./Ultimate.py --spec ../sv-benchmarks/c/properties/unreach-call.prp --file ../sv-benchmarks/c/product-lines/minepump_spec2_product50.cil.c --full-output --architecture 32bit -------------------------------------------------------------------------------- Checking for ERROR reachability Using default analysis Version c3fed411 Calling Ultimate with: /usr/bin/java -Dosgi.configuration.area=/storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/data/config -Xmx15G -Xms4m -jar /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/plugins/org.eclipse.equinox.launcher_1.5.800.v20200727-1323.jar -data @noDefault -ultimatedata /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/data -tc /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/config/AutomizerReach.xml -i ../sv-benchmarks/c/product-lines/minepump_spec2_product50.cil.c -s /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/config/svcomp-Reach-32bit-Automizer_Default.epf --cacsl2boogietranslator.entry.function main --witnessprinter.witness.directory /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux --witnessprinter.witness.filename witness.graphml --witnessprinter.write.witness.besides.input.file false --witnessprinter.graph.data.specification CHECK( init(main()), LTL(G ! call(reach_error())) ) --witnessprinter.graph.data.producer Automizer --witnessprinter.graph.data.architecture 32bit --witnessprinter.graph.data.programhash f645b80d4169704e02b3c19c65a00755e1e28cc942f5a2526cd4b4e1dcca30cf --- Real Ultimate output --- This is Ultimate 0.2.2-tmp.no-commuhash-c3fed41 [2021-12-17 15:07:41,185 INFO L177 SettingsManager]: Resetting all preferences to default values... [2021-12-17 15:07:41,186 INFO L181 SettingsManager]: Resetting UltimateCore preferences to default values [2021-12-17 15:07:41,206 INFO L184 SettingsManager]: Ultimate Commandline Interface provides no preferences, ignoring... [2021-12-17 15:07:41,206 INFO L181 SettingsManager]: Resetting Boogie Preprocessor preferences to default values [2021-12-17 15:07:41,207 INFO L181 SettingsManager]: Resetting Boogie Procedure Inliner preferences to default values [2021-12-17 15:07:41,208 INFO L181 SettingsManager]: Resetting Abstract Interpretation preferences to default values [2021-12-17 15:07:41,209 INFO L181 SettingsManager]: Resetting LassoRanker preferences to default values [2021-12-17 15:07:41,210 INFO L181 SettingsManager]: Resetting Reaching Definitions preferences to default values [2021-12-17 15:07:41,215 INFO L181 SettingsManager]: Resetting SyntaxChecker preferences to default values [2021-12-17 15:07:41,215 INFO L181 SettingsManager]: Resetting Sifa preferences to default values [2021-12-17 15:07:41,216 INFO L184 SettingsManager]: Büchi Program Product provides no preferences, ignoring... [2021-12-17 15:07:41,217 INFO L181 SettingsManager]: Resetting LTL2Aut preferences to default values [2021-12-17 15:07:41,219 INFO L181 SettingsManager]: Resetting PEA to Boogie preferences to default values [2021-12-17 15:07:41,220 INFO L181 SettingsManager]: Resetting BlockEncodingV2 preferences to default values [2021-12-17 15:07:41,222 INFO L181 SettingsManager]: Resetting ChcToBoogie preferences to default values [2021-12-17 15:07:41,224 INFO L181 SettingsManager]: Resetting AutomataScriptInterpreter preferences to default values [2021-12-17 15:07:41,225 INFO L181 SettingsManager]: Resetting BuchiAutomizer preferences to default values [2021-12-17 15:07:41,226 INFO L181 SettingsManager]: Resetting CACSL2BoogieTranslator preferences to default values [2021-12-17 15:07:41,228 INFO L181 SettingsManager]: Resetting CodeCheck preferences to default values [2021-12-17 15:07:41,232 INFO L181 SettingsManager]: Resetting InvariantSynthesis preferences to default values [2021-12-17 15:07:41,232 INFO L181 SettingsManager]: Resetting RCFGBuilder preferences to default values [2021-12-17 15:07:41,233 INFO L181 SettingsManager]: Resetting Referee preferences to default values [2021-12-17 15:07:41,234 INFO L181 SettingsManager]: Resetting TraceAbstraction preferences to default values [2021-12-17 15:07:41,236 INFO L184 SettingsManager]: TraceAbstractionConcurrent provides no preferences, ignoring... [2021-12-17 15:07:41,238 INFO L184 SettingsManager]: TraceAbstractionWithAFAs provides no preferences, ignoring... [2021-12-17 15:07:41,238 INFO L181 SettingsManager]: Resetting TreeAutomizer preferences to default values [2021-12-17 15:07:41,239 INFO L181 SettingsManager]: Resetting IcfgToChc preferences to default values [2021-12-17 15:07:41,240 INFO L181 SettingsManager]: Resetting IcfgTransformer preferences to default values [2021-12-17 15:07:41,240 INFO L184 SettingsManager]: ReqToTest provides no preferences, ignoring... [2021-12-17 15:07:41,241 INFO L181 SettingsManager]: Resetting Boogie Printer preferences to default values [2021-12-17 15:07:41,241 INFO L181 SettingsManager]: Resetting ChcSmtPrinter preferences to default values [2021-12-17 15:07:41,242 INFO L181 SettingsManager]: Resetting ReqPrinter preferences to default values [2021-12-17 15:07:41,243 INFO L181 SettingsManager]: Resetting Witness Printer preferences to default values [2021-12-17 15:07:41,244 INFO L184 SettingsManager]: Boogie PL CUP Parser provides no preferences, ignoring... [2021-12-17 15:07:41,244 INFO L181 SettingsManager]: Resetting CDTParser preferences to default values [2021-12-17 15:07:41,245 INFO L184 SettingsManager]: AutomataScriptParser provides no preferences, ignoring... [2021-12-17 15:07:41,245 INFO L184 SettingsManager]: ReqParser provides no preferences, ignoring... [2021-12-17 15:07:41,245 INFO L181 SettingsManager]: Resetting SmtParser preferences to default values [2021-12-17 15:07:41,246 INFO L181 SettingsManager]: Resetting Witness Parser preferences to default values [2021-12-17 15:07:41,246 INFO L188 SettingsManager]: Finished resetting all preferences to default values... [2021-12-17 15:07:41,247 INFO L101 SettingsManager]: Beginning loading settings from /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/config/svcomp-Reach-32bit-Automizer_Default.epf [2021-12-17 15:07:41,268 INFO L113 SettingsManager]: Loading preferences was successful [2021-12-17 15:07:41,268 INFO L115 SettingsManager]: Preferences different from defaults after loading the file: [2021-12-17 15:07:41,269 INFO L136 SettingsManager]: Preferences of UltimateCore differ from their defaults: [2021-12-17 15:07:41,269 INFO L138 SettingsManager]: * Log level for class=de.uni_freiburg.informatik.ultimate.lib.smtlibutils.quantifier.QuantifierPusher=ERROR; [2021-12-17 15:07:41,269 INFO L136 SettingsManager]: Preferences of Boogie Procedure Inliner differ from their defaults: [2021-12-17 15:07:41,270 INFO L138 SettingsManager]: * Ignore calls to procedures called more than once=ONLY_FOR_SEQUENTIAL_PROGRAMS [2021-12-17 15:07:41,270 INFO L136 SettingsManager]: Preferences of BlockEncodingV2 differ from their defaults: [2021-12-17 15:07:41,270 INFO L138 SettingsManager]: * Create parallel compositions if possible=false [2021-12-17 15:07:41,270 INFO L138 SettingsManager]: * Use SBE=true [2021-12-17 15:07:41,270 INFO L136 SettingsManager]: Preferences of CACSL2BoogieTranslator differ from their defaults: [2021-12-17 15:07:41,271 INFO L138 SettingsManager]: * sizeof long=4 [2021-12-17 15:07:41,271 INFO L138 SettingsManager]: * Overapproximate operations on floating types=true [2021-12-17 15:07:41,271 INFO L138 SettingsManager]: * sizeof POINTER=4 [2021-12-17 15:07:41,271 INFO L138 SettingsManager]: * Check division by zero=IGNORE [2021-12-17 15:07:41,272 INFO L138 SettingsManager]: * Pointer to allocated memory at dereference=IGNORE [2021-12-17 15:07:41,272 INFO L138 SettingsManager]: * If two pointers are subtracted or compared they have the same base address=IGNORE [2021-12-17 15:07:41,272 INFO L138 SettingsManager]: * Check array bounds for arrays that are off heap=IGNORE [2021-12-17 15:07:41,272 INFO L138 SettingsManager]: * sizeof long double=12 [2021-12-17 15:07:41,272 INFO L138 SettingsManager]: * Check if freed pointer was valid=false [2021-12-17 15:07:41,272 INFO L138 SettingsManager]: * Use constant arrays=true [2021-12-17 15:07:41,272 INFO L138 SettingsManager]: * Pointer base address is valid at dereference=IGNORE [2021-12-17 15:07:41,273 INFO L136 SettingsManager]: Preferences of RCFGBuilder differ from their defaults: [2021-12-17 15:07:41,273 INFO L138 SettingsManager]: * Size of a code block=SequenceOfStatements [2021-12-17 15:07:41,273 INFO L138 SettingsManager]: * SMT solver=External_DefaultMode [2021-12-17 15:07:41,273 INFO L138 SettingsManager]: * Command for external solver=z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in -t:2000 [2021-12-17 15:07:41,273 INFO L136 SettingsManager]: Preferences of TraceAbstraction differ from their defaults: [2021-12-17 15:07:41,273 INFO L138 SettingsManager]: * Compute Interpolants along a Counterexample=FPandBP [2021-12-17 15:07:41,273 INFO L138 SettingsManager]: * Positions where we compute the Hoare Annotation=LoopsAndPotentialCycles [2021-12-17 15:07:41,274 INFO L138 SettingsManager]: * Trace refinement strategy=CAMEL [2021-12-17 15:07:41,274 INFO L138 SettingsManager]: * Command for external solver=z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in [2021-12-17 15:07:41,274 INFO L138 SettingsManager]: * Large block encoding in concurrent analysis=OFF [2021-12-17 15:07:41,274 INFO L138 SettingsManager]: * Automaton type used in concurrency analysis=PETRI_NET [2021-12-17 15:07:41,274 INFO L138 SettingsManager]: * Compute Hoare Annotation of negated interpolant automaton, abstraction and CFG=true [2021-12-17 15:07:41,274 INFO L138 SettingsManager]: * Trace refinement exception blacklist=NONE [2021-12-17 15:07:41,275 INFO L138 SettingsManager]: * SMT solver=External_ModelsAndUnsatCoreMode WARNING: An illegal reflective access operation has occurred WARNING: Illegal reflective access by com.sun.xml.bind.v2.runtime.reflect.opt.Injector$1 (file:/storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/plugins/com.sun.xml.bind_2.2.0.v201505121915.jar) to method java.lang.ClassLoader.defineClass(java.lang.String,byte[],int,int) WARNING: Please consider reporting this to the maintainers of com.sun.xml.bind.v2.runtime.reflect.opt.Injector$1 WARNING: Use --illegal-access=warn to enable warnings of further illegal reflective access operations WARNING: All illegal access operations will be denied in a future release Applying setting for plugin de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator: Entry function -> main Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Witness directory -> /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Witness filename -> witness.graphml Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Write witness besides input file -> false Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Graph data specification -> CHECK( init(main()), LTL(G ! call(reach_error())) ) Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Graph data producer -> Automizer Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Graph data architecture -> 32bit Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Graph data programhash -> f645b80d4169704e02b3c19c65a00755e1e28cc942f5a2526cd4b4e1dcca30cf [2021-12-17 15:07:41,480 INFO L75 nceAwareModelManager]: Repository-Root is: /tmp [2021-12-17 15:07:41,503 INFO L261 ainManager$Toolchain]: [Toolchain 1]: Applicable parser(s) successfully (re)initialized [2021-12-17 15:07:41,513 INFO L217 ainManager$Toolchain]: [Toolchain 1]: Toolchain selected. [2021-12-17 15:07:41,514 INFO L271 PluginConnector]: Initializing CDTParser... [2021-12-17 15:07:41,515 INFO L275 PluginConnector]: CDTParser initialized [2021-12-17 15:07:41,517 INFO L432 ainManager$Toolchain]: [Toolchain 1]: Parsing single file: /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/../sv-benchmarks/c/product-lines/minepump_spec2_product50.cil.c [2021-12-17 15:07:41,575 INFO L220 CDTParser]: Created temporary CDT project at /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/data/c8bf64aff/c244c2d13f2840cf827aafd4d54e8e6c/FLAGbb988d2df [2021-12-17 15:07:41,973 INFO L306 CDTParser]: Found 1 translation units. [2021-12-17 15:07:41,973 INFO L160 CDTParser]: Scanning /storage/repos/ultimate/releaseScripts/default/sv-benchmarks/c/product-lines/minepump_spec2_product50.cil.c [2021-12-17 15:07:41,984 INFO L349 CDTParser]: About to delete temporary CDT project at /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/data/c8bf64aff/c244c2d13f2840cf827aafd4d54e8e6c/FLAGbb988d2df [2021-12-17 15:07:42,366 INFO L357 CDTParser]: Successfully deleted /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/data/c8bf64aff/c244c2d13f2840cf827aafd4d54e8e6c [2021-12-17 15:07:42,368 INFO L299 ainManager$Toolchain]: ####################### [Toolchain 1] ####################### [2021-12-17 15:07:42,369 INFO L131 ToolchainWalker]: Walking toolchain with 6 elements. [2021-12-17 15:07:42,370 INFO L113 PluginConnector]: ------------------------CACSL2BoogieTranslator---------------------------- [2021-12-17 15:07:42,370 INFO L271 PluginConnector]: Initializing CACSL2BoogieTranslator... [2021-12-17 15:07:42,372 INFO L275 PluginConnector]: CACSL2BoogieTranslator initialized [2021-12-17 15:07:42,372 INFO L185 PluginConnector]: Executing the observer ACSLObjectContainerObserver from plugin CACSL2BoogieTranslator for "CDTParser AST 17.12 03:07:42" (1/1) ... [2021-12-17 15:07:42,373 INFO L205 PluginConnector]: Invalid model from CACSL2BoogieTranslator for observer de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator.ACSLObjectContainerObserver@75ebdd3 and model type de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 17.12 03:07:42, skipping insertion in model container [2021-12-17 15:07:42,373 INFO L185 PluginConnector]: Executing the observer CACSL2BoogieTranslatorObserver from plugin CACSL2BoogieTranslator for "CDTParser AST 17.12 03:07:42" (1/1) ... [2021-12-17 15:07:42,377 INFO L145 MainTranslator]: Starting translation in SV-COMP mode [2021-12-17 15:07:42,399 INFO L178 MainTranslator]: Built tables and reachable declarations [2021-12-17 15:07:42,648 WARN L230 ndardFunctionHandler]: Function reach_error is already implemented but we override the implementation for the call at /storage/repos/ultimate/releaseScripts/default/sv-benchmarks/c/product-lines/minepump_spec2_product50.cil.c[18939,18952] [2021-12-17 15:07:42,653 INFO L209 PostProcessor]: Analyzing one entry point: main [2021-12-17 15:07:42,662 INFO L203 MainTranslator]: Completed pre-run [2021-12-17 15:07:42,722 WARN L230 ndardFunctionHandler]: Function reach_error is already implemented but we override the implementation for the call at /storage/repos/ultimate/releaseScripts/default/sv-benchmarks/c/product-lines/minepump_spec2_product50.cil.c[18939,18952] [2021-12-17 15:07:42,727 INFO L209 PostProcessor]: Analyzing one entry point: main [2021-12-17 15:07:42,740 INFO L208 MainTranslator]: Completed translation [2021-12-17 15:07:42,740 INFO L202 PluginConnector]: Adding new model de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 17.12 03:07:42 WrapperNode [2021-12-17 15:07:42,740 INFO L132 PluginConnector]: ------------------------ END CACSL2BoogieTranslator---------------------------- [2021-12-17 15:07:42,741 INFO L113 PluginConnector]: ------------------------Boogie Procedure Inliner---------------------------- [2021-12-17 15:07:42,741 INFO L271 PluginConnector]: Initializing Boogie Procedure Inliner... [2021-12-17 15:07:42,741 INFO L275 PluginConnector]: Boogie Procedure Inliner initialized [2021-12-17 15:07:42,746 INFO L185 PluginConnector]: Executing the observer TypeChecker from plugin Boogie Procedure Inliner for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 17.12 03:07:42" (1/1) ... [2021-12-17 15:07:42,767 INFO L185 PluginConnector]: Executing the observer Inliner from plugin Boogie Procedure Inliner for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 17.12 03:07:42" (1/1) ... [2021-12-17 15:07:42,799 INFO L137 Inliner]: procedures = 57, calls = 156, calls flagged for inlining = 24, calls inlined = 21, statements flattened = 262 [2021-12-17 15:07:42,800 INFO L132 PluginConnector]: ------------------------ END Boogie Procedure Inliner---------------------------- [2021-12-17 15:07:42,801 INFO L113 PluginConnector]: ------------------------Boogie Preprocessor---------------------------- [2021-12-17 15:07:42,801 INFO L271 PluginConnector]: Initializing Boogie Preprocessor... [2021-12-17 15:07:42,801 INFO L275 PluginConnector]: Boogie Preprocessor initialized [2021-12-17 15:07:42,807 INFO L185 PluginConnector]: Executing the observer EnsureBoogieModelObserver from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 17.12 03:07:42" (1/1) ... [2021-12-17 15:07:42,807 INFO L185 PluginConnector]: Executing the observer TypeChecker from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 17.12 03:07:42" (1/1) ... [2021-12-17 15:07:42,813 INFO L185 PluginConnector]: Executing the observer ConstExpander from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 17.12 03:07:42" (1/1) ... [2021-12-17 15:07:42,814 INFO L185 PluginConnector]: Executing the observer StructExpander from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 17.12 03:07:42" (1/1) ... [2021-12-17 15:07:42,824 INFO L185 PluginConnector]: Executing the observer UnstructureCode from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 17.12 03:07:42" (1/1) ... [2021-12-17 15:07:42,834 INFO L185 PluginConnector]: Executing the observer FunctionInliner from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 17.12 03:07:42" (1/1) ... [2021-12-17 15:07:42,836 INFO L185 PluginConnector]: Executing the observer BoogieSymbolTableConstructor from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 17.12 03:07:42" (1/1) ... [2021-12-17 15:07:42,840 INFO L132 PluginConnector]: ------------------------ END Boogie Preprocessor---------------------------- [2021-12-17 15:07:42,841 INFO L113 PluginConnector]: ------------------------RCFGBuilder---------------------------- [2021-12-17 15:07:42,841 INFO L271 PluginConnector]: Initializing RCFGBuilder... [2021-12-17 15:07:42,842 INFO L275 PluginConnector]: RCFGBuilder initialized [2021-12-17 15:07:42,843 INFO L185 PluginConnector]: Executing the observer RCFGBuilderObserver from plugin RCFGBuilder for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 17.12 03:07:42" (1/1) ... [2021-12-17 15:07:42,848 INFO L168 SolverBuilder]: Constructing external solver with command: z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in -t:2000 [2021-12-17 15:07:42,855 INFO L189 MonitoredProcess]: No working directory specified, using /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 [2021-12-17 15:07:42,865 INFO L229 MonitoredProcess]: Starting monitored process 1 with /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in -t:2000 (exit command is (exit), workingDir is null) [2021-12-17 15:07:42,871 INFO L327 MonitoredProcess]: [MP /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in -t:2000 (1)] Waiting until timeout for monitored process [2021-12-17 15:07:42,889 INFO L130 BoogieDeclarations]: Found specification of procedure #Ultimate.allocInit [2021-12-17 15:07:42,890 INFO L130 BoogieDeclarations]: Found specification of procedure processEnvironment__wrappee__base [2021-12-17 15:07:42,890 INFO L138 BoogieDeclarations]: Found implementation of procedure processEnvironment__wrappee__base [2021-12-17 15:07:42,890 INFO L130 BoogieDeclarations]: Found specification of procedure isMethaneLevelCritical [2021-12-17 15:07:42,890 INFO L138 BoogieDeclarations]: Found implementation of procedure isMethaneLevelCritical [2021-12-17 15:07:42,890 INFO L130 BoogieDeclarations]: Found specification of procedure timeShift [2021-12-17 15:07:42,890 INFO L138 BoogieDeclarations]: Found implementation of procedure timeShift [2021-12-17 15:07:42,890 INFO L130 BoogieDeclarations]: Found specification of procedure cleanup [2021-12-17 15:07:42,891 INFO L138 BoogieDeclarations]: Found implementation of procedure cleanup [2021-12-17 15:07:42,891 INFO L130 BoogieDeclarations]: Found specification of procedure processEnvironment__wrappee__highWaterSensor [2021-12-17 15:07:42,891 INFO L138 BoogieDeclarations]: Found implementation of procedure processEnvironment__wrappee__highWaterSensor [2021-12-17 15:07:42,891 INFO L130 BoogieDeclarations]: Found specification of procedure waterRise [2021-12-17 15:07:42,891 INFO L138 BoogieDeclarations]: Found implementation of procedure waterRise [2021-12-17 15:07:42,891 INFO L130 BoogieDeclarations]: Found specification of procedure write~init~int [2021-12-17 15:07:42,891 INFO L130 BoogieDeclarations]: Found specification of procedure changeMethaneLevel [2021-12-17 15:07:42,891 INFO L138 BoogieDeclarations]: Found implementation of procedure changeMethaneLevel [2021-12-17 15:07:42,892 INFO L130 BoogieDeclarations]: Found specification of procedure ULTIMATE.start [2021-12-17 15:07:42,892 INFO L138 BoogieDeclarations]: Found implementation of procedure ULTIMATE.start [2021-12-17 15:07:42,938 INFO L236 CfgBuilder]: Building ICFG [2021-12-17 15:07:42,939 INFO