./Ultimate.py --spec ../sv-benchmarks/c/properties/unreach-call.prp --file ../sv-benchmarks/c/product-lines/minepump_spec2_product52.cil.c --full-output --architecture 32bit -------------------------------------------------------------------------------- Checking for ERROR reachability Using default analysis Version c3fed411 Calling Ultimate with: /usr/bin/java -Dosgi.configuration.area=/storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/data/config -Xmx15G -Xms4m -jar /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/plugins/org.eclipse.equinox.launcher_1.5.800.v20200727-1323.jar -data @noDefault -ultimatedata /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/data -tc /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/config/AutomizerReach.xml -i ../sv-benchmarks/c/product-lines/minepump_spec2_product52.cil.c -s /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/config/svcomp-Reach-32bit-Automizer_Default.epf --cacsl2boogietranslator.entry.function main --witnessprinter.witness.directory /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux --witnessprinter.witness.filename witness.graphml --witnessprinter.write.witness.besides.input.file false --witnessprinter.graph.data.specification CHECK( init(main()), LTL(G ! call(reach_error())) ) --witnessprinter.graph.data.producer Automizer --witnessprinter.graph.data.architecture 32bit --witnessprinter.graph.data.programhash 4583285deb29d8014ded34089a46614a743cea13eee9bbb990cdfd770bfce36e --- Real Ultimate output --- This is Ultimate 0.2.2-tmp.no-commuhash-c3fed41 [2021-12-16 00:59:14,701 INFO L177 SettingsManager]: Resetting all preferences to default values... [2021-12-16 00:59:14,703 INFO L181 SettingsManager]: Resetting UltimateCore preferences to default values [2021-12-16 00:59:14,745 INFO L184 SettingsManager]: Ultimate Commandline Interface provides no preferences, ignoring... [2021-12-16 00:59:14,746 INFO L181 SettingsManager]: Resetting Boogie Preprocessor preferences to default values [2021-12-16 00:59:14,746 INFO L181 SettingsManager]: Resetting Boogie Procedure Inliner preferences to default values [2021-12-16 00:59:14,752 INFO L181 SettingsManager]: Resetting Abstract Interpretation preferences to default values [2021-12-16 00:59:14,754 INFO L181 SettingsManager]: Resetting LassoRanker preferences to default values [2021-12-16 00:59:14,755 INFO L181 SettingsManager]: Resetting Reaching Definitions preferences to default values [2021-12-16 00:59:14,755 INFO L181 SettingsManager]: Resetting SyntaxChecker preferences to default values [2021-12-16 00:59:14,756 INFO L181 SettingsManager]: Resetting Sifa preferences to default values [2021-12-16 00:59:14,757 INFO L184 SettingsManager]: Büchi Program Product provides no preferences, ignoring... [2021-12-16 00:59:14,757 INFO L181 SettingsManager]: Resetting LTL2Aut preferences to default values [2021-12-16 00:59:14,757 INFO L181 SettingsManager]: Resetting PEA to Boogie preferences to default values [2021-12-16 00:59:14,758 INFO L181 SettingsManager]: Resetting BlockEncodingV2 preferences to default values [2021-12-16 00:59:14,759 INFO L181 SettingsManager]: Resetting ChcToBoogie preferences to default values [2021-12-16 00:59:14,760 INFO L181 SettingsManager]: Resetting AutomataScriptInterpreter preferences to default values [2021-12-16 00:59:14,760 INFO L181 SettingsManager]: Resetting BuchiAutomizer preferences to default values [2021-12-16 00:59:14,761 INFO L181 SettingsManager]: Resetting CACSL2BoogieTranslator preferences to default values [2021-12-16 00:59:14,763 INFO L181 SettingsManager]: Resetting CodeCheck preferences to default values [2021-12-16 00:59:14,764 INFO L181 SettingsManager]: Resetting InvariantSynthesis preferences to default values [2021-12-16 00:59:14,764 INFO L181 SettingsManager]: Resetting RCFGBuilder preferences to default values [2021-12-16 00:59:14,765 INFO L181 SettingsManager]: Resetting Referee preferences to default values [2021-12-16 00:59:14,766 INFO L181 SettingsManager]: Resetting TraceAbstraction preferences to default values [2021-12-16 00:59:14,768 INFO L184 SettingsManager]: TraceAbstractionConcurrent provides no preferences, ignoring... [2021-12-16 00:59:14,769 INFO L184 SettingsManager]: TraceAbstractionWithAFAs provides no preferences, ignoring... [2021-12-16 00:59:14,769 INFO L181 SettingsManager]: Resetting TreeAutomizer preferences to default values [2021-12-16 00:59:14,770 INFO L181 SettingsManager]: Resetting IcfgToChc preferences to default values [2021-12-16 00:59:14,770 INFO L181 SettingsManager]: Resetting IcfgTransformer preferences to default values [2021-12-16 00:59:14,771 INFO L184 SettingsManager]: ReqToTest provides no preferences, ignoring... [2021-12-16 00:59:14,771 INFO L181 SettingsManager]: Resetting Boogie Printer preferences to default values [2021-12-16 00:59:14,771 INFO L181 SettingsManager]: Resetting ChcSmtPrinter preferences to default values [2021-12-16 00:59:14,772 INFO L181 SettingsManager]: Resetting ReqPrinter preferences to default values [2021-12-16 00:59:14,773 INFO L181 SettingsManager]: Resetting Witness Printer preferences to default values [2021-12-16 00:59:14,773 INFO L184 SettingsManager]: Boogie PL CUP Parser provides no preferences, ignoring... [2021-12-16 00:59:14,774 INFO L181 SettingsManager]: Resetting CDTParser preferences to default values [2021-12-16 00:59:14,774 INFO L184 SettingsManager]: AutomataScriptParser provides no preferences, ignoring... [2021-12-16 00:59:14,774 INFO L184 SettingsManager]: ReqParser provides no preferences, ignoring... [2021-12-16 00:59:14,774 INFO L181 SettingsManager]: Resetting SmtParser preferences to default values [2021-12-16 00:59:14,775 INFO L181 SettingsManager]: Resetting Witness Parser preferences to default values [2021-12-16 00:59:14,776 INFO L188 SettingsManager]: Finished resetting all preferences to default values... [2021-12-16 00:59:14,776 INFO L101 SettingsManager]: Beginning loading settings from /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/config/svcomp-Reach-32bit-Automizer_Default.epf [2021-12-16 00:59:14,791 INFO L113 SettingsManager]: Loading preferences was successful [2021-12-16 00:59:14,795 INFO L115 SettingsManager]: Preferences different from defaults after loading the file: [2021-12-16 00:59:14,795 INFO L136 SettingsManager]: Preferences of UltimateCore differ from their defaults: [2021-12-16 00:59:14,796 INFO L138 SettingsManager]: * Log level for class=de.uni_freiburg.informatik.ultimate.lib.smtlibutils.quantifier.QuantifierPusher=ERROR; [2021-12-16 00:59:14,796 INFO L136 SettingsManager]: Preferences of Boogie Procedure Inliner differ from their defaults: [2021-12-16 00:59:14,797 INFO L138 SettingsManager]: * Ignore calls to procedures called more than once=ONLY_FOR_SEQUENTIAL_PROGRAMS [2021-12-16 00:59:14,797 INFO L136 SettingsManager]: Preferences of BlockEncodingV2 differ from their defaults: [2021-12-16 00:59:14,797 INFO L138 SettingsManager]: * Create parallel compositions if possible=false [2021-12-16 00:59:14,797 INFO L138 SettingsManager]: * Use SBE=true [2021-12-16 00:59:14,798 INFO L136 SettingsManager]: Preferences of CACSL2BoogieTranslator differ from their defaults: [2021-12-16 00:59:14,798 INFO L138 SettingsManager]: * sizeof long=4 [2021-12-16 00:59:14,798 INFO L138 SettingsManager]: * Overapproximate operations on floating types=true [2021-12-16 00:59:14,799 INFO L138 SettingsManager]: * sizeof POINTER=4 [2021-12-16 00:59:14,799 INFO L138 SettingsManager]: * Check division by zero=IGNORE [2021-12-16 00:59:14,799 INFO L138 SettingsManager]: * Pointer to allocated memory at dereference=IGNORE [2021-12-16 00:59:14,799 INFO L138 SettingsManager]: * If two pointers are subtracted or compared they have the same base address=IGNORE [2021-12-16 00:59:14,799 INFO L138 SettingsManager]: * Check array bounds for arrays that are off heap=IGNORE [2021-12-16 00:59:14,799 INFO L138 SettingsManager]: * sizeof long double=12 [2021-12-16 00:59:14,800 INFO L138 SettingsManager]: * Check if freed pointer was valid=false [2021-12-16 00:59:14,800 INFO L138 SettingsManager]: * Use constant arrays=true [2021-12-16 00:59:14,800 INFO L138 SettingsManager]: * Pointer base address is valid at dereference=IGNORE [2021-12-16 00:59:14,800 INFO L136 SettingsManager]: Preferences of RCFGBuilder differ from their defaults: [2021-12-16 00:59:14,800 INFO L138 SettingsManager]: * Size of a code block=SequenceOfStatements [2021-12-16 00:59:14,800 INFO L138 SettingsManager]: * SMT solver=External_DefaultMode [2021-12-16 00:59:14,801 INFO L138 SettingsManager]: * Command for external solver=z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in -t:2000 [2021-12-16 00:59:14,801 INFO L136 SettingsManager]: Preferences of TraceAbstraction differ from their defaults: [2021-12-16 00:59:14,801 INFO L138 SettingsManager]: * Compute Interpolants along a Counterexample=FPandBP [2021-12-16 00:59:14,801 INFO L138 SettingsManager]: * Positions where we compute the Hoare Annotation=LoopsAndPotentialCycles [2021-12-16 00:59:14,801 INFO L138 SettingsManager]: * Trace refinement strategy=CAMEL [2021-12-16 00:59:14,801 INFO L138 SettingsManager]: * Command for external solver=z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in [2021-12-16 00:59:14,802 INFO L138 SettingsManager]: * Large block encoding in concurrent analysis=OFF [2021-12-16 00:59:14,802 INFO L138 SettingsManager]: * Automaton type used in concurrency analysis=PETRI_NET [2021-12-16 00:59:14,802 INFO L138 SettingsManager]: * Compute Hoare Annotation of negated interpolant automaton, abstraction and CFG=true [2021-12-16 00:59:14,802 INFO L138 SettingsManager]: * Trace refinement exception blacklist=NONE [2021-12-16 00:59:14,802 INFO L138 SettingsManager]: * SMT solver=External_ModelsAndUnsatCoreMode WARNING: An illegal reflective access operation has occurred WARNING: Illegal reflective access by com.sun.xml.bind.v2.runtime.reflect.opt.Injector$1 (file:/storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/plugins/com.sun.xml.bind_2.2.0.v201505121915.jar) to method java.lang.ClassLoader.defineClass(java.lang.String,byte[],int,int) WARNING: Please consider reporting this to the maintainers of com.sun.xml.bind.v2.runtime.reflect.opt.Injector$1 WARNING: Use --illegal-access=warn to enable warnings of further illegal reflective access operations WARNING: All illegal access operations will be denied in a future release Applying setting for plugin de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator: Entry function -> main Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Witness directory -> /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Witness filename -> witness.graphml Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Write witness besides input file -> false Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Graph data specification -> CHECK( init(main()), LTL(G ! call(reach_error())) ) Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Graph data producer -> Automizer Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Graph data architecture -> 32bit Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Graph data programhash -> 4583285deb29d8014ded34089a46614a743cea13eee9bbb990cdfd770bfce36e [2021-12-16 00:59:14,950 INFO L75 nceAwareModelManager]: Repository-Root is: /tmp [2021-12-16 00:59:14,972 INFO L261 ainManager$Toolchain]: [Toolchain 1]: Applicable parser(s) successfully (re)initialized [2021-12-16 00:59:14,974 INFO L217 ainManager$Toolchain]: [Toolchain 1]: Toolchain selected. [2021-12-16 00:59:14,975 INFO L271 PluginConnector]: Initializing CDTParser... [2021-12-16 00:59:14,975 INFO L275 PluginConnector]: CDTParser initialized [2021-12-16 00:59:14,976 INFO L432 ainManager$Toolchain]: [Toolchain 1]: Parsing single file: /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/../sv-benchmarks/c/product-lines/minepump_spec2_product52.cil.c [2021-12-16 00:59:15,026 INFO L220 CDTParser]: Created temporary CDT project at /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/data/ed67b3216/68da9cd8a2e24f48ae53f4eab594fa2c/FLAG136ade8b4 [2021-12-16 00:59:15,396 INFO L306 CDTParser]: Found 1 translation units. [2021-12-16 00:59:15,398 INFO L160 CDTParser]: Scanning /storage/repos/ultimate/releaseScripts/default/sv-benchmarks/c/product-lines/minepump_spec2_product52.cil.c [2021-12-16 00:59:15,411 INFO L349 CDTParser]: About to delete temporary CDT project at /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/data/ed67b3216/68da9cd8a2e24f48ae53f4eab594fa2c/FLAG136ade8b4 [2021-12-16 00:59:15,803 INFO L357 CDTParser]: Successfully deleted /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/data/ed67b3216/68da9cd8a2e24f48ae53f4eab594fa2c [2021-12-16 00:59:15,805 INFO L299 ainManager$Toolchain]: ####################### [Toolchain 1] ####################### [2021-12-16 00:59:15,805 INFO L131 ToolchainWalker]: Walking toolchain with 6 elements. [2021-12-16 00:59:15,806 INFO L113 PluginConnector]: ------------------------CACSL2BoogieTranslator---------------------------- [2021-12-16 00:59:15,806 INFO L271 PluginConnector]: Initializing CACSL2BoogieTranslator... [2021-12-16 00:59:15,808 INFO L275 PluginConnector]: CACSL2BoogieTranslator initialized [2021-12-16 00:59:15,809 INFO L185 PluginConnector]: Executing the observer ACSLObjectContainerObserver from plugin CACSL2BoogieTranslator for "CDTParser AST 16.12 12:59:15" (1/1) ... [2021-12-16 00:59:15,809 INFO L205 PluginConnector]: Invalid model from CACSL2BoogieTranslator for observer de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator.ACSLObjectContainerObserver@386cf852 and model type de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 16.12 12:59:15, skipping insertion in model container [2021-12-16 00:59:15,809 INFO L185 PluginConnector]: Executing the observer CACSL2BoogieTranslatorObserver from plugin CACSL2BoogieTranslator for "CDTParser AST 16.12 12:59:15" (1/1) ... [2021-12-16 00:59:15,813 INFO L145 MainTranslator]: Starting translation in SV-COMP mode [2021-12-16 00:59:15,855 INFO L178 MainTranslator]: Built tables and reachable declarations [2021-12-16 00:59:16,023 WARN L230 ndardFunctionHandler]: Function reach_error is already implemented but we override the implementation for the call at /storage/repos/ultimate/releaseScripts/default/sv-benchmarks/c/product-lines/minepump_spec2_product52.cil.c[19177,19190] [2021-12-16 00:59:16,029 INFO L209 PostProcessor]: Analyzing one entry point: main [2021-12-16 00:59:16,035 INFO L203 MainTranslator]: Completed pre-run [2021-12-16 00:59:16,105 WARN L230 ndardFunctionHandler]: Function reach_error is already implemented but we override the implementation for the call at /storage/repos/ultimate/releaseScripts/default/sv-benchmarks/c/product-lines/minepump_spec2_product52.cil.c[19177,19190] [2021-12-16 00:59:16,105 INFO L209 PostProcessor]: Analyzing one entry point: main [2021-12-16 00:59:16,116 INFO L208 MainTranslator]: Completed translation [2021-12-16 00:59:16,117 INFO L202 PluginConnector]: Adding new model de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 16.12 12:59:16 WrapperNode [2021-12-16 00:59:16,117 INFO L132 PluginConnector]: ------------------------ END CACSL2BoogieTranslator---------------------------- [2021-12-16 00:59:16,118 INFO L113 PluginConnector]: ------------------------Boogie Procedure Inliner---------------------------- [2021-12-16 00:59:16,118 INFO L271 PluginConnector]: Initializing Boogie Procedure Inliner... [2021-12-16 00:59:16,118 INFO L275 PluginConnector]: Boogie Procedure Inliner initialized [2021-12-16 00:59:16,122 INFO L185 PluginConnector]: Executing the observer TypeChecker from plugin Boogie Procedure Inliner for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 16.12 12:59:16" (1/1) ... [2021-12-16 00:59:16,132 INFO L185 PluginConnector]: Executing the observer Inliner from plugin Boogie Procedure Inliner for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 16.12 12:59:16" (1/1) ... [2021-12-16 00:59:16,156 INFO L137 Inliner]: procedures = 58, calls = 158, calls flagged for inlining = 24, calls inlined = 21, statements flattened = 265 [2021-12-16 00:59:16,156 INFO L132 PluginConnector]: ------------------------ END Boogie Procedure Inliner---------------------------- [2021-12-16 00:59:16,157 INFO L113 PluginConnector]: ------------------------Boogie Preprocessor---------------------------- [2021-12-16 00:59:16,157 INFO L271 PluginConnector]: Initializing Boogie Preprocessor... [2021-12-16 00:59:16,157 INFO L275 PluginConnector]: Boogie Preprocessor initialized [2021-12-16 00:59:16,163 INFO L185 PluginConnector]: Executing the observer EnsureBoogieModelObserver from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 16.12 12:59:16" (1/1) ... [2021-12-16 00:59:16,163 INFO L185 PluginConnector]: Executing the observer TypeChecker from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 16.12 12:59:16" (1/1) ... [2021-12-16 00:59:16,170 INFO L185 PluginConnector]: Executing the observer ConstExpander from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 16.12 12:59:16" (1/1) ... [2021-12-16 00:59:16,175 INFO L185 PluginConnector]: Executing the observer StructExpander from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 16.12 12:59:16" (1/1) ... [2021-12-16 00:59:16,178 INFO L185 PluginConnector]: Executing the observer UnstructureCode from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 16.12 12:59:16" (1/1) ... [2021-12-16 00:59:16,187 INFO L185 PluginConnector]: Executing the observer FunctionInliner from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 16.12 12:59:16" (1/1) ... [2021-12-16 00:59:16,187 INFO L185 PluginConnector]: Executing the observer BoogieSymbolTableConstructor from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 16.12 12:59:16" (1/1) ... [2021-12-16 00:59:16,189 INFO L132 PluginConnector]: ------------------------ END Boogie Preprocessor---------------------------- [2021-12-16 00:59:16,190 INFO L113 PluginConnector]: ------------------------RCFGBuilder---------------------------- [2021-12-16 00:59:16,194 INFO L271 PluginConnector]: Initializing RCFGBuilder... [2021-12-16 00:59:16,194 INFO L275 PluginConnector]: RCFGBuilder initialized [2021-12-16 00:59:16,195 INFO L185 PluginConnector]: Executing the observer RCFGBuilderObserver from plugin RCFGBuilder for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 16.12 12:59:16" (1/1) ... [2021-12-16 00:59:16,199 INFO L168 SolverBuilder]: Constructing external solver with command: z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in -t:2000 [2021-12-16 00:59:16,206 INFO L189 MonitoredProcess]: No working directory specified, using /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 [2021-12-16 00:59:16,214 INFO L229 MonitoredProcess]: Starting monitored process 1 with /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in -t:2000 (exit command is (exit), workingDir is null) [2021-12-16 00:59:16,221 INFO L327 MonitoredProcess]: [MP /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in -t:2000 (1)] Waiting until timeout for monitored process [2021-12-16 00:59:16,257 INFO L130 BoogieDeclarations]: Found specification of procedure #Ultimate.allocInit [2021-12-16 00:59:16,258 INFO L130 BoogieDeclarations]: Found specification of procedure processEnvironment__wrappee__base [2021-12-16 00:59:16,258 INFO L138 BoogieDeclarations]: Found implementation of procedure processEnvironment__wrappee__base [2021-12-16 00:59:16,258 INFO L130 BoogieDeclarations]: Found specification of procedure isMethaneLevelCritical [2021-12-16 00:59:16,258 INFO L138 BoogieDeclarations]: Found implementation of procedure isMethaneLevelCritical [2021-12-16 00:59:16,258 INFO L130 BoogieDeclarations]: Found specification of procedure cleanup [2021-12-16 00:59:16,258 INFO L138 BoogieDeclarations]: Found implementation of procedure cleanup [2021-12-16 00:59:16,258 INFO L130 BoogieDeclarations]: Found specification of procedure timeShift [2021-12-16 00:59:16,259 INFO L138 BoogieDeclarations]: Found implementation of procedure timeShift [2021-12-16 00:59:16,259 INFO L130 BoogieDeclarations]: Found specification of procedure processEnvironment__wrappee__highWaterSensor [2021-12-16 00:59:16,259 INFO L138 BoogieDeclarations]: Found implementation of procedure processEnvironment__wrappee__highWaterSensor [2021-12-16 00:59:16,259 INFO L130 BoogieDeclarations]: Found specification of procedure waterRise [2021-12-16 00:59:16,259 INFO L138 BoogieDeclarations]: Found implementation of procedure waterRise [2021-12-16 00:59:16,259 INFO L130 BoogieDeclarations]: Found specification of procedure deactivatePump [2021-12-16 00:59:16,259 INFO L138 BoogieDeclarations]: Found implementation of procedure deactivatePump [2021-12-16 00:59:16,259 INFO L130 BoogieDeclarations]: Found specification of procedure write~init~int [2021-12-16 00:59:16,260 INFO L130 BoogieDeclarations]: Found specification of procedure changeMethaneLevel [2021-12-16 00:59:16,260 INFO L138 BoogieDeclarations]: Found implementation of procedure changeMethaneLevel [2021-12-16 00:59:16,260 INFO L130 BoogieDeclarations]: Found specification of procedure ULTIMATE.start [2021-12-16 00:59:16,260 INFO L138 BoogieDeclarations]: Found implementation of procedure ULTIMATE.start [2021-12-16 00:59:16,369 INFO L236 CfgBuilder]: Building ICFG [2021-12-16 00:59:16,371 INFO L262 CfgBuilder]: Building CFG for each procedure with an implementation [2021-12-16 00:59:16,575 INFO L277 CfgBuilder]: Performing block encoding [2021-12-16 00:59:16,580 INFO L296 CfgBuilder]: Using the 1 location(s) as analysis (start of procedure ULTIMATE.start) [2021-12-16 00:59:16,580 INFO L301 CfgBuilder]: Removed 2 assume(true) statements. [2021-12-16 00:59:16,581 INFO L202 PluginConnector]: