./Ultimate.py --spec ../sv-benchmarks/c/properties/unreach-call.prp --file ../sv-benchmarks/c/product-lines/minepump_spec3_product37.cil.c --full-output --architecture 32bit -------------------------------------------------------------------------------- Checking for ERROR reachability Using default analysis Version c3fed411 Calling Ultimate with: /usr/bin/java -Dosgi.configuration.area=/storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/data/config -Xmx15G -Xms4m -jar /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/plugins/org.eclipse.equinox.launcher_1.5.800.v20200727-1323.jar -data @noDefault -ultimatedata /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/data -tc /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/config/AutomizerReach.xml -i ../sv-benchmarks/c/product-lines/minepump_spec3_product37.cil.c -s /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/config/svcomp-Reach-32bit-Automizer_Default.epf --cacsl2boogietranslator.entry.function main --witnessprinter.witness.directory /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux --witnessprinter.witness.filename witness.graphml --witnessprinter.write.witness.besides.input.file false --witnessprinter.graph.data.specification CHECK( init(main()), LTL(G ! call(reach_error())) ) --witnessprinter.graph.data.producer Automizer --witnessprinter.graph.data.architecture 32bit --witnessprinter.graph.data.programhash 29e70cf9c9b1d0bd005d907ed1d78af9dd0d19752a19f66dfee72f35dd243fc7 --- Real Ultimate output --- This is Ultimate 0.2.2-tmp.no-commuhash-c3fed41 [2021-12-16 00:59:47,935 INFO L177 SettingsManager]: Resetting all preferences to default values... [2021-12-16 00:59:47,937 INFO L181 SettingsManager]: Resetting UltimateCore preferences to default values [2021-12-16 00:59:48,013 INFO L184 SettingsManager]: Ultimate Commandline Interface provides no preferences, ignoring... [2021-12-16 00:59:48,013 INFO L181 SettingsManager]: Resetting Boogie Preprocessor preferences to default values [2021-12-16 00:59:48,016 INFO L181 SettingsManager]: Resetting Boogie Procedure Inliner preferences to default values [2021-12-16 00:59:48,017 INFO L181 SettingsManager]: Resetting Abstract Interpretation preferences to default values [2021-12-16 00:59:48,021 INFO L181 SettingsManager]: Resetting LassoRanker preferences to default values [2021-12-16 00:59:48,024 INFO L181 SettingsManager]: Resetting Reaching Definitions preferences to default values [2021-12-16 00:59:48,028 INFO L181 SettingsManager]: Resetting SyntaxChecker preferences to default values [2021-12-16 00:59:48,029 INFO L181 SettingsManager]: Resetting Sifa preferences to default values [2021-12-16 00:59:48,030 INFO L184 SettingsManager]: Büchi Program Product provides no preferences, ignoring... [2021-12-16 00:59:48,030 INFO L181 SettingsManager]: Resetting LTL2Aut preferences to default values [2021-12-16 00:59:48,033 INFO L181 SettingsManager]: Resetting PEA to Boogie preferences to default values [2021-12-16 00:59:48,034 INFO L181 SettingsManager]: Resetting BlockEncodingV2 preferences to default values [2021-12-16 00:59:48,053 INFO L181 SettingsManager]: Resetting ChcToBoogie preferences to default values [2021-12-16 00:59:48,054 INFO L181 SettingsManager]: Resetting AutomataScriptInterpreter preferences to default values [2021-12-16 00:59:48,054 INFO L181 SettingsManager]: Resetting BuchiAutomizer preferences to default values [2021-12-16 00:59:48,056 INFO L181 SettingsManager]: Resetting CACSL2BoogieTranslator preferences to default values [2021-12-16 00:59:48,061 INFO L181 SettingsManager]: Resetting CodeCheck preferences to default values [2021-12-16 00:59:48,062 INFO L181 SettingsManager]: Resetting InvariantSynthesis preferences to default values [2021-12-16 00:59:48,063 INFO L181 SettingsManager]: Resetting RCFGBuilder preferences to default values [2021-12-16 00:59:48,065 INFO L181 SettingsManager]: Resetting Referee preferences to default values [2021-12-16 00:59:48,066 INFO L181 SettingsManager]: Resetting TraceAbstraction preferences to default values [2021-12-16 00:59:48,075 INFO L184 SettingsManager]: TraceAbstractionConcurrent provides no preferences, ignoring... [2021-12-16 00:59:48,076 INFO L184 SettingsManager]: TraceAbstractionWithAFAs provides no preferences, ignoring... [2021-12-16 00:59:48,076 INFO L181 SettingsManager]: Resetting TreeAutomizer preferences to default values [2021-12-16 00:59:48,077 INFO L181 SettingsManager]: Resetting IcfgToChc preferences to default values [2021-12-16 00:59:48,078 INFO L181 SettingsManager]: Resetting IcfgTransformer preferences to default values [2021-12-16 00:59:48,078 INFO L184 SettingsManager]: ReqToTest provides no preferences, ignoring... [2021-12-16 00:59:48,079 INFO L181 SettingsManager]: Resetting Boogie Printer preferences to default values [2021-12-16 00:59:48,080 INFO L181 SettingsManager]: Resetting ChcSmtPrinter preferences to default values [2021-12-16 00:59:48,081 INFO L181 SettingsManager]: Resetting ReqPrinter preferences to default values [2021-12-16 00:59:48,082 INFO L181 SettingsManager]: Resetting Witness Printer preferences to default values [2021-12-16 00:59:48,083 INFO L184 SettingsManager]: Boogie PL CUP Parser provides no preferences, ignoring... [2021-12-16 00:59:48,083 INFO L181 SettingsManager]: Resetting CDTParser preferences to default values [2021-12-16 00:59:48,085 INFO L184 SettingsManager]: AutomataScriptParser provides no preferences, ignoring... [2021-12-16 00:59:48,085 INFO L184 SettingsManager]: ReqParser provides no preferences, ignoring... [2021-12-16 00:59:48,085 INFO L181 SettingsManager]: Resetting SmtParser preferences to default values [2021-12-16 00:59:48,086 INFO L181 SettingsManager]: Resetting Witness Parser preferences to default values [2021-12-16 00:59:48,086 INFO L188 SettingsManager]: Finished resetting all preferences to default values... [2021-12-16 00:59:48,087 INFO L101 SettingsManager]: Beginning loading settings from /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/config/svcomp-Reach-32bit-Automizer_Default.epf [2021-12-16 00:59:48,113 INFO L113 SettingsManager]: Loading preferences was successful [2021-12-16 00:59:48,113 INFO L115 SettingsManager]: Preferences different from defaults after loading the file: [2021-12-16 00:59:48,113 INFO L136 SettingsManager]: Preferences of UltimateCore differ from their defaults: [2021-12-16 00:59:48,114 INFO L138 SettingsManager]: * Log level for class=de.uni_freiburg.informatik.ultimate.lib.smtlibutils.quantifier.QuantifierPusher=ERROR; [2021-12-16 00:59:48,114 INFO L136 SettingsManager]: Preferences of Boogie Procedure Inliner differ from their defaults: [2021-12-16 00:59:48,115 INFO L138 SettingsManager]: * Ignore calls to procedures called more than once=ONLY_FOR_SEQUENTIAL_PROGRAMS [2021-12-16 00:59:48,115 INFO L136 SettingsManager]: Preferences of BlockEncodingV2 differ from their defaults: [2021-12-16 00:59:48,115 INFO L138 SettingsManager]: * Create parallel compositions if possible=false [2021-12-16 00:59:48,115 INFO L138 SettingsManager]: * Use SBE=true [2021-12-16 00:59:48,116 INFO L136 SettingsManager]: Preferences of CACSL2BoogieTranslator differ from their defaults: [2021-12-16 00:59:48,116 INFO L138 SettingsManager]: * sizeof long=4 [2021-12-16 00:59:48,117 INFO L138 SettingsManager]: * Overapproximate operations on floating types=true [2021-12-16 00:59:48,117 INFO L138 SettingsManager]: * sizeof POINTER=4 [2021-12-16 00:59:48,117 INFO L138 SettingsManager]: * Check division by zero=IGNORE [2021-12-16 00:59:48,117 INFO L138 SettingsManager]: * Pointer to allocated memory at dereference=IGNORE [2021-12-16 00:59:48,117 INFO L138 SettingsManager]: * If two pointers are subtracted or compared they have the same base address=IGNORE [2021-12-16 00:59:48,118 INFO L138 SettingsManager]: * Check array bounds for arrays that are off heap=IGNORE [2021-12-16 00:59:48,118 INFO L138 SettingsManager]: * sizeof long double=12 [2021-12-16 00:59:48,118 INFO L138 SettingsManager]: * Check if freed pointer was valid=false [2021-12-16 00:59:48,118 INFO L138 SettingsManager]: * Use constant arrays=true [2021-12-16 00:59:48,118 INFO L138 SettingsManager]: * Pointer base address is valid at dereference=IGNORE [2021-12-16 00:59:48,118 INFO L136 SettingsManager]: Preferences of RCFGBuilder differ from their defaults: [2021-12-16 00:59:48,119 INFO L138 SettingsManager]: * Size of a code block=SequenceOfStatements [2021-12-16 00:59:48,119 INFO L138 SettingsManager]: * SMT solver=External_DefaultMode [2021-12-16 00:59:48,119 INFO L138 SettingsManager]: * Command for external solver=z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in -t:2000 [2021-12-16 00:59:48,119 INFO L136 SettingsManager]: Preferences of TraceAbstraction differ from their defaults: [2021-12-16 00:59:48,119 INFO L138 SettingsManager]: * Compute Interpolants along a Counterexample=FPandBP [2021-12-16 00:59:48,120 INFO L138 SettingsManager]: * Positions where we compute the Hoare Annotation=LoopsAndPotentialCycles [2021-12-16 00:59:48,121 INFO L138 SettingsManager]: * Trace refinement strategy=CAMEL [2021-12-16 00:59:48,121 INFO L138 SettingsManager]: * Command for external solver=z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in [2021-12-16 00:59:48,121 INFO L138 SettingsManager]: * Large block encoding in concurrent analysis=OFF [2021-12-16 00:59:48,121 INFO L138 SettingsManager]: * Automaton type used in concurrency analysis=PETRI_NET [2021-12-16 00:59:48,121 INFO L138 SettingsManager]: * Compute Hoare Annotation of negated interpolant automaton, abstraction and CFG=true [2021-12-16 00:59:48,122 INFO L138 SettingsManager]: * Trace refinement exception blacklist=NONE [2021-12-16 00:59:48,122 INFO L138 SettingsManager]: * SMT solver=External_ModelsAndUnsatCoreMode WARNING: An illegal reflective access operation has occurred WARNING: Illegal reflective access by com.sun.xml.bind.v2.runtime.reflect.opt.Injector$1 (file:/storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/plugins/com.sun.xml.bind_2.2.0.v201505121915.jar) to method java.lang.ClassLoader.defineClass(java.lang.String,byte[],int,int) WARNING: Please consider reporting this to the maintainers of com.sun.xml.bind.v2.runtime.reflect.opt.Injector$1 WARNING: Use --illegal-access=warn to enable warnings of further illegal reflective access operations WARNING: All illegal access operations will be denied in a future release Applying setting for plugin de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator: Entry function -> main Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Witness directory -> /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Witness filename -> witness.graphml Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Write witness besides input file -> false Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Graph data specification -> CHECK( init(main()), LTL(G ! call(reach_error())) ) Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Graph data producer -> Automizer Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Graph data architecture -> 32bit Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Graph data programhash -> 29e70cf9c9b1d0bd005d907ed1d78af9dd0d19752a19f66dfee72f35dd243fc7 [2021-12-16 00:59:48,344 INFO L75 nceAwareModelManager]: Repository-Root is: /tmp [2021-12-16 00:59:48,363 INFO L261 ainManager$Toolchain]: [Toolchain 1]: Applicable parser(s) successfully (re)initialized [2021-12-16 00:59:48,366 INFO L217 ainManager$Toolchain]: [Toolchain 1]: Toolchain selected. [2021-12-16 00:59:48,367 INFO L271 PluginConnector]: Initializing CDTParser... [2021-12-16 00:59:48,367 INFO L275 PluginConnector]: CDTParser initialized [2021-12-16 00:59:48,368 INFO L432 ainManager$Toolchain]: [Toolchain 1]: Parsing single file: /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/../sv-benchmarks/c/product-lines/minepump_spec3_product37.cil.c [2021-12-16 00:59:48,422 INFO L220 CDTParser]: Created temporary CDT project at /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/data/e9e8e2fb1/8afc977a6f0a41a6ad03830dd9922d3c/FLAG3ff0ec522 [2021-12-16 00:59:48,850 INFO L306 CDTParser]: Found 1 translation units. [2021-12-16 00:59:48,853 INFO L160 CDTParser]: Scanning /storage/repos/ultimate/releaseScripts/default/sv-benchmarks/c/product-lines/minepump_spec3_product37.cil.c [2021-12-16 00:59:48,869 INFO L349 CDTParser]: About to delete temporary CDT project at /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/data/e9e8e2fb1/8afc977a6f0a41a6ad03830dd9922d3c/FLAG3ff0ec522 [2021-12-16 00:59:48,883 INFO L357 CDTParser]: Successfully deleted /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/data/e9e8e2fb1/8afc977a6f0a41a6ad03830dd9922d3c [2021-12-16 00:59:48,887 INFO L299 ainManager$Toolchain]: ####################### [Toolchain 1] ####################### [2021-12-16 00:59:48,888 INFO L131 ToolchainWalker]: Walking toolchain with 6 elements. [2021-12-16 00:59:48,891 INFO L113 PluginConnector]: ------------------------CACSL2BoogieTranslator---------------------------- [2021-12-16 00:59:48,891 INFO L271 PluginConnector]: Initializing CACSL2BoogieTranslator... [2021-12-16 00:59:48,894 INFO L275 PluginConnector]: CACSL2BoogieTranslator initialized [2021-12-16 00:59:48,895 INFO L185 PluginConnector]: Executing the observer ACSLObjectContainerObserver from plugin CACSL2BoogieTranslator for "CDTParser AST 16.12 12:59:48" (1/1) ... [2021-12-16 00:59:48,896 INFO L205 PluginConnector]: Invalid model from CACSL2BoogieTranslator for observer de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator.ACSLObjectContainerObserver@210b7b04 and model type de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 16.12 12:59:48, skipping insertion in model container [2021-12-16 00:59:48,896 INFO L185 PluginConnector]: Executing the observer CACSL2BoogieTranslatorObserver from plugin CACSL2BoogieTranslator for "CDTParser AST 16.12 12:59:48" (1/1) ... [2021-12-16 00:59:48,902 INFO L145 MainTranslator]: Starting translation in SV-COMP mode [2021-12-16 00:59:48,951 INFO L178 MainTranslator]: Built tables and reachable declarations [2021-12-16 00:59:49,246 WARN L230 ndardFunctionHandler]: Function reach_error is already implemented but we override the implementation for the call at /storage/repos/ultimate/releaseScripts/default/sv-benchmarks/c/product-lines/minepump_spec3_product37.cil.c[17206,17219] [2021-12-16 00:59:49,258 INFO L209 PostProcessor]: Analyzing one entry point: main [2021-12-16 00:59:49,266 INFO L203 MainTranslator]: Completed pre-run [2021-12-16 00:59:49,311 WARN L230 ndardFunctionHandler]: Function reach_error is already implemented but we override the implementation for the call at /storage/repos/ultimate/releaseScripts/default/sv-benchmarks/c/product-lines/minepump_spec3_product37.cil.c[17206,17219] [2021-12-16 00:59:49,314 INFO L209 PostProcessor]: Analyzing one entry point: main [2021-12-16 00:59:49,327 INFO L208 MainTranslator]: Completed translation [2021-12-16 00:59:49,329 INFO L202 PluginConnector]: Adding new model de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 16.12 12:59:49 WrapperNode [2021-12-16 00:59:49,329 INFO L132 PluginConnector]: ------------------------ END CACSL2BoogieTranslator---------------------------- [2021-12-16 00:59:49,330 INFO L113 PluginConnector]: ------------------------Boogie Procedure Inliner---------------------------- [2021-12-16 00:59:49,330 INFO L271 PluginConnector]: Initializing Boogie Procedure Inliner... [2021-12-16 00:59:49,330 INFO L275 PluginConnector]: Boogie Procedure Inliner initialized [2021-12-16 00:59:49,336 INFO L185 PluginConnector]: Executing the observer TypeChecker from plugin Boogie Procedure Inliner for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 16.12 12:59:49" (1/1) ... [2021-12-16 00:59:49,362 INFO L185 PluginConnector]: Executing the observer Inliner from plugin Boogie Procedure Inliner for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 16.12 12:59:49" (1/1) ... [2021-12-16 00:59:49,388 INFO L137 Inliner]: procedures = 53, calls = 154, calls flagged for inlining = 22, calls inlined = 19, statements flattened = 251 [2021-12-16 00:59:49,389 INFO L132 PluginConnector]: ------------------------ END Boogie Procedure Inliner---------------------------- [2021-12-16 00:59:49,390 INFO L113 PluginConnector]: ------------------------Boogie Preprocessor---------------------------- [2021-12-16 00:59:49,390 INFO L271 PluginConnector]: Initializing Boogie Preprocessor... [2021-12-16 00:59:49,390 INFO L275 PluginConnector]: Boogie Preprocessor initialized [2021-12-16 00:59:49,397 INFO L185 PluginConnector]: Executing the observer EnsureBoogieModelObserver from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 16.12 12:59:49" (1/1) ... [2021-12-16 00:59:49,397 INFO L185 PluginConnector]: Executing the observer TypeChecker from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 16.12 12:59:49" (1/1) ... [2021-12-16 00:59:49,399 INFO L185 PluginConnector]: Executing the observer ConstExpander from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 16.12 12:59:49" (1/1) ... [2021-12-16 00:59:49,399 INFO L185 PluginConnector]: Executing the observer StructExpander from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 16.12 12:59:49" (1/1) ... [2021-12-16 00:59:49,403 INFO L185 PluginConnector]: Executing the observer UnstructureCode from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 16.12 12:59:49" (1/1) ... [2021-12-16 00:59:49,413 INFO L185 PluginConnector]: Executing the observer FunctionInliner from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 16.12 12:59:49" (1/1) ... [2021-12-16 00:59:49,416 INFO L185 PluginConnector]: Executing the observer BoogieSymbolTableConstructor from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 16.12 12:59:49" (1/1) ... [2021-12-16 00:59:49,418 INFO L132 PluginConnector]: ------------------------ END Boogie Preprocessor---------------------------- [2021-12-16 00:59:49,418 INFO L113 PluginConnector]: ------------------------RCFGBuilder---------------------------- [2021-12-16 00:59:49,419 INFO L271 PluginConnector]: Initializing RCFGBuilder... [2021-12-16 00:59:49,419 INFO L275 PluginConnector]: RCFGBuilder initialized [2021-12-16 00:59:49,419 INFO L185 PluginConnector]: Executing the observer RCFGBuilderObserver from plugin RCFGBuilder for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 16.12 12:59:49" (1/1) ... [2021-12-16 00:59:49,427 INFO L168 SolverBuilder]: Constructing external solver with command: z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in -t:2000 [2021-12-16 00:59:49,435 INFO L189 MonitoredProcess]: No working directory specified, using /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 [2021-12-16 00:59:49,446 INFO L229 MonitoredProcess]: Starting monitored process 1 with /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in -t:2000 (exit command is (exit), workingDir is null) [2021-12-16 00:59:49,447 INFO L327 MonitoredProcess]: [MP /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in -t:2000 (1)] Waiting until timeout for monitored process [2021-12-16 00:59:49,479 INFO L130 BoogieDeclarations]: Found specification of procedure #Ultimate.allocInit [2021-12-16 00:59:49,479 INFO L130 BoogieDeclarations]: Found specification of procedure processEnvironment__wrappee__base [2021-12-16 00:59:49,480 INFO L138 BoogieDeclarations]: Found implementation of procedure processEnvironment__wrappee__base [2021-12-16 00:59:49,480 INFO L130 BoogieDeclarations]: Found specification of procedure isMethaneLevelCritical [2021-12-16 00:59:49,480 INFO L138 BoogieDeclarations]: Found implementation of procedure isMethaneLevelCritical [2021-12-16 00:59:49,480 INFO L130 BoogieDeclarations]: Found specification of procedure timeShift [2021-12-16 00:59:49,481 INFO L138 