./Ultimate.py --spec ../sv-benchmarks/c/properties/unreach-call.prp --file ../sv-benchmarks/c/product-lines/minepump_spec3_product54.cil.c --full-output --architecture 32bit -------------------------------------------------------------------------------- Checking for ERROR reachability Using default analysis Version c3fed411 Calling Ultimate with: /usr/bin/java -Dosgi.configuration.area=/storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/data/config -Xmx15G -Xms4m -jar /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/plugins/org.eclipse.equinox.launcher_1.5.800.v20200727-1323.jar -data @noDefault -ultimatedata /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/data -tc /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/config/AutomizerReach.xml -i ../sv-benchmarks/c/product-lines/minepump_spec3_product54.cil.c -s /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/config/svcomp-Reach-32bit-Automizer_Default.epf --cacsl2boogietranslator.entry.function main --witnessprinter.witness.directory /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux --witnessprinter.witness.filename witness.graphml --witnessprinter.write.witness.besides.input.file false --witnessprinter.graph.data.specification CHECK( init(main()), LTL(G ! call(reach_error())) ) --witnessprinter.graph.data.producer Automizer --witnessprinter.graph.data.architecture 32bit --witnessprinter.graph.data.programhash cbcb1e9315abec7fabb6a689d6a1c811fb94154c71589df191460c14d014c3cb --- Real Ultimate output --- This is Ultimate 0.2.2-tmp.no-commuhash-c3fed41 [2021-12-16 00:59:58,106 INFO L177 SettingsManager]: Resetting all preferences to default values... [2021-12-16 00:59:58,131 INFO L181 SettingsManager]: Resetting UltimateCore preferences to default values [2021-12-16 00:59:58,162 INFO L184 SettingsManager]: Ultimate Commandline Interface provides no preferences, ignoring... [2021-12-16 00:59:58,163 INFO L181 SettingsManager]: Resetting Boogie Preprocessor preferences to default values [2021-12-16 00:59:58,166 INFO L181 SettingsManager]: Resetting Boogie Procedure Inliner preferences to default values [2021-12-16 00:59:58,168 INFO L181 SettingsManager]: Resetting Abstract Interpretation preferences to default values [2021-12-16 00:59:58,173 INFO L181 SettingsManager]: Resetting LassoRanker preferences to default values [2021-12-16 00:59:58,174 INFO L181 SettingsManager]: Resetting Reaching Definitions preferences to default values [2021-12-16 00:59:58,179 INFO L181 SettingsManager]: Resetting SyntaxChecker preferences to default values [2021-12-16 00:59:58,180 INFO L181 SettingsManager]: Resetting Sifa preferences to default values [2021-12-16 00:59:58,181 INFO L184 SettingsManager]: Büchi Program Product provides no preferences, ignoring... [2021-12-16 00:59:58,181 INFO L181 SettingsManager]: Resetting LTL2Aut preferences to default values [2021-12-16 00:59:58,183 INFO L181 SettingsManager]: Resetting PEA to Boogie preferences to default values [2021-12-16 00:59:58,184 INFO L181 SettingsManager]: Resetting BlockEncodingV2 preferences to default values [2021-12-16 00:59:58,188 INFO L181 SettingsManager]: Resetting ChcToBoogie preferences to default values [2021-12-16 00:59:58,189 INFO L181 SettingsManager]: Resetting AutomataScriptInterpreter preferences to default values [2021-12-16 00:59:58,190 INFO L181 SettingsManager]: Resetting BuchiAutomizer preferences to default values [2021-12-16 00:59:58,193 INFO L181 SettingsManager]: Resetting CACSL2BoogieTranslator preferences to default values [2021-12-16 00:59:58,196 INFO L181 SettingsManager]: Resetting CodeCheck preferences to default values [2021-12-16 00:59:58,197 INFO L181 SettingsManager]: Resetting InvariantSynthesis preferences to default values [2021-12-16 00:59:58,198 INFO L181 SettingsManager]: Resetting RCFGBuilder preferences to default values [2021-12-16 00:59:58,200 INFO L181 SettingsManager]: Resetting Referee preferences to default values [2021-12-16 00:59:58,200 INFO L181 SettingsManager]: Resetting TraceAbstraction preferences to default values [2021-12-16 00:59:58,203 INFO L184 SettingsManager]: TraceAbstractionConcurrent provides no preferences, ignoring... [2021-12-16 00:59:58,203 INFO L184 SettingsManager]: TraceAbstractionWithAFAs provides no preferences, ignoring... [2021-12-16 00:59:58,204 INFO L181 SettingsManager]: Resetting TreeAutomizer preferences to default values [2021-12-16 00:59:58,205 INFO L181 SettingsManager]: Resetting IcfgToChc preferences to default values [2021-12-16 00:59:58,205 INFO L181 SettingsManager]: Resetting IcfgTransformer preferences to default values [2021-12-16 00:59:58,206 INFO L184 SettingsManager]: ReqToTest provides no preferences, ignoring... [2021-12-16 00:59:58,206 INFO L181 SettingsManager]: Resetting Boogie Printer preferences to default values [2021-12-16 00:59:58,207 INFO L181 SettingsManager]: Resetting ChcSmtPrinter preferences to default values [2021-12-16 00:59:58,208 INFO L181 SettingsManager]: Resetting ReqPrinter preferences to default values [2021-12-16 00:59:58,209 INFO L181 SettingsManager]: Resetting Witness Printer preferences to default values [2021-12-16 00:59:58,210 INFO L184 SettingsManager]: Boogie PL CUP Parser provides no preferences, ignoring... [2021-12-16 00:59:58,210 INFO L181 SettingsManager]: Resetting CDTParser preferences to default values [2021-12-16 00:59:58,210 INFO L184 SettingsManager]: AutomataScriptParser provides no preferences, ignoring... [2021-12-16 00:59:58,210 INFO L184 SettingsManager]: ReqParser provides no preferences, ignoring... [2021-12-16 00:59:58,211 INFO L181 SettingsManager]: Resetting SmtParser preferences to default values [2021-12-16 00:59:58,211 INFO L181 SettingsManager]: Resetting Witness Parser preferences to default values [2021-12-16 00:59:58,212 INFO L188 SettingsManager]: Finished resetting all preferences to default values... [2021-12-16 00:59:58,213 INFO L101 SettingsManager]: Beginning loading settings from /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/config/svcomp-Reach-32bit-Automizer_Default.epf [2021-12-16 00:59:58,239 INFO L113 SettingsManager]: Loading preferences was successful [2021-12-16 00:59:58,239 INFO L115 SettingsManager]: Preferences different from defaults after loading the file: [2021-12-16 00:59:58,239 INFO L136 SettingsManager]: Preferences of UltimateCore differ from their defaults: [2021-12-16 00:59:58,239 INFO L138 SettingsManager]: * Log level for class=de.uni_freiburg.informatik.ultimate.lib.smtlibutils.quantifier.QuantifierPusher=ERROR; [2021-12-16 00:59:58,240 INFO L136 SettingsManager]: Preferences of Boogie Procedure Inliner differ from their defaults: [2021-12-16 00:59:58,240 INFO L138 SettingsManager]: * Ignore calls to procedures called more than once=ONLY_FOR_SEQUENTIAL_PROGRAMS [2021-12-16 00:59:58,240 INFO L136 SettingsManager]: Preferences of BlockEncodingV2 differ from their defaults: [2021-12-16 00:59:58,240 INFO L138 SettingsManager]: * Create parallel compositions if possible=false [2021-12-16 00:59:58,240 INFO L138 SettingsManager]: * Use SBE=true [2021-12-16 00:59:58,240 INFO L136 SettingsManager]: Preferences of CACSL2BoogieTranslator differ from their defaults: [2021-12-16 00:59:58,240 INFO L138 SettingsManager]: * sizeof long=4 [2021-12-16 00:59:58,240 INFO L138 SettingsManager]: * Overapproximate operations on floating types=true [2021-12-16 00:59:58,241 INFO L138 SettingsManager]: * sizeof POINTER=4 [2021-12-16 00:59:58,241 INFO L138 SettingsManager]: * Check division by zero=IGNORE [2021-12-16 00:59:58,241 INFO L138 SettingsManager]: * Pointer to allocated memory at dereference=IGNORE [2021-12-16 00:59:58,241 INFO L138 SettingsManager]: * If two pointers are subtracted or compared they have the same base address=IGNORE [2021-12-16 00:59:58,241 INFO L138 SettingsManager]: * Check array bounds for arrays that are off heap=IGNORE [2021-12-16 00:59:58,241 INFO L138 SettingsManager]: * sizeof long double=12 [2021-12-16 00:59:58,241 INFO L138 SettingsManager]: * Check if freed pointer was valid=false [2021-12-16 00:59:58,241 INFO L138 SettingsManager]: * Use constant arrays=true [2021-12-16 00:59:58,241 INFO L138 SettingsManager]: * Pointer base address is valid at dereference=IGNORE [2021-12-16 00:59:58,241 INFO L136 SettingsManager]: Preferences of RCFGBuilder differ from their defaults: [2021-12-16 00:59:58,241 INFO L138 SettingsManager]: * Size of a code block=SequenceOfStatements [2021-12-16 00:59:58,241 INFO L138 SettingsManager]: * SMT solver=External_DefaultMode [2021-12-16 00:59:58,242 INFO L138 SettingsManager]: * Command for external solver=z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in -t:2000 [2021-12-16 00:59:58,242 INFO L136 SettingsManager]: Preferences of TraceAbstraction differ from their defaults: [2021-12-16 00:59:58,242 INFO L138 SettingsManager]: * Compute Interpolants along a Counterexample=FPandBP [2021-12-16 00:59:58,242 INFO L138 SettingsManager]: * Positions where we compute the Hoare Annotation=LoopsAndPotentialCycles [2021-12-16 00:59:58,242 INFO L138 SettingsManager]: * Trace refinement strategy=CAMEL [2021-12-16 00:59:58,242 INFO L138 SettingsManager]: * Command for external solver=z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in [2021-12-16 00:59:58,242 INFO L138 SettingsManager]: * Large block encoding in concurrent analysis=OFF [2021-12-16 00:59:58,242 INFO L138 SettingsManager]: * Automaton type used in concurrency analysis=PETRI_NET [2021-12-16 00:59:58,242 INFO L138 SettingsManager]: * Compute Hoare Annotation of negated interpolant automaton, abstraction and CFG=true [2021-12-16 00:59:58,242 INFO L138 SettingsManager]: * Trace refinement exception blacklist=NONE [2021-12-16 00:59:58,242 INFO L138 SettingsManager]: * SMT solver=External_ModelsAndUnsatCoreMode WARNING: An illegal reflective access operation has occurred WARNING: Illegal reflective access by com.sun.xml.bind.v2.runtime.reflect.opt.Injector$1 (file:/storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/plugins/com.sun.xml.bind_2.2.0.v201505121915.jar) to method java.lang.ClassLoader.defineClass(java.lang.String,byte[],int,int) WARNING: Please consider reporting this to the maintainers of com.sun.xml.bind.v2.runtime.reflect.opt.Injector$1 WARNING: Use --illegal-access=warn to enable warnings of further illegal reflective access operations WARNING: All illegal access operations will be denied in a future release Applying setting for plugin de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator: Entry function -> main Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Witness directory -> /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Witness filename -> witness.graphml Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Write witness besides input file -> false Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Graph data specification -> CHECK( init(main()), LTL(G ! call(reach_error())) ) Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Graph data producer -> Automizer Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Graph data architecture -> 32bit Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Graph data programhash -> cbcb1e9315abec7fabb6a689d6a1c811fb94154c71589df191460c14d014c3cb [2021-12-16 00:59:58,420 INFO L75 nceAwareModelManager]: Repository-Root is: /tmp [2021-12-16 00:59:58,441 INFO L261 ainManager$Toolchain]: [Toolchain 1]: Applicable parser(s) successfully (re)initialized [2021-12-16 00:59:58,443 INFO L217 ainManager$Toolchain]: [Toolchain 1]: Toolchain selected. [2021-12-16 00:59:58,444 INFO L271 PluginConnector]: Initializing CDTParser... [2021-12-16 00:59:58,445 INFO L275 PluginConnector]: CDTParser initialized [2021-12-16 00:59:58,446 INFO L432 ainManager$Toolchain]: [Toolchain 1]: Parsing single file: /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/../sv-benchmarks/c/product-lines/minepump_spec3_product54.cil.c [2021-12-16 00:59:58,505 INFO L220 CDTParser]: Created temporary CDT project at /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/data/9aab40b88/2090241379d4453a84d2aea4b3bee69c/FLAGd872a7ba2 [2021-12-16 00:59:58,818 INFO L306 CDTParser]: Found 1 translation units. [2021-12-16 00:59:58,819 INFO L160 CDTParser]: Scanning /storage/repos/ultimate/releaseScripts/default/sv-benchmarks/c/product-lines/minepump_spec3_product54.cil.c [2021-12-16 00:59:58,826 INFO L349 CDTParser]: About to delete temporary CDT project at /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/data/9aab40b88/2090241379d4453a84d2aea4b3bee69c/FLAGd872a7ba2 [2021-12-16 00:59:59,227 INFO L357 CDTParser]: Successfully deleted /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/data/9aab40b88/2090241379d4453a84d2aea4b3bee69c [2021-12-16 00:59:59,229 INFO L299 ainManager$Toolchain]: ####################### [Toolchain 1] ####################### [2021-12-16 00:59:59,230 INFO L131 ToolchainWalker]: Walking toolchain with 6 elements. [2021-12-16 00:59:59,232 INFO L113 PluginConnector]: ------------------------CACSL2BoogieTranslator---------------------------- [2021-12-16 00:59:59,232 INFO L271 PluginConnector]: Initializing CACSL2BoogieTranslator... [2021-12-16 00:59:59,235 INFO L275 PluginConnector]: CACSL2BoogieTranslator initialized [2021-12-16 00:59:59,235 INFO L185 PluginConnector]: Executing the observer ACSLObjectContainerObserver from plugin CACSL2BoogieTranslator for "CDTParser AST 16.12 12:59:59" (1/1) ... [2021-12-16 00:59:59,236 INFO L205 PluginConnector]: Invalid model from CACSL2BoogieTranslator for observer de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator.ACSLObjectContainerObserver@1673f37e and model type de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 16.12 12:59:59, skipping insertion in model container [2021-12-16 00:59:59,236 INFO L185 PluginConnector]: Executing the observer CACSL2BoogieTranslatorObserver from plugin CACSL2BoogieTranslator for "CDTParser AST 16.12 12:59:59" (1/1) ... [2021-12-16 00:59:59,251 INFO L145 MainTranslator]: Starting translation in SV-COMP mode [2021-12-16 00:59:59,295 INFO L178 MainTranslator]: Built tables and reachable declarations [2021-12-16 00:59:59,447 WARN L230 ndardFunctionHandler]: Function reach_error is already implemented but we override the implementation for the call at /storage/repos/ultimate/releaseScripts/default/sv-benchmarks/c/product-lines/minepump_spec3_product54.cil.c[4478,4491] [2021-12-16 00:59:59,511 INFO L209 PostProcessor]: Analyzing one entry point: main [2021-12-16 00:59:59,537 INFO L203 MainTranslator]: Completed pre-run [2021-12-16 00:59:59,560 WARN L230 ndardFunctionHandler]: Function reach_error is already implemented but we override the implementation for the call at /storage/repos/ultimate/releaseScripts/default/sv-benchmarks/c/product-lines/minepump_spec3_product54.cil.c[4478,4491] [2021-12-16 00:59:59,602 INFO L209 PostProcessor]: Analyzing one entry point: main [2021-12-16 00:59:59,613 INFO L208 MainTranslator]: Completed translation [2021-12-16 00:59:59,614 INFO L202 PluginConnector]: Adding new model de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 16.12 12:59:59 WrapperNode [2021-12-16 00:59:59,614 INFO L132 PluginConnector]: ------------------------ END CACSL2BoogieTranslator---------------------------- [2021-12-16 00:59:59,615 INFO L113 PluginConnector]: ------------------------Boogie Procedure Inliner---------------------------- [2021-12-16 00:59:59,615 INFO L271 PluginConnector]: Initializing Boogie Procedure Inliner... [2021-12-16 00:59:59,615 INFO L275 PluginConnector]: Boogie Procedure Inliner initialized [2021-12-16 00:59:59,620 INFO L185 PluginConnector]: Executing the observer TypeChecker from plugin Boogie Procedure Inliner for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 16.12 12:59:59" (1/1) ... [2021-12-16 00:59:59,635 INFO L185 PluginConnector]: Executing the observer Inliner from plugin Boogie Procedure Inliner for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 16.12 12:59:59" (1/1) ... [2021-12-16 00:59:59,674 INFO L137 Inliner]: procedures = 57, calls = 160, calls flagged for inlining = 24, calls inlined = 21, statements flattened = 284 [2021-12-16 00:59:59,682 INFO L132 PluginConnector]: ------------------------ END Boogie Procedure Inliner---------------------------- [2021-12-16 00:59:59,682 INFO L113 PluginConnector]: ------------------------Boogie Preprocessor---------------------------- [2021-12-16 00:59:59,683 INFO L271 PluginConnector]: Initializing Boogie Preprocessor... [2021-12-16 00:59:59,683 INFO L275 PluginConnector]: Boogie Preprocessor initialized [2021-12-16 00:59:59,688 INFO L185 PluginConnector]: Executing the observer EnsureBoogieModelObserver from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 16.12 12:59:59" (1/1) ... [2021-12-16 00:59:59,689 INFO L185 PluginConnector]: Executing the observer TypeChecker from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 16.12 12:59:59" (1/1) ... [2021-12-16 00:59:59,691 INFO L185 PluginConnector]: Executing the observer ConstExpander from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 16.12 12:59:59" (1/1) ... [2021-12-16 00:59:59,695 INFO L185 PluginConnector]: Executing the observer StructExpander from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 16.12 12:59:59" (1/1) ... [2021-12-16 00:59:59,699 INFO L185 PluginConnector]: Executing the observer UnstructureCode from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 16.12 12:59:59" (1/1) ... [2021-12-16 00:59:59,715 INFO L185 PluginConnector]: Executing the observer FunctionInliner from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 16.12 12:59:59" (1/1) ... [2021-12-16 00:59:59,716 INFO L185 PluginConnector]: Executing the observer BoogieSymbolTableConstructor from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 16.12 12:59:59" (1/1) ... [2021-12-16 00:59:59,724 INFO L132 PluginConnector]: ------------------------ END Boogie Preprocessor---------------------------- [2021-12-16 00:59:59,725 INFO L113 PluginConnector]: ------------------------RCFGBuilder---------------------------- [2021-12-16 00:59:59,725 INFO L271 PluginConnector]: Initializing RCFGBuilder... [2021-12-16 00:59:59,725 INFO L275 PluginConnector]: RCFGBuilder initialized [2021-12-16 00:59:59,726 INFO L185 PluginConnector]: Executing the observer RCFGBuilderObserver from plugin RCFGBuilder for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 16.12 12:59:59" (1/1) ... [2021-12-16 00:59:59,745 INFO L168 SolverBuilder]: Constructing external solver with command: z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in -t:2000 [2021-12-16 00:59:59,761 INFO L189 MonitoredProcess]: No working directory specified, using /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 [2021-12-16 00:59:59,786 INFO L229 MonitoredProcess]: Starting monitored process 1 with /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in -t:2000 (exit command is (exit), workingDir is null) [2021-12-16 00:59:59,787 INFO L327 MonitoredProcess]: [MP /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in -t:2000 (1)] Waiting until timeout for monitored process [2021-12-16 00:59:59,845 INFO L130 BoogieDeclarations]: Found specification of procedure #Ultimate.allocInit [2021-12-16 00:59:59,845 INFO L130 BoogieDeclarations]: Found specification of procedure processEnvironment__wrappee__base [2021-12-16 00:59:59,845 INFO L138 BoogieDeclarations]: Found implementation of procedure processEnvironment__wrappee__base [2021-12-16 00:59:59,845 INFO L130 BoogieDeclarations]: Found specification of procedure timeShift [2021-12-16 00:59:59,845 INFO L138 BoogieDeclarations]: Found implementation of procedure timeShift [2021-12-16 00:59:59,845 INFO L130 BoogieDeclarations]: Found specification of procedure cleanup [2021-12-16 00:59:59,845 INFO L138 BoogieDeclarations]: Found implementation of procedure cleanup [2021-12-16 00:59:59,845 INFO L130 BoogieDeclarations]: Found specification of procedure isMethaneLevelCritical [2021-12-16 00:59:59,846 INFO L138 BoogieDeclarations]: Found implementation of procedure isMethaneLevelCritical [2021-12-16 00:59:59,846 INFO L130 BoogieDeclarations]: Found specification of procedure processEnvironment__wrappee__highWaterSensor [2021-12-16 00:59:59,846 INFO L138 BoogieDeclarations]: Found implementation of procedure processEnvironment__wrappee__highWaterSensor [2021-12-16 00:59:59,846 INFO L130 BoogieDeclarations]: Found specification of procedure waterRise [2021-12-16 00:59:59,846 INFO L138 BoogieDeclarations]: Found implementation of procedure waterRise [2021-12-16 00:59:59,847 INFO L130 BoogieDeclarations]: Found specification of procedure processEnvironment__wrappee__lowWaterSensor [2021-12-16 00:59:59,847 INFO L138 BoogieDeclarations]: Found implementation of procedure processEnvironment__wrappee__lowWaterSensor [2021-12-16 00:59:59,847 INFO L130 BoogieDeclarations]: Found specification of procedure deactivatePump [2021-12-16 00:59:59,847 INFO L138 BoogieDeclarations]: Found implementation of procedure deactivatePump [2021-12-16 00:59:59,847 INFO L130 BoogieDeclarations]: Found specification of procedure write~init~int [2021-12-16 00:59:59,847 INFO L130 BoogieDeclarations]: Found specification of procedure changeMethaneLevel [2021-12-16 00:59:59,847 INFO L138 BoogieDeclarations]: Found implementation of procedure changeMethaneLevel [2021-12-16 00:59:59,847 INFO L130 BoogieDeclarations]: Found specification of procedure ULTIMATE.start [2021-12-16 00:59:59,847 INFO L138 BoogieDeclarations]: Found implementation of procedure ULTIMATE.start [2021-12-16 00:59:59,947 INFO L236 CfgBuilder]: Building ICFG [2021-12-16 00:59:59,963 INFO L262 CfgBuilder]: Building CFG for each procedure with an implementation [2021-12-16 01:00:00,344 INFO L277 CfgBuilder]: Performing block encoding [2021-12-16 01:00:00,348 INFO L296 CfgBuilder]: Using the 1 location(s) as analysis (start of procedure ULTIMATE.start) [2021-12-16 01:00:00,349 INFO L301 CfgBuilder]: Removed 2 assume(true) statements. [2021-12-16 01:00:00,350 INFO L202 PluginConnector]: Adding new model de.uni_freiburg.informatik.ultimate.plugins.generator.rcfgbuilder CFG 16.12 01:00:00 BoogieIcfgContainer [2021-12-16 01:00:00,350 INFO L132 PluginConnector]: ------------------------ END RCFGBuilder---------------------------- [2021-12-16 01:00:00,365 INFO L113 PluginConnector]: ------------------------TraceAbstraction---------------------------- [2021-12-16 01:00:00,365 INFO L271 PluginConnector]: Initializing TraceAbstraction... [2021-12-16 01:00:00,368 INFO L275 PluginConnector]: TraceAbstraction initialized [2021-12-16 01:00:00,375 INFO L185 PluginConnector]: Executing the observer TraceAbstractionObserver from plugin TraceAbstraction for "CDTParser AST 16.12 12:59:59" (1/3) ... [2021-12-16 01:00:00,376 INFO L205 PluginConnector]: Invalid model from TraceAbstraction for observer de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction.TraceAbstractionObserver@3178bd34 and model type de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction AST 16.12 01:00:00, skipping insertion in model container [2021-12-16 01:00:00,376 INFO L185 PluginConnector]: Executing the observer TraceAbstractionObserver from plugin TraceAbstraction for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 16.12 12:59:59" (2/3) ... [2021-12-16 01:00:00,376 INFO L205 PluginConnector]: Invalid model from TraceAbstraction for observer de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction.TraceAbstractionObserver@3178bd34 and model type de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction AST 16.12 01:00:00, skipping insertion in model container [2021-12-16 01:00:00,376 INFO L185 PluginConnector]: Executing the observer TraceAbstractionObserver from plugin TraceAbstraction for "de.uni_freiburg.informatik.ultimate.plugins.generator.rcfgbuilder CFG 16.12 01:00:00" (3/3) ... [2021-12-16 01:00:00,386 INFO L111 eAbstractionObserver]: Analyzing ICFG minepump_spec3_product54.cil.c [2021-12-16 01:00:00,389 INFO L204 ceAbstractionStarter]: Automizer settings: Hoare:true NWA Interpolation:FPandBP Determinization: PREDICATE_ABSTRACTION [2021-12-16 01:00:00,390 INFO L163 ceAbstractionStarter]: Applying trace abstraction to program that has 1 error locations. [2021-12-16 01:00:00,466 INFO L338 AbstractCegarLoop]: ======== Iteration 0 == of CEGAR loop == AllErrorsAtOnce ======== [2021-12-16 01:00:00,472 INFO L339 AbstractCegarLoop]: Settings: SEPARATE_VIOLATION_CHECK=true, mInterprocedural=true, mMaxIterations=1000000, mWatchIteration=1000000, mArtifact=RCFG, mInterpolation=FPandBP, mInterpolantAutomaton=STRAIGHT_LINE, mDumpAutomata=false, mAutomataFormat=ATS_NUMERATE, mDumpPath=., mDeterminiation=PREDICATE_ABSTRACTION, mMinimize=MINIMIZE_SEVPA, mHoare=true, mAutomataTypeConcurrency=PETRI_NET, mHoareTripleChecks=INCREMENTAL, mHoareAnnotationPositions=LoopsAndPotentialCycles, mDumpOnlyReuseAutomata=false, mLimitTraceHistogram=0, mErrorLocTimeLimit=0, mLimitPathProgramCount=0, mCollectInterpolantStatistics=true, mHeuristicEmptinessCheck=false, mHeuristicEmptinessCheckAStarHeuristic=ZERO, mHeuristicEmptinessCheckAStarHeuristicRandomSeed=1337, mHeuristicEmptinessCheckSmtFeatureScoringMethod=DAGSIZE, mSMTFeatureExtraction=false, mSMTFeatureExtractionDumpPath=., mOverrideInterpolantAutomaton=false, mMcrInterpolantMethod=WP, mLoopAccelerationTechnique=FAST_UPR [2021-12-16 01:00:00,473 INFO L340 AbstractCegarLoop]: Starting to check reachability of 1 error locations. [2021-12-16 01:00:00,519 INFO L276 IsEmpty]: Start isEmpty. Operand has 103 states, 76 states have (on average 1.381578947368421) internal successors, (105), 86 states have internal predecessors, (105), 16 states have call successors, (16), 9 states have call predecessors, (16), 9 states have return successors, (16), 11 states have call predecessors, (16), 16 states have call successors, (16) [2021-12-16 01:00:00,526 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 26 [2021-12-16 01:00:00,527 INFO L506 BasicCegarLoop]: Found error trace [2021-12-16 01:00:00,527 INFO L514 BasicCegarLoop]: trace histogram [1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2021-12-16 01:00:00,528 INFO L402 AbstractCegarLoop]: === Iteration 1 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2021-12-16 01:00:00,531 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2021-12-16 01:00:00,532 INFO L85 PathProgramCache]: Analyzing trace with hash 149329663, now seen corresponding path program 1 times [2021-12-16 01:00:00,540 INFO L121 FreeRefinementEngine]: Executing refinement strategy CAMEL [2021-12-16 01:00:00,541 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [1265464535] [2021-12-16 01:00:00,541 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2021-12-16 01:00:00,541 INFO L126 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2021-12-16 01:00:00,731 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 01:00:00,840 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 14 [2021-12-16 01:00:00,844 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 01:00:00,865 INFO L134 CoverageAnalysis]: Checked inductivity of 0 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2021-12-16 01:00:00,865 INFO L139 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2021-12-16 01:00:00,865 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [1265464535] [2021-12-16 01:00:00,866 INFO L160 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [1265464535] provided 1 perfect and 0 imperfect interpolant sequences [2021-12-16 01:00:00,866 INFO L186 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2021-12-16 01:00:00,866 INFO L199 FreeRefinementEngine]: Number of different interpolants: perfect sequences [2] imperfect sequences [] total 2 [2021-12-16 01:00:00,867 INFO L115 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [1143708476] [2021-12-16 01:00:00,868 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2021-12-16 01:00:00,871 INFO L546 AbstractCegarLoop]: INTERPOLANT automaton has 2 states [2021-12-16 01:00:00,871 INFO L103 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2021-12-16 01:00:00,909 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 2 interpolants. [2021-12-16 01:00:00,909 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=1, Invalid=1, Unknown=0, NotChecked=0, Total=2 [2021-12-16 01:00:00,912 INFO L87 Difference]: Start difference. First operand has 103 states, 76 states have (on average 1.381578947368421) internal successors, (105), 86 states have internal predecessors, (105), 16 states have call successors, (16), 9 states have call predecessors, (16), 9 states have return successors, (16), 11 states have call predecessors, (16), 16 states have call successors, (16) Second operand has 2 states, 2 states have (on average 10.5) internal successors, (21), 2 states have internal predecessors, (21), 1 states have call successors, (3), 2 states have call predecessors, (3), 1 states have return successors, (1), 1 states have call predecessors, (1), 1 states have call successors, (1) [2021-12-16 01:00:00,980 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2021-12-16 01:00:00,980 INFO L93 Difference]: Finished difference Result 198 states and 269 transitions. [2021-12-16 01:00:00,981 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 2 states. [2021-12-16 01:00:00,981 INFO L78 Accepts]: Start accepts. Automaton has has 2 states, 2 states have (on average 10.5) internal successors, (21), 2 states have internal predecessors, (21), 1 states have call successors, (3), 2 states have call predecessors, (3), 1 states have return successors, (1), 1 states have call predecessors, (1), 1 states have call successors, (1) Word has length 25 [2021-12-16 01:00:00,981 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2021-12-16 01:00:00,988 INFO L225 Difference]: With dead ends: 198 [2021-12-16 01:00:00,989 INFO L226 Difference]: Without dead ends: 94 [2021-12-16 01:00:01,006 INFO L932 BasicCegarLoop]: 0 DeclaredPredicates, 4 GetRequests, 4 SyntacticMatches, 0 SemanticMatches, 0 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 0 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=1, Invalid=1, Unknown=0, NotChecked=0, Total=2 [2021-12-16 01:00:01,009 INFO L933 BasicCegarLoop]: 131 mSDtfsCounter, 0 mSDsluCounter, 0 mSDsCounter, 0 mSdLazyCounter, 0 mSolverCounterSat, 0 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.0s Time, 0 mProtectedPredicate, 0 mProtectedAction, 0 SdHoareTripleChecker+Valid, 131 SdHoareTripleChecker+Invalid, 0 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 0 IncrementalHoareTripleChecker+Valid, 0 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.0s IncrementalHoareTripleChecker+Time [2021-12-16 01:00:01,009 INFO L934 BasicCegarLoop]: SdHoareTripleChecker [0 Valid, 131 Invalid, 0 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [0 Valid, 0 Invalid, 0 Unknown, 0 Unchecked, 0.0s Time] [2021-12-16 01:00:01,033 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 94 states. [2021-12-16 01:00:01,070 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 94 to 94. [2021-12-16 01:00:01,071 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 94 states, 69 states have (on average 1.318840579710145) internal successors, (91), 78 states have internal predecessors, (91), 16 states have call successors, (16), 9 states have call predecessors, (16), 8 states have return successors, (15), 10 states have call predecessors, (15), 15 states have call successors, (15) [2021-12-16 01:00:01,076 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 94 states to 94 states and 122 transitions. [2021-12-16 01:00:01,078 INFO L78 Accepts]: Start accepts. Automaton has 94 states and 122 transitions. Word has length 25 [2021-12-16 01:00:01,078 INFO L84 Accepts]: Finished accepts. word is rejected. [2021-12-16 01:00:01,078 INFO L470 AbstractCegarLoop]: Abstraction has 94 states and 122 transitions. [2021-12-16 01:00:01,078 INFO L471 AbstractCegarLoop]: INTERPOLANT automaton has has 2 states, 2 states have (on average 10.5) internal successors, (21), 2 states have internal predecessors, (21), 1 states have call successors, (3), 2 states have call predecessors, (3), 1 states have return successors, (1), 1 states have call predecessors, (1), 1 states have call successors, (1) [2021-12-16 01:00:01,078 INFO L276 IsEmpty]: Start isEmpty. Operand 94 states and 122 transitions. [2021-12-16 01:00:01,082 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 27 [2021-12-16 01:00:01,082 INFO L506 BasicCegarLoop]: Found error trace [2021-12-16 01:00:01,083 INFO L514 BasicCegarLoop]: trace histogram [1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2021-12-16 01:00:01,083 WARN L452 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable0 [2021-12-16 01:00:01,086 INFO L402 AbstractCegarLoop]: === Iteration 2 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2021-12-16 01:00:01,088 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2021-12-16 01:00:01,088 INFO L85 PathProgramCache]: Analyzing trace with hash 67554452, now seen corresponding path program 1 times [2021-12-16 01:00:01,089 INFO L121 FreeRefinementEngine]: Executing refinement strategy CAMEL [2021-12-16 01:00:01,089 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [2120219994] [2021-12-16 01:00:01,089 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2021-12-16 01:00:01,089 INFO L126 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2021-12-16 01:00:01,132 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 01:00:01,200 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 15 [2021-12-16 01:00:01,203 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 01:00:01,209 INFO L134 CoverageAnalysis]: Checked inductivity of 0 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2021-12-16 01:00:01,209 INFO L139 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2021-12-16 01:00:01,209 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [2120219994] [2021-12-16 01:00:01,210 INFO L160 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [2120219994] provided 1 perfect and 0 imperfect interpolant sequences [2021-12-16 01:00:01,210 INFO L186 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2021-12-16 01:00:01,210 INFO L199 FreeRefinementEngine]: Number of different interpolants: perfect sequences [3] imperfect sequences [] total 3 [2021-12-16 01:00:01,210 INFO L115 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [1812902169] [2021-12-16 01:00:01,210 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2021-12-16 01:00:01,211 INFO L546 AbstractCegarLoop]: INTERPOLANT automaton has 3 states [2021-12-16 01:00:01,211 INFO L103 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2021-12-16 01:00:01,211 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 3 interpolants. [2021-12-16 01:00:01,211 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=3, Invalid=3, Unknown=0, NotChecked=0, Total=6 [2021-12-16 01:00:01,212 INFO L87 Difference]: Start difference. First operand 94 states and 122 transitions. Second operand has 3 states, 3 states have (on average 7.333333333333333) internal successors, (22), 3 states have internal predecessors, (22), 1 states have call successors, (3), 2 states have call predecessors, (3), 1 states have return successors, (1), 1 states have call predecessors, (1), 1 states have call successors, (1) [2021-12-16 01:00:01,247 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2021-12-16 01:00:01,247 INFO L93 Difference]: Finished difference Result 153 states and 199 transitions. [2021-12-16 01:00:01,249 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 3 states. [2021-12-16 01:00:01,249 INFO L78 Accepts]: Start accepts. Automaton has has 3 states, 3 states have (on average 7.333333333333333) internal successors, (22), 3 states have internal predecessors, (22), 1 states have call successors, (3), 2 states have call predecessors, (3), 1 states have return successors, (1), 1 states have call predecessors, (1), 1 states have call successors, (1) Word has length 26 [2021-12-16 01:00:01,263 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2021-12-16 01:00:01,265 INFO L225 Difference]: With dead ends: 153 [2021-12-16 01:00:01,265 INFO L226 Difference]: Without dead ends: 85 [2021-12-16 01:00:01,267 INFO L932 BasicCegarLoop]: 0 DeclaredPredicates, 5 GetRequests, 4 SyntacticMatches, 0 SemanticMatches, 1 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 0 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=3, Invalid=3, Unknown=0, NotChecked=0, Total=6 [2021-12-16 01:00:01,268 INFO L933 BasicCegarLoop]: 109 mSDtfsCounter, 13 mSDsluCounter, 92 mSDsCounter, 0 mSdLazyCounter, 1 mSolverCounterSat, 0 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.0s Time, 0 mProtectedPredicate, 0 mProtectedAction, 16 SdHoareTripleChecker+Valid, 201 SdHoareTripleChecker+Invalid, 1 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 0 IncrementalHoareTripleChecker+Valid, 1 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.0s IncrementalHoareTripleChecker+Time [2021-12-16 01:00:01,268 INFO L934 BasicCegarLoop]: SdHoareTripleChecker [16 Valid, 201 Invalid, 1 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [0 Valid, 1 Invalid, 0 Unknown, 0 Unchecked, 0.0s Time] [2021-12-16 01:00:01,269 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 85 states. [2021-12-16 01:00:01,278 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 85 to 85. [2021-12-16 01:00:01,280 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 85 states, 63 states have (on average 1.3333333333333333) internal successors, (84), 72 states have internal predecessors, (84), 13 states have call successors, (13), 8 states have call predecessors, (13), 8 states have return successors, (13), 8 states have call predecessors, (13), 13 states have call successors, (13) [2021-12-16 01:00:01,281 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 85 states to 85 states and 110 transitions. [2021-12-16 01:00:01,281 INFO L78 Accepts]: Start accepts. Automaton has 85 states and 110 transitions. Word has length 26 [2021-12-16 01:00:01,281 INFO L84 Accepts]: Finished accepts. word is rejected. [2021-12-16 01:00:01,282 INFO L470 AbstractCegarLoop]: Abstraction has 85 states and 110 transitions. [2021-12-16 01:00:01,282 INFO L471 AbstractCegarLoop]: INTERPOLANT automaton has has 3 states, 3 states have (on average 7.333333333333333) internal successors, (22), 3 states have internal predecessors, (22), 1 states have call successors, (3), 2 states have call predecessors, (3), 1 states have return successors, (1), 1 states have call predecessors, (1), 1 states have call successors, (1) [2021-12-16 01:00:01,282 INFO L276 IsEmpty]: Start isEmpty. Operand 85 states and 110 transitions. [2021-12-16 01:00:01,285 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 32 [2021-12-16 01:00:01,286 INFO L506 BasicCegarLoop]: Found error trace [2021-12-16 01:00:01,286 INFO L514 BasicCegarLoop]: trace histogram [1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2021-12-16 01:00:01,286 WARN L452 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable1 [2021-12-16 01:00:01,286 INFO L402 AbstractCegarLoop]: === Iteration 3 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2021-12-16 01:00:01,286 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2021-12-16 01:00:01,289 INFO L85 PathProgramCache]: Analyzing trace with hash -6965766, now seen corresponding path program 1 times [2021-12-16 01:00:01,289 INFO L121 FreeRefinementEngine]: Executing refinement strategy CAMEL [2021-12-16 01:00:01,290 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [772258687] [2021-12-16 01:00:01,290 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2021-12-16 01:00:01,290 INFO L126 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2021-12-16 01:00:01,316 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 01:00:01,388 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 20 [2021-12-16 01:00:01,391 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 01:00:01,396 INFO L134 CoverageAnalysis]: Checked inductivity of 0 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2021-12-16 01:00:01,396 INFO L139 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2021-12-16 01:00:01,396 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [772258687] [2021-12-16 01:00:01,397 INFO L160 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [772258687] provided 