L262 CfgBuilder]: Building CFG for each procedure with an implementation [2021-12-17 15:07:43,120 INFO L277 CfgBuilder]: Performing block encoding [2021-12-17 15:07:43,125 INFO L296 CfgBuilder]: Using the 1 location(s) as analysis (start of procedure ULTIMATE.start) [2021-12-17 15:07:43,126 INFO L301 CfgBuilder]: Removed 2 assume(true) statements. [2021-12-17 15:07:43,127 INFO L202 PluginConnector]: Adding new model de.uni_freiburg.informatik.ultimate.plugins.generator.rcfgbuilder CFG 17.12 03:07:43 BoogieIcfgContainer [2021-12-17 15:07:43,127 INFO L132 PluginConnector]: ------------------------ END RCFGBuilder---------------------------- [2021-12-17 15:07:43,128 INFO L113 PluginConnector]: ------------------------TraceAbstraction---------------------------- [2021-12-17 15:07:43,128 INFO L271 PluginConnector]: Initializing TraceAbstraction... [2021-12-17 15:07:43,131 INFO L275 PluginConnector]: TraceAbstraction initialized [2021-12-17 15:07:43,131 INFO L185 PluginConnector]: Executing the observer TraceAbstractionObserver from plugin TraceAbstraction for "CDTParser AST 17.12 03:07:42" (1/3) ... [2021-12-17 15:07:43,131 INFO L205 PluginConnector]: Invalid model from TraceAbstraction for observer de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction.TraceAbstractionObserver@a476c9 and model type de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction AST 17.12 03:07:43, skipping insertion in model container [2021-12-17 15:07:43,132 INFO L185 PluginConnector]: Executing the observer TraceAbstractionObserver from plugin TraceAbstraction for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 17.12 03:07:42" (2/3) ... [2021-12-17 15:07:43,132 INFO L205 PluginConnector]: Invalid model from TraceAbstraction for observer de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction.TraceAbstractionObserver@a476c9 and model type de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction AST 17.12 03:07:43, skipping insertion in model container [2021-12-17 15:07:43,132 INFO L185 PluginConnector]: Executing the observer TraceAbstractionObserver from plugin TraceAbstraction for "de.uni_freiburg.informatik.ultimate.plugins.generator.rcfgbuilder CFG 17.12 03:07:43" (3/3) ... [2021-12-17 15:07:43,133 INFO L111 eAbstractionObserver]: Analyzing ICFG minepump_spec2_product50.cil.c [2021-12-17 15:07:43,136 INFO L204 ceAbstractionStarter]: Automizer settings: Hoare:true NWA Interpolation:FPandBP Determinization: PREDICATE_ABSTRACTION [2021-12-17 15:07:43,136 INFO L163 ceAbstractionStarter]: Applying trace abstraction to program that has 1 error locations. [2021-12-17 15:07:43,166 INFO L338 AbstractCegarLoop]: ======== Iteration 0 == of CEGAR loop == AllErrorsAtOnce ======== [2021-12-17 15:07:43,171 INFO L339 AbstractCegarLoop]: Settings: SEPARATE_VIOLATION_CHECK=true, mInterprocedural=true, mMaxIterations=1000000, mWatchIteration=1000000, mArtifact=RCFG, mInterpolation=FPandBP, mInterpolantAutomaton=STRAIGHT_LINE, mDumpAutomata=false, mAutomataFormat=ATS_NUMERATE, mDumpPath=., mDeterminiation=PREDICATE_ABSTRACTION, mMinimize=MINIMIZE_SEVPA, mHoare=true, mAutomataTypeConcurrency=PETRI_NET, mHoareTripleChecks=INCREMENTAL, mHoareAnnotationPositions=LoopsAndPotentialCycles, mDumpOnlyReuseAutomata=false, mLimitTraceHistogram=0, mErrorLocTimeLimit=0, mLimitPathProgramCount=0, mCollectInterpolantStatistics=true, mHeuristicEmptinessCheck=false, mHeuristicEmptinessCheckAStarHeuristic=ZERO, mHeuristicEmptinessCheckAStarHeuristicRandomSeed=1337, mHeuristicEmptinessCheckSmtFeatureScoringMethod=DAGSIZE, mSMTFeatureExtraction=false, mSMTFeatureExtractionDumpPath=., mOverrideInterpolantAutomaton=false, mMcrInterpolantMethod=WP, mLoopAccelerationTechnique=FAST_UPR [2021-12-17 15:07:43,171 INFO L340 AbstractCegarLoop]: Starting to check reachability of 1 error locations. [2021-12-17 15:07:43,183 INFO L276 IsEmpty]: Start isEmpty. Operand has 89 states, 69 states have (on average 1.391304347826087) internal successors, (96), 77 states have internal predecessors, (96), 11 states have call successors, (11), 7 states have call predecessors, (11), 7 states have return successors, (11), 9 states have call predecessors, (11), 11 states have call successors, (11) [2021-12-17 15:07:43,188 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 26 [2021-12-17 15:07:43,189 INFO L506 BasicCegarLoop]: Found error trace [2021-12-17 15:07:43,189 INFO L514 BasicCegarLoop]: trace histogram [1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2021-12-17 15:07:43,189 INFO L402 AbstractCegarLoop]: === Iteration 1 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2021-12-17 15:07:43,193 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2021-12-17 15:07:43,193 INFO L85 PathProgramCache]: Analyzing trace with hash 778842968, now seen corresponding path program 1 times [2021-12-17 15:07:43,199 INFO L121 FreeRefinementEngine]: Executing refinement strategy CAMEL [2021-12-17 15:07:43,199 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [984851387] [2021-12-17 15:07:43,199 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2021-12-17 15:07:43,200 INFO L126 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2021-12-17 15:07:43,272 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:07:43,331 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 15 [2021-12-17 15:07:43,334 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:07:43,337 INFO L134 CoverageAnalysis]: Checked inductivity of 0 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2021-12-17 15:07:43,337 INFO L139 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2021-12-17 15:07:43,338 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [984851387] [2021-12-17 15:07:43,338 INFO L160 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [984851387] provided 1 perfect and 0 imperfect interpolant sequences [2021-12-17 15:07:43,338 INFO L186 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2021-12-17 15:07:43,338 INFO L199 FreeRefinementEngine]: Number of different interpolants: perfect sequences [2] imperfect sequences [] total 2 [2021-12-17 15:07:43,339 INFO L115 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [63523770] [2021-12-17 15:07:43,340 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2021-12-17 15:07:43,343 INFO L546 AbstractCegarLoop]: INTERPOLANT automaton has 2 states [2021-12-17 15:07:43,343 INFO L103 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2021-12-17 15:07:43,359 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 2 interpolants. [2021-12-17 15:07:43,360 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=1, Invalid=1, Unknown=0, NotChecked=0, Total=2 [2021-12-17 15:07:43,361 INFO L87 Difference]: Start difference. First operand has 89 states, 69 states have (on average 1.391304347826087) internal successors, (96), 77 states have internal predecessors, (96), 11 states have call successors, (11), 7 states have call predecessors, (11), 7 states have return successors, (11), 9 states have call predecessors, (11), 11 states have call successors, (11) Second operand has 2 states, 2 states have (on average 10.5) internal successors, (21), 2 states have internal predecessors, (21), 1 states have call successors, (3), 2 states have call predecessors, (3), 1 states have return successors, (1), 1 states have call predecessors, (1), 1 states have call successors, (1) [2021-12-17 15:07:43,381 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2021-12-17 15:07:43,382 INFO L93 Difference]: Finished difference Result 169 states and 230 transitions. [2021-12-17 15:07:43,382 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 2 states. [2021-12-17 15:07:43,383 INFO L78 Accepts]: Start accepts. Automaton has has 2 states, 2 states have (on average 10.5) internal successors, (21), 2 states have internal predecessors, (21), 1 states have call successors, (3), 2 states have call predecessors, (3), 1 states have return successors, (1), 1 states have call predecessors, (1), 1 states have call successors, (1) Word has length 25 [2021-12-17 15:07:43,383 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2021-12-17 15:07:43,389 INFO L225 Difference]: With dead ends: 169 [2021-12-17 15:07:43,389 INFO L226 Difference]: Without dead ends: 80 [2021-12-17 15:07:43,392 INFO L932 BasicCegarLoop]: 0 DeclaredPredicates, 4 GetRequests, 4 SyntacticMatches, 0 SemanticMatches, 0 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 0 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=1, Invalid=1, Unknown=0, NotChecked=0, Total=2 [2021-12-17 15:07:43,394 INFO L933 BasicCegarLoop]: 112 mSDtfsCounter, 0 mSDsluCounter, 0 mSDsCounter, 0 mSdLazyCounter, 0 mSolverCounterSat, 0 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.0s Time, 0 mProtectedPredicate, 0 mProtectedAction, 0 SdHoareTripleChecker+Valid, 112 SdHoareTripleChecker+Invalid, 0 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 0 IncrementalHoareTripleChecker+Valid, 0 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.0s IncrementalHoareTripleChecker+Time [2021-12-17 15:07:43,395 INFO L934 BasicCegarLoop]: SdHoareTripleChecker [0 Valid, 112 Invalid, 0 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [0 Valid, 0 Invalid, 0 Unknown, 0 Unchecked, 0.0s Time] [2021-12-17 15:07:43,405 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 80 states. [2021-12-17 15:07:43,419 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 80 to 80. [2021-12-17 15:07:43,420 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 80 states, 62 states have (on average 1.3225806451612903) internal successors, (82), 69 states have internal predecessors, (82), 11 states have call successors, (11), 7 states have call predecessors, (11), 6 states have return successors, (10), 8 states have call predecessors, (10), 10 states have call successors, (10) [2021-12-17 15:07:43,422 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 80 states to 80 states and 103 transitions. [2021-12-17 15:07:43,436 INFO L78 Accepts]: Start accepts. Automaton has 80 states and 103 transitions. Word has length 25 [2021-12-17 15:07:43,436 INFO L84 Accepts]: Finished accepts. word is rejected. [2021-12-17 15:07:43,436 INFO L470 AbstractCegarLoop]: Abstraction has 80 states and 103 transitions. [2021-12-17 15:07:43,437 INFO L471 AbstractCegarLoop]: INTERPOLANT automaton has has 2 states, 2 states have (on average 10.5) internal successors, (21), 2 states have internal predecessors, (21), 1 states have call successors, (3), 2 states have call predecessors, (3), 1 states have return successors, (1), 1 states have call predecessors, (1), 1 states have call successors, (1) [2021-12-17 15:07:43,437 INFO L276 IsEmpty]: Start isEmpty. Operand 80 states and 103 transitions. [2021-12-17 15:07:43,438 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 27 [2021-12-17 15:07:43,438 INFO L506 BasicCegarLoop]: Found error trace [2021-12-17 15:07:43,439 INFO L514 BasicCegarLoop]: trace histogram [1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2021-12-17 15:07:43,439 WARN L452 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable0 [2021-12-17 15:07:43,439 INFO L402 AbstractCegarLoop]: === Iteration 2 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2021-12-17 15:07:43,440 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2021-12-17 15:07:43,440 INFO L85 PathProgramCache]: Analyzing trace with hash -1591426498, now seen corresponding path program 1 times [2021-12-17 15:07:43,440 INFO L121 FreeRefinementEngine]: Executing refinement strategy CAMEL [2021-12-17 15:07:43,440 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [850688023] [2021-12-17 15:07:43,440 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2021-12-17 15:07:43,441 INFO L126 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2021-12-17 15:07:43,457 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:07:43,483 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 16 [2021-12-17 15:07:43,485 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:07:43,487 INFO L134 CoverageAnalysis]: Checked inductivity of 0 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2021-12-17 15:07:43,488 INFO L139 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2021-12-17 15:07:43,488 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [850688023] [2021-12-17 15:07:43,488 INFO L160 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [850688023] provided 1 perfect and 0 imperfect interpolant sequences [2021-12-17 15:07:43,488 INFO L186 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2021-12-17 15:07:43,488 INFO L199 FreeRefinementEngine]: Number of different interpolants: perfect sequences [3] imperfect sequences [] total 3 [2021-12-17 15:07:43,488 INFO L115 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [945262354] [2021-12-17 15:07:43,489 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2021-12-17 15:07:43,490 INFO L546 AbstractCegarLoop]: INTERPOLANT automaton has 3 states [2021-12-17 15:07:43,490 INFO L103 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2021-12-17 15:07:43,490 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 3 interpolants. [2021-12-17 15:07:43,490 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=3, Invalid=3, Unknown=0, NotChecked=0, Total=6 [2021-12-17 15:07:43,491 INFO L87 Difference]: Start difference. First operand 80 states and 103 transitions. Second operand has 3 states, 3 states have (on average 7.333333333333333) internal successors, (22), 3 states have internal predecessors, (22), 1 states have call successors, (3), 2 states have call predecessors, (3), 1 states have return successors, (1), 1 states have call predecessors, (1), 1 states have call successors, (1) [2021-12-17 15:07:43,501 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2021-12-17 15:07:43,501 INFO L93 Difference]: Finished difference Result 124 states and 160 transitions. [2021-12-17 15:07:43,501 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 3 states. [2021-12-17 15:07:43,501 INFO L78 Accepts]: Start accepts. Automaton has has 3 states, 3 states have (on average 7.333333333333333) internal successors, (22), 3 states have internal predecessors, (22), 1 states have call successors, (3), 2 states have call predecessors, (3), 1 states have return successors, (1), 1 states have call predecessors, (1), 1 states have call successors, (1) Word has length 26 [2021-12-17 15:07:43,502 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2021-12-17 15:07:43,503 INFO L225 Difference]: With dead ends: 124 [2021-12-17 15:07:43,503 INFO L226 Difference]: Without dead ends: 71 [2021-12-17 15:07:43,503 INFO L932 BasicCegarLoop]: 0 DeclaredPredicates, 5 GetRequests, 4 SyntacticMatches, 0 SemanticMatches, 1 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 0 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=3, Invalid=3, Unknown=0, NotChecked=0, Total=6 [2021-12-17 15:07:43,504 INFO L933 BasicCegarLoop]: 90 mSDtfsCounter, 13 mSDsluCounter, 73 mSDsCounter, 0 mSdLazyCounter, 1 mSolverCounterSat, 0 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.0s Time, 0 mProtectedPredicate, 0 mProtectedAction, 16 SdHoareTripleChecker+Valid, 163 SdHoareTripleChecker+Invalid, 1 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 0 IncrementalHoareTripleChecker+Valid, 1 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.0s IncrementalHoareTripleChecker+Time [2021-12-17 15:07:43,505 INFO L934 BasicCegarLoop]: SdHoareTripleChecker [16 Valid, 163 Invalid, 1 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [0 Valid, 1 Invalid, 0 Unknown, 0 Unchecked, 0.0s Time] [2021-12-17 15:07:43,505 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 71 states. [2021-12-17 15:07:43,510 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 71 to 71. [2021-12-17 15:07:43,510 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 71 states, 56 states have (on average 1.3392857142857142) internal successors, (75), 63 states have internal predecessors, (75), 8 states have call successors, (8), 6 states have call predecessors, (8), 6 states have return successors, (8), 6 states have call predecessors, (8), 8 states have call successors, (8) [2021-12-17 15:07:43,511 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 71 states to 71 states and 91 transitions. [2021-12-17 15:07:43,511 INFO L78 Accepts]: Start accepts. Automaton has 71 states and 91 transitions. Word has length 26 [2021-12-17 15:07:43,511 INFO L84 Accepts]: Finished accepts. word is rejected. [2021-12-17 15:07:43,511 INFO L470 AbstractCegarLoop]: Abstraction has 71 states and 91 transitions. [2021-12-17 15:07:43,512 INFO L471 AbstractCegarLoop]: INTERPOLANT automaton has has 3 states, 3 states have (on average 7.333333333333333) internal successors, (22), 3 states have internal predecessors, (22), 1 states have call successors, (3), 2 states have call predecessors, (3), 1 states have return successors, (1), 1 states have call predecessors, (1), 1 states have call successors, (1) [2021-12-17 15:07:43,512 INFO L276 IsEmpty]: Start isEmpty. Operand 71 states and 91 transitions. [2021-12-17 15:07:43,513 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 32 [2021-12-17 15:07:43,513 INFO L506 BasicCegarLoop]: Found error trace [2021-12-17 15:07:43,513 INFO L514 BasicCegarLoop]: trace histogram [1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2021-12-17 15:07:43,513 WARN L452 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable1 [2021-12-17 15:07:43,513 INFO L402 AbstractCegarLoop]: === Iteration 3 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2021-12-17 15:07:43,514 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2021-12-17 15:07:43,514 INFO L85 PathProgramCache]: Analyzing trace with hash 18143891, now seen corresponding path program 1 times [2021-12-17 15:07:43,514 INFO L121 FreeRefinementEngine]: Executing refinement strategy CAMEL [2021-12-17 15:07:43,514 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [1011319081] [2021-12-17 15:07:43,514 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2021-12-17 15:07:43,514 INFO L126 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2021-12-17 15:07:43,531 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:07:43,554 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 21 [2021-12-17 15:07:43,555 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:07:43,558 INFO L134 CoverageAnalysis]: Checked inductivity of 0 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2021-12-17 15:07:43,558 INFO L139 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2021-12-17 15:07:43,558 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [1011319081] [2021-12-17 15:07:43,558 INFO L160 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [1011319081] provided 1 perfect and 0 imperfect interpolant sequences [2021-12-17 15:07:43,558 INFO L186 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2021-12-17 15:07:43,558 INFO L199 FreeRefinementEngine]: Number of different interpolants: perfect sequences [3] imperfect sequences [] total 3 [2021-12-17 15:07:43,559 INFO L115 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [211443639] [2021-12-17 15:07:43,559 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2021-12-17 15:07:43,559 INFO L546 AbstractCegarLoop]: INTERPOLANT automaton has 3 states [2021-12-17 15:07:43,559 INFO L103 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2021-12-17 15:07:43,560 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 3 interpolants. [2021-12-17 15:07:43,560 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=3, Invalid=3, Unknown=0, NotChecked=0, Total=6 [2021-12-17 15:07:43,560 INFO L87 Difference]: Start difference. First operand 71 states and 91 transitions. Second operand has 3 states, 3 states have (on average 9.333333333333334) internal successors, (28), 3 states have internal predecessors, (28), 2 states have call successors, (2), 2 states have call predecessors, (2), 1 states have return successors, (1), 1 states have call predecessors, (1), 1 states have call successors, (1) [2021-12-17 15:07:43,575 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2021-12-17 15:07:43,576 INFO L93 Difference]: Finished difference Result 134 states and 175 transitions. [2021-12-17 15:07:43,576 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 3 states. [2021-12-17 15:07:43,576 INFO L78 Accepts]: Start accepts. Automaton has has 3 states, 3 states have (on average 9.333333333333334) internal successors, (28), 3 states have internal predecessors, (28), 2 states have call successors, (2), 2 states have call predecessors, (2), 1 states have return successors, (1), 1 states have call predecessors, (1), 1 states have call successors, (1) Word has length 31 [2021-12-17 15:07:43,576 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2021-12-17 15:07:43,577 INFO L225 Difference]: With dead ends: 134 [2021-12-17 15:07:43,577 INFO L226 Difference]: Without dead ends: 71 [2021-12-17 15:07:43,578 INFO L932 BasicCegarLoop]: 0 DeclaredPredicates, 5 GetRequests, 4 SyntacticMatches, 0 SemanticMatches, 1 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 0 