Adding new model de.uni_freiburg.informatik.ultimate.plugins.generator.rcfgbuilder CFG 16.12 12:59:16 BoogieIcfgContainer [2021-12-16 00:59:16,581 INFO L132 PluginConnector]: ------------------------ END RCFGBuilder---------------------------- [2021-12-16 00:59:16,582 INFO L113 PluginConnector]: ------------------------TraceAbstraction---------------------------- [2021-12-16 00:59:16,582 INFO L271 PluginConnector]: Initializing TraceAbstraction... [2021-12-16 00:59:16,593 INFO L275 PluginConnector]: TraceAbstraction initialized [2021-12-16 00:59:16,593 INFO L185 PluginConnector]: Executing the observer TraceAbstractionObserver from plugin TraceAbstraction for "CDTParser AST 16.12 12:59:15" (1/3) ... [2021-12-16 00:59:16,593 INFO L205 PluginConnector]: Invalid model from TraceAbstraction for observer de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction.TraceAbstractionObserver@11479a0a and model type de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction AST 16.12 12:59:16, skipping insertion in model container [2021-12-16 00:59:16,594 INFO L185 PluginConnector]: Executing the observer TraceAbstractionObserver from plugin TraceAbstraction for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 16.12 12:59:16" (2/3) ... [2021-12-16 00:59:16,594 INFO L205 PluginConnector]: Invalid model from TraceAbstraction for observer de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction.TraceAbstractionObserver@11479a0a and model type de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction AST 16.12 12:59:16, skipping insertion in model container [2021-12-16 00:59:16,594 INFO L185 PluginConnector]: Executing the observer TraceAbstractionObserver from plugin TraceAbstraction for "de.uni_freiburg.informatik.ultimate.plugins.generator.rcfgbuilder CFG 16.12 12:59:16" (3/3) ... [2021-12-16 00:59:16,595 INFO L111 eAbstractionObserver]: Analyzing ICFG minepump_spec2_product52.cil.c [2021-12-16 00:59:16,598 INFO L204 ceAbstractionStarter]: Automizer settings: Hoare:true NWA Interpolation:FPandBP Determinization: PREDICATE_ABSTRACTION [2021-12-16 00:59:16,599 INFO L163 ceAbstractionStarter]: Applying trace abstraction to program that has 1 error locations. [2021-12-16 00:59:16,638 INFO L338 AbstractCegarLoop]: ======== Iteration 0 == of CEGAR loop == AllErrorsAtOnce ======== [2021-12-16 00:59:16,646 INFO L339 AbstractCegarLoop]: Settings: SEPARATE_VIOLATION_CHECK=true, mInterprocedural=true, mMaxIterations=1000000, mWatchIteration=1000000, mArtifact=RCFG, mInterpolation=FPandBP, mInterpolantAutomaton=STRAIGHT_LINE, mDumpAutomata=false, mAutomataFormat=ATS_NUMERATE, mDumpPath=., mDeterminiation=PREDICATE_ABSTRACTION, mMinimize=MINIMIZE_SEVPA, mHoare=true, mAutomataTypeConcurrency=PETRI_NET, mHoareTripleChecks=INCREMENTAL, mHoareAnnotationPositions=LoopsAndPotentialCycles, mDumpOnlyReuseAutomata=false, mLimitTraceHistogram=0, mErrorLocTimeLimit=0, mLimitPathProgramCount=0, mCollectInterpolantStatistics=true, mHeuristicEmptinessCheck=false, mHeuristicEmptinessCheckAStarHeuristic=ZERO, mHeuristicEmptinessCheckAStarHeuristicRandomSeed=1337, mHeuristicEmptinessCheckSmtFeatureScoringMethod=DAGSIZE, mSMTFeatureExtraction=false, mSMTFeatureExtractionDumpPath=., mOverrideInterpolantAutomaton=false, mMcrInterpolantMethod=WP, mLoopAccelerationTechnique=FAST_UPR [2021-12-16 00:59:16,646 INFO L340 AbstractCegarLoop]: Starting to check reachability of 1 error locations. [2021-12-16 00:59:16,667 INFO L276 IsEmpty]: Start isEmpty. Operand has 96 states, 73 states have (on average 1.3835616438356164) internal successors, (101), 82 states have internal predecessors, (101), 13 states have call successors, (13), 8 states have call predecessors, (13), 8 states have return successors, (13), 10 states have call predecessors, (13), 13 states have call successors, (13) [2021-12-16 00:59:16,672 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 26 [2021-12-16 00:59:16,673 INFO L506 BasicCegarLoop]: Found error trace [2021-12-16 00:59:16,673 INFO L514 BasicCegarLoop]: trace histogram [1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2021-12-16 00:59:16,674 INFO L402 AbstractCegarLoop]: === Iteration 1 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2021-12-16 00:59:16,678 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2021-12-16 00:59:16,678 INFO L85 PathProgramCache]: Analyzing trace with hash -656399671, now seen corresponding path program 1 times [2021-12-16 00:59:16,684 INFO L121 FreeRefinementEngine]: Executing refinement strategy CAMEL [2021-12-16 00:59:16,684 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [1253064494] [2021-12-16 00:59:16,684 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2021-12-16 00:59:16,685 INFO L126 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2021-12-16 00:59:16,791 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 00:59:16,829 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 15 [2021-12-16 00:59:16,831 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 00:59:16,834 INFO L134 CoverageAnalysis]: Checked inductivity of 0 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2021-12-16 00:59:16,834 INFO L139 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2021-12-16 00:59:16,834 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [1253064494] [2021-12-16 00:59:16,835 INFO L160 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [1253064494] provided 1 perfect and 0 imperfect interpolant sequences [2021-12-16 00:59:16,835 INFO L186 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2021-12-16 00:59:16,835 INFO L199 FreeRefinementEngine]: Number of different interpolants: perfect sequences [2] imperfect sequences [] total 2 [2021-12-16 00:59:16,837 INFO L115 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [1425707589] [2021-12-16 00:59:16,837 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2021-12-16 00:59:16,840 INFO L546 AbstractCegarLoop]: INTERPOLANT automaton has 2 states [2021-12-16 00:59:16,840 INFO L103 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2021-12-16 00:59:16,860 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 2 interpolants. [2021-12-16 00:59:16,861 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=1, Invalid=1, Unknown=0, NotChecked=0, Total=2 [2021-12-16 00:59:16,863 INFO L87 Difference]: Start difference. First operand has 96 states, 73 states have (on average 1.3835616438356164) internal successors, (101), 82 states have internal predecessors, (101), 13 states have call successors, (13), 8 states have call predecessors, (13), 8 states have return successors, (13), 10 states have call predecessors, (13), 13 states have call successors, (13) Second operand has 2 states, 2 states have (on average 10.5) internal successors, (21), 2 states have internal predecessors, (21), 1 states have call successors, (3), 2 states have call predecessors, (3), 1 states have return successors, (1), 1 states have call predecessors, (1), 1 states have call successors, (1) [2021-12-16 00:59:16,901 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2021-12-16 00:59:16,901 INFO L93 Difference]: Finished difference Result 183 states and 248 transitions. [2021-12-16 00:59:16,902 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 2 states. [2021-12-16 00:59:16,903 INFO L78 Accepts]: Start accepts. Automaton has has 2 states, 2 states have (on average 10.5) internal successors, (21), 2 states have internal predecessors, (21), 1 states have call successors, (3), 2 states have call predecessors, (3), 1 states have return successors, (1), 1 states have call predecessors, (1), 1 states have call successors, (1) Word has length 25 [2021-12-16 00:59:16,903 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2021-12-16 00:59:16,909 INFO L225 Difference]: With dead ends: 183 [2021-12-16 00:59:16,910 INFO L226 Difference]: Without dead ends: 87 [2021-12-16 00:59:16,914 INFO L932 BasicCegarLoop]: 0 DeclaredPredicates, 4 GetRequests, 4 SyntacticMatches, 0 SemanticMatches, 0 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 0 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=1, Invalid=1, Unknown=0, NotChecked=0, Total=2 [2021-12-16 00:59:16,917 INFO L933 BasicCegarLoop]: 121 mSDtfsCounter, 0 mSDsluCounter, 0 mSDsCounter, 0 mSdLazyCounter, 0 mSolverCounterSat, 0 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.0s Time, 0 mProtectedPredicate, 0 mProtectedAction, 0 SdHoareTripleChecker+Valid, 121 SdHoareTripleChecker+Invalid, 0 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 0 IncrementalHoareTripleChecker+Valid, 0 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.0s IncrementalHoareTripleChecker+Time [2021-12-16 00:59:16,917 INFO L934 BasicCegarLoop]: SdHoareTripleChecker [0 Valid, 121 Invalid, 0 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [0 Valid, 0 Invalid, 0 Unknown, 0 Unchecked, 0.0s Time] [2021-12-16 00:59:16,932 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 87 states. [2021-12-16 00:59:16,954 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 87 to 87. [2021-12-16 00:59:16,956 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 87 states, 66 states have (on average 1.3181818181818181) internal successors, (87), 74 states have internal predecessors, (87), 13 states have call successors, (13), 8 states have call predecessors, (13), 7 states have return successors, (12), 9 states have call predecessors, (12), 12 states have call successors, (12) [2021-12-16 00:59:16,961 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 87 states to 87 states and 112 transitions. [2021-12-16 00:59:16,962 INFO L78 Accepts]: Start accepts. Automaton has 87 states and 112 transitions. Word has length 25 [2021-12-16 00:59:16,963 INFO L84 Accepts]: Finished accepts. word is rejected. [2021-12-16 00:59:16,963 INFO L470 AbstractCegarLoop]: Abstraction has 87 states and 112 transitions. [2021-12-16 00:59:16,963 INFO L471 AbstractCegarLoop]: INTERPOLANT automaton has has 2 states, 2 states have (on average 10.5) internal successors, (21), 2 states have internal predecessors, (21), 1 states have call successors, (3), 2 states have call predecessors, (3), 1 states have return successors, (1), 1 states have call predecessors, (1), 1 states have call successors, (1) [2021-12-16 00:59:16,964 INFO L276 IsEmpty]: Start isEmpty. Operand 87 states and 112 transitions. [2021-12-16 00:59:16,967 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 27 [2021-12-16 00:59:16,967 INFO L506 BasicCegarLoop]: Found error trace [2021-12-16 00:59:16,967 INFO L514 BasicCegarLoop]: trace histogram [1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2021-12-16 00:59:16,967 WARN L452 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable0 [2021-12-16 00:59:16,968 INFO L402 AbstractCegarLoop]: === Iteration 2 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2021-12-16 00:59:16,970 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2021-12-16 00:59:16,970 INFO L85 PathProgramCache]: Analyzing trace with hash -1991216904, now seen corresponding path program 1 times [2021-12-16 00:59:16,971 INFO L121 FreeRefinementEngine]: Executing refinement strategy CAMEL [2021-12-16 00:59:16,971 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [363617966] [2021-12-16 00:59:16,971 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2021-12-16 00:59:16,971 INFO L126 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2021-12-16 00:59:16,999 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 00:59:17,025 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 16 [2021-12-16 00:59:17,026 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 00:59:17,044 INFO L134 CoverageAnalysis]: Checked inductivity of 0 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2021-12-16 00:59:17,045 INFO L139 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2021-12-16 00:59:17,045 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [363617966] [2021-12-16 00:59:17,045 INFO L160 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [363617966] provided 1 perfect and 0 imperfect interpolant sequences [2021-12-16 00:59:17,046 INFO L186 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2021-12-16 00:59:17,046 INFO L199 FreeRefinementEngine]: Number of different interpolants: perfect sequences [3] imperfect sequences [] total 3 [2021-12-16 00:59:17,046 INFO L115 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [2122770043] [2021-12-16 00:59:17,046 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2021-12-16 00:59:17,047 INFO L546 AbstractCegarLoop]: INTERPOLANT automaton has 3 states [2021-12-16 00:59:17,048 INFO L103 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2021-12-16 00:59:17,048 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 3 interpolants. [2021-12-16 00:59:17,049 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=3, Invalid=3, Unknown=0, NotChecked=0, Total=6 [2021-12-16 00:59:17,049 INFO L87 Difference]: Start difference. First operand 87 states and 112 transitions. Second operand has 3 states, 3 states have (on average 7.333333333333333) internal successors, (22), 3 states have internal predecessors, (22), 1 states have call successors, (3), 2 states have call predecessors, (3), 1 states have return successors, (1), 1 states have call predecessors, (1), 1 states have call successors, (1) [2021-12-16 00:59:17,067 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2021-12-16 00:59:17,067 INFO L93 Difference]: Finished difference Result 134 states and 172 transitions. [2021-12-16 00:59:17,068 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 3 states. [2021-12-16 00:59:17,068 INFO L78 Accepts]: Start accepts. Automaton has has 3 states, 3 states have (on average 7.333333333333333) internal successors, (22), 3 states have internal predecessors, (22), 1 states have call successors, (3), 2 states have call predecessors, (3), 1 states have return successors, (1), 1 states have call predecessors, (1), 1 states have call successors, (1) Word has length 26 [2021-12-16 00:59:17,068 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2021-12-16 00:59:17,069 INFO L225 Difference]: With dead ends: 134 [2021-12-16 00:59:17,069 INFO L226 Difference]: Without dead ends: 78 [2021-12-16 00:59:17,069 INFO L932 BasicCegarLoop]: 0 DeclaredPredicates, 5 GetRequests, 4 SyntacticMatches, 0 SemanticMatches, 1 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 0 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=3, Invalid=3, Unknown=0, NotChecked=0, Total=6 [2021-12-16 00:59:17,070 INFO L933 BasicCegarLoop]: 99 mSDtfsCounter, 17 mSDsluCounter, 77 mSDsCounter, 0 mSdLazyCounter, 1 mSolverCounterSat, 0 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.0s Time, 0 mProtectedPredicate, 0 mProtectedAction, 21 SdHoareTripleChecker+Valid, 176 SdHoareTripleChecker+Invalid, 1 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 0 IncrementalHoareTripleChecker+Valid, 1 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.0s IncrementalHoareTripleChecker+Time [2021-12-16 00:59:17,071 INFO L934 BasicCegarLoop]: SdHoareTripleChecker [21 Valid, 176 Invalid, 1 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [0 Valid, 1 Invalid, 0 Unknown, 0 Unchecked, 0.0s Time] [2021-12-16 00:59:17,072 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 78 states. [2021-12-16 00:59:17,076 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 78 to 78. [2021-12-16 00:59:17,077 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 78 states, 60 states have (on average 1.3333333333333333) internal successors, (80), 68 states have internal predecessors, (80), 10 states have call successors, (10), 7 states have call predecessors, (10), 7 states have return successors, (10), 7 states have call predecessors, (10), 10 states have call successors, (10) [2021-12-16 00:59:17,077 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 78 states to 78 states and 100 transitions. [2021-12-16 00:59:17,078 INFO L78 Accepts]: Start accepts. Automaton has 78 states and 100 transitions. Word has length 26 [2021-12-16 00:59:17,078 INFO L84 Accepts]: Finished accepts. word is rejected. [2021-12-16 00:59:17,078 INFO L470 AbstractCegarLoop]: Abstraction has 78 states and 100 transitions. [2021-12-16 00:59:17,079 INFO L471 AbstractCegarLoop]: INTERPOLANT automaton has has 3 states, 3 states have (on average 7.333333333333333) internal successors, (22), 3 states have internal predecessors, (22), 1 states have call successors, (3), 2 states have call predecessors, (3), 1 states have return successors, (1), 1 states have call predecessors, (1), 1 states have call successors, (1) [2021-12-16 00:59:17,079 INFO L276 IsEmpty]: Start isEmpty. Operand 78 states and 100 transitions. [2021-12-16 00:59:17,080 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 32 [2021-12-16 00:59:17,081 INFO L506 BasicCegarLoop]: Found error trace [2021-12-16 00:59:17,081 INFO L514 BasicCegarLoop]: trace histogram [1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2021-12-16 00:59:17,081 WARN L452 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable1 [2021-12-16 00:59:17,081 INFO L402 AbstractCegarLoop]: === Iteration 3 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2021-12-16 00:59:17,081 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2021-12-16 00:59:17,084 INFO L85 PathProgramCache]: Analyzing trace with hash -1985117727, now seen corresponding path program 1 times [2021-12-16 00:59:17,085 INFO L121 FreeRefinementEngine]: Executing refinement strategy CAMEL [2021-12-16 00:59:17,085 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [1779931673] [2021-12-16 00:59:17,085 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2021-12-16 00:59:17,085 INFO L126 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2021-12-16 00:59:17,097 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 00:59:17,151 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 21 [2021-12-16 00:59:17,152 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 00:59:17,156 INFO L134 CoverageAnalysis]: Checked inductivity of 0 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2021-12-16 00:59:17,157 INFO L139 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2021-12-16 00:59:17,157 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [1779931673] [2021-12-16 00:59:17,157 INFO L160 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [1779931673] provided 1 perfect and 0 imperfect interpolant sequences [2021-12-16 00:59:17,158 INFO L186 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2021-12-16 00:59:17,158 INFO L199 FreeRefinementEngine]: Number of different interpolants: perfect sequences [5] imperfect sequences [] total 5 [2021-12-16 00:59:17,158 INFO L115 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [1351594867] [2021-12-16 00:59:17,158 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2021-12-16 00:59:17,159 INFO L546 AbstractCegarLoop]: INTERPOLANT automaton has 5 states [2021-12-16 00:59:17,159 INFO L103 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2021-12-16 00:59:17,159 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 5 interpolants. [2021-12-16 00:59:17,160 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=7, Invalid=13, Unknown=0, NotChecked=0, Total=20 [2021-12-16 00:59:17,160 INFO L87 Difference]: Start difference. First operand 78 states and 100 transitions. Second operand has 5 states, 5 states have (on average 5.6) internal successors, (28), 5 states have internal predecessors, (28), 2 states have call successors, (2), 2 states have call predecessors, (2), 1 states have return successors, (1), 1 states have call predecessors, (1), 1 states have call successors, (1) [2021-12-16 00:59:17,239 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2021-12-16 00:59:17,240 INFO L93 Difference]: Finished difference Result 191 states and 249 transitions. [2021-12-16 00:59:17,240 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 6 states. [2021-12-16 00:59:17,240 INFO L78 Accepts]: Start accepts. Automaton has has 5 states, 5 states have (on average 5.6) internal successors, (28), 5 states have internal predecessors, (28), 2 states have call successors, (2), 2 states have call predecessors, (2), 1 states have return successors, (1), 1 states have call predecessors, (1), 1 states have call successors, (1) Word has length 31 [2021-12-16 00:59:17,240 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2021-12-16 00:59:17,241 INFO L225 Difference]: With dead ends: 191 [2021-12-16 00:59:17,242 INFO L226 Difference]: Without dead ends: 121 [2021-12-16 00:59:17,244 INFO L932 BasicCegarLoop]: 0 DeclaredPredicates, 13 GetRequests, 7 SyntacticMatches, 0 SemanticMatches, 6 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 2 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=22, Invalid=34, Unknown=0, NotChecked=0, Total=56 [2021-12-16 00:59:17,245 INFO L933 BasicCegarLoop]: 114 mSDtfsCounter, 165 mSDsluCounter, 228 mSDsCounter, 0 mSdLazyCounter, 12 mSolverCounterSat, 21 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.0s Time, 0 mProtectedPredicate, 0 mProtectedAction, 165 SdHoareTripleChecker+Valid, 342 SdHoareTripleChecker+Invalid, 33 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 21 IncrementalHoareTripleChecker+Valid, 12 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.0s IncrementalHoareTripleChecker+Time [2021-12-16 00:59:17,245 INFO L934 BasicCegarLoop]: SdHoareTripleChecker [165 Valid, 342 Invalid, 33 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [21 Valid, 12 Invalid, 0 Unknown, 0 Unchecked, 0.0s Time] [2021-12-16 00:59:17,246 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 121 states. [2021-12-16 00:59:17,255 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 121 to 118. [2021-12-16 