1 perfect and 0 imperfect interpolant sequences [2021-12-16 01:00:01,397 INFO L186 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2021-12-16 01:00:01,397 INFO L199 FreeRefinementEngine]: Number of different interpolants: perfect sequences [5] imperfect sequences [] total 5 [2021-12-16 01:00:01,397 INFO L115 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [890536383] [2021-12-16 01:00:01,397 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2021-12-16 01:00:01,398 INFO L546 AbstractCegarLoop]: INTERPOLANT automaton has 5 states [2021-12-16 01:00:01,398 INFO L103 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2021-12-16 01:00:01,398 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 5 interpolants. [2021-12-16 01:00:01,398 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=7, Invalid=13, Unknown=0, NotChecked=0, Total=20 [2021-12-16 01:00:01,399 INFO L87 Difference]: Start difference. First operand 85 states and 110 transitions. Second operand has 5 states, 5 states have (on average 5.6) internal successors, (28), 5 states have internal predecessors, (28), 2 states have call successors, (2), 2 states have call predecessors, (2), 1 states have return successors, (1), 1 states have call predecessors, (1), 1 states have call successors, (1) [2021-12-16 01:00:01,483 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2021-12-16 01:00:01,483 INFO L93 Difference]: Finished difference Result 163 states and 214 transitions. [2021-12-16 01:00:01,483 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 5 states. [2021-12-16 01:00:01,483 INFO L78 Accepts]: Start accepts. Automaton has has 5 states, 5 states have (on average 5.6) internal successors, (28), 5 states have internal predecessors, (28), 2 states have call successors, (2), 2 states have call predecessors, (2), 1 states have return successors, (1), 1 states have call predecessors, (1), 1 states have call successors, (1) Word has length 31 [2021-12-16 01:00:01,484 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2021-12-16 01:00:01,486 INFO L225 Difference]: With dead ends: 163 [2021-12-16 01:00:01,486 INFO L226 Difference]: Without dead ends: 85 [2021-12-16 01:00:01,487 INFO L932 BasicCegarLoop]: 0 DeclaredPredicates, 11 GetRequests, 6 SyntacticMatches, 0 SemanticMatches, 5 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 0 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=17, Invalid=25, Unknown=0, NotChecked=0, Total=42 [2021-12-16 01:00:01,492 INFO L933 BasicCegarLoop]: 103 mSDtfsCounter, 135 mSDsluCounter, 174 mSDsCounter, 0 mSdLazyCounter, 9 mSolverCounterSat, 9 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.0s Time, 0 mProtectedPredicate, 0 mProtectedAction, 135 SdHoareTripleChecker+Valid, 277 SdHoareTripleChecker+Invalid, 18 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 9 IncrementalHoareTripleChecker+Valid, 9 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.0s IncrementalHoareTripleChecker+Time [2021-12-16 01:00:01,493 INFO L934 BasicCegarLoop]: SdHoareTripleChecker [135 Valid, 277 Invalid, 18 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [9 Valid, 9 Invalid, 0 Unknown, 0 Unchecked, 0.0s Time] [2021-12-16 01:00:01,494 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 85 states. [2021-12-16 01:00:01,501 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 85 to 85. [2021-12-16 01:00:01,502 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 85 states, 63 states have (on average 1.3174603174603174) internal successors, (83), 72 states have internal predecessors, (83), 13 states have call successors, (13), 8 states have call predecessors, (13), 8 states have return successors, (13), 8 states have call predecessors, (13), 13 states have call successors, (13) [2021-12-16 01:00:01,502 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 85 states to 85 states and 109 transitions. [2021-12-16 01:00:01,502 INFO L78 Accepts]: Start accepts. Automaton has 85 states and 109 transitions. Word has length 31 [2021-12-16 01:00:01,503 INFO L84 Accepts]: Finished accepts. word is rejected. [2021-12-16 01:00:01,503 INFO L470 AbstractCegarLoop]: Abstraction has 85 states and 109 transitions. [2021-12-16 01:00:01,503 INFO L471 AbstractCegarLoop]: INTERPOLANT automaton has has 5 states, 5 states have (on average 5.6) internal successors, (28), 5 states have internal predecessors, (28), 2 states have call successors, (2), 2 states have call predecessors, (2), 1 states have return successors, (1), 1 states have call predecessors, (1), 1 states have call successors, (1) [2021-12-16 01:00:01,503 INFO L276 IsEmpty]: Start isEmpty. Operand 85 states and 109 transitions. [2021-12-16 01:00:01,504 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 45 [2021-12-16 01:00:01,504 INFO L506 BasicCegarLoop]: Found error trace [2021-12-16 01:00:01,504 INFO L514 BasicCegarLoop]: trace histogram [2, 2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2021-12-16 01:00:01,504 WARN L452 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable2 [2021-12-16 01:00:01,504 INFO L402 AbstractCegarLoop]: === Iteration 4 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2021-12-16 01:00:01,504 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2021-12-16 01:00:01,512 INFO L85 PathProgramCache]: Analyzing trace with hash 1330354743, now seen corresponding path program 1 times [2021-12-16 01:00:01,512 INFO L121 FreeRefinementEngine]: Executing refinement strategy CAMEL [2021-12-16 01:00:01,513 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [893826148] [2021-12-16 01:00:01,513 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2021-12-16 01:00:01,514 INFO L126 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2021-12-16 01:00:01,542 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 01:00:01,567 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 20 [2021-12-16 01:00:01,568 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 01:00:01,575 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 27 [2021-12-16 01:00:01,577 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 01:00:01,579 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 33 [2021-12-16 01:00:01,581 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 01:00:01,584 INFO L134 CoverageAnalysis]: Checked inductivity of 3 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 3 trivial. 0 not checked. [2021-12-16 01:00:01,584 INFO L139 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2021-12-16 01:00:01,584 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [893826148] [2021-12-16 01:00:01,584 INFO L160 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [893826148] provided 1 perfect and 0 imperfect interpolant sequences [2021-12-16 01:00:01,584 INFO L186 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2021-12-16 01:00:01,584 INFO L199 FreeRefinementEngine]: Number of different interpolants: perfect sequences [4] imperfect sequences [] total 4 [2021-12-16 01:00:01,585 INFO L115 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [62367341] [2021-12-16 01:00:01,585 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2021-12-16 01:00:01,586 INFO L546 AbstractCegarLoop]: INTERPOLANT automaton has 4 states [2021-12-16 01:00:01,586 INFO L103 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2021-12-16 01:00:01,586 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 4 interpolants. [2021-12-16 01:00:01,586 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=5, Invalid=7, Unknown=0, NotChecked=0, Total=12 [2021-12-16 01:00:01,586 INFO L87 Difference]: Start difference. First operand 85 states and 109 transitions. Second operand has 4 states, 4 states have (on average 8.75) internal successors, (35), 3 states have internal predecessors, (35), 2 states have call successors, (4), 3 states have call predecessors, (4), 1 states have return successors, (3), 1 states have call predecessors, (3), 1 states have call successors, (3) [2021-12-16 01:00:01,706 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2021-12-16 01:00:01,706 INFO L93 Difference]: Finished difference Result 246 states and 320 transitions. [2021-12-16 01:00:01,706 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 5 states. [2021-12-16 01:00:01,706 INFO L78 Accepts]: Start accepts. Automaton has has 4 states, 4 states have (on average 8.75) internal successors, (35), 3 states have internal predecessors, (35), 2 states have call successors, (4), 3 states have call predecessors, (4), 1 states have return successors, (3), 1 states have call predecessors, (3), 1 states have call successors, (3) Word has length 44 [2021-12-16 01:00:01,706 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2021-12-16 01:00:01,707 INFO L225 Difference]: With dead ends: 246 [2021-12-16 01:00:01,708 INFO L226 Difference]: Without dead ends: 168 [2021-12-16 01:00:01,708 INFO L932 BasicCegarLoop]: 0 DeclaredPredicates, 11 GetRequests, 8 SyntacticMatches, 0 SemanticMatches, 3 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 0 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=9, Invalid=11, Unknown=0, NotChecked=0, Total=20 [2021-12-16 01:00:01,709 INFO L933 BasicCegarLoop]: 117 mSDtfsCounter, 154 mSDsluCounter, 121 mSDsCounter, 0 mSdLazyCounter, 78 mSolverCounterSat, 41 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.1s Time, 0 mProtectedPredicate, 0 mProtectedAction, 160 SdHoareTripleChecker+Valid, 238 SdHoareTripleChecker+Invalid, 119 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 41 IncrementalHoareTripleChecker+Valid, 78 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.1s IncrementalHoareTripleChecker+Time [2021-12-16 01:00:01,709 INFO L934 BasicCegarLoop]: SdHoareTripleChecker [160 Valid, 238 Invalid, 119 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [41 Valid, 78 Invalid, 0 Unknown, 0 Unchecked, 0.1s Time] [2021-12-16 01:00:01,709 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 168 states. [2021-12-16 01:00:01,721 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 168 to 162. [2021-12-16 01:00:01,721 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 162 states, 122 states have (on average 1.2868852459016393) internal successors, (157), 130 states have internal predecessors, (157), 19 states have call successors, (19), 15 states have call predecessors, (19), 20 states have return successors, (30), 21 states have call predecessors, (30), 19 states have call successors, (30) [2021-12-16 01:00:01,722 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 162 states to 162 states and 206 transitions. [2021-12-16 01:00:01,722 INFO L78 Accepts]: Start accepts. Automaton has 162 states and 206 transitions. Word has length 44 [2021-12-16 01:00:01,722 INFO L84 Accepts]: Finished accepts. word is rejected. [2021-12-16 01:00:01,722 INFO L470 AbstractCegarLoop]: Abstraction has 162 states and 206 transitions. [2021-12-16 01:00:01,722 INFO L471 AbstractCegarLoop]: INTERPOLANT automaton has has 4 states, 4 states have (on average 8.75) internal successors, (35), 3 states have internal predecessors, (35), 2 states have call successors, (4), 3 states have call predecessors, (4), 1 states have return successors, (3), 1 states have call predecessors, (3), 1 states have call successors, (3) [2021-12-16 01:00:01,722 INFO L276 IsEmpty]: Start isEmpty. Operand 162 states and 206 transitions. [2021-12-16 01:00:01,723 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 51 [2021-12-16 01:00:01,723 INFO L506 BasicCegarLoop]: Found error trace [2021-12-16 01:00:01,723 INFO L514 BasicCegarLoop]: trace histogram [1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2021-12-16 01:00:01,723 WARN L452 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable3 [2021-12-16 01:00:01,723 INFO L402 AbstractCegarLoop]: === Iteration 5 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2021-12-16 01:00:01,724 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2021-12-16 01:00:01,724 INFO L85 PathProgramCache]: Analyzing trace with hash 1858639799, now seen corresponding path program 1 times [2021-12-16 01:00:01,724 INFO L121 FreeRefinementEngine]: Executing refinement strategy CAMEL [2021-12-16 01:00:01,724 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [2132643513] [2021-12-16 01:00:01,724 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2021-12-16 01:00:01,724 INFO L126 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2021-12-16 01:00:01,734 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 01:00:01,748 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 20 [2021-12-16 01:00:01,751 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 01:00:01,755 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 2 [2021-12-16 01:00:01,757 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 01:00:01,774 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 39 [2021-12-16 01:00:01,775 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 01:00:01,777 INFO L134 CoverageAnalysis]: Checked inductivity of 0 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2021-12-16 01:00:01,777 INFO L139 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2021-12-16 01:00:01,777 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [2132643513] [2021-12-16 01:00:01,777 INFO L160 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [2132643513] provided 1 perfect and 0 imperfect interpolant sequences [2021-12-16 01:00:01,777 INFO L186 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2021-12-16 01:00:01,777 INFO L199 FreeRefinementEngine]: Number of different interpolants: perfect sequences [6] imperfect sequences [] total 6 [2021-12-16 01:00:01,778 INFO L115 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [44633617] [2021-12-16 01:00:01,778 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2021-12-16 01:00:01,778 INFO L546 AbstractCegarLoop]: INTERPOLANT automaton has 6 states [2021-12-16 01:00:01,778 INFO L103 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2021-12-16 01:00:01,778 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 6 interpolants. [2021-12-16 01:00:01,778 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=9, Invalid=21, Unknown=0, NotChecked=0, Total=30 [2021-12-16 01:00:01,779 INFO L87 Difference]: Start difference. First operand 162 states and 206 transitions. Second operand has 6 states, 6 states have (on average 7.166666666666667) internal successors, (43), 5 states have internal predecessors, (43), 2 states have call successors, (4), 2 states have call predecessors, (4), 2 states have return successors, (3), 1 states have call predecessors, (3), 2 states have call successors, (3) [2021-12-16 01:00:01,884 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2021-12-16 01:00:01,884 INFO L93 Difference]: Finished difference Result 325 states and 421 transitions. [2021-12-16 01:00:01,884 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 7 states. [2021-12-16 01:00:01,885 INFO L78 Accepts]: Start accepts. Automaton has has 6 states, 6 states have (on average 7.166666666666667) internal successors, (43), 5 states have internal predecessors, (43), 2 states have call successors, (4), 2 states have call predecessors, (4), 2 states have return successors, (3), 1 states have call predecessors, (3), 2 states have call successors, (3) Word has length 50 [2021-12-16 01:00:01,885 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2021-12-16 01:00:01,886 INFO L225 Difference]: With dead ends: 325 [2021-12-16 01:00:01,886 INFO L226 Difference]: Without dead ends: 170 [2021-12-16 01:00:01,886 INFO L932 BasicCegarLoop]: 0 DeclaredPredicates, 17 GetRequests, 9 SyntacticMatches, 0 SemanticMatches, 8 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 3 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=32, Invalid=58, Unknown=0, NotChecked=0, Total=90 [2021-12-16 01:00:01,887 INFO L933 BasicCegarLoop]: 111 mSDtfsCounter, 71 mSDsluCounter, 340 mSDsCounter, 0 mSdLazyCounter, 128 mSolverCounterSat, 23 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.1s Time, 0 mProtectedPredicate, 0 mProtectedAction, 74 SdHoareTripleChecker+Valid, 451 SdHoareTripleChecker+Invalid, 151 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 23 IncrementalHoareTripleChecker+Valid, 128 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.1s IncrementalHoareTripleChecker+Time [2021-12-16 01:00:01,887 INFO L934 BasicCegarLoop]: SdHoareTripleChecker [74 Valid, 451 Invalid, 151 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [23 Valid, 128 Invalid, 0 Unknown, 0 Unchecked, 0.1s Time] [2021-12-16 01:00:01,888 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 170 states. [2021-12-16 01:00:01,895 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 170 to 165. [2021-12-16 01:00:01,895 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 165 states, 125 states have (on average 1.28) internal successors, (160), 133 states have internal predecessors, (160), 19 states have call successors, (19), 15 states have call predecessors, (19), 20 states have return successors, (30), 21 states have call predecessors, (30), 19 states have call successors, (30) [2021-12-16 01:00:01,896 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 165 states to 165 states and 209 transitions. [2021-12-16 01:00:01,896 INFO L78 Accepts]: Start accepts. Automaton has 165 states and 209 transitions. Word has length 50 [2021-12-16 01:00:01,896 INFO L84 Accepts]: Finished accepts. word is rejected. [2021-12-16 01:00:01,896 INFO L470 AbstractCegarLoop]: Abstraction has 165 states and 209 transitions. [2021-12-16 01:00:01,896 INFO L471 AbstractCegarLoop]: INTERPOLANT automaton has has 6 states, 6 states have (on average 7.166666666666667) internal successors, (43), 5 states have internal predecessors, (43), 2 states have call successors, (4), 2 states have call predecessors, (4), 2 states have return successors, (3), 1 states have call predecessors, (3), 2 states have call successors, (3) [2021-12-16 01:00:01,896 INFO L276 IsEmpty]: Start isEmpty. Operand 165 states and 209 transitions. [2021-12-16 01:00:01,897 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 51 [2021-12-16 01:00:01,897 INFO L506 BasicCegarLoop]: Found error trace [2021-12-16 01:00:01,897 INFO L514 BasicCegarLoop]: trace histogram [1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2021-12-16 01:00:01,897 WARN L452 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable4 [2021-12-16 01:00:01,897 INFO L402 AbstractCegarLoop]: === Iteration 6 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2021-12-16 01:00:01,897 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2021-12-16 01:00:01,898 INFO L85 PathProgramCache]: Analyzing trace with hash 2077494517, now seen corresponding path program 1 times [2021-12-16 01:00:01,898 INFO L121 FreeRefinementEngine]: Executing refinement strategy CAMEL [2021-12-16 01:00:01,898 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [388063512] [2021-12-16 01:00:01,898 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2021-12-16 01:00:01,898 INFO L126 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2021-12-16 01:00:01,906 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 01:00:01,917 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 20 [2021-12-16 01:00:01,926 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 01:00:01,930 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 2 [2021-12-16 01:00:01,931 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 01:00:01,942 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 39 [2021-12-16 01:00:01,942 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 01:00:01,944 INFO L134 CoverageAnalysis]: Checked inductivity of 0 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2021-12-16 01:00:01,944 INFO L139 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2021-12-16 01:00:01,944 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [388063512] [2021-12-16 01:00:01,944 INFO L160 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [388063512] provided 1 perfect and 0 imperfect interpolant sequences [2021-12-16 01:00:01,944 INFO L186 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2021-12-16 01:00:01,944 