./Ultimate.py --spec ../sv-benchmarks/c/properties/unreach-call.prp --file ../sv-benchmarks/c/product-lines/minepump_spec4_product58.cil.c --full-output --architecture 32bit -------------------------------------------------------------------------------- Checking for ERROR reachability Using default analysis Version c3fed411 Calling Ultimate with: /usr/bin/java -Dosgi.configuration.area=/storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/data/config -Xmx15G -Xms4m -jar /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/plugins/org.eclipse.equinox.launcher_1.5.800.v20200727-1323.jar -data @noDefault -ultimatedata /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/data -tc /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/config/AutomizerReach.xml -i ../sv-benchmarks/c/product-lines/minepump_spec4_product58.cil.c -s /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/config/svcomp-Reach-32bit-Automizer_Default.epf --cacsl2boogietranslator.entry.function main --witnessprinter.witness.directory /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux --witnessprinter.witness.filename witness.graphml --witnessprinter.write.witness.besides.input.file false --witnessprinter.graph.data.specification CHECK( init(main()), LTL(G ! call(reach_error())) ) --witnessprinter.graph.data.producer Automizer --witnessprinter.graph.data.architecture 32bit --witnessprinter.graph.data.programhash debcf50bf3bb3961401c62ca4b7217ea7cc93038f750143121614e56b550164d --- Real Ultimate output --- This is Ultimate 0.2.2-tmp.no-commuhash-c3fed41 [2021-12-16 01:00:43,483 INFO L177 SettingsManager]: Resetting all preferences to default values... [2021-12-16 01:00:43,493 INFO L181 SettingsManager]: Resetting UltimateCore preferences to default values [2021-12-16 01:00:43,534 INFO L184 SettingsManager]: Ultimate Commandline Interface provides no preferences, ignoring... [2021-12-16 01:00:43,534 INFO L181 SettingsManager]: Resetting Boogie Preprocessor preferences to default values [2021-12-16 01:00:43,537 INFO L181 SettingsManager]: Resetting Boogie Procedure Inliner preferences to default values [2021-12-16 01:00:43,539 INFO L181 SettingsManager]: Resetting Abstract Interpretation preferences to default values [2021-12-16 01:00:43,544 INFO L181 SettingsManager]: Resetting LassoRanker preferences to default values [2021-12-16 01:00:43,546 INFO L181 SettingsManager]: Resetting Reaching Definitions preferences to default values [2021-12-16 01:00:43,548 INFO L181 SettingsManager]: Resetting SyntaxChecker preferences to default values [2021-12-16 01:00:43,549 INFO L181 SettingsManager]: Resetting Sifa preferences to default values [2021-12-16 01:00:43,551 INFO L184 SettingsManager]: Büchi Program Product provides no preferences, ignoring... [2021-12-16 01:00:43,551 INFO L181 SettingsManager]: Resetting LTL2Aut preferences to default values [2021-12-16 01:00:43,557 INFO L181 SettingsManager]: Resetting PEA to Boogie preferences to default values [2021-12-16 01:00:43,558 INFO L181 SettingsManager]: Resetting BlockEncodingV2 preferences to default values [2021-12-16 01:00:43,560 INFO L181 SettingsManager]: Resetting ChcToBoogie preferences to default values [2021-12-16 01:00:43,565 INFO L181 SettingsManager]: Resetting AutomataScriptInterpreter preferences to default values [2021-12-16 01:00:43,566 INFO L181 SettingsManager]: Resetting BuchiAutomizer preferences to default values [2021-12-16 01:00:43,567 INFO L181 SettingsManager]: Resetting CACSL2BoogieTranslator preferences to default values [2021-12-16 01:00:43,569 INFO L181 SettingsManager]: Resetting CodeCheck preferences to default values [2021-12-16 01:00:43,573 INFO L181 SettingsManager]: Resetting InvariantSynthesis preferences to default values [2021-12-16 01:00:43,574 INFO L181 SettingsManager]: Resetting RCFGBuilder preferences to default values [2021-12-16 01:00:43,575 INFO L181 SettingsManager]: Resetting Referee preferences to default values [2021-12-16 01:00:43,576 INFO L181 SettingsManager]: Resetting TraceAbstraction preferences to default values [2021-12-16 01:00:43,578 INFO L184 SettingsManager]: TraceAbstractionConcurrent provides no preferences, ignoring... [2021-12-16 01:00:43,579 INFO L184 SettingsManager]: TraceAbstractionWithAFAs provides no preferences, ignoring... [2021-12-16 01:00:43,579 INFO L181 SettingsManager]: Resetting TreeAutomizer preferences to default values [2021-12-16 01:00:43,580 INFO L181 SettingsManager]: Resetting IcfgToChc preferences to default values [2021-12-16 01:00:43,580 INFO L181 SettingsManager]: Resetting IcfgTransformer preferences to default values [2021-12-16 01:00:43,581 INFO L184 SettingsManager]: ReqToTest provides no preferences, ignoring... [2021-12-16 01:00:43,581 INFO L181 SettingsManager]: Resetting Boogie Printer preferences to default values [2021-12-16 01:00:43,582 INFO L181 SettingsManager]: Resetting ChcSmtPrinter preferences to default values [2021-12-16 01:00:43,583 INFO L181 SettingsManager]: Resetting ReqPrinter preferences to default values [2021-12-16 01:00:43,583 INFO L181 SettingsManager]: Resetting Witness Printer preferences to default values [2021-12-16 01:00:43,585 INFO L184 SettingsManager]: Boogie PL CUP Parser provides no preferences, ignoring... [2021-12-16 01:00:43,585 INFO L181 SettingsManager]: Resetting CDTParser preferences to default values [2021-12-16 01:00:43,586 INFO L184 SettingsManager]: AutomataScriptParser provides no preferences, ignoring... [2021-12-16 01:00:43,587 INFO L184 SettingsManager]: ReqParser provides no preferences, ignoring... [2021-12-16 01:00:43,587 INFO L181 SettingsManager]: Resetting SmtParser preferences to default values [2021-12-16 01:00:43,588 INFO L181 SettingsManager]: Resetting Witness Parser preferences to default values [2021-12-16 01:00:43,588 INFO L188 SettingsManager]: Finished resetting all preferences to default values... [2021-12-16 01:00:43,589 INFO L101 SettingsManager]: Beginning loading settings from /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/config/svcomp-Reach-32bit-Automizer_Default.epf [2021-12-16 01:00:43,623 INFO L113 SettingsManager]: Loading preferences was successful [2021-12-16 01:00:43,625 INFO L115 SettingsManager]: Preferences different from defaults after loading the file: [2021-12-16 01:00:43,625 INFO L136 SettingsManager]: Preferences of UltimateCore differ from their defaults: [2021-12-16 01:00:43,625 INFO L138 SettingsManager]: * Log level for class=de.uni_freiburg.informatik.ultimate.lib.smtlibutils.quantifier.QuantifierPusher=ERROR; [2021-12-16 01:00:43,626 INFO L136 SettingsManager]: Preferences of Boogie Procedure Inliner differ from their defaults: [2021-12-16 01:00:43,626 INFO L138 SettingsManager]: * Ignore calls to procedures called more than once=ONLY_FOR_SEQUENTIAL_PROGRAMS [2021-12-16 01:00:43,627 INFO L136 SettingsManager]: Preferences of BlockEncodingV2 differ from their defaults: [2021-12-16 01:00:43,627 INFO L138 SettingsManager]: * Create parallel compositions if possible=false [2021-12-16 01:00:43,627 INFO L138 SettingsManager]: * Use SBE=true [2021-12-16 01:00:43,628 INFO L136 SettingsManager]: Preferences of CACSL2BoogieTranslator differ from their defaults: [2021-12-16 01:00:43,628 INFO L138 SettingsManager]: * sizeof long=4 [2021-12-16 01:00:43,629 INFO L138 SettingsManager]: * Overapproximate operations on floating types=true [2021-12-16 01:00:43,629 INFO L138 SettingsManager]: * sizeof POINTER=4 [2021-12-16 01:00:43,629 INFO L138 SettingsManager]: * Check division by zero=IGNORE [2021-12-16 01:00:43,629 INFO L138 SettingsManager]: * Pointer to allocated memory at dereference=IGNORE [2021-12-16 01:00:43,629 INFO L138 SettingsManager]: * If two pointers are subtracted or compared they have the same base address=IGNORE [2021-12-16 01:00:43,629 INFO L138 SettingsManager]: * Check array bounds for arrays that are off heap=IGNORE [2021-12-16 01:00:43,630 INFO L138 SettingsManager]: * sizeof long double=12 [2021-12-16 01:00:43,630 INFO L138 SettingsManager]: * Check if freed pointer was valid=false [2021-12-16 01:00:43,630 INFO L138 SettingsManager]: * Use constant arrays=true [2021-12-16 01:00:43,630 INFO L138 SettingsManager]: * Pointer base address is valid at dereference=IGNORE [2021-12-16 01:00:43,630 INFO L136 SettingsManager]: Preferences of RCFGBuilder differ from their defaults: [2021-12-16 01:00:43,631 INFO L138 SettingsManager]: * Size of a code block=SequenceOfStatements [2021-12-16 01:00:43,631 INFO L138 SettingsManager]: * SMT solver=External_DefaultMode [2021-12-16 01:00:43,631 INFO L138 SettingsManager]: * Command for external solver=z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in -t:2000 [2021-12-16 01:00:43,631 INFO L136 SettingsManager]: Preferences of TraceAbstraction differ from their defaults: [2021-12-16 01:00:43,631 INFO L138 SettingsManager]: * Compute Interpolants along a Counterexample=FPandBP [2021-12-16 01:00:43,631 INFO L138 SettingsManager]: * Positions where we compute the Hoare Annotation=LoopsAndPotentialCycles [2021-12-16 01:00:43,632 INFO L138 SettingsManager]: * Trace refinement strategy=CAMEL [2021-12-16 01:00:43,632 INFO L138 SettingsManager]: * Command for external solver=z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in [2021-12-16 01:00:43,632 INFO L138 SettingsManager]: * Large block encoding in concurrent analysis=OFF [2021-12-16 01:00:43,632 INFO L138 SettingsManager]: * Automaton type used in concurrency analysis=PETRI_NET [2021-12-16 01:00:43,633 INFO L138 SettingsManager]: * Compute Hoare Annotation of negated interpolant automaton, abstraction and CFG=true [2021-12-16 01:00:43,633 INFO L138 SettingsManager]: * Trace refinement exception blacklist=NONE [2021-12-16 01:00:43,633 INFO L138 SettingsManager]: * SMT solver=External_ModelsAndUnsatCoreMode WARNING: An illegal reflective access operation has occurred WARNING: Illegal reflective access by com.sun.xml.bind.v2.runtime.reflect.opt.Injector$1 (file:/storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/plugins/com.sun.xml.bind_2.2.0.v201505121915.jar) to method java.lang.ClassLoader.defineClass(java.lang.String,byte[],int,int) WARNING: Please consider reporting this to the maintainers of com.sun.xml.bind.v2.runtime.reflect.opt.Injector$1 WARNING: Use --illegal-access=warn to enable warnings of further illegal reflective access operations WARNING: All illegal access operations will be denied in a future release Applying setting for plugin de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator: Entry function -> main Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Witness directory -> /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Witness filename -> witness.graphml Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Write witness besides input file -> false Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Graph data specification -> CHECK( init(main()), LTL(G ! call(reach_error())) ) Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Graph data producer -> Automizer Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Graph data architecture -> 32bit Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Graph data programhash -> debcf50bf3bb3961401c62ca4b7217ea7cc93038f750143121614e56b550164d [2021-12-16 01:00:43,846 INFO L75 nceAwareModelManager]: Repository-Root is: /tmp [2021-12-16 01:00:43,875 INFO L261 ainManager$Toolchain]: [Toolchain 1]: Applicable parser(s) successfully (re)initialized [2021-12-16 01:00:43,877 INFO L217 ainManager$Toolchain]: [Toolchain 1]: Toolchain selected. [2021-12-16 01:00:43,878 INFO L271 PluginConnector]: Initializing CDTParser... [2021-12-16 01:00:43,878 INFO L275 PluginConnector]: CDTParser initialized [2021-12-16 01:00:43,880 INFO L432 ainManager$Toolchain]: [Toolchain 1]: Parsing single file: /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/../sv-benchmarks/c/product-lines/minepump_spec4_product58.cil.c [2021-12-16 01:00:43,937 INFO L220 CDTParser]: Created temporary CDT project at /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/data/36c2cbee9/8f7b7d1cfade41319a7a4967600e2a5b/FLAGb5c96216f [2021-12-16 01:00:44,385 INFO L306 CDTParser]: Found 1 translation units. [2021-12-16 01:00:44,386 INFO L160 CDTParser]: Scanning /storage/repos/ultimate/releaseScripts/default/sv-benchmarks/c/product-lines/minepump_spec4_product58.cil.c [2021-12-16 01:00:44,399 INFO L349 CDTParser]: About to delete temporary CDT project at /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/data/36c2cbee9/8f7b7d1cfade41319a7a4967600e2a5b/FLAGb5c96216f [2021-12-16 01:00:44,767 INFO L357 CDTParser]: Successfully deleted /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/data/36c2cbee9/8f7b7d1cfade41319a7a4967600e2a5b [2021-12-16 01:00:44,770 INFO L299 ainManager$Toolchain]: ####################### [Toolchain 1] ####################### [2021-12-16 01:00:44,771 INFO L131 ToolchainWalker]: Walking toolchain with 6 elements. [2021-12-16 01:00:44,771 INFO L113 PluginConnector]: ------------------------CACSL2BoogieTranslator---------------------------- [2021-12-16 01:00:44,772 INFO L271 PluginConnector]: Initializing CACSL2BoogieTranslator... [2021-12-16 01:00:44,776 INFO L275 PluginConnector]: CACSL2BoogieTranslator initialized [2021-12-16 01:00:44,777 INFO L185 PluginConnector]: Executing the observer ACSLObjectContainerObserver from plugin CACSL2BoogieTranslator for "CDTParser AST 16.12 01:00:44" (1/1) ... [2021-12-16 01:00:44,778 INFO L205 PluginConnector]: Invalid model from CACSL2BoogieTranslator for observer de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator.ACSLObjectContainerObserver@7d6d33cd and model type de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 16.12 01:00:44, skipping insertion in model container [2021-12-16 01:00:44,779 INFO L185 PluginConnector]: Executing the observer CACSL2BoogieTranslatorObserver from plugin CACSL2BoogieTranslator for "CDTParser AST 16.12 01:00:44" (1/1) ... [2021-12-16 01:00:44,784 INFO L145 MainTranslator]: Starting translation in SV-COMP mode [2021-12-16 01:00:44,826 INFO L178 MainTranslator]: Built tables and reachable declarations [2021-12-16 01:00:45,005 WARN L230 ndardFunctionHandler]: Function reach_error is already implemented but we override the implementation for the call at /storage/repos/ultimate/releaseScripts/default/sv-benchmarks/c/product-lines/minepump_spec4_product58.cil.c[11718,11731] [2021-12-16 01:00:45,041 INFO L209 PostProcessor]: Analyzing one entry point: main [2021-12-16 01:00:45,050 INFO L203 MainTranslator]: Completed pre-run [2021-12-16 01:00:45,096 WARN L230 ndardFunctionHandler]: Function reach_error is already implemented but we override the implementation for the call at /storage/repos/ultimate/releaseScripts/default/sv-benchmarks/c/product-lines/minepump_spec4_product58.cil.c[11718,11731] [2021-12-16 01:00:45,140 INFO L209 PostProcessor]: Analyzing one entry point: main [2021-12-16 01:00:45,160 INFO L208 MainTranslator]: Completed translation [2021-12-16 01:00:45,161 INFO L202 PluginConnector]: Adding new model de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 16.12 01:00:45 WrapperNode [2021-12-16 01:00:45,161 INFO L132 PluginConnector]: ------------------------ END CACSL2BoogieTranslator---------------------------- [2021-12-16 01:00:45,162 INFO L113 PluginConnector]: ------------------------Boogie Procedure Inliner---------------------------- [2021-12-16 01:00:45,162 INFO L271 PluginConnector]: Initializing Boogie Procedure Inliner... [2021-12-16 01:00:45,162 INFO L275 PluginConnector]: Boogie Procedure Inliner initialized [2021-12-16 01:00:45,169 INFO L185 PluginConnector]: Executing the observer TypeChecker from plugin Boogie Procedure Inliner for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 16.12 01:00:45" (1/1) ... [2021-12-16 01:00:45,198 INFO L185 PluginConnector]: Executing the observer Inliner from plugin Boogie Procedure Inliner for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 16.12 01:00:45" (1/1) ... [2021-12-16 01:00:45,235 INFO L137 Inliner]: procedures = 57, calls = 157, calls flagged for inlining = 27, calls inlined = 24, statements flattened = 283 [2021-12-16 01:00:45,236 INFO L132 PluginConnector]: ------------------------ END Boogie Procedure Inliner---------------------------- [2021-12-16 01:00:45,237 INFO L113 PluginConnector]: ------------------------Boogie Preprocessor---------------------------- [2021-12-16 01:00:45,238 INFO L271 PluginConnector]: Initializing Boogie Preprocessor... [2021-12-16 01:00:45,238 INFO L275 PluginConnector]: Boogie Preprocessor initialized [2021-12-16 01:00:45,245 INFO L185 PluginConnector]: Executing the observer EnsureBoogieModelObserver from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 16.12 01:00:45" (1/1) ... [2021-12-16 01:00:45,246 INFO L185 PluginConnector]: Executing the observer TypeChecker from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 16.12 01:00:45" (1/1) ... [2021-12-16 01:00:45,255 INFO L185 PluginConnector]: Executing the observer ConstExpander from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 16.12 01:00:45" (1/1) ... [2021-12-16 01:00:45,255 INFO L185 PluginConnector]: Executing the observer StructExpander from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 16.12 01:00:45" (1/1) ... [2021-12-16 01:00:45,265 INFO L185 PluginConnector]: Executing the observer UnstructureCode from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 16.12 01:00:45" (1/1) ... [2021-12-16 01:00:45,269 INFO L185 PluginConnector]: Executing the observer FunctionInliner from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 16.12 01:00:45" (1/1) ... [2021-12-16 01:00:45,270 INFO L185 PluginConnector]: Executing the observer BoogieSymbolTableConstructor from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 16.12 01:00:45" (1/1) ... [2021-12-16 01:00:45,277 INFO L132 PluginConnector]: ------------------------ END Boogie Preprocessor---------------------------- [2021-12-16 01:00:45,278 INFO L113 PluginConnector]: ------------------------RCFGBuilder---------------------------- [2021-12-16 01:00:45,278 INFO L271 PluginConnector]: Initializing RCFGBuilder... [2021-12-16 01:00:45,278 INFO L275 PluginConnector]: RCFGBuilder initialized [2021-12-16 01:00:45,279 INFO L185 PluginConnector]: Executing the observer RCFGBuilderObserver from plugin