./Ultimate.py --spec ../sv-benchmarks/c/properties/unreach-call.prp --file ../sv-benchmarks/c/product-lines/minepump_spec2_product46.cil.c --full-output --architecture 32bit -------------------------------------------------------------------------------- Checking for ERROR reachability Using default analysis Version c3fed411 Calling Ultimate with: /usr/bin/java -Dosgi.configuration.area=/storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/data/config -Xmx15G -Xms4m -jar /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/plugins/org.eclipse.equinox.launcher_1.5.800.v20200727-1323.jar -data @noDefault -ultimatedata /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/data -tc /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/config/AutomizerReach.xml -i ../sv-benchmarks/c/product-lines/minepump_spec2_product46.cil.c -s /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/config/svcomp-Reach-32bit-Automizer_Default.epf --cacsl2boogietranslator.entry.function main --witnessprinter.witness.directory /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux --witnessprinter.witness.filename witness.graphml --witnessprinter.write.witness.besides.input.file false --witnessprinter.graph.data.specification CHECK( init(main()), LTL(G ! call(reach_error())) ) --witnessprinter.graph.data.producer Automizer --witnessprinter.graph.data.architecture 32bit --witnessprinter.graph.data.programhash 02fb1fa00f2030f7900be70496baf2f4c44344da378fa11ef09f1f26dc14ae9d --- Real Ultimate output --- This is Ultimate 0.2.2-tmp.no-commuhash-c3fed41 [2021-12-17 15:07:38,413 INFO L177 SettingsManager]: Resetting all preferences to default values... [2021-12-17 15:07:38,414 INFO L181 SettingsManager]: Resetting UltimateCore preferences to default values [2021-12-17 15:07:38,459 INFO L184 SettingsManager]: Ultimate Commandline Interface provides no preferences, ignoring... [2021-12-17 15:07:38,460 INFO L181 SettingsManager]: Resetting Boogie Preprocessor preferences to default values [2021-12-17 15:07:38,461 INFO L181 SettingsManager]: Resetting Boogie Procedure Inliner preferences to default values [2021-12-17 15:07:38,461 INFO L181 SettingsManager]: Resetting Abstract Interpretation preferences to default values [2021-12-17 15:07:38,463 INFO L181 SettingsManager]: Resetting LassoRanker preferences to default values [2021-12-17 15:07:38,464 INFO L181 SettingsManager]: Resetting Reaching Definitions preferences to default values [2021-12-17 15:07:38,464 INFO L181 SettingsManager]: Resetting SyntaxChecker preferences to default values [2021-12-17 15:07:38,465 INFO L181 SettingsManager]: Resetting Sifa preferences to default values [2021-12-17 15:07:38,466 INFO L184 SettingsManager]: Büchi Program Product provides no preferences, ignoring... [2021-12-17 15:07:38,466 INFO L181 SettingsManager]: Resetting LTL2Aut preferences to default values [2021-12-17 15:07:38,467 INFO L181 SettingsManager]: Resetting PEA to Boogie preferences to default values [2021-12-17 15:07:38,468 INFO L181 SettingsManager]: Resetting BlockEncodingV2 preferences to default values [2021-12-17 15:07:38,468 INFO L181 SettingsManager]: Resetting ChcToBoogie preferences to default values [2021-12-17 15:07:38,469 INFO L181 SettingsManager]: Resetting AutomataScriptInterpreter preferences to default values [2021-12-17 15:07:38,470 INFO L181 SettingsManager]: Resetting BuchiAutomizer preferences to default values [2021-12-17 15:07:38,471 INFO L181 SettingsManager]: Resetting CACSL2BoogieTranslator preferences to default values [2021-12-17 15:07:38,472 INFO L181 SettingsManager]: Resetting CodeCheck preferences to default values [2021-12-17 15:07:38,473 INFO L181 SettingsManager]: Resetting InvariantSynthesis preferences to default values [2021-12-17 15:07:38,474 INFO L181 SettingsManager]: Resetting RCFGBuilder preferences to default values [2021-12-17 15:07:38,474 INFO L181 SettingsManager]: Resetting Referee preferences to default values [2021-12-17 15:07:38,475 INFO L181 SettingsManager]: Resetting TraceAbstraction preferences to default values [2021-12-17 15:07:38,477 INFO L184 SettingsManager]: TraceAbstractionConcurrent provides no preferences, ignoring... [2021-12-17 15:07:38,479 INFO L184 SettingsManager]: TraceAbstractionWithAFAs provides no preferences, ignoring... [2021-12-17 15:07:38,479 INFO L181 SettingsManager]: Resetting TreeAutomizer preferences to default values [2021-12-17 15:07:38,480 INFO L181 SettingsManager]: Resetting IcfgToChc preferences to default values [2021-12-17 15:07:38,480 INFO L181 SettingsManager]: Resetting IcfgTransformer preferences to default values [2021-12-17 15:07:38,481 INFO L184 SettingsManager]: ReqToTest provides no preferences, ignoring... [2021-12-17 15:07:38,481 INFO L181 SettingsManager]: Resetting Boogie Printer preferences to default values [2021-12-17 15:07:38,481 INFO L181 SettingsManager]: Resetting ChcSmtPrinter preferences to default values [2021-12-17 15:07:38,482 INFO L181 SettingsManager]: Resetting ReqPrinter preferences to default values [2021-12-17 15:07:38,486 INFO L181 SettingsManager]: Resetting Witness Printer preferences to default values [2021-12-17 15:07:38,487 INFO L184 SettingsManager]: Boogie PL CUP Parser provides no preferences, ignoring... [2021-12-17 15:07:38,487 INFO L181 SettingsManager]: Resetting CDTParser preferences to default values [2021-12-17 15:07:38,487 INFO L184 SettingsManager]: AutomataScriptParser provides no preferences, ignoring... [2021-12-17 15:07:38,488 INFO L184 SettingsManager]: ReqParser provides no preferences, ignoring... [2021-12-17 15:07:38,488 INFO L181 SettingsManager]: Resetting SmtParser preferences to default values [2021-12-17 15:07:38,488 INFO L181 SettingsManager]: Resetting Witness Parser preferences to default values [2021-12-17 15:07:38,489 INFO L188 SettingsManager]: Finished resetting all preferences to default values... [2021-12-17 15:07:38,490 INFO L101 SettingsManager]: Beginning loading settings from /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/config/svcomp-Reach-32bit-Automizer_Default.epf [2021-12-17 15:07:38,505 INFO L113 SettingsManager]: Loading preferences was successful [2021-12-17 15:07:38,506 INFO L115 SettingsManager]: Preferences different from defaults after loading the file: [2021-12-17 15:07:38,506 INFO L136 SettingsManager]: Preferences of UltimateCore differ from their defaults: [2021-12-17 15:07:38,506 INFO L138 SettingsManager]: * Log level for class=de.uni_freiburg.informatik.ultimate.lib.smtlibutils.quantifier.QuantifierPusher=ERROR; [2021-12-17 15:07:38,507 INFO L136 SettingsManager]: Preferences of Boogie Procedure Inliner differ from their defaults: [2021-12-17 15:07:38,509 INFO L138 SettingsManager]: * Ignore calls to procedures called more than once=ONLY_FOR_SEQUENTIAL_PROGRAMS [2021-12-17 15:07:38,512 INFO L136 SettingsManager]: Preferences of BlockEncodingV2 differ from their defaults: [2021-12-17 15:07:38,512 INFO L138 SettingsManager]: * Create parallel compositions if possible=false [2021-12-17 15:07:38,512 INFO L138 SettingsManager]: * Use SBE=true [2021-12-17 15:07:38,512 INFO L136 SettingsManager]: Preferences of CACSL2BoogieTranslator differ from their defaults: [2021-12-17 15:07:38,512 INFO L138 SettingsManager]: * sizeof long=4 [2021-12-17 15:07:38,512 INFO L138 SettingsManager]: * Overapproximate operations on floating types=true [2021-12-17 15:07:38,513 INFO L138 SettingsManager]: * sizeof POINTER=4 [2021-12-17 15:07:38,513 INFO L138 SettingsManager]: * Check division by zero=IGNORE [2021-12-17 15:07:38,513 INFO L138 SettingsManager]: * Pointer to allocated memory at dereference=IGNORE [2021-12-17 15:07:38,513 INFO L138 SettingsManager]: * If two pointers are subtracted or compared they have the same base address=IGNORE [2021-12-17 15:07:38,513 INFO L138 SettingsManager]: * Check array bounds for arrays that are off heap=IGNORE [2021-12-17 15:07:38,514 INFO L138 SettingsManager]: * sizeof long double=12 [2021-12-17 15:07:38,514 INFO L138 SettingsManager]: * Check if freed pointer was valid=false [2021-12-17 15:07:38,514 INFO L138 SettingsManager]: * Use constant arrays=true [2021-12-17 15:07:38,514 INFO L138 SettingsManager]: * Pointer base address is valid at dereference=IGNORE [2021-12-17 15:07:38,514 INFO L136 SettingsManager]: Preferences of RCFGBuilder differ from their defaults: [2021-12-17 15:07:38,514 INFO L138 SettingsManager]: * Size of a code block=SequenceOfStatements [2021-12-17 15:07:38,515 INFO L138 SettingsManager]: * SMT solver=External_DefaultMode [2021-12-17 15:07:38,515 INFO L138 SettingsManager]: * Command for external solver=z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in -t:2000 [2021-12-17 15:07:38,515 INFO L136 SettingsManager]: Preferences of TraceAbstraction differ from their defaults: [2021-12-17 15:07:38,515 INFO L138 SettingsManager]: * Compute Interpolants along a Counterexample=FPandBP [2021-12-17 15:07:38,515 INFO L138 SettingsManager]: * Positions where we compute the Hoare Annotation=LoopsAndPotentialCycles [2021-12-17 15:07:38,516 INFO L138 SettingsManager]: * Trace refinement strategy=CAMEL [2021-12-17 15:07:38,516 INFO L138 SettingsManager]: * Command for external solver=z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in [2021-12-17 15:07:38,516 INFO L138 SettingsManager]: * Large block encoding in concurrent analysis=OFF [2021-12-17 15:07:38,516 INFO L138 SettingsManager]: * Automaton type used in concurrency analysis=PETRI_NET [2021-12-17 15:07:38,516 INFO L138 SettingsManager]: * Compute Hoare Annotation of negated interpolant automaton, abstraction and CFG=true [2021-12-17 15:07:38,516 INFO L138 SettingsManager]: * Trace refinement exception blacklist=NONE [2021-12-17 15:07:38,517 INFO L138 SettingsManager]: * SMT solver=External_ModelsAndUnsatCoreMode WARNING: An illegal reflective access operation has occurred WARNING: Illegal reflective access by com.sun.xml.bind.v2.runtime.reflect.opt.Injector$1 (file:/storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/plugins/com.sun.xml.bind_2.2.0.v201505121915.jar) to method java.lang.ClassLoader.defineClass(java.lang.String,byte[],int,int) WARNING: Please consider reporting this to the maintainers of com.sun.xml.bind.v2.runtime.reflect.opt.Injector$1 WARNING: Use --illegal-access=warn to enable warnings of further illegal reflective access operations WARNING: All illegal access operations will be denied in a future release Applying setting for plugin de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator: Entry function -> main Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Witness directory -> /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Witness filename -> witness.graphml Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Write witness besides input file -> false Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Graph data specification -> CHECK( init(main()), LTL(G ! call(reach_error())) ) Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Graph data producer -> Automizer Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Graph data architecture -> 32bit Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Graph data programhash -> 02fb1fa00f2030f7900be70496baf2f4c44344da378fa11ef09f1f26dc14ae9d [2021-12-17 15:07:38,701 INFO L75 nceAwareModelManager]: Repository-Root is: /tmp [2021-12-17 15:07:38,721 INFO L261 ainManager$Toolchain]: [Toolchain 1]: Applicable parser(s) successfully (re)initialized [2021-12-17 15:07:38,724 INFO L217 ainManager$Toolchain]: [Toolchain 1]: Toolchain selected. [2021-12-17 15:07:38,725 INFO L271 PluginConnector]: Initializing CDTParser... [2021-12-17 15:07:38,726 INFO L275 PluginConnector]: CDTParser initialized [2021-12-17 15:07:38,727 INFO L432 ainManager$Toolchain]: [Toolchain 1]: Parsing single file: /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/../sv-benchmarks/c/product-lines/minepump_spec2_product46.cil.c [2021-12-17 15:07:38,793 INFO L220 CDTParser]: Created temporary CDT project at /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/data/c55fe4fa8/cf7926529be44c3981eafa929d2a2e21/FLAGdbca73e9c [2021-12-17 15:07:39,220 INFO L306 CDTParser]: Found 1 translation units. [2021-12-17 15:07:39,221 INFO L160 CDTParser]: Scanning /storage/repos/ultimate/releaseScripts/default/sv-benchmarks/c/product-lines/minepump_spec2_product46.cil.c [2021-12-17 15:07:39,230 INFO L349 CDTParser]: About to delete temporary CDT project at /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/data/c55fe4fa8/cf7926529be44c3981eafa929d2a2e21/FLAGdbca73e9c [2021-12-17 15:07:39,239 INFO L357 CDTParser]: Successfully deleted /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/data/c55fe4fa8/cf7926529be44c3981eafa929d2a2e21 [2021-12-17 15:07:39,241 INFO L299 ainManager$Toolchain]: ####################### [Toolchain 1] ####################### [2021-12-17 15:07:39,242 INFO L131 ToolchainWalker]: Walking toolchain with 6 elements. [2021-12-17 15:07:39,243 INFO L113 PluginConnector]: ------------------------CACSL2BoogieTranslator---------------------------- [2021-12-17 15:07:39,243 INFO L271 PluginConnector]: Initializing CACSL2BoogieTranslator... [2021-12-17 15:07:39,245 INFO L275 PluginConnector]: CACSL2BoogieTranslator initialized [2021-12-17 15:07:39,245 INFO L185 PluginConnector]: Executing the observer ACSLObjectContainerObserver from plugin CACSL2BoogieTranslator for "CDTParser AST 17.12 03:07:39" (1/1) ... [2021-12-17 15:07:39,246 INFO L205 PluginConnector]: Invalid model from CACSL2BoogieTranslator for observer de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator.ACSLObjectContainerObserver@7f925a4f and model type de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 17.12 03:07:39, skipping insertion in model container [2021-12-17 15:07:39,246 INFO L185 PluginConnector]: Executing the observer CACSL2BoogieTranslatorObserver from plugin CACSL2BoogieTranslator for "CDTParser AST 17.12 03:07:39" (1/1) ... [2021-12-17 15:07:39,250 INFO L145 MainTranslator]: Starting translation in SV-COMP mode [2021-12-17 15:07:39,279 INFO L178 MainTranslator]: Built tables and reachable declarations [2021-12-17 15:07:39,497 WARN L230 ndardFunctionHandler]: Function reach_error is already implemented but we override the implementation for the call at /storage/repos/ultimate/releaseScripts/default/sv-benchmarks/c/product-lines/minepump_spec2_product46.cil.c[17174,17187] [2021-12-17 15:07:39,506 INFO L209 PostProcessor]: Analyzing one entry point: main [2021-12-17 15:07:39,512 INFO L203 MainTranslator]: Completed pre-run [2021-12-17 15:07:39,583 WARN L230 ndardFunctionHandler]: Function reach_error is already implemented but we override the implementation for the call at /storage/repos/ultimate/releaseScripts/default/sv-benchmarks/c/product-lines/minepump_spec2_product46.cil.c[17174,17187] [2021-12-17 15:07:39,585 INFO L209 PostProcessor]: Analyzing one entry point: main [2021-12-17 15:07:39,597 INFO L208 MainTranslator]: Completed translation [2021-12-17 15:07:39,598 INFO L202 PluginConnector]: Adding new model de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 17.12 03:07:39 WrapperNode [2021-12-17 15:07:39,598 INFO L132 PluginConnector]: ------------------------ END CACSL2BoogieTranslator---------------------------- [2021-12-17 15:07:39,599 INFO L113 PluginConnector]: ------------------------Boogie Procedure Inliner---------------------------- [2021-12-17 15:07:39,599 INFO L271 PluginConnector]: Initializing Boogie Procedure Inliner... [2021-12-17 15:07:39,600 INFO L275 PluginConnector]: Boogie Procedure Inliner initialized [2021-12-17 15:07:39,604 INFO L185 PluginConnector]: Executing the observer TypeChecker from plugin Boogie Procedure Inliner for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 17.12 03:07:39" (1/1) ... [2021-12-17 15:07:39,614 INFO L185 PluginConnector]: Executing the observer Inliner from plugin Boogie Procedure Inliner for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 17.12 03:07:39" (1/1) ... [2021-12-17 15:07:39,632 INFO L137 Inliner]: procedures = 56, calls = 157, calls flagged for inlining = 23, calls inlined = 20, statements flattened = 249 [2021-12-17 15:07:39,632 INFO L132 PluginConnector]: ------------------------ END Boogie Procedure Inliner---------------------------- [2021-12-17 15:07:39,633 INFO L113 PluginConnector]: ------------------------Boogie Preprocessor---------------------------- [2021-12-17 15:07:39,633 INFO L271 PluginConnector]: Initializing Boogie Preprocessor... [2021-12-17 15:07:39,633 INFO L275 PluginConnector]: Boogie Preprocessor initialized [2021-12-17 15:07:39,643 INFO L185 PluginConnector]: Executing the observer EnsureBoogieModelObserver from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 17.12 03:07:39" (1/1) ... [2021-12-17 15:07:39,644 INFO L185 PluginConnector]: Executing the observer TypeChecker from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 17.12 03:07:39" (1/1) ... [2021-12-17 15:07:39,662 INFO L185 PluginConnector]: Executing the observer ConstExpander from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 17.12 03:07:39" (1/1) ... [2021-12-17 15:07:39,662 INFO L185 PluginConnector]: Executing the observer StructExpander from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 17.12 03:07:39" (1/1) ... [2021-12-17 15:07:39,666 INFO L185 PluginConnector]: Executing the observer UnstructureCode from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 17.12 03:07:39" (1/1) ... [2021-12-17 15:07:39,674 INFO L185 PluginConnector]: Executing the observer FunctionInliner from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 17.12 03:07:39" (1/1) ... [2021-12-17 15:07:39,675 INFO L185 PluginConnector]: Executing the observer BoogieSymbolTableConstructor from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 17.12 03:07:39" (1/1) ... [2021-12-17 15:07:39,677 INFO L132 PluginConnector]: ------------------------ END Boogie Preprocessor---------------------------- [2021-12-17 15:07:39,677 INFO L113 PluginConnector]: ------------------------RCFGBuilder---------------------------- [2021-12-17 15:07:39,677 INFO L271 PluginConnector]: Initializing RCFGBuilder... [2021-12-17 15:07:39,677 INFO L275 PluginConnector]: RCFGBuilder initialized [2021-12-17 15:07:39,678 INFO L185 PluginConnector]: Executing the observer RCFGBuilderObserver from plugin RCFGBuilder for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 17.12 03:07:39" (1/1) ... [2021-12-17 15:07:39,683 INFO L168 SolverBuilder]: Constructing external solver with command: z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in -t:2000 [2021-12-17 15:07:39,703 INFO L189 MonitoredProcess]: No working directory specified, using /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 [2021-12-17 15:07:39,718 INFO L229 MonitoredProcess]: Starting monitored process 1 with /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in -t:2000 (exit command is (exit), workingDir is null) [2021-12-17 15:07:39,728 INFO L327 MonitoredProcess]: [MP /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in -t:2000 (1)] Waiting until timeout for monitored process [2021-12-17 15:07:39,742 INFO L130 BoogieDeclarations]: Found specification of procedure #Ultimate.allocInit [2021-12-17 15:07:39,743 INFO L130 