./Ultimate.py --spec ../sv-benchmarks/c/properties/unreach-call.prp --file ../sv-benchmarks/c/product-lines/minepump_spec1_product59.cil.c --full-output --architecture 32bit -------------------------------------------------------------------------------- Checking for ERROR reachability Using default analysis Version c3fed411 Calling Ultimate with: /usr/bin/java -Dosgi.configuration.area=/storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/data/config -Xmx15G -Xms4m -jar /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/plugins/org.eclipse.equinox.launcher_1.5.800.v20200727-1323.jar -data @noDefault -ultimatedata /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/data -tc /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/config/AutomizerReach.xml -i ../sv-benchmarks/c/product-lines/minepump_spec1_product59.cil.c -s /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/config/svcomp-Reach-32bit-Automizer_Default.epf --cacsl2boogietranslator.entry.function main --witnessprinter.witness.directory /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux --witnessprinter.witness.filename witness.graphml --witnessprinter.write.witness.besides.input.file false --witnessprinter.graph.data.specification CHECK( init(main()), LTL(G ! call(reach_error())) ) --witnessprinter.graph.data.producer Automizer --witnessprinter.graph.data.architecture 32bit --witnessprinter.graph.data.programhash 5a0a9a5f1521df25ea0ff390c35c7186e45318cd30c225704d83030e156744fb --- Real Ultimate output --- This is Ultimate 0.2.2-tmp.no-commuhash-c3fed41 [2021-12-16 00:58:41,874 INFO L177 SettingsManager]: Resetting all preferences to default values... [2021-12-16 00:58:41,876 INFO L181 SettingsManager]: Resetting UltimateCore preferences to default values [2021-12-16 00:58:41,938 INFO L184 SettingsManager]: Ultimate Commandline Interface provides no preferences, ignoring... [2021-12-16 00:58:41,939 INFO L181 SettingsManager]: Resetting Boogie Preprocessor preferences to default values [2021-12-16 00:58:41,941 INFO L181 SettingsManager]: Resetting Boogie Procedure Inliner preferences to default values [2021-12-16 00:58:41,942 INFO L181 SettingsManager]: Resetting Abstract Interpretation preferences to default values [2021-12-16 00:58:41,944 INFO L181 SettingsManager]: Resetting LassoRanker preferences to default values [2021-12-16 00:58:41,946 INFO L181 SettingsManager]: Resetting Reaching Definitions preferences to default values [2021-12-16 00:58:41,951 INFO L181 SettingsManager]: Resetting SyntaxChecker preferences to default values [2021-12-16 00:58:41,952 INFO L181 SettingsManager]: Resetting Sifa preferences to default values [2021-12-16 00:58:41,953 INFO L184 SettingsManager]: Büchi Program Product provides no preferences, ignoring... [2021-12-16 00:58:41,954 INFO L181 SettingsManager]: Resetting LTL2Aut preferences to default values [2021-12-16 00:58:41,956 INFO L181 SettingsManager]: Resetting PEA to Boogie preferences to default values [2021-12-16 00:58:41,958 INFO L181 SettingsManager]: Resetting BlockEncodingV2 preferences to default values [2021-12-16 00:58:41,959 INFO L181 SettingsManager]: Resetting ChcToBoogie preferences to default values [2021-12-16 00:58:41,960 INFO L181 SettingsManager]: Resetting AutomataScriptInterpreter preferences to default values [2021-12-16 00:58:41,961 INFO L181 SettingsManager]: Resetting BuchiAutomizer preferences to default values [2021-12-16 00:58:41,964 INFO L181 SettingsManager]: Resetting CACSL2BoogieTranslator preferences to default values [2021-12-16 00:58:41,970 INFO L181 SettingsManager]: Resetting CodeCheck preferences to default values [2021-12-16 00:58:41,974 INFO L181 SettingsManager]: Resetting InvariantSynthesis preferences to default values [2021-12-16 00:58:41,975 INFO L181 SettingsManager]: Resetting RCFGBuilder preferences to default values [2021-12-16 00:58:41,976 INFO L181 SettingsManager]: Resetting Referee preferences to default values [2021-12-16 00:58:41,977 INFO L181 SettingsManager]: Resetting TraceAbstraction preferences to default values [2021-12-16 00:58:41,980 INFO L184 SettingsManager]: TraceAbstractionConcurrent provides no preferences, ignoring... [2021-12-16 00:58:41,981 INFO L184 SettingsManager]: TraceAbstractionWithAFAs provides no preferences, ignoring... [2021-12-16 00:58:41,981 INFO L181 SettingsManager]: Resetting TreeAutomizer preferences to default values [2021-12-16 00:58:41,982 INFO L181 SettingsManager]: Resetting IcfgToChc preferences to default values [2021-12-16 00:58:41,983 INFO L181 SettingsManager]: Resetting IcfgTransformer preferences to default values [2021-12-16 00:58:41,984 INFO L184 SettingsManager]: ReqToTest provides no preferences, ignoring... [2021-12-16 00:58:41,984 INFO L181 SettingsManager]: Resetting Boogie Printer preferences to default values [2021-12-16 00:58:41,985 INFO L181 SettingsManager]: Resetting ChcSmtPrinter preferences to default values [2021-12-16 00:58:41,986 INFO L181 SettingsManager]: Resetting ReqPrinter preferences to default values [2021-12-16 00:58:41,987 INFO L181 SettingsManager]: Resetting Witness Printer preferences to default values [2021-12-16 00:58:41,988 INFO L184 SettingsManager]: Boogie PL CUP Parser provides no preferences, ignoring... [2021-12-16 00:58:41,988 INFO L181 SettingsManager]: Resetting CDTParser preferences to default values [2021-12-16 00:58:41,989 INFO L184 SettingsManager]: AutomataScriptParser provides no preferences, ignoring... [2021-12-16 00:58:41,989 INFO L184 SettingsManager]: ReqParser provides no preferences, ignoring... [2021-12-16 00:58:41,989 INFO L181 SettingsManager]: Resetting SmtParser preferences to default values [2021-12-16 00:58:41,990 INFO L181 SettingsManager]: Resetting Witness Parser preferences to default values [2021-12-16 00:58:41,991 INFO L188 SettingsManager]: Finished resetting all preferences to default values... [2021-12-16 00:58:41,992 INFO L101 SettingsManager]: Beginning loading settings from /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/config/svcomp-Reach-32bit-Automizer_Default.epf [2021-12-16 00:58:42,023 INFO L113 SettingsManager]: Loading preferences was successful [2021-12-16 00:58:42,024 INFO L115 SettingsManager]: Preferences different from defaults after loading the file: [2021-12-16 00:58:42,024 INFO L136 SettingsManager]: Preferences of UltimateCore differ from their defaults: [2021-12-16 00:58:42,024 INFO L138 SettingsManager]: * Log level for class=de.uni_freiburg.informatik.ultimate.lib.smtlibutils.quantifier.QuantifierPusher=ERROR; [2021-12-16 00:58:42,025 INFO L136 SettingsManager]: Preferences of Boogie Procedure Inliner differ from their defaults: [2021-12-16 00:58:42,025 INFO L138 SettingsManager]: * Ignore calls to procedures called more than once=ONLY_FOR_SEQUENTIAL_PROGRAMS [2021-12-16 00:58:42,026 INFO L136 SettingsManager]: Preferences of BlockEncodingV2 differ from their defaults: [2021-12-16 00:58:42,026 INFO L138 SettingsManager]: * Create parallel compositions if possible=false [2021-12-16 00:58:42,026 INFO L138 SettingsManager]: * Use SBE=true [2021-12-16 00:58:42,027 INFO L136 SettingsManager]: Preferences of CACSL2BoogieTranslator differ from their defaults: [2021-12-16 00:58:42,027 INFO L138 SettingsManager]: * sizeof long=4 [2021-12-16 00:58:42,028 INFO L138 SettingsManager]: * Overapproximate operations on floating types=true [2021-12-16 00:58:42,028 INFO L138 SettingsManager]: * sizeof POINTER=4 [2021-12-16 00:58:42,028 INFO L138 SettingsManager]: * Check division by zero=IGNORE [2021-12-16 00:58:42,028 INFO L138 SettingsManager]: * Pointer to allocated memory at dereference=IGNORE [2021-12-16 00:58:42,028 INFO L138 SettingsManager]: * If two pointers are subtracted or compared they have the same base address=IGNORE [2021-12-16 00:58:42,029 INFO L138 SettingsManager]: * Check array bounds for arrays that are off heap=IGNORE [2021-12-16 00:58:42,029 INFO L138 SettingsManager]: * sizeof long double=12 [2021-12-16 00:58:42,029 INFO L138 SettingsManager]: * Check if freed pointer was valid=false [2021-12-16 00:58:42,029 INFO L138 SettingsManager]: * Use constant arrays=true [2021-12-16 00:58:42,029 INFO L138 SettingsManager]: * Pointer base address is valid at dereference=IGNORE [2021-12-16 00:58:42,030 INFO L136 SettingsManager]: Preferences of RCFGBuilder differ from their defaults: [2021-12-16 00:58:42,030 INFO L138 SettingsManager]: * Size of a code block=SequenceOfStatements [2021-12-16 00:58:42,030 INFO L138 SettingsManager]: * SMT solver=External_DefaultMode [2021-12-16 00:58:42,030 INFO L138 SettingsManager]: * Command for external solver=z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in -t:2000 [2021-12-16 00:58:42,030 INFO L136 SettingsManager]: Preferences of TraceAbstraction differ from their defaults: [2021-12-16 00:58:42,031 INFO L138 SettingsManager]: * Compute Interpolants along a Counterexample=FPandBP [2021-12-16 00:58:42,031 INFO L138 SettingsManager]: * Positions where we compute the Hoare Annotation=LoopsAndPotentialCycles [2021-12-16 00:58:42,031 INFO L138 SettingsManager]: * Trace refinement strategy=CAMEL [2021-12-16 00:58:42,031 INFO L138 SettingsManager]: * Command for external solver=z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in [2021-12-16 00:58:42,031 INFO L138 SettingsManager]: * Large block encoding in concurrent analysis=OFF [2021-12-16 00:58:42,032 INFO L138 SettingsManager]: * Automaton type used in concurrency analysis=PETRI_NET [2021-12-16 00:58:42,032 INFO L138 SettingsManager]: * Compute Hoare Annotation of negated interpolant automaton, abstraction and CFG=true [2021-12-16 00:58:42,032 INFO L138 SettingsManager]: * Trace refinement exception blacklist=NONE [2021-12-16 00:58:42,032 INFO L138 SettingsManager]: * SMT solver=External_ModelsAndUnsatCoreMode WARNING: An illegal reflective access operation has occurred WARNING: Illegal reflective access by com.sun.xml.bind.v2.runtime.reflect.opt.Injector$1 (file:/storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/plugins/com.sun.xml.bind_2.2.0.v201505121915.jar) to method java.lang.ClassLoader.defineClass(java.lang.String,byte[],int,int) WARNING: Please consider reporting this to the maintainers of com.sun.xml.bind.v2.runtime.reflect.opt.Injector$1 WARNING: Use --illegal-access=warn to enable warnings of further illegal reflective access operations WARNING: All illegal access operations will be denied in a future release Applying setting for plugin de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator: Entry function -> main Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Witness directory -> /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Witness filename -> witness.graphml Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Write witness besides input file -> false Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Graph data specification -> CHECK( init(main()), LTL(G ! call(reach_error())) ) Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Graph data producer -> Automizer Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Graph data architecture -> 32bit Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Graph data programhash -> 5a0a9a5f1521df25ea0ff390c35c7186e45318cd30c225704d83030e156744fb [2021-12-16 00:58:42,282 INFO L75 nceAwareModelManager]: Repository-Root is: /tmp [2021-12-16 00:58:42,308 INFO L261 ainManager$Toolchain]: [Toolchain 1]: Applicable parser(s) successfully (re)initialized [2021-12-16 00:58:42,310 INFO L217 ainManager$Toolchain]: [Toolchain 1]: Toolchain selected. [2021-12-16 00:58:42,311 INFO L271 PluginConnector]: Initializing CDTParser... [2021-12-16 00:58:42,312 INFO L275 PluginConnector]: CDTParser initialized [2021-12-16 00:58:42,313 INFO L432 ainManager$Toolchain]: [Toolchain 1]: Parsing single file: /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/../sv-benchmarks/c/product-lines/minepump_spec1_product59.cil.c [2021-12-16 00:58:42,378 INFO L220 CDTParser]: Created temporary CDT project at /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/data/8510356c3/b1d922b09035474ba33979bc5ac6f385/FLAG14e0b5180 [2021-12-16 00:58:42,844 INFO L306 CDTParser]: Found 1 translation units. [2021-12-16 00:58:42,845 INFO L160 CDTParser]: Scanning /storage/repos/ultimate/releaseScripts/default/sv-benchmarks/c/product-lines/minepump_spec1_product59.cil.c [2021-12-16 00:58:42,857 INFO L349 CDTParser]: About to delete temporary CDT project at /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/data/8510356c3/b1d922b09035474ba33979bc5ac6f385/FLAG14e0b5180 [2021-12-16 00:58:43,342 INFO L357 CDTParser]: Successfully deleted /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/data/8510356c3/b1d922b09035474ba33979bc5ac6f385 [2021-12-16 00:58:43,344 INFO L299 ainManager$Toolchain]: ####################### [Toolchain 1] ####################### [2021-12-16 00:58:43,345 INFO L131 ToolchainWalker]: Walking toolchain with 6 elements. [2021-12-16 00:58:43,353 INFO L113 PluginConnector]: ------------------------CACSL2BoogieTranslator---------------------------- [2021-12-16 00:58:43,353 INFO L271 PluginConnector]: Initializing CACSL2BoogieTranslator... [2021-12-16 00:58:43,356 INFO L275 PluginConnector]: CACSL2BoogieTranslator initialized [2021-12-16 00:58:43,357 INFO L185 PluginConnector]: Executing the observer ACSLObjectContainerObserver from plugin CACSL2BoogieTranslator for "CDTParser AST 16.12 12:58:43" (1/1) ... [2021-12-16 00:58:43,358 INFO L205 PluginConnector]: Invalid model from CACSL2BoogieTranslator for observer de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator.ACSLObjectContainerObserver@74b4ef7f and model type de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 16.12 12:58:43, skipping insertion in model container [2021-12-16 00:58:43,358 INFO L185 PluginConnector]: Executing the observer CACSL2BoogieTranslatorObserver from plugin CACSL2BoogieTranslator for "CDTParser AST 16.12 12:58:43" (1/1) ... [2021-12-16 00:58:43,365 INFO L145 MainTranslator]: Starting translation in SV-COMP mode [2021-12-16 00:58:43,401 INFO L178 MainTranslator]: Built tables and reachable declarations [2021-12-16 00:58:43,567 WARN L230 ndardFunctionHandler]: Function reach_error is already implemented but we override the implementation for the call at /storage/repos/ultimate/releaseScripts/default/sv-benchmarks/c/product-lines/minepump_spec1_product59.cil.c[3645,3658] [2021-12-16 00:58:43,661 INFO L209 PostProcessor]: Analyzing one entry point: main [2021-12-16 00:58:43,672 INFO L203 MainTranslator]: Completed pre-run [2021-12-16 00:58:43,702 WARN L230 ndardFunctionHandler]: Function reach_error is already implemented but we override the implementation for the call at /storage/repos/ultimate/releaseScripts/default/sv-benchmarks/c/product-lines/minepump_spec1_product59.cil.c[3645,3658] [2021-12-16 00:58:43,759 INFO L209 PostProcessor]: Analyzing one entry point: main [2021-12-16 00:58:43,773 INFO L208 MainTranslator]: Completed translation [2021-12-16 00:58:43,774 INFO L202 PluginConnector]: Adding new model de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 16.12 12:58:43 WrapperNode [2021-12-16 00:58:43,774 INFO L132 PluginConnector]: ------------------------ END CACSL2BoogieTranslator---------------------------- [2021-12-16 00:58:43,775 INFO L113 PluginConnector]: ------------------------Boogie Procedure Inliner---------------------------- [2021-12-16 00:58:43,775 INFO L271 PluginConnector]: Initializing Boogie Procedure Inliner... [2021-12-16 00:58:43,776 INFO L275 PluginConnector]: Boogie Procedure Inliner initialized [2021-12-16 00:58:43,782 INFO L185 PluginConnector]: Executing the observer TypeChecker from plugin Boogie Procedure Inliner for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 16.12 12:58:43" (1/1) ... [2021-12-16 00:58:43,795 INFO L185 PluginConnector]: Executing the observer Inliner from plugin Boogie Procedure Inliner for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 16.12 12:58:43" (1/1) ... [2021-12-16 00:58:43,841 INFO L137 Inliner]: procedures = 57, calls = 158, calls flagged for inlining = 24, calls inlined = 21, statements flattened = 271 [2021-12-16 00:58:43,842 INFO L132 PluginConnector]: ------------------------ END Boogie Procedure Inliner---------------------------- [2021-12-16 00:58:43,842 INFO L113 PluginConnector]: ------------------------Boogie Preprocessor---------------------------- [2021-12-16 00:58:43,842 INFO L271 PluginConnector]: Initializing Boogie Preprocessor... [2021-12-16 00:58:43,843 INFO L275 PluginConnector]: Boogie Preprocessor initialized [2021-12-16 00:58:43,850 INFO L185 PluginConnector]: Executing the observer EnsureBoogieModelObserver from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 16.12 12:58:43" (1/1) ... [2021-12-16 00:58:43,850 INFO L185 PluginConnector]: Executing the observer TypeChecker from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 16.12 12:58:43" (1/1) ... [2021-12-16 00:58:43,862 INFO L185 PluginConnector]: Executing the observer ConstExpander from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 16.12 12:58:43" (1/1) ... [2021-12-16 00:58:43,862 INFO L185 PluginConnector]: Executing the observer StructExpander from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 16.12 12:58:43" (1/1) ... [2021-12-16 00:58:43,873 INFO L185 PluginConnector]: Executing the observer UnstructureCode from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 16.12 12:58:43" (1/1) ... [2021-12-16 00:58:43,882 INFO L185 PluginConnector]: Executing the observer FunctionInliner from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 16.12 12:58:43" (1/1) ... [2021-12-16 00:58:43,895 INFO L185 PluginConnector]: Executing the observer BoogieSymbolTableConstructor from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 16.12 12:58:43" (1/1) ... [2021-12-16 00:58:43,897 INFO L132 PluginConnector]: ------------------------ END Boogie Preprocessor---------------------------- [2021-12-16 00:58:43,898 INFO L113 PluginConnector]: ------------------------RCFGBuilder---------------------------- [2021-12-16 00:58:43,898 INFO L271 PluginConnector]: Initializing RCFGBuilder... [2021-12-16 00:58:43,898 INFO L275 PluginConnector]: RCFGBuilder initialized [2021-12-16 00:58:43,899 INFO L185 PluginConnector]: Executing the observer RCFGBuilderObserver from plugin RCFGBuilder for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 16.12 12:58:43" (1/1) ... [2021-12-16 00:58:43,909 INFO L168 SolverBuilder]: Constructing external solver with command: z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in -t:2000 [2021-12-16 00:58:43,919 INFO L189 MonitoredProcess]: No working directory specified, using /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 [2021-12-16 00:58:43,932 INFO L229 MonitoredProcess]: Starting monitored process 1 with /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in -t:2000 (exit command is (exit), workingDir is null) [2021-12-16 00:58:43,937 INFO L327 MonitoredProcess]: [MP /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in -t:2000 (1)] Waiting until timeout for monitored process [2021-12-16 00:58:43,967 INFO L130 BoogieDeclarations]: Found specification of procedure #Ultimate.allocInit [2021-12-16 00:58:43,967 INFO L130 BoogieDeclarations]: Found specification of procedure processEnvironment__wrappee__base [2021-12-16 00:58:43,967 INFO L138 BoogieDeclarations]: Found implementation of procedure processEnvironment__wrappee__base [2021-12-16 00:58:43,967 INFO L130 BoogieDeclarations]: Found specification of procedure cleanup [2021-12-16 00:58:43,968 INFO L138 BoogieDeclarations]: Found implementation of procedure cleanup [2021-12-16 00:58:43,968 INFO L130 BoogieDeclarations]: Found specification of procedure timeShift [2021-12-16 00:58:43,968 INFO L138 BoogieDeclarations]: Found implementation of procedure timeShift [2021-12-16 00:58:43,969 INFO L130 BoogieDeclarations]: Found specification of procedure isMethaneLevelCritical [2021-12-16 00:58:43,970 INFO L138 BoogieDeclarations]: Found implementation of procedure isMethaneLevelCritical [2021-12-16 00:58:43,970 INFO L130 BoogieDeclarations]: Found specification of procedure processEnvironment__wrappee__highWaterSensor [2021-12-16 00:58:43,970 INFO L138 BoogieDeclarations]: Found implementation of procedure processEnvironment__wrappee__highWaterSensor [2021-12-16 00:58:43,970 INFO L130 BoogieDeclarations]: Found specification of procedure waterRise [2021-12-16 00:58:43,970 INFO L138 BoogieDeclarations]: Found implementation of procedure waterRise [2021-12-16 00:58:43,970 INFO L130 BoogieDeclarations]: Found specification of procedure deactivatePump [2021-12-16 00:58:43,970 INFO L138 BoogieDeclarations]: Found implementation of procedure deactivatePump [2021-12-16 00:58:43,971 INFO L130 BoogieDeclarations]: Found specification of procedure write~init~int [2021-12-16 00:58:43,971 INFO L130 