./Ultimate.py --spec ../sv-benchmarks/c/properties/unreach-call.prp --file ../sv-benchmarks/c/product-lines/minepump_spec2_product47.cil.c --full-output --architecture 32bit -------------------------------------------------------------------------------- Checking for ERROR reachability Using default analysis Version c3fed411 Calling Ultimate with: /usr/bin/java -Dosgi.configuration.area=/storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/data/config -Xmx15G -Xms4m -jar /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/plugins/org.eclipse.equinox.launcher_1.5.800.v20200727-1323.jar -data @noDefault -ultimatedata /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/data -tc /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/config/AutomizerReach.xml -i ../sv-benchmarks/c/product-lines/minepump_spec2_product47.cil.c -s /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/config/svcomp-Reach-32bit-Automizer_Default.epf --cacsl2boogietranslator.entry.function main --witnessprinter.witness.directory /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux --witnessprinter.witness.filename witness.graphml --witnessprinter.write.witness.besides.input.file false --witnessprinter.graph.data.specification CHECK( init(main()), LTL(G ! call(reach_error())) ) --witnessprinter.graph.data.producer Automizer --witnessprinter.graph.data.architecture 32bit --witnessprinter.graph.data.programhash 2bb4b23c61a0ce6fb5d219efb233ba1e5b1970509ba14aea9115d570a0ea376d --- Real Ultimate output --- This is Ultimate 0.2.2-tmp.no-commuhash-c3fed41 [2021-12-17 15:07:39,709 INFO L177 SettingsManager]: Resetting all preferences to default values... [2021-12-17 15:07:39,712 INFO L181 SettingsManager]: Resetting UltimateCore preferences to default values [2021-12-17 15:07:39,763 INFO L184 SettingsManager]: Ultimate Commandline Interface provides no preferences, ignoring... [2021-12-17 15:07:39,764 INFO L181 SettingsManager]: Resetting Boogie Preprocessor preferences to default values [2021-12-17 15:07:39,767 INFO L181 SettingsManager]: Resetting Boogie Procedure Inliner preferences to default values [2021-12-17 15:07:39,768 INFO L181 SettingsManager]: Resetting Abstract Interpretation preferences to default values [2021-12-17 15:07:39,771 INFO L181 SettingsManager]: Resetting LassoRanker preferences to default values [2021-12-17 15:07:39,773 INFO L181 SettingsManager]: Resetting Reaching Definitions preferences to default values [2021-12-17 15:07:39,777 INFO L181 SettingsManager]: Resetting SyntaxChecker preferences to default values [2021-12-17 15:07:39,778 INFO L181 SettingsManager]: Resetting Sifa preferences to default values [2021-12-17 15:07:39,780 INFO L184 SettingsManager]: Büchi Program Product provides no preferences, ignoring... [2021-12-17 15:07:39,780 INFO L181 SettingsManager]: Resetting LTL2Aut preferences to default values [2021-12-17 15:07:39,782 INFO L181 SettingsManager]: Resetting PEA to Boogie preferences to default values [2021-12-17 15:07:39,784 INFO L181 SettingsManager]: Resetting BlockEncodingV2 preferences to default values [2021-12-17 15:07:39,787 INFO L181 SettingsManager]: Resetting ChcToBoogie preferences to default values [2021-12-17 15:07:39,788 INFO L181 SettingsManager]: Resetting AutomataScriptInterpreter preferences to default values [2021-12-17 15:07:39,789 INFO L181 SettingsManager]: Resetting BuchiAutomizer preferences to default values [2021-12-17 15:07:39,791 INFO L181 SettingsManager]: Resetting CACSL2BoogieTranslator preferences to default values [2021-12-17 15:07:39,796 INFO L181 SettingsManager]: Resetting CodeCheck preferences to default values [2021-12-17 15:07:39,798 INFO L181 SettingsManager]: Resetting InvariantSynthesis preferences to default values [2021-12-17 15:07:39,799 INFO L181 SettingsManager]: Resetting RCFGBuilder preferences to default values [2021-12-17 15:07:39,800 INFO L181 SettingsManager]: Resetting Referee preferences to default values [2021-12-17 15:07:39,801 INFO L181 SettingsManager]: Resetting TraceAbstraction preferences to default values [2021-12-17 15:07:39,807 INFO L184 SettingsManager]: TraceAbstractionConcurrent provides no preferences, ignoring... [2021-12-17 15:07:39,808 INFO L184 SettingsManager]: TraceAbstractionWithAFAs provides no preferences, ignoring... [2021-12-17 15:07:39,808 INFO L181 SettingsManager]: Resetting TreeAutomizer preferences to default values [2021-12-17 15:07:39,810 INFO L181 SettingsManager]: Resetting IcfgToChc preferences to default values [2021-12-17 15:07:39,810 INFO L181 SettingsManager]: Resetting IcfgTransformer preferences to default values [2021-12-17 15:07:39,811 INFO L184 SettingsManager]: ReqToTest provides no preferences, ignoring... [2021-12-17 15:07:39,811 INFO L181 SettingsManager]: Resetting Boogie Printer preferences to default values [2021-12-17 15:07:39,812 INFO L181 SettingsManager]: Resetting ChcSmtPrinter preferences to default values [2021-12-17 15:07:39,814 INFO L181 SettingsManager]: Resetting ReqPrinter preferences to default values [2021-12-17 15:07:39,815 INFO L181 SettingsManager]: Resetting Witness Printer preferences to default values [2021-12-17 15:07:39,816 INFO L184 SettingsManager]: Boogie PL CUP Parser provides no preferences, ignoring... [2021-12-17 15:07:39,816 INFO L181 SettingsManager]: Resetting CDTParser preferences to default values [2021-12-17 15:07:39,817 INFO L184 SettingsManager]: AutomataScriptParser provides no preferences, ignoring... [2021-12-17 15:07:39,817 INFO L184 SettingsManager]: ReqParser provides no preferences, ignoring... [2021-12-17 15:07:39,817 INFO L181 SettingsManager]: Resetting SmtParser preferences to default values [2021-12-17 15:07:39,818 INFO L181 SettingsManager]: Resetting Witness Parser preferences to default values [2021-12-17 15:07:39,819 INFO L188 SettingsManager]: Finished resetting all preferences to default values... [2021-12-17 15:07:39,821 INFO L101 SettingsManager]: Beginning loading settings from /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/config/svcomp-Reach-32bit-Automizer_Default.epf [2021-12-17 15:07:39,852 INFO L113 SettingsManager]: Loading preferences was successful [2021-12-17 15:07:39,852 INFO L115 SettingsManager]: Preferences different from defaults after loading the file: [2021-12-17 15:07:39,853 INFO L136 SettingsManager]: Preferences of UltimateCore differ from their defaults: [2021-12-17 15:07:39,853 INFO L138 SettingsManager]: * Log level for class=de.uni_freiburg.informatik.ultimate.lib.smtlibutils.quantifier.QuantifierPusher=ERROR; [2021-12-17 15:07:39,854 INFO L136 SettingsManager]: Preferences of Boogie Procedure Inliner differ from their defaults: [2021-12-17 15:07:39,854 INFO L138 SettingsManager]: * Ignore calls to procedures called more than once=ONLY_FOR_SEQUENTIAL_PROGRAMS [2021-12-17 15:07:39,855 INFO L136 SettingsManager]: Preferences of BlockEncodingV2 differ from their defaults: [2021-12-17 15:07:39,855 INFO L138 SettingsManager]: * Create parallel compositions if possible=false [2021-12-17 15:07:39,855 INFO L138 SettingsManager]: * Use SBE=true [2021-12-17 15:07:39,855 INFO L136 SettingsManager]: Preferences of CACSL2BoogieTranslator differ from their defaults: [2021-12-17 15:07:39,856 INFO L138 SettingsManager]: * sizeof long=4 [2021-12-17 15:07:39,857 INFO L138 SettingsManager]: * Overapproximate operations on floating types=true [2021-12-17 15:07:39,857 INFO L138 SettingsManager]: * sizeof POINTER=4 [2021-12-17 15:07:39,857 INFO L138 SettingsManager]: * Check division by zero=IGNORE [2021-12-17 15:07:39,857 INFO L138 SettingsManager]: * Pointer to allocated memory at dereference=IGNORE [2021-12-17 15:07:39,857 INFO L138 SettingsManager]: * If two pointers are subtracted or compared they have the same base address=IGNORE [2021-12-17 15:07:39,857 INFO L138 SettingsManager]: * Check array bounds for arrays that are off heap=IGNORE [2021-12-17 15:07:39,858 INFO L138 SettingsManager]: * sizeof long double=12 [2021-12-17 15:07:39,858 INFO L138 SettingsManager]: * Check if freed pointer was valid=false [2021-12-17 15:07:39,858 INFO L138 SettingsManager]: * Use constant arrays=true [2021-12-17 15:07:39,858 INFO L138 SettingsManager]: * Pointer base address is valid at dereference=IGNORE [2021-12-17 15:07:39,858 INFO L136 SettingsManager]: Preferences of RCFGBuilder differ from their defaults: [2021-12-17 15:07:39,859 INFO L138 SettingsManager]: * Size of a code block=SequenceOfStatements [2021-12-17 15:07:39,859 INFO L138 SettingsManager]: * SMT solver=External_DefaultMode [2021-12-17 15:07:39,859 INFO L138 SettingsManager]: * Command for external solver=z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in -t:2000 [2021-12-17 15:07:39,859 INFO L136 SettingsManager]: Preferences of TraceAbstraction differ from their defaults: [2021-12-17 15:07:39,859 INFO L138 SettingsManager]: * Compute Interpolants along a Counterexample=FPandBP [2021-12-17 15:07:39,861 INFO L138 SettingsManager]: * Positions where we compute the Hoare Annotation=LoopsAndPotentialCycles [2021-12-17 15:07:39,861 INFO L138 SettingsManager]: * Trace refinement strategy=CAMEL [2021-12-17 15:07:39,861 INFO L138 SettingsManager]: * Command for external solver=z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in [2021-12-17 15:07:39,861 INFO L138 SettingsManager]: * Large block encoding in concurrent analysis=OFF [2021-12-17 15:07:39,862 INFO L138 SettingsManager]: * Automaton type used in concurrency analysis=PETRI_NET [2021-12-17 15:07:39,862 INFO L138 SettingsManager]: * Compute Hoare Annotation of negated interpolant automaton, abstraction and CFG=true [2021-12-17 15:07:39,862 INFO L138 SettingsManager]: * Trace refinement exception blacklist=NONE [2021-12-17 15:07:39,862 INFO L138 SettingsManager]: * SMT solver=External_ModelsAndUnsatCoreMode WARNING: An illegal reflective access operation has occurred WARNING: Illegal reflective access by com.sun.xml.bind.v2.runtime.reflect.opt.Injector$1 (file:/storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/plugins/com.sun.xml.bind_2.2.0.v201505121915.jar) to method java.lang.ClassLoader.defineClass(java.lang.String,byte[],int,int) WARNING: Please consider reporting this to the maintainers of com.sun.xml.bind.v2.runtime.reflect.opt.Injector$1 WARNING: Use --illegal-access=warn to enable warnings of further illegal reflective access operations WARNING: All illegal access operations will be denied in a future release Applying setting for plugin de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator: Entry function -> main Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Witness directory -> /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Witness filename -> witness.graphml Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Write witness besides input file -> false Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Graph data specification -> CHECK( init(main()), LTL(G ! call(reach_error())) ) Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Graph data producer -> Automizer Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Graph data architecture -> 32bit Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Graph data programhash -> 2bb4b23c61a0ce6fb5d219efb233ba1e5b1970509ba14aea9115d570a0ea376d [2021-12-17 15:07:40,118 INFO L75 nceAwareModelManager]: Repository-Root is: /tmp [2021-12-17 15:07:40,147 INFO L261 ainManager$Toolchain]: [Toolchain 1]: Applicable parser(s) successfully (re)initialized [2021-12-17 15:07:40,149 INFO L217 ainManager$Toolchain]: [Toolchain 1]: Toolchain selected. [2021-12-17 15:07:40,151 INFO L271 PluginConnector]: Initializing CDTParser... [2021-12-17 15:07:40,151 INFO L275 PluginConnector]: CDTParser initialized [2021-12-17 15:07:40,153 INFO L432 ainManager$Toolchain]: [Toolchain 1]: Parsing single file: /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/../sv-benchmarks/c/product-lines/minepump_spec2_product47.cil.c [2021-12-17 15:07:40,225 INFO L220 CDTParser]: Created temporary CDT project at /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/data/35fe5bc35/7fa2bded9ca34bf1b09c95480527a63b/FLAG201c86166 [2021-12-17 15:07:40,652 INFO L306 CDTParser]: Found 1 translation units. [2021-12-17 15:07:40,661 INFO L160 CDTParser]: Scanning /storage/repos/ultimate/releaseScripts/default/sv-benchmarks/c/product-lines/minepump_spec2_product47.cil.c [2021-12-17 15:07:40,671 INFO L349 CDTParser]: About to delete temporary CDT project at /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/data/35fe5bc35/7fa2bded9ca34bf1b09c95480527a63b/FLAG201c86166 [2021-12-17 15:07:41,029 INFO L357 CDTParser]: Successfully deleted /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/data/35fe5bc35/7fa2bded9ca34bf1b09c95480527a63b [2021-12-17 15:07:41,031 INFO L299 ainManager$Toolchain]: ####################### [Toolchain 1] ####################### [2021-12-17 15:07:41,033 INFO L131 ToolchainWalker]: Walking toolchain with 6 elements. [2021-12-17 15:07:41,035 INFO L113 PluginConnector]: ------------------------CACSL2BoogieTranslator---------------------------- [2021-12-17 15:07:41,035 INFO L271 PluginConnector]: Initializing CACSL2BoogieTranslator... [2021-12-17 15:07:41,037 INFO L275 PluginConnector]: CACSL2BoogieTranslator initialized [2021-12-17 15:07:41,038 INFO L185 PluginConnector]: Executing the observer ACSLObjectContainerObserver from plugin CACSL2BoogieTranslator for "CDTParser AST 17.12 03:07:41" (1/1) ... [2021-12-17 15:07:41,039 INFO L205 PluginConnector]: Invalid model from CACSL2BoogieTranslator for observer de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator.ACSLObjectContainerObserver@c3475c3 and model type de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 17.12 03:07:41, skipping insertion in model container [2021-12-17 15:07:41,039 INFO L185 PluginConnector]: Executing the observer CACSL2BoogieTranslatorObserver from plugin CACSL2BoogieTranslator for "CDTParser AST 17.12 03:07:41" (1/1) ... [2021-12-17 15:07:41,044 INFO L145 MainTranslator]: Starting translation in SV-COMP mode [2021-12-17 15:07:41,079 INFO L178 MainTranslator]: Built tables and reachable declarations [2021-12-17 15:07:41,229 WARN L230 ndardFunctionHandler]: Function reach_error is already implemented but we override the implementation for the call at /storage/repos/ultimate/releaseScripts/default/sv-benchmarks/c/product-lines/minepump_spec2_product47.cil.c[1605,1618] [2021-12-17 15:07:41,326 INFO L209 PostProcessor]: Analyzing one entry point: main [2021-12-17 15:07:41,333 INFO L203 MainTranslator]: Completed pre-run [2021-12-17 15:07:41,343 WARN L230 ndardFunctionHandler]: Function reach_error is already implemented but we override the implementation for the call at /storage/repos/ultimate/releaseScripts/default/sv-benchmarks/c/product-lines/minepump_spec2_product47.cil.c[1605,1618] [2021-12-17 15:07:41,396 INFO L209 PostProcessor]: Analyzing one entry point: main [2021-12-17 15:07:41,410 INFO L208 MainTranslator]: Completed translation [2021-12-17 15:07:41,411 INFO L202 PluginConnector]: Adding new model de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 17.12 03:07:41 WrapperNode [2021-12-17 15:07:41,411 INFO L132 PluginConnector]: ------------------------ END CACSL2BoogieTranslator---------------------------- [2021-12-17 15:07:41,412 INFO L113 PluginConnector]: ------------------------Boogie Procedure Inliner---------------------------- [2021-12-17 15:07:41,412 INFO L271 PluginConnector]: Initializing Boogie Procedure Inliner... [2021-12-17 15:07:41,412 INFO L275 PluginConnector]: Boogie Procedure Inliner initialized [2021-12-17 15:07:41,418 INFO L185 PluginConnector]: Executing the observer TypeChecker from plugin Boogie Procedure Inliner for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 17.12 03:07:41" (1/1) ... [2021-12-17 15:07:41,437 INFO L185 PluginConnector]: Executing the observer Inliner from plugin Boogie Procedure Inliner for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 17.12 03:07:41" (1/1) ... [2021-12-17 15:07:41,467 INFO L137 Inliner]: procedures = 56, calls = 158, calls flagged for inlining = 22, calls inlined = 19, statements flattened = 249 [2021-12-17 15:07:41,468 INFO L132 PluginConnector]: ------------------------ END Boogie Procedure Inliner---------------------------- [2021-12-17 15:07:41,469 INFO L113 PluginConnector]: ------------------------Boogie Preprocessor---------------------------- [2021-12-17 15:07:41,469 INFO L271 PluginConnector]: Initializing Boogie Preprocessor... [2021-12-17 15:07:41,469 INFO L275 PluginConnector]: Boogie Preprocessor initialized [2021-12-17 15:07:41,476 INFO L185 PluginConnector]: Executing the observer EnsureBoogieModelObserver from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 17.12 03:07:41" (1/1) ... [2021-12-17 15:07:41,476 INFO L185 PluginConnector]: Executing the observer TypeChecker from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 17.12 03:07:41" (1/1) ... [2021-12-17 15:07:41,487 INFO L185 PluginConnector]: Executing the observer ConstExpander from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 17.12 03:07:41" (1/1) ... [2021-12-17 15:07:41,488 INFO L185 PluginConnector]: Executing the observer StructExpander from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 17.12 03:07:41" (1/1) ... [2021-12-17 15:07:41,500 INFO L185 PluginConnector]: Executing the observer UnstructureCode from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 17.12 03:07:41" (1/1) ... [2021-12-17 15:07:41,512 INFO L185 PluginConnector]: Executing the observer FunctionInliner from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 17.12 03:07:41" (1/1) ... [2021-12-17 15:07:41,516 INFO L185 PluginConnector]: Executing the observer BoogieSymbolTableConstructor from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 17.12 03:07:41" (1/1) ... [2021-12-17 15:07:41,518 INFO L132 PluginConnector]: ------------------------ END Boogie Preprocessor---------------------------- [2021-12-17 15:07:41,519 INFO L113 PluginConnector]: ------------------------RCFGBuilder---------------------------- [2021-12-17 15:07:41,519 INFO L271 PluginConnector]: Initializing RCFGBuilder... [2021-12-17 15:07:41,520 INFO L275 PluginConnector]: RCFGBuilder initialized [2021-12-17 15:07:41,521 INFO L185 PluginConnector]: Executing the observer RCFGBuilderObserver from plugin RCFGBuilder for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 17.12 03:07:41" (1/1) ... [2021-12-17 15:07:41,526 INFO L168 SolverBuilder]: Constructing external solver with command: z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in -t:2000 [2021-12-17 15:07:41,537 INFO L189 MonitoredProcess]: No working directory specified, using /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 [2021-12-17 15:07:41,550 INFO L229 MonitoredProcess]: Starting monitored process 1 with /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in -t:2000 (exit command is (exit), workingDir is null) [2021-12-17 15:07:41,553 INFO L327 MonitoredProcess]: [MP /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in -t:2000 (1)] Waiting until timeout for monitored process [2021-12-17 15:07:41,588 INFO L130 BoogieDeclarations]: Found specification of procedure #Ultimate.allocInit [2021-12-17 15:07:41,588 INFO L130 BoogieDeclarations]: Found specification of procedure processEnvironment__wrappee__base [2021-12-17 15:07:41,588 INFO L138 BoogieDeclarations]: Found implementation of procedure processEnvironment__wrappee__base [2021-12-17 15:07:41,589 INFO L130 BoogieDeclarations]: Found specification of procedure timeShift [2021-12-17 15:07:41,589 INFO L138 BoogieDeclarations]: Found implementation of procedure timeShift [2021-12-17 15:07:41,589 INFO L130 BoogieDeclarations]: Found specification of procedure cleanup [2021-12-17 15:07:41,589 INFO L138 BoogieDeclarations]: Found implementation of procedure cleanup [2021-12-17 15:07:41,589 INFO L130 BoogieDeclarations]: Found specification of procedure isMethaneLevelCritical [2021-12-17 15:07:41,590 INFO L138 BoogieDeclarations]: Found implementation of procedure isMethaneLevelCritical [2021-12-17 15:07:41,590 INFO L130 BoogieDeclarations]: Found specification of procedure waterRise [2021-12-17 15:07:41,590 INFO L138 BoogieDeclarations]: Found implementation of procedure waterRise [2021-12-17 15:07:41,590 INFO L130 BoogieDeclarations]: Found specification of procedure processEnvironment__wrappee__methaneQuery [2021-12-17 15:07:41,590 INFO L138 BoogieDeclarations]: Found implementation of procedure processEnvironment__wrappee__methaneQuery [2021-12-17 15:07:41,591 INFO L130 BoogieDeclarations]: Found specification of procedure isMethaneAlarm [2021-12-17 15:07:41,591 INFO L138 BoogieDeclarations]: Found implementation of procedure isMethaneAlarm [2021-12-17 15:07:41,591 INFO L130 BoogieDeclarations]: Found specification of procedure deactivatePump [2021-12-17 15:07:41,591 INFO L138 BoogieDeclarations]: Found implementation of procedure deactivatePump [2021-12-17 15:07:41,591 INFO L130 BoogieDeclarations]: Found specification of procedure write~init~int [2021-12-17 15:07:41,591 INFO L130 BoogieDeclarations]: Found specification of procedure changeMethaneLevel [2021-12-17 15:07:41,591 INFO L138 BoogieDeclarations]: Found implementation of procedure changeMethaneLevel [2021-12-17 15:07:41,591 INFO L130 BoogieDeclarations]: Found specification of procedure ULTIMATE.start [2021-12-17 15:07:41,591 INFO L138 BoogieDeclarations]: Found implementation of procedure ULTIMATE.start [2021-12-17 15:07:41,669 INFO L236 CfgBuilder]: Building ICFG [2021-12-17 15:07:41,670 INFO L262 CfgBuilder]: Building CFG for each procedure with an implementation [2021-12-17 15:07:41,937 INFO L277 CfgBuilder]: Performing block encoding [2021-12-17 15:07:41,954 INFO L296 CfgBuilder]: Using the 1 location(s) as analysis (start of procedure ULTIMATE.start) [2021-12-17 15:07:41,957 INFO L301 CfgBuilder]: Removed 2 assume(true) statements. [2021-12-17 15:07:41,959 INFO L202 PluginConnector]: Adding new model de.uni_freiburg.informatik.ultimate.plugins.generator.rcfgbuilder CFG 17.12 03:07:41 BoogieIcfgContainer [2021-12-17 15:07:41,960 INFO L132 PluginConnector]: ------------------------ END RCFGBuilder---------------------------- [2021-12-17 15:07:41,962 INFO L113 PluginConnector]: ------------------------TraceAbstraction---------------------------- [2021-12-17 15:07:41,962 INFO L271 PluginConnector]: Initializing TraceAbstraction... [2021-12-17 15:07:41,965 INFO L275 PluginConnector]: TraceAbstraction initialized [2021-12-17 15:07:41,966 INFO L185 PluginConnector]: Executing the observer TraceAbstractionObserver from plugin TraceAbstraction for "CDTParser AST 17.12 03:07:41" (1/3) ... [2021-12-17 15:07:41,967 INFO L205 PluginConnector]: Invalid model from TraceAbstraction for observer de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction.TraceAbstractionObserver@27e534cd and model type de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction AST 17.12 03:07:41, skipping insertion in model container [2021-12-17 15:07:41,967 INFO L185 PluginConnector]: Executing the observer TraceAbstractionObserver from plugin TraceAbstraction for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 17.12 03:07:41" (2/3) ... [2021-12-17 15:07:41,967 INFO L205 PluginConnector]: Invalid model from TraceAbstraction for observer de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction.TraceAbstractionObserver@27e534cd and model type de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction AST 17.12 03:07:41, skipping insertion in model container [2021-12-17 15:07:41,968 INFO L185 PluginConnector]: Executing the observer TraceAbstractionObserver from plugin TraceAbstraction for "de.uni_freiburg.informatik.ultimate.plugins.generator.rcfgbuilder CFG 17.12 03:07:41" (3/3) ... [2021-12-17 15:07:41,969 INFO L111 eAbstractionObserver]: Analyzing ICFG minepump_spec2_product47.cil.c [2021-12-17 15:07:41,974 INFO L204 ceAbstractionStarter]: Automizer settings: Hoare:true NWA Interpolation:FPandBP Determinization: PREDICATE_ABSTRACTION [2021-12-17 15:07:41,974 INFO L163 ceAbstractionStarter]: Applying trace abstraction to program that has 1 error locations. [2021-12-17 15:07:42,026 INFO L338 AbstractCegarLoop]: ======== Iteration 0 == of CEGAR loop == AllErrorsAtOnce ======== [2021-12-17 15:07:42,032 INFO L339 AbstractCegarLoop]: Settings: SEPARATE_VIOLATION_CHECK=true, mInterprocedural=true, mMaxIterations=1000000, mWatchIteration=1000000, mArtifact=RCFG, mInterpolation=FPandBP, mInterpolantAutomaton=STRAIGHT_LINE, mDumpAutomata=false, mAutomataFormat=ATS_NUMERATE, mDumpPath=., mDeterminiation=PREDICATE_ABSTRACTION, mMinimize=MINIMIZE_SEVPA, mHoare=true, mAutomataTypeConcurrency=PETRI_NET, mHoareTripleChecks=INCREMENTAL, mHoareAnnotationPositions=LoopsAndPotentialCycles, mDumpOnlyReuseAutomata=false, mLimitTraceHistogram=0, mErrorLocTimeLimit=0, mLimitPathProgramCount=0, mCollectInterpolantStatistics=true, mHeuristicEmptinessCheck=false, mHeuristicEmptinessCheckAStarHeuristic=ZERO, mHeuristicEmptinessCheckAStarHeuristicRandomSeed=1337, mHeuristicEmptinessCheckSmtFeatureScoringMethod=DAGSIZE, mSMTFeatureExtraction=false, mSMTFeatureExtractionDumpPath=., mOverrideInterpolantAutomaton=false, mMcrInterpolantMethod=WP, mLoopAccelerationTechnique=FAST_UPR [2021-12-17 15:07:42,032 INFO L340 AbstractCegarLoop]: Starting to check reachability of 1 error locations. [2021-12-17 15:07:42,054 INFO L276 IsEmpty]: Start isEmpty. Operand has 102 states, 75 states have (on average 1.3733333333333333) internal successors, (103), 84 states have internal predecessors, (103), 16 states have call successors, (16), 9 states have call predecessors, (16), 9 states have return successors, (16), 13 states have call predecessors, (16), 16 states have call successors, (16) [2021-12-17 15:07:42,060 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 26 [2021-12-17 15:07:42,060 INFO L506 BasicCegarLoop]: Found error trace [2021-12-17 15:07:42,061 INFO L514 BasicCegarLoop]: trace histogram [1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2021-12-17 15:07:42,061 INFO L402 AbstractCegarLoop]: === Iteration 1 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2021-12-17 15:07:42,065 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2021-12-17 15:07:42,065 INFO L85 PathProgramCache]: Analyzing trace with hash -320439114, now seen corresponding path program 1 times [2021-12-17 15:07:42,072 INFO L121 FreeRefinementEngine]: Executing refinement strategy CAMEL [2021-12-17 15:07:42,072 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [702437920] [2021-12-17 15:07:42,073 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2021-12-17 15:07:42,073 INFO L126 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2021-12-17 15:07:42,172 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:07:42,245 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 15 [2021-12-17 15:07:42,248 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:07:42,253 INFO L134 CoverageAnalysis]: Checked inductivity of 0 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2021-12-17 15:07:42,254 INFO L139 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2021-12-17 15:07:42,254 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [702437920] [2021-12-17 15:07:42,255 INFO L160 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [702437920] provided 1 perfect and 0 imperfect interpolant sequences [2021-12-17 15:07:42,255 INFO L186 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2021-12-17 15:07:42,256 INFO L199 FreeRefinementEngine]: Number of different interpolants: perfect sequences [2] imperfect sequences [] total 2 [2021-12-17 15:07:42,257 INFO L115 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [1911784550] [2021-12-17 15:07:42,258 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2021-12-17 15:07:42,261 INFO L546 AbstractCegarLoop]: INTERPOLANT automaton has 2 states [2021-12-17 15:07:42,262 INFO L103 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2021-12-17 15:07:42,291 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 2 interpolants. [2021-12-17 15:07:42,295 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=1, Invalid=1, Unknown=0, NotChecked=0, Total=2 [2021-12-17 15:07:42,298 INFO L87 Difference]: Start difference. First operand has 102 states, 75 states have (on average 1.3733333333333333) internal successors, (103), 84 states have internal predecessors, (103), 16 states have call successors, (16), 9 states have call predecessors, (16), 9 states have return successors, (16), 13 states have call predecessors, (16), 16 states have call successors, (16) Second operand has 2 states, 2 states have (on average 10.5) internal successors, (21), 2 states have internal predecessors, (21), 1 states have call successors, (3), 2 states have call predecessors, (3), 1 states have return successors, (1), 1 states have call predecessors, (1), 1 states have call successors, (1) [2021-12-17 15:07:42,330 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2021-12-17 15:07:42,330 INFO L93 Difference]: Finished difference Result 195 states and 264 transitions. [2021-12-17 15:07:42,331 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 2 states. [2021-12-17 15:07:42,332 INFO L78 Accepts]: Start accepts. Automaton has has 2 states, 2 states have (on average 10.5) internal successors, (21), 2 states have internal predecessors, (21), 1 states have call successors, (3), 2 states have call predecessors, (3), 1 states have return successors, (1), 1 states have call predecessors, (1), 1 states have call successors, (1) Word has length 25 [2021-12-17 15:07:42,333 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2021-12-17 15:07:42,340 INFO L225 Difference]: With dead ends: 195 [2021-12-17 15:07:42,340 INFO L226 Difference]: Without dead ends: 93 [2021-12-17 15:07:42,344 INFO L932 BasicCegarLoop]: 0 DeclaredPredicates, 4 GetRequests, 4 SyntacticMatches, 0 SemanticMatches, 0 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 0 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=1, Invalid=1, Unknown=0, NotChecked=0, Total=2 [2021-12-17 15:07:42,347 INFO L933 BasicCegarLoop]: 129 mSDtfsCounter, 0 mSDsluCounter, 0 mSDsCounter, 0 mSdLazyCounter, 0 mSolverCounterSat, 0 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.0s Time, 0 mProtectedPredicate, 0 mProtectedAction, 0 SdHoareTripleChecker+Valid, 129 SdHoareTripleChecker+Invalid, 0 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 0 IncrementalHoareTripleChecker+Valid, 0 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.0s IncrementalHoareTripleChecker+Time [2021-12-17 15:07:42,348 INFO L934 BasicCegarLoop]: SdHoareTripleChecker [0 Valid, 129 Invalid, 0 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [0 Valid, 0 Invalid, 0 Unknown, 0 Unchecked, 0.0s Time] [2021-12-17 15:07:42,361 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 93 states. [2021-12-17 15:07:42,381 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 93 to 93. [2021-12-17 15:07:42,382 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 93 states, 68 states have (on average 1.3088235294117647) internal successors, (89), 76 states have internal predecessors, (89), 16 states have call successors, (16), 9 states have call predecessors, (16), 8 states have return successors, (15), 12 states have call predecessors, (15), 15 states have call successors, (15) [2021-12-17 15:07:42,385 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 93 states to 93 states and 120 transitions. [2021-12-17 15:07:42,386 INFO L78 Accepts]: Start accepts. Automaton has 93 states and 120 transitions. Word has length 25 [2021-12-17 15:07:42,386 INFO L84 Accepts]: Finished accepts. word is rejected. [2021-12-17 15:07:42,386 INFO L470 AbstractCegarLoop]: Abstraction has 93 states and 120 transitions. [2021-12-17 15:07:42,387 INFO L471 AbstractCegarLoop]: INTERPOLANT automaton has has 2 states, 2 states have (on average 10.5) internal successors, (21), 2 states have internal predecessors, (21), 1 states have call successors, (3), 2 states have call predecessors, (3), 1 states have return successors, (1), 1 states have call predecessors, (1), 1 states have call successors, (1) [2021-12-17 15:07:42,387 INFO L276 IsEmpty]: Start isEmpty. Operand 93 states and 120 transitions. [2021-12-17 15:07:42,389 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 27 [2021-12-17 15:07:42,389 INFO L506 BasicCegarLoop]: Found error trace [2021-12-17 15:07:42,389 INFO L514 BasicCegarLoop]: trace histogram [1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2021-12-17 15:07:42,390 WARN L452 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable0 [2021-12-17 15:07:42,390 INFO L402 AbstractCegarLoop]: === Iteration 2 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2021-12-17 15:07:42,391 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2021-12-17 15:07:42,391 INFO L85 PathProgramCache]: Analyzing trace with hash -1934434610, now seen corresponding path program 1 times [2021-12-17 15:07:42,391 INFO L121 FreeRefinementEngine]: Executing refinement strategy CAMEL [2021-12-17 15:07:42,391 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [1137122661] [2021-12-17 15:07:42,391 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2021-12-17 15:07:42,392 INFO L126 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2021-12-17 15:07:42,417 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:07:42,469 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 16 [2021-12-17 15:07:42,471 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:07:42,478 INFO L134 CoverageAnalysis]: Checked inductivity of 0 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2021-12-17 15:07:42,478 INFO L139 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2021-12-17 15:07:42,478 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [1137122661] [2021-12-17 15:07:42,478 INFO L160 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [1137122661] provided 1 perfect and 0 imperfect interpolant sequences [2021-12-17 15:07:42,478 INFO L186 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2021-12-17 15:07:42,479 INFO L199 FreeRefinementEngine]: Number of different interpolants: perfect sequences [3] imperfect sequences [] total 3 [2021-12-17 15:07:42,479 INFO L115 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [189277717] [2021-12-17 15:07:42,479 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2021-12-17 15:07:42,480 INFO L546 AbstractCegarLoop]: INTERPOLANT automaton has 3 states [2021-12-17 15:07:42,480 INFO L103 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2021-12-17 15:07:42,481 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 3 interpolants. [2021-12-17 15:07:42,481 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=3, Invalid=3, Unknown=0, NotChecked=0, Total=6 [2021-12-17 15:07:42,481 INFO L87 Difference]: Start difference. First operand 93 states and 120 transitions. Second operand has 3 states, 3 states have (on average 7.333333333333333) internal successors, (22), 3 states have internal predecessors, (22), 1 states have call successors, (3), 2 states have call predecessors, (3), 1 states have return successors, (1), 1 states have call predecessors, (1), 1 states have call successors, (1) [2021-12-17 15:07:42,497 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2021-12-17 15:07:42,497 INFO L93 Difference]: Finished difference Result 147 states and 189 transitions. [2021-12-17 15:07:42,497 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 3 states. [2021-12-17 15:07:42,498 INFO L78 Accepts]: Start accepts. Automaton has has 3 states, 3 states have (on average 7.333333333333333) internal successors, (22), 3 states have internal predecessors, (22), 1 states have call successors, (3), 2 states have call predecessors, (3), 1 states have return successors, (1), 1 states have call predecessors, (1), 1 states have call successors, (1) Word has length 26 [2021-12-17 15:07:42,498 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2021-12-17 15:07:42,499 INFO L225 Difference]: With dead ends: 147 [2021-12-17 15:07:42,499 INFO L226 Difference]: Without dead ends: 84 [2021-12-17 15:07:42,500 INFO L932 BasicCegarLoop]: 0 DeclaredPredicates, 5 GetRequests, 4 SyntacticMatches, 0 SemanticMatches, 1 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 0 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=3, Invalid=3, Unknown=0, NotChecked=0, Total=6 [2021-12-17 15:07:42,501 INFO L933 BasicCegarLoop]: 107 mSDtfsCounter, 16 mSDsluCounter, 86 mSDsCounter, 0 mSdLazyCounter, 1 mSolverCounterSat, 0 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.0s Time, 0 mProtectedPredicate, 0 mProtectedAction, 20 SdHoareTripleChecker+Valid, 193 SdHoareTripleChecker+Invalid, 1 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 0 IncrementalHoareTripleChecker+Valid, 1 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.0s IncrementalHoareTripleChecker+Time [2021-12-17 15:07:42,502 INFO L934 BasicCegarLoop]: SdHoareTripleChecker [20 Valid, 193 Invalid, 1 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [0 Valid, 1 Invalid, 0 Unknown, 0 Unchecked, 0.0s Time] [2021-12-17 15:07:42,503 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 84 states. [2021-12-17 15:07:42,510 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 84 to 84. [2021-12-17 15:07:42,514 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 84 states, 62 states have (on average 1.3225806451612903) internal successors, (82), 70 states have internal predecessors, (82), 13 states have call successors, (13), 8 states have call predecessors, (13), 8 states have return successors, (13), 10 states have call predecessors, (13), 13 states have call successors, (13) [2021-12-17 15:07:42,520 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 84 states to 84 states and 108 transitions. [2021-12-17 15:07:42,521 INFO L78 Accepts]: Start accepts. Automaton has 84 states and 108 transitions. Word has length 26 [2021-12-17 15:07:42,521 INFO L84 Accepts]: Finished accepts. word is rejected. [2021-12-17 15:07:42,522 INFO L470 AbstractCegarLoop]: Abstraction has 84 states and 108 transitions. [2021-12-17 15:07:42,522 INFO L471 AbstractCegarLoop]: INTERPOLANT automaton has has 3 states, 3 states have (on average 7.333333333333333) internal successors, (22), 3 states have internal predecessors, (22), 1 states have call successors, (3), 2 states have call predecessors, (3), 1 states have return successors, (1), 1 states have call predecessors, (1), 1 states have call successors, (1) [2021-12-17 15:07:42,523 INFO L276 IsEmpty]: Start isEmpty. Operand 84 states and 108 transitions. [2021-12-17 15:07:42,526 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 31 [2021-12-17 15:07:42,528 INFO L506 BasicCegarLoop]: Found error trace [2021-12-17 15:07:42,528 INFO L514 BasicCegarLoop]: trace histogram [1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2021-12-17 15:07:42,529 WARN L452 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable1 [2021-12-17 15:07:42,529 INFO L402 AbstractCegarLoop]: === Iteration 3 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2021-12-17 15:07:42,530 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2021-12-17 15:07:42,531 INFO L85 PathProgramCache]: Analyzing trace with hash -172475024, now seen corresponding path program 1 times [2021-12-17 15:07:42,531 INFO L121 FreeRefinementEngine]: Executing refinement strategy CAMEL [2021-12-17 15:07:42,531 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [1017154019] [2021-12-17 15:07:42,531 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2021-12-17 15:07:42,531 INFO L126 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2021-12-17 15:07:42,553 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:07:42,625 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 20 [2021-12-17 15:07:42,627 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:07:42,630 INFO L134 CoverageAnalysis]: Checked inductivity of 0 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2021-12-17 15:07:42,637 INFO L139 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2021-12-17 15:07:42,637 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [1017154019] [2021-12-17 15:07:42,638 INFO L160 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [1017154019] provided 1 perfect and 0 imperfect interpolant sequences [2021-12-17 15:07:42,638 INFO L186 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2021-12-17 15:07:42,638 INFO L199 FreeRefinementEngine]: Number of different interpolants: perfect sequences [3] imperfect sequences [] total 3 [2021-12-17 15:07:42,638 INFO L115 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [705608640] [2021-12-17 15:07:42,639 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2021-12-17 15:07:42,639 INFO L546 AbstractCegarLoop]: INTERPOLANT automaton has 3 states [2021-12-17 15:07:42,639 INFO L103 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2021-12-17 15:07:42,640 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 3 interpolants. [2021-12-17 15:07:42,640 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=3, Invalid=3, Unknown=0, NotChecked=0, Total=6 [2021-12-17 15:07:42,640 INFO L87 Difference]: Start difference. First operand 84 states and 108 transitions. Second operand has 3 states, 3 states have (on average 9.0) internal successors, (27), 3 states have internal predecessors, (27), 2 states have call successors, (2), 2 states have call predecessors, (2), 1 states have return successors, (1), 1 states have call predecessors, (1), 1 states have call successors, (1) [2021-12-17 15:07:42,669 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2021-12-17 15:07:42,669 INFO L93 Difference]: Finished difference Result 235 states and 308 transitions. [2021-12-17 15:07:42,670 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 3 states. [2021-12-17 15:07:42,670 INFO L78 Accepts]: Start accepts. Automaton has has 3 states, 3 states have (on average 9.0) internal successors, (27), 3 states have internal predecessors, (27), 2 states have call successors, (2), 2 states have call predecessors, (2), 1 states have return successors, (1), 1 states have call predecessors, (1), 1 states have call successors, (1) Word has length 30 [2021-12-17 15:07:42,670 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2021-12-17 15:07:42,672 INFO L225 Difference]: With dead ends: 235 [2021-12-17 15:07:42,672 INFO L226 Difference]: Without dead ends: 159 [2021-12-17 15:07:42,673 INFO L932 BasicCegarLoop]: 0 DeclaredPredicates, 4 GetRequests, 3 SyntacticMatches, 0 SemanticMatches, 1 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 0 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=3, Invalid=3, Unknown=0, NotChecked=0, Total=6 [2021-12-17 15:07:42,674 INFO L933 BasicCegarLoop]: 138 mSDtfsCounter, 87 mSDsluCounter, 97 mSDsCounter, 0 mSdLazyCounter, 4 mSolverCounterSat, 0 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.0s Time, 0 mProtectedPredicate, 0 mProtectedAction, 87 SdHoareTripleChecker+Valid, 235 SdHoareTripleChecker+Invalid, 4 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 0 IncrementalHoareTripleChecker+Valid, 4 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.0s IncrementalHoareTripleChecker+Time [2021-12-17 15:07:42,675 INFO L934 BasicCegarLoop]: SdHoareTripleChecker [87 Valid, 235 Invalid, 4 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [0 Valid, 4 Invalid, 0 Unknown, 0 Unchecked, 0.0s Time] [2021-12-17 15:07:42,676 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 159 states. [2021-12-17 15:07:42,695 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 159 to 156. [2021-12-17 15:07:42,696 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 156 states, 113 states have (on average 1.345132743362832) internal successors, (152), 128 states have internal predecessors, (152), 26 states have call successors, (26), 16 states have call predecessors, (26), 16 states have return successors, (26), 19 states have call predecessors, (26), 26 states have call successors, (26) [2021-12-17 15:07:42,698 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 156 states to 156 states and 204 transitions. [2021-12-17 15:07:42,698 INFO L78 Accepts]: Start accepts. Automaton has 156 states and 204 transitions. Word has length 30 [2021-12-17 15:07:42,698 INFO L84 Accepts]: Finished accepts. word is rejected. [2021-12-17 15:07:42,699 INFO L470 AbstractCegarLoop]: Abstraction has 156 states and 204 transitions. [2021-12-17 15:07:42,699 INFO L471 AbstractCegarLoop]: INTERPOLANT automaton has has 3 states, 3 states have (on average 9.0) internal successors, (27), 3 states have internal predecessors, (27), 2 states have call successors, (2), 2 states have call predecessors, (2), 1 states have return successors, (1), 1 states have call predecessors, (1), 1 states have call successors, (1) [2021-12-17 15:07:42,699 INFO L276 IsEmpty]: Start isEmpty. Operand 156 states and 204 transitions. [2021-12-17 15:07:42,700 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 35 [2021-12-17 15:07:42,700 INFO L506 BasicCegarLoop]: Found error trace [2021-12-17 15:07:42,701 INFO L514 BasicCegarLoop]: trace histogram [1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2021-12-17 15:07:42,701 WARN L452 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable2 [2021-12-17 15:07:42,701 INFO L402 AbstractCegarLoop]: === Iteration 4 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2021-12-17 15:07:42,702 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2021-12-17 15:07:42,702 INFO L85 PathProgramCache]: Analyzing trace with hash -1019876102, now seen corresponding path program 1 times [2021-12-17 15:07:42,702 INFO L121 FreeRefinementEngine]: Executing refinement strategy CAMEL [2021-12-17 15:07:42,702 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [907931199] [2021-12-17 15:07:42,702 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2021-12-17 15:07:42,703 INFO L126 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2021-12-17 15:07:42,722 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:07:42,765 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 24 [2021-12-17 15:07:42,767 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:07:42,777 INFO L134 CoverageAnalysis]: Checked inductivity of 0 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2021-12-17 15:07:42,777 INFO L139 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2021-12-17 15:07:42,777 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [907931199] [2021-12-17 15:07:42,777 INFO L160 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [907931199] provided 1 perfect and 0 imperfect interpolant sequences [2021-12-17 15:07:42,778 INFO L186 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2021-12-17 15:07:42,778 INFO L199 FreeRefinementEngine]: Number of different interpolants: perfect sequences [6] imperfect sequences [] total 6 [2021-12-17 15:07:42,778 INFO L115 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [2004452320] [2021-12-17 15:07:42,778 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2021-12-17 15:07:42,779 INFO L546 AbstractCegarLoop]: INTERPOLANT automaton has 6 states [2021-12-17 15:07:42,779 INFO L103 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2021-12-17 15:07:42,779 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 6 interpolants. [2021-12-17 15:07:42,780 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=9, Invalid=21, Unknown=0, NotChecked=0, Total=30 [2021-12-17 15:07:42,780 INFO L87 Difference]: Start difference. First operand 156 states and 204 transitions. Second operand has 6 states, 6 states have (on average 5.166666666666667) internal successors, (31), 4 states have internal predecessors, (31), 1 states have call successors, (2), 2 states have call predecessors, (2), 1 states have return successors, (1), 1 states have call predecessors, (1), 1 states have call successors, (1) [2021-12-17 15:07:42,935 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2021-12-17 15:07:42,935 INFO L93 Difference]: Finished difference Result 450 states and 597 transitions. [2021-12-17 15:07:42,936 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 8 states. [2021-12-17 15:07:42,936 INFO L78 Accepts]: Start accepts. Automaton has has 6 states, 6 states have (on average 5.166666666666667) internal successors, (31), 4 states have internal predecessors, (31), 1 states have call successors, (2), 2 states have call predecessors, (2), 1 states have return successors, (1), 1 states have call predecessors, (1), 1 states have call successors, (1) Word has length 34 [2021-12-17 15:07:42,937 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2021-12-17 15:07:42,940 INFO L225 Difference]: With dead ends: 450 [2021-12-17 15:07:42,943 INFO L226 Difference]: Without dead ends: 302 [2021-12-17 15:07:42,944 INFO L932 BasicCegarLoop]: 0 DeclaredPredicates, 9 GetRequests, 2 SyntacticMatches, 0 SemanticMatches, 7 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 3 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=21, Invalid=51, Unknown=0, NotChecked=0, Total=72 [2021-12-17 15:07:42,948 INFO L933 BasicCegarLoop]: 118 mSDtfsCounter, 76 mSDsluCounter, 414 mSDsCounter, 0 mSdLazyCounter, 52 mSolverCounterSat, 4 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.1s Time, 0 mProtectedPredicate, 0 mProtectedAction, 79 SdHoareTripleChecker+Valid, 532 SdHoareTripleChecker+Invalid, 56 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 4 IncrementalHoareTripleChecker+Valid, 52 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.1s IncrementalHoareTripleChecker+Time [2021-12-17 15:07:42,950 INFO L934 BasicCegarLoop]: SdHoareTripleChecker [79 Valid, 532 Invalid, 56 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [4 Valid, 52 Invalid, 0 Unknown, 0 Unchecked, 0.1s Time] [2021-12-17 15:07:42,952 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 302 states. [2021-12-17 15:07:42,989 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 302 to 296. [2021-12-17 15:07:42,990 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 296 states, 211 states have (on average 1.3317535545023698) internal successors, (281), 240 states have internal predecessors, (281), 52 states have call successors, (52), 32 states have call predecessors, (52), 32 states have return successors, (54), 38 states have call predecessors, (54), 52 states have call successors, (54) [2021-12-17 15:07:42,992 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 296 states to 296 states and 387 transitions. [2021-12-17 15:07:42,992 INFO L78 Accepts]: Start accepts. Automaton has 296 states and 387 transitions. Word has length 34 [2021-12-17 15:07:42,992 INFO L84 Accepts]: Finished accepts. word is rejected. [2021-12-17 15:07:42,993 INFO L470 AbstractCegarLoop]: Abstraction has 296 states and 387 transitions. [2021-12-17 15:07:42,993 INFO L471 AbstractCegarLoop]: INTERPOLANT automaton has has 6 states, 6 states have (on average 5.166666666666667) internal successors, (31), 4 states have internal predecessors, (31), 1 states have call successors, (2), 2 states have call predecessors, (2), 1 states have return successors, (1), 1 states have call predecessors, (1), 1 states have call successors, (1) [2021-12-17 15:07:42,993 INFO L276 IsEmpty]: Start isEmpty. Operand 296 states and 387 transitions. [2021-12-17 15:07:42,995 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 39 [2021-12-17 15:07:42,995 INFO L506 BasicCegarLoop]: Found error trace [2021-12-17 15:07:42,995 INFO L514 BasicCegarLoop]: trace histogram [1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2021-12-17 15:07:42,995 WARN L452 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable3 [2021-12-17 15:07:42,996 INFO L402 AbstractCegarLoop]: === Iteration 5 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2021-12-17 15:07:42,996 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2021-12-17 15:07:42,996 INFO L85 PathProgramCache]: Analyzing trace with hash 292189750, now seen corresponding path program 1 times [2021-12-17 15:07:42,997 INFO L121 FreeRefinementEngine]: Executing refinement strategy CAMEL [2021-12-17 15:07:42,997 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [308737625] [2021-12-17 15:07:42,997 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2021-12-17 15:07:42,997 INFO L126 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2021-12-17 15:07:43,013 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:07:43,143 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 14 [2021-12-17 15:07:43,145 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:07:43,148 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 28 [2021-12-17 15:07:43,150 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:07:43,153 INFO L134 CoverageAnalysis]: Checked inductivity of 0 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2021-12-17 15:07:43,153 INFO L139 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2021-12-17 15:07:43,154 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [308737625] [2021-12-17 15:07:43,154 INFO L160 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [308737625] provided 1 perfect and 0 imperfect interpolant sequences [2021-12-17 15:07:43,154 INFO L186 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2021-12-17 15:07:43,154 INFO L199 FreeRefinementEngine]: Number of different interpolants: perfect sequences [6] imperfect sequences [] total 6 [2021-12-17 15:07:43,154 INFO L115 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [811880525] [2021-12-17 15:07:43,155 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2021-12-17 15:07:43,155 INFO L546 AbstractCegarLoop]: INTERPOLANT automaton has 6 states [2021-12-17 15:07:43,155 INFO L103 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2021-12-17 15:07:43,156 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 6 interpolants. [2021-12-17 15:07:43,156 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=9, Invalid=21, Unknown=0, NotChecked=0, Total=30 [2021-12-17 15:07:43,156 INFO L87 Difference]: Start difference. First operand 296 states and 387 transitions. Second operand has 6 states, 6 states have (on average 5.5) internal successors, (33), 5 states have internal predecessors, (33), 1 states have call successors, (3), 3 states have call predecessors, (3), 1 states have return successors, (2), 1 states have call predecessors, (2), 1 states have call successors, (2) [2021-12-17 15:07:43,435 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2021-12-17 15:07:43,436 INFO L93 Difference]: Finished difference Result 780 states and 1032 transitions. [2021-12-17 15:07:43,436 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 8 states. [2021-12-17 15:07:43,436 INFO L78 Accepts]: Start accepts. Automaton has has 6 states, 6 states have (on average 5.5) internal successors, (33), 5 states have internal predecessors, (33), 1 states have call successors, (3), 3 states have call predecessors, (3), 1 states have return successors, (2), 1 states have call predecessors, (2), 1 states have call successors, (2) Word has length 38 [2021-12-17 15:07:43,437 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2021-12-17 15:07:43,440 INFO L225 Difference]: With dead ends: 780 [2021-12-17 15:07:43,440 INFO L226 Difference]: Without dead ends: 492 [2021-12-17 15:07:43,441 INFO L932 BasicCegarLoop]: 0 DeclaredPredicates, 14 GetRequests, 6 SyntacticMatches, 0 SemanticMatches, 8 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 3 ImplicationChecksByTransitivity, 0.1s TimeCoverageRelationStatistics Valid=32, Invalid=58, Unknown=0, NotChecked=0, Total=90 [2021-12-17 15:07:43,442 INFO L933 BasicCegarLoop]: 98 mSDtfsCounter, 130 mSDsluCounter, 154 mSDsCounter, 0 mSdLazyCounter, 223 mSolverCounterSat, 49 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.2s Time, 0 mProtectedPredicate, 0 mProtectedAction, 137 SdHoareTripleChecker+Valid, 252 SdHoareTripleChecker+Invalid, 272 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 49 IncrementalHoareTripleChecker+Valid, 223 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.2s IncrementalHoareTripleChecker+Time [2021-12-17 15:07:43,443 INFO L934 BasicCegarLoop]: SdHoareTripleChecker [137 Valid, 252 Invalid, 272 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [49 Valid, 223 Invalid, 0 Unknown, 0 Unchecked, 0.2s Time] [2021-12-17 15:07:43,444 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 492 states. [2021-12-17 15:07:43,474 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 492 to 478. [2021-12-17 15:07:43,476 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 478 states, 345 states have (on average 1.2782608695652173) internal successors, (441), 378 states have internal predecessors, (441), 72 states have call successors, (72), 60 states have call predecessors, (72), 60 states have return successors, (92), 66 states have call predecessors, (92), 72 states have call successors, (92) [2021-12-17 15:07:43,478 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 478 states to 478 states and 605 transitions. [2021-12-17 15:07:43,479 INFO L78 Accepts]: Start accepts. Automaton has 478 states and 605 transitions. Word has length 38 [2021-12-17 15:07:43,479 INFO L84 Accepts]: Finished accepts. word is rejected. [2021-12-17 15:07:43,480 INFO L470 AbstractCegarLoop]: Abstraction has 478 states and 605 transitions. [2021-12-17 15:07:43,480 INFO L471 AbstractCegarLoop]: INTERPOLANT automaton has has 6 states, 6 states have (on average 5.5) internal successors, (33), 5 states have internal predecessors, (33), 1 states have call successors, (3), 3 states have call predecessors, (3), 1 states have return successors, (2), 1 states have call predecessors, (2), 1 states have call successors, (2) [2021-12-17 15:07:43,480 INFO L276 IsEmpty]: Start isEmpty. Operand 478 states and 605 transitions. [2021-12-17 15:07:43,482 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 61 [2021-12-17 15:07:43,482 INFO L506 BasicCegarLoop]: Found error trace [2021-12-17 15:07:43,483 INFO L514 BasicCegarLoop]: trace histogram [2, 2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2021-12-17 15:07:43,483 WARN L452 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable4 [2021-12-17 15:07:43,483 INFO L402 AbstractCegarLoop]: === Iteration 6 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2021-12-17 15:07:43,484 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2021-12-17 15:07:43,484 INFO L85 PathProgramCache]: Analyzing trace with hash 363168403, now seen corresponding path program 1 times [2021-12-17 15:07:43,484 INFO L121 FreeRefinementEngine]: Executing refinement strategy CAMEL [2021-12-17 15:07:43,484 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [269520467] [2021-12-17 15:07:43,484 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2021-12-17 15:07:43,485 INFO L126 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2021-12-17 15:07:43,499 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:07:43,529 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 14 [2021-12-17 15:07:43,531 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:07:43,537 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 24 [2021-12-17 15:07:43,541 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:07:43,560 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 8 [2021-12-17 15:07:43,563 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:07:43,568 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 1 [2021-12-17 15:07:43,569 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:07:43,574 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 50 [2021-12-17 15:07:43,575 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:07:43,580 INFO L134 CoverageAnalysis]: Checked inductivity of 3 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 3 trivial. 