BoogieDeclarations]: Found specification of procedure processEnvironment__wrappee__base [2021-12-17 15:07:39,743 INFO L138 BoogieDeclarations]: Found implementation of procedure processEnvironment__wrappee__base [2021-12-17 15:07:39,743 INFO L130 BoogieDeclarations]: Found specification of procedure timeShift [2021-12-17 15:07:39,743 INFO L138 BoogieDeclarations]: Found implementation of procedure timeShift [2021-12-17 15:07:39,743 INFO L130 BoogieDeclarations]: Found specification of procedure cleanup [2021-12-17 15:07:39,743 INFO L138 BoogieDeclarations]: Found implementation of procedure cleanup [2021-12-17 15:07:39,744 INFO L130 BoogieDeclarations]: Found specification of procedure isMethaneLevelCritical [2021-12-17 15:07:39,745 INFO L138 BoogieDeclarations]: Found implementation of procedure isMethaneLevelCritical [2021-12-17 15:07:39,745 INFO L130 BoogieDeclarations]: Found specification of procedure waterRise [2021-12-17 15:07:39,745 INFO L138 BoogieDeclarations]: Found implementation of procedure waterRise [2021-12-17 15:07:39,745 INFO L130 BoogieDeclarations]: Found specification of procedure processEnvironment__wrappee__methaneQuery [2021-12-17 15:07:39,745 INFO L138 BoogieDeclarations]: Found implementation of procedure processEnvironment__wrappee__methaneQuery [2021-12-17 15:07:39,745 INFO L130 BoogieDeclarations]: Found specification of procedure isMethaneAlarm [2021-12-17 15:07:39,746 INFO L138 BoogieDeclarations]: Found implementation of procedure isMethaneAlarm [2021-12-17 15:07:39,746 INFO L130 BoogieDeclarations]: Found specification of procedure write~init~int [2021-12-17 15:07:39,746 INFO L130 BoogieDeclarations]: Found specification of procedure changeMethaneLevel [2021-12-17 15:07:39,746 INFO L138 BoogieDeclarations]: Found implementation of procedure changeMethaneLevel [2021-12-17 15:07:39,746 INFO L130 BoogieDeclarations]: Found specification of procedure ULTIMATE.start [2021-12-17 15:07:39,746 INFO L138 BoogieDeclarations]: Found implementation of procedure ULTIMATE.start [2021-12-17 15:07:39,821 INFO L236 CfgBuilder]: Building ICFG [2021-12-17 15:07:39,825 INFO L262 CfgBuilder]: Building CFG for each procedure with an implementation [2021-12-17 15:07:40,037 INFO L277 CfgBuilder]: Performing block encoding [2021-12-17 15:07:40,042 INFO L296 CfgBuilder]: Using the 1 location(s) as analysis (start of procedure ULTIMATE.start) [2021-12-17 15:07:40,042 INFO L301 CfgBuilder]: Removed 2 assume(true) statements. [2021-12-17 15:07:40,049 INFO L202 PluginConnector]: Adding new model de.uni_freiburg.informatik.ultimate.plugins.generator.rcfgbuilder CFG 17.12 03:07:40 BoogieIcfgContainer [2021-12-17 15:07:40,049 INFO L132 PluginConnector]: ------------------------ END RCFGBuilder---------------------------- [2021-12-17 15:07:40,050 INFO L113 PluginConnector]: ------------------------TraceAbstraction---------------------------- [2021-12-17 15:07:40,050 INFO L271 PluginConnector]: Initializing TraceAbstraction... [2021-12-17 15:07:40,053 INFO L275 PluginConnector]: TraceAbstraction initialized [2021-12-17 15:07:40,054 INFO L185 PluginConnector]: Executing the observer TraceAbstractionObserver from plugin TraceAbstraction for "CDTParser AST 17.12 03:07:39" (1/3) ... [2021-12-17 15:07:40,054 INFO L205 PluginConnector]: Invalid model from TraceAbstraction for observer de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction.TraceAbstractionObserver@3a592dcd and model type de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction AST 17.12 03:07:40, skipping insertion in model container [2021-12-17 15:07:40,054 INFO L185 PluginConnector]: Executing the observer TraceAbstractionObserver from plugin TraceAbstraction for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 17.12 03:07:39" (2/3) ... [2021-12-17 15:07:40,055 INFO L205 PluginConnector]: Invalid model from TraceAbstraction for observer de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction.TraceAbstractionObserver@3a592dcd and model type de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction AST 17.12 03:07:40, skipping insertion in model container [2021-12-17 15:07:40,055 INFO L185 PluginConnector]: Executing the observer TraceAbstractionObserver from plugin TraceAbstraction for "de.uni_freiburg.informatik.ultimate.plugins.generator.rcfgbuilder CFG 17.12 03:07:40" (3/3) ... [2021-12-17 15:07:40,056 INFO L111 eAbstractionObserver]: Analyzing ICFG minepump_spec2_product46.cil.c [2021-12-17 15:07:40,060 INFO L204 ceAbstractionStarter]: Automizer settings: Hoare:true NWA Interpolation:FPandBP Determinization: PREDICATE_ABSTRACTION [2021-12-17 15:07:40,060 INFO L163 ceAbstractionStarter]: Applying trace abstraction to program that has 1 error locations. [2021-12-17 15:07:40,098 INFO L338 AbstractCegarLoop]: ======== Iteration 0 == of CEGAR loop == AllErrorsAtOnce ======== [2021-12-17 15:07:40,104 INFO L339 AbstractCegarLoop]: Settings: SEPARATE_VIOLATION_CHECK=true, mInterprocedural=true, mMaxIterations=1000000, mWatchIteration=1000000, mArtifact=RCFG, mInterpolation=FPandBP, mInterpolantAutomaton=STRAIGHT_LINE, mDumpAutomata=false, mAutomataFormat=ATS_NUMERATE, mDumpPath=., mDeterminiation=PREDICATE_ABSTRACTION, mMinimize=MINIMIZE_SEVPA, mHoare=true, mAutomataTypeConcurrency=PETRI_NET, mHoareTripleChecks=INCREMENTAL, mHoareAnnotationPositions=LoopsAndPotentialCycles, mDumpOnlyReuseAutomata=false, mLimitTraceHistogram=0, mErrorLocTimeLimit=0, mLimitPathProgramCount=0, mCollectInterpolantStatistics=true, mHeuristicEmptinessCheck=false, mHeuristicEmptinessCheckAStarHeuristic=ZERO, mHeuristicEmptinessCheckAStarHeuristicRandomSeed=1337, mHeuristicEmptinessCheckSmtFeatureScoringMethod=DAGSIZE, mSMTFeatureExtraction=false, mSMTFeatureExtractionDumpPath=., mOverrideInterpolantAutomaton=false, mMcrInterpolantMethod=WP, mLoopAccelerationTechnique=FAST_UPR [2021-12-17 15:07:40,104 INFO L340 AbstractCegarLoop]: Starting to check reachability of 1 error locations. [2021-12-17 15:07:40,148 INFO L276 IsEmpty]: Start isEmpty. Operand has 96 states, 72 states have (on average 1.375) internal successors, (99), 80 states have internal predecessors, (99), 14 states have call successors, (14), 8 states have call predecessors, (14), 8 states have return successors, (14), 12 states have call predecessors, (14), 14 states have call successors, (14) [2021-12-17 15:07:40,156 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 26 [2021-12-17 15:07:40,157 INFO L506 BasicCegarLoop]: Found error trace [2021-12-17 15:07:40,158 INFO L514 BasicCegarLoop]: trace histogram [1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2021-12-17 15:07:40,158 INFO L402 AbstractCegarLoop]: === Iteration 1 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2021-12-17 15:07:40,162 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2021-12-17 15:07:40,163 INFO L85 PathProgramCache]: Analyzing trace with hash 92222794, now seen corresponding path program 1 times [2021-12-17 15:07:40,171 INFO L121 FreeRefinementEngine]: Executing refinement strategy CAMEL [2021-12-17 15:07:40,172 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [770768617] [2021-12-17 15:07:40,172 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2021-12-17 15:07:40,173 INFO L126 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2021-12-17 15:07:40,316 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:07:40,399 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 15 [2021-12-17 15:07:40,405 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:07:40,413 INFO L134 CoverageAnalysis]: Checked inductivity of 0 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2021-12-17 15:07:40,413 INFO L139 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2021-12-17 15:07:40,414 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [770768617] [2021-12-17 15:07:40,415 INFO L160 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [770768617] provided 1 perfect and 0 imperfect interpolant sequences [2021-12-17 15:07:40,415 INFO L186 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2021-12-17 15:07:40,415 INFO L199 FreeRefinementEngine]: Number of different interpolants: perfect sequences [2] imperfect sequences [] total 2 [2021-12-17 15:07:40,416 INFO L115 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [1463641498] [2021-12-17 15:07:40,417 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2021-12-17 15:07:40,420 INFO L546 AbstractCegarLoop]: INTERPOLANT automaton has 2 states [2021-12-17 15:07:40,421 INFO L103 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2021-12-17 15:07:40,443 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 2 interpolants. [2021-12-17 15:07:40,445 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=1, Invalid=1, Unknown=0, NotChecked=0, Total=2 [2021-12-17 15:07:40,447 INFO L87 Difference]: Start difference. First operand has 96 states, 72 states have (on average 1.375) internal successors, (99), 80 states have internal predecessors, (99), 14 states have call successors, (14), 8 states have call predecessors, (14), 8 states have return successors, (14), 12 states have call predecessors, (14), 14 states have call successors, (14) Second operand has 2 states, 2 states have (on average 10.5) internal successors, (21), 2 states have internal predecessors, (21), 1 states have call successors, (3), 2 states have call predecessors, (3), 1 states have return successors, (1), 1 states have call predecessors, (1), 1 states have call successors, (1) [2021-12-17 15:07:40,480 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2021-12-17 15:07:40,481 INFO L93 Difference]: Finished difference Result 183 states and 248 transitions. [2021-12-17 15:07:40,481 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 2 states. [2021-12-17 15:07:40,482 INFO L78 Accepts]: Start accepts. Automaton has has 2 states, 2 states have (on average 10.5) internal successors, (21), 2 states have internal predecessors, (21), 1 states have call successors, (3), 2 states have call predecessors, (3), 1 states have return successors, (1), 1 states have call predecessors, (1), 1 states have call successors, (1) Word has length 25 [2021-12-17 15:07:40,483 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2021-12-17 15:07:40,490 INFO L225 Difference]: With dead ends: 183 [2021-12-17 15:07:40,490 INFO L226 Difference]: Without dead ends: 87 [2021-12-17 15:07:40,495 INFO L932 BasicCegarLoop]: 0 DeclaredPredicates, 4 GetRequests, 4 SyntacticMatches, 0 SemanticMatches, 0 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 0 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=1, Invalid=1, Unknown=0, NotChecked=0, Total=2 [2021-12-17 15:07:40,498 INFO L933 BasicCegarLoop]: 121 mSDtfsCounter, 0 mSDsluCounter, 0 mSDsCounter, 0 mSdLazyCounter, 0 mSolverCounterSat, 0 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.0s Time, 0 mProtectedPredicate, 0 mProtectedAction, 0 SdHoareTripleChecker+Valid, 121 SdHoareTripleChecker+Invalid, 0 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 0 IncrementalHoareTripleChecker+Valid, 0 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.0s IncrementalHoareTripleChecker+Time [2021-12-17 15:07:40,498 INFO L934 BasicCegarLoop]: SdHoareTripleChecker [0 Valid, 121 Invalid, 0 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [0 Valid, 0 Invalid, 0 Unknown, 0 Unchecked, 0.0s Time] [2021-12-17 15:07:40,510 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 87 states. [2021-12-17 15:07:40,530 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 87 to 87. [2021-12-17 15:07:40,532 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 87 states, 65 states have (on average 1.3076923076923077) internal successors, (85), 72 states have internal predecessors, (85), 14 states have call successors, (14), 8 states have call predecessors, (14), 7 states have return successors, (13), 11 states have call predecessors, (13), 13 states have call successors, (13) [2021-12-17 15:07:40,533 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 87 states to 87 states and 112 transitions. [2021-12-17 15:07:40,534 INFO L78 Accepts]: Start accepts. Automaton has 87 states and 112 transitions. Word has length 25 [2021-12-17 15:07:40,534 INFO L84 Accepts]: Finished accepts. word is rejected. [2021-12-17 15:07:40,535 INFO L470 AbstractCegarLoop]: Abstraction has 87 states and 112 transitions. [2021-12-17 15:07:40,535 INFO L471 AbstractCegarLoop]: INTERPOLANT automaton has has 2 states, 2 states have (on average 10.5) internal successors, (21), 2 states have internal predecessors, (21), 1 states have call successors, (3), 2 states have call predecessors, (3), 1 states have return successors, (1), 1 states have call predecessors, (1), 1 states have call successors, (1) [2021-12-17 15:07:40,535 INFO L276 IsEmpty]: Start isEmpty. Operand 87 states and 112 transitions. [2021-12-17 15:07:40,536 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 27 [2021-12-17 15:07:40,536 INFO L506 BasicCegarLoop]: Found error trace [2021-12-17 15:07:40,536 INFO L514 BasicCegarLoop]: trace histogram [1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2021-12-17 15:07:40,537 WARN L452 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable0 [2021-12-17 15:07:40,537 INFO L402 AbstractCegarLoop]: === Iteration 2 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2021-12-17 15:07:40,537 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2021-12-17 15:07:40,537 INFO L85 PathProgramCache]: Analyzing trace with hash -1552792509, now seen corresponding path program 1 times [2021-12-17 15:07:40,537 INFO L121 FreeRefinementEngine]: Executing refinement strategy CAMEL [2021-12-17 15:07:40,538 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [180165598] [2021-12-17 15:07:40,538 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2021-12-17 15:07:40,538 INFO L126 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2021-12-17 15:07:40,552 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:07:40,590 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 16 [2021-12-17 15:07:40,592 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:07:40,594 INFO L134 CoverageAnalysis]: Checked inductivity of 0 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2021-12-17 15:07:40,594 INFO L139 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2021-12-17 15:07:40,594 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [180165598] [2021-12-17 15:07:40,594 INFO L160 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [180165598] provided 1 perfect and 0 imperfect interpolant sequences [2021-12-17 15:07:40,595 INFO L186 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2021-12-17 15:07:40,595 INFO L199 FreeRefinementEngine]: Number of different interpolants: perfect sequences [3] imperfect sequences [] total 3 [2021-12-17 15:07:40,595 INFO L115 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [1202091085] [2021-12-17 15:07:40,595 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2021-12-17 15:07:40,596 INFO L546 AbstractCegarLoop]: INTERPOLANT automaton has 3 states [2021-12-17 15:07:40,596 INFO L103 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2021-12-17 15:07:40,597 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 3 interpolants. [2021-12-17 15:07:40,597 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=3, Invalid=3, Unknown=0, NotChecked=0, Total=6 [2021-12-17 15:07:40,597 INFO L87 Difference]: Start difference. First operand 87 states and 112 transitions. Second operand has 3 states, 3 states have (on average 7.333333333333333) internal successors, (22), 3 states have internal predecessors, (22), 1 states have call successors, (3), 2 states have call predecessors, (3), 1 states have return successors, (1), 1 states have call predecessors, (1), 1 states have call successors, (1) [2021-12-17 15:07:40,608 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2021-12-17 15:07:40,608 INFO L93 Difference]: Finished difference Result 138 states and 178 transitions. [2021-12-17 15:07:40,609 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 3 states. [2021-12-17 15:07:40,609 INFO L78 Accepts]: Start accepts. Automaton has has 3 states, 3 states have (on average 7.333333333333333) internal successors, (22), 3 states have internal predecessors, (22), 1 states have call successors, (3), 2 states have call predecessors, (3), 1 states have return successors, (1), 1 states have call predecessors, (1), 1 states have call successors, (1) Word has length 26 [2021-12-17 15:07:40,609 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2021-12-17 15:07:40,610 INFO L225 Difference]: With dead ends: 138 [2021-12-17 15:07:40,610 INFO L226 Difference]: Without dead ends: 78 [2021-12-17 15:07:40,611 INFO L932 BasicCegarLoop]: 0 DeclaredPredicates, 5 GetRequests, 4 SyntacticMatches, 0 SemanticMatches, 1 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 0 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=3, Invalid=3, Unknown=0, NotChecked=0, Total=6 [2021-12-17 15:07:40,612 INFO L933 BasicCegarLoop]: 99 mSDtfsCounter, 13 mSDsluCounter, 82 mSDsCounter, 0 mSdLazyCounter, 1 mSolverCounterSat, 0 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.0s Time, 0 mProtectedPredicate, 0 mProtectedAction, 16 SdHoareTripleChecker+Valid, 181 SdHoareTripleChecker+Invalid, 1 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 0 IncrementalHoareTripleChecker+Valid, 1 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.0s IncrementalHoareTripleChecker+Time [2021-12-17 15:07:40,612 INFO L934 BasicCegarLoop]: SdHoareTripleChecker [16 Valid, 181 Invalid, 1 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [0 Valid, 1 Invalid, 0 Unknown, 0 Unchecked, 0.0s Time] [2021-12-17 15:07:40,613 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 78 states. [2021-12-17 15:07:40,619 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 78 to 78. [2021-12-17 15:07:40,620 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 78 states, 59 states have (on average 1.3220338983050848) internal successors, (78), 66 states have internal predecessors, (78), 11 states have call successors, (11), 7 states have call predecessors, (11), 7 states have return successors, (11), 9 states have call predecessors, (11), 11 states have call successors, (11) [2021-12-17 15:07:40,620 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 78 states to 78 states and 100 transitions. [2021-12-17 15:07:40,621 INFO L78 Accepts]: Start accepts. Automaton has 78 states and 100 transitions. Word has length 26 [2021-12-17 15:07:40,621 INFO L84 Accepts]: Finished accepts. word is rejected. [2021-12-17 15:07:40,621 INFO L470 AbstractCegarLoop]: Abstraction has 78 states and 100 transitions. [2021-12-17 15:07:40,621 INFO L471 AbstractCegarLoop]: INTERPOLANT automaton has has 3 states, 3 states have (on average 7.333333333333333) internal successors, (22), 3 states have internal predecessors, (22), 1 states have call successors, (3), 2 states have call predecessors, (3), 1 states have return successors, (1), 1 states have call predecessors, (1), 1 states have call successors, (1) [2021-12-17 15:07:40,621 INFO L276 IsEmpty]: Start isEmpty. Operand 78 states and 100 transitions. [2021-12-17 15:07:40,622 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 