./Ultimate.py --spec ../sv-benchmarks/c/properties/unreach-call.prp --file ../sv-benchmarks/c/product-lines/minepump_spec5_product62.cil.c --full-output --architecture 32bit -------------------------------------------------------------------------------- Checking for ERROR reachability Using default analysis Version c3fed411 Calling Ultimate with: /usr/bin/java -Dosgi.configuration.area=/storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/data/config -Xmx15G -Xms4m -jar /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/plugins/org.eclipse.equinox.launcher_1.5.800.v20200727-1323.jar -data @noDefault -ultimatedata /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/data -tc /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/config/AutomizerReach.xml -i ../sv-benchmarks/c/product-lines/minepump_spec5_product62.cil.c -s /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/config/svcomp-Reach-32bit-Automizer_Default.epf --cacsl2boogietranslator.entry.function main --witnessprinter.witness.directory /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux --witnessprinter.witness.filename witness.graphml --witnessprinter.write.witness.besides.input.file false --witnessprinter.graph.data.specification CHECK( init(main()), LTL(G ! call(reach_error())) ) --witnessprinter.graph.data.producer Automizer --witnessprinter.graph.data.architecture 32bit --witnessprinter.graph.data.programhash 34b47c00ac265c7154b048b065075686f0b0d02157935b615817b802464c404c --- Real Ultimate output --- This is Ultimate 0.2.2-tmp.no-commuhash-c3fed41 [2021-12-16 01:01:40,187 INFO L177 SettingsManager]: Resetting all preferences to default values... [2021-12-16 01:01:40,216 INFO L181 SettingsManager]: Resetting UltimateCore preferences to default values [2021-12-16 01:01:40,251 INFO L184 SettingsManager]: Ultimate Commandline Interface provides no preferences, ignoring... [2021-12-16 01:01:40,251 INFO L181 SettingsManager]: Resetting Boogie Preprocessor preferences to default values [2021-12-16 01:01:40,254 INFO L181 SettingsManager]: Resetting Boogie Procedure Inliner preferences to default values [2021-12-16 01:01:40,255 INFO L181 SettingsManager]: Resetting Abstract Interpretation preferences to default values [2021-12-16 01:01:40,258 INFO L181 SettingsManager]: Resetting LassoRanker preferences to default values [2021-12-16 01:01:40,259 INFO L181 SettingsManager]: Resetting Reaching Definitions preferences to default values [2021-12-16 01:01:40,264 INFO L181 SettingsManager]: Resetting SyntaxChecker preferences to default values [2021-12-16 01:01:40,264 INFO L181 SettingsManager]: Resetting Sifa preferences to default values [2021-12-16 01:01:40,265 INFO L184 SettingsManager]: Büchi Program Product provides no preferences, ignoring... [2021-12-16 01:01:40,266 INFO L181 SettingsManager]: Resetting LTL2Aut preferences to default values [2021-12-16 01:01:40,268 INFO L181 SettingsManager]: Resetting PEA to Boogie preferences to default values [2021-12-16 01:01:40,269 INFO L181 SettingsManager]: Resetting BlockEncodingV2 preferences to default values [2021-12-16 01:01:40,272 INFO L181 SettingsManager]: Resetting ChcToBoogie preferences to default values [2021-12-16 01:01:40,273 INFO L181 SettingsManager]: Resetting AutomataScriptInterpreter preferences to default values [2021-12-16 01:01:40,274 INFO L181 SettingsManager]: Resetting BuchiAutomizer preferences to default values [2021-12-16 01:01:40,276 INFO L181 SettingsManager]: Resetting CACSL2BoogieTranslator preferences to default values [2021-12-16 01:01:40,280 INFO L181 SettingsManager]: Resetting CodeCheck preferences to default values [2021-12-16 01:01:40,281 INFO L181 SettingsManager]: Resetting InvariantSynthesis preferences to default values [2021-12-16 01:01:40,282 INFO L181 SettingsManager]: Resetting RCFGBuilder preferences to default values [2021-12-16 01:01:40,283 INFO L181 SettingsManager]: Resetting Referee preferences to default values [2021-12-16 01:01:40,283 INFO L181 SettingsManager]: Resetting TraceAbstraction preferences to default values [2021-12-16 01:01:40,285 INFO L184 SettingsManager]: TraceAbstractionConcurrent provides no preferences, ignoring... [2021-12-16 01:01:40,285 INFO L184 SettingsManager]: TraceAbstractionWithAFAs provides no preferences, ignoring... [2021-12-16 01:01:40,286 INFO L181 SettingsManager]: Resetting TreeAutomizer preferences to default values [2021-12-16 01:01:40,287 INFO L181 SettingsManager]: Resetting IcfgToChc preferences to default values [2021-12-16 01:01:40,287 INFO L181 SettingsManager]: Resetting IcfgTransformer preferences to default values [2021-12-16 01:01:40,288 INFO L184 SettingsManager]: ReqToTest provides no preferences, ignoring... [2021-12-16 01:01:40,288 INFO L181 SettingsManager]: Resetting Boogie Printer preferences to default values [2021-12-16 01:01:40,289 INFO L181 SettingsManager]: Resetting ChcSmtPrinter preferences to default values [2021-12-16 01:01:40,290 INFO L181 SettingsManager]: Resetting ReqPrinter preferences to default values [2021-12-16 01:01:40,291 INFO L181 SettingsManager]: Resetting Witness Printer preferences to default values [2021-12-16 01:01:40,292 INFO L184 SettingsManager]: Boogie PL CUP Parser provides no preferences, ignoring... [2021-12-16 01:01:40,292 INFO L181 SettingsManager]: Resetting CDTParser preferences to default values [2021-12-16 01:01:40,293 INFO L184 SettingsManager]: AutomataScriptParser provides no preferences, ignoring... [2021-12-16 01:01:40,293 INFO L184 SettingsManager]: ReqParser provides no preferences, ignoring... [2021-12-16 01:01:40,293 INFO L181 SettingsManager]: Resetting SmtParser preferences to default values [2021-12-16 01:01:40,293 INFO L181 SettingsManager]: Resetting Witness Parser preferences to default values [2021-12-16 01:01:40,294 INFO L188 SettingsManager]: Finished resetting all preferences to default values... [2021-12-16 01:01:40,295 INFO L101 SettingsManager]: Beginning loading settings from /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/config/svcomp-Reach-32bit-Automizer_Default.epf [2021-12-16 01:01:40,320 INFO L113 SettingsManager]: Loading preferences was successful [2021-12-16 01:01:40,320 INFO L115 SettingsManager]: Preferences different from defaults after loading the file: [2021-12-16 01:01:40,321 INFO L136 SettingsManager]: Preferences of UltimateCore differ from their defaults: [2021-12-16 01:01:40,321 INFO L138 SettingsManager]: * Log level for class=de.uni_freiburg.informatik.ultimate.lib.smtlibutils.quantifier.QuantifierPusher=ERROR; [2021-12-16 01:01:40,322 INFO L136 SettingsManager]: Preferences of Boogie Procedure Inliner differ from their defaults: [2021-12-16 01:01:40,322 INFO L138 SettingsManager]: * Ignore calls to procedures called more than once=ONLY_FOR_SEQUENTIAL_PROGRAMS [2021-12-16 01:01:40,323 INFO L136 SettingsManager]: Preferences of BlockEncodingV2 differ from their defaults: [2021-12-16 01:01:40,323 INFO L138 SettingsManager]: * Create parallel compositions if possible=false [2021-12-16 01:01:40,323 INFO L138 SettingsManager]: * Use SBE=true [2021-12-16 01:01:40,323 INFO L136 SettingsManager]: Preferences of CACSL2BoogieTranslator differ from their defaults: [2021-12-16 01:01:40,324 INFO L138 SettingsManager]: * sizeof long=4 [2021-12-16 01:01:40,324 INFO L138 SettingsManager]: * Overapproximate operations on floating types=true [2021-12-16 01:01:40,324 INFO L138 SettingsManager]: * sizeof POINTER=4 [2021-12-16 01:01:40,324 INFO L138 SettingsManager]: * Check division by zero=IGNORE [2021-12-16 01:01:40,325 INFO L138 SettingsManager]: * Pointer to allocated memory at dereference=IGNORE [2021-12-16 01:01:40,325 INFO L138 SettingsManager]: * If two pointers are subtracted or compared they have the same base address=IGNORE [2021-12-16 01:01:40,325 INFO L138 SettingsManager]: * Check array bounds for arrays that are off heap=IGNORE [2021-12-16 01:01:40,325 INFO L138 SettingsManager]: * sizeof long double=12 [2021-12-16 01:01:40,325 INFO L138 SettingsManager]: * Check if freed pointer was valid=false [2021-12-16 01:01:40,325 INFO L138 SettingsManager]: * Use constant arrays=true [2021-12-16 01:01:40,325 INFO L138 SettingsManager]: * Pointer base address is valid at dereference=IGNORE [2021-12-16 01:01:40,326 INFO L136 SettingsManager]: Preferences of RCFGBuilder differ from their defaults: [2021-12-16 01:01:40,326 INFO L138 SettingsManager]: * Size of a code block=SequenceOfStatements [2021-12-16 01:01:40,326 INFO L138 SettingsManager]: * SMT solver=External_DefaultMode [2021-12-16 01:01:40,326 INFO L138 SettingsManager]: * Command for external solver=z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in -t:2000 [2021-12-16 01:01:40,326 INFO L136 SettingsManager]: Preferences of TraceAbstraction differ from their defaults: [2021-12-16 01:01:40,326 INFO L138 SettingsManager]: * Compute Interpolants along a Counterexample=FPandBP [2021-12-16 01:01:40,328 INFO L138 SettingsManager]: * Positions where we compute the Hoare Annotation=LoopsAndPotentialCycles [2021-12-16 01:01:40,328 INFO L138 SettingsManager]: * Trace refinement strategy=CAMEL [2021-12-16 01:01:40,328 INFO L138 SettingsManager]: * Command for external solver=z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in [2021-12-16 01:01:40,328 INFO L138 SettingsManager]: * Large block encoding in concurrent analysis=OFF [2021-12-16 01:01:40,328 INFO L138 SettingsManager]: * Automaton type used in concurrency analysis=PETRI_NET [2021-12-16 01:01:40,329 INFO L138 SettingsManager]: * Compute Hoare Annotation of negated interpolant automaton, abstraction and CFG=true [2021-12-16 01:01:40,329 INFO L138 SettingsManager]: * Trace refinement exception blacklist=NONE [2021-12-16 01:01:40,329 INFO L138 SettingsManager]: * SMT solver=External_ModelsAndUnsatCoreMode WARNING: An illegal reflective access operation has occurred WARNING: Illegal reflective access by com.sun.xml.bind.v2.runtime.reflect.opt.Injector$1 (file:/storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/plugins/com.sun.xml.bind_2.2.0.v201505121915.jar) to method java.lang.ClassLoader.defineClass(java.lang.String,byte[],int,int) WARNING: Please consider reporting this to the maintainers of com.sun.xml.bind.v2.runtime.reflect.opt.Injector$1 WARNING: Use --illegal-access=warn to enable warnings of further illegal reflective access operations WARNING: All illegal access operations will be denied in a future release Applying setting for plugin de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator: Entry function -> main Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Witness directory -> /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Witness filename -> witness.graphml Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Write witness besides input file -> false Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Graph data specification -> CHECK( init(main()), LTL(G ! call(reach_error())) ) Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Graph data producer -> Automizer Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Graph data architecture -> 32bit Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Graph data programhash -> 34b47c00ac265c7154b048b065075686f0b0d02157935b615817b802464c404c [2021-12-16 01:01:40,534 INFO L75 nceAwareModelManager]: Repository-Root is: /tmp [2021-12-16 01:01:40,560 INFO L261 ainManager$Toolchain]: [Toolchain 1]: Applicable parser(s) successfully (re)initialized [2021-12-16 01:01:40,562 INFO L217 ainManager$Toolchain]: [Toolchain 1]: Toolchain selected. [2021-12-16 01:01:40,563 INFO L271 PluginConnector]: Initializing CDTParser... [2021-12-16 01:01:40,567 INFO L275 PluginConnector]: CDTParser initialized [2021-12-16 01:01:40,568 INFO L432 ainManager$Toolchain]: [Toolchain 1]: Parsing single file: /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/../sv-benchmarks/c/product-lines/minepump_spec5_product62.cil.c [2021-12-16 01:01:40,632 INFO L220 CDTParser]: Created temporary CDT project at /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/data/dfcc79f50/97fe991f47a346e491ca52a4f518a64f/FLAG25870e0ba [2021-12-16 01:01:41,012 INFO L306 CDTParser]: Found 1 translation units. [2021-12-16 01:01:41,013 INFO L160 CDTParser]: Scanning /storage/repos/ultimate/releaseScripts/default/sv-benchmarks/c/product-lines/minepump_spec5_product62.cil.c [2021-12-16 01:01:41,021 INFO L349 CDTParser]: About to delete temporary CDT project at /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/data/dfcc79f50/97fe991f47a346e491ca52a4f518a64f/FLAG25870e0ba [2021-12-16 01:01:41,032 INFO L357 CDTParser]: Successfully deleted /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/data/dfcc79f50/97fe991f47a346e491ca52a4f518a64f [2021-12-16 01:01:41,034 INFO L299 ainManager$Toolchain]: ####################### [Toolchain 1] ####################### [2021-12-16 01:01:41,035 INFO L131 ToolchainWalker]: Walking toolchain with 6 elements. [2021-12-16 01:01:41,036 INFO L113 PluginConnector]: ------------------------CACSL2BoogieTranslator---------------------------- [2021-12-16 01:01:41,036 INFO L271 PluginConnector]: Initializing CACSL2BoogieTranslator... [2021-12-16 01:01:41,038 INFO L275 PluginConnector]: CACSL2BoogieTranslator initialized [2021-12-16 01:01:41,039 INFO L185 PluginConnector]: Executing the observer ACSLObjectContainerObserver from plugin CACSL2BoogieTranslator for "CDTParser AST 16.12 01:01:41" (1/1) ... [2021-12-16 01:01:41,040 INFO L205 PluginConnector]: Invalid model from CACSL2BoogieTranslator for observer de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator.ACSLObjectContainerObserver@336d4f40 and model type de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 16.12 01:01:41, skipping insertion in model container [2021-12-16 01:01:41,040 INFO L185 PluginConnector]: Executing the observer CACSL2BoogieTranslatorObserver from plugin CACSL2BoogieTranslator for "CDTParser AST 16.12 01:01:41" (1/1) ... [2021-12-16 01:01:41,046 INFO L145 MainTranslator]: Starting translation in SV-COMP mode [2021-12-16 01:01:41,087 INFO L178 MainTranslator]: Built tables and reachable declarations [2021-12-16 01:01:41,304 WARN L230 ndardFunctionHandler]: Function reach_error is already implemented but we override the implementation for the call at /storage/repos/ultimate/releaseScripts/default/sv-benchmarks/c/product-lines/minepump_spec5_product62.cil.c[19180,19193] [2021-12-16 01:01:41,308 INFO L209 PostProcessor]: Analyzing one entry point: main [2021-12-16 01:01:41,314 INFO L203 MainTranslator]: Completed pre-run [2021-12-16 01:01:41,355 WARN L230 ndardFunctionHandler]: Function reach_error is already implemented but we override the implementation for the call at /storage/repos/ultimate/releaseScripts/default/sv-benchmarks/c/product-lines/minepump_spec5_product62.cil.c[19180,19193] [2021-12-16 01:01:41,357 INFO L209 PostProcessor]: Analyzing one entry point: main [2021-12-16 01:01:41,369 INFO L208 MainTranslator]: Completed translation [2021-12-16 01:01:41,369 INFO L202 PluginConnector]: Adding new model de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 16.12 01:01:41 WrapperNode [2021-12-16 01:01:41,369 INFO L132 PluginConnector]: ------------------------ END CACSL2BoogieTranslator---------------------------- [2021-12-16 01:01:41,370 INFO L113 PluginConnector]: ------------------------Boogie Procedure Inliner---------------------------- [2021-12-16 01:01:41,371 INFO L271 PluginConnector]: Initializing Boogie Procedure Inliner... [2021-12-16 01:01:41,371 INFO L275 PluginConnector]: Boogie Procedure Inliner initialized [2021-12-16 01:01:41,376 INFO L185 PluginConnector]: Executing the observer TypeChecker from plugin Boogie Procedure Inliner for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 16.12 01:01:41" (1/1) ... [2021-12-16 01:01:41,400 INFO L185 PluginConnector]: Executing the observer Inliner from plugin Boogie Procedure Inliner for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 16.12 01:01:41" (1/1) ... [2021-12-16 01:01:41,423 INFO L137 Inliner]: procedures = 60, calls = 164, calls flagged for inlining = 26, calls inlined = 23, statements flattened = 297 [2021-12-16 01:01:41,424 INFO L132 PluginConnector]: ------------------------ END Boogie Procedure Inliner---------------------------- [2021-12-16 01:01:41,425 INFO L113 PluginConnector]: ------------------------Boogie Preprocessor---------------------------- [2021-12-16 01:01:41,425 INFO L271 PluginConnector]: Initializing Boogie Preprocessor... [2021-12-16 01:01:41,425 INFO L275 PluginConnector]: Boogie Preprocessor initialized [2021-12-16 01:01:41,431 INFO L185 PluginConnector]: Executing the observer EnsureBoogieModelObserver from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 16.12 01:01:41" (1/1) ... [2021-12-16 01:01:41,431 INFO L185 PluginConnector]: Executing the observer TypeChecker from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 16.12 01:01:41" (1/1) ... [2021-12-16 01:01:41,441 INFO L185 PluginConnector]: Executing the observer ConstExpander from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 16.12 01:01:41" (1/1) ... [2021-12-16 01:01:41,443 INFO L185 PluginConnector]: Executing the observer StructExpander from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 16.12 01:01:41" (1/1) ... [2021-12-16 01:01:41,447 INFO L185 PluginConnector]: Executing the observer UnstructureCode from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 16.12 01:01:41" (1/1) ... [2021-12-16 01:01:41,450 INFO L185 PluginConnector]: Executing the observer FunctionInliner from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 16.12 01:01:41" (1/1) ... [2021-12-16 01:01:41,461 INFO L185 PluginConnector]: Executing the observer BoogieSymbolTableConstructor from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 16.12 01:01:41" (1/1) ... [2021-12-16 01:01:41,472 INFO L132 PluginConnector]: ------------------------ END Boogie Preprocessor---------------------------- [2021-12-16 01:01:41,472 INFO L113 PluginConnector]: ------------------------RCFGBuilder---------------------------- [2021-12-16 01:01:41,473 INFO L271 PluginConnector]: Initializing RCFGBuilder... [2021-12-16 01:01:41,473 INFO L275 PluginConnector]: RCFGBuilder initialized [2021-12-16 01:01:41,473 INFO L185 PluginConnector]: Executing the observer RCFGBuilderObserver from plugin RCFGBuilder for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 16.12 01:01:41" (1/1) ... [2021-12-16 01:01:41,478 INFO L168 SolverBuilder]: Constructing external solver with command: z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in -t:2000 [2021-12-16 01:01:41,512 INFO L189 MonitoredProcess]: No working directory specified, using /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 [2021-12-16 01:01:41,524 INFO L229 MonitoredProcess]: Starting monitored process 1 with /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in -t:2000 (exit command is (exit), workingDir is null) [2021-12-16 01:01:41,546 INFO L327 MonitoredProcess]: [MP /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in -t:2000 (1)] Waiting until timeout for monitored process [2021-12-16 01:01:41,575 INFO L130 BoogieDeclarations]: Found specification of procedure #Ultimate.allocInit [2021-12-16 01:01:41,575 INFO L130 BoogieDeclarations]: Found specification of procedure processEnvironment__wrappee__base [2021-12-16 01:01:41,575 INFO L138 BoogieDeclarations]: Found implementation of procedure processEnvironment__wrappee__base [2021-12-16 01:01:41,575 INFO L130 BoogieDeclarations]: Found specification