./Ultimate.py --spec ../sv-benchmarks/c/properties/unreach-call.prp --file ../sv-benchmarks/c/product-lines/minepump_spec2_product46.cil.c --full-output --architecture 32bit -------------------------------------------------------------------------------- Checking for ERROR reachability Using default analysis Version c3fed411 Calling Ultimate with: /usr/bin/java -Dosgi.configuration.area=/storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/data/config -Xmx15G -Xms4m -jar /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/plugins/org.eclipse.equinox.launcher_1.5.800.v20200727-1323.jar -data @noDefault -ultimatedata /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/data -tc /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/config/AutomizerReach.xml -i ../sv-benchmarks/c/product-lines/minepump_spec2_product46.cil.c -s /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/config/svcomp-Reach-32bit-Automizer_Default.epf --cacsl2boogietranslator.entry.function main --witnessprinter.witness.directory /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux --witnessprinter.witness.filename witness.graphml --witnessprinter.write.witness.besides.input.file false --witnessprinter.graph.data.specification CHECK( init(main()), LTL(G ! call(reach_error())) ) --witnessprinter.graph.data.producer Automizer --witnessprinter.graph.data.architecture 32bit --witnessprinter.graph.data.programhash 02fb1fa00f2030f7900be70496baf2f4c44344da378fa11ef09f1f26dc14ae9d --- Real Ultimate output --- This is Ultimate 0.2.2-tmp.no-commuhash-c3fed41 [2021-12-16 00:59:10,069 INFO L177 SettingsManager]: Resetting all preferences to default values... [2021-12-16 00:59:10,071 INFO L181 SettingsManager]: Resetting UltimateCore preferences to default values [2021-12-16 00:59:10,106 INFO L184 SettingsManager]: Ultimate Commandline Interface provides no preferences, ignoring... [2021-12-16 00:59:10,107 INFO L181 SettingsManager]: Resetting Boogie Preprocessor preferences to default values [2021-12-16 00:59:10,110 INFO L181 SettingsManager]: Resetting Boogie Procedure Inliner preferences to default values [2021-12-16 00:59:10,111 INFO L181 SettingsManager]: Resetting Abstract Interpretation preferences to default values [2021-12-16 00:59:10,113 INFO L181 SettingsManager]: Resetting LassoRanker preferences to default values [2021-12-16 00:59:10,114 INFO L181 SettingsManager]: Resetting Reaching Definitions preferences to default values [2021-12-16 00:59:10,116 INFO L181 SettingsManager]: Resetting SyntaxChecker preferences to default values [2021-12-16 00:59:10,117 INFO L181 SettingsManager]: Resetting Sifa preferences to default values [2021-12-16 00:59:10,118 INFO L184 SettingsManager]: Büchi Program Product provides no preferences, ignoring... [2021-12-16 00:59:10,118 INFO L181 SettingsManager]: Resetting LTL2Aut preferences to default values [2021-12-16 00:59:10,120 INFO L181 SettingsManager]: Resetting PEA to Boogie preferences to default values [2021-12-16 00:59:10,121 INFO L181 SettingsManager]: Resetting BlockEncodingV2 preferences to default values [2021-12-16 00:59:10,123 INFO L181 SettingsManager]: Resetting ChcToBoogie preferences to default values [2021-12-16 00:59:10,124 INFO L181 SettingsManager]: Resetting AutomataScriptInterpreter preferences to default values [2021-12-16 00:59:10,124 INFO L181 SettingsManager]: Resetting BuchiAutomizer preferences to default values [2021-12-16 00:59:10,126 INFO L181 SettingsManager]: Resetting CACSL2BoogieTranslator preferences to default values [2021-12-16 00:59:10,128 INFO L181 SettingsManager]: Resetting CodeCheck preferences to default values [2021-12-16 00:59:10,131 INFO L181 SettingsManager]: Resetting InvariantSynthesis preferences to default values [2021-12-16 00:59:10,131 INFO L181 SettingsManager]: Resetting RCFGBuilder preferences to default values [2021-12-16 00:59:10,133 INFO L181 SettingsManager]: Resetting Referee preferences to default values [2021-12-16 00:59:10,133 INFO L181 SettingsManager]: Resetting TraceAbstraction preferences to default values [2021-12-16 00:59:10,139 INFO L184 SettingsManager]: TraceAbstractionConcurrent provides no preferences, ignoring... [2021-12-16 00:59:10,140 INFO L184 SettingsManager]: TraceAbstractionWithAFAs provides no preferences, ignoring... [2021-12-16 00:59:10,141 INFO L181 SettingsManager]: Resetting TreeAutomizer preferences to default values [2021-12-16 00:59:10,141 INFO L181 SettingsManager]: Resetting IcfgToChc preferences to default values [2021-12-16 00:59:10,142 INFO L181 SettingsManager]: Resetting IcfgTransformer preferences to default values [2021-12-16 00:59:10,143 INFO L184 SettingsManager]: ReqToTest provides no preferences, ignoring... [2021-12-16 00:59:10,143 INFO L181 SettingsManager]: Resetting Boogie Printer preferences to default values [2021-12-16 00:59:10,144 INFO L181 SettingsManager]: Resetting ChcSmtPrinter preferences to default values [2021-12-16 00:59:10,145 INFO L181 SettingsManager]: Resetting ReqPrinter preferences to default values [2021-12-16 00:59:10,145 INFO L181 SettingsManager]: Resetting Witness Printer preferences to default values [2021-12-16 00:59:10,146 INFO L184 SettingsManager]: Boogie PL CUP Parser provides no preferences, ignoring... [2021-12-16 00:59:10,147 INFO L181 SettingsManager]: Resetting CDTParser preferences to default values [2021-12-16 00:59:10,147 INFO L184 SettingsManager]: AutomataScriptParser provides no preferences, ignoring... [2021-12-16 00:59:10,148 INFO L184 SettingsManager]: ReqParser provides no preferences, ignoring... [2021-12-16 00:59:10,148 INFO L181 SettingsManager]: Resetting SmtParser preferences to default values [2021-12-16 00:59:10,148 INFO L181 SettingsManager]: Resetting Witness Parser preferences to default values [2021-12-16 00:59:10,149 INFO L188 SettingsManager]: Finished resetting all preferences to default values... [2021-12-16 00:59:10,150 INFO L101 SettingsManager]: Beginning loading settings from /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/config/svcomp-Reach-32bit-Automizer_Default.epf [2021-12-16 00:59:10,169 INFO L113 SettingsManager]: Loading preferences was successful [2021-12-16 00:59:10,169 INFO L115 SettingsManager]: Preferences different from defaults after loading the file: [2021-12-16 00:59:10,170 INFO L136 SettingsManager]: Preferences of UltimateCore differ from their defaults: [2021-12-16 00:59:10,170 INFO L138 SettingsManager]: * Log level for class=de.uni_freiburg.informatik.ultimate.lib.smtlibutils.quantifier.QuantifierPusher=ERROR; [2021-12-16 00:59:10,171 INFO L136 SettingsManager]: Preferences of Boogie Procedure Inliner differ from their defaults: [2021-12-16 00:59:10,171 INFO L138 SettingsManager]: * Ignore calls to procedures called more than once=ONLY_FOR_SEQUENTIAL_PROGRAMS [2021-12-16 00:59:10,171 INFO L136 SettingsManager]: Preferences of BlockEncodingV2 differ from their defaults: [2021-12-16 00:59:10,171 INFO L138 SettingsManager]: * Create parallel compositions if possible=false [2021-12-16 00:59:10,172 INFO L138 SettingsManager]: * Use SBE=true [2021-12-16 00:59:10,172 INFO L136 SettingsManager]: Preferences of CACSL2BoogieTranslator differ from their defaults: [2021-12-16 00:59:10,172 INFO L138 SettingsManager]: * sizeof long=4 [2021-12-16 00:59:10,173 INFO L138 SettingsManager]: * Overapproximate operations on floating types=true [2021-12-16 00:59:10,173 INFO L138 SettingsManager]: * sizeof POINTER=4 [2021-12-16 00:59:10,173 INFO L138 SettingsManager]: * Check division by zero=IGNORE [2021-12-16 00:59:10,173 INFO L138 SettingsManager]: * Pointer to allocated memory at dereference=IGNORE [2021-12-16 00:59:10,173 INFO L138 SettingsManager]: * If two pointers are subtracted or compared they have the same base address=IGNORE [2021-12-16 00:59:10,173 INFO L138 SettingsManager]: * Check array bounds for arrays that are off heap=IGNORE [2021-12-16 00:59:10,173 INFO L138 SettingsManager]: * sizeof long double=12 [2021-12-16 00:59:10,174 INFO L138 SettingsManager]: * Check if freed pointer was valid=false [2021-12-16 00:59:10,174 INFO L138 SettingsManager]: * Use constant arrays=true [2021-12-16 00:59:10,174 INFO L138 SettingsManager]: * Pointer base address is valid at dereference=IGNORE [2021-12-16 00:59:10,174 INFO L136 SettingsManager]: Preferences of RCFGBuilder differ from their defaults: [2021-12-16 00:59:10,174 INFO L138 SettingsManager]: * Size of a code block=SequenceOfStatements [2021-12-16 00:59:10,174 INFO L138 SettingsManager]: * SMT solver=External_DefaultMode [2021-12-16 00:59:10,174 INFO L138 SettingsManager]: * Command for external solver=z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in -t:2000 [2021-12-16 00:59:10,175 INFO L136 SettingsManager]: Preferences of TraceAbstraction differ from their defaults: [2021-12-16 00:59:10,175 INFO L138 SettingsManager]: * Compute Interpolants along a Counterexample=FPandBP [2021-12-16 00:59:10,176 INFO L138 SettingsManager]: * Positions where we compute the Hoare Annotation=LoopsAndPotentialCycles [2021-12-16 00:59:10,176 INFO L138 SettingsManager]: * Trace refinement strategy=CAMEL [2021-12-16 00:59:10,176 INFO L138 SettingsManager]: * Command for external solver=z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in [2021-12-16 00:59:10,176 INFO L138 SettingsManager]: * Large block encoding in concurrent analysis=OFF [2021-12-16 00:59:10,177 INFO L138 SettingsManager]: * Automaton type used in concurrency analysis=PETRI_NET [2021-12-16 00:59:10,177 INFO L138 SettingsManager]: * Compute Hoare Annotation of negated interpolant automaton, abstraction and CFG=true [2021-12-16 00:59:10,177 INFO L138 SettingsManager]: * Trace refinement exception blacklist=NONE [2021-12-16 00:59:10,177 INFO L138 SettingsManager]: * SMT solver=External_ModelsAndUnsatCoreMode WARNING: An illegal reflective access operation has occurred WARNING: Illegal reflective access by com.sun.xml.bind.v2.runtime.reflect.opt.Injector$1 (file:/storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/plugins/com.sun.xml.bind_2.2.0.v201505121915.jar) to method java.lang.ClassLoader.defineClass(java.lang.String,byte[],int,int) WARNING: Please consider reporting this to the maintainers of com.sun.xml.bind.v2.runtime.reflect.opt.Injector$1 WARNING: Use --illegal-access=warn to enable warnings of further illegal reflective access operations WARNING: All illegal access operations will be denied in a future release Applying setting for plugin de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator: Entry function -> main Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Witness directory -> /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Witness filename -> witness.graphml Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Write witness besides input file -> false Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Graph data specification -> CHECK( init(main()), LTL(G ! call(reach_error())) ) Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Graph data producer -> Automizer Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Graph data architecture -> 32bit Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Graph data programhash -> 02fb1fa00f2030f7900be70496baf2f4c44344da378fa11ef09f1f26dc14ae9d [2021-12-16 00:59:10,361 INFO L75 nceAwareModelManager]: Repository-Root is: /tmp [2021-12-16 00:59:10,379 INFO L261 ainManager$Toolchain]: [Toolchain 1]: Applicable parser(s) successfully (re)initialized [2021-12-16 00:59:10,382 INFO L217 ainManager$Toolchain]: [Toolchain 1]: Toolchain selected. [2021-12-16 00:59:10,382 INFO L271 PluginConnector]: Initializing CDTParser... [2021-12-16 00:59:10,383 INFO L275 PluginConnector]: CDTParser initialized [2021-12-16 00:59:10,384 INFO L432 ainManager$Toolchain]: [Toolchain 1]: Parsing single file: /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/../sv-benchmarks/c/product-lines/minepump_spec2_product46.cil.c [2021-12-16 00:59:10,436 INFO L220 CDTParser]: Created temporary CDT project at /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/data/10d36f152/2cff757ecccb43d485f1e34f3959a6dc/FLAGd3dbd0f42 [2021-12-16 00:59:10,814 INFO L306 CDTParser]: Found 1 translation units. [2021-12-16 00:59:10,815 INFO L160 CDTParser]: Scanning /storage/repos/ultimate/releaseScripts/default/sv-benchmarks/c/product-lines/minepump_spec2_product46.cil.c [2021-12-16 00:59:10,822 INFO L349 CDTParser]: About to delete temporary CDT project at /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/data/10d36f152/2cff757ecccb43d485f1e34f3959a6dc/FLAGd3dbd0f42 [2021-12-16 00:59:10,830 INFO L357 CDTParser]: Successfully deleted /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/data/10d36f152/2cff757ecccb43d485f1e34f3959a6dc [2021-12-16 00:59:10,832 INFO L299 ainManager$Toolchain]: ####################### [Toolchain 1] ####################### [2021-12-16 00:59:10,833 INFO L131 ToolchainWalker]: Walking toolchain with 6 elements. [2021-12-16 00:59:10,834 INFO L113 PluginConnector]: ------------------------CACSL2BoogieTranslator---------------------------- [2021-12-16 00:59:10,834 INFO L271 PluginConnector]: Initializing CACSL2BoogieTranslator... [2021-12-16 00:59:10,836 INFO L275 PluginConnector]: CACSL2BoogieTranslator initialized [2021-12-16 00:59:10,837 INFO L185 PluginConnector]: Executing the observer ACSLObjectContainerObserver from plugin CACSL2BoogieTranslator for "CDTParser AST 16.12 12:59:10" (1/1) ... [2021-12-16 00:59:10,838 INFO L205 PluginConnector]: Invalid model from CACSL2BoogieTranslator for observer de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator.ACSLObjectContainerObserver@255ecdd3 and model type de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 16.12 12:59:10, skipping insertion in model container [2021-12-16 00:59:10,838 INFO L185 PluginConnector]: Executing the observer CACSL2BoogieTranslatorObserver from plugin CACSL2BoogieTranslator for "CDTParser AST 16.12 12:59:10" (1/1) ... [2021-12-16 00:59:10,842 INFO L145 MainTranslator]: Starting translation in SV-COMP mode [2021-12-16 00:59:10,866 INFO L178 MainTranslator]: Built tables and reachable declarations [2021-12-16 00:59:11,057 WARN L230 ndardFunctionHandler]: Function reach_error is already implemented but we override the implementation for the call at /storage/repos/ultimate/releaseScripts/default/sv-benchmarks/c/product-lines/minepump_spec2_product46.cil.c[17174,17187] [2021-12-16 00:59:11,062 INFO L209 PostProcessor]: Analyzing one entry point: main [2021-12-16 00:59:11,068 INFO L203 MainTranslator]: Completed pre-run [2021-12-16 00:59:11,107 WARN L230 ndardFunctionHandler]: Function reach_error is already implemented but we override the implementation for the call at /storage/repos/ultimate/releaseScripts/default/sv-benchmarks/c/product-lines/minepump_spec2_product46.cil.c[17174,17187] [2021-12-16 00:59:11,109 INFO L209 PostProcessor]: Analyzing one entry point: main [2021-12-16 00:59:11,121 INFO L208 MainTranslator]: Completed translation [2021-12-16 00:59:11,121 INFO L202 PluginConnector]: Adding new model de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 16.12 12:59:11 WrapperNode [2021-12-16 00:59:11,121 INFO L132 PluginConnector]: ------------------------ END CACSL2BoogieTranslator---------------------------- [2021-12-16 00:59:11,122 INFO L113 PluginConnector]: ------------------------Boogie Procedure Inliner---------------------------- [2021-12-16 00:59:11,122 INFO L271 PluginConnector]: Initializing Boogie Procedure Inliner... [2021-12-16 00:59:11,122 INFO L275 PluginConnector]: Boogie Procedure Inliner initialized [2021-12-16 00:59:11,132 INFO L185 PluginConnector]: Executing the observer TypeChecker from plugin Boogie Procedure Inliner for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 16.12 12:59:11" (1/1) ... [2021-12-16 00:59:11,141 INFO L185 PluginConnector]: Executing the observer Inliner from plugin Boogie Procedure Inliner for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 16.12 12:59:11" (1/1) ... [2021-12-16 00:59:11,160 INFO L137 Inliner]: procedures = 56, calls = 157, calls flagged for inlining = 23, calls inlined = 20, statements flattened = 249 [2021-12-16 00:59:11,160 INFO L132 PluginConnector]: ------------------------ END Boogie Procedure Inliner---------------------------- [2021-12-16 00:59:11,161 INFO L113 PluginConnector]: ------------------------Boogie Preprocessor---------------------------- [2021-12-16 00:59:11,161 INFO L271 PluginConnector]: Initializing Boogie Preprocessor... [2021-12-16 00:59:11,161 INFO L275 PluginConnector]: Boogie Preprocessor initialized [2021-12-16 00:59:11,166 INFO L185 PluginConnector]: Executing the observer EnsureBoogieModelObserver from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 16.12 12:59:11" (1/1) ... [2021-12-16 00:59:11,167 INFO L185 PluginConnector]: Executing the observer TypeChecker from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 16.12 12:59:11" (1/1) ... [2021-12-16 00:59:11,168 INFO L185 PluginConnector]: Executing the observer ConstExpander from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 16.12 12:59:11" (1/1) ... [2021-12-16 00:59:11,169 INFO L185 PluginConnector]: Executing the observer StructExpander from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 16.12 12:59:11" (1/1) ... [2021-12-16 00:59:11,172 INFO L185 PluginConnector]: Executing the observer UnstructureCode from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 16.12 12:59:11" (1/1) ... [2021-12-16 00:59:11,175 INFO L185 PluginConnector]: Executing the observer FunctionInliner from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 16.12 12:59:11" (1/1) ... [2021-12-16 00:59:11,176 INFO L185 PluginConnector]: Executing the observer BoogieSymbolTableConstructor from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 16.12 12:59:11" (1/1) ... [2021-12-16 00:59:11,178 INFO L132 PluginConnector]: ------------------------ END Boogie Preprocessor---------------------------- [2021-12-16 00:59:11,178 INFO L113 PluginConnector]: ------------------------RCFGBuilder---------------------------- [2021-12-16 00:59:11,179 INFO L271 PluginConnector]: Initializing RCFGBuilder... [2021-12-16 00:59:11,179 INFO L275 PluginConnector]: RCFGBuilder initialized [2021-12-16 00:59:11,179 INFO L185 PluginConnector]: Executing the observer RCFGBuilderObserver from plugin RCFGBuilder for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 16.12 12:59:11" (1/1) ... [2021-12-16 00:59:11,197 INFO L168 SolverBuilder]: Constructing external solver with command: z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in -t:2000 [2021-12-16 00:59:11,205 INFO L189 MonitoredProcess]: No working directory specified, using /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 [2021-12-16 00:59:11,214 INFO L229 MonitoredProcess]: Starting monitored process 1 with /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in -t:2000 (exit command is (exit), workingDir is null) [2021-12-16 00:59:11,216 INFO L327 MonitoredProcess]: [MP /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in -t:2000 (1)] Waiting until timeout for monitored process [2021-12-16 00:59:11,242 INFO L130 BoogieDeclarations]: Found specification of procedure #Ultimate.allocInit [2021-12-16 00:59:11,242 INFO L130 BoogieDeclarations]: Found specification of procedure processEnvironment__wrappee__base [2021-12-16 00:59:11,242 INFO L138 BoogieDeclarations]: Found implementation of procedure processEnvironment__wrappee__base [2021-12-16 00:59:11,242 INFO L130 BoogieDeclarations]: Found specification of procedure timeShift [2021-12-16 00:59:11,242 INFO L138 BoogieDeclarations]: Found implementation of procedure timeShift [2021-12-16 00:59:11,243 INFO L130 BoogieDeclarations]: Found specification of procedure cleanup [2021-12-16 00:59:11,243 INFO L138 BoogieDeclarations]: Found implementation of procedure cleanup [2021-12-16 00:59:11,243 INFO L130 BoogieDeclarations]: Found specification of procedure isMethaneLevelCritical [2021-12-16 00:59:11,243 INFO L138 BoogieDeclarations]: Found implementation of procedure isMethaneLevelCritical [2021-12-16 00:59:11,243 INFO L130 BoogieDeclarations]: Found specification of procedure waterRise [2021-12-16 00:59:11,243 INFO L138 BoogieDeclarations]: Found implementation of procedure waterRise [2021-12-16 00:59:11,243 INFO L130 BoogieDeclarations]: Found specification of procedure processEnvironment__wrappee__methaneQuery [2021-12-16 00:59:11,243 INFO L138 BoogieDeclarations]: Found implementation of procedure processEnvironment__wrappee__methaneQuery [2021-12-16 00:59:11,243 INFO L130 BoogieDeclarations]: Found specification of procedure isMethaneAlarm [2021-12-16 00:59:11,244 INFO L138 BoogieDeclarations]: Found implementation of procedure isMethaneAlarm [2021-12-16 00:59:11,244 INFO L130 BoogieDeclarations]: Found specification of procedure write~init~int [2021-12-16 00:59:11,244 INFO L130 BoogieDeclarations]: Found specification of procedure changeMethaneLevel [2021-12-16 00:59:11,244 INFO L138 BoogieDeclarations]: Found implementation of procedure changeMethaneLevel [2021-12-16 00:59:11,244 INFO L130 BoogieDeclarations]: Found specification of procedure ULTIMATE.start [2021-12-16 00:59:11,244 INFO L138 BoogieDeclarations]: Found implementation of procedure ULTIMATE.start [2021-12-16 00:59:11,299 INFO L236 CfgBuilder]: Building ICFG [2021-12-16 00:59:11,301 INFO L262 CfgBuilder]: Building CFG for each procedure with an implementation [2021-12-16 00:59:11,453 INFO L277 CfgBuilder]: Performing block encoding [2021-12-16 00:59:11,458 INFO L296 CfgBuilder]: Using the 1 location(s) as analysis (start of procedure ULTIMATE.start) [2021-12-16 00:59:11,458 INFO L301 CfgBuilder]: Removed 2 assume(true) statements. [2021-12-16 00:59:11,460 INFO L202 PluginConnector]: Adding new model de.uni_freiburg.informatik.ultimate.plugins.generator.rcfgbuilder CFG 16.12 12:59:11 BoogieIcfgContainer [2021-12-16 00:59:11,460 INFO L132 PluginConnector]: ------------------------ END RCFGBuilder---------------------------- [2021-12-16 00:59:11,461 INFO L113 PluginConnector]: ------------------------TraceAbstraction---------------------------- [2021-12-16 00:59:11,461 INFO L271 PluginConnector]: Initializing TraceAbstraction... [2021-12-16 00:59:11,463 INFO L275 PluginConnector]: TraceAbstraction initialized [2021-12-16 00:59:11,463 INFO L185 PluginConnector]: Executing the observer TraceAbstractionObserver from plugin TraceAbstraction for "CDTParser AST 16.12 12:59:10" (1/3) ... [2021-12-16 00:59:11,464 INFO L205 PluginConnector]: Invalid model from TraceAbstraction for observer de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction.TraceAbstractionObserver@6778b8ee and model type de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction AST 16.12 12:59:11, skipping insertion in model container [2021-12-16 00:59:11,464 INFO L185 PluginConnector]: Executing the observer TraceAbstractionObserver from plugin TraceAbstraction for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 16.12 12:59:11" (2/3) ... [2021-12-16 00:59:11,464 INFO L205 PluginConnector]: Invalid model from TraceAbstraction for observer de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction.TraceAbstractionObserver@6778b8ee and model type de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction AST 16.12 12:59:11, skipping insertion in model container [2021-12-16 00:59:11,464 INFO L185 PluginConnector]: Executing the observer TraceAbstractionObserver from plugin TraceAbstraction for "de.uni_freiburg.informatik.ultimate.plugins.generator.rcfgbuilder CFG 16.12 12:59:11" (3/3) ... [2021-12-16 00:59:11,465 INFO L111 eAbstractionObserver]: Analyzing ICFG minepump_spec2_product46.cil.c [2021-12-16 00:59:11,468 INFO L204 ceAbstractionStarter]: Automizer settings: Hoare:true NWA Interpolation:FPandBP Determinization: PREDICATE_ABSTRACTION [2021-12-16 00:59:11,468 INFO L163 ceAbstractionStarter]: Applying trace abstraction to program that has 1 error locations. [2021-12-16 00:59:11,496 INFO L338 AbstractCegarLoop]: ======== Iteration 0 == of CEGAR loop == AllErrorsAtOnce ======== [2021-12-16 00:59:11,501 INFO L339 AbstractCegarLoop]: Settings: SEPARATE_VIOLATION_CHECK=true, mInterprocedural=true, mMaxIterations=1000000, mWatchIteration=1000000, mArtifact=RCFG, mInterpolation=FPandBP, mInterpolantAutomaton=STRAIGHT_LINE, mDumpAutomata=false, mAutomataFormat=ATS_NUMERATE, mDumpPath=., mDeterminiation=PREDICATE_ABSTRACTION, mMinimize=MINIMIZE_SEVPA, mHoare=true, mAutomataTypeConcurrency=PETRI_NET, mHoareTripleChecks=INCREMENTAL, mHoareAnnotationPositions=LoopsAndPotentialCycles, mDumpOnlyReuseAutomata=false, mLimitTraceHistogram=0, mErrorLocTimeLimit=0, mLimitPathProgramCount=0, mCollectInterpolantStatistics=true, mHeuristicEmptinessCheck=false, mHeuristicEmptinessCheckAStarHeuristic=ZERO, mHeuristicEmptinessCheckAStarHeuristicRandomSeed=1337, mHeuristicEmptinessCheckSmtFeatureScoringMethod=DAGSIZE, mSMTFeatureExtraction=false, mSMTFeatureExtractionDumpPath=., mOverrideInterpolantAutomaton=false, mMcrInterpolantMethod=WP, mLoopAccelerationTechnique=FAST_UPR [2021-12-16 00:59:11,501 INFO L340 AbstractCegarLoop]: Starting to check reachability of 1 error locations. [2021-12-16 00:59:11,514 INFO L276 IsEmpty]: Start isEmpty. Operand has 96 states, 72 states have (on average 1.375) internal successors, (99), 80 states have internal predecessors, (99), 14 states have call successors, (14), 8 states have call predecessors, (14), 8 states have return successors, (14), 12 states have call predecessors, (14), 14 states have call successors, (14) [2021-12-16 00:59:11,519 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 26 [2021-12-16 00:59:11,519 INFO L506 BasicCegarLoop]: Found error trace [2021-12-16 00:59:11,520 INFO L514 BasicCegarLoop]: trace histogram [1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2021-12-16 00:59:11,520 INFO L402 AbstractCegarLoop]: === Iteration 1 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2021-12-16 00:59:11,525 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2021-12-16 00:59:11,525 INFO L85 PathProgramCache]: Analyzing trace with hash 92222794, now seen corresponding path program 1 times [2021-12-16 00:59:11,531 INFO L121 FreeRefinementEngine]: Executing refinement strategy CAMEL [2021-12-16 00:59:11,532 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [998633266] [2021-12-16 00:59:11,532 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2021-12-16 00:59:11,533 INFO L126 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2021-12-16 00:59:11,607 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 00:59:11,658 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 15 [2021-12-16 00:59:11,660 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 00:59:11,664 INFO L134 CoverageAnalysis]: Checked inductivity of 0 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2021-12-16 00:59:11,664 INFO L139 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2021-12-16 00:59:11,664 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [998633266] [2021-12-16 00:59:11,665 INFO L160 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [998633266] provided 1 perfect and 0 imperfect interpolant sequences [2021-12-16 00:59:11,665 INFO L186 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2021-12-16 00:59:11,665 INFO L199 FreeRefinementEngine]: Number of different interpolants: perfect sequences [2] imperfect sequences [] total 2 [2021-12-16 00:59:11,666 INFO L115 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [398399298] [2021-12-16 00:59:11,675 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2021-12-16 00:59:11,678 INFO L546 AbstractCegarLoop]: INTERPOLANT automaton has 2 states [2021-12-16 00:59:11,678 INFO L103 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2021-12-16 00:59:11,706 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 2 interpolants. [2021-12-16 00:59:11,708 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=1, Invalid=1, Unknown=0, NotChecked=0, Total=2 [2021-12-16 00:59:11,711 INFO L87 Difference]: Start difference. First operand has 96 states, 72 states have (on average 1.375) internal successors, (99), 80 states have internal predecessors, (99), 14 states have call successors, (14), 8 states have call predecessors, (14), 8 states have return successors, (14), 12 states have call predecessors, (14), 14 states have call successors, (14) Second operand has 2 states, 2 states have (on average 10.5) internal successors, (21), 2 states have internal predecessors, (21), 1 states have call successors, (3), 2 states have call predecessors, (3), 1 states have return successors, (1), 1 states have call predecessors, (1), 1 states have call successors, (1) [2021-12-16 00:59:11,755 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2021-12-16 00:59:11,756 INFO L93 Difference]: Finished difference Result 183 states and 248 transitions. [2021-12-16 00:59:11,756 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 2 states. [2021-12-16 00:59:11,758 INFO L78 Accepts]: Start accepts. Automaton has has 2 states, 2 states have (on average 10.5) internal successors, (21), 2 states have internal predecessors, (21), 1 states have call successors, (3), 2 states have call predecessors, (3), 1 states have return successors, (1), 1 states have call predecessors, (1), 1 states have call successors, (1) Word has length 25 [2021-12-16 00:59:11,758 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2021-12-16 00:59:11,772 INFO L225 Difference]: With dead ends: 183 [2021-12-16 00:59:11,773 INFO L226 Difference]: Without dead ends: 87 [2021-12-16 00:59:11,777 INFO L932 BasicCegarLoop]: 0 DeclaredPredicates, 4 GetRequests, 4 SyntacticMatches, 0 SemanticMatches, 0 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 0 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=1, Invalid=1, Unknown=0, NotChecked=0, Total=2 [2021-12-16 00:59:11,782 INFO L933 BasicCegarLoop]: 121 mSDtfsCounter, 0 mSDsluCounter, 0 mSDsCounter, 0 mSdLazyCounter, 0 mSolverCounterSat, 0 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.0s Time, 0 mProtectedPredicate, 0 mProtectedAction, 0 SdHoareTripleChecker+Valid, 121 SdHoareTripleChecker+Invalid, 0 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 0 IncrementalHoareTripleChecker+Valid, 0 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.0s IncrementalHoareTripleChecker+Time [2021-12-16 00:59:11,782 INFO L934 BasicCegarLoop]: SdHoareTripleChecker [0 Valid, 121 Invalid, 0 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [0 Valid, 0 Invalid, 0 Unknown, 0 Unchecked, 0.0s Time] [2021-12-16 00:59:11,793 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 87 states. [2021-12-16 00:59:11,817 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 87 to 87. [2021-12-16 00:59:11,820 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 87 states, 65 states have (on average 1.3076923076923077) internal successors, (85), 72 states have internal predecessors, (85), 14 states have call successors, (14), 8 states have call predecessors, (14), 7 states have return successors, (13), 11 states have call predecessors, (13), 13 states have call successors, (13) [2021-12-16 00:59:11,826 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 87 states to 87 states and 112 transitions. [2021-12-16 00:59:11,827 INFO L78 Accepts]: Start accepts. Automaton has 87 states and 112 transitions. Word has length 25 [2021-12-16 00:59:11,827 INFO L84 Accepts]: Finished accepts. word is rejected. [2021-12-16 00:59:11,827 INFO L470 AbstractCegarLoop]: Abstraction has 87 states and 112 transitions. [2021-12-16 00:59:11,827 INFO L471 AbstractCegarLoop]: INTERPOLANT automaton has has 2 states, 2 states have (on average 10.5) internal successors, (21), 2 states have internal predecessors, (21), 1 states have call successors, (3), 2 states have call predecessors, (3), 1 states have return successors, (1), 1 states have call predecessors, (1), 1 states have call successors, (1) [2021-12-16 00:59:11,828 INFO L276 IsEmpty]: Start isEmpty. Operand 87 states and 112 transitions. [2021-12-16 00:59:11,832 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 27 [2021-12-16 00:59:11,832 INFO L506 BasicCegarLoop]: Found error trace [2021-12-16 00:59:11,832 INFO L514 BasicCegarLoop]: trace histogram [1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2021-12-16 00:59:11,832 WARN L452 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable0 [2021-12-16 00:59:11,833 INFO L402 AbstractCegarLoop]: === Iteration 2 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2021-12-16 00:59:11,838 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2021-12-16 00:59:11,838 INFO L85 PathProgramCache]: Analyzing trace with hash -1552792509, now seen corresponding path program 1 times [2021-12-16 00:59:11,838 INFO L121 FreeRefinementEngine]: Executing refinement strategy CAMEL [2021-12-16 00:59:11,838 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [776054055] [2021-12-16 00:59:11,838 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2021-12-16 00:59:11,839 INFO L126 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2021-12-16 00:59:11,874 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 00:59:11,907 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 16 [2021-12-16 00:59:11,911 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 00:59:11,918 INFO L134 CoverageAnalysis]: Checked inductivity of 0 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2021-12-16 00:59:11,919 INFO L139 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2021-12-16 00:59:11,919 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [776054055] [2021-12-16 00:59:11,920 INFO L160 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [776054055] provided 1 perfect and 0 imperfect interpolant sequences [2021-12-16 00:59:11,920 INFO L186 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2021-12-16 00:59:11,920 INFO L199 FreeRefinementEngine]: Number of different interpolants: perfect sequences [3] imperfect sequences [] total 3 [2021-12-16 00:59:11,920 INFO L115 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [712647080] [2021-12-16 00:59:11,920 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2021-12-16 00:59:11,921 INFO L546 AbstractCegarLoop]: INTERPOLANT automaton has 3 states [2021-12-16 00:59:11,922 INFO L103 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2021-12-16 00:59:11,923 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 3 interpolants. [2021-12-16 00:59:11,923 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=3, Invalid=3, Unknown=0, NotChecked=0, Total=6 [2021-12-16 00:59:11,923 INFO L87 Difference]: Start difference. First operand 87 states and 112 transitions. Second operand has 3 states, 3 states have (on average 7.333333333333333) internal successors, (22), 3 states have internal predecessors, (22), 1 states have call successors, (3), 2 states have call predecessors, (3), 1 states have return successors, (1), 1 states have call predecessors, (1), 1 states have call successors, (1) [2021-12-16 00:59:11,947 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2021-12-16 00:59:11,948 INFO L93 Difference]: Finished difference Result 138 states and 178 transitions. [2021-12-16 00:59:11,950 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 3 states. [2021-12-16 00:59:11,950 INFO L78 Accepts]: Start accepts. Automaton has has 3 states, 3 states have (on average 7.333333333333333) internal successors, (22), 3 states have internal predecessors, (22), 1 states have call successors, (3), 2 states have call predecessors, (3), 1 states have return successors, (1), 1 states have call predecessors, (1), 1 states have call successors, (1) Word has length 26 [2021-12-16 00:59:11,951 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2021-12-16 00:59:11,951 INFO L225 Difference]: With dead ends: 138 [2021-12-16 00:59:11,952 INFO L226 Difference]: Without dead ends: 78 [2021-12-16 00:59:11,953 INFO L932 BasicCegarLoop]: 0 DeclaredPredicates, 5 GetRequests, 4 SyntacticMatches, 0 SemanticMatches, 1 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 0 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=3, Invalid=3, Unknown=0, NotChecked=0, Total=6 [2021-12-16 00:59:11,954 INFO L933 BasicCegarLoop]: 99 mSDtfsCounter, 13 mSDsluCounter, 82 mSDsCounter, 0 mSdLazyCounter, 1 mSolverCounterSat, 0 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.0s Time, 0 mProtectedPredicate, 0 mProtectedAction, 16 SdHoareTripleChecker+Valid, 181 SdHoareTripleChecker+Invalid, 1 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 0 IncrementalHoareTripleChecker+Valid, 1 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.0s IncrementalHoareTripleChecker+Time [2021-12-16 00:59:11,955 INFO L934 BasicCegarLoop]: SdHoareTripleChecker [16 Valid, 181 Invalid, 1 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [0 Valid, 1 Invalid, 0 Unknown, 0 Unchecked, 0.0s Time] [2021-12-16 00:59:11,956 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 78 states. [2021-12-16 00:59:11,962 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 78 to 78. [2021-12-16 00:59:11,965 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 78 states, 59 states have (on average 1.3220338983050848) internal successors, (78), 66 states have internal predecessors, (78), 11 states have call successors, (11), 7 states have call predecessors, (11), 7 states have return successors, (11), 9 states have call predecessors, (11), 11 states have call successors, (11) [2021-12-16 00:59:11,967 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 78 states to 78 states and 100 transitions. [2021-12-16 00:59:11,967 INFO L78 Accepts]: Start accepts. Automaton has 78 states and 100 transitions. Word has length 26 [2021-12-16 00:59:11,967 INFO L84 Accepts]: Finished accepts. word is rejected. [2021-12-16 00:59:11,968 INFO L470 AbstractCegarLoop]: Abstraction has 78 states and 100 transitions. [2021-12-16 00:59:11,968 INFO L471 AbstractCegarLoop]: INTERPOLANT automaton has has 3 states, 3 states have (on average 7.333333333333333) internal successors, (22), 3 states have internal predecessors, (22), 1 states have call successors, (3), 2 states have call predecessors, (3), 1 states have return successors, (1), 1 states have call predecessors, (1), 1 states have call successors, (1) [2021-12-16 00:59:11,968 INFO L276 IsEmpty]: Start isEmpty. Operand 78 states and 100 transitions. [2021-12-16 00:59:11,972 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 32 [2021-12-16 00:59:11,972 INFO L506 BasicCegarLoop]: Found error trace [2021-12-16 00:59:11,972 INFO L514 BasicCegarLoop]: trace histogram [1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2021-12-16 00:59:11,972 WARN L452 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable1 [2021-12-16 00:59:11,973 INFO L402 AbstractCegarLoop]: === Iteration 3 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2021-12-16 00:59:11,973 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2021-12-16 00:59:11,973 INFO L85 PathProgramCache]: Analyzing trace with hash 877193570, now seen corresponding path program 1 times [2021-12-16 00:59:11,974 INFO L121 FreeRefinementEngine]: Executing refinement strategy CAMEL [2021-12-16 00:59:11,974 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [1859838767] [2021-12-16 00:59:11,974 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2021-12-16 00:59:11,974 INFO L126 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2021-12-16 00:59:11,998 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 00:59:12,063 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 21 [2021-12-16 00:59:12,065 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 00:59:12,067 INFO L134 CoverageAnalysis]: Checked inductivity of 0 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2021-12-16 00:59:12,067 INFO L139 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2021-12-16 00:59:12,067 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [1859838767] [2021-12-16 00:59:12,067 INFO L160 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [1859838767] provided 1 perfect and 0 imperfect interpolant sequences [2021-12-16 00:59:12,068 INFO L186 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2021-12-16 00:59:12,068 INFO L199 FreeRefinementEngine]: Number of different interpolants: perfect sequences [6] imperfect sequences [] total 6 [2021-12-16 00:59:12,068 INFO L115 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [1120911071] [2021-12-16 00:59:12,068 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2021-12-16 00:59:12,068 INFO L546 AbstractCegarLoop]: INTERPOLANT automaton has 6 states [2021-12-16 00:59:12,069 INFO L103 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2021-12-16 00:59:12,069 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 6 interpolants. [2021-12-16 00:59:12,069 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=10, Invalid=20, Unknown=0, NotChecked=0, Total=30 [2021-12-16 00:59:12,069 INFO L87 Difference]: Start difference. First operand 78 states and 100 transitions. Second operand has 6 states, 6 states have (on average 4.666666666666667) internal successors, (28), 6 states have internal predecessors, (28), 2 states have call successors, (2), 2 states have call predecessors, (2), 1 states have return successors, (1), 1 states have call predecessors, (1), 1 states have call successors, (1) [2021-12-16 00:59:12,169 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2021-12-16 00:59:12,169 INFO L93 Difference]: Finished difference Result 148 states and 193 transitions. [2021-12-16 00:59:12,169 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 5 states. [2021-12-16 00:59:12,170 INFO L78 Accepts]: Start accepts. Automaton has has 6 states, 6 states have (on average 4.666666666666667) internal successors, (28), 6 states have internal predecessors, (28), 2 states have call successors, (2), 2 states have call predecessors, (2), 1 states have return successors, (1), 1 states have call predecessors, (1), 1 states have call successors, (1) Word has length 31 [2021-12-16 00:59:12,170 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2021-12-16 00:59:12,171 INFO L225 Difference]: With dead ends: 148 [2021-12-16 00:59:12,172 INFO L226 Difference]: Without dead ends: 78 [2021-12-16 00:59:12,173 INFO L932 BasicCegarLoop]: 0 DeclaredPredicates, 9 GetRequests, 3 SyntacticMatches, 0 SemanticMatches, 6 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 0 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=22, Invalid=34, Unknown=0, NotChecked=0, Total=56 [2021-12-16 00:59:12,176 INFO L933 BasicCegarLoop]: 93 mSDtfsCounter, 187 mSDsluCounter, 112 mSDsCounter, 0 mSdLazyCounter, 49 mSolverCounterSat, 35 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.0s Time, 0 mProtectedPredicate, 0 mProtectedAction, 187 SdHoareTripleChecker+Valid, 205 SdHoareTripleChecker+Invalid, 84 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 35 IncrementalHoareTripleChecker+Valid, 49 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.1s IncrementalHoareTripleChecker+Time [2021-12-16 00:59:12,176 INFO L934 BasicCegarLoop]: SdHoareTripleChecker [187 Valid, 205 Invalid, 84 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [35 Valid, 49 Invalid, 0 Unknown, 0 Unchecked, 0.1s Time] [2021-12-16 00:59:12,177 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 78 states. [2021-12-16 00:59:12,183 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 78 to 78. [2021-12-16 00:59:12,186 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 78 states, 59 states have (on average 1.305084745762712) internal successors, (77), 66 states have internal predecessors, (77), 11 states have call successors, (11), 7 states have call predecessors, (11), 7 states have return successors, (11), 9 states have call predecessors, (11), 11 states have call successors, (11) [2021-12-16 00:59:12,186 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 78 states to 78 states and 99 transitions. [2021-12-16 00:59:12,187 INFO L78 Accepts]: Start accepts. Automaton has 78 states and 99 transitions. Word has length 31 [2021-12-16 00:59:12,187 INFO L84 Accepts]: Finished accepts. word is rejected. [2021-12-16 00:59:12,187 INFO L470 AbstractCegarLoop]: Abstraction has 78 states and 99 transitions. [2021-12-16 00:59:12,187 INFO L471 AbstractCegarLoop]: INTERPOLANT automaton has has 6 states, 6 states have (on average 4.666666666666667) internal successors, (28), 6 states have internal predecessors, (28), 2 states have call successors, (2), 2 states have call predecessors, (2), 1 states have return successors, (1), 1 states have call predecessors, (1), 1 states have call successors, (1) [2021-12-16 00:59:12,187 INFO L276 IsEmpty]: Start isEmpty. Operand 78 states and 99 transitions. [2021-12-16 00:59:12,189 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 42 [2021-12-16 00:59:12,189 INFO L506 BasicCegarLoop]: Found error trace [2021-12-16 00:59:12,189 INFO L514 BasicCegarLoop]: trace histogram [1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2021-12-16 00:59:12,189 WARN L452 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable2 [2021-12-16 00:59:12,190 INFO L402 AbstractCegarLoop]: === Iteration 4 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2021-12-16 00:59:12,190 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2021-12-16 00:59:12,190 INFO L85 PathProgramCache]: Analyzing trace with hash -100681773, now seen corresponding path program 1 times [2021-12-16 00:59:12,190 INFO L121 FreeRefinementEngine]: Executing refinement strategy CAMEL [2021-12-16 00:59:12,191 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [1260473489] [2021-12-16 00:59:12,191 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2021-12-16 00:59:12,191 INFO L126 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2021-12-16 00:59:12,211 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 00:59:12,272 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 21 [2021-12-16 00:59:12,275 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 00:59:12,289 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 2 [2021-12-16 00:59:12,292 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 00:59:12,295 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 31 [2021-12-16 00:59:12,296 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 00:59:12,299 INFO L134 CoverageAnalysis]: Checked inductivity of 0 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2021-12-16 00:59:12,299 INFO L139 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2021-12-16 00:59:12,300 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [1260473489] [2021-12-16 00:59:12,300 INFO L160 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [1260473489] provided 1 perfect and 0 imperfect interpolant sequences [2021-12-16 00:59:12,300 INFO L186 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2021-12-16 00:59:12,300 INFO L199 FreeRefinementEngine]: Number of different interpolants: perfect sequences [5] imperfect sequences [] total 5 [2021-12-16 00:59:12,300 INFO L115 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [682338630] [2021-12-16 00:59:12,300 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2021-12-16 00:59:12,301 INFO L546 AbstractCegarLoop]: INTERPOLANT automaton has 5 states [2021-12-16 00:59:12,301 INFO L103 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2021-12-16 00:59:12,302 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 5 interpolants. [2021-12-16 00:59:12,302 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=7, Invalid=13, Unknown=0, NotChecked=0, Total=20 [2021-12-16 00:59:12,302 INFO L87 Difference]: Start difference. First operand 78 states and 99 transitions. Second operand has 5 states, 5 states have (on average 6.8) internal successors, (34), 5 states have internal predecessors, (34), 3 states have call successors, (4), 3 states have call predecessors, (4), 2 states have return successors, (3), 2 states have call predecessors, (3), 3 states have call successors, (3) [2021-12-16 00:59:12,455 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2021-12-16 00:59:12,455 INFO L93 Difference]: Finished difference Result 229 states and 291 transitions. [2021-12-16 00:59:12,455 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 7 states. [2021-12-16 00:59:12,456 INFO L78 Accepts]: Start accepts. Automaton has has 5 states, 5 states have (on average 6.8) internal successors, (34), 5 states have internal predecessors, (34), 3 states have call successors, (4), 3 states have call predecessors, (4), 2 states have return successors, (3), 2 states have call predecessors, (3), 3 states have call successors, (3) Word has length 41 [2021-12-16 00:59:12,456 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2021-12-16 00:59:12,457 INFO L225 Difference]: With dead ends: 229 [2021-12-16 00:59:12,457 INFO L226 Difference]: Without dead ends: 159 [2021-12-16 00:59:12,458 INFO L932 BasicCegarLoop]: 0 DeclaredPredicates, 15 GetRequests, 8 SyntacticMatches, 1 SemanticMatches, 6 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 3 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=19, Invalid=37, Unknown=0, NotChecked=0, Total=56 [2021-12-16 00:59:12,458 INFO L933 BasicCegarLoop]: 135 mSDtfsCounter, 181 mSDsluCounter, 174 mSDsCounter, 0 mSdLazyCounter, 106 mSolverCounterSat, 58 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.1s Time, 0 mProtectedPredicate, 0 mProtectedAction, 183 SdHoareTripleChecker+Valid, 309 SdHoareTripleChecker+Invalid, 164 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 58 IncrementalHoareTripleChecker+Valid, 106 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.1s IncrementalHoareTripleChecker+Time [2021-12-16 00:59:12,459 INFO L934 BasicCegarLoop]: SdHoareTripleChecker [183 Valid, 309 Invalid, 164 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [58 Valid, 106 Invalid, 0 Unknown, 0 Unchecked, 0.1s Time] [2021-12-16 00:59:12,459 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 159 states. [2021-12-16 00:59:12,469 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 159 to 153. [2021-12-16 00:59:12,469 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 153 states, 116 states have (on average 1.2672413793103448) internal successors, (147), 124 states have internal predecessors, (147), 18 states have call successors, (18), 15 states have call predecessors, (18), 18 states have return successors, (23), 19 states have call predecessors, (23), 18 states have call successors, (23) [2021-12-16 00:59:12,470 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 153 states to 153 states and 188 transitions. [2021-12-16 00:59:12,470 INFO L78 Accepts]: Start accepts. Automaton has 153 states and 188 transitions. Word has length 41 [2021-12-16 00:59:12,470 INFO L84 Accepts]: Finished accepts. word is rejected. [2021-12-16 00:59:12,470 INFO L470 AbstractCegarLoop]: Abstraction has 153 states and 188 transitions. [2021-12-16 00:59:12,471 INFO L471 AbstractCegarLoop]: INTERPOLANT automaton has has 5 states, 5 states have (on average 6.8) internal successors, (34), 5 states have internal predecessors, (34), 3 states have call successors, (4), 3 states have call predecessors, (4), 2 states have return successors, (3), 2 states have call predecessors, (3), 3 states have call successors, (3) [2021-12-16 00:59:12,471 INFO L276 IsEmpty]: Start isEmpty. Operand 153 states and 188 transitions. [2021-12-16 00:59:12,471 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 48 [2021-12-16 00:59:12,471 INFO L506 BasicCegarLoop]: Found error trace [2021-12-16 00:59:12,472 INFO L514 BasicCegarLoop]: trace histogram [1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2021-12-16 00:59:12,472 WARN L452 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable3 [2021-12-16 00:59:12,472 INFO L402 AbstractCegarLoop]: === Iteration 5 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2021-12-16 00:59:12,472 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2021-12-16 00:59:12,472 INFO L85 PathProgramCache]: Analyzing trace with hash -1653796005, now seen corresponding path program 1 times [2021-12-16 00:59:12,473 INFO L121 FreeRefinementEngine]: Executing refinement strategy CAMEL [2021-12-16 00:59:12,473 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [125856828] [2021-12-16 00:59:12,473 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2021-12-16 00:59:12,473 INFO L126 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2021-12-16 00:59:12,482 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 00:59:12,509 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 21 [2021-12-16 00:59:12,516 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 00:59:12,524 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 8 [2021-12-16 00:59:12,527 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 00:59:12,532 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 37 [2021-12-16 00:59:12,534 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 00:59:12,541 INFO L134 CoverageAnalysis]: Checked inductivity of 0 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2021-12-16 00:59:12,541 INFO L139 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2021-12-16 00:59:12,541 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [125856828] [2021-12-16 00:59:12,542 INFO L160 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [125856828] provided 1 perfect and 0 imperfect interpolant sequences [2021-12-16 00:59:12,542 INFO L186 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2021-12-16 00:59:12,542 INFO L199 FreeRefinementEngine]: Number of different interpolants: perfect sequences [7] imperfect sequences [] total 7 [2021-12-16 00:59:12,544 INFO L115 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [283355058] [2021-12-16 00:59:12,544 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2021-12-16 00:59:12,545 INFO L546 AbstractCegarLoop]: INTERPOLANT automaton has 7 states [2021-12-16 00:59:12,545 INFO L103 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2021-12-16 00:59:12,545 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 7 interpolants. [2021-12-16 00:59:12,545 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=11, Invalid=31, Unknown=0, NotChecked=0, Total=42 [2021-12-16 00:59:12,545 INFO L87 Difference]: Start difference. First operand 153 states and 188 transitions. Second operand has 7 states, 7 states have (on average 5.714285714285714) internal successors, (40), 5 states have internal predecessors, (40), 2 states have call successors, (4), 3 states have call predecessors, (4), 2 states have return successors, (3), 3 states have call predecessors, (3), 2 states have call successors, (3) [2021-12-16 00:59:12,724 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2021-12-16 00:59:12,724 INFO L93 Difference]: Finished difference Result 443 states and 552 transitions. [2021-12-16 00:59:12,724 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 13 states. [2021-12-16 00:59:12,733 INFO L78 Accepts]: Start accepts. Automaton has has 7 states, 7 states have (on average 5.714285714285714) internal successors, (40), 5 states have internal predecessors, (40), 2 states have call successors, (4), 3 states have call predecessors, (4), 2 states have return successors, (3), 3 states have call predecessors, (3), 2 states have call successors, (3) Word has length 47 [2021-12-16 00:59:12,733 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2021-12-16 00:59:12,735 INFO L225 Difference]: With dead ends: 443 [2021-12-16 00:59:12,735 INFO L226 Difference]: Without dead ends: 298 [2021-12-16 00:59:12,735 INFO L932 BasicCegarLoop]: 0 DeclaredPredicates, 19 GetRequests, 6 SyntacticMatches, 0 SemanticMatches, 13 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 23 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=53, Invalid=157, Unknown=0, NotChecked=0, Total=210 [2021-12-16 00:59:12,736 INFO L933 BasicCegarLoop]: 97 mSDtfsCounter, 148 mSDsluCounter, 349 mSDsCounter, 0 mSdLazyCounter, 209 mSolverCounterSat, 55 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.1s Time, 0 mProtectedPredicate, 0 mProtectedAction, 157 SdHoareTripleChecker+Valid, 446 SdHoareTripleChecker+Invalid, 264 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 55 IncrementalHoareTripleChecker+Valid, 209 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.1s IncrementalHoareTripleChecker+Time [2021-12-16 00:59:12,736 INFO L934 BasicCegarLoop]: SdHoareTripleChecker [157 Valid, 446 Invalid, 264 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [55 Valid, 209 Invalid, 0 Unknown, 0 Unchecked, 0.1s Time] [2021-12-16 00:59:12,737 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 298 states. [2021-12-16 00:59:12,751 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 298 to 284. [2021-12-16 00:59:12,751 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 284 states, 211 states have (on average 1.2274881516587677) internal successors, (259), 226 states have internal predecessors, (259), 36 states have call successors, (36), 30 states have call predecessors, (36), 36 states have return successors, (48), 38 states have call predecessors, (48), 36 states have call successors, (48) [2021-12-16 00:59:12,753 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 284 states to 284 states and 343 transitions. [2021-12-16 00:59:12,753 INFO L78 Accepts]: Start accepts. Automaton has 284 states and 343 transitions. Word has length 47 [2021-12-16 00:59:12,753 INFO L84 Accepts]: Finished accepts. word is rejected. [2021-12-16 00:59:12,753 INFO L470 AbstractCegarLoop]: Abstraction has 284 states and 343 transitions. [2021-12-16 00:59:12,753 INFO L471 AbstractCegarLoop]: INTERPOLANT automaton has has 