./Ultimate.py --spec ../sv-benchmarks/c/properties/unreach-call.prp --file ../sv-benchmarks/c/product-lines/minepump_spec2_product49.cil.c --full-output --architecture 32bit -------------------------------------------------------------------------------- Checking for ERROR reachability Using default analysis Version c3fed411 Calling Ultimate with: /usr/bin/java -Dosgi.configuration.area=/storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/data/config -Xmx15G -Xms4m -jar /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/plugins/org.eclipse.equinox.launcher_1.5.800.v20200727-1323.jar -data @noDefault -ultimatedata /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/data -tc /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/config/AutomizerReach.xml -i ../sv-benchmarks/c/product-lines/minepump_spec2_product49.cil.c -s /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/config/svcomp-Reach-32bit-Automizer_Default.epf --cacsl2boogietranslator.entry.function main --witnessprinter.witness.directory /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux --witnessprinter.witness.filename witness.graphml --witnessprinter.write.witness.besides.input.file false --witnessprinter.graph.data.specification CHECK( init(main()), LTL(G ! call(reach_error())) ) --witnessprinter.graph.data.producer Automizer --witnessprinter.graph.data.architecture 32bit --witnessprinter.graph.data.programhash 8ebbbe9395fd7f6497497f0e6f84282075bb296e20acc9821d0fb2d7075b331d --- Real Ultimate output --- This is Ultimate 0.2.2-tmp.no-commuhash-c3fed41 [2021-12-16 00:59:11,657 INFO L177 SettingsManager]: Resetting all preferences to default values... [2021-12-16 00:59:11,665 INFO L181 SettingsManager]: Resetting UltimateCore preferences to default values [2021-12-16 00:59:11,696 INFO L184 SettingsManager]: Ultimate Commandline Interface provides no preferences, ignoring... [2021-12-16 00:59:11,696 INFO L181 SettingsManager]: Resetting Boogie Preprocessor preferences to default values [2021-12-16 00:59:11,697 INFO L181 SettingsManager]: Resetting Boogie Procedure Inliner preferences to default values [2021-12-16 00:59:11,698 INFO L181 SettingsManager]: Resetting Abstract Interpretation preferences to default values [2021-12-16 00:59:11,699 INFO L181 SettingsManager]: Resetting LassoRanker preferences to default values [2021-12-16 00:59:11,700 INFO L181 SettingsManager]: Resetting Reaching Definitions preferences to default values [2021-12-16 00:59:11,701 INFO L181 SettingsManager]: Resetting SyntaxChecker preferences to default values [2021-12-16 00:59:11,701 INFO L181 SettingsManager]: Resetting Sifa preferences to default values [2021-12-16 00:59:11,702 INFO L184 SettingsManager]: Büchi Program Product provides no preferences, ignoring... [2021-12-16 00:59:11,702 INFO L181 SettingsManager]: Resetting LTL2Aut preferences to default values [2021-12-16 00:59:11,703 INFO L181 SettingsManager]: Resetting PEA to Boogie preferences to default values [2021-12-16 00:59:11,704 INFO L181 SettingsManager]: Resetting BlockEncodingV2 preferences to default values [2021-12-16 00:59:11,705 INFO L181 SettingsManager]: Resetting ChcToBoogie preferences to default values [2021-12-16 00:59:11,706 INFO L181 SettingsManager]: Resetting AutomataScriptInterpreter preferences to default values [2021-12-16 00:59:11,706 INFO L181 SettingsManager]: Resetting BuchiAutomizer preferences to default values [2021-12-16 00:59:11,707 INFO L181 SettingsManager]: Resetting CACSL2BoogieTranslator preferences to default values [2021-12-16 00:59:11,708 INFO L181 SettingsManager]: Resetting CodeCheck preferences to default values [2021-12-16 00:59:11,709 INFO L181 SettingsManager]: Resetting InvariantSynthesis preferences to default values [2021-12-16 00:59:11,710 INFO L181 SettingsManager]: Resetting RCFGBuilder preferences to default values [2021-12-16 00:59:11,711 INFO L181 SettingsManager]: Resetting Referee preferences to default values [2021-12-16 00:59:11,712 INFO L181 SettingsManager]: Resetting TraceAbstraction preferences to default values [2021-12-16 00:59:11,713 INFO L184 SettingsManager]: TraceAbstractionConcurrent provides no preferences, ignoring... [2021-12-16 00:59:11,714 INFO L184 SettingsManager]: TraceAbstractionWithAFAs provides no preferences, ignoring... [2021-12-16 00:59:11,714 INFO L181 SettingsManager]: Resetting TreeAutomizer preferences to default values [2021-12-16 00:59:11,715 INFO L181 SettingsManager]: Resetting IcfgToChc preferences to default values [2021-12-16 00:59:11,715 INFO L181 SettingsManager]: Resetting IcfgTransformer preferences to default values [2021-12-16 00:59:11,716 INFO L184 SettingsManager]: ReqToTest provides no preferences, ignoring... [2021-12-16 00:59:11,716 INFO L181 SettingsManager]: Resetting Boogie Printer preferences to default values [2021-12-16 00:59:11,716 INFO L181 SettingsManager]: Resetting ChcSmtPrinter preferences to default values [2021-12-16 00:59:11,717 INFO L181 SettingsManager]: Resetting ReqPrinter preferences to default values [2021-12-16 00:59:11,720 INFO L181 SettingsManager]: Resetting Witness Printer preferences to default values [2021-12-16 00:59:11,720 INFO L184 SettingsManager]: Boogie PL CUP Parser provides no preferences, ignoring... [2021-12-16 00:59:11,721 INFO L181 SettingsManager]: Resetting CDTParser preferences to default values [2021-12-16 00:59:11,721 INFO L184 SettingsManager]: AutomataScriptParser provides no preferences, ignoring... [2021-12-16 00:59:11,721 INFO L184 SettingsManager]: ReqParser provides no preferences, ignoring... [2021-12-16 00:59:11,722 INFO L181 SettingsManager]: Resetting SmtParser preferences to default values [2021-12-16 00:59:11,722 INFO L181 SettingsManager]: Resetting Witness Parser preferences to default values [2021-12-16 00:59:11,723 INFO L188 SettingsManager]: Finished resetting all preferences to default values... [2021-12-16 00:59:11,724 INFO L101 SettingsManager]: Beginning loading settings from /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/config/svcomp-Reach-32bit-Automizer_Default.epf [2021-12-16 00:59:11,737 INFO L113 SettingsManager]: Loading preferences was successful [2021-12-16 00:59:11,737 INFO L115 SettingsManager]: Preferences different from defaults after loading the file: [2021-12-16 00:59:11,738 INFO L136 SettingsManager]: Preferences of UltimateCore differ from their defaults: [2021-12-16 00:59:11,738 INFO L138 SettingsManager]: * Log level for class=de.uni_freiburg.informatik.ultimate.lib.smtlibutils.quantifier.QuantifierPusher=ERROR; [2021-12-16 00:59:11,738 INFO L136 SettingsManager]: Preferences of Boogie Procedure Inliner differ from their defaults: [2021-12-16 00:59:11,739 INFO L138 SettingsManager]: * Ignore calls to procedures called more than once=ONLY_FOR_SEQUENTIAL_PROGRAMS [2021-12-16 00:59:11,739 INFO L136 SettingsManager]: Preferences of BlockEncodingV2 differ from their defaults: [2021-12-16 00:59:11,739 INFO L138 SettingsManager]: * Create parallel compositions if possible=false [2021-12-16 00:59:11,739 INFO L138 SettingsManager]: * Use SBE=true [2021-12-16 00:59:11,740 INFO L136 SettingsManager]: Preferences of CACSL2BoogieTranslator differ from their defaults: [2021-12-16 00:59:11,740 INFO L138 SettingsManager]: * sizeof long=4 [2021-12-16 00:59:11,740 INFO L138 SettingsManager]: * Overapproximate operations on floating types=true [2021-12-16 00:59:11,740 INFO L138 SettingsManager]: * sizeof POINTER=4 [2021-12-16 00:59:11,740 INFO L138 SettingsManager]: * Check division by zero=IGNORE [2021-12-16 00:59:11,740 INFO L138 SettingsManager]: * Pointer to allocated memory at dereference=IGNORE [2021-12-16 00:59:11,741 INFO L138 SettingsManager]: * If two pointers are subtracted or compared they have the same base address=IGNORE [2021-12-16 00:59:11,741 INFO L138 SettingsManager]: * Check array bounds for arrays that are off heap=IGNORE [2021-12-16 00:59:11,741 INFO L138 SettingsManager]: * sizeof long double=12 [2021-12-16 00:59:11,741 INFO L138 SettingsManager]: * Check if freed pointer was valid=false [2021-12-16 00:59:11,741 INFO L138 SettingsManager]: * Use constant arrays=true [2021-12-16 00:59:11,741 INFO L138 SettingsManager]: * Pointer base address is valid at dereference=IGNORE [2021-12-16 00:59:11,742 INFO L136 SettingsManager]: Preferences of RCFGBuilder differ from their defaults: [2021-12-16 00:59:11,742 INFO L138 SettingsManager]: * Size of a code block=SequenceOfStatements [2021-12-16 00:59:11,742 INFO L138 SettingsManager]: * SMT solver=External_DefaultMode [2021-12-16 00:59:11,742 INFO L138 SettingsManager]: * Command for external solver=z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in -t:2000 [2021-12-16 00:59:11,742 INFO L136 SettingsManager]: Preferences of TraceAbstraction differ from their defaults: [2021-12-16 00:59:11,743 INFO L138 SettingsManager]: * Compute Interpolants along a Counterexample=FPandBP [2021-12-16 00:59:11,743 INFO L138 SettingsManager]: * Positions where we compute the Hoare Annotation=LoopsAndPotentialCycles [2021-12-16 00:59:11,743 INFO L138 SettingsManager]: * Trace refinement strategy=CAMEL [2021-12-16 00:59:11,743 INFO L138 SettingsManager]: * Command for external solver=z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in [2021-12-16 00:59:11,743 INFO L138 SettingsManager]: * Large block encoding in concurrent analysis=OFF [2021-12-16 00:59:11,743 INFO L138 SettingsManager]: * Automaton type used in concurrency analysis=PETRI_NET [2021-12-16 00:59:11,744 INFO L138 SettingsManager]: * Compute Hoare Annotation of negated interpolant automaton, abstraction and CFG=true [2021-12-16 00:59:11,744 INFO L138 SettingsManager]: * Trace refinement exception blacklist=NONE [2021-12-16 00:59:11,744 INFO L138 SettingsManager]: * SMT solver=External_ModelsAndUnsatCoreMode WARNING: An illegal reflective access operation has occurred WARNING: Illegal reflective access by com.sun.xml.bind.v2.runtime.reflect.opt.Injector$1 (file:/storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/plugins/com.sun.xml.bind_2.2.0.v201505121915.jar) to method java.lang.ClassLoader.defineClass(java.lang.String,byte[],int,int) WARNING: Please consider reporting this to the maintainers of com.sun.xml.bind.v2.runtime.reflect.opt.Injector$1 WARNING: Use --illegal-access=warn to enable warnings of further illegal reflective access operations WARNING: All illegal access operations will be denied in a future release Applying setting for plugin de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator: Entry function -> main Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Witness directory -> /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Witness filename -> witness.graphml Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Write witness besides input file -> false Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Graph data specification -> CHECK( init(main()), LTL(G ! call(reach_error())) ) Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Graph data producer -> Automizer Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Graph data architecture -> 32bit Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Graph data programhash -> 8ebbbe9395fd7f6497497f0e6f84282075bb296e20acc9821d0fb2d7075b331d [2021-12-16 00:59:11,914 INFO L75 nceAwareModelManager]: Repository-Root is: /tmp [2021-12-16 00:59:11,927 INFO L261 ainManager$Toolchain]: [Toolchain 1]: Applicable parser(s) successfully (re)initialized [2021-12-16 00:59:11,929 INFO L217 ainManager$Toolchain]: [Toolchain 1]: Toolchain selected. [2021-12-16 00:59:11,930 INFO L271 PluginConnector]: Initializing CDTParser... [2021-12-16 00:59:11,931 INFO L275 PluginConnector]: CDTParser initialized [2021-12-16 00:59:11,931 INFO L432 ainManager$Toolchain]: [Toolchain 1]: Parsing single file: /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/../sv-benchmarks/c/product-lines/minepump_spec2_product49.cil.c [2021-12-16 00:59:11,969 INFO L220 CDTParser]: Created temporary CDT project at /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/data/fa080a186/f304c16cfa554b6695721b97fec2e604/FLAGab74f0a08 [2021-12-16 00:59:12,319 INFO L306 CDTParser]: Found 1 translation units. [2021-12-16 00:59:12,320 INFO L160 CDTParser]: Scanning /storage/repos/ultimate/releaseScripts/default/sv-benchmarks/c/product-lines/minepump_spec2_product49.cil.c [2021-12-16 00:59:12,334 INFO L349 CDTParser]: About to delete temporary CDT project at /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/data/fa080a186/f304c16cfa554b6695721b97fec2e604/FLAGab74f0a08 [2021-12-16 00:59:12,706 INFO L357 CDTParser]: Successfully deleted /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/data/fa080a186/f304c16cfa554b6695721b97fec2e604 [2021-12-16 00:59:12,708 INFO L299 ainManager$Toolchain]: ####################### [Toolchain 1] ####################### [2021-12-16 00:59:12,709 INFO L131 ToolchainWalker]: Walking toolchain with 6 elements. [2021-12-16 00:59:12,714 INFO L113 PluginConnector]: ------------------------CACSL2BoogieTranslator---------------------------- [2021-12-16 00:59:12,715 INFO L271 PluginConnector]: Initializing CACSL2BoogieTranslator... [2021-12-16 00:59:12,717 INFO L275 PluginConnector]: CACSL2BoogieTranslator initialized [2021-12-16 00:59:12,718 INFO L185 PluginConnector]: Executing the observer ACSLObjectContainerObserver from plugin CACSL2BoogieTranslator for "CDTParser AST 16.12 12:59:12" (1/1) ... [2021-12-16 00:59:12,718 INFO L205 PluginConnector]: Invalid model from CACSL2BoogieTranslator for observer de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator.ACSLObjectContainerObserver@76bef5e5 and model type de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 16.12 12:59:12, skipping insertion in model container [2021-12-16 00:59:12,719 INFO L185 PluginConnector]: Executing the observer CACSL2BoogieTranslatorObserver from plugin CACSL2BoogieTranslator for "CDTParser AST 16.12 12:59:12" (1/1) ... [2021-12-16 00:59:12,723 INFO L145 MainTranslator]: Starting translation in SV-COMP mode [2021-12-16 00:59:12,758 INFO L178 MainTranslator]: Built tables and reachable declarations [2021-12-16 00:59:12,992 WARN L230 ndardFunctionHandler]: Function reach_error is already implemented but we override the implementation for the call at /storage/repos/ultimate/releaseScripts/default/sv-benchmarks/c/product-lines/minepump_spec2_product49.cil.c[18359,18372] [2021-12-16 00:59:12,996 INFO L209 PostProcessor]: Analyzing one entry point: main [2021-12-16 00:59:13,002 INFO L203 MainTranslator]: Completed pre-run [2021-12-16 00:59:13,042 WARN L230 ndardFunctionHandler]: Function reach_error is already implemented but we override the implementation for the call at /storage/repos/ultimate/releaseScripts/default/sv-benchmarks/c/product-lines/minepump_spec2_product49.cil.c[18359,18372] [2021-12-16 00:59:13,043 INFO L209 PostProcessor]: Analyzing one entry point: main [2021-12-16 00:59:13,054 INFO L208 MainTranslator]: Completed translation [2021-12-16 00:59:13,055 INFO L202 PluginConnector]: Adding new model de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 16.12 12:59:13 WrapperNode [2021-12-16 00:59:13,055 INFO L132 PluginConnector]: ------------------------ END CACSL2BoogieTranslator---------------------------- [2021-12-16 00:59:13,056 INFO L113 PluginConnector]: ------------------------Boogie Procedure Inliner---------------------------- [2021-12-16 00:59:13,056 INFO L271 PluginConnector]: Initializing Boogie Procedure Inliner... [2021-12-16 00:59:13,056 INFO L275 PluginConnector]: Boogie Procedure Inliner initialized [2021-12-16 00:59:13,075 INFO L185 PluginConnector]: Executing the observer TypeChecker from plugin Boogie Procedure Inliner for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 16.12 12:59:13" (1/1) ... [2021-12-16 00:59:13,098 INFO L185 PluginConnector]: Executing the observer Inliner from plugin Boogie Procedure Inliner for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 16.12 12:59:13" (1/1) ... [2021-12-16 00:59:13,128 INFO L137 Inliner]: procedures = 56, calls = 155, calls flagged for inlining = 23, calls inlined = 20, statements flattened = 259 [2021-12-16 00:59:13,128 INFO L132 PluginConnector]: ------------------------ END Boogie Procedure Inliner---------------------------- [2021-12-16 00:59:13,129 INFO L113 PluginConnector]: ------------------------Boogie Preprocessor---------------------------- [2021-12-16 00:59:13,130 INFO L271 PluginConnector]: Initializing Boogie Preprocessor... [2021-12-16 00:59:13,130 INFO L275 PluginConnector]: Boogie Preprocessor initialized [2021-12-16 00:59:13,135 INFO L185 PluginConnector]: Executing the observer EnsureBoogieModelObserver from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 16.12 12:59:13" (1/1) ... [2021-12-16 00:59:13,135 INFO L185 PluginConnector]: Executing the observer TypeChecker from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 16.12 12:59:13" (1/1) ... [2021-12-16 00:59:13,141 INFO L185 PluginConnector]: Executing the observer ConstExpander from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 16.12 12:59:13" (1/1) ... [2021-12-16 00:59:13,141 INFO L185 PluginConnector]: Executing the observer StructExpander from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 16.12 12:59:13" (1/1) ... [2021-12-16 00:59:13,153 INFO L185 PluginConnector]: Executing the observer UnstructureCode from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 16.12 12:59:13" (1/1) ... [2021-12-16 00:59:13,172 INFO L185 PluginConnector]: Executing the observer FunctionInliner from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 16.12 12:59:13" (1/1) ... [2021-12-16 00:59:13,173 INFO L185 PluginConnector]: Executing the observer BoogieSymbolTableConstructor from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 16.12 12:59:13" (1/1) ... [2021-12-16 00:59:13,175 INFO L132 PluginConnector]: ------------------------ END Boogie Preprocessor---------------------------- [2021-12-16 00:59:13,175 INFO L113 PluginConnector]: ------------------------RCFGBuilder---------------------------- [2021-12-16 00:59:13,175 INFO L271 PluginConnector]: Initializing RCFGBuilder... [2021-12-16 00:59:13,176 INFO L275 PluginConnector]: RCFGBuilder initialized [2021-12-16 00:59:13,184 INFO L185 PluginConnector]: Executing the observer RCFGBuilderObserver from plugin RCFGBuilder for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 16.12 12:59:13" (1/1) ... [2021-12-16 00:59:13,189 INFO L168 SolverBuilder]: Constructing external solver with command: z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in -t:2000 [2021-12-16 00:59:13,201 INFO L189 MonitoredProcess]: No working directory specified, using /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 [2021-12-16 00:59:13,220 INFO L229 MonitoredProcess]: Starting monitored process 1 with /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in -t:2000 (exit command is (exit), workingDir is null) [2021-12-16 00:59:13,241 INFO L327 MonitoredProcess]: [MP /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in -t:2000 (1)] Waiting until timeout for monitored process [2021-12-16 00:59:13,253 INFO L130 BoogieDeclarations]: Found specification of procedure #Ultimate.allocInit [2021-12-16 00:59:13,253 INFO L130 BoogieDeclarations]: Found specification of procedure processEnvironment__wrappee__base [2021-12-16 00:59:13,253 INFO L138 BoogieDeclarations]: Found implementation of procedure processEnvironment__wrappee__base [2021-12-16 00:59:13,253 INFO L130 BoogieDeclarations]: Found specification of procedure isMethaneLevelCritical [2021-12-16 00:59:13,253 INFO L138 BoogieDeclarations]: Found implementation of procedure isMethaneLevelCritical [2021-12-16 00:59:13,253 INFO L130 BoogieDeclarations]: Found specification of procedure timeShift [2021-12-16 00:59:13,253 INFO L138 BoogieDeclarations]: Found implementation of procedure timeShift [2021-12-16 00:59:13,254 INFO L130 BoogieDeclarations]: Found specification of procedure cleanup [2021-12-16 00:59:13,254 INFO L138 BoogieDeclarations]: Found implementation of procedure cleanup [2021-12-16 00:59:13,254 INFO L130 BoogieDeclarations]: Found specification of procedure processEnvironment__wrappee__highWaterSensor [2021-12-16 00:59:13,254 INFO L138 BoogieDeclarations]: Found implementation of procedure processEnvironment__wrappee__highWaterSensor [2021-12-16 00:59:13,254 INFO L130 BoogieDeclarations]: Found specification of procedure waterRise [2021-12-16 00:59:13,254 INFO L138 BoogieDeclarations]: Found implementation of procedure waterRise [2021-12-16 00:59:13,254 INFO L130 BoogieDeclarations]: Found specification of procedure write~init~int [2021-12-16 00:59:13,254 INFO L130 BoogieDeclarations]: Found specification of procedure changeMethaneLevel [2021-12-16 00:59:13,255 INFO L138 BoogieDeclarations]: Found implementation of procedure changeMethaneLevel [2021-12-16 00:59:13,255 INFO L130 BoogieDeclarations]: Found specification of procedure ULTIMATE.start [2021-12-16 00:59:13,255 INFO L138 BoogieDeclarations]: Found implementation of procedure ULTIMATE.start [2021-12-16 00:59:13,320 INFO L236 CfgBuilder]: Building ICFG [2021-12-16 00:59:13,321 INFO L262 CfgBuilder]: Building CFG for each procedure with an implementation [2021-12-16 00:59:13,535 INFO L277 CfgBuilder]: Performing block encoding [2021-12-16 00:59:13,540 INFO L296 CfgBuilder]: Using the 1 location(s) as analysis (start of procedure