./Ultimate.py --spec ../sv-benchmarks/c/properties/unreach-call.prp --file ../sv-benchmarks/c/product-lines/minepump_spec3_product54.cil.c --full-output --architecture 32bit -------------------------------------------------------------------------------- Checking for ERROR reachability Using default analysis Version c3fed411 Calling Ultimate with: /usr/bin/java -Dosgi.configuration.area=/storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/data/config -Xmx15G -Xms4m -jar /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/plugins/org.eclipse.equinox.launcher_1.5.800.v20200727-1323.jar -data @noDefault -ultimatedata /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/data -tc /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/config/AutomizerReach.xml -i ../sv-benchmarks/c/product-lines/minepump_spec3_product54.cil.c -s /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/config/svcomp-Reach-32bit-Automizer_Default.epf --cacsl2boogietranslator.entry.function main --witnessprinter.witness.directory /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux --witnessprinter.witness.filename witness.graphml --witnessprinter.write.witness.besides.input.file false --witnessprinter.graph.data.specification CHECK( init(main()), LTL(G ! call(reach_error())) ) --witnessprinter.graph.data.producer Automizer --witnessprinter.graph.data.architecture 32bit --witnessprinter.graph.data.programhash cbcb1e9315abec7fabb6a689d6a1c811fb94154c71589df191460c14d014c3cb --- Real Ultimate output --- This is Ultimate 0.2.2-tmp.no-commuhash-c3fed41 [2021-12-17 15:08:26,872 INFO L177 SettingsManager]: Resetting all preferences to default values... [2021-12-17 15:08:26,874 INFO L181 SettingsManager]: Resetting UltimateCore preferences to default values [2021-12-17 15:08:26,937 INFO L184 SettingsManager]: Ultimate Commandline Interface provides no preferences, ignoring... [2021-12-17 15:08:26,939 INFO L181 SettingsManager]: Resetting Boogie Preprocessor preferences to default values [2021-12-17 15:08:26,940 INFO L181 SettingsManager]: Resetting Boogie Procedure Inliner preferences to default values [2021-12-17 15:08:26,942 INFO L181 SettingsManager]: Resetting Abstract Interpretation preferences to default values [2021-12-17 15:08:26,946 INFO L181 SettingsManager]: Resetting LassoRanker preferences to default values [2021-12-17 15:08:26,949 INFO L181 SettingsManager]: Resetting Reaching Definitions preferences to default values [2021-12-17 15:08:26,950 INFO L181 SettingsManager]: Resetting SyntaxChecker preferences to default values [2021-12-17 15:08:26,951 INFO L181 SettingsManager]: Resetting Sifa preferences to default values [2021-12-17 15:08:26,952 INFO L184 SettingsManager]: Büchi Program Product provides no preferences, ignoring... [2021-12-17 15:08:26,953 INFO L181 SettingsManager]: Resetting LTL2Aut preferences to default values [2021-12-17 15:08:26,954 INFO L181 SettingsManager]: Resetting PEA to Boogie preferences to default values [2021-12-17 15:08:26,955 INFO L181 SettingsManager]: Resetting BlockEncodingV2 preferences to default values [2021-12-17 15:08:26,956 INFO L181 SettingsManager]: Resetting ChcToBoogie preferences to default values [2021-12-17 15:08:26,956 INFO L181 SettingsManager]: Resetting AutomataScriptInterpreter preferences to default values [2021-12-17 15:08:26,957 INFO L181 SettingsManager]: Resetting BuchiAutomizer preferences to default values [2021-12-17 15:08:26,959 INFO L181 SettingsManager]: Resetting CACSL2BoogieTranslator preferences to default values [2021-12-17 15:08:26,961 INFO L181 SettingsManager]: Resetting CodeCheck preferences to default values [2021-12-17 15:08:26,962 INFO L181 SettingsManager]: Resetting InvariantSynthesis preferences to default values [2021-12-17 15:08:26,968 INFO L181 SettingsManager]: Resetting RCFGBuilder preferences to default values [2021-12-17 15:08:26,969 INFO L181 SettingsManager]: Resetting Referee preferences to default values [2021-12-17 15:08:26,971 INFO L181 SettingsManager]: Resetting TraceAbstraction preferences to default values [2021-12-17 15:08:26,975 INFO L184 SettingsManager]: TraceAbstractionConcurrent provides no preferences, ignoring... [2021-12-17 15:08:26,980 INFO L184 SettingsManager]: TraceAbstractionWithAFAs provides no preferences, ignoring... [2021-12-17 15:08:26,981 INFO L181 SettingsManager]: Resetting TreeAutomizer preferences to default values [2021-12-17 15:08:26,982 INFO L181 SettingsManager]: Resetting IcfgToChc preferences to default values [2021-12-17 15:08:26,984 INFO L181 SettingsManager]: Resetting IcfgTransformer preferences to default values [2021-12-17 15:08:26,985 INFO L184 SettingsManager]: ReqToTest provides no preferences, ignoring... [2021-12-17 15:08:26,985 INFO L181 SettingsManager]: Resetting Boogie Printer preferences to default values [2021-12-17 15:08:26,986 INFO L181 SettingsManager]: Resetting ChcSmtPrinter preferences to default values [2021-12-17 15:08:26,987 INFO L181 SettingsManager]: Resetting ReqPrinter preferences to default values [2021-12-17 15:08:26,988 INFO L181 SettingsManager]: Resetting Witness Printer preferences to default values [2021-12-17 15:08:26,989 INFO L184 SettingsManager]: Boogie PL CUP Parser provides no preferences, ignoring... [2021-12-17 15:08:26,990 INFO L181 SettingsManager]: Resetting CDTParser preferences to default values [2021-12-17 15:08:26,990 INFO L184 SettingsManager]: AutomataScriptParser provides no preferences, ignoring... [2021-12-17 15:08:26,991 INFO L184 SettingsManager]: ReqParser provides no preferences, ignoring... [2021-12-17 15:08:26,991 INFO L181 SettingsManager]: Resetting SmtParser preferences to default values [2021-12-17 15:08:26,992 INFO L181 SettingsManager]: Resetting Witness Parser preferences to default values [2021-12-17 15:08:26,992 INFO L188 SettingsManager]: Finished resetting all preferences to default values... [2021-12-17 15:08:26,993 INFO L101 SettingsManager]: Beginning loading settings from /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/config/svcomp-Reach-32bit-Automizer_Default.epf [2021-12-17 15:08:27,029 INFO L113 SettingsManager]: Loading preferences was successful [2021-12-17 15:08:27,030 INFO L115 SettingsManager]: Preferences different from defaults after loading the file: [2021-12-17 15:08:27,030 INFO L136 SettingsManager]: Preferences of UltimateCore differ from their defaults: [2021-12-17 15:08:27,031 INFO L138 SettingsManager]: * Log level for class=de.uni_freiburg.informatik.ultimate.lib.smtlibutils.quantifier.QuantifierPusher=ERROR; [2021-12-17 15:08:27,032 INFO L136 SettingsManager]: Preferences of Boogie Procedure Inliner differ from their defaults: [2021-12-17 15:08:27,032 INFO L138 SettingsManager]: * Ignore calls to procedures called more than once=ONLY_FOR_SEQUENTIAL_PROGRAMS [2021-12-17 15:08:27,032 INFO L136 SettingsManager]: Preferences of BlockEncodingV2 differ from their defaults: [2021-12-17 15:08:27,033 INFO L138 SettingsManager]: * Create parallel compositions if possible=false [2021-12-17 15:08:27,033 INFO L138 SettingsManager]: * Use SBE=true [2021-12-17 15:08:27,033 INFO L136 SettingsManager]: Preferences of CACSL2BoogieTranslator differ from their defaults: [2021-12-17 15:08:27,034 INFO L138 SettingsManager]: * sizeof long=4 [2021-12-17 15:08:27,034 INFO L138 SettingsManager]: * Overapproximate operations on floating types=true [2021-12-17 15:08:27,034 INFO L138 SettingsManager]: * sizeof POINTER=4 [2021-12-17 15:08:27,034 INFO L138 SettingsManager]: * Check division by zero=IGNORE [2021-12-17 15:08:27,035 INFO L138 SettingsManager]: * Pointer to allocated memory at dereference=IGNORE [2021-12-17 15:08:27,035 INFO L138 SettingsManager]: * If two pointers are subtracted or compared they have the same base address=IGNORE [2021-12-17 15:08:27,035 INFO L138 SettingsManager]: * Check array bounds for arrays that are off heap=IGNORE [2021-12-17 15:08:27,035 INFO L138 SettingsManager]: * sizeof long double=12 [2021-12-17 15:08:27,035 INFO L138 SettingsManager]: * Check if freed pointer was valid=false [2021-12-17 15:08:27,035 INFO L138 SettingsManager]: * Use constant arrays=true [2021-12-17 15:08:27,036 INFO L138 SettingsManager]: * Pointer base address is valid at dereference=IGNORE [2021-12-17 15:08:27,036 INFO L136 SettingsManager]: Preferences of RCFGBuilder differ from their defaults: [2021-12-17 15:08:27,036 INFO L138 SettingsManager]: * Size of a code block=SequenceOfStatements [2021-12-17 15:08:27,036 INFO L138 SettingsManager]: * SMT solver=External_DefaultMode [2021-12-17 15:08:27,036 INFO L138 SettingsManager]: * Command for external solver=z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in -t:2000 [2021-12-17 15:08:27,037 INFO L136 SettingsManager]: Preferences of TraceAbstraction differ from their defaults: [2021-12-17 15:08:27,037 INFO L138 SettingsManager]: * Compute Interpolants along a Counterexample=FPandBP [2021-12-17 15:08:27,037 INFO L138 SettingsManager]: * Positions where we compute the Hoare Annotation=LoopsAndPotentialCycles [2021-12-17 15:08:27,038 INFO L138 SettingsManager]: * Trace refinement strategy=CAMEL [2021-12-17 15:08:27,038 INFO L138 SettingsManager]: * Command for external solver=z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in [2021-12-17 15:08:27,038 INFO L138 SettingsManager]: * Large block encoding in concurrent analysis=OFF [2021-12-17 15:08:27,039 INFO L138 SettingsManager]: * Automaton type used in concurrency analysis=PETRI_NET [2021-12-17 15:08:27,039 INFO L138 SettingsManager]: * Compute Hoare Annotation of negated interpolant automaton, abstraction and CFG=true [2021-12-17 15:08:27,039 INFO L138 SettingsManager]: * Trace refinement exception blacklist=NONE [2021-12-17 15:08:27,039 INFO L138 SettingsManager]: * SMT solver=External_ModelsAndUnsatCoreMode WARNING: An illegal reflective access operation has occurred WARNING: Illegal reflective access by com.sun.xml.bind.v2.runtime.reflect.opt.Injector$1 (file:/storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/plugins/com.sun.xml.bind_2.2.0.v201505121915.jar) to method java.lang.ClassLoader.defineClass(java.lang.String,byte[],int,int) WARNING: Please consider reporting this to the maintainers of com.sun.xml.bind.v2.runtime.reflect.opt.Injector$1 WARNING: Use --illegal-access=warn to enable warnings of further illegal reflective access operations WARNING: All illegal access operations will be denied in a future release Applying setting for plugin de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator: Entry function -> main Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Witness directory -> /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Witness filename -> witness.graphml Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Write witness besides input file -> false Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Graph data specification -> CHECK( init(main()), LTL(G ! call(reach_error())) ) Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Graph data producer -> Automizer Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Graph data architecture -> 32bit Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Graph data programhash -> cbcb1e9315abec7fabb6a689d6a1c811fb94154c71589df191460c14d014c3cb [2021-12-17 15:08:27,293 INFO L75 nceAwareModelManager]: Repository-Root is: /tmp [2021-12-17 15:08:27,310 INFO L261 ainManager$Toolchain]: [Toolchain 1]: Applicable parser(s) successfully (re)initialized [2021-12-17 15:08:27,312 INFO L217 ainManager$Toolchain]: [Toolchain 1]: Toolchain selected. [2021-12-17 15:08:27,314 INFO L271 PluginConnector]: Initializing CDTParser... [2021-12-17 15:08:27,315 INFO L275 PluginConnector]: CDTParser initialized [2021-12-17 15:08:27,316 INFO L432 ainManager$Toolchain]: [Toolchain 1]: Parsing single file: /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/../sv-benchmarks/c/product-lines/minepump_spec3_product54.cil.c [2021-12-17 15:08:27,395 INFO L220 CDTParser]: Created temporary CDT project at /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/data/1607d6334/88c1d4ab45114c92934988c71b6527ae/FLAG718452e96 [2021-12-17 15:08:27,783 INFO L306 CDTParser]: Found 1 translation units. [2021-12-17 15:08:27,783 INFO L160 CDTParser]: Scanning /storage/repos/ultimate/releaseScripts/default/sv-benchmarks/c/product-lines/minepump_spec3_product54.cil.c [2021-12-17 15:08:27,799 INFO L349 CDTParser]: About to delete temporary CDT project at /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/data/1607d6334/88c1d4ab45114c92934988c71b6527ae/FLAG718452e96 [2021-12-17 15:08:28,174 INFO L357 CDTParser]: Successfully deleted /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/data/1607d6334/88c1d4ab45114c92934988c71b6527ae [2021-12-17 15:08:28,177 INFO L299 ainManager$Toolchain]: ####################### [Toolchain 1] ####################### [2021-12-17 15:08:28,178 INFO L131 ToolchainWalker]: Walking toolchain with 6 elements. [2021-12-17 15:08:28,181 INFO L113 PluginConnector]: ------------------------CACSL2BoogieTranslator---------------------------- [2021-12-17 15:08:28,182 INFO L271 PluginConnector]: Initializing CACSL2BoogieTranslator... [2021-12-17 15:08:28,184 INFO L275 PluginConnector]: CACSL2BoogieTranslator initialized [2021-12-17 15:08:28,185 INFO L185 PluginConnector]: Executing the observer ACSLObjectContainerObserver from plugin CACSL2BoogieTranslator for "CDTParser AST 17.12 03:08:28" (1/1) ... [2021-12-17 15:08:28,186 INFO L205 PluginConnector]: Invalid model from CACSL2BoogieTranslator for observer de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator.ACSLObjectContainerObserver@15b6ae48 and model type de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 17.12 03:08:28, skipping insertion in model container [2021-12-17 15:08:28,187 INFO L185 PluginConnector]: Executing the observer CACSL2BoogieTranslatorObserver from plugin CACSL2BoogieTranslator for "CDTParser AST 17.12 03:08:28" (1/1) ... [2021-12-17 15:08:28,192 INFO L145 MainTranslator]: Starting translation in SV-COMP mode [2021-12-17 15:08:28,237 INFO L178 MainTranslator]: Built tables and reachable declarations [2021-12-17 15:08:28,417 WARN L230 ndardFunctionHandler]: Function reach_error is already implemented but we override the implementation for the call at /storage/repos/ultimate/releaseScripts/default/sv-benchmarks/c/product-lines/minepump_spec3_product54.cil.c[4478,4491] [2021-12-17 15:08:28,536 INFO L209 PostProcessor]: Analyzing one entry point: main [2021-12-17 15:08:28,549 INFO L203 MainTranslator]: Completed pre-run [2021-12-17 15:08:28,580 WARN L230 ndardFunctionHandler]: Function reach_error is already implemented but we override the implementation for the call at /storage/repos/ultimate/releaseScripts/default/sv-benchmarks/c/product-lines/minepump_spec3_product54.cil.c[4478,4491] [2021-12-17 15:08:28,607 INFO L209 PostProcessor]: Analyzing one entry point: main [2021-12-17 15:08:28,623 INFO L208 MainTranslator]: Completed translation [2021-12-17 15:08:28,624 INFO L202 PluginConnector]: Adding new model de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 17.12 03:08:28 WrapperNode [2021-12-17 15:08:28,624 INFO L132 PluginConnector]: ------------------------ END CACSL2BoogieTranslator---------------------------- [2021-12-17 15:08:28,625 INFO L113 PluginConnector]: ------------------------Boogie Procedure Inliner---------------------------- [2021-12-17 15:08:28,625 INFO L271 PluginConnector]: Initializing Boogie Procedure Inliner... [2021-12-17 15:08:28,625 INFO L275 PluginConnector]: Boogie Procedure Inliner initialized [2021-12-17 15:08:28,632 INFO L185 PluginConnector]: Executing the observer TypeChecker from plugin Boogie Procedure Inliner for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 17.12 03:08:28" (1/1) ... [2021-12-17 15:08:28,655 INFO L185 PluginConnector]: Executing the observer Inliner from plugin Boogie Procedure Inliner for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 17.12 03:08:28" (1/1) ... [2021-12-17 15:08:28,679 INFO L137 Inliner]: procedures = 57, calls = 160, calls flagged for inlining = 24, calls inlined = 21, statements flattened = 284 [2021-12-17 15:08:28,680 INFO L132 PluginConnector]: ------------------------ END Boogie Procedure Inliner---------------------------- [2021-12-17 15:08:28,681 INFO L113 PluginConnector]: ------------------------Boogie Preprocessor---------------------------- [2021-12-17 15:08:28,681 INFO L271 PluginConnector]: Initializing Boogie Preprocessor... [2021-12-17 15:08:28,681 INFO L275 PluginConnector]: Boogie Preprocessor initialized [2021-12-17 15:08:28,688 INFO L185 PluginConnector]: Executing the observer EnsureBoogieModelObserver from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 17.12 03:08:28" (1/1) ... [2021-12-17 15:08:28,688 INFO L185 PluginConnector]: Executing the observer TypeChecker from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 17.12 03:08:28" (1/1) ... [2021-12-17 15:08:28,690 INFO L185 PluginConnector]: Executing the observer ConstExpander from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 17.12 03:08:28" (1/1) ... [2021-12-17 15:08:28,691 INFO L185 PluginConnector]: Executing the observer StructExpander from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 17.12 03:08:28" (1/1) ... [2021-12-17 15:08:28,696 INFO L185 PluginConnector]: Executing the observer UnstructureCode from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 17.12 03:08:28" (1/1) ... [2021-12-17 15:08:28,700 INFO L185 PluginConnector]: Executing the observer FunctionInliner from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 17.12 03:08:28" (1/1) ... [2021-12-17 15:08:28,707 INFO L185 PluginConnector]: Executing the observer BoogieSymbolTableConstructor from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 17.12 03:08:28" (1/1) ... [2021-12-17 15:08:28,710 INFO L132 PluginConnector]: ------------------------ END Boogie Preprocessor---------------------------- [2021-12-17 15:08:28,711 INFO L113 PluginConnector]: ------------------------RCFGBuilder---------------------------- [2021-12-17 15:08:28,720 INFO L271 PluginConnector]: Initializing RCFGBuilder... [2021-12-17 15:08:28,721 INFO L275 PluginConnector]: RCFGBuilder initialized [2021-12-17 15:08:28,722 INFO L185 PluginConnector]: Executing the observer RCFGBuilderObserver from plugin RCFGBuilder for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 17.12 03:08:28" (1/1) ... [2021-12-17 15:08:28,727 INFO L168 SolverBuilder]: Constructing external solver with command: z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in -t:2000 [2021-12-17 15:08:28,740 INFO L189 MonitoredProcess]: No working directory specified, using /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 [2021-12-17 15:08:28,757 INFO L229 MonitoredProcess]: Starting monitored process 1 with /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in -t:2000 (exit command is (exit), workingDir is null) [2021-12-17 15:08:28,783 INFO L327 MonitoredProcess]: [MP /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in -t:2000 (1)] Waiting until timeout for monitored process [2021-12-17 15:08:28,800 INFO L130 BoogieDeclarations]: Found specification of procedure #Ultimate.allocInit [2021-12-17 15:08:28,801 INFO L130 BoogieDeclarations]: Found specification of procedure processEnvironment__wrappee__base [2021-12-17 15:08:28,801 INFO L138 BoogieDeclarations]: Found implementation of procedure processEnvironment__wrappee__base [2021-12-17 15:08:28,801 INFO L130 BoogieDeclarations]: Found specification of procedure timeShift [2021-12-17 15:08:28,801 INFO L138 BoogieDeclarations]: Found implementation of procedure timeShift [2021-12-17 15:08:28,801 INFO L130 BoogieDeclarations]: Found specification of procedure cleanup [2021-12-17 15:08:28,802 INFO L138 BoogieDeclarations]: Found implementation of procedure cleanup [2021-12-17 15:08:28,802 INFO L130 BoogieDeclarations]: Found specification of procedure isMethaneLevelCritical [2021-12-17 15:08:28,802 INFO L138 BoogieDeclarations]: Found implementation of procedure isMethaneLevelCritical [2021-12-17 15:08:28,802 INFO L130 BoogieDeclarations]: Found specification of procedure