RCFGBuilder for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 16.12 01:00:45" (1/1) ... [2021-12-16 01:00:45,288 INFO L168 SolverBuilder]: Constructing external solver with command: z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in -t:2000 [2021-12-16 01:00:45,299 INFO L189 MonitoredProcess]: No working directory specified, using /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 [2021-12-16 01:00:45,308 INFO L229 MonitoredProcess]: Starting monitored process 1 with /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in -t:2000 (exit command is (exit), workingDir is null) [2021-12-16 01:00:45,315 INFO L327 MonitoredProcess]: [MP /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in -t:2000 (1)] Waiting until timeout for monitored process [2021-12-16 01:00:45,340 INFO L130 BoogieDeclarations]: Found specification of procedure #Ultimate.allocInit [2021-12-16 01:00:45,341 INFO L130 BoogieDeclarations]: Found specification of procedure processEnvironment__wrappee__base [2021-12-16 01:00:45,341 INFO L138 BoogieDeclarations]: Found implementation of procedure processEnvironment__wrappee__base [2021-12-16 01:00:45,341 INFO L130 BoogieDeclarations]: Found specification of procedure timeShift [2021-12-16 01:00:45,341 INFO L138 BoogieDeclarations]: Found implementation of procedure timeShift [2021-12-16 01:00:45,341 INFO L130 BoogieDeclarations]: Found specification of procedure cleanup [2021-12-16 01:00:45,341 INFO L138 BoogieDeclarations]: Found implementation of procedure cleanup [2021-12-16 01:00:45,342 INFO L130 BoogieDeclarations]: Found specification of procedure processEnvironment__wrappee__highWaterSensor [2021-12-16 01:00:45,342 INFO L138 BoogieDeclarations]: Found implementation of procedure processEnvironment__wrappee__highWaterSensor [2021-12-16 01:00:45,342 INFO L130 BoogieDeclarations]: Found specification of procedure waterRise [2021-12-16 01:00:45,342 INFO L138 BoogieDeclarations]: Found implementation of procedure waterRise [2021-12-16 01:00:45,342 INFO L130 BoogieDeclarations]: Found specification of procedure write~init~int [2021-12-16 01:00:45,342 INFO L130 BoogieDeclarations]: Found specification of procedure changeMethaneLevel [2021-12-16 01:00:45,342 INFO L138 BoogieDeclarations]: Found implementation of procedure changeMethaneLevel [2021-12-16 01:00:45,343 INFO L130 BoogieDeclarations]: Found specification of procedure ULTIMATE.start [2021-12-16 01:00:45,343 INFO L138 BoogieDeclarations]: Found implementation of procedure ULTIMATE.start [2021-12-16 01:00:45,400 INFO L236 CfgBuilder]: Building ICFG [2021-12-16 01:00:45,401 INFO L262 CfgBuilder]: Building CFG for each procedure with an implementation [2021-12-16 01:00:45,648 INFO L277 CfgBuilder]: Performing block encoding [2021-12-16 01:00:45,654 INFO L296 CfgBuilder]: Using the 1 location(s) as analysis (start of procedure ULTIMATE.start) [2021-12-16 01:00:45,654 INFO L301 CfgBuilder]: Removed 2 assume(true) statements. [2021-12-16 01:00:45,655 INFO L202 PluginConnector]: Adding new model de.uni_freiburg.informatik.ultimate.plugins.generator.rcfgbuilder CFG 16.12 01:00:45 BoogieIcfgContainer [2021-12-16 01:00:45,656 INFO L132 PluginConnector]: ------------------------ END RCFGBuilder---------------------------- [2021-12-16 01:00:45,657 INFO L113 PluginConnector]: ------------------------TraceAbstraction---------------------------- [2021-12-16 01:00:45,657 INFO L271 PluginConnector]: Initializing TraceAbstraction... [2021-12-16 01:00:45,672 INFO L275 PluginConnector]: TraceAbstraction initialized [2021-12-16 01:00:45,672 INFO L185 PluginConnector]: Executing the observer TraceAbstractionObserver from plugin TraceAbstraction for "CDTParser AST 16.12 01:00:44" (1/3) ... [2021-12-16 01:00:45,673 INFO L205 PluginConnector]: Invalid model from TraceAbstraction for observer de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction.TraceAbstractionObserver@66911009 and model type de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction AST 16.12 01:00:45, skipping insertion in model container [2021-12-16 01:00:45,673 INFO L185 PluginConnector]: Executing the observer TraceAbstractionObserver from plugin TraceAbstraction for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 16.12 01:00:45" (2/3) ... [2021-12-16 01:00:45,673 INFO L205 PluginConnector]: Invalid model from TraceAbstraction for observer de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction.TraceAbstractionObserver@66911009 and model type de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction AST 16.12 01:00:45, skipping insertion in model container [2021-12-16 01:00:45,674 INFO L185 PluginConnector]: Executing the observer TraceAbstractionObserver from plugin TraceAbstraction for "de.uni_freiburg.informatik.ultimate.plugins.generator.rcfgbuilder CFG 16.12 01:00:45" (3/3) ... [2021-12-16 01:00:45,675 INFO L111 eAbstractionObserver]: Analyzing ICFG minepump_spec4_product58.cil.c [2021-12-16 01:00:45,679 INFO L204 ceAbstractionStarter]: Automizer settings: Hoare:true NWA Interpolation:FPandBP Determinization: PREDICATE_ABSTRACTION [2021-12-16 01:00:45,680 INFO L163 ceAbstractionStarter]: Applying trace abstraction to program that has 1 error locations. [2021-12-16 01:00:45,726 INFO L338 AbstractCegarLoop]: ======== Iteration 0 == of CEGAR loop == AllErrorsAtOnce ======== [2021-12-16 01:00:45,736 INFO L339 AbstractCegarLoop]: Settings: SEPARATE_VIOLATION_CHECK=true, mInterprocedural=true, mMaxIterations=1000000, mWatchIteration=1000000, mArtifact=RCFG, mInterpolation=FPandBP, mInterpolantAutomaton=STRAIGHT_LINE, mDumpAutomata=false, mAutomataFormat=ATS_NUMERATE, mDumpPath=., mDeterminiation=PREDICATE_ABSTRACTION, mMinimize=MINIMIZE_SEVPA, mHoare=true, mAutomataTypeConcurrency=PETRI_NET, mHoareTripleChecks=INCREMENTAL, mHoareAnnotationPositions=LoopsAndPotentialCycles, mDumpOnlyReuseAutomata=false, mLimitTraceHistogram=0, mErrorLocTimeLimit=0, mLimitPathProgramCount=0, mCollectInterpolantStatistics=true, mHeuristicEmptinessCheck=false, mHeuristicEmptinessCheckAStarHeuristic=ZERO, mHeuristicEmptinessCheckAStarHeuristicRandomSeed=1337, mHeuristicEmptinessCheckSmtFeatureScoringMethod=DAGSIZE, mSMTFeatureExtraction=false, mSMTFeatureExtractionDumpPath=., mOverrideInterpolantAutomaton=false, mMcrInterpolantMethod=WP, mLoopAccelerationTechnique=FAST_UPR [2021-12-16 01:00:45,736 INFO L340 AbstractCegarLoop]: Starting to check reachability of 1 error locations. [2021-12-16 01:00:45,768 INFO L276 IsEmpty]: Start isEmpty. Operand has 87 states, 69 states have (on average 1.391304347826087) internal successors, (96), 77 states have internal predecessors, (96), 10 states have call successors, (10), 6 states have call predecessors, (10), 6 states have return successors, (10), 8 states have call predecessors, (10), 10 states have call successors, (10) [2021-12-16 01:00:45,774 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 20 [2021-12-16 01:00:45,774 INFO L506 BasicCegarLoop]: Found error trace [2021-12-16 01:00:45,775 INFO L514 BasicCegarLoop]: trace histogram [1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2021-12-16 01:00:45,776 INFO L402 AbstractCegarLoop]: === Iteration 1 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2021-12-16 01:00:45,781 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2021-12-16 01:00:45,781 INFO L85 PathProgramCache]: Analyzing trace with hash -644164364, now seen corresponding path program 1 times [2021-12-16 01:00:45,789 INFO L121 FreeRefinementEngine]: Executing refinement strategy CAMEL [2021-12-16 01:00:45,789 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [1871371519] [2021-12-16 01:00:45,790 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2021-12-16 01:00:45,790 INFO L126 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2021-12-16 01:00:45,941 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 01:00:46,007 INFO L134 CoverageAnalysis]: Checked inductivity of 0 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2021-12-16 01:00:46,008 INFO L139 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2021-12-16 01:00:46,008 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [1871371519] [2021-12-16 01:00:46,009 INFO L160 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [1871371519] provided 1 perfect and 0 imperfect interpolant sequences [2021-12-16 01:00:46,009 INFO L186 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2021-12-16 01:00:46,010 INFO L199 FreeRefinementEngine]: Number of different interpolants: perfect sequences [2] imperfect sequences [] total 2 [2021-12-16 01:00:46,011 INFO L115 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [968544949] [2021-12-16 01:00:46,012 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2021-12-16 01:00:46,017 INFO L546 AbstractCegarLoop]: INTERPOLANT automaton has 2 states [2021-12-16 01:00:46,017 INFO L103 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2021-12-16 01:00:46,044 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 2 interpolants. [2021-12-16 01:00:46,045 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=1, Invalid=1, Unknown=0, NotChecked=0, Total=2 [2021-12-16 01:00:46,048 INFO L87 Difference]: Start difference. First operand has 87 states, 69 states have (on average 1.391304347826087) internal successors, (96), 77 states have internal predecessors, (96), 10 states have call successors, (10), 6 states have call predecessors, (10), 6 states have return successors, (10), 8 states have call predecessors, (10), 10 states have call successors, (10) Second operand has 2 states, 2 states have (on average 8.5) internal successors, (17), 2 states have internal predecessors, (17), 1 states have call successors, (2), 1 states have call predecessors, (2), 0 states have return successors, (0), 0 states have call predecessors, (0), 0 states have call successors, (0) [2021-12-16 01:00:46,094 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2021-12-16 01:00:46,095 INFO L93 Difference]: Finished difference Result 166 states and 227 transitions. [2021-12-16 01:00:46,096 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 2 states. [2021-12-16 01:00:46,097 INFO L78 Accepts]: Start accepts. Automaton has has 2 states, 2 states have (on average 8.5) internal successors, (17), 2 states have internal predecessors, (17), 1 states have call successors, (2), 1 states have call predecessors, (2), 0 states have return successors, (0), 0 states have call predecessors, (0), 0 states have call successors, (0) Word has length 19 [2021-12-16 01:00:46,097 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2021-12-16 01:00:46,105 INFO L225 Difference]: With dead ends: 166 [2021-12-16 01:00:46,105 INFO L226 Difference]: Without dead ends: 78 [2021-12-16 01:00:46,109 INFO L932 BasicCegarLoop]: 0 DeclaredPredicates, 2 GetRequests, 2 SyntacticMatches, 0 SemanticMatches, 0 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 0 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=1, Invalid=1, Unknown=0, NotChecked=0, Total=2 [2021-12-16 01:00:46,112 INFO L933 BasicCegarLoop]: 110 mSDtfsCounter, 0 mSDsluCounter, 0 mSDsCounter, 0 mSdLazyCounter, 0 mSolverCounterSat, 0 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.0s Time, 0 mProtectedPredicate, 0 mProtectedAction, 0 SdHoareTripleChecker+Valid, 110 SdHoareTripleChecker+Invalid, 0 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 0 IncrementalHoareTripleChecker+Valid, 0 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.0s IncrementalHoareTripleChecker+Time [2021-12-16 01:00:46,113 INFO L934 BasicCegarLoop]: SdHoareTripleChecker [0 Valid, 110 Invalid, 0 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [0 Valid, 0 Invalid, 0 Unknown, 0 Unchecked, 0.0s Time] [2021-12-16 01:00:46,127 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 78 states. [2021-12-16 01:00:46,163 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 78 to 78. [2021-12-16 01:00:46,165 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 78 states, 62 states have (on average 1.3225806451612903) internal successors, (82), 69 states have internal predecessors, (82), 10 states have call successors, (10), 6 states have call predecessors, (10), 5 states have return successors, (9), 7 states have call predecessors, (9), 9 states have call successors, (9) [2021-12-16 01:00:46,169 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 78 states to 78 states and 101 transitions. [2021-12-16 01:00:46,171 INFO L78 Accepts]: Start accepts. Automaton has 78 states and 101 transitions. Word has length 19 [2021-12-16 01:00:46,171 INFO L84 Accepts]: Finished accepts. word is rejected. [2021-12-16 01:00:46,171 INFO L470 AbstractCegarLoop]: Abstraction has 78 states and 101 transitions. [2021-12-16 01:00:46,172 INFO L471 AbstractCegarLoop]: INTERPOLANT automaton has has 2 states, 2 states have (on average 8.5) internal successors, (17), 2 states have internal predecessors, (17), 1 states have call successors, (2), 1 states have call predecessors, (2), 0 states have return successors, (0), 0 states have call predecessors, (0), 0 states have call successors, (0) [2021-12-16 01:00:46,172 INFO L276 IsEmpty]: Start isEmpty. Operand 78 states and 101 transitions. [2021-12-16 01:00:46,176 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 21 [2021-12-16 01:00:46,176 INFO L506 BasicCegarLoop]: Found error trace [2021-12-16 01:00:46,177 INFO L514 BasicCegarLoop]: trace histogram [1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2021-12-16 01:00:46,177 WARN L452 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable0 [2021-12-16 01:00:46,178 INFO L402 AbstractCegarLoop]: === Iteration 2 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2021-12-16 01:00:46,181 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2021-12-16 01:00:46,181 INFO L85 PathProgramCache]: Analyzing trace with hash -1321297108, now seen corresponding path program 1 times [2021-12-16 01:00:46,181 INFO L121 FreeRefinementEngine]: Executing refinement strategy CAMEL [2021-12-16 01:00:46,182 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [1690723099] [2021-12-16 01:00:46,182 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2021-12-16 01:00:46,182 INFO L126 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2021-12-16 01:00:46,212 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 01:00:46,251 INFO L134 CoverageAnalysis]: Checked inductivity of 0 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2021-12-16 01:00:46,252 INFO L139 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2021-12-16 01:00:46,252 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [1690723099] [2021-12-16 01:00:46,252 INFO L160 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [1690723099] provided 1 perfect and 0 imperfect interpolant sequences [2021-12-16 01:00:46,256 INFO L186 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2021-12-16 01:00:46,256 INFO L199 FreeRefinementEngine]: Number of different interpolants: perfect sequences [3] imperfect sequences [] total 3 [2021-12-16 01:00:46,257 INFO L115 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [1167912885] [2021-12-16 01:00:46,257 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2021-12-16 01:00:46,258 INFO L546 AbstractCegarLoop]: INTERPOLANT automaton has 3 states [2021-12-16 01:00:46,258 INFO L103 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2021-12-16 01:00:46,259 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 3 interpolants. [2021-12-16 01:00:46,259 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=3, Invalid=3, Unknown=0, NotChecked=0, Total=6 [2021-12-16 01:00:46,259 INFO L87 Difference]: Start difference. First operand 78 states and 101 transitions. Second operand has 3 states, 3 states have (on average 6.0) internal successors, (18), 3 states have internal predecessors, (18), 1 states have call successors, (2), 1 states have call predecessors, (2), 0 states have return successors, (0), 0 states have call predecessors, (0), 0 states have call successors, (0) [2021-12-16 01:00:46,277 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2021-12-16 01:00:46,279 INFO L93 Difference]: Finished difference Result 121 states and 157 transitions. [2021-12-16 01:00:46,283 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 3 states. [2021-12-16 01:00:46,284 INFO L78 Accepts]: Start accepts. Automaton has has 3 states, 3 states have (on average 6.0) internal successors, (18), 3 states have internal predecessors, (18), 1 states have call successors, (2), 1 states have call predecessors, (2), 0 states have return successors, (0), 0 states have call predecessors, (0), 0 states have call successors, (0) Word has length 20 [2021-12-16 01:00:46,284 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2021-12-16 01:00:46,285 INFO L225 Difference]: With dead ends: 121 [2021-12-16 01:00:46,287 INFO L226 Difference]: Without dead ends: 69 [2021-12-16 01:00:46,287 INFO L932 BasicCegarLoop]: 0 DeclaredPredicates, 3 GetRequests, 2 SyntacticMatches, 0 SemanticMatches, 1 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 0 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=3, Invalid=3, Unknown=0, NotChecked=0, Total=6 [2021-12-16 01:00:46,289 INFO L933 BasicCegarLoop]: 88 mSDtfsCounter, 13 mSDsluCounter, 71 mSDsCounter, 0 mSdLazyCounter, 1 mSolverCounterSat, 0 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.0s Time, 0 mProtectedPredicate, 0 mProtectedAction, 16 SdHoareTripleChecker+Valid, 159 SdHoareTripleChecker+Invalid, 1 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 0 IncrementalHoareTripleChecker+Valid, 1 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.0s IncrementalHoareTripleChecker+Time [2021-12-16 01:00:46,291 INFO L934 BasicCegarLoop]: SdHoareTripleChecker [16 Valid, 159 Invalid, 1 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [0 Valid, 1 Invalid, 0 Unknown, 0 Unchecked, 0.0s Time] [2021-12-16 01:00:46,292 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 69 states. [2021-12-16 01:00:46,299 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 69 to 69. [2021-12-16 01:00:46,301 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 69 states, 56 states have (on average 1.3392857142857142) internal successors, (75), 63 states have internal predecessors, (75), 7 states have call successors, (7), 5 states have call