32 [2021-12-17 15:07:40,622 INFO L506 BasicCegarLoop]: Found error trace [2021-12-17 15:07:40,622 INFO L514 BasicCegarLoop]: trace histogram [1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2021-12-17 15:07:40,622 WARN L452 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable1 [2021-12-17 15:07:40,623 INFO L402 AbstractCegarLoop]: === Iteration 3 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2021-12-17 15:07:40,623 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2021-12-17 15:07:40,623 INFO L85 PathProgramCache]: Analyzing trace with hash 877193570, now seen corresponding path program 1 times [2021-12-17 15:07:40,623 INFO L121 FreeRefinementEngine]: Executing refinement strategy CAMEL [2021-12-17 15:07:40,624 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [2133934202] [2021-12-17 15:07:40,624 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2021-12-17 15:07:40,624 INFO L126 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2021-12-17 15:07:40,637 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:07:40,695 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 21 [2021-12-17 15:07:40,696 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:07:40,702 INFO L134 CoverageAnalysis]: Checked inductivity of 0 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2021-12-17 15:07:40,703 INFO L139 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2021-12-17 15:07:40,703 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [2133934202] [2021-12-17 15:07:40,703 INFO L160 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [2133934202] provided 1 perfect and 0 imperfect interpolant sequences [2021-12-17 15:07:40,703 INFO L186 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2021-12-17 15:07:40,703 INFO L199 FreeRefinementEngine]: Number of different interpolants: perfect sequences [6] imperfect sequences [] total 6 [2021-12-17 15:07:40,703 INFO L115 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [360694099] [2021-12-17 15:07:40,703 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2021-12-17 15:07:40,704 INFO L546 AbstractCegarLoop]: INTERPOLANT automaton has 6 states [2021-12-17 15:07:40,704 INFO L103 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2021-12-17 15:07:40,704 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 6 interpolants. [2021-12-17 15:07:40,704 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=10, Invalid=20, Unknown=0, NotChecked=0, Total=30 [2021-12-17 15:07:40,704 INFO L87 Difference]: Start difference. First operand 78 states and 100 transitions. Second operand has 6 states, 6 states have (on average 4.666666666666667) internal successors, (28), 6 states have internal predecessors, (28), 2 states have call successors, (2), 2 states have call predecessors, (2), 1 states have return successors, (1), 1 states have call predecessors, (1), 1 states have call successors, (1) [2021-12-17 15:07:40,809 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2021-12-17 15:07:40,810 INFO L93 Difference]: Finished difference Result 148 states and 193 transitions. [2021-12-17 15:07:40,810 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 5 states. [2021-12-17 15:07:40,810 INFO L78 Accepts]: Start accepts. Automaton has has 6 states, 6 states have (on average 4.666666666666667) internal successors, (28), 6 states have internal predecessors, (28), 2 states have call successors, (2), 2 states have call predecessors, (2), 1 states have return successors, (1), 1 states have call predecessors, (1), 1 states have call successors, (1) Word has length 31 [2021-12-17 15:07:40,811 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2021-12-17 15:07:40,812 INFO L225 Difference]: With dead ends: 148 [2021-12-17 15:07:40,813 INFO L226 Difference]: Without dead ends: 78 [2021-12-17 15:07:40,814 INFO L932 BasicCegarLoop]: 0 DeclaredPredicates, 9 GetRequests, 3 SyntacticMatches, 0 SemanticMatches, 6 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 0 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=22, Invalid=34, Unknown=0, NotChecked=0, Total=56 [2021-12-17 15:07:40,816 INFO L933 BasicCegarLoop]: 93 mSDtfsCounter, 187 mSDsluCounter, 112 mSDsCounter, 0 mSdLazyCounter, 49 mSolverCounterSat, 35 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.0s Time, 0 mProtectedPredicate, 0 mProtectedAction, 187 SdHoareTripleChecker+Valid, 205 SdHoareTripleChecker+Invalid, 84 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 35 IncrementalHoareTripleChecker+Valid, 49 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.1s IncrementalHoareTripleChecker+Time [2021-12-17 15:07:40,818 INFO L934 BasicCegarLoop]: SdHoareTripleChecker [187 Valid, 205 Invalid, 84 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [35 Valid, 49 Invalid, 0 Unknown, 0 Unchecked, 0.1s Time] [2021-12-17 15:07:40,819 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 78 states. [2021-12-17 15:07:40,826 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 78 to 78. [2021-12-17 15:07:40,828 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 78 states, 59 states have (on average 1.305084745762712) internal successors, (77), 66 states have internal predecessors, (77), 11 states have call successors, (11), 7 states have call predecessors, (11), 7 states have return successors, (11), 9 states have call predecessors, (11), 11 states have call successors, (11) [2021-12-17 15:07:40,829 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 78 states to 78 states and 99 transitions. [2021-12-17 15:07:40,829 INFO L78 Accepts]: Start accepts. Automaton has 78 states and 99 transitions. Word has length 31 [2021-12-17 15:07:40,829 INFO L84 Accepts]: Finished accepts. word is rejected. [2021-12-17 15:07:40,830 INFO L470 AbstractCegarLoop]: Abstraction has 78 states and 99 transitions. [2021-12-17 15:07:40,830 INFO L471 AbstractCegarLoop]: INTERPOLANT automaton has has 6 states, 6 states have (on average 4.666666666666667) internal successors, (28), 6 states have internal predecessors, (28), 2 states have call successors, (2), 2 states have call predecessors, (2), 1 states have return successors, (1), 1 states have call predecessors, (1), 1 states have call successors, (1) [2021-12-17 15:07:40,830 INFO L276 IsEmpty]: Start isEmpty. Operand 78 states and 99 transitions. [2021-12-17 15:07:40,832 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 42 [2021-12-17 15:07:40,834 INFO L506 BasicCegarLoop]: Found error trace [2021-12-17 15:07:40,834 INFO L514 BasicCegarLoop]: trace histogram [1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2021-12-17 15:07:40,834 WARN L452 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable2 [2021-12-17 15:07:40,834 INFO L402 AbstractCegarLoop]: === Iteration 4 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2021-12-17 15:07:40,835 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2021-12-17 15:07:40,836 INFO L85 PathProgramCache]: Analyzing trace with hash -100681773, now seen corresponding path program 1 times [2021-12-17 15:07:40,837 INFO L121 FreeRefinementEngine]: Executing refinement strategy CAMEL [2021-12-17 15:07:40,837 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [1371802732] [2021-12-17 15:07:40,837 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2021-12-17 15:07:40,837 INFO L126 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2021-12-17 15:07:40,846 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:07:40,877 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 21 [2021-12-17 15:07:40,879 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:07:40,892 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 2 [2021-12-17 15:07:40,894 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:07:40,896 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 31 [2021-12-17 15:07:40,897 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:07:40,900 INFO L134 CoverageAnalysis]: Checked inductivity of 0 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2021-12-17 15:07:40,901 INFO L139 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2021-12-17 15:07:40,901 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [1371802732] [2021-12-17 15:07:40,901 INFO L160 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [1371802732] provided 1 perfect and 0 imperfect interpolant sequences [2021-12-17 15:07:40,901 INFO L186 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2021-12-17 15:07:40,901 INFO L199 FreeRefinementEngine]: Number of different interpolants: perfect sequences [5] imperfect sequences [] total 5 [2021-12-17 15:07:40,901 INFO L115 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [554359679] [2021-12-17 15:07:40,902 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2021-12-17 15:07:40,904 INFO L546 AbstractCegarLoop]: INTERPOLANT automaton has 5 states [2021-12-17 15:07:40,904 INFO L103 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2021-12-17 15:07:40,904 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 5 interpolants. [2021-12-17 15:07:40,904 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=7, Invalid=13, Unknown=0, NotChecked=0, Total=20 [2021-12-17 15:07:40,904 INFO L87 Difference]: Start difference. First operand 78 states and 99 transitions. Second operand has 5 states, 5 states have (on average 6.8) internal successors, (34), 5 states have internal predecessors, (34), 3 states have call successors, (4), 3 states have call predecessors, (4), 2 states have return successors, (3), 2 states have call predecessors, (3), 3 states have call successors, (3) [2021-12-17 15:07:41,085 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2021-12-17 15:07:41,085 INFO L93 Difference]: Finished difference Result 229 states and 291 transitions. [2021-12-17 15:07:41,085 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 7 states. [2021-12-17 15:07:41,085 INFO L78 Accepts]: Start accepts. Automaton has has 5 states, 5 states have (on average 6.8) internal successors, (34), 5 states have internal predecessors, (34), 3 states have call successors, (4), 3 states have call predecessors, (4), 2 states have return successors, (3), 2 states have call predecessors, (3), 3 states have call successors, (3) Word has length 41 [2021-12-17 15:07:41,086 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2021-12-17 15:07:41,089 INFO L225 Difference]: With dead ends: 229 [2021-12-17 15:07:41,089 INFO L226 Difference]: Without dead ends: 159 [2021-12-17 15:07:41,090 INFO L932 BasicCegarLoop]: 0 DeclaredPredicates, 15 GetRequests, 8 SyntacticMatches, 1 SemanticMatches, 6 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 3 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=19, Invalid=37, Unknown=0, NotChecked=0, Total=56 [2021-12-17 15:07:41,097 INFO L933 BasicCegarLoop]: 135 mSDtfsCounter, 181 mSDsluCounter, 174 mSDsCounter, 0 mSdLazyCounter, 106 mSolverCounterSat, 58 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.1s Time, 0 mProtectedPredicate, 0 mProtectedAction, 183 SdHoareTripleChecker+Valid, 309 SdHoareTripleChecker+Invalid, 164 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 58 IncrementalHoareTripleChecker+Valid, 106 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.1s IncrementalHoareTripleChecker+Time [2021-12-17 15:07:41,098 INFO L934 BasicCegarLoop]: SdHoareTripleChecker [183 Valid, 309 Invalid, 164 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [58 Valid, 106 Invalid, 0 Unknown, 0 Unchecked, 0.1s Time] [2021-12-17 15:07:41,100 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 159 states. [2021-12-17 15:07:41,117 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 159 to 153. [2021-12-17 15:07:41,118 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 153 states, 116 states have (on average 1.2672413793103448) internal successors, (147), 124 states have internal predecessors, (147), 18 states have call successors, (18), 15 states have call predecessors, (18), 18 states have return successors, (23), 19 states have call predecessors, (23), 18 states have call successors, (23) [2021-12-17 15:07:41,118 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 153 states to 153 states and 188 transitions. [2021-12-17 15:07:41,119 INFO L78 Accepts]: Start accepts. Automaton has 153 states and 188 transitions. Word has length 41 [2021-12-17 15:07:41,119 INFO L84 Accepts]: Finished accepts. word is rejected. [2021-12-17 15:07:41,119 INFO L470 AbstractCegarLoop]: Abstraction has 153 states and 188 transitions. [2021-12-17 15:07:41,119 INFO L471 AbstractCegarLoop]: INTERPOLANT automaton has has 5 states, 5 states have (on average 6.8) internal successors, (34), 5 states have internal predecessors, (34), 3 states have call successors, (4), 3 states have call predecessors, (4), 2 states have return successors, (3), 2 states have call predecessors, (3), 3 states have call successors, (3) [2021-12-17 15:07:41,119 INFO L276 IsEmpty]: Start isEmpty. Operand 153 states and 188 transitions. [2021-12-17 15:07:41,130 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 48 [2021-12-17 15:07:41,131 INFO L506 BasicCegarLoop]: Found error trace [2021-12-17 15:07:41,131 INFO L514 BasicCegarLoop]: trace histogram [1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2021-12-17 15:07:41,131 WARN L452 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable3 [2021-12-17 15:07:41,131 INFO L402 AbstractCegarLoop]: === Iteration 5 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2021-12-17 15:07:41,132 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2021-12-17 15:07:41,132 INFO L85 PathProgramCache]: Analyzing trace with hash -1653796005, now seen corresponding path program 1 times [2021-12-17 15:07:41,132 INFO L121 FreeRefinementEngine]: Executing refinement strategy CAMEL [2021-12-17 15:07:41,132 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [960602642] [2021-12-17 15:07:41,132 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2021-12-17 15:07:41,132 INFO L126 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2021-12-17 15:07:41,143 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:07:41,191 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 21 [2021-12-17 15:07:41,194 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:07:41,204 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 8 [2021-12-17 15:07:41,205 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:07:41,207 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 37 [2021-12-17 15:07:41,208 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:07:41,214 INFO L134 CoverageAnalysis]: Checked inductivity of 0 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2021-12-17 15:07:41,214 INFO L139 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2021-12-17 15:07:41,214 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [960602642] [2021-12-17 15:07:41,215 INFO L160 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [960602642] provided 1 perfect and 0 imperfect interpolant sequences [2021-12-17 15:07:41,215 INFO L186 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2021-12-17 15:07:41,215 INFO L199 FreeRefinementEngine]: Number of different interpolants: perfect sequences [7] imperfect sequences [] total 7 [2021-12-17 15:07:41,215 INFO L115 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [1693755742] [2021-12-17 15:07:41,215 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2021-12-17 15:07:41,215 INFO L546 AbstractCegarLoop]: INTERPOLANT automaton has 7 states [2021-12-17 15:07:41,215 INFO L103 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2021-12-17 15:07:41,216 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 7 interpolants. [2021-12-17 15:07:41,216 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=11, Invalid=31, Unknown=0, NotChecked=0, Total=42 [2021-12-17 15:07:41,216 INFO L87 Difference]: Start difference. First operand 153 states and 188 transitions. Second operand has 7 states, 7 states have (on average 5.714285714285714) internal successors, (40), 5 states have internal predecessors, (40), 2 states have call successors, (4), 3 states have call predecessors, (4), 2 states have return successors, (3), 3 states have call predecessors, (3), 2 states have call successors, (3) [2021-12-17 15:07:41,418 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2021-12-17 15:07:41,419 INFO L93 Difference]: Finished difference Result 443 states and 552 transitions. [2021-12-17 15:07:41,420 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 13 states. [2021-12-17 15:07:41,420 INFO L78 Accepts]: Start accepts. Automaton has has 7 states, 7 states have (on average 5.714285714285714) internal successors, (40), 5 states have internal predecessors, (40), 2 states have call successors, (4), 3 states have call predecessors, (4), 2 states have return successors, (3), 3 states have call predecessors, (3), 2 states have call successors, (3) Word has length 47 [2021-12-17 15:07:41,420 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2021-12-17 15:07:41,424 INFO L225 Difference]: With dead ends: 443 [2021-12-17 15:07:41,424 INFO L226 Difference]: Without dead ends: 298 [2021-12-17 15:07:41,426 INFO L932 BasicCegarLoop]: 0 DeclaredPredicates, 19 GetRequests, 6 SyntacticMatches, 0 SemanticMatches, 13 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 23 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=53, Invalid=157, Unknown=0, NotChecked=0, Total=210 [2021-12-17 15:07:41,430 INFO L933 BasicCegarLoop]: 97 mSDtfsCounter, 148 mSDsluCounter, 349 mSDsCounter, 0 mSdLazyCounter, 209 mSolverCounterSat, 55 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.1s Time, 0 mProtectedPredicate, 0 mProtectedAction, 157 SdHoareTripleChecker+Valid, 446 SdHoareTripleChecker+Invalid, 264 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 55 IncrementalHoareTripleChecker+Valid, 209 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.1s IncrementalHoareTripleChecker+Time [2021-12-17 15:07:41,430 INFO L934 BasicCegarLoop]: SdHoareTripleChecker [157 Valid, 446 Invalid, 264 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [55 Valid, 209 Invalid, 0 Unknown, 0 Unchecked, 0.1s Time] [2021-12-17 15:07:41,432 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 298 states. [2021-12-17 15:07:41,454 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 298 to 284. [2021-12-17 15:07:41,454 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 284 states, 211 states have (on average 1.2274881516587677) internal successors, (259), 226 states have internal predecessors, (259), 36 states have call successors, (36), 30 states have call predecessors, (36), 36 states have return successors, (48), 38 states have call predecessors, (48), 36 states have call successors, (48) [2021-12-17 15:07:41,455 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 284 states to 284 states and 343 transitions. [2021-12-17 15:07:41,456 INFO L78 Accepts]: Start accepts. Automaton has 284 states and 343 transitions. Word has length 47 [2021-12-17 15:07:41,456 INFO L84 Accepts]: Finished accepts. word is rejected. [2021-12-17 15:07:41,456 INFO L470 AbstractCegarLoop]: Abstraction has 284 states and 343 transitions. [2021-12-17 15:07:41,456 INFO L471 AbstractCegarLoop]: INTERPOLANT automaton