BoogieDeclarations]: Found implementation of procedure timeShift [2021-12-16 00:59:49,484 INFO L130 BoogieDeclarations]: Found specification of procedure cleanup [2021-12-16 00:59:49,484 INFO L138 BoogieDeclarations]: Found implementation of procedure cleanup [2021-12-16 00:59:49,484 INFO L130 BoogieDeclarations]: Found specification of procedure processEnvironment__wrappee__highWaterSensor [2021-12-16 00:59:49,485 INFO L138 BoogieDeclarations]: Found implementation of procedure processEnvironment__wrappee__highWaterSensor [2021-12-16 00:59:49,485 INFO L130 BoogieDeclarations]: Found specification of procedure waterRise [2021-12-16 00:59:49,485 INFO L138 BoogieDeclarations]: Found implementation of procedure waterRise [2021-12-16 00:59:49,485 INFO L130 BoogieDeclarations]: Found specification of procedure write~init~int [2021-12-16 00:59:49,485 INFO L130 BoogieDeclarations]: Found specification of procedure changeMethaneLevel [2021-12-16 00:59:49,485 INFO L138 BoogieDeclarations]: Found implementation of procedure changeMethaneLevel [2021-12-16 00:59:49,485 INFO L130 BoogieDeclarations]: Found specification of procedure ULTIMATE.start [2021-12-16 00:59:49,485 INFO L138 BoogieDeclarations]: Found implementation of procedure ULTIMATE.start [2021-12-16 00:59:49,573 INFO L236 CfgBuilder]: Building ICFG [2021-12-16 00:59:49,575 INFO L262 CfgBuilder]: Building CFG for each procedure with an implementation [2021-12-16 00:59:49,831 INFO L277 CfgBuilder]: Performing block encoding [2021-12-16 00:59:49,843 INFO L296 CfgBuilder]: Using the 1 location(s) as analysis (start of procedure ULTIMATE.start) [2021-12-16 00:59:49,843 INFO L301 CfgBuilder]: Removed 2 assume(true) statements. [2021-12-16 00:59:49,845 INFO L202 PluginConnector]: Adding new model de.uni_freiburg.informatik.ultimate.plugins.generator.rcfgbuilder CFG 16.12 12:59:49 BoogieIcfgContainer [2021-12-16 00:59:49,845 INFO L132 PluginConnector]: ------------------------ END RCFGBuilder---------------------------- [2021-12-16 00:59:49,846 INFO L113 PluginConnector]: ------------------------TraceAbstraction---------------------------- [2021-12-16 00:59:49,851 INFO L271 PluginConnector]: Initializing TraceAbstraction... [2021-12-16 00:59:49,854 INFO L275 PluginConnector]: TraceAbstraction initialized [2021-12-16 00:59:49,854 INFO L185 PluginConnector]: Executing the observer TraceAbstractionObserver from plugin TraceAbstraction for "CDTParser AST 16.12 12:59:48" (1/3) ... [2021-12-16 00:59:49,855 INFO L205 PluginConnector]: Invalid model from TraceAbstraction for observer de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction.TraceAbstractionObserver@3fb4f9ff and model type de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction AST 16.12 12:59:49, skipping insertion in model container [2021-12-16 00:59:49,855 INFO L185 PluginConnector]: Executing the observer TraceAbstractionObserver from plugin TraceAbstraction for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 16.12 12:59:49" (2/3) ... [2021-12-16 00:59:49,855 INFO L205 PluginConnector]: Invalid model from TraceAbstraction for observer de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction.TraceAbstractionObserver@3fb4f9ff and model type de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction AST 16.12 12:59:49, skipping insertion in model container [2021-12-16 00:59:49,856 INFO L185 PluginConnector]: Executing the observer TraceAbstractionObserver from plugin TraceAbstraction for "de.uni_freiburg.informatik.ultimate.plugins.generator.rcfgbuilder CFG 16.12 12:59:49" (3/3) ... [2021-12-16 00:59:49,872 INFO L111 eAbstractionObserver]: Analyzing ICFG minepump_spec3_product37.cil.c [2021-12-16 00:59:49,876 INFO L204 ceAbstractionStarter]: Automizer settings: Hoare:true NWA Interpolation:FPandBP Determinization: PREDICATE_ABSTRACTION [2021-12-16 00:59:49,876 INFO L163 ceAbstractionStarter]: Applying trace abstraction to program that has 1 error locations. [2021-12-16 00:59:49,929 INFO L338 AbstractCegarLoop]: ======== Iteration 0 == of CEGAR loop == AllErrorsAtOnce ======== [2021-12-16 00:59:49,935 INFO L339 AbstractCegarLoop]: Settings: SEPARATE_VIOLATION_CHECK=true, mInterprocedural=true, mMaxIterations=1000000, mWatchIteration=1000000, mArtifact=RCFG, mInterpolation=FPandBP, mInterpolantAutomaton=STRAIGHT_LINE, mDumpAutomata=false, mAutomataFormat=ATS_NUMERATE, mDumpPath=., mDeterminiation=PREDICATE_ABSTRACTION, mMinimize=MINIMIZE_SEVPA, mHoare=true, mAutomataTypeConcurrency=PETRI_NET, mHoareTripleChecks=INCREMENTAL, mHoareAnnotationPositions=LoopsAndPotentialCycles, mDumpOnlyReuseAutomata=false, mLimitTraceHistogram=0, mErrorLocTimeLimit=0, mLimitPathProgramCount=0, mCollectInterpolantStatistics=true, mHeuristicEmptinessCheck=false, mHeuristicEmptinessCheckAStarHeuristic=ZERO, mHeuristicEmptinessCheckAStarHeuristicRandomSeed=1337, mHeuristicEmptinessCheckSmtFeatureScoringMethod=DAGSIZE, mSMTFeatureExtraction=false, mSMTFeatureExtractionDumpPath=., mOverrideInterpolantAutomaton=false, mMcrInterpolantMethod=WP, mLoopAccelerationTechnique=FAST_UPR [2021-12-16 00:59:49,935 INFO L340 AbstractCegarLoop]: Starting to check reachability of 1 error locations. [2021-12-16 00:59:49,949 INFO L276 IsEmpty]: Start isEmpty. Operand has 87 states, 66 states have (on average 1.393939393939394) internal successors, (92), 74 states have internal predecessors, (92), 12 states have call successors, (12), 7 states have call predecessors, (12), 7 states have return successors, (12), 10 states have call predecessors, (12), 12 states have call successors, (12) [2021-12-16 00:59:49,955 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 26 [2021-12-16 00:59:49,956 INFO L506 BasicCegarLoop]: Found error trace [2021-12-16 00:59:49,957 INFO L514 BasicCegarLoop]: trace histogram [1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2021-12-16 00:59:49,957 INFO L402 AbstractCegarLoop]: === Iteration 1 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2021-12-16 00:59:49,965 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2021-12-16 00:59:49,966 INFO L85 PathProgramCache]: Analyzing trace with hash -817040355, now seen corresponding path program 1 times [2021-12-16 00:59:49,973 INFO L121 FreeRefinementEngine]: Executing refinement strategy CAMEL [2021-12-16 00:59:49,974 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [1656896545] [2021-12-16 00:59:49,974 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2021-12-16 00:59:49,975 INFO L126 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2021-12-16 00:59:50,104 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 00:59:50,159 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 14 [2021-12-16 00:59:50,162 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 00:59:50,171 INFO L134 CoverageAnalysis]: Checked inductivity of 0 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2021-12-16 00:59:50,173 INFO L139 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2021-12-16 00:59:50,174 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [1656896545] [2021-12-16 00:59:50,174 INFO L160 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [1656896545] provided 1 perfect and 0 imperfect interpolant sequences [2021-12-16 00:59:50,175 INFO L186 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2021-12-16 00:59:50,175 INFO L199 FreeRefinementEngine]: Number of different interpolants: perfect sequences [2] imperfect sequences [] total 2 [2021-12-16 00:59:50,177 INFO L115 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [1234799666] [2021-12-16 00:59:50,177 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2021-12-16 00:59:50,180 INFO L546 AbstractCegarLoop]: INTERPOLANT automaton has 2 states [2021-12-16 00:59:50,180 INFO L103 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2021-12-16 00:59:50,212 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 2 interpolants. [2021-12-16 00:59:50,213 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=1, Invalid=1, Unknown=0, NotChecked=0, Total=2 [2021-12-16 00:59:50,216 INFO L87 Difference]: Start difference. First operand has 87 states, 66 states have (on average 1.393939393939394) internal successors, (92), 74 states have internal predecessors, (92), 12 states have call successors, (12), 7 states have call predecessors, (12), 7 states have return successors, (12), 10 states have call predecessors, (12), 12 states have call successors, (12) Second operand has 2 states, 2 states have (on average 10.5) internal successors, (21), 2 states have internal predecessors, (21), 1 states have call successors, (3), 2 states have call predecessors, (3), 1 states have return successors, (1), 1 states have call predecessors, (1), 1 states have call successors, (1) [2021-12-16 00:59:50,259 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2021-12-16 00:59:50,259 INFO L93 Difference]: Finished difference Result 166 states and 227 transitions. [2021-12-16 00:59:50,260 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 2 states. [2021-12-16 00:59:50,261 INFO L78 Accepts]: Start accepts. Automaton has has 2 states, 2 states have (on average 10.5) internal successors, (21), 2 states have internal predecessors, (21), 1 states have call successors, (3), 2 states have call predecessors, (3), 1 states have return successors, (1), 1 states have call predecessors, (1), 1 states have call successors, (1) Word has length 25 [2021-12-16 00:59:50,261 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2021-12-16 00:59:50,269 INFO L225 Difference]: With dead ends: 166 [2021-12-16 00:59:50,270 INFO L226 Difference]: Without dead ends: 78 [2021-12-16 00:59:50,273 INFO L932 BasicCegarLoop]: 0 DeclaredPredicates, 4 GetRequests, 4 SyntacticMatches, 0 SemanticMatches, 0 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 0 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=1, Invalid=1, Unknown=0, NotChecked=0, Total=2 [2021-12-16 00:59:50,276 INFO L933 BasicCegarLoop]: 110 mSDtfsCounter, 0 mSDsluCounter, 0 mSDsCounter, 0 mSdLazyCounter, 0 mSolverCounterSat, 0 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.0s Time, 0 mProtectedPredicate, 0 mProtectedAction, 0 SdHoareTripleChecker+Valid, 110 SdHoareTripleChecker+Invalid, 0 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 0 IncrementalHoareTripleChecker+Valid, 0 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.0s IncrementalHoareTripleChecker+Time [2021-12-16 00:59:50,277 INFO L934 BasicCegarLoop]: SdHoareTripleChecker [0 Valid, 110 Invalid, 0 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [0 Valid, 0 Invalid, 0 Unknown, 0 Unchecked, 0.0s Time] [2021-12-16 00:59:50,289 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 78 states. [2021-12-16 00:59:50,322 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 78 to 78. [2021-12-16 00:59:50,323 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 78 states, 59 states have (on average 1.3220338983050848) internal successors, (78), 66 states have internal predecessors, (78), 12 states have call successors, (12), 7 states have call predecessors, (12), 6 states have return successors, (11), 9 states have call predecessors, (11), 11 states have call successors, (11) [2021-12-16 00:59:50,327 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 78 states to 78 states and 101 transitions. [2021-12-16 00:59:50,328 INFO L78 Accepts]: Start accepts. Automaton has 78 states and 101 transitions. Word has length 25 [2021-12-16 00:59:50,328 INFO L84 Accepts]: Finished accepts. word is rejected. [2021-12-16 00:59:50,328 INFO L470 AbstractCegarLoop]: Abstraction has 78 states and 101 transitions. [2021-12-16 00:59:50,329 INFO L471 AbstractCegarLoop]: INTERPOLANT automaton has has 2 states, 2 states have (on average 10.5) internal successors, (21), 2 states have internal predecessors, (21), 1 states have call successors, (3), 2 states have call predecessors, (3), 1 states have return successors, (1), 1 states have call predecessors, (1), 1 states have call successors, (1) [2021-12-16 00:59:50,329 INFO L276 IsEmpty]: Start isEmpty. Operand 78 states and 101 transitions. [2021-12-16 00:59:50,333 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 27 [2021-12-16 00:59:50,333 INFO L506 BasicCegarLoop]: Found error trace [2021-12-16 00:59:50,334 INFO L514 BasicCegarLoop]: trace histogram [1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2021-12-16 00:59:50,334 WARN L452 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable0 [2021-12-16 00:59:50,335 INFO L402 AbstractCegarLoop]: === Iteration 2 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2021-12-16 00:59:50,337 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2021-12-16 00:59:50,338 INFO L85 PathProgramCache]: Analyzing trace with hash -929835373, now seen corresponding path program 1 times [2021-12-16 00:59:50,338 INFO L121 FreeRefinementEngine]: Executing refinement strategy CAMEL [2021-12-16 00:59:50,338 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [1236649754] [2021-12-16 00:59:50,339 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2021-12-16 00:59:50,339 INFO L126 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2021-12-16 00:59:50,383 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 00:59:50,448 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 15 [2021-12-16 00:59:50,450 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 00:59:50,454 INFO L134 CoverageAnalysis]: Checked inductivity of 0 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2021-12-16 00:59:50,454 INFO L139 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2021-12-16 00:59:50,454 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [1236649754] [2021-12-16 00:59:50,455 INFO L160 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [1236649754] provided 1 perfect and 0 imperfect interpolant sequences [2021-12-16 00:59:50,455 INFO L186 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2021-12-16 00:59:50,455 INFO L199 FreeRefinementEngine]: Number of different interpolants: perfect sequences [3] imperfect sequences [] total 3 [2021-12-16 00:59:50,455 INFO L115 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [1774104180] [2021-12-16 00:59:50,455 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2021-12-16 00:59:50,456 INFO L546 AbstractCegarLoop]: INTERPOLANT automaton has 3 states [2021-12-16 00:59:50,456 INFO L103 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2021-12-16 00:59:50,457 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 3 interpolants. [2021-12-16 00:59:50,457 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=3, Invalid=3, Unknown=0, NotChecked=0, Total=6 [2021-12-16 00:59:50,458 INFO L87 Difference]: Start difference. First operand 78 states and 101 transitions. Second operand has 3 states, 3 states have (on average 7.333333333333333) internal successors, (22), 3 states have internal predecessors, (22), 1 states have call successors, (3), 2 states have call predecessors, (3), 1 states have return successors, (1), 1 states have call predecessors, (1), 1 states have call successors, (1) [2021-12-16 00:59:50,473 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2021-12-16 00:59:50,473 INFO L93 Difference]: Finished difference Result 122 states and 158 transitions. [2021-12-16 00:59:50,476 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 3 states. [2021-12-16 00:59:50,476 INFO L78 Accepts]: Start accepts. Automaton has has 3 states, 3 states have (on average 7.333333333333333) internal successors, (22), 3 states have internal predecessors, (22), 1 states have call successors, (3), 2 states have call predecessors, (3), 1 states have return successors, (1), 1 states have call predecessors, (1), 1 states have call successors, (1) Word has length 26 [2021-12-16 00:59:50,479 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2021-12-16 00:59:50,481 INFO L225 Difference]: With dead ends: 122 [2021-12-16 00:59:50,481 INFO L226 Difference]: Without dead ends: 69 [2021-12-16 00:59:50,487 INFO L932 BasicCegarLoop]: 0 DeclaredPredicates, 5 GetRequests, 4 SyntacticMatches, 0 SemanticMatches, 1 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 0 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=3, Invalid=3, Unknown=0, NotChecked=0, Total=6 [2021-12-16 00:59:50,488 INFO L933 BasicCegarLoop]: 88 mSDtfsCounter, 12 mSDsluCounter, 72 mSDsCounter, 0 mSdLazyCounter, 1 mSolverCounterSat, 0 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.0s Time, 0 mProtectedPredicate, 0 mProtectedAction, 15 SdHoareTripleChecker+Valid, 160 SdHoareTripleChecker+Invalid, 1 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 0 IncrementalHoareTripleChecker+Valid, 1 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.0s IncrementalHoareTripleChecker+Time [2021-12-16 00:59:50,490 INFO L934 BasicCegarLoop]: SdHoareTripleChecker [15 Valid, 160 Invalid, 1 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [0 Valid, 1 Invalid, 0 Unknown, 0 Unchecked, 0.0s Time] [2021-12-16 00:59:50,492 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 69 states. [2021-12-16 00:59:50,503 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 69 to 69. [2021-12-16 00:59:50,504 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 69 states, 53 states have (on average 1.3396226415094339) internal successors, (71), 60 states have internal predecessors, (71), 9 states have call successors, (9), 6 states have call predecessors, (9), 6 states have return successors, (9), 7 states have call predecessors, (9), 9 states have call successors, (9) [2021-12-16 00:59:50,505 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 69 states to 69 states and 89 transitions. [2021-12-16 00:59:50,505 INFO L78 Accepts]: Start accepts. Automaton has 69 states and 89 transitions. Word has length 26 [2021-12-16 00:59:50,505 INFO L84 Accepts]: Finished accepts. word is rejected. [2021-12-16 00:59:50,506 INFO L470 AbstractCegarLoop]: Abstraction has 69 states and 89 transitions. [2021-12-16 00:59:50,506 INFO L471 AbstractCegarLoop]: INTERPOLANT automaton has has 3 states, 3 states have (on average 7.333333333333333) internal successors, (22), 3 states have internal predecessors, (22), 1 states have call successors, (3), 2 states have call predecessors, (3), 1 states have return successors, (1), 1 states have call predecessors, (1), 1 states have call successors, (1) [2021-12-16 00:59:50,506 INFO L276 IsEmpty]: Start isEmpty. Operand 69 states and 89 transitions. [2021-12-16 00:59:50,507 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 31 [2021-12-16 00:59:50,507 INFO L506 BasicCegarLoop]: Found error trace [2021-12-16 00:59:50,508 INFO L514 BasicCegarLoop]: trace histogram [1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2021-12-16 00:59:50,508 WARN L452 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable1 [2021-12-16 00:59:50,508 INFO L402 AbstractCegarLoop]: === Iteration 3 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2021-12-16 00:59:50,512 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2021-12-16 00:59:50,515 INFO L85 PathProgramCache]: Analyzing trace with hash 1035191503, now seen corresponding path program 1 times [2021-12-16 00:59:50,515 INFO L121 FreeRefinementEngine]: Executing refinement strategy CAMEL [2021-12-16 00:59:50,516 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [982591153] [2021-12-16 00:59:50,516 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2021-12-16 00:59:50,516 INFO L126 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2021-12-16 00:59:50,537 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 00:59:50,620 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 19 [2021-12-16 00:59:50,622 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 00:59:50,627 INFO L134 CoverageAnalysis]: Checked inductivity of 0 