0 not checked. [2021-12-17 15:07:43,580 INFO L139 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2021-12-17 15:07:43,580 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [269520467] [2021-12-17 15:07:43,580 INFO L160 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [269520467] provided 1 perfect and 0 imperfect interpolant sequences [2021-12-17 15:07:43,580 INFO L186 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2021-12-17 15:07:43,580 INFO L199 FreeRefinementEngine]: Number of different interpolants: perfect sequences [7] imperfect sequences [] total 7 [2021-12-17 15:07:43,581 INFO L115 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [172771509] [2021-12-17 15:07:43,581 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2021-12-17 15:07:43,581 INFO L546 AbstractCegarLoop]: INTERPOLANT automaton has 7 states [2021-12-17 15:07:43,581 INFO L103 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2021-12-17 15:07:43,582 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 7 interpolants. [2021-12-17 15:07:43,582 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=11, Invalid=31, Unknown=0, NotChecked=0, Total=42 [2021-12-17 15:07:43,582 INFO L87 Difference]: Start difference. First operand 478 states and 605 transitions. Second operand has 7 states, 7 states have (on average 6.714285714285714) internal successors, (47), 5 states have internal predecessors, (47), 3 states have call successors, (6), 4 states have call predecessors, (6), 2 states have return successors, (5), 3 states have call predecessors, (5), 3 states have call successors, (5) [2021-12-17 15:07:44,047 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2021-12-17 15:07:44,048 INFO L93 Difference]: Finished difference Result 1590 states and 2112 transitions. [2021-12-17 15:07:44,048 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 16 states. [2021-12-17 15:07:44,048 INFO L78 Accepts]: Start accepts. Automaton has has 7 states, 7 states have (on average 6.714285714285714) internal successors, (47), 5 states have internal predecessors, (47), 3 states have call successors, (6), 4 states have call predecessors, (6), 2 states have return successors, (5), 3 states have call predecessors, (5), 3 states have call successors, (5) Word has length 60 [2021-12-17 15:07:44,049 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2021-12-17 15:07:44,055 INFO L225 Difference]: With dead ends: 1590 [2021-12-17 15:07:44,055 INFO L226 Difference]: Without dead ends: 1120 [2021-12-17 15:07:44,057 INFO L932 BasicCegarLoop]: 0 DeclaredPredicates, 30 GetRequests, 14 SyntacticMatches, 0 SemanticMatches, 16 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 49 ImplicationChecksByTransitivity, 0.1s TimeCoverageRelationStatistics Valid=85, Invalid=221, Unknown=0, NotChecked=0, Total=306 [2021-12-17 15:07:44,058 INFO L933 BasicCegarLoop]: 117 mSDtfsCounter, 338 mSDsluCounter, 186 mSDsCounter, 0 mSdLazyCounter, 340 mSolverCounterSat, 140 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.2s Time, 0 mProtectedPredicate, 0 mProtectedAction, 340 SdHoareTripleChecker+Valid, 303 SdHoareTripleChecker+Invalid, 480 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 140 IncrementalHoareTripleChecker+Valid, 340 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.3s IncrementalHoareTripleChecker+Time [2021-12-17 15:07:44,059 INFO L934 BasicCegarLoop]: SdHoareTripleChecker [340 Valid, 303 Invalid, 480 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [140 Valid, 340 Invalid, 0 Unknown, 0 Unchecked, 0.3s Time] [2021-12-17 15:07:44,060 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 1120 states. [2021-12-17 15:07:44,117 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 1120 to 938. [2021-12-17 15:07:44,119 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 938 states, 693 states have (on average 1.2424242424242424) internal successors, (861), 740 states have internal predecessors, (861), 130 states have call successors, (130), 106 states have call predecessors, (130), 114 states have return successors, (194), 128 states have call predecessors, (194), 130 states have call successors, (194) [2021-12-17 15:07:44,126 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 938 states to 938 states and 1185 transitions. [2021-12-17 15:07:44,127 INFO L78 Accepts]: Start accepts. Automaton has 938 states and 1185 transitions. Word has length 60 [2021-12-17 15:07:44,128 INFO L84 Accepts]: Finished accepts. word is rejected. [2021-12-17 15:07:44,128 INFO L470 AbstractCegarLoop]: Abstraction has 938 states and 1185 transitions. [2021-12-17 15:07:44,128 INFO L471 AbstractCegarLoop]: INTERPOLANT automaton has has 7 states, 7 states have (on average 6.714285714285714) internal successors, (47), 5 states have internal predecessors, (47), 3 states have call successors, (6), 4 states have call predecessors, (6), 2 states have return successors, (5), 3 states have call predecessors, (5), 3 states have call successors, (5) [2021-12-17 15:07:44,128 INFO L276 IsEmpty]: Start isEmpty. Operand 938 states and 1185 transitions. [2021-12-17 15:07:44,132 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 61 [2021-12-17 15:07:44,132 INFO L506 BasicCegarLoop]: Found error trace [2021-12-17 15:07:44,132 INFO L514 BasicCegarLoop]: trace histogram [2, 2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2021-12-17 15:07:44,132 WARN L452 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable5 [2021-12-17 15:07:44,132 INFO L402 AbstractCegarLoop]: === Iteration 7 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2021-12-17 15:07:44,133 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2021-12-17 15:07:44,133 INFO L85 PathProgramCache]: Analyzing trace with hash 435554961, now seen corresponding path program 1 times [2021-12-17 15:07:44,133 INFO L121 FreeRefinementEngine]: Executing refinement strategy CAMEL [2021-12-17 15:07:44,133 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [761846547] [2021-12-17 15:07:44,133 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2021-12-17 15:07:44,133 INFO L126 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2021-12-17 15:07:44,146 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:07:44,163 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 14 [2021-12-17 15:07:44,164 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:07:44,170 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 24 [2021-12-17 15:07:44,174 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:07:44,196 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 8 [2021-12-17 15:07:44,199 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:07:44,202 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 1 [2021-12-17 15:07:44,203 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:07:44,208 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 50 [2021-12-17 15:07:44,210 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:07:44,213 INFO L134 CoverageAnalysis]: Checked inductivity of 3 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 3 trivial. 0 not checked. [2021-12-17 15:07:44,213 INFO L139 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2021-12-17 15:07:44,213 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [761846547] [2021-12-17 15:07:44,214 INFO L160 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [761846547] provided 1 perfect and 0 imperfect interpolant sequences [2021-12-17 15:07:44,214 INFO L186 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2021-12-17 15:07:44,214 INFO L199 FreeRefinementEngine]: Number of different interpolants: perfect sequences [7] imperfect sequences [] total 7 [2021-12-17 15:07:44,214 INFO L115 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [1798521002] [2021-12-17 15:07:44,214 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2021-12-17 15:07:44,215 INFO L546 AbstractCegarLoop]: INTERPOLANT automaton has 7 states [2021-12-17 15:07:44,216 INFO L103 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2021-12-17 15:07:44,216 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 7 interpolants. [2021-12-17 15:07:44,216 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=11, Invalid=31, Unknown=0, NotChecked=0, Total=42 [2021-12-17 15:07:44,216 INFO L87 Difference]: Start difference. First operand 938 states and 1185 transitions. Second operand has 7 states, 7 states have (on average 6.714285714285714) internal successors, (47), 5 states have internal predecessors, (47), 2 states have call successors, (6), 3 states have call predecessors, (6), 2 states have return successors, (5), 2 states have call predecessors, (5), 2 states have call successors, (5) [2021-12-17 15:07:44,479 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2021-12-17 15:07:44,479 INFO L93 Difference]: Finished difference Result 1934 states and 2515 transitions. [2021-12-17 15:07:44,480 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 9 states. [2021-12-17 15:07:44,480 INFO L78 Accepts]: Start accepts. Automaton has has 7 states, 7 states have (on average 6.714285714285714) internal successors, (47), 5 states have internal predecessors, (47), 2 states have call successors, (6), 3 states have call predecessors, (6), 2 states have return successors, (5), 2 states have call predecessors, (5), 2 states have call successors, (5) Word has length 60 [2021-12-17 15:07:44,480 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2021-12-17 15:07:44,485 INFO L225 Difference]: With dead ends: 1934 [2021-12-17 15:07:44,486 INFO L226 Difference]: Without dead ends: 1004 [2021-12-17 15:07:44,490 INFO L932 BasicCegarLoop]: 0 DeclaredPredicates, 22 GetRequests, 12 SyntacticMatches, 0 SemanticMatches, 10 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 3 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=46, Invalid=86, Unknown=0, NotChecked=0, Total=132 [2021-12-17 15:07:44,493 INFO L933 BasicCegarLoop]: 90 mSDtfsCounter, 136 mSDsluCounter, 174 mSDsCounter, 0 mSdLazyCounter, 278 mSolverCounterSat, 60 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.1s Time, 0 mProtectedPredicate, 0 mProtectedAction, 137 SdHoareTripleChecker+Valid, 264 SdHoareTripleChecker+Invalid, 338 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 60 IncrementalHoareTripleChecker+Valid, 278 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.2s IncrementalHoareTripleChecker+Time [2021-12-17 15:07:44,493 INFO L934 BasicCegarLoop]: SdHoareTripleChecker [137 Valid, 264 Invalid, 338 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [60 Valid, 278 Invalid, 0 Unknown, 0 Unchecked, 0.2s Time] [2021-12-17 15:07:44,495 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 1004 states. [2021-12-17 15:07:44,539 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 1004 to 962. [2021-12-17 15:07:44,541 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 962 states, 717 states have (on average 1.2343096234309623) internal successors, (885), 764 states have internal predecessors, (885), 130 states have call successors, (130), 106 states have call predecessors, (130), 114 states have return successors, (194), 128 states have call predecessors, (194), 130 states have call successors, (194) [2021-12-17 15:07:44,547 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 962 states to 962 states and 1209 transitions. [2021-12-17 15:07:44,548 INFO L78 Accepts]: Start accepts. Automaton has 962 states and 1209 transitions. Word has length 60 [2021-12-17 15:07:44,548 INFO L84 Accepts]: Finished accepts. word is rejected. [2021-12-17 15:07:44,548 INFO L470 AbstractCegarLoop]: Abstraction has 962 states and 1209 transitions. [2021-12-17 15:07:44,553 INFO L471 AbstractCegarLoop]: INTERPOLANT automaton has has 7 states, 7 states have (on average 6.714285714285714) internal successors, (47), 5 states have internal predecessors, (47), 2 states have call successors, (6), 3 states have call predecessors, (6), 2 states have return successors, (5), 2 states have call predecessors, (5), 2 states have call successors, (5) [2021-12-17 15:07:44,553 INFO L276 IsEmpty]: Start isEmpty. Operand 962 states and 1209 transitions. [2021-12-17 15:07:44,555 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 61 [2021-12-17 15:07:44,556 INFO L506 BasicCegarLoop]: Found error trace [2021-12-17 15:07:44,556 INFO L514 BasicCegarLoop]: trace histogram [2, 2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2021-12-17 15:07:44,556 WARN L452 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable6 [2021-12-17 15:07:44,556 INFO L402 AbstractCegarLoop]: === Iteration 8 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2021-12-17 15:07:44,557 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2021-12-17 15:07:44,558 INFO L85 PathProgramCache]: Analyzing trace with hash 1137154835, now seen corresponding path program 1 times [2021-12-17 15:07:44,558 INFO L121 FreeRefinementEngine]: Executing refinement strategy CAMEL [2021-12-17 15:07:44,558 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [251872734] [2021-12-17 15:07:44,558 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2021-12-17 15:07:44,558 INFO L126 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2021-12-17 15:07:44,578 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:07:44,624 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 14 [2021-12-17 15:07:44,626 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:07:44,633 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 24 [2021-12-17 15:07:44,641 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:07:44,661 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 8 [2021-12-17 15:07:44,663 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:07:44,666 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 1 [2021-12-17 15:07:44,667 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:07:44,669 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 50 [2021-12-17 15:07:44,670 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:07:44,672 INFO L134 CoverageAnalysis]: Checked inductivity of 3 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 3 trivial. 0 not checked. [2021-12-17 15:07:44,673 INFO L139 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2021-12-17 15:07:44,673 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [251872734] [2021-12-17 15:07:44,673 INFO L160 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [251872734] provided 1 perfect and 0 imperfect interpolant sequences [2021-12-17 15:07:44,673 INFO L186 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2021-12-17 15:07:44,673 INFO L199 FreeRefinementEngine]: Number of different interpolants: perfect sequences [7] imperfect sequences [] total 7 [2021-12-17 15:07:44,674 INFO L115 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [57679514] [2021-12-17 15:07:44,674 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2021-12-17 15:07:44,674 INFO L546 AbstractCegarLoop]: INTERPOLANT automaton has 7 states [2021-12-17 15:07:44,674 INFO L103 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2021-12-17 15:07:44,675 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 7 interpolants. [2021-12-17 15:07:44,675 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=11, Invalid=31, Unknown=0, NotChecked=0, Total=42 [2021-12-17 15:07:44,675 INFO L87 Difference]: Start difference. First operand 962 states and 1209 transitions. Second operand has 7 states, 7 states have (on average 6.714285714285714) internal successors, (47), 5 states have internal predecessors, (47), 3 states have call successors, (6), 4 states have call predecessors, (6), 2 states have return successors, (5), 3 states have call predecessors, (5), 3 states have call successors, (5) [2021-12-17 15:07:45,072 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2021-12-17 15:07:45,072 INFO L93 Difference]: Finished difference Result 1746 states and 2221 transitions. [2021-12-17 15:07:45,073 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 13 states. [2021-12-17 15:07:45,073 INFO L78 Accepts]: Start accepts. Automaton has has 7 states, 7 states have (on average 6.714285714285714) internal successors, (47), 5 states have internal predecessors, (47), 3 states have call successors, (6), 4 states have call predecessors, (6), 2 states have return successors, (5), 3 states have call predecessors, (5), 3 states have call successors, (5) Word has length 60 [2021-12-17 15:07:45,075 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2021-12-17 15:07:45,079 INFO L225 Difference]: With dead ends: 1746 [2021-12-17 15:07:45,079 INFO L226 Difference]: Without dead ends: 792 [2021-12-17 15:07:45,084 INFO L932 BasicCegarLoop]: 0 DeclaredPredicates, 27 GetRequests, 14 SyntacticMatches, 0 SemanticMatches, 13 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 25 ImplicationChecksByTransitivity, 0.1s TimeCoverageRelationStatistics Valid=70, Invalid=140, Unknown=0, NotChecked=0, Total=210 [2021-12-17 15:07:45,085 INFO L933 BasicCegarLoop]: 108 mSDtfsCounter, 329 mSDsluCounter, 177 mSDsCounter, 0 mSdLazyCounter, 352 mSolverCounterSat, 136 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.2s Time, 0 mProtectedPredicate, 0 mProtectedAction, 334 SdHoareTripleChecker+Valid, 285 SdHoareTripleChecker+Invalid, 488 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 136 IncrementalHoareTripleChecker+Valid, 352 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.3s IncrementalHoareTripleChecker+Time [2021-12-17 15:07:45,085 INFO L934 BasicCegarLoop]: SdHoareTripleChecker [334 Valid, 285 Invalid, 488 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [136 Valid, 352 Invalid, 0 Unknown, 0 Unchecked, 0.3s Time] [2021-12-17 15:07:45,086 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 792 states. [2021-12-17 15:07:45,118 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 792 to 766. [2021-12-17 15:07:45,120 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 