has has 7 states, 7 states have (on average 5.714285714285714) internal successors, (40), 5 states have internal predecessors, (40), 2 states have call successors, (4), 3 states have call predecessors, (4), 2 states have return successors, (3), 3 states have call predecessors, (3), 2 states have call successors, (3) [2021-12-17 15:07:41,456 INFO L276 IsEmpty]: Start isEmpty. Operand 284 states and 343 transitions. [2021-12-17 15:07:41,457 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 52 [2021-12-17 15:07:41,457 INFO L506 BasicCegarLoop]: Found error trace [2021-12-17 15:07:41,457 INFO L514 BasicCegarLoop]: trace histogram [1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2021-12-17 15:07:41,457 WARN L452 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable4 [2021-12-17 15:07:41,457 INFO L402 AbstractCegarLoop]: === Iteration 6 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2021-12-17 15:07:41,458 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2021-12-17 15:07:41,458 INFO L85 PathProgramCache]: Analyzing trace with hash 858621823, now seen corresponding path program 1 times [2021-12-17 15:07:41,458 INFO L121 FreeRefinementEngine]: Executing refinement strategy CAMEL [2021-12-17 15:07:41,458 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [296362629] [2021-12-17 15:07:41,458 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2021-12-17 15:07:41,458 INFO L126 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2021-12-17 15:07:41,467 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:07:41,496 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 14 [2021-12-17 15:07:41,497 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:07:41,503 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 25 [2021-12-17 15:07:41,505 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:07:41,509 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 8 [2021-12-17 15:07:41,510 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:07:41,511 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 41 [2021-12-17 15:07:41,512 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:07:41,514 INFO L134 CoverageAnalysis]: Checked inductivity of 0 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2021-12-17 15:07:41,514 INFO L139 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2021-12-17 15:07:41,514 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [296362629] [2021-12-17 15:07:41,514 INFO L160 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [296362629] provided 1 perfect and 0 imperfect interpolant sequences [2021-12-17 15:07:41,514 INFO L186 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2021-12-17 15:07:41,514 INFO L199 FreeRefinementEngine]: Number of different interpolants: perfect sequences [7] imperfect sequences [] total 7 [2021-12-17 15:07:41,514 INFO L115 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [137998827] [2021-12-17 15:07:41,514 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2021-12-17 15:07:41,515 INFO L546 AbstractCegarLoop]: INTERPOLANT automaton has 7 states [2021-12-17 15:07:41,515 INFO L103 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2021-12-17 15:07:41,515 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 7 interpolants. [2021-12-17 15:07:41,515 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=11, Invalid=31, Unknown=0, NotChecked=0, Total=42 [2021-12-17 15:07:41,515 INFO L87 Difference]: Start difference. First operand 284 states and 343 transitions. Second operand has 7 states, 7 states have (on average 6.0) internal successors, (42), 5 states have internal predecessors, (42), 1 states have call successors, (5), 4 states have call predecessors, (5), 2 states have return successors, (4), 1 states have call predecessors, (4), 1 states have call successors, (4) [2021-12-17 15:07:41,807 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2021-12-17 15:07:41,807 INFO L93 Difference]: Finished difference Result 572 states and 692 transitions. [2021-12-17 15:07:41,807 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 15 states. [2021-12-17 15:07:41,808 INFO L78 Accepts]: Start accepts. Automaton has has 7 states, 7 states have (on average 6.0) internal successors, (42), 5 states have internal predecessors, (42), 1 states have call successors, (5), 4 states have call predecessors, (5), 2 states have return successors, (4), 1 states have call predecessors, (4), 1 states have call successors, (4) Word has length 51 [2021-12-17 15:07:41,808 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2021-12-17 15:07:41,809 INFO L225 Difference]: With dead ends: 572 [2021-12-17 15:07:41,809 INFO L226 Difference]: Without dead ends: 296 [2021-12-17 15:07:41,810 INFO L932 BasicCegarLoop]: 0 DeclaredPredicates, 28 GetRequests, 13 SyntacticMatches, 0 SemanticMatches, 15 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 35 ImplicationChecksByTransitivity, 0.1s TimeCoverageRelationStatistics Valid=84, Invalid=188, Unknown=0, NotChecked=0, Total=272 [2021-12-17 15:07:41,810 INFO L933 BasicCegarLoop]: 101 mSDtfsCounter, 187 mSDsluCounter, 151 mSDsCounter, 0 mSdLazyCounter, 336 mSolverCounterSat, 70 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.1s Time, 0 mProtectedPredicate, 0 mProtectedAction, 189 SdHoareTripleChecker+Valid, 252 SdHoareTripleChecker+Invalid, 406 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 70 IncrementalHoareTripleChecker+Valid, 336 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.2s IncrementalHoareTripleChecker+Time [2021-12-17 15:07:41,810 INFO L934 BasicCegarLoop]: SdHoareTripleChecker [189 Valid, 252 Invalid, 406 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [70 Valid, 336 Invalid, 0 Unknown, 0 Unchecked, 0.2s Time] [2021-12-17 15:07:41,811 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 296 states. [2021-12-17 15:07:41,835 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 296 to 282. [2021-12-17 15:07:41,836 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 282 states, 209 states have (on average 1.2105263157894737) internal successors, (253), 224 states have internal predecessors, (253), 36 states have call successors, (36), 30 states have call predecessors, (36), 36 states have return successors, (48), 38 states have call predecessors, (48), 36 states have call successors, (48) [2021-12-17 15:07:41,837 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 282 states to 282 states and 337 transitions. [2021-12-17 15:07:41,837 INFO L78 Accepts]: Start accepts. Automaton has 282 states and 337 transitions. Word has length 51 [2021-12-17 15:07:41,838 INFO L84 Accepts]: Finished accepts. word is rejected. [2021-12-17 15:07:41,838 INFO L470 AbstractCegarLoop]: Abstraction has 282 states and 337 transitions. [2021-12-17 15:07:41,838 INFO L471 AbstractCegarLoop]: INTERPOLANT automaton has has 7 states, 7 states have (on average 6.0) internal successors, (42), 5 states have internal predecessors, (42), 1 states have call successors, (5), 4 states have call predecessors, (5), 2 states have return successors, (4), 1 states have call predecessors, (4), 1 states have call successors, (4) [2021-12-17 15:07:41,838 INFO L276 IsEmpty]: Start isEmpty. Operand 282 states and 337 transitions. [2021-12-17 15:07:41,839 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 62 [2021-12-17 15:07:41,839 INFO L506 BasicCegarLoop]: Found error trace [2021-12-17 15:07:41,839 INFO L514 BasicCegarLoop]: trace histogram [2, 2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2021-12-17 15:07:41,839 WARN L452 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable5 [2021-12-17 15:07:41,840 INFO L402 AbstractCegarLoop]: === Iteration 7 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2021-12-17 15:07:41,840 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2021-12-17 15:07:41,840 INFO L85 PathProgramCache]: Analyzing trace with hash 1850253156, now seen corresponding path program 1 times [2021-12-17 15:07:41,840 INFO L121 FreeRefinementEngine]: Executing refinement strategy CAMEL [2021-12-17 15:07:41,840 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [482306899] [2021-12-17 15:07:41,840 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2021-12-17 15:07:41,840 INFO L126 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2021-12-17 15:07:41,849 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:07:41,861 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 14 [2021-12-17 15:07:41,862 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:07:41,868 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 25 [2021-12-17 15:07:41,871 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:07:41,890 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 8 [2021-12-17 15:07:41,893 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:07:41,895 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 1 [2021-12-17 15:07:41,896 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:07:41,898 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 51 [2021-12-17 15:07:41,899 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:07:41,904 INFO L134 CoverageAnalysis]: Checked inductivity of 3 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 3 trivial. 0 not checked. [2021-12-17 15:07:41,904 INFO L139 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2021-12-17 15:07:41,904 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [482306899] [2021-12-17 15:07:41,904 INFO L160 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [482306899] provided 1 perfect and 0 imperfect interpolant sequences [2021-12-17 15:07:41,904 INFO L186 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2021-12-17 15:07:41,904 INFO L199 FreeRefinementEngine]: Number of different interpolants: perfect sequences [7] imperfect sequences [] total 7 [2021-12-17 15:07:41,904 INFO L115 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [1345704982] [2021-12-17 15:07:41,905 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2021-12-17 15:07:41,906 INFO L546 AbstractCegarLoop]: INTERPOLANT automaton has 7 states [2021-12-17 15:07:41,906 INFO L103 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2021-12-17 15:07:41,906 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 7 interpolants. [2021-12-17 15:07:41,906 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=11, Invalid=31, Unknown=0, NotChecked=0, Total=42 [2021-12-17 15:07:41,906 INFO L87 Difference]: Start difference. First operand 282 states and 337 transitions. Second operand has 7 states, 7 states have (on average 6.857142857142857) internal successors, (48), 5 states have internal predecessors, (48), 2 states have call successors, (6), 3 states have call predecessors, (6), 2 states have return successors, (5), 2 states have call predecessors, (5), 2 states have call successors, (5) [2021-12-17 15:07:42,118 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2021-12-17 15:07:42,118 INFO L93 Difference]: Finished difference Result 574 states and 699 transitions. [2021-12-17 15:07:42,119 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 9 states. [2021-12-17 15:07:42,119 INFO L78 Accepts]: Start accepts. Automaton has has 7 states, 7 states have (on average 6.857142857142857) internal successors, (48), 5 states have internal predecessors, (48), 2 states have call successors, (6), 3 states have call predecessors, (6), 2 states have return successors, (5), 2 states have call predecessors, (5), 2 states have call successors, (5) Word has length 61 [2021-12-17 15:07:42,119 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2021-12-17 15:07:42,120 INFO L225 Difference]: With dead ends: 574 [2021-12-17 15:07:42,120 INFO L226 Difference]: Without dead ends: 300 [2021-12-17 15:07:42,121 INFO L932 BasicCegarLoop]: 0 DeclaredPredicates, 22 GetRequests, 12 SyntacticMatches, 0 SemanticMatches, 10 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 3 ImplicationChecksByTransitivity, 0.1s TimeCoverageRelationStatistics Valid=46, Invalid=86, Unknown=0, NotChecked=0, Total=132 [2021-12-17 15:07:42,121 INFO L933 BasicCegarLoop]: 91 mSDtfsCounter, 122 mSDsluCounter, 155 mSDsCounter, 0 mSdLazyCounter, 281 mSolverCounterSat, 52 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.1s Time, 0 mProtectedPredicate, 0 mProtectedAction, 123 SdHoareTripleChecker+Valid, 246 SdHoareTripleChecker+Invalid, 333 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 52 IncrementalHoareTripleChecker+Valid, 281 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.1s IncrementalHoareTripleChecker+Time [2021-12-17 15:07:42,122 INFO L934 BasicCegarLoop]: SdHoareTripleChecker [123 Valid, 246 Invalid, 333 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [52 Valid, 281 Invalid, 0 Unknown, 0 Unchecked, 0.1s Time] [2021-12-17 15:07:42,122 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 300 states. [2021-12-17 15:07:42,131 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 300 to 288. [2021-12-17 15:07:42,132 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 288 states, 215 states have (on average 1.2046511627906977) internal successors, (259), 230 states have internal predecessors, (259), 36 states have call successors, (36), 30 states have call predecessors, (36), 36 states have return successors, (48), 38 states have call predecessors, (48), 36 states have call successors, (48) [2021-12-17 15:07:42,133 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 288 states to 288 states and 343 transitions. [2021-12-17 15:07:42,133 INFO L78 Accepts]: Start accepts. Automaton has 288 states and 343 transitions. Word has length 61 [2021-12-17 15:07:42,133 INFO L84 Accepts]: Finished accepts. word is rejected. [2021-12-17 15:07:42,133 INFO L470 AbstractCegarLoop]: Abstraction has 288 states and 343 transitions. [2021-12-17 15:07:42,133 INFO L471 AbstractCegarLoop]: INTERPOLANT automaton has has 7 states, 7 states have (on average 6.857142857142857) internal successors, (48), 5 states have internal predecessors, (48), 2 states have call successors, (6), 3 states have call predecessors, (6), 2 states have return successors, (5), 2 states have call predecessors, (5), 2 states have call successors, (5) [2021-12-17 15:07:42,134 INFO L276 IsEmpty]: Start isEmpty. Operand 288 states and 343 transitions. [2021-12-17 15:07:42,134 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 62 [2021-12-17 15:07:42,134 INFO L506 BasicCegarLoop]: Found error trace [2021-12-17 15:07:42,135 INFO L514 BasicCegarLoop]: trace histogram [2, 2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2021-12-17 15:07:42,135 WARN L452 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable6 [2021-12-17 15:07:42,135 INFO L402 AbstractCegarLoop]: === Iteration 8 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2021-12-17 15:07:42,135 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2021-12-17 15:07:42,135 INFO L85 PathProgramCache]: Analyzing trace with hash -1743114266, now seen corresponding path program 1 times [2021-12-17 15:07:42,135 INFO L121 FreeRefinementEngine]: Executing refinement strategy CAMEL [2021-12-17 15:07:42,135 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [589854731] [2021-12-17 15:07:42,135 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2021-12-17 15:07:42,135 INFO L126 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2021-12-17 15:07:42,143 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:07:42,161 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 14 [2021-12-17 15:07:42,162 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:07:42,166 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 25 [2021-12-17 15:07:42,168 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:07:42,183 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 8 [2021-12-17 15:07:42,184 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:07:42,187 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 1 [2021-12-17 15:07:42,188 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:07:42,192 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 51 [2021-12-17 15:07:42,193 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:07:42,195 INFO L134 CoverageAnalysis]: Checked inductivity of 3 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 3 trivial. 0 not checked. [2021-12-17 15:07:42,195 INFO L139 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2021-12-17 15:07:42,195 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [589854731] [2021-12-17 15:07:42,195 INFO L160 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [589854731] provided 1 perfect and 0 imperfect interpolant sequences [2021-12-17 15:07:42,195 INFO L186 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2021-12-17 15:07:42,195 INFO L199 FreeRefinementEngine]: Number of different interpolants: perfect sequences [6] imperfect sequences [] total 6 [2021-12-17 15:07:42,195 INFO L115 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [147082776] [2021-12-17 15:07:42,195 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2021-12-17 15:07:42,195 INFO L546 AbstractCegarLoop]: INTERPOLANT automaton has 6 states [2021-12-17 15:07:42,196 INFO L103 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2021-12-17 15:07:42,196 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 6 interpolants. [2021-12-17 15:07:42,196 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=9, Invalid=21, Unknown=0, NotChecked=0, Total=30 [2021-12-17 15:07:42,196 INFO L87 Difference]: Start difference. First operand 288 states and 343 transitions. Second operand has 6 states, 6 states have (on average 8.0) internal successors, (48), 4 states have internal predecessors, (48), 2 states have call successors, (6), 3 states have call predecessors, (6), 2 states have return successors, (5), 2 states have call predecessors, (5), 2 states have call successors, (5) [2021-12-17 15:07:42,330 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2021-12-17 15:07:42,331 INFO L93 Difference]: Finished difference Result 586 states and 711 transitions. [2021-12-17 15:07:42,331 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 7 states. [2021-12-17 15:07:42,331 INFO L78 Accepts]: Start accepts. Automaton has has 6 states, 6 states have (on average 8.0) internal successors, (48), 4 states have internal predecessors, (48), 2 states have call successors, (6), 3 states have call predecessors, (6), 2 states have return successors, (5), 2 states have call predecessors, (5), 2 states have call successors, (5) Word has length 61 [2021-12-17 15:07:42,331 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2021-12-17 15:07:42,333 INFO L225 Difference]: With dead ends: 586 [2021-12-17 15:07:42,333 INFO L226 Difference]: Without dead ends: 306 [2021-12-17 15:07:42,334 INFO L932 BasicCegarLoop]: 0 DeclaredPredicates, 19 GetRequests, 12 SyntacticMatches, 0 SemanticMatches, 7 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 0 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=27, Invalid=45, Unknown=0, NotChecked=0, Total=72 [2021-12-17 15:07:42,335 INFO L933 BasicCegarLoop]: 91 mSDtfsCounter, 128 mSDsluCounter, 118 mSDsCounter, 0 mSdLazyCounter, 203 mSolverCounterSat, 49 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.1s Time, 0 