INFO L199 FreeRefinementEngine]: Number of different interpolants: perfect sequences [5] imperfect sequences [] total 5 [2021-12-16 01:00:01,944 INFO L115 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [903383412] [2021-12-16 01:00:01,945 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2021-12-16 01:00:01,945 INFO L546 AbstractCegarLoop]: INTERPOLANT automaton has 5 states [2021-12-16 01:00:01,945 INFO L103 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2021-12-16 01:00:01,945 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 5 interpolants. [2021-12-16 01:00:01,945 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=7, Invalid=13, Unknown=0, NotChecked=0, Total=20 [2021-12-16 01:00:01,945 INFO L87 Difference]: Start difference. First operand 165 states and 209 transitions. Second operand has 5 states, 5 states have (on average 8.6) internal successors, (43), 4 states have internal predecessors, (43), 2 states have call successors, (4), 2 states have call predecessors, (4), 2 states have return successors, (3), 1 states have call predecessors, (3), 2 states have call successors, (3) [2021-12-16 01:00:02,024 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2021-12-16 01:00:02,025 INFO L93 Difference]: Finished difference Result 333 states and 435 transitions. [2021-12-16 01:00:02,025 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 5 states. [2021-12-16 01:00:02,025 INFO L78 Accepts]: Start accepts. Automaton has has 5 states, 5 states have (on average 8.6) internal successors, (43), 4 states have internal predecessors, (43), 2 states have call successors, (4), 2 states have call predecessors, (4), 2 states have return successors, (3), 1 states have call predecessors, (3), 2 states have call successors, (3) Word has length 50 [2021-12-16 01:00:02,025 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2021-12-16 01:00:02,026 INFO L225 Difference]: With dead ends: 333 [2021-12-16 01:00:02,026 INFO L226 Difference]: Without dead ends: 175 [2021-12-16 01:00:02,027 INFO L932 BasicCegarLoop]: 0 DeclaredPredicates, 14 GetRequests, 9 SyntacticMatches, 0 SemanticMatches, 5 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 0 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=17, Invalid=25, Unknown=0, NotChecked=0, Total=42 [2021-12-16 01:00:02,027 INFO L933 BasicCegarLoop]: 112 mSDtfsCounter, 74 mSDsluCounter, 240 mSDsCounter, 0 mSdLazyCounter, 97 mSolverCounterSat, 19 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.0s Time, 0 mProtectedPredicate, 0 mProtectedAction, 78 SdHoareTripleChecker+Valid, 352 SdHoareTripleChecker+Invalid, 116 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 19 IncrementalHoareTripleChecker+Valid, 97 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.1s IncrementalHoareTripleChecker+Time [2021-12-16 01:00:02,028 INFO L934 BasicCegarLoop]: SdHoareTripleChecker [78 Valid, 352 Invalid, 116 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [19 Valid, 97 Invalid, 0 Unknown, 0 Unchecked, 0.1s Time] [2021-12-16 01:00:02,028 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 175 states. [2021-12-16 01:00:02,034 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 175 to 167. [2021-12-16 01:00:02,034 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 167 states, 127 states have (on average 1.2755905511811023) internal successors, (162), 135 states have internal predecessors, (162), 19 states have call successors, (19), 15 states have call predecessors, (19), 20 states have return successors, (30), 21 states have call predecessors, (30), 19 states have call successors, (30) [2021-12-16 01:00:02,035 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 167 states to 167 states and 211 transitions. [2021-12-16 01:00:02,035 INFO L78 Accepts]: Start accepts. Automaton has 167 states and 211 transitions. Word has length 50 [2021-12-16 01:00:02,035 INFO L84 Accepts]: Finished accepts. word is rejected. [2021-12-16 01:00:02,036 INFO L470 AbstractCegarLoop]: Abstraction has 167 states and 211 transitions. [2021-12-16 01:00:02,036 INFO L471 AbstractCegarLoop]: INTERPOLANT automaton has has 5 states, 5 states have (on average 8.6) internal successors, (43), 4 states have internal predecessors, (43), 2 states have call successors, (4), 2 states have call predecessors, (4), 2 states have return successors, (3), 1 states have call predecessors, (3), 2 states have call successors, (3) [2021-12-16 01:00:02,036 INFO L276 IsEmpty]: Start isEmpty. Operand 167 states and 211 transitions. [2021-12-16 01:00:02,036 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 51 [2021-12-16 01:00:02,036 INFO L506 BasicCegarLoop]: Found error trace [2021-12-16 01:00:02,036 INFO L514 BasicCegarLoop]: trace histogram [1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2021-12-16 01:00:02,036 WARN L452 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable5 [2021-12-16 01:00:02,037 INFO L402 AbstractCegarLoop]: === Iteration 7 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2021-12-16 01:00:02,037 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2021-12-16 01:00:02,037 INFO L85 PathProgramCache]: Analyzing trace with hash 1943481011, now seen corresponding path program 1 times [2021-12-16 01:00:02,037 INFO L121 FreeRefinementEngine]: Executing refinement strategy CAMEL [2021-12-16 01:00:02,037 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [841330759] [2021-12-16 01:00:02,037 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2021-12-16 01:00:02,037 INFO L126 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2021-12-16 01:00:02,045 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 01:00:02,066 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 20 [2021-12-16 01:00:02,068 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 01:00:02,075 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 2 [2021-12-16 01:00:02,076 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 01:00:02,083 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 39 [2021-12-16 01:00:02,084 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 01:00:02,086 INFO L134 CoverageAnalysis]: Checked inductivity of 0 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2021-12-16 01:00:02,086 INFO L139 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2021-12-16 01:00:02,086 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [841330759] [2021-12-16 01:00:02,086 INFO L160 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [841330759] provided 1 perfect and 0 imperfect interpolant sequences [2021-12-16 01:00:02,086 INFO L186 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2021-12-16 01:00:02,086 INFO L199 FreeRefinementEngine]: Number of different interpolants: perfect sequences [5] imperfect sequences [] total 5 [2021-12-16 01:00:02,086 INFO L115 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [771933913] [2021-12-16 01:00:02,086 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2021-12-16 01:00:02,087 INFO L546 AbstractCegarLoop]: INTERPOLANT automaton has 5 states [2021-12-16 01:00:02,087 INFO L103 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2021-12-16 01:00:02,087 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 5 interpolants. [2021-12-16 01:00:02,087 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=7, Invalid=13, Unknown=0, NotChecked=0, Total=20 [2021-12-16 01:00:02,087 INFO L87 Difference]: Start difference. First operand 167 states and 211 transitions. Second operand has 5 states, 5 states have (on average 8.6) internal successors, (43), 4 states have internal predecessors, (43), 3 states have call successors, (4), 3 states have call predecessors, (4), 2 states have return successors, (3), 2 states have call predecessors, (3), 3 states have call successors, (3) [2021-12-16 01:00:02,323 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2021-12-16 01:00:02,323 INFO L93 Difference]: Finished difference Result 467 states and 611 transitions. [2021-12-16 01:00:02,323 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 7 states. [2021-12-16 01:00:02,324 INFO L78 Accepts]: Start accepts. Automaton has has 5 states, 5 states have (on average 8.6) internal successors, (43), 4 states have internal predecessors, (43), 3 states have call successors, (4), 3 states have call predecessors, (4), 2 states have return successors, (3), 2 states have call predecessors, (3), 3 states have call successors, (3) Word has length 50 [2021-12-16 01:00:02,324 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2021-12-16 01:00:02,325 INFO L225 Difference]: With dead ends: 467 [2021-12-16 01:00:02,325 INFO L226 Difference]: Without dead ends: 307 [2021-12-16 01:00:02,326 INFO L932 BasicCegarLoop]: 0 DeclaredPredicates, 16 GetRequests, 10 SyntacticMatches, 1 SemanticMatches, 5 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 1 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=15, Invalid=27, Unknown=0, NotChecked=0, Total=42 [2021-12-16 01:00:02,326 INFO L933 BasicCegarLoop]: 162 mSDtfsCounter, 226 mSDsluCounter, 201 mSDsCounter, 0 mSdLazyCounter, 172 mSolverCounterSat, 65 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.1s Time, 0 mProtectedPredicate, 0 mProtectedAction, 233 SdHoareTripleChecker+Valid, 363 SdHoareTripleChecker+Invalid, 237 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 65 IncrementalHoareTripleChecker+Valid, 172 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.2s IncrementalHoareTripleChecker+Time [2021-12-16 01:00:02,326 INFO L934 BasicCegarLoop]: SdHoareTripleChecker [233 Valid, 363 Invalid, 237 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [65 Valid, 172 Invalid, 0 Unknown, 0 Unchecked, 0.2s Time] [2021-12-16 01:00:02,327 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 307 states. [2021-12-16 01:00:02,360 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 307 to 299. [2021-12-16 01:00:02,361 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 299 states, 226 states have (on average 1.252212389380531) internal successors, (283), 238 states have internal predecessors, (283), 36 states have call successors, (36), 33 states have call predecessors, (36), 36 states have return successors, (62), 37 states have call predecessors, (62), 36 states have call successors, (62) [2021-12-16 01:00:02,374 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 299 states to 299 states and 381 transitions. [2021-12-16 01:00:02,374 INFO L78 Accepts]: Start accepts. Automaton has 299 states and 381 transitions. Word has length 50 [2021-12-16 01:00:02,374 INFO L84 Accepts]: Finished accepts. word is rejected. [2021-12-16 01:00:02,375 INFO L470 AbstractCegarLoop]: Abstraction has 299 states and 381 transitions. [2021-12-16 01:00:02,375 INFO L471 AbstractCegarLoop]: INTERPOLANT automaton has has 5 states, 5 states have (on average 8.6) internal successors, (43), 4 states have internal predecessors, (43), 3 states have call successors, (4), 3 states have call predecessors, (4), 2 states have return successors, (3), 2 states have call predecessors, (3), 3 states have call successors, (3) [2021-12-16 01:00:02,375 INFO L276 IsEmpty]: Start isEmpty. Operand 299 states and 381 transitions. [2021-12-16 01:00:02,375 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 53 [2021-12-16 01:00:02,375 INFO L506 BasicCegarLoop]: Found error trace [2021-12-16 01:00:02,376 INFO L514 BasicCegarLoop]: trace histogram [1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2021-12-16 01:00:02,376 WARN L452 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable6 [2021-12-16 01:00:02,376 INFO L402 AbstractCegarLoop]: === Iteration 8 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2021-12-16 01:00:02,376 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2021-12-16 01:00:02,376 INFO L85 PathProgramCache]: Analyzing trace with hash -432802525, now seen corresponding path program 1 times [2021-12-16 01:00:02,376 INFO L121 FreeRefinementEngine]: Executing refinement strategy CAMEL [2021-12-16 01:00:02,376 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [114215849] [2021-12-16 01:00:02,377 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2021-12-16 01:00:02,377 INFO L126 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2021-12-16 01:00:02,391 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 01:00:02,417 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 20 [2021-12-16 01:00:02,419 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 01:00:02,421 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 2 [2021-12-16 01:00:02,422 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 01:00:02,425 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 8 [2021-12-16 01:00:02,425 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 01:00:02,426 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 41 [2021-12-16 01:00:02,427 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 01:00:02,439 INFO L134 CoverageAnalysis]: Checked inductivity of 0 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2021-12-16 01:00:02,439 INFO L139 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2021-12-16 01:00:02,439 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [114215849] [2021-12-16 01:00:02,439 INFO L160 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [114215849] provided 1 perfect and 0 imperfect interpolant sequences [2021-12-16 01:00:02,439 INFO L186 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2021-12-16 01:00:02,439 INFO L199 FreeRefinementEngine]: Number of different interpolants: perfect sequences [6] imperfect sequences [] total 6 [2021-12-16 01:00:02,440 INFO L115 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [344429649] [2021-12-16 01:00:02,440 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2021-12-16 01:00:02,440 INFO L546 AbstractCegarLoop]: INTERPOLANT automaton has 6 states [2021-12-16 01:00:02,440 INFO L103 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2021-12-16 01:00:02,440 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 6 interpolants. [2021-12-16 01:00:02,440 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=9, Invalid=21, Unknown=0, NotChecked=0, Total=30 [2021-12-16 01:00:02,441 INFO L87 Difference]: Start difference. First operand 299 states and 381 transitions. Second operand has 6 states, 6 states have (on average 7.166666666666667) internal successors, (43), 5 states have internal predecessors, (43), 2 states have call successors, (5), 3 states have call predecessors, (5), 1 states have return successors, (4), 2 states have call predecessors, (4), 2 states have call successors, (4) [2021-12-16 01:00:02,587 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2021-12-16 01:00:02,587 INFO L93 Difference]: Finished difference Result 594 states and 757 transitions. [2021-12-16 01:00:02,587 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 7 states. [2021-12-16 01:00:02,588 INFO L78 Accepts]: Start accepts. Automaton has has 6 states, 6 states have (on average 7.166666666666667) internal successors, (43), 5 states have internal predecessors, (43), 2 states have call successors, (5), 3 states have call predecessors, (5), 1 states have return successors, (4), 2 states have call predecessors, (4), 2 states have call successors, (4) Word has length 52 [2021-12-16 01:00:02,588 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2021-12-16 01:00:02,589 INFO L225 Difference]: With dead ends: 594 [2021-12-16 01:00:02,589 INFO L226 Difference]: Without dead ends: 302 [2021-12-16 01:00:02,591 INFO L932 BasicCegarLoop]: 0 DeclaredPredicates, 17 GetRequests, 10 SyntacticMatches, 0 SemanticMatches, 7 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 0 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=27, Invalid=45, Unknown=0, NotChecked=0, Total=72 [2021-12-16 01:00:02,591 INFO L933 BasicCegarLoop]: 102 mSDtfsCounter, 126 mSDsluCounter, 314 mSDsCounter, 0 mSdLazyCounter, 149 mSolverCounterSat, 33 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.1s Time, 0 mProtectedPredicate, 0 mProtectedAction, 131 SdHoareTripleChecker+Valid, 416 SdHoareTripleChecker+Invalid, 182 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 33 IncrementalHoareTripleChecker+Valid, 149 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.1s IncrementalHoareTripleChecker+Time [2021-12-16 01:00:02,591 INFO L934 BasicCegarLoop]: SdHoareTripleChecker [131 Valid, 416 Invalid, 182 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [33 Valid, 149 Invalid, 0 Unknown, 0 Unchecked, 0.1s Time] [2021-12-16 01:00:02,592 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 302 states. [2021-12-16 01:00:02,601 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 302 to 297. [2021-12-16 01:00:02,602 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 297 states, 224 states have (on average 1.2455357142857142) internal successors, (279), 236 states have internal predecessors, (279), 36 states have call successors, (36), 33 states have call predecessors, (36), 36 states have return successors, (62), 37 states have call predecessors, (62), 36 states have call successors, (62) [2021-12-16 01:00:02,603 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 297 states to 297 states and 377 transitions. [2021-12-16 01:00:02,604 INFO L78 Accepts]: Start accepts. Automaton has 297 states and 377 transitions. Word has length 52 [2021-12-16 01:00:02,604 INFO L84 Accepts]: Finished accepts. word is rejected. [2021-12-16 01:00:02,604 INFO L470 AbstractCegarLoop]: Abstraction has 297 states and 377 transitions. [2021-12-16 01:00:02,604 INFO L471 AbstractCegarLoop]: INTERPOLANT automaton has has 6 states, 6 states have (on average 7.166666666666667) internal successors, (43), 5 states have internal predecessors, (43), 2 states have call successors, (5), 3 states have call predecessors, (5), 1 states have return successors, (4), 2 states have call predecessors, (4), 2 states have call successors, (4) [2021-12-16 01:00:02,604 INFO L276 IsEmpty]: Start isEmpty. Operand 297 states and 377 transitions. [2021-12-16 01:00:02,605 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 55 [2021-12-16 01:00:02,605 INFO L506 BasicCegarLoop]: Found error trace [2021-12-16 01:00:02,605 INFO L514 BasicCegarLoop]: trace histogram [1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2021-12-16 01:00:02,605 WARN L452 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable7 [2021-12-16 01:00:02,605 INFO L402 AbstractCegarLoop]: === Iteration 9 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2021-12-16 01:00:02,605 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2021-12-16 01:00:02,605 INFO L85 PathProgramCache]: Analyzing trace with hash -1117904615, now seen corresponding path program 1 times [2021-12-16 01:00:02,605 INFO L121 FreeRefinementEngine]: Executing refinement strategy CAMEL [2021-12-16 01:00:02,605 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [995219664] [2021-12-16 01:00:02,606 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2021-12-16 01:00:02,606 INFO L126 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2021-12-16 01:00:02,613 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 01:00:02,635 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 11 [2021-12-16 01:00:02,636 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 01:00:02,641 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 24 [2021-12-16 01:00:02,642 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 01:00:02,646 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 2 [2021-12-16 01:00:02,647 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 01:00:02,651 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 43 [2021-12-16 01:00:02,652 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 01:00:02,653 INFO L134 CoverageAnalysis]: Checked inductivity of 0 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2021-12-16 01:00:02,653 INFO L139 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2021-12-16 01:00:02,653 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [995219664] [2021-12-16 01:00:02,653 INFO L160 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [995219664] provided 1 perfect and 0 imperfect interpolant