00:59:17,256 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 118 states, 90 states have (on average 1.3555555555555556) internal successors, (122), 101 states have internal predecessors, (122), 15 states have call successors, (15), 12 states have call predecessors, (15), 12 states have return successors, (16), 11 states have call predecessors, (16), 15 states have call successors, (16) [2021-12-16 00:59:17,256 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 118 states to 118 states and 153 transitions. [2021-12-16 00:59:17,257 INFO L78 Accepts]: Start accepts. Automaton has 118 states and 153 transitions. Word has length 31 [2021-12-16 00:59:17,257 INFO L84 Accepts]: Finished accepts. word is rejected. [2021-12-16 00:59:17,257 INFO L470 AbstractCegarLoop]: Abstraction has 118 states and 153 transitions. [2021-12-16 00:59:17,257 INFO L471 AbstractCegarLoop]: INTERPOLANT automaton has has 5 states, 5 states have (on average 5.6) internal successors, (28), 5 states have internal predecessors, (28), 2 states have call successors, (2), 2 states have call predecessors, (2), 1 states have return successors, (1), 1 states have call predecessors, (1), 1 states have call successors, (1) [2021-12-16 00:59:17,257 INFO L276 IsEmpty]: Start isEmpty. Operand 118 states and 153 transitions. [2021-12-16 00:59:17,259 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 35 [2021-12-16 00:59:17,259 INFO L506 BasicCegarLoop]: Found error trace [2021-12-16 00:59:17,259 INFO L514 BasicCegarLoop]: trace histogram [1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2021-12-16 00:59:17,259 WARN L452 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable2 [2021-12-16 00:59:17,260 INFO L402 AbstractCegarLoop]: === Iteration 4 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2021-12-16 00:59:17,260 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2021-12-16 00:59:17,260 INFO L85 PathProgramCache]: Analyzing trace with hash 1980394589, now seen corresponding path program 1 times [2021-12-16 00:59:17,260 INFO L121 FreeRefinementEngine]: Executing refinement strategy CAMEL [2021-12-16 00:59:17,260 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [1448826900] [2021-12-16 00:59:17,260 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2021-12-16 00:59:17,260 INFO L126 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2021-12-16 00:59:17,272 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 00:59:17,318 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 24 [2021-12-16 00:59:17,321 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 00:59:17,330 INFO L134 CoverageAnalysis]: Checked inductivity of 0 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2021-12-16 00:59:17,331 INFO L139 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2021-12-16 00:59:17,331 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [1448826900] [2021-12-16 00:59:17,331 INFO L160 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [1448826900] provided 1 perfect and 0 imperfect interpolant sequences [2021-12-16 00:59:17,331 INFO L186 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2021-12-16 00:59:17,331 INFO L199 FreeRefinementEngine]: Number of different interpolants: perfect sequences [6] imperfect sequences [] total 6 [2021-12-16 00:59:17,331 INFO L115 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [1680813312] [2021-12-16 00:59:17,331 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2021-12-16 00:59:17,332 INFO L546 AbstractCegarLoop]: INTERPOLANT automaton has 6 states [2021-12-16 00:59:17,332 INFO L103 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2021-12-16 00:59:17,332 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 6 interpolants. [2021-12-16 00:59:17,333 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=9, Invalid=21, Unknown=0, NotChecked=0, Total=30 [2021-12-16 00:59:17,333 INFO L87 Difference]: Start difference. First operand 118 states and 153 transitions. Second operand has 6 states, 6 states have (on average 5.166666666666667) internal successors, (31), 4 states have internal predecessors, (31), 1 states have call successors, (2), 2 states have call predecessors, (2), 1 states have return successors, (1), 1 states have call predecessors, (1), 1 states have call successors, (1) [2021-12-16 00:59:17,437 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2021-12-16 00:59:17,437 INFO L93 Difference]: Finished difference Result 336 states and 446 transitions. [2021-12-16 00:59:17,437 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 8 states. [2021-12-16 00:59:17,437 INFO L78 Accepts]: Start accepts. Automaton has has 6 states, 6 states have (on average 5.166666666666667) internal successors, (31), 4 states have internal predecessors, (31), 1 states have call successors, (2), 2 states have call predecessors, (2), 1 states have return successors, (1), 1 states have call predecessors, (1), 1 states have call successors, (1) Word has length 34 [2021-12-16 00:59:17,437 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2021-12-16 00:59:17,441 INFO L225 Difference]: With dead ends: 336 [2021-12-16 00:59:17,441 INFO L226 Difference]: Without dead ends: 226 [2021-12-16 00:59:17,442 INFO L932 BasicCegarLoop]: 0 DeclaredPredicates, 9 GetRequests, 2 SyntacticMatches, 0 SemanticMatches, 7 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 3 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=21, Invalid=51, Unknown=0, NotChecked=0, Total=72 [2021-12-16 00:59:17,444 INFO L933 BasicCegarLoop]: 107 mSDtfsCounter, 69 mSDsluCounter, 381 mSDsCounter, 0 mSdLazyCounter, 44 mSolverCounterSat, 4 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.0s Time, 0 mProtectedPredicate, 0 mProtectedAction, 71 SdHoareTripleChecker+Valid, 488 SdHoareTripleChecker+Invalid, 48 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 4 IncrementalHoareTripleChecker+Valid, 44 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.0s IncrementalHoareTripleChecker+Time [2021-12-16 00:59:17,444 INFO L934 BasicCegarLoop]: SdHoareTripleChecker [71 Valid, 488 Invalid, 48 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [4 Valid, 44 Invalid, 0 Unknown, 0 Unchecked, 0.0s Time] [2021-12-16 00:59:17,445 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 226 states. [2021-12-16 00:59:17,463 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 226 to 220. [2021-12-16 00:59:17,469 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 220 states, 165 states have (on average 1.3393939393939394) internal successors, (221), 186 states have internal predecessors, (221), 30 states have call successors, (30), 24 states have call predecessors, (30), 24 states have return successors, (34), 22 states have call predecessors, (34), 30 states have call successors, (34) [2021-12-16 00:59:17,470 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 220 states to 220 states and 285 transitions. [2021-12-16 00:59:17,471 INFO L78 Accepts]: Start accepts. Automaton has 220 states and 285 transitions. Word has length 34 [2021-12-16 00:59:17,471 INFO L84 Accepts]: Finished accepts. word is rejected. [2021-12-16 00:59:17,471 INFO L470 AbstractCegarLoop]: Abstraction has 220 states and 285 transitions. [2021-12-16 00:59:17,471 INFO L471 AbstractCegarLoop]: INTERPOLANT automaton has has 6 states, 6 states have (on average 5.166666666666667) internal successors, (31), 4 states have internal predecessors, (31), 1 states have call successors, (2), 2 states have call predecessors, (2), 1 states have return successors, (1), 1 states have call predecessors, (1), 1 states have call successors, (1) [2021-12-16 00:59:17,471 INFO L276 IsEmpty]: Start isEmpty. Operand 220 states and 285 transitions. [2021-12-16 00:59:17,472 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 39 [2021-12-16 00:59:17,472 INFO L506 BasicCegarLoop]: Found error trace [2021-12-16 00:59:17,472 INFO L514 BasicCegarLoop]: trace histogram [1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2021-12-16 00:59:17,473 WARN L452 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable3 [2021-12-16 00:59:17,473 INFO L402 AbstractCegarLoop]: === Iteration 5 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2021-12-16 00:59:17,473 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2021-12-16 00:59:17,473 INFO L85 PathProgramCache]: Analyzing trace with hash -973115463, now seen corresponding path program 1 times [2021-12-16 00:59:17,473 INFO L121 FreeRefinementEngine]: Executing refinement strategy CAMEL [2021-12-16 00:59:17,473 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [115983559] [2021-12-16 00:59:17,473 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2021-12-16 00:59:17,473 INFO L126 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2021-12-16 00:59:17,482 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 00:59:17,511 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 14 [2021-12-16 00:59:17,512 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 00:59:17,514 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 28 [2021-12-16 00:59:17,515 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 00:59:17,517 INFO L134 CoverageAnalysis]: Checked inductivity of 0 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2021-12-16 00:59:17,517 INFO L139 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2021-12-16 00:59:17,517 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [115983559] [2021-12-16 00:59:17,517 INFO L160 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [115983559] provided 1 perfect and 0 imperfect interpolant sequences [2021-12-16 00:59:17,517 INFO L186 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2021-12-16 00:59:17,517 INFO L199 FreeRefinementEngine]: Number of different interpolants: perfect sequences [6] imperfect sequences [] total 6 [2021-12-16 00:59:17,517 INFO L115 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [2047452589] [2021-12-16 00:59:17,517 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2021-12-16 00:59:17,517 INFO L546 AbstractCegarLoop]: INTERPOLANT automaton has 6 states [2021-12-16 00:59:17,518 INFO L103 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2021-12-16 00:59:17,518 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 6 interpolants. [2021-12-16 00:59:17,518 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=9, Invalid=21, Unknown=0, NotChecked=0, Total=30 [2021-12-16 00:59:17,518 INFO L87 Difference]: Start difference. First operand 220 states and 285 transitions. Second operand has 6 states, 6 states have (on average 5.5) internal successors, (33), 5 states have internal predecessors, (33), 1 states have call successors, (3), 3 states have call predecessors, (3), 1 states have return successors, (2), 1 states have call predecessors, (2), 1 states have call successors, (2) [2021-12-16 00:59:17,700 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2021-12-16 00:59:17,701 INFO L93 Difference]: Finished difference Result 510 states and 679 transitions. [2021-12-16 00:59:17,701 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 8 states. [2021-12-16 00:59:17,701 INFO L78 Accepts]: Start accepts. Automaton has has 6 states, 6 states have (on average 5.5) internal successors, (33), 5 states have internal predecessors, (33), 1 states have call successors, (3), 3 states have call predecessors, (3), 1 states have return successors, (2), 1 states have call predecessors, (2), 1 states have call successors, (2) Word has length 38 [2021-12-16 00:59:17,701 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2021-12-16 00:59:17,703 INFO L225 Difference]: With dead ends: 510 [2021-12-16 00:59:17,703 INFO L226 Difference]: Without dead ends: 298 [2021-12-16 00:59:17,703 INFO L932 BasicCegarLoop]: 0 DeclaredPredicates, 14 GetRequests, 6 SyntacticMatches, 0 SemanticMatches, 8 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 3 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=32, Invalid=58, Unknown=0, NotChecked=0, Total=90 [2021-12-16 00:59:17,704 INFO L933 BasicCegarLoop]: 93 mSDtfsCounter, 114 mSDsluCounter, 146 mSDsCounter, 0 mSdLazyCounter, 207 mSolverCounterSat, 38 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.1s Time, 0 mProtectedPredicate, 0 mProtectedAction, 119 SdHoareTripleChecker+Valid, 239 SdHoareTripleChecker+Invalid, 245 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 38 IncrementalHoareTripleChecker+Valid, 207 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.1s IncrementalHoareTripleChecker+Time [2021-12-16 00:59:17,704 INFO L934 BasicCegarLoop]: SdHoareTripleChecker [119 Valid, 239 Invalid, 245 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [38 Valid, 207 Invalid, 0 Unknown, 0 Unchecked, 0.1s Time] [2021-12-16 00:59:17,705 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 298 states. [2021-12-16 00:59:17,727 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 298 to 287. [2021-12-16 00:59:17,731 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 287 states, 216 states have (on average 1.2777777777777777) internal successors, (276), 235 states have internal predecessors, (276), 36 states have call successors, (36), 34 states have call predecessors, (36), 34 states have return successors, (51), 34 states have call predecessors, (51), 36 states have call successors, (51) [2021-12-16 00:59:17,733 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 287 states to 287 states and 363 transitions. [2021-12-16 00:59:17,733 INFO L78 Accepts]: Start accepts. Automaton has 287 states and 363 transitions. Word has length 38 [2021-12-16 00:59:17,735 INFO L84 Accepts]: Finished accepts. word is rejected. [2021-12-16 00:59:17,735 INFO L470 AbstractCegarLoop]: Abstraction has 287 states and 363 transitions. [2021-12-16 00:59:17,735 INFO L471 AbstractCegarLoop]: INTERPOLANT automaton has has 6 states, 6 states have (on average 5.5) internal successors, (33), 5 states have internal predecessors, (33), 1 states have call successors, (3), 3 states have call predecessors, (3), 1 states have return successors, (2), 1 states have call predecessors, (2), 1 states have call successors, (2) [2021-12-16 00:59:17,735 INFO L276 IsEmpty]: Start isEmpty. Operand 287 states and 363 transitions. [2021-12-16 00:59:17,737 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 53 [2021-12-16 00:59:17,737 INFO L506 BasicCegarLoop]: Found error trace [2021-12-16 00:59:17,738 INFO L514 BasicCegarLoop]: trace histogram [1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2021-12-16 00:59:17,738 WARN L452 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable4 [2021-12-16 00:59:17,738 INFO L402 AbstractCegarLoop]: === Iteration 6 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2021-12-16 00:59:17,739 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2021-12-16 00:59:17,739 INFO L85 PathProgramCache]: Analyzing trace with hash -1171118211, now seen corresponding path program 1 times [2021-12-16 00:59:17,739 INFO L121 FreeRefinementEngine]: Executing refinement strategy CAMEL [2021-12-16 00:59:17,739 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [1635068544] [2021-12-16 00:59:17,739 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2021-12-16 00:59:17,739 INFO L126 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2021-12-16 00:59:17,759 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 00:59:17,804 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 14 [2021-12-16 00:59:17,805 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 00:59:17,814 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 28 [2021-12-16 00:59:17,816 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 00:59:17,820 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 42 [2021-12-16 00:59:17,821 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 00:59:17,824 INFO L134 CoverageAnalysis]: Checked inductivity of 0 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2021-12-16 00:59:17,824 INFO L139 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2021-12-16 00:59:17,824 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [1635068544] [2021-12-16 00:59:17,824 INFO L160 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [1635068544] provided 1 perfect and 0 imperfect interpolant sequences [2021-12-16 00:59:17,824 INFO L186 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2021-12-16 00:59:17,824 INFO L199 FreeRefinementEngine]: Number of different interpolants: perfect sequences [5] imperfect sequences [] total 5 [2021-12-16 00:59:17,824 INFO L115 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [1395874978] [2021-12-16 00:59:17,824 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2021-12-16 00:59:17,824 INFO L546 AbstractCegarLoop]: INTERPOLANT automaton has 5 states [2021-12-16 00:59:17,824 INFO L103 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2021-12-16 00:59:17,825 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 5 interpolants. [2021-12-16 00:59:17,825 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=7, Invalid=13, Unknown=0, NotChecked=0, Total=20 [2021-12-16 00:59:17,825 INFO L87 Difference]: Start difference. First operand 287 states and 363 transitions. Second operand has 5 states, 5 states have (on average 9.0) internal successors, (45), 3 states have internal predecessors, (45), 3 states have call successors, (4), 4 states have call predecessors, (4), 1 states have return successors, (3), 2 states have call predecessors, (3), 2 states have call successors, (3) [2021-12-16 00:59:17,995 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2021-12-16 00:59:17,996 INFO L93 Difference]: Finished difference Result 613 states and 772 transitions. [2021-12-16 00:59:17,996 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 8 states. [2021-12-16 00:59:17,996 INFO L78 Accepts]: Start accepts. Automaton has has 5 states, 5 states have (on average 9.0) internal successors, (45), 3 states have internal predecessors, (45), 3 states have call successors, (4), 4 states have call predecessors, (4), 1 states have return successors, (3), 2 states have call predecessors, (3), 2 states have call successors, (3) Word has length 52 [2021-12-16 00:59:17,997 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2021-12-16 00:59:17,998 INFO L225 Difference]: With dead ends: 613 [2021-12-16 00:59:17,998 INFO L226 Difference]: Without dead ends: 334 [2021-12-16 00:59:17,999 INFO L932 BasicCegarLoop]: 0 DeclaredPredicates, 15 GetRequests, 9 SyntacticMatches, 0 SemanticMatches, 6 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 2 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=22, Invalid=34, Unknown=0, NotChecked=0, Total=56 [2021-12-16 00:59:17,999 INFO L933 BasicCegarLoop]: 115 mSDtfsCounter, 149 mSDsluCounter, 119 mSDsCounter, 0 mSdLazyCounter, 144 mSolverCounterSat, 42 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.1s Time, 0 mProtectedPredicate, 0 mProtectedAction, 153 SdHoareTripleChecker+Valid, 234 SdHoareTripleChecker+Invalid, 186 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 42 IncrementalHoareTripleChecker+Valid, 144 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.1s IncrementalHoareTripleChecker+Time [2021-12-16 00:59:18,000 INFO L934 BasicCegarLoop]: SdHoareTripleChecker [153 Valid, 234 Invalid, 186 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [42 Valid, 144 Invalid, 0 Unknown, 0 Unchecked, 0.1s Time] [2021-12-16 00:59:18,001 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 334 states. [2021-12-16 00:59:18,014 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 334 to 328. [2021-12-16 00:59:18,015 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 328 states, 247 states have (on average 1.2510121457489878) internal successors, (309), 266 states have internal predecessors, (309), 40 states have call successors, (40), 34 states have call predecessors, (40), 40 states have return successors, (57), 42 states have call predecessors, (57), 40 states have call successors, (57) [2021-12-16 00:59:18,016 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 328 states to 328 states and 406 transitions. [2021-12-16 00:59:18,016 INFO L78 Accepts]: Start accepts. Automaton has 328 states and 406 transitions. Word has length 52 [2021-12-16 00:59:18,016 INFO L84 Accepts]: Finished accepts. word is rejected. [2021-12-16 00:59:18,017 INFO L470 AbstractCegarLoop]: Abstraction has 328 states and 406 transitions. [2021-12-16 00:59:18,017 INFO L471 AbstractCegarLoop]: INTERPOLANT automaton has has 5 states, 5 states have (on average 9.0) internal successors, (45), 3 states have internal predecessors, (45), 3 states have call successors, (4), 4 states have call predecessors, (4), 1 states have return successors, (3), 2 states have call predecessors, (3), 2 states have call successors, (3) [2021-12-16 00:59:18,017 INFO L276 IsEmpty]: Start isEmpty. Operand 328 states and 406 transitions. [2021-12-16 00:59:18,017 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 50 [2021-12-16 00:59:18,018 INFO L506 BasicCegarLoop]: Found error trace [2021-12-16 00:59:18,018 INFO L514 BasicCegarLoop]: trace histogram [1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2021-12-16 00:59:18,018 WARN L452 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable5 [2021-12-16 00:59:18,018 INFO L402 AbstractCegarLoop]: === Iteration 7 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2021-12-16 00:59:18,018 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2021-12-16 00:59:18,018 INFO L85 PathProgramCache]: Analyzing trace with hash 1523834569, now seen corresponding path program 1 times [2021-12-16 00:59:18,019 INFO L121 FreeRefinementEngine]: Executing refinement strategy CAMEL [2021-12-16 00:59:18,019 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [1569531000] [2021-12-16 