mProtectedPredicate, 0 mProtectedAction, 129 SdHoareTripleChecker+Valid, 209 SdHoareTripleChecker+Invalid, 252 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 49 IncrementalHoareTripleChecker+Valid, 203 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.1s IncrementalHoareTripleChecker+Time [2021-12-17 15:07:42,335 INFO L934 BasicCegarLoop]: SdHoareTripleChecker [129 Valid, 209 Invalid, 252 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [49 Valid, 203 Invalid, 0 Unknown, 0 Unchecked, 0.1s Time] [2021-12-17 15:07:42,335 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 306 states. [2021-12-17 15:07:42,346 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 306 to 292. [2021-12-17 15:07:42,347 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 292 states, 219 states have (on average 1.2009132420091324) internal successors, (263), 234 states have internal predecessors, (263), 36 states have call successors, (36), 30 states have call predecessors, (36), 36 states have return successors, (48), 38 states have call predecessors, (48), 36 states have call successors, (48) [2021-12-17 15:07:42,349 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 292 states to 292 states and 347 transitions. [2021-12-17 15:07:42,350 INFO L78 Accepts]: Start accepts. Automaton has 292 states and 347 transitions. Word has length 61 [2021-12-17 15:07:42,350 INFO L84 Accepts]: Finished accepts. word is rejected. [2021-12-17 15:07:42,350 INFO L470 AbstractCegarLoop]: Abstraction has 292 states and 347 transitions. [2021-12-17 15:07:42,350 INFO L471 AbstractCegarLoop]: INTERPOLANT automaton has has 6 states, 6 states have (on average 8.0) internal successors, (48), 4 states have internal predecessors, (48), 2 states have call successors, (6), 3 states have call predecessors, (6), 2 states have return successors, (5), 2 states have call predecessors, (5), 2 states have call successors, (5) [2021-12-17 15:07:42,350 INFO L276 IsEmpty]: Start isEmpty. Operand 292 states and 347 transitions. [2021-12-17 15:07:42,352 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 62 [2021-12-17 15:07:42,352 INFO L506 BasicCegarLoop]: Found error trace [2021-12-17 15:07:42,352 INFO L514 BasicCegarLoop]: trace histogram [2, 2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2021-12-17 15:07:42,352 WARN L452 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable7 [2021-12-17 15:07:42,352 INFO L402 AbstractCegarLoop]: === Iteration 9 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2021-12-17 15:07:42,353 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2021-12-17 15:07:42,353 INFO L85 PathProgramCache]: Analyzing trace with hash -1815500824, now seen corresponding path program 1 times [2021-12-17 15:07:42,353 INFO L121 FreeRefinementEngine]: Executing refinement strategy CAMEL [2021-12-17 15:07:42,353 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [1608795299] [2021-12-17 15:07:42,353 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2021-12-17 15:07:42,353 INFO L126 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2021-12-17 15:07:42,366 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:07:42,393 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 14 [2021-12-17 15:07:42,394 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:07:42,398 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 25 [2021-12-17 15:07:42,400 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:07:42,419 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 8 [2021-12-17 15:07:42,421 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:07:42,425 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 1 [2021-12-17 15:07:42,425 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:07:42,427 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 51 [2021-12-17 15:07:42,428 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:07:42,430 INFO L134 CoverageAnalysis]: Checked inductivity of 3 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 3 trivial. 0 not checked. [2021-12-17 15:07:42,430 INFO L139 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2021-12-17 15:07:42,430 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [1608795299] [2021-12-17 15:07:42,430 INFO L160 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [1608795299] provided 1 perfect and 0 imperfect interpolant sequences [2021-12-17 15:07:42,430 INFO L186 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2021-12-17 15:07:42,430 INFO L199 FreeRefinementEngine]: Number of different interpolants: perfect sequences [6] imperfect sequences [] total 6 [2021-12-17 15:07:42,430 INFO L115 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [2146751806] [2021-12-17 15:07:42,431 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2021-12-17 15:07:42,431 INFO L546 AbstractCegarLoop]: INTERPOLANT automaton has 6 states [2021-12-17 15:07:42,431 INFO L103 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2021-12-17 15:07:42,432 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 6 interpolants. [2021-12-17 15:07:42,432 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=9, Invalid=21, Unknown=0, NotChecked=0, Total=30 [2021-12-17 15:07:42,432 INFO L87 Difference]: Start difference. First operand 292 states and 347 transitions. Second operand has 6 states, 6 states have (on average 8.0) internal successors, (48), 4 states have internal predecessors, (48), 4 states have call successors, (6), 4 states have call predecessors, (6), 2 states have return successors, (5), 4 states have call predecessors, (5), 4 states have call successors, (5) [2021-12-17 15:07:42,657 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2021-12-17 15:07:42,658 INFO L93 Difference]: Finished difference Result 804 states and 1007 transitions. [2021-12-17 15:07:42,658 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 12 states. [2021-12-17 15:07:42,658 INFO L78 Accepts]: Start accepts. Automaton has has 6 states, 6 states have (on average 8.0) internal successors, (48), 4 states have internal predecessors, (48), 4 states have call successors, (6), 4 states have call predecessors, (6), 2 states have return successors, (5), 4 states have call predecessors, (5), 4 states have call successors, (5) Word has length 61 [2021-12-17 15:07:42,658 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2021-12-17 15:07:42,660 INFO L225 Difference]: With dead ends: 804 [2021-12-17 15:07:42,660 INFO L226 Difference]: Without dead ends: 520 [2021-12-17 15:07:42,661 INFO L932 BasicCegarLoop]: 0 DeclaredPredicates, 25 GetRequests, 15 SyntacticMatches, 0 SemanticMatches, 10 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 15 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=40, Invalid=92, Unknown=0, NotChecked=0, Total=132 [2021-12-17 15:07:42,662 INFO L933 BasicCegarLoop]: 135 mSDtfsCounter, 298 mSDsluCounter, 124 mSDsCounter, 0 mSdLazyCounter, 253 mSolverCounterSat, 129 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.1s Time, 0 mProtectedPredicate, 0 mProtectedAction, 300 SdHoareTripleChecker+Valid, 259 SdHoareTripleChecker+Invalid, 382 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 129 IncrementalHoareTripleChecker+Valid, 253 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.2s IncrementalHoareTripleChecker+Time [2021-12-17 15:07:42,662 INFO L934 BasicCegarLoop]: SdHoareTripleChecker [300 Valid, 259 Invalid, 382 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [129 Valid, 253 Invalid, 0 Unknown, 0 Unchecked, 0.2s Time] [2021-12-17 15:07:42,662 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 520 states. [2021-12-17 15:07:42,677 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 520 to 518. [2021-12-17 15:07:42,678 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 518 states, 389 states have (on average 1.19280205655527) internal successors, (464), 412 states have internal predecessors, (464), 66 states have call successors, (66), 60 states have call predecessors, (66), 62 states have return successors, (101), 66 states have call predecessors, (101), 66 states have call successors, (101) [2021-12-17 15:07:42,680 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 518 states to 518 states and 631 transitions. [2021-12-17 15:07:42,680 INFO L78 Accepts]: Start accepts. Automaton has 518 states and 631 transitions. Word has length 61 [2021-12-17 15:07:42,680 INFO L84 Accepts]: Finished accepts. word is rejected. [2021-12-17 15:07:42,681 INFO L470 AbstractCegarLoop]: Abstraction has 518 states and 631 transitions. [2021-12-17 15:07:42,681 INFO L471 AbstractCegarLoop]: INTERPOLANT automaton has has 6 states, 6 states have (on average 8.0) internal successors, (48), 4 states have internal predecessors, (48), 4 states have call successors, (6), 4 states have call predecessors, (6), 2 states have return successors, (5), 4 states have call predecessors, (5), 4 states have call successors, (5) [2021-12-17 15:07:42,681 INFO L276 IsEmpty]: Start isEmpty. Operand 518 states and 631 transitions. [2021-12-17 15:07:42,682 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 66 [2021-12-17 15:07:42,682 INFO L506 BasicCegarLoop]: Found error trace [2021-12-17 15:07:42,682 INFO L514 BasicCegarLoop]: trace histogram [2, 2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2021-12-17 15:07:42,682 WARN L452 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable8 [2021-12-17 15:07:42,682 INFO L402 AbstractCegarLoop]: === Iteration 10 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2021-12-17 15:07:42,683 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2021-12-17 15:07:42,683 INFO L85 PathProgramCache]: Analyzing trace with hash -1657207794, now seen corresponding path program 1 times [2021-12-17 15:07:42,683 INFO L121 FreeRefinementEngine]: Executing refinement strategy CAMEL [2021-12-17 15:07:42,683 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [1528228574] [2021-12-17 15:07:42,683 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2021-12-17 15:07:42,683 INFO L126 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2021-12-17 15:07:42,690 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:07:42,726 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 12 [2021-12-17 15:07:42,727 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:07:42,732 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 18 [2021-12-17 15:07:42,733 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:07:42,743 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 29 [2021-12-17 15:07:42,746 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:07:42,770 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 8 [2021-12-17 15:07:42,772 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:07:42,787 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 1 [2021-12-17 15:07:42,788 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:07:42,798 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 55 [2021-12-17 15:07:42,799 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:07:42,804 INFO L134 CoverageAnalysis]: Checked inductivity of 3 backedges. 0 proven. 2 refuted. 0 times theorem prover too weak. 1 trivial. 0 not checked. [2021-12-17 15:07:42,805 INFO L139 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2021-12-17 15:07:42,805 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [1528228574] [2021-12-17 15:07:42,805 INFO L160 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [1528228574] provided 0 perfect and 1 imperfect interpolant sequences [2021-12-17 15:07:42,805 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleZ3 [2056154985] [2021-12-17 15:07:42,805 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2021-12-17 15:07:42,805 INFO L168 SolverBuilder]: Constructing external solver with command: z3 -smt2 -in SMTLIB2_COMPLIANT=true [2021-12-17 15:07:42,806 INFO L189 MonitoredProcess]: No working directory specified, using /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 [2021-12-17 15:07:42,811 INFO L229 MonitoredProcess]: Starting monitored process 2 with /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 -smt2 -in SMTLIB2_COMPLIANT=true (exit command is (exit), workingDir is null) [2021-12-17 15:07:42,859 INFO L327 MonitoredProcess]: [MP /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 -smt2 -in SMTLIB2_COMPLIANT=true (2)] Waiting until timeout for monitored process [2021-12-17 15:07:42,897 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:07:42,900 INFO L263 TraceCheckSpWp]: Trace formula consists of 397 conjuncts, 9 conjunts are in the unsatisfiable core [2021-12-17 15:07:42,904 INFO L286 TraceCheckSpWp]: Computing forward predicates... [2021-12-17 15:07:43,203 INFO L134 CoverageAnalysis]: Checked inductivity of 3 backedges. 3 proven. 0 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2021-12-17 15:07:43,203 INFO L324 TraceCheckSpWp]: Omiting computation of backward sequence because forward sequence was already perfect [2021-12-17 15:07:43,203 INFO L160 FreeRefinementEngine]: IpTcStrategyModuleZ3 [2056154985] provided 1 perfect and 0 imperfect interpolant sequences [2021-12-17 15:07:43,203 INFO L186 FreeRefinementEngine]: Found 1 perfect and 1 imperfect interpolant sequences. [2021-12-17 15:07:43,203 INFO L199 FreeRefinementEngine]: Number of different interpolants: perfect sequences [8] imperfect sequences [15] total 20 [2021-12-17 15:07:43,203 INFO L115 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [783877774] [2021-12-17 15:07:43,203 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2021-12-17 15:07:43,204 INFO L546 AbstractCegarLoop]: INTERPOLANT automaton has 8 states [2021-12-17 15:07:43,204 INFO L103 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2021-12-17 15:07:43,204 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 8 interpolants. [2021-12-17 15:07:43,204 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=48, Invalid=332, Unknown=0, NotChecked=0, Total=380 [2021-12-17 15:07:43,204 INFO L87 Difference]: Start difference. First operand 518 states and 631 transitions. Second operand has 8 states, 8 states have (on average 6.5) internal successors, (52), 6 states have internal predecessors, (52), 3 states have call successors, (7), 3 states have call predecessors, (7), 5 states have return successors, (6), 5 states have call predecessors, (6), 3 states have call successors, (6) [2021-12-17 15:07:43,284 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2021-12-17 15:07:43,284 INFO L93 Difference]: Finished difference Result 1006 states and 1230 transitions. [2021-12-17 15:07:43,284 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 8 states. [2021-12-17 15:07:43,285 INFO L78 Accepts]: Start accepts. Automaton has has 8 states, 8 states have (on average 6.5) internal successors, (52), 6 states have internal predecessors, (52), 3 states have call successors, (7), 3 states have call predecessors, (7), 5 states have return successors, (6), 5 states have call predecessors, (6), 3 states have call successors, (6) Word has length 65 [2021-12-17 15:07:43,285 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2021-12-17 15:07:43,287 INFO L225 Difference]: With dead ends: 1006 [2021-12-17 15:07:43,287 INFO L226 Difference]: Without dead ends: 496 [2021-12-17 15:07:43,288 INFO L932 BasicCegarLoop]: 0 DeclaredPredicates, 87 GetRequests, 69 SyntacticMatches, 0 SemanticMatches, 18 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 7 ImplicationChecksByTransitivity, 0.1s TimeCoverageRelationStatistics Valid=48, Invalid=332, Unknown=0, NotChecked=0, Total=380 [2021-12-17 15:07:43,288 INFO L933 BasicCegarLoop]: 175 mSDtfsCounter, 61 mSDsluCounter, 648 mSDsCounter, 0 mSdLazyCounter, 158 mSolverCounterSat, 3 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.0s Time, 0 mProtectedPredicate, 0 mProtectedAction, 65 SdHoareTripleChecker+Valid, 823 SdHoareTripleChecker+Invalid, 161 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 3 IncrementalHoareTripleChecker+Valid, 158 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.1s IncrementalHoareTripleChecker+Time [2021-12-17 15:07:43,289 INFO L934 BasicCegarLoop]: SdHoareTripleChecker [65 Valid, 823 Invalid, 161 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [3 Valid, 158 Invalid, 0 Unknown, 0 Unchecked, 0.1s Time] [2021-12-17 15:07:43,289 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 496 states. [2021-12-17 15:07:43,302 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 496 to 494. [2021-12-17 15:07:43,303 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 494 states, 370 states have (on average 1.1756756756756757) internal successors, (435), 392 states have internal predecessors, (435), 64 states have call successors, (64), 58 states have call predecessors, (64), 59 states have return successors, (88), 63 states have call predecessors, (88), 64 states have call successors, (88) [2021-12-17 15:07:43,305 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 494 states to 494 states and 587 transitions. [2021-12-17 15:07:43,305 INFO L78 Accepts]: Start accepts. Automaton has 494 states and 587 transitions. Word has length 65 [2021-12-17 15:07:43,305 INFO L84 Accepts]: Finished accepts. word is rejected. [2021-12-17 15:07:43,305 INFO L470 AbstractCegarLoop]: Abstraction has 494 states and 587 transitions. [2021-12-17 15:07:43,306 INFO L471 AbstractCegarLoop]: INTERPOLANT automaton has has 8 states, 8 states have (on average 6.5) internal successors, (52), 6 states have internal predecessors, (52), 3 states have call successors, (7), 3 states have call predecessors, (7), 5 states have return successors, (6), 5 states have call predecessors, (6), 3 states have call successors, (6) [2021-12-17 15:07:43,306 INFO L276 IsEmpty]: Start isEmpty. Operand 494 states and 587 transitions. [2021-12-17 15:07:43,307 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 111 [2021-12-17 15:07:43,307 INFO L506 BasicCegarLoop]: Found error trace [2021-12-17 15:07:43,307 INFO L514 BasicCegarLoop]: trace histogram [4, 4, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2021-12-17 15:07:43,326 INFO L540 MonitoredProcess]: [MP /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 -smt2 -in SMTLIB2_COMPLIANT=true (2)] Forceful destruction successful, exit code 0 [2021-12-17 15:07:43,524 WARN L452 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: 2 /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 -smt2 -in SMTLIB2_COMPLIANT=true,SelfDestructingSolverStorable9 [2021-12-17 15:07:43,524 INFO L402 AbstractCegarLoop]: === Iteration 11 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2021-12-17 15:07:43,524 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2021-12-17 15:07:43,525 INFO L85 PathProgramCache]: Analyzing trace with hash 1520356328, now seen corresponding path program 1 times [2021-12-17 15:07:43,525 INFO L121 FreeRefinementEngine]: Executing refinement strategy CAMEL [2021-12-17 15:07:43,525 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [719536213] [2021-12-17 15:07:43,525 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2021-12-17 15:07:43,525 INFO L126 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2021-12-17 15:07:43,534 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:07:43,571 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 12 [2021-12-17 15:07:43,572 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:07:43,580 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 21 [2021-12-17 15:07:43,582 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:07:43,592 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 3 [2021-12-17 15:07:43,593 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:07:43,596 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 8 [2021-12-17 15:07:43,596 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:07:43,600 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 1 [2021-12-17 15:07:43,600 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:07:43,602 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 29 [2021-12-17 15:07:43,602 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:07:43,608 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 66 [2021-12-17 15:07:43,609 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:07:43,622 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 79 [2021-12-17 15:07:43,623 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:07:43,654 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 1 [2021-12-17 15:07:43,656 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:07:43,666 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 90 [2021-12-17 15:07:43,667 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:07:43,668 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 2 [2021-12-17 15:07:43,669 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:07:43,670 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 100 [2021-12-17 15:07:43,670 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:07:43,671 INFO L134 CoverageAnalysis]: Checked inductivity of 45 backedges. 