BoogieDeclarations]: Found specification of procedure changeMethaneLevel [2021-12-16 00:58:43,971 INFO L138 BoogieDeclarations]: Found implementation of procedure changeMethaneLevel [2021-12-16 00:58:43,971 INFO L130 BoogieDeclarations]: Found specification of procedure ULTIMATE.start [2021-12-16 00:58:43,971 INFO L138 BoogieDeclarations]: Found implementation of procedure ULTIMATE.start [2021-12-16 00:58:44,064 INFO L236 CfgBuilder]: Building ICFG [2021-12-16 00:58:44,066 INFO L262 CfgBuilder]: Building CFG for each procedure with an implementation [2021-12-16 00:58:44,345 INFO L277 CfgBuilder]: Performing block encoding [2021-12-16 00:58:44,351 INFO L296 CfgBuilder]: Using the 1 location(s) as analysis (start of procedure ULTIMATE.start) [2021-12-16 00:58:44,351 INFO L301 CfgBuilder]: Removed 2 assume(true) statements. [2021-12-16 00:58:44,353 INFO L202 PluginConnector]: Adding new model de.uni_freiburg.informatik.ultimate.plugins.generator.rcfgbuilder CFG 16.12 12:58:44 BoogieIcfgContainer [2021-12-16 00:58:44,353 INFO L132 PluginConnector]: ------------------------ END RCFGBuilder---------------------------- [2021-12-16 00:58:44,354 INFO L113 PluginConnector]: ------------------------TraceAbstraction---------------------------- [2021-12-16 00:58:44,354 INFO L271 PluginConnector]: Initializing TraceAbstraction... [2021-12-16 00:58:44,357 INFO L275 PluginConnector]: TraceAbstraction initialized [2021-12-16 00:58:44,358 INFO L185 PluginConnector]: Executing the observer TraceAbstractionObserver from plugin TraceAbstraction for "CDTParser AST 16.12 12:58:43" (1/3) ... [2021-12-16 00:58:44,358 INFO L205 PluginConnector]: Invalid model from TraceAbstraction for observer de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction.TraceAbstractionObserver@1c3c3589 and model type de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction AST 16.12 12:58:44, skipping insertion in model container [2021-12-16 00:58:44,359 INFO L185 PluginConnector]: Executing the observer TraceAbstractionObserver from plugin TraceAbstraction for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 16.12 12:58:43" (2/3) ... [2021-12-16 00:58:44,363 INFO L205 PluginConnector]: Invalid model from TraceAbstraction for observer de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction.TraceAbstractionObserver@1c3c3589 and model type de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction AST 16.12 12:58:44, skipping insertion in model container [2021-12-16 00:58:44,363 INFO L185 PluginConnector]: Executing the observer TraceAbstractionObserver from plugin TraceAbstraction for "de.uni_freiburg.informatik.ultimate.plugins.generator.rcfgbuilder CFG 16.12 12:58:44" (3/3) ... [2021-12-16 00:58:44,365 INFO L111 eAbstractionObserver]: Analyzing ICFG minepump_spec1_product59.cil.c [2021-12-16 00:58:44,371 INFO L204 ceAbstractionStarter]: Automizer settings: Hoare:true NWA Interpolation:FPandBP Determinization: PREDICATE_ABSTRACTION [2021-12-16 00:58:44,371 INFO L163 ceAbstractionStarter]: Applying trace abstraction to program that has 1 error locations. [2021-12-16 00:58:44,418 INFO L338 AbstractCegarLoop]: ======== Iteration 0 == of CEGAR loop == AllErrorsAtOnce ======== [2021-12-16 00:58:44,425 INFO L339 AbstractCegarLoop]: Settings: SEPARATE_VIOLATION_CHECK=true, mInterprocedural=true, mMaxIterations=1000000, mWatchIteration=1000000, mArtifact=RCFG, mInterpolation=FPandBP, mInterpolantAutomaton=STRAIGHT_LINE, mDumpAutomata=false, mAutomataFormat=ATS_NUMERATE, mDumpPath=., mDeterminiation=PREDICATE_ABSTRACTION, mMinimize=MINIMIZE_SEVPA, mHoare=true, mAutomataTypeConcurrency=PETRI_NET, mHoareTripleChecks=INCREMENTAL, mHoareAnnotationPositions=LoopsAndPotentialCycles, mDumpOnlyReuseAutomata=false, mLimitTraceHistogram=0, mErrorLocTimeLimit=0, mLimitPathProgramCount=0, mCollectInterpolantStatistics=true, mHeuristicEmptinessCheck=false, mHeuristicEmptinessCheckAStarHeuristic=ZERO, mHeuristicEmptinessCheckAStarHeuristicRandomSeed=1337, mHeuristicEmptinessCheckSmtFeatureScoringMethod=DAGSIZE, mSMTFeatureExtraction=false, mSMTFeatureExtractionDumpPath=., mOverrideInterpolantAutomaton=false, mMcrInterpolantMethod=WP, mLoopAccelerationTechnique=FAST_UPR [2021-12-16 00:58:44,425 INFO L340 AbstractCegarLoop]: Starting to check reachability of 1 error locations. [2021-12-16 00:58:44,456 INFO L276 IsEmpty]: Start isEmpty. Operand has 98 states, 74 states have (on average 1.3783783783783783) internal successors, (102), 83 states have internal predecessors, (102), 14 states have call successors, (14), 8 states have call predecessors, (14), 8 states have return successors, (14), 11 states have call predecessors, (14), 14 states have call successors, (14) [2021-12-16 00:58:44,463 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 24 [2021-12-16 00:58:44,463 INFO L506 BasicCegarLoop]: Found error trace [2021-12-16 00:58:44,463 INFO L514 BasicCegarLoop]: trace histogram [1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2021-12-16 00:58:44,464 INFO L402 AbstractCegarLoop]: === Iteration 1 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2021-12-16 00:58:44,468 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2021-12-16 00:58:44,468 INFO L85 PathProgramCache]: Analyzing trace with hash 896796979, now seen corresponding path program 1 times [2021-12-16 00:58:44,475 INFO L121 FreeRefinementEngine]: Executing refinement strategy CAMEL [2021-12-16 00:58:44,476 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [1847102408] [2021-12-16 00:58:44,476 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2021-12-16 00:58:44,476 INFO L126 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2021-12-16 00:58:44,588 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 00:58:44,655 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 14 [2021-12-16 00:58:44,657 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 00:58:44,662 INFO L134 CoverageAnalysis]: Checked inductivity of 0 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2021-12-16 00:58:44,663 INFO L139 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2021-12-16 00:58:44,663 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [1847102408] [2021-12-16 00:58:44,664 INFO L160 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [1847102408] provided 1 perfect and 0 imperfect interpolant sequences [2021-12-16 00:58:44,664 INFO L186 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2021-12-16 00:58:44,664 INFO L199 FreeRefinementEngine]: Number of different interpolants: perfect sequences [2] imperfect sequences [] total 2 [2021-12-16 00:58:44,665 INFO L115 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [113336117] [2021-12-16 00:58:44,666 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2021-12-16 00:58:44,669 INFO L546 AbstractCegarLoop]: INTERPOLANT automaton has 2 states [2021-12-16 00:58:44,669 INFO L103 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2021-12-16 00:58:44,690 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 2 interpolants. [2021-12-16 00:58:44,690 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=1, Invalid=1, Unknown=0, NotChecked=0, Total=2 [2021-12-16 00:58:44,692 INFO L87 Difference]: Start difference. First operand has 98 states, 74 states have (on average 1.3783783783783783) internal successors, (102), 83 states have internal predecessors, (102), 14 states have call successors, (14), 8 states have call predecessors, (14), 8 states have return successors, (14), 11 states have call predecessors, (14), 14 states have call successors, (14) Second operand has 2 states, 2 states have (on average 9.5) internal successors, (19), 2 states have internal predecessors, (19), 1 states have call successors, (3), 2 states have call predecessors, (3), 1 states have return successors, (1), 1 states have call predecessors, (1), 1 states have call successors, (1) [2021-12-16 00:58:44,720 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2021-12-16 00:58:44,721 INFO L93 Difference]: Finished difference Result 188 states and 255 transitions. [2021-12-16 00:58:44,722 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 2 states. [2021-12-16 00:58:44,723 INFO L78 Accepts]: Start accepts. Automaton has has 2 states, 2 states have (on average 9.5) internal successors, (19), 2 states have internal predecessors, (19), 1 states have call successors, (3), 2 states have call predecessors, (3), 1 states have return successors, (1), 1 states have call predecessors, (1), 1 states have call successors, (1) Word has length 23 [2021-12-16 00:58:44,723 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2021-12-16 00:58:44,732 INFO L225 Difference]: With dead ends: 188 [2021-12-16 00:58:44,732 INFO L226 Difference]: Without dead ends: 89 [2021-12-16 00:58:44,736 INFO L932 BasicCegarLoop]: 0 DeclaredPredicates, 4 GetRequests, 4 SyntacticMatches, 0 SemanticMatches, 0 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 0 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=1, Invalid=1, Unknown=0, NotChecked=0, Total=2 [2021-12-16 00:58:44,741 INFO L933 BasicCegarLoop]: 124 mSDtfsCounter, 0 mSDsluCounter, 0 mSDsCounter, 0 mSdLazyCounter, 0 mSolverCounterSat, 0 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.0s Time, 0 mProtectedPredicate, 0 mProtectedAction, 0 SdHoareTripleChecker+Valid, 124 SdHoareTripleChecker+Invalid, 0 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 0 IncrementalHoareTripleChecker+Valid, 0 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.0s IncrementalHoareTripleChecker+Time [2021-12-16 00:58:44,742 INFO L934 BasicCegarLoop]: SdHoareTripleChecker [0 Valid, 124 Invalid, 0 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [0 Valid, 0 Invalid, 0 Unknown, 0 Unchecked, 0.0s Time] [2021-12-16 00:58:44,756 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 89 states. [2021-12-16 00:58:44,781 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 89 to 89. [2021-12-16 00:58:44,782 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 89 states, 67 states have (on average 1.3134328358208955) internal successors, (88), 75 states have internal predecessors, (88), 14 states have call successors, (14), 8 states have call predecessors, (14), 7 states have return successors, (13), 10 states have call predecessors, (13), 13 states have call successors, (13) [2021-12-16 00:58:44,785 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 89 states to 89 states and 115 transitions. [2021-12-16 00:58:44,786 INFO L78 Accepts]: Start accepts. Automaton has 89 states and 115 transitions. Word has length 23 [2021-12-16 00:58:44,786 INFO L84 Accepts]: Finished accepts. word is rejected. [2021-12-16 00:58:44,786 INFO L470 AbstractCegarLoop]: Abstraction has 89 states and 115 transitions. [2021-12-16 00:58:44,787 INFO L471 AbstractCegarLoop]: INTERPOLANT automaton has has 2 states, 2 states have (on average 9.5) internal successors, (19), 2 states have internal predecessors, (19), 1 states have call successors, (3), 2 states have call predecessors, (3), 1 states have return successors, (1), 1 states have call predecessors, (1), 1 states have call successors, (1) [2021-12-16 00:58:44,787 INFO L276 IsEmpty]: Start isEmpty. Operand 89 states and 115 transitions. [2021-12-16 00:58:44,789 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 25 [2021-12-16 00:58:44,790 INFO L506 BasicCegarLoop]: Found error trace [2021-12-16 00:58:44,790 INFO L514 BasicCegarLoop]: trace histogram [1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2021-12-16 00:58:44,790 WARN L452 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable0 [2021-12-16 00:58:44,790 INFO L402 AbstractCegarLoop]: === Iteration 2 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2021-12-16 00:58:44,792 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2021-12-16 00:58:44,793 INFO L85 PathProgramCache]: Analyzing trace with hash 1625202696, now seen corresponding path program 1 times [2021-12-16 00:58:44,793 INFO L121 FreeRefinementEngine]: Executing refinement strategy CAMEL [2021-12-16 00:58:44,793 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [857406920] [2021-12-16 00:58:44,793 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2021-12-16 00:58:44,794 INFO L126 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2021-12-16 00:58:44,834 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 00:58:44,871 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 15 [2021-12-16 00:58:44,873 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 00:58:44,877 INFO L134 CoverageAnalysis]: Checked inductivity of 0 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2021-12-16 00:58:44,877 INFO L139 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2021-12-16 00:58:44,878 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [857406920] [2021-12-16 00:58:44,879 INFO L160 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [857406920] provided 1 perfect and 0 imperfect interpolant sequences [2021-12-16 00:58:44,879 INFO L186 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2021-12-16 00:58:44,879 INFO L199 FreeRefinementEngine]: Number of different interpolants: perfect sequences [3] imperfect sequences [] total 3 [2021-12-16 00:58:44,879 INFO L115 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [112052571] [2021-12-16 00:58:44,880 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2021-12-16 00:58:44,881 INFO L546 AbstractCegarLoop]: INTERPOLANT automaton has 3 states [2021-12-16 00:58:44,882 INFO L103 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2021-12-16 00:58:44,884 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 3 interpolants. [2021-12-16 00:58:44,884 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=3, Invalid=3, Unknown=0, NotChecked=0, Total=6 [2021-12-16 00:58:44,884 INFO L87 Difference]: Start difference. First operand 89 states and 115 transitions. Second operand has 3 states, 3 states have (on average 6.666666666666667) internal successors, (20), 3 states have internal predecessors, (20), 1 states have call successors, (3), 2 states have call predecessors, (3), 1 states have return successors, (1), 1 states have call predecessors, (1), 1 states have call successors, (1) [2021-12-16 00:58:44,900 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2021-12-16 00:58:44,901 INFO L93 Difference]: Finished difference Result 140 states and 180 transitions. [2021-12-16 00:58:44,901 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 3 states. [2021-12-16 00:58:44,902 INFO L78 Accepts]: Start accepts. Automaton has has 3 states, 3 states have (on average 6.666666666666667) internal successors, (20), 3 states have internal predecessors, (20), 1 states have call successors, (3), 2 states have call predecessors, (3), 1 states have return successors, (1), 1 states have call predecessors, (1), 1 states have call successors, (1) Word has length 24 [2021-12-16 00:58:44,902 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2021-12-16 00:58:44,903 INFO L225 Difference]: With dead ends: 140 [2021-12-16 00:58:44,903 INFO L226 Difference]: Without dead ends: 80 [2021-12-16 00:58:44,904 INFO L932 BasicCegarLoop]: 0 DeclaredPredicates, 5 GetRequests, 4 SyntacticMatches, 0 SemanticMatches, 1 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 0 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=3, Invalid=3, Unknown=0, NotChecked=0, Total=6 [2021-12-16 00:58:44,905 INFO L933 BasicCegarLoop]: 102 mSDtfsCounter, 16 mSDsluCounter, 81 mSDsCounter, 0 mSdLazyCounter, 1 mSolverCounterSat, 0 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.0s Time, 0 mProtectedPredicate, 0 mProtectedAction, 20 SdHoareTripleChecker+Valid, 183 SdHoareTripleChecker+Invalid, 1 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 0 IncrementalHoareTripleChecker+Valid, 1 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.0s IncrementalHoareTripleChecker+Time [2021-12-16 00:58:44,906 INFO L934 BasicCegarLoop]: SdHoareTripleChecker [20 Valid, 183 Invalid, 1 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [0 Valid, 1 Invalid, 0 Unknown, 0 Unchecked, 0.0s Time] [2021-12-16 00:58:44,907 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 80 states. [2021-12-16 00:58:44,913 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 80 to 80. [2021-12-16 00:58:44,914 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 80 states, 61 states have (on average 1.3278688524590163) internal successors, (81), 69 states have internal predecessors, (81), 11 states have call successors, (11), 7 states have call predecessors, (11), 7 states have return successors, (11), 8 states have call predecessors, (11), 11 states have call successors, (11) [2021-12-16 00:58:44,915 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 80 states to 80 states and 103 transitions. [2021-12-16 00:58:44,915 INFO L78 Accepts]: Start accepts. Automaton has 80 states and 103 transitions. Word has length 24 [2021-12-16 00:58:44,916 INFO L84 Accepts]: Finished accepts. word is rejected. [2021-12-16 00:58:44,916 INFO L470 AbstractCegarLoop]: Abstraction has 80 states and 103 transitions. [2021-12-16 00:58:44,916 INFO L471 AbstractCegarLoop]: INTERPOLANT automaton has has 3 states, 3 states have (on average 6.666666666666667) internal successors, (20), 3 states have internal predecessors, (20), 1 states have call successors, (3), 2 states have call predecessors, (3), 1 states have return successors, (1), 1 states have call predecessors, (1), 1 states have call successors, (1) [2021-12-16 00:58:44,916 INFO L276 IsEmpty]: Start isEmpty. Operand 80 states and 103 transitions. [2021-12-16 00:58:44,917 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 29 [2021-12-16 00:58:44,917 INFO L506 BasicCegarLoop]: Found error trace [2021-12-16 00:58:44,918 INFO L514 BasicCegarLoop]: trace histogram [1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2021-12-16 00:58:44,918 WARN L452 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable1 [2021-12-16 00:58:44,918 INFO L402 AbstractCegarLoop]: === Iteration 3 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2021-12-16 00:58:44,918 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2021-12-16 00:58:44,919 INFO L85 PathProgramCache]: Analyzing trace with hash 2098135563, now seen corresponding path program 1 times [2021-12-16 00:58:44,919 INFO L121 FreeRefinementEngine]: Executing refinement strategy CAMEL [2021-12-16 00:58:44,919 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [1303000191] [2021-12-16 00:58:44,919 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2021-12-16 00:58:44,920 INFO L126 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2021-12-16 00:58:44,941 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 00:58:44,985 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 19 [2021-12-16 00:58:44,987 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 00:58:44,990 INFO L134 CoverageAnalysis]: Checked inductivity of 0 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2021-12-16 00:58:44,990 INFO L139 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2021-12-16 00:58:44,990 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [1303000191] [2021-12-16 00:58:44,991 INFO L160 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [1303000191] provided 1 perfect and 0 imperfect interpolant sequences [2021-12-16 00:58:44,991 INFO L186 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2021-12-16 00:58:44,991 INFO L199 FreeRefinementEngine]: Number of different interpolants: perfect sequences [6] imperfect sequences [] total 6 [2021-12-16 00:58:44,991 INFO L115 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [78396131] [2021-12-16 00:58:44,991 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2021-12-16 00:58:44,992 INFO L546 AbstractCegarLoop]: INTERPOLANT automaton has 6 states [2021-12-16 00:58:44,992 INFO L103 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2021-12-16 00:58:44,992 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 6 interpolants. [2021-12-16 00:58:44,993 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=10, Invalid=20, Unknown=0, NotChecked=0, Total=30 [2021-12-16 00:58:44,993 INFO L87 Difference]: Start difference. First operand 80 states and 103 transitions. Second operand has 6 states, 6 states have (on average 4.166666666666667) internal successors, (25), 6 states have internal predecessors, (25), 2 states have call successors, (2), 2 states have call predecessors, (2), 1 states have return successors, (1), 1 states have call predecessors, (1), 1 states have call successors, (1) [2021-12-16 00:58:45,242 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2021-12-16 00:58:45,242 INFO L93 Difference]: Finished difference Result 267 states and 350 transitions. [2021-12-16 00:58:45,242 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 6 states. [2021-12-16 00:58:45,243 INFO L78 Accepts]: Start accepts. Automaton has has 6 states, 6 states have (on average 4.166666666666667) internal successors, (25), 6 states have internal predecessors, (25), 2 states have call successors, (2), 2 states have call predecessors, (2), 1 states have return successors, (1), 1 states have call predecessors, (1), 1 states have call successors, (1) Word has length 28 [2021-12-16 00:58:45,243 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2021-12-16 00:58:45,245 INFO L225 Difference]: With dead ends: 267 [2021-12-16 00:58:45,245 INFO L226 Difference]: Without dead ends: 194 [2021-12-16 00:58:45,246 INFO L932 BasicCegarLoop]: 0 DeclaredPredicates, 9 GetRequests, 3 SyntacticMatches, 0 SemanticMatches, 6 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 0 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=22, Invalid=34, Unknown=0, NotChecked=0, Total=56 [2021-12-16 00:58:45,247 INFO L933 BasicCegarLoop]: 126 mSDtfsCounter, 277 mSDsluCounter, 333 mSDsCounter, 0 mSdLazyCounter, 103 mSolverCounterSat, 35 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.1s Time, 0 mProtectedPredicate, 0 mProtectedAction, 277 SdHoareTripleChecker+Valid, 459 SdHoareTripleChecker+Invalid, 138 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 35 IncrementalHoareTripleChecker+Valid, 103 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.2s IncrementalHoareTripleChecker+Time [2021-12-16 00:58:45,247 INFO L934 BasicCegarLoop]: SdHoareTripleChecker [277 Valid, 459 Invalid, 138 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [35 Valid, 103 Invalid, 0 Unknown, 0 Unchecked, 0.2s Time] [2021-12-16 00:58:45,248 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 194 states. [2021-12-16 00:58:45,285 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 194 to 188. [2021-12-16 00:58:45,286 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 188 states, 141 states have (on average 1.3546099290780143) internal successors, (191), 159 states have internal predecessors, (191), 27 states have call successors, (27), 19 states have call predecessors, (27), 19 states have return successors, (28), 19 states have call predecessors, (28), 27 states have call successors, (28) [2021-12-16 00:58:45,288 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 188 states to 188 states and 246 transitions. [2021-12-16 00:58:45,288 INFO L78 Accepts]: Start accepts. Automaton has 188 states and 246 transitions. Word has length 28 [2021-12-16 00:58:45,300 INFO L84 Accepts]: Finished accepts. word is rejected. [2021-12-16 00:58:45,300 INFO L470 AbstractCegarLoop]: Abstraction has 188 states and 246 transitions. [2021-12-16 00:58:45,300 INFO L471 AbstractCegarLoop]: INTERPOLANT automaton has has 6 states, 6 states have (on average 4.166666666666667) internal successors, (25), 6 states have internal predecessors, (25), 2 states have call successors, (2), 2 states have call predecessors, (2), 1 states have return successors, (1), 1 states have call predecessors, (1), 1 states have call successors, (1) [2021-12-16 00:58:45,301 INFO L276 IsEmpty]: Start isEmpty. Operand 188 states and 246 transitions. [2021-12-16 00:58:45,302 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 33 [2021-12-16 00:58:45,304 INFO L506 BasicCegarLoop]: Found error trace [2021-12-16 00:58:45,305 INFO L514 BasicCegarLoop]: trace histogram [1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2021-12-16 00:58:45,305 WARN L452 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable2 [2021-12-16 00:58:45,305 INFO L402 AbstractCegarLoop]: === Iteration 4 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2021-12-16 00:58:45,306 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2021-12-16 00:58:45,306 INFO L85 PathProgramCache]: Analyzing trace with hash -440127999, now seen corresponding path program 1 times [2021-12-16 00:58:45,306 INFO L121 FreeRefinementEngine]: Executing refinement strategy CAMEL [2021-12-16 00:58:45,306 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [674708378] [2021-12-16 00:58:45,306 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2021-12-16 00:58:45,306 INFO L126 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2021-12-16 00:58:45,324 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 00:58:45,362 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 23 [2021-12-16 00:58:45,364 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 00:58:45,372 INFO L134 CoverageAnalysis]: Checked inductivity of 0 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2021-12-16 00:58:45,372 INFO L139 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2021-12-16 00:58:45,372 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [674708378] [2021-12-16 00:58:45,372 INFO L160 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [674708378] provided 1 perfect and 0 imperfect interpolant sequences [2021-12-16 00:58:45,373 INFO L186 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2021-12-16 00:58:45,373 INFO L199 FreeRefinementEngine]: Number of different interpolants: perfect sequences [6] imperfect sequences [] total 6 [2021-12-16 00:58:45,373 INFO L115 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [1347235036] [2021-12-16 00:58:45,373 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2021-12-16 00:58:45,374 INFO L546 AbstractCegarLoop]: INTERPOLANT automaton has 6 states [2021-12-16 00:58:45,374 INFO L103 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2021-12-16 00:58:45,374 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 6 interpolants. [2021-12-16 00:58:45,374 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=9, Invalid=21, Unknown=0, NotChecked=0, Total=30 [2021-12-16 00:58:45,375 INFO L87 Difference]: Start difference. First operand 188 states and 246 transitions. Second operand has 6 states, 6 states have (on average 4.833333333333333) internal successors, (29), 4 states have internal predecessors, (29), 1 states have call successors, (2), 2 states have call predecessors, (2), 1 states have return successors, (1), 1 states have call predecessors, (1), 1 states have call successors, (1) [2021-12-16 00:58:45,467 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2021-12-16 00:58:45,468 INFO L93 Difference]: Finished difference Result 551 states and 734 transitions. [2021-12-16 00:58:45,468 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 8 states. [2021-12-16 00:58:45,468 INFO L78 Accepts]: Start accepts. Automaton has has 6 states, 6 states have (on average 4.833333333333333) internal successors, (29), 4 states have internal predecessors, (29), 1 states have call successors, (2), 2 states have call predecessors, (2), 1 states have return successors, (1), 1 states have call predecessors, (1), 1 states have call successors, (1) Word has length 32 [2021-12-16 00:58:45,469 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2021-12-16 00:58:45,472 INFO L225 Difference]: With dead ends: 551 [2021-12-16 00:58:45,472 INFO L226 Difference]: Without dead ends: 370 [2021-12-16 00:58:45,473 INFO L932 BasicCegarLoop]: 0 DeclaredPredicates, 9 GetRequests, 2 SyntacticMatches, 0 SemanticMatches, 7 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 3 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=21, Invalid=51, Unknown=0, NotChecked=0, Total=72 [2021-12-16 00:58:45,474 INFO L933 BasicCegarLoop]: 111 mSDtfsCounter, 74 mSDsluCounter, 393 mSDsCounter, 0 mSdLazyCounter, 48 mSolverCounterSat, 4 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.0s Time, 0 mProtectedPredicate, 0 mProtectedAction, 77 SdHoareTripleChecker+Valid, 504 SdHoareTripleChecker+Invalid, 52 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 4 IncrementalHoareTripleChecker+Valid, 48 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.0s IncrementalHoareTripleChecker+Time [2021-12-16 00:58:45,475 INFO L934 BasicCegarLoop]: SdHoareTripleChecker [77 Valid, 504 Invalid, 52 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [4 Valid, 48 Invalid, 0 Unknown, 0 Unchecked, 0.0s Time] [2021-12-16 00:58:45,476 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 370 states. [2021-12-16 00:58:45,507 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 370 to 361. [2021-12-16 00:58:45,508 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 361 states, 268 states have (on average 1.3395522388059702) internal successors, (359), 303 states have internal predecessors, (359), 54 states have call successors, (54), 38 states have call predecessors, (54), 38 states have return successors, (59), 38 states have call predecessors, (59), 54 states have call successors, (59) [2021-12-16 00:58:45,511 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 361 states to 361 states and 472 transitions. [2021-12-16 00:58:45,511 INFO L78 Accepts]: Start accepts. Automaton has 361 states and 472 transitions. Word has length 32 [2021-12-16 00:58:45,511 INFO L84 Accepts]: Finished accepts. word is rejected. [2021-12-16 00:58:45,511 INFO L470 AbstractCegarLoop]: Abstraction has 361 states and 472 transitions. [2021-12-16 00:58:45,512 INFO L471 AbstractCegarLoop]: INTERPOLANT automaton has has 6 states, 6 states have (on average 4.833333333333333) internal successors, (29), 4 states have internal predecessors, (29), 1 states have call successors, (2), 2 states have call predecessors, (2), 1 states have return successors, (1), 1 states have call predecessors, (1), 1 states have call successors, (1) [2021-12-16 00:58:45,512 INFO L276 IsEmpty]: Start isEmpty. Operand 361 states and 472 transitions. [2021-12-16 00:58:45,514 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 37 [2021-12-16 00:58:45,514 INFO L506 BasicCegarLoop]: Found error trace [2021-12-16 00:58:45,514 INFO L514 BasicCegarLoop]: trace histogram [1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2021-12-16 00:58:45,515 WARN L452 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable3 [2021-12-16 00:58:45,515 INFO L402 AbstractCegarLoop]: === Iteration 5 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2021-12-16 00:58:45,515 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2021-12-16 00:58:45,516 INFO L85 PathProgramCache]: Analyzing trace with hash -1869434011, now seen corresponding path program 1 times [2021-12-16 00:58:45,516 INFO L121 FreeRefinementEngine]: Executing refinement strategy CAMEL [2021-12-16 00:58:45,516 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [598816820] [2021-12-16 00:58:45,516 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2021-12-16 00:58:45,516 INFO L126 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2021-12-16 00:58:45,541 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 00:58:45,606 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 13 [2021-12-16 00:58:45,608 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 00:58:45,611 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 27 [2021-12-16 00:58:45,612 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 00:58:45,615 INFO L134 CoverageAnalysis]: Checked inductivity of 0 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2021-12-16 00:58:45,615 INFO L139 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2021-12-16 00:58:45,615 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [598816820] [2021-12-16 00:58:45,615 INFO L160 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [598816820] provided 1 perfect and 0 imperfect interpolant sequences [2021-12-16 00:58:45,616 INFO L186 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2021-12-16 00:58:45,616 INFO L199 FreeRefinementEngine]: Number of different interpolants: perfect sequences [6] imperfect sequences [] total 6 [2021-12-16 00:58:45,616 INFO L115 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [438826999] [2021-12-16 00:58:45,616 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2021-12-16 00:58:45,617 INFO L546 AbstractCegarLoop]: INTERPOLANT automaton has 6 states [2021-12-16 00:58:45,617 INFO L103 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2021-12-16 00:58:45,617 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 6 interpolants. [2021-12-16 00:58:45,617 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=9, Invalid=21, Unknown=0, NotChecked=0, Total=30 [2021-12-16 00:58:45,618 INFO L87 Difference]: Start difference. First operand 361 states and 472 transitions. Second operand has 6 states, 6 states have (on average 5.166666666666667) internal successors, (31), 5 states have internal predecessors, (31), 1 states have call successors, (3), 3 states have call predecessors, (3), 1 states have return successors, (2), 1 states have call predecessors, (2), 1 states have call successors, (2) [2021-12-16 00:58:45,886 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2021-12-16 00:58:45,887 INFO L93 Difference]: Finished difference Result 882 states and 1178 transitions. [2021-12-16 00:58:45,887 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 8 states. [2021-12-16 00:58:45,887 INFO L78 Accepts]: Start accepts. Automaton has has 6 states, 6 states have (on average 5.166666666666667) internal successors, (31), 5 states have internal predecessors, (31), 1 states have call successors, (3), 3 states have call predecessors, (3), 1 states have return successors, (2), 1 states have call predecessors, (2), 1 states have call successors, (2) Word has length 36 [2021-12-16 00:58:45,888 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2021-12-16 00:58:45,899 INFO L225 Difference]: With dead ends: 882 [2021-12-16 00:58:45,899 INFO L226 Difference]: Without dead ends: 528 [2021-12-16 00:58:45,904 INFO L932 BasicCegarLoop]: 0 DeclaredPredicates, 14 GetRequests, 6 SyntacticMatches, 0 SemanticMatches, 8 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 3 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=32, Invalid=58, Unknown=0, NotChecked=0, Total=90 [2021-12-16 00:58:45,911 INFO L933 BasicCegarLoop]: 93 mSDtfsCounter, 124 mSDsluCounter, 141 mSDsCounter, 0 mSdLazyCounter, 208 mSolverCounterSat, 43 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.2s Time, 0 mProtectedPredicate, 0 mProtectedAction, 129 SdHoareTripleChecker+Valid, 234 SdHoareTripleChecker+Invalid, 251 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 43 IncrementalHoareTripleChecker+Valid, 208 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.2s IncrementalHoareTripleChecker+Time [2021-12-16 00:58:45,912 INFO L934 BasicCegarLoop]: SdHoareTripleChecker [129 Valid, 234 Invalid, 251 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [43 Valid, 208 Invalid, 0 Unknown, 0 Unchecked, 0.2s Time] [2021-12-16 00:58:45,914 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 528 states. [2021-12-16 00:58:45,959 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 528 to 509. [2021-12-16 00:58:45,962 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 509 states, 380 states have (on average 1.2842105263157895) internal successors, (488), 417 states have internal predecessors, (488), 68 states have call successors, (68), 60 states have call predecessors, (68), 60 states have return successors, (93), 62 states have call predecessors, (93), 68 states have call successors, (93) [2021-12-16 00:58:45,967 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 509 states to 509 states and 649 transitions. [2021-12-16 00:58:45,968 INFO L78 Accepts]: Start accepts. Automaton has 509 states and 649 transitions. Word has length 36 [2021-12-16 00:58:45,968 INFO L84 Accepts]: Finished accepts. word is rejected. [2021-12-16 00:58:45,968 INFO L470 AbstractCegarLoop]: Abstraction has 509 states and 649 transitions. [2021-12-16 00:58:45,969 INFO L471 AbstractCegarLoop]: INTERPOLANT automaton has has 6 states, 6 states have (on average 5.166666666666667) internal successors, (31), 5 states have internal predecessors, (31), 1 states have call successors, (3), 3 states have call predecessors, (3), 1 states have return successors, (2), 1 states have call predecessors, (2), 1 states have call successors, (2) [2021-12-16 00:58:45,969 INFO L276 IsEmpty]: Start isEmpty. Operand 509 states and 649 transitions. [2021-12-16 00:58:45,974 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 55 [2021-12-16 00:58:45,974 INFO L506 BasicCegarLoop]: Found error trace [2021-12-16 00:58:45,974 INFO L514 BasicCegarLoop]: trace histogram [2, 2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2021-12-16 00:58:45,974 WARN L452 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable4 [2021-12-16 00:58:45,975 INFO L402 AbstractCegarLoop]: === Iteration 6 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2021-12-16 00:58:45,976 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2021-12-16 00:58:45,977 INFO L85 PathProgramCache]: Analyzing trace with hash 1110744655, now seen corresponding path program 1 times [2021-12-16 00:58:45,977 INFO L121 FreeRefinementEngine]: Executing refinement strategy CAMEL [2021-12-16 00:58:45,977 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [593123166] [2021-12-16 00:58:45,977 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2021-12-16 00:58:45,977 INFO L126 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2021-12-16 00:58:46,005 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 00:58:46,027 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 13 [2021-12-16 00:58:46,028 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 00:58:46,034 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 23 [2021-12-16 00:58:46,037 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 00:58:46,058 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 8 [2021-12-16 00:58:46,059 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 00:58:46,061 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 45 [2021-12-16 00:58:46,062 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 00:58:46,064 INFO L134 CoverageAnalysis]: Checked inductivity of 3 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 3 trivial. 