766 states, 569 states have (on average 1.2144112478031635) internal successors, (691), 606 states have internal predecessors, (691), 104 states have call successors, (104), 84 states have call predecessors, (104), 92 states have return successors, (138), 102 states have call predecessors, (138), 104 states have call successors, (138) [2021-12-17 15:07:45,123 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 766 states to 766 states and 933 transitions. [2021-12-17 15:07:45,124 INFO L78 Accepts]: Start accepts. Automaton has 766 states and 933 transitions. Word has length 60 [2021-12-17 15:07:45,124 INFO L84 Accepts]: Finished accepts. word is rejected. [2021-12-17 15:07:45,124 INFO L470 AbstractCegarLoop]: Abstraction has 766 states and 933 transitions. [2021-12-17 15:07:45,124 INFO L471 AbstractCegarLoop]: INTERPOLANT automaton has has 7 states, 7 states have (on average 6.714285714285714) internal successors, (47), 5 states have internal predecessors, (47), 3 states have call successors, (6), 4 states have call predecessors, (6), 2 states have return successors, (5), 3 states have call predecessors, (5), 3 states have call successors, (5) [2021-12-17 15:07:45,125 INFO L276 IsEmpty]: Start isEmpty. Operand 766 states and 933 transitions. [2021-12-17 15:07:45,126 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 65 [2021-12-17 15:07:45,126 INFO L506 BasicCegarLoop]: Found error trace [2021-12-17 15:07:45,127 INFO L514 BasicCegarLoop]: trace histogram [2, 2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2021-12-17 15:07:45,127 WARN L452 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable7 [2021-12-17 15:07:45,127 INFO L402 AbstractCegarLoop]: === Iteration 9 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2021-12-17 15:07:45,127 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2021-12-17 15:07:45,128 INFO L85 PathProgramCache]: Analyzing trace with hash 1046043951, now seen corresponding path program 1 times [2021-12-17 15:07:45,128 INFO L121 FreeRefinementEngine]: Executing refinement strategy CAMEL [2021-12-17 15:07:45,128 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [871498520] [2021-12-17 15:07:45,128 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2021-12-17 15:07:45,128 INFO L126 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2021-12-17 15:07:45,138 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:07:45,167 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 12 [2021-12-17 15:07:45,169 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:07:45,176 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 18 [2021-12-17 15:07:45,177 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:07:45,190 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 28 [2021-12-17 15:07:45,193 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:07:45,226 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 8 [2021-12-17 15:07:45,228 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:07:45,249 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 1 [2021-12-17 15:07:45,250 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:07:45,264 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 54 [2021-12-17 15:07:45,265 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:07:45,267 INFO L134 CoverageAnalysis]: Checked inductivity of 3 backedges. 0 proven. 2 refuted. 0 times theorem prover too weak. 1 trivial. 0 not checked. [2021-12-17 15:07:45,267 INFO L139 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2021-12-17 15:07:45,267 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [871498520] [2021-12-17 15:07:45,267 INFO L160 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [871498520] provided 0 perfect and 1 imperfect interpolant sequences [2021-12-17 15:07:45,268 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleZ3 [1626752805] [2021-12-17 15:07:45,268 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2021-12-17 15:07:45,268 INFO L168 SolverBuilder]: Constructing external solver with command: z3 -smt2 -in SMTLIB2_COMPLIANT=true [2021-12-17 15:07:45,268 INFO L189 MonitoredProcess]: No working directory specified, using /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 [2021-12-17 15:07:45,275 INFO L229 MonitoredProcess]: Starting monitored process 2 with /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 -smt2 -in SMTLIB2_COMPLIANT=true (exit command is (exit), workingDir is null) [2021-12-17 15:07:45,299 INFO L327 MonitoredProcess]: [MP /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 -smt2 -in SMTLIB2_COMPLIANT=true (2)] Waiting until timeout for monitored process [2021-12-17 15:07:45,363 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:07:45,366 INFO L263 TraceCheckSpWp]: Trace formula consists of 391 conjuncts, 9 conjunts are in the unsatisfiable core [2021-12-17 15:07:45,371 INFO L286 TraceCheckSpWp]: Computing forward predicates... [2021-12-17 15:07:45,731 INFO L134 CoverageAnalysis]: Checked inductivity of 3 backedges. 3 proven. 0 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2021-12-17 15:07:45,731 INFO L324 TraceCheckSpWp]: Omiting computation of backward sequence because forward sequence was already perfect [2021-12-17 15:07:45,732 INFO L160 FreeRefinementEngine]: IpTcStrategyModuleZ3 [1626752805] provided 1 perfect and 0 imperfect interpolant sequences [2021-12-17 15:07:45,732 INFO L186 FreeRefinementEngine]: Found 1 perfect and 1 imperfect interpolant sequences. [2021-12-17 15:07:45,732 INFO L199 FreeRefinementEngine]: Number of different interpolants: perfect sequences [8] imperfect sequences [15] total 21 [2021-12-17 15:07:45,732 INFO L115 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [1916175260] [2021-12-17 15:07:45,733 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2021-12-17 15:07:45,733 INFO L546 AbstractCegarLoop]: INTERPOLANT automaton has 8 states [2021-12-17 15:07:45,733 INFO L103 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2021-12-17 15:07:45,734 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 8 interpolants. [2021-12-17 15:07:45,734 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=52, Invalid=368, Unknown=0, NotChecked=0, Total=420 [2021-12-17 15:07:45,734 INFO L87 Difference]: Start difference. First operand 766 states and 933 transitions. Second operand has 8 states, 8 states have (on average 6.375) internal successors, (51), 6 states have internal predecessors, (51), 3 states have call successors, (7), 3 states have call predecessors, (7), 5 states have return successors, (6), 5 states have call predecessors, (6), 3 states have call successors, (6) [2021-12-17 15:07:45,870 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2021-12-17 15:07:45,870 INFO L93 Difference]: Finished difference Result 1498 states and 1830 transitions. [2021-12-17 15:07:45,871 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 8 states. [2021-12-17 15:07:45,871 INFO L78 Accepts]: Start accepts. Automaton has has 8 states, 8 states have (on average 6.375) internal successors, (51), 6 states have internal predecessors, (51), 3 states have call successors, (7), 3 states have call predecessors, (7), 5 states have return successors, (6), 5 states have call predecessors, (6), 3 states have call successors, (6) Word has length 64 [2021-12-17 15:07:45,871 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2021-12-17 15:07:45,875 INFO L225 Difference]: With dead ends: 1498 [2021-12-17 15:07:45,875 INFO L226 Difference]: Without dead ends: 740 [2021-12-17 15:07:45,877 INFO L932 BasicCegarLoop]: 0 DeclaredPredicates, 84 GetRequests, 65 SyntacticMatches, 0 SemanticMatches, 19 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 12 ImplicationChecksByTransitivity, 0.2s TimeCoverageRelationStatistics Valid=52, Invalid=368, Unknown=0, NotChecked=0, Total=420 [2021-12-17 15:07:45,878 INFO L933 BasicCegarLoop]: 187 mSDtfsCounter, 71 mSDsluCounter, 687 mSDsCounter, 0 mSdLazyCounter, 184 mSolverCounterSat, 3 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.1s Time, 0 mProtectedPredicate, 0 mProtectedAction, 75 SdHoareTripleChecker+Valid, 874 SdHoareTripleChecker+Invalid, 187 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 3 IncrementalHoareTripleChecker+Valid, 184 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.1s IncrementalHoareTripleChecker+Time [2021-12-17 15:07:45,878 INFO L934 BasicCegarLoop]: SdHoareTripleChecker [75 Valid, 874 Invalid, 187 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [3 Valid, 184 Invalid, 0 Unknown, 0 Unchecked, 0.1s Time] [2021-12-17 15:07:45,879 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 740 states. [2021-12-17 15:07:45,903 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 740 to 736. [2021-12-17 15:07:45,905 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 736 states, 545 states have (on average 1.198165137614679) internal successors, (653), 580 states have internal predecessors, (653), 102 states have call successors, (102), 84 states have call predecessors, (102), 88 states have return successors, (122), 98 states have call predecessors, (122), 102 states have call successors, (122) [2021-12-17 15:07:45,908 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 736 states to 736 states and 877 transitions. [2021-12-17 15:07:45,909 INFO L78 Accepts]: Start accepts. Automaton has 736 states and 877 transitions. Word has length 64 [2021-12-17 15:07:45,909 INFO L84 Accepts]: Finished accepts. word is rejected. [2021-12-17 15:07:45,909 INFO L470 AbstractCegarLoop]: Abstraction has 736 states and 877 transitions. [2021-12-17 15:07:45,909 INFO L471 AbstractCegarLoop]: INTERPOLANT automaton has has 8 states, 8 states have (on average 6.375) internal successors, (51), 6 states have internal predecessors, (51), 3 states have call successors, (7), 3 states have call predecessors, (7), 5 states have return successors, (6), 5 states have call predecessors, (6), 3 states have call successors, (6) [2021-12-17 15:07:45,910 INFO L276 IsEmpty]: Start isEmpty. Operand 736 states and 877 transitions. [2021-12-17 15:07:45,912 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 92 [2021-12-17 15:07:45,912 INFO L506 BasicCegarLoop]: Found error trace [2021-12-17 15:07:45,912 INFO L514 BasicCegarLoop]: trace histogram [3, 3, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2021-12-17 15:07:45,938 INFO L552 MonitoredProcess]: [MP /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 -smt2 -in SMTLIB2_COMPLIANT=true (2)] Ended with exit code 0 [2021-12-17 15:07:46,125 WARN L452 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable8,2 /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 -smt2 -in SMTLIB2_COMPLIANT=true [2021-12-17 15:07:46,126 INFO L402 AbstractCegarLoop]: === Iteration 10 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2021-12-17 15:07:46,126 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2021-12-17 15:07:46,126 INFO L85 PathProgramCache]: Analyzing trace with hash -862141541, now seen corresponding path program 1 times [2021-12-17 15:07:46,126 INFO L121 FreeRefinementEngine]: Executing refinement strategy CAMEL [2021-12-17 15:07:46,126 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [833173228] [2021-12-17 15:07:46,127 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2021-12-17 15:07:46,127 INFO L126 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2021-12-17 15:07:46,136 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:07:46,161 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 12 [2021-12-17 15:07:46,162 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:07:46,170 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 24 [2021-12-17 15:07:46,174 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:07:46,188 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 3 [2021-12-17 15:07:46,191 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:07:46,195 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 8 [2021-12-17 15:07:46,196 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:07:46,206 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 1 [2021-12-17 15:07:46,206 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:07:46,210 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 29 [2021-12-17 15:07:46,212 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:07:46,219 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 69 [2021-12-17 15:07:46,220 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:07:46,224 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 81 [2021-12-17 15:07:46,225 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:07:46,226 INFO L134 CoverageAnalysis]: Checked inductivity of 24 backedges. 15 proven. 0 refuted. 0 times theorem prover too weak. 9 trivial. 0 not checked. [2021-12-17 15:07:46,227 INFO L139 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2021-12-17 15:07:46,227 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [833173228] [2021-12-17 15:07:46,227 INFO L160 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [833173228] provided 1 perfect and 0 imperfect interpolant sequences [2021-12-17 15:07:46,227 INFO L186 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2021-12-17 15:07:46,227 INFO L199 FreeRefinementEngine]: Number of different interpolants: perfect sequences [8] imperfect sequences [] total 8 [2021-12-17 15:07:46,227 INFO L115 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [411186677] [2021-12-17 15:07:46,227 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2021-12-17 15:07:46,228 INFO L546 AbstractCegarLoop]: INTERPOLANT automaton has 8 states [2021-12-17 15:07:46,228 INFO L103 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2021-12-17 15:07:46,228 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 8 interpolants. [2021-12-17 15:07:46,228 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=15, Invalid=41, Unknown=0, NotChecked=0, Total=56 [2021-12-17 15:07:46,228 INFO L87 Difference]: Start difference. First operand 736 states and 877 transitions. Second operand has 8 states, 8 states have (on average 8.75) internal successors, (70), 4 states have internal predecessors, (70), 4 states have call successors, (9), 6 states have call predecessors, (9), 2 states have return successors, (8), 3 states have call predecessors, (8), 4 states have call successors, (8) [2021-12-17 15:07:46,605 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2021-12-17 15:07:46,605 INFO L93 Difference]: Finished difference Result 973 states and 1171 transitions. [2021-12-17 15:07:46,605 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 14 states. [2021-12-17 15:07:46,606 INFO L78 Accepts]: Start accepts. Automaton has has 8 states, 8 states have (on average 8.75) internal successors, (70), 4 states have internal predecessors, (70), 4 states have call successors, (9), 6 states have call predecessors, (9), 2 states have return successors, (8), 3 states have call predecessors, (8), 4 states have call successors, (8) Word has length 91 [2021-12-17 15:07:46,606 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2021-12-17 15:07:46,608 INFO L225 Difference]: With dead ends: 973 [2021-12-17 15:07:46,608 INFO L226 Difference]: Without dead ends: 454 [2021-12-17 15:07:46,610 INFO L932 BasicCegarLoop]: 0 DeclaredPredicates, 36 GetRequests, 20 SyntacticMatches, 0 SemanticMatches, 16 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 52 ImplicationChecksByTransitivity, 0.1s TimeCoverageRelationStatistics Valid=86, Invalid=220, Unknown=0, NotChecked=0, Total=306 [2021-12-17 15:07:46,610 INFO L933 BasicCegarLoop]: 120 mSDtfsCounter, 326 mSDsluCounter, 191 mSDsCounter, 0 mSdLazyCounter, 323 mSolverCounterSat, 134 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.2s Time, 0 mProtectedPredicate, 0 mProtectedAction, 336 SdHoareTripleChecker+Valid, 311 SdHoareTripleChecker+Invalid, 457 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 134 IncrementalHoareTripleChecker+Valid, 323 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.3s IncrementalHoareTripleChecker+Time [2021-12-17 15:07:46,611 INFO L934 BasicCegarLoop]: SdHoareTripleChecker [336 Valid, 311 Invalid, 457 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [134 Valid, 323 Invalid, 0 Unknown, 0 Unchecked, 0.3s Time] [2021-12-17 15:07:46,611 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 454 states. [2021-12-17 15:07:46,634 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 454 to 383. [2021-12-17 15:07:46,635 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 383 states, 281 states have (on average 1.1672597864768683) internal successors, (328), 303 states have internal predecessors, (328), 55 states have call successors, (55), 42 states have call predecessors, (55), 46 states have return successors, (71), 50 states have call predecessors, (71), 55 states have call successors, (71) [2021-12-17 15:07:46,637 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 383 states to 383 states and 454 transitions. [2021-12-17 15:07:46,637 INFO L78 Accepts]: Start accepts. Automaton has 383 states and 454 transitions. Word has length 91 [2021-12-17 15:07:46,637 INFO L84 Accepts]: Finished accepts. word is rejected. [2021-12-17 15:07:46,638 INFO L470 AbstractCegarLoop]: Abstraction has 383 states and 454 transitions. [2021-12-17 15:07:46,638 INFO L471 AbstractCegarLoop]: INTERPOLANT automaton has has 8 states, 8 states have (on average 8.75) internal successors, (70), 4 states have internal predecessors, (70), 4 states have call successors, (9), 6 states have call predecessors, (9), 2 states have return successors, (8), 3 states have call predecessors, (8), 4 states have call successors, (8) [2021-12-17 15:07:46,638 INFO L276 IsEmpty]: Start isEmpty. Operand 383 states and 454 transitions. [2021-12-17 15:07:46,640 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 109 [2021-12-17 15:07:46,640 INFO L506 BasicCegarLoop]: Found error trace [2021-12-17 15:07:46,640 INFO L514 BasicCegarLoop]: trace histogram [4, 4, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2021-12-17 15:07:46,640 WARN L452 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable9 [2021-12-17 15:07:46,640 INFO L402 AbstractCegarLoop]: === Iteration 11 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2021-12-17 15:07:46,641 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2021-12-17 15:07:46,641 INFO L85 PathProgramCache]: Analyzing trace with hash -1331262979, now seen corresponding path program 1 times [2021-12-17 15:07:46,641 INFO L121 FreeRefinementEngine]: Executing refinement strategy CAMEL [2021-12-17 15:07:46,641 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [936577420] [2021-12-17 15:07:46,641 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2021-12-17 15:07:46,641 INFO L126 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2021-12-17 15:07:46,654 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:07:46,691 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 12 [2021-12-17 15:07:46,692 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:07:46,703 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 20 [2021-12-17 15:07:46,705 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:07:46,715 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 3 [2021-12-17 15:07:46,716 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:07:46,719 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 8 [2021-12-17 15:07:46,721 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:07:46,724 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 1 [2021-12-17 15:07:46,725 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:07:46,727 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 29 [2021-12-17 15:07:46,728 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:07:46,736 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 65 [2021-12-17 15:07:46,739 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:07:46,750 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 77 [2021-12-17 15:07:46,754 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:07:46,796 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 1 [2021-12-17 15:07:46,798 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:07:46,812 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 88 [2021-12-17 15:07:46,813 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:07:46,815 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 2 [2021-12-17 15:07:46,816 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:07:46,820 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 98 [2021-12-17 15:07:46,821 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:07:46,823 INFO L134 CoverageAnalysis]: Checked inductivity of 44 backedges. 