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=3, Invalid=3, Unknown=0, NotChecked=0, Total=6 [2021-12-17 15:07:43,579 INFO L933 BasicCegarLoop]: 89 mSDtfsCounter, 85 mSDsluCounter, 0 mSDsCounter, 0 mSdLazyCounter, 1 mSolverCounterSat, 1 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.0s Time, 0 mProtectedPredicate, 0 mProtectedAction, 85 SdHoareTripleChecker+Valid, 89 SdHoareTripleChecker+Invalid, 2 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 1 IncrementalHoareTripleChecker+Valid, 1 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.0s IncrementalHoareTripleChecker+Time [2021-12-17 15:07:43,579 INFO L934 BasicCegarLoop]: SdHoareTripleChecker [85 Valid, 89 Invalid, 2 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [1 Valid, 1 Invalid, 0 Unknown, 0 Unchecked, 0.0s Time] [2021-12-17 15:07:43,580 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 71 states. [2021-12-17 15:07:43,585 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 71 to 71. [2021-12-17 15:07:43,586 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 71 states, 56 states have (on average 1.3214285714285714) internal successors, (74), 63 states have internal predecessors, (74), 8 states have call successors, (8), 6 states have call predecessors, (8), 6 states have return successors, (8), 6 states have call predecessors, (8), 8 states have call successors, (8) [2021-12-17 15:07:43,586 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 71 states to 71 states and 90 transitions. [2021-12-17 15:07:43,587 INFO L78 Accepts]: Start accepts. Automaton has 71 states and 90 transitions. Word has length 31 [2021-12-17 15:07:43,587 INFO L84 Accepts]: Finished accepts. word is rejected. [2021-12-17 15:07:43,587 INFO L470 AbstractCegarLoop]: Abstraction has 71 states and 90 transitions. [2021-12-17 15:07:43,587 INFO L471 AbstractCegarLoop]: INTERPOLANT automaton has has 3 states, 3 states have (on average 9.333333333333334) internal successors, (28), 3 states have internal predecessors, (28), 2 states have call successors, (2), 2 states have call predecessors, (2), 1 states have return successors, (1), 1 states have call predecessors, (1), 1 states have call successors, (1) [2021-12-17 15:07:43,587 INFO L276 IsEmpty]: Start isEmpty. Operand 71 states and 90 transitions. [2021-12-17 15:07:43,588 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 42 [2021-12-17 15:07:43,588 INFO L506 BasicCegarLoop]: Found error trace [2021-12-17 15:07:43,588 INFO L514 BasicCegarLoop]: trace histogram [1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2021-12-17 15:07:43,589 WARN L452 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable2 [2021-12-17 15:07:43,589 INFO L402 AbstractCegarLoop]: === Iteration 4 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2021-12-17 15:07:43,589 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2021-12-17 15:07:43,589 INFO L85 PathProgramCache]: Analyzing trace with hash -26266963, now seen corresponding path program 1 times [2021-12-17 15:07:43,590 INFO L121 FreeRefinementEngine]: Executing refinement strategy CAMEL [2021-12-17 15:07:43,590 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [524004680] [2021-12-17 15:07:43,590 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2021-12-17 15:07:43,590 INFO L126 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2021-12-17 15:07:43,603 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:07:43,631 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 21 [2021-12-17 15:07:43,632 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:07:43,644 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 2 [2021-12-17 15:07:43,645 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:07:43,647 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 31 [2021-12-17 15:07:43,648 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:07:43,650 INFO L134 CoverageAnalysis]: Checked inductivity of 0 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2021-12-17 15:07:43,651 INFO L139 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2021-12-17 15:07:43,651 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [524004680] [2021-12-17 15:07:43,651 INFO L160 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [524004680] provided 1 perfect and 0 imperfect interpolant sequences [2021-12-17 15:07:43,651 INFO L186 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2021-12-17 15:07:43,651 INFO L199 FreeRefinementEngine]: Number of different interpolants: perfect sequences [5] imperfect sequences [] total 5 [2021-12-17 15:07:43,652 INFO L115 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [296216712] [2021-12-17 15:07:43,652 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2021-12-17 15:07:43,652 INFO L546 AbstractCegarLoop]: INTERPOLANT automaton has 5 states [2021-12-17 15:07:43,652 INFO L103 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2021-12-17 15:07:43,653 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 5 interpolants. [2021-12-17 15:07:43,653 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=7, Invalid=13, Unknown=0, NotChecked=0, Total=20 [2021-12-17 15:07:43,653 INFO L87 Difference]: Start difference. First operand 71 states and 90 transitions. Second operand has 5 states, 5 states have (on average 6.8) internal successors, (34), 5 states have internal predecessors, (34), 3 states have call successors, (4), 3 states have call predecessors, (4), 2 states have return successors, (3), 2 states have call predecessors, (3), 3 states have call successors, (3) [2021-12-17 15:07:43,781 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2021-12-17 15:07:43,781 INFO L93 Difference]: Finished difference Result 209 states and 267 transitions. [2021-12-17 15:07:43,782 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 7 states. [2021-12-17 15:07:43,782 INFO L78 Accepts]: Start accepts. Automaton has has 5 states, 5 states have (on average 6.8) internal successors, (34), 5 states have internal predecessors, (34), 3 states have call successors, (4), 3 states have call predecessors, (4), 2 states have return successors, (3), 2 states have call predecessors, (3), 3 states have call successors, (3) Word has length 41 [2021-12-17 15:07:43,782 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2021-12-17 15:07:43,783 INFO L225 Difference]: With dead ends: 209 [2021-12-17 15:07:43,783 INFO L226 Difference]: Without dead ends: 146 [2021-12-17 15:07:43,784 INFO L932 BasicCegarLoop]: 0 DeclaredPredicates, 15 GetRequests, 8 SyntacticMatches, 1 SemanticMatches, 6 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 3 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=19, Invalid=37, Unknown=0, NotChecked=0, Total=56 [2021-12-17 15:07:43,785 INFO L933 BasicCegarLoop]: 132 mSDtfsCounter, 167 mSDsluCounter, 175 mSDsCounter, 0 mSdLazyCounter, 92 mSolverCounterSat, 41 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.1s Time, 0 mProtectedPredicate, 0 mProtectedAction, 169 SdHoareTripleChecker+Valid, 307 SdHoareTripleChecker+Invalid, 133 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 41 IncrementalHoareTripleChecker+Valid, 92 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.1s IncrementalHoareTripleChecker+Time [2021-12-17 15:07:43,785 INFO L934 BasicCegarLoop]: SdHoareTripleChecker [169 Valid, 307 Invalid, 133 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [41 Valid, 92 Invalid, 0 Unknown, 0 Unchecked, 0.1s Time] [2021-12-17 15:07:43,786 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 146 states. [2021-12-17 15:07:43,798 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 146 to 140. [2021-12-17 15:07:43,798 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 140 states, 109 states have (on average 1.2844036697247707) internal successors, (140), 116 states have internal predecessors, (140), 14 states have call successors, (14), 13 states have call predecessors, (14), 16 states have return successors, (19), 15 states have call predecessors, (19), 14 states have call successors, (19) [2021-12-17 15:07:43,799 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 140 states to 140 states and 173 transitions. [2021-12-17 15:07:43,800 INFO L78 Accepts]: Start accepts. Automaton has 140 states and 173 transitions. Word has length 41 [2021-12-17 15:07:43,800 INFO L84 Accepts]: Finished accepts. word is rejected. [2021-12-17 15:07:43,800 INFO L470 AbstractCegarLoop]: Abstraction has 140 states and 173 transitions. [2021-12-17 15:07:43,800 INFO L471 AbstractCegarLoop]: INTERPOLANT automaton has has 5 states, 5 states have (on average 6.8) internal successors, (34), 5 states have internal predecessors, (34), 3 states have call successors, (4), 3 states have call predecessors, (4), 2 states have return successors, (3), 2 states have call predecessors, (3), 3 states have call successors, (3) [2021-12-17 15:07:43,800 INFO L276 IsEmpty]: Start isEmpty. Operand 140 states and 173 transitions. [2021-12-17 15:07:43,801 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 46 [2021-12-17 15:07:43,801 INFO L506 BasicCegarLoop]: Found error trace [2021-12-17 15:07:43,801 INFO L514 BasicCegarLoop]: trace histogram [1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2021-12-17 15:07:43,801 WARN L452 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable3 [2021-12-17 15:07:43,802 INFO L402 AbstractCegarLoop]: === Iteration 5 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2021-12-17 15:07:43,802 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2021-12-17 15:07:43,802 INFO L85 PathProgramCache]: Analyzing trace with hash -970342054, now seen corresponding path program 1 times [2021-12-17 15:07:43,802 INFO L121 FreeRefinementEngine]: Executing refinement strategy CAMEL [2021-12-17 15:07:43,803 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [483807236] [2021-12-17 15:07:43,803 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2021-12-17 15:07:43,803 INFO L126 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2021-12-17 15:07:43,813 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:07:43,875 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 21 [2021-12-17 15:07:43,878 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:07:43,912 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 35 [2021-12-17 15:07:43,916 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:07:43,922 INFO L134 CoverageAnalysis]: Checked inductivity of 0 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2021-12-17 15:07:43,923 INFO L139 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2021-12-17 15:07:43,923 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [483807236] [2021-12-17 15:07:43,923 INFO L160 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [483807236] provided 1 perfect and 0 imperfect interpolant sequences [2021-12-17 15:07:43,923 INFO L186 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2021-12-17 15:07:43,923 INFO L199 FreeRefinementEngine]: Number of different interpolants: perfect sequences [5] imperfect sequences [] total 5 [2021-12-17 15:07:43,924 INFO L115 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [908760540] [2021-12-17 15:07:43,924 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2021-12-17 15:07:43,924 INFO L546 AbstractCegarLoop]: INTERPOLANT automaton has 5 states [2021-12-17 15:07:43,924 INFO L103 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2021-12-17 15:07:43,925 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 5 interpolants. [2021-12-17 15:07:43,925 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=7, Invalid=13, Unknown=0, NotChecked=0, Total=20 [2021-12-17 15:07:43,925 INFO L87 Difference]: Start difference. First operand 140 states and 173 transitions. Second operand has 5 states, 5 states have (on average 8.0) internal successors, (40), 4 states have internal predecessors, (40), 2 states have call successors, (3), 2 states have call predecessors, (3), 2 states have return successors, (2), 1 states have call predecessors, (2), 2 states have call successors, (2) [2021-12-17 15:07:44,031 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2021-12-17 15:07:44,032 INFO L93 Difference]: Finished difference Result 285 states and 359 transitions. [2021-12-17 15:07:44,032 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 6 states. [2021-12-17 15:07:44,032 INFO L78 Accepts]: Start accepts. Automaton has has 5 states, 5 states have (on average 8.0) internal successors, (40), 4 states have internal predecessors, (40), 2 states have call successors, (3), 2 states have call predecessors, (3), 2 states have return successors, (2), 1 states have call predecessors, (2), 2 states have call successors, (2) Word has length 45 [2021-12-17 15:07:44,032 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2021-12-17 15:07:44,033 INFO L225 Difference]: With dead ends: 285 [2021-12-17 15:07:44,034 INFO L226 Difference]: Without dead ends: 153 [2021-12-17 15:07:44,034 INFO L932 BasicCegarLoop]: 0 DeclaredPredicates, 12 GetRequests, 6 SyntacticMatches, 0 SemanticMatches, 6 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 2 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=22, Invalid=34, Unknown=0, NotChecked=0, Total=56 [2021-12-17 15:07:44,035 INFO L933 BasicCegarLoop]: 94 mSDtfsCounter, 69 mSDsluCounter, 205 mSDsCounter, 0 mSdLazyCounter, 71 mSolverCounterSat, 14 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.1s Time, 0 mProtectedPredicate, 0 mProtectedAction, 72 SdHoareTripleChecker+Valid, 299 SdHoareTripleChecker+Invalid, 85 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 14 IncrementalHoareTripleChecker+Valid, 71 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.1s IncrementalHoareTripleChecker+Time [2021-12-17 15:07:44,036 INFO L934 BasicCegarLoop]: SdHoareTripleChecker [72 Valid, 299 Invalid, 85 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [14 Valid, 71 Invalid, 0 Unknown, 0 Unchecked, 0.1s Time] [2021-12-17 15:07:44,037 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 153 states. [2021-12-17 15:07:44,044 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 153 to 142. [2021-12-17 15:07:44,045 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 142 states, 111 states have (on average 1.2792792792792793) internal successors, (142), 118 states have internal predecessors, (142), 14 states have call successors, (14), 13 states have call predecessors, (14), 16 states have return successors, (19), 15 states have call predecessors, (19), 14 states have call successors, (19) [2021-12-17 15:07:44,046 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 142 states to 142 states and 175 transitions. [2021-12-17 15:07:44,046 INFO L78 Accepts]: Start accepts. Automaton has 142 states and 175 transitions. Word has length 45 [2021-12-17 15:07:44,046 INFO L84 Accepts]: Finished accepts. word is rejected. [2021-12-17 15:07:44,046 INFO L470 AbstractCegarLoop]: Abstraction has 142 states and 175 transitions. [2021-12-17 15:07:44,046 INFO L471 AbstractCegarLoop]: INTERPOLANT automaton has has 5 states, 5 states have (on average 8.0) internal successors, (40), 4 states have internal predecessors, (40), 2 states have call successors, (3), 2 states have call predecessors, (3), 2 states have return successors, (2), 1 states have call predecessors, (2), 2 states have call successors, (2) [2021-12-17 15:07:44,047 INFO L276 IsEmpty]: Start isEmpty. Operand 142 states and 175 transitions. [2021-12-17 15:07:44,047 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 46 [2021-12-17 15:07:44,047 INFO L506 BasicCegarLoop]: Found error trace [2021-12-17 15:07:44,048 INFO L514 BasicCegarLoop]: trace histogram [1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2021-12-17 15:07:44,048 WARN L452 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable4 [2021-12-17 15:07:44,048 INFO L402 AbstractCegarLoop]: === Iteration 6 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2021-12-17 15:07:44,048 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2021-12-17 15:07:44,049 INFO L85 PathProgramCache]: Analyzing trace with hash 718601688, now seen corresponding path program 1 times [2021-12-17 15:07:44,049 INFO L121 FreeRefinementEngine]: Executing refinement strategy CAMEL [2021-12-17 15:07:44,049 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [1636587496] [2021-12-17 15:07:44,049 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2021-12-17 15:07:44,049 INFO L126 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2021-12-17 15:07:44,059 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:07:44,072 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 21 [2021-12-17 15:07:44,075 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:07:44,092 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 35 [2021-12-17 15:07:44,093 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:07:44,095 INFO L134 CoverageAnalysis]: Checked inductivity of 0 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2021-12-17 15:07:44,095 INFO L139 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2021-12-17 15:07:44,095 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [1636587496] [2021-12-17 15:07:44,095 INFO L160 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [1636587496] provided 1 perfect and 0 imperfect interpolant sequences [2021-12-17 15:07:44,096 INFO L186 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2021-12-17 15:07:44,096 INFO L199 FreeRefinementEngine]: Number of different interpolants: perfect sequences [6] imperfect sequences [] total 6 [2021-12-17 15:07:44,096 INFO L115 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [1869719382] [2021-12-17 15:07:44,096 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2021-12-17 15:07:44,096 INFO L546 AbstractCegarLoop]: INTERPOLANT automaton has 6 states [2021-12-17 15:07:44,097 INFO L103 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2021-12-17 15:07:44,097 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 6 interpolants. [2021-12-17 15:07:44,097 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=9, Invalid=21, Unknown=0, NotChecked=0, Total=30 [2021-12-17 15:07:44,097 INFO L87 Difference]: Start difference. First operand 142 states and 175 transitions. Second operand has 6 states, 6 states have (on average 6.666666666666667) internal successors, (40), 5 states have internal predecessors, (40), 2 states have call successors, (3), 2 states have call predecessors, (3), 2 states have return successors, (2), 1 states have call predecessors, (2), 2 states have call successors, (2) [2021-12-17 15:07:44,180 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2021-12-17 15:07:44,180 INFO L93 Difference]: Finished difference Result 284 states and 354 transitions. [2021-12-17 15:07:44,181 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 7 states. [2021-12-17 15:07:44,181 INFO L78 Accepts]: Start accepts. Automaton has has 6 states, 6 states have (on average 6.666666666666667) internal successors, (40), 5 states have internal predecessors, (40), 2 states have call successors, (3), 2 states have call predecessors, (3), 2 states have return successors, (2), 1 states have call predecessors, (2), 2 states have call successors, (2) Word has length 45 [2021-12-17 15:07:44,181 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2021-12-17 15:07:44,182 INFO L225 Difference]: With dead ends: 284 [2021-12-17 15:07:44,182 INFO L226 Difference]: Without dead ends: 150 [2021-12-17 15:07:44,183 INFO L932 BasicCegarLoop]: 0 DeclaredPredicates, 14 GetRequests, 6 SyntacticMatches, 0 SemanticMatches, 8 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 3 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=32, Invalid=58, Unknown=0, NotChecked=0, Total=90 [2021-12-17 15:07:44,184 INFO L933 BasicCegarLoop]: 93 mSDtfsCounter, 63 mSDsluCounter, 288 mSDsCounter, 0 mSdLazyCounter, 95 mSolverCounterSat, 18 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.0s Time, 0 mProtectedPredicate, 0 mProtectedAction, 65 SdHoareTripleChecker+Valid, 381 SdHoareTripleChecker+Invalid, 113 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 18 IncrementalHoareTripleChecker+Valid, 95 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.1s IncrementalHoareTripleChecker+Time [2021-12-17 15:07:44,184 INFO L934 BasicCegarLoop]: SdHoareTripleChecker [65 Valid, 381 Invalid, 113 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [18 Valid, 95 Invalid, 0 Unknown, 0 Unchecked, 0.1s Time] [2021-12-17 15:07:44,185 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 150 states. [2021-12-17 15:07:44,192 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 150 to 145. [2021-12-17 15:07:44,193 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 145 states, 114 states have (on average 1.2719298245614035) internal successors, (145), 121 states have internal predecessors, (145), 14 states have call successors, (14), 13 states have call predecessors, (14), 16 states have return successors, (19), 15 states have call predecessors, (19), 14 states have call successors, (19) [2021-12-17 15:07:44,193 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 145 states to 145 states and 178 transitions. [2021-12-17 