of procedure cleanup [2021-12-16 01:01:41,575 INFO L138 BoogieDeclarations]: Found implementation of procedure cleanup [2021-12-16 01:01:41,575 INFO L130 BoogieDeclarations]: Found specification of procedure timeShift [2021-12-16 01:01:41,576 INFO L138 BoogieDeclarations]: Found implementation of procedure timeShift [2021-12-16 01:01:41,576 INFO L130 BoogieDeclarations]: Found specification of procedure processEnvironment__wrappee__highWaterSensor [2021-12-16 01:01:41,576 INFO L138 BoogieDeclarations]: Found implementation of procedure processEnvironment__wrappee__highWaterSensor [2021-12-16 01:01:41,576 INFO L130 BoogieDeclarations]: Found specification of procedure waterRise [2021-12-16 01:01:41,576 INFO L138 BoogieDeclarations]: Found implementation of procedure waterRise [2021-12-16 01:01:41,576 INFO L130 BoogieDeclarations]: Found specification of procedure processEnvironment__wrappee__methaneQuery [2021-12-16 01:01:41,576 INFO L138 BoogieDeclarations]: Found implementation of procedure processEnvironment__wrappee__methaneQuery [2021-12-16 01:01:41,576 INFO L130 BoogieDeclarations]: Found specification of procedure isPumpRunning [2021-12-16 01:01:41,577 INFO L138 BoogieDeclarations]: Found implementation of procedure isPumpRunning [2021-12-16 01:01:41,577 INFO L130 BoogieDeclarations]: Found specification of procedure isMethaneAlarm [2021-12-16 01:01:41,577 INFO L138 BoogieDeclarations]: Found implementation of procedure isMethaneAlarm [2021-12-16 01:01:41,577 INFO L130 BoogieDeclarations]: Found specification of procedure deactivatePump [2021-12-16 01:01:41,577 INFO L138 BoogieDeclarations]: Found implementation of procedure deactivatePump [2021-12-16 01:01:41,577 INFO L130 BoogieDeclarations]: Found specification of procedure write~init~int [2021-12-16 01:01:41,577 INFO L130 BoogieDeclarations]: Found specification of procedure changeMethaneLevel [2021-12-16 01:01:41,577 INFO L138 BoogieDeclarations]: Found implementation of procedure changeMethaneLevel [2021-12-16 01:01:41,578 INFO L130 BoogieDeclarations]: Found specification of procedure ULTIMATE.start [2021-12-16 01:01:41,578 INFO L138 BoogieDeclarations]: Found implementation of procedure ULTIMATE.start [2021-12-16 01:01:41,646 INFO L236 CfgBuilder]: Building ICFG [2021-12-16 01:01:41,647 INFO L262 CfgBuilder]: Building CFG for each procedure with an implementation [2021-12-16 01:01:41,847 INFO L277 CfgBuilder]: Performing block encoding [2021-12-16 01:01:41,852 INFO L296 CfgBuilder]: Using the 1 location(s) as analysis (start of procedure ULTIMATE.start) [2021-12-16 01:01:41,852 INFO L301 CfgBuilder]: Removed 2 assume(true) statements. [2021-12-16 01:01:41,853 INFO L202 PluginConnector]: Adding new model de.uni_freiburg.informatik.ultimate.plugins.generator.rcfgbuilder CFG 16.12 01:01:41 BoogieIcfgContainer [2021-12-16 01:01:41,854 INFO L132 PluginConnector]: ------------------------ END RCFGBuilder---------------------------- [2021-12-16 01:01:41,855 INFO L113 PluginConnector]: ------------------------TraceAbstraction---------------------------- [2021-12-16 01:01:41,855 INFO L271 PluginConnector]: Initializing TraceAbstraction... [2021-12-16 01:01:41,857 INFO L275 PluginConnector]: TraceAbstraction initialized [2021-12-16 01:01:41,857 INFO L185 PluginConnector]: Executing the observer TraceAbstractionObserver from plugin TraceAbstraction for "CDTParser AST 16.12 01:01:41" (1/3) ... [2021-12-16 01:01:41,858 INFO L205 PluginConnector]: Invalid model from TraceAbstraction for observer de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction.TraceAbstractionObserver@5fd38840 and model type de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction AST 16.12 01:01:41, skipping insertion in model container [2021-12-16 01:01:41,858 INFO L185 PluginConnector]: Executing the observer TraceAbstractionObserver from plugin TraceAbstraction for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 16.12 01:01:41" (2/3) ... [2021-12-16 01:01:41,858 INFO L205 PluginConnector]: Invalid model from TraceAbstraction for observer de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction.TraceAbstractionObserver@5fd38840 and model type de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction AST 16.12 01:01:41, skipping insertion in model container [2021-12-16 01:01:41,858 INFO L185 PluginConnector]: Executing the observer TraceAbstractionObserver from plugin TraceAbstraction for "de.uni_freiburg.informatik.ultimate.plugins.generator.rcfgbuilder CFG 16.12 01:01:41" (3/3) ... [2021-12-16 01:01:41,859 INFO L111 eAbstractionObserver]: Analyzing ICFG minepump_spec5_product62.cil.c [2021-12-16 01:01:41,862 INFO L204 ceAbstractionStarter]: Automizer settings: Hoare:true NWA Interpolation:FPandBP Determinization: PREDICATE_ABSTRACTION [2021-12-16 01:01:41,863 INFO L163 ceAbstractionStarter]: Applying trace abstraction to program that has 1 error locations. [2021-12-16 01:01:41,892 INFO L338 AbstractCegarLoop]: ======== Iteration 0 == of CEGAR loop == AllErrorsAtOnce ======== [2021-12-16 01:01:41,896 INFO L339 AbstractCegarLoop]: Settings: SEPARATE_VIOLATION_CHECK=true, mInterprocedural=true, mMaxIterations=1000000, mWatchIteration=1000000, mArtifact=RCFG, mInterpolation=FPandBP, mInterpolantAutomaton=STRAIGHT_LINE, mDumpAutomata=false, mAutomataFormat=ATS_NUMERATE, mDumpPath=., mDeterminiation=PREDICATE_ABSTRACTION, mMinimize=MINIMIZE_SEVPA, mHoare=true, mAutomataTypeConcurrency=PETRI_NET, mHoareTripleChecks=INCREMENTAL, mHoareAnnotationPositions=LoopsAndPotentialCycles, mDumpOnlyReuseAutomata=false, mLimitTraceHistogram=0, mErrorLocTimeLimit=0, mLimitPathProgramCount=0, mCollectInterpolantStatistics=true, mHeuristicEmptinessCheck=false, mHeuristicEmptinessCheckAStarHeuristic=ZERO, mHeuristicEmptinessCheckAStarHeuristicRandomSeed=1337, mHeuristicEmptinessCheckSmtFeatureScoringMethod=DAGSIZE, mSMTFeatureExtraction=false, mSMTFeatureExtractionDumpPath=., mOverrideInterpolantAutomaton=false, mMcrInterpolantMethod=WP, mLoopAccelerationTechnique=FAST_UPR [2021-12-16 01:01:41,896 INFO L340 AbstractCegarLoop]: Starting to check reachability of 1 error locations. [2021-12-16 01:01:41,915 INFO L276 IsEmpty]: Start isEmpty. Operand has 114 states, 84 states have (on average 1.3571428571428572) internal successors, (114), 94 states have internal predecessors, (114), 18 states have call successors, (18), 10 states have call predecessors, (18), 10 states have return successors, (18), 13 states have call predecessors, (18), 18 states have call successors, (18) [2021-12-16 01:01:41,920 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 33 [2021-12-16 01:01:41,920 INFO L506 BasicCegarLoop]: Found error trace [2021-12-16 01:01:41,921 INFO L514 BasicCegarLoop]: trace histogram [2, 2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2021-12-16 01:01:41,921 INFO L402 AbstractCegarLoop]: === Iteration 1 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2021-12-16 01:01:41,925 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2021-12-16 01:01:41,925 INFO L85 PathProgramCache]: Analyzing trace with hash 1960372766, now seen corresponding path program 1 times [2021-12-16 01:01:41,931 INFO L121 FreeRefinementEngine]: Executing refinement strategy CAMEL [2021-12-16 01:01:41,931 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [1293335253] [2021-12-16 01:01:41,931 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2021-12-16 01:01:41,932 INFO L126 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2021-12-16 01:01:42,004 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 01:01:42,049 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 13 [2021-12-16 01:01:42,051 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 01:01:42,054 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 24 [2021-12-16 01:01:42,056 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 01:01:42,059 INFO L134 CoverageAnalysis]: Checked inductivity of 3 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 3 trivial. 0 not checked. [2021-12-16 01:01:42,059 INFO L139 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2021-12-16 01:01:42,059 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [1293335253] [2021-12-16 01:01:42,060 INFO L160 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [1293335253] provided 1 perfect and 0 imperfect interpolant sequences [2021-12-16 01:01:42,060 INFO L186 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2021-12-16 01:01:42,060 INFO L199 FreeRefinementEngine]: Number of different interpolants: perfect sequences [2] imperfect sequences [] total 2 [2021-12-16 01:01:42,061 INFO L115 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [1332403228] [2021-12-16 01:01:42,062 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2021-12-16 01:01:42,064 INFO L546 AbstractCegarLoop]: INTERPOLANT automaton has 2 states [2021-12-16 01:01:42,065 INFO L103 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2021-12-16 01:01:42,081 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 2 interpolants. [2021-12-16 01:01:42,081 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=1, Invalid=1, Unknown=0, NotChecked=0, Total=2 [2021-12-16 01:01:42,084 INFO L87 Difference]: Start difference. First operand has 114 states, 84 states have (on average 1.3571428571428572) internal successors, (114), 94 states have internal predecessors, (114), 18 states have call successors, (18), 10 states have call predecessors, (18), 10 states have return successors, (18), 13 states have call predecessors, (18), 18 states have call successors, (18) Second operand has 2 states, 2 states have (on average 12.0) internal successors, (24), 2 states have internal predecessors, (24), 1 states have call successors, (4), 2 states have call predecessors, (4), 1 states have return successors, (2), 1 states have call predecessors, (2), 1 states have call successors, (2) [2021-12-16 01:01:42,117 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2021-12-16 01:01:42,117 INFO L93 Difference]: Finished difference Result 219 states and 294 transitions. [2021-12-16 01:01:42,118 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 2 states. [2021-12-16 01:01:42,119 INFO L78 Accepts]: Start accepts. Automaton has has 2 states, 2 states have (on average 12.0) internal successors, (24), 2 states have internal predecessors, (24), 1 states have call successors, (4), 2 states have call predecessors, (4), 1 states have return successors, (2), 1 states have call predecessors, (2), 1 states have call successors, (2) Word has length 32 [2021-12-16 01:01:42,119 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2021-12-16 01:01:42,128 INFO L225 Difference]: With dead ends: 219 [2021-12-16 01:01:42,129 INFO L226 Difference]: Without dead ends: 105 [2021-12-16 01:01:42,145 INFO L932 BasicCegarLoop]: 0 DeclaredPredicates, 6 GetRequests, 6 SyntacticMatches, 0 SemanticMatches, 0 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 0 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=1, Invalid=1, Unknown=0, NotChecked=0, Total=2 [2021-12-16 01:01:42,149 INFO L933 BasicCegarLoop]: 144 mSDtfsCounter, 0 mSDsluCounter, 0 mSDsCounter, 0 mSdLazyCounter, 0 mSolverCounterSat, 0 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.0s Time, 0 mProtectedPredicate, 0 mProtectedAction, 0 SdHoareTripleChecker+Valid, 144 SdHoareTripleChecker+Invalid, 0 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 0 IncrementalHoareTripleChecker+Valid, 0 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.0s IncrementalHoareTripleChecker+Time [2021-12-16 01:01:42,150 INFO L934 BasicCegarLoop]: SdHoareTripleChecker [0 Valid, 144 Invalid, 0 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [0 Valid, 0 Invalid, 0 Unknown, 0 Unchecked, 0.0s Time] [2021-12-16 01:01:42,162 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 105 states. [2021-12-16 01:01:42,192 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 105 to 105. [2021-12-16 01:01:42,194 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 105 states, 77 states have (on average 1.2987012987012987) internal successors, (100), 86 states have internal predecessors, (100), 18 states have call successors, (18), 10 states have call predecessors, (18), 9 states have return successors, (17), 12 states have call predecessors, (17), 17 states have call successors, (17) [2021-12-16 01:01:42,199 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 105 states to 105 states and 135 transitions. [2021-12-16 01:01:42,201 INFO L78 Accepts]: Start accepts. Automaton has 105 states and 135 transitions. Word has length 32 [2021-12-16 01:01:42,201 INFO L84 Accepts]: Finished accepts. word is rejected. [2021-12-16 01:01:42,201 INFO L470 AbstractCegarLoop]: Abstraction has 105 states and 135 transitions. [2021-12-16 01:01:42,201 INFO L471 AbstractCegarLoop]: INTERPOLANT automaton has has 2 states, 2 states have (on average 12.0) internal successors, (24), 2 states have internal predecessors, (24), 1 states have call successors, (4), 2 states have call predecessors, (4), 1 states have return successors, (2), 1 states have call predecessors, (2), 1 states have call successors, (2) [2021-12-16 01:01:42,202 INFO L276 IsEmpty]: Start isEmpty. Operand 105 states and 135 transitions. [2021-12-16 01:01:42,208 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 34 [2021-12-16 01:01:42,209 INFO L506 BasicCegarLoop]: Found error trace [2021-12-16 01:01:42,209 INFO L514 BasicCegarLoop]: trace histogram [2, 2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2021-12-16 01:01:42,209 WARN L452 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable0 [2021-12-16 01:01:42,210 INFO L402 AbstractCegarLoop]: === Iteration 2 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2021-12-16 01:01:42,211 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2021-12-16 01:01:42,211 INFO L85 PathProgramCache]: Analyzing trace with hash -526010073, now seen corresponding path program 1 times [2021-12-16 01:01:42,211 INFO L121 FreeRefinementEngine]: Executing refinement strategy CAMEL [2021-12-16 01:01:42,211 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [1418199088] [2021-12-16 01:01:42,211 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2021-12-16 01:01:42,212 INFO L126 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2021-12-16 01:01:42,248 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 01:01:42,308 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 14 [2021-12-16 01:01:42,309 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 01:01:42,316 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 25 [2021-12-16 01:01:42,317 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 01:01:42,329 INFO L134 CoverageAnalysis]: Checked inductivity of 3 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 3 trivial. 0 not checked. [2021-12-16 01:01:42,329 INFO L139 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2021-12-16 01:01:42,329 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [1418199088] [2021-12-16 01:01:42,330 INFO L160 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [1418199088] provided 1 perfect and 0 imperfect interpolant sequences [2021-12-16 01:01:42,330 INFO L186 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2021-12-16 01:01:42,330 INFO L199 FreeRefinementEngine]: Number of different interpolants: perfect sequences [3] imperfect sequences [] total 3 [2021-12-16 01:01:42,330 INFO L115 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [2041998773] [2021-12-16 01:01:42,330 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2021-12-16 01:01:42,331 INFO L546 AbstractCegarLoop]: INTERPOLANT automaton has 3 states [2021-12-16 01:01:42,331 INFO L103 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2021-12-16 01:01:42,332 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 3 interpolants. [2021-12-16 01:01:42,332 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=3, Invalid=3, Unknown=0, NotChecked=0, Total=6 [2021-12-16 01:01:42,332 INFO L87 Difference]: Start difference. First operand 105 states and 135 transitions. Second operand has 3 states, 3 states have (on average 8.333333333333334) internal successors, (25), 3 states have internal predecessors, (25), 1 states have call successors, (4), 2 states have call predecessors, (4), 1 states have return successors, (2), 1 states have call predecessors, (2), 1 states have call successors, (2) [2021-12-16 01:01:42,343 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2021-12-16 01:01:42,346 INFO L93 Difference]: Finished difference Result 174 states and 224 transitions. [2021-12-16 01:01:42,347 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 3 states. [2021-12-16 01:01:42,348 INFO L78 Accepts]: Start accepts. Automaton has has 3 states, 3 states have (on average 8.333333333333334) internal successors, (25), 3 states have internal predecessors, (25), 1 states have call successors, (4), 2 states have call predecessors, (4), 1 states have return successors, (2), 1 states have call predecessors, (2), 1 states have call successors, (2) Word has length 33 [2021-12-16 01:01:42,348 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2021-12-16 01:01:42,349 INFO L225 Difference]: With dead ends: 174 [2021-12-16 01:01:42,350 INFO L226 Difference]: Without dead ends: 96 [2021-12-16 01:01:42,351 INFO L932 BasicCegarLoop]: 0 DeclaredPredicates, 7 GetRequests, 6 SyntacticMatches, 0 SemanticMatches, 1 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 0 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=3, Invalid=3, Unknown=0, NotChecked=0, Total=6 [2021-12-16 01:01:42,353 INFO L933 BasicCegarLoop]: 122 mSDtfsCounter, 13 mSDsluCounter, 105 mSDsCounter, 0 mSdLazyCounter, 1 mSolverCounterSat, 0 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.0s Time, 0 mProtectedPredicate, 0 mProtectedAction, 16 SdHoareTripleChecker+Valid, 227 SdHoareTripleChecker+Invalid, 1 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 0 IncrementalHoareTripleChecker+Valid, 1 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.0s IncrementalHoareTripleChecker+Time [2021-12-16 01:01:42,355 INFO L934 BasicCegarLoop]: SdHoareTripleChecker [16 Valid, 227 Invalid, 1 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [0 Valid, 1 Invalid, 0 Unknown, 0 Unchecked, 0.0s Time] [2021-12-16 01:01:42,356 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 96 states. [2021-12-16 01:01:42,367 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 96 to 96. [2021-12-16 01:01:42,369 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 96 states, 71 states have (on average 1.3098591549295775) internal successors, (93), 80 states have internal predecessors, (93), 15 states have call successors, (15), 9 states have call predecessors, (15), 9 states have return successors, (15), 10 states have call predecessors, (15), 15 states have call successors, (15) [2021-12-16 01:01:42,369 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 96 states to 96 states and 123 transitions. [2021-12-16 01:01:42,370 INFO L78 Accepts]: Start accepts. Automaton has 96 states and 123 transitions. Word has length 33 [2021-12-16 01:01:42,370 INFO L84 Accepts]: Finished accepts. word is rejected. [2021-12-16 01:01:42,370 INFO L470 AbstractCegarLoop]: Abstraction has 96 states and 123 transitions. [2021-12-16 01:01:42,370 INFO L471 AbstractCegarLoop]: INTERPOLANT automaton has has 3 states, 3 states have (on average 8.333333333333334) internal successors, (25), 3 states have internal predecessors, (25), 1 states have call successors, (4), 2 states have call predecessors, (4), 1 states have return successors, (2), 1 states have call predecessors, (2), 1 states have call successors, (2) [2021-12-16 01:01:42,370 INFO L276 IsEmpty]: Start isEmpty. Operand 96 states and 123 transitions. [2021-12-16 01:01:42,371 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 39 [2021-12-16 01:01:42,371 INFO L506 BasicCegarLoop]: Found error trace [2021-12-16 01:01:42,371 INFO L514 BasicCegarLoop]: trace histogram [2, 2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2021-12-16 01:01:42,371 WARN L452 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable1 [2021-12-16 01:01:42,371 INFO L402 AbstractCegarLoop]: === Iteration 3 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2021-12-16 01:01:42,372 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2021-12-16 01:01:42,372 INFO L85 PathProgramCache]: Analyzing trace with hash -1914406272, now seen corresponding path program 1 times [2021-12-16 01:01:42,372 INFO L121 FreeRefinementEngine]: Executing refinement strategy CAMEL [2021-12-16 01:01:42,372 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [1357065259] [2021-12-16 01:01:42,372 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2021-12-16 01:01:42,372 INFO L126 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2021-12-16 01:01:42,384 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 01:01:42,417 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 19 [2021-12-16 01:01:42,420 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 01:01:42,424 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 30 [2021-12-16 01:01:42,425 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 01:01:42,444 INFO L134 CoverageAnalysis]: Checked inductivity of 3 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 3 trivial. 