826) no Hoare annotation was computed. [2022-07-13 18:00:28,857 INFO L899 garLoopResultBuilder]: For program point L820-1(lines 820 826) no Hoare annotation was computed. [2022-07-13 18:00:28,857 INFO L902 garLoopResultBuilder]: At program point L903(lines 840 907) the Hoare annotation is: true [2022-07-13 18:00:28,857 INFO L899 garLoopResultBuilder]: For program point L870(lines 870 876) no Hoare annotation was computed. [2022-07-13 18:00:28,857 INFO L899 garLoopResultBuilder]: For program point L870-1(lines 870 876) no Hoare annotation was computed. [2022-07-13 18:00:28,857 INFO L899 garLoopResultBuilder]: For program point L-1(line -1) no Hoare annotation was computed. [2022-07-13 18:00:28,857 INFO L895 garLoopResultBuilder]: At program point L862(line 862) the Hoare annotation is: (let ((.cse0 (= |ULTIMATE.start_valid_product_#res#1| 1)) (.cse1 (= |ULTIMATE.start_main_~tmp~0#1| 1)) (.cse2 (= |ULTIMATE.start_test_~splverifierCounter~0#1| 0))) (or (and (= ~pumpRunning~0 0) .cse0 .cse1 .cse2 (<= 1 ~waterLevel~0)) (and .cse0 .cse1 (<= 2 ~waterLevel~0) .cse2 (not (= 0 ~systemActive~0))))) [2022-07-13 18:00:28,858 INFO L899 garLoopResultBuilder]: For program point ULTIMATE.startENTRY(line -1) no Hoare annotation was computed. [2022-07-13 18:00:28,858 INFO L899 garLoopResultBuilder]: For program point ULTIMATE.startFINAL(line -1) no Hoare annotation was computed. [2022-07-13 18:00:28,858 INFO L895 garLoopResultBuilder]: At program point L900(lines 849 901) the Hoare annotation is: false [2022-07-13 18:00:28,858 INFO L899 garLoopResultBuilder]: For program point ULTIMATE.startEXIT(line -1) no Hoare annotation was computed. [2022-07-13 18:00:28,858 INFO L899 garLoopResultBuilder]: For program point L888(lines 888 894) no Hoare annotation was computed. [2022-07-13 18:00:28,858 INFO L895 garLoopResultBuilder]: At program point L822(line 822) the Hoare annotation is: (and (= |ULTIMATE.start_valid_product_#res#1| 1) (= |ULTIMATE.start_main_~tmp~0#1| 1) (<= 2 ~waterLevel~0) (= |ULTIMATE.start_test_~splverifierCounter~0#1| 0) (not (= 0 ~systemActive~0))) [2022-07-13 18:00:28,858 INFO L895 garLoopResultBuilder]: At program point L888-2(lines 880 895) the Hoare annotation is: (let ((.cse0 (= |ULTIMATE.start_valid_product_#res#1| 1)) (.cse1 (= |ULTIMATE.start_main_~tmp~0#1| 1)) (.cse2 (= |ULTIMATE.start_test_~splverifierCounter~0#1| 0))) (or (and (= ~pumpRunning~0 0) .cse0 .cse1 .cse2 (<= 1 ~waterLevel~0)) (and .cse0 .cse1 (<= 2 ~waterLevel~0) .cse2 (not (= 0 ~systemActive~0))))) [2022-07-13 18:00:28,859 INFO L895 garLoopResultBuilder]: At program point L83(lines 78 86) the Hoare annotation is: (and (= ~pumpRunning~0 0) (= 1 ~systemActive~0) (= |ULTIMATE.start_valid_product_#res#1| ~systemActive~0) (= ~waterLevel~0 1)) [2022-07-13 18:00:28,859 INFO L899 garLoopResultBuilder]: For program point L851(lines 850 899) no Hoare annotation was computed. [2022-07-13 18:00:28,859 INFO L899 garLoopResultBuilder]: For program point L880(lines 880 895) no Hoare annotation was computed. [2022-07-13 18:00:28,859 INFO L895 garLoopResultBuilder]: At program point L75(lines 71 77) the Hoare annotation is: (and (= ~pumpRunning~0 0) (= 1 ~systemActive~0) (= ~waterLevel~0 1)) [2022-07-13 18:00:28,859 INFO L895 garLoopResultBuilder]: At program point L872(line 872) the Hoare annotation is: (let ((.cse0 (= |ULTIMATE.start_valid_product_#res#1| 1)) (.cse1 (= |ULTIMATE.start_main_~tmp~0#1| 1)) (.cse2 (= |ULTIMATE.start_test_~splverifierCounter~0#1| 0))) (or (and (= ~pumpRunning~0 0) .cse0 .cse1 .cse2 (<= 1 ~waterLevel~0)) (and .cse0 .cse1 (<= 2 ~waterLevel~0) .cse2 (not (= 0 ~systemActive~0))))) [2022-07-13 18:00:28,859 INFO L902 garLoopResultBuilder]: At program point L162(lines 155 164) the Hoare annotation is: true [2022-07-13 18:00:28,859 INFO L895 garLoopResultBuilder]: At program point L897(lines 850 899) the Hoare annotation is: (let ((.cse0 (= |ULTIMATE.start_valid_product_#res#1| 1)) (.cse1 (= |ULTIMATE.start_main_~tmp~0#1| 1)) (.cse2 (= |ULTIMATE.start_test_~splverifierCounter~0#1| 0))) (or (and (= ~pumpRunning~0 0) .cse0 .cse1 .cse2 (<= 1 ~waterLevel~0)) (and .cse0 .cse1 (<= 2 ~waterLevel~0) .cse2 (not (= 0 ~systemActive~0))))) [2022-07-13 