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2021-12-16 00:59:50,627 INFO L139 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2021-12-16 00:59:50,627 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [982591153] [2021-12-16 00:59:50,627 INFO L160 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [982591153] provided 1 perfect and 0 imperfect interpolant sequences [2021-12-16 00:59:50,629 INFO L186 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2021-12-16 00:59:50,629 INFO L199 FreeRefinementEngine]: Number of different interpolants: perfect sequences [6] imperfect sequences [] total 6 [2021-12-16 00:59:50,629 INFO L115 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [105662486] [2021-12-16 00:59:50,629 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2021-12-16 00:59:50,630 INFO L546 AbstractCegarLoop]: INTERPOLANT automaton has 6 states [2021-12-16 00:59:50,630 INFO L103 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2021-12-16 00:59:50,631 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 6 interpolants. [2021-12-16 00:59:50,631 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=10, Invalid=20, Unknown=0, NotChecked=0, Total=30 [2021-12-16 00:59:50,631 INFO L87 Difference]: Start difference. First operand 69 states and 89 transitions. Second operand has 6 states, 6 states have (on average 4.5) internal successors, (27), 6 states have internal predecessors, (27), 2 states have call successors, (2), 2 states have call predecessors, (2), 1 states have return successors, (1), 1 states have call predecessors, (1), 1 states have call successors, (1) [2021-12-16 00:59:50,733 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2021-12-16 00:59:50,733 INFO L93 Difference]: Finished difference Result 131 states and 172 transitions. [2021-12-16 00:59:50,733 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 5 states. [2021-12-16 00:59:50,734 INFO L78 Accepts]: Start accepts. Automaton has has 6 states, 6 states have (on average 4.5) internal successors, (27), 6 states have internal predecessors, (27), 2 states have call successors, (2), 2 states have call predecessors, (2), 1 states have return successors, (1), 1 states have call predecessors, (1), 1 states have call successors, (1) Word has length 30 [2021-12-16 00:59:50,734 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2021-12-16 00:59:50,735 INFO L225 Difference]: With dead ends: 131 [2021-12-16 00:59:50,735 INFO L226 Difference]: Without dead ends: 69 [2021-12-16 00:59:50,735 INFO L932 BasicCegarLoop]: 0 DeclaredPredicates, 9 GetRequests, 3 SyntacticMatches, 0 SemanticMatches, 6 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 0 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=22, Invalid=34, Unknown=0, NotChecked=0, Total=56 [2021-12-16 00:59:50,736 INFO L933 BasicCegarLoop]: 82 mSDtfsCounter, 171 mSDsluCounter, 102 mSDsCounter, 0 mSdLazyCounter, 41 mSolverCounterSat, 27 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.0s Time, 0 mProtectedPredicate, 0 mProtectedAction, 171 SdHoareTripleChecker+Valid, 184 SdHoareTripleChecker+Invalid, 68 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 27 IncrementalHoareTripleChecker+Valid, 41 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.1s IncrementalHoareTripleChecker+Time [2021-12-16 00:59:50,737 INFO L934 BasicCegarLoop]: SdHoareTripleChecker [171 Valid, 184 Invalid, 68 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [27 Valid, 41 Invalid, 0 Unknown, 0 Unchecked, 0.1s Time] [2021-12-16 00:59:50,737 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 69 states. [2021-12-16 00:59:50,743 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 69 to 69. [2021-12-16 00:59:50,743 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 69 states, 53 states have (on average 1.320754716981132) internal successors, (70), 60 states have internal predecessors, (70), 9 states have call successors, (9), 6 states have call predecessors, (9), 6 states have return successors, (9), 7 states have call predecessors, (9), 9 states have call successors, (9) [2021-12-16 00:59:50,744 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 69 states to 69 states and 88 transitions. [2021-12-16 00:59:50,744 INFO L78 Accepts]: Start accepts. Automaton has 69 states and 88 transitions. Word has length 30 [2021-12-16 00:59:50,744 INFO L84 Accepts]: Finished accepts. word is rejected. [2021-12-16 00:59:50,744 INFO L470 AbstractCegarLoop]: Abstraction has 69 states and 88 transitions. [2021-12-16 00:59:50,745 INFO L471 AbstractCegarLoop]: INTERPOLANT automaton has has 6 states, 6 states have (on average 4.5) internal successors, (27), 6 states have internal predecessors, (27), 2 states have call successors, (2), 2 states have call predecessors, (2), 1 states have return successors, (1), 1 states have call predecessors, (1), 1 states have call successors, (1) [2021-12-16 00:59:50,745 INFO L276 IsEmpty]: Start isEmpty. Operand 69 states and 88 transitions. [2021-12-16 00:59:50,746 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 41 [2021-12-16 00:59:50,746 INFO L506 BasicCegarLoop]: Found error trace [2021-12-16 00:59:50,746 INFO L514 BasicCegarLoop]: trace histogram [1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2021-12-16 00:59:50,746 WARN L452 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable2 [2021-12-16 00:59:50,746 INFO L402 AbstractCegarLoop]: === Iteration 4 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2021-12-16 00:59:50,747 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2021-12-16 00:59:50,747 INFO L85 PathProgramCache]: Analyzing trace with hash -2104271006, now seen corresponding path program 1 times [2021-12-16 00:59:50,747 INFO L121 FreeRefinementEngine]: Executing refinement strategy CAMEL [2021-12-16 00:59:50,747 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [945078800] [2021-12-16 00:59:50,747 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2021-12-16 00:59:50,747 INFO L126 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2021-12-16 00:59:50,760 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 00:59:50,795 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 19 [2021-12-16 00:59:50,797 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 00:59:50,808 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 2 [2021-12-16 00:59:50,810 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 00:59:50,812 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 29 [2021-12-16 00:59:50,813 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 00:59:50,815 INFO L134 CoverageAnalysis]: Checked inductivity of 0 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2021-12-16 00:59:50,815 INFO L139 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2021-12-16 00:59:50,815 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [945078800] [2021-12-16 00:59:50,815 INFO L160 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [945078800] provided 1 perfect and 0 imperfect interpolant sequences [2021-12-16 00:59:50,815 INFO L186 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2021-12-16 00:59:50,815 INFO L199 FreeRefinementEngine]: Number of different interpolants: perfect sequences [5] imperfect sequences [] total 5 [2021-12-16 00:59:50,815 INFO L115 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [144868345] [2021-12-16 00:59:50,816 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2021-12-16 00:59:50,816 INFO L546 AbstractCegarLoop]: INTERPOLANT automaton has 5 states [2021-12-16 00:59:50,816 INFO L103 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2021-12-16 00:59:50,817 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 5 interpolants. [2021-12-16 00:59:50,817 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=7, Invalid=13, Unknown=0, NotChecked=0, Total=20 [2021-12-16 00:59:50,817 INFO L87 Difference]: Start difference. First operand 69 states and 88 transitions. Second operand has 5 states, 5 states have (on average 6.6) internal successors, (33), 5 states have internal predecessors, (33), 3 states have call successors, (4), 3 states have call predecessors, (4), 2 states have return successors, (3), 2 states have call predecessors, (3), 3 states have call successors, (3) [2021-12-16 00:59:50,946 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2021-12-16 00:59:50,946 INFO L93 Difference]: Finished difference Result 208 states and 266 transitions. [2021-12-16 00:59:50,946 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 7 states. [2021-12-16 00:59:50,946 INFO L78 Accepts]: Start accepts. Automaton has has 5 states, 5 states have (on average 6.6) internal successors, (33), 5 states have internal predecessors, (33), 3 states have call successors, (4), 3 states have call predecessors, (4), 2 states have return successors, (3), 2 states have call predecessors, (3), 3 states have call successors, (3) Word has length 40 [2021-12-16 00:59:50,947 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2021-12-16 00:59:50,948 INFO L225 Difference]: With dead ends: 208 [2021-12-16 00:59:50,948 INFO L226 Difference]: Without dead ends: 146 [2021-12-16 00:59:50,949 INFO L932 BasicCegarLoop]: 0 DeclaredPredicates, 15 GetRequests, 8 SyntacticMatches, 1 SemanticMatches, 6 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 3 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=19, Invalid=37, Unknown=0, NotChecked=0, Total=56 [2021-12-16 00:59:50,949 INFO L933 BasicCegarLoop]: 132 mSDtfsCounter, 167 mSDsluCounter, 173 mSDsCounter, 0 mSdLazyCounter, 95 mSolverCounterSat, 45 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.1s Time, 0 mProtectedPredicate, 0 mProtectedAction, 169 SdHoareTripleChecker+Valid, 305 SdHoareTripleChecker+Invalid, 140 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 45 IncrementalHoareTripleChecker+Valid, 95 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.1s IncrementalHoareTripleChecker+Time [2021-12-16 00:59:50,950 INFO L934 BasicCegarLoop]: SdHoareTripleChecker [169 Valid, 305 Invalid, 140 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [45 Valid, 95 Invalid, 0 Unknown, 0 Unchecked, 0.1s Time] [2021-12-16 00:59:50,950 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 146 states. [2021-12-16 00:59:50,962 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 146 to 140. [2021-12-16 00:59:50,963 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 140 states, 108 states have (on average 1.2777777777777777) internal successors, (138), 115 states have internal predecessors, (138), 15 states have call successors, (15), 13 states have call predecessors, (15), 16 states have return successors, (20), 16 states have call predecessors, (20), 15 states have call successors, (20) [2021-12-16 00:59:50,963 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 140 states to 140 states and 173 transitions. [2021-12-16 00:59:50,964 INFO L78 Accepts]: Start accepts. Automaton has 140 states and 173 transitions. Word has length 40 [2021-12-16 00:59:50,964 INFO L84 Accepts]: Finished accepts. word is rejected. [2021-12-16 00:59:50,964 INFO L470 AbstractCegarLoop]: Abstraction has 140 states and 173 transitions. [2021-12-16 00:59:50,964 INFO L471 AbstractCegarLoop]: INTERPOLANT automaton has has 5 states, 5 states have (on average 6.6) internal successors, (33), 5 states have internal predecessors, (33), 3 states have call successors, (4), 3 states have call predecessors, (4), 2 states have return successors, (3), 2 states have call predecessors, (3), 3 states have call successors, (3) [2021-12-16 00:59:50,964 INFO L276 IsEmpty]: Start isEmpty. Operand 140 states and 173 transitions. [2021-12-16 00:59:50,965 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 45 [2021-12-16 00:59:50,966 INFO L506 BasicCegarLoop]: Found error trace [2021-12-16 00:59:50,966 INFO L514 BasicCegarLoop]: trace histogram [1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2021-12-16 00:59:50,966 WARN L452 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable3 [2021-12-16 00:59:50,966 INFO L402 AbstractCegarLoop]: === Iteration 5 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2021-12-16 00:59:50,966 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2021-12-16 00:59:50,967 INFO L85 PathProgramCache]: Analyzing trace with hash 1015544271, now seen corresponding path program 1 times [2021-12-16 00:59:50,967 INFO L121 FreeRefinementEngine]: Executing refinement strategy CAMEL [2021-12-16 00:59:50,967 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [621965063] [2021-12-16 00:59:50,967 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2021-12-16 00:59:50,967 INFO L126 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2021-12-16 00:59:50,977 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 00:59:51,007 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 19 [2021-12-16 00:59:51,010 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 00:59:51,029 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 33 [2021-12-16 00:59:51,031 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 00:59:51,035 INFO L134 CoverageAnalysis]: Checked inductivity of 0 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2021-12-16 00:59:51,036 INFO L139 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2021-12-16 00:59:51,036 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [621965063] [2021-12-16 00:59:51,036 INFO L160 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [621965063] provided 1 perfect and 0 imperfect interpolant sequences [2021-12-16 00:59:51,036 INFO L186 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2021-12-16 00:59:51,037 INFO L199 FreeRefinementEngine]: Number of different interpolants: perfect sequences [6] imperfect sequences [] total 6 [2021-12-16 00:59:51,037 INFO L115 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [1096629628] [2021-12-16 00:59:51,038 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2021-12-16 00:59:51,039 INFO L546 AbstractCegarLoop]: INTERPOLANT automaton has 6 states [2021-12-16 00:59:51,039 INFO L103 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2021-12-16 00:59:51,043 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 6 interpolants. [2021-12-16 00:59:51,043 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=9, Invalid=21, Unknown=0, NotChecked=0, Total=30 [2021-12-16 00:59:51,043 INFO L87 Difference]: Start difference. First operand 140 states and 173 transitions. Second operand has 6 states, 6 states have (on average 6.5) internal successors, (39), 5 states have internal predecessors, (39), 2 states have call successors, (3), 3 states have call predecessors, (3), 2 states have return successors, (2), 1 states have call predecessors, (2), 2 states have call successors, (2) [2021-12-16 00:59:51,258 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2021-12-16 00:59:51,258 INFO L93 Difference]: Finished difference Result 392 states and 507 transitions. [2021-12-16 00:59:51,258 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 12 states. [2021-12-16 00:59:51,259 INFO L78 Accepts]: Start accepts. Automaton has has 6 states, 6 states have (on average 6.5) internal successors, (39), 5 states have internal predecessors, (39), 2 states have call successors, (3), 3 states have call predecessors, (3), 2 states have return successors, (2), 1 states have call predecessors, (2), 2 states have call successors, (2) Word has length 44 [2021-12-16 00:59:51,259 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2021-12-16 00:59:51,261 INFO L225 Difference]: With dead ends: 392 [2021-12-16 00:59:51,261 INFO L226 Difference]: Without dead ends: 259 [2021-12-16 00:59:51,261 INFO L932 BasicCegarLoop]: 0 DeclaredPredicates, 19 GetRequests, 8 SyntacticMatches, 0 SemanticMatches, 11 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 19 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=45, Invalid=111, Unknown=0, NotChecked=0, Total=156 [2021-12-16 00:59:51,262 INFO L933 BasicCegarLoop]: 109 mSDtfsCounter, 157 mSDsluCounter, 291 mSDsCounter, 0 mSdLazyCounter, 149 mSolverCounterSat, 41 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.1s Time, 0 mProtectedPredicate, 0 mProtectedAction, 163 SdHoareTripleChecker+Valid, 400 SdHoareTripleChecker+Invalid, 190 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 41 IncrementalHoareTripleChecker+Valid, 149 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.1s IncrementalHoareTripleChecker+Time [2021-12-16 00:59:51,263 INFO L934 BasicCegarLoop]: SdHoareTripleChecker [163 Valid, 400 Invalid, 190 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [41 Valid, 149 Invalid, 0 Unknown, 0 Unchecked, 0.1s Time] [2021-12-16 00:59:51,263 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 259 states. [2021-12-16 00:59:51,282 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 259 to 226. [2021-12-16 00:59:51,283 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 226 states, 175 states have (on average 1.28) internal successors, (224), 184 states have internal predecessors, (224), 25 states have call successors, (25), 23 states have call predecessors, (25), 25 states have return successors, (35), 25 states have call predecessors, (35), 25 states have call successors, (35) [2021-12-16 00:59:51,284 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 226 states to 226 states and 284 transitions. [2021-12-16 00:59:51,285 INFO L78 Accepts]: Start accepts. Automaton has 226 states and 284 transitions. Word has length 44 [2021-12-16 00:59:51,285 INFO L84 Accepts]: Finished accepts. word is rejected. [2021-12-16 00:59:51,285 INFO L470 AbstractCegarLoop]: Abstraction has 226 states and 284 transitions. [2021-12-16 00:59:51,285 INFO L471 AbstractCegarLoop]: INTERPOLANT automaton has has 6 states, 6 states have (on average 6.5) internal successors, (39), 5 states have internal predecessors, (39), 2 states have call successors, (3), 3 states have call predecessors, (3), 2 states have return successors, (2), 1 states have call predecessors, (2), 2 states have call successors, (2) [2021-12-16 00:59:51,285 INFO L276 IsEmpty]: Start isEmpty. Operand 226 states and 284 transitions. [2021-12-16 00:59:51,287 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 45 [2021-12-16 00:59:51,287 INFO L506 BasicCegarLoop]: Found error trace [2021-12-16 00:59:51,287 INFO L514 BasicCegarLoop]: trace histogram [1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2021-12-16 00:59:51,287 WARN L452 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable4 [2021-12-16 00:59:51,287 INFO L402 AbstractCegarLoop]: === Iteration 6 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2021-12-16 00:59:51,288 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2021-12-16 00:59:51,288 INFO L85 PathProgramCache]: Analyzing trace with hash 796689553, now seen corresponding path program 1 times [2021-12-16 00:59:51,288 INFO L121 FreeRefinementEngine]: Executing refinement strategy CAMEL [2021-12-16 00:59:51,288 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [2071918194] [2021-12-16 00:59:51,288 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2021-12-16 00:59:51,288 INFO L126 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2021-12-16 00:59:51,301 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 00:59:51,315 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 19 [2021-12-16 00:59:51,318 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 00:59:51,339 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 33 [2021-12-16 00:59:51,340 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 00:59:51,342 INFO L134 CoverageAnalysis]: Checked inductivity of 0 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2021-12-16 00:59:51,342 INFO L139 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2021-12-16 00:59:51,342 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [2071918194] [2021-12-16 