14 proven. 12 refuted. 0 times theorem prover too weak. 18 trivial. 0 not checked. [2021-12-17 15:07:46,824 INFO L139 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2021-12-17 15:07:46,824 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [936577420] [2021-12-17 15:07:46,824 INFO L160 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [936577420] provided 0 perfect and 1 imperfect interpolant sequences [2021-12-17 15:07:46,824 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleZ3 [1713076773] [2021-12-17 15:07:46,824 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2021-12-17 15:07:46,824 INFO L168 SolverBuilder]: Constructing external solver with command: z3 -smt2 -in SMTLIB2_COMPLIANT=true [2021-12-17 15:07:46,824 INFO L189 MonitoredProcess]: No working directory specified, using /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 [2021-12-17 15:07:46,828 INFO L229 MonitoredProcess]: Starting monitored process 3 with /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 -smt2 -in SMTLIB2_COMPLIANT=true (exit command is (exit), workingDir is null) [2021-12-17 15:07:46,856 INFO L327 MonitoredProcess]: [MP /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 -smt2 -in SMTLIB2_COMPLIANT=true (3)] Waiting until timeout for monitored process [2021-12-17 15:07:46,919 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:07:46,922 INFO L263 TraceCheckSpWp]: Trace formula consists of 496 conjuncts, 9 conjunts are in the unsatisfiable core [2021-12-17 15:07:46,925 INFO L286 TraceCheckSpWp]: Computing forward predicates... [2021-12-17 15:07:47,186 INFO L134 CoverageAnalysis]: Checked inductivity of 44 backedges. 35 proven. 0 refuted. 0 times theorem prover too weak. 9 trivial. 0 not checked. [2021-12-17 15:07:47,186 INFO L324 TraceCheckSpWp]: Omiting computation of backward sequence because forward sequence was already perfect [2021-12-17 15:07:47,187 INFO L160 FreeRefinementEngine]: IpTcStrategyModuleZ3 [1713076773] provided 1 perfect and 0 imperfect interpolant sequences [2021-12-17 15:07:47,187 INFO L186 FreeRefinementEngine]: Found 1 perfect and 1 imperfect interpolant sequences. [2021-12-17 15:07:47,187 INFO L199 FreeRefinementEngine]: Number of different interpolants: perfect sequences [8] imperfect sequences [14] total 19 [2021-12-17 15:07:47,187 INFO L115 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [2016812172] [2021-12-17 15:07:47,187 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2021-12-17 15:07:47,188 INFO L546 AbstractCegarLoop]: INTERPOLANT automaton has 8 states [2021-12-17 15:07:47,188 INFO L103 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2021-12-17 15:07:47,188 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 8 interpolants. [2021-12-17 15:07:47,189 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=48, Invalid=294, Unknown=0, NotChecked=0, Total=342 [2021-12-17 15:07:47,189 INFO L87 Difference]: Start difference. First operand 383 states and 454 transitions. Second operand has 8 states, 8 states have (on average 9.625) internal successors, (77), 6 states have internal predecessors, (77), 3 states have call successors, (13), 3 states have call predecessors, (13), 5 states have return successors, (12), 5 states have call predecessors, (12), 3 states have call successors, (12) [2021-12-17 15:07:47,313 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2021-12-17 15:07:47,313 INFO L93 Difference]: Finished difference Result 642 states and 770 transitions. [2021-12-17 15:07:47,314 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 8 states. [2021-12-17 15:07:47,314 INFO L78 Accepts]: Start accepts. Automaton has has 8 states, 8 states have (on average 9.625) internal successors, (77), 6 states have internal predecessors, (77), 3 states have call successors, (13), 3 states have call predecessors, (13), 5 states have return successors, (12), 5 states have call predecessors, (12), 3 states have call successors, (12) Word has length 108 [2021-12-17 15:07:47,314 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2021-12-17 15:07:47,315 INFO L225 Difference]: With dead ends: 642 [2021-12-17 15:07:47,315 INFO L226 Difference]: Without dead ends: 0 [2021-12-17 15:07:47,317 INFO L932 BasicCegarLoop]: 0 DeclaredPredicates, 142 GetRequests, 123 SyntacticMatches, 0 SemanticMatches, 19 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 43 ImplicationChecksByTransitivity, 0.2s TimeCoverageRelationStatistics Valid=60, Invalid=360, Unknown=0, NotChecked=0, Total=420 [2021-12-17 15:07:47,317 INFO L933 BasicCegarLoop]: 170 mSDtfsCounter, 68 mSDsluCounter, 684 mSDsCounter, 0 mSdLazyCounter, 111 mSolverCounterSat, 6 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.1s Time, 0 mProtectedPredicate, 0 mProtectedAction, 72 SdHoareTripleChecker+Valid, 854 SdHoareTripleChecker+Invalid, 117 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 6 IncrementalHoareTripleChecker+Valid, 111 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.1s IncrementalHoareTripleChecker+Time [2021-12-17 15:07:47,318 INFO L934 BasicCegarLoop]: SdHoareTripleChecker [72 Valid, 854 Invalid, 117 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [6 Valid, 111 Invalid, 0 Unknown, 0 Unchecked, 0.1s Time] [2021-12-17 15:07:47,318 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 0 states. [2021-12-17 15:07:47,318 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 0 to 0. [2021-12-17 15:07:47,318 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 0 states, 0 states have (on average 0.0) internal successors, (0), 0 states have internal predecessors, (0), 0 states have call successors, (0), 0 states have call predecessors, (0), 0 states have return successors, (0), 0 states have call predecessors, (0), 0 states have call successors, (0) [2021-12-17 15:07:47,318 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 0 states to 0 states and 0 transitions. [2021-12-17 15:07:47,319 INFO L78 Accepts]: Start accepts. Automaton has 0 states and 0 transitions. Word has length 108 [2021-12-17 15:07:47,319 INFO L84 Accepts]: Finished accepts. word is rejected. [2021-12-17 15:07:47,319 INFO L470 AbstractCegarLoop]: Abstraction has 0 states and 0 transitions. [2021-12-17 15:07:47,319 INFO L471 AbstractCegarLoop]: INTERPOLANT automaton has has 8 states, 8 states have (on average 9.625) internal successors, (77), 6 states have internal predecessors, (77), 3 states have call successors, (13), 3 states have call predecessors, (13), 5 states have return successors, (12), 5 states have call predecessors, (12), 3 states have call successors, (12) [2021-12-17 15:07:47,319 INFO L276 IsEmpty]: Start isEmpty. Operand 0 states and 0 transitions. [2021-12-17 15:07:47,320 INFO L282 IsEmpty]: Finished isEmpty. No accepting run. [2021-12-17 15:07:47,322 INFO L764 garLoopResultBuilder]: Registering result SAFE for location timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION (0 of 1 remaining) [2021-12-17 15:07:47,353 INFO L540 MonitoredProcess]: [MP /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 -smt2 -in SMTLIB2_COMPLIANT=true (3)] Forceful destruction successful, exit code 0 [2021-12-17 15:07:47,540 WARN L452 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: 3 /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 -smt2 -in SMTLIB2_COMPLIANT=true,SelfDestructingSolverStorable10 [2021-12-17 15:07:47,542 INFO L343 DoubleDeckerVisitor]: Before removal of dead ends 0 states and 0 transitions. [2021-12-17 15:07:50,416 INFO L854 garLoopResultBuilder]: At program point deactivatePumpENTRY(lines 818 825) the Hoare annotation is: (let ((.cse0 (not (= 1 ~systemActive~0))) (.cse1 (= ~pumpRunning~0 |old(~pumpRunning~0)|))) (and (or .cse0 .cse1 (not (= ~methaneLevelCritical~0 0))) (or .cse0 (not (<= 1 ~methaneLevelCritical~0)) .cse1))) [2021-12-17 15:07:50,416 INFO L858 garLoopResultBuilder]: For program point deactivatePumpEXIT(lines 818 825) no Hoare annotation was computed. [2021-12-17 15:07:50,416 INFO L858 garLoopResultBuilder]: For program point deactivatePumpFINAL(lines 818 825) no Hoare annotation was computed. [2021-12-17 15:07:50,417 INFO L858 garLoopResultBuilder]: For program point processEnvironment__wrappee__baseEXIT(lines 734 740) no Hoare annotation was computed. [2021-12-17 15:07:50,417 INFO L861 garLoopResultBuilder]: At program point processEnvironment__wrappee__baseFINAL(lines 734 740) the Hoare annotation is: true [2021-12-17 15:07:50,417 INFO L858 garLoopResultBuilder]: For program point L640-1(lines 636 647) no Hoare annotation was computed. [2021-12-17 15:07:50,417 INFO L854 garLoopResultBuilder]: At program point changeMethaneLevelENTRY(lines 636 647) the Hoare annotation is: (let ((.cse4 (not (= |old(~methaneLevelCritical~0)| 0))) (.cse6 (= ~methaneLevelCritical~0 0)) (.cse3 (not (= ~systemActive~0 0))) (.cse0 (not (= ~pumpRunning~0 0))) (.cse5 (not (= 1 ~systemActive~0))) (.cse1 (= ~methaneLevelCritical~0 |old(~methaneLevelCritical~0)|)) (.cse2 (not (<= 1 |old(~methaneLevelCritical~0)|)))) (and (or .cse0 .cse1 .cse2 .cse3) (or .cse4 .cse5 .cse6) (or .cse4 .cse0 .cse6 .cse3) (or .cse0 .cse5 .cse1 .cse2))) [2021-12-17 15:07:50,417 INFO L858 garLoopResultBuilder]: For program point changeMethaneLevelEXIT(lines 636 647) no Hoare annotation was computed. [2021-12-17 15:07:50,417 INFO L854 garLoopResultBuilder]: At program point L787(line 787) the Hoare annotation is: (let ((.cse1 (not (<= 1 ~methaneLevelCritical~0))) (.cse0 (not (= 1 ~systemActive~0))) (.cse2 (and (= ~waterLevel~0 |old(~waterLevel~0)|) (= ~methAndRunningLastTime~0 |old(~methAndRunningLastTime~0)|) (= ~pumpRunning~0 |old(~pumpRunning~0)|) (= ~pumpRunning~0 0))) (.cse3 (not (= |old(~pumpRunning~0)| 0))) (.cse5 (not (= ~methaneLevelCritical~0 0))) (.cse4 (not (= ~systemActive~0 0)))) (and (or .cse0 .cse1 .cse2) (or .cse1 .cse3 .cse4) (or .cse0 .cse2 .cse5) (or .cse3 .cse5 .cse4))) [2021-12-17 15:07:50,418 INFO L854 garLoopResultBuilder]: At program point L787-1(lines 768 792) the Hoare annotation is: (let ((.cse4 (= ~waterLevel~0 |old(~waterLevel~0)|)) (.cse2 (not (= ~systemActive~0 0))) (.cse1 (not (= |old(~pumpRunning~0)| 0))) (.cse5 (not (= ~methaneLevelCritical~0 0))) (.cse6 (= ~methAndRunningLastTime~0 |old(~methAndRunningLastTime~0)|)) (.cse3 (not (= 1 ~systemActive~0))) (.cse0 (not (<= 1 ~methaneLevelCritical~0))) (.cse7 (= ~pumpRunning~0 0))) (and (or .cse0 .cse1 .cse2) (or .cse3 .cse4 .cse1 .cse5) (or .cse3 (and .cse4 .cse6) .cse0 .cse1) (or .cse1 .cse5 .cse2) (or (not (= |old(~waterLevel~0)| 1)) .cse3 .cse1 .cse5 (and .cse6 .cse7)) (or .cse3 .cse0 .cse7))) [2021-12-17 15:07:50,418 INFO L858 garLoopResultBuilder]: For program point L721-1(lines 721 727) no Hoare annotation was computed. [2021-12-17 15:07:50,418 INFO L858 garLoopResultBuilder]: For program point timeShiftFINAL(lines 710 733) no Hoare annotation was computed. [2021-12-17 15:07:50,418 INFO L858 garLoopResultBuilder]: For program point L486(lines 486 496) no Hoare annotation was computed. [2021-12-17 15:07:50,418 INFO L858 garLoopResultBuilder]: For program point L482(lines 482 499) no Hoare annotation was computed. [2021-12-17 15:07:50,419 INFO L854 garLoopResultBuilder]: At program point L482-1(lines 474 502) the Hoare annotation is: (let ((.cse1 (= |timeShift___utac_acc__Specification2_spec__2_~tmp~3#1| 0)) (.cse6 (not (= ~systemActive~0 0))) (.cse7 (not (<= 1 ~methaneLevelCritical~0))) (.cse3 (= ~waterLevel~0 |old(~waterLevel~0)|)) (.cse0 (not (= 1 ~systemActive~0))) (.cse4 (not (= |old(~pumpRunning~0)| 0))) (.cse2 (not (= ~methaneLevelCritical~0 0))) (.cse5 (= ~pumpRunning~0 0))) (and (or .cse0 .cse1 .cse2) (or .cse0 .cse3 .cse4 .cse2) (or .cse4 (and .cse1 .cse3 .cse5) .cse2 .cse6) (or .cse0 .cse7 .cse5) (or (and .cse3 (= ~pumpRunning~0 |old(~pumpRunning~0)|)) .cse7 .cse4 .cse6) (or .cse0 .cse7 .cse3 .cse4) (or (not (= |old(~waterLevel~0)| 1)) .cse0 .cse4 .cse2 .cse5))) [2021-12-17 15:07:50,419 INFO L854 garLoopResultBuilder]: At program point L842(lines 837 845) the Hoare annotation is: (let ((.cse2 (not (= 1 ~systemActive~0))) (.cse4 (not (= ~methaneLevelCritical~0 0))) (.cse0 (= |timeShift_isPumpRunning_#res#1| 0)) (.cse6 (= ~methAndRunningLastTime~0 |old(~methAndRunningLastTime~0)|)) (.cse5 (= ~waterLevel~0 |old(~waterLevel~0)|)) (.cse1 (= ~pumpRunning~0 0)) (.cse3 (not (<= 1 ~methaneLevelCritical~0))) (.cse7 (not (= |old(~pumpRunning~0)| 0))) (.cse8 (not (= ~systemActive~0 0)))) (and (or (and .cse0 .cse1) .cse2 .cse3) (or .cse2 .cse4) (or .cse2 (and .cse5 .cse6) .cse3 .cse7) (or .cse7 .cse4 .cse8) (or (and .cse0 .cse6 .cse5 .cse1) .cse3 .cse7 .cse8))) [2021-12-17 15:07:50,419 INFO L858 garLoopResultBuilder]: For program point L714-1(lines 713 732) no Hoare annotation was computed. [2021-12-17 15:07:50,419 INFO L858 garLoopResultBuilder]: For program point L776(lines 776 784) no Hoare annotation was computed. [2021-12-17 15:07:50,419 INFO L858 garLoopResultBuilder]: For program point L487(lines 487 493) no Hoare annotation was computed. [2021-12-17 15:07:50,419 INFO L858 garLoopResultBuilder]: For program point L772(lines 772 789) no Hoare annotation was computed. [2021-12-17 15:07:50,419 INFO L858 garLoopResultBuilder]: For program point L54(line 54) no Hoare annotation was computed. [2021-12-17 15:07:50,419 INFO L858 garLoopResultBuilder]: For program point L616(lines 616 620) no Hoare annotation was computed. [2021-12-17 15:07:50,419 INFO L854 garLoopResultBuilder]: At program point L616-2(lines 612 623) the Hoare annotation is: (let ((.cse1 (not (= |old(~pumpRunning~0)| 0))) (.cse4 (not (= ~systemActive~0 0))) (.cse2 (not (= ~methaneLevelCritical~0 0))) (.cse0 (not (= 1 ~systemActive~0))) (.cse3 (not (<= 1 ~methaneLevelCritical~0))) (.cse5 (= ~pumpRunning~0 |old(~pumpRunning~0)|))) (and (or .cse0 .cse1 .cse2) (or .cse0 .cse3 .cse1) (or .cse3 .cse1 .cse4) (or .cse1 .cse2 .cse4) (or .cse0 .cse5 .cse2) (or .cse0 .cse3 .cse5))) [2021-12-17 15:07:50,420 INFO L854 garLoopResultBuilder]: At program point L480(line 480) the Hoare annotation is: (let ((.cse7 (= ~methAndRunningLastTime~0 |old(~methAndRunningLastTime~0)|)) (.cse6 (= ~waterLevel~0 |old(~waterLevel~0)|)) (.cse8 (= ~pumpRunning~0 0))) (let ((.cse0 (and .cse7 .cse6 .cse8)) (.cse3 (not (= ~systemActive~0 0))) (.cse1 (not (= |old(~pumpRunning~0)| 0))) (.cse2 (not (= ~methaneLevelCritical~0 0))) (.cse5 (not (= 1 ~systemActive~0))) (.cse4 (not (<= 1 ~methaneLevelCritical~0)))) (and (or .cse0 .cse1 .cse2 .cse3) (or .cse0 .cse4 .cse1 .cse3) (or .cse5 .cse6 .cse1 .cse2) (or .cse5 (and .cse6 .cse7) .cse4 .cse1) (or (not (= |old(~waterLevel~0)| 1)) .cse5 .cse1 .cse2 (and .cse7 .cse8)) (or .cse5 .cse4 .cse8)))) [2021-12-17 15:07:50,420 INFO L858 garLoopResultBuilder]: For program point L480-1(line 480) no Hoare annotation was computed. [2021-12-17 15:07:50,420 INFO L854 garLoopResultBuilder]: At program point L55(lines 50 57) the Hoare annotation is: (let ((.cse3 (not (= |old(~pumpRunning~0)| 0))) (.cse1 (not (= ~methaneLevelCritical~0 0))) (.cse4 (not (= ~systemActive~0 0))) (.cse0 (not (= 1 ~systemActive~0))) (.cse2 (not (<= 1 ~methaneLevelCritical~0)))) (and (or .cse0 .cse1) (or .cse2 .cse3 .cse4) (or .cse3 .cse1 .cse4) (or .cse0 .cse2))) [2021-12-17 15:07:50,420 INFO L854 garLoopResultBuilder]: At program point timeShiftENTRY(lines 710 733) the Hoare annotation is: (let ((.cse8 (= ~methAndRunningLastTime~0 |old(~methAndRunningLastTime~0)|)) (.cse7 (= ~waterLevel~0 |old(~waterLevel~0)|))) (let ((.cse3 (and .cse8 .cse7 (= ~pumpRunning~0 0))) (.cse1 (not (<= 1 ~methaneLevelCritical~0))) (.cse4 (not (= |old(~pumpRunning~0)| 0))) (.cse6 (not (= ~systemActive~0 0))) (.cse0 (not (= 1 ~systemActive~0))) (.cse5 (not (= ~methaneLevelCritical~0 0))) (.cse2 (and .cse7 .cse8 (= ~pumpRunning~0 |old(~pumpRunning~0)|)))) (and (or .cse0 .cse1 .cse2) (or .cse3 .cse4 .cse5 .cse6) (or .cse3 .cse1 .cse4 .cse6) (or .cse0 .cse5 .cse2)))) [2021-12-17 15:07:50,420 INFO L854 garLoopResultBuilder]: At program point L782(line 782) the Hoare annotation is: (let ((.cse1 (not (= |old(~pumpRunning~0)| 0))) (.cse4 (not (= ~systemActive~0 0))) (.cse3 (not (<= 1 ~methaneLevelCritical~0))) (.cse0 (not (= 1 ~systemActive~0))) (.cse2 (not (= ~methaneLevelCritical~0 0)))) (and (or .cse0 .cse1 .cse2) (or .cse3 .cse1 .cse4) (or .cse1 .cse2 .cse4) (or .cse0 .cse3) (or .cse0 (= ~pumpRunning~0 |old(~pumpRunning~0)|) .cse2))) [2021-12-17 15:07:50,420 INFO L858 garLoopResultBuilder]: For program point timeShiftEXIT(lines 710 733) no Hoare annotation was computed. [2021-12-17 15:07:50,421 INFO L854 garLoopResultBuilder]: At program point L778(line 778) the Hoare annotation is: (let ((.cse1 (not (= |old(~pumpRunning~0)| 0))) (.cse4 (not (= ~systemActive~0 0))) (.cse2 (not (= ~methaneLevelCritical~0 0))) (.cse0 (not (= 1 ~systemActive~0))) (.cse3 (not (<= 1 ~methaneLevelCritical~0))) (.cse5 (= ~pumpRunning~0 |old(~pumpRunning~0)|))) (and (or .cse0 .cse1 .cse2) (or .cse0 .cse3 .cse1) (or .cse3 .cse1 .cse4) (or .cse1 .cse2 .cse4) (or .cse0 .cse5 .cse2) (or .cse0 .cse3 (and (<= 1 |timeShift_processEnvironment_~tmp~6#1|) .cse5)))) [2021-12-17 15:07:50,421 INFO L858 garLoopResultBuilder]: For program point timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION(line 54) no Hoare annotation was computed. [2021-12-17 15:07:50,421 INFO L854 garLoopResultBuilder]: At program point L774(line 774) the Hoare annotation is: (let ((.cse1 (not (= |old(~pumpRunning~0)| 0))) (.cse4 (not (= ~systemActive~0 0))) (.cse2 (not (= ~methaneLevelCritical~0 0))) (.cse0 (not (= 1 ~systemActive~0))) (.cse3 (not (<= 1 ~methaneLevelCritical~0))) (.cse5 (= ~pumpRunning~0 |old(~pumpRunning~0)|))) (and (or .cse0 .cse1 .cse2) (or .cse0 .cse3 .cse1) (or .cse3 .cse1 .cse4) (or .cse1 .cse2 .cse4) (or .cse0 .cse5 .cse2) (or .cse0 .cse3 .cse5))) [2021-12-17 15:07:50,421 INFO L858 garLoopResultBuilder]: For program point L774-1(line 774) no Hoare annotation was computed. [2021-12-17 15:07:50,421 INFO L861 garLoopResultBuilder]: At program point L512(line 512) the Hoare annotation is: true [2021-12-17 15:07:50,422 INFO L858 garLoopResultBuilder]: For program point cleanupEXIT(lines 506 535) no Hoare annotation was computed. [2021-12-17 15:07:50,422 INFO L858 garLoopResultBuilder]: For program point