0 not checked. [2021-12-16 00:58:46,064 INFO L139 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2021-12-16 00:58:46,065 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [593123166] [2021-12-16 00:58:46,065 INFO L160 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [593123166] provided 1 perfect and 0 imperfect interpolant sequences [2021-12-16 00:58:46,065 INFO L186 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2021-12-16 00:58:46,065 INFO L199 FreeRefinementEngine]: Number of different interpolants: perfect sequences [7] imperfect sequences [] total 7 [2021-12-16 00:58:46,065 INFO L115 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [320792384] [2021-12-16 00:58:46,065 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2021-12-16 00:58:46,066 INFO L546 AbstractCegarLoop]: INTERPOLANT automaton has 7 states [2021-12-16 00:58:46,066 INFO L103 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2021-12-16 00:58:46,067 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 7 interpolants. [2021-12-16 00:58:46,067 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=11, Invalid=31, Unknown=0, NotChecked=0, Total=42 [2021-12-16 00:58:46,067 INFO L87 Difference]: Start difference. First operand 509 states and 649 transitions. Second operand has 7 states, 7 states have (on average 6.142857142857143) internal successors, (43), 5 states have internal predecessors, (43), 2 states have call successors, (5), 3 states have call predecessors, (5), 2 states have return successors, (4), 2 states have call predecessors, (4), 2 states have call successors, (4) [2021-12-16 00:58:46,322 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2021-12-16 00:58:46,322 INFO L93 Difference]: Finished difference Result 1125 states and 1470 transitions. [2021-12-16 00:58:46,322 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 9 states. [2021-12-16 00:58:46,323 INFO L78 Accepts]: Start accepts. Automaton has has 7 states, 7 states have (on average 6.142857142857143) internal successors, (43), 5 states have internal predecessors, (43), 2 states have call successors, (5), 3 states have call predecessors, (5), 2 states have return successors, (4), 2 states have call predecessors, (4), 2 states have call successors, (4) Word has length 54 [2021-12-16 00:58:46,323 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2021-12-16 00:58:46,326 INFO L225 Difference]: With dead ends: 1125 [2021-12-16 00:58:46,326 INFO L226 Difference]: Without dead ends: 623 [2021-12-16 00:58:46,328 INFO L932 BasicCegarLoop]: 0 DeclaredPredicates, 20 GetRequests, 10 SyntacticMatches, 0 SemanticMatches, 10 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 3 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=46, Invalid=86, Unknown=0, NotChecked=0, Total=132 [2021-12-16 00:58:46,331 INFO L933 BasicCegarLoop]: 86 mSDtfsCounter, 133 mSDsluCounter, 163 mSDsCounter, 0 mSdLazyCounter, 262 mSolverCounterSat, 50 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.1s Time, 0 mProtectedPredicate, 0 mProtectedAction, 134 SdHoareTripleChecker+Valid, 249 SdHoareTripleChecker+Invalid, 312 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 50 IncrementalHoareTripleChecker+Valid, 262 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.2s IncrementalHoareTripleChecker+Time [2021-12-16 00:58:46,332 INFO L934 BasicCegarLoop]: SdHoareTripleChecker [134 Valid, 249 Invalid, 312 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [50 Valid, 262 Invalid, 0 Unknown, 0 Unchecked, 0.2s Time] [2021-12-16 00:58:46,333 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 623 states. [2021-12-16 00:58:46,362 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 623 to 601. [2021-12-16 00:58:46,363 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 601 states, 452 states have (on average 1.252212389380531) internal successors, (566), 489 states have internal predecessors, (566), 76 states have call successors, (76), 60 states have call predecessors, (76), 72 states have return successors, (113), 78 states have call predecessors, (113), 76 states have call successors, (113) [2021-12-16 00:58:46,367 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 601 states to 601 states and 755 transitions. [2021-12-16 00:58:46,368 INFO L78 Accepts]: Start accepts. Automaton has 601 states and 755 transitions. Word has length 54 [2021-12-16 00:58:46,370 INFO L84 Accepts]: Finished accepts. word is rejected. [2021-12-16 00:58:46,370 INFO L470 AbstractCegarLoop]: Abstraction has 601 states and 755 transitions. [2021-12-16 00:58:46,370 INFO L471 AbstractCegarLoop]: INTERPOLANT automaton has has 7 states, 7 states have (on average 6.142857142857143) internal successors, (43), 5 states have internal predecessors, (43), 2 states have call successors, (5), 3 states have call predecessors, (5), 2 states have return successors, (4), 2 states have call predecessors, (4), 2 states have call successors, (4) [2021-12-16 00:58:46,370 INFO L276 IsEmpty]: Start isEmpty. Operand 601 states and 755 transitions. [2021-12-16 00:58:46,371 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 55 [2021-12-16 00:58:46,371 INFO L506 BasicCegarLoop]: Found error trace [2021-12-16 00:58:46,372 INFO L514 BasicCegarLoop]: trace histogram [2, 2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2021-12-16 00:58:46,372 WARN L452 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable5 [2021-12-16 00:58:46,372 INFO L402 AbstractCegarLoop]: === Iteration 7 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2021-12-16 00:58:46,373 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2021-12-16 00:58:46,373 INFO L85 PathProgramCache]: Analyzing trace with hash 1172784269, now seen corresponding path program 1 times [2021-12-16 00:58:46,373 INFO L121 FreeRefinementEngine]: Executing refinement strategy CAMEL [2021-12-16 00:58:46,373 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [643724599] [2021-12-16 00:58:46,373 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2021-12-16 00:58:46,373 INFO L126 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2021-12-16 00:58:46,401 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 00:58:46,440 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 13 [2021-12-16 00:58:46,441 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 00:58:46,450 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 23 [2021-12-16 00:58:46,453 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 00:58:46,485 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 8 [2021-12-16 00:58:46,486 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 00:58:46,488 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 45 [2021-12-16 00:58:46,489 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 00:58:46,490 INFO L134 CoverageAnalysis]: Checked inductivity of 3 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 3 trivial. 0 not checked. [2021-12-16 00:58:46,491 INFO L139 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2021-12-16 00:58:46,491 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [643724599] [2021-12-16 00:58:46,491 INFO L160 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [643724599] provided 1 perfect and 0 imperfect interpolant sequences [2021-12-16 00:58:46,491 INFO L186 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2021-12-16 00:58:46,491 INFO L199 FreeRefinementEngine]: Number of different interpolants: perfect sequences [8] imperfect sequences [] total 8 [2021-12-16 00:58:46,491 INFO L115 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [2093991624] [2021-12-16 00:58:46,491 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2021-12-16 00:58:46,492 INFO L546 AbstractCegarLoop]: INTERPOLANT automaton has 8 states [2021-12-16 00:58:46,492 INFO L103 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2021-12-16 00:58:46,492 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 8 interpolants. [2021-12-16 00:58:46,492 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=13, Invalid=43, Unknown=0, NotChecked=0, Total=56 [2021-12-16 00:58:46,493 INFO L87 Difference]: Start difference. First operand 601 states and 755 transitions. Second operand has 8 states, 8 states have (on average 5.375) internal successors, (43), 6 states have internal predecessors, (43), 2 states have call successors, (5), 3 states have call predecessors, (5), 2 states have return successors, (4), 2 states have call predecessors, (4), 2 states have call successors, (4) [2021-12-16 00:58:46,794 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2021-12-16 00:58:46,795 INFO L93 Difference]: Finished difference Result 1241 states and 1604 transitions. [2021-12-16 00:58:46,795 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 10 states. [2021-12-16 00:58:46,796 INFO L78 Accepts]: Start accepts. Automaton has has 8 states, 8 states have (on average 5.375) internal successors, (43), 6 states have internal predecessors, (43), 2 states have call successors, (5), 3 states have call predecessors, (5), 2 states have return successors, (4), 2 states have call predecessors, (4), 2 states have call successors, (4) Word has length 54 [2021-12-16 00:58:46,796 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2021-12-16 00:58:46,799 INFO L225 Difference]: With dead ends: 1241 [2021-12-16 00:58:46,799 INFO L226 Difference]: Without dead ends: 647 [2021-12-16 00:58:46,801 INFO L932 BasicCegarLoop]: 0 DeclaredPredicates, 23 GetRequests, 12 SyntacticMatches, 0 SemanticMatches, 11 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 6 ImplicationChecksByTransitivity, 0.1s TimeCoverageRelationStatistics Valid=42, Invalid=114, Unknown=0, NotChecked=0, Total=156 [2021-12-16 00:58:46,802 INFO L933 BasicCegarLoop]: 84 mSDtfsCounter, 188 mSDsluCounter, 144 mSDsCounter, 0 mSdLazyCounter, 344 mSolverCounterSat, 63 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.2s Time, 0 mProtectedPredicate, 0 mProtectedAction, 189 SdHoareTripleChecker+Valid, 228 SdHoareTripleChecker+Invalid, 407 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 63 IncrementalHoareTripleChecker+Valid, 344 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.2s IncrementalHoareTripleChecker+Time [2021-12-16 00:58:46,803 INFO L934 BasicCegarLoop]: SdHoareTripleChecker [189 Valid, 228 Invalid, 407 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [63 Valid, 344 Invalid, 0 Unknown, 0 Unchecked, 0.2s Time] [2021-12-16 00:58:46,805 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 647 states. [2021-12-16 00:58:46,837 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 647 to 609. [2021-12-16 00:58:46,838 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 609 states, 460 states have (on average 1.2478260869565216) internal successors, (574), 497 states have internal predecessors, (574), 76 states have call successors, (76), 60 states have call predecessors, (76), 72 states have return successors, (113), 78 states have call predecessors, (113), 76 states have call successors, (113) [2021-12-16 00:58:46,841 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 609 states to 609 states and 763 transitions. [2021-12-16 00:58:46,844 INFO L78 Accepts]: Start accepts. Automaton has 609 states and 763 transitions. Word has length 54 [2021-12-16 00:58:46,844 INFO L84 Accepts]: Finished accepts. word is rejected. [2021-12-16 00:58:46,844 INFO L470 AbstractCegarLoop]: Abstraction has 609 states and 763 transitions. [2021-12-16 00:58:46,844 INFO L471 AbstractCegarLoop]: INTERPOLANT automaton has has 8 states, 8 states have (on average 5.375) internal successors, (43), 6 states have internal predecessors, (43), 2 states have call successors, (5), 3 states have call predecessors, (5), 2 states have return successors, (4), 2 states have call predecessors, (4), 2 states have call successors, (4) [2021-12-16 00:58:46,845 INFO L276 IsEmpty]: Start isEmpty. Operand 609 states and 763 transitions. [2021-12-16 00:58:46,847 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 55 [2021-12-16 00:58:46,847 INFO L506 BasicCegarLoop]: Found error trace [2021-12-16 00:58:46,847 INFO L514 BasicCegarLoop]: trace histogram [2, 2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2021-12-16 00:58:46,847 WARN L452 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable6 [2021-12-16 00:58:46,851 INFO L402 AbstractCegarLoop]: === Iteration 8 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2021-12-16 00:58:46,852 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2021-12-16 00:58:46,852 INFO L85 PathProgramCache]: Analyzing trace with hash 663311179, now seen corresponding path program 1 times [2021-12-16 00:58:46,852 INFO L121 FreeRefinementEngine]: Executing refinement strategy CAMEL [2021-12-16 00:58:46,852 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [1296223382] [2021-12-16 00:58:46,852 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2021-12-16 00:58:46,853 INFO L126 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2021-12-16 00:58:46,863 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 00:58:46,885 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 13 [2021-12-16 00:58:46,886 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 00:58:46,897 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 23 [2021-12-16 00:58:46,900 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 00:58:46,915 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 8 [2021-12-16 00:58:46,916 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 00:58:46,919 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 45 [2021-12-16 00:58:46,921 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 00:58:46,923 INFO L134 CoverageAnalysis]: Checked inductivity of 3 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 3 trivial. 0 not checked. [2021-12-16 00:58:46,923 INFO L139 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2021-12-16 00:58:46,923 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [1296223382] [2021-12-16 00:58:46,923 INFO L160 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [1296223382] provided 1 perfect and 0 imperfect interpolant sequences [2021-12-16 00:58:46,923 INFO L186 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2021-12-16 00:58:46,924 INFO L199 FreeRefinementEngine]: Number of different interpolants: perfect sequences [6] imperfect sequences [] total 6 [2021-12-16 00:58:46,924 INFO L115 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [2128457351] [2021-12-16 00:58:46,924 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2021-12-16 00:58:46,925 INFO L546 AbstractCegarLoop]: INTERPOLANT automaton has 6 states [2021-12-16 00:58:46,925 INFO L103 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2021-12-16 00:58:46,925 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 6 interpolants. [2021-12-16 00:58:46,926 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=9, Invalid=21, Unknown=0, NotChecked=0, Total=30 [2021-12-16 00:58:46,926 INFO L87 Difference]: Start difference. First operand 609 states and 763 transitions. Second operand has 6 states, 6 states have (on average 7.166666666666667) internal successors, (43), 4 states have internal predecessors, (43), 3 states have call successors, (5), 4 states have call predecessors, (5), 2 states have return successors, (4), 3 states have call predecessors, (4), 3 states have call successors, (4) [2021-12-16 00:58:47,233 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2021-12-16 00:58:47,234 INFO L93 Difference]: Finished difference Result 1817 states and 2376 transitions. [2021-12-16 00:58:47,234 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 12 states. [2021-12-16 00:58:47,234 INFO L78 Accepts]: Start accepts. Automaton has has 6 states, 6 states have (on average 7.166666666666667) internal successors, (43), 4 states have internal predecessors, (43), 3 states have call successors, (5), 4 states have call predecessors, (5), 2 states have return successors, (4), 3 states have call predecessors, (4), 3 states have call successors, (4) Word has length 54 [2021-12-16 00:58:47,234 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2021-12-16 00:58:47,239 INFO L225 Difference]: With dead ends: 1817 [2021-12-16 00:58:47,239 INFO L226 Difference]: Without dead ends: 1215 [2021-12-16 00:58:47,242 INFO L932 BasicCegarLoop]: 0 DeclaredPredicates, 23 GetRequests, 13 SyntacticMatches, 0 SemanticMatches, 10 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 15 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=40, Invalid=92, Unknown=0, NotChecked=0, Total=132 [2021-12-16 00:58:47,244 INFO L933 BasicCegarLoop]: 134 mSDtfsCounter, 320 mSDsluCounter, 137 mSDsCounter, 0 mSdLazyCounter, 248 mSolverCounterSat, 126 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.2s Time, 0 mProtectedPredicate, 0 mProtectedAction, 323 SdHoareTripleChecker+Valid, 271 SdHoareTripleChecker+Invalid, 374 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 126 IncrementalHoareTripleChecker+Valid, 248 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.2s IncrementalHoareTripleChecker+Time [2021-12-16 00:58:47,244 INFO L934 BasicCegarLoop]: SdHoareTripleChecker [323 Valid, 271 Invalid, 374 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [126 Valid, 248 Invalid, 0 Unknown, 0 Unchecked, 0.2s Time] [2021-12-16 00:58:47,246 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 1215 states. [2021-12-16 00:58:47,296 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 1215 to 1203. [2021-12-16 00:58:47,298 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 1203 states, 904 states have (on average 1.2234513274336283) internal successors, (1106), 965 states have internal predecessors, (1106), 154 states have call successors, (154), 142 states have call predecessors, (154), 144 states have return successors, (257), 150 states have call predecessors, (257), 154 states have call successors, (257) [2021-12-16 00:58:47,304 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 1203 states to 1203 states and 1517 transitions. [2021-12-16 00:58:47,304 INFO L78 Accepts]: Start accepts. Automaton has 1203 states and 1517 transitions. Word has length 54 [2021-12-16 00:58:47,304 INFO L84 Accepts]: Finished accepts. word is rejected. [2021-12-16 00:58:47,307 INFO L470 AbstractCegarLoop]: Abstraction has 1203 states and 1517 transitions. [2021-12-16 00:58:47,307 INFO L471 AbstractCegarLoop]: INTERPOLANT automaton has has 6 states, 6 states have (on average 7.166666666666667) internal successors, (43), 4 states have internal predecessors, (43), 3 states have call successors, (5), 4 states have call predecessors, (5), 2 states have return successors, (4), 3 states have call predecessors, (4), 3 states have call successors, (4) [2021-12-16 00:58:47,307 INFO L276 IsEmpty]: Start isEmpty. Operand 1203 states and 1517 transitions. [2021-12-16 00:58:47,309 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 59 [2021-12-16 00:58:47,310 INFO L506 BasicCegarLoop]: Found error trace [2021-12-16 00:58:47,310 INFO L514 BasicCegarLoop]: trace histogram [2, 2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2021-12-16 00:58:47,310 WARN L452 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable7 [2021-12-16 00:58:47,310 INFO L402 AbstractCegarLoop]: === Iteration 9 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2021-12-16 00:58:47,310 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2021-12-16 00:58:47,310 INFO L85 PathProgramCache]: Analyzing trace with hash 740773105, now seen corresponding path program 1 times [2021-12-16 00:58:47,311 INFO L121 FreeRefinementEngine]: Executing refinement strategy CAMEL [2021-12-16 00:58:47,311 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [1101493362] [2021-12-16 00:58:47,311 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2021-12-16 00:58:47,311 INFO L126 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2021-12-16 00:58:47,323 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 00:58:47,358 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 11 [2021-12-16 00:58:47,359 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 00:58:47,365 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 17 [2021-12-16 00:58:47,366 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 00:58:47,383 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 27 [2021-12-16 00:58:47,386 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 00:58:47,430 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 8 [2021-12-16 00:58:47,431 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 00:58:47,441 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 49 [2021-12-16 00:58:47,442 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 00:58:47,444 INFO L134 CoverageAnalysis]: Checked inductivity of 3 backedges. 0 proven. 2 refuted. 0 times theorem prover too weak. 1 trivial. 0 not checked. [2021-12-16 00:58:47,444 INFO L139 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2021-12-16 00:58:47,444 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [1101493362] [2021-12-16 00:58:47,444 INFO L160 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [1101493362] provided 0 perfect and 1 imperfect interpolant sequences [2021-12-16 00:58:47,444 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleZ3 [2069387361] [2021-12-16 00:58:47,444 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2021-12-16 00:58:47,445 INFO L168 SolverBuilder]: Constructing external solver with command: z3 -smt2 -in SMTLIB2_COMPLIANT=true [2021-12-16 00:58:47,445 INFO L189 MonitoredProcess]: No working directory specified, using /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 [2021-12-16 00:58:47,447 INFO L229 MonitoredProcess]: Starting monitored process 2 with /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 -smt2 -in SMTLIB2_COMPLIANT=true (exit command is (exit), workingDir is null) [2021-12-16 00:58:47,456 INFO L327 MonitoredProcess]: [MP /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 -smt2 -in SMTLIB2_COMPLIANT=true (2)] Waiting until timeout for monitored process [2021-12-16 00:58:47,528 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 00:58:47,531 INFO L263 TraceCheckSpWp]: Trace formula consists of 375 conjuncts, 8 conjunts are in the unsatisfiable core [2021-12-16 00:58:47,544 INFO L286 TraceCheckSpWp]: Computing forward predicates... [2021-12-16 00:58:47,767 INFO L134 CoverageAnalysis]: Checked inductivity of 3 backedges. 3 proven. 