0 not checked. [2021-12-16 01:01:42,444 INFO L139 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2021-12-16 01:01:42,445 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [1357065259] [2021-12-16 01:01:42,445 INFO L160 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [1357065259] provided 1 perfect and 0 imperfect interpolant sequences [2021-12-16 01:01:42,445 INFO L186 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2021-12-16 01:01:42,445 INFO L199 FreeRefinementEngine]: Number of different interpolants: perfect sequences [5] imperfect sequences [] total 5 [2021-12-16 01:01:42,445 INFO L115 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [1001593410] [2021-12-16 01:01:42,445 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2021-12-16 01:01:42,446 INFO L546 AbstractCegarLoop]: INTERPOLANT automaton has 5 states [2021-12-16 01:01:42,446 INFO L103 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2021-12-16 01:01:42,446 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 5 interpolants. [2021-12-16 01:01:42,447 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=7, Invalid=13, Unknown=0, NotChecked=0, Total=20 [2021-12-16 01:01:42,447 INFO L87 Difference]: Start difference. First operand 96 states and 123 transitions. Second operand has 5 states, 5 states have (on average 6.2) internal successors, (31), 5 states have internal predecessors, (31), 2 states have call successors, (3), 2 states have call predecessors, (3), 1 states have return successors, (2), 2 states have call predecessors, (2), 2 states have call successors, (2) [2021-12-16 01:01:42,492 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2021-12-16 01:01:42,493 INFO L93 Difference]: Finished difference Result 184 states and 239 transitions. [2021-12-16 01:01:42,493 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 5 states. [2021-12-16 01:01:42,493 INFO L78 Accepts]: Start accepts. Automaton has has 5 states, 5 states have (on average 6.2) internal successors, (31), 5 states have internal predecessors, (31), 2 states have call successors, (3), 2 states have call predecessors, (3), 1 states have return successors, (2), 2 states have call predecessors, (2), 2 states have call successors, (2) Word has length 38 [2021-12-16 01:01:42,493 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2021-12-16 01:01:42,494 INFO L225 Difference]: With dead ends: 184 [2021-12-16 01:01:42,494 INFO L226 Difference]: Without dead ends: 96 [2021-12-16 01:01:42,495 INFO L932 BasicCegarLoop]: 0 DeclaredPredicates, 13 GetRequests, 8 SyntacticMatches, 0 SemanticMatches, 5 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 0 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=17, Invalid=25, Unknown=0, NotChecked=0, Total=42 [2021-12-16 01:01:42,496 INFO L933 BasicCegarLoop]: 116 mSDtfsCounter, 146 mSDsluCounter, 198 mSDsCounter, 0 mSdLazyCounter, 9 mSolverCounterSat, 9 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.0s Time, 0 mProtectedPredicate, 0 mProtectedAction, 146 SdHoareTripleChecker+Valid, 314 SdHoareTripleChecker+Invalid, 18 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 9 IncrementalHoareTripleChecker+Valid, 9 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.0s IncrementalHoareTripleChecker+Time [2021-12-16 01:01:42,496 INFO L934 BasicCegarLoop]: SdHoareTripleChecker [146 Valid, 314 Invalid, 18 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [9 Valid, 9 Invalid, 0 Unknown, 0 Unchecked, 0.0s Time] [2021-12-16 01:01:42,497 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 96 states. [2021-12-16 01:01:42,503 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 96 to 96. [2021-12-16 01:01:42,503 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 96 states, 71 states have (on average 1.295774647887324) internal successors, (92), 80 states have internal predecessors, (92), 15 states have call successors, (15), 9 states have call predecessors, (15), 9 states have return successors, (15), 10 states have call predecessors, (15), 15 states have call successors, (15) [2021-12-16 01:01:42,504 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 96 states to 96 states and 122 transitions. [2021-12-16 01:01:42,504 INFO L78 Accepts]: Start accepts. Automaton has 96 states and 122 transitions. Word has length 38 [2021-12-16 01:01:42,505 INFO L84 Accepts]: Finished accepts. word is rejected. [2021-12-16 01:01:42,505 INFO L470 AbstractCegarLoop]: Abstraction has 96 states and 122 transitions. [2021-12-16 01:01:42,505 INFO L471 AbstractCegarLoop]: INTERPOLANT automaton has has 5 states, 5 states have (on average 6.2) internal successors, (31), 5 states have internal predecessors, (31), 2 states have call successors, (3), 2 states have call predecessors, (3), 1 states have return successors, (2), 2 states have call predecessors, (2), 2 states have call successors, (2) [2021-12-16 01:01:42,506 INFO L276 IsEmpty]: Start isEmpty. Operand 96 states and 122 transitions. [2021-12-16 01:01:42,506 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 52 [2021-12-16 01:01:42,506 INFO L506 BasicCegarLoop]: Found error trace [2021-12-16 01:01:42,507 INFO L514 BasicCegarLoop]: trace histogram [2, 2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2021-12-16 01:01:42,507 WARN L452 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable2 [2021-12-16 01:01:42,507 INFO L402 AbstractCegarLoop]: === Iteration 4 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2021-12-16 01:01:42,507 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2021-12-16 01:01:42,508 INFO L85 PathProgramCache]: Analyzing trace with hash 1685949316, now seen corresponding path program 1 times [2021-12-16 01:01:42,508 INFO L121 FreeRefinementEngine]: Executing refinement strategy CAMEL [2021-12-16 01:01:42,508 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [407569617] [2021-12-16 01:01:42,508 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2021-12-16 01:01:42,508 INFO L126 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2021-12-16 01:01:42,519 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 01:01:42,539 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 19 [2021-12-16 01:01:42,540 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 01:01:42,542 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 28 [2021-12-16 01:01:42,543 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 01:01:42,548 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 35 [2021-12-16 01:01:42,549 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 01:01:42,551 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 43 [2021-12-16 01:01:42,551 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 01:01:42,553 INFO L134 CoverageAnalysis]: Checked inductivity of 3 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 3 trivial. 0 not checked. [2021-12-16 01:01:42,553 INFO L139 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2021-12-16 01:01:42,554 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [407569617] [2021-12-16 01:01:42,554 INFO L160 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [407569617] provided 1 perfect and 0 imperfect interpolant sequences [2021-12-16 01:01:42,554 INFO L186 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2021-12-16 01:01:42,554 INFO L199 FreeRefinementEngine]: Number of different interpolants: perfect sequences [4] imperfect sequences [] total 4 [2021-12-16 01:01:42,554 INFO L115 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [1683480769] [2021-12-16 01:01:42,554 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2021-12-16 01:01:42,555 INFO L546 AbstractCegarLoop]: INTERPOLANT automaton has 4 states [2021-12-16 01:01:42,555 INFO L103 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2021-12-16 01:01:42,555 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 4 interpolants. [2021-12-16 01:01:42,555 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=5, Invalid=7, Unknown=0, NotChecked=0, Total=12 [2021-12-16 01:01:42,556 INFO L87 Difference]: Start difference. First operand 96 states and 122 transitions. Second operand has 4 states, 4 states have (on average 10.0) internal successors, (40), 3 states have internal predecessors, (40), 2 states have call successors, (5), 3 states have call predecessors, (5), 1 states have return successors, (4), 2 states have call predecessors, (4), 2 states have call successors, (4) [2021-12-16 01:01:42,670 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2021-12-16 01:01:42,670 INFO L93 Difference]: Finished difference Result 273 states and 351 transitions. [2021-12-16 01:01:42,670 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 5 states. [2021-12-16 01:01:42,671 INFO L78 Accepts]: Start accepts. Automaton has has 4 states, 4 states have (on average 10.0) internal successors, (40), 3 states have internal predecessors, (40), 2 states have call successors, (5), 3 states have call predecessors, (5), 1 states have return successors, (4), 2 states have call predecessors, (4), 2 states have call successors, (4) Word has length 51 [2021-12-16 01:01:42,671 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2021-12-16 01:01:42,672 INFO L225 Difference]: With dead ends: 273 [2021-12-16 01:01:42,672 INFO L226 Difference]: Without dead ends: 185 [2021-12-16 01:01:42,673 INFO L932 BasicCegarLoop]: 0 DeclaredPredicates, 13 GetRequests, 10 SyntacticMatches, 0 SemanticMatches, 3 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 0 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=9, Invalid=11, Unknown=0, NotChecked=0, Total=20 [2021-12-16 01:01:42,674 INFO L933 BasicCegarLoop]: 112 mSDtfsCounter, 174 mSDsluCounter, 125 mSDsCounter, 0 mSdLazyCounter, 82 mSolverCounterSat, 50 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.1s Time, 0 mProtectedPredicate, 0 mProtectedAction, 181 SdHoareTripleChecker+Valid, 237 SdHoareTripleChecker+Invalid, 132 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 50 IncrementalHoareTripleChecker+Valid, 82 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.1s IncrementalHoareTripleChecker+Time [2021-12-16 01:01:42,674 INFO L934 BasicCegarLoop]: SdHoareTripleChecker [181 Valid, 237 Invalid, 132 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [50 Valid, 82 Invalid, 0 Unknown, 0 Unchecked, 0.1s Time] [2021-12-16 01:01:42,674 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 185 states. [2021-12-16 01:01:42,686 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 185 to 179. [2021-12-16 01:01:42,686 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 179 states, 134 states have (on average 1.2686567164179106) internal successors, (170), 143 states have internal predecessors, (170), 22 states have call successors, (22), 17 states have call predecessors, (22), 22 states have return successors, (33), 24 states have call predecessors, (33), 22 states have call successors, (33) [2021-12-16 01:01:42,687 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 179 states to 179 states and 225 transitions. [2021-12-16 01:01:42,687 INFO L78 Accepts]: Start accepts. Automaton has 179 states and 225 transitions. Word has length 51 [2021-12-16 01:01:42,688 INFO L84 Accepts]: Finished accepts. word is rejected. [2021-12-16 01:01:42,688 INFO L470 AbstractCegarLoop]: Abstraction has 179 states and 225 transitions. [2021-12-16 01:01:42,688 INFO L471 AbstractCegarLoop]: INTERPOLANT automaton has has 4 states, 4 states have (on average 10.0) internal successors, (40), 3 states have internal predecessors, (40), 2 states have call successors, (5), 3 states have call predecessors, (5), 1 states have return successors, (4), 2 states have call predecessors, (4), 2 states have call successors, (4) [2021-12-16 01:01:42,688 INFO L276 IsEmpty]: Start isEmpty. Operand 179 states and 225 transitions. [2021-12-16 01:01:42,689 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 60 [2021-12-16 01:01:42,689 INFO L506 BasicCegarLoop]: Found error trace [2021-12-16 01:01:42,689 INFO L514 BasicCegarLoop]: trace histogram [2, 2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2021-12-16 01:01:42,689 WARN L452 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable3 [2021-12-16 01:01:42,689 INFO L402 AbstractCegarLoop]: === Iteration 5 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2021-12-16 01:01:42,689 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2021-12-16 01:01:42,690 INFO L85 PathProgramCache]: Analyzing trace with hash -1718008340, now seen corresponding path program 1 times [2021-12-16 01:01:42,690 INFO L121 FreeRefinementEngine]: Executing refinement strategy CAMEL [2021-12-16 01:01:42,690 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [487479177] [2021-12-16 01:01:42,690 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2021-12-16 01:01:42,690 INFO L126 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2021-12-16 01:01:42,703 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 01:01:42,756 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 19 [2021-12-16 01:01:42,760 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 01:01:42,767 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 28 [2021-12-16 01:01:42,778 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 01:01:42,791 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 2 [2021-12-16 01:01:42,796 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 01:01:42,809 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 8 [2021-12-16 01:01:42,811 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 01:01:42,814 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 51 [2021-12-16 01:01:42,834 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 01:01:42,846 INFO L134 CoverageAnalysis]: Checked inductivity of 3 backedges. 2 proven. 0 refuted. 0 times theorem prover too weak. 1 trivial. 0 not checked. [2021-12-16 01:01:42,847 INFO L139 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2021-12-16 01:01:42,847 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [487479177] [2021-12-16 01:01:42,848 INFO L160 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [487479177] provided 1 perfect and 0 imperfect interpolant sequences [2021-12-16 01:01:42,848 INFO L186 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2021-12-16 01:01:42,848 INFO L199 FreeRefinementEngine]: Number of different interpolants: perfect sequences [7] imperfect sequences [] total 7 [2021-12-16 01:01:42,848 INFO L115 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [100440700] [2021-12-16 01:01:42,849 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2021-12-16 01:01:42,850 INFO L546 AbstractCegarLoop]: INTERPOLANT automaton has 7 states [2021-12-16 01:01:42,850 INFO L103 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2021-12-16 01:01:42,850 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 7 interpolants. [2021-12-16 01:01:42,850 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=11, Invalid=31, Unknown=0, NotChecked=0, Total=42 [2021-12-16 01:01:42,851 INFO L87 Difference]: Start difference. First operand 179 states and 225 transitions. Second operand has 7 states, 7 states have (on average 6.857142857142857) internal successors, (48), 5 states have internal predecessors, (48), 2 states have call successors, (6), 3 states have call predecessors, (6), 3 states have return successors, (5), 2 states have call predecessors, (5), 2 states have call successors, (5) [2021-12-16 01:01:43,075 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2021-12-16 01:01:43,075 INFO L93 Difference]: Finished difference Result 362 states and 456 transitions. [2021-12-16 01:01:43,076 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 13 states. [2021-12-16 01:01:43,076 INFO L78 Accepts]: Start accepts. Automaton has has 7 states, 7 states have (on average 6.857142857142857) internal successors, (48), 5 states have internal predecessors, (48), 2 states have call successors, (6), 3 states have call predecessors, (6), 3 states have return successors, (5), 2 states have call predecessors, (5), 2 states have call successors, (5) Word has length 59 [2021-12-16 01:01:43,076 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2021-12-16 01:01:43,078 INFO L225 Difference]: With dead ends: 362 [2021-12-16 01:01:43,078 INFO L226 Difference]: Without dead ends: 191 [2021-12-16 01:01:43,079 INFO L932 BasicCegarLoop]: 0 DeclaredPredicates, 27 GetRequests, 14 SyntacticMatches, 0 SemanticMatches, 13 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 25 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=53, Invalid=157, Unknown=0, NotChecked=0, Total=210 [2021-12-16 01:01:43,079 INFO L933 BasicCegarLoop]: 118 mSDtfsCounter, 142 mSDsluCounter, 409 mSDsCounter, 0 mSdLazyCounter, 246 mSolverCounterSat, 45 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.1s Time, 0 mProtectedPredicate, 0 mProtectedAction, 149 SdHoareTripleChecker+Valid, 527 SdHoareTripleChecker+Invalid, 291 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 45 IncrementalHoareTripleChecker+Valid, 246 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.1s IncrementalHoareTripleChecker+Time [2021-12-16 01:01:43,080 INFO L934 BasicCegarLoop]: SdHoareTripleChecker [149 Valid, 527 Invalid, 291 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [45 Valid, 246 Invalid, 0 Unknown, 0 Unchecked, 0.1s Time] [2021-12-16 01:01:43,080 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 191 states. [2021-12-16 01:01:43,091 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 191 to 177. [2021-12-16 01:01:43,091 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 177 states, 132 states have (on average 1.2424242424242424) internal successors, (164), 141 states have internal