15:07:44,194 INFO L78 Accepts]: Start accepts. Automaton has 145 states and 178 transitions. Word has length 45 [2021-12-17 15:07:44,194 INFO L84 Accepts]: Finished accepts. word is rejected. [2021-12-17 15:07:44,194 INFO L470 AbstractCegarLoop]: Abstraction has 145 states and 178 transitions. [2021-12-17 15:07:44,194 INFO L471 AbstractCegarLoop]: INTERPOLANT automaton has has 6 states, 6 states have (on average 6.666666666666667) internal successors, (40), 5 states have internal predecessors, (40), 2 states have call successors, (3), 2 states have call predecessors, (3), 2 states have return successors, (2), 1 states have call predecessors, (2), 2 states have call successors, (2) [2021-12-17 15:07:44,194 INFO L276 IsEmpty]: Start isEmpty. Operand 145 states and 178 transitions. [2021-12-17 15:07:44,195 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 46 [2021-12-17 15:07:44,195 INFO L506 BasicCegarLoop]: Found error trace [2021-12-17 15:07:44,195 INFO L514 BasicCegarLoop]: trace histogram [1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2021-12-17 15:07:44,196 WARN L452 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable5 [2021-12-17 15:07:44,196 INFO L402 AbstractCegarLoop]: === Iteration 7 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2021-12-17 15:07:44,196 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2021-12-17 15:07:44,196 INFO L85 PathProgramCache]: Analyzing trace with hash -547640228, now seen corresponding path program 1 times [2021-12-17 15:07:44,196 INFO L121 FreeRefinementEngine]: Executing refinement strategy CAMEL [2021-12-17 15:07:44,197 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [849187986] [2021-12-17 15:07:44,197 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2021-12-17 15:07:44,197 INFO L126 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2021-12-17 15:07:44,204 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:07:44,221 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 21 [2021-12-17 15:07:44,224 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:07:44,232 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 35 [2021-12-17 15:07:44,233 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:07:44,234 INFO L134 CoverageAnalysis]: Checked inductivity of 0 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2021-12-17 15:07:44,234 INFO L139 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2021-12-17 15:07:44,235 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [849187986] [2021-12-17 15:07:44,235 INFO L160 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [849187986] provided 1 perfect and 0 imperfect interpolant sequences [2021-12-17 15:07:44,235 INFO L186 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2021-12-17 15:07:44,235 INFO L199 FreeRefinementEngine]: Number of different interpolants: perfect sequences [5] imperfect sequences [] total 5 [2021-12-17 15:07:44,235 INFO L115 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [1582618477] [2021-12-17 15:07:44,235 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2021-12-17 15:07:44,236 INFO L546 AbstractCegarLoop]: INTERPOLANT automaton has 5 states [2021-12-17 15:07:44,236 INFO L103 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2021-12-17 15:07:44,236 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 5 interpolants. [2021-12-17 15:07:44,236 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=7, Invalid=13, Unknown=0, NotChecked=0, Total=20 [2021-12-17 15:07:44,237 INFO L87 Difference]: Start difference. First operand 145 states and 178 transitions. Second operand has 5 states, 5 states have (on average 8.0) internal successors, (40), 4 states have internal predecessors, (40), 2 states have call successors, (3), 3 states have call predecessors, (3), 2 states have return successors, (2), 1 states have call predecessors, (2), 2 states have call successors, (2) [2021-12-17 15:07:44,355 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2021-12-17 15:07:44,355 INFO L93 Difference]: Finished difference Result 407 states and 521 transitions. [2021-12-17 15:07:44,356 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 7 states. [2021-12-17 15:07:44,356 INFO L78 Accepts]: Start accepts. Automaton has has 5 states, 5 states have (on average 8.0) internal successors, (40), 4 states have internal predecessors, (40), 2 states have call successors, (3), 3 states have call predecessors, (3), 2 states have return successors, (2), 1 states have call predecessors, (2), 2 states have call successors, (2) Word has length 45 [2021-12-17 15:07:44,356 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2021-12-17 15:07:44,373 INFO L225 Difference]: With dead ends: 407 [2021-12-17 15:07:44,373 INFO L226 Difference]: Without dead ends: 270 [2021-12-17 15:07:44,374 INFO L932 BasicCegarLoop]: 0 DeclaredPredicates, 12 GetRequests, 7 SyntacticMatches, 0 SemanticMatches, 5 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 1 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=15, Invalid=27, Unknown=0, NotChecked=0, Total=42 [2021-12-17 15:07:44,375 INFO L933 BasicCegarLoop]: 147 mSDtfsCounter, 199 mSDsluCounter, 176 mSDsCounter, 0 mSdLazyCounter, 130 mSolverCounterSat, 50 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.1s Time, 0 mProtectedPredicate, 0 mProtectedAction, 205 SdHoareTripleChecker+Valid, 323 SdHoareTripleChecker+Invalid, 180 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 50 IncrementalHoareTripleChecker+Valid, 130 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.1s IncrementalHoareTripleChecker+Time [2021-12-17 15:07:44,375 INFO L934 BasicCegarLoop]: SdHoareTripleChecker [205 Valid, 323 Invalid, 180 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [50 Valid, 130 Invalid, 0 Unknown, 0 Unchecked, 0.1s Time] [2021-12-17 15:07:44,376 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 270 states. [2021-12-17 15:07:44,386 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 270 to 262. [2021-12-17 15:07:44,387 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 262 states, 203 states have (on average 1.2610837438423645) internal successors, (256), 214 states have internal predecessors, (256), 29 states have call successors, (29), 28 states have call predecessors, (29), 29 states have return successors, (44), 29 states have call predecessors, (44), 29 states have call successors, (44) [2021-12-17 15:07:44,388 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 262 states to 262 states and 329 transitions. [2021-12-17 15:07:44,388 INFO L78 Accepts]: Start accepts. Automaton has 262 states and 329 transitions. Word has length 45 [2021-12-17 15:07:44,388 INFO L84 Accepts]: Finished accepts. word is rejected. [2021-12-17 15:07:44,389 INFO L470 AbstractCegarLoop]: Abstraction has 262 states and 329 transitions. [2021-12-17 15:07:44,389 INFO L471 AbstractCegarLoop]: INTERPOLANT automaton has has 5 states, 5 states have (on average 8.0) internal successors, (40), 4 states have internal predecessors, (40), 2 states have call successors, (3), 3 states have call predecessors, (3), 2 states have return successors, (2), 1 states have call predecessors, (2), 2 states have call successors, (2) [2021-12-17 15:07:44,389 INFO L276 IsEmpty]: Start isEmpty. Operand 262 states and 329 transitions. [2021-12-17 15:07:44,390 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 48 [2021-12-17 15:07:44,390 INFO L506 BasicCegarLoop]: Found error trace [2021-12-17 15:07:44,390 INFO L514 BasicCegarLoop]: trace histogram [1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2021-12-17 15:07:44,390 WARN L452 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable6 [2021-12-17 15:07:44,391 INFO L402 AbstractCegarLoop]: === Iteration 8 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2021-12-17 15:07:44,391 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2021-12-17 15:07:44,391 INFO L85 PathProgramCache]: Analyzing trace with hash 2090838197, now seen corresponding path program 1 times [2021-12-17 15:07:44,391 INFO L121 FreeRefinementEngine]: Executing refinement strategy CAMEL [2021-12-17 15:07:44,391 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [1758587990] [2021-12-17 15:07:44,392 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2021-12-17 15:07:44,392 INFO L126 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2021-12-17 15:07:44,426 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:07:44,478 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 21 [2021-12-17 15:07:44,481 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:07:44,484 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 8 [2021-12-17 15:07:44,484 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:07:44,485 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 37 [2021-12-17 15:07:44,486 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:07:44,492 INFO L134 CoverageAnalysis]: Checked inductivity of 0 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2021-12-17 15:07:44,493 INFO L139 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2021-12-17 15:07:44,493 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [1758587990] [2021-12-17 15:07:44,493 INFO L160 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [1758587990] provided 1 perfect and 0 imperfect interpolant sequences [2021-12-17 15:07:44,493 INFO L186 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2021-12-17 15:07:44,493 INFO L199 FreeRefinementEngine]: Number of different interpolants: perfect sequences [7] imperfect sequences [] total 7 [2021-12-17 15:07:44,493 INFO L115 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [1264898810] [2021-12-17 15:07:44,493 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2021-12-17 15:07:44,494 INFO L546 AbstractCegarLoop]: INTERPOLANT automaton has 7 states [2021-12-17 15:07:44,494 INFO L103 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2021-12-17 15:07:44,494 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 7 interpolants. [2021-12-17 15:07:44,494 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=11, Invalid=31, Unknown=0, NotChecked=0, Total=42 [2021-12-17 15:07:44,495 INFO L87 Difference]: Start difference. First operand 262 states and 329 transitions. Second operand has 7 states, 7 states have (on average 5.714285714285714) internal successors, (40), 5 states have internal predecessors, (40), 2 states have call successors, (4), 3 states have call predecessors, (4), 2 states have return successors, (3), 3 states have call predecessors, (3), 2 states have call successors, (3) [2021-12-17 15:07:44,691 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2021-12-17 15:07:44,704 INFO L93 Difference]: Finished difference Result 770 states and 993 transitions. [2021-12-17 15:07:44,704 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 13 states. [2021-12-17 15:07:44,704 INFO L78 Accepts]: Start accepts. Automaton has has 7 states, 7 states have (on average 5.714285714285714) internal successors, (40), 5 states have internal predecessors, (40), 2 states have call successors, (4), 3 states have call predecessors, (4), 2 states have return successors, (3), 3 states have call predecessors, (3), 2 states have call successors, (3) Word has length 47 [2021-12-17 15:07:44,705 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2021-12-17 15:07:44,707 INFO L225 Difference]: With dead ends: 770 [2021-12-17 15:07:44,707 INFO L226 Difference]: Without dead ends: 516 [2021-12-17 15:07:44,708 INFO L932 BasicCegarLoop]: 0 DeclaredPredicates, 19 GetRequests, 6 SyntacticMatches, 0 SemanticMatches, 13 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 25 ImplicationChecksByTransitivity, 0.1s TimeCoverageRelationStatistics Valid=53, Invalid=157, Unknown=0, NotChecked=0, Total=210 [2021-12-17 15:07:44,709 INFO L933 BasicCegarLoop]: 80 mSDtfsCounter, 146 mSDsluCounter, 294 mSDsCounter, 0 mSdLazyCounter, 158 mSolverCounterSat, 42 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.1s Time, 0 mProtectedPredicate, 0 mProtectedAction, 153 SdHoareTripleChecker+Valid, 374 SdHoareTripleChecker+Invalid, 200 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 42 IncrementalHoareTripleChecker+Valid, 158 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.1s IncrementalHoareTripleChecker+Time [2021-12-17 15:07:44,709 INFO L934 BasicCegarLoop]: SdHoareTripleChecker [153 Valid, 374 Invalid, 200 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [42 Valid, 158 Invalid, 0 Unknown, 0 Unchecked, 0.1s Time] [2021-12-17 15:07:44,710 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 516 states. [2021-12-17 15:07:44,741 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 516 to 496. [2021-12-17 15:07:44,742 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 496 states, 379 states have (on average 1.2189973614775726) internal successors, (462), 400 states have internal predecessors, (462), 58 states have call successors, (58), 56 states have call predecessors, (58), 58 states have return successors, (93), 58 states have call predecessors, (93), 58 states have call successors, (93) [2021-12-17 15:07:44,745 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 496 states to 496 states and 613 transitions. [2021-12-17 15:07:44,745 INFO L78 Accepts]: Start accepts. Automaton has 496 states and 613 transitions. Word has length 47 [2021-12-17 15:07:44,745 INFO L84 Accepts]: Finished accepts. word is rejected. [2021-12-17 15:07:44,748 INFO L470 AbstractCegarLoop]: Abstraction has 496 states and 613 transitions. [2021-12-17 15:07:44,748 INFO L471 AbstractCegarLoop]: INTERPOLANT automaton has has 7 states, 7 states have (on average 5.714285714285714) internal successors, (40), 5 states have internal predecessors, (40), 2 states have call successors, (4), 3 states have call predecessors, (4), 2 states have return successors, (3), 3 states have call predecessors, (3), 2 states have call successors, (3) [2021-12-17 15:07:44,748 INFO L276 IsEmpty]: Start isEmpty. Operand 496 states and 613 transitions. [2021-12-17 15:07:44,751 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 52 [2021-12-17 15:07:44,751 INFO L506 BasicCegarLoop]: Found error trace [2021-12-17 15:07:44,751 INFO L514 BasicCegarLoop]: trace histogram [1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2021-12-17 15:07:44,752 WARN L452 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable7 [2021-12-17 15:07:44,752 INFO L402 AbstractCegarLoop]: === Iteration 9 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2021-12-17 15:07:44,752 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2021-12-17 15:07:44,752 INFO L85 PathProgramCache]: Analyzing trace with hash 887089017, now seen corresponding path program 1 times [2021-12-17 15:07:44,752 INFO L121 FreeRefinementEngine]: Executing refinement strategy CAMEL [2021-12-17 15:07:44,752 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [1065423902] [2021-12-17 15:07:44,753 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2021-12-17 15:07:44,753 INFO L126 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2021-12-17 15:07:44,779 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:07:44,820 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 14 [2021-12-17 15:07:44,834 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:07:44,839 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 25 [2021-12-17 15:07:44,841 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:07:44,845 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 8 [2021-12-17 15:07:44,846 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:07:44,847 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 41 [2021-12-17 15:07:44,849 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:07:44,851 INFO L134 CoverageAnalysis]: Checked inductivity of 0 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2021-12-17 15:07:44,851 INFO L139 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2021-12-17 15:07:44,851 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [1065423902] [2021-12-17 15:07:44,851 INFO L160 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [1065423902] provided 1 perfect and 0 imperfect interpolant sequences [2021-12-17 15:07:44,852 INFO L186 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2021-12-17 15:07:44,852 INFO L199 FreeRefinementEngine]: Number of different interpolants: perfect sequences [7] imperfect sequences [] total 7 [2021-12-17 15:07:44,852 INFO L115 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [1807751353] [2021-12-17 15:07:44,852 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2021-12-17 15:07:44,852 INFO L546 AbstractCegarLoop]: INTERPOLANT automaton has 7 states [2021-12-17 15:07:44,852 INFO L103 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2021-12-17 15:07:44,859 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 7 interpolants. [2021-12-17 15:07:44,860 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=11, Invalid=31, Unknown=0, NotChecked=0, Total=42 [2021-12-17 15:07:44,860 INFO L87 Difference]: Start difference. First operand 496 states and 613 transitions. Second operand has 7 states, 7 states have (on average 6.0) internal successors, (42), 5 states have internal predecessors, (42), 1 states have call successors, (5), 4 states have call predecessors, (5), 2 states have return successors, (4), 1 states have call predecessors, (4), 1 states have call successors, (4) [2021-12-17 15:07:45,131 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2021-12-17 15:07:45,131 INFO L93 Difference]: Finished difference Result 1000 states and 1247 transitions. [2021-12-17 15:07:45,132 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 15 states. [2021-12-17 15:07:45,132 INFO L78 Accepts]: Start accepts. Automaton has has 7 states, 7 states have (on average 6.0) internal successors, (42), 5 states have internal predecessors, (42), 1 states have call successors, (5), 4 states have call predecessors, (5), 2 states have return successors, (4), 1 states have call predecessors, (4), 1 states have call successors, (4) Word has length 51 [2021-12-17 15:07:45,132 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2021-12-17 15:07:45,134 INFO L225 Difference]: With dead ends: 1000 [2021-12-17 15:07:45,135 INFO L226 Difference]: Without dead ends: 512 [2021-12-17 15:07:45,136 INFO L932 BasicCegarLoop]: 0 DeclaredPredicates, 28 GetRequests, 13 SyntacticMatches, 0 SemanticMatches, 15 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 39 ImplicationChecksByTransitivity, 0.1s TimeCoverageRelationStatistics Valid=84, Invalid=188, Unknown=0, NotChecked=0, Total=272 [2021-12-17 15:07:45,136 INFO L933 BasicCegarLoop]: 85 mSDtfsCounter, 175 mSDsluCounter, 139 mSDsCounter, 0 mSdLazyCounter, 300 mSolverCounterSat, 51 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.2s Time, 0 mProtectedPredicate, 0 mProtectedAction, 177 SdHoareTripleChecker+Valid, 224 SdHoareTripleChecker+Invalid, 351 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 51 IncrementalHoareTripleChecker+Valid, 300 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.2s IncrementalHoareTripleChecker+Time [2021-12-17 15:07:45,137 INFO L934 BasicCegarLoop]: SdHoareTripleChecker [177 Valid, 224 Invalid, 351 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [51 Valid, 300 Invalid, 0 Unknown, 0 Unchecked, 0.2s Time] [2021-12-17 15:07:45,137 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 512 states. [2021-12-17 15:07:45,158 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 512 to 492. [2021-12-17 15:07:45,159 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 492 states, 375 states have (on average 1.2) internal successors, (450), 396 states have internal predecessors, (450), 58 states have call successors, (58), 56 states have call predecessors, (58), 58 states have return successors, (93), 58 states have call predecessors, (93), 58 states have call successors, (93) [2021-12-17 15:07:45,160 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 492 states to 492 states and 601 transitions. [2021-12-17 15:07:45,161 INFO L78 Accepts]: Start accepts. Automaton has 492 states and 601 transitions. Word has length 51 [2021-12-17 15:07:45,161 INFO L84 Accepts]: Finished accepts. word is rejected. [2021-12-17 15:07:45,161 INFO L470 AbstractCegarLoop]: Abstraction has 492 states and 601 transitions. [2021-12-17 15:07:45,161 INFO L471 AbstractCegarLoop]: INTERPOLANT automaton has has 7 states, 7 states have (on average 6.0) internal successors, (42), 5 states have internal predecessors, (42), 1 states have call successors, (5), 4 states have call predecessors, (5), 2 states have return successors, (4), 1 states have call predecessors, (4), 1 states have call successors, (4) [2021-12-17 15:07:45,162 INFO L276 IsEmpty]: Start isEmpty. Operand 492 states and 601 transitions. [2021-12-17 15:07:45,162 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 54 [2021-12-17 15:07:45,163 INFO L506 BasicCegarLoop]: Found error trace [2021-12-17 15:07:45,163 INFO L514 BasicCegarLoop]: trace histogram [1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2021-12-17 15:07:45,163 WARN L452 