00:59:51,342 INFO L160 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [2071918194] provided 1 perfect and 0 imperfect interpolant sequences [2021-12-16 00:59:51,343 INFO L186 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2021-12-16 00:59:51,343 INFO L199 FreeRefinementEngine]: Number of different interpolants: perfect sequences [6] imperfect sequences [] total 6 [2021-12-16 00:59:51,343 INFO L115 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [1706883893] [2021-12-16 00:59:51,343 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2021-12-16 00:59:51,343 INFO L546 AbstractCegarLoop]: INTERPOLANT automaton has 6 states [2021-12-16 00:59:51,343 INFO L103 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2021-12-16 00:59:51,344 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 6 interpolants. [2021-12-16 00:59:51,344 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=9, Invalid=21, Unknown=0, NotChecked=0, Total=30 [2021-12-16 00:59:51,344 INFO L87 Difference]: Start difference. First operand 226 states and 284 transitions. Second operand has 6 states, 6 states have (on average 6.5) internal successors, (39), 5 states have internal predecessors, (39), 2 states have call successors, (3), 2 states have call predecessors, (3), 2 states have return successors, (2), 1 states have call predecessors, (2), 2 states have call successors, (2) [2021-12-16 00:59:51,484 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2021-12-16 00:59:51,485 INFO L93 Difference]: Finished difference Result 459 states and 584 transitions. [2021-12-16 00:59:51,485 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 7 states. [2021-12-16 00:59:51,485 INFO L78 Accepts]: Start accepts. Automaton has has 6 states, 6 states have (on average 6.5) internal successors, (39), 5 states have internal predecessors, (39), 2 states have call successors, (3), 2 states have call predecessors, (3), 2 states have return successors, (2), 1 states have call predecessors, (2), 2 states have call successors, (2) Word has length 44 [2021-12-16 00:59:51,486 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2021-12-16 00:59:51,487 INFO L225 Difference]: With dead ends: 459 [2021-12-16 00:59:51,487 INFO L226 Difference]: Without dead ends: 240 [2021-12-16 00:59:51,488 INFO L932 BasicCegarLoop]: 0 DeclaredPredicates, 14 GetRequests, 6 SyntacticMatches, 0 SemanticMatches, 8 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 3 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=32, Invalid=58, Unknown=0, NotChecked=0, Total=90 [2021-12-16 00:59:51,489 INFO L933 BasicCegarLoop]: 92 mSDtfsCounter, 59 mSDsluCounter, 281 mSDsCounter, 0 mSdLazyCounter, 103 mSolverCounterSat, 18 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.1s Time, 0 mProtectedPredicate, 0 mProtectedAction, 62 SdHoareTripleChecker+Valid, 373 SdHoareTripleChecker+Invalid, 121 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 18 IncrementalHoareTripleChecker+Valid, 103 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.1s IncrementalHoareTripleChecker+Time [2021-12-16 00:59:51,489 INFO L934 BasicCegarLoop]: SdHoareTripleChecker [62 Valid, 373 Invalid, 121 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [18 Valid, 103 Invalid, 0 Unknown, 0 Unchecked, 0.1s Time] [2021-12-16 00:59:51,490 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 240 states. [2021-12-16 00:59:51,502 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 240 to 232. [2021-12-16 00:59:51,503 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 232 states, 181 states have (on average 1.270718232044199) internal successors, (230), 190 states have internal predecessors, (230), 25 states have call successors, (25), 23 states have call predecessors, (25), 25 states have return successors, (35), 25 states have call predecessors, (35), 25 states have call successors, (35) [2021-12-16 00:59:51,504 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 232 states to 232 states and 290 transitions. [2021-12-16 00:59:51,504 INFO L78 Accepts]: Start accepts. Automaton has 232 states and 290 transitions. Word has length 44 [2021-12-16 00:59:51,504 INFO L84 Accepts]: Finished accepts. word is rejected. [2021-12-16 00:59:51,505 INFO L470 AbstractCegarLoop]: Abstraction has 232 states and 290 transitions. [2021-12-16 00:59:51,505 INFO L471 AbstractCegarLoop]: INTERPOLANT automaton has has 6 states, 6 states have (on average 6.5) internal successors, (39), 5 states have internal predecessors, (39), 2 states have call successors, (3), 2 states have call predecessors, (3), 2 states have return successors, (2), 1 states have call predecessors, (2), 2 states have call successors, (2) [2021-12-16 00:59:51,505 INFO L276 IsEmpty]: Start isEmpty. Operand 232 states and 290 transitions. [2021-12-16 00:59:51,506 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 45 [2021-12-16 00:59:51,506 INFO L506 BasicCegarLoop]: Found error trace [2021-12-16 00:59:51,506 INFO L514 BasicCegarLoop]: trace histogram [1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2021-12-16 00:59:51,506 WARN L452 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable5 [2021-12-16 00:59:51,506 INFO L402 AbstractCegarLoop]: === Iteration 7 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2021-12-16 00:59:51,507 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2021-12-16 00:59:51,509 INFO L85 PathProgramCache]: Analyzing trace with hash -20958897, now seen corresponding path program 1 times [2021-12-16 00:59:51,510 INFO L121 FreeRefinementEngine]: Executing refinement strategy CAMEL [2021-12-16 00:59:51,510 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [121555382] [2021-12-16 00:59:51,510 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2021-12-16 00:59:51,510 INFO L126 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2021-12-16 00:59:51,519 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 00:59:51,542 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 19 [2021-12-16 00:59:51,545 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 00:59:51,564 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 33 [2021-12-16 00:59:51,565 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 00:59:51,567 INFO L134 CoverageAnalysis]: Checked inductivity of 0 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2021-12-16 00:59:51,567 INFO L139 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2021-12-16 00:59:51,567 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [121555382] [2021-12-16 00:59:51,567 INFO L160 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [121555382] provided 1 perfect and 0 imperfect interpolant sequences [2021-12-16 00:59:51,567 INFO L186 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2021-12-16 00:59:51,567 INFO L199 FreeRefinementEngine]: Number of different interpolants: perfect sequences [7] imperfect sequences [] total 7 [2021-12-16 00:59:51,568 INFO L115 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [1382995071] [2021-12-16 00:59:51,568 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2021-12-16 00:59:51,568 INFO L546 AbstractCegarLoop]: INTERPOLANT automaton has 7 states [2021-12-16 00:59:51,568 INFO L103 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2021-12-16 00:59:51,568 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 7 interpolants. [2021-12-16 00:59:51,569 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=11, Invalid=31, Unknown=0, NotChecked=0, Total=42 [2021-12-16 00:59:51,569 INFO L87 Difference]: Start difference. First operand 232 states and 290 transitions. Second operand has 7 states, 7 states have (on average 5.571428571428571) internal successors, (39), 6 states have internal predecessors, (39), 2 states have call successors, (3), 2 states have call predecessors, (3), 2 states have return successors, (2), 1 states have call predecessors, (2), 2 states have call successors, (2) [2021-12-16 00:59:51,707 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2021-12-16 00:59:51,707 INFO L93 Difference]: Finished difference Result 423 states and 534 transitions. [2021-12-16 00:59:51,707 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 7 states. [2021-12-16 00:59:51,707 INFO L78 Accepts]: Start accepts. Automaton has has 7 states, 7 states have (on average 5.571428571428571) internal successors, (39), 6 states have internal predecessors, (39), 2 states have call successors, (3), 2 states have call predecessors, (3), 2 states have return successors, (2), 1 states have call predecessors, (2), 2 states have call successors, (2) Word has length 44 [2021-12-16 00:59:51,708 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2021-12-16 00:59:51,712 INFO L225 Difference]: With dead ends: 423 [2021-12-16 00:59:51,712 INFO L226 Difference]: Without dead ends: 198 [2021-12-16 00:59:51,713 INFO L932 BasicCegarLoop]: 0 DeclaredPredicates, 16 GetRequests, 8 SyntacticMatches, 0 SemanticMatches, 8 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 2 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=25, Invalid=65, Unknown=0, NotChecked=0, Total=90 [2021-12-16 00:59:51,715 INFO L933 BasicCegarLoop]: 72 mSDtfsCounter, 93 mSDsluCounter, 248 mSDsCounter, 0 mSdLazyCounter, 132 mSolverCounterSat, 24 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.1s Time, 0 mProtectedPredicate, 0 mProtectedAction, 97 SdHoareTripleChecker+Valid, 320 SdHoareTripleChecker+Invalid, 156 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 24 IncrementalHoareTripleChecker+Valid, 132 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.1s IncrementalHoareTripleChecker+Time [2021-12-16 00:59:51,716 INFO L934 BasicCegarLoop]: SdHoareTripleChecker [97 Valid, 320 Invalid, 156 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [24 Valid, 132 Invalid, 0 Unknown, 0 Unchecked, 0.1s Time] [2021-12-16 00:59:51,717 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 198 states. [2021-12-16 00:59:51,732 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 198 to 193. [2021-12-16 00:59:51,732 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 193 states, 150 states have (on average 1.2466666666666666) internal successors, (187), 158 states have internal predecessors, (187), 21 states have call successors, (21), 19 states have call predecessors, (21), 21 states have return successors, (26), 21 states have call predecessors, (26), 21 states have call successors, (26) [2021-12-16 00:59:51,733 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 193 states to 193 states and 234 transitions. [2021-12-16 00:59:51,733 INFO L78 Accepts]: Start accepts. Automaton has 193 states and 234 transitions. Word has length 44 [2021-12-16 00:59:51,734 INFO L84 Accepts]: Finished accepts. word is rejected. [2021-12-16 00:59:51,734 INFO L470 AbstractCegarLoop]: Abstraction has 193 states and 234 transitions. [2021-12-16 00:59:51,734 INFO L471 AbstractCegarLoop]: INTERPOLANT automaton has has 7 states, 7 states have (on average 5.571428571428571) internal successors, (39), 6 states have internal predecessors, (39), 2 states have call successors, (3), 2 states have call predecessors, (3), 2 states have return successors, (2), 1 states have call predecessors, (2), 2 states have call successors, (2) [2021-12-16 00:59:51,734 INFO L276 IsEmpty]: Start isEmpty. Operand 193 states and 234 transitions. [2021-12-16 00:59:51,735 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 47 [2021-12-16 00:59:51,735 INFO L506 BasicCegarLoop]: Found error trace [2021-12-16 00:59:51,735 INFO L514 BasicCegarLoop]: trace histogram [1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2021-12-16 00:59:51,736 WARN L452 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable6 [2021-12-16 00:59:51,736 INFO L402 AbstractCegarLoop]: === Iteration 8 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2021-12-16 00:59:51,736 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2021-12-16 00:59:51,736 INFO L85 PathProgramCache]: Analyzing trace with hash -766382886, now seen corresponding path program 1 times [2021-12-16 00:59:51,737 INFO L121 FreeRefinementEngine]: Executing refinement strategy CAMEL [2021-12-16 00:59:51,737 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [2063725347] [2021-12-16 00:59:51,737 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2021-12-16 00:59:51,737 INFO L126 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2021-12-16 00:59:51,747 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 00:59:51,776 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 19 [2021-12-16 00:59:51,778 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 00:59:51,782 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 8 [2021-12-16 00:59:51,783 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 00:59:51,784 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 35 [2021-12-16 00:59:51,785 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 00:59:51,787 INFO L134 CoverageAnalysis]: Checked inductivity of 0 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2021-12-16 00:59:51,787 INFO L139 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2021-12-16 00:59:51,788 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [2063725347] [2021-12-16 00:59:51,788 INFO L160 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [2063725347] provided 1 perfect and 0 imperfect interpolant sequences [2021-12-16 00:59:51,788 INFO L186 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2021-12-16 00:59:51,788 INFO L199 FreeRefinementEngine]: Number of different interpolants: perfect sequences [6] imperfect sequences [] total 6 [2021-12-16 00:59:51,788 INFO L115 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [825365900] [2021-12-16 00:59:51,788 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2021-12-16 00:59:51,789 INFO L546 AbstractCegarLoop]: INTERPOLANT automaton has 6 states [2021-12-16 00:59:51,789 INFO L103 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2021-12-16 00:59:51,789 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 6 interpolants. [2021-12-16 00:59:51,790 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=9, Invalid=21, Unknown=0, NotChecked=0, Total=30 [2021-12-16 00:59:51,790 INFO L87 Difference]: Start difference. First operand 193 states and 234 transitions. Second operand has 6 states, 6 states have (on average 6.5) internal successors, (39), 5 states have internal predecessors, (39), 2 states have call successors, (4), 3 states have call predecessors, (4), 1 states have return successors, (3), 2 states have call predecessors, (3), 2 states have call successors, (3) [2021-12-16 00:59:51,914 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2021-12-16 00:59:51,915 INFO L93 Difference]: Finished difference Result 382 states and 463 transitions. [2021-12-16 00:59:51,915 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 7 states. [2021-12-16 00:59:51,915 INFO L78 Accepts]: Start accepts. Automaton has has 6 states, 6 states have (on average 6.5) internal successors, (39), 5 states have internal predecessors, (39), 2 states have call successors, (4), 3 states have call predecessors, (4), 1 states have return successors, (3), 2 states have call predecessors, (3), 2 states have call successors, (3) Word has length 46 [2021-12-16 00:59:51,916 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2021-12-16 00:59:51,917 INFO L225 Difference]: With dead ends: 382 [2021-12-16 00:59:51,917 INFO L226 Difference]: Without dead ends: 196 [2021-12-16 00:59:51,918 INFO L932 BasicCegarLoop]: 0 DeclaredPredicates, 15 GetRequests, 8 SyntacticMatches, 0 SemanticMatches, 7 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 0 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=27, Invalid=45, Unknown=0, NotChecked=0, Total=72 [2021-12-16 00:59:51,918 INFO L933 BasicCegarLoop]: 84 mSDtfsCounter, 108 mSDsluCounter, 257 mSDsCounter, 0 mSdLazyCounter, 125 mSolverCounterSat, 25 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.1s Time, 0 mProtectedPredicate, 0 mProtectedAction, 113 SdHoareTripleChecker+Valid, 341 SdHoareTripleChecker+Invalid, 150 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 25 IncrementalHoareTripleChecker+Valid, 125 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.1s IncrementalHoareTripleChecker+Time [2021-12-16 00:59:51,919 INFO L934 BasicCegarLoop]: SdHoareTripleChecker [113 Valid, 341 Invalid, 150 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [25 Valid, 125 Invalid, 0 Unknown, 0 Unchecked, 0.1s Time] [2021-12-16 00:59:51,919 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 196 states. [2021-12-16 00:59:51,926 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 196 to 191. [2021-12-16 00:59:51,927 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 191 states, 148 states have (on average 1.2364864864864864) internal successors, (183), 156 states have internal predecessors, (183), 21 states have call successors, (21), 19 states have call predecessors, (21), 21 states have return successors, (26), 21 states have call predecessors, (26), 21 states have call successors, (26) [2021-12-16 00:59:51,928 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 191 states to 191 states and 230 transitions. [2021-12-16 00:59:51,928 INFO L78 Accepts]: Start accepts. Automaton has 191 states and 230 transitions. Word has length 46 [2021-12-16 00:59:51,929 INFO L84 Accepts]: Finished accepts. word is rejected. [2021-12-16 00:59:51,929 INFO L470 AbstractCegarLoop]: Abstraction has 191 states and 230 transitions. [2021-12-16 00:59:51,929 INFO L471 AbstractCegarLoop]: INTERPOLANT automaton has has 6 states, 6 states have (on average 6.5) internal successors, (39), 5 states have internal predecessors, (39), 2 states have call successors, (4), 3 states have call predecessors, (4), 1 states have return successors, (3), 2 states have call predecessors, (3), 2 states have call successors, (3) [2021-12-16 00:59:51,929 INFO L276 IsEmpty]: Start isEmpty. Operand 191 states and 230 transitions. [2021-12-16 00:59:51,930 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 49 [2021-12-16 00:59:51,930 INFO L506 BasicCegarLoop]: Found error trace [2021-12-16 00:59:51,930 INFO L514 BasicCegarLoop]: trace histogram [1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2021-12-16 00:59:51,930 WARN L452 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable7 [2021-12-16 00:59:51,930 INFO L402 AbstractCegarLoop]: === Iteration 9 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2021-12-16 00:59:51,931 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2021-12-16 00:59:51,931 INFO L85 PathProgramCache]: Analyzing trace with hash 390915315, now seen corresponding path program 1 times [2021-12-16 00:59:51,931 INFO L121 FreeRefinementEngine]: Executing refinement strategy CAMEL [2021-12-16 00:59:51,931 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [1375928110] [2021-12-16 00:59:51,931 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2021-12-16 00:59:51,932 INFO L126 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2021-12-16 00:59:51,941 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 00:59:52,001 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 11 [2021-12-16 00:59:52,002 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 00:59:52,015 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 23 [2021-12-16 00:59:52,018 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 00:59:52,030 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 37 [2021-12-16 00:59:52,032 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 00:59:52,035 INFO L134 CoverageAnalysis]: Checked inductivity of 0 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2021-12-16 00:59:52,035 INFO L139 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2021-12-16 