./Ultimate.py --spec ../sv-benchmarks/c/properties/unreach-call.prp --file ../sv-benchmarks/c/product-lines/minepump_spec4_product17.cil.c --full-output --architecture 32bit -------------------------------------------------------------------------------- Checking for ERROR reachability Using default analysis Version c3fed411 Calling Ultimate with: /usr/bin/java -Dosgi.configuration.area=/storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/data/config -Xmx15G -Xms4m -jar /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/plugins/org.eclipse.equinox.launcher_1.5.800.v20200727-1323.jar -data @noDefault -ultimatedata /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/data -tc /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/config/AutomizerReach.xml -i ../sv-benchmarks/c/product-lines/minepump_spec4_product17.cil.c -s /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/config/svcomp-Reach-32bit-Automizer_Default.epf --cacsl2boogietranslator.entry.function main --witnessprinter.witness.directory /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux --witnessprinter.witness.filename witness.graphml --witnessprinter.write.witness.besides.input.file false --witnessprinter.graph.data.specification CHECK( init(main()), LTL(G ! call(reach_error())) ) --witnessprinter.graph.data.producer Automizer --witnessprinter.graph.data.architecture 32bit --witnessprinter.graph.data.programhash f81a9f08305b957d008555f277c01d95103d8323a1ced34ab05d9bf457dca169 --- Real Ultimate output --- This is Ultimate 0.2.2-tmp.no-commuhash-c3fed41 [2021-12-17 15:08:45,065 INFO L177 SettingsManager]: Resetting all preferences to default values... [2021-12-17 15:08:45,066 INFO L181 SettingsManager]: Resetting UltimateCore preferences to default values [2021-12-17 15:08:45,123 INFO L184 SettingsManager]: Ultimate Commandline Interface provides no preferences, ignoring... [2021-12-17 15:08:45,124 INFO L181 SettingsManager]: Resetting Boogie Preprocessor preferences to default values [2021-12-17 15:08:45,125 INFO L181 SettingsManager]: Resetting Boogie Procedure Inliner preferences to default values [2021-12-17 15:08:45,127 INFO L181 SettingsManager]: Resetting Abstract Interpretation preferences to default values [2021-12-17 15:08:45,130 INFO L181 SettingsManager]: Resetting LassoRanker preferences to default values [2021-12-17 15:08:45,132 INFO L181 SettingsManager]: Resetting Reaching Definitions preferences to default values [2021-12-17 15:08:45,132 INFO L181 SettingsManager]: Resetting SyntaxChecker preferences to default values [2021-12-17 15:08:45,133 INFO L181 SettingsManager]: Resetting Sifa preferences to default values [2021-12-17 15:08:45,134 INFO L184 SettingsManager]: Büchi Program Product provides no preferences, ignoring... [2021-12-17 15:08:45,135 INFO L181 SettingsManager]: Resetting LTL2Aut preferences to default values [2021-12-17 15:08:45,137 INFO L181 SettingsManager]: Resetting PEA to Boogie preferences to default values [2021-12-17 15:08:45,138 INFO L181 SettingsManager]: Resetting BlockEncodingV2 preferences to default values [2021-12-17 15:08:45,140 INFO L181 SettingsManager]: Resetting ChcToBoogie preferences to default values [2021-12-17 15:08:45,141 INFO L181 SettingsManager]: Resetting AutomataScriptInterpreter preferences to default values [2021-12-17 15:08:45,145 INFO L181 SettingsManager]: Resetting BuchiAutomizer preferences to default values [2021-12-17 15:08:45,146 INFO L181 SettingsManager]: Resetting CACSL2BoogieTranslator preferences to default values [2021-12-17 15:08:45,151 INFO L181 SettingsManager]: Resetting CodeCheck preferences to default values [2021-12-17 15:08:45,151 INFO L181 SettingsManager]: Resetting InvariantSynthesis preferences to default values [2021-12-17 15:08:45,152 INFO L181 SettingsManager]: Resetting RCFGBuilder preferences to default values [2021-12-17 15:08:45,155 INFO L181 SettingsManager]: Resetting Referee preferences to default values [2021-12-17 15:08:45,155 INFO L181 SettingsManager]: Resetting TraceAbstraction preferences to default values [2021-12-17 15:08:45,157 INFO L184 SettingsManager]: TraceAbstractionConcurrent provides no preferences, ignoring... [2021-12-17 15:08:45,159 INFO L184 SettingsManager]: TraceAbstractionWithAFAs provides no preferences, ignoring... [2021-12-17 15:08:45,159 INFO L181 SettingsManager]: Resetting TreeAutomizer preferences to default values [2021-12-17 15:08:45,160 INFO L181 SettingsManager]: Resetting IcfgToChc preferences to default values [2021-12-17 15:08:45,161 INFO L181 SettingsManager]: Resetting IcfgTransformer preferences to default values [2021-12-17 15:08:45,162 INFO L184 SettingsManager]: ReqToTest provides no preferences, ignoring... [2021-12-17 15:08:45,162 INFO L181 SettingsManager]: Resetting Boogie Printer preferences to default values [2021-12-17 15:08:45,163 INFO L181 SettingsManager]: Resetting ChcSmtPrinter preferences to default values [2021-12-17 15:08:45,163 INFO L181 SettingsManager]: Resetting ReqPrinter preferences to default values [2021-12-17 15:08:45,164 INFO L181 SettingsManager]: Resetting Witness Printer preferences to default values [2021-12-17 15:08:45,165 INFO L184 SettingsManager]: Boogie PL CUP Parser provides no preferences, ignoring... [2021-12-17 15:08:45,166 INFO L181 SettingsManager]: Resetting CDTParser preferences to default values [2021-12-17 15:08:45,166 INFO L184 SettingsManager]: AutomataScriptParser provides no preferences, ignoring... [2021-12-17 15:08:45,166 INFO L184 SettingsManager]: ReqParser provides no preferences, ignoring... [2021-12-17 15:08:45,167 INFO L181 SettingsManager]: Resetting SmtParser preferences to default values [2021-12-17 15:08:45,167 INFO L181 SettingsManager]: Resetting Witness Parser preferences to default values [2021-12-17 15:08:45,168 INFO L188 SettingsManager]: Finished resetting all preferences to default values... [2021-12-17 15:08:45,168 INFO L101 SettingsManager]: Beginning loading settings from /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/config/svcomp-Reach-32bit-Automizer_Default.epf [2021-12-17 15:08:45,190 INFO L113 SettingsManager]: Loading preferences was successful [2021-12-17 15:08:45,194 INFO L115 SettingsManager]: Preferences different from defaults after loading the file: [2021-12-17 15:08:45,195 INFO L136 SettingsManager]: Preferences of UltimateCore differ from their defaults: [2021-12-17 15:08:45,195 INFO L138 SettingsManager]: * Log level for class=de.uni_freiburg.informatik.ultimate.lib.smtlibutils.quantifier.QuantifierPusher=ERROR; [2021-12-17 15:08:45,196 INFO L136 SettingsManager]: Preferences of Boogie Procedure Inliner differ from their defaults: [2021-12-17 15:08:45,196 INFO L138 SettingsManager]: * Ignore calls to procedures called more than once=ONLY_FOR_SEQUENTIAL_PROGRAMS [2021-12-17 15:08:45,196 INFO L136 SettingsManager]: Preferences of BlockEncodingV2 differ from their defaults: [2021-12-17 15:08:45,197 INFO L138 SettingsManager]: * Create parallel compositions if possible=false [2021-12-17 15:08:45,197 INFO L138 SettingsManager]: * Use SBE=true [2021-12-17 15:08:45,197 INFO L136 SettingsManager]: Preferences of CACSL2BoogieTranslator differ from their defaults: [2021-12-17 15:08:45,198 INFO L138 SettingsManager]: * sizeof long=4 [2021-12-17 15:08:45,198 INFO L138 SettingsManager]: * Overapproximate operations on floating types=true [2021-12-17 15:08:45,198 INFO L138 SettingsManager]: * sizeof POINTER=4 [2021-12-17 15:08:45,198 INFO L138 SettingsManager]: * Check division by zero=IGNORE [2021-12-17 15:08:45,198 INFO L138 SettingsManager]: * Pointer to allocated memory at dereference=IGNORE [2021-12-17 15:08:45,198 INFO L138 SettingsManager]: * If two pointers are subtracted or compared they have the same base address=IGNORE [2021-12-17 15:08:45,199 INFO L138 SettingsManager]: * Check array bounds for arrays that are off heap=IGNORE [2021-12-17 15:08:45,199 INFO L138 SettingsManager]: * sizeof long double=12 [2021-12-17 15:08:45,199 INFO L138 SettingsManager]: * Check if freed pointer was valid=false [2021-12-17 15:08:45,199 INFO L138 SettingsManager]: * Use constant arrays=true [2021-12-17 15:08:45,199 INFO L138 SettingsManager]: * Pointer base address is valid at dereference=IGNORE [2021-12-17 15:08:45,199 INFO L136 SettingsManager]: Preferences of RCFGBuilder differ from their defaults: [2021-12-17 15:08:45,199 INFO L138 SettingsManager]: * Size of a code block=SequenceOfStatements [2021-12-17 15:08:45,200 INFO L138 SettingsManager]: * SMT solver=External_DefaultMode [2021-12-17 15:08:45,200 INFO L138 SettingsManager]: * Command for external solver=z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in -t:2000 [2021-12-17 15:08:45,200 INFO L136 SettingsManager]: Preferences of TraceAbstraction differ from their defaults: [2021-12-17 15:08:45,200 INFO L138 SettingsManager]: * Compute Interpolants along a Counterexample=FPandBP [2021-12-17 15:08:45,201 INFO L138 SettingsManager]: * Positions where we compute the Hoare Annotation=LoopsAndPotentialCycles [2021-12-17 15:08:45,201 INFO L138 SettingsManager]: * Trace refinement strategy=CAMEL [2021-12-17 15:08:45,201 INFO L138 SettingsManager]: * Command for external solver=z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in [2021-12-17 15:08:45,201 INFO L138 SettingsManager]: * Large block encoding in concurrent analysis=OFF [2021-12-17 15:08:45,201 INFO L138 SettingsManager]: * Automaton type used in concurrency analysis=PETRI_NET [2021-12-17 15:08:45,202 INFO L138 SettingsManager]: * Compute Hoare Annotation of negated interpolant automaton, abstraction and CFG=true [2021-12-17 15:08:45,202 INFO L138 SettingsManager]: * Trace refinement exception blacklist=NONE [2021-12-17 15:08:45,202 INFO L138 SettingsManager]: * SMT solver=External_ModelsAndUnsatCoreMode WARNING: An illegal reflective access operation has occurred WARNING: Illegal reflective access by com.sun.xml.bind.v2.runtime.reflect.opt.Injector$1 (file:/storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/plugins/com.sun.xml.bind_2.2.0.v201505121915.jar) to method java.lang.ClassLoader.defineClass(java.lang.String,byte[],int,int) WARNING: Please consider reporting this to the maintainers of com.sun.xml.bind.v2.runtime.reflect.opt.Injector$1 WARNING: Use --illegal-access=warn to enable warnings of further illegal reflective access operations WARNING: All illegal access operations will be denied in a future release Applying setting for plugin de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator: Entry function -> main Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Witness directory -> /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Witness filename -> witness.graphml Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Write witness besides input file -> false Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Graph data specification -> CHECK( init(main()), LTL(G ! call(reach_error())) ) Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Graph data producer -> Automizer Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Graph data architecture -> 32bit Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Graph data programhash -> f81a9f08305b957d008555f277c01d95103d8323a1ced34ab05d9bf457dca169 [2021-12-17 15:08:45,424 INFO L75 nceAwareModelManager]: Repository-Root is: /tmp [2021-12-17 15:08:45,440 INFO L261 ainManager$Toolchain]: [Toolchain 1]: Applicable parser(s) successfully (re)initialized [2021-12-17 15:08:45,442 INFO L217 ainManager$Toolchain]: [Toolchain 1]: Toolchain selected. [2021-12-17 15:08:45,443 INFO L271 PluginConnector]: Initializing CDTParser... [2021-12-17 15:08:45,443 INFO L275 PluginConnector]: CDTParser initialized [2021-12-17 15:08:45,444 INFO L432 ainManager$Toolchain]: [Toolchain 1]: Parsing single file: /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/../sv-benchmarks/c/product-lines/minepump_spec4_product17.cil.c [2021-12-17 15:08:45,498 INFO L220 CDTParser]: Created temporary CDT project at /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/data/178a74da2/dd74e287000c413cbbcd279beec9c24c/FLAG6f8ead632 [2021-12-17 15:08:45,856 INFO L306 CDTParser]: Found 1 translation units. [2021-12-17 15:08:45,857 INFO L160 CDTParser]: Scanning /storage/repos/ultimate/releaseScripts/default/sv-benchmarks/c/product-lines/minepump_spec4_product17.cil.c [2021-12-17 15:08:45,874 INFO L349 CDTParser]: About to delete temporary CDT project at /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/data/178a74da2/dd74e287000c413cbbcd279beec9c24c/FLAG6f8ead632 [2021-12-17 15:08:46,254 INFO L357 CDTParser]: Successfully deleted /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/data/178a74da2/dd74e287000c413cbbcd279beec9c24c [2021-12-17 15:08:46,256 INFO L299 ainManager$Toolchain]: ####################### [Toolchain 1] ####################### [2021-12-17 15:08:46,257 INFO L131 ToolchainWalker]: Walking toolchain with 6 elements. [2021-12-17 15:08:46,258 INFO L113 PluginConnector]: ------------------------CACSL2BoogieTranslator---------------------------- [2021-12-17 15:08:46,258 INFO L271 PluginConnector]: Initializing CACSL2BoogieTranslator... [2021-12-17 15:08:46,265 INFO L275 PluginConnector]: CACSL2BoogieTranslator initialized [2021-12-17 15:08:46,265 INFO L185 PluginConnector]: Executing the observer ACSLObjectContainerObserver from plugin CACSL2BoogieTranslator for "CDTParser AST 17.12 03:08:46" (1/1) ... [2021-12-17 15:08:46,266 INFO L205 PluginConnector]: Invalid model from CACSL2BoogieTranslator for observer de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator.ACSLObjectContainerObserver@2177546f and model type de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 17.12 03:08:46, skipping insertion in model container [2021-12-17 15:08:46,269 INFO L185 PluginConnector]: Executing the observer CACSL2BoogieTranslatorObserver from plugin CACSL2BoogieTranslator for "CDTParser AST 17.12 03:08:46" (1/1) ... [2021-12-17 15:08:46,274 INFO L145 MainTranslator]: Starting translation in SV-COMP mode [2021-12-17 15:08:46,315 INFO L178 MainTranslator]: Built tables and reachable declarations [2021-12-17 15:08:46,446 WARN L230 ndardFunctionHandler]: Function reach_error is already implemented but we override the implementation for the call at /storage/repos/ultimate/releaseScripts/default/sv-benchmarks/c/product-lines/minepump_spec4_product17.cil.c[3323,3336] [2021-12-17 15:08:46,492 INFO L209 PostProcessor]: Analyzing one entry point: main [2021-12-17 15:08:46,498 INFO L203 MainTranslator]: Completed pre-run [2021-12-17 15:08:46,511 WARN L230 ndardFunctionHandler]: Function reach_error is already implemented but we override the implementation for the call at /storage/repos/ultimate/releaseScripts/default/sv-benchmarks/c/product-lines/minepump_spec4_product17.cil.c[3323,3336] [2021-12-17 15:08:46,561 INFO L209 PostProcessor]: Analyzing one entry point: main [2021-12-17 15:08:46,580 INFO L208 MainTranslator]: Completed translation [2021-12-17 15:08:46,581 INFO L202 PluginConnector]: Adding new model de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 17.12 03:08:46 WrapperNode [2021-12-17 15:08:46,581 INFO L132 PluginConnector]: ------------------------ END CACSL2BoogieTranslator---------------------------- [2021-12-17 15:08:46,583 INFO L113 PluginConnector]: ------------------------Boogie Procedure Inliner---------------------------- [2021-12-17 15:08:46,583 INFO L271 PluginConnector]: Initializing Boogie Procedure Inliner... [2021-12-17 15:08:46,583 INFO L275 PluginConnector]: Boogie Procedure Inliner initialized [2021-12-17 15:08:46,588 INFO L185 PluginConnector]: Executing the observer TypeChecker from plugin Boogie Procedure Inliner for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 17.12 03:08:46" (1/1) ... [2021-12-17 15:08:46,614 INFO L185 PluginConnector]: Executing the observer Inliner from plugin Boogie Procedure Inliner for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 17.12 03:08:46" (1/1) ... [2021-12-17 15:08:46,633 INFO L137 Inliner]: procedures = 52, calls = 149, calls flagged for inlining = 21, calls inlined = 17, statements flattened = 219 [2021-12-17 15:08:46,636 INFO L132 PluginConnector]: ------------------------ END Boogie Procedure Inliner---------------------------- [2021-12-17 15:08:46,636 INFO L113 PluginConnector]: ------------------------Boogie Preprocessor---------------------------- [2021-12-17 15:08:46,636 INFO L271 PluginConnector]: Initializing Boogie Preprocessor... [2021-12-17 15:08:46,637 INFO L275 PluginConnector]: Boogie Preprocessor initialized [2021-12-17 15:08:46,642 INFO L185 PluginConnector]: Executing the observer EnsureBoogieModelObserver from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 17.12 03:08:46" (1/1) ... [2021-12-17 15:08:46,642 INFO L185 PluginConnector]: Executing the observer TypeChecker from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 17.12 03:08:46" (1/1) ... [2021-12-17 15:08:46,646 INFO L185 PluginConnector]: Executing the observer ConstExpander from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 17.12 03:08:46" (1/1) ... [2021-12-17 15:08:46,648 INFO L185 PluginConnector]: Executing the observer StructExpander from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 17.12 03:08:46" (1/1) ... [2021-12-17 15:08:46,652 INFO L185 PluginConnector]: Executing the observer UnstructureCode from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 17.12 03:08:46" (1/1) ... [2021-12-17 15:08:46,660 INFO L185 PluginConnector]: Executing the observer FunctionInliner from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 17.12 03:08:46" (1/1) ... [2021-12-17 15:08:46,663 INFO L185 PluginConnector]: Executing the observer BoogieSymbolTableConstructor from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 17.12 03:08:46" (1/1) ... [2021-12-17 15:08:46,665 INFO L132 PluginConnector]: ------------------------ END Boogie Preprocessor---------------------------- [2021-12-17 15:08:46,666 INFO L113 PluginConnector]: ------------------------RCFGBuilder---------------------------- [2021-12-17 15:08:46,679 INFO L271 PluginConnector]: Initializing RCFGBuilder... [2021-12-17 15:08:46,679 INFO L275 PluginConnector]: RCFGBuilder initialized [2021-12-17 15:08:46,680 INFO L185 PluginConnector]: Executing the observer RCFGBuilderObserver from plugin RCFGBuilder for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 17.12 03:08:46" (1/1) ... [2021-12-17 15:08:46,685 INFO L168 SolverBuilder]: Constructing external solver with command: z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in -t:2000 [2021-12-17 15:08:46,694 INFO L189 MonitoredProcess]: No working directory specified, using /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 [2021-12-17 15:08:46,724 INFO L229 MonitoredProcess]: Starting monitored process 1 with /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in -t:2000 (exit command is (exit), workingDir is null) [2021-12-17 15:08:46,729 INFO L327 MonitoredProcess]: [MP /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in -t:2000 (1)] Waiting until timeout for monitored process [2021-12-17 15:08:46,749 INFO L130 BoogieDeclarations]: Found specification of procedure #Ultimate.allocInit [2021-12-17 15:08:46,750 INFO L130 BoogieDeclarations]: Found specification of procedure processEnvironment__wrappee__base [2021-12-17 15:08:46,750 INFO L138 BoogieDeclarations]: Found implementation of procedure processEnvironment__wrappee__base [2021-12-17 15:08:46,750 INFO L130 BoogieDeclarations]: Found specification of procedure timeShift [2021-12-17 15:08:46,750 INFO L138 BoogieDeclarations]: Found implementation of procedure timeShift [2021-12-17 15:08:46,750 INFO L130 BoogieDeclarations]: Found specification of procedure cleanup [2021-12-17 15:08:46,750 INFO L138 BoogieDeclarations]: Found implementation of procedure cleanup [2021-12-17 15:08:46,750 INFO L130 BoogieDeclarations]: Found specification of procedure waterRise [2021-12-17 15:08:46,751 INFO L138 BoogieDeclarations]: Found implementation of procedure waterRise [2021-12-17 15:08:46,751 INFO L130 BoogieDeclarations]: Found specification of procedure write~init~int [2021-12-17 15:08:46,751 INFO L130 BoogieDeclarations]: Found specification of procedure changeMethaneLevel [2021-12-17 15:08:46,751 INFO L138 BoogieDeclarations]: Found implementation of procedure changeMethaneLevel [2021-12-17 15:08:46,751 INFO L130 BoogieDeclarations]: Found specification of procedure ULTIMATE.start [2021-12-17 15:08:46,751 INFO L138 BoogieDeclarations]: Found implementation of procedure ULTIMATE.start [2021-12-17 15:08:46,814 INFO L236 CfgBuilder]: Building ICFG [2021-12-17 15:08:46,815 INFO L262 CfgBuilder]: Building CFG for each procedure with an implementation [2021-12-17 15:08:46,999 INFO L277 CfgBuilder]: Performing block encoding [2021-12-17 15:08:47,003 INFO L296 CfgBuilder]: Using the 1 location(s) as analysis (start of procedure ULTIMATE.start) [2021-12-17 15:08:47,004 INFO L301 CfgBuilder]: Removed 2 assume(true) statements. [2021-12-17 15:08:47,005 INFO L202 PluginConnector]: Adding new model de.uni_freiburg.informatik.ultimate.plugins.generator.rcfgbuilder CFG 17.12 03:08:47 BoogieIcfgContainer [2021-12-17 15:08:47,005 INFO L132 PluginConnector]: ------------------------ END RCFGBuilder---------------------------- [2021-12-17 15:08:47,006 INFO L113 PluginConnector]: ------------------------TraceAbstraction---------------------------- [2021-12-17 15:08:47,006 INFO L271 PluginConnector]: Initializing TraceAbstraction... [2021-12-17 15:08:47,009 INFO L275 PluginConnector]: TraceAbstraction initialized [2021-12-17 15:08:47,009 INFO L185 PluginConnector]: Executing the observer TraceAbstractionObserver from plugin TraceAbstraction for "CDTParser AST 17.12 03:08:46" (1/3) ... [2021-12-17 15:08:47,009 INFO L205 PluginConnector]: Invalid model from TraceAbstraction for observer de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction.TraceAbstractionObserver@64507cdf and model type de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction AST 17.12 03:08:47, skipping insertion in model container [2021-12-17 15:08:47,010 INFO L185 PluginConnector]: Executing the observer TraceAbstractionObserver from plugin TraceAbstraction for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 17.12 03:08:46" (2/3) ... [2021-12-17 15:08:47,010 INFO L205 PluginConnector]: Invalid model from TraceAbstraction for observer de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction.TraceAbstractionObserver@64507cdf and model type de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction AST 17.12 03:08:47, skipping insertion in model container [2021-12-17 15:08:47,010 INFO L185 PluginConnector]: Executing the observer TraceAbstractionObserver from plugin TraceAbstraction for "de.uni_freiburg.informatik.ultimate.plugins.generator.rcfgbuilder CFG 17.12 03:08:47" (3/3) ... [2021-12-17 15:08:47,011 INFO L111 eAbstractionObserver]: Analyzing ICFG minepump_spec4_product17.cil.c [2021-12-17 15:08:47,014 INFO L204 ceAbstractionStarter]: Automizer settings: Hoare:true NWA Interpolation:FPandBP Determinization: PREDICATE_ABSTRACTION [2021-12-17 15:08:47,014 INFO L163 ceAbstractionStarter]: Applying trace abstraction to program that has 1 error locations. [2021-12-17 15:08:47,044 INFO L338 AbstractCegarLoop]: ======== Iteration 0 == of CEGAR loop == AllErrorsAtOnce ======== [2021-12-17 15:08:47,049 INFO L339 AbstractCegarLoop]: Settings: SEPARATE_VIOLATION_CHECK=true, mInterprocedural=true, mMaxIterations=1000000, mWatchIteration=1000000, mArtifact=RCFG, mInterpolation=FPandBP, mInterpolantAutomaton=STRAIGHT_LINE, mDumpAutomata=false, mAutomataFormat=ATS_NUMERATE, mDumpPath=., mDeterminiation=PREDICATE_ABSTRACTION, mMinimize=MINIMIZE_SEVPA, mHoare=true, mAutomataTypeConcurrency=PETRI_NET, mHoareTripleChecks=INCREMENTAL, mHoareAnnotationPositions=LoopsAndPotentialCycles, mDumpOnlyReuseAutomata=false, mLimitTraceHistogram=0, mErrorLocTimeLimit=0, mLimitPathProgramCount=0, mCollectInterpolantStatistics=true, mHeuristicEmptinessCheck=false, mHeuristicEmptinessCheckAStarHeuristic=ZERO, mHeuristicEmptinessCheckAStarHeuristicRandomSeed=1337, mHeuristicEmptinessCheckSmtFeatureScoringMethod=DAGSIZE, mSMTFeatureExtraction=false, mSMTFeatureExtractionDumpPath=., mOverrideInterpolantAutomaton=false, mMcrInterpolantMethod=WP, mLoopAccelerationTechnique=FAST_UPR [2021-12-17 15:08:47,049 INFO L340 AbstractCegarLoop]: Starting to check reachability of 1 error locations. [2021-12-17 15:08:47,062 INFO L276 IsEmpty]: Start isEmpty. Operand has 69 states, 54 states have (on average 1.4074074074074074) internal successors, (76), 60 states have internal predecessors, (76), 8 states have call successors, (8), 5 states have call predecessors, (8), 5 states have return successors, (8), 7 states have call predecessors, (8), 8 states have call successors, (8) [2021-12-17 15:08:47,066 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 20 [2021-12-17 15:08:47,066 INFO L506 BasicCegarLoop]: Found error trace [2021-12-17 15:08:47,067 INFO L514 BasicCegarLoop]: trace histogram [1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2021-12-17 15:08:47,067 INFO L402 AbstractCegarLoop]: === Iteration 1 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2021-12-17 15:08:47,071 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2021-12-17 15:08:47,071 INFO L85 PathProgramCache]: Analyzing trace with hash 568623252, now seen corresponding path program 1 times [2021-12-17 15:08:47,096 INFO L121 FreeRefinementEngine]: Executing refinement strategy CAMEL [2021-12-17 15:08:47,096 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [195372432] [2021-12-17 15:08:47,097 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2021-12-17 15:08:47,097 INFO L126 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2021-12-17 15:08:47,224 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:08:47,295 INFO L134 CoverageAnalysis]: Checked inductivity of 0 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2021-12-17 15:08:47,296 INFO L139 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2021-12-17 15:08:47,296 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [195372432] [2021-12-17 15:08:47,297 INFO L160 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [195372432] provided 1 perfect and 0 imperfect interpolant sequences [2021-12-17 15:08:47,298 INFO L186 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2021-12-17 15:08:47,298 INFO L199 FreeRefinementEngine]: Number of different interpolants: perfect sequences [2] imperfect sequences [] total 2 [2021-12-17 15:08:47,299 INFO L115 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [1758549375] [2021-12-17 15:08:47,300 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2021-12-17 15:08:47,304 INFO L546 AbstractCegarLoop]: INTERPOLANT automaton has 2 states [2021-12-17 15:08:47,305 INFO L103 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2021-12-17 15:08:47,330 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 2 interpolants. [2021-12-17 15:08:47,332 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=1, Invalid=1, Unknown=0, NotChecked=0, Total=2 [2021-12-17 15:08:47,334 INFO L87 Difference]: Start difference. First operand has 69 states, 54 states have (on average 1.4074074074074074) internal successors, (76), 60 states have internal predecessors, (76), 8 states have call successors, (8), 5 states have call predecessors, (8), 5 states have return successors, (8), 7 states have call predecessors, (8), 8 states have call successors, (8) Second operand has 2 states, 2 states have (on average 8.5) internal successors, (17), 2 states have internal predecessors, (17), 1 states have call successors, (2), 1 states have call predecessors, (2), 0 states have return successors, (0), 0 states have call predecessors, (0), 0 states have call successors, (0) [2021-12-17 15:08:47,366 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2021-12-17 15:08:47,366 INFO L93 Difference]: Finished difference Result 130 states and 179 transitions. [2021-12-17 15:08:47,367 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 2 states. [2021-12-17 15:08:47,368 INFO L78 Accepts]: Start accepts. Automaton has has 2 states, 2 states have (on average 8.5) internal successors, (17), 2 states have internal predecessors, (17), 1 states have call successors, (2), 1 states have call predecessors, (2), 0 states have return successors, (0), 0 states have call predecessors, (0), 0 states have call successors, (0) Word has length 19 [2021-12-17 15:08:47,369 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2021-12-17 15:08:47,380 INFO L225 Difference]: With dead ends: 130 [2021-12-17 15:08:47,380 INFO L226 Difference]: Without dead ends: 60 [2021-12-17 15:08:47,384 INFO L932 BasicCegarLoop]: 0 DeclaredPredicates, 2 GetRequests, 2 SyntacticMatches, 0 SemanticMatches, 0 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 0 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=1, Invalid=1, Unknown=0, NotChecked=0, Total=2 [2021-12-17 15:08:47,389 INFO L933 BasicCegarLoop]: 86 mSDtfsCounter, 0 mSDsluCounter, 0 mSDsCounter, 0 mSdLazyCounter, 0 mSolverCounterSat, 0 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.0s Time, 0 mProtectedPredicate, 0 mProtectedAction, 0 SdHoareTripleChecker+Valid, 86 SdHoareTripleChecker+Invalid, 0 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 0 IncrementalHoareTripleChecker+Valid, 0 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.0s IncrementalHoareTripleChecker+Time [2021-12-17 15:08:47,390 INFO L934 BasicCegarLoop]: SdHoareTripleChecker [0 Valid, 86 Invalid, 0 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [0 Valid, 0 Invalid, 0 Unknown, 0 Unchecked, 0.0s Time] [2021-12-17 15:08:47,401 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 60 states. [2021-12-17 15:08:47,427 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 60 to 60. [2021-12-17 15:08:47,428 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 60 states, 47 states have (on average 1.3191489361702127) internal successors, (62), 52 states have internal predecessors, (62), 8 states have call successors, (8), 5 states have call predecessors, (8), 4 states have return successors, (7), 6 states have call predecessors, (7), 7 states have call successors, (7) [2021-12-17 15:08:47,429 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 60 states to 60 states and 77 transitions. [2021-12-17 15:08:47,430 INFO L78 Accepts]: Start accepts. Automaton has 60 states and 77 transitions. Word has length 19 [2021-12-17 15:08:47,430 INFO L84 Accepts]: Finished accepts. word is rejected. [2021-12-17 15:08:47,430 INFO L470 AbstractCegarLoop]: Abstraction has 60 states and 77 transitions. [2021-12-17 15:08:47,430 INFO L471 AbstractCegarLoop]: INTERPOLANT automaton has has 2 states, 2 states have (on average 8.5) internal successors, (17), 2 states have internal predecessors, (17), 1 states have call successors, (2), 1 states have call predecessors, (2), 0 states have return successors, (0), 0 states have call predecessors, (0), 0 states have call successors, (0) [2021-12-17 15:08:47,431 INFO L276 IsEmpty]: Start isEmpty. Operand 60 states and 77 transitions. [2021-12-17 15:08:47,435 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 21 [2021-12-17 15:08:47,436 INFO L506 BasicCegarLoop]: Found error trace [2021-12-17 15:08:47,436 INFO L514 BasicCegarLoop]: trace histogram [1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2021-12-17 15:08:47,437 WARN L452 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable0 [2021-12-17 15:08:47,437 INFO L402 AbstractCegarLoop]: === Iteration 2 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2021-12-17 15:08:47,441 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2021-12-17 15:08:47,441 INFO L85 PathProgramCache]: Analyzing trace with hash -108509492, now seen corresponding path program 1 times [2021-12-17 15:08:47,441 INFO L121 FreeRefinementEngine]: Executing refinement strategy CAMEL [2021-12-17 15:08:47,441 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [24930037] [2021-12-17 15:08:47,441 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2021-12-17 15:08:47,442 INFO L126 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2021-12-17 15:08:47,469 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:08:47,522 INFO L134 CoverageAnalysis]: Checked inductivity of 0 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2021-12-17 15:08:47,522 INFO L139 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2021-12-17 15:08:47,523 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [24930037] [2021-12-17 15:08:47,523 INFO L160 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [24930037] provided 1 perfect and 0 imperfect interpolant sequences [2021-12-17 15:08:47,523 INFO L186 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2021-12-17 15:08:47,523 INFO L199 FreeRefinementEngine]: Number of different interpolants: perfect sequences [3] imperfect sequences [] total 3 [2021-12-17 15:08:47,524 INFO L115 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [1624654449] [2021-12-17 15:08:47,524 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2021-12-17 15:08:47,525 INFO L546 AbstractCegarLoop]: INTERPOLANT automaton has 3 states [2021-12-17 15:08:47,525 INFO L103 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2021-12-17 15:08:47,526 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 3 interpolants. [2021-12-17 15:08:47,526 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=3, Invalid=3, Unknown=0, NotChecked=0, Total=6 [2021-12-17 15:08:47,527 INFO L87 Difference]: Start difference. First operand 60 states and 77 transitions. Second operand has 3 states, 3 states have (on average 6.0) internal successors, (18), 3 states have internal predecessors, (18), 1 states have call successors, (2), 1 states have call predecessors, (2), 0 states have return successors, (0), 0 states have call predecessors, (0), 0 states have call successors, (0) [2021-12-17 15:08:47,539 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2021-12-17 15:08:47,539 INFO L93 Difference]: Finished difference Result 86 states and 110 transitions. [2021-12-17 15:08:47,540 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 3 states. [2021-12-17 15:08:47,540 INFO L78 Accepts]: Start accepts. Automaton has has 3 states, 3 states have (on average 6.0) internal successors, (18), 3 states have internal predecessors, (18), 1 states have call successors, (2), 1 states have call predecessors, (2), 0 states have return successors, (0), 0 states have call predecessors, (0), 0 states have call successors, (0) Word has length 20 [2021-12-17 15:08:47,540 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2021-12-17 15:08:47,542 INFO L225 Difference]: With dead ends: 86 [2021-12-17 15:08:47,542 INFO L226 Difference]: Without dead ends: 51 [2021-12-17 15:08:47,543 INFO L932 BasicCegarLoop]: 0 DeclaredPredicates, 3 GetRequests, 2 SyntacticMatches, 0 SemanticMatches, 1 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 0 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=3, Invalid=3, Unknown=0, NotChecked=0, Total=6 [2021-12-17 15:08:47,545 INFO L933 BasicCegarLoop]: 64 mSDtfsCounter, 12 mSDsluCounter, 48 mSDsCounter, 0 mSdLazyCounter, 1 mSolverCounterSat, 0 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.0s Time, 0 mProtectedPredicate, 0 mProtectedAction, 15 SdHoareTripleChecker+Valid, 112 SdHoareTripleChecker+Invalid, 1 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 0 IncrementalHoareTripleChecker+Valid, 1 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.0s IncrementalHoareTripleChecker+Time [2021-12-17 15:08:47,546 INFO L934 BasicCegarLoop]: SdHoareTripleChecker [15 Valid, 112 Invalid, 1 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [0 Valid, 1 Invalid, 0 Unknown, 0 Unchecked, 0.0s Time] [2021-12-17 15:08:47,547 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 51 states. [2021-12-17 15:08:47,552 