ULTIMATE.start) [2021-12-16 00:59:13,540 INFO L301 CfgBuilder]: Removed 2 assume(true) statements. [2021-12-16 00:59:13,541 INFO L202 PluginConnector]: Adding new model de.uni_freiburg.informatik.ultimate.plugins.generator.rcfgbuilder CFG 16.12 12:59:13 BoogieIcfgContainer [2021-12-16 00:59:13,541 INFO L132 PluginConnector]: ------------------------ END RCFGBuilder---------------------------- [2021-12-16 00:59:13,543 INFO L113 PluginConnector]: ------------------------TraceAbstraction---------------------------- [2021-12-16 00:59:13,543 INFO L271 PluginConnector]: Initializing TraceAbstraction... [2021-12-16 00:59:13,549 INFO L275 PluginConnector]: TraceAbstraction initialized [2021-12-16 00:59:13,549 INFO L185 PluginConnector]: Executing the observer TraceAbstractionObserver from plugin TraceAbstraction for "CDTParser AST 16.12 12:59:12" (1/3) ... [2021-12-16 00:59:13,550 INFO L205 PluginConnector]: Invalid model from TraceAbstraction for observer de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction.TraceAbstractionObserver@42715964 and model type de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction AST 16.12 12:59:13, skipping insertion in model container [2021-12-16 00:59:13,550 INFO L185 PluginConnector]: Executing the observer TraceAbstractionObserver from plugin TraceAbstraction for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 16.12 12:59:13" (2/3) ... [2021-12-16 00:59:13,551 INFO L205 PluginConnector]: Invalid model from TraceAbstraction for observer de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction.TraceAbstractionObserver@42715964 and model type de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction AST 16.12 12:59:13, skipping insertion in model container [2021-12-16 00:59:13,551 INFO L185 PluginConnector]: Executing the observer TraceAbstractionObserver from plugin TraceAbstraction for "de.uni_freiburg.informatik.ultimate.plugins.generator.rcfgbuilder CFG 16.12 12:59:13" (3/3) ... [2021-12-16 00:59:13,552 INFO L111 eAbstractionObserver]: Analyzing ICFG minepump_spec2_product49.cil.c [2021-12-16 00:59:13,556 INFO L204 ceAbstractionStarter]: Automizer settings: Hoare:true NWA Interpolation:FPandBP Determinization: PREDICATE_ABSTRACTION [2021-12-16 00:59:13,556 INFO L163 ceAbstractionStarter]: Applying trace abstraction to program that has 1 error locations. [2021-12-16 00:59:13,595 INFO L338 AbstractCegarLoop]: ======== Iteration 0 == of CEGAR loop == AllErrorsAtOnce ======== [2021-12-16 00:59:13,600 INFO L339 AbstractCegarLoop]: Settings: SEPARATE_VIOLATION_CHECK=true, mInterprocedural=true, mMaxIterations=1000000, mWatchIteration=1000000, mArtifact=RCFG, mInterpolation=FPandBP, mInterpolantAutomaton=STRAIGHT_LINE, mDumpAutomata=false, mAutomataFormat=ATS_NUMERATE, mDumpPath=., mDeterminiation=PREDICATE_ABSTRACTION, mMinimize=MINIMIZE_SEVPA, mHoare=true, mAutomataTypeConcurrency=PETRI_NET, mHoareTripleChecks=INCREMENTAL, mHoareAnnotationPositions=LoopsAndPotentialCycles, mDumpOnlyReuseAutomata=false, mLimitTraceHistogram=0, mErrorLocTimeLimit=0, mLimitPathProgramCount=0, mCollectInterpolantStatistics=true, mHeuristicEmptinessCheck=false, mHeuristicEmptinessCheckAStarHeuristic=ZERO, mHeuristicEmptinessCheckAStarHeuristicRandomSeed=1337, mHeuristicEmptinessCheckSmtFeatureScoringMethod=DAGSIZE, mSMTFeatureExtraction=false, mSMTFeatureExtractionDumpPath=., mOverrideInterpolantAutomaton=false, mMcrInterpolantMethod=WP, mLoopAccelerationTechnique=FAST_UPR [2021-12-16 00:59:13,600 INFO L340 AbstractCegarLoop]: Starting to check reachability of 1 error locations. [2021-12-16 00:59:13,612 INFO L276 IsEmpty]: Start isEmpty. Operand has 88 states, 68 states have (on average 1.3970588235294117) internal successors, (95), 76 states have internal predecessors, (95), 11 states have call successors, (11), 7 states have call predecessors, (11), 7 states have return successors, (11), 9 states have call predecessors, (11), 11 states have call successors, (11) [2021-12-16 00:59:13,617 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 26 [2021-12-16 00:59:13,617 INFO L506 BasicCegarLoop]: Found error trace [2021-12-16 00:59:13,618 INFO L514 BasicCegarLoop]: trace histogram [1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2021-12-16 00:59:13,618 INFO L402 AbstractCegarLoop]: === Iteration 1 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2021-12-16 00:59:13,622 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2021-12-16 00:59:13,622 INFO L85 PathProgramCache]: Analyzing trace with hash -1277571174, now seen corresponding path program 1 times [2021-12-16 00:59:13,628 INFO L121 FreeRefinementEngine]: Executing refinement strategy CAMEL [2021-12-16 00:59:13,628 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [1356508581] [2021-12-16 00:59:13,628 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2021-12-16 00:59:13,629 INFO L126 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2021-12-16 00:59:13,746 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 00:59:13,797 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 15 [2021-12-16 00:59:13,799 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 00:59:13,802 INFO L134 CoverageAnalysis]: Checked inductivity of 0 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2021-12-16 00:59:13,802 INFO L139 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2021-12-16 00:59:13,803 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [1356508581] [2021-12-16 00:59:13,803 INFO L160 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [1356508581] provided 1 perfect and 0 imperfect interpolant sequences [2021-12-16 00:59:13,803 INFO L186 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2021-12-16 00:59:13,804 INFO L199 FreeRefinementEngine]: Number of different interpolants: perfect sequences [2] imperfect sequences [] total 2 [2021-12-16 00:59:13,805 INFO L115 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [235010524] [2021-12-16 00:59:13,805 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2021-12-16 00:59:13,808 INFO L546 AbstractCegarLoop]: INTERPOLANT automaton has 2 states [2021-12-16 00:59:13,808 INFO L103 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2021-12-16 00:59:13,824 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 2 interpolants. [2021-12-16 00:59:13,825 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=1, Invalid=1, Unknown=0, NotChecked=0, Total=2 [2021-12-16 00:59:13,827 INFO L87 Difference]: Start difference. First operand has 88 states, 68 states have (on average 1.3970588235294117) internal successors, (95), 76 states have internal predecessors, (95), 11 states have call successors, (11), 7 states have call predecessors, (11), 7 states have return successors, (11), 9 states have call predecessors, (11), 11 states have call successors, (11) Second operand has 2 states, 2 states have (on average 10.5) internal successors, (21), 2 states have internal predecessors, (21), 1 states have call successors, (3), 2 states have call predecessors, (3), 1 states have return successors, (1), 1 states have call predecessors, (1), 1 states have call successors, (1) [2021-12-16 00:59:13,863 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2021-12-16 00:59:13,863 INFO L93 Difference]: Finished difference Result 167 states and 228 transitions. [2021-12-16 00:59:13,865 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 2 states. [2021-12-16 00:59:13,866 INFO L78 Accepts]: Start accepts. Automaton has has 2 states, 2 states have (on average 10.5) internal successors, (21), 2 states have internal predecessors, (21), 1 states have call successors, (3), 2 states have call predecessors, (3), 1 states have return successors, (1), 1 states have call predecessors, (1), 1 states have call successors, (1) Word has length 25 [2021-12-16 00:59:13,867 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2021-12-16 00:59:13,872 INFO L225 Difference]: With dead ends: 167 [2021-12-16 00:59:13,872 INFO L226 Difference]: Without dead ends: 79 [2021-12-16 00:59:13,875 INFO L932 BasicCegarLoop]: 0 DeclaredPredicates, 4 GetRequests, 4 SyntacticMatches, 0 SemanticMatches, 0 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 0 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=1, Invalid=1, Unknown=0, NotChecked=0, Total=2 [2021-12-16 00:59:13,877 INFO L933 BasicCegarLoop]: 111 mSDtfsCounter, 0 mSDsluCounter, 0 mSDsCounter, 0 mSdLazyCounter, 0 mSolverCounterSat, 0 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.0s Time, 0 mProtectedPredicate, 0 mProtectedAction, 0 SdHoareTripleChecker+Valid, 111 SdHoareTripleChecker+Invalid, 0 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 0 IncrementalHoareTripleChecker+Valid, 0 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.0s IncrementalHoareTripleChecker+Time [2021-12-16 00:59:13,878 INFO L934 BasicCegarLoop]: SdHoareTripleChecker [0 Valid, 111 Invalid, 0 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [0 Valid, 0 Invalid, 0 Unknown, 0 Unchecked, 0.0s Time] [2021-12-16 00:59:13,888 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 79 states. [2021-12-16 00:59:13,902 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 79 to 79. [2021-12-16 00:59:13,903 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 79 states, 61 states have (on average 1.3278688524590163) internal successors, (81), 68 states have internal predecessors, (81), 11 states have call successors, (11), 7 states have call predecessors, (11), 6 states have return successors, (10), 8 states have call predecessors, (10), 10 states have call successors, (10) [2021-12-16 00:59:13,905 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 79 states to 79 states and 102 transitions. [2021-12-16 00:59:13,906 INFO L78 Accepts]: Start accepts. Automaton has 79 states and 102 transitions. Word has length 25 [2021-12-16 00:59:13,906 INFO L84 Accepts]: Finished accepts. word is rejected. [2021-12-16 00:59:13,906 INFO L470 AbstractCegarLoop]: Abstraction has 79 states and 102 transitions. [2021-12-16 00:59:13,906 INFO L471 AbstractCegarLoop]: INTERPOLANT automaton has has 2 states, 2 states have (on average 10.5) internal successors, (21), 2 states have internal predecessors, (21), 1 states have call successors, (3), 2 states have call predecessors, (3), 1 states have return successors, (1), 1 states have call predecessors, (1), 1 states have call successors, (1) [2021-12-16 00:59:13,906 INFO L276 IsEmpty]: Start isEmpty. Operand 79 states and 102 transitions. [2021-12-16 00:59:13,908 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 27 [2021-12-16 00:59:13,908 INFO L506 BasicCegarLoop]: Found error trace [2021-12-16 00:59:13,908 INFO L514 BasicCegarLoop]: trace histogram [1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2021-12-16 00:59:13,908 WARN L452 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable0 [2021-12-16 00:59:13,909 INFO L402 AbstractCegarLoop]: === Iteration 2 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2021-12-16 00:59:13,909 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2021-12-16 00:59:13,909 INFO L85 PathProgramCache]: Analyzing trace with hash -941221246, now seen corresponding path program 1 times [2021-12-16 00:59:13,910 INFO L121 FreeRefinementEngine]: Executing refinement strategy CAMEL [2021-12-16 00:59:13,910 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [70419305] [2021-12-16 00:59:13,910 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2021-12-16 00:59:13,910 INFO L126 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2021-12-16 00:59:13,925 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 00:59:13,951 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 16 [2021-12-16 00:59:13,954 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 00:59:13,969 INFO L134 CoverageAnalysis]: Checked inductivity of 0 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2021-12-16 00:59:13,969 INFO L139 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2021-12-16 00:59:13,969 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [70419305] [2021-12-16 00:59:13,969 INFO L160 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [70419305] provided 1 perfect and 0 imperfect interpolant sequences [2021-12-16 00:59:13,969 INFO L186 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2021-12-16 00:59:13,970 INFO L199 FreeRefinementEngine]: Number of different interpolants: perfect sequences [3] imperfect sequences [] total 3 [2021-12-16 00:59:13,970 INFO L115 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [1183303599] [2021-12-16 00:59:13,970 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2021-12-16 00:59:13,971 INFO L546 AbstractCegarLoop]: INTERPOLANT automaton has 3 states [2021-12-16 00:59:13,971 INFO L103 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2021-12-16 00:59:13,972 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 3 interpolants. [2021-12-16 00:59:13,972 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=3, Invalid=3, Unknown=0, NotChecked=0, Total=6 [2021-12-16 00:59:13,972 INFO L87 Difference]: Start difference. First operand 79 states and 102 transitions. Second operand has 3 states, 3 states have (on average 7.333333333333333) internal successors, (22), 3 states have internal predecessors, (22), 1 states have call successors, (3), 2 states have call predecessors, (3), 1 states have return successors, (1), 1 states have call predecessors, (1), 1 states have call successors, (1) [2021-12-16 00:59:13,994 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2021-12-16 00:59:13,994 INFO L93 Difference]: Finished difference Result 123 states and 159 transitions. [2021-12-16 00:59:13,997 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 3 states. [2021-12-16 00:59:13,997 INFO L78 Accepts]: Start accepts. Automaton has has 3 states, 3 states have (on average 7.333333333333333) internal successors, (22), 3 states have internal predecessors, (22), 1 states have call successors, (3), 2 states have call predecessors, (3), 1 states have return successors, (1), 1 states have call predecessors, (1), 1 states have call successors, (1) Word has length 26 [2021-12-16 00:59:13,999 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2021-12-16 00:59:14,000 INFO L225 Difference]: With dead ends: 123 [2021-12-16 00:59:14,001 INFO L226 Difference]: Without dead ends: 70 [2021-12-16 00:59:14,001 INFO L932 BasicCegarLoop]: 0 DeclaredPredicates, 5 GetRequests, 4 SyntacticMatches, 0 SemanticMatches, 1 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 0 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=3, Invalid=3, Unknown=0, NotChecked=0, Total=6 [2021-12-16 00:59:14,002 INFO L933 BasicCegarLoop]: 89 mSDtfsCounter, 12 mSDsluCounter, 73 mSDsCounter, 0 mSdLazyCounter, 1 mSolverCounterSat, 0 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.0s Time, 0 mProtectedPredicate, 0 mProtectedAction, 15 SdHoareTripleChecker+Valid, 162 SdHoareTripleChecker+Invalid, 1 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 0 IncrementalHoareTripleChecker+Valid, 1 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.0s IncrementalHoareTripleChecker+Time [2021-12-16 00:59:14,003 INFO L934 BasicCegarLoop]: SdHoareTripleChecker [15 Valid, 162 Invalid, 1 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [0 Valid, 1 Invalid, 0 Unknown, 0 Unchecked, 0.0s Time] [2021-12-16 00:59:14,003 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 70 states. [2021-12-16 00:59:14,008 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 70 to 70. [2021-12-16 00:59:14,009 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 70 states, 55 states have (on average 1.3454545454545455) internal successors, (74), 62 states have internal predecessors, (74), 8 states have call successors, (8), 6 states have call predecessors, (8), 6 states have return successors, (8), 6 states have call predecessors, (8), 8 states have call successors, (8) [2021-12-16 00:59:14,010 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 70 states to 70 states and 90 transitions. [2021-12-16 00:59:14,011 INFO L78 Accepts]: Start accepts. Automaton has 70 states and 90 transitions. Word has length 26 [2021-12-16 00:59:14,011 INFO L84 Accepts]: Finished accepts. word is rejected. [2021-12-16 00:59:14,011 INFO L470 AbstractCegarLoop]: Abstraction has 70 states and 90 transitions. [2021-12-16 00:59:14,012 INFO L471 AbstractCegarLoop]: INTERPOLANT automaton has has 3 states, 3 states have (on average 7.333333333333333) internal successors, (22), 3 states have internal predecessors, (22), 1 states have call successors, (3), 2 states have call predecessors, (3), 1 states have return successors, (1), 1 states have call predecessors, (1), 1 states have call successors, (1) [2021-12-16 00:59:14,012 INFO L276 IsEmpty]: Start isEmpty. Operand 70 states and 90 transitions. [2021-12-16 00:59:14,013 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 31 [2021-12-16 00:59:14,014 INFO L506 BasicCegarLoop]: Found error trace [2021-12-16 00:59:14,014 INFO L514 BasicCegarLoop]: trace histogram [1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2021-12-16 00:59:14,014 WARN L452 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable1 [2021-12-16 00:59:14,014 INFO L402 AbstractCegarLoop]: === Iteration 3 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2021-12-16 00:59:14,015 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2021-12-16 00:59:14,015 INFO L85 PathProgramCache]: Analyzing trace with hash -913943674, now seen corresponding path program 1 times [2021-12-16 00:59:14,015 INFO L121 FreeRefinementEngine]: Executing refinement strategy CAMEL [2021-12-16 00:59:14,015 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [1678959814] [2021-12-16 00:59:14,016 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2021-12-16 00:59:14,016 INFO L126 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2021-12-16 00:59:14,037 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 00:59:14,084 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 20 [2021-12-16 00:59:14,085 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 00:59:14,088 INFO L134 CoverageAnalysis]: Checked inductivity of 0 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2021-12-16 00:59:14,088 INFO L139 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2021-12-16 00:59:14,088 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [1678959814] [2021-12-16 00:59:14,089 INFO L160 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [1678959814] provided 1 perfect and 0 imperfect interpolant sequences [2021-12-16 00:59:14,089 INFO L186 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2021-12-16 00:59:14,089 INFO L199 FreeRefinementEngine]: Number of different interpolants: perfect sequences [6] imperfect sequences [] total 6 [2021-12-16 00:59:14,089 INFO L115 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [183369035] [2021-12-16 00:59:14,089 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2021-12-16 00:59:14,090 INFO L546 AbstractCegarLoop]: INTERPOLANT automaton has 6 states [2021-12-16 00:59:14,090 INFO L103 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2021-12-16 00:59:14,090 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 6 interpolants. [2021-12-16 00:59:14,091 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=10, Invalid=20, Unknown=0, NotChecked=0, Total=30 [2021-12-16 00:59:14,091 INFO L87 Difference]: Start difference. First operand 70 states and 90 transitions. Second operand has 6 states, 6 states have (on average 4.5) internal successors, (27), 6 states have internal predecessors, (27), 2 states have call successors, (2), 2 states have call predecessors, (2), 1 states have return successors, (1), 1 states have call predecessors, (1), 1 states have call successors, (1) [2021-12-16 00:59:14,154 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2021-12-16 00:59:14,155 INFO L93 Difference]: Finished difference Result 132 states and 173 transitions. [2021-12-16 00:59:14,155 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 5 states. [2021-12-16 00:59:14,155 INFO L78 Accepts]: Start accepts. Automaton has has 6 states, 6 states have (on average 4.5) internal successors, (27), 6 states have internal predecessors, (27), 2 states have call successors, (2), 2 states have call predecessors, (2), 1 states have return successors, (1), 1 states have call predecessors, (1), 1 states have call successors, (1) Word has length 30 [2021-12-16 00:59:14,156 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2021-12-16 00:59:14,156 INFO L225 Difference]: With dead ends: 132 [2021-12-16 00:59:14,156 INFO L226 Difference]: Without dead ends: 70 [2021-12-16 00:59:14,157 INFO L932 BasicCegarLoop]: 0 DeclaredPredicates, 9 GetRequests, 3 SyntacticMatches, 0 SemanticMatches, 6 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 0 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=22, Invalid=34, Unknown=0, NotChecked=0, Total=56 [2021-12-16 00:59:14,158 INFO L933 BasicCegarLoop]: 83 mSDtfsCounter, 176 mSDsluCounter, 106 mSDsCounter, 0 mSdLazyCounter, 37 mSolverCounterSat, 25 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.0s Time, 0 mProtectedPredicate, 0 mProtectedAction, 176 SdHoareTripleChecker+Valid, 189 SdHoareTripleChecker+Invalid, 62 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 25 IncrementalHoareTripleChecker+Valid, 37 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.0s