00:59:52,035 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [1375928110] [2021-12-16 00:59:52,036 INFO L160 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [1375928110] provided 1 perfect and 0 imperfect interpolant sequences [2021-12-16 00:59:52,036 INFO L186 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2021-12-16 00:59:52,036 INFO L199 FreeRefinementEngine]: Number of different interpolants: perfect sequences [10] imperfect sequences [] total 10 [2021-12-16 00:59:52,037 INFO L115 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [1449820373] [2021-12-16 00:59:52,037 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2021-12-16 00:59:52,038 INFO L546 AbstractCegarLoop]: INTERPOLANT automaton has 10 states [2021-12-16 00:59:52,038 INFO L103 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2021-12-16 00:59:52,038 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 10 interpolants. [2021-12-16 00:59:52,038 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=18, Invalid=72, Unknown=0, NotChecked=0, Total=90 [2021-12-16 00:59:52,039 INFO L87 Difference]: Start difference. First operand 191 states and 230 transitions. Second operand has 10 states, 10 states have (on average 4.1) internal successors, (41), 8 states have internal predecessors, (41), 2 states have call successors, (4), 3 states have call predecessors, (4), 2 states have return successors, (3), 2 states have call predecessors, (3), 2 states have call successors, (3) [2021-12-16 00:59:52,490 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2021-12-16 00:59:52,490 INFO L93 Difference]: Finished difference Result 388 states and 468 transitions. [2021-12-16 00:59:52,490 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 20 states. [2021-12-16 00:59:52,491 INFO L78 Accepts]: Start accepts. Automaton has has 10 states, 10 states have (on average 4.1) internal successors, (41), 8 states have internal predecessors, (41), 2 states have call successors, (4), 3 states have call predecessors, (4), 2 states have return successors, (3), 2 states have call predecessors, (3), 2 states have call successors, (3) Word has length 48 [2021-12-16 00:59:52,491 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2021-12-16 00:59:52,492 INFO L225 Difference]: With dead ends: 388 [2021-12-16 00:59:52,492 INFO L226 Difference]: Without dead ends: 250 [2021-12-16 00:59:52,493 INFO L932 BasicCegarLoop]: 0 DeclaredPredicates, 34 GetRequests, 12 SyntacticMatches, 0 SemanticMatches, 22 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 75 ImplicationChecksByTransitivity, 0.1s TimeCoverageRelationStatistics Valid=128, Invalid=424, Unknown=0, NotChecked=0, Total=552 [2021-12-16 00:59:52,494 INFO L933 BasicCegarLoop]: 129 mSDtfsCounter, 296 mSDsluCounter, 452 mSDsCounter, 0 mSdLazyCounter, 409 mSolverCounterSat, 114 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.2s Time, 0 mProtectedPredicate, 0 mProtectedAction, 297 SdHoareTripleChecker+Valid, 581 SdHoareTripleChecker+Invalid, 523 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 114 IncrementalHoareTripleChecker+Valid, 409 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.3s IncrementalHoareTripleChecker+Time [2021-12-16 00:59:52,494 INFO L934 BasicCegarLoop]: SdHoareTripleChecker [297 Valid, 581 Invalid, 523 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [114 Valid, 409 Invalid, 0 Unknown, 0 Unchecked, 0.3s Time] [2021-12-16 00:59:52,495 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 250 states. [2021-12-16 00:59:52,505 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 250 to 193. [2021-12-16 00:59:52,506 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 193 states, 149 states have (on average 1.2147651006711409) internal successors, (181), 158 states have internal predecessors, (181), 21 states have call successors, (21), 19 states have call predecessors, (21), 22 states have return successors, (25), 21 states have call predecessors, (25), 21 states have call successors, (25) [2021-12-16 00:59:52,508 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 193 states to 193 states and 227 transitions. [2021-12-16 00:59:52,508 INFO L78 Accepts]: Start accepts. Automaton has 193 states and 227 transitions. Word has length 48 [2021-12-16 00:59:52,508 INFO L84 Accepts]: Finished accepts. word is rejected. [2021-12-16 00:59:52,508 INFO L470 AbstractCegarLoop]: Abstraction has 193 states and 227 transitions. [2021-12-16 00:59:52,509 INFO L471 AbstractCegarLoop]: INTERPOLANT automaton has has 10 states, 10 states have (on average 4.1) internal successors, (41), 8 states have internal predecessors, (41), 2 states have call successors, (4), 3 states have call predecessors, (4), 2 states have return successors, (3), 2 states have call predecessors, (3), 2 states have call successors, (3) [2021-12-16 00:59:52,509 INFO L276 IsEmpty]: Start isEmpty. Operand 193 states and 227 transitions. [2021-12-16 00:59:52,510 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 51 [2021-12-16 00:59:52,510 INFO L506 BasicCegarLoop]: Found error trace [2021-12-16 00:59:52,510 INFO L514 BasicCegarLoop]: trace histogram [1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2021-12-16 00:59:52,511 WARN L452 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable8 [2021-12-16 00:59:52,511 INFO L402 AbstractCegarLoop]: === Iteration 10 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2021-12-16 00:59:52,511 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2021-12-16 00:59:52,511 INFO L85 PathProgramCache]: Analyzing trace with hash 126598332, now seen corresponding path program 1 times [2021-12-16 00:59:52,511 INFO L121 FreeRefinementEngine]: Executing refinement strategy CAMEL [2021-12-16 00:59:52,511 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [2032095114] [2021-12-16 00:59:52,512 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2021-12-16 00:59:52,512 INFO L126 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2021-12-16 00:59:52,522 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 00:59:52,544 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 11 [2021-12-16 00:59:52,545 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 00:59:52,550 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 23 [2021-12-16 00:59:52,552 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 00:59:52,577 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 8 [2021-12-16 00:59:52,577 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 00:59:52,581 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 39 [2021-12-16 00:59:52,581 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 00:59:52,583 INFO L134 CoverageAnalysis]: Checked inductivity of 0 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2021-12-16 00:59:52,583 INFO L139 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2021-12-16 00:59:52,583 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [2032095114] [2021-12-16 00:59:52,583 INFO L160 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [2032095114] provided 1 perfect and 0 imperfect interpolant sequences [2021-12-16 00:59:52,583 INFO L186 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2021-12-16 00:59:52,583 INFO L199 FreeRefinementEngine]: Number of different interpolants: perfect sequences [9] imperfect sequences [] total 9 [2021-12-16 00:59:52,583 INFO L115 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [1541267301] [2021-12-16 00:59:52,583 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2021-12-16 00:59:52,584 INFO L546 AbstractCegarLoop]: INTERPOLANT automaton has 9 states [2021-12-16 00:59:52,584 INFO L103 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2021-12-16 00:59:52,584 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 9 interpolants. [2021-12-16 00:59:52,584 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=15, Invalid=57, Unknown=0, NotChecked=0, Total=72 [2021-12-16 00:59:52,585 INFO L87 Difference]: Start difference. First operand 193 states and 227 transitions. Second operand has 9 states, 9 states have (on average 4.555555555555555) internal successors, (41), 7 states have internal predecessors, (41), 2 states have call successors, (5), 3 states have call predecessors, (5), 2 states have return successors, (4), 2 states have call predecessors, (4), 2 states have call successors, (4) [2021-12-16 00:59:52,800 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2021-12-16 00:59:52,800 INFO L93 Difference]: Finished difference Result 372 states and 443 transitions. [2021-12-16 00:59:52,801 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 11 states. [2021-12-16 00:59:52,801 INFO L78 Accepts]: Start accepts. Automaton has has 9 states, 9 states have (on average 4.555555555555555) internal successors, (41), 7 states have internal predecessors, (41), 2 states have call successors, (5), 3 states have call predecessors, (5), 2 states have return successors, (4), 2 states have call predecessors, (4), 2 states have call successors, (4) Word has length 50 [2021-12-16 00:59:52,802 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2021-12-16 00:59:52,803 INFO L225 Difference]: With dead ends: 372 [2021-12-16 00:59:52,803 INFO L226 Difference]: Without dead ends: 232 [2021-12-16 00:59:52,804 INFO L932 BasicCegarLoop]: 0 DeclaredPredicates, 25 GetRequests, 12 SyntacticMatches, 0 SemanticMatches, 13 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 9 ImplicationChecksByTransitivity, 0.1s TimeCoverageRelationStatistics Valid=54, Invalid=156, Unknown=0, NotChecked=0, Total=210 [2021-12-16 00:59:52,804 INFO L933 BasicCegarLoop]: 72 mSDtfsCounter, 161 mSDsluCounter, 303 mSDsCounter, 0 mSdLazyCounter, 284 mSolverCounterSat, 56 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.1s Time, 0 mProtectedPredicate, 0 mProtectedAction, 164 SdHoareTripleChecker+Valid, 375 SdHoareTripleChecker+Invalid, 340 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 56 IncrementalHoareTripleChecker+Valid, 284 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.2s IncrementalHoareTripleChecker+Time [2021-12-16 00:59:52,804 INFO L934 BasicCegarLoop]: SdHoareTripleChecker [164 Valid, 375 Invalid, 340 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [56 Valid, 284 Invalid, 0 Unknown, 0 Unchecked, 0.2s Time] [2021-12-16 00:59:52,805 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 232 states. [2021-12-16 00:59:52,814 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 232 to 193. [2021-12-16 00:59:52,814 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 193 states, 149 states have (on average 1.2080536912751678) internal successors, (180), 158 states have internal predecessors, (180), 21 states have call successors, (21), 19 states have call predecessors, (21), 22 states have return successors, (25), 21 states have call predecessors, (25), 21 states have call successors, (25) [2021-12-16 00:59:52,815 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 193 states to 193 states and 226 transitions. [2021-12-16 00:59:52,815 INFO L78 Accepts]: Start accepts. Automaton has 193 states and 226 transitions. Word has length 50 [2021-12-16 00:59:52,815 INFO L84 Accepts]: Finished accepts. word is rejected. [2021-12-16 00:59:52,816 INFO L470 AbstractCegarLoop]: Abstraction has 193 states and 226 transitions. [2021-12-16 00:59:52,816 INFO L471 AbstractCegarLoop]: INTERPOLANT automaton has has 9 states, 9 states have (on average 4.555555555555555) internal successors, (41), 7 states have internal predecessors, (41), 2 states have call successors, (5), 3 states have call predecessors, (5), 2 states have return successors, (4), 2 states have call predecessors, (4), 2 states have call successors, (4) [2021-12-16 00:59:52,816 INFO L276 IsEmpty]: Start isEmpty. Operand 193 states and 226 transitions. [2021-12-16 00:59:52,816 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 51 [2021-12-16 00:59:52,817 INFO L506 BasicCegarLoop]: Found error trace [2021-12-16 00:59:52,817 INFO L514 BasicCegarLoop]: trace histogram [1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2021-12-16 00:59:52,817 WARN L452 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable9 [2021-12-16 00:59:52,817 INFO L402 AbstractCegarLoop]: === Iteration 11 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2021-12-16 00:59:52,817 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2021-12-16 00:59:52,818 INFO L85 PathProgramCache]: Analyzing trace with hash 41757120, now seen corresponding path program 1 times [2021-12-16 00:59:52,818 INFO L121 FreeRefinementEngine]: Executing refinement strategy CAMEL [2021-12-16 00:59:52,818 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [1196710322] [2021-12-16 00:59:52,818 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2021-12-16 00:59:52,818 INFO L126 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2021-12-16 00:59:52,827 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 00:59:52,855 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 11 [2021-12-16 00:59:52,856 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 00:59:52,862 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 23 [2021-12-16 00:59:52,864 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 00:59:52,873 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 8 [2021-12-16 00:59:52,874 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 00:59:52,875 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 39 [2021-12-16 00:59:52,876 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 00:59:52,884 INFO L134 CoverageAnalysis]: Checked inductivity of 0 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2021-12-16 00:59:52,884 INFO L139 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2021-12-16 00:59:52,884 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [1196710322] [2021-12-16 00:59:52,885 INFO L160 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [1196710322] provided 1 perfect and 0 imperfect interpolant sequences [2021-12-16 00:59:52,885 INFO L186 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2021-12-16 00:59:52,885 INFO L199 FreeRefinementEngine]: Number of different interpolants: perfect sequences [8] imperfect sequences [] total 8 [2021-12-16 00:59:52,885 INFO L115 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [197544978] [2021-12-16 00:59:52,885 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2021-12-16 00:59:52,885 INFO L546 AbstractCegarLoop]: INTERPOLANT automaton has 8 states [2021-12-16 00:59:52,885 INFO L103 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2021-12-16 00:59:52,886 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 8 interpolants. [2021-12-16 00:59:52,886 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=14, Invalid=42, Unknown=0, NotChecked=0, Total=56 [2021-12-16 00:59:52,886 INFO L87 Difference]: Start difference. First operand 193 states and 226 transitions. Second operand has 8 states, 8 states have (on average 5.125) internal successors, (41), 6 states have internal predecessors, (41), 3 states have call successors, (5), 3 states have call predecessors, (5), 2 states have return successors, (4), 3 states have call predecessors, (4), 3 states have call successors, (4) [2021-12-16 00:59:53,219 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2021-12-16 00:59:53,220 INFO L93 Difference]: Finished difference Result 472 states and 578 transitions. [2021-12-16 00:59:53,220 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 20 states. [2021-12-16 00:59:53,220 INFO L78 Accepts]: Start accepts. Automaton has has 8 states, 8 states have (on average 5.125) internal successors, (41), 6 states have internal predecessors, (41), 3 states have call successors, (5), 3 states have call predecessors, (5), 2 states have return successors, (4), 3 states have call predecessors, (4), 3 states have call successors, (4) Word has length 50 [2021-12-16 00:59:53,221 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2021-12-16 00:59:53,222 INFO L225 Difference]: With dead ends: 472 [2021-12-16 00:59:53,222 INFO L226 Difference]: Without dead ends: 332 [2021-12-16 00:59:53,223 INFO L932 BasicCegarLoop]: 0 DeclaredPredicates, 32 GetRequests, 12 SyntacticMatches, 0 SemanticMatches, 20 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 87 ImplicationChecksByTransitivity, 0.1s TimeCoverageRelationStatistics Valid=132, Invalid=330, Unknown=0, NotChecked=0, Total=462 [2021-12-16 00:59:53,224 INFO L933 BasicCegarLoop]: 78 mSDtfsCounter, 251 mSDsluCounter, 356 mSDsCounter, 0 mSdLazyCounter, 304 mSolverCounterSat, 87 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.2s Time, 0 mProtectedPredicate, 0 mProtectedAction, 256 SdHoareTripleChecker+Valid, 434 SdHoareTripleChecker+Invalid, 391 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 87 IncrementalHoareTripleChecker+Valid, 304 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.2s IncrementalHoareTripleChecker+Time [2021-12-16 00:59:53,224 INFO L934 BasicCegarLoop]: SdHoareTripleChecker [256 Valid, 434 Invalid, 391 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [87 Valid, 304 Invalid, 0 Unknown, 0 Unchecked, 0.2s Time] [2021-12-16 00:59:53,225 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 332 states. [2021-12-16 00:59:53,239 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 332 to 303. [2021-12-16 00:59:53,240 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 303 states, 233 states have (on average 1.1974248927038627) internal successors, (279), 247 states have internal predecessors, (279), 36 states have call successors, (36), 29 states have call predecessors, (36), 33 states have return successors, (46), 34 states have call predecessors, (46), 36 states have call successors, (46) [2021-12-16 00:59:53,241 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 303 states to 303 states and 361 transitions. [2021-12-16 00:59:53,241 INFO L78 Accepts]: Start accepts. Automaton has 303 states and 361 transitions. Word has length 50 [2021-12-16 00:59:53,242 INFO L84 Accepts]: Finished accepts. word is rejected. [2021-12-16 00:59:53,242 INFO L470 AbstractCegarLoop]: Abstraction has 303 states and 361 transitions. [2021-12-16 00:59:53,242 INFO L471 AbstractCegarLoop]: INTERPOLANT automaton has has 8 states, 8 states have (on average 5.125) internal successors, (41), 6 states have internal predecessors, (41), 3 states have call successors, (5), 3 states have call predecessors, (5), 2 states have return successors, (4), 3 states have call predecessors, (4), 3 states have call successors, (4) [2021-12-16 00:59:53,242 INFO L276 IsEmpty]: Start isEmpty. Operand 303 states and 361 transitions. [2021-12-16 00:59:53,243 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 82 [2021-12-16 00:59:53,244 INFO L506 BasicCegarLoop]: Found error trace [2021-12-16 00:59:53,244 INFO L514 BasicCegarLoop]: trace histogram [3, 3, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2021-12-16 00:59:53,244 WARN L452 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable10 [2021-12-16 00:59:53,244 INFO L402 AbstractCegarLoop]: === Iteration 12 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2021-12-16 00:59:53,244 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2021-12-16 00:59:53,245 INFO L85 PathProgramCache]: Analyzing trace with hash -365727847, now seen corresponding path program 1 times [2021-12-16 00:59:53,245 INFO L121 FreeRefinementEngine]: Executing refinement strategy CAMEL [2021-12-16 00:59:53,245 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [735039556] [2021-12-16 00:59:53,245 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2021-12-16 00:59:53,245 INFO L126 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2021-12-16 00:59:53,255 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 00:59:53,273 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 11 [2021-12-16 00:59:53,275 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 00:59:53,282 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 19 [2021-12-16 00:59:53,285 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 00:59:53,315 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 3 [2021-12-16 00:59:53,317 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 00:59:53,321 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 17 [2021-12-16 00:59:53,322 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 00:59:53,330 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 60 [2021-12-16 00:59:53,330 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 00:59:53,335 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 70 [2021-12-16 00:59:53,336 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 00:59:53,337 INFO L134 CoverageAnalysis]: Checked inductivity of 26 backedges. 