sequences [2021-12-16 01:00:02,654 INFO L186 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2021-12-16 01:00:02,654 INFO L199 FreeRefinementEngine]: Number of different interpolants: perfect sequences [7] imperfect sequences [] total 7 [2021-12-16 01:00:02,654 INFO L115 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [69352644] [2021-12-16 01:00:02,654 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2021-12-16 01:00:02,654 INFO L546 AbstractCegarLoop]: INTERPOLANT automaton has 7 states [2021-12-16 01:00:02,654 INFO L103 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2021-12-16 01:00:02,654 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 7 interpolants. [2021-12-16 01:00:02,654 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=11, Invalid=31, Unknown=0, NotChecked=0, Total=42 [2021-12-16 01:00:02,655 INFO L87 Difference]: Start difference. First operand 297 states and 377 transitions. Second operand has 7 states, 7 states have (on average 6.428571428571429) internal successors, (45), 5 states have internal predecessors, (45), 2 states have call successors, (5), 3 states have call predecessors, (5), 2 states have return successors, (4), 2 states have call predecessors, (4), 2 states have call successors, (4) [2021-12-16 01:00:03,024 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2021-12-16 01:00:03,024 INFO L93 Difference]: Finished difference Result 583 states and 752 transitions. [2021-12-16 01:00:03,025 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 15 states. [2021-12-16 01:00:03,025 INFO L78 Accepts]: Start accepts. Automaton has has 7 states, 7 states have (on average 6.428571428571429) internal successors, (45), 5 states have internal predecessors, (45), 2 states have call successors, (5), 3 states have call predecessors, (5), 2 states have return successors, (4), 2 states have call predecessors, (4), 2 states have call successors, (4) Word has length 54 [2021-12-16 01:00:03,025 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2021-12-16 01:00:03,026 INFO L225 Difference]: With dead ends: 583 [2021-12-16 01:00:03,026 INFO L226 Difference]: Without dead ends: 345 [2021-12-16 01:00:03,027 INFO L932 BasicCegarLoop]: 0 DeclaredPredicates, 28 GetRequests, 13 SyntacticMatches, 0 SemanticMatches, 15 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 24 ImplicationChecksByTransitivity, 0.1s TimeCoverageRelationStatistics Valid=87, Invalid=185, Unknown=0, NotChecked=0, Total=272 [2021-12-16 01:00:03,028 INFO L933 BasicCegarLoop]: 164 mSDtfsCounter, 235 mSDsluCounter, 381 mSDsCounter, 0 mSdLazyCounter, 347 mSolverCounterSat, 77 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.2s Time, 0 mProtectedPredicate, 0 mProtectedAction, 239 SdHoareTripleChecker+Valid, 545 SdHoareTripleChecker+Invalid, 424 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 77 IncrementalHoareTripleChecker+Valid, 347 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.3s IncrementalHoareTripleChecker+Time [2021-12-16 01:00:03,028 INFO L934 BasicCegarLoop]: SdHoareTripleChecker [239 Valid, 545 Invalid, 424 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [77 Valid, 347 Invalid, 0 Unknown, 0 Unchecked, 0.3s Time] [2021-12-16 01:00:03,028 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 345 states. [2021-12-16 01:00:03,037 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 345 to 332. [2021-12-16 01:00:03,038 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 332 states, 251 states have (on average 1.2151394422310757) internal successors, (305), 266 states have internal predecessors, (305), 41 states have call successors, (41), 33 states have call predecessors, (41), 39 states have return successors, (58), 42 states have call predecessors, (58), 41 states have call successors, (58) [2021-12-16 01:00:03,052 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 332 states to 332 states and 404 transitions. [2021-12-16 01:00:03,052 INFO L78 Accepts]: Start accepts. Automaton has 332 states and 404 transitions. Word has length 54 [2021-12-16 01:00:03,052 INFO L84 Accepts]: Finished accepts. word is rejected. [2021-12-16 01:00:03,052 INFO L470 AbstractCegarLoop]: Abstraction has 332 states and 404 transitions. [2021-12-16 01:00:03,052 INFO L471 AbstractCegarLoop]: INTERPOLANT automaton has has 7 states, 7 states have (on average 6.428571428571429) internal successors, (45), 5 states have internal predecessors, (45), 2 states have call successors, (5), 3 states have call predecessors, (5), 2 states have return successors, (4), 2 states have call predecessors, (4), 2 states have call successors, (4) [2021-12-16 01:00:03,052 INFO L276 IsEmpty]: Start isEmpty. Operand 332 states and 404 transitions. [2021-12-16 01:00:03,053 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 57 [2021-12-16 01:00:03,053 INFO L506 BasicCegarLoop]: Found error trace [2021-12-16 01:00:03,053 INFO L514 BasicCegarLoop]: trace histogram [1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2021-12-16 01:00:03,053 WARN L452 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable8 [2021-12-16 01:00:03,053 INFO L402 AbstractCegarLoop]: === Iteration 10 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2021-12-16 01:00:03,053 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2021-12-16 01:00:03,054 INFO L85 PathProgramCache]: Analyzing trace with hash -309751737, now seen corresponding path program 1 times [2021-12-16 01:00:03,054 INFO L121 FreeRefinementEngine]: Executing refinement strategy CAMEL [2021-12-16 01:00:03,054 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [1933696378] [2021-12-16 01:00:03,054 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2021-12-16 01:00:03,054 INFO L126 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2021-12-16 01:00:03,073 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 01:00:03,089 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 11 [2021-12-16 01:00:03,090 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 01:00:03,094 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 24 [2021-12-16 01:00:03,095 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 01:00:03,113 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 2 [2021-12-16 01:00:03,114 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 01:00:03,127 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 8 [2021-12-16 01:00:03,127 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 01:00:03,129 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 45 [2021-12-16 01:00:03,130 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 01:00:03,140 INFO L134 CoverageAnalysis]: Checked inductivity of 0 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2021-12-16 01:00:03,140 INFO L139 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2021-12-16 01:00:03,140 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [1933696378] [2021-12-16 01:00:03,140 INFO L160 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [1933696378] provided 1 perfect and 0 imperfect interpolant sequences [2021-12-16 01:00:03,140 INFO L186 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2021-12-16 01:00:03,140 INFO L199 FreeRefinementEngine]: Number of different interpolants: perfect sequences [6] imperfect sequences [] total 6 [2021-12-16 01:00:03,140 INFO L115 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [1855185671] [2021-12-16 01:00:03,141 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2021-12-16 01:00:03,141 INFO L546 AbstractCegarLoop]: INTERPOLANT automaton has 6 states [2021-12-16 01:00:03,141 INFO L103 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2021-12-16 01:00:03,141 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 6 interpolants. [2021-12-16 01:00:03,141 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=9, Invalid=21, Unknown=0, NotChecked=0, Total=30 [2021-12-16 01:00:03,141 INFO L87 Difference]: Start difference. First operand 332 states and 404 transitions. Second operand has 6 states, 6 states have (on average 7.5) internal successors, (45), 4 states have internal predecessors, (45), 2 states have call successors, (6), 3 states have call predecessors, (6), 2 states have return successors, (5), 2 states have call predecessors, (5), 2 states have call successors, (5) [2021-12-16 01:00:03,380 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2021-12-16 01:00:03,380 INFO L93 Difference]: Finished difference Result 604 states and 746 transitions. [2021-12-16 01:00:03,381 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 8 states. [2021-12-16 01:00:03,381 INFO L78 Accepts]: Start accepts. Automaton has has 6 states, 6 states have (on average 7.5) internal successors, (45), 4 states have internal predecessors, (45), 2 states have call successors, (6), 3 states have call predecessors, (6), 2 states have return successors, (5), 2 states have call predecessors, (5), 2 states have call successors, (5) Word has length 56 [2021-12-16 01:00:03,381 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2021-12-16 01:00:03,382 INFO L225 Difference]: With dead ends: 604 [2021-12-16 01:00:03,382 INFO L226 Difference]: Without dead ends: 333 [2021-12-16 01:00:03,383 INFO L932 BasicCegarLoop]: 0 DeclaredPredicates, 21 GetRequests, 13 SyntacticMatches, 0 SemanticMatches, 8 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 3 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=33, Invalid=57, Unknown=0, NotChecked=0, Total=90 [2021-12-16 01:00:03,383 INFO L933 BasicCegarLoop]: 103 mSDtfsCounter, 157 mSDsluCounter, 224 mSDsCounter, 0 mSdLazyCounter, 194 mSolverCounterSat, 54 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.2s Time, 0 mProtectedPredicate, 0 mProtectedAction, 160 SdHoareTripleChecker+Valid, 327 SdHoareTripleChecker+Invalid, 248 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 54 IncrementalHoareTripleChecker+Valid, 194 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.2s IncrementalHoareTripleChecker+Time [2021-12-16 01:00:03,383 INFO L934 BasicCegarLoop]: SdHoareTripleChecker [160 Valid, 327 Invalid, 248 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [54 Valid, 194 Invalid, 0 Unknown, 0 Unchecked, 0.2s Time] [2021-12-16 01:00:03,384 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 333 states. [2021-12-16 01:00:03,407 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 333 to 329. [2021-12-16 01:00:03,407 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 329 states, 248 states have (on average 1.2137096774193548) internal successors, (301), 263 states have internal predecessors, (301), 41 states have call successors, (41), 33 states have call predecessors, (41), 39 states have return successors, (58), 42 states have call predecessors, (58), 41 states have call successors, (58) [2021-12-16 01:00:03,408 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 329 states to 329 states and 400 transitions. [2021-12-16 01:00:03,408 INFO L78 Accepts]: Start accepts. Automaton has 329 states and 400 transitions. Word has length 56 [2021-12-16 01:00:03,409 INFO L84 Accepts]: Finished accepts. word is rejected. [2021-12-16 01:00:03,409 INFO L470 AbstractCegarLoop]: Abstraction has 329 states and 400 transitions. [2021-12-16 01:00:03,409 INFO L471 AbstractCegarLoop]: INTERPOLANT automaton has has 6 states, 6 states have (on average 7.5) internal successors, (45), 4 states have internal predecessors, (45), 2 states have call successors, (6), 3 states have call predecessors, (6), 2 states have return successors, (5), 2 states have call predecessors, (5), 2 states have call successors, (5) [2021-12-16 01:00:03,409 INFO L276 IsEmpty]: Start isEmpty. Operand 329 states and 400 transitions. [2021-12-16 01:00:03,409 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 57 [2021-12-16 01:00:03,409 INFO L506 BasicCegarLoop]: Found error trace [2021-12-16 01:00:03,409 INFO L514 BasicCegarLoop]: trace histogram [1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2021-12-16 01:00:03,409 WARN L452 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable9 [2021-12-16 01:00:03,409 INFO L402 AbstractCegarLoop]: === Iteration 11 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2021-12-16 01:00:03,410 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2021-12-16 01:00:03,410 INFO L85 PathProgramCache]: Analyzing trace with hash -443765243, now seen corresponding path program 1 times [2021-12-16 01:00:03,410 INFO L121 FreeRefinementEngine]: Executing refinement strategy CAMEL [2021-12-16 01:00:03,410 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [1954672337] [2021-12-16 01:00:03,410 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2021-12-16 01:00:03,410 INFO L126 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2021-12-16 01:00:03,416 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 01:00:03,426 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 11 [2021-12-16 01:00:03,427 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 01:00:03,430 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 24 [2021-12-16 01:00:03,432 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 01:00:03,436 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 2 [2021-12-16 01:00:03,437 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 01:00:03,465 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 8 [2021-12-16 01:00:03,466 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 01:00:03,467 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 45 [2021-12-16 01:00:03,468 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 01:00:03,469 INFO L134 CoverageAnalysis]: Checked inductivity of 0 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2021-12-16 01:00:03,469 INFO L139 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2021-12-16 01:00:03,469 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [1954672337] [2021-12-16 01:00:03,469 INFO L160 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [1954672337] provided 1 perfect and 0 imperfect interpolant sequences [2021-12-16 01:00:03,469 INFO L186 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2021-12-16 01:00:03,469 INFO L199 FreeRefinementEngine]: Number of different interpolants: perfect sequences [7] imperfect sequences [] total 7 [2021-12-16 01:00:03,469 INFO L115 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [943915171] [2021-12-16 01:00:03,470 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2021-12-16 01:00:03,470 INFO L546 AbstractCegarLoop]: INTERPOLANT automaton has 7 states [2021-12-16 01:00:03,470 INFO L103 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2021-12-16 01:00:03,470 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 7 interpolants. [2021-12-16 01:00:03,470 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=11, Invalid=31, Unknown=0, NotChecked=0, Total=42 [2021-12-16 01:00:03,470 INFO L87 Difference]: Start difference. First operand 329 states and 400 transitions. Second operand has 7 states, 7 states have (on average 6.428571428571429) internal successors, (45), 5 states have internal predecessors, (45), 2 states have call successors, (6), 3 states have call predecessors, (6), 2 states have return successors, (5), 2 states have call predecessors, (5), 2 states have call successors, (5) [2021-12-16 01:00:03,665 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2021-12-16 01:00:03,665 INFO L93 Difference]: Finished difference Result 573 states and 705 transitions. [2021-12-16 01:00:03,665 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 9 states. [2021-12-16 01:00:03,666 INFO L78 Accepts]: Start accepts. Automaton has has 7 states, 7 states have (on average 6.428571428571429) internal successors, (45), 5 states have internal predecessors, (45), 2 states have call successors, (6), 3 states have call predecessors, (6), 2 states have return successors, (5), 2 states have call predecessors, (5), 2 states have call successors, (5) Word has length 56 [2021-12-16 01:00:03,666 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2021-12-16 01:00:03,667 INFO L225 Difference]: With dead ends: 573 [2021-12-16 01:00:03,667 INFO L226 Difference]: Without dead ends: 305 [2021-12-16 01:00:03,668 INFO L932 BasicCegarLoop]: 0 DeclaredPredicates, 23 GetRequests, 13 SyntacticMatches, 0 SemanticMatches, 10 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 4 ImplicationChecksByTransitivity, 0.1s TimeCoverageRelationStatistics Valid=46, Invalid=86, Unknown=0, NotChecked=0, Total=132 [2021-12-16 01:00:03,668 INFO L933 BasicCegarLoop]: 102 mSDtfsCounter, 147 mSDsluCounter, 303 mSDsCounter, 0 mSdLazyCounter, 258 mSolverCounterSat, 54 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.1s Time, 0 mProtectedPredicate, 0 mProtectedAction, 150 SdHoareTripleChecker+Valid, 405 SdHoareTripleChecker+Invalid, 312 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 54 IncrementalHoareTripleChecker+Valid, 258 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.1s IncrementalHoareTripleChecker+Time [2021-12-16 01:00:03,668 INFO L934 BasicCegarLoop]: SdHoareTripleChecker [150 Valid, 405 Invalid, 312 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [54 Valid, 258 Invalid, 0 Unknown, 0 Unchecked, 0.1s Time] [2021-12-16 01:00:03,669 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 305 states. [2021-12-16 01:00:03,677 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 305 to 301. [2021-12-16 01:00:03,677 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 301 states, 228 states have (on average 1.2105263157894737) internal successors, (276), 242 states have internal predecessors, (276), 38 states have call successors, (38), 30 states have call predecessors, (38), 34 states have return successors, (49), 37 states have call predecessors, (49), 38 states have call successors, (49) [2021-12-16 01:00:03,678 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 301 states to 301 states and 363 transitions. [2021-12-16 01:00:03,679 INFO L78 Accepts]: Start accepts. Automaton has 301 states and 363 transitions. Word has length 56 [2021-12-16 01:00:03,679 INFO L84 Accepts]: Finished accepts. word is rejected. [2021-12-16 01:00:03,679 INFO L470 AbstractCegarLoop]: Abstraction has 301 states and 363 transitions. [2021-12-16 01:00:03,679 INFO L471 AbstractCegarLoop]: INTERPOLANT automaton has has 7 states, 7 states have (on average 6.428571428571429) internal successors, (45), 5 states have internal predecessors, (45), 2 states have call successors, (6), 3 states have call predecessors, (6), 2 states have return successors, (5), 2 states have call predecessors, (5), 2 states have call successors, (5) [2021-12-16 01:00:03,679 INFO L276 IsEmpty]: Start isEmpty. Operand 301 states and 363 transitions. [2021-12-16 01:00:03,679 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 92 [2021-12-16 01:00:03,680 INFO L506 BasicCegarLoop]: Found error trace [2021-12-16 01:00:03,680 INFO L514 BasicCegarLoop]: trace histogram [3, 3, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2021-12-16 01:00:03,680 WARN L452 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable10 [2021-12-16 01:00:03,680 INFO L402 AbstractCegarLoop]: === Iteration 12 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2021-12-16 01:00:03,680 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2021-12-16 01:00:03,680 INFO L85 PathProgramCache]: Analyzing trace with hash 872263225, now seen corresponding path program 1 times [2021-12-16 01:00:03,680 INFO L121 FreeRefinementEngine]: Executing refinement strategy CAMEL [2021-12-16 01:00:03,680 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [522580954] [2021-12-16 01:00:03,680 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2021-12-16 01:00:03,681 INFO L126 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2021-12-16 01:00:03,687 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 01:00:03,701 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 11 [2021-12-16 01:00:03,703 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 01:00:03,709 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 20 [2021-12-16 01:00:03,712 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 01:00:03,741 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 3 [2021-12-16 01:00:03,742 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 01:00:03,744 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 2 [2021-12-16 01:00:03,745 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 01:00:03,747 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 22 [2021-12-16 01:00:03,748 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 01:00:03,755 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 67 [2021-12-16 01:00:03,755 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 01:00:03,757 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 74 [2021-12-16 01:00:03,758 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 01:00:03,759 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 80 [2021-12-16 01:00:03,760 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 01:00:03,761 INFO L134 CoverageAnalysis]: Checked inductivity of 27 backedges. 