18:00:28,859 INFO L899 garLoopResultBuilder]: For program point L860(lines 860 866) no Hoare annotation was computed. [2022-07-13 18:00:28,860 INFO L899 garLoopResultBuilder]: For program point L860-1(lines 860 866) no Hoare annotation was computed. [2022-07-13 18:00:28,860 INFO L899 garLoopResultBuilder]: For program point L852(lines 852 856) no Hoare annotation was computed. [2022-07-13 18:00:28,860 INFO L899 garLoopResultBuilder]: For program point L175(lines 175 182) no Hoare annotation was computed. [2022-07-13 18:00:28,860 INFO L899 garLoopResultBuilder]: For program point L175-2(lines 175 182) no Hoare annotation was computed. [2022-07-13 18:00:28,860 INFO L895 garLoopResultBuilder]: At program point L68(lines 64 70) the Hoare annotation is: (and (= ~pumpRunning~0 0) (= 1 ~systemActive~0) (= ~waterLevel~0 1)) [2022-07-13 18:00:28,860 INFO L895 garLoopResultBuilder]: At program point L836(lines 831 838) the Hoare annotation is: (let ((.cse0 (= |ULTIMATE.start_valid_product_#res#1| 1)) (.cse1 (= |ULTIMATE.start_main_~tmp~0#1| 1)) (.cse2 (= 1 ~systemActive~0)) (.cse3 (= |ULTIMATE.start_test_~splverifierCounter~0#1| 0))) (or (and .cse0 .cse1 (<= 2 ~waterLevel~0) .cse2 .cse3) (and (= ~pumpRunning~0 0) .cse0 .cse1 .cse2 .cse3 (= ~waterLevel~0 1)))) [2022-07-13 18:00:28,860 INFO L895 garLoopResultBuilder]: At program point processEnvironment__wrappee__highWaterSensorENTRY(lines 637 661) the Hoare annotation is: (or (not (= |old(~pumpRunning~0)| 0)) (= ~pumpRunning~0 0) (not (<= 1 ~waterLevel~0)) (= 0 ~systemActive~0)) [2022-07-13 18:00:28,861 INFO L899 garLoopResultBuilder]: For program point L704(lines 704 710) no Hoare annotation was computed. [2022-07-13 18:00:28,861 INFO L895 garLoopResultBuilder]: At program point L704-2(lines 697 713) the Hoare annotation is: (or (not (= |old(~pumpRunning~0)| 0)) (not (<= 1 ~waterLevel~0)) (<= 2 ~waterLevel~0) (= 0 ~systemActive~0)) [2022-07-13 18:00:28,861 INFO L895 garLoopResultBuilder]: At program point L793(lines 778 796) the Hoare annotation is: (let ((.cse0 (not (= |old(~pumpRunning~0)| 0))) (.cse1 (= ~pumpRunning~0 0)) (.cse2 (= 0 ~systemActive~0))) (and (or .cse0 .cse1 (not (<= 2 ~waterLevel~0)) .cse2) (or (not (= ~waterLevel~0 1)) .cse0 (and (not (= |processEnvironment__wrappee__highWaterSensor_isHighWaterLevel_~tmp~8#1| 0)) .cse1 (= |processEnvironment__wrappee__highWaterSensor_isHighWaterLevel_~tmp___0~1#1| 0) (not (= |processEnvironment__wrappee__highWaterSensor_isHighWaterSensorDry_#res#1| 0)) (= |processEnvironment__wrappee__highWaterSensor_isHighWaterLevel_#res#1| 0)) .cse2))) [2022-07-13 18:00:28,861 INFO L895 garLoopResultBuilder]: At program point L729(lines 722 732) the Hoare annotation is: (let ((.cse0 (not (= |old(~pumpRunning~0)| 0))) (.cse1 (= 0 ~systemActive~0))) (and (or .cse0 (= ~pumpRunning~0 0) (not (<= 2 ~waterLevel~0)) .cse1) (or (not (= ~waterLevel~0 1)) .cse0 .cse1))) [2022-07-13 18:00:28,861 INFO L895 garLoopResultBuilder]: At program point L952(lines 947 955) the Hoare annotation is: (let ((.cse0 (not (= |old(~pumpRunning~0)| 0))) (.cse1 (= 0 ~systemActive~0))) (and (or .cse0 (= ~pumpRunning~0 0) (not (<= 2 ~waterLevel~0)) .cse1) (or (not (= ~waterLevel~0 1)) .cse0 .cse1))) [2022-07-13 18:00:28,861 INFO L899 garLoopResultBuilder]: For program point L787(lines 787 791) no Hoare annotation was computed. [2022-07-13 18:00:28,861 INFO L899 garLoopResultBuilder]: For program point L787-2(lines 787 791) no Hoare annotation was computed. [2022-07-13 18:00:28,862 INFO L895 garLoopResultBuilder]: At program point L651(line 651) the Hoare annotation is: (let ((.cse0 (not (= |old(~pumpRunning~0)| 0))) (.cse2 (= ~pumpRunning~0 0)) (.cse3 (= |processEnvironment__wrappee__highWaterSensor_~tmp~5#1| 0)) (.cse1 (= 0 ~systemActive~0))) (and (or (not (= ~waterLevel~0 1)) .cse0 .cse1 (and (not (= |processEnvironment__wrappee__highWaterSensor_isHighWaterLevel_~tmp~8#1| 0)) .cse2 .cse3 (not (= |processEnvironment__wrappee__highWaterSensor_isHighWaterSensorDry_#res#1| 0)))) (or .cse0 (and .cse2 .cse3) (not (<= 2 ~waterLevel~0)) .cse1))) [2022-07-13 18:00:28,862 INFO L899 garLoopResultBuilder]: For program point L645(lines 645 653) no