18 proven. 3 refuted. 0 times theorem prover too weak. 24 trivial. 0 not checked. [2021-12-17 15:07:43,672 INFO L139 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2021-12-17 15:07:43,672 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [719536213] [2021-12-17 15:07:43,672 INFO L160 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [719536213] provided 0 perfect and 1 imperfect interpolant sequences [2021-12-17 15:07:43,672 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleZ3 [1400314262] [2021-12-17 15:07:43,672 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2021-12-17 15:07:43,672 INFO L168 SolverBuilder]: Constructing external solver with command: z3 -smt2 -in SMTLIB2_COMPLIANT=true [2021-12-17 15:07:43,672 INFO L189 MonitoredProcess]: No working directory specified, using /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 [2021-12-17 15:07:43,673 INFO L229 MonitoredProcess]: Starting monitored process 3 with /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 -smt2 -in SMTLIB2_COMPLIANT=true (exit command is (exit), workingDir is null) [2021-12-17 15:07:43,674 INFO L327 MonitoredProcess]: [MP /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 -smt2 -in SMTLIB2_COMPLIANT=true (3)] Waiting until timeout for monitored process [2021-12-17 15:07:43,751 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:07:43,753 INFO L263 TraceCheckSpWp]: Trace formula consists of 508 conjuncts, 9 conjunts are in the unsatisfiable core [2021-12-17 15:07:43,756 INFO L286 TraceCheckSpWp]: Computing forward predicates... [2021-12-17 15:07:43,954 INFO L134 CoverageAnalysis]: Checked inductivity of 45 backedges. 36 proven. 0 refuted. 0 times theorem prover too weak. 9 trivial. 0 not checked. [2021-12-17 15:07:43,954 INFO L324 TraceCheckSpWp]: Omiting computation of backward sequence because forward sequence was already perfect [2021-12-17 15:07:43,955 INFO L160 FreeRefinementEngine]: IpTcStrategyModuleZ3 [1400314262] provided 1 perfect and 0 imperfect interpolant sequences [2021-12-17 15:07:43,955 INFO L186 FreeRefinementEngine]: Found 1 perfect and 1 imperfect interpolant sequences. [2021-12-17 15:07:43,955 INFO L199 FreeRefinementEngine]: Number of different interpolants: perfect sequences [8] imperfect sequences [15] total 20 [2021-12-17 15:07:43,955 INFO L115 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [1052728153] [2021-12-17 15:07:43,955 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2021-12-17 15:07:43,956 INFO L546 AbstractCegarLoop]: INTERPOLANT automaton has 8 states [2021-12-17 15:07:43,956 INFO L103 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2021-12-17 15:07:43,956 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 8 interpolants. [2021-12-17 15:07:43,956 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=50, Invalid=330, Unknown=0, NotChecked=0, Total=380 [2021-12-17 15:07:43,956 INFO L87 Difference]: Start difference. First operand 494 states and 587 transitions. Second operand has 8 states, 8 states have (on average 9.875) internal successors, (79), 6 states have internal predecessors, (79), 3 states have call successors, (13), 3 states have call predecessors, (13), 5 states have return successors, (12), 5 states have call predecessors, (12), 3 states have call successors, (12) [2021-12-17 15:07:44,039 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2021-12-17 15:07:44,040 INFO L93 Difference]: Finished difference Result 845 states and 1014 transitions. [2021-12-17 15:07:44,040 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 8 states. [2021-12-17 15:07:44,040 INFO L78 Accepts]: Start accepts. Automaton has has 8 states, 8 states have (on average 9.875) internal successors, (79), 6 states have internal predecessors, (79), 3 states have call successors, (13), 3 states have call predecessors, (13), 5 states have return successors, (12), 5 states have call predecessors, (12), 3 states have call successors, (12) Word has length 110 [2021-12-17 15:07:44,041 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2021-12-17 15:07:44,041 INFO L225 Difference]: With dead ends: 845 [2021-12-17 15:07:44,041 INFO L226 Difference]: Without dead ends: 0 [2021-12-17 15:07:44,042 INFO L932 BasicCegarLoop]: 0 DeclaredPredicates, 146 GetRequests, 126 SyntacticMatches, 0 SemanticMatches, 20 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 43 ImplicationChecksByTransitivity, 0.1s TimeCoverageRelationStatistics Valid=62, Invalid=400, Unknown=0, NotChecked=0, Total=462 [2021-12-17 15:07:44,043 INFO L933 BasicCegarLoop]: 174 mSDtfsCounter, 68 mSDsluCounter, 607 mSDsCounter, 0 mSdLazyCounter, 101 mSolverCounterSat, 4 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.0s Time, 0 mProtectedPredicate, 0 mProtectedAction, 72 SdHoareTripleChecker+Valid, 781 SdHoareTripleChecker+Invalid, 105 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 4 IncrementalHoareTripleChecker+Valid, 101 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.1s IncrementalHoareTripleChecker+Time [2021-12-17 15:07:44,043 INFO L934 BasicCegarLoop]: SdHoareTripleChecker [72 Valid, 781 Invalid, 105 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [4 Valid, 101 Invalid, 0 Unknown, 0 Unchecked, 0.1s Time] [2021-12-17 15:07:44,044 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 0 states. [2021-12-17 15:07:44,044 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 0 to 0. [2021-12-17 15:07:44,044 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 0 states, 0 states have (on average 0.0) internal successors, (0), 0 states have internal predecessors, (0), 0 states have call successors, (0), 0 states have call predecessors, (0), 0 states have return successors, (0), 0 states have call predecessors, (0), 0 states have call successors, (0) [2021-12-17 15:07:44,044 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 0 states to 0 states and 0 transitions. [2021-12-17 15:07:44,044 INFO L78 Accepts]: Start accepts. Automaton has 0 states and 0 transitions. Word has length 110 [2021-12-17 15:07:44,044 INFO L84 Accepts]: Finished accepts. word is rejected. [2021-12-17 15:07:44,045 INFO L470 AbstractCegarLoop]: Abstraction has 0 states and 0 transitions. [2021-12-17 15:07:44,045 INFO L471 AbstractCegarLoop]: INTERPOLANT automaton has has 8 states, 8 states have (on average 9.875) internal successors, (79), 6 states have internal predecessors, (79), 3 states have call successors, (13), 3 states have call predecessors, (13), 5 states have return successors, (12), 5 states have call predecessors, (12), 3 states have call successors, (12) [2021-12-17 15:07:44,045 INFO L276 IsEmpty]: Start isEmpty. Operand 0 states and 0 transitions. [2021-12-17 15:07:44,045 INFO L282 IsEmpty]: Finished isEmpty. No accepting run. [2021-12-17 15:07:44,047 INFO L764 garLoopResultBuilder]: Registering result SAFE for location timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION (0 of 1 remaining) [2021-12-17 15:07:44,078 INFO L540 MonitoredProcess]: [MP /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 -smt2 -in SMTLIB2_COMPLIANT=true (3)] Forceful destruction successful, exit code 0 [2021-12-17 15:07:44,280 WARN L452 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: 3 /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 -smt2 -in SMTLIB2_COMPLIANT=true,SelfDestructingSolverStorable10 [2021-12-17 15:07:44,281 INFO L343 DoubleDeckerVisitor]: Before removal of dead ends 0 states and 0 transitions. [2021-12-17 15:07:46,600 INFO L858 garLoopResultBuilder]: For program point processEnvironment__wrappee__baseEXIT(lines 688 694) no Hoare annotation was computed. [2021-12-17 15:07:46,601 INFO L861 garLoopResultBuilder]: At program point processEnvironment__wrappee__baseFINAL(lines 688 694) the Hoare annotation is: true [2021-12-17 15:07:46,602 INFO L854 garLoopResultBuilder]: At program point changeMethaneLevelENTRY(lines 487 498) the Hoare annotation is: (let ((.cse0 (not (= ~systemActive~0 1)))) (and (or (not (= ~pumpRunning~0 0)) (= ~methaneLevelCritical~0 |old(~methaneLevelCritical~0)|) (not (<= 1 |old(~methaneLevelCritical~0)|)) .cse0) (or (not (= |old(~methaneLevelCritical~0)| 0)) (= ~methaneLevelCritical~0 0) .cse0))) [2021-12-17 15:07:46,602 INFO L858 garLoopResultBuilder]: For program point L491-1(lines 487 498) no Hoare annotation was computed. [2021-12-17 15:07:46,602 INFO L858 garLoopResultBuilder]: For program point changeMethaneLevelEXIT(lines 487 498) no Hoare annotation was computed. [2021-12-17 15:07:46,602 INFO L858 garLoopResultBuilder]: For program point L894(lines 894 904) no Hoare annotation was computed. [2021-12-17 15:07:46,602 INFO L858 garLoopResultBuilder]: For program point L890(lines 890 907) no Hoare annotation was computed. [2021-12-17 15:07:46,602 INFO L854 garLoopResultBuilder]: At program point L890-1(lines 882 910) the Hoare annotation is: (let ((.cse11 (= |timeShift___utac_acc__Specification2_spec__2_~tmp~8#1| 0)) (.cse12 (= ~methaneLevelCritical~0 0)) (.cse8 (<= 2 ~waterLevel~0))) (let ((.cse4 (not (<= 2 |old(~waterLevel~0)|))) (.cse2 (not (<= 1 ~methaneLevelCritical~0))) (.cse9 (not (= |old(~waterLevel~0)| 1))) (.cse10 (= ~waterLevel~0 1)) (.cse7 (not (= |old(~pumpRunning~0)| 0))) (.cse5 (and .cse11 .cse12 .cse8)) (.cse1 (= ~pumpRunning~0 0)) (.cse0 (= ~pumpRunning~0 |old(~pumpRunning~0)|)) (.cse6 (not .cse12)) (.cse3 (not (= ~systemActive~0 1)))) (and (or (and .cse0 .cse1) .cse2 (and (<= 1 |timeShift_processEnvironment_~tmp~5#1|) .cse1) .cse3) (or .cse4 .cse5 (not (= 0 |old(~pumpRunning~0)|)) .cse6 .cse3) (or .cse4 .cse2 .cse7 .cse8 .cse3) (or .cse9 .cse10 .cse2 .cse7 .cse3) (or .cse9 .cse10 .cse7 .cse6 .cse3) (or .cse5 (and .cse11 .cse1) (and .cse11 .cse0) .cse6 .cse3)))) [2021-12-17 15:07:46,603 INFO L858 garLoopResultBuilder]: For program point timeShiftFINAL(lines 664 687) no Hoare annotation was computed. [2021-12-17 15:07:46,603 INFO L858 garLoopResultBuilder]: For program point L895(lines 895 901) no Hoare annotation was computed. [2021-12-17 15:07:46,603 INFO L854 garLoopResultBuilder]: At program point L796(lines 791 799) the Hoare annotation is: (let ((.cse2 (not (= |old(~pumpRunning~0)| 0))) (.cse1 (not (<= 1 ~methaneLevelCritical~0))) (.cse0 (not (= ~systemActive~0 1)))) (and (or (not (= ~methaneLevelCritical~0 0)) .cse0) (or (not (<= 2 |old(~waterLevel~0)|)) .cse1 .cse2 (<= 2 ~waterLevel~0) .cse0) (or (not (= |old(~waterLevel~0)| 1)) (= ~waterLevel~0 1) .cse1 .cse2 .cse0) (let ((.cse3 (= |timeShift_isPumpRunning_#res#1| 0)) (.cse4 (= ~pumpRunning~0 0))) (or (and (<= 1 |timeShift_processEnvironment_~tmp~5#1|) .cse3 .cse4) (and .cse3 (= ~pumpRunning~0 |old(~pumpRunning~0)|) .cse4) .cse1 .cse0)))) [2021-12-17 15:07:46,603 INFO L858 garLoopResultBuilder]: For program point L668-1(lines 667 686) no Hoare annotation was computed. [2021-12-17 15:07:46,603 INFO L858 garLoopResultBuilder]: For program point L730(lines 730 738) no Hoare annotation was computed. [2021-12-17 15:07:46,603 INFO L858 garLoopResultBuilder]: For program point L726(lines 726 743) no Hoare annotation was computed. [2021-12-17 15:07:46,603 INFO L854 garLoopResultBuilder]: At program point L888(line 888) the Hoare annotation is: (let ((.cse12 (= ~methaneLevelCritical~0 0)) (.cse9 (<= 2 ~waterLevel~0)) (.cse2 (= ~pumpRunning~0 0))) (let ((.cse0 (and (not (= 0 |old(~pumpRunning~0)|)) (<= 1 |timeShift_processEnvironment_~tmp~5#1|) .cse2)) (.cse3 (not (<= 1 ~methaneLevelCritical~0))) (.cse8 (not (<= 2 |old(~waterLevel~0)|))) (.cse5 (not (= |old(~waterLevel~0)| 1))) (.cse6 (= ~waterLevel~0 1)) (.cse7 (not (= |old(~pumpRunning~0)| 0))) (.cse10 (and .cse12 .cse9)) (.cse1 (= ~pumpRunning~0 |old(~pumpRunning~0)|)) (.cse11 (not .cse12)) (.cse4 (not (= ~systemActive~0 1)))) (and (or .cse0 (and .cse1 .cse2) .cse3 .cse4) (or .cse5 .cse6 .cse3 .cse7 .cse4) (or .cse8 .cse0 .cse3 .cse9 .cse4) (or .cse8 .cse10 .cse7 .cse11 .cse4) (or .cse5 .cse6 .cse7 .cse11 .cse4) (or .cse10 .cse1 .cse11 .cse4 .cse2)))) [2021-12-17 15:07:46,604 INFO L858 garLoopResultBuilder]: For program point L888-1(line 888) no Hoare annotation was computed. [2021-12-17 15:07:46,604 INFO L858 garLoopResultBuilder]: For program point L467(lines 467 471) no Hoare annotation was computed. [2021-12-17 15:07:46,604 INFO L854 garLoopResultBuilder]: At program point L467-2(lines 463 474) the Hoare annotation is: (let ((.cse0 (not (= ~systemActive~0 1))) (.cse1 (and (not (= 0 |old(~pumpRunning~0)|)) (= ~pumpRunning~0 |old(~pumpRunning~0)|)))) (and (or (not (= ~methaneLevelCritical~0 0)) .cse0 .cse1) (or (not (<= 1 ~methaneLevelCritical~0)) .cse0 .cse1))) [2021-12-17 15:07:46,604 INFO L854 garLoopResultBuilder]: At program point L777(lines 772 779) the Hoare annotation is: (let ((.cse0 (not (<= 1 ~methaneLevelCritical~0))) (.cse2 (= ~pumpRunning~0 0)) (.cse1 (not (= ~systemActive~0 1)))) (and (or .cse0 (not (= |old(~pumpRunning~0)| 0)) .cse1) (or .cse0 (and (<= 1 |timeShift_processEnvironment_~tmp~5#1|) .cse2) .cse1) (or (not (= ~methaneLevelCritical~0 0)) (and (not (= 0 |old(~pumpRunning~0)|)) .cse2) .cse1))) [2021-12-17 15:07:46,604 INFO L858 garLoopResultBuilder]: For program point L868(line 868) no Hoare annotation was computed. [2021-12-17 15:07:46,605 INFO L854 garLoopResultBuilder]: At program point L736(line 736) the Hoare annotation is: (let ((.cse0 (not (= ~systemActive~0 1)))) (and (or (not (= ~methaneLevelCritical~0 0)) .cse0 (and (not (= 0 |old(~pumpRunning~0)|)) (= ~pumpRunning~0 |old(~pumpRunning~0)|))) (or (not (<= 1 ~methaneLevelCritical~0)) .cse0))) [2021-12-17 15:07:46,605 INFO L854 garLoopResultBuilder]: At program point L728(line 728) the Hoare annotation is: (let ((.cse0 (not (= ~systemActive~0 1))) (.cse1 (and (not (= 0 |old(~pumpRunning~0)|)) (= ~pumpRunning~0 |old(~pumpRunning~0)|)))) (and (or (not (= ~methaneLevelCritical~0 0)) .cse0 .cse1) (or (not (<= 1 ~methaneLevelCritical~0)) .cse0 .cse1))) [2021-12-17 15:07:46,605 INFO L858 garLoopResultBuilder]: For program point L728-1(line 728) no Hoare annotation was computed. [2021-12-17 15:07:46,605 INFO L854 garLoopResultBuilder]: At program point timeShiftENTRY(lines 664 687) the Hoare annotation is: (let ((.cse0 (not (= |old(~waterLevel~0)| 1))) (.cse1 (= ~waterLevel~0 1)) (.cse3 (not (= |old(~pumpRunning~0)| 0))) (.cse5 (= ~pumpRunning~0 |old(~pumpRunning~0)|)) (.cse2 (not (<= 1 ~methaneLevelCritical~0))) (.cse7 (not (<= 2 |old(~waterLevel~0)|))) (.cse8 (<= 2 ~waterLevel~0)) (.cse6 (not (= ~methaneLevelCritical~0 0))) (.cse4 (not (= ~systemActive~0 1)))) (and (or .cse0 .cse1 .cse2 .cse3 .cse4) (or .cse2 .cse5 .cse4) (or .cse0 .cse1 .cse3 .cse6 .cse4) (or .cse5 .cse6 .cse4) (or .cse7 .cse2 .cse8 .cse4) (or .cse7 .cse8 .cse6 .cse4))) [2021-12-17 15:07:46,605 INFO L858 garLoopResultBuilder]: For program point timeShiftEXIT(lines 664 687) no Hoare annotation was computed. [2021-12-17 15:07:46,605 INFO L858 garLoopResultBuilder]: For program point timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION(line 868) no Hoare annotation was computed. [2021-12-17 15:07:46,605 INFO L854 garLoopResultBuilder]: At program point L741(line 741) the Hoare annotation is: (let ((.cse4 (and (= ~pumpRunning~0 |old(~pumpRunning~0)|) (= ~pumpRunning~0 0))) (.cse2 (not (= ~methaneLevelCritical~0 0))) (.cse6 (not (<= 2 |old(~waterLevel~0)|))) (.cse7 (<= 2 ~waterLevel~0)) (.cse0 (not (= |old(~waterLevel~0)| 1))) (.cse1 (= ~waterLevel~0 1)) (.cse5 (not (<= 1 ~methaneLevelCritical~0))) (.cse3 (not (= ~systemActive~0 1)))) (and (or .cse0 .cse1 .cse2 .cse3) (or .cse4 .cse5 .cse3) (or .cse4 .cse2 .cse3) (or .cse6 .cse7 .cse2 .cse3) (or .cse6 .cse5 .cse7 .cse3) (or .cse0 .cse1 .cse5 .cse3))) [2021-12-17 15:07:46,605 INFO L854 garLoopResultBuilder]: At program point L869(lines 864 871) the Hoare annotation is: (let ((.cse0 (not (= ~systemActive~0 1)))) (and (or (not (= ~methaneLevelCritical~0 0)) .cse0) (or (not (<= 1 ~methaneLevelCritical~0)) .cse0))) [2021-12-17 15:07:46,606 INFO L854 garLoopResultBuilder]: At program point L741-1(lines 722 746) the Hoare annotation is: (let ((.cse12 (= ~methaneLevelCritical~0 0)) (.cse9 (<= 2 ~waterLevel~0)) (.cse2 (= ~pumpRunning~0 0))) (let ((.cse0 (and (not (= 0 |old(~pumpRunning~0)|)) (<= 1 |timeShift_processEnvironment_~tmp~5#1|) .cse2)) (.cse3 (not (<= 1 ~methaneLevelCritical~0))) (.cse8 (not (<= 2 |old(~waterLevel~0)|))) (.cse5 (not (= |old(~waterLevel~0)| 1))) (.cse6 (= ~waterLevel~0 1)) (.cse7 (not (= |old(~pumpRunning~0)| 0))) (.cse10 (and .cse12 .cse9)) (.cse1 (= ~pumpRunning~0 |old(~pumpRunning~0)|)) (.cse11 (not .cse12)) (.cse4 (not (= ~systemActive~0 1)))) (and (or .cse0 (and .cse1 .cse2) .cse3 .cse4) (or .cse5 .cse6 .cse3 .cse7 .cse4) (or .cse8 .cse0 .cse3 .cse9 .cse4) (or .cse8 .cse10 .cse7 .cse11 .cse4) (or .cse5 .cse6 .cse7 .cse11 .cse4) (or .cse10 .cse1 .cse11 .cse4 .cse2)))) [2021-12-17 15:07:46,606 INFO L858 garLoopResultBuilder]: For program point L675-1(lines 675 681) no Hoare annotation was computed. [2021-12-17 15:07:46,606 INFO L858 garLoopResultBuilder]: For program point cleanupEXIT(lines 557 586) no Hoare annotation was computed. [2021-12-17 15:07:46,606 INFO L861 garLoopResultBuilder]: At program point cleanupENTRY(lines 557 586) the Hoare annotation is: true [2021-12-17 15:07:46,606 INFO L858 garLoopResultBuilder]: For program point L571(lines 571 575) no Hoare annotation was computed. [2021-12-17 15:07:46,606 INFO L861 garLoopResultBuilder]: At program point L571-1(lines 571 575) the Hoare annotation is: true [2021-12-17 15:07:46,614 INFO L858 