0 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2021-12-16 00:58:47,767 INFO L324 TraceCheckSpWp]: Omiting computation of backward sequence because forward sequence was already perfect [2021-12-16 00:58:47,768 INFO L160 FreeRefinementEngine]: IpTcStrategyModuleZ3 [2069387361] provided 1 perfect and 0 imperfect interpolant sequences [2021-12-16 00:58:47,768 INFO L186 FreeRefinementEngine]: Found 1 perfect and 1 imperfect interpolant sequences. [2021-12-16 00:58:47,768 INFO L199 FreeRefinementEngine]: Number of different interpolants: perfect sequences [7] imperfect sequences [14] total 18 [2021-12-16 00:58:47,768 INFO L115 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [421250256] [2021-12-16 00:58:47,768 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2021-12-16 00:58:47,768 INFO L546 AbstractCegarLoop]: INTERPOLANT automaton has 7 states [2021-12-16 00:58:47,769 INFO L103 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2021-12-16 00:58:47,769 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 7 interpolants. [2021-12-16 00:58:47,769 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=42, Invalid=264, Unknown=0, NotChecked=0, Total=306 [2021-12-16 00:58:47,769 INFO L87 Difference]: Start difference. First operand 1203 states and 1517 transitions. Second operand has 7 states, 7 states have (on average 6.714285714285714) internal successors, (47), 6 states have internal predecessors, (47), 3 states have call successors, (6), 3 states have call predecessors, (6), 4 states have return successors, (5), 4 states have call predecessors, (5), 3 states have call successors, (5) [2021-12-16 00:58:47,936 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2021-12-16 00:58:47,936 INFO L93 Difference]: Finished difference Result 2357 states and 2985 transitions. [2021-12-16 00:58:47,937 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 7 states. [2021-12-16 00:58:47,937 INFO L78 Accepts]: Start accepts. Automaton has has 7 states, 7 states have (on average 6.714285714285714) internal successors, (47), 6 states have internal predecessors, (47), 3 states have call successors, (6), 3 states have call predecessors, (6), 4 states have return successors, (5), 4 states have call predecessors, (5), 3 states have call successors, (5) Word has length 58 [2021-12-16 00:58:47,938 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2021-12-16 00:58:47,945 INFO L225 Difference]: With dead ends: 2357 [2021-12-16 00:58:47,945 INFO L226 Difference]: Without dead ends: 1161 [2021-12-16 00:58:47,949 INFO L932 BasicCegarLoop]: 0 DeclaredPredicates, 78 GetRequests, 61 SyntacticMatches, 0 SemanticMatches, 17 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 6 ImplicationChecksByTransitivity, 0.1s TimeCoverageRelationStatistics Valid=48, Invalid=294, Unknown=0, NotChecked=0, Total=342 [2021-12-16 00:58:47,951 INFO L933 BasicCegarLoop]: 187 mSDtfsCounter, 75 mSDsluCounter, 628 mSDsCounter, 0 mSdLazyCounter, 134 mSolverCounterSat, 2 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.1s Time, 0 mProtectedPredicate, 0 mProtectedAction, 77 SdHoareTripleChecker+Valid, 815 SdHoareTripleChecker+Invalid, 136 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 2 IncrementalHoareTripleChecker+Valid, 134 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.1s IncrementalHoareTripleChecker+Time [2021-12-16 00:58:47,952 INFO L934 BasicCegarLoop]: SdHoareTripleChecker [77 Valid, 815 Invalid, 136 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [2 Valid, 134 Invalid, 0 Unknown, 0 Unchecked, 0.1s Time] [2021-12-16 00:58:47,954 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 1161 states. [2021-12-16 00:58:48,014 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 1161 to 1157. [2021-12-16 00:58:48,016 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 1157 states, 868 states have (on average 1.2085253456221199) internal successors, (1049), 927 states have internal predecessors, (1049), 150 states have call successors, (150), 138 states have call predecessors, (150), 138 states have return successors, (224), 144 states have call predecessors, (224), 150 states have call successors, (224) [2021-12-16 00:58:48,022 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 1157 states to 1157 states and 1423 transitions. [2021-12-16 00:58:48,022 INFO L78 Accepts]: Start accepts. Automaton has 1157 states and 1423 transitions. Word has length 58 [2021-12-16 00:58:48,023 INFO L84 Accepts]: Finished accepts. word is rejected. [2021-12-16 00:58:48,023 INFO L470 AbstractCegarLoop]: Abstraction has 1157 states and 1423 transitions. [2021-12-16 00:58:48,024 INFO L471 AbstractCegarLoop]: INTERPOLANT automaton has has 7 states, 7 states have (on average 6.714285714285714) internal successors, (47), 6 states have internal predecessors, (47), 3 states have call successors, (6), 3 states have call predecessors, (6), 4 states have return successors, (5), 4 states have call predecessors, (5), 3 states have call successors, (5) [2021-12-16 00:58:48,024 INFO L276 IsEmpty]: Start isEmpty. Operand 1157 states and 1423 transitions. [2021-12-16 00:58:48,027 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 97 [2021-12-16 00:58:48,027 INFO L506 BasicCegarLoop]: Found error trace [2021-12-16 00:58:48,027 INFO L514 BasicCegarLoop]: trace histogram [3, 3, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2021-12-16 00:58:48,052 INFO L552 MonitoredProcess]: [MP /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 -smt2 -in SMTLIB2_COMPLIANT=true (2)] Ended with exit code 0 [2021-12-16 00:58:48,251 WARN L452 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable8,2 /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 -smt2 -in SMTLIB2_COMPLIANT=true [2021-12-16 00:58:48,252 INFO L402 AbstractCegarLoop]: === Iteration 10 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2021-12-16 00:58:48,252 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2021-12-16 00:58:48,252 INFO L85 PathProgramCache]: Analyzing trace with hash 2065692327, now seen corresponding path program 1 times [2021-12-16 00:58:48,252 INFO L121 FreeRefinementEngine]: Executing refinement strategy CAMEL [2021-12-16 00:58:48,253 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [1060257453] [2021-12-16 00:58:48,253 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2021-12-16 00:58:48,253 INFO L126 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2021-12-16 00:58:48,272 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 00:58:48,317 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 11 [2021-12-16 00:58:48,318 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 00:58:48,327 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 19 [2021-12-16 00:58:48,331 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 00:58:48,346 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 3 [2021-12-16 00:58:48,349 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 00:58:48,358 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 8 [2021-12-16 00:58:48,360 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 00:58:48,362 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 25 [2021-12-16 00:58:48,362 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 00:58:48,370 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 60 [2021-12-16 00:58:48,372 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 00:58:48,373 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 77 [2021-12-16 00:58:48,374 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 00:58:48,380 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 2 [2021-12-16 00:58:48,381 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 00:58:48,382 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 87 [2021-12-16 00:58:48,383 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 00:58:48,385 INFO L134 CoverageAnalysis]: Checked inductivity of 30 backedges. 16 proven. 3 refuted. 0 times theorem prover too weak. 11 trivial. 0 not checked. [2021-12-16 00:58:48,385 INFO L139 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2021-12-16 00:58:48,385 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [1060257453] [2021-12-16 00:58:48,385 INFO L160 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [1060257453] provided 0 perfect and 1 imperfect interpolant sequences [2021-12-16 00:58:48,385 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleZ3 [594983431] [2021-12-16 00:58:48,386 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2021-12-16 00:58:48,386 INFO L168 SolverBuilder]: Constructing external solver with command: z3 -smt2 -in SMTLIB2_COMPLIANT=true [2021-12-16 00:58:48,386 INFO L189 MonitoredProcess]: No working directory specified, using /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 [2021-12-16 00:58:48,387 INFO L229 MonitoredProcess]: Starting monitored process 3 with /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 -smt2 -in SMTLIB2_COMPLIANT=true (exit command is (exit), workingDir is null) [2021-12-16 00:58:48,414 INFO L327 MonitoredProcess]: [MP /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 -smt2 -in SMTLIB2_COMPLIANT=true (3)] Waiting until timeout for monitored process [2021-12-16 00:58:48,483 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 00:58:48,485 INFO L263 TraceCheckSpWp]: Trace formula consists of 466 conjuncts, 11 conjunts are in the unsatisfiable core [2021-12-16 00:58:48,488 INFO L286 TraceCheckSpWp]: Computing forward predicates... [2021-12-16 00:58:48,666 INFO L134 CoverageAnalysis]: Checked inductivity of 30 backedges. 27 proven. 0 refuted. 0 times theorem prover too weak. 3 trivial. 0 not checked. [2021-12-16 00:58:48,667 INFO L324 TraceCheckSpWp]: Omiting computation of backward sequence because forward sequence was already perfect [2021-12-16 00:58:48,667 INFO L160 FreeRefinementEngine]: IpTcStrategyModuleZ3 [594983431] provided 1 perfect and 0 imperfect interpolant sequences [2021-12-16 00:58:48,667 INFO L186 FreeRefinementEngine]: Found 1 perfect and 1 imperfect interpolant sequences. [2021-12-16 00:58:48,667 INFO L199 FreeRefinementEngine]: Number of different interpolants: perfect sequences [6] imperfect sequences [10] total 10 [2021-12-16 00:58:48,667 INFO L115 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [1118854953] [2021-12-16 00:58:48,668 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2021-12-16 00:58:48,668 INFO L546 AbstractCegarLoop]: INTERPOLANT automaton has 6 states [2021-12-16 00:58:48,668 INFO L103 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2021-12-16 00:58:48,669 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 6 interpolants. [2021-12-16 00:58:48,669 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=20, Invalid=70, Unknown=0, NotChecked=0, Total=90 [2021-12-16 00:58:48,669 INFO L87 Difference]: Start difference. First operand 1157 states and 1423 transitions. Second operand has 6 states, 6 states have (on average 12.5) internal successors, (75), 6 states have internal predecessors, (75), 3 states have call successors, (10), 3 states have call predecessors, (10), 3 states have return successors, (9), 3 states have call predecessors, (9), 3 states have call successors, (9) [2021-12-16 00:58:48,853 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2021-12-16 00:58:48,853 INFO L93 Difference]: Finished difference Result 3043 states and 3934 transitions. [2021-12-16 00:58:48,854 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 9 states. [2021-12-16 00:58:48,854 INFO L78 Accepts]: Start accepts. Automaton has has 6 states, 6 states have (on average 12.5) internal successors, (75), 6 states have internal predecessors, (75), 3 states have call successors, (10), 3 states have call predecessors, (10), 3 states have return successors, (9), 3 states have call predecessors, (9), 3 states have call successors, (9) Word has length 96 [2021-12-16 00:58:48,854 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2021-12-16 00:58:48,865 INFO L225 Difference]: With dead ends: 3043 [2021-12-16 00:58:48,865 INFO L226 Difference]: Without dead ends: 2137 [2021-12-16 00:58:48,869 INFO L932 BasicCegarLoop]: 0 DeclaredPredicates, 126 GetRequests, 112 SyntacticMatches, 2 SemanticMatches, 12 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 17 ImplicationChecksByTransitivity, 0.1s TimeCoverageRelationStatistics Valid=44, Invalid=138, Unknown=0, NotChecked=0, Total=182 [2021-12-16 00:58:48,870 INFO L933 BasicCegarLoop]: 204 mSDtfsCounter, 179 mSDsluCounter, 557 mSDsCounter, 0 mSdLazyCounter, 65 mSolverCounterSat, 31 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.1s Time, 0 mProtectedPredicate, 0 mProtectedAction, 182 SdHoareTripleChecker+Valid, 761 SdHoareTripleChecker+Invalid, 96 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 31 IncrementalHoareTripleChecker+Valid, 65 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.1s IncrementalHoareTripleChecker+Time [2021-12-16 00:58:48,870 INFO L934 BasicCegarLoop]: SdHoareTripleChecker [182 Valid, 761 Invalid, 96 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [31 Valid, 65 Invalid, 0 Unknown, 0 Unchecked, 0.1s Time] [2021-12-16 00:58:48,873 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 2137 states. [2021-12-16 00:58:48,949 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 2137 to 1785. [2021-12-16 00:58:48,952 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 1785 states, 1336 states have (on average 1.2050898203592815) internal successors, (1610), 1427 states have internal predecessors, (1610), 234 states have call successors, (234), 198 states have call predecessors, (234), 214 states have return successors, (391), 224 states have call predecessors, (391), 234 states have call successors, (391) [2021-12-16 00:58:48,960 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 1785 states to 1785 states and 2235 transitions. [2021-12-16 00:58:48,960 INFO L78 Accepts]: Start accepts. Automaton has 1785 states and 2235 transitions. Word has length 96 [2021-12-16 00:58:48,961 INFO L84 Accepts]: Finished accepts. word is rejected. [2021-12-16 00:58:48,961 INFO L470 AbstractCegarLoop]: Abstraction has 1785 states and 2235 transitions. [2021-12-16 00:58:48,961 INFO L471 AbstractCegarLoop]: INTERPOLANT automaton has has 6 states, 6 states have (on average 12.5) internal successors, (75), 6 states have internal predecessors, (75), 3 states have call successors, (10), 3 states have call predecessors, (10), 3 states have return successors, (9), 3 states have call predecessors, (9), 3 states have call successors, (9) [2021-12-16 00:58:48,961 INFO L276 IsEmpty]: Start isEmpty. Operand 1785 states and 2235 transitions. [2021-12-16 00:58:48,964 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 97 [2021-12-16 00:58:48,964 INFO L506 BasicCegarLoop]: Found error trace [2021-12-16 00:58:48,964 INFO L514 BasicCegarLoop]: trace histogram [3, 3, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2021-12-16 00:58:48,991 INFO L540 MonitoredProcess]: [MP /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 -smt2 -in SMTLIB2_COMPLIANT=true (3)] Forceful destruction successful, exit code 0 [2021-12-16 00:58:49,183 WARN L452 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: 3 /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 -smt2 -in SMTLIB2_COMPLIANT=true,SelfDestructingSolverStorable9 [2021-12-16 00:58:49,183 INFO L402 AbstractCegarLoop]: === Iteration 11 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2021-12-16 00:58:49,183 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2021-12-16 00:58:49,184 INFO L85 PathProgramCache]: Analyzing trace with hash 260253993, now seen corresponding path program 1 times [2021-12-16 00:58:49,184 INFO L121 FreeRefinementEngine]: Executing refinement strategy CAMEL [2021-12-16 00:58:49,184 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [786235906] [2021-12-16 00:58:49,184 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2021-12-16 00:58:49,184 INFO L126 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2021-12-16 00:58:49,206 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 00:58:49,258 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 11 [2021-12-16 00:58:49,259 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 00:58:49,268 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 19 [2021-12-16 00:58:49,270 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 00:58:49,278 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 3 [2021-12-16 00:58:49,280 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 00:58:49,282 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 8 [2021-12-16 00:58:49,283 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 00:58:49,284 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 25 [2021-12-16 00:58:49,285 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 00:58:49,293 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 60 [2021-12-16 00:58:49,294 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 00:58:49,296 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 77 [2021-12-16 00:58:49,297 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 00:58:49,298 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 2 [2021-12-16 00:58:49,299 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 00:58:49,300 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 87 [2021-12-16 00:58:49,300 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 00:58:49,302 INFO L134 CoverageAnalysis]: Checked inductivity of 30 backedges. 5 proven. 1 refuted. 0 times theorem prover too weak. 24 trivial. 0 not checked. [2021-12-16 00:58:49,302 INFO L139 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2021-12-16 00:58:49,302 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [786235906] [2021-12-16 00:58:49,302 INFO L160 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [786235906] provided 0 perfect and 1 imperfect interpolant sequences [2021-12-16 00:58:49,303 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleZ3 [1152995138] [2021-12-16 00:58:49,303 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2021-12-16 00:58:49,303 INFO L168 SolverBuilder]: Constructing external solver with command: z3 -smt2 -in SMTLIB2_COMPLIANT=true [2021-12-16 00:58:49,303 INFO L189 MonitoredProcess]: No working directory specified, using /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 [2021-12-16 00:58:49,304 INFO L229 MonitoredProcess]: Starting monitored process 4 with /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 -smt2 -in SMTLIB2_COMPLIANT=true (exit command is (exit), workingDir is null) [2021-12-16 00:58:49,328 INFO L327 MonitoredProcess]: [MP /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 -smt2 -in SMTLIB2_COMPLIANT=true (4)] Waiting until timeout for monitored process [2021-12-16 00:58:49,395 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 00:58:49,397 INFO L263 TraceCheckSpWp]: Trace formula consists of 467 conjuncts, 5 conjunts are in the unsatisfiable core [2021-12-16 00:58:49,402 INFO L286 TraceCheckSpWp]: Computing forward predicates... [2021-12-16 00:58:49,555 INFO L134 CoverageAnalysis]: Checked inductivity of 30 backedges. 15 proven. 0 refuted. 0 times theorem prover too weak. 15 trivial. 