Hoare annotation was computed. [2022-07-13 18:00:28,862 INFO L899 garLoopResultBuilder]: For program point L641(lines 641 658) no Hoare annotation was computed. [2022-07-13 18:00:28,862 INFO L899 garLoopResultBuilder]: For program point L992(lines 992 998) no Hoare annotation was computed. [2022-07-13 18:00:28,862 INFO L899 garLoopResultBuilder]: For program point processEnvironment__wrappee__highWaterSensorEXIT(lines 637 661) no Hoare annotation was computed. [2022-07-13 18:00:28,862 INFO L895 garLoopResultBuilder]: At program point L693(lines 688 695) the Hoare annotation is: (or (not (= ~waterLevel~0 1)) (not (= |old(~pumpRunning~0)| 0)) (= 0 ~systemActive~0)) [2022-07-13 18:00:28,862 INFO L895 garLoopResultBuilder]: At program point L656(line 656) the Hoare annotation is: (or (not (= |old(~pumpRunning~0)| 0)) (not (<= 1 ~waterLevel~0)) (= 0 ~systemActive~0)) [2022-07-13 18:00:28,862 INFO L899 garLoopResultBuilder]: For program point L656-1(lines 637 661) no Hoare annotation was computed. [2022-07-13 18:00:28,863 INFO L895 garLoopResultBuilder]: At program point L997(lines 988 1001) the Hoare annotation is: (let ((.cse0 (= ~pumpRunning~0 0))) (or (not (= |old(~pumpRunning~0)| 0)) (not (<= 1 ~waterLevel~0)) (and .cse0 (not (= |processEnvironment__wrappee__highWaterSensor_isHighWaterSensorDry_#res#1| 0))) (and .cse0 (<= 2 ~waterLevel~0)) (= 0 ~systemActive~0))) [2022-07-13 18:00:28,863 INFO L899 garLoopResultBuilder]: For program point waterRiseEXIT(lines 923 934) no Hoare annotation was computed. [2022-07-13 18:00:28,863 INFO L899 garLoopResultBuilder]: For program point L927-1(lines 923 934) no Hoare annotation was computed. [2022-07-13 18:00:28,863 INFO L895 garLoopResultBuilder]: At program point waterRiseENTRY(lines 923 934) the Hoare annotation is: (let ((.cse0 (= |old(~waterLevel~0)| ~waterLevel~0))) (and (or (not (= ~pumpRunning~0 0)) (not (<= 1 |old(~waterLevel~0)|)) .cse0) (or .cse0 (= 0 ~systemActive~0) (not (<= 2 |old(~waterLevel~0)|))))) [2022-07-13 18:00:28,866 INFO L356 BasicCegarLoop]: Path program histogram: [2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-07-13 18:00:28,867 INFO L176 ceAbstractionStarter]: Computing trace abstraction results [2022-07-13 18:00:28,888 INFO L202 PluginConnector]: Adding new model de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction CFG 13.07 06:00:28 BoogieIcfgContainer [2022-07-13 18:00:28,888 INFO L132 PluginConnector]: ------------------------ END TraceAbstraction---------------------------- [2022-07-13 18:00:28,889 INFO L113 PluginConnector]: ------------------------Witness Printer---------------------------- [2022-07-13 18:00:28,889 INFO L271 PluginConnector]: Initializing Witness Printer... [2022-07-13 18:00:28,889 INFO L275 PluginConnector]: Witness Printer initialized [2022-07-13 18:00:28,890 INFO L185 PluginConnector]: Executing the observer RCFGCatcher from plugin Witness Printer for "de.uni_freiburg.informatik.ultimate.plugins.generator.rcfgbuilder CFG 13.07 06:00:18" (3/4) ... [2022-07-13 18:00:28,892 INFO L137 WitnessPrinter]: Generating witness for correct program [2022-07-13 18:00:28,897 INFO L354 RCFGBacktranslator]: Ignoring RootEdge to procedure deactivatePump [2022-07-13 18:00:28,897 INFO L354 RCFGBacktranslator]: Ignoring RootEdge to procedure processEnvironment__wrappee__base [2022-07-13 18:00:28,897 INFO L354 RCFGBacktranslator]: Ignoring RootEdge to procedure changeMethaneLevel [2022-07-13 18:00:28,897 INFO L354 RCFGBacktranslator]: Ignoring RootEdge to procedure timeShift [2022-07-13 18:00:28,897 INFO L354 RCFGBacktranslator]: Ignoring RootEdge to procedure cleanup [2022-07-13 18:00:28,898 INFO L354 RCFGBacktranslator]: Ignoring RootEdge to procedure processEnvironment__wrappee__highWaterSensor [2022-07-13 18:00:28,898 INFO L354 RCFGBacktranslator]: Ignoring RootEdge to procedure waterRise [2022-07-13 18:00:28,904 INFO L910 BoogieBacktranslator]: Reduced CFG by removing 55 nodes and edges [2022-07-13 18:00:28,905 INFO L910 BoogieBacktranslator]: Reduced CFG by removing 22 nodes and edges [2022-07-13 18:00:28,905 INFO L910 BoogieBacktranslator]: Reduced CFG by removing 11 nodes and edges [2022-07-13 18:00:28,906 