garLoopResultBuilder]: For program point L568(line 568) no Hoare annotation was computed. [2021-12-17 15:07:46,614 INFO L861 garLoopResultBuilder]: At program point L567-2(lines 567 581) the Hoare annotation is: true [2021-12-17 15:07:46,614 INFO L861 garLoopResultBuilder]: At program point L563(line 563) the Hoare annotation is: true [2021-12-17 15:07:46,614 INFO L858 garLoopResultBuilder]: For program point L563-1(line 563) no Hoare annotation was computed. [2021-12-17 15:07:46,614 INFO L861 garLoopResultBuilder]: At program point L582(lines 557 586) the Hoare annotation is: true [2021-12-17 15:07:46,614 INFO L858 garLoopResultBuilder]: For program point L578(line 578) no Hoare annotation was computed. [2021-12-17 15:07:46,614 INFO L861 garLoopResultBuilder]: At program point isMethaneLevelCriticalENTRY(lines 499 507) the Hoare annotation is: true [2021-12-17 15:07:46,615 INFO L858 garLoopResultBuilder]: For program point isMethaneLevelCriticalFINAL(lines 499 507) no Hoare annotation was computed. [2021-12-17 15:07:46,615 INFO L858 garLoopResultBuilder]: For program point isMethaneLevelCriticalEXIT(lines 499 507) no Hoare annotation was computed. [2021-12-17 15:07:46,615 INFO L858 garLoopResultBuilder]: For program point L960(lines 960 964) no Hoare annotation was computed. [2021-12-17 15:07:46,615 INFO L858 garLoopResultBuilder]: For program point L642-2(lines 642 649) no Hoare annotation was computed. [2021-12-17 15:07:46,615 INFO L854 garLoopResultBuilder]: At program point L960-2(lines 952 965) the Hoare annotation is: (let ((.cse0 (= |ULTIMATE.start_test_~splverifierCounter~0#1| 0)) (.cse1 (= ~systemActive~0 |ULTIMATE.start_main_~tmp~3#1|)) (.cse2 (= ~systemActive~0 |ULTIMATE.start_valid_product_#res#1|)) (.cse3 (= ~systemActive~0 1))) (or (and .cse0 .cse1 .cse2 (<= 1 ~methaneLevelCritical~0) .cse3) (and .cse0 .cse1 .cse2 (= ~methaneLevelCritical~0 0) .cse3))) [2021-12-17 15:07:46,615 INFO L858 garLoopResultBuilder]: For program point L923(lines 922 969) no Hoare annotation was computed. [2021-12-17 15:07:46,615 INFO L858 garLoopResultBuilder]: For program point L952(lines 952 965) no Hoare annotation was computed. [2021-12-17 15:07:46,615 INFO L854 garLoopResultBuilder]: At program point L944(line 944) the Hoare annotation is: (let ((.cse0 (= |ULTIMATE.start_test_~splverifierCounter~0#1| 0)) (.cse1 (= ~systemActive~0 |ULTIMATE.start_main_~tmp~3#1|)) (.cse2 (= ~systemActive~0 |ULTIMATE.start_valid_product_#res#1|)) (.cse3 (= ~systemActive~0 1))) (or (and .cse0 .cse1 .cse2 (<= 1 ~methaneLevelCritical~0) .cse3 (= ~pumpRunning~0 0)) (and .cse0 .cse1 .cse2 (= ~methaneLevelCritical~0 0) .cse3))) [2021-12-17 15:07:46,616 INFO L861 garLoopResultBuilder]: At program point L973(lines 912 977) the Hoare annotation is: true [2021-12-17 15:07:46,616 INFO L861 garLoopResultBuilder]: At program point L651(lines 632 654) the Hoare annotation is: true [2021-12-17 15:07:46,616 INFO L858 garLoopResultBuilder]: For program point L932(lines 932 938) no Hoare annotation was computed. [2021-12-17 15:07:46,616 INFO L858 garLoopResultBuilder]: For program point L932-1(lines 932 938) no Hoare annotation was computed. [2021-12-17 15:07:46,616 INFO L858 garLoopResultBuilder]: For program point L-1(line -1) no Hoare annotation was computed. [2021-12-17 15:07:46,616 INFO L858 garLoopResultBuilder]: For program point ULTIMATE.startENTRY(line -1) no Hoare annotation was computed. [2021-12-17 15:07:46,616 INFO L858 garLoopResultBuilder]: For program point ULTIMATE.startFINAL(line -1) no Hoare annotation was computed. [2021-12-17 15:07:46,616 INFO L858 garLoopResultBuilder]: For program point L924(lines 924 928) no Hoare annotation was computed. [2021-12-17 15:07:46,616 INFO L854 garLoopResultBuilder]: At program point L879(lines 874 881) the Hoare annotation is: (and (= ~systemActive~0 |ULTIMATE.start_main_~tmp~3#1|) (= ~systemActive~0 |ULTIMATE.start_valid_product_#res#1|) (= ~waterLevel~0 1) (= ~methaneLevelCritical~0 0) (= ~systemActive~0 1) (= ~pumpRunning~0 0)) [2021-12-17 15:07:46,617 INFO L854 garLoopResultBuilder]: At program point L970(lines 921 971) the Hoare annotation is: false [2021-12-17 15:07:46,617 INFO L858 garLoopResultBuilder]: For program point ULTIMATE.startEXIT(line -1) no Hoare annotation was computed. [2021-12-17 15:07:46,617 INFO L854 garLoopResultBuilder]: At program point L83(lines 78 86) the Hoare annotation is: (and (= ~systemActive~0 |ULTIMATE.start_valid_product_#res#1|) (= ~waterLevel~0 1) (= ~methaneLevelCritical~0 0) (= ~systemActive~0 1) (= ~pumpRunning~0 0)) [2021-12-17 15:07:46,617 INFO L858 garLoopResultBuilder]: For program point L942(lines 942 948) no Hoare annotation was computed. [2021-12-17 15:07:46,617 INFO L858 garLoopResultBuilder]: For program point L942-1(lines 942 948) no Hoare annotation was computed. [2021-12-17 15:07:46,617 INFO L854 garLoopResultBuilder]: At program point L75(lines 71 77) the Hoare annotation is: (and (= ~waterLevel~0 1) (= ~methaneLevelCritical~0 0) (= ~systemActive~0 1) (= ~pumpRunning~0 0)) [2021-12-17 15:07:46,617 INFO L854 garLoopResultBuilder]: At program point L616(lines 612 618) the Hoare annotation is: (and (= ~systemActive~0 |ULTIMATE.start_main_~tmp~3#1|) (= ~systemActive~0 |ULTIMATE.start_valid_product_#res#1|) (= ~waterLevel~0 1) (= ~methaneLevelCritical~0 0) (= ~systemActive~0 1) (= ~pumpRunning~0 0)) [2021-12-17 15:07:46,617 INFO L854 garLoopResultBuilder]: At program point L967(lines 922 969) the Hoare annotation is: (let ((.cse0 (= |ULTIMATE.start_test_~splverifierCounter~0#1| 0)) (.cse1 (= ~systemActive~0 |ULTIMATE.start_main_~tmp~3#1|)) (.cse2 (= ~systemActive~0 |ULTIMATE.start_valid_product_#res#1|)) (.cse3 (= ~systemActive~0 1))) (or (and .cse0 .cse1 .cse2 (<= 1 ~methaneLevelCritical~0) .cse3 (= ~pumpRunning~0 0)) (and .cse0 .cse1 .cse2 (= ~methaneLevelCritical~0 0) .cse3))) [2021-12-17 15:07:46,618 INFO L854 garLoopResultBuilder]: At program point L934(line 934) the Hoare annotation is: (let ((.cse0 (= |ULTIMATE.start_test_~splverifierCounter~0#1| 0)) (.cse1 (= ~systemActive~0 |ULTIMATE.start_main_~tmp~3#1|)) (.cse2 (= ~systemActive~0 |ULTIMATE.start_valid_product_#res#1|)) (.cse3 (= ~systemActive~0 1))) (or (and .cse0 .cse1 .cse2 (<= 1 ~methaneLevelCritical~0) .cse3 (= ~pumpRunning~0 0)) (and .cse0 .cse1 .cse2 (= ~methaneLevelCritical~0 0) .cse3))) [2021-12-17 15:07:46,618 INFO L854 garLoopResultBuilder]: At program point L860(lines 855 862) the Hoare annotation is: (let ((.cse0 (= |ULTIMATE.start_test_~splverifierCounter~0#1| 0)) (.cse1 (= ~systemActive~0 |ULTIMATE.start_main_~tmp~3#1|)) (.cse2 (= ~systemActive~0 |ULTIMATE.start_valid_product_#res#1|)) (.cse3 (= ~systemActive~0 1))) (or (and .cse0 .cse1 .cse2 (<= 1 ~methaneLevelCritical~0) .cse3) (and .cse0 .cse1 .cse2 (= ~methaneLevelCritical~0 0) .cse3))) [2021-12-17 15:07:46,618 INFO L861 garLoopResultBuilder]: At program point L629(lines 621 631) the Hoare annotation is: true [2021-12-17 15:07:46,618 INFO L854 garLoopResultBuilder]: At program point L68(lines 64 70) the Hoare annotation is: (and (= ~waterLevel~0 1) (= ~methaneLevelCritical~0 0) (= ~systemActive~0 1) (= ~pumpRunning~0 0)) [2021-12-17 15:07:46,618 INFO L858 garLoopResultBuilder]: For program point L642(lines 642 649) no Hoare annotation was computed. [2021-12-17 15:07:46,618 INFO L858 garLoopResultBuilder]: For program point waterRiseEXIT(lines 475 486) no Hoare annotation was computed. [2021-12-17 15:07:46,618 INFO L858 garLoopResultBuilder]: For program point L479-1(lines 475 486) no Hoare annotation was computed. [2021-12-17 15:07:46,618 INFO L854 garLoopResultBuilder]: At program point waterRiseENTRY(lines 475 486) the Hoare annotation is: (let ((.cse3 (not (= ~methaneLevelCritical~0 0))) (.cse5 (not (<= 2 |old(~waterLevel~0)|))) (.cse6 (<= 2 ~waterLevel~0)) (.cse0 (not (= |old(~waterLevel~0)| 1))) (.cse1 (= ~waterLevel~0 1)) (.cse2 (not (= ~pumpRunning~0 0))) (.cse7 (not (<= 1 ~methaneLevelCritical~0))) (.cse4 (not (= ~systemActive~0 1)))) (and (or .cse0 .cse1 .cse2 .cse3 .cse4) (or .cse5 .cse6 .cse3 .cse4) (or .cse5 .cse2 .cse7 .cse6 .cse4) (or .cse0 .cse1 .cse2 .cse7 .cse4))) [2021-12-17 15:07:46,619 INFO L858 garLoopResultBuilder]: For program point L704(lines 704 712) no Hoare annotation was computed. [2021-12-17 15:07:46,619 INFO L858 garLoopResultBuilder]: For program point L700(lines 700 717) no Hoare annotation was computed. [2021-12-17 15:07:46,619 INFO L858 garLoopResultBuilder]: For program point L762(lines 762 768) no Hoare annotation was computed. [2021-12-17 15:07:46,619 INFO L854 garLoopResultBuilder]: At program point L760(line 760) the Hoare annotation is: (let ((.cse0 (and (<= 2 ~waterLevel~0) (= ~pumpRunning~0 0))) (.cse1 (not (= ~methaneLevelCritical~0 0))) (.cse2 (not (= ~systemActive~0 1)))) (and (or .cse0 .cse1 .cse2) (or .cse0 (not (<= 1 ~methaneLevelCritical~0)) (not (= |old(~pumpRunning~0)| 0)) .cse2) (or (= 0 |old(~pumpRunning~0)|) .cse1 .cse2))) [2021-12-17 15:07:46,619 INFO L854 garLoopResultBuilder]: At program point L762-2(lines 755 771) the Hoare annotation is: (let ((.cse0 (<= 2 ~waterLevel~0)) (.cse2 (not (= ~methaneLevelCritical~0 0))) (.cse1 (not (= ~systemActive~0 1)))) (and (or (not (<= 1 ~methaneLevelCritical~0)) (not (= |old(~pumpRunning~0)| 0)) (and (<= ~methaneLevelCritical~0 |processEnvironment__wrappee__methaneQuery_activatePump_~tmp~6#1|) .cse0 (= ~pumpRunning~0 0)) .cse1) (or .cse0 .cse2 .cse1) (or (= 0 |old(~pumpRunning~0)|) .cse2 .cse1))) [2021-12-17 15:07:46,619 INFO L858 garLoopResultBuilder]: For program point L760-1(line 760) no Hoare annotation was computed. [2021-12-17 15:07:46,619 INFO L854 garLoopResultBuilder]: At program point L851(lines 836 854) the Hoare annotation is: (let ((.cse5 (= ~pumpRunning~0 0))) (let ((.cse0 (not (= ~methaneLevelCritical~0 0))) (.cse2 (and (<= 2 ~waterLevel~0) .cse5)) (.cse3 (= |processEnvironment__wrappee__methaneQuery_isHighWaterLevel_~tmp___0~0#1| 0)) (.cse4 (= |processEnvironment__wrappee__methaneQuery_isHighWaterLevel_#res#1| 0)) (.cse1 (not (= ~systemActive~0 1)))) (and (or (= 0 |old(~pumpRunning~0)|) .cse0 .cse1) (or .cse2 (and .cse3 .cse4 .cse5) .cse0 .cse1) (or .cse2 (not (<= 1 ~methaneLevelCritical~0)) (and .cse3 (= ~pumpRunning~0 |old(~pumpRunning~0)|) .cse4) (not (= |old(~pumpRunning~0)| 0)) .cse1)))) [2021-12-17 15:07:46,620 INFO L854 garLoopResultBuilder]: At program point L752(lines 747 754) the Hoare annotation is: (let ((.cse1 (not (= ~methaneLevelCritical~0 0))) (.cse0 (not (= ~systemActive~0 1)))) (and (or (not (<= 1 ~methaneLevelCritical~0)) (not (= |old(~pumpRunning~0)| 0)) .cse0) (or (<= 2 ~waterLevel~0) .cse1 .cse0) (or (= 0 |old(~pumpRunning~0)|) .cse1 .cse0))) [2021-12-17 15:07:46,620 INFO L858 garLoopResultBuilder]: For program point L845(lines 845 849) no Hoare annotation was computed. [2021-12-17 15:07:46,620 INFO L858 garLoopResultBuilder]: For program point L845-2(lines 845 849) no Hoare annotation was computed. [2021-12-17 15:07:46,620 INFO L854 garLoopResultBuilder]: At program point L715(line 715) the Hoare annotation is: (let ((.cse0 (not (= |old(~pumpRunning~0)| 0))) (.cse1 (not (= ~methaneLevelCritical~0 0))) (.cse2 (not (= ~systemActive~0 1)))) (and (or .cse0 .cse1 .cse2) (or (not (<= 1 ~methaneLevelCritical~0)) .cse0 .cse2) (or (= ~pumpRunning~0 |old(~pumpRunning~0)|) .cse1 .cse2))) [2021-12-17 15:07:46,620 INFO L858 garLoopResultBuilder]: For program point L715-1(lines 696 720) no Hoare annotation was computed. [2021-12-17 15:07:46,620 INFO L858 garLoopResultBuilder]: For program point L544(lines 544 550) no Hoare annotation was computed. [2021-12-17 15:07:46,620 INFO L854 garLoopResultBuilder]: At program point processEnvironment__wrappee__methaneQueryENTRY(lines 696 720) the Hoare annotation is: (let ((.cse0 (not (= ~systemActive~0 1)))) (and (or (not (<= 1 ~methaneLevelCritical~0)) (not (= |old(~pumpRunning~0)| 0)) .cse0 (= ~pumpRunning~0 0)) (or (= ~pumpRunning~0 |old(~pumpRunning~0)|) (not (= ~methaneLevelCritical~0 0)) .cse0))) [2021-12-17 15:07:46,620 INFO L858 garLoopResultBuilder]: For program point processEnvironment__wrappee__methaneQueryEXIT(lines 696 720) no Hoare annotation was computed. [2021-12-17 15:07:46,621 INFO L854 garLoopResultBuilder]: At program point L710(line 710) the Hoare annotation is: (let ((.cse2 (and (= |processEnvironment__wrappee__methaneQuery_~tmp~4#1| 0) (= ~pumpRunning~0 0))) (.cse0 (not (= ~methaneLevelCritical~0 0))) (.cse1 (not (= ~systemActive~0 1)))) (and (or (= 0 |old(~pumpRunning~0)|) .cse0 .cse1) (or (not (<= 1 ~methaneLevelCritical~0)) (not (= |old(~pumpRunning~0)| 0)) .cse2 .cse1) (or .cse2 .cse0 .cse1))) [2021-12-17 15:07:46,621 INFO L854 garLoopResultBuilder]: At program point L549(lines 540 553) the Hoare annotation is: (let ((.cse4 (= ~pumpRunning~0 0))) (let ((.cse0 (and (<= 2 ~waterLevel~0) .cse4)) (.cse3 (not (= ~methaneLevelCritical~0 0))) (.cse1 (not (= ~systemActive~0 1))) (.cse2 (and (= |processEnvironment__wrappee__methaneQuery_isHighWaterSensorDry_#res#1| 1) .cse4))) (and (or .cse0 (not (<= 1 ~methaneLevelCritical~0)) (not (= |old(~pumpRunning~0)| 0)) .cse1 .cse2) (or (= 0 |old(~pumpRunning~0)|) .cse3 .cse1) (or .cse0 .cse3 .cse1 .cse2)))) [2021-12-17 15:07:46,621 INFO L861 garLoopResultBuilder]: At program point L785(line 785) the Hoare annotation is: true [2021-12-17 15:07:46,621 INFO L858 garLoopResultBuilder]: For program point L785-1(line 785) no Hoare annotation was computed. [2021-12-17 15:07:46,621 INFO L861 garLoopResultBuilder]: At program point isMethaneAlarmENTRY(lines 780 790) the Hoare annotation is: true [2021-12-17 15:07:46,621 INFO L858 garLoopResultBuilder]: For program point isMethaneAlarmEXIT(lines 780 790) no Hoare annotation was computed. [2021-12-17 15:07:46,621 INFO L858 garLoopResultBuilder]: For program point isMethaneAlarmFINAL(lines 780 790) no Hoare annotation was computed. [2021-12-17 15:07:46,624 INFO L732 BasicCegarLoop]: Path program histogram: [1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2021-12-17 15:07:46,625 INFO L179 ceAbstractionStarter]: Computing trace abstraction results [2021-12-17 15:07:46,657 INFO L202 PluginConnector]: Adding new model de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction CFG 17.12 03:07:46 BoogieIcfgContainer [2021-12-17 15:07:46,667 INFO L132 PluginConnector]: ------------------------ END TraceAbstraction---------------------------- [2021-12-17 15:07:46,668 INFO L113 PluginConnector]: ------------------------Witness Printer---------------------------- [2021-12-17 15:07:46,668 INFO L271 PluginConnector]: Initializing Witness Printer... [2021-12-17 15:07:46,668 INFO L275 PluginConnector]: Witness Printer initialized [2021-12-17 15:07:46,668 INFO L185 PluginConnector]: Executing the observer RCFGCatcher from plugin Witness Printer for "de.uni_freiburg.informatik.ultimate.plugins.generator.rcfgbuilder CFG 17.12 03:07:40" (3/4) ... [2021-12-17 15:07:46,670 INFO L137 WitnessPrinter]: Generating witness for correct program [2021-12-17 15:07:46,675 INFO L354 RCFGBacktranslator]: Ignoring RootEdge to procedure processEnvironment__wrappee__base [2021-12-17 15:07:46,675 INFO L354 RCFGBacktranslator]: Ignoring RootEdge to procedure changeMethaneLevel [2021-12-17 15:07:46,675 INFO L354 RCFGBacktranslator]: Ignoring RootEdge to procedure timeShift [2021-12-17 15:07:46,675 INFO L354 RCFGBacktranslator]: Ignoring RootEdge to procedure cleanup [2021-12-17 15:07:46,675 INFO L354 RCFGBacktranslator]: Ignoring RootEdge to procedure isMethaneLevelCritical [2021-12-17 15:07:46,676 INFO L354 RCFGBacktranslator]: Ignoring RootEdge to procedure waterRise [2021-12-17 15:07:46,676 INFO L354 RCFGBacktranslator]: Ignoring RootEdge to procedure processEnvironment__wrappee__methaneQuery [2021-12-17 15:07:46,676 INFO L354 RCFGBacktranslator]: Ignoring RootEdge to procedure isMethaneAlarm [2021-12-17 15:07:46,684 INFO L910 BoogieBacktranslator]: Reduced CFG by removing 50 nodes and edges [2021-12-17 15:07:46,685 INFO L910 BoogieBacktranslator]: Reduced CFG by removing 22 nodes and edges [2021-12-17 15:07:46,685 INFO L910 BoogieBacktranslator]: Reduced CFG by removing 11 nodes and edges [2021-12-17 15:07:46,686 INFO L910 BoogieBacktranslator]: Reduced CFG by removing 5 nodes and edges [2021-12-17 15:07:46,686 INFO L910 BoogieBacktranslator]: Reduced CFG by removing 2 nodes and edges [2021-12-17 15:07:46,686 INFO L910 BoogieBacktranslator]: Reduced CFG by removing 1 nodes and edges [2021-12-17 15:07:46,686 INFO L910 BoogieBacktranslator]: Reduced CFG by removing 1 nodes and edges [2021-12-17 15:07:46,701 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (((systemActive == \result && waterLevel == 1) && methaneLevelCritical == 0) && systemActive == 1) && pumpRunning == 0 [2021-12-17 15:07:46,702 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: ((((systemActive == tmp && systemActive == \result) && waterLevel == 1) && methaneLevelCritical == 0) && systemActive == 1) && pumpRunning == 0 [2021-12-17 15:07:46,702 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: ((((systemActive == tmp && systemActive == \result) && waterLevel == 1) && methaneLevelCritical == 0) && systemActive == 1) && pumpRunning == 0 [2021-12-17 15:07:46,702 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (((((splverifierCounter == 0 && systemActive == tmp) && systemActive == \result) && 1 <= methaneLevelCritical) && systemActive == 1) && pumpRunning == 0) || ((((splverifierCounter == 0 && systemActive == tmp) && systemActive == \result) && methaneLevelCritical == 0) && systemActive == 1) [2021-12-17 15:07:46,703 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: ((!(methaneLevelCritical == 0) || !(systemActive == 1)) || (!(0 == \old(pumpRunning)) && pumpRunning == \old(pumpRunning))) && ((!(1 <= methaneLevelCritical) || !(systemActive == 1)) || (!(0 == \old(pumpRunning)) && pumpRunning == \old(pumpRunning))) [2021-12-17 15:07:46,704 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (((((((((!(0 == \old(pumpRunning)) && 1 <= tmp) && pumpRunning == 0) || (pumpRunning == \old(pumpRunning) && pumpRunning == 0)) || !(1 <= methaneLevelCritical)) || !(systemActive == 1)) && ((((!(\old(waterLevel) == 1) || waterLevel == 1) || !(1 <= methaneLevelCritical)) || !(\old(pumpRunning) == 0)) || !(systemActive == 1))) && ((((!(2 <= \old(waterLevel)) || ((!(0 == \old(pumpRunning)) && 1 <= tmp) && pumpRunning == 0)) || !(1 <= methaneLevelCritical)) || 2 <= waterLevel) || !(systemActive == 1))) && ((((!(2 <= \old(waterLevel)) || (methaneLevelCritical == 0 && 2 <= waterLevel)) || !(\old(pumpRunning) == 0)) || !(methaneLevelCritical == 0)) || !(systemActive == 1))) && ((((!(\old(waterLevel) == 1) || waterLevel == 1) || !(\old(pumpRunning) == 0)) || !(methaneLevelCritical == 0)) || !(systemActive == 1))) && (((((methaneLevelCritical == 0 && 2 <= waterLevel) || pumpRunning == \old(pumpRunning)) || !(methaneLevelCritical == 0)) || !(systemActive == 1)) || pumpRunning == 0) [2021-12-17 15:07:46,706 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: ((((splverifierCounter == 0 && systemActive == tmp) && systemActive == \result) && 1 <= methaneLevelCritical) && systemActive == 1) || ((((splverifierCounter == 0 && systemActive == tmp) && systemActive == \result) && methaneLevelCritical == 0) && systemActive == 1) [2021-12-17 15:07:46,706 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: ((((((((pumpRunning == \old(pumpRunning) && pumpRunning == 0) || !