IncrementalHoareTripleChecker+Time [2021-12-16 00:59:14,158 INFO L934 BasicCegarLoop]: SdHoareTripleChecker [176 Valid, 189 Invalid, 62 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [25 Valid, 37 Invalid, 0 Unknown, 0 Unchecked, 0.0s Time] [2021-12-16 00:59:14,159 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 70 states. [2021-12-16 00:59:14,164 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 70 to 70. [2021-12-16 00:59:14,164 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 70 states, 55 states have (on average 1.3272727272727274) internal successors, (73), 62 states have internal predecessors, (73), 8 states have call successors, (8), 6 states have call predecessors, (8), 6 states have return successors, (8), 6 states have call predecessors, (8), 8 states have call successors, (8) [2021-12-16 00:59:14,165 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 70 states to 70 states and 89 transitions. [2021-12-16 00:59:14,165 INFO L78 Accepts]: Start accepts. Automaton has 70 states and 89 transitions. Word has length 30 [2021-12-16 00:59:14,165 INFO L84 Accepts]: Finished accepts. word is rejected. [2021-12-16 00:59:14,165 INFO L470 AbstractCegarLoop]: Abstraction has 70 states and 89 transitions. [2021-12-16 00:59:14,165 INFO L471 AbstractCegarLoop]: INTERPOLANT automaton has has 6 states, 6 states have (on average 4.5) internal successors, (27), 6 states have internal predecessors, (27), 2 states have call successors, (2), 2 states have call predecessors, (2), 1 states have return successors, (1), 1 states have call predecessors, (1), 1 states have call successors, (1) [2021-12-16 00:59:14,166 INFO L276 IsEmpty]: Start isEmpty. Operand 70 states and 89 transitions. [2021-12-16 00:59:14,166 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 41 [2021-12-16 00:59:14,166 INFO L506 BasicCegarLoop]: Found error trace [2021-12-16 00:59:14,167 INFO L514 BasicCegarLoop]: trace histogram [1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2021-12-16 00:59:14,167 WARN L452 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable2 [2021-12-16 00:59:14,167 INFO L402 AbstractCegarLoop]: === Iteration 4 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2021-12-16 00:59:14,167 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2021-12-16 00:59:14,168 INFO L85 PathProgramCache]: Analyzing trace with hash 1798308510, now seen corresponding path program 1 times [2021-12-16 00:59:14,168 INFO L121 FreeRefinementEngine]: Executing refinement strategy CAMEL [2021-12-16 00:59:14,168 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [2067426006] [2021-12-16 00:59:14,168 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2021-12-16 00:59:14,168 INFO L126 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2021-12-16 00:59:14,180 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 00:59:14,209 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 20 [2021-12-16 00:59:14,211 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 00:59:14,221 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 2 [2021-12-16 00:59:14,223 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 00:59:14,225 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 30 [2021-12-16 00:59:14,226 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 00:59:14,228 INFO L134 CoverageAnalysis]: Checked inductivity of 0 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2021-12-16 00:59:14,228 INFO L139 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2021-12-16 00:59:14,228 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [2067426006] [2021-12-16 00:59:14,229 INFO L160 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [2067426006] provided 1 perfect and 0 imperfect interpolant sequences [2021-12-16 00:59:14,229 INFO L186 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2021-12-16 00:59:14,229 INFO L199 FreeRefinementEngine]: Number of different interpolants: perfect sequences [5] imperfect sequences [] total 5 [2021-12-16 00:59:14,229 INFO L115 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [836755210] [2021-12-16 00:59:14,229 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2021-12-16 00:59:14,230 INFO L546 AbstractCegarLoop]: INTERPOLANT automaton has 5 states [2021-12-16 00:59:14,230 INFO L103 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2021-12-16 00:59:14,230 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 5 interpolants. [2021-12-16 00:59:14,230 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=7, Invalid=13, Unknown=0, NotChecked=0, Total=20 [2021-12-16 00:59:14,230 INFO L87 Difference]: Start difference. First operand 70 states and 89 transitions. Second operand has 5 states, 5 states have (on average 6.6) internal successors, (33), 5 states have internal predecessors, (33), 3 states have call successors, (4), 3 states have call predecessors, (4), 2 states have return successors, (3), 2 states have call predecessors, (3), 3 states have call successors, (3) [2021-12-16 00:59:14,353 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2021-12-16 00:59:14,354 INFO L93 Difference]: Finished difference Result 206 states and 264 transitions. [2021-12-16 00:59:14,354 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 7 states. [2021-12-16 00:59:14,354 INFO L78 Accepts]: Start accepts. Automaton has has 5 states, 5 states have (on average 6.6) internal successors, (33), 5 states have internal predecessors, (33), 3 states have call successors, (4), 3 states have call predecessors, (4), 2 states have return successors, (3), 2 states have call predecessors, (3), 3 states have call successors, (3) Word has length 40 [2021-12-16 00:59:14,355 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2021-12-16 00:59:14,356 INFO L225 Difference]: With dead ends: 206 [2021-12-16 00:59:14,356 INFO L226 Difference]: Without dead ends: 144 [2021-12-16 00:59:14,356 INFO L932 BasicCegarLoop]: 0 DeclaredPredicates, 15 GetRequests, 8 SyntacticMatches, 1 SemanticMatches, 6 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 3 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=19, Invalid=37, Unknown=0, NotChecked=0, Total=56 [2021-12-16 00:59:14,358 INFO L933 BasicCegarLoop]: 131 mSDtfsCounter, 167 mSDsluCounter, 172 mSDsCounter, 0 mSdLazyCounter, 92 mSolverCounterSat, 41 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.1s Time, 0 mProtectedPredicate, 0 mProtectedAction, 169 SdHoareTripleChecker+Valid, 303 SdHoareTripleChecker+Invalid, 133 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 41 IncrementalHoareTripleChecker+Valid, 92 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.1s IncrementalHoareTripleChecker+Time [2021-12-16 00:59:14,358 INFO L934 BasicCegarLoop]: SdHoareTripleChecker [169 Valid, 303 Invalid, 133 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [41 Valid, 92 Invalid, 0 Unknown, 0 Unchecked, 0.1s Time] [2021-12-16 00:59:14,359 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 144 states. [2021-12-16 00:59:14,375 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 144 to 138. [2021-12-16 00:59:14,375 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 138 states, 107 states have (on average 1.2897196261682242) internal successors, (138), 114 states have internal predecessors, (138), 14 states have call successors, (14), 13 states have call predecessors, (14), 16 states have return successors, (19), 15 states have call predecessors, (19), 14 states have call successors, (19) [2021-12-16 00:59:14,376 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 138 states to 138 states and 171 transitions. [2021-12-16 00:59:14,376 INFO L78 Accepts]: Start accepts. Automaton has 138 states and 171 transitions. Word has length 40 [2021-12-16 00:59:14,376 INFO L84 Accepts]: Finished accepts. word is rejected. [2021-12-16 00:59:14,377 INFO L470 AbstractCegarLoop]: Abstraction has 138 states and 171 transitions. [2021-12-16 00:59:14,377 INFO L471 AbstractCegarLoop]: INTERPOLANT automaton has has 5 states, 5 states have (on average 6.6) internal successors, (33), 5 states have internal predecessors, (33), 3 states have call successors, (4), 3 states have call predecessors, (4), 2 states have return successors, (3), 2 states have call predecessors, (3), 3 states have call successors, (3) [2021-12-16 00:59:14,377 INFO L276 IsEmpty]: Start isEmpty. Operand 138 states and 171 transitions. [2021-12-16 00:59:14,378 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 45 [2021-12-16 00:59:14,378 INFO L506 BasicCegarLoop]: Found error trace [2021-12-16 00:59:14,378 INFO L514 BasicCegarLoop]: trace histogram [1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2021-12-16 00:59:14,378 WARN L452 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable3 [2021-12-16 00:59:14,378 INFO L402 AbstractCegarLoop]: === Iteration 5 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2021-12-16 00:59:14,379 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2021-12-16 00:59:14,379 INFO L85 PathProgramCache]: Analyzing trace with hash 1579167755, now seen corresponding path program 1 times [2021-12-16 00:59:14,379 INFO L121 FreeRefinementEngine]: Executing refinement strategy CAMEL [2021-12-16 00:59:14,379 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [604066406] [2021-12-16 00:59:14,380 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2021-12-16 00:59:14,380 INFO L126 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2021-12-16 00:59:14,395 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 00:59:14,440 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 20 [2021-12-16 00:59:14,446 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 00:59:14,472 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 34 [2021-12-16 00:59:14,474 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 00:59:14,477 INFO L134 CoverageAnalysis]: Checked inductivity of 0 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2021-12-16 00:59:14,477 INFO L139 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2021-12-16 00:59:14,477 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [604066406] [2021-12-16 00:59:14,477 INFO L160 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [604066406] provided 1 perfect and 0 imperfect interpolant sequences [2021-12-16 00:59:14,477 INFO L186 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2021-12-16 00:59:14,477 INFO L199 FreeRefinementEngine]: Number of different interpolants: perfect sequences [6] imperfect sequences [] total 6 [2021-12-16 00:59:14,477 INFO L115 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [987946782] [2021-12-16 00:59:14,478 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2021-12-16 00:59:14,478 INFO L546 AbstractCegarLoop]: INTERPOLANT automaton has 6 states [2021-12-16 00:59:14,478 INFO L103 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2021-12-16 00:59:14,478 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 6 interpolants. [2021-12-16 00:59:14,478 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=9, Invalid=21, Unknown=0, NotChecked=0, Total=30 [2021-12-16 00:59:14,479 INFO L87 Difference]: Start difference. First operand 138 states and 171 transitions. Second operand has 6 states, 6 states have (on average 6.5) internal successors, (39), 5 states have internal predecessors, (39), 2 states have call successors, (3), 2 states have call predecessors, (3), 2 states have return successors, (2), 1 states have call predecessors, (2), 2 states have call successors, (2) [2021-12-16 00:59:14,629 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2021-12-16 00:59:14,629 INFO L93 Difference]: Finished difference Result 276 states and 346 transitions. [2021-12-16 00:59:14,632 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 7 states. [2021-12-16 00:59:14,632 INFO L78 Accepts]: Start accepts. Automaton has has 6 states, 6 states have (on average 6.5) internal successors, (39), 5 states have internal predecessors, (39), 2 states have call successors, (3), 2 states have call predecessors, (3), 2 states have return successors, (2), 1 states have call predecessors, (2), 2 states have call successors, (2) Word has length 44 [2021-12-16 00:59:14,633 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2021-12-16 00:59:14,634 INFO L225 Difference]: With dead ends: 276 [2021-12-16 00:59:14,634 INFO L226 Difference]: Without dead ends: 146 [2021-12-16 00:59:14,635 INFO L932 BasicCegarLoop]: 0 DeclaredPredicates, 14 GetRequests, 6 SyntacticMatches, 0 SemanticMatches, 8 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 3 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=32, Invalid=58, Unknown=0, NotChecked=0, Total=90 [2021-12-16 00:59:14,635 INFO L933 BasicCegarLoop]: 92 mSDtfsCounter, 63 mSDsluCounter, 284 mSDsCounter, 0 mSdLazyCounter, 95 mSolverCounterSat, 18 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.1s Time, 0 mProtectedPredicate, 0 mProtectedAction, 65 SdHoareTripleChecker+Valid, 376 SdHoareTripleChecker+Invalid, 113 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 18 IncrementalHoareTripleChecker+Valid, 95 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.1s IncrementalHoareTripleChecker+Time [2021-12-16 00:59:14,636 INFO L934 BasicCegarLoop]: SdHoareTripleChecker [65 Valid, 376 Invalid, 113 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [18 Valid, 95 Invalid, 0 Unknown, 0 Unchecked, 0.1s Time] [2021-12-16 00:59:14,636 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 146 states. [2021-12-16 00:59:14,646 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 146 to 141. [2021-12-16 00:59:14,649 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 141 states, 110 states have (on average 1.2818181818181817) internal successors, (141), 117 states have internal predecessors, (141), 14 states have call successors, (14), 13 states have call predecessors, (14), 16 states have return successors, (19), 15 states have call predecessors, (19), 14 states have call successors, (19) [2021-12-16 00:59:14,650 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 141 states to 141 states and 174 transitions. [2021-12-16 00:59:14,650 INFO L78 Accepts]: Start accepts. Automaton has 141 states and 174 transitions. Word has length 44 [2021-12-16 00:59:14,650 INFO L84 Accepts]: Finished accepts. word is rejected. [2021-12-16 00:59:14,650 INFO L470 AbstractCegarLoop]: Abstraction has 141 states and 174 transitions. [2021-12-16 00:59:14,650 INFO L471 AbstractCegarLoop]: INTERPOLANT automaton has has 6 states, 6 states have (on average 6.5) internal successors, (39), 5 states have internal predecessors, (39), 2 states have call successors, (3), 2 states have call predecessors, (3), 2 states have return successors, (2), 1 states have call predecessors, (2), 2 states have call successors, (2) [2021-12-16 00:59:14,651 INFO L276 IsEmpty]: Start isEmpty. Operand 141 states and 174 transitions. [2021-12-16 00:59:14,651 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 45 [2021-12-16 00:59:14,652 INFO L506 BasicCegarLoop]: Found error trace [2021-12-16 00:59:14,652 INFO L514 BasicCegarLoop]: trace histogram [1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2021-12-16 00:59:14,652 WARN L452 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable4 [2021-12-16 00:59:14,652 INFO L402 AbstractCegarLoop]: === Iteration 6 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2021-12-16 00:59:14,653 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2021-12-16 00:59:14,653 INFO L85 PathProgramCache]: Analyzing trace with hash -109775987, now seen corresponding path program 1 times [2021-12-16 00:59:14,653 INFO L121 FreeRefinementEngine]: Executing refinement strategy CAMEL [2021-12-16 00:59:14,653 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [1112340571] [2021-12-16 00:59:14,653 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2021-12-16 00:59:14,653 INFO L126 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2021-12-16 00:59:14,663 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 00:59:14,711 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 20 [2021-12-16 00:59:14,714 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 00:59:14,741 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 34 [2021-12-16 00:59:14,742 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 00:59:14,751 INFO L134 CoverageAnalysis]: Checked inductivity of 0 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2021-12-16 00:59:14,752 INFO L139 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2021-12-16 00:59:14,752 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [1112340571] [2021-12-16 00:59:14,752 INFO L160 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [1112340571] provided 1 perfect and 0 imperfect interpolant sequences [2021-12-16 00:59:14,752 INFO L186 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2021-12-16 00:59:14,753 INFO L199 FreeRefinementEngine]: Number of different interpolants: perfect sequences [7] imperfect sequences [] total 7 [2021-12-16 00:59:14,753 INFO L115 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [602204347] [2021-12-16 00:59:14,753 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2021-12-16 00:59:14,753 INFO L546 AbstractCegarLoop]: INTERPOLANT automaton has 7 states [2021-12-16 00:59:14,754 INFO L103 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2021-12-16 00:59:14,754 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 7 interpolants. [2021-12-16 00:59:14,755 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=11, Invalid=31, Unknown=0, NotChecked=0, Total=42 [2021-12-16 00:59:14,755 INFO L87 Difference]: Start difference. First operand 141 states and 174 transitions. Second operand has 7 states, 7 states have (on average 5.571428571428571) internal successors, (39), 6 states have internal predecessors, (39), 2 states have call successors, (3), 2 states have call predecessors, (3), 2 states have return successors, (2), 1 states have call predecessors, (2), 2 states have call successors, (2) [2021-12-16 00:59:14,879 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2021-12-16 00:59:14,880 INFO L93 Difference]: Finished difference Result 287 states and 361 transitions. [2021-12-16 00:59:14,880 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 8 states. [2021-12-16 00:59:14,880 INFO L78 Accepts]: Start accepts. Automaton has has 7 states, 7 states have (on average 5.571428571428571) internal successors, (39), 6 states have internal predecessors, (39), 2 states have call successors, (3), 2 states have call predecessors, (3), 2 states have return successors, (2), 1 states have call predecessors, (2), 2 states have call successors, (2) Word has length 44 [2021-12-16 00:59:14,881 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2021-12-16 00:59:14,885 INFO L225 Difference]: With dead ends: 287 [2021-12-16 00:59:14,886 INFO L226 Difference]: Without dead ends: 154 [2021-12-16 00:59:14,889 INFO L932 BasicCegarLoop]: 0 DeclaredPredicates, 17 GetRequests, 8 SyntacticMatches, 0 SemanticMatches, 9 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 5 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=30, Invalid=80, Unknown=0, NotChecked=0, Total=110 [2021-12-16 00:59:14,894 INFO L933 BasicCegarLoop]: 91 mSDtfsCounter, 106 mSDsluCounter, 320 mSDsCounter, 0 mSdLazyCounter, 131 mSolverCounterSat, 25 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.1s Time, 0 mProtectedPredicate, 0 mProtectedAction, 109 SdHoareTripleChecker+Valid, 411 SdHoareTripleChecker+Invalid, 156 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 25 IncrementalHoareTripleChecker+Valid, 131 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.1s IncrementalHoareTripleChecker+Time [2021-12-16 00:59:14,896 INFO L934 BasicCegarLoop]: SdHoareTripleChecker [109 Valid, 411 Invalid, 156 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [25 Valid, 131 Invalid, 0 Unknown, 0 Unchecked, 0.1s Time] [2021-12-16 00:59:14,899 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 154 states. [2021-12-16 00:59:14,910 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 154 to 143. [2021-12-16 00:59:14,917 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 143 states, 112 states have (on average 1.2767857142857142) internal successors, (143), 119 states have internal predecessors, (143), 14 states have call successors, (14), 13 states have call predecessors, (14), 16 states have return successors, (19), 15 states have call predecessors, (19), 14 states have call successors, (19) [2021-12-16 00:59:14,918 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 143 states to 143 states and 176 transitions. [2021-12-16 00:59:14,919 INFO L78 Accepts]: Start accepts. Automaton has 143 states and 176 transitions. Word has length 44 [2021-12-16 00:59:14,920 INFO L84 Accepts]: Finished accepts. word is rejected. [2021-12-16 00:59:14,920 INFO L470 AbstractCegarLoop]: Abstraction has 143 states and 176 transitions. [2021-12-16 00:59:14,921 INFO L471 AbstractCegarLoop]: INTERPOLANT automaton has has 7 states, 7 states have (on average 5.571428571428571) internal successors, (39), 6 states have internal predecessors, (39), 2 states have call successors, (3), 2 states have call predecessors, (3), 2 states have return successors, (2), 1 states have call predecessors, (2), 2 states have call successors, (2) [2021-12-16 00:59:14,921 INFO L276 IsEmpty]: Start isEmpty. Operand 