predecessors, (7), 5 states have return successors, (7), 5 states have call predecessors, (7), 7 states have call successors, (7) [2021-12-16 01:00:46,303 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 69 states to 69 states and 89 transitions. [2021-12-16 01:00:46,305 INFO L78 Accepts]: Start accepts. Automaton has 69 states and 89 transitions. Word has length 20 [2021-12-16 01:00:46,305 INFO L84 Accepts]: Finished accepts. word is rejected. [2021-12-16 01:00:46,305 INFO L470 AbstractCegarLoop]: Abstraction has 69 states and 89 transitions. [2021-12-16 01:00:46,306 INFO L471 AbstractCegarLoop]: INTERPOLANT automaton has has 3 states, 3 states have (on average 6.0) internal successors, (18), 3 states have internal predecessors, (18), 1 states have call successors, (2), 1 states have call predecessors, (2), 0 states have return successors, (0), 0 states have call predecessors, (0), 0 states have call successors, (0) [2021-12-16 01:00:46,306 INFO L276 IsEmpty]: Start isEmpty. Operand 69 states and 89 transitions. [2021-12-16 01:00:46,307 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 26 [2021-12-16 01:00:46,308 INFO L506 BasicCegarLoop]: Found error trace [2021-12-16 01:00:46,308 INFO L514 BasicCegarLoop]: trace histogram [1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2021-12-16 01:00:46,308 WARN L452 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable1 [2021-12-16 01:00:46,309 INFO L402 AbstractCegarLoop]: === Iteration 3 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2021-12-16 01:00:46,309 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2021-12-16 01:00:46,310 INFO L85 PathProgramCache]: Analyzing trace with hash 2055869510, now seen corresponding path program 1 times [2021-12-16 01:00:46,310 INFO L121 FreeRefinementEngine]: Executing refinement strategy CAMEL [2021-12-16 01:00:46,310 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [1544768518] [2021-12-16 01:00:46,311 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2021-12-16 01:00:46,311 INFO L126 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2021-12-16 01:00:46,331 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 01:00:46,401 INFO L134 CoverageAnalysis]: Checked inductivity of 0 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2021-12-16 01:00:46,401 INFO L139 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2021-12-16 01:00:46,402 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [1544768518] [2021-12-16 01:00:46,402 INFO L160 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [1544768518] provided 1 perfect and 0 imperfect interpolant sequences [2021-12-16 01:00:46,402 INFO L186 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2021-12-16 01:00:46,402 INFO L199 FreeRefinementEngine]: Number of different interpolants: perfect sequences [5] imperfect sequences [] total 5 [2021-12-16 01:00:46,402 INFO L115 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [573583998] [2021-12-16 01:00:46,404 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2021-12-16 01:00:46,404 INFO L546 AbstractCegarLoop]: INTERPOLANT automaton has 6 states [2021-12-16 01:00:46,404 INFO L103 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2021-12-16 01:00:46,405 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 6 interpolants. [2021-12-16 01:00:46,406 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=10, Invalid=20, Unknown=0, NotChecked=0, Total=30 [2021-12-16 01:00:46,406 INFO L87 Difference]: Start difference. First operand 69 states and 89 transitions. Second operand has 6 states, 6 states have (on average 4.0) internal successors, (24), 5 states have internal predecessors, (24), 1 states have call successors, (1), 1 states have call predecessors, (1), 0 states have return successors, (0), 0 states have call predecessors, (0), 0 states have call successors, (0) [2021-12-16 01:00:46,537 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2021-12-16 01:00:46,537 INFO L93 Difference]: Finished difference Result 131 states and 172 transitions. [2021-12-16 01:00:46,538 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 5 states. [2021-12-16 01:00:46,538 INFO L78 Accepts]: Start accepts. Automaton has has 6 states, 6 states have (on average 4.0) internal successors, (24), 5 states have internal predecessors, (24), 1 states have call successors, (1), 1 states have call predecessors, (1), 0 states have return successors, (0), 0 states have call predecessors, (0), 0 states have call successors, (0) Word has length 25 [2021-12-16 01:00:46,538 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2021-12-16 01:00:46,540 INFO L225 Difference]: With dead ends: 131 [2021-12-16 01:00:46,540 INFO L226 Difference]: Without dead ends: 69 [2021-12-16 01:00:46,540 INFO L932 BasicCegarLoop]: 0 DeclaredPredicates, 7 GetRequests, 1 SyntacticMatches, 0 SemanticMatches, 6 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 0 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=22, Invalid=34, Unknown=0, NotChecked=0, Total=56 [2021-12-16 01:00:46,541 INFO L933 BasicCegarLoop]: 82 mSDtfsCounter, 172 mSDsluCounter, 108 mSDsCounter, 0 mSdLazyCounter, 33 mSolverCounterSat, 27 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.1s Time, 0 mProtectedPredicate, 0 mProtectedAction, 172 SdHoareTripleChecker+Valid, 190 SdHoareTripleChecker+Invalid, 60 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 27 IncrementalHoareTripleChecker+Valid, 33 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.1s IncrementalHoareTripleChecker+Time [2021-12-16 01:00:46,542 INFO L934 BasicCegarLoop]: SdHoareTripleChecker [172 Valid, 190 Invalid, 60 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [27 Valid, 33 Invalid, 0 Unknown, 0 Unchecked, 0.1s Time] [2021-12-16 01:00:46,543 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 69 states. [2021-12-16 01:00:46,549 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 69 to 69. [2021-12-16 01:00:46,549 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 69 states, 56 states have (on average 1.3214285714285714) internal successors, (74), 63 states have internal predecessors, (74), 7 states have call successors, (7), 5 states have call predecessors, (7), 5 states have return successors, (7), 5 states have call predecessors, (7), 7 states have call successors, (7) [2021-12-16 01:00:46,550 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 69 states to 69 states and 88 transitions. [2021-12-16 01:00:46,550 INFO L78 Accepts]: Start accepts. Automaton has 69 states and 88 transitions. Word has length 25 [2021-12-16 01:00:46,550 INFO L84 Accepts]: Finished accepts. word is rejected. [2021-12-16 01:00:46,550 INFO L470 AbstractCegarLoop]: Abstraction has 69 states and 88 transitions. [2021-12-16 01:00:46,550 INFO L471 AbstractCegarLoop]: INTERPOLANT automaton has has 6 states, 6 states have (on average 4.0) internal successors, (24), 5 states have internal predecessors, (24), 1 states have call successors, (1), 1 states have call predecessors, (1), 0 states have return successors, (0), 0 states have call predecessors, (0), 0 states have call successors, (0) [2021-12-16 01:00:46,551 INFO L276 IsEmpty]: Start isEmpty. Operand 69 states and 88 transitions. [2021-12-16 01:00:46,553 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 36 [2021-12-16 01:00:46,553 INFO L506 BasicCegarLoop]: Found error trace [2021-12-16 01:00:46,554 INFO L514 BasicCegarLoop]: trace histogram [1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2021-12-16 01:00:46,554 WARN L452 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable2 [2021-12-16 01:00:46,554 INFO L402 AbstractCegarLoop]: === Iteration 4 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2021-12-16 01:00:46,554 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2021-12-16 01:00:46,554 INFO L85 PathProgramCache]: Analyzing trace with hash 86695610, now seen corresponding path program 1 times [2021-12-16 01:00:46,555 INFO L121 FreeRefinementEngine]: Executing refinement strategy CAMEL [2021-12-16 01:00:46,555 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [1708607811] [2021-12-16 01:00:46,555 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2021-12-16 01:00:46,555 INFO L126 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2021-12-16 01:00:46,574 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 01:00:46,603 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 20 [2021-12-16 01:00:46,605 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 01:00:46,617 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 2 [2021-12-16 01:00:46,618 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 01:00:46,620 INFO L134 CoverageAnalysis]: Checked inductivity of 0 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2021-12-16 01:00:46,621 INFO L139 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2021-12-16 01:00:46,621 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [1708607811] [2021-12-16 01:00:46,621 INFO L160 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [1708607811] provided 1 perfect and 0 imperfect interpolant sequences [2021-12-16 01:00:46,621 INFO L186 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2021-12-16 01:00:46,621 INFO L199 FreeRefinementEngine]: Number of different interpolants: perfect sequences [5] imperfect sequences [] total 5 [2021-12-16 01:00:46,622 INFO L115 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [1966066279] [2021-12-16 01:00:46,622 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2021-12-16 01:00:46,622 INFO L546 AbstractCegarLoop]: INTERPOLANT automaton has 5 states [2021-12-16 01:00:46,622 INFO L103 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2021-12-16 01:00:46,623 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 5 interpolants. [2021-12-16 01:00:46,623 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=7, Invalid=13, Unknown=0, NotChecked=0, Total=20 [2021-12-16 01:00:46,623 INFO L87 Difference]: Start difference. First operand 69 states and 88 transitions. Second operand has 5 states, 5 states have (on average 6.0) internal successors, (30), 5 states have internal predecessors, (30), 2 states have call successors, (3), 3 states have call predecessors, (3), 2 states have return successors, (2), 2 states have call predecessors, (2), 2 states have call successors, (2) [2021-12-16 01:00:46,763 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2021-12-16 01:00:46,764 INFO L93 Difference]: Finished difference Result 195 states and 249 transitions. [2021-12-16 01:00:46,764 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 7 states. [2021-12-16 01:00:46,764 INFO L78 Accepts]: Start accepts. Automaton has has 5 states, 5 states have (on average 6.0) internal successors, (30), 5 states have internal predecessors, (30), 2 states have call successors, (3), 3 states have call predecessors, (3), 2 states have return successors, (2), 2 states have call predecessors, (2), 2 states have call successors, (2) Word has length 35 [2021-12-16 01:00:46,764 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2021-12-16 01:00:46,770 INFO L225 Difference]: With dead ends: 195 [2021-12-16 01:00:46,770 INFO L226 Difference]: Without dead ends: 133 [2021-12-16 01:00:46,771 INFO L932 BasicCegarLoop]: 0 DeclaredPredicates, 13 GetRequests, 6 SyntacticMatches, 1 SemanticMatches, 6 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 3 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=19, Invalid=37, Unknown=0, NotChecked=0, Total=56 [2021-12-16 01:00:46,772 INFO L933 BasicCegarLoop]: 103 mSDtfsCounter, 159 mSDsluCounter, 152 mSDsCounter, 0 mSdLazyCounter, 71 mSolverCounterSat, 31 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.1s Time, 0 mProtectedPredicate, 0 mProtectedAction, 161 SdHoareTripleChecker+Valid, 255 SdHoareTripleChecker+Invalid, 102 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 31 IncrementalHoareTripleChecker+Valid, 71 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.1s IncrementalHoareTripleChecker+Time [2021-12-16 01:00:46,775 INFO L934 BasicCegarLoop]: SdHoareTripleChecker [161 Valid, 255 Invalid, 102 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [31 Valid, 71 Invalid, 0 Unknown, 0 Unchecked, 0.1s Time] [2021-12-16 01:00:46,776 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 133 states. [2021-12-16 01:00:46,793 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 133 to 127. [2021-12-16 01:00:46,799 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 127 states, 103 states have (on average 1.2718446601941749) internal successors, (131), 111 states have internal predecessors, (131), 10 states have call successors, (10), 10 states have call predecessors, (10), 13 states have return successors, (15), 11 states have call predecessors, (15), 10 states have call successors, (15) [2021-12-16 01:00:46,800 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 127 states to 127 states and 156 transitions. [2021-12-16 01:00:46,800 INFO L78 Accepts]: Start accepts. Automaton has 127 states and 156 transitions. Word has length 35 [2021-12-16 01:00:46,800 INFO L84 Accepts]: Finished accepts. word is rejected. [2021-12-16 01:00:46,800 INFO L470 AbstractCegarLoop]: Abstraction has 127 states and 156 transitions. [2021-12-16 01:00:46,801 INFO L471 AbstractCegarLoop]: INTERPOLANT automaton has has 5 states, 5 states have (on average 6.0) internal successors, (30), 5 states have internal predecessors, (30), 2 states have call successors, (3), 3 states have call predecessors, (3), 2 states have return successors, (2), 2 states have call predecessors, (2), 2 states have call successors, (2) [2021-12-16 01:00:46,801 INFO L276 IsEmpty]: Start isEmpty. Operand 127 states and 156 transitions. [2021-12-16 01:00:46,804 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 42 [2021-12-16 01:00:46,804 INFO L506 BasicCegarLoop]: Found error trace [2021-12-16 01:00:46,804 INFO L514 BasicCegarLoop]: trace histogram [1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2021-12-16 01:00:46,805 WARN L452 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable3 [2021-12-16 01:00:46,805 INFO L402 AbstractCegarLoop]: === Iteration 5 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2021-12-16 01:00:46,805 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2021-12-16 01:00:46,805 INFO L85 PathProgramCache]: Analyzing trace with hash 585874736, now seen corresponding path program 1 times [2021-12-16 01:00:46,806 INFO L121 FreeRefinementEngine]: Executing refinement strategy CAMEL [2021-12-16 01:00:46,807 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [1878422342] [2021-12-16 01:00:46,807 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2021-12-16 01:00:46,807 INFO L126 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2021-12-16 01:00:46,835 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 01:00:46,884 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 20 [2021-12-16 01:00:46,890 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 01:00:46,909 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 8 [2021-12-16 01:00:46,910 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 01:00:46,912 INFO L134 CoverageAnalysis]: Checked inductivity of 0 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2021-12-16 01:00:46,912 INFO L139 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2021-12-16 01:00:46,912 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [1878422342] [2021-12-16 01:00:46,913 INFO L160 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [1878422342] provided 1 perfect and 0 imperfect interpolant sequences [2021-12-16 01:00:46,913 INFO L186 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2021-12-16 01:00:46,913 INFO L199 FreeRefinementEngine]: Number of different interpolants: perfect sequences [6] imperfect sequences [] total 6 [2021-12-16 01:00:46,913 INFO L115 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [141032723] [2021-12-16 01:00:46,913 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2021-12-16 01:00:46,913 INFO L546 AbstractCegarLoop]: INTERPOLANT automaton has 6 states [2021-12-16 01:00:46,913 INFO L103 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2021-12-16 01:00:46,914 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 6 interpolants. [2021-12-16 01:00:46,914 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=9, Invalid=21, Unknown=0, NotChecked=0, Total=30 [2021-12-16 01:00:46,914 INFO L87 Difference]: Start difference. First operand 127 states and 156 transitions. Second operand has 6 states, 6 states have (on average 6.0) internal successors, (36), 5 states have internal predecessors, (36), 2 states have call successors, (3), 3 states have call predecessors, (3), 2 states have return successors, (2), 1 states have call predecessors, (2), 2 states have call successors, (2) [2021-12-16 01:00:47,144 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2021-12-16 01:00:47,144 INFO L93 Difference]: Finished difference Result 376 states and 485 transitions. [2021-12-16 01:00:47,145 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 12 states. [2021-12-16 01:00:47,145 INFO L78 Accepts]: Start accepts. Automaton has has 6 states, 6 states have (on average 6.0) internal successors, (36), 5 states have internal predecessors, (36), 2 states have call successors, (3), 3 states have call predecessors, (3), 2 states have return successors, (2), 1 states have call predecessors, (2), 2 states have call successors, (2) Word has length 41 [2021-12-16 01:00:47,146 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2021-12-16 01:00:47,153 INFO L225 Difference]: With dead ends: 376 [2021-12-16 01:00:47,153 INFO L226 Difference]: Without dead ends: 256 [2021-12-16 01:00:47,159 INFO L932 BasicCegarLoop]: 0 DeclaredPredicates, 19 GetRequests, 8 SyntacticMatches, 0 SemanticMatches, 11 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 19 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=45, Invalid=111, Unknown=0, NotChecked=0, Total=156 [2021-12-16 01:00:47,162 INFO L933 BasicCegarLoop]: 100 mSDtfsCounter, 203 mSDsluCounter, 249 mSDsCounter, 0 mSdLazyCounter, 123 mSolverCounterSat, 37 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.1s Time, 0 mProtectedPredicate, 0 mProtectedAction, 206 SdHoareTripleChecker+Valid, 349 SdHoareTripleChecker+Invalid, 