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 51 to 51. [2021-12-17 15:08:47,554 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 51 states, 41 states have (on average 1.3414634146341464) internal successors, (55), 46 states have internal predecessors, (55), 5 states have call successors, (5), 4 states have call predecessors, (5), 4 states have return successors, (5), 4 states have call predecessors, (5), 5 states have call successors, (5) [2021-12-17 15:08:47,556 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 51 states to 51 states and 65 transitions. [2021-12-17 15:08:47,557 INFO L78 Accepts]: Start accepts. Automaton has 51 states and 65 transitions. Word has length 20 [2021-12-17 15:08:47,557 INFO L84 Accepts]: Finished accepts. word is rejected. [2021-12-17 15:08:47,558 INFO L470 AbstractCegarLoop]: Abstraction has 51 states and 65 transitions. [2021-12-17 15:08:47,559 INFO L471 AbstractCegarLoop]: INTERPOLANT automaton has has 3 states, 3 states have (on average 6.0) internal successors, (18), 3 states have internal predecessors, (18), 1 states have call successors, (2), 1 states have call predecessors, (2), 0 states have return successors, (0), 0 states have call predecessors, (0), 0 states have call successors, (0) [2021-12-17 15:08:47,559 INFO L276 IsEmpty]: Start isEmpty. Operand 51 states and 65 transitions. [2021-12-17 15:08:47,560 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 25 [2021-12-17 15:08:47,560 INFO L506 BasicCegarLoop]: Found error trace [2021-12-17 15:08:47,563 INFO L514 BasicCegarLoop]: trace histogram [1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2021-12-17 15:08:47,563 WARN L452 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable1 [2021-12-17 15:08:47,564 INFO L402 AbstractCegarLoop]: === Iteration 3 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2021-12-17 15:08:47,564 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2021-12-17 15:08:47,565 INFO L85 PathProgramCache]: Analyzing trace with hash 1864722990, now seen corresponding path program 1 times [2021-12-17 15:08:47,565 INFO L121 FreeRefinementEngine]: Executing refinement strategy CAMEL [2021-12-17 15:08:47,565 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [21473974] [2021-12-17 15:08:47,565 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2021-12-17 15:08:47,565 INFO L126 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2021-12-17 15:08:47,577 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:08:47,646 INFO L134 CoverageAnalysis]: Checked inductivity of 0 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2021-12-17 15:08:47,646 INFO L139 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2021-12-17 15:08:47,646 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [21473974] [2021-12-17 15:08:47,646 INFO L160 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [21473974] provided 1 perfect and 0 imperfect interpolant sequences [2021-12-17 15:08:47,647 INFO L186 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2021-12-17 15:08:47,647 INFO L199 FreeRefinementEngine]: Number of different interpolants: perfect sequences [5] imperfect sequences [] total 5 [2021-12-17 15:08:47,647 INFO L115 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [1973399957] [2021-12-17 15:08:47,647 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2021-12-17 15:08:47,647 INFO L546 AbstractCegarLoop]: INTERPOLANT automaton has 6 states [2021-12-17 15:08:47,647 INFO L103 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2021-12-17 15:08:47,648 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 6 interpolants. [2021-12-17 15:08:47,648 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=10, Invalid=20, Unknown=0, NotChecked=0, Total=30 [2021-12-17 15:08:47,648 INFO L87 Difference]: Start difference. First operand 51 states and 65 transitions. Second operand has 6 states, 6 states have (on average 3.8333333333333335) internal successors, (23), 5 states have internal predecessors, (23), 1 states have call successors, (1), 1 states have call predecessors, (1), 0 states have return successors, (0), 0 states have call predecessors, (0), 0 states have call successors, (0) [2021-12-17 15:08:47,707 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2021-12-17 15:08:47,708 INFO L93 Difference]: Finished difference Result 95 states and 124 transitions. [2021-12-17 15:08:47,708 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 5 states. [2021-12-17 15:08:47,708 INFO L78 Accepts]: Start accepts. Automaton has has 6 states, 6 states have (on average 3.8333333333333335) internal successors, (23), 5 states have internal predecessors, (23), 1 states have call successors, (1), 1 states have call predecessors, (1), 0 states have return successors, (0), 0 states have call predecessors, (0), 0 states have call successors, (0) Word has length 24 [2021-12-17 15:08:47,709 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2021-12-17 15:08:47,709 INFO L225 Difference]: With dead ends: 95 [2021-12-17 15:08:47,712 INFO L226 Difference]: Without dead ends: 51 [2021-12-17 15:08:47,712 INFO L932 BasicCegarLoop]: 0 DeclaredPredicates, 7 GetRequests, 1 SyntacticMatches, 0 SemanticMatches, 6 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 0 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=22, Invalid=34, Unknown=0, NotChecked=0, Total=56 [2021-12-17 15:08:47,713 INFO L933 BasicCegarLoop]: 58 mSDtfsCounter, 91 mSDsluCounter, 70 mSDsCounter, 0 mSdLazyCounter, 25 mSolverCounterSat, 10 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.0s Time, 0 mProtectedPredicate, 0 mProtectedAction, 91 SdHoareTripleChecker+Valid, 128 SdHoareTripleChecker+Invalid, 35 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 10 IncrementalHoareTripleChecker+Valid, 25 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.0s IncrementalHoareTripleChecker+Time [2021-12-17 15:08:47,713 INFO L934 BasicCegarLoop]: SdHoareTripleChecker [91 Valid, 128 Invalid, 35 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [10 Valid, 25 Invalid, 0 Unknown, 0 Unchecked, 0.0s Time] [2021-12-17 15:08:47,714 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 51 states. [2021-12-17 15:08:47,720 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 51 to 51. [2021-12-17 15:08:47,722 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 51 states, 41 states have (on average 1.3170731707317074) internal successors, (54), 46 states have internal predecessors, (54), 5 states have call successors, (5), 4 states have call predecessors, (5), 4 states have return successors, (5), 4 states have call predecessors, (5), 5 states have call successors, (5) [2021-12-17 15:08:47,723 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 51 states to 51 states and 64 transitions. [2021-12-17 15:08:47,724 INFO L78 Accepts]: Start accepts. Automaton has 51 states and 64 transitions. Word has length 24 [2021-12-17 15:08:47,724 INFO L84 Accepts]: Finished accepts. word is rejected. [2021-12-17 15:08:47,724 INFO L470 AbstractCegarLoop]: Abstraction has 51 states and 64 transitions. [2021-12-17 15:08:47,724 INFO L471 AbstractCegarLoop]: INTERPOLANT automaton has has 6 states, 6 states have (on average 3.8333333333333335) internal successors, (23), 5 states have internal predecessors, (23), 1 states have call successors, (1), 1 states have call predecessors, (1), 0 states have return successors, (0), 0 states have call predecessors, (0), 0 states have call successors, (0) [2021-12-17 15:08:47,724 INFO L276 IsEmpty]: Start isEmpty. Operand 51 states and 64 transitions. [2021-12-17 15:08:47,725 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 30 [2021-12-17 15:08:47,725 INFO L506 BasicCegarLoop]: Found error trace [2021-12-17 15:08:47,725 INFO L514 BasicCegarLoop]: trace histogram [1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2021-12-17 15:08:47,725 WARN L452 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable2 [2021-12-17 15:08:47,725 INFO L402 AbstractCegarLoop]: === Iteration 4 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2021-12-17 15:08:47,726 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2021-12-17 15:08:47,726 INFO L85 PathProgramCache]: Analyzing trace with hash -491768668, now seen corresponding path program 1 times [2021-12-17 15:08:47,726 INFO L121 FreeRefinementEngine]: Executing refinement strategy CAMEL [2021-12-17 15:08:47,726 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [57461327] [2021-12-17 15:08:47,726 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2021-12-17 15:08:47,727 INFO L126 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2021-12-17 15:08:47,736 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:08:47,792 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 19 [2021-12-17 15:08:47,798 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:08:47,802 INFO L134 CoverageAnalysis]: Checked inductivity of 0 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2021-12-17 15:08:47,802 INFO L139 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2021-12-17 15:08:47,802 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [57461327] [2021-12-17 15:08:47,802 INFO L160 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [57461327] provided 1 perfect and 0 imperfect interpolant sequences [2021-12-17 15:08:47,802 INFO L186 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2021-12-17 15:08:47,803 INFO L199 FreeRefinementEngine]: Number of different interpolants: perfect sequences [8] imperfect sequences [] total 8 [2021-12-17 15:08:47,803 INFO L115 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [2042150583] [2021-12-17 15:08:47,803 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2021-12-17 15:08:47,803 INFO L546 AbstractCegarLoop]: INTERPOLANT automaton has 8 states [2021-12-17 15:08:47,804 INFO L103 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2021-12-17 15:08:47,804 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 8 interpolants. [2021-12-17 15:08:47,804 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=14, Invalid=42, Unknown=0, NotChecked=0, Total=56 [2021-12-17 15:08:47,804 INFO L87 Difference]: Start difference. First operand 51 states and 64 transitions. Second operand has 8 states, 8 states have (on average 3.25) internal successors, (26), 8 states have internal predecessors, (26), 1 states have call successors, (2), 2 states have call predecessors, (2), 1 states have return successors, (1), 1 states have call predecessors, (1), 1 states have call successors, (1) [2021-12-17 15:08:47,997 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2021-12-17 15:08:47,998 INFO L93 Difference]: Finished difference Result 175 states and 237 transitions. [2021-12-17 15:08:47,998 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 11 states. [2021-12-17 15:08:47,998 INFO L78 Accepts]: Start accepts. Automaton has has 8 states, 8 states have (on average 3.25) internal successors, (26), 8 states have internal predecessors, (26), 1 states have call successors, (2), 2 states have call predecessors, (2), 1 states have return successors, (1), 1 states have call predecessors, (1), 1 states have call successors, (1) Word has length 29 [2021-12-17 15:08:47,998 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2021-12-17 15:08:47,999 INFO L225 Difference]: With dead ends: 175 [2021-12-17 15:08:48,000 INFO L226 Difference]: Without dead ends: 131 [2021-12-17 15:08:48,000 INFO L932 BasicCegarLoop]: 0 DeclaredPredicates, 16 GetRequests, 4 SyntacticMatches, 0 SemanticMatches, 12 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 15 ImplicationChecksByTransitivity, 0.1s TimeCoverageRelationStatistics Valid=51, Invalid=131, Unknown=0, NotChecked=0, Total=182 [2021-12-17 15:08:48,001 INFO L933 BasicCegarLoop]: 66 mSDtfsCounter, 153 mSDsluCounter, 324 mSDsCounter, 0 mSdLazyCounter, 109 mSolverCounterSat, 22 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.1s Time, 0 mProtectedPredicate, 0 mProtectedAction, 153 SdHoareTripleChecker+Valid, 390 