0 not checked. [2021-12-16 00:58:49,556 INFO L324 TraceCheckSpWp]: Omiting computation of backward sequence because forward sequence was already perfect [2021-12-16 00:58:49,556 INFO L160 FreeRefinementEngine]: IpTcStrategyModuleZ3 [1152995138] provided 1 perfect and 0 imperfect interpolant sequences [2021-12-16 00:58:49,556 INFO L186 FreeRefinementEngine]: Found 1 perfect and 1 imperfect interpolant sequences. [2021-12-16 00:58:49,556 INFO L199 FreeRefinementEngine]: Number of different interpolants: perfect sequences [5] imperfect sequences [11] total 14 [2021-12-16 00:58:49,556 INFO L115 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [1197192350] [2021-12-16 00:58:49,556 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2021-12-16 00:58:49,557 INFO L546 AbstractCegarLoop]: INTERPOLANT automaton has 5 states [2021-12-16 00:58:49,557 INFO L103 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2021-12-16 00:58:49,557 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 5 interpolants. [2021-12-16 00:58:49,558 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=30, Invalid=152, Unknown=0, NotChecked=0, Total=182 [2021-12-16 00:58:49,558 INFO L87 Difference]: Start difference. First operand 1785 states and 2235 transitions. Second operand has 5 states, 5 states have (on average 13.6) internal successors, (68), 5 states have internal predecessors, (68), 2 states have call successors, (9), 2 states have call predecessors, (9), 2 states have return successors, (9), 2 states have call predecessors, (9), 2 states have call successors, (9) [2021-12-16 00:58:49,623 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2021-12-16 00:58:49,623 INFO L93 Difference]: Finished difference Result 2505 states and 3119 transitions. [2021-12-16 00:58:49,624 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 5 states. [2021-12-16 00:58:49,624 INFO L78 Accepts]: Start accepts. Automaton has has 5 states, 5 states have (on average 13.6) internal successors, (68), 5 states have internal predecessors, (68), 2 states have call successors, (9), 2 states have call predecessors, (9), 2 states have return successors, (9), 2 states have call predecessors, (9), 2 states have call successors, (9) Word has length 96 [2021-12-16 00:58:49,624 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2021-12-16 00:58:49,625 INFO L225 Difference]: With dead ends: 2505 [2021-12-16 00:58:49,625 INFO L226 Difference]: Without dead ends: 0 [2021-12-16 00:58:49,631 INFO L932 BasicCegarLoop]: 0 DeclaredPredicates, 124 GetRequests, 110 SyntacticMatches, 0 SemanticMatches, 14 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 15 ImplicationChecksByTransitivity, 0.1s TimeCoverageRelationStatistics Valid=45, Invalid=195, Unknown=0, NotChecked=0, Total=240 [2021-12-16 00:58:49,632 INFO L933 BasicCegarLoop]: 102 mSDtfsCounter, 33 mSDsluCounter, 269 mSDsCounter, 0 mSdLazyCounter, 7 mSolverCounterSat, 6 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.0s Time, 0 mProtectedPredicate, 0 mProtectedAction, 33 SdHoareTripleChecker+Valid, 371 SdHoareTripleChecker+Invalid, 13 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 6 IncrementalHoareTripleChecker+Valid, 7 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.0s IncrementalHoareTripleChecker+Time [2021-12-16 00:58:49,632 INFO L934 BasicCegarLoop]: SdHoareTripleChecker [33 Valid, 371 Invalid, 13 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [6 Valid, 7 Invalid, 0 Unknown, 0 Unchecked, 0.0s Time] [2021-12-16 00:58:49,633 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 0 states. [2021-12-16 00:58:49,633 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 0 to 0. [2021-12-16 00:58:49,633 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 0 states, 0 states have (on average 0.0) internal successors, (0), 0 states have internal predecessors, (0), 0 states have call successors, (0), 0 states have call predecessors, (0), 0 states have return successors, (0), 0 states have call predecessors, (0), 0 states have call successors, (0) [2021-12-16 00:58:49,633 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 0 states to 0 states and 0 transitions. [2021-12-16 00:58:49,634 INFO L78 Accepts]: Start accepts. Automaton has 0 states and 0 transitions. Word has length 96 [2021-12-16 00:58:49,634 INFO L84 Accepts]: Finished accepts. word is rejected. [2021-12-16 00:58:49,634 INFO L470 AbstractCegarLoop]: Abstraction has 0 states and 0 transitions. [2021-12-16 00:58:49,634 INFO L471 AbstractCegarLoop]: INTERPOLANT automaton has has 5 states, 5 states have (on average 13.6) internal successors, (68), 5 states have internal predecessors, (68), 2 states have call successors, (9), 2 states have call predecessors, (9), 2 states have return successors, (9), 2 states have call predecessors, (9), 2 states have call successors, (9) [2021-12-16 00:58:49,634 INFO L276 IsEmpty]: Start isEmpty. Operand 0 states and 0 transitions. [2021-12-16 00:58:49,634 INFO L282 IsEmpty]: Finished isEmpty. No accepting run. [2021-12-16 00:58:49,636 INFO L764 garLoopResultBuilder]: Registering result SAFE for location timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION (0 of 1 remaining) [2021-12-16 00:58:49,663 INFO L540 MonitoredProcess]: [MP /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 -smt2 -in SMTLIB2_COMPLIANT=true (4)] Forceful destruction successful, exit code 0 [2021-12-16 00:58:49,855 WARN L452 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable10,4 /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 -smt2 -in SMTLIB2_COMPLIANT=true [2021-12-16 00:58:49,857 INFO L343 DoubleDeckerVisitor]: Before removal of dead ends 0 states and 0 transitions. [2021-12-16 00:58:54,413 INFO L854 garLoopResultBuilder]: At program point deactivatePumpENTRY(lines 383 390) the Hoare annotation is: (let ((.cse0 (= 0 ~systemActive~0)) (.cse1 (not (<= 1 ~waterLevel~0))) (.cse2 (= ~pumpRunning~0 |old(~pumpRunning~0)|))) (and (or .cse0 .cse1 .cse2 (not (= ~methaneLevelCritical~0 0))) (or .cse0 .cse1 (not (<= 1 ~methaneLevelCritical~0)) .cse2))) [2021-12-16 00:58:54,413 INFO L858 garLoopResultBuilder]: For program point deactivatePumpEXIT(lines 383 390) no Hoare annotation was computed. [2021-12-16 00:58:54,413 INFO L858 garLoopResultBuilder]: For program point deactivatePumpFINAL(lines 383 390) no Hoare annotation was computed. [2021-12-16 00:58:54,413 INFO L858 garLoopResultBuilder]: For program point processEnvironment__wrappee__baseEXIT(lines 298 304) no Hoare annotation was computed. [2021-12-16 00:58:54,414 INFO L861 garLoopResultBuilder]: At program point processEnvironment__wrappee__baseFINAL(lines 298 304) the Hoare annotation is: true [2021-12-16 00:58:54,414 INFO L854 garLoopResultBuilder]: At program point changeMethaneLevelENTRY(lines 84 95) the Hoare annotation is: (let ((.cse0 (not (= |old(~methaneLevelCritical~0)| 0))) (.cse2 (not (= ~pumpRunning~0 0))) (.cse3 (not (<= 1 ~waterLevel~0))) (.cse1 (= ~methaneLevelCritical~0 0))) (and (or (= 0 ~systemActive~0) .cse0 .cse1 (not (<= 2 ~waterLevel~0))) (or .cse2 (= ~methaneLevelCritical~0 |old(~methaneLevelCritical~0)|) .cse3 (not (<= 1 |old(~methaneLevelCritical~0)|))) (or .cse0 .cse2 .cse3 .cse1))) [2021-12-16 00:58:54,414 INFO L858 garLoopResultBuilder]: For program point L88-1(lines 84 95) no Hoare annotation was computed. [2021-12-16 00:58:54,414 INFO L858 garLoopResultBuilder]: For program point changeMethaneLevelEXIT(lines 84 95) no Hoare annotation was computed. [2021-12-16 00:58:54,414 INFO L858 garLoopResultBuilder]: For program point cleanupEXIT(lines 906 935) no Hoare annotation was computed. [2021-12-16 00:58:54,414 INFO L858 garLoopResultBuilder]: For program point L927(line 927) no Hoare annotation was computed. [2021-12-16 00:58:54,415 INFO L861 garLoopResultBuilder]: At program point cleanupENTRY(lines 906 935) the Hoare annotation is: true [2021-12-16 00:58:54,415 INFO L858 garLoopResultBuilder]: For program point L920(lines 920 924) no Hoare annotation was computed. [2021-12-16 00:58:54,415 INFO L861 garLoopResultBuilder]: At program point L920-1(lines 920 924) the Hoare annotation is: true [2021-12-16 00:58:54,415 INFO L858 garLoopResultBuilder]: For program point L917(line 917) no Hoare annotation was computed. [2021-12-16 00:58:54,415 INFO L861 garLoopResultBuilder]: At program point L916-2(lines 916 930) the Hoare annotation is: true [2021-12-16 00:58:54,415 INFO L861 garLoopResultBuilder]: At program point L912(line 912) the Hoare annotation is: true [2021-12-16 00:58:54,415 INFO L858 garLoopResultBuilder]: For program point L912-1(line 912) no Hoare annotation was computed. [2021-12-16 00:58:54,415 INFO L861 garLoopResultBuilder]: At program point L931(lines 906 935) the Hoare annotation is: true [2021-12-16 00:58:54,415 INFO L854 garLoopResultBuilder]: At program point L481(lines 466 484) the Hoare annotation is: (let ((.cse1 (not (= |old(~pumpRunning~0)| 0))) (.cse2 (not (<= 1 |old(~waterLevel~0)|))) (.cse3 (not (= ~methaneLevelCritical~0 0))) (.cse4 (not (<= 2 |old(~waterLevel~0)|))) (.cse5 (= 0 ~systemActive~0)) (.cse0 (not (<= 1 ~methaneLevelCritical~0))) (.cse6 (and (<= 1 |timeShift_isLowWaterLevel_~tmp___0~3#1|) (<= 1 |timeShift_isLowWaterLevel_#res#1|) (= ~pumpRunning~0 |old(~pumpRunning~0)|) (= |timeShift_isLowWaterSensorDry_#res#1| 0) (<= 1 ~waterLevel~0) (= |timeShift_isLowWaterLevel_~tmp~6#1| 0)))) (and (or .cse0 .cse1 .cse2) (or .cse1 .cse3 .cse2) (or .cse4 .cse5 .cse3 .cse6) (or .cse4 .cse5 .cse0 .cse6))) [2021-12-16 00:58:54,415 INFO L858 garLoopResultBuilder]: For program point L64(lines 64 68) no Hoare annotation was computed. [2021-12-16 00:58:54,416 INFO L854 garLoopResultBuilder]: At program point L64-2(lines 60 71) the Hoare annotation is: (let ((.cse3 (not (<= 2 |old(~waterLevel~0)|))) (.cse4 (= 0 ~systemActive~0)) (.cse0 (not (<= 1 ~methaneLevelCritical~0))) (.cse5 (and (= ~pumpRunning~0 |old(~pumpRunning~0)|) (<= 1 ~waterLevel~0))) (.cse1 (not (= |old(~pumpRunning~0)| 0))) (.cse6 (not (= ~methaneLevelCritical~0 0))) (.cse2 (not (<= 1 |old(~waterLevel~0)|)))) (and (or .cse0 .cse1 .cse2) (or .cse3 .cse4 .cse5 .cse6) (or .cse3 .cse4 .cse0 .cse5) (or .cse1 .cse6 .cse2))) [2021-12-16 00:58:54,416 INFO L854 garLoopResultBuilder]: At program point L407(lines 402 410) the Hoare annotation is: (let ((.cse1 (not (= ~methaneLevelCritical~0 0))) (.cse3 (= 0 ~systemActive~0)) (.cse2 (not (<= 2 |old(~waterLevel~0)|))) (.cse5 (not (<= 1 ~methaneLevelCritical~0))) (.cse0 (not (= |old(~pumpRunning~0)| 0))) (.cse6 (= |timeShift_isPumpRunning_#res#1| 0)) (.cse4 (= ~pumpRunning~0 0))) (and (or .cse0 .cse1 (not (<= 1 |old(~waterLevel~0)|))) (or .cse2 .cse3 .cse1) (or .cse2 .cse3 (and (= ~pumpRunning~0 |old(~pumpRunning~0)|) .cse4) .cse5 (and (<= 1 |timeShift_isLowWaterLevel_~tmp___0~3#1|) .cse6 (<= 1 |timeShift_isLowWaterLevel_#res#1|) (= |timeShift_isLowWaterSensorDry_#res#1| 0) (<= 1 |timeShift_processEnvironment_~tmp~3#1|) (<= 1 ~waterLevel~0) (= |timeShift_isLowWaterLevel_~tmp~6#1| 0) .cse4)) (or .cse2 .cse5 (and .cse6 (<= 2 ~waterLevel~0) .cse4) .cse0) (or (not (= |old(~waterLevel~0)| 1)) .cse5 .cse0 (and (= ~waterLevel~0 1) .cse6 .cse4)))) [2021-12-16 00:58:54,416 INFO L858 garLoopResultBuilder]: For program point timeShiftFINAL(lines 274 297) no Hoare annotation was computed. [2021-12-16 00:58:54,416 INFO L858 garLoopResultBuilder]: For program point L193(line 193) no Hoare annotation was computed. [2021-12-16 00:58:54,416 INFO L854 garLoopResultBuilder]: At program point L156(lines 151 159) the Hoare annotation is: (let ((.cse0 (not (<= 1 ~methaneLevelCritical~0))) (.cse1 (not (= |old(~pumpRunning~0)| 0))) (.cse2 (not (<= 1 |old(~waterLevel~0)|))) (.cse3 (not (<= 2 |old(~waterLevel~0)|))) (.cse4 (= 0 ~systemActive~0)) (.cse6 (not (= ~methaneLevelCritical~0 0))) (.cse5 (and (= ~pumpRunning~0 |old(~pumpRunning~0)|) (= |timeShift_isLowWaterSensorDry_#res#1| 0) (<= 1 ~waterLevel~0)))) (and (or .cse0 .cse1 .cse2) (or .cse3 .cse4 .cse0 .cse5) (or .cse1 .cse6 .cse2) (or .cse3 .cse4 .cse6 .cse5))) [2021-12-16 00:58:54,416 INFO L854 garLoopResultBuilder]: At program point L346(line 346) the Hoare annotation is: (let ((.cse0 (not (<= 1 ~methaneLevelCritical~0))) (.cse1 (not (= |old(~pumpRunning~0)| 0))) (.cse2 (not (<= 1 |old(~waterLevel~0)|))) (.cse3 (not (<= 2 |old(~waterLevel~0)|))) (.cse4 (= 0 ~systemActive~0)) (.cse5 (not (= ~methaneLevelCritical~0 0)))) (and (or .cse0 .cse1 .cse2) (or .cse3 .cse4 .cse0) (or .cse1 .cse5 .cse2) (or .cse3 .cse4 .cse5))) [2021-12-16 00:58:54,417 INFO L854 garLoopResultBuilder]: At program point L342(line 342) the Hoare annotation is: (let ((.cse1 (not (= |old(~pumpRunning~0)| 0))) (.cse5 (not (= ~methaneLevelCritical~0 0))) (.cse2 (not (<= 1 |old(~waterLevel~0)|))) (.cse3 (not (<= 2 |old(~waterLevel~0)|))) (.cse4 (= 0 ~systemActive~0)) (.cse0 (not (<= 1 ~methaneLevelCritical~0))) (.cse6 (and (<= 1 |timeShift_isLowWaterLevel_~tmp___0~3#1|) (<= 1 |timeShift_isLowWaterLevel_#res#1|) (= ~pumpRunning~0 |old(~pumpRunning~0)|) (= |timeShift_isLowWaterSensorDry_#res#1| 0) (<= 1 |timeShift_processEnvironment_~tmp~3#1|) (<= 1 ~waterLevel~0) (= |timeShift_isLowWaterLevel_~tmp~6#1| 0)))) (and (or .cse0 .cse1 .cse2) (or .cse3 .cse4 .cse5 .cse6) (or .cse1 .cse5 .cse2) (or .cse3 .cse4 .cse0 .cse6))) [2021-12-16 00:58:54,417 INFO L854 garLoopResultBuilder]: At program point L169(line 169) the Hoare annotation is: (let ((.cse11 (= ~methaneLevelCritical~0 0)) (.cse1 (= 0 ~systemActive~0)) (.cse12 (<= 2 ~waterLevel~0)) (.cse8 (= ~pumpRunning~0 0))) (let ((.cse5 (and .cse12 .cse8)) (.cse4 (and .cse11 .cse12 (not .cse1))) (.cse0 (not (<= 2 |old(~waterLevel~0)|))) (.cse2 (and (<= 1 |timeShift_isLowWaterLevel_~tmp___0~3#1|) (<= 1 |timeShift_isLowWaterLevel_#res#1|) (= |timeShift_isLowWaterSensorDry_#res#1| 0) (<= 1 |timeShift_processEnvironment_~tmp~3#1|) (<= 1 ~waterLevel~0) (= |timeShift_isLowWaterLevel_~tmp~6#1| 0) .cse8)) (.cse6 (not (<= 1 ~methaneLevelCritical~0))) (.cse9 (not (= |old(~waterLevel~0)| 1))) (.cse7 (not (= |old(~pumpRunning~0)| 0))) (.cse10 (and (= ~waterLevel~0 1) .cse8)) (.cse3 (not .cse11))) (and (or .cse0 .cse1 .cse2 .cse3 .cse4) (or .cse0 .cse5 .cse6 .cse7) (or .cse0 .cse5 .cse7 .cse3 .cse4) (or .cse0 .cse1 .cse2 (and (= ~pumpRunning~0 |old(~pumpRunning~0)|) .cse8) .cse6) (or .cse9 .cse6 .cse7 .cse10) (or .cse9 .cse7 .cse10 .cse3)))) [2021-12-16 00:58:54,417 INFO L858 garLoopResultBuilder]: For program point L169-1(line 169) no Hoare annotation was computed. [2021-12-16 00:58:54,417 INFO L854 garLoopResultBuilder]: At program point L194(lines 189 196) the Hoare annotation is: (let ((.cse0 (not (<= 1 ~methaneLevelCritical~0))) (.cse1 (not (= |old(~pumpRunning~0)| 0))) (.cse2 (not (<= 1 |old(~waterLevel~0)|))) (.cse3 (not (<= 2 |old(~waterLevel~0)|))) (.cse4 (= 0 ~systemActive~0)) (.cse5 (not (= ~methaneLevelCritical~0 0)))) (and (or .cse0 .cse1 .cse2) (or .cse3 .cse4 .cse0) (or .cse1 .cse5 .cse2) (or .cse3 .cse4 .cse5))) [2021-12-16 00:58:54,417 INFO L854 garLoopResultBuilder]: At program point L351(line 351) the Hoare annotation is: (let ((.cse1 (= 0 ~systemActive~0))) (let ((.cse13 (= ~methaneLevelCritical~0 0)) (.cse12 (= ~pumpRunning~0 |old(~pumpRunning~0)|)) (.cse10 (not .cse1)) (.cse11 (= ~pumpRunning~0 0))) (let ((.cse4 (not (= |old(~waterLevel~0)| 1))) (.cse5 (= ~waterLevel~0 1)) (.cse2 (and .cse13 .cse12 (<= 1 ~waterLevel~0) .cse10 .cse11)) (.cse3 (not .cse13)) (.cse7 (not (= |old(~pumpRunning~0)| 0))) (.cse9 (not (<= 1 |old(~waterLevel~0)|))) (.cse0 (not (<= 2 |old(~waterLevel~0)|))) (.cse6 (not (<= 1 ~methaneLevelCritical~0))) (.cse8 (<= 2 ~waterLevel~0))) (and (or .cse0 .cse1 .cse2 .cse3) (or .cse4 .cse5 .cse6 .cse7) (or .cse4 .cse5 .cse7 .cse3) (or .cse0 .cse7 .cse8 .cse3) (or .cse2 .cse7 .cse3 .cse9) (or (and .cse10 .cse11) .cse6 .cse7 .cse9) (or .cse0 .cse1 .cse6 (and .cse12 .cse8 .cse11)))))) [2021-12-16 00:58:54,417 INFO L854 garLoopResultBuilder]: At program point L351-1(lines 332 356) the Hoare annotation is: (let ((.cse7 (= 0 ~systemActive~0))) (let ((.cse12 (<= 1 ~methaneLevelCritical~0)) (.cse10 (= ~pumpRunning~0 0)) (.cse14 (= ~methaneLevelCritical~0 0)) (.cse13 (<= 2 ~waterLevel~0)) (.cse9 (not .cse7))) (let ((.cse6 (and .cse14 .cse13 .cse9)) (.cse0 (not (= |old(~waterLevel~0)| 1))) (.cse1 (= ~waterLevel~0 1)) (.cse5 (not .cse14)) (.cse8 (and (<= 1 |timeShift_isLowWaterLevel_~tmp___0~3#1|) (<= 1 |timeShift_isLowWaterLevel_#res#1|) (= |timeShift_isLowWaterSensorDry_#res#1| 0) (<= 1 |timeShift_processEnvironment_~tmp~3#1|) (<= 1 ~waterLevel~0) (= |timeShift_isLowWaterLevel_~tmp~6#1| 0) .cse10)) (.cse4 (not (<= 2 |old(~waterLevel~0)|))) (.cse11 (and (= ~pumpRunning~0 |old(~pumpRunning~0)|) .cse13 .cse12 .cse9 .cse10)) (.cse2 (not .cse12)) (.cse3 (not (= |old(~pumpRunning~0)| 0)))) (and (or .cse0 .cse1 .cse2 .cse3) (or .cse4 .cse3 .cse5 .cse6) (or .cse4 .cse7 .cse8 .cse5 .cse6) (or .cse0 (and .cse1 .cse9 .cse10) .cse3 .cse5) (or .cse4 .cse7 .cse8 .cse2 .cse11) (or .cse4 .cse2 .cse3 .cse11) (or (and .cse9 .cse10) .cse2 .cse3 (not (<= 1 |old(~waterLevel~0)|))))))) [2021-12-16 00:58:54,417 INFO L858 garLoopResultBuilder]: For program point L285-1(lines 285 291) no Hoare annotation was computed. [2021-12-16 00:58:54,418 INFO L858 garLoopResultBuilder]: For program point L475(lines 475 479) no Hoare annotation was computed. [2021-12-16 00:58:54,418 INFO L858 garLoopResultBuilder]: For program point L475-2(lines 475 479) no Hoare annotation was computed. [2021-12-16 00:58:54,418 INFO L858 garLoopResultBuilder]: For program point L278-1(lines 277 296) no Hoare annotation was computed. [2021-12-16 00:58:54,418 INFO L858 garLoopResultBuilder]: For program point L340(lines 340 348) no Hoare annotation was computed. [2021-12-16 00:58:54,418 INFO L858 garLoopResultBuilder]: For program point L336(lines 336 353) no Hoare annotation was computed. [2021-12-16 00:58:54,418 INFO L854 garLoopResultBuilder]: At program point timeShiftENTRY(lines 274 297) the Hoare annotation is: (let ((.cse8 (<= 2 ~waterLevel~0))) (let ((.cse0 (not (= |old(~waterLevel~0)| 1))) (.cse1 (= ~waterLevel~0 1)) (.cse4 (not (= ~methaneLevelCritical~0 0))) (.cse5 (not (<= 2 |old(~waterLevel~0)|))) (.cse6 (= 0 ~systemActive~0)) (.cse7 (and (= ~pumpRunning~0 |old(~pumpRunning~0)|) .cse8)) (.cse2 (not (<= 1 ~methaneLevelCritical~0))) (.cse3 (not (= |old(~pumpRunning~0)| 0))) (.cse9 (not (<= 1 |old(~waterLevel~0)|))) (.cse10 (= ~pumpRunning~0 0))) (and (or .cse0 .cse1 .cse2 .cse3) (or .cse0 .cse1 .cse3 .cse4) (or .cse5 .cse6 .cse7 .cse4) (or .cse5 .cse3 .cse8 .cse4) (or .cse5 .cse2 .cse3 .cse8) (or .cse3 .cse4 .cse9 .cse10) (or .cse5 .cse6 .cse7 .cse2) (or .cse2 .cse3 .cse9 .cse10)))) [2021-12-16 00:58:54,418 INFO L858 garLoopResultBuilder]: For program point L175(lines 175 181) no Hoare annotation was computed. [2021-12-16 00:58:54,419 INFO L858 garLoopResultBuilder]: For program point L171(lines 171 184) no Hoare annotation was computed. [2021-12-16 00:58:54,419 INFO L858 garLoopResultBuilder]: For program point timeShiftEXIT(lines 274 297) no Hoare annotation was computed. [2021-12-16 00:58:54,419 INFO L854 garLoopResultBuilder]: At program point L171-1(lines 163 187) the Hoare annotation is: (let ((.cse5 (= 0 ~systemActive~0))) (let ((.cse9 (= |timeShift___utac_acc__Specification1_spec__1_~tmp~0#1| 0)) (.cse18 (<= 2 ~waterLevel~0)) (.cse19 (not .cse5))) (let ((.cse0 (not (= |old(~waterLevel~0)| 1))) (.cse1 (= ~waterLevel~0 1)) (.cse4 (not (<= 2 |old(~waterLevel~0)|))) (.cse2 (not (<= 1 ~methaneLevelCritical~0))) (.cse7 (<= 1 |timeShift_isLowWaterLevel_~tmp___0~3#1|)) (.cse8 (<= 1 |timeShift_isLowWaterLevel_#res#1|)) (.cse10 (= |timeShift_isLowWaterSensorDry_#res#1| 0)) (.cse11 (<= 1 |timeShift_processEnvironment_~tmp~3#1|)) (.cse12 (<= 1 ~waterLevel~0)) (.cse13 (= |timeShift_isLowWaterLevel_~tmp~6#1| 0)) (.cse16 (= ~pumpRunning~0 |old(~pumpRunning~0)|)) (.cse6 (and .cse9 .cse18 .cse19)) (.cse14 (= ~pumpRunning~0 0)) (.cse3 (not (= |old(~pumpRunning~0)| 0))) (.cse15 (not (= ~methaneLevelCritical~0 0))) (.cse17 (not (<= 1 |old(~waterLevel~0)|)))) (and (or .cse0 .cse1 .cse2 .cse3) (or .cse4 .cse5 .cse6 (and .cse7 .cse8 .cse9 .cse10 .cse11 .cse12 .cse13 .cse14) .cse15) (or .cse2 .cse3 .cse16 .cse17) (or .cse0 .cse1 .cse3 .cse15) (or .cse4 .cse3 .cse18 .cse15) (or .cse4 .cse2 .cse3 .cse18) (or .cse4 .cse5 .cse2 (and .cse7 .cse8 .cse10 .cse11 .cse12 .cse19 .cse13 .cse14) (and .cse16 .cse19 .cse14)) (or .cse6 (and .cse9 .cse14) .cse3 .cse15 .cse17))))) [2021-12-16 00:58:54,419 INFO L858 garLoopResultBuilder]: For program point timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION(line 193) no Hoare annotation was computed. [2021-12-16 00:58:54,419 INFO L861 garLoopResultBuilder]: At program point isMethaneLevelCriticalENTRY(lines 96 104) the Hoare annotation is: true [2021-12-16 00:58:54,419 INFO L858 garLoopResultBuilder]: For program point isMethaneLevelCriticalFINAL(lines 96 104) no Hoare annotation was computed. [2021-12-16 00:58:54,419 INFO L858 garLoopResultBuilder]: For program point isMethaneLevelCriticalEXIT(lines 96 104) no Hoare annotation was computed. [2021-12-16 00:58:54,419 INFO L858 garLoopResultBuilder]: For program point L221(lines 221 227) no Hoare annotation was computed. [2021-12-16 00:58:54,419 INFO L858 garLoopResultBuilder]: For program point L221-1(lines 221 227) no Hoare annotation was computed. [2021-12-16 00:58:54,419 INFO L858 garLoopResultBuilder]: For program point L213(lines 213 217) no Hoare annotation was computed. [2021-12-16 00:58:54,420 INFO L854 garLoopResultBuilder]: At program point L259(lines 210 260) the Hoare annotation is: false [2021-12-16 00:58:54,420 INFO L858 garLoopResultBuilder]: For program point L-1(line -1) no Hoare annotation was computed. [2021-12-16 00:58:54,420 INFO L858 garLoopResultBuilder]: For program point ULTIMATE.startENTRY(line -1) no Hoare annotation was computed. [2021-12-16 00:58:54,420 INFO L858 garLoopResultBuilder]: For program point ULTIMATE.startFINAL(line -1) no Hoare annotation was computed. [2021-12-16 00:58:54,420 INFO L858 garLoopResultBuilder]: For program point L247(lines 247 253) no Hoare annotation was computed. [2021-12-16 00:58:54,420 INFO L854 garLoopResultBuilder]: At program point L247-2(lines 241 254) the Hoare annotation is: (let ((.cse4 (<= 2 ~waterLevel~0)) (.cse5 (not (= 0 ~systemActive~0))) (.cse6 (<= 1 ~methaneLevelCritical~0)) (.cse0 (= |ULTIMATE.start_test_~splverifierCounter~0#1| 0)) (.cse1 (= 1 |ULTIMATE.start_main_~tmp~10#1|)) (.cse2 (= ~methaneLevelCritical~0 0)) (.cse3 (= 1 |ULTIMATE.start_valid_product_#res#1|)) (.cse7 (<= 1 ~waterLevel~0)) (.cse8 (= ~pumpRunning~0 0))) (or (and .cse0 .cse1 .cse2 .cse3 .cse4 .cse5) (and .cse0 .cse1 .cse3 .cse4 .cse6 .cse5) (and .cse0 .cse1 .cse3 .cse6 .cse7 .cse8) (and .cse0 .cse1 .cse2 .cse3 .cse7 .cse8))) [2021-12-16 00:58:54,420 INFO L861 garLoopResultBuilder]: At program point L974(lines 967 976) the Hoare annotation is: true [2021-12-16 00:58:54,420 INFO L854 garLoopResultBuilder]: At program point L491(line 491) the Hoare annotation is: (let ((.cse0 (= |ULTIMATE.start_test_~splverifierCounter~0#1| 0)) (.cse1 (= 1 |ULTIMATE.start_main_~tmp~10#1|)) (.cse2 (= 1 |ULTIMATE.start_valid_product_#res#1|)) (.cse3 (<= 2 ~waterLevel~0)) (.cse4 (not (= 0 ~systemActive~0)))) (or (and .cse0 .cse1 (= ~methaneLevelCritical~0 0) .cse2 .cse3 .cse4) (and .cse0 .cse1 .cse2 .cse3 (<= 1 ~methaneLevelCritical~0) .cse4))) [2021-12-16 00:58:54,420 INFO L858 garLoopResultBuilder]: For program point L231(lines 231 237) no Hoare annotation was computed. [2021-12-16 00:58:54,420 INFO L858 garLoopResultBuilder]: For program point L231-1(lines 231 237) no Hoare annotation was computed. [2021-12-16 00:58:54,420 INFO L854 garLoopResultBuilder]: At program point L900(lines 895 903) the Hoare annotation is: (and (= ~waterLevel~0 1) (= ~methaneLevelCritical~0 0) (= 1 |ULTIMATE.start_valid_product_#res#1|) (= ~systemActive~0 1) (= ~pumpRunning~0 0)) [2021-12-16 