17 proven. 4 refuted. 0 times theorem prover too weak. 5 trivial. 0 not checked. [2021-12-16 00:59:53,337 INFO L139 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2021-12-16 00:59:53,338 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [735039556] [2021-12-16 00:59:53,338 INFO L160 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [735039556] provided 0 perfect and 1 imperfect interpolant sequences [2021-12-16 00:59:53,338 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleZ3 [1935652378] [2021-12-16 00:59:53,338 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2021-12-16 00:59:53,338 INFO L168 SolverBuilder]: Constructing external solver with command: z3 -smt2 -in SMTLIB2_COMPLIANT=true [2021-12-16 00:59:53,339 INFO L189 MonitoredProcess]: No working directory specified, using /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 [2021-12-16 00:59:53,347 INFO L229 MonitoredProcess]: Starting monitored process 2 with /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 -smt2 -in SMTLIB2_COMPLIANT=true (exit command is (exit), workingDir is null) [2021-12-16 00:59:53,354 INFO L327 MonitoredProcess]: [MP /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 -smt2 -in SMTLIB2_COMPLIANT=true (2)] Waiting until timeout for monitored process [2021-12-16 00:59:53,439 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 00:59:53,442 INFO L263 TraceCheckSpWp]: Trace formula consists of 433 conjuncts, 13 conjunts are in the unsatisfiable core [2021-12-16 00:59:53,447 INFO L286 TraceCheckSpWp]: Computing forward predicates... [2021-12-16 00:59:53,749 INFO L134 CoverageAnalysis]: Checked inductivity of 26 backedges. 6 proven. 12 refuted. 0 times theorem prover too weak. 8 trivial. 0 not checked. [2021-12-16 00:59:53,749 INFO L328 TraceCheckSpWp]: Computing backward predicates... [2021-12-16 00:59:54,067 INFO L134 CoverageAnalysis]: Checked inductivity of 26 backedges. 8 proven. 4 refuted. 0 times theorem prover too weak. 14 trivial. 0 not checked. [2021-12-16 00:59:54,068 INFO L160 FreeRefinementEngine]: IpTcStrategyModuleZ3 [1935652378] provided 0 perfect and 2 imperfect interpolant sequences [2021-12-16 00:59:54,068 INFO L186 FreeRefinementEngine]: Found 0 perfect and 3 imperfect interpolant sequences. [2021-12-16 00:59:54,068 INFO L199 FreeRefinementEngine]: Number of different interpolants: perfect sequences [] imperfect sequences [10, 8, 9] total 19 [2021-12-16 00:59:54,069 INFO L115 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [419022040] [2021-12-16 00:59:54,069 INFO L85 oduleStraightlineAll]: Using 3 imperfect interpolants to construct interpolant automaton [2021-12-16 00:59:54,069 INFO L546 AbstractCegarLoop]: INTERPOLANT automaton has 19 states [2021-12-16 00:59:54,070 INFO L103 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2021-12-16 00:59:54,070 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 19 interpolants. [2021-12-16 00:59:54,070 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=60, Invalid=282, Unknown=0, NotChecked=0, Total=342 [2021-12-16 00:59:54,071 INFO L87 Difference]: Start difference. First operand 303 states and 361 transitions. Second operand has 19 states, 19 states have (on average 6.578947368421052) internal successors, (125), 14 states have internal predecessors, (125), 7 states have call successors, (20), 10 states have call predecessors, (20), 8 states have return successors, (18), 8 states have call predecessors, (18), 7 states have call successors, (18) [2021-12-16 00:59:55,348 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2021-12-16 00:59:55,348 INFO L93 Difference]: Finished difference Result 929 states and 1194 transitions. [2021-12-16 00:59:55,348 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 52 states. [2021-12-16 00:59:55,349 INFO L78 Accepts]: Start accepts. Automaton has has 19 states, 19 states have (on average 6.578947368421052) internal successors, (125), 14 states have internal predecessors, (125), 7 states have call successors, (20), 10 states have call predecessors, (20), 8 states have return successors, (18), 8 states have call predecessors, (18), 7 states have call successors, (18) Word has length 81 [2021-12-16 00:59:55,349 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2021-12-16 00:59:55,349 INFO L225 Difference]: With dead ends: 929 [2021-12-16 00:59:55,349 INFO L226 Difference]: Without dead ends: 0 [2021-12-16 00:59:55,353 INFO L932 BasicCegarLoop]: 0 DeclaredPredicates, 237 GetRequests, 169 SyntacticMatches, 1 SemanticMatches, 67 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 1203 ImplicationChecksByTransitivity, 0.7s TimeCoverageRelationStatistics Valid=927, Invalid=3765, Unknown=0, NotChecked=0, Total=4692 [2021-12-16 00:59:55,353 INFO L933 BasicCegarLoop]: 106 mSDtfsCounter, 1062 mSDsluCounter, 554 mSDsCounter, 0 mSdLazyCounter, 1007 mSolverCounterSat, 521 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.5s Time, 0 mProtectedPredicate, 0 mProtectedAction, 1062 SdHoareTripleChecker+Valid, 660 SdHoareTripleChecker+Invalid, 1528 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 521 IncrementalHoareTripleChecker+Valid, 1007 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.6s IncrementalHoareTripleChecker+Time [2021-12-16 00:59:55,354 INFO L934 BasicCegarLoop]: SdHoareTripleChecker [1062 Valid, 660 Invalid, 1528 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [521 Valid, 1007 Invalid, 0 Unknown, 0 Unchecked, 0.6s Time] [2021-12-16 00:59:55,354 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 0 states. [2021-12-16 00:59:55,354 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 0 to 0. [2021-12-16 00:59:55,354 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 0 states, 0 states have (on average 0.0) internal successors, (0), 0 states have internal predecessors, (0), 0 states have call successors, (0), 0 states have call predecessors, (0), 0 states have return successors, (0), 0 states have call predecessors, (0), 0 states have call successors, (0) [2021-12-16 00:59:55,355 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 0 states to 0 states and 0 transitions. [2021-12-16 00:59:55,355 INFO L78 Accepts]: Start accepts. Automaton has 0 states and 0 transitions. Word has length 81 [2021-12-16 00:59:55,355 INFO L84 Accepts]: Finished accepts. word is rejected. [2021-12-16 00:59:55,355 INFO L470 AbstractCegarLoop]: Abstraction has 0 states and 0 transitions. [2021-12-16 00:59:55,355 INFO L471 AbstractCegarLoop]: INTERPOLANT automaton has has 19 states, 19 states have (on average 6.578947368421052) internal successors, (125), 14 states have internal predecessors, (125), 7 states have call successors, (20), 10 states have call predecessors, (20), 8 states have return successors, (18), 8 states have call predecessors, (18), 7 states have call successors, (18) [2021-12-16 00:59:55,356 INFO L276 IsEmpty]: Start isEmpty. Operand 0 states and 0 transitions. [2021-12-16 00:59:55,356 INFO L282 IsEmpty]: Finished isEmpty. No accepting run. [2021-12-16 00:59:55,358 INFO L764 garLoopResultBuilder]: Registering result SAFE for location timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION (0 of 1 remaining) [2021-12-16 00:59:55,388 INFO L552 MonitoredProcess]: [MP /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 -smt2 -in SMTLIB2_COMPLIANT=true (2)] Ended with exit code 0 [2021-12-16 00:59:55,582 WARN L452 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: 2 /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 -smt2 -in SMTLIB2_COMPLIANT=true,SelfDestructingSolverStorable11 [2021-12-16 00:59:55,584 INFO L343 DoubleDeckerVisitor]: Before removal of dead ends 0 states and 0 transitions. [2021-12-16 00:59:59,128 INFO L858 garLoopResultBuilder]: For program point processEnvironment__wrappee__baseEXIT(lines 555 561) no Hoare annotation was computed. [2021-12-16 00:59:59,128 INFO L861 garLoopResultBuilder]: At program point processEnvironment__wrappee__baseFINAL(lines 555 561) the Hoare annotation is: true [2021-12-16 00:59:59,128 INFO L858 garLoopResultBuilder]: For program point L802-1(lines 798 809) no Hoare annotation was computed. [2021-12-16 00:59:59,129 INFO L854 garLoopResultBuilder]: At program point changeMethaneLevelENTRY(lines 798 809) the Hoare annotation is: (let ((.cse6 (not (= ~pumpRunning~0 0))) (.cse2 (not (= 0 ~methaneLevelCritical~0))) (.cse3 (= 0 |old(~methaneLevelCritical~0)|)) (.cse5 (not (= |old(~methaneLevelCritical~0)| 0))) (.cse0 (not (<= 1 ~pumpRunning~0))) (.cse7 (= ~methaneLevelCritical~0 0)) (.cse1 (not (<= ~waterLevel~0 2))) (.cse4 (not (= ~systemActive~0 1)))) (and (or .cse0 .cse1 .cse2 .cse3 .cse4) (or .cse5 .cse6 .cse7 .cse1 .cse4) (or .cse6 .cse1 .cse2 .cse3 .cse4) (or .cse5 .cse0 .cse7 .cse1 .cse4))) [2021-12-16 00:59:59,129 INFO L858 garLoopResultBuilder]: For program point changeMethaneLevelEXIT(lines 798 809) no Hoare annotation was computed. [2021-12-16 00:59:59,129 INFO L861 garLoopResultBuilder]: At program point isMethaneLevelCriticalENTRY(lines 810 818) the Hoare annotation is: true [2021-12-16 00:59:59,129 INFO L858 garLoopResultBuilder]: For program point isMethaneLevelCriticalFINAL(lines 810 818) no Hoare annotation was computed. [2021-12-16 00:59:59,129 INFO L858 garLoopResultBuilder]: For program point isMethaneLevelCriticalEXIT(lines 810 818) no Hoare annotation was computed. [2021-12-16 00:59:59,130 INFO L858 garLoopResultBuilder]: For program point L894(lines 894 900) no Hoare annotation was computed. [2021-12-16 00:59:59,130 INFO L858 garLoopResultBuilder]: For program point L890(lines 890 903) no Hoare annotation was computed. [2021-12-16 00:59:59,130 INFO L854 garLoopResultBuilder]: At program point L890-1(lines 875 907) the Hoare annotation is: (let ((.cse10 (<= ~waterLevel~0 1)) (.cse4 (= ~waterLevel~0 |old(~waterLevel~0)|)) (.cse11 (= ~pumpRunning~0 |old(~pumpRunning~0)|)) (.cse6 (= ~methaneLevelCritical~0 |timeShift___utac_acc__Specification3_spec__1_~tmp~8#1|))) (let ((.cse0 (and .cse10 .cse4 .cse11 .cse6)) (.cse5 (<= 1 ~pumpRunning~0)) (.cse1 (not (= |old(~pumpRunning~0)| 0))) (.cse3 (not (<= |old(~waterLevel~0)| 2))) (.cse7 (and (<= |timeShift___utac_acc__Specification3_spec__1_~tmp___0~2#1| 1) (<= |timeShift_getWaterLevel_#res#1| 1))) (.cse8 (not (= ~methaneLevelCritical~0 0))) (.cse2 (not (= ~systemActive~0 1))) (.cse12 (not (<= 1 |old(~pumpRunning~0)|)))) (and (or .cse0 .cse1 .cse2 (not (<= |old(~waterLevel~0)| 1))) (or .cse3 (and .cse4 .cse5 .cse6) .cse0 .cse1 .cse2) (or .cse3 (and .cse4 .cse5) .cse7 .cse1 .cse8 .cse2) (let ((.cse9 (<= ~waterLevel~0 |old(~waterLevel~0)|))) (or .cse3 (and .cse9 .cse10 .cse6 (= ~pumpRunning~0 0)) (and .cse9 .cse10 .cse11 .cse6) .cse2 .cse12)) (or .cse3 .cse7 .cse8 .cse2 .cse12)))) [2021-12-16 00:59:59,130 INFO L858 garLoopResultBuilder]: For program point L535-1(lines 534 553) no Hoare annotation was computed. [2021-12-16 00:59:59,130 INFO L858 garLoopResultBuilder]: For program point L597(lines 597 605) no Hoare annotation was computed. [2021-12-16 00:59:59,131 INFO L854 garLoopResultBuilder]: At program point L882(line 882) the Hoare annotation is: (let ((.cse6 (<= ~waterLevel~0 1)) (.cse1 (= ~waterLevel~0 |old(~waterLevel~0)|)) (.cse7 (= ~pumpRunning~0 |old(~pumpRunning~0)|)) (.cse8 (= ~pumpRunning~0 0))) (let ((.cse0 (not (<= |old(~waterLevel~0)| 2))) (.cse2 (and .cse6 .cse1 .cse7 .cse8)) (.cse3 (not (= |old(~pumpRunning~0)| 0))) (.cse4 (not (= ~systemActive~0 1)))) (and (or .cse0 (and .cse1 (<= 1 ~pumpRunning~0)) .cse2 .cse3 .cse4) (let ((.cse5 (<= ~waterLevel~0 |old(~waterLevel~0)|))) (or .cse0 (and .cse5 .cse6 .cse7) (and .cse5 .cse6 .cse8) .cse4 (not (<= 1 |old(~pumpRunning~0)|)))) (or .cse2 .cse3 .cse4 (not (<= |old(~waterLevel~0)| 1)))))) [2021-12-16 00:59:59,131 INFO L858 garLoopResultBuilder]: For program point L593(lines 593 610) no Hoare annotation was computed. [2021-12-16 00:59:59,131 INFO L858 garLoopResultBuilder]: For program point L882-1(line 882) no Hoare annotation was computed. [2021-12-16 00:59:59,131 INFO L858 garLoopResultBuilder]: For program point timeShiftFINAL(lines 531 554) no Hoare annotation was computed. [2021-12-16 00:59:59,131 INFO L858 garLoopResultBuilder]: For program point L870(line 870) no Hoare annotation was computed. [2021-12-16 00:59:59,131 INFO L854 garLoopResultBuilder]: At program point L635(line 635) the Hoare annotation is: (let ((.cse0 (not (<= |old(~waterLevel~0)| 2))) (.cse1 (not (= ~systemActive~0 1)))) (and (or .cse0 (and (<= ~waterLevel~0 |old(~waterLevel~0)|) (<= ~waterLevel~0 1) (= ~pumpRunning~0 |old(~pumpRunning~0)|)) .cse1 (not (<= 1 |old(~pumpRunning~0)|))) (or .cse0 (not (= |old(~pumpRunning~0)| 0)) .cse1))) [2021-12-16 00:59:59,131 INFO L858 garLoopResultBuilder]: For program point L635-1(line 635) no Hoare annotation was computed. [2021-12-16 00:59:59,131 INFO L854 garLoopResultBuilder]: At program point L627(lines 622 629) the Hoare annotation is: (let ((.cse0 (not (<= |old(~waterLevel~0)| 2))) (.cse1 (not (= ~systemActive~0 1)))) (and (or .cse0 (and (<= ~waterLevel~0 |old(~waterLevel~0)|) (<= ~waterLevel~0 1) (= ~pumpRunning~0 0)) .cse1 (not (<= 1 |old(~pumpRunning~0)|))) (or .cse0 (not (= |old(~pumpRunning~0)| 0)) .cse1))) [2021-12-16 00:59:59,131 INFO L854 garLoopResultBuilder]: At program point L871(lines 866 873) the Hoare annotation is: (let ((.cse0 (not (<= |old(~waterLevel~0)| 2))) (.cse1 (not (= ~systemActive~0 1)))) (and (or .cse0 .cse1 (not (<= 1 |old(~pumpRunning~0)|))) (or .cse0 (not (= |old(~pumpRunning~0)| 0)) .cse1))) [2021-12-16 00:59:59,131 INFO L854 garLoopResultBuilder]: At program point L603(line 603) the Hoare annotation is: (let ((.cse0 (not (<= |old(~waterLevel~0)| 2))) (.cse1 (not (= ~systemActive~0 1)))) (and (or .cse0 (and (<= ~waterLevel~0 |old(~waterLevel~0)|) (<= ~waterLevel~0 1) (= ~pumpRunning~0 |old(~pumpRunning~0)|)) .cse1 (not (<= 1 |old(~pumpRunning~0)|))) (or .cse0 (not (= |old(~pumpRunning~0)| 0)) .cse1))) [2021-12-16 00:59:59,132 INFO L858 garLoopResultBuilder]: For program point L884(lines 884 904) no Hoare annotation was computed. [2021-12-16 00:59:59,132 INFO L854 garLoopResultBuilder]: At program point L847(lines 842 850) the Hoare annotation is: (let ((.cse2 (<= ~waterLevel~0 1)) (.cse3 (<= |timeShift_getWaterLevel_#res#1| 1)) (.cse10 (= ~waterLevel~0 |old(~waterLevel~0)|)) (.cse5 (= ~methaneLevelCritical~0 |timeShift___utac_acc__Specification3_spec__1_~tmp~8#1|)) (.cse6 (= ~pumpRunning~0 0))) (let ((.cse0 (not (<= |old(~waterLevel~0)| 2))) (.cse8 (not (= |old(~pumpRunning~0)| 0))) (.cse9 (and .cse2 .cse3 .cse10 .cse5 .cse6)) (.cse7 (not (= ~systemActive~0 1)))) (and (let ((.cse1 (<= ~waterLevel~0 |old(~waterLevel~0)|)) (.cse4 (= ~methaneLevelCritical~0 0))) (or .cse0 (and .cse1 .cse2 .cse3 .cse4 .cse5 .cse6) (and .cse1 .cse2 .cse3 .cse4 (= ~pumpRunning~0 |old(~pumpRunning~0)|) .cse5) .cse7 (not (<= 1 |old(~pumpRunning~0)|)))) (or .cse0 .cse8 .cse7 (= 0 ~methaneLevelCritical~0)) (or (not (= |old(~waterLevel~0)| 1)) (= |timeShift_getWaterLevel_#res#1| 1) .cse8 .cse7) (or .cse8 .cse9 .cse7 (not (<= |old(~waterLevel~0)| 1))) (or .cse0 (and .cse10 (<= 1 ~pumpRunning~0) .cse5) .cse8 .cse9 .cse7)))) [2021-12-16 00:59:59,132 INFO L854 garLoopResultBuilder]: At program point L608(line 608) the Hoare annotation is: (let ((.cse0 (not (<= |old(~waterLevel~0)| 2))) (.cse1 (not (= ~systemActive~0 1)))) (and (or .cse0 .cse1 (not (<= 1 |old(~pumpRunning~0)|))) (or .cse0 (and (= ~waterLevel~0 |old(~waterLevel~0)|) (= ~pumpRunning~0 0)) (not (= |old(~pumpRunning~0)| 0)) .cse1))) [2021-12-16 00:59:59,132 INFO L854 garLoopResultBuilder]: At program point L608-1(lines 589 613) the Hoare annotation is: (let ((.cse6 (<= ~waterLevel~0 1)) (.cse1 (= ~waterLevel~0 |old(~waterLevel~0)|)) (.cse7 (= ~pumpRunning~0 |old(~pumpRunning~0)|)) (.cse8 (= ~pumpRunning~0 0))) (let ((.cse0 (not (<= |old(~waterLevel~0)| 2))) (.cse2 (and .cse6 .cse1 .cse7 .cse8)) (.cse3 (not (= |old(~pumpRunning~0)| 0))) (.cse4 (not (= ~systemActive~0 1)))) (and (or .cse0 (and .cse1 (<= 1 ~pumpRunning~0)) .cse2 .cse3 .cse4) (let ((.cse5 (<= ~waterLevel~0 |old(~waterLevel~0)|))) (or .cse0 (and .cse5 .cse6 .cse7) (and .cse5 .cse6 .cse8) .cse4 (not (<= 1 |old(~pumpRunning~0)|)))) (or .cse2 .cse3 .cse4 (not (<= |old(~waterLevel~0)| 1)))))) [2021-12-16 00:59:59,132 INFO L854 garLoopResultBuilder]: At program point L637(lines 630 640) the Hoare annotation is: (let ((.cse0 (not (<= |old(~waterLevel~0)| 2))) (.cse1 (not (= ~systemActive~0 1)))) (and (or .cse0 (and (<= ~waterLevel~0 |old(~waterLevel~0)|) (<= ~waterLevel~0 1) (= ~pumpRunning~0 |old(~pumpRunning~0)|)) .cse1 (not (<= 1 |old(~pumpRunning~0)|))) (or .cse0 (not (= |old(~pumpRunning~0)| 0)) .cse1))) [2021-12-16 00:59:59,133 INFO L858 garLoopResultBuilder]: For program point L542-1(lines 542 548) no Hoare annotation was computed. [2021-12-16 00:59:59,133 INFO L854 garLoopResultBuilder]: At program point timeShiftENTRY(lines 531 554) the Hoare annotation is: (let ((.cse0 (not (<= |old(~waterLevel~0)| 2))) (.cse1 (= ~waterLevel~0 |old(~waterLevel~0)|)) (.cse2 (not (= ~systemActive~0 1)))) (and (or .cse0 (and .cse1 (= ~pumpRunning~0 |old(~pumpRunning~0)|)) .cse2 (not (<= 1 |old(~pumpRunning~0)|))) (or .cse0 (and .cse1 (= ~pumpRunning~0 0)) (not (= |old(~pumpRunning~0)| 0)) .cse2))) [2021-12-16 00:59:59,133 INFO L858 garLoopResultBuilder]: For program point timeShiftEXIT(lines 531 554) no Hoare annotation was computed. [2021-12-16 00:59:59,133 INFO L858 garLoopResultBuilder]: For program point L778(lines 778 782) no Hoare annotation was computed. [2021-12-16 00:59:59,133 INFO L858 garLoopResultBuilder]: For program point timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION(line 870) no Hoare annotation was computed. [2021-12-16 00:59:59,133 INFO L854 garLoopResultBuilder]: At program point L778-2(lines 774 785) the Hoare annotation is: (let ((.cse0 (not (<= |old(~waterLevel~0)| 2))) (.cse1 (not (= ~systemActive~0 1)))) (and (or .cse0 (and (<= ~waterLevel~0 |old(~waterLevel~0)|) (<= ~waterLevel~0 1) (= ~pumpRunning~0 |old(~pumpRunning~0)|)) .cse1 (not (<= 1 |old(~pumpRunning~0)|))) (or .cse0 (not (= |old(~pumpRunning~0)| 0)) .cse1))) [2021-12-16 00:59:59,134 INFO L854 garLoopResultBuilder]: At program point L646(lines 641 649) the Hoare annotation is: (let ((.cse0 (not (<= |old(~waterLevel~0)| 2))) (.cse2 (not (= |old(~pumpRunning~0)| 0))) (.cse1 (not (= ~systemActive~0 1)))) (and (or .cse0 .cse1 (not (<= 1 |old(~pumpRunning~0)|))) (or .cse2 .cse1 (not (<= |old(~waterLevel~0)| 1))) (or .cse0 .cse2 .cse1 (= 0 ~methaneLevelCritical~0)) (or .cse0 .cse2 (and (= ~waterLevel~0 |old(~waterLevel~0)|) (<= 1 ~pumpRunning~0) (not (= 0 |timeShift_isPumpRunning_#res#1|)) (= ~methaneLevelCritical~0 |timeShift___utac_acc__Specification3_spec__1_~tmp~8#1|)) .cse1))) [2021-12-16 00:59:59,134 INFO L861 garLoopResultBuilder]: At program point L66-1(lines 66 70) the Hoare annotation is: true [2021-12-16 