(1 <= methaneLevelCritical)) || (1 <= tmp && pumpRunning == 0)) || !(systemActive == 1)) && ((((!(2 <= \old(waterLevel)) || ((tmp == 0 && methaneLevelCritical == 0) && 2 <= waterLevel)) || !(0 == \old(pumpRunning))) || !(methaneLevelCritical == 0)) || !(systemActive == 1))) && ((((!(2 <= \old(waterLevel)) || !(1 <= methaneLevelCritical)) || !(\old(pumpRunning) == 0)) || 2 <= waterLevel) || !(systemActive == 1))) && ((((!(\old(waterLevel) == 1) || waterLevel == 1) || !(1 <= methaneLevelCritical)) || !(\old(pumpRunning) == 0)) || !(systemActive == 1))) && ((((!(\old(waterLevel) == 1) || waterLevel == 1) || !(\old(pumpRunning) == 0)) || !(methaneLevelCritical == 0)) || !(systemActive == 1))) && ((((((tmp == 0 && methaneLevelCritical == 0) && 2 <= waterLevel) || (tmp == 0 && pumpRunning == 0)) || (tmp == 0 && pumpRunning == \old(pumpRunning))) || !(methaneLevelCritical == 0)) || !(systemActive == 1)) [2021-12-17 15:07:46,706 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (((!(1 <= methaneLevelCritical) || !(\old(pumpRunning) == 0)) || !(systemActive == 1)) && ((!(1 <= methaneLevelCritical) || (1 <= tmp && pumpRunning == 0)) || !(systemActive == 1))) && ((!(methaneLevelCritical == 0) || (!(0 == \old(pumpRunning)) && pumpRunning == 0)) || !(systemActive == 1)) [2021-12-17 15:07:46,706 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (((!(methaneLevelCritical == 0) || !(systemActive == 1)) && ((((!(2 <= \old(waterLevel)) || !(1 <= methaneLevelCritical)) || !(\old(pumpRunning) == 0)) || 2 <= waterLevel) || !(systemActive == 1))) && ((((!(\old(waterLevel) == 1) || waterLevel == 1) || !(1 <= methaneLevelCritical)) || !(\old(pumpRunning) == 0)) || !(systemActive == 1))) && (((((1 <= tmp && \result == 0) && pumpRunning == 0) || ((\result == 0 && pumpRunning == \old(pumpRunning)) && pumpRunning == 0)) || !(1 <= methaneLevelCritical)) || !(systemActive == 1)) [2021-12-17 15:07:46,706 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: ((((!(1 <= methaneLevelCritical) || !(\old(pumpRunning) == 0)) || ((methaneLevelCritical <= tmp && 2 <= waterLevel) && pumpRunning == 0)) || !(systemActive == 1)) && ((2 <= waterLevel || !(methaneLevelCritical == 0)) || !(systemActive == 1))) && ((0 == \old(pumpRunning) || !(methaneLevelCritical == 0)) || !(systemActive == 1)) [2021-12-17 15:07:46,707 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (((!(1 <= methaneLevelCritical) || !(\old(pumpRunning) == 0)) || !(systemActive == 1)) && ((2 <= waterLevel || !(methaneLevelCritical == 0)) || !(systemActive == 1))) && ((0 == \old(pumpRunning) || !(methaneLevelCritical == 0)) || !(systemActive == 1)) [2021-12-17 15:07:46,707 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: ((((((2 <= waterLevel && pumpRunning == 0) || !(1 <= methaneLevelCritical)) || !(\old(pumpRunning) == 0)) || !(systemActive == 1)) || (\result == 1 && pumpRunning == 0)) && ((0 == \old(pumpRunning) || !(methaneLevelCritical == 0)) || !(systemActive == 1))) && ((((2 <= waterLevel && pumpRunning == 0) || !(methaneLevelCritical == 0)) || !(systemActive == 1)) || (\result == 1 && pumpRunning == 0)) [2021-12-17 15:07:46,707 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (((0 == \old(pumpRunning) || !(methaneLevelCritical == 0)) || !(systemActive == 1)) && ((((2 <= waterLevel && pumpRunning == 0) || ((tmp___0 == 0 && \result == 0) && pumpRunning == 0)) || !(methaneLevelCritical == 0)) || !(systemActive == 1))) && (((((2 <= waterLevel && pumpRunning == 0) || !(1 <= methaneLevelCritical)) || ((tmp___0 == 0 && pumpRunning == \old(pumpRunning)) && \result == 0)) || !(\old(pumpRunning) == 0)) || !(systemActive == 1)) [2021-12-17 15:07:46,731 INFO L141 WitnessManager]: Wrote witness to /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/witness.graphml [2021-12-17 15:07:46,732 INFO L132 PluginConnector]: ------------------------ END Witness Printer---------------------------- [2021-12-17 15:07:46,732 INFO L158 Benchmark]: Toolchain (without parser) took 7490.43ms. Allocated memory was 107.0MB in the beginning and 144.7MB in the end (delta: 37.7MB). Free memory was 71.1MB in the beginning and 111.4MB in the end (delta: -40.4MB). There was no memory consumed. Max. memory is 16.1GB. [2021-12-17 15:07:46,732 INFO L158 Benchmark]: CDTParser took 0.26ms. Allocated memory is still 107.0MB. Free memory was 78.1MB in the beginning and 78.0MB in the end (delta: 28.0kB). There was no memory consumed. Max. memory is 16.1GB. [2021-12-17 15:07:46,732 INFO L158 Benchmark]: CACSL2BoogieTranslator took 356.04ms. Allocated memory is still 107.0MB. Free memory was 70.9MB in the beginning and 75.3MB in the end (delta: -4.4MB). Peak memory consumption was 12.6MB. Max. memory is 16.1GB. [2021-12-17 15:07:46,733 INFO L158 Benchmark]: Boogie Procedure Inliner took 32.90ms. Allocated memory is still 107.0MB. Free memory was 75.3MB in the beginning and 72.8MB in the end (delta: 2.5MB). Peak memory consumption was 2.1MB. Max. memory is 16.1GB. [2021-12-17 15:07:46,733 INFO L158 Benchmark]: Boogie Preprocessor took 44.17ms. Allocated memory is still 107.0MB. Free memory was 72.8MB in the beginning and 71.2MB in the end (delta: 1.7MB). Peak memory consumption was 2.1MB. Max. memory is 16.1GB. [2021-12-17 15:07:46,733 INFO L158 Benchmark]: RCFGBuilder took 371.79ms. Allocated memory is still 107.0MB. Free memory was 71.2MB in the beginning and 54.8MB in the end (delta: 16.4MB). Peak memory consumption was 16.8MB. Max. memory is 16.1GB. [2021-12-17 15:07:46,734 INFO L158 Benchmark]: TraceAbstraction took 6616.88ms. Allocated memory was 107.0MB in the beginning and 144.7MB in the end (delta: 37.7MB). Free memory was 54.4MB in the beginning and 117.7MB in the end (delta: -63.3MB). Peak memory consumption was 61.7MB. Max. memory is 16.1GB. [2021-12-17 15:07:46,734 INFO L158 Benchmark]: Witness Printer took 64.18ms. Allocated memory is still 144.7MB. Free memory was 117.7MB in the beginning and 111.4MB in the end (delta: 6.3MB). Peak memory consumption was 6.3MB. Max. memory is 16.1GB. [2021-12-17 15:07:46,735 INFO L339 ainManager$Toolchain]: ####################### End [Toolchain 1] ####################### --- Results --- * Results from de.uni_freiburg.informatik.ultimate.core: - StatisticsResult: Toolchain Benchmarks Benchmark results are: * CDTParser took 0.26ms. Allocated memory is still 107.0MB. Free memory was 78.1MB in the beginning and 78.0MB in the end (delta: 28.0kB). There was no memory consumed. Max. memory is 16.1GB. * CACSL2BoogieTranslator took 356.04ms. Allocated memory is still 107.0MB. Free memory was 70.9MB in the beginning and 75.3MB in the end (delta: -4.4MB). Peak memory consumption was 12.6MB. Max. memory is 16.1GB. * Boogie Procedure Inliner took 32.90ms. Allocated memory is still 107.0MB. Free memory was 75.3MB in the beginning and 72.8MB in the end (delta: 2.5MB). Peak memory consumption was 2.1MB. Max. memory is 16.1GB. * Boogie Preprocessor took 44.17ms. Allocated memory is still 107.0MB. Free memory was 72.8MB in the beginning and 71.2MB in the end (delta: 1.7MB). Peak memory consumption was 2.1MB. Max. memory is 16.1GB. * RCFGBuilder took 371.79ms. Allocated memory is still 107.0MB. Free memory was 71.2MB in the beginning and 54.8MB in the end (delta: 16.4MB). Peak memory consumption was 16.8MB. Max. memory is 16.1GB. * TraceAbstraction took 6616.88ms. Allocated memory was 107.0MB in the beginning and 144.7MB in the end (delta: 37.7MB). Free memory was 54.4MB in the beginning and 117.7MB in the end (delta: -63.3MB). Peak memory consumption was 61.7MB. Max. memory is 16.1GB. * Witness Printer took 64.18ms. Allocated memory is still 144.7MB. Free memory was 117.7MB in the beginning and 111.4MB in the end (delta: 6.3MB). Peak memory consumption was 6.3MB. Max. memory is 16.1GB. * Results from de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction: - StatisticsResult: ErrorAutomatonStatistics NumberErrorTraces: 0, NumberStatementsAllTraces: 0, NumberRelevantStatements: 0, 0.0s ErrorAutomatonConstructionTimeTotal, 0.0s FaulLocalizationTime, NumberStatementsFirstTrace: -1, TraceLengthAvg: 0, 0.0s ErrorAutomatonConstructionTimeAvg, 0.0s ErrorAutomatonDifferenceTimeAvg, 0.0s ErrorAutomatonDifferenceTimeTotal, NumberOfNoEnhancement: 0, NumberOfFiniteEnhancement: 0, NumberOfInfiniteEnhancement: 0 - PositiveResult [Line: 868]: call to reach_error is unreachable For all program executions holds that call to reach_error is unreachable at this location - StatisticsResult: Ultimate Automizer benchmark data CFG has 9 procedures, 96 locations, 1 error locations. Started 1 CEGAR loops. OverallTime: 6.5s, OverallIterations: 11, TraceHistogramMax: 4, PathProgramHistogramMax: 1, EmptinessCheckTime: 0.1s, AutomataDifference: 1.7s, DeadEndRemovalTime: 0.0s, HoareAnnotationTime: 2.3s, InitialAbstractionConstructionTime: 0.0s, PartialOrderReductionTime: 0.0s, HoareTripleCheckerStatistics: 0 mSolverCounterUnknown, 1421 SdHoareTripleChecker+Valid, 1.0s IncrementalHoareTripleChecker+Time, 0 mSdLazyCounter, 1393 mSDsluCounter, 3832 SdHoareTripleChecker+Invalid, 0.8s Time, 0 mProtectedAction, 0 SdHoareTripleChecker+Unchecked, 0 IncrementalHoareTripleChecker+Unchecked, 2520 mSDsCounter, 455 IncrementalHoareTripleChecker+Valid, 0 mProtectedPredicate, 1697 IncrementalHoareTripleChecker+Invalid, 2152 SdHoareTripleChecker+Unknown, 0 mSolverCounterNotChecked, 455 mSolverCounterUnsat, 1312 mSDtfsCounter, 1697 mSolverCounterSat, 0.0s SdHoareTripleChecker+Time, 0 IncrementalHoareTripleChecker+Unknown, PredicateUnifierStatistics: 0 DeclaredPredicates, 379 GetRequests, 272 SyntacticMatches, 1 SemanticMatches, 106 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 129 ImplicationChecksByTransitivity, 0.5s Time, 0.0s BasicInterpolantAutomatonTime, BiggestAbstraction: size=518occurred in iteration=9, InterpolantAutomatonStates: 89, traceCheckStatistics: No data available, InterpolantConsolidationStatistics: No data available, PathInvariantsStatistics: No data available, 0/0 InterpolantCoveringCapability, TotalInterpolationStatistics: No data available, 0.0s DumpTime, AutomataMinimizationStatistics: 0.2s AutomataMinimizationTime, 11 MinimizatonAttempts, 64 StatesRemovedByMinimization, 7 NontrivialMinimizations, HoareAnnotationStatistics: 0.0s HoareAnnotationTime, 44 LocationsWithAnnotation, 1304 PreInvPairs, 1493 NumberOfFragments, 1619 HoareAnnotationTreeSize, 1304 FomulaSimplifications, 0 FormulaSimplificationTreeSizeReduction, 0.2s HoareSimplificationTime, 44 FomulaSimplificationsInter, 7687 FormulaSimplificationTreeSizeReductionInter, 2.1s HoareSimplificationTimeInter, RefinementEngineStatistics: TRACE_CHECK: 0.0s SsaConstructionTime, 0.2s SatisfiabilityAnalysisTime, 1.3s InterpolantComputationTime, 754 NumberOfCodeBlocks, 754 NumberOfCodeBlocksAsserted, 13 NumberOfCheckSat, 741 ConstructedInterpolants, 0 QuantifiedInterpolants, 1384 SizeOfPredicates, 6 NumberOfNonLiveVariables, 905 ConjunctsInSsa, 18 ConjunctsInUnsatCore, 13 InterpolantComputations, 11 PerfectInterpolantSequences, 100/105 InterpolantCoveringCapability, INVARIANT_SYNTHESIS: No data available, INTERPOLANT_CONSOLIDATION: No data available, ABSTRACT_INTERPRETATION: No data available, PDR: No data available, ACCELERATED_INTERPOLATION: No data available, SIFA: No data available, ReuseStatistics: No data available - AllSpecificationsHoldResult: All specifications hold 1 specifications checked. All of them hold - InvariantResult [Line: 882]: Loop Invariant Derived loop invariant: ((((((((pumpRunning == \old(pumpRunning) && pumpRunning == 0) || !(1 <= methaneLevelCritical)) || (1 <= tmp && pumpRunning == 0)) || !(systemActive == 1)) && ((((!(2 <= \old(waterLevel)) || ((tmp == 0 && methaneLevelCritical == 0) && 2 <= waterLevel)) || !(0 == \old(pumpRunning))) || !(methaneLevelCritical == 0)) || !(systemActive == 1))) && ((((!(2 <= \old(waterLevel)) || !(1 <= methaneLevelCritical)) || !(\old(pumpRunning) == 0)) || 2 <= waterLevel) || !(systemActive == 1))) && ((((!(\old(waterLevel) == 1) || waterLevel == 1) || !(1 <= methaneLevelCritical)) || !(\old(pumpRunning) == 0)) || !(systemActive == 1))) && ((((!(\old(waterLevel) == 1) || waterLevel == 1) || !(\old(pumpRunning) == 0)) || !(methaneLevelCritical == 0)) || !(systemActive == 1))) && ((((((tmp == 0 && methaneLevelCritical == 0) && 2 <= waterLevel) || (tmp == 0 && pumpRunning == 0)) || (tmp == 0 && pumpRunning == \old(pumpRunning))) || !(methaneLevelCritical == 0)) || !(systemActive == 1)) - InvariantResult [Line: 864]: Loop Invariant Derived loop invariant: (!(methaneLevelCritical == 0) || !(systemActive == 1)) && (!(1 <= methaneLevelCritical) || !(systemActive == 1)) - InvariantResult [Line: 747]: Loop Invariant Derived loop invariant: (((!(1 <= methaneLevelCritical) || !(\old(pumpRunning) == 0)) || !(systemActive == 1)) && ((2 <= waterLevel || !(methaneLevelCritical == 0)) || !(systemActive == 1))) && ((0 == \old(pumpRunning) || !(methaneLevelCritical == 0)) || !(systemActive == 1)) - InvariantResult [Line: 612]: Loop Invariant Derived loop invariant: ((((systemActive == tmp && systemActive == \result) && waterLevel == 1) && methaneLevelCritical == 0) && systemActive == 1) && pumpRunning == 0 - InvariantResult [Line: 874]: Loop Invariant Derived loop invariant: ((((systemActive == tmp && systemActive == \result) && waterLevel == 1) && methaneLevelCritical == 0) && systemActive == 1) && pumpRunning == 0 - InvariantResult [Line: 921]: Loop Invariant Derived loop invariant: 0 - InvariantResult [Line: 78]: Loop Invariant Derived loop invariant: (((systemActive == \result && waterLevel == 1) && methaneLevelCritical == 0) && systemActive == 1) && pumpRunning == 0 - InvariantResult [Line: 855]: Loop Invariant Derived loop invariant: ((((splverifierCounter == 0 && systemActive == tmp) && systemActive == \result) && 1 <= methaneLevelCritical) && systemActive == 1) || ((((splverifierCounter == 0 && systemActive == tmp) && systemActive == \result) && methaneLevelCritical == 0) && systemActive == 1) - InvariantResult [Line: 64]: Loop Invariant Derived loop invariant: ((waterLevel == 1 && methaneLevelCritical == 0) && systemActive == 1) && pumpRunning == 0 - InvariantResult [Line: 755]: Loop Invariant Derived loop invariant: ((((!(1 <= methaneLevelCritical) || !(\old(pumpRunning) == 0)) || ((methaneLevelCritical <= tmp && 2 <= waterLevel) && pumpRunning == 0)) || !(systemActive == 1)) && ((2 <= waterLevel || !(methaneLevelCritical == 0)) || !(systemActive == 1))) && ((0 == \old(pumpRunning) || !(methaneLevelCritical == 0)) || !(systemActive == 1)) - InvariantResult [Line: 463]: Loop Invariant Derived loop invariant: ((!(methaneLevelCritical == 0) || !(systemActive == 1)) || (!(0 == \old(pumpRunning)) && pumpRunning == \old(pumpRunning))) && ((!(1 <= methaneLevelCritical) || !(systemActive == 1)) || (!(0 == \old(pumpRunning)) && pumpRunning == \old(pumpRunning))) - InvariantResult [Line: 836]: Loop Invariant Derived loop invariant: (((0 == \old(pumpRunning) || !(methaneLevelCritical == 0)) || !(systemActive == 1)) && ((((2 <= waterLevel && pumpRunning == 0) || ((tmp___0 == 0 && \result == 0) && pumpRunning == 0)) || !(methaneLevelCritical == 0)) || !(systemActive == 1))) && (((((2 <= waterLevel && pumpRunning == 0) || !(1 <= methaneLevelCritical)) || ((tmp___0 == 0 && pumpRunning == \old(pumpRunning)) && \result == 0)) || !(\old(pumpRunning) == 0)) || !(systemActive == 1)) - InvariantResult [Line: 71]: Loop Invariant Derived loop invariant: ((waterLevel == 1 && methaneLevelCritical == 0) && systemActive == 1) && pumpRunning == 0 - InvariantResult [Line: 772]: Loop Invariant Derived loop invariant: (((!(1 <= methaneLevelCritical) || !(\old(pumpRunning) == 0)) || !(systemActive == 1)) && ((!(1 <= methaneLevelCritical) || (1 <= tmp && pumpRunning == 0)) || !(systemActive == 1))) && ((!(methaneLevelCritical == 0) || (!(0 == \old(pumpRunning)) && pumpRunning == 0)) || !(systemActive == 1)) - InvariantResult [Line: 922]: Loop Invariant Derived loop invariant: (((((splverifierCounter == 0 && systemActive == tmp) && systemActive == \result) && 1 <= methaneLevelCritical) && systemActive == 1) && pumpRunning == 0) || ((((splverifierCounter == 0 && systemActive == tmp) && systemActive == \result) && methaneLevelCritical == 0) && systemActive == 1) - InvariantResult [Line: 722]: Loop Invariant Derived loop invariant: (((((((((!(0 == \old(pumpRunning)) && 1 <= tmp) && pumpRunning == 0) || (pumpRunning == \old(pumpRunning) && pumpRunning == 0)) || !(1 <= methaneLevelCritical)) || !(systemActive == 1)) && ((((!(\old(waterLevel) == 1) || waterLevel == 1) || !(1 <= methaneLevelCritical)) || !(\old(pumpRunning) == 0)) || !(systemActive == 1))) && ((((!(2 <= \old(waterLevel)) || ((!(0 == \old(pumpRunning)) && 1 <= tmp) && pumpRunning == 0)) || !(1 <= methaneLevelCritical)) || 2 <= waterLevel) || !(systemActive == 1))) && ((((!(2 <= \old(waterLevel)) || (methaneLevelCritical == 0 && 2 <= waterLevel)) || !(\old(pumpRunning) == 0)) || !(methaneLevelCritical == 0)) || !(systemActive == 1))) && ((((!(\old(waterLevel) == 1) || waterLevel == 1) || !(\old(pumpRunning) == 0)) || !(methaneLevelCritical == 0)) || !(systemActive == 1))) && (((((methaneLevelCritical == 0 && 2 <= waterLevel) || pumpRunning == \old(pumpRunning)) || !(methaneLevelCritical == 0)) || !(systemActive == 1)) || pumpRunning == 0) - InvariantResult [Line: 791]: Loop Invariant Derived loop invariant: (((!(methaneLevelCritical == 0) || !(systemActive == 1)) && ((((!(2 <= \old(waterLevel)) || !(1 <= methaneLevelCritical)) || !(\old(pumpRunning) == 0)) || 2 <= waterLevel) || !(systemActive == 1))) && ((((!(\old(waterLevel) == 1) || waterLevel == 1) || !(1 <= methaneLevelCritical)) || !(\old(pumpRunning) == 0)) || !(systemActive == 1))) && (((((1 <= tmp && \result == 0) && pumpRunning == 0) || ((\result == 0 && pumpRunning == \old(pumpRunning)) && pumpRunning == 0)) || !(1 <= methaneLevelCritical)) || !(systemActive == 1)) - InvariantResult [Line: 567]: Loop Invariant Derived loop invariant: 1 - InvariantResult [Line: 621]: Loop Invariant Derived loop invariant: 1 - InvariantResult [Line: 557]: Loop Invariant Derived loop invariant: 1 - InvariantResult [Line: 912]: Loop Invariant Derived loop invariant: 1 - InvariantResult [Line: 540]: Loop Invariant Derived loop invariant: ((((((2 <= waterLevel && pumpRunning == 0) || !(1 <= methaneLevelCritical)) || !(\old(pumpRunning) == 0)) || !(systemActive == 1)) || (\result == 1 && pumpRunning == 0)) && ((0 == \old(pumpRunning) || !(methaneLevelCritical == 0)) || !(systemActive == 1))) && ((((2 <= waterLevel && pumpRunning == 0) || !(methaneLevelCritical == 0)) || !(systemActive == 1)) || (\result == 1 && pumpRunning == 0)) - InvariantResult [Line: 632]: Loop Invariant Derived loop invariant: 1 RESULT: Ultimate proved your program to be correct! [2021-12-17 15:07:46,781 INFO L540 MonitoredProcess]: [MP /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in -t:2000 (1)] Forceful destruction successful, exit code 0 Received shutdown request... --- End real Ultimate output --- Execution finished normally Writing output log to file Ultimate.log Result: TRUE