SdHoareTripleChecker+Invalid, 131 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 22 IncrementalHoareTripleChecker+Valid, 109 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.1s IncrementalHoareTripleChecker+Time [2021-12-17 15:08:48,001 INFO L934 BasicCegarLoop]: SdHoareTripleChecker [153 Valid, 390 Invalid, 131 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [22 Valid, 109 Invalid, 0 Unknown, 0 Unchecked, 0.1s Time] [2021-12-17 15:08:48,002 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 131 states. [2021-12-17 15:08:48,021 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 131 to 126. [2021-12-17 15:08:48,021 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 126 states, 100 states have (on average 1.32) internal successors, (132), 112 states have internal predecessors, (132), 14 states have call successors, (14), 11 states have call predecessors, (14), 11 states have return successors, (17), 11 states have call predecessors, (17), 14 states have call successors, (17) [2021-12-17 15:08:48,022 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 126 states to 126 states and 163 transitions. [2021-12-17 15:08:48,022 INFO L78 Accepts]: Start accepts. Automaton has 126 states and 163 transitions. Word has length 29 [2021-12-17 15:08:48,023 INFO L84 Accepts]: Finished accepts. word is rejected. [2021-12-17 15:08:48,023 INFO L470 AbstractCegarLoop]: Abstraction has 126 states and 163 transitions. [2021-12-17 15:08:48,023 INFO L471 AbstractCegarLoop]: INTERPOLANT automaton has has 8 states, 8 states have (on average 3.25) internal successors, (26), 8 states have internal predecessors, (26), 1 states have call successors, (2), 2 states have call predecessors, (2), 1 states have return successors, (1), 1 states have call predecessors, (1), 1 states have call successors, (1) [2021-12-17 15:08:48,023 INFO L276 IsEmpty]: Start isEmpty. Operand 126 states and 163 transitions. [2021-12-17 15:08:48,024 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 32 [2021-12-17 15:08:48,024 INFO L506 BasicCegarLoop]: Found error trace [2021-12-17 15:08:48,024 INFO L514 BasicCegarLoop]: trace histogram [1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2021-12-17 15:08:48,024 WARN L452 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable3 [2021-12-17 15:08:48,024 INFO L402 AbstractCegarLoop]: === Iteration 5 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2021-12-17 15:08:48,025 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2021-12-17 15:08:48,025 INFO L85 PathProgramCache]: Analyzing trace with hash 880095359, now seen corresponding path program 1 times [2021-12-17 15:08:48,025 INFO L121 FreeRefinementEngine]: Executing refinement strategy CAMEL [2021-12-17 15:08:48,025 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [1112925283] [2021-12-17 15:08:48,025 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2021-12-17 15:08:48,025 INFO L126 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2021-12-17 15:08:48,034 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:08:48,050 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 21 [2021-12-17 15:08:48,051 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:08:48,054 INFO L134 CoverageAnalysis]: Checked inductivity of 0 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2021-12-17 15:08:48,054 INFO L139 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2021-12-17 15:08:48,054 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [1112925283] [2021-12-17 15:08:48,055 INFO L160 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [1112925283] provided 1 perfect and 0 imperfect interpolant sequences [2021-12-17 15:08:48,055 INFO L186 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2021-12-17 15:08:48,055 INFO L199 FreeRefinementEngine]: Number of different interpolants: perfect sequences [3] imperfect sequences [] total 3 [2021-12-17 15:08:48,055 INFO L115 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [1082975184] [2021-12-17 15:08:48,055 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2021-12-17 15:08:48,055 INFO L546 AbstractCegarLoop]: INTERPOLANT automaton has 3 states [2021-12-17 15:08:48,056 INFO L103 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2021-12-17 15:08:48,056 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 3 interpolants. [2021-12-17 15:08:48,056 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=3, Invalid=3, Unknown=0, NotChecked=0, Total=6 [2021-12-17 15:08:48,056 INFO L87 Difference]: Start difference. First operand 126 states and 163 transitions. Second operand has 3 states, 3 states have (on average 9.333333333333334) internal successors, (28), 3 states have internal predecessors, (28), 2 states have call successors, (2), 2 states have call predecessors, (2), 1 states have return successors, (1), 1 states have call predecessors, (1), 1 states have call successors, (1) [2021-12-17 15:08:48,068 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2021-12-17 15:08:48,068 INFO L93 Difference]: Finished difference Result 219 states and 285 transitions. [2021-12-17 15:08:48,068 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 3 states. [2021-12-17 15:08:48,068 INFO L78 Accepts]: Start accepts. Automaton has has 3 states, 3 states have (on average 9.333333333333334) internal successors, (28), 3 states have internal predecessors, (28), 2 states have call successors, (2), 2 states have call predecessors, (2), 1 states have return successors, (1), 1 states have call predecessors, (1), 1 states have call successors, (1) Word has length 31 [2021-12-17 15:08:48,069 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2021-12-17 15:08:48,069 INFO L225 Difference]: With dead ends: 219 [2021-12-17 15:08:48,069 INFO L226 Difference]: Without dead ends: 100 [2021-12-17 15:08:48,070 INFO L932 BasicCegarLoop]: 0 DeclaredPredicates, 5 GetRequests, 4 SyntacticMatches, 0 SemanticMatches, 1 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 0 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=3, Invalid=3, Unknown=0, NotChecked=0, Total=6 [2021-12-17 15:08:48,071 INFO L933 BasicCegarLoop]: 46 mSDtfsCounter, 33 mSDsluCounter, 0 mSDsCounter, 0 mSdLazyCounter, 3 mSolverCounterSat, 1 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.0s Time, 0 mProtectedPredicate, 0 mProtectedAction, 33 SdHoareTripleChecker+Valid, 46 SdHoareTripleChecker+Invalid, 4 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 1 IncrementalHoareTripleChecker+Valid, 3 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.0s IncrementalHoareTripleChecker+Time [2021-12-17 15:08:48,071 INFO L934 BasicCegarLoop]: SdHoareTripleChecker [33 Valid, 46 Invalid, 4 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [1 Valid, 3 Invalid, 0 Unknown, 0 Unchecked, 0.0s Time] [2021-12-17 15:08:48,072 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 100 states. [2021-12-17 15:08:48,077 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 100 to 100. [2021-12-17 15:08:48,078 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 100 states, 77 states have (on average 1.2337662337662338) internal successors, (95), 83 states have internal predecessors, (95), 11 states have call successors, (11), 11 states have call predecessors, (11), 11 states have return successors, (12), 11 states have call predecessors, (12), 11 states have call successors, (12) [2021-12-17 15:08:48,078 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 100 states to 100 states and 118 transitions. [2021-12-17 15:08:48,078 INFO L78 Accepts]: Start accepts. Automaton has 100 states and 118 transitions. Word has length 31 [2021-12-17 15:08:48,079 INFO L84 Accepts]: Finished accepts. word is rejected. [2021-12-17 15:08:48,079 INFO L470 AbstractCegarLoop]: Abstraction has 100 states and 118 transitions. [2021-12-17 15:08:48,079 INFO L471 AbstractCegarLoop]: INTERPOLANT automaton has has 3 states, 3 states have (on average 9.333333333333334) internal successors, (28), 3 states have internal predecessors, (28), 2 states have call successors, (2), 2 states have call predecessors, (2), 1 states have return successors, (1), 1 states have call predecessors, (1), 1 states have call successors, (1) [2021-12-17 15:08:48,079 INFO L276 IsEmpty]: Start isEmpty. Operand 100 states and 118 transitions. [2021-12-17 15:08:48,080 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 60 [2021-12-17 15:08:48,080 INFO L506 BasicCegarLoop]: Found error trace [2021-12-17 15:08:48,080 INFO L514 BasicCegarLoop]: trace histogram [2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2021-12-17 15:08:48,081 WARN L452 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable4 [2021-12-17 15:08:48,081 INFO L402 AbstractCegarLoop]: === Iteration 6 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2021-12-17 15:08:48,081 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2021-12-17 15:08:48,081 INFO L85 PathProgramCache]: Analyzing trace with hash -169338653, now seen corresponding path program 1 times [2021-12-17 15:08:48,081 INFO L121 FreeRefinementEngine]: Executing refinement strategy CAMEL [2021-12-17 15:08:48,082 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [1723792869] [2021-12-17 15:08:48,082 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2021-12-17 15:08:48,082 INFO L126 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2021-12-17 15:08:48,092 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:08:48,123 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 11 [2021-12-17 15:08:48,124 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:08:48,137 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 19 [2021-12-17 15:08:48,139 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:08:48,143 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 3 [2021-12-17 15:08:48,144 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:08:48,146 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 37 [2021-12-17 15:08:48,147 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:08:48,149 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 49 [2021-12-17 15:08:48,149 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:08:48,151 INFO L134 CoverageAnalysis]: Checked inductivity of 23 backedges. 0 proven. 1 refuted. 0 times theorem prover too weak. 22 trivial. 0 not checked. [2021-12-17 15:08:48,151 INFO L139 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2021-12-17 15:08:48,151 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [1723792869] [2021-12-17 15:08:48,151 INFO L160 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [1723792869] provided 0 perfect and 1 imperfect interpolant sequences [2021-12-17 15:08:48,152 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleZ3 [901579480] [2021-12-17 15:08:48,152 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2021-12-17 15:08:48,152 INFO L168 SolverBuilder]: Constructing external solver with command: z3 -smt2 -in SMTLIB2_COMPLIANT=true [2021-12-17 15:08:48,152 INFO L189 MonitoredProcess]: No working directory specified, using /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 [2021-12-17 15:08:48,153 INFO L229 MonitoredProcess]: Starting monitored process 2 with /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 -smt2 -in SMTLIB2_COMPLIANT=true (exit command is (exit), workingDir is null) [2021-12-17 15:08:48,154 INFO L327 MonitoredProcess]: [MP /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 -smt2 -in SMTLIB2_COMPLIANT=true (2)] Waiting until timeout for monitored process [2021-12-17 15:08:48,244 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2021-12-17 15:08:48,247 INFO L263 TraceCheckSpWp]: Trace formula consists of 366 conjuncts, 9 conjunts are in the unsatisfiable core [2021-12-17 15:08:48,251 INFO L286 TraceCheckSpWp]: Computing forward predicates... [2021-12-17 15:08:48,440 INFO L134 CoverageAnalysis]: Checked inductivity of 23 backedges. 20 proven. 2 refuted. 0 times theorem prover too weak. 1 trivial. 