7 states, 7 states have (on average 5.714285714285714) internal successors, (40), 5 states have internal predecessors, (40), 2 states have call successors, (4), 3 states have call predecessors, (4), 2 states have return successors, (3), 3 states have call predecessors, (3), 2 states have call successors, (3) [2021-12-16 00:59:12,753 INFO L276 IsEmpty]: Start isEmpty. Operand 284 states and 343 transitions. [2021-12-16 00:59:12,754 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 52 [2021-12-16 00:59:12,754 INFO L506 BasicCegarLoop]: Found error trace [2021-12-16 00:59:12,754 INFO L514 BasicCegarLoop]: trace histogram [1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2021-12-16 00:59:12,755 WARN L452 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable4 [2021-12-16 00:59:12,755 INFO L402 AbstractCegarLoop]: === Iteration 6 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2021-12-16 00:59:12,755 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2021-12-16 00:59:12,755 INFO L85 PathProgramCache]: Analyzing trace with hash 858621823, now seen corresponding path program 1 times [2021-12-16 00:59:12,755 INFO L121 FreeRefinementEngine]: Executing refinement strategy CAMEL [2021-12-16 00:59:12,756 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [94192361] [2021-12-16 00:59:12,756 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2021-12-16 00:59:12,756 INFO L126 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2021-12-16 00:59:12,764 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 00:59:12,799 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 14 [2021-12-16 00:59:12,800 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 00:59:12,807 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 25 [2021-12-16 00:59:12,809 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 00:59:12,814 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 8 [2021-12-16 00:59:12,815 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 00:59:12,816 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 41 [2021-12-16 00:59:12,817 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 00:59:12,819 INFO L134 CoverageAnalysis]: Checked inductivity of 0 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2021-12-16 00:59:12,819 INFO L139 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2021-12-16 00:59:12,819 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [94192361] [2021-12-16 00:59:12,819 INFO L160 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [94192361] provided 1 perfect and 0 imperfect interpolant sequences [2021-12-16 00:59:12,819 INFO L186 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2021-12-16 00:59:12,819 INFO L199 FreeRefinementEngine]: Number of different interpolants: perfect sequences [7] imperfect sequences [] total 7 [2021-12-16 00:59:12,820 INFO L115 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [2019048335] [2021-12-16 00:59:12,820 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2021-12-16 00:59:12,820 INFO L546 AbstractCegarLoop]: INTERPOLANT automaton has 7 states [2021-12-16 00:59:12,820 INFO L103 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2021-12-16 00:59:12,821 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 7 interpolants. [2021-12-16 00:59:12,821 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=11, Invalid=31, Unknown=0, NotChecked=0, Total=42 [2021-12-16 00:59:12,821 INFO L87 Difference]: Start difference. First operand 284 states and 343 transitions. Second operand has 7 states, 7 states have (on average 6.0) internal successors, (42), 5 states have internal predecessors, (42), 1 states have call successors, (5), 4 states have call predecessors, (5), 2 states have return successors, (4), 1 states have call predecessors, (4), 1 states have call successors, (4) [2021-12-16 00:59:13,124 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2021-12-16 00:59:13,125 INFO L93 Difference]: Finished difference Result 572 states and 692 transitions. [2021-12-16 00:59:13,125 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 15 states. [2021-12-16 00:59:13,125 INFO L78 Accepts]: Start accepts. Automaton has has 7 states, 7 states have (on average 6.0) internal successors, (42), 5 states have internal predecessors, (42), 1 states have call successors, (5), 4 states have call predecessors, (5), 2 states have return successors, (4), 1 states have call predecessors, (4), 1 states have call successors, (4) Word has length 51 [2021-12-16 00:59:13,126 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2021-12-16 00:59:13,127 INFO L225 Difference]: With dead ends: 572 [2021-12-16 00:59:13,127 INFO L226 Difference]: Without dead ends: 296 [2021-12-16 00:59:13,128 INFO L932 BasicCegarLoop]: 0 DeclaredPredicates, 28 GetRequests, 13 SyntacticMatches, 0 SemanticMatches, 15 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 35 ImplicationChecksByTransitivity, 0.1s TimeCoverageRelationStatistics Valid=84, Invalid=188, Unknown=0, NotChecked=0, Total=272 [2021-12-16 00:59:13,128 INFO L933 BasicCegarLoop]: 101 mSDtfsCounter, 187 mSDsluCounter, 151 mSDsCounter, 0 mSdLazyCounter, 336 mSolverCounterSat, 70 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.2s Time, 0 mProtectedPredicate, 0 mProtectedAction, 189 SdHoareTripleChecker+Valid, 252 SdHoareTripleChecker+Invalid, 406 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 70 IncrementalHoareTripleChecker+Valid, 336 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.2s IncrementalHoareTripleChecker+Time [2021-12-16 00:59:13,129 INFO L934 BasicCegarLoop]: SdHoareTripleChecker [189 Valid, 252 Invalid, 406 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [70 Valid, 336 Invalid, 0 Unknown, 0 Unchecked, 0.2s Time] [2021-12-16 00:59:13,129 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 296 states. [2021-12-16 00:59:13,140 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 296 to 282. [2021-12-16 00:59:13,141 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 282 states, 209 states have (on average 1.2105263157894737) internal successors, (253), 224 states have internal predecessors, (253), 36 states have call successors, (36), 30 states have call predecessors, (36), 36 states have return successors, (48), 38 states have call predecessors, (48), 36 states have call successors, (48) [2021-12-16 00:59:13,142 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 282 states to 282 states and 337 transitions. [2021-12-16 00:59:13,142 INFO L78 Accepts]: Start accepts. Automaton has 282 states and 337 transitions. Word has length 51 [2021-12-16 00:59:13,143 INFO L84 Accepts]: Finished accepts. word is rejected. [2021-12-16 00:59:13,143 INFO L470 AbstractCegarLoop]: Abstraction has 282 states and 337 transitions. [2021-12-16 00:59:13,143 INFO L471 AbstractCegarLoop]: INTERPOLANT automaton has has 7 states, 7 states have (on average 6.0) internal successors, (42), 5 states have internal predecessors, (42), 1 states have call successors, (5), 4 states have call predecessors, (5), 2 states have return successors, (4), 1 states have call predecessors, (4), 1 states have call successors, (4) [2021-12-16 00:59:13,143 INFO L276 IsEmpty]: Start isEmpty. Operand 282 states and 337 transitions. [2021-12-16 00:59:13,144 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 62 [2021-12-16 00:59:13,144 INFO L506 BasicCegarLoop]: Found error trace [2021-12-16 00:59:13,144 INFO L514 BasicCegarLoop]: trace histogram [2, 2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2021-12-16 00:59:13,144 WARN L452 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable5 [2021-12-16 00:59:13,144 INFO L402 AbstractCegarLoop]: === Iteration 7 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2021-12-16 00:59:13,145 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2021-12-16 00:59:13,145 INFO L85 PathProgramCache]: Analyzing trace with hash 1850253156, now seen corresponding path program 1 times [2021-12-16 00:59:13,145 INFO L121 FreeRefinementEngine]: Executing refinement strategy CAMEL [2021-12-16 00:59:13,145 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [331852497] [2021-12-16 00:59:13,145 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2021-12-16 00:59:13,145 INFO L126 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2021-12-16 00:59:13,153 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 00:59:13,166 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 14 [2021-12-16 00:59:13,166 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 00:59:13,170 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 25 [2021-12-16 00:59:13,172 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 00:59:13,188 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 8 [2021-12-16 00:59:13,190 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 00:59:13,191 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 1 [2021-12-16 00:59:13,192 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 00:59:13,193 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 51 [2021-12-16 00:59:13,193 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 00:59:13,195 INFO L134 CoverageAnalysis]: Checked inductivity of 3 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 3 trivial. 0 not checked. [2021-12-16 00:59:13,195 INFO L139 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2021-12-16 00:59:13,195 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [331852497] [2021-12-16 00:59:13,195 INFO L160 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [331852497] provided 1 perfect and 0 imperfect interpolant sequences [2021-12-16 00:59:13,195 INFO L186 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2021-12-16 00:59:13,196 INFO L199 FreeRefinementEngine]: Number of different interpolants: perfect sequences [7] imperfect sequences [] total 7 [2021-12-16 00:59:13,196 INFO L115 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [1318681725] [2021-12-16 00:59:13,196 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2021-12-16 00:59:13,196 INFO L546 AbstractCegarLoop]: INTERPOLANT automaton has 7 states [2021-12-16 00:59:13,196 INFO L103 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2021-12-16 00:59:13,197 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 7 interpolants. [2021-12-16 00:59:13,197 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=11, Invalid=31, Unknown=0, NotChecked=0, Total=42 [2021-12-16 00:59:13,197 INFO L87 Difference]: Start difference. First operand 282 states and 337 transitions. Second operand has 7 states, 7 states have (on average 6.857142857142857) internal successors, (48), 5 states have internal predecessors, (48), 2 states have call successors, (6), 3 states have call predecessors, (6), 2 states have return successors, (5), 2 states have call predecessors, (5), 2 states have call successors, (5) [2021-12-16 00:59:13,398 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2021-12-16 00:59:13,398 INFO L93 Difference]: Finished difference Result 574 states and 699 transitions. [2021-12-16 00:59:13,398 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 9 states. [2021-12-16 00:59:13,398 INFO L78 Accepts]: Start accepts. Automaton has has 7 states, 7 states have (on average 6.857142857142857) internal successors, (48), 5 states have internal predecessors, (48), 2 states have call successors, (6), 3 states have call predecessors, (6), 2 states have return successors, (5), 2 states have call predecessors, (5), 2 states have call successors, (5) Word has length 61 [2021-12-16 00:59:13,399 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2021-12-16 00:59:13,400 INFO L225 Difference]: With dead ends: 574 [2021-12-16 00:59:13,400 INFO L226 Difference]: Without dead ends: 300 [2021-12-16 00:59:13,401 INFO L932 BasicCegarLoop]: 0 DeclaredPredicates, 22 GetRequests, 12 SyntacticMatches, 0 SemanticMatches, 10 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 3 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=46, Invalid=86, Unknown=0, NotChecked=0, Total=132 [2021-12-16 00:59:13,401 INFO L933 BasicCegarLoop]: 91 mSDtfsCounter, 122 mSDsluCounter, 155 mSDsCounter, 0 mSdLazyCounter, 281 mSolverCounterSat, 52 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.1s Time, 0 mProtectedPredicate, 0 mProtectedAction, 123 SdHoareTripleChecker+Valid, 246 SdHoareTripleChecker+Invalid, 333 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 52 IncrementalHoareTripleChecker+Valid, 281 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.2s IncrementalHoareTripleChecker+Time [2021-12-16 00:59:13,401 INFO L934 BasicCegarLoop]: SdHoareTripleChecker [123 Valid, 246 Invalid, 333 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [52 Valid, 281 Invalid, 0 Unknown, 0 Unchecked, 0.2s Time] [2021-12-16 00:59:13,402 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 300 states. [2021-12-16 00:59:13,412 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 300 to 288. [2021-12-16 00:59:13,412 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 288 states, 215 states have (on average 1.2046511627906977) internal successors, (259), 230 states have internal predecessors, (259), 36 states have call successors, (36), 30 states have call predecessors, (36), 36 states have return successors, (48), 38 states have call predecessors, (48), 36 states have call successors, (48) [2021-12-16 00:59:13,413 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 288 states to 288 states and 343 transitions. [2021-12-16 00:59:13,413 INFO L78 Accepts]: Start accepts. Automaton has 288 states and 343 transitions. Word has length 61 [2021-12-16 00:59:13,414 INFO L84 Accepts]: Finished accepts. word is rejected. [2021-12-16 00:59:13,414 INFO L470 AbstractCegarLoop]: Abstraction has 288 states and 343 transitions. [2021-12-16 00:59:13,414 INFO L471 AbstractCegarLoop]: INTERPOLANT automaton has has 7 states, 7 states have (on average 6.857142857142857) internal successors, (48), 5 states have internal predecessors, (48), 2 states have call successors, (6), 3 states have call predecessors, (6), 2 states have return successors, (5), 2 states have call predecessors, (5), 2 states have call successors, (5) [2021-12-16 00:59:13,414 INFO L276 IsEmpty]: Start isEmpty. Operand 288 states and 343 transitions. [2021-12-16 00:59:13,415 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 62 [2021-12-16 00:59:13,415 INFO L506 BasicCegarLoop]: Found error trace [2021-12-16 00:59:13,415 INFO L514 BasicCegarLoop]: trace histogram [2, 2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2021-12-16 00:59:13,415 WARN L452 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable6 [2021-12-16 00:59:13,415 INFO L402 AbstractCegarLoop]: === Iteration 8 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2021-12-16 00:59:13,415 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2021-12-16 00:59:13,416 INFO L85 PathProgramCache]: Analyzing trace with hash -1743114266, now seen corresponding path program 1 times [2021-12-16 00:59:13,416 INFO L121 FreeRefinementEngine]: Executing refinement strategy CAMEL [2021-12-16 00:59:13,416 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [1197405773] [2021-12-16 00:59:13,416 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2021-12-16 00:59:13,416 INFO L126 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2021-12-16 00:59:13,423 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 00:59:13,435 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 14 [2021-12-16 00:59:13,436 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 00:59:13,439 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 25 [2021-12-16 00:59:13,441 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 00:59:13,461 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 8 [2021-12-16 00:59:13,462 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 00:59:13,464 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 1 [2021-12-16 00:59:13,464 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 00:59:13,465 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 51 [2021-12-16 00:59:13,466 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 00:59:13,467 INFO L134 CoverageAnalysis]: Checked inductivity of 3 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 3 trivial. 0 not checked. [2021-12-16 00:59:13,467 INFO L139 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2021-12-16 00:59:13,467 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [1197405773] [2021-12-16 00:59:13,467 INFO L160 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [1197405773] provided 1 perfect and 0 imperfect interpolant sequences [2021-12-16 00:59:13,467 INFO L186 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2021-12-16 00:59:13,467 INFO L199 FreeRefinementEngine]: Number of different interpolants: perfect sequences [6] imperfect sequences [] total 6 [2021-12-16 00:59:13,467 INFO L115 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [2002456746] [2021-12-16 00:59:13,467 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2021-12-16 00:59:13,468 INFO L546 AbstractCegarLoop]: INTERPOLANT automaton has 6 states [2021-12-16 00:59:13,468 INFO L103 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2021-12-16 00:59:13,468 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 6 interpolants. [2021-12-16 00:59:13,468 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=9, Invalid=21, Unknown=0, NotChecked=0, Total=30 [2021-12-16 00:59:13,468 INFO L87 Difference]: Start difference. First operand 288 states and 343 transitions. Second operand has 6 states, 6 states have (on average 8.0) internal successors, (48), 4 states have internal predecessors, (48), 2 states have call successors, (6), 3 states have call predecessors, (6), 2 states have return successors, (5), 2 states have call predecessors, (5), 2 states have call successors, (5) [2021-12-16 00:59:13,672 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2021-12-16 00:59:13,672 INFO L93 Difference]: Finished difference Result 586 states and 711 transitions. [2021-12-16 00:59:13,672 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 7 states. [2021-12-16 00:59:13,673 INFO L78 Accepts]: Start accepts. Automaton has has 6 states, 6 states have (on average 8.0) internal successors, (48), 4 states have internal predecessors, (48), 2 states have call successors, (6), 3 states have call predecessors, (6), 2 states have return successors, (5), 2 states have call predecessors, (5), 2 states have call successors, (5) Word has length 61 [2021-12-16 00:59:13,673 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2021-12-16 00:59:13,677 INFO L225 Difference]: With dead ends: 586 [2021-12-16 00:59:13,678 INFO L226 Difference]: Without dead ends: 306 [2021-12-16 00:59:13,678 INFO L932 BasicCegarLoop]: 0 DeclaredPredicates, 19 GetRequests, 12 SyntacticMatches, 0 SemanticMatches, 7 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 0 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=27, Invalid=45, Unknown=0, NotChecked=0, Total=72 [2021-12-16 00:59:13,679 INFO L933 BasicCegarLoop]: 91 mSDtfsCounter, 128 mSDsluCounter, 118 mSDsCounter, 0 mSdLazyCounter, 203 mSolverCounterSat, 49 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.1s Time, 0 