18 proven. 4 refuted. 0 times theorem prover too weak. 5 trivial. 0 not checked. [2021-12-16 01:00:03,761 INFO L139 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2021-12-16 01:00:03,762 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [522580954] [2021-12-16 01:00:03,762 INFO L160 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [522580954] provided 0 perfect and 1 imperfect interpolant sequences [2021-12-16 01:00:03,762 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleZ3 [1331677857] [2021-12-16 01:00:03,762 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2021-12-16 01:00:03,762 INFO L168 SolverBuilder]: Constructing external solver with command: z3 -smt2 -in SMTLIB2_COMPLIANT=true [2021-12-16 01:00:03,762 INFO L189 MonitoredProcess]: No working directory specified, using /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 [2021-12-16 01:00:03,763 INFO L229 MonitoredProcess]: Starting monitored process 2 with /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 -smt2 -in SMTLIB2_COMPLIANT=true (exit command is (exit), workingDir is null) [2021-12-16 01:00:03,764 INFO L327 MonitoredProcess]: [MP /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 -smt2 -in SMTLIB2_COMPLIANT=true (2)] Waiting until timeout for monitored process [2021-12-16 01:00:03,840 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 01:00:03,842 INFO L263 TraceCheckSpWp]: Trace formula consists of 455 conjuncts, 13 conjunts are in the unsatisfiable core [2021-12-16 01:00:03,847 INFO L286 TraceCheckSpWp]: Computing forward predicates... [2021-12-16 01:00:04,126 INFO L134 CoverageAnalysis]: Checked inductivity of 27 backedges. 6 proven. 12 refuted. 0 times theorem prover too weak. 9 trivial. 0 not checked. [2021-12-16 01:00:04,126 INFO L328 TraceCheckSpWp]: Computing backward predicates... [2021-12-16 01:00:04,489 INFO L134 CoverageAnalysis]: Checked inductivity of 27 backedges. 8 proven. 4 refuted. 0 times theorem prover too weak. 15 trivial. 0 not checked. [2021-12-16 01:00:04,489 INFO L160 FreeRefinementEngine]: IpTcStrategyModuleZ3 [1331677857] provided 0 perfect and 2 imperfect interpolant sequences [2021-12-16 01:00:04,489 INFO L186 FreeRefinementEngine]: Found 0 perfect and 3 imperfect interpolant sequences. [2021-12-16 01:00:04,489 INFO L199 FreeRefinementEngine]: Number of different interpolants: perfect sequences [] imperfect sequences [10, 8, 9] total 19 [2021-12-16 01:00:04,489 INFO L115 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [345978396] [2021-12-16 01:00:04,489 INFO L85 oduleStraightlineAll]: Using 3 imperfect interpolants to construct interpolant automaton [2021-12-16 01:00:04,490 INFO L546 AbstractCegarLoop]: INTERPOLANT automaton has 19 states [2021-12-16 01:00:04,490 INFO L103 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2021-12-16 01:00:04,490 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 19 interpolants. [2021-12-16 01:00:04,490 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=60, Invalid=282, Unknown=0, NotChecked=0, Total=342 [2021-12-16 01:00:04,491 INFO L87 Difference]: Start difference. First operand 301 states and 363 transitions. Second operand has 19 states, 19 states have (on average 7.105263157894737) internal successors, (135), 14 states have internal predecessors, (135), 7 states have call successors, (25), 10 states have call predecessors, (25), 8 states have return successors, (22), 8 states have call predecessors, (22), 7 states have call successors, (22) [2021-12-16 01:00:05,954 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2021-12-16 01:00:05,955 INFO L93 Difference]: Finished difference Result 913 states and 1175 transitions. [2021-12-16 01:00:05,955 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 52 states. [2021-12-16 01:00:05,955 INFO L78 Accepts]: Start accepts. Automaton has has 19 states, 19 states have (on average 7.105263157894737) internal successors, (135), 14 states have internal predecessors, (135), 7 states have call successors, (25), 10 states have call predecessors, (25), 8 states have return successors, (22), 8 states have call predecessors, (22), 7 states have call successors, (22) Word has length 91 [2021-12-16 01:00:05,955 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2021-12-16 01:00:05,956 INFO L225 Difference]: With dead ends: 913 [2021-12-16 01:00:05,956 INFO L226 Difference]: Without dead ends: 0 [2021-12-16 01:00:05,960 INFO L932 BasicCegarLoop]: 0 DeclaredPredicates, 261 GetRequests, 193 SyntacticMatches, 1 SemanticMatches, 67 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 1202 ImplicationChecksByTransitivity, 0.7s TimeCoverageRelationStatistics Valid=927, Invalid=3765, Unknown=0, NotChecked=0, Total=4692 [2021-12-16 01:00:05,961 INFO L933 BasicCegarLoop]: 152 mSDtfsCounter, 1083 mSDsluCounter, 676 mSDsCounter, 0 mSdLazyCounter, 1453 mSolverCounterSat, 566 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.7s Time, 0 mProtectedPredicate, 0 mProtectedAction, 1083 SdHoareTripleChecker+Valid, 828 SdHoareTripleChecker+Invalid, 2019 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 566 IncrementalHoareTripleChecker+Valid, 1453 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.8s IncrementalHoareTripleChecker+Time [2021-12-16 01:00:05,961 INFO L934 BasicCegarLoop]: SdHoareTripleChecker [1083 Valid, 828 Invalid, 2019 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [566 Valid, 1453 Invalid, 0 Unknown, 0 Unchecked, 0.8s Time] [2021-12-16 01:00:05,961 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 0 states. [2021-12-16 01:00:05,962 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 0 to 0. [2021-12-16 01:00:05,962 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 0 states, 0 states have (on average 0.0) internal successors, (0), 0 states have internal predecessors, (0), 0 states have call successors, (0), 0 states have call predecessors, (0), 0 states have return successors, (0), 0 states have call predecessors, (0), 0 states have call successors, (0) [2021-12-16 01:00:05,962 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 0 states to 0 states and 0 transitions. [2021-12-16 01:00:05,962 INFO L78 Accepts]: Start accepts. Automaton has 0 states and 0 transitions. Word has length 91 [2021-12-16 01:00:05,962 INFO L84 Accepts]: Finished accepts. word is rejected. [2021-12-16 01:00:05,962 INFO L470 AbstractCegarLoop]: Abstraction has 0 states and 0 transitions. [2021-12-16 01:00:05,963 INFO L471 AbstractCegarLoop]: INTERPOLANT automaton has has 19 states, 19 states have (on average 7.105263157894737) internal successors, (135), 14 states have internal predecessors, (135), 7 states have call successors, (25), 10 states have call predecessors, (25), 8 states have return successors, (22), 8 states have call predecessors, (22), 7 states have call successors, (22) [2021-12-16 01:00:05,963 INFO L276 IsEmpty]: Start isEmpty. Operand 0 states and 0 transitions. [2021-12-16 01:00:05,963 INFO L282 IsEmpty]: Finished isEmpty. No accepting run. [2021-12-16 01:00:05,965 INFO L764 garLoopResultBuilder]: Registering result SAFE for location timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION (0 of 1 remaining) [2021-12-16 01:00:05,986 INFO L540 MonitoredProcess]: [MP /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 -smt2 -in SMTLIB2_COMPLIANT=true (2)] Forceful destruction successful, exit code 0 [2021-12-16 01:00:06,183 WARN L452 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: 2 /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 -smt2 -in SMTLIB2_COMPLIANT=true,SelfDestructingSolverStorable11 [2021-12-16 01:00:06,184 INFO L343 DoubleDeckerVisitor]: Before removal of dead ends 0 states and 0 transitions. [2021-12-16 01:00:09,789 INFO L854 garLoopResultBuilder]: At program point deactivatePumpENTRY(lines 898 905) the Hoare annotation is: (or (= 0 ~systemActive~0) (not (<= ~waterLevel~0 1)) (= ~pumpRunning~0 |old(~pumpRunning~0)|) (not (= |old(~pumpRunning~0)| 1))) [2021-12-16 01:00:09,789 INFO L858 garLoopResultBuilder]: For program point deactivatePumpEXIT(lines 898 905) no Hoare annotation was computed. [2021-12-16 01:00:09,790 INFO L858 garLoopResultBuilder]: For program point deactivatePumpFINAL(lines 898 905) no Hoare annotation was computed. [2021-12-16 01:00:09,790 INFO L858 garLoopResultBuilder]: For program point processEnvironment__wrappee__baseEXIT(lines 805 811) no Hoare annotation was computed. [2021-12-16 01:00:09,790 INFO L861 garLoopResultBuilder]: At program point processEnvironment__wrappee__baseFINAL(lines 805 811) the Hoare annotation is: true [2021-12-16 01:00:09,790 INFO L854 garLoopResultBuilder]: At program point changeMethaneLevelENTRY(lines 84 95) the Hoare annotation is: (let ((.cse5 (not (= |old(~methaneLevelCritical~0)| 0))) (.cse1 (not (= ~pumpRunning~0 1))) (.cse7 (= ~methaneLevelCritical~0 0)) (.cse0 (= 0 ~systemActive~0)) (.cse6 (not (= ~pumpRunning~0 0))) (.cse2 (not (<= ~waterLevel~0 2))) (.cse3 (not (= 0 ~methaneLevelCritical~0))) (.cse4 (= 0 |old(~methaneLevelCritical~0)|))) (and (or .cse0 .cse1 .cse2 .cse3 .cse4) (or .cse0 .cse5 .cse6 .cse7 .cse2) (or .cse0 .cse5 .cse1 .cse7 .cse2) (or .cse0 .cse6 .cse2 .cse3 .cse4))) [2021-12-16 01:00:09,790 INFO L858 garLoopResultBuilder]: For program point L88-1(lines 84 95) no Hoare annotation was computed. [2021-12-16 01:00:09,790 INFO L858 garLoopResultBuilder]: For program point changeMethaneLevelEXIT(lines 84 95) no Hoare annotation was computed. [2021-12-16 01:00:09,790 INFO L858 garLoopResultBuilder]: For program point L64(lines 64 68) no Hoare annotation was computed. [2021-12-16 01:00:09,790 INFO L854 garLoopResultBuilder]: At program point L64-2(lines 60 71) the Hoare annotation is: (let ((.cse0 (= 0 ~systemActive~0)) (.cse1 (not (<= |old(~waterLevel~0)| 2)))) (and (or .cse0 .cse1 (and (<= ~waterLevel~0 |old(~waterLevel~0)|) (<= ~waterLevel~0 1) (= ~pumpRunning~0 |old(~pumpRunning~0)|)) (not (= |old(~pumpRunning~0)| 1))) (or .cse0 .cse1 (not (= |old(~pumpRunning~0)| 0))))) [2021-12-16 01:00:09,790 INFO L854 garLoopResultBuilder]: At program point L911(line 911) the Hoare annotation is: (let ((.cse0 (= 0 ~systemActive~0)) (.cse1 (not (<= |old(~waterLevel~0)| 2)))) (and (or .cse0 .cse1 (and (<= ~waterLevel~0 |old(~waterLevel~0)|) (<= ~waterLevel~0 1) (= ~pumpRunning~0 |old(~pumpRunning~0)|)) (not (= |old(~pumpRunning~0)| 1))) (or .cse0 .cse1 (not (= |old(~pumpRunning~0)| 0))))) [2021-12-16 01:00:09,790 INFO L858 garLoopResultBuilder]: For program point L911-1(line 911) no Hoare annotation was computed. [2021-12-16 01:00:09,790 INFO L858 garLoopResultBuilder]: For program point L267(line 267) no Hoare annotation was computed. [2021-12-16 01:00:09,792 INFO L858 garLoopResultBuilder]: For program point timeShiftFINAL(lines 781 804) no Hoare annotation was computed. [2021-12-16 01:00:09,792 INFO L858 garLoopResultBuilder]: For program point L292(lines 292 298) no Hoare annotation was computed. [2021-12-16 01:00:09,792 INFO L858 garLoopResultBuilder]: For program point L288(lines 288 301) no Hoare annotation was computed. [2021-12-16 01:00:09,792 INFO L854 garLoopResultBuilder]: At program point L288-1(lines 273 305) the Hoare annotation is: (let ((.cse7 (= ~methaneLevelCritical~0 |timeShift___utac_acc__Specification3_spec__1_~tmp~1#1|)) (.cse9 (= ~waterLevel~0 |old(~waterLevel~0)|)) (.cse0 (= 0 ~systemActive~0))) (let ((.cse1 (and (<= |timeShift___utac_acc__Specification3_spec__1_~tmp___0~0#1| 1) (<= |timeShift_getWaterLevel_#res#1| 1))) (.cse5 (not (= ~methaneLevelCritical~0 0))) (.cse3 (not (= |old(~pumpRunning~0)| 0))) (.cse4 (and .cse7 (= ~pumpRunning~0 1) .cse9 (<= 2 ~waterLevel~0) (not .cse0))) (.cse2 (not (<= |old(~waterLevel~0)| 2))) (.cse8 (<= ~waterLevel~0 1)) (.cse10 (= ~pumpRunning~0 0)) (.cse6 (not (= |old(~pumpRunning~0)| 1)))) (and (or .cse0 .cse1 .cse2 .cse3 .cse4 .cse5) (or .cse0 .cse1 .cse2 .cse5 .cse6) (or .cse0 .cse2 .cse3 .cse4 (and .cse7 .cse8 .cse9 .cse10)) (let ((.cse11 (<= ~waterLevel~0 |old(~waterLevel~0)|))) (or .cse0 .cse2 (and .cse11 .cse7 .cse8 (= ~pumpRunning~0 |old(~pumpRunning~0)|)) (and .cse11 .cse7 .cse8 .cse10) .cse6))))) [2021-12-16 01:00:09,792 INFO L854 garLoopResultBuilder]: At program point L280(line 280) the Hoare annotation is: (let ((.cse3 (= ~pumpRunning~0 0)) (.cse0 (= 0 ~systemActive~0)) (.cse2 (not (<= |old(~waterLevel~0)| 2))) (.cse4 (not (= |old(~pumpRunning~0)| 0)))) (and (let ((.cse1 (= ~waterLevel~0 |old(~waterLevel~0)|))) (or .cse0 (and .cse1 (<= 2 ~waterLevel~0)) .cse2 (and .cse1 .cse3) .cse4)) (let ((.cse5 (<= ~waterLevel~0 |old(~waterLevel~0)|)) (.cse6 (<= ~waterLevel~0 1))) (or .cse0 .cse2 (and .cse5 .cse6 (= ~pumpRunning~0 |old(~pumpRunning~0)|)) (and .cse5 .cse6 .cse3) (not (= |old(~pumpRunning~0)| 1)))) (or (not (<= 2 |old(~waterLevel~0)|)) .cse0 .cse2 (= ~pumpRunning~0 1) .cse4))) [2021-12-16 01:00:09,792 INFO L858 garLoopResultBuilder]: For program point L792-1(lines 792 798) no Hoare annotation was computed. [2021-12-16 01:00:09,793 INFO L858 garLoopResultBuilder]: For program point L280-1(line 280) no Hoare annotation was computed. [2021-12-16 01:00:09,793 INFO L854 garLoopResultBuilder]: At program point L879(line 879) the Hoare annotation is: (let ((.cse0 (= 0 ~systemActive~0)) (.cse1 (not (<= |old(~waterLevel~0)| 2)))) (and (or .cse0 .cse1 (and (<= ~waterLevel~0 |old(~waterLevel~0)|) (<= ~waterLevel~0 1) (= ~pumpRunning~0 |old(~pumpRunning~0)|)) (not (= |old(~pumpRunning~0)| 1))) (or .cse0 .cse1 (not (= |old(~pumpRunning~0)| 0))))) [2021-12-16 01:00:09,793 INFO L854 garLoopResultBuilder]: At program point L268(lines 263 270) the Hoare annotation is: (let ((.cse0 (= 0 ~systemActive~0)) (.cse1 (not (<= |old(~waterLevel~0)| 2)))) (and (or .cse0 .cse1 (not (= |old(~pumpRunning~0)| 1))) (or .cse0 .cse1 (not (= |old(~pumpRunning~0)| 0))))) [2021-12-16 01:00:09,793 INFO L854 garLoopResultBuilder]: At program point L875(line 875) the Hoare annotation is: (let ((.cse0 (= 0 ~systemActive~0)) (.cse1 (not (<= |old(~waterLevel~0)| 2)))) (and (or .cse0 .cse1 (and (<= ~waterLevel~0 |old(~waterLevel~0)|) (<= ~waterLevel~0 1) (= ~pumpRunning~0 |old(~pumpRunning~0)|)) (not (= |old(~pumpRunning~0)| 1))) (or .cse0 .cse1 (not (= |old(~pumpRunning~0)| 0))))) [2021-12-16 01:00:09,793 INFO L854 garLoopResultBuilder]: At program point L884(line 884) the Hoare annotation is: (let ((.cse0 (= 0 ~systemActive~0)) (.cse1 (not (<= |old(~waterLevel~0)| 2)))) (and (or .cse0 .cse1 (and (= ~waterLevel~0 |old(~waterLevel~0)|) (= ~pumpRunning~0 0)) (not (= |old(~pumpRunning~0)| 0))) (or .cse0 .cse1 (not (= |old(~pumpRunning~0)| 1))))) [2021-12-16 01:00:09,793 INFO L854 garLoopResultBuilder]: At program point L884-1(lines 865 889) the Hoare annotation is: (let ((.cse3 (= ~pumpRunning~0 0)) (.cse0 (= 0 ~systemActive~0)) (.cse2 (not (<= |old(~waterLevel~0)| 2))) (.cse4 (not (= |old(~pumpRunning~0)| 0)))) (and (let ((.cse1 (= ~waterLevel~0 |old(~waterLevel~0)|))) (or .cse0 (and .cse1 (<= 2 ~waterLevel~0)) .cse2 (and .cse1 .cse3) .cse4)) (let ((.cse5 (<= ~waterLevel~0 |old(~waterLevel~0)|)) (.cse6 (<= ~waterLevel~0 1))) (or .cse0 .cse2 (and .cse5 .cse6 (= ~pumpRunning~0 |old(~pumpRunning~0)|)) (and .cse5 .cse6 .cse3) (not (= |old(~pumpRunning~0)| 1)))) (or (not (<= 2 |old(~waterLevel~0)|)) .cse0 .cse2 (= ~pumpRunning~0 1) .cse4))) [2021-12-16 01:00:09,793 INFO L854 garLoopResultBuilder]: At program point L913(lines 906 916) the Hoare annotation is: (let ((.cse0 (= 0 ~systemActive~0)) (.cse1 (not (<= |old(~waterLevel~0)| 2)))) (and (or .cse0 .cse1 (and (<= ~waterLevel~0 |old(~waterLevel~0)|) (<= ~waterLevel~0 1) (= ~pumpRunning~0 |old(~pumpRunning~0)|)) (not (= |old(~pumpRunning~0)| 1))) (or .cse0 .cse1 (not (= |old(~pumpRunning~0)| 0))))) [2021-12-16 01:00:09,794 INFO L858 garLoopResultBuilder]: For program point L785-1(lines 784 803) no Hoare annotation was computed. [2021-12-16 01:00:09,794 INFO L854 garLoopResultBuilder]: At program point L133(lines 128 136) the Hoare annotation is: (let ((.cse7 (= ~pumpRunning~0 0)) (.cse2 (= ~methaneLevelCritical~0 |timeShift___utac_acc__Specification3_spec__1_~tmp~1#1|)) (.cse5 (<= ~waterLevel~0 1)) (.cse6 (<= |timeShift_getWaterLevel_#res#1| 1)) (.cse0 (= 0 ~systemActive~0)) (.cse4 (not (<= |old(~waterLevel~0)| 2))) (.cse1 (not (= |old(~pumpRunning~0)| 0)))) (and (or .cse0 (not (= |old(~waterLevel~0)| 1)) (= |timeShift_getWaterLevel_#res#1| 1) .cse1) (let ((.cse3 (= ~waterLevel~0 |old(~waterLevel~0)|))) (or .cse0 (and .cse2 (= ~pumpRunning~0 1) .cse3 (<= 2 ~waterLevel~0)) .cse4 (and .cse2 .cse5 .cse6 .cse3 .cse7) .cse1)) (let ((.cse8 (<= ~waterLevel~0 |old(~waterLevel~0)|)) (.cse9 (= ~methaneLevelCritical~0 0))) (or .cse0 (and .cse8 .cse2 .cse5 .cse6 .cse9 .cse7) (and .cse8 .cse2 .cse5 .cse6 .cse9 (= ~pumpRunning~0 |old(~pumpRunning~0)|)) .cse4 (not (= |old(~pumpRunning~0)| 1)))) (or .cse0 .cse4 .cse1 (= 0 ~methaneLevelCritical~0)))) [2021-12-16 01:00:09,794 INFO L858 garLoopResultBuilder]: For program point L282(lines 282 302) no Hoare annotation was computed. [2021-12-16 01:00:09,794 INFO L854 garLoopResultBuilder]: At program point L922(lines 917 925) the Hoare annotation is: (let ((.cse0 (= 0 ~systemActive~0)) (.cse1 (not (<= |old(~waterLevel~0)| 2)))) (and (or .cse0 .cse1 (not (= |old(~pumpRunning~0)| 1))) (or .cse0 .cse1 (not (= |old(~pumpRunning~0)| 0)) (and (= |timeShift_isPumpRunning_#res#1| 1) (= ~methaneLevelCritical~0 |timeShift___utac_acc__Specification3_spec__1_~tmp~1#1|) (= ~pumpRunning~0 1) (= ~waterLevel~0 |old(~waterLevel~0)|) (= ~methaneLevelCritical~0 0) (<= 2 ~waterLevel~0))))) [2021-12-16 01:00:09,794 INFO L854 garLoopResultBuilder]: At program point timeShiftENTRY(lines 781 804) the Hoare annotation is: (let ((.cse0 (= 0 ~systemActive~0)) (.cse1 (not (<= |old(~waterLevel~0)| 2))) (.cse2 (= ~waterLevel~0 |old(~waterLevel~0)|))) (and (or .cse0 .cse1 (and .cse2 (= ~pumpRunning~0 0)) (not (= |old(~pumpRunning~0)| 0))) (or .cse0 .cse1 (and .cse2 (= ~pumpRunning~0 |old(~pumpRunning~0)|)) (not (= |old(~pumpRunning~0)| 1))))) [2021-12-16 01:00:09,794 INFO L858 garLoopResultBuilder]: For program point timeShiftEXIT(lines 781 804) no Hoare annotation was computed. [2021-12-16 01:00:09,794 INFO L858 garLoopResultBuilder]: For program point L873(lines 873 881) no Hoare annotation was computed. [2021-12-16 01:00:09,794 INFO L858 garLoopResultBuilder]: For program point timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION(line 267) no Hoare annotation was computed. [2021-12-16 01:00:09,795 INFO L858 garLoopResultBuilder]: For program point L869(lines 869 886) no Hoare annotation was computed. [2021-12-16 01:00:09,795 INFO L858 garLoopResultBuilder]: For program point cleanupEXIT(lines 163 192) no Hoare annotation was computed. [2021-12-16 01:00:09,795 INFO L861 garLoopResultBuilder]: At program point cleanupENTRY(lines 163 192) the Hoare annotation is: true [2021-12-16 01:00:09,796 INFO L861 garLoopResultBuilder]: At program point L188(lines 163 192) the Hoare annotation is: true [2021-12-16 01:00:09,796 INFO L858 garLoopResultBuilder]: For program point L184(line 184) no Hoare annotation was computed. [2021-12-16 01:00:09,796 INFO L858 garLoopResultBuilder]: For program point L177(lines 177 181) no Hoare annotation was computed. [2021-12-16 01:00:09,796 INFO L861 garLoopResultBuilder]: At program point L177-1(lines 