0 not checked. [2021-12-17 15:08:48,440 INFO L328 TraceCheckSpWp]: Computing backward predicates... [2021-12-17 15:08:48,647 INFO L134 CoverageAnalysis]: Checked inductivity of 23 backedges. 18 proven. 3 refuted. 0 times theorem prover too weak. 2 trivial. 0 not checked. [2021-12-17 15:08:48,648 INFO L160 FreeRefinementEngine]: IpTcStrategyModuleZ3 [901579480] provided 0 perfect and 2 imperfect interpolant sequences [2021-12-17 15:08:48,648 INFO L186 FreeRefinementEngine]: Found 0 perfect and 3 imperfect interpolant sequences. [2021-12-17 15:08:48,648 INFO L199 FreeRefinementEngine]: Number of different interpolants: perfect sequences [] imperfect sequences [7, 7, 8] total 15 [2021-12-17 15:08:48,648 INFO L115 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [216630615] [2021-12-17 15:08:48,648 INFO L85 oduleStraightlineAll]: Using 3 imperfect interpolants to construct interpolant automaton [2021-12-17 15:08:48,649 INFO L546 AbstractCegarLoop]: INTERPOLANT automaton has 15 states [2021-12-17 15:08:48,649 INFO L103 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2021-12-17 15:08:48,649 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 15 interpolants. [2021-12-17 15:08:48,649 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=48, Invalid=162, Unknown=0, NotChecked=0, Total=210 [2021-12-17 15:08:48,649 INFO L87 Difference]: Start difference. First operand 100 states and 118 transitions. Second operand has 15 states, 15 states have (on average 6.0) internal successors, (90), 12 states have internal predecessors, (90), 6 states have call successors, (15), 8 states have call predecessors, (15), 8 states have return successors, (12), 5 states have call predecessors, (12), 6 states have call successors, (12) [2021-12-17 15:08:48,776 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2021-12-17 15:08:48,776 INFO L93 Difference]: Finished difference Result 133 states and 157 transitions. [2021-12-17 15:08:48,776 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 7 states. [2021-12-17 15:08:48,777 INFO L78 Accepts]: Start accepts. Automaton has has 15 states, 15 states have (on average 6.0) internal successors, (90), 12 states have internal predecessors, (90), 6 states have call successors, (15), 8 states have call predecessors, (15), 8 states have return successors, (12), 5 states have call predecessors, (12), 6 states have call successors, (12) Word has length 59 [2021-12-17 15:08:48,777 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2021-12-17 15:08:48,777 INFO L225 Difference]: With dead ends: 133 [2021-12-17 15:08:48,777 INFO L226 Difference]: Without dead ends: 0 [2021-12-17 15:08:48,778 INFO L932 BasicCegarLoop]: 0 DeclaredPredicates, 139 GetRequests, 121 SyntacticMatches, 0 SemanticMatches, 18 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 40 ImplicationChecksByTransitivity, 0.1s TimeCoverageRelationStatistics Valid=99, Invalid=281, Unknown=0, NotChecked=0, Total=380 [2021-12-17 15:08:48,779 INFO L933 BasicCegarLoop]: 63 mSDtfsCounter, 155 mSDsluCounter, 230 mSDsCounter, 0 mSdLazyCounter, 152 mSolverCounterSat, 59 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.1s Time, 0 mProtectedPredicate, 0 mProtectedAction, 155 SdHoareTripleChecker+Valid, 293 SdHoareTripleChecker+Invalid, 211 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 59 IncrementalHoareTripleChecker+Valid, 152 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.1s IncrementalHoareTripleChecker+Time [2021-12-17 15:08:48,779 INFO L934 BasicCegarLoop]: SdHoareTripleChecker [155 Valid, 293 Invalid, 211 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [59 Valid, 152 Invalid, 0 Unknown, 0 Unchecked, 0.1s Time] [2021-12-17 15:08:48,779 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 0 states. [2021-12-17 15:08:48,779 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 0 to 0. [2021-12-17 15:08:48,780 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 0 states, 0 states have (on average 0.0) internal successors, (0), 0 states have internal predecessors, (0), 0 states have call successors, (0), 0 states have call predecessors, (0), 0 states have return successors, (0), 0 states have call predecessors, (0), 0 states have call successors, (0) [2021-12-17 15:08:48,780 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 0 states to 0 states and 0 transitions. [2021-12-17 15:08:48,780 INFO L78 Accepts]: Start accepts. Automaton has 0 states and 0 transitions. Word has length 59 [2021-12-17 15:08:48,780 INFO L84 Accepts]: Finished accepts. word is rejected. [2021-12-17 15:08:48,780 INFO L470 AbstractCegarLoop]: Abstraction has 0 states and 0 transitions. [2021-12-17 15:08:48,780 INFO L471 AbstractCegarLoop]: INTERPOLANT automaton has has 15 states, 15 states have (on average 6.0) internal successors, (90), 12 states have internal predecessors, (90), 6 states have call successors, (15), 8 states have call predecessors, (15), 8 states have return successors, (12), 5 states have call predecessors, (12), 6 states have call successors, (12) [2021-12-17 15:08:48,781 INFO L276 IsEmpty]: Start isEmpty. Operand 0 states and 0 transitions. [2021-12-17 15:08:48,781 INFO L282 IsEmpty]: Finished isEmpty. No accepting run. [2021-12-17 15:08:48,783 INFO L764 garLoopResultBuilder]: Registering result SAFE for location timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION (0 of 1 remaining) [2021-12-17 15:08:48,816 INFO L552 MonitoredProcess]: [MP /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 -smt2 -in SMTLIB2_COMPLIANT=true (2)] Ended with exit code 0 [2021-12-17 15:08:49,001 WARN L452 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: 2 /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 -smt2 -in SMTLIB2_COMPLIANT=true,SelfDestructingSolverStorable5 [2021-12-17 15:08:49,003 INFO L343 DoubleDeckerVisitor]: Before removal of dead ends 0 states and 0 transitions. [2021-12-17 15:08:49,519 INFO L858 garLoopResultBuilder]: For program point processEnvironment__wrappee__baseEXIT(lines 325 331) no Hoare annotation was computed. [2021-12-17 15:08:49,519 INFO L861 garLoopResultBuilder]: At program point processEnvironment__wrappee__baseFINAL(lines 325 331) the Hoare annotation is: true [2021-12-17 15:08:49,519 INFO L858 garLoopResultBuilder]: For program point L480-1(lines 476 487) no Hoare annotation was computed. [2021-12-17 15:08:49,519 INFO L861 garLoopResultBuilder]: At program point changeMethaneLevelENTRY(lines 476 487) the Hoare annotation is: true [2021-12-17 15:08:49,519 INFO L858 garLoopResultBuilder]: For program point changeMethaneLevelEXIT(lines 476 487) no Hoare annotation was computed. [2021-12-17 15:08:49,519 INFO L854 garLoopResultBuilder]: At program point L188(lines 183 190) the Hoare annotation is: (or (not (= |old(~pumpRunning~0)| 0)) (not (= ~systemActive~0 1)) (not (<= 1 |old(~waterLevel~0)|))) [2021-12-17 15:08:49,519 INFO L858 garLoopResultBuilder]: For program point L312-1(lines 312 318) no Hoare annotation was computed. [2021-12-17 15:08:49,519 INFO L858 garLoopResultBuilder]: For program point L341(lines 341 349) no Hoare annotation was computed. [2021-12-17 15:08:49,519 INFO L858 garLoopResultBuilder]: For program point L337(lines 337 354) no Hoare annotation was computed. [2021-12-17 15:08:49,519 INFO L858 garLoopResultBuilder]: For program point timeShiftFINAL(lines 301 324) no Hoare annotation was computed. [2021-12-17 15:08:49,519 INFO L858 garLoopResultBuilder]: For program point L65(lines 65 71) no Hoare annotation was computed. [2021-12-17 15:08:49,520 INFO L854 garLoopResultBuilder]: At program point L445(lines 430 448) the Hoare annotation is: (or (not (= |old(~pumpRunning~0)| 0)) (not (= ~systemActive~0 1)) (not (<= 1 |old(~waterLevel~0)|))) [2021-12-17 15:08:49,520 INFO L858 garLoopResultBuilder]: For program point L61(lines 61 74) no Hoare annotation was computed. [2021-12-17 15:08:49,520 INFO L854 garLoopResultBuilder]: At program point L61-1(lines 53 77) the Hoare annotation is: (let ((.cse0 (not (= |old(~pumpRunning~0)| 0))) (.cse1 (and (not (= 0 |timeShift___utac_acc__Specification4_spec__1_~tmp~0#1|)) (= ~waterLevel~0 |old(~waterLevel~0)|) (not (= 0 |timeShift_getWaterLevel_#res#1|)) (= ~pumpRunning~0 0))) (.cse2 (not (= ~systemActive~0 1)))) (and (or (not (= |old(~waterLevel~0)| 1)) .cse0 .cse1 .cse2) (or (not (<= 2 |old(~waterLevel~0)|)) .cse0 .cse1 .cse2))) [2021-12-17 15:08:49,520 INFO L854 garLoopResultBuilder]: At program point L371(lines 366 373) the Hoare annotation is: (or (not (= |old(~pumpRunning~0)| 0)) (not (= ~systemActive~0 1)) (not (<= 1 |old(~waterLevel~0)|))) [2021-12-17 15:08:49,520 INFO L858 garLoopResultBuilder]: For program point L305-1(lines 304 323) no Hoare annotation was computed. [2021-12-17 15:08:49,520 INFO L854 garLoopResultBuilder]: At program point L347(line 347) the Hoare annotation is: (or (not (= |old(~pumpRunning~0)| 0)) (not (= ~systemActive~0 1)) (not (<= 1 |old(~waterLevel~0)|))) [2021-12-17 15:08:49,520 INFO L854 garLoopResultBuilder]: At program point L525(lines 520 528) the Hoare annotation is: (let ((.cse0 (and (= ~waterLevel~0 |old(~waterLevel~0)|) (not (= 0 |timeShift_getWaterLevel_#res#1|)) (= ~pumpRunning~0 0))) (.cse1 (not (= |old(~pumpRunning~0)| 0))) (.cse2 (not (= ~systemActive~0 1)))) (and (or (not (<= 2 |old(~waterLevel~0)|)) .cse0 .cse1 .cse2) (or (not (= |old(~waterLevel~0)| 1)) .cse0 .cse1 .cse2))) [2021-12-17 15:08:49,520 INFO L854 garLoopResultBuilder]: At program point L352(line 352) the Hoare annotation is: (let ((.cse0 (and (= ~waterLevel~0 |old(~waterLevel~0)|) (= ~pumpRunning~0 0))) (.cse1 (not (= |old(~pumpRunning~0)| 0))) (.cse2 (not (= ~systemActive~0 1)))) (and (or (not (= |old(~waterLevel~0)| 1)) .cse0 .cse1 .cse2) (or (not (<= 2 |old(~waterLevel~0)|)) .cse0 .cse1 .cse2))) [2021-12-17 15:08:49,520 INFO L854 garLoopResultBuilder]: At program point L352-1(lines 333 357) the Hoare annotation is: (let ((.cse0 (and (= ~waterLevel~0 |old(~waterLevel~0)|) (= ~pumpRunning~0 0))) (.cse1 (not (= |old(~pumpRunning~0)| 0))) (.cse2 (not (= ~systemActive~0 1)))) (and (or (not (= |old(~waterLevel~0)| 1)) .cse0 .cse1 .cse2) (or (not (<= 2 |old(~waterLevel~0)|)) .cse0 .cse1 .cse2))) [2021-12-17 15:08:49,520 INFO L858 garLoopResultBuilder]: For program point L187(line 187) no Hoare annotation was computed. [2021-12-17 15:08:49,520 INFO L858 garLoopResultBuilder]: For program point L439(lines 439 443) no Hoare annotation was computed. [2021-12-17 15:08:49,520 INFO L854 garLoopResultBuilder]: At program point L534(lines 529 537) the Hoare annotation is: (or (not (= |old(~pumpRunning~0)| 0)) (not (= ~systemActive~0 1)) (not (<= 1 |old(~waterLevel~0)|))) [2021-12-17 15:08:49,520 INFO L858 garLoopResultBuilder]: For program point L439-2(lines 439 443) no Hoare annotation was computed. [2021-12-17 15:08:49,520 INFO L854 garLoopResultBuilder]: At program point timeShiftENTRY(lines 301 324) the Hoare annotation is: (let ((.cse0 (and (= ~waterLevel~0 |old(~waterLevel~0)|) (= ~pumpRunning~0 0))) (.cse1 (not (= |old(~pumpRunning~0)| 0))) (.cse2 (not (= ~systemActive~0 1)))) (and (or (not (= |old(~waterLevel~0)| 1)) .cse0 .cse1 .cse2) (or (not (<= 2 |old(~waterLevel~0)|)) .cse0 .cse1 .cse2))) [2021-12-17 15:08:49,520 INFO L858 garLoopResultBuilder]: For program point timeShiftEXIT(lines 301 324) no Hoare annotation was computed. [2021-12-17 15:08:49,521 INFO L858 garLoopResultBuilder]: For program point timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION(line 187) no Hoare annotation was computed. [2021-12-17 15:08:49,521 INFO L858 garLoopResultBuilder]: For program point L456(lines 456 460) no Hoare annotation was computed. [2021-12-17 15:08:49,521 INFO L854 garLoopResultBuilder]: At program point L456-2(lines 452 463) the Hoare annotation is: (or (not (= |old(~pumpRunning~0)| 0)) (not (= ~systemActive~0 1)) (not (<= 1 |old(~waterLevel~0)|))) [2021-12-17 15:08:49,521 INFO L854 garLoopResultBuilder]: At program point L390(lines 385 393) the Hoare annotation is: (or (not (= |old(~pumpRunning~0)| 0)) (not (= ~systemActive~0 1)) (not (<= 1 |old(~waterLevel~0)|))) [2021-12-17 