INFO L910 BoogieBacktranslator]: Reduced CFG by removing 5 nodes and edges [2022-07-13 18:00:28,906 INFO L910 BoogieBacktranslator]: Reduced CFG by removing 2 nodes and edges [2022-07-13 18:00:28,907 INFO L910 BoogieBacktranslator]: Reduced CFG by removing 1 nodes and edges [2022-07-13 18:00:28,907 INFO L910 BoogieBacktranslator]: Reduced CFG by removing 1 nodes and edges [2022-07-13 18:00:28,926 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: ((pumpRunning == 0 && 1 == systemActive) && \result == systemActive) && waterLevel == 1 [2022-07-13 18:00:28,926 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (((pumpRunning == 0 && tmp == 1) && 1 == systemActive) && \result == systemActive) && waterLevel == 1 [2022-07-13 18:00:28,926 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: ((((pumpRunning == 0 && \result == 1) && tmp == 1) && splverifierCounter == 0) && 1 <= waterLevel) || ((((\result == 1 && tmp == 1) && 2 <= waterLevel) && splverifierCounter == 0) && !(0 == systemActive)) [2022-07-13 18:00:28,927 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (!(\old(pumpRunning) == 0) || !(1 <= \old(waterLevel))) && (((pumpRunning == \old(pumpRunning) && 1 <= waterLevel) || 0 == systemActive) || !(2 <= \old(waterLevel))) [2022-07-13 18:00:28,927 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (((!(\old(pumpRunning) == 0) || !(1 <= \old(waterLevel))) || ((pumpRunning == 0 && \old(waterLevel) == waterLevel) && !(0 == systemActive))) || ((2 <= waterLevel && \old(waterLevel) == waterLevel) && !(0 == systemActive))) && (((((((pumpRunning == 0 && 1 <= \result) && 1 <= tmp) && 1 <= waterLevel) && 1 <= tmp___0) || 2 <= waterLevel) || 0 == systemActive) || !(2 <= \old(waterLevel))) [2022-07-13 18:00:28,928 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: ((((\result == 1 && tmp == 1) && 2 <= waterLevel) && 1 == systemActive) && splverifierCounter == 0) || (((((pumpRunning == 0 && \result == 1) && tmp == 1) && 1 == systemActive) && splverifierCounter == 0) && waterLevel == 1) [2022-07-13 18:00:28,928 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: ((((((!(\old(pumpRunning) == 0) || (((2 <= waterLevel && \old(waterLevel) == waterLevel) && 2 <= \result) && !(0 == systemActive))) || 0 == systemActive) || !(2 <= \old(waterLevel))) && ((!(\old(pumpRunning) == 0) || 1 <= \result) || !(2 <= \old(waterLevel)))) && (((!(\old(pumpRunning) == 0) || (pumpRunning == 0 && \old(waterLevel) == waterLevel)) || (((2 <= waterLevel && \old(waterLevel) == waterLevel) && 2 <= \result) && !(0 == systemActive))) || !(1 <= \old(waterLevel)))) && ((((2 <= waterLevel && 2 <= \result) || (((((pumpRunning == 0 && 1 <= \result) && 1 <= tmp) && 1 <= waterLevel) && 1 <= \result) && 1 <= tmp___0)) || 0 == systemActive) || !(2 <= \old(waterLevel)))) && ((!(\old(pumpRunning) == 0) || !(\old(waterLevel) == 1)) || \result == 1) [2022-07-13 18:00:28,928 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (((pumpRunning == 0 && \result == 1) && tmp == 1) && splverifierCounter == 0) && 1 <= waterLevel [2022-07-13 18:00:28,928 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: ((((((!(\old(pumpRunning) == 0) || (pumpRunning == 0 && \old(waterLevel) == waterLevel)) || ((((2 <= waterLevel && \old(waterLevel) == waterLevel) && 2 <= \result) && 2 <= tmp) && !(0 == systemActive))) || !(1 <= \old(waterLevel))) && ((!(\old(pumpRunning) == 0) || !(\old(waterLevel) == 1)) || (tmp == 1 && \result == 1))) && ((!(\old(pumpRunning) == 0) || (1 <= \result && 1 <= tmp)) || !(2 <= \old(waterLevel)))) && (((((((((pumpRunning == 0 && 1 <= \result) && 1 <= tmp) && 1 <= waterLevel) && 1 <= \result) && 1 <= tmp) && 1 <= tmp___0) || ((2 <= waterLevel && 2 <= \result) && 2 <= tmp)) || 0 == systemActive) || !(2 <= \old(waterLevel)))) && (((!(\old(pumpRunning) == 0) || ((((2 <= waterLevel && \old(waterLevel) == waterLevel) && 2 <= \result) && 2 <= tmp) && !(0 == systemActive))) || 0 == systemActive) || !(2 <= \old(waterLevel))) [2022-07-13 18:00:28,929 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (!(\old(pumpRunning) == 0) || !(1 <= \old(waterLevel))) && ((((pumpRunning == \old(pumpRunning) && \result == 0) && 1 <= waterLevel) || 0 == systemActive) || !