160 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 37 IncrementalHoareTripleChecker+Valid, 123 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.1s IncrementalHoareTripleChecker+Time [2021-12-16 01:00:47,163 INFO L934 BasicCegarLoop]: SdHoareTripleChecker [206 Valid, 349 Invalid, 160 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [37 Valid, 123 Invalid, 0 Unknown, 0 Unchecked, 0.1s Time] [2021-12-16 01:00:47,164 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 256 states. [2021-12-16 01:00:47,193 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 256 to 208. [2021-12-16 01:00:47,194 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 208 states, 169 states have (on average 1.272189349112426) internal successors, (215), 180 states have internal predecessors, (215), 18 states have call successors, (18), 18 states have call predecessors, (18), 20 states have return successors, (28), 18 states have call predecessors, (28), 18 states have call successors, (28) [2021-12-16 01:00:47,196 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 208 states to 208 states and 261 transitions. [2021-12-16 01:00:47,196 INFO L78 Accepts]: Start accepts. Automaton has 208 states and 261 transitions. Word has length 41 [2021-12-16 01:00:47,196 INFO L84 Accepts]: Finished accepts. word is rejected. [2021-12-16 01:00:47,196 INFO L470 AbstractCegarLoop]: Abstraction has 208 states and 261 transitions. [2021-12-16 01:00:47,196 INFO L471 AbstractCegarLoop]: INTERPOLANT automaton has has 6 states, 6 states have (on average 6.0) internal successors, (36), 5 states have internal predecessors, (36), 2 states have call successors, (3), 3 states have call predecessors, (3), 2 states have return successors, (2), 1 states have call predecessors, (2), 2 states have call successors, (2) [2021-12-16 01:00:47,196 INFO L276 IsEmpty]: Start isEmpty. Operand 208 states and 261 transitions. [2021-12-16 01:00:47,197 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 42 [2021-12-16 01:00:47,197 INFO L506 BasicCegarLoop]: Found error trace [2021-12-16 01:00:47,198 INFO L514 BasicCegarLoop]: trace histogram [1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2021-12-16 01:00:47,198 WARN L452 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable4 [2021-12-16 01:00:47,198 INFO L402 AbstractCegarLoop]: === Iteration 6 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2021-12-16 01:00:47,198 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2021-12-16 01:00:47,198 INFO L85 PathProgramCache]: Analyzing trace with hash -1714947854, now seen corresponding path program 1 times [2021-12-16 01:00:47,198 INFO L121 FreeRefinementEngine]: Executing refinement strategy CAMEL [2021-12-16 01:00:47,199 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [709896995] [2021-12-16 01:00:47,199 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2021-12-16 01:00:47,199 INFO L126 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2021-12-16 01:00:47,213 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 01:00:47,267 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 20 [2021-12-16 01:00:47,271 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 01:00:47,282 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 8 [2021-12-16 01:00:47,283 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 01:00:47,288 INFO L134 CoverageAnalysis]: Checked inductivity of 0 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2021-12-16 01:00:47,288 INFO L139 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2021-12-16 01:00:47,288 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [709896995] [2021-12-16 01:00:47,288 INFO L160 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [709896995] provided 1 perfect and 0 imperfect interpolant sequences [2021-12-16 01:00:47,288 INFO L186 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2021-12-16 01:00:47,288 INFO L199 FreeRefinementEngine]: Number of different interpolants: perfect sequences [9] imperfect sequences [] total 9 [2021-12-16 01:00:47,288 INFO L115 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [695879306] [2021-12-16 01:00:47,289 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2021-12-16 01:00:47,289 INFO L546 AbstractCegarLoop]: INTERPOLANT automaton has 9 states [2021-12-16 01:00:47,289 INFO L103 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2021-12-16 01:00:47,289 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 9 interpolants. [2021-12-16 01:00:47,290 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=16, Invalid=56, Unknown=0, NotChecked=0, Total=72 [2021-12-16 01:00:47,290 INFO L87 Difference]: Start difference. First operand 208 states and 261 transitions. Second operand has 9 states, 9 states have (on average 4.0) internal successors, (36), 8 states have internal predecessors, (36), 2 states have call successors, (3), 3 states have call predecessors, (3), 1 states have return successors, (2), 2 states have call predecessors, (2), 2 states have call successors, (2) [2021-12-16 01:00:47,661 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2021-12-16 01:00:47,661 INFO L93 Difference]: Finished difference Result 529 states and 690 transitions. [2021-12-16 01:00:47,661 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 19 states. [2021-12-16 01:00:47,661 INFO L78 Accepts]: Start accepts. Automaton has has 9 states, 9 states have (on average 4.0) internal successors, (36), 8 states have internal predecessors, (36), 2 states have call successors, (3), 3 states have call predecessors, (3), 1 states have return successors, (2), 2 states have call predecessors, (2), 2 states have call successors, (2) Word has length 41 [2021-12-16 01:00:47,662 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2021-12-16 01:00:47,664 INFO L225 Difference]: With dead ends: 529 [2021-12-16 01:00:47,664 INFO L226 Difference]: Without dead ends: 328 [2021-12-16 01:00:47,665 INFO L932 BasicCegarLoop]: 0 DeclaredPredicates, 27 GetRequests, 7 SyntacticMatches, 0 SemanticMatches, 20 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 77 ImplicationChecksByTransitivity, 0.1s TimeCoverageRelationStatistics Valid=113, Invalid=349, Unknown=0, NotChecked=0, Total=462 [2021-12-16 01:00:47,665 INFO L933 BasicCegarLoop]: 89 mSDtfsCounter, 334 mSDsluCounter, 452 mSDsCounter, 0 mSdLazyCounter, 293 mSolverCounterSat, 71 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.2s Time, 0 mProtectedPredicate, 0 mProtectedAction, 337 SdHoareTripleChecker+Valid, 541 SdHoareTripleChecker+Invalid, 364 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 71 IncrementalHoareTripleChecker+Valid, 293 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.2s IncrementalHoareTripleChecker+Time [2021-12-16 01:00:47,666 INFO L934 BasicCegarLoop]: SdHoareTripleChecker [337 Valid, 541 Invalid, 364 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [71 Valid, 293 Invalid, 0 Unknown, 0 Unchecked, 0.2s Time] [2021-12-16 01:00:47,667 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 328 states. [2021-12-16 01:00:47,704 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 328 to 310. [2021-12-16 01:00:47,705 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 310 states, 250 states have (on average 1.24) internal successors, (310), 268 states have internal predecessors, (310), 26 states have call successors, (26), 26 states have call predecessors, (26), 33 states have return successors, (51), 29 states have call predecessors, (51), 26 states have call successors, (51) [2021-12-16 01:00:47,706 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 310 states to 310 states and 387 transitions. [2021-12-16 01:00:47,706 INFO L78 Accepts]: Start accepts. Automaton has 310 states and 387 transitions. Word has length 41 [2021-12-16 01:00:47,707 INFO L84 Accepts]: Finished accepts. word is rejected. [2021-12-16 01:00:47,707 INFO L470 AbstractCegarLoop]: Abstraction has 310 states and 387 transitions. [2021-12-16 01:00:47,707 INFO L471 AbstractCegarLoop]: INTERPOLANT automaton has has 9 states, 9 states have (on average 4.0) internal successors, (36), 8 states have internal predecessors, (36), 2 states have call successors, (3), 3 states have call predecessors, (3), 1 states have return successors, (2), 2 states have call predecessors, (2), 2 states have call successors, (2) [2021-12-16 01:00:47,707 INFO L276 IsEmpty]: Start isEmpty. Operand 310 states and 387 transitions. [2021-12-16 01:00:47,709 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 72 [2021-12-16 01:00:47,709 INFO L506 BasicCegarLoop]: Found error trace [2021-12-16 01:00:47,709 INFO L514 BasicCegarLoop]: trace histogram [2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2021-12-16 01:00:47,710 WARN L452 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable5 [2021-12-16 01:00:47,710 INFO L402 AbstractCegarLoop]: === Iteration 7 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2021-12-16 01:00:47,710 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2021-12-16 01:00:47,710 INFO L85 PathProgramCache]: Analyzing trace with hash -683942373, now seen corresponding path program 1 times [2021-12-16 01:00:47,710 INFO L121 FreeRefinementEngine]: Executing refinement strategy CAMEL [2021-12-16 01:00:47,711 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [2128246941] [2021-12-16 01:00:47,711 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2021-12-16 01:00:47,711 INFO L126 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2021-12-16 01:00:47,725 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 01:00:47,755 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 16 [2021-12-16 01:00:47,760 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 01:00:47,770 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 3 [2021-12-16 01:00:47,773 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 01:00:47,797 INFO L134 CoverageAnalysis]: Checked inductivity of 17 backedges. 13 proven. 0 refuted. 0 times theorem prover too weak. 4 trivial. 0 not checked. [2021-12-16 01:00:47,797 INFO L139 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2021-12-16 01:00:47,798 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [2128246941] [2021-12-16 01:00:47,798 INFO L160 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [2128246941] provided 1 perfect and 0 imperfect interpolant sequences [2021-12-16 01:00:47,798 INFO L186 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2021-12-16 01:00:47,798 INFO L199 FreeRefinementEngine]: Number of different interpolants: perfect sequences [7] imperfect sequences [] total 7 [2021-12-16 01:00:47,798 INFO L115 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [1167850038] [2021-12-16 01:00:47,798 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2021-12-16 01:00:47,799 INFO L546 AbstractCegarLoop]: INTERPOLANT automaton has 7 states [2021-12-16 01:00:47,799 INFO L103 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2021-12-16 01:00:47,799 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 7 interpolants. [2021-12-16 01:00:47,799 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=12, Invalid=30, Unknown=0, NotChecked=0, Total=42 [2021-12-16 01:00:47,800 INFO L87 Difference]: Start difference. First operand 310 states and 387 transitions. Second operand has 7 states, 7 states have (on average 9.0) internal successors, (63), 5 states have internal predecessors, (63), 2 states have call successors, (3), 3 states have call predecessors, (3), 1 states have return successors, (2), 1 states have call predecessors, (2), 1 states have call successors, (2) [2021-12-16 01:00:47,978 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2021-12-16 01:00:47,979 INFO L93 Difference]: Finished difference Result 663 states and 843 transitions. [2021-12-16 01:00:47,979 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 8 states. [2021-12-16 01:00:47,979 INFO L78 Accepts]: Start accepts. Automaton has has 7 states, 7 states have (on average 9.0) internal successors, (63), 5 states have internal predecessors, (63), 2 states have call successors, (3), 3 states have call predecessors, (3), 1 states have return successors, (2), 1 states have call predecessors, (2), 1 states have call successors, (2) Word has length 71 [2021-12-16 01:00:47,980 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2021-12-16 01:00:47,984 INFO L225 Difference]: With dead ends: 663 [2021-12-16 01:00:47,985 INFO L226 Difference]: Without dead ends: 360 [2021-12-16 01:00:47,986 INFO L932 BasicCegarLoop]: 0 DeclaredPredicates, 15 GetRequests, 6 SyntacticMatches, 0 SemanticMatches, 9 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 6 ImplicationChecksByTransitivity, 0.1s TimeCoverageRelationStatistics Valid=39, Invalid=71, Unknown=0, NotChecked=0, Total=110 [2021-12-16 01:00:47,988 INFO L933 BasicCegarLoop]: 87 mSDtfsCounter, 83 mSDsluCounter, 291 mSDsCounter, 0 mSdLazyCounter, 176 mSolverCounterSat, 22 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.1s Time, 0 mProtectedPredicate, 0 mProtectedAction, 84 SdHoareTripleChecker+Valid, 378 SdHoareTripleChecker+Invalid, 198 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 22 IncrementalHoareTripleChecker+Valid, 176 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.1s IncrementalHoareTripleChecker+Time [2021-12-16 01:00:47,988 INFO L934 BasicCegarLoop]: SdHoareTripleChecker [84 Valid, 378 Invalid, 198 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [22 Valid, 176 Invalid, 0 Unknown, 0 Unchecked, 0.1s Time] [2021-12-16 01:00:47,991 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 360 states. [2021-12-16 01:00:48,015 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 360 to 344. [2021-12-16 01:00:48,016 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 344 states, 278 states have (on average 1.2302158273381294) internal successors, (342), 300 states have internal predecessors, (342), 28 states have call successors, (28), 26 states have call predecessors, (28), 37 states have return successors, (55), 31 states have call predecessors, (55), 28 states have call successors, (55) [2021-12-16 01:00:48,018 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 344 states to 344 states and 425 transitions. [2021-12-16 01:00:48,018 INFO L78 Accepts]: Start accepts. Automaton has 344 states and 425 transitions. Word has length 71 [2021-12-16 01:00:48,018 INFO L84 Accepts]: Finished accepts. word is rejected. [2021-12-16 01:00:48,018 INFO L470 AbstractCegarLoop]: Abstraction has 344 states and 425 transitions. [2021-12-16 01:00:48,018 INFO L471 AbstractCegarLoop]: INTERPOLANT automaton has has 7 states, 7 states have (on average 9.0) internal successors, (63), 5 states have internal predecessors, (63), 2 states have call successors, (3), 3 states have call predecessors, (3), 1 states have return successors, (2), 1 states have call predecessors, (2), 1 states have call successors, (2) [2021-12-16 01:00:48,019 INFO L276 IsEmpty]: Start isEmpty. Operand 344 states and 425 transitions. [2021-12-16 01:00:48,020 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 72 [2021-12-16 01:00:48,020 INFO L506 BasicCegarLoop]: Found error trace [2021-12-16 01:00:48,021 INFO L514 BasicCegarLoop]: trace histogram [2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2021-12-16 01:00:48,021 WARN L452 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable6 [2021-12-16 01:00:48,021 INFO L402 AbstractCegarLoop]: === Iteration 8 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2021-12-16 01:00:48,021 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2021-12-16 01:00:48,021 INFO L85 PathProgramCache]: Analyzing trace with hash 1244330329, now seen corresponding path program 1 times [2021-12-16 01:00:48,022 INFO L121 FreeRefinementEngine]: Executing refinement strategy CAMEL [2021-12-16 01:00:48,022 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [893276450] [2021-12-16 01:00:48,022 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2021-12-16 01:00:48,022 INFO L126 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2021-12-16 01:00:48,033 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 01:00:48,071 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 16 [2021-12-16 01:00:48,078 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 01:00:48,094 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 3 [2021-12-16 01:00:48,097 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 01:00:48,118 INFO L134 CoverageAnalysis]: Checked inductivity of 17 backedges. 13 proven. 0 refuted. 0 times theorem prover too weak. 4 trivial. 