143 states and 176 transitions. [2021-12-16 00:59:14,922 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 45 [2021-12-16 00:59:14,923 INFO L506 BasicCegarLoop]: Found error trace [2021-12-16 00:59:14,923 INFO L514 BasicCegarLoop]: trace histogram [1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2021-12-16 00:59:14,924 WARN L452 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable5 [2021-12-16 00:59:14,924 INFO L402 AbstractCegarLoop]: === Iteration 7 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2021-12-16 00:59:14,924 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2021-12-16 00:59:14,924 INFO L85 PathProgramCache]: Analyzing trace with hash 312925839, now seen corresponding path program 1 times [2021-12-16 00:59:14,925 INFO L121 FreeRefinementEngine]: Executing refinement strategy CAMEL [2021-12-16 00:59:14,925 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [1745395372] [2021-12-16 00:59:14,925 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2021-12-16 00:59:14,925 INFO L126 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2021-12-16 00:59:14,934 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 00:59:14,974 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 20 [2021-12-16 00:59:14,977 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 00:59:14,988 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 34 [2021-12-16 00:59:14,992 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 00:59:14,996 INFO L134 CoverageAnalysis]: Checked inductivity of 0 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2021-12-16 00:59:14,997 INFO L139 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2021-12-16 00:59:14,997 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [1745395372] [2021-12-16 00:59:14,997 INFO L160 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [1745395372] provided 1 perfect and 0 imperfect interpolant sequences [2021-12-16 00:59:14,997 INFO L186 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2021-12-16 00:59:14,998 INFO L199 FreeRefinementEngine]: Number of different interpolants: perfect sequences [5] imperfect sequences [] total 5 [2021-12-16 00:59:14,998 INFO L115 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [526636263] [2021-12-16 00:59:14,998 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2021-12-16 00:59:14,998 INFO L546 AbstractCegarLoop]: INTERPOLANT automaton has 5 states [2021-12-16 00:59:14,999 INFO L103 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2021-12-16 00:59:14,999 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 5 interpolants. [2021-12-16 00:59:14,999 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=7, Invalid=13, Unknown=0, NotChecked=0, Total=20 [2021-12-16 00:59:15,000 INFO L87 Difference]: Start difference. First operand 143 states and 176 transitions. Second operand has 5 states, 5 states have (on average 7.8) internal successors, (39), 4 states have internal predecessors, (39), 2 states have call successors, (3), 3 states have call predecessors, (3), 2 states have return successors, (2), 1 states have call predecessors, (2), 2 states have call successors, (2) [2021-12-16 00:59:15,136 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2021-12-16 00:59:15,137 INFO L93 Difference]: Finished difference Result 400 states and 514 transitions. [2021-12-16 00:59:15,137 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 7 states. [2021-12-16 00:59:15,137 INFO L78 Accepts]: Start accepts. Automaton has has 5 states, 5 states have (on average 7.8) internal successors, (39), 4 states have internal predecessors, (39), 2 states have call successors, (3), 3 states have call predecessors, (3), 2 states have return successors, (2), 1 states have call predecessors, (2), 2 states have call successors, (2) Word has length 44 [2021-12-16 00:59:15,138 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2021-12-16 00:59:15,140 INFO L225 Difference]: With dead ends: 400 [2021-12-16 00:59:15,140 INFO L226 Difference]: Without dead ends: 265 [2021-12-16 00:59:15,141 INFO L932 BasicCegarLoop]: 0 DeclaredPredicates, 12 GetRequests, 7 SyntacticMatches, 0 SemanticMatches, 5 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 1 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=15, Invalid=27, Unknown=0, NotChecked=0, Total=42 [2021-12-16 00:59:15,143 INFO L933 BasicCegarLoop]: 143 mSDtfsCounter, 198 mSDsluCounter, 171 mSDsCounter, 0 mSdLazyCounter, 128 mSolverCounterSat, 52 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.1s Time, 0 mProtectedPredicate, 0 mProtectedAction, 204 SdHoareTripleChecker+Valid, 314 SdHoareTripleChecker+Invalid, 180 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 52 IncrementalHoareTripleChecker+Valid, 128 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.1s IncrementalHoareTripleChecker+Time [2021-12-16 00:59:15,143 INFO L934 BasicCegarLoop]: SdHoareTripleChecker [204 Valid, 314 Invalid, 180 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [52 Valid, 128 Invalid, 0 Unknown, 0 Unchecked, 0.1s Time] [2021-12-16 00:59:15,145 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 265 states. [2021-12-16 00:59:15,177 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 265 to 257. [2021-12-16 00:59:15,177 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 257 states, 198 states have (on average 1.2676767676767677) internal successors, (251), 209 states have internal predecessors, (251), 29 states have call successors, (29), 28 states have call predecessors, (29), 29 states have return successors, (44), 29 states have call predecessors, (44), 29 states have call successors, (44) [2021-12-16 00:59:15,179 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 257 states to 257 states and 324 transitions. [2021-12-16 00:59:15,179 INFO L78 Accepts]: Start accepts. Automaton has 257 states and 324 transitions. Word has length 44 [2021-12-16 00:59:15,179 INFO L84 Accepts]: Finished accepts. word is rejected. [2021-12-16 00:59:15,179 INFO L470 AbstractCegarLoop]: Abstraction has 257 states and 324 transitions. [2021-12-16 00:59:15,179 INFO L471 AbstractCegarLoop]: INTERPOLANT automaton has has 5 states, 5 states have (on average 7.8) internal successors, (39), 4 states have internal predecessors, (39), 2 states have call successors, (3), 3 states have call predecessors, (3), 2 states have return successors, (2), 1 states have call predecessors, (2), 2 states have call successors, (2) [2021-12-16 00:59:15,180 INFO L276 IsEmpty]: Start isEmpty. Operand 257 states and 324 transitions. [2021-12-16 00:59:15,180 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 47 [2021-12-16 00:59:15,180 INFO L506 BasicCegarLoop]: Found error trace [2021-12-16 00:59:15,181 INFO L514 BasicCegarLoop]: trace histogram [1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2021-12-16 00:59:15,181 WARN L452 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable6 [2021-12-16 00:59:15,181 INFO L402 AbstractCegarLoop]: === Iteration 8 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2021-12-16 00:59:15,181 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2021-12-16 00:59:15,181 INFO L85 PathProgramCache]: Analyzing trace with hash 299238822, now seen corresponding path program 1 times [2021-12-16 00:59:15,181 INFO L121 FreeRefinementEngine]: Executing refinement strategy CAMEL [2021-12-16 00:59:15,182 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [1503017938] [2021-12-16 00:59:15,182 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2021-12-16 00:59:15,182 INFO L126 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2021-12-16 00:59:15,190 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 00:59:15,214 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 20 [2021-12-16 00:59:15,216 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 00:59:15,221 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 8 [2021-12-16 00:59:15,221 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 00:59:15,223 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 36 [2021-12-16 00:59:15,224 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 00:59:15,231 INFO L134 CoverageAnalysis]: Checked inductivity of 0 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2021-12-16 00:59:15,232 INFO L139 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2021-12-16 00:59:15,232 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [1503017938] [2021-12-16 00:59:15,232 INFO L160 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [1503017938] provided 1 perfect and 0 imperfect interpolant sequences [2021-12-16 00:59:15,233 INFO L186 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2021-12-16 00:59:15,233 INFO L199 FreeRefinementEngine]: Number of different interpolants: perfect sequences [7] imperfect sequences [] total 7 [2021-12-16 00:59:15,233 INFO L115 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [549857956] [2021-12-16 00:59:15,233 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2021-12-16 00:59:15,233 INFO L546 AbstractCegarLoop]: INTERPOLANT automaton has 7 states [2021-12-16 00:59:15,234 INFO L103 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2021-12-16 00:59:15,235 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 7 interpolants. [2021-12-16 00:59:15,235 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=11, Invalid=31, Unknown=0, NotChecked=0, Total=42 [2021-12-16 00:59:15,235 INFO L87 Difference]: Start difference. First operand 257 states and 324 transitions. Second operand has 7 states, 7 states have (on average 5.571428571428571) internal successors, (39), 5 states have internal predecessors, (39), 2 states have call successors, (4), 3 states have call predecessors, (4), 2 states have return successors, (3), 3 states have call predecessors, (3), 2 states have call successors, (3) [2021-12-16 00:59:15,402 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2021-12-16 00:59:15,402 INFO L93 Difference]: Finished difference Result 755 states and 978 transitions. [2021-12-16 00:59:15,402 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 13 states. [2021-12-16 00:59:15,403 INFO L78 Accepts]: Start accepts. Automaton has has 7 states, 7 states have (on average 5.571428571428571) internal successors, (39), 5 states have internal predecessors, (39), 2 states have call successors, (4), 3 states have call predecessors, (4), 2 states have return successors, (3), 3 states have call predecessors, (3), 2 states have call successors, (3) Word has length 46 [2021-12-16 00:59:15,403 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2021-12-16 00:59:15,406 INFO L225 Difference]: With dead ends: 755 [2021-12-16 00:59:15,406 INFO L226 Difference]: Without dead ends: 506 [2021-12-16 00:59:15,407 INFO L932 BasicCegarLoop]: 0 DeclaredPredicates, 19 GetRequests, 6 SyntacticMatches, 0 SemanticMatches, 13 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 25 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=53, Invalid=157, Unknown=0, NotChecked=0, Total=210 [2021-12-16 00:59:15,407 INFO L933 BasicCegarLoop]: 79 mSDtfsCounter, 146 mSDsluCounter, 289 mSDsCounter, 0 mSdLazyCounter, 158 mSolverCounterSat, 42 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.1s Time, 0 mProtectedPredicate, 0 mProtectedAction, 153 SdHoareTripleChecker+Valid, 368 SdHoareTripleChecker+Invalid, 200 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 42 IncrementalHoareTripleChecker+Valid, 158 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.1s IncrementalHoareTripleChecker+Time [2021-12-16 00:59:15,408 INFO L934 BasicCegarLoop]: SdHoareTripleChecker [153 Valid, 368 Invalid, 200 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [42 Valid, 158 Invalid, 0 Unknown, 0 Unchecked, 0.1s Time] [2021-12-16 00:59:15,408 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 506 states. [2021-12-16 00:59:15,437 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 506 to 486. [2021-12-16 00:59:15,439 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 486 states, 369 states have (on average 1.2249322493224932) internal successors, (452), 390 states have internal predecessors, (452), 58 states have call successors, (58), 56 states have call predecessors, (58), 58 states have return successors, (93), 58 states have call predecessors, (93), 58 states have call successors, (93) [2021-12-16 00:59:15,441 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 486 states to 486 states and 603 transitions. [2021-12-16 00:59:15,441 INFO L78 Accepts]: Start accepts. Automaton has 486 states and 603 transitions. Word has length 46 [2021-12-16 00:59:15,443 INFO L84 Accepts]: Finished accepts. word is rejected. [2021-12-16 00:59:15,443 INFO L470 AbstractCegarLoop]: Abstraction has 486 states and 603 transitions. [2021-12-16 00:59:15,444 INFO L471 AbstractCegarLoop]: INTERPOLANT automaton has has 7 states, 7 states have (on average 5.571428571428571) internal successors, (39), 5 states have internal predecessors, (39), 2 states have call successors, (4), 3 states have call predecessors, (4), 2 states have return successors, (3), 3 states have call predecessors, (3), 2 states have call successors, (3) [2021-12-16 00:59:15,444 INFO L276 IsEmpty]: Start isEmpty. Operand 486 states and 603 transitions. [2021-12-16 00:59:15,447 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 51 [2021-12-16 00:59:15,447 INFO L506 BasicCegarLoop]: Found error trace [2021-12-16 00:59:15,447 INFO L514 BasicCegarLoop]: trace histogram [1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2021-12-16 00:59:15,447 WARN L452 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable7 [2021-12-16 00:59:15,447 INFO L402 AbstractCegarLoop]: === Iteration 9 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2021-12-16 00:59:15,448 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2021-12-16 00:59:15,448 INFO L85 PathProgramCache]: Analyzing trace with hash -658311774, now seen corresponding path program 1 times [2021-12-16 00:59:15,448 INFO L121 FreeRefinementEngine]: Executing refinement strategy CAMEL [2021-12-16 00:59:15,448 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [216135818] [2021-12-16 00:59:15,448 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2021-12-16 00:59:15,448 INFO L126 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2021-12-16 00:59:15,470 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 00:59:15,513 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 14 [2021-12-16 00:59:15,516 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 00:59:15,522 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 24 [2021-12-16 00:59:15,523 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 00:59:15,530 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 8 [2021-12-16 00:59:15,531 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 00:59:15,533 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 40 [2021-12-16 00:59:15,533 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 00:59:15,537 INFO L134 CoverageAnalysis]: Checked inductivity of 0 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2021-12-16 00:59:15,537 INFO L139 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2021-12-16 00:59:15,537 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [216135818] [2021-12-16 00:59:15,538 INFO L160 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [216135818] provided 1 perfect and 0 imperfect interpolant sequences [2021-12-16 00:59:15,538 INFO L186 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2021-12-16 00:59:15,538 INFO L199 FreeRefinementEngine]: Number of different interpolants: perfect sequences [7] imperfect sequences [] total 7 [2021-12-16 00:59:15,538 INFO L115 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [1875436729] [2021-12-16 00:59:15,538 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2021-12-16 00:59:15,539 INFO L546 AbstractCegarLoop]: INTERPOLANT automaton has 7 states [2021-12-16 00:59:15,539 INFO L103 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2021-12-16 00:59:15,539 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 7 interpolants. [2021-12-16 00:59:15,539 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=11, Invalid=31, Unknown=0, NotChecked=0, Total=42 [2021-12-16 00:59:15,540 INFO L87 Difference]: Start difference. First operand 486 states and 603 transitions. Second operand has 7 states, 7 states have (on average 5.857142857142857) internal successors, (41), 5 states have internal predecessors, (41), 1 states have call successors, (5), 4 states have call predecessors, (5), 2 states have return successors, (4), 1 states have call predecessors, (4), 1 states have call successors, (4) [2021-12-16 00:59:15,854 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2021-12-16 00:59:15,854 INFO L93 Difference]: Finished difference Result 980 states and 1227 transitions. [2021-12-16 00:59:15,855 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 15 states. [2021-12-16 00:59:15,855 INFO L78 Accepts]: Start accepts. Automaton has has 7 states, 7 states have (on average 5.857142857142857) internal successors, (41), 5 states have internal predecessors, (41), 1 states have call successors, (5), 4 states have call predecessors, (5), 2 states have return successors, (4), 1 states have call predecessors, (4), 1 states have call successors, (4) Word has length 50 [2021-12-16 00:59:15,856 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2021-12-16 00:59:15,858 INFO L225 Difference]: With dead ends: 980 [2021-12-16 00:59:15,858 INFO L226 Difference]: Without dead ends: 502 [2021-12-16 00:59:15,859 INFO L932 BasicCegarLoop]: 0 DeclaredPredicates, 28 GetRequests, 13 SyntacticMatches, 0 SemanticMatches, 15 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 39 ImplicationChecksByTransitivity, 0.1s TimeCoverageRelationStatistics Valid=84, Invalid=188, Unknown=0, NotChecked=0, Total=272 [2021-12-16 00:59:15,861 INFO L933 BasicCegarLoop]: 84 mSDtfsCounter, 175 mSDsluCounter, 134 mSDsCounter, 0 mSdLazyCounter, 300 mSolverCounterSat, 51 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.1s Time, 0 mProtectedPredicate, 0 mProtectedAction, 177 SdHoareTripleChecker+Valid, 218 SdHoareTripleChecker+Invalid, 351 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 51 IncrementalHoareTripleChecker+Valid, 300 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.2s IncrementalHoareTripleChecker+Time [2021-12-16 00:59:15,861 INFO L934 BasicCegarLoop]: SdHoareTripleChecker [177 Valid, 218 Invalid, 351 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [51 Valid, 300 Invalid, 0 Unknown, 0 Unchecked, 0.2s Time] [2021-12-16 00:59:15,861 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 502 states. [2021-12-16 00:59:15,885 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 502 to 482. [2021-12-16 00:59:15,886 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 482 states, 365 states have (on average 1.2054794520547945) internal successors, (440), 386 states have internal predecessors, (440), 58 states have call successors, (58), 56 states have call predecessors, (58), 58 states have return successors, (93), 58 states have call predecessors, (93), 58 states have call successors, (93) [2021-12-16 00:59:15,889 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 482 states to 482 states and 591 transitions. [2021-12-16 00:59:15,889 INFO L78 Accepts]: Start accepts. Automaton has 482 states and 591 transitions. Word has length 50 [2021-12-16 00:59:15,889 INFO L84 Accepts]: Finished accepts. word is rejected. [2021-12-16 00:59:15,889 INFO L470 AbstractCegarLoop]: Abstraction has 482 states and 591 transitions. [2021-12-16 00:59:15,890 INFO L471 AbstractCegarLoop]: INTERPOLANT automaton has has 7 states, 7 states have (on average 5.857142857142857) internal successors, (41), 5 states have internal predecessors, (41), 1 states have call successors, (5), 4 states have call predecessors, (5), 2 states have return successors, (4), 1 states have call predecessors, (4), 1 states have call successors, (4) [2021-12-16 00:59:15,890 INFO L276 IsEmpty]: Start isEmpty. Operand 482 states and 591 transitions. [2021-12-16 00:59:15,891 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 53 [2021-12-16 00:59:15,891 INFO L506 BasicCegarLoop]: Found error trace [2021-12-16 00:59:15,892 INFO L514 BasicCegarLoop]: trace histogram [1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2021-12-16 00:59:15,892 WARN L452 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable8 [2021-12-16 00:59:15,892 INFO L402 AbstractCegarLoop]: === Iteration 10 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2021-12-16 00:59:15,892 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2021-12-16 00:59:15,892 INFO L85 PathProgramCache]: Analyzing trace with hash -1829706971, now seen corresponding path program 1 times [2021-12-16 00:59:15,892 INFO L121 FreeRefinementEngine]: Executing refinement strategy CAMEL [2021-12-16 00:59:15,893 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [152977473] [2021-12-16 00:59:15,893 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2021-12-16 00:59:15,893 INFO L126 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2021-12-16 00:59:15,905 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 00:59:15,935 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 12 [2021-12-16 00:59:15,937 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 