(2 <= \old(waterLevel))) [2022-07-13 18:00:28,929 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (((!(\old(pumpRunning) == 0) || !(1 <= waterLevel)) || (pumpRunning == 0 && !(\result == 0))) || (pumpRunning == 0 && 2 <= waterLevel)) || 0 == systemActive [2022-07-13 18:00:28,929 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (!(\old(pumpRunning) == 0) || !(1 <= \old(waterLevel))) && (0 == systemActive || !(2 <= \old(waterLevel))) [2022-07-13 18:00:28,929 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (!(\old(pumpRunning) == 0) || !(1 <= \old(waterLevel))) && (((((((pumpRunning == \old(pumpRunning) && \result == 0) && 1 <= \result) && tmp == 0) && 1 <= waterLevel) && 1 <= tmp___0) || 0 == systemActive) || !(2 <= \old(waterLevel))) [2022-07-13 18:00:28,930 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (((!(\old(pumpRunning) == 0) || pumpRunning == 0) || !(2 <= waterLevel)) || 0 == systemActive) && (((!(waterLevel == 1) || !(\old(pumpRunning) == 0)) || ((((!(tmp == 0) && pumpRunning == 0) && tmp___0 == 0) && !(\result == 0)) && \result == 0)) || 0 == systemActive) [2022-07-13 18:00:28,930 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (!(\old(pumpRunning) == 0) || !(1 <= \old(waterLevel))) && (0 == systemActive || !(2 <= \old(waterLevel))) [2022-07-13 18:00:28,930 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (((!(\old(pumpRunning) == 0) || pumpRunning == 0) || !(2 <= waterLevel)) || 0 == systemActive) && ((!(waterLevel == 1) || !(\old(pumpRunning) == 0)) || 0 == systemActive) [2022-07-13 18:00:28,930 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (((!(\old(pumpRunning) == 0) || pumpRunning == 0) || !(2 <= waterLevel)) || 0 == systemActive) && ((!(waterLevel == 1) || !(\old(pumpRunning) == 0)) || 0 == systemActive) [2022-07-13 18:00:28,930 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: ((!(\old(pumpRunning) == 0) || !(1 <= waterLevel)) || 2 <= waterLevel) || 0 == systemActive [2022-07-13 18:00:28,931 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (!(waterLevel == 1) || !(\old(pumpRunning) == 0)) || 0 == systemActive [2022-07-13 18:00:28,951 INFO L141 WitnessManager]: Wrote witness to /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/witness.graphml [2022-07-13 18:00:28,951 INFO L132 PluginConnector]: ------------------------ END Witness Printer---------------------------- [2022-07-13 18:00:28,951 INFO L158 Benchmark]: Toolchain (without parser) took 11982.78ms. Allocated memory was 136.3MB in the beginning and 211.8MB in the end (delta: 75.5MB). Free memory was 101.1MB in the beginning and 87.7MB in the end (delta: 13.4MB). Peak memory consumption was 87.7MB. Max. memory is 16.1GB. [2022-07-13 18:00:28,952 INFO L158 Benchmark]: CDTParser took 0.13ms. Allocated memory is still 83.9MB. Free memory was 58.1MB in the beginning and 58.1MB in the end (delta: 27.8kB). There was no memory consumed. Max. memory is 16.1GB. [2022-07-13 18:00:28,952 INFO L158 Benchmark]: CACSL2BoogieTranslator took 496.85ms. Allocated memory is still 136.3MB. Free memory was 100.8MB in the beginning and 101.8MB in the end (delta: -973.1kB). Peak memory consumption was 8.4MB. Max. memory is 16.1GB. [2022-07-13 18:00:28,952 INFO L158 Benchmark]: Boogie Procedure Inliner took 68.30ms. Allocated memory is still 136.3MB. Free memory was 101.8MB in the beginning and 98.9MB in the end (delta: 2.9MB). Peak memory consumption was 2.1MB. Max. memory is 16.1GB. [2022-07-13 18:00:28,952 INFO L158 Benchmark]: Boogie Preprocessor took 21.62ms. Allocated memory is still 136.3MB. Free memory was 98.9MB in the beginning and 96.9MB in the end (delta: 2.0MB). Peak memory consumption was 2.1MB. Max. memory is 16.1GB. [2022-07-13 18:00:28,953 INFO L158 Benchmark]: RCFGBuilder took 451.35ms. Allocated memory is still 136.3MB. Free memory was 96.9MB in the beginning and 80.1MB in the end (delta: 16.8MB). Peak memory consumption was 16.8MB. Max. memory is 16.1GB. [2022-07-13 18:00:28,953 INFO L158 Benchmark]: TraceAbstraction took 10876.67ms. Allocated memory was 136.3MB in the beginning and 211.8MB in the end (delta: 75.5MB). Free memory was 79.5MB in the beginning and 