00:59:18,019 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2021-12-16 00:59:18,019 INFO L126 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2021-12-16 00:59:18,027 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 00:59:18,039 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 14 [2021-12-16 00:59:18,040 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 00:59:18,058 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 25 [2021-12-16 00:59:18,060 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 00:59:18,075 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 39 [2021-12-16 00:59:18,076 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 00:59:18,077 INFO L134 CoverageAnalysis]: Checked inductivity of 0 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2021-12-16 00:59:18,077 INFO L139 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2021-12-16 00:59:18,077 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [1569531000] [2021-12-16 00:59:18,078 INFO L160 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [1569531000] provided 1 perfect and 0 imperfect interpolant sequences [2021-12-16 00:59:18,078 INFO L186 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2021-12-16 00:59:18,078 INFO L199 FreeRefinementEngine]: Number of different interpolants: perfect sequences [7] imperfect sequences [] total 7 [2021-12-16 00:59:18,078 INFO L115 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [895001105] [2021-12-16 00:59:18,078 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2021-12-16 00:59:18,078 INFO L546 AbstractCegarLoop]: INTERPOLANT automaton has 7 states [2021-12-16 00:59:18,078 INFO L103 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2021-12-16 00:59:18,079 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 7 interpolants. [2021-12-16 00:59:18,079 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=11, Invalid=31, Unknown=0, NotChecked=0, Total=42 [2021-12-16 00:59:18,079 INFO L87 Difference]: Start difference. First operand 328 states and 406 transitions. Second operand has 7 states, 7 states have (on average 6.0) internal successors, (42), 5 states have internal predecessors, (42), 2 states have call successors, (4), 3 states have call predecessors, (4), 2 states have return successors, (3), 2 states have call predecessors, (3), 2 states have call successors, (3) [2021-12-16 00:59:18,302 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2021-12-16 00:59:18,302 INFO L93 Difference]: Finished difference Result 662 states and 831 transitions. [2021-12-16 00:59:18,303 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 9 states. [2021-12-16 00:59:18,303 INFO L78 Accepts]: Start accepts. Automaton has has 7 states, 7 states have (on average 6.0) internal successors, (42), 5 states have internal predecessors, (42), 2 states have call successors, (4), 3 states have call predecessors, (4), 2 states have return successors, (3), 2 states have call predecessors, (3), 2 states have call successors, (3) Word has length 49 [2021-12-16 00:59:18,303 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2021-12-16 00:59:18,305 INFO L225 Difference]: With dead ends: 662 [2021-12-16 00:59:18,305 INFO L226 Difference]: Without dead ends: 342 [2021-12-16 00:59:18,305 INFO L932 BasicCegarLoop]: 0 DeclaredPredicates, 18 GetRequests, 8 SyntacticMatches, 0 SemanticMatches, 10 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 3 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=46, Invalid=86, Unknown=0, NotChecked=0, Total=132 [2021-12-16 00:59:18,306 INFO L933 BasicCegarLoop]: 88 mSDtfsCounter, 123 mSDsluCounter, 170 mSDsCounter, 0 mSdLazyCounter, 266 mSolverCounterSat, 43 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.1s Time, 0 mProtectedPredicate, 0 mProtectedAction, 124 SdHoareTripleChecker+Valid, 258 SdHoareTripleChecker+Invalid, 309 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 43 IncrementalHoareTripleChecker+Valid, 266 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.2s IncrementalHoareTripleChecker+Time [2021-12-16 00:59:18,306 INFO L934 BasicCegarLoop]: SdHoareTripleChecker [124 Valid, 258 Invalid, 309 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [43 Valid, 266 Invalid, 0 Unknown, 0 Unchecked, 0.2s Time] [2021-12-16 00:59:18,306 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 342 states. [2021-12-16 00:59:18,318 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 342 to 334. [2021-12-16 00:59:18,319 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 334 states, 253 states have (on average 1.2450592885375493) internal successors, (315), 272 states have internal predecessors, (315), 40 states have call successors, (40), 34 states have call predecessors, (40), 40 states have return successors, (57), 42 states have call predecessors, (57), 40 states have call successors, (57) [2021-12-16 00:59:18,320 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 334 states to 334 states and 412 transitions. [2021-12-16 00:59:18,320 INFO L78 Accepts]: Start accepts. Automaton has 334 states and 412 transitions. Word has length 49 [2021-12-16 00:59:18,320 INFO L84 Accepts]: Finished accepts. word is rejected. [2021-12-16 00:59:18,320 INFO L470 AbstractCegarLoop]: Abstraction has 334 states and 412 transitions. [2021-12-16 00:59:18,320 INFO L471 AbstractCegarLoop]: INTERPOLANT automaton has has 7 states, 7 states have (on average 6.0) internal successors, (42), 5 states have internal predecessors, (42), 2 states have call successors, (4), 3 states have call predecessors, (4), 2 states have return successors, (3), 2 states have call predecessors, (3), 2 states have call successors, (3) [2021-12-16 00:59:18,320 INFO L276 IsEmpty]: Start isEmpty. Operand 334 states and 412 transitions. [2021-12-16 00:59:18,321 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 50 [2021-12-16 00:59:18,321 INFO L506 BasicCegarLoop]: Found error trace [2021-12-16 00:59:18,321 INFO L514 BasicCegarLoop]: trace histogram [1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2021-12-16 00:59:18,321 WARN L452 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable6 [2021-12-16 00:59:18,321 INFO L402 AbstractCegarLoop]: === Iteration 8 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2021-12-16 00:59:18,321 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2021-12-16 00:59:18,321 INFO L85 PathProgramCache]: Analyzing trace with hash -165109173, now seen corresponding path program 1 times [2021-12-16 00:59:18,322 INFO L121 FreeRefinementEngine]: Executing refinement strategy CAMEL [2021-12-16 00:59:18,322 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [1849721677] [2021-12-16 00:59:18,322 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2021-12-16 00:59:18,322 INFO L126 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2021-12-16 00:59:18,329 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 00:59:18,339 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 14 [2021-12-16 00:59:18,340 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 00:59:18,343 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 25 [2021-12-16 00:59:18,345 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 00:59:18,356 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 39 [2021-12-16 00:59:18,357 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 00:59:18,358 INFO L134 CoverageAnalysis]: Checked inductivity of 0 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2021-12-16 00:59:18,358 INFO L139 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2021-12-16 00:59:18,358 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [1849721677] [2021-12-16 00:59:18,358 INFO L160 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [1849721677] provided 1 perfect and 0 imperfect interpolant sequences [2021-12-16 00:59:18,358 INFO L186 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2021-12-16 00:59:18,358 INFO L199 FreeRefinementEngine]: Number of different interpolants: perfect sequences [6] imperfect sequences [] total 6 [2021-12-16 00:59:18,358 INFO L115 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [575435117] [2021-12-16 00:59:18,358 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2021-12-16 00:59:18,359 INFO L546 AbstractCegarLoop]: INTERPOLANT automaton has 6 states [2021-12-16 00:59:18,359 INFO L103 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2021-12-16 00:59:18,359 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 6 interpolants. [2021-12-16 00:59:18,359 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=9, Invalid=21, Unknown=0, NotChecked=0, Total=30 [2021-12-16 00:59:18,359 INFO L87 Difference]: Start difference. First operand 334 states and 412 transitions. Second operand has 6 states, 6 states have (on average 7.0) internal successors, (42), 4 states have internal predecessors, (42), 2 states have call successors, (4), 3 states have call predecessors, (4), 2 states have return successors, (3), 2 states have call predecessors, (3), 2 states have call successors, (3) [2021-12-16 00:59:18,501 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2021-12-16 00:59:18,501 INFO L93 Difference]: Finished difference Result 678 states and 855 transitions. [2021-12-16 00:59:18,502 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 7 states. [2021-12-16 00:59:18,502 INFO L78 Accepts]: Start accepts. Automaton has has 6 states, 6 states have (on average 7.0) internal successors, (42), 4 states have internal predecessors, (42), 2 states have call successors, (4), 3 states have call predecessors, (4), 2 states have return successors, (3), 2 states have call predecessors, (3), 2 states have call successors, (3) Word has length 49 [2021-12-16 00:59:18,502 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2021-12-16 00:59:18,504 INFO L225 Difference]: With dead ends: 678 [2021-12-16 00:59:18,504 INFO L226 Difference]: Without dead ends: 352 [2021-12-16 00:59:18,505 INFO L932 BasicCegarLoop]: 0 DeclaredPredicates, 15 GetRequests, 8 SyntacticMatches, 0 SemanticMatches, 7 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 0 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=27, Invalid=45, Unknown=0, NotChecked=0, Total=72 [2021-12-16 00:59:18,505 INFO L933 BasicCegarLoop]: 89 mSDtfsCounter, 128 mSDsluCounter, 130 mSDsCounter, 0 mSdLazyCounter, 197 mSolverCounterSat, 40 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.1s Time, 0 mProtectedPredicate, 0 mProtectedAction, 129 SdHoareTripleChecker+Valid, 219 SdHoareTripleChecker+Invalid, 237 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 40 IncrementalHoareTripleChecker+Valid, 197 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.1s IncrementalHoareTripleChecker+Time [2021-12-16 00:59:18,505 INFO L934 BasicCegarLoop]: SdHoareTripleChecker [129 Valid, 219 Invalid, 237 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [40 Valid, 197 Invalid, 0 Unknown, 0 Unchecked, 0.1s Time] [2021-12-16 00:59:18,506 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 352 states. [2021-12-16 00:59:18,522 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 352 to 338. [2021-12-16 00:59:18,522 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 338 states, 257 states have (on average 1.2412451361867705) internal successors, (319), 276 states have internal predecessors, (319), 40 states have call successors, (40), 34 states have call predecessors, (40), 40 states have return successors, (57), 42 states have call predecessors, (57), 40 states have call successors, (57) [2021-12-16 00:59:18,524 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 338 states to 338 states and 416 transitions. [2021-12-16 00:59:18,524 INFO L78 Accepts]: Start accepts. Automaton has 338 states and 416 transitions. Word has length 49 [2021-12-16 00:59:18,524 INFO L84 Accepts]: Finished accepts. word is rejected. [2021-12-16 00:59:18,524 INFO L470 AbstractCegarLoop]: Abstraction has 338 states and 416 transitions. [2021-12-16 00:59:18,524 INFO L471 AbstractCegarLoop]: INTERPOLANT automaton has has 6 states, 6 states have (on average 7.0) internal successors, (42), 4 states have internal predecessors, (42), 2 states have call successors, (4), 3 states have call predecessors, (4), 2 states have return successors, (3), 2 states have call predecessors, (3), 2 states have call successors, (3) [2021-12-16 00:59:18,525 INFO L276 IsEmpty]: Start isEmpty. Operand 338 states and 416 transitions. [2021-12-16 00:59:18,525 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 50 [2021-12-16 00:59:18,525 INFO L506 BasicCegarLoop]: Found error trace [2021-12-16 00:59:18,525 INFO L514 BasicCegarLoop]: trace histogram [1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2021-12-16 00:59:18,526 WARN L452 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable7 [2021-12-16 00:59:18,526 INFO L402 AbstractCegarLoop]: === Iteration 9 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2021-12-16 00:59:18,526 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2021-12-16 00:59:18,526 INFO L85 PathProgramCache]: Analyzing trace with hash 257592653, now seen corresponding path program 1 times [2021-12-16 00:59:18,526 INFO L121 FreeRefinementEngine]: Executing refinement strategy CAMEL [2021-12-16 00:59:18,527 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [564735730] [2021-12-16 00:59:18,527 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2021-12-16 00:59:18,527 INFO L126 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2021-12-16 00:59:18,534 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 00:59:18,550 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 14 [2021-12-16 00:59:18,551 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 00:59:18,556 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 25 [2021-12-16 00:59:18,557 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 00:59:18,566 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 39 [2021-12-16 00:59:18,567 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 00:59:18,568 INFO L134 CoverageAnalysis]: Checked inductivity of 0 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2021-12-16 00:59:18,568 INFO L139 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2021-12-16 00:59:18,568 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [564735730] [2021-12-16 00:59:18,568 INFO L160 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [564735730] provided 1 perfect and 0 imperfect interpolant sequences [2021-12-16 00:59:18,569 INFO L186 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2021-12-16 00:59:18,569 INFO L199 FreeRefinementEngine]: Number of different interpolants: perfect sequences [6] imperfect sequences [] total 6 [2021-12-16 00:59:18,569 INFO L115 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [612005789] [2021-12-16 00:59:18,569 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2021-12-16 00:59:18,569 INFO L546 AbstractCegarLoop]: INTERPOLANT automaton has 6 states [2021-12-16 00:59:18,569 INFO L103 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2021-12-16 00:59:18,569 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 6 interpolants. [2021-12-16 00:59:18,570 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=9, Invalid=21, Unknown=0, NotChecked=0, Total=30 [2021-12-16 00:59:18,570 INFO L87 Difference]: Start difference. First operand 338 states and 416 transitions. Second operand has 6 states, 6 states have (on average 7.0) internal successors, (42), 4 states have internal predecessors, (42), 2 states have call successors, (4), 4 states have call predecessors, (4), 2 states have return successors, (3), 2 states have call predecessors, (3), 2 states have call successors, (3) [2021-12-16 00:59:18,821 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2021-12-16 00:59:18,821 INFO L93 Difference]: Finished difference Result 1044 states and 1333 transitions. [2021-12-16 00:59:18,821 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 12 states. [2021-12-16 00:59:18,822 INFO L78 Accepts]: Start accepts. Automaton has has 6 states, 6 states have (on average 7.0) internal successors, (42), 4 states have internal predecessors, (42), 2 states have call successors, (4), 4 states have call predecessors, (4), 2 states have return successors, (3), 2 states have call predecessors, (3), 2 states have call successors, (3) Word has length 49 [2021-12-16 00:59:18,822 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2021-12-16 00:59:18,825 INFO L225 Difference]: With dead ends: 1044 [2021-12-16 00:59:18,825 INFO L226 Difference]: Without dead ends: 714 [2021-12-16 00:59:18,826 INFO L932 BasicCegarLoop]: 0 DeclaredPredicates, 21 GetRequests, 11 SyntacticMatches, 0 SemanticMatches, 10 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 15 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=40, Invalid=92, Unknown=0, NotChecked=0, Total=132 [2021-12-16 00:59:18,835 INFO L933 BasicCegarLoop]: 137 mSDtfsCounter, 314 mSDsluCounter, 146 mSDsCounter, 0 mSdLazyCounter, 251 mSolverCounterSat, 119 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.2s Time, 0 mProtectedPredicate, 0 mProtectedAction, 317 SdHoareTripleChecker+Valid, 283 SdHoareTripleChecker+Invalid, 370 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 119 IncrementalHoareTripleChecker+Valid, 251 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.2s IncrementalHoareTripleChecker+Time [2021-12-16 00:59:18,835 INFO L934 BasicCegarLoop]: SdHoareTripleChecker [317 Valid, 283 Invalid, 370 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [119 Valid, 251 Invalid, 0 Unknown, 0 Unchecked, 0.2s Time] [2021-12-16 00:59:18,836 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 714 states. [2021-12-16 00:59:18,855 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 714 to 712. [2021-12-16 00:59:18,856 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 712 states, 539 states have (on average 1.2133580705009277) internal successors, (654), 574 states have internal predecessors, (654), 88 states have call successors, (88), 84 states have call predecessors, (88), 84 states have return successors, (136), 86 states have call predecessors, (136), 88 states have call successors, (136) [2021-12-16 00:59:18,858 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 712 states to 712 states and 878 transitions. [2021-12-16 00:59:18,858 INFO L78 Accepts]: Start accepts. Automaton has 712 states and 878 transitions. Word has length 49 [2021-12-16 00:59:18,858 INFO L84 Accepts]: Finished accepts. word is rejected. [2021-12-16 00:59:18,858 INFO L470 AbstractCegarLoop]: Abstraction has 712 states and 878 transitions. [2021-12-16 00:59:18,858 INFO L471 AbstractCegarLoop]: INTERPOLANT automaton has has 6 states, 6 states have (on average 7.0) internal successors, (42), 4 states have internal predecessors, (42), 2 states have call successors, (4), 4 states have call predecessors, (4), 2 states have return successors, (3), 2 states have call predecessors, (3), 2 states have call successors, (3) [2021-12-16 00:59:18,858 INFO L276 IsEmpty]: Start isEmpty. Operand 712 states and 878 transitions. [2021-12-16 00:59:18,859 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 54 [2021-12-16 00:59:18,859 INFO L506 BasicCegarLoop]: Found error trace [2021-12-16 00:59:18,859 INFO L514 BasicCegarLoop]: trace histogram [1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2021-12-16 00:59:18,859 WARN L452 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable8 [2021-12-16 00:59:18,859 INFO L402 AbstractCegarLoop]: === Iteration 10 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2021-12-16 00:59:18,860 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2021-12-16 00:59:18,860 INFO L85 PathProgramCache]: Analyzing trace with hash -715401485, now seen corresponding path program 1 times [2021-12-16 00:59:18,860 INFO L121 FreeRefinementEngine]: Executing refinement strategy CAMEL [2021-12-16 00:59:18,860 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [35486186] [2021-12-16 00:59:18,860 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2021-12-16 00:59:18,860 INFO L126 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2021-12-16 00:59:18,867 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 00:59:18,892 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 12 [2021-12-16 00:59:18,895 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 00:59:18,901 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 18 [2021-12-16 00:59:18,905 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 00:59:18,910 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 29 [2021-12-16 00:59:18,911 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 00:59:18,914 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 43 [2021-12-16 00:59:18,914 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 00:59:18,916 INFO L134 CoverageAnalysis]: Checked inductivity of 0 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2021-12-16 00:59:18,916 INFO L139 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2021-12-16 00:59:18,916 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [35486186] [2021-12-16 00:59:18,916 INFO L160 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [35486186] provided 1 perfect and 0 imperfect interpolant sequences [2021-12-16 00:59:18,916 INFO L186 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2021-12-16 00:59:18,917 INFO L199 FreeRefinementEngine]: Number of different interpolants: perfect sequences [6] imperfect sequences [] total 6 [2021-12-16 00:59:18,917 INFO L115 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [2142006356] [2021-12-16 00:59:18,917 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2021-12-16 00:59:18,917 INFO L546 AbstractCegarLoop]: INTERPOLANT automaton has 6 states [2021-12-16 00:59:18,917 INFO L103 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2021-12-16 00:59:18,917 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 6 interpolants. [2021-12-16 00:59:18,918 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=9, Invalid=21, Unknown=0, NotChecked=0, Total=30 [2021-12-16 00:59:18,918 INFO L87 Difference]: Start difference. First operand 712 states and 878 transitions. Second operand has 6 states, 6 states have (on average 7.333333333333333) internal successors, (44), 3 states have internal predecessors, (44), 1 states have call successors, (5), 5 states have call predecessors, (5), 1 states have return successors, (4), 1 states have call predecessors, (4), 1 states have call successors, (4) [2021-12-16 00:59:19,237 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2021-12-16 00:59:19,237 INFO L93 Difference]: Finished difference Result 1266 states and 1625 transitions. [2021-12-16 00:59:19,237 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 13 states. [2021-12-16 00:59:19,238 INFO L78 Accepts]: Start accepts. Automaton has has 6 states, 6 states have (on average 7.333333333333333) internal successors, (44), 3 states have internal predecessors, (44), 1 states have call successors, (5), 5 states have call predecessors, (5), 1 states have return successors, (4), 1 states have call predecessors, (4), 1 states have call successors, (4) Word has length 53 [2021-12-16 00:59:19,238 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2021-12-16 00:59:19,242 INFO L225 Difference]: With dead ends: 1266 [2021-12-16 00:59:19,242 INFO L226 Difference]: Without dead ends: 1264 [2021-12-16 00:59:19,243 INFO L932 BasicCegarLoop]: 0 DeclaredPredicates, 29 GetRequests, 16 SyntacticMatches, 0 SemanticMatches, 13 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 35 ImplicationChecksByTransitivity, 0.1s TimeCoverageRelationStatistics Valid=67, Invalid=143, Unknown=0, NotChecked=0, Total=210 [2021-12-16 00:59:19,243 INFO L933 BasicCegarLoop]: 99 mSDtfsCounter, 420 mSDsluCounter, 117 mSDsCounter, 0 mSdLazyCounter, 244 mSolverCounterSat, 192 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.2s Time, 0 mProtectedPredicate, 0 mProtectedAction, 422 SdHoareTripleChecker+Valid, 216 SdHoareTripleChecker+Invalid, 436 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 192 IncrementalHoareTripleChecker+Valid, 244 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.2s IncrementalHoareTripleChecker+Time [2021-12-16 00:59:19,243 INFO L934 BasicCegarLoop]: SdHoareTripleChecker [422 Valid, 216 Invalid, 436 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [192 Valid, 244 Invalid, 0 Unknown, 0 Unchecked, 0.2s Time] [2021-12-16 00:59:19,244 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 1264 states. [2021-12-16 00:59:19,274 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 1264 to 976. [2021-12-16 00:59:19,276 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 976 states, 740 states have (on average 1.2175675675675677) internal successors, (901), 795 states have internal predecessors, (901), 120 states have call successors, (120), 98 states have call predecessors, (120), 115 states have return successors, (231), 119 states have call predecessors, (231), 120 states have call successors, (231) [2021-12-16 00:59:19,279 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 976 states to 976 states and 1252 transitions. [2021-12-16 00:59:19,279 INFO L78 Accepts]: Start accepts. Automaton has 976 states and 1252 transitions. Word has length 53 [2021-12-16 00:59:19,279 INFO L84 Accepts]: Finished accepts. word is rejected. [2021-12-16 00:59:19,279 INFO L470 AbstractCegarLoop]: Abstraction has 976 states and 1252 transitions. [2021-12-16 00:59:19,279 INFO L471 AbstractCegarLoop]: INTERPOLANT automaton has has 6 states, 6 states have (on average 7.333333333333333) internal successors, (44), 3 states have internal predecessors, (44), 1 states have call successors, (5), 5 states have call predecessors, (5), 1 states have return successors, (4), 1 states have call predecessors, (4), 1 states have call successors, (4) [2021-12-16 00:59:19,280 INFO L276 IsEmpty]: Start isEmpty. Operand 976 states and 1252 transitions. [2021-12-16 00:59:19,281 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 93 [2021-12-16 00:59:19,282 INFO L506 BasicCegarLoop]: Found error trace [2021-12-16 00:59:19,282 INFO L514 BasicCegarLoop]: trace histogram [2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2021-12-16 00:59:19,282 WARN L452 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable9 [2021-12-16 00:59:19,282 INFO L402 AbstractCegarLoop]: === Iteration 11 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2021-12-16 00:59:19,282 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2021-12-16 00:59:19,283 INFO L85 PathProgramCache]: Analyzing trace with hash -1895528892, now seen corresponding path program 1 times [2021-12-16 00:59:19,283 INFO L121 FreeRefinementEngine]: Executing refinement strategy CAMEL [2021-12-16 00:59:19,283 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [1678666900] [2021-12-16 00:59:19,283 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2021-12-16 00:59:19,283 INFO L126 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2021-12-16 00:59:19,297 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 00:59:19,322 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 12 [2021-12-16 00:59:19,323 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 00:59:19,328 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 18 [2021-12-16 00:59:19,328 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 00:59:19,336 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 25 [2021-12-16 00:59:19,339 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 00:59:19,353 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 3 [2021-12-16 00:59:19,355 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 00:59:19,367 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 17 [2021-12-16 00:59:19,368 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 00:59:19,371 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 68 [2021-12-16 00:59:19,372 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 00:59:19,373 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 82 [2021-12-16 00:59:19,374 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 00:59:19,376 INFO L134 CoverageAnalysis]: Checked inductivity of 36 backedges. 21 proven. 4 refuted. 0 times theorem prover too weak. 11 trivial. 0 not checked. [2021-12-16 00:59:19,376 INFO L139 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2021-12-16 00:59:19,376 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [1678666900] [2021-12-16 00:59:19,376 INFO L160 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [1678666900] provided 0 perfect and 1 imperfect interpolant sequences [2021-12-16 00:59:19,376 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleZ3 [1978264116] [2021-12-16 00:59:19,376 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2021-12-16 00:59:19,376 INFO L168 SolverBuilder]: Constructing external solver with command: z3 -smt2 -in SMTLIB2_COMPLIANT=true [2021-12-16 00:59:19,377 INFO L189 MonitoredProcess]: No working directory specified, using /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 [2021-12-16 00:59:19,380 INFO L229 MonitoredProcess]: Starting monitored process 2 with /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 -smt2 -in SMTLIB2_COMPLIANT=true (exit command is (exit), workingDir is null) [2021-12-16 00:59:19,414 INFO L327 MonitoredProcess]: [MP /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 -smt2 -in SMTLIB2_COMPLIANT=true (2)] Waiting until timeout for monitored process [2021-12-16 00:59:19,463 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 00:59:19,465 INFO L263 TraceCheckSpWp]: Trace formula consists of 472 conjuncts, 4 conjunts are in the unsatisfiable core [2021-12-16 00:59:19,470 INFO L286 TraceCheckSpWp]: Computing forward predicates... [2021-12-16 00:59:19,671 INFO L134 CoverageAnalysis]: Checked inductivity of 36 backedges. 36 proven. 0 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2021-12-16 00:59:19,671 INFO L324 TraceCheckSpWp]: Omiting computation of backward sequence because forward sequence was already perfect [2021-12-16 00:59:19,671 INFO L160 FreeRefinementEngine]: IpTcStrategyModuleZ3 [1978264116] provided 1 perfect and 0 imperfect interpolant sequences [2021-12-16 00:59:19,671 INFO L186 FreeRefinementEngine]: Found 1 perfect and 1 imperfect interpolant sequences. [2021-12-16 00:59:19,671 INFO L199 FreeRefinementEngine]: Number of different interpolants: perfect sequences [3] imperfect sequences [10] total 10 [2021-12-16 00:59:19,671 INFO L115 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [317389736] [2021-12-16 00:59:19,671 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2021-12-16 00:59:19,672 INFO L546 AbstractCegarLoop]: INTERPOLANT automaton has 3 states [2021-12-16 00:59:19,672 INFO L103 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2021-12-16 00:59:19,672 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 3 interpolants. [2021-12-16 00:59:19,672 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=20, Invalid=70, Unknown=0, NotChecked=0, Total=90 [2021-12-16 00:59:19,672 INFO L87 Difference]: Start difference. First operand 976 states and 1252 transitions. Second operand has 3 states, 3 states have (on average 25.666666666666668) internal successors, (77), 3 states have internal predecessors, (77), 3 states have call successors, (8), 3 states have call predecessors, (8), 3 states have return successors, (7), 3 states have call predecessors, (7), 3 states have call successors, (7) [2021-12-16 00:59:19,714 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2021-12-16 00:59:19,714 INFO L93 Difference]: Finished difference Result 1680 states and 2193 transitions. [2021-12-16 00:59:19,715 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 3 states. [2021-12-16 00:59:19,715 INFO L78 Accepts]: Start accepts. Automaton has has 3 states, 3 states have (on average 25.666666666666668) internal successors, (77), 3 states have internal predecessors, (77), 3 states have call successors, (8), 3 states have call predecessors, (8), 3 states have return successors, (7), 3 states have call predecessors, (7), 3 states have call successors, (7) Word has length 92 [2021-12-16 00:59:19,715 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2021-12-16 00:59:19,718 INFO L225 Difference]: With dead ends: 1680 [2021-12-16 00:59:19,718 INFO L226 Difference]: Without dead ends: 876 [2021-12-16 00:59:19,722 INFO L932 BasicCegarLoop]: 0 DeclaredPredicates, 114 GetRequests, 106 SyntacticMatches, 0 SemanticMatches, 8 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 3 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=20, Invalid=70, Unknown=0, NotChecked=0, Total=90 [2021-12-16 00:59:19,722 INFO L933 BasicCegarLoop]: 141 mSDtfsCounter, 42 mSDsluCounter, 68 mSDsCounter, 0 mSdLazyCounter, 12 mSolverCounterSat, 3 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.0s Time, 0 mProtectedPredicate, 0 mProtectedAction, 42 SdHoareTripleChecker+Valid, 209 SdHoareTripleChecker+Invalid, 15 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 3 IncrementalHoareTripleChecker+Valid, 12 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.0s IncrementalHoareTripleChecker+Time [2021-12-16 00:59:19,723 INFO L934 BasicCegarLoop]: SdHoareTripleChecker [42 Valid, 209 Invalid, 15 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [3 Valid, 12 Invalid, 0 Unknown, 0 Unchecked, 0.0s Time] [2021-12-16 00:59:19,724 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 876 states. [2021-12-16 00:59:19,747 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 876 to 876. [2021-12-16 00:59:19,748 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 876 states, 664 states have (on average 1.1957831325301205) internal successors, (794), 714 states have internal predecessors, (794), 107 states have call successors, (107), 93 states have call predecessors, (107), 104 states have return successors, (156), 105 states have call predecessors, (156), 107 states have call successors, (156) [2021-12-16 00:59:19,750 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 876 states to 876 states and 1057 transitions. [2021-12-16 00:59:19,751 INFO L78 Accepts]: Start accepts. Automaton has 876 states and 1057 transitions. Word has length 92 [2021-12-16 00:59:19,751 INFO L84 Accepts]: Finished accepts. word is rejected. [2021-12-16 00:59:19,752 INFO L470 AbstractCegarLoop]: Abstraction has 876 states and 1057 transitions. [2021-12-16 00:59:19,752 INFO L471 AbstractCegarLoop]: INTERPOLANT automaton has has 3 states, 3 states have (on average 25.666666666666668) internal successors, (77), 3 states have internal predecessors, (77), 3 states have call successors, (8), 3 states have call predecessors, (8), 3 states have return successors, (7), 3 states have call predecessors, (7), 3 states have call successors, (7) [2021-12-16 00:59:19,752 INFO L276 IsEmpty]: Start isEmpty. Operand 876 states and 1057 transitions. [2021-12-16 00:59:19,753 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 96 [2021-12-16 00:59:19,754 INFO L506 BasicCegarLoop]: Found error trace [2021-12-16 00:59:19,754 INFO L514 BasicCegarLoop]: trace histogram [2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2021-12-16 00:59:19,787 INFO L540 MonitoredProcess]: [MP /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 -smt2 -in SMTLIB2_COMPLIANT=true (2)] Forceful destruction successful, exit code 0 [2021-12-16 00:59:19,965 WARN L452 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: 2 /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 -smt2 -in SMTLIB2_COMPLIANT=true,SelfDestructingSolverStorable10 [2021-12-16 00:59:19,966 INFO L402 AbstractCegarLoop]: === Iteration 12 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2021-12-16 00:59:19,966 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2021-12-16 00:59:19,966 INFO L85 PathProgramCache]: Analyzing trace with hash 1739782447, now seen corresponding path program 1 times [2021-12-16 00:59:19,966 INFO L121 FreeRefinementEngine]: Executing refinement strategy CAMEL [2021-12-16 00:59:19,966 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [1218624965] [2021-12-16 00:59:19,966 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2021-12-16 00:59:19,966 INFO L126 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2021-12-16 00:59:19,985 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 00:59:20,027 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 12 [2021-12-16 00:59:20,028 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 00:59:20,034 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 18 [2021-12-16 00:59:20,035 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 00:59:20,044 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 25 [2021-12-16 00:59:20,046 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 00:59:20,056 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 3 [2021-12-16 00:59:20,058 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 00:59:20,062 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 17 [2021-12-16 00:59:20,063 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 00:59:20,064 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 75 [2021-12-16 00:59:20,067 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 00:59:20,068 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 2 [2021-12-16 00:59:20,069 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 00:59:20,070 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 85 [2021-12-16 00:59:20,071 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 00:59:20,074 INFO L134 CoverageAnalysis]: Checked inductivity of 28 backedges. 8 proven. 1 refuted. 0 times theorem prover too weak. 19 trivial. 0 not checked. [2021-12-16 00:59:20,074 INFO L139 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2021-12-16 00:59:20,074 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [1218624965] [2021-12-16 00:59:20,074 INFO L160 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [1218624965] provided 0 perfect and 1 imperfect interpolant sequences [2021-12-16 00:59:20,074 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleZ3 [768475467] [2021-12-16 00:59:20,074 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2021-12-16 00:59:20,074 INFO L168 SolverBuilder]: Constructing external solver with command: z3 -smt2 -in SMTLIB2_COMPLIANT=true [2021-12-16 00:59:20,074 INFO L189 MonitoredProcess]: No working directory specified, using /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 [2021-12-16 00:59:20,075 INFO L229 MonitoredProcess]: Starting monitored process 3 with /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 -smt2 -in SMTLIB2_COMPLIANT=true (exit command is (exit), workingDir is null) [2021-12-16 00:59:20,096 INFO L327 MonitoredProcess]: [MP /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 -smt2 -in SMTLIB2_COMPLIANT=true (3)] Waiting until timeout for monitored process [2021-12-16 00:59:20,150 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 00:59:20,152 INFO L263 TraceCheckSpWp]: Trace formula consists of 475 conjuncts, 5 conjunts are in the unsatisfiable core [2021-12-16 00:59:20,154 INFO L286 TraceCheckSpWp]: Computing forward predicates... [2021-12-16 00:59:20,283 INFO L134 CoverageAnalysis]: Checked inductivity of 28 backedges. 15 proven. 0 refuted. 0 times theorem prover too weak. 13 trivial. 0 not checked. [2021-12-16 00:59:20,283 INFO L324 TraceCheckSpWp]: Omiting computation of backward sequence because forward sequence was already perfect [2021-12-16 00:59:20,283 INFO L160 FreeRefinementEngine]: IpTcStrategyModuleZ3 [768475467] provided 1 perfect and 0 imperfect interpolant sequences [2021-12-16 00:59:20,283 INFO L186 FreeRefinementEngine]: Found 1 perfect and 1 imperfect interpolant sequences. [2021-12-16 00:59:20,284 INFO L199 FreeRefinementEngine]: Number of different interpolants: perfect sequences [5] imperfect sequences [11] total 14 [2021-12-16 00:59:20,284 INFO L115 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [1714517691] [2021-12-16 00:59:20,284 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2021-12-16 00:59:20,284 INFO L546 AbstractCegarLoop]: INTERPOLANT automaton has 5 states [2021-12-16 00:59:20,284 INFO L103 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2021-12-16 00:59:20,285 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 5 interpolants. [2021-12-16 00:59:20,285 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=30, Invalid=152, Unknown=0, NotChecked=0, Total=182 [2021-12-16 00:59:20,285 INFO L87 Difference]: Start difference. First operand 876 states and 1057 transitions. Second operand has 5 states, 5 states have (on average 14.0) internal successors, (70), 5 states have internal predecessors, (70), 2 states have call successors, (8), 2 states have call predecessors, (8), 2 states have return successors, (8), 2 states have call predecessors, (8), 2 states have call successors, (8) [2021-12-16 00:59:20,328 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2021-12-16 00:59:20,328 INFO L93 Difference]: Finished difference Result 1638 states and 2014 transitions. [2021-12-16 00:59:20,329 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 5 states. [2021-12-16 00:59:20,329 INFO L78 Accepts]: Start accepts. Automaton has has 5 states, 5 states have (on average 14.0) internal successors, (70), 5 states have internal predecessors, (70), 2 states have call successors, (8), 2 states have call predecessors, (8), 2 states have return successors, (8), 2 states have call predecessors, (8), 2 states have call successors, (8) Word has length 95 [2021-12-16 00:59:20,330 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2021-12-16 00:59:20,333 INFO L225 Difference]: With dead ends: 1638 [2021-12-16 00:59:20,333 INFO L226 Difference]: Without dead ends: 934 [2021-12-16 00:59:20,334 INFO L932 BasicCegarLoop]: 0 DeclaredPredicates, 121 GetRequests, 107 SyntacticMatches, 0 SemanticMatches, 14 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 13 ImplicationChecksByTransitivity, 0.1s TimeCoverageRelationStatistics Valid=45, Invalid=195, Unknown=0, NotChecked=0, Total=240 [2021-12-16 00:59:20,335 INFO L933 BasicCegarLoop]: 110 mSDtfsCounter, 33 mSDsluCounter, 294 mSDsCounter, 0 mSdLazyCounter, 14 mSolverCounterSat, 6 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.0s Time, 0 mProtectedPredicate, 0 mProtectedAction, 33 SdHoareTripleChecker+Valid, 404 SdHoareTripleChecker+Invalid, 20 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 6 IncrementalHoareTripleChecker+Valid, 14 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.0s IncrementalHoareTripleChecker+Time [2021-12-16 00:59:20,335 INFO L934 BasicCegarLoop]: SdHoareTripleChecker [33 Valid, 404 Invalid, 20 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [6 Valid, 14 Invalid, 0 Unknown, 0 Unchecked, 0.0s Time] [2021-12-16 00:59:20,336 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 934 states. [2021-12-16 00:59:20,360 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 934 to 888. [2021-12-16 00:59:20,361 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 888 states, 676 states have (on average 1.1923076923076923) internal successors, (806), 726 states have internal predecessors, (806), 107 states have call successors, (107), 93 states have call predecessors, (107), 104 states have return successors, (156), 105 states have call predecessors, (156), 107 states have call