mProtectedPredicate, 0 mProtectedAction, 129 SdHoareTripleChecker+Valid, 209 SdHoareTripleChecker+Invalid, 252 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 49 IncrementalHoareTripleChecker+Valid, 203 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.2s IncrementalHoareTripleChecker+Time [2021-12-16 00:59:13,680 INFO L934 BasicCegarLoop]: SdHoareTripleChecker [129 Valid, 209 Invalid, 252 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [49 Valid, 203 Invalid, 0 Unknown, 0 Unchecked, 0.2s Time] [2021-12-16 00:59:13,680 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 306 states. [2021-12-16 00:59:13,693 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 306 to 292. [2021-12-16 00:59:13,694 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 292 states, 219 states have (on average 1.2009132420091324) internal successors, (263), 234 states have internal predecessors, (263), 36 states have call successors, (36), 30 states have call predecessors, (36), 36 states have return successors, (48), 38 states have call predecessors, (48), 36 states have call successors, (48) [2021-12-16 00:59:13,696 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 292 states to 292 states and 347 transitions. [2021-12-16 00:59:13,696 INFO L78 Accepts]: Start accepts. Automaton has 292 states and 347 transitions. Word has length 61 [2021-12-16 00:59:13,696 INFO L84 Accepts]: Finished accepts. word is rejected. [2021-12-16 00:59:13,697 INFO L470 AbstractCegarLoop]: Abstraction has 292 states and 347 transitions. [2021-12-16 00:59:13,697 INFO L471 AbstractCegarLoop]: INTERPOLANT automaton has has 6 states, 6 states have (on average 8.0) internal successors, (48), 4 states have internal predecessors, (48), 2 states have call successors, (6), 3 states have call predecessors, (6), 2 states have return successors, (5), 2 states have call predecessors, (5), 2 states have call successors, (5) [2021-12-16 00:59:13,698 INFO L276 IsEmpty]: Start isEmpty. Operand 292 states and 347 transitions. [2021-12-16 00:59:13,699 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 62 [2021-12-16 00:59:13,699 INFO L506 BasicCegarLoop]: Found error trace [2021-12-16 00:59:13,699 INFO L514 BasicCegarLoop]: trace histogram [2, 2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2021-12-16 00:59:13,699 WARN L452 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable7 [2021-12-16 00:59:13,700 INFO L402 AbstractCegarLoop]: === Iteration 9 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2021-12-16 00:59:13,700 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2021-12-16 00:59:13,700 INFO L85 PathProgramCache]: Analyzing trace with hash -1815500824, now seen corresponding path program 1 times [2021-12-16 00:59:13,700 INFO L121 FreeRefinementEngine]: Executing refinement strategy CAMEL [2021-12-16 00:59:13,700 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [1371535365] [2021-12-16 00:59:13,701 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2021-12-16 00:59:13,701 INFO L126 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2021-12-16 00:59:13,715 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 00:59:13,741 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 14 [2021-12-16 00:59:13,743 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 00:59:13,747 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 25 [2021-12-16 00:59:13,748 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 00:59:13,769 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 8 [2021-12-16 00:59:13,771 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 00:59:13,775 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 1 [2021-12-16 00:59:13,775 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 00:59:13,777 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 51 [2021-12-16 00:59:13,777 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 00:59:13,780 INFO L134 CoverageAnalysis]: Checked inductivity of 3 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 3 trivial. 0 not checked. [2021-12-16 00:59:13,781 INFO L139 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2021-12-16 00:59:13,781 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [1371535365] [2021-12-16 00:59:13,781 INFO L160 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [1371535365] provided 1 perfect and 0 imperfect interpolant sequences [2021-12-16 00:59:13,781 INFO L186 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2021-12-16 00:59:13,781 INFO L199 FreeRefinementEngine]: Number of different interpolants: perfect sequences [6] imperfect sequences [] total 6 [2021-12-16 00:59:13,781 INFO L115 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [96345368] [2021-12-16 00:59:13,781 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2021-12-16 00:59:13,782 INFO L546 AbstractCegarLoop]: INTERPOLANT automaton has 6 states [2021-12-16 00:59:13,783 INFO L103 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2021-12-16 00:59:13,783 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 6 interpolants. [2021-12-16 00:59:13,783 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=9, Invalid=21, Unknown=0, NotChecked=0, Total=30 [2021-12-16 00:59:13,785 INFO L87 Difference]: Start difference. First operand 292 states and 347 transitions. Second operand has 6 states, 6 states have (on average 8.0) internal successors, (48), 4 states have internal predecessors, (48), 4 states have call successors, (6), 4 states have call predecessors, (6), 2 states have return successors, (5), 4 states have call predecessors, (5), 4 states have call successors, (5) [2021-12-16 00:59:14,052 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2021-12-16 00:59:14,053 INFO L93 Difference]: Finished difference Result 804 states and 1007 transitions. [2021-12-16 00:59:14,053 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 12 states. [2021-12-16 00:59:14,053 INFO L78 Accepts]: Start accepts. Automaton has has 6 states, 6 states have (on average 8.0) internal successors, (48), 4 states have internal predecessors, (48), 4 states have call successors, (6), 4 states have call predecessors, (6), 2 states have return successors, (5), 4 states have call predecessors, (5), 4 states have call successors, (5) Word has length 61 [2021-12-16 00:59:14,054 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2021-12-16 00:59:14,058 INFO L225 Difference]: With dead ends: 804 [2021-12-16 00:59:14,058 INFO L226 Difference]: Without dead ends: 520 [2021-12-16 00:59:14,059 INFO L932 BasicCegarLoop]: 0 DeclaredPredicates, 25 GetRequests, 15 SyntacticMatches, 0 SemanticMatches, 10 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 15 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=40, Invalid=92, Unknown=0, NotChecked=0, Total=132 [2021-12-16 00:59:14,060 INFO L933 BasicCegarLoop]: 135 mSDtfsCounter, 298 mSDsluCounter, 124 mSDsCounter, 0 mSdLazyCounter, 253 mSolverCounterSat, 129 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.2s Time, 0 mProtectedPredicate, 0 mProtectedAction, 300 SdHoareTripleChecker+Valid, 259 SdHoareTripleChecker+Invalid, 382 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 129 IncrementalHoareTripleChecker+Valid, 253 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.2s IncrementalHoareTripleChecker+Time [2021-12-16 00:59:14,061 INFO L934 BasicCegarLoop]: SdHoareTripleChecker [300 Valid, 259 Invalid, 382 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [129 Valid, 253 Invalid, 0 Unknown, 0 Unchecked, 0.2s Time] [2021-12-16 00:59:14,061 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 520 states. [2021-12-16 00:59:14,096 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 520 to 518. [2021-12-16 00:59:14,097 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 518 states, 389 states have (on average 1.19280205655527) internal successors, (464), 412 states have internal predecessors, (464), 66 states have call successors, (66), 60 states have call predecessors, (66), 62 states have return successors, (101), 66 states have call predecessors, (101), 66 states have call successors, (101) [2021-12-16 00:59:14,101 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 518 states to 518 states and 631 transitions. [2021-12-16 00:59:14,102 INFO L78 Accepts]: Start accepts. Automaton has 518 states and 631 transitions. Word has length 61 [2021-12-16 00:59:14,102 INFO L84 Accepts]: Finished accepts. word is rejected. [2021-12-16 00:59:14,102 INFO L470 AbstractCegarLoop]: Abstraction has 518 states and 631 transitions. [2021-12-16 00:59:14,102 INFO L471 AbstractCegarLoop]: INTERPOLANT automaton has has 6 states, 6 states have (on average 8.0) internal successors, (48), 4 states have internal predecessors, (48), 4 states have call successors, (6), 4 states have call predecessors, (6), 2 states have return successors, (5), 4 states have call predecessors, (5), 4 states have call successors, (5) [2021-12-16 00:59:14,102 INFO L276 IsEmpty]: Start isEmpty. Operand 518 states and 631 transitions. [2021-12-16 00:59:14,103 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 66 [2021-12-16 00:59:14,103 INFO L506 BasicCegarLoop]: Found error trace [2021-12-16 00:59:14,103 INFO L514 BasicCegarLoop]: trace histogram [2, 2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2021-12-16 00:59:14,104 WARN L452 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable8 [2021-12-16 00:59:14,104 INFO L402 AbstractCegarLoop]: === Iteration 10 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2021-12-16 00:59:14,104 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2021-12-16 00:59:14,104 INFO L85 PathProgramCache]: Analyzing trace with hash -1657207794, now seen corresponding path program 1 times [2021-12-16 00:59:14,104 INFO L121 FreeRefinementEngine]: Executing refinement strategy CAMEL [2021-12-16 00:59:14,105 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [1038413169] [2021-12-16 00:59:14,105 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2021-12-16 00:59:14,105 INFO L126 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2021-12-16 00:59:14,115 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 00:59:14,154 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 12 [2021-12-16 00:59:14,156 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 00:59:14,161 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 18 [2021-12-16 00:59:14,162 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 00:59:14,172 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 29 [2021-12-16 00:59:14,177 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 00:59:14,201 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 8 [2021-12-16 00:59:14,203 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 00:59:14,220 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 1 [2021-12-16 00:59:14,221 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 00:59:14,231 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 55 [2021-12-16 00:59:14,232 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 00:59:14,234 INFO L134 CoverageAnalysis]: Checked inductivity of 3 backedges. 0 proven. 2 refuted. 0 times theorem prover too weak. 1 trivial. 0 not checked. [2021-12-16 00:59:14,234 INFO L139 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2021-12-16 00:59:14,234 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [1038413169] [2021-12-16 00:59:14,247 INFO L160 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [1038413169] provided 0 perfect and 1 imperfect interpolant sequences [2021-12-16 00:59:14,247 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleZ3 [1969147172] [2021-12-16 00:59:14,247 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2021-12-16 00:59:14,248 INFO L168 SolverBuilder]: Constructing external solver with command: z3 -smt2 -in SMTLIB2_COMPLIANT=true [2021-12-16 00:59:14,248 INFO L189 MonitoredProcess]: No working directory specified, using /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 [2021-12-16 00:59:14,252 INFO L229 MonitoredProcess]: Starting monitored process 2 with /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 -smt2 -in SMTLIB2_COMPLIANT=true (exit command is (exit), workingDir is null) [2021-12-16 00:59:14,275 INFO L327 MonitoredProcess]: [MP /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 -smt2 -in SMTLIB2_COMPLIANT=true (2)] Waiting until timeout for monitored process [2021-12-16 00:59:14,349 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 00:59:14,351 INFO L263 TraceCheckSpWp]: Trace formula consists of 397 conjuncts, 9 conjunts are in the unsatisfiable core [2021-12-16 00:59:14,355 INFO L286 TraceCheckSpWp]: Computing forward predicates... [2021-12-16 00:59:14,649 INFO L134 CoverageAnalysis]: Checked inductivity of 3 backedges. 3 proven. 0 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2021-12-16 00:59:14,649 INFO L324 TraceCheckSpWp]: Omiting computation of backward sequence because forward sequence was already perfect [2021-12-16 00:59:14,649 INFO L160 FreeRefinementEngine]: IpTcStrategyModuleZ3 [1969147172] provided 1 perfect and 0 imperfect interpolant sequences [2021-12-16 00:59:14,649 INFO L186 FreeRefinementEngine]: Found 1 perfect and 1 imperfect interpolant sequences. [2021-12-16 00:59:14,649 INFO L199 FreeRefinementEngine]: Number of different interpolants: perfect sequences [8] imperfect sequences [15] total 20 [2021-12-16 00:59:14,650 INFO L115 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [1086454584] [2021-12-16 00:59:14,650 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2021-12-16 00:59:14,650 INFO L546 AbstractCegarLoop]: INTERPOLANT automaton has 8 states [2021-12-16 00:59:14,650 INFO L103 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2021-12-16 00:59:14,650 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 8 interpolants. [2021-12-16 00:59:14,651 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=48, Invalid=332, Unknown=0, NotChecked=0, Total=380 [2021-12-16 00:59:14,651 INFO L87 Difference]: Start difference. First operand 518 states and 631 transitions. Second operand has 8 states, 8 states have (on average 6.5) internal successors, (52), 6 states have internal predecessors, (52), 3 states have call successors, (7), 3 states have call predecessors, (7), 5 states have return successors, (6), 5 states have call predecessors, (6), 3 states have call successors, (6) [2021-12-16 00:59:14,805 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2021-12-16 00:59:14,805 INFO L93 Difference]: Finished difference Result 1006 states and 1230 transitions. [2021-12-16 00:59:14,806 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 8 states. [2021-12-16 00:59:14,806 INFO L78 Accepts]: Start accepts. Automaton has has 8 states, 8 states have (on average 6.5) internal successors, (52), 6 states have internal predecessors, (52), 3 states have call successors, (7), 3 states have call predecessors, (7), 5 states have return successors, (6), 5 states have call predecessors, (6), 3 states have call successors, (6) Word has length 65 [2021-12-16 00:59:14,806 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2021-12-16 00:59:14,808 INFO L225 Difference]: With dead ends: 1006 [2021-12-16 00:59:14,808 INFO L226 Difference]: Without dead ends: 496 [2021-12-16 00:59:14,809 INFO L932 BasicCegarLoop]: 0 DeclaredPredicates, 87 GetRequests, 69 SyntacticMatches, 0 SemanticMatches, 18 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 7 ImplicationChecksByTransitivity, 0.2s TimeCoverageRelationStatistics Valid=48, Invalid=332, Unknown=0, NotChecked=0, Total=380 [2021-12-16 00:59:14,809 INFO L933 BasicCegarLoop]: 175 mSDtfsCounter, 61 mSDsluCounter, 648 mSDsCounter, 0 mSdLazyCounter, 158 mSolverCounterSat, 3 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.1s Time, 0 mProtectedPredicate, 0 mProtectedAction, 65 SdHoareTripleChecker+Valid, 823 SdHoareTripleChecker+Invalid, 161 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 3 IncrementalHoareTripleChecker+Valid, 158 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.1s IncrementalHoareTripleChecker+Time [2021-12-16 00:59:14,810 INFO L934 BasicCegarLoop]: SdHoareTripleChecker [65 Valid, 823 Invalid, 161 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [3 Valid, 158 Invalid, 0 Unknown, 0 Unchecked, 0.1s Time] [2021-12-16 00:59:14,810 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 496 states. [2021-12-16 00:59:14,829 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 496 to 494. [2021-12-16 00:59:14,830 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 494 states, 370 states have (on average 1.1756756756756757) internal successors, (435), 392 states have internal predecessors, (435), 64 states have call successors, (64), 58 states have call predecessors, (64), 59 states have return successors, (88), 63 states have call predecessors, (88), 64 states have call successors, (88) [2021-12-16 00:59:14,831 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 494 states to 494 states and 587 transitions. [2021-12-16 00:59:14,831 INFO L78 Accepts]: Start accepts. Automaton has 494 states and 587 transitions. Word has length 65 [2021-12-16 00:59:14,832 INFO L84 Accepts]: Finished accepts. word is rejected. [2021-12-16 00:59:14,832 INFO L470 AbstractCegarLoop]: Abstraction has 494 states and 587 transitions. [2021-12-16 00:59:14,833 INFO L471 AbstractCegarLoop]: INTERPOLANT automaton has has 8 states, 8 states have (on average 6.5) internal successors, (52), 6 states have internal predecessors, (52), 3 states have call successors, (7), 3 states have call predecessors, (7), 5 states have return successors, (6), 5 states have call predecessors, (6), 3 states have call successors, (6) [2021-12-16 00:59:14,833 INFO L276 IsEmpty]: Start isEmpty. Operand 494 states and 587 transitions. [2021-12-16 00:59:14,837 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 111 [2021-12-16 00:59:14,837 INFO L506 BasicCegarLoop]: Found error trace [2021-12-16 00:59:14,837 INFO L514 BasicCegarLoop]: trace histogram [4, 4, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2021-12-16 00:59:14,875 INFO L552 MonitoredProcess]: [MP /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 -smt2 -in SMTLIB2_COMPLIANT=true (2)] Ended with exit code 0 [2021-12-16 00:59:15,055 WARN L452 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: 2 /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 -smt2 -in SMTLIB2_COMPLIANT=true,SelfDestructingSolverStorable9 [2021-12-16 00:59:15,055 INFO L402 AbstractCegarLoop]: === Iteration 11 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2021-12-16 00:59:15,056 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2021-12-16 00:59:15,056 INFO L85 PathProgramCache]: Analyzing trace with hash 1520356328, now seen corresponding path program 1 times [2021-12-16 00:59:15,056 INFO L121 FreeRefinementEngine]: Executing refinement strategy CAMEL [2021-12-16 00:59:15,056 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [479356938] [2021-12-16 00:59:15,056 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2021-12-16 00:59:15,057 INFO L126 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2021-12-16 00:59:15,073 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 00:59:15,112 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 12 [2021-12-16 00:59:15,112 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 00:59:15,121 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 21 [2021-12-16 00:59:15,122 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 00:59:15,130 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 3 [2021-12-16 00:59:15,131 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 00:59:15,133 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 8 [2021-12-16 00:59:15,134 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 00:59:15,135 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 1 [2021-12-16 00:59:15,135 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 00:59:15,137 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 29 [2021-12-16 00:59:15,137 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 00:59:15,143 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 66 [2021-12-16 00:59:15,144 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 00:59:15,152 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 79 [2021-12-16 00:59:15,153 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 00:59:15,206 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 1 [2021-12-16 00:59:15,207 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 00:59:15,217 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 90 [2021-12-16 00:59:15,217 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 00:59:15,219 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 2 [2021-12-16 00:59:15,219 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 00:59:15,220 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 100 [2021-12-16 00:59:15,220 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 00:59:15,222 INFO L134 CoverageAnalysis]: Checked inductivity of 45 backedges. 