00:59:15,942 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 18 [2021-12-16 00:59:15,942 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 00:59:15,947 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 28 [2021-12-16 00:59:15,949 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 00:59:15,951 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 42 [2021-12-16 00:59:15,952 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 00:59:15,954 INFO L134 CoverageAnalysis]: Checked inductivity of 0 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2021-12-16 00:59:15,955 INFO L139 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2021-12-16 00:59:15,955 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [152977473] [2021-12-16 00:59:15,955 INFO L160 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [152977473] provided 1 perfect and 0 imperfect interpolant sequences [2021-12-16 00:59:15,955 INFO L186 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2021-12-16 00:59:15,956 INFO L199 FreeRefinementEngine]: Number of different interpolants: perfect sequences [6] imperfect sequences [] total 6 [2021-12-16 00:59:15,959 INFO L115 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [1563729216] [2021-12-16 00:59:15,959 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2021-12-16 00:59:15,959 INFO L546 AbstractCegarLoop]: INTERPOLANT automaton has 6 states [2021-12-16 00:59:15,960 INFO L103 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2021-12-16 00:59:15,960 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 6 interpolants. [2021-12-16 00:59:15,960 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=9, Invalid=21, Unknown=0, NotChecked=0, Total=30 [2021-12-16 00:59:15,960 INFO L87 Difference]: Start difference. First operand 482 states and 591 transitions. Second operand has 6 states, 6 states have (on average 7.166666666666667) internal successors, (43), 3 states have internal predecessors, (43), 1 states have call successors, (5), 5 states have call predecessors, (5), 1 states have return successors, (4), 1 states have call predecessors, (4), 1 states have call successors, (4) [2021-12-16 00:59:16,265 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2021-12-16 00:59:16,266 INFO L93 Difference]: Finished difference Result 855 states and 1065 transitions. [2021-12-16 00:59:16,266 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 13 states. [2021-12-16 00:59:16,268 INFO L78 Accepts]: Start accepts. Automaton has has 6 states, 6 states have (on average 7.166666666666667) internal successors, (43), 3 states have internal predecessors, (43), 1 states have call successors, (5), 5 states have call predecessors, (5), 1 states have return successors, (4), 1 states have call predecessors, (4), 1 states have call successors, (4) Word has length 52 [2021-12-16 00:59:16,269 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2021-12-16 00:59:16,272 INFO L225 Difference]: With dead ends: 855 [2021-12-16 00:59:16,272 INFO L226 Difference]: Without dead ends: 853 [2021-12-16 00:59:16,272 INFO L932 BasicCegarLoop]: 0 DeclaredPredicates, 29 GetRequests, 16 SyntacticMatches, 0 SemanticMatches, 13 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 35 ImplicationChecksByTransitivity, 0.1s TimeCoverageRelationStatistics Valid=67, Invalid=143, Unknown=0, NotChecked=0, Total=210 [2021-12-16 00:59:16,273 INFO L933 BasicCegarLoop]: 90 mSDtfsCounter, 378 mSDsluCounter, 98 mSDsCounter, 0 mSdLazyCounter, 227 mSolverCounterSat, 144 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.2s Time, 0 mProtectedPredicate, 0 mProtectedAction, 379 SdHoareTripleChecker+Valid, 188 SdHoareTripleChecker+Invalid, 371 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 144 IncrementalHoareTripleChecker+Valid, 227 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.2s IncrementalHoareTripleChecker+Time [2021-12-16 00:59:16,274 INFO L934 BasicCegarLoop]: SdHoareTripleChecker [379 Valid, 188 Invalid, 371 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [144 Valid, 227 Invalid, 0 Unknown, 0 Unchecked, 0.2s Time] [2021-12-16 00:59:16,274 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 853 states. [2021-12-16 00:59:16,306 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 853 to 689. [2021-12-16 00:59:16,308 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 689 states, 526 states have (on average 1.209125475285171) internal successors, (636), 562 states have internal predecessors, (636), 80 states have call successors, (80), 70 states have call predecessors, (80), 82 states have return successors, (146), 79 states have call predecessors, (146), 80 states have call successors, (146) [2021-12-16 00:59:16,312 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 689 states to 689 states and 862 transitions. [2021-12-16 00:59:16,313 INFO L78 Accepts]: Start accepts. Automaton has 689 states and 862 transitions. Word has length 52 [2021-12-16 00:59:16,313 INFO L84 Accepts]: Finished accepts. word is rejected. [2021-12-16 00:59:16,313 INFO L470 AbstractCegarLoop]: Abstraction has 689 states and 862 transitions. [2021-12-16 00:59:16,313 INFO L471 AbstractCegarLoop]: INTERPOLANT automaton has has 6 states, 6 states have (on average 7.166666666666667) internal successors, (43), 3 states have internal predecessors, (43), 1 states have call successors, (5), 5 states have call predecessors, (5), 1 states have return successors, (4), 1 states have call predecessors, (4), 1 states have call successors, (4) [2021-12-16 00:59:16,314 INFO L276 IsEmpty]: Start isEmpty. Operand 689 states and 862 transitions. [2021-12-16 00:59:16,315 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 91 [2021-12-16 00:59:16,315 INFO L506 BasicCegarLoop]: Found error trace [2021-12-16 00:59:16,315 INFO L514 BasicCegarLoop]: trace histogram [2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2021-12-16 00:59:16,315 WARN L452 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable9 [2021-12-16 00:59:16,316 INFO L402 AbstractCegarLoop]: === Iteration 11 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2021-12-16 00:59:16,316 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2021-12-16 00:59:16,316 INFO L85 PathProgramCache]: Analyzing trace with hash 16335344, now seen corresponding path program 1 times [2021-12-16 00:59:16,316 INFO L121 FreeRefinementEngine]: Executing refinement strategy CAMEL [2021-12-16 00:59:16,316 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [1960921765] [2021-12-16 00:59:16,317 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2021-12-16 00:59:16,317 INFO L126 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2021-12-16 00:59:16,332 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 00:59:16,379 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 12 [2021-12-16 00:59:16,380 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 00:59:16,397 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 18 [2021-12-16 00:59:16,398 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 00:59:16,406 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 24 [2021-12-16 00:59:16,408 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 00:59:16,427 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 3 [2021-12-16 00:59:16,428 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 00:59:16,446 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 17 [2021-12-16 00:59:16,447 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 00:59:16,448 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 66 [2021-12-16 00:59:16,449 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 00:59:16,451 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 80 [2021-12-16 00:59:16,451 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 00:59:16,453 INFO L134 CoverageAnalysis]: Checked inductivity of 35 backedges. 20 proven. 4 refuted. 0 times theorem prover too weak. 11 trivial. 0 not checked. [2021-12-16 00:59:16,453 INFO L139 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2021-12-16 00:59:16,453 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [1960921765] [2021-12-16 00:59:16,453 INFO L160 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [1960921765] provided 0 perfect and 1 imperfect interpolant sequences [2021-12-16 00:59:16,453 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleZ3 [2141681193] [2021-12-16 00:59:16,453 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2021-12-16 00:59:16,453 INFO L168 SolverBuilder]: Constructing external solver with command: z3 -smt2 -in SMTLIB2_COMPLIANT=true [2021-12-16 00:59:16,453 INFO L189 MonitoredProcess]: No working directory specified, using /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 [2021-12-16 00:59:16,480 INFO L229 MonitoredProcess]: Starting monitored process 2 with /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 -smt2 -in SMTLIB2_COMPLIANT=true (exit command is (exit), workingDir is null) [2021-12-16 00:59:16,530 INFO L327 MonitoredProcess]: [MP /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 -smt2 -in SMTLIB2_COMPLIANT=true (2)] Waiting until timeout for monitored process [2021-12-16 00:59:16,595 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 00:59:16,597 INFO L263 TraceCheckSpWp]: Trace formula consists of 466 conjuncts, 4 conjunts are in the unsatisfiable core [2021-12-16 00:59:16,603 INFO L286 TraceCheckSpWp]: Computing forward predicates... [2021-12-16 00:59:16,801 INFO L134 CoverageAnalysis]: Checked inductivity of 35 backedges. 35 proven. 0 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2021-12-16 00:59:16,801 INFO L324 TraceCheckSpWp]: Omiting computation of backward sequence because forward sequence was already perfect [2021-12-16 00:59:16,802 INFO L160 FreeRefinementEngine]: IpTcStrategyModuleZ3 [2141681193] provided 1 perfect and 0 imperfect interpolant sequences [2021-12-16 00:59:16,802 INFO L186 FreeRefinementEngine]: Found 1 perfect and 1 imperfect interpolant sequences. [2021-12-16 00:59:16,802 INFO L199 FreeRefinementEngine]: Number of different interpolants: perfect sequences [3] imperfect sequences [10] total 10 [2021-12-16 00:59:16,802 INFO L115 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [401867989] [2021-12-16 00:59:16,802 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2021-12-16 00:59:16,803 INFO L546 AbstractCegarLoop]: INTERPOLANT automaton has 3 states [2021-12-16 00:59:16,803 INFO L103 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2021-12-16 00:59:16,803 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 3 interpolants. [2021-12-16 00:59:16,803 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=20, Invalid=70, Unknown=0, NotChecked=0, Total=90 [2021-12-16 00:59:16,803 INFO L87 Difference]: Start difference. First operand 689 states and 862 transitions. Second operand has 3 states, 3 states have (on average 25.0) internal successors, (75), 3 states have internal predecessors, (75), 3 states have call successors, (8), 3 states have call predecessors, (8), 3 states have return successors, (7), 3 states have call predecessors, (7), 3 states have call successors, (7) [2021-12-16 00:59:16,835 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2021-12-16 00:59:16,835 INFO L93 Difference]: Finished difference Result 1227 states and 1554 transitions. [2021-12-16 00:59:16,835 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 3 states. [2021-12-16 00:59:16,836 INFO L78 Accepts]: Start accepts. Automaton has has 3 states, 3 states have (on average 25.0) internal successors, (75), 3 states have internal predecessors, (75), 3 states have call successors, (8), 3 states have call predecessors, (8), 3 states have return successors, (7), 3 states have call predecessors, (7), 3 states have call successors, (7) Word has length 90 [2021-12-16 00:59:16,836 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2021-12-16 00:59:16,838 INFO L225 Difference]: With dead ends: 1227 [2021-12-16 00:59:16,838 INFO L226 Difference]: Without dead ends: 640 [2021-12-16 00:59:16,839 INFO L932 BasicCegarLoop]: 0 DeclaredPredicates, 112 GetRequests, 104 SyntacticMatches, 0 SemanticMatches, 8 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 3 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=20, Invalid=70, Unknown=0, NotChecked=0, Total=90 [2021-12-16 00:59:16,840 INFO L933 BasicCegarLoop]: 129 mSDtfsCounter, 38 mSDsluCounter, 62 mSDsCounter, 0 mSdLazyCounter, 10 mSolverCounterSat, 0 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.0s Time, 0 mProtectedPredicate, 0 mProtectedAction, 38 SdHoareTripleChecker+Valid, 191 SdHoareTripleChecker+Invalid, 10 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 0 IncrementalHoareTripleChecker+Valid, 10 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.0s IncrementalHoareTripleChecker+Time [2021-12-16 00:59:16,840 INFO L934 BasicCegarLoop]: SdHoareTripleChecker [38 Valid, 191 Invalid, 10 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [0 Valid, 10 Invalid, 0 Unknown, 0 Unchecked, 0.0s Time] [2021-12-16 00:59:16,840 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 640 states. [2021-12-16 00:59:16,877 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 640 to 640. [2021-12-16 00:59:16,878 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 640 states, 488 states have (on average 1.2008196721311475) internal successors, (586), 522 states have internal predecessors, (586), 75 states have call successors, (75), 65 states have call predecessors, (75), 76 states have return successors, (119), 75 states have call predecessors, (119), 75 states have call successors, (119) [2021-12-16 00:59:16,881 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 640 states to 640 states and 780 transitions. [2021-12-16 00:59:16,881 INFO L78 Accepts]: Start accepts. Automaton has 640 states and 780 transitions. Word has length 90 [2021-12-16 00:59:16,881 INFO L84 Accepts]: Finished accepts. word is rejected. [2021-12-16 00:59:16,881 INFO L470 AbstractCegarLoop]: Abstraction has 640 states and 780 transitions. [2021-12-16 00:59:16,881 INFO L471 AbstractCegarLoop]: INTERPOLANT automaton has has 3 states, 3 states have (on average 25.0) internal successors, (75), 3 states have internal predecessors, (75), 3 states have call successors, (8), 3 states have call predecessors, (8), 3 states have return successors, (7), 3 states have call predecessors, (7), 3 states have call successors, (7) [2021-12-16 00:59:16,882 INFO L276 IsEmpty]: Start isEmpty. Operand 640 states and 780 transitions. [2021-12-16 00:59:16,883 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 94 [2021-12-16 00:59:16,883 INFO L506 BasicCegarLoop]: Found error trace [2021-12-16 00:59:16,883 INFO L514 BasicCegarLoop]: trace histogram [2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2021-12-16 00:59:16,922 INFO L540 MonitoredProcess]: [MP /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 -smt2 -in SMTLIB2_COMPLIANT=true (2)] Forceful destruction successful, exit code 0 [2021-12-16 00:59:17,102 WARN L452 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: 2 /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 -smt2 -in SMTLIB2_COMPLIANT=true,SelfDestructingSolverStorable10 [2021-12-16 00:59:17,103 INFO L402 AbstractCegarLoop]: === Iteration 12 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2021-12-16 00:59:17,103 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2021-12-16 00:59:17,103 INFO L85 PathProgramCache]: Analyzing trace with hash 1128084440, now seen corresponding path program 1 times [2021-12-16 00:59:17,103 INFO L121 FreeRefinementEngine]: Executing refinement strategy CAMEL [2021-12-16 00:59:17,104 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [922762535] [2021-12-16 00:59:17,104 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2021-12-16 00:59:17,104 INFO L126 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2021-12-16 00:59:17,117 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 00:59:17,158 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 12 [2021-12-16 00:59:17,159 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 00:59:17,168 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 18 [2021-12-16 00:59:17,168 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 00:59:17,175 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 24 [2021-12-16 00:59:17,177 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 00:59:17,192 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 3 [2021-12-16 00:59:17,193 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 00:59:17,197 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 17 [2021-12-16 00:59:17,198 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 00:59:17,199 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 73 [2021-12-16 00:59:17,200 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 00:59:17,201 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 2 [2021-12-16 00:59:17,201 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 00:59:17,202 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 83 [2021-12-16 00:59:17,203 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 00:59:17,204 INFO L134 CoverageAnalysis]: Checked inductivity of 27 backedges. 19 proven. 3 refuted. 0 times theorem prover too weak. 5 trivial. 0 not checked. [2021-12-16 00:59:17,204 INFO L139 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2021-12-16 00:59:17,204 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [922762535] [2021-12-16 00:59:17,205 INFO L160 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [922762535] provided 0 perfect and 1 imperfect interpolant sequences [2021-12-16 00:59:17,205 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleZ3 [1767447578] [2021-12-16 00:59:17,205 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2021-12-16 00:59:17,205 INFO L168 SolverBuilder]: Constructing external solver with command: z3 -smt2 -in SMTLIB2_COMPLIANT=true [2021-12-16 00:59:17,205 INFO L189 MonitoredProcess]: No working directory specified, using /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 [2021-12-16 00:59:17,206 INFO L229 MonitoredProcess]: Starting monitored process 3 with /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 -smt2 -in SMTLIB2_COMPLIANT=true (exit command is (exit), workingDir is null) [2021-12-16 00:59:17,237 INFO L327 MonitoredProcess]: [MP /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 -smt2 -in SMTLIB2_COMPLIANT=true (3)] Waiting until timeout for monitored process [2021-12-16 00:59:17,276 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 00:59:17,277 INFO L263 TraceCheckSpWp]: Trace formula consists of 468 conjuncts, 11 conjunts are in the unsatisfiable core [2021-12-16 00:59:17,279 INFO L286 TraceCheckSpWp]: Computing forward predicates... [2021-12-16 00:59:17,434 INFO L134 CoverageAnalysis]: Checked inductivity of 27 backedges. 27 proven. 