successors, (156) [2021-12-16 00:59:20,363 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 888 states to 888 states and 1069 transitions. [2021-12-16 00:59:20,364 INFO L78 Accepts]: Start accepts. Automaton has 888 states and 1069 transitions. Word has length 95 [2021-12-16 00:59:20,364 INFO L84 Accepts]: Finished accepts. word is rejected. [2021-12-16 00:59:20,364 INFO L470 AbstractCegarLoop]: Abstraction has 888 states and 1069 transitions. [2021-12-16 00:59:20,364 INFO L471 AbstractCegarLoop]: INTERPOLANT automaton has has 5 states, 5 states have (on average 14.0) internal successors, (70), 5 states have internal predecessors, (70), 2 states have call successors, (8), 2 states have call predecessors, (8), 2 states have return successors, (8), 2 states have call predecessors, (8), 2 states have call successors, (8) [2021-12-16 00:59:20,364 INFO L276 IsEmpty]: Start isEmpty. Operand 888 states and 1069 transitions. [2021-12-16 00:59:20,370 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 96 [2021-12-16 00:59:20,370 INFO L506 BasicCegarLoop]: Found error trace [2021-12-16 00:59:20,370 INFO L514 BasicCegarLoop]: trace histogram [2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2021-12-16 00:59:20,389 INFO L540 MonitoredProcess]: [MP /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 -smt2 -in SMTLIB2_COMPLIANT=true (3)] Forceful destruction successful, exit code 0 [2021-12-16 00:59:20,583 WARN L452 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: 3 /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 -smt2 -in SMTLIB2_COMPLIANT=true,SelfDestructingSolverStorable11 [2021-12-16 00:59:20,583 INFO L402 AbstractCegarLoop]: === Iteration 13 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2021-12-16 00:59:20,584 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2021-12-16 00:59:20,584 INFO L85 PathProgramCache]: Analyzing trace with hash 1873795953, now seen corresponding path program 1 times [2021-12-16 00:59:20,584 INFO L121 FreeRefinementEngine]: Executing refinement strategy CAMEL [2021-12-16 00:59:20,584 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [1028397920] [2021-12-16 00:59:20,584 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2021-12-16 00:59:20,584 INFO L126 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2021-12-16 00:59:20,594 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 00:59:20,632 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 12 [2021-12-16 00:59:20,633 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 00:59:20,638 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 18 [2021-12-16 00:59:20,638 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 00:59:20,646 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 25 [2021-12-16 00:59:20,648 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 00:59:20,658 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 3 [2021-12-16 00:59:20,659 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 00:59:20,664 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 17 [2021-12-16 00:59:20,664 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 00:59:20,666 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 75 [2021-12-16 00:59:20,666 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 00:59:20,667 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 2 [2021-12-16 00:59:20,668 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 00:59:20,669 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 85 [2021-12-16 00:59:20,669 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 00:59:20,670 INFO L134 CoverageAnalysis]: Checked inductivity of 28 backedges. 20 proven. 3 refuted. 0 times theorem prover too weak. 5 trivial. 0 not checked. [2021-12-16 00:59:20,670 INFO L139 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2021-12-16 00:59:20,670 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [1028397920] [2021-12-16 00:59:20,670 INFO L160 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [1028397920] provided 0 perfect and 1 imperfect interpolant sequences [2021-12-16 00:59:20,670 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleZ3 [13809150] [2021-12-16 00:59:20,670 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2021-12-16 00:59:20,670 INFO L168 SolverBuilder]: Constructing external solver with command: z3 -smt2 -in SMTLIB2_COMPLIANT=true [2021-12-16 00:59:20,671 INFO L189 MonitoredProcess]: No working directory specified, using /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 [2021-12-16 00:59:20,671 INFO L229 MonitoredProcess]: Starting monitored process 4 with /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 -smt2 -in SMTLIB2_COMPLIANT=true (exit command is (exit), workingDir is null) [2021-12-16 00:59:20,672 INFO L327 MonitoredProcess]: [MP /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 -smt2 -in SMTLIB2_COMPLIANT=true (4)] Waiting until timeout for monitored process [2021-12-16 00:59:20,745 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 00:59:20,747 INFO L263 TraceCheckSpWp]: Trace formula consists of 474 conjuncts, 11 conjunts are in the unsatisfiable core [2021-12-16 00:59:20,749 INFO L286 TraceCheckSpWp]: Computing forward predicates... [2021-12-16 00:59:20,885 INFO L134 CoverageAnalysis]: Checked inductivity of 28 backedges. 28 proven. 0 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2021-12-16 00:59:20,885 INFO L324 TraceCheckSpWp]: Omiting computation of backward sequence because forward sequence was already perfect [2021-12-16 00:59:20,885 INFO L160 FreeRefinementEngine]: IpTcStrategyModuleZ3 [13809150] provided 1 perfect and 0 imperfect interpolant sequences [2021-12-16 00:59:20,885 INFO L186 FreeRefinementEngine]: Found 1 perfect and 1 imperfect interpolant sequences. [2021-12-16 00:59:20,885 INFO L199 FreeRefinementEngine]: Number of different interpolants: perfect sequences [6] imperfect sequences [10] total 10 [2021-12-16 00:59:20,887 INFO L115 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [108668707] [2021-12-16 00:59:20,887 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2021-12-16 00:59:20,887 INFO L546 AbstractCegarLoop]: INTERPOLANT automaton has 6 states [2021-12-16 00:59:20,887 INFO L103 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2021-12-16 00:59:20,888 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 6 interpolants. [2021-12-16 00:59:20,888 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=20, Invalid=70, Unknown=0, NotChecked=0, Total=90 [2021-12-16 00:59:20,888 INFO L87 Difference]: Start difference. First operand 888 states and 1069 transitions. Second operand has 6 states, 6 states have (on average 13.0) internal successors, (78), 6 states have internal predecessors, (78), 3 states have call successors, (9), 3 states have call predecessors, (9), 3 states have return successors, (8), 3 states have call predecessors, (8), 3 states have call successors, (8) [2021-12-16 00:59:20,970 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2021-12-16 00:59:20,971 INFO L93 Difference]: Finished difference Result 1478 states and 1798 transitions. [2021-12-16 00:59:20,971 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 6 states. [2021-12-16 00:59:20,971 INFO L78 Accepts]: Start accepts. Automaton has has 6 states, 6 states have (on average 13.0) internal successors, (78), 6 states have internal predecessors, (78), 3 states have call successors, (9), 3 states have call predecessors, (9), 3 states have return successors, (8), 3 states have call predecessors, (8), 3 states have call successors, (8) Word has length 95 [2021-12-16 00:59:20,972 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2021-12-16 00:59:20,972 INFO L225 Difference]: With dead ends: 1478 [2021-12-16 00:59:20,972 INFO L226 Difference]: Without dead ends: 0 [2021-12-16 00:59:20,974 INFO L932 BasicCegarLoop]: 0 DeclaredPredicates, 121 GetRequests, 107 SyntacticMatches, 4 SemanticMatches, 10 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 13 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=30, Invalid=102, Unknown=0, NotChecked=0, Total=132 [2021-12-16 00:59:20,975 INFO L933 BasicCegarLoop]: 150 mSDtfsCounter, 150 mSDsluCounter, 342 mSDsCounter, 0 mSdLazyCounter, 43 mSolverCounterSat, 21 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.0s Time, 0 mProtectedPredicate, 0 mProtectedAction, 150 SdHoareTripleChecker+Valid, 492 SdHoareTripleChecker+Invalid, 64 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 21 IncrementalHoareTripleChecker+Valid, 43 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.0s IncrementalHoareTripleChecker+Time [2021-12-16 00:59:20,975 INFO L934 BasicCegarLoop]: SdHoareTripleChecker [150 Valid, 492 Invalid, 64 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [21 Valid, 43 Invalid, 0 Unknown, 0 Unchecked, 0.0s Time] [2021-12-16 00:59:20,976 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 0 states. [2021-12-16 00:59:20,976 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 0 to 0. [2021-12-16 00:59:20,976 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 0 states, 0 states have (on average 0.0) internal successors, (0), 0 states have internal predecessors, (0), 0 states have call successors, (0), 0 states have call predecessors, (0), 0 states have return successors, (0), 0 states have call predecessors, (0), 0 states have call successors, (0) [2021-12-16 00:59:20,976 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 0 states to 0 states and 0 transitions. [2021-12-16 00:59:20,976 INFO L78 Accepts]: Start accepts. Automaton has 0 states and 0 transitions. Word has length 95 [2021-12-16 00:59:20,976 INFO L84 Accepts]: Finished accepts. word is rejected. [2021-12-16 00:59:20,977 INFO L470 AbstractCegarLoop]: Abstraction has 0 states and 0 transitions. [2021-12-16 00:59:20,977 INFO L471 AbstractCegarLoop]: INTERPOLANT automaton has has 6 states, 6 states have (on average 13.0) internal successors, (78), 6 states have internal predecessors, (78), 3 states have call successors, (9), 3 states have call predecessors, (9), 3 states have return successors, (8), 3 states have call predecessors, (8), 3 states have call successors, (8) [2021-12-16 00:59:20,977 INFO L276 IsEmpty]: Start isEmpty. Operand 0 states and 0 transitions. [2021-12-16 00:59:20,977 INFO L282 IsEmpty]: Finished isEmpty. No accepting run. [2021-12-16 00:59:20,979 INFO L764 garLoopResultBuilder]: Registering result SAFE for location timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION (0 of 1 remaining) [2021-12-16 00:59:21,011 INFO L540 MonitoredProcess]: [MP /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 -smt2 -in SMTLIB2_COMPLIANT=true (4)] Forceful destruction successful, exit code 0 [2021-12-16 00:59:21,187 WARN L452 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable12,4 /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 -smt2 -in SMTLIB2_COMPLIANT=true [2021-12-16 00:59:21,189 INFO L343 DoubleDeckerVisitor]: Before removal of dead ends 0 states and 0 transitions. [2021-12-16 00:59:24,502 INFO L854 garLoopResultBuilder]: At program point deactivatePumpENTRY(lines 229 236) the Hoare annotation is: (or (= 0 ~systemActive~0) (not (<= 1 ~waterLevel~0)) (= ~pumpRunning~0 |old(~pumpRunning~0)|) (not (<= 1 |old(~pumpRunning~0)|))) [2021-12-16 00:59:24,502 INFO L858 garLoopResultBuilder]: For program point deactivatePumpEXIT(lines 229 236) no Hoare annotation was computed. [2021-12-16 00:59:24,502 INFO L858 garLoopResultBuilder]: For program point deactivatePumpFINAL(lines 229 236) no Hoare annotation was computed. [2021-12-16 00:59:24,503 INFO L858 garLoopResultBuilder]: For program point processEnvironment__wrappee__baseEXIT(lines 162 168) no Hoare annotation was computed. [2021-12-16 00:59:24,503 INFO L861 garLoopResultBuilder]: At program point processEnvironment__wrappee__baseFINAL(lines 162 168) the Hoare annotation is: true [2021-12-16 00:59:24,503 INFO L858 garLoopResultBuilder]: For program point L562-1(lines 558 569) no Hoare annotation was computed. [2021-12-16 00:59:24,503 INFO L854 garLoopResultBuilder]: At program point changeMethaneLevelENTRY(lines 558 569) the Hoare annotation is: (let ((.cse0 (= ~methaneLevelCritical~0 |old(~methaneLevelCritical~0)|))) (and (or (not (= ~pumpRunning~0 0)) .cse0 (not (<= 1 ~waterLevel~0)) (not (= ~methAndRunningLastTime~0 0))) (or (= 0 ~systemActive~0) .cse0 (not (<= 1 ~pumpRunning~0)) (not (<= 2 ~waterLevel~0))))) [2021-12-16 00:59:24,503 INFO L858 garLoopResultBuilder]: For program point changeMethaneLevelEXIT(lines 558 569) no Hoare annotation was computed. [2021-12-16 00:59:24,503 INFO L861 garLoopResultBuilder]: At program point isMethaneLevelCriticalENTRY(lines 570 578) the Hoare annotation is: true [2021-12-16 00:59:24,503 INFO L858 garLoopResultBuilder]: For program point isMethaneLevelCriticalFINAL(lines 570 578) no Hoare annotation was computed. [2021-12-16 00:59:24,503 INFO L858 garLoopResultBuilder]: For program point isMethaneLevelCriticalEXIT(lines 570 578) no Hoare annotation was computed. [2021-12-16 00:59:24,503 INFO L858 garLoopResultBuilder]: For program point cleanupEXIT(lines 356 385) no Hoare annotation was computed. [2021-12-16 00:59:24,503 INFO L861 garLoopResultBuilder]: At program point L381(lines 356 385) the Hoare annotation is: true [2021-12-16 00:59:24,503 INFO L861 garLoopResultBuilder]: At program point cleanupENTRY(lines 356 385) the Hoare annotation is: true [2021-12-16 00:59:24,503 INFO L858 garLoopResultBuilder]: For program point L377(line 377) no Hoare annotation was computed. [2021-12-16 00:59:24,503 INFO L858 garLoopResultBuilder]: For program point L370(lines 370 374) no Hoare annotation was computed. [2021-12-16 00:59:24,503 INFO L861 garLoopResultBuilder]: At program point L370-1(lines 370 374) the Hoare annotation is: true [2021-12-16 00:59:24,504 INFO L858 garLoopResultBuilder]: For program point L367(line 367) no Hoare annotation was computed. [2021-12-16 00:59:24,504 INFO L861 garLoopResultBuilder]: At program point L366-2(lines 366 380) the Hoare annotation is: true [2021-12-16 00:59:24,504 INFO L861 garLoopResultBuilder]: At program point L362(line 362) the Hoare annotation is: true [2021-12-16 00:59:24,504 INFO L858 garLoopResultBuilder]: For program point L362-1(line 362) no Hoare annotation was computed. [2021-12-16 00:59:24,504 INFO L854 garLoopResultBuilder]: At program point L630(lines 625 633) the Hoare annotation is: (let ((.cse2 (not (<= 2 |old(~waterLevel~0)|))) (.cse3 (= 0 ~systemActive~0)) (.cse4 (not (<= 1 |old(~pumpRunning~0)|))) (.cse0 (not (= |old(~pumpRunning~0)| 0))) (.cse1 (not (<= 1 |old(~waterLevel~0)|))) (.cse5 (not (= |old(~methAndRunningLastTime~0)| 0)))) (and (or .cse0 .cse1 (not (= ~systemActive~0 0))) (or .cse2 .cse3 (and (<= 0 |timeShift_isLowWaterSensorDry_#res#1|) (<= |timeShift_isLowWaterSensorDry_#res#1| 0) (= ~pumpRunning~0 |old(~pumpRunning~0)|) (<= 1 ~waterLevel~0)) .cse4) (or .cse2 .cse3 (= ~methAndRunningLastTime~0 0) .cse4 .cse5) (or .cse0 .cse1 .cse5))) [2021-12-16 00:59:24,504 INFO L854 garLoopResultBuilder]: At program point L1006(lines 1001 1008) the Hoare annotation is: (let ((.cse0 (not (= |old(~pumpRunning~0)| 0))) (.cse1 (not (<= 1 |old(~waterLevel~0)|)))) (and (or .cse0 .cse1 (not (= ~systemActive~0 0))) (or (not (<= 2 |old(~waterLevel~0)|)) (= 0 ~systemActive~0) (not (<= 1 |old(~pumpRunning~0)|))) (or .cse0 .cse1 (not (= |old(~methAndRunningLastTime~0)| 0))))) [2021-12-16 00:59:24,504 INFO L858 garLoopResultBuilder]: For program point timeShiftFINAL(lines 138 161) no Hoare annotation was computed. [2021-12-16 00:59:24,504 INFO L858 garLoopResultBuilder]: For program point L321(lines 321 325) no Hoare annotation was computed. [2021-12-16 00:59:24,504 INFO L858 garLoopResultBuilder]: For program point L321-2(lines 321 325) no Hoare annotation was computed. [2021-12-16 00:59:24,505 INFO L858 garLoopResultBuilder]: For program point L478(lines 478 488) no Hoare annotation was computed. [2021-12-16 00:59:24,505 INFO L858 garLoopResultBuilder]: For program point L474(lines 474 491) no Hoare annotation was computed. [2021-12-16 00:59:24,505 INFO L854 garLoopResultBuilder]: At program point L474-1(lines 466 494) the Hoare annotation is: (let ((.cse5 (= 0 ~systemActive~0))) (let ((.cse0 (= ~waterLevel~0 |old(~waterLevel~0)|)) (.cse8 (not (= |old(~methAndRunningLastTime~0)| 0))) (.cse1 (= ~methAndRunningLastTime~0 0)) (.cse6 (not .cse5)) (.cse7 (= ~pumpRunning~0 0)) (.cse11 (not (<= 2 |old(~waterLevel~0)|))) (.cse12 (not (<= 1 |old(~pumpRunning~0)|))) (.cse2 (not (= |old(~pumpRunning~0)| 0))) (.cse10 (not (= ~methaneLevelCritical~0 0))) (.cse3 (not (<= 1 |old(~waterLevel~0)|))) (.cse9 (= |timeShift___utac_acc__Specification2_spec__2_~tmp~6#1| 0)) (.cse4 (not (= ~systemActive~0 0)))) (and (or (and .cse0 (= ~pumpRunning~0 |old(~pumpRunning~0)|) .cse1) .cse2 .cse3 .cse4) (or .cse5 (and .cse0 (<= 1 ~pumpRunning~0) (<= 2 ~waterLevel~0)) (and .cse0 .cse1 .cse6 .cse7) .cse2 .cse3 .cse8) (or (and .cse1 .cse9) .cse2 .cse10 .cse3 .cse8) (or .cse11 .cse5 (and (<= |timeShift_isLowWaterLevel_~tmp~4#1| 0) (<= 0 |timeShift_isLowWaterSensorDry_#res#1|) (<= |timeShift_isLowWaterSensorDry_#res#1| 0) .cse1 (<= 1 ~waterLevel~0) .cse6 (< 0 (+ |timeShift_isLowWaterLevel_~tmp~4#1| 1)) .cse7) .cse12) (or .cse11 .cse5 .cse10 .cse9 .cse12) (or .cse2 .cse10 .cse3 .cse9 .cse4)))) [2021-12-16 00:59:24,505 INFO L854 garLoopResultBuilder]: At program point L210(line 210) the Hoare annotation is: (let ((.cse0 (not (= |old(~pumpRunning~0)| 0))) (.cse1 (not (<= 1 |old(~waterLevel~0)|)))) (and (or .cse0 .cse1 (not (= ~systemActive~0 0))) (or (not (<= 2 |old(~waterLevel~0)|)) (= 0 ~systemActive~0) (not (<= 1 |old(~pumpRunning~0)|))) (or .cse0 .cse1 (not (= |old(~methAndRunningLastTime~0)| 0))))) [2021-12-16 00:59:24,505 INFO L854 garLoopResultBuilder]: At program point L206(line 206) the Hoare annotation is: (let ((.cse0 (not (= |old(~pumpRunning~0)| 0))) (.cse1 (not (<= 1 |old(~waterLevel~0)|)))) (and (or (not (<= 2 |old(~waterLevel~0)|)) (= 0 ~systemActive~0) (and (<= |timeShift_isLowWaterLevel_~tmp~4#1| 0) (<= 0 |timeShift_isLowWaterSensorDry_#res#1|) (<= |timeShift_isLowWaterSensorDry_#res#1| 0) (= ~pumpRunning~0 |old(~pumpRunning~0)|) (<= 1 ~waterLevel~0) (< 0 (+ |timeShift_isLowWaterLevel_~tmp~4#1| 1))) (not (<= 1 |old(~pumpRunning~0)|))) (or .cse0 .cse1 (not (= ~systemActive~0 0))) (or .cse0 .cse1 (not (= |old(~methAndRunningLastTime~0)| 0))))) [2021-12-16 00:59:24,505 INFO L858 garLoopResultBuilder]: For program point L479(lines 479 485) no Hoare annotation was computed. [2021-12-16 00:59:24,505 INFO L854 garLoopResultBuilder]: At program point L215(line 215) the Hoare annotation is: (let ((.cse0 (not (= |old(~pumpRunning~0)| 0))) (.cse1 (not (<= 1 |old(~waterLevel~0)|)))) (and (or .cse0 .cse1 (not (= ~systemActive~0 0))) (or (not (<= 2 |old(~waterLevel~0)|)) (= 0 ~systemActive~0) (not (<= 1 |old(~pumpRunning~0)|))) (or .cse0 (and (= ~waterLevel~0 |old(~waterLevel~0)|) (= ~methAndRunningLastTime~0 0) (= ~pumpRunning~0 0)) .cse1 (not (= |old(~methAndRunningLastTime~0)| 0))))) [2021-12-16 00:59:24,506 INFO L854 garLoopResultBuilder]: At program point L215-1(lines 196 220) the Hoare annotation is: (let ((.cse1 (= ~methAndRunningLastTime~0 0)) (.cse4 (= ~pumpRunning~0 0)) (.cse0 (not (= |old(~pumpRunning~0)| 0))) (.cse3 (not (<= 1 |old(~waterLevel~0)|))) (.cse2 (not (= |old(~methAndRunningLastTime~0)| 0)))) (and (or (not (= |old(~waterLevel~0)| 1)) .cse0 .cse1 .cse2) (or .cse0 .cse3 (not (= ~systemActive~0 0))) (or (not (<= 2 |old(~waterLevel~0)|)) (= 0 ~systemActive~0) (and (<= |timeShift_isLowWaterLevel_~tmp~4#1| 0) (<= 0 |timeShift_isLowWaterSensorDry_#res#1|) (<= |timeShift_isLowWaterSensorDry_#res#1| 0) (<= 1 ~waterLevel~0) (< 0 (+ |timeShift_isLowWaterLevel_~tmp~4#1| 1)) .cse4) (not (<= 1 |old(~pumpRunning~0)|))) (let ((.cse5 (= ~waterLevel~0 |old(~waterLevel~0)|))) (or (and .cse5 (<= 1 ~pumpRunning~0) (<= 2 ~waterLevel~0) .cse1) (and .cse5 .cse4) .cse0 .cse3 .cse2)))) [2021-12-16 00:59:24,506 INFO L858 garLoopResultBuilder]: For program point L149-1(lines 149 155) no Hoare annotation was computed. [2021-12-16 00:59:24,506 INFO L854 garLoopResultBuilder]: At program point L327(lines 312 330) the Hoare annotation is: (let ((.cse0 (not (= |old(~pumpRunning~0)| 0))) (.cse1 (not (<= 1 |old(~waterLevel~0)|)))) (and (or .cse0 .cse1 (not (= ~systemActive~0 0))) (or (not (<= 2 |old(~waterLevel~0)|)) (= 0 ~systemActive~0) (and (<= 1 |timeShift_isLowWaterLevel_~tmp___0~2#1|) (<= |timeShift_isLowWaterLevel_~tmp~4#1| 0) (<= 0 |timeShift_isLowWaterSensorDry_#res#1|) (<= |timeShift_isLowWaterSensorDry_#res#1| 0) (<= 1 |timeShift_isLowWaterLevel_#res#1|) (= ~pumpRunning~0 |old(~pumpRunning~0)|) (<= 1 ~waterLevel~0) (< 0 (+ |timeShift_isLowWaterLevel_~tmp~4#1| 1))) (not (<= 1 |old(~pumpRunning~0)|))) (or .cse0 .cse1 (not (= |old(~methAndRunningLastTime~0)| 0))))) [2021-12-16 00:59:24,506 INFO L854 garLoopResultBuilder]: At program point L253(lines 248 256) the Hoare annotation is: (let ((.cse10 (= |timeShift_isPumpRunning_#res#1| 0)) (.cse3 (= ~waterLevel~0 |old(~waterLevel~0)|)) (.cse11 (= ~pumpRunning~0 0))) (let ((.cse1 (= ~methAndRunningLastTime~0 0)) (.cse2 (not (= |old(~methAndRunningLastTime~0)| 0))) (.cse4 (and .cse10 .cse3 .cse11)) (.cse0 (not (= |old(~pumpRunning~0)| 0))) (.cse5 (not (<= 1 |old(~waterLevel~0)|))) (.cse7 (not (= ~systemActive~0 0))) (.cse8 (not (<= 2 |old(~waterLevel~0)|))) (.cse9 (= 0 ~systemActive~0)) (.cse6 (not (= ~methaneLevelCritical~0 0))) (.cse12 (not (<= 1 |old(~pumpRunning~0)|)))) (and (or (not (= |old(~waterLevel~0)| 1)) .cse0 .cse1 .cse2) (or (and .cse3 (<= 1 ~pumpRunning~0) (<= 2 ~waterLevel~0) .cse1) .cse4 .cse0 .cse5 .cse2) (or .cse0 .cse6 .cse5 .cse7) (or .cse0 .cse6 .cse5 .cse2) (or .cse4 .cse0 .cse5 .cse7) (or .cse8 .cse9 (and (<= |timeShift_isLowWaterLevel_~tmp~4#1| 0) (<= 0 |timeShift_isLowWaterSensorDry_#res#1|) .cse10 (<= |timeShift_isLowWaterSensorDry_#res#1| 0) (<= 1 ~waterLevel~0) (< 0 (+ |timeShift_isLowWaterLevel_~tmp~4#1| 1)) .cse11) .cse12) (or .cse8 .cse9 .cse6 .cse12)))) [2021-12-16 00:59:24,506 INFO L858 garLoopResultBuilder]: For program point L538(lines 538 542) no Hoare annotation was computed. [2021-12-16 00:59:24,506 INFO L854 garLoopResultBuilder]: At program point L538-2(lines 534 545) the Hoare annotation is: (let ((.cse0 (not (<= 2 |old(~waterLevel~0)|))) (.cse1 (= 0 ~systemActive~0)) (.cse2 (not (<= 1 |old(~pumpRunning~0)|))) (.cse3 (not (= |old(~pumpRunning~0)| 0))) (.cse4 (not (<= 1 |old(~waterLevel~0)|))) (.cse5 (not (= |old(~methAndRunningLastTime~0)| 0)))) (and (or .cse0 .cse1 (and (= ~pumpRunning~0 |old(~pumpRunning~0)|) (<= 1 ~waterLevel~0)) .cse2) (or .cse3 .cse4 (not (= ~systemActive~0 0))) (or .cse0 .cse1 (= ~methAndRunningLastTime~0 0) .cse2 .cse5) (or .cse3 .cse4 .cse5))) [2021-12-16 00:59:24,507 INFO L854 garLoopResultBuilder]: At program point L472(line 472) the Hoare annotation is: (let ((.cse7 (= ~waterLevel~0 |old(~waterLevel~0)|)) (.cse6 (= ~pumpRunning~0 0))) (let ((.cse0 (not (= |old(~waterLevel~0)| 1))) (.cse5 (not (<= 2 |old(~waterLevel~0)|))) (.cse4 (and .cse7 .cse6)) (.cse1 (not (= |old(~pumpRunning~0)| 0))) (.cse2 (= ~methAndRunningLastTime~0 0)) (.cse3 (not (= |old(~methAndRunningLastTime~0)| 0)))) (and (or .cse0 .cse1 .cse2 .cse3) (or .cse0 .cse4 .cse1 .cse3) (or .cse5 (= 0 ~systemActive~0) (and (<= |timeShift_isLowWaterLevel_~tmp~4#1| 0) (<= 0 |timeShift_isLowWaterSensorDry_#res#1|) (<= |timeShift_isLowWaterSensorDry_#res#1| 0) (<= 1 ~waterLevel~0) (< 0 (+ |timeShift_isLowWaterLevel_~tmp~4#1| 1)) .cse6) (not (<= 1 |old(~pumpRunning~0)|))) (or .cse4 .cse1 (not (<= 1 |old(~waterLevel~0)|)) (not (= ~systemActive~0 0))) (or .cse5 .cse4 .cse1 (and .cse7 (<= 1 ~pumpRunning~0) .cse2) .cse3)))) [2021-12-16 00:59:24,507 INFO L858 garLoopResultBuilder]: For program point L472-1(line 472) no Hoare annotation was computed. [2021-12-16 00:59:24,507 INFO L854 garLoopResultBuilder]: At program point timeShiftENTRY(lines 138 161) the Hoare annotation is: (let ((.cse0 (not (= |old(~pumpRunning~0)| 0))) (.cse5 (= ~waterLevel~0 |old(~waterLevel~0)|)) (.cse7 (= ~pumpRunning~0 0)) (.cse8 (not (<= 1 |old(~waterLevel~0)|))) (.cse3 (not (<= 2 |old(~waterLevel~0)|))) (.cse4 (= 0 ~systemActive~0)) (.cse1 (= ~methAndRunningLastTime~0 0)) (.cse6 (not (<= 1 |old(~pumpRunning~0)|))) (.cse2 (not (= |old(~methAndRunningLastTime~0)| 0)))) (and (or (not (= |old(~waterLevel~0)| 1)) .cse0 .cse1 .cse2) (or .cse3 .cse4 (and .cse5 (= ~pumpRunning~0 |old(~pumpRunning~0)|)) .cse6) (or (and .cse5 .cse7) .cse0 .cse8 (not (= ~systemActive~0 0))) (or .cse4 .cse0 (and .cse5 .cse1 .cse7) .cse8 .cse2) (or .cse3 .cse4 .cse1 .cse6 .cse2))) [2021-12-16 00:59:24,508 INFO L858 garLoopResultBuilder]: For program point L142-1(lines 141 160) no Hoare annotation was computed. [2021-12-16 00:59:24,508 INFO L858 garLoopResultBuilder]: For program point L1005(line 1005) no Hoare annotation was computed. [2021-12-16 00:59:24,508 INFO L858 garLoopResultBuilder]: For program point L204(lines 204 212) no Hoare annotation was computed. [2021-12-16 00:59:24,509 INFO L858 garLoopResultBuilder]: For program point timeShiftEXIT(lines 138 161) no Hoare annotation was computed. [2021-12-16 00:59:24,509 INFO L858 garLoopResultBuilder]: For program point timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION(line 1005) no Hoare annotation was computed. [2021-12-16 00:59:24,509 INFO L858 garLoopResultBuilder]: For program point L200(lines 200 217) no Hoare annotation was computed. [2021-12-16 00:59:24,509 INFO L854 garLoopResultBuilder]: At program point L337(line 337) the Hoare annotation is: (and (= |ULTIMATE.start_test_~splverifierCounter~0#1| 0) (= 1 |ULTIMATE.start_main_~tmp~5#1|) (= 1 |ULTIMATE.start_valid_product_#res#1|) (<= 1 ~pumpRunning~0) (<= 2 ~waterLevel~0) (not (= 0 ~systemActive~0))) [2021-12-16 00:59:24,509 INFO L858 garLoopResultBuilder]: For program point L-1(line -1) no Hoare annotation was computed. [2021-12-16 00:59:24,509 INFO L854 garLoopResultBuilder]: At program point L511(lines 507 513) the Hoare annotation is: (and (= ~waterLevel~0 1) (= ~methaneLevelCritical~0 0) (= ~methAndRunningLastTime~0 0) (not (= 0 ~systemActive~0)) (= ~pumpRunning~0 0)) [2021-12-16 00:59:24,509 INFO L858 garLoopResultBuilder]: For program point ULTIMATE.startENTRY(line -1) no Hoare annotation was computed. [2021-12-16 00:59:24,509 INFO L858 garLoopResultBuilder]: For program point ULTIMATE.startFINAL(line -1) no Hoare annotation was computed. [2021-12-16 00:59:24,509 INFO L861 garLoopResultBuilder]: At program point L119(lines 56 123) the Hoare annotation is: true [2021-12-16 00:59:24,509 INFO L858 garLoopResultBuilder]: For program point L86(lines 86 92) no Hoare annotation was computed. [2021-12-16 00:59:24,509 INFO L858 garLoopResultBuilder]: For program point L86-1(lines 86 92) no Hoare annotation was computed. [2021-12-16 00:59:24,510 INFO L854 garLoopResultBuilder]: At program point L78(line 78) the Hoare annotation is: (let ((.cse0 (= |ULTIMATE.start_test_~splverifierCounter~0#1| 0)) (.cse1 (= 1 |ULTIMATE.start_main_~tmp~5#1|)) (.cse2 (= 1 |ULTIMATE.start_valid_product_#res#1|))) (or (and .cse0 .cse1 .cse2 (= ~methAndRunningLastTime~0 0) (<= 1 ~waterLevel~0) (= ~pumpRunning~0 0)) (and .cse0 .cse1 .cse2 (<= 1 ~pumpRunning~0) (<= 2 ~waterLevel~0) (not (= 0 ~systemActive~0))))) [2021-12-16 00:59:24,510 INFO L858 garLoopResultBuilder]: For program point ULTIMATE.startEXIT(line -1) no Hoare annotation was computed. [2021-12-16 00:59:24,510 INFO L854 garLoopResultBuilder]: At program point L351(lines 346 353) the Hoare annotation is: (let ((.cse0 (= |ULTIMATE.start_test_~splverifierCounter~0#1| 0)) (.cse1 (= 1 |ULTIMATE.start_main_~tmp~5#1|)) (.cse2 (= 1 |ULTIMATE.start_valid_product_#res#1|)) (.cse3 (not (= 0 ~systemActive~0)))) (or (and .cse0 .cse1 .cse2 (<= 1 ~pumpRunning~0) (<= 2 ~waterLevel~0) .cse3) (and .cse0 .cse1 .cse2 (= ~methAndRunningLastTime~0 0) (<= 1 ~waterLevel~0) .cse3 (= ~pumpRunning~0 0)))) [2021-12-16 00:59:24,510 INFO L858 garLoopResultBuilder]: For program point L442(lines 442 449) no Hoare annotation was computed. [2021-12-16 00:59:24,510 INFO L858 garLoopResultBuilder]: For program point L442-2(lines 442 449) no Hoare annotation was computed. [2021-12-16 00:59:24,510 INFO L854 garLoopResultBuilder]: At program point L343(lines 331 345) the Hoare annotation is: (and (= |ULTIMATE.start_test_~splverifierCounter~0#1| 0) (= 1 |ULTIMATE.start_main_~tmp~5#1|) (= ~systemActive~0 0) (= 1 |ULTIMATE.start_valid_product_#res#1|) (<= 1 ~waterLevel~0) (= ~pumpRunning~0 0)) [2021-12-16 00:59:24,510 INFO L854 garLoopResultBuilder]: At program point L116(lines 65 117) the Hoare annotation is: false [2021-12-16 00:59:24,510 INFO L854 garLoopResultBuilder]: At program point L463(lines 458 465) the Hoare annotation is: (and (= 1 |ULTIMATE.start_main_~tmp~5#1|) (= ~waterLevel~0 1) (= ~methaneLevelCritical~0 0) (= 1 |ULTIMATE.start_valid_product_#res#1|) (= ~methAndRunningLastTime~0 0) (not (= 0 ~systemActive~0)) (= ~pumpRunning~0 0)) [2021-12-16 00:59:24,510 INFO L858 garLoopResultBuilder]: For program point L335(lines 335 341) no Hoare annotation was computed. [2021-12-16 00:59:24,510 INFO L858 garLoopResultBuilder]: For program point L335-1(lines 335 341) no Hoare annotation was computed. [2021-12-16 00:59:24,510 INFO L861 garLoopResultBuilder]: At program point L426(lines 418 428) the Hoare annotation is: true [2021-12-16 00:59:24,510 INFO L858 garLoopResultBuilder]: For program point L104(lines 104 110) no Hoare annotation was computed. [2021-12-16 00:59:24,510 INFO L854 garLoopResultBuilder]: At program point L104-2(lines 96 111) the Hoare annotation is: (let ((.cse0 (= |ULTIMATE.start_test_~splverifierCounter~0#1| 0)) (.cse1 (= 1 |ULTIMATE.start_main_~tmp~5#1|)) (.cse2 (= 1 |ULTIMATE.start_valid_product_#res#1|)) (.cse3 (<= 1 ~waterLevel~0)) (.cse4 (= ~pumpRunning~0 0))) (or (and .cse0 .cse1 .cse2 (= ~methAndRunningLastTime~0 0) .cse3 .cse4) (and .cse0 .cse1 .cse2 (<= 1 ~pumpRunning~0) (<= 2 ~waterLevel~0) (not (= 0 ~systemActive~0))) (and .cse0 .cse1 (= ~systemActive~0 0) .cse2 .cse3 .cse4))) [2021-12-16 00:59:24,510 INFO L858 garLoopResultBuilder]: For program point L67(lines 66 115) no Hoare annotation was computed. [2021-12-16 00:59:24,510 INFO L861 garLoopResultBuilder]: At program point L451(lines 432 454) the Hoare annotation is: true [2021-12-16 00:59:24,511 INFO L858 garLoopResultBuilder]: For program point L96(lines 96 111) no Hoare annotation was computed. [2021-12-16 00:59:24,511 INFO L854 garLoopResultBuilder]: At program point L414(lines 410 416) the Hoare annotation is: (and (= 1 |ULTIMATE.start_main_~tmp~5#1|) (= ~waterLevel~0 1) (= ~methaneLevelCritical~0 0) (= 1 |ULTIMATE.start_valid_product_#res#1|) (= ~methAndRunningLastTime~0 0) (not (= 0 ~systemActive~0)) (= ~pumpRunning~0 0)) [2021-12-16 00:59:24,511 INFO L854 garLoopResultBuilder]: At program point L88(line 88) the Hoare annotation is: (let ((.cse0 (= |ULTIMATE.start_test_~splverifierCounter~0#1| 0)) (.cse1 (= 1 |ULTIMATE.start_main_~tmp~5#1|)) (.cse2 (= 1 |ULTIMATE.start_valid_product_#res#1|))) (or (and .cse0 .cse1 .cse2 (= ~methAndRunningLastTime~0 0) (<= 1 ~waterLevel~0) (= ~pumpRunning~0 0)) (and .cse0 .cse1 .cse2 (<= 1 ~pumpRunning~0) (<= 2 ~waterLevel~0) (not (= 0 ~systemActive~0))))) [2021-12-16 00:59:24,511 INFO L854 garLoopResultBuilder]: At program point L113(lines 66 115) the Hoare annotation is: (let ((.cse0 (= |ULTIMATE.start_test_~splverifierCounter~0#1| 0)) (.cse1 (= 1 |ULTIMATE.start_main_~tmp~5#1|)) (.cse2 (= 1 |ULTIMATE.start_valid_product_#res#1|))) (or (and .cse0 .cse1 .cse2 (= ~methAndRunningLastTime~0 0) (<= 1 ~waterLevel~0) (= ~pumpRunning~0 0)) (and .cse0 .cse1 .cse2 (<= 1 ~pumpRunning~0) (<= 2 ~waterLevel~0) (not (= 0 ~systemActive~0))))) [2021-12-16 00:59:24,511 INFO L854 garLoopResultBuilder]: At program point L526(lines 521 529) the Hoare annotation is: (and (= ~waterLevel~0 1) (= ~methaneLevelCritical~0 0) (= 1 |ULTIMATE.start_valid_product_#res#1|) (= ~methAndRunningLastTime~0 0) (not (= 0 ~systemActive~0)) (= ~pumpRunning~0 0)) [2021-12-16 00:59:24,511 INFO L858 garLoopResultBuilder]: For program point L76(lines 76 82) no Hoare annotation was computed. [2021-12-16 00:59:24,511 INFO L858 garLoopResultBuilder]: For program point L76-1(lines 76 82) no Hoare annotation was computed. [2021-12-16 00:59:24,511 INFO L854 garLoopResultBuilder]: At program point L518(lines 514 520) the Hoare annotation is: (and (= ~waterLevel~0 1) (= ~methaneLevelCritical~0 0) (= ~methAndRunningLastTime~0 0) (not (= 0 ~systemActive~0)) (= ~pumpRunning~0 0)) [2021-12-16 00:59:24,512 INFO L858 garLoopResultBuilder]: For program point L68(lines 68 72) no Hoare annotation was computed. [2021-12-16 00:59:24,512 INFO L854 garLoopResultBuilder]: At program point processEnvironment__wrappee__highWaterSensorENTRY(lines 170 194) the Hoare annotation is: (let ((.cse0 (= 0 ~systemActive~0)) (.cse1 (not (<= 1 ~waterLevel~0))) (.cse2 (not (= |old(~pumpRunning~0)| 0))) (.cse3 (= ~pumpRunning~0 0))) (and (or .cse0 .cse1 .cse2 (not (= ~methaneLevelCritical~0 0)) .cse3) (or .cse0 .cse1 .cse2 (not (= ~methAndRunningLastTime~0 0)) .cse3))) [2021-12-16 00:59:24,512 INFO L854 garLoopResultBuilder]: At program point L184(line 184) the Hoare annotation is: (let ((.cse0 (= 0 ~systemActive~0)) (.cse1 (= |processEnvironment__wrappee__highWaterSensor_~tmp~1#1| 0)) (.cse2 (not (<= 1 ~waterLevel~0))) (.cse3 (not (= |old(~pumpRunning~0)| 0)))) (and (or .cse0 (and (= ~pumpRunning~0 0) .cse1) .cse2 .cse3 (not (= ~methAndRunningLastTime~0 0))) (or .cse0 (and (= ~pumpRunning~0 |old(~pumpRunning~0)|) .cse1) .cse2 .cse3 (not (= ~methaneLevelCritical~0 0))))) [2021-12-16 00:59:24,512 INFO L854 garLoopResultBuilder]: At program point L308(lines 293 311) the Hoare annotation is: (let ((.cse5 (= ~pumpRunning~0 0))) (let ((.cse2 (and (= |processEnvironment__wrappee__highWaterSensor_isHighWaterLevel_#res#1| 0) (= |processEnvironment__wrappee__highWaterSensor_isHighWaterLevel_~tmp___0~1#1| 0) .cse5)) (.cse1 (and (<= 2 ~waterLevel~0) .cse5)) (.cse0 (= 0 ~systemActive~0)) (.cse3 (not (<= 1 ~waterLevel~0))) (.cse4 (not (= |old(~pumpRunning~0)| 0)))) (and (or .cse0 .cse1 .cse2 .cse3 .cse4 (not (= ~methAndRunningLastTime~0 0))) (or .cse2 .cse1 .cse0 .cse3 .cse4 (not (= ~methaneLevelCritical~0 0)))))) [2021-12-16 00:59:24,512 INFO L858 garLoopResultBuilder]: For program point L178(lines 178 186) no Hoare annotation was computed. [2021-12-16 00:59:24,512 INFO L858 garLoopResultBuilder]: For program point L174(lines 174 191) no Hoare annotation was computed. [2021-12-16 00:59:24,512 INFO L858 garLoopResultBuilder]: For program point L302(lines 302 306) no Hoare annotation was computed. [2021-12-16 00:59:24,512 INFO L854 garLoopResultBuilder]: At program point L620(lines 611 624) the Hoare annotation is: (let ((.cse5 (= ~pumpRunning~0 0))) (let ((.cse1 (and (<= 2 ~waterLevel~0) .cse5)) (.cse0 (= 0 ~systemActive~0)) (.cse2 (and (<= 1 |processEnvironment__wrappee__highWaterSensor_isHighWaterSensorDry_#res#1|) .cse5)) (.cse3 (not (<= 1 ~waterLevel~0))) (.cse4 (not (= |old(~pumpRunning~0)| 0)))) (and (or .cse0 .cse1 .cse2 .cse3 .cse4 (not (= ~methAndRunningLastTime~0 0))) (or .cse1 .cse0 .cse2 .cse3 .cse4 (not (= ~methaneLevelCritical~0 0)))))) [2021-12-16 00:59:24,513 INFO L858 garLoopResultBuilder]: For program point L302-2(lines 302 306) no Hoare annotation was computed. [2021-12-16 00:59:24,513 INFO L854 garLoopResultBuilder]: At program point L226(lines 221 228) the Hoare annotation is: (let ((.cse0 (= 0 ~systemActive~0)) (.cse1 (and (<= 1 ~pumpRunning~0) (<= 2 ~waterLevel~0))) (.cse2 (not (<= 1 ~waterLevel~0))) (.cse3 (not (= |old(~pumpRunning~0)| 0)))) (and (or .cse0 .cse1 .cse2 .cse3 (not (= ~methaneLevelCritical~0 0))) (or .cse0 .cse1 .cse2 .cse3 (not (= ~methAndRunningLastTime~0 0))))) [2021-12-16 00:59:24,513 INFO L854 garLoopResultBuilder]: At program point L189(line 189) the Hoare annotation is: (let ((.cse0 (= 0 ~systemActive~0)) (.cse1 (not (<= 1 ~waterLevel~0))) (.cse2 (not (= |old(~pumpRunning~0)| 0)))) (and (or .cse0 .cse1 .cse2 (not (= ~methaneLevelCritical~0 0))) (or .cse0 .cse1 .cse2 (not (= ~methAndRunningLastTime~0 0))))) [2021-12-16 00:59:24,513 INFO L858 garLoopResultBuilder]: For program point L189-1(lines 170 194) no Hoare annotation was computed. [2021-12-16 00:59:24,513 INFO L858 garLoopResultBuilder]: For program point processEnvironment__wrappee__highWaterSensorEXIT(lines 170 194) no Hoare annotation was computed. [2021-12-16 00:59:24,513 INFO L858 garLoopResultBuilder]: For program point L615(lines 615 621) no Hoare annotation was computed. [2021-12-16 00:59:24,513 INFO L858 garLoopResultBuilder]: For program point waterRiseEXIT(lines 546 557) no Hoare annotation was computed. [2021-12-16 00:59:24,513 INFO L858 garLoopResultBuilder]: For program point L550-1(lines 546 557) no Hoare annotation was computed. [2021-12-16 00:59:24,513 INFO L854 garLoopResultBuilder]: At program point waterRiseENTRY(lines 546 557) the Hoare annotation is: (let ((.cse0 (= ~waterLevel~0 |old(~waterLevel~0)|))) (and (or (not (= ~pumpRunning~0 0)) .cse0 (not (= ~methAndRunningLastTime~0 0)) (not (<= 1 |old(~waterLevel~0)|))) (or (not (<= 2 |old(~waterLevel~0)|)) (= 0 ~systemActive~0) (not (<= 1 ~pumpRunning~0)) .cse0))) [2021-12-16 00:59:24,516 INFO L732 BasicCegarLoop]: Path program histogram: [1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2021-12-16 00:59:24,516 INFO L179 ceAbstractionStarter]: Computing trace abstraction results [2021-12-16 00:59:24,533 INFO L202 PluginConnector]: Adding new model de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction CFG 16.12 12:59:24 BoogieIcfgContainer [2021-12-16 00:59:24,533 INFO L132 PluginConnector]: ------------------------ END TraceAbstraction---------------------------- [2021-12-16 00:59:24,533 INFO L113 PluginConnector]: ------------------------Witness Printer---------------------------- [2021-12-16 00:59:24,533 INFO L271 PluginConnector]: Initializing Witness Printer... [2021-12-16 00:59:24,534 INFO L275 PluginConnector]: Witness Printer initialized [2021-12-16 00:59:24,534 INFO L185 PluginConnector]: Executing the observer RCFGCatcher from plugin Witness Printer for "de.uni_freiburg.informatik.ultimate.plugins.generator.rcfgbuilder CFG 16.12 12:59:16" (3/4) ... [2021-12-16 00:59:24,536 INFO L137 WitnessPrinter]: Generating witness for correct program [2021-12-16 00:59:24,540 INFO L354 RCFGBacktranslator]: Ignoring RootEdge to procedure deactivatePump [2021-12-16 00:59:24,540 INFO L354 RCFGBacktranslator]: Ignoring RootEdge to procedure processEnvironment__wrappee__base [2021-12-16 00:59:24,540 INFO L354 RCFGBacktranslator]: Ignoring RootEdge to procedure changeMethaneLevel [2021-12-16 00:59:24,540 INFO L354 RCFGBacktranslator]: Ignoring RootEdge to procedure isMethaneLevelCritical [2021-12-16 00:59:24,540 INFO L354 RCFGBacktranslator]: Ignoring RootEdge to procedure cleanup [2021-12-16 00:59:24,540 INFO L354 RCFGBacktranslator]: Ignoring RootEdge to procedure timeShift [2021-12-16 00:59:24,540 INFO L354 RCFGBacktranslator]: Ignoring RootEdge to procedure processEnvironment__wrappee__highWaterSensor [2021-12-16 00:59:24,541 INFO L354 RCFGBacktranslator]: Ignoring RootEdge to procedure waterRise [2021-12-16 00:59:24,548 INFO L910 BoogieBacktranslator]: Reduced CFG by removing 51 nodes and edges [2021-12-16 00:59:24,548 INFO L910 BoogieBacktranslator]: Reduced CFG by removing 22 nodes and edges [2021-12-16 00:59:24,549 INFO L910 BoogieBacktranslator]: Reduced CFG by removing 11 nodes and edges [2021-12-16 00:59:24,549 INFO L910 BoogieBacktranslator]: Reduced CFG by removing 5 nodes and edges [2021-12-16 00:59:24,549 INFO L910 BoogieBacktranslator]: Reduced CFG by removing 2 nodes and edges [2021-12-16 00:59:24,550 INFO L910 BoogieBacktranslator]: Reduced CFG by removing 1 nodes and edges [2021-12-16 00:59:24,550 INFO L910 BoogieBacktranslator]: Reduced CFG by removing 1 nodes and edges [2021-12-16 00:59:24,563 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: ((((waterLevel == 1 && methaneLevelCritical == 0) && 1 == \result) && methAndRunningLastTime == 0) && !(0 == systemActive)) && pumpRunning == 0 [2021-12-16 00:59:24,564 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (((((1 == tmp && waterLevel == 1) && methaneLevelCritical == 0) && 1 == \result) && methAndRunningLastTime == 0) && !(0 == systemActive)) && pumpRunning == 0 [2021-12-16 00:59:24,564 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (((((1 == tmp && waterLevel == 1) && methaneLevelCritical == 0) && 1 == \result) && methAndRunningLastTime == 0) && !(0 == systemActive)) && pumpRunning == 0 [2021-12-16 00:59:24,564 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (((((splverifierCounter == 0 && 1 == tmp) && 1 == \result) && methAndRunningLastTime == 0) && 1 <= waterLevel) && pumpRunning == 0) || (((((splverifierCounter == 0 && 1 == tmp) && 1 == \result) && 1 <= pumpRunning) && 2 <= waterLevel) && !(0 == systemActive)) [2021-12-16 00:59:24,564 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (((((!(2 <= \old(waterLevel)) || 0 == systemActive) || (pumpRunning == \old(pumpRunning) && 1 <= waterLevel)) || !(1 <= \old(pumpRunning))) && ((!(\old(pumpRunning) == 0) || !(1 <= \old(waterLevel))) || !(systemActive == 0))) && ((((!(2 <= \old(waterLevel)) || 0 == systemActive) || methAndRunningLastTime == 0) || !(1 <= \old(pumpRunning))) || !(\old(methAndRunningLastTime) == 0))) && ((!(\old(pumpRunning) == 0) || !(1 <= \old(waterLevel))) || !(\old(methAndRunningLastTime) == 0)) [2021-12-16 00:59:24,565 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (((((!(\old(waterLevel) == 1) || !(\old(pumpRunning) == 0)) || methAndRunningLastTime == 0) || !(\old(methAndRunningLastTime) == 0)) && ((!(\old(pumpRunning) == 0) || !(1 <= \old(waterLevel))) || !(systemActive == 0))) && (((!(2 <= \old(waterLevel)) || 0 == systemActive) || (((((tmp <= 0 && 0 <= \result) && \result <= 0) && 1 <= waterLevel) && 0 < tmp + 1) && pumpRunning == 0)) || !(1 <= \old(pumpRunning)))) && (((((((waterLevel == \old(waterLevel) && 1 <= pumpRunning) && 2 <= waterLevel) && methAndRunningLastTime == 0) || (waterLevel == \old(waterLevel) && pumpRunning == 0)) || !(\old(pumpRunning) == 0)) || !(1 <= \old(waterLevel))) || !(\old(methAndRunningLastTime) == 0)) [2021-12-16 00:59:24,565 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (((((splverifierCounter == 0 && 1 == tmp) && 1 == \result) && 1 <= pumpRunning) && 2 <= waterLevel) && !(0 == systemActive)) || ((((((splverifierCounter == 0 && 1 == tmp) && 1 == \result) && methAndRunningLastTime == 0) && 1 <= waterLevel) && !(0 == systemActive)) && pumpRunning == 0) [2021-12-16 00:59:24,565 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (((((((((waterLevel == \old(waterLevel) && pumpRunning == \old(pumpRunning)) && methAndRunningLastTime == 0) || !(\old(pumpRunning) == 0)) || !(1 <= \old(waterLevel))) || !(systemActive == 0)) && (((((0 == systemActive || ((waterLevel == \old(waterLevel) && 1 <= pumpRunning) && 2 <= waterLevel)) || (((waterLevel == \old(waterLevel) && methAndRunningLastTime == 0) && !(0 == systemActive)) && pumpRunning == 0)) || !(\old(pumpRunning) == 0)) || !(1 <= \old(waterLevel))) || !(\old(methAndRunningLastTime) == 0))) && (((((methAndRunningLastTime == 0 && tmp == 0) || !(\old(pumpRunning) == 0)) || !(methaneLevelCritical == 0)) || !(1 <= \old(waterLevel))) || !(\old(methAndRunningLastTime) == 0))) && (((!