92.9MB in the end (delta: -13.4MB). Peak memory consumption was 98.8MB. Max. memory is 16.1GB. [2022-07-13 18:00:28,953 INFO L158 Benchmark]: Witness Printer took 62.14ms. Allocated memory is still 211.8MB. Free memory was 92.9MB in the beginning and 87.7MB in the end (delta: 5.2MB). Peak memory consumption was 4.2MB. Max. memory is 16.1GB. [2022-07-13 18:00:28,955 INFO L339 ainManager$Toolchain]: ####################### End [Toolchain 1] ####################### --- Results --- * Results from de.uni_freiburg.informatik.ultimate.core: - StatisticsResult: Toolchain Benchmarks Benchmark results are: * CDTParser took 0.13ms. Allocated memory is still 83.9MB. Free memory was 58.1MB in the beginning and 58.1MB in the end (delta: 27.8kB). There was no memory consumed. Max. memory is 16.1GB. * CACSL2BoogieTranslator took 496.85ms. Allocated memory is still 136.3MB. Free memory was 100.8MB in the beginning and 101.8MB in the end (delta: -973.1kB). Peak memory consumption was 8.4MB. Max. memory is 16.1GB. * Boogie Procedure Inliner took 68.30ms. Allocated memory is still 136.3MB. Free memory was 101.8MB in the beginning and 98.9MB in the end (delta: 2.9MB). Peak memory consumption was 2.1MB. Max. memory is 16.1GB. * Boogie Preprocessor took 21.62ms. Allocated memory is still 136.3MB. Free memory was 98.9MB in the beginning and 96.9MB in the end (delta: 2.0MB). Peak memory consumption was 2.1MB. Max. memory is 16.1GB. * RCFGBuilder took 451.35ms. Allocated memory is still 136.3MB. Free memory was 96.9MB in the beginning and 80.1MB in the end (delta: 16.8MB). Peak memory consumption was 16.8MB. Max. memory is 16.1GB. * TraceAbstraction took 10876.67ms. Allocated memory was 136.3MB in the beginning and 211.8MB in the end (delta: 75.5MB). Free memory was 79.5MB in the beginning and 92.9MB in the end (delta: -13.4MB). Peak memory consumption was 98.8MB. Max. memory is 16.1GB. * Witness Printer took 62.14ms. Allocated memory is still 211.8MB. Free memory was 92.9MB in the beginning and 87.7MB in the end (delta: 5.2MB). Peak memory consumption was 4.2MB. Max. memory is 16.1GB. * Results from de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction: - StatisticsResult: ErrorAutomatonStatistics NumberErrorTraces: 0, NumberStatementsAllTraces: 0, NumberRelevantStatements: 0, 0.0s ErrorAutomatonConstructionTimeTotal, 0.0s FaulLocalizationTime, NumberStatementsFirstTrace: -1, TraceLengthAvg: 0, 0.0s ErrorAutomatonConstructionTimeAvg, 0.0s ErrorAutomatonDifferenceTimeAvg, 0.0s ErrorAutomatonDifferenceTimeTotal, NumberOfNoEnhancement: 0, NumberOfFiniteEnhancement: 0, NumberOfInfiniteEnhancement: 0 - PositiveResult [Line: 588]: call to reach_error is unreachable For all program executions holds that call to reach_error is unreachable at this location - StatisticsResult: Ultimate Automizer benchmark data CFG has 8 procedures, 94 locations, 1 error locations. Started 1 CEGAR loops. OverallTime: 10.8s, OverallIterations: 12, TraceHistogramMax: 3, PathProgramHistogramMax: 2, EmptinessCheckTime: 0.0s, AutomataDifference: 3.4s, DeadEndRemovalTime: 0.0s, HoareAnnotationTime: 3.7s, InitialAbstractionConstructionTime: 0.0s, HoareTripleCheckerStatistics: 0 mSolverCounterUnknown, 1917 SdHoareTripleChecker+Valid, 2.0s IncrementalHoareTripleChecker+Time, 0 mSdLazyCounter, 1899 mSDsluCounter, 4282 SdHoareTripleChecker+Invalid, 1.7s Time, 0 mProtectedAction, 0 SdHoareTripleChecker+Unchecked, 0 IncrementalHoareTripleChecker+Unchecked, 2947 mSDsCounter, 453 IncrementalHoareTripleChecker+Valid, 0 mProtectedPredicate, 1948 IncrementalHoareTripleChecker+Invalid, 2401 SdHoareTripleChecker+Unknown, 0 mSolverCounterNotChecked, 453 mSolverCounterUnsat, 1335 mSDtfsCounter, 1948 mSolverCounterSat, 0.0s SdHoareTripleChecker+Time, 0 IncrementalHoareTripleChecker+Unknown, PredicateUnifierStatistics: 0 DeclaredPredicates, 477 GetRequests, 355 SyntacticMatches, 7 SemanticMatches, 115 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 340 ImplicationChecksByTransitivity, 1.0s Time, 0.0s BasicInterpolantAutomatonTime, BiggestAbstraction: size=1505occurred in iteration=11, InterpolantAutomatonStates: 112, traceCheckStatistics: No data