00:58:54,420 INFO L858 garLoopResultBuilder]: For program point ULTIMATE.startEXIT(line -1) no Hoare annotation was computed. [2021-12-16 00:58:54,420 INFO L854 garLoopResultBuilder]: At program point L256(lines 211 258) the Hoare annotation is: (let ((.cse0 (= |ULTIMATE.start_test_~splverifierCounter~0#1| 0)) (.cse1 (= 1 |ULTIMATE.start_main_~tmp~10#1|)) (.cse2 (= ~methaneLevelCritical~0 0)) (.cse3 (= 1 |ULTIMATE.start_valid_product_#res#1|)) (.cse4 (<= 1 ~waterLevel~0)) (.cse5 (= ~pumpRunning~0 0))) (or (and .cse0 .cse1 .cse2 .cse3 (<= 2 ~waterLevel~0) (not (= 0 ~systemActive~0))) (and .cse0 .cse1 .cse3 (<= 1 ~methaneLevelCritical~0) .cse4 .cse5) (and .cse0 .cse1 .cse2 .cse3 .cse4 .cse5))) [2021-12-16 00:58:54,421 INFO L854 garLoopResultBuilder]: At program point L223(line 223) the Hoare annotation is: (let ((.cse0 (= |ULTIMATE.start_test_~splverifierCounter~0#1| 0)) (.cse1 (= 1 |ULTIMATE.start_main_~tmp~10#1|)) (.cse2 (= ~methaneLevelCritical~0 0)) (.cse3 (= 1 |ULTIMATE.start_valid_product_#res#1|)) (.cse4 (<= 1 ~waterLevel~0)) (.cse5 (= ~pumpRunning~0 0))) (or (and .cse0 .cse1 .cse2 .cse3 (<= 2 ~waterLevel~0) (not (= 0 ~systemActive~0))) (and .cse0 .cse1 .cse3 (<= 1 ~methaneLevelCritical~0) .cse4 .cse5) (and .cse0 .cse1 .cse2 .cse3 .cse4 .cse5))) [2021-12-16 00:58:54,421 INFO L854 garLoopResultBuilder]: At program point L892(lines 888 894) the Hoare annotation is: (and (= ~waterLevel~0 1) (= ~methaneLevelCritical~0 0) (= ~systemActive~0 1) (= ~pumpRunning~0 0)) [2021-12-16 00:58:54,421 INFO L858 garLoopResultBuilder]: For program point L987(lines 987 994) no Hoare annotation was computed. [2021-12-16 00:58:54,421 INFO L858 garLoopResultBuilder]: For program point L987-2(lines 987 994) no Hoare annotation was computed. [2021-12-16 00:58:54,421 INFO L861 garLoopResultBuilder]: At program point L996(lines 977 999) the Hoare annotation is: true [2021-12-16 00:58:54,421 INFO L854 garLoopResultBuilder]: At program point L885(lines 881 887) the Hoare annotation is: (and (= ~waterLevel~0 1) (= ~methaneLevelCritical~0 0) (= ~systemActive~0 1) (= ~pumpRunning~0 0)) [2021-12-16 00:58:54,421 INFO L858 garLoopResultBuilder]: For program point L212(lines 211 258) no Hoare annotation was computed. [2021-12-16 00:58:54,422 INFO L858 garLoopResultBuilder]: For program point L241(lines 241 254) no Hoare annotation was computed. [2021-12-16 00:58:54,422 INFO L854 garLoopResultBuilder]: At program point L497(lines 485 499) the Hoare annotation is: (let ((.cse0 (= |ULTIMATE.start_test_~splverifierCounter~0#1| 0)) (.cse1 (= 1 |ULTIMATE.start_main_~tmp~10#1|)) (.cse2 (= 1 |ULTIMATE.start_valid_product_#res#1|)) (.cse3 (<= 1 ~waterLevel~0)) (.cse4 (= ~pumpRunning~0 0))) (or (and .cse0 .cse1 .cse2 (<= 1 ~methaneLevelCritical~0) .cse3 .cse4) (and .cse0 .cse1 (= ~methaneLevelCritical~0 0) .cse2 .cse3 .cse4))) [2021-12-16 00:58:54,422 INFO L854 garLoopResultBuilder]: At program point L233(line 233) the Hoare annotation is: (let ((.cse0 (= |ULTIMATE.start_test_~splverifierCounter~0#1| 0)) (.cse1 (= 1 |ULTIMATE.start_main_~tmp~10#1|)) (.cse2 (= ~methaneLevelCritical~0 0)) (.cse3 (= 1 |ULTIMATE.start_valid_product_#res#1|)) (.cse4 (<= 1 ~waterLevel~0)) (.cse5 (= ~pumpRunning~0 0))) (or (and .cse0 .cse1 .cse2 .cse3 (<= 2 ~waterLevel~0) (not (= 0 ~systemActive~0))) (and .cse0 .cse1 .cse3 (<= 1 ~methaneLevelCritical~0) .cse4 .cse5) (and .cse0 .cse1 .cse2 .cse3 .cse4 .cse5))) [2021-12-16 00:58:54,422 INFO L858 garLoopResultBuilder]: For program point L489(lines 489 495) no Hoare annotation was computed. [2021-12-16 00:58:54,422 INFO L858 garLoopResultBuilder]: For program point L489-1(lines 489 495) no Hoare annotation was computed. [2021-12-16 00:58:54,422 INFO L861 garLoopResultBuilder]: At program point L262(lines 201 266) the Hoare annotation is: true [2021-12-16 00:58:54,422 INFO L854 garLoopResultBuilder]: At program point L964(lines 960 966) the Hoare annotation is: (and (= ~waterLevel~0 1) (= 1 |ULTIMATE.start_main_~tmp~10#1|) (= ~methaneLevelCritical~0 0) (= 1 |ULTIMATE.start_valid_product_#res#1|) (= ~systemActive~0 1) (= ~pumpRunning~0 0)) [2021-12-16 00:58:54,423 INFO L854 garLoopResultBuilder]: At program point processEnvironment__wrappee__highWaterSensorENTRY(lines 306 330) the Hoare annotation is: (let ((.cse0 (= 0 ~systemActive~0)) (.cse1 (not (<= 1 ~waterLevel~0))) (.cse2 (not (= |old(~pumpRunning~0)| 0))) (.cse3 (= ~pumpRunning~0 0))) (and (or .cse0 .cse1 .cse2 (not (= ~methaneLevelCritical~0 0)) .cse3) (or .cse0 .cse1 (not (<= 1 ~methaneLevelCritical~0)) .cse2 .cse3))) [2021-12-16 00:58:54,423 INFO L854 garLoopResultBuilder]: At program point L320(line 320) the Hoare annotation is: (let ((.cse0 (= 0 ~systemActive~0)) (.cse1 (not (<= 1 ~waterLevel~0))) (.cse2 (and (= |processEnvironment__wrappee__highWaterSensor_~tmp~2#1| 0) (= ~pumpRunning~0 0))) (.cse3 (not (= |old(~pumpRunning~0)| 0)))) (and (or .cse0 .cse1 .cse2 .cse3 (not (= ~methaneLevelCritical~0 0))) (or .cse0 .cse1 (not (<= 1 ~methaneLevelCritical~0)) .cse2 .cse3))) [2021-12-16 00:58:54,423 INFO L858 garLoopResultBuilder]: For program point L314(lines 314 322) no Hoare annotation was computed. [2021-12-16 00:58:54,423 INFO L858 garLoopResultBuilder]: For program point L310(lines 310 327) no Hoare annotation was computed. [2021-12-16 00:58:54,423 INFO L858 garLoopResultBuilder]: For program point L141(lines 141 147) no Hoare annotation was computed. [2021-12-16 00:58:54,423 INFO L854 garLoopResultBuilder]: At program point L362(lines 357 364) the Hoare annotation is: (let ((.cse0 (= 0 ~systemActive~0)) (.cse1 (not (<= 1 ~waterLevel~0))) (.cse2 (not (= |old(~pumpRunning~0)| 0)))) (and (or .cse0 .cse1 .cse2 (<= 2 ~waterLevel~0) (not (= ~methaneLevelCritical~0 0))) (or .cse0 .cse1 (not (<= 1 ~methaneLevelCritical~0)) .cse2))) [2021-12-16 00:58:54,424 INFO L854 garLoopResultBuilder]: At program point L325(line 325) the Hoare annotation is: (let ((.cse0 (= 0 ~systemActive~0)) (.cse1 (not (<= 1 ~waterLevel~0))) (.cse2 (not (= |old(~pumpRunning~0)| 0)))) (and (or .cse0 .cse1 .cse2 (not (= ~methaneLevelCritical~0 0))) (or .cse0 .cse1 (not (<= 1 ~methaneLevelCritical~0)) .cse2))) [2021-12-16 00:58:54,424 INFO L858 garLoopResultBuilder]: For program point L325-1(lines 306 330) no Hoare annotation was computed. [2021-12-16 00:58:54,424 INFO L858 garLoopResultBuilder]: For program point processEnvironment__wrappee__highWaterSensorEXIT(lines 306 330) no Hoare annotation was computed. [2021-12-16 00:58:54,424 INFO L858 garLoopResultBuilder]: For program point L373(lines 373 379) no Hoare annotation was computed. [2021-12-16 00:58:54,424 INFO L854 garLoopResultBuilder]: At program point L373-2(lines 366 382) the Hoare annotation is: (let ((.cse1 (not (= ~waterLevel~0 1))) (.cse0 (= 0 ~systemActive~0)) (.cse3 (not (<= 1 ~methaneLevelCritical~0))) (.cse2 (not (= |old(~pumpRunning~0)| 0)))) (and (or .cse0 .cse1 .cse2 (not (= ~methaneLevelCritical~0 0))) (or .cse0 .cse1 .cse3 .cse2) (or .cse0 (and (<= ~methaneLevelCritical~0 |processEnvironment__wrappee__highWaterSensor_isMethaneAlarm_#res#1|) (<= ~methaneLevelCritical~0 |processEnvironment__wrappee__highWaterSensor_activatePump_~tmp~4#1|) (= ~pumpRunning~0 0)) .cse3 .cse2 (not (<= 2 ~waterLevel~0))))) [2021-12-16 00:58:54,424 INFO L854 garLoopResultBuilder]: At program point L146(lines 137 150) the Hoare annotation is: (let ((.cse5 (= ~pumpRunning~0 0))) (let ((.cse3 (not (= ~methaneLevelCritical~0 0))) (.cse0 (= 0 ~systemActive~0)) (.cse4 (<= 2 ~waterLevel~0)) (.cse1 (and (not (= |processEnvironment__wrappee__highWaterSensor_isHighWaterSensorDry_#res#1| 0)) .cse5)) (.cse2 (not (= |old(~pumpRunning~0)| 0)))) (and (or .cse0 .cse1 (not (= ~waterLevel~0 1)) .cse2 .cse3) (or .cse0 .cse2 .cse3 (not .cse4) .cse5) (or .cse0 (and .cse4 .cse5) .cse1 (not (<= 1 ~waterLevel~0)) (not (<= 1 ~methaneLevelCritical~0)) .cse2)))) [2021-12-16 00:58:54,425 INFO L854 garLoopResultBuilder]: At program point L462(lines 447 465) the Hoare annotation is: (let ((.cse7 (= ~pumpRunning~0 0))) (let ((.cse1 (and (<= 2 ~waterLevel~0) .cse7)) (.cse0 (= 0 ~systemActive~0)) (.cse5 (not (<= 1 ~waterLevel~0))) (.cse2 (not (= 0 |processEnvironment__wrappee__highWaterSensor_isHighWaterLevel_~tmp~5#1|))) (.cse3 (= |processEnvironment__wrappee__highWaterSensor_isHighWaterLevel_#res#1| 0)) (.cse4 (= |processEnvironment__wrappee__highWaterSensor_isHighWaterLevel_~tmp___0~2#1| 0)) (.cse6 (not (= |old(~pumpRunning~0)| 0)))) (and (or .cse0 .cse1 (and .cse2 .cse3 (= ~pumpRunning~0 |old(~pumpRunning~0)|) .cse4) .cse5 (not (<= 1 ~methaneLevelCritical~0)) .cse6) (or .cse1 .cse0 .cse5 (and .cse2 .cse3 .cse4 .cse7) .cse6 (not (= ~methaneLevelCritical~0 0)))))) [2021-12-16 00:58:54,425 INFO L854 garLoopResultBuilder]: At program point L398(lines 391 401) the Hoare annotation is: (let ((.cse1 (= ~pumpRunning~0 0)) (.cse0 (<= 2 ~waterLevel~0)) (.cse2 (= 0 ~systemActive~0)) (.cse4 (not (<= 1 ~methaneLevelCritical~0))) (.cse3 (not (= |old(~pumpRunning~0)| 0)))) (and (or (and .cse0 .cse1) .cse2 (not (<= 1 ~waterLevel~0)) .cse3 (not (= ~methaneLevelCritical~0 0))) (or .cse2 (and (<= ~methaneLevelCritical~0 |processEnvironment__wrappee__highWaterSensor_isMethaneAlarm_#res#1|) .cse1) .cse4 .cse3 (not .cse0)) (or .cse2 (not (= ~waterLevel~0 1)) .cse4 .cse3))) [2021-12-16 00:58:54,425 INFO L854 garLoopResultBuilder]: At program point L396(line 396) the Hoare annotation is: (let ((.cse1 (= 0 ~systemActive~0)) (.cse0 (and (<= 2 ~waterLevel~0) (= ~pumpRunning~0 0))) (.cse2 (not (<= 1 ~waterLevel~0))) (.cse3 (not (= |old(~pumpRunning~0)| 0)))) (and (or .cse0 .cse1 .cse2 .cse3 (not (= ~methaneLevelCritical~0 0))) (or .cse1 .cse0 .cse2 (not (<= 1 ~methaneLevelCritical~0)) .cse3))) [2021-12-16 00:58:54,425 INFO L858 garLoopResultBuilder]: For program point L396-1(line 396) no Hoare annotation was computed. [2021-12-16 00:58:54,425 INFO L858 garLoopResultBuilder]: For program point L456(lines 456 460) no Hoare annotation was computed. [2021-12-16 00:58:54,425 INFO L858 garLoopResultBuilder]: For program point L456-2(lines 456 460) no Hoare annotation was computed. [2021-12-16 00:58:54,425 INFO L858 garLoopResultBuilder]: For program point waterRiseEXIT(lines 72 83) no Hoare annotation was computed. [2021-12-16 00:58:54,426 INFO L858 garLoopResultBuilder]: For program point L76-1(lines 72 83) no Hoare annotation was computed. [2021-12-16 00:58:54,426 INFO L854 garLoopResultBuilder]: At program point waterRiseENTRY(lines 72 83) the Hoare annotation is: (let ((.cse0 (not (<= 2 |old(~waterLevel~0)|))) (.cse6 (not (<= 1 ~methaneLevelCritical~0))) (.cse1 (<= 2 ~waterLevel~0)) (.cse3 (not (= |old(~waterLevel~0)| 1))) (.cse5 (not (= ~pumpRunning~0 0))) (.cse4 (= ~waterLevel~0 1)) (.cse2 (not (= ~methaneLevelCritical~0 0)))) (and (or .cse0 (= 0 ~systemActive~0) .cse1 .cse2) (or .cse3 .cse4 .cse5 .cse6) (or .cse0 .cse5 .cse1 .cse2) (or .cse0 .cse5 .cse6 .cse1) (or .cse3 .cse5 .cse4 .cse2))) [2021-12-16 00:58:54,428 INFO L732 BasicCegarLoop]: Path program histogram: [1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2021-12-16 00:58:54,430 INFO L179 ceAbstractionStarter]: Computing trace abstraction results [2021-12-16 00:58:54,456 INFO L202 PluginConnector]: Adding new model de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction CFG 16.12 12:58:54 BoogieIcfgContainer [2021-12-16 00:58:54,456 INFO L132 PluginConnector]: ------------------------ END TraceAbstraction---------------------------- [2021-12-16 00:58:54,457 INFO L113 PluginConnector]: ------------------------Witness Printer---------------------------- [2021-12-16 00:58:54,457 INFO L271 PluginConnector]: Initializing Witness Printer... [2021-12-16 00:58:54,457 INFO L275 PluginConnector]: Witness Printer initialized [2021-12-16 00:58:54,457 INFO L185 PluginConnector]: Executing the observer RCFGCatcher from plugin Witness Printer for "de.uni_freiburg.informatik.ultimate.plugins.generator.rcfgbuilder CFG 16.12 12:58:44" (3/4) ... [2021-12-16 00:58:54,460 INFO L137 WitnessPrinter]: Generating witness for correct program [2021-12-16 00:58:54,464 INFO L354 RCFGBacktranslator]: Ignoring RootEdge to procedure deactivatePump [2021-12-16 00:58:54,464 INFO L354 RCFGBacktranslator]: Ignoring RootEdge to procedure processEnvironment__wrappee__base [2021-12-16 00:58:54,464 INFO L354 RCFGBacktranslator]: Ignoring RootEdge to procedure changeMethaneLevel [2021-12-16 00:58:54,465 INFO L354 RCFGBacktranslator]: Ignoring RootEdge to procedure cleanup [2021-12-16 00:58:54,465 INFO L354 RCFGBacktranslator]: Ignoring RootEdge to procedure timeShift [2021-12-16 00:58:54,465 INFO L354 RCFGBacktranslator]: Ignoring RootEdge to procedure isMethaneLevelCritical [2021-12-16 00:58:54,465 INFO L354 RCFGBacktranslator]: Ignoring RootEdge to procedure processEnvironment__wrappee__highWaterSensor [2021-12-16 00:58:54,465 INFO L354 RCFGBacktranslator]: Ignoring RootEdge to procedure waterRise [2021-12-16 00:58:54,472 INFO L910 BoogieBacktranslator]: Reduced CFG by removing 52 nodes and edges [2021-12-16 00:58:54,472 INFO L910 BoogieBacktranslator]: Reduced CFG by removing 22 nodes and edges [2021-12-16 00:58:54,473 INFO L910 BoogieBacktranslator]: Reduced CFG by removing 11 nodes and edges [2021-12-16 00:58:54,473 INFO L910 BoogieBacktranslator]: Reduced CFG by removing 5 nodes and edges [2021-12-16 00:58:54,474 INFO L910 BoogieBacktranslator]: Reduced CFG by removing 2 nodes and edges [2021-12-16 00:58:54,474 INFO L910 BoogieBacktranslator]: Reduced CFG by removing 1 nodes and edges [2021-12-16 00:58:54,474 INFO L910 BoogieBacktranslator]: Reduced CFG by removing 1 nodes and edges [2021-12-16 00:58:54,492 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (((waterLevel == 1 && methaneLevelCritical == 0) && 1 == \result) && systemActive == 1) && pumpRunning == 0 [2021-12-16 00:58:54,492 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: ((((waterLevel == 1 && 1 == tmp) && methaneLevelCritical == 0) && 1 == \result) && systemActive == 1) && pumpRunning == 0 [2021-12-16 00:58:54,492 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: ((((((splverifierCounter == 0 && 1 == tmp) && methaneLevelCritical == 0) && 1 == \result) && 2 <= waterLevel) && !(0 == systemActive)) || (((((splverifierCounter == 0 && 1 == tmp) && 1 == \result) && 1 <= methaneLevelCritical) && 1 <= waterLevel) && pumpRunning == 0)) || (((((splverifierCounter == 0 && 1 == tmp) && methaneLevelCritical == 0) && 1 == \result) && 1 <= waterLevel) && pumpRunning == 0) [2021-12-16 00:58:54,493 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: ((((!(1 <= methaneLevelCritical) || !(\old(pumpRunning) == 0)) || !(1 <= \old(waterLevel))) && (((!(2 <= \old(waterLevel)) || 0 == systemActive) || (pumpRunning == \old(pumpRunning) && 1 <= waterLevel)) || !(methaneLevelCritical == 0))) && (((!(2 <= \old(waterLevel)) || 0 == systemActive) || !(1 <= methaneLevelCritical)) || (pumpRunning == \old(pumpRunning) && 1 <= waterLevel))) && ((!(\old(pumpRunning) == 0) || !(methaneLevelCritical == 0)) || !(1 <= \old(waterLevel))) [2021-12-16 00:58:54,493 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: ((((((((!(\old(waterLevel) == 1) || waterLevel == 1) || !(1 <= methaneLevelCritical)) || !(\old(pumpRunning) == 0)) && (((!(2 <= \old(waterLevel)) || !(\old(pumpRunning) == 0)) || !(methaneLevelCritical == 0)) || ((methaneLevelCritical == 0 && 2 <= waterLevel) && !(0 == systemActive)))) && ((((!(2 <= \old(waterLevel)) || 0 == systemActive) || ((((((1 <= tmp___0 && 1 <= \result) && \result == 0) && 1 <= tmp) && 1 <= waterLevel) && tmp == 0) && pumpRunning == 0)) || !(methaneLevelCritical == 0)) || ((methaneLevelCritical == 0 && 2 <= waterLevel) && !(0 == systemActive)))) && (((!(\old(waterLevel) == 1) || ((waterLevel == 1 && !(0 == systemActive)) && pumpRunning == 0)) || !(\old(pumpRunning) == 0)) || !(methaneLevelCritical == 0))) && ((((!(2 <= \old(waterLevel)) || 0 == systemActive) || ((((((1 <= tmp___0 && 1 <= \result) && \result == 0) && 1 <= tmp) && 1 <= waterLevel) && tmp == 0) && pumpRunning == 0)) || !(1 <= methaneLevelCritical)) || ((((pumpRunning == \old(pumpRunning) && 2 <= waterLevel) && 1 <= methaneLevelCritical) && !(0 == systemActive)) && pumpRunning == 0))) && (((!(2 <= \old(waterLevel)) || !(1 <= methaneLevelCritical)) || !(\old(pumpRunning) == 0)) || ((((pumpRunning == \old(pumpRunning) && 2 <= waterLevel) && 1 <= methaneLevelCritical) && !(0 == systemActive)) && pumpRunning == 0))) && ((((!(0 == systemActive) && pumpRunning == 0) || !(1 <= methaneLevelCritical)) || !(\old(pumpRunning) == 0)) || !(1 <= \old(waterLevel))) [2021-12-16 00:58:54,494 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (((((((((!(\old(waterLevel) == 1) || waterLevel == 1) || !(1 <= methaneLevelCritical)) || !(\old(pumpRunning) == 0)) && ((((!(2 <= \old(waterLevel)) || 0 == systemActive) || ((tmp == 0 && 2 <= waterLevel) && !(0 == systemActive))) || (((((((1 <= tmp___0 && 1 <= \result) && tmp == 0) && \result == 0) && 1 <= tmp) && 1 <= waterLevel) && tmp == 0) && pumpRunning == 0)) || !(methaneLevelCritical == 0))) && (((!(1 <= methaneLevelCritical) || !(\old(pumpRunning) == 0)) || pumpRunning == \old(pumpRunning)) || !(1 <= \old(waterLevel)))) && (((!(\old(waterLevel) == 1) || waterLevel == 1) || !(\old(pumpRunning) == 0)) || !(methaneLevelCritical == 0))) && (((!(2 <= \old(waterLevel)) || !(\old(pumpRunning) == 0)) || 2 <= waterLevel) || !(methaneLevelCritical == 0))) && (((!(2 <= \old(waterLevel)) || !(1 <= methaneLevelCritical)) || !(\old(pumpRunning) == 0)) || 2 <= waterLevel)) && ((((!(2 <= \old(waterLevel)) || 0 == systemActive) || !(1 <= methaneLevelCritical)) || (((((((1 <= tmp___0 && 1 <= \result) && \result == 0) && 1 <= tmp) && 1 <= waterLevel) && !(0 == systemActive)) && tmp == 0) && pumpRunning == 0)) || ((pumpRunning == \old(pumpRunning) && !(0 == systemActive)) && pumpRunning == 0))) && ((((((tmp == 0 && 2 <= waterLevel) && !(0 == systemActive)) || (tmp == 0 && pumpRunning == 0)) || !(\old(pumpRunning) == 0)) || !(methaneLevelCritical == 0)) || !(1 <= \old(waterLevel))) [2021-12-16 00:58:54,494 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: ((((((2 <= waterLevel && pumpRunning == 0) || 0 == systemActive) || !(1 <= waterLevel)) || !(\old(pumpRunning) == 0)) || !(methaneLevelCritical == 0)) && ((((0 == systemActive || (methaneLevelCritical <= \result && pumpRunning == 0)) || !(1 <= methaneLevelCritical)) || !(\old(pumpRunning) == 0)) || !(2 <= waterLevel))) && (((0 == systemActive || !(waterLevel == 1)) || !(1 <= methaneLevelCritical)) || !(\old(pumpRunning) == 0)) [2021-12-16 00:58:54,494 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (((((splverifierCounter == 0 && 1 == tmp) && 1 == \result) && 1 <= methaneLevelCritical) && 1 <= waterLevel) && pumpRunning == 0) || (((((splverifierCounter == 0 && 1 == tmp) && methaneLevelCritical == 0) && 1 == \result) && 1 <= waterLevel) && pumpRunning == 0) [2021-12-16 00:58:54,495 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (((((!(\old(pumpRunning) == 0) || !(methaneLevelCritical == 0)) || !(1 <= \old(waterLevel))) && ((!(2 <= \old(waterLevel)) || 0 == systemActive) || !(methaneLevelCritical == 0))) && ((((!(2 <= \old(waterLevel)) || 0 == systemActive) || (pumpRunning == \old(pumpRunning) && pumpRunning == 0)) || !(1 <= methaneLevelCritical)) || (((((((1 <= tmp___0 && \result == 0) && 1 <= \result) && \result == 0) && 1 <= tmp) && 1 <= waterLevel) && tmp == 0) && pumpRunning == 0))) && (((!(2 <= \old(waterLevel)) || !(1 <= methaneLevelCritical)) || ((\result == 0 && 2 <= waterLevel) && pumpRunning == 0)) || !(\old(pumpRunning) == 0))) && (((!(\old(waterLevel) == 1) || !(1 <= methaneLevelCritical)) || !(\old(pumpRunning) == 0)) || ((waterLevel == 1 && \result == 0) && pumpRunning == 0)) [2021-12-16 00:58:54,495 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: ((((!(1 <= methaneLevelCritical) || !(\old(pumpRunning) == 0)) || !(1 <= \old(waterLevel))) && (((!(2 <= \old(waterLevel)) || 0 == systemActive) || !(1 <= methaneLevelCritical)) || ((pumpRunning == \old(pumpRunning) && \result == 0) && 1 <= waterLevel))) && ((!(\old(pumpRunning) == 0) || !(methaneLevelCritical == 0)) || !(1 <= \old(waterLevel)))) && (((!(2 <= \old(waterLevel)) || 0 == systemActive) || !(methaneLevelCritical == 0)) || ((pumpRunning == \old(pumpRunning) && \result == 0) && 1 <= waterLevel)) [2021-12-16 00:58:54,495 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: ((((0 == systemActive || !(waterLevel == 1)) || !(\old(pumpRunning) == 0)) || !(methaneLevelCritical == 0)) && (((0 == systemActive || !(waterLevel == 1)) || !(1 <= methaneLevelCritical)) || !(\old(pumpRunning) == 0))) && ((((0 == systemActive || ((methaneLevelCritical <= \result && methaneLevelCritical <= tmp) && pumpRunning == 0)) || !(1 <= methaneLevelCritical)) || !(\old(pumpRunning) == 0)) || !(2 <= waterLevel)) [2021-12-16 00:58:54,495 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (((((0 == systemActive || (!