177 181) the Hoare annotation is: true [2021-12-16 01:00:09,796 INFO L858 garLoopResultBuilder]: For program point L174(line 174) no Hoare annotation was computed. [2021-12-16 01:00:09,796 INFO L861 garLoopResultBuilder]: At program point L173-2(lines 173 187) the Hoare annotation is: true [2021-12-16 01:00:09,796 INFO L861 garLoopResultBuilder]: At program point L169(line 169) the Hoare annotation is: true [2021-12-16 01:00:09,796 INFO L858 garLoopResultBuilder]: For program point L169-1(line 169) no Hoare annotation was computed. [2021-12-16 01:00:09,797 INFO L861 garLoopResultBuilder]: At program point isMethaneLevelCriticalENTRY(lines 96 104) the Hoare annotation is: true [2021-12-16 01:00:09,797 INFO L858 garLoopResultBuilder]: For program point isMethaneLevelCriticalFINAL(lines 96 104) no Hoare annotation was computed. [2021-12-16 01:00:09,797 INFO L858 garLoopResultBuilder]: For program point isMethaneLevelCriticalEXIT(lines 96 104) no Hoare annotation was computed. [2021-12-16 01:00:09,797 INFO L858 garLoopResultBuilder]: For program point L729(lines 729 735) no Hoare annotation was computed. [2021-12-16 01:00:09,797 INFO L858 garLoopResultBuilder]: For program point L729-1(lines 729 735) no Hoare annotation was computed. [2021-12-16 01:00:09,797 INFO L854 garLoopResultBuilder]: At program point L337(lines 332 340) the Hoare annotation is: (and (= ~waterLevel~0 1) (= ~methaneLevelCritical~0 0) (= 1 |ULTIMATE.start_valid_product_#res#1|) (not (= 0 ~systemActive~0)) (= ~pumpRunning~0 0)) [2021-12-16 01:00:09,798 INFO L858 garLoopResultBuilder]: For program point L721(lines 721 725) no Hoare annotation was computed. [2021-12-16 01:00:09,798 INFO L854 garLoopResultBuilder]: At program point L329(lines 325 331) the Hoare annotation is: (and (= ~waterLevel~0 1) (= ~methaneLevelCritical~0 0) (not (= 0 ~systemActive~0)) (= ~pumpRunning~0 0)) [2021-12-16 01:00:09,798 INFO L858 garLoopResultBuilder]: For program point L-1(line -1) no Hoare annotation was computed. [2021-12-16 01:00:09,798 INFO L854 garLoopResultBuilder]: At program point L767(lines 718 768) the Hoare annotation is: false [2021-12-16 01:00:09,798 INFO L854 garLoopResultBuilder]: At program point L222(lines 218 224) the Hoare annotation is: (and (= ~waterLevel~0 1) (= ~methaneLevelCritical~0 0) (= 1 |ULTIMATE.start_valid_product_#res#1|) (= 1 |ULTIMATE.start_main_~tmp~0#1|) (not (= 0 ~systemActive~0)) (= ~pumpRunning~0 0)) [2021-12-16 01:00:09,798 INFO L858 garLoopResultBuilder]: For program point ULTIMATE.startENTRY(line -1) no Hoare annotation was computed. [2021-12-16 01:00:09,798 INFO L858 garLoopResultBuilder]: For program point ULTIMATE.startFINAL(line -1) no Hoare annotation was computed. [2021-12-16 01:00:09,799 INFO L858 garLoopResultBuilder]: For program point L739(lines 739 745) no Hoare annotation was computed. [2021-12-16 01:00:09,800 INFO L854 garLoopResultBuilder]: At program point L322(lines 318 324) the Hoare annotation is: (and (= ~waterLevel~0 1) (= ~methaneLevelCritical~0 0) (not (= 0 ~systemActive~0)) (= ~pumpRunning~0 0)) [2021-12-16 01:00:09,800 INFO L858 garLoopResultBuilder]: For program point L739-1(lines 739 745) no Hoare annotation was computed. [2021-12-16 01:00:09,800 INFO L858 garLoopResultBuilder]: For program point ULTIMATE.startEXIT(line -1) no Hoare annotation was computed. [2021-12-16 01:00:09,800 INFO L854 garLoopResultBuilder]: At program point L764(lines 719 766) the Hoare annotation is: (let ((.cse0 (= |ULTIMATE.start_test_~splverifierCounter~0#1| 0)) (.cse1 (= 1 |ULTIMATE.start_valid_product_#res#1|)) (.cse2 (= 1 |ULTIMATE.start_main_~tmp~0#1|)) (.cse3 (not (= 0 ~systemActive~0)))) (or (and .cse0 (= ~pumpRunning~0 1) .cse1 .cse2 (<= ~waterLevel~0 2) .cse3) (and .cse0 (<= ~waterLevel~0 1) .cse1 .cse2 .cse3 (= ~pumpRunning~0 0)))) [2021-12-16 01:00:09,800 INFO L854 garLoopResultBuilder]: At program point L731(line 731) the Hoare annotation is: (let ((.cse0 (= |ULTIMATE.start_test_~splverifierCounter~0#1| 0)) (.cse1 (= 1 |ULTIMATE.start_valid_product_#res#1|)) (.cse2 (= 1 |ULTIMATE.start_main_~tmp~0#1|)) (.cse3 (not (= 0 ~systemActive~0)))) (or (and .cse0 (= ~pumpRunning~0 1) .cse1 .cse2 (<= ~waterLevel~0 2) .cse3) (and .cse0 (<= ~waterLevel~0 1) .cse1 .cse2 .cse3 (= ~pumpRunning~0 0)))) [2021-12-16 01:00:09,800 INFO L858 garLoopResultBuilder]: For program point L249(lines 249 256) no Hoare annotation was computed. [2021-12-16 01:00:09,800 INFO L858 garLoopResultBuilder]: For program point L249-2(lines 249 256) no Hoare annotation was computed. [2021-12-16 01:00:09,801 INFO L858 garLoopResultBuilder]: For program point L757(lines 757 761) no Hoare annotation was computed. [2021-12-16 01:00:09,801 INFO L854 garLoopResultBuilder]: At program point L757-2(lines 749 762) the Hoare annotation is: (let ((.cse0 (= |ULTIMATE.start_test_~splverifierCounter~0#1| 0)) (.cse1 (= 1 |ULTIMATE.start_valid_product_#res#1|)) (.cse2 (= 1 |ULTIMATE.start_main_~tmp~0#1|)) (.cse3 (<= ~waterLevel~0 2)) (.cse4 (not (= 0 ~systemActive~0)))) (or (and .cse0 (= ~pumpRunning~0 1) .cse1 .cse2 .cse3 .cse4) (and .cse0 .cse1 .cse2 .cse3 .cse4 (= ~pumpRunning~0 0)))) [2021-12-16 01:00:09,801 INFO L858 garLoopResultBuilder]: For program point L720(lines 719 766) no Hoare annotation was computed. [2021-12-16 01:00:09,801 INFO L858 garLoopResultBuilder]: For program point L749(lines 749 762) no Hoare annotation was computed. [2021-12-16 01:00:09,801 INFO L854 garLoopResultBuilder]: At program point L1005(lines 1000 1007) the Hoare annotation is: (let ((.cse0 (= |ULTIMATE.start_test_~splverifierCounter~0#1| 0)) (.cse1 (= 1 |ULTIMATE.start_valid_product_#res#1|)) (.cse2 (= 1 |ULTIMATE.start_main_~tmp~0#1|)) (.cse3 (<= ~waterLevel~0 2)) (.cse4 (not (= 0 ~systemActive~0)))) (or (and .cse0 (= ~pumpRunning~0 1) .cse1 .cse2 .cse3 .cse4) (and .cse0 .cse1 .cse2 .cse3 .cse4 (= ~pumpRunning~0 0)))) [2021-12-16 01:00:09,802 INFO L861 garLoopResultBuilder]: At program point L233(lines 226 235) the Hoare annotation is: true [2021-12-16 01:00:09,803 INFO L854 garLoopResultBuilder]: At program point L741(line 741) the Hoare annotation is: (let ((.cse0 (= |ULTIMATE.start_test_~splverifierCounter~0#1| 0)) (.cse1 (= 1 |ULTIMATE.start_valid_product_#res#1|)) (.cse2 (= 1 |ULTIMATE.start_main_~tmp~0#1|)) (.cse3 (<= ~waterLevel~0 2)) (.cse4 (not (= 0 ~systemActive~0)))) (or (and .cse0 (= ~pumpRunning~0 1) .cse1 .cse2 .cse3 .cse4) (and .cse0 .cse1 .cse2 .cse3 .cse4 (= ~pumpRunning~0 0)))) [2021-12-16 01:00:09,803 INFO L861 garLoopResultBuilder]: At program point L770(lines 709 774) the Hoare annotation is: true [2021-12-16 01:00:09,803 INFO L861 garLoopResultBuilder]: At program point L258(lines 239 261) the Hoare annotation is: true [2021-12-16 01:00:09,803 INFO L854 garLoopResultBuilder]: At program point processEnvironment__wrappee__highWaterSensorENTRY(lines 813 837) the Hoare annotation is: (let ((.cse0 (= 0 ~systemActive~0))) (and (or .cse0 (not (<= ~waterLevel~0 2)) (not (= |old(~pumpRunning~0)| 0)) (= ~pumpRunning~0 0)) (or .cse0 (not (<= ~waterLevel~0 1)) (= ~pumpRunning~0 |old(~pumpRunning~0)|) (not (= |old(~pumpRunning~0)| 1))))) [2021-12-16 01:00:09,803 INFO L854 garLoopResultBuilder]: At program point L832(line 832) the Hoare annotation is: (let ((.cse0 (= 0 ~systemActive~0))) (and (or .cse0 (not (<= ~waterLevel~0 2)) (not (= |old(~pumpRunning~0)| 0))) (or .cse0 (not (<= ~waterLevel~0 1)) (= ~pumpRunning~0 |old(~pumpRunning~0)|) (not (= |old(~pumpRunning~0)| 1))))) [2021-12-16 01:00:09,803 INFO L858 garLoopResultBuilder]: For program point L832-1(lines 813 837) no Hoare annotation was computed. [2021-12-16 01:00:09,803 INFO L854 garLoopResultBuilder]: At program point L977(lines 962 980) the Hoare annotation is: (let ((.cse4 (= ~pumpRunning~0 0)) (.cse5 (<= ~waterLevel~0 1))) (let ((.cse0 (= 0 ~systemActive~0)) (.cse1 (not .cse5)) (.cse2 (and (= |processEnvironment__wrappee__highWaterSensor_isHighWaterLevel_#res#1| 0) .cse5 (= |processEnvironment__wrappee__highWaterSensor_isHighWaterLevel_~tmp___0~2#1| 0) .cse4)) (.cse3 (not (= |old(~pumpRunning~0)| 0)))) (and (or .cse0 .cse1 (not (= |old(~pumpRunning~0)| 1))) (or .cse0 .cse2 (not (<= ~waterLevel~0 2)) .cse3 (and (<= 1 |processEnvironment__wrappee__highWaterSensor_isHighWaterLevel_#res#1|) (= |processEnvironment__wrappee__highWaterSensor_isHighWaterLevel_~tmp~9#1| 0) (<= 1 |processEnvironment__wrappee__highWaterSensor_isHighWaterLevel_~tmp___0~2#1|) .cse4 (= |processEnvironment__wrappee__highWaterSensor_isHighWaterSensorDry_#res#1| 0))) (or .cse0 .cse1 .cse2 .cse3)))) [2021-12-16 01:00:09,804 INFO L858 garLoopResultBuilder]: For program point L141(lines 141 147) no Hoare annotation was computed. [2021-12-16 01:00:09,804 INFO L858 garLoopResultBuilder]: For program point L971(lines 971 975) no Hoare annotation was computed. [2021-12-16 01:00:09,804 INFO L858 garLoopResultBuilder]: For program point L971-2(lines 971 975) no Hoare annotation was computed. [2021-12-16 01:00:09,804 INFO L854 garLoopResultBuilder]: At program point L895(lines 890 897) the Hoare annotation is: (let ((.cse0 (= 0 ~systemActive~0))) (and (or .cse0 (not (<= ~waterLevel~0 1)) (not (= |old(~pumpRunning~0)| 1))) (or .cse0 (not (<= ~waterLevel~0 2)) (not (= |old(~pumpRunning~0)| 0)) (and (= ~pumpRunning~0 1) (<= 1 |processEnvironment__wrappee__highWaterSensor_isHighWaterLevel_#res#1|) (<= 2 ~waterLevel~0) (= |processEnvironment__wrappee__highWaterSensor_isHighWaterLevel_~tmp~9#1| 0) (<= 1 |processEnvironment__wrappee__highWaterSensor_~tmp~6#1|) (<= 1 |processEnvironment__wrappee__highWaterSensor_isHighWaterLevel_~tmp___0~2#1|) (= |processEnvironment__wrappee__highWaterSensor_isHighWaterSensorDry_#res#1| 0))))) [2021-12-16 01:00:09,804 INFO L858 garLoopResultBuilder]: For program point processEnvironment__wrappee__highWaterSensorEXIT(lines 813 837) no Hoare annotation was computed. [2021-12-16 01:00:09,804 INFO L854 garLoopResultBuilder]: At program point L827(line 827) the Hoare annotation is: (let ((.cse0 (= 0 ~systemActive~0)) (.cse1 (<= ~waterLevel~0 1))) (and (or .cse0 (not .cse1) (not (= |old(~pumpRunning~0)| 1))) (or .cse0 (and (= |processEnvironment__wrappee__highWaterSensor_~tmp~6#1| 0) .cse1 (= ~pumpRunning~0 0)) (not (<= ~waterLevel~0 2)) (not (= |old(~pumpRunning~0)| 0))))) [2021-12-16 01:00:09,804 INFO L858 garLoopResultBuilder]: For program point L821(lines 821 829) no Hoare annotation was computed. [2021-12-16 01:00:09,804 INFO L854 garLoopResultBuilder]: At program point L146(lines 137 150) the Hoare annotation is: (let ((.cse0 (= 0 ~systemActive~0)) (.cse1 (<= ~waterLevel~0 1))) (and (or .cse0 (not .cse1) (not (= |old(~pumpRunning~0)| 1))) (let ((.cse2 (= ~pumpRunning~0 0))) (or .cse0 (and (<= 2 ~waterLevel~0) .cse2 (= |processEnvironment__wrappee__highWaterSensor_isHighWaterSensorDry_#res#1| 0)) (and .cse1 (<= 1 |processEnvironment__wrappee__highWaterSensor_isHighWaterSensorDry_#res#1|) .cse2) (not (<= ~waterLevel~0 2)) (not (= |old(~pumpRunning~0)| 0)))))) [2021-12-16 01:00:09,805 INFO L858 garLoopResultBuilder]: For program point L817(lines 817 834) no Hoare annotation was computed. [2021-12-16 01:00:09,805 INFO L858 garLoopResultBuilder]: For program point waterRiseEXIT(lines 72 83) no Hoare annotation was computed. [2021-12-16 01:00:09,805 INFO L858 garLoopResultBuilder]: For program point L76-1(lines 72 83) no Hoare annotation was computed. [2021-12-16 01:00:09,805 INFO L854 garLoopResultBuilder]: At program point waterRiseENTRY(lines 72 83) the Hoare annotation is: (let ((.cse1 (not (= ~pumpRunning~0 1))) (.cse0 (= 0 ~systemActive~0)) (.cse2 (= ~waterLevel~0 |old(~waterLevel~0)|)) (.cse3 (not (<= |old(~waterLevel~0)| 1)))) (and (or .cse0 .cse1 .cse2 .cse3) (or (not (<= 2 |old(~waterLevel~0)|)) .cse0 (not (<= |old(~waterLevel~0)| 2)) .cse1 (and (<= 2 ~waterLevel~0) (<= ~waterLevel~0 2))) (or .cse0 (not (= ~pumpRunning~0 0)) .cse2 .cse3))) [2021-12-16 01:00:09,805 INFO L854 garLoopResultBuilder]: At program point processEnvironment__wrappee__lowWaterSensorENTRY(lines 839 863) the Hoare annotation is: (let ((.cse0 (= 0 ~systemActive~0))) (and (or .cse0 (not (<= ~waterLevel~0 2)) (not (= |old(~pumpRunning~0)| 0)) (= ~pumpRunning~0 0)) (or .cse0 (not (<= ~waterLevel~0 1)) (= ~pumpRunning~0 |old(~pumpRunning~0)|) (not (= |old(~pumpRunning~0)| 1))))) [2021-12-16 01:00:09,806 INFO L854 garLoopResultBuilder]: At program point L853(line 853) the Hoare annotation is: (let ((.cse0 (= 0 ~systemActive~0))) (and (or .cse0 (not (<= ~waterLevel~0 2)) (not (= |old(~pumpRunning~0)| 0))) (or .cse0 (not (<= ~waterLevel~0 1)) (= ~pumpRunning~0 |old(~pumpRunning~0)|) (not (= |old(~pumpRunning~0)| 1))))) [2021-12-16 01:00:09,806 INFO L854 garLoopResultBuilder]: At program point L849(line 849) the Hoare annotation is: (let ((.cse0 (= 0 ~systemActive~0))) (and (or .cse0 (not (<= ~waterLevel~0 2)) (not (= |old(~pumpRunning~0)| 0))) (or .cse0 (not (<= ~waterLevel~0 1)) (= ~pumpRunning~0 |old(~pumpRunning~0)|) (not (= |old(~pumpRunning~0)| 1))))) [2021-12-16 01:00:09,806 INFO L858 garLoopResultBuilder]: For program point L847(lines 847 855) no Hoare annotation was computed. [2021-12-16 01:00:09,806 INFO L858 garLoopResultBuilder]: For program point L843(lines 843 860) no Hoare annotation was computed. [2021-12-16 01:00:09,807 INFO L854 garLoopResultBuilder]: At program point L996(lines 981 999) the Hoare annotation is: (let ((.cse0 (= 0 ~systemActive~0))) (and (or .cse0 (not (<= ~waterLevel~0 2)) (not (= |old(~pumpRunning~0)| 0))) (or .cse0 (not (<= ~waterLevel~0 1)) (= ~pumpRunning~0 |old(~pumpRunning~0)|) (not (= |old(~pumpRunning~0)| 1))))) [2021-12-16 01:00:09,807 INFO L858 garLoopResultBuilder]: For program point L990(lines 990 994) no Hoare annotation was computed. [2021-12-16 01:00:09,807 INFO L858 garLoopResultBuilder]: For program point processEnvironment__wrappee__lowWaterSensorEXIT(lines 839 863) no Hoare annotation was computed. [2021-12-16 01:00:09,807 INFO L854 garLoopResultBuilder]: At program point L156(lines 151 159) the Hoare annotation is: (let ((.cse0 (= 0 ~systemActive~0))) (and (or .cse0 (not (<= ~waterLevel~0 2)) (not (= |old(~pumpRunning~0)| 0))) (or .cse0 (not (<= ~waterLevel~0 1)) (= ~pumpRunning~0 |old(~pumpRunning~0)|) (not (= |old(~pumpRunning~0)| 1))))) [2021-12-16 01:00:09,807 INFO L858 garLoopResultBuilder]: For program point L990-2(lines 990 994) no Hoare annotation was computed. [2021-12-16 01:00:09,808 INFO L854 garLoopResultBuilder]: At program point L858(line 858) the Hoare annotation is: (let ((.cse0 (= 0 ~systemActive~0))) (and (or .cse0 (not (<= ~waterLevel~0 1)) (not (= |old(~pumpRunning~0)| 1))) (or .cse0 (not (<= ~waterLevel~0 2)) (not (= |old(~pumpRunning~0)| 0)) (= ~pumpRunning~0 0)))) [2021-12-16 01:00:09,808 INFO L858 garLoopResultBuilder]: For program point L858-1(lines 839 863) no Hoare annotation was computed. [2021-12-16 01:00:09,810 INFO L732 BasicCegarLoop]: Path program histogram: [1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2021-12-16 01:00:09,811 INFO L179 ceAbstractionStarter]: Computing trace abstraction results [2021-12-16 01:00:09,852 INFO L202 PluginConnector]: Adding new model de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction CFG 16.12 01:00:09 BoogieIcfgContainer [2021-12-16 01:00:09,855 INFO L132 PluginConnector]: ------------------------ END TraceAbstraction---------------------------- [2021-12-16 01:00:09,855 INFO L113 PluginConnector]: ------------------------Witness Printer---------------------------- [2021-12-16 01:00:09,856 INFO L271 PluginConnector]: Initializing Witness Printer... [2021-12-16 01:00:09,856 INFO L275 PluginConnector]: Witness Printer initialized [2021-12-16 01:00:09,856 INFO L185 PluginConnector]: Executing the observer RCFGCatcher from plugin Witness Printer for "de.uni_freiburg.informatik.ultimate.plugins.generator.rcfgbuilder CFG 16.12 01:00:00" (3/4) ... [2021-12-16 01:00:09,858 INFO L137 WitnessPrinter]: Generating witness for correct program [2021-12-16 01:00:09,862 INFO L354 RCFGBacktranslator]: Ignoring RootEdge to procedure deactivatePump [2021-12-16 01:00:09,863 INFO L354 RCFGBacktranslator]: Ignoring RootEdge to procedure processEnvironment__wrappee__base [2021-12-16 01:00:09,863 INFO L354 RCFGBacktranslator]: Ignoring RootEdge to procedure changeMethaneLevel [2021-12-16 01:00:09,863 INFO L354 RCFGBacktranslator]: Ignoring RootEdge to procedure timeShift [2021-12-16 01:00:09,863 INFO L354 RCFGBacktranslator]: Ignoring RootEdge to procedure cleanup [2021-12-16 01:00:09,863 INFO L354 RCFGBacktranslator]: Ignoring RootEdge to procedure isMethaneLevelCritical [2021-12-16 01:00:09,863 INFO L354 RCFGBacktranslator]: Ignoring RootEdge to procedure processEnvironment__wrappee__highWaterSensor [2021-12-16 01:00:09,864 INFO L354 RCFGBacktranslator]: Ignoring RootEdge to procedure waterRise [2021-12-16 01:00:09,864 INFO L354 RCFGBacktranslator]: Ignoring RootEdge to procedure processEnvironment__wrappee__lowWaterSensor [2021-12-16 01:00:09,872 INFO L910 BoogieBacktranslator]: Reduced CFG by removing 55 nodes and edges [2021-12-16 01:00:09,873 INFO L910 BoogieBacktranslator]: Reduced CFG by removing 22 nodes and edges [2021-12-16 01:00:09,873 INFO L910 BoogieBacktranslator]: Reduced CFG by removing 11 nodes and edges [2021-12-16 01:00:09,873 INFO L910 BoogieBacktranslator]: Reduced CFG by removing 5 nodes and edges [2021-12-16 01:00:09,874 INFO L910 BoogieBacktranslator]: Reduced CFG by removing 2 nodes and edges [2021-12-16 01:00:09,874 INFO L910 BoogieBacktranslator]: Reduced CFG by removing 1 nodes and edges [2021-12-16 01:00:09,874 INFO L910 BoogieBacktranslator]: Reduced CFG by removing 1 nodes and edges [2021-12-16 01:00:09,889 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (((waterLevel == 1 && methaneLevelCritical == 0) && 1 == \result) && !(0 == systemActive)) && pumpRunning == 0 [2021-12-16 01:00:09,889 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: ((((waterLevel == 1 && methaneLevelCritical == 0) && 1 == \result) && 1 == tmp) && !(0 == systemActive)) && pumpRunning == 0 [2021-12-16 01:00:09,889 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (((((splverifierCounter == 0 && pumpRunning == 1) && 1 == \result) && 1 == tmp) && waterLevel <= 2) && !(0 == systemActive)) || (((((splverifierCounter == 0 && waterLevel <= 1) && 1 == \result) && 1 == tmp) && !(0 == systemActive)) && pumpRunning == 0) [2021-12-16 01:00:09,890 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (((0 == systemActive || !(\old(waterLevel) <= 2)) || ((waterLevel <= \old(waterLevel) && waterLevel <= 1) && pumpRunning == \old(pumpRunning))) || !(\old(pumpRunning) == 1)) && ((0 == systemActive || !(\old(waterLevel) <= 2)) || !(\old(pumpRunning) == 0)) [2021-12-16 01:00:09,891 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (((((0 == systemActive || (waterLevel == \old(waterLevel) && 2 <= waterLevel)) || !(\old(waterLevel) <= 2)) || (waterLevel == \old(waterLevel) && pumpRunning == 0)) || !(\old(pumpRunning) == 0)) && ((((0 == systemActive || !(\old(waterLevel) <= 2)) || ((waterLevel <= \old(waterLevel) && waterLevel <= 1) && pumpRunning == \old(pumpRunning))) || ((waterLevel <= \old(waterLevel) && waterLevel <= 1) && pumpRunning == 0)) || !(\old(pumpRunning) == 1))) && ((((!(2 <= \old(waterLevel)) || 0 == systemActive) || !(\old(waterLevel) <= 2)) || pumpRunning == 1) || !(\old(pumpRunning) == 0)) [2021-12-16 01:00:09,892 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (((((splverifierCounter == 0 && pumpRunning == 1) && 1 == \result) && 1 == tmp) && waterLevel <= 2) && !(0 == systemActive)) || (((((splverifierCounter == 0 && 1 == \result) && 1 == tmp) && waterLevel <= 2) && !(0 == systemActive)) && pumpRunning == 0) [2021-12-16 01:00:09,892 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (((((((0 == systemActive || (tmp___0 <= 1 && \result <= 1)) || !(\old(waterLevel) <= 2)) || !(\old(pumpRunning) == 0)) || ((((methaneLevelCritical == tmp && pumpRunning == 1) && waterLevel == \old(waterLevel)) && 2 <= waterLevel) && !(0 == systemActive))) || !(methaneLevelCritical == 0)) && ((((0 == systemActive || (tmp___0 <= 1 && \result <= 1)) || !(\old(waterLevel) <= 2)) || !(methaneLevelCritical == 0)) || !(\old(pumpRunning) == 1))) && ((((0 == systemActive || !