0 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2021-12-16 00:59:17,434 INFO L324 TraceCheckSpWp]: Omiting computation of backward sequence because forward sequence was already perfect [2021-12-16 00:59:17,435 INFO L160 FreeRefinementEngine]: IpTcStrategyModuleZ3 [1767447578] provided 1 perfect and 0 imperfect interpolant sequences [2021-12-16 00:59:17,435 INFO L186 FreeRefinementEngine]: Found 1 perfect and 1 imperfect interpolant sequences. [2021-12-16 00:59:17,435 INFO L199 FreeRefinementEngine]: Number of different interpolants: perfect sequences [6] imperfect sequences [10] total 11 [2021-12-16 00:59:17,435 INFO L115 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [434641243] [2021-12-16 00:59:17,435 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2021-12-16 00:59:17,436 INFO L546 AbstractCegarLoop]: INTERPOLANT automaton has 6 states [2021-12-16 00:59:17,436 INFO L103 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2021-12-16 00:59:17,436 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 6 interpolants. [2021-12-16 00:59:17,436 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=24, Invalid=86, Unknown=0, NotChecked=0, Total=110 [2021-12-16 00:59:17,436 INFO L87 Difference]: Start difference. First operand 640 states and 780 transitions. Second operand has 6 states, 6 states have (on average 12.666666666666666) internal successors, (76), 6 states have internal predecessors, (76), 3 states have call successors, (9), 3 states have call predecessors, (9), 3 states have return successors, (8), 3 states have call predecessors, (8), 3 states have call successors, (8) [2021-12-16 00:59:17,529 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2021-12-16 00:59:17,530 INFO L93 Difference]: Finished difference Result 1641 states and 2101 transitions. [2021-12-16 00:59:17,530 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 7 states. [2021-12-16 00:59:17,530 INFO L78 Accepts]: Start accepts. Automaton has has 6 states, 6 states have (on average 12.666666666666666) internal successors, (76), 6 states have internal predecessors, (76), 3 states have call successors, (9), 3 states have call predecessors, (9), 3 states have return successors, (8), 3 states have call predecessors, (8), 3 states have call successors, (8) Word has length 93 [2021-12-16 00:59:17,530 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2021-12-16 00:59:17,534 INFO L225 Difference]: With dead ends: 1641 [2021-12-16 00:59:17,534 INFO L226 Difference]: Without dead ends: 1103 [2021-12-16 00:59:17,535 INFO L932 BasicCegarLoop]: 0 DeclaredPredicates, 119 GetRequests, 106 SyntacticMatches, 2 SemanticMatches, 11 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 13 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=36, Invalid=120, Unknown=0, NotChecked=0, Total=156 [2021-12-16 00:59:17,536 INFO L933 BasicCegarLoop]: 161 mSDtfsCounter, 172 mSDsluCounter, 472 mSDsCounter, 0 mSdLazyCounter, 54 mSolverCounterSat, 26 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.0s Time, 0 mProtectedPredicate, 0 mProtectedAction, 174 SdHoareTripleChecker+Valid, 633 SdHoareTripleChecker+Invalid, 80 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 26 IncrementalHoareTripleChecker+Valid, 54 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.0s IncrementalHoareTripleChecker+Time [2021-12-16 00:59:17,536 INFO L934 BasicCegarLoop]: SdHoareTripleChecker [174 Valid, 633 Invalid, 80 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [26 Valid, 54 Invalid, 0 Unknown, 0 Unchecked, 0.0s Time] [2021-12-16 00:59:17,537 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 1103 states. [2021-12-16 00:59:17,593 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 1103 to 903. [2021-12-16 00:59:17,594 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 903 states, 686 states have (on average 1.2011661807580174) internal successors, (824), 733 states have internal predecessors, (824), 107 states have call successors, (107), 95 states have call predecessors, (107), 109 states have return successors, (173), 102 states have call predecessors, (173), 107 states have call successors, (173) [2021-12-16 00:59:17,597 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 903 states to 903 states and 1104 transitions. [2021-12-16 00:59:17,597 INFO L78 Accepts]: Start accepts. Automaton has 903 states and 1104 transitions. Word has length 93 [2021-12-16 00:59:17,598 INFO L84 Accepts]: Finished accepts. word is rejected. [2021-12-16 00:59:17,598 INFO L470 AbstractCegarLoop]: Abstraction has 903 states and 1104 transitions. [2021-12-16 00:59:17,598 INFO L471 AbstractCegarLoop]: INTERPOLANT automaton has has 6 states, 6 states have (on average 12.666666666666666) internal successors, (76), 6 states have internal predecessors, (76), 3 states have call successors, (9), 3 states have call predecessors, (9), 3 states have return successors, (8), 3 states have call predecessors, (8), 3 states have call successors, (8) [2021-12-16 00:59:17,598 INFO L276 IsEmpty]: Start isEmpty. Operand 903 states and 1104 transitions. [2021-12-16 00:59:17,599 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 94 [2021-12-16 00:59:17,599 INFO L506 BasicCegarLoop]: Found error trace [2021-12-16 00:59:17,600 INFO L514 BasicCegarLoop]: trace histogram [2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2021-12-16 00:59:17,634 INFO L540 MonitoredProcess]: [MP /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 -smt2 -in SMTLIB2_COMPLIANT=true (3)] Forceful destruction successful, exit code 0 [2021-12-16 00:59:17,816 WARN L452 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: 3 /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 -smt2 -in SMTLIB2_COMPLIANT=true,SelfDestructingSolverStorable11 [2021-12-16 00:59:17,817 INFO L402 AbstractCegarLoop]: === Iteration 13 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2021-12-16 00:59:17,817 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2021-12-16 00:59:17,817 INFO L85 PathProgramCache]: Analyzing trace with hash 994070934, now seen corresponding path program 1 times [2021-12-16 00:59:17,817 INFO L121 FreeRefinementEngine]: Executing refinement strategy CAMEL [2021-12-16 00:59:17,817 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [1307170256] [2021-12-16 00:59:17,817 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2021-12-16 00:59:17,818 INFO L126 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2021-12-16 00:59:17,828 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 00:59:17,855 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 12 [2021-12-16 00:59:17,856 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 00:59:17,861 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 18 [2021-12-16 00:59:17,861 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 00:59:17,871 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 24 [2021-12-16 00:59:17,872 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 00:59:17,879 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 3 [2021-12-16 00:59:17,881 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 00:59:17,882 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 17 [2021-12-16 00:59:17,882 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 00:59:17,883 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 73 [2021-12-16 00:59:17,884 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 00:59:17,885 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 2 [2021-12-16 00:59:17,885 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 00:59:17,886 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 83 [2021-12-16 00:59:17,887 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 00:59:17,888 INFO L134 CoverageAnalysis]: Checked inductivity of 27 backedges. 8 proven. 1 refuted. 0 times theorem prover too weak. 18 trivial. 0 not checked. [2021-12-16 00:59:17,888 INFO L139 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2021-12-16 00:59:17,888 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [1307170256] [2021-12-16 00:59:17,888 INFO L160 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [1307170256] provided 0 perfect and 1 imperfect interpolant sequences [2021-12-16 00:59:17,888 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleZ3 [1590248896] [2021-12-16 00:59:17,889 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2021-12-16 00:59:17,889 INFO L168 SolverBuilder]: Constructing external solver with command: z3 -smt2 -in SMTLIB2_COMPLIANT=true [2021-12-16 00:59:17,889 INFO L189 MonitoredProcess]: No working directory specified, using /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 [2021-12-16 00:59:17,890 INFO L229 MonitoredProcess]: Starting monitored process 4 with /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 -smt2 -in SMTLIB2_COMPLIANT=true (exit command is (exit), workingDir is null) [2021-12-16 00:59:17,891 INFO L327 MonitoredProcess]: [MP /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 -smt2 -in SMTLIB2_COMPLIANT=true (4)] Waiting until timeout for monitored process [2021-12-16 00:59:17,956 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 00:59:17,957 INFO L263 TraceCheckSpWp]: Trace formula consists of 469 conjuncts, 5 conjunts are in the unsatisfiable core [2021-12-16 00:59:17,963 INFO L286 TraceCheckSpWp]: Computing forward predicates... [2021-12-16 00:59:18,094 INFO L134 CoverageAnalysis]: Checked inductivity of 27 backedges. 15 proven. 0 refuted. 0 times theorem prover too weak. 12 trivial. 0 not checked. [2021-12-16 00:59:18,094 INFO L324 TraceCheckSpWp]: Omiting computation of backward sequence because forward sequence was already perfect [2021-12-16 00:59:18,094 INFO L160 FreeRefinementEngine]: IpTcStrategyModuleZ3 [1590248896] provided 1 perfect and 0 imperfect interpolant sequences [2021-12-16 00:59:18,095 INFO L186 FreeRefinementEngine]: Found 1 perfect and 1 imperfect interpolant sequences. [2021-12-16 00:59:18,095 INFO L199 FreeRefinementEngine]: Number of different interpolants: perfect sequences [5] imperfect sequences [9] total 12 [2021-12-16 00:59:18,096 INFO L115 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [1109093382] [2021-12-16 00:59:18,096 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2021-12-16 00:59:18,097 INFO L546 AbstractCegarLoop]: INTERPOLANT automaton has 5 states [2021-12-16 00:59:18,097 INFO L103 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2021-12-16 00:59:18,097 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 5 interpolants. [2021-12-16 00:59:18,097 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=26, Invalid=106, Unknown=0, NotChecked=0, Total=132 [2021-12-16 00:59:18,097 INFO L87 Difference]: Start difference. First operand 903 states and 1104 transitions. Second operand has 5 states, 5 states have (on average 13.8) internal successors, (69), 5 states have internal predecessors, (69), 2 states have call successors, (8), 2 states have call predecessors, (8), 2 states have return successors, (8), 2 states have call predecessors, (8), 2 states have call successors, (8) [2021-12-16 00:59:18,132 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2021-12-16 00:59:18,132 INFO L93 Difference]: Finished difference Result 1237 states and 1508 transitions. [2021-12-16 00:59:18,132 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 5 states. [2021-12-16 00:59:18,133 INFO L78 Accepts]: Start accepts. Automaton has has 5 states, 5 states have (on average 13.8) internal successors, (69), 5 states have internal predecessors, (69), 2 states have call successors, (8), 2 states have call predecessors, (8), 2 states have return successors, (8), 2 states have call predecessors, (8), 2 states have call successors, (8) Word has length 93 [2021-12-16 00:59:18,133 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2021-12-16 00:59:18,133 INFO L225 Difference]: With dead ends: 1237 [2021-12-16 00:59:18,133 INFO L226 Difference]: Without dead ends: 0 [2021-12-16 00:59:18,136 INFO L932 BasicCegarLoop]: 0 DeclaredPredicates, 116 GetRequests, 104 SyntacticMatches, 0 SemanticMatches, 12 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 12 ImplicationChecksByTransitivity, 0.1s TimeCoverageRelationStatistics Valid=36, Invalid=146, Unknown=0, NotChecked=0, Total=182 [2021-12-16 00:59:18,137 INFO L933 BasicCegarLoop]: 88 mSDtfsCounter, 36 mSDsluCounter, 227 mSDsCounter, 0 mSdLazyCounter, 7 mSolverCounterSat, 3 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.0s Time, 0 mProtectedPredicate, 0 mProtectedAction, 36 SdHoareTripleChecker+Valid, 315 SdHoareTripleChecker+Invalid, 10 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 3 IncrementalHoareTripleChecker+Valid, 7 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.0s IncrementalHoareTripleChecker+Time [2021-12-16 00:59:18,137 INFO L934 BasicCegarLoop]: SdHoareTripleChecker [36 Valid, 315 Invalid, 10 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [3 Valid, 7 Invalid, 0 Unknown, 0 Unchecked, 0.0s Time] [2021-12-16 00:59:18,138 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 0 states. [2021-12-16 00:59:18,138 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 0 to 0. [2021-12-16 00:59:18,138 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 0 states, 0 states have (on average 0.0) internal successors, (0), 0 states have internal predecessors, (0), 0 states have call successors, (0), 0 states have call predecessors, (0), 0 states have return successors, (0), 0 states have call predecessors, (0), 0 states have call successors, (0) [2021-12-16 00:59:18,138 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 0 states to 0 states and 0 transitions. [2021-12-16 00:59:18,138 INFO L78 Accepts]: Start accepts. Automaton has 0 states and 0 transitions. Word has length 93 [2021-12-16 00:59:18,139 INFO L84 Accepts]: Finished accepts. word is rejected. [2021-12-16 00:59:18,139 INFO L470 AbstractCegarLoop]: Abstraction has 0 states and 0 transitions. [2021-12-16 00:59:18,139 INFO L471 AbstractCegarLoop]: INTERPOLANT automaton has has 5 states, 5 states have (on average 13.8) internal successors, (69), 5 states have internal predecessors, (69), 2 states have call successors, (8), 2 states have call predecessors, (8), 2 states have return successors, (8), 2 states have call predecessors, (8), 2 states have call successors, (8) [2021-12-16 00:59:18,139 INFO L276 IsEmpty]: Start isEmpty. Operand 0 states and 0 transitions. [2021-12-16 00:59:18,139 INFO L282 IsEmpty]: Finished isEmpty. No accepting run. [2021-12-16 00:59:18,141 INFO L764 garLoopResultBuilder]: Registering result SAFE for location timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION (0 of 1 remaining) [2021-12-16 00:59:18,161 INFO L540 MonitoredProcess]: [MP /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 -smt2 -in SMTLIB2_COMPLIANT=true (4)] Forceful destruction successful, exit code 0 [2021-12-16 00:59:18,362 WARN L452 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable12,4 /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 -smt2 -in SMTLIB2_COMPLIANT=true [2021-12-16 00:59:18,363 INFO L343 DoubleDeckerVisitor]: Before removal of dead ends 0 states and 0 transitions. [2021-12-16 00:59:20,789 INFO L858 garLoopResultBuilder]: For program point processEnvironment__wrappee__baseEXIT(lines 400 406) no Hoare annotation was computed. [2021-12-16 00:59:20,789 INFO L861 garLoopResultBuilder]: At program point processEnvironment__wrappee__baseFINAL(lines 400 406) the Hoare annotation is: true [2021-12-16 00:59:20,790 INFO L858 garLoopResultBuilder]: For program point L192-1(lines 188 199) no Hoare annotation was computed. [2021-12-16 00:59:20,790 INFO L854 garLoopResultBuilder]: At program point changeMethaneLevelENTRY(lines 188 199) the Hoare annotation is: (let ((.cse0 (= ~methaneLevelCritical~0 |old(~methaneLevelCritical~0)|)) (.cse1 (not (= ~systemActive~0 1)))) (and (or (not (= ~pumpRunning~0 0)) .cse0 (not (<= 1 ~waterLevel~0)) (not (= ~methAndRunningLastTime~0 0)) .cse1) (or .cse0 (not (<= 1 ~pumpRunning~0)) .cse1 (not (<= 2 ~waterLevel~0))))) [2021-12-16 00:59:20,790 INFO L858 garLoopResultBuilder]: For program point changeMethaneLevelEXIT(lines 188 199) no Hoare annotation was computed. [2021-12-16 00:59:20,790 INFO L861 garLoopResultBuilder]: At program point isMethaneLevelCriticalENTRY(lines 200 208) the Hoare annotation is: true [2021-12-16 00:59:20,790 INFO L858 garLoopResultBuilder]: For program point isMethaneLevelCriticalFINAL(lines 200 208) no Hoare annotation was computed. [2021-12-16 00:59:20,790 INFO L858 garLoopResultBuilder]: For program point isMethaneLevelCriticalEXIT(lines 200 208) no Hoare annotation was computed. [2021-12-16 00:59:20,790 INFO L854 garLoopResultBuilder]: At program point L448(line 448) the Hoare annotation is: (let ((.cse0 (not (= ~systemActive~0 1)))) (and (or (not (<= 2 |old(~waterLevel~0)|)) .cse0 (not (<= 1 |old(~pumpRunning~0)|))) (or (not (= |old(~pumpRunning~0)| 0)) .cse0 (not (<= 1 |old(~waterLevel~0)|)) (not (= |old(~methAndRunningLastTime~0)| 0))))) [2021-12-16 00:59:20,791 INFO L858 garLoopResultBuilder]: For program point L940(line 940) no Hoare annotation was computed. [2021-12-16 00:59:20,791 INFO L858 garLoopResultBuilder]: For program point L168(lines 168 172) no Hoare annotation was computed. [2021-12-16 00:59:20,791 INFO L858 garLoopResultBuilder]: For program point timeShiftFINAL(lines 376 399) no Hoare annotation was computed. [2021-12-16 00:59:20,791 INFO L854 garLoopResultBuilder]: At program point L168-2(lines 164 175) the Hoare annotation is: (let ((.cse0 (not (<= 2 |old(~waterLevel~0)|))) (.cse2 (not (<= 1 |old(~pumpRunning~0)|))) (.cse1 (not (= ~systemActive~0 1))) (.cse3 (not (= |old(~methAndRunningLastTime~0)| 0)))) (and (or .cse0 (= ~methAndRunningLastTime~0 0) .cse1 .cse2 .cse3) (or .cse0 (and (= ~pumpRunning~0 |old(~pumpRunning~0)|) (<= 1 ~waterLevel~0)) .cse1 .cse2) (or (not (= |old(~pumpRunning~0)| 0)) .cse1 (not (<= 1 |old(~waterLevel~0)|)) .cse3))) [2021-12-16 00:59:20,791 INFO L854 garLoopResultBuilder]: At program point L453(line 453) the Hoare annotation is: (let ((.cse0 (not (= ~systemActive~0 1)))) (and (or (not (<= 2 |old(~waterLevel~0)|)) .cse0 (not (<= 1 |old(~pumpRunning~0)|))) (or (not (= |old(~pumpRunning~0)| 0)) (and (= ~waterLevel~0 |old(~waterLevel~0)|) (= ~methAndRunningLastTime~0 0) (= ~pumpRunning~0 0)) .cse0 (not (<= 1 |old(~waterLevel~0)|)) (not (= |old(~methAndRunningLastTime~0)| 0))))) [2021-12-16 00:59:20,791 INFO L854 garLoopResultBuilder]: At program point L453-1(lines 434 458) the Hoare annotation is: (let ((.cse1 (= ~methAndRunningLastTime~0 0)) (.cse0 (not (= |old(~pumpRunning~0)| 0))) (.cse3 (not (= |old(~methAndRunningLastTime~0)| 0))) (.cse5 (= ~pumpRunning~0 0)) (.cse2 (not (= ~systemActive~0 1)))) (and (or (not (= |old(~waterLevel~0)| 1)) .cse0 .cse1 .cse2 .cse3) (let ((.cse4 (= ~waterLevel~0 |old(~waterLevel~0)|))) (or (and .cse4 (<= 1 ~pumpRunning~0) (<= 2 ~waterLevel~0) .cse1) (and .cse4 .cse5) .cse0 .cse2 (not (<= 1 |old(~waterLevel~0)|)) .cse3)) (or (not (<= 2 |old(~waterLevel~0)|)) (and (<= 1 |timeShift_isLowWaterLevel_~tmp___0~3#1|) (<= 1 |timeShift_processEnvironment_~tmp~4#1|) (<= 1 |timeShift_isLowWaterLevel_#res#1|) (= |timeShift_isLowWaterSensorDry_#res#1| 0) (<= 1 ~waterLevel~0) (= |timeShift_isLowWaterLevel_~tmp~6#1| 0) .cse5) .cse2 (not (<= 1 |old(~pumpRunning~0)|))))) [2021-12-16 00:59:20,791 INFO L858 garLoopResultBuilder]: For program point L387-1(lines 387 393) no Hoare annotation was computed. [2021-12-16 00:59:20,792 INFO L858 garLoopResultBuilder]: For program point L288(lines 288 298) no Hoare annotation was computed. [2021-12-16 00:59:20,792 INFO L858 garLoopResultBuilder]: For program point L284(lines 284 301) no Hoare annotation was computed. [2021-12-16 00:59:20,792 INFO L854 garLoopResultBuilder]: At program point L284-1(lines 276 304) the Hoare annotation is: (let ((.cse0 (not (= |old(~waterLevel~0)| 1))) (.cse7 (= |timeShift___utac_acc__Specification2_spec__2_~tmp~1#1| 0)) (.cse3 (not (= |old(~pumpRunning~0)| 0))) (.cse8 (not (= ~methaneLevelCritical~0 0))) (.cse5 (not (= |old(~methAndRunningLastTime~0)| 0))) (.cse6 (not (<= 2 |old(~waterLevel~0)|))) (.cse1 (= ~methAndRunningLastTime~0 0)) (.cse2 (= ~pumpRunning~0 0)) (.cse4 (not (= ~systemActive~0 1))) (.cse9 (not (<= 1 |old(~pumpRunning~0)|)))) (and (or .cse0 (and (= ~waterLevel~0 1) .cse1 .cse2) .cse3 .cse4 .cse5) (or .cse6 .cse7 .cse8 .cse4 .cse9) (or .cse7 .cse0 .cse3 .cse8 .cse4 .cse5) (let ((.cse10 (= ~waterLevel~0 |old(~waterLevel~0)|))) (or .cse6 (and .cse10 (= ~pumpRunning~0 |old(~pumpRunning~0)|) .cse1) (and .cse10 (<= 1 ~pumpRunning~0)) .cse3 .cse4 .cse5)) (or .cse6 (and .cse7 .cse1) .cse3 .cse8 .cse4 .cse5) (or .cse6 (and (<= 1 |timeShift_isLowWaterLevel_~tmp___0~3#1|) (<= 1 |timeShift_processEnvironment_~tmp~4#1|) (<= 1 |timeShift_isLowWaterLevel_#res#1|) (= |timeShift_isLowWaterSensorDry_#res#1| 0) .cse1 (<= 1 ~waterLevel~0) (= |timeShift_isLowWaterLevel_~tmp~6#1| 0) .cse2) .cse4 .cse9))) [2021-12-16 00:59:20,792 INFO L854 garLoopResultBuilder]: At program point L565(lines 550 568) the Hoare annotation is: (let ((.cse3 (not (= |old(~methAndRunningLastTime~0)| 0))) (.cse0 (not (<= 2 |old(~waterLevel~0)|))) (.cse1 (not (= ~systemActive~0 1))) (.cse2 (not (<= 1 |old(~pumpRunning~0)|)))) (and (or .cse0 (= ~methAndRunningLastTime~0 0) .cse1 .cse2 .cse3) (or (not (= |old(~pumpRunning~0)| 0)) .cse1 (not (<= 1 |old(~waterLevel~0)|)) .cse3) (or .cse0 (and (<= 1 |timeShift_isLowWaterLevel_~tmp___0~3#1|) (<= 1 |timeShift_isLowWaterLevel_#res#1|) (= ~pumpRunning~0 |old(~pumpRunning~0)|) (= |timeShift_isLowWaterSensorDry_#res#1| 0) (<= 1 ~waterLevel~0) (= |timeShift_isLowWaterLevel_~tmp~6#1| 0)) .cse1 .cse2))) [2021-12-16 00:59:20,792 INFO L854 garLoopResultBuilder]: At program point L941(lines 936 943) the Hoare annotation is: (let ((.cse0 (not (= ~systemActive~0 1)))) (and (or (not (<= 2 |old(~waterLevel~0)|)) .cse0 (not (<= 1 |old(~pumpRunning~0)|))) (or (not (= |old(~pumpRunning~0)| 0)) .cse0 (not (<= 1 |old(~waterLevel~0)|)) (not (= |old(~methAndRunningLastTime~0)| 0))))) [2021-12-16 00:59:20,792 INFO L854 garLoopResultBuilder]: At program point L491(lines 486 494) the Hoare annotation is: (let ((.cse5 (= ~methAndRunningLastTime~0 0)) (.cse4 (not (= |old(~pumpRunning~0)| 0))) (.cse1 (not (= ~methaneLevelCritical~0 0))) (.cse10 (not (<= 1 |old(~waterLevel~0)|))) (.cse6 (not (= |old(~methAndRunningLastTime~0)| 0))) (.cse0 (not (<= 2 |old(~waterLevel~0)|))) (.cse8 (= |timeShift_isPumpRunning_#res#1| 0)) (.cse9 (= ~pumpRunning~0 0)) (.cse2 (not (= ~systemActive~0 1))) (.cse3 (not (<= 1 |old(~pumpRunning~0)|)))) (and (or .cse0 .cse1 .cse2 .cse3) (or (not (= |old(~waterLevel~0)| 1)) .cse4 .cse5 .cse2 .cse6) (let ((.cse7 (= ~waterLevel~0 |old(~waterLevel~0)|))) (or (and .cse7 (<= 1 ~pumpRunning~0) (<= 2 ~waterLevel~0) .cse5) (and .cse8 .cse7 .cse9) .cse4 .cse2 .cse10 .cse6)) (or .cse4 .cse1 .cse2 .cse10 .cse6) (or .cse0 (and (<= 1 |timeShift_isLowWaterLevel_~tmp___0~3#1|) (<= 1 |timeShift_processEnvironment_~tmp~4#1|) .cse8 (<= 1 |timeShift_isLowWaterLevel_#res#1|) (= |timeShift_isLowWaterSensorDry_#res#1| 0) (<= 1 ~waterLevel~0) (= |timeShift_isLowWaterLevel_~tmp~6#1| 0) .cse9) .cse2 .cse3))) [2021-12-16 00:59:20,793 INFO L854 garLoopResultBuilder]: At program point L260(lines 255 263) the Hoare annotation is: (let ((.cse0 (not (<= 2 |old(~waterLevel~0)|))) (.cse2 (not (<= 1 |old(~pumpRunning~0)|))) (.cse1 (not (= ~systemActive~0 1))) (.cse3 (not (= |old(~methAndRunningLastTime~0)| 0)))) (and (or .cse0 (= ~methAndRunningLastTime~0 0) .cse1 .cse2 .cse3) (or .cse0 .cse1 (and (= ~pumpRunning~0 |old(~pumpRunning~0)|) (= |timeShift_isLowWaterSensorDry_#res#1| 0) (<= 1 ~waterLevel~0)) .cse2) (or (not (= |old(~pumpRunning~0)| 0)) .cse1 (not (<= 1 |old(~waterLevel~0)|)) .cse3))) [2021-12-16 00:59:20,793 INFO L858 garLoopResultBuilder]: For program point L289(lines 289 295) no Hoare