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable8 [2021-12-17 15:07:45,163 INFO L402 AbstractCegarLoop]: === Iteration 10 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2021-12-17 15:07:45,164 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2021-12-17 15:07:45,164 INFO L85 PathProgramCache]: Analyzing trace with hash 1653053766, now seen corresponding path program 1 times [2021-12-17 15:07:45,164 INFO L121 FreeRefinementEngine]: Executing refinement strategy CAMEL [2021-12-17 15:07:45,164 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [1761279271] [2021-12-17 15:07:45,164 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2021-12-17 15:07:45,164 INFO L126 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2021-12-17 15:07:45,172 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:07:45,189 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 12 [2021-12-17 15:07:45,191 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:07:45,195 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 18 [2021-12-17 15:07:45,196 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:07:45,201 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 29 [2021-12-17 15:07:45,202 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:07:45,204 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 43 [2021-12-17 15:07:45,205 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:07:45,206 INFO L134 CoverageAnalysis]: Checked inductivity of 0 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2021-12-17 15:07:45,207 INFO L139 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2021-12-17 15:07:45,207 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [1761279271] [2021-12-17 15:07:45,207 INFO L160 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [1761279271] provided 1 perfect and 0 imperfect interpolant sequences [2021-12-17 15:07:45,207 INFO L186 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2021-12-17 15:07:45,207 INFO L199 FreeRefinementEngine]: Number of different interpolants: perfect sequences [6] imperfect sequences [] total 6 [2021-12-17 15:07:45,207 INFO L115 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [593033295] [2021-12-17 15:07:45,208 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2021-12-17 15:07:45,208 INFO L546 AbstractCegarLoop]: INTERPOLANT automaton has 6 states [2021-12-17 15:07:45,208 INFO L103 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2021-12-17 15:07:45,208 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 6 interpolants. [2021-12-17 15:07:45,209 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=9, Invalid=21, Unknown=0, NotChecked=0, Total=30 [2021-12-17 15:07:45,209 INFO L87 Difference]: Start difference. First operand 492 states and 601 transitions. Second operand has 6 states, 6 states have (on average 7.333333333333333) internal successors, (44), 3 states have internal predecessors, (44), 1 states have call successors, (5), 5 states have call predecessors, (5), 1 states have return successors, (4), 1 states have call predecessors, (4), 1 states have call successors, (4) [2021-12-17 15:07:45,511 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2021-12-17 15:07:45,511 INFO L93 Difference]: Finished difference Result 869 states and 1079 transitions. [2021-12-17 15:07:45,511 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 13 states. [2021-12-17 15:07:45,512 INFO L78 Accepts]: Start accepts. Automaton has has 6 states, 6 states have (on average 7.333333333333333) internal successors, (44), 3 states have internal predecessors, (44), 1 states have call successors, (5), 5 states have call predecessors, (5), 1 states have return successors, (4), 1 states have call predecessors, (4), 1 states have call successors, (4) Word has length 53 [2021-12-17 15:07:45,512 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2021-12-17 15:07:45,515 INFO L225 Difference]: With dead ends: 869 [2021-12-17 15:07:45,515 INFO L226 Difference]: Without dead ends: 867 [2021-12-17 15:07:45,516 INFO L932 BasicCegarLoop]: 0 DeclaredPredicates, 29 GetRequests, 16 SyntacticMatches, 0 SemanticMatches, 13 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 35 ImplicationChecksByTransitivity, 0.1s TimeCoverageRelationStatistics Valid=67, Invalid=143, Unknown=0, NotChecked=0, Total=210 [2021-12-17 15:07:45,516 INFO L933 BasicCegarLoop]: 91 mSDtfsCounter, 378 mSDsluCounter, 102 mSDsCounter, 0 mSdLazyCounter, 227 mSolverCounterSat, 144 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.2s Time, 0 mProtectedPredicate, 0 mProtectedAction, 379 SdHoareTripleChecker+Valid, 193 SdHoareTripleChecker+Invalid, 371 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 144 IncrementalHoareTripleChecker+Valid, 227 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.2s IncrementalHoareTripleChecker+Time [2021-12-17 15:07:45,516 INFO L934 BasicCegarLoop]: SdHoareTripleChecker [379 Valid, 193 Invalid, 371 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [144 Valid, 227 Invalid, 0 Unknown, 0 Unchecked, 0.2s Time] [2021-12-17 15:07:45,517 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 867 states. [2021-12-17 15:07:45,539 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 867 to 701. [2021-12-17 15:07:45,540 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 701 states, 538 states have (on average 1.204460966542751) internal successors, (648), 574 states have internal predecessors, (648), 80 states have call successors, (80), 70 states have call predecessors, (80), 82 states have return successors, (146), 79 states have call predecessors, (146), 80 states have call successors, (146) [2021-12-17 15:07:45,542 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 701 states to 701 states and 874 transitions. [2021-12-17 15:07:45,542 INFO L78 Accepts]: Start accepts. Automaton has 701 states and 874 transitions. Word has length 53 [2021-12-17 15:07:45,542 INFO L84 Accepts]: Finished accepts. word is rejected. [2021-12-17 15:07:45,543 INFO L470 AbstractCegarLoop]: Abstraction has 701 states and 874 transitions. [2021-12-17 15:07:45,543 INFO L471 AbstractCegarLoop]: INTERPOLANT automaton has has 6 states, 6 states have (on average 7.333333333333333) internal successors, (44), 3 states have internal predecessors, (44), 1 states have call successors, (5), 5 states have call predecessors, (5), 1 states have return successors, (4), 1 states have call predecessors, (4), 1 states have call successors, (4) [2021-12-17 15:07:45,543 INFO L276 IsEmpty]: Start isEmpty. Operand 701 states and 874 transitions. [2021-12-17 15:07:45,544 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 93 [2021-12-17 15:07:45,544 INFO L506 BasicCegarLoop]: Found error trace [2021-12-17 15:07:45,545 INFO L514 BasicCegarLoop]: trace histogram [2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2021-12-17 15:07:45,545 WARN L452 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable9 [2021-12-17 15:07:45,545 INFO L402 AbstractCegarLoop]: === Iteration 11 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2021-12-17 15:07:45,545 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2021-12-17 15:07:45,545 INFO L85 PathProgramCache]: Analyzing trace with hash 1975485720, now seen corresponding path program 1 times [2021-12-17 15:07:45,546 INFO L121 FreeRefinementEngine]: Executing refinement strategy CAMEL [2021-12-17 15:07:45,546 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [303784354] [2021-12-17 15:07:45,546 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2021-12-17 15:07:45,546 INFO L126 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2021-12-17 15:07:45,561 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:07:45,582 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 12 [2021-12-17 15:07:45,583 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:07:45,587 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 18 [2021-12-17 15:07:45,587 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:07:45,594 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 25 [2021-12-17 15:07:45,596 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:07:45,631 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 3 [2021-12-17 15:07:45,633 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:07:45,636 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 17 [2021-12-17 15:07:45,637 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:07:45,638 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 68 [2021-12-17 15:07:45,639 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:07:45,641 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 82 [2021-12-17 15:07:45,641 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:07:45,643 INFO L134 CoverageAnalysis]: Checked inductivity of 36 backedges. 19 proven. 6 refuted. 0 times theorem prover too weak. 11 trivial. 0 not checked. [2021-12-17 15:07:45,643 INFO L139 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2021-12-17 15:07:45,643 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [303784354] [2021-12-17 15:07:45,643 INFO L160 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [303784354] provided 0 perfect and 1 imperfect interpolant sequences [2021-12-17 15:07:45,643 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleZ3 [1460959858] [2021-12-17 15:07:45,643 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2021-12-17 15:07:45,644 INFO L168 SolverBuilder]: Constructing external solver with command: z3 -smt2 -in SMTLIB2_COMPLIANT=true [2021-12-17 15:07:45,644 INFO L189 MonitoredProcess]: No working directory specified, using /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 [2021-12-17 15:07:45,645 INFO L229 MonitoredProcess]: Starting monitored process 2 with /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 -smt2 -in SMTLIB2_COMPLIANT=true (exit command is (exit), workingDir is null) [2021-12-17 15:07:45,707 INFO L327 MonitoredProcess]: [MP /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 -smt2 -in SMTLIB2_COMPLIANT=true (2)] Waiting until timeout for monitored process [2021-12-17 15:07:45,769 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:07:45,771 INFO L263 TraceCheckSpWp]: Trace formula consists of 472 conjuncts, 4 conjunts are in the unsatisfiable core [2021-12-17 15:07:45,777 INFO L286 TraceCheckSpWp]: Computing forward predicates... [2021-12-17 15:07:46,042 INFO L134 CoverageAnalysis]: Checked inductivity of 36 backedges. 36 proven. 0 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2021-12-17 15:07:46,043 INFO L324 TraceCheckSpWp]: Omiting computation of backward sequence because forward sequence was already perfect [2021-12-17 15:07:46,043 INFO L160 FreeRefinementEngine]: IpTcStrategyModuleZ3 [1460959858] provided 1 perfect and 0 imperfect interpolant sequences [2021-12-17 15:07:46,043 INFO L186 FreeRefinementEngine]: Found 1 perfect and 1 imperfect interpolant sequences. [2021-12-17 15:07:46,043 INFO L199 FreeRefinementEngine]: Number of different interpolants: perfect sequences [3] imperfect sequences [9] total 9 [2021-12-17 15:07:46,043 INFO L115 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [27109968] [2021-12-17 15:07:46,044 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2021-12-17 15:07:46,044 INFO L546 AbstractCegarLoop]: INTERPOLANT automaton has 3 states [2021-12-17 15:07:46,044 INFO L103 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2021-12-17 15:07:46,044 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 3 interpolants. [2021-12-17 15:07:46,045 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=18, Invalid=54, Unknown=0, NotChecked=0, Total=72 [2021-12-17 15:07:46,045 INFO L87 Difference]: Start difference. First operand 701 states and 874 transitions. Second operand has 3 states, 3 states have (on average 25.666666666666668) internal successors, (77), 3 states have internal predecessors, (77), 3 states have call successors, (8), 3 states have call predecessors, (8), 3 states have return successors, (7), 3 states have call predecessors, (7), 3 states have call successors, (7) [2021-12-17 15:07:46,077 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2021-12-17 15:07:46,077 INFO L93 Difference]: Finished difference Result 1249 states and 1576 transitions. [2021-12-17 15:07:46,077 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 3 states. [2021-12-17 15:07:46,078 INFO L78 Accepts]: Start accepts. Automaton has has 3 states, 3 states have (on average 25.666666666666668) internal successors, (77), 3 states have internal predecessors, (77), 3 states have call successors, (8), 3 states have call predecessors, (8), 3 states have return successors, (7), 3 states have call predecessors, (7), 3 states have call successors, (7) Word has length 92 [2021-12-17 15:07:46,078 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2021-12-17 15:07:46,081 INFO L225 Difference]: With dead ends: 1249 [2021-12-17 15:07:46,081 INFO L226 Difference]: Without dead ends: 652 [2021-12-17 15:07:46,083 INFO L932 BasicCegarLoop]: 0 DeclaredPredicates, 112 GetRequests, 105 SyntacticMatches, 0 SemanticMatches, 7 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 3 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=18, Invalid=54, Unknown=0, NotChecked=0, Total=72 [2021-12-17 15:07:46,084 INFO L933 BasicCegarLoop]: 131 mSDtfsCounter, 38 mSDsluCounter, 63 mSDsCounter, 0 mSdLazyCounter, 10 mSolverCounterSat, 0 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.0s Time, 0 mProtectedPredicate, 0 mProtectedAction, 38 SdHoareTripleChecker+Valid, 194 SdHoareTripleChecker+Invalid, 10 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 0 IncrementalHoareTripleChecker+Valid, 10 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.0s IncrementalHoareTripleChecker+Time [2021-12-17 15:07:46,084 INFO L934 BasicCegarLoop]: SdHoareTripleChecker [38 Valid, 194 Invalid, 10 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [0 Valid, 10 Invalid, 0 Unknown, 0 Unchecked, 0.0s Time] [2021-12-17 15:07:46,085 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 652 states. [2021-12-17 15:07:46,108 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 652 to 652. [2021-12-17 15:07:46,109 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 652 states, 500 states have (on average 1.196) internal successors, (598), 534 states have internal predecessors, (598), 75 states have call successors, (75), 65 states have call predecessors, (75), 76 states have return successors, (119), 75 states have call predecessors, (119), 75 states have call successors, (119) [2021-12-17 15:07:46,112 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 652 states to 652 states and 792 transitions. [2021-12-17 15:07:46,113 INFO L78 Accepts]: Start accepts. Automaton has 652 states and 792 transitions. Word has length 92 [2021-12-17 15:07:46,113 INFO L84 Accepts]: Finished accepts. word is rejected. [2021-12-17 15:07:46,113 INFO L470 AbstractCegarLoop]: Abstraction has 652 states and 792 transitions. [2021-12-17 15:07:46,114 INFO L471 AbstractCegarLoop]: INTERPOLANT automaton has has 3 states, 3 states have (on average 25.666666666666668) internal successors, (77), 3 states have internal predecessors, (77), 3 states have call successors, (8), 3 states have call predecessors, (8), 3 states have return successors, (7), 3 states have call predecessors, (7), 3 states have call successors, (7) [2021-12-17 15:07:46,114 INFO L276 IsEmpty]: Start isEmpty. Operand 652 states and 792 transitions. [2021-12-17 15:07:46,116 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 96 [2021-12-17 15:07:46,116 INFO L506 BasicCegarLoop]: Found error trace [2021-12-17 15:07:46,117 INFO L514 BasicCegarLoop]: trace histogram [2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2021-12-17 15:07:46,139 INFO L540 MonitoredProcess]: [MP /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 -smt2 -in SMTLIB2_COMPLIANT=true (2)] Forceful destruction successful, exit code 0 [2021-12-17 15:07:46,336 WARN L452 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: 2 /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 -smt2 -in SMTLIB2_COMPLIANT=true,SelfDestructingSolverStorable10 [2021-12-17 15:07:46,337 INFO L402 AbstractCegarLoop]: === Iteration 12 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2021-12-17 15:07:46,337 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2021-12-17 15:07:46,337 INFO L85 PathProgramCache]: Analyzing trace with hash 1543524338, now seen corresponding path program 1 times [2021-12-17 15:07:46,337 INFO L121 FreeRefinementEngine]: Executing refinement strategy CAMEL [2021-12-17 15:07:46,337 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [784633280] [2021-12-17 15:07:46,337 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2021-12-17 15:07:46,337 INFO L126 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2021-12-17 15:07:46,378 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:07:46,452 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 12 [2021-12-17 15:07:46,453 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:07:46,465 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 18 [2021-12-17 15:07:46,465 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:07:46,487 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 25 [2021-12-17 15:07:46,490 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:07:46,507 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 3 [2021-12-17 15:07:46,510 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:07:46,518 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 17 [2021-12-17 15:07:46,521 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:07:46,523 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 75 [2021-12-17 15:07:46,525 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:07:46,527 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 2 [2021-12-17 15:07:46,535 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:07:46,540 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 85 [2021-12-17 15:07:46,541 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:07:46,545 INFO L134 CoverageAnalysis]: Checked inductivity of 28 backedges. 20 proven. 3 refuted. 0 times theorem prover too weak. 5 trivial. 0 not checked. [2021-12-17 15:07:46,545 INFO L139 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2021-12-17 15:07:46,546 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [784633280] [2021-12-17 15:07:46,546 INFO L160 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [784633280] provided 0 perfect and 1 imperfect interpolant sequences [2021-12-17 15:07:46,546 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleZ3 [1912699963] [2021-12-17 15:07:46,547 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2021-12-17 15:07:46,547 INFO L168 SolverBuilder]: Constructing external solver with command: z3 -smt2 -in SMTLIB2_COMPLIANT=true [2021-12-17 15:07:46,547 INFO L189 MonitoredProcess]: No working directory specified, using /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 [2021-12-17 15:07:46,557 INFO L229 MonitoredProcess]: Starting monitored process 3 with /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 -smt2 -in SMTLIB2_COMPLIANT=true (exit command is (exit), workingDir is null) [2021-12-17 15:07:46,559 INFO L327 MonitoredProcess]: [MP /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 -smt2 -in SMTLIB2_COMPLIANT=true (3)] Waiting until timeout for monitored process [2021-12-17 15:07:46,647 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:07:46,650 INFO L263 TraceCheckSpWp]: Trace formula consists of 474 conjuncts, 11 conjunts are in the unsatisfiable core [2021-12-17 15:07:46,656 INFO L286 TraceCheckSpWp]: Computing forward predicates... [2021-12-17 15:07:46,848 INFO L134 CoverageAnalysis]: Checked inductivity of 28 backedges. 28 proven. 