0 not checked. [2021-12-16 01:00:48,119 INFO L139 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2021-12-16 01:00:48,119 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [893276450] [2021-12-16 01:00:48,119 INFO L160 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [893276450] provided 1 perfect and 0 imperfect interpolant sequences [2021-12-16 01:00:48,120 INFO L186 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2021-12-16 01:00:48,120 INFO L199 FreeRefinementEngine]: Number of different interpolants: perfect sequences [8] imperfect sequences [] total 8 [2021-12-16 01:00:48,120 INFO L115 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [648984229] [2021-12-16 01:00:48,120 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2021-12-16 01:00:48,120 INFO L546 AbstractCegarLoop]: INTERPOLANT automaton has 8 states [2021-12-16 01:00:48,121 INFO L103 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2021-12-16 01:00:48,122 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 8 interpolants. [2021-12-16 01:00:48,122 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=14, Invalid=42, Unknown=0, NotChecked=0, Total=56 [2021-12-16 01:00:48,122 INFO L87 Difference]: Start difference. First operand 344 states and 425 transitions. Second operand has 8 states, 8 states have (on average 7.875) internal successors, (63), 6 states have internal predecessors, (63), 2 states have call successors, (3), 3 states have call predecessors, (3), 1 states have return successors, (2), 1 states have call predecessors, (2), 1 states have call successors, (2) [2021-12-16 01:00:48,282 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2021-12-16 01:00:48,282 INFO L93 Difference]: Finished difference Result 626 states and 785 transitions. [2021-12-16 01:00:48,282 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 8 states. [2021-12-16 01:00:48,282 INFO L78 Accepts]: Start accepts. Automaton has has 8 states, 8 states have (on average 7.875) internal successors, (63), 6 states have internal predecessors, (63), 2 states have call successors, (3), 3 states have call predecessors, (3), 1 states have return successors, (2), 1 states have call predecessors, (2), 1 states have call successors, (2) Word has length 71 [2021-12-16 01:00:48,283 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2021-12-16 01:00:48,284 INFO L225 Difference]: With dead ends: 626 [2021-12-16 01:00:48,284 INFO L226 Difference]: Without dead ends: 289 [2021-12-16 01:00:48,286 INFO L932 BasicCegarLoop]: 0 DeclaredPredicates, 17 GetRequests, 7 SyntacticMatches, 1 SemanticMatches, 9 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 4 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=30, Invalid=80, Unknown=0, NotChecked=0, Total=110 [2021-12-16 01:00:48,286 INFO L933 BasicCegarLoop]: 86 mSDtfsCounter, 155 mSDsluCounter, 281 mSDsCounter, 0 mSdLazyCounter, 213 mSolverCounterSat, 37 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.1s Time, 0 mProtectedPredicate, 0 mProtectedAction, 157 SdHoareTripleChecker+Valid, 367 SdHoareTripleChecker+Invalid, 250 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 37 IncrementalHoareTripleChecker+Valid, 213 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.1s IncrementalHoareTripleChecker+Time [2021-12-16 01:00:48,286 INFO L934 BasicCegarLoop]: SdHoareTripleChecker [157 Valid, 367 Invalid, 250 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [37 Valid, 213 Invalid, 0 Unknown, 0 Unchecked, 0.1s Time] [2021-12-16 01:00:48,287 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 289 states. [2021-12-16 01:00:48,301 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 289 to 285. [2021-12-16 01:00:48,301 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 285 states, 228 states have (on average 1.2149122807017543) internal successors, (277), 245 states have internal predecessors, (277), 25 states have call successors, (25), 23 states have call predecessors, (25), 31 states have return successors, (44), 27 states have call predecessors, (44), 25 states have call successors, (44) [2021-12-16 01:00:48,303 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 285 states to 285 states and 346 transitions. [2021-12-16 01:00:48,303 INFO L78 Accepts]: Start accepts. Automaton has 285 states and 346 transitions. Word has length 71 [2021-12-16 01:00:48,303 INFO L84 Accepts]: Finished accepts. word is rejected. [2021-12-16 01:00:48,303 INFO L470 AbstractCegarLoop]: Abstraction has 285 states and 346 transitions. [2021-12-16 01:00:48,303 INFO L471 AbstractCegarLoop]: INTERPOLANT automaton has has 8 states, 8 states have (on average 7.875) internal successors, (63), 6 states have internal predecessors, (63), 2 states have call successors, (3), 3 states have call predecessors, (3), 1 states have return successors, (2), 1 states have call predecessors, (2), 1 states have call successors, (2) [2021-12-16 01:00:48,304 INFO L276 IsEmpty]: Start isEmpty. Operand 285 states and 346 transitions. [2021-12-16 01:00:48,305 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 76 [2021-12-16 01:00:48,305 INFO L506 BasicCegarLoop]: Found error trace [2021-12-16 01:00:48,305 INFO L514 BasicCegarLoop]: trace histogram [2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2021-12-16 01:00:48,305 WARN L452 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable7 [2021-12-16 01:00:48,305 INFO L402 AbstractCegarLoop]: === Iteration 9 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2021-12-16 01:00:48,305 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2021-12-16 01:00:48,306 INFO L85 PathProgramCache]: Analyzing trace with hash -1821675151, now seen corresponding path program 1 times [2021-12-16 01:00:48,306 INFO L121 FreeRefinementEngine]: Executing refinement strategy CAMEL [2021-12-16 01:00:48,306 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [1199921139] [2021-12-16 01:00:48,306 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2021-12-16 01:00:48,306 INFO L126 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2021-12-16 01:00:48,322 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 01:00:48,353 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 11 [2021-12-16 01:00:48,354 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 01:00:48,361 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 20 [2021-12-16 01:00:48,363 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 01:00:48,371 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 3 [2021-12-16 01:00:48,372 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 01:00:48,375 INFO L134 CoverageAnalysis]: Checked inductivity of 17 backedges. 4 proven. 1 refuted. 0 times theorem prover too weak. 12 trivial. 0 not checked. [2021-12-16 01:00:48,375 INFO L139 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2021-12-16 01:00:48,376 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [1199921139] [2021-12-16 01:00:48,376 INFO L160 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [1199921139] provided 0 perfect and 1 imperfect interpolant sequences [2021-12-16 01:00:48,376 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleZ3 [1255689852] [2021-12-16 01:00:48,376 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2021-12-16 01:00:48,376 INFO L168 SolverBuilder]: Constructing external solver with command: z3 -smt2 -in SMTLIB2_COMPLIANT=true [2021-12-16 01:00:48,376 INFO L189 MonitoredProcess]: No working directory specified, using /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 [2021-12-16 01:00:48,383 INFO L229 MonitoredProcess]: Starting monitored process 2 with /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 -smt2 -in SMTLIB2_COMPLIANT=true (exit command is (exit), workingDir is null) [2021-12-16 01:00:48,401 INFO L327 MonitoredProcess]: [MP /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 -smt2 -in SMTLIB2_COMPLIANT=true (2)] Waiting until timeout for monitored process [2021-12-16 01:00:48,475 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 01:00:48,478 INFO L263 TraceCheckSpWp]: Trace formula consists of 436 conjuncts, 8 conjunts are in the unsatisfiable core [2021-12-16 01:00:48,483 INFO L286 TraceCheckSpWp]: Computing forward predicates... [2021-12-16 01:00:48,690 INFO L134 CoverageAnalysis]: Checked inductivity of 17 backedges. 13 proven. 4 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2021-12-16 01:00:48,690 INFO L328 TraceCheckSpWp]: Computing backward predicates... [2021-12-16 01:00:48,891 INFO L134 CoverageAnalysis]: Checked inductivity of 17 backedges. 13 proven. 4 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2021-12-16 01:00:48,891 INFO L160 FreeRefinementEngine]: IpTcStrategyModuleZ3 [1255689852] provided 0 perfect and 2 imperfect interpolant sequences [2021-12-16 01:00:48,891 INFO L186 FreeRefinementEngine]: Found 0 perfect and 3 imperfect interpolant sequences. [2021-12-16 01:00:48,891 INFO L199 FreeRefinementEngine]: Number of different interpolants: perfect sequences [] imperfect sequences [8, 6, 6] total 12 [2021-12-16 01:00:48,892 INFO L115 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [511681135] [2021-12-16 01:00:48,892 INFO L85 oduleStraightlineAll]: Using 3 imperfect interpolants to construct interpolant automaton [2021-12-16 01:00:48,893 INFO L546 AbstractCegarLoop]: INTERPOLANT automaton has 12 states [2021-12-16 01:00:48,893 INFO L103 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2021-12-16 01:00:48,893 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 12 interpolants. [2021-12-16 01:00:48,893 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=24, Invalid=108, Unknown=0, NotChecked=0, Total=132 [2021-12-16 01:00:48,894 INFO L87 Difference]: Start difference. First operand 285 states and 346 transitions. Second operand has 12 states, 12 states have (on average 8.666666666666666) internal successors, (104), 9 states have internal predecessors, (104), 2 states have call successors, (7), 5 states have call predecessors, (7), 2 states have return successors, (5), 2 states have call predecessors, (5), 1 states have call successors, (5) [2021-12-16 01:00:49,673 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2021-12-16 01:00:49,673 INFO L93 Difference]: Finished difference Result 670 states and 865 transitions. [2021-12-16 01:00:49,673 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 36 states. [2021-12-16 01:00:49,673 INFO L78 Accepts]: Start accepts. Automaton has has 12 states, 12 states have (on average 8.666666666666666) internal successors, (104), 9 states have internal predecessors, (104), 2 states have call successors, (7), 5 states have call predecessors, (7), 2 states have return successors, (5), 2 states have call predecessors, (5), 1 states have call successors, (5) Word has length 75 [2021-12-16 01:00:49,674 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2021-12-16 01:00:49,676 INFO L225 Difference]: With dead ends: 670 [2021-12-16 01:00:49,676 INFO L226 Difference]: Without dead ends: 435 [2021-12-16 01:00:49,678 INFO L932 BasicCegarLoop]: 0 DeclaredPredicates, 197 GetRequests, 157 SyntacticMatches, 1 SemanticMatches, 39 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 401 ImplicationChecksByTransitivity, 0.3s TimeCoverageRelationStatistics Valid=312, Invalid=1328, Unknown=0, NotChecked=0, Total=1640 [2021-12-16 01:00:49,678 INFO L933 BasicCegarLoop]: 148 mSDtfsCounter, 331 mSDsluCounter, 870 mSDsCounter, 0 mSdLazyCounter, 743 mSolverCounterSat, 89 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.4s Time, 0 mProtectedPredicate, 0 mProtectedAction, 335 SdHoareTripleChecker+Valid, 1018 SdHoareTripleChecker+Invalid, 832 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 89 IncrementalHoareTripleChecker+Valid, 743 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.5s IncrementalHoareTripleChecker+Time [2021-12-16 01:00:49,679 INFO L934 BasicCegarLoop]: SdHoareTripleChecker [335 Valid, 1018 Invalid, 832 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [89 Valid, 743 Invalid, 0 Unknown, 0 Unchecked, 0.5s Time] [2021-12-16 01:00:49,679 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 435 states. [2021-12-16 01:00:49,697 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 435 to 364. [2021-12-16 01:00:49,697 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 364 states, 291 states have (on average 1.2164948453608246) internal successors, (354), 311 states have internal predecessors, (354), 34 states have call successors, (34), 33 states have call predecessors, (34), 38 states have return successors, (61), 32 states have call predecessors, (61), 34 states have call successors, (61) [2021-12-16 01:00:49,699 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 364 states to 364 states and 449 transitions. [2021-12-16 01:00:49,699 INFO L78 Accepts]: Start accepts. Automaton has 364 states and 449 transitions. Word has length 75 [2021-12-16 01:00:49,699 INFO L84 Accepts]: Finished accepts. word is rejected. [2021-12-16 01:00:49,700 INFO L470 AbstractCegarLoop]: Abstraction has 364 states and 449 transitions. [2021-12-16 01:00:49,700 INFO L471 AbstractCegarLoop]: INTERPOLANT automaton has has 12 states, 12 states have (on average 8.666666666666666) internal successors, (104), 9 states have internal predecessors, (104), 2 states have call successors, (7), 5 states have call predecessors, (7), 2 states have return successors, (5), 2 states have call predecessors, (5), 1 states have call successors, (5) [2021-12-16 01:00:49,700 INFO L276 IsEmpty]: Start isEmpty. Operand 364 states and 449 transitions. [2021-12-16 01:00:49,701 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 111 [2021-12-16 01:00:49,701 INFO L506 BasicCegarLoop]: Found error trace [2021-12-16 01:00:49,702 INFO L514 BasicCegarLoop]: trace histogram [3, 3, 3, 3, 3, 3, 3, 3, 3, 3, 3, 3, 3, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2021-12-16 01:00:49,730 INFO L540 MonitoredProcess]: [MP /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 -smt2 -in SMTLIB2_COMPLIANT=true (2)] Forceful destruction successful, exit code 0 [2021-12-16 01:00:49,927 WARN L452 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable8,2 /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 -smt2 -in SMTLIB2_COMPLIANT=true [2021-12-16 01:00:49,927 INFO L402 AbstractCegarLoop]: === Iteration 10 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2021-12-16 01:00:49,927 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2021-12-16 01:00:49,927 INFO L85 PathProgramCache]: Analyzing trace with hash 1004345305, now seen corresponding path program 1 times [2021-12-16 01:00:49,928 INFO L121 FreeRefinementEngine]: Executing refinement strategy CAMEL [2021-12-16 01:00:49,928 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [316397193] [2021-12-16 01:00:49,928 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2021-12-16 01:00:49,928 INFO L126 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2021-12-16 01:00:49,959 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 01:00:50,008 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 11 [2021-12-16 01:00:50,009 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 01:00:50,020 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 20 [2021-12-16 01:00:50,022 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 01:00:50,034 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 3 [2021-12-16 01:00:50,036 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 01:00:50,043 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 56 [2021-12-16 01:00:50,045 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 01:00:50,048 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 10 [2021-12-16 01:00:50,049 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 01:00:50,051 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 2 [2021-12-16 01:00:50,051 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 01:00:50,053 INFO L134 CoverageAnalysis]: Checked inductivity of 65 backedges. 8 proven. 2 refuted. 0 times theorem prover too weak. 55 trivial. 0 not checked. [2021-12-16 01:00:50,053 INFO L139 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2021-12-16 01:00:50,053 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [316397193] [2021-12-16 01:00:50,053 INFO L160 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [316397193] provided 0 perfect and 1 imperfect interpolant sequences [2021-12-16 01:00:50,053 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleZ3 [101161279] [2021-12-16 01:00:50,053 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2021-12-16 01:00:50,054 INFO L168 SolverBuilder]: Constructing external solver with command: z3 -smt2 -in SMTLIB2_COMPLIANT=true [2021-12-16 01:00:50,054 INFO L189 MonitoredProcess]: No working directory specified, using /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 [2021-12-16 01:00:50,055 INFO L229 MonitoredProcess]: Starting monitored process 3 with /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 -smt2 -in SMTLIB2_COMPLIANT=true (exit command is (exit), workingDir is null) [2021-12-16 01:00:50,056 INFO L327 MonitoredProcess]: [MP /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 -smt2 -in SMTLIB2_COMPLIANT=true (3)] Waiting until timeout for monitored process [2021-12-16 01:00:50,150 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 01:00:50,153 INFO L263 TraceCheckSpWp]: Trace formula consists of 526 conjuncts, 11 conjunts are in the unsatisfiable core [2021-12-16 01:00:50,161 INFO L286 TraceCheckSpWp]: Computing forward predicates... [2021-12-16 01:00:50,483 INFO L134 CoverageAnalysis]: Checked inductivity of 65 backedges. 56 proven. 9 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2021-12-16 01:00:50,483 INFO L328 TraceCheckSpWp]: Computing backward predicates... [2021-12-16 01:00:50,822 INFO L134 CoverageAnalysis]: Checked inductivity of 65 backedges. 54 proven. 9 refuted. 0 times theorem prover too weak. 2 trivial. 