processEnvironment__wrappee__highWaterSensor [2021-12-17 15:08:28,803 INFO L138 BoogieDeclarations]: Found implementation of procedure processEnvironment__wrappee__highWaterSensor [2021-12-17 15:08:28,803 INFO L130 BoogieDeclarations]: Found specification of procedure waterRise [2021-12-17 15:08:28,803 INFO L138 BoogieDeclarations]: Found implementation of procedure waterRise [2021-12-17 15:08:28,803 INFO L130 BoogieDeclarations]: Found specification of procedure processEnvironment__wrappee__lowWaterSensor [2021-12-17 15:08:28,803 INFO L138 BoogieDeclarations]: Found implementation of procedure processEnvironment__wrappee__lowWaterSensor [2021-12-17 15:08:28,804 INFO L130 BoogieDeclarations]: Found specification of procedure deactivatePump [2021-12-17 15:08:28,804 INFO L138 BoogieDeclarations]: Found implementation of procedure deactivatePump [2021-12-17 15:08:28,804 INFO L130 BoogieDeclarations]: Found specification of procedure write~init~int [2021-12-17 15:08:28,804 INFO L130 BoogieDeclarations]: Found specification of procedure changeMethaneLevel [2021-12-17 15:08:28,804 INFO L138 BoogieDeclarations]: Found implementation of procedure changeMethaneLevel [2021-12-17 15:08:28,804 INFO L130 BoogieDeclarations]: Found specification of procedure ULTIMATE.start [2021-12-17 15:08:28,804 INFO L138 BoogieDeclarations]: Found implementation of procedure ULTIMATE.start [2021-12-17 15:08:28,897 INFO L236 CfgBuilder]: Building ICFG [2021-12-17 15:08:28,899 INFO L262 CfgBuilder]: Building CFG for each procedure with an implementation [2021-12-17 15:08:29,193 INFO L277 CfgBuilder]: Performing block encoding [2021-12-17 15:08:29,203 INFO L296 CfgBuilder]: Using the 1 location(s) as analysis (start of procedure ULTIMATE.start) [2021-12-17 15:08:29,204 INFO L301 CfgBuilder]: Removed 2 assume(true) statements. [2021-12-17 15:08:29,206 INFO L202 PluginConnector]: Adding new model de.uni_freiburg.informatik.ultimate.plugins.generator.rcfgbuilder CFG 17.12 03:08:29 BoogieIcfgContainer [2021-12-17 15:08:29,206 INFO L132 PluginConnector]: ------------------------ END RCFGBuilder---------------------------- [2021-12-17 15:08:29,208 INFO L113 PluginConnector]: ------------------------TraceAbstraction---------------------------- [2021-12-17 15:08:29,208 INFO L271 PluginConnector]: Initializing TraceAbstraction... [2021-12-17 15:08:29,215 INFO L275 PluginConnector]: TraceAbstraction initialized [2021-12-17 15:08:29,215 INFO L185 PluginConnector]: Executing the observer TraceAbstractionObserver from plugin TraceAbstraction for "CDTParser AST 17.12 03:08:28" (1/3) ... [2021-12-17 15:08:29,216 INFO L205 PluginConnector]: Invalid model from TraceAbstraction for observer de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction.TraceAbstractionObserver@282b1565 and model type de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction AST 17.12 03:08:29, skipping insertion in model container [2021-12-17 15:08:29,216 INFO L185 PluginConnector]: Executing the observer TraceAbstractionObserver from plugin TraceAbstraction for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 17.12 03:08:28" (2/3) ... [2021-12-17 15:08:29,216 INFO L205 PluginConnector]: Invalid model from TraceAbstraction for observer de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction.TraceAbstractionObserver@282b1565 and model type de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction AST 17.12 03:08:29, skipping insertion in model container [2021-12-17 15:08:29,216 INFO L185 PluginConnector]: Executing the observer TraceAbstractionObserver from plugin TraceAbstraction for "de.uni_freiburg.informatik.ultimate.plugins.generator.rcfgbuilder CFG 17.12 03:08:29" (3/3) ... [2021-12-17 15:08:29,218 INFO L111 eAbstractionObserver]: Analyzing ICFG minepump_spec3_product54.cil.c [2021-12-17 15:08:29,222 INFO L204 ceAbstractionStarter]: Automizer settings: Hoare:true NWA Interpolation:FPandBP Determinization: PREDICATE_ABSTRACTION [2021-12-17 15:08:29,222 INFO L163 ceAbstractionStarter]: Applying trace abstraction to program that has 1 error locations. [2021-12-17 15:08:29,264 INFO L338 AbstractCegarLoop]: ======== Iteration 0 == of CEGAR loop == AllErrorsAtOnce ======== [2021-12-17 15:08:29,270 INFO L339 AbstractCegarLoop]: Settings: SEPARATE_VIOLATION_CHECK=true, mInterprocedural=true, mMaxIterations=1000000, mWatchIteration=1000000, mArtifact=RCFG, mInterpolation=FPandBP, mInterpolantAutomaton=STRAIGHT_LINE, mDumpAutomata=false, mAutomataFormat=ATS_NUMERATE, mDumpPath=., mDeterminiation=PREDICATE_ABSTRACTION, mMinimize=MINIMIZE_SEVPA, mHoare=true, mAutomataTypeConcurrency=PETRI_NET, mHoareTripleChecks=INCREMENTAL, mHoareAnnotationPositions=LoopsAndPotentialCycles, mDumpOnlyReuseAutomata=false, mLimitTraceHistogram=0, mErrorLocTimeLimit=0, mLimitPathProgramCount=0, mCollectInterpolantStatistics=true, mHeuristicEmptinessCheck=false, mHeuristicEmptinessCheckAStarHeuristic=ZERO, mHeuristicEmptinessCheckAStarHeuristicRandomSeed=1337, mHeuristicEmptinessCheckSmtFeatureScoringMethod=DAGSIZE, mSMTFeatureExtraction=false, mSMTFeatureExtractionDumpPath=., mOverrideInterpolantAutomaton=false, mMcrInterpolantMethod=WP, mLoopAccelerationTechnique=FAST_UPR [2021-12-17 15:08:29,270 INFO L340 AbstractCegarLoop]: Starting to check reachability of 1 error locations. [2021-12-17 15:08:29,286 INFO L276 IsEmpty]: Start isEmpty. Operand has 103 states, 76 states have (on average 1.381578947368421) internal successors, (105), 86 states have internal predecessors, (105), 16 states have call successors, (16), 9 states have call predecessors, (16), 9 states have return successors, (16), 11 states have call predecessors, (16), 16 states have call successors, (16) [2021-12-17 15:08:29,293 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 26 [2021-12-17 15:08:29,293 INFO L506 BasicCegarLoop]: Found error trace [2021-12-17 15:08:29,293 INFO L514 BasicCegarLoop]: trace histogram [1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2021-12-17 15:08:29,294 INFO L402 AbstractCegarLoop]: === Iteration 1 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2021-12-17 15:08:29,298 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2021-12-17 15:08:29,299 INFO L85 PathProgramCache]: Analyzing trace with hash 149329663, now seen corresponding path program 1 times [2021-12-17 15:08:29,306 INFO L121 FreeRefinementEngine]: Executing refinement strategy CAMEL [2021-12-17 15:08:29,306 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [1411140648] [2021-12-17 15:08:29,307 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2021-12-17 15:08:29,307 INFO L126 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2021-12-17 15:08:29,455 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:08:29,531 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 14 [2021-12-17 15:08:29,539 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:08:29,549 INFO L134 CoverageAnalysis]: Checked inductivity of 0 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2021-12-17 15:08:29,550 INFO L139 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2021-12-17 15:08:29,550 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [1411140648] [2021-12-17 15:08:29,550 INFO L160 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [1411140648] provided 1 perfect and 0 imperfect interpolant sequences [2021-12-17 15:08:29,551 INFO L186 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2021-12-17 15:08:29,551 INFO L199 FreeRefinementEngine]: Number of different interpolants: perfect sequences [2] imperfect sequences [] total 2 [2021-12-17 15:08:29,553 INFO L115 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [486439997] [2021-12-17 15:08:29,554 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2021-12-17 15:08:29,557 INFO L546 AbstractCegarLoop]: INTERPOLANT automaton has 2 states [2021-12-17 15:08:29,558 INFO L103 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2021-12-17 15:08:29,607 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 2 interpolants. [2021-12-17 15:08:29,609 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=1, Invalid=1, Unknown=0, NotChecked=0, Total=2 [2021-12-17 15:08:29,612 INFO L87 Difference]: Start difference. First operand has 103 states, 76 states have (on average 1.381578947368421) internal successors, (105), 86 states have internal predecessors, (105), 16 states have call successors, (16), 9 states have call predecessors, (16), 9 states have return successors, (16), 11 states have call predecessors, (16), 16 states have call successors, (16) Second operand has 2 states, 2 states have (on average 10.5) internal successors, (21), 2 states have internal predecessors, (21), 1 states have call successors, (3), 2 states have call predecessors, (3), 1 states have return successors, (1), 1 states have call predecessors, (1), 1 states have call successors, (1) [2021-12-17 15:08:29,665 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2021-12-17 15:08:29,666 INFO L93 Difference]: Finished difference Result 198 states and 269 transitions. [2021-12-17 15:08:29,666 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 2 states. [2021-12-17 15:08:29,668 INFO L78 Accepts]: Start accepts. Automaton has has 2 states, 2 states have (on average 10.5) internal successors, (21), 2 states have internal predecessors, (21), 1 states have call successors, (3), 2 states have call predecessors, (3), 1 states have return successors, (1), 1 states have call predecessors, (1), 1 states have call successors, (1) Word has length 25 [2021-12-17 15:08:29,668 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2021-12-17 15:08:29,677 INFO L225 Difference]: With dead ends: 198 [2021-12-17 15:08:29,677 INFO L226 Difference]: Without dead ends: 94 [2021-12-17 15:08:29,682 INFO L932 BasicCegarLoop]: 0 DeclaredPredicates, 4 GetRequests, 4 SyntacticMatches, 0 SemanticMatches, 0 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 0 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=1, Invalid=1, Unknown=0, NotChecked=0, Total=2 [2021-12-17 15:08:29,686 INFO L933 BasicCegarLoop]: 131 mSDtfsCounter, 0 mSDsluCounter, 0 mSDsCounter, 0 mSdLazyCounter, 0 mSolverCounterSat, 0 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.0s Time, 0 mProtectedPredicate, 0 mProtectedAction, 0 SdHoareTripleChecker+Valid, 131 SdHoareTripleChecker+Invalid, 0 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 0 IncrementalHoareTripleChecker+Valid, 0 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.0s IncrementalHoareTripleChecker+Time [2021-12-17 15:08:29,687 INFO L934 BasicCegarLoop]: SdHoareTripleChecker [0 Valid, 131 Invalid, 0 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [0 Valid, 0 Invalid, 0 Unknown, 0 Unchecked, 0.0s Time] [2021-12-17 15:08:29,700 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 94 states. [2021-12-17 15:08:29,729 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 94 to 94. [2021-12-17 15:08:29,730 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 94 states, 69 states have (on average 1.318840579710145) internal successors, (91), 78 states have internal predecessors, (91), 16 states have call successors, (16), 9 states have call predecessors, (16), 8 states have return successors, (15), 10 states have call predecessors, (15), 15 states have call successors, (15) [2021-12-17 15:08:29,737 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 94 states to 94 states and 122 transitions. [2021-12-17 15:08:29,738 INFO L78 Accepts]: Start accepts. Automaton has 94 states and 122 transitions. Word has length 25 [2021-12-17 15:08:29,739 INFO L84 Accepts]: Finished accepts. word is rejected. [2021-12-17 15:08:29,739 INFO L470 AbstractCegarLoop]: Abstraction has 94 states and 122 transitions. [2021-12-17 15:08:29,739 INFO L471 AbstractCegarLoop]: INTERPOLANT automaton has has 2 states, 2 states have (on average 10.5) internal successors, (21), 2 states have internal predecessors, (21), 1 states have call successors, (3), 2 states have call predecessors, (3), 1 states have return successors, (1), 1 states have call predecessors, (1), 1 states have call successors, (1) [2021-12-17 15:08:29,740 INFO L276 IsEmpty]: Start isEmpty. Operand 94 states and 122 transitions. [2021-12-17 15:08:29,745 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 27 [2021-12-17 15:08:29,746 INFO L506 BasicCegarLoop]: Found error trace [2021-12-17 15:08:29,746 INFO L514 BasicCegarLoop]: trace histogram [1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2021-12-17 15:08:29,747 WARN L452 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable0 [2021-12-17 15:08:29,747 INFO L402 AbstractCegarLoop]: === Iteration 2 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2021-12-17 15:08:29,750 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2021-12-17 15:08:29,750 INFO L85 PathProgramCache]: Analyzing trace with hash 67554452, now seen corresponding path program 1 times [2021-12-17 15:08:29,751 INFO L121 FreeRefinementEngine]: Executing refinement strategy CAMEL [2021-12-17 15:08:29,752 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [341137445] [2021-12-17 15:08:29,752 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2021-12-17 15:08:29,752 INFO L126 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2021-12-17 15:08:29,782 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:08:29,844 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 15 [2021-12-17 15:08:29,846 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:08:29,851 INFO L134 CoverageAnalysis]: Checked inductivity of 0 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2021-12-17 15:08:29,852 INFO L139 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2021-12-17 15:08:29,853 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [341137445] [2021-12-17 15:08:29,853 INFO L160 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [341137445] provided 1 perfect and 0 imperfect interpolant sequences [2021-12-17 15:08:29,853 INFO L186 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2021-12-17 15:08:29,853 INFO L199 FreeRefinementEngine]: Number of different interpolants: perfect sequences [3] imperfect sequences [] total 3 [2021-12-17 15:08:29,854 INFO L115 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [199273220] [2021-12-17 15:08:29,854 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2021-12-17 15:08:29,855 INFO L546 AbstractCegarLoop]: INTERPOLANT automaton has 3 states [2021-12-17 15:08:29,855 INFO L103 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2021-12-17 15:08:29,856 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 3 interpolants. [2021-12-17 15:08:29,856 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=3, Invalid=3, Unknown=0, NotChecked=0, Total=6 [2021-12-17 15:08:29,856 INFO L87 Difference]: Start difference. First operand 94 states and 122 transitions. Second operand has 3 states, 3 states have (on average 7.333333333333333) internal successors, (22), 3 states have internal predecessors, (22), 1 states have call successors, (3), 2 states have call predecessors, (3), 1 states have return successors, (1), 1 states have call predecessors, (1), 1 states have call successors, (1) [2021-12-17 15:08:29,877 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2021-12-17 15:08:29,878 INFO L93 Difference]: Finished difference Result 153 states and 199 transitions. [2021-12-17 15:08:29,878 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 3 states. [2021-12-17 15:08:29,878 INFO L78 Accepts]: Start accepts. Automaton has has 3 states, 3 states have (on average 7.333333333333333) internal successors, (22), 3 states have internal predecessors, (22), 1 states have call successors, (3), 2 states have call predecessors, (3), 1 states have return successors, (1), 1 states have call predecessors, (1), 1 states have call successors, (1) Word has length 26 [2021-12-17 15:08:29,879 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2021-12-17 15:08:29,881 INFO L225 Difference]: With dead ends: 153 [2021-12-17 15:08:29,881 INFO L226 Difference]: Without dead ends: 85 [2021-12-17 15:08:29,888 INFO L932 BasicCegarLoop]: 0 DeclaredPredicates, 5 GetRequests, 4 SyntacticMatches, 0 SemanticMatches, 1 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 0 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=3, Invalid=3, Unknown=0, NotChecked=0, Total=6 [2021-12-17 15:08:29,890 INFO L933 BasicCegarLoop]: 109 mSDtfsCounter, 13 mSDsluCounter, 92 mSDsCounter, 0 mSdLazyCounter, 1 mSolverCounterSat, 0 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.0s Time, 0 mProtectedPredicate, 0 mProtectedAction, 16 SdHoareTripleChecker+Valid, 201 SdHoareTripleChecker+Invalid, 1 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 0 IncrementalHoareTripleChecker+Valid, 1 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.0s IncrementalHoareTripleChecker+Time [2021-12-17 15:08:29,893 INFO L934 BasicCegarLoop]: SdHoareTripleChecker [16 Valid, 201 Invalid, 1 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [0 Valid, 1 Invalid, 0 Unknown, 0 Unchecked, 0.0s Time] [2021-12-17 15:08:29,894 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 85 states. [2021-12-17 15:08:29,902 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 85 to 85. [2021-12-17 15:08:29,906 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 85 states, 63 states have (on average 1.3333333333333333) internal successors, (84), 72 states have internal predecessors, (84), 13 states have call successors, (13), 8 states have call predecessors, (13), 8 states have return successors, (13), 8 states have call predecessors, (13), 13 states have call successors, (13) [2021-12-17 15:08:29,907 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 85 states to 85 states and 110 transitions. [2021-12-17 15:08:29,907 INFO L78 Accepts]: Start accepts. Automaton has 85 states and 110 transitions. Word has length 26 [2021-12-17 15:08:29,907 INFO L84 Accepts]: Finished accepts. word is rejected. [2021-12-17 15:08:29,908 INFO L470 AbstractCegarLoop]: Abstraction has 85 states and 110 transitions. [2021-12-17 15:08:29,908 INFO L471 AbstractCegarLoop]: INTERPOLANT automaton has has 3 states, 3 states have (on average 7.333333333333333) internal successors, (22), 3 states have internal predecessors, (22), 1 states have call successors, (3), 2 states have call predecessors, (3), 1 states have return successors, (1), 1 states have call predecessors, (1), 1 states have call successors, (1) [2021-12-17 15:08:29,909 INFO L276 IsEmpty]: Start isEmpty. Operand 85 states and 110 transitions. [2021-12-17 15:08:29,916 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 32 [2021-12-17 15:08:29,916 INFO L506 BasicCegarLoop]: Found error trace [2021-12-17 15:08:29,917 INFO L514 BasicCegarLoop]: trace histogram [1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2021-12-17 15:08:29,917 WARN L452 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable1 [2021-12-17 15:08:29,917 INFO L402 AbstractCegarLoop]: === Iteration 3 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2021-12-17 15:08:29,918 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2021-12-17 15:08:29,918 INFO L85 PathProgramCache]: Analyzing trace with hash -6965766, now seen corresponding path program 1 times [2021-12-17 15:08:29,919 INFO L121 FreeRefinementEngine]: Executing refinement strategy CAMEL [2021-12-17 15:08:29,919 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [1462265007] [2021-12-17 15:08:29,919 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2021-12-17 15:08:29,919 INFO L126 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2021-12-17 15:08:29,946 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:08:29,985 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 20 [2021-12-17 15:08:29,988 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:08:29,996 INFO L134 CoverageAnalysis]: Checked inductivity of 0 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2021-12-17 15:08:29,997 INFO L139 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2021-12-17 15:08:29,997 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [1462265007] [2021-12-17 15:08:29,997 INFO