0 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2021-12-17 15:07:46,848 INFO L324 TraceCheckSpWp]: Omiting computation of backward sequence because forward sequence was already perfect [2021-12-17 15:07:46,848 INFO L160 FreeRefinementEngine]: IpTcStrategyModuleZ3 [1912699963] provided 1 perfect and 0 imperfect interpolant sequences [2021-12-17 15:07:46,848 INFO L186 FreeRefinementEngine]: Found 1 perfect and 1 imperfect interpolant sequences. [2021-12-17 15:07:46,848 INFO L199 FreeRefinementEngine]: Number of different interpolants: perfect sequences [6] imperfect sequences [10] total 11 [2021-12-17 15:07:46,848 INFO L115 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [1601990117] [2021-12-17 15:07:46,848 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2021-12-17 15:07:46,849 INFO L546 AbstractCegarLoop]: INTERPOLANT automaton has 6 states [2021-12-17 15:07:46,849 INFO L103 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2021-12-17 15:07:46,849 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 6 interpolants. [2021-12-17 15:07:46,849 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=24, Invalid=86, Unknown=0, NotChecked=0, Total=110 [2021-12-17 15:07:46,849 INFO L87 Difference]: Start difference. First operand 652 states and 792 transitions. Second operand has 6 states, 6 states have (on average 13.0) internal successors, (78), 6 states have internal predecessors, (78), 3 states have call successors, (9), 3 states have call predecessors, (9), 3 states have return successors, (8), 3 states have call predecessors, (8), 3 states have call successors, (8) [2021-12-17 15:07:46,942 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2021-12-17 15:07:46,942 INFO L93 Difference]: Finished difference Result 1673 states and 2133 transitions. [2021-12-17 15:07:46,942 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 7 states. [2021-12-17 15:07:46,942 INFO L78 Accepts]: Start accepts. Automaton has has 6 states, 6 states have (on average 13.0) internal successors, (78), 6 states have internal predecessors, (78), 3 states have call successors, (9), 3 states have call predecessors, (9), 3 states have return successors, (8), 3 states have call predecessors, (8), 3 states have call successors, (8) Word has length 95 [2021-12-17 15:07:46,943 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2021-12-17 15:07:46,946 INFO L225 Difference]: With dead ends: 1673 [2021-12-17 15:07:46,946 INFO L226 Difference]: Without dead ends: 1125 [2021-12-17 15:07:46,948 INFO L932 BasicCegarLoop]: 0 DeclaredPredicates, 121 GetRequests, 108 SyntacticMatches, 2 SemanticMatches, 11 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 13 ImplicationChecksByTransitivity, 0.1s TimeCoverageRelationStatistics Valid=36, Invalid=120, Unknown=0, NotChecked=0, Total=156 [2021-12-17 15:07:46,948 INFO L933 BasicCegarLoop]: 162 mSDtfsCounter, 173 mSDsluCounter, 470 mSDsCounter, 0 mSdLazyCounter, 54 mSolverCounterSat, 26 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.0s Time, 0 mProtectedPredicate, 0 mProtectedAction, 175 SdHoareTripleChecker+Valid, 632 SdHoareTripleChecker+Invalid, 80 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 26 IncrementalHoareTripleChecker+Valid, 54 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.0s IncrementalHoareTripleChecker+Time [2021-12-17 15:07:46,948 INFO L934 BasicCegarLoop]: SdHoareTripleChecker [175 Valid, 632 Invalid, 80 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [26 Valid, 54 Invalid, 0 Unknown, 0 Unchecked, 0.0s Time] [2021-12-17 15:07:46,949 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 1125 states. [2021-12-17 15:07:46,979 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 1125 to 920. [2021-12-17 15:07:46,980 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 920 states, 703 states have (on average 1.1963015647226174) internal successors, (841), 750 states have internal predecessors, (841), 107 states have call successors, (107), 95 states have call predecessors, (107), 109 states have return successors, (173), 102 states have call predecessors, (173), 107 states have call successors, (173) [2021-12-17 15:07:46,983 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 920 states to 920 states and 1121 transitions. [2021-12-17 15:07:46,983 INFO L78 Accepts]: Start accepts. Automaton has 920 states and 1121 transitions. Word has length 95 [2021-12-17 15:07:46,983 INFO L84 Accepts]: Finished accepts. word is rejected. [2021-12-17 15:07:46,983 INFO L470 AbstractCegarLoop]: Abstraction has 920 states and 1121 transitions. [2021-12-17 15:07:46,983 INFO L471 AbstractCegarLoop]: INTERPOLANT automaton has has 6 states, 6 states have (on average 13.0) internal successors, (78), 6 states have internal predecessors, (78), 3 states have call successors, (9), 3 states have call predecessors, (9), 3 states have return successors, (8), 3 states have call predecessors, (8), 3 states have call successors, (8) [2021-12-17 15:07:46,983 INFO L276 IsEmpty]: Start isEmpty. Operand 920 states and 1121 transitions. [2021-12-17 15:07:46,984 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 96 [2021-12-17 15:07:46,985 INFO L506 BasicCegarLoop]: Found error trace [2021-12-17 15:07:46,985 INFO L514 BasicCegarLoop]: trace histogram [2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2021-12-17 15:07:47,003 INFO L552 MonitoredProcess]: [MP /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 -smt2 -in SMTLIB2_COMPLIANT=true (3)] Ended with exit code 0 [2021-12-17 15:07:47,199 WARN L452 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: 3 /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 -smt2 -in SMTLIB2_COMPLIANT=true,SelfDestructingSolverStorable11 [2021-12-17 15:07:47,199 INFO L402 AbstractCegarLoop]: === Iteration 13 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2021-12-17 15:07:47,200 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2021-12-17 15:07:47,200 INFO L85 PathProgramCache]: Analyzing trace with hash 1409510832, now seen corresponding path program 1 times [2021-12-17 15:07:47,200 INFO L121 FreeRefinementEngine]: Executing refinement strategy CAMEL [2021-12-17 15:07:47,200 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [150335619] [2021-12-17 15:07:47,200 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2021-12-17 15:07:47,200 INFO L126 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2021-12-17 15:07:47,208 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:07:47,231 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 12 [2021-12-17 15:07:47,231 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:07:47,236 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 18 [2021-12-17 15:07:47,237 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:07:47,244 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 25 [2021-12-17 15:07:47,246 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:07:47,252 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 3 [2021-12-17 15:07:47,252 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:07:47,255 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 17 [2021-12-17 15:07:47,255 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:07:47,256 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 75 [2021-12-17 15:07:47,257 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:07:47,258 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 2 [2021-12-17 15:07:47,258 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:07:47,259 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 85 [2021-12-17 15:07:47,259 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:07:47,262 INFO L134 CoverageAnalysis]: Checked inductivity of 28 backedges. 8 proven. 1 refuted. 0 times theorem prover too weak. 19 trivial. 0 not checked. [2021-12-17 15:07:47,262 INFO L139 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2021-12-17 15:07:47,262 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [150335619] [2021-12-17 15:07:47,262 INFO L160 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [150335619] provided 0 perfect and 1 imperfect interpolant sequences [2021-12-17 15:07:47,262 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleZ3 [365995225] [2021-12-17 15:07:47,262 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2021-12-17 15:07:47,262 INFO L168 SolverBuilder]: Constructing external solver with command: z3 -smt2 -in SMTLIB2_COMPLIANT=true [2021-12-17 15:07:47,262 INFO L189 MonitoredProcess]: No working directory specified, using /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 [2021-12-17 15:07:47,275 INFO L229 MonitoredProcess]: Starting monitored process 4 with /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 -smt2 -in SMTLIB2_COMPLIANT=true (exit command is (exit), workingDir is null) [2021-12-17 15:07:47,276 INFO L327 MonitoredProcess]: [MP /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 -smt2 -in SMTLIB2_COMPLIANT=true (4)] Waiting until timeout for monitored process [2021-12-17 15:07:47,355 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:07:47,357 INFO L263 TraceCheckSpWp]: Trace formula consists of 475 conjuncts, 5 conjunts are in the unsatisfiable core [2021-12-17 15:07:47,358 INFO L286 TraceCheckSpWp]: Computing forward predicates... [2021-12-17 15:07:47,490 INFO L134 CoverageAnalysis]: Checked inductivity of 28 backedges. 15 proven. 0 refuted. 0 times theorem prover too weak. 13 trivial. 0 not checked. [2021-12-17 15:07:47,490 INFO L324 TraceCheckSpWp]: Omiting computation of backward sequence because forward sequence was already perfect [2021-12-17 15:07:47,491 INFO L160 FreeRefinementEngine]: IpTcStrategyModuleZ3 [365995225] provided 1 perfect and 0 imperfect interpolant sequences [2021-12-17 15:07:47,491 INFO L186 FreeRefinementEngine]: Found 1 perfect and 1 imperfect interpolant sequences. [2021-12-17 15:07:47,491 INFO L199 FreeRefinementEngine]: Number of different interpolants: perfect sequences [5] imperfect sequences [9] total 12 [2021-12-17 15:07:47,491 INFO L115 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [506874985] [2021-12-17 15:07:47,491 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2021-12-17 15:07:47,491 INFO L546 AbstractCegarLoop]: INTERPOLANT automaton has 5 states [2021-12-17 15:07:47,491 INFO L103 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2021-12-17 15:07:47,491 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 5 interpolants. [2021-12-17 15:07:47,492 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=26, Invalid=106, Unknown=0, NotChecked=0, Total=132 [2021-12-17 15:07:47,492 INFO L87 Difference]: Start difference. First operand 920 states and 1121 transitions. Second operand has 5 states, 5 states have (on average 14.0) internal successors, (70), 5 states have internal predecessors, (70), 2 states have call successors, (8), 2 states have call predecessors, (8), 2 states have return successors, (8), 2 states have call predecessors, (8), 2 states have call successors, (8) [2021-12-17 15:07:47,546 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2021-12-17 15:07:47,546 INFO L93 Difference]: Finished difference Result 1261 states and 1532 transitions. [2021-12-17 15:07:47,547 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 5 states. [2021-12-17 15:07:47,547 INFO L78 Accepts]: Start accepts. Automaton has has 5 states, 5 states have (on average 14.0) internal successors, (70), 5 states have internal predecessors, (70), 2 states have call successors, (8), 2 states have call predecessors, (8), 2 states have return successors, (8), 2 states have call predecessors, (8), 2 states have call successors, (8) Word has length 95 [2021-12-17 15:07:47,548 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2021-12-17 15:07:47,548 INFO L225 Difference]: With dead ends: 1261 [2021-12-17 15:07:47,548 INFO L226 Difference]: Without dead ends: 0 [2021-12-17 15:07:47,550 INFO L932 BasicCegarLoop]: 0 DeclaredPredicates, 118 GetRequests, 106 SyntacticMatches, 0 SemanticMatches, 12 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 12 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=36, Invalid=146, Unknown=0, NotChecked=0, Total=182 [2021-12-17 15:07:47,550 INFO L933 BasicCegarLoop]: 89 mSDtfsCounter, 36 mSDsluCounter, 230 mSDsCounter, 0 mSdLazyCounter, 7 mSolverCounterSat, 3 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.0s Time, 0 mProtectedPredicate, 0 mProtectedAction, 36 SdHoareTripleChecker+Valid, 319 SdHoareTripleChecker+Invalid, 10 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 3 IncrementalHoareTripleChecker+Valid, 7 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.0s IncrementalHoareTripleChecker+Time [2021-12-17 15:07:47,550 INFO L934 BasicCegarLoop]: SdHoareTripleChecker [36 Valid, 319 Invalid, 10 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [3 Valid, 7 Invalid, 0 Unknown, 0 Unchecked, 0.0s Time] [2021-12-17 15:07:47,550 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 0 states. [2021-12-17 15:07:47,551 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 0 to 0. [2021-12-17 15:07:47,551 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 0 states, 0 states have (on average 0.0) internal successors, (0), 0 states have internal predecessors, (0), 0 states have call successors, (0), 0 states have call predecessors, (0), 0 states have return successors, (0), 0 states have call predecessors, (0), 0 states have call successors, (0) [2021-12-17 15:07:47,551 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 0 states to 0 states and 0 transitions. [2021-12-17 15:07:47,551 INFO L78 Accepts]: Start accepts. Automaton has 0 states and 0 transitions. Word has length 95 [2021-12-17 15:07:47,551 INFO L84 Accepts]: Finished accepts. word is rejected. [2021-12-17 15:07:47,551 INFO L470 AbstractCegarLoop]: Abstraction has 0 states and 0 transitions. [2021-12-17 15:07:47,551 INFO L471 AbstractCegarLoop]: INTERPOLANT automaton has has 5 states, 5 states have (on average 14.0) internal successors, (70), 5 states have internal predecessors, (70), 2 states have call successors, (8), 2 states have call predecessors, (8), 2 states have return successors, (8), 2 states have call predecessors, (8), 2 states have call successors, (8) [2021-12-17 15:07:47,551 INFO L276 IsEmpty]: Start isEmpty. Operand 0 states and 0 transitions. [2021-12-17 15:07:47,551 INFO L282 IsEmpty]: Finished isEmpty. No accepting run. [2021-12-17 15:07:47,553 INFO L764 garLoopResultBuilder]: Registering result SAFE for location timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION (0 of 1 remaining) [2021-12-17 15:07:47,572 INFO L540 MonitoredProcess]: [MP /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 -smt2 -in SMTLIB2_COMPLIANT=true (4)] Forceful destruction successful, exit code 0 [2021-12-17 15:07:47,770 WARN L452 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable12,4 /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 -smt2 -in SMTLIB2_COMPLIANT=true [2021-12-17 15:07:47,772 INFO L343 DoubleDeckerVisitor]: Before removal of dead ends 0 states and 0 transitions. [2021-12-17 15:07:50,800 INFO L858 garLoopResultBuilder]: For program point processEnvironment__wrappee__baseEXIT(lines 371 377) no Hoare annotation was computed. [2021-12-17 15:07:50,800 INFO L861 garLoopResultBuilder]: At program point processEnvironment__wrappee__baseFINAL(lines 371 377) the Hoare annotation is: true [2021-12-17 15:07:50,800 INFO L854 garLoopResultBuilder]: At program point changeMethaneLevelENTRY(lines 264 275) the Hoare annotation is: (let ((.cse0 (= ~methaneLevelCritical~0 |old(~methaneLevelCritical~0)|)) (.cse1 (not (= ~systemActive~0 1)))) (and (or (not (= ~pumpRunning~0 0)) .cse0 (not (<= 1 ~waterLevel~0)) (not (= ~methAndRunningLastTime~0 0)) .cse1) (or .cse0 (not (<= 1 ~pumpRunning~0)) .cse1 (not (<= 2 ~waterLevel~0))))) [2021-12-17 15:07:50,800 INFO L858 garLoopResultBuilder]: For program point L268-1(lines 264 275) no Hoare annotation was computed. [2021-12-17 15:07:50,800 INFO L858 garLoopResultBuilder]: For program point changeMethaneLevelEXIT(lines 264 275) no Hoare annotation was computed. [2021-12-17 15:07:50,800 INFO L861 garLoopResultBuilder]: At program point isMethaneLevelCriticalENTRY(lines 276 284) the Hoare annotation is: true [2021-12-17 15:07:50,800 INFO L858 garLoopResultBuilder]: For program point isMethaneLevelCriticalFINAL(lines 276 284) no Hoare annotation was computed. [2021-12-17 15:07:50,800 INFO L858 garLoopResultBuilder]: For program point isMethaneLevelCriticalEXIT(lines 276 284) no Hoare annotation was computed. [2021-12-17 15:07:50,801 INFO L854 garLoopResultBuilder]: At program point L209(line 209) the Hoare annotation is: (let ((.cse1 (= ~methAndRunningLastTime~0 0)) (.cse0 (not (= |old(~pumpRunning~0)| 0))) (.cse3 (not (= |old(~methAndRunningLastTime~0)| 0))) (.cse2 (not (= ~systemActive~0 1))) (.cse5 (= ~pumpRunning~0 0))) (and (or (not (= |old(~waterLevel~0)| 1)) .cse0 .cse1 .cse2 .cse3) (let ((.cse4 (= ~waterLevel~0 |old(~waterLevel~0)|))) (or (and .cse4 (<= 1 ~pumpRunning~0) (<= 2 ~waterLevel~0) .cse1) (and .cse4 .cse5) .cse0 .cse2 (not (<= 1 |old(~waterLevel~0)|)) .cse3)) (or (not (<= 2 |old(~waterLevel~0)|)) .cse2 (and (<= 1 |timeShift_isLowWaterLevel_~tmp___0~2#1|) (<= 1 |timeShift_isLowWaterLevel_#res#1|) (= |timeShift_isLowWaterSensorDry_#res#1| 0) (<= 1 |timeShift_processEnvironment_~tmp~3#1|) (<= 1 ~waterLevel~0) (= |timeShift_isLowWaterLevel_~tmp~5#1| 0) .cse5) (not (<= 1 |old(~pumpRunning~0)|))))) [2021-12-17 15:07:50,801 INFO L858 garLoopResultBuilder]: For program point L209-1(line 209) no Hoare annotation was computed. [2021-12-17 15:07:50,801 INFO L854 garLoopResultBuilder]: At program point L424(line 424) the Hoare annotation is: (let ((.cse0 (not (= ~systemActive~0 1)))) (and (or (not (<= 2 |old(~waterLevel~0)|)) .cse0 (not (<= 1 |old(~pumpRunning~0)|))) (or (not (= |old(~pumpRunning~0)| 0)) (and (= ~waterLevel~0 |old(~waterLevel~0)|) (= ~methAndRunningLastTime~0 0) (= ~pumpRunning~0 0)) .cse0 (not (<= 1 |old(~waterLevel~0)|)) (not (= |old(~methAndRunningLastTime~0)| 0))))) [2021-12-17 15:07:50,801 INFO L854 garLoopResultBuilder]: At program point L424-1(lines 405 429) the Hoare annotation is: (let ((.cse1 (= ~methAndRunningLastTime~0 0)) (.cse0 (not (= |old(~pumpRunning~0)| 0))) (.cse3 (not (= |old(~methAndRunningLastTime~0)| 0))) (.cse2 (not (= ~systemActive~0 1))) (.cse5 (= ~pumpRunning~0 0))) (and (or (not (= |old(~waterLevel~0)| 1)) .cse0 .cse1 .cse2 .cse3) (let ((.cse4 (= ~waterLevel~0 |old(~waterLevel~0)|))) (or (and .cse4 (<= 1 ~pumpRunning~0) (<= 2 ~waterLevel~0) .cse1) (and .cse4 .cse5) .cse0 .cse2 (not (<= 1 |old(~waterLevel~0)|)) .cse3)) (or (not (<= 2 |old(~waterLevel~0)|)) .cse2 (and (<= 1 |timeShift_isLowWaterLevel_~tmp___0~2#1|) (<= 1 |timeShift_isLowWaterLevel_#res#1|) (= |timeShift_isLowWaterSensorDry_#res#1| 0) (<= 1 |timeShift_processEnvironment_~tmp~3#1|) (<= 1 ~waterLevel~0) (= |timeShift_isLowWaterLevel_~tmp~5#1| 0) .cse5) (not (<= 1 |old(~pumpRunning~0)|))))) [2021-12-17 15:07:50,801 INFO L858 garLoopResultBuilder]: For program point timeShiftFINAL(lines 347 370) no Hoare annotation was computed. [2021-12-17 15:07:50,801 INFO L858 garLoopResultBuilder]: For program point L358-1(lines 358 364) no Hoare annotation was computed. [2021-12-17 15:07:50,801 INFO L858 garLoopResultBuilder]: For program point L986(line 986) no Hoare annotation was computed. [2021-12-17 15:07:50,801 INFO L854 garLoopResultBuilder]: At program point L536(lines 521 539) the Hoare annotation is: (let ((.cse0 (not (<= 2 |old(~waterLevel~0)|))) (.cse2 (not (<= 1 |old(~pumpRunning~0)|))) (.cse1 (not (= ~systemActive~0 1))) (.cse3 (not (= |old(~methAndRunningLastTime~0)| 0)))) (and (or .cse0 (and (<= 1 |timeShift_isLowWaterLevel_~tmp___0~2#1|) (<= 1 |timeShift_isLowWaterLevel_#res#1|) (= ~pumpRunning~0 |old(~pumpRunning~0)|) (= |timeShift_isLowWaterSensorDry_#res#1| 0) (<= 1 ~waterLevel~0) (= |timeShift_isLowWaterLevel_~tmp~5#1| 0)) .cse1 .cse2) (or .cse0 (= ~methAndRunningLastTime~0 0) .cse1 .cse2 .cse3) (or (not (= |old(~pumpRunning~0)| 0)) .cse1 (not (<= 1 |old(~waterLevel~0)|)) .cse3))) [2021-12-17 15:07:50,801 INFO L854 garLoopResultBuilder]: At program point L462(lines 457 465) the Hoare annotation is: (let ((.cse5 (= ~methAndRunningLastTime~0 0)) (.cse0 (not (<= 2 |old(~waterLevel~0)|))) (.cse8 (= |timeShift_isPumpRunning_#res#1| 0)) (.cse9 (= ~pumpRunning~0 0)) (.cse3 (not (<= 1 |old(~pumpRunning~0)|))) (.cse4 (not (= |old(~pumpRunning~0)| 0))) (.cse1 (not (= ~methaneLevelCritical~0 0))) (.cse2 (not (= ~systemActive~0 1))) (.cse10 (not (<= 1 |old(~waterLevel~0)|))) (.cse6 (not (= |old(~methAndRunningLastTime~0)| 0)))) (and (or .cse0 .cse1 .cse2 .cse3) (or (not (= |old(~waterLevel~0)| 1)) .cse4 .cse5 .cse2 .cse6) (let ((.cse7 (= ~waterLevel~0 |old(~waterLevel~0)|))) (or (and .cse7 (<= 1 ~pumpRunning~0) (<= 2 ~waterLevel~0) .cse5) (and .cse8 .cse7 .cse9) .cse4 .cse2 .cse10 .cse6)) (or .cse0 (and (<= 1 |timeShift_isLowWaterLevel_~tmp___0~2#1|) .cse8 (<= 1 |timeShift_isLowWaterLevel_#res#1|) (= |timeShift_isLowWaterSensorDry_#res#1| 0) (<= 1 |timeShift_processEnvironment_~tmp~3#1|) (<= 1 ~waterLevel~0) (= |timeShift_isLowWaterLevel_~tmp~5#1| 0) .cse9) .cse2 .cse3) (or .cse4 .cse1 .cse2 .cse10 .cse6))) [2021-12-17 15:07:50,801 INFO L858 garLoopResultBuilder]: For program point L351-1(lines 350 369) no Hoare annotation was computed. [2021-12-17 15:07:50,801 INFO L858 garLoopResultBuilder]: For program point L413(lines 413 421) no Hoare annotation was computed. [2021-12-17 15:07:50,801 INFO L854 garLoopResultBuilder]: At program point L987(lines 982 989) the Hoare annotation is: (let ((.cse0 (not (= ~systemActive~0 1)))) (and (or (not (<= 2 |old(~waterLevel~0)|)) .cse0 (not (<= 1 |old(~pumpRunning~0)|))) (or (not (= |old(~pumpRunning~0)| 0)) .cse0 (not (<= 1 |old(~waterLevel~0)|)) (not (= |old(~methAndRunningLastTime~0)| 0))))) [2021-12-17 15:07:50,801 INFO L858 garLoopResultBuilder]: For program point L409(lines 409 426) no Hoare annotation was computed. [2021-12-17 15:07:50,802 INFO L858 garLoopResultBuilder]: For program point L215(lines 215 225) no Hoare annotation was computed. [2021-12-17 15:07:50,802 INFO L858 garLoopResultBuilder]: For program point L244(lines 244 248) no Hoare annotation was computed. [2021-12-17 15:07:50,802 INFO L858 garLoopResultBuilder]: For program point L211(lines 211 228) no Hoare annotation was computed. [2021-12-17 15:07:50,802 INFO L854 garLoopResultBuilder]: At program point L244-2(lines 