predecessors, (164), 22 states have call successors, (22), 17 states have call predecessors, (22), 22 states have return successors, (33), 24 states have call predecessors, (33), 22 states have call successors, (33) [2021-12-16 01:01:43,092 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 177 states to 177 states and 219 transitions. [2021-12-16 01:01:43,092 INFO L78 Accepts]: Start accepts. Automaton has 177 states and 219 transitions. Word has length 59 [2021-12-16 01:01:43,093 INFO L84 Accepts]: Finished accepts. word is rejected. [2021-12-16 01:01:43,093 INFO L470 AbstractCegarLoop]: Abstraction has 177 states and 219 transitions. [2021-12-16 01:01:43,093 INFO L471 AbstractCegarLoop]: INTERPOLANT automaton has has 7 states, 7 states have (on average 6.857142857142857) internal successors, (48), 5 states have internal predecessors, (48), 2 states have call successors, (6), 3 states have call predecessors, (6), 3 states have return successors, (5), 2 states have call predecessors, (5), 2 states have call successors, (5) [2021-12-16 01:01:43,093 INFO L276 IsEmpty]: Start isEmpty. Operand 177 states and 219 transitions. [2021-12-16 01:01:43,094 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 66 [2021-12-16 01:01:43,094 INFO L506 BasicCegarLoop]: Found error trace [2021-12-16 01:01:43,095 INFO L514 BasicCegarLoop]: trace histogram [2, 2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2021-12-16 01:01:43,095 WARN L452 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable4 [2021-12-16 01:01:43,095 INFO L402 AbstractCegarLoop]: === Iteration 6 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2021-12-16 01:01:43,095 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2021-12-16 01:01:43,096 INFO L85 PathProgramCache]: Analyzing trace with hash -12885391, now seen corresponding path program 1 times [2021-12-16 01:01:43,096 INFO L121 FreeRefinementEngine]: Executing refinement strategy CAMEL [2021-12-16 01:01:43,096 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [1463434746] [2021-12-16 01:01:43,096 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2021-12-16 01:01:43,096 INFO L126 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2021-12-16 01:01:43,106 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 01:01:43,118 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 19 [2021-12-16 01:01:43,119 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 01:01:43,122 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 28 [2021-12-16 01:01:43,125 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 01:01:43,130 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 2 [2021-12-16 01:01:43,133 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 01:01:43,147 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 8 [2021-12-16 01:01:43,149 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 01:01:43,151 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 57 [2021-12-16 01:01:43,151 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 01:01:43,153 INFO L134 CoverageAnalysis]: Checked inductivity of 3 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 3 trivial. 0 not checked. [2021-12-16 01:01:43,153 INFO L139 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2021-12-16 01:01:43,153 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [1463434746] [2021-12-16 01:01:43,153 INFO L160 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [1463434746] provided 1 perfect and 0 imperfect interpolant sequences [2021-12-16 01:01:43,154 INFO L186 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2021-12-16 01:01:43,154 INFO L199 FreeRefinementEngine]: Number of different interpolants: perfect sequences [6] imperfect sequences [] total 6 [2021-12-16 01:01:43,154 INFO L115 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [867715189] [2021-12-16 01:01:43,154 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2021-12-16 01:01:43,154 INFO L546 AbstractCegarLoop]: INTERPOLANT automaton has 6 states [2021-12-16 01:01:43,154 INFO L103 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2021-12-16 01:01:43,155 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 6 interpolants. [2021-12-16 01:01:43,155 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=9, Invalid=21, Unknown=0, NotChecked=0, Total=30 [2021-12-16 01:01:43,155 INFO L87 Difference]: Start difference. First operand 177 states and 219 transitions. Second operand has 6 states, 6 states have (on average 8.666666666666666) internal successors, (52), 5 states have internal predecessors, (52), 2 states have call successors, (6), 2 states have call predecessors, (6), 2 states have return successors, (5), 2 states have call predecessors, (5), 2 states have call successors, (5) [2021-12-16 01:01:43,272 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2021-12-16 01:01:43,272 INFO L93 Difference]: Finished difference Result 356 states and 455 transitions. [2021-12-16 01:01:43,273 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 7 states. [2021-12-16 01:01:43,273 INFO L78 Accepts]: Start accepts. Automaton has has 6 states, 6 states have (on average 8.666666666666666) internal successors, (52), 5 states have internal predecessors, (52), 2 states have call successors, (6), 2 states have call predecessors, (6), 2 states have return successors, (5), 2 states have call predecessors, (5), 2 states have call successors, (5) Word has length 65 [2021-12-16 01:01:43,273 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2021-12-16 01:01:43,274 INFO L225 Difference]: With dead ends: 356 [2021-12-16 01:01:43,274 INFO L226 Difference]: Without dead ends: 187 [2021-12-16 01:01:43,275 INFO L932 BasicCegarLoop]: 0 DeclaredPredicates, 21 GetRequests, 13 SyntacticMatches, 0 SemanticMatches, 8 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 3 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=32, Invalid=58, Unknown=0, NotChecked=0, Total=90 [2021-12-16 01:01:43,275 INFO L933 BasicCegarLoop]: 107 mSDtfsCounter, 81 mSDsluCounter, 326 mSDsCounter, 0 mSdLazyCounter, 137 mSolverCounterSat, 28 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.1s Time, 0 mProtectedPredicate, 0 mProtectedAction, 86 SdHoareTripleChecker+Valid, 433 SdHoareTripleChecker+Invalid, 165 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 28 IncrementalHoareTripleChecker+Valid, 137 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.1s IncrementalHoareTripleChecker+Time [2021-12-16 01:01:43,276 INFO L934 BasicCegarLoop]: SdHoareTripleChecker [86 Valid, 433 Invalid, 165 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [28 Valid, 137 Invalid, 0 Unknown, 0 Unchecked, 0.1s Time] [2021-12-16 01:01:43,276 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 187 states. [2021-12-16 01:01:43,283 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 187 to 180. [2021-12-16 01:01:43,284 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 180 states, 135 states have (on average 1.237037037037037) internal successors, (167), 144 states have internal predecessors, (167), 22 states have call successors, (22), 17 states have call predecessors, (22), 22 states have return successors, (33), 24 states have call predecessors, (33), 22 states have call successors, (33) [2021-12-16 01:01:43,284 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 180 states to 180 states and 222 transitions. [2021-12-16 01:01:43,285 INFO L78 Accepts]: Start accepts. Automaton has 180 states and 222 transitions. Word has length 65 [2021-12-16 01:01:43,285 INFO L84 Accepts]: Finished accepts. word is rejected. [2021-12-16 01:01:43,285 INFO L470 AbstractCegarLoop]: Abstraction has 180 states and 222 transitions. [2021-12-16 01:01:43,285 INFO L471 AbstractCegarLoop]: INTERPOLANT automaton has has 6 states, 6 states have (on average 8.666666666666666) internal successors, (52), 5 states have internal predecessors, (52), 2 states have call successors, (6), 2 states have call predecessors, (6), 2 states have return successors, (5), 2 states have call predecessors, (5), 2 states have call successors, (5) [2021-12-16 01:01:43,285 INFO L276 IsEmpty]: Start isEmpty. Operand 180 states and 222 transitions. [2021-12-16 01:01:43,286 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 66 [2021-12-16 01:01:43,286 INFO L506 BasicCegarLoop]: Found error trace [2021-12-16 01:01:43,286 INFO L514 BasicCegarLoop]: trace histogram [2, 2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2021-12-16 01:01:43,286 WARN L452 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable5 [2021-12-16 01:01:43,286 INFO L402 AbstractCegarLoop]: === Iteration 7 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2021-12-16 01:01:43,287 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2021-12-16 01:01:43,287 INFO L85 PathProgramCache]: Analyzing trace with hash 1373318003, now seen corresponding path program 1 times [2021-12-16 01:01:43,287 INFO L121 FreeRefinementEngine]: Executing refinement strategy CAMEL [2021-12-16 01:01:43,287 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [790205871] [2021-12-16 01:01:43,287 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2021-12-16 01:01:43,287 INFO L126 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2021-12-16 01:01:43,295 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 01:01:43,306 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 19 [2021-12-16 01:01:43,307 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 01:01:43,310 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 28 [2021-12-16 01:01:43,313 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 01:01:43,318 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 2 [2021-12-16 01:01:43,320 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 01:01:43,331 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 8 [2021-12-16 01:01:43,332 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 01:01:43,334 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 57 [2021-12-16 01:01:43,335 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 01:01:43,336 INFO L134 CoverageAnalysis]: Checked inductivity of 3 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 3 trivial. 0 not checked. [2021-12-16 01:01:43,336 INFO L139 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2021-12-16 01:01:43,336 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [790205871] [2021-12-16 01:01:43,337 INFO L160 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [790205871] provided 1 perfect and 0 imperfect interpolant sequences [2021-12-16 01:01:43,337 INFO L186 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2021-12-16 01:01:43,337 INFO L199 FreeRefinementEngine]: Number of different interpolants: perfect sequences [5] imperfect sequences [] total 5 [2021-12-16 01:01:43,337 INFO L115 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [993818187] [2021-12-16 01:01:43,337 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2021-12-16 01:01:43,337 INFO L546 AbstractCegarLoop]: INTERPOLANT automaton has 5 states [2021-12-16 01:01:43,337 INFO L103 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2021-12-16 01:01:43,337 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 5 interpolants. [2021-12-16 01:01:43,338 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=7, Invalid=13, Unknown=0, NotChecked=0, Total=20 [2021-12-16 01:01:43,338 INFO L87 Difference]: Start difference. First operand 180 states and 222 transitions. Second operand has 5 states, 5 states have (on average 10.4) internal successors, (52), 4 states have internal predecessors, (52), 2 states have call successors, (6), 2 states have call predecessors, (6), 2 states have return successors, (5), 2 states have call predecessors, (5), 2 states have call successors, (5) [2021-12-16 01:01:43,437 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2021-12-16 01:01:43,437 INFO L93 Difference]: Finished difference Result 362 states and 460 transitions. [2021-12-16 01:01:43,437 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 5 states. [2021-12-16 01:01:43,438 INFO L78 Accepts]: Start accepts. Automaton has has 5 states, 5 states have (on average 10.4) internal successors, (52), 4 states have internal predecessors, (52), 2 states have call successors, (6), 2 states have call predecessors, (6), 2 states have return successors, (5), 2 states have call predecessors, (5), 2 states have call successors, (5) Word has length 65 [2021-12-16 01:01:43,438 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2021-12-16 01:01:43,439 INFO L225 Difference]: With dead ends: 362 [2021-12-16 01:01:43,439 INFO L226 Difference]: Without dead ends: 190 [2021-12-16 01:01:43,439 INFO L932 BasicCegarLoop]: 0 DeclaredPredicates, 18 GetRequests, 13 SyntacticMatches, 0 SemanticMatches, 5 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 0 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=17, Invalid=25, Unknown=0, NotChecked=0, Total=42 [2021-12-16 01:01:43,440 INFO L933 BasicCegarLoop]: 109 mSDtfsCounter, 82 mSDsluCounter, 231 mSDsCounter, 0 mSdLazyCounter, 106 mSolverCounterSat, 22 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.1s Time, 0 mProtectedPredicate, 0 mProtectedAction, 88 SdHoareTripleChecker+Valid, 340 SdHoareTripleChecker+Invalid, 128 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 22 IncrementalHoareTripleChecker+Valid, 106 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.1s IncrementalHoareTripleChecker+Time [2021-12-16 01:01:43,440 INFO L934 BasicCegarLoop]: SdHoareTripleChecker [88 Valid, 340 Invalid, 128 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [22 Valid, 106 Invalid, 0 Unknown, 0 Unchecked, 0.1s Time] [2021-12-16 01:01:43,441 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 190 states. [2021-12-16 01:01:43,447 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 190 to 182. [2021-12-16 01:01:43,447 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 182 states, 137 states have (on average 1.2335766423357664) internal successors, (169), 146 states have internal predecessors, (169), 22 states have call successors, (22), 17 states have call predecessors, (22), 22 states have return successors, (33), 24 states have call predecessors, (33), 22 states have call successors, (33) [2021-12-16 01:01:43,448 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 182 states to 182 states and 224 transitions. [2021-12-16 01:01:43,448 INFO L78 Accepts]: Start accepts. Automaton has 182 states and 224 transitions. Word has length 65 [2021-12-16 01:01:43,449 INFO L84 Accepts]: Finished accepts. word is rejected. [2021-12-16 01:01:43,449 INFO L470 AbstractCegarLoop]: Abstraction has 182 states and 224 transitions. [2021-12-16 01:01:43,449 INFO L471 AbstractCegarLoop]: INTERPOLANT automaton has has 5 states, 5 states have (on average 10.4) internal successors, (52), 4 states have internal predecessors, (52), 2 states have call successors, (6), 2 states have call predecessors, (6), 2 states have return successors, (5), 2 states have call predecessors, (5), 2 states have call successors, (5) [2021-12-16 01:01:43,449 INFO L276 IsEmpty]: Start isEmpty. Operand 182 states and 224 transitions. [2021-12-16 01:01:43,449 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 66 [2021-12-16 01:01:43,449 INFO L506 BasicCegarLoop]: Found error trace [2021-12-16 01:01:43,450 INFO L514 BasicCegarLoop]: trace histogram [2, 2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2021-12-16 01:01:43,450 WARN L452 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable6 [2021-12-16 01:01:43,450 INFO L402 AbstractCegarLoop]: === Iteration 8 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2021-12-16 01:01:43,450 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2021-12-16 01:01:43,450 INFO L85 PathProgramCache]: Analyzing trace with hash 2074917877, now seen corresponding path program 1 times [2021-12-16 01:01:43,450 INFO L121 FreeRefinementEngine]: Executing refinement strategy CAMEL [2021-12-16 01:01:43,450 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [1982050799] [2021-12-16 01:01:43,450 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2021-12-16 01:01:43,450 INFO L126 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2021-12-16 01:01:43,457 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 01:01:43,477 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 19 [2021-12-16 01:01:43,478 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 01:01:43,481 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 28 [2021-12-16 01:01:43,484 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 01:01:43,491 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 2 [2021-12-16 01:01:43,493 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 01:01:43,501 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 8 [2021-12-16 01:01:43,502 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 01:01:43,505 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 57 [2021-12-16 01:01:43,505 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 01:01:43,507 INFO L134 CoverageAnalysis]: Checked inductivity of 3 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 3 trivial. 