L160 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [1462265007] provided 1 perfect and 0 imperfect interpolant sequences [2021-12-17 15:08:29,998 INFO L186 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2021-12-17 15:08:29,998 INFO L199 FreeRefinementEngine]: Number of different interpolants: perfect sequences [5] imperfect sequences [] total 5 [2021-12-17 15:08:29,998 INFO L115 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [984141439] [2021-12-17 15:08:29,998 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2021-12-17 15:08:29,999 INFO L546 AbstractCegarLoop]: INTERPOLANT automaton has 5 states [2021-12-17 15:08:29,999 INFO L103 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2021-12-17 15:08:30,000 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 5 interpolants. [2021-12-17 15:08:30,000 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=7, Invalid=13, Unknown=0, NotChecked=0, Total=20 [2021-12-17 15:08:30,000 INFO L87 Difference]: Start difference. First operand 85 states and 110 transitions. Second operand has 5 states, 5 states have (on average 5.6) internal successors, (28), 5 states have internal predecessors, (28), 2 states have call successors, (2), 2 states have call predecessors, (2), 1 states have return successors, (1), 1 states have call predecessors, (1), 1 states have call successors, (1) [2021-12-17 15:08:30,078 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2021-12-17 15:08:30,078 INFO L93 Difference]: Finished difference Result 163 states and 214 transitions. [2021-12-17 15:08:30,079 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 5 states. [2021-12-17 15:08:30,079 INFO L78 Accepts]: Start accepts. Automaton has has 5 states, 5 states have (on average 5.6) internal successors, (28), 5 states have internal predecessors, (28), 2 states have call successors, (2), 2 states have call predecessors, (2), 1 states have return successors, (1), 1 states have call predecessors, (1), 1 states have call successors, (1) Word has length 31 [2021-12-17 15:08:30,080 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2021-12-17 15:08:30,083 INFO L225 Difference]: With dead ends: 163 [2021-12-17 15:08:30,083 INFO L226 Difference]: Without dead ends: 85 [2021-12-17 15:08:30,084 INFO L932 BasicCegarLoop]: 0 DeclaredPredicates, 11 GetRequests, 6 SyntacticMatches, 0 SemanticMatches, 5 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 0 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=17, Invalid=25, Unknown=0, NotChecked=0, Total=42 [2021-12-17 15:08:30,089 INFO L933 BasicCegarLoop]: 103 mSDtfsCounter, 135 mSDsluCounter, 174 mSDsCounter, 0 mSdLazyCounter, 9 mSolverCounterSat, 9 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.0s Time, 0 mProtectedPredicate, 0 mProtectedAction, 135 SdHoareTripleChecker+Valid, 277 SdHoareTripleChecker+Invalid, 18 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 9 IncrementalHoareTripleChecker+Valid, 9 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.0s IncrementalHoareTripleChecker+Time [2021-12-17 15:08:30,091 INFO L934 BasicCegarLoop]: SdHoareTripleChecker [135 Valid, 277 Invalid, 18 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [9 Valid, 9 Invalid, 0 Unknown, 0 Unchecked, 0.0s Time] [2021-12-17 15:08:30,092 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 85 states. [2021-12-17 15:08:30,100 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 85 to 85. [2021-12-17 15:08:30,100 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 85 states, 63 states have (on average 1.3174603174603174) internal successors, (83), 72 states have internal predecessors, (83), 13 states have call successors, (13), 8 states have call predecessors, (13), 8 states have return successors, (13), 8 states have call predecessors, (13), 13 states have call successors, (13) [2021-12-17 15:08:30,101 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 85 states to 85 states and 109 transitions. [2021-12-17 15:08:30,101 INFO L78 Accepts]: Start accepts. Automaton has 85 states and 109 transitions. Word has length 31 [2021-12-17 15:08:30,101 INFO L84 Accepts]: Finished accepts. word is rejected. [2021-12-17 15:08:30,102 INFO L470 AbstractCegarLoop]: Abstraction has 85 states and 109 transitions. [2021-12-17 15:08:30,102 INFO L471 AbstractCegarLoop]: INTERPOLANT automaton has has 5 states, 5 states have (on average 5.6) internal successors, (28), 5 states have internal predecessors, (28), 2 states have call successors, (2), 2 states have call predecessors, (2), 1 states have return successors, (1), 1 states have call predecessors, (1), 1 states have call successors, (1) [2021-12-17 15:08:30,102 INFO L276 IsEmpty]: Start isEmpty. Operand 85 states and 109 transitions. [2021-12-17 15:08:30,103 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 45 [2021-12-17 15:08:30,103 INFO L506 BasicCegarLoop]: Found error trace [2021-12-17 15:08:30,103 INFO L514 BasicCegarLoop]: trace histogram [2, 2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2021-12-17 15:08:30,104 WARN L452 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable2 [2021-12-17 15:08:30,104 INFO L402 AbstractCegarLoop]: === Iteration 4 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2021-12-17 15:08:30,104 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2021-12-17 15:08:30,104 INFO L85 PathProgramCache]: Analyzing trace with hash 1330354743, now seen corresponding path program 1 times [2021-12-17 15:08:30,105 INFO L121 FreeRefinementEngine]: Executing refinement strategy CAMEL [2021-12-17 15:08:30,105 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [266418286] [2021-12-17 15:08:30,105 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2021-12-17 15:08:30,105 INFO L126 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2021-12-17 15:08:30,121 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:08:30,145 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 20 [2021-12-17 15:08:30,147 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:08:30,152 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 27 [2021-12-17 15:08:30,153 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:08:30,155 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 33 [2021-12-17 15:08:30,156 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:08:30,159 INFO L134 CoverageAnalysis]: Checked inductivity of 3 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 3 trivial. 0 not checked. [2021-12-17 15:08:30,159 INFO L139 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2021-12-17 15:08:30,159 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [266418286] [2021-12-17 15:08:30,159 INFO L160 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [266418286] provided 1 perfect and 0 imperfect interpolant sequences [2021-12-17 15:08:30,159 INFO L186 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2021-12-17 15:08:30,160 INFO L199 FreeRefinementEngine]: Number of different interpolants: perfect sequences [4] imperfect sequences [] total 4 [2021-12-17 15:08:30,160 INFO L115 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [1424651762] [2021-12-17 15:08:30,160 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2021-12-17 15:08:30,160 INFO L546 AbstractCegarLoop]: INTERPOLANT automaton has 4 states [2021-12-17 15:08:30,161 INFO L103 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2021-12-17 15:08:30,161 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 4 interpolants. [2021-12-17 15:08:30,161 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=5, Invalid=7, Unknown=0, NotChecked=0, Total=12 [2021-12-17 15:08:30,161 INFO L87 Difference]: Start difference. First operand 85 states and 109 transitions. Second operand has 4 states, 4 states have (on average 8.75) internal successors, (35), 3 states have internal predecessors, (35), 2 states have call successors, (4), 3 states have call predecessors, (4), 1 states have return successors, (3), 1 states have call predecessors, (3), 1 states have call successors, (3) [2021-12-17 15:08:30,293 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2021-12-17 15:08:30,294 INFO L93 Difference]: Finished difference Result 246 states and 320 transitions. [2021-12-17 15:08:30,294 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 5 states. [2021-12-17 15:08:30,294 INFO L78 Accepts]: Start accepts. Automaton has has 4 states, 4 states have (on average 8.75) internal successors, (35), 3 states have internal predecessors, (35), 2 states have call successors, (4), 3 states have call predecessors, (4), 1 states have return successors, (3), 1 states have call predecessors, (3), 1 states have call successors, (3) Word has length 44 [2021-12-17 15:08:30,295 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2021-12-17 15:08:30,296 INFO L225 Difference]: With dead ends: 246 [2021-12-17 15:08:30,296 INFO L226 Difference]: Without dead ends: 168 [2021-12-17 15:08:30,297 INFO L932 BasicCegarLoop]: 0 DeclaredPredicates, 11 GetRequests, 8 SyntacticMatches, 0 SemanticMatches, 3 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 0 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=9, Invalid=11, Unknown=0, NotChecked=0, Total=20 [2021-12-17 15:08:30,298 INFO L933 BasicCegarLoop]: 117 mSDtfsCounter, 154 mSDsluCounter, 121 mSDsCounter, 0 mSdLazyCounter, 78 mSolverCounterSat, 41 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.1s Time, 0 mProtectedPredicate, 0 mProtectedAction, 160 SdHoareTripleChecker+Valid, 238 SdHoareTripleChecker+Invalid, 119 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 41 IncrementalHoareTripleChecker+Valid, 78 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.1s IncrementalHoareTripleChecker+Time [2021-12-17 15:08:30,298 INFO L934 BasicCegarLoop]: SdHoareTripleChecker [160 Valid, 238 Invalid, 119 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [41 Valid, 78 Invalid, 0 Unknown, 0 Unchecked, 0.1s Time] [2021-12-17 15:08:30,299 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 168 states. [2021-12-17 15:08:30,315 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 168 to 162. [2021-12-17 15:08:30,316 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 162 states, 122 states have (on average 1.2868852459016393) internal successors, (157), 130 states have internal predecessors, (157), 19 states have call successors, (19), 15 states have call predecessors, (19), 20 states have return successors, (30), 21 states have call predecessors, (30), 19 states have call successors, (30) [2021-12-17 15:08:30,317 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 162 states to 162 states and 206 transitions. [2021-12-17 15:08:30,317 INFO L78 Accepts]: Start accepts. Automaton has 162 states and 206 transitions. Word has length 44 [2021-12-17 15:08:30,317 INFO L84 Accepts]: Finished accepts. word is rejected. [2021-12-17 15:08:30,318 INFO L470 AbstractCegarLoop]: Abstraction has 162 states and 206 transitions. [2021-12-17 15:08:30,318 INFO L471 AbstractCegarLoop]: INTERPOLANT automaton has has 4 states, 4 states have (on average 8.75) internal successors, (35), 3 states have internal predecessors, (35), 2 states have call successors, (4), 3 states have call predecessors, (4), 1 states have return successors, (3), 1 states have call predecessors, (3), 1 states have call successors, (3) [2021-12-17 15:08:30,318 INFO L276 IsEmpty]: Start isEmpty. Operand 162 states and 206 transitions. [2021-12-17 15:08:30,319 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 51 [2021-12-17 15:08:30,319 INFO L506 BasicCegarLoop]: Found error trace [2021-12-17 15:08:30,320 INFO L514 BasicCegarLoop]: trace histogram [1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2021-12-17 15:08:30,320 WARN L452 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable3 [2021-12-17 15:08:30,320 INFO L402 AbstractCegarLoop]: === Iteration 5 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2021-12-17 15:08:30,320 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2021-12-17 15:08:30,321 INFO L85 PathProgramCache]: Analyzing trace with hash 1858639799, now seen corresponding path program 1 times [2021-12-17 15:08:30,321 INFO L121 FreeRefinementEngine]: Executing refinement strategy CAMEL [2021-12-17 15:08:30,321 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [271783690] [2021-12-17 15:08:30,321 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2021-12-17 15:08:30,321 INFO L126 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2021-12-17 15:08:30,335 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:08:30,353 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 20 [2021-12-17 15:08:30,357 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:08:30,362 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 2 [2021-12-17 15:08:30,365 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:08:30,394 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 39 [2021-12-17 15:08:30,395 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:08:30,398 INFO L134 CoverageAnalysis]: Checked inductivity of 0 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2021-12-17 15:08:30,399 INFO L139 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2021-12-17 15:08:30,399 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [271783690] [2021-12-17 15:08:30,399 INFO L160 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [271783690] provided 1 perfect and 0 imperfect interpolant sequences [2021-12-17 15:08:30,401 INFO L186 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2021-12-17 15:08:30,401 INFO L199 FreeRefinementEngine]: Number of different interpolants: perfect sequences [6] imperfect sequences [] total 6 [2021-12-17 15:08:30,401 INFO L115 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [2051819140] [2021-12-17 15:08:30,402 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2021-12-17 15:08:30,403 INFO L546 AbstractCegarLoop]: INTERPOLANT automaton has 6 states [2021-12-17 15:08:30,403 INFO L103 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2021-12-17 15:08:30,404 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 6 interpolants. [2021-12-17 15:08:30,404 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=9, Invalid=21, Unknown=0, NotChecked=0, Total=30 [2021-12-17 15:08:30,404 INFO L87 Difference]: Start difference. First operand 162 states and 206 transitions. Second operand has 6 states, 6 states have (on average 7.166666666666667) internal successors, (43), 5 states have internal predecessors, (43), 2 states have call successors, (4), 2 states have call predecessors, (4), 2 states have return successors, (3), 1 states have call predecessors, (3), 2 states have call successors, (3) [2021-12-17 15:08:30,556 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2021-12-17 15:08:30,556 INFO L93 Difference]: Finished difference Result 325 states and 421 transitions. [2021-12-17 15:08:30,556 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 7 states. [2021-12-17 15:08:30,557 INFO L78 Accepts]: Start accepts. Automaton has has 6 states, 6 states have (on average 7.166666666666667) internal successors, (43), 5 states have internal predecessors, (43), 2 states have call successors, (4), 2 states have call predecessors, (4), 2 states have return successors, (3), 1 states have call predecessors, (3), 2 states have call successors, (3) Word has length 50 [2021-12-17 15:08:30,557 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2021-12-17 15:08:30,558 INFO L225 Difference]: With dead ends: 325 [2021-12-17 15:08:30,558 INFO L226 Difference]: Without dead ends: 170 [2021-12-17 15:08:30,559 INFO L932 BasicCegarLoop]: 0 DeclaredPredicates, 17 GetRequests, 9 SyntacticMatches, 0 SemanticMatches, 8 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 3 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=32, Invalid=58, Unknown=0, NotChecked=0, Total=90 [2021-12-17 15:08:30,560 INFO L933 BasicCegarLoop]: 111 mSDtfsCounter, 71 mSDsluCounter, 340 mSDsCounter, 0 mSdLazyCounter, 128 mSolverCounterSat, 23 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.1s Time, 0 mProtectedPredicate, 0 mProtectedAction, 74 SdHoareTripleChecker+Valid, 451 SdHoareTripleChecker+Invalid, 151 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 23 IncrementalHoareTripleChecker+Valid, 128 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.1s IncrementalHoareTripleChecker+Time [2021-12-17 15:08:30,560 INFO L934 BasicCegarLoop]: SdHoareTripleChecker [74 Valid, 451 Invalid, 151 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [23 Valid, 128 Invalid, 0 Unknown, 0 Unchecked, 0.1s Time] [2021-12-17 15:08:30,561 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 170 states. [2021-12-17 15:08:30,572 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 170 to 165. [2021-12-17 15:08:30,573 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 165 states, 125 states have (on average 1.28) internal successors, (160), 133 states have internal predecessors, (160), 19 states have call successors, (19), 15 states have call predecessors, (19), 20 states have return successors, (30), 21 states have call predecessors, (30), 19 states have call successors, (30) [2021-12-17 15:08:30,574 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 165 states to 165 states and 209 transitions. [2021-12-17 15:08:30,574 INFO L78 Accepts]: Start accepts. Automaton has 165 states and 209 transitions. Word has length 50 [2021-12-17 15:08:30,574 INFO L84 Accepts]: Finished accepts. word is rejected. [2021-12-17 15:08:30,574 INFO L470 AbstractCegarLoop]: Abstraction has 165 states and 209 transitions. [2021-12-17 15:08:30,574 INFO L471 AbstractCegarLoop]: INTERPOLANT automaton has has 6 states, 6 states have (on average 7.166666666666667) internal successors, (43), 5 states have internal predecessors, (43), 2 states have call successors, (4), 2 states have call predecessors, (4), 2 states have return successors, (3), 1 states have call predecessors, (3), 2 states have call successors, (3) [2021-12-17 15:08:30,575 INFO L276 IsEmpty]: Start isEmpty. Operand 165 states and 209 transitions. [2021-12-17 15:08:30,575 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 51 [2021-12-17 15:08:30,575 INFO L506 BasicCegarLoop]: Found error trace [2021-12-17 15:08:30,576 INFO L514 BasicCegarLoop]: trace histogram [1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2021-12-17 15:08:30,576 WARN L452 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable4 [2021-12-17 15:08:30,576 INFO L402 AbstractCegarLoop]: === Iteration 6 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2021-12-17 15:08:30,576 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2021-12-17 15:08:30,576 INFO L85 PathProgramCache]: Analyzing trace with hash 2077494517, now seen corresponding path program 1 times [2021-12-17 15:08:30,576 INFO L121 FreeRefinementEngine]: Executing refinement strategy CAMEL [2021-12-17 15:08:30,577 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [692116689] [2021-12-17 15:08:30,577 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2021-12-17 15:08:30,577 INFO L126 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2021-12-17 15:08:30,588 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:08:30,603 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 20 [2021-12-17 15:08:30,606 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:08:30,611 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 2 [2021-12-17 15:08:30,614 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:08:30,627 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 39 [2021-12-17 15:08:30,628 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:08:30,629 INFO L134 CoverageAnalysis]: Checked inductivity of 0 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2021-12-17 15:08:30,630 INFO L139 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2021-12-17 15:08:30,630 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [692116689] [2021-12-17 15:08:30,630 INFO L160 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [692116689] provided 1 perfect and 0 imperfect interpolant sequences [2021-12-17 15:08:30,630 INFO L186 