available, InterpolantConsolidationStatistics: No data available, PathInvariantsStatistics: No data available, 0/0 InterpolantCoveringCapability, TotalInterpolationStatistics: No data available, 0.0s DumpTime, AutomataMinimizationStatistics: 0.5s AutomataMinimizationTime, 12 MinimizatonAttempts, 503 StatesRemovedByMinimization, 8 NontrivialMinimizations, HoareAnnotationStatistics: 0.0s HoareAnnotationTime, 45 LocationsWithAnnotation, 2691 PreInvPairs, 3001 NumberOfFragments, 1108 HoareAnnotationTreeSize, 2691 FomulaSimplifications, 4094 FormulaSimplificationTreeSizeReduction, 0.9s HoareSimplificationTime, 45 FomulaSimplificationsInter, 23822 FormulaSimplificationTreeSizeReductionInter, 2.7s HoareSimplificationTimeInter, RefinementEngineStatistics: TRACE_CHECK: 0.1s SsaConstructionTime, 0.4s SatisfiabilityAnalysisTime, 1.8s InterpolantComputationTime, 810 NumberOfCodeBlocks, 810 NumberOfCodeBlocksAsserted, 15 NumberOfCheckSat, 877 ConstructedInterpolants, 0 QuantifiedInterpolants, 1678 SizeOfPredicates, 8 NumberOfNonLiveVariables, 990 ConjunctsInSsa, 18 ConjunctsInUnsatCore, 15 InterpolantComputations, 11 PerfectInterpolantSequences, 264/294 InterpolantCoveringCapability, INVARIANT_SYNTHESIS: No data available, INTERPOLANT_CONSOLIDATION: No data available, ABSTRACT_INTERPRETATION: No data available, PDR: No data available, ACCELERATED_INTERPOLATION: No data available, SIFA: No data available, ReuseStatistics: No data available - AllSpecificationsHoldResult: All specifications hold 1 specifications checked. All of them hold - InvariantResult [Line: 840]: Loop Invariant Derived loop invariant: 1 - InvariantResult [Line: 584]: Loop Invariant Derived loop invariant: (!(\old(pumpRunning) == 0) || !(1 <= \old(waterLevel))) && (0 == systemActive || !(2 <= \old(waterLevel))) - InvariantResult [Line: 90]: Loop Invariant Derived loop invariant: 1 - InvariantResult [Line: 558]: Loop Invariant Derived loop invariant: ((((((!(\old(pumpRunning) == 0) || (pumpRunning == 0 && \old(waterLevel) == waterLevel)) || ((((2 <= waterLevel && \old(waterLevel) == waterLevel) && 2 <= \result) && 2 <= tmp) && !(0 == systemActive))) || !(1 <= \old(waterLevel))) && ((!(\old(pumpRunning) == 0) || !(\old(waterLevel) == 1)) || (tmp == 1 && \result == 1))) && ((!(\old(pumpRunning) == 0) || (1 <= \result && 1 <= tmp)) || !(2 <= \old(waterLevel)))) && (((((((((pumpRunning == 0 && 1 <= \result) && 1 <= tmp) && 1 <= waterLevel) && 1 <= \result) && 1 <= tmp) && 1 <= tmp___0) || ((2 <= waterLevel && 2 <= \result) && 2 <= tmp)) || 0 == systemActive) || !(2 <= \old(waterLevel)))) && (((!(\old(pumpRunning) == 0) || ((((2 <= waterLevel && \old(waterLevel) == waterLevel) && 2 <= \result) && 2 <= tmp) && !(0 == systemActive))) || 0 == systemActive) || !(2 <= \old(waterLevel))) - InvariantResult [Line: 688]: Loop Invariant Derived loop invariant: (!(waterLevel == 1) || !(\old(pumpRunning) == 0)) || 0 == systemActive - InvariantResult [Line: 663]: Loop Invariant Derived loop invariant: (((!(\old(pumpRunning) == 0) || !(1 <= \old(waterLevel))) || ((pumpRunning == 0 && \old(waterLevel) == waterLevel) && !(0 == systemActive))) || ((2 <= waterLevel && \old(waterLevel) == waterLevel) && !(0 == systemActive))) && (((((((pumpRunning == 0 && 1 <= \result) && 1 <= tmp) && 1 <= waterLevel) && 1 <= tmp___0) || 2 <= waterLevel) || 0 == systemActive) || !(2 <= \old(waterLevel))) - InvariantResult [Line: 850]: Loop Invariant Derived loop invariant: ((((pumpRunning == 0 && \result == 1) && tmp == 1) && splverifierCounter == 0) && 1 <= waterLevel) || ((((\result == 1 && tmp == 1) && 2 <= waterLevel) && splverifierCounter == 0) && !(0 == systemActive)) - InvariantResult [Line: 988]: Loop Invariant Derived loop invariant: (((!(\old(pumpRunning) == 0) || !(1 <= waterLevel)) || (pumpRunning == 0 && !(\result == 0))) || (pumpRunning == 0 && 2 <= waterLevel)) || 0 == systemActive - InvariantResult [Line: 697]: Loop Invariant Derived loop invariant: ((!(\old(pumpRunning) == 0) || !