00:59:59,134 INFO L858 garLoopResultBuilder]: For program point cleanupEXIT(lines 52 81) no Hoare annotation was computed. [2021-12-16 00:59:59,134 INFO L858 garLoopResultBuilder]: For program point L63(line 63) no Hoare annotation was computed. [2021-12-16 00:59:59,134 INFO L861 garLoopResultBuilder]: At program point cleanupENTRY(lines 52 81) the Hoare annotation is: true [2021-12-16 00:59:59,134 INFO L861 garLoopResultBuilder]: At program point L62-2(lines 62 76) the Hoare annotation is: true [2021-12-16 00:59:59,134 INFO L861 garLoopResultBuilder]: At program point L58(line 58) the Hoare annotation is: true [2021-12-16 00:59:59,135 INFO L858 garLoopResultBuilder]: For program point L58-1(line 58) no Hoare annotation was computed. [2021-12-16 00:59:59,135 INFO L861 garLoopResultBuilder]: At program point L77(lines 52 81) the Hoare annotation is: true [2021-12-16 00:59:59,135 INFO L858 garLoopResultBuilder]: For program point L73(line 73) no Hoare annotation was computed. [2021-12-16 00:59:59,135 INFO L858 garLoopResultBuilder]: For program point L66(lines 66 70) no Hoare annotation was computed. [2021-12-16 00:59:59,135 INFO L854 garLoopResultBuilder]: At program point L762(lines 715 763) the Hoare annotation is: false [2021-12-16 00:59:59,135 INFO L858 garLoopResultBuilder]: For program point L717(lines 716 761) no Hoare annotation was computed. [2021-12-16 00:59:59,135 INFO L858 garLoopResultBuilder]: For program point L746(lines 746 757) no Hoare annotation was computed. [2021-12-16 00:59:59,136 INFO L854 garLoopResultBuilder]: At program point L738(line 738) the Hoare annotation is: (let ((.cse0 (= |ULTIMATE.start_test_~splverifierCounter~0#1| 0)) (.cse1 (= 1 |ULTIMATE.start_valid_product_#res#1|)) (.cse2 (= 1 |ULTIMATE.start_main_~tmp~0#1|)) (.cse3 (<= ~waterLevel~0 2)) (.cse4 (= ~systemActive~0 1))) (or (and .cse0 .cse1 (<= 1 ~pumpRunning~0) .cse2 .cse3 .cse4) (and .cse0 .cse1 .cse2 .cse3 .cse4 (= ~pumpRunning~0 0)))) [2021-12-16 00:59:59,136 INFO L858 garLoopResultBuilder]: For program point L-1(line -1) no Hoare annotation was computed. [2021-12-16 00:59:59,136 INFO L858 garLoopResultBuilder]: For program point ULTIMATE.startENTRY(line -1) no Hoare annotation was computed. [2021-12-16 00:59:59,136 INFO L858 garLoopResultBuilder]: For program point ULTIMATE.startFINAL(line -1) no Hoare annotation was computed. [2021-12-16 00:59:59,136 INFO L854 garLoopResultBuilder]: At program point L924(lines 920 926) the Hoare annotation is: (and (= ~waterLevel~0 1) (= ~methaneLevelCritical~0 0) (= ~systemActive~0 1) (= ~pumpRunning~0 0)) [2021-12-16 00:59:59,136 INFO L854 garLoopResultBuilder]: At program point L759(lines 716 761) the Hoare annotation is: (let ((.cse0 (= |ULTIMATE.start_test_~splverifierCounter~0#1| 0)) (.cse1 (= 1 |ULTIMATE.start_valid_product_#res#1|)) (.cse2 (= 1 |ULTIMATE.start_main_~tmp~0#1|)) (.cse3 (= ~systemActive~0 1))) (or (and .cse0 .cse1 (<= 1 ~pumpRunning~0) .cse2 (<= ~waterLevel~0 2) .cse3) (and .cse0 (<= ~waterLevel~0 1) .cse1 .cse2 .cse3 (= ~pumpRunning~0 0)))) [2021-12-16 00:59:59,137 INFO L858 garLoopResultBuilder]: For program point L726(lines 726 732) no Hoare annotation was computed. [2021-12-16 00:59:59,137 INFO L858 garLoopResultBuilder]: For program point L726-1(lines 726 732) no Hoare annotation was computed. [2021-12-16 00:59:59,137 INFO L858 garLoopResultBuilder]: For program point L718(lines 718 722) no Hoare annotation was computed. [2021-12-16 00:59:59,137 INFO L858 garLoopResultBuilder]: For program point L140(lines 140 147) no Hoare annotation was computed. [2021-12-16 00:59:59,137 INFO L858 garLoopResultBuilder]: For program point L140-2(lines 140 147) no Hoare annotation was computed. [2021-12-16 00:59:59,137 INFO L858 garLoopResultBuilder]: For program point ULTIMATE.startEXIT(line -1) no Hoare annotation was computed. [2021-12-16 00:59:59,137 INFO L861 garLoopResultBuilder]: At program point L124(lines 117 126) the Hoare annotation is: true [2021-12-16 00:59:59,137 INFO L861 garLoopResultBuilder]: At program point L149(lines 130 152) the Hoare annotation is: true [2021-12-16 00:59:59,138 INFO L858 garLoopResultBuilder]: For program point L752(lines 752 756) no Hoare annotation was computed. [2021-12-16 00:59:59,138 INFO L854 garLoopResultBuilder]: At program point L752-2(lines 746 757) the Hoare annotation is: (let ((.cse0 (= |ULTIMATE.start_test_~splverifierCounter~0#1| 0)) (.cse1 (= 1 |ULTIMATE.start_valid_product_#res#1|)) (.cse2 (= 1 |ULTIMATE.start_main_~tmp~0#1|)) (.cse3 (<= ~waterLevel~0 2)) (.cse4 (= ~systemActive~0 1))) (or (and .cse0 .cse1 (<= 1 ~pumpRunning~0) .cse2 .cse3 .cse4) (and .cse0 .cse1 .cse2 .cse3 .cse4 (= ~pumpRunning~0 0)))) [2021-12-16 00:59:59,138 INFO L858 garLoopResultBuilder]: For program point L736(lines 736 742) no Hoare annotation was computed. [2021-12-16 00:59:59,138 INFO L858 garLoopResultBuilder]: For program point L736-1(lines 736 742) no Hoare annotation was computed. [2021-12-16 00:59:59,138 INFO L861 garLoopResultBuilder]: At program point L765(lines 706 769) the Hoare annotation is: true [2021-12-16 00:59:59,138 INFO L854 garLoopResultBuilder]: At program point L728(line 728) the Hoare annotation is: (let ((.cse0 (= |ULTIMATE.start_test_~splverifierCounter~0#1| 0)) (.cse1 (= 1 |ULTIMATE.start_valid_product_#res#1|)) (.cse2 (= 1 |ULTIMATE.start_main_~tmp~0#1|)) (.cse3 (= ~systemActive~0 1))) (or (and .cse0 .cse1 (<= 1 ~pumpRunning~0) .cse2 (<= ~waterLevel~0 2) .cse3) (and .cse0 (<= ~waterLevel~0 1) .cse1 .cse2 .cse3 (= ~pumpRunning~0 0)))) [2021-12-16 00:59:59,138 INFO L854 garLoopResultBuilder]: At program point L113(lines 109 115) the Hoare annotation is: (and (= ~waterLevel~0 1) (= ~methaneLevelCritical~0 0) (= 1 |ULTIMATE.start_valid_product_#res#1|) (= 1 |ULTIMATE.start_main_~tmp~0#1|) (= ~systemActive~0 1) (= ~pumpRunning~0 0)) [2021-12-16 00:59:59,138 INFO L854 garLoopResultBuilder]: At program point L939(lines 934 942) the Hoare annotation is: (and (= ~waterLevel~0 1) (= ~methaneLevelCritical~0 0) (= 1 |ULTIMATE.start_valid_product_#res#1|) (= ~systemActive~0 1) (= ~pumpRunning~0 0)) [2021-12-16 00:59:59,138 INFO L854 garLoopResultBuilder]: At program point L931(lines 927 933) the Hoare annotation is: (and (= ~waterLevel~0 1) (= ~methaneLevelCritical~0 0) (= ~systemActive~0 1) (= ~pumpRunning~0 0)) [2021-12-16 00:59:59,138 INFO L854 garLoopResultBuilder]: At program point processEnvironment__wrappee__highWaterSensorENTRY(lines 563 587) the Hoare annotation is: (let ((.cse0 (not (= ~systemActive~0 1)))) (and (or (not (<= ~waterLevel~0 1)) (= ~pumpRunning~0 |old(~pumpRunning~0)|) .cse0 (not (<= 1 |old(~pumpRunning~0)|))) (or (not (<= ~waterLevel~0 2)) (not (= |old(~pumpRunning~0)| 0)) .cse0 (= ~pumpRunning~0 0)))) [2021-12-16 00:59:59,139 INFO L858 garLoopResultBuilder]: For program point L855(lines 855 861) no Hoare annotation was computed. [2021-12-16 00:59:59,139 INFO L854 garLoopResultBuilder]: At program point L577(line 577) the Hoare annotation is: (let ((.cse0 (not (= |old(~pumpRunning~0)| 0))) (.cse2 (<= ~waterLevel~0 1)) (.cse1 (not (= ~systemActive~0 1)))) (and (or (not (= ~waterLevel~0 1)) (and (not (= |processEnvironment__wrappee__highWaterSensor_isHighWaterSensorDry_#res#1| 0)) (not (= 0 |processEnvironment__wrappee__highWaterSensor_isHighWaterLevel_~tmp~6#1|))) .cse0 .cse1) (or (and .cse2 (= ~pumpRunning~0 |old(~pumpRunning~0)|) (= |processEnvironment__wrappee__highWaterSensor_~tmp~4#1| 0)) (not (<= ~waterLevel~0 2)) .cse0 .cse1) (or (not .cse2) .cse1 (not (<= 1 |old(~pumpRunning~0)|))))) [2021-12-16 00:59:59,139 INFO L854 garLoopResultBuilder]: At program point L701(lines 686 704) the Hoare annotation is: (let ((.cse6 (<= ~waterLevel~0 1)) (.cse3 (= ~pumpRunning~0 |old(~pumpRunning~0)|)) (.cse4 (= ~pumpRunning~0 0))) (let ((.cse0 (and (= |processEnvironment__wrappee__highWaterSensor_isHighWaterLevel_~tmp___0~0#1| 0) (not (= |processEnvironment__wrappee__highWaterSensor_isHighWaterSensorDry_#res#1| 0)) (= |processEnvironment__wrappee__highWaterSensor_isHighWaterLevel_#res#1| 0) .cse6 (not (= 0 |processEnvironment__wrappee__highWaterSensor_isHighWaterLevel_~tmp~6#1|)) .cse3 .cse4)) (.cse1 (not (= |old(~pumpRunning~0)| 0))) (.cse5 (not .cse6)) (.cse2 (not (= ~systemActive~0 1)))) (and (or .cse0 (not (<= ~waterLevel~0 2)) .cse1 .cse2 (and (<= 1 |processEnvironment__wrappee__highWaterSensor_isHighWaterLevel_~tmp___0~0#1|) (<= 1 |processEnvironment__wrappee__highWaterSensor_isHighWaterLevel_#res#1|) .cse3 .cse4)) (or .cse0 .cse5 .cse1 .cse2) (or .cse5 .cse2 (not (<= 1 |old(~pumpRunning~0)|)))))) [2021-12-16 00:59:59,139 INFO L854 garLoopResultBuilder]: At program point L860(lines 851 864) the Hoare annotation is: (let ((.cse10 (= |processEnvironment__wrappee__highWaterSensor_isHighWaterSensorDry_#res#1| 0))) (let ((.cse6 (= 0 ~methaneLevelCritical~0)) (.cse11 (not .cse10)) (.cse12 (<= ~waterLevel~0 1)) (.cse14 (= ~methaneLevelCritical~0 0)) (.cse13 (= ~pumpRunning~0 |old(~pumpRunning~0)|)) (.cse9 (= ~pumpRunning~0 0))) (let ((.cse2 (and .cse11 .cse12 .cse14 .cse13 .cse9)) (.cse3 (not .cse14)) (.cse0 (not .cse12)) (.cse7 (not (<= ~waterLevel~0 2))) (.cse1 (not (= |old(~pumpRunning~0)| 0))) (.cse5 (and .cse11 .cse12 .cse13 (not .cse6) .cse9)) (.cse8 (and .cse9 .cse10)) (.cse4 (not (= ~systemActive~0 1)))) (and (or .cse0 .cse1 .cse2 .cse3 .cse4) (or .cse0 .cse1 .cse5 .cse4 .cse6) (or .cse7 .cse1 .cse8 .cse2 .cse3 .cse4) (or .cse0 .cse4 (not (<= 1 |old(~pumpRunning~0)|))) (or .cse7 .cse1 .cse5 .cse8 .cse4 .cse6))))) [2021-12-16 00:59:59,139 INFO L858 garLoopResultBuilder]: For program point processEnvironment__wrappee__highWaterSensorEXIT(lines 563 587) no Hoare annotation was computed. [2021-12-16 00:59:59,139 INFO L858 garLoopResultBuilder]: For program point L571(lines 571 579) no Hoare annotation was computed. [2021-12-16 00:59:59,139 INFO L858 garLoopResultBuilder]: For program point L567(lines 567 584) no Hoare annotation was computed. [2021-12-16 00:59:59,139 INFO L858 garLoopResultBuilder]: For program point L695(lines 695 699) no Hoare annotation was computed. [2021-12-16 00:59:59,139 INFO L858 garLoopResultBuilder]: For program point L695-2(lines 695 699) no Hoare annotation was computed. [2021-12-16 00:59:59,140 INFO L854 garLoopResultBuilder]: At program point L619(lines 614 621) the Hoare annotation is: (let ((.cse2 (not (<= ~waterLevel~0 1))) (.cse0 (not (= |old(~pumpRunning~0)| 0))) (.cse1 (not (= ~systemActive~0 1)))) (and (or (not (<= ~waterLevel~0 2)) .cse0 (and (<= 1 |processEnvironment__wrappee__highWaterSensor_isHighWaterLevel_~tmp___0~0#1|) (<= 1 |processEnvironment__wrappee__highWaterSensor_~tmp~4#1|) (<= 1 |processEnvironment__wrappee__highWaterSensor_isHighWaterLevel_#res#1|) (<= 1 ~pumpRunning~0)) .cse1) (or .cse2 .cse1 (not (<= 1 |old(~pumpRunning~0)|))) (or .cse2 .cse0 .cse1))) [2021-12-16 00:59:59,140 INFO L854 garLoopResultBuilder]: At program point L582(line 582) the Hoare annotation is: (let ((.cse0 (not (= ~systemActive~0 1)))) (and (or (not (<= ~waterLevel~0 1)) (= ~pumpRunning~0 |old(~pumpRunning~0)|) .cse0 (not (<= 1 |old(~pumpRunning~0)|))) (or (not (<= ~waterLevel~0 2)) (not (= |old(~pumpRunning~0)| 0)) .cse0))) [2021-12-16 00:59:59,140 INFO L858 garLoopResultBuilder]: For program point L582-1(lines 563 587) no Hoare annotation was computed. [2021-12-16 00:59:59,140 INFO L858 garLoopResultBuilder]: For program point waterRiseEXIT(lines 786 797) no Hoare annotation was computed. [2021-12-16 00:59:59,140 INFO L858 garLoopResultBuilder]: For program point L790-1(lines 786 797) no Hoare annotation was computed. [2021-12-16 00:59:59,140 INFO L854 garLoopResultBuilder]: At program point waterRiseENTRY(lines 786 797) the Hoare annotation is: (let ((.cse0 (= ~waterLevel~0 |old(~waterLevel~0)|)) (.cse1 (not (= ~systemActive~0 1)))) (and (or (not (<= |old(~waterLevel~0)| 2)) (not (<= 1 ~pumpRunning~0)) .cse0 .cse1) (or (not (= ~pumpRunning~0 0)) .cse0 .cse1 (not (<= |old(~waterLevel~0)| 1))))) [2021-12-16 00:59:59,143 INFO L732 BasicCegarLoop]: Path program histogram: [1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2021-12-16 00:59:59,143 INFO L179 ceAbstractionStarter]: Computing trace abstraction results [2021-12-16 00:59:59,176 INFO L202 PluginConnector]: Adding new model de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction CFG 16.12 12:59:59 BoogieIcfgContainer [2021-12-16 00:59:59,176 INFO L132 PluginConnector]: ------------------------ END TraceAbstraction---------------------------- [2021-12-16 00:59:59,177 INFO L113 PluginConnector]: ------------------------Witness Printer---------------------------- [2021-12-16 00:59:59,177 INFO L271 PluginConnector]: Initializing Witness Printer... [2021-12-16 00:59:59,177 INFO L275 PluginConnector]: Witness Printer initialized [2021-12-16 00:59:59,178 INFO L185 PluginConnector]: Executing the observer RCFGCatcher from plugin Witness Printer for "de.uni_freiburg.informatik.ultimate.plugins.generator.rcfgbuilder CFG 16.12 12:59:49" (3/4) ... [2021-12-16 00:59:59,180 INFO L137 WitnessPrinter]: Generating witness for correct program [2021-12-16 00:59:59,185 INFO L354 RCFGBacktranslator]: Ignoring RootEdge to procedure processEnvironment__wrappee__base [2021-12-16 00:59:59,185 INFO L354 RCFGBacktranslator]: Ignoring RootEdge to procedure changeMethaneLevel [2021-12-16 00:59:59,185 INFO L354 RCFGBacktranslator]: Ignoring RootEdge to procedure isMethaneLevelCritical [2021-12-16 00:59:59,185 INFO L354 RCFGBacktranslator]: Ignoring RootEdge to procedure timeShift [2021-12-16 00:59:59,186 INFO L354 RCFGBacktranslator]: Ignoring RootEdge to procedure cleanup [2021-12-16 00:59:59,186 INFO L354 RCFGBacktranslator]: Ignoring RootEdge to procedure processEnvironment__wrappee__highWaterSensor [2021-12-16 00:59:59,186 INFO L354 RCFGBacktranslator]: Ignoring RootEdge to procedure waterRise [2021-12-16 00:59:59,192 INFO L910 BoogieBacktranslator]: Reduced CFG by removing 52 nodes and edges [2021-12-16 00:59:59,193 INFO L910 BoogieBacktranslator]: Reduced CFG by removing 22 nodes and edges [2021-12-16 00:59:59,193 INFO L910 BoogieBacktranslator]: Reduced CFG by removing 11 nodes and edges [2021-12-16 00:59:59,193 INFO L910 BoogieBacktranslator]: Reduced CFG by removing 5 nodes and edges [2021-12-16 00:59:59,194 INFO L910 BoogieBacktranslator]: Reduced CFG by removing 2 nodes and edges [2021-12-16 00:59:59,194 INFO L910 BoogieBacktranslator]: Reduced CFG by removing 1 nodes and edges [2021-12-16 00:59:59,195 INFO L910 BoogieBacktranslator]: Reduced CFG by removing 1 nodes and edges [2021-12-16 00:59:59,211 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (((waterLevel == 1 && methaneLevelCritical == 0) && 1 == \result) && systemActive == 1) && pumpRunning == 0 [2021-12-16 00:59:59,211 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: ((((waterLevel == 1 && methaneLevelCritical == 0) && 1 == \result) && 1 == tmp) && systemActive == 1) && pumpRunning == 0 [2021-12-16 00:59:59,212 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (((((splverifierCounter == 0 && 1 == \result) && 1 <= pumpRunning) && 1 == tmp) && waterLevel <= 2) && systemActive == 1) || (((((splverifierCounter == 0 && waterLevel <= 1) && 1 == \result) && 1 == tmp) && systemActive == 1) && pumpRunning == 0) [2021-12-16 00:59:59,212 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (((!(\old(waterLevel) <= 2) || ((waterLevel <= \old(waterLevel) && waterLevel <= 1) && pumpRunning == \old(pumpRunning))) || !(systemActive == 1)) || !(1 <= \old(pumpRunning))) && ((!(\old(waterLevel) <= 2) || !(\old(pumpRunning) == 0)) || !(systemActive == 1)) [2021-12-16 00:59:59,213 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (((((!(\old(waterLevel) <= 2) || (waterLevel == \old(waterLevel) && 1 <= pumpRunning)) || (((waterLevel <= 1 && waterLevel == \old(waterLevel)) && pumpRunning == \old(pumpRunning)) && pumpRunning == 0)) || !(\old(pumpRunning) == 0)) || !(systemActive == 1)) && ((((!(\old(waterLevel) <= 2) || ((waterLevel <= \old(waterLevel) && waterLevel <= 1) && pumpRunning == \old(pumpRunning))) || ((waterLevel <= \old(waterLevel) && waterLevel <= 1) && pumpRunning == 0)) || !(systemActive == 1)) || !(1 <= \old(pumpRunning)))) && ((((((waterLevel <= 1 && waterLevel == \old(waterLevel)) && pumpRunning == \old(pumpRunning)) && pumpRunning == 0) || !(\old(pumpRunning) == 0)) || !(systemActive == 1)) || !(\old(waterLevel) <= 1)) [2021-12-16 00:59:59,213 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (((((((((waterLevel <= 1 && waterLevel == \old(waterLevel)) && pumpRunning == \old(pumpRunning)) && methaneLevelCritical == tmp) || !(\old(pumpRunning) == 0)) || !(systemActive == 1)) || !(\old(waterLevel) <= 1)) && ((((!(\old(waterLevel) <= 2) || ((waterLevel == \old(waterLevel) && 1 <= pumpRunning) && methaneLevelCritical == tmp)) || (((waterLevel <= 1 && waterLevel == \old(waterLevel)) && pumpRunning == \old(pumpRunning)) && methaneLevelCritical == tmp)) || !(\old(pumpRunning) == 0)) || !(systemActive == 1))) && (((((!(\old(waterLevel) <= 2) || (waterLevel == \old(waterLevel) && 1 <= pumpRunning)) || (tmp___0 <= 1 && \result <= 1)) || !(\old(pumpRunning) == 0)) || !(methaneLevelCritical == 0)) || !(systemActive == 1))) && ((((!(\old(waterLevel) <= 2) || (((waterLevel <= \old(waterLevel) && waterLevel <= 1) && methaneLevelCritical == tmp) && pumpRunning == 0)) || (((waterLevel <= \old(waterLevel) && waterLevel <= 1) && pumpRunning == \old(pumpRunning)) && methaneLevelCritical == tmp)) || !(systemActive == 1)) || !(1 <= \old(pumpRunning)))) && ((((!(\old(waterLevel) <= 2) || (tmp___0 <= 1 && \result <= 1)) || !(methaneLevelCritical == 0)) || !(systemActive == 1)) || !(1 <= \old(pumpRunning))) [2021-12-16 00:59:59,214 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (((!(\old(waterLevel) <= 2) || ((waterLevel <= \old(waterLevel) && waterLevel <= 1) && pumpRunning == \old(pumpRunning))) || !(systemActive == 1)) || !(1 <= \old(pumpRunning))) && ((!(\old(waterLevel) <= 2) || !(\old(pumpRunning) == 0)) || !(systemActive == 1)) [2021-12-16 00:59:59,214 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (((((((!(\old(waterLevel) <= 2) || (((((waterLevel <= \old(waterLevel) && waterLevel <= 1) && \result <= 1) && methaneLevelCritical == 0) && methaneLevelCritical == tmp) && pumpRunning == 0)) || (((((waterLevel <= \old(waterLevel) && waterLevel <= 1) && \result <= 1) && methaneLevelCritical == 0) && pumpRunning == \old(pumpRunning)) && methaneLevelCritical == tmp)) || !(systemActive == 1)) || !(1 <= \old(pumpRunning))) && (((!(\old(waterLevel) <= 2) || !(\old(pumpRunning) == 0)) || !(systemActive == 1)) || 0 == methaneLevelCritical)) && (((!(\old(waterLevel) == 1) || \result == 1) || !(\old(pumpRunning) == 0)) || !(systemActive == 1))) && (((!(\old(pumpRunning) == 0) || ((((waterLevel <= 1 && \result <= 1) && waterLevel == \old(waterLevel)) && methaneLevelCritical == tmp) && pumpRunning == 0)) || !(systemActive == 1)) || !(\old(waterLevel) <= 1))) && ((((!(\old(waterLevel) <= 2) || ((waterLevel == \old(waterLevel) && 1 <= pumpRunning) && methaneLevelCritical == tmp)) || !(\old(pumpRunning) == 0)) || ((((waterLevel <= 1 && \result <= 1) && waterLevel == \old(waterLevel)) && methaneLevelCritical == tmp) && pumpRunning == 0)) || !(systemActive == 1)) [2021-12-16 00:59:59,214 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (((!(\old(waterLevel) <= 2) || ((waterLevel <= \old(waterLevel) && waterLevel <= 1) && pumpRunning == 0)) || !(systemActive == 1)) || !(1 <= \old(pumpRunning))) && ((!(\old(waterLevel) <= 2) || !(\old(pumpRunning) == 0)) || !(systemActive == 1)) [2021-12-16 00:59:59,214 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (((((((!(waterLevel <= 1) || !(\old(pumpRunning) == 0)) || ((((!(\result == 0) && waterLevel <= 1) && methaneLevelCritical == 0) && pumpRunning == \old(pumpRunning)) && pumpRunning == 0)) || !