0 not checked. [2021-12-16 01:00:50,823 INFO L160 FreeRefinementEngine]: IpTcStrategyModuleZ3 [101161279] provided 0 perfect and 2 imperfect interpolant sequences [2021-12-16 01:00:50,823 INFO L186 FreeRefinementEngine]: Found 0 perfect and 3 imperfect interpolant sequences. [2021-12-16 01:00:50,823 INFO L199 FreeRefinementEngine]: Number of different interpolants: perfect sequences [] imperfect sequences [8, 9, 8] total 20 [2021-12-16 01:00:50,823 INFO L115 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [821889095] [2021-12-16 01:00:50,823 INFO L85 oduleStraightlineAll]: Using 3 imperfect interpolants to construct interpolant automaton [2021-12-16 01:00:50,824 INFO L546 AbstractCegarLoop]: INTERPOLANT automaton has 20 states [2021-12-16 01:00:50,824 INFO L103 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2021-12-16 01:00:50,824 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 20 interpolants. [2021-12-16 01:00:50,825 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=71, Invalid=309, Unknown=0, NotChecked=0, Total=380 [2021-12-16 01:00:50,825 INFO L87 Difference]: Start difference. First operand 364 states and 449 transitions. Second operand has 20 states, 20 states have (on average 7.8) internal successors, (156), 17 states have internal predecessors, (156), 6 states have call successors, (14), 8 states have call predecessors, (14), 5 states have return successors, (12), 6 states have call predecessors, (12), 5 states have call successors, (12) [2021-12-16 01:00:52,458 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2021-12-16 01:00:52,458 INFO L93 Difference]: Finished difference Result 941 states and 1219 transitions. [2021-12-16 01:00:52,459 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 42 states. [2021-12-16 01:00:52,459 INFO L78 Accepts]: Start accepts. Automaton has has 20 states, 20 states have (on average 7.8) internal successors, (156), 17 states have internal predecessors, (156), 6 states have call successors, (14), 8 states have call predecessors, (14), 5 states have return successors, (12), 6 states have call predecessors, (12), 5 states have call successors, (12) Word has length 110 [2021-12-16 01:00:52,460 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2021-12-16 01:00:52,463 INFO L225 Difference]: With dead ends: 941 [2021-12-16 01:00:52,464 INFO L226 Difference]: Without dead ends: 626 [2021-12-16 01:00:52,466 INFO L932 BasicCegarLoop]: 0 DeclaredPredicates, 294 GetRequests, 239 SyntacticMatches, 2 SemanticMatches, 53 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 603 ImplicationChecksByTransitivity, 0.9s TimeCoverageRelationStatistics Valid=636, Invalid=2334, Unknown=0, NotChecked=0, Total=2970 [2021-12-16 01:00:52,466 INFO L933 BasicCegarLoop]: 226 mSDtfsCounter, 881 mSDsluCounter, 1270 mSDsCounter, 0 mSdLazyCounter, 1467 mSolverCounterSat, 264 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.7s Time, 0 mProtectedPredicate, 0 mProtectedAction, 888 SdHoareTripleChecker+Valid, 1496 SdHoareTripleChecker+Invalid, 1731 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 264 IncrementalHoareTripleChecker+Valid, 1467 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.8s IncrementalHoareTripleChecker+Time [2021-12-16 01:00:52,467 INFO L934 BasicCegarLoop]: SdHoareTripleChecker [888 Valid, 1496 Invalid, 1731 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [264 Valid, 1467 Invalid, 0 Unknown, 0 Unchecked, 0.8s Time] [2021-12-16 01:00:52,468 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 626 states. [2021-12-16 01:00:52,496 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 626 to 538. [2021-12-16 01:00:52,497 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 538 states, 424 states have (on average 1.2028301886792452) internal successors, (510), 449 states have internal predecessors, (510), 56 states have call successors, (56), 54 states have call predecessors, (56), 57 states have return successors, (91), 51 states have call predecessors, (91), 56 states have call successors, (91) [2021-12-16 01:00:52,499 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 538 states to 538 states and 657 transitions. [2021-12-16 01:00:52,500 INFO L78 Accepts]: Start accepts. Automaton has 538 states and 657 transitions. Word has length 110 [2021-12-16 01:00:52,500 INFO L84 Accepts]: Finished accepts. word is rejected. [2021-12-16 01:00:52,500 INFO L470 AbstractCegarLoop]: Abstraction has 538 states and 657 transitions. [2021-12-16 01:00:52,500 INFO L471 AbstractCegarLoop]: INTERPOLANT automaton has has 20 states, 20 states have (on average 7.8) internal successors, (156), 17 states have internal predecessors, (156), 6 states have call successors, (14), 8 states have call predecessors, (14), 5 states have return successors, (12), 6 states have call predecessors, (12), 5 states have call successors, (12) [2021-12-16 01:00:52,501 INFO L276 IsEmpty]: Start isEmpty. Operand 538 states and 657 transitions. [2021-12-16 01:00:52,502 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 118 [2021-12-16 01:00:52,502 INFO L506 BasicCegarLoop]: Found error trace [2021-12-16 01:00:52,503 INFO L514 BasicCegarLoop]: trace histogram [3, 3, 3, 3, 3, 3, 3, 3, 3, 3, 3, 3, 3, 3, 3, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2021-12-16 01:00:52,531 INFO L540 MonitoredProcess]: [MP /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 -smt2 -in SMTLIB2_COMPLIANT=true (3)] Forceful destruction successful, exit code 0 [2021-12-16 01:00:52,723 WARN L452 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: 3 /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 -smt2 -in SMTLIB2_COMPLIANT=true,SelfDestructingSolverStorable9 [2021-12-16 01:00:52,724 INFO L402 AbstractCegarLoop]: === Iteration 11 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2021-12-16 01:00:52,724 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2021-12-16 01:00:52,724 INFO L85 PathProgramCache]: Analyzing trace with hash 1976293721, now seen corresponding path program 1 times [2021-12-16 01:00:52,724 INFO L121 FreeRefinementEngine]: Executing refinement strategy CAMEL [2021-12-16 01:00:52,724 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [580010426] [2021-12-16 01:00:52,724 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2021-12-16 01:00:52,724 INFO L126 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2021-12-16 01:00:52,738 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 01:00:52,768 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 11 [2021-12-16 01:00:52,769 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 01:00:52,775 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 20 [2021-12-16 01:00:52,776 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 01:00:52,784 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 3 [2021-12-16 01:00:52,785 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 01:00:52,788 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 56 [2021-12-16 01:00:52,800 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 01:00:52,830 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 10 [2021-12-16 01:00:52,831 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 01:00:52,833 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 2 [2021-12-16 01:00:52,834 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 01:00:52,835 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 102 [2021-12-16 01:00:52,836 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 01:00:52,839 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 2 [2021-12-16 01:00:52,839 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 01:00:52,840 INFO L134 CoverageAnalysis]: Checked inductivity of 77 backedges. 44 proven. 0 refuted. 0 times theorem prover too weak. 33 trivial. 0 not checked. [2021-12-16 01:00:52,841 INFO L139 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2021-12-16 01:00:52,841 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [580010426] [2021-12-16 01:00:52,841 INFO L160 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [580010426] provided 1 perfect and 0 imperfect interpolant sequences [2021-12-16 01:00:52,841 INFO L186 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2021-12-16 01:00:52,841 INFO L199 FreeRefinementEngine]: Number of different interpolants: perfect sequences [8] imperfect sequences [] total 8 [2021-12-16 01:00:52,841 INFO L115 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [1929353926] [2021-12-16 01:00:52,841 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2021-12-16 01:00:52,841 INFO L546 AbstractCegarLoop]: INTERPOLANT automaton has 8 states [2021-12-16 01:00:52,842 INFO L103 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2021-12-16 01:00:52,842 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 8 interpolants. [2021-12-16 01:00:52,842 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=15, Invalid=41, Unknown=0, NotChecked=0, Total=56 [2021-12-16 01:00:52,843 INFO L87 Difference]: Start difference. First operand 538 states and 657 transitions. Second operand has 8 states, 8 states have (on average 10.25) internal successors, (82), 5 states have internal predecessors, (82), 2 states have call successors, (6), 5 states have call predecessors, (6), 2 states have return successors, (6), 2 states have call predecessors, (6), 2 states have call successors, (6) [2021-12-16 01:00:52,971 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2021-12-16 01:00:52,971 INFO L93 Difference]: Finished difference Result 694 states and 842 transitions. [2021-12-16 01:00:52,971 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 9 states. [2021-12-16 01:00:52,972 INFO L78 Accepts]: Start accepts. Automaton has has 8 states, 8 states have (on average 10.25) internal successors, (82), 5 states have internal predecessors, (82), 2 states have call successors, (6), 5 states have call predecessors, (6), 2 states have return successors, (6), 2 states have call predecessors, (6), 2 states have call successors, (6) Word has length 117 [2021-12-16 01:00:52,972 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2021-12-16 01:00:52,973 INFO L225 Difference]: With dead ends: 694 [2021-12-16 01:00:52,973 INFO L226 Difference]: Without dead ends: 0 [2021-12-16 01:00:52,975 INFO L932 BasicCegarLoop]: 0 DeclaredPredicates, 27 GetRequests, 17 SyntacticMatches, 0 SemanticMatches, 10 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 14 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=39, Invalid=93, Unknown=0, NotChecked=0, Total=132 [2021-12-16 01:00:52,975 INFO L933 BasicCegarLoop]: 74 mSDtfsCounter, 83 mSDsluCounter, 249 mSDsCounter, 0 mSdLazyCounter, 185 mSolverCounterSat, 16 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.1s Time, 0 mProtectedPredicate, 0 mProtectedAction, 85 SdHoareTripleChecker+Valid, 323 SdHoareTripleChecker+Invalid, 201 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 16 IncrementalHoareTripleChecker+Valid, 185 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.1s IncrementalHoareTripleChecker+Time [2021-12-16 01:00:52,976 INFO L934 BasicCegarLoop]: SdHoareTripleChecker [85 Valid, 323 Invalid, 201 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [16 Valid, 185 Invalid, 0 Unknown, 0 Unchecked, 0.1s Time] [2021-12-16 01:00:52,976 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 0 states. [2021-12-16 01:00:52,976 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 0 to 0. [2021-12-16 01:00:52,976 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 0 states, 0 states have (on average 0.0) internal successors, (0), 0 states have internal predecessors, (0), 0 states have call successors, (0), 0 states have call predecessors, (0), 0 states have return successors, (0), 0 states have call predecessors, (0), 0 states have call successors, (0) [2021-12-16 01:00:52,977 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 0 states to 0 states and 0 transitions. [2021-12-16 01:00:52,977 INFO L78 Accepts]: Start accepts. Automaton has 0 states and 0 transitions. Word has length 117 [2021-12-16 01:00:52,977 INFO L84 Accepts]: Finished accepts. word is rejected. [2021-12-16 01:00:52,977 INFO L470 AbstractCegarLoop]: Abstraction has 0 states and 0 transitions. [2021-12-16 01:00:52,977 INFO L471 AbstractCegarLoop]: INTERPOLANT automaton has has 8 states, 8 states have (on average 10.25) internal successors, (82), 5 states have internal predecessors, (82), 2 states have call successors, (6), 5 states have call predecessors, (6), 2 states have return successors, (6), 2 states have call predecessors, (6), 2 states have call successors, (6) [2021-12-16 01:00:52,977 INFO L276 IsEmpty]: Start isEmpty. Operand 0 states and 0 transitions. [2021-12-16 01:00:52,977 INFO L282 IsEmpty]: Finished isEmpty. No accepting run. [2021-12-16 01:00:52,980 INFO L764 garLoopResultBuilder]: Registering result SAFE for location timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION (0 of 1 remaining) [2021-12-16 01:00:52,980 WARN L452 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable10 [2021-12-16 01:00:52,982 INFO L343 DoubleDeckerVisitor]: Before removal of dead ends 0 states and 0 transitions. [2021-12-16 01:00:54,816 INFO L858 garLoopResultBuilder]: For program point processEnvironment__wrappee__baseEXIT(lines 731 737) no Hoare annotation was computed. [2021-12-16 01:00:54,817 INFO L861 garLoopResultBuilder]: At program point processEnvironment__wrappee__baseFINAL(lines 731 737) the Hoare annotation is: true [2021-12-16 01:00:54,817 INFO L861 garLoopResultBuilder]: At program point changeMethaneLevelENTRY(lines 487 498) the Hoare annotation is: true [2021-12-16 01:00:54,817 INFO L858 garLoopResultBuilder]: For program point L491-1(lines 487 498) no Hoare annotation was computed. [2021-12-16 01:00:54,817 INFO L858 garLoopResultBuilder]: For program point changeMethaneLevelEXIT(lines 487 498) no Hoare annotation was computed. [2021-12-16 01:00:54,817 INFO L854 garLoopResultBuilder]: At program point L779(line 779) the Hoare annotation is: (let ((.cse0 (not (= ~systemActive~0 1)))) (and (or (not (<= 2 |old(~waterLevel~0)|)) .cse0) (or (not (= |old(~pumpRunning~0)| 0)) .cse0 (not (<= 1 |old(~waterLevel~0)|))))) [2021-12-16 01:00:54,817 INFO L858 garLoopResultBuilder]: For program point timeShiftFINAL(lines 707 730) no Hoare annotation was computed. [2021-12-16 01:00:54,817 INFO L858 garLoopResultBuilder]: For program point L449(line 449) no Hoare annotation was computed. [2021-12-16 01:00:54,818 INFO L854 garLoopResultBuilder]: At program point L536(lines 531 539) the Hoare annotation is: (let ((.cse4 (= ~waterLevel~0 |old(~waterLevel~0)|)) (.cse0 (<= 1 |timeShift_getWaterLevel_#res#1|)) (.cse5 (= ~systemActive~0 1))) (let ((.cse1 (= ~pumpRunning~0 0)) (.cse2 (and .cse4 (<= 2 ~waterLevel~0) .cse0 .cse5)) (.cse3 (not .cse5))) (and (or (not (<= 2 |old(~waterLevel~0)|)) (and (<= 1 |timeShift_isLowWaterLevel_~tmp___0~2#1|) (= |timeShift_isLowWaterLevel_~tmp~9#1| 0) (<= 1 |timeShift_processEnvironment_~tmp~6#1|) (<= 1 |timeShift_isLowWaterLevel_#res#1|) (= |timeShift_isLowWaterSensorDry_#res#1| 0) (<= |old(~waterLevel~0)| (+ ~waterLevel~0 1)) .cse0 .cse1) .cse2 .cse3) (or (and .cse4 .cse0 .cse1) (not (= |old(~pumpRunning~0)| 0)) .cse2 .cse3 (not (<= 1 |old(~waterLevel~0)|)))))) [2021-12-16 01:00:54,818 INFO L854 garLoopResultBuilder]: At program point L821(lines 816 823) the Hoare annotation is: (let ((.cse0 (not (= ~systemActive~0 1)))) (and (or (not (<= 2 |old(~waterLevel~0)|)) (and (<= 1 |timeShift_isLowWaterLevel_~tmp___0~2#1|) (= |timeShift_isLowWaterLevel_~tmp~9#1| 0) (<= 1 |timeShift_processEnvironment_~tmp~6#1|) (<= 1 |timeShift_isLowWaterLevel_#res#1|) (= |timeShift_isLowWaterSensorDry_#res#1| 0) (<= |old(~waterLevel~0)| (+ ~waterLevel~0 1)) (= ~pumpRunning~0 0)) .cse0) (or (not (= |old(~pumpRunning~0)| 0)) .cse0 (not (<= 1 |old(~waterLevel~0)|))))) [2021-12-16 01:00:54,818 INFO L854 garLoopResultBuilder]: At program point L784(line 784) the Hoare annotation is: (let ((.cse0 (= ~pumpRunning~0 0)) (.cse1 (not (= ~systemActive~0 1)))) (and (or (and (= ~waterLevel~0 |old(~waterLevel~0)|) .cse0) (not (= |old(~pumpRunning~0)| 0)) .cse1 (not (<= 1 |old(~waterLevel~0)|))) (or (not (<= 2 |old(~waterLevel~0)|)) (and (= ~pumpRunning~0 |old(~pumpRunning~0)|) .cse0) .cse1))) [2021-12-16 01:00:54,818 INFO L854 garLoopResultBuilder]: At program point L784-1(lines 765 789) the Hoare annotation is: (let ((.cse3 (= ~waterLevel~0 |old(~waterLevel~0)|)) (.cse4 (= ~systemActive~0 1))) (let ((.cse0 (and .cse3 (<= 2 ~waterLevel~0) .cse4)) (.cse1 (= ~pumpRunning~0 0)) (.cse2 (not .cse4))) (and (or .cse0 (not (<= 2 |old(~waterLevel~0)|)) (and (<= 1 |timeShift_isLowWaterLevel_~tmp___0~2#1|) (= |timeShift_isLowWaterLevel_~tmp~9#1| 0) (<= 1 |timeShift_processEnvironment_~tmp~6#1|) (<= 1 |timeShift_isLowWaterLevel_#res#1|) (= |timeShift_isLowWaterSensorDry_#res#1| 0) (<= |old(~waterLevel~0)| (+ ~waterLevel~0 1)) .cse1) .cse2) (or .cse0 (and .cse3 .cse1) (not (= |old(~pumpRunning~0)| 0)) .cse2 (not (<= 1 |old(~waterLevel~0)|)))))) [2021-12-16 01:00:54,819 INFO L858 garLoopResultBuilder]: For program point L718-1(lines 718 724) no Hoare annotation was computed. [2021-12-16 01:00:54,819 INFO L858 garLoopResultBuilder]: For program point L908(lines 908 912) no Hoare annotation was computed. [2021-12-16 01:00:54,819 INFO L858 garLoopResultBuilder]: For program point L908-2(lines 908 912) no Hoare annotation was computed. [2021-12-16 01:00:54,820 INFO L854 garLoopResultBuilder]: At program point L450(lines 445 452) the Hoare annotation is: (let ((.cse0 (not (= ~systemActive~0 1)))) (and (or (not (<= 2 |old(~waterLevel~0)|)) .cse0) (or (not (= |old(~pumpRunning~0)| 0)) .cse0 (not (<= 1 |old(~waterLevel~0)|))))) [2021-12-16 01:00:54,820 INFO L858 garLoopResultBuilder]: For program point L467(lines 467 471) no Hoare annotation was computed. [2021-12-16 01:00:54,820 INFO L854 garLoopResultBuilder]: At program point L467-2(lines 463 474) the Hoare annotation is: (let ((.cse0 (not (= ~systemActive~0 1)))) (and (or (not (= |old(~pumpRunning~0)| 0)) .cse0 (not (<= 1 |old(~waterLevel~0)|))) (or (not (<= 2 |old(~waterLevel~0)|)) (and (= ~pumpRunning~0 |old(~pumpRunning~0)|) (<= |old(~waterLevel~0)| (+ ~waterLevel~0 1))) .cse0))) [2021-12-16 01:00:54,820 INFO L858 garLoopResultBuilder]: For program point L711-1(lines 710 729) no Hoare annotation was computed. [2021-12-16 01:00:54,820 INFO L858 garLoopResultBuilder]: For program point L773(lines 773 781) no Hoare annotation was computed. [2021-12-16 01:00:54,820 INFO L858 garLoopResultBuilder]: For program point L769(lines 769 786) no Hoare annotation was computed. [2021-12-16 01:00:54,820 INFO L854 garLoopResultBuilder]: At program point L914(lines 899 917) the Hoare annotation is: (let ((.cse0 (not (= ~systemActive~0 1)))) (and (or (not (= |old(~pumpRunning~0)| 0)) .cse0 (not (<= 1 |old(~waterLevel~0)|))) (or (not (<= 2 |old(~waterLevel~0)|)) (and (<= 1 |timeShift_isLowWaterLevel_~tmp___0~2#1|) (= |timeShift_isLowWaterLevel_~tmp~9#1| 0) (<= 1 |timeShift_isLowWaterLevel_#res#1|) (= |timeShift_isLowWaterSensorDry_#res#1| 0) (= ~pumpRunning~0 |old(~pumpRunning~0)|) (<= |old(~waterLevel~0)| (+ ~waterLevel~0 1))) .cse0))) [2021-12-16 01:00:54,821 INFO L854 garLoopResultBuilder]: At program point timeShiftENTRY(lines 707 730) the Hoare annotation is: (let ((.cse0 (= ~waterLevel~0 |old(~waterLevel~0)|)) (.cse1 (not (= ~systemActive~0 1)))) (and (or (not (<= 2 |old(~waterLevel~0)|)) (and .cse0 (= ~pumpRunning~0 |old(~pumpRunning~0)|)) .cse1) (or (and .cse0 (= ~pumpRunning~0 0)) (not (= |old(~pumpRunning~0)| 0)) .cse1 (not (<= 1 |old(~waterLevel~0)|))))) [2021-12-16 01:00:54,821 INFO L854 garLoopResultBuilder]: At program point L559(lines 554 562) the Hoare annotation is: (let ((.cse0 (not (= ~systemActive~0 1)))) (and (or (not (<= 2 |old(~waterLevel~0)|)) (and (= |timeShift_isLowWaterSensorDry_#res#1| 0) (= ~pumpRunning~0 |old(~pumpRunning~0)|) (<= |old(~waterLevel~0)| (+ ~waterLevel~0 1))) .cse0) (or (not (= |old(~pumpRunning~0)| 0)) .cse0 (not (<= 1 |old(~waterLevel~0)|))))) [2021-12-16 01:00:54,821 INFO L858 garLoopResultBuilder]: For program point L431(lines 431 437) no Hoare annotation was computed. [2021-12-16 01:00:54,821 INFO L858 garLoopResultBuilder]: For program point L427(lines 427 440) no Hoare annotation was computed. [2021-12-16 01:00:54,821 INFO L858 garLoopResultBuilder]: For program point timeShiftEXIT(lines 707 730) no