0 not checked. [2021-12-16 01:01:43,507 INFO L139 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2021-12-16 01:01:43,507 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [1982050799] [2021-12-16 01:01:43,507 INFO L160 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [1982050799] provided 1 perfect and 0 imperfect interpolant sequences [2021-12-16 01:01:43,507 INFO L186 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2021-12-16 01:01:43,508 INFO L199 FreeRefinementEngine]: Number of different interpolants: perfect sequences [5] imperfect sequences [] total 5 [2021-12-16 01:01:43,508 INFO L115 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [1202983464] [2021-12-16 01:01:43,508 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2021-12-16 01:01:43,508 INFO L546 AbstractCegarLoop]: INTERPOLANT automaton has 5 states [2021-12-16 01:01:43,508 INFO L103 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2021-12-16 01:01:43,508 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 5 interpolants. [2021-12-16 01:01:43,508 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=7, Invalid=13, Unknown=0, NotChecked=0, Total=20 [2021-12-16 01:01:43,508 INFO L87 Difference]: Start difference. First operand 182 states and 224 transitions. Second operand has 5 states, 5 states have (on average 10.4) internal successors, (52), 4 states have internal predecessors, (52), 4 states have call successors, (6), 3 states have call predecessors, (6), 2 states have return successors, (5), 3 states have call predecessors, (5), 4 states have call successors, (5) [2021-12-16 01:01:43,674 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2021-12-16 01:01:43,675 INFO L93 Difference]: Finished difference Result 498 states and 640 transitions. [2021-12-16 01:01:43,675 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 7 states. [2021-12-16 01:01:43,675 INFO L78 Accepts]: Start accepts. Automaton has has 5 states, 5 states have (on average 10.4) internal successors, (52), 4 states have internal predecessors, (52), 4 states have call successors, (6), 3 states have call predecessors, (6), 2 states have return successors, (5), 3 states have call predecessors, (5), 4 states have call successors, (5) Word has length 65 [2021-12-16 01:01:43,676 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2021-12-16 01:01:43,677 INFO L225 Difference]: With dead ends: 498 [2021-12-16 01:01:43,677 INFO L226 Difference]: Without dead ends: 324 [2021-12-16 01:01:43,678 INFO L932 BasicCegarLoop]: 0 DeclaredPredicates, 20 GetRequests, 14 SyntacticMatches, 1 SemanticMatches, 5 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 1 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=15, Invalid=27, Unknown=0, NotChecked=0, Total=42 [2021-12-16 01:01:43,679 INFO L933 BasicCegarLoop]: 161 mSDtfsCounter, 241 mSDsluCounter, 202 mSDsCounter, 0 mSdLazyCounter, 179 mSolverCounterSat, 80 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.1s Time, 0 mProtectedPredicate, 0 mProtectedAction, 249 SdHoareTripleChecker+Valid, 363 SdHoareTripleChecker+Invalid, 259 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 80 IncrementalHoareTripleChecker+Valid, 179 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.1s IncrementalHoareTripleChecker+Time [2021-12-16 01:01:43,679 INFO L934 BasicCegarLoop]: SdHoareTripleChecker [249 Valid, 363 Invalid, 259 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [80 Valid, 179 Invalid, 0 Unknown, 0 Unchecked, 0.1s Time] [2021-12-16 01:01:43,679 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 324 states. [2021-12-16 01:01:43,690 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 324 to 322. [2021-12-16 01:01:43,691 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 322 states, 241 states have (on average 1.2074688796680497) internal successors, (291), 254 states have internal predecessors, (291), 42 states have call successors, (42), 35 states have call predecessors, (42), 38 states have return successors, (68), 43 states have call predecessors, (68), 42 states have call successors, (68) [2021-12-16 01:01:43,692 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 322 states to 322 states and 401 transitions. [2021-12-16 01:01:43,692 INFO L78 Accepts]: Start accepts. Automaton has 322 states and 401 transitions. Word has length 65 [2021-12-16 01:01:43,692 INFO L84 Accepts]: Finished accepts. word is rejected. [2021-12-16 01:01:43,693 INFO L470 AbstractCegarLoop]: Abstraction has 322 states and 401 transitions. [2021-12-16 01:01:43,693 INFO L471 AbstractCegarLoop]: INTERPOLANT automaton has has 5 states, 5 states have (on average 10.4) internal successors, (52), 4 states have internal predecessors, (52), 4 states have call successors, (6), 3 states have call predecessors, (6), 2 states have return successors, (5), 3 states have call predecessors, (5), 4 states have call successors, (5) [2021-12-16 01:01:43,693 INFO L276 IsEmpty]: Start isEmpty. Operand 322 states and 401 transitions. [2021-12-16 01:01:43,693 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 70 [2021-12-16 01:01:43,694 INFO L506 BasicCegarLoop]: Found error trace [2021-12-16 01:01:43,694 INFO L514 BasicCegarLoop]: trace histogram [2, 2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2021-12-16 01:01:43,694 WARN L452 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable7 [2021-12-16 01:01:43,694 INFO L402 AbstractCegarLoop]: === Iteration 9 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2021-12-16 01:01:43,694 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2021-12-16 01:01:43,694 INFO L85 PathProgramCache]: Analyzing trace with hash 843636315, now seen corresponding path program 1 times [2021-12-16 01:01:43,695 INFO L121 FreeRefinementEngine]: Executing refinement strategy CAMEL [2021-12-16 01:01:43,695 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [1206756488] [2021-12-16 01:01:43,695 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2021-12-16 01:01:43,695 INFO L126 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2021-12-16 01:01:43,704 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 01:01:43,754 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 12 [2021-12-16 01:01:43,755 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 01:01:43,758 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 23 [2021-12-16 01:01:43,760 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 01:01:43,766 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 32 [2021-12-16 01:01:43,768 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 01:01:43,787 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 2 [2021-12-16 01:01:43,790 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 01:01:43,798 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 8 [2021-12-16 01:01:43,799 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 01:01:43,802 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 61 [2021-12-16 01:01:43,803 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 01:01:43,805 INFO L134 CoverageAnalysis]: Checked inductivity of 3 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 3 trivial. 0 not checked. [2021-12-16 01:01:43,805 INFO L139 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2021-12-16 01:01:43,805 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [1206756488] [2021-12-16 01:01:43,805 INFO L160 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [1206756488] provided 1 perfect and 0 imperfect interpolant sequences [2021-12-16 01:01:43,805 INFO L186 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2021-12-16 01:01:43,805 INFO L199 FreeRefinementEngine]: Number of different interpolants: perfect sequences [10] imperfect sequences [] total 10 [2021-12-16 01:01:43,805 INFO L115 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [201456200] [2021-12-16 01:01:43,806 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2021-12-16 01:01:43,806 INFO L546 AbstractCegarLoop]: INTERPOLANT automaton has 10 states [2021-12-16 01:01:43,806 INFO L103 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2021-12-16 01:01:43,807 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 10 interpolants. [2021-12-16 01:01:43,807 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=20, Invalid=70, Unknown=0, NotChecked=0, Total=90 [2021-12-16 01:01:43,807 INFO L87 Difference]: Start difference. First operand 322 states and 401 transitions. Second operand has 10 states, 10 states have (on average 5.4) internal successors, (54), 8 states have internal predecessors, (54), 5 states have call successors, (7), 4 states have call predecessors, (7), 3 states have return successors, (6), 4 states have call predecessors, (6), 5 states have call successors, (6) [2021-12-16 01:01:44,463 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2021-12-16 01:01:44,463 INFO L93 Difference]: Finished difference Result 867 states and 1137 transitions. [2021-12-16 01:01:44,464 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 29 states. [2021-12-16 01:01:44,464 INFO L78 Accepts]: Start accepts. Automaton has has 10 states, 10 states have (on average 5.4) internal successors, (54), 8 states have internal predecessors, (54), 5 states have call successors, (7), 4 states have call predecessors, (7), 3 states have return successors, (6), 4 states have call predecessors, (6), 5 states have call successors, (6) Word has length 69 [2021-12-16 01:01:44,464 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2021-12-16 01:01:44,466 INFO L225 Difference]: With dead ends: 867 [2021-12-16 01:01:44,466 INFO L226 Difference]: Without dead ends: 609 [2021-12-16 01:01:44,467 INFO L932 BasicCegarLoop]: 0 DeclaredPredicates, 48 GetRequests, 16 SyntacticMatches, 0 SemanticMatches, 32 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 280 ImplicationChecksByTransitivity, 0.2s TimeCoverageRelationStatistics Valid=258, Invalid=864, Unknown=0, NotChecked=0, Total=1122 [2021-12-16 01:01:44,468 INFO L933 BasicCegarLoop]: 158 mSDtfsCounter, 674 mSDsluCounter, 473 mSDsCounter, 0 mSdLazyCounter, 737 mSolverCounterSat, 275 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.3s Time, 0 mProtectedPredicate, 0 mProtectedAction, 679 SdHoareTripleChecker+Valid, 631 SdHoareTripleChecker+Invalid, 1012 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 275 IncrementalHoareTripleChecker+Valid, 737 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.4s IncrementalHoareTripleChecker+Time [2021-12-16 01:01:44,468 INFO L934 BasicCegarLoop]: SdHoareTripleChecker [679 Valid, 631 Invalid, 1012 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [275 Valid, 737 Invalid, 0 Unknown, 0 Unchecked, 0.4s Time] [2021-12-16 01:01:44,469 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 609 states. [2021-12-16 01:01:44,486 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 609 to 500. [2021-12-16 01:01:44,487 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 500 states, 373 states have (on average 1.198391420911528) internal successors, (447), 396 states have internal predecessors, (447), 66 states have call successors, (66), 50 states have call predecessors, (66), 60 states have return successors, (108), 66 states have call predecessors, (108), 66 states have call successors, (108) [2021-12-16 01:01:44,489 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 500 states to 500 states and 621 transitions. [2021-12-16 01:01:44,489 INFO L78 Accepts]: Start accepts. Automaton has 500 states and 621 transitions. Word has length 69 [2021-12-16 01:01:44,489 INFO L84 Accepts]: Finished accepts. word is rejected. [2021-12-16 01:01:44,489 INFO L470 AbstractCegarLoop]: Abstraction has 500 states and 621 transitions. [2021-12-16 01:01:44,489 INFO L471 AbstractCegarLoop]: INTERPOLANT automaton has has 10 states, 10 states have (on average 5.4) internal successors, (54), 8 states have internal predecessors, (54), 5 states have call successors, (7), 4 states have call predecessors, (7), 3 states have return successors, (6), 4 states have call predecessors, (6), 5 states have call successors, (6) [2021-12-16 01:01:44,489 INFO L276 IsEmpty]: Start isEmpty. Operand 500 states and 621 transitions. [2021-12-16 01:01:44,490 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 124 [2021-12-16 01:01:44,490 INFO L506 BasicCegarLoop]: Found error trace [2021-12-16 01:01:44,490 INFO L514 BasicCegarLoop]: trace histogram [3, 3, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2021-12-16 01:01:44,490 WARN L452 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable8 [2021-12-16 01:01:44,491 INFO L402 AbstractCegarLoop]: === Iteration 10 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2021-12-16 01:01:44,491 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2021-12-16 01:01:44,491 INFO L85 PathProgramCache]: Analyzing trace with hash 2033626689, now seen corresponding path program 1 times [2021-12-16 01:01:44,491 INFO L121 FreeRefinementEngine]: Executing refinement strategy CAMEL [2021-12-16 01:01:44,491 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [1515270678] [2021-12-16 01:01:44,491 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2021-12-16 01:01:44,491 INFO L126 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2021-12-16 01:01:44,503 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 01:01:44,553 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 12 [2021-12-16 01:01:44,554 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 01:01:44,561 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 21 [2021-12-16 01:01:44,564 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 01:01:44,573 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 1 [2021-12-16 01:01:44,573 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 01:01:44,579 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 10 [2021-12-16 01:01:44,581 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 01:01:44,586 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 2 [2021-12-16 01:01:44,588 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 01:01:44,592 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 8 [2021-12-16 01:01:44,593 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 01:01:44,594 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 75 [2021-12-16 01:01:44,595 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 01:01:44,604 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 86 [2021-12-16 01:01:44,605 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 01:01:44,608 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 93 [2021-12-16 01:01:44,609 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 01:01:44,614 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 7 [2021-12-16 01:01:44,615 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 01:01:44,616 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 2 [2021-12-16 01:01:44,616 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 01:01:44,618 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 115 [2021-12-16 01:01:44,618 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 01:01:44,624 INFO L134 CoverageAnalysis]: Checked inductivity of 42 backedges. 18 proven. 11 refuted. 0 times theorem prover too weak. 13 trivial. 0 not checked. [2021-12-16 01:01:44,624 INFO L139 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2021-12-16 01:01:44,624 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [1515270678] [2021-12-16 01:01:44,624 INFO L160 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [1515270678] provided 0 perfect and 1 imperfect interpolant sequences [2021-12-16 01:01:44,624 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleZ3 [165555468] [2021-12-16 01:01:44,624 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2021-12-16 01:01:44,625 INFO L168 SolverBuilder]: Constructing external solver with command: z3 -smt2 -in SMTLIB2_COMPLIANT=true [2021-12-16 01:01:44,625 INFO L189 MonitoredProcess]: No working directory specified, using /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 [2021-12-16 01:01:44,626 INFO L229 MonitoredProcess]: Starting monitored process 2 with /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 -smt2 -in SMTLIB2_COMPLIANT=true (exit command is (exit), workingDir is null) [2021-12-16 01:01:44,656 INFO L327 MonitoredProcess]: [MP /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 -smt2 -in SMTLIB2_COMPLIANT=true (2)] Waiting until timeout for monitored process [2021-12-16 01:01:44,745 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-16 01:01:44,748 INFO L263 TraceCheckSpWp]: Trace formula consists of 541 conjuncts, 8 conjunts are in the unsatisfiable core [2021-12-16 01:01:44,753 INFO L286 TraceCheckSpWp]: Computing forward predicates... [2021-12-16 01:01:45,021 INFO L134 CoverageAnalysis]: Checked inductivity of 42 backedges. 31 proven. 11 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2021-12-16 01:01:45,022 INFO L328 TraceCheckSpWp]: Computing backward predicates... [2021-12-16 01:01:45,298 INFO L134 CoverageAnalysis]: Checked inductivity of 42 backedges. 19 proven. 10 refuted. 0 times theorem prover too weak. 13 trivial. 0 not checked. [2021-12-16 01:01:45,299 INFO L160 FreeRefinementEngine]: IpTcStrategyModuleZ3 [165555468] provided 0 perfect and 2 imperfect interpolant sequences [2021-12-16 01:01:45,299 INFO L186 FreeRefinementEngine]: Found 0 perfect and 3 imperfect interpolant sequences. [2021-12-16 01:01:45,299 INFO L199 FreeRefinementEngine]: Number of different interpolants: perfect sequences [] imperfect sequences [12, 6, 6] total 16 [2021-12-16 01:01:45,299 INFO L115 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [244414872] [2021-12-16 01:01:45,299 INFO L85 oduleStraightlineAll]: Using 3 imperfect interpolants to construct interpolant automaton [2021-12-16 01:01:45,300 INFO L546 AbstractCegarLoop]: INTERPOLANT automaton has 16 states [2021-12-16 01:01:45,300 INFO L103 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2021-12-16 01:01:45,300 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 16 interpolants. [2021-12-16 01:01:45,301 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=38, Invalid=202, Unknown=0, NotChecked=0, Total=240 [2021-12-16 01:01:45,301 INFO L87 Difference]: Start difference. First operand 500 states and 621 transitions. Second operand has 16 states, 16 states have (on average 9.0625) internal successors, (145), 11 states have internal predecessors, (145), 5 states have call successors, (29), 7 states have call predecessors, (29), 6 states have return successors, (23), 7 states have call predecessors, (23), 5 states have call successors, (23) [2021-12-16 01:01:46,076 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2021-12-16 01:01:46,077 INFO L93 Difference]: Finished difference Result 1022 states and 1297 transitions. [2021-12-16 01:01:46,077 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 30 states. [2021-12-16 01:01:46,077 INFO L78 Accepts]: Start accepts. Automaton has has 16 states, 16 states have (on average 9.0625) internal successors, (145), 11 states have internal predecessors, (145), 5 states have call successors, (29), 7 states have call predecessors, (29), 6 states have return successors, (23), 7 states have call predecessors, (23), 5 states have call successors, (23) Word has length 123 [2021-12-16 01:01:46,077 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2021-12-16 01:01:46,078 INFO L225 Difference]: With dead ends: 1022 [2021-12-16 01:01:46,078 INFO L226 Difference]: Without dead ends: 0 [2021-12-16 01:01:46,080 INFO L932 BasicCegarLoop]: 0 DeclaredPredicates, 318 GetRequests, 279 SyntacticMatches, 1 SemanticMatches, 38 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 339 ImplicationChecksByTransitivity, 0.3s TimeCoverageRelationStatistics Valid=279, Invalid=1281, Unknown=0, NotChecked=0, Total=1560 [2021-12-16 01:01:46,080 INFO L933 BasicCegarLoop]: 238 mSDtfsCounter, 436 mSDsluCounter, 1133 mSDsCounter, 0 mSdLazyCounter, 1236 mSolverCounterSat, 189 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.4s Time, 0 mProtectedPredicate, 0 mProtectedAction, 437 SdHoareTripleChecker+Valid, 1371 SdHoareTripleChecker+Invalid, 1425 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 189 IncrementalHoareTripleChecker+Valid, 1236 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.5s IncrementalHoareTripleChecker+Time [2021-12-16 01:01:46,081 INFO L934 BasicCegarLoop]: SdHoareTripleChecker [437 Valid, 1371 Invalid, 1425 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [189 Valid, 1236 Invalid, 0 Unknown, 0 Unchecked, 0.5s Time] [2021-12-16 01:01:46,082 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 0 states. [2021-12-16 01:01:46,082 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 0 to 0. [2021-12-16 01:01:46,082 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 0 states, 0 states have (on average 0.0) internal successors, (0), 0 states have internal predecessors, (0), 0 states have call successors, (0), 0 states have call predecessors, (0), 0 states have return successors, (0), 0 states have call predecessors, (0), 0 states have call successors, (0) [2021-12-16 01:01:46,082 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 0 states to 0 states and 0 transitions. [2021-12-16 01:01:46,083 INFO L78 Accepts]: Start accepts. Automaton has 0 states and 0 transitions. Word has length 123 [2021-12-16 01:01:46,083 INFO L84 Accepts]: Finished accepts. word is rejected. [2021-12-16 01:01:46,083 INFO L470 AbstractCegarLoop]: Abstraction has 0 states and 0 transitions. [2021-12-16 01:01:46,083 INFO L471 AbstractCegarLoop]: INTERPOLANT automaton has has 16 states, 16 states have (on average 9.0625) internal successors, (145), 11 states have internal predecessors, (145), 5 states have call successors, (29), 7 states have call predecessors, (29), 6 states have return successors, (23), 