annotation was computed. [2021-12-16 00:59:20,793 INFO L858 garLoopResultBuilder]: For program point L380-1(lines 379 398) no Hoare annotation was computed. [2021-12-16 00:59:20,793 INFO L858 garLoopResultBuilder]: For program point L442(lines 442 450) no Hoare annotation was computed. [2021-12-16 00:59:20,793 INFO L858 garLoopResultBuilder]: For program point L438(lines 438 455) no Hoare annotation was computed. [2021-12-16 00:59:20,793 INFO L854 garLoopResultBuilder]: At program point L282(line 282) the Hoare annotation is: (let ((.cse1 (= ~methAndRunningLastTime~0 0)) (.cse0 (not (= |old(~pumpRunning~0)| 0))) (.cse3 (not (= |old(~methAndRunningLastTime~0)| 0))) (.cse5 (= ~pumpRunning~0 0)) (.cse2 (not (= ~systemActive~0 1)))) (and (or (not (= |old(~waterLevel~0)| 1)) .cse0 .cse1 .cse2 .cse3) (let ((.cse4 (= ~waterLevel~0 |old(~waterLevel~0)|))) (or (and .cse4 (<= 1 ~pumpRunning~0) (<= 2 ~waterLevel~0) .cse1) (and .cse4 .cse5) .cse0 .cse2 (not (<= 1 |old(~waterLevel~0)|)) .cse3)) (or (not (<= 2 |old(~waterLevel~0)|)) (and (<= 1 |timeShift_isLowWaterLevel_~tmp___0~3#1|) (<= 1 |timeShift_processEnvironment_~tmp~4#1|) (<= 1 |timeShift_isLowWaterLevel_#res#1|) (= |timeShift_isLowWaterSensorDry_#res#1| 0) (<= 1 ~waterLevel~0) (= |timeShift_isLowWaterLevel_~tmp~6#1| 0) .cse5) .cse2 (not (<= 1 |old(~pumpRunning~0)|))))) [2021-12-16 00:59:20,793 INFO L858 garLoopResultBuilder]: For program point L282-1(line 282) no Hoare annotation was computed. [2021-12-16 00:59:20,793 INFO L854 garLoopResultBuilder]: At program point L472(lines 467 474) the Hoare annotation is: (let ((.cse0 (not (= ~systemActive~0 1)))) (and (or (not (= |old(~pumpRunning~0)| 0)) .cse0 (not (<= 1 |old(~waterLevel~0)|)) (not (= |old(~methAndRunningLastTime~0)| 0))) (or (not (<= 2 |old(~waterLevel~0)|)) (and (<= 1 |timeShift_isLowWaterLevel_~tmp___0~3#1|) (<= 1 |timeShift_processEnvironment_~tmp~4#1|) (<= 1 |timeShift_isLowWaterLevel_#res#1|) (= |timeShift_isLowWaterSensorDry_#res#1| 0) (<= 1 ~waterLevel~0) (= |timeShift_isLowWaterLevel_~tmp~6#1| 0) (= ~pumpRunning~0 0)) .cse0 (not (<= 1 |old(~pumpRunning~0)|))))) [2021-12-16 00:59:20,794 INFO L854 garLoopResultBuilder]: At program point timeShiftENTRY(lines 376 399) the Hoare annotation is: (let ((.cse0 (not (<= 2 |old(~waterLevel~0)|))) (.cse3 (not (<= 1 |old(~pumpRunning~0)|))) (.cse1 (= ~waterLevel~0 |old(~waterLevel~0)|)) (.cse4 (= ~methAndRunningLastTime~0 0)) (.cse2 (not (= ~systemActive~0 1))) (.cse5 (not (= |old(~methAndRunningLastTime~0)| 0)))) (and (or .cse0 (and .cse1 (= ~pumpRunning~0 |old(~pumpRunning~0)|)) .cse2 .cse3) (or .cse0 .cse4 .cse2 .cse3 .cse5) (or (not (= |old(~pumpRunning~0)| 0)) (and .cse1 .cse4 (= ~pumpRunning~0 0)) .cse2 (not (<= 1 |old(~waterLevel~0)|)) .cse5))) [2021-12-16 00:59:20,794 INFO L858 garLoopResultBuilder]: For program point L559(lines 559 563) no Hoare annotation was computed. [2021-12-16 00:59:20,794 INFO L858 garLoopResultBuilder]: For program point L559-2(lines 559 563) no Hoare annotation was computed. [2021-12-16 00:59:20,794 INFO L858 garLoopResultBuilder]: For program point timeShiftEXIT(lines 376 399) no Hoare annotation was computed. [2021-12-16 00:59:20,794 INFO L858 garLoopResultBuilder]: For program point timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION(line 940) no Hoare annotation was computed. [2021-12-16 00:59:20,794 INFO L861 garLoopResultBuilder]: At program point L66-1(lines 66 70) the Hoare annotation is: true [2021-12-16 00:59:20,794 INFO L858 garLoopResultBuilder]: For program point cleanupEXIT(lines 52 81) no Hoare annotation was computed. [2021-12-16 00:59:20,794 INFO L858 garLoopResultBuilder]: For program point L63(line 63) no Hoare annotation was computed. [2021-12-16 00:59:20,795 INFO L861 garLoopResultBuilder]: At program point cleanupENTRY(lines 52 81) the Hoare annotation is: true [2021-12-16 00:59:20,795 INFO L861 garLoopResultBuilder]: At program point L62-2(lines 62 76) the Hoare annotation is: true [2021-12-16 00:59:20,795 INFO L861 garLoopResultBuilder]: At program point L58(line 58) the Hoare annotation is: true [2021-12-16 00:59:20,795 INFO L858 garLoopResultBuilder]: For program point L58-1(line 58) no Hoare annotation was computed. [2021-12-16 00:59:20,795 INFO L861 garLoopResultBuilder]: At program point L77(lines 52 81) the Hoare annotation is: true [2021-12-16 00:59:20,795 INFO L858 garLoopResultBuilder]: For program point L73(line 73) no Hoare annotation was computed. [2021-12-16 00:59:20,795 INFO L858 garLoopResultBuilder]: For program point L66(lines 66 70) no Hoare annotation was computed. [2021-12-16 00:59:20,795 INFO L854 garLoopResultBuilder]: At program point L960(lines 956 962) the Hoare annotation is: (and (= ~waterLevel~0 1) (= ~methaneLevelCritical~0 0) (= ~methAndRunningLastTime~0 0) (= ~systemActive~0 1) (= ~pumpRunning~0 0)) [2021-12-16 00:59:20,795 INFO L861 garLoopResultBuilder]: At program point L126(lines 118 128) the Hoare annotation is: true [2021-12-16 00:59:20,796 INFO L861 garLoopResultBuilder]: At program point L151(lines 132 154) the Hoare annotation is: true [2021-12-16 00:59:20,796 INFO L854 garLoopResultBuilder]: At program point L362(lines 315 363) the Hoare annotation is: false [2021-12-16 00:59:20,796 INFO L858 garLoopResultBuilder]: For program point L-1(line -1) no Hoare annotation was computed. [2021-12-16 00:59:20,796 INFO L858 garLoopResultBuilder]: For program point ULTIMATE.startENTRY(line -1) no Hoare annotation was computed. [2021-12-16 00:59:20,796 INFO L858 garLoopResultBuilder]: For program point L317(lines 316 361) no Hoare annotation was computed. [2021-12-16 00:59:20,796 INFO L858 garLoopResultBuilder]: For program point ULTIMATE.startFINAL(line -1) no Hoare annotation was computed. [2021-12-16 00:59:20,796 INFO L858 garLoopResultBuilder]: For program point L346(lines 346 357) no Hoare annotation was computed. [2021-12-16 00:59:20,796 INFO L854 garLoopResultBuilder]: At program point L338(line 338) the Hoare annotation is: (let ((.cse2 (= ~methAndRunningLastTime~0 0)) (.cse5 (= ~pumpRunning~0 0)) (.cse0 (= |ULTIMATE.start_test_~splverifierCounter~0#1| 0)) (.cse1 (= 1 |ULTIMATE.start_valid_product_#res#1|)) (.cse3 (= 1 |ULTIMATE.start_main_~tmp~0#1|)) (.cse6 (<= 2 ~waterLevel~0)) (.cse4 (= ~systemActive~0 1))) (or (and .cse0 (= ~waterLevel~0 1) .cse1 .cse2 .cse3 .cse4 .cse5) (and .cse0 .cse1 .cse3 .cse2 .cse6 .cse4 .cse5) (and .cse0 .cse1 (<= 1 ~pumpRunning~0) .cse3 .cse6 .cse4))) [2021-12-16 00:59:20,797 INFO L854 garLoopResultBuilder]: At program point L359(lines 316 361) the Hoare annotation is: (let ((.cse0 (= |ULTIMATE.start_test_~splverifierCounter~0#1| 0)) (.cse1 (= 1 |ULTIMATE.start_valid_product_#res#1|)) (.cse2 (= 1 |ULTIMATE.start_main_~tmp~0#1|)) (.cse3 (= ~systemActive~0 1))) (or (and .cse0 .cse1 (<= 1 ~pumpRunning~0) .cse2 (<= 2 ~waterLevel~0) .cse3) (and .cse0 .cse1 .cse2 (= ~methAndRunningLastTime~0 0) (<= 1 ~waterLevel~0) .cse3 (= ~pumpRunning~0 0)))) [2021-12-16 00:59:20,797 INFO L858 garLoopResultBuilder]: For program point L326(lines 326 332) no Hoare annotation was computed. [2021-12-16 00:59:20,797 INFO L858 garLoopResultBuilder]: For program point L326-1(lines 326 332) no Hoare annotation was computed. [2021-12-16 00:59:20,797 INFO L858 garLoopResultBuilder]: For program point ULTIMATE.startEXIT(line -1) no Hoare annotation was computed. [2021-12-16 00:59:20,797 INFO L858 garLoopResultBuilder]: For program point L318(lines 318 322) no Hoare annotation was computed. [2021-12-16 00:59:20,797 INFO L854 garLoopResultBuilder]: At program point L273(lines 268 275) the Hoare annotation is: (and (= ~waterLevel~0 1) (= ~methaneLevelCritical~0 0) (= 1 |ULTIMATE.start_valid_product_#res#1|) (= ~methAndRunningLastTime~0 0) (= 1 |ULTIMATE.start_main_~tmp~0#1|) (= ~systemActive~0 1) (= ~pumpRunning~0 0)) [2021-12-16 00:59:20,797 INFO L854 garLoopResultBuilder]: At program point L975(lines 970 978) the Hoare annotation is: (and (= ~waterLevel~0 1) (= ~methaneLevelCritical~0 0) (= 1 |ULTIMATE.start_valid_product_#res#1|) (= ~methAndRunningLastTime~0 0) (= ~systemActive~0 1) (= ~pumpRunning~0 0)) [2021-12-16 00:59:20,797 INFO L854 garLoopResultBuilder]: At program point L967(lines 963 969) the Hoare annotation is: (and (= ~waterLevel~0 1) (= ~methaneLevelCritical~0 0) (= ~methAndRunningLastTime~0 0) (= ~systemActive~0 1) (= ~pumpRunning~0 0)) [2021-12-16 00:59:20,797 INFO L858 garLoopResultBuilder]: For program point L352(lines 352 356) no Hoare annotation was computed. [2021-12-16 00:59:20,798 INFO L854 garLoopResultBuilder]: At program point L352-2(lines 346 357) the Hoare annotation is: (let ((.cse2 (= ~methAndRunningLastTime~0 0)) (.cse5 (= ~pumpRunning~0 0)) (.cse0 (= |ULTIMATE.start_test_~splverifierCounter~0#1| 0)) (.cse1 (= 1 |ULTIMATE.start_valid_product_#res#1|)) (.cse3 (= 1 |ULTIMATE.start_main_~tmp~0#1|)) (.cse6 (<= 2 ~waterLevel~0)) (.cse4 (= ~systemActive~0 1))) (or (and .cse0 (= ~waterLevel~0 1) .cse1 .cse2 .cse3 .cse4 .cse5) (and .cse0 .cse1 .cse3 .cse2 .cse6 .cse4 .cse5) (and .cse0 .cse1 (<= 1 ~pumpRunning~0) .cse3 .cse6 .cse4))) [2021-12-16 00:59:20,798 INFO L854 garLoopResultBuilder]: At program point L113(lines 109 115) the Hoare annotation is: (and (= ~waterLevel~0 1) (= ~methaneLevelCritical~0 0) (= 1 |ULTIMATE.start_valid_product_#res#1|) (= ~methAndRunningLastTime~0 0) (= 1 |ULTIMATE.start_main_~tmp~0#1|) (= ~systemActive~0 1) (= ~pumpRunning~0 0)) [2021-12-16 00:59:20,798 INFO L858 garLoopResultBuilder]: For program point L336(lines 336 342) no Hoare annotation was computed. [2021-12-16 00:59:20,798 INFO L858 garLoopResultBuilder]: For program point L336-1(lines 336 342) no Hoare annotation was computed. [2021-12-16 00:59:20,798 INFO L858 garLoopResultBuilder]: For program point L142(lines 142 149) no Hoare annotation was computed. [2021-12-16 00:59:20,798 INFO L861 garLoopResultBuilder]: At program point L365(lines 306 369) the Hoare annotation is: true [2021-12-16 00:59:20,798 INFO L858 garLoopResultBuilder]: For program point L142-2(lines 142 149) no Hoare annotation was computed. [2021-12-16 00:59:20,798 INFO L854 garLoopResultBuilder]: At program point L328(line 328) the Hoare annotation is: (let ((.cse0 (= |ULTIMATE.start_test_~splverifierCounter~0#1| 0)) (.cse1 (= 1 |ULTIMATE.start_valid_product_#res#1|)) (.cse2 (= 1 |ULTIMATE.start_main_~tmp~0#1|)) (.cse3 (= ~systemActive~0 1))) (or (and .cse0 .cse1 (<= 1 ~pumpRunning~0) .cse2 (<= 2 ~waterLevel~0) .cse3) (and .cse0 .cse1 .cse2 (= ~methAndRunningLastTime~0 0) (<= 1 ~waterLevel~0) .cse3 (= ~pumpRunning~0 0)))) [2021-12-16 00:59:20,799 INFO L854 garLoopResultBuilder]: At program point processEnvironment__wrappee__highWaterSensorENTRY(lines 408 432) the Hoare annotation is: (let ((.cse0 (not (<= 1 ~waterLevel~0))) (.cse1 (not (= |old(~pumpRunning~0)| 0))) (.cse2 (not (= ~systemActive~0 1))) (.cse3 (= ~pumpRunning~0 0))) (and (or .cse0 .cse1 (not (= ~methAndRunningLastTime~0 0)) .cse2 .cse3) (or .cse0 .cse1 (not (= ~methaneLevelCritical~0 0)) .cse2 .cse3))) [2021-12-16 00:59:20,799 INFO L854 garLoopResultBuilder]: At program point L250(lines 241 254) the Hoare annotation is: (let ((.cse4 (= ~pumpRunning~0 0))) (let ((.cse1 (not (= ~methAndRunningLastTime~0 0))) (.cse3 (<= 2 ~waterLevel~0)) (.cse5 (and (not (= |processEnvironment__wrappee__highWaterSensor_isHighWaterSensorDry_#res#1| 0)) .cse4)) (.cse0 (not (= |old(~pumpRunning~0)| 0))) (.cse2 (not (= ~systemActive~0 1)))) (and (or .cse0 .cse1 .cse2 (not .cse3) .cse4) (or .cse5 (not (= ~waterLevel~0 1)) .cse0 .cse1 .cse2) (or (and .cse3 .cse4) .cse5 (not (<= 1 ~waterLevel~0)) .cse0 (not (= ~methaneLevelCritical~0 0)) .cse2)))) [2021-12-16 00:59:20,799 INFO L854 garLoopResultBuilder]: At program point L422(line 422) the Hoare annotation is: (let ((.cse4 (= ~systemActive~0 1))) (let ((.cse0 (and (= |processEnvironment__wrappee__highWaterSensor_~tmp~3#1| 0) .cse4 (= ~pumpRunning~0 0))) (.cse1 (not (<= 1 ~waterLevel~0))) (.cse2 (not (= |old(~pumpRunning~0)| 0))) (.cse3 (not .cse4))) (and (or .cse0 .cse1 .cse2 (not (= ~methaneLevelCritical~0 0)) .cse3) (or .cse0 .cse1 .cse2 (not (= ~methAndRunningLastTime~0 0)) .cse3)))) [2021-12-16 00:59:20,799 INFO L854 garLoopResultBuilder]: At program point L546(lines 531 549) the Hoare annotation is: (let ((.cse5 (= ~systemActive~0 1))) (let ((.cse0 (and (<= 2 ~waterLevel~0) (= ~pumpRunning~0 0))) (.cse1 (and (not (= 0 |processEnvironment__wrappee__highWaterSensor_isHighWaterLevel_~tmp~5#1|)) (= |processEnvironment__wrappee__highWaterSensor_isHighWaterLevel_#res#1| 0) (= ~pumpRunning~0 |old(~pumpRunning~0)|) (= |processEnvironment__wrappee__highWaterSensor_isHighWaterLevel_~tmp___0~2#1| 0) .cse5)) (.cse2 (not (<= 1 ~waterLevel~0))) (.cse3 (not (= |old(~pumpRunning~0)| 0))) (.cse4 (not .cse5))) (and (or .cse0 .cse1 .cse2 .cse3 (not (= ~methAndRunningLastTime~0 0)) .cse4) (or .cse0 .cse1 .cse2 .cse3 (not (= ~methaneLevelCritical~0 0)) .cse4)))) [2021-12-16 00:59:20,799 INFO L858 garLoopResultBuilder]: For program point L416(lines 416 424) no Hoare annotation was computed. [2021-12-16 00:59:20,799 INFO L858 garLoopResultBuilder]: For program point L412(lines 412 429) no Hoare annotation was computed. [2021-12-16 00:59:20,799 INFO L858 garLoopResultBuilder]: For program point L540(lines 540 544) no Hoare annotation was computed. [2021-12-16 00:59:20,800 INFO L858 garLoopResultBuilder]: For program point processEnvironment__wrappee__highWaterSensorEXIT(lines 408 432) no Hoare annotation was computed. [2021-12-16 00:59:20,800 INFO L858 garLoopResultBuilder]: For program point L540-2(lines 540 544) no Hoare annotation was computed. [2021-12-16 00:59:20,800 INFO L858 garLoopResultBuilder]: For program point L245(lines 245 251) no Hoare annotation was computed. [2021-12-16 00:59:20,800 INFO L854 garLoopResultBuilder]: At program point L464(lines 459 466) the Hoare annotation is: (let ((.cse0 (and (<= 1 ~pumpRunning~0) (<= 2 ~waterLevel~0))) (.cse1 (not (<= 1 ~waterLevel~0))) (.cse2 (not (= |old(~pumpRunning~0)| 0))) (.cse3 (not (= ~systemActive~0 1)))) (and (or .cse0 .cse1 .cse2 (not (= ~methaneLevelCritical~0 0)) .cse3) (or .cse0 .cse1 .cse2 (not (= ~methAndRunningLastTime~0 0)) .cse3))) [2021-12-16 00:59:20,800 INFO L854 garLoopResultBuilder]: At program point L427(line 427) the Hoare annotation is: (let ((.cse0 (not (<= 1 ~waterLevel~0))) (.cse1 (not (= |old(~pumpRunning~0)| 0))) (.cse2 (not (= ~systemActive~0 1)))) (and (or .cse0 .cse1 (not (= ~methaneLevelCritical~0 0)) .cse2) (or .cse0 .cse1 (not (= ~methAndRunningLastTime~0 0)) .cse2))) [2021-12-16 00:59:20,800 INFO L858 garLoopResultBuilder]: For program point L427-1(lines 408 432) no Hoare annotation was computed. [2021-12-16 00:59:20,800 INFO L858 garLoopResultBuilder]: For program point waterRiseEXIT(lines 176 187) no Hoare annotation was computed. [2021-12-16 00:59:20,800 INFO L854 garLoopResultBuilder]: At program point waterRiseENTRY(lines 176 187) the Hoare annotation is: (let ((.cse4 (not (<= 2 |old(~waterLevel~0)|))) (.cse0 (not (= ~pumpRunning~0 0))) (.cse1 (= ~waterLevel~0 |old(~waterLevel~0)|)) (.cse2 (not (= ~methAndRunningLastTime~0 0))) (.cse3 (not (= ~systemActive~0 1)))) (and (or (not (= |old(~waterLevel~0)| 1)) .cse0 .cse1 .cse2 .cse3) (or .cse4 (not (<= 1 ~pumpRunning~0)) .cse1 .cse3) (or .cse4 .cse0 .cse1 .cse2 .cse3))) [2021-12-16 00:59:20,801 INFO L858 garLoopResultBuilder]: For program point L180-1(lines 176 187) no Hoare annotation was computed. [2021-12-16 00:59:20,803 INFO L732 BasicCegarLoop]: Path program histogram: [1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2021-12-16 00:59:20,804 INFO L179 ceAbstractionStarter]: Computing trace abstraction results [2021-12-16 00:59:20,826 INFO L202 PluginConnector]: Adding new model de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction CFG 16.12 12:59:20 BoogieIcfgContainer [2021-12-16 00:59:20,826 INFO L132 PluginConnector]: ------------------------ END TraceAbstraction---------------------------- [2021-12-16 00:59:20,827 INFO L113 PluginConnector]: ------------------------Witness Printer---------------------------- [2021-12-16 00:59:20,827 INFO L271 PluginConnector]: Initializing Witness Printer... [2021-12-16 00:59:20,827 INFO L275 PluginConnector]: Witness Printer initialized [2021-12-16 00:59:20,828 INFO L185 PluginConnector]: Executing the observer RCFGCatcher from plugin Witness Printer for "de.uni_freiburg.informatik.ultimate.plugins.generator.rcfgbuilder CFG 16.12 12:59:13" (3/4) ... [2021-12-16 00:59:20,830 INFO L137 WitnessPrinter]: Generating witness for correct program [2021-12-16 00:59:20,835 INFO L354 RCFGBacktranslator]: Ignoring RootEdge to procedure processEnvironment__wrappee__base [2021-12-16 00:59:20,835 INFO L354 RCFGBacktranslator]: Ignoring RootEdge to procedure changeMethaneLevel [2021-12-16 00:59:20,836 INFO L354 RCFGBacktranslator]: Ignoring RootEdge to procedure isMethaneLevelCritical [2021-12-16 00:59:20,836 INFO L354 RCFGBacktranslator]: Ignoring RootEdge to procedure timeShift [2021-12-16 00:59:20,836 INFO L354 RCFGBacktranslator]: Ignoring RootEdge to procedure cleanup [2021-12-16 00:59:20,836 INFO L354 RCFGBacktranslator]: Ignoring RootEdge to procedure processEnvironment__wrappee__highWaterSensor [2021-12-16 00:59:20,836 INFO L354 RCFGBacktranslator]: Ignoring RootEdge to procedure waterRise [2021-12-16 00:59:20,842 INFO L910 BoogieBacktranslator]: Reduced CFG by removing 52 nodes and edges [2021-12-16 00:59:20,842 INFO L910 BoogieBacktranslator]: Reduced CFG by removing 22 nodes and edges [2021-12-16 00:59:20,843 INFO L910 BoogieBacktranslator]: Reduced CFG by removing 11 nodes and edges [2021-12-16 00:59:20,843 INFO L910 BoogieBacktranslator]: Reduced CFG by removing 5 nodes and edges [2021-12-16 00:59:20,844 INFO L910 BoogieBacktranslator]: Reduced CFG by removing 2 nodes and edges [2021-12-16 00:59:20,844 INFO L910 BoogieBacktranslator]: Reduced CFG by removing 1 nodes and edges [2021-12-16 00:59:20,844 INFO L910 BoogieBacktranslator]: Reduced CFG by removing 1 nodes and edges [2021-12-16 00:59:20,862 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: ((((waterLevel == 1 && methaneLevelCritical == 0) && 1 == \result) && methAndRunningLastTime == 0) && systemActive == 1) && pumpRunning == 0 [2021-12-16 00:59:20,862 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (((((waterLevel == 1 && methaneLevelCritical == 0) && 1 == \result) && methAndRunningLastTime == 0) && 1 == tmp) && systemActive == 1) && pumpRunning == 0 [2021-12-16 00:59:20,863 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (((((waterLevel == 1 && methaneLevelCritical == 0) && 1 == \result) && methAndRunningLastTime == 0) && 1 == tmp) && systemActive == 1) && pumpRunning == 0 [2021-12-16 00:59:20,863 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (((((splverifierCounter == 0 && 1 == \result) && 1 <= pumpRunning) && 1 == tmp) && 2 <= waterLevel) && systemActive == 1) || ((((((splverifierCounter == 0 && 1 == \result) && 1 == tmp) && methAndRunningLastTime == 0) && 1 <= waterLevel) && systemActive == 1) && pumpRunning == 0) [2021-12-16 00:59:20,863 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (((((!(2 <= \old(waterLevel)) || methAndRunningLastTime == 0) || !(systemActive == 1)) || !(1 <= \old(pumpRunning))) || !(\old(methAndRunningLastTime) == 0)) && (((!(2 <= \old(waterLevel)) || (pumpRunning == \old(pumpRunning) && 1 <= waterLevel)) || !(systemActive == 1)) || !(1 <= \old(pumpRunning)))) && (((!(\old(pumpRunning) == 0) || !(systemActive == 1)) || !(1 <= \old(waterLevel))) || !(\old(methAndRunningLastTime) == 0)) [2021-12-16 00:59:20,864 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (((((!(\old(waterLevel) == 1) || !(\old(pumpRunning) == 0)) || methAndRunningLastTime == 0) || !(systemActive == 1)) || !(\old(methAndRunningLastTime) == 0)) && ((((((((waterLevel == \old(waterLevel) && 1 <= pumpRunning) && 2 <= waterLevel) && methAndRunningLastTime == 0) || (waterLevel == \old(waterLevel) && pumpRunning == 0)) || !(\old(pumpRunning) == 0)) || !(systemActive == 1)) || !(1 <= \old(waterLevel))) || !(\old(methAndRunningLastTime) == 0))) && (((!(2 <= \old(waterLevel)) || ((((((1 <= tmp___0 && 1 <= tmp) && 1 <= \result) && \result == 0) && 1 <= waterLevel) && tmp == 0) && pumpRunning == 0)) || !(systemActive == 1)) || !(1 <= \old(pumpRunning))) [2021-12-16 00:59:20,864 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: ((((((((!(\old(waterLevel) == 1) || ((waterLevel == 1 && methAndRunningLastTime == 0) && pumpRunning == 0)) || !(\old(pumpRunning) == 0)) || !(systemActive == 1)) || !(\old(methAndRunningLastTime) == 0)) && ((((!(2 <= \old(waterLevel)) || tmp == 0) || !(methaneLevelCritical == 0)) || !(systemActive == 1)) || !(1 <= \old(pumpRunning)))) && (((((tmp == 0 || !(\old(waterLevel) == 1)) || !(\old(pumpRunning) == 0)) || !(methaneLevelCritical == 0)) || !(systemActive == 1)) || !(\old(methAndRunningLastTime) == 0))) && (((((!(2 <= \old(waterLevel)) || ((waterLevel == \old(waterLevel) && pumpRunning == \old(pumpRunning)) && methAndRunningLastTime == 0)) || (waterLevel == \old(waterLevel) && 1 <= pumpRunning)) || !(\old(pumpRunning) == 0)) || !(systemActive == 1)) || !(\old(methAndRunningLastTime) == 0))) && (((((!(2 <= \old(waterLevel)) || (tmp == 0 && methAndRunningLastTime == 0)) || !(\old(pumpRunning) == 0)) || !(methaneLevelCritical == 0)) || !(systemActive == 1)) || !(\old(methAndRunningLastTime) == 0))) && (((!