L512-1(line 512) no Hoare annotation was computed. [2021-12-17 15:07:50,422 INFO L861 garLoopResultBuilder]: At program point cleanupENTRY(lines 506 535) the Hoare annotation is: true [2021-12-17 15:07:50,422 INFO L861 garLoopResultBuilder]: At program point L531(lines 506 535) the Hoare annotation is: true [2021-12-17 15:07:50,422 INFO L858 garLoopResultBuilder]: For program point L527(line 527) no Hoare annotation was computed. [2021-12-17 15:07:50,422 INFO L858 garLoopResultBuilder]: For program point L520(lines 520 524) no Hoare annotation was computed. [2021-12-17 15:07:50,422 INFO L861 garLoopResultBuilder]: At program point L520-1(lines 520 524) the Hoare annotation is: true [2021-12-17 15:07:50,423 INFO L858 garLoopResultBuilder]: For program point L517(line 517) no Hoare annotation was computed. [2021-12-17 15:07:50,423 INFO L861 garLoopResultBuilder]: At program point L516-2(lines 516 530) the Hoare annotation is: true [2021-12-17 15:07:50,423 INFO L861 garLoopResultBuilder]: At program point isMethaneLevelCriticalENTRY(lines 648 656) the Hoare annotation is: true [2021-12-17 15:07:50,423 INFO L858 garLoopResultBuilder]: For program point isMethaneLevelCriticalFINAL(lines 648 656) no Hoare annotation was computed. [2021-12-17 15:07:50,423 INFO L858 garLoopResultBuilder]: For program point isMethaneLevelCriticalEXIT(lines 648 656) no Hoare annotation was computed. [2021-12-17 15:07:50,423 INFO L861 garLoopResultBuilder]: At program point L601(lines 582 604) the Hoare annotation is: true [2021-12-17 15:07:50,423 INFO L854 garLoopResultBuilder]: At program point L77(lines 73 79) the Hoare annotation is: (and (= ~waterLevel~0 1) (= ~methaneLevelCritical~0 0) (= ~systemActive~0 1) (= ~pumpRunning~0 0)) [2021-12-17 15:07:50,424 INFO L854 garLoopResultBuilder]: At program point L907(line 907) the Hoare annotation is: (let ((.cse0 (= |ULTIMATE.start_test_~splverifierCounter~0#1| 0)) (.cse1 (= ~systemActive~0 1))) (or (and .cse0 (<= 1 ~methaneLevelCritical~0) .cse1) (and .cse0 (= ~methaneLevelCritical~0 0) .cse1))) [2021-12-17 15:07:50,424 INFO L858 garLoopResultBuilder]: For program point L928(lines 927 974) no Hoare annotation was computed. [2021-12-17 15:07:50,424 INFO L858 garLoopResultBuilder]: For program point L-1(line -1) no Hoare annotation was computed. [2021-12-17 15:07:50,424 INFO L858 garLoopResultBuilder]: For program point ULTIMATE.startENTRY(line -1) no Hoare annotation was computed. [2021-12-17 15:07:50,424 INFO L858 garLoopResultBuilder]: For program point L957(lines 957 970) no Hoare annotation was computed. [2021-12-17 15:07:50,424 INFO L858 garLoopResultBuilder]: For program point ULTIMATE.startFINAL(line -1) no Hoare annotation was computed. [2021-12-17 15:07:50,424 INFO L854 garLoopResultBuilder]: At program point L949(line 949) the Hoare annotation is: (let ((.cse2 (= ~systemActive~0 1)) (.cse4 (= ~methaneLevelCritical~0 0)) (.cse0 (= |ULTIMATE.start_test_~splverifierCounter~0#1| 0)) (.cse5 (= ~systemActive~0 0)) (.cse1 (<= 1 ~methaneLevelCritical~0)) (.cse3 (= ~pumpRunning~0 0))) (or (and .cse0 .cse1 .cse2 .cse3) (and .cse0 .cse4 .cse2) (and .cse0 .cse5 .cse4 .cse3) (and .cse0 .cse5 .cse1 .cse3))) [2021-12-17 15:07:50,425 INFO L861 garLoopResultBuilder]: At program point L978(lines 917 982) the Hoare annotation is: true [2021-12-17 15:07:50,425 INFO L858 garLoopResultBuilder]: For program point L937(lines 937 943) no Hoare annotation was computed. [2021-12-17 15:07:50,425 INFO L858 garLoopResultBuilder]: For program point L937-1(lines 937 943) no Hoare annotation was computed. [2021-12-17 15:07:50,425 INFO L858 garLoopResultBuilder]: For program point L929(lines 929 933) no Hoare annotation was computed. [2021-12-17 15:07:50,425 INFO L858 garLoopResultBuilder]: For program point ULTIMATE.startEXIT(line -1) no Hoare annotation was computed. [2021-12-17 15:07:50,425 INFO L854 garLoopResultBuilder]: At program point L471(lines 466 473) the Hoare annotation is: (and (= ~waterLevel~0 1) (= ~methaneLevelCritical~0 0) (= ~systemActive~0 1) (= ~pumpRunning~0 0)) [2021-12-17 15:07:50,425 INFO L854 garLoopResultBuilder]: At program point L913(lines 901 915) the Hoare annotation is: (let ((.cse0 (= |ULTIMATE.start_test_~splverifierCounter~0#1| 0)) (.cse1 (= ~systemActive~0 0)) (.cse2 (= ~pumpRunning~0 0))) (or (and .cse0 .cse1 (= ~methaneLevelCritical~0 0) .cse2) (and .cse0 .cse1 (<= 1 ~methaneLevelCritical~0) .cse2))) [2021-12-17 15:07:50,426 INFO L854 garLoopResultBuilder]: At program point L975(lines 926 976) the Hoare annotation is: false [2021-12-17 15:07:50,426 INFO L858 garLoopResultBuilder]: For program point L905(lines 905 911) no Hoare annotation was computed. [2021-12-17 15:07:50,426 INFO L858 garLoopResultBuilder]: For program point L905-1(lines 905 911) no Hoare annotation was computed. [2021-12-17 15:07:50,426 INFO L858 garLoopResultBuilder]: For program point L963(lines 963 969) no Hoare annotation was computed. [2021-12-17 15:07:50,426 INFO L861 garLoopResultBuilder]: At program point L579(lines 571 581) the Hoare annotation is: true [2021-12-17 15:07:50,426 INFO L854 garLoopResultBuilder]: At program point L963-2(lines 957 970) the Hoare annotation is: (let ((.cse2 (= ~systemActive~0 1)) (.cse3 (= ~methaneLevelCritical~0 0)) (.cse0 (= |ULTIMATE.start_test_~splverifierCounter~0#1| 0)) (.cse4 (= ~systemActive~0 0)) (.cse1 (<= 1 ~methaneLevelCritical~0)) (.cse5 (= ~pumpRunning~0 0))) (or (and .cse0 .cse1 .cse2) (and .cse0 .cse3 .cse2) (and .cse0 .cse4 .cse3 .cse5) (and .cse0 .cse4 .cse1 .cse5))) [2021-12-17 15:07:50,427 INFO L854 garLoopResultBuilder]: At program point L92(lines 87 95) the Hoare annotation is: (and (= ~waterLevel~0 1) (= ~methaneLevelCritical~0 0) (= ~systemActive~0 1) (= ~pumpRunning~0 0)) [2021-12-17 15:07:50,427 INFO L854 garLoopResultBuilder]: At program point L567(lines 563 569) the Hoare annotation is: (and (= ~waterLevel~0 1) (= ~methaneLevelCritical~0 0) (= ~systemActive~0 1) (= ~pumpRunning~0 0)) [2021-12-17 15:07:50,427 INFO L854 garLoopResultBuilder]: At program point L84(lines 80 86) the Hoare annotation is: (and (= ~waterLevel~0 1) (= ~methaneLevelCritical~0 0) (= ~systemActive~0 1) (= ~pumpRunning~0 0)) [2021-12-17 15:07:50,427 INFO L858 garLoopResultBuilder]: For program point L947(lines 947 953) no Hoare annotation was computed. [2021-12-17 15:07:50,427 INFO L858 garLoopResultBuilder]: For program point L947-1(lines 947 953) no Hoare annotation was computed. [2021-12-17 15:07:50,427 INFO L858 garLoopResultBuilder]: For program point L592(lines 592 599) no Hoare annotation was computed. [2021-12-17 15:07:50,427 INFO L858 garLoopResultBuilder]: For program point L592-2(lines 592 599) no Hoare annotation was computed. [2021-12-17 15:07:50,428 INFO L854 garLoopResultBuilder]: At program point L972(lines 927 974) the Hoare annotation is: (let ((.cse2 (= ~systemActive~0 1)) (.cse4 (= ~methaneLevelCritical~0 0)) (.cse0 (= |ULTIMATE.start_test_~splverifierCounter~0#1| 0)) (.cse5 (= ~systemActive~0 0)) (.cse1 (<= 1 ~methaneLevelCritical~0)) (.cse3 (= ~pumpRunning~0 0))) (or (and .cse0 .cse1 .cse2 .cse3) (and .cse0 .cse4 .cse2) (and .cse0 .cse5 .cse4 .cse3) (and .cse0 .cse5 .cse1 .cse3))) [2021-12-17 15:07:50,428 INFO L854 garLoopResultBuilder]: At program point L939(line 939) the Hoare annotation is: (let ((.cse2 (= ~systemActive~0 1)) (.cse4 (= ~methaneLevelCritical~0 0)) (.cse0 (= |ULTIMATE.start_test_~splverifierCounter~0#1| 0)) (.cse5 (= ~systemActive~0 0)) (.cse1 (<= 1 ~methaneLevelCritical~0)) (.cse3 (= ~pumpRunning~0 0))) (or (and .cse0 .cse1 .cse2 .cse3) (and .cse0 .cse4 .cse2) (and .cse0 .cse5 .cse4 .cse3) (and .cse0 .cse5 .cse1 .cse3))) [2021-12-17 15:07:50,428 INFO L858 garLoopResultBuilder]: For program point waterRiseEXIT(lines 624 635) no Hoare annotation was computed. [2021-12-17 15:07:50,428 INFO L854 garLoopResultBuilder]: At program point waterRiseENTRY(lines 624 635) the Hoare annotation is: (let ((.cse3 (not (= ~systemActive~0 0))) (.cse4 (not (= ~methaneLevelCritical~0 0))) (.cse0 (not (= ~pumpRunning~0 0))) (.cse5 (not (= 1 ~systemActive~0))) (.cse1 (not (<= 1 ~methaneLevelCritical~0))) (.cse2 (= ~waterLevel~0 |old(~waterLevel~0)|))) (and (or .cse0 .cse1 .cse2 .cse3) (or .cse0 .cse2 .cse4 .cse3) (or .cse5 .cse2 .cse4) (or .cse0 .cse5 .cse1 .cse2))) [2021-12-17 15:07:50,428 INFO L858 garLoopResultBuilder]: For program point L628-1(lines 624 635) no Hoare annotation was computed. [2021-12-17 15:07:50,429 INFO L854 garLoopResultBuilder]: At program point L698(lines 689 702) the Hoare annotation is: (let ((.cse0 (not (= ~waterLevel~0 1))) (.cse7 (not (= ~methaneLevelCritical~0 0))) (.cse1 (not (= 1 ~systemActive~0))) (.cse3 (not (<= 1 ~methaneLevelCritical~0))) (.cse8 (= |processEnvironment__wrappee__methaneQuery_isHighWaterSensorDry_#res#1| 0)) (.cse4 (not (= |old(~pumpRunning~0)| 0))) (.cse2 (<= 1 |processEnvironment__wrappee__methaneQuery_isHighWaterSensorDry_#res#1|)) (.cse6 (= ~pumpRunning~0 0))) (and (or .cse0 .cse1 .cse2 .cse3 .cse4) (let ((.cse5 (= ~pumpRunning~0 |old(~pumpRunning~0)|))) (or (and .cse2 .cse5 .cse6) .cse1 .cse7 (and .cse8 .cse5 .cse6))) (or .cse0 .cse2 .cse1 .cse7) (or .cse1 .cse3 (and .cse8 .cse6) .cse4 (and .cse2 .cse6)))) [2021-12-17 15:07:50,429 INFO L854 garLoopResultBuilder]: At program point L756(line 756) the Hoare annotation is: (let ((.cse2 (= |processEnvironment__wrappee__methaneQuery_~tmp~5#1| 0)) (.cse3 (= ~pumpRunning~0 0)) (.cse6 (not (<= 1 ~methaneLevelCritical~0))) (.cse7 (not (= |old(~pumpRunning~0)| 0))) (.cse4 (and (<= 1 |processEnvironment__wrappee__methaneQuery_isHighWaterSensorDry_#res#1|) (<= 1 |processEnvironment__wrappee__methaneQuery_isHighWaterLevel_~tmp~8#1|))) (.cse5 (not (= ~waterLevel~0 1))) (.cse0 (not (= 1 ~systemActive~0))) (.cse1 (not (= ~methaneLevelCritical~0 0)))) (and (or .cse0 .cse1 (and (= ~pumpRunning~0 |old(~pumpRunning~0)|) .cse2 .cse3)) (or .cse4 .cse5 .cse0 .cse6 .cse7) (or .cse0 (and .cse2 .cse3) .cse6 .cse7) (or .cse4 .cse5 .cse0 .cse1))) [2021-12-17 15:07:50,429 INFO L858 garLoopResultBuilder]: For program point L750(lines 750 758) no Hoare annotation was computed. [2021-12-17 15:07:50,429 INFO L858 garLoopResultBuilder]: For program point L746(lines 746 763) no Hoare annotation was computed. [2021-12-17 15:07:50,429 INFO L858 garLoopResultBuilder]: For program point L808(lines 808 814) no Hoare annotation was computed. [2021-12-17 15:07:50,429 INFO L854 garLoopResultBuilder]: At program point L806(line 806) the Hoare annotation is: (let ((.cse4 (not (<= 1 ~methaneLevelCritical~0))) (.cse0 (= ~pumpRunning~0 |old(~pumpRunning~0)|)) (.cse5 (not (= |old(~pumpRunning~0)| 0))) (.cse3 (not (= ~waterLevel~0 1))) (.cse1 (not (= 1 ~systemActive~0))) (.cse2 (not (= ~methaneLevelCritical~0 0)))) (and (or (and .cse0 (= ~pumpRunning~0 0)) .cse1 .cse2) (or .cse3 .cse1 .cse4 .cse5) (or .cse1 .cse4 .cse0 .cse5) (or .cse3 .cse1 .cse2))) [2021-12-17 15:07:50,430 INFO L854 garLoopResultBuilder]: At program point L808-2(lines 801 817) the Hoare annotation is: (let ((.cse2 (not (<= 1 ~methaneLevelCritical~0))) (.cse0 (not (= ~waterLevel~0 1))) (.cse1 (not (= 1 ~systemActive~0))) (.cse3 (not (= |old(~pumpRunning~0)| 0)))) (and (or .cse0 .cse1 .cse2 .cse3) (or (and (<= ~methaneLevelCritical~0 |processEnvironment__wrappee__methaneQuery_activatePump_~tmp~7#1|) (= ~pumpRunning~0 |old(~pumpRunning~0)|)) .cse1 .cse2 .cse3) (or .cse0 .cse1 .cse3 (not (= ~methaneLevelCritical~0 0))))) [2021-12-17 15:07:50,430 INFO L858 garLoopResultBuilder]: For program point L806-1(line 806) no Hoare annotation was computed. [2021-12-17 15:07:50,430 INFO L854 garLoopResultBuilder]: At program point L897(lines 882 900) the Hoare annotation is: (let ((.cse0 (= ~pumpRunning~0 |old(~pumpRunning~0)|)) (.cse3 (not (<= 1 ~methaneLevelCritical~0))) (.cse4 (not (= |old(~pumpRunning~0)| 0))) (.cse5 (not (= ~waterLevel~0 1))) (.cse1 (not (= 1 ~systemActive~0))) (.cse2 (not (= ~methaneLevelCritical~0 0))) (.cse6 (and (<= 1 |processEnvironment__wrappee__methaneQuery_isHighWaterSensorDry_#res#1|) (<= 1 |processEnvironment__wrappee__methaneQuery_isHighWaterLevel_~tmp~8#1|) (= |processEnvironment__wrappee__methaneQuery_isHighWaterLevel_~tmp___0~1#1| 0) (= |processEnvironment__wrappee__methaneQuery_isHighWaterLevel_#res#1| 0)))) (and (or (and .cse0 (= ~pumpRunning~0 0)) .cse1 .cse2) (or .cse1 .cse3 .cse0 .cse4) (or .cse5 .cse1 .cse3 .cse4 .cse6) (or .cse5 .cse1 .cse2 .cse6))) [2021-12-17 15:07:50,430 INFO L854 garLoopResultBuilder]: At program point L798(lines 793 800) the Hoare annotation is: (let ((.cse0 (not (= 1 ~systemActive~0))) (.cse1 (not (= |old(~pumpRunning~0)| 0)))) (and (or .cse0 (not (<= 1 ~methaneLevelCritical~0)) .cse1) (or (not (= ~waterLevel~0 1)) .cse0 .cse1 (not (= ~methaneLevelCritical~0 0))))) [2021-12-17 15:07:50,430 INFO L858 garLoopResultBuilder]: For program point L891(lines 891 895) no Hoare annotation was computed. [2021-12-17 15:07:50,430 INFO L858 garLoopResultBuilder]: For program point L891-2(lines 891 895) no Hoare annotation was computed. [2021-12-17 15:07:50,431 INFO L854 garLoopResultBuilder]: At program point L761(line 761) the Hoare annotation is: (let ((.cse1 (not (= |old(~pumpRunning~0)| 0))) (.cse0 (not (= 1 ~systemActive~0))) (.cse2 (not (= ~methaneLevelCritical~0 0)))) (and (or .cse0 .cse1 .cse2) (or .cse0 (not (<= 1 ~methaneLevelCritical~0)) .cse1) (or .cse0 (= ~pumpRunning~0 |old(~pumpRunning~0)|) .cse2))) [2021-12-17 15:07:50,431 INFO L858 garLoopResultBuilder]: For program point L761-1(lines 742 766) no Hoare annotation was computed. [2021-12-17 15:07:50,431 INFO L858 garLoopResultBuilder]: For program point L693(lines 693 699) no Hoare annotation was computed. [2021-12-17 15:07:50,431 INFO L854 garLoopResultBuilder]: At program point processEnvironment__wrappee__methaneQueryENTRY(lines 742 766) the Hoare annotation is: (let ((.cse0 (not (= 1 ~systemActive~0)))) (and (or .cse0 (not (<= 1 ~methaneLevelCritical~0)) (not (= |old(~pumpRunning~0)| 0)) (= ~pumpRunning~0 0)) (or .cse0 (= ~pumpRunning~0 |old(~pumpRunning~0)|) (not (= ~methaneLevelCritical~0 0))))) [2021-12-17 15:07:50,431 INFO L858 garLoopResultBuilder]: For program point processEnvironment__wrappee__methaneQueryEXIT(lines 742 766) no Hoare annotation was computed. [2021-12-17 15:07:50,431 INFO L861 garLoopResultBuilder]: At program point isMethaneAlarmENTRY(lines 826 836) the Hoare annotation is: true [2021-12-17 15:07:50,431 INFO L861 garLoopResultBuilder]: At program point L831(line 831) the Hoare annotation is: true [2021-12-17 15:07:50,432 INFO L858 garLoopResultBuilder]: For program point L831-1(line 831) no Hoare annotation was computed. [2021-12-17 15:07:50,432 INFO L858 garLoopResultBuilder]: For program point isMethaneAlarmEXIT(lines 826 836) no Hoare annotation was computed. [2021-12-17 15:07:50,432 INFO L858 garLoopResultBuilder]: For program point isMethaneAlarmFINAL(lines 826 836) no Hoare annotation was computed. [2021-12-17 15:07:50,435 INFO L732 BasicCegarLoop]: Path program histogram: [1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2021-12-17 15:07:50,436 INFO L179 ceAbstractionStarter]: Computing trace abstraction results [2021-12-17 15:07:50,468 INFO L202 PluginConnector]: Adding new model de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction CFG 17.12 03:07:50 BoogieIcfgContainer [2021-12-17 15:07:50,469 INFO L132 PluginConnector]: ------------------------ END TraceAbstraction---------------------------- [2021-12-17 15:07:50,469 INFO L113 PluginConnector]: ------------------------Witness Printer---------------------------- [2021-12-17 15:07:50,469 INFO L271 PluginConnector]: Initializing Witness Printer... [2021-12-17 15:07:50,470 INFO L275 PluginConnector]: Witness Printer initialized [2021-12-17 15:07:50,470 INFO L185 PluginConnector]: Executing the observer RCFGCatcher from plugin Witness Printer for "de.uni_freiburg.informatik.ultimate.plugins.generator.rcfgbuilder CFG 17.12 03:07:41" (3/4) ... [2021-12-17 15:07:50,473 INFO L137 WitnessPrinter]: Generating witness for correct program [2021-12-17 15:07:50,478 INFO L354 RCFGBacktranslator]: Ignoring RootEdge to procedure deactivatePump [2021-12-17 15:07:50,478 INFO L354 RCFGBacktranslator]: Ignoring RootEdge to procedure processEnvironment__wrappee__base [2021-12-17 15:07:50,478 INFO L354 RCFGBacktranslator]: Ignoring RootEdge to procedure changeMethaneLevel [2021-12-17 15:07:50,478 INFO L354 RCFGBacktranslator]: Ignoring RootEdge to procedure timeShift [2021-12-17 15:07:50,478 INFO L354 RCFGBacktranslator]: Ignoring RootEdge to procedure cleanup [2021-12-17 15:07:50,478 INFO L354 RCFGBacktranslator]: Ignoring RootEdge to procedure isMethaneLevelCritical [2021-12-17 15:07:50,479 INFO L354 RCFGBacktranslator]: Ignoring RootEdge to procedure waterRise [2021-12-17 15:07:50,479 INFO L354 RCFGBacktranslator]: Ignoring RootEdge to procedure processEnvironment__wrappee__methaneQuery [2021-12-17 15:07:50,479 INFO L354 RCFGBacktranslator]: Ignoring RootEdge to procedure isMethaneAlarm [2021-12-17 15:07:50,485 INFO L910 BoogieBacktranslator]: Reduced CFG by removing 50 nodes and edges [2021-12-17 15:07:50,486 INFO L910 BoogieBacktranslator]: Reduced CFG by removing 22 nodes and edges [2021-12-17 15:07:50,486 INFO L910 BoogieBacktranslator]: Reduced CFG by removing 11 nodes and edges [2021-12-17 15:07:50,487 INFO L910 BoogieBacktranslator]: Reduced CFG by removing 5 nodes and edges [2021-12-17 15:07:50,487 INFO L910 BoogieBacktranslator]: Reduced CFG by removing 2 nodes and edges [2021-12-17 15:07:50,488 INFO L910 BoogieBacktranslator]: Reduced CFG by removing 1 nodes and edges [2021-12-17 15:07:50,488 INFO L910 BoogieBacktranslator]: Reduced CFG by removing 1 nodes and edges [2021-12-17 15:07:50,507 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: ((((((!(1 == systemActive) || !(\old(pumpRunning) == 0)) || !(methaneLevelCritical == 0)) && ((!(1 == systemActive) || !(1 <= methaneLevelCritical)) || !(\old(pumpRunning) == 0))) && ((!(1 <= methaneLevelCritical) || !(\old(pumpRunning) == 0)) || !(systemActive == 0))) && ((!(\old(pumpRunning) == 0) || !(methaneLevelCritical == 0)) || !(systemActive == 0))) && ((!(1 == systemActive) || pumpRunning == \old(pumpRunning)) || !(methaneLevelCritical == 0))) && ((!(1 == systemActive) || !(1 <= methaneLevelCritical)) || pumpRunning == \old(pumpRunning)) [2021-12-17 15:07:50,507 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: ((((((!(1 <= methaneLevelCritical) || !(\old(pumpRunning) == 0)) || !(systemActive == 0)) && (((!(1 == systemActive) || waterLevel == \old(waterLevel)) || !(\old(pumpRunning) == 0)) || !(methaneLevelCritical == 0))) && (((!(1 == systemActive) || (waterLevel == \old(waterLevel) && methAndRunningLastTime == \old(methAndRunningLastTime))) || !(1 <= methaneLevelCritical)) || !(\old(pumpRunning) == 0))) && ((!(\old(pumpRunning) == 0) || !(methaneLevelCritical == 0)) || !(systemActive == 0))) && ((((!(\old(waterLevel) == 1) || !(1 == systemActive)) || !(\old(pumpRunning) == 0)) || !(methaneLevelCritical == 0)) || (methAndRunningLastTime == \old(methAndRunningLastTime) && pumpRunning == 0))) && ((!(1 == systemActive) || !(1 <= methaneLevelCritical)) || pumpRunning == 0) [2021-12-17 15:07:50,508 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (((((((!(1 == systemActive) || tmp == 0) || !(methaneLevelCritical == 0)) && (((!(1 == systemActive) || waterLevel == \old(waterLevel)) || !(\old(pumpRunning) == 0)) || !(methaneLevelCritical == 0))) && (((!