7 states have call predecessors, (23), 5 states have call successors, (23) [2021-12-16 01:01:46,083 INFO L276 IsEmpty]: Start isEmpty. Operand 0 states and 0 transitions. [2021-12-16 01:01:46,084 INFO L282 IsEmpty]: Finished isEmpty. No accepting run. [2021-12-16 01:01:46,085 INFO L764 garLoopResultBuilder]: Registering result SAFE for location timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION (0 of 1 remaining) [2021-12-16 01:01:46,103 INFO L552 MonitoredProcess]: [MP /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 -smt2 -in SMTLIB2_COMPLIANT=true (2)] Ended with exit code 0 [2021-12-16 01:01:46,302 WARN L452 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: 2 /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 -smt2 -in SMTLIB2_COMPLIANT=true,SelfDestructingSolverStorable9 [2021-12-16 01:01:46,304 INFO L343 DoubleDeckerVisitor]: Before removal of dead ends 0 states and 0 transitions. [2021-12-16 01:01:49,391 INFO L854 garLoopResultBuilder]: At program point deactivatePumpENTRY(lines 203 210) the Hoare annotation is: (or (= 0 ~systemActive~0) (not (<= 1 ~switchedOnBeforeTS~0)) (not (<= ~waterLevel~0 2)) (= ~pumpRunning~0 |old(~pumpRunning~0)|) (not (<= 1 |old(~pumpRunning~0)|))) [2021-12-16 01:01:49,392 INFO L858 garLoopResultBuilder]: For program point deactivatePumpEXIT(lines 203 210) no Hoare annotation was computed. [2021-12-16 01:01:49,392 INFO L858 garLoopResultBuilder]: For program point deactivatePumpFINAL(lines 203 210) no Hoare annotation was computed. [2021-12-16 01:01:49,392 INFO L858 garLoopResultBuilder]: For program point processEnvironment__wrappee__baseEXIT(lines 93 99) no Hoare annotation was computed. [2021-12-16 01:01:49,392 INFO L861 garLoopResultBuilder]: At program point processEnvironment__wrappee__baseFINAL(lines 93 99) the Hoare annotation is: true [2021-12-16 01:01:49,392 INFO L854 garLoopResultBuilder]: At program point L141(line 141) the Hoare annotation is: (let ((.cse0 (= 0 ~systemActive~0)) (.cse1 (not (<= ~waterLevel~0 2)))) (and (or .cse0 (not (<= 1 ~switchedOnBeforeTS~0)) .cse1 (= ~pumpRunning~0 |old(~pumpRunning~0)|) (not (<= 1 |old(~pumpRunning~0)|))) (or .cse0 .cse1 (not (= |old(~pumpRunning~0)| 0))))) [2021-12-16 01:01:49,393 INFO L854 garLoopResultBuilder]: At program point L137(line 137) the Hoare annotation is: (let ((.cse0 (= 0 ~systemActive~0)) (.cse1 (not (<= ~waterLevel~0 2)))) (and (or .cse0 (not (<= 1 ~switchedOnBeforeTS~0)) .cse1 (= ~pumpRunning~0 |old(~pumpRunning~0)|) (not (<= 1 |old(~pumpRunning~0)|))) (or .cse0 .cse1 (not (= |old(~pumpRunning~0)| 0))))) [2021-12-16 01:01:49,393 INFO L858 garLoopResultBuilder]: For program point L135(lines 135 143) no Hoare annotation was computed. [2021-12-16 01:01:49,393 INFO L858 garLoopResultBuilder]: For program point L131(lines 131 148) no Hoare annotation was computed. [2021-12-16 01:01:49,393 INFO L854 garLoopResultBuilder]: At program point L899(lines 894 902) the Hoare annotation is: (let ((.cse0 (= 0 ~systemActive~0)) (.cse1 (not (<= ~waterLevel~0 2)))) (and (or .cse0 (not (<= 1 ~switchedOnBeforeTS~0)) .cse1 (= ~pumpRunning~0 |old(~pumpRunning~0)|) (not (<= 1 |old(~pumpRunning~0)|))) (or .cse0 .cse1 (not (= |old(~pumpRunning~0)| 0))))) [2021-12-16 01:01:49,393 INFO L854 garLoopResultBuilder]: At program point L146(line 146) the Hoare annotation is: (let ((.cse0 (= 0 ~systemActive~0)) (.cse1 (not (<= ~waterLevel~0 2)))) (and (or .cse0 (not (<= 1 ~switchedOnBeforeTS~0)) .cse1 (not (<= 1 |old(~pumpRunning~0)|))) (or .cse0 .cse1 (not (= |old(~pumpRunning~0)| 0)) (= ~pumpRunning~0 0)))) [2021-12-16 01:01:49,393 INFO L858 garLoopResultBuilder]: For program point L146-1(lines 127 151) no Hoare annotation was computed. [2021-12-16 01:01:49,393 INFO L854 garLoopResultBuilder]: At program point processEnvironment__wrappee__methaneQueryENTRY(lines 127 151) the Hoare annotation is: (let ((.cse0 (= 0 ~systemActive~0)) (.cse1 (not (<= ~waterLevel~0 2)))) (and (or .cse0 (not (<= 1 ~switchedOnBeforeTS~0)) .cse1 (= ~pumpRunning~0 |old(~pumpRunning~0)|) (not (<= 1 |old(~pumpRunning~0)|))) (or .cse0 .cse1 (not (= |old(~pumpRunning~0)| 0)) (= ~pumpRunning~0 0)))) [2021-12-16 01:01:49,394 INFO L854 garLoopResultBuilder]: At program point L301(lines 286 304) the Hoare annotation is: (let ((.cse0 (= 0 ~systemActive~0)) (.cse1 (not (<= ~waterLevel~0 2)))) (and (or .cse0 (not (<= 1 ~switchedOnBeforeTS~0)) .cse1 (= ~pumpRunning~0 |old(~pumpRunning~0)|) (not (<= 1 |old(~pumpRunning~0)|))) (or .cse0 .cse1 (not (= |old(~pumpRunning~0)| 0))))) [2021-12-16 01:01:49,394 INFO L858 garLoopResultBuilder]: For program point processEnvironment__wrappee__methaneQueryEXIT(lines 127 151) no Hoare annotation was computed. [2021-12-16 01:01:49,394 INFO L858 garLoopResultBuilder]: For program point L295(lines 295 299) no Hoare annotation was computed. [2021-12-16 01:01:49,394 INFO L858 garLoopResultBuilder]: For program point L295-2(lines 295 299) no Hoare annotation was computed. [2021-12-16 01:01:49,394 INFO L858 garLoopResultBuilder]: For program point isPumpRunningEXIT(lines 222 230) no Hoare annotation was computed. [2021-12-16 01:01:49,394 INFO L861 garLoopResultBuilder]: At program point isPumpRunningENTRY(lines 222 230) the Hoare annotation is: true [2021-12-16 01:01:49,394 INFO L858 garLoopResultBuilder]: For program point isPumpRunningFINAL(lines 222 230) no Hoare annotation was computed. [2021-12-16 01:01:49,394 INFO L858 garLoopResultBuilder]: For program point L831-1(lines 827 838) no Hoare annotation was computed. [2021-12-16 01:01:49,395 INFO L861 garLoopResultBuilder]: At program point changeMethaneLevelENTRY(lines 827 838) the Hoare annotation is: true [2021-12-16 01:01:49,395 INFO L858 garLoopResultBuilder]: For program point changeMethaneLevelEXIT(lines 827 838) no Hoare annotation was computed. [2021-12-16 01:01:49,395 INFO L858 garLoopResultBuilder]: For program point cleanupEXIT(lines 905 934) no Hoare annotation was computed. [2021-12-16 01:01:49,395 INFO L858 garLoopResultBuilder]: For program point L926(line 926) no Hoare annotation was computed. [2021-12-16 01:01:49,395 INFO L861 garLoopResultBuilder]: At program point cleanupENTRY(lines 905 934) the Hoare annotation is: true [2021-12-16 01:01:49,395 INFO L858 garLoopResultBuilder]: For program point L919(lines 919 923) no Hoare annotation was computed. [2021-12-16 01:01:49,395 INFO L861 garLoopResultBuilder]: At program point L919-1(lines 919 923) the Hoare annotation is: true [2021-12-16 01:01:49,395 INFO L858 garLoopResultBuilder]: For program point L916(line 916) no Hoare annotation was computed. [2021-12-16 01:01:49,395 INFO L861 garLoopResultBuilder]: At program point L915-2(lines 915 929) the Hoare annotation is: true [2021-12-16 01:01:49,396 INFO L861 garLoopResultBuilder]: At program point L911(line 911) the Hoare annotation is: true [2021-12-16 01:01:49,396 INFO L858 garLoopResultBuilder]: For program point L911-1(line 911) no Hoare annotation was computed. [2021-12-16 01:01:49,396 INFO L861 garLoopResultBuilder]: At program point L930(lines 905 934) the Hoare annotation is: true [2021-12-16 01:01:49,396 INFO L854 garLoopResultBuilder]: At program point L159(line 159) the Hoare annotation is: (let ((.cse2 (<= 1 ~switchedOnBeforeTS~0)) (.cse3 (= ~pumpRunning~0 |old(~pumpRunning~0)|)) (.cse4 (not (<= 1 |old(~pumpRunning~0)|))) (.cse0 (= 0 ~systemActive~0)) (.cse1 (not (<= |old(~waterLevel~0)| 2)))) (and (or (not (<= 2 |old(~waterLevel~0)|)) .cse0 .cse1 (and .cse2 (= ~waterLevel~0 1) .cse3) .cse4) (or .cse0 .cse1 (not (<= 1 |old(~switchedOnBeforeTS~0)|)) (and .cse2 .cse3 (<= ~waterLevel~0 2)) .cse4) (or .cse0 .cse1 (not (= |old(~pumpRunning~0)| 0))))) [2021-12-16 01:01:49,396 INFO L858 garLoopResultBuilder]: For program point L159-1(line 159) no Hoare annotation was computed. [2021-12-16 01:01:49,396 INFO L854 garLoopResultBuilder]: At program point L345(line 345) the Hoare annotation is: (let ((.cse7 (= ~pumpRunning~0 |old(~pumpRunning~0)|)) (.cse5 (<= 1 ~switchedOnBeforeTS~0)) (.cse2 (= ~pumpRunning~0 0)) (.cse8 (not (<= 1 |old(~pumpRunning~0)|))) (.cse4 (not (<= 2 |old(~waterLevel~0)|))) (.cse0 (= 0 ~systemActive~0)) (.cse1 (not (<= |old(~waterLevel~0)| 2))) (.cse3 (not (= |old(~pumpRunning~0)| 0)))) (and (or .cse0 .cse1 (and (= ~waterLevel~0 |old(~waterLevel~0)|) .cse2) .cse3) (let ((.cse6 (= ~waterLevel~0 1))) (or .cse4 .cse0 .cse1 (and .cse5 .cse6 .cse7) (and .cse5 .cse6 .cse2) .cse8)) (let ((.cse9 (<= ~waterLevel~0 2))) (or .cse0 .cse1 (not (<= 1 |old(~switchedOnBeforeTS~0)|)) (and .cse5 .cse7 .cse9) (and .cse5 .cse9 .cse2) .cse8)) (or .cse4 .cse0 .cse1 .cse3))) [2021-12-16 01:01:49,396 INFO L858 garLoopResultBuilder]: For program point L345-1(line 345) no Hoare annotation was computed. [2021-12-16 01:01:49,397 INFO L854 garLoopResultBuilder]: At program point L172(line 172) the Hoare annotation is: (let ((.cse0 (= 0 ~systemActive~0)) (.cse1 (not (<= |old(~waterLevel~0)| 2))) (.cse2 (not (<= 1 |old(~pumpRunning~0)|)))) (and (or .cse0 .cse1 (and (= ~waterLevel~0 |old(~waterLevel~0)|) (= ~pumpRunning~0 0)) (not (= |old(~pumpRunning~0)| 0))) (or (not (<= 2 |old(~waterLevel~0)|)) .cse0 .cse1 .cse2) (or .cse0 .cse1 (not (<= 1 |old(~switchedOnBeforeTS~0)|)) .cse2))) [2021-12-16 01:01:49,397 INFO L854 garLoopResultBuilder]: At program point L172-1(lines 153 177) the Hoare annotation is: (let ((.cse0 (= 0 ~systemActive~0)) (.cse2 (not (<= |old(~waterLevel~0)| 2))) (.cse6 (= ~pumpRunning~0 |old(~pumpRunning~0)|)) (.cse4 (<= 1 ~switchedOnBeforeTS~0)) (.cse3 (= ~pumpRunning~0 0)) (.cse7 (not (<= 1 |old(~pumpRunning~0)|)))) (and (let ((.cse1 (= ~waterLevel~0 |old(~waterLevel~0)|))) (or .cse0 (and .cse1 (<= 1 ~pumpRunning~0) (<= 2 ~waterLevel~0)) .cse2 (and .cse1 .cse3) (not (= |old(~pumpRunning~0)| 0)))) (let ((.cse5 (= ~waterLevel~0 1))) (or (not (<= 2 |old(~waterLevel~0)|)) .cse0 .cse2 (and .cse4 .cse5 .cse6) (and .cse4 .cse5 .cse3) .cse7)) (let ((.cse8 (<= ~waterLevel~0 2))) (or .cse0 .cse2 (not (<= 1 |old(~switchedOnBeforeTS~0)|)) (and .cse4 .cse6 .cse8) (and .cse4 .cse8 .cse3) .cse7)))) [2021-12-16 01:01:49,397 INFO L858 garLoopResultBuilder]: For program point L73(lines 73 79) no Hoare annotation was computed. [2021-12-16 01:01:49,397 INFO L858 garLoopResultBuilder]: For program point L73-2(lines 69 91) no Hoare annotation was computed. [2021-12-16 01:01:49,397 INFO L858 garLoopResultBuilder]: For program point timeShiftFINAL(lines 66 92) no Hoare annotation was computed. [2021-12-16 01:01:49,397 INFO L854 garLoopResultBuilder]: At program point L330(line 330) the Hoare annotation is: (let ((.cse3 (= ~pumpRunning~0 |old(~pumpRunning~0)|)) (.cse5 (not (<= 1 |old(~pumpRunning~0)|))) (.cse0 (= 0 ~systemActive~0)) (.cse1 (not (<= |old(~waterLevel~0)| 2))) (.cse2 (= ~waterLevel~0 |old(~waterLevel~0)|)) (.cse4 (= ~switchedOnBeforeTS~0 |old(~switchedOnBeforeTS~0)|))) (and (or .cse0 .cse1 (not (<= 1 |old(~switchedOnBeforeTS~0)|)) (and .cse2 .cse3 .cse4) .cse5) (or (not (<= 2 |old(~waterLevel~0)|)) .cse0 .cse1 (and .cse3 .cse4 (<= 2 ~waterLevel~0) (<= ~waterLevel~0 2)) .cse5) (or .cse0 .cse1 (and .cse2 .cse4 (= ~pumpRunning~0 0)) (not (= |old(~pumpRunning~0)| 0))))) [2021-12-16 01:01:49,397 INFO L858 garLoopResultBuilder]: For program point L330-1(line 330) no Hoare annotation was computed. [2021-12-16 01:01:49,398 INFO L858 garLoopResultBuilder]: For program point L161(lines 161 169) no Hoare annotation was computed. [2021-12-16 01:01:49,398 INFO L858 garLoopResultBuilder]: For program point L157(lines 157 174) no Hoare annotation was computed. [2021-12-16 01:01:49,398 INFO L858 garLoopResultBuilder]: For program point L347(lines 347 357) no Hoare annotation was computed. [2021-12-16 01:01:49,398 INFO L858 garLoopResultBuilder]: For program point L343(lines 343 360) no Hoare annotation was computed. [2021-12-16 01:01:49,398 INFO L854 garLoopResultBuilder]: At program point L343-1(lines 335 363) the Hoare annotation is: (let ((.cse5 (= 0 ~systemActive~0))) (let ((.cse1 (<= 1 ~switchedOnBeforeTS~0)) (.cse3 (not .cse5)) (.cse4 (= ~pumpRunning~0 0)) (.cse8 (not (<= 1 |old(~pumpRunning~0)|))) (.cse0 (not (<= 2 |old(~waterLevel~0)|))) (.cse6 (not (<= |old(~waterLevel~0)| 2))) (.cse7 (= ~pumpRunning~0 |old(~pumpRunning~0)|)) (.cse10 (not (= |old(~pumpRunning~0)| 0)))) (and (let ((.cse2 (= ~waterLevel~0 1))) (or .cse0 (and .cse1 .cse2 .cse3 .cse4) .cse5 .cse6 (and .cse1 .cse2 .cse7 .cse3) .cse8)) (let ((.cse9 (<= ~waterLevel~0 2))) (or .cse5 .cse6 (not (<= 1 |old(~switchedOnBeforeTS~0)|)) (and .cse1 .cse7 .cse9 .cse3) (and .cse1 .cse9 .cse3 .cse4) .cse8)) (or .cse0 .cse5 .cse6 (and (<= |timeShift_getWaterLevel_#res#1| 2) (<= |timeShift___utac_acc__Specification5_spec__3_~tmp~6#1| 2) (<= 2 |timeShift_getWaterLevel_#res#1|) (< 1 |timeShift___utac_acc__Specification5_spec__3_~tmp~6#1|)) .cse10) (let ((.cse11 (= ~waterLevel~0 |old(~waterLevel~0)|))) (or .cse5 (and .cse11 (<= 1 ~pumpRunning~0) (<= 2 ~waterLevel~0)) .cse6 (and .cse11 .cse7) .cse10))))) [2021-12-16 01:01:49,398 INFO L858 garLoopResultBuilder]: For program point L1008(line 1008) no Hoare annotation was computed. [2021-12-16 01:01:49,398 INFO L854 garLoopResultBuilder]: At program point L876(lines 871 879) the Hoare annotation is: (let ((.cse8 (= ~pumpRunning~0 |old(~pumpRunning~0)|)) (.cse6 (<= 1 ~switchedOnBeforeTS~0)) (.cse3 (= ~pumpRunning~0 0)) (.cse9 (not (<= 1 |old(~pumpRunning~0)|))) (.cse5 (not (<= 2 |old(~waterLevel~0)|))) (.cse0 (= 0 ~systemActive~0)) (.cse2 (not (<= |old(~waterLevel~0)| 2))) (.cse4 (not (= |old(~pumpRunning~0)| 0)))) (and (let ((.cse1 (= ~waterLevel~0 |old(~waterLevel~0)|))) (or .cse0 (and .cse1 (<= 1 ~pumpRunning~0) (<= 2 ~waterLevel~0)) .cse2 (and .cse1 .cse3) .cse4)) (let ((.cse7 (= ~waterLevel~0 1))) (or .cse5 .cse0 .cse2 (and .cse6 .cse7 .cse8) (and .cse6 .cse7 .cse3) .cse9)) (let ((.cse10 (<= ~waterLevel~0 2))) (or .cse0 .cse2 (not (<= 1 |old(~switchedOnBeforeTS~0)|)) (and .cse6 .cse8 .cse10) (and .cse6 .cse10 .cse3) .cse9)) (or .cse5 .cse0 (and (<= |timeShift_getWaterLevel_#res#1| 2) (<= 2 |timeShift_getWaterLevel_#res#1|)) .cse2 .cse4))) [2021-12-16 01:01:49,399 INFO L858 garLoopResultBuilder]: For program point L348(lines 348 354) no Hoare annotation was computed. [2021-12-16 01:01:49,399 INFO L854 garLoopResultBuilder]: At program point L1009(lines 1004 1011) the Hoare annotation is: (let ((.cse0 (= 0 ~systemActive~0)) (.cse1 (not (<= |old(~waterLevel~0)| 2))) (.cse2 (not (<= 1 |old(~pumpRunning~0)|)))) (and (or (not (<= 2 |old(~waterLevel~0)|)) .cse0 .cse1 .cse2) (or .cse0 .cse1 (not (= |old(~pumpRunning~0)| 0))) (or .cse0 .cse1 (not (<= 1 |old(~switchedOnBeforeTS~0)|)) .cse2))) [2021-12-16 01:01:49,399 INFO L854 garLoopResultBuilder]: At program point timeShiftENTRY(lines 66 92) the Hoare annotation is: (let ((.cse3 (= ~pumpRunning~0 |old(~pumpRunning~0)|)) (.cse5 (not (<= 1 |old(~pumpRunning~0)|))) (.cse0 (= 0 ~systemActive~0)) (.cse1 (not (<= |old(~waterLevel~0)| 2))) (.cse2 (= ~waterLevel~0 |old(~waterLevel~0)|)) (.cse4 (= ~switchedOnBeforeTS~0 |old(~switchedOnBeforeTS~0)|))) (and (or .cse0 .cse1 (not (<= 1 |old(~switchedOnBeforeTS~0)|)) (and .cse2 .cse3 .cse4) .cse5) (or (not (<= 2 |old(~waterLevel~0)|)) .cse0 .cse1 (and .cse3 .cse4 (<= 2 ~waterLevel~0) (<= ~waterLevel~0 2)) .cse5) (or .cse0 .cse1 (and .cse2 .cse4 (= ~pumpRunning~0 0)) (not (= |old(~pumpRunning~0)| 0))))) [2021-12-16 01:01:49,399 INFO L858 garLoopResultBuilder]: For program point L80-1(lines 80 86) no Hoare annotation was computed. [2021-12-16 01:01:49,399 INFO L854 garLoopResultBuilder]: At program point L332(lines 325 334) the Hoare annotation is: (let ((.cse2 (= ~waterLevel~0 |old(~waterLevel~0)|)) (.cse0 (= 0 ~systemActive~0)) (.cse1 (not (<= |old(~waterLevel~0)| 2))) (.cse3 (<= 1 ~switchedOnBeforeTS~0)) (.cse4 (= ~pumpRunning~0 |old(~pumpRunning~0)|)) (.cse5 (not (<= 1 |old(~pumpRunning~0)|)))) (and (or .cse0 .cse1 (and .cse2 (= ~pumpRunning~0 0)) (not (= |old(~pumpRunning~0)| 0))) (or .cse0 .cse1 (not (<= 1 |old(~switchedOnBeforeTS~0)|)) (and .cse3 .cse2 .cse4) .cse5) (or (not (<= 2 |old(~waterLevel~0)|)) .cse0 .cse1 (and .cse3 .cse4 (<= 2 ~waterLevel~0) (<= ~waterLevel~0 2)) .cse5))) [2021-12-16 01:01:49,399 INFO L858 garLoopResultBuilder]: For program point timeShiftEXIT(lines 66 92) no Hoare annotation was computed. [2021-12-16 01:01:49,399 INFO L858 garLoopResultBuilder]: For program point timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION(line 1008) no Hoare annotation was computed. [2021-12-16 01:01:49,400 INFO L858 garLoopResultBuilder]: For program point L807(lines 807 811) no Hoare annotation was computed. [2021-12-16 01:01:49,400 INFO L854 garLoopResultBuilder]: At program point L167(line 167) the Hoare annotation is: (let ((.cse2 (<= 1 ~switchedOnBeforeTS~0)) (.cse3 (= ~pumpRunning~0 |old(~pumpRunning~0)|)) (.cse4 (not (<= 1 |old(~pumpRunning~0)|))) (.cse0 (= 0 ~systemActive~0)) (.cse1 (not (<= |old(~waterLevel~0)| 2)))) (and (or (not (<= 2 |old(~waterLevel~0)|)) .cse0 .cse1 (and .cse2 (= ~waterLevel~0 1) .cse3) .cse4) (or .cse0 .cse1 (not (<= 1 |old(~switchedOnBeforeTS~0)|)) (and .cse2 .cse3 (<= ~waterLevel~0 2)) .cse4) (or .cse0 .cse1 (not (= |old(~pumpRunning~0)| 0))))) [2021-12-16 01:01:49,400 INFO L854 garLoopResultBuilder]: At program point L807-2(lines 803 814) the Hoare annotation is: (let ((.cse2 (<= 1 ~switchedOnBeforeTS~0)) (.cse3 (= ~pumpRunning~0 |old(~pumpRunning~0)|)) (.cse4 (not (<= 1 |old(~pumpRunning~0)|))) (.cse0 (= 0 ~systemActive~0)) (.cse1 (not (<= |old(~waterLevel~0)| 2)))) (and (or (not (<= 2 |old(~waterLevel~0)|)) .cse0 .cse1 (and .cse2 (= ~waterLevel~0 1) .cse3) .cse4) (or .cse0 .cse1 (not (<= 1 |old(~switchedOnBeforeTS~0)|)) (and .cse2 .cse3 (<= ~waterLevel~0 2)) .cse4) (or .cse0 .cse1 (not (= |old(~pumpRunning~0)| 0))))) [2021-12-16 01:01:49,400 INFO L854 garLoopResultBuilder]: At program point L163(line 163) the Hoare annotation is: (let ((.cse2 (<= 1 ~switchedOnBeforeTS~0)) (.cse3 (= ~pumpRunning~0 |old(~pumpRunning~0)|)) (.cse4 (not (<= 1 |old(~pumpRunning~0)|))) (.cse0 (= 0 ~systemActive~0)) (.cse1 (not (<= |old(~waterLevel~0)| 2)))) (and (or (not (<= 2 |old(~waterLevel~0)|)) .cse0 .cse1 (and .cse2 (= ~waterLevel~0 1) .cse3) .cse4) (or .cse0 .cse1 (not (<= 1 |old(~switchedOnBeforeTS~0)|)) (and .cse2 .cse3 (<= ~waterLevel~0 2)) .cse4) (or .cse0 .cse1 (not (= |old(~pumpRunning~0)| 0))))) [2021-12-16 01:01:49,400 INFO L854 garLoopResultBuilder]: At program point L1043(lines 1038 1046) the Hoare annotation is: (and (= ~waterLevel~0 1) (= 1 |ULTIMATE.start_valid_product_#res#1|) (not (= 0 ~systemActive~0)) (= ~pumpRunning~0 0)) [2021-12-16 01:01:49,400 INFO L854 garLoopResultBuilder]: At program point L1035(lines 1031 1037) the Hoare annotation is: (and (= ~waterLevel~0 1) (not (= 0 ~systemActive~0)) (= ~pumpRunning~0 0)) [2021-12-16 01:01:49,400 INFO L858 garLoopResultBuilder]: For program point L416(lines 416 420) no Hoare annotation was computed. [2021-12-16 01:01:49,401 INFO L858 garLoopResultBuilder]: For program point L-1(line -1) no Hoare annotation was computed. [2021-12-16 01:01:49,401 INFO L858 garLoopResultBuilder]: For program point L990(lines 990 997) no Hoare annotation was computed. [2021-12-16 01:01:49,401 INFO L854 garLoopResultBuilder]: At program point L416-2(lines 408 421) the Hoare annotation is: (let ((.cse0 (= |ULTIMATE.start_test_~splverifierCounter~0#1| 0)) (.cse1 (= 1 |ULTIMATE.start_main_~tmp~11#1|)) (.cse2 (= 1 |ULTIMATE.start_valid_product_#res#1|)) (.cse5 (<= 1 ~pumpRunning~0)) (.cse3 (<= ~waterLevel~0 2)) (.cse4 (not (= 0 ~systemActive~0)))) (or (and .cse0 .cse1 .cse2 .cse3 .cse4 (= ~pumpRunning~0 0)) (and .cse0 .cse1 .cse2 .cse5 (<= 2 ~waterLevel~0) .cse3 .cse4) (and .cse0 (<= 1 ~switchedOnBeforeTS~0) .cse1 .cse2 .cse5 .cse3 .cse4))) [2021-12-16 01:01:49,401 INFO L858 garLoopResultBuilder]: For program point ULTIMATE.startENTRY(line -1) no Hoare annotation was computed. [2021-12-16 01:01:49,401 INFO L858 garLoopResultBuilder]: For program point ULTIMATE.startFINAL(line -1) no Hoare annotation was computed. [2021-12-16 01:01:49,401 INFO L858 garLoopResultBuilder]: For program point L990-2(lines 990 997) no Hoare annotation was computed. [2021-12-16 01:01:49,401 INFO L858 garLoopResultBuilder]: For program point L379(lines 378 425) no Hoare annotation was computed. [2021-12-16 01:01:49,401 INFO L858 garLoopResultBuilder]: For program point L408(lines 408 421) no Hoare annotation was computed. [2021-12-16 01:01:49,401 INFO L854 garLoopResultBuilder]: At program point L400(line 400) the Hoare annotation is: (let ((.cse0 (= |ULTIMATE.start_test_~splverifierCounter~0#1| 0)) (.cse1 (= 1 |ULTIMATE.start_main_~tmp~11#1|)) (.cse2 (= 1 |ULTIMATE.start_valid_product_#res#1|)) (.cse5 (<= 1 ~pumpRunning~0)) (.cse3 (<= ~waterLevel~0 2)) (.cse4 (not (= 0 ~systemActive~0)))) (or (and .cse0 .cse1 .cse2 .cse3 .cse4 (= ~pumpRunning~0 0)) (and .cse0 .cse1 .cse2 .cse5 (<= 2 ~waterLevel~0) .cse3 .cse4) (and .cse0 (<= 1 ~switchedOnBeforeTS~0) .cse1 .cse2 .cse5 .cse3 .cse4))) [2021-12-16 01:01:49,402 INFO L861 garLoopResultBuilder]: At program point L974(lines 966 976) the Hoare annotation is: true [2021-12-16 01:01:49,402 INFO L861 garLoopResultBuilder]: At program point L429(lines 368 433) the Hoare annotation is: true [2021-12-16 01:01:49,402 INFO L861 garLoopResultBuilder]: At program point L999(lines 980 1002) the Hoare annotation is: true [2021-12-16 01:01:49,402 INFO L854 garLoopResultBuilder]: At program point L1028(lines 1024 1030) the Hoare annotation is: (and (= ~waterLevel~0 1) (not (= 0 ~systemActive~0)) (= ~pumpRunning~0 0)) [2021-12-16 01:01:49,402 INFO L858 garLoopResultBuilder]: For program point L388(lines 388 394) no Hoare annotation was computed. [2021-12-16 01:01:49,402 INFO L858 garLoopResultBuilder]: For program point L388-1(lines 388 394) no Hoare annotation was computed. [2021-12-16 01:01:49,402 INFO L854 garLoopResultBuilder]: At program point L322(lines 317 324) the Hoare annotation is: (and (= ~waterLevel~0 1) (= 1 |ULTIMATE.start_main_~tmp~11#1|) (= 1 |ULTIMATE.start_valid_product_#res#1|) (not (= 0 ~systemActive~0)) (= ~pumpRunning~0 0)) [2021-12-16 01:01:49,402 INFO L858 garLoopResultBuilder]: For program point ULTIMATE.startEXIT(line -1) no Hoare annotation was computed. [2021-12-16 01:01:49,403 INFO L858 garLoopResultBuilder]: For program point L380(lines 380 384) no Hoare annotation was computed. [2021-12-16 01:01:49,403 INFO L854 garLoopResultBuilder]: At program point L310(lines 305 312) the Hoare annotation is: (let ((.cse0 (= |ULTIMATE.start_test_~splverifierCounter~0#1| 0)) (.cse1 (= 1 |ULTIMATE.start_main_~tmp~11#1|)) (.cse2 (= 1 |ULTIMATE.start_valid_product_#res#1|)) (.cse5 (<= 1 ~pumpRunning~0)) (.cse3 (<= ~waterLevel~0 2)) (.cse4 (not (= 0 ~systemActive~0)))) (or (and .cse0 .cse1 .cse2 .cse3 .cse4 (= ~pumpRunning~0 0)) (and .cse0 .cse1 .cse2 .cse5 (<= 2 ~waterLevel~0) .cse3 .cse4) (and .cse0 (<= 1 ~switchedOnBeforeTS~0) .cse1 .cse2 .cse5 .cse3 .cse4))) [2021-12-16 01:01:49,403 INFO L854 garLoopResultBuilder]: At program point L426(lines 377 427) the Hoare annotation is: false [2021-12-16 01:01:49,403 INFO L854 garLoopResultBuilder]: At program point L963(lines 959 965) the Hoare annotation is: (and (= ~waterLevel~0 1) (= 1 |ULTIMATE.start_main_~tmp~11#1|) (= 1 |ULTIMATE.start_valid_product_#res#1|) (not (= 0 ~systemActive~0)) (= ~pumpRunning~0 0)) [2021-12-16 01:01:49,403 INFO L858 garLoopResultBuilder]: For program point L398(lines 398 404) no Hoare annotation was computed. [2021-12-16 01:01:49,403 INFO L858 garLoopResultBuilder]: For program point L398-1(lines 398 404) no Hoare annotation was computed. [2021-12-16 01:01:49,403 INFO L854 garLoopResultBuilder]: At program point L423(lines 378 425) the Hoare annotation is: (let ((.cse0 (= |ULTIMATE.start_test_~splverifierCounter~0#1| 0)) (.cse1 (= 1 |ULTIMATE.start_main_~tmp~11#1|)) (.cse2 (= 1 |ULTIMATE.start_valid_product_#res#1|)) (.cse5 (<= 1 ~pumpRunning~0)) (.cse3 (<= ~waterLevel~0 2)) (.cse4 (not (= 0 ~systemActive~0)))) (or (and .cse0 .cse1 .cse2 .cse3 .cse4 (= ~pumpRunning~0 0)) (and .cse0 .cse1 .cse2 .cse5 (<= 2 ~waterLevel~0) .cse3 .cse4) (and .cse0 (<= 1 ~switchedOnBeforeTS~0) .cse1 .cse2 .cse5 .cse3 .cse4))) [2021-12-16 01:01:49,403 INFO L854 garLoopResultBuilder]: At program point L390(line 390) the Hoare annotation is: (let ((.cse0 (= |ULTIMATE.start_test_~splverifierCounter~0#1| 0)) (.cse1 (= 1 |ULTIMATE.start_main_~tmp~11#1|)) (.cse2 (= 1 |ULTIMATE.start_valid_product_#res#1|)) (.cse5 (<= 1 ~pumpRunning~0)) (.cse3 (<= ~waterLevel~0 2)) (.cse4 (not (= 0 ~systemActive~0)))) (or (and .cse0 .cse1 .cse2 .cse3 .cse4 (= ~pumpRunning~0 0)) (and .cse0 .cse1 .cse2 .cse5 (<= 2 ~waterLevel~0) .cse3 .cse4) (and .cse0 (<= 1 ~switchedOnBeforeTS~0) .cse1 .cse2 .cse5 .cse3 .cse4))) [2021-12-16 01:01:49,404 INFO L854 garLoopResultBuilder]: At program point processEnvironment__wrappee__highWaterSensorENTRY(lines 101 125) the Hoare annotation is: (let ((.cse0 (= 0 ~systemActive~0)) (.cse1 (not (<= ~waterLevel~0 2)))) (and (or .cse0 (not (<= 1 ~switchedOnBeforeTS~0)) .cse1 (= ~pumpRunning~0 |old(~pumpRunning~0)|) (not (<= 1 |old(~pumpRunning~0)|))) (or .cse0 .cse1 (not (= |old(~pumpRunning~0)| 0)) (= ~pumpRunning~0 0)))) [2021-12-16 01:01:49,404 INFO L854 garLoopResultBuilder]: At program point L120(line 120) the Hoare annotation is: (let ((.cse0 (= 0 ~systemActive~0)) (.cse1 (not (<= ~waterLevel~0 2)))) (and (or .cse0 (not (<= 1 ~switchedOnBeforeTS~0)) .cse1 (= ~pumpRunning~0 |old(~pumpRunning~0)|) (not (<= 1 |old(~pumpRunning~0)|))) (or .cse0 .cse1 (not (= |old(~pumpRunning~0)| 0))))) [2021-12-16 01:01:49,404 INFO L858 garLoopResultBuilder]: For program point L120-1(lines 101 125) no Hoare annotation was computed. [2021-12-16 01:01:49,404 INFO L858 garLoopResultBuilder]: For program point L884(lines 884 890) no Hoare annotation was computed. [2021-12-16 01:01:49,404 INFO L858 garLoopResultBuilder]: For program point L193(lines 193 199) no Hoare annotation was computed. [2021-12-16 01:01:49,404 INFO L854 garLoopResultBuilder]: At program point L191(line 191) the Hoare annotation is: (let ((.cse0 (= 0 ~systemActive~0)) (.cse1 (not (<= ~waterLevel~0 2)))) (and (or .cse0 (not (<= 1 ~switchedOnBeforeTS~0)) .cse1 (not (<= 1 |old(~pumpRunning~0)|))) (or (and (<= 2 ~waterLevel~0) (= ~pumpRunning~0 0)) .cse0 .cse1 (not (= |old(~pumpRunning~0)| 0))))) [2021-12-16 01:01:49,404 INFO L854 garLoopResultBuilder]: At program point L193-2(lines 186 202) the Hoare annotation is: (let ((.cse0 (= 0 ~systemActive~0)) (.cse1 (not (<= ~waterLevel~0 2)))) (and (or .cse0 (not (<= 1 ~switchedOnBeforeTS~0)) .cse1 (not (<= 1 |old(~pumpRunning~0)|))) (let ((.cse2 (<= 2 ~waterLevel~0))) (or (and .cse2 (= ~pumpRunning~0 0)) .cse0 (and (<= 1 ~pumpRunning~0) .cse2) .cse1 (not (= |old(~pumpRunning~0)| 0)))))) [2021-12-16 01:01:49,404 INFO L858 garLoopResultBuilder]: For program point L191-1(line 191) no Hoare annotation was computed. [2021-12-16 01:01:49,405 INFO L858 garLoopResultBuilder]: For program point processEnvironment__wrappee__highWaterSensorEXIT(lines 101 125) no Hoare annotation was computed. [2021-12-16 01:01:49,405 INFO L854 garLoopResultBuilder]: At program point L282(lines 267 285) the Hoare annotation is: (let ((.cse0 (= 0 ~systemActive~0)) (.cse1 (not (<= ~waterLevel~0 2)))) (and (or .cse0 (not (<= 1 ~switchedOnBeforeTS~0)) .cse1 (not (<= 1 |old(~pumpRunning~0)|))) (let ((.cse2 (= ~pumpRunning~0 0))) (or (and (<= 2 ~waterLevel~0) .cse2) .cse0 (and (= |processEnvironment__wrappee__highWaterSensor_isHighWaterLevel_~tmp___0~0#1| 0) (= |processEnvironment__wrappee__highWaterSensor_isHighWaterLevel_#res#1| 0) .cse2) .cse1 (not (= |old(~pumpRunning~0)| 0)))))) [2021-12-16 01:01:49,407 INFO L854 garLoopResultBuilder]: At program point L889(lines 880 893) the Hoare annotation is: (let ((.cse0 (= 0 ~systemActive~0)) (.cse1 (not (<= ~waterLevel~0 2)))) (and (or .cse0 (not (<= 1 ~switchedOnBeforeTS~0)) .cse1 (not (<= 1 |old(~pumpRunning~0)|))) (let ((.cse2 (= ~pumpRunning~0 0))) (or (and (<= 2 ~waterLevel~0) .cse2) .cse0 (and (<= 1 |processEnvironment__wrappee__highWaterSensor_isHighWaterSensorDry_#res#1|) .cse2) .cse1 (not (= |old(~pumpRunning~0)| 0)))))) [2021-12-16 01:01:49,407 INFO L854 garLoopResultBuilder]: At program point L183(lines 178 185) the Hoare annotation is: (let ((.cse0 (= 0 ~systemActive~0)) (.cse1 (not (<= ~waterLevel~0 2)))) (and (or .cse0 (not (<= 1 ~switchedOnBeforeTS~0)) .cse1 (not (<= 1 |old(~pumpRunning~0)|))) (or .cse0 (and (<= 1 ~pumpRunning~0) (<= 2 ~waterLevel~0)) .cse1 (not (= |old(~pumpRunning~0)| 0))))) [2021-12-16 01:01:49,407 INFO L858 garLoopResultBuilder]: For program point L276(lines 276 280) no Hoare annotation was computed. [2021-12-16 01:01:49,407 INFO L854 garLoopResultBuilder]: At program point L115(line 115) the Hoare annotation is: (let ((.cse0 (= 0 ~systemActive~0)) (.cse1 (not (<= ~waterLevel~0 2)))) (and (or .cse0 (and (= |processEnvironment__wrappee__highWaterSensor_~tmp~0#1| 0) (= ~pumpRunning~0 0)) .cse1 (not (= |old(~pumpRunning~0)| 0))) (or .cse0 (not (<= 1 ~switchedOnBeforeTS~0)) .cse1 (not (<= 1 |old(~pumpRunning~0)|))))) [2021-12-16 01:01:49,407 INFO L858 garLoopResultBuilder]: For program point L276-2(lines 276 280) no Hoare annotation was computed. [2021-12-16 01:01:49,408 INFO L858 garLoopResultBuilder]: For program point L109(lines 109 117) no Hoare annotation was computed. [2021-12-16 01:01:49,408 INFO L858 garLoopResultBuilder]: For program point L105(lines 105 122) no Hoare annotation was computed. [2021-12-16 01:01:49,408 INFO L858 garLoopResultBuilder]: For program point waterRiseEXIT(lines 815 826) no Hoare annotation was computed. [2021-12-16 01:01:49,408 INFO L854 garLoopResultBuilder]: At program point waterRiseENTRY(lines 815 826) the Hoare annotation is: (let ((.cse2 (not (<= 1 ~pumpRunning~0))) (.cse0 (= 0 ~systemActive~0)) (.cse1 (not (<= |old(~waterLevel~0)| 2))) (.cse3 (= ~waterLevel~0 |old(~waterLevel~0)|))) (and (or (not (<= 2 |old(~waterLevel~0)|)) .cse0 .cse1 (and (<= 2 ~waterLevel~0) (<= ~waterLevel~0 2)) .cse2) (or .cse0 (not (<= 1 ~switchedOnBeforeTS~0)) .cse1 .cse2 .cse3) (or .cse0 .cse1 (not (= ~pumpRunning~0 0)) .cse3))) [2021-12-16 01:01:49,408 INFO L858 garLoopResultBuilder]: For program point L819-1(lines 815 826) no Hoare annotation was computed. [2021-12-16 01:01:49,408 INFO L861 garLoopResultBuilder]: At program point isMethaneAlarmENTRY(lines 211 221) the Hoare annotation is: true [2021-12-16 01:01:49,408 INFO L861 garLoopResultBuilder]: At program point L844(lines 839 847) the Hoare annotation is: true [2021-12-16 01:01:49,408 INFO L858 garLoopResultBuilder]: For program point isMethaneAlarmEXIT(lines 211 221) no Hoare annotation was computed. [2021-12-16 01:01:49,409 INFO L858 garLoopResultBuilder]: For program point isMethaneAlarmFINAL(lines 211 221) no Hoare annotation was computed. [2021-12-16 01:01:49,411 INFO L732 BasicCegarLoop]: Path program histogram: [1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2021-12-16 01:01:49,412 INFO L179 ceAbstractionStarter]: Computing trace abstraction results [2021-12-16 01:01:49,442 INFO L202 PluginConnector]: Adding new model de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction CFG 16.12 01:01:49 BoogieIcfgContainer [2021-12-16 01:01:49,447 INFO L132 PluginConnector]: ------------------------ END TraceAbstraction---------------------------- [2021-12-16 01:01:49,447 INFO L113 PluginConnector]: ------------------------Witness Printer---------------------------- [2021-12-16 01:01:49,447 INFO L271 PluginConnector]: Initializing Witness Printer... [2021-12-16 01:01:49,448 INFO L275 PluginConnector]: Witness Printer initialized [2021-12-16 01:01:49,448 INFO L185 PluginConnector]: Executing the observer RCFGCatcher from plugin Witness Printer for "de.uni_freiburg.informatik.ultimate.plugins.generator.rcfgbuilder CFG 16.12 01:01:41" (3/4) ... [2021-12-16 01:01:49,450 INFO L137 WitnessPrinter]: Generating witness for correct program [2021-12-16 01:01:49,454 INFO L354 RCFGBacktranslator]: Ignoring RootEdge to procedure deactivatePump [2021-12-16 01:01:49,454 INFO L354 RCFGBacktranslator]: Ignoring RootEdge to procedure processEnvironment__wrappee__base [2021-12-16 01:01:49,454 INFO L354 RCFGBacktranslator]: Ignoring RootEdge to procedure changeMethaneLevel [2021-12-16 01:01:49,454 INFO L354 RCFGBacktranslator]: Ignoring RootEdge to procedure cleanup [2021-12-16 01:01:49,454 INFO L354 RCFGBacktranslator]: Ignoring RootEdge to procedure timeShift [2021-12-16 01:01:49,454 INFO L354 RCFGBacktranslator]: Ignoring RootEdge to procedure processEnvironment__wrappee__highWaterSensor [2021-12-16 01:01:49,455 INFO L354 RCFGBacktranslator]: Ignoring RootEdge to procedure waterRise [2021-12-16 01:01:49,455 INFO L354 RCFGBacktranslator]: Ignoring RootEdge to procedure processEnvironment__wrappee__methaneQuery [2021-12-16 01:01:49,455 INFO L354 RCFGBacktranslator]: Ignoring RootEdge to procedure isPumpRunning [2021-12-16 01:01:49,455 INFO L354 RCFGBacktranslator]: Ignoring RootEdge to procedure isMethaneAlarm [2021-12-16 01:01:49,467 INFO L910 BoogieBacktranslator]: Reduced CFG by removing 53 nodes and edges [2021-12-16 01:01:49,467 INFO L910 BoogieBacktranslator]: Reduced CFG by removing 22 nodes and edges [2021-12-16 01:01:49,468 INFO L910 BoogieBacktranslator]: Reduced CFG by removing 11 nodes and edges [2021-12-16 01:01:49,468 INFO L910 BoogieBacktranslator]: Reduced CFG by removing 5 nodes and edges [2021-12-16 01:01:49,468 INFO L910 BoogieBacktranslator]: Reduced CFG by removing 2 nodes and edges [2021-12-16 01:01:49,468 INFO L910 BoogieBacktranslator]: Reduced CFG by removing 1 nodes and edges [2021-12-16 01:01:49,469 INFO L910 BoogieBacktranslator]: Reduced CFG by removing 1 nodes and edges [2021-12-16 01:01:49,483 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: ((waterLevel == 1 && 1 == \result) && !(0 == systemActive)) && pumpRunning == 0 [2021-12-16 01:01:49,483 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (((waterLevel == 1 && 1 == tmp) && 1 == \result) && !(0 == systemActive)) && pumpRunning == 0 [2021-12-16 01:01:49,483 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (((waterLevel == 1 && 1 == tmp) && 1 == \result) && !(0 == systemActive)) && pumpRunning == 0 [2021-12-16 01:01:49,484 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: ((((((splverifierCounter == 0 && 1 == tmp) && 1 == \result) && waterLevel <= 2) && !(0 == systemActive)) && pumpRunning == 0) || ((((((splverifierCounter == 0 && 1 == tmp) && 1 == \result) && 1 <= pumpRunning) && 2 <= waterLevel) && waterLevel <= 2) && !(0 == systemActive))) || ((((((splverifierCounter == 0 && 1 <= switchedOnBeforeTS) && 1 == tmp) && 1 == \result) && 1 <= pumpRunning) && waterLevel <= 2) && !(0 == systemActive)) [2021-12-16 01:01:49,485 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: ((((0 == systemActive || !(\old(waterLevel) <= 2)) || (waterLevel == \old(waterLevel) && pumpRunning == 0)) || !(\old(pumpRunning) == 0)) && ((((0 == systemActive || !(\old(waterLevel) <= 2)) || !(1 <= \old(switchedOnBeforeTS))) || ((1 <= switchedOnBeforeTS && waterLevel == \old(waterLevel)) && pumpRunning == \old(pumpRunning))) || !(1 <= \old(pumpRunning)))) && ((((!(2 <= \old(waterLevel)) || 0 == systemActive) || !(\old(waterLevel) <= 2)) || (((1 <= switchedOnBeforeTS && pumpRunning == \old(pumpRunning)) && 2 <= waterLevel) && waterLevel <= 2)) || !(1 <= \old(pumpRunning))) [2021-12-16 01:01:49,485 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (((((!(2 <= \old(waterLevel)) || 0 == systemActive) || !(\old(waterLevel) <= 2)) || ((1 <= switchedOnBeforeTS && waterLevel == 1) && pumpRunning == \old(pumpRunning))) || !(1 <= \old(pumpRunning))) && ((((0 == systemActive || !(\old(waterLevel) <= 2)) || !(1 <= \old(switchedOnBeforeTS))) || ((1 <= switchedOnBeforeTS && pumpRunning == \old(pumpRunning)) && waterLevel <= 2)) || !(1 <= \old(pumpRunning)))) && ((0 == systemActive || !(\old(waterLevel) <= 2)) || !(\old(pumpRunning) == 0)) [2021-12-16 01:01:49,486 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: ((((((splverifierCounter == 0 && 1 == tmp) && 1 == \result) && waterLevel <= 2) && !(0 == systemActive)) && pumpRunning == 0) || ((((((splverifierCounter == 0 && 1 == tmp) && 1 == \result) && 1 <= pumpRunning) && 2 <= waterLevel) && waterLevel <= 2) && !(0 == systemActive))) || ((((((splverifierCounter == 0 && 1 <= switchedOnBeforeTS) && 1 == tmp) && 1 == \result) && 1 <= pumpRunning) && waterLevel <= 2) && !(0 == systemActive)) [2021-12-16 01:01:49,486 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (((((((!(2 <= \old(waterLevel)) || (((1 <= switchedOnBeforeTS && waterLevel == 1) && !(0 == systemActive)) && pumpRunning == 0)) || 0 == systemActive) || !(\old(waterLevel) <= 2)) || (((1 <= switchedOnBeforeTS && waterLevel == 1) && pumpRunning == \old(pumpRunning)) && !(0 == systemActive))) || !(1 <= \old(pumpRunning))) && (((((0 == systemActive || !(\old(waterLevel) <= 2)) || !(1 <= \old(switchedOnBeforeTS))) || (((1 <= switchedOnBeforeTS && pumpRunning == \old(pumpRunning)) && waterLevel <= 2) && !(0 == systemActive))) || (((1 <= switchedOnBeforeTS && waterLevel <= 2) && !(0 == systemActive)) && pumpRunning == 0)) || !(1 <= \old(pumpRunning)))) && ((((!(2 <= \old(waterLevel)) || 0 == systemActive) || !(\old(waterLevel) <= 2)) || (((\result <= 2 && tmp <= 2) && 2 <= \result) && 1 < tmp)) || !(\old(pumpRunning) == 0))) && ((((0 == systemActive || ((waterLevel == \old(waterLevel) && 1 <= pumpRunning) && 2 <= waterLevel)) || !(\old(waterLevel) <= 2)) || (waterLevel == \old(waterLevel) && pumpRunning == \old(pumpRunning))) || !(\old(pumpRunning) == 0)) [2021-12-16 01:01:49,487 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (((((0 == systemActive || ((waterLevel == \old(waterLevel) && 1 <= pumpRunning) && 2 <= waterLevel)) || !(\old(waterLevel) <= 2)) || (waterLevel == \old(waterLevel) && pumpRunning == 0)) || !(\old(pumpRunning) == 0)) && (((((!(2 <= \old(waterLevel)) || 0 == systemActive) || !(\old(waterLevel) <= 2)) || ((1 <= switchedOnBeforeTS && waterLevel == 1) && pumpRunning == \old(pumpRunning))) || ((1 <= switchedOnBeforeTS && waterLevel == 1) && pumpRunning == 0)) || !(1 <= \old(pumpRunning)))) && (((((0 == systemActive || !(\old(waterLevel) <= 2)) || !(1 <= \old(switchedOnBeforeTS))) || ((1 <= switchedOnBeforeTS && pumpRunning == \old(pumpRunning)) && waterLevel <= 2)) || ((1 <= switchedOnBeforeTS && waterLevel <= 2) && pumpRunning == 0)) || !(1 <= \old(pumpRunning))) [2021-12-16 01:01:49,487 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: ((((!(2 <= \old(waterLevel)) || 0 == systemActive) || !(\old(waterLevel) <= 2)) || !(1 <= \old(pumpRunning))) && ((0 == systemActive || !(\old(waterLevel) <= 2)) || !(\old(pumpRunning) == 0))) && (((0 == systemActive || !(\old(waterLevel) <= 2)) || !(1 <= \old(switchedOnBeforeTS))) || !(1 <= \old(pumpRunning))) [2021-12-16 01:01:49,487 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: ((((((0 == systemActive || ((waterLevel == \old(waterLevel) && 1 <= pumpRunning) && 2 <= waterLevel)) || !(\old(waterLevel) <= 2)) || (waterLevel == \old(waterLevel) && pumpRunning == 0)) || !