Hoare annotation was computed. [2021-12-16 01:00:54,821 INFO L854 garLoopResultBuilder]: At program point L427-1(lines 419 443) the Hoare annotation is: (let ((.cse1 (<= 1 |timeShift___utac_acc__Specification4_spec__1_~tmp~3#1|)) (.cse5 (= ~waterLevel~0 |old(~waterLevel~0)|)) (.cse2 (<= 1 |timeShift_getWaterLevel_#res#1|)) (.cse6 (= ~systemActive~0 1))) (let ((.cse3 (= ~pumpRunning~0 0)) (.cse0 (and .cse1 .cse5 (<= 2 ~waterLevel~0) .cse2 .cse6)) (.cse4 (not .cse6))) (and (or (not (<= 2 |old(~waterLevel~0)|)) .cse0 (and .cse1 (<= 1 |timeShift_isLowWaterLevel_~tmp___0~2#1|) (= |timeShift_isLowWaterLevel_~tmp~9#1| 0) (<= 1 |timeShift_processEnvironment_~tmp~6#1|) (<= 1 |timeShift_isLowWaterLevel_#res#1|) (= |timeShift_isLowWaterSensorDry_#res#1| 0) (<= |old(~waterLevel~0)| (+ ~waterLevel~0 1)) .cse2 .cse3) .cse4) (or (and .cse1 .cse5 .cse2 .cse3) (not (= |old(~pumpRunning~0)| 0)) .cse0 .cse4 (not (<= 1 |old(~waterLevel~0)|)))))) [2021-12-16 01:00:54,822 INFO L858 garLoopResultBuilder]: For program point timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION(line 449) no Hoare annotation was computed. [2021-12-16 01:00:54,822 INFO L854 garLoopResultBuilder]: At program point L840(lines 835 843) the Hoare annotation is: (let ((.cse0 (not (= ~systemActive~0 1)))) (and (or (not (<= 2 |old(~waterLevel~0)|)) .cse0) (or (not (= |old(~pumpRunning~0)| 0)) .cse0 (not (<= 1 |old(~waterLevel~0)|))))) [2021-12-16 01:00:54,822 INFO L858 garLoopResultBuilder]: For program point L577(line 577) no Hoare annotation was computed. [2021-12-16 01:00:54,822 INFO L858 garLoopResultBuilder]: For program point cleanupEXIT(lines 566 595) no Hoare annotation was computed. [2021-12-16 01:00:54,822 INFO L861 garLoopResultBuilder]: At program point L576-2(lines 576 590) the Hoare annotation is: true [2021-12-16 01:00:54,822 INFO L861 garLoopResultBuilder]: At program point cleanupENTRY(lines 566 595) the Hoare annotation is: true [2021-12-16 01:00:54,823 INFO L861 garLoopResultBuilder]: At program point L572(line 572) the Hoare annotation is: true [2021-12-16 01:00:54,823 INFO L858 garLoopResultBuilder]: For program point L572-1(line 572) no Hoare annotation was computed. [2021-12-16 01:00:54,823 INFO L861 garLoopResultBuilder]: At program point L591(lines 566 595) the Hoare annotation is: true [2021-12-16 01:00:54,823 INFO L858 garLoopResultBuilder]: For program point L587(line 587) no Hoare annotation was computed. [2021-12-16 01:00:54,823 INFO L858 garLoopResultBuilder]: For program point L580(lines 580 584) no Hoare annotation was computed. [2021-12-16 01:00:54,823 INFO L861 garLoopResultBuilder]: At program point L580-1(lines 580 584) the Hoare annotation is: true [2021-12-16 01:00:54,823 INFO L854 garLoopResultBuilder]: At program point L923(lines 918 925) the Hoare annotation is: (let ((.cse0 (= |ULTIMATE.start_test_~splverifierCounter~0#1| 0)) (.cse1 (= 1 |ULTIMATE.start_valid_product_#res#1|)) (.cse2 (= ~systemActive~0 |ULTIMATE.start_main_~tmp~4#1|)) (.cse3 (= ~systemActive~0 1))) (or (and .cse0 .cse1 .cse2 (= ~waterLevel~0 |ULTIMATE.start_main_~tmp~4#1|) .cse3 (= ~pumpRunning~0 0)) (and .cse0 .cse1 (<= 2 ~waterLevel~0) .cse2 .cse3))) [2021-12-16 01:00:54,824 INFO L854 garLoopResultBuilder]: At program point L985(lines 936 986) the Hoare annotation is: false [2021-12-16 01:00:54,824 INFO L854 garLoopResultBuilder]: At program point L696(lines 691 699) the Hoare annotation is: (and (= ~waterLevel~0 1) (= 1 |ULTIMATE.start_valid_product_#res#1|) (= ~systemActive~0 1) (= ~pumpRunning~0 0)) [2021-12-16 01:00:54,824 INFO L854 garLoopResultBuilder]: At program point L688(lines 684 690) the Hoare annotation is: (and (= ~waterLevel~0 1) (= ~systemActive~0 1) (= ~pumpRunning~0 0)) [2021-12-16 01:00:54,824 INFO L858 garLoopResultBuilder]: For program point L-1(line -1) no Hoare annotation was computed. [2021-12-16 01:00:54,824 INFO L858 garLoopResultBuilder]: For program point ULTIMATE.startENTRY(line -1) no Hoare annotation was computed. [2021-12-16 01:00:54,824 INFO L858 garLoopResultBuilder]: For program point L957(lines 957 963) no Hoare annotation was computed. [2021-12-16 01:00:54,824 INFO L858 garLoopResultBuilder]: For program point ULTIMATE.startFINAL(line -1) no Hoare annotation was computed. [2021-12-16 01:00:54,824 INFO L858 garLoopResultBuilder]: For program point L957-1(lines 957 963) no Hoare annotation was computed. [2021-12-16 01:00:54,825 INFO L854 garLoopResultBuilder]: At program point L982(lines 937 984) the Hoare annotation is: (let ((.cse0 (= |ULTIMATE.start_test_~splverifierCounter~0#1| 0)) (.cse1 (= 1 |ULTIMATE.start_valid_product_#res#1|)) (.cse2 (= ~systemActive~0 |ULTIMATE.start_main_~tmp~4#1|)) (.cse3 (= ~systemActive~0 1))) (or (and .cse0 .cse1 .cse2 (= ~waterLevel~0 |ULTIMATE.start_main_~tmp~4#1|) .cse3 (= ~pumpRunning~0 0)) (and .cse0 .cse1 (<= 2 ~waterLevel~0) .cse2 .cse3))) [2021-12-16 01:00:54,825 INFO L854 garLoopResultBuilder]: At program point L949(line 949) the Hoare annotation is: (let ((.cse0 (= |ULTIMATE.start_test_~splverifierCounter~0#1| 0)) (.cse1 (= 1 |ULTIMATE.start_valid_product_#res#1|)) (.cse2 (= ~systemActive~0 1))) (or (and .cse0 .cse1 (= ~systemActive~0 |ULTIMATE.start_main_~tmp~4#1|) (= ~waterLevel~0 |ULTIMATE.start_main_~tmp~4#1|) .cse2 (= ~pumpRunning~0 0)) (and .cse0 (= 1 |ULTIMATE.start_main_~tmp~4#1|) .cse1 (<= 2 ~waterLevel~0) .cse2))) [2021-12-16 01:00:54,825 INFO L858 garLoopResultBuilder]: For program point L652(lines 652 659) no Hoare annotation was computed. [2021-12-16 01:00:54,825 INFO L858 garLoopResultBuilder]: For program point L652-2(lines 652 659) no Hoare annotation was computed. [2021-12-16 01:00:54,825 INFO L854 garLoopResultBuilder]: At program point L681(lines 677 683) the Hoare annotation is: (and (= ~waterLevel~0 1) (= ~systemActive~0 1) (= ~pumpRunning~0 0)) [2021-12-16 01:00:54,825 INFO L858 garLoopResultBuilder]: For program point ULTIMATE.startEXIT(line -1) no Hoare annotation was computed. [2021-12-16 01:00:54,825 INFO L861 garLoopResultBuilder]: At program point L636(lines 629 638) the Hoare annotation is: true [2021-12-16 01:00:54,825 INFO L861 garLoopResultBuilder]: At program point L661(lines 642 664) the Hoare annotation is: true [2021-12-16 01:00:54,826 INFO L858 garLoopResultBuilder]: For program point L975(lines 975 979) no Hoare annotation was computed. [2021-12-16 01:00:54,826 INFO L854 garLoopResultBuilder]: At program point L975-2(lines 967 980) the Hoare annotation is: (let ((.cse0 (= |ULTIMATE.start_test_~splverifierCounter~0#1| 0)) (.cse1 (= 1 |ULTIMATE.start_valid_product_#res#1|)) (.cse2 (= ~systemActive~0 |ULTIMATE.start_main_~tmp~4#1|)) (.cse3 (= ~systemActive~0 1))) (or (and .cse0 .cse1 .cse2 (= ~waterLevel~0 |ULTIMATE.start_main_~tmp~4#1|) .cse3 (= ~pumpRunning~0 0)) (and .cse0 .cse1 (<= 2 ~waterLevel~0) .cse2 .cse3))) [2021-12-16 01:00:54,826 INFO L858 garLoopResultBuilder]: For program point L938(lines 937 984) no Hoare annotation was computed. [2021-12-16 01:00:54,826 INFO L858 garLoopResultBuilder]: For program point L967(lines 967 980) no Hoare annotation was computed. [2021-12-16 01:00:54,826 INFO L854 garLoopResultBuilder]: At program point L959(line 959) the Hoare annotation is: (let ((.cse0 (= |ULTIMATE.start_test_~splverifierCounter~0#1| 0)) (.cse1 (= 1 |ULTIMATE.start_valid_product_#res#1|)) (.cse2 (= ~systemActive~0 |ULTIMATE.start_main_~tmp~4#1|)) (.cse3 (= ~systemActive~0 1))) (or (and .cse0 .cse1 .cse2 (= ~waterLevel~0 |ULTIMATE.start_main_~tmp~4#1|) .cse3 (= ~pumpRunning~0 0)) (and .cse0 .cse1 (<= 2 ~waterLevel~0) .cse2 .cse3))) [2021-12-16 01:00:54,827 INFO L861 garLoopResultBuilder]: At program point L988(lines 927 992) the Hoare annotation is: true [2021-12-16 01:00:54,827 INFO L858 garLoopResultBuilder]: For program point L947(lines 947 953) no Hoare annotation was computed. [2021-12-16 01:00:54,827 INFO L858 garLoopResultBuilder]: For program point L947-1(lines 947 953) no Hoare annotation was computed. [2021-12-16 01:00:54,827 INFO L854 garLoopResultBuilder]: At program point L625(lines 621 627) the Hoare annotation is: (and (= 1 |ULTIMATE.start_valid_product_#res#1|) (= ~systemActive~0 |ULTIMATE.start_main_~tmp~4#1|) (= ~waterLevel~0 |ULTIMATE.start_main_~tmp~4#1|) (= ~systemActive~0 1) (= ~pumpRunning~0 0)) [2021-12-16 01:00:54,827 INFO L858 garLoopResultBuilder]: For program point L939(lines 939 943) no Hoare annotation was computed. [2021-12-16 01:00:54,827 INFO L854 garLoopResultBuilder]: At program point processEnvironment__wrappee__highWaterSensorENTRY(lines 739 763) the Hoare annotation is: (or (not (<= 1 ~waterLevel~0)) (not (= |old(~pumpRunning~0)| 0)) (not (= ~systemActive~0 1)) (= ~pumpRunning~0 0)) [2021-12-16 01:00:54,828 INFO L854 garLoopResultBuilder]: At program point L795(lines 790 797) the Hoare annotation is: (or (not (<= 1 ~waterLevel~0)) (not (= |old(~pumpRunning~0)| 0)) (<= 2 ~waterLevel~0) (not (= ~systemActive~0 1))) [2021-12-16 01:00:54,828 INFO L854 garLoopResultBuilder]: At program point L504(lines 499 507) the Hoare annotation is: (or (and (<= 2 ~waterLevel~0) (= ~pumpRunning~0 0)) (not (<= 1 ~waterLevel~0)) (not (= |old(~pumpRunning~0)| 0)) (not (= ~systemActive~0 1))) [2021-12-16 01:00:54,828 INFO L854 garLoopResultBuilder]: At program point L758(line 758) the Hoare annotation is: (or (not (<= 1 ~waterLevel~0)) (not (= |old(~pumpRunning~0)| 0)) (not (= ~systemActive~0 1))) [2021-12-16 01:00:54,828 INFO L858 garLoopResultBuilder]: For program point L758-1(lines 739 763) no Hoare annotation was computed. [2021-12-16 01:00:54,829 INFO L858 garLoopResultBuilder]: For program point L806(lines 806 812) no Hoare annotation was computed. [2021-12-16 01:00:54,829 INFO L854 garLoopResultBuilder]: At program point L806-2(lines 799 815) the Hoare annotation is: (or (not (<= 1 ~waterLevel~0)) (not (= |old(~pumpRunning~0)| 0)) (<= 2 ~waterLevel~0) (not (= ~systemActive~0 1))) [2021-12-16 01:00:54,829 INFO L858 garLoopResultBuilder]: For program point L544(lines 544 550) no Hoare annotation was computed. [2021-12-16 01:00:54,830 INFO L854 garLoopResultBuilder]: At program point L895(lines 880 898) the Hoare annotation is: (let ((.cse1 (not (= |old(~pumpRunning~0)| 0))) (.cse2 (not (= ~systemActive~0 1))) (.cse0 (= ~pumpRunning~0 0))) (and (or (and (= |processEnvironment__wrappee__highWaterSensor_isHighWaterLevel_#res#1| 0) (= |processEnvironment__wrappee__highWaterSensor_isHighWaterLevel_~tmp___0~1#1| 0) (<= 1 |processEnvironment__wrappee__highWaterSensor_isHighWaterLevel_~tmp~8#1|) (<= 1 |processEnvironment__wrappee__highWaterSensor_isHighWaterSensorDry_#res#1|) .cse0) (not (= ~waterLevel~0 1)) .cse1 .cse2) (or .cse1 .cse2 .cse0 (not (<= 2 ~waterLevel~0))))) [2021-12-16 01:00:54,831 INFO L854 garLoopResultBuilder]: At program point L831(lines 824 834) the Hoare annotation is: (or (and (<= 2 ~waterLevel~0) (= ~pumpRunning~0 0)) (not (<= 1 ~waterLevel~0)) (not (= |old(~pumpRunning~0)| 0)) (not (= ~systemActive~0 1))) [2021-12-16 01:00:54,831 INFO L858 garLoopResultBuilder]: For program point processEnvironment__wrappee__highWaterSensorEXIT(lines 739 763) no Hoare annotation was computed. [2021-12-16 01:00:54,831 INFO L858 garLoopResultBuilder]: For program point L889(lines 889 893) no Hoare annotation was computed. [2021-12-16 01:00:54,831 INFO L858 garLoopResultBuilder]: For program point L889-2(lines 889 893) no Hoare annotation was computed. [2021-12-16 01:00:54,832 INFO L854 garLoopResultBuilder]: At program point L753(line 753) the Hoare annotation is: (let ((.cse0 (= |processEnvironment__wrappee__highWaterSensor_~tmp~5#1| 0)) (.cse1 (= ~pumpRunning~0 0))) (or (and .cse0 (<= 2 ~waterLevel~0) .cse1) (not (<= 1 ~waterLevel~0)) (and .cse0 (<= 1 |processEnvironment__wrappee__highWaterSensor_isHighWaterLevel_~tmp~8#1|) (<= 1 |processEnvironment__wrappee__highWaterSensor_isHighWaterSensorDry_#res#1|) .cse1) (not (= |old(~pumpRunning~0)| 0)) (not (= ~systemActive~0 1)))) [2021-12-16 01:00:54,832 INFO L858 garLoopResultBuilder]: For program point L747(lines 747 755) no Hoare annotation was computed. [2021-12-16 01:00:54,832 INFO L858 garLoopResultBuilder]: For program point L743(lines 743 760) no Hoare annotation was computed. [2021-12-16 01:00:54,832 INFO L854 garLoopResultBuilder]: At program point L549(lines 540 553) the Hoare annotation is: (let ((.cse1 (= ~pumpRunning~0 0)) (.cse0 (not (= |old(~pumpRunning~0)| 0))) (.cse2 (not (= ~systemActive~0 1)))) (and (or .cse0 (and .cse1 (= |processEnvironment__wrappee__highWaterSensor_isHighWaterSensorDry_#res#1| 0)) .cse2 (not (<= 2 ~waterLevel~0))) (or (and (<= 1 |processEnvironment__wrappee__highWaterSensor_isHighWaterSensorDry_#res#1|) .cse1) (not (= ~waterLevel~0 1)) .cse0 .cse2))) [2021-12-16 01:00:54,832 INFO L858 garLoopResultBuilder]: For program point waterRiseEXIT(lines 475 486) no Hoare annotation was computed. [2021-12-16 01:00:54,832 INFO L858 garLoopResultBuilder]: For program point L479-1(lines 475 486) no Hoare annotation was computed. [2021-12-16 01:00:54,832 INFO L854 garLoopResultBuilder]: At program point waterRiseENTRY(lines 475 486) the Hoare annotation is: (let ((.cse0 (= ~waterLevel~0 |old(~waterLevel~0)|)) (.cse1 (not (= ~systemActive~0 1)))) (and (or (not (= ~pumpRunning~0 0)) .cse0 .cse1 (not (<= 1 |old(~waterLevel~0)|))) (or (not (<= 2 |old(~waterLevel~0)|)) .cse0 .cse1))) [2021-12-16 01:00:54,835 INFO L732 BasicCegarLoop]: Path program histogram: [1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2021-12-16 01:00:54,836 INFO L179 ceAbstractionStarter]: Computing trace abstraction results [2021-12-16 01:00:54,869 INFO L202 PluginConnector]: Adding new model de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction CFG 16.12 01:00:54 BoogieIcfgContainer [2021-12-16 01:00:54,869 INFO L132 PluginConnector]: ------------------------ END TraceAbstraction---------------------------- [2021-12-16 01:00:54,870 INFO L113 PluginConnector]: ------------------------Witness Printer---------------------------- [2021-12-16 01:00:54,870 INFO L271 PluginConnector]: Initializing Witness Printer... [2021-12-16 01:00:54,870 INFO L275 PluginConnector]: Witness Printer initialized [2021-12-16 01:00:54,871 INFO L185 PluginConnector]: Executing the observer RCFGCatcher from plugin Witness Printer for "de.uni_freiburg.informatik.ultimate.plugins.generator.rcfgbuilder CFG 16.12 01:00:45" (3/4) ... [2021-12-16 01:00:54,873 INFO L137 WitnessPrinter]: Generating witness for correct program [2021-12-16 01:00:54,878 INFO L354 RCFGBacktranslator]: Ignoring RootEdge to procedure processEnvironment__wrappee__base [2021-12-16 01:00:54,878 INFO L354 RCFGBacktranslator]: Ignoring RootEdge to procedure changeMethaneLevel [2021-12-16 01:00:54,878 INFO L354 RCFGBacktranslator]: Ignoring RootEdge to procedure timeShift [2021-12-16 01:00:54,879 INFO L354 RCFGBacktranslator]: Ignoring RootEdge to procedure cleanup [2021-12-16 01:00:54,879 INFO L354 RCFGBacktranslator]: Ignoring RootEdge to procedure processEnvironment__wrappee__highWaterSensor [2021-12-16 01:00:54,879 INFO L354 RCFGBacktranslator]: Ignoring RootEdge to procedure waterRise [2021-12-16 01:00:54,886 INFO L910 BoogieBacktranslator]: Reduced CFG by removing 55 nodes and edges [2021-12-16 01:00:54,886 INFO L910 BoogieBacktranslator]: Reduced CFG by removing 22 nodes and edges [2021-12-16 01:00:54,887 INFO L910 BoogieBacktranslator]: Reduced CFG by removing 11 nodes and edges [2021-12-16 01:00:54,887 INFO L910 BoogieBacktranslator]: Reduced CFG by removing 5 nodes and edges [2021-12-16 01:00:54,887 INFO L910 BoogieBacktranslator]: Reduced CFG by removing 2 nodes and edges [2021-12-16 01:00:54,888 INFO L910 BoogieBacktranslator]: Reduced CFG by removing 1 nodes and edges [2021-12-16 01:00:54,888 INFO L910 BoogieBacktranslator]: Reduced CFG by removing 1 nodes and edges [2021-12-16 01:00:54,904 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: ((waterLevel == 1 && 1 == \result) && systemActive == 1) && pumpRunning == 0 [2021-12-16 01:00:54,904 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (((1 == \result && systemActive == tmp) && waterLevel == tmp) && systemActive == 1) && pumpRunning == 0 [2021-12-16 01:00:54,904 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (((((splverifierCounter == 0 && 1 == \result) && systemActive == tmp) && waterLevel == tmp) && systemActive == 1) && pumpRunning == 0) || ((((splverifierCounter == 0 && 1 == \result) && 2 <= waterLevel) && systemActive == tmp) && systemActive == 1) [2021-12-16 01:00:54,905 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: ((!(\old(pumpRunning) == 0) || !(systemActive == 1)) || !(1 <= \old(waterLevel))) && ((!(2 <= \old(waterLevel)) || (pumpRunning == \old(pumpRunning) && \old(waterLevel) <= waterLevel + 1)) || !(systemActive == 1)) [2021-12-16 01:00:54,905 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (((((waterLevel == \old(waterLevel) && 2 <= waterLevel) && systemActive == 1) || !(2 <= \old(waterLevel))) || ((((((1 <= tmp___0 && tmp == 0) && 1 <= tmp) && 1 <= \result) && \result == 0) && \old(waterLevel) <= waterLevel + 1) && pumpRunning == 0)) || !(systemActive == 1)) && ((((((waterLevel == \old(waterLevel) && 2 <= waterLevel) && systemActive == 1) || (waterLevel == \old(waterLevel) && pumpRunning == 0)) || !(\old(pumpRunning) == 0)) || !(systemActive == 1)) || !(1 <= \old(waterLevel))) [2021-12-16 01:00:54,906 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (((((splverifierCounter == 0 && 1 == \result) && systemActive == tmp) && waterLevel == tmp) && systemActive == 1) && pumpRunning == 0) || ((((splverifierCounter == 0 && 1 == \result) && 2 <= waterLevel) && systemActive == tmp) && systemActive == 1) [2021-12-16 01:00:54,906 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (((!(2 <= \old(waterLevel)) || (((((((1 <= tmp___0 && tmp == 0) && 1 <= tmp) && 1 <= \result) && \result == 0) && \old(waterLevel) <= waterLevel + 1) && 1 <= \result) && pumpRunning == 0)) || (((waterLevel == \old(waterLevel) && 2 <= waterLevel) && 1 <= \result) && systemActive == 1)) || !(systemActive == 1)) && ((((((waterLevel == \old(waterLevel) && 1 <= \result) && pumpRunning == 0) || !(\old(pumpRunning) == 0)) || (((waterLevel == \old(waterLevel) && 2 <= waterLevel) && 1 <= \result) && systemActive == 1)) || !(systemActive == 1)) || !(1 <= \old(waterLevel))) [2021-12-16 01:00:54,906 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (((!