(2 <= \old(waterLevel)) || (((((((1 <= tmp___0 && 1 <= tmp) && 1 <= \result) && \result == 0) && methAndRunningLastTime == 0) && 1 <= waterLevel) && tmp == 0) && pumpRunning == 0)) || !(systemActive == 1)) || !(1 <= \old(pumpRunning))) [2021-12-16 00:59:20,865 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: ((((((!(2 <= \old(waterLevel)) || !(methaneLevelCritical == 0)) || !(systemActive == 1)) || !(1 <= \old(pumpRunning))) && ((((!(\old(waterLevel) == 1) || !(\old(pumpRunning) == 0)) || methAndRunningLastTime == 0) || !(systemActive == 1)) || !(\old(methAndRunningLastTime) == 0))) && ((((((((waterLevel == \old(waterLevel) && 1 <= pumpRunning) && 2 <= waterLevel) && methAndRunningLastTime == 0) || ((\result == 0 && waterLevel == \old(waterLevel)) && pumpRunning == 0)) || !(\old(pumpRunning) == 0)) || !(systemActive == 1)) || !(1 <= \old(waterLevel))) || !(\old(methAndRunningLastTime) == 0))) && ((((!(\old(pumpRunning) == 0) || !(methaneLevelCritical == 0)) || !(systemActive == 1)) || !(1 <= \old(waterLevel))) || !(\old(methAndRunningLastTime) == 0))) && (((!(2 <= \old(waterLevel)) || (((((((1 <= tmp___0 && 1 <= tmp) && \result == 0) && 1 <= \result) && \result == 0) && 1 <= waterLevel) && tmp == 0) && pumpRunning == 0)) || !(systemActive == 1)) || !(1 <= \old(pumpRunning))) [2021-12-16 00:59:20,865 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (((((!(2 <= \old(waterLevel)) || methAndRunningLastTime == 0) || !(systemActive == 1)) || !(1 <= \old(pumpRunning))) || !(\old(methAndRunningLastTime) == 0)) && (((!(2 <= \old(waterLevel)) || !(systemActive == 1)) || ((pumpRunning == \old(pumpRunning) && \result == 0) && 1 <= waterLevel)) || !(1 <= \old(pumpRunning)))) && (((!(\old(pumpRunning) == 0) || !(systemActive == 1)) || !(1 <= \old(waterLevel))) || !(\old(methAndRunningLastTime) == 0)) [2021-12-16 00:59:20,865 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (((((!(\old(pumpRunning) == 0) || !(methAndRunningLastTime == 0)) || !(systemActive == 1)) || !(2 <= waterLevel)) || pumpRunning == 0) && (((((!(\result == 0) && pumpRunning == 0) || !(waterLevel == 1)) || !(\old(pumpRunning) == 0)) || !(methAndRunningLastTime == 0)) || !(systemActive == 1))) && ((((((2 <= waterLevel && pumpRunning == 0) || (!(\result == 0) && pumpRunning == 0)) || !(1 <= waterLevel)) || !(\old(pumpRunning) == 0)) || !(methaneLevelCritical == 0)) || !(systemActive == 1)) [2021-12-16 00:59:20,865 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (((((!(2 <= \old(waterLevel)) || methAndRunningLastTime == 0) || !(systemActive == 1)) || !(1 <= \old(pumpRunning))) || !(\old(methAndRunningLastTime) == 0)) && (((!(\old(pumpRunning) == 0) || !(systemActive == 1)) || !(1 <= \old(waterLevel))) || !(\old(methAndRunningLastTime) == 0))) && (((!(2 <= \old(waterLevel)) || (((((1 <= tmp___0 && 1 <= \result) && pumpRunning == \old(pumpRunning)) && \result == 0) && 1 <= waterLevel) && tmp == 0)) || !(systemActive == 1)) || !(1 <= \old(pumpRunning))) [2021-12-16 00:59:20,865 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: ((!(2 <= \old(waterLevel)) || !(systemActive == 1)) || !(1 <= \old(pumpRunning))) && (((!(\old(pumpRunning) == 0) || !(systemActive == 1)) || !(1 <= \old(waterLevel))) || !(\old(methAndRunningLastTime) == 0)) [2021-12-16 00:59:20,866 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: ((((((2 <= waterLevel && pumpRunning == 0) || ((((!(0 == tmp) && \result == 0) && pumpRunning == \old(pumpRunning)) && tmp___0 == 0) && systemActive == 1)) || !(1 <= waterLevel)) || !(\old(pumpRunning) == 0)) || !(methAndRunningLastTime == 0)) || !(systemActive == 1)) && ((((((2 <= waterLevel && pumpRunning == 0) || ((((!(0 == tmp) && \result == 0) && pumpRunning == \old(pumpRunning)) && tmp___0 == 0) && systemActive == 1)) || !(1 <= waterLevel)) || !(\old(pumpRunning) == 0)) || !(methaneLevelCritical == 0)) || !(systemActive == 1)) [2021-12-16 00:59:20,866 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (((!(\old(pumpRunning) == 0) || !(systemActive == 1)) || !(1 <= \old(waterLevel))) || !(\old(methAndRunningLastTime) == 0)) && (((!(2 <= \old(waterLevel)) || ((((((1 <= tmp___0 && 1 <= tmp) && 1 <= \result) && \result == 0) && 1 <= waterLevel) && tmp == 0) && pumpRunning == 0)) || !(systemActive == 1)) || !(1 <= \old(pumpRunning))) [2021-12-16 00:59:20,866 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (((((1 <= pumpRunning && 2 <= waterLevel) || !(1 <= waterLevel)) || !(\old(pumpRunning) == 0)) || !(methaneLevelCritical == 0)) || !(systemActive == 1)) && (((((1 <= pumpRunning && 2 <= waterLevel) || !(1 <= waterLevel)) || !(\old(pumpRunning) == 0)) || !(methAndRunningLastTime == 0)) || !(systemActive == 1)) [2021-12-16 00:59:20,882 INFO L141 WitnessManager]: Wrote witness to /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/witness.graphml [2021-12-16 00:59:20,883 INFO L132 PluginConnector]: ------------------------ END Witness Printer---------------------------- [2021-12-16 00:59:20,883 INFO L158 Benchmark]: Toolchain (without parser) took 8174.07ms. Allocated memory was 96.5MB in the beginning and 220.2MB in the end (delta: 123.7MB). Free memory was 59.8MB in the beginning and 74.5MB in the end (delta: -14.7MB). Peak memory consumption was 110.1MB. Max. memory is 16.1GB. [2021-12-16 00:59:20,883 INFO L158 Benchmark]: CDTParser took 0.17ms. Allocated memory is still 96.5MB. Free memory is still 77.2MB. There was no memory consumed. Max. memory is 16.1GB. [2021-12-16 00:59:20,884 INFO L158 Benchmark]: CACSL2BoogieTranslator took 340.72ms. Allocated memory is still 96.5MB. Free memory was 59.6MB in the beginning and 64.7MB in the end (delta: -5.1MB). Peak memory consumption was 8.4MB. Max. memory is 16.1GB. [2021-12-16 00:59:20,884 INFO L158 Benchmark]: Boogie Procedure Inliner took 72.50ms. Allocated memory is still 96.5MB. Free memory was 64.7MB in the beginning and 62.2MB in the end (delta: 2.6MB). Peak memory consumption was 2.1MB. Max. memory is 16.1GB. [2021-12-16 00:59:20,884 INFO L158 Benchmark]: Boogie Preprocessor took 45.36ms. Allocated memory is still 96.5MB. Free memory was 62.2MB in the beginning and 61.0MB in the end (delta: 1.2MB). Peak memory consumption was 2.1MB. Max. memory is 16.1GB. [2021-12-16 00:59:20,884 INFO L158 Benchmark]: RCFGBuilder took 366.33ms. Allocated memory is still 96.5MB. Free memory was 61.0MB in the beginning and 44.2MB in the end (delta: 16.8MB). Peak memory consumption was 16.8MB. Max. memory is 16.1GB. [2021-12-16 00:59:20,885 INFO L158 Benchmark]: TraceAbstraction took 7283.69ms. Allocated memory was 96.5MB in the beginning and 220.2MB in the end (delta: 123.7MB). Free memory was 43.7MB in the beginning and 80.8MB in the end (delta: -37.0MB). Peak memory consumption was 93.8MB. Max. memory is 16.1GB. [2021-12-16 00:59:20,885 INFO L158 Benchmark]: Witness Printer took 55.69ms. Allocated memory is still 220.2MB. Free memory was 80.8MB in the beginning and 74.5MB in the end (delta: 6.3MB). Peak memory consumption was 6.3MB. Max. memory is 16.1GB. [2021-12-16 00:59:20,886 INFO L339 ainManager$Toolchain]: ####################### End [Toolchain 1] ####################### --- Results --- * Results from de.uni_freiburg.informatik.ultimate.core: - StatisticsResult: Toolchain Benchmarks Benchmark results are: * CDTParser took 0.17ms. Allocated memory is still 96.5MB. Free memory is still 77.2MB. There was no memory consumed. Max. memory is 16.1GB. * CACSL2BoogieTranslator took 340.72ms. Allocated memory is still 96.5MB. Free memory was 59.6MB in the beginning and 64.7MB in the end (delta: -5.1MB). Peak memory consumption was 8.4MB. Max. memory is 16.1GB. * Boogie Procedure Inliner took 72.50ms. Allocated memory is still 96.5MB. Free memory was 64.7MB in the beginning and 62.2MB in the end (delta: 2.6MB). Peak memory consumption was 2.1MB. Max. memory is 16.1GB. * Boogie Preprocessor took 45.36ms. Allocated memory is still 96.5MB. Free memory was 62.2MB in the beginning and 61.0MB in the end (delta: 1.2MB). Peak memory consumption was 2.1MB. Max. memory is 16.1GB. * RCFGBuilder took 366.33ms. Allocated memory is still 96.5MB. Free memory was 61.0MB in the beginning and 44.2MB in the end (delta: 16.8MB). Peak memory consumption was 16.8MB. Max. memory is 16.1GB. * TraceAbstraction took 7283.69ms. Allocated memory was 96.5MB in the beginning and 220.2MB in the end (delta: 123.7MB). Free memory was 43.7MB in the beginning and 80.8MB in the end (delta: -37.0MB). Peak memory consumption was 93.8MB. Max. memory is 16.1GB. * Witness Printer took 55.69ms. Allocated memory is still 220.2MB. Free memory was 80.8MB in the beginning and 74.5MB in the end (delta: 6.3MB). Peak memory consumption was 6.3MB. Max. memory is 16.1GB. * Results from de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction: - StatisticsResult: ErrorAutomatonStatistics NumberErrorTraces: 0, NumberStatementsAllTraces: 0, NumberRelevantStatements: 0, 0.0s ErrorAutomatonConstructionTimeTotal, 0.0s FaulLocalizationTime, NumberStatementsFirstTrace: -1, TraceLengthAvg: 0, 0.0s ErrorAutomatonConstructionTimeAvg, 0.0s ErrorAutomatonDifferenceTimeAvg, 0.0s ErrorAutomatonDifferenceTimeTotal, NumberOfNoEnhancement: 0, NumberOfFiniteEnhancement: 0, NumberOfInfiniteEnhancement: 0 - PositiveResult [Line: 940]: call to reach_error is unreachable For all program executions holds that call to reach_error is unreachable at this location - StatisticsResult: Ultimate Automizer benchmark data CFG has 8 procedures, 88 locations, 1 error locations. Started 1 CEGAR loops. OverallTime: 7.2s, OverallIterations: 13, TraceHistogramMax: 2, PathProgramHistogramMax: 1, EmptinessCheckTime: 0.0s, AutomataDifference: 1.7s, DeadEndRemovalTime: 0.0s, HoareAnnotationTime: 2.4s, InitialAbstractionConstructionTime: 0.0s, PartialOrderReductionTime: 0.0s, HoareTripleCheckerStatistics: 0 mSolverCounterUnknown, 1695 SdHoareTripleChecker+Valid, 1.0s IncrementalHoareTripleChecker+Time, 0 mSdLazyCounter, 1667 mSDsluCounter, 3779 SdHoareTripleChecker+Invalid, 0.7s Time, 0 mProtectedAction, 0 SdHoareTripleChecker+Unchecked, 0 IncrementalHoareTripleChecker+Unchecked, 2408 mSDsCounter, 427 IncrementalHoareTripleChecker+Valid, 0 mProtectedPredicate, 1240 IncrementalHoareTripleChecker+Invalid, 1667 SdHoareTripleChecker+Unknown, 0 mSolverCounterNotChecked, 427 mSolverCounterUnsat, 1371 mSDtfsCounter, 1240 mSolverCounterSat, 0.0s SdHoareTripleChecker+Time, 0 IncrementalHoareTripleChecker+Unknown, PredicateUnifierStatistics: 0 DeclaredPredicates, 499 GetRequests, 389 SyntacticMatches, 3 SemanticMatches, 107 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 139 ImplicationChecksByTransitivity, 0.5s Time, 0.0s BasicInterpolantAutomatonTime, BiggestAbstraction: size=903occurred in iteration=12, InterpolantAutomatonStates: 95, traceCheckStatistics: No data available, InterpolantConsolidationStatistics: No data available, PathInvariantsStatistics: No data available, 0/0 InterpolantCoveringCapability, TotalInterpolationStatistics: No data available, 0.0s DumpTime, AutomataMinimizationStatistics: 0.3s AutomataMinimizationTime, 13 MinimizatonAttempts, 434 StatesRemovedByMinimization, 8 NontrivialMinimizations, HoareAnnotationStatistics: 0.0s HoareAnnotationTime, 40 LocationsWithAnnotation, 1597 PreInvPairs, 1740 NumberOfFragments, 1661 HoareAnnotationTreeSize, 1597 FomulaSimplifications, 117 FormulaSimplificationTreeSizeReduction, 0.2s HoareSimplificationTime, 40 FomulaSimplificationsInter, 12259 FormulaSimplificationTreeSizeReductionInter, 2.2s HoareSimplificationTimeInter, RefinementEngineStatistics: TRACE_CHECK: 0.1s SsaConstructionTime, 0.3s SatisfiabilityAnalysisTime, 1.3s InterpolantComputationTime, 953 NumberOfCodeBlocks, 953 NumberOfCodeBlocksAsserted, 16 NumberOfCheckSat, 937 ConstructedInterpolants, 0 QuantifiedInterpolants, 1637 SizeOfPredicates, 8 NumberOfNonLiveVariables, 1403 ConjunctsInSsa, 20 ConjunctsInUnsatCore, 16 InterpolantComputations, 13 PerfectInterpolantSequences, 170/178 InterpolantCoveringCapability, INVARIANT_SYNTHESIS: No data available, INTERPOLANT_CONSOLIDATION: No data available, ABSTRACT_INTERPRETATION: No data available, PDR: No data available, ACCELERATED_INTERPOLATION: No data available, SIFA: No data available, ReuseStatistics: No data available - AllSpecificationsHoldResult: All specifications hold 1 specifications checked. All of them hold - InvariantResult [Line: 531]: Loop Invariant Derived loop invariant: ((((((2 <= waterLevel && pumpRunning == 0) || ((((!(0 == tmp) && \result == 0) && pumpRunning == \old(pumpRunning)) && tmp___0 == 0) && systemActive == 1)) || !(1 <= waterLevel)) || !(\old(pumpRunning) == 0)) || !(methAndRunningLastTime == 0)) || !(systemActive == 1)) && ((((((2 <= waterLevel && pumpRunning == 0) || ((((!(0 == tmp) && \result == 0) && pumpRunning == \old(pumpRunning)) && tmp___0 == 0) && systemActive == 1)) || !(1 <= waterLevel)) || !(\old(pumpRunning) == 0)) || !(methaneLevelCritical == 0)) || !(systemActive == 1)) - InvariantResult [Line: 118]: Loop Invariant Derived loop invariant: 1 - InvariantResult [Line: 52]: Loop Invariant Derived loop invariant: 1 - InvariantResult [Line: 306]: Loop Invariant Derived loop invariant: 1 - InvariantResult [Line: 459]: Loop Invariant Derived loop invariant: (((((1 <= pumpRunning && 2 <= waterLevel) || !(1 <= waterLevel)) || !(\old(pumpRunning) == 0)) || !(methaneLevelCritical == 0)) || !(systemActive == 1)) && (((((1 <= pumpRunning && 2 <= waterLevel) || !(1 <= waterLevel)) || !(\old(pumpRunning) == 0)) || !(methAndRunningLastTime == 0)) || !(systemActive == 1)) - InvariantResult [Line: 956]: Loop Invariant Derived loop invariant: (((waterLevel == 1 && methaneLevelCritical == 0) && methAndRunningLastTime == 0) && systemActive == 1) && pumpRunning == 0 - InvariantResult [Line: 486]: Loop Invariant Derived loop invariant: ((((((!(2 <= \old(waterLevel)) || !(methaneLevelCritical == 0)) || !(systemActive == 1)) || !(1 <= \old(pumpRunning))) && ((((!(\old(waterLevel) == 1) || !(\old(pumpRunning) == 0)) || methAndRunningLastTime == 0) || !(systemActive == 1)) || !(\old(methAndRunningLastTime) == 0))) && ((((((((waterLevel == \old(waterLevel) && 1 <= pumpRunning) && 2 <= waterLevel) && methAndRunningLastTime == 0) || ((\result == 0 && waterLevel == \old(waterLevel)) && pumpRunning == 0)) || !(\old(pumpRunning) == 0)) || !(systemActive == 1)) || !(1 <= \old(waterLevel))) || !(\old(methAndRunningLastTime) == 0))) && ((((!(\old(pumpRunning) == 0) || !(methaneLevelCritical == 0)) || !(systemActive == 1)) || !(1 <= \old(waterLevel))) || !(\old(methAndRunningLastTime) == 0))) && (((!(2 <= \old(waterLevel)) || (((((((1 <= tmp___0 && 1 <= tmp) && \result == 0) && 1 <= \result) && \result == 0) && 1 <= waterLevel) && tmp == 0) && pumpRunning == 0)) || !(systemActive == 1)) || !(1 <= \old(pumpRunning))) - InvariantResult [Line: 255]: Loop Invariant Derived loop invariant: (((((!(2 <= \old(waterLevel)) || methAndRunningLastTime == 0) || !(systemActive == 1)) || !(1 <= \old(pumpRunning))) || !(\old(methAndRunningLastTime) == 0)) && (((!(2 <= \old(waterLevel)) || !(systemActive == 1)) || ((pumpRunning == \old(pumpRunning) && \result == 0) && 1 <= waterLevel)) || !(1 <= \old(pumpRunning)))) && (((!(\old(pumpRunning) == 0) || !(systemActive == 1)) || !(1 <= \old(waterLevel))) || !(\old(methAndRunningLastTime) == 0)) - InvariantResult [Line: 550]: Loop Invariant Derived loop invariant: (((((!(2 <= \old(waterLevel)) || methAndRunningLastTime == 0) || !(systemActive == 1)) || !(1 <= \old(pumpRunning))) || !(\old(methAndRunningLastTime) == 0)) && (((!(\old(pumpRunning) == 0) || !(systemActive == 1)) || !(1 <= \old(waterLevel))) || !(\old(methAndRunningLastTime) == 0))) && (((!(2 <= \old(waterLevel)) || (((((1 <= tmp___0 && 1 <= \result) && pumpRunning == \old(pumpRunning)) && \result == 0) && 1 <= waterLevel) && tmp == 0)) || !(systemActive == 1)) || !(1 <= \old(pumpRunning))) - InvariantResult [Line: 276]: Loop Invariant Derived loop invariant: ((((((((!(\old(waterLevel) == 1) || ((waterLevel == 1 && methAndRunningLastTime == 0) && pumpRunning == 0)) || !(\old(pumpRunning) == 0)) || !(systemActive == 1)) || !(\old(methAndRunningLastTime) == 0)) && ((((!(2 <= \old(waterLevel)) || tmp == 0) || !(methaneLevelCritical == 0)) || !(systemActive == 1)) || !(1 <= \old(pumpRunning)))) && (((((tmp == 0 || !(\old(waterLevel) == 1)) || !(\old(pumpRunning) == 0)) || !(methaneLevelCritical == 0)) || !(systemActive == 1)) || !(\old(methAndRunningLastTime) == 0))) && (((((!(2 <= \old(waterLevel)) || ((waterLevel == \old(waterLevel) && pumpRunning == \old(pumpRunning)) && methAndRunningLastTime == 0)) || (waterLevel == \old(waterLevel) && 1 <= pumpRunning)) || !(\old(pumpRunning) == 0)) || !(systemActive == 1)) || !(\old(methAndRunningLastTime) == 0))) && (((((!(2 <= \old(waterLevel)) || (tmp == 0 && methAndRunningLastTime == 0)) || !(\old(pumpRunning) == 0)) || !(methaneLevelCritical == 0)) || !(systemActive == 1)) || !(\old(methAndRunningLastTime) == 0))) && (((!(2 <= \old(waterLevel)) || (((((((1 <= tmp___0 && 1 <= tmp) && 1 <= \result) && \result == 0) && methAndRunningLastTime == 0) && 1 <= waterLevel) && tmp == 0) && pumpRunning == 0)) || !(systemActive == 1)) || !(1 <= \old(pumpRunning))) - InvariantResult [Line: 467]: Loop Invariant Derived loop invariant: (((!(\old(pumpRunning) == 0) || !(systemActive == 1)) || !(1 <= \old(waterLevel))) || !(\old(methAndRunningLastTime) == 0)) && (((!(2 <= \old(waterLevel)) || ((((((1 <= tmp___0 && 1 <= tmp) && 1 <= \result) && \result == 0) && 1 <= waterLevel) && tmp == 0) && pumpRunning == 0)) || !(systemActive == 1)) || !(1 <= \old(pumpRunning))) - InvariantResult [Line: 315]: Loop Invariant Derived loop invariant: 0 - InvariantResult [Line: 316]: Loop Invariant Derived loop invariant: (((((splverifierCounter == 0 && 1 == \result) && 1 <= pumpRunning) && 1 == tmp) && 2 <= waterLevel) && systemActive == 1) || ((((((splverifierCounter == 0 && 1 == \result) && 1 == tmp) && methAndRunningLastTime == 0) && 1 <= waterLevel) && systemActive == 1) && pumpRunning == 0) - InvariantResult [Line: 936]: Loop Invariant Derived loop invariant: ((!(2 <= \old(waterLevel)) || !(systemActive == 1)) || !(1 <= \old(pumpRunning))) && (((!(\old(pumpRunning) == 0) || !(systemActive == 1)) || !(1 <= \old(waterLevel))) || !(\old(methAndRunningLastTime) == 0)) - InvariantResult [Line: 963]: Loop Invariant Derived loop invariant: (((waterLevel == 1 && methaneLevelCritical == 0) && methAndRunningLastTime == 0) && systemActive == 1) && pumpRunning == 0 - InvariantResult [Line: 970]: Loop Invariant Derived loop invariant: ((((waterLevel == 1 && methaneLevelCritical == 0) && 1 == \result) && methAndRunningLastTime == 0) && systemActive == 1) && pumpRunning == 0 - InvariantResult [Line: 109]: Loop Invariant Derived loop invariant: (((((waterLevel == 1 && methaneLevelCritical == 0) && 1 == \result) && methAndRunningLastTime == 0) && 1 == tmp) && systemActive == 1) && pumpRunning == 0 - InvariantResult [Line: 268]: Loop Invariant Derived loop invariant: (((((waterLevel == 1 && methaneLevelCritical == 0) && 1 == \result) && methAndRunningLastTime == 0) && 1 == tmp) && systemActive == 1) && pumpRunning == 0 - InvariantResult [Line: 164]: Loop Invariant Derived loop invariant: (((((!(2 <= \old(waterLevel)) || methAndRunningLastTime == 0) || !(systemActive == 1)) || !(1 <= \old(pumpRunning))) || !(\old(methAndRunningLastTime) == 0)) && (((!(2 <= \old(waterLevel)) || (pumpRunning == \old(pumpRunning) && 1 <= waterLevel)) || !(systemActive == 1)) || !(1 <= \old(pumpRunning)))) && (((!(\old(pumpRunning) == 0) || !(systemActive == 1)) || !(1 <= \old(waterLevel))) || !(\old(methAndRunningLastTime) == 0)) - InvariantResult [Line: 62]: Loop Invariant Derived loop invariant: 1 - InvariantResult [Line: 241]: Loop Invariant Derived loop invariant: (((((!(\old(pumpRunning) == 0) || !(methAndRunningLastTime == 0)) || !(systemActive == 1)) || !(2 <= waterLevel)) || pumpRunning == 0) && (((((!(\result == 0) && pumpRunning == 0) || !(waterLevel == 1)) || !(\old(pumpRunning) == 0)) || !(methAndRunningLastTime == 0)) || !(systemActive == 1))) && ((((((2 <= waterLevel && pumpRunning == 0) || (!(\result == 0) && pumpRunning == 0)) || !(1 <= waterLevel)) || !(\old(pumpRunning) == 0)) || !(methaneLevelCritical == 0)) || !(systemActive == 1)) - InvariantResult [Line: 132]: Loop Invariant Derived loop invariant: 1 - InvariantResult [Line: 434]: Loop Invariant Derived loop invariant: (((((!(\old(waterLevel) == 1) || !(\old(pumpRunning) == 0)) || methAndRunningLastTime == 0) || !(systemActive == 1)) || !(\old(methAndRunningLastTime) == 0)) && ((((((((waterLevel == \old(waterLevel) && 1 <= pumpRunning) && 2 <= waterLevel) && methAndRunningLastTime == 0) || (waterLevel == \old(waterLevel) && pumpRunning == 0)) || !(\old(pumpRunning) == 0)) || !(systemActive == 1)) || !(1 <= \old(waterLevel))) || !(\old(methAndRunningLastTime) == 0))) && (((!(2 <= \old(waterLevel)) || ((((((1 <= tmp___0 && 1 <= tmp) && 1 <= \result) && \result == 0) && 1 <= waterLevel) && tmp == 0) && pumpRunning == 0)) || !(systemActive == 1)) || !(1 <= \old(pumpRunning))) RESULT: Ultimate proved your program to be correct! [2021-12-16 00:59:20,971 INFO L540 MonitoredProcess]: [MP /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in -t:2000 (1)] Forceful destruction successful, exit code 0 Received shutdown request... --- End real Ultimate output --- Execution finished normally Writing output log to file Ultimate.log Result: TRUE