(\old(waterLevel) <= 2)) || !(\old(pumpRunning) == 0)) || ((((methaneLevelCritical == tmp && pumpRunning == 1) && waterLevel == \old(waterLevel)) && 2 <= waterLevel) && !(0 == systemActive))) || (((methaneLevelCritical == tmp && waterLevel <= 1) && waterLevel == \old(waterLevel)) && pumpRunning == 0))) && ((((0 == systemActive || !(\old(waterLevel) <= 2)) || (((waterLevel <= \old(waterLevel) && methaneLevelCritical == tmp) && waterLevel <= 1) && pumpRunning == \old(pumpRunning))) || (((waterLevel <= \old(waterLevel) && methaneLevelCritical == tmp) && waterLevel <= 1) && pumpRunning == 0)) || !(\old(pumpRunning) == 1)) [2021-12-16 01:00:09,892 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (((0 == systemActive || !(\old(waterLevel) <= 2)) || ((waterLevel <= \old(waterLevel) && waterLevel <= 1) && pumpRunning == \old(pumpRunning))) || !(\old(pumpRunning) == 1)) && ((0 == systemActive || !(\old(waterLevel) <= 2)) || !(\old(pumpRunning) == 0)) [2021-12-16 01:00:09,893 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (((((0 == systemActive || !(\old(waterLevel) == 1)) || \result == 1) || !(\old(pumpRunning) == 0)) && ((((0 == systemActive || (((methaneLevelCritical == tmp && pumpRunning == 1) && waterLevel == \old(waterLevel)) && 2 <= waterLevel)) || !(\old(waterLevel) <= 2)) || ((((methaneLevelCritical == tmp && waterLevel <= 1) && \result <= 1) && waterLevel == \old(waterLevel)) && pumpRunning == 0)) || !(\old(pumpRunning) == 0))) && ((((0 == systemActive || (((((waterLevel <= \old(waterLevel) && methaneLevelCritical == tmp) && waterLevel <= 1) && \result <= 1) && methaneLevelCritical == 0) && pumpRunning == 0)) || (((((waterLevel <= \old(waterLevel) && methaneLevelCritical == tmp) && waterLevel <= 1) && \result <= 1) && methaneLevelCritical == 0) && pumpRunning == \old(pumpRunning))) || !(\old(waterLevel) <= 2)) || !(\old(pumpRunning) == 1))) && (((0 == systemActive || !(\old(waterLevel) <= 2)) || !(\old(pumpRunning) == 0)) || 0 == methaneLevelCritical) [2021-12-16 01:00:09,893 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: ((0 == systemActive || !(waterLevel <= 2)) || !(\old(pumpRunning) == 0)) && (((0 == systemActive || !(waterLevel <= 1)) || pumpRunning == \old(pumpRunning)) || !(\old(pumpRunning) == 1)) [2021-12-16 01:00:09,893 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: ((0 == systemActive || !(waterLevel <= 1)) || !(\old(pumpRunning) == 1)) && ((((0 == systemActive || ((2 <= waterLevel && pumpRunning == 0) && \result == 0)) || ((waterLevel <= 1 && 1 <= \result) && pumpRunning == 0)) || !(waterLevel <= 2)) || !(\old(pumpRunning) == 0)) [2021-12-16 01:00:09,893 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: ((0 == systemActive || !(waterLevel <= 2)) || !(\old(pumpRunning) == 0)) && (((0 == systemActive || !(waterLevel <= 1)) || pumpRunning == \old(pumpRunning)) || !(\old(pumpRunning) == 1)) [2021-12-16 01:00:09,893 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: ((0 == systemActive || !(\old(waterLevel) <= 2)) || !(\old(pumpRunning) == 1)) && (((0 == systemActive || !(\old(waterLevel) <= 2)) || !(\old(pumpRunning) == 0)) || (((((\result == 1 && methaneLevelCritical == tmp) && pumpRunning == 1) && waterLevel == \old(waterLevel)) && methaneLevelCritical == 0) && 2 <= waterLevel)) [2021-12-16 01:00:09,894 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (((0 == systemActive || !(waterLevel <= 1)) || !(\old(pumpRunning) == 1)) && ((((0 == systemActive || (((\result == 0 && waterLevel <= 1) && tmp___0 == 0) && pumpRunning == 0)) || !(waterLevel <= 2)) || !(\old(pumpRunning) == 0)) || ((((1 <= \result && tmp == 0) && 1 <= tmp___0) && pumpRunning == 0) && \result == 0))) && (((0 == systemActive || !(waterLevel <= 1)) || (((\result == 0 && waterLevel <= 1) && tmp___0 == 0) && pumpRunning == 0)) || !(\old(pumpRunning) == 0)) [2021-12-16 01:00:09,896 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: ((0 == systemActive || !(\old(waterLevel) <= 2)) || !(\old(pumpRunning) == 1)) && ((0 == systemActive || !(\old(waterLevel) <= 2)) || !(\old(pumpRunning) == 0)) [2021-12-16 01:00:09,896 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: ((0 == systemActive || !(waterLevel <= 1)) || !(\old(pumpRunning) == 1)) && (((0 == systemActive || !(waterLevel <= 2)) || !(\old(pumpRunning) == 0)) || ((((((pumpRunning == 1 && 1 <= \result) && 2 <= waterLevel) && tmp == 0) && 1 <= tmp) && 1 <= tmp___0) && \result == 0)) [2021-12-16 01:00:09,927 INFO L141 WitnessManager]: Wrote witness to /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/witness.graphml [2021-12-16 01:00:09,928 INFO L132 PluginConnector]: ------------------------ END Witness Printer---------------------------- [2021-12-16 01:00:09,928 INFO L158 Benchmark]: Toolchain (without parser) took 10698.01ms. Allocated memory was 86.0MB in the beginning and 182.5MB in the end (delta: 96.5MB). Free memory was 47.2MB in the beginning and 92.0MB in the end (delta: -44.7MB). Peak memory consumption was 52.2MB. Max. memory is 16.1GB. [2021-12-16 01:00:09,928 INFO L158 Benchmark]: CDTParser took 0.18ms. Allocated memory is still 86.0MB. Free memory is still 64.2MB. There was no memory consumed. Max. memory is 16.1GB. [2021-12-16 01:00:09,929 INFO L158 Benchmark]: CACSL2BoogieTranslator took 382.54ms. Allocated memory is still 86.0MB. Free memory was 47.0MB in the beginning and 53.6MB in the end (delta: -6.5MB). Peak memory consumption was 8.6MB. Max. memory is 16.1GB. [2021-12-16 01:00:09,929 INFO L158 Benchmark]: Boogie Procedure Inliner took 66.67ms. Allocated memory is still 86.0MB. Free memory was 53.6MB in the beginning and 51.1MB in the end (delta: 2.5MB). Peak memory consumption was 2.1MB. Max. memory is 16.1GB. [2021-12-16 01:00:09,929 INFO L158 Benchmark]: Boogie Preprocessor took 41.54ms. Allocated memory is still 86.0MB. Free memory was 51.1MB in the beginning and 49.4MB in the end (delta: 1.7MB). Peak memory consumption was 2.1MB. Max. memory is 16.1GB. [2021-12-16 01:00:09,930 INFO L158 Benchmark]: RCFGBuilder took 625.48ms. Allocated memory was 86.0MB in the beginning and 104.9MB in the end (delta: 18.9MB). Free memory was 49.4MB in the beginning and 80.2MB in the end (delta: -30.8MB). Peak memory consumption was 19.4MB. Max. memory is 16.1GB. [2021-12-16 01:00:09,930 INFO L158 Benchmark]: TraceAbstraction took 9489.77ms. Allocated memory was 104.9MB in the beginning and 182.5MB in the end (delta: 77.6MB). Free memory was 79.7MB in the beginning and 99.3MB in the end (delta: -19.6MB). Peak memory consumption was 89.4MB. Max. memory is 16.1GB. [2021-12-16 01:00:09,930 INFO L158 Benchmark]: Witness Printer took 72.35ms. Allocated memory is still 182.5MB. Free memory was 99.3MB in the beginning and 92.0MB in the end (delta: 7.3MB). Peak memory consumption was 8.4MB. Max. memory is 16.1GB. [2021-12-16 01:00:09,933 INFO L339 ainManager$Toolchain]: ####################### End [Toolchain 1] ####################### --- Results --- * Results from de.uni_freiburg.informatik.ultimate.core: - StatisticsResult: Toolchain Benchmarks Benchmark results are: * CDTParser took 0.18ms. Allocated memory is still 86.0MB. Free memory is still 64.2MB. There was no memory consumed. Max. memory is 16.1GB. * CACSL2BoogieTranslator took 382.54ms. Allocated memory is still 86.0MB. Free memory was 47.0MB in the beginning and 53.6MB in the end (delta: -6.5MB). Peak memory consumption was 8.6MB. Max. memory is 16.1GB. * Boogie Procedure Inliner took 66.67ms. Allocated memory is still 86.0MB. Free memory was 53.6MB in the beginning and 51.1MB in the end (delta: 2.5MB). Peak memory consumption was 2.1MB. Max. memory is 16.1GB. * Boogie Preprocessor took 41.54ms. Allocated memory is still 86.0MB. Free memory was 51.1MB in the beginning and 49.4MB in the end (delta: 1.7MB). Peak memory consumption was 2.1MB. Max. memory is 16.1GB. * RCFGBuilder took 625.48ms. Allocated memory was 86.0MB in the beginning and 104.9MB in the end (delta: 18.9MB). Free memory was 49.4MB in the beginning and 80.2MB in the end (delta: -30.8MB). Peak memory consumption was 19.4MB. Max. memory is 16.1GB. * TraceAbstraction took 9489.77ms. Allocated memory was 104.9MB in the beginning and 182.5MB in the end (delta: 77.6MB). Free memory was 79.7MB in the beginning and 99.3MB in the end (delta: -19.6MB). Peak memory consumption was 89.4MB. Max. memory is 16.1GB. * Witness Printer took 72.35ms. Allocated memory is still 182.5MB. Free memory was 99.3MB in the beginning and 92.0MB in the end (delta: 7.3MB). Peak memory consumption was 8.4MB. Max. memory is 16.1GB. * Results from de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction: - StatisticsResult: ErrorAutomatonStatistics NumberErrorTraces: 0, NumberStatementsAllTraces: 0, NumberRelevantStatements: 0, 0.0s ErrorAutomatonConstructionTimeTotal, 0.0s FaulLocalizationTime, NumberStatementsFirstTrace: -1, TraceLengthAvg: 0, 0.0s ErrorAutomatonConstructionTimeAvg, 0.0s ErrorAutomatonDifferenceTimeAvg, 0.0s ErrorAutomatonDifferenceTimeTotal, NumberOfNoEnhancement: 0, NumberOfFiniteEnhancement: 0, NumberOfInfiniteEnhancement: 0 - PositiveResult [Line: 267]: call to reach_error is unreachable For all program executions holds that call to reach_error is unreachable at this location - StatisticsResult: Ultimate Automizer benchmark data CFG has 10 procedures, 103 locations, 1 error locations. Started 1 CEGAR loops. OverallTime: 9.3s, OverallIterations: 12, TraceHistogramMax: 3, PathProgramHistogramMax: 1, EmptinessCheckTime: 0.0s, AutomataDifference: 3.3s, DeadEndRemovalTime: 0.0s, HoareAnnotationTime: 3.6s, InitialAbstractionConstructionTime: 0.0s, PartialOrderReductionTime: 0.0s, HoareTripleCheckerStatistics: 0 mSolverCounterUnknown, 2459 SdHoareTripleChecker+Valid, 2.0s IncrementalHoareTripleChecker+Time, 0 mSdLazyCounter, 2421 mSDsluCounter, 4534 SdHoareTripleChecker+Invalid, 1.6s Time, 0 mProtectedAction, 0 SdHoareTripleChecker+Unchecked, 0 IncrementalHoareTripleChecker+Unchecked, 3066 mSDsCounter, 941 IncrementalHoareTripleChecker+Valid, 0 mProtectedPredicate, 2886 IncrementalHoareTripleChecker+Invalid, 3827 SdHoareTripleChecker+Unknown, 0 mSolverCounterNotChecked, 941 mSolverCounterUnsat, 1468 mSDtfsCounter, 2886 mSolverCounterSat, 0.0s SdHoareTripleChecker+Time, 0 IncrementalHoareTripleChecker+Unknown, PredicateUnifierStatistics: 0 DeclaredPredicates, 428 GetRequests, 292 SyntacticMatches, 2 SemanticMatches, 134 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 1237 ImplicationChecksByTransitivity, 1.0s Time, 0.0s BasicInterpolantAutomatonTime, BiggestAbstraction: size=332occurred in iteration=9, InterpolantAutomatonStates: 125, traceCheckStatistics: No data available, InterpolantConsolidationStatistics: No data available, PathInvariantsStatistics: No data available, 0/0 InterpolantCoveringCapability, TotalInterpolationStatistics: No data available, 0.0s DumpTime, AutomataMinimizationStatistics: 0.2s AutomataMinimizationTime, 12 MinimizatonAttempts, 53 StatesRemovedByMinimization, 8 NontrivialMinimizations, HoareAnnotationStatistics: 0.0s HoareAnnotationTime, 48 LocationsWithAnnotation, 1415 PreInvPairs, 1666 NumberOfFragments, 1600 HoareAnnotationTreeSize, 1415 FomulaSimplifications, 132 FormulaSimplificationTreeSizeReduction, 0.2s HoareSimplificationTime, 48 FomulaSimplificationsInter, 13045 FormulaSimplificationTreeSizeReductionInter, 3.3s HoareSimplificationTimeInter, RefinementEngineStatistics: TRACE_CHECK: 0.0s SsaConstructionTime, 0.2s SatisfiabilityAnalysisTime, 1.4s InterpolantComputationTime, 676 NumberOfCodeBlocks, 676 NumberOfCodeBlocksAsserted, 13 NumberOfCheckSat, 753 ConstructedInterpolants, 0 QuantifiedInterpolants, 1392 SizeOfPredicates, 4 NumberOfNonLiveVariables, 455 ConjunctsInSsa, 13 ConjunctsInUnsatCore, 14 InterpolantComputations, 11 PerfectInterpolantSequences, 64/84 InterpolantCoveringCapability, INVARIANT_SYNTHESIS: No data available, INTERPOLANT_CONSOLIDATION: No data available, ABSTRACT_INTERPRETATION: No data available, PDR: No data available, ACCELERATED_INTERPOLATION: No data available, SIFA: No data available, ReuseStatistics: No data available - AllSpecificationsHoldResult: All specifications hold 1 specifications checked. All of them hold - InvariantResult [Line: 325]: Loop Invariant Derived loop invariant: ((waterLevel == 1 && methaneLevelCritical == 0) && !(0 == systemActive)) && pumpRunning == 0 - InvariantResult [Line: 890]: Loop Invariant Derived loop invariant: ((0 == systemActive || !(waterLevel <= 1)) || !(\old(pumpRunning) == 1)) && (((0 == systemActive || !(waterLevel <= 2)) || !(\old(pumpRunning) == 0)) || ((((((pumpRunning == 1 && 1 <= \result) && 2 <= waterLevel) && tmp == 0) && 1 <= tmp) && 1 <= tmp___0) && \result == 0)) - InvariantResult [Line: 917]: Loop Invariant Derived loop invariant: ((0 == systemActive || !(\old(waterLevel) <= 2)) || !(\old(pumpRunning) == 1)) && (((0 == systemActive || !(\old(waterLevel) <= 2)) || !(\old(pumpRunning) == 0)) || (((((\result == 1 && methaneLevelCritical == tmp) && pumpRunning == 1) && waterLevel == \old(waterLevel)) && methaneLevelCritical == 0) && 2 <= waterLevel)) - InvariantResult [Line: 318]: Loop Invariant Derived loop invariant: ((waterLevel == 1 && methaneLevelCritical == 0) && !(0 == systemActive)) && pumpRunning == 0 - InvariantResult [Line: 128]: Loop Invariant Derived loop invariant: (((((0 == systemActive || !(\old(waterLevel) == 1)) || \result == 1) || !(\old(pumpRunning) == 0)) && ((((0 == systemActive || (((methaneLevelCritical == tmp && pumpRunning == 1) && waterLevel == \old(waterLevel)) && 2 <= waterLevel)) || !(\old(waterLevel) <= 2)) || ((((methaneLevelCritical == tmp && waterLevel <= 1) && \result <= 1) && waterLevel == \old(waterLevel)) && pumpRunning == 0)) || !(\old(pumpRunning) == 0))) && ((((0 == systemActive || (((((waterLevel <= \old(waterLevel) && methaneLevelCritical == tmp) && waterLevel <= 1) && \result <= 1) && methaneLevelCritical == 0) && pumpRunning == 0)) || (((((waterLevel <= \old(waterLevel) && methaneLevelCritical == tmp) && waterLevel <= 1) && \result <= 1) && methaneLevelCritical == 0) && pumpRunning == \old(pumpRunning))) || !(\old(waterLevel) <= 2)) || !(\old(pumpRunning) == 1))) && (((0 == systemActive || !(\old(waterLevel) <= 2)) || !(\old(pumpRunning) == 0)) || 0 == methaneLevelCritical) - InvariantResult [Line: 263]: Loop Invariant Derived loop invariant: ((0 == systemActive || !(\old(waterLevel) <= 2)) || !(\old(pumpRunning) == 1)) && ((0 == systemActive || !(\old(waterLevel) <= 2)) || !(\old(pumpRunning) == 0)) - InvariantResult [Line: 906]: Loop Invariant Derived loop invariant: (((0 == systemActive || !(\old(waterLevel) <= 2)) || ((waterLevel <= \old(waterLevel) && waterLevel <= 1) && pumpRunning == \old(pumpRunning))) || !(\old(pumpRunning) == 1)) && ((0 == systemActive || !(\old(waterLevel) <= 2)) || !(\old(pumpRunning) == 0)) - InvariantResult [Line: 173]: Loop Invariant Derived loop invariant: 1 - InvariantResult [Line: 718]: Loop Invariant Derived loop invariant: 0 - InvariantResult [Line: 163]: Loop Invariant Derived loop invariant: 1 - InvariantResult [Line: 962]: Loop Invariant Derived loop invariant: (((0 == systemActive || !(waterLevel <= 1)) || !(\old(pumpRunning) == 1)) && ((((0 == systemActive || (((\result == 0 && waterLevel <= 1) && tmp___0 == 0) && pumpRunning == 0)) || !(waterLevel <= 2)) || !(\old(pumpRunning) == 0)) || ((((1 <= \result && tmp == 0) && 1 <= tmp___0) && pumpRunning == 0) && \result == 0))) && (((0 == systemActive || !(waterLevel <= 1)) || (((\result == 0 && waterLevel <= 1) && tmp___0 == 0) && pumpRunning == 0)) || !(\old(pumpRunning) == 0)) - InvariantResult [Line: 332]: Loop Invariant Derived loop invariant: (((waterLevel == 1 && methaneLevelCritical == 0) && 1 == \result) && !(0 == systemActive)) && pumpRunning == 0 - InvariantResult [Line: 60]: Loop Invariant Derived loop invariant: (((0 == systemActive || !(\old(waterLevel) <= 2)) || ((waterLevel <= \old(waterLevel) && waterLevel <= 1) && pumpRunning == \old(pumpRunning))) || !(\old(pumpRunning) == 1)) && ((0 == systemActive || !(\old(waterLevel) <= 2)) || !(\old(pumpRunning) == 0)) - InvariantResult [Line: 981]: Loop Invariant Derived loop invariant: ((0 == systemActive || !(waterLevel <= 2)) || !(\old(pumpRunning) == 0)) && (((0 == systemActive || !(waterLevel <= 1)) || pumpRunning == \old(pumpRunning)) || !(\old(pumpRunning) == 1)) - InvariantResult [Line: 719]: Loop Invariant Derived loop invariant: (((((splverifierCounter == 0 && pumpRunning == 1) && 1 == \result) && 1 == tmp) && waterLevel <= 2) && !(0 == systemActive)) || (((((splverifierCounter == 0 && waterLevel <= 1) && 1 == \result) && 1 == tmp) && !(0 == systemActive)) && pumpRunning == 0) - InvariantResult [Line: 151]: Loop Invariant Derived loop invariant: ((0 == systemActive || !(waterLevel <= 2)) || !(\old(pumpRunning) == 0)) && (((0 == systemActive || !(waterLevel <= 1)) || pumpRunning == \old(pumpRunning)) || !(\old(pumpRunning) == 1)) - InvariantResult [Line: 865]: Loop Invariant Derived loop invariant: (((((0 == systemActive || (waterLevel == \old(waterLevel) && 2 <= waterLevel)) || !(\old(waterLevel) <= 2)) || (waterLevel == \old(waterLevel) && pumpRunning == 0)) || !(\old(pumpRunning) == 0)) && ((((0 == systemActive || !(\old(waterLevel) <= 2)) || ((waterLevel <= \old(waterLevel) && waterLevel <= 1) && pumpRunning == \old(pumpRunning))) || ((waterLevel <= \old(waterLevel) && waterLevel <= 1) && pumpRunning == 0)) || !(\old(pumpRunning) == 1))) && ((((!(2 <= \old(waterLevel)) || 0 == systemActive) || !(\old(waterLevel) <= 2)) || pumpRunning == 1) || !(\old(pumpRunning) == 0)) - InvariantResult [Line: 137]: Loop Invariant Derived loop invariant: ((0 == systemActive || !(waterLevel <= 1)) || !(\old(pumpRunning) == 1)) && ((((0 == systemActive || ((2 <= waterLevel && pumpRunning == 0) && \result == 0)) || ((waterLevel <= 1 && 1 <= \result) && pumpRunning == 0)) || !(waterLevel <= 2)) || !(\old(pumpRunning) == 0)) - InvariantResult [Line: 239]: Loop Invariant Derived loop invariant: 1 - InvariantResult [Line: 226]: Loop Invariant Derived loop invariant: 1 - InvariantResult [Line: 273]: Loop Invariant Derived loop invariant: (((((((0 == systemActive || (tmp___0 <= 1 && \result <= 1)) || !(\old(waterLevel) <= 2)) || !(\old(pumpRunning) == 0)) || ((((methaneLevelCritical == tmp && pumpRunning == 1) && waterLevel == \old(waterLevel)) && 2 <= waterLevel) && !(0 == systemActive))) || !(methaneLevelCritical == 0)) && ((((0 == systemActive || (tmp___0 <= 1 && \result <= 1)) || !(\old(waterLevel) <= 2)) || !(methaneLevelCritical == 0)) || !(\old(pumpRunning) == 1))) && ((((0 == systemActive || !(\old(waterLevel) <= 2)) || !(\old(pumpRunning) == 0)) || ((((methaneLevelCritical == tmp && pumpRunning == 1) && waterLevel == \old(waterLevel)) && 2 <= waterLevel) && !(0 == systemActive))) || (((methaneLevelCritical == tmp && waterLevel <= 1) && waterLevel == \old(waterLevel)) && pumpRunning == 0))) && ((((0 == systemActive || !(\old(waterLevel) <= 2)) || (((waterLevel <= \old(waterLevel) && methaneLevelCritical == tmp) && waterLevel <= 1) && pumpRunning == \old(pumpRunning))) || (((waterLevel <= \old(waterLevel) && methaneLevelCritical == tmp) && waterLevel <= 1) && pumpRunning == 0)) || !(\old(pumpRunning) == 1)) - InvariantResult [Line: 709]: Loop Invariant Derived loop invariant: 1 - InvariantResult [Line: 218]: Loop Invariant Derived loop invariant: ((((waterLevel == 1 && methaneLevelCritical == 0) && 1 == \result) && 1 == tmp) && !(0 == systemActive)) && pumpRunning == 0 - InvariantResult [Line: 1000]: Loop Invariant Derived loop invariant: (((((splverifierCounter == 0 && pumpRunning == 1) && 1 == \result) && 1 == tmp) && waterLevel <= 2) && !(0 == systemActive)) || (((((splverifierCounter == 0 && 1 == \result) && 1 == tmp) && waterLevel <= 2) && !(0 == systemActive)) && pumpRunning == 0) RESULT: Ultimate proved your program to be correct! [2021-12-16 01:00:09,974 INFO L540 MonitoredProcess]: [MP /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in -t:2000 (1)] Forceful destruction successful, exit code 0 Received shutdown request... --- End real Ultimate output --- Execution finished normally Writing output log to file Ultimate.log Result: TRUE