(\old(pumpRunning) == 0) || ((tmp == 0 && waterLevel == \old(waterLevel)) && pumpRunning == 0)) || !(methaneLevelCritical == 0)) || !(systemActive == 0))) && ((!(1 == systemActive) || !(1 <= methaneLevelCritical)) || pumpRunning == 0)) && ((((waterLevel == \old(waterLevel) && pumpRunning == \old(pumpRunning)) || !(1 <= methaneLevelCritical)) || !(\old(pumpRunning) == 0)) || !(systemActive == 0))) && (((!(1 == systemActive) || !(1 <= methaneLevelCritical)) || waterLevel == \old(waterLevel)) || !(\old(pumpRunning) == 0))) && ((((!(\old(waterLevel) == 1) || !(1 == systemActive)) || !(\old(pumpRunning) == 0)) || !(methaneLevelCritical == 0)) || pumpRunning == 0) [2021-12-17 15:07:50,509 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: ((((((\result == 0 && pumpRunning == 0) || !(1 == systemActive)) || !(1 <= methaneLevelCritical)) && (!(1 == systemActive) || !(methaneLevelCritical == 0))) && (((!(1 == systemActive) || (waterLevel == \old(waterLevel) && methAndRunningLastTime == \old(methAndRunningLastTime))) || !(1 <= methaneLevelCritical)) || !(\old(pumpRunning) == 0))) && ((!(\old(pumpRunning) == 0) || !(methaneLevelCritical == 0)) || !(systemActive == 0))) && ((((((\result == 0 && methAndRunningLastTime == \old(methAndRunningLastTime)) && waterLevel == \old(waterLevel)) && pumpRunning == 0) || !(1 <= methaneLevelCritical)) || !(\old(pumpRunning) == 0)) || !(systemActive == 0)) [2021-12-17 15:07:50,509 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: ((((!(waterLevel == 1) || !(1 == systemActive)) || !(1 <= methaneLevelCritical)) || !(\old(pumpRunning) == 0)) && ((((methaneLevelCritical <= tmp && pumpRunning == \old(pumpRunning)) || !(1 == systemActive)) || !(1 <= methaneLevelCritical)) || !(\old(pumpRunning) == 0))) && (((!(waterLevel == 1) || !(1 == systemActive)) || !(\old(pumpRunning) == 0)) || !(methaneLevelCritical == 0)) [2021-12-17 15:07:50,509 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: ((!(1 == systemActive) || !(1 <= methaneLevelCritical)) || !(\old(pumpRunning) == 0)) && (((!(waterLevel == 1) || !(1 == systemActive)) || !(\old(pumpRunning) == 0)) || !(methaneLevelCritical == 0)) [2021-12-17 15:07:50,509 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: ((((((!(waterLevel == 1) || !(1 == systemActive)) || 1 <= \result) || !(1 <= methaneLevelCritical)) || !(\old(pumpRunning) == 0)) && (((((1 <= \result && pumpRunning == \old(pumpRunning)) && pumpRunning == 0) || !(1 == systemActive)) || !(methaneLevelCritical == 0)) || ((\result == 0 && pumpRunning == \old(pumpRunning)) && pumpRunning == 0))) && (((!(waterLevel == 1) || 1 <= \result) || !(1 == systemActive)) || !(methaneLevelCritical == 0))) && ((((!(1 == systemActive) || !(1 <= methaneLevelCritical)) || (\result == 0 && pumpRunning == 0)) || !(\old(pumpRunning) == 0)) || (1 <= \result && pumpRunning == 0)) [2021-12-17 15:07:50,509 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (((!(1 == systemActive) || !(methaneLevelCritical == 0)) && ((!(1 <= methaneLevelCritical) || !(\old(pumpRunning) == 0)) || !(systemActive == 0))) && ((!(\old(pumpRunning) == 0) || !(methaneLevelCritical == 0)) || !(systemActive == 0))) && (!(1 == systemActive) || !(1 <= methaneLevelCritical)) [2021-12-17 15:07:50,510 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (((((pumpRunning == \old(pumpRunning) && pumpRunning == 0) || !(1 == systemActive)) || !(methaneLevelCritical == 0)) && (((!(1 == systemActive) || !(1 <= methaneLevelCritical)) || pumpRunning == \old(pumpRunning)) || !(\old(pumpRunning) == 0))) && ((((!(waterLevel == 1) || !(1 == systemActive)) || !(1 <= methaneLevelCritical)) || !(\old(pumpRunning) == 0)) || (((1 <= \result && 1 <= tmp) && tmp___0 == 0) && \result == 0))) && (((!(waterLevel == 1) || !(1 == systemActive)) || !(methaneLevelCritical == 0)) || (((1 <= \result && 1 <= tmp) && tmp___0 == 0) && \result == 0)) [2021-12-17 15:07:50,534 INFO L141 WitnessManager]: Wrote witness to /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/witness.graphml [2021-12-17 15:07:50,534 INFO L132 PluginConnector]: ------------------------ END Witness Printer---------------------------- [2021-12-17 15:07:50,535 INFO L158 Benchmark]: Toolchain (without parser) took 9501.14ms. Allocated memory was 88.1MB in the beginning and 167.8MB in the end (delta: 79.7MB). Free memory was 54.8MB in the beginning and 48.0MB in the end (delta: 6.9MB). Peak memory consumption was 87.2MB. Max. memory is 16.1GB. [2021-12-17 15:07:50,535 INFO L158 Benchmark]: CDTParser took 0.25ms. Allocated memory is still 88.1MB. Free memory is still 44.8MB. There was no memory consumed. Max. memory is 16.1GB. [2021-12-17 15:07:50,535 INFO L158 Benchmark]: CACSL2BoogieTranslator took 376.63ms. Allocated memory is still 88.1MB. Free memory was 54.5MB in the beginning and 56.2MB in the end (delta: -1.7MB). Peak memory consumption was 10.5MB. Max. memory is 16.1GB. [2021-12-17 15:07:50,536 INFO L158 Benchmark]: Boogie Procedure Inliner took 56.14ms. Allocated memory is still 88.1MB. Free memory was 56.2MB in the beginning and 53.7MB in the end (delta: 2.5MB). Peak memory consumption was 2.1MB. Max. memory is 16.1GB. [2021-12-17 15:07:50,536 INFO L158 Benchmark]: Boogie Preprocessor took 49.99ms. Allocated memory is still 88.1MB. Free memory was 53.7MB in the beginning and 51.9MB in the end (delta: 1.8MB). Peak memory consumption was 2.1MB. Max. memory is 16.1GB. [2021-12-17 15:07:50,536 INFO L158 Benchmark]: RCFGBuilder took 440.92ms. Allocated memory was 88.1MB in the beginning and 115.3MB in the end (delta: 27.3MB). Free memory was 51.9MB in the beginning and 92.0MB in the end (delta: -40.1MB). Peak memory consumption was 21.6MB. Max. memory is 16.1GB. [2021-12-17 15:07:50,537 INFO L158 Benchmark]: TraceAbstraction took 8507.11ms. Allocated memory was 115.3MB in the beginning and 167.8MB in the end (delta: 52.4MB). Free memory was 91.5MB in the beginning and 55.3MB in the end (delta: 36.1MB). Peak memory consumption was 100.2MB. Max. memory is 16.1GB. [2021-12-17 15:07:50,537 INFO L158 Benchmark]: Witness Printer took 64.96ms. Allocated memory is still 167.8MB. Free memory was 55.3MB in the beginning and 48.0MB in the end (delta: 7.3MB). Peak memory consumption was 8.4MB. Max. memory is 16.1GB. [2021-12-17 15:07:50,539 INFO L339 ainManager$Toolchain]: ####################### End [Toolchain 1] ####################### --- Results --- * Results from de.uni_freiburg.informatik.ultimate.core: - StatisticsResult: Toolchain Benchmarks Benchmark results are: * CDTParser took 0.25ms. Allocated memory is still 88.1MB. Free memory is still 44.8MB. There was no memory consumed. Max. memory is 16.1GB. * CACSL2BoogieTranslator took 376.63ms. Allocated memory is still 88.1MB. Free memory was 54.5MB in the beginning and 56.2MB in the end (delta: -1.7MB). Peak memory consumption was 10.5MB. Max. memory is 16.1GB. * Boogie Procedure Inliner took 56.14ms. Allocated memory is still 88.1MB. Free memory was 56.2MB in the beginning and 53.7MB in the end (delta: 2.5MB). Peak memory consumption was 2.1MB. Max. memory is 16.1GB. * Boogie Preprocessor took 49.99ms. Allocated memory is still 88.1MB. Free memory was 53.7MB in the beginning and 51.9MB in the end (delta: 1.8MB). Peak memory consumption was 2.1MB. Max. memory is 16.1GB. * RCFGBuilder took 440.92ms. Allocated memory was 88.1MB in the beginning and 115.3MB in the end (delta: 27.3MB). Free memory was 51.9MB in the beginning and 92.0MB in the end (delta: -40.1MB). Peak memory consumption was 21.6MB. Max. memory is 16.1GB. * TraceAbstraction took 8507.11ms. Allocated memory was 115.3MB in the beginning and 167.8MB in the end (delta: 52.4MB). Free memory was 91.5MB in the beginning and 55.3MB in the end (delta: 36.1MB). Peak memory consumption was 100.2MB. Max. memory is 16.1GB. * Witness Printer took 64.96ms. Allocated memory is still 167.8MB. Free memory was 55.3MB in the beginning and 48.0MB in the end (delta: 7.3MB). Peak memory consumption was 8.4MB. Max. memory is 16.1GB. * Results from de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction: - StatisticsResult: ErrorAutomatonStatistics NumberErrorTraces: 0, NumberStatementsAllTraces: 0, NumberRelevantStatements: 0, 0.0s ErrorAutomatonConstructionTimeTotal, 0.0s FaulLocalizationTime, NumberStatementsFirstTrace: -1, TraceLengthAvg: 0, 0.0s ErrorAutomatonConstructionTimeAvg, 0.0s ErrorAutomatonDifferenceTimeAvg, 0.0s ErrorAutomatonDifferenceTimeTotal, NumberOfNoEnhancement: 0, NumberOfFiniteEnhancement: 0, NumberOfInfiniteEnhancement: 0 - PositiveResult [Line: 54]: call to reach_error is unreachable For all program executions holds that call to reach_error is unreachable at this location - StatisticsResult: Ultimate Automizer benchmark data CFG has 10 procedures, 102 locations, 1 error locations. Started 1 CEGAR loops. OverallTime: 8.4s, OverallIterations: 11, TraceHistogramMax: 4, PathProgramHistogramMax: 1, EmptinessCheckTime: 0.0s, AutomataDifference: 2.4s, DeadEndRemovalTime: 0.0s, HoareAnnotationTime: 2.9s, InitialAbstractionConstructionTime: 0.0s, PartialOrderReductionTime: 0.0s, HoareTripleCheckerStatistics: 0 mSolverCounterUnknown, 1617 SdHoareTripleChecker+Valid, 1.5s IncrementalHoareTripleChecker+Time, 0 mSdLazyCounter, 1577 mSDsluCounter, 4232 SdHoareTripleChecker+Invalid, 1.2s Time, 0 mProtectedAction, 0 SdHoareTripleChecker+Unchecked, 0 IncrementalHoareTripleChecker+Unchecked, 2850 mSDsCounter, 532 IncrementalHoareTripleChecker+Valid, 0 mProtectedPredicate, 1868 IncrementalHoareTripleChecker+Invalid, 2400 SdHoareTripleChecker+Unknown, 0 mSolverCounterNotChecked, 532 mSolverCounterUnsat, 1382 mSDtfsCounter, 1868 mSolverCounterSat, 0.1s SdHoareTripleChecker+Time, 0 IncrementalHoareTripleChecker+Unknown, PredicateUnifierStatistics: 0 DeclaredPredicates, 377 GetRequests, 267 SyntacticMatches, 0 SemanticMatches, 110 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 190 ImplicationChecksByTransitivity, 0.8s Time, 0.0s BasicInterpolantAutomatonTime, BiggestAbstraction: size=962occurred in iteration=7, InterpolantAutomatonStates: 92, traceCheckStatistics: No data available, InterpolantConsolidationStatistics: No data available, PathInvariantsStatistics: No data available, 0/0 InterpolantCoveringCapability, TotalInterpolationStatistics: No data available, 0.0s DumpTime, AutomataMinimizationStatistics: 0.4s AutomataMinimizationTime, 11 MinimizatonAttempts, 348 StatesRemovedByMinimization, 8 NontrivialMinimizations, HoareAnnotationStatistics: 0.0s HoareAnnotationTime, 46 LocationsWithAnnotation, 2242 PreInvPairs, 2406 NumberOfFragments, 1873 HoareAnnotationTreeSize, 2242 FomulaSimplifications, 1612 FormulaSimplificationTreeSizeReduction, 0.4s HoareSimplificationTime, 46 FomulaSimplificationsInter, 8560 FormulaSimplificationTreeSizeReductionInter, 2.4s HoareSimplificationTimeInter, RefinementEngineStatistics: TRACE_CHECK: 0.1s SsaConstructionTime, 0.3s SatisfiabilityAnalysisTime, 1.7s InterpolantComputationTime, 768 NumberOfCodeBlocks, 768 NumberOfCodeBlocksAsserted, 13 NumberOfCheckSat, 755 ConstructedInterpolants, 0 QuantifiedInterpolants, 1411 SizeOfPredicates, 6 NumberOfNonLiveVariables, 887 ConjunctsInSsa, 18 ConjunctsInUnsatCore, 13 InterpolantComputations, 11 PerfectInterpolantSequences, 113/127 InterpolantCoveringCapability, INVARIANT_SYNTHESIS: No data available, INTERPOLANT_CONSOLIDATION: No data available, ABSTRACT_INTERPRETATION: No data available, PDR: No data available, ACCELERATED_INTERPOLATION: No data available, SIFA: No data available, ReuseStatistics: No data available - AllSpecificationsHoldResult: All specifications hold 1 specifications checked. All of them hold - InvariantResult [Line: 80]: Loop Invariant Derived loop invariant: ((waterLevel == 1 && methaneLevelCritical == 0) && systemActive == 1) && pumpRunning == 0 - InvariantResult [Line: 506]: Loop Invariant Derived loop invariant: 1 - InvariantResult [Line: 901]: Loop Invariant Derived loop invariant: (((splverifierCounter == 0 && systemActive == 0) && methaneLevelCritical == 0) && pumpRunning == 0) || (((splverifierCounter == 0 && systemActive == 0) && 1 <= methaneLevelCritical) && pumpRunning == 0) - InvariantResult [Line: 768]: Loop Invariant Derived loop invariant: ((((((!(1 <= methaneLevelCritical) || !(\old(pumpRunning) == 0)) || !(systemActive == 0)) && (((!(1 == systemActive) || waterLevel == \old(waterLevel)) || !(\old(pumpRunning) == 0)) || !(methaneLevelCritical == 0))) && (((!(1 == systemActive) || (waterLevel == \old(waterLevel) && methAndRunningLastTime == \old(methAndRunningLastTime))) || !(1 <= methaneLevelCritical)) || !(\old(pumpRunning) == 0))) && ((!(\old(pumpRunning) == 0) || !(methaneLevelCritical == 0)) || !(systemActive == 0))) && ((((!(\old(waterLevel) == 1) || !(1 == systemActive)) || !(\old(pumpRunning) == 0)) || !(methaneLevelCritical == 0)) || (methAndRunningLastTime == \old(methAndRunningLastTime) && pumpRunning == 0))) && ((!(1 == systemActive) || !(1 <= methaneLevelCritical)) || pumpRunning == 0) - InvariantResult [Line: 516]: Loop Invariant Derived loop invariant: 1 - InvariantResult [Line: 837]: Loop Invariant Derived loop invariant: ((((((\result == 0 && pumpRunning == 0) || !(1 == systemActive)) || !(1 <= methaneLevelCritical)) && (!(1 == systemActive) || !(methaneLevelCritical == 0))) && (((!(1 == systemActive) || (waterLevel == \old(waterLevel) && methAndRunningLastTime == \old(methAndRunningLastTime))) || !(1 <= methaneLevelCritical)) || !(\old(pumpRunning) == 0))) && ((!(\old(pumpRunning) == 0) || !(methaneLevelCritical == 0)) || !(systemActive == 0))) && ((((((\result == 0 && methAndRunningLastTime == \old(methAndRunningLastTime)) && waterLevel == \old(waterLevel)) && pumpRunning == 0) || !(1 <= methaneLevelCritical)) || !(\old(pumpRunning) == 0)) || !(systemActive == 0)) - InvariantResult [Line: 474]: Loop Invariant Derived loop invariant: (((((((!(1 == systemActive) || tmp == 0) || !(methaneLevelCritical == 0)) && (((!(1 == systemActive) || waterLevel == \old(waterLevel)) || !(\old(pumpRunning) == 0)) || !(methaneLevelCritical == 0))) && (((!(\old(pumpRunning) == 0) || ((tmp == 0 && waterLevel == \old(waterLevel)) && pumpRunning == 0)) || !(methaneLevelCritical == 0)) || !(systemActive == 0))) && ((!(1 == systemActive) || !(1 <= methaneLevelCritical)) || pumpRunning == 0)) && ((((waterLevel == \old(waterLevel) && pumpRunning == \old(pumpRunning)) || !(1 <= methaneLevelCritical)) || !(\old(pumpRunning) == 0)) || !(systemActive == 0))) && (((!(1 == systemActive) || !(1 <= methaneLevelCritical)) || waterLevel == \old(waterLevel)) || !(\old(pumpRunning) == 0))) && ((((!(\old(waterLevel) == 1) || !(1 == systemActive)) || !(\old(pumpRunning) == 0)) || !(methaneLevelCritical == 0)) || pumpRunning == 0) - InvariantResult [Line: 793]: Loop Invariant Derived loop invariant: ((!(1 == systemActive) || !(1 <= methaneLevelCritical)) || !(\old(pumpRunning) == 0)) && (((!(waterLevel == 1) || !(1 == systemActive)) || !(\old(pumpRunning) == 0)) || !(methaneLevelCritical == 0)) - InvariantResult [Line: 582]: Loop Invariant Derived loop invariant: 1 - InvariantResult [Line: 73]: Loop Invariant Derived loop invariant: ((waterLevel == 1 && methaneLevelCritical == 0) && systemActive == 1) && pumpRunning == 0 - InvariantResult [Line: 466]: Loop Invariant Derived loop invariant: ((waterLevel == 1 && methaneLevelCritical == 0) && systemActive == 1) && pumpRunning == 0 - InvariantResult [Line: 917]: Loop Invariant Derived loop invariant: 1 - InvariantResult [Line: 87]: Loop Invariant Derived loop invariant: ((waterLevel == 1 && methaneLevelCritical == 0) && systemActive == 1) && pumpRunning == 0 - InvariantResult [Line: 571]: Loop Invariant Derived loop invariant: 1 - InvariantResult [Line: 926]: Loop Invariant Derived loop invariant: 0 - InvariantResult [Line: 689]: Loop Invariant Derived loop invariant: ((((((!(waterLevel == 1) || !(1 == systemActive)) || 1 <= \result) || !(1 <= methaneLevelCritical)) || !(\old(pumpRunning) == 0)) && (((((1 <= \result && pumpRunning == \old(pumpRunning)) && pumpRunning == 0) || !(1 == systemActive)) || !(methaneLevelCritical == 0)) || ((\result == 0 && pumpRunning == \old(pumpRunning)) && pumpRunning == 0))) && (((!(waterLevel == 1) || 1 <= \result) || !(1 == systemActive)) || !(methaneLevelCritical == 0))) && ((((!(1 == systemActive) || !(1 <= methaneLevelCritical)) || (\result == 0 && pumpRunning == 0)) || !(\old(pumpRunning) == 0)) || (1 <= \result && pumpRunning == 0)) - InvariantResult [Line: 882]: Loop Invariant Derived loop invariant: (((((pumpRunning == \old(pumpRunning) && pumpRunning == 0) || !(1 == systemActive)) || !(methaneLevelCritical == 0)) && (((!(1 == systemActive) || !(1 <= methaneLevelCritical)) || pumpRunning == \old(pumpRunning)) || !(\old(pumpRunning) == 0))) && ((((!(waterLevel == 1) || !(1 == systemActive)) || !(1 <= methaneLevelCritical)) || !(\old(pumpRunning) == 0)) || (((1 <= \result && 1 <= tmp) && tmp___0 == 0) && \result == 0))) && (((!(waterLevel == 1) || !(1 == systemActive)) || !(methaneLevelCritical == 0)) || (((1 <= \result && 1 <= tmp) && tmp___0 == 0) && \result == 0)) - InvariantResult [Line: 563]: Loop Invariant Derived loop invariant: ((waterLevel == 1 && methaneLevelCritical == 0) && systemActive == 1) && pumpRunning == 0 - InvariantResult [Line: 50]: Loop Invariant Derived loop invariant: (((!(1 == systemActive) || !(methaneLevelCritical == 0)) && ((!(1 <= methaneLevelCritical) || !(\old(pumpRunning) == 0)) || !(systemActive == 0))) && ((!(\old(pumpRunning) == 0) || !(methaneLevelCritical == 0)) || !(systemActive == 0))) && (!(1 == systemActive) || !(1 <= methaneLevelCritical)) - InvariantResult [Line: 801]: Loop Invariant Derived loop invariant: ((((!(waterLevel == 1) || !(1 == systemActive)) || !(1 <= methaneLevelCritical)) || !(\old(pumpRunning) == 0)) && ((((methaneLevelCritical <= tmp && pumpRunning == \old(pumpRunning)) || !(1 == systemActive)) || !(1 <= methaneLevelCritical)) || !(\old(pumpRunning) == 0))) && (((!(waterLevel == 1) || !(1 == systemActive)) || !(\old(pumpRunning) == 0)) || !(methaneLevelCritical == 0)) - InvariantResult [Line: 612]: Loop Invariant Derived loop invariant: ((((((!(1 == systemActive) || !(\old(pumpRunning) == 0)) || !(methaneLevelCritical == 0)) && ((!(1 == systemActive) || !(1 <= methaneLevelCritical)) || !(\old(pumpRunning) == 0))) && ((!(1 <= methaneLevelCritical) || !(\old(pumpRunning) == 0)) || !(systemActive == 0))) && ((!(\old(pumpRunning) == 0) || !(methaneLevelCritical == 0)) || !(systemActive == 0))) && ((!(1 == systemActive) || pumpRunning == \old(pumpRunning)) || !(methaneLevelCritical == 0))) && ((!(1 == systemActive) || !(1 <= methaneLevelCritical)) || pumpRunning == \old(pumpRunning)) - InvariantResult [Line: 927]: Loop Invariant Derived loop invariant: (((((splverifierCounter == 0 && 1 <= methaneLevelCritical) && systemActive == 1) && pumpRunning == 0) || ((splverifierCounter == 0 && methaneLevelCritical == 0) && systemActive == 1)) || (((splverifierCounter == 0 && systemActive == 0) && methaneLevelCritical == 0) && pumpRunning == 0)) || (((splverifierCounter == 0 && systemActive == 0) && 1 <= methaneLevelCritical) && pumpRunning == 0) RESULT: Ultimate proved your program to be correct! [2021-12-17 15:07:50,582 INFO L552 MonitoredProcess]: [MP /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in -t:2000 (1)] Ended with exit code 0 Received shutdown request... --- End real Ultimate output --- Execution finished normally Writing output log to file Ultimate.log Result: TRUE