(\result == 0) && pumpRunning == 0)) || !(waterLevel == 1)) || !(\old(pumpRunning) == 0)) || !(methaneLevelCritical == 0)) && ((((0 == systemActive || !(\old(pumpRunning) == 0)) || !(methaneLevelCritical == 0)) || !(2 <= waterLevel)) || pumpRunning == 0)) && (((((0 == systemActive || (2 <= waterLevel && pumpRunning == 0)) || (!(\result == 0) && pumpRunning == 0)) || !(1 <= waterLevel)) || !(1 <= methaneLevelCritical)) || !(\old(pumpRunning) == 0)) [2021-12-16 00:58:54,495 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: ((((0 == systemActive || !(1 <= waterLevel)) || !(\old(pumpRunning) == 0)) || 2 <= waterLevel) || !(methaneLevelCritical == 0)) && (((0 == systemActive || !(1 <= waterLevel)) || !(1 <= methaneLevelCritical)) || !(\old(pumpRunning) == 0)) [2021-12-16 00:58:54,496 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: ((((!(1 <= methaneLevelCritical) || !(\old(pumpRunning) == 0)) || !(1 <= \old(waterLevel))) && ((!(2 <= \old(waterLevel)) || 0 == systemActive) || !(1 <= methaneLevelCritical))) && ((!(\old(pumpRunning) == 0) || !(methaneLevelCritical == 0)) || !(1 <= \old(waterLevel)))) && ((!(2 <= \old(waterLevel)) || 0 == systemActive) || !(methaneLevelCritical == 0)) [2021-12-16 00:58:54,496 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: ((((!(1 <= methaneLevelCritical) || !(\old(pumpRunning) == 0)) || !(1 <= \old(waterLevel))) && ((!(\old(pumpRunning) == 0) || !(methaneLevelCritical == 0)) || !(1 <= \old(waterLevel)))) && (((!(2 <= \old(waterLevel)) || 0 == systemActive) || !(methaneLevelCritical == 0)) || (((((1 <= tmp___0 && 1 <= \result) && pumpRunning == \old(pumpRunning)) && \result == 0) && 1 <= waterLevel) && tmp == 0))) && (((!(2 <= \old(waterLevel)) || 0 == systemActive) || !(1 <= methaneLevelCritical)) || (((((1 <= tmp___0 && 1 <= \result) && pumpRunning == \old(pumpRunning)) && \result == 0) && 1 <= waterLevel) && tmp == 0)) [2021-12-16 00:58:54,496 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (((((0 == systemActive || (2 <= waterLevel && pumpRunning == 0)) || (((!(0 == tmp) && \result == 0) && pumpRunning == \old(pumpRunning)) && tmp___0 == 0)) || !(1 <= waterLevel)) || !(1 <= methaneLevelCritical)) || !(\old(pumpRunning) == 0)) && ((((((2 <= waterLevel && pumpRunning == 0) || 0 == systemActive) || !(1 <= waterLevel)) || (((!(0 == tmp) && \result == 0) && tmp___0 == 0) && pumpRunning == 0)) || !(\old(pumpRunning) == 0)) || !(methaneLevelCritical == 0)) [2021-12-16 00:58:54,521 INFO L141 WitnessManager]: Wrote witness to /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/witness.graphml [2021-12-16 00:58:54,521 INFO L132 PluginConnector]: ------------------------ END Witness Printer---------------------------- [2021-12-16 00:58:54,522 INFO L158 Benchmark]: Toolchain (without parser) took 11176.23ms. Allocated memory was 100.7MB in the beginning and 176.2MB in the end (delta: 75.5MB). Free memory was 69.9MB in the beginning and 94.4MB in the end (delta: -24.5MB). Peak memory consumption was 50.4MB. Max. memory is 16.1GB. [2021-12-16 00:58:54,522 INFO L158 Benchmark]: CDTParser took 0.21ms. Allocated memory is still 83.9MB. Free memory is still 41.2MB. There was no memory consumed. Max. memory is 16.1GB. [2021-12-16 00:58:54,522 INFO L158 Benchmark]: CACSL2BoogieTranslator took 421.54ms. Allocated memory is still 100.7MB. Free memory was 69.3MB in the beginning and 69.7MB in the end (delta: -390.4kB). Peak memory consumption was 8.4MB. Max. memory is 16.1GB. [2021-12-16 00:58:54,523 INFO L158 Benchmark]: Boogie Procedure Inliner took 66.38ms. Allocated memory is still 100.7MB. Free memory was 69.7MB in the beginning and 67.1MB in the end (delta: 2.6MB). Peak memory consumption was 2.1MB. Max. memory is 16.1GB. [2021-12-16 00:58:54,523 INFO L158 Benchmark]: Boogie Preprocessor took 54.62ms. Allocated memory is still 100.7MB. Free memory was 67.1MB in the beginning and 65.3MB in the end (delta: 1.8MB). Peak memory consumption was 2.1MB. Max. memory is 16.1GB. [2021-12-16 00:58:54,523 INFO L158 Benchmark]: RCFGBuilder took 455.47ms. Allocated memory is still 100.7MB. Free memory was 65.3MB in the beginning and 48.3MB in the end (delta: 17.1MB). Peak memory consumption was 16.8MB. Max. memory is 16.1GB. [2021-12-16 00:58:54,524 INFO L158 Benchmark]: TraceAbstraction took 10102.16ms. Allocated memory was 100.7MB in the beginning and 176.2MB in the end (delta: 75.5MB). Free memory was 47.7MB in the beginning and 100.7MB in the end (delta: -53.0MB). Peak memory consumption was 81.1MB. Max. memory is 16.1GB. [2021-12-16 00:58:54,524 INFO L158 Benchmark]: Witness Printer took 64.54ms. Allocated memory is still 176.2MB. Free memory was 100.7MB in the beginning and 94.4MB in the end (delta: 6.3MB). Peak memory consumption was 6.3MB. Max. memory is 16.1GB. [2021-12-16 00:58:54,525 INFO L339 ainManager$Toolchain]: ####################### End [Toolchain 1] ####################### --- Results --- * Results from de.uni_freiburg.informatik.ultimate.core: - StatisticsResult: Toolchain Benchmarks Benchmark results are: * CDTParser took 0.21ms. Allocated memory is still 83.9MB. Free memory is still 41.2MB. There was no memory consumed. Max. memory is 16.1GB. * CACSL2BoogieTranslator took 421.54ms. Allocated memory is still 100.7MB. Free memory was 69.3MB in the beginning and 69.7MB in the end (delta: -390.4kB). Peak memory consumption was 8.4MB. Max. memory is 16.1GB. * Boogie Procedure Inliner took 66.38ms. Allocated memory is still 100.7MB. Free memory was 69.7MB in the beginning and 67.1MB in the end (delta: 2.6MB). Peak memory consumption was 2.1MB. Max. memory is 16.1GB. * Boogie Preprocessor took 54.62ms. Allocated memory is still 100.7MB. Free memory was 67.1MB in the beginning and 65.3MB in the end (delta: 1.8MB). Peak memory consumption was 2.1MB. Max. memory is 16.1GB. * RCFGBuilder took 455.47ms. Allocated memory is still 100.7MB. Free memory was 65.3MB in the beginning and 48.3MB in the end (delta: 17.1MB). Peak memory consumption was 16.8MB. Max. memory is 16.1GB. * TraceAbstraction took 10102.16ms. Allocated memory was 100.7MB in the beginning and 176.2MB in the end (delta: 75.5MB). Free memory was 47.7MB in the beginning and 100.7MB in the end (delta: -53.0MB). Peak memory consumption was 81.1MB. Max. memory is 16.1GB. * Witness Printer took 64.54ms. Allocated memory is still 176.2MB. Free memory was 100.7MB in the beginning and 94.4MB in the end (delta: 6.3MB). Peak memory consumption was 6.3MB. Max. memory is 16.1GB. * Results from de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction: - StatisticsResult: ErrorAutomatonStatistics NumberErrorTraces: 0, NumberStatementsAllTraces: 0, NumberRelevantStatements: 0, 0.0s ErrorAutomatonConstructionTimeTotal, 0.0s FaulLocalizationTime, NumberStatementsFirstTrace: -1, TraceLengthAvg: 0, 0.0s ErrorAutomatonConstructionTimeAvg, 0.0s ErrorAutomatonDifferenceTimeAvg, 0.0s ErrorAutomatonDifferenceTimeTotal, NumberOfNoEnhancement: 0, NumberOfFiniteEnhancement: 0, NumberOfInfiniteEnhancement: 0 - PositiveResult [Line: 193]: call to reach_error is unreachable For all program executions holds that call to reach_error is unreachable at this location - StatisticsResult: Ultimate Automizer benchmark data CFG has 9 procedures, 98 locations, 1 error locations. Started 1 CEGAR loops. OverallTime: 10.0s, OverallIterations: 11, TraceHistogramMax: 3, PathProgramHistogramMax: 1, EmptinessCheckTime: 0.0s, AutomataDifference: 2.1s, DeadEndRemovalTime: 0.0s, HoareAnnotationTime: 4.6s, InitialAbstractionConstructionTime: 0.0s, PartialOrderReductionTime: 0.0s, HoareTripleCheckerStatistics: 0 mSolverCounterUnknown, 1441 SdHoareTripleChecker+Valid, 1.2s IncrementalHoareTripleChecker+Time, 0 mSdLazyCounter, 1419 mSDsluCounter, 4199 SdHoareTripleChecker+Invalid, 0.9s Time, 0 mProtectedAction, 0 SdHoareTripleChecker+Unchecked, 0 IncrementalHoareTripleChecker+Unchecked, 2846 mSDsCounter, 360 IncrementalHoareTripleChecker+Valid, 0 mProtectedPredicate, 1420 IncrementalHoareTripleChecker+Invalid, 1780 SdHoareTripleChecker+Unknown, 0 mSolverCounterNotChecked, 360 mSolverCounterUnsat, 1353 mSDtfsCounter, 1420 mSolverCounterSat, 0.0s SdHoareTripleChecker+Time, 0 IncrementalHoareTripleChecker+Unknown, PredicateUnifierStatistics: 0 DeclaredPredicates, 435 GetRequests, 337 SyntacticMatches, 2 SemanticMatches, 96 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 68 ImplicationChecksByTransitivity, 0.5s Time, 0.0s BasicInterpolantAutomatonTime, BiggestAbstraction: size=1785occurred in iteration=10, InterpolantAutomatonStates: 79, traceCheckStatistics: No data available, InterpolantConsolidationStatistics: No data available, PathInvariantsStatistics: No data available, 0/0 InterpolantCoveringCapability, TotalInterpolationStatistics: No data available, 0.0s DumpTime, AutomataMinimizationStatistics: 0.5s AutomataMinimizationTime, 11 MinimizatonAttempts, 462 StatesRemovedByMinimization, 8 NontrivialMinimizations, HoareAnnotationStatistics: 0.0s HoareAnnotationTime, 45 LocationsWithAnnotation, 3373 PreInvPairs, 3758 NumberOfFragments, 2464 HoareAnnotationTreeSize, 3373 FomulaSimplifications, 662 FormulaSimplificationTreeSizeReduction, 0.5s HoareSimplificationTime, 45 FomulaSimplificationsInter, 19589 FormulaSimplificationTreeSizeReductionInter, 3.9s HoareSimplificationTimeInter, RefinementEngineStatistics: TRACE_CHECK: 0.1s SsaConstructionTime, 0.3s SatisfiabilityAnalysisTime, 1.4s InterpolantComputationTime, 805 NumberOfCodeBlocks, 805 NumberOfCodeBlocksAsserted, 14 NumberOfCheckSat, 791 ConstructedInterpolants, 0 QuantifiedInterpolants, 1385 SizeOfPredicates, 11 NumberOfNonLiveVariables, 1308 ConjunctsInSsa, 24 ConjunctsInUnsatCore, 14 InterpolantComputations, 11 PerfectInterpolantSequences, 129/135 InterpolantCoveringCapability, INVARIANT_SYNTHESIS: No data available, INTERPOLANT_CONSOLIDATION: No data available, ABSTRACT_INTERPRETATION: No data available, PDR: No data available, ACCELERATED_INTERPOLATION: No data available, SIFA: No data available, ReuseStatistics: No data available - AllSpecificationsHoldResult: All specifications hold 1 specifications checked. All of them hold - InvariantResult [Line: 332]: Loop Invariant Derived loop invariant: ((((((((!(\old(waterLevel) == 1) || waterLevel == 1) || !(1 <= methaneLevelCritical)) || !(\old(pumpRunning) == 0)) && (((!(2 <= \old(waterLevel)) || !(\old(pumpRunning) == 0)) || !(methaneLevelCritical == 0)) || ((methaneLevelCritical == 0 && 2 <= waterLevel) && !(0 == systemActive)))) && ((((!(2 <= \old(waterLevel)) || 0 == systemActive) || ((((((1 <= tmp___0 && 1 <= \result) && \result == 0) && 1 <= tmp) && 1 <= waterLevel) && tmp == 0) && pumpRunning == 0)) || !(methaneLevelCritical == 0)) || ((methaneLevelCritical == 0 && 2 <= waterLevel) && !(0 == systemActive)))) && (((!(\old(waterLevel) == 1) || ((waterLevel == 1 && !(0 == systemActive)) && pumpRunning == 0)) || !(\old(pumpRunning) == 0)) || !(methaneLevelCritical == 0))) && ((((!(2 <= \old(waterLevel)) || 0 == systemActive) || ((((((1 <= tmp___0 && 1 <= \result) && \result == 0) && 1 <= tmp) && 1 <= waterLevel) && tmp == 0) && pumpRunning == 0)) || !(1 <= methaneLevelCritical)) || ((((pumpRunning == \old(pumpRunning) && 2 <= waterLevel) && 1 <= methaneLevelCritical) && !(0 == systemActive)) && pumpRunning == 0))) && (((!(2 <= \old(waterLevel)) || !(1 <= methaneLevelCritical)) || !(\old(pumpRunning) == 0)) || ((((pumpRunning == \old(pumpRunning) && 2 <= waterLevel) && 1 <= methaneLevelCritical) && !(0 == systemActive)) && pumpRunning == 0))) && ((((!(0 == systemActive) && pumpRunning == 0) || !(1 <= methaneLevelCritical)) || !(\old(pumpRunning) == 0)) || !(1 <= \old(waterLevel))) - InvariantResult [Line: 210]: Loop Invariant Derived loop invariant: 0 - InvariantResult [Line: 211]: Loop Invariant Derived loop invariant: ((((((splverifierCounter == 0 && 1 == tmp) && methaneLevelCritical == 0) && 1 == \result) && 2 <= waterLevel) && !(0 == systemActive)) || (((((splverifierCounter == 0 && 1 == tmp) && 1 == \result) && 1 <= methaneLevelCritical) && 1 <= waterLevel) && pumpRunning == 0)) || (((((splverifierCounter == 0 && 1 == tmp) && methaneLevelCritical == 0) && 1 == \result) && 1 <= waterLevel) && pumpRunning == 0) - InvariantResult [Line: 895]: Loop Invariant Derived loop invariant: (((waterLevel == 1 && methaneLevelCritical == 0) && 1 == \result) && systemActive == 1) && pumpRunning == 0 - InvariantResult [Line: 163]: Loop Invariant Derived loop invariant: (((((((((!(\old(waterLevel) == 1) || waterLevel == 1) || !(1 <= methaneLevelCritical)) || !(\old(pumpRunning) == 0)) && ((((!(2 <= \old(waterLevel)) || 0 == systemActive) || ((tmp == 0 && 2 <= waterLevel) && !(0 == systemActive))) || (((((((1 <= tmp___0 && 1 <= \result) && tmp == 0) && \result == 0) && 1 <= tmp) && 1 <= waterLevel) && tmp == 0) && pumpRunning == 0)) || !(methaneLevelCritical == 0))) && (((!(1 <= methaneLevelCritical) || !(\old(pumpRunning) == 0)) || pumpRunning == \old(pumpRunning)) || !(1 <= \old(waterLevel)))) && (((!(\old(waterLevel) == 1) || waterLevel == 1) || !(\old(pumpRunning) == 0)) || !(methaneLevelCritical == 0))) && (((!(2 <= \old(waterLevel)) || !(\old(pumpRunning) == 0)) || 2 <= waterLevel) || !(methaneLevelCritical == 0))) && (((!(2 <= \old(waterLevel)) || !(1 <= methaneLevelCritical)) || !(\old(pumpRunning) == 0)) || 2 <= waterLevel)) && ((((!(2 <= \old(waterLevel)) || 0 == systemActive) || !(1 <= methaneLevelCritical)) || (((((((1 <= tmp___0 && 1 <= \result) && \result == 0) && 1 <= tmp) && 1 <= waterLevel) && !(0 == systemActive)) && tmp == 0) && pumpRunning == 0)) || ((pumpRunning == \old(pumpRunning) && !(0 == systemActive)) && pumpRunning == 0))) && ((((((tmp == 0 && 2 <= waterLevel) && !(0 == systemActive)) || (tmp == 0 && pumpRunning == 0)) || !(\old(pumpRunning) == 0)) || !(methaneLevelCritical == 0)) || !(1 <= \old(waterLevel))) - InvariantResult [Line: 366]: Loop Invariant Derived loop invariant: ((((0 == systemActive || !(waterLevel == 1)) || !(\old(pumpRunning) == 0)) || !(methaneLevelCritical == 0)) && (((0 == systemActive || !(waterLevel == 1)) || !(1 <= methaneLevelCritical)) || !(\old(pumpRunning) == 0))) && ((((0 == systemActive || ((methaneLevelCritical <= \result && methaneLevelCritical <= tmp) && pumpRunning == 0)) || !(1 <= methaneLevelCritical)) || !(\old(pumpRunning) == 0)) || !(2 <= waterLevel)) - InvariantResult [Line: 485]: Loop Invariant Derived loop invariant: (((((splverifierCounter == 0 && 1 == tmp) && 1 == \result) && 1 <= methaneLevelCritical) && 1 <= waterLevel) && pumpRunning == 0) || (((((splverifierCounter == 0 && 1 == tmp) && methaneLevelCritical == 0) && 1 == \result) && 1 <= waterLevel) && pumpRunning == 0) - InvariantResult [Line: 881]: Loop Invariant Derived loop invariant: ((waterLevel == 1 && methaneLevelCritical == 0) && systemActive == 1) && pumpRunning == 0 - InvariantResult [Line: 466]: Loop Invariant Derived loop invariant: ((((!(1 <= methaneLevelCritical) || !(\old(pumpRunning) == 0)) || !(1 <= \old(waterLevel))) && ((!(\old(pumpRunning) == 0) || !(methaneLevelCritical == 0)) || !(1 <= \old(waterLevel)))) && (((!(2 <= \old(waterLevel)) || 0 == systemActive) || !(methaneLevelCritical == 0)) || (((((1 <= tmp___0 && 1 <= \result) && pumpRunning == \old(pumpRunning)) && \result == 0) && 1 <= waterLevel) && tmp == 0))) && (((!(2 <= \old(waterLevel)) || 0 == systemActive) || !(1 <= methaneLevelCritical)) || (((((1 <= tmp___0 && 1 <= \result) && pumpRunning == \old(pumpRunning)) && \result == 0) && 1 <= waterLevel) && tmp == 0)) - InvariantResult [Line: 960]: Loop Invariant Derived loop invariant: ((((waterLevel == 1 && 1 == tmp) && methaneLevelCritical == 0) && 1 == \result) && systemActive == 1) && pumpRunning == 0 - InvariantResult [Line: 977]: Loop Invariant Derived loop invariant: 1 - InvariantResult [Line: 189]: Loop Invariant Derived loop invariant: ((((!(1 <= methaneLevelCritical) || !(\old(pumpRunning) == 0)) || !(1 <= \old(waterLevel))) && ((!(2 <= \old(waterLevel)) || 0 == systemActive) || !(1 <= methaneLevelCritical))) && ((!(\old(pumpRunning) == 0) || !(methaneLevelCritical == 0)) || !(1 <= \old(waterLevel)))) && ((!(2 <= \old(waterLevel)) || 0 == systemActive) || !(methaneLevelCritical == 0)) - InvariantResult [Line: 916]: Loop Invariant Derived loop invariant: 1 - InvariantResult [Line: 201]: Loop Invariant Derived loop invariant: 1 - InvariantResult [Line: 906]: Loop Invariant Derived loop invariant: 1 - InvariantResult [Line: 60]: Loop Invariant Derived loop invariant: ((((!(1 <= methaneLevelCritical) || !(\old(pumpRunning) == 0)) || !(1 <= \old(waterLevel))) && (((!(2 <= \old(waterLevel)) || 0 == systemActive) || (pumpRunning == \old(pumpRunning) && 1 <= waterLevel)) || !(methaneLevelCritical == 0))) && (((!(2 <= \old(waterLevel)) || 0 == systemActive) || !(1 <= methaneLevelCritical)) || (pumpRunning == \old(pumpRunning) && 1 <= waterLevel))) && ((!(\old(pumpRunning) == 0) || !(methaneLevelCritical == 0)) || !(1 <= \old(waterLevel))) - InvariantResult [Line: 357]: Loop Invariant Derived loop invariant: ((((0 == systemActive || !(1 <= waterLevel)) || !(\old(pumpRunning) == 0)) || 2 <= waterLevel) || !(methaneLevelCritical == 0)) && (((0 == systemActive || !(1 <= waterLevel)) || !(1 <= methaneLevelCritical)) || !(\old(pumpRunning) == 0)) - InvariantResult [Line: 967]: Loop Invariant Derived loop invariant: 1 - InvariantResult [Line: 151]: Loop Invariant Derived loop invariant: ((((!(1 <= methaneLevelCritical) || !(\old(pumpRunning) == 0)) || !(1 <= \old(waterLevel))) && (((!(2 <= \old(waterLevel)) || 0 == systemActive) || !(1 <= methaneLevelCritical)) || ((pumpRunning == \old(pumpRunning) && \result == 0) && 1 <= waterLevel))) && ((!(\old(pumpRunning) == 0) || !(methaneLevelCritical == 0)) || !(1 <= \old(waterLevel)))) && (((!(2 <= \old(waterLevel)) || 0 == systemActive) || !(methaneLevelCritical == 0)) || ((pumpRunning == \old(pumpRunning) && \result == 0) && 1 <= waterLevel)) - InvariantResult [Line: 137]: Loop Invariant Derived loop invariant: (((((0 == systemActive || (!(\result == 0) && pumpRunning == 0)) || !(waterLevel == 1)) || !(\old(pumpRunning) == 0)) || !(methaneLevelCritical == 0)) && ((((0 == systemActive || !(\old(pumpRunning) == 0)) || !(methaneLevelCritical == 0)) || !(2 <= waterLevel)) || pumpRunning == 0)) && (((((0 == systemActive || (2 <= waterLevel && pumpRunning == 0)) || (!(\result == 0) && pumpRunning == 0)) || !(1 <= waterLevel)) || !(1 <= methaneLevelCritical)) || !(\old(pumpRunning) == 0)) - InvariantResult [Line: 402]: Loop Invariant Derived loop invariant: (((((!(\old(pumpRunning) == 0) || !(methaneLevelCritical == 0)) || !(1 <= \old(waterLevel))) && ((!(2 <= \old(waterLevel)) || 0 == systemActive) || !(methaneLevelCritical == 0))) && ((((!(2 <= \old(waterLevel)) || 0 == systemActive) || (pumpRunning == \old(pumpRunning) && pumpRunning == 0)) || !(1 <= methaneLevelCritical)) || (((((((1 <= tmp___0 && \result == 0) && 1 <= \result) && \result == 0) && 1 <= tmp) && 1 <= waterLevel) && tmp == 0) && pumpRunning == 0))) && (((!(2 <= \old(waterLevel)) || !(1 <= methaneLevelCritical)) || ((\result == 0 && 2 <= waterLevel) && pumpRunning == 0)) || !(\old(pumpRunning) == 0))) && (((!(\old(waterLevel) == 1) || !(1 <= methaneLevelCritical)) || !(\old(pumpRunning) == 0)) || ((waterLevel == 1 && \result == 0) && pumpRunning == 0)) - InvariantResult [Line: 447]: Loop Invariant Derived loop invariant: (((((0 == systemActive || (2 <= waterLevel && pumpRunning == 0)) || (((!(0 == tmp) && \result == 0) && pumpRunning == \old(pumpRunning)) && tmp___0 == 0)) || !(1 <= waterLevel)) || !(1 <= methaneLevelCritical)) || !(\old(pumpRunning) == 0)) && ((((((2 <= waterLevel && pumpRunning == 0) || 0 == systemActive) || !(1 <= waterLevel)) || (((!(0 == tmp) && \result == 0) && tmp___0 == 0) && pumpRunning == 0)) || !(\old(pumpRunning) == 0)) || !(methaneLevelCritical == 0)) - InvariantResult [Line: 391]: Loop Invariant Derived loop invariant: ((((((2 <= waterLevel && pumpRunning == 0) || 0 == systemActive) || !(1 <= waterLevel)) || !(\old(pumpRunning) == 0)) || !(methaneLevelCritical == 0)) && ((((0 == systemActive || (methaneLevelCritical <= \result && pumpRunning == 0)) || !(1 <= methaneLevelCritical)) || !(\old(pumpRunning) == 0)) || !(2 <= waterLevel))) && (((0 == systemActive || !(waterLevel == 1)) || !(1 <= methaneLevelCritical)) || !(\old(pumpRunning) == 0)) - InvariantResult [Line: 888]: Loop Invariant Derived loop invariant: ((waterLevel == 1 && methaneLevelCritical == 0) && systemActive == 1) && pumpRunning == 0 RESULT: Ultimate proved your program to be correct! [2021-12-16 00:58:54,585 INFO L540 MonitoredProcess]: [MP /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in -t:2000 (1)] Forceful destruction successful, exit code 0 Received shutdown request... --- End real Ultimate output --- Execution finished normally Writing output log to file Ultimate.log Result: TRUE