(2 <= \old(waterLevel)) || 0 == systemActive) || (((((((tmp <= 0 && 0 <= \result) && \result <= 0) && methAndRunningLastTime == 0) && 1 <= waterLevel) && !(0 == systemActive)) && 0 < tmp + 1) && pumpRunning == 0)) || !(1 <= \old(pumpRunning)))) && ((((!(2 <= \old(waterLevel)) || 0 == systemActive) || !(methaneLevelCritical == 0)) || tmp == 0) || !(1 <= \old(pumpRunning)))) && ((((!(\old(pumpRunning) == 0) || !(methaneLevelCritical == 0)) || !(1 <= \old(waterLevel))) || tmp == 0) || !(systemActive == 0)) [2021-12-16 00:59:24,566 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: ((((splverifierCounter == 0 && 1 == tmp) && systemActive == 0) && 1 == \result) && 1 <= waterLevel) && pumpRunning == 0 [2021-12-16 00:59:24,566 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: ((((((((!(\old(waterLevel) == 1) || !(\old(pumpRunning) == 0)) || methAndRunningLastTime == 0) || !(\old(methAndRunningLastTime) == 0)) && (((((((waterLevel == \old(waterLevel) && 1 <= pumpRunning) && 2 <= waterLevel) && methAndRunningLastTime == 0) || ((\result == 0 && waterLevel == \old(waterLevel)) && pumpRunning == 0)) || !(\old(pumpRunning) == 0)) || !(1 <= \old(waterLevel))) || !(\old(methAndRunningLastTime) == 0))) && (((!(\old(pumpRunning) == 0) || !(methaneLevelCritical == 0)) || !(1 <= \old(waterLevel))) || !(systemActive == 0))) && (((!(\old(pumpRunning) == 0) || !(methaneLevelCritical == 0)) || !(1 <= \old(waterLevel))) || !(\old(methAndRunningLastTime) == 0))) && (((((\result == 0 && waterLevel == \old(waterLevel)) && pumpRunning == 0) || !(\old(pumpRunning) == 0)) || !(1 <= \old(waterLevel))) || !(systemActive == 0))) && (((!(2 <= \old(waterLevel)) || 0 == systemActive) || ((((((tmp <= 0 && 0 <= \result) && \result == 0) && \result <= 0) && 1 <= waterLevel) && 0 < tmp + 1) && pumpRunning == 0)) || !(1 <= \old(pumpRunning)))) && (((!(2 <= \old(waterLevel)) || 0 == systemActive) || !(methaneLevelCritical == 0)) || !(1 <= \old(pumpRunning))) [2021-12-16 00:59:24,566 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: ((((!(\old(pumpRunning) == 0) || !(1 <= \old(waterLevel))) || !(systemActive == 0)) && (((!(2 <= \old(waterLevel)) || 0 == systemActive) || (((0 <= \result && \result <= 0) && pumpRunning == \old(pumpRunning)) && 1 <= waterLevel)) || !(1 <= \old(pumpRunning)))) && ((((!(2 <= \old(waterLevel)) || 0 == systemActive) || methAndRunningLastTime == 0) || !(1 <= \old(pumpRunning))) || !(\old(methAndRunningLastTime) == 0))) && ((!(\old(pumpRunning) == 0) || !(1 <= \old(waterLevel))) || !(\old(methAndRunningLastTime) == 0)) [2021-12-16 00:59:24,566 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (((((0 == systemActive || (2 <= waterLevel && pumpRunning == 0)) || (1 <= \result && pumpRunning == 0)) || !(1 <= waterLevel)) || !(\old(pumpRunning) == 0)) || !(methAndRunningLastTime == 0)) && ((((((2 <= waterLevel && pumpRunning == 0) || 0 == systemActive) || (1 <= \result && pumpRunning == 0)) || !(1 <= waterLevel)) || !(\old(pumpRunning) == 0)) || !(methaneLevelCritical == 0)) [2021-12-16 00:59:24,566 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (((!(\old(pumpRunning) == 0) || !(1 <= \old(waterLevel))) || !(systemActive == 0)) && (((!(2 <= \old(waterLevel)) || 0 == systemActive) || (((((((1 <= tmp___0 && tmp <= 0) && 0 <= \result) && \result <= 0) && 1 <= \result) && pumpRunning == \old(pumpRunning)) && 1 <= waterLevel) && 0 < tmp + 1)) || !(1 <= \old(pumpRunning)))) && ((!(\old(pumpRunning) == 0) || !(1 <= \old(waterLevel))) || !(\old(methAndRunningLastTime) == 0)) [2021-12-16 00:59:24,567 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (((!(\old(pumpRunning) == 0) || !(1 <= \old(waterLevel))) || !(systemActive == 0)) && ((!(2 <= \old(waterLevel)) || 0 == systemActive) || !(1 <= \old(pumpRunning)))) && ((!(\old(pumpRunning) == 0) || !(1 <= \old(waterLevel))) || !(\old(methAndRunningLastTime) == 0)) [2021-12-16 00:59:24,567 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (((((0 == systemActive || (2 <= waterLevel && pumpRunning == 0)) || ((\result == 0 && tmp___0 == 0) && pumpRunning == 0)) || !(1 <= waterLevel)) || !(\old(pumpRunning) == 0)) || !(methAndRunningLastTime == 0)) && (((((((\result == 0 && tmp___0 == 0) && pumpRunning == 0) || (2 <= waterLevel && pumpRunning == 0)) || 0 == systemActive) || !(1 <= waterLevel)) || !(\old(pumpRunning) == 0)) || !(methaneLevelCritical == 0)) [2021-12-16 00:59:24,567 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: ((((0 == systemActive || (1 <= pumpRunning && 2 <= waterLevel)) || !(1 <= waterLevel)) || !(\old(pumpRunning) == 0)) || !(methaneLevelCritical == 0)) && ((((0 == systemActive || (1 <= pumpRunning && 2 <= waterLevel)) || !(1 <= waterLevel)) || !(\old(pumpRunning) == 0)) || !(methAndRunningLastTime == 0)) [2021-12-16 00:59:24,589 INFO L141 WitnessManager]: Wrote witness to /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/witness.graphml [2021-12-16 00:59:24,589 INFO L132 PluginConnector]: ------------------------ END Witness Printer---------------------------- [2021-12-16 00:59:24,589 INFO L158 Benchmark]: Toolchain (without parser) took 8783.92ms. Allocated memory was 90.2MB in the beginning and 142.6MB in the end (delta: 52.4MB). Free memory was 59.6MB in the beginning and 42.4MB in the end (delta: 17.2MB). Peak memory consumption was 70.2MB. Max. memory is 16.1GB. [2021-12-16 00:59:24,590 INFO L158 Benchmark]: CDTParser took 0.17ms. Allocated memory is still 90.2MB. Free memory is still 47.6MB. There was no memory consumed. Max. memory is 16.1GB. [2021-12-16 00:59:24,590 INFO L158 Benchmark]: CACSL2BoogieTranslator took 310.73ms. Allocated memory was 90.2MB in the beginning and 117.4MB in the end (delta: 27.3MB). Free memory was 59.6MB in the beginning and 85.1MB in the end (delta: -25.5MB). Peak memory consumption was 10.5MB. Max. memory is 16.1GB. [2021-12-16 00:59:24,591 INFO L158 Benchmark]: Boogie Procedure Inliner took 38.92ms. Allocated memory is still 117.4MB. Free memory was 85.1MB in the beginning and 83.0MB in the end (delta: 2.1MB). Peak memory consumption was 2.1MB. Max. memory is 16.1GB. [2021-12-16 00:59:24,591 INFO L158 Benchmark]: Boogie Preprocessor took 32.57ms. Allocated memory is still 117.4MB. Free memory was 83.0MB in the beginning and 80.9MB in the end (delta: 2.1MB). Peak memory consumption was 2.1MB. Max. memory is 16.1GB. [2021-12-16 00:59:24,591 INFO L158 Benchmark]: RCFGBuilder took 390.89ms. Allocated memory is still 117.4MB. Free memory was 80.9MB in the beginning and 64.1MB in the end (delta: 16.8MB). Peak memory consumption was 16.8MB. Max. memory is 16.1GB. [2021-12-16 00:59:24,592 INFO L158 Benchmark]: TraceAbstraction took 7950.61ms. Allocated memory was 117.4MB in the beginning and 142.6MB in the end (delta: 25.2MB). Free memory was 63.4MB in the beginning and 49.8MB in the end (delta: 13.6MB). Peak memory consumption was 55.5MB. Max. memory is 16.1GB. [2021-12-16 00:59:24,592 INFO L158 Benchmark]: Witness Printer took 55.66ms. Allocated memory is still 142.6MB. Free memory was 49.8MB in the beginning and 42.4MB in the end (delta: 7.4MB). Peak memory consumption was 8.4MB. Max. memory is 16.1GB. [2021-12-16 00:59:24,595 INFO L339 ainManager$Toolchain]: ####################### End [Toolchain 1] ####################### --- Results --- * Results from de.uni_freiburg.informatik.ultimate.core: - StatisticsResult: Toolchain Benchmarks Benchmark results are: * CDTParser took 0.17ms. Allocated memory is still 90.2MB. Free memory is still 47.6MB. There was no memory consumed. Max. memory is 16.1GB. * CACSL2BoogieTranslator took 310.73ms. Allocated memory was 90.2MB in the beginning and 117.4MB in the end (delta: 27.3MB). Free memory was 59.6MB in the beginning and 85.1MB in the end (delta: -25.5MB). Peak memory consumption was 10.5MB. Max. memory is 16.1GB. * Boogie Procedure Inliner took 38.92ms. Allocated memory is still 117.4MB. Free memory was 85.1MB in the beginning and 83.0MB in the end (delta: 2.1MB). Peak memory consumption was 2.1MB. Max. memory is 16.1GB. * Boogie Preprocessor took 32.57ms. Allocated memory is still 117.4MB. Free memory was 83.0MB in the beginning and 80.9MB in the end (delta: 2.1MB). Peak memory consumption was 2.1MB. Max. memory is 16.1GB. * RCFGBuilder took 390.89ms. Allocated memory is still 117.4MB. Free memory was 80.9MB in the beginning and 64.1MB in the end (delta: 16.8MB). Peak memory consumption was 16.8MB. Max. memory is 16.1GB. * TraceAbstraction took 7950.61ms. Allocated memory was 117.4MB in the beginning and 142.6MB in the end (delta: 25.2MB). Free memory was 63.4MB in the beginning and 49.8MB in the end (delta: 13.6MB). Peak memory consumption was 55.5MB. Max. memory is 16.1GB. * Witness Printer took 55.66ms. Allocated memory is still 142.6MB. Free memory was 49.8MB in the beginning and 42.4MB in the end (delta: 7.4MB). Peak memory consumption was 8.4MB. Max. memory is 16.1GB. * Results from de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction: - StatisticsResult: ErrorAutomatonStatistics NumberErrorTraces: 0, NumberStatementsAllTraces: 0, NumberRelevantStatements: 0, 0.0s ErrorAutomatonConstructionTimeTotal, 0.0s FaulLocalizationTime, NumberStatementsFirstTrace: -1, TraceLengthAvg: 0, 0.0s ErrorAutomatonConstructionTimeAvg, 0.0s ErrorAutomatonDifferenceTimeAvg, 0.0s ErrorAutomatonDifferenceTimeTotal, NumberOfNoEnhancement: 0, NumberOfFiniteEnhancement: 0, NumberOfInfiniteEnhancement: 0 - PositiveResult [Line: 1005]: call to reach_error is unreachable For all program executions holds that call to reach_error is unreachable at this location - StatisticsResult: Ultimate Automizer benchmark data CFG has 9 procedures, 96 locations, 1 error locations. Started 1 CEGAR loops. OverallTime: 7.9s, OverallIterations: 13, TraceHistogramMax: 2, PathProgramHistogramMax: 1, EmptinessCheckTime: 0.0s, AutomataDifference: 1.8s, DeadEndRemovalTime: 0.0s, HoareAnnotationTime: 3.3s, InitialAbstractionConstructionTime: 0.0s, PartialOrderReductionTime: 0.0s, HoareTripleCheckerStatistics: 0 mSolverCounterUnknown, 1746 SdHoareTripleChecker+Valid, 1.1s IncrementalHoareTripleChecker+Time, 0 mSdLazyCounter, 1724 mSDsluCounter, 3681 SdHoareTripleChecker+Invalid, 0.9s Time, 0 mProtectedAction, 0 SdHoareTripleChecker+Unchecked, 0 IncrementalHoareTripleChecker+Unchecked, 2218 mSDsCounter, 529 IncrementalHoareTripleChecker+Valid, 0 mProtectedPredicate, 1435 IncrementalHoareTripleChecker+Invalid, 1964 SdHoareTripleChecker+Unknown, 0 mSolverCounterNotChecked, 529 mSolverCounterUnsat, 1463 mSDtfsCounter, 1435 mSolverCounterSat, 0.0s SdHoareTripleChecker+Time, 0 IncrementalHoareTripleChecker+Unknown, PredicateUnifierStatistics: 0 DeclaredPredicates, 499 GetRequests, 395 SyntacticMatches, 4 SemanticMatches, 100 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 92 ImplicationChecksByTransitivity, 0.4s Time, 0.0s BasicInterpolantAutomatonTime, BiggestAbstraction: size=976occurred in iteration=10, InterpolantAutomatonStates: 90, traceCheckStatistics: No data available, InterpolantConsolidationStatistics: No data available, PathInvariantsStatistics: No data available, 0/0 InterpolantCoveringCapability, TotalInterpolationStatistics: No data available, 0.0s DumpTime, AutomataMinimizationStatistics: 0.3s AutomataMinimizationTime, 13 MinimizatonAttempts, 384 StatesRemovedByMinimization, 9 NontrivialMinimizations, HoareAnnotationStatistics: 0.0s HoareAnnotationTime, 44 LocationsWithAnnotation, 2044 PreInvPairs, 2291 NumberOfFragments, 1781 HoareAnnotationTreeSize, 2044 FomulaSimplifications, 537 FormulaSimplificationTreeSizeReduction, 0.4s HoareSimplificationTime, 44 FomulaSimplificationsInter, 19824 FormulaSimplificationTreeSizeReductionInter, 2.9s HoareSimplificationTimeInter, RefinementEngineStatistics: TRACE_CHECK: 0.1s SsaConstructionTime, 0.3s SatisfiabilityAnalysisTime, 1.2s InterpolantComputationTime, 970 NumberOfCodeBlocks, 970 NumberOfCodeBlocksAsserted, 16 NumberOfCheckSat, 954 ConstructedInterpolants, 0 QuantifiedInterpolants, 1601 SizeOfPredicates, 9 NumberOfNonLiveVariables, 1421 ConjunctsInSsa, 20 ConjunctsInUnsatCore, 16 InterpolantComputations, 13 PerfectInterpolantSequences, 176/184 InterpolantCoveringCapability, INVARIANT_SYNTHESIS: No data available, INTERPOLANT_CONSOLIDATION: No data available, ABSTRACT_INTERPRETATION: No data available, PDR: No data available, ACCELERATED_INTERPOLATION: No data available, SIFA: No data available, ReuseStatistics: No data available - AllSpecificationsHoldResult: All specifications hold 1 specifications checked. All of them hold - InvariantResult [Line: 346]: Loop Invariant Derived loop invariant: (((((splverifierCounter == 0 && 1 == tmp) && 1 == \result) && 1 <= pumpRunning) && 2 <= waterLevel) && !(0 == systemActive)) || ((((((splverifierCounter == 0 && 1 == tmp) && 1 == \result) && methAndRunningLastTime == 0) && 1 <= waterLevel) && !(0 == systemActive)) && pumpRunning == 0) - InvariantResult [Line: 56]: Loop Invariant Derived loop invariant: 1 - InvariantResult [Line: 507]: Loop Invariant Derived loop invariant: (((waterLevel == 1 && methaneLevelCritical == 0) && methAndRunningLastTime == 0) && !(0 == systemActive)) && pumpRunning == 0 - InvariantResult [Line: 312]: Loop Invariant Derived loop invariant: (((!(\old(pumpRunning) == 0) || !(1 <= \old(waterLevel))) || !(systemActive == 0)) && (((!(2 <= \old(waterLevel)) || 0 == systemActive) || (((((((1 <= tmp___0 && tmp <= 0) && 0 <= \result) && \result <= 0) && 1 <= \result) && pumpRunning == \old(pumpRunning)) && 1 <= waterLevel) && 0 < tmp + 1)) || !(1 <= \old(pumpRunning)))) && ((!(\old(pumpRunning) == 0) || !(1 <= \old(waterLevel))) || !(\old(methAndRunningLastTime) == 0)) - InvariantResult [Line: 611]: Loop Invariant Derived loop invariant: (((((0 == systemActive || (2 <= waterLevel && pumpRunning == 0)) || (1 <= \result && pumpRunning == 0)) || !(1 <= waterLevel)) || !(\old(pumpRunning) == 0)) || !(methAndRunningLastTime == 0)) && ((((((2 <= waterLevel && pumpRunning == 0) || 0 == systemActive) || (1 <= \result && pumpRunning == 0)) || !(1 <= waterLevel)) || !(\old(pumpRunning) == 0)) || !(methaneLevelCritical == 0)) - InvariantResult [Line: 410]: Loop Invariant Derived loop invariant: (((((1 == tmp && waterLevel == 1) && methaneLevelCritical == 0) && 1 == \result) && methAndRunningLastTime == 0) && !(0 == systemActive)) && pumpRunning == 0 - InvariantResult [Line: 466]: Loop Invariant Derived loop invariant: (((((((((waterLevel == \old(waterLevel) && pumpRunning == \old(pumpRunning)) && methAndRunningLastTime == 0) || !(\old(pumpRunning) == 0)) || !(1 <= \old(waterLevel))) || !(systemActive == 0)) && (((((0 == systemActive || ((waterLevel == \old(waterLevel) && 1 <= pumpRunning) && 2 <= waterLevel)) || (((waterLevel == \old(waterLevel) && methAndRunningLastTime == 0) && !(0 == systemActive)) && pumpRunning == 0)) || !(\old(pumpRunning) == 0)) || !(1 <= \old(waterLevel))) || !(\old(methAndRunningLastTime) == 0))) && (((((methAndRunningLastTime == 0 && tmp == 0) || !(\old(pumpRunning) == 0)) || !(methaneLevelCritical == 0)) || !(1 <= \old(waterLevel))) || !(\old(methAndRunningLastTime) == 0))) && (((!(2 <= \old(waterLevel)) || 0 == systemActive) || (((((((tmp <= 0 && 0 <= \result) && \result <= 0) && methAndRunningLastTime == 0) && 1 <= waterLevel) && !(0 == systemActive)) && 0 < tmp + 1) && pumpRunning == 0)) || !(1 <= \old(pumpRunning)))) && ((((!(2 <= \old(waterLevel)) || 0 == systemActive) || !(methaneLevelCritical == 0)) || tmp == 0) || !(1 <= \old(pumpRunning)))) && ((((!(\old(pumpRunning) == 0) || !(methaneLevelCritical == 0)) || !(1 <= \old(waterLevel))) || tmp == 0) || !(systemActive == 0)) - InvariantResult [Line: 221]: Loop Invariant Derived loop invariant: ((((0 == systemActive || (1 <= pumpRunning && 2 <= waterLevel)) || !(1 <= waterLevel)) || !(\old(pumpRunning) == 0)) || !(methaneLevelCritical == 0)) && ((((0 == systemActive || (1 <= pumpRunning && 2 <= waterLevel)) || !(1 <= waterLevel)) || !(\old(pumpRunning) == 0)) || !(methAndRunningLastTime == 0)) - InvariantResult [Line: 458]: Loop Invariant Derived loop invariant: (((((1 == tmp && waterLevel == 1) && methaneLevelCritical == 0) && 1 == \result) && methAndRunningLastTime == 0) && !(0 == systemActive)) && pumpRunning == 0 - InvariantResult [Line: 248]: Loop Invariant Derived loop invariant: ((((((((!(\old(waterLevel) == 1) || !(\old(pumpRunning) == 0)) || methAndRunningLastTime == 0) || !(\old(methAndRunningLastTime) == 0)) && (((((((waterLevel == \old(waterLevel) && 1 <= pumpRunning) && 2 <= waterLevel) && methAndRunningLastTime == 0) || ((\result == 0 && waterLevel == \old(waterLevel)) && pumpRunning == 0)) || !(\old(pumpRunning) == 0)) || !(1 <= \old(waterLevel))) || !(\old(methAndRunningLastTime) == 0))) && (((!(\old(pumpRunning) == 0) || !(methaneLevelCritical == 0)) || !(1 <= \old(waterLevel))) || !(systemActive == 0))) && (((!(\old(pumpRunning) == 0) || !(methaneLevelCritical == 0)) || !(1 <= \old(waterLevel))) || !(\old(methAndRunningLastTime) == 0))) && (((((\result == 0 && waterLevel == \old(waterLevel)) && pumpRunning == 0) || !(\old(pumpRunning) == 0)) || !(1 <= \old(waterLevel))) || !(systemActive == 0))) && (((!(2 <= \old(waterLevel)) || 0 == systemActive) || ((((((tmp <= 0 && 0 <= \result) && \result == 0) && \result <= 0) && 1 <= waterLevel) && 0 < tmp + 1) && pumpRunning == 0)) || !(1 <= \old(pumpRunning)))) && (((!(2 <= \old(waterLevel)) || 0 == systemActive) || !(methaneLevelCritical == 0)) || !(1 <= \old(pumpRunning))) - InvariantResult [Line: 293]: Loop Invariant Derived loop invariant: (((((0 == systemActive || (2 <= waterLevel && pumpRunning == 0)) || ((\result == 0 && tmp___0 == 0) && pumpRunning == 0)) || !(1 <= waterLevel)) || !(\old(pumpRunning) == 0)) || !(methAndRunningLastTime == 0)) && (((((((\result == 0 && tmp___0 == 0) && pumpRunning == 0) || (2 <= waterLevel && pumpRunning == 0)) || 0 == systemActive) || !(1 <= waterLevel)) || !(\old(pumpRunning) == 0)) || !(methaneLevelCritical == 0)) - InvariantResult [Line: 514]: Loop Invariant Derived loop invariant: (((waterLevel == 1 && methaneLevelCritical == 0) && methAndRunningLastTime == 0) && !(0 == systemActive)) && pumpRunning == 0 - InvariantResult [Line: 196]: Loop Invariant Derived loop invariant: (((((!(\old(waterLevel) == 1) || !(\old(pumpRunning) == 0)) || methAndRunningLastTime == 0) || !(\old(methAndRunningLastTime) == 0)) && ((!(\old(pumpRunning) == 0) || !(1 <= \old(waterLevel))) || !(systemActive == 0))) && (((!(2 <= \old(waterLevel)) || 0 == systemActive) || (((((tmp <= 0 && 0 <= \result) && \result <= 0) && 1 <= waterLevel) && 0 < tmp + 1) && pumpRunning == 0)) || !(1 <= \old(pumpRunning)))) && (((((((waterLevel == \old(waterLevel) && 1 <= pumpRunning) && 2 <= waterLevel) && methAndRunningLastTime == 0) || (waterLevel == \old(waterLevel) && pumpRunning == 0)) || !(\old(pumpRunning) == 0)) || !(1 <= \old(waterLevel))) || !(\old(methAndRunningLastTime) == 0)) - InvariantResult [Line: 331]: Loop Invariant Derived loop invariant: ((((splverifierCounter == 0 && 1 == tmp) && systemActive == 0) && 1 == \result) && 1 <= waterLevel) && pumpRunning == 0 - InvariantResult [Line: 625]: Loop Invariant Derived loop invariant: ((((!(\old(pumpRunning) == 0) || !(1 <= \old(waterLevel))) || !(systemActive == 0)) && (((!(2 <= \old(waterLevel)) || 0 == systemActive) || (((0 <= \result && \result <= 0) && pumpRunning == \old(pumpRunning)) && 1 <= waterLevel)) || !(1 <= \old(pumpRunning)))) && ((((!(2 <= \old(waterLevel)) || 0 == systemActive) || methAndRunningLastTime == 0) || !(1 <= \old(pumpRunning))) || !(\old(methAndRunningLastTime) == 0))) && ((!(\old(pumpRunning) == 0) || !(1 <= \old(waterLevel))) || !(\old(methAndRunningLastTime) == 0)) - InvariantResult [Line: 366]: Loop Invariant Derived loop invariant: 1 - InvariantResult [Line: 534]: Loop Invariant Derived loop invariant: (((((!(2 <= \old(waterLevel)) || 0 == systemActive) || (pumpRunning == \old(pumpRunning) && 1 <= waterLevel)) || !(1 <= \old(pumpRunning))) && ((!(\old(pumpRunning) == 0) || !(1 <= \old(waterLevel))) || !(systemActive == 0))) && ((((!(2 <= \old(waterLevel)) || 0 == systemActive) || methAndRunningLastTime == 0) || !(1 <= \old(pumpRunning))) || !(\old(methAndRunningLastTime) == 0))) && ((!(\old(pumpRunning) == 0) || !(1 <= \old(waterLevel))) || !(\old(methAndRunningLastTime) == 0)) - InvariantResult [Line: 521]: Loop Invariant Derived loop invariant: ((((waterLevel == 1 && methaneLevelCritical == 0) && 1 == \result) && methAndRunningLastTime == 0) && !(0 == systemActive)) && pumpRunning == 0 - InvariantResult [Line: 1001]: Loop Invariant Derived loop invariant: (((!(\old(pumpRunning) == 0) || !(1 <= \old(waterLevel))) || !(systemActive == 0)) && ((!(2 <= \old(waterLevel)) || 0 == systemActive) || !(1 <= \old(pumpRunning)))) && ((!(\old(pumpRunning) == 0) || !(1 <= \old(waterLevel))) || !(\old(methAndRunningLastTime) == 0)) - InvariantResult [Line: 66]: Loop Invariant Derived loop invariant: (((((splverifierCounter == 0 && 1 == tmp) && 1 == \result) && methAndRunningLastTime == 0) && 1 <= waterLevel) && pumpRunning == 0) || (((((splverifierCounter == 0 && 1 == tmp) && 1 == \result) && 1 <= pumpRunning) && 2 <= waterLevel) && !(0 == systemActive)) - InvariantResult [Line: 65]: Loop Invariant Derived loop invariant: 0 - InvariantResult [Line: 356]: Loop Invariant Derived loop invariant: 1 - InvariantResult [Line: 418]: Loop Invariant Derived loop invariant: 1 - InvariantResult [Line: 432]: Loop Invariant Derived loop invariant: 1 RESULT: Ultimate proved your program to be correct! [2021-12-16 00:59:24,645 INFO L540 MonitoredProcess]: [MP /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in -t:2000 (1)] Forceful destruction successful, exit code 0 Received shutdown request... --- End real Ultimate output --- Execution finished normally Writing output log to file Ultimate.log Result: TRUE