(2 <= \old(waterLevel)) || ((((1 <= tmp && waterLevel == \old(waterLevel)) && 2 <= waterLevel) && 1 <= \result) && systemActive == 1)) || ((((((((1 <= tmp && 1 <= tmp___0) && tmp == 0) && 1 <= tmp) && 1 <= \result) && \result == 0) && \old(waterLevel) <= waterLevel + 1) && 1 <= \result) && pumpRunning == 0)) || !(systemActive == 1)) && (((((((1 <= tmp && waterLevel == \old(waterLevel)) && 1 <= \result) && pumpRunning == 0) || !(\old(pumpRunning) == 0)) || ((((1 <= tmp && waterLevel == \old(waterLevel)) && 2 <= waterLevel) && 1 <= \result) && systemActive == 1)) || !(systemActive == 1)) || !(1 <= \old(waterLevel))) [2021-12-16 01:00:54,906 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: ((!(2 <= \old(waterLevel)) || ((\result == 0 && pumpRunning == \old(pumpRunning)) && \old(waterLevel) <= waterLevel + 1)) || !(systemActive == 1)) && ((!(\old(pumpRunning) == 0) || !(systemActive == 1)) || !(1 <= \old(waterLevel))) [2021-12-16 01:00:54,907 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (((!(\old(pumpRunning) == 0) || (pumpRunning == 0 && \result == 0)) || !(systemActive == 1)) || !(2 <= waterLevel)) && ((((1 <= \result && pumpRunning == 0) || !(waterLevel == 1)) || !(\old(pumpRunning) == 0)) || !(systemActive == 1)) [2021-12-16 01:00:54,907 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (!(2 <= \old(waterLevel)) || !(systemActive == 1)) && ((!(\old(pumpRunning) == 0) || !(systemActive == 1)) || !(1 <= \old(waterLevel))) [2021-12-16 01:00:54,907 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: ((!(\old(pumpRunning) == 0) || !(systemActive == 1)) || !(1 <= \old(waterLevel))) && ((!(2 <= \old(waterLevel)) || (((((1 <= tmp___0 && tmp == 0) && 1 <= \result) && \result == 0) && pumpRunning == \old(pumpRunning)) && \old(waterLevel) <= waterLevel + 1)) || !(systemActive == 1)) [2021-12-16 01:00:54,908 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (((((((\result == 0 && tmp___0 == 0) && 1 <= tmp) && 1 <= \result) && pumpRunning == 0) || !(waterLevel == 1)) || !(\old(pumpRunning) == 0)) || !(systemActive == 1)) && (((!(\old(pumpRunning) == 0) || !(systemActive == 1)) || pumpRunning == 0) || !(2 <= waterLevel)) [2021-12-16 01:00:54,908 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (!(2 <= \old(waterLevel)) || !(systemActive == 1)) && ((!(\old(pumpRunning) == 0) || !(systemActive == 1)) || !(1 <= \old(waterLevel))) [2021-12-16 01:00:54,908 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: ((!(2 <= \old(waterLevel)) || ((((((1 <= tmp___0 && tmp == 0) && 1 <= tmp) && 1 <= \result) && \result == 0) && \old(waterLevel) <= waterLevel + 1) && pumpRunning == 0)) || !(systemActive == 1)) && ((!(\old(pumpRunning) == 0) || !(systemActive == 1)) || !(1 <= \old(waterLevel))) [2021-12-16 01:00:54,908 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (((2 <= waterLevel && pumpRunning == 0) || !(1 <= waterLevel)) || !(\old(pumpRunning) == 0)) || !(systemActive == 1) [2021-12-16 01:00:54,908 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (((2 <= waterLevel && pumpRunning == 0) || !(1 <= waterLevel)) || !(\old(pumpRunning) == 0)) || !(systemActive == 1) [2021-12-16 01:00:54,915 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: ((!(1 <= waterLevel) || !(\old(pumpRunning) == 0)) || 2 <= waterLevel) || !(systemActive == 1) [2021-12-16 01:00:54,915 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: ((!(1 <= waterLevel) || !(\old(pumpRunning) == 0)) || 2 <= waterLevel) || !(systemActive == 1) [2021-12-16 01:00:54,942 INFO L141 WitnessManager]: Wrote witness to /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/witness.graphml [2021-12-16 01:00:54,942 INFO L132 PluginConnector]: ------------------------ END Witness Printer---------------------------- [2021-12-16 01:00:54,943 INFO L158 Benchmark]: Toolchain (without parser) took 10172.45ms. Allocated memory was 83.9MB in the beginning and 161.5MB in the end (delta: 77.6MB). Free memory was 53.2MB in the beginning and 133.2MB in the end (delta: -80.0MB). Peak memory consumption was 89.9MB. Max. memory is 16.1GB. [2021-12-16 01:00:54,943 INFO L158 Benchmark]: CDTParser took 0.22ms. Allocated memory is still 83.9MB. Free memory was 43.4MB in the beginning and 43.3MB in the end (delta: 45.0kB). There was no memory consumed. Max. memory is 16.1GB. [2021-12-16 01:00:54,944 INFO L158 Benchmark]: CACSL2BoogieTranslator took 389.79ms. Allocated memory was 83.9MB in the beginning and 111.1MB in the end (delta: 27.3MB). Free memory was 53.0MB in the beginning and 80.0MB in the end (delta: -27.0MB). Peak memory consumption was 8.4MB. Max. memory is 16.1GB. [2021-12-16 01:00:54,944 INFO L158 Benchmark]: Boogie Procedure Inliner took 73.78ms. Allocated memory is still 111.1MB. Free memory was 80.0MB in the beginning and 77.6MB in the end (delta: 2.4MB). Peak memory consumption was 2.1MB. Max. memory is 16.1GB. [2021-12-16 01:00:54,945 INFO L158 Benchmark]: Boogie Preprocessor took 39.76ms. Allocated memory is still 111.1MB. Free memory was 77.2MB in the beginning and 75.9MB in the end (delta: 1.3MB). Peak memory consumption was 2.1MB. Max. memory is 16.1GB. [2021-12-16 01:00:54,945 INFO L158 Benchmark]: RCFGBuilder took 377.86ms. Allocated memory is still 111.1MB. Free memory was 75.9MB in the beginning and 59.5MB in the end (delta: 16.4MB). Peak memory consumption was 16.8MB. Max. memory is 16.1GB. [2021-12-16 01:00:54,945 INFO L158 Benchmark]: TraceAbstraction took 9212.53ms. Allocated memory was 111.1MB in the beginning and 161.5MB in the end (delta: 50.3MB). Free memory was 59.1MB in the beginning and 47.6MB in the end (delta: 11.5MB). Peak memory consumption was 69.7MB. Max. memory is 16.1GB. [2021-12-16 01:00:54,946 INFO L158 Benchmark]: Witness Printer took 72.75ms. Allocated memory is still 161.5MB. Free memory was 47.6MB in the beginning and 133.2MB in the end (delta: -85.5MB). Peak memory consumption was 5.7MB. Max. memory is 16.1GB. [2021-12-16 01:00:54,947 INFO L339 ainManager$Toolchain]: ####################### End [Toolchain 1] ####################### --- Results --- * Results from de.uni_freiburg.informatik.ultimate.core: - StatisticsResult: Toolchain Benchmarks Benchmark results are: * CDTParser took 0.22ms. Allocated memory is still 83.9MB. Free memory was 43.4MB in the beginning and 43.3MB in the end (delta: 45.0kB). There was no memory consumed. Max. memory is 16.1GB. * CACSL2BoogieTranslator took 389.79ms. Allocated memory was 83.9MB in the beginning and 111.1MB in the end (delta: 27.3MB). Free memory was 53.0MB in the beginning and 80.0MB in the end (delta: -27.0MB). Peak memory consumption was 8.4MB. Max. memory is 16.1GB. * Boogie Procedure Inliner took 73.78ms. Allocated memory is still 111.1MB. Free memory was 80.0MB in the beginning and 77.6MB in the end (delta: 2.4MB). Peak memory consumption was 2.1MB. Max. memory is 16.1GB. * Boogie Preprocessor took 39.76ms. Allocated memory is still 111.1MB. Free memory was 77.2MB in the beginning and 75.9MB in the end (delta: 1.3MB). Peak memory consumption was 2.1MB. Max. memory is 16.1GB. * RCFGBuilder took 377.86ms. Allocated memory is still 111.1MB. Free memory was 75.9MB in the beginning and 59.5MB in the end (delta: 16.4MB). Peak memory consumption was 16.8MB. Max. memory is 16.1GB. * TraceAbstraction took 9212.53ms. Allocated memory was 111.1MB in the beginning and 161.5MB in the end (delta: 50.3MB). Free memory was 59.1MB in the beginning and 47.6MB in the end (delta: 11.5MB). Peak memory consumption was 69.7MB. Max. memory is 16.1GB. * Witness Printer took 72.75ms. Allocated memory is still 161.5MB. Free memory was 47.6MB in the beginning and 133.2MB in the end (delta: -85.5MB). Peak memory consumption was 5.7MB. Max. memory is 16.1GB. * Results from de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction: - StatisticsResult: ErrorAutomatonStatistics NumberErrorTraces: 0, NumberStatementsAllTraces: 0, NumberRelevantStatements: 0, 0.0s ErrorAutomatonConstructionTimeTotal, 0.0s FaulLocalizationTime, NumberStatementsFirstTrace: -1, TraceLengthAvg: 0, 0.0s ErrorAutomatonConstructionTimeAvg, 0.0s ErrorAutomatonDifferenceTimeAvg, 0.0s ErrorAutomatonDifferenceTimeTotal, NumberOfNoEnhancement: 0, NumberOfFiniteEnhancement: 0, NumberOfInfiniteEnhancement: 0 - PositiveResult [Line: 449]: call to reach_error is unreachable For all program executions holds that call to reach_error is unreachable at this location - StatisticsResult: Ultimate Automizer benchmark data CFG has 7 procedures, 87 locations, 1 error locations. Started 1 CEGAR loops. OverallTime: 9.1s, OverallIterations: 11, TraceHistogramMax: 3, PathProgramHistogramMax: 1, EmptinessCheckTime: 0.0s, AutomataDifference: 4.0s, DeadEndRemovalTime: 0.0s, HoareAnnotationTime: 1.8s, InitialAbstractionConstructionTime: 0.0s, PartialOrderReductionTime: 0.0s, HoareTripleCheckerStatistics: 0 mSolverCounterUnknown, 2441 SdHoareTripleChecker+Valid, 2.2s IncrementalHoareTripleChecker+Time, 0 mSdLazyCounter, 2414 mSDsluCounter, 5186 SdHoareTripleChecker+Invalid, 1.7s Time, 0 mProtectedAction, 0 SdHoareTripleChecker+Unchecked, 0 IncrementalHoareTripleChecker+Unchecked, 3993 mSDsCounter, 594 IncrementalHoareTripleChecker+Valid, 0 mProtectedPredicate, 3305 IncrementalHoareTripleChecker+Invalid, 3899 SdHoareTripleChecker+Unknown, 0 mSolverCounterNotChecked, 594 mSolverCounterUnsat, 1193 mSDtfsCounter, 3305 mSolverCounterSat, 0.1s SdHoareTripleChecker+Time, 0 IncrementalHoareTripleChecker+Unknown, PredicateUnifierStatistics: 0 DeclaredPredicates, 621 GetRequests, 452 SyntacticMatches, 5 SemanticMatches, 164 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 1127 ImplicationChecksByTransitivity, 1.6s Time, 0.0s BasicInterpolantAutomatonTime, BiggestAbstraction: size=538occurred in iteration=10, InterpolantAutomatonStates: 151, traceCheckStatistics: No data available, InterpolantConsolidationStatistics: No data available, PathInvariantsStatistics: No data available, 0/0 InterpolantCoveringCapability, TotalInterpolationStatistics: No data available, 0.0s DumpTime, AutomataMinimizationStatistics: 0.3s AutomataMinimizationTime, 11 MinimizatonAttempts, 251 StatesRemovedByMinimization, 7 NontrivialMinimizations, HoareAnnotationStatistics: 0.0s HoareAnnotationTime, 42 LocationsWithAnnotation, 1193 PreInvPairs, 1283 NumberOfFragments, 1052 HoareAnnotationTreeSize, 1193 FomulaSimplifications, 1679 FormulaSimplificationTreeSizeReduction, 0.2s HoareSimplificationTime, 42 FomulaSimplificationsInter, 5440 FormulaSimplificationTreeSizeReductionInter, 1.6s HoareSimplificationTimeInter, RefinementEngineStatistics: TRACE_CHECK: 0.1s SsaConstructionTime, 0.3s SatisfiabilityAnalysisTime, 1.8s InterpolantComputationTime, 810 NumberOfCodeBlocks, 810 NumberOfCodeBlocksAsserted, 13 NumberOfCheckSat, 980 ConstructedInterpolants, 0 QuantifiedInterpolants, 1824 SizeOfPredicates, 7 NumberOfNonLiveVariables, 962 ConjunctsInSsa, 19 ConjunctsInUnsatCore, 15 InterpolantComputations, 9 PerfectInterpolantSequences, 328/357 InterpolantCoveringCapability, INVARIANT_SYNTHESIS: No data available, INTERPOLANT_CONSOLIDATION: No data available, ABSTRACT_INTERPRETATION: No data available, PDR: No data available, ACCELERATED_INTERPOLATION: No data available, SIFA: No data available, ReuseStatistics: No data available - AllSpecificationsHoldResult: All specifications hold 1 specifications checked. All of them hold - InvariantResult [Line: 816]: Loop Invariant Derived loop invariant: ((!(2 <= \old(waterLevel)) || ((((((1 <= tmp___0 && tmp == 0) && 1 <= tmp) && 1 <= \result) && \result == 0) && \old(waterLevel) <= waterLevel + 1) && pumpRunning == 0)) || !(systemActive == 1)) && ((!(\old(pumpRunning) == 0) || !(systemActive == 1)) || !(1 <= \old(waterLevel))) - InvariantResult [Line: 419]: Loop Invariant Derived loop invariant: (((!(2 <= \old(waterLevel)) || ((((1 <= tmp && waterLevel == \old(waterLevel)) && 2 <= waterLevel) && 1 <= \result) && systemActive == 1)) || ((((((((1 <= tmp && 1 <= tmp___0) && tmp == 0) && 1 <= tmp) && 1 <= \result) && \result == 0) && \old(waterLevel) <= waterLevel + 1) && 1 <= \result) && pumpRunning == 0)) || !(systemActive == 1)) && (((((((1 <= tmp && waterLevel == \old(waterLevel)) && 1 <= \result) && pumpRunning == 0) || !(\old(pumpRunning) == 0)) || ((((1 <= tmp && waterLevel == \old(waterLevel)) && 2 <= waterLevel) && 1 <= \result) && systemActive == 1)) || !(systemActive == 1)) || !(1 <= \old(waterLevel))) - InvariantResult [Line: 918]: Loop Invariant Derived loop invariant: (((((splverifierCounter == 0 && 1 == \result) && systemActive == tmp) && waterLevel == tmp) && systemActive == 1) && pumpRunning == 0) || ((((splverifierCounter == 0 && 1 == \result) && 2 <= waterLevel) && systemActive == tmp) && systemActive == 1) - InvariantResult [Line: 937]: Loop Invariant Derived loop invariant: (((((splverifierCounter == 0 && 1 == \result) && systemActive == tmp) && waterLevel == tmp) && systemActive == 1) && pumpRunning == 0) || ((((splverifierCounter == 0 && 1 == \result) && 2 <= waterLevel) && systemActive == tmp) && systemActive == 1) - InvariantResult [Line: 927]: Loop Invariant Derived loop invariant: 1 - InvariantResult [Line: 799]: Loop Invariant Derived loop invariant: ((!(1 <= waterLevel) || !(\old(pumpRunning) == 0)) || 2 <= waterLevel) || !(systemActive == 1) - InvariantResult [Line: 642]: Loop Invariant Derived loop invariant: 1 - InvariantResult [Line: 576]: Loop Invariant Derived loop invariant: 1 - InvariantResult [Line: 463]: Loop Invariant Derived loop invariant: ((!(\old(pumpRunning) == 0) || !(systemActive == 1)) || !(1 <= \old(waterLevel))) && ((!(2 <= \old(waterLevel)) || (pumpRunning == \old(pumpRunning) && \old(waterLevel) <= waterLevel + 1)) || !(systemActive == 1)) - InvariantResult [Line: 835]: Loop Invariant Derived loop invariant: (!(2 <= \old(waterLevel)) || !(systemActive == 1)) && ((!(\old(pumpRunning) == 0) || !(systemActive == 1)) || !(1 <= \old(waterLevel))) - InvariantResult [Line: 691]: Loop Invariant Derived loop invariant: ((waterLevel == 1 && 1 == \result) && systemActive == 1) && pumpRunning == 0 - InvariantResult [Line: 554]: Loop Invariant Derived loop invariant: ((!(2 <= \old(waterLevel)) || ((\result == 0 && pumpRunning == \old(pumpRunning)) && \old(waterLevel) <= waterLevel + 1)) || !(systemActive == 1)) && ((!(\old(pumpRunning) == 0) || !(systemActive == 1)) || !(1 <= \old(waterLevel))) - InvariantResult [Line: 790]: Loop Invariant Derived loop invariant: ((!(1 <= waterLevel) || !(\old(pumpRunning) == 0)) || 2 <= waterLevel) || !(systemActive == 1) - InvariantResult [Line: 880]: Loop Invariant Derived loop invariant: (((((((\result == 0 && tmp___0 == 0) && 1 <= tmp) && 1 <= \result) && pumpRunning == 0) || !(waterLevel == 1)) || !(\old(pumpRunning) == 0)) || !(systemActive == 1)) && (((!(\old(pumpRunning) == 0) || !(systemActive == 1)) || pumpRunning == 0) || !(2 <= waterLevel)) - InvariantResult [Line: 531]: Loop Invariant Derived loop invariant: (((!(2 <= \old(waterLevel)) || (((((((1 <= tmp___0 && tmp == 0) && 1 <= tmp) && 1 <= \result) && \result == 0) && \old(waterLevel) <= waterLevel + 1) && 1 <= \result) && pumpRunning == 0)) || (((waterLevel == \old(waterLevel) && 2 <= waterLevel) && 1 <= \result) && systemActive == 1)) || !(systemActive == 1)) && ((((((waterLevel == \old(waterLevel) && 1 <= \result) && pumpRunning == 0) || !(\old(pumpRunning) == 0)) || (((waterLevel == \old(waterLevel) && 2 <= waterLevel) && 1 <= \result) && systemActive == 1)) || !(systemActive == 1)) || !(1 <= \old(waterLevel))) - InvariantResult [Line: 621]: Loop Invariant Derived loop invariant: (((1 == \result && systemActive == tmp) && waterLevel == tmp) && systemActive == 1) && pumpRunning == 0 - InvariantResult [Line: 445]: Loop Invariant Derived loop invariant: (!(2 <= \old(waterLevel)) || !(systemActive == 1)) && ((!(\old(pumpRunning) == 0) || !(systemActive == 1)) || !(1 <= \old(waterLevel))) - InvariantResult [Line: 499]: Loop Invariant Derived loop invariant: (((2 <= waterLevel && pumpRunning == 0) || !(1 <= waterLevel)) || !(\old(pumpRunning) == 0)) || !(systemActive == 1) - InvariantResult [Line: 899]: Loop Invariant Derived loop invariant: ((!(\old(pumpRunning) == 0) || !(systemActive == 1)) || !(1 <= \old(waterLevel))) && ((!(2 <= \old(waterLevel)) || (((((1 <= tmp___0 && tmp == 0) && 1 <= \result) && \result == 0) && pumpRunning == \old(pumpRunning)) && \old(waterLevel) <= waterLevel + 1)) || !(systemActive == 1)) - InvariantResult [Line: 629]: Loop Invariant Derived loop invariant: 1 - InvariantResult [Line: 765]: Loop Invariant Derived loop invariant: (((((waterLevel == \old(waterLevel) && 2 <= waterLevel) && systemActive == 1) || !(2 <= \old(waterLevel))) || ((((((1 <= tmp___0 && tmp == 0) && 1 <= tmp) && 1 <= \result) && \result == 0) && \old(waterLevel) <= waterLevel + 1) && pumpRunning == 0)) || !(systemActive == 1)) && ((((((waterLevel == \old(waterLevel) && 2 <= waterLevel) && systemActive == 1) || (waterLevel == \old(waterLevel) && pumpRunning == 0)) || !(\old(pumpRunning) == 0)) || !(systemActive == 1)) || !(1 <= \old(waterLevel))) - InvariantResult [Line: 677]: Loop Invariant Derived loop invariant: (waterLevel == 1 && systemActive == 1) && pumpRunning == 0 - InvariantResult [Line: 824]: Loop Invariant Derived loop invariant: (((2 <= waterLevel && pumpRunning == 0) || !(1 <= waterLevel)) || !(\old(pumpRunning) == 0)) || !(systemActive == 1) - InvariantResult [Line: 936]: Loop Invariant Derived loop invariant: 0 - InvariantResult [Line: 566]: Loop Invariant Derived loop invariant: 1 - InvariantResult [Line: 540]: Loop Invariant Derived loop invariant: (((!(\old(pumpRunning) == 0) || (pumpRunning == 0 && \result == 0)) || !(systemActive == 1)) || !(2 <= waterLevel)) && ((((1 <= \result && pumpRunning == 0) || !(waterLevel == 1)) || !(\old(pumpRunning) == 0)) || !(systemActive == 1)) - InvariantResult [Line: 684]: Loop Invariant Derived loop invariant: (waterLevel == 1 && systemActive == 1) && pumpRunning == 0 RESULT: Ultimate proved your program to be correct! [2021-12-16 01:00:55,008 INFO L540 MonitoredProcess]: [MP /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in -t:2000 (1)] Forceful destruction successful, exit code 0 Received shutdown request... --- End real Ultimate output --- Execution finished normally Writing output log to file Ultimate.log Result: TRUE