240 251) the Hoare annotation is: (let ((.cse0 (not (<= 2 |old(~waterLevel~0)|))) (.cse2 (not (<= 1 |old(~pumpRunning~0)|))) (.cse1 (not (= ~systemActive~0 1))) (.cse3 (not (= |old(~methAndRunningLastTime~0)| 0)))) (and (or .cse0 (= ~methAndRunningLastTime~0 0) .cse1 .cse2 .cse3) (or .cse0 (and (= ~pumpRunning~0 |old(~pumpRunning~0)|) (<= 1 ~waterLevel~0)) .cse1 .cse2) (or (not (= |old(~pumpRunning~0)| 0)) .cse1 (not (<= 1 |old(~waterLevel~0)|)) .cse3))) [2021-12-17 15:07:50,802 INFO L854 garLoopResultBuilder]: At program point L211-1(lines 203 231) the Hoare annotation is: (let ((.cse3 (= ~pumpRunning~0 0)) (.cse9 (not (<= 1 |old(~pumpRunning~0)|))) (.cse6 (not (<= 2 |old(~waterLevel~0)|))) (.cse7 (= |timeShift___utac_acc__Specification2_spec__2_~tmp~1#1| 0)) (.cse2 (= ~methAndRunningLastTime~0 0)) (.cse1 (not (= |old(~pumpRunning~0)| 0))) (.cse8 (not (= ~methaneLevelCritical~0 0))) (.cse4 (not (= ~systemActive~0 1))) (.cse5 (not (= |old(~methAndRunningLastTime~0)| 0)))) (and (let ((.cse0 (= ~waterLevel~0 |old(~waterLevel~0)|))) (or (and .cse0 (<= 1 ~pumpRunning~0) (<= 2 ~waterLevel~0)) .cse1 (and .cse0 .cse2 .cse3) .cse4 (not (<= 1 |old(~waterLevel~0)|)) .cse5)) (or .cse6 .cse7 .cse8 .cse4 .cse9) (or .cse6 (and (<= 1 |timeShift_isLowWaterLevel_~tmp___0~2#1|) (<= 1 |timeShift_isLowWaterLevel_#res#1|) (= |timeShift_isLowWaterSensorDry_#res#1| 0) .cse2 (<= 1 |timeShift_processEnvironment_~tmp~3#1|) (<= 1 ~waterLevel~0) (= |timeShift_isLowWaterLevel_~tmp~5#1| 0) .cse3) .cse4 .cse9) (or .cse7 (not (= |old(~waterLevel~0)| 1)) .cse1 .cse8 .cse4 .cse5) (or .cse6 (and .cse7 .cse2) .cse1 .cse8 .cse4 .cse5))) [2021-12-17 15:07:50,802 INFO L854 garLoopResultBuilder]: At program point L443(lines 438 445) the Hoare annotation is: (let ((.cse0 (not (= ~systemActive~0 1)))) (and (or (not (= |old(~pumpRunning~0)| 0)) .cse0 (not (<= 1 |old(~waterLevel~0)|)) (not (= |old(~methAndRunningLastTime~0)| 0))) (or (not (<= 2 |old(~waterLevel~0)|)) .cse0 (and (<= 1 |timeShift_isLowWaterLevel_~tmp___0~2#1|) (<= 1 |timeShift_isLowWaterLevel_#res#1|) (= |timeShift_isLowWaterSensorDry_#res#1| 0) (<= 1 |timeShift_processEnvironment_~tmp~3#1|) (<= 1 ~waterLevel~0) (= |timeShift_isLowWaterLevel_~tmp~5#1| 0) (= ~pumpRunning~0 0)) (not (<= 1 |old(~pumpRunning~0)|))))) [2021-12-17 15:07:50,802 INFO L858 garLoopResultBuilder]: For program point L216(lines 216 222) no Hoare annotation was computed. [2021-12-17 15:07:50,802 INFO L858 garLoopResultBuilder]: For program point L530(lines 530 534) no Hoare annotation was computed. [2021-12-17 15:07:50,802 INFO L854 garLoopResultBuilder]: At program point L336(lines 331 339) the Hoare annotation is: (let ((.cse0 (not (<= 2 |old(~waterLevel~0)|))) (.cse2 (not (<= 1 |old(~pumpRunning~0)|))) (.cse1 (not (= ~systemActive~0 1))) (.cse3 (not (= |old(~methAndRunningLastTime~0)| 0)))) (and (or .cse0 (= ~methAndRunningLastTime~0 0) .cse1 .cse2 .cse3) (or .cse0 .cse1 (and (= ~pumpRunning~0 |old(~pumpRunning~0)|) (= |timeShift_isLowWaterSensorDry_#res#1| 0) (<= 1 ~waterLevel~0)) .cse2) (or (not (= |old(~pumpRunning~0)| 0)) .cse1 (not (<= 1 |old(~waterLevel~0)|)) .cse3))) [2021-12-17 15:07:50,802 INFO L858 garLoopResultBuilder]: For program point L530-2(lines 530 534) no Hoare annotation was computed. [2021-12-17 15:07:50,802 INFO L854 garLoopResultBuilder]: At program point timeShiftENTRY(lines 347 370) the Hoare annotation is: (let ((.cse0 (not (<= 2 |old(~waterLevel~0)|))) (.cse3 (not (<= 1 |old(~pumpRunning~0)|))) (.cse1 (= ~waterLevel~0 |old(~waterLevel~0)|)) (.cse4 (= ~methAndRunningLastTime~0 0)) (.cse2 (not (= ~systemActive~0 1))) (.cse5 (not (= |old(~methAndRunningLastTime~0)| 0)))) (and (or .cse0 (and .cse1 (= ~pumpRunning~0 |old(~pumpRunning~0)|)) .cse2 .cse3) (or .cse0 .cse4 .cse2 .cse3 .cse5) (or (not (= |old(~pumpRunning~0)| 0)) (and .cse1 .cse4 (= ~pumpRunning~0 0)) .cse2 (not (<= 1 |old(~waterLevel~0)|)) .cse5))) [2021-12-17 15:07:50,802 INFO L858 garLoopResultBuilder]: For program point timeShiftEXIT(lines 347 370) no Hoare annotation was computed. [2021-12-17 15:07:50,803 INFO L858 garLoopResultBuilder]: For program point timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION(line 986) no Hoare annotation was computed. [2021-12-17 15:07:50,803 INFO L854 garLoopResultBuilder]: At program point L419(line 419) the Hoare annotation is: (let ((.cse0 (not (= ~systemActive~0 1)))) (and (or (not (<= 2 |old(~waterLevel~0)|)) .cse0 (not (<= 1 |old(~pumpRunning~0)|))) (or (not (= |old(~pumpRunning~0)| 0)) .cse0 (not (<= 1 |old(~waterLevel~0)|)) (not (= |old(~methAndRunningLastTime~0)| 0))))) [2021-12-17 15:07:50,803 INFO L861 garLoopResultBuilder]: At program point L96(line 96) the Hoare annotation is: true [2021-12-17 15:07:50,803 INFO L858 garLoopResultBuilder]: For program point cleanupEXIT(lines 90 119) no Hoare annotation was computed. [2021-12-17 15:07:50,803 INFO L858 garLoopResultBuilder]: For program point L96-1(line 96) no Hoare annotation was computed. [2021-12-17 15:07:50,803 INFO L861 garLoopResultBuilder]: At program point cleanupENTRY(lines 90 119) the Hoare annotation is: true [2021-12-17 15:07:50,803 INFO L861 garLoopResultBuilder]: At program point L115(lines 90 119) the Hoare annotation is: true [2021-12-17 15:07:50,803 INFO L858 garLoopResultBuilder]: For program point L111(line 111) no Hoare annotation was computed. [2021-12-17 15:07:50,803 INFO L858 garLoopResultBuilder]: For program point L104(lines 104 108) no Hoare annotation was computed. [2021-12-17 15:07:50,803 INFO L861 garLoopResultBuilder]: At program point L104-1(lines 104 108) the Hoare annotation is: true [2021-12-17 15:07:50,803 INFO L858 garLoopResultBuilder]: For program point L101(line 101) no Hoare annotation was computed. [2021-12-17 15:07:50,803 INFO L861 garLoopResultBuilder]: At program point L100-2(lines 100 114) the Hoare annotation is: true [2021-12-17 15:07:50,803 INFO L854 garLoopResultBuilder]: At program point L151(lines 147 153) the Hoare annotation is: (and (= ~waterLevel~0 1) (= ~methaneLevelCritical~0 0) (= ~methAndRunningLastTime~0 0) (= ~systemActive~0 1) (= ~pumpRunning~0 0)) [2021-12-17 15:07:50,804 INFO L858 garLoopResultBuilder]: For program point L597(lines 597 601) no Hoare annotation was computed. [2021-12-17 15:07:50,804 INFO L854 garLoopResultBuilder]: At program point L597-2(lines 589 602) the Hoare annotation is: (let ((.cse0 (= |ULTIMATE.start_test_~splverifierCounter~0#1| 0)) (.cse1 (= ~systemActive~0 1))) (or (and .cse0 (<= 1 ~pumpRunning~0) (<= 2 ~waterLevel~0) .cse1) (and .cse0 (= ~methAndRunningLastTime~0 0) (<= 1 ~waterLevel~0) .cse1 (= ~pumpRunning~0 0)))) [2021-12-17 15:07:50,804 INFO L858 garLoopResultBuilder]: For program point L560(lines 559 606) no Hoare annotation was computed. [2021-12-17 15:07:50,804 INFO L858 garLoopResultBuilder]: For program point L589(lines 589 602) no Hoare annotation was computed. [2021-12-17 15:07:50,804 INFO L854 garLoopResultBuilder]: At program point L581(line 581) the Hoare annotation is: (let ((.cse0 (= |ULTIMATE.start_test_~splverifierCounter~0#1| 0)) (.cse1 (= ~systemActive~0 1))) (or (and .cse0 (<= 1 ~pumpRunning~0) (<= 2 ~waterLevel~0) .cse1) (and .cse0 (= ~methAndRunningLastTime~0 0) (<= 1 ~waterLevel~0) .cse1 (= ~pumpRunning~0 0)))) [2021-12-17 15:07:50,804 INFO L861 garLoopResultBuilder]: At program point L164(lines 156 166) the Hoare annotation is: true [2021-12-17 15:07:50,804 INFO L861 garLoopResultBuilder]: At program point L610(lines 549 614) the Hoare annotation is: true [2021-12-17 15:07:50,804 INFO L858 garLoopResultBuilder]: For program point L-1(line -1) no Hoare annotation was computed. [2021-12-17 15:07:50,804 INFO L858 garLoopResultBuilder]: For program point ULTIMATE.startENTRY(line -1) no Hoare annotation was computed. [2021-12-17 15:07:50,804 INFO L858 garLoopResultBuilder]: For program point ULTIMATE.startFINAL(line -1) no Hoare annotation was computed. [2021-12-17 15:07:50,804 INFO L858 garLoopResultBuilder]: For program point L569(lines 569 575) no Hoare annotation was computed. [2021-12-17 15:07:50,804 INFO L858 garLoopResultBuilder]: For program point L569-1(lines 569 575) no Hoare annotation was computed. [2021-12-17 15:07:50,804 INFO L858 garLoopResultBuilder]: For program point L177(lines 177 184) no Hoare annotation was computed. [2021-12-17 15:07:50,804 INFO L858 garLoopResultBuilder]: For program point L561(lines 561 565) no Hoare annotation was computed. [2021-12-17 15:07:50,804 INFO L858 garLoopResultBuilder]: For program point L177-2(lines 177 184) no Hoare annotation was computed. [2021-12-17 15:07:50,804 INFO L854 garLoopResultBuilder]: At program point L545(lines 540 547) the Hoare annotation is: (let ((.cse0 (= |ULTIMATE.start_test_~splverifierCounter~0#1| 0)) (.cse1 (= ~systemActive~0 1))) (or (and .cse0 (<= 1 ~pumpRunning~0) (<= 2 ~waterLevel~0) .cse1) (and .cse0 (= ~methAndRunningLastTime~0 0) (<= 1 ~waterLevel~0) .cse1 (= ~pumpRunning~0 0)))) [2021-12-17 15:07:50,805 INFO L858 garLoopResultBuilder]: For program point ULTIMATE.startEXIT(line -1) no Hoare annotation was computed. [2021-12-17 15:07:50,805 INFO L854 garLoopResultBuilder]: At program point L607(lines 558 608) the Hoare annotation is: false [2021-12-17 15:07:50,805 INFO L861 garLoopResultBuilder]: At program point L186(lines 167 189) the Hoare annotation is: true [2021-12-17 15:07:50,805 INFO L854 garLoopResultBuilder]: At program point L83(lines 78 86) the Hoare annotation is: (and (= ~waterLevel~0 1) (= ~methaneLevelCritical~0 0) (= ~methAndRunningLastTime~0 0) (= ~systemActive~0 1) (= ~pumpRunning~0 0)) [2021-12-17 15:07:50,805 INFO L854 garLoopResultBuilder]: At program point L75(lines 71 77) the Hoare annotation is: (and (= ~waterLevel~0 1) (= ~methaneLevelCritical~0 0) (= ~methAndRunningLastTime~0 0) (= ~systemActive~0 1) (= ~pumpRunning~0 0)) [2021-12-17 15:07:50,805 INFO L858 garLoopResultBuilder]: For program point L579(lines 579 585) no Hoare annotation was computed. [2021-12-17 15:07:50,805 INFO L858 garLoopResultBuilder]: For program point L579-1(lines 579 585) no Hoare annotation was computed. [2021-12-17 15:07:50,805 INFO L854 garLoopResultBuilder]: At program point L604(lines 559 606) the Hoare annotation is: (let ((.cse0 (= |ULTIMATE.start_test_~splverifierCounter~0#1| 0)) (.cse1 (= ~systemActive~0 1))) (or (and .cse0 (<= 1 ~pumpRunning~0) (<= 2 ~waterLevel~0) .cse1) (and .cse0 (= ~methAndRunningLastTime~0 0) (<= 1 ~waterLevel~0) .cse1 (= ~pumpRunning~0 0)))) [2021-12-17 15:07:50,805 INFO L854 garLoopResultBuilder]: At program point L571(line 571) the Hoare annotation is: (let ((.cse0 (= |ULTIMATE.start_test_~splverifierCounter~0#1| 0)) (.cse1 (= ~systemActive~0 1))) (or (and .cse0 (<= 1 ~pumpRunning~0) (<= 2 ~waterLevel~0) .cse1) (and .cse0 (= ~methAndRunningLastTime~0 0) (<= 1 ~waterLevel~0) .cse1 (= ~pumpRunning~0 0)))) [2021-12-17 15:07:50,805 INFO L854 garLoopResultBuilder]: At program point L200(lines 195 202) the Hoare annotation is: (and (= ~waterLevel~0 1) (= ~methaneLevelCritical~0 0) (= ~methAndRunningLastTime~0 0) (= ~systemActive~0 1) (= ~pumpRunning~0 0)) [2021-12-17 15:07:50,805 INFO L854 garLoopResultBuilder]: At program point L68(lines 64 70) the Hoare annotation is: (and (= ~waterLevel~0 1) (= ~methaneLevelCritical~0 0) (= ~methAndRunningLastTime~0 0) (= ~systemActive~0 1) (= ~pumpRunning~0 0)) [2021-12-17 15:07:50,805 INFO L854 garLoopResultBuilder]: At program point processEnvironment__wrappee__highWaterSensorENTRY(lines 379 403) the Hoare annotation is: (let ((.cse0 (not (<= 1 ~waterLevel~0))) (.cse1 (not (= |old(~pumpRunning~0)| 0))) (.cse2 (not (= ~systemActive~0 1))) (.cse3 (= ~pumpRunning~0 0))) (and (or .cse0 .cse1 (not (= ~methAndRunningLastTime~0 0)) .cse2 .cse3) (or .cse0 .cse1 (not (= ~methaneLevelCritical~0 0)) .cse2 .cse3))) [2021-12-17 15:07:50,805 INFO L854 garLoopResultBuilder]: At program point L393(line 393) the Hoare annotation is: (let ((.cse4 (= ~systemActive~0 1))) (let ((.cse0 (and (= |processEnvironment__wrappee__highWaterSensor_~tmp~2#1| 0) .cse4 (= ~pumpRunning~0 0))) (.cse1 (not (= |old(~pumpRunning~0)| 0))) (.cse3 (not (= ~methAndRunningLastTime~0 0))) (.cse2 (not .cse4))) (and (or .cse0 (not (<= 1 ~waterLevel~0)) .cse1 (not (= ~methaneLevelCritical~0 0)) .cse2) (or .cse0 .cse1 .cse3 .cse2 (not (<= 2 ~waterLevel~0))) (or (not (= ~waterLevel~0 1)) .cse0 .cse1 .cse3 .cse2)))) [2021-12-17 15:07:50,806 INFO L854 garLoopResultBuilder]: At program point L517(lines 502 520) the Hoare annotation is: (let ((.cse2 (not (= ~methAndRunningLastTime~0 0))) (.cse5 (= |processEnvironment__wrappee__highWaterSensor_isHighWaterLevel_#res#1| 0)) (.cse6 (= |processEnvironment__wrappee__highWaterSensor_isHighWaterLevel_~tmp___0~1#1| 0)) (.cse4 (= ~pumpRunning~0 0)) (.cse0 (not (<= 1 ~waterLevel~0))) (.cse1 (not (= |old(~pumpRunning~0)| 0))) (.cse3 (not (= ~systemActive~0 1)))) (and (or .cse0 .cse1 .cse2 .cse3 .cse4) (or (not (= ~waterLevel~0 1)) .cse1 .cse2 (and .cse5 .cse6) .cse3) (or (and .cse5 .cse6 .cse4) (and (<= 2 ~waterLevel~0) .cse4) .cse0 .cse1 (not (= ~methaneLevelCritical~0 0)) .cse3))) [2021-12-17 15:07:50,806 INFO L858 garLoopResultBuilder]: For program point L387(lines 387 395) no Hoare annotation was computed. [2021-12-17 15:07:50,806 INFO L858 garLoopResultBuilder]: For program point L321(lines 321 327) no Hoare annotation was computed. [2021-12-17 15:07:50,806 INFO L858 garLoopResultBuilder]: For program point L383(lines 383 400) no Hoare annotation was computed. [2021-12-17 15:07:50,806 INFO L858 garLoopResultBuilder]: For program point L511(lines 511 515) no Hoare annotation was computed. [2021-12-17 15:07:50,806 INFO L858 garLoopResultBuilder]: For program point L511-2(lines 511 515) no Hoare annotation was computed. [2021-12-17 15:07:50,806 INFO L858 garLoopResultBuilder]: For program point processEnvironment__wrappee__highWaterSensorEXIT(lines 379 403) no Hoare annotation was computed. [2021-12-17 15:07:50,806 INFO L854 garLoopResultBuilder]: At program point L435(lines 430 437) the Hoare annotation is: (let ((.cse0 (and (<= 1 ~pumpRunning~0) (<= 2 ~waterLevel~0))) (.cse1 (not (<= 1 ~waterLevel~0))) (.cse2 (not (= |old(~pumpRunning~0)| 0))) (.cse3 (not (= ~systemActive~0 1)))) (and (or .cse0 .cse1 .cse2 (not (= ~methaneLevelCritical~0 0)) .cse3) (or .cse0 .cse1 .cse2 (not (= ~methAndRunningLastTime~0 0)) .cse3))) [2021-12-17 15:07:50,806 INFO L854 garLoopResultBuilder]: At program point L398(line 398) the Hoare annotation is: (let ((.cse0 (not (<= 1 ~waterLevel~0))) (.cse1 (not (= |old(~pumpRunning~0)| 0))) (.cse2 (not (= ~systemActive~0 1)))) (and (or .cse0 .cse1 (not (= ~methaneLevelCritical~0 0)) .cse2) (or .cse0 .cse1 (not (= ~methAndRunningLastTime~0 0)) .cse2))) [2021-12-17 15:07:50,806 INFO L858 garLoopResultBuilder]: For program point L398-1(lines 379 403) no Hoare annotation was computed. [2021-12-17 15:07:50,806 INFO L854 garLoopResultBuilder]: At program point L326(lines 317 330) the Hoare annotation is: (let ((.cse4 (= ~pumpRunning~0 0)) (.cse0 (not (<= 1 ~waterLevel~0))) (.cse1 (not (= |old(~pumpRunning~0)| 0))) (.cse2 (not (= ~methAndRunningLastTime~0 0))) (.cse3 (not (= ~systemActive~0 1))) (.cse5 (<= 1 |processEnvironment__wrappee__highWaterSensor_isHighWaterSensorDry_#res#1|))) (and (or .cse0 .cse1 .cse2 .cse3 .cse4) (or (and (<= 2 ~waterLevel~0) .cse4) (and .cse5 .cse4) .cse0 .cse1 (not (= ~methaneLevelCritical~0 0)) .cse3) (or (not (= ~waterLevel~0 1)) .cse1 .cse2 .cse3 .cse5))) [2021-12-17 15:07:50,806 INFO L858 garLoopResultBuilder]: For program point L256-1(lines 252 263) no Hoare annotation was computed. [2021-12-17 15:07:50,806 INFO L858 garLoopResultBuilder]: For program point waterRiseEXIT(lines 252 263) no Hoare annotation was computed. [2021-12-17 15:07:50,807 INFO L854 garLoopResultBuilder]: At program point waterRiseENTRY(lines 252 263) the Hoare annotation is: (let ((.cse4 (not (<= 2 |old(~waterLevel~0)|))) (.cse0 (not (= ~pumpRunning~0 0))) (.cse1 (= ~waterLevel~0 |old(~waterLevel~0)|)) (.cse2 (not (= ~methAndRunningLastTime~0 0))) (.cse3 (not (= ~systemActive~0 1)))) (and (or (not (= |old(~waterLevel~0)| 1)) .cse0 .cse1 .cse2 .cse3) (or .cse4 (not (<= 1 ~pumpRunning~0)) .cse1 .cse3) (or .cse4 .cse0 .cse1 .cse2 .cse3))) [2021-12-17 15:07:50,813 INFO L732 BasicCegarLoop]: Path program histogram: [1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2021-12-17 15:07:50,814 INFO L179 ceAbstractionStarter]: Computing trace abstraction results [2021-12-17 15:07:50,836 INFO L202 PluginConnector]: Adding new model de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction CFG 17.12 03:07:50 BoogieIcfgContainer [2021-12-17 15:07:50,836 INFO L132 PluginConnector]: ------------------------ END TraceAbstraction---------------------------- [2021-12-17 15:07:50,837 INFO L113 PluginConnector]: ------------------------Witness Printer---------------------------- [2021-12-17 15:07:50,837 INFO L271 PluginConnector]: Initializing Witness Printer... [2021-12-17 15:07:50,837 INFO L275 PluginConnector]: Witness Printer initialized [2021-12-17 15:07:50,838 INFO L185 PluginConnector]: Executing the observer RCFGCatcher from plugin Witness Printer for "de.uni_freiburg.informatik.ultimate.plugins.generator.rcfgbuilder CFG 17.12 03:07:43" (3/4) ... [2021-12-17 15:07:50,840 INFO L137 WitnessPrinter]: Generating witness for correct program [2021-12-17 15:07:50,844 INFO L354 RCFGBacktranslator]: Ignoring RootEdge to procedure processEnvironment__wrappee__base [2021-12-17 15:07:50,844 INFO L354 RCFGBacktranslator]: Ignoring RootEdge to procedure changeMethaneLevel [2021-12-17 15:07:50,844 INFO L354 RCFGBacktranslator]: Ignoring RootEdge to procedure isMethaneLevelCritical [2021-12-17 15:07:50,844 INFO L354 RCFGBacktranslator]: Ignoring RootEdge to procedure timeShift [2021-12-17 15:07:50,845 INFO L354 RCFGBacktranslator]: Ignoring RootEdge to procedure cleanup [2021-12-17 15:07:50,845 INFO L354 RCFGBacktranslator]: Ignoring RootEdge to procedure processEnvironment__wrappee__highWaterSensor [2021-12-17 15:07:50,845 INFO L354 RCFGBacktranslator]: Ignoring RootEdge to procedure waterRise [2021-12-17 15:07:50,850 INFO L910 BoogieBacktranslator]: Reduced CFG by removing 52 nodes and edges [2021-12-17 15:07:50,850 INFO L910 BoogieBacktranslator]: Reduced CFG by removing 22 nodes and edges [2021-12-17 15:07:50,850 INFO L910 BoogieBacktranslator]: Reduced CFG by removing 11 nodes and edges [2021-12-17 15:07:50,851 INFO L910 BoogieBacktranslator]: Reduced CFG by removing 5 nodes and edges [2021-12-17 15:07:50,851 INFO L910 BoogieBacktranslator]: Reduced CFG by removing 2 nodes and edges [2021-12-17 15:07:50,851 INFO L910 BoogieBacktranslator]: Reduced CFG by removing 1 nodes and edges [2021-12-17 15:07:50,852 INFO L910 BoogieBacktranslator]: Reduced CFG by removing 1 nodes and edges [2021-12-17 15:07:50,868 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (((((!(2 <= \old(waterLevel)) || methAndRunningLastTime == 0) || !(systemActive == 1)) || !(1 <= \old(pumpRunning))) || !(\old(methAndRunningLastTime) == 0)) && (((!(2 <= \old(waterLevel)) || (pumpRunning == \old(pumpRunning) && 1 <= waterLevel)) || !(systemActive == 1)) || !(1 <= \old(pumpRunning)))) && (((!(\old(pumpRunning) == 0) || !(systemActive == 1)) || !(1 <= \old(waterLevel))) || !(\old(methAndRunningLastTime) == 0)) [2021-12-17 15:07:50,868 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (((((!(\old(waterLevel) == 1) || !(\old(pumpRunning) == 0)) || methAndRunningLastTime == 0) || !(systemActive == 1)) || !(\old(methAndRunningLastTime) == 0)) && ((((((((waterLevel == \old(waterLevel) && 1 <= pumpRunning) && 2 <= waterLevel) && methAndRunningLastTime == 0) || (waterLevel == \old(waterLevel) && pumpRunning == 0)) || !(\old(pumpRunning) == 0)) || !(systemActive == 1)) || !(1 <= \old(waterLevel))) || !(\old(methAndRunningLastTime) == 0))) && (((!(2 <= \old(waterLevel)) || !(systemActive == 1)) || ((((((1 <= tmp___0 && 1 <= \result) && \result == 0) && 1 <= tmp) && 1 <= waterLevel) && tmp == 0) && pumpRunning == 0)) || !(1 <= \old(pumpRunning))) [2021-12-17 15:07:50,869 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: ((((((((((waterLevel == \old(waterLevel) && 1 <= pumpRunning) && 2 <= waterLevel) || !(\old(pumpRunning) == 0)) || ((waterLevel == \old(waterLevel) && methAndRunningLastTime == 0) && pumpRunning == 0)) || !(systemActive == 1)) || !(1 <= \old(waterLevel))) || !(\old(methAndRunningLastTime) == 0)) && ((((!(2 <= \old(waterLevel)) || tmp == 0) || !(methaneLevelCritical == 0)) || !(systemActive == 1)) || !(1 <= \old(pumpRunning)))) && (((!(2 <= \old(waterLevel)) || (((((((1 <= tmp___0 && 1 <= \result) && \result == 0) && methAndRunningLastTime == 0) && 1 <= tmp) && 1 <= waterLevel) && tmp == 0) && pumpRunning == 0)) || !(systemActive == 1)) || !(1 <= \old(pumpRunning)))) && (((((tmp == 0 || !(\old(waterLevel) == 1)) || !(\old(pumpRunning) == 0)) || !(methaneLevelCritical == 0)) || !(systemActive == 1)) || !(\old(methAndRunningLastTime) == 0))) && (((((!(2 <= \old(waterLevel)) || (tmp == 0 && methAndRunningLastTime == 0)) || !(\old(pumpRunning) == 0)) || !(methaneLevelCritical == 0)) || !(systemActive == 1)) || !