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2021-12-17 15:08:30,630 INFO L199 FreeRefinementEngine]: Number of different interpolants: perfect sequences [5] imperfect sequences [] total 5 [2021-12-17 15:08:30,630 INFO L115 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [551036464] [2021-12-17 15:08:30,630 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2021-12-17 15:08:30,631 INFO L546 AbstractCegarLoop]: INTERPOLANT automaton has 5 states [2021-12-17 15:08:30,631 INFO L103 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2021-12-17 15:08:30,631 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 5 interpolants. [2021-12-17 15:08:30,631 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=7, Invalid=13, Unknown=0, NotChecked=0, Total=20 [2021-12-17 15:08:30,632 INFO L87 Difference]: Start difference. First operand 165 states and 209 transitions. Second operand has 5 states, 5 states have (on average 8.6) internal successors, (43), 4 states have internal predecessors, (43), 2 states have call successors, (4), 2 states have call predecessors, (4), 2 states have return successors, (3), 1 states have call predecessors, (3), 2 states have call successors, (3) [2021-12-17 15:08:30,744 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2021-12-17 15:08:30,744 INFO L93 Difference]: Finished difference Result 333 states and 435 transitions. [2021-12-17 15:08:30,744 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 5 states. [2021-12-17 15:08:30,745 INFO L78 Accepts]: Start accepts. Automaton has has 5 states, 5 states have (on average 8.6) internal successors, (43), 4 states have internal predecessors, (43), 2 states have call successors, (4), 2 states have call predecessors, (4), 2 states have return successors, (3), 1 states have call predecessors, (3), 2 states have call successors, (3) Word has length 50 [2021-12-17 15:08:30,745 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2021-12-17 15:08:30,747 INFO L225 Difference]: With dead ends: 333 [2021-12-17 15:08:30,748 INFO L226 Difference]: Without dead ends: 175 [2021-12-17 15:08:30,749 INFO L932 BasicCegarLoop]: 0 DeclaredPredicates, 14 GetRequests, 9 SyntacticMatches, 0 SemanticMatches, 5 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 0 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=17, Invalid=25, Unknown=0, NotChecked=0, Total=42 [2021-12-17 15:08:30,750 INFO L933 BasicCegarLoop]: 112 mSDtfsCounter, 74 mSDsluCounter, 240 mSDsCounter, 0 mSdLazyCounter, 97 mSolverCounterSat, 19 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.1s Time, 0 mProtectedPredicate, 0 mProtectedAction, 78 SdHoareTripleChecker+Valid, 352 SdHoareTripleChecker+Invalid, 116 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 19 IncrementalHoareTripleChecker+Valid, 97 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.1s IncrementalHoareTripleChecker+Time [2021-12-17 15:08:30,750 INFO L934 BasicCegarLoop]: SdHoareTripleChecker [78 Valid, 352 Invalid, 116 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [19 Valid, 97 Invalid, 0 Unknown, 0 Unchecked, 0.1s Time] [2021-12-17 15:08:30,751 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 175 states. [2021-12-17 15:08:30,775 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 175 to 167. [2021-12-17 15:08:30,776 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 167 states, 127 states have (on average 1.2755905511811023) internal successors, (162), 135 states have internal predecessors, (162), 19 states have call successors, (19), 15 states have call predecessors, (19), 20 states have return successors, (30), 21 states have call predecessors, (30), 19 states have call successors, (30) [2021-12-17 15:08:30,777 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 167 states to 167 states and 211 transitions. [2021-12-17 15:08:30,777 INFO L78 Accepts]: Start accepts. Automaton has 167 states and 211 transitions. Word has length 50 [2021-12-17 15:08:30,777 INFO L84 Accepts]: Finished accepts. word is rejected. [2021-12-17 15:08:30,778 INFO L470 AbstractCegarLoop]: Abstraction has 167 states and 211 transitions. [2021-12-17 15:08:30,778 INFO L471 AbstractCegarLoop]: INTERPOLANT automaton has has 5 states, 5 states have (on average 8.6) internal successors, (43), 4 states have internal predecessors, (43), 2 states have call successors, (4), 2 states have call predecessors, (4), 2 states have return successors, (3), 1 states have call predecessors, (3), 2 states have call successors, (3) [2021-12-17 15:08:30,778 INFO L276 IsEmpty]: Start isEmpty. Operand 167 states and 211 transitions. [2021-12-17 15:08:30,779 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 51 [2021-12-17 15:08:30,779 INFO L506 BasicCegarLoop]: Found error trace [2021-12-17 15:08:30,779 INFO L514 BasicCegarLoop]: trace histogram [1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2021-12-17 15:08:30,779 WARN L452 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable5 [2021-12-17 15:08:30,779 INFO L402 AbstractCegarLoop]: === Iteration 7 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2021-12-17 15:08:30,780 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2021-12-17 15:08:30,780 INFO L85 PathProgramCache]: Analyzing trace with hash 1943481011, now seen corresponding path program 1 times [2021-12-17 15:08:30,780 INFO L121 FreeRefinementEngine]: Executing refinement strategy CAMEL [2021-12-17 15:08:30,780 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [1144679043] [2021-12-17 15:08:30,780 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2021-12-17 15:08:30,780 INFO L126 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2021-12-17 15:08:30,806 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:08:30,837 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 20 [2021-12-17 15:08:30,841 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:08:30,849 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 2 [2021-12-17 15:08:30,855 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:08:30,865 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 39 [2021-12-17 15:08:30,866 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:08:30,868 INFO L134 CoverageAnalysis]: Checked inductivity of 0 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2021-12-17 15:08:30,868 INFO L139 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2021-12-17 15:08:30,868 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [1144679043] [2021-12-17 15:08:30,868 INFO L160 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [1144679043] provided 1 perfect and 0 imperfect interpolant sequences [2021-12-17 15:08:30,868 INFO L186 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2021-12-17 15:08:30,868 INFO L199 FreeRefinementEngine]: Number of different interpolants: perfect sequences [5] imperfect sequences [] total 5 [2021-12-17 15:08:30,869 INFO L115 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [645466374] [2021-12-17 15:08:30,869 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2021-12-17 15:08:30,869 INFO L546 AbstractCegarLoop]: INTERPOLANT automaton has 5 states [2021-12-17 15:08:30,869 INFO L103 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2021-12-17 15:08:30,870 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 5 interpolants. [2021-12-17 15:08:30,870 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=7, Invalid=13, Unknown=0, NotChecked=0, Total=20 [2021-12-17 15:08:30,870 INFO L87 Difference]: Start difference. First operand 167 states and 211 transitions. Second operand has 5 states, 5 states have (on average 8.6) internal successors, (43), 4 states have internal predecessors, (43), 3 states have call successors, (4), 3 states have call predecessors, (4), 2 states have return successors, (3), 2 states have call predecessors, (3), 3 states have call successors, (3) [2021-12-17 15:08:31,083 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2021-12-17 15:08:31,083 INFO L93 Difference]: Finished difference Result 467 states and 611 transitions. [2021-12-17 15:08:31,083 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 7 states. [2021-12-17 15:08:31,084 INFO L78 Accepts]: Start accepts. Automaton has has 5 states, 5 states have (on average 8.6) internal successors, (43), 4 states have internal predecessors, (43), 3 states have call successors, (4), 3 states have call predecessors, (4), 2 states have return successors, (3), 2 states have call predecessors, (3), 3 states have call successors, (3) Word has length 50 [2021-12-17 15:08:31,084 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2021-12-17 15:08:31,086 INFO L225 Difference]: With dead ends: 467 [2021-12-17 15:08:31,086 INFO L226 Difference]: Without dead ends: 307 [2021-12-17 15:08:31,087 INFO L932 BasicCegarLoop]: 0 DeclaredPredicates, 16 GetRequests, 10 SyntacticMatches, 1 SemanticMatches, 5 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 1 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=15, Invalid=27, Unknown=0, NotChecked=0, Total=42 [2021-12-17 15:08:31,087 INFO L933 BasicCegarLoop]: 162 mSDtfsCounter, 226 mSDsluCounter, 201 mSDsCounter, 0 mSdLazyCounter, 172 mSolverCounterSat, 65 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.1s Time, 0 mProtectedPredicate, 0 mProtectedAction, 233 SdHoareTripleChecker+Valid, 363 SdHoareTripleChecker+Invalid, 237 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 65 IncrementalHoareTripleChecker+Valid, 172 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.2s IncrementalHoareTripleChecker+Time [2021-12-17 15:08:31,088 INFO L934 BasicCegarLoop]: SdHoareTripleChecker [233 Valid, 363 Invalid, 237 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [65 Valid, 172 Invalid, 0 Unknown, 0 Unchecked, 0.2s Time] [2021-12-17 15:08:31,091 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 307 states. [2021-12-17 15:08:31,121 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 307 to 299. [2021-12-17 15:08:31,121 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 299 states, 226 states have (on average 1.252212389380531) internal successors, (283), 238 states have internal predecessors, (283), 36 states have call successors, (36), 33 states have call predecessors, (36), 36 states have return successors, (62), 37 states have call predecessors, (62), 36 states have call successors, (62) [2021-12-17 15:08:31,123 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 299 states to 299 states and 381 transitions. [2021-12-17 15:08:31,123 INFO L78 Accepts]: Start accepts. Automaton has 299 states and 381 transitions. Word has length 50 [2021-12-17 15:08:31,124 INFO L84 Accepts]: Finished accepts. word is rejected. [2021-12-17 15:08:31,124 INFO L470 AbstractCegarLoop]: Abstraction has 299 states and 381 transitions. [2021-12-17 15:08:31,124 INFO L471 AbstractCegarLoop]: INTERPOLANT automaton has has 5 states, 5 states have (on average 8.6) internal successors, (43), 4 states have internal predecessors, (43), 3 states have call successors, (4), 3 states have call predecessors, (4), 2 states have return successors, (3), 2 states have call predecessors, (3), 3 states have call successors, (3) [2021-12-17 15:08:31,124 INFO L276 IsEmpty]: Start isEmpty. Operand 299 states and 381 transitions. [2021-12-17 15:08:31,125 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 53 [2021-12-17 15:08:31,125 INFO L506 BasicCegarLoop]: Found error trace [2021-12-17 15:08:31,125 INFO L514 BasicCegarLoop]: trace histogram [1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2021-12-17 15:08:31,125 WARN L452 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable6 [2021-12-17 15:08:31,125 INFO L402 AbstractCegarLoop]: === Iteration 8 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2021-12-17 15:08:31,126 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2021-12-17 15:08:31,126 INFO L85 PathProgramCache]: Analyzing trace with hash -432802525, now seen corresponding path program 1 times [2021-12-17 15:08:31,126 INFO L121 FreeRefinementEngine]: Executing refinement strategy CAMEL [2021-12-17 15:08:31,126 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [1700783739] [2021-12-17 15:08:31,126 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2021-12-17 15:08:31,126 INFO L126 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2021-12-17 15:08:31,135 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:08:31,164 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 20 [2021-12-17 15:08:31,167 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:08:31,170 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 2 [2021-12-17 15:08:31,171 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:08:31,173 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 8 [2021-12-17 15:08:31,174 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:08:31,175 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 41 [2021-12-17 15:08:31,176 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:08:31,178 INFO L134 CoverageAnalysis]: Checked inductivity of 0 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2021-12-17 15:08:31,178 INFO L139 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2021-12-17 15:08:31,178 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [1700783739] [2021-12-17 15:08:31,178 INFO L160 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [1700783739] provided 1 perfect and 0 imperfect interpolant sequences [2021-12-17 15:08:31,178 INFO L186 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2021-12-17 15:08:31,179 INFO L199 FreeRefinementEngine]: Number of different interpolants: perfect sequences [6] imperfect sequences [] total 6 [2021-12-17 15:08:31,179 INFO L115 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [526191847] [2021-12-17 15:08:31,179 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2021-12-17 15:08:31,179 INFO L546 AbstractCegarLoop]: INTERPOLANT automaton has 6 states [2021-12-17 15:08:31,179 INFO L103 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2021-12-17 15:08:31,180 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 6 interpolants. [2021-12-17 15:08:31,180 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=9, Invalid=21, Unknown=0, NotChecked=0, Total=30 [2021-12-17 15:08:31,180 INFO L87 Difference]: Start difference. First operand 299 states and 381 transitions. Second operand has 6 states, 6 states have (on average 7.166666666666667) internal successors, (43), 5 states have internal predecessors, (43), 2 states have call successors, (5), 3 states have call predecessors, (5), 1 states have return successors, (4), 2 states have call predecessors, (4), 2 states have call successors, (4) [2021-12-17 15:08:31,328 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2021-12-17 15:08:31,328 INFO L93 Difference]: Finished difference Result 594 states and 757 transitions. [2021-12-17 15:08:31,329 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 7 states. [2021-12-17 15:08:31,329 INFO L78 Accepts]: Start accepts. Automaton has has 6 states, 6 states have (on average 7.166666666666667) internal successors, (43), 5 states have internal predecessors, (43), 2 states have call successors, (5), 3 states have call predecessors, (5), 1 states have return successors, (4), 2 states have call predecessors, (4), 2 states have call successors, (4) Word has length 52 [2021-12-17 15:08:31,329 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2021-12-17 15:08:31,331 INFO L225 Difference]: With dead ends: 594 [2021-12-17 15:08:31,331 INFO L226 Difference]: Without dead ends: 302 [2021-12-17 15:08:31,332 INFO L932 BasicCegarLoop]: 0 DeclaredPredicates, 17 GetRequests, 10 SyntacticMatches, 0 SemanticMatches, 7 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 0 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=27, Invalid=45, Unknown=0, NotChecked=0, Total=72 [2021-12-17 15:08:31,332 INFO L933 BasicCegarLoop]: 102 mSDtfsCounter, 126 mSDsluCounter, 314 mSDsCounter, 0 mSdLazyCounter, 149 mSolverCounterSat, 33 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.1s Time, 0 mProtectedPredicate, 0 mProtectedAction, 131 SdHoareTripleChecker+Valid, 416 SdHoareTripleChecker+Invalid, 182 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 33 IncrementalHoareTripleChecker+Valid, 149 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.1s IncrementalHoareTripleChecker+Time [2021-12-17 15:08:31,333 INFO L934 BasicCegarLoop]: SdHoareTripleChecker [131 Valid, 416 Invalid, 182 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [33 Valid, 149 Invalid, 0 Unknown, 0 Unchecked, 0.1s Time] [2021-12-17 15:08:31,333 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 302 states. [2021-12-17 15:08:31,346 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 302 to 297. [2021-12-17 15:08:31,347 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 297 states, 224 states have (on average 1.2455357142857142) internal successors, (279), 236 states have internal predecessors, (279), 36 states have call successors, (36), 33 states have call predecessors, (36), 36 states have return successors, (62), 37 states have call predecessors, (62), 36 states have call successors, (62) [2021-12-17 15:08:31,350 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 297 states to 297 states and 377 transitions. [2021-12-17 15:08:31,350 INFO L78 Accepts]: Start accepts. Automaton has 297 states and 377 transitions. Word has length 52 [2021-12-17 15:08:31,351 INFO L84 Accepts]: Finished accepts. word is rejected. [2021-12-17 15:08:31,351 INFO L470 AbstractCegarLoop]: Abstraction has 297 states and 377 transitions. [2021-12-17 15:08:31,351 INFO L471 AbstractCegarLoop]: INTERPOLANT automaton has has 6 states, 6 states have (on average 7.166666666666667) internal successors, (43), 5 states have internal predecessors, (43), 2 states have call successors, (5), 3 states have call predecessors, (5), 1 states have return successors, (4), 2 states have call predecessors, (4), 2 states have call successors, (4) [2021-12-17 15:08:31,352 INFO L276 IsEmpty]: Start isEmpty. Operand 297 states and 377 transitions. [2021-12-17 15:08:31,352 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 55 [2021-12-17 15:08:31,352 INFO L506 BasicCegarLoop]: Found error trace [2021-12-17 15:08:31,352 INFO L514 BasicCegarLoop]: trace histogram [1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2021-12-17 15:08:31,353 WARN L452 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable7 [2021-12-17 15:08:31,353 INFO L402 AbstractCegarLoop]: === Iteration 9 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2021-12-17 15:08:31,353 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2021-12-17 15:08:31,353 INFO L85 PathProgramCache]: Analyzing trace with hash -1117904615, now seen corresponding path program 1 times [2021-12-17 15:08:31,353 INFO L121 FreeRefinementEngine]: Executing refinement strategy CAMEL [2021-12-17 15:08:31,353 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [1434139832] [2021-12-17 15:08:31,354 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2021-12-17 15:08:31,354 INFO L126 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2021-12-17 15:08:31,376 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:08:31,412 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 11 [2021-12-17 15:08:31,413 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:08:31,419 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 24 [2021-12-17 15:08:31,422 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:08:31,430 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 2 [2021-12-17 15:08:31,431 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:08:31,437 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 43 [2021-12-17 15:08:31,438 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:08:31,440 INFO L134 CoverageAnalysis]: Checked inductivity of 0 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2021-12-17 15:08:31,440 INFO L139 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2021-12-17 15:08:31,440 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [1434139832] [2021-12-17 15:08:31,440 INFO L160 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [1434139832] provided 