(\old(pumpRunning) == 0)) && (((((!(2 <= \old(waterLevel)) || 0 == systemActive) || !(\old(waterLevel) <= 2)) || ((1 <= switchedOnBeforeTS && waterLevel == 1) && pumpRunning == \old(pumpRunning))) || ((1 <= switchedOnBeforeTS && waterLevel == 1) && pumpRunning == 0)) || !(1 <= \old(pumpRunning)))) && (((((0 == systemActive || !(\old(waterLevel) <= 2)) || !(1 <= \old(switchedOnBeforeTS))) || ((1 <= switchedOnBeforeTS && pumpRunning == \old(pumpRunning)) && waterLevel <= 2)) || ((1 <= switchedOnBeforeTS && waterLevel <= 2) && pumpRunning == 0)) || !(1 <= \old(pumpRunning)))) && ((((!(2 <= \old(waterLevel)) || 0 == systemActive) || (\result <= 2 && 2 <= \result)) || !(\old(waterLevel) <= 2)) || !(\old(pumpRunning) == 0)) [2021-12-16 01:01:49,488 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: ((((0 == systemActive || !(1 <= switchedOnBeforeTS)) || !(waterLevel <= 2)) || pumpRunning == \old(pumpRunning)) || !(1 <= \old(pumpRunning))) && ((0 == systemActive || !(waterLevel <= 2)) || !(\old(pumpRunning) == 0)) [2021-12-16 01:01:49,488 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (((0 == systemActive || !(1 <= switchedOnBeforeTS)) || !(waterLevel <= 2)) || !(1 <= \old(pumpRunning))) && (((((2 <= waterLevel && pumpRunning == 0) || 0 == systemActive) || (1 <= pumpRunning && 2 <= waterLevel)) || !(waterLevel <= 2)) || !(\old(pumpRunning) == 0)) [2021-12-16 01:01:49,488 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (((0 == systemActive || !(1 <= switchedOnBeforeTS)) || !(waterLevel <= 2)) || !(1 <= \old(pumpRunning))) && (((((2 <= waterLevel && pumpRunning == 0) || 0 == systemActive) || (1 <= \result && pumpRunning == 0)) || !(waterLevel <= 2)) || !(\old(pumpRunning) == 0)) [2021-12-16 01:01:49,490 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (((0 == systemActive || !(1 <= switchedOnBeforeTS)) || !(waterLevel <= 2)) || !(1 <= \old(pumpRunning))) && (((0 == systemActive || (1 <= pumpRunning && 2 <= waterLevel)) || !(waterLevel <= 2)) || !(\old(pumpRunning) == 0)) [2021-12-16 01:01:49,490 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: ((((0 == systemActive || !(1 <= switchedOnBeforeTS)) || !(waterLevel <= 2)) || pumpRunning == \old(pumpRunning)) || !(1 <= \old(pumpRunning))) && ((0 == systemActive || !(waterLevel <= 2)) || !(\old(pumpRunning) == 0)) [2021-12-16 01:01:49,491 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (((0 == systemActive || !(1 <= switchedOnBeforeTS)) || !(waterLevel <= 2)) || !(1 <= \old(pumpRunning))) && (((((2 <= waterLevel && pumpRunning == 0) || 0 == systemActive) || ((tmp___0 == 0 && \result == 0) && pumpRunning == 0)) || !(waterLevel <= 2)) || !(\old(pumpRunning) == 0)) [2021-12-16 01:01:49,519 INFO L141 WitnessManager]: Wrote witness to /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/witness.graphml [2021-12-16 01:01:49,519 INFO L132 PluginConnector]: ------------------------ END Witness Printer---------------------------- [2021-12-16 01:01:49,520 INFO L158 Benchmark]: Toolchain (without parser) took 8484.58ms. Allocated memory was 98.6MB in the beginning and 148.9MB in the end (delta: 50.3MB). Free memory was 66.2MB in the beginning and 49.3MB in the end (delta: 16.9MB). Peak memory consumption was 68.2MB. Max. memory is 16.1GB. [2021-12-16 01:01:49,520 INFO L158 Benchmark]: CDTParser took 0.21ms. Allocated memory is still 75.5MB. Free memory was 45.7MB in the beginning and 45.7MB in the end (delta: 18.4kB). There was no memory consumed. Max. memory is 16.1GB. [2021-12-16 01:01:49,520 INFO L158 Benchmark]: CACSL2BoogieTranslator took 333.62ms. Allocated memory is still 98.6MB. Free memory was 65.9MB in the beginning and 65.9MB in the end (delta: -48.2kB). Peak memory consumption was 8.4MB. Max. memory is 16.1GB. [2021-12-16 01:01:49,520 INFO L158 Benchmark]: Boogie Procedure Inliner took 53.91ms. Allocated memory is still 98.6MB. Free memory was 65.9MB in the beginning and 63.2MB in the end (delta: 2.7MB). Peak memory consumption was 2.1MB. Max. memory is 16.1GB. [2021-12-16 01:01:49,520 INFO L158 Benchmark]: Boogie Preprocessor took 47.02ms. Allocated memory is still 98.6MB. Free memory was 63.2MB in the beginning and 61.7MB in the end (delta: 1.5MB). Peak memory consumption was 2.1MB. Max. memory is 16.1GB. [2021-12-16 01:01:49,521 INFO L158 Benchmark]: RCFGBuilder took 381.28ms. Allocated memory is still 98.6MB. Free memory was 61.1MB in the beginning and 43.8MB in the end (delta: 17.3MB). Peak memory consumption was 16.8MB. Max. memory is 16.1GB. [2021-12-16 01:01:49,521 INFO L158 Benchmark]: TraceAbstraction took 7592.33ms. Allocated memory was 98.6MB in the beginning and 148.9MB in the end (delta: 50.3MB). Free memory was 43.4MB in the beginning and 56.7MB in the end (delta: -13.3MB). Peak memory consumption was 60.4MB. Max. memory is 16.1GB. [2021-12-16 01:01:49,521 INFO L158 Benchmark]: Witness Printer took 71.85ms. Allocated memory is still 148.9MB. Free memory was 56.7MB in the beginning and 49.3MB in the end (delta: 7.3MB). Peak memory consumption was 8.4MB. Max. memory is 16.1GB. [2021-12-16 01:01:49,522 INFO L339 ainManager$Toolchain]: ####################### End [Toolchain 1] ####################### --- Results --- * Results from de.uni_freiburg.informatik.ultimate.core: - StatisticsResult: Toolchain Benchmarks Benchmark results are: * CDTParser took 0.21ms. Allocated memory is still 75.5MB. Free memory was 45.7MB in the beginning and 45.7MB in the end (delta: 18.4kB). There was no memory consumed. Max. memory is 16.1GB. * CACSL2BoogieTranslator took 333.62ms. Allocated memory is still 98.6MB. Free memory was 65.9MB in the beginning and 65.9MB in the end (delta: -48.2kB). Peak memory consumption was 8.4MB. Max. memory is 16.1GB. * Boogie Procedure Inliner took 53.91ms. Allocated memory is still 98.6MB. Free memory was 65.9MB in the beginning and 63.2MB in the end (delta: 2.7MB). Peak memory consumption was 2.1MB. Max. memory is 16.1GB. * Boogie Preprocessor took 47.02ms. Allocated memory is still 98.6MB. Free memory was 63.2MB in the beginning and 61.7MB in the end (delta: 1.5MB). Peak memory consumption was 2.1MB. Max. memory is 16.1GB. * RCFGBuilder took 381.28ms. Allocated memory is still 98.6MB. Free memory was 61.1MB in the beginning and 43.8MB in the end (delta: 17.3MB). Peak memory consumption was 16.8MB. Max. memory is 16.1GB. * TraceAbstraction took 7592.33ms. Allocated memory was 98.6MB in the beginning and 148.9MB in the end (delta: 50.3MB). Free memory was 43.4MB in the beginning and 56.7MB in the end (delta: -13.3MB). Peak memory consumption was 60.4MB. Max. memory is 16.1GB. * Witness Printer took 71.85ms. Allocated memory is still 148.9MB. Free memory was 56.7MB in the beginning and 49.3MB in the end (delta: 7.3MB). Peak memory consumption was 8.4MB. Max. memory is 16.1GB. * Results from de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction: - StatisticsResult: ErrorAutomatonStatistics NumberErrorTraces: 0, NumberStatementsAllTraces: 0, NumberRelevantStatements: 0, 0.0s ErrorAutomatonConstructionTimeTotal, 0.0s FaulLocalizationTime, NumberStatementsFirstTrace: -1, TraceLengthAvg: 0, 0.0s ErrorAutomatonConstructionTimeAvg, 0.0s ErrorAutomatonDifferenceTimeAvg, 0.0s ErrorAutomatonDifferenceTimeTotal, NumberOfNoEnhancement: 0, NumberOfFiniteEnhancement: 0, NumberOfInfiniteEnhancement: 0 - PositiveResult [Line: 1008]: call to reach_error is unreachable For all program executions holds that call to reach_error is unreachable at this location - StatisticsResult: Ultimate Automizer benchmark data CFG has 11 procedures, 114 locations, 1 error locations. Started 1 CEGAR loops. OverallTime: 7.5s, OverallIterations: 10, TraceHistogramMax: 3, PathProgramHistogramMax: 1, EmptinessCheckTime: 0.0s, AutomataDifference: 2.4s, DeadEndRemovalTime: 0.0s, HoareAnnotationTime: 3.1s, InitialAbstractionConstructionTime: 0.0s, PartialOrderReductionTime: 0.0s, HoareTripleCheckerStatistics: 0 mSolverCounterUnknown, 2031 SdHoareTripleChecker+Valid, 1.5s IncrementalHoareTripleChecker+Time, 0 mSdLazyCounter, 1989 mSDsluCounter, 4587 SdHoareTripleChecker+Invalid, 1.2s Time, 0 mProtectedAction, 0 SdHoareTripleChecker+Unchecked, 0 IncrementalHoareTripleChecker+Unchecked, 3202 mSDsCounter, 698 IncrementalHoareTripleChecker+Valid, 0 mProtectedPredicate, 2733 IncrementalHoareTripleChecker+Invalid, 3431 SdHoareTripleChecker+Unknown, 0 mSolverCounterNotChecked, 698 mSolverCounterUnsat, 1385 mSDtfsCounter, 2733 mSolverCounterSat, 0.0s SdHoareTripleChecker+Time, 0 IncrementalHoareTripleChecker+Unknown, PredicateUnifierStatistics: 0 DeclaredPredicates, 491 GetRequests, 379 SyntacticMatches, 2 SemanticMatches, 110 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 648 ImplicationChecksByTransitivity, 0.6s Time, 0.0s BasicInterpolantAutomatonTime, BiggestAbstraction: size=500occurred in iteration=9, InterpolantAutomatonStates: 106, traceCheckStatistics: No data available, InterpolantConsolidationStatistics: No data available, PathInvariantsStatistics: No data available, 0/0 InterpolantCoveringCapability, TotalInterpolationStatistics: No data available, 0.0s DumpTime, AutomataMinimizationStatistics: 0.1s AutomataMinimizationTime, 10 MinimizatonAttempts, 146 StatesRemovedByMinimization, 6 NontrivialMinimizations, HoareAnnotationStatistics: 0.0s HoareAnnotationTime, 53 LocationsWithAnnotation, 1198 PreInvPairs, 1399 NumberOfFragments, 2068 HoareAnnotationTreeSize, 1198 FomulaSimplifications, 701 FormulaSimplificationTreeSizeReduction, 0.2s HoareSimplificationTime, 53 FomulaSimplificationsInter, 9253 FormulaSimplificationTreeSizeReductionInter, 2.8s HoareSimplificationTimeInter, RefinementEngineStatistics: TRACE_CHECK: 0.0s SsaConstructionTime, 0.2s SatisfiabilityAnalysisTime, 1.3s InterpolantComputationTime, 723 NumberOfCodeBlocks, 723 NumberOfCodeBlocksAsserted, 11 NumberOfCheckSat, 834 ConstructedInterpolants, 0 QuantifiedInterpolants, 1620 SizeOfPredicates, 3 NumberOfNonLiveVariables, 541 ConjunctsInSsa, 8 ConjunctsInUnsatCore, 12 InterpolantComputations, 9 PerfectInterpolantSequences, 121/153 InterpolantCoveringCapability, INVARIANT_SYNTHESIS: No data available, INTERPOLANT_CONSOLIDATION: No data available, ABSTRACT_INTERPRETATION: No data available, PDR: No data available, ACCELERATED_INTERPOLATION: No data available, SIFA: No data available, ReuseStatistics: No data available - AllSpecificationsHoldResult: All specifications hold 1 specifications checked. All of them hold - InvariantResult [Line: 1031]: Loop Invariant Derived loop invariant: (waterLevel == 1 && !(0 == systemActive)) && pumpRunning == 0 - InvariantResult [Line: 305]: Loop Invariant Derived loop invariant: ((((((splverifierCounter == 0 && 1 == tmp) && 1 == \result) && waterLevel <= 2) && !(0 == systemActive)) && pumpRunning == 0) || ((((((splverifierCounter == 0 && 1 == tmp) && 1 == \result) && 1 <= pumpRunning) && 2 <= waterLevel) && waterLevel <= 2) && !(0 == systemActive))) || ((((((splverifierCounter == 0 && 1 <= switchedOnBeforeTS) && 1 == tmp) && 1 == \result) && 1 <= pumpRunning) && waterLevel <= 2) && !(0 == systemActive)) - InvariantResult [Line: 915]: Loop Invariant Derived loop invariant: 1 - InvariantResult [Line: 905]: Loop Invariant Derived loop invariant: 1 - InvariantResult [Line: 803]: Loop Invariant Derived loop invariant: (((((!(2 <= \old(waterLevel)) || 0 == systemActive) || !(\old(waterLevel) <= 2)) || ((1 <= switchedOnBeforeTS && waterLevel == 1) && pumpRunning == \old(pumpRunning))) || !(1 <= \old(pumpRunning))) && ((((0 == systemActive || !(\old(waterLevel) <= 2)) || !(1 <= \old(switchedOnBeforeTS))) || ((1 <= switchedOnBeforeTS && pumpRunning == \old(pumpRunning)) && waterLevel <= 2)) || !(1 <= \old(pumpRunning)))) && ((0 == systemActive || !(\old(waterLevel) <= 2)) || !(\old(pumpRunning) == 0)) - InvariantResult [Line: 894]: Loop Invariant Derived loop invariant: ((((0 == systemActive || !(1 <= switchedOnBeforeTS)) || !(waterLevel <= 2)) || pumpRunning == \old(pumpRunning)) || !(1 <= \old(pumpRunning))) && ((0 == systemActive || !(waterLevel <= 2)) || !(\old(pumpRunning) == 0)) - InvariantResult [Line: 839]: Loop Invariant Derived loop invariant: 1 - InvariantResult [Line: 966]: Loop Invariant Derived loop invariant: 1 - InvariantResult [Line: 377]: Loop Invariant Derived loop invariant: 0 - InvariantResult [Line: 368]: Loop Invariant Derived loop invariant: 1 - InvariantResult [Line: 178]: Loop Invariant Derived loop invariant: (((0 == systemActive || !(1 <= switchedOnBeforeTS)) || !(waterLevel <= 2)) || !(1 <= \old(pumpRunning))) && (((0 == systemActive || (1 <= pumpRunning && 2 <= waterLevel)) || !(waterLevel <= 2)) || !(\old(pumpRunning) == 0)) - InvariantResult [Line: 1038]: Loop Invariant Derived loop invariant: ((waterLevel == 1 && 1 == \result) && !(0 == systemActive)) && pumpRunning == 0 - InvariantResult [Line: 880]: Loop Invariant Derived loop invariant: (((0 == systemActive || !(1 <= switchedOnBeforeTS)) || !(waterLevel <= 2)) || !(1 <= \old(pumpRunning))) && (((((2 <= waterLevel && pumpRunning == 0) || 0 == systemActive) || (1 <= \result && pumpRunning == 0)) || !(waterLevel <= 2)) || !(\old(pumpRunning) == 0)) - InvariantResult [Line: 980]: Loop Invariant Derived loop invariant: 1 - InvariantResult [Line: 871]: Loop Invariant Derived loop invariant: ((((((0 == systemActive || ((waterLevel == \old(waterLevel) && 1 <= pumpRunning) && 2 <= waterLevel)) || !(\old(waterLevel) <= 2)) || (waterLevel == \old(waterLevel) && pumpRunning == 0)) || !(\old(pumpRunning) == 0)) && (((((!(2 <= \old(waterLevel)) || 0 == systemActive) || !(\old(waterLevel) <= 2)) || ((1 <= switchedOnBeforeTS && waterLevel == 1) && pumpRunning == \old(pumpRunning))) || ((1 <= switchedOnBeforeTS && waterLevel == 1) && pumpRunning == 0)) || !(1 <= \old(pumpRunning)))) && (((((0 == systemActive || !(\old(waterLevel) <= 2)) || !(1 <= \old(switchedOnBeforeTS))) || ((1 <= switchedOnBeforeTS && pumpRunning == \old(pumpRunning)) && waterLevel <= 2)) || ((1 <= switchedOnBeforeTS && waterLevel <= 2) && pumpRunning == 0)) || !(1 <= \old(pumpRunning)))) && ((((!(2 <= \old(waterLevel)) || 0 == systemActive) || (\result <= 2 && 2 <= \result)) || !(\old(waterLevel) <= 2)) || !(\old(pumpRunning) == 0)) - InvariantResult [Line: 378]: Loop Invariant Derived loop invariant: ((((((splverifierCounter == 0 && 1 == tmp) && 1 == \result) && waterLevel <= 2) && !(0 == systemActive)) && pumpRunning == 0) || ((((((splverifierCounter == 0 && 1 == tmp) && 1 == \result) && 1 <= pumpRunning) && 2 <= waterLevel) && waterLevel <= 2) && !(0 == systemActive))) || ((((((splverifierCounter == 0 && 1 <= switchedOnBeforeTS) && 1 == tmp) && 1 == \result) && 1 <= pumpRunning) && waterLevel <= 2) && !(0 == systemActive)) - InvariantResult [Line: 317]: Loop Invariant Derived loop invariant: (((waterLevel == 1 && 1 == tmp) && 1 == \result) && !(0 == systemActive)) && pumpRunning == 0 - InvariantResult [Line: 1004]: Loop Invariant Derived loop invariant: ((((!(2 <= \old(waterLevel)) || 0 == systemActive) || !(\old(waterLevel) <= 2)) || !(1 <= \old(pumpRunning))) && ((0 == systemActive || !(\old(waterLevel) <= 2)) || !(\old(pumpRunning) == 0))) && (((0 == systemActive || !(\old(waterLevel) <= 2)) || !(1 <= \old(switchedOnBeforeTS))) || !(1 <= \old(pumpRunning))) - InvariantResult [Line: 325]: Loop Invariant Derived loop invariant: ((((0 == systemActive || !(\old(waterLevel) <= 2)) || (waterLevel == \old(waterLevel) && pumpRunning == 0)) || !(\old(pumpRunning) == 0)) && ((((0 == systemActive || !(\old(waterLevel) <= 2)) || !(1 <= \old(switchedOnBeforeTS))) || ((1 <= switchedOnBeforeTS && waterLevel == \old(waterLevel)) && pumpRunning == \old(pumpRunning))) || !(1 <= \old(pumpRunning)))) && ((((!(2 <= \old(waterLevel)) || 0 == systemActive) || !(\old(waterLevel) <= 2)) || (((1 <= switchedOnBeforeTS && pumpRunning == \old(pumpRunning)) && 2 <= waterLevel) && waterLevel <= 2)) || !(1 <= \old(pumpRunning))) - InvariantResult [Line: 267]: Loop Invariant Derived loop invariant: (((0 == systemActive || !(1 <= switchedOnBeforeTS)) || !(waterLevel <= 2)) || !(1 <= \old(pumpRunning))) && (((((2 <= waterLevel && pumpRunning == 0) || 0 == systemActive) || ((tmp___0 == 0 && \result == 0) && pumpRunning == 0)) || !(waterLevel <= 2)) || !(\old(pumpRunning) == 0)) - InvariantResult [Line: 1024]: Loop Invariant Derived loop invariant: (waterLevel == 1 && !(0 == systemActive)) && pumpRunning == 0 - InvariantResult [Line: 335]: Loop Invariant Derived loop invariant: (((((((!(2 <= \old(waterLevel)) || (((1 <= switchedOnBeforeTS && waterLevel == 1) && !(0 == systemActive)) && pumpRunning == 0)) || 0 == systemActive) || !(\old(waterLevel) <= 2)) || (((1 <= switchedOnBeforeTS && waterLevel == 1) && pumpRunning == \old(pumpRunning)) && !(0 == systemActive))) || !(1 <= \old(pumpRunning))) && (((((0 == systemActive || !(\old(waterLevel) <= 2)) || !(1 <= \old(switchedOnBeforeTS))) || (((1 <= switchedOnBeforeTS && pumpRunning == \old(pumpRunning)) && waterLevel <= 2) && !(0 == systemActive))) || (((1 <= switchedOnBeforeTS && waterLevel <= 2) && !(0 == systemActive)) && pumpRunning == 0)) || !(1 <= \old(pumpRunning)))) && ((((!(2 <= \old(waterLevel)) || 0 == systemActive) || !(\old(waterLevel) <= 2)) || (((\result <= 2 && tmp <= 2) && 2 <= \result) && 1 < tmp)) || !(\old(pumpRunning) == 0))) && ((((0 == systemActive || ((waterLevel == \old(waterLevel) && 1 <= pumpRunning) && 2 <= waterLevel)) || !(\old(waterLevel) <= 2)) || (waterLevel == \old(waterLevel) && pumpRunning == \old(pumpRunning))) || !(\old(pumpRunning) == 0)) - InvariantResult [Line: 153]: Loop Invariant Derived loop invariant: (((((0 == systemActive || ((waterLevel == \old(waterLevel) && 1 <= pumpRunning) && 2 <= waterLevel)) || !(\old(waterLevel) <= 2)) || (waterLevel == \old(waterLevel) && pumpRunning == 0)) || !(\old(pumpRunning) == 0)) && (((((!(2 <= \old(waterLevel)) || 0 == systemActive) || !(\old(waterLevel) <= 2)) || ((1 <= switchedOnBeforeTS && waterLevel == 1) && pumpRunning == \old(pumpRunning))) || ((1 <= switchedOnBeforeTS && waterLevel == 1) && pumpRunning == 0)) || !(1 <= \old(pumpRunning)))) && (((((0 == systemActive || !(\old(waterLevel) <= 2)) || !(1 <= \old(switchedOnBeforeTS))) || ((1 <= switchedOnBeforeTS && pumpRunning == \old(pumpRunning)) && waterLevel <= 2)) || ((1 <= switchedOnBeforeTS && waterLevel <= 2) && pumpRunning == 0)) || !(1 <= \old(pumpRunning))) - InvariantResult [Line: 959]: Loop Invariant Derived loop invariant: (((waterLevel == 1 && 1 == tmp) && 1 == \result) && !(0 == systemActive)) && pumpRunning == 0 - InvariantResult [Line: 286]: Loop Invariant Derived loop invariant: ((((0 == systemActive || !(1 <= switchedOnBeforeTS)) || !(waterLevel <= 2)) || pumpRunning == \old(pumpRunning)) || !(1 <= \old(pumpRunning))) && ((0 == systemActive || !(waterLevel <= 2)) || !(\old(pumpRunning) == 0)) - InvariantResult [Line: 186]: Loop Invariant Derived loop invariant: (((0 == systemActive || !(1 <= switchedOnBeforeTS)) || !(waterLevel <= 2)) || !(1 <= \old(pumpRunning))) && (((((2 <= waterLevel && pumpRunning == 0) || 0 == systemActive) || (1 <= pumpRunning && 2 <= waterLevel)) || !(waterLevel <= 2)) || !(\old(pumpRunning) == 0)) RESULT: Ultimate proved your program to be correct! [2021-12-16 01:01:49,572 INFO L540 MonitoredProcess]: [MP /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in -t:2000 (1)] Forceful destruction successful, exit code 0 Received shutdown request... --- End real Ultimate output --- Execution finished normally Writing output log to file Ultimate.log Result: TRUE