(\old(methAndRunningLastTime) == 0)) [2021-12-17 15:07:50,869 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: ((((((!(2 <= \old(waterLevel)) || !(methaneLevelCritical == 0)) || !(systemActive == 1)) || !(1 <= \old(pumpRunning))) && ((((!(\old(waterLevel) == 1) || !(\old(pumpRunning) == 0)) || methAndRunningLastTime == 0) || !(systemActive == 1)) || !(\old(methAndRunningLastTime) == 0))) && ((((((((waterLevel == \old(waterLevel) && 1 <= pumpRunning) && 2 <= waterLevel) && methAndRunningLastTime == 0) || ((\result == 0 && waterLevel == \old(waterLevel)) && pumpRunning == 0)) || !(\old(pumpRunning) == 0)) || !(systemActive == 1)) || !(1 <= \old(waterLevel))) || !(\old(methAndRunningLastTime) == 0))) && (((!(2 <= \old(waterLevel)) || (((((((1 <= tmp___0 && \result == 0) && 1 <= \result) && \result == 0) && 1 <= tmp) && 1 <= waterLevel) && tmp == 0) && pumpRunning == 0)) || !(systemActive == 1)) || !(1 <= \old(pumpRunning)))) && ((((!(\old(pumpRunning) == 0) || !(methaneLevelCritical == 0)) || !(systemActive == 1)) || !(1 <= \old(waterLevel))) || !(\old(methAndRunningLastTime) == 0)) [2021-12-17 15:07:50,869 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (((((!(2 <= \old(waterLevel)) || methAndRunningLastTime == 0) || !(systemActive == 1)) || !(1 <= \old(pumpRunning))) || !(\old(methAndRunningLastTime) == 0)) && (((!(2 <= \old(waterLevel)) || !(systemActive == 1)) || ((pumpRunning == \old(pumpRunning) && \result == 0) && 1 <= waterLevel)) || !(1 <= \old(pumpRunning)))) && (((!(\old(pumpRunning) == 0) || !(systemActive == 1)) || !(1 <= \old(waterLevel))) || !(\old(methAndRunningLastTime) == 0)) [2021-12-17 15:07:50,869 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (((((!(1 <= waterLevel) || !(\old(pumpRunning) == 0)) || !(methAndRunningLastTime == 0)) || !(systemActive == 1)) || pumpRunning == 0) && ((((((2 <= waterLevel && pumpRunning == 0) || (1 <= \result && pumpRunning == 0)) || !(1 <= waterLevel)) || !(\old(pumpRunning) == 0)) || !(methaneLevelCritical == 0)) || !(systemActive == 1))) && ((((!(waterLevel == 1) || !(\old(pumpRunning) == 0)) || !(methAndRunningLastTime == 0)) || !(systemActive == 1)) || 1 <= \result) [2021-12-17 15:07:50,870 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: ((((!(2 <= \old(waterLevel)) || (((((1 <= tmp___0 && 1 <= \result) && pumpRunning == \old(pumpRunning)) && \result == 0) && 1 <= waterLevel) && tmp == 0)) || !(systemActive == 1)) || !(1 <= \old(pumpRunning))) && ((((!(2 <= \old(waterLevel)) || methAndRunningLastTime == 0) || !(systemActive == 1)) || !(1 <= \old(pumpRunning))) || !(\old(methAndRunningLastTime) == 0))) && (((!(\old(pumpRunning) == 0) || !(systemActive == 1)) || !(1 <= \old(waterLevel))) || !(\old(methAndRunningLastTime) == 0)) [2021-12-17 15:07:50,870 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: ((!(2 <= \old(waterLevel)) || !(systemActive == 1)) || !(1 <= \old(pumpRunning))) && (((!(\old(pumpRunning) == 0) || !(systemActive == 1)) || !(1 <= \old(waterLevel))) || !(\old(methAndRunningLastTime) == 0)) [2021-12-17 15:07:50,870 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (((((!(1 <= waterLevel) || !(\old(pumpRunning) == 0)) || !(methAndRunningLastTime == 0)) || !(systemActive == 1)) || pumpRunning == 0) && ((((!(waterLevel == 1) || !(\old(pumpRunning) == 0)) || !(methAndRunningLastTime == 0)) || (\result == 0 && tmp___0 == 0)) || !(systemActive == 1))) && (((((((\result == 0 && tmp___0 == 0) && pumpRunning == 0) || (2 <= waterLevel && pumpRunning == 0)) || !(1 <= waterLevel)) || !(\old(pumpRunning) == 0)) || !(methaneLevelCritical == 0)) || !(systemActive == 1)) [2021-12-17 15:07:50,870 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (((!(\old(pumpRunning) == 0) || !(systemActive == 1)) || !(1 <= \old(waterLevel))) || !(\old(methAndRunningLastTime) == 0)) && (((!(2 <= \old(waterLevel)) || !(systemActive == 1)) || ((((((1 <= tmp___0 && 1 <= \result) && \result == 0) && 1 <= tmp) && 1 <= waterLevel) && tmp == 0) && pumpRunning == 0)) || !(1 <= \old(pumpRunning))) [2021-12-17 15:07:50,870 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (((((1 <= pumpRunning && 2 <= waterLevel) || !(1 <= waterLevel)) || !(\old(pumpRunning) == 0)) || !(methaneLevelCritical == 0)) || !(systemActive == 1)) && (((((1 <= pumpRunning && 2 <= waterLevel) || !(1 <= waterLevel)) || !(\old(pumpRunning) == 0)) || !(methAndRunningLastTime == 0)) || !(systemActive == 1)) [2021-12-17 15:07:50,885 INFO L141 WitnessManager]: Wrote witness to /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/witness.graphml [2021-12-17 15:07:50,885 INFO L132 PluginConnector]: ------------------------ END Witness Printer---------------------------- [2021-12-17 15:07:50,885 INFO L158 Benchmark]: Toolchain (without parser) took 8516.80ms. Allocated memory was 100.7MB in the beginning and 222.3MB in the end (delta: 121.6MB). Free memory was 70.8MB in the beginning and 150.2MB in the end (delta: -79.4MB). Peak memory consumption was 40.4MB. Max. memory is 16.1GB. [2021-12-17 15:07:50,886 INFO L158 Benchmark]: CDTParser took 0.25ms. Allocated memory is still 100.7MB. Free memory is still 57.9MB. There was no memory consumed. Max. memory is 16.1GB. [2021-12-17 15:07:50,886 INFO L158 Benchmark]: CACSL2BoogieTranslator took 370.86ms. Allocated memory was 100.7MB in the beginning and 142.6MB in the end (delta: 41.9MB). Free memory was 70.5MB in the beginning and 109.7MB in the end (delta: -39.1MB). Peak memory consumption was 8.4MB. Max. memory is 16.1GB. [2021-12-17 15:07:50,886 INFO L158 Benchmark]: Boogie Procedure Inliner took 59.02ms. Allocated memory is still 142.6MB. Free memory was 109.7MB in the beginning and 107.6MB in the end (delta: 2.1MB). Peak memory consumption was 2.1MB. Max. memory is 16.1GB. [2021-12-17 15:07:50,886 INFO L158 Benchmark]: Boogie Preprocessor took 39.63ms. Allocated memory is still 142.6MB. Free memory was 107.6MB in the beginning and 106.0MB in the end (delta: 1.5MB). Peak memory consumption was 2.1MB. Max. memory is 16.1GB. [2021-12-17 15:07:50,887 INFO L158 Benchmark]: RCFGBuilder took 286.26ms. Allocated memory is still 142.6MB. Free memory was 105.5MB in the beginning and 89.2MB in the end (delta: 16.2MB). Peak memory consumption was 16.8MB. Max. memory is 16.1GB. [2021-12-17 15:07:50,887 INFO L158 Benchmark]: TraceAbstraction took 7708.30ms. Allocated memory was 142.6MB in the beginning and 222.3MB in the end (delta: 79.7MB). Free memory was 89.2MB in the beginning and 157.5MB in the end (delta: -68.2MB). Peak memory consumption was 82.6MB. Max. memory is 16.1GB. [2021-12-17 15:07:50,887 INFO L158 Benchmark]: Witness Printer took 48.10ms. Allocated memory is still 222.3MB. Free memory was 156.4MB in the beginning and 150.2MB in the end (delta: 6.3MB). Peak memory consumption was 6.3MB. Max. memory is 16.1GB. [2021-12-17 15:07:50,888 INFO L339 ainManager$Toolchain]: ####################### End [Toolchain 1] ####################### --- Results --- * Results from de.uni_freiburg.informatik.ultimate.core: - StatisticsResult: Toolchain Benchmarks Benchmark results are: * CDTParser took 0.25ms. Allocated memory is still 100.7MB. Free memory is still 57.9MB. There was no memory consumed. Max. memory is 16.1GB. * CACSL2BoogieTranslator took 370.86ms. Allocated memory was 100.7MB in the beginning and 142.6MB in the end (delta: 41.9MB). Free memory was 70.5MB in the beginning and 109.7MB in the end (delta: -39.1MB). Peak memory consumption was 8.4MB. Max. memory is 16.1GB. * Boogie Procedure Inliner took 59.02ms. Allocated memory is still 142.6MB. Free memory was 109.7MB in the beginning and 107.6MB in the end (delta: 2.1MB). Peak memory consumption was 2.1MB. Max. memory is 16.1GB. * Boogie Preprocessor took 39.63ms. Allocated memory is still 142.6MB. Free memory was 107.6MB in the beginning and 106.0MB in the end (delta: 1.5MB). Peak memory consumption was 2.1MB. Max. memory is 16.1GB. * RCFGBuilder took 286.26ms. Allocated memory is still 142.6MB. Free memory was 105.5MB in the beginning and 89.2MB in the end (delta: 16.2MB). Peak memory consumption was 16.8MB. Max. memory is 16.1GB. * TraceAbstraction took 7708.30ms. Allocated memory was 142.6MB in the beginning and 222.3MB in the end (delta: 79.7MB). Free memory was 89.2MB in the beginning and 157.5MB in the end (delta: -68.2MB). Peak memory consumption was 82.6MB. Max. memory is 16.1GB. * Witness Printer took 48.10ms. Allocated memory is still 222.3MB. Free memory was 156.4MB in the beginning and 150.2MB in the end (delta: 6.3MB). Peak memory consumption was 6.3MB. Max. memory is 16.1GB. * Results from de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction: - StatisticsResult: ErrorAutomatonStatistics NumberErrorTraces: 0, NumberStatementsAllTraces: 0, NumberRelevantStatements: 0, 0.0s ErrorAutomatonConstructionTimeTotal, 0.0s FaulLocalizationTime, NumberStatementsFirstTrace: -1, TraceLengthAvg: 0, 0.0s ErrorAutomatonConstructionTimeAvg, 0.0s ErrorAutomatonDifferenceTimeAvg, 0.0s ErrorAutomatonDifferenceTimeTotal, NumberOfNoEnhancement: 0, NumberOfFiniteEnhancement: 0, NumberOfInfiniteEnhancement: 0 - PositiveResult [Line: 986]: call to reach_error is unreachable For all program executions holds that call to reach_error is unreachable at this location - StatisticsResult: Ultimate Automizer benchmark data CFG has 8 procedures, 89 locations, 1 error locations. Started 1 CEGAR loops. OverallTime: 7.6s, OverallIterations: 13, TraceHistogramMax: 2, PathProgramHistogramMax: 1, EmptinessCheckTime: 0.0s, AutomataDifference: 1.6s, DeadEndRemovalTime: 0.0s, HoareAnnotationTime: 3.0s, InitialAbstractionConstructionTime: 0.0s, PartialOrderReductionTime: 0.0s, HoareTripleCheckerStatistics: 0 mSolverCounterUnknown, 1570 SdHoareTripleChecker+Valid, 0.9s IncrementalHoareTripleChecker+Time, 0 mSdLazyCounter, 1542 mSDsluCounter, 3610 SdHoareTripleChecker+Invalid, 0.7s Time, 0 mProtectedAction, 0 SdHoareTripleChecker+Unchecked, 0 IncrementalHoareTripleChecker+Unchecked, 2215 mSDsCounter, 390 IncrementalHoareTripleChecker+Valid, 0 mProtectedPredicate, 1146 IncrementalHoareTripleChecker+Invalid, 1536 SdHoareTripleChecker+Unknown, 0 mSolverCounterNotChecked, 390 mSolverCounterUnsat, 1395 mSDtfsCounter, 1146 mSolverCounterSat, 0.0s SdHoareTripleChecker+Time, 0 IncrementalHoareTripleChecker+Unknown, PredicateUnifierStatistics: 0 DeclaredPredicates, 494 GetRequests, 393 SyntacticMatches, 3 SemanticMatches, 98 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 136 ImplicationChecksByTransitivity, 0.4s Time, 0.0s BasicInterpolantAutomatonTime, BiggestAbstraction: size=920occurred in iteration=12, InterpolantAutomatonStates: 91, traceCheckStatistics: No data available, InterpolantConsolidationStatistics: No data available, PathInvariantsStatistics: No data available, 0/0 InterpolantCoveringCapability, TotalInterpolationStatistics: No data available, 0.0s DumpTime, AutomataMinimizationStatistics: 0.2s AutomataMinimizationTime, 13 MinimizatonAttempts, 441 StatesRemovedByMinimization, 8 NontrivialMinimizations, HoareAnnotationStatistics: 0.0s HoareAnnotationTime, 41 LocationsWithAnnotation, 1598 PreInvPairs, 1750 NumberOfFragments, 1577 HoareAnnotationTreeSize, 1598 FomulaSimplifications, 189 FormulaSimplificationTreeSizeReduction, 0.3s HoareSimplificationTime, 41 FomulaSimplificationsInter, 11483 FormulaSimplificationTreeSizeReductionInter, 2.7s HoareSimplificationTimeInter, RefinementEngineStatistics: TRACE_CHECK: 0.1s SsaConstructionTime, 0.3s SatisfiabilityAnalysisTime, 1.4s InterpolantComputationTime, 973 NumberOfCodeBlocks, 973 NumberOfCodeBlocksAsserted, 16 NumberOfCheckSat, 957 ConstructedInterpolants, 0 QuantifiedInterpolants, 1629 SizeOfPredicates, 8 NumberOfNonLiveVariables, 1421 ConjunctsInSsa, 20 ConjunctsInUnsatCore, 16 InterpolantComputations, 13 PerfectInterpolantSequences, 174/184 InterpolantCoveringCapability, INVARIANT_SYNTHESIS: No data available, INTERPOLANT_CONSOLIDATION: No data available, ABSTRACT_INTERPRETATION: No data available, PDR: No data available, ACCELERATED_INTERPOLATION: No data available, SIFA: No data available, ReuseStatistics: No data available - AllSpecificationsHoldResult: All specifications hold 1 specifications checked. All of them hold - InvariantResult [Line: 438]: Loop Invariant Derived loop invariant: (((!(\old(pumpRunning) == 0) || !(systemActive == 1)) || !(1 <= \old(waterLevel))) || !(\old(methAndRunningLastTime) == 0)) && (((!(2 <= \old(waterLevel)) || !(systemActive == 1)) || ((((((1 <= tmp___0 && 1 <= \result) && \result == 0) && 1 <= tmp) && 1 <= waterLevel) && tmp == 0) && pumpRunning == 0)) || !(1 <= \old(pumpRunning))) - InvariantResult [Line: 156]: Loop Invariant Derived loop invariant: 1 - InvariantResult [Line: 521]: Loop Invariant Derived loop invariant: ((((!(2 <= \old(waterLevel)) || (((((1 <= tmp___0 && 1 <= \result) && pumpRunning == \old(pumpRunning)) && \result == 0) && 1 <= waterLevel) && tmp == 0)) || !(systemActive == 1)) || !(1 <= \old(pumpRunning))) && ((((!(2 <= \old(waterLevel)) || methAndRunningLastTime == 0) || !(systemActive == 1)) || !(1 <= \old(pumpRunning))) || !(\old(methAndRunningLastTime) == 0))) && (((!(\old(pumpRunning) == 0) || !(systemActive == 1)) || !(1 <= \old(waterLevel))) || !(\old(methAndRunningLastTime) == 0)) - InvariantResult [Line: 195]: Loop Invariant Derived loop invariant: (((waterLevel == 1 && methaneLevelCritical == 0) && methAndRunningLastTime == 0) && systemActive == 1) && pumpRunning == 0 - InvariantResult [Line: 549]: Loop Invariant Derived loop invariant: 1 - InvariantResult [Line: 90]: Loop Invariant Derived loop invariant: 1 - InvariantResult [Line: 982]: Loop Invariant Derived loop invariant: ((!(2 <= \old(waterLevel)) || !(systemActive == 1)) || !(1 <= \old(pumpRunning))) && (((!(\old(pumpRunning) == 0) || !(systemActive == 1)) || !(1 <= \old(waterLevel))) || !(\old(methAndRunningLastTime) == 0)) - InvariantResult [Line: 240]: Loop Invariant Derived loop invariant: (((((!(2 <= \old(waterLevel)) || methAndRunningLastTime == 0) || !(systemActive == 1)) || !(1 <= \old(pumpRunning))) || !(\old(methAndRunningLastTime) == 0)) && (((!(2 <= \old(waterLevel)) || (pumpRunning == \old(pumpRunning) && 1 <= waterLevel)) || !(systemActive == 1)) || !(1 <= \old(pumpRunning)))) && (((!(\old(pumpRunning) == 0) || !(systemActive == 1)) || !(1 <= \old(waterLevel))) || !(\old(methAndRunningLastTime) == 0)) - InvariantResult [Line: 540]: Loop Invariant Derived loop invariant: (((splverifierCounter == 0 && 1 <= pumpRunning) && 2 <= waterLevel) && systemActive == 1) || ((((splverifierCounter == 0 && methAndRunningLastTime == 0) && 1 <= waterLevel) && systemActive == 1) && pumpRunning == 0) - InvariantResult [Line: 203]: Loop Invariant Derived loop invariant: ((((((((((waterLevel == \old(waterLevel) && 1 <= pumpRunning) && 2 <= waterLevel) || !(\old(pumpRunning) == 0)) || ((waterLevel == \old(waterLevel) && methAndRunningLastTime == 0) && pumpRunning == 0)) || !(systemActive == 1)) || !(1 <= \old(waterLevel))) || !(\old(methAndRunningLastTime) == 0)) && ((((!(2 <= \old(waterLevel)) || tmp == 0) || !(methaneLevelCritical == 0)) || !(systemActive == 1)) || !(1 <= \old(pumpRunning)))) && (((!(2 <= \old(waterLevel)) || (((((((1 <= tmp___0 && 1 <= \result) && \result == 0) && methAndRunningLastTime == 0) && 1 <= tmp) && 1 <= waterLevel) && tmp == 0) && pumpRunning == 0)) || !(systemActive == 1)) || !(1 <= \old(pumpRunning)))) && (((((tmp == 0 || !(\old(waterLevel) == 1)) || !(\old(pumpRunning) == 0)) || !(methaneLevelCritical == 0)) || !(systemActive == 1)) || !(\old(methAndRunningLastTime) == 0))) && (((((!(2 <= \old(waterLevel)) || (tmp == 0 && methAndRunningLastTime == 0)) || !(\old(pumpRunning) == 0)) || !(methaneLevelCritical == 0)) || !(systemActive == 1)) || !(\old(methAndRunningLastTime) == 0)) - InvariantResult [Line: 317]: Loop Invariant Derived loop invariant: (((((!(1 <= waterLevel) || !(\old(pumpRunning) == 0)) || !(methAndRunningLastTime == 0)) || !(systemActive == 1)) || pumpRunning == 0) && ((((((2 <= waterLevel && pumpRunning == 0) || (1 <= \result && pumpRunning == 0)) || !(1 <= waterLevel)) || !(\old(pumpRunning) == 0)) || !(methaneLevelCritical == 0)) || !(systemActive == 1))) && ((((!(waterLevel == 1) || !(\old(pumpRunning) == 0)) || !(methAndRunningLastTime == 0)) || !(systemActive == 1)) || 1 <= \result) - InvariantResult [Line: 430]: Loop Invariant Derived loop invariant: (((((1 <= pumpRunning && 2 <= waterLevel) || !(1 <= waterLevel)) || !(\old(pumpRunning) == 0)) || !(methaneLevelCritical == 0)) || !(systemActive == 1)) && (((((1 <= pumpRunning && 2 <= waterLevel) || !(1 <= waterLevel)) || !(\old(pumpRunning) == 0)) || !(methAndRunningLastTime == 0)) || !(systemActive == 1)) - InvariantResult [Line: 78]: Loop Invariant Derived loop invariant: (((waterLevel == 1 && methaneLevelCritical == 0) && methAndRunningLastTime == 0) && systemActive == 1) && pumpRunning == 0 - InvariantResult [Line: 64]: Loop Invariant Derived loop invariant: (((waterLevel == 1 && methaneLevelCritical == 0) && methAndRunningLastTime == 0) && systemActive == 1) && pumpRunning == 0 - InvariantResult [Line: 71]: Loop Invariant Derived loop invariant: (((waterLevel == 1 && methaneLevelCritical == 0) && methAndRunningLastTime == 0) && systemActive == 1) && pumpRunning == 0 - InvariantResult [Line: 405]: Loop Invariant Derived loop invariant: (((((!(\old(waterLevel) == 1) || !(\old(pumpRunning) == 0)) || methAndRunningLastTime == 0) || !(systemActive == 1)) || !(\old(methAndRunningLastTime) == 0)) && ((((((((waterLevel == \old(waterLevel) && 1 <= pumpRunning) && 2 <= waterLevel) && methAndRunningLastTime == 0) || (waterLevel == \old(waterLevel) && pumpRunning == 0)) || !(\old(pumpRunning) == 0)) || !(systemActive == 1)) || !(1 <= \old(waterLevel))) || !(\old(methAndRunningLastTime) == 0))) && (((!(2 <= \old(waterLevel)) || !(systemActive == 1)) || ((((((1 <= tmp___0 && 1 <= \result) && \result == 0) && 1 <= tmp) && 1 <= waterLevel) && tmp == 0) && pumpRunning == 0)) || !(1 <= \old(pumpRunning))) - InvariantResult [Line: 457]: Loop Invariant Derived loop invariant: ((((((!(2 <= \old(waterLevel)) || !(methaneLevelCritical == 0)) || !(systemActive == 1)) || !(1 <= \old(pumpRunning))) && ((((!(\old(waterLevel) == 1) || !(\old(pumpRunning) == 0)) || methAndRunningLastTime == 0) || !(systemActive == 1)) || !(\old(methAndRunningLastTime) == 0))) && ((((((((waterLevel == \old(waterLevel) && 1 <= pumpRunning) && 2 <= waterLevel) && methAndRunningLastTime == 0) || ((\result == 0 && waterLevel == \old(waterLevel)) && pumpRunning == 0)) || !(\old(pumpRunning) == 0)) || !(systemActive == 1)) || !(1 <= \old(waterLevel))) || !(\old(methAndRunningLastTime) == 0))) && (((!(2 <= \old(waterLevel)) || (((((((1 <= tmp___0 && \result == 0) && 1 <= \result) && \result == 0) && 1 <= tmp) && 1 <= waterLevel) && tmp == 0) && pumpRunning == 0)) || !(systemActive == 1)) || !(1 <= \old(pumpRunning)))) && ((((!(\old(pumpRunning) == 0) || !(methaneLevelCritical == 0)) || !(systemActive == 1)) || !(1 <= \old(waterLevel))) || !(\old(methAndRunningLastTime) == 0)) - InvariantResult [Line: 502]: Loop Invariant Derived loop invariant: (((((!(1 <= waterLevel) || !(\old(pumpRunning) == 0)) || !(methAndRunningLastTime == 0)) || !(systemActive == 1)) || pumpRunning == 0) && ((((!(waterLevel == 1) || !(\old(pumpRunning) == 0)) || !(methAndRunningLastTime == 0)) || (\result == 0 && tmp___0 == 0)) || !(systemActive == 1))) && (((((((\result == 0 && tmp___0 == 0) && pumpRunning == 0) || (2 <= waterLevel && pumpRunning == 0)) || !(1 <= waterLevel)) || !(\old(pumpRunning) == 0)) || !(methaneLevelCritical == 0)) || !(systemActive == 1)) - InvariantResult [Line: 559]: Loop Invariant Derived loop invariant: (((splverifierCounter == 0 && 1 <= pumpRunning) && 2 <= waterLevel) && systemActive == 1) || ((((splverifierCounter == 0 && methAndRunningLastTime == 0) && 1 <= waterLevel) && systemActive == 1) && pumpRunning == 0) - InvariantResult [Line: 167]: Loop Invariant Derived loop invariant: 1 - InvariantResult [Line: 147]: Loop Invariant Derived loop invariant: (((waterLevel == 1 && methaneLevelCritical == 0) && methAndRunningLastTime == 0) && systemActive == 1) && pumpRunning == 0 - InvariantResult [Line: 558]: Loop Invariant Derived loop invariant: 0 - InvariantResult [Line: 331]: Loop Invariant Derived loop invariant: (((((!(2 <= \old(waterLevel)) || methAndRunningLastTime == 0) || !(systemActive == 1)) || !(1 <= \old(pumpRunning))) || !(\old(methAndRunningLastTime) == 0)) && (((!(2 <= \old(waterLevel)) || !(systemActive == 1)) || ((pumpRunning == \old(pumpRunning) && \result == 0) && 1 <= waterLevel)) || !(1 <= \old(pumpRunning)))) && (((!(\old(pumpRunning) == 0) || !(systemActive == 1)) || !(1 <= \old(waterLevel))) || !(\old(methAndRunningLastTime) == 0)) - InvariantResult [Line: 100]: Loop Invariant Derived loop invariant: 1 RESULT: Ultimate proved your program to be correct! [2021-12-17 15:07:50,922 INFO L540 MonitoredProcess]: [MP /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in -t:2000 (1)] Forceful destruction successful, exit code 0 Received shutdown request... --- End real Ultimate output --- Execution finished normally Writing output log to file Ultimate.log Result: TRUE