1 perfect and 0 imperfect interpolant sequences [2021-12-17 15:08:31,441 INFO L186 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2021-12-17 15:08:31,441 INFO L199 FreeRefinementEngine]: Number of different interpolants: perfect sequences [7] imperfect sequences [] total 7 [2021-12-17 15:08:31,441 INFO L115 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [446899739] [2021-12-17 15:08:31,441 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2021-12-17 15:08:31,442 INFO L546 AbstractCegarLoop]: INTERPOLANT automaton has 7 states [2021-12-17 15:08:31,442 INFO L103 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2021-12-17 15:08:31,442 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 7 interpolants. [2021-12-17 15:08:31,442 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=11, Invalid=31, Unknown=0, NotChecked=0, Total=42 [2021-12-17 15:08:31,443 INFO L87 Difference]: Start difference. First operand 297 states and 377 transitions. Second operand has 7 states, 7 states have (on average 6.428571428571429) internal successors, (45), 5 states have internal predecessors, (45), 2 states have call successors, (5), 3 states have call predecessors, (5), 2 states have return successors, (4), 2 states have call predecessors, (4), 2 states have call successors, (4) [2021-12-17 15:08:31,794 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2021-12-17 15:08:31,794 INFO L93 Difference]: Finished difference Result 583 states and 752 transitions. [2021-12-17 15:08:31,795 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 15 states. [2021-12-17 15:08:31,795 INFO L78 Accepts]: Start accepts. Automaton has has 7 states, 7 states have (on average 6.428571428571429) internal successors, (45), 5 states have internal predecessors, (45), 2 states have call successors, (5), 3 states have call predecessors, (5), 2 states have return successors, (4), 2 states have call predecessors, (4), 2 states have call successors, (4) Word has length 54 [2021-12-17 15:08:31,795 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2021-12-17 15:08:31,797 INFO L225 Difference]: With dead ends: 583 [2021-12-17 15:08:31,797 INFO L226 Difference]: Without dead ends: 345 [2021-12-17 15:08:31,798 INFO L932 BasicCegarLoop]: 0 DeclaredPredicates, 28 GetRequests, 13 SyntacticMatches, 0 SemanticMatches, 15 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 24 ImplicationChecksByTransitivity, 0.1s TimeCoverageRelationStatistics Valid=87, Invalid=185, Unknown=0, NotChecked=0, Total=272 [2021-12-17 15:08:31,799 INFO L933 BasicCegarLoop]: 164 mSDtfsCounter, 235 mSDsluCounter, 381 mSDsCounter, 0 mSdLazyCounter, 347 mSolverCounterSat, 77 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.2s Time, 0 mProtectedPredicate, 0 mProtectedAction, 239 SdHoareTripleChecker+Valid, 545 SdHoareTripleChecker+Invalid, 424 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 77 IncrementalHoareTripleChecker+Valid, 347 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.2s IncrementalHoareTripleChecker+Time [2021-12-17 15:08:31,799 INFO L934 BasicCegarLoop]: SdHoareTripleChecker [239 Valid, 545 Invalid, 424 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [77 Valid, 347 Invalid, 0 Unknown, 0 Unchecked, 0.2s Time] [2021-12-17 15:08:31,800 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 345 states. [2021-12-17 15:08:31,812 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 345 to 332. [2021-12-17 15:08:31,813 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 332 states, 251 states have (on average 1.2151394422310757) internal successors, (305), 266 states have internal predecessors, (305), 41 states have call successors, (41), 33 states have call predecessors, (41), 39 states have return successors, (58), 42 states have call predecessors, (58), 41 states have call successors, (58) [2021-12-17 15:08:31,814 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 332 states to 332 states and 404 transitions. [2021-12-17 15:08:31,815 INFO L78 Accepts]: Start accepts. Automaton has 332 states and 404 transitions. Word has length 54 [2021-12-17 15:08:31,815 INFO L84 Accepts]: Finished accepts. word is rejected. [2021-12-17 15:08:31,815 INFO L470 AbstractCegarLoop]: Abstraction has 332 states and 404 transitions. [2021-12-17 15:08:31,815 INFO L471 AbstractCegarLoop]: INTERPOLANT automaton has has 7 states, 7 states have (on average 6.428571428571429) internal successors, (45), 5 states have internal predecessors, (45), 2 states have call successors, (5), 3 states have call predecessors, (5), 2 states have return successors, (4), 2 states have call predecessors, (4), 2 states have call successors, (4) [2021-12-17 15:08:31,815 INFO L276 IsEmpty]: Start isEmpty. Operand 332 states and 404 transitions. [2021-12-17 15:08:31,816 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 57 [2021-12-17 15:08:31,816 INFO L506 BasicCegarLoop]: Found error trace [2021-12-17 15:08:31,816 INFO L514 BasicCegarLoop]: trace histogram [1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2021-12-17 15:08:31,817 WARN L452 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable8 [2021-12-17 15:08:31,817 INFO L402 AbstractCegarLoop]: === Iteration 10 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2021-12-17 15:08:31,817 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2021-12-17 15:08:31,817 INFO L85 PathProgramCache]: Analyzing trace with hash -309751737, now seen corresponding path program 1 times [2021-12-17 15:08:31,817 INFO L121 FreeRefinementEngine]: Executing refinement strategy CAMEL [2021-12-17 15:08:31,818 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [684875854] [2021-12-17 15:08:31,818 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2021-12-17 15:08:31,818 INFO L126 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2021-12-17 15:08:31,826 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:08:31,841 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 11 [2021-12-17 15:08:31,842 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:08:31,846 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 24 [2021-12-17 15:08:31,848 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:08:31,853 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 2 [2021-12-17 15:08:31,854 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:08:31,875 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 8 [2021-12-17 15:08:31,876 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:08:31,878 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 45 [2021-12-17 15:08:31,878 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:08:31,883 INFO L134 CoverageAnalysis]: Checked inductivity of 0 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2021-12-17 15:08:31,883 INFO L139 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2021-12-17 15:08:31,883 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [684875854] [2021-12-17 15:08:31,883 INFO L160 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [684875854] provided 1 perfect and 0 imperfect interpolant sequences [2021-12-17 15:08:31,883 INFO L186 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2021-12-17 15:08:31,883 INFO L199 FreeRefinementEngine]: Number of different interpolants: perfect sequences [6] imperfect sequences [] total 6 [2021-12-17 15:08:31,884 INFO L115 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [1998226877] [2021-12-17 15:08:31,884 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2021-12-17 15:08:31,884 INFO L546 AbstractCegarLoop]: INTERPOLANT automaton has 6 states [2021-12-17 15:08:31,884 INFO L103 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2021-12-17 15:08:31,885 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 6 interpolants. [2021-12-17 15:08:31,885 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=9, Invalid=21, Unknown=0, NotChecked=0, Total=30 [2021-12-17 15:08:31,885 INFO L87 Difference]: Start difference. First operand 332 states and 404 transitions. Second operand has 6 states, 6 states have (on average 7.5) internal successors, (45), 4 states have internal predecessors, (45), 2 states have call successors, (6), 3 states have call predecessors, (6), 2 states have return successors, (5), 2 states have call predecessors, (5), 2 states have call successors, (5) [2021-12-17 15:08:32,085 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2021-12-17 15:08:32,085 INFO L93 Difference]: Finished difference Result 604 states and 746 transitions. [2021-12-17 15:08:32,086 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 8 states. [2021-12-17 15:08:32,086 INFO L78 Accepts]: Start accepts. Automaton has has 6 states, 6 states have (on average 7.5) internal successors, (45), 4 states have internal predecessors, (45), 2 states have call successors, (6), 3 states have call predecessors, (6), 2 states have return successors, (5), 2 states have call predecessors, (5), 2 states have call successors, (5) Word has length 56 [2021-12-17 15:08:32,086 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2021-12-17 15:08:32,088 INFO L225 Difference]: With dead ends: 604 [2021-12-17 15:08:32,088 INFO L226 Difference]: Without dead ends: 333 [2021-12-17 15:08:32,089 INFO L932 BasicCegarLoop]: 0 DeclaredPredicates, 21 GetRequests, 13 SyntacticMatches, 0 SemanticMatches, 8 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 3 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=33, Invalid=57, Unknown=0, NotChecked=0, Total=90 [2021-12-17 15:08:32,090 INFO L933 BasicCegarLoop]: 103 mSDtfsCounter, 157 mSDsluCounter, 224 mSDsCounter, 0 mSdLazyCounter, 194 mSolverCounterSat, 54 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.1s Time, 0 mProtectedPredicate, 0 mProtectedAction, 160 SdHoareTripleChecker+Valid, 327 SdHoareTripleChecker+Invalid, 248 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 54 IncrementalHoareTripleChecker+Valid, 194 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.1s IncrementalHoareTripleChecker+Time [2021-12-17 15:08:32,090 INFO L934 BasicCegarLoop]: SdHoareTripleChecker [160 Valid, 327 Invalid, 248 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [54 Valid, 194 Invalid, 0 Unknown, 0 Unchecked, 0.1s Time] [2021-12-17 15:08:32,091 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 333 states. [2021-12-17 15:08:32,103 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 333 to 329. [2021-12-17 15:08:32,104 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 329 states, 248 states have (on average 1.2137096774193548) internal successors, (301), 263 states have internal predecessors, (301), 41 states have call successors, (41), 33 states have call predecessors, (41), 39 states have return successors, (58), 42 states have call predecessors, (58), 41 states have call successors, (58) [2021-12-17 15:08:32,106 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 329 states to 329 states and 400 transitions. [2021-12-17 15:08:32,106 INFO L78 Accepts]: Start accepts. Automaton has 329 states and 400 transitions. Word has length 56 [2021-12-17 15:08:32,106 INFO L84 Accepts]: Finished accepts. word is rejected. [2021-12-17 15:08:32,106 INFO L470 AbstractCegarLoop]: Abstraction has 329 states and 400 transitions. [2021-12-17 15:08:32,107 INFO L471 AbstractCegarLoop]: INTERPOLANT automaton has has 6 states, 6 states have (on average 7.5) internal successors, (45), 4 states have internal predecessors, (45), 2 states have call successors, (6), 3 states have call predecessors, (6), 2 states have return successors, (5), 2 states have call predecessors, (5), 2 states have call successors, (5) [2021-12-17 15:08:32,107 INFO L276 IsEmpty]: Start isEmpty. Operand 329 states and 400 transitions. [2021-12-17 15:08:32,107 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 57 [2021-12-17 15:08:32,108 INFO L506 BasicCegarLoop]: Found error trace [2021-12-17 15:08:32,108 INFO L514 BasicCegarLoop]: trace histogram [1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2021-12-17 15:08:32,108 WARN L452 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable9 [2021-12-17 15:08:32,108 INFO L402 AbstractCegarLoop]: === Iteration 11 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2021-12-17 15:08:32,108 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2021-12-17 15:08:32,109 INFO L85 PathProgramCache]: Analyzing trace with hash -443765243, now seen corresponding path program 1 times [2021-12-17 15:08:32,109 INFO L121 FreeRefinementEngine]: Executing refinement strategy CAMEL [2021-12-17 15:08:32,109 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [202882634] [2021-12-17 15:08:32,109 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2021-12-17 15:08:32,109 INFO L126 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2021-12-17 15:08:32,118 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:08:32,130 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 11 [2021-12-17 15:08:32,131 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:08:32,135 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 24 [2021-12-17 15:08:32,137 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:08:32,142 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 2 [2021-12-17 15:08:32,148 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:08:32,180 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 8 [2021-12-17 15:08:32,181 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:08:32,183 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 45 [2021-12-17 15:08:32,184 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:08:32,186 INFO L134 CoverageAnalysis]: Checked inductivity of 0 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2021-12-17 15:08:32,186 INFO L139 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2021-12-17 15:08:32,186 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [202882634] [2021-12-17 15:08:32,186 INFO L160 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [202882634] provided 1 perfect and 0 imperfect interpolant sequences [2021-12-17 15:08:32,186 INFO L186 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2021-12-17 15:08:32,186 INFO L199 FreeRefinementEngine]: Number of different interpolants: perfect sequences [7] imperfect sequences [] total 7 [2021-12-17 15:08:32,187 INFO L115 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [319560315] [2021-12-17 15:08:32,187 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2021-12-17 15:08:32,187 INFO L546 AbstractCegarLoop]: INTERPOLANT automaton has 7 states [2021-12-17 15:08:32,187 INFO L103 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2021-12-17 15:08:32,188 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 7 interpolants. [2021-12-17 15:08:32,188 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=11, Invalid=31, Unknown=0, NotChecked=0, Total=42 [2021-12-17 15:08:32,188 INFO L87 Difference]: Start difference. First operand 329 states and 400 transitions. Second operand has 7 states, 7 states have (on average 6.428571428571429) internal successors, (45), 5 states have internal predecessors, (45), 2 states have call successors, (6), 3 states have call predecessors, (6), 2 states have return successors, (5), 2 states have call predecessors, (5), 2 states have call successors, (5) [2021-12-17 15:08:32,430 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2021-12-17 15:08:32,430 INFO L93 Difference]: Finished difference Result 573 states and 705 transitions. [2021-12-17 15:08:32,431 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 9 states. [2021-12-17 15:08:32,431 INFO L78 Accepts]: Start accepts. Automaton has has 7 states, 7 states have (on average 6.428571428571429) internal successors, (45), 5 states have internal predecessors, (45), 2 states have call successors, (6), 3 states have call predecessors, (6), 2 states have return successors, (5), 2 states have call predecessors, (5), 2 states have call successors, (5) Word has length 56 [2021-12-17 15:08:32,431 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2021-12-17 15:08:32,433 INFO L225 Difference]: With dead ends: 573 [2021-12-17 15:08:32,433 INFO L226 Difference]: Without dead ends: 305 [2021-12-17 15:08:32,434 INFO L932 BasicCegarLoop]: 0 DeclaredPredicates, 23 GetRequests, 13 SyntacticMatches, 0 SemanticMatches, 10 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 4 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=46, Invalid=86, Unknown=0, NotChecked=0, Total=132 [2021-12-17 15:08:32,434 INFO L933 BasicCegarLoop]: 102 mSDtfsCounter, 147 mSDsluCounter, 303 mSDsCounter, 0 mSdLazyCounter, 258 mSolverCounterSat, 54 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.1s Time, 0 mProtectedPredicate, 0 mProtectedAction, 150 SdHoareTripleChecker+Valid, 405 SdHoareTripleChecker+Invalid, 312 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 54 IncrementalHoareTripleChecker+Valid, 258 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.2s IncrementalHoareTripleChecker+Time [2021-12-17 15:08:32,435 INFO L934 BasicCegarLoop]: SdHoareTripleChecker [150 Valid, 405 Invalid, 312 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [54 Valid, 258 Invalid, 0 Unknown, 0 Unchecked, 0.2s Time] [2021-12-17 15:08:32,435 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 305 states. [2021-12-17 15:08:32,447 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 305 to 301. [2021-12-17 15:08:32,447 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 301 states, 228 states have (on average 1.2105263157894737) internal successors, (276), 242 states have internal predecessors, (276), 38 states have call successors, (38), 30 states have call predecessors, (38), 34 states have return successors, (49), 37 states have call predecessors, (49), 38 states have call successors, (49) [2021-12-17 15:08:32,448 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 301 states to 301 states and 363 transitions. [2021-12-17 15:08:32,449 INFO L78 Accepts]: Start accepts. Automaton has 301 states and 363 transitions. Word has length 56 [2021-12-17 15:08:32,449 INFO L84 Accepts]: Finished accepts. word is rejected. [2021-12-17 15:08:32,449 INFO L470 AbstractCegarLoop]: Abstraction has 301 states and 363 transitions. [2021-12-17 15:08:32,449 INFO L471 AbstractCegarLoop]: INTERPOLANT automaton has has 7 states, 7 states have (on average 6.428571428571429) internal successors, (45), 5 states have internal predecessors, (45), 2 states have call successors, (6), 3 states have call predecessors, (6), 2 states have return successors, (5), 2 states have call predecessors, (5), 2 states have call successors, (5) [2021-12-17 15:08:32,449 INFO L276 IsEmpty]: Start isEmpty. Operand 301 states and 363 transitions. [2021-12-17 15:08:32,450 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 92 [2021-12-17 15:08:32,450 INFO L506 BasicCegarLoop]: Found error trace [2021-12-17 15:08:32,450 INFO L514 BasicCegarLoop]: trace histogram [3, 3, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2021-12-17 15:08:32,450 WARN L452 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable10 [2021-12-17 15:08:32,451 INFO L402 AbstractCegarLoop]: === Iteration 12 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2021-12-17 15:08:32,451 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2021-12-17 15:08:32,451 INFO L85 PathProgramCache]: Analyzing trace with hash 872263225, now seen corresponding path program 1 times [2021-12-17 15:08:32,451 INFO L121 FreeRefinementEngine]: Executing refinement strategy CAMEL [2021-12-17 15:08:32,451 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [636528028] [2021-12-17 15:08:32,451 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2021-12-17 15:08:32,451 INFO L126 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2021-12-17 15:08:32,462 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:08:32,482 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 11 [2021-12-17 15:08:32,483 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:08:32,489 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 20 [2021-12-17 15:08:32,492 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:08:32,517 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 3 [2021-12-17 15:08:32,519 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:08:32,522 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 2 [2021-12-17 15:08:32,523 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:08:32,526 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 22 [2021-12-17 15:08:32,527 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:08:32,539 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 67 [2021-12-17 15:08:32,541 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:08:32,545 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 74 [2021-12-17 15:08:32,546 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:08:32,548 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 80 [2021-12-17 15:08:32,551 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:08:32,553 INFO L134 CoverageAnalysis]: Checked inductivity of 27 backedges. 