15:08:49,521 INFO L858 garLoopResultBuilder]: For program point cleanupEXIT(lines 81 110) no Hoare annotation was computed. [2021-12-17 15:08:49,521 INFO L858 garLoopResultBuilder]: For program point L95(lines 95 99) no Hoare annotation was computed. [2021-12-17 15:08:49,521 INFO L861 garLoopResultBuilder]: At program point L95-1(lines 95 99) the Hoare annotation is: true [2021-12-17 15:08:49,521 INFO L861 garLoopResultBuilder]: At program point cleanupENTRY(lines 81 110) the Hoare annotation is: true [2021-12-17 15:08:49,521 INFO L858 garLoopResultBuilder]: For program point L92(line 92) no Hoare annotation was computed. [2021-12-17 15:08:49,521 INFO L861 garLoopResultBuilder]: At program point L91-2(lines 91 105) the Hoare annotation is: true [2021-12-17 15:08:49,521 INFO L861 garLoopResultBuilder]: At program point L87(line 87) the Hoare annotation is: true [2021-12-17 15:08:49,521 INFO L858 garLoopResultBuilder]: For program point L87-1(line 87) no Hoare annotation was computed. [2021-12-17 15:08:49,521 INFO L861 garLoopResultBuilder]: At program point L106(lines 81 110) the Hoare annotation is: true [2021-12-17 15:08:49,521 INFO L858 garLoopResultBuilder]: For program point L102(line 102) no Hoare annotation was computed. [2021-12-17 15:08:49,521 INFO L854 garLoopResultBuilder]: At program point L283(lines 236 284) the Hoare annotation is: false [2021-12-17 15:08:49,521 INFO L858 garLoopResultBuilder]: For program point L238(lines 237 282) no Hoare annotation was computed. [2021-12-17 15:08:49,521 INFO L858 garLoopResultBuilder]: For program point L267(lines 267 278) no Hoare annotation was computed. [2021-12-17 15:08:49,521 INFO L854 garLoopResultBuilder]: At program point L259(line 259) the Hoare annotation is: (let ((.cse0 (= |ULTIMATE.start_test_~splverifierCounter~0#1| 0)) (.cse1 (= ~systemActive~0 |ULTIMATE.start_main_~tmp~1#1|)) (.cse2 (= ~systemActive~0 1)) (.cse3 (= ~pumpRunning~0 0))) (or (and .cse0 (= ~systemActive~0 |ULTIMATE.start_valid_product_#res#1|) .cse1 (<= 2 ~waterLevel~0) .cse2 .cse3) (and .cse0 (= ~waterLevel~0 |ULTIMATE.start_valid_product_#res#1|) .cse1 (= ~waterLevel~0 1) .cse2 .cse3))) [2021-12-17 15:08:49,521 INFO L858 garLoopResultBuilder]: For program point L-1(line -1) no Hoare annotation was computed. [2021-12-17 15:08:49,522 INFO L854 garLoopResultBuilder]: At program point L222(lines 217 225) the Hoare annotation is: (and (= ~waterLevel~0 |ULTIMATE.start_valid_product_#res#1|) (= ~waterLevel~0 1) (= ~systemActive~0 1) (= ~pumpRunning~0 0)) [2021-12-17 15:08:49,522 INFO L858 garLoopResultBuilder]: For program point ULTIMATE.startENTRY(line -1) no Hoare annotation was computed. [2021-12-17 15:08:49,522 INFO L858 garLoopResultBuilder]: For program point ULTIMATE.startFINAL(line -1) no Hoare annotation was computed. [2021-12-17 15:08:49,522 INFO L854 garLoopResultBuilder]: At program point L280(lines 237 282) the Hoare annotation is: (let ((.cse0 (= |ULTIMATE.start_test_~splverifierCounter~0#1| 0)) (.cse1 (= ~systemActive~0 |ULTIMATE.start_main_~tmp~1#1|)) (.cse2 (= ~systemActive~0 1)) (.cse3 (= ~pumpRunning~0 0))) (or (and .cse0 (= ~systemActive~0 |ULTIMATE.start_valid_product_#res#1|) .cse1 (<= 2 ~waterLevel~0) .cse2 .cse3) (and .cse0 (= ~waterLevel~0 |ULTIMATE.start_valid_product_#res#1|) .cse1 (= ~waterLevel~0 1) .cse2 .cse3))) [2021-12-17 15:08:49,522 INFO L858 garLoopResultBuilder]: For program point L247(lines 247 253) no Hoare annotation was computed. [2021-12-17 15:08:49,522 INFO L854 garLoopResultBuilder]: At program point L214(lines 210 216) the Hoare annotation is: (and (= ~waterLevel~0 1) (= ~systemActive~0 1) (= ~pumpRunning~0 0)) [2021-12-17 15:08:49,522 INFO L858 garLoopResultBuilder]: For program point L247-1(lines 247 253) no Hoare annotation was computed. [2021-12-17 15:08:49,522 INFO L858 garLoopResultBuilder]: For program point L239(lines 239 243) no Hoare annotation was computed. [2021-12-17 15:08:49,522 INFO L858 garLoopResultBuilder]: For program point L169(lines 169 176) no Hoare annotation was computed. [2021-12-17 15:08:49,522 INFO L858 garLoopResultBuilder]: For program point L169-2(lines 169 176) no Hoare annotation was computed. [2021-12-17 15:08:49,522 INFO L858 garLoopResultBuilder]: For program point ULTIMATE.startEXIT(line -1) no Hoare annotation was computed. [2021-12-17 15:08:49,522 INFO L861 garLoopResultBuilder]: At program point L153(lines 146 155) the Hoare annotation is: true [2021-12-17 15:08:49,522 INFO L861 garLoopResultBuilder]: At program point L178(lines 159 181) the Hoare annotation is: true [2021-12-17 15:08:49,522 INFO L858 garLoopResultBuilder]: For program point L273(lines 273 277) no Hoare annotation was computed. [2021-12-17 15:08:49,522 INFO L854 garLoopResultBuilder]: At program point L207(lines 203 209) the Hoare annotation is: (and (= ~waterLevel~0 1) (= ~systemActive~0 1) (= ~pumpRunning~0 0)) [2021-12-17 15:08:49,522 INFO L854 garLoopResultBuilder]: At program point L273-2(lines 267 278) the Hoare annotation is: (let ((.cse0 (= |ULTIMATE.start_test_~splverifierCounter~0#1| 0)) (.cse1 (= ~systemActive~0 |ULTIMATE.start_main_~tmp~1#1|)) (.cse2 (= ~systemActive~0 1)) (.cse3 (= ~pumpRunning~0 0))) (or (and .cse0 (= ~systemActive~0 |ULTIMATE.start_valid_product_#res#1|) .cse1 (<= 2 ~waterLevel~0) .cse2 .cse3) (and .cse0 (= ~waterLevel~0 |ULTIMATE.start_valid_product_#res#1|) .cse1 (= ~waterLevel~0 1) .cse2 .cse3))) [2021-12-17 15:08:49,522 INFO L858 garLoopResultBuilder]: For program point L257(lines 257 263) no Hoare annotation was computed. [2021-12-17 15:08:49,522 INFO L858 garLoopResultBuilder]: For program point L257-1(lines 257 263) no Hoare annotation was computed. [2021-12-17 15:08:49,522 INFO L861 garLoopResultBuilder]: At program point L286(lines 227 290) the Hoare annotation is: true [2021-12-17 15:08:49,522 INFO L854 garLoopResultBuilder]: At program point L249(line 249) the Hoare annotation is: (let ((.cse0 (= |ULTIMATE.start_test_~splverifierCounter~0#1| 0)) (.cse1 (= ~systemActive~0 |ULTIMATE.start_main_~tmp~1#1|)) (.cse2 (= ~systemActive~0 1)) (.cse3 (= ~pumpRunning~0 0))) (or (and .cse0 (= ~systemActive~0 |ULTIMATE.start_valid_product_#res#1|) .cse1 (<= 2 ~waterLevel~0) .cse2 .cse3) (and .cse0 (= ~waterLevel~0 |ULTIMATE.start_valid_product_#res#1|) .cse1 (= ~waterLevel~0 1) .cse2 .cse3))) [2021-12-17 15:08:49,523 INFO L854 garLoopResultBuilder]: At program point L142(lines 138 144) the Hoare annotation is: (and (= ~waterLevel~0 |ULTIMATE.start_valid_product_#res#1|) (= ~systemActive~0 |ULTIMATE.start_main_~tmp~1#1|) (= ~waterLevel~0 1) (= ~systemActive~0 1) (= ~pumpRunning~0 0)) [2021-12-17 15:08:49,523 INFO L858 garLoopResultBuilder]: For program point waterRiseEXIT(lines 464 475) no Hoare annotation was computed. [2021-12-17 15:08:49,523 INFO L854 garLoopResultBuilder]: At program point waterRiseENTRY(lines 464 475) the Hoare annotation is: (let ((.cse0 (not (= ~pumpRunning~0 0))) (.cse1 (= ~waterLevel~0 |old(~waterLevel~0)|)) (.cse2 (not (= ~systemActive~0 1)))) (and (or (not (= |old(~waterLevel~0)| 1)) .cse0 .cse1 .cse2) (or (not (<= 2 |old(~waterLevel~0)|)) .cse0 .cse1 .cse2))) [2021-12-17 15:08:49,523 INFO L858 garLoopResultBuilder]: For program point L468-1(lines 464 475) no Hoare annotation was computed. [2021-12-17 15:08:49,525 INFO L732 BasicCegarLoop]: Path program histogram: [1, 1, 1, 1, 1, 1] [2021-12-17 15:08:49,526 INFO L179 ceAbstractionStarter]: Computing trace abstraction results [2021-12-17 15:08:49,539 INFO L202 PluginConnector]: Adding new model de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction CFG 17.12 03:08:49 BoogieIcfgContainer [2021-12-17 15:08:49,539 INFO L132 PluginConnector]: ------------------------ END TraceAbstraction---------------------------- [2021-12-17 15:08:49,539 INFO L113 PluginConnector]: ------------------------Witness Printer---------------------------- [2021-12-17 15:08:49,539 INFO L271 PluginConnector]: Initializing Witness Printer... [2021-12-17 15:08:49,540 INFO L275 PluginConnector]: Witness Printer initialized [2021-12-17 15:08:49,540 INFO L185 PluginConnector]: Executing the observer RCFGCatcher from plugin Witness Printer for "de.uni_freiburg.informatik.ultimate.plugins.generator.rcfgbuilder CFG 17.12 03:08:47" (3/4) ... [2021-12-17 15:08:49,542 INFO L137 WitnessPrinter]: Generating witness for correct program [2021-12-17 15:08:49,552 INFO L354 RCFGBacktranslator]: Ignoring RootEdge to procedure processEnvironment__wrappee__base [2021-12-17 15:08:49,552 INFO L354 RCFGBacktranslator]: Ignoring RootEdge to procedure changeMethaneLevel [2021-12-17 15:08:49,552 INFO L354 RCFGBacktranslator]: Ignoring RootEdge to procedure timeShift [2021-12-17 15:08:49,552 INFO L354 RCFGBacktranslator]: Ignoring RootEdge to procedure cleanup [2021-12-17 15:08:49,552 INFO L354 RCFGBacktranslator]: Ignoring RootEdge to procedure waterRise [2021-12-17 15:08:49,557 INFO L910 BoogieBacktranslator]: Reduced CFG by removing 50 nodes and edges [2021-12-17 15:08:49,557 INFO L910 BoogieBacktranslator]: Reduced CFG by removing 22 nodes and edges [2021-12-17 15:08:49,557 INFO L910 BoogieBacktranslator]: Reduced CFG by removing 11 nodes and edges [2021-12-17 15:08:49,558 INFO L910 BoogieBacktranslator]: Reduced CFG by removing 5 nodes and edges [2021-12-17 15:08:49,558 INFO L910 BoogieBacktranslator]: Reduced CFG by removing 2 nodes and edges [2021-12-17 15:08:49,558 INFO L910 BoogieBacktranslator]: Reduced CFG by removing 1 nodes and edges [2021-12-17 15:08:49,558 INFO L910 BoogieBacktranslator]: Reduced CFG by removing 1 nodes and edges [2021-12-17 15:08:49,578 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: ((waterLevel == \result && waterLevel == 1) && systemActive == 1) && pumpRunning == 0 [2021-12-17 15:08:49,578 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (((waterLevel == \result && systemActive == tmp) && waterLevel == 1) && systemActive == 1) && pumpRunning == 0 [2021-12-17 15:08:49,578 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (((((splverifierCounter == 0 && systemActive == \result) && systemActive == tmp) && 2 <= waterLevel) && systemActive == 1) && pumpRunning == 0) || (((((splverifierCounter == 0 && waterLevel == \result) && systemActive == tmp) && waterLevel == 1) && systemActive == 1) && pumpRunning == 0) [2021-12-17 15:08:49,579 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (!(\old(pumpRunning) == 0) || !(systemActive == 1)) || !(1 <= \old(waterLevel)) [2021-12-17 15:08:49,580 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (((!(\old(waterLevel) == 1) || (waterLevel == \old(waterLevel) && pumpRunning == 0)) || !(\old(pumpRunning) == 0)) || !(systemActive == 1)) && (((!(2 <= \old(waterLevel)) || (waterLevel == \old(waterLevel) && pumpRunning == 0)) || !(\old(pumpRunning) == 0)) || !(systemActive == 1)) [2021-12-17 15:08:49,580 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (((!(2 <= \old(waterLevel)) || ((waterLevel == \old(waterLevel) && !(0 == \result)) && pumpRunning == 0)) || !(\old(pumpRunning) == 0)) || !(systemActive == 1)) && (((!(\old(waterLevel) == 1) || ((waterLevel == \old(waterLevel) && !(0 == \result)) && pumpRunning == 0)) || !(\old(pumpRunning) == 0)) || !(systemActive == 1)) [2021-12-17 15:08:49,581 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (((!(\old(waterLevel) == 1) || !(\old(pumpRunning) == 0)) || (((!(0 == tmp) && waterLevel == \old(waterLevel)) && !(0 == \result)) && pumpRunning == 0)) || !(systemActive == 1)) && (((!(2 <= \old(waterLevel)) || !(\old(pumpRunning) == 0)) || (((!(0 == tmp) && waterLevel == \old(waterLevel)) && !(0 == \result)) && pumpRunning == 0)) || !(systemActive == 1)) [2021-12-17 15:08:49,581 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (!(\old(pumpRunning) == 0) || !(systemActive == 1)) || !(1 <= \old(waterLevel)) [2021-12-17 15:08:49,581 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (!(\old(pumpRunning) == 0) || !(systemActive == 1)) || !(1 <= \old(waterLevel)) [2021-12-17 15:08:49,581 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (!(\old(pumpRunning) == 0) || !(systemActive == 1)) || !(1 <= \old(waterLevel)) [2021-12-17 15:08:49,582 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (!(\old(pumpRunning) == 0) || !(systemActive == 1)) || !(1 <= \old(waterLevel)) [2021-12-17 15:08:49,582 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (!(\old(pumpRunning) == 0) || !(systemActive == 1)) || !(1 <= \old(waterLevel)) [2021-12-17 15:08:49,599 INFO L141 WitnessManager]: Wrote witness to /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/witness.graphml [2021-12-17 15:08:49,599 INFO L132 PluginConnector]: ------------------------ END Witness Printer---------------------------- [2021-12-17 15:08:49,600 INFO L158 Benchmark]: Toolchain (without parser) took 3342.64ms. Allocated memory was 90.2MB in the beginning and 113.2MB in the end (delta: 23.1MB). Free memory was 52.8MB in the beginning and 79.0MB in the end (delta: -26.2MB). There was no memory consumed. Max. memory is 16.1GB. [2021-12-17 15:08:49,600 INFO L158 Benchmark]: CDTParser took 0.18ms. Allocated memory is still 90.2MB. Free memory was 70.0MB in the beginning and 70.0MB in the end (delta: 42.9kB). There was no memory consumed. Max. memory is 16.1GB. [2021-12-17 15:08:49,600 INFO L158 Benchmark]: CACSL2BoogieTranslator took 323.68ms. Allocated memory is still 90.2MB. Free memory was 52.6MB in the beginning and 59.3MB in the end (delta: -6.8MB). Peak memory consumption was 4.2MB. Max. memory is 16.1GB. [2021-12-17 15:08:49,600 INFO L158 Benchmark]: Boogie Procedure Inliner took 52.92ms. Allocated memory is still 90.2MB. Free memory was 59.3MB in the beginning and 57.0MB in the end (delta: 2.4MB). Peak memory consumption was 2.1MB. Max. memory is 16.1GB. [2021-12-17 15:08:49,601 INFO L158 Benchmark]: Boogie Preprocessor took 28.80ms. Allocated memory is still 90.2MB. Free memory was 57.0MB in the beginning and 55.6MB in the end (delta: 1.4MB). There was no memory consumed. Max. memory is 16.1GB. [2021-12-17 15:08:49,601 INFO L158 Benchmark]: RCFGBuilder took 339.79ms. Allocated memory is still 90.2MB. Free memory was 55.4MB in the beginning and 40.5MB in the end (delta: 14.9MB). Peak memory consumption was 16.8MB. Max. memory is 16.1GB. [2021-12-17 15:08:49,601 INFO L158 Benchmark]: TraceAbstraction took 2532.64ms. Allocated memory was 90.2MB in the beginning and 113.2MB in the end (delta: 23.1MB). Free memory was 40.2MB in the beginning and 84.2MB in the end (delta: -44.0MB). Peak memory consumption was 31.7MB. Max. memory is 16.1GB. [2021-12-17 15:08:49,601 INFO L158 Benchmark]: Witness Printer took 59.88ms. Allocated memory is still 113.2MB. Free memory was 84.2MB in the beginning and 79.0MB in the end (delta: 5.2MB). Peak memory consumption was 4.2MB. Max. memory is 16.1GB. [2021-12-17 15:08:49,602 INFO L339 ainManager$Toolchain]: ####################### End [Toolchain 1] ####################### --- Results --- * Results from de.uni_freiburg.informatik.ultimate.core: - StatisticsResult: Toolchain Benchmarks Benchmark results are: * CDTParser took 0.18ms. Allocated memory is still 90.2MB. Free memory was 70.0MB in the beginning and 70.0MB in the end (delta: 42.9kB). There was no memory consumed. Max. memory is 16.1GB. * CACSL2BoogieTranslator took 323.68ms. Allocated memory is still 90.2MB. Free memory was 52.6MB in the beginning and 59.3MB in the end (delta: -6.8MB). Peak memory consumption was 4.2MB. Max. memory is 16.1GB. * Boogie Procedure Inliner took 52.92ms. Allocated memory is still 90.2MB. Free memory was 59.3MB in the beginning and 57.0MB in the end (delta: 2.4MB). Peak memory consumption was 2.1MB. Max. memory is 16.1GB. * Boogie Preprocessor took 28.80ms. Allocated memory is still 90.2MB. Free memory was 57.0MB in the beginning and 55.6MB in the end (delta: 1.4MB). There was no memory consumed. Max. memory is 16.1GB. * RCFGBuilder took 339.79ms. Allocated memory is still 90.2MB. Free memory was 55.4MB in the beginning and 40.5MB in the end (delta: 14.9MB). Peak memory consumption was 16.8MB. Max. memory is 16.1GB. * TraceAbstraction took 2532.64ms. Allocated memory was 90.2MB in the beginning and 113.2MB in the end (delta: 23.1MB). Free memory was 40.2MB in the beginning and 84.2MB in the end (delta: -44.0MB). Peak memory consumption was 31.7MB. Max. memory is 16.1GB. * Witness Printer took 59.88ms. Allocated memory is still 113.2MB. Free memory was 84.2MB in the beginning and 79.0MB in the end (delta: 5.2MB). Peak memory consumption was 4.2MB. Max. memory is 16.1GB. * Results from de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction: - StatisticsResult: ErrorAutomatonStatistics NumberErrorTraces: 0, NumberStatementsAllTraces: 0, NumberRelevantStatements: 0, 0.0s ErrorAutomatonConstructionTimeTotal, 0.0s FaulLocalizationTime, NumberStatementsFirstTrace: -1, TraceLengthAvg: 0, 0.0s ErrorAutomatonConstructionTimeAvg, 0.0s ErrorAutomatonDifferenceTimeAvg, 0.0s ErrorAutomatonDifferenceTimeTotal, NumberOfNoEnhancement: 0, NumberOfFiniteEnhancement: 0, NumberOfInfiniteEnhancement: 0 - PositiveResult [Line: 187]: call to reach_error is unreachable For all program executions holds that call to reach_error is unreachable at this location - StatisticsResult: Ultimate Automizer benchmark data CFG has 6 procedures, 69 locations, 1 error locations. Started 1 CEGAR loops. OverallTime: 2.5s, OverallIterations: 6, TraceHistogramMax: 2, PathProgramHistogramMax: 1, EmptinessCheckTime: 0.0s, AutomataDifference: 0.5s, DeadEndRemovalTime: 0.0s, HoareAnnotationTime: 0.5s, InitialAbstractionConstructionTime: 0.0s, PartialOrderReductionTime: 0.0s, HoareTripleCheckerStatistics: 0 mSolverCounterUnknown, 447 SdHoareTripleChecker+Valid, 0.2s IncrementalHoareTripleChecker+Time, 0 mSdLazyCounter, 444 mSDsluCounter, 1055 SdHoareTripleChecker+Invalid, 0.2s Time, 0 mProtectedAction, 0 SdHoareTripleChecker+Unchecked, 0 IncrementalHoareTripleChecker+Unchecked, 672 mSDsCounter, 92 IncrementalHoareTripleChecker+Valid, 0 mProtectedPredicate, 290 IncrementalHoareTripleChecker+Invalid, 382 SdHoareTripleChecker+Unknown, 0 mSolverCounterNotChecked, 92 mSolverCounterUnsat, 383 mSDtfsCounter, 290 mSolverCounterSat, 0.0s SdHoareTripleChecker+Time, 0 IncrementalHoareTripleChecker+Unknown, PredicateUnifierStatistics: 0 DeclaredPredicates, 172 GetRequests, 134 SyntacticMatches, 0 SemanticMatches, 38 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 55 ImplicationChecksByTransitivity, 0.2s Time, 0.0s BasicInterpolantAutomatonTime, BiggestAbstraction: size=126occurred in iteration=4, InterpolantAutomatonStates: 31, traceCheckStatistics: No data available, InterpolantConsolidationStatistics: No data available, PathInvariantsStatistics: No data available, 0/0 InterpolantCoveringCapability, TotalInterpolationStatistics: No data available, 0.0s DumpTime, AutomataMinimizationStatistics: 0.1s AutomataMinimizationTime, 6 MinimizatonAttempts, 5 StatesRemovedByMinimization, 1 NontrivialMinimizations, HoareAnnotationStatistics: 0.0s HoareAnnotationTime, 32 LocationsWithAnnotation, 226 PreInvPairs, 246 NumberOfFragments, 569 HoareAnnotationTreeSize, 226 FomulaSimplifications, 97 FormulaSimplificationTreeSizeReduction, 0.0s HoareSimplificationTime, 32 FomulaSimplificationsInter, 493 FormulaSimplificationTreeSizeReductionInter, 0.5s HoareSimplificationTimeInter, RefinementEngineStatistics: TRACE_CHECK: 0.0s SsaConstructionTime, 0.1s SatisfiabilityAnalysisTime, 0.7s InterpolantComputationTime, 241 NumberOfCodeBlocks, 241 NumberOfCodeBlocksAsserted, 7 NumberOfCheckSat, 292 ConstructedInterpolants, 0 QuantifiedInterpolants, 756 SizeOfPredicates, 0 NumberOfNonLiveVariables, 366 ConjunctsInSsa, 9 ConjunctsInUnsatCore, 8 InterpolantComputations, 5 PerfectInterpolantSequences, 63/69 InterpolantCoveringCapability, INVARIANT_SYNTHESIS: No data available, INTERPOLANT_CONSOLIDATION: No data available, ABSTRACT_INTERPRETATION: No data available, PDR: No data available, ACCELERATED_INTERPOLATION: No data available, SIFA: No data available, ReuseStatistics: No data available - AllSpecificationsHoldResult: All specifications hold 1 specifications checked. All of them hold - InvariantResult [Line: 91]: Loop Invariant Derived loop invariant: 1 - InvariantResult [Line: 183]: Loop Invariant Derived loop invariant: (!(\old(pumpRunning) == 0) || !(systemActive == 1)) || !(1 <= \old(waterLevel)) - InvariantResult [Line: 203]: Loop Invariant Derived loop invariant: (waterLevel == 1 && systemActive == 1) && pumpRunning == 0 - InvariantResult [Line: 520]: Loop Invariant Derived loop invariant: (((!(2 <= \old(waterLevel)) || ((waterLevel == \old(waterLevel) && !(0 == \result)) && pumpRunning == 0)) || !(\old(pumpRunning) == 0)) || !(systemActive == 1)) && (((!(\old(waterLevel) == 1) || ((waterLevel == \old(waterLevel) && !(0 == \result)) && pumpRunning == 0)) || !(\old(pumpRunning) == 0)) || !(systemActive == 1)) - InvariantResult [Line: 53]: Loop Invariant Derived loop invariant: (((!(\old(waterLevel) == 1) || !(\old(pumpRunning) == 0)) || (((!(0 == tmp) && waterLevel == \old(waterLevel)) && !(0 == \result)) && pumpRunning == 0)) || !(systemActive == 1)) && (((!(2 <= \old(waterLevel)) || !(\old(pumpRunning) == 0)) || (((!(0 == tmp) && waterLevel == \old(waterLevel)) && !(0 == \result)) && pumpRunning == 0)) || !(systemActive == 1)) - InvariantResult [Line: 210]: Loop Invariant Derived loop invariant: (waterLevel == 1 && systemActive == 1) && pumpRunning == 0 - InvariantResult [Line: 146]: Loop Invariant Derived loop invariant: 1 - InvariantResult [Line: 81]: Loop Invariant Derived loop invariant: 1 - InvariantResult [Line: 237]: Loop Invariant Derived loop invariant: (((((splverifierCounter == 0 && systemActive == \result) && systemActive == tmp) && 2 <= waterLevel) && systemActive == 1) && pumpRunning == 0) || (((((splverifierCounter == 0 && waterLevel == \result) && systemActive == tmp) && waterLevel == 1) && systemActive == 1) && pumpRunning == 0) - InvariantResult [Line: 529]: Loop Invariant Derived loop invariant: (!(\old(pumpRunning) == 0) || !(systemActive == 1)) || !(1 <= \old(waterLevel)) - InvariantResult [Line: 333]: Loop Invariant Derived loop invariant: (((!(\old(waterLevel) == 1) || (waterLevel == \old(waterLevel) && pumpRunning == 0)) || !(\old(pumpRunning) == 0)) || !(systemActive == 1)) && (((!(2 <= \old(waterLevel)) || (waterLevel == \old(waterLevel) && pumpRunning == 0)) || !(\old(pumpRunning) == 0)) || !(systemActive == 1)) - InvariantResult [Line: 366]: Loop Invariant Derived loop invariant: (!(\old(pumpRunning) == 0) || !(systemActive == 1)) || !(1 <= \old(waterLevel)) - InvariantResult [Line: 236]: Loop Invariant Derived loop invariant: 0 - InvariantResult [Line: 159]: Loop Invariant Derived loop invariant: 1 - InvariantResult [Line: 430]: Loop Invariant Derived loop invariant: (!(\old(pumpRunning) == 0) || !(systemActive == 1)) || !(1 <= \old(waterLevel)) - InvariantResult [Line: 138]: Loop Invariant Derived loop invariant: (((waterLevel == \result && systemActive == tmp) && waterLevel == 1) && systemActive == 1) && pumpRunning == 0 - InvariantResult [Line: 385]: Loop Invariant Derived loop invariant: (!(\old(pumpRunning) == 0) || !(systemActive == 1)) || !(1 <= \old(waterLevel)) - InvariantResult [Line: 452]: Loop Invariant Derived loop invariant: (!(\old(pumpRunning) == 0) || !(systemActive == 1)) || !(1 <= \old(waterLevel)) - InvariantResult [Line: 217]: Loop Invariant Derived loop invariant: ((waterLevel == \result && waterLevel == 1) && systemActive == 1) && pumpRunning == 0 - InvariantResult [Line: 227]: Loop Invariant Derived loop invariant: 1 RESULT: Ultimate proved your program to be correct! [2021-12-17 15:08:49,645 INFO L540 MonitoredProcess]: [MP /storage/repos/ultimate/releaseScripts/default/UAutomizer-linux/z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in -t:2000 (1)] Forceful destruction successful, exit code 0 Received shutdown request... --- End real Ultimate output --- Execution finished normally Writing output log to file Ultimate.log Result: TRUE