(1 <= waterLevel)) || 2 <= waterLevel) || 0 == systemActive - InvariantResult [Line: 831]: Loop Invariant Derived loop invariant: ((((\result == 1 && tmp == 1) && 2 <= waterLevel) && 1 == systemActive) && splverifierCounter == 0) || (((((pumpRunning == 0 && \result == 1) && tmp == 1) && 1 == systemActive) && splverifierCounter == 0) && waterLevel == 1) - InvariantResult [Line: 733]: Loop Invariant Derived loop invariant: (!(\old(pumpRunning) == 0) || !(1 <= \old(waterLevel))) && (0 == systemActive || !(2 <= \old(waterLevel))) - InvariantResult [Line: 147]: Loop Invariant Derived loop invariant: (((pumpRunning == 0 && tmp == 1) && 1 == systemActive) && \result == systemActive) && waterLevel == 1 - InvariantResult [Line: 1002]: Loop Invariant Derived loop invariant: (!(\old(pumpRunning) == 0) || !(1 <= \old(waterLevel))) && ((((pumpRunning == \old(pumpRunning) && \result == 0) && 1 <= waterLevel) || 0 == systemActive) || !(2 <= \old(waterLevel))) - InvariantResult [Line: 165]: Loop Invariant Derived loop invariant: 1 - InvariantResult [Line: 911]: Loop Invariant Derived loop invariant: (!(\old(pumpRunning) == 0) || !(1 <= \old(waterLevel))) && (((pumpRunning == \old(pumpRunning) && 1 <= waterLevel) || 0 == systemActive) || !(2 <= \old(waterLevel))) - InvariantResult [Line: 100]: Loop Invariant Derived loop invariant: 1 - InvariantResult [Line: 722]: Loop Invariant Derived loop invariant: (((!(\old(pumpRunning) == 0) || pumpRunning == 0) || !(2 <= waterLevel)) || 0 == systemActive) && ((!(waterLevel == 1) || !(\old(pumpRunning) == 0)) || 0 == systemActive) - InvariantResult [Line: 849]: Loop Invariant Derived loop invariant: 0 - InvariantResult [Line: 947]: Loop Invariant Derived loop invariant: (((!(\old(pumpRunning) == 0) || pumpRunning == 0) || !(2 <= waterLevel)) || 0 == systemActive) && ((!(waterLevel == 1) || !(\old(pumpRunning) == 0)) || 0 == systemActive) - InvariantResult [Line: 797]: Loop Invariant Derived loop invariant: (!(\old(pumpRunning) == 0) || !(1 <= \old(waterLevel))) && (((((((pumpRunning == \old(pumpRunning) && \result == 0) && 1 <= \result) && tmp == 0) && 1 <= waterLevel) && 1 <= tmp___0) || 0 == systemActive) || !(2 <= \old(waterLevel))) - InvariantResult [Line: 816]: Loop Invariant Derived loop invariant: (((pumpRunning == 0 && \result == 1) && tmp == 1) && splverifierCounter == 0) && 1 <= waterLevel - InvariantResult [Line: 78]: Loop Invariant Derived loop invariant: ((pumpRunning == 0 && 1 == systemActive) && \result == systemActive) && waterLevel == 1 - InvariantResult [Line: 64]: Loop Invariant Derived loop invariant: (pumpRunning == 0 && 1 == systemActive) && waterLevel == 1 - InvariantResult [Line: 71]: Loop Invariant Derived loop invariant: (pumpRunning == 0 && 1 == systemActive) && waterLevel == 1 - InvariantResult [Line: 979]: Loop Invariant Derived loop invariant: ((((((!(\old(pumpRunning) == 0) || (((2 <= waterLevel && \old(waterLevel) == waterLevel) && 2 <= \result) && !(0 == systemActive))) || 0 == systemActive) || !(2 <= \old(waterLevel))) && ((!(\old(pumpRunning) == 0) || 1 <= \result) || !(2 <= \old(waterLevel)))) && (((!(\old(pumpRunning) == 0) || (pumpRunning == 0 && \old(waterLevel) == waterLevel)) || (((2 <= waterLevel && \old(waterLevel) == waterLevel) && 2 <= \result) && !(0 == systemActive))) || !(1 <= \old(waterLevel)))) && ((((2 <= waterLevel && 2 <= \result) || (((((pumpRunning == 0 && 1 <= \result) && 1 <= tmp) && 1 <= waterLevel) && 1 <= \result) && 1 <= tmp___0)) || 0 == systemActive) || !(2 <= \old(waterLevel)))) && ((!(\old(pumpRunning) == 0) || !(\old(waterLevel) == 1)) || \result == 1) - InvariantResult [Line: 778]: Loop Invariant Derived loop invariant: (((!(\old(pumpRunning) == 0) || pumpRunning == 0) || !(2 <= waterLevel)) || 0 == systemActive) && (((!(waterLevel == 1) || !(\old(pumpRunning) == 0)) || ((((!(tmp == 0) && pumpRunning == 0) && tmp___0 == 0) && !(\result == 0)) && \result == 0)) || 0 == systemActive) - InvariantResult [Line: 155]: Loop Invariant Derived loop invariant: 1 RESULT: Ultimate proved your program to be correct! [2022-07-13 18:00:28,996 INFO L540 MonitoredProcess]: [MP /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in -t:2000 (1)] Forceful destruction successful, exit code 0 Received shutdown request... --- End real Ultimate output --- Execution finished normally Writing output log to file Ultimate.log Result: TRUE