18 proven. 4 refuted. 0 times theorem prover too weak. 5 trivial. 0 not checked. [2021-12-17 15:08:32,553 INFO L139 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2021-12-17 15:08:32,553 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [636528028] [2021-12-17 15:08:32,553 INFO L160 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [636528028] provided 0 perfect and 1 imperfect interpolant sequences [2021-12-17 15:08:32,553 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleZ3 [352507320] [2021-12-17 15:08:32,554 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2021-12-17 15:08:32,554 INFO L168 SolverBuilder]: Constructing external solver with command: z3 -smt2 -in SMTLIB2_COMPLIANT=true [2021-12-17 15:08:32,554 INFO L189 MonitoredProcess]: No working directory specified, using /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 [2021-12-17 15:08:32,559 INFO L229 MonitoredProcess]: Starting monitored process 2 with /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 -smt2 -in SMTLIB2_COMPLIANT=true (exit command is (exit), workingDir is null) [2021-12-17 15:08:32,582 INFO L327 MonitoredProcess]: [MP /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 -smt2 -in SMTLIB2_COMPLIANT=true (2)] Waiting until timeout for monitored process [2021-12-17 15:08:32,654 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:08:32,657 INFO L263 TraceCheckSpWp]: Trace formula consists of 455 conjuncts, 13 conjunts are in the unsatisfiable core [2021-12-17 15:08:32,676 INFO L286 TraceCheckSpWp]: Computing forward predicates... [2021-12-17 15:08:32,992 INFO L134 CoverageAnalysis]: Checked inductivity of 27 backedges. 6 proven. 12 refuted. 0 times theorem prover too weak. 9 trivial. 0 not checked. [2021-12-17 15:08:32,993 INFO L328 TraceCheckSpWp]: Computing backward predicates... [2021-12-17 15:08:33,345 INFO L134 CoverageAnalysis]: Checked inductivity of 27 backedges. 8 proven. 4 refuted. 0 times theorem prover too weak. 15 trivial. 0 not checked. [2021-12-17 15:08:33,345 INFO L160 FreeRefinementEngine]: IpTcStrategyModuleZ3 [352507320] provided 0 perfect and 2 imperfect interpolant sequences [2021-12-17 15:08:33,345 INFO L186 FreeRefinementEngine]: Found 0 perfect and 3 imperfect interpolant sequences. [2021-12-17 15:08:33,345 INFO L199 FreeRefinementEngine]: Number of different interpolants: perfect sequences [] imperfect sequences [10, 8, 9] total 19 [2021-12-17 15:08:33,345 INFO L115 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [71579546] [2021-12-17 15:08:33,346 INFO L85 oduleStraightlineAll]: Using 3 imperfect interpolants to construct interpolant automaton [2021-12-17 15:08:33,346 INFO L546 AbstractCegarLoop]: INTERPOLANT automaton has 19 states [2021-12-17 15:08:33,346 INFO L103 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2021-12-17 15:08:33,347 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 19 interpolants. [2021-12-17 15:08:33,347 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=60, Invalid=282, Unknown=0, NotChecked=0, Total=342 [2021-12-17 15:08:33,347 INFO L87 Difference]: Start difference. First operand 301 states and 363 transitions. Second operand has 19 states, 19 states have (on average 7.105263157894737) internal successors, (135), 14 states have internal predecessors, (135), 7 states have call successors, (25), 10 states have call predecessors, (25), 8 states have return successors, (22), 8 states have call predecessors, (22), 7 states have call successors, (22) [2021-12-17 15:08:34,902 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2021-12-17 15:08:34,902 INFO L93 Difference]: Finished difference Result 913 states and 1175 transitions. [2021-12-17 15:08:34,903 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 52 states. [2021-12-17 15:08:34,903 INFO L78 Accepts]: Start accepts. Automaton has has 19 states, 19 states have (on average 7.105263157894737) internal successors, (135), 14 states have internal predecessors, (135), 7 states have call successors, (25), 10 states have call predecessors, (25), 8 states have return successors, (22), 8 states have call predecessors, (22), 7 states have call successors, (22) Word has length 91 [2021-12-17 15:08:34,903 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2021-12-17 15:08:34,904 INFO L225 Difference]: With dead ends: 913 [2021-12-17 15:08:34,904 INFO L226 Difference]: Without dead ends: 0 [2021-12-17 15:08:34,908 INFO L932 BasicCegarLoop]: 0 DeclaredPredicates, 261 GetRequests, 193 SyntacticMatches, 1 SemanticMatches, 67 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 1202 ImplicationChecksByTransitivity, 0.7s TimeCoverageRelationStatistics Valid=927, Invalid=3765, Unknown=0, NotChecked=0, Total=4692 [2021-12-17 15:08:34,908 INFO L933 BasicCegarLoop]: 152 mSDtfsCounter, 1083 mSDsluCounter, 676 mSDsCounter, 0 mSdLazyCounter, 1453 mSolverCounterSat, 566 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.7s Time, 0 mProtectedPredicate, 0 mProtectedAction, 1083 SdHoareTripleChecker+Valid, 828 SdHoareTripleChecker+Invalid, 2019 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 566 IncrementalHoareTripleChecker+Valid, 1453 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.9s IncrementalHoareTripleChecker+Time [2021-12-17 15:08:34,909 INFO L934 BasicCegarLoop]: SdHoareTripleChecker [1083 Valid, 828 Invalid, 2019 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [566 Valid, 1453 Invalid, 0 Unknown, 0 Unchecked, 0.9s Time] [2021-12-17 15:08:34,909 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 0 states. [2021-12-17 15:08:34,909 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 0 to 0. [2021-12-17 15:08:34,909 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 0 states, 0 states have (on average 0.0) internal successors, (0), 0 states have internal predecessors, (0), 0 states have call successors, (0), 0 states have call predecessors, (0), 0 states have return successors, (0), 0 states have call predecessors, (0), 0 states have call successors, (0) [2021-12-17 15:08:34,909 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 0 states to 0 states and 0 transitions. [2021-12-17 15:08:34,910 INFO L78 Accepts]: Start accepts. Automaton has 0 states and 0 transitions. Word has length 91 [2021-12-17 15:08:34,910 INFO L84 Accepts]: Finished accepts. word is rejected. [2021-12-17 15:08:34,910 INFO L470 AbstractCegarLoop]: Abstraction has 0 states and 0 transitions. [2021-12-17 15:08:34,910 INFO L471 AbstractCegarLoop]: INTERPOLANT automaton has has 19 states, 19 states have (on average 7.105263157894737) internal successors, (135), 14 states have internal predecessors, (135), 7 states have call successors, (25), 10 states have call predecessors, (25), 8 states have return successors, (22), 8 states have call predecessors, (22), 7 states have call successors, (22) [2021-12-17 15:08:34,910 INFO L276 IsEmpty]: Start isEmpty. Operand 0 states and 0 transitions. [2021-12-17 15:08:34,910 INFO L282 IsEmpty]: Finished isEmpty. No accepting run. [2021-12-17 15:08:34,913 INFO L764 garLoopResultBuilder]: Registering result SAFE for location timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION (0 of 1 remaining) [2021-12-17 15:08:34,935 INFO L540 MonitoredProcess]: [MP /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 -smt2 -in SMTLIB2_COMPLIANT=true (2)] Forceful destruction successful, exit code 0 [2021-12-17 15:08:35,127 WARN L452 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: 2 /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 -smt2 -in SMTLIB2_COMPLIANT=true,SelfDestructingSolverStorable11 [2021-12-17 15:08:35,129 INFO L343 DoubleDeckerVisitor]: Before removal of dead ends 0 states and 0 transitions. [2021-12-17 15:08:38,907 INFO L854 garLoopResultBuilder]: At program point deactivatePumpENTRY(lines 898 905) the Hoare annotation is: (or (= 0 ~systemActive~0) (not (<= ~waterLevel~0 1)) (= ~pumpRunning~0 |old(~pumpRunning~0)|) (not (= |old(~pumpRunning~0)| 1))) [2021-12-17 15:08:38,908 INFO L858 garLoopResultBuilder]: For program point deactivatePumpEXIT(lines 898 905) no Hoare annotation was computed. [2021-12-17 15:08:38,908 INFO L858 garLoopResultBuilder]: For program point deactivatePumpFINAL(lines 898 905) no Hoare annotation was computed. [2021-12-17 15:08:38,908 INFO L858 garLoopResultBuilder]: For program point processEnvironment__wrappee__baseEXIT(lines 805 811) no Hoare annotation was computed. [2021-12-17 15:08:38,908 INFO L861 garLoopResultBuilder]: At program point processEnvironment__wrappee__baseFINAL(lines 805 811) the Hoare annotation is: true [2021-12-17 15:08:38,908 INFO L854 garLoopResultBuilder]: At program point changeMethaneLevelENTRY(lines 84 95) the Hoare annotation is: (let ((.cse5 (not (= |old(~methaneLevelCritical~0)| 0))) (.cse1 (not (= ~pumpRunning~0 1))) (.cse7 (= ~methaneLevelCritical~0 0)) (.cse0 (= 0 ~systemActive~0)) (.cse6 (not (= ~pumpRunning~0 0))) (.cse2 (not (<= ~waterLevel~0 2))) (.cse3 (not (= 0 ~methaneLevelCritical~0))) (.cse4 (= 0 |old(~methaneLevelCritical~0)|))) (and (or .cse0 .cse1 .cse2 .cse3 .cse4) (or .cse0 .cse5 .cse6 .cse7 .cse2) (or .cse0 .cse5 .cse1 .cse7 .cse2) (or .cse0 .cse6 .cse2 .cse3 .cse4))) [2021-12-17 15:08:38,908 INFO L858 garLoopResultBuilder]: For program point L88-1(lines 84 95) no Hoare annotation was computed. [2021-12-17 15:08:38,908 INFO L858 garLoopResultBuilder]: For program point changeMethaneLevelEXIT(lines 84 95) no Hoare annotation was computed. [2021-12-17 15:08:38,908 INFO L858 garLoopResultBuilder]: For program point L64(lines 64 68) no Hoare annotation was computed. [2021-12-17 15:08:38,908 INFO L854 garLoopResultBuilder]: At program point L64-2(lines 60 71) the Hoare annotation is: (let ((.cse0 (= 0 ~systemActive~0)) (.cse1 (not (<= |old(~waterLevel~0)| 2)))) (and (or .cse0 .cse1 (and (<= ~waterLevel~0 |old(~waterLevel~0)|) (<= ~waterLevel~0 1) (= ~pumpRunning~0 |old(~pumpRunning~0)|)) (not (= |old(~pumpRunning~0)| 1))) (or .cse0 .cse1 (not (= |old(~pumpRunning~0)| 0))))) [2021-12-17 15:08:38,908 INFO L854 garLoopResultBuilder]: At program point L911(line 911) the Hoare annotation is: (let ((.cse0 (= 0 ~systemActive~0)) (.cse1 (not (<= |old(~waterLevel~0)| 2)))) (and (or .cse0 .cse1 (and (<= ~waterLevel~0 |old(~waterLevel~0)|) (<= ~waterLevel~0 1) (= ~pumpRunning~0 |old(~pumpRunning~0)|)) (not (= |old(~pumpRunning~0)| 1))) (or .cse0 .cse1 (not (= |old(~pumpRunning~0)| 0))))) [2021-12-17 15:08:38,908 INFO L858 garLoopResultBuilder]: For program point L911-1(line 911) no Hoare annotation was computed. [2021-12-17 15:08:38,909 INFO L858 garLoopResultBuilder]: For program point L267(line 267) no Hoare annotation was computed. [2021-12-17 15:08:38,909 INFO L858 garLoopResultBuilder]: For program point timeShiftFINAL(lines 781 804) no Hoare annotation was computed. [2021-12-17 15:08:38,909 INFO L858 garLoopResultBuilder]: For program point L292(lines 292 298) no Hoare annotation was computed. [2021-12-17 15:08:38,909 INFO L858 garLoopResultBuilder]: For program point L288(lines 288 301) no Hoare annotation was computed. [2021-12-17 15:08:38,909 INFO L854 garLoopResultBuilder]: At program point L288-1(lines 273 305) the Hoare annotation is: (let ((.cse7 (= ~methaneLevelCritical~0 |timeShift___utac_acc__Specification3_spec__1_~tmp~1#1|)) (.cse9 (= ~waterLevel~0 |old(~waterLevel~0)|)) (.cse0 (= 0 ~systemActive~0))) (let ((.cse1 (and (<= |timeShift___utac_acc__Specification3_spec__1_~tmp___0~0#1| 1) (<= |timeShift_getWaterLevel_#res#1| 1))) (.cse5 (not (= ~methaneLevelCritical~0 0))) (.cse3 (not (= |old(~pumpRunning~0)| 0))) (.cse4 (and .cse7 (= ~pumpRunning~0 1) .cse9 (<= 2 ~waterLevel~0) (not .cse0))) (.cse2 (not (<= |old(~waterLevel~0)| 2))) (.cse8 (<= ~waterLevel~0 1)) (.cse10 (= ~pumpRunning~0 0)) (.cse6 (not (= |old(~pumpRunning~0)| 1)))) (and (or .cse0 .cse1 .cse2 .cse3 .cse4 .cse5) (or .cse0 .cse1 .cse2 .cse5 .cse6) (or .cse0 .cse2 .cse3 .cse4 (and .cse7 .cse8 .cse9 .cse10)) (let ((.cse11 (<= ~waterLevel~0 |old(~waterLevel~0)|))) (or .cse0 .cse2 (and .cse11 .cse7 .cse8 (= ~pumpRunning~0 |old(~pumpRunning~0)|)) (and .cse11 .cse7 .cse8 .cse10) .cse6))))) [2021-12-17 15:08:38,909 INFO L854 garLoopResultBuilder]: At program point L280(line 280) the Hoare annotation is: (let ((.cse3 (= ~pumpRunning~0 0)) (.cse0 (= 0 ~systemActive~0)) (.cse2 (not (<= |old(~waterLevel~0)| 2))) (.cse4 (not (= |old(~pumpRunning~0)| 0)))) (and (let ((.cse1 (= ~waterLevel~0 |old(~waterLevel~0)|))) (or .cse0 (and .cse1 (<= 2 ~waterLevel~0)) .cse2 (and .cse1 .cse3) .cse4)) (let ((.cse5 (<= ~waterLevel~0 |old(~waterLevel~0)|)) (.cse6 (<= ~waterLevel~0 1))) (or .cse0 .cse2 (and .cse5 .cse6 (= ~pumpRunning~0 |old(~pumpRunning~0)|)) (and .cse5 .cse6 .cse3) (not (= |old(~pumpRunning~0)| 1)))) (or (not (<= 2 |old(~waterLevel~0)|)) .cse0 .cse2 (= ~pumpRunning~0 1) .cse4))) [2021-12-17 15:08:38,910 INFO L858 garLoopResultBuilder]: For program point L792-1(lines 792 798) no Hoare annotation was computed. [2021-12-17 15:08:38,910 INFO L858 garLoopResultBuilder]: For program point L280-1(line 280) no Hoare annotation was computed. [2021-12-17 15:08:38,910 INFO L854 garLoopResultBuilder]: At program point L879(line 879) the Hoare annotation is: (let ((.cse0 (= 0 ~systemActive~0)) (.cse1 (not (<= |old(~waterLevel~0)| 2)))) (and (or .cse0 .cse1 (and (<= ~waterLevel~0 |old(~waterLevel~0)|) (<= ~waterLevel~0 1) (= ~pumpRunning~0 |old(~pumpRunning~0)|)) (not (= |old(~pumpRunning~0)| 1))) (or .cse0 .cse1 (not (= |old(~pumpRunning~0)| 0))))) [2021-12-17 15:08:38,910 INFO L854 garLoopResultBuilder]: At program point L268(lines 263 270) the Hoare annotation is: (let ((.cse0 (= 0 ~systemActive~0)) (.cse1 (not (<= |old(~waterLevel~0)| 2)))) (and (or .cse0 .cse1 (not (= |old(~pumpRunning~0)| 1))) (or .cse0 .cse1 (not (= |old(~pumpRunning~0)| 0))))) [2021-12-17 15:08:38,910 INFO L854 garLoopResultBuilder]: At program point L875(line 875) the Hoare annotation is: (let ((.cse0 (= 0 ~systemActive~0)) (.cse1 (not (<= |old(~waterLevel~0)| 2)))) (and (or .cse0 .cse1 (and (<= ~waterLevel~0 |old(~waterLevel~0)|) (<= ~waterLevel~0 1) (= ~pumpRunning~0 |old(~pumpRunning~0)|)) (not (= |old(~pumpRunning~0)| 1))) (or .cse0 .cse1 (not (= |old(~pumpRunning~0)| 0))))) [2021-12-17 15:08:38,910 INFO L854 garLoopResultBuilder]: At program point L884(line 884) the Hoare annotation is: (let ((.cse0 (= 0 ~systemActive~0)) (.cse1 (not (<= |old(~waterLevel~0)| 2)))) (and (or .cse0 .cse1 (and (= ~waterLevel~0 |old(~waterLevel~0)|) (= ~pumpRunning~0 0)) (not (= |old(~pumpRunning~0)| 0))) (or .cse0 .cse1 (not (= |old(~pumpRunning~0)| 1))))) [2021-12-17 15:08:38,911 INFO L854 garLoopResultBuilder]: At program point L884-1(lines 865 889) the Hoare annotation is: (let ((.cse3 (= ~pumpRunning~0 0)) (.cse0 (= 0 ~systemActive~0)) (.cse2 (not (<= |old(~waterLevel~0)| 2))) (.cse4 (not (= |old(~pumpRunning~0)| 0)))) (and (let ((.cse1 (= ~waterLevel~0 |old(~waterLevel~0)|))) (or .cse0 (and .cse1 (<= 2 ~waterLevel~0)) .cse2 (and .cse1 .cse3) .cse4)) (let ((.cse5 (<= ~waterLevel~0 |old(~waterLevel~0)|)) (.cse6 (<= ~waterLevel~0 1))) (or .cse0 .cse2 (and .cse5 .cse6 (= ~pumpRunning~0 |old(~pumpRunning~0)|)) (and .cse5 .cse6 .cse3) (not (= |old(~pumpRunning~0)| 1)))) (or (not (<= 2 |old(~waterLevel~0)|)) .cse0 .cse2 (= ~pumpRunning~0 1) .cse4))) [2021-12-17 15:08:38,911 INFO L854 garLoopResultBuilder]: At program point L913(lines 906 916) the Hoare annotation is: (let ((.cse0 (= 0 ~systemActive~0)) (.cse1 (not (<= |old(~waterLevel~0)| 2)))) (and (or .cse0 .cse1 (and (<= ~waterLevel~0 |old(~waterLevel~0)|) (<= ~waterLevel~0 1) (= ~pumpRunning~0 |old(~pumpRunning~0)|)) (not (= |old(~pumpRunning~0)| 1))) (or .cse0 .cse1 (not (= |old(~pumpRunning~0)| 0))))) [2021-12-17 15:08:38,911 INFO L858 garLoopResultBuilder]: For program point L785-1(lines 784 803) no Hoare annotation was computed. [2021-12-17 15:08:38,911 INFO L854 garLoopResultBuilder]: At program point L133(lines 128 136) the Hoare annotation is: (let ((.cse7 (= ~pumpRunning~0 0)) (.cse2 (= ~methaneLevelCritical~0 |timeShift___utac_acc__Specification3_spec__1_~tmp~1#1|)) (.cse5 (<= ~waterLevel~0 1)) (.cse6 (<= |timeShift_getWaterLevel_#res#1| 1)) (.cse0 (= 0 ~systemActive~0)) (.cse4 (not (<= |old(~waterLevel~0)| 2))) (.cse1 (not (= |old(~pumpRunning~0)| 0)))) (and (or .cse0 (not (= |old(~waterLevel~0)| 1)) (= |timeShift_getWaterLevel_#res#1| 1) .cse1) (let ((.cse3 (= ~waterLevel~0 |old(~waterLevel~0)|))) (or .cse0 (and .cse2 (= ~pumpRunning~0 1) .cse3 (<= 2 ~waterLevel~0)) .cse4 (and .cse2 .cse5 .cse6 .cse3 .cse7) .cse1)) (let ((.cse8 (<= ~waterLevel~0 |old(~waterLevel~0)|)) (.cse9 (= ~methaneLevelCritical~0 0))) (or .cse0 (and .cse8 .cse2 .cse5 .cse6 .cse9 .cse7) (and .cse8 .cse2 .cse5 .cse6 .cse9 (= ~pumpRunning~0 |old(~pumpRunning~0)|)) .cse4 (not (= |old(~pumpRunning~0)| 1)))) (or .cse0 .cse4 .cse1 (= 0 ~methaneLevelCritical~0)))) [2021-12-17 15:08:38,911 INFO L858 garLoopResultBuilder]: For program point L282(lines 282 302) no Hoare annotation was computed. [2021-12-17 15:08:38,912 INFO L854 garLoopResultBuilder]: At program point L922(lines 917 925) the Hoare annotation is: (let ((.cse0 (= 0 ~systemActive~0)) (.cse1 (not (<= |old(~waterLevel~0)| 2)))) (and (or .cse0 .cse1 (not (= |old(~pumpRunning~0)| 1))) (or .cse0 .cse1 (not (= |old(~pumpRunning~0)| 0)) (and (= |timeShift_isPumpRunning_#res#1| 1) (= ~methaneLevelCritical~0 |timeShift___utac_acc__Specification3_spec__1_~tmp~1#1|) (= ~pumpRunning~0 1) (= ~waterLevel~0 |old(~waterLevel~0)|) (= ~methaneLevelCritical~0 0) (<= 2 ~waterLevel~0))))) [2021-12-17 15:08:38,912 INFO L854 garLoopResultBuilder]: At program point timeShiftENTRY(lines 781 804) the Hoare annotation is: (let ((.cse0 (= 0 ~systemActive~0)) (.cse1 (not (<= |old(~waterLevel~0)| 2))) (.cse2 (= ~waterLevel~0 |old(~waterLevel~0)|))) (and (or .cse0 .cse1 (and .cse2 (= ~pumpRunning~0 0)) (not (= |old(~pumpRunning~0)| 0))) (or .cse0 .cse1 (and .cse2 (= ~pumpRunning~0 |old(~pumpRunning~0)|)) (not (= |old(~pumpRunning~0)| 1))))) [2021-12-17 15:08:38,912 INFO L858 garLoopResultBuilder]: For program point timeShiftEXIT(lines 781 804) no Hoare annotation was computed. [2021-12-17 15:08:38,912 INFO L858 garLoopResultBuilder]: For program point L873(lines 873 881) no Hoare annotation was computed. [2021-12-17 15:08:38,912 INFO L858 garLoopResultBuilder]: For program point timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION(line 267) no Hoare annotation was computed. [2021-12-17 15:08:38,912 INFO L858 garLoopResultBuilder]: For program point L869(lines 869 886) no Hoare annotation was computed. [2021-12-17 15:08:38,912 INFO L858 garLoopResultBuilder]: For program point cleanupEXIT(lines 163 192) no Hoare annotation was computed. [2021-12-17 15:08:38,913 INFO L861 garLoopResultBuilder]: At program point cleanupENTRY(lines 163 192) the Hoare annotation is: true [2021-12-17 15:08:38,913 INFO L861 garLoopResultBuilder]: At program point L188(lines 163 192) the Hoare annotation is: true [2021-12-17 15:08:38,913 INFO L858 garLoopResultBuilder]: For program point L184(line 184) no Hoare annotation was computed. [2021-12-17 15:08:38,913 INFO L858 garLoopResultBuilder]: For program point L177(lines 177 181) no Hoare annotation was computed. [2021-12-17 15:08:38,913 INFO L861 garLoopResultBuilder]: At program point L177-1(lines 177 181) the Hoare annotation is: true [2021-12-17 15:08:38,913 INFO L858 garLoopResultBuilder]: For program point L174(line 174) no Hoare annotation was computed. [2021-12-17 15:08:38,913 INFO L861 garLoopResultBuilder]: At program point L173-2(lines 173 187) the Hoare annotation is: true [2021-12-17 15:08:38,913 INFO L861 garLoopResultBuilder]: At program point L169(line 169) the Hoare annotation is: true [2021-12-17 15:08:38,913 INFO L858 garLoopResultBuilder]: For program point L169-1(line 169) no Hoare annotation was computed. [2021-12-17 15:08:38,913 INFO L861 garLoopResultBuilder]: At program point isMethaneLevelCriticalENTRY(lines 96 104) the Hoare annotation is: true [2021-12-17 15:08:38,913 INFO L858 garLoopResultBuilder]: For program point isMethaneLevelCriticalFINAL(lines 96 104) no Hoare annotation was computed. [2021-12-17 15:08:38,913 INFO L858 garLoopResultBuilder]: For program point isMethaneLevelCriticalEXIT(lines 96 104) no Hoare annotation was computed. [2021-12-17 15:08:38,913 INFO L858 garLoopResultBuilder]: For program point L729(lines 729 735) no Hoare annotation was computed. [2021-12-17 15:08:38,914 INFO L858 garLoopResultBuilder]: For program point L729-1(lines 729 735) no Hoare annotation was computed. [2021-12-17 15:08:38,914 INFO L854 garLoopResultBuilder]: At program point L337(lines 332 340) the Hoare annotation is: (and (= ~waterLevel~0 1) (= ~methaneLevelCritical~0 0) (= 1 |ULTIMATE.start_valid_product_#res#1|) (not (= 0 ~systemActive~0)) (= ~pumpRunning~0 0)) [2021-12-17 15:08:38,914 INFO L858 garLoopResultBuilder]: For program point L721(lines 721 725) no Hoare annotation was computed. [2021-12-17 15:08:38,914 INFO L854 garLoopResultBuilder]: At program point L329(lines 325 331) the Hoare annotation is: (and (= ~waterLevel~0 1) (= ~methaneLevelCritical~0 0) (not (= 0 ~systemActive~0)) (= ~pumpRunning~0 0)) [2021-12-17 15:08:38,914 INFO L858 garLoopResultBuilder]: For program point L-1(line -1) no Hoare annotation was computed. [2021-12-17 15:08:38,914 INFO L854 garLoopResultBuilder]: At program point L767(lines 718 768) the Hoare annotation is: false [2021-12-17 15:08:38,914 INFO L854 garLoopResultBuilder]: At program point L222(lines 218 224) the Hoare annotation is: (and (= ~waterLevel~0 1) (= ~methaneLevelCritical~0 0) (= 1 |ULTIMATE.start_valid_product_#res#1|) (= 1 |ULTIMATE.start_main_~tmp~0#1|) (not (= 0 ~systemActive~0)) (= ~pumpRunning~0 0)) [2021-12-17 15:08:38,914 INFO L858 garLoopResultBuilder]: For program point ULTIMATE.startENTRY(line -1) no Hoare annotation was computed. [2021-12-17 15:08:38,914 INFO L858 garLoopResultBuilder]: For program point ULTIMATE.startFINAL(line -1) no Hoare annotation was computed. [2021-12-17 15:08:38,914 INFO L858 garLoopResultBuilder]: For program point L739(lines 739 745) no Hoare annotation was computed. [2021-12-17 15:08:38,914 INFO L854 garLoopResultBuilder]: At program point L322(lines 318 324) the Hoare annotation is: (and (= ~waterLevel~0 1) (= ~methaneLevelCritical~0 0) (not (= 0 ~systemActive~0)) (= ~pumpRunning~0 0)) [2021-12-17 15:08:38,914 INFO L858 garLoopResultBuilder]: For program point L739-1(lines 739 745) no Hoare annotation was computed. [2021-12-17 15:08:38,915 INFO L858 garLoopResultBuilder]: For program point ULTIMATE.startEXIT(line -1) no Hoare annotation was computed. [2021-12-17 15:08:38,915 INFO L854 garLoopResultBuilder]: At program point L764(lines 719 766) the Hoare annotation is: (let ((.cse0 (= |ULTIMATE.start_test_~splverifierCounter~0#1| 0)) (.cse1 (= 1 |ULTIMATE.start_valid_product_#res#1|)) (.cse2 (= 1 |ULTIMATE.start_main_~tmp~0#1|)) (.cse3 (not (= 0 ~systemActive~0)))) (or (and .cse0 (= ~pumpRunning~0 1) .cse1 .cse2 (<= ~waterLevel~0 2) .cse3) (and .cse0 (<= ~waterLevel~0 1) .cse1 .cse2 .cse3 (= ~pumpRunning~0 0)))) [2021-12-17 15:08:38,915 INFO L854 garLoopResultBuilder]: At program point L731(line 731) the Hoare annotation is: (let ((.cse0 (= |ULTIMATE.start_test_~splverifierCounter~0#1| 0)) (.cse1 (= 1 |ULTIMATE.start_valid_product_#res#1|)) (.cse2 (= 1 |ULTIMATE.start_main_~tmp~0#1|)) (.cse3 (not (= 0 ~systemActive~0)))) (or (and .cse0 (= ~pumpRunning~0 1) .cse1 .cse2 (<= ~waterLevel~0 2) .cse3) (and .cse0 (<= ~waterLevel~0 1) .cse1 .cse2 .cse3 (= ~pumpRunning~0 0)))) [2021-12-17 15:08:38,915 INFO L858 garLoopResultBuilder]: For program point L249(lines 249 256) no Hoare annotation was computed. [2021-12-17 15:08:38,915 INFO L858 garLoopResultBuilder]: For program point L249-2(lines 249 256) no Hoare annotation was computed. [2021-12-17 15:08:38,916 INFO L858 garLoopResultBuilder]: For program point L757(lines 757 761) no Hoare annotation was computed. [2021-12-17 15:08:38,916 INFO L854 garLoopResultBuilder]: At program point L757-2(lines 749 762) the Hoare annotation is: (let ((.cse0 (= |ULTIMATE.start_test_~splverifierCounter~0#1| 0)) (.cse1 (= 1 |ULTIMATE.start_valid_product_#res#1|)) (.cse2 (= 1 |ULTIMATE.start_main_~tmp~0#1|)) (.cse3 (<= ~waterLevel~0 2)) (.cse4 (not (= 0 ~systemActive~0)))) (or (and .cse0 (= ~pumpRunning~0 1) .cse1 .cse2 .cse3 .cse4) (and .cse0 .cse1 .cse2 .cse3 .cse4 (= ~pumpRunning~0 0)))) [2021-12-17 15:08:38,916 INFO L858 garLoopResultBuilder]: For program point L720(lines 719 766) no Hoare annotation was computed. [2021-12-17 15:08:38,916 INFO L858 garLoopResultBuilder]: For program point L749(lines 749 762) no Hoare annotation was computed. [2021-12-17 15:08:38,916 INFO L854 garLoopResultBuilder]: At program point L1005(lines 1000 1007) the Hoare annotation is: (let ((.cse0 (= |ULTIMATE.start_test_~splverifierCounter~0#1| 0)) (.cse1 (= 1 |ULTIMATE.start_valid_product_#res#1|)) (.cse2 (= 1 |ULTIMATE.start_main_~tmp~0#1|)) (.cse3 (<= ~waterLevel~0 2)) (.cse4 (not (= 0 ~systemActive~0)))) (or (and .cse0 (= ~pumpRunning~0 1) .cse1 .cse2 .cse3 .cse4) (and .cse0 .cse1 .cse2 .cse3 .cse4 (= ~pumpRunning~0 0)))) [2021-12-17 15:08:38,916 INFO L861 garLoopResultBuilder]: At program point L233(lines 226 235) the Hoare annotation is: true [2021-12-17 15:08:38,916 INFO L854 garLoopResultBuilder]: At program point L741(line 741) the Hoare annotation is: (let ((.cse0 (= |ULTIMATE.start_test_~splverifierCounter~0#1| 0)) (.cse1 (= 1 |ULTIMATE.start_valid_product_#res#1|)) (.cse2 (= 1 |ULTIMATE.start_main_~tmp~0#1|)) (.cse3 (<= ~waterLevel~0 2)) (.cse4 (not (= 0 ~systemActive~0)))) (or (and .cse0 (= ~pumpRunning~0 1) .cse1 .cse2 .cse3 .cse4) (and .cse0 .cse1 .cse2 .cse3 .cse4 (= ~pumpRunning~0 0)))) [2021-12-17 15:08:38,917 INFO L861 garLoopResultBuilder]: At program point L770(lines 709 774) the Hoare annotation is: true [2021-12-17 15:08:38,917 INFO L861 garLoopResultBuilder]: At program point L258(lines 239 261) the Hoare annotation is: true [2021-12-17 15:08:38,917 INFO L854 garLoopResultBuilder]: At program point processEnvironment__wrappee__highWaterSensorENTRY(lines 813 837) the Hoare annotation is: (let ((.cse0 (= 0 ~systemActive~0))) (and (or .cse0 (not (<= ~waterLevel~0 2)) (not (= |old(~pumpRunning~0)| 0)) (= ~pumpRunning~0 0)) (or .cse0 (not (<= ~waterLevel~0 1)) (= ~pumpRunning~0 |old(~pumpRunning~0)|) (not (= |old(~pumpRunning~0)| 1))))) [2021-12-17 15:08:38,917 INFO L854 garLoopResultBuilder]: At program point L832(line 832) the Hoare annotation is: (let ((.cse0 (= 0 ~systemActive~0))) (and (or .cse0 (not (<= ~waterLevel~0 2)) (not (= |old(~pumpRunning~0)| 0))) (or .cse0 (not (<= ~waterLevel~0 1)) (= ~pumpRunning~0 |old(~pumpRunning~0)|) (not (= |old(~pumpRunning~0)| 1))))) [2021-12-17 15:08:38,917 INFO L858 garLoopResultBuilder]: For program point L832-1(lines 813 837) no Hoare annotation was computed. [2021-12-17 15:08:38,917 INFO L854 garLoopResultBuilder]: At program point L977(lines 962 980) the Hoare annotation is: (let ((.cse4 (= ~pumpRunning~0 0)) (.cse5 (<= ~waterLevel~0 1))) (let ((.cse0 (= 0 ~systemActive~0)) (.cse1 (not .cse5)) (.cse2 (and (= |processEnvironment__wrappee__highWaterSensor_isHighWaterLevel_#res#1| 0) .cse5 (= |processEnvironment__wrappee__highWaterSensor_isHighWaterLevel_~tmp___0~2#1| 0) .cse4)) (.cse3 (not (= |old(~pumpRunning~0)| 0)))) (and (or .cse0 .cse1 (not (= |old(~pumpRunning~0)| 1))) (or .cse0 .cse2 (not (<= ~waterLevel~0 2)) .cse3 (and (<= 1 |processEnvironment__wrappee__highWaterSensor_isHighWaterLevel_#res#1|) (= |processEnvironment__wrappee__highWaterSensor_isHighWaterLevel_~tmp~9#1| 0) (<= 1 |processEnvironment__wrappee__highWaterSensor_isHighWaterLevel_~tmp___0~2#1|) .cse4 (= |processEnvironment__wrappee__highWaterSensor_isHighWaterSensorDry_#res#1| 0))) (or .cse0 .cse1 .cse2 .cse3)))) [2021-12-17 15:08:38,917 INFO L858 garLoopResultBuilder]: For program point L141(lines 141 147) no Hoare annotation was computed. [2021-12-17 15:08:38,918 INFO L858 garLoopResultBuilder]: For program point L971(lines 971 975) no Hoare annotation was computed. [2021-12-17 15:08:38,918 INFO L858 garLoopResultBuilder]: For program point L971-2(lines 971 975) no Hoare annotation was computed. [2021-12-17 15:08:38,918 INFO L854 garLoopResultBuilder]: At program point L895(lines 890 897) the Hoare annotation is: (let ((.cse0 (= 0 ~systemActive~0))) (and (or .cse0 (not (<= ~waterLevel~0 1)) (not (= |old(~pumpRunning~0)| 1))) (or .cse0 (not (<= ~waterLevel~0 2)) (not (= |old(~pumpRunning~0)| 0)) (and (= ~pumpRunning~0 1) (<= 1 |processEnvironment__wrappee__highWaterSensor_isHighWaterLevel_#res#1|) (<= 2 ~waterLevel~0) (= |processEnvironment__wrappee__highWaterSensor_isHighWaterLevel_~tmp~9#1| 0) (<= 1 |processEnvironment__wrappee__highWaterSensor_~tmp~6#1|) (<= 1 |processEnvironment__wrappee__highWaterSensor_isHighWaterLevel_~tmp___0~2#1|) (= |processEnvironment__wrappee__highWaterSensor_isHighWaterSensorDry_#res#1| 0))))) [2021-12-17 15:08:38,918 INFO L858 garLoopResultBuilder]: For program point processEnvironment__wrappee__highWaterSensorEXIT(lines 813 837) no Hoare annotation was computed. [2021-12-17 15:08:38,918 INFO L854 garLoopResultBuilder]: At program point L827(line 827) the Hoare annotation is: (let ((.cse0 (= 0 ~systemActive~0)) (.cse1 (<= ~waterLevel~0 1))) (and (or .cse0 (not .cse1) (not (= |old(~pumpRunning~0)| 1))) (or .cse0 (and (= |processEnvironment__wrappee__highWaterSensor_~tmp~6#1| 0) .cse1 (= ~pumpRunning~0 0)) (not (<= ~waterLevel~0 2)) (not (= |old(~pumpRunning~0)| 0))))) [2021-12-17 15:08:38,918 INFO L858 garLoopResultBuilder]: For program point L821(lines 821 829) no Hoare annotation was computed. [2021-12-17 15:08:38,919 INFO L854 garLoopResultBuilder]: At program point L146(lines 137 150) the Hoare annotation is: (let ((.cse0 (= 0 ~systemActive~0)) (.cse1 (<= ~waterLevel~0 1))) (and (or .cse0 (not .cse1) (not (= |old(~pumpRunning~0)| 1))) (let ((.cse2 (= ~pumpRunning~0 0))) (or .cse0 (and (<= 2 ~waterLevel~0) .cse2 (= |processEnvironment__wrappee__highWaterSensor_isHighWaterSensorDry_#res#1| 0)) (and .cse1 (<= 1 |processEnvironment__wrappee__highWaterSensor_isHighWaterSensorDry_#res#1|) .cse2) (not (<= ~waterLevel~0 2)) (not (= |old(~pumpRunning~0)| 0)))))) [2021-12-17 15:08:38,919 INFO L858 garLoopResultBuilder]: For program point L817(lines 817 834) no Hoare annotation was computed. [2021-12-17 15:08:38,919 INFO L858 garLoopResultBuilder]: For program point waterRiseEXIT(lines 72 83) no Hoare annotation was computed. [2021-12-17 15:08:38,919 INFO L858 garLoopResultBuilder]: For program point L76-1(lines 72 83) no Hoare annotation was computed. [2021-12-17 15:08:38,919 INFO L854 garLoopResultBuilder]: At program point waterRiseENTRY(lines 72 83) the Hoare annotation is: (let ((.cse1 (not (= ~pumpRunning~0 1))) (.cse0 (= 0 ~systemActive~0)) (.cse2 (= ~waterLevel~0 |old(~waterLevel~0)|)) (.cse3 (not (<= |old(~waterLevel~0)| 1)))) (and (or .cse0 .cse1 .cse2 .cse3) (or (not (<= 2 |old(~waterLevel~0)|)) .cse0 (not (<= |old(~waterLevel~0)| 2)) .cse1 (and (<= 2 ~waterLevel~0) (<= ~waterLevel~0 2))) (or .cse0 (not (= ~pumpRunning~0 0)) .cse2 .cse3))) [2021-12-17 15:08:38,919 INFO L854 garLoopResultBuilder]: At program point processEnvironment__wrappee__lowWaterSensorENTRY(lines 839 863) the Hoare annotation is: (let ((.cse0 (= 0 ~systemActive~0))) (and (or .cse0 (not (<= ~waterLevel~0 2)) (not (= |old(~pumpRunning~0)| 0)) (= ~pumpRunning~0 0)) (or .cse0 (not (<= ~waterLevel~0 1)) (= ~pumpRunning~0 |old(~pumpRunning~0)|) (not (= |old(~pumpRunning~0)| 1))))) [2021-12-17 15:08:38,919 INFO L854 garLoopResultBuilder]: At program point L853(line 853) the Hoare annotation is: (let ((.cse0 (= 0 ~systemActive~0))) (and (or .cse0 (not (<= ~waterLevel~0 2)) (not (= |old(~pumpRunning~0)| 0))) (or .cse0 (not (<= ~waterLevel~0 1)) (= ~pumpRunning~0 |old(~pumpRunning~0)|) (not (= |old(~pumpRunning~0)| 1))))) [2021-12-17 15:08:38,920 INFO L854 garLoopResultBuilder]: At program point L849(line 849) the Hoare annotation is: (let ((.cse0 (= 0 ~systemActive~0))) (and (or .cse0 (not (<= ~waterLevel~0 2)) (not (= |old(~pumpRunning~0)| 0))) (or .cse0 (not (<= ~waterLevel~0 1)) (= ~pumpRunning~0 |old(~pumpRunning~0)|) (not (= |old(~pumpRunning~0)| 1))))) [2021-12-17 15:08:38,920 INFO L858 garLoopResultBuilder]: For program point L847(lines 847 855) no Hoare annotation was computed. [2021-12-17 15:08:38,920 INFO L858 garLoopResultBuilder]: For program point L843(lines 843 860) no Hoare annotation was computed. [2021-12-17 15:08:38,920 INFO L854 garLoopResultBuilder]: At program point L996(lines 981 999) the Hoare annotation is: (let ((.cse0 (= 0 ~systemActive~0))) (and (or .cse0 (not (<= ~waterLevel~0 2)) (not (= |old(~pumpRunning~0)| 0))) (or .cse0 (not (<= ~waterLevel~0 1)) (= ~pumpRunning~0 |old(~pumpRunning~0)|) (not (= |old(~pumpRunning~0)| 1))))) [2021-12-17 15:08:38,920 INFO L858 garLoopResultBuilder]: For program point L990(lines 990 994) no Hoare annotation was computed. [2021-12-17 15:08:38,920 INFO L858 garLoopResultBuilder]: For program point processEnvironment__wrappee__lowWaterSensorEXIT(lines 839 863) no Hoare annotation was computed. [2021-12-17 15:08:38,920 INFO L854 garLoopResultBuilder]: At program point L156(lines 151 159) the Hoare annotation is: (let ((.cse0 (= 0 ~systemActive~0))) (and (or .cse0 (not (<= ~waterLevel~0 2)) (not (= |old(~pumpRunning~0)| 0))) (or .cse0 (not (<= ~waterLevel~0 1)) (= ~pumpRunning~0 |old(~pumpRunning~0)|) (not (= |old(~pumpRunning~0)| 1))))) [2021-12-17 15:08:38,921 INFO L858 garLoopResultBuilder]: For program point L990-2(lines 990 994) no Hoare annotation was computed. [2021-12-17 15:08:38,921 INFO L854 garLoopResultBuilder]: At program point L858(line 858) the Hoare annotation is: (let ((.cse0 (= 0 ~systemActive~0))) (and (or .cse0 (not (<= ~waterLevel~0 1)) (not (= |old(~pumpRunning~0)| 1))) (or .cse0 (not (<= ~waterLevel~0 2)) (not (= |old(~pumpRunning~0)| 0)) (= ~pumpRunning~0 0)))) [2021-12-17 15:08:38,921 INFO L858 garLoopResultBuilder]: For program point L858-1(lines 839 863) no Hoare annotation was computed. [2021-12-17 15:08:38,924 INFO L732 BasicCegarLoop]: Path program histogram: [1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2021-12-17 15:08:38,925 INFO L179 ceAbstractionStarter]: Computing trace abstraction results [2021-12-17 15:08:38,948 INFO L202 PluginConnector]: Adding new model de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction CFG 17.12 03:08:38 BoogieIcfgContainer [2021-12-17 15:08:38,948 INFO L132 PluginConnector]: ------------------------ END TraceAbstraction---------------------------- [2021-12-17 15:08:38,948 INFO L113 PluginConnector]: ------------------------Witness Printer---------------------------- [2021-12-17 15:08:38,949 INFO L271 PluginConnector]: Initializing Witness Printer... [2021-12-17 15:08:38,949 INFO L275 PluginConnector]: Witness Printer initialized [2021-12-17 15:08:38,949 INFO L185 PluginConnector]: Executing the observer RCFGCatcher from plugin Witness Printer for "de.uni_freiburg.informatik.ultimate.plugins.generator.rcfgbuilder CFG 17.12 03:08:29" (3/4) ... [2021-12-17 15:08:38,952 INFO L137 WitnessPrinter]: Generating witness for correct program [2021-12-17 15:08:38,956 INFO L354 RCFGBacktranslator]: Ignoring RootEdge to procedure deactivatePump [2021-12-17 15:08:38,957 INFO L354 RCFGBacktranslator]: Ignoring RootEdge to procedure processEnvironment__wrappee__base [2021-12-17 15:08:38,957 INFO L354 RCFGBacktranslator]: Ignoring RootEdge to procedure changeMethaneLevel [2021-12-17 15:08:38,957 INFO L354 RCFGBacktranslator]: Ignoring RootEdge to procedure timeShift [2021-12-17 15:08:38,957 INFO L354 RCFGBacktranslator]: Ignoring RootEdge to procedure cleanup [2021-12-17 15:08:38,957 INFO L354 RCFGBacktranslator]: Ignoring RootEdge to procedure isMethaneLevelCritical [2021-12-17 15:08:38,957 INFO L354 RCFGBacktranslator]: Ignoring RootEdge to procedure processEnvironment__wrappee__highWaterSensor [2021-12-17 15:08:38,957 INFO L354 RCFGBacktranslator]: Ignoring RootEdge to procedure waterRise [2021-12-17 15:08:38,958 INFO L354 RCFGBacktranslator]: Ignoring RootEdge to procedure processEnvironment__wrappee__lowWaterSensor [2021-12-17 15:08:38,966 INFO L910 BoogieBacktranslator]: Reduced CFG by removing 55 nodes and edges [2021-12-17 15:08:38,967 INFO L910 BoogieBacktranslator]: Reduced CFG by removing 22 nodes and edges [2021-12-17 15:08:38,967 INFO L910 BoogieBacktranslator]: Reduced CFG by removing 11 nodes and edges [2021-12-17 15:08:38,968 INFO L910 BoogieBacktranslator]: Reduced CFG by removing 5 nodes and edges [2021-12-17 15:08:38,968 INFO L910 BoogieBacktranslator]: Reduced CFG by removing 2 nodes and edges [2021-12-17 15:08:38,969 INFO L910 BoogieBacktranslator]: Reduced CFG by removing 1 nodes and edges [2021-12-17 15:08:38,969 INFO L910 BoogieBacktranslator]: Reduced CFG by removing 1 nodes and edges [2021-12-17 15:08:38,987 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (((waterLevel == 1 && methaneLevelCritical == 0) && 1 == \result) && !(0 == systemActive)) && pumpRunning == 0 [2021-12-17 15:08:38,987 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: ((((waterLevel == 1 && methaneLevelCritical == 0) && 1 == \result) && 1 == tmp) && !(0 == systemActive)) && pumpRunning == 0 [2021-12-17 15:08:38,987 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (((((splverifierCounter == 0 && pumpRunning == 1) && 1 == \result) && 1 == tmp) && waterLevel <= 2) && !(0 == systemActive)) || (((((splverifierCounter == 0 && waterLevel <= 1) && 1 == \result) && 1 == tmp) && !(0 == systemActive)) && pumpRunning == 0) [2021-12-17 15:08:38,988 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (((0 == systemActive || !(\old(waterLevel) <= 2)) || ((waterLevel <= \old(waterLevel) && waterLevel <= 1) && pumpRunning == \old(pumpRunning))) || !(\old(pumpRunning) == 1)) && ((0 == systemActive || !(\old(waterLevel) <= 2)) || !(\old(pumpRunning) == 0)) [2021-12-17 15:08:38,988 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (((((0 == systemActive || (waterLevel == \old(waterLevel) && 2 <= waterLevel)) || !(\old(waterLevel) <= 2)) || (waterLevel == \old(waterLevel) && pumpRunning == 0)) || !(\old(pumpRunning) == 0)) && ((((0 == systemActive || !(\old(waterLevel) <= 2)) || ((waterLevel <= \old(waterLevel) && waterLevel <= 1) && pumpRunning == \old(pumpRunning))) || ((waterLevel <= \old(waterLevel) && waterLevel <= 1) && pumpRunning == 0)) || !(\old(pumpRunning) == 1))) && ((((!(2 <= \old(waterLevel)) || 0 == systemActive) || !(\old(waterLevel) <= 2)) || pumpRunning == 1) || !(\old(pumpRunning) == 0)) [2021-12-17 15:08:38,989 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (((((splverifierCounter == 0 && pumpRunning == 1) && 1 == \result) && 1 == tmp) && waterLevel <= 2) && !(0 == systemActive)) || (((((splverifierCounter == 0 && 1 == \result) && 1 == tmp) && waterLevel <= 2) && !(0 == systemActive)) && pumpRunning == 0) [2021-12-17 15:08:38,989 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (((((((0 == systemActive || (tmp___0 <= 1 && \result <= 1)) || !(\old(waterLevel) <= 2)) || !(\old(pumpRunning) == 0)) || ((((methaneLevelCritical == tmp && pumpRunning == 1) && waterLevel == \old(waterLevel)) && 2 <= waterLevel) && !(0 == systemActive))) || !(methaneLevelCritical == 0)) && ((((0 == systemActive || (tmp___0 <= 1 && \result <= 1)) || !(\old(waterLevel) <= 2)) || !(methaneLevelCritical == 0)) || !(\old(pumpRunning) == 1))) && ((((0 == systemActive || !(\old(waterLevel) <= 2)) || !(\old(pumpRunning) == 0)) || ((((methaneLevelCritical == tmp && pumpRunning == 1) && waterLevel == \old(waterLevel)) && 2 <= waterLevel) && !(0 == systemActive))) || (((methaneLevelCritical == tmp && waterLevel <= 1) && waterLevel == \old(waterLevel)) && pumpRunning == 0))) && ((((0 == systemActive || !(\old(waterLevel) <= 2)) || (((waterLevel <= \old(waterLevel) && methaneLevelCritical == tmp) && waterLevel <= 1) && pumpRunning == \old(pumpRunning))) || (((waterLevel <= \old(waterLevel) && methaneLevelCritical == tmp) && waterLevel <= 1) && pumpRunning == 0)) || !(\old(pumpRunning) == 1)) [2021-12-17 15:08:38,990 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (((0 == systemActive || !(\old(waterLevel) <= 2)) || ((waterLevel <= \old(waterLevel) && waterLevel <= 1) && pumpRunning == \old(pumpRunning))) || !(\old(pumpRunning) == 1)) && ((0 == systemActive || !(\old(waterLevel) <= 2)) || !(\old(pumpRunning) == 0)) [2021-12-17 15:08:38,990 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (((((0 == systemActive || !(\old(waterLevel) == 1)) || \result == 1) || !(\old(pumpRunning) == 0)) && ((((0 == systemActive || (((methaneLevelCritical == tmp && pumpRunning == 1) && waterLevel == \old(waterLevel)) && 2 <= waterLevel)) || !(\old(waterLevel) <= 2)) || ((((methaneLevelCritical == tmp && waterLevel <= 1) && \result <= 1) && waterLevel == \old(waterLevel)) && pumpRunning == 0)) || !(\old(pumpRunning) == 0))) && ((((0 == systemActive || (((((waterLevel <= \old(waterLevel) && methaneLevelCritical == tmp) && waterLevel <= 1) && \result <= 1) && methaneLevelCritical == 0) && pumpRunning == 0)) || (((((waterLevel <= \old(waterLevel) && methaneLevelCritical == tmp) && waterLevel <= 1) && \result <= 1) && methaneLevelCritical == 0) && pumpRunning == \old(pumpRunning))) || !(\old(waterLevel) <= 2)) || !(\old(pumpRunning) == 1))) && (((0 == systemActive || !(\old(waterLevel) <= 2)) || !(\old(pumpRunning) == 0)) || 0 == methaneLevelCritical) [2021-12-17 15:08:38,990 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: ((0 == systemActive || !(waterLevel <= 2)) || !(\old(pumpRunning) == 0)) && (((0 == systemActive || !(waterLevel <= 1)) || pumpRunning == \old(pumpRunning)) || !(\old(pumpRunning) == 1)) [2021-12-17 15:08:38,991 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: ((0 == systemActive || !(waterLevel <= 1)) || !(\old(pumpRunning) == 1)) && ((((0 == systemActive || ((2 <= waterLevel && pumpRunning == 0) && \result == 0)) || ((waterLevel <= 1 && 1 <= \result) && pumpRunning == 0)) || !(waterLevel <= 2)) || !(\old(pumpRunning) == 0)) [2021-12-17 15:08:38,991 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: ((0 == systemActive || !(waterLevel <= 2)) || !(\old(pumpRunning) == 0)) && (((0 == systemActive || !(waterLevel <= 1)) || pumpRunning == \old(pumpRunning)) || !(\old(pumpRunning) == 1)) [2021-12-17 15:08:38,991 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: ((0 == systemActive || !(\old(waterLevel) <= 2)) || !(\old(pumpRunning) == 1)) && (((0 == systemActive || !(\old(waterLevel) <= 2)) || !(\old(pumpRunning) == 0)) || (((((\result == 1 && methaneLevelCritical == tmp) && pumpRunning == 1) && waterLevel == \old(waterLevel)) && methaneLevelCritical == 0) && 2 <= waterLevel)) [2021-12-17 15:08:38,992 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (((0 == systemActive || !(waterLevel <= 1)) || !(\old(pumpRunning) == 1)) && ((((0 == systemActive || (((\result == 0 && waterLevel <= 1) && tmp___0 == 0) && pumpRunning == 0)) || !(waterLevel <= 2)) || !(\old(pumpRunning) == 0)) || ((((1 <= \result && tmp == 0) && 1 <= tmp___0) && pumpRunning == 0) && \result == 0))) && (((0 == systemActive || !(waterLevel <= 1)) || (((\result == 0 && waterLevel <= 1) && tmp___0 == 0) && pumpRunning == 0)) || !(\old(pumpRunning) == 0)) [2021-12-17 15:08:38,995 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: ((0 == systemActive || !(\old(waterLevel) <= 2)) || !(\old(pumpRunning) == 1)) && ((0 == systemActive || !(\old(waterLevel) <= 2)) || !(\old(pumpRunning) == 0)) [2021-12-17 15:08:38,996 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: ((0 == systemActive || !(waterLevel <= 1)) || !(\old(pumpRunning) == 1)) && (((0 == systemActive || !(waterLevel <= 2)) || !(\old(pumpRunning) == 0)) || ((((((pumpRunning == 1 && 1 <= \result) && 2 <= waterLevel) && tmp == 0) && 1 <= tmp) && 1 <= tmp___0) && \result == 0)) [2021-12-17 15:08:39,020 INFO L141 WitnessManager]: Wrote witness to /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/witness.graphml [2021-12-17 15:08:39,021 INFO L132 PluginConnector]: ------------------------ END Witness Printer---------------------------- [2021-12-17 15:08:39,021 INFO L158 Benchmark]: Toolchain (without parser) took 10843.05ms. Allocated memory was 109.1MB in the beginning and 163.6MB in the end (delta: 54.5MB). Free memory was 75.2MB in the beginning and 72.3MB in the end (delta: 2.9MB). Peak memory consumption was 55.6MB. Max. memory is 16.1GB. [2021-12-17 15:08:39,021 INFO L158 Benchmark]: CDTParser took 0.23ms. Allocated memory is still 77.6MB. Free memory is still 35.6MB. There was no memory consumed. Max. memory is 16.1GB. [2021-12-17 15:08:39,022 INFO L158 Benchmark]: CACSL2BoogieTranslator took 442.90ms. Allocated memory is still 109.1MB. Free memory was 75.0MB in the beginning and 77.0MB in the end (delta: -2.0MB). Peak memory consumption was 8.4MB. Max. memory is 16.1GB. [2021-12-17 15:08:39,022 INFO L158 Benchmark]: Boogie Procedure Inliner took 55.03ms. Allocated memory is still 109.1MB. Free memory was 77.0MB in the beginning and 74.3MB in the end (delta: 2.7MB). Peak memory consumption was 2.1MB. Max. memory is 16.1GB. [2021-12-17 15:08:39,022 INFO L158 Benchmark]: Boogie Preprocessor took 29.36ms. Allocated memory is still 109.1MB. Free memory was 74.3MB in the beginning and 72.8MB in the end (delta: 1.5MB). Peak memory consumption was 2.1MB. Max. memory is 16.1GB. [2021-12-17 15:08:39,023 INFO L158 Benchmark]: RCFGBuilder took 495.88ms. Allocated memory is still 109.1MB. Free memory was 72.8MB in the beginning and 55.4MB in the end (delta: 17.4MB). Peak memory consumption was 16.8MB. Max. memory is 16.1GB. [2021-12-17 15:08:39,023 INFO L158 Benchmark]: TraceAbstraction took 9740.27ms. Allocated memory was 109.1MB in the beginning and 163.6MB in the end (delta: 54.5MB). Free memory was 55.4MB in the beginning and 79.6MB in the end (delta: -24.2MB). Peak memory consumption was 70.3MB. Max. memory is 16.1GB. [2021-12-17 15:08:39,023 INFO L158 Benchmark]: Witness Printer took 72.32ms. Allocated memory is still 163.6MB. Free memory was 79.6MB in the beginning and 72.3MB in the end (delta: 7.3MB). Peak memory consumption was 6.3MB. Max. memory is 16.1GB. [2021-12-17 15:08:39,025 INFO L339 ainManager$Toolchain]: ####################### End [Toolchain 1] ####################### --- Results --- * Results from de.uni_freiburg.informatik.ultimate.core: - StatisticsResult: Toolchain Benchmarks Benchmark results are: * CDTParser took 0.23ms. Allocated memory is still 77.6MB. Free memory is still 35.6MB. There was no memory consumed. Max. memory is 16.1GB. * CACSL2BoogieTranslator took 442.90ms. Allocated memory is still 109.1MB. Free memory was 75.0MB in the beginning and 77.0MB in the end (delta: -2.0MB). Peak memory consumption was 8.4MB. Max. memory is 16.1GB. * Boogie Procedure Inliner took 55.03ms. Allocated memory is still 109.1MB. Free memory was 77.0MB in the beginning and 74.3MB in the end (delta: 2.7MB). Peak memory consumption was 2.1MB. Max. memory is 16.1GB. * Boogie Preprocessor took 29.36ms. Allocated memory is still 109.1MB. Free memory was 74.3MB in the beginning and 72.8MB in the end (delta: 1.5MB). Peak memory consumption was 2.1MB. Max. memory is 16.1GB. * RCFGBuilder took 495.88ms. Allocated memory is still 109.1MB. Free memory was 72.8MB in the beginning and 55.4MB in the end (delta: 17.4MB). Peak memory consumption was 16.8MB. Max. memory is 16.1GB. * TraceAbstraction took 9740.27ms. Allocated memory was 109.1MB in the beginning and 163.6MB in the end (delta: 54.5MB). Free memory was 55.4MB in the beginning and 79.6MB in the end (delta: -24.2MB). Peak memory consumption was 70.3MB. Max. memory is 16.1GB. * Witness Printer took 72.32ms. Allocated memory is still 163.6MB. Free memory was 79.6MB in the beginning and 72.3MB in the end (delta: 7.3MB). Peak memory consumption was 6.3MB. Max. memory is 16.1GB. * Results from de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction: - StatisticsResult: ErrorAutomatonStatistics NumberErrorTraces: 0, NumberStatementsAllTraces: 0, NumberRelevantStatements: 0, 0.0s ErrorAutomatonConstructionTimeTotal, 0.0s FaulLocalizationTime, NumberStatementsFirstTrace: -1, TraceLengthAvg: 0, 0.0s ErrorAutomatonConstructionTimeAvg, 0.0s ErrorAutomatonDifferenceTimeAvg, 0.0s ErrorAutomatonDifferenceTimeTotal, NumberOfNoEnhancement: 0, NumberOfFiniteEnhancement: 0, NumberOfInfiniteEnhancement: 0 - PositiveResult [Line: 267]: call to reach_error is unreachable For all program executions holds that call to reach_error is unreachable at this location - StatisticsResult: Ultimate Automizer benchmark data CFG has 10 procedures, 103 locations, 1 error locations. Started 1 CEGAR loops. OverallTime: 9.7s, OverallIterations: 12, TraceHistogramMax: 3, PathProgramHistogramMax: 1, EmptinessCheckTime: 0.0s, AutomataDifference: 3.4s, DeadEndRemovalTime: 0.0s, HoareAnnotationTime: 3.8s, InitialAbstractionConstructionTime: 0.0s, PartialOrderReductionTime: 0.0s, HoareTripleCheckerStatistics: 0 mSolverCounterUnknown, 2459 SdHoareTripleChecker+Valid, 2.1s IncrementalHoareTripleChecker+Time, 0 mSdLazyCounter, 2421 mSDsluCounter, 4534 SdHoareTripleChecker+Invalid, 1.6s Time, 0 mProtectedAction, 0 SdHoareTripleChecker+Unchecked, 0 IncrementalHoareTripleChecker+Unchecked, 3066 mSDsCounter, 941 IncrementalHoareTripleChecker+Valid, 0 mProtectedPredicate, 2886 IncrementalHoareTripleChecker+Invalid, 3827 SdHoareTripleChecker+Unknown, 0 mSolverCounterNotChecked, 941 mSolverCounterUnsat, 1468 mSDtfsCounter, 2886 mSolverCounterSat, 0.1s SdHoareTripleChecker+Time, 0 IncrementalHoareTripleChecker+Unknown, PredicateUnifierStatistics: 0 DeclaredPredicates, 428 GetRequests, 292 SyntacticMatches, 2 SemanticMatches, 134 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 1237 ImplicationChecksByTransitivity, 1.0s Time, 0.0s BasicInterpolantAutomatonTime, BiggestAbstraction: size=332occurred in iteration=9, InterpolantAutomatonStates: 125, traceCheckStatistics: No data available, InterpolantConsolidationStatistics: No data available, PathInvariantsStatistics: No data available, 0/0 InterpolantCoveringCapability, TotalInterpolationStatistics: No data available, 0.0s DumpTime, AutomataMinimizationStatistics: 0.2s AutomataMinimizationTime, 12 MinimizatonAttempts, 53 StatesRemovedByMinimization, 8 NontrivialMinimizations, HoareAnnotationStatistics: 0.0s HoareAnnotationTime, 48 LocationsWithAnnotation, 1415 PreInvPairs, 1666 NumberOfFragments, 1600 HoareAnnotationTreeSize, 1415 FomulaSimplifications, 132 FormulaSimplificationTreeSizeReduction, 0.2s HoareSimplificationTime, 48 FomulaSimplificationsInter, 13045 FormulaSimplificationTreeSizeReductionInter, 3.5s HoareSimplificationTimeInter, RefinementEngineStatistics: TRACE_CHECK: 0.1s SsaConstructionTime, 0.2s SatisfiabilityAnalysisTime, 1.4s InterpolantComputationTime, 676 NumberOfCodeBlocks, 676 NumberOfCodeBlocksAsserted, 13 NumberOfCheckSat, 753 ConstructedInterpolants, 0 QuantifiedInterpolants, 1392 SizeOfPredicates, 4 NumberOfNonLiveVariables, 455 ConjunctsInSsa, 13 ConjunctsInUnsatCore, 14 InterpolantComputations, 11 PerfectInterpolantSequences, 64/84 InterpolantCoveringCapability, INVARIANT_SYNTHESIS: No data available, INTERPOLANT_CONSOLIDATION: No data available, ABSTRACT_INTERPRETATION: No data available, PDR: No data available, ACCELERATED_INTERPOLATION: No data available, SIFA: No data available, ReuseStatistics: No data available - AllSpecificationsHoldResult: All specifications hold 1 specifications checked. All of them hold - InvariantResult [Line: 325]: Loop Invariant Derived loop invariant: ((waterLevel == 1 && methaneLevelCritical == 0) && !(0 == systemActive)) && pumpRunning == 0 - InvariantResult [Line: 890]: Loop Invariant Derived loop invariant: ((0 == systemActive || !(waterLevel <= 1)) || !(\old(pumpRunning) == 1)) && (((0 == systemActive || !(waterLevel <= 2)) || !(\old(pumpRunning) == 0)) || ((((((pumpRunning == 1 && 1 <= \result) && 2 <= waterLevel) && tmp == 0) && 1 <= tmp) && 1 <= tmp___0) && \result == 0)) - InvariantResult [Line: 917]: Loop Invariant Derived loop invariant: ((0 == systemActive || !(\old(waterLevel) <= 2)) || !(\old(pumpRunning) == 1)) && (((0 == systemActive || !(\old(waterLevel) <= 2)) || !(\old(pumpRunning) == 0)) || (((((\result == 1 && methaneLevelCritical == tmp) && pumpRunning == 1) && waterLevel == \old(waterLevel)) && methaneLevelCritical == 0) && 2 <= waterLevel)) - InvariantResult [Line: 318]: Loop Invariant Derived loop invariant: ((waterLevel == 1 && methaneLevelCritical == 0) && !(0 == systemActive)) && pumpRunning == 0 - InvariantResult [Line: 128]: Loop Invariant Derived loop invariant: (((((0 == systemActive || !(\old(waterLevel) == 1)) || \result == 1) || !(\old(pumpRunning) == 0)) && ((((0 == systemActive || (((methaneLevelCritical == tmp && pumpRunning == 1) && waterLevel == \old(waterLevel)) && 2 <= waterLevel)) || !(\old(waterLevel) <= 2)) || ((((methaneLevelCritical == tmp && waterLevel <= 1) && \result <= 1) && waterLevel == \old(waterLevel)) && pumpRunning == 0)) || !(\old(pumpRunning) == 0))) && ((((0 == systemActive || (((((waterLevel <= \old(waterLevel) && methaneLevelCritical == tmp) && waterLevel <= 1) && \result <= 1) && methaneLevelCritical == 0) && pumpRunning == 0)) || (((((waterLevel <= \old(waterLevel) && methaneLevelCritical == tmp) && waterLevel <= 1) && \result <= 1) && methaneLevelCritical == 0) && pumpRunning == \old(pumpRunning))) || !(\old(waterLevel) <= 2)) || !(\old(pumpRunning) == 1))) && (((0 == systemActive || !(\old(waterLevel) <= 2)) || !(\old(pumpRunning) == 0)) || 0 == methaneLevelCritical) - InvariantResult [Line: 263]: Loop Invariant Derived loop invariant: ((0 == systemActive || !(\old(waterLevel) <= 2)) || !(\old(pumpRunning) == 1)) && ((0 == systemActive || !(\old(waterLevel) <= 2)) || !(\old(pumpRunning) == 0)) - InvariantResult [Line: 906]: Loop Invariant Derived loop invariant: (((0 == systemActive || !(\old(waterLevel) <= 2)) || ((waterLevel <= \old(waterLevel) && waterLevel <= 1) && pumpRunning == \old(pumpRunning))) || !(\old(pumpRunning) == 1)) && ((0 == systemActive || !(\old(waterLevel) <= 2)) || !(\old(pumpRunning) == 0)) - InvariantResult [Line: 173]: Loop Invariant Derived loop invariant: 1 - InvariantResult [Line: 718]: Loop Invariant Derived loop invariant: 0 - InvariantResult [Line: 163]: Loop Invariant Derived loop invariant: 1 - InvariantResult [Line: 962]: Loop Invariant Derived loop invariant: (((0 == systemActive || !(waterLevel <= 1)) || !(\old(pumpRunning) == 1)) && ((((0 == systemActive || (((\result == 0 && waterLevel <= 1) && tmp___0 == 0) && pumpRunning == 0)) || !(waterLevel <= 2)) || !(\old(pumpRunning) == 0)) || ((((1 <= \result && tmp == 0) && 1 <= tmp___0) && pumpRunning == 0) && \result == 0))) && (((0 == systemActive || !(waterLevel <= 1)) || (((\result == 0 && waterLevel <= 1) && tmp___0 == 0) && pumpRunning == 0)) || !(\old(pumpRunning) == 0)) - InvariantResult [Line: 332]: Loop Invariant Derived loop invariant: (((waterLevel == 1 && methaneLevelCritical == 0) && 1 == \result) && !(0 == systemActive)) && pumpRunning == 0 - InvariantResult [Line: 60]: Loop Invariant Derived loop invariant: (((0 == systemActive || !(\old(waterLevel) <= 2)) || ((waterLevel <= \old(waterLevel) && waterLevel <= 1) && pumpRunning == \old(pumpRunning))) || !(\old(pumpRunning) == 1)) && ((0 == systemActive || !(\old(waterLevel) <= 2)) || !(\old(pumpRunning) == 0)) - InvariantResult [Line: 981]: Loop Invariant Derived loop invariant: ((0 == systemActive || !(waterLevel <= 2)) || !(\old(pumpRunning) == 0)) && (((0 == systemActive || !(waterLevel <= 1)) || pumpRunning == \old(pumpRunning)) || !(\old(pumpRunning) == 1)) - InvariantResult [Line: 719]: Loop Invariant Derived loop invariant: (((((splverifierCounter == 0 && pumpRunning == 1) && 1 == \result) && 1 == tmp) && waterLevel <= 2) && !(0 == systemActive)) || (((((splverifierCounter == 0 && waterLevel <= 1) && 1 == \result) && 1 == tmp) && !(0 == systemActive)) && pumpRunning == 0) - InvariantResult [Line: 151]: Loop Invariant Derived loop invariant: ((0 == systemActive || !(waterLevel <= 2)) || !(\old(pumpRunning) == 0)) && (((0 == systemActive || !(waterLevel <= 1)) || pumpRunning == \old(pumpRunning)) || !(\old(pumpRunning) == 1)) - InvariantResult [Line: 865]: Loop Invariant Derived loop invariant: (((((0 == systemActive || (waterLevel == \old(waterLevel) && 2 <= waterLevel)) || !(\old(waterLevel) <= 2)) || (waterLevel == \old(waterLevel) && pumpRunning == 0)) || !(\old(pumpRunning) == 0)) && ((((0 == systemActive || !(\old(waterLevel) <= 2)) || ((waterLevel <= \old(waterLevel) && waterLevel <= 1) && pumpRunning == \old(pumpRunning))) || ((waterLevel <= \old(waterLevel) && waterLevel <= 1) && pumpRunning == 0)) || !(\old(pumpRunning) == 1))) && ((((!(2 <= \old(waterLevel)) || 0 == systemActive) || !(\old(waterLevel) <= 2)) || pumpRunning == 1) || !(\old(pumpRunning) == 0)) - InvariantResult [Line: 137]: Loop Invariant Derived loop invariant: ((0 == systemActive || !(waterLevel <= 1)) || !(\old(pumpRunning) == 1)) && ((((0 == systemActive || ((2 <= waterLevel && pumpRunning == 0) && \result == 0)) || ((waterLevel <= 1 && 1 <= \result) && pumpRunning == 0)) || !(waterLevel <= 2)) || !(\old(pumpRunning) == 0)) - InvariantResult [Line: 239]: Loop Invariant Derived loop invariant: 1 - InvariantResult [Line: 226]: Loop Invariant Derived loop invariant: 1 - InvariantResult [Line: 273]: Loop Invariant Derived loop invariant: (((((((0 == systemActive || (tmp___0 <= 1 && \result <= 1)) || !(\old(waterLevel) <= 2)) || !(\old(pumpRunning) == 0)) || ((((methaneLevelCritical == tmp && pumpRunning == 1) && waterLevel == \old(waterLevel)) && 2 <= waterLevel) && !(0 == systemActive))) || !(methaneLevelCritical == 0)) && ((((0 == systemActive || (tmp___0 <= 1 && \result <= 1)) || !(\old(waterLevel) <= 2)) || !(methaneLevelCritical == 0)) || !(\old(pumpRunning) == 1))) && ((((0 == systemActive || !(\old(waterLevel) <= 2)) || !(\old(pumpRunning) == 0)) || ((((methaneLevelCritical == tmp && pumpRunning == 1) && waterLevel == \old(waterLevel)) && 2 <= waterLevel) && !(0 == systemActive))) || (((methaneLevelCritical == tmp && waterLevel <= 1) && waterLevel == \old(waterLevel)) && pumpRunning == 0))) && ((((0 == systemActive || !(\old(waterLevel) <= 2)) || (((waterLevel <= \old(waterLevel) && methaneLevelCritical == tmp) && waterLevel <= 1) && pumpRunning == \old(pumpRunning))) || (((waterLevel <= \old(waterLevel) && methaneLevelCritical == tmp) && waterLevel <= 1) && pumpRunning == 0)) || !(\old(pumpRunning) == 1)) - InvariantResult [Line: 709]: Loop Invariant Derived loop invariant: 1 - InvariantResult [Line: 218]: Loop Invariant Derived loop invariant: ((((waterLevel == 1 && methaneLevelCritical == 0) && 1 == \result) && 1 == tmp) && !(0 == systemActive)) && pumpRunning == 0 - InvariantResult [Line: 1000]: Loop Invariant Derived loop invariant: (((((splverifierCounter == 0 && pumpRunning == 1) && 1 == \result) && 1 == tmp) && waterLevel <= 2) && !(0 == systemActive)) || (((((splverifierCounter == 0 && 1 == \result) && 1 == tmp) && waterLevel <= 2) && !(0 == systemActive)) && pumpRunning == 0) RESULT: Ultimate proved your program to be correct! [2021-12-17 15:08:39,085 INFO L540 MonitoredProcess]: [MP /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in -t:2000 (1)] Forceful destruction successful, exit code 0 Received shutdown request... --- End real Ultimate output --- Execution finished normally Writing output log to file Ultimate.log Result: TRUE