(methaneLevelCritical == 0)) || !(systemActive == 1)) && ((((!(waterLevel <= 1) || !(\old(pumpRunning) == 0)) || ((((!(\result == 0) && waterLevel <= 1) && pumpRunning == \old(pumpRunning)) && !(0 == methaneLevelCritical)) && pumpRunning == 0)) || !(systemActive == 1)) || 0 == methaneLevelCritical)) && (((((!(waterLevel <= 2) || !(\old(pumpRunning) == 0)) || (pumpRunning == 0 && \result == 0)) || ((((!(\result == 0) && waterLevel <= 1) && methaneLevelCritical == 0) && pumpRunning == \old(pumpRunning)) && pumpRunning == 0)) || !(methaneLevelCritical == 0)) || !(systemActive == 1))) && ((!(waterLevel <= 1) || !(systemActive == 1)) || !(1 <= \old(pumpRunning)))) && (((((!(waterLevel <= 2) || !(\old(pumpRunning) == 0)) || ((((!(\result == 0) && waterLevel <= 1) && pumpRunning == \old(pumpRunning)) && !(0 == methaneLevelCritical)) && pumpRunning == 0)) || (pumpRunning == 0 && \result == 0)) || !(systemActive == 1)) || 0 == methaneLevelCritical) [2021-12-16 00:59:59,215 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: ((((!(\old(waterLevel) <= 2) || !(systemActive == 1)) || !(1 <= \old(pumpRunning))) && ((!(\old(pumpRunning) == 0) || !(systemActive == 1)) || !(\old(waterLevel) <= 1))) && (((!(\old(waterLevel) <= 2) || !(\old(pumpRunning) == 0)) || !(systemActive == 1)) || 0 == methaneLevelCritical)) && (((!(\old(waterLevel) <= 2) || !(\old(pumpRunning) == 0)) || (((waterLevel == \old(waterLevel) && 1 <= pumpRunning) && !(0 == \result)) && methaneLevelCritical == tmp)) || !(systemActive == 1)) [2021-12-16 00:59:59,215 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (((((((((((tmp___0 == 0 && !(\result == 0)) && \result == 0) && waterLevel <= 1) && !(0 == tmp)) && pumpRunning == \old(pumpRunning)) && pumpRunning == 0) || !(waterLevel <= 2)) || !(\old(pumpRunning) == 0)) || !(systemActive == 1)) || (((1 <= tmp___0 && 1 <= \result) && pumpRunning == \old(pumpRunning)) && pumpRunning == 0)) && (((((((((tmp___0 == 0 && !(\result == 0)) && \result == 0) && waterLevel <= 1) && !(0 == tmp)) && pumpRunning == \old(pumpRunning)) && pumpRunning == 0) || !(waterLevel <= 1)) || !(\old(pumpRunning) == 0)) || !(systemActive == 1))) && ((!(waterLevel <= 1) || !(systemActive == 1)) || !(1 <= \old(pumpRunning))) [2021-12-16 00:59:59,215 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: ((((!(waterLevel <= 2) || !(\old(pumpRunning) == 0)) || (((1 <= tmp___0 && 1 <= tmp) && 1 <= \result) && 1 <= pumpRunning)) || !(systemActive == 1)) && ((!(waterLevel <= 1) || !(systemActive == 1)) || !(1 <= \old(pumpRunning)))) && ((!(waterLevel <= 1) || !(\old(pumpRunning) == 0)) || !(systemActive == 1)) [2021-12-16 00:59:59,215 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: ((!(\old(waterLevel) <= 2) || !(systemActive == 1)) || !(1 <= \old(pumpRunning))) && ((!(\old(waterLevel) <= 2) || !(\old(pumpRunning) == 0)) || !(systemActive == 1)) [2021-12-16 00:59:59,239 INFO L141 WitnessManager]: Wrote witness to /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/witness.graphml [2021-12-16 00:59:59,239 INFO L132 PluginConnector]: ------------------------ END Witness Printer---------------------------- [2021-12-16 00:59:59,240 INFO L158 Benchmark]: Toolchain (without parser) took 10351.64ms. Allocated memory was 100.7MB in the beginning and 146.8MB in the end (delta: 46.1MB). Free memory was 71.3MB in the beginning and 50.6MB in the end (delta: 20.7MB). Peak memory consumption was 65.9MB. Max. memory is 16.1GB. [2021-12-16 00:59:59,240 INFO L158 Benchmark]: CDTParser took 0.22ms. Allocated memory is still 83.9MB. Free memory was 41.0MB in the beginning and 41.0MB in the end (delta: 42.1kB). There was no memory consumed. Max. memory is 16.1GB. [2021-12-16 00:59:59,241 INFO L158 Benchmark]: CACSL2BoogieTranslator took 438.23ms. Allocated memory is still 100.7MB. Free memory was 71.3MB in the beginning and 69.5MB in the end (delta: 1.9MB). Peak memory consumption was 8.4MB. Max. memory is 16.1GB. [2021-12-16 00:59:59,241 INFO L158 Benchmark]: Boogie Procedure Inliner took 59.08ms. Allocated memory is still 100.7MB. Free memory was 69.5MB in the beginning and 66.9MB in the end (delta: 2.6MB). Peak memory consumption was 2.1MB. Max. memory is 16.1GB. [2021-12-16 00:59:59,241 INFO L158 Benchmark]: Boogie Preprocessor took 28.03ms. Allocated memory is still 100.7MB. Free memory was 66.9MB in the beginning and 65.4MB in the end (delta: 1.5MB). Peak memory consumption was 2.1MB. Max. memory is 16.1GB. [2021-12-16 00:59:59,242 INFO L158 Benchmark]: RCFGBuilder took 426.61ms. Allocated memory is still 100.7MB. Free memory was 65.4MB in the beginning and 49.8MB in the end (delta: 15.6MB). Peak memory consumption was 14.7MB. Max. memory is 16.1GB. [2021-12-16 00:59:59,242 INFO L158 Benchmark]: TraceAbstraction took 9329.89ms. Allocated memory was 100.7MB in the beginning and 146.8MB in the end (delta: 46.1MB). Free memory was 49.2MB in the beginning and 56.9MB in the end (delta: -7.7MB). Peak memory consumption was 61.5MB. Max. memory is 16.1GB. [2021-12-16 00:59:59,242 INFO L158 Benchmark]: Witness Printer took 62.96ms. Allocated memory is still 146.8MB. Free memory was 56.9MB in the beginning and 50.6MB in the end (delta: 6.3MB). Peak memory consumption was 6.3MB. Max. memory is 16.1GB. [2021-12-16 00:59:59,244 INFO L339 ainManager$Toolchain]: ####################### End [Toolchain 1] ####################### --- Results --- * Results from de.uni_freiburg.informatik.ultimate.core: - StatisticsResult: Toolchain Benchmarks Benchmark results are: * CDTParser took 0.22ms. Allocated memory is still 83.9MB. Free memory was 41.0MB in the beginning and 41.0MB in the end (delta: 42.1kB). There was no memory consumed. Max. memory is 16.1GB. * CACSL2BoogieTranslator took 438.23ms. Allocated memory is still 100.7MB. Free memory was 71.3MB in the beginning and 69.5MB in the end (delta: 1.9MB). Peak memory consumption was 8.4MB. Max. memory is 16.1GB. * Boogie Procedure Inliner took 59.08ms. Allocated memory is still 100.7MB. Free memory was 69.5MB in the beginning and 66.9MB in the end (delta: 2.6MB). Peak memory consumption was 2.1MB. Max. memory is 16.1GB. * Boogie Preprocessor took 28.03ms. Allocated memory is still 100.7MB. Free memory was 66.9MB in the beginning and 65.4MB in the end (delta: 1.5MB). Peak memory consumption was 2.1MB. Max. memory is 16.1GB. * RCFGBuilder took 426.61ms. Allocated memory is still 100.7MB. Free memory was 65.4MB in the beginning and 49.8MB in the end (delta: 15.6MB). Peak memory consumption was 14.7MB. Max. memory is 16.1GB. * TraceAbstraction took 9329.89ms. Allocated memory was 100.7MB in the beginning and 146.8MB in the end (delta: 46.1MB). Free memory was 49.2MB in the beginning and 56.9MB in the end (delta: -7.7MB). Peak memory consumption was 61.5MB. Max. memory is 16.1GB. * Witness Printer took 62.96ms. Allocated memory is still 146.8MB. Free memory was 56.9MB in the beginning and 50.6MB in the end (delta: 6.3MB). Peak memory consumption was 6.3MB. Max. memory is 16.1GB. * Results from de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction: - StatisticsResult: ErrorAutomatonStatistics NumberErrorTraces: 0, NumberStatementsAllTraces: 0, NumberRelevantStatements: 0, 0.0s ErrorAutomatonConstructionTimeTotal, 0.0s FaulLocalizationTime, NumberStatementsFirstTrace: -1, TraceLengthAvg: 0, 0.0s ErrorAutomatonConstructionTimeAvg, 0.0s ErrorAutomatonDifferenceTimeAvg, 0.0s ErrorAutomatonDifferenceTimeTotal, NumberOfNoEnhancement: 0, NumberOfFiniteEnhancement: 0, NumberOfInfiniteEnhancement: 0 - PositiveResult [Line: 870]: call to reach_error is unreachable For all program executions holds that call to reach_error is unreachable at this location - StatisticsResult: Ultimate Automizer benchmark data CFG has 8 procedures, 87 locations, 1 error locations. Started 1 CEGAR loops. OverallTime: 9.2s, OverallIterations: 12, TraceHistogramMax: 3, PathProgramHistogramMax: 1, EmptinessCheckTime: 0.0s, AutomataDifference: 3.3s, DeadEndRemovalTime: 0.0s, HoareAnnotationTime: 3.5s, InitialAbstractionConstructionTime: 0.0s, PartialOrderReductionTime: 0.0s, HoareTripleCheckerStatistics: 0 mSolverCounterUnknown, 2569 SdHoareTripleChecker+Valid, 1.9s IncrementalHoareTripleChecker+Time, 0 mSdLazyCounter, 2537 mSDsluCounter, 4243 SdHoareTripleChecker+Invalid, 1.5s Time, 0 mProtectedAction, 0 SdHoareTripleChecker+Unchecked, 0 IncrementalHoareTripleChecker+Unchecked, 3089 mSDsCounter, 958 IncrementalHoareTripleChecker+Valid, 0 mProtectedPredicate, 2650 IncrementalHoareTripleChecker+Invalid, 3608 SdHoareTripleChecker+Unknown, 0 mSolverCounterNotChecked, 958 mSolverCounterUnsat, 1154 mSDtfsCounter, 2650 mSolverCounterSat, 0.0s SdHoareTripleChecker+Time, 0 IncrementalHoareTripleChecker+Unknown, PredicateUnifierStatistics: 0 DeclaredPredicates, 425 GetRequests, 254 SyntacticMatches, 2 SemanticMatches, 169 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 1401 ImplicationChecksByTransitivity, 1.3s Time, 0.0s BasicInterpolantAutomatonTime, BiggestAbstraction: size=303occurred in iteration=11, InterpolantAutomatonStates: 153, traceCheckStatistics: No data available, InterpolantConsolidationStatistics: No data available, PathInvariantsStatistics: No data available, 0/0 InterpolantCoveringCapability, TotalInterpolationStatistics: No data available, 0.0s DumpTime, AutomataMinimizationStatistics: 0.2s AutomataMinimizationTime, 12 MinimizatonAttempts, 182 StatesRemovedByMinimization, 8 NontrivialMinimizations, HoareAnnotationStatistics: 0.0s HoareAnnotationTime, 40 LocationsWithAnnotation, 1075 PreInvPairs, 1325 NumberOfFragments, 1634 HoareAnnotationTreeSize, 1075 FomulaSimplifications, 198 FormulaSimplificationTreeSizeReduction, 0.3s HoareSimplificationTime, 40 FomulaSimplificationsInter, 22491 FormulaSimplificationTreeSizeReductionInter, 3.2s HoareSimplificationTimeInter, RefinementEngineStatistics: TRACE_CHECK: 0.0s SsaConstructionTime, 0.2s SatisfiabilityAnalysisTime, 1.4s InterpolantComputationTime, 609 NumberOfCodeBlocks, 609 NumberOfCodeBlocksAsserted, 13 NumberOfCheckSat, 676 ConstructedInterpolants, 0 QuantifiedInterpolants, 1354 SizeOfPredicates, 4 NumberOfNonLiveVariables, 433 ConjunctsInSsa, 13 ConjunctsInUnsatCore, 14 InterpolantComputations, 11 PerfectInterpolantSequences, 58/78 InterpolantCoveringCapability, INVARIANT_SYNTHESIS: No data available, INTERPOLANT_CONSOLIDATION: No data available, ABSTRACT_INTERPRETATION: No data available, PDR: No data available, ACCELERATED_INTERPOLATION: No data available, SIFA: No data available, ReuseStatistics: No data available - AllSpecificationsHoldResult: All specifications hold 1 specifications checked. All of them hold - InvariantResult [Line: 875]: Loop Invariant Derived loop invariant: (((((((((waterLevel <= 1 && waterLevel == \old(waterLevel)) && pumpRunning == \old(pumpRunning)) && methaneLevelCritical == tmp) || !(\old(pumpRunning) == 0)) || !(systemActive == 1)) || !(\old(waterLevel) <= 1)) && ((((!(\old(waterLevel) <= 2) || ((waterLevel == \old(waterLevel) && 1 <= pumpRunning) && methaneLevelCritical == tmp)) || (((waterLevel <= 1 && waterLevel == \old(waterLevel)) && pumpRunning == \old(pumpRunning)) && methaneLevelCritical == tmp)) || !(\old(pumpRunning) == 0)) || !(systemActive == 1))) && (((((!(\old(waterLevel) <= 2) || (waterLevel == \old(waterLevel) && 1 <= pumpRunning)) || (tmp___0 <= 1 && \result <= 1)) || !(\old(pumpRunning) == 0)) || !(methaneLevelCritical == 0)) || !(systemActive == 1))) && ((((!(\old(waterLevel) <= 2) || (((waterLevel <= \old(waterLevel) && waterLevel <= 1) && methaneLevelCritical == tmp) && pumpRunning == 0)) || (((waterLevel <= \old(waterLevel) && waterLevel <= 1) && pumpRunning == \old(pumpRunning)) && methaneLevelCritical == tmp)) || !(systemActive == 1)) || !(1 <= \old(pumpRunning)))) && ((((!(\old(waterLevel) <= 2) || (tmp___0 <= 1 && \result <= 1)) || !(methaneLevelCritical == 0)) || !(systemActive == 1)) || !(1 <= \old(pumpRunning))) - InvariantResult [Line: 641]: Loop Invariant Derived loop invariant: ((((!(\old(waterLevel) <= 2) || !(systemActive == 1)) || !(1 <= \old(pumpRunning))) && ((!(\old(pumpRunning) == 0) || !(systemActive == 1)) || !(\old(waterLevel) <= 1))) && (((!(\old(waterLevel) <= 2) || !(\old(pumpRunning) == 0)) || !(systemActive == 1)) || 0 == methaneLevelCritical)) && (((!(\old(waterLevel) <= 2) || !(\old(pumpRunning) == 0)) || (((waterLevel == \old(waterLevel) && 1 <= pumpRunning) && !(0 == \result)) && methaneLevelCritical == tmp)) || !(systemActive == 1)) - InvariantResult [Line: 920]: Loop Invariant Derived loop invariant: ((waterLevel == 1 && methaneLevelCritical == 0) && systemActive == 1) && pumpRunning == 0 - InvariantResult [Line: 52]: Loop Invariant Derived loop invariant: 1 - InvariantResult [Line: 716]: Loop Invariant Derived loop invariant: (((((splverifierCounter == 0 && 1 == \result) && 1 <= pumpRunning) && 1 == tmp) && waterLevel <= 2) && systemActive == 1) || (((((splverifierCounter == 0 && waterLevel <= 1) && 1 == \result) && 1 == tmp) && systemActive == 1) && pumpRunning == 0) - InvariantResult [Line: 706]: Loop Invariant Derived loop invariant: 1 - InvariantResult [Line: 630]: Loop Invariant Derived loop invariant: (((!(\old(waterLevel) <= 2) || ((waterLevel <= \old(waterLevel) && waterLevel <= 1) && pumpRunning == \old(pumpRunning))) || !(systemActive == 1)) || !(1 <= \old(pumpRunning))) && ((!(\old(waterLevel) <= 2) || !(\old(pumpRunning) == 0)) || !(systemActive == 1)) - InvariantResult [Line: 614]: Loop Invariant Derived loop invariant: ((((!(waterLevel <= 2) || !(\old(pumpRunning) == 0)) || (((1 <= tmp___0 && 1 <= tmp) && 1 <= \result) && 1 <= pumpRunning)) || !(systemActive == 1)) && ((!(waterLevel <= 1) || !(systemActive == 1)) || !(1 <= \old(pumpRunning)))) && ((!(waterLevel <= 1) || !(\old(pumpRunning) == 0)) || !(systemActive == 1)) - InvariantResult [Line: 851]: Loop Invariant Derived loop invariant: (((((((!(waterLevel <= 1) || !(\old(pumpRunning) == 0)) || ((((!(\result == 0) && waterLevel <= 1) && methaneLevelCritical == 0) && pumpRunning == \old(pumpRunning)) && pumpRunning == 0)) || !(methaneLevelCritical == 0)) || !(systemActive == 1)) && ((((!(waterLevel <= 1) || !(\old(pumpRunning) == 0)) || ((((!(\result == 0) && waterLevel <= 1) && pumpRunning == \old(pumpRunning)) && !(0 == methaneLevelCritical)) && pumpRunning == 0)) || !(systemActive == 1)) || 0 == methaneLevelCritical)) && (((((!(waterLevel <= 2) || !(\old(pumpRunning) == 0)) || (pumpRunning == 0 && \result == 0)) || ((((!(\result == 0) && waterLevel <= 1) && methaneLevelCritical == 0) && pumpRunning == \old(pumpRunning)) && pumpRunning == 0)) || !(methaneLevelCritical == 0)) || !(systemActive == 1))) && ((!(waterLevel <= 1) || !(systemActive == 1)) || !(1 <= \old(pumpRunning)))) && (((((!(waterLevel <= 2) || !(\old(pumpRunning) == 0)) || ((((!(\result == 0) && waterLevel <= 1) && pumpRunning == \old(pumpRunning)) && !(0 == methaneLevelCritical)) && pumpRunning == 0)) || (pumpRunning == 0 && \result == 0)) || !(systemActive == 1)) || 0 == methaneLevelCritical) - InvariantResult [Line: 715]: Loop Invariant Derived loop invariant: 0 - InvariantResult [Line: 927]: Loop Invariant Derived loop invariant: ((waterLevel == 1 && methaneLevelCritical == 0) && systemActive == 1) && pumpRunning == 0 - InvariantResult [Line: 842]: Loop Invariant Derived loop invariant: (((((((!(\old(waterLevel) <= 2) || (((((waterLevel <= \old(waterLevel) && waterLevel <= 1) && \result <= 1) && methaneLevelCritical == 0) && methaneLevelCritical == tmp) && pumpRunning == 0)) || (((((waterLevel <= \old(waterLevel) && waterLevel <= 1) && \result <= 1) && methaneLevelCritical == 0) && pumpRunning == \old(pumpRunning)) && methaneLevelCritical == tmp)) || !(systemActive == 1)) || !(1 <= \old(pumpRunning))) && (((!(\old(waterLevel) <= 2) || !(\old(pumpRunning) == 0)) || !(systemActive == 1)) || 0 == methaneLevelCritical)) && (((!(\old(waterLevel) == 1) || \result == 1) || !(\old(pumpRunning) == 0)) || !(systemActive == 1))) && (((!(\old(pumpRunning) == 0) || ((((waterLevel <= 1 && \result <= 1) && waterLevel == \old(waterLevel)) && methaneLevelCritical == tmp) && pumpRunning == 0)) || !(systemActive == 1)) || !(\old(waterLevel) <= 1))) && ((((!(\old(waterLevel) <= 2) || ((waterLevel == \old(waterLevel) && 1 <= pumpRunning) && methaneLevelCritical == tmp)) || !(\old(pumpRunning) == 0)) || ((((waterLevel <= 1 && \result <= 1) && waterLevel == \old(waterLevel)) && methaneLevelCritical == tmp) && pumpRunning == 0)) || !(systemActive == 1)) - InvariantResult [Line: 774]: Loop Invariant Derived loop invariant: (((!(\old(waterLevel) <= 2) || ((waterLevel <= \old(waterLevel) && waterLevel <= 1) && pumpRunning == \old(pumpRunning))) || !(systemActive == 1)) || !(1 <= \old(pumpRunning))) && ((!(\old(waterLevel) <= 2) || !(\old(pumpRunning) == 0)) || !(systemActive == 1)) - InvariantResult [Line: 130]: Loop Invariant Derived loop invariant: 1 - InvariantResult [Line: 622]: Loop Invariant Derived loop invariant: (((!(\old(waterLevel) <= 2) || ((waterLevel <= \old(waterLevel) && waterLevel <= 1) && pumpRunning == 0)) || !(systemActive == 1)) || !(1 <= \old(pumpRunning))) && ((!(\old(waterLevel) <= 2) || !(\old(pumpRunning) == 0)) || !(systemActive == 1)) - InvariantResult [Line: 866]: Loop Invariant Derived loop invariant: ((!(\old(waterLevel) <= 2) || !(systemActive == 1)) || !(1 <= \old(pumpRunning))) && ((!(\old(waterLevel) <= 2) || !(\old(pumpRunning) == 0)) || !(systemActive == 1)) - InvariantResult [Line: 109]: Loop Invariant Derived loop invariant: ((((waterLevel == 1 && methaneLevelCritical == 0) && 1 == \result) && 1 == tmp) && systemActive == 1) && pumpRunning == 0 - InvariantResult [Line: 589]: Loop Invariant Derived loop invariant: (((((!(\old(waterLevel) <= 2) || (waterLevel == \old(waterLevel) && 1 <= pumpRunning)) || (((waterLevel <= 1 && waterLevel == \old(waterLevel)) && pumpRunning == \old(pumpRunning)) && pumpRunning == 0)) || !(\old(pumpRunning) == 0)) || !(systemActive == 1)) && ((((!(\old(waterLevel) <= 2) || ((waterLevel <= \old(waterLevel) && waterLevel <= 1) && pumpRunning == \old(pumpRunning))) || ((waterLevel <= \old(waterLevel) && waterLevel <= 1) && pumpRunning == 0)) || !(systemActive == 1)) || !(1 <= \old(pumpRunning)))) && ((((((waterLevel <= 1 && waterLevel == \old(waterLevel)) && pumpRunning == \old(pumpRunning)) && pumpRunning == 0) || !(\old(pumpRunning) == 0)) || !(systemActive == 1)) || !(\old(waterLevel) <= 1)) - InvariantResult [Line: 686]: Loop Invariant Derived loop invariant: (((((((((((tmp___0 == 0 && !(\result == 0)) && \result == 0) && waterLevel <= 1) && !(0 == tmp)) && pumpRunning == \old(pumpRunning)) && pumpRunning == 0) || !(waterLevel <= 2)) || !(\old(pumpRunning) == 0)) || !(systemActive == 1)) || (((1 <= tmp___0 && 1 <= \result) && pumpRunning == \old(pumpRunning)) && pumpRunning == 0)) && (((((((((tmp___0 == 0 && !(\result == 0)) && \result == 0) && waterLevel <= 1) && !(0 == tmp)) && pumpRunning == \old(pumpRunning)) && pumpRunning == 0) || !(waterLevel <= 1)) || !(\old(pumpRunning) == 0)) || !(systemActive == 1))) && ((!(waterLevel <= 1) || !(systemActive == 1)) || !(1 <= \old(pumpRunning))) - InvariantResult [Line: 62]: Loop Invariant Derived loop invariant: 1 - InvariantResult [Line: 117]: Loop Invariant Derived loop invariant: 1 - InvariantResult [Line: 934]: Loop Invariant Derived loop invariant: (((waterLevel == 1 && methaneLevelCritical == 0) && 1 == \result) && systemActive == 1) && pumpRunning == 0 RESULT: Ultimate proved your program to be correct! [2021-12-16 00:59:59,289 INFO L540 MonitoredProcess]: [MP /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in -t:2000 (1)] Forceful destruction successful, exit code 0 Received shutdown request... --- End real Ultimate output --- Execution finished normally Writing output log to file Ultimate.log Result: TRUE