18 proven. 3 refuted. 0 times theorem prover too weak. 24 trivial. 0 not checked. [2021-12-16 00:59:15,222 INFO L139 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2021-12-16 00:59:15,222 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [479356938] [2021-12-16 00:59:15,222 INFO L160 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [479356938] provided 0 perfect and 1 imperfect interpolant sequences [2021-12-16 00:59:15,222 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleZ3 [839923177] [2021-12-16 00:59:15,222 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2021-12-16 00:59:15,222 INFO L168 SolverBuilder]: Constructing external solver with command: z3 -smt2 -in SMTLIB2_COMPLIANT=true [2021-12-16 00:59:15,222 INFO L189 MonitoredProcess]: No working directory specified, using /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 [2021-12-16 00:59:15,236 INFO L229 MonitoredProcess]: Starting monitored process 3 with /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 -smt2 -in SMTLIB2_COMPLIANT=true (exit command is (exit), workingDir is null) [2021-12-16 00:59:15,278 INFO L327 MonitoredProcess]: [MP /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 -smt2 -in SMTLIB2_COMPLIANT=true (3)] Waiting until timeout for monitored process [2021-12-16 00:59:15,336 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 00:59:15,338 INFO L263 TraceCheckSpWp]: Trace formula consists of 508 conjuncts, 9 conjunts are in the unsatisfiable core [2021-12-16 00:59:15,345 INFO L286 TraceCheckSpWp]: Computing forward predicates... [2021-12-16 00:59:15,566 INFO L134 CoverageAnalysis]: Checked inductivity of 45 backedges. 36 proven. 0 refuted. 0 times theorem prover too weak. 9 trivial. 0 not checked. [2021-12-16 00:59:15,566 INFO L324 TraceCheckSpWp]: Omiting computation of backward sequence because forward sequence was already perfect [2021-12-16 00:59:15,566 INFO L160 FreeRefinementEngine]: IpTcStrategyModuleZ3 [839923177] provided 1 perfect and 0 imperfect interpolant sequences [2021-12-16 00:59:15,566 INFO L186 FreeRefinementEngine]: Found 1 perfect and 1 imperfect interpolant sequences. [2021-12-16 00:59:15,567 INFO L199 FreeRefinementEngine]: Number of different interpolants: perfect sequences [8] imperfect sequences [15] total 20 [2021-12-16 00:59:15,567 INFO L115 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [346690659] [2021-12-16 00:59:15,567 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2021-12-16 00:59:15,567 INFO L546 AbstractCegarLoop]: INTERPOLANT automaton has 8 states [2021-12-16 00:59:15,568 INFO L103 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2021-12-16 00:59:15,568 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 8 interpolants. [2021-12-16 00:59:15,568 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=50, Invalid=330, Unknown=0, NotChecked=0, Total=380 [2021-12-16 00:59:15,569 INFO L87 Difference]: Start difference. First operand 494 states and 587 transitions. Second operand has 8 states, 8 states have (on average 9.875) internal successors, (79), 6 states have internal predecessors, (79), 3 states have call successors, (13), 3 states have call predecessors, (13), 5 states have return successors, (12), 5 states have call predecessors, (12), 3 states have call successors, (12) [2021-12-16 00:59:15,666 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2021-12-16 00:59:15,666 INFO L93 Difference]: Finished difference Result 845 states and 1014 transitions. [2021-12-16 00:59:15,666 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 8 states. [2021-12-16 00:59:15,667 INFO L78 Accepts]: Start accepts. Automaton has has 8 states, 8 states have (on average 9.875) internal successors, (79), 6 states have internal predecessors, (79), 3 states have call successors, (13), 3 states have call predecessors, (13), 5 states have return successors, (12), 5 states have call predecessors, (12), 3 states have call successors, (12) Word has length 110 [2021-12-16 00:59:15,667 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2021-12-16 00:59:15,667 INFO L225 Difference]: With dead ends: 845 [2021-12-16 00:59:15,667 INFO L226 Difference]: Without dead ends: 0 [2021-12-16 00:59:15,669 INFO L932 BasicCegarLoop]: 0 DeclaredPredicates, 146 GetRequests, 126 SyntacticMatches, 0 SemanticMatches, 20 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 43 ImplicationChecksByTransitivity, 0.2s TimeCoverageRelationStatistics Valid=62, Invalid=400, Unknown=0, NotChecked=0, Total=462 [2021-12-16 00:59:15,669 INFO L933 BasicCegarLoop]: 174 mSDtfsCounter, 68 mSDsluCounter, 607 mSDsCounter, 0 mSdLazyCounter, 101 mSolverCounterSat, 4 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.0s Time, 0 mProtectedPredicate, 0 mProtectedAction, 72 SdHoareTripleChecker+Valid, 781 SdHoareTripleChecker+Invalid, 105 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 4 IncrementalHoareTripleChecker+Valid, 101 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.1s IncrementalHoareTripleChecker+Time [2021-12-16 00:59:15,669 INFO L934 BasicCegarLoop]: SdHoareTripleChecker [72 Valid, 781 Invalid, 105 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [4 Valid, 101 Invalid, 0 Unknown, 0 Unchecked, 0.1s Time] [2021-12-16 00:59:15,669 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 0 states. [2021-12-16 00:59:15,670 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 0 to 0. [2021-12-16 00:59:15,670 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 0 states, 0 states have (on average 0.0) internal successors, (0), 0 states have internal predecessors, (0), 0 states have call successors, (0), 0 states have call predecessors, (0), 0 states have return successors, (0), 0 states have call predecessors, (0), 0 states have call successors, (0) [2021-12-16 00:59:15,670 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 0 states to 0 states and 0 transitions. [2021-12-16 00:59:15,670 INFO L78 Accepts]: Start accepts. Automaton has 0 states and 0 transitions. Word has length 110 [2021-12-16 00:59:15,670 INFO L84 Accepts]: Finished accepts. word is rejected. [2021-12-16 00:59:15,670 INFO L470 AbstractCegarLoop]: Abstraction has 0 states and 0 transitions. [2021-12-16 00:59:15,670 INFO L471 AbstractCegarLoop]: INTERPOLANT automaton has has 8 states, 8 states have (on average 9.875) internal successors, (79), 6 states have internal predecessors, (79), 3 states have call successors, (13), 3 states have call predecessors, (13), 5 states have return successors, (12), 5 states have call predecessors, (12), 3 states have call successors, (12) [2021-12-16 00:59:15,671 INFO L276 IsEmpty]: Start isEmpty. Operand 0 states and 0 transitions. [2021-12-16 00:59:15,671 INFO L282 IsEmpty]: Finished isEmpty. No accepting run. [2021-12-16 00:59:15,672 INFO L764 garLoopResultBuilder]: Registering result SAFE for location timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION (0 of 1 remaining) [2021-12-16 00:59:15,690 INFO L540 MonitoredProcess]: [MP /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 -smt2 -in SMTLIB2_COMPLIANT=true (3)] Forceful destruction successful, exit code 0 [2021-12-16 00:59:15,889 WARN L452 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: 3 /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 -smt2 -in SMTLIB2_COMPLIANT=true,SelfDestructingSolverStorable10 [2021-12-16 00:59:15,891 INFO L343 DoubleDeckerVisitor]: Before removal of dead ends 0 states and 0 transitions. [2021-12-16 00:59:18,503 INFO L858 garLoopResultBuilder]: For program point processEnvironment__wrappee__baseEXIT(lines 688 694) no Hoare annotation was computed. [2021-12-16 00:59:18,503 INFO L861 garLoopResultBuilder]: At program point processEnvironment__wrappee__baseFINAL(lines 688 694) the Hoare annotation is: true [2021-12-16 00:59:18,504 INFO L854 garLoopResultBuilder]: At program point changeMethaneLevelENTRY(lines 487 498) the Hoare annotation is: (let ((.cse0 (not (= ~systemActive~0 1)))) (and (or (not (= ~pumpRunning~0 0)) (= ~methaneLevelCritical~0 |old(~methaneLevelCritical~0)|) (not (<= 1 |old(~methaneLevelCritical~0)|)) .cse0) (or (not (= |old(~methaneLevelCritical~0)| 0)) (= ~methaneLevelCritical~0 0) .cse0))) [2021-12-16 00:59:18,504 INFO L858 garLoopResultBuilder]: For program point L491-1(lines 487 498) no Hoare annotation was computed. [2021-12-16 00:59:18,504 INFO L858 garLoopResultBuilder]: For program point changeMethaneLevelEXIT(lines 487 498) no Hoare annotation was computed. [2021-12-16 00:59:18,504 INFO L858 garLoopResultBuilder]: For program point L894(lines 894 904) no Hoare annotation was computed. [2021-12-16 00:59:18,505 INFO L858 garLoopResultBuilder]: For program point L890(lines 890 907) no Hoare annotation was computed. [2021-12-16 00:59:18,505 INFO L854 garLoopResultBuilder]: At program point L890-1(lines 882 910) the Hoare annotation is: (let ((.cse11 (= |timeShift___utac_acc__Specification2_spec__2_~tmp~8#1| 0)) (.cse12 (= ~methaneLevelCritical~0 0)) (.cse8 (<= 2 ~waterLevel~0))) (let ((.cse4 (not (<= 2 |old(~waterLevel~0)|))) (.cse2 (not (<= 1 ~methaneLevelCritical~0))) (.cse9 (not (= |old(~waterLevel~0)| 1))) (.cse10 (= ~waterLevel~0 1)) (.cse7 (not (= |old(~pumpRunning~0)| 0))) (.cse5 (and .cse11 .cse12 .cse8)) (.cse1 (= ~pumpRunning~0 0)) (.cse0 (= ~pumpRunning~0 |old(~pumpRunning~0)|)) (.cse6 (not .cse12)) (.cse3 (not (= ~systemActive~0 1)))) (and (or (and .cse0 .cse1) .cse2 (and (<= 1 |timeShift_processEnvironment_~tmp~5#1|) .cse1) .cse3) (or .cse4 .cse5 (not (= 0 |old(~pumpRunning~0)|)) .cse6 .cse3) (or .cse4 .cse2 .cse7 .cse8 .cse3) (or .cse9 .cse10 .cse2 .cse7 .cse3) (or .cse9 .cse10 .cse7 .cse6 .cse3) (or .cse5 (and .cse11 .cse1) (and .cse11 .cse0) .cse6 .cse3)))) [2021-12-16 00:59:18,505 INFO L858 garLoopResultBuilder]: For program point timeShiftFINAL(lines 664 687) no Hoare annotation was computed. [2021-12-16 00:59:18,505 INFO L858 garLoopResultBuilder]: For program point L895(lines 895 901) no Hoare annotation was computed. [2021-12-16 00:59:18,506 INFO L854 garLoopResultBuilder]: At program point L796(lines 791 799) the Hoare annotation is: (let ((.cse2 (not (= |old(~pumpRunning~0)| 0))) (.cse1 (not (<= 1 ~methaneLevelCritical~0))) (.cse0 (not (= ~systemActive~0 1)))) (and (or (not (= ~methaneLevelCritical~0 0)) .cse0) (or (not (<= 2 |old(~waterLevel~0)|)) .cse1 .cse2 (<= 2 ~waterLevel~0) .cse0) (or (not (= |old(~waterLevel~0)| 1)) (= ~waterLevel~0 1) .cse1 .cse2 .cse0) (let ((.cse3 (= |timeShift_isPumpRunning_#res#1| 0)) (.cse4 (= ~pumpRunning~0 0))) (or (and (<= 1 |timeShift_processEnvironment_~tmp~5#1|) .cse3 .cse4) (and .cse3 (= ~pumpRunning~0 |old(~pumpRunning~0)|) .cse4) .cse1 .cse0)))) [2021-12-16 00:59:18,506 INFO L858 garLoopResultBuilder]: For program point L668-1(lines 667 686) no Hoare annotation was computed. [2021-12-16 00:59:18,506 INFO L858 garLoopResultBuilder]: For program point L730(lines 730 738) no Hoare annotation was computed. [2021-12-16 00:59:18,506 INFO L858 garLoopResultBuilder]: For program point L726(lines 726 743) no Hoare annotation was computed. [2021-12-16 00:59:18,506 INFO L854 garLoopResultBuilder]: At program point L888(line 888) the Hoare annotation is: (let ((.cse12 (= ~methaneLevelCritical~0 0)) (.cse9 (<= 2 ~waterLevel~0)) (.cse2 (= ~pumpRunning~0 0))) (let ((.cse0 (and (not (= 0 |old(~pumpRunning~0)|)) (<= 1 |timeShift_processEnvironment_~tmp~5#1|) .cse2)) (.cse3 (not (<= 1 ~methaneLevelCritical~0))) (.cse8 (not (<= 2 |old(~waterLevel~0)|))) (.cse5 (not (= |old(~waterLevel~0)| 1))) (.cse6 (= ~waterLevel~0 1)) (.cse7 (not (= |old(~pumpRunning~0)| 0))) (.cse10 (and .cse12 .cse9)) (.cse1 (= ~pumpRunning~0 |old(~pumpRunning~0)|)) (.cse11 (not .cse12)) (.cse4 (not (= ~systemActive~0 1)))) (and (or .cse0 (and .cse1 .cse2) .cse3 .cse4) (or .cse5 .cse6 .cse3 .cse7 .cse4) (or .cse8 .cse0 .cse3 .cse9 .cse4) (or .cse8 .cse10 .cse7 .cse11 .cse4) (or .cse5 .cse6 .cse7 .cse11 .cse4) (or .cse10 .cse1 .cse11 .cse4 .cse2)))) [2021-12-16 00:59:18,507 INFO L858 garLoopResultBuilder]: For program point L888-1(line 888) no Hoare annotation was computed. [2021-12-16 00:59:18,507 INFO L858 garLoopResultBuilder]: For program point L467(lines 467 471) no Hoare annotation was computed. [2021-12-16 00:59:18,507 INFO L854 garLoopResultBuilder]: At program point L467-2(lines 463 474) the Hoare annotation is: (let ((.cse0 (not (= ~systemActive~0 1))) (.cse1 (and (not (= 0 |old(~pumpRunning~0)|)) (= ~pumpRunning~0 |old(~pumpRunning~0)|)))) (and (or (not (= ~methaneLevelCritical~0 0)) .cse0 .cse1) (or (not (<= 1 ~methaneLevelCritical~0)) .cse0 .cse1))) [2021-12-16 00:59:18,507 INFO L854 garLoopResultBuilder]: At program point L777(lines 772 779) the Hoare annotation is: (let ((.cse0 (not (<= 1 ~methaneLevelCritical~0))) (.cse2 (= ~pumpRunning~0 0)) (.cse1 (not (= ~systemActive~0 1)))) (and (or .cse0 (not (= |old(~pumpRunning~0)| 0)) .cse1) (or .cse0 (and (<= 1 |timeShift_processEnvironment_~tmp~5#1|) .cse2) .cse1) (or (not (= ~methaneLevelCritical~0 0)) (and (not (= 0 |old(~pumpRunning~0)|)) .cse2) .cse1))) [2021-12-16 00:59:18,507 INFO L858 garLoopResultBuilder]: For program point L868(line 868) no Hoare annotation was computed. [2021-12-16 00:59:18,507 INFO L854 garLoopResultBuilder]: At program point L736(line 736) the Hoare annotation is: (let ((.cse0 (not (= ~systemActive~0 1)))) (and (or (not (= ~methaneLevelCritical~0 0)) .cse0 (and (not (= 0 |old(~pumpRunning~0)|)) (= ~pumpRunning~0 |old(~pumpRunning~0)|))) (or (not (<= 1 ~methaneLevelCritical~0)) .cse0))) [2021-12-16 00:59:18,507 INFO L854 garLoopResultBuilder]: At program point L728(line 728) the Hoare annotation is: (let ((.cse0 (not (= ~systemActive~0 1))) (.cse1 (and (not (= 0 |old(~pumpRunning~0)|)) (= ~pumpRunning~0 |old(~pumpRunning~0)|)))) (and (or (not (= ~methaneLevelCritical~0 0)) .cse0 .cse1) (or (not (<= 1 ~methaneLevelCritical~0)) .cse0 .cse1))) [2021-12-16 00:59:18,508 INFO L858 garLoopResultBuilder]: For program point L728-1(line 728) no Hoare annotation was computed. [2021-12-16 00:59:18,508 INFO L854 garLoopResultBuilder]: At program point timeShiftENTRY(lines 664 687) the Hoare annotation is: (let ((.cse0 (not (= |old(~waterLevel~0)| 1))) (.cse1 (= ~waterLevel~0 1)) (.cse3 (not (= |old(~pumpRunning~0)| 0))) (.cse5 (= ~pumpRunning~0 |old(~pumpRunning~0)|)) (.cse2 (not (<= 1 ~methaneLevelCritical~0))) (.cse7 (not (<= 2 |old(~waterLevel~0)|))) (.cse8 (<= 2 ~waterLevel~0)) (.cse6 (not (= ~methaneLevelCritical~0 0))) (.cse4 (not (= ~systemActive~0 1)))) (and (or .cse0 .cse1 .cse2 .cse3 .cse4) (or .cse2 .cse5 .cse4) (or .cse0 .cse1 .cse3 .cse6 .cse4) (or .cse5 .cse6 .cse4) (or .cse7 .cse2 .cse8 .cse4) (or .cse7 .cse8 .cse6 .cse4))) [2021-12-16 00:59:18,508 INFO L858 garLoopResultBuilder]: For program point timeShiftEXIT(lines 664 687) no Hoare annotation was computed. [2021-12-16 00:59:18,508 INFO L858 garLoopResultBuilder]: For program point timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION(line 868) no Hoare annotation was computed. [2021-12-16 00:59:18,508 INFO L854 garLoopResultBuilder]: At program point L741(line 741) the Hoare annotation is: (let ((.cse4 (and (= ~pumpRunning~0 |old(~pumpRunning~0)|) (= ~pumpRunning~0 0))) (.cse2 (not (= ~methaneLevelCritical~0 0))) (.cse6 (not (<= 2 |old(~waterLevel~0)|))) (.cse7 (<= 2 ~waterLevel~0)) (.cse0 (not (= |old(~waterLevel~0)| 1))) (.cse1 (= ~waterLevel~0 1)) (.cse5 (not (<= 1 ~methaneLevelCritical~0))) (.cse3 (not (= ~systemActive~0 1)))) (and (or .cse0 .cse1 .cse2 .cse3) (or .cse4 .cse5 .cse3) (or .cse4 .cse2 .cse3) (or .cse6 .cse7 .cse2 .cse3) (or .cse6 .cse5 .cse7 .cse3) (or .cse0 .cse1 .cse5 .cse3))) [2021-12-16 00:59:18,508 INFO L854 garLoopResultBuilder]: At program point L869(lines 864 871) the Hoare annotation is: (let ((.cse0 (not (= ~systemActive~0 1)))) (and (or (not (= ~methaneLevelCritical~0 0)) .cse0) (or (not (<= 1 ~methaneLevelCritical~0)) .cse0))) [2021-12-16 00:59:18,508 INFO L854 garLoopResultBuilder]: At program point L741-1(lines 722 746) the Hoare annotation is: (let ((.cse12 (= ~methaneLevelCritical~0 0)) (.cse9 (<= 2 ~waterLevel~0)) (.cse2 (= ~pumpRunning~0 0))) (let ((.cse0 (and (not (= 0 |old(~pumpRunning~0)|)) (<= 1 |timeShift_processEnvironment_~tmp~5#1|) .cse2)) (.cse3 (not (<= 1 ~methaneLevelCritical~0))) (.cse8 (not (<= 2 |old(~waterLevel~0)|))) (.cse5 (not (= |old(~waterLevel~0)| 1))) (.cse6 (= ~waterLevel~0 1)) (.cse7 (not (= |old(~pumpRunning~0)| 0))) (.cse10 (and .cse12 .cse9)) (.cse1 (= ~pumpRunning~0 |old(~pumpRunning~0)|)) (.cse11 (not .cse12)) (.cse4 (not (= ~systemActive~0 1)))) (and (or .cse0 (and .cse1 .cse2) .cse3 .cse4) (or .cse5 .cse6 .cse3 .cse7 .cse4) (or .cse8 .cse0 .cse3 .cse9 .cse4) (or .cse8 .cse10 .cse7 .cse11 .cse4) (or .cse5 .cse6 .cse7 .cse11 .cse4) (or .cse10 .cse1 .cse11 .cse4 .cse2)))) [2021-12-16 00:59:18,509 INFO L858 garLoopResultBuilder]: For program point L675-1(lines 675 681) no Hoare annotation was computed. [2021-12-16 00:59:18,509 INFO L858 garLoopResultBuilder]: For program point cleanupEXIT(lines 557 586) no Hoare annotation was computed. [2021-12-16 00:59:18,509 INFO L861 garLoopResultBuilder]: At program point cleanupENTRY(lines 557 586) the Hoare annotation is: true [2021-12-16 00:59:18,509 INFO L858 garLoopResultBuilder]: For program point L571(lines 571 575) no Hoare annotation was computed. [2021-12-16 00:59:18,509 INFO L861 garLoopResultBuilder]: At program point L571-1(lines 571 575) the Hoare annotation is: true [2021-12-16 00:59:18,509 INFO L858 garLoopResultBuilder]: For program point L568(line 568) no Hoare annotation was computed. [2021-12-16 00:59:18,509 INFO L861 garLoopResultBuilder]: At program point L567-2(lines 567 581) the Hoare annotation is: true [2021-12-16 00:59:18,509 INFO L861 garLoopResultBuilder]: At program point L563(line 563) the Hoare annotation is: true [2021-12-16 00:59:18,509 INFO L858 garLoopResultBuilder]: For program point L563-1(line 563) no Hoare annotation was computed. [2021-12-16 00:59:18,510 INFO L861 garLoopResultBuilder]: At program point L582(lines 557 586) the Hoare annotation is: true [2021-12-16 00:59:18,510 INFO L858 garLoopResultBuilder]: For program point L578(line 578) no Hoare annotation was computed. [2021-12-16 00:59:18,510 INFO L861 garLoopResultBuilder]: At program point isMethaneLevelCriticalENTRY(lines 499 507) the Hoare annotation is: true [2021-12-16 00:59:18,510 INFO L858 garLoopResultBuilder]: For program point isMethaneLevelCriticalFINAL(lines 499 507) no Hoare annotation was computed. [2021-12-16 00:59:18,510 INFO L858 garLoopResultBuilder]: For program point isMethaneLevelCriticalEXIT(lines 499 507) no Hoare annotation was computed. [2021-12-16 00:59:18,510 INFO L858 garLoopResultBuilder]: For program point L960(lines 960 964) no Hoare annotation was computed. [2021-12-16 00:59:18,510 INFO L858 garLoopResultBuilder]: For program point L642-2(lines 642 649) no Hoare annotation was computed. [2021-12-16 00:59:18,510 INFO L854 garLoopResultBuilder]: At program point L960-2(lines 952 965) the Hoare annotation is: (let ((.cse0 (= |ULTIMATE.start_test_~splverifierCounter~0#1| 0)) (.cse1 (= ~systemActive~0 |ULTIMATE.start_main_~tmp~3#1|)) (.cse2 (= ~systemActive~0 |ULTIMATE.start_valid_product_#res#1|)) (.cse3 (= ~systemActive~0 1))) (or (and .cse0 .cse1 .cse2 (<= 1 ~methaneLevelCritical~0) .cse3) (and .cse0 .cse1 .cse2 (= ~methaneLevelCritical~0 0) .cse3))) [2021-12-16 00:59:18,510 INFO L858 garLoopResultBuilder]: For program point L923(lines 922 969) no Hoare annotation was computed. [2021-12-16 00:59:18,511 INFO L858 garLoopResultBuilder]: For program point L952(lines 952 965) no Hoare annotation was computed. [2021-12-16 00:59:18,511 INFO L854 garLoopResultBuilder]: At program point L944(line 944) the Hoare annotation is: (let ((.cse0 (= |ULTIMATE.start_test_~splverifierCounter~0#1| 0)) (.cse1 (= ~systemActive~0 |ULTIMATE.start_main_~tmp~3#1|)) (.cse2 (= ~systemActive~0 |ULTIMATE.start_valid_product_#res#1|)) (.cse3 (= ~systemActive~0 1))) (or (and .cse0 .cse1 .cse2 (<= 1 ~methaneLevelCritical~0) .cse3 (= ~pumpRunning~0 0)) (and .cse0 .cse1 .cse2 (= ~methaneLevelCritical~0 0) .cse3))) [2021-12-16 00:59:18,511 INFO L861 garLoopResultBuilder]: At program point L973(lines 912 977) the Hoare annotation is: true [2021-12-16 00:59:18,511 INFO L861 garLoopResultBuilder]: At program point L651(lines 632 654) the Hoare annotation is: true [2021-12-16 00:59:18,511 INFO L858 garLoopResultBuilder]: For program point L932(lines 932 938) no Hoare annotation was computed. [2021-12-16 00:59:18,511 INFO L858 garLoopResultBuilder]: For program point L932-1(lines 932 938) no Hoare annotation was computed. [2021-12-16 00:59:18,511 INFO L858 garLoopResultBuilder]: For program point L-1(line -1) no Hoare annotation was computed. [2021-12-16 00:59:18,511 INFO L858 garLoopResultBuilder]: For program point ULTIMATE.startENTRY(line -1) no Hoare annotation was computed. [2021-12-16 00:59:18,512 INFO L858 garLoopResultBuilder]: For program point ULTIMATE.startFINAL(line -1) no Hoare annotation was computed. [2021-12-16 00:59:18,512 INFO L858 garLoopResultBuilder]: For program point L924(lines 924 928) no Hoare annotation was computed. [2021-12-16 00:59:18,512 INFO L854 garLoopResultBuilder]: At program point L879(lines 874 881) the Hoare annotation is: (and (= ~systemActive~0 |ULTIMATE.start_main_~tmp~3#1|) (= ~systemActive~0 |ULTIMATE.start_valid_product_#res#1|) (= ~waterLevel~0 1) (= ~methaneLevelCritical~0 0) (= ~systemActive~0 1) (= ~pumpRunning~0 0)) [2021-12-16 00:59:18,512 INFO L854 garLoopResultBuilder]: At program point L970(lines 921 971) the Hoare annotation is: false [2021-12-16 00:59:18,512 INFO L858 garLoopResultBuilder]: For program point ULTIMATE.startEXIT(line -1) no Hoare annotation was computed. [2021-12-16 00:59:18,512 INFO L854 garLoopResultBuilder]: At program point L83(lines 78 86) the Hoare annotation is: (and (= ~systemActive~0 |ULTIMATE.start_valid_product_#res#1|) (= ~waterLevel~0 1) (= ~methaneLevelCritical~0 0) (= ~systemActive~0 1) (= ~pumpRunning~0 0)) [2021-12-16 00:59:18,512 INFO L858 garLoopResultBuilder]: For program point L942(lines 942 948) no Hoare annotation was computed. [2021-12-16 00:59:18,512 INFO L858 garLoopResultBuilder]: For program point L942-1(lines 942 948) no Hoare annotation was computed. [2021-12-16 00:59:18,512 INFO L854 garLoopResultBuilder]: At program point L75(lines 71 77) the Hoare annotation is: (and (= ~waterLevel~0 1) (= ~methaneLevelCritical~0 0) (= ~systemActive~0 1) (= ~pumpRunning~0 0)) [2021-12-16 00:59:18,513 INFO L854 garLoopResultBuilder]: At program point L616(lines 612 618) the Hoare annotation is: (and (= ~systemActive~0 |ULTIMATE.start_main_~tmp~3#1|) (= ~systemActive~0 |ULTIMATE.start_valid_product_#res#1|) (= ~waterLevel~0 1) (= ~methaneLevelCritical~0 0) (= ~systemActive~0 1) (= ~pumpRunning~0 0)) [2021-12-16 00:59:18,513 INFO L854 garLoopResultBuilder]: At program point L967(lines 922 969) the Hoare annotation is: (let ((.cse0 (= |ULTIMATE.start_test_~splverifierCounter~0#1| 0)) (.cse1 (= ~systemActive~0 |ULTIMATE.start_main_~tmp~3#1|)) (.cse2 (= ~systemActive~0 |ULTIMATE.start_valid_product_#res#1|)) (.cse3 (= ~systemActive~0 1))) (or (and .cse0 .cse1 .cse2 (<= 1 ~methaneLevelCritical~0) .cse3 (= ~pumpRunning~0 0)) (and .cse0 .cse1 .cse2 (= ~methaneLevelCritical~0 0) .cse3))) [2021-12-16 00:59:18,513 INFO L854 garLoopResultBuilder]: At program point L934(line 934) the Hoare annotation is: (let ((.cse0 (= |ULTIMATE.start_test_~splverifierCounter~0#1| 0)) (.cse1 (= ~systemActive~0 |ULTIMATE.start_main_~tmp~3#1|)) (.cse2 (= ~systemActive~0 |ULTIMATE.start_valid_product_#res#1|)) (.cse3 (= ~systemActive~0 1))) (or (and .cse0 .cse1 .cse2 (<= 1 ~methaneLevelCritical~0) .cse3 (= ~pumpRunning~0 0)) (and .cse0 .cse1 .cse2 (= ~methaneLevelCritical~0 0) .cse3))) [2021-12-16 00:59:18,513 INFO L854 garLoopResultBuilder]: At program point L860(lines 855 862) the Hoare annotation is: (let ((.cse0 (= |ULTIMATE.start_test_~splverifierCounter~0#1| 0)) (.cse1 (= ~systemActive~0 |ULTIMATE.start_main_~tmp~3#1|)) (.cse2 (= ~systemActive~0 |ULTIMATE.start_valid_product_#res#1|)) (.cse3 (= ~systemActive~0 1))) (or (and .cse0 .cse1 .cse2 (<= 1 ~methaneLevelCritical~0) .cse3) (and .cse0 .cse1 .cse2 (= ~methaneLevelCritical~0 0) .cse3))) [2021-12-16 00:59:18,513 INFO L861 garLoopResultBuilder]: At program point L629(lines 621 631) the Hoare annotation is: true [2021-12-16 00:59:18,513 INFO L854 garLoopResultBuilder]: At program point L68(lines 64 70) the Hoare annotation is: (and (= ~waterLevel~0 1) (= ~methaneLevelCritical~0 0) (= ~systemActive~0 1) (= ~pumpRunning~0 0)) [2021-12-16 00:59:18,513 INFO L858 garLoopResultBuilder]: For program point L642(lines 642 649) no Hoare annotation was computed. [2021-12-16 00:59:18,513 INFO L858 garLoopResultBuilder]: For program point waterRiseEXIT(lines 475 486) no Hoare annotation was computed. [2021-12-16 00:59:18,514 INFO L858 garLoopResultBuilder]: For program point L479-1(lines 475 486) no Hoare annotation was computed. [2021-12-16 00:59:18,514 INFO L854 garLoopResultBuilder]: At program point waterRiseENTRY(lines 475 486) the Hoare annotation is: (let ((.cse3 (not (= ~methaneLevelCritical~0 0))) (.cse5 (not (<= 2 |old(~waterLevel~0)|))) (.cse6 (<= 2 ~waterLevel~0)) (.cse0 (not (= |old(~waterLevel~0)| 1))) (.cse1 (= ~waterLevel~0 1)) (.cse2 (not (= ~pumpRunning~0 0))) (.cse7 (not (<= 1 ~methaneLevelCritical~0))) (.cse4 (not (= ~systemActive~0 1)))) (and (or .cse0 .cse1 .cse2 .cse3 .cse4) (or .cse5 .cse6 .cse3 .cse4) (or .cse5 .cse2 .cse7 .cse6 .cse4) (or .cse0 .cse1 .cse2 .cse7 .cse4))) [2021-12-16 00:59:18,514 INFO L858 garLoopResultBuilder]: For program point L704(lines 704 712) no Hoare annotation was computed. [2021-12-16 00:59:18,514 INFO L858 garLoopResultBuilder]: For program point L700(lines 700 717) no Hoare annotation was computed. [2021-12-16 00:59:18,514 INFO L858 garLoopResultBuilder]: For program point L762(lines 762 768) no Hoare annotation was computed. [2021-12-16 00:59:18,514 INFO L854 garLoopResultBuilder]: At program point L760(line 760) the Hoare annotation is: (let ((.cse0 (and (<= 2 ~waterLevel~0) (= ~pumpRunning~0 0))) (.cse1 (not (= ~methaneLevelCritical~0 0))) (.cse2 (not (= ~systemActive~0 1)))) (and (or .cse0 .cse1 .cse2) (or .cse0 (not (<= 1 ~methaneLevelCritical~0)) (not (= |old(~pumpRunning~0)| 0)) .cse2) (or (= 0 |old(~pumpRunning~0)|) .cse1 .cse2))) [2021-12-16 00:59:18,514 INFO L854 garLoopResultBuilder]: At program point L762-2(lines 755 771) the Hoare annotation is: (let ((.cse0 (<= 2 ~waterLevel~0)) (.cse2 (not (= ~methaneLevelCritical~0 0))) (.cse1 (not (= ~systemActive~0 1)))) (and (or (not (<= 1 ~methaneLevelCritical~0)) (not (= |old(~pumpRunning~0)| 0)) (and (<= ~methaneLevelCritical~0 |processEnvironment__wrappee__methaneQuery_activatePump_~tmp~6#1|) .cse0 (= ~pumpRunning~0 0)) .cse1) (or .cse0 .cse2 .cse1) (or (= 0 |old(~pumpRunning~0)|) .cse2 .cse1))) [2021-12-16 00:59:18,514 INFO L858 garLoopResultBuilder]: For program point L760-1(line 760) no Hoare annotation was computed. [2021-12-16 00:59:18,515 INFO L854 garLoopResultBuilder]: At program point L851(lines 836 854) the Hoare annotation is: (let ((.cse5 (= ~pumpRunning~0 0))) (let ((.cse0 (not (= ~methaneLevelCritical~0 0))) (.cse2 (and (<= 2 ~waterLevel~0) .cse5)) (.cse3 (= |processEnvironment__wrappee__methaneQuery_isHighWaterLevel_~tmp___0~0#1| 0)) (.cse4 (= |processEnvironment__wrappee__methaneQuery_isHighWaterLevel_#res#1| 0)) (.cse1 (not (= ~systemActive~0 1)))) (and (or (= 0 |old(~pumpRunning~0)|) .cse0 .cse1) (or .cse2 (and .cse3 .cse4 .cse5) .cse0 .cse1) (or .cse2 (not (<= 1 ~methaneLevelCritical~0)) (and .cse3 (= ~pumpRunning~0 |old(~pumpRunning~0)|) .cse4) (not (= |old(~pumpRunning~0)| 0)) .cse1)))) [2021-12-16 00:59:18,515 INFO L854 garLoopResultBuilder]: At program point L752(lines 747 754) the Hoare annotation is: (let ((.cse1 (not (= ~methaneLevelCritical~0 0))) (.cse0 (not (= ~systemActive~0 1)))) (and (or (not (<= 1 ~methaneLevelCritical~0)) (not (= |old(~pumpRunning~0)| 0)) .cse0) (or (<= 2 ~waterLevel~0) .cse1 .cse0) (or (= 0 |old(~pumpRunning~0)|) .cse1 .cse0))) [2021-12-16 00:59:18,515 INFO L858 garLoopResultBuilder]: For program point L845(lines 845 849) no Hoare annotation was computed. [2021-12-16 00:59:18,515 INFO L858 garLoopResultBuilder]: For program point L845-2(lines 845 849) no Hoare annotation was computed. [2021-12-16 00:59:18,515 INFO L854 garLoopResultBuilder]: At program point L715(line 715) the Hoare annotation is: (let ((.cse0 (not (= |old(~pumpRunning~0)| 0))) (.cse1 (not (= ~methaneLevelCritical~0 0))) (.cse2 (not (= ~systemActive~0 1)))) (and (or .cse0 .cse1 .cse2) (or (not (<= 1 ~methaneLevelCritical~0)) .cse0 .cse2) (or (= ~pumpRunning~0 |old(~pumpRunning~0)|) .cse1 .cse2))) [2021-12-16 00:59:18,515 INFO L858 garLoopResultBuilder]: For program point L715-1(lines 696 720) no Hoare annotation was computed. [2021-12-16 00:59:18,515 INFO L858 garLoopResultBuilder]: For program point L544(lines 544 550) no Hoare annotation was computed. [2021-12-16 00:59:18,516 INFO L854 garLoopResultBuilder]: At program point processEnvironment__wrappee__methaneQueryENTRY(lines 696 720) the Hoare annotation is: (let ((.cse0 (not (= ~systemActive~0 1)))) (and (or (not (<= 1 ~methaneLevelCritical~0)) (not (= |old(~pumpRunning~0)| 0)) .cse0 (= ~pumpRunning~0 0)) (or (= ~pumpRunning~0 |old(~pumpRunning~0)|) (not (= ~methaneLevelCritical~0 0)) .cse0))) [2021-12-16 00:59:18,516 INFO L858 garLoopResultBuilder]: For program point processEnvironment__wrappee__methaneQueryEXIT(lines 696 720) no Hoare annotation was computed. [2021-12-16 00:59:18,516 INFO L854 garLoopResultBuilder]: At program point L710(line 710) the Hoare annotation is: (let ((.cse2 (and (= |processEnvironment__wrappee__methaneQuery_~tmp~4#1| 0) (= ~pumpRunning~0 0))) (.cse0 (not (= ~methaneLevelCritical~0 0))) (.cse1 (not (= ~systemActive~0 1)))) (and (or (= 0 |old(~pumpRunning~0)|) .cse0 .cse1) (or (not (<= 1 ~methaneLevelCritical~0)) (not (= |old(~pumpRunning~0)| 0)) .cse2 .cse1) (or .cse2 .cse0 .cse1))) [2021-12-16 00:59:18,516 INFO L854 garLoopResultBuilder]: At program point L549(lines 540 553) the Hoare annotation is: (let ((.cse4 (= ~pumpRunning~0 0))) (let ((.cse0 (and (<= 2 ~waterLevel~0) .cse4)) (.cse3 (not (= ~methaneLevelCritical~0 0))) (.cse1 (not (= ~systemActive~0 1))) (.cse2 (and (= |processEnvironment__wrappee__methaneQuery_isHighWaterSensorDry_#res#1| 1) .cse4))) (and (or .cse0 (not (<= 1 ~methaneLevelCritical~0)) (not (= |old(~pumpRunning~0)| 0)) .cse1 .cse2) (or (= 0 |old(~pumpRunning~0)|) .cse3 .cse1) (or .cse0 .cse3 .cse1 .cse2)))) [2021-12-16 00:59:18,516 INFO L861 garLoopResultBuilder]: At program point L785(line 785) the Hoare annotation is: true [2021-12-16 00:59:18,516 INFO L858 garLoopResultBuilder]: For program point L785-1(line 785) no Hoare annotation was computed. [2021-12-16 00:59:18,516 INFO L861 garLoopResultBuilder]: At program point isMethaneAlarmENTRY(lines 780 790) the Hoare annotation is: true [2021-12-16 00:59:18,516 INFO L858 garLoopResultBuilder]: For program point isMethaneAlarmEXIT(lines 780 790) no Hoare annotation was computed. [2021-12-16 00:59:18,516 INFO L858 garLoopResultBuilder]: For program point isMethaneAlarmFINAL(lines 780 790) no Hoare annotation was computed. [2021-12-16 00:59:18,519 INFO L732 BasicCegarLoop]: Path program histogram: [1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2021-12-16 00:59:18,520 INFO L179 ceAbstractionStarter]: Computing trace abstraction results [2021-12-16 00:59:18,550 INFO L202 PluginConnector]: Adding new model de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction CFG 16.12 12:59:18 BoogieIcfgContainer [2021-12-16 00:59:18,550 INFO L132 PluginConnector]: ------------------------ END TraceAbstraction---------------------------- [2021-12-16 00:59:18,551 INFO L113 PluginConnector]: ------------------------Witness Printer---------------------------- [2021-12-16 00:59:18,551 INFO L271 PluginConnector]: Initializing Witness Printer... [2021-12-16 00:59:18,551 INFO L275 PluginConnector]: Witness Printer initialized [2021-12-16 00:59:18,552 INFO L185 PluginConnector]: Executing the observer RCFGCatcher from plugin Witness Printer for "de.uni_freiburg.informatik.ultimate.plugins.generator.rcfgbuilder CFG 16.12 12:59:11" (3/4) ... [2021-12-16 00:59:18,554 INFO L137 WitnessPrinter]: Generating witness for correct program [2021-12-16 00:59:18,558 INFO L354 RCFGBacktranslator]: Ignoring RootEdge to procedure processEnvironment__wrappee__base [2021-12-16 00:59:18,559 INFO L354 RCFGBacktranslator]: Ignoring RootEdge to procedure changeMethaneLevel [2021-12-16 00:59:18,559 INFO L354 RCFGBacktranslator]: Ignoring RootEdge to procedure timeShift [2021-12-16 00:59:18,560 INFO L354 RCFGBacktranslator]: Ignoring RootEdge to procedure cleanup [2021-12-16 00:59:18,560 INFO L354 RCFGBacktranslator]: Ignoring RootEdge to procedure isMethaneLevelCritical [2021-12-16 00:59:18,560 INFO L354 RCFGBacktranslator]: Ignoring RootEdge to procedure waterRise [2021-12-16 00:59:18,560 INFO L354 RCFGBacktranslator]: Ignoring RootEdge to procedure processEnvironment__wrappee__methaneQuery [2021-12-16 00:59:18,560 INFO L354 RCFGBacktranslator]: Ignoring RootEdge to procedure isMethaneAlarm [2021-12-16 00:59:18,565 INFO L910 BoogieBacktranslator]: Reduced CFG by removing 50 nodes and edges [2021-12-16 00:59:18,567 INFO L910 BoogieBacktranslator]: Reduced CFG by removing 22 nodes and edges [2021-12-16 00:59:18,567 INFO L910 BoogieBacktranslator]: Reduced CFG by removing 11 nodes and edges [2021-12-16 00:59:18,567 INFO L910 BoogieBacktranslator]: Reduced CFG by removing 5 nodes and edges [2021-12-16 00:59:18,568 INFO L910 BoogieBacktranslator]: Reduced CFG by removing 2 nodes and edges [2021-12-16 00:59:18,568 INFO L910 BoogieBacktranslator]: Reduced CFG by removing 1 nodes and edges [2021-12-16 00:59:18,568 INFO L910 BoogieBacktranslator]: Reduced CFG by removing 1 nodes and edges [2021-12-16 00:59:18,583 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (((systemActive == \result && waterLevel == 1) && methaneLevelCritical == 0) && systemActive == 1) && pumpRunning == 0 [2021-12-16 00:59:18,584 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: ((((systemActive == tmp && systemActive == \result) && waterLevel == 1) && methaneLevelCritical == 0) && systemActive == 1) && pumpRunning == 0 [2021-12-16 00:59:18,584 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: ((((systemActive == tmp && systemActive == \result) && waterLevel == 1) && methaneLevelCritical == 0) && systemActive == 1) && pumpRunning == 0 [2021-12-16 00:59:18,584 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (((((splverifierCounter == 0 && systemActive == tmp) && systemActive == \result) && 1 <= methaneLevelCritical) && systemActive == 1) && pumpRunning == 0) || ((((splverifierCounter == 0 && systemActive == tmp) && systemActive == \result) && methaneLevelCritical == 0) && systemActive == 1) [2021-12-16 00:59:18,585 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: ((!(methaneLevelCritical == 0) || !(systemActive == 1)) || (!(0 == \old(pumpRunning)) && pumpRunning == \old(pumpRunning))) && ((!(1 <= methaneLevelCritical) || !(systemActive == 1)) || (!(0 == \old(pumpRunning)) && pumpRunning == \old(pumpRunning))) [2021-12-16 00:59:18,586 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (((((((((!(0 == \old(pumpRunning)) && 1 <= tmp) && pumpRunning == 0) || (pumpRunning == \old(pumpRunning) && pumpRunning == 0)) || !(1 <= methaneLevelCritical)) || !(systemActive == 1)) && ((((!(\old(waterLevel) == 1) || waterLevel == 1) || !(1 <= methaneLevelCritical)) || !(\old(pumpRunning) == 0)) || !(systemActive == 1))) && ((((!(2 <= \old(waterLevel)) || ((!(0 == \old(pumpRunning)) && 1 <= tmp) && pumpRunning == 0)) || !(1 <= methaneLevelCritical)) || 2 <= waterLevel) || !(systemActive == 1))) && ((((!(2 <= \old(waterLevel)) || (methaneLevelCritical == 0 && 2 <= waterLevel)) || !(\old(pumpRunning) == 0)) || !(methaneLevelCritical == 0)) || !(systemActive == 1))) && ((((!(\old(waterLevel) == 1) || waterLevel == 1) || !(\old(pumpRunning) == 0)) || !(methaneLevelCritical == 0)) || !(systemActive == 1))) && (((((methaneLevelCritical == 0 && 2 <= waterLevel) || pumpRunning == \old(pumpRunning)) || !(methaneLevelCritical == 0)) || !(systemActive == 1)) || pumpRunning == 0) [2021-12-16 00:59:18,586 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: ((((splverifierCounter == 0 && systemActive == tmp) && systemActive == \result) && 1 <= methaneLevelCritical) && systemActive == 1) || ((((splverifierCounter == 0 && systemActive == tmp) && systemActive == \result) && methaneLevelCritical == 0) && systemActive == 1) [2021-12-16 00:59:18,586 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: ((((((((pumpRunning == \old(pumpRunning) && pumpRunning == 0) || !(1 <= methaneLevelCritical)) || (1 <= tmp && pumpRunning == 0)) || !(systemActive == 1)) && ((((!(2 <= \old(waterLevel)) || ((tmp == 0 && methaneLevelCritical == 0) && 2 <= waterLevel)) || !(0 == \old(pumpRunning))) || !(methaneLevelCritical == 0)) || !(systemActive == 1))) && ((((!(2 <= \old(waterLevel)) || !(1 <= methaneLevelCritical)) || !(\old(pumpRunning) == 0)) || 2 <= waterLevel) || !(systemActive == 1))) && ((((!(\old(waterLevel) == 1) || waterLevel == 1) || !(1 <= methaneLevelCritical)) || !(\old(pumpRunning) == 0)) || !(systemActive == 1))) && ((((!(\old(waterLevel) == 1) || waterLevel == 1) || !(\old(pumpRunning) == 0)) || !(methaneLevelCritical == 0)) || !(systemActive == 1))) && ((((((tmp == 0 && methaneLevelCritical == 0) && 2 <= waterLevel) || (tmp == 0 && pumpRunning == 0)) || (tmp == 0 && pumpRunning == \old(pumpRunning))) || !(methaneLevelCritical == 0)) || !(systemActive == 1)) [2021-12-16 00:59:18,587 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (((!(1 <= methaneLevelCritical) || !(\old(pumpRunning) == 0)) || !(systemActive == 1)) && ((!(1 <= methaneLevelCritical) || (1 <= tmp && pumpRunning == 0)) || !(systemActive == 1))) && ((!(methaneLevelCritical == 0) || (!(0 == \old(pumpRunning)) && pumpRunning == 0)) || !(systemActive == 1)) [2021-12-16 00:59:18,587 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (((!(methaneLevelCritical == 0) || !(systemActive == 1)) && ((((!(2 <= \old(waterLevel)) || !(1 <= methaneLevelCritical)) || !(\old(pumpRunning) == 0)) || 2 <= waterLevel) || !(systemActive == 1))) && ((((!(\old(waterLevel) == 1) || waterLevel == 1) || !(1 <= methaneLevelCritical)) || !(\old(pumpRunning) == 0)) || !(systemActive == 1))) && (((((1 <= tmp && \result == 0) && pumpRunning == 0) || ((\result == 0 && pumpRunning == \old(pumpRunning)) && pumpRunning == 0)) || !(1 <= methaneLevelCritical)) || !(systemActive == 1)) [2021-12-16 00:59:18,587 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: ((((!(1 <= methaneLevelCritical) || !(\old(pumpRunning) == 0)) || ((methaneLevelCritical <= tmp && 2 <= waterLevel) && pumpRunning == 0)) || !(systemActive == 1)) && ((2 <= waterLevel || !(methaneLevelCritical == 0)) || !(systemActive == 1))) && ((0 == \old(pumpRunning) || !(methaneLevelCritical == 0)) || !(systemActive == 1)) [2021-12-16 00:59:18,587 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (((!(1 <= methaneLevelCritical) || !(\old(pumpRunning) == 0)) || !(systemActive == 1)) && ((2 <= waterLevel || !(methaneLevelCritical == 0)) || !(systemActive == 1))) && ((0 == \old(pumpRunning) || !(methaneLevelCritical == 0)) || !(systemActive == 1)) [2021-12-16 00:59:18,587 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: ((((((2 <= waterLevel && pumpRunning == 0) || !(1 <= methaneLevelCritical)) || !(\old(pumpRunning) == 0)) || !(systemActive == 1)) || (\result == 1 && pumpRunning == 0)) && ((0 == \old(pumpRunning) || !(methaneLevelCritical == 0)) || !(systemActive == 1))) && ((((2 <= waterLevel && pumpRunning == 0) || !(methaneLevelCritical == 0)) || !(systemActive == 1)) || (\result == 1 && pumpRunning == 0)) [2021-12-16 00:59:18,587 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (((0 == \old(pumpRunning) || !(methaneLevelCritical == 0)) || !(systemActive == 1)) && ((((2 <= waterLevel && pumpRunning == 0) || ((tmp___0 == 0 && \result == 0) && pumpRunning == 0)) || !(methaneLevelCritical == 0)) || !(systemActive == 1))) && (((((2 <= waterLevel && pumpRunning == 0) || !(1 <= methaneLevelCritical)) || ((tmp___0 == 0 && pumpRunning == \old(pumpRunning)) && \result == 0)) || !(\old(pumpRunning) == 0)) || !(systemActive == 1)) [2021-12-16 00:59:18,604 INFO L141 WitnessManager]: Wrote witness to /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/witness.graphml [2021-12-16 00:59:18,605 INFO L132 PluginConnector]: ------------------------ END Witness Printer---------------------------- [2021-12-16 00:59:18,605 INFO L158 Benchmark]: Toolchain (without parser) took 7771.95ms. Allocated memory was 109.1MB in the beginning and 159.4MB in the end (delta: 50.3MB). Free memory was 72.8MB in the beginning and 88.7MB in the end (delta: -15.9MB). Peak memory consumption was 34.4MB. Max. memory is 16.1GB. [2021-12-16 00:59:18,605 INFO L158 Benchmark]: CDTParser took 0.18ms. Allocated memory is still 109.1MB. Free memory was 81.9MB in the beginning and 81.8MB in the end (delta: 21.2kB). There was no memory consumed. Max. memory is 16.1GB. [2021-12-16 00:59:18,605 INFO L158 Benchmark]: CACSL2BoogieTranslator took 287.42ms. Allocated memory is still 109.1MB. Free memory was 72.8MB in the beginning and 76.4MB in the end (delta: -3.7MB). Peak memory consumption was 10.5MB. Max. memory is 16.1GB. [2021-12-16 00:59:18,606 INFO L158 Benchmark]: Boogie Procedure Inliner took 38.05ms. Allocated memory is still 109.1MB. Free memory was 76.4MB in the beginning and 73.8MB in the end (delta: 2.7MB). Peak memory consumption was 2.1MB. Max. memory is 16.1GB. [2021-12-16 00:59:18,606 INFO L158 Benchmark]: Boogie Preprocessor took 17.39ms. Allocated memory is still 109.1MB. Free memory was 73.8MB in the beginning and 72.2MB in the end (delta: 1.5MB). Peak memory consumption was 2.1MB. Max. memory is 16.1GB. [2021-12-16 00:59:18,606 INFO L158 Benchmark]: RCFGBuilder took 281.43ms. Allocated memory is still 109.1MB. Free memory was 72.2MB in the beginning and 56.0MB in the end (delta: 16.2MB). Peak memory consumption was 16.8MB. Max. memory is 16.1GB. [2021-12-16 00:59:18,606 INFO L158 Benchmark]: TraceAbstraction took 7089.57ms. Allocated memory was 109.1MB in the beginning and 159.4MB in the end (delta: 50.3MB). Free memory was 55.5MB in the beginning and 95.0MB in the end (delta: -39.6MB). Peak memory consumption was 68.7MB. Max. memory is 16.1GB. [2021-12-16 00:59:18,607 INFO L158 Benchmark]: Witness Printer took 53.71ms. Allocated memory is still 159.4MB. Free memory was 95.0MB in the beginning and 88.7MB in the end (delta: 6.3MB). Peak memory consumption was 6.3MB. Max. memory is 16.1GB. [2021-12-16 00:59:18,608 INFO L339 ainManager$Toolchain]: ####################### End [Toolchain 1] ####################### --- Results --- * Results from de.uni_freiburg.informatik.ultimate.core: - StatisticsResult: Toolchain Benchmarks Benchmark results are: * CDTParser took 0.18ms. Allocated memory is still 109.1MB. Free memory was 81.9MB in the beginning and 81.8MB in the end (delta: 21.2kB). There was no memory consumed. Max. memory is 16.1GB. * CACSL2BoogieTranslator took 287.42ms. Allocated memory is still 109.1MB. Free memory was 72.8MB in the beginning and 76.4MB in the end (delta: -3.7MB). Peak memory consumption was 10.5MB. Max. memory is 16.1GB. * Boogie Procedure Inliner took 38.05ms. Allocated memory is still 109.1MB. Free memory was 76.4MB in the beginning and 73.8MB in the end (delta: 2.7MB). Peak memory consumption was 2.1MB. Max. memory is 16.1GB. * Boogie Preprocessor took 17.39ms. Allocated memory is still 109.1MB. Free memory was 73.8MB in the beginning and 72.2MB in the end (delta: 1.5MB). Peak memory consumption was 2.1MB. Max. memory is 16.1GB. * RCFGBuilder took 281.43ms. Allocated memory is still 109.1MB. Free memory was 72.2MB in the beginning and 56.0MB in the end (delta: 16.2MB). Peak memory consumption was 16.8MB. Max. memory is 16.1GB. * TraceAbstraction took 7089.57ms. Allocated memory was 109.1MB in the beginning and 159.4MB in the end (delta: 50.3MB). Free memory was 55.5MB in the beginning and 95.0MB in the end (delta: -39.6MB). Peak memory consumption was 68.7MB. Max. memory is 16.1GB. * Witness Printer took 53.71ms. Allocated memory is still 159.4MB. Free memory was 95.0MB in the beginning and 88.7MB in the end (delta: 6.3MB). Peak memory consumption was 6.3MB. Max. memory is 16.1GB. * Results from de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction: - StatisticsResult: ErrorAutomatonStatistics NumberErrorTraces: 0, NumberStatementsAllTraces: 0, NumberRelevantStatements: 0, 0.0s ErrorAutomatonConstructionTimeTotal, 0.0s FaulLocalizationTime, NumberStatementsFirstTrace: -1, TraceLengthAvg: 0, 0.0s ErrorAutomatonConstructionTimeAvg, 0.0s ErrorAutomatonDifferenceTimeAvg, 0.0s ErrorAutomatonDifferenceTimeTotal, NumberOfNoEnhancement: 0, NumberOfFiniteEnhancement: 0, NumberOfInfiniteEnhancement: 0 - PositiveResult [Line: 868]: call to reach_error is unreachable For all program executions holds that call to reach_error is unreachable at this location - StatisticsResult: Ultimate Automizer benchmark data CFG has 9 procedures, 96 locations, 1 error locations. Started 1 CEGAR loops. OverallTime: 7.0s, OverallIterations: 11, TraceHistogramMax: 4, PathProgramHistogramMax: 1, EmptinessCheckTime: 0.0s, AutomataDifference: 1.9s, DeadEndRemovalTime: 0.0s, HoareAnnotationTime: 2.6s, InitialAbstractionConstructionTime: 0.0s, PartialOrderReductionTime: 0.0s, HoareTripleCheckerStatistics: 0 mSolverCounterUnknown, 1421 SdHoareTripleChecker+Valid, 1.2s IncrementalHoareTripleChecker+Time, 0 mSdLazyCounter, 1393 mSDsluCounter, 3832 SdHoareTripleChecker+Invalid, 1.0s Time, 0 mProtectedAction, 0 SdHoareTripleChecker+Unchecked, 0 IncrementalHoareTripleChecker+Unchecked, 2520 mSDsCounter, 455 IncrementalHoareTripleChecker+Valid, 0 mProtectedPredicate, 1697 IncrementalHoareTripleChecker+Invalid, 2152 SdHoareTripleChecker+Unknown, 0 mSolverCounterNotChecked, 455 mSolverCounterUnsat, 1312 mSDtfsCounter, 1697 mSolverCounterSat, 0.0s SdHoareTripleChecker+Time, 0 IncrementalHoareTripleChecker+Unknown, PredicateUnifierStatistics: 0 DeclaredPredicates, 379 GetRequests, 272 SyntacticMatches, 1 SemanticMatches, 106 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 129 ImplicationChecksByTransitivity, 0.6s Time, 0.0s BasicInterpolantAutomatonTime, BiggestAbstraction: size=518occurred in iteration=9, InterpolantAutomatonStates: 89, traceCheckStatistics: No data available, InterpolantConsolidationStatistics: No data available, PathInvariantsStatistics: No data available, 0/0 InterpolantCoveringCapability, TotalInterpolationStatistics: No data available, 0.0s DumpTime, AutomataMinimizationStatistics: 0.2s AutomataMinimizationTime, 11 MinimizatonAttempts, 64 StatesRemovedByMinimization, 7 NontrivialMinimizations, HoareAnnotationStatistics: 0.0s HoareAnnotationTime, 44 LocationsWithAnnotation, 1304 PreInvPairs, 1493 NumberOfFragments, 1619 HoareAnnotationTreeSize, 1304 FomulaSimplifications, 0 FormulaSimplificationTreeSizeReduction, 0.2s HoareSimplificationTime, 44 FomulaSimplificationsInter, 7687 FormulaSimplificationTreeSizeReductionInter, 2.3s HoareSimplificationTimeInter, RefinementEngineStatistics: TRACE_CHECK: 0.0s SsaConstructionTime, 0.2s SatisfiabilityAnalysisTime, 1.3s InterpolantComputationTime, 754 NumberOfCodeBlocks, 754 NumberOfCodeBlocksAsserted, 13 NumberOfCheckSat, 741 ConstructedInterpolants, 0 QuantifiedInterpolants, 1384 SizeOfPredicates, 6 NumberOfNonLiveVariables, 905 ConjunctsInSsa, 18 ConjunctsInUnsatCore, 13 InterpolantComputations, 11 PerfectInterpolantSequences, 100/105 InterpolantCoveringCapability, INVARIANT_SYNTHESIS: No data available, INTERPOLANT_CONSOLIDATION: No data available, ABSTRACT_INTERPRETATION: No data available, PDR: No data available, ACCELERATED_INTERPOLATION: No data available, SIFA: No data available, ReuseStatistics: No data available - AllSpecificationsHoldResult: All specifications hold 1 specifications checked. All of them hold - InvariantResult [Line: 882]: Loop Invariant Derived loop invariant: ((((((((pumpRunning == \old(pumpRunning) && pumpRunning == 0) || !(1 <= methaneLevelCritical)) || (1 <= tmp && pumpRunning == 0)) || !(systemActive == 1)) && ((((!(2 <= \old(waterLevel)) || ((tmp == 0 && methaneLevelCritical == 0) && 2 <= waterLevel)) || !(0 == \old(pumpRunning))) || !(methaneLevelCritical == 0)) || !(systemActive == 1))) && ((((!(2 <= \old(waterLevel)) || !(1 <= methaneLevelCritical)) || !(\old(pumpRunning) == 0)) || 2 <= waterLevel) || !(systemActive == 1))) && ((((!(\old(waterLevel) == 1) || waterLevel == 1) || !(1 <= methaneLevelCritical)) || !(\old(pumpRunning) == 0)) || !(systemActive == 1))) && ((((!(\old(waterLevel) == 1) || waterLevel == 1) || !(\old(pumpRunning) == 0)) || !(methaneLevelCritical == 0)) || !(systemActive == 1))) && ((((((tmp == 0 && methaneLevelCritical == 0) && 2 <= waterLevel) || (tmp == 0 && pumpRunning == 0)) || (tmp == 0 && pumpRunning == \old(pumpRunning))) || !(methaneLevelCritical == 0)) || !(systemActive == 1)) - InvariantResult [Line: 864]: Loop Invariant Derived loop invariant: (!(methaneLevelCritical == 0) || !(systemActive == 1)) && (!(1 <= methaneLevelCritical) || !(systemActive == 1)) - InvariantResult [Line: 747]: Loop Invariant Derived loop invariant: (((!(1 <= methaneLevelCritical) || !(\old(pumpRunning) == 0)) || !(systemActive == 1)) && ((2 <= waterLevel || !(methaneLevelCritical == 0)) || !(systemActive == 1))) && ((0 == \old(pumpRunning) || !(methaneLevelCritical == 0)) || !(systemActive == 1)) - InvariantResult [Line: 612]: Loop Invariant Derived loop invariant: ((((systemActive == tmp && systemActive == \result) && waterLevel == 1) && methaneLevelCritical == 0) && systemActive == 1) && pumpRunning == 0 - InvariantResult [Line: 874]: Loop Invariant Derived loop invariant: ((((systemActive == tmp && systemActive == \result) && waterLevel == 1) && methaneLevelCritical == 0) && systemActive == 1) && pumpRunning == 0 - InvariantResult [Line: 921]: Loop Invariant Derived loop invariant: 0 - InvariantResult [Line: 78]: Loop Invariant Derived loop invariant: (((systemActive == \result && waterLevel == 1) && methaneLevelCritical == 0) && systemActive == 1) && pumpRunning == 0 - InvariantResult [Line: 855]: Loop Invariant Derived loop invariant: ((((splverifierCounter == 0 && systemActive == tmp) && systemActive == \result) && 1 <= methaneLevelCritical) && systemActive == 1) || ((((splverifierCounter == 0 && systemActive == tmp) && systemActive == \result) && methaneLevelCritical == 0) && systemActive == 1) - InvariantResult [Line: 64]: Loop Invariant Derived loop invariant: ((waterLevel == 1 && methaneLevelCritical == 0) && systemActive == 1) && pumpRunning == 0 - InvariantResult [Line: 755]: Loop Invariant Derived loop invariant: ((((!(1 <= methaneLevelCritical) || !(\old(pumpRunning) == 0)) || ((methaneLevelCritical <= tmp && 2 <= waterLevel) && pumpRunning == 0)) || !(systemActive == 1)) && ((2 <= waterLevel || !(methaneLevelCritical == 0)) || !(systemActive == 1))) && ((0 == \old(pumpRunning) || !(methaneLevelCritical == 0)) || !(systemActive == 1)) - InvariantResult [Line: 463]: Loop Invariant Derived loop invariant: ((!(methaneLevelCritical == 0) || !(systemActive == 1)) || (!(0 == \old(pumpRunning)) && pumpRunning == \old(pumpRunning))) && ((!(1 <= methaneLevelCritical) || !(systemActive == 1)) || (!(0 == \old(pumpRunning)) && pumpRunning == \old(pumpRunning))) - InvariantResult [Line: 836]: Loop Invariant Derived loop invariant: (((0 == \old(pumpRunning) || !(methaneLevelCritical == 0)) || !(systemActive == 1)) && ((((2 <= waterLevel && pumpRunning == 0) || ((tmp___0 == 0 && \result == 0) && pumpRunning == 0)) || !(methaneLevelCritical == 0)) || !(systemActive == 1))) && (((((2 <= waterLevel && pumpRunning == 0) || !(1 <= methaneLevelCritical)) || ((tmp___0 == 0 && pumpRunning == \old(pumpRunning)) && \result == 0)) || !(\old(pumpRunning) == 0)) || !(systemActive == 1)) - InvariantResult [Line: 71]: Loop Invariant Derived loop invariant: ((waterLevel == 1 && methaneLevelCritical == 0) && systemActive == 1) && pumpRunning == 0 - InvariantResult [Line: 772]: Loop Invariant Derived loop invariant: (((!(1 <= methaneLevelCritical) || !(\old(pumpRunning) == 0)) || !(systemActive == 1)) && ((!(1 <= methaneLevelCritical) || (1 <= tmp && pumpRunning == 0)) || !(systemActive == 1))) && ((!(methaneLevelCritical == 0) || (!(0 == \old(pumpRunning)) && pumpRunning == 0)) || !(systemActive == 1)) - InvariantResult [Line: 922]: Loop Invariant Derived loop invariant: (((((splverifierCounter == 0 && systemActive == tmp) && systemActive == \result) && 1 <= methaneLevelCritical) && systemActive == 1) && pumpRunning == 0) || ((((splverifierCounter == 0 && systemActive == tmp) && systemActive == \result) && methaneLevelCritical == 0) && systemActive == 1) - InvariantResult [Line: 722]: Loop Invariant Derived loop invariant: (((((((((!(0 == \old(pumpRunning)) && 1 <= tmp) && pumpRunning == 0) || (pumpRunning == \old(pumpRunning) && pumpRunning == 0)) || !(1 <= methaneLevelCritical)) || !(systemActive == 1)) && ((((!(\old(waterLevel) == 1) || waterLevel == 1) || !(1 <= methaneLevelCritical)) || !(\old(pumpRunning) == 0)) || !(systemActive == 1))) && ((((!(2 <= \old(waterLevel)) || ((!(0 == \old(pumpRunning)) && 1 <= tmp) && pumpRunning == 0)) || !(1 <= methaneLevelCritical)) || 2 <= waterLevel) || !(systemActive == 1))) && ((((!(2 <= \old(waterLevel)) || (methaneLevelCritical == 0 && 2 <= waterLevel)) || !(\old(pumpRunning) == 0)) || !(methaneLevelCritical == 0)) || !(systemActive == 1))) && ((((!(\old(waterLevel) == 1) || waterLevel == 1) || !(\old(pumpRunning) == 0)) || !(methaneLevelCritical == 0)) || !(systemActive == 1))) && (((((methaneLevelCritical == 0 && 2 <= waterLevel) || pumpRunning == \old(pumpRunning)) || !(methaneLevelCritical == 0)) || !(systemActive == 1)) || pumpRunning == 0) - InvariantResult [Line: 791]: Loop Invariant Derived loop invariant: (((!(methaneLevelCritical == 0) || !(systemActive == 1)) && ((((!(2 <= \old(waterLevel)) || !(1 <= methaneLevelCritical)) || !(\old(pumpRunning) == 0)) || 2 <= waterLevel) || !(systemActive == 1))) && ((((!(\old(waterLevel) == 1) || waterLevel == 1) || !(1 <= methaneLevelCritical)) || !(\old(pumpRunning) == 0)) || !(systemActive == 1))) && (((((1 <= tmp && \result == 0) && pumpRunning == 0) || ((\result == 0 && pumpRunning == \old(pumpRunning)) && pumpRunning == 0)) || !(1 <= methaneLevelCritical)) || !(systemActive == 1)) - InvariantResult [Line: 567]: Loop Invariant Derived loop invariant: 1 - InvariantResult [Line: 621]: Loop Invariant Derived loop invariant: 1 - InvariantResult [Line: 557]: Loop Invariant Derived loop invariant: 1 - InvariantResult [Line: 912]: Loop Invariant Derived loop invariant: 1 - InvariantResult [Line: 540]: Loop Invariant Derived loop invariant: ((((((2 <= waterLevel && pumpRunning == 0) || !(1 <= methaneLevelCritical)) || !(\old(pumpRunning) == 0)) || !(systemActive == 1)) || (\result == 1 && pumpRunning == 0)) && ((0 == \old(pumpRunning) || !(methaneLevelCritical == 0)) || !(systemActive == 1))) && ((((2 <= waterLevel && pumpRunning == 0) || !(methaneLevelCritical == 0)) || !(systemActive == 1)) || (\result == 1 && pumpRunning == 0)) - InvariantResult [Line: 632]: Loop Invariant Derived loop invariant: 1 RESULT: Ultimate proved your program to be correct! [2021-12-16 00:59:18,643 INFO L540 MonitoredProcess